Jump to content

Recommended Posts

Posted
I have somehow downloaded this browser hijacker and now cannot find it to uninstall it, any help would be greatly appreciated. Thanks.:)
  • Replies 31
  • Created
  • Last Reply

Top Posters In This Topic

Posted

Hi debi239,

 

My name is etavares and I'll help you remove this. To begin, please follow these instructions in the link below:

 

Before posting for Malware Removal help.

 

Please copy/paste all requested logs directly into your reply this this thread.

 

Thanks!

-etavares

Posted

I'm sorry but I have to send each scan separate.

 

Malwarebytes Anti-Malware 1.70.0.1100

www.malwarebytes.org

Database version: v2013.02.01.05

Windows 7 Service Pack 1 x64 NTFS

Internet Explorer 8.0.7601.17514

Deb :: DEB-PC [administrator]

2/1/2013 7:39:44 AM

mbam-log-2013-02-01 (07-39-44).txt

Scan type: Full scan (C:\|D:\|)

Scan options enabled: Memory | Startup | Registry | File System | Heuristics/Extra | Heuristics/Shuriken | PUP | PUM

Scan options disabled: P2P

Objects scanned: 1143749

Time elapsed: 9 hour(s), 56 minute(s), 14 second(s)

Memory Processes Detected: 0

(No malicious items detected)

Memory Modules Detected: 0

(No malicious items detected)

Registry Keys Detected: 37

HKCR\CLSID\{75EBB0AA-4214-4CB4-90EC-E3E07ECD04F7} (PUP.FunMoods) -> Quarantined and deleted successfully.

HKCR\funmoods.funmoodsHlpr.1 (PUP.FunMoods) -> Quarantined and deleted successfully.

HKCR\funmoods.funmoodsHlpr (PUP.FunMoods) -> Quarantined and deleted successfully.

HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{75EBB0AA-4214-4CB4-90EC-E3E07ECD04F7} (PUP.FunMoods) -> Quarantined and deleted successfully.

HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Settings\{75EBB0AA-4214-4CB4-90EC-E3E07ECD04F7} (PUP.FunMoods) -> Quarantined and deleted successfully.

HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{75EBB0AA-4214-4CB4-90EC-E3E07ECD04F7} (PUP.FunMoods) -> Quarantined and deleted successfully.

HKCR\CLSID\{965B9DBE-B104-44AC-950A-8A5F97AFF439} (PUP.Funmoods) -> Quarantined and deleted successfully.

HKCR\CLSID\{A4C272EC-ED9E-4ACE-A6F2-9558C7F29EF3} (PUP.Funmoods) -> Quarantined and deleted successfully.

HKCR\funmoods.dskBnd.1 (PUP.Funmoods) -> Quarantined and deleted successfully.

HKCR\funmoods.dskBnd (PUP.Funmoods) -> Quarantined and deleted successfully.

HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Settings\{A4C272EC-ED9E-4ACE-A6F2-9558C7F29EF3} (PUP.Funmoods) -> Quarantined and deleted successfully.

HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{A4C272EC-ED9E-4ACE-A6F2-9558C7F29EF3} (PUP.Funmoods) -> Quarantined and deleted successfully.

HKCR\CLSID\{A9DB719C-7156-415E-B49D-BAD039DE4F13} (PUP.Funmoods) -> Quarantined and deleted successfully.

HKCR\funmoodsApp.appCore.1 (PUP.Funmoods) -> Quarantined and deleted successfully.

HKCR\funmoodsApp.appCore (PUP.Funmoods) -> Quarantined and deleted successfully.

HKCR\CLSID\{F03FD9D0-4F2B-497C-8A71-DD41D70B07D9} (PUP.Funmoods) -> Quarantined and deleted successfully.

HKCR\f (PUP.Funmoods) -> Quarantined and deleted successfully.

HKCR\Typelib\{1D085C0A-E4F4-4F66-BDBF-4BE51015BFC3} (PUP.Funmoods) -> Quarantined and deleted successfully.

HKCR\Interface\{0D80F1C5-D17B-4177-AC68-955F3EF9F191} (PUP.Funmoods) -> Quarantined and deleted successfully.

HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Settings\{103089DA-0F31-4A8B-843F-7D24A7FE8345} (PUP.InfoAtoms) -> Quarantined and deleted successfully.

HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{103089DA-0F31-4A8B-843F-7D24A7FE8345} (PUP.InfoAtoms) -> Quarantined and deleted successfully.

HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Settings\{11111111-1111-1111-1111-110011221158} (Adware.GamePlayLab) -> Quarantined and deleted successfully.

HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{11111111-1111-1111-1111-110011221158} (Adware.GamePlayLab) -> Quarantined and deleted successfully.

HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{11111111-1111-1111-1111-110011221158} (Adware.GamePlayLab) -> Quarantined and deleted successfully.

HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Settings\{5D79F641-C168-40DF-A32F-BACEA7509E75} (PUP.MyWebSearch) -> Quarantined and deleted successfully.

HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{5D79F641-C168-40DF-A32F-BACEA7509E75} (PUP.MyWebSearch) -> Quarantined and deleted successfully.

HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Settings\{C98D5B61-B0EA-4D48-9839-1079D352D880} (PUP.MyWebSearch) -> Quarantined and deleted successfully.

HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{C98D5B61-B0EA-4D48-9839-1079D352D880} (PUP.MyWebSearch) -> Quarantined and deleted successfully.

HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Settings\{CB41FC95-F1B3-4797-8BB6-1012FF62ABBA} (PUP.MyWebSearch) -> Quarantined and deleted successfully.

HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{CB41FC95-F1B3-4797-8BB6-1012FF62ABBA} (PUP.MyWebSearch) -> Quarantined and deleted successfully.

HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{04D2B915-19FF-41E9-994D-95DC898BEA43} (PUP.MyWebSearch) -> Quarantined and deleted successfully.

HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{0696F815-A3A9-490A-BB14-9EC3350B1276} (PUP.MyWebSearch) -> Quarantined and deleted successfully.

HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{65bcd620-07dd-012f-819f-073cf1b8f7c6} (Adware.GamePlayLab) -> Quarantined and deleted successfully.

HKCU\Software\Google\Chrome\Extensions\bbjciahceamgodcoidkjpchnokgfpphh (PUP.Funmoods) -> Quarantined and deleted successfully.

HKCU\Software\Google\Chrome\Extensions\cjpglkicenollcignonpgiafdgfeehoj (PUP.FunMoods) -> Quarantined and deleted successfully.

HKLM\SOFTWARE\Google\Chrome\Extensions\bbjciahceamgodcoidkjpchnokgfpphh (PUP.Funmoods) -> Quarantined and deleted successfully.

HKLM\SOFTWARE\Google\Chrome\Extensions\cjpglkicenollcignonpgiafdgfeehoj (PUP.FunMoods) -> Quarantined and deleted successfully.

Registry Values Detected: 2

HKLM\SOFTWARE\Microsoft\Internet Explorer\Toolbar|{A4C272EC-ED9E-4ACE-A6F2-9558C7F29EF3} (PUP.Funmoods) -> Data: Funmoods Toolbar -> Quarantined and deleted successfully.

HKLM\SOFTWARE\Microsoft\Internet Explorer\Toolbar\{A4C272EC-ED9E-4ACE-A6F2-9558C7F29EF3} (PUP.Funmoods) -> Data: -> Quarantined and deleted successfully.

Registry Data Items Detected: 5

HKCU\SOFTWARE\Microsoft\Internet Explorer\Main|Search Bar (Hijack.SearchPage) -> Bad: (http://search.certified-toolbar.com?si=41460&tid=3204&bs=true&q=) Good: (http://www.google.com) -> Quarantined and repaired successfully.

HKCU\SOFTWARE\Microsoft\Internet Explorer\Main|Default_Search_URL (Hijack.SearchPage) -> Bad: (http://search.certified-toolbar.com?si=41460&tid=3204&bs=true&q=) Good: (http://www.google.com) -> Quarantined and repaired successfully.

HKCU\SOFTWARE\Microsoft\Internet Explorer\Search|Default_Search_URL (Hijack.SearchPage) -> Bad: (http://search.certified-toolbar.com?si=41460&tid=3204&bs=true&q=) Good: (http://www.google.com/) -> Quarantined and repaired successfully.

HKLM\SOFTWARE\Microsoft\Internet Explorer\Main|Search Bar (Hijack.SearchPage) -> Bad: (http://search.certified-toolbar.com?si=41460&tid=3204&bs=true&q=) Good: (http://www.google.com) -> Quarantined and repaired successfully.

HKLM\SOFTWARE\Microsoft\Internet Explorer\Search|Default_Search_URL (Hijack.SearchPage) -> Bad: (http://search.certified-toolbar.com?si=41460&tid=3204&bs=true&q=) Good: (http://www.google.com/) -> Quarantined and repaired successfully.

Folders Detected: 3

C:\Program Files (x86)\MyWebSearch (PUP.MyWebSearch) -> Quarantined and deleted successfully.

C:\Program Files (x86)\MyWebSearch\bar (PUP.MyWebSearch) -> Quarantined and deleted successfully.

C:\Program Files (x86)\MyWebSearch\bar\1.bin (PUP.MyWebSearch) -> Quarantined and deleted successfully.

Files Detected: 10

C:\Program Files (x86)\64res.dll (PUP.MyWebSearch) -> Quarantined and deleted successfully.

C:\Program Files (x86)\64Uninstall TelevisionFanatic.dll (PUP.MyWebSearch) -> Quarantined and deleted successfully.

C:\Program Files (x86)\MyWebSearch\bar\1.bin\F3IMSTUB.DLL (PUP.FunWebProducts) -> Quarantined and deleted successfully.

C:\Program Files (x86)\MyWebSearch\bar\1.bin\M3MEDINT.EXE (PUP.MyWebSearch) -> Quarantined and deleted successfully.

C:\Program Files (x86)\WnSoft PicturesToExe\5.6\PicturesToExe.exe (Rogue.FakeMSE) -> Quarantined and deleted successfully.

C:\Users\Deb\AppData\LocalLow\DailyBibleGuideEI\Installr\Cache\004632E3.exe (PUP.MyWebSearch) -> Quarantined and deleted successfully.

C:\Users\Deb\AppData\LocalLow\TelevisionFanaticEI\Installr\Cache\00216C3A.exe (PUP.MyWebSearch) -> Quarantined and deleted successfully.

C:\Users\Deb\Downloads\Program\CORE10k.EXE (Dont.Steal.Our.Software) -> Quarantined and deleted successfully.

C:\Windows\System32\t5rdv.dll (Malware.Packer.Gen) -> Quarantined and deleted successfully.

C:\Program Files (x86)\MyWebSearch\bar\1.bin\CHROME.MANIFEST (PUP.MyWebSearch) -> Quarantined and deleted successfully.

(end)

Posted

This is what I get when I try to post the OTL scans. Is there any other way I can get them to you.

 

[h=3]The following errors occurred with your submission[/h]

  1. The text that you have entered is too long (91261 characters). Please shorten it to 80000 characters long.

Posted

Hi debi;

 

Make two posts. Put part of the text in each post please.

We are all members helping other members. Please return here where you may be able to help someone else. After all, no one knows everything and you may have the answer that someone needs.

Get help with computer problems. Join Free PC Help here

 

Donations are welcome. Read Here

Posted

OTL logfile created on: 2/1/2013 5:52:35 PM - Run 1

OTL by OldTimer - Version 3.2.69.0 Folder = C:\Users\Deb\Desktop

64bit- Home Premium Edition Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation

Internet Explorer (Version = 8.0.7601.17514)

Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

 

3.97 Gb Total Physical Memory | 1.43 Gb Available Physical Memory | 35.95% Memory free

7.93 Gb Paging File | 5.56 Gb Available in Paging File | 70.17% Paging File free

Paging file location(s): ?:\pagefile.sys [binary data]

 

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)

Drive C: | 116.44 Gb Total Space | 26.69 Gb Free Space | 22.92% Space Free | Partition Type: NTFS

Drive D: | 337.60 Gb Total Space | 87.33 Gb Free Space | 25.87% Space Free | Partition Type: NTFS

 

Computer Name: DEB-PC | User Name: Deb | Logged in as Administrator.

Boot Mode: Normal | Scan Mode: Current user | Include 64bit Scans

Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

 

========== Processes (SafeList) ==========

 

PRC - C:\Users\Deb\Desktop\OTL.scr (OldTimer Tools)

PRC - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe (Adobe Systems Incorporated)

PRC - C:\Program Files (x86)\Real\RealPlayer\Update\realsched.exe (RealNetworks, Inc.)

PRC - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbarUser_32.exe (Google Inc.)

PRC - C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe (Avira Operations GmbH & Co. KG)

PRC - C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe (Avira Operations GmbH & Co. KG)

PRC - C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe (Avira Operations GmbH & Co. KG)

PRC - C:\Program Files (x86)\RealNetworks\RealDownloader\rndlresolversvc.exe ()

PRC - C:\Users\Deb\AppData\Local\Akamai\netsession_win.exe (Akamai Technologies, Inc.)

PRC - C:\Program Files (x86)\lg_fwupdate\fwupdate.exe (BitLeader)

PRC - C:\Program Files (x86)\Kodak\AiO\Center\EKAiOHostService.exe (Eastman Kodak Company)

PRC - C:\Program Files (x86)\Common Files\ArcSoft\esinter\Bin\eservutil.exe (ArcSoft Inc.)

PRC - C:\Program Files (x86)\DailyBibleGuide\bar\1.bin\2vbarsvc.exe (DailyBibleGuide)

PRC - C:\Program Files (x86)\DailyBibleGuide\bar\1.bin\2vbrmon.exe (DailyBibleGuide)

PRC - C:\Program Files (x86)\Pando Networks\Pando\Pando.exe (Pando Networks)

PRC - C:\Program Files (x86)\HiYo\Bin\HiYo.exe (IncrediMail, Ltd.)

PRC - C:\Program Files (x86)\AWS\WeatherBug\Weather.exe (AWS Convergence Technologies, Inc.)

PRC - C:\Windows\AsScrPro.exe (ASUS)

PRC - C:\Program Files (x86)\ASUS\Wireless Console 3\wcourier.exe ()

PRC - C:\Windows\SysWOW64\Fast Boot\FastBootAgent.exe (ASUSTeK Computer Inc.)

PRC - C:\Program Files (x86)\ASUS\ControlDeck\ControlDeckStartUp.exe ()

PRC - C:\Program Files (x86)\ASUS\ATK Hotkey\HControl.exe (ASUS)

PRC - C:\Program Files (x86)\ASUS\ATKOSD2\ATKOSD2.exe (ASUS)

PRC - C:\Program Files (x86)\ASUS\ASUS Data Security Manager\ADSMTray.exe (ASUSTek Computer Inc.)

PRC - C:\Program Files (x86)\ASUS\ATK Hotkey\HControlUser.exe (ASUS)

PRC - C:\Program Files (x86)\ASUS\ATK Hotkey\ATKOSD.exe (ASUS)

PRC - C:\Program Files (x86)\ASUS\ATK Hotkey\AsLdrSrv.exe (ASUS)

PRC - C:\Program Files (x86)\ASUS\SmartLogon\sensorsrv.exe (ASUS)

PRC - C:\Program Files (x86)\ASUS\ATK Media\DMedia.exe (ASUS)

PRC - C:\Program Files (x86)\ASUS\ATK Hotkey\WDC.exe (ASUS)

PRC - C:\Program Files (x86)\Yahoo!\SoftwareUpdate\YahooAUService.exe (Yahoo! Inc.)

PRC - C:\Program Files (x86)\ASUS\ATK Hotkey\KBFiltr.exe (ASUS)

PRC - C:\Program Files (x86)\ASUS\ATK Hotkey\Atouch64.exe ()

PRC - C:\Program Files (x86)\ASUS\ASUS Data Security Manager\ADSMSrv.exe (ASUSTek Computer Inc.)

PRC - C:\Program Files (x86)\ASUS\ASUS Live Update\ALU.exe ()

PRC - C:\Program Files (x86)\Webroot\Washer\WasherSvc.exe (Webroot Software, Inc.)

PRC - C:\Program Files (x86)\Webroot\Washer\wwDisp.exe (Webroot Software, Inc.)

PRC - C:\Program Files\ATKGFNEX\GFNEXSrv.exe ()

PRC - C:\Sierra\Planner\PLNRnote.exe (Sierra Online)

 

 

========== Modules (No Company Name) ==========

 

MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\PresentationFramewo#\d7d20811a7ce7cc589153648cbb1ce5c\PresentationFramework.Aero.ni.dll ()

MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\PresentationFramewo#\ff7c9a4f41f7cccc47e696c11b9f8469\PresentationFramework.ni.dll ()

MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\PresentationCore\19b3d17c3ce0e264c4fb62028161adf7\PresentationCore.ni.dll ()

MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\WindowsBase\cf827fe7bc99d9bcf0ba3621054ef527\WindowsBase.ni.dll ()

MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\System\369f8bdca364e2b4936d18dea582912c\System.ni.dll ()

MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\mscorlib\7150b9136fad5b79e88f6c7f9d3d2c39\mscorlib.ni.dll ()

MOD - C:\Program Files (x86)\HiYo\Bin\AppServerCommunication.dll ()

MOD - C:\Program Files (x86)\HiYo\Bin\IMHttpComm.dll ()

MOD - C:\Program Files (x86)\ASUS\Wireless Console 3\wcourier.exe ()

MOD - C:\Program Files (x86)\ASUS\ControlDeck\ControlDeckStartUp.exe ()

MOD - C:\Program Files (x86)\ASUS\VirtualCamera\virtualCamera.ax ()

MOD - C:\Program Files (x86)\ASUS\ASUS Live Update\ALU.exe ()

MOD - C:\Program Files (x86)\Webroot\Washer\Languages\English.dll ()

MOD - C:\Program Files (x86)\ASUS\ASUS Data Security Manager\ShlExt\x86\OverlayIconShlExt.dll ()

MOD - C:\Program Files (x86)\ASUS\ASUS Data Security Manager\ShlExt\x86\OverlayIconShlExt1.dll ()

 

 

========== Services (SafeList) ==========

 

SRV:64bit: - (wlcrasvc) -- C:\Program Files\Windows Live\Mesh\wlcrasvc.exe (Microsoft Corporation)

SRV:64bit: - (WinDefend) -- C:\Program Files\Windows Defender\MpSvc.dll (Microsoft Corporation)

SRV:64bit: - (ATKGFNEXSrv) -- C:\Program Files\ATKGFNEX\GFNEXSrv.exe ()

SRV - (AdobeFlashPlayerUpdateSvc) -- C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe (Adobe Systems Incorporated)

SRV - (AdobeARMservice) -- C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe (Adobe Systems Incorporated)

SRV - (FBDiskOptimizer) -- C:\Program Files (x86)\FixBee\FBDefragSrv64.exe (FixBee., (www.fixbee.com))

SRV - (AntiVirSchedulerService) -- C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe (Avira Operations GmbH & Co. KG)

SRV - (AntiVirService) -- C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe (Avira Operations GmbH & Co. KG)

SRV - (RealNetworks Downloader Resolver Service) -- C:\Program Files (x86)\RealNetworks\RealDownloader\rndlresolversvc.exe ()

SRV - (Akamai) -- c:\program files (x86)\common files\akamai/netsession_win_ce5ba24.dll ()

SRV - (Kodak AiO Network Discovery Service) -- C:\Program Files (x86)\Kodak\AiO\Center\EKAiOHostService.exe (Eastman Kodak Company)

SRV - (ADExchange) -- C:\Program Files (x86)\Common Files\ArcSoft\esinter\Bin\eservutil.exe (ArcSoft Inc.)

SRV - (FLEXnet Licensing Service) -- C:\Program Files (x86)\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe (Macrovision Europe Ltd.)

SRV - (DailyBibleGuideService) -- C:\Program Files (x86)\DailyBibleGuide\bar\1.bin\2vbarsvc.exe (DailyBibleGuide)

SRV - (clr_optimization_v4.0.30319_32) -- C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe (Microsoft Corporation)

SRV - (SwitchBoard) -- C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe (Adobe Systems Incorporated)

SRV - (FastBootAgent) -- C:\Windows\SysWOW64\Fast Boot\FastBootAgent.exe (ASUSTeK Computer Inc.)

SRV - (ASLDRService) -- C:\Program Files (x86)\ASUS\ATK Hotkey\AsLdrSrv.exe (ASUS)

SRV - (clr_optimization_v2.0.50727_32) -- C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe (Microsoft Corporation)

SRV - (YahooAUService) -- C:\Program Files (x86)\Yahoo!\SoftwareUpdate\YahooAUService.exe (Yahoo! Inc.)

SRV - (ADSMService) -- C:\Program Files (x86)\ASUS\ASUS Data Security Manager\ADSMSrv.exe (ASUSTek Computer Inc.)

SRV - (wwEngineSvc) -- C:\Program Files (x86)\Webroot\Washer\WasherSvc.exe (Webroot Software, Inc.)

SRV - (Crypkey License) -- C:\Windows\SysWow64\Crypserv.exe (Kenonic Controls Ltd.)

 

 

========== Driver Services (SafeList) ==========

 

DRV:64bit: - (avipbb) -- C:\Windows\SysNative\drivers\avipbb.sys (Avira Operations GmbH & Co. KG)

DRV:64bit: - (avgntflt) -- C:\Windows\SysNative\drivers\avgntflt.sys (Avira Operations GmbH & Co. KG)

DRV:64bit: - (avkmgr) -- C:\Windows\SysNative\drivers\avkmgr.sys (Avira Operations GmbH & Co. KG)

DRV:64bit: - (PCWinSoft) -- C:\Windows\SysNative\drivers\scrcamnetdriver_x64.sys (Windows ® Server 2003 DDK provider)

DRV:64bit: - (fssfltr) -- C:\Windows\SysNative\drivers\fssfltr.sys (Microsoft Corporation)

DRV:64bit: - (Fs_Rec) -- C:\Windows\SysNative\drivers\fs_rec.sys (Microsoft Corporation)

DRV:64bit: - (DigiartyVirtualCDBus) -- C:\Windows\SysNative\drivers\DigiartyVirtualCDBus.sys (Digiarty Software, Inc.)

DRV:64bit: - (athr) -- C:\Windows\SysNative\drivers\athrx.sys (Atheros Communications, Inc.)

DRV:64bit: - (AnyDVD) -- C:\Windows\SysNative\drivers\AnyDVD.sys (SlySoft, Inc.)

DRV:64bit: - (amdsata) -- C:\Windows\SysNative\drivers\amdsata.sys (Advanced Micro Devices)

DRV:64bit: - (amdxata) -- C:\Windows\SysNative\drivers\amdxata.sys (Advanced Micro Devices)

DRV:64bit: - (igfx) -- C:\Windows\SysNative\drivers\igdkmd64.sys (Intel Corporation)

DRV:64bit: - (FARMNTIO) -- C:\Windows\SysNative\drivers\FarMntIo.sys ()

DRV:64bit: - (ElbyCDIO) -- C:\Windows\SysNative\drivers\ElbyCDIO.sys (Elaborate Bytes AG)

DRV:64bit: - (HpSAMD) -- C:\Windows\SysNative\drivers\HpSAMD.sys (Hewlett-Packard Company)

DRV:64bit: - (TsUsbFlt) -- C:\Windows\SysNative\drivers\TsUsbFlt.sys (Microsoft Corporation)

DRV:64bit: - (AsDsm) -- C:\Windows\SysNative\drivers\AsDsm.sys (ASUSTek Computer Inc)

DRV:64bit: - (L1E) -- C:\Windows\SysNative\drivers\L1E62x64.sys (Atheros Communications, Inc.)

DRV:64bit: - (kbfiltr) -- C:\Windows\SysNative\drivers\kbfiltr.sys ( )

DRV:64bit: - (amdsbs) -- C:\Windows\SysNative\drivers\amdsbs.sys (AMD Technologies Inc.)

DRV:64bit: - (LSI_SAS2) -- C:\Windows\SysNative\drivers\lsi_sas2.sys (LSI Corporation)

DRV:64bit: - (stexstor) -- C:\Windows\SysNative\drivers\stexstor.sys (Promise Technology)

DRV:64bit: - (StillCam) -- C:\Windows\SysNative\drivers\serscan.sys (Microsoft Corporation)

DRV:64bit: - (VIAHdAudAddService) -- C:\Windows\SysNative\drivers\viahduaa.sys (VIA Technologies, Inc.)

DRV:64bit: - (ETD) -- C:\Windows\SysNative\drivers\ETD.sys (ELAN Microelectronic Corp.)

DRV:64bit: - (lullaby) -- C:\Windows\SysNative\drivers\lullaby.sys (Windows ® Win 7 DDK provider)

DRV:64bit: - (SiSGbeLH) -- C:\Windows\SysNative\drivers\SiSG664.sys (Silicon Integrated Systems Corp.)

DRV:64bit: - (ebdrv) -- C:\Windows\SysNative\drivers\evbda.sys (Broadcom Corporation)

DRV:64bit: - (b06bdrv) -- C:\Windows\SysNative\drivers\bxvbda.sys (Broadcom Corporation)

DRV:64bit: - (b57nd60a) -- C:\Windows\SysNative\drivers\b57nd60a.sys (Broadcom Corporation)

DRV:64bit: - (hcw85cir) -- C:\Windows\SysNative\drivers\hcw85cir.sys (Hauppauge Computer Works, Inc.)

DRV:64bit: - (iaStor) -- C:\Windows\SysNative\drivers\iaStor.sys (Intel Corporation)

DRV:64bit: - (AmUStor) -- C:\Windows\SysNative\drivers\AmUStor.sys (Alcor Micro, Corp.)

DRV:64bit: - (SNP2UVC) -- C:\Windows\SysNative\drivers\snp2uvc.sys ()

DRV:64bit: - (MTsensor) -- C:\Windows\SysNative\drivers\ATK64AMD.sys (ASUS)

DRV:64bit: - (WimFltr) -- C:\Windows\SysNative\drivers\WimFltr.sys (Microsoft Corporation)

DRV:64bit: - (ASMMAP64) -- C:\Program Files\ATKGFNEX\ASMMAP64.sys ()

DRV:64bit: - (SCDEmu) -- C:\Windows\SysNative\drivers\scdemu.sys (PowerISO Computing, Inc.)

DRV - (AnyDVD) -- C:\Windows\SysWOW64\drivers\AnyDVD.sys (SlySoft, Inc.)

DRV - (WIMMount) -- C:\Windows\SysWOW64\drivers\wimmount.sys (Microsoft Corporation)

DRV - (NetworkX) -- C:\Windows\SysWOW64\Ckldrv.sys ()

 

 

========== Standard Registry (SafeList) ==========

 

 

========== Internet Explorer ==========

 

IE:64bit: - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://start.funmoods.com/?f=1&a=bf3&chnl=bf3&cd=2XzuyEtN2Y1L1Qzu0EtD0C0ByE0EtA0DyEyDtC0FtAyCtBtAtN0D0Tzu0CtBtAtBtN1L2XzutBtFtCtFtCtFtAtCtB&cr=801427480

IE:64bit: - HKLM\..\SearchScopes,DefaultScope = {6A1806CD-94D4-4689-BA73-E35EA1EA9990}

IE:64bit: - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}&FORM=IE8SRC

IE:64bit: - HKLM\..\SearchScopes\{6A1806CD-94D4-4689-BA73-E35EA1EA9990}: "URL" = http://www.google.com/search?q={searchTerms}&rls=com.microsoft:{language}:{referrer:source?}&ie={inputEncoding}&oe={outputEncoding}&sourceid=ie7

IE:64bit: - HKLM\..\SearchScopes\{9BB47C17-9C68-4BB3-B188-DD9AF0FD2408}: "URL" = http://dts.search-results.com/sr?src=ieb&gct=ds&appid=104&systemid=408&apn_dtid=BND408&apn_ptnrs=AGF&o=APN10654&apn_uid=7193510456114116&q={searchTerms}

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = about:blank

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = about:blank

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Search Bar = http://www.google.com

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Default_Page_URL = http://search.certified-toolbar.com?si=41460&home=true&tid=3204

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = about:blank

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,Default_Search_URL = http://www.google.com/

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,Search Bar = http://search.certified-toolbar.com?si=41460&tid=3204&bs=true&q=

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,Search Page = http://search.certified-toolbar.com?si=41460&tid=3204&bs=true&q=

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,Start Default_Page_URL = http://search.certified-toolbar.com?si=41460&home=true&tid=3204

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,Start Page = http://search.certified-toolbar.com?si=41460&home=true&tid=3204

IE - HKLM\..\URLSearchHook: {d40b90b4-d3b1-4d6b-a5d7-dc041c1b76c0} - C:\Program Files (x86)\IncrediMail_MediaBar_2\prxtbInc0.dll (Conduit Ltd.)

IE - HKLM\..\SearchScopes,Backup.Old.DefaultScope = {6A1806CD-94D4-4689-BA73-E35EA1EA9990}

IE - HKLM\..\SearchScopes,DefaultScope = {afdbddaa-5d3f-42ee-b79c-185a7020515b}

IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}&FORM=IE8SRC

IE - HKLM\..\SearchScopes\{34e26447-bf30-4c78-a5b9-61dfa8a55e67}: "URL" = http://search.mywebsearch.com/mywebsearch/GGmain.jhtml?id=XMxdm0488Jus&ptnrS=XMxdm0488Jus&si=100767&ptb=858F2DF0-1B0D-40B3-8F33-AD80FF15F0F6&psa=&ind=2011050310&st=sb&n=77de3146&searchfor={searchTerms}

IE - HKLM\..\SearchScopes\{6A1806CD-94D4-4689-BA73-E35EA1EA9990}: "URL" = http://start.funmoods.com/results.php?f=4&q={searchTerms}&a=bf3&chnl=bf3&cd=2XzuyEtN2Y1L1Qzu0EtD0C0ByE0EtA0DyEyDtC0FtAyCtBtAtN0D0Tzu0CtBtAtBtN1L2XzutBtFtCtFtCtFtAtCtB&cr=801427480

IE - HKLM\..\SearchScopes\{7C19EC30-6FAD-B9F6-82AA-0C5189279B17}: "URL" = http://search.certified-toolbar.com?si=41460&bs=true&tid=3204&q={searchTerms}

IE - HKLM\..\SearchScopes\{9BB47C17-9C68-4BB3-B188-DD9AF0FD2408}: "URL" = http://dts.search-results.com/sr?src=ieb&gct=ds&appid=104&systemid=408&apn_dtid=BND408&apn_ptnrs=AGF&o=APN10654&apn_uid=7193510456114116&q={searchTerms}

IE - HKLM\..\SearchScopes\{afdbddaa-5d3f-42ee-b79c-185a7020515b}: "URL" = http://www.google.com/search?q={searchTerms}&rls=com.microsoft:{language}:{referrer:source?}&ie={inputEncoding}&oe={outputEncoding}&sourceid=ie7

IE - HKLM\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

 

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Backup.Old.Start Page = http://www.google.com/ig

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL = http://www.google.com

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = about:blank

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Bar = http://www.google.com

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Default_Page_URL = http://search.certified-toolbar.com?si=41460&home=true&tid=3204

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://igoogle.com/

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = http://www.msn.com/

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = en-us

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = D6 0A A2 81 91 98 CB 01 [binary data]

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Restore = http://mystart.hiyo.com

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Search,Default_Search_URL = http://www.google.com/

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Search,Search Bar = http://search.certified-toolbar.com?si=41460&tid=3204&bs=true&q=

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Search,Search Page = http://search.certified-toolbar.com?si=41460&tid=3204&bs=true&q=

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Search,Start Default_Page_URL = http://search.certified-toolbar.com?si=41460&home=true&tid=3204

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Search,Start Page = http://search.certified-toolbar.com?si=41460&home=true&tid=3204

IE - HKCU\..\URLSearchHook: {f15ff29f-85a1-43cd-9674-e5ba40016c97} - C:\Program Files (x86)\DailyBibleGuide\bar\1.bin\2vSrcAs.dll (DailyBibleGuide)

IE - HKCU\..\SearchScopes,Backup.Old.DefaultScope = {6A1806CD-94D4-4689-BA73-E35EA1EA9990}

IE - HKCU\..\SearchScopes,DefaultScope = {6A1806CD-94D4-4689-BA73-E35EA1EA9990}

IE - HKCU\..\SearchScopes\{0169E633-8781-F882-9BC7-7B014AE4DE4E}: "URL" = http://www.bing.com/search?q={searchTerms}&pc=Z206&form=ZGAIDF&install_date=20111005&iesrc={referrer:source}

IE - HKCU\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}&src=IE-SearchBox&FORM=IE8SRC

IE - HKCU\..\SearchScopes\{30CFB165-2CF1-7712-E58F-3A8DBE9E3CFA}: "URL" = http://www.incredimail-start.com/s/?q={searchTerms}&iesrc=IE-SearchBox&site=Bing&cfg=2-428-0-2x4co

IE - HKCU\..\SearchScopes\{34e26447-bf30-4c78-a5b9-61dfa8a55e67}: "URL" = http://search.mywebsearch.com/mywebsearch/GGmain.jhtml?id=XMxdm0488Jus&ptnrS=XMxdm0488Jus&si=100767&ptb=858F2DF0-1B0D-40B3-8F33-AD80FF15F0F6&psa=&ind=2011050310&st=sb&n=77de3146&searchfor={searchTerms}

IE - HKCU\..\SearchScopes\{4A7BC363-1B1A-469A-8A9F-B08D6190106D}: "URL" = http://search.yahoo.com/search?fr=chr-greentree_ie&ei=utf-8&type=685749&p={searchTerms}

IE - HKCU\..\SearchScopes\{63EA0726-C83D-C02E-CF27-0160BA4048EB}: "URL" = http://www.bing.com/search?q={searchTerms}&pc=ZUGO&form=ZGAIDF

IE - HKCU\..\SearchScopes\{6A1806CD-94D4-4689-BA73-E35EA1EA9990}: "URL" = http://www.google.com/search?q={searchTerms}&rls=com.microsoft:{language}:{referrer:source?}&ie={inputEncoding}&oe={outputEncoding}&sourceid=ie7&rlz=1I7ADRA_enUS409

IE - HKCU\..\SearchScopes\{7B778A05-D20F-5F8F-66DF-EA2ADE1B9C35}: "URL" = http://www.bing.com/search?q={searchTerms}&pc=ZUGO&form=ZGAIDF

IE - HKCU\..\SearchScopes\{7C19EC30-6FAD-B9F6-82AA-0C5189279B17}: "URL" = http://www.google.com/search?q={searchTerms}&rls=com.microsoft:{language}:{referrer:source?}&ie={inputEncoding}&oe={outputEncoding}&sourceid=ie7&rlz=1I7ADRA_enUS409

IE - HKCU\..\SearchScopes\{8B63A8D6-BBED-4341-8867-790E5F524C96}: "URL" = http://mystart.incredimail.com/?search={searchTerms}&loc=search_box

IE - HKCU\..\SearchScopes\{9BB47C17-9C68-4BB3-B188-DD9AF0FD2408}: "URL" = http://dts.search-results.com/sr?src=ieb&gct=ds&appid=104&systemid=408&apn_dtid=BND408&apn_ptnrs=AGF&o=APN10654&apn_uid=7193510456114116&q={searchTerms}

IE - HKCU\..\SearchScopes\{afdbddaa-5d3f-42ee-b79c-185a7020515b}: "URL" = http://www.google.com/search?q={searchTerms}&rls=com.microsoft:{language}:{referrer:source?}&ie={inputEncoding}&oe={outputEncoding}&sourceid=ie7&rlz=1I7ADRA_enUS409

IE - HKCU\..\SearchScopes\{C7576B9D-B442-46bc-AF74-080A9E723E01}: "URL" = http://websearch.search-results.com/redirect?client=ie&tb=BBY2-SRS&o=41647948&src=crm&q={searchTerms}&locale=en_US&apn_ptnrs=7S&apn_dtid=YYYYYYYYUS&apn_uid=9031D046-42A2-4C65-84EC-C9DFB269878A&apn_sauid=7AB86833-9B02-4D34-9041-8E0487E93484

IE - HKCU\..\SearchScopes\{CFF4DB9B-135F-47c0-9269-B4C6572FD61A}: "URL" = http://mystart.incredimail.com//?search={searchTerms}&loc=search_box&a=1pcqIQ5iKit

IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = 127.0.0.1:9421;<local>

 

 

========== FireFox ==========

 

FF:64bit: - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: disabled File not found

FF - HKLM\Software\MozillaPlugins\@DailyBibleGuide.com/Plugin: C:\Program Files (x86)\DailyBibleGuide\bar\1.bin\NP2vStub.dll (DailyBibleGuide)

FF - HKLM\Software\MozillaPlugins\@java.com/DTPlugin,version=1.6.0_37: C:\Windows\SysWOW64\npdeployJava1.dll (Sun Microsystems, Inc.)

FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin: C:\Program Files (x86)\Java\jre6\bin\plugin2\npjp2.dll (Sun Microsystems, Inc.)

FF - HKLM\Software\MozillaPlugins\@messenger.yahoo.com/YahooMessengerStatePlugin;version=1.0.0.6: C:\Program Files (x86)\Yahoo!\Shared\npYState.dll (Yahoo! Inc.)

FF - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: disabled File not found

FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: C:\Program Files (x86)\Microsoft Silverlight\4.1.10329.0\npctrl.dll ( Microsoft Corporation)

FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3502.0922: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)

FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3508.1109: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)

FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3538.0513: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)

FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3555.0308: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)

FF - HKLM\Software\MozillaPlugins\@real.com/nppl3260;version=16.0.0.282: c:\program files (x86)\real\realplayer\Netscape6\nppl3260.dll (RealNetworks, Inc.)

FF - HKLM\Software\MozillaPlugins\@real.com/nprndlchromebrowserrecordext;version=1.3.0: C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\MozillaPlugins\nprndlchromebrowserrecordext.dll (RealNetworks, Inc.)

FF - HKLM\Software\MozillaPlugins\@real.com/nprndlhtml5videoshim;version=1.3.0: C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\MozillaPlugins\nprndlhtml5videoshim.dll (RealNetworks, Inc.)

FF - HKLM\Software\MozillaPlugins\@real.com/nprndlpepperflashvideoshim;version=1.3.0: C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\MozillaPlugins\nprndlpepperflashvideoshim.dll (RealNetworks, Inc.)

FF - HKLM\Software\MozillaPlugins\@real.com/nprpplugin;version=16.0.0.282: c:\program files (x86)\real\realplayer\Netscape6\nprpplugin.dll (RealPlayer)

FF - HKLM\Software\MozillaPlugins\@realnetworks.com/npdlplugin;version=1: C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\npdlplugin.dll (RealDownloader)

FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Program Files (x86)\Google\Update\1.3.21.123\npGoogleUpdate3.dll (Google Inc.)

FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Program Files (x86)\Google\Update\1.3.21.123\npGoogleUpdate3.dll (Google Inc.)

FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files (x86)\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)

 

FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\smartwebprinting@hp.com: C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3 [2012/05/28 07:33:53 | 000,000,000 | ---D | M]

FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\2vffxtbr@DailyBibleGuide.com: C:\Program Files (x86)\DailyBibleGuide\bar\1.bin [2011/10/14 06:41:49 | 000,000,000 | ---D | M]

FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{ABDE892B-13A8-4d1b-88E6-365A6E755758}: C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\Firefox\Ext

FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{97E22097-9A2F-45b1-8DAF-36AD648C7EF4}: C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\Firefox\Ext

FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{34712C68-7391-4c47-94F3-8F88D49AD632}: C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\Firefox\Ext\ [2012/12/18 08:19:49 | 000,000,000 | ---D | M]

FF - HKEY_CURRENT_USER\software\mozilla\Firefox\Extensions\\smartwebprinting@hp.com: C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3 [2012/05/28 07:33:53 | 000,000,000 | ---D | M]

 

[2013/02/01 05:54:32 | 000,000,000 | ---D | M] (No name found) -- C:\Program Files (x86)\Mozilla Firefox\extensions

 

========== Chrome ==========

 

CHR - plugin: Babylon Translator (Enabled) = dhkplhfnhceodhffomolpfigojocbpcb\1.4_0

CHR - plugin: Error reading preferences file

CHR - Extension: No name found = C:\Users\Deb\AppData\Local\Google\Chrome\User Data\Default\Extensions\bbjciahceamgodcoidkjpchnokgfpphh\1.0_0\

CHR - Extension: No name found = C:\Users\Deb\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.5_1\

CHR - Extension: No name found = C:\Users\Deb\AppData\Local\Google\Chrome\User Data\Default\Extensions\cjpglkicenollcignonpgiafdgfeehoj\4.0_0\

CHR - Extension: No name found = C:\Users\Deb\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf\0.0.0.19_1\

CHR - Extension: No name found = C:\Users\Deb\AppData\Local\Google\Chrome\User Data\Default\Extensions\dhkplhfnhceodhffomolpfigojocbpcb\1.4_0\

CHR - Extension: No name found = C:\Users\Deb\AppData\Local\Google\Chrome\User Data\Default\Extensions\fpcpcabjajdjmbkfinphfdflfipmalnj\1.0_0\

CHR - Extension: No name found = C:\Users\Deb\AppData\Local\Google\Chrome\User Data\Default\Extensions\idhngdhcfkoamngbedgpaokgjbnpdiji\1.3.0_0\

CHR - Extension: No name found = C:\Users\Deb\AppData\Local\Google\Chrome\User Data\Default\Extensions\ihflimipbcaljfnojhhknppphnnciiif\1.6.0_0\

CHR - Extension: No name found = C:\Users\Deb\AppData\Local\Google\Chrome\User Data\Default\Extensions\ihflimipbcaljfnojhhknppphnnciiif\1.6.0_0\facemoods\

CHR - Extension: No name found = C:\Users\Deb\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia\7_1\

 

O1 HOSTS File: ([2009/06/10 15:00:26 | 000,000,824 | ---- | M]) - C:\Windows\SysNative\drivers\etc\hosts

O2:64bit: - BHO: (SnagIt Toolbar Loader) - {00C6482D-C502-44C8-8409-FCE54AD9C208} - C:\Program Files (x86)\TechSmith\Snagit 10\DLLx64\SnagitBHO64.dll (TechSmith Corporation)

O2:64bit: - BHO: (Google Toolbar Helper) - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll (Google Inc.)

O2:64bit: - BHO: (Google Toolbar Notifier BHO) - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.7.8313.1002\swg64.dll (Google Inc.)

O2 - BHO: (SnagIt Toolbar Loader) - {00C6482D-C502-44C8-8409-FCE54AD9C208} - C:\Program Files (x86)\TechSmith\Snagit 10\SnagitBHO.dll (TechSmith Corporation)

O2 - BHO: (&Yahoo! Toolbar Helper) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\Program Files (x86)\Yahoo!\Companion\Installs\cpn0\yt.dll (Yahoo! Inc.)

O2 - BHO: (Search Assistant BHO) - {0631bff0-6846-48ca-982d-d62d7f376e97} - C:\Program Files (x86)\DailyBibleGuide\bar\1.bin\2vSrcAs.dll (DailyBibleGuide)

O2 - BHO: (RealNetworks Download and Record Plugin for Internet Explorer) - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\IE\rndlbrowserrecordplugin.dll (RealDownloader)

O2 - BHO: (Java Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre6\bin\ssv.dll (Sun Microsystems, Inc.)

O2 - BHO: (no name) - {9D425283-D487-4337-BAB6-AB8354A81457} - No CLSID value found.

O2 - BHO: (Google Toolbar Notifier BHO) - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files (x86)\Google\GoogleToolbarNotifier\5.7.8313.1002\swg.dll (Google Inc.)

O2 - BHO: (Toolbar BHO) - {beea7fa9-d1f4-49a2-9b1f-6fb7a2d9bc2a} - C:\Program Files (x86)\DailyBibleGuide\bar\1.bin\2vbar.dll (DailyBibleGuide)

O2 - BHO: (IeMonitorBho Class) - {bf00e119-21a3-4fd1-b178-3b8537e75c92} - C:\Program Files (x86)\Megaupload\Mega Manager\MegaIEMn.dll (Megaupload Limited)

O2 - BHO: (IncrediMail MediaBar 2 Toolbar) - {d40b90b4-d3b1-4d6b-a5d7-dc041c1b76c0} - C:\Program Files (x86)\IncrediMail_MediaBar_2\prxtbInc0.dll (Conduit Ltd.)

O2 - BHO: (SingleInstance Class) - {FDAD4DA1-61A2-4FD8-9C17-86F7AC245081} - C:\Program Files (x86)\Yahoo!\Companion\Installs\cpn0\YTSingleInstance.dll (Yahoo! Inc)

O3:64bit: - HKLM\..\Toolbar: (Google Toolbar) - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll (Google Inc.)

O3:64bit: - HKLM\..\Toolbar: (Snagit) - {8FF5E183-ABDE-46EB-B09E-D2AAB95CABE3} - C:\Program Files (x86)\TechSmith\Snagit 10\DLLx64\SnagitIEAddin64.dll (TechSmith Corporation)

O3:64bit: - HKLM\..\Toolbar: (no name) - Locked - No CLSID value found.

O3 - HKLM\..\Toolbar: (DailyBibleGuide) - {2a942ab7-2073-49bc-a7e1-77e93835889a} - C:\Program Files (x86)\DailyBibleGuide\bar\1.bin\2vbar.dll (DailyBibleGuide)

O3 - HKLM\..\Toolbar: (Snagit) - {8FF5E183-ABDE-46EB-B09E-D2AAB95CABE3} - C:\Program Files (x86)\TechSmith\Snagit 10\SnagitIEAddin.dll (TechSmith Corporation)

O3 - HKLM\..\Toolbar: (no name) - {9D425283-D487-4337-BAB6-AB8354A81457} - No CLSID value found.

O3 - HKLM\..\Toolbar: (IncrediMail MediaBar 2 Toolbar) - {d40b90b4-d3b1-4d6b-a5d7-dc041c1b76c0} - C:\Program Files (x86)\IncrediMail_MediaBar_2\prxtbInc0.dll (Conduit Ltd.)

O3 - HKLM\..\Toolbar: (Yahoo! Toolbar) - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files (x86)\Yahoo!\Companion\Installs\cpn0\yt.dll (Yahoo! Inc.)

O3 - HKLM\..\Toolbar: (no name) - Locked - No CLSID value found.

O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {22E03916-85C5-44B0-8DC9-1830C11238D9} - No CLSID value found.

O3:64bit: - HKCU\..\Toolbar\WebBrowser: (Google Toolbar) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll (Google Inc.)

O3 - HKCU\..\Toolbar\WebBrowser: (DailyBibleGuide) - {2A942AB7-2073-49BC-A7E1-77E93835889A} - C:\Program Files (x86)\DailyBibleGuide\bar\1.bin\2vbar.dll (DailyBibleGuide)

O3 - HKCU\..\Toolbar\WebBrowser: (IncrediMail MediaBar 2 Toolbar) - {D40B90B4-D3B1-4D6B-A5D7-DC041C1B76C0} - C:\Program Files (x86)\IncrediMail_MediaBar_2\prxtbInc0.dll (Conduit Ltd.)

O4:64bit: - HKLM..\Run: [AmIcoSinglun64] C:\Program Files (x86)\AmIcoSingLun\AmIcoSinglun64.exe (AlcorMicro Co., Ltd.)

O4:64bit: - HKLM..\Run: [EKAIO2StatusMonitor] C:\Windows\SysNative\spool\drivers\x64\3\EKAiO2MUI.exe (Eastman Kodak Company)

O4:64bit: - HKLM..\Run: [ETDWare] C:\Program Files\Elantech\ETDCtrl.exe (ELAN Microelectronic Corp.)

O4:64bit: - HKLM..\Run: [HotKeysCmds] C:\Windows\SysNative\hkcmd.exe (Intel Corporation)

O4:64bit: - HKLM..\Run: [igfxTray] C:\Windows\SysNative\igfxtray.exe (Intel Corporation)

O4:64bit: - HKLM..\Run: [Persistence] C:\Windows\SysNative\igfxpers.exe (Intel Corporation)

O4 - HKLM..\Run: [] File not found

O4 - HKLM..\Run: [AdobeCS5ServiceManager] C:\Program Files (x86)\Common Files\Adobe\CS5ServiceManager\CS5ServiceManager.exe (Adobe Systems Incorporated)

O4 - HKLM..\Run: [ATKMEDIA] C:\Program Files (x86)\ASUS\ATK Media\DMedia.exe (ASUS)

O4 - HKLM..\Run: [ATKOSD2] C:\Program Files (x86)\ASUS\ATKOSD2\ATKOSD2.exe (ASUS)

O4 - HKLM..\Run: [avgnt] C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe (Avira Operations GmbH & Co. KG)

O4 - HKLM..\Run: [Conime] %windir%\system32\conime.exe File not found

O4 - HKLM..\Run: [DailyBibleGuide Browser Plugin Loader] C:\Program Files (x86)\DailyBibleGuide\bar\1.bin\2vbrmon.exe (DailyBibleGuide)

O4 - HKLM..\Run: [HControlUser] C:\Program Files (x86)\ASUS\ATK Hotkey\HControlUser.exe (ASUS)

O4 - HKLM..\Run: [HDAudDeck] C:\Program Files (x86)\VIA\VIAudioi\VDeck\VDeck.exe (VIA)

O4 - HKLM..\Run: [Hiyo] C:\Program Files (x86)\HiYo\bin\HiYo.exe (IncrediMail, Ltd.)

O4 - HKLM..\Run: [LGODDFU] C:\Program Files (x86)\lg_fwupdate\lgfw.exe (Bitleader)

O4 - HKLM..\Run: [switchBoard] C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe (Adobe Systems Incorporated)

O4 - HKLM..\Run: [TkBellExe] c:\program files (x86)\real\realplayer\Update\realsched.exe (RealNetworks, Inc.)

O4 - HKLM..\Run: [updateLBPShortCut] C:\Program Files (x86)\CyberLink\LabelPrint\MUITransfer\MUIStartMenu.exe (CyberLink Corp.)

O4 - HKCU..\Run: [] File not found

O4 - HKCU..\Run: [AdobeBridge] File not found

O4 - HKCU..\Run: [Akamai NetSession Interface] C:\Users\Deb\AppData\Local\Akamai\netsession_win.exe (Akamai Technologies, Inc.)

O4 - HKCU..\Run: [MimarSinan Rubber Ducky Update Setup for All Users] C:\ProgramData\{C357FF4B-BB69-4DC2-9869-55F052974DA8}\Rubber Ducky.exe (MimarSinan International )

O4 - HKCU..\Run: [Pando] C:\Program Files (x86)\Pando Networks\Pando\pando.exe (Pando Networks)

O4 - HKCU..\Run: [Weather] C:\Program Files (x86)\AWS\WeatherBug\Weather.exe (AWS Convergence Technologies, Inc.)

O4 - HKCU..\Run: [Window Washer] C:\Program Files (x86)\Webroot\Washer\wwDisp.exe (Webroot Software, Inc.)

O4 - HKLM..\RunOnce: [Malwarebytes Anti-Malware] C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe (Malwarebytes Corporation)

O4 - HKLM..\RunOnce: [Malwarebytes Anti-Malware (cleanup)] C:\ProgramData\Malwarebytes\Malwarebytes' Anti-Malware\cleanup.dll (Malwarebytes Corporation)

O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Activities present

O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktop = 1

O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktopChanges = 1

O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 5

O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3

O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: PromptOnSecureDesktop = 0

O8:64bit: - Extra context menu item: Append Link Target to Existing PDF - res://C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIEAppendSelLinks.html File not found

O8:64bit: - Extra context menu item: Append to Existing PDF - res://C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIEAppend.html File not found

O8:64bit: - Extra context menu item: Convert Link Target to Adobe PDF - res://C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIECaptureSelLinks.html File not found

O8:64bit: - Extra context menu item: Convert to Adobe PDF - res://C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIECapture.html File not found

O8:64bit: - Extra context menu item: Download with Mipony - C:\Program Files (x86)\MiPony\Browser\IEContext.htm ()

O8 - Extra context menu item: Append Link Target to Existing PDF - res://C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIEAppendSelLinks.html File not found

O8 - Extra context menu item: Append to Existing PDF - res://C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIEAppend.html File not found

O8 - Extra context menu item: Convert Link Target to Adobe PDF - res://C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIECaptureSelLinks.html File not found

O8 - Extra context menu item: Convert to Adobe PDF - res://C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIECapture.html File not found

O8 - Extra context menu item: Download with Mipony - C:\Program Files (x86)\MiPony\Browser\IEContext.htm ()

O9:64bit: - Extra Button: Add to VideoGet - {88CFA58B-A63F-4A94-9C54-0C7A58E3333E} - C:\Program Files (x86)\Nuclear Coffee\VideoGet\Plugins\VideoGet_IE_x64.dll ()

O9:64bit: - Extra 'Tools' menuitem : Add to &VideoGet - {88CFA58B-A63F-4A94-9C54-0C7A58E3333E} - C:\Program Files (x86)\Nuclear Coffee\VideoGet\Plugins\VideoGet_IE_x64.dll ()

O1364bit: - gopher Prefix: missing

O13 - gopher Prefix: missing

O16 - DPF: {0D41B8C5-2599-4893-8183-00195EC8D5F9} http://support.asus.com/select/asusTek_sys_ctrl3.cab (asusTek_sysctrl Class)

O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} http://download.microsoft.com/download/E/5/6/E5611B10-0D6D-4117-8430-A67417AA88CD/LegitCheckControl.cab (Windows Genuine Advantage Validation Tool)

O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-1_6_0_37-windows-i586.cab (Java Plug-in 1.6.0_37)

O16 - DPF: {CAFEEFAC-0016-0000-0037-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-1_6_0_37-windows-i586.cab (Java Plug-in 1.6.0_37)

O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-1_6_0_37-windows-i586.cab (Java Plug-in 1.6.0_37)

O16 - DPF: {D71F9A27-723E-4B8B-B428-B725E47CBA3E} http://imikimi.com/download/imikimi_plugin_0.5.1.cab (Imikimi_activex_plugin Control)

O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab (Reg Error: Key error.)

O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.2.1

O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{FFE16A46-948F-4F90-964E-E3E86D151408}: DhcpNameServer = 192.168.2.1

O18:64bit: - Protocol\Handler\grooveLocalGWS - No CLSID value found

O18:64bit: - Protocol\Handler\livecall - No CLSID value found

O18:64bit: - Protocol\Handler\ms-help - No CLSID value found

O18:64bit: - Protocol\Handler\ms-itss - No CLSID value found

O18:64bit: - Protocol\Handler\msnim - No CLSID value found

O18:64bit: - Protocol\Handler\wlmailhtml - No CLSID value found

O18:64bit: - Protocol\Handler\wlpg - No CLSID value found

O20:64bit: - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)

O20:64bit: - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\SysNative\userinit.exe (Microsoft Corporation)

O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\SysWow64\explorer.exe (Microsoft Corporation)

O20 - HKLM Winlogon: UserInit - (C:\Windows\System32\userinit.exe) - C:\Windows\SysWOW64\userinit.exe (Microsoft Corporation)

O20:64bit: - Winlogon\Notify\igfxcui: DllName - (igfxdev.dll) - C:\Windows\SysNative\igfxdev.dll (Intel Corporation)

O21:64bit: - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.

O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.

O28:64bit: - HKLM ShellExecuteHooks: {AEB6717E-7E19-11d0-97EE-00C04FD91972} - No CLSID value found.

O32 - HKLM CDRom: AutoRun - 1

O34 - HKLM BootExecute: (autocheck autochk *)

O35:64bit: - HKLM\..comfile [open] -- "%1" %*

O35:64bit: - HKLM\..exefile [open] -- "%1" %*

O35 - HKLM\..comfile [open] -- "%1" %*

O35 - HKLM\..exefile [open] -- "%1" %*

O37:64bit: - HKLM\...com [@ = comfile] -- "%1" %*

O37:64bit: - HKLM\...exe [@ = exefile] -- "%1" %*

O37 - HKLM\...com [@ = comfile] -- "%1" %*

O37 - HKLM\...exe [@ = exefile] -- "%1" %*

O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)

O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2)

O38 - SubSystems\\Windows: (ServerDll=sxssrv,4)

Posted

MsConfig:64bit - StartUpFolder: C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^Event Reminder.lnk - C:\Program Files (x86)\Broderbund\PrintMaster\pmremind.exe - (Broderbund Properties LLC)

MsConfig:64bit - StartUpFolder: C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^FancyStart daemon.lnk - C:\Windows\Installer\{F0DF4513-3C4C-4EB8-8012-2C5F70AF3988}\_A1DDD39913A1970387B7B3.exe - ()

MsConfig:64bit - StartUpFolder: C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^HP Digital Imaging Monitor.lnk - C:\Program Files (x86)\HP\Digital Imaging\bin\hpqtra08.exe - (Hewlett-Packard Co.)

MsConfig:64bit - StartUpReg: AdobeAAMUpdater-1.0 - hkey= - key= - C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe (Adobe Systems Incorporated)

MsConfig:64bit - StartUpReg: facemoods - hkey= - key= - File not found

MsConfig:64bit - StartUpReg: HP Software Update - hkey= - key= - C:\Program Files (x86)\HP\HP Software Update\hpwuschd2.exe (Hewlett-Packard)

MsConfig:64bit - StartUpReg: InstallIQUpdater - hkey= - key= - C:\Program Files (x86)\W3i\InstallIQUpdater\InstallIQUpdater.exe (W3i, LLC)

MsConfig:64bit - StartUpReg: Messenger (Yahoo!) - hkey= - key= - C:\Program Files (x86)\Yahoo!\Messenger\YahooMessenger.exe (Yahoo! Inc.)

MsConfig:64bit - StartUpReg: PWRISOVM.EXE - hkey= - key= - C:\Program Files (x86)\PowerISO\PWRISOVM.EXE (PowerISO Computing, Inc.)

MsConfig:64bit - StartUpReg: Startup Defender - hkey= - key= - File not found

MsConfig:64bit - StartUpReg: TelevisionFanatic Browser Plugin Loader - hkey= - key= - File not found

MsConfig:64bit - State: "startup" - Reg Error: Key error.

 

CREATERESTOREPOINT

Restore point Set: OTL Restore Point

 

========== Files/Folders - Created Within 30 Days ==========

 

[2013/02/01 17:44:54 | 000,602,112 | ---- | C] (OldTimer Tools) -- C:\Users\Deb\Desktop\OTL.scr

[2013/02/01 17:25:46 | 000,000,000 | ---D | C] -- C:\Users\Deb\AppData\Local\{42234831-8B08-43B1-96A6-6045FEE150A9}

[2013/02/01 07:38:01 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes' Anti-Malware

[2013/02/01 07:37:59 | 000,024,176 | ---- | C] (Malwarebytes Corporation) -- C:\Windows\SysNative\drivers\mbam.sys

[2013/02/01 07:36:21 | 010,156,344 | ---- | C] (Malwarebytes Corporation ) -- C:\Users\Deb\Desktop\mbam-setup-1.70.0.1100.exe

[2013/02/01 05:25:08 | 000,000,000 | ---D | C] -- C:\Users\Deb\AppData\Local\{95CF7132-8491-4CD2-9E5E-97B82B87D47A}

[2013/01/31 10:01:41 | 000,000,000 | ---D | C] -- C:\Users\Deb\AppData\Local\{5047659E-C3FF-4879-99C3-07F8CA609FA6}

[2013/01/31 08:33:24 | 000,000,000 | ---D | C] -- C:\Users\Deb\AppData\Local\{0287C327-9C05-46BF-B7A1-9086769A2D0C}

[2013/01/30 08:59:26 | 000,000,000 | ---D | C] -- C:\Users\Deb\AppData\Local\{0731825A-EC4A-41FA-8E38-BAD4E1A1B061}

[2013/01/29 08:42:50 | 000,000,000 | ---D | C] -- C:\Users\Deb\AppData\Local\{553FB952-2015-4903-A09D-4F0E26A63C5E}

[2013/01/28 08:41:45 | 000,000,000 | ---D | C] -- C:\Users\Deb\AppData\Local\{A1A41F13-03AE-4BBA-A4E2-D4A593DF6E31}

[2013/01/27 09:26:47 | 000,000,000 | ---D | C] -- C:\Users\Deb\AppData\Roaming\Malwarebytes

[2013/01/27 09:26:20 | 000,000,000 | ---D | C] -- C:\ProgramData\Malwarebytes

[2013/01/27 09:26:16 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Malwarebytes' Anti-Malware

[2013/01/27 09:25:33 | 000,000,000 | ---D | C] -- C:\Users\Deb\AppData\Local\Programs

[2013/01/27 08:40:52 | 000,000,000 | ---D | C] -- C:\Users\Deb\AppData\Local\{E65F738D-9443-4971-9352-F66A692643C4}

[2013/01/24 19:47:50 | 000,000,000 | ---D | C] -- C:\Users\Deb\AppData\Local\{740A36B2-621C-4272-845E-DF12E99C78C1}

[2013/01/24 07:47:23 | 000,000,000 | ---D | C] -- C:\Users\Deb\AppData\Local\{6B52BFC3-84B8-4BC2-896D-8D8E04863DC9}

[2013/01/20 09:13:03 | 000,000,000 | ---D | C] -- C:\Users\Deb\AppData\Local\{E2E3FE0B-6FBE-4A1E-AF47-BD5041A3624B}

[2013/01/19 21:08:46 | 000,000,000 | ---D | C] -- C:\Users\Deb\AppData\Local\{B966D18E-7F69-47D5-8401-8BA6A11669E6}

[2013/01/19 19:33:46 | 000,000,000 | ---D | C] -- C:\Program Files\Microsoft Security Client

[2013/01/19 09:51:27 | 000,000,000 | ---D | C] -- C:\Users\Deb\AppData\Roaming\Anvisoft

[2013/01/19 09:51:15 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\anvisoft

[2013/01/19 09:51:13 | 000,000,000 | ---D | C] -- C:\ProgramData\Anvisoft

[2013/01/19 05:54:49 | 000,000,000 | ---D | C] -- C:\Users\Deb\AppData\Roaming\FixBee

[2013/01/19 05:54:49 | 000,000,000 | ---D | C] -- C:\ProgramData\FixBee

[2013/01/18 21:07:46 | 000,000,000 | ---D | C] -- C:\Users\Deb\AppData\Local\{2E3324BA-5C42-4324-A5C6-7336F189E63C}

[2013/01/18 14:39:02 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\FixBee Disk Optimizer

[2013/01/18 14:38:59 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\FixBee

[2013/01/18 14:38:56 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\SRToolbar

[2013/01/18 09:07:11 | 000,000,000 | ---D | C] -- C:\Users\Deb\AppData\Local\{8EC434FA-420B-47B7-9554-BD9441DB3FFE}

[2013/01/18 08:14:08 | 000,000,000 | ---D | C] -- C:\Windows\pss

[2013/01/17 19:55:16 | 000,000,000 | ---D | C] -- C:\Users\Deb\AppData\Roaming\WinRAR

[2013/01/17 19:55:15 | 000,000,000 | ---D | C] -- C:\Users\Deb\AppData\Local\DownTango

[2013/01/17 19:55:13 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\DownTango

[2013/01/17 19:54:50 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Red Sky

[2013/01/17 19:53:12 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Protected Search

[2013/01/17 09:06:14 | 000,000,000 | ---D | C] -- C:\Users\Deb\AppData\Local\{2CA50C82-3F07-4F48-9707-A62F0F77B23D}

[2013/01/16 17:48:37 | 000,000,000 | ---D | C] -- C:\Users\Deb\AppData\Local\{4A67868C-A839-44EC-B25E-87C83532E0DF}

[2013/01/16 07:05:52 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\EaseUS Data Recovery Wizard 5.6.5

[2013/01/16 05:48:02 | 000,000,000 | ---D | C] -- C:\Users\Deb\AppData\Local\{18C7CAE6-2D57-42B1-B823-8C0E23BBA00C}

[2013/01/15 09:13:53 | 000,000,000 | ---D | C] -- C:\Users\Deb\AppData\Local\{D8C64BCE-62CF-4985-90EC-1082D4CA5EF3}

[2013/01/14 15:29:14 | 000,000,000 | ---D | C] -- C:\Users\Deb\AppData\Local\{E3C4DD56-2019-4342-B117-6974C6D81EEC}

[2013/01/13 04:56:07 | 000,000,000 | ---D | C] -- C:\Users\Deb\AppData\Local\{1E9789FD-D1E5-4F0A-8197-3C96A6246FC6}

[2013/01/12 10:29:12 | 000,000,000 | ---D | C] -- C:\Users\Deb\Desktop\Good_morning!

[2013/01/12 08:22:48 | 000,000,000 | ---D | C] -- C:\Users\Deb\AppData\Local\{D5C04CAA-7B0D-46DC-A43D-5A8934F1A00A}

[2013/01/11 16:37:46 | 000,000,000 | ---D | C] -- C:\Users\Deb\AppData\Local\{86AE18EA-D2D7-4F78-A316-559CD87554C6}

[2013/01/11 04:37:23 | 000,000,000 | ---D | C] -- C:\Users\Deb\AppData\Local\{38263396-8971-473D-9686-D9E0B043A04E}

[2013/01/10 07:19:53 | 000,000,000 | ---D | C] -- C:\Users\Deb\AppData\Local\{66363DFD-6584-42C3-ABF6-26DF6393D0A3}

[2013/01/09 08:19:55 | 000,750,592 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\win32spl.dll

[2013/01/09 08:19:55 | 000,492,032 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\win32spl.dll

[2013/01/09 08:19:39 | 000,307,200 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\ncrypt.dll

[2013/01/09 08:19:36 | 000,800,768 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\usp10.dll

[2013/01/09 08:19:27 | 000,046,592 | ---- | C] (Microsoft) -- C:\Windows\SysWow64\fpb.rs

[2013/01/09 08:19:27 | 000,046,592 | ---- | C] (Microsoft) -- C:\Windows\SysNative\fpb.rs

[2013/01/09 08:19:27 | 000,045,568 | ---- | C] (Microsoft) -- C:\Windows\SysWow64\oflc-nz.rs

[2013/01/09 08:19:27 | 000,045,568 | ---- | C] (Microsoft) -- C:\Windows\SysNative\oflc-nz.rs

[2013/01/09 08:19:27 | 000,044,544 | ---- | C] (Microsoft) -- C:\Windows\SysWow64\pegibbfc.rs

[2013/01/09 08:19:27 | 000,043,520 | ---- | C] (Microsoft) -- C:\Windows\SysWow64\csrr.rs

[2013/01/09 08:19:27 | 000,043,520 | ---- | C] (Microsoft) -- C:\Windows\SysNative\csrr.rs

[2013/01/09 08:19:27 | 000,040,960 | ---- | C] (Microsoft) -- C:\Windows\SysWow64\cob-au.rs

[2013/01/09 08:19:27 | 000,040,960 | ---- | C] (Microsoft) -- C:\Windows\SysNative\cob-au.rs

[2013/01/09 08:19:26 | 002,746,368 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\gameux.dll

[2013/01/09 08:19:26 | 002,576,384 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\gameux.dll

[2013/01/09 08:19:26 | 000,441,856 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\Wpc.dll

[2013/01/09 08:19:26 | 000,044,544 | ---- | C] (Microsoft) -- C:\Windows\SysNative\pegibbfc.rs

[2013/01/09 08:19:26 | 000,030,720 | ---- | C] (Microsoft) -- C:\Windows\SysWow64\usk.rs

[2013/01/09 08:19:26 | 000,030,720 | ---- | C] (Microsoft) -- C:\Windows\SysNative\usk.rs

[2013/01/09 08:19:26 | 000,021,504 | ---- | C] (Microsoft) -- C:\Windows\SysWow64\grb.rs

[2013/01/09 08:19:26 | 000,021,504 | ---- | C] (Microsoft) -- C:\Windows\SysNative\grb.rs

[2013/01/09 08:19:26 | 000,020,480 | ---- | C] (Microsoft) -- C:\Windows\SysWow64\pegi-pt.rs

[2013/01/09 08:19:26 | 000,020,480 | ---- | C] (Microsoft) -- C:\Windows\SysNative\pegi-pt.rs

[2013/01/09 08:19:26 | 000,020,480 | ---- | C] (Microsoft) -- C:\Windows\SysWow64\pegi.rs

[2013/01/09 08:19:26 | 000,020,480 | ---- | C] (Microsoft) -- C:\Windows\SysNative\pegi.rs

[2013/01/09 08:19:26 | 000,015,360 | ---- | C] (Microsoft) -- C:\Windows\SysWow64\djctq.rs

[2013/01/09 08:19:26 | 000,015,360 | ---- | C] (Microsoft) -- C:\Windows\SysNative\djctq.rs

[2013/01/09 08:19:25 | 000,308,736 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\Wpc.dll

[2013/01/09 08:19:25 | 000,055,296 | ---- | C] (Microsoft) -- C:\Windows\SysWow64\cero.rs

[2013/01/09 08:19:25 | 000,055,296 | ---- | C] (Microsoft) -- C:\Windows\SysNative\cero.rs

[2013/01/09 08:19:25 | 000,051,712 | ---- | C] (Microsoft) -- C:\Windows\SysWow64\esrb.rs

[2013/01/09 08:19:25 | 000,051,712 | ---- | C] (Microsoft) -- C:\Windows\SysNative\esrb.rs

[2013/01/09 08:19:25 | 000,023,552 | ---- | C] (Microsoft) -- C:\Windows\SysWow64\oflc.rs

[2013/01/09 08:19:25 | 000,023,552 | ---- | C] (Microsoft) -- C:\Windows\SysNative\oflc.rs

[2013/01/09 08:19:25 | 000,020,480 | ---- | C] (Microsoft) -- C:\Windows\SysWow64\pegi-fi.rs

[2013/01/09 08:19:25 | 000,020,480 | ---- | C] (Microsoft) -- C:\Windows\SysNative\pegi-fi.rs

[2013/01/09 08:18:51 | 000,424,448 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\KernelBase.dll

[2013/01/09 08:18:49 | 001,161,216 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\kernel32.dll

[2013/01/09 08:18:49 | 000,362,496 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\wow64win.dll

[2013/01/09 08:18:48 | 000,338,432 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\conhost.exe

[2013/01/09 08:18:48 | 000,243,200 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\wow64.dll

[2013/01/09 08:18:48 | 000,215,040 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\winsrv.dll

[2013/01/09 08:18:48 | 000,016,384 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\ntvdm64.dll

[2013/01/09 08:18:48 | 000,014,336 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\ntvdm64.dll

[2013/01/09 08:18:48 | 000,013,312 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\wow64cpu.dll

[2013/01/09 08:18:48 | 000,006,144 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysNative\api-ms-win-security-base-l1-1-0.dll

[2013/01/09 08:18:48 | 000,005,120 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\api-ms-win-core-file-l1-1-0.dll

[2013/01/09 08:18:48 | 000,005,120 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysNative\api-ms-win-core-file-l1-1-0.dll

[2013/01/09 08:18:48 | 000,005,120 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\wow32.dll

[2013/01/09 08:18:48 | 000,004,608 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysNative\api-ms-win-core-threadpool-l1-1-0.dll

[2013/01/09 08:18:48 | 000,004,608 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\api-ms-win-core-processthreads-l1-1-0.dll

[2013/01/09 08:18:48 | 000,004,608 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysNative\api-ms-win-core-processthreads-l1-1-0.dll

[2013/01/09 08:18:48 | 000,004,096 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\api-ms-win-core-sysinfo-l1-1-0.dll

[2013/01/09 08:18:48 | 000,004,096 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysNative\api-ms-win-core-sysinfo-l1-1-0.dll

[2013/01/09 08:18:48 | 000,004,096 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\api-ms-win-core-synch-l1-1-0.dll

[2013/01/09 08:18:48 | 000,004,096 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysNative\api-ms-win-core-synch-l1-1-0.dll

[2013/01/09 08:18:48 | 000,004,096 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\api-ms-win-core-misc-l1-1-0.dll

[2013/01/09 08:18:48 | 000,004,096 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\api-ms-win-core-localregistry-l1-1-0.dll

[2013/01/09 08:18:48 | 000,004,096 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysNative\api-ms-win-core-localregistry-l1-1-0.dll

[2013/01/09 08:18:48 | 000,003,584 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysNative\api-ms-win-core-rtlsupport-l1-1-0.dll

[2013/01/09 08:18:48 | 000,003,584 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\api-ms-win-core-processenvironment-l1-1-0.dll

[2013/01/09 08:18:48 | 000,003,584 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysNative\api-ms-win-core-processenvironment-l1-1-0.dll

[2013/01/09 08:18:48 | 000,003,584 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\api-ms-win-core-namedpipe-l1-1-0.dll

[2013/01/09 08:18:48 | 000,003,584 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysNative\api-ms-win-core-namedpipe-l1-1-0.dll

[2013/01/09 08:18:48 | 000,003,584 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysNative\api-ms-win-core-misc-l1-1-0.dll

[2013/01/09 08:18:48 | 000,003,584 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\api-ms-win-core-memory-l1-1-0.dll

[2013/01/09 08:18:48 | 000,003,584 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysNative\api-ms-win-core-memory-l1-1-0.dll

[2013/01/09 08:18:48 | 000,003,584 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\api-ms-win-core-libraryloader-l1-1-0.dll

[2013/01/09 08:18:48 | 000,003,584 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysNative\api-ms-win-core-libraryloader-l1-1-0.dll

[2013/01/09 08:18:48 | 000,003,584 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\api-ms-win-core-interlocked-l1-1-0.dll

[2013/01/09 08:18:48 | 000,003,584 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\api-ms-win-core-heap-l1-1-0.dll

[2013/01/09 08:18:48 | 000,003,072 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysNative\api-ms-win-core-xstate-l1-1-0.dll

[2013/01/09 08:18:48 | 000,003,072 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysNative\api-ms-win-core-util-l1-1-0.dll

[2013/01/09 08:18:48 | 000,003,072 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\api-ms-win-core-string-l1-1-0.dll

[2013/01/09 08:18:48 | 000,003,072 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysNative\api-ms-win-core-string-l1-1-0.dll

[2013/01/09 08:18:48 | 000,003,072 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\api-ms-win-core-profile-l1-1-0.dll

[2013/01/09 08:18:48 | 000,003,072 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysNative\api-ms-win-core-profile-l1-1-0.dll

[2013/01/09 08:18:48 | 000,003,072 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\api-ms-win-core-io-l1-1-0.dll

[2013/01/09 08:18:48 | 000,003,072 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysNative\api-ms-win-core-io-l1-1-0.dll

[2013/01/09 08:18:48 | 000,003,072 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysNative\api-ms-win-core-interlocked-l1-1-0.dll

[2013/01/09 08:18:48 | 000,003,072 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\api-ms-win-core-errorhandling-l1-1-0.dll

[2013/01/09 08:18:48 | 000,003,072 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\api-ms-win-core-delayload-l1-1-0.dll

[2013/01/09 08:18:48 | 000,003,072 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysNative\api-ms-win-core-delayload-l1-1-0.dll

[2013/01/09 08:18:47 | 000,003,584 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysNative\api-ms-win-core-heap-l1-1-0.dll

[2013/01/09 08:18:47 | 000,003,072 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\api-ms-win-core-handle-l1-1-0.dll

[2013/01/09 08:18:47 | 000,003,072 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysNative\api-ms-win-core-handle-l1-1-0.dll

[2013/01/09 08:18:47 | 000,003,072 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\api-ms-win-core-fibers-l1-1-0.dll

[2013/01/09 08:18:47 | 000,003,072 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysNative\api-ms-win-core-fibers-l1-1-0.dll

[2013/01/09 08:18:47 | 000,003,072 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysNative\api-ms-win-core-errorhandling-l1-1-0.dll

[2013/01/09 08:18:47 | 000,003,072 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\api-ms-win-core-debug-l1-1-0.dll

[2013/01/09 08:18:47 | 000,003,072 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysNative\api-ms-win-core-debug-l1-1-0.dll

[2013/01/09 08:18:47 | 000,003,072 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysNative\api-ms-win-core-datetime-l1-1-0.dll

[2013/01/09 08:18:46 | 000,025,600 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\setup16.exe

[2013/01/09 08:18:46 | 000,007,680 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\instnm.exe

[2013/01/09 08:18:46 | 000,006,144 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\api-ms-win-security-base-l1-1-0.dll

[2013/01/09 08:18:46 | 000,004,608 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\api-ms-win-core-threadpool-l1-1-0.dll

[2013/01/09 08:18:46 | 000,004,096 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\api-ms-win-core-localization-l1-1-0.dll

[2013/01/09 08:18:46 | 000,003,584 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\api-ms-win-core-xstate-l1-1-0.dll

[2013/01/09 08:18:46 | 000,003,072 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\api-ms-win-core-util-l1-1-0.dll

[2013/01/09 08:18:46 | 000,003,072 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\api-ms-win-core-rtlsupport-l1-1-0.dll

[2013/01/09 08:18:46 | 000,003,072 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\api-ms-win-core-datetime-l1-1-0.dll

[2013/01/09 08:18:45 | 000,004,096 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysNative\api-ms-win-core-localization-l1-1-0.dll

[2013/01/09 08:18:45 | 000,003,072 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\api-ms-win-core-console-l1-1-0.dll

[2013/01/09 08:18:45 | 000,003,072 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysNative\api-ms-win-core-console-l1-1-0.dll

[2013/01/09 08:18:45 | 000,002,048 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\user.exe

[2013/01/09 08:18:29 | 000,068,608 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\taskhost.exe

[2013/01/09 08:03:43 | 000,000,000 | ---D | C] -- C:\Users\Deb\AppData\Local\{21D7C0B8-0255-4EBE-95C2-63E2609F7963}

[2013/01/08 07:54:44 | 000,000,000 | ---D | C] -- C:\Users\Deb\AppData\Local\{08D71E41-6BCB-4D7E-8115-90912FEFFEDF}

[2013/01/07 06:58:03 | 000,000,000 | ---D | C] -- C:\Users\Deb\AppData\Local\{AC76A610-688C-47B5-9263-19DF34042B56}

[2013/01/06 06:04:06 | 000,000,000 | ---D | C] -- C:\Users\Deb\AppData\Local\{C3841884-8F5F-4B2D-BB68-75D301AD91B2}

[2013/01/05 07:11:51 | 000,000,000 | ---D | C] -- C:\Users\Deb\Documents\Medical Files

[2013/01/05 06:03:16 | 000,000,000 | ---D | C] -- C:\Users\Deb\AppData\Local\{3424CDF3-9FE0-42D6-B607-687B3EE116CC}

[2008/08/11 22:45:20 | 000,155,648 | ---- | C] (ASUS) -- C:\Program Files (x86)\Common Files\MSIactionall.dll

[1 C:\Windows\SysWow64\*.tmp files -> C:\Windows\SysWow64\*.tmp -> ]

[1 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ]

 

========== Files - Modified Within 30 Days ==========

 

[2013/02/01 17:44:56 | 000,602,112 | ---- | M] (OldTimer Tools) -- C:\Users\Deb\Desktop\OTL.scr

[2013/02/01 17:35:00 | 000,000,830 | ---- | M] () -- C:\Windows\tasks\Adobe Flash Player Updater.job

[2013/02/01 17:35:00 | 000,000,314 | ---- | M] () -- C:\Windows\tasks\PrintProjects Communicator.job

[2013/02/01 17:10:05 | 000,000,892 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineUA.job

[2013/02/01 10:10:01 | 000,000,888 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineCore.job

[2013/02/01 08:34:00 | 000,000,490 | ---- | M] () -- C:\Windows\tasks\03-31-2011_103440.job

[2013/02/01 07:38:01 | 000,001,115 | ---- | M] () -- C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk

[2013/02/01 07:36:25 | 010,156,344 | ---- | M] (Malwarebytes Corporation ) -- C:\Users\Deb\Desktop\mbam-setup-1.70.0.1100.exe

[2013/02/01 06:37:30 | 000,010,240 | -H-- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0

[2013/02/01 06:37:30 | 000,010,240 | -H-- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0

[2013/02/01 06:33:31 | 000,792,550 | ---- | M] () -- C:\Windows\SysNative\PerfStringBackup.INI

[2013/02/01 06:33:31 | 000,669,298 | ---- | M] () -- C:\Windows\SysNative\perfh009.dat

[2013/02/01 06:33:31 | 000,125,452 | ---- | M] () -- C:\Windows\SysNative\perfc009.dat

[2013/02/01 06:31:37 | 000,000,344 | ---- | M] () -- C:\Windows\lgfwup.ini

[2013/02/01 06:28:56 | 000,067,584 | --S- | M] () -- C:\Windows\bootstat.dat

[2013/02/01 06:28:48 | 3193,765,888 | -HS- | M] () -- C:\hiberfil.sys

[2013/01/20 06:30:57 | 000,010,841 | ---- | M] () -- C:\Users\Deb\Documents\paisley.pat

[2013/01/18 14:39:04 | 000,000,997 | ---- | M] () -- C:\Users\Deb\Application Data\Microsoft\Internet Explorer\Quick Launch\FixBee Disk Optimizer.lnk

[2013/01/18 14:39:03 | 000,002,057 | ---- | M] () -- C:\Users\Public\Desktop\FixBee Disk Optimizer.lnk

[2013/01/18 09:41:22 | 000,001,056 | ---- | M] () -- C:\prefs.js

[2013/01/17 19:55:01 | 000,000,000 | ---- | M] () -- C:\end

[2013/01/17 19:54:59 | 000,000,000 | ---- | M] () -- C:\extensions.sqlite

[2013/01/17 19:53:11 | 000,002,236 | ---- | M] () -- C:\Users\Deb\Application Data\Microsoft\Internet Explorer\Quick Launch\Snagit 10.lnk

[2013/01/17 19:53:11 | 000,001,897 | ---- | M] () -- C:\Users\Deb\Application Data\Microsoft\Internet Explorer\Quick Launch\TOSHIBA DVD PLAYER.lnk

[2013/01/17 19:53:11 | 000,001,448 | ---- | M] () -- C:\Users\Deb\Application Data\Microsoft\Internet Explorer\Quick Launch\Wondershare DVD Slideshow Builder Standard.lnk

[2013/01/17 19:53:11 | 000,001,385 | ---- | M] () -- C:\Users\Deb\Application Data\Microsoft\Internet Explorer\Quick Launch\Wondershare Photo Collage Studio.lnk

[2013/01/17 19:53:11 | 000,001,319 | ---- | M] () -- C:\Users\Deb\Application Data\Microsoft\Internet Explorer\Quick Launch\Picture Collage Maker.lnk

[2013/01/17 19:53:11 | 000,001,303 | ---- | M] () -- C:\Users\Deb\Application Data\Microsoft\Internet Explorer\Quick Launch\Yahoo! Messenger.lnk

[2013/01/17 19:53:11 | 000,001,279 | ---- | M] () -- C:\Users\Deb\Application Data\Microsoft\Internet Explorer\Quick Launch\Pixpedia Publisher.lnk

[2013/01/17 19:53:11 | 000,001,213 | ---- | M] () -- C:\Users\Deb\Application Data\Microsoft\Internet Explorer\Quick Launch\WinX DVD Copy Pro.lnk

[2013/01/17 19:53:11 | 000,001,085 | ---- | M] () -- C:\Users\Deb\Application Data\Microsoft\Internet Explorer\Quick Launch\XnView.lnk

[2013/01/17 19:53:11 | 000,000,955 | ---- | M] () -- C:\Users\Deb\Application Data\Microsoft\Internet Explorer\Quick Launch\Spyware Terminator.lnk

[2013/01/17 19:53:11 | 000,000,859 | ---- | M] () -- C:\Users\Deb\Application Data\Microsoft\Internet Explorer\Quick Launch\Xara3D6.lnk

[2013/01/17 19:53:11 | 000,000,859 | ---- | M] () -- C:\Users\Deb\Application Data\Microsoft\Internet Explorer\Quick Launch\RegistryBooster.lnk

[2013/01/17 19:53:11 | 000,000,426 | ---- | M] () -- C:\Users\Deb\Application Data\Microsoft\Internet Explorer\Quick Launch\Shows Desktop.lnk

[2013/01/17 19:53:11 | 000,000,408 | ---- | M] () -- C:\Users\Deb\Application Data\Microsoft\Internet Explorer\Quick Launch\Window Switcher.lnk

[2013/01/17 19:53:10 | 000,002,825 | ---- | M] () -- C:\Users\Deb\Application Data\Microsoft\Internet Explorer\Quick Launch\Jasc Paint Shop Pro 9.lnk

[2013/01/17 19:53:10 | 000,002,813 | ---- | M] () -- C:\Users\Deb\Application Data\Microsoft\Internet Explorer\Quick Launch\Jasc Paint Shop Pro 9 (1).lnk

[2013/01/17 19:53:10 | 000,002,381 | ---- | M] () -- C:\Users\Deb\Application Data\Microsoft\Internet Explorer\Quick Launch\Google Chrome.lnk

[2013/01/17 19:53:10 | 000,002,300 | ---- | M] () -- C:\Users\Deb\Application Data\Microsoft\Internet Explorer\Quick Launch\mediAvatar Photo to Flash.lnk

[2013/01/17 19:53:10 | 000,002,143 | ---- | M] () -- C:\Users\Deb\Application Data\Microsoft\Internet Explorer\Quick Launch\IncrediMail 2.0.lnk

[2013/01/17 19:53:10 | 000,002,116 | ---- | M] () -- C:\Users\Deb\Application Data\Microsoft\Internet Explorer\Quick Launch\Nero Express.lnk

[2013/01/17 19:53:10 | 000,001,579 | ---- | M] () -- C:\Users\Deb\Application Data\Microsoft\Internet Explorer\Quick Launch\Launch Internet Explorer Browser.lnk

[2013/01/17 19:53:10 | 000,001,315 | ---- | M] () -- C:\Users\Deb\Application Data\Microsoft\Internet Explorer\Quick Launch\Free GMT AVI to DVD.lnk

[2013/01/17 19:53:10 | 000,001,238 | ---- | M] () -- C:\Users\Deb\Application Data\Microsoft\Internet Explorer\Quick Launch\Game Booster.lnk

[2013/01/17 19:53:10 | 000,001,145 | ---- | M] () -- C:\Users\Deb\Application Data\Microsoft\Internet Explorer\Quick Launch\MiPony.lnk

[2013/01/17 19:53:10 | 000,001,109 | ---- | M] () -- C:\Users\Deb\Application Data\Microsoft\Internet Explorer\Quick Launch\NeoPaint.lnk

[2013/01/17 19:53:10 | 000,001,006 | ---- | M] () -- C:\Users\Deb\Application Data\Microsoft\Internet Explorer\Quick Launch\GOM Player.lnk

[2013/01/17 19:53:10 | 000,000,859 | ---- | M] () -- C:\Users\Deb\Application Data\Microsoft\Internet Explorer\Quick Launch\Opera.lnk

[2013/01/17 19:53:10 | 000,000,859 | ---- | M] () -- C:\Users\Deb\Application Data\Microsoft\Internet Explorer\Quick Launch\Log Analysis - Sax2.lnk

[2013/01/17 19:53:10 | 000,000,859 | ---- | M] () -- C:\Users\Deb\Application Data\Microsoft\Internet Explorer\Quick Launch\Intrusion Detection System - Sax2.lnk

[2013/01/17 19:53:09 | 000,002,231 | ---- | M] () -- C:\Users\Deb\Application Data\Microsoft\Internet Explorer\Quick Launch\Corel Paint Shop Pro X.lnk

[2013/01/17 19:53:09 | 000,001,498 | ---- | M] () -- C:\Users\Deb\Application Data\Microsoft\Internet Explorer\Quick Launch\Batch Photo Watermarker.lnk

[2013/01/17 19:53:09 | 000,001,362 | ---- | M] () -- C:\Users\Deb\Application Data\Microsoft\Internet Explorer\Quick Launch\ConvertXtoDVD 4.lnk

[2013/01/17 19:53:09 | 000,001,265 | ---- | M] () -- C:\Users\Deb\Application Data\Microsoft\Internet Explorer\Quick Launch\FoxTab AVI Converter.lnk

[2013/01/17 19:53:09 | 000,001,259 | ---- | M] () -- C:\Users\Deb\Application Data\Microsoft\Internet Explorer\Quick Launch\Free Easy Burner.lnk

[2013/01/17 19:53:09 | 000,001,221 | ---- | M] () -- C:\Users\Deb\Application Data\Microsoft\Internet Explorer\Quick Launch\Final*******.lnk

[2013/01/17 19:53:09 | 000,001,214 | ---- | M] () -- C:\Users\Deb\Application Data\Microsoft\Internet Explorer\Quick Launch\easyQuizzy.lnk

[2013/01/17 19:53:09 | 000,001,149 | ---- | M] () -- C:\Users\Deb\Application Data\Microsoft\Internet Explorer\Quick Launch\DVD Shrink 3.2.lnk

[2013/01/17 19:53:09 | 000,001,149 | ---- | M] () -- C:\Users\Deb\Application Data\Microsoft\Internet Explorer\Quick Launch\BatchInpaint.lnk

[2013/01/17 19:53:09 | 000,001,119 | ---- | M] () -- C:\Users\Deb\Application Data\Microsoft\Internet Explorer\Quick Launch\CollageIt.lnk

[2013/01/17 19:53:08 | 000,002,584 | ---- | M] () -- C:\Users\Deb\Application Data\Microsoft\Internet Explorer\Quick Launch\Aiseesoft Total Media Converter.lnk

[2013/01/17 19:53:08 | 000,002,344 | ---- | M] () -- C:\Users\Deb\Application Data\Microsoft\Internet Explorer\Quick Launch\Adobe Digital Editions.lnk

[2013/01/17 19:53:08 | 000,002,325 | ---- | M] () -- C:\Users\Deb\Application Data\Microsoft\Internet Explorer\Quick Launch\4Media Photo Slideshow Maker.lnk

[2013/01/17 19:53:08 | 000,002,269 | ---- | M] () -- C:\Users\Deb\Application Data\Microsoft\Internet Explorer\Quick Launch\4Media Ringtone Maker.lnk

[2013/01/17 19:53:08 | 000,001,254 | ---- | M] () -- C:\Users\Deb\Application Data\Microsoft\Internet Explorer\Quick Launch\AnyPic Image Resizer Pro.lnk

[2013/01/17 19:53:08 | 000,000,859 | ---- | M] () -- C:\Users\Deb\Application Data\Microsoft\Internet Explorer\Quick Launch\Ashampoo Burning Studio 2010 Advanced.lnk

[2013/01/17 19:24:50 | 000,045,169 | ---- | M] () -- C:\Users\Deb\Desktop\PolkaDot_Baby_Blanket.pdf

[2013/01/11 04:33:21 | 005,620,584 | ---- | M] () -- C:\Windows\SysNative\FNTCACHE.DAT

[2013/01/10 07:42:38 | 000,786,766 | ---- | M] () -- C:\Windows\SysWow64\PerfStringBackup.INI

[2013/01/09 10:35:18 | 000,697,864 | ---- | M] (Adobe Systems Incorporated) -- C:\Windows\SysWow64\FlashPlayerApp.exe

[2013/01/09 10:35:18 | 000,074,248 | ---- | M] (Adobe Systems Incorporated) -- C:\Windows\SysWow64\FlashPlayerCPLApp.cpl

[2013/01/03 07:18:52 | 000,015,360 | ---- | M] () -- C:\Windows\Launcher.exe

[1 C:\Windows\SysWow64\*.tmp files -> C:\Windows\SysWow64\*.tmp -> ]

[1 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ]

 

========== Files Created - No Company Name ==========

 

[2013/02/01 07:38:01 | 000,001,115 | ---- | C] () -- C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk

[2013/01/20 06:30:57 | 000,010,841 | ---- | C] () -- C:\Users\Deb\Documents\paisley.pat

[2013/01/18 14:39:04 | 000,000,997 | ---- | C] () -- C:\Users\Deb\Application Data\Microsoft\Internet Explorer\Quick Launch\FixBee Disk Optimizer.lnk

[2013/01/18 14:39:03 | 000,002,057 | ---- | C] () -- C:\Users\Public\Desktop\FixBee Disk Optimizer.lnk

[2013/01/17 19:54:59 | 000,000,000 | ---- | C] () -- C:\extensions.sqlite

[2013/01/17 19:54:50 | 000,000,000 | ---- | C] () -- C:\end

[2013/01/17 19:53:13 | 000,015,360 | ---- | C] () -- C:\Windows\Launcher.exe

[2013/01/17 19:24:49 | 000,045,169 | ---- | C] () -- C:\Users\Deb\Desktop\PolkaDot_Baby_Blanket.pdf

[2012/08/20 09:46:35 | 000,384,844 | ---- | C] () -- C:\Users\Deb\AppData\Local\funmoods-speeddial.crx

[2012/08/12 08:45:52 | 000,004,470 | ---- | C] () -- C:\Users\Deb\pspbrwse.jbf

[2012/04/06 14:07:58 | 000,000,344 | ---- | C] () -- C:\Windows\lgfwup.ini

[2011/11/27 07:09:54 | 000,161,694 | ---- | C] () -- C:\Windows\Animated Wallpaper Maker Uninstaller.exe

[2011/11/13 13:30:25 | 000,000,288 | ---- | C] () -- C:\Windows\ODBC.INI

[2011/11/13 13:30:24 | 000,001,644 | ---- | C] () -- C:\Windows\ODBCINST.INI

[2011/10/05 08:31:08 | 000,000,038 | ---- | C] () -- C:\Windows\avisplitter.ini

[2011/10/05 08:31:07 | 000,650,752 | ---- | C] () -- C:\Windows\SysWow64\xvidcore.dll

[2011/10/05 08:31:07 | 000,243,200 | ---- | C] () -- C:\Windows\SysWow64\xvidvfw.dll

[2011/09/28 04:49:43 | 000,087,040 | ---- | C] () -- C:\Windows\UnGins.exe

[2011/08/15 12:34:07 | 000,044,544 | ---- | C] () -- C:\Windows\SysWow64\gif89.dll

[2011/08/15 12:33:54 | 000,000,285 | ---- | C] () -- C:\Windows\SIERRA.INI

[2011/08/15 04:20:07 | 000,007,597 | ---- | C] () -- C:\Users\Deb\AppData\Local\Resmon.ResmonCfg

[2011/08/06 03:20:57 | 000,161,807 | ---- | C] () -- C:\Windows\Animated Screensaver Maker Uninstaller.exe

[2011/07/11 13:27:17 | 000,026,000 | ---- | C] () -- C:\Windows\SysWow64\PteVideo.dll

[2011/07/01 06:16:12 | 000,000,069 | ---- | C] () -- C:\Windows\NeroDigital.ini

[2011/05/21 03:16:40 | 000,162,598 | ---- | C] () -- C:\Windows\DP Animation Maker Uninstaller.exe

[2011/04/23 06:19:51 | 000,027,648 | R--- | C] () -- C:\Windows\Setup_ck.exe

[2011/04/23 06:19:51 | 000,024,608 | ---- | C] () -- C:\Windows\SysWow64\Ckldrv.sys

[2011/04/23 06:19:51 | 000,018,432 | ---- | C] () -- C:\Windows\Setup_ck.dll

[2011/04/23 06:19:51 | 000,011,776 | ---- | C] () -- C:\Windows\Ckrfresh.exe

[2011/04/20 09:44:49 | 000,000,368 | ---- | C] () -- C:\Users\Deb\AppData\Roaming\wklnhst.dat

[2011/03/23 16:54:15 | 000,786,766 | ---- | C] () -- C:\Windows\SysWow64\PerfStringBackup.INI

[2011/03/18 16:13:04 | 000,000,042 | ---- | C] () -- C:\Windows\PCSPATS.DAT

[2011/02/19 19:42:30 | 000,000,091 | ---- | C] () -- C:\Windows\Crypkey.ini

[2010/12/21 10:06:03 | 000,000,069 | ---- | C] () -- C:\Users\Deb\AppData\Roaming\IncrediMail Collection ManagerIcm.ini

[2010/12/19 11:55:26 | 000,001,057 | ---- | C] () -- C:\Users\Deb\AppData\Roaming\vso_ts_preview.xml

[2010/12/15 12:16:53 | 000,035,840 | ---- | C] () -- C:\Users\Deb\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini

[2010/12/15 11:14:41 | 000,000,080 | -HS- | C] () -- C:\ProgramData\.zreglib

[2010/12/11 13:35:07 | 019,985,265 | ---- | C] () -- C:\ProgramData\vlc-1.1.5-win32.exe

[2009/04/08 11:31:56 | 000,106,496 | ---- | C] () -- C:\Program Files (x86)\Common Files\CPInstallAction.dll

[2009/03/27 10:14:04 | 000,033,940 | ---- | C] () -- C:\Users\Deb\qotw.jpg

[2009/03/22 13:46:48 | 000,016,769 | ---- | C] () -- C:\Users\Deb\flowers.PLC

[2009/03/03 11:32:32 | 000,705,558 | ---- | C] () -- C:\Users\Deb\QBD_-_LaceBorderNFramesScripts.zip

[2009/02/16 19:30:54 | 000,658,608 | ---- | C] () -- C:\Program Files (x86)\MagicDVDRipper.exe

[2009/02/09 11:56:30 | 000,313,344 | ---- | C] () -- C:\Program Files (x86)\hjsplit.exe

[2009/01/18 08:46:29 | 000,001,024 | ---- | C] () -- C:\Users\Deb\.rnd

[2008/05/22 09:35:54 | 000,051,962 | ---- | C] () -- C:\Program Files (x86)\Common Files\banner.jpg

[2006/11/02 06:50:50 | 000,000,174 | -HS- | C] () -- C:\Program Files (x86)\desktop (1).ini

 

========== ZeroAccess Check ==========

 

[2011/07/03 14:29:46 | 000,000,000 | ---D | M] -- C:\$Recycle.bin\S-1-5-21-4070860634-2794675311-1628887733-1000\$ROXZ5D7\L

[2009/07/13 22:55:00 | 000,000,227 | RHS- | M] () -- C:\Windows\assembly\Desktop.ini

 

[HKEY_CURRENT_USER\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] /64

 

[HKEY_CURRENT_USER\Software\Classes\Wow6432node\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]

 

[HKEY_CURRENT_USER\Software\Classes\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32] /64

 

[HKEY_CURRENT_USER\Software\Classes\Wow6432node\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32]

 

[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] /64

"" = C:\Windows\SysNative\shell32.dll -- [2012/06/08 23:43:10 | 014,172,672 | ---- | M] (Microsoft Corporation)

"ThreadingModel" = Apartment

 

[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]

"" = %SystemRoot%\system32\shell32.dll -- [2012/06/08 22:41:00 | 012,873,728 | ---- | M] (Microsoft Corporation)

"ThreadingModel" = Apartment

 

[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32] /64

"" = C:\Windows\SysNative\wbem\fastprox.dll -- [2009/07/13 19:40:51 | 000,909,312 | ---- | M] (Microsoft Corporation)

"ThreadingModel" = Free

 

[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32]

"" = %systemroot%\system32\wbem\fastprox.dll -- [2010/11/20 06:19:02 | 000,606,208 | ---- | M] (Microsoft Corporation)

"ThreadingModel" = Free

 

[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32] /64

"" = C:\Windows\SysNative\wbem\wbemess.dll -- [2009/07/13 19:41:56 | 000,505,856 | ---- | M] (Microsoft Corporation)

"ThreadingModel" = Both

 

[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32]

 

========== LOP Check ==========

 

[2011/04/27 17:18:59 | 000,000,000 | -HSD | M] -- C:\Users\Deb\AppData\Roaming\.#

[2012/03/30 12:58:05 | 000,000,000 | ---D | M] -- C:\Users\Deb\AppData\Roaming\4Media

[2013/01/19 19:38:06 | 000,000,000 | ---D | M] -- C:\Users\Deb\AppData\Roaming\Anvisoft

[2011/07/03 04:19:51 | 000,000,000 | ---D | M] -- C:\Users\Deb\AppData\Roaming\AnyPic Image Converter

[2011/05/08 10:59:39 | 000,000,000 | ---D | M] -- C:\Users\Deb\AppData\Roaming\AnyPic Image Resizer Pro

[2012/01/09 07:02:50 | 000,000,000 | ---D | M] -- C:\Users\Deb\AppData\Roaming\Ashampoo

[2011/11/14 13:03:49 | 000,000,000 | ---D | M] -- C:\Users\Deb\AppData\Roaming\BlitzCards

[2011/06/21 08:31:19 | 000,000,000 | ---D | M] -- C:\Users\Deb\AppData\Roaming\Byngo

[2011/06/27 14:30:19 | 000,000,000 | ---D | M] -- C:\Users\Deb\AppData\Roaming\calibre

[2011/11/19 09:21:55 | 000,000,000 | ---D | M] -- C:\Users\Deb\AppData\Roaming\chc.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1

[2011/10/28 05:57:48 | 000,000,000 | ---D | M] -- C:\Users\Deb\AppData\Roaming\Digiarty

[2010/12/17 12:55:31 | 000,000,000 | ---D | M] -- C:\Users\Deb\AppData\Roaming\DVDVideoSoft

[2011/03/28 05:24:17 | 000,000,000 | ---D | M] -- C:\Users\Deb\AppData\Roaming\Engelmann Media

[2011/02/02 14:12:43 | 000,000,000 | ---D | M] -- C:\Users\Deb\AppData\Roaming\Final*******

[2013/01/19 19:48:35 | 000,000,000 | ---D | M] -- C:\Users\Deb\AppData\Roaming\FixBee

[2012/03/30 12:58:05 | 000,000,000 | ---D | M] -- C:\Users\Deb\AppData\Roaming\FreeBurner

[2011/02/01 19:03:46 | 000,000,000 | ---D | M] -- C:\Users\Deb\AppData\Roaming\gmt_free_avi_to_dvd

[2010/12/10 13:18:51 | 000,000,000 | ---D | M] -- C:\Users\Deb\AppData\Roaming\HiYo

[2010/12/11 20:29:08 | 000,000,000 | ---D | M] -- C:\Users\Deb\AppData\Roaming\ImageBadger

[2010/12/21 10:06:03 | 000,000,000 | ---D | M] -- C:\Users\Deb\AppData\Roaming\IncrediMail Collection Manager

[2011/04/23 05:54:59 | 000,000,000 | ---D | M] -- C:\Users\Deb\AppData\Roaming\IObit

[2010/12/15 10:02:00 | 000,000,000 | ---D | M] -- C:\Users\Deb\AppData\Roaming\Jasc

[2011/04/10 04:32:43 | 000,000,000 | ---D | M] -- C:\Users\Deb\AppData\Roaming\Leawo

[2011/12/25 05:54:56 | 000,000,000 | ---D | M] -- C:\Users\Deb\AppData\Roaming\LifeSniffer

[2011/04/03 05:29:09 | 000,000,000 | ---D | M] -- C:\Users\Deb\AppData\Roaming\mediAvatar

[2011/12/14 16:38:12 | 000,000,000 | ---D | M] -- C:\Users\Deb\AppData\Roaming\Mipony

[2011/02/18 17:55:10 | 000,000,000 | ---D | M] -- C:\Users\Deb\AppData\Roaming\Mobipocket

[2011/04/10 04:32:43 | 000,000,000 | ---D | M] -- C:\Users\Deb\AppData\Roaming\Moyea

[2011/12/03 06:19:44 | 000,000,000 | ---D | M] -- C:\Users\Deb\AppData\Roaming\Nik Software

[2012/10/12 05:02:38 | 000,000,000 | ---D | M] -- C:\Users\Deb\AppData\Roaming\Nuclear Coffee

[2012/04/08 06:07:10 | 000,000,000 | ---D | M] -- C:\Users\Deb\AppData\Roaming\PearlMountain

[2011/04/27 18:09:56 | 000,000,000 | ---D | M] -- C:\Users\Deb\AppData\Roaming\PearlMountainSoft

[2011/01/18 15:25:42 | 000,000,000 | ---D | M] -- C:\Users\Deb\AppData\Roaming\Pixpedia Publisher

[2012/10/12 14:11:08 | 000,000,000 | ---D | M] -- C:\Users\Deb\AppData\Roaming\PlayFirst

[2011/04/10 04:32:43 | 000,000,000 | ---D | M] -- C:\Users\Deb\AppData\Roaming\PPT2DVD

[2011/10/05 08:54:49 | 000,000,000 | ---D | M] -- C:\Users\Deb\AppData\Roaming\QuizResultsAnalyzer.E7BED6E5DDA59983786DD72EBFA46B1598278E07.1

[2012/08/20 09:46:30 | 000,000,000 | ---D | M] -- C:\Users\Deb\AppData\Roaming\SendSpace

[2011/06/14 07:04:49 | 000,000,000 | ---D | M] -- C:\Users\Deb\AppData\Roaming\Softplicity

[2011/11/12 22:18:28 | 000,000,000 | ---D | M] -- C:\Users\Deb\AppData\Roaming\Solveig Multimedia

[2012/05/30 10:37:07 | 000,000,000 | ---D | M] -- C:\Users\Deb\AppData\Roaming\Temp

[2010/12/28 12:10:38 | 000,000,000 | ---D | M] -- C:\Users\Deb\AppData\Roaming\Template

[2011/10/15 13:45:53 | 000,000,000 | ---D | M] -- C:\Users\Deb\AppData\Roaming\Thinstall

[2011/08/01 17:33:44 | 000,000,000 | ---D | M] -- C:\Users\Deb\AppData\Roaming\Tibo Software

[2011/04/06 14:52:04 | 000,000,000 | ---D | M] -- C:\Users\Deb\AppData\Roaming\Titanium Gears

[2012/06/06 06:39:18 | 000,000,000 | ---D | M] -- C:\Users\Deb\AppData\Roaming\Visan

[2011/04/20 06:00:25 | 000,000,000 | ---D | M] -- C:\Users\Deb\AppData\Roaming\visualsearchpony.com

[2010/12/19 11:56:10 | 000,000,000 | ---D | M] -- C:\Users\Deb\AppData\Roaming\Vso

[2010/12/10 13:55:37 | 000,000,000 | ---D | M] -- C:\Users\Deb\AppData\Roaming\WeatherBug

[2010/12/10 13:26:42 | 000,000,000 | ---D | M] -- C:\Users\Deb\AppData\Roaming\Windows Live Writer

[2012/01/30 08:02:39 | 000,000,000 | ---D | M] -- C:\Users\Deb\AppData\Roaming\XnView

 

========== Purity Check ==========

 

 

 

========== Custom Scans ==========

 

========== Drive Information ==========

 

Physical Drives

---------------

 

Drive: \\\\.\\PHYSICALDRIVE0 - Fixed hard disk media

Interface type: IDE

Media Type: Fixed hard disk media

Model: ST9500325AS

Partitions: 3

Status: OK

Status Info: 0

 

Partitions

---------------

 

DeviceID: Disk #0, Partition #0

PartitionType: Unknown

Bootable: False

BootPartition: False

PrimaryPartition: True

Size: 12.00GB

Starting Offset: 1048576

Hidden sectors: 0

 

 

DeviceID: Disk #0, Partition #1

PartitionType: Installable File System

Bootable: True

BootPartition: True

PrimaryPartition: True

Size: 116.00GB

Starting Offset: 12583960576

Hidden sectors: 0

 

 

DeviceID: Disk #0, Partition #2

PartitionType: Extended w/Extended Int 13

Bootable: False

BootPartition: False

PrimaryPartition: False

Size: 338.00GB

Starting Offset: 137610919936

Hidden sectors: 0

 

 

< %SYSTEMDRIVE%\*.* >

[2005/07/06 13:12:58 | 000,060,370 | ---- | M] () -- C:\Air Freshener Covers Series BK1 1.gif

[2005/07/06 13:13:14 | 000,057,415 | ---- | M] () -- C:\Air Freshener Covers Series BK1 2.gif

[2005/07/06 13:13:30 | 000,064,908 | ---- | M] () -- C:\Air Freshener Covers Series BK1 3.gif

[2005/07/06 13:13:46 | 000,059,575 | ---- | M] () -- C:\Air Freshener Covers Series BK1 4.gif

[2005/07/06 13:14:06 | 000,061,367 | ---- | M] () -- C:\Air Freshener Covers Series BK1 5.gif

[2005/07/06 13:14:24 | 000,045,478 | ---- | M] () -- C:\Air Freshener Covers Series BK1 6.gif

[2005/07/06 13:14:40 | 000,028,722 | ---- | M] () -- C:\Air Freshener Covers Series BK1 bc.jpg

[2005/07/06 13:12:40 | 000,024,648 | ---- | M] () -- C:\Air Freshener Covers Series BK1.jpg

[2010/11/20 06:40:07 | 000,383,786 | RHS- | M] () -- C:\bootmgr

[2009/07/29 00:03:37 | 000,008,192 | RHS- | M] () -- C:\BOOTSECT.BAK

[2010/03/16 07:13:46 | 000,013,114 | ---- | M] () -- C:\devlist.txt

[2013/01/17 19:55:01 | 000,000,000 | ---- | M] () -- C:\end

[2013/01/17 19:54:59 | 000,000,000 | ---- | M] () -- C:\extensions.sqlite

[2010/03/16 07:13:46 | 000,000,009 | ---- | M] () -- C:\Finish.log

[2013/02/01 06:28:48 | 3193,765,888 | -HS- | M] () -- C:\hiberfil.sys

[2010/03/16 07:37:58 | 000,963,411 | ---- | M] () -- C:\inject.log.txt

[2009/06/25 19:14:43 | 001,048,576 | RH-- | M] () -- C:\K60IJ.BIN

[2009/08/09 21:04:57 | 000,000,019 | ---- | M] () -- C:\K60IJ_WIN7.10

[2011/04/09 00:54:52 | 002,729,984 | ---- | M] () -- C:\KahlownSetup.msi

[2013/02/01 06:28:53 | 4258,357,248 | -HS- | M] () -- C:\pagefile.sys

[2010/03/15 18:03:22 | 000,000,105 | ---- | M] () -- C:\Pass.txt

[2009/12/16 23:48:04 | 000,000,277 | ---- | M] () -- C:\Patch_Win7.log

[2011/01/17 10:49:26 | 018,420,224 | ---- | M] () -- C:\Pixo.msi

[2013/01/18 09:41:22 | 000,001,056 | ---- | M] () -- C:\prefs.js

[2009/08/09 21:04:57 | 000,000,007 | ---- | M] () -- C:\RECOVERY.DAT

[2011/07/20 06:34:19 | 000,004,096 | RHS- | M] () -- C:\RESCUMBR.BIN

[2013/01/17 19:53:12 | 000,000,351 | ---- | M] () -- C:\SetSearchAndHomepageInBrowserLog.txt

[2012/08/05 10:39:00 | 000,000,540 | ---- | M] () -- C:\settings.ini

[2010/03/16 07:00:55 | 000,000,090 | ---- | M] () -- C:\setup.log

[2010/03/16 07:10:05 | 000,000,170 | ---- | M] () -- C:\SumHidd.txt

[2010/03/16 07:09:51 | 000,000,098 | ---- | M] () -- C:\SumOS.txt

[2009/09/16 12:04:46 | 000,000,024 | ---- | M] () -- C:\v82.txt

 

< %systemroot%\system32\Spool\prtprocs\w32x86\*.dll >

 

< %systemroot%\*. /mp /s >

 

< %systemroot%\system32\*.dll /lockedfiles >

[2012/10/27 00:23:14 | 011,020,800 | ---- | M] (Microsoft Corporation) Unable to obtain MD5 -- C:\Windows\system32\ieframe.dll

[1 C:\Windows\system32\*.tmp files -> C:\Windows\system32\*.tmp -> ]

 

< %systemroot%\Tasks\*.job /lockedfiles >

 

< %systemroot%\system32\drivers\*.sys /lockedfiles >

 

< %systemroot%\system32\*.exe /lockedfiles >

[1 C:\Windows\system32\*.tmp files -> C:\Windows\system32\*.tmp -> ]

 

< %systemroot%\System32\config\*.sav >

 

< %PROGRAMFILES%\* >

[2008/01/20 20:43:21 | 000,000,174 | -HS- | M] () -- C:\Program Files (x86)\desktop (1).ini

[2009/07/13 22:54:24 | 000,000,174 | -HS- | M] () -- C:\Program Files (x86)\desktop.ini

[2007/02/01 18:02:54 | 000,313,344 | ---- | M] () -- C:\Program Files (x86)\hjsplit.exe

[2006/04/02 01:23:06 | 000,658,608 | ---- | M] () -- C:\Program Files (x86)\MagicDVDRipper.exe

 

< %USERPROFILE%\..|smtmp;true;true;true /FP >

 

< HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Win dows\WindowsUpdate\AU >

 

< hklm\software\clients\startmenuinternet|command /rs >

HKEY_LOCAL_MACHINE\software\clients\startmenuinternet\Google Chrome\InstallInfo\\ShowIconsCommand: "C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --show-icons [2013/01/25 20:35:08 | 001,248,208 | ---- | M] (Google Inc.)

HKEY_LOCAL_MACHINE\software\clients\startmenuinternet\Google Chrome\InstallInfo\\HideIconsCommand: "C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --hide-icons [2013/01/25 20:35:08 | 001,248,208 | ---- | M] (Google Inc.)

HKEY_LOCAL_MACHINE\software\clients\startmenuinternet\Google Chrome\InstallInfo\\ReinstallCommand: "C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --make-default-browser [2013/01/25 20:35:08 | 001,248,208 | ---- | M] (Google Inc.)

HKEY_LOCAL_MACHINE\software\clients\startmenuinternet\Google Chrome\shell\open\command\\: "C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" [2013/01/25 20:35:08 | 001,248,208 | ---- | M] (Google Inc.)

HKEY_LOCAL_MACHINE\software\clients\startmenuinternet\IEXPLORE.EXE\InstallInfo\\ShowIconsCommand: "C:\Windows\System32\ie4uinit.exe" -show [2010/11/20 06:17:13 | 000,176,128 | ---- | M] (Microsoft Corporation)

HKEY_LOCAL_MACHINE\software\clients\startmenuinternet\IEXPLORE.EXE\InstallInfo\\ReinstallCommand: "C:\Windows\System32\ie4uinit.exe" -reinstall [2010/11/20 06:17:13 | 000,176,128 | ---- | M] (Microsoft Corporation)

HKEY_LOCAL_MACHINE\software\clients\startmenuinternet\IEXPLORE.EXE\InstallInfo\\HideIconsCommand: "C:\Windows\System32\ie4uinit.exe" -hide [2010/11/20 06:17:13 | 000,176,128 | ---- | M] (Microsoft Corporation)

HKEY_LOCAL_MACHINE\software\clients\startmenuinternet\IEXPLORE.EXE\shell\naom\command\\: "C:\Program Files (x86)\Internet Explorer\iexplore.exe" -extoff [2010/11/20 06:22:51 | 000,673,040 | ---- | M] (Microsoft Corporation)

HKEY_LOCAL_MACHINE\software\clients\startmenuinternet\IEXPLORE.EXE\shell\open\command\\: C:\Program Files (x86)\Internet Explorer\iexplore.exe [2010/11/20 06:22:51 | 000,673,040 | ---- | M] (Microsoft Corporation)

 

< hklm\software\clients\startmenuinternet|command /64 /rs >

64bit-HKEY_LOCAL_MACHINE\software\clients\startmenuinternet\Google Chrome\InstallInfo\\ShowIconsCommand: "C:\PROGRAM FILES (X86)\GOOGLE\CHROME\APPLICATION\CHROME.EXE" --SHOW-ICONS [2013/01/25 20:35:08 | 001,248,208 | ---- | M] (Google Inc.)

64bit-HKEY_LOCAL_MACHINE\software\clients\startmenuinternet\Google Chrome\InstallInfo\\HideIconsCommand: "C:\PROGRAM FILES (X86)\GOOGLE\CHROME\APPLICATION\CHROME.EXE" --HIDE-ICONS [2013/01/25 20:35:08 | 001,248,208 | ---- | M] (Google Inc.)

64bit-HKEY_LOCAL_MACHINE\software\clients\startmenuinternet\Google Chrome\InstallInfo\\ReinstallCommand: "C:\PROGRAM FILES (X86)\GOOGLE\CHROME\APPLICATION\CHROME.EXE" --MAKE-DEFAULT-BROWSER [2013/01/25 20:35:08 | 001,248,208 | ---- | M] (Google Inc.)

64bit-HKEY_LOCAL_MACHINE\software\clients\startmenuinternet\Google Chrome\shell\open\command\\: "C:\PROGRAM FILES (X86)\GOOGLE\CHROME\APPLICATION\CHROME.EXE" [2013/01/25 20:35:08 | 001,248,208 | ---- | M] (Google Inc.)

64bit-HKEY_LOCAL_MACHINE\software\clients\startmenuinternet\IEXPLORE.EXE\InstallInfo\\ShowIconsCommand: "C:\WINDOWS\SYSTEM32\IE4UINIT.EXE" -SHOW [2009/07/13 19:39:12 | 000,073,728 | ---- | M] (Microsoft Corporation)

64bit-HKEY_LOCAL_MACHINE\software\clients\startmenuinternet\IEXPLORE.EXE\InstallInfo\\ReinstallCommand: "C:\WINDOWS\SYSTEM32\IE4UINIT.EXE" -REINSTALL [2009/07/13 19:39:12 | 000,073,728 | ---- | M] (Microsoft Corporation)

64bit-HKEY_LOCAL_MACHINE\software\clients\startmenuinternet\IEXPLORE.EXE\InstallInfo\\HideIconsCommand: "C:\WINDOWS\SYSTEM32\IE4UINIT.EXE" -HIDE [2009/07/13 19:39:12 | 000,073,728 | ---- | M] (Microsoft Corporation)

64bit-HKEY_LOCAL_MACHINE\software\clients\startmenuinternet\IEXPLORE.EXE\shell\naom\command\\: "C:\PROGRAM FILES (X86)\INTERNET EXPLORER\IEXPLORE.EXE" -EXTOFF [2010/11/20 06:22:51 | 000,673,040 | ---- | M] (Microsoft Corporation)

64bit-HKEY_LOCAL_MACHINE\software\clients\startmenuinternet\IEXPLORE.EXE\shell\open\command\\: C:\PROGRAM FILES (X86)\INTERNET EXPLORER\IEXPLORE.EXE [2010/11/20 06:22:51 | 000,673,040 | ---- | M] (Microsoft Corporation)

 

========== Alternate Data Streams ==========

 

@Alternate Data Stream - 127 bytes -> C:\ProgramData\TEMP:22741C1F

@Alternate Data Stream - 118 bytes -> C:\ProgramData\TEMP:A31FAD21

< End of report >

Posted

OTL Extras logfile created on: 2/1/2013 5:52:35 PM - Run 1

OTL by OldTimer - Version 3.2.69.0 Folder = C:\Users\Deb\Desktop

64bit- Home Premium Edition Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation

Internet Explorer (Version = 8.0.7601.17514)

Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

 

3.97 Gb Total Physical Memory | 1.43 Gb Available Physical Memory | 35.95% Memory free

7.93 Gb Paging File | 5.56 Gb Available in Paging File | 70.17% Paging File free

Paging file location(s): ?:\pagefile.sys [binary data]

 

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)

Drive C: | 116.44 Gb Total Space | 26.69 Gb Free Space | 22.92% Space Free | Partition Type: NTFS

Drive D: | 337.60 Gb Total Space | 87.33 Gb Free Space | 25.87% Space Free | Partition Type: NTFS

 

Computer Name: DEB-PC | User Name: Deb | Logged in as Administrator.

Boot Mode: Normal | Scan Mode: Current user | Include 64bit Scans

Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

 

========== Extra Registry (SafeList) ==========

 

 

========== File Associations ==========

 

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<extension>]

.url[@ = InternetShortcut] -- C:\Windows\SysNative\rundll32.exe (Microsoft Corporation)

 

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<extension>]

.cpl [@ = cplfile] -- C:\Windows\SysWow64\control.exe (Microsoft Corporation)

 

[HKEY_CURRENT_USER\SOFTWARE\Classes\<extension>]

.html [@ = htmlfile] -- Reg Error: Key error. File not found

 

========== Shell Spawning ==========

 

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<key>\shell\[command]\command]

batfile [open] -- "%1" %*

cmdfile [open] -- "%1" %*

comfile [open] -- "%1" %*

exefile [open] -- "%1" %*

helpfile [open] -- Reg Error: Key error.

inffile [install] -- %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation)

InternetShortcut [open] -- "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\ieframe.dll",OpenURL %l (Microsoft Corporation)

InternetShortcut [print] -- "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\mshtml.dll",PrintHTML "%1" (Microsoft Corporation)

piffile [open] -- "%1" %*

regfile [merge] -- Reg Error: Key error.

scrfile [config] -- "%1"

scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l

scrfile [open] -- "%1" /S

txtfile [edit] -- Reg Error: Key error.

Unknown [openas] -- %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1

Directory [AddToPlaylistVLC] -- C:\Program Files (x86)\VideoLAN\VLC\vlc.exe --started-from-file --playlist-enqueue "%1" ()

Directory [bridge] -- C:\Program Files (x86)\Adobe\Adobe Bridge CS5\Bridge.exe "%L" (Adobe Systems, Inc.)

Directory [cmd] -- cmd.exe /s /k pushd "%V" (Microsoft Corporation)

Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)

Directory [LovelyFolders] -- C:\Program Files (x86)\Lovely Folders\LFolders.exe "%1" (Lovelysoft)

Directory [PlayWithVLC] -- C:\Program Files (x86)\VideoLAN\VLC\vlc.exe --started-from-file --no-playlist-enqueue "%1" ()

Folder [open] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)

Folder [explore] -- Reg Error: Value error.

Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)

 

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<key>\shell\[command]\command]

batfile [open] -- "%1" %*

cmdfile [open] -- "%1" %*

comfile [open] -- "%1" %*

cplfile [cplopen] -- %SystemRoot%\System32\control.exe "%1",%* (Microsoft Corporation)

exefile [open] -- "%1" %*

helpfile [open] -- Reg Error: Key error.

inffile [install] -- %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation)

piffile [open] -- "%1" %*

regfile [merge] -- Reg Error: Key error.

scrfile [config] -- "%1"

scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l

scrfile [open] -- "%1" /S

txtfile [edit] -- Reg Error: Key error.

Unknown [openas] -- %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1

Directory [AddToPlaylistVLC] -- C:\Program Files (x86)\VideoLAN\VLC\vlc.exe --started-from-file --playlist-enqueue "%1" ()

Directory [bridge] -- C:\Program Files (x86)\Adobe\Adobe Bridge CS5\Bridge.exe "%L" (Adobe Systems, Inc.)

Directory [cmd] -- cmd.exe /s /k pushd "%V" (Microsoft Corporation)

Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)

Directory [LovelyFolders] -- C:\Program Files (x86)\Lovely Folders\LFolders.exe "%1" (Lovelysoft)

Directory [PlayWithVLC] -- C:\Program Files (x86)\VideoLAN\VLC\vlc.exe --started-from-file --no-playlist-enqueue "%1" ()

Folder [open] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)

Folder [explore] -- Reg Error: Value error.

Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)

 

========== Security Center Settings ==========

 

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]

"cval" = 1

 

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]

 

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]

"VistaSp1" = 28 4D B2 76 41 04 CA 01 [binary data]

"AntiVirusOverride" = 0

"AntiSpywareOverride" = 0

"FirewallOverride" = 0

 

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc\Vol]

 

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]

 

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]

 

========== Firewall Settings ==========

 

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]

"DisableNotifications" = 0

"EnableFirewall" = 1

 

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]

"DisableNotifications" = 0

"EnableFirewall" = 1

 

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\PublicProfile]

"DisableNotifications" = 0

"EnableFirewall" = 1

 

========== Authorized Applications List ==========

 

 

========== Vista Active Open Ports Exception List ==========

 

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]

"{09420363-7A8A-4FA1-B16D-217877D3C30C}" = lport=2869 | protocol=6 | dir=in | name=windows live communications platform (upnp) |

"{0AD6C65D-0EA8-4985-A7DA-56EE32509D56}" = lport=rpc | protocol=6 | dir=in | svc=spooler | app=%systemroot%\system32\spoolsv.exe |

"{16BA28AB-0081-4362-847F-DA36B36A0A27}" = lport=6004 | protocol=17 | dir=in | app=c:\program files (x86)\microsoft office\office12\outlook.exe |

"{18E6E986-CE1A-4086-9640-1B45DDD631FA}" = lport=5353 | protocol=17 | dir=in | name=bonjour port 5353 |

"{1ABF8D59-E6DA-4DE0-BF87-2A9F72ACBFA5}" = lport=1900 | protocol=17 | dir=in | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe |

"{20A3FAFB-9CC2-471D-80C2-AE6B331F8354}" = lport=5000 | protocol=17 | dir=in | name=akamai netsession interface |

"{29F51CD3-C1AD-4A36-9216-AAF8093DC64B}" = lport=5355 | protocol=17 | dir=in | svc=dnscache | app=%systemroot%\system32\svchost.exe |

"{36678064-DB2B-431F-956F-AC91E57E4F16}" = rport=5355 | protocol=17 | dir=out | svc=dnscache | app=%systemroot%\system32\svchost.exe |

"{3791DCB3-43C3-4DE1-80D3-C453AA67200F}" = lport=138 | protocol=17 | dir=in | app=system |

"{38B7FE68-261C-4FE0-B70C-3305162A9A73}" = lport=9322 | protocol=6 | dir=in | name=ekdiscovery |

"{4EBBDFA6-89F3-4E7C-BB3D-39E724B33831}" = lport=3702 | protocol=17 | dir=in | svc=fdrespub | app=%systemroot%\system32\svchost.exe |

"{4FF65309-1A0B-4BB2-88A8-D47489C38DB7}" = lport=1900 | protocol=17 | dir=in | name=windows live communications platform (ssdp) |

"{53424228-80F3-4F48-8C11-15668BD41957}" = lport=1900 | protocol=17 | dir=in | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe |

"{5BB8FA0B-834A-4B4F-98C4-DD97D6107EDE}" = lport=5353 | protocol=17 | dir=in | name=bonjour port 5353 |

"{5FB42AA2-F072-4C49-B2C4-DB4114258E0F}" = rport=10243 | protocol=6 | dir=out | app=system |

"{5FCFA5EC-ECB6-4889-BB4E-423C3C30C0E0}" = rport=5355 | protocol=17 | dir=out | svc=dnscache | app=%systemroot%\system32\svchost.exe |

"{64AF56FF-8F05-44AF-8B94-73B3CD2A4540}" = lport=10243 | protocol=6 | dir=in | app=system |

"{6904FB5C-6436-4A36-B98F-015B8D0339D8}" = lport=2869 | protocol=6 | dir=in | app=system |

"{6D8065E3-7C49-4563-A964-44F980522819}" = rport=2177 | protocol=17 | dir=out | svc=qwave | app=%systemroot%\system32\svchost.exe |

"{6EE8837B-A34A-4608-ACAE-B9AD2B4AFBDB}" = rport=137 | protocol=17 | dir=out | app=system |

"{9D259EC5-A808-4BEB-99D5-0310163666F8}" = lport=139 | protocol=6 | dir=in | app=system |

"{A4358BA7-3A66-48E2-A9FF-C4DB21AAEA3E}" = lport=9322 | protocol=6 | dir=in | name=ekdiscovery |

"{A8BC8FD3-55EF-4988-9D2F-7B6F770E3968}" = lport=5355 | protocol=17 | dir=in | svc=dnscache | app=%systemroot%\system32\svchost.exe |

"{AF734322-E583-4195-A0FA-2891178746F3}" = lport=rpc-epmap | protocol=6 | dir=in | svc=rpcss | name=@firewallapi.dll,-28539 |

"{B0CAA045-4311-4D03-9770-CCBD29A8A5BA}" = lport=5355 | protocol=17 | dir=in | svc=dnscache | app=%systemroot%\system32\svchost.exe |

"{B28F8BAF-BA5B-4D98-B14A-46CEAAD5416F}" = rport=139 | protocol=6 | dir=out | app=system |

"{B2CB7B88-DC21-43B9-9386-36F9D001E79D}" = rport=3702 | protocol=17 | dir=out | svc=fdrespub | app=%systemroot%\system32\svchost.exe |

"{B8F5DF16-0CEE-439B-BEB4-39B1BDF2E878}" = rport=1900 | protocol=17 | dir=out | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe |

"{B9E4AAFA-6A5D-4F0C-9BD9-4038425331FC}" = lport=445 | protocol=6 | dir=in | app=system |

"{C4A71CD3-D502-4C27-8D36-BC151EC86FA6}" = rport=138 | protocol=17 | dir=out | app=system |

"{C888BECC-8399-433D-B5C6-29DDA78F8BE8}" = rport=1900 | protocol=17 | dir=out | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe |

"{CB25B4D3-A19B-4DFD-A57A-9B9BF118D105}" = rport=3702 | protocol=17 | dir=out | svc=fdphost | app=%systemroot%\system32\svchost.exe |

"{CD808F78-38FB-4B5F-AECE-F0BBF2405D74}" = lport=808 | protocol=6 | dir=in | svc=nettcpactivator | app=c:\windows\microsoft.net\framework64\v4.0.30319\smsvchost.exe |

"{CDDAB182-4079-41CB-A3E0-C62E4A33516F}" = rport=2177 | protocol=6 | dir=out | svc=qwave | app=%systemroot%\system32\svchost.exe |

"{D7638201-420F-4EFF-BD97-CCAFEF24C7FA}" = lport=3702 | protocol=17 | dir=in | svc=fdphost | app=%systemroot%\system32\svchost.exe |

"{DC3F4419-602E-44F0-ACAF-6682B3A6BB34}" = lport=137 | protocol=17 | dir=in | app=system |

"{E703D467-9229-4E32-B44F-F565FAB4C3F5}" = rport=445 | protocol=6 | dir=out | app=system |

"{F493EE6C-3798-4269-8D82-714B24C6E6F8}" = lport=49166 | protocol=6 | dir=in | name=akamai netsession interface |

"{F62521A8-1CB6-4AC0-8715-CBAAE964F8E9}" = rport=5355 | protocol=17 | dir=out | svc=dnscache | app=%systemroot%\system32\svchost.exe |

"{FB10AB82-DEF7-4E1C-A38D-2915CC0E4975}" = lport=2177 | protocol=6 | dir=in | svc=qwave | app=%systemroot%\system32\svchost.exe |

"{FCB0B73A-9AE2-4912-A77E-6228A888D9EF}" = lport=2177 | protocol=17 | dir=in | svc=qwave | app=%systemroot%\system32\svchost.exe |

 

========== Vista Active Application Exception List ==========

 

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]

"{01CB0866-F8ED-48CF-B335-E0F882EDE588}" = dir=in | app=c:\program files (x86)\hp\digital imaging\bin\hpiscnapp.exe |

"{05AB7D77-1AB1-4563-A5E3-78E12A13C1CB}" = dir=in | app=c:\program files (x86)\windows live\contacts\wlcomm.exe |

"{086B1134-CBB7-497A-A997-D9EFCE8001C5}" = dir=in | app=c:\program files (x86)\hp\digital imaging\bin\hpoews01.exe |

"{08B92A59-6CEE-43B9-BFD3-254F379607EB}" = dir=in | app=c:\program files (x86)\hp\digital imaging\bin\hpqkygrp.exe |

"{1C1B540A-C68C-4E83-83BB-B6356F4D72E8}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmplayer.exe |

"{212AE434-4794-4F2A-9A19-33B01D47EFD6}" = dir=in | app=c:\program files (x86)\hp\digital imaging\bin\hpqusgm.exe |

"{263EB0E1-ACE1-4D6D-911A-448918EC6BAE}" = protocol=6 | dir=in | app=c:\users\deb\appdata\local\akamai\netsession_win.exe |

"{30BC4EB4-D801-4ABD-8AC0-5768AF967299}" = protocol=6 | dir=in | app=c:\programdata\kodak\installer\setup.exe |

"{31D267AC-CC03-4741-8870-B4718A2348D3}" = protocol=17 | dir=in | app=c:\program files (x86)\kodak\aio\center\aiohomecenter.exe |

"{3939FFEA-B3BD-4446-8CB9-873E8EAF1F64}" = protocol=17 | dir=in | app=c:\users\deb\appdata\local\akamai\netsession_win.exe |

"{3C188F9F-DD38-49A7-A257-9E87B0A61405}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmplayer.exe |

"{3E78EE9D-289C-4596-8A82-210BDAAB3C2F}" = dir=in | app=c:\program files (x86)\common files\hp\digital imaging\bin\hpqphotocrm.exe |

"{42C93078-E31A-4473-A5FD-F8EC9A7B3E35}" = protocol=6 | dir=in | app=c:\program files (x86)\pando networks\pando\pando.exe |

"{436B4BF2-51A4-41C3-9886-F7957106CDE1}" = protocol=17 | dir=in | app=c:\programdata\kodak\installer\setup.exe |

"{43C6BCA9-E729-4476-9F64-9DC43A14B536}" = dir=in | app=c:\program files (x86)\hp\digital imaging\bin\hpqgplgtupl.exe |

"{440120BC-665F-4A8F-B113-B6FEBD1C8B41}" = dir=out | app=c:\program files (x86)\protected search\protectedsearch.exe |

"{466C76F7-0BC4-41C5-8A57-88BADD73D509}" = protocol=6 | dir=in | app=c:\program files (x86)\kodak\aio\firmware\kodakaioupdater.exe |

"{53401D4D-9306-4C24-B438-43FCDCE2B7CC}" = protocol=6 | dir=in | app=c:\program files (x86)\kodak\aio\center\aiohomecenter.exe |

"{5A98B82A-5F32-498C-91AA-8D1B4D31B85E}" = dir=in | app=c:\program files (x86)\finaltorrent\finaltorrent.exe |

"{6352F1D8-2543-4387-86C2-E9640C0AA8A3}" = protocol=17 | dir=in | app=c:\program files (x86)\microsoft office\office12\onenote.exe |

"{66552376-21C6-4E64-B653-912F29B63F04}" = protocol=58 | dir=in | name=@firewallapi.dll,-28545 |

"{68221AF8-6990-4CA3-9D6A-6721B2116E85}" = dir=in | app=c:\program files (x86)\hp\digital imaging\bin\hposid01.exe |

"{6BD7B9FF-22CB-40F5-86BA-4FA7A4454860}" = protocol=6 | dir=in | app=c:\program files (x86)\microsoft office\office12\onenote.exe |

"{7061CAB0-CD28-420C-BD93-3C5544A03CBB}" = protocol=6 | dir=in | app=%programfiles%\windows media player\wmpnetwk.exe |

"{7145CB7E-C0C8-4618-ACAC-30EB1079AA06}" = protocol=17 | dir=in | app=c:\program files (x86)\pando networks\pando\pando.exe |

"{73012904-3E02-41D3-927A-A0E76BCD6FFE}" = protocol=17 | dir=in | app=%programfiles(x86)%\windows media player\wmplayer.exe |

"{76D16319-360E-43E9-B333-408135723B42}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmpnetwk.exe |

"{76DF68B8-7A1C-41B4-99DD-9BF92669ABC1}" = protocol=6 | dir=out | svc=upnphost | app=%systemroot%\system32\svchost.exe |

"{77FD5C2D-0415-43BD-A4A3-AF3D6ECDCB4C}" = protocol=17 | dir=out | app=%programfiles(x86)%\windows media player\wmplayer.exe |

"{802BA8A5-7E2A-4C15-AD72-27B0778389EB}" = dir=in | app=c:\program files (x86)\windows live\messenger\msnmsgr.exe |

"{84B9DB2F-382F-435E-9AA0-4EED0A20097F}" = protocol=17 | dir=in | app=c:\program files (x86)\kodak\aio\center\networkprinterdiscovery.exe |

"{858CEDF3-BFA4-4C89-9F00-F6613A8E98CC}" = protocol=6 | dir=in | app=c:\program files (x86)\kodak\aio\center\networkprinterdiscovery.exe |

"{8F50342A-BEA0-44DF-ADF1-8939E3168856}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmpnetwk.exe |

"{8F88F43D-868D-4969-9839-B5A72F0BE6A8}" = dir=in | app=c:\program files (x86)\pando networks\pando\pando.exe |

"{925A5C26-4FC3-4608-807B-921E0633361C}" = dir=in | app=c:\program files (x86)\protected search\protectedsearch.exe |

"{93A0A1A5-AF75-42C4-A8E6-34B68A5835C8}" = protocol=6 | dir=in | app=c:\users\deb\appdata\local\microsoft\windows\temporary internet files\content.ie5\rwy1ik2t\aviconvertersetup[1].exe |

"{96F35B97-0FB0-496C-B9F2-6E1597017791}" = dir=in | app=c:\program files (x86)\hp\digital imaging\bin\hpqgpc01.exe |

"{973341D9-CB84-4595-ADF6-2B8EE21DCC72}" = protocol=58 | dir=out | name=@firewallapi.dll,-28546 |

"{981A034C-1263-49DF-8417-39E4AC586785}" = dir=in | app=c:\program files (x86)\hp\digital imaging\bin\hpfccopy.exe |

"{98DAA843-3BF7-40FE-BB79-8F1342FBC380}" = dir=in | app=c:\program files (x86)\hp\hp software update\hpwucli.exe |

"{9DD47EF7-8560-49D0-861B-E5F1EFA11875}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmplayer.exe |

"{A02FC901-EE66-4B4D-B182-3FEAABBD4702}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmpnetwk.exe |

"{A1F6869D-4D1D-40E4-8991-27A07CB80A09}" = dir=in | app=c:\program files (x86)\hp\digital imaging\smart web printing\smartwebprintexe.exe |

"{A7B167E4-B722-447B-B3AB-5CC77B7E97C3}" = protocol=17 | dir=in | app=c:\program files (x86)\kodak\aio\center\kodak.statistics.exe |

"{A8537B52-BB25-4020-9D7C-F9A6686075AD}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmplayer.exe |

"{AD350902-978F-4CF1-A58B-4EA6B2C38A84}" = protocol=17 | dir=in | app=c:\program files (x86)\microsoft office\office12\groove.exe |

"{B2885286-A65C-4A5E-82C4-E3AE9BC5A9D2}" = protocol=6 | dir=in | app=c:\program files (x86)\microsoft office\office12\groove.exe |

"{B943B2E3-BB1D-490B-AA1B-2E7FFBC13B93}" = protocol=1 | dir=in | name=@firewallapi.dll,-28543 |

"{BA27E891-58D2-4950-B107-CDE9417B5ECE}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmplayer.exe |

"{BB14BF45-6E48-4593-A6A7-4FC11C080796}" = protocol=6 | dir=in | app=c:\program files (x86)\kodak\aio\center\kodak.statistics.exe |

"{CE5669BE-4DBB-4253-A78B-B3A09CB3EF02}" = protocol=6 | dir=out | svc=upnphost | app=%systemroot%\system32\svchost.exe |

"{D2B227D4-42E8-4F79-A94F-1E1CF044C274}" = protocol=17 | dir=in | app=c:\users\deb\appdata\local\microsoft\windows\temporary internet files\content.ie5\rwy1ik2t\aviconvertersetup[1].exe |

"{D5569629-8B97-4F73-935C-1F8B19BC92AB}" = dir=in | app=c:\program files (x86)\hp\digital imaging\bin\hpqste08.exe |

"{D5D76651-022E-4F74-9519-A93880C08789}" = protocol=6 | dir=out | app=system |

"{DEEDCCF1-1B80-48CC-98A6-D64B2060B85A}" = protocol=17 | dir=in | app=c:\program files (x86)\kodak\aio\firmware\kodakaioupdater.exe |

"{DEF9FAFA-2D6A-4F67-A348-A4CF1F09BDF2}" = dir=in | app=c:\program files (x86)\hp\digital imaging\bin\hpqcopy2.exe |

"{E59EA0BB-20F3-4998-BC19-F70BE9B60601}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmplayer.exe |

"{E8F0ECE5-B3D2-47C6-B1E3-B2B98AED33B6}" = protocol=6 | dir=out | app=%programfiles(x86)%\windows media player\wmplayer.exe |

"{EAA9D16C-C96E-496C-AB8A-706C8022FBC7}" = dir=in | app=c:\program files (x86)\hp\digital imaging\bin\hpqtra08.exe |

"{EB7ED54F-0592-4CAA-983A-5D817C1093A1}" = dir=in | app=c:\program files (x86)\hp\digital imaging\bin\hpqusgh.exe |

"{FA4EF43E-C321-4671-B98C-B2D547B3780D}" = dir=in | app=c:\program files (x86)\windows live\mesh\moe.exe |

"{FB57E60A-692C-4294-B8C4-FD34C9F0EF1A}" = protocol=1 | dir=out | name=@firewallapi.dll,-28544 |

"TCP Query User{3C09D715-AA25-4E64-8B9D-818246E89C63}C:\program files (x86)\internet explorer\iexplore.exe" = protocol=6 | dir=in | app=c:\program files (x86)\internet explorer\iexplore.exe |

"TCP Query User{6052DDC6-96D9-4361-A5B6-1B1C270DDDEB}C:\program files (x86)\yahoo!\messenger\yahoomessenger.exe" = protocol=6 | dir=in | app=c:\program files (x86)\yahoo!\messenger\yahoomessenger.exe |

"TCP Query User{F6DA13F1-B97A-4102-904D-AC4CD473BDCE}C:\users\deb\appdata\local\akamai\netsession_win.exe" = protocol=6 | dir=in | app=c:\users\deb\appdata\local\akamai\netsession_win.exe |

"UDP Query User{502BFDBB-4877-4317-9137-3C3EE3ABA889}C:\program files (x86)\internet explorer\iexplore.exe" = protocol=17 | dir=in | app=c:\program files (x86)\internet explorer\iexplore.exe |

"UDP Query User{CFBE5BEF-FB7C-4F27-A51C-A427B95E0D05}C:\users\deb\appdata\local\akamai\netsession_win.exe" = protocol=17 | dir=in | app=c:\users\deb\appdata\local\akamai\netsession_win.exe |

"UDP Query User{D507254C-1C66-4CA5-AC61-1CB0867B78E9}C:\program files (x86)\yahoo!\messenger\yahoomessenger.exe" = protocol=17 | dir=in | app=c:\program files (x86)\yahoo!\messenger\yahoomessenger.exe |

 

========== HKEY_LOCAL_MACHINE Uninstall List ==========

 

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]

"{027E5FAB-1476-4C59-AAB4-32EF28520399}" = Windows Live Language Selector

"{02A5BD31-16AC-45DF-BE9F-A3167BC4AFB2}" = Windows Live Family Safety

"{0D87AE67-14EB-4C10-88A5-DA6C3181EB18}" = Windows Live Family Safety

"{1686C4D1-B1FD-42E8-B7A8-FB4C4DBA5BA8}" = ASUS Power4Gear Hybrid

"{1ACC8FFB-9D84-4C05-A4DE-D28A9BC91698}" = Windows Live ID Sign-in Assistant

"{1E9FC118-651D-4934-97BE-E53CAE5C7D45}" = Microsoft_VC80_MFCLOC_x86_x64

"{27EF8E7F-88D1-4ec5-ADE2-7E447FDF114E}" = Kodak AIO Printer

"{4569AD91-47F4-4D9E-8FC9-717EC32D7AE1}" = Microsoft_VC80_CRT_x86_x64

"{656DEEDE-F6AC-47CA-A568-A1B4E34B5760}" = Windows Live Remote Service Resources

"{847B0532-55E3-4AAF-8D7B-E3A1A7CD17E5}" = Windows Live Remote Client Resources

"{8557397C-A42D-486F-97B3-A2CBC2372593}" = Microsoft_VC90_ATL_x86_x64

"{889DF117-14D1-44EE-9F31-C5FB5D47F68B}" = Yontoo Layers Runtime 1.10.01

"{8E34682C-8118-31F1-BC4C-98CD9675E1C2}" = Microsoft .NET Framework 4 Extended

"{90120000-002A-0000-1000-0000000FF1CE}" = Microsoft Office Office 64-bit Components 2007

"{90120000-002A-0409-1000-0000000FF1CE}" = Microsoft Office Shared 64-bit MUI (English) 2007

"{90120000-0116-0409-1000-0000000FF1CE}" = Microsoft Office Shared 64-bit Setup Metadata MUI (English) 2007

"{925D058B-564A-443A-B4B2-7E90C6432E55}" = Microsoft_VC80_ATL_x86_x64

"{92A3CA0D-55CD-4C5D-BA95-5C2600C20F26}" = Microsoft_VC90_CRT_x86_x64

"{95120000-00B9-0409-1000-0000000FF1CE}" = Microsoft Application Error Reporting

"{A472B9E4-0AFF-4F7B-B25D-F64F8E928AAB}" = Microsoft_VC90_MFC_x86_x64

"{C8C1BAD5-54E6-4146-AD07-3A8AD36569C3}" = Microsoft_VC80_MFC_x86_x64

"{CDBF8C2D-04B0-4F9B-9AE1-7422F7F0EC94}" = HP Deskjet F2400 All-In-One Driver Software 13.0 Rel .6

"{DA54F80E-261C-41A2-A855-549A144F2F59}" = Windows Live MIME IFilter

"{DF6D988A-EEA0-4277-AAB8-158E086E439B}" = Windows Live Remote Client

"{E02A6548-6FDE-40E2-8ED9-119D7D7E641F}" = Windows Live Remote Service

"{F5B09CFD-F0B2-36AF-8DF4-1DF6B63FC7B4}" = Microsoft .NET Framework 4 Client Profile

"{FF21C3E6-97FD-474F-9518-8DCBE94C2854}" = 64 Bit HP CIO Components Installer

"Desktop Icon Toy_is1" = Desktop Icon Toy 4.6

"Elantech" = ETDWare PS/2-x64 7.0.5.7_WHQL

"Folder Marker_is1" = Folder Marker Home v 3.2 GAOTD Edition

"HDMI" = Intel® Graphics Media Accelerator Driver

"HP Imaging Device Functions" = HP Imaging Device Functions 13.0

"HP Print Projects" = HP Print Projects 1.0

"HP Smart Web Printing" = HP Smart Web Printing 4.5

"HP Solution Center & Imaging Support Tools" = HP Solution Center 13.0

"HPExtendedCapabilities" = HP Customer Participation Program 13.0

"Microsoft .NET Framework 4 Client Profile" = Microsoft .NET Framework 4 Client Profile

"Microsoft .NET Framework 4 Extended" = Microsoft .NET Framework 4 Extended

"Shop for HP Supplies" = Shop for HP Supplies

"WinX DVD Copy Pro_is1" = WinX DVD Copy Pro 3.0.0

 

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]

"{00E1E235-AB45-4695-A156-073118949ED4}" = HiYo

"{01FB4998-33C4-4431-85ED-079E3EEFE75D}" = LG CyberLink YouCam

"{033E378E-6AD3-4AD5-BDEB-CBD69B31046C}" = Microsoft_VC90_ATL_x86

"{06585B02-F20D-4AB2-9A64-86EF2AE0F8F0}" = ASUS AI Recovery

"{06A1D88C-E102-4527-AF70-29FFD7AF215A}" = Scan

"{07FB17D8-7DB6-4F06-80C4-8BE1719CB6A1}" = hpWLPGInstaller

"{08D2E121-7F6A-43EB-97FD-629B44903403}" = Microsoft_VC90_CRT_x86

"{0969AF05-4FF6-4C00-9406-43599238DE0D}" = ASUS Splendid Video Enhancement Technology

"{0B0F231F-CE6A-483D-AA23-77B364F75917}" = Windows Live Installer

"{0D2DBE8A-43D0-7830-7AE7-CA6C99A832E7}" = Adobe Community Help

"{0F3647F8-E51D-4FCC-8862-9A8D0C5ACF25}" = Microsoft_VC80_ATL_x86

"{175F0111-2968-4935-8F70-33108C6A4DE3}" = MarketResearch

"{18455581-E099-4BA8-BC6B-F34B2F06600C}" = Google Toolbar for Internet Explorer

"{18DB3375-0649-4EA3-959A-44F1ACD278BA}" = IncrediMail

"{19BA08F7-C728-469C-8A35-BFBD3633BE08}" = Windows Live Movie Maker

"{1A15507A-8551-4626-915D-3D5FA095CC1B}" = Corel Paint Shop Pro X

"{1a413f37-ed88-4fec-9666-5c48dc4b7bb7}" = YouTube Downloader 2.7.2

"{1DBD1F12-ED93-49C0-A7CC-56CBDE488158}" = ASUS LifeFrame3

"{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148

"{1F2DF2C6-08F7-40BD-8E85-D16CB436E7F0}" = Free NaturalReader

"{1F6AB0E7-8CDD-4B93-8A23-AA9EB2FEFCE4}" = Junk Mail filter update

"{1FAD9CDD-BEE6-4240-BE2C-A47A2573F29D}_is1" = Leawo PowerPoint to DVD Pro version 4.1.0.200

"{1FBF6C24-C1FD-4101-A42B-0C564F9E8E79}" = LG CyberLink Media Suite

"{200FEC62-3C34-4D60-9CE8-EC372E01C08F}" = Windows Live SOXE Definitions

"{20D4A895-748C-4D88-871C-FDB1695B0169}" = Platform

"{20E674AD-8ECC-4680-92D6-18ABE4FC1DE0}" = Hallmark Comedy Card Studio

"{20FDF948-C8ED-4543-A539-F7F4AEF5AFA2}" = Wireless Console 3

"{21A2F5EE-1DC5-488A-BE7E-E526F8C61488}" = DeviceDiscovery

"{2318C2B1-4965-11d4-9B18-009027A5CD4F}" = Google Toolbar for Internet Explorer

"{26A24AE4-039D-4CA4-87B4-2F83216033FF}" = Java 6 Update 37

"{28006915-2739-4EBE-B5E8-49B25D32EB33}" = Atheros Client Installation Program

"{28C2DED6-325B-4CC7-983A-1777C8F7FBAB}" = RealUpgrade 1.1

"{2902F983-B4C1-44BA-B85D-5C6D52E2C441}" = Windows Live Mesh ActiveX Control for Remote Connections

"{297DCADA-86A1-4A42-8A13-66B7D7A09FD2}" = WeatherBug

"{2A27F3BC-AB3D-4E25-89AF-6D31DE7E1927}_is1" = IncrediMail Collection Manager 2.04

"{2A304FDE-F4E3-446D-AA0D-31425C897B71}" = PrintMaster 12

"{2A3FC24C-6EC0-4519-A52B-FDA4EA9B2D24}" = Windows Live Messenger

"{2EEA7AA4-C203-4b90-A34F-19FB7EF1C81C}" = BufferChm

"{2EFA4E4C-7B5F-48F7-A1C0-1AA882B7A9C3}" = HP Update

"{2FCFFE64-B076-4C21-874E-1C8ADEE8B378}_is1" = AnyPic Image Converter 1.0.1

"{3108C217-BE83-42E4-AE9E-A56A2A92E549}" = Atheros Communications Inc.® AR8121/AR8113/AR8114 Gigabit/Fast Ethernet Driver

"{3336F667-9049-4D46-98B6-4C743EEBC5B1}" = Windows Live Photo Gallery

"{342126E1-173C-4585-BFBE-3EBDD20E3E9E}" = Mobipocket Reader 6.2

"{34F4D9A4-42C2-4348-BEF4-E553C84549E7}" = Windows Live Photo Gallery

"{3B05F2FB-745B-4012-ADF2-439F36B2E70B}" = ATKOSD2

"{3B6E3FC6-274C-4B6C-BC85-5C3B15DE18E2}" = Mega Manager

"{3F41BA46-09C3-4500-96D7-DC4390AD0124}" = Acrobat X Suite

"{416D80BA-6F6D-4672-B7CF-F54DA2F80B44}" = Microsoft Works

"{42E2EEB2-D48E-4A47-B181-32ECA031D93B}" = DJ_AIO_06_F2400_SW_Min

"{43CDF946-F5D9-4292-B006-BA0D92013021}" = WebReg

"{48B41C3A-9A92-4B81-B653-C97FEB85C910}" = C4USelfUpdater

"{4A70EF07-7F88-4434-BB61-D1DE8AE93DD4}" = SolutionCenter

"{4F41AD68-89F2-4262-A32C-2F70B01FCE9E}" = Photo Story 3 for Windows

"{4F93ABBE-5A1D-4D56-94CB-022F109FDE4D}" = Adobe Presenter 7

"{50206644-C226-498D-8273-9F5F300807E2}_is1" = NeoPaint 4.7c

"{50816F92-1652-4A7C-B9BC-48F682742C4B}" = Messenger Companion

"{56BA241F-580C-43D2-8403-947241AAE633}" = center

"{579684A4-DDD5-4CA3-9EA8-7BE7D9593DB4}" = Windows Live UX Platform Language Pack

"{5A22D889-FBDD-4AE8-86EC-089D45FC133E}" = Alcor Micro USB Card Reader

"{5B5E949E-3924-45E3-9229-84E8270BED68}" = ArcSoft Perfect365

"{5B65EF64-1DFA-414A-8C94-7BB726158E21}" = ControlDeck

"{5BCC634A-58AD-42F9-B3C6-2EA52F81CF85}" = Snagit 10

"{607169F0-07F6-4797-99D2-D5E7C4715E20}" = Mega Manager

"{6179550A-3E7C-499E-BCC9-9E8113E0A285}" = LG ODD Auto Firmware Update

"{635FED5B-2C6D-49BE-87E6-7A6FCD22BC5A}" = Microsoft_VC90_MFC_x86

"{63FF21C9-A810-464F-B60A-3111747B1A6D}" = GPBaseService2

"{64452561-169F-4A36-A2FF-B5E118EC65F5}" = ASUS SmartLogon

"{682B3E4F-696A-42DE-A41C-4C07EA1678B4}" = Windows Live SOXE

"{686695ED-BB3F-415D-B0DB-18CF535F7B50}" = Driver Manager

"{68A10D12-0D0F-4212-BDE6-D87FAD32A8FA}" = SmartWebPrinting

"{69B6B9E1-A5DF-3177-2B1D-3B672F29EF86}" = Adobe Captivate Quiz Results Analyzer

"{6A9736BC-F478-4C89-B6EB-7BC6BE1358B7}" = Event Planner

"{6AB7673C-A0FE-4B67-A29E-323FE3AD17A6}" = ArcSoft PhotoStudio Paint

"{6B2FFB21-AC88-45C3-9A7D-4BB3E744EC91}" = HPSSupply

"{6B77A7F6-DD63-4F13-A6FF-83137A5AC354}" = ASUS CopyProtect

"{6BAA71B6-8F43-4C72-931A-3354ABB0258A}" = F2400

"{6BBA26E9-AB03-4FE7-831A-3535584CA002}" = Toolbox

"{6C47663A-C5B9-4404-A4BA-E75392F33B2C}_is1" = ScreenCamera.Net version 1.3.8.80

"{6D308A90-6C14-4A02-9B04-CB0EF17894A9}_is1" = Picture Collage Maker Pro 2.5.7

"{6F340107-F9AA-47C6-B54C-C3A19F11553F}" = Hewlett-Packard ACLM.NET v1.1.0.0

"{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}" = Microsoft Visual C++ 2005 Redistributable

"{770657D0-A123-3C07-8E44-1C83EC895118}" = Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053

"{7770E71B-2D43-4800-9CB3-5B6CAAEBEBEA}" = RealNetworks - Microsoft Visual C++ 2008 Runtime

"{77DCDCE3-2DED-62F3-8154-05E745472D07}" = Acrobat.com

"{788A0222-5690-4212-AA9C-C48FD0E1C9AE}" = Photo Notifier and Animation Creator

"{78A96B4C-A643-4D0F-98C2-A8E16A6669F9}" = Windows Live Messenger Companion Core

"{7C05592D-424B-46CB-B505-E0013E8E75C9}" = ATK Hotkey

"{7C4196CA-CA41-4F34-9C08-7724E7705D52}" = Jasc Animation Shop 3

"{7D466431-D6EE-4732-BF02-74BD0817E881}_is1" = AnyPic Image Resizer Pro 1.1.0

"{7EEE783B-C117-4DF5-B5BE-E94E99BE969B}" = calibre

"{837b34e3-7c30-493c-8f6a-2b0f04e2912c}" = Microsoft Visual C++ 2005 Redistributable

"{83C292B7-38A5-440B-A731-07070E81A64F}" = Windows Live PIMT Platform

"{8432FFD1-6F4D-F9B8-D641-5932E60359A2}" = Adobe Captivate Reviewer

"{846B5DED-DC8C-4E1A-B5B4-9F5B39A0CACE}" = HPDiagnosticAlert

"{86CE85E6-DBAC-3FFD-B977-E4B79F83C909}" = Microsoft Visual C++ 2008 Redistributable - KB2467174 - x86 9.0.30729.5570

"{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight

"{8C6D6116-B724-4810-8F2D-D047E6B7D68E}" = Mesh Runtime

"{8DD46C6A-0056-4FEC-B70A-28BB16A1F11F}" = MSVCRT

"{8E1CB0F1-67BF-4052-AA23-FA22E94804C1}" = InstallIQ Updater

Posted

"{8E45B56B-F2BB-44D5-B728-7EAE92B6969D}_is1" = IncrediMail Data Manager 2.02

"{8F21291E-0444-4B1D-B9F9-4370A73E346D}" = WinFlash

"{90120000-0015-0409-0000-0000000FF1CE}" = Microsoft Office Access MUI (English) 2007

"{90120000-0015-0409-0000-0000000FF1CE}_ENTERPRISE_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = 2007 Microsoft Office Suite Service Pack 2 (SP2)

"{90120000-0016-0409-0000-0000000FF1CE}" = Microsoft Office Excel MUI (English) 2007

"{90120000-0016-0409-0000-0000000FF1CE}_ENTERPRISE_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = 2007 Microsoft Office Suite Service Pack 2 (SP2)

"{90120000-0018-0409-0000-0000000FF1CE}" = Microsoft Office PowerPoint MUI (English) 2007

"{90120000-0018-0409-0000-0000000FF1CE}_ENTERPRISE_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = 2007 Microsoft Office Suite Service Pack 2 (SP2)

"{90120000-0019-0409-0000-0000000FF1CE}" = Microsoft Office Publisher MUI (English) 2007

"{90120000-0019-0409-0000-0000000FF1CE}_ENTERPRISE_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = 2007 Microsoft Office Suite Service Pack 2 (SP2)

"{90120000-001A-0409-0000-0000000FF1CE}" = Microsoft Office Outlook MUI (English) 2007

"{90120000-001A-0409-0000-0000000FF1CE}_ENTERPRISE_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = 2007 Microsoft Office Suite Service Pack 2 (SP2)

"{90120000-001B-0409-0000-0000000FF1CE}" = Microsoft Office Word MUI (English) 2007

"{90120000-001B-0409-0000-0000000FF1CE}_ENTERPRISE_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = 2007 Microsoft Office Suite Service Pack 2 (SP2)

"{90120000-001F-0409-0000-0000000FF1CE}" = Microsoft Office Proof (English) 2007

"{90120000-001F-0409-0000-0000000FF1CE}_ENTERPRISE_{ABDDE972-355B-4AF1-89A8-DA50B7B5C045}" = 2007 Microsoft Office Suite Service Pack 2 (SP2)

"{90120000-001F-040C-0000-0000000FF1CE}" = Microsoft Office Proof (French) 2007

"{90120000-001F-040C-0000-0000000FF1CE}_ENTERPRISE_{F580DDD5-8D37-4998-968E-EBB76BB86787}" = 2007 Microsoft Office Suite Service Pack 2 (SP2)

"{90120000-001F-0C0A-0000-0000000FF1CE}" = Microsoft Office Proof (Spanish) 2007

"{90120000-001F-0C0A-0000-0000000FF1CE}_ENTERPRISE_{187308AB-5FA7-4F14-9AB9-D290383A10D9}" = 2007 Microsoft Office Suite Service Pack 2 (SP2)

"{90120000-002A-0000-1000-0000000FF1CE}_ENTERPRISE_{E64BA721-2310-4B55-BE5A-2925F9706192}" = 2007 Microsoft Office Suite Service Pack 2 (SP2)

"{90120000-002A-0409-1000-0000000FF1CE}_ENTERPRISE_{DE5A002D-8122-4278-A7EE-3121E7EA254E}" = 2007 Microsoft Office Suite Service Pack 2 (SP2)

"{90120000-002C-0409-0000-0000000FF1CE}" = Microsoft Office Proofing (English) 2007

"{90120000-0030-0000-0000-0000000FF1CE}" = Microsoft Office Enterprise 2007

"{90120000-0030-0000-0000-0000000FF1CE}_ENTERPRISE_{0B36C6D6-F5D8-4EAF-BF94-4376A230AD5B}" = 2007 Microsoft Office Suite Service Pack 2 (SP2)

"{90120000-0044-0409-0000-0000000FF1CE}" = Microsoft Office InfoPath MUI (English) 2007

"{90120000-0044-0409-0000-0000000FF1CE}_ENTERPRISE_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = 2007 Microsoft Office Suite Service Pack 2 (SP2)

"{90120000-006E-0409-0000-0000000FF1CE}" = Microsoft Office Shared MUI (English) 2007

"{90120000-006E-0409-0000-0000000FF1CE}_ENTERPRISE_{DE5A002D-8122-4278-A7EE-3121E7EA254E}" = 2007 Microsoft Office Suite Service Pack 2 (SP2)

"{90120000-00A1-0409-0000-0000000FF1CE}" = Microsoft Office OneNote MUI (English) 2007

"{90120000-00A1-0409-0000-0000000FF1CE}_ENTERPRISE_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = 2007 Microsoft Office Suite Service Pack 2 (SP2)

"{90120000-00BA-0409-0000-0000000FF1CE}" = Microsoft Office Groove MUI (English) 2007

"{90120000-00BA-0409-0000-0000000FF1CE}_ENTERPRISE_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = 2007 Microsoft Office Suite Service Pack 2 (SP2)

"{90120000-0114-0409-0000-0000000FF1CE}" = Microsoft Office Groove Setup Metadata MUI (English) 2007

"{90120000-0114-0409-0000-0000000FF1CE}_ENTERPRISE_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = 2007 Microsoft Office Suite Service Pack 2 (SP2)

"{90120000-0115-0409-0000-0000000FF1CE}" = Microsoft Office Shared Setup Metadata MUI (English) 2007

"{90120000-0115-0409-0000-0000000FF1CE}_ENTERPRISE_{DE5A002D-8122-4278-A7EE-3121E7EA254E}" = 2007 Microsoft Office Suite Service Pack 2 (SP2)

"{90120000-0116-0409-1000-0000000FF1CE}_ENTERPRISE_{DE5A002D-8122-4278-A7EE-3121E7EA254E}" = 2007 Microsoft Office Suite Service Pack 2 (SP2)

"{90120000-0117-0409-0000-0000000FF1CE}" = Microsoft Office Access Setup Metadata MUI (English) 2007

"{90120000-0117-0409-0000-0000000FF1CE}_ENTERPRISE_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = 2007 Microsoft Office Suite Service Pack 2 (SP2)

"{92D58719-BBC1-4CC3-A08B-56C9E884CC2C}" = Microsoft_VC80_CRT_x86

"{92EA4134-10D1-418A-91E1-5A0453131A38}" = Windows Live Movie Maker

"{9A25302D-30C0-39D9-BD6F-21E6EC160475}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17

"{9BE518E6-ECC6-35A9-88E4-87755C07200F}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161

"{9CE2B4FB-8127-4058-B028-C5961242A480}" = Pattern Maker for cross stitch - v4

"{9D48531D-2135-49FC-BC29-ACCDA5396A76}" = ASUS MultiFrame

"{9D56775A-93F3-44A3-8092-840E3826DE30}" = Windows Live Mail

"{A0C91188-C88F-4E86-93E6-CD7C9A266649}" = Windows Live Mesh

"{A16656CE-4B17-4484-A13F-22B9500E5223}" = Fast Boot

"{A254D625} PicturesToExe 5.6_is1" = PicturesToExe 5.6

"{A2BCA9F1-566C-4805-97D1-7FDC93386723}" = Adobe AIR

"{A436F67F-687E-4736-BD2B-537121A804CF}" = HP Product Detection

"{A61AE368-B88C-414C-9118-503EECFC3AC8}_is1" = Photo Toolbox for Windows version 1.7.4.5

"{A726AE06-AAA3-43D1-87E3-70F510314F04}" = Windows Live Writer

"{A78FE97A-C0C8-49CE-89D0-EDD524A17392}" = PDF Settings CS5

"{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}" = Google Update Helper

"{A9BDCA6B-3653-467B-AC83-94367DA3BFE3}" = Windows Live Photo Common

"{AAAFC670-569B-4A2F-82B4-42945E0DE3EF}" = Windows Live Writer

"{AAECF7BA-E83B-4A10-87EA-DE0B333F8734}" = RealNetworks - Microsoft Visual C++ 2010 Runtime

"{AAF4238F-7C29-451D-9925-C753271A5728}" = Microsoft Visual C++ Run Time Lib Setup

"{AAF454FC-82CA-4F29-AB31-6A109485E76E}" = Windows Live Writer

"{AB480DA0-7EE9-465D-9C12-4CDE65BF18FB}" = Pando

"{AC76BA86-7AD7-1033-7B44-AA1000000001}" = Adobe Reader X (10.1.5)

"{ADD5DB49-72CF-11D8-9D75-000129760D75}" = LG CyberLink PowerBackup

"{AE8705FB-E13C-40A9-8A2D-68D6733FBFC2}" = Status

"{AF7EBCA4-9FAF-4DC8-8D09-67854BB84D34}" = RealDownloader

"{B07CB2BA-819B-41C5-BBE0-484A4C23972E}" = Easy Flyer Creator 3.0

"{B39DC03B-F2C0-4F7E-B1DD-328F73BD98FD}" = Font Thumbnail

"{B6D38690-755E-4F40-A35A-23F8BC2B86AC}" = Microsoft_VC90_MFCLOC_x86

"{BA413735-865A-4BF5-AAD2-B4D2998ED019}}_is1" = BatchInpaint 1.0

"{BD7204BA-DD64-499E-9B55-6A282CDF4FA4}" = Destinations

"{BE94C681-68E2-4561-8ABC-8D2E799168B4}" = essentials

"{BFBCF96F-7361-486A-965C-54B17AC35421}" = ocr

"{C2B9C70F-165E-450D-9EC1-F7B160016291}" = Living 3D Dolphin

"{C43326F5-F135-4551-8270-7F7ABA0462E1}" = HPProductAssistant

"{C59C179C-668D-49A9-B6EA-0121CCFC1243}" = LG CyberLink LabelPrint

"{C66824E4-CBB3-4851-BB3F-E8CFD6350923}" = Windows Live Mail

"{c6c214df-2922-4809-94aa-f4d67d4451ec}" = Music Oasis

"{C75CDBA2-3C86-481e-BD10-BDDA758F9DFF}" = hpPrintProjects

"{CA16B670-D9BD-4051-882A-B5AB057F7128}_is1" = FixBee Disk Optimizer

"{CAE4213F-F797-439D-BD9E-79B71D115BE3}" = HPPhotoGadget

"{CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1}" = Microsoft .NET Framework 1.1

"{CD0DD6A4-B951-4021-8E05-C73733C5D15B}" = MimarSinan Rubber Ducky

"{CE95A79E-E4FC-4FFF-8A75-29F04B942FF2}" = Windows Live UX Platform

"{D0B44725-3666-492D-BEF6-587A14BD9BD9}" = MSVCRT_amd64

"{D1A19B02-817E-4296-A45B-07853FD74D57}" = Microsoft_VC80_MFC_x86

"{D1E5870E-E3E5-4475-98A6-ADD614524ADF}" = ATK Media

"{D3CB90C2-BEC1-4D15-8E05-11623357861B}" = Kahlown

"{D3D54F3E-C5C3-443D-978F-87A72E5616E8}" = ATK Generic Function Service

"{D436F577-1695-4D2F-8B44-AC76C99E0002}" = Windows Live Photo Common

"{D45240D3-B6B3-4FF9-B243-54ECE3E10066}" = Windows Live Communications Platform

"{D53599B0-AA76-4CC6-B9EF-CC2F27B56F24}_is1" = Picture Collage Maker 3.2.8

"{D8262480-2A04-407C-B2F7-1439B789C349}" = Print Artist Gold 21

"{D92BBB52-82FF-42ED-8A3C-4E062F944AB7}" = Microsoft_VC80_MFCLOC_x86

"{D9757258-30B2-496E-86F2-84920C5858E1}_is1" = CollageIt 1.2.2

"{DA5BDB2A-12F0-4343-8351-21AAEB293990}" = PreReq

"{DB6AB705-C9BD-40E3-8929-2EA57F36A4FF}_is1" = ConvertXtoDVD 4.1.2.336

"{DC0A5F99-FD66-433F-9D3A-05DCBA64BE42}" = TrayApp

"{DDC8BDEE-DCAC-404D-8257-3E8D4B782467}" = Windows Live Writer Resources

"{DE3A9DC5-9A5D-6485-9662-347162C7E4CA}" = Adobe Media Player

"{DECDCB7C-58CC-4865-91AF-627F9798FE48}" = Windows Live Mesh

"{E09C4DB7-630C-4F06-A631-8EA7239923AF}" = D3DX10

"{E0F274B7-592B-4669-8FB8-8D9825A09858}" = KODAK AiO Software

"{E5B21F11-6933-4E0B-A25C-7963E3C07D11}" = Windows Live Messenger

"{E657B243-9AD4-4ECC-BE81-4CCF8D667FD0}" = ASUS Live Update

"{EC8BD21F-0CA0-4BBF-97D9-4A52B30041A1}" = ASUS Virtual Camera

"{EF53BFAB-4C10-40DB-A82D-9B07111715C6}" = aioscnnr

"{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}" = Microsoft SQL Server 2005 Compact Edition [ENU]

"{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}" = Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219

"{F0DF4513-3C4C-4EB8-8012-2C5F70AF3988}" = ASUS FancyStart

"{F2A69CA0-8BBF-4404-BA68-DB79A3548E34}" = PCStitch 7

"{F843C6A3-224D-4615-94F8-3C461BD9AEA0}" = Jasc Paint Shop Pro 9

"{FA2092C5-7979-412D-A962-6485274AE1EE}" = ASUS Data Security Manager

"{FAAEB46F-6BEE-409B-8983-264C21B9C415}" = Pixo

"{FAF26102-09D7-4C58-AB01-0D59A2E517CA}" = Copy

"{FC274982-5AAD-4C20-848D-4424A5043009}_is1" = WinUtilities 9.98 Professional Edition

"{FE044230-9CA5-43F7-9B58-5AC5A28A1F33}" = Windows Live Essentials

"{FF66E9F6-83E7-3A3E-AF14-8DE9A809A6A4}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.21022

"{gmt_free_avi_to_dvd-66712EEE-ECBC-AXXXX-videosoft}_is1" = Free GMT AVI to DVD 4.9.5.0

"4Media Photo Slideshow Maker" = 4Media Photo Slideshow Maker

"4Media Ringtone Maker" = 4Media Ringtone Maker

"7-Zip" = 7-Zip 9.20

"ABC Birthday Reminder_is1" = ABC Birthday Reminder version 2.6

"Adobe Acrobat 4.0" = Adobe Acrobat 4.0

"Adobe AIR" = Adobe AIR

"Adobe Flash Player ActiveX" = Adobe Flash Player 11 ActiveX

"Adobe Photoshop CS5" = Adobe Photoshop CS5

"Adobe Presenter 7" = Adobe Presenter 7

"AdobeCaptivateReviewer2.E7BED6E5DDA59983786DD72EBFA46B1598278E07.1" = Adobe Captivate Reviewer

"Aiseesoft Total Media Converter_is1" = Aiseesoft Total Media Converter 5.2.30

"Akamai" = Akamai NetSession Interface Service

"Animated Screensaver Maker" = Animated Screensaver Maker

"Animated Wallpaper Maker" = Animated Wallpaper Maker

"AnvSoft Photo Flash Maker Free" = AnvSoft Photo Flash Maker Free 5.21

"AnyDVD" = AnyDVD

"Ashampoo Burning Studio Elements_is1" = Ashampoo Burning Studio Elements 10.0.9

"Asus_Camera_ScreenSaver" = Asus_Camera_ScreenSaver

"Avira AntiVir Desktop" = Avira Free Antivirus

"Batch Photo Watermarker_is1" = Batch Photo Watermarker 3.5

"Blitz FlashCards (GOTD Version)" = Blitz FlashCards (GOTD Version) (remove only)

"CCleaner" = CCleaner (remove only)

"chc.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1" = Adobe Community Help

"com.adobe.amp.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1" = Adobe Media Player

"DailyBibleGuidebar Uninstall" = DailyBibleGuide

"Desktop Crossword" = Desktop Crossword

"Digital Editions" = Adobe Digital Editions

"DP Animation Maker" = DP Animation Maker

"DVD Photo Slideshow Professional_is1" = DVD Photo Slideshow Professional 8.00

"DVD Shrink_is1" = DVD Shrink 3.2

"EaseUS Data Recovery Wizard 5.6.5_is1" = EaseUS Data Recovery Wizard 5.6.5

"Easy Clone Detective1.4" = Easy Clone Detective

"ENTERPRISE" = Microsoft Office Enterprise 2007

"Filters Unlimited_is1" = Filters Unlimited 2.0

"FinalTorrent_is1" = FinalTorrent 2010

"FineCrosser2_is1" = FineCrosser Pro 2.4.2

"Font Xplorer" = Font Xplorer 1.2.2

"Free Audio Converter_is1" = Free Audio Converter version 2.2.11

"Free Easy Burner_is1" = Free Easy Burner V 4.4.1

"FX - AVI Converter" = FoxTab AVI Converter (remove only)

"Game Booster_is1" = Game Booster

"Google Chrome" = Google Chrome

"Halotea Lite" = Halotea Lite v1.105

"HiYo" = HiYo

"IBN Video Joiner2.0.1" = IBN Video Joiner

"Imikimi Plugin" = Imikimi Plugin

"Incomedia WebSite X5 v8 - Smart" = Incomedia WebSite X5 v8 - Smart

"IncrediMail" = IncrediMail 2.0

"IncrediMail_MediaBar_2 Toolbar" = IncrediMail MediaBar 2 Toolbar

"InstallShield_{01FB4998-33C4-4431-85ED-079E3EEFE75D}" = LG CyberLink YouCam

"InstallShield_{1FBF6C24-C1FD-4101-A42B-0C564F9E8E79}" = LG CyberLink Media Suite

"InstallShield_{20D4A895-748C-4D88-871C-FDB1695B0169}" = VIA Platform Device Manager

"InstallShield_{5A22D889-FBDD-4AE8-86EC-089D45FC133E}" = Alcor Micro USB Card Reader

"InstallShield_{C59C179C-668D-49A9-B6EA-0121CCFC1243}" = LG CyberLink LabelPrint

"InstantStorm_is1" = InstantStorm 2.0

"Jigsaw Puzzle Platinum Edition Deluxe" = Jigsaw Puzzle Platinum Edition Deluxe

"KLiteCodecPack_is1" = K-Lite Codec Pack 7.8.0 (Full)

"Lovely Folders" = Lovely Folders

"Malwarebytes' Anti-Malware_is1" = Malwarebytes Anti-Malware version 1.70.0.1100

"mediAvatar Photo to Flash" = mediAvatar Photo to Flash

"MimarSinan Rubber Ducky" = MimarSinan Rubber Ducky

"MiPony" = MiPony 1.5.2

"Nero8Lite_is1" = Nero 8 Lite 8.3.6.0

"OpenAL" = OpenAL

"Photo Notifier and Animation Creator" = Photo Notifier and Animation Creator

"Photo Stamp Remover_is1" = Photo Stamp Remover 3.1

"pixpedia-en_is1" = Pixpedia Publisher 3.0.8

"PowerISO" = PowerISO

"PrintProjects" = PrintProjects

"QuizResultsAnalyzer.E7BED6E5DDA59983786DD72EBFA46B1598278E07.1" = Adobe Captivate Quiz Results Analyzer

"RealPlayer 16.0" = RealPlayer

"Revo Uninstaller" = Revo Uninstaller 1.92

"RonyaSoft CD DVD Label Maker" = RonyaSoft CD DVD Label Maker 3.01

"Scrapbook Design Studio 2.0_is1" = Scrapbook Design Studio 2.0

"Simpo PDF to PowerPoint_is1" = Simpo PDF to PowerPoint

"Slideshow Wizard Trial Version_is1" = Slideshow Wizard 3.2 Trial Version

"ST6UNST #1" = Dispatch Labels v5.0

"SwordBible_is1" = SwordBible 5.42

"ThunderSoft Flash Slideshow Factory_is1" = ThunderSoft Flash Slideshow Factory (2.5.0.0)

"Total Audio Converter_is1" = TotalAudioConverter

"Uninstall_is1" = Uninstall 1.0.0.1

"VideoBooth" = Video Booth

"VideoGet_is1" = Nuclear Coffee - VideoGet

"Vizros Plug-ins 4.1" = Vizros Plug-ins 4.1

"VLC media player" = VLC media player 0.9.2

"WebPost" = Microsoft Web Publishing Wizard 1.52

"WinAVI Video Converter_is1" = WinAVI Video Converter

"Window Washer" = Window Washer

"WinLiveSuite" = Windows Live Essentials

"WinRAR archiver" = WinRAR archiver

"Wondershare DVD Slideshow Builder Standard_is1" = Wondershare DVD Slideshow Builder Standard(Build 6.1.1.46)

"Wondershare Photo Collage Studio GOTD Edition_is1" = Wondershare Photo Collage Studio 4.2.16.5

"XnView_is1" = XnView 1.98.5

"Yahoo! Companion" = Yahoo! Toolbar

"Yahoo! Messenger" = Yahoo! Messenger

"Yahoo! Software Update" = Yahoo! Software Update

"yBook_is1" = yBook

 

========== HKEY_CURRENT_USER Uninstall List ==========

 

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]

"Akamai" = Akamai NetSession Interface

"Amazon Kindle" = Amazon Kindle

"easyQuizzy_is1" = easyQuizzy 2.0.421

"ImageBadger Image Converter" = ImageBadger Image Converter

"Password Manager Deluxe" = Password Manager Deluxe

 

========== Last 20 Event Log Errors ==========

 

[ Application Events ]

Error - 1/24/2013 10:01:39 AM | Computer Name = Deb-PC | Source = Application Error | ID = 1000

Description = Faulting application name: IncMail.exe, version: 6.2.9.4978, time

stamp: 0x4dd190e6 Faulting module name: KERNELBASE.dll, version: 6.1.7601.18015,

time stamp: 0x50b83c8a Exception code: 0xe06d7363 Fault offset: 0x0000c41f Faulting

process id: 0x1a28 Faulting application start time: 0x01cdfa395eb57c87 Faulting application

path: C:\Program Files (x86)\IncrediMail\Bin\IncMail.exe Faulting module path: C:\Windows\syswow64\KERNELBASE.dll

Report

Id: 92a5ac20-662e-11e2-ac95-e0cb4e3d451f

 

Error - 1/24/2013 9:16:34 PM | Computer Name = Deb-PC | Source = Application Hang | ID = 1002

Description = The program avscan.exe version 13.6.0.402 stopped interacting with

Windows and was closed. To see if more information about the problem is available,

check the problem history in the Action Center control panel. Process ID: 2098 Start

Time: 01cdfa996394acbf Termination Time: 54451 Application Path: C:\Program Files

(x86)\Avira\AntiVir Desktop\avscan.exe Report Id: aee53a52-668c-11e2-83e6-e0cb4e3d451f

 

Error - 1/28/2013 3:56:43 AM | Computer Name = Deb-PC | Source = SideBySide | ID = 16842815

Description = Activation context generation failed for "C:\Program Files (x86)\Common

Files\Adobe AIR\Versions\1.0\Adobe AIR.dll".Error in manifest or policy file "C:\Program

Files (x86)\Common Files\Adobe AIR\Versions\1.0\Adobe AIR.dll" on line 3. The value

"MAJOR_VERSION.MINOR_VERSION.BUILD_NUMBER_MAJOR.BUILD_NUMBER_MINOR" of attribute

"version" in element "assemblyIdentity" is invalid.

 

Error - 1/28/2013 3:59:55 AM | Computer Name = Deb-PC | Source = SideBySide | ID = 16842832

Description = Activation context generation failed for "c:\program files (x86)\Nero\nero

toolkit\nero discspeed\DiscSpeed.exe".Error in manifest or policy file "" on line

. A component version required by the application conflicts with another component

version already active. Conflicting components are:. Component 1: C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest.

Component

2: C:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2.manifest.

 

Error - 1/31/2013 11:55:06 AM | Computer Name = Deb-PC | Source = Avira Antivirus | ID = 4110

Description = An unknown error occurred during init of the engine! Returned error

code: 0x35

 

Error - 1/31/2013 12:21:13 PM | Computer Name = Deb-PC | Source = SideBySide | ID = 16842815

Description = Activation context generation failed for "C:\Program Files (x86)\Common

Files\Adobe AIR\Versions\1.0\Adobe AIR.dll".Error in manifest or policy file "C:\Program

Files (x86)\Common Files\Adobe AIR\Versions\1.0\Adobe AIR.dll" on line 3. The value

"MAJOR_VERSION.MINOR_VERSION.BUILD_NUMBER_MAJOR.BUILD_NUMBER_MINOR" of attribute

"version" in element "assemblyIdentity" is invalid.

 

Error - 1/31/2013 12:22:12 PM | Computer Name = Deb-PC | Source = SideBySide | ID = 16842832

Description = Activation context generation failed for "c:\program files (x86)\Nero\nero

toolkit\nero discspeed\DiscSpeed.exe".Error in manifest or policy file "" on line

. A component version required by the application conflicts with another component

version already active. Conflicting components are:. Component 1: C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest.

Component

2: C:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2.manifest.

 

Error - 2/1/2013 7:23:20 AM | Computer Name = Deb-PC | Source = Avira Antivirus | ID = 4110

Description = An unknown error occurred during init of the engine! Returned error

code: 0x35

 

Error - 2/1/2013 1:14:25 PM | Computer Name = Deb-PC | Source = SideBySide | ID = 16842815

Description = Activation context generation failed for "C:\Program Files (x86)\Common

Files\Adobe AIR\Versions\1.0\Adobe AIR.dll".Error in manifest or policy file "C:\Program

Files (x86)\Common Files\Adobe AIR\Versions\1.0\Adobe AIR.dll" on line 3. The value

"MAJOR_VERSION.MINOR_VERSION.BUILD_NUMBER_MAJOR.BUILD_NUMBER_MINOR" of attribute

"version" in element "assemblyIdentity" is invalid.

 

Error - 2/1/2013 1:17:13 PM | Computer Name = Deb-PC | Source = SideBySide | ID = 16842832

Description = Activation context generation failed for "c:\program files (x86)\Nero\nero

toolkit\nero discspeed\DiscSpeed.exe".Error in manifest or policy file "" on line

. A component version required by the application conflicts with another component

version already active. Conflicting components are:. Component 1: C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest.

Component

2: C:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2.manifest.

 

[ Media Center Events ]

Error - 4/15/2011 11:17:18 AM | Computer Name = Deb-PC | Source = MCUpdate | ID = 0

Description = 10:17:17 AM - Failed to retrieve SportsSchedule (Error: The underlying

connection was closed: Could not establish trust relationship for the SSL/TLS secure

channel.)

 

[ System Events ]

Error - 2/1/2013 8:23:27 AM | Computer Name = Deb-PC | Source = Service Control Manager | ID = 7001

Description = The Computer Browser service depends on the Server service which failed

to start because of the following error: %%1068

 

Error - 2/1/2013 8:23:35 AM | Computer Name = Deb-PC | Source = DCOM | ID = 10005

Description =

 

Error - 2/1/2013 8:25:24 AM | Computer Name = Deb-PC | Source = Service Control Manager | ID = 7001

Description = The Computer Browser service depends on the Server service which failed

to start because of the following error: %%1068

 

Error - 2/1/2013 8:25:24 AM | Computer Name = Deb-PC | Source = Service Control Manager | ID = 7001

Description = The Computer Browser service depends on the Server service which failed

to start because of the following error: %%1068

 

Error - 2/1/2013 8:25:24 AM | Computer Name = Deb-PC | Source = Service Control Manager | ID = 7001

Description = The Computer Browser service depends on the Server service which failed

to start because of the following error: %%1068

 

Error - 2/1/2013 8:25:24 AM | Computer Name = Deb-PC | Source = Service Control Manager | ID = 7001

Description = The Computer Browser service depends on the Server service which failed

to start because of the following error: %%1068

 

Error - 2/1/2013 8:25:24 AM | Computer Name = Deb-PC | Source = Service Control Manager | ID = 7001

Description = The Computer Browser service depends on the Server service which failed

to start because of the following error: %%1068

 

Error - 2/1/2013 8:25:24 AM | Computer Name = Deb-PC | Source = Service Control Manager | ID = 7001

Description = The Computer Browser service depends on the Server service which failed

to start because of the following error: %%1068

 

Error - 2/1/2013 8:29:05 AM | Computer Name = Deb-PC | Source = Service Control Manager | ID = 7000

Description = The Crypkey License service failed to start due to the following error:

%%2

 

Error - 2/1/2013 8:29:32 AM | Computer Name = Deb-PC | Source = Service Control Manager | ID = 7026

Description = The following boot-start or system-start driver(s) failed to load:

NetworkX

 

 

< End of report >

Posted

Hello, debi239.

 

 

 

 

Step 1

 

 

 

 

Please uninstall these programs via Add/Remove Programs:

  • IncrediMail
  • IncrediMail Collection Manager 2.04
  • IncrediMail Data Manager 2.02
  • DailyBibleGuide
  • HiYo

 

 

They come bundled with questionable toolbars that may contain tracking functionality. If you really want them, you can reinstall them once we're done.

 

 

 

 

 

 

 

 

 

 

Step 2

 

 

Install ERUNT

This tool will create a complete backup of your registry. After every reboot, a new backup is created to ensure we have a safety net after each step. Do not delete these backups until we are finished.


  •  
  • Please download erunt-setup.exe to your desktop.
     
  • Double click erunt-setup.exe. Follow the prompts and allow ERUNT to be installed with the settings at default. If you do not want a Desktop icon, feel free to uncheck that. When asked if you want to create an ERUNT entry in the startup folder, answer Yes. You can delete the installation file after use.
     
  • Erunt will open when the installation is finished. Check all items to be backed up in the default location and click OK.

 

 

The automatic part won't work with Vista or W7. Please backup manually using ERUNT with the following instructions:

  1. Please locate the ERUNT icon on the desktop. If it is not there, click Start and type ERUNT into the search box.
  2. Right click the ERUNT icon in the desktop or the Start menu, and select Run as Administrator
  3. Click OK at the first message box.
  4. Ensure the checkboxes for both "system registry" and "current user registry" are checked. Leave the default save location in there.
  5. Click OK.
  6. Click Yes to create the new folder.
  7. You'll get a window saying "registry backup complete" once it's done. Click OK. If you get an error message, please STOP here and let me know. Do not proceed with any additional instructions until you check back with me.

 

 

 

 

 

 

Step 3

 

 

We need run an OTL Script

  1. Please download OTL from one of the following mirrors if you do not still have it.

[*]Save it to your desktop.

[*]Double click on the http://billy-oneal.com/Canned%20Speeches/speechimages/OTL/otlDesktopIcon.png icon on your desktop.

[*]Paste the following code under the Custom Scans/Fixes box at the bottom.

:OTL
IE:64bit: - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://start.funmoods.com/?f=1&a=bf3...B&cr=801427480
IE:64bit: - HKLM\..\SearchScopes\{9BB47C17-9C68-4BB3-B188-DD9AF0FD2408}: "URL" = http://dts.search-results.com/sr?src...q={searchTerms}
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Default_Page_URL = http://search.certified-toolbar.com?...=true&tid=3204
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,Search Bar = http://search.certified-toolbar.com?...3204&bs=true&q=
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,Search Page = http://search.certified-toolbar.com?...3204&bs=true&q=
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,Start Default_Page_URL = http://search.certified-toolbar.com?...=true&tid=3204
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,Start Page = http://search.certified-toolbar.com?...=true&tid=3204
IE - HKLM\..\URLSearchHook: {d40b90b4-d3b1-4d6b-a5d7-dc041c1b76c0} - C:\Program Files (x86)\IncrediMail_MediaBar_2\prxtbInc0.dll (Conduit Ltd.)
IE - HKLM\..\SearchScopes,Backup.Old.DefaultScope = {6A1806CD-94D4-4689-BA73-E35EA1EA9990}
IE - HKLM\..\SearchScopes\{34e26447-bf30-4c78-a5b9-61dfa8a55e67}: "URL" = http://search.mywebsearch.com/mywebs...r={searchTerms}
IE - HKLM\..\SearchScopes\{6A1806CD-94D4-4689-BA73-E35EA1EA9990}: "URL" = http://start.funmoods.com/results.ph...B&cr=801427480
IE - HKLM\..\SearchScopes\{7C19EC30-6FAD-B9F6-82AA-0C5189279B17}: "URL" = http://search.certified-toolbar.com?...q={searchTerms}
IE - HKLM\..\SearchScopes\{9BB47C17-9C68-4BB3-B188-DD9AF0FD2408}: "URL" = http://dts.search-results.com/sr?src...q={searchTerms}
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Default_Page_URL = http://search.certified-toolbar.com?...=true&tid=3204
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://igoogle.com/
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Restore = http://mystart.hiyo.com
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Search,Search Bar = http://search.certified-toolbar.com?...3204&bs=true&q=
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Search,Search Page = http://search.certified-toolbar.com?...3204&bs=true&q=
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Search,Start Default_Page_URL = http://search.certified-toolbar.com?...=true&tid=3204
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Search,Start Page = http://search.certified-toolbar.com?...=true&tid=3204
IE - HKCU\..\URLSearchHook: {f15ff29f-85a1-43cd-9674-e5ba40016c97} - C:\Program Files (x86)\DailyBibleGuide\bar\1.bin\2vSrcAs.dll (DailyBibleGuide)
IE - HKCU\..\SearchScopes,Backup.Old.DefaultScope = {6A1806CD-94D4-4689-BA73-E35EA1EA9990}
IE - HKCU\..\SearchScopes\{30CFB165-2CF1-7712-E58F-3A8DBE9E3CFA}: "URL" = http://www.incredimail-start.com/s/?...=2-428-0-2x4co
IE - HKCU\..\SearchScopes\{34e26447-bf30-4c78-a5b9-61dfa8a55e67}: "URL" = http://search.mywebsearch.com/mywebs...r={searchTerms}
IE - HKCU\..\SearchScopes\{8B63A8D6-BBED-4341-8867-790E5F524C96}: "URL" = http://mystart.incredimail.com/?sear...loc=search_box
IE - HKCU\..\SearchScopes\{9BB47C17-9C68-4BB3-B188-DD9AF0FD2408}: "URL" = http://dts.search-results.com/sr?src...q={searchTerms}
IE - HKCU\..\SearchScopes\{C7576B9D-B442-46bc-AF74-080A9E723E01}: "URL" = http://websearch.search-results.com/...1-8E0487E93484
IE - HKCU\..\SearchScopes\{CFF4DB9B-135F-47c0-9269-B4C6572FD61A}: "URL" = http://mystart.incredimail.com//?sea...&a=1pcqIQ5iKit
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Int ernet Settings: "ProxyOverride" = 127.0.0.1:9421;<local>
FF - HKLM\Software\MozillaPlugins\@DailyBibleGuide.com/Plugin: C:\Program Files (x86)\DailyBibleGuide\bar\1.bin\NP2vStub.dll (DailyBibleGuide)
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extens ions\\2vffxtbr@DailyBibleGuide.com: C:\Program Files (x86)\DailyBibleGuide\bar\1.bin [2011/10/14 06:41:49 | 000,000,000 | ---D | M]
O2 - BHO: (Search Assistant BHO) - {0631bff0-6846-48ca-982d-d62d7f376e97} - C:\Program Files (x86)\DailyBibleGuide\bar\1.bin\2vSrcAs.dll (DailyBibleGuide)
O2 - BHO: (no name) - {9D425283-D487-4337-BAB6-AB8354A81457} - No CLSID value found.
O2 - BHO: (Toolbar BHO) - {beea7fa9-d1f4-49a2-9b1f-6fb7a2d9bc2a} - C:\Program Files (x86)\DailyBibleGuide\bar\1.bin\2vbar.dll (DailyBibleGuide)
O2 - BHO: (IncrediMail MediaBar 2 Toolbar) - {d40b90b4-d3b1-4d6b-a5d7-dc041c1b76c0} - C:\Program Files (x86)\IncrediMail_MediaBar_2\prxtbInc0.dll (Conduit Ltd.)
O3 - HKLM\..\Toolbar: (DailyBibleGuide) - {2a942ab7-2073-49bc-a7e1-77e93835889a} - C:\Program Files (x86)\DailyBibleGuide\bar\1.bin\2vbar.dll (DailyBibleGuide)
O3 - HKLM\..\Toolbar: (no name) - {9D425283-D487-4337-BAB6-AB8354A81457} - No CLSID value found.
O3 - HKLM\..\Toolbar: (IncrediMail MediaBar 2 Toolbar) - {d40b90b4-d3b1-4d6b-a5d7-dc041c1b76c0} - C:\Program Files (x86)\IncrediMail_MediaBar_2\prxtbInc0.dll (Conduit Ltd.)
O3 - HKLM\..\Toolbar: (no name) - Locked - No CLSID value found.
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {22E03916-85C5-44B0-8DC9-1830C11238D9} - No CLSID value found.
O3 - HKCU\..\Toolbar\WebBrowser: (DailyBibleGuide) - {2A942AB7-2073-49BC-A7E1-77E93835889A} - C:\Program Files (x86)\DailyBibleGuide\bar\1.bin\2vbar.dll (DailyBibleGuide)
O3 - HKCU\..\Toolbar\WebBrowser: (IncrediMail MediaBar 2 Toolbar) - {D40B90B4-D3B1-4D6B-A5D7-DC041C1B76C0} - C:\Program Files (x86)\IncrediMail_MediaBar_2\prxtbInc0.dll (Conduit Ltd.)
O4 - HKLM..\Run: [DailyBibleGuide Browser Plugin Loader] C:\Program Files (x86)\DailyBibleGuide\bar\1.bin\2vbrmon.exe (DailyBibleGuide)
O4 - HKLM..\Run: [Hiyo] C:\Program Files (x86)\HiYo\bin\HiYo.exe (IncrediMail, Ltd.)
O4 - HKCU..\Run: [AdobeBridge] File not found
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab (Reg Error: Key error.)
MsConfig:64bit - StartUpReg: facemoods - hkey= - key= - File not found
MsConfig:64bit - StartUpReg: Startup Defender - hkey= - key= - File not found
MsConfig:64bit - StartUpReg: TelevisionFanatic Browser Plugin Loader - hkey= - key= - File not found
:files
C:\Program Files (x86)\IncrediMail_MediaBar_2\
C:\Program Files (x86)\DailyBibleGuide
C:\Program Files (x86)\HiYo
C:\Program Files (x86)\Red Sky
C:\Program Files (x86)\Protected Search

[*]Click the Run Fix button at the top.

[*]let the program run unhindered and reboot when it is done.

[*]You will get a log when it is done, please post that in your reply.

[*]Please then create a new OTL report....

[*]Click the "Scan All Users" checkbox.

[*]Push the http://billy-oneal.com/Canned%20Speeches/speechimages/OTL/runscanbutton.png button.

[*]A report will open, copy and paste it in a reply here.

 

 

 

 

 

 

Step 4

 

 

 

 

Please lauch Malwarebytes' ANti-Malware, allow it to update and run a Quick Scan. Post the resulting log in your reply.

 

 

 

 

 

 

Step 5

 

 

Please download shortcut cleaner and save it to your desktop.

 

 

Double-click on the ss-cleaner.exe file that should now be on your desktop

You will need to allow it to run when the prompt appears.

Shortcut Cleaner will now start and scan your computer for hijacked Windows shortcuts and if any are found it will automatically clean them for you. When it is done, it will show you a log that contains a list of shortcuts that were cleaned. Please copy/paste it into your reply.

 

 

etavares

Posted
Hello Etavares, everytime I get to Step 3 the OTL script won't run it says fix it says that it's not responding. Thank you.
Posted

Hello, debi239.

 

OK, please run this instead and we'll do it manually.

 

 

Download SystemLook from one of the links below and save it to your Desktop.

Download Mirror #1

Download Mirror #2

 

 

If you have a 64-bit system, please download the 64 bit version from here:

SystemLook (64-bit)

 

 

  • Double-click SystemLook.exe to run it.
  • A blank Windows shall open with the title "SystemLook v1.0-by Jpshortstuff".
  • Copy and Paste the content of the following codebox into the main textfield under "File":
    :reg
    HKLM\Software\Microsoft\Internet Explorer\ /s
    HKCU\Software\Microsoft\Internet Explorer /s
    HKLM\Software\Mozilla\Firefox\Extensions\ /s
    HKLM\Software\MozillaPlugins\ /s
    


  • Please Confirm everything is copied and Pasted as I have provided above
  • Click the Look button to start the scan.
  • When finished, a notepad window will open with the results of the scan.
  • Please post this log in your next reply.

 

 

Note: The log can also be found on your Desktop entitled SystemLook.txt

2nd Note: The scan may take a while from several seconds to a minute or more depending on the number of files you have and how fast your computer can perform the task

 

 

etavares

Posted

[HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\\Extension Compatibility\{00021a13-0000-0000-c000-000000000046}]

"BlockType"="0x1"

"Version"="0.0.0.0-11.65535.65535.65535"

"DllName"="visio.exe"

"CompatibilityFlags"="0x0"

[HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\\Extension Compatibility\{00021a14-0000-0000-c000-000000000046}]

"BlockType"="0x1"

"Version"="0.0.0.0-11.65535.65535.65535"

"DllName"="visio.exe"

"CompatibilityFlags"="0x0"

[HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\\Extension Compatibility\{053017A8-53F7-4EA3-AA38-A4CCAAF1F9E7}]

"FWLink"="http://go.microsoft.com/fwlink/?LinkId=72976"

"BlockType"="0x06"

"Version"="0-2.0.0.7751"

"DllName"="PluckExplorerBar.dll"

"CompatibilityFlags"="0x00"

[HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\\Extension Compatibility\{053F9267-DC04-4294-A72C-58F732D338C0}]

"FWLink"="http://go.microsoft.com/fwlink/?LinkId=124993"

"BlockType"="0x02"

"Version"="0.0.0.0-2.15.9.0"

"DllName"="hpswp_framework.dll"

"CompatibilityFlags"="0x00"

[HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\\Extension Compatibility\{06E58E5E-F8CB-4049-991E-A41C03BD419E}]

"FWLink"="http://go.microsoft.com/fwlink/?LinkId=148101"

"BlockType"="0x02"

"Version"="2.4.1.9"

"DllName"="upromisetoolbar.dll"

"CompatibilityFlags"="0x00"

Posted

[HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\\Extension Compatibility\{09AF76DD-6988-4664-97D0-362F1011E311}]

"BlockType"="0x06"

"Version"="0-2.0.0.7751"

"DllName"="PluckExplorerBar.dll"

"CompatibilityFlags"="0x00"

"MasterCLSID"="{053017A8-53F7-4EA3-AA38-A4CCAAF1F9E7}"

[HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\\Extension Compatibility\{11359F4A-B191-42D7-905A-594F8CF0387B}]

"FWLink"="http://go.microsoft.com/fwlink/?LinkId=71073"

"BlockType"="0x05"

"Version"="0-1.2.0.1"

"DllName"="lexbar.dll"

"CompatibilityFlags"="0x00"

[HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\\Extension Compatibility\{14CEEAFF-96DD-4101-AE37-D5ECDC23C3F6}]

"FWLink"="http://go.microsoft.com/fwlink/?LinkId=199443"

"BlockType"="0x40"

"Version"="2.5.12000.509"

"DllName"="alotBHO.dll"

"CompatibilityFlags"="0x00"

"MasterCLSID"="{5AA2BA46-9913-4DC7-9620-69AB0FA17AE7}"

[HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\\Extension Compatibility\{179E4A98-A3C4-407D-8C66-E63B67BB6F4A}]

"BlockType"="0x02"

"Version"="0-1.0.0.1"

"DllName"="mojibho.dll"

"CompatibilityFlags"="0x00"

"MasterCLSID"="{BF09613A-4564-4936-B6BB-B23B1D3D4FD7}"

[HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\\Extension Compatibility\{22BF413B-C6D2-4D91-82A9-A0F997BA588C}]

"FWLink"="http://go.microsoft.com/fwlink/?LinkId=124997"

"BlockType"="0x01;0x11"

"Version"="0-2.2.0.181;2.2.0.182-2.2.0.205"

"DllName"="SkypeIEPlugin.dll;SkypeIEPlugin.dll"

"CompatibilityFlags"="0x00;0x00"

[HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\\Extension Compatibility\{22D8E815-4A5E-4DFB-845E-AAB64207F5BD}]

"BlockType"="0x05"

"Version"="0-2.3999.9999.9999"

"DllName"="eBayTB.dll"

"CompatibilityFlags"="0x00"

"MasterCLSID"="{92085AD4-F48A-450D-BD93-B28CC7DF67CE}"

[HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\\Extension Compatibility\{22FC6CE8-7D47-479F-B74A-BFBB04ADB9AF}]

"FWLink"="http://go.microsoft.com/fwlink/?LinkId=148102"

"BlockType"="0x02"

"Version"="2008.1.0.1"

"DllName"="PCCBHO.dll"

"CompatibilityFlags"="0x00"

[HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\\Extension Compatibility\{2318C2B1-4965-11D4-9B18-009027A5CD4F}]

"FWLink"="http://go.microsoft.com/fwlink/?LinkId=124995"

"BlockType"="0x02;0x02;0x05;0x02;0x02;0x02;0x02"

"Version"="2.0.114.10;3.0.131.0;4.0.513.2948;4.0.1020.6156;4.0.1602.12068;5.0.1112.3348;5.0.1112.7760"

"DllName"="googletoolbar*.dll;googletoolbar*.dll;googletoolbar*.dll;googletoolbar*.dll;googletoolbar*.dll;googletoolbar*.dll;googletoolbar*.dll"

"CompatibilityFlags"="0x00;0x00;0x00;0x00;0x00;0x00;0x00"

[HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\\Extension Compatibility\{238F6F83-B8B4-11CF-8771-00A024541EE3}]

"FWLink"="http://www.citrix.com/downloadclients"

"BlockType"="0x2"

"Version"="0.0.0.0-9.150.39151.0"

"DllName"="Wfica.ocx"

"CompatibilityFlags"="0x0"

[HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\\Extension Compatibility\{2E5E800E-6AC0-411E-940A-369530A35E43}]

"FWLink"="http://go.microsoft.com/fwlink/?LinkID=142880"

"BlockType"="0x02"

"Version"="0-2.0.0.1"

"DllName"="TwcToolbarIe7.dll"

"CompatibilityFlags"="0x00"

[HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\\Extension Compatibility\{2F039DED-D55D-436B-ABF6-28D343C1F9E2}]

"BlockType"="0x02"

"Version"="0-1.0.0.4"

"DllName"="logos_ie.dll"

"CompatibilityFlags"="0x00"

"MasterCLSID"="{C94158E1-6151-4442-ABE6-FD53D6534CCB}"

[HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\\Extension Compatibility\{31CF9EBE-5755-4A1D-AC25-2834D952D9B4}]

"FWLink"="http://go.microsoft.com/fwlink/?LinkID=142881"

"BlockType"="0x02"

"Version"="0.0.0.0-3.3.0.1"

"DllName"="PDFCreator_Toolbar.dll"

"CompatibilityFlags"="0x00"

[HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\\Extension Compatibility\{387EDF53-1CF2-4523-BC2F-13462651BE8C}]

"FWLink"="http://go.microsoft.com/fwlink/?LinkId=71086"

"BlockType"="0x02"

"Version"="0-3.7.0.0"

"DllName"="BhoCitUS.dll"

"CompatibilityFlags"="0x00"

[HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\\Extension Compatibility\{3CA2F312-6F6E-4B53-A66E-4E65E497C8C0}]

"FWLink"="http://go.microsoft.com/fwlink/?LinkID=144284"

"BlockType"="0x12"

"Version"="8.0.0.101-8.0.0.184"

"DllName"="avgssie.dll"

"CompatibilityFlags"="0x00"

[HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\\Extension Compatibility\{3EB9C349-7473-48AC-A59B-42F31751974B}]

"FWLink"="http://go.microsoft.com/fwlink/?LinkId=71085"

"BlockType"="0x06"

"Version"="0-3.0.0.0"

"DllName"="TomahawkBar.dll"

"CompatibilityFlags"="0x00"

[HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\\Extension Compatibility\{43D9E6F0-1776-4897-AE14-ECEDECBAFEC0}]

"FWLink"="http://go.microsoft.com/fwlink/?LinkId=71084"

"BlockType"="0x02;0x02"

"Version"="0-3.0.16208.959;0-3.0.16208.959"

"DllName"="askbarAB.dll;askbarAC.dll"

"CompatibilityFlags"="0x00;0x00"

[HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\\Extension Compatibility\{48FFE35F-36D9-44bd-A6CC-1D34414EAC0D}]

"FWLink"="http://go.microsoft.com/fwlink/?LinkID=108474"

"BlockType"="0x20"

"Version"="0-1.0.2188.0"

"DllName"="IEDevToolbar.dll"

"CompatibilityFlags"="0x00"

"MasterCLSID"="{CC7E636D-39AA-49B6-B511-65413DA137A1}"

[HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\\Extension Compatibility\{4A5BE5EE-CFAD-11D9-8FAD-0007E9AA247E}]

"FWLink"="http://go.microsoft.com/fwlink/?LinkId=71094"

"BlockType"="0x05"

"Version"="0-1.0.0.1"

"DllName"="RSS.dll"

"CompatibilityFlags"="0x00"

[HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\\Extension Compatibility\{4E7BD74F-2B8D-469E-8CB2-BC60BB9AAE22}]

"FWLink"="http://go.microsoft.com/fwlink/?LinkId=71093"

"BlockType"="0x02"

"Version"="0-4.0.1.26"

"DllName"="aml_toolbar.dll"

"CompatibilityFlags"="0x00"

[HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\\Extension Compatibility\{4E7BD74F-2B8D-469E-99FF-FD60BB9AAE2D}]

"FWLink"="http://go.microsoft.com/fwlink/?LinkId=71087"

"BlockType"="0x02"

"Version"="0-4.0.1.113"

"DllName"="YPTOOLBAR.DLL"

"CompatibilityFlags"="0x00"

[HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\\Extension Compatibility\{57F02779-3D88-4958-8AD3-83C12D86ADC7}]

"FWLink"="http://go.microsoft.com/fwlink/?LinkId=71088"

"BlockType"="0x06"

"Version"="0-2.0.0.0"

"DllName"="advancedsearchbar.dll"

"CompatibilityFlags"="0x00"

[HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\\Extension Compatibility\{5A074B21-F830-49DE-A31B-5BB9D7F6B407}]

"BlockType"="0x02;0x02"

"Version"="0-4.0.1.3;0-3.1.1.0"

"DllName"="askBar.dll;ajBar.dll"

"CompatibilityFlags"="0x00;0x00"

"MasterCLSID"="{5A074B29-F830-49DE-A31B-5BB9D7F6B407}"

[HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\\Extension Compatibility\{5A074B29-F830-49DE-A31B-5BB9D7F6B407}]

"FWLink"="http://go.microsoft.com/fwlink/?LinkId=71084"

"BlockType"="0x02;0x02"

"Version"="0-4.0.1.3;0-3.1.1.0"

"DllName"="askBar.dll;ajBar.dll"

"CompatibilityFlags"="0x00;0x00"

[HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\\Extension Compatibility\{5AA2BA46-9913-4DC7-9620-69AB0FA17AE7}]

"FWLink"="http://go.microsoft.com/fwlink/?LinkId=199443"

"BlockType"="0x40"

"Version"="2.5.12000.509"

"DllName"="alot.dll"

"CompatibilityFlags"="0x00"

[HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\\Extension Compatibility\{5CA3D70E-1895-11CF-8E15-001234567890}]

"FWLink"="http://go.microsoft.com/fwlink/?LinkId=124996"

"BlockType"="0x02"

"Version"="1-5.9999.9999.9999"

"DllName"="*"

"CompatibilityFlags"="0x00"

[HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\\Extension Compatibility\{64818d10-4f9b-11cf-86ea-00aa00b929e8}]

"BlockType"="0x1"

"Version"="0.0.0.0-11.65535.65535.65535"

"DllName"="powerpnt.exe"

"CompatibilityFlags"="0x0"

[HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\\Extension Compatibility\{69ABB8E4-3A44-461C-93BC-C3BB6BDF2DF3}]

"FWLink"="http://go.microsoft.com/fwlink/?LinkId=194205"

"BlockType"="0x40"

"Version"="1.1.0.0"

"DllName"="Backcountry.com.Steepandcheap.Toolbar.dll"

"CompatibilityFlags"="0x00"

"MasterCLSID"="{F98BA7F6-48D8-4CE7-A8D0-39D13FD6F14F}"

[HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\\Extension Compatibility\{724D43A0-0D85-11D4-9908-00400523E39A}]

"FWLink"="http://go.microsoft.com/fwlink/?LinkId=71075"

"BlockType"="0x06"

"Version"="0-6.6.5"

"DllName"="roboform.dll"

"CompatibilityFlags"="0x00"

[HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\\Extension Compatibility\{724D43A9-0D85-11D4-9908-00400523E39A}]

"BlockType"="0x06"

"Version"="0-6.6.5"

"DllName"="roboform.dll"

"CompatibilityFlags"="0x00"

"MasterCLSID"="{724D43A0-0D85-11D4-9908-00400523E39A}"

[HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\\Extension Compatibility\{777D0B4C-75C9-4874-ABFF-80B4BE8DC532}]

"FWLink"="http://go.microsoft.com/fwlink/?LinkId=71078"

"BlockType"="0x05"

"Version"="0-2.4.0.3"

"DllName"="IEBand2.dll"

"CompatibilityFlags"="0x00"

[HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\\Extension Compatibility\{77BF5300-1474-4EC7-9980-D32B190E9B07}]

"FWLink"="http://go.microsoft.com/fwlink/?LinkId=124997"

"BlockType"="0x01;0x11"

"Version"="0-2.2.0.181;2.2.0.182-2.2.0.205"

"DllName"="SkypeIEPlugin.dll;SkypeIEPlugin.dll"

"CompatibilityFlags"="0x00;0x00"

[HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\\Extension Compatibility\{77FEF28E-EB96-44FF-B511-3185DEA48697}]

"BlockType"="0x00;0x40;0x40;0x40"

"Version"="*;2.0.5.32;2.0.6.10;2.0.6.12"

"DllName"="baidubar.dll;BaiduBarX.dll;BaiduBarX.dll;BaiduBarX.dll"

"CompatibilityFlags"="0x80000000;0x00;0x00;0x00"

"MasterCLSID"="{B580CF65-E151-49C3-B73F-70B13FCA8E86}"

"FWLink"="http://go.microsoft.com/fwlink/?LinkId=166124"

[HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\\Extension Compatibility\{79CEEA4E-C231-4614-9E3B-53B2A02F39B7}]

"FWLink"="http://go.microsoft.com/fwlink/?LinkId=194273"

"BlockType"="0x40"

"Version"="1.0.0.9"

"DllName"="comcastdx.dll"

"CompatibilityFlags"="0x00"

[HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\\Extension Compatibility\{855F3B16-6D32-4FE6-8A56-BBB695989046}]

"FWLink"="http://go.microsoft.com/fwlink/?LinkId=71098"

"BlockType"="0x06"

"Version"="0-1.0.10.20"

"DllName"="toolbaru.dll"

"CompatibilityFlags"="0x00"

[HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\\Extension Compatibility\{8B4F961F-0B84-4201-BBB1-34E45368F39E}]

"BlockType"="0x02"

"Version"="0-1.0.0.4"

"DllName"="adelphia.dll"

"CompatibilityFlags"="0x00"

"MasterCLSID"="{E5E2F8B2-79A4-495C-8581-90BA2C845CC2}"

[HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\\Extension Compatibility\{8E929F51-5914-11D6-971F-0050FC3F9161}]

"FWLink"="http://go.microsoft.com/fwlink/?LinkID=73332"

"BlockType"="0x05"

"Version"="0-1.2.0.4"

"DllName"="Pictures.dll"

"CompatibilityFlags"="0x00"

[HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\\Extension Compatibility\{9030D464-4C02-4ABF-8ECC-5164760863C6}]

"FWLink"="http://go.microsoft.com/fwlink/?LinkID=142882"

"BlockType"="0x20"

"Version"="0.0.0.0-5.0.817.0"

"DllName"="WindowsLiveLogin.dll"

"CompatibilityFlags"="0x00"

[HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\\Extension Compatibility\{91397D20-1446-11D4-8AF4-0040CA1127B6}]

"FWLink"="http://go.microsoft.com/fwlink/?LinkId=194275"

"BlockType"="0x40;0x40"

"Version"="4.4.0.1048;5.0.3.1147"

"DllName"="yndbar.dll;yndbar.dll"

"CompatibilityFlags"="0x00;0x00"

Posted

[HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\\Extension Compatibility\{92085AD4-F48A-450D-BD93-B28CC7DF67CE}]

"FWLink"="http://go.microsoft.com/fwlink/?LinkId=71081"

"BlockType"="0x05"

"Version"="0-2.3999.9999.9999"

"DllName"="eBayTB.dll"

"CompatibilityFlags"="0x00"

[HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\\Extension Compatibility\{9394EDE7-C8B5-483E-8773-474BF36AF6E4}]

"BlockType"="0x01"

"Version"="0-1.2.5000.1021"

"DllName"="stmain.dll"

"CompatibilityFlags"="0x00"

"MasterCLSID"="{BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0}"

[HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\\Extension Compatibility\{A202B231-EF71-4A08-BDB9-4CE5AE8BDE0A}]

"FWLink"="http://go.microsoft.com/fwlink/?LinkID=108474"

"BlockType"="0x20"

"Version"="0-1.0.2188.0"

"DllName"="IEDevToolbar.dll"

"CompatibilityFlags"="0x00"

"MasterCLSID"="{CC7E636D-39AA-49B6-B511-65413DA137A1}"

[HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\\Extension Compatibility\{A3BC75A2-1F87-4686-AA43-5347D756017C}]

"FWLink"="http://go.microsoft.com/fwlink/?LinkID=166122"

"BlockType"="0x40;0x40"

"Version"="4.504.19.2;4.906.30.2"

"DllName"="IEToolbar.dll;IEToolbar.dll"

"CompatibilityFlags"="0x00;0x00"

"MasterCLSID"="{CCC7A320-B3CA-4199-B1A6-9F516DD6982}"

[HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\\Extension Compatibility\{A411D7F4-8D11-43EF-BDE4-AA921666388A}]

"FWLink"="http://go.microsoft.com/fwlink/?LinkId=194274"

"BlockType"="0x40"

"Version"="5.0.0.4"

"DllName"="Quero.dll"

"CompatibilityFlags"="0x00"

[HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\\Extension Compatibility\{A986E409-30CC-4185-89BB-AB212C104524}]

"FWLink"="http://go.microsoft.com/fwlink/?LinkId=141062"

"BlockType"="0x02"

"Version"="1.0.0.24-1.0.0.27"

"DllName"="DownloaderManager.dll"

"CompatibilityFlags"="0x00"

[HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\\Extension Compatibility\{AA58ED58-01DD-4D91-8333-CF10577473F7}]

"BlockType"="0x02;0x02;0x05;0x02;0x02;0x02;0x02"

"Version"="2.0.114.10;3.0.131.0;4.0.513.2948;4.0.1020.6156;4.0.1602.12068;5.0.1112.3348;5.0.1112.7760"

"DllName"="googletoolbar*.dll;googletoolbar*.dll;googletoolbar*.dll;googletoolbar*.dll;googletoolbar*.dll;googletoolbar*.dll;googletoolbar*.dll"

"CompatibilityFlags"="0x00;0x00;0x00;0x00;0x00;0x00;0x00"

"MasterCLSID"="{2318C2B1-4965-11D4-9B18-009027A5CD4F}"

[HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\\Extension Compatibility\{B580CF65-E151-49C3-B73F-70B13FCA8E86}]

"BlockType"="0x00;0x40;0x40;0x40"

"Version"="*;2.0.5.32;2.0.6.10;2.0.6.12"

"DllName"="baidubar.dll;BaiduBarX.dll;BaiduBarX.dll;BaiduBarX.dll"

"CompatibilityFlags"="0x80000000;0x00;0x00;0x00"

"FWLink"="http://go.microsoft.com/fwlink/?LinkId=166124"

[HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\\Extension Compatibility\{BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0}]

"FWLink"="http://go.microsoft.com/fwlink/?LinkId=71067"

"BlockType"="0x01"

"Version"="0-1.2.5000.1021"

"DllName"="msntb.dll"

"CompatibilityFlags"="0x00"

[HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\\Extension Compatibility\{BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0}]

"BlockType"="0x01;0x00"

"Version"="0-1.2.5000.1021;0-4.0.0.0"

"DllName"="msntb.dll;msntb.dll"

"CompatibilityFlags"="0x00;0x80000000"

"MasterCLSID"="{BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0}"

[HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\\Extension Compatibility\{BF09613A-4564-4936-B6BB-B23B1D3D4FD7}]

"FWLink"="http://go.microsoft.com/fwlink/?LinkId=71090"

"BlockType"="0x02"

"Version"="0-1.0.0.1"

"DllName"="mojiie.dll"

"CompatibilityFlags"="0x00"

[HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\\Extension Compatibility\{BF8C499A-AC6E-4F58-82EA-9E5FCC41C34B}]

"BlockType"="0x00"

"Version"="0-1.0.1.2"

"DllName"="ppupload.dll"

"CompatibilityFlags"="0x80000000"

[HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\\Extension Compatibility\{C1D79200-7718-4656-A7B2-F23046E264E7}]

"FWLink"="http://go.microsoft.com/fwlink/?LinkId=71082"

"BlockType"="0x06"

"Version"="0-1.0.0.0"

"DllName"="insptbar.dll"

"CompatibilityFlags"="0x00"

[HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\\Extension Compatibility\{C451C08A-EC37-45DF-AAAD-18B51AB5E837}]

"FWLink"="http://go.microsoft.com/fwlink/?LinkID=142881"

"BlockType"="0x02"

"Version"="0.0.0.0-3.3.0.1"

"DllName"="PDFCreator_Toolbar.dll"

"CompatibilityFlags"="0x00"

"MasterCLSID"="{31CF9EBE-5755-4A1D-AC25-2834D952D9B4}"

[HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\\Extension Compatibility\{C94158E1-6151-4442-ABE6-FD53D6534CCB}]

"FWLink"="http://go.microsoft.com/fwlink/?LinkId=71091"

"BlockType"="0x02"

"Version"="0-1.0.0.4"

"DllName"="logos_ie.dll"

"CompatibilityFlags"="0x00"

[HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\\Extension Compatibility\{CC7E636D-39AA-49B6-B511-65413DA137A1}]

"BlockType"="0x20"

"Version"="0-1.0.2188.0"

"DllName"="IEDevToolbar.dll"

"CompatibilityFlags"="0x00"

"MasterCLSID"="{CC962137-2E78-4F94-975E-FC0C07DBD78F}"

[HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\\Extension Compatibility\{CC7E636D-39AA-49B6-B511-65413DA137A1}\Subcomponents]

"{48FFE35F-36D9-44bd-A6CC-1D34414EAC0D}"=""

"{A202B231-EF71-4A08-BDB9-4CE5AE8BDE0A}"=""

[HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\\Extension Compatibility\{CC962137-2E78-4F94-975E-FC0C07DBD78F}]

"FWLink"="http://go.microsoft.com/fwlink/?LinkId=71074"

"BlockType"="0x20"

"Version"="0-1.0.2188.0"

"DllName"="IEDevToolbar.dll"

"CompatibilityFlags"="0x00"

[HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\\Extension Compatibility\{CCC7A320-B3CA-4199-B1A6-9F516DD69829}]

"FWLink"="http://go.microsoft.com/fwlink/?LinkID=166122"

"BlockType"="0x40;0x40"

"Version"="4.504.19.2;4.906.30.2"

"DllName"="IEToolbar.dll;IEToolbar.dll"

"CompatibilityFlags"="0x00;0x00"

[HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\\Extension Compatibility\{CDEEC43D-3572-4E95-A2A5-F519D29F00C0}]

"BlockType"="0x06"

"Version"="0-2.0.0.0"

"DllName"="advancedsearchbar.dll"

"CompatibilityFlags"="0x00"

"MasterCLSID"="{57F02779-3D88-4958-8AD3-83C12D86ADC7}"

[HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\\Extension Compatibility\{CE000992-A58C-4441-8938-744CD72AB27F}]

"FWLink"="http://go.microsoft.com/fwlink/?LinkId=71070"

"BlockType"="0x01"

"Version"="0-4.2.1.0"

"DllName"="i-nav_4_2_1.dll"

"CompatibilityFlags"="0x00"

[HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\\Extension Compatibility\{DC99E960-6594-45E3-9D5D-141D825B8096}]

"FWLink"="http://go.microsoft.com/fwlink/?LinkId=71077"

"BlockType"="0x01"

"Version"="0-1.1.0.5"

"DllName"="PrvcBand.dll"

"CompatibilityFlags"="0x00"

[HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\\Extension Compatibility\{DCC70A83-E184-40A3-906B-779AF5E941C4}]

"FWLink"="http://go.microsoft.com/fwlink/?LinkId=194276"

"BlockType"="0x40"

"Version"="1.0.0.14"

"DllName"="xfinitydx.dll"

"CompatibilityFlags"="0x00"

[HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\\Extension Compatibility\{E5E2F8B2-79A4-495C-8581-90BA2C845CC2}]

"FWLink"="http://go.microsoft.com/fwlink/?LinkId=71092"

"BlockType"="0x02"

"Version"="0-1.0.0.4"

"DllName"="adelphia.dll"

"CompatibilityFlags"="0x00"

[HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\\Extension Compatibility\{E97B5F2E-CA8E-4D34-BDA3-44EEC4ED2B12}]

"FWLink"="http://go.microsoft.com/fwlink/?LinkId=194271"

"BlockType"="0x40"

"Version"="3.3.317.0"

"DllName"="ToolbarContainer101000317.dll"

"CompatibilityFlags"="0x00"

[HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\\Extension Compatibility\{EAEE5C74-6D0D-4ACA-9232-0DA4A7B866BA}]

"FWLink"="http://go.microsoft.com/fwlink/?LinkID=142956"

"BlockType"="0x02"

"Version"="1.8.0.4272"

"DllName"="piclens.dll"

"CompatibilityFlags"="0x00"

[HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\\Extension Compatibility\{EDC0F17F-F4B7-47E4-B73E-887FAEB376FA}]

"FWLink"="http://go.microsoft.com/fwlink/?LinkId=148101"

"BlockType"="0x02"

"Version"="2.4.1.9"

"DllName"="upromisetoolbar.dll"

"CompatibilityFlags"="0x00"

"MasterCLSID"="{06E58E5E-F8CB-4049-991E-A41C03BD419E}"

[HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\\Extension Compatibility\{EF99BD32-C1FB-11D2-892F-0090271D4F88}]

"BlockType"="0x0;0x0;0x0;0x0;0x0;0x0;0x0;0x0"

"Version"="0.0.0-6.3.4;0.0.0-6.2.3;6.0-6.5;0.0.0-6.2.3;0.0.0-6.2.3;0.0.0-6.2.3;0.0.0-6.2.3;0.0.0-6.2.3"

"DllName"="yt.dll;yt.dll;yt.dll;ycomp5_5_5_0.dll;ycomp5_5_7_0.dll;ycomp5_5_9_1.dll;ycomp5_6_0_0.dll;ycomp5_6_2_0.dll"

"CompatibilityFlags"="0x08;0x06;0x01;0x06;0x06;0x06;0x06;0x06"

[HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\\Extension Compatibility\{F98BA7F6-48D8-4CE7-A8D0-39D13FD6F14F}]

"FWLink"="http://go.microsoft.com/fwlink/?LinkId=194205"

"BlockType"="0x40"

"Version"="1.1.0.0"

"DllName"="Backcountry.com.Steepandcheap.Toolbar.dll"

"CompatibilityFlags"="0x00"

[HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\\Extension Compatibility\{FFFFFFFF-CF4E-4F2B-BDC2-0E72E116A856}]

"FWLink"="http://go.microsoft.com/fwlink/?LinkId=124993"

"BlockType"="0x02"

"Version"="100.0.0.0-110.0.19060.0"

"DllName"="hpswp_BHO.dll"

"CompatibilityFlags"="0x00"

[HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\\Extension Compatibility\{FFFFFFFF-FF12-44C5-91EC-068E3AA1B2D7}]

"FWLink"="http://go.microsoft.com/fwlink/?LinkId=124993"

"BlockType"="0x02"

"Version"="3.0.0.0-3.0.17.0"

"DllName"="hpswp_framework.dll"

"CompatibilityFlags"="0x00"

[HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\\Extensions]

(No values found)

[HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\\Extensions\{88CFA58B-A63F-4A94-9C54-0C7A58E3333E}]

"ButtonText"="Add to VideoGet"

"ClsidExtension"="{17A84966-F1E9-4645-AA9E-5E771EE1C859}"

"CLSID"="{1FBA04EE-3024-11d2-8F1F-0000F87ABD16}"

"Default Visible"="Yes"

"Icon"="C:\Program Files (x86)\Nuclear Coffee\VideoGet\VideoGet.ico"

"HotIcon"="C:\Program Files (x86)\Nuclear Coffee\VideoGet\VideoGet.ico"

"MenuText"="Add to &VideoGet"

[HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\\Feed Discovery]

"Type1"="application/atom+xml"

"Type0"="application/rss+xml"

[HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\\Image Caching]

"Number"=04 00 00 00 (REG_BINARY)

[HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\\InformationCard Token Provider]

@="{D978F0CB-DEBA-4388-83BE-D3E106E02A4F}"

[HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\\LinksBar]

"Enabled"= 0x0000000001 (1)

[HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\\Low Rights]

"DefaultElevationPolicy"= 0x0000000002 (2)

[HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\\Low Rights\DragDrop]

(No values found)

[HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\\Low Rights\DragDrop\{0002df01-0000-0000-c000-000000000046}]

"Policy"= 0x0000000003 (3)

"AppPath"="C:\Program Files\Internet Explorer"

"AppName"="iexplore.exe"

[HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\\Low Rights\DragDrop\{20D04FE0-3AEA-1069-A2D8-08002B30309D}]

"Policy"= 0x0000000003 (3)

"AppPath"="C:\Windows"

"AppName"="explorer.exe"

[HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\\Low Rights\DragDrop\{4becf16c-74f0-429b-8d3e-4fba507ac661}]

"Policy"= 0x0000000003 (3)

"AppPath"="C:\Program Files (x86)\adobe\acrobat 7.0\reader"

"AppName"="acrord32.exe"

[HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\\Low Rights\DragDrop\{95a4104c-1c49-4c2a-9830-1be0f47e926c}]

"Policy"= 0x0000000003 (3)

"AppPath"="C:\Program Files (x86)\adobe\acrobat 7.0\Acrobat"

"AppName"="acrobat.exe"

[HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\\Low Rights\DragDrop\{9da1d2cb-796d-4bec-bbaa-0aa9ccd80e15}]

"Policy"= 0x0000000003 (3)

"AppPath"="C:\Program Files (x86)\adobe\acrobat 7.0\Acrobat Elements"

"AppName"="Acrobat Elements.exe"

[HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\\Low Rights\DragDrop\{f1804479-982b-479f-95eb-c6972fb8c767}]

"Policy"= 0x0000000003 (3)

"AppPath"="C:\Program Files (x86)\adobe\acrobat 6.0\reader"

"AppName"="acrord32.exe"

[HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\\Low Rights\DragDrop\{F41E8255-3897-4cf4-AEC7-4F85171A0B3C}]

"Policy"= 0x0000000003 (3)

"AppPath"="C:\Windows\System32"

"AppName"="notepad.exe"

[HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\\Low Rights\ElevationPolicy]

(No values found)

[HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\\Low Rights\ElevationPolicy\{0002df01-0000-0000-c000-000000000046}]

"Policy"= 0x0000000003 (3)

"AppPath"="C:\Program Files\Internet Explorer"

"AppName"="iexplore.exe"

"IID"="{9B61C454-C2A2-4685-8885-9752F9A3F28F}"

[HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\\Low Rights\ElevationPolicy\{054aae20-4bea-4347-8a35-64a533254a9d}]

"Policy"= 0x0000000001 (1)

"AppPath"="C:\Program Files\Common Files\Microsoft Shared\Ink"

"AppName"="tabtip.exe"

[HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\\Low Rights\ElevationPolicy\{07d873dc-b9b9-44f5-af0b-fb59fa54fb7a}]

"Policy"= 0x0000000003 (3)

"AppPath"="C:\Windows\System32"

"AppName"="wpcer.exe"

[HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\\Low Rights\ElevationPolicy\{08f24d68-9087-4b24-81ad-7b34af3e3ed5}]

"Policy"= 0x0000000003 (3)

"AppPath"="C:\Program Files (x86)\adobe\acrobat 6.0\Acrobat Elements"

"AppName"="Acrobat Elements.exe"

[HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\\Low Rights\ElevationPolicy\{0a402d70-1f10-4ae7-bec9-286a98240695}]

"Policy"= 0x0000000003 (3)

"AppPath"="C:\Windows\System32"

"AppName"="winfxdocobj.exe"

[HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\\Low Rights\ElevationPolicy\{1138506a-b949-46a7-b6c0-ee26499fdeaf}]

"Policy"= 0x0000000003 (3)

"AppPath"="C:\Windows\System32"

"AppName"="wuapp.exe"

[HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\\Low Rights\ElevationPolicy\{130c40f0-1bcb-4852-8b63-291cf90a600b}]

"Policy"= 0x0000000003 (3)

"AppPath"="C:\Windows\System32"

"AppName"="msdt.exe"

[HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\\Low Rights\ElevationPolicy\{186e0934-aee9-11da-961b-0014223d2a70}]

"Policy"= 0x0000000003 (3)

"AppPath"="C:\Windows\microsoft.net\framework64\v2.0.50727"

"AppName"="dfsvc.exe"

[HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\\Low Rights\ElevationPolicy\{186e0935-aee9-11da-961b-0014223d2a70}]

"Policy"= 0x0000000003 (3)

"AppPath"="C:\Windows\microsoft.net\framework64\v2.0.50727"

"AppName"="dfsvc.exe"

[HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\\Low Rights\ElevationPolicy\{1A972DAF-A7EC-4ce3-B6C9-7B523CD6685F}]

"AppName"="GoogleToolbarUser_32.exe"

"AppPath"="C:\Program Files (x86)\Google\Google Toolbar"

"Policy"= 0x0000000003 (3)

[HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\\Low Rights\ElevationPolicy\{1F1E561D-AF17-4510-B996-351BBA0862A7}]

"CLSID"="{20FD4E26-8E0F-4F73-A0E0-F27B8C57BE6F}"

"Policy"= 0x0000000003 (3)

[HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\\Low Rights\ElevationPolicy\{2391d819-9d17-44ec-9ac1-f6aa07549469}]

"Policy"= 0x0000000003 (3)

"AppPath"="%systemroot%\system32"

"AppName"="wermgr.exe"

"IID"="{aa586b2c-26ee-491f-955d-3dd0ac95c45b}"

[HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\\Low Rights\ElevationPolicy\{26fe7361-bd5a-4dcb-b309-c6f42dde661c}]

"Policy"= 0x0000000001 (1)

"AppPath"="C:\Program Files\Internet Explorer"

"AppName"="ieinstal.exe"

[HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\\Low Rights\ElevationPolicy\{4becf16c-74f0-429b-8d3e-4fba507ac661}]

"Policy"= 0x0000000003 (3)

"AppPath"="C:\Program Files (x86)\adobe\acrobat 7.0\reader"

"AppName"="acrord32.exe"

[HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\\Low Rights\ElevationPolicy\{6bf52a52-394a-11d3-b153-00c04f79faa6}]

"Policy"= 0x0000000003 (3)

"AppPath"="%ProgramFiles%\Windows Media Player"

"AppName"="wmplayer.exe"

[HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\\Low Rights\ElevationPolicy\{6bf52a52-394a-11d3-b153-00c04f79faa6}-32]

"Policy"= 0x0000000003 (3)

"AppPath"="%ProgramFiles(x86)%\Windows Media Player"

"AppName"="wmplayer.exe"

[HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\\Low Rights\ElevationPolicy\{70f641fd-9ffc-4d5b-a4dc-962af4ed7999}]

"Policy"= 0x0000000001 (1)

"AppPath"="C:\Program Files\Internet Explorer"

"AppName"="iedw.exe"

[HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\\Low Rights\ElevationPolicy\{78c7b664-c9bf-4ce9-8b3a-b05d442e451e}]

"Policy"= 0x0000000003 (3)

"AppName"="CertEnrollCtrl.exe"

"AppPath"="C:\Windows\system32\"

[HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\\Low Rights\ElevationPolicy\{7aaae723-5fb5-4b2d-9327-75519f336825}]

"Policy"= 0x0000000003 (3)

"CLSID"="{33246F92-D56F-4E34-837A-9A49BFC91DF3}"

[HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\\Low Rights\ElevationPolicy\{7eb01fb2-f185-445a-94e4-ec4e1ba2202c}]

"Policy"= 0x0000000001 (1)

"AppPath"="C:\Windows\System32"

"AppName"="verclsid.exe"

[HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\\Low Rights\ElevationPolicy\{80B84A0A-EDA4-47fd-8BE1-6B49F4197EE5}]

"AppName"="GoogleToolbarNotifier.exe"

"AppPath"="C:\Program Files (x86)\Google\GoogleToolbarNotifier"

"Policy"= 0x0000000003 (3)

[HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\\Low Rights\ElevationPolicy\{85fc331e-bb64-4c53-ba25-3d8a956c02fd}]

"Policy"= 0x0000000003 (3)

"AppPath"="C:\Windows\System32"

"AppName"="ctfmon.exe"

[HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\\Low Rights\ElevationPolicy\{86300DD7-B136-40d9-823C-22EBD55D7858}]

"AppName"="Snagit32.exe"

"AppPath"="C:\Program Files (x86)\TechSmith\Snagit 10"

"Policy"= 0x0000000003 (3)

[HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\\Low Rights\ElevationPolicy\{8cec58ae-07a1-11d9-b15e-000d56bfe6ee}]

"Policy"= 0x0000000003 (3)

"AppPath"="C:\Windows"

"AppName"="helppane.exe"

[HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\\Low Rights\ElevationPolicy\{95a4104c-1c49-4c2a-9830-1be0f47e926c}]

"Policy"= 0x0000000003 (3)

"AppPath"="C:\Program Files (x86)\adobe\acrobat 7.0\Acrobat"

"AppName"="acrobat.exe"

[HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\\Low Rights\ElevationPolicy\{9da1d2cb-796d-4bec-bbaa-0aa9ccd80e15}]

"Policy"= 0x0000000003 (3)

"AppPath"="C:\Program Files (x86)\adobe\acrobat 7.0\Acrobat Elements"

"AppName"="Acrobat Elements.exe"

[HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\\Low Rights\ElevationPolicy\{a5a2d52a-4944-47c4-a3e0-8bd92e14d953}]

"Policy"= 0x0000000003 (3)

"AppPath"="C:\Windows\SysWOW64\xpsviewer"

"AppName"="xpsviewer.exe"

[HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\\Low Rights\ElevationPolicy\{A5B020FD-E04B-4e67-B65A-E7DEED25B2CF}]

"Policy"= 0x0000000001 (1)

"AppPath"="%SystemRoot%\System32"

"AppName"="wisptis.exe"

[HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\\Low Rights\ElevationPolicy\{aff735eb-cdf9-4894-aa69-3e3131128618}]

"Policy"= 0x0000000000 (0)

"AppPath"="C:\Windows\System32"

"AppName"="cmd.exe"

[HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\\Low Rights\ElevationPolicy\{B43A0C1E-B63F-4691-B68F-CD807A45DA01}]

"AppName"="TSWbPrxy.exe"

"Policy"= 0x0000000003 (3)

"AppPath"="%systemroot%\system32"

[HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\\Low Rights\ElevationPolicy\{BD18A03F-31CC-4CC0-B52D-9E199122923D}]

"Policy"= 0x0000000003 (3)

"CLSID"="{6B9228DA-9C15-419e-856C-19E768A13BDC}"

[HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\\Low Rights\ElevationPolicy\{C8999AEC-AECE-4E27-9BCB-5358B13F9FF9}]

"AppName"="dfsvc.exe"

"AppPath"="C:\Windows\Microsoft.NET\Framework\v4.0.30319\"

"Policy"= 0x0000000003 (3)

[HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\\Low Rights\ElevationPolicy\{C8999AED-AECE-4E27-9BCB-5358B13F9FF9}]

"AppName"="dfsvc.exe"

"AppPath"="C:\Windows\Microsoft.NET\Framework64\v4.0.30319\"

"Policy"= 0x0000000003 (3)

[HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\\Low Rights\ElevationPolicy\{dc6bf185-7ae4-444e-8c35-e447b0d2bd1e}]

"Policy"= 0x0000000003 (3)

"AppPath"="C:\Windows\System32"

"AppName"="notepad.exe"

[HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\\Low Rights\ElevationPolicy\{e5f90a07-7db7-4dcb-bd6d-d3fecd376ca3}]

"Policy"= 0x0000000003 (3)

"AppPath"="C:\Program Files (x86)\adobe\acrobat 6.0\reader"

"AppName"="acrord32.exe"

[HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\\Low Rights\ElevationPolicy\{EE0B94B9-335F-4d2c-8B43-DACCD1EA6FF1}]

"AppName"="GoogleToolbarUser_64.exe"

"AppPath"="C:\Program Files (x86)\Google\Google Toolbar"

"Policy"= 0x0000000003 (3)

[HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\\Low Rights\ElevationPolicy\{eee261cc-4b3e-46e7-affb-61f297155bf2}]

"Policy"= 0x0000000003 (3)

"AppPath"="C:\Windows\System32"

"AppName"="presentationhost.exe"

[HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\\Low Rights\ElevationPolicy\{FAF199D2-BFA7-4394-A4DE-044A08E59B32}]

"Policy"= 0x0000000003 (3)

"AppPath"="C:\Windows\system32\Macromed\Flash"

"AppName"="FlashUtil64_11_5_502_146_ActiveX.exe"

[HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\\Low Rights\ElevationPolicy\{fb9e068b-c612-4fa8-bdb9-d728a716a420}]

"Policy"= 0x0000000003 (3)

"AppPath"="C:\Program Files (x86)\adobe\acrobat 6.0\Acrobat"

"AppName"="acrobat.exe"

[HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\\Low Rights\RunDLl32Policy]

(No values found)

[HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\\Low Rights\RunDLl32Policy\cnmsm47.dll]

(No values found)

[HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\\Low Rights\RunDLl32Policy\cnmsm48.dll]

(No values found)

[HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\\Low Rights\RunDLl32Policy\cnmsm49.dll]

(No values found)

[HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\\Low Rights\RunDLl32Policy\cnmsm4a.dll]

(No values found)

[HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\\Low Rights\RunDLl32Policy\cnmsm4b.dll]

(No values found)

[HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\\Low Rights\RunDLl32Policy\cnmsm4c.dll]

(No values found)

[HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\\Low Rights\RunDLl32Policy\cnmsm4o.dll]

(No values found)

[HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\\Low Rights\RunDLl32Policy\cnmsm4p.dll]

(No values found)

[HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\\Low Rights\RunDLl32Policy\cnmsm4s.dll]

(No values found)

[HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\\Low Rights\RunDLl32Policy\cnmsm4t.dll]

(No values found)

[HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\\Low Rights\RunDLl32Policy\cnmsm4u.dll]

(No values found)

[HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\\Low Rights\RunDLl32Policy\cnmsm4v.dll]

(No values found)

[HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\\Low Rights\RunDLl32Policy\cnmsm4w.dll]

(No values found)

[HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\\Low Rights\RunDLl32Policy\cnmsm4x.dll]

(No values found)

[HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\\Low Rights\RunDLl32Policy\cnmsm4y.dll]

(No values found)

[HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\\Low Rights\RunDLl32Policy\cnmsm4z.dll]

(No values found)

[HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\\Low Rights\RunDLl32Policy\cnmsm50.dll]

(No values found)

[HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\\Low Rights\RunDLl32Policy\cnmsm52.dll]

(No values found)

[HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\\Low Rights\RunDLl32Policy\cnmsm53.dll]

(No values found)

[HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\\Low Rights\RunDLl32Policy\cnmsm55.dll]

(No values found)

[HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\\Low Rights\RunDLl32Policy\cnmsm56.dll]

(No values found)

[HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\\Low Rights\RunDLl32Policy\cnmsm57.dll]

(No values found)

[HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\\Low Rights\RunDLl32Policy\cnmsm58.dll]

(No values found)

[HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\\Low Rights\RunDLl32Policy\cnmsm59.dll]

(No values found)

[HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\\Low Rights\RunDLl32Policy\cnmsm5a.dll]

(No values found)

[HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\\Low Rights\RunDLl32Policy\cnmsm5b.dll]

(No values found)

[HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\\Low Rights\RunDLl32Policy\cnmsm5c.dll]

(No values found)

[HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\\Low Rights\RunDLl32Policy\cnmsm5d.dll]

(No values found)

[HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\\Low Rights\RunDLl32Policy\cnmsm5i.dll]

(No values found)

[HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\\Low Rights\RunDLl32Policy\cnmsm5j.dll]

(No values found)

[HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\\Low Rights\RunDLl32Policy\cnmsm5k.dll]

(No values found)

[HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\\Low Rights\RunDLl32Policy\cnmsm5l.dll]

(No values found)

[HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\\Low Rights\RunDLl32Policy\cnmsm5m.dll]

(No values found)

[HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\\Low Rights\RunDLl32Policy\cnmsm5n.dll]

(No values found)

[HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\\Low Rights\RunDLl32Policy\cnmsm5p.dll]

(No values found)

[HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\\Low Rights\RunDLl32Policy\cnmsm5q.dll]

(No values found)

[HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\\Low Rights\RunDLl32Policy\cnmsm5s.dll]

(No values found)

[HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\\Low Rights\RunDLl32Policy\cnmsm5u.dll]

(No values found)

[HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\\Low Rights\RunDLl32Policy\cnmsm5v.dll]

(No values found)

[HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\\Low Rights\RunDLl32Policy\cnmsm5x.dll]

(No values found)

[HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\\Low Rights\RunDLl32Policy\cnmsm5y.dll]

(No values found)

[HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\\Low Rights\RunDLl32Policy\cnmsm5z.dll]

(No values found)

[HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\\Low Rights\RunDLl32Policy\cnmsm61.dll]

(No values found)

[HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\\Low Rights\RunDLl32Policy\cnmsm62.dll]

(No values found)

[HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\\Low Rights\RunDLl32Policy\cnmsm64.dll]

(No values found)

[HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\\Low Rights\RunDLl32Policy\cnmsm65.dll]

(No values found)

[HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\\Low Rights\RunDLl32Policy\cnmsm66.dll]

(No values found)

[HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\\Low Rights\RunDLl32Policy\cnmsm67.dll]

(No values found)

[HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\\Low Rights\RunDLl32Policy\cnmsm69.dll]

(No values found)

[HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\\Low Rights\RunDLl32Policy\cnmsm6a.dll]

(No values found)

[HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\\Low Rights\RunDLl32Policy\cnmsm6d.dll]

(No values found)

[HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\\Low Rights\RunDLl32Policy\cnmsm6e.dll]

(No values found)

[HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\\Low Rights\RunDLl32Policy\cnmsm6f.dll]

(No values found)

[HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\\Low Rights\RunDLl32Policy\cnmsm6h.dll]

(No values found)

[HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\\Low Rights\RunDLl32Policy\cnmsm6i.dll]

(No values found)

[HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\\Low Rights\RunDLl32Policy\cnmsm6j.dll]

(No values found)

[HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\\Low Rights\RunDLl32Policy\cnmsm6k.dll]

(No values found)

[HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\\Low Rights\RunDLl32Policy\cnmsm6l.dll]

(No values found)

Posted

[HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\\Low Rights\RunDLl32Policy\cnmsm6l.dll]

(No values found)

[HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\\Low Rights\RunDLl32Policy\cnmsm6m.dll]

(No values found)

[HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\\Low Rights\RunDLl32Policy\cnmsm6n.dll]

(No values found)

[HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\\Low Rights\RunDLl32Policy\cnmsm6o.dll]

(No values found)

[HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\\Low Rights\RunDLl32Policy\cnmsm6p.dll]

(No values found)

[HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\\Low Rights\RunDLl32Policy\cnmsm6r.dll]

(No values found)

[HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\\Low Rights\RunDLl32Policy\cnmsm6s.dll]

(No values found)

[HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\\Low Rights\RunDLl32Policy\cnmsm6v.dll]

(No values found)

[HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\\Low Rights\RunDLl32Policy\cnmsm6y.dll]

(No values found)

[HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\\Low Rights\RunDLl32Policy\cnmsm6z.dll]

(No values found)

[HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\\Low Rights\RunDLl32Policy\cnmsm70.dll]

(No values found)

[HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\\Low Rights\RunDLl32Policy\cnmsm71.dll]

(No values found)

[HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\\Low Rights\RunDLl32Policy\cnmsm72.dll]

(No values found)

[HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\\Low Rights\RunDLl32Policy\cnmsm74.dll]

(No values found)

[HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\\Low Rights\RunDLl32Policy\cnmsm75.dll]

(No values found)

[HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\\Low Rights\RunDLl32Policy\cnmsm76.dll]

(No values found)

[HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\\Low Rights\RunDLl32Policy\cnmsm78.dll]

(No values found)

[HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\\Low Rights\RunDLl32Policy\cnmsm79.dll]

(No values found)

[HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\\Low Rights\RunDLl32Policy\cnmsm7a.dll]

(No values found)

[HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\\Low Rights\RunDLl32Policy\cnmsm7b.dll]

(No values found)

[HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\\Low Rights\RunDLl32Policy\cnmsm7c.dll]

(No values found)

[HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\\Low Rights\RunDLl32Policy\cnmsm7d.dll]

(No values found)

[HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\\Low Rights\RunDLl32Policy\cnmsm7e.dll]

(No values found)

[HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\\Low Rights\RunDLl32Policy\cnmsm7f.dll]

(No values found)

[HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\\Low Rights\RunDLl32Policy\cnmsm7i.dll]

(No values found)

[HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\\Low Rights\RunDLl32Policy\cnmsm7j.dll]

(No values found)

[HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\\Low Rights\RunDLl32Policy\cnmsm7k.dll]

(No values found)

[HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\\Low Rights\RunDLl32Policy\cnmsm7l.dll]

(No values found)

[HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\\Low Rights\RunDLl32Policy\cnmsm7m.dll]

(No values found)

[HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\\Low Rights\RunDLl32Policy\cnmsm7n.dll]

(No values found)

[HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\\Low Rights\RunDLl32Policy\cnmsm7o.dll]

(No values found)

[HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\\Low Rights\RunDLl32Policy\cnmsm7q.dll]

(No values found)

[HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\\Low Rights\RunDLl32Policy\cnmsm7r.dll]

(No values found)

[HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\\Low Rights\RunDLl32Policy\cnmsm7s.dll]

(No values found)

[HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\\Low Rights\RunDLl32Policy\cnmsm7t.dll]

(No values found)

[HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\\Low Rights\RunDLl32Policy\cnmsm7u.dll]

(No values found)

[HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\\Low Rights\RunDLl32Policy\cnmsm7v.dll]

(No values found)

[HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\\MAIN]

"AutoHide"="yes"

"Security Risk Page"="about:SecurityRisk"

"Extensions Off Page"="about:NoAdd-ons"

"Default_Search_URL"="http://go.microsoft.com/fwlink/?LinkId=54896"

"Default_Page_URL"="http://go.microsoft.com/fwlink/?LinkId=69157"

"Anchor_Visitation_Horizon"=01 00 00 00 (REG_BINARY)

"Cache_Percent_of_Disk"=0a 00 00 00 (REG_BINARY)

"Placeholder_Width"=1a 00 00 00 (REG_BINARY)

"Placeholder_Height"=1a 00 00 00 (REG_BINARY)

"Default_Secondary_Page_URL"=""

"Use_Async_DNS"="yes"

"Start Page"=""

"Local Page"="C:\Windows\System32\blank.htm"

"Search Page"="http://go.microsoft.com/fwlink/?LinkId=54896"

"Delete_Temp_Files_On_Exit"="yes"

"Enable_Disk_Cache"="yes"

"TabProcGrowth"="Medium"

"Print_Background"= 0x0000000000 (0)

"AlwaysShowMenus"= 0x0000000000 (0)

"StatusBarWeb"= 0x0000000001 (1)

[HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\\MAIN\ErrorThresholds]

"406"= 0x0000000200 (512)

"405"= 0x0000000100 (256)

"501"= 0x0000000200 (512)

"404"= 0x0000000200 (512)

"500"= 0x0000000200 (512)

"403"= 0x0000000100 (256)

"409"= 0x0000000200 (512)

"505"= 0x0000000200 (512)

"408"= 0x0000000200 (512)

"400"= 0x0000000200 (512)

"410"= 0x0000000100 (256)

[HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\\MAIN\FeatureControl]

(No values found)

[HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\\MAIN\FeatureControl\FEATURE_96DPI_PIXEL]

"WindowsAnytimeUpgradeUI.exe"= 0x0000000001 (1)

[HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\\MAIN\FeatureControl\FEATURE_ACTIVEX_REPURPOSEDETECTION]

"PresentationHost.exe"= 0x0000000001 (1)

[HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\\MAIN\FeatureControl\FEATURE_ADDON_MANAGEMENT]

"prevhost.exe"= 0x0000000001 (1)

"wmplayer.exe"= 0x0000000001 (1)

[HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\\MAIN\FeatureControl\FEATURE_BEHAVIORS]

"*"= 0x0000000001 (1)

"explorer.exe"= 0x0000000001 (1)

"iexplore.exe"= 0x0000000001 (1)

"infopath.exe"= 0x0000000000 (0)

"msn6.exe"= 0x0000000000 (0)

"wmplayer.exe"= 0x0000000001 (1)

"ehExtHost.exe"= 0x0000000001 (1)

[HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\\MAIN\FeatureControl\FEATURE_BLOCK_INPUT_PROMPTS]

"prevhost.exe"= 0x0000000001 (1)

[HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\\MAIN\FeatureControl\FEATURE_BLOCK_LMZ_IMG]

"PresentationHost.exe"= 0x0000000001 (1)

[HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\\MAIN\FeatureControl\FEATURE_BLOCK_LMZ_OBJECT]

"PresentationHost.exe"= 0x0000000001 (1)

[HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\\MAIN\FeatureControl\FEATURE_BLOCK_LMZ_SCRIPT]

"PresentationHost.exe"= 0x0000000001 (1)

[HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\\MAIN\FeatureControl\FEATURE_BROWSER_EMULATION]

"prevhost.exe"= 0x0000001f40 (8000)

[HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\\MAIN\FeatureControl\FEATURE_DISABLE_ISO_2022_JP_SNIFFING]

"iexplore.exe"= 0x0000000001 (1)

"*"= 0x0000000000 (0)

[HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\\MAIN\FeatureControl\FEATURE_DISABLE_LEGACY_COMPRESSION]

"PresentationHost.exe"= 0x0000000001 (1)

[HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\\MAIN\FeatureControl\FEATURE_DISABLE_MK_PROTOCOL]

"*"= 0x0000000001 (1)

"explorer.exe"= 0x0000000001 (1)

"iexplore.exe"= 0x0000000001 (1)

"SAPfewgsrv.exe"= 0x0000000000 (0)

"SAPGuiIT.exe"= 0x0000000000 (0)

"SAPGUI.exe"= 0x0000000000 (0)

"SAPLgPad.exe"= 0x0000000000 (0)

"SAPLOGON.exe"= 0x0000000000 (0)

"Scale_for_R3.exe"= 0x0000000000 (0)

"wmplayer.exe"= 0x0000000001 (1)

"ehExtHost.exe"= 0x0000000001 (1)

[HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\\MAIN\FeatureControl\FEATURE_DISABLE_SQM_UPLOAD_FOR_APP]

"ieuser.exe"= 0x0000000001 (1)

"iexplore.exe"= 0x0000000001 (1)

[HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\\MAIN\FeatureControl\FEATURE_DISABLE_TELNET_PROTOCOL]

"PresentationHost.exe"= 0x0000000001 (1)

[HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\\MAIN\FeatureControl\FEATURE_DISABLE_UNICODE_HANDLE_CLOSING_CALLBACK]

"YahooMusicEngine.exe"= 0x0000000001 (1)

[HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\\MAIN\FeatureControl\FEATURE_ENABLE_SCRIPT_PASTE_URLACTION_IF_PROMPT]

"devenv.exe"= 0x0000000001 (1)

"dexplore.exe"= 0x0000000001 (1)

"helppane.exe"= 0x0000000001 (1)

"PresentationHost.exe"= 0x0000000000 (0)

[HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\\MAIN\FeatureControl\FEATURE_FEEDS]

"msfeedssync.exe"= 0x0000000001 (1)

[HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\\MAIN\FeatureControl\FEATURE_FORCE_ADDR_AND_STATUS]

"prevhost.exe"= 0x0000000001 (1)

"PresentationHost.exe"= 0x0000000001 (1)

[HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\\MAIN\FeatureControl\FEATURE_HIGH_CONTRAST_BACKGROUND_IMAGES]

"sidebar.exe"= 0x0000000001 (1)

[HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\\MAIN\FeatureControl\FEATURE_HTTP_USERNAME_PASSWORD_DISABLE]

"wmplayer.exe"= 0x0000000001 (1)

"ehExtHost.exe"= 0x0000000001 (1)

[HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\\MAIN\FeatureControl\FEATURE_IGNORE_XML_PROLOG]

@=""

"msiexec.exe"= 0x0000000000 (0)

[HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\\MAIN\FeatureControl\FEATURE_IMAGING_USE_ART]

"wm.exe"= 0x0000000001 (1)

"cs.exe"= 0x0000000001 (1)

"waol.exe"= 0x0000000001 (1)

[HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\\MAIN\FeatureControl\FEATURE_INTERNET_SHELL_FOLDERS]

"iexplore.exe"= 0x0000000000 (0)

[HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\\MAIN\FeatureControl\FEATURE_LEGACY_DISPPARAMS]

"helppane.exe"= 0x0000000000 (0)

[HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\\MAIN\FeatureControl\FEATURE_LEGACY_DLCONTROL_BEHAVIORS]

"wlmail.exe"= 0x0000000001 (1)

[HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\\MAIN\FeatureControl\FEATURE_LOCALMACHINE_LOCKDOWN]

"explorer.exe"= 0x0000000001 (1)

"iexplore.exe"= 0x0000000001 (1)

"prevhost.exe"= 0x0000000001 (1)

"wmplayer.exe"= 0x0000000001 (1)

"PresentationHost.exe"= 0x0000000001 (1)

[HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\\MAIN\FeatureControl\FEATURE_MAXCONNECTIONSPER1_0SERVER]

"explorer.exe"= 0x0000000004 (4)

[HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\\MAIN\FeatureControl\FEATURE_MAXCONNECTIONSPERSERVER]

"explorer.exe"= 0x0000000002 (2)

[HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\\MAIN\FeatureControl\FEATURE_MIME_HANDLING]

"explorer.exe"= 0x0000000001 (1)

"iexplore.exe"= 0x0000000001 (1)

"prevhost.exe"= 0x0000000001 (1)

"wmplayer.exe"= 0x0000000001 (1)

"ehExtHost.exe"= 0x0000000001 (1)

[HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\\MAIN\FeatureControl\FEATURE_MIME_SNIFFING]

"explorer.exe"= 0x0000000001 (1)

"iexplore.exe"= 0x0000000001 (1)

"wmplayer.exe"= 0x0000000001 (1)

"ehExtHost.exe"= 0x0000000001 (1)

[HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\\MAIN\FeatureControl\FEATURE_MSHTML_AUTOLOAD_IEFRAME]

"mshta.exe"= 0x0000000001 (1)

"outlook.exe"= 0x0000000001 (1)

"sidebar.exe"= 0x0000000001 (1)

[HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\\MAIN\FeatureControl\FEATURE_OBJECT_CACHING]

"explorer.exe"= 0x0000000001 (1)

"iexplore.exe"= 0x0000000001 (1)

"wmplayer.exe"= 0x0000000001 (1)

"ehExtHost.exe"= 0x0000000000 (0)

[HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\\MAIN\FeatureControl\FEATURE_PROTOCOL_LOCKDOWN]

"explorer.exe"= 0x0000000000 (0)

"iexplore.exe"= 0x0000000000 (0)

"wmplayer.exe"= 0x0000000001 (1)

"ehExtHost.exe"= 0x0000000001 (1)

[HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\\MAIN\FeatureControl\FEATURE_RELEASE_CALLBACK_ON_STOP_BINDING]

"communicator.exe"= 0x0000000001 (1)

[HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\\MAIN\FeatureControl\FEATURE_RESTRICT_ABOUT_PROTOCOL_IE7]

"prevhost.exe"= 0x0000000001 (1)

"PresentationHost.exe"= 0x0000000001 (1)

[HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\\MAIN\FeatureControl\FEATURE_RESTRICT_ACTIVEXINSTALL]

"prevhost.exe"= 0x0000000001 (1)

"wmplayer.exe"= 0x0000000001 (1)

[HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\\MAIN\FeatureControl\FEATURE_RESTRICT_FILEDOWNLOAD]

"msimn.exe"= 0x0000000001 (1)

"winmail.exe"= 0x0000000001 (1)

"prevhost.exe"= 0x0000000001 (1)

"wmplayer.exe"= 0x0000000001 (1)

[HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\\MAIN\FeatureControl\FEATURE_RESTRICT_OBJECT_DATA_ATTRIBUTE]

"PresentationHost.exe"= 0x0000000001 (1)

[HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\\MAIN\FeatureControl\FEATURE_RESTRICT_RES_TO_LMZ]

"prevhost.exe"= 0x0000000001 (1)

"PresentationHost.exe"= 0x0000000001 (1)

[HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\\MAIN\FeatureControl\FEATURE_SAFE_BINDTOOBJECT]

"explorer.exe"= 0x0000000001 (1)

"iexplore.exe"= 0x0000000001 (1)

"wmplayer.exe"= 0x0000000001 (1)

"ehExtHost.exe"= 0x0000000001 (1)

[HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\\MAIN\FeatureControl\FEATURE_SECURITYBAND]

"prevhost.exe"= 0x0000000001 (1)

"wmplayer.exe"= 0x0000000001 (1)

[HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\\MAIN\FeatureControl\FEATURE_SHIM_MSHELP_COMBINE]

"prevhost.exe"= 0x0000000000 (0)

[HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\\MAIN\FeatureControl\FEATURE_SHOW_APP_PROTOCOL_WARN_DIALOG]

"PresentationHost.exe"= 0x0000000001 (1)

[HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\\MAIN\FeatureControl\FEATURE_SSLUX]

"PresentationHost.exe"= 0x0000000001 (1)

[HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\\MAIN\FeatureControl\FEATURE_SUBDOWNLOAD_LOCKDOWN]

"winmail.exe"= 0x0000000001 (1)

"msimn.exe"= 0x0000000001 (1)

"outlook.exe"= 0x0000000001 (1)

[HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\\MAIN\FeatureControl\FEATURE_UNC_SAVEDFILECHECK]

"wmplayer.exe"= 0x0000000001 (1)

"ehExtHost.exe"= 0x0000000001 (1)

[HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\\MAIN\FeatureControl\FEATURE_USE_WINDOWEDSELECTCONTROL]

"infopath.exe"= 0x0000000001 (1)

"winword.exe"= 0x0000000001 (1)

"excel.exe"= 0x0000000001 (1)

"powerpnt.exe"= 0x0000000001 (1)

[HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\\MAIN\FeatureControl\FEATURE_VALIDATE_NAVIGATE_URL]

"prevhost.exe"= 0x0000000001 (1)

"wmplayer.exe"= 0x0000000001 (1)

"ehExtHost.exe"= 0x0000000001 (1)

[HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\\MAIN\FeatureControl\FEATURE_WEBOC_MOVESIZECHILD]

"msn6.exe"= 0x0000000001 (1)

"msn.exe"= 0x0000000001 (1)

[HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\\MAIN\FeatureControl\FEATURE_WEBOC_POPUPMANAGEMENT]

"explorer.exe"= 0x0000000001 (1)

"iexplore.exe"= 0x0000000001 (1)

"wmplayer.exe"= 0x0000000001 (1)

[HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\\MAIN\FeatureControl\FEATURE_WINDOW_RESTRICTIONS]

"explorer.exe"= 0x0000000001 (1)

"iexplore.exe"= 0x0000000001 (1)

"wmplayer.exe"= 0x0000000001 (1)

[HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\\MAIN\FeatureControl\FEATURE_XSSFILTER]

"iexplore.exe"= 0x0000000001 (1)

"prevhost.exe"= 0x0000000001 (1)

[HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\\MAIN\FeatureControl\FEATURE_ZONE_ELEVATION]

"explorer.exe"= 0x0000000001 (1)

"iexplore.exe"= 0x0000000001 (1)

"prevhost.exe"= 0x0000000001 (1)

"PresentationHost.exe"= 0x0000000001 (1)

"wmplayer.exe"= 0x0000000001 (1)

"ehExtHost.exe"= 0x0000000001 (1)

[HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\\MAIN\UrlTemplate]

"1"="www.%s.com"

"3"="www.%s.net"

"2"="www.%s.org"

"4"="www.%s.edu"

[HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\\Migration]

"IE Installed Date"=2a 41 7b 83 ba a6 cb 01 (REG_BINARY)

[HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\\P3]

(No values found)

[HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\\P3\Write]

"Registration"=".microsoft.com"

[HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\\PhishingFilter]

"EnabledV8"= 0x0000000001 (1)

[HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\\Plugins]

(No values found)

[HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\\Plugins\Extension]

(No values found)

[HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\\Plugins\MIME]

(No values found)

[HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\\Plugins\PluginsPage]

@="http://activex.microsoft.com/controls/find.asp?ext=%s&mime=%s"

[HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\\Plugins\PluginsPageFriendlyName]

@="Microsoft ActiveX Gallery"

[HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\\ProtocolExecute]

(No values found)

[HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\\ProtocolExecute\wpc]

"WarnOnOpen"= 0x0000000000 (0)

[HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\\Registration]

"ProductId"="00359-OEM-8992687-00007"

"DigitalProductId"=a4 00 00 00 03 00 00 00 30 30 33 35 39 2d 4f 45 4d 2d 38 39 39 32 36 38 37 2d 30 30 30 30 37 00 b2 00 00 00 58 31 35 2d 33 37 33 37 39 00 00 00 00 00 00 00 ab e7 ec 74 dd 42 75 40 36 3d 25 62 85 79 04 00 00 00 00 00 b7 76 6f 4a 9e dd d9 c3 02 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 78 54 b3 39 (REG_BINARY)

"DigitalProductId4"=f8 04 00 00 04 00 00 00 30 00 30 00 33 00 35 00 39 00 2d 00 30 00 30 00 31 00 37 00 38 00 2d 00 39 00 32 00 36 00 2d 00 38 00 30 00 30 00 30 00 30 00 37 00 2d 00 30 00 32 00 2d 00 31 00 30 00 33 00 33 00 2d 00 37 00 36 00 30 00 30 00 2e 00 30 00 30 00 30 00 30 00 2d 00 32 00 30 00 39 00 32 00 30 00 30 00 39 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 64 00 32 00 63 00 30 00 34 00 65 00 39 00 30 00 2d 00 63 00 33 00 64 00 64 00 2d 00 34 00 32 00 36 00 30 00 2d 00 62 00 30 00 66 00 33 00 2d 00 66 00 38 00 34 00 35 00 66 00 35 00 64 00 32 00 37 00 64 00 36 00 34 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 48 00 6f 00 6d 00 65 00 50 00 72 00 65 00 6d 00 69 00 75 00 6d 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 (REG_BINARY)

[HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\\Safety]

(No values found)

[HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\\Safety\PrivacIE]

"Mode"= 0x0000000002 (2)

[HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\\SearchScopes]

"DefaultScope"="{6A1806CD-94D4-4689-BA73-E35EA1EA9990}"

[HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}]

@="Bing"

"URL"="http://www.bing.com/search?q={searchTerms}&FORM=IE8SRC"

"DisplayName"="@ieframe.dll,-12512"

[HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\\SearchScopes\{6A1806CD-94D4-4689-BA73-E35EA1EA9990}]

"DisplayName"="Google"

"URL"="http://www.google.com/search?q={searchTerms}&rls=com.microsoft:{language}:{referrer:source?}&ie={inputEncoding}&oe={outputEncoding}&sourceid=ie7"

"FaviconURL"="http://www.google.com/favicon.ico"

"SuggestionsURL"="http://clients5.google.com/complete/search?hl={language}&q={searchTerms}&client=ie8&inputencoding={inputEncoding}&outputencoding={outputEncoding}"

"ShowSearchSuggestions"= 0x0000000001 (1)

"SortIndex"= 0x0000000000 (0)

"TopResultURLFallback"="http://start.funmoods.com/results.php?f=4&q={searchTerms}&a=bf3&chnl=bf3&cd=2XzuyEtN2Y1L1Qzu0EtD0C0ByE0EtA0DyEyDtC0FtAyCtBtAtN0D0Tzu0CtBtAtBtN1L2XzutBtFtCtFtCtFtAtCtB&cr=801427480"

"FaviconURLFallback"="http://start.funmoods.com/favicon.ico"

@="Funmoods"

[HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\\SearchUrl]

(No values found)

[HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\\Security]

(No values found)

[HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\\Security\DPA]

"Flags"=1a 00 00 00 (REG_BINARY)

[HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\\Security\MSN]

"Flags"=0a 00 00 00 (REG_BINARY)

[HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\\Security\Negotiate]

"Flags"=18 00 00 00 (REG_BINARY)

[HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\\Security\NTLM]

"Flags"=08 00 00 00 (REG_BINARY)

[HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\\Setup]

(No values found)

[HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\\Setup\9.0]

"DoNotOfferIE90"= 0x0000000001 (1)

[HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\\Styles]

"Count_Style_Sheets"=05 00 00 00 (REG_BINARY)

[HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\\TabbedBrowsing]

"Groups"= 0x0000000001 (1)

[HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\\Toolbar]

"Locked"= 0x0000000000 (0)

"{8FF5E183-ABDE-46EB-B09E-D2AAB95CABE3}"=""

"{2318C2B1-4965-11d4-9B18-009027A5CD4F}"=00 (REG_BINARY)

[HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\\Transitions]

"PageBack"="progid:DXImageTransform.Microsoft.Fade(Duration=0.4)"

"PageForward"="progid:DXImageTransform.Microsoft.Fade(Duration=0.4)"

"SiteNav"="progid:DXImageTransform.Microsoft.Fade(Duration=0.4)"

[HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\\Unattend]

(No values found)

[HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\\Unattend\New Windows]

"AllowHTTPS"= 0x0000000000 (0)

"BlockControls"= 0x0000000000 (0)

"BlockUserInit"= 0x0000000000 (0)

"UseHooks"= 0x0000000001 (1)

"UseTimerMethod"= 0x0000000000 (0)

[HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\\UnattendBackup]

(No values found)

[HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\\UnattendBackup\ActiveSetup]

(No values found)

[HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\\UnattendBackup\ActiveSetup\CompanyName]

"CompanyName"=""

[HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\\UnattendBackup\ActiveSetup\DisableFirstRunWizard]

"DisableFirstRunWizard"= 0x0000000000 (0)

[HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\\UnattendBackup\ActiveSetup\DisableWelcomePage]

"DisableWelcomePage"= 0x0000000001 (1)

[HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\\UnattendBackup\ActiveSetup\FavoritesDelete]

"FavoritesDelete"= 0x0000000000 (0)

[HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\\UnattendBackup\ActiveSetup\FavoritesList]

(No values found)

[HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\\UnattendBackup\ActiveSetup\FavoritesList\1]

"FavTitle"="ASUS E-Service\ASUS Homepage"

"FavURL"="http://www.asus.com"

[HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\\UnattendBackup\ActiveSetup\FavoritesList\2]

"FavTitle"="ASUS E-Service\ASUS Technical Support"

"FavURL"="http://www.asus.com/support"

[HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\\UnattendBackup\ActiveSetup\FavoritesList\3]

"FavTitle"="ASUS E-Service\ASUS Member"

"FavURL"="http://member.asus.com"

[HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\\UnattendBackup\ActiveSetup\FavoritesList\4]

"FavTitle"="ASUS E-Service\ASUS Software Download"

"FavURL"="http://www.asus.com/support/download"

[HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\\UnattendBackup\ActiveSetup\FavoritesOnTop]

"FavoritesOnTop"= 0x0000000000 (0)

[HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\\UnattendBackup\ActiveSetup\Help_Page]

"Help_Page"=""

[HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\\UnattendBackup\ActiveSetup\Home_Page]

"Home_Page"=""

[HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\\UnattendBackup\ActiveSetup\IEWelcomeMsg]

"IEWelcomeMsg"= 0x0000000000 (0)

[HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\\UnattendBackup\ActiveSetup\NoDial]

"NoDial"= 0x0000000000 (0)

[HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\\UnattendBackup\ActiveSetup\UserAgent]

"UserAgent"=""

[HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\\UnattendBackup\ActiveSetup\Window_Title_CN]

"Window_Title_CN"=""

[HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\\UnattendBackup\AllowedSites]

"AllowedSites"=""

[HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\\UnattendBackup\AllSitesCompatibilityMode]

"AllSitesCompatibilityMode"= 0x0000000000 (0)

[HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\\UnattendBackup\BlockPopups]

(No values found)

[HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\\UnattendBackup\CommandLabelDisplay]

"TextOption"= 0x0000000000 (0)

[HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\\UnattendBackup\CompatibilityViewDomains]

"CompatibilityViewDomains"=""

[HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\\UnattendBackup\DisableAccelerators]

"NoActivities"= 0x0000000000 (0)

[HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\\UnattendBackup\DisableDataExecutionPrevention]

(No values found)

[HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\\UnattendBackup\DisableDevTools]

(No values found)

[HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\\UnattendBackup\DisableOOBAccelerators]

"NoOOBActivities"= 0x0000000000 (0)

[HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\\UnattendBackup\EnableLinksBar]

"Enabled"= 0x0000000001 (1)

[HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\\UnattendBackup\FilterLevel]

"FilterLevel"="Medium"

[HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\\UnattendBackup\FindProvidersURL]

(No values found)

[HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\\UnattendBackup\GroupTabs]

"Groups"= 0x0000000001 (1)

Posted

[HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\\UnattendBackup\HKLMEmailName]

(No values found)

[HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\\UnattendBackup\IntranetCompatibilityMode]

"IntranetCompatibilityMode"= 0x0000000001 (1)

[HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\\UnattendBackup\LocalIntranetSites]

"LocalIntranetSites"=""

[HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\\UnattendBackup\LockToolbars]

"Locked"= 0x0000000000 (0)

[HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\\UnattendBackup\MSCompatibilityMode]

"MSCompatibilityMode"= 0x0000000000 (0)

[HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\\UnattendBackup\PlaySound]

(No values found)

[HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\\UnattendBackup\PrintBackground]

"Print_Background"= 0x0000000000 (0)

[HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\\UnattendBackup\PrivacyAdvisorMode]

"Mode"= 0x0000000002 (2)

[HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\\UnattendBackup\ShowCommandBar]

"Enabled"= 0x0000000001 (1)

[HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\\UnattendBackup\ShowCompatibilityViewButton]

"ShowCompatibilityViewButton"= 0x0000000001 (1)

[HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\\UnattendBackup\ShowInformationBar]

(No values found)

[HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\\UnattendBackup\ShowLeftAddressToolbar]

"ShowLeftAddressToolbar"= 0x0000000000 (0)

[HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\\UnattendBackup\ShowMenuBar]

"AlwaysShowMenus"= 0x0000000000 (0)

[HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\\UnattendBackup\ShowStatusBar]

"StatusBarWeb"= 0x0000000001 (1)

[HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\\UnattendBackup\SmallCommandBarIcons]

"SmallIcons"= 0x0000000001 (1)

[HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\\UnattendBackup\SuggestedSitesEnabled]

(No values found)

[HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\\UnattendBackup\TabProcessGrowth]

"TabProcGrowth"="Medium"

[HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\\UnattendBackup\TrustedSites]

"TrustedSites"=""

[HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\\URL Compatibility]

"Version"="5.1"

[HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\\URL Compatibility\~/CONNWIZ.HTM]

"Compatibility Flags"= 0x0000000004 (4)

[HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\\URL Compatibility\~/CWIZINTR.HTM]

"Compatibility Flags"= 0x0000000004 (4)

[HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\\Version Vector]

"VML"="1.0"

"IE"="8.0000"

"WindowsEdition"="3"

 

[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer]

"Download Directory"="C:\Users\Deb\Desktop"

[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\AboutURLs]

"Tabs"="http://newtab.certified-toolbar.com/nie?si=41460&tid=3204&new=true"

[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\BrowserEmulation]

"TLDUpdates"= 0x0000000000 (0)

"UnattendLoaded"= 0x0000000001 (1)

"MSCompatibilityMode"= 0x0000000001 (1)

"IECompatVersionHigh"= 0x0000080000 (524288)

"IECompatVersionLow"= 0x001db14503 (498156803)

"StaleCompatCache"= 0x0000000000 (0)

[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\BrowserEmulation\ClearableListData]

(No values found)

[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\BrowserEmulation\LowMic]

"IECompatVersionHigh"= 0x0000080000 (524288)

"IECompatVersionLow"= 0x001db14503 (498156803)

"StaleCompatCache"= 0x0000000000 (0)

[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\CaretBrowsing]

(No values found)

[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\CommandBar]

"ToolBandWidth"= 0x0000000189 (393)

"CompatibilityViewButtonBalloonCount"= 0x0000000002 (2)

"CommandBarEnabled"= 0x0000000001 (1)

[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Desktop]

(No values found)

[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Desktop\General]

"WallpaperSource"="D:\Wallpapers\27.jpg"

[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Document Windows]

"Maximized"="no"

"height"=00 00 00 00 (REG_BINARY)

"width"=00 00 00 80 (REG_BINARY)

"x"=00 00 00 80 (REG_BINARY)

"y"=00 00 00 00 (REG_BINARY)

[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\DOMStorage]

(No values found)

[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\DOMStorage\giveawayoftheday.com]

@= 0x00000206ac (132780)

[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\DOMStorage\Total]

@= 0x00000206ac (132780)

[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Download]

"CheckExeSignatures"="yes"

[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Explorer Bars]

(No values found)

[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Explorer Bars\{555D4D79-4BD2-4094-A395-CFC534424A05}]

(No values found)

[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Help_Menu_URLs]

(No values found)

[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\IEDevTools]

"Pinned"= 0x0000000000 (0)

[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\IETld]

"IETldDllVersionHigh"= 0x0000080000 (524288)

"IETldDllVersionLow"= 0x001db14640 (498157120)

"IETldVersionHigh"= 0x0000000001 (1)

"IETldVersionLow"= 0x0000000008 (8)

"StaleIETldCache"= 0x0000000000 (0)

[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\IETld\LowMic]

"IETldDllVersionHigh"= 0x0000080000 (524288)

"IETldDllVersionLow"= 0x001db14640 (498157120)

"IETldVersionHigh"= 0x0000000001 (1)

"IETldVersionLow"= 0x0000000008 (8)

"StaleIETldCache"= 0x0000000000 (0)

[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\IntelliForms]

"PSMigrated"= 0x0000000001 (1)

"AskUser"= 0x0000000000 (0)

[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\IntelliForms\Storage1]

"AE698CFE08B29271644798AD167B0FD791F9116BCB"=01 00 00 00 d0 8c 9d df 01 15 d1 11 8c 7a 00 c0 4f c2 97 eb 01 00 00 00 04 ae 72 13 3a 84 f1 4a 99 2f 70 e7 3b 78 23 f2 00 00 00 00 02 00 00 00 00 00 10 66 00 00 00 01 00 00 20 00 00 00 f3 ae 35 65 6e 4e 50 1e 5c 6d b6 76 c1 41 08 29 e6 3b fc 9f 1f 9f c5 9c 26 66 6f 24 e7 85 dd dd 00 00 00 00 0e 80 00 00 00 02 00 00 20 00 00 00 d3 03 ad ff 74 e6 ac 35 10 80 e9 39 5d 26 55 f0 bc ef 11 03 36 99 40 db 62 33 65 24 67 ea 81 b5 60 04 00 00 7b 44 ab a0 2d 0e 5c cb 78 a8 b3 88 4a 5b 1b ff 45 ab 8b c7 7c d2 a1 11 c7 3b 82 b1 e0 0a e7 6b 8a 08 50 84 db 02 98 50 8c b7 18 31 89 a9 35 94 32 c0 c6 f0 6e f9 07 61 53 a8 dd bc d0 b1 50 e4 0b 0a e8 9b b8 cf bf a3 25 0d c6 5d 0c 6a e6 c3 e8 4b 2e 37 97 eb 94 95 f5 0d dd b3 e1 b6 c7 48 62 72 d0 b4 20 a6 fd 68 6f 19 4d f6 d5 56 04 ab b5 04 d7 5a 46 d9 e4 fa a1 b4 a1 fe bf 00 4f 50 c2 0d ba eb 68 27 d8 f4 72 fc e6 7e eb 28 82 b6 52 53 67 84 0a 84 ab c0 b8 3d 19 3b 37 bf da 0b 3c 0f 23 bd ff c1 bb 84 0a 34 b7 88 1f 73 4e 36 c5 92 05 4b ce b0 f6 ce 4a c6 24 05 55 93 8a 42 fe d4 c8 (REG_BINARY)

"DABBFD35854177D84D61FFF79D2BC7215D6470A506"=01 00 00 00 d0 8c 9d df 01 15 d1 11 8c 7a 00 c0 4f c2 97 eb 01 00 00 00 fa a3 72 49 a9 04 8c 41 b0 23 5e 0b 9e 7a ce 75 00 00 00 00 02 00 00 00 00 00 10 66 00 00 00 01 00 00 20 00 00 00 7f 67 c4 e1 4e 16 f9 ae 7f b1 bd 4b 40 0e 8a 77 16 fe 17 d0 99 4f f3 a0 ea 3e 17 67 5a 00 5f b7 00 00 00 00 0e 80 00 00 00 02 00 00 20 00 00 00 7e e3 3f 12 00 17 86 79 73 0a 6e 89 fd 69 63 89 57 21 75 f2 4f 5f 77 26 ed 2d 12 09 6c e3 f2 79 10 02 00 00 01 6b 52 1f f2 94 9a 40 43 e1 70 35 a5 69 98 45 38 34 5e 87 48 9d c8 be c0 07 34 3a 6e 0e b3 13 eb ca a1 a4 d7 b8 07 cf bc 7d be 41 e4 76 d4 c0 5e cf f4 e7 a4 ad f0 09 cc 06 90 c4 04 4b be 85 49 3e e5 7f d3 33 df 03 a5 8f 60 f4 22 ab 72 f7 e5 cb 3f 33 09 23 5e fd fc 8b 11 82 3f dd e9 83 e1 fd 35 b0 ee ac 0c d7 52 2a b7 4b b1 65 fa cd 52 96 70 32 c4 e0 fd 5e 13 04 ad 8f b7 31 42 ab d2 d4 cb d2 2c 49 fa 99 3c 18 c2 9b df 20 28 bf f0 d2 01 62 56 9c 61 95 22 88 fd a3 09 d2 c5 dd f2 d7 12 a8 93 cb 48 33 04 48 07 e3 1c 99 ae 53 c6 d2 83 aa f5 f0 49 6d 4a 8c ee da 41 65 94 41 c8 64 75 (REG_BINARY)

"924EB1974AFEBEB0FD6CC5317D3C6485375EB92C59"=01 00 00 00 d0 8c 9d df 01 15 d1 11 8c 7a 00 c0 4f c2 97 eb 01 00 00 00 c2 cf 8c 3a d2 c3 42 44 b9 f0 64 2f 97 f2 c7 d7 00 00 00 00 02 00 00 00 00 00 10 66 00 00 00 01 00 00 20 00 00 00 d7 b6 8b d0 11 5a b5 d2 a1 ce bd 9d 70 9a b4 db c4 4c 43 5a 83 0f 13 15 85 53 1d 3f 96 23 a3 21 00 00 00 00 0e 80 00 00 00 02 00 00 20 00 00 00 78 4f f4 71 6f ec 6c aa 8e 1f 76 e6 dd 88 86 24 f3 e3 da 6d 55 18 ab ec 6a 9a 6f b0 57 26 9e 48 50 00 00 00 8c 28 52 59 ce d4 fe 1a 2c 58 c2 85 9a 68 8b 98 10 92 ef b1 7c 04 f6 28 2e c8 af b0 d5 89 b9 1c cd 1a 2f d8 6a fa d6 b3 bc eb ba 45 95 4d 35 37 7b 61 b5 84 42 ee ee c3 01 a1 29 85 78 11 bd 58 b4 40 76 ff 5b c6 f6 e8 97 82 72 2e d3 c4 98 03 40 00 00 00 07 56 9a 89 e0 0d 43 a5 87 62 8b 98 d9 6f 63 b3 f1 d5 a2 dd 20 6e 42 2f 73 66 a9 7a 64 72 80 55 a7 f9 21 8c 26 7a 74 e8 11 39 d9 1d 18 a7 d8 5b 0b ec 6e 99 a1 b8 9c a6 e9 28 b8 24 93 d4 fa 96 (REG_BINARY)

"25D63977B5D48876833346C856116F99872EDE978F"=01 00 00 00 d0 8c 9d df 01 15 d1 11 8c 7a 00 c0 4f c2 97 eb 01 00 00 00 c2 cf 8c 3a d2 c3 42 44 b9 f0 64 2f 97 f2 c7 d7 00 00 00 00 02 00 00 00 00 00 10 66 00 00 00 01 00 00 20 00 00 00 20 d6 af fd 2c 4a 0a d3 cf 6c 74 58 cf f7 9a 6b 4a 63 62 71 82 59 1c a6 6f 0e fc aa a0 e3 c8 37 00 00 00 00 0e 80 00 00 00 02 00 00 20 00 00 00 cf 02 69 d2 f7 a6 99 b6 44 ec f6 86 44 2b a1 c3 0d 4d b4 3b bd bd 9f dc ac 1a 3a 27 1a 86 98 0b 60 00 00 00 52 4e 00 76 f1 66 69 f0 c3 09 a0 cb 19 dc c5 a3 cf 61 00 50 83 ce 36 06 2a af 8a 89 b4 26 55 1d 0d 47 fb c8 f0 b2 94 e3 c9 50 21 53 37 ab c9 51 c4 3b 6e be e0 0c 5e 0a a4 e5 9b e1 eb 92 bb 62 0d 9b 02 0b ad a0 b0 e6 73 88 b1 c8 17 5f 96 cd dc 3f 7b 0c 79 dc 8f 99 2f 32 7b a6 d7 59 db 5e 40 00 00 00 46 32 bc 74 da a0 27 e0 1c 5c 0c 6b 44 fb fc c8 11 56 3a e4 7a de 29 48 5c ea 82 a9 95 e3 4a c8 12 51 64 11 eb ef 66 b0 ca 03 71 ed 2f 14 1a 00 65 28 d5 98 0f e9 01 46 38 d4 c6 12 d1 37 50 69 (REG_BINARY)

"1C6C20FFA0A8BC6A180DD8A5004DA830FB5EC84D4A"=01 00 00 00 d0 8c 9d df 01 15 d1 11 8c 7a 00 c0 4f c2 97 eb 01 00 00 00 fa a3 72 49 a9 04 8c 41 b0 23 5e 0b 9e 7a ce 75 00 00 00 00 02 00 00 00 00 00 10 66 00 00 00 01 00 00 20 00 00 00 f4 e0 1b 76 60 2b 9b 50 d6 19 2b 9d ee 91 ff 1c 89 98 81 f9 28 3e 36 40 dc c2 a9 47 ba 96 8e cb 00 00 00 00 0e 80 00 00 00 02 00 00 20 00 00 00 ac d1 37 bd 37 5f 4a 2a ba d0 a1 9f 6b 25 2a 3a 50 58 27 ad e9 cd 60 40 97 ae 4b 97 11 22 2d bd b0 00 00 00 94 05 5d 37 89 bf da 04 65 61 5c 21 f5 51 5e 67 1f 12 e7 99 be f7 14 c1 f8 2a b9 96 c6 1b 19 3f 9e 45 22 56 46 d8 79 e0 38 bb 9b f5 be 5d 83 b8 e0 8d ec 8d aa 31 a0 91 7f 98 a0 bd 57 8d ae f6 ca 2c 1e ea 5b 3a 65 4f b0 e5 6d b0 0a e9 5f 5f 09 ae 30 e2 d3 4c a3 3e 71 88 d4 1d fa 0f 36 80 5e ae 13 b8 2c bb 6e 5c de e1 da 6c 92 58 fd 09 5a 26 3b 79 be 09 ad a8 de 2a af fe 97 a6 bc 17 b0 99 9a c0 c8 68 66 36 c3 65 63 65 b1 8d d8 23 70 5e f3 23 ea 57 59 fd 04 19 31 f4 5d ed 46 19 8e 99 e6 d4 ea c5 08 61 75 27 9f be 7d d2 a0 29 40 00 00 00 75 cc a6 81 81 4d 24 53 3d 1c ca 5b 07 f9 3f (REG_BINARY)

"C6FB044EC2BD401521D6B1082276415638196D8004"=01 00 00 00 d0 8c 9d df 01 15 d1 11 8c 7a 00 c0 4f c2 97 eb 01 00 00 00 fa a3 72 49 a9 04 8c 41 b0 23 5e 0b 9e 7a ce 75 00 00 00 00 02 00 00 00 00 00 10 66 00 00 00 01 00 00 20 00 00 00 1f 53 91 f3 a8 a1 10 b2 8d 34 b8 b5 04 11 27 3c 02 83 39 1f 3b d5 04 ce fa a2 69 38 90 8c a1 33 00 00 00 00 0e 80 00 00 00 02 00 00 20 00 00 00 31 25 0f 15 9a 06 ab 14 23 7f d5 c3 bf 53 0c 02 ea 66 88 4b e7 bc 2a 9b 30 e0 8d 60 6d fb b1 19 c0 0b 00 00 2b 36 2b 04 fe b4 88 2f a4 a8 1b 9b 16 22 94 71 c8 6c 33 70 78 d3 4b 12 93 ea 51 d2 0b 57 f4 3e d2 6f ec 08 7b 02 cf 37 45 08 79 95 9b b4 f8 ab f6 d7 2e 90 64 13 78 36 68 66 a5 f7 33 c9 ad 8c d3 35 12 d2 d2 e1 78 f4 e9 f7 52 e0 30 87 1e af 1b c1 09 a9 c2 87 83 9c aa 16 4b bf 8c 6d 6f 41 2a 19 40 b1 63 6b 97 31 ed ba 68 38 70 c7 75 fb 24 fa 5d fc 90 8d 74 03 de e5 2d cc 22 4c 81 35 14 19 ac 75 f1 58 ec 3d 83 44 5a 3b d1 1c e0 58 3a ee e2 57 fc 60 79 1a b2 b4 4b 58 1c 82 a6 49 05 55 63 68 33 be 73 88 5e 46 23 10 64 0f 6f 36 e9 ed 33 05 57 59 7a 31 2b e0 1f 99 34 55 2c 22 91 be 2b (REG_BINARY)

"096420CE1C9A31839715B788EF20650AE3D02A535E"=01 00 00 00 d0 8c 9d df 01 15 d1 11 8c 7a 00 c0 4f c2 97 eb 01 00 00 00 c2 cf 8c 3a d2 c3 42 44 b9 f0 64 2f 97 f2 c7 d7 00 00 00 00 02 00 00 00 00 00 10 66 00 00 00 01 00 00 20 00 00 00 ca 7d 60 bf 7f d2 1d 42 b3 52 59 07 75 e1 a7 c5 8a 6b 71 4b 15 a1 b1 3a 52 11 8d f3 dc 5a 9c 04 00 00 00 00 0e 80 00 00 00 02 00 00 20 00 00 00 c6 47 b2 03 4a 52 c1 6e d5 04 7c 40 ed b9 df b8 af 7f 0d 5e 67 59 7a ce f6 f4 64 b2 81 61 83 fd 80 00 00 00 65 4d c7 bf 4c 9f 74 fc cc 23 02 5a 2a 5d 1d e1 01 dd f5 46 a3 55 a7 a8 31 a9 92 cf ba 04 32 ee 48 c8 ab c8 ec a5 e2 20 e7 2e 24 84 59 b6 8f a0 67 6e 0e 45 2d cd 81 f7 96 f3 21 ec 10 c1 3f 24 79 03 7c 42 b5 05 df 32 bf ea 25 18 30 5a da ee 34 28 e8 63 58 c1 ce 9c e5 c9 24 a2 28 6c 2f 94 da 75 c3 98 aa 9c 49 5c 58 c9 04 a1 2f 6e 9c a9 d4 c0 01 0f 4d 1b ef 9d e9 23 bc 14 21 6a b9 86 40 00 00 00 d7 13 a1 c8 95 07 2c e5 14 6c 05 88 2c 2e 4f fe 1d a8 a2 ee fc 3f c6 33 d9 11 7b a2 83 49 3d 23 9f fb 70 b0 08 ea 2f da 95 4b eb 0d d4 fc 90 79 f8 41 c4 b7 3d de 0e a4 bb d4 56 95 a1 b4 2f (REG_BINARY)

"4D13E0440141F4A946A15AD5D799B3182A6A7D9156"=01 00 00 00 d0 8c 9d df 01 15 d1 11 8c 7a 00 c0 4f c2 97 eb 01 00 00 00 c2 cf 8c 3a d2 c3 42 44 b9 f0 64 2f 97 f2 c7 d7 00 00 00 00 02 00 00 00 00 00 10 66 00 00 00 01 00 00 20 00 00 00 1f 07 7f e1 d2 59 d8 29 95 4a 70 a0 21 ee 16 26 63 ab f9 f0 eb 58 d2 56 27 3a 5a 97 10 ed 63 08 00 00 00 00 0e 80 00 00 00 02 00 00 20 00 00 00 ea cc 02 ed 7b 68 4c ca 0f a4 9b 6d 5f fc 41 31 eb 72 cf de 04 e4 eb f1 51 fa 46 fd ee 86 3d 09 80 00 00 00 ad 92 56 ca f3 b2 b4 32 98 3d b5 de 00 b7 b1 e1 4f 6f 3b 22 75 42 e5 73 cb ba da f6 52 16 0d 9b 0b ff 2d ae ab b7 35 6a de 68 ef 4e 4d 10 70 e6 4b 8e c4 72 96 db ef f7 9a 61 39 21 27 7f 75 6e 34 bd 6a 79 49 e2 dc 7f 89 a0 37 0b d0 06 50 52 93 54 2d 98 dc c4 3d 68 c4 a0 f9 fe 44 b8 e5 f3 7e 33 f6 f4 71 ed 4d b0 96 a5 c3 cd 3b 95 32 ce 2e 3d 0a 06 41 51 29 92 9e 70 17 86 64 cb 49 03 40 00 00 00 5d ce c3 4b 2c fc c9 24 81 fb d8 d9 9c e5 a7 cb 95 b6 d5 04 b7 db c0 73 0c 35 bf 9b 88 5e c5 6c b8 2d ce 85 ce 2b 1a 69 87 1e 2c 2c ed 5e 6a f7 fc eb 9b 1e b9 a2 dc f9 95 9c 8b 74 0d a3 35 (REG_BINARY)

"6E93C85D71708197754FB5CA3C86A5FB920D941108"=01 00 00 00 d0 8c 9d df 01 15 d1 11 8c 7a 00 c0 4f c2 97 eb 01 00 00 00 fa a3 72 49 a9 04 8c 41 b0 23 5e 0b 9e 7a ce 75 00 00 00 00 02 00 00 00 00 00 10 66 00 00 00 01 00 00 20 00 00 00 fa a7 1f 65 44 fb 3d 18 b6 60 43 e5 92 28 7c b1 a4 b3 4d 2f 78 59 77 18 aa 3f 06 8b d9 05 5d 8a 00 00 00 00 0e 80 00 00 00 02 00 00 20 00 00 00 fb 76 09 58 ef 9f 72 51 7d b5 22 a4 f7 2d 2d 4b 87 2f c4 21 af d7 fe 3f f1 84 a2 79 44 e8 6a 88 20 01 00 00 95 a3 7c 64 54 23 04 ab ed 0f f7 7c 15 84 d2 7b e6 52 4d e6 56 f7 27 ed 1f 29 da ea 99 83 e1 fc 05 f1 b2 9c 1f a1 00 c2 aa 18 33 de 47 c4 c8 21 6b 10 ad 0e 9c 5c f9 a0 f5 e6 e1 34 90 88 bd a4 71 d6 07 43 38 4a fe 11 24 13 0e 39 ba dc fe 37 d9 2b 0f 00 a9 d6 13 f8 76 80 f1 24 5d 3e f8 68 48 7f b1 7a 81 4c 1a 6d 1a 0f 1f 0c 9f 3d a0 aa ca 2c 7d 35 08 c1 4b c0 dd f2 e6 fe 97 91 51 bd 70 0b 8a d7 d2 10 fd f5 66 58 b6 f1 ae 34 b6 10 3e 55 cc 50 c4 5a 03 d8 83 39 e7 dc 7a a9 29 e8 4b 30 e4 2b 17 a5 b0 86 76 43 ff e9 6b 83 34 bc 51 d6 e3 b4 8f ed 05 9f 5f dc 5a 51 45 62 3d 10 d5 0c 0f (REG_BINARY)

"A7301AB81D7D809D725CB2004475E966776980AAF2"=01 00 00 00 d0 8c 9d df 01 15 d1 11 8c 7a 00 c0 4f c2 97 eb 01 00 00 00 7d f0 bc 5c 1d ce 57 41 b2 1b 5d c0 56 9d a6 96 00 00 00 00 02 00 00 00 00 00 10 66 00 00 00 01 00 00 20 00 00 00 59 cd 88 b0 00 35 82 90 84 1a d9 31 93 55 a7 ee 71 1f 51 b3 b4 12 a0 d2 09 93 7e 55 32 da 34 6e 00 00 00 00 0e 80 00 00 00 02 00 00 20 00 00 00 b3 2e 23 20 18 e7 08 05 f8 96 d2 59 c4 ac 72 6f e3 96 a4 6c 49 38 8e 7c df df d7 2a 3e 8e b3 a9 c0 01 00 00 de 77 b8 05 1d 6f 50 d7 b9 4a 84 7b c0 f1 b4 97 cd 76 96 e1 6a 51 d1 eb 95 98 b2 be ef 20 3a c6 18 6d 6c 4a 10 d1 3d 45 74 82 e4 81 fc c9 e0 1b 65 cb ab 9c d7 0d 28 20 20 f8 f9 43 8b 0e 1b 13 05 ad dc 8f 2b e8 8c f1 4d 77 09 f0 86 d3 c6 60 94 63 87 97 b2 b3 86 57 34 00 ce 70 af 9c 9c b2 a7 ba fb 04 af c0 53 cc 4d 3a dc 93 f2 09 7c 9b c5 56 6c cc 8f d3 ef 64 c6 7a 4a a4 d4 10 e7 c6 67 c4 d0 80 06 05 88 b3 a1 24 8f 90 68 d2 a6 4e 8c cb 42 e0 54 7a 7e d3 80 59 9f 94 4b 61 f5 a8 23 16 01 90 62 a1 da 82 c8 ff 1f f5 da 81 01 97 fe 81 59 a6 ab 77 a9 f1 b2 4d f7 ee a7 d0 1b e6 49 27 7c (REG_BINARY)

"E4C8031156725AE776172EF7EA1830E573F904FDFF"=01 00 00 00 d0 8c 9d df 01 15 d1 11 8c 7a 00 c0 4f c2 97 eb 01 00 00 00 c2 cf 8c 3a d2 c3 42 44 b9 f0 64 2f 97 f2 c7 d7 00 00 00 00 02 00 00 00 00 00 10 66 00 00 00 01 00 00 20 00 00 00 fe 70 1d 86 73 0d bb 58 63 11 6c 3e a9 33 c9 38 19 77 38 3f b5 21 ea f2 09 30 4f 53 88 a8 35 51 00 00 00 00 0e 80 00 00 00 02 00 00 20 00 00 00 0d b6 6a 44 f0 b7 69 03 86 6e 9c 89 ca 57 2d 29 dd 40 12 1e 51 da dd b8 a0 5c 91 5b 25 59 c6 45 50 00 00 00 05 2c 77 af a3 94 08 c0 39 21 28 8d 55 0f 91 9d b5 89 2e c5 c5 73 97 16 c2 f1 11 60 fb d8 5f 72 33 0e f1 f7 d7 21 c0 26 f8 89 62 c3 02 15 bf 6a f1 36 f3 74 49 1e 0c 9c 54 a9 fb 32 d0 b9 a3 54 53 9c 93 26 db e6 5f 15 14 b9 14 df d8 15 bc f3 40 00 00 00 89 84 e2 f8 d4 6c cc f3 d1 56 9b f2 60 ee 85 d8 d5 6d cb 93 cc 50 cd 91 4d 58 c7 22 50 8b 1b 99 ec e3 8a 97 47 79 6a 5c d1 e2 cf 6a bd 1e 66 de 5a 19 3d 4c 91 47 f0 2d 64 08 b2 ef dd 02 0b 34 (REG_BINARY)

"37ADB64C2CDA898AC56C464BD00BAFF748AC1E267A"=01 00 00 00 d0 8c 9d df 01 15 d1 11 8c 7a 00 c0 4f c2 97 eb 01 00 00 00 c2 cf 8c 3a d2 c3 42 44 b9 f0 64 2f 97 f2 c7 d7 00 00 00 00 02 00 00 00 00 00 10 66 00 00 00 01 00 00 20 00 00 00 64 d4 61 ae 2a d5 2c 16 e7 b9 63 a0 d0 eb 6b 7d a5 28 b4 04 b6 a4 85 75 68 cb e0 99 ef 15 dd 59 00 00 00 00 0e 80 00 00 00 02 00 00 20 00 00 00 61 12 cc 28 ff e3 b0 06 16 78 f7 98 7d df 63 b4 48 1c 0b 69 93 45 0f 8c 06 f0 59 db 51 2b b0 62 60 00 00 00 b4 5b 75 0d 1f 34 5b 63 31 2e 37 96 b5 94 88 ab e0 6b 3b 42 d9 e9 70 eb d6 a3 26 05 f7 40 cc 3f 26 15 fa af fe b2 af 71 94 b1 4c ce 1b fa f0 7b c1 1d d3 6c b8 a7 c7 59 ee e1 9f 77 bf c6 10 ac 2e 36 d9 bb cd 7a ca f3 87 8d 66 87 98 33 42 3a c5 fd 48 e0 c9 9d 98 64 dd 09 17 66 17 79 d6 ff 40 00 00 00 11 6b 7b c9 33 b6 07 76 ac d9 70 37 a7 aa 18 ef ca 28 72 eb 19 36 b6 b9 66 d1 1f 82 45 67 2c 06 18 24 0f ba 15 0f 95 f1 b8 6a 2a 7e 6d a9 18 0d 2f 33 15 0c d5 c1 df e0 a1 8d 75 d2 70 dc ad 2f (REG_BINARY)

"BEE9113CBB15337F699571D41E7D887DDF37055CD0"=01 00 00 00 d0 8c 9d df 01 15 d1 11 8c 7a 00 c0 4f c2 97 eb 01 00 00 00 c2 cf 8c 3a d2 c3 42 44 b9 f0 64 2f 97 f2 c7 d7 00 00 00 00 02 00 00 00 00 00 10 66 00 00 00 01 00 00 20 00 00 00 2a 37 ee 95 a5 70 b0 28 cf 2c 6d 57 20 bb 31 ac c1 27 36 08 25 bc ad 71 6b 02 c8 56 ea 00 6a ac 00 00 00 00 0e 80 00 00 00 02 00 00 20 00 00 00 84 eb 15 80 a4 32 ea 9c 61 1a cc 33 90 8a a5 d2 b9 ac 9c ad 1d 71 34 f4 cf 2f ad e1 35 53 b6 55 50 00 00 00 ec e5 75 9d af 33 02 e4 e2 6d 18 08 4b a6 d3 ce 5f 65 d5 7e 91 2a fd e2 db 65 26 dd b9 db b6 01 47 0a eb 1f aa f1 3e 45 9c e1 2e d7 7e ea ca 63 71 d1 11 2a 3c f1 bb 02 87 a1 44 48 5f 7a a8 43 6b 61 ab d0 71 a0 47 00 68 c3 20 9b c3 53 73 49 40 00 00 00 23 36 9f ac ea f2 bc 32 35 34 86 1a 13 de 5e a9 37 6b 87 74 77 82 a3 09 7d cd fd e5 a5 85 5a d2 f9 0e 22 bb 29 7a 21 0f d7 81 ea 27 75 43 50 7d 43 b6 3c 47 df b5 97 51 29 9f a8 ca 55 37 59 6a (REG_BINARY)

"F10FD9E6D178A4A9BB12FCD905C528678472F70F4C"=01 00 00 00 d0 8c 9d df 01 15 d1 11 8c 7a 00 c0 4f c2 97 eb 01 00 00 00 c2 cf 8c 3a d2 c3 42 44 b9 f0 64 2f 97 f2 c7 d7 00 00 00 00 02 00 00 00 00 00 10 66 00 00 00 01 00 00 20 00 00 00 47 33 e0 71 86 d2 ab 0e c1 91 8f ab 1b 34 66 bc 97 76 9b c1 65 5d eb d3 82 2a 0d cd f1 e2 52 bf 00 00 00 00 0e 80 00 00 00 02 00 00 20 00 00 00 4b 93 a0 12 a1 67 b4 a3 86 66 0d 93 40 ab 84 aa 1d ab 20 37 88 54 20 5c 62 00 43 b5 79 bc d8 7d 50 00 00 00 0c e1 b0 57 ad fd 20 c4 07 2f 38 41 9d ba 71 25 38 33 10 c4 49 1b 4b ce a7 6a 79 e7 aa 3f 65 67 67 13 c7 01 ad 9e 0f b9 c1 c5 9a d2 c1 9b ed e2 30 33 ac d0 33 3a c9 95 70 7b 65 9b d2 3b 0f 42 42 3b e1 2d 24 e4 8b 30 ed d6 89 47 79 04 6a a6 40 00 00 00 3b ab 9a 99 8a 71 81 98 6f 7b 59 28 e9 e2 89 00 89 89 dd 8d a8 9c 74 ab 1d 3b 7e 90 c3 c9 d8 d0 16 bf 43 09 e0 dd 67 d4 78 8c 3d 22 98 0c ba 37 51 ca a9 66 3c 41 bb b3 7b 89 62 c5 9b 89 09 1d (REG_BINARY)

"CCE7D6897E34A3152B11E238F315AC9BE45C397610"=01 00 00 00 d0 8c 9d df 01 15 d1 11 8c 7a 00 c0 4f c2 97 eb 01 00 00 00 c2 cf 8c 3a d2 c3 42 44 b9 f0 64 2f 97 f2 c7 d7 00 00 00 00 02 00 00 00 00 00 10 66 00 00 00 01 00 00 20 00 00 00 1f 56 92 aa ea 83 a9 d2 00 a6 c8 57 9a 86 c9 83 a4 5f 67 eb ae 01 27 67 d9 fd 3e a4 65 c4 b2 6a 00 00 00 00 0e 80 00 00 00 02 00 00 20 00 00 00 2d 2b 3b 0b 5e 37 06 ba a7 71 9b b9 57 ec 3e 21 45 67 8b 92 d8 58 fc 7a bf 1a 2b c8 dd 1f 32 73 40 00 00 00 c6 3d 0a 4c 82 1a 9a ff 81 12 0f 6c 0e ee 8c b0 6f f6 b3 7e 1a 4b b7 68 46 e7 0f 25 c2 1d 8b a4 47 d4 55 4e 76 a5 e1 47 53 9f ee 01 49 7a 67 1a e6 fe fc 4f 85 67 2f a0 c6 20 f9 39 95 98 e0 20 40 00 00 00 58 f8 a9 ff ae 3e 81 71 ff 8a 60 16 38 d7 b8 9c fe 11 a4 05 80 06 3d b8 27 03 f6 ee 46 36 c1 18 b3 51 0b 61 4c 13 d8 1d 00 3b 77 f9 08 e4 bb f5 0e 5d b6 e6 10 d4 93 8f 2a 20 f6 a0 58 bc 4e 67 (REG_BINARY)

"DD043914DD02231ABE7740D90D427B313E31FDACAB"=01 00 00 00 d0 8c 9d df 01 15 d1 11 8c 7a 00 c0 4f c2 97 eb 01 00 00 00 c2 cf 8c 3a d2 c3 42 44 b9 f0 64 2f 97 f2 c7 d7 00 00 00 00 02 00 00 00 00 00 10 66 00 00 00 01 00 00 20 00 00 00 66 36 3a 18 2d aa 32 a7 5e 27 c9 84 b5 71 ab 8d 2c 49 54 e4 8f d0 d9 38 63 f1 1d 8c 86 7a b1 60 00 00 00 00 0e 80 00 00 00 02 00 00 20 00 00 00 43 e7 13 95 c2 32 f8 02 ba a3 03 7e 40 73 a5 44 18 6d 31 a1 c5 d1 56 b1 5e 2f ae 99 16 87 e1 d8 50 00 00 00 4b ac ea 98 30 72 de 10 15 47 a1 b8 58 b6 33 07 7b 3e 13 ef da da c6 55 1a fe cc a0 6f 3d e8 0d 17 d4 8e b5 ee 9c 73 3b 01 13 da e8 e4 09 ac 73 89 be 42 7d 73 fd c2 62 d7 54 0a 57 fb ca 7d 20 f7 60 d4 f6 b0 cc cf ca 03 44 c2 65 a5 d7 d9 19 40 00 00 00 c4 61 63 5f 20 ca 54 8d 75 ac c4 27 6d d3 92 b3 61 9f f3 97 51 d2 fb 4f 51 57 a2 c6 60 d0 11 6e 4b 84 5b 09 7a 0a 69 c8 56 02 ab c9 cf 4d 59 d5 d9 5f dc 49 f1 c8 5e 03 c4 17 6d 93 21 12 c7 ba (REG_BINARY)

"72B9F7879945CD82128EA98C1A81E14CF92DF9DC6E"=01 00 00 00 d0 8c 9d df 01 15 d1 11 8c 7a 00 c0 4f c2 97 eb 01 00 00 00 c2 cf 8c 3a d2 c3 42 44 b9 f0 64 2f 97 f2 c7 d7 00 00 00 00 02 00 00 00 00 00 10 66 00 00 00 01 00 00 20 00 00 00 18 df ed ef 5b 09 35 b7 82 de b3 c4 e3 a4 30 c7 e2 6c a1 60 e4 06 19 64 6b 1a 19 c9 ac 43 48 b4 00 00 00 00 0e 80 00 00 00 02 00 00 20 00 00 00 af d7 95 f6 d6 cf c6 c7 2f c9 3e 2c 34 14 da d9 65 35 aa db a4 93 b7 98 ee b2 05 65 f5 5e f4 17 40 00 00 00 7d de 9c 23 f2 c6 71 f6 56 67 5e 2f 30 66 50 8c 37 bc 0f d3 c6 54 49 2f 52 5a 60 3f 03 79 5e 75 d4 fb 95 c3 0e 31 aa e7 6e 89 e0 b3 d7 41 0e 3b 06 c8 2e 1e 68 2c 52 77 2b 8d af f2 95 cc 61 21 40 00 00 00 4e 71 9c 32 48 62 b8 17 0b f8 3e 74 93 f4 38 ad ce 83 6b dc a1 96 43 dd 8a fa 73 b2 74 36 5d bf 05 9f 60 3f b5 a9 31 55 30 b8 ab 9e 72 58 8f 83 f8 3a a1 4c 4f f2 9b 2d 8c b7 f2 c2 a6 91 f0 18 (REG_BINARY)

"67027095D7C972F0846B26C33A9F1F2B488135D23B"=01 00 00 00 d0 8c 9d df 01 15 d1 11 8c 7a 00 c0 4f c2 97 eb 01 00 00 00 c2 cf 8c 3a d2 c3 42 44 b9 f0 64 2f 97 f2 c7 d7 00 00 00 00 02 00 00 00 00 00 10 66 00 00 00 01 00 00 20 00 00 00 3e 1a 63 c6 55 b1 57 53 f6 50 fe d1 af 91 06 84 ca ad 0f 16 04 5f f7 38 99 b9 18 52 4e ef 5b 22 00 00 00 00 0e 80 00 00 00 02 00 00 20 00 00 00 db 27 4d 42 4c 91 04 58 20 31 72 de 34 ee 49 17 b6 36 98 5e 39 c4 fb 7a 67 3d a0 8b 61 c6 76 a0 40 00 00 00 8d ea 9c f5 53 6b 4e 4b c5 02 28 71 80 2e 7b b1 06 f8 25 32 a7 4c 64 f4 f2 16 df 50 48 74 b6 f7 46 95 1c f2 28 5b 5e c5 5f 5c f8 a7 8e cd 14 e9 cf b3 8e 17 cc 72 8c 4f 15 25 b6 51 90 77 d5 0f 40 00 00 00 72 d3 cb c8 33 be e9 a9 0a ef e7 26 45 e3 86 22 5e 7c 45 19 10 c4 c6 22 5a fa db ad 9a fa ca 50 4a d9 d2 db 02 df d8 60 73 67 64 ca 63 4d 1a 84 0b 6e 32 22 ce a3 34 e3 8b 87 b3 6a 61 c4 f9 23 (REG_BINARY)

"4A08BFF993FEB540429405C15C0AB12E10B9AF3E27"=01 00 00 00 d0 8c 9d df 01 15 d1 11 8c 7a 00 c0 4f c2 97 eb 01 00 00 00 c2 cf 8c 3a d2 c3 42 44 b9 f0 64 2f 97 f2 c7 d7 00 00 00 00 02 00 00 00 00 00 10 66 00 00 00 01 00 00 20 00 00 00 40 b9 2a 27 30 70 c1 95 4b e2 2d 95 db 5a ab 78 51 91 ec d2 91 97 07 35 65 2b f1 ad a7 2d ce d1 00 00 00 00 0e 80 00 00 00 02 00 00 20 00 00 00 3a 46 87 63 96 e7 f6 7e 3b 22 7c 7b 4a 27 ad e9 db cc c7 4f 46 c9 ca a9 79 82 4b bd 61 42 76 77 40 00 00 00 13 fb 12 ff 9f aa a3 d2 d2 4c 74 09 79 37 6f dc 6c 7b ac ca eb a0 9f 2d 5c c2 31 6d 73 36 c1 48 74 b5 21 22 35 db 71 28 f9 da 1a dc 53 a8 32 4b 3c c4 af ce 99 7a 1e 93 97 09 b0 d0 a5 8c 17 f4 40 00 00 00 9f f9 cc 31 a4 c9 66 00 56 2f 1a 43 b6 82 66 09 03 b3 88 8a a5 29 1f a3 0d 3f ac 86 aa c9 4e 8d 89 b6 86 c7 75 b1 f7 0d 74 59 c0 31 9f 36 7b 73 5b 0e 7c 95 27 44 d7 d6 ed eb 67 9f 31 a7 c4 00 (REG_BINARY)

"48AFA9E93B9296921462981A85E8595849AB1F15EC"=01 00 00 00 d0 8c 9d df 01 15 d1 11 8c 7a 00 c0 4f c2 97 eb 01 00 00 00 c2 cf 8c 3a d2 c3 42 44 b9 f0 64 2f 97 f2 c7 d7 00 00 00 00 02 00 00 00 00 00 10 66 00 00 00 01 00 00 20 00 00 00 ef 56 64 96 37 ac b8 36 b0 af f9 77 50 3d 6f c2 8f d1 09 7e 96 c9 a5 2c 5b d4 5b c2 2e de c6 6f 00 00 00 00 0e 80 00 00 00 02 00 00 20 00 00 00 75 83 c9 88 63 0c 4e f0 59 50 d2 be 95 03 c9 76 dc bc d1 5b af 9c b7 e5 f7 8b ca 9b a3 bc 8b b0 40 00 00 00 7f c7 e2 2f a8 cc 79 42 8e e1 33 f3 b5 bd 92 e0 70 81 d2 4e 28 42 45 1b ea 21 e4 eb b7 01 ee 3f 9d 45 e7 57 9c f0 91 cb b2 f6 77 d8 e8 27 62 28 32 8e 72 7b be 77 ae 81 eb 10 85 70 fb 2b 82 ed 40 00 00 00 ea e5 45 c8 fc 68 c4 11 1b 53 6a 20 68 e6 62 f8 be 15 53 ff bc 88 c8 bd 17 a4 d8 4c d1 01 92 ba 5f cd 4d 39 9e d3 1c 5e 0b 02 23 6d 63 d5 f2 2a d9 bc ef 27 32 a6 83 69 ee 51 b6 90 80 3d 2e 0d (REG_BINARY)

"D3C90BA40F9C3A2AF77BBF0C5C249A980BDF742DD4"=01 00 00 00 d0 8c 9d df 01 15 d1 11 8c 7a 00 c0 4f c2 97 eb 01 00 00 00 c2 cf 8c 3a d2 c3 42 44 b9 f0 64 2f 97 f2 c7 d7 00 00 00 00 02 00 00 00 00 00 10 66 00 00 00 01 00 00 20 00 00 00 eb a9 e2 1e b0 11 45 44 19 fb 5a be 75 d6 de 97 08 30 27 25 43 02 da 38 ac 0e b6 b4 1c ee 73 c5 00 00 00 00 0e 80 00 00 00 02 00 00 20 00 00 00 7c cf fe a6 58 32 24 26 08 8c 13 69 6b fa 54 a0 99 44 a1 24 70 23 56 70 ca 7a 0f 56 40 78 aa bc 60 00 00 00 bc 60 0d d8 97 40 ad 85 d1 e8 70 9d 85 e1 dc 83 6d 53 f0 d1 1f bf 80 f5 72 66 a8 97 3e 21 41 87 25 25 9f 00 29 1c 20 60 cf 42 f4 49 11 36 56 b9 bc 38 46 1c 02 a8 59 00 d6 1c c7 56 27 fa dd 38 72 01 33 99 d4 88 ff f5 1e 99 50 c8 99 02 58 b8 51 22 2d cd 1c 80 0b db e2 62 49 7e 04 71 e4 ea 40 00 00 00 1e 04 ea d6 63 cd df 99 89 30 53 80 3d 8d 45 33 82 1b f8 67 fa 93 84 1c 2b 1f 13 dd 76 c5 47 55 40 a2 3d 01 e5 2b 3f 02 c3 ea 30 ba db d7 ab d7 e9 fa 14 06 c6 69 2a 98 83 54 e4 be 72 40 47 06 (REG_BINARY)

"A85DB3B00F8E4C2E6C71ADF6B7791E6E6A6B664238"=01 00 00 00 d0 8c 9d df 01 15 d1 11 8c 7a 00 c0 4f c2 97 eb 01 00 00 00 04 ae 72 13 3a 84 f1 4a 99 2f 70 e7 3b 78 23 f2 00 00 00 00 02 00 00 00 00 00 10 66 00 00 00 01 00 00 20 00 00 00 08 54 c0 01 7b 76 b0 a0 d0 6a 4a 0a 35 13 23 fb 83 a8 c8 7f db 5c ba 07 f8 a0 df 08 26 92 c7 7c 00 00 00 00 0e 80 00 00 00 02 00 00 20 00 00 00 a1 ea 79 74 86 44 60 13 92 f6 77 92 cc 2c a5 45 d3 99 4a 2b c5 9f 84 ab cb 87 d1 9c b5 2b a6 41 90 00 00 00 da 17 d4 c9 a2 5b ff a9 47 79 63 9f 87 df 8d ac 08 38 19 d1 bb 34 8c 8e 8d 89 84 fd 8a e8 71 b5 b9 c7 55 3b 73 7e 8e 73 d2 46 99 64 41 7f 3b 8e ea 6f 0f e1 e9 68 7f 6f f7 3a a4 02 47 4c 80 96 50 d4 2f 4f aa 89 8d 46 c8 34 4e e7 ba b3 56 28 76 fc 61 8a 3a 72 1c 3c 4a 76 e2 30 7f 8a a9 94 11 c6 03 c2 8f b4 d5 b6 ad af bb 04 53 d4 62 b1 11 e6 ee dc 6d b0 77 d7 5a d5 a8 3e 37 70 ab cf cf 8a 73 33 d5 da 3e 53 cc d0 d2 a2 7d a6 b3 80 40 00 00 00 fa d2 03 5e 05 45 97 c2 f2 19 40 32 53 f7 a1 3f 07 b6 02 f8 69 e8 97 5e df b5 23 2f f8 0d 8b c4 3d b1 45 58 50 b5 a2 e3 db bf e6 cf a6 f6 55 (REG_BINARY)

"280960C8406F5B54472F854047DC521120CFA69BA8"=01 00 00 00 d0 8c 9d df 01 15 d1 11 8c 7a 00 c0 4f c2 97 eb 01 00 00 00 c2 cf 8c 3a d2 c3 42 44 b9 f0 64 2f 97 f2 c7 d7 00 00 00 00 02 00 00 00 00 00 10 66 00 00 00 01 00 00 20 00 00 00 10 4f b5 79 f3 76 0a 6b cc 4d 22 c7 f3 31 95 1e 20 5c 2a a6 8b 71 85 15 8f 06 ea ed 67 13 8a 18 00 00 00 00 0e 80 00 00 00 02 00 00 20 00 00 00 ad 7b a0 47 83 80 54 1e cf 0b 0a 39 88 6f f5 83 f0 a3 c0 f9 15 c5 0a a3 4c b6 bc 28 13 d1 b0 ec b0 00 00 00 26 1f d0 1e 9d e5 0d 76 30 40 1e 12 09 81 ff a6 b0 d0 f7 8a f0 68 5e b6 5f db 18 23 76 37 36 e8 e5 ad cc 32 25 23 02 1f 13 5b 7c 30 9b 2c 7f 65 c1 4f 60 a8 d3 b0 4e 55 10 1e 15 f5 1d 85 2b e8 12 9f ee 43 6e 85 0a 3c ff 1d 4f b0 fc fc ae 8e 98 2d da cf 60 66 b4 30 a4 76 02 31 54 b6 51 40 6e f9 ce de 9c b2 ed 92 58 24 3e db 3b 68 7c 87 3e 53 e1 66 fe 7e 62 59 79 49 43 6c 4d 92 63 24 d7 73 e5 a1 50 2f c0 a9 9e ca 6d 82 b1 c2 99 f9 b4 af e7 ec d7 8a 1b 2b ce 8b 3d af ca 03 21 9c 06 b4 15 09 c0 2b c5 e7 f4 c4 65 cb d4 9c 02 27 40 00 00 00 10 4d 30 17 39 3d eb 9c 9f a3 69 c1 98 ac 2e (REG_BINARY)

"0BA59E6EA4F2E8C97BA317DBCEAE25A2847A942B13"=01 00 00 00 d0 8c 9d df 01 15 d1 11 8c 7a 00 c0 4f c2 97 eb 01 00 00 00 c2 cf 8c 3a d2 c3 42 44 b9 f0 64 2f 97 f2 c7 d7 00 00 00 00 02 00 00 00 00 00 10 66 00 00 00 01 00 00 20 00 00 00 e8 b5 77 77 e6 a1 bf f3 b4 ce db f7 04 b3 5c 94 7c 6b 72 b1 50 29 df 3a 9e 17 b8 df 27 aa ed 51 00 00 00 00 0e 80 00 00 00 02 00 00 20 00 00 00 4f bc b7 7d 44 37 bc 6c 85 9c 99 0c e5 58 02 0c c8 f7 25 7f 25 9b 8e 1c d2 c2 2d 07 fc ec b4 9b 50 00 00 00 f0 fb 56 a8 72 c2 92 d7 f4 5d b3 f3 20 f5 68 e1 da f4 c1 de 3f 59 d4 c8 77 2c 55 30 d7 ea 7c c4 7d 4a 29 ad ca 25 c7 c6 51 d5 3f 49 49 f5 83 b1 f3 66 2d e5 38 d1 ff 04 f0 ab 61 37 35 ef d0 d1 55 7b da 68 56 14 7b a8 8c 48 96 33 08 cf 82 27 40 00 00 00 f5 91 4a 97 36 fe d4 55 7d 03 ce 15 51 5d ea da 4a ee 2f 9b 86 84 85 f1 22 39 97 d2 ef 45 af ea fd bc 45 08 ba f6 0b 47 f0 53 5e ad 53 e1 11 72 d9 a0 08 6c 59 c7 a1 14 78 0b 74 b0 99 c3 00 88 (REG_BINARY)

"710D91E52989D9063F237E934DFB5B9A1208775B21"=01 00 00 00 d0 8c 9d df 01 15 d1 11 8c 7a 00 c0 4f c2 97 eb 01 00 00 00 c2 cf 8c 3a d2 c3 42 44 b9 f0 64 2f 97 f2 c7 d7 00 00 00 00 02 00 00 00 00 00 10 66 00 00 00 01 00 00 20 00 00 00 22 60 b9 4c 9b af 66 62 44 c3 b6 ab a3 02 0d 6b c2 aa 73 30 f2 92 00 0a 14 f9 c2 40 bd 6e 47 28 00 00 00 00 0e 80 00 00 00 02 00 00 20 00 00 00 5c b2 ac fc da 74 cd 3e f7 69 cb aa b7 fb 62 d1 6b 2f 90 74 9c bd 91 83 e7 3d d9 34 ac 66 36 14 60 00 00 00 55 8b 94 94 b6 5e 0a 21 34 5b 25 08 9b e9 d7 34 ff 3a d6 5f cb 5d 08 fd d6 64 93 36 b2 64 0d d9 46 9b ae 74 34 50 96 01 e1 46 d4 42 98 ec ad 51 bc d2 ab 24 60 9d da 67 a3 ef d7 ad 9c 84 0c 5f a3 79 6a f1 41 9b dc b5 76 07 15 75 de 42 95 d0 65 af 0f 5c ac 8e 85 45 02 38 eb 6b d9 a3 dc 32 40 00 00 00 91 6d 3e c0 8e f6 fd d7 bf 87 54 06 3a 8a 60 fc 52 75 57 8f fd a0 45 b9 9c b3 4e 57 e1 19 6f 18 a1 5b 9e 47 16 99 81 94 ac e6 2d b4 55 fa 77 60 61 3b 22 b7 f1 ea 7d 24 70 12 df d8 66 48 be 44 (REG_BINARY)

"3EECBED6028B282FE1E7A5299DE569434BAEE41558"=01 00 00 00 d0 8c 9d df 01 15 d1 11 8c 7a 00 c0 4f c2 97 eb 01 00 00 00 c2 cf 8c 3a d2 c3 42 44 b9 f0 64 2f 97 f2 c7 d7 00 00 00 00 02 00 00 00 00 00 10 66 00 00 00 01 00 00 20 00 00 00 6b 04 4e 5b 4a 43 83 39 91 65 9c 50 55 6e 98 dd b5 94 0d 97 28 04 71 ce ec bc 75 55 0f e2 51 80 00 00 00 00 0e 80 00 00 00 02 00 00 20 00 00 00 34 a2 f1 ce 42 d3 31 be 9f c9 9c 9c 5e 25 84 92 77 fa 97 af d9 67 be 17 b5 a8 13 37 6f ac 81 51 50 00 00 00 8f 1c 19 9d a9 d9 60 45 d0 c0 ba e4 05 e6 9f 85 f2 b2 d2 2b 22 d0 62 4c 8b 60 f3 47 0e f4 5b 6e e7 9c ea b5 08 1b 38 7a d3 ec 47 d6 66 ed 90 86 9c 8a 21 ee 86 74 4f 58 d2 15 2e d8 bc 39 bb 0e fc 13 df 36 0a 61 8d ff 0a 9a 52 e5 72 d3 a8 f2 40 00 00 00 bc 3b 6e 59 c3 f2 11 21 81 95 e7 fa d3 b4 4e 73 96 a9 93 7b 9b fd c0 11 4f b2 db e0 42 8a d5 c2 eb 4a 7b 98 bb f9 79 c2 b2 c1 ff d0 95 87 a3 97 16 e2 a7 6d 8e 19 ca b6 3b 72 8c 86 84 8c 5f 82 (REG_BINARY)

"047B0A999BE29C6465483501EA4893E81978A395F8"=01 00 00 00 d0 8c 9d df 01 15 d1 11 8c 7a 00 c0 4f c2 97 eb 01 00 00 00 c2 cf 8c 3a d2 c3 42 44 b9 f0 64 2f 97 f2 c7 d7 00 00 00 00 02 00 00 00 00 00 10 66 00 00 00 01 00 00 20 00 00 00 15 53 bd 12 ac d2 3d 07 46 5b cf f1 54 04 cc 59 d9 fc ad b0 70 e0 82 8d 71 c9 cf 07 a6 84 26 a4 00 00 00 00 0e 80 00 00 00 02 00 00 20 00 00 00 4a 4c 0e 66 c4 aa 74 be 6e 42 17 9a 5c de 83 28 46 dc 76 4f 0a ab f8 b8 6a 8c 5c 01 4a 40 1e 92 50 00 00 00 c3 d1 e8 74 af a4 c0 e8 56 9f f6 6d 11 30 7b 35 18 89 b2 9b 79 d7 c8 c2 74 db 94 e3 25 4a a2 df 81 92 84 b5 71 b1 2c bd 51 29 66 11 b2 22 98 ff 9d a2 b3 5a fd ce d2 f0 99 46 de a5 0f ca 27 46 15 b3 12 b2 d0 c8 5e 87 25 bc e9 30 5d 3f c8 36 40 00 00 00 08 f8 0d ee de eb fb ef 2b 3c 12 98 2b cc f6 fc 11 55 64 e8 9a 86 28 15 bd 91 3d 61 a1 0c d8 11 dc a4 e3 42 c9 24 fc 0d 32 36 04 83 62 bb e1 08 67 3d fb 8e 1c 48 99 b2 22 26 7d 24 0f 64 55 26 (REG_BINARY)

"18F22D7CD3BBAEF4D6D1C9BF29FE5EC3BFB0404D56"=01 00 00 00 d0 8c 9d df 01 15 d1 11 8c 7a 00 c0 4f c2 97 eb 01 00 00 00 c2 cf 8c 3a d2 c3 42 44 b9 f0 64 2f 97 f2 c7 d7 00 00 00 00 02 00 00 00 00 00 10 66 00 00 00 01 00 00 20 00 00 00 71 e6 85 24 92 59 6e 5a 44 0d 88 d9 8c 8d a9 dc 68 dc ae 56 b2 95 34 ce 86 a0 01 45 3c 53 94 c8 00 00 00 00 0e 80 00 00 00 02 00 00 20 00 00 00 8f 91 86 55 12 0f 98 02 68 37 17 09 f3 da 1e a1 a9 d4 78 c2 5c ab c0 ed 76 9c ed 28 0c a4 60 60 50 00 00 00 fc 99 9d b2 42 c5 09 a3 fd 56 33 9d e1 c8 3f b7 13 1b d0 50 3a fb f2 07 a2 ba f9 eb be bb fd cc ab 17 c9 46 b2 31 78 ef 10 e0 60 dd b7 bb e3 9d 70 47 17 e6 58 77 df 6e 7c b0 d2 66 85 a8 41 e0 cc c7 f5 ff 2e ff a5 23 96 a4 cc 6f 45 bb 3e 5a 40 00 00 00 e2 45 58 54 ae 81 96 28 4b 63 bf 79 fa bc 55 a8 ef 65 71 3b ed be 14 c5 41 13 e2 8c 1a d3 e5 6e 23 b7 86 2e 8e 4c e6 9a 64 81 8e 84 61 6b 1b d9 51 c9 c4 fe c8 c0 af 59 73 be c8 ac d5 b8 d3 ee (REG_BINARY)

"7DAC7BC00FAF594202F3D0B9F92C48F45B0066F956"=01 00 00 00 d0 8c 9d df 01 15 d1 11 8c 7a 00 c0 4f c2 97 eb 01 00 00 00 c2 cf 8c 3a d2 c3 42 44 b9 f0 64 2f 97 f2 c7 d7 00 00 00 00 02 00 00 00 00 00 10 66 00 00 00 01 00 00 20 00 00 00 50 ee 8f 01 26 39 f3 51 95 42 87 1d 70 53 2d b1 c5 1e 2b 47 d5 fd 44 ed 27 dc 47 f6 c5 2a 1c 6d 00 00 00 00 0e 80 00 00 00 02 00 00 20 00 00 00 6a 6c b4 7a a5 5e e4 3b 3e d2 56 43 b2 d5 e7 69 06 ac 40 32 1b 9a fc 2e 58 e9 70 6b 41 80 75 8a 40 00 00 00 6f 63 cf 54 48 e1 b8 42 24 46 e8 11 ce bb 1a 68 57 5a 26 97 1b d7 b6 57 a9 8d 78 90 85 92 81 18 41 fe 65 02 63 99 e4 de 3f 37 a5 3b c1 5d f9 4b e0 ce c0 b1 ae 42 0c ed 69 21 4c 09 02 8b 8a a3 40 00 00 00 69 9c 85 87 93 ae 98 98 64 82 d5 42 ad bd db d7 e5 0c 55 69 71 08 e9 4f c4 8f 35 6e d3 c2 78 d2 5f 45 ba 25 97 ca 00 40 06 26 bb 96 35 2d c1 ec 5f 90 11 c4 d9 6f 6c 74 a9 05 d5 c5 51 bd 15 6d (REG_BINARY)

"9A487C01AF93AEF3F218373ED252D45069BAD6C0C2"=01 00 00 00 d0 8c 9d df 01 15 d1 11 8c 7a 00 c0 4f c2 97 eb 01 00 00 00 c2 cf 8c 3a d2 c3 42 44 b9 f0 64 2f 97 f2 c7 d7 00 00 00 00 02 00 00 00 00 00 10 66 00 00 00 01 00 00 20 00 00 00 da 7f d1 31 24 fd 5c 48 a1 10 76 d0 62 f1 bd c9 b3 30 0d f1 77 2a 0a a4 7b 63 70 13 c9 84 26 ae 00 00 00 00 0e 80 00 00 00 02 00 00 20 00 00 00 ff e5 af fb a1 2d 0e d3 b0 ab 67 e9 54 78 d2 03 09 31 f5 23 76 4f 11 7e 9f f8 1f 7c 5a 9d f4 51 60 00 00 00 f1 57 e4 c6 c4 4e 84 94 30 ec 55 df 73 5a f1 ec ba 49 02 50 60 19 69 b3 de 3e fc 04 46 36 1e 40 d1 c4 65 31 3a b0 84 ed 4f 09 f9 85 c1 f5 8e 52 90 bc 57 16 fe 3e b3 7b a2 e3 9b d3 24 81 a1 51 73 a0 34 a4 fd 9b 36 5c b3 64 25 50 4d c3 54 3b 4b 3b 90 b6 f8 c3 da bf 75 78 f8 9c c6 81 a1 4f 40 00 00 00 eb 56 dd cf a8 f0 fd bf 06 89 cf 21 bd 7c dd c0 7c 1a 51 c3 9a f7 89 90 46 87 cd 71 17 a0 55 68 dd 04 88 0f f7 81 6d 69 3c d9 ad bd 31 bc 28 44 3b a3 c7 01 77 39 fc 5a 9b 1c 13 95 91 bd cb 5d (REG_BINARY)

"277687B2398A1345F223BE0F0889717B4494E7B5C4"=01 00 00 00 d0 8c 9d df 01 15 d1 11 8c 7a 00 c0 4f c2 97 eb 01 00 00 00 c2 cf 8c 3a d2 c3 42 44 b9 f0 64 2f 97 f2 c7 d7 00 00 00 00 02 00 00 00 00 00 10 66 00 00 00 01 00 00 20 00 00 00 aa 87 2c 45 94 73 76 44 61 50 2c a1 46 8f 1c 65 f3 40 62 f2 37 56 fd af a0 9e 8c 83 f5 dd 3c 0b 00 00 00 00 0e 80 00 00 00 02 00 00 20 00 00 00 7c 28 38 c1 44 52 a3 27 6e d3 6f ff 84 9c 4e d7 9e c4 49 df d7 c9 d4 57 e6 81 7b e3 bd d3 c0 98 a0 00 00 00 e3 07 97 08 81 6e 22 b0 9e 93 46 8e cb 1b 62 30 2c f4 f7 c5 22 cc 8d f2 69 3d b8 17 3d 20 8c 5e 61 88 5b 4b 38 ad 7d a1 63 0e d5 6d 99 46 f2 a5 ba f9 26 c9 b8 74 49 c3 f9 07 68 24 89 d6 87 5e c8 fc 18 f9 92 9b aa 62 06 bf 7f ba a3 a3 0a 58 62 b3 21 63 82 64 32 4d 97 89 af dd 2f 8d 7e 50 eb 61 15 c4 1a a0 d2 67 93 f9 0d a0 c4 ec 0b 76 4f 87 f4 f6 f8 26 c6 5e 59 0f b8 43 ee 65 59 1a 2e f9 f0 96 17 6a c4 80 ad 0b cf fd 80 c6 10 fc 08 ab 4c 5f 69 c3 d8 bf 56 ea 96 4e 40 d6 f8 9c 40 00 00 00 51 ee ec ed d8 58 d8 dd 87 b6 c9 68 6b 8b cc 33 5b 08 08 c8 80 99 7e 43 89 26 35 7f 86 a6 fd (REG_BINARY)

"90D5C215D3DA44C6D0D6B7E9FD3CA053A5EFBEF1A8"=01 00 00 00 d0 8c 9d df 01 15 d1 11 8c 7a 00 c0 4f c2 97 eb 01 00 00 00 c2 cf 8c 3a d2 c3 42 44 b9 f0 64 2f 97 f2 c7 d7 00 00 00 00 02 00 00 00 00 00 10 66 00 00 00 01 00 00 20 00 00 00 b1 a9 7e b2 31 5e ce 5a 8e b7 7e b1 60 b9 ff a6 bd 31 36 1a 41 b5 c9 43 c5 17 7d c3 bb e7 39 69 00 00 00 00 0e 80 00 00 00 02 00 00 20 00 00 00 da 89 d3 e0 e2 76 2b 9f 90 5c 5b c2 86 b0 e7 b5 6a c1 59 ca 1c 22 96 10 65 89 b8 ff 3a e8 5d 58 d0 00 00 00 ea b6 8f e9 87 ab b8 b4 0c 66 f1 06 b9 59 50 95 cc 08 9e eb 23 d2 b9 67 55 86 c1 ce b2 84 8d c2 47 10 3d ea 7e 00 14 75 a5 db cf 4f 29 75 60 9e 8f 2e dd c0 0c ca 4c ff 18 17 7a f1 b1 b4 8f c7 cb 30 e9 06 2c b3 71 57 73 92 93 5d aa 3d e1 22 11 f0 b9 72 a1 68 aa 92 01 2c 63 9b b4 bf 5b 26 45 99 be 3a bd 0e f7 a6 2d 76 5e f2 d5 50 1c 5e 78 4c 6e c5 bf b9 36 21 39 e9 99 a9 3d 14 c1 21 01 de c8 a7 81 e0 91 bd c4 a9 bc e6 f2 3a e5 10 04 40 3c a6 e1 f9 95 42 85 13 5e dc 29 35 f7 5e 1c ff d9 7b 5e 86 0f 85 f7 c7 09 48 24 9f 53 62 67 1e a9 b5 f7 fb 3b 55 69 f7 be 27 86 f3 5a ce 3f f1 78 (REG_BINARY)

"83EBB6A39BB833B1414D793064CB18F84F12266E69"=01 00 00 00 d0 8c 9d df 01 15 d1 11 8c 7a 00 c0 4f c2 97 eb 01 00 00 00 c2 cf 8c 3a d2 c3 42 44 b9 f0 64 2f 97 f2 c7 d7 00 00 00 00 02 00 00 00 00 00 10 66 00 00 00 01 00 00 20 00 00 00 b8 81 dd b1 99 b5 75 62 ec 55 a9 34 15 44 e3 3e 50 81 46 5a 60 c2 d8 2f ec a6 c1 46 9b 02 bc 7e 00 00 00 00 0e 80 00 00 00 02 00 00 20 00 00 00 d5 4f 70 22 e1 83 5c 08 34 f8 84 74 bd 69 3a 30 81 6f 17 60 b7 c4 42 c3 30 30 37 58 24 f0 e4 63 50 00 00 00 e0 3e e7 74 29 c5 c4 9b 38 09 de c6 d3 06 9f fd 65 57 fd bf b6 1d 65 38 4b 44 e0 23 9a be 24 e5 e6 8a 52 14 2a a4 5e 79 fe 10 55 c0 5a 2e 04 f4 8c 04 74 3c 17 e9 5d 2a 55 4d 14 36 05 e7 c9 31 98 d6 2e 01 a9 e9 55 92 cf e5 d9 d3 d3 06 e1 5a 40 00 00 00 b5 1c 63 4b 8c 8d f6 5e a6 a4 a0 e4 3e ac dd d5 d4 15 9c 37 6a be 4b 39 5e ca 2f bb 65 b6 96 56 28 eb e8 e4 f8 d6 94 de a5 55 0d 26 99 fb 2f fd f8 9f d3 b8 43 4e db d5 56 b1 c7 8b a3 17 34 61 (REG_BINARY)

"CCB7AA85A8A10855C2FD402E545B1A05776C11256C"=01 00 00 00 d0 8c 9d df 01 15 d1 11 8c 7a 00 c0 4f c2 97 eb 01 00 00 00 c2 cf 8c 3a d2 c3 42 44 b9 f0 64 2f 97 f2 c7 d7 00 00 00 00 02 00 00 00 00 00 10 66 00 00 00 01 00 00 20 00 00 00 6d 95 9e c4 70 76 b6 05 c5 1c a0 38 1f 53 46 03 c1 87 03 f3 6f 0d 2e 62 b1 5a a3 f9 19 39 d9 bd 00 00 00 00 0e 80 00 00 00 02 00 00 20 00 00 00 e5 a6 ac 94 e0 81 ff 2e ea f7 70 15 78 e5 80 af 19 a1 7d ba 7e a1 d6 89 aa ec 05 8c aa c0 41 d8 50 00 00 00 4d a2 2e d0 03 d9 26 33 f0 af 8a 7c d5 c8 5a 10 06 80 09 31 1b 82 fa 2f da 21 5d 9d 52 0a 00 42 3b 3a d8 8a 3a b8 d9 2f 48 73 12 0d 09 1f cb fe 34 e2 0f 5b 9e fc 3f 65 7c f7 7d f2 8b a2 e3 46 de 6f 36 1c f3 10 18 18 4b 31 c3 b4 be fb 94 6b 40 00 00 00 64 94 69 f0 87 75 13 5a 17 a4 5e d4 73 08 af 6c 76 eb cd f7 aa 00 3c 49 91 3d c5 98 83 1d d5 59 10 c5 9d 94 f3 0f aa b2 ec 09 71 cc a3 01 36 35 cd 7c 93 97 fb 57 80 cb d8 5e 00 43 b3 86 70 a6 (REG_BINARY)

"D54147DB1C362F0995D2B42EA73FA59BA45E4737B1"=01 00 00 00 d0 8c 9d df 01 15 d1 11 8c 7a 00 c0 4f c2 97 eb 01 00 00 00 c2 cf 8c 3a d2 c3 42 44 b9 f0 64 2f 97 f2 c7 d7 00 00 00 00 02 00 00 00 00 00 10 66 00 00 00 01 00 00 20 00 00 00 7a 6f 32 2a 20 23 f8 a3 ec c2 08 66 2b 2f b6 0b ee dd 41 bb c0 4a ee 03 a5 49 5c 41 12 9c f6 7f 00 00 00 00 0e 80 00 00 00 02 00 00 20 00 00 00 a3 61 83 a5 f6 2b 13 31 97 8a c1 11 ef ff 95 d7 4f fc 4d 48 d3 85 7e 96 d5 fc f4 b5 68 c7 e7 a0 50 00 00 00 a1 61 42 92 20 04 79 7e 9d 66 6b af ea b2 e7 1c d7 cc 2b ef 87 f8 da 0b 5a 5e 22 fe 8f 8b d3 79 6a 3d e2 14 26 3d 05 e9 43 c0 ac 33 45 f5 96 01 99 57 4b ff 80 cc 59 1d 46 f7 41 b4 6d 1a ea f5 f8 99 27 e9 33 27 f5 ad c1 44 22 ce c9 4d 70 b0 40 00 00 00 2c 1e b1 e0 00 4e 92 23 93 1e fa 83 1b b9 9f fe d4 0d 7a 7b 2d 9e 54 d5 5a b5 ff 89 c4 42 ba eb 26 fc 28 63 1f d0 1d db 91 dc de 4c 90 0a 97 35 94 61 a9 53 27 24 fd a3 a6 38 f5 3b 53 ba 42 c0 (REG_BINARY)

"151C5B278B9543FD3F7C057F70B7CF8B2318C31EEF"=01 00 00 00 d0 8c 9d df 01 15 d1 11 8c 7a 00 c0 4f c2 97 eb 01 00 00 00 f2 ea f7 4b 1c ee c3 40 9c 25 6d b7 04 75 e9 d4 00 00 00 00 02 00 00 00 00 00 10 66 00 00 00 01 00 00 20 00 00 00 54 eb b9 e4 2c c5 1c f7 fb f2 47 c9 23 54 d0 e0 82 92 73 d8 ae a1 29 3a 25 32 17 a5 9c 13 2b 1f 00 00 00 00 0e 80 00 00 00 02 00 00 20 00 00 00 84 e7 1f 87 44 77 5f 71 46 ca 0e d6 b2 90 9b 61 3b 4b 25 06 0a 61 ca 69 c4 86 df 93 cc 3c 5a 5e 40 01 00 00 15 28 9a ed 38 5b 19 d8 b2 d9 5f 3e a3 ac 59 c0 86 a1 a2 a9 0d 57 2b 76 8b f9 8f 88 82 fc 27 79 94 27 f4 72 86 61 e6 58 27 93 d2 3d 18 f2 33 6f 44 54 53 6f a5 3e fb 61 94 64 14 03 93 91 c0 0f 49 54 cc 57 c4 09 72 cf 61 29 5e fd 6d 3d 6d a8 08 b0 0b 01 c0 01 a7 55 a3 90 42 25 95 0f 3c 32 2e e7 ee e6 ef dc e9 2b 0e 79 40 6f e2 83 89 24 d8 9b ee 32 76 e3 44 f0 8e 5f d1 99 69 e0 69 07 1a a5 92 41 91 32 90 15 5f 16 65 2f a3 eb 11 c7 97 24 45 8e d8 5f f9 1e 80 86 c5 77 1f 41 78 5e c9 78 c1 dd db 2a 31 9b a3 c9 7d 2d fc 37 a7 a2 a2 a9 ff d3 04 fd c5 f7 3d 3d 9e 7f bd e6 54 c7 93 56 d8 (REG_BINARY)

"C410D75D9FAB47D9ED29D3544E241F537DA1B3D93D"=01 00 00 00 d0 8c 9d df 01 15 d1 11 8c 7a 00 c0 4f c2 97 eb 01 00 00 00 c2 cf 8c 3a d2 c3 42 44 b9 f0 64 2f 97 f2 c7 d7 00 00 00 00 02 00 00 00 00 00 10 66 00 00 00 01 00 00 20 00 00 00 43 e6 cb 62 cf 7f 65 bb d6 56 7b 1f bc b1 dc 7b 13 ea 81 7c 09 77 77 ca 56 40 ff 22 0e e9 44 78 00 00 00 00 0e 80 00 00 00 02 00 00 20 00 00 00 74 d8 aa 02 1a be 8f 14 57 9a 35 04 11 e2 93 0d 0f ab ad a6 21 72 35 4a 07 83 fb 1a 30 4c ab 3b 50 00 00 00 b4 67 80 28 fc 3c b1 dc 3a 59 d9 48 79 9d d6 a0 77 c4 6b e5 55 b2 3a 6d 06 e6 6c 8c 79 f0 2a c9 5e 2d 5d 33 ad b7 14 f0 92 45 17 3b f8 d8 b5 16 80 f4 c3 a2 df 48 5d 03 8c 01 82 21 30 45 8e 58 cd 3e 21 3c f3 b6 d8 a5 89 1e 18 e0 5e d1 5b e2 40 00 00 00 0e 0f 7e fe a3 55 f5 ae 2e 80 db 45 4a 5b a2 da 72 17 e4 4c 0e 9d fb f4 af b6 f5 5c 64 61 3a eb a2 81 e2 6a 0b 34 c7 7b 09 bc 52 b3 8d af ac 64 00 3f 94 c8 2d a9 ec f0 7c d0 d3 26 c4 13 42 23 (REG_BINARY)

"02043DC0EE6FA30DA5C5225FA57DCD4F6DEFFF4CE0"=01 00 00 00 d0 8c 9d df 01 15 d1 11 8c 7a 00 c0 4f c2 97 eb 01 00 00 00 c2 cf 8c 3a d2 c3 42 44 b9 f0 64 2f 97 f2 c7 d7 00 00 00 00 02 00 00 00 00 00 10 66 00 00 00 01 00 00 20 00 00 00 a9 cc 21 dc ae b6 fe 02 8d d5 62 a1 aa 52 25 38 4c 4f 4b f9 ec 59 de 5e c7 2b 3b e6 d4 34 82 1d 00 00 00 00 0e 80 00 00 00 02 00 00 20 00 00 00 7b 21 d0 5a d6 c8 25 be 5a d3 4b 1e ae 41 75 45 b9 7b a6 20 02 ca 77 8e e8 9d 51 7d 79 f1 39 1f 60 00 00 00 3a 34 3f 65 e2 de 00 26 42 3c a3 32 37 94 12 b7 db 76 a3 c4 c2 63 f0 4c df 2d 9b 3b b1 68 33 d6 bf ca 2a 18 0c d1 00 44 fb 65 c0 8f 16 7a 0f 54 5a e6 83 b0 d3 8e 86 16 ed cc fa e4 18 6d 27 93 2d b1 6a eb 2a 38 73 4e 33 60 b4 d1 f8 fc 4f 8e a7 c7 59 06 52 e1 cd a5 f2 e7 db 77 8c 90 52 96 40 00 00 00 db 28 ea 44 58 3c 52 a0 d7 da d0 f7 42 29 4b 22 f6 c5 66 1a aa 8a b7 8f dd 3d 56 d2 b8 9d 15 99 ad af f1 44 9f f5 93 40 96 cc 86 8e f5 1f f5 ca 65 b6 58 5d c1 ff 2c ce 8a fa 6e 30 9d cc ff 3b (REG_BINARY)

Posted

Hi,

 

Instead of running Step 3, replace that with this instruction:

 

Step 3A: Download and save the attached file (Fixme.zip) and save it to your desktop. Double-click to open it. MOve fixme.reg inside that folder onto your desktop. Double-click fixme.reg to run it. Allow it to run if Windows asks you. It will ask you to merge the information in it to the registry. Let it do so.

 

ATTACHED FILE: [ATTACH]964.vB5-legacyid=1862[/ATTACH]

 

Step 3B: Click Start --> Computer and delete these folders:

 

C:\Program Files (x86)\DailyBibleGuide

C:\Program Files (x86)\HiYo

C:\Program Files (x86)\Red Sky

C:\Program Files (x86)\Protected Search

 

Step 3C: Then, run an OTL quick Scan and post the resulting log in your reply.

 

Continue with Step 4 in the previous instructions.

 

WARNING: The attached registry fix is custom made for this user. Yours will be different. Use at your own risk.

fixme.zip

Posted

[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\IntelliForms\Storage1]

"AE698CFE08B29271644798AD167B0FD791F9116BCB"=01 00 00 00 d0 8c 9d df 01 15 d1 11 8c 7a 00 c0 4f c2 97 eb 01 00 00 00 04 ae 72 13 3a 84 f1 4a 99 2f 70 e7 3b 78 23 f2 00 00 00 00 02 00 00 00 00 00 10 66 00 00 00 01 00 00 20 00 00 00 f3 ae 35 65 6e 4e 50 1e 5c 6d b6 76 c1 41 08 29 e6 3b fc 9f 1f 9f c5 9c 26 66 6f 24 e7 85 dd dd 00 00 00 00 0e 80 00 00 00 02 00 00 20 00 00 00 d3 03 ad ff 74 e6 ac 35 10 80 e9 39 5d 26 55 f0 bc ef 11 03 36 99 40 db 62 33 65 24 67 ea 81 b5 60 04 00 00 7b 44 ab a0 2d 0e 5c cb 78 a8 b3 88 4a 5b 1b ff 45 ab 8b c7 7c d2 a1 11 c7 3b 82 b1 e0 0a e7 6b 8a 08 50 84 db 02 98 50 8c b7 18 31 89 a9 35 94 32 c0 c6 f0 6e f9 07 61 53 a8 dd bc d0 b1 50 e4 0b 0a e8 9b b8 cf bf a3 25 0d c6 5d 0c 6a e6 c3 e8 4b 2e 37 97 eb 94 95 f5 0d dd b3 e1 b6 c7 48 62 72 d0 b4 20 a6 fd 68 6f 19 4d f6 d5 56 04 ab b5 04 d7 5a 46 d9 e4 fa a1 b4 a1 fe bf 00 4f 50 c2 0d ba eb 68 27 d8 f4 72 fc e6 7e eb 28 82 b6 52 53 67 84 0a 84 ab c0 b8 3d 19 3b 37 bf da 0b 3c 0f 23 bd ff c1 bb 84 0a 34 b7 88 1f 73 4e 36 c5 92 05 4b ce b0 f6 ce 4a c6 24 05 55 93 8a 42 fe d4 c8 (REG_BINARY)

"DABBFD35854177D84D61FFF79D2BC7215D6470A506"=01 00 00 00 d0 8c 9d df 01 15 d1 11 8c 7a 00 c0 4f c2 97 eb 01 00 00 00 fa a3 72 49 a9 04 8c 41 b0 23 5e 0b 9e 7a ce 75 00 00 00 00 02 00 00 00 00 00 10 66 00 00 00 01 00 00 20 00 00 00 7f 67 c4 e1 4e 16 f9 ae 7f b1 bd 4b 40 0e 8a 77 16 fe 17 d0 99 4f f3 a0 ea 3e 17 67 5a 00 5f b7 00 00 00 00 0e 80 00 00 00 02 00 00 20 00 00 00 7e e3 3f 12 00 17 86 79 73 0a 6e 89 fd 69 63 89 57 21 75 f2 4f 5f 77 26 ed 2d 12 09 6c e3 f2 79 10 02 00 00 01 6b 52 1f f2 94 9a 40 43 e1 70 35 a5 69 98 45 38 34 5e 87 48 9d c8 be c0 07 34 3a 6e 0e b3 13 eb ca a1 a4 d7 b8 07 cf bc 7d be 41 e4 76 d4 c0 5e cf f4 e7 a4 ad f0 09 cc 06 90 c4 04 4b be 85 49 3e e5 7f d3 33 df 03 a5 8f 60 f4 22 ab 72 f7 e5 cb 3f 33 09 23 5e fd fc 8b 11 82 3f dd e9 83 e1 fd 35 b0 ee ac 0c d7 52 2a b7 4b b1 65 fa cd 52 96 70 32 c4 e0 fd 5e 13 04 ad 8f b7 31 42 ab d2 d4 cb d2 2c 49 fa 99 3c 18 c2 9b df 20 28 bf f0 d2 01 62 56 9c 61 95 22 88 fd a3 09 d2 c5 dd f2 d7 12 a8 93 cb 48 33 04 48 07 e3 1c 99 ae 53 c6 d2 83 aa f5 f0 49 6d 4a 8c ee da 41 65 94 41 c8 64 75 (REG_BINARY)

"924EB1974AFEBEB0FD6CC5317D3C6485375EB92C59"=01 00 00 00 d0 8c 9d df 01 15 d1 11 8c 7a 00 c0 4f c2 97 eb 01 00 00 00 c2 cf 8c 3a d2 c3 42 44 b9 f0 64 2f 97 f2 c7 d7 00 00 00 00 02 00 00 00 00 00 10 66 00 00 00 01 00 00 20 00 00 00 d7 b6 8b d0 11 5a b5 d2 a1 ce bd 9d 70 9a b4 db c4 4c 43 5a 83 0f 13 15 85 53 1d 3f 96 23 a3 21 00 00 00 00 0e 80 00 00 00 02 00 00 20 00 00 00 78 4f f4 71 6f ec 6c aa 8e 1f 76 e6 dd 88 86 24 f3 e3 da 6d 55 18 ab ec 6a 9a 6f b0 57 26 9e 48 50 00 00 00 8c 28 52 59 ce d4 fe 1a 2c 58 c2 85 9a 68 8b 98 10 92 ef b1 7c 04 f6 28 2e c8 af b0 d5 89 b9 1c cd 1a 2f d8 6a fa d6 b3 bc eb ba 45 95 4d 35 37 7b 61 b5 84 42 ee ee c3 01 a1 29 85 78 11 bd 58 b4 40 76 ff 5b c6 f6 e8 97 82 72 2e d3 c4 98 03 40 00 00 00 07 56 9a 89 e0 0d 43 a5 87 62 8b 98 d9 6f 63 b3 f1 d5 a2 dd 20 6e 42 2f 73 66 a9 7a 64 72 80 55 a7 f9 21 8c 26 7a 74 e8 11 39 d9 1d 18 a7 d8 5b 0b ec 6e 99 a1 b8 9c a6 e9 28 b8 24 93 d4 fa 96 (REG_BINARY)

"25D63977B5D48876833346C856116F99872EDE978F"=01 00 00 00 d0 8c 9d df 01 15 d1 11 8c 7a 00 c0 4f c2 97 eb 01 00 00 00 c2 cf 8c 3a d2 c3 42 44 b9 f0 64 2f 97 f2 c7 d7 00 00 00 00 02 00 00 00 00 00 10 66 00 00 00 01 00 00 20 00 00 00 20 d6 af fd 2c 4a 0a d3 cf 6c 74 58 cf f7 9a 6b 4a 63 62 71 82 59 1c a6 6f 0e fc aa a0 e3 c8 37 00 00 00 00 0e 80 00 00 00 02 00 00 20 00 00 00 cf 02 69 d2 f7 a6 99 b6 44 ec f6 86 44 2b a1 c3 0d 4d b4 3b bd bd 9f dc ac 1a 3a 27 1a 86 98 0b 60 00 00 00 52 4e 00 76 f1 66 69 f0 c3 09 a0 cb 19 dc c5 a3 cf 61 00 50 83 ce 36 06 2a af 8a 89 b4 26 55 1d 0d 47 fb c8 f0 b2 94 e3 c9 50 21 53 37 ab c9 51 c4 3b 6e be e0 0c 5e 0a a4 e5 9b e1 eb 92 bb 62 0d 9b 02 0b ad a0 b0 e6 73 88 b1 c8 17 5f 96 cd dc 3f 7b 0c 79 dc 8f 99 2f 32 7b a6 d7 59 db 5e 40 00 00 00 46 32 bc 74 da a0 27 e0 1c 5c 0c 6b 44 fb fc c8 11 56 3a e4 7a de 29 48 5c ea 82 a9 95 e3 4a c8 12 51 64 11 eb ef 66 b0 ca 03 71 ed 2f 14 1a 00 65 28 d5 98 0f e9 01 46 38 d4 c6 12 d1 37 50 69 (REG_BINARY)

"1C6C20FFA0A8BC6A180DD8A5004DA830FB5EC84D4A"=01 00 00 00 d0 8c 9d df 01 15 d1 11 8c 7a 00 c0 4f c2 97 eb 01 00 00 00 fa a3 72 49 a9 04 8c 41 b0 23 5e 0b 9e 7a ce 75 00 00 00 00 02 00 00 00 00 00 10 66 00 00 00 01 00 00 20 00 00 00 f4 e0 1b 76 60 2b 9b 50 d6 19 2b 9d ee 91 ff 1c 89 98 81 f9 28 3e 36 40 dc c2 a9 47 ba 96 8e cb 00 00 00 00 0e 80 00 00 00 02 00 00 20 00 00 00 ac d1 37 bd 37 5f 4a 2a ba d0 a1 9f 6b 25 2a 3a 50 58 27 ad e9 cd 60 40 97 ae 4b 97 11 22 2d bd b0 00 00 00 94 05 5d 37 89 bf da 04 65 61 5c 21 f5 51 5e 67 1f 12 e7 99 be f7 14 c1 f8 2a b9 96 c6 1b 19 3f 9e 45 22 56 46 d8 79 e0 38 bb 9b f5 be 5d 83 b8 e0 8d ec 8d aa 31 a0 91 7f 98 a0 bd 57 8d ae f6 ca 2c 1e ea 5b 3a 65 4f b0 e5 6d b0 0a e9 5f 5f 09 ae 30 e2 d3 4c a3 3e 71 88 d4 1d fa 0f 36 80 5e ae 13 b8 2c bb 6e 5c de e1 da 6c 92 58 fd 09 5a 26 3b 79 be 09 ad a8 de 2a af fe 97 a6 bc 17 b0 99 9a c0 c8 68 66 36 c3 65 63 65 b1 8d d8 23 70 5e f3 23 ea 57 59 fd 04 19 31 f4 5d ed 46 19 8e 99 e6 d4 ea c5 08 61 75 27 9f be 7d d2 a0 29 40 00 00 00 75 cc a6 81 81 4d 24 53 3d 1c ca 5b 07 f9 3f (REG_BINARY)

"C6FB044EC2BD401521D6B1082276415638196D8004"=01 00 00 00 d0 8c 9d df 01 15 d1 11 8c 7a 00 c0 4f c2 97 eb 01 00 00 00 fa a3 72 49 a9 04 8c 41 b0 23 5e 0b 9e 7a ce 75 00 00 00 00 02 00 00 00 00 00 10 66 00 00 00 01 00 00 20 00 00 00 1f 53 91 f3 a8 a1 10 b2 8d 34 b8 b5 04 11 27 3c 02 83 39 1f 3b d5 04 ce fa a2 69 38 90 8c a1 33 00 00 00 00 0e 80 00 00 00 02 00 00 20 00 00 00 31 25 0f 15 9a 06 ab 14 23 7f d5 c3 bf 53 0c 02 ea 66 88 4b e7 bc 2a 9b 30 e0 8d 60 6d fb b1 19 c0 0b 00 00 2b 36 2b 04 fe b4 88 2f a4 a8 1b 9b 16 22 94 71 c8 6c 33 70 78 d3 4b 12 93 ea 51 d2 0b 57 f4 3e d2 6f ec 08 7b 02 cf 37 45 08 79 95 9b b4 f8 ab f6 d7 2e 90 64 13 78 36 68 66 a5 f7 33 c9 ad 8c d3 35 12 d2 d2 e1 78 f4 e9 f7 52 e0 30 87 1e af 1b c1 09 a9 c2 87 83 9c aa 16 4b bf 8c 6d 6f 41 2a 19 40 b1 63 6b 97 31 ed ba 68 38 70 c7 75 fb 24 fa 5d fc 90 8d 74 03 de e5 2d cc 22 4c 81 35 14 19 ac 75 f1 58 ec 3d 83 44 5a 3b d1 1c e0 58 3a ee e2 57 fc 60 79 1a b2 b4 4b 58 1c 82 a6 49 05 55 63 68 33 be 73 88 5e 46 23 10 64 0f 6f 36 e9 ed 33 05 57 59 7a 31 2b e0 1f 99 34 55 2c 22 91 be 2b (REG_BINARY)

"096420CE1C9A31839715B788EF20650AE3D02A535E"=01 00 00 00 d0 8c 9d df 01 15 d1 11 8c 7a 00 c0 4f c2 97 eb 01 00 00 00 c2 cf 8c 3a d2 c3 42 44 b9 f0 64 2f 97 f2 c7 d7 00 00 00 00 02 00 00 00 00 00 10 66 00 00 00 01 00 00 20 00 00 00 ca 7d 60 bf 7f d2 1d 42 b3 52 59 07 75 e1 a7 c5 8a 6b 71 4b 15 a1 b1 3a 52 11 8d f3 dc 5a 9c 04 00 00 00 00 0e 80 00 00 00 02 00 00 20 00 00 00 c6 47 b2 03 4a 52 c1 6e d5 04 7c 40 ed b9 df b8 af 7f 0d 5e 67 59 7a ce f6 f4 64 b2 81 61 83 fd 80 00 00 00 65 4d c7 bf 4c 9f 74 fc cc 23 02 5a 2a 5d 1d e1 01 dd f5 46 a3 55 a7 a8 31 a9 92 cf ba 04 32 ee 48 c8 ab c8 ec a5 e2 20 e7 2e 24 84 59 b6 8f a0 67 6e 0e 45 2d cd 81 f7 96 f3 21 ec 10 c1 3f 24 79 03 7c 42 b5 05 df 32 bf ea 25 18 30 5a da ee 34 28 e8 63 58 c1 ce 9c e5 c9 24 a2 28 6c 2f 94 da 75 c3 98 aa 9c 49 5c 58 c9 04 a1 2f 6e 9c a9 d4 c0 01 0f 4d 1b ef 9d e9 23 bc 14 21 6a b9 86 40 00 00 00 d7 13 a1 c8 95 07 2c e5 14 6c 05 88 2c 2e 4f fe 1d a8 a2 ee fc 3f c6 33 d9 11 7b a2 83 49 3d 23 9f fb 70 b0 08 ea 2f da 95 4b eb 0d d4 fc 90 79 f8 41 c4 b7 3d de 0e a4 bb d4 56 95 a1 b4 2f (REG_BINARY)

"4D13E0440141F4A946A15AD5D799B3182A6A7D9156"=01 00 00 00 d0 8c 9d df 01 15 d1 11 8c 7a 00 c0 4f c2 97 eb 01 00 00 00 c2 cf 8c 3a d2 c3 42 44 b9 f0 64 2f 97 f2 c7 d7 00 00 00 00 02 00 00 00 00 00 10 66 00 00 00 01 00 00 20 00 00 00 1f 07 7f e1 d2 59 d8 29 95 4a 70 a0 21 ee 16 26 63 ab f9 f0 eb 58 d2 56 27 3a 5a 97 10 ed 63 08 00 00 00 00 0e 80 00 00 00 02 00 00 20 00 00 00 ea cc 02 ed 7b 68 4c ca 0f a4 9b 6d 5f fc 41 31 eb 72 cf de 04 e4 eb f1 51 fa 46 fd ee 86 3d 09 80 00 00 00 ad 92 56 ca f3 b2 b4 32 98 3d b5 de 00 b7 b1 e1 4f 6f 3b 22 75 42 e5 73 cb ba da f6 52 16 0d 9b 0b ff 2d ae ab b7 35 6a de 68 ef 4e 4d 10 70 e6 4b 8e c4 72 96 db ef f7 9a 61 39 21 27 7f 75 6e 34 bd 6a 79 49 e2 dc 7f 89 a0 37 0b d0 06 50 52 93 54 2d 98 dc c4 3d 68 c4 a0 f9 fe 44 b8 e5 f3 7e 33 f6 f4 71 ed 4d b0 96 a5 c3 cd 3b 95 32 ce 2e 3d 0a 06 41 51 29 92 9e 70 17 86 64 cb 49 03 40 00 00 00 5d ce c3 4b 2c fc c9 24 81 fb d8 d9 9c e5 a7 cb 95 b6 d5 04 b7 db c0 73 0c 35 bf 9b 88 5e c5 6c b8 2d ce 85 ce 2b 1a 69 87 1e 2c 2c ed 5e 6a f7 fc eb 9b 1e b9 a2 dc f9 95 9c 8b 74 0d a3 35 (REG_BINARY)

"6E93C85D71708197754FB5CA3C86A5FB920D941108"=01 00 00 00 d0 8c 9d df 01 15 d1 11 8c 7a 00 c0 4f c2 97 eb 01 00 00 00 fa a3 72 49 a9 04 8c 41 b0 23 5e 0b 9e 7a ce 75 00 00 00 00 02 00 00 00 00 00 10 66 00 00 00 01 00 00 20 00 00 00 fa a7 1f 65 44 fb 3d 18 b6 60 43 e5 92 28 7c b1 a4 b3 4d 2f 78 59 77 18 aa 3f 06 8b d9 05 5d 8a 00 00 00 00 0e 80 00 00 00 02 00 00 20 00 00 00 fb 76 09 58 ef 9f 72 51 7d b5 22 a4 f7 2d 2d 4b 87 2f c4 21 af d7 fe 3f f1 84 a2 79 44 e8 6a 88 20 01 00 00 95 a3 7c 64 54 23 04 ab ed 0f f7 7c 15 84 d2 7b e6 52 4d e6 56 f7 27 ed 1f 29 da ea 99 83 e1 fc 05 f1 b2 9c 1f a1 00 c2 aa 18 33 de 47 c4 c8 21 6b 10 ad 0e 9c 5c f9 a0 f5 e6 e1 34 90 88 bd a4 71 d6 07 43 38 4a fe 11 24 13 0e 39 ba dc fe 37 d9 2b 0f 00 a9 d6 13 f8 76 80 f1 24 5d 3e f8 68 48 7f b1 7a 81 4c 1a 6d 1a 0f 1f 0c 9f 3d a0 aa ca 2c 7d 35 08 c1 4b c0 dd f2 e6 fe 97 91 51 bd 70 0b 8a d7 d2 10 fd f5 66 58 b6 f1 ae 34 b6 10 3e 55 cc 50 c4 5a 03 d8 83 39 e7 dc 7a a9 29 e8 4b 30 e4 2b 17 a5 b0 86 76 43 ff e9 6b 83 34 bc 51 d6 e3 b4 8f ed 05 9f 5f dc 5a 51 45 62 3d 10 d5 0c 0f (REG_BINARY)

"A7301AB81D7D809D725CB2004475E966776980AAF2"=01 00 00 00 d0 8c 9d df 01 15 d1 11 8c 7a 00 c0 4f c2 97 eb 01 00 00 00 7d f0 bc 5c 1d ce 57 41 b2 1b 5d c0 56 9d a6 96 00 00 00 00 02 00 00 00 00 00 10 66 00 00 00 01 00 00 20 00 00 00 59 cd 88 b0 00 35 82 90 84 1a d9 31 93 55 a7 ee 71 1f 51 b3 b4 12 a0 d2 09 93 7e 55 32 da 34 6e 00 00 00 00 0e 80 00 00 00 02 00 00 20 00 00 00 b3 2e 23 20 18 e7 08 05 f8 96 d2 59 c4 ac 72 6f e3 96 a4 6c 49 38 8e 7c df df d7 2a 3e 8e b3 a9 c0 01 00 00 de 77 b8 05 1d 6f 50 d7 b9 4a 84 7b c0 f1 b4 97 cd 76 96 e1 6a 51 d1 eb 95 98 b2 be ef 20 3a c6 18 6d 6c 4a 10 d1 3d 45 74 82 e4 81 fc c9 e0 1b 65 cb ab 9c d7 0d 28 20 20 f8 f9 43 8b 0e 1b 13 05 ad dc 8f 2b e8 8c f1 4d 77 09 f0 86 d3 c6 60 94 63 87 97 b2 b3 86 57 34 00 ce 70 af 9c 9c b2 a7 ba fb 04 af c0 53 cc 4d 3a dc 93 f2 09 7c 9b c5 56 6c cc 8f d3 ef 64 c6 7a 4a a4 d4 10 e7 c6 67 c4 d0 80 06 05 88 b3 a1 24 8f 90 68 d2 a6 4e 8c cb 42 e0 54 7a 7e d3 80 59 9f 94 4b 61 f5 a8 23 16 01 90 62 a1 da 82 c8 ff 1f f5 da 81 01 97 fe 81 59 a6 ab 77 a9 f1 b2 4d f7 ee a7 d0 1b e6 49 27 7c (REG_BINARY)

"E4C8031156725AE776172EF7EA1830E573F904FDFF"=01 00 00 00 d0 8c 9d df 01 15 d1 11 8c 7a 00 c0 4f c2 97 eb 01 00 00 00 c2 cf 8c 3a d2 c3 42 44 b9 f0 64 2f 97 f2 c7 d7 00 00 00 00 02 00 00 00 00 00 10 66 00 00 00 01 00 00 20 00 00 00 fe 70 1d 86 73 0d bb 58 63 11 6c 3e a9 33 c9 38 19 77 38 3f b5 21 ea f2 09 30 4f 53 88 a8 35 51 00 00 00 00 0e 80 00 00 00 02 00 00 20 00 00 00 0d b6 6a 44 f0 b7 69 03 86 6e 9c 89 ca 57 2d 29 dd 40 12 1e 51 da dd b8 a0 5c 91 5b 25 59 c6 45 50 00 00 00 05 2c 77 af a3 94 08 c0 39 21 28 8d 55 0f 91 9d b5 89 2e c5 c5 73 97 16 c2 f1 11 60 fb d8 5f 72 33 0e f1 f7 d7 21 c0 26 f8 89 62 c3 02 15 bf 6a f1 36 f3 74 49 1e 0c 9c 54 a9 fb 32 d0 b9 a3 54 53 9c 93 26 db e6 5f 15 14 b9 14 df d8 15 bc f3 40 00 00 00 89 84 e2 f8 d4 6c cc f3 d1 56 9b f2 60 ee 85 d8 d5 6d cb 93 cc 50 cd 91 4d 58 c7 22 50 8b 1b 99 ec e3 8a 97 47 79 6a 5c d1 e2 cf 6a bd 1e 66 de 5a 19 3d 4c 91 47 f0 2d 64 08 b2 ef dd 02 0b 34 (REG_BINARY)

"37ADB64C2CDA898AC56C464BD00BAFF748AC1E267A"=01 00 00 00 d0 8c 9d df 01 15 d1 11 8c 7a 00 c0 4f c2 97 eb 01 00 00 00 c2 cf 8c 3a d2 c3 42 44 b9 f0 64 2f 97 f2 c7 d7 00 00 00 00 02 00 00 00 00 00 10 66 00 00 00 01 00 00 20 00 00 00 64 d4 61 ae 2a d5 2c 16 e7 b9 63 a0 d0 eb 6b 7d a5 28 b4 04 b6 a4 85 75 68 cb e0 99 ef 15 dd 59 00 00 00 00 0e 80 00 00 00 02 00 00 20 00 00 00 61 12 cc 28 ff e3 b0 06 16 78 f7 98 7d df 63 b4 48 1c 0b 69 93 45 0f 8c 06 f0 59 db 51 2b b0 62 60 00 00 00 b4 5b 75 0d 1f 34 5b 63 31 2e 37 96 b5 94 88 ab e0 6b 3b 42 d9 e9 70 eb d6 a3 26 05 f7 40 cc 3f 26 15 fa af fe b2 af 71 94 b1 4c ce 1b fa f0 7b c1 1d d3 6c b8 a7 c7 59 ee e1 9f 77 bf c6 10 ac 2e 36 d9 bb cd 7a ca f3 87 8d 66 87 98 33 42 3a c5 fd 48 e0 c9 9d 98 64 dd 09 17 66 17 79 d6 ff 40 00 00 00 11 6b 7b c9 33 b6 07 76 ac d9 70 37 a7 aa 18 ef ca 28 72 eb 19 36 b6 b9 66 d1 1f 82 45 67 2c 06 18 24 0f ba 15 0f 95 f1 b8 6a 2a 7e 6d a9 18 0d 2f 33 15 0c d5 c1 df e0 a1 8d 75 d2 70 dc ad 2f (REG_BINARY)

"BEE9113CBB15337F699571D41E7D887DDF37055CD0"=01 00 00 00 d0 8c 9d df 01 15 d1 11 8c 7a 00 c0 4f c2 97 eb 01 00 00 00 c2 cf 8c 3a d2 c3 42 44 b9 f0 64 2f 97 f2 c7 d7 00 00 00 00 02 00 00 00 00 00 10 66 00 00 00 01 00 00 20 00 00 00 2a 37 ee 95 a5 70 b0 28 cf 2c 6d 57 20 bb 31 ac c1 27 36 08 25 bc ad 71 6b 02 c8 56 ea 00 6a ac 00 00 00 00 0e 80 00 00 00 02 00 00 20 00 00 00 84 eb 15 80 a4 32 ea 9c 61 1a cc 33 90 8a a5 d2 b9 ac 9c ad 1d 71 34 f4 cf 2f ad e1 35 53 b6 55 50 00 00 00 ec e5 75 9d af 33 02 e4 e2 6d 18 08 4b a6 d3 ce 5f 65 d5 7e 91 2a fd e2 db 65 26 dd b9 db b6 01 47 0a eb 1f aa f1 3e 45 9c e1 2e d7 7e ea ca 63 71 d1 11 2a 3c f1 bb 02 87 a1 44 48 5f 7a a8 43 6b 61 ab d0 71 a0 47 00 68 c3 20 9b c3 53 73 49 40 00 00 00 23 36 9f ac ea f2 bc 32 35 34 86 1a 13 de 5e a9 37 6b 87 74 77 82 a3 09 7d cd fd e5 a5 85 5a d2 f9 0e 22 bb 29 7a 21 0f d7 81 ea 27 75 43 50 7d 43 b6 3c 47 df b5 97 51 29 9f a8 ca 55 37 59 6a (REG_BINARY)

"F10FD9E6D178A4A9BB12FCD905C528678472F70F4C"=01 00 00 00 d0 8c 9d df 01 15 d1 11 8c 7a 00 c0 4f c2 97 eb 01 00 00 00 c2 cf 8c 3a d2 c3 42 44 b9 f0 64 2f 97 f2 c7 d7 00 00 00 00 02 00 00 00 00 00 10 66 00 00 00 01 00 00 20 00 00 00 47 33 e0 71 86 d2 ab 0e c1 91 8f ab 1b 34 66 bc 97 76 9b c1 65 5d eb d3 82 2a 0d cd f1 e2 52 bf 00 00 00 00 0e 80 00 00 00 02 00 00 20 00 00 00 4b 93 a0 12 a1 67 b4 a3 86 66 0d 93 40 ab 84 aa 1d ab 20 37 88 54 20 5c 62 00 43 b5 79 bc d8 7d 50 00 00 00 0c e1 b0 57 ad fd 20 c4 07 2f 38 41 9d ba 71 25 38 33 10 c4 49 1b 4b ce a7 6a 79 e7 aa 3f 65 67 67 13 c7 01 ad 9e 0f b9 c1 c5 9a d2 c1 9b ed e2 30 33 ac d0 33 3a c9 95 70 7b 65 9b d2 3b 0f 42 42 3b e1 2d 24 e4 8b 30 ed d6 89 47 79 04 6a a6 40 00 00 00 3b ab 9a 99 8a 71 81 98 6f 7b 59 28 e9 e2 89 00 89 89 dd 8d a8 9c 74 ab 1d 3b 7e 90 c3 c9 d8 d0 16 bf 43 09 e0 dd 67 d4 78 8c 3d 22 98 0c ba 37 51 ca a9 66 3c 41 bb b3 7b 89 62 c5 9b 89 09 1d (REG_BINARY)

"CCE7D6897E34A3152B11E238F315AC9BE45C397610"=01 00 00 00 d0 8c 9d df 01 15 d1 11 8c 7a 00 c0 4f c2 97 eb 01 00 00 00 c2 cf 8c 3a d2 c3 42 44 b9 f0 64 2f 97 f2 c7 d7 00 00 00 00 02 00 00 00 00 00 10 66 00 00 00 01 00 00 20 00 00 00 1f 56 92 aa ea 83 a9 d2 00 a6 c8 57 9a 86 c9 83 a4 5f 67 eb ae 01 27 67 d9 fd 3e a4 65 c4 b2 6a 00 00 00 00 0e 80 00 00 00 02 00 00 20 00 00 00 2d 2b 3b 0b 5e 37 06 ba a7 71 9b b9 57 ec 3e 21 45 67 8b 92 d8 58 fc 7a bf 1a 2b c8 dd 1f 32 73 40 00 00 00 c6 3d 0a 4c 82 1a 9a ff 81 12 0f 6c 0e ee 8c b0 6f f6 b3 7e 1a 4b b7 68 46 e7 0f 25 c2 1d 8b a4 47 d4 55 4e 76 a5 e1 47 53 9f ee 01 49 7a 67 1a e6 fe fc 4f 85 67 2f a0 c6 20 f9 39 95 98 e0 20 40 00 00 00 58 f8 a9 ff ae 3e 81 71 ff 8a 60 16 38 d7 b8 9c fe 11 a4 05 80 06 3d b8 27 03 f6 ee 46 36 c1 18 b3 51 0b 61 4c 13 d8 1d 00 3b 77 f9 08 e4 bb f5 0e 5d b6 e6 10 d4 93 8f 2a 20 f6 a0 58 bc 4e 67 (REG_BINARY)

"DD043914DD02231ABE7740D90D427B313E31FDACAB"=01 00 00 00 d0 8c 9d df 01 15 d1 11 8c 7a 00 c0 4f c2 97 eb 01 00 00 00 c2 cf 8c 3a d2 c3 42 44 b9 f0 64 2f 97 f2 c7 d7 00 00 00 00 02 00 00 00 00 00 10 66 00 00 00 01 00 00 20 00 00 00 66 36 3a 18 2d aa 32 a7 5e 27 c9 84 b5 71 ab 8d 2c 49 54 e4 8f d0 d9 38 63 f1 1d 8c 86 7a b1 60 00 00 00 00 0e 80 00 00 00 02 00 00 20 00 00 00 43 e7 13 95 c2 32 f8 02 ba a3 03 7e 40 73 a5 44 18 6d 31 a1 c5 d1 56 b1 5e 2f ae 99 16 87 e1 d8 50 00 00 00 4b ac ea 98 30 72 de 10 15 47 a1 b8 58 b6 33 07 7b 3e 13 ef da da c6 55 1a fe cc a0 6f 3d e8 0d 17 d4 8e b5 ee 9c 73 3b 01 13 da e8 e4 09 ac 73 89 be 42 7d 73 fd c2 62 d7 54 0a 57 fb ca 7d 20 f7 60 d4 f6 b0 cc cf ca 03 44 c2 65 a5 d7 d9 19 40 00 00 00 c4 61 63 5f 20 ca 54 8d 75 ac c4 27 6d d3 92 b3 61 9f f3 97 51 d2 fb 4f 51 57 a2 c6 60 d0 11 6e 4b 84 5b 09 7a 0a 69 c8 56 02 ab c9 cf 4d 59 d5 d9 5f dc 49 f1 c8 5e 03 c4 17 6d 93 21 12 c7 ba (REG_BINARY)

"72B9F7879945CD82128EA98C1A81E14CF92DF9DC6E"=01 00 00 00 d0 8c 9d df 01 15 d1 11 8c 7a 00 c0 4f c2 97 eb 01 00 00 00 c2 cf 8c 3a d2 c3 42 44 b9 f0 64 2f 97 f2 c7 d7 00 00 00 00 02 00 00 00 00 00 10 66 00 00 00 01 00 00 20 00 00 00 18 df ed ef 5b 09 35 b7 82 de b3 c4 e3 a4 30 c7 e2 6c a1 60 e4 06 19 64 6b 1a 19 c9 ac 43 48 b4 00 00 00 00 0e 80 00 00 00 02 00 00 20 00 00 00 af d7 95 f6 d6 cf c6 c7 2f c9 3e 2c 34 14 da d9 65 35 aa db a4 93 b7 98 ee b2 05 65 f5 5e f4 17 40 00 00 00 7d de 9c 23 f2 c6 71 f6 56 67 5e 2f 30 66 50 8c 37 bc 0f d3 c6 54 49 2f 52 5a 60 3f 03 79 5e 75 d4 fb 95 c3 0e 31 aa e7 6e 89 e0 b3 d7 41 0e 3b 06 c8 2e 1e 68 2c 52 77 2b 8d af f2 95 cc 61 21 40 00 00 00 4e 71 9c 32 48 62 b8 17 0b f8 3e 74 93 f4 38 ad ce 83 6b dc a1 96 43 dd 8a fa 73 b2 74 36 5d bf 05 9f 60 3f b5 a9 31 55 30 b8 ab 9e 72 58 8f 83 f8 3a a1 4c 4f f2 9b 2d 8c b7 f2 c2 a6 91 f0 18 (REG_BINARY)

"67027095D7C972F0846B26C33A9F1F2B488135D23B"=01 00 00 00 d0 8c 9d df 01 15 d1 11 8c 7a 00 c0 4f c2 97 eb 01 00 00 00 c2 cf 8c 3a d2 c3 42 44 b9 f0 64 2f 97 f2 c7 d7 00 00 00 00 02 00 00 00 00 00 10 66 00 00 00 01 00 00 20 00 00 00 3e 1a 63 c6 55 b1 57 53 f6 50 fe d1 af 91 06 84 ca ad 0f 16 04 5f f7 38 99 b9 18 52 4e ef 5b 22 00 00 00 00 0e 80 00 00 00 02 00 00 20 00 00 00 db 27 4d 42 4c 91 04 58 20 31 72 de 34 ee 49 17 b6 36 98 5e 39 c4 fb 7a 67 3d a0 8b 61 c6 76 a0 40 00 00 00 8d ea 9c f5 53 6b 4e 4b c5 02 28 71 80 2e 7b b1 06 f8 25 32 a7 4c 64 f4 f2 16 df 50 48 74 b6 f7 46 95 1c f2 28 5b 5e c5 5f 5c f8 a7 8e cd 14 e9 cf b3 8e 17 cc 72 8c 4f 15 25 b6 51 90 77 d5 0f 40 00 00 00 72 d3 cb c8 33 be e9 a9 0a ef e7 26 45 e3 86 22 5e 7c 45 19 10 c4 c6 22 5a fa db ad 9a fa ca 50 4a d9 d2 db 02 df d8 60 73 67 64 ca 63 4d 1a 84 0b 6e 32 22 ce a3 34 e3 8b 87 b3 6a 61 c4 f9 23 (REG_BINARY)

"4A08BFF993FEB540429405C15C0AB12E10B9AF3E27"=01 00 00 00 d0 8c 9d df 01 15 d1 11 8c 7a 00 c0 4f c2 97 eb 01 00 00 00 c2 cf 8c 3a d2 c3 42 44 b9 f0 64 2f 97 f2 c7 d7 00 00 00 00 02 00 00 00 00 00 10 66 00 00 00 01 00 00 20 00 00 00 40 b9 2a 27 30 70 c1 95 4b e2 2d 95 db 5a ab 78 51 91 ec d2 91 97 07 35 65 2b f1 ad a7 2d ce d1 00 00 00 00 0e 80 00 00 00 02 00 00 20 00 00 00 3a 46 87 63 96 e7 f6 7e 3b 22 7c 7b 4a 27 ad e9 db cc c7 4f 46 c9 ca a9 79 82 4b bd 61 42 76 77 40 00 00 00 13 fb 12 ff 9f aa a3 d2 d2 4c 74 09 79 37 6f dc 6c 7b ac ca eb a0 9f 2d 5c c2 31 6d 73 36 c1 48 74 b5 21 22 35 db 71 28 f9 da 1a dc 53 a8 32 4b 3c c4 af ce 99 7a 1e 93 97 09 b0 d0 a5 8c 17 f4 40 00 00 00 9f f9 cc 31 a4 c9 66 00 56 2f 1a 43 b6 82 66 09 03 b3 88 8a a5 29 1f a3 0d 3f ac 86 aa c9 4e 8d 89 b6 86 c7 75 b1 f7 0d 74 59 c0 31 9f 36 7b 73 5b 0e 7c 95 27 44 d7 d6 ed eb 67 9f 31 a7 c4 00 (REG_BINARY)

"48AFA9E93B9296921462981A85E8595849AB1F15EC"=01 00 00 00 d0 8c 9d df 01 15 d1 11 8c 7a 00 c0 4f c2 97 eb 01 00 00 00 c2 cf 8c 3a d2 c3 42 44 b9 f0 64 2f 97 f2 c7 d7 00 00 00 00 02 00 00 00 00 00 10 66 00 00 00 01 00 00 20 00 00 00 ef 56 64 96 37 ac b8 36 b0 af f9 77 50 3d 6f c2 8f d1 09 7e 96 c9 a5 2c 5b d4 5b c2 2e de c6 6f 00 00 00 00 0e 80 00 00 00 02 00 00 20 00 00 00 75 83 c9 88 63 0c 4e f0 59 50 d2 be 95 03 c9 76 dc bc d1 5b af 9c b7 e5 f7 8b ca 9b a3 bc 8b b0 40 00 00 00 7f c7 e2 2f a8 cc 79 42 8e e1 33 f3 b5 bd 92 e0 70 81 d2 4e 28 42 45 1b ea 21 e4 eb b7 01 ee 3f 9d 45 e7 57 9c f0 91 cb b2 f6 77 d8 e8 27 62 28 32 8e 72 7b be 77 ae 81 eb 10 85 70 fb 2b 82 ed 40 00 00 00 ea e5 45 c8 fc 68 c4 11 1b 53 6a 20 68 e6 62 f8 be 15 53 ff bc 88 c8 bd 17 a4 d8 4c d1 01 92 ba 5f cd 4d 39 9e d3 1c 5e 0b 02 23 6d 63 d5 f2 2a d9 bc ef 27 32 a6 83 69 ee 51 b6 90 80 3d 2e 0d (REG_BINARY)

"D3C90BA40F9C3A2AF77BBF0C5C249A980BDF742DD4"=01 00 00 00 d0 8c 9d df 01 15 d1 11 8c 7a 00 c0 4f c2 97 eb 01 00 00 00 c2 cf 8c 3a d2 c3 42 44 b9 f0 64 2f 97 f2 c7 d7 00 00 00 00 02 00 00 00 00 00 10 66 00 00 00 01 00 00 20 00 00 00 eb a9 e2 1e b0 11 45 44 19 fb 5a be 75 d6 de 97 08 30 27 25 43 02 da 38 ac 0e b6 b4 1c ee 73 c5 00 00 00 00 0e 80 00 00 00 02 00 00 20 00 00 00 7c cf fe a6 58 32 24 26 08 8c 13 69 6b fa 54 a0 99 44 a1 24 70 23 56 70 ca 7a 0f 56 40 78 aa bc 60 00 00 00 bc 60 0d d8 97 40 ad 85 d1 e8 70 9d 85 e1 dc 83 6d 53 f0 d1 1f bf 80 f5 72 66 a8 97 3e 21 41 87 25 25 9f 00 29 1c 20 60 cf 42 f4 49 11 36 56 b9 bc 38 46 1c 02 a8 59 00 d6 1c c7 56 27 fa dd 38 72 01 33 99 d4 88 ff f5 1e 99 50 c8 99 02 58 b8 51 22 2d cd 1c 80 0b db e2 62 49 7e 04 71 e4 ea 40 00 00 00 1e 04 ea d6 63 cd df 99 89 30 53 80 3d 8d 45 33 82 1b f8 67 fa 93 84 1c 2b 1f 13 dd 76 c5 47 55 40 a2 3d 01 e5 2b 3f 02 c3 ea 30 ba db d7 ab d7 e9 fa 14 06 c6 69 2a 98 83 54 e4 be 72 40 47 06 (REG_BINARY)

"A85DB3B00F8E4C2E6C71ADF6B7791E6E6A6B664238"=01 00 00 00 d0 8c 9d df 01 15 d1 11 8c 7a 00 c0 4f c2 97 eb 01 00 00 00 04 ae 72 13 3a 84 f1 4a 99 2f 70 e7 3b 78 23 f2 00 00 00 00 02 00 00 00 00 00 10 66 00 00 00 01 00 00 20 00 00 00 08 54 c0 01 7b 76 b0 a0 d0 6a 4a 0a 35 13 23 fb 83 a8 c8 7f db 5c ba 07 f8 a0 df 08 26 92 c7 7c 00 00 00 00 0e 80 00 00 00 02 00 00 20 00 00 00 a1 ea 79 74 86 44 60 13 92 f6 77 92 cc 2c a5 45 d3 99 4a 2b c5 9f 84 ab cb 87 d1 9c b5 2b a6 41 90 00 00 00 da 17 d4 c9 a2 5b ff a9 47 79 63 9f 87 df 8d ac 08 38 19 d1 bb 34 8c 8e 8d 89 84 fd 8a e8 71 b5 b9 c7 55 3b 73 7e 8e 73 d2 46 99 64 41 7f 3b 8e ea 6f 0f e1 e9 68 7f 6f f7 3a a4 02 47 4c 80 96 50 d4 2f 4f aa 89 8d 46 c8 34 4e e7 ba b3 56 28 76 fc 61 8a 3a 72 1c 3c 4a 76 e2 30 7f 8a a9 94 11 c6 03 c2 8f b4 d5 b6 ad af bb 04 53 d4 62 b1 11 e6 ee dc 6d b0 77 d7 5a d5 a8 3e 37 70 ab cf cf 8a 73 33 d5 da 3e 53 cc d0 d2 a2 7d a6 b3 80 40 00 00 00 fa d2 03 5e 05 45 97 c2 f2 19 40 32 53 f7 a1 3f 07 b6 02 f8 69 e8 97 5e df b5 23 2f f8 0d 8b c4 3d b1 45 58 50 b5 a2 e3 db bf e6 cf a6 f6 55 (REG_BINARY)

"280960C8406F5B54472F854047DC521120CFA69BA8"=01 00 00 00 d0 8c 9d df 01 15 d1 11 8c 7a 00 c0 4f c2 97 eb 01 00 00 00 c2 cf 8c 3a d2 c3 42 44 b9 f0 64 2f 97 f2 c7 d7 00 00 00 00 02 00 00 00 00 00 10 66 00 00 00 01 00 00 20 00 00 00 10 4f b5 79 f3 76 0a 6b cc 4d 22 c7 f3 31 95 1e 20 5c 2a a6 8b 71 85 15 8f 06 ea ed 67 13 8a 18 00 00 00 00 0e 80 00 00 00 02 00 00 20 00 00 00 ad 7b a0 47 83 80 54 1e cf 0b 0a 39 88 6f f5 83 f0 a3 c0 f9 15 c5 0a a3 4c b6 bc 28 13 d1 b0 ec b0 00 00 00 26 1f d0 1e 9d e5 0d 76 30 40 1e 12 09 81 ff a6 b0 d0 f7 8a f0 68 5e b6 5f db 18 23 76 37 36 e8 e5 ad cc 32 25 23 02 1f 13 5b 7c 30 9b 2c 7f 65 c1 4f 60 a8 d3 b0 4e 55 10 1e 15 f5 1d 85 2b e8 12 9f ee 43 6e 85 0a 3c ff 1d 4f b0 fc fc ae 8e 98 2d da cf 60 66 b4 30 a4 76 02 31 54 b6 51 40 6e f9 ce de 9c b2 ed 92 58 24 3e db 3b 68 7c 87 3e 53 e1 66 fe 7e 62 59 79 49 43 6c 4d 92 63 24 d7 73 e5 a1 50 2f c0 a9 9e ca 6d 82 b1 c2 99 f9 b4 af e7 ec d7 8a 1b 2b ce 8b 3d af ca 03 21 9c 06 b4 15 09 c0 2b c5 e7 f4 c4 65 cb d4 9c 02 27 40 00 00 00 10 4d 30 17 39 3d eb 9c 9f a3 69 c1 98 ac 2e (REG_BINARY)

"0BA59E6EA4F2E8C97BA317DBCEAE25A2847A942B13"=01 00 00 00 d0 8c 9d df 01 15 d1 11 8c 7a 00 c0 4f c2 97 eb 01 00 00 00 c2 cf 8c 3a d2 c3 42 44 b9 f0 64 2f 97 f2 c7 d7 00 00 00 00 02 00 00 00 00 00 10 66 00 00 00 01 00 00 20 00 00 00 e8 b5 77 77 e6 a1 bf f3 b4 ce db f7 04 b3 5c 94 7c 6b 72 b1 50 29 df 3a 9e 17 b8 df 27 aa ed 51 00 00 00 00 0e 80 00 00 00 02 00 00 20 00 00 00 4f bc b7 7d 44 37 bc 6c 85 9c 99 0c e5 58 02 0c c8 f7 25 7f 25 9b 8e 1c d2 c2 2d 07 fc ec b4 9b 50 00 00 00 f0 fb 56 a8 72 c2 92 d7 f4 5d b3 f3 20 f5 68 e1 da f4 c1 de 3f 59 d4 c8 77 2c 55 30 d7 ea 7c c4 7d 4a 29 ad ca 25 c7 c6 51 d5 3f 49 49 f5 83 b1 f3 66 2d e5 38 d1 ff 04 f0 ab 61 37 35 ef d0 d1 55 7b da 68 56 14 7b a8 8c 48 96 33 08 cf 82 27 40 00 00 00 f5 91 4a 97 36 fe d4 55 7d 03 ce 15 51 5d ea da 4a ee 2f 9b 86 84 85 f1 22 39 97 d2 ef 45 af ea fd bc 45 08 ba f6 0b 47 f0 53 5e ad 53 e1 11 72 d9 a0 08 6c 59 c7 a1 14 78 0b 74 b0 99 c3 00 88 (REG_BINARY)

"710D91E52989D9063F237E934DFB5B9A1208775B21"=01 00 00 00 d0 8c 9d df 01 15 d1 11 8c 7a 00 c0 4f c2 97 eb 01 00 00 00 c2 cf 8c 3a d2 c3 42 44 b9 f0 64 2f 97 f2 c7 d7 00 00 00 00 02 00 00 00 00 00 10 66 00 00 00 01 00 00 20 00 00 00 22 60 b9 4c 9b af 66 62 44 c3 b6 ab a3 02 0d 6b c2 aa 73 30 f2 92 00 0a 14 f9 c2 40 bd 6e 47 28 00 00 00 00 0e 80 00 00 00 02 00 00 20 00 00 00 5c b2 ac fc da 74 cd 3e f7 69 cb aa b7 fb 62 d1 6b 2f 90 74 9c bd 91 83 e7 3d d9 34 ac 66 36 14 60 00 00 00 55 8b 94 94 b6 5e 0a 21 34 5b 25 08 9b e9 d7 34 ff 3a d6 5f cb 5d 08 fd d6 64 93 36 b2 64 0d d9 46 9b ae 74 34 50 96 01 e1 46 d4 42 98 ec ad 51 bc d2 ab 24 60 9d da 67 a3 ef d7 ad 9c 84 0c 5f a3 79 6a f1 41 9b dc b5 76 07 15 75 de 42 95 d0 65 af 0f 5c ac 8e 85 45 02 38 eb 6b d9 a3 dc 32 40 00 00 00 91 6d 3e c0 8e f6 fd d7 bf 87 54 06 3a 8a 60 fc 52 75 57 8f fd a0 45 b9 9c b3 4e 57 e1 19 6f 18 a1 5b 9e 47 16 99 81 94 ac e6 2d b4 55 fa 77 60 61 3b 22 b7 f1 ea 7d 24 70 12 df d8 66 48 be 44 (REG_BINARY)

"3EECBED6028B282FE1E7A5299DE569434BAEE41558"=01 00 00 00 d0 8c 9d df 01 15 d1 11 8c 7a 00 c0 4f c2 97 eb 01 00 00 00 c2 cf 8c 3a d2 c3 42 44 b9 f0 64 2f 97 f2 c7 d7 00 00 00 00 02 00 00 00 00 00 10 66 00 00 00 01 00 00 20 00 00 00 6b 04 4e 5b 4a 43 83 39 91 65 9c 50 55 6e 98 dd b5 94 0d 97 28 04 71 ce ec bc 75 55 0f e2 51 80 00 00 00 00 0e 80 00 00 00 02 00 00 20 00 00 00 34 a2 f1 ce 42 d3 31 be 9f c9 9c 9c 5e 25 84 92 77 fa 97 af d9 67 be 17 b5 a8 13 37 6f ac 81 51 50 00 00 00 8f 1c 19 9d a9 d9 60 45 d0 c0 ba e4 05 e6 9f 85 f2 b2 d2 2b 22 d0 62 4c 8b 60 f3 47 0e f4 5b 6e e7 9c ea b5 08 1b 38 7a d3 ec 47 d6 66 ed 90 86 9c 8a 21 ee 86 74 4f 58 d2 15 2e d8 bc 39 bb 0e fc 13 df 36 0a 61 8d ff 0a 9a 52 e5 72 d3 a8 f2 40 00 00 00 bc 3b 6e 59 c3 f2 11 21 81 95 e7 fa d3 b4 4e 73 96 a9 93 7b 9b fd c0 11 4f b2 db e0 42 8a d5 c2 eb 4a 7b 98 bb f9 79 c2 b2 c1 ff d0 95 87 a3 97 16 e2 a7 6d 8e 19 ca b6 3b 72 8c 86 84 8c 5f 82 (REG_BINARY)

"047B0A999BE29C6465483501EA4893E81978A395F8"=01 00 00 00 d0 8c 9d df 01 15 d1 11 8c 7a 00 c0 4f c2 97 eb 01 00 00 00 c2 cf 8c 3a d2 c3 42 44 b9 f0 64 2f 97 f2 c7 d7 00 00 00 00 02 00 00 00 00 00 10 66 00 00 00 01 00 00 20 00 00 00 15 53 bd 12 ac d2 3d 07 46 5b cf f1 54 04 cc 59 d9 fc ad b0 70 e0 82 8d 71 c9 cf 07 a6 84 26 a4 00 00 00 00 0e 80 00 00 00 02 00 00 20 00 00 00 4a 4c 0e 66 c4 aa 74 be 6e 42 17 9a 5c de 83 28 46 dc 76 4f 0a ab f8 b8 6a 8c 5c 01 4a 40 1e 92 50 00 00 00 c3 d1 e8 74 af a4 c0 e8 56 9f f6 6d 11 30 7b 35 18 89 b2 9b 79 d7 c8 c2 74 db 94 e3 25 4a a2 df 81 92 84 b5 71 b1 2c bd 51 29 66 11 b2 22 98 ff 9d a2 b3 5a fd ce d2 f0 99 46 de a5 0f ca 27 46 15 b3 12 b2 d0 c8 5e 87 25 bc e9 30 5d 3f c8 36 40 00 00 00 08 f8 0d ee de eb fb ef 2b 3c 12 98 2b cc f6 fc 11 55 64 e8 9a 86 28 15 bd 91 3d 61 a1 0c d8 11 dc a4 e3 42 c9 24 fc 0d 32 36 04 83 62 bb e1 08 67 3d fb 8e 1c 48 99 b2 22 26 7d 24 0f 64 55 26 (REG_BINARY)

"18F22D7CD3BBAEF4D6D1C9BF29FE5EC3BFB0404D56"=01 00 00 00 d0 8c 9d df 01 15 d1 11 8c 7a 00 c0 4f c2 97 eb 01 00 00 00 c2 cf 8c 3a d2 c3 42 44 b9 f0 64 2f 97 f2 c7 d7 00 00 00 00 02 00 00 00 00 00 10 66 00 00 00 01 00 00 20 00 00 00 71 e6 85 24 92 59 6e 5a 44 0d 88 d9 8c 8d a9 dc 68 dc ae 56 b2 95 34 ce 86 a0 01 45 3c 53 94 c8 00 00 00 00 0e 80 00 00 00 02 00 00 20 00 00 00 8f 91 86 55 12 0f 98 02 68 37 17 09 f3 da 1e a1 a9 d4 78 c2 5c ab c0 ed 76 9c ed 28 0c a4 60 60 50 00 00 00 fc 99 9d b2 42 c5 09 a3 fd 56 33 9d e1 c8 3f b7 13 1b d0 50 3a fb f2 07 a2 ba f9 eb be bb fd cc ab 17 c9 46 b2 31 78 ef 10 e0 60 dd b7 bb e3 9d 70 47 17 e6 58 77 df 6e 7c b0 d2 66 85 a8 41 e0 cc c7 f5 ff 2e ff a5 23 96 a4 cc 6f 45 bb 3e 5a 40 00 00 00 e2 45 58 54 ae 81 96 28 4b 63 bf 79 fa bc 55 a8 ef 65 71 3b ed be 14 c5 41 13 e2 8c 1a d3 e5 6e 23 b7 86 2e 8e 4c e6 9a 64 81 8e 84 61 6b 1b d9 51 c9 c4 fe c8 c0 af 59 73 be c8 ac d5 b8 d3 ee (REG_BINARY)

"7DAC7BC00FAF594202F3D0B9F92C48F45B0066F956"=01 00 00 00 d0 8c 9d df 01 15 d1 11 8c 7a 00 c0 4f c2 97 eb 01 00 00 00 c2 cf 8c 3a d2 c3 42 44 b9 f0 64 2f 97 f2 c7 d7 00 00 00 00 02 00 00 00 00 00 10 66 00 00 00 01 00 00 20 00 00 00 50 ee 8f 01 26 39 f3 51 95 42 87 1d 70 53 2d b1 c5 1e 2b 47 d5 fd 44 ed 27 dc 47 f6 c5 2a 1c 6d 00 00 00 00 0e 80 00 00 00 02 00 00 20 00 00 00 6a 6c b4 7a a5 5e e4 3b 3e d2 56 43 b2 d5 e7 69 06 ac 40 32 1b 9a fc 2e 58 e9 70 6b 41 80 75 8a 40 00 00 00 6f 63 cf 54 48 e1 b8 42 24 46 e8 11 ce bb 1a 68 57 5a 26 97 1b d7 b6 57 a9 8d 78 90 85 92 81 18 41 fe 65 02 63 99 e4 de 3f 37 a5 3b c1 5d f9 4b e0 ce c0 b1 ae 42 0c ed 69 21 4c 09 02 8b 8a a3 40 00 00 00 69 9c 85 87 93 ae 98 98 64 82 d5 42 ad bd db d7 e5 0c 55 69 71 08 e9 4f c4 8f 35 6e d3 c2 78 d2 5f 45 ba 25 97 ca 00 40 06 26 bb 96 35 2d c1 ec 5f 90 11 c4 d9 6f 6c 74 a9 05 d5 c5 51 bd 15 6d (REG_BINARY)

"9A487C01AF93AEF3F218373ED252D45069BAD6C0C2"=01 00 00 00 d0 8c 9d df 01 15 d1 11 8c 7a 00 c0 4f c2 97 eb 01 00 00 00 c2 cf 8c 3a d2 c3 42 44 b9 f0 64 2f 97 f2 c7 d7 00 00 00 00 02 00 00 00 00 00 10 66 00 00 00 01 00 00 20 00 00 00 da 7f d1 31 24 fd 5c 48 a1 10 76 d0 62 f1 bd c9 b3 30 0d f1 77 2a 0a a4 7b 63 70 13 c9 84 26 ae 00 00 00 00 0e 80 00 00 00 02 00 00 20 00 00 00 ff e5 af fb a1 2d 0e d3 b0 ab 67 e9 54 78 d2 03 09 31 f5 23 76 4f 11 7e 9f f8 1f 7c 5a 9d f4 51 60 00 00 00 f1 57 e4 c6 c4 4e 84 94 30 ec 55 df 73 5a f1 ec ba 49 02 50 60 19 69 b3 de 3e fc 04 46 36 1e 40 d1 c4 65 31 3a b0 84 ed 4f 09 f9 85 c1 f5 8e 52 90 bc 57 16 fe 3e b3 7b a2 e3 9b d3 24 81 a1 51 73 a0 34 a4 fd 9b 36 5c b3 64 25 50 4d c3 54 3b 4b 3b 90 b6 f8 c3 da bf 75 78 f8 9c c6 81 a1 4f 40 00 00 00 eb 56 dd cf a8 f0 fd bf 06 89 cf 21 bd 7c dd c0 7c 1a 51 c3 9a f7 89 90 46 87 cd 71 17 a0 55 68 dd 04 88 0f f7 81 6d 69 3c d9 ad bd 31 bc 28 44 3b a3 c7 01 77 39 fc 5a 9b 1c 13 95 91 bd cb 5d (REG_BINARY)

"277687B2398A1345F223BE0F0889717B4494E7B5C4"=01 00 00 00 d0 8c 9d df 01 15 d1 11 8c 7a 00 c0 4f c2 97 eb 01 00 00 00 c2 cf 8c 3a d2 c3 42 44 b9 f0 64 2f 97 f2 c7 d7 00 00 00 00 02 00 00 00 00 00 10 66 00 00 00 01 00 00 20 00 00 00 aa 87 2c 45 94 73 76 44 61 50 2c a1 46 8f 1c 65 f3 40 62 f2 37 56 fd af a0 9e 8c 83 f5 dd 3c 0b 00 00 00 00 0e 80 00 00 00 02 00 00 20 00 00 00 7c 28 38 c1 44 52 a3 27 6e d3 6f ff 84 9c 4e d7 9e c4 49 df d7 c9 d4 57 e6 81 7b e3 bd d3 c0 98 a0 00 00 00 e3 07 97 08 81 6e 22 b0 9e 93 46 8e cb 1b 62 30 2c f4 f7 c5 22 cc 8d f2 69 3d b8 17 3d 20 8c 5e 61 88 5b 4b 38 ad 7d a1 63 0e d5 6d 99 46 f2 a5 ba f9 26 c9 b8 74 49 c3 f9 07 68 24 89 d6 87 5e c8 fc 18 f9 92 9b aa 62 06 bf 7f ba a3 a3 0a 58 62 b3 21 63 82 64 32 4d 97 89 af dd 2f 8d 7e 50 eb 61 15 c4 1a a0 d2 67 93 f9 0d a0 c4 ec 0b 76 4f 87 f4 f6 f8 26 c6 5e 59 0f b8 43 ee 65 59 1a 2e f9 f0 96 17 6a c4 80 ad 0b cf fd 80 c6 10 fc 08 ab 4c 5f 69 c3 d8 bf 56 ea 96 4e 40 d6 f8 9c 40 00 00 00 51 ee ec ed d8 58 d8 dd 87 b6 c9 68 6b 8b cc 33 5b 08 08 c8 80 99 7e 43 89 26 35 7f 86 a6 fd (REG_BINARY)

"90D5C215D3DA44C6D0D6B7E9FD3CA053A5EFBEF1A8"=01 00 00 00 d0 8c 9d df 01 15 d1 11 8c 7a 00 c0 4f c2 97 eb 01 00 00 00 c2 cf 8c 3a d2 c3 42 44 b9 f0 64 2f 97 f2 c7 d7 00 00 00 00 02 00 00 00 00 00 10 66 00 00 00 01 00 00 20 00 00 00 b1 a9 7e b2 31 5e ce 5a 8e b7 7e b1 60 b9 ff a6 bd 31 36 1a 41 b5 c9 43 c5 17 7d c3 bb e7 39 69 00 00 00 00 0e 80 00 00 00 02 00 00 20 00 00 00 da 89 d3 e0 e2 76 2b 9f 90 5c 5b c2 86 b0 e7 b5 6a c1 59 ca 1c 22 96 10 65 89 b8 ff 3a e8 5d 58 d0 00 00 00 ea b6 8f e9 87 ab b8 b4 0c 66 f1 06 b9 59 50 95 cc 08 9e eb 23 d2 b9 67 55 86 c1 ce b2 84 8d c2 47 10 3d ea 7e 00 14 75 a5 db cf 4f 29 75 60 9e 8f 2e dd c0 0c ca 4c ff 18 17 7a f1 b1 b4 8f c7 cb 30 e9 06 2c b3 71 57 73 92 93 5d aa 3d e1 22 11 f0 b9 72 a1 68 aa 92 01 2c 63 9b b4 bf 5b 26 45 99 be 3a bd 0e f7 a6 2d 76 5e f2 d5 50 1c 5e 78 4c 6e c5 bf b9 36 21 39 e9 99 a9 3d 14 c1 21 01 de c8 a7 81 e0 91 bd c4 a9 bc e6 f2 3a e5 10 04 40 3c a6 e1 f9 95 42 85 13 5e dc 29 35 f7 5e 1c ff d9 7b 5e 86 0f 85 f7 c7 09 48 24 9f 53 62 67 1e a9 b5 f7 fb 3b 55 69 f7 be 27 86 f3 5a ce 3f f1 78 (REG_BINARY)

"83EBB6A39BB833B1414D793064CB18F84F12266E69"=01 00 00 00 d0 8c 9d df 01 15 d1 11 8c 7a 00 c0 4f c2 97 eb 01 00 00 00 c2 cf 8c 3a d2 c3 42 44 b9 f0 64 2f 97 f2 c7 d7 00 00 00 00 02 00 00 00 00 00 10 66 00 00 00 01 00 00 20 00 00 00 b8 81 dd b1 99 b5 75 62 ec 55 a9 34 15 44 e3 3e 50 81 46 5a 60 c2 d8 2f ec a6 c1 46 9b 02 bc 7e 00 00 00 00 0e 80 00 00 00 02 00 00 20 00 00 00 d5 4f 70 22 e1 83 5c 08 34 f8 84 74 bd 69 3a 30 81 6f 17 60 b7 c4 42 c3 30 30 37 58 24 f0 e4 63 50 00 00 00 e0 3e e7 74 29 c5 c4 9b 38 09 de c6 d3 06 9f fd 65 57 fd bf b6 1d 65 38 4b 44 e0 23 9a be 24 e5 e6 8a 52 14 2a a4 5e 79 fe 10 55 c0 5a 2e 04 f4 8c 04 74 3c 17 e9 5d 2a 55 4d 14 36 05 e7 c9 31 98 d6 2e 01 a9 e9 55 92 cf e5 d9 d3 d3 06 e1 5a 40 00 00 00 b5 1c 63 4b 8c 8d f6 5e a6 a4 a0 e4 3e ac dd d5 d4 15 9c 37 6a be 4b 39 5e ca 2f bb 65 b6 96 56 28 eb e8 e4 f8 d6 94 de a5 55 0d 26 99 fb 2f fd f8 9f d3 b8 43 4e db d5 56 b1 c7 8b a3 17 34 61 (REG_BINARY)

"CCB7AA85A8A10855C2FD402E545B1A05776C11256C"=01 00 00 00 d0 8c 9d df 01 15 d1 11 8c 7a 00 c0 4f c2 97 eb 01 00 00 00 c2 cf 8c 3a d2 c3 42 44 b9 f0 64 2f 97 f2 c7 d7 00 00 00 00 02 00 00 00 00 00 10 66 00 00 00 01 00 00 20 00 00 00 6d 95 9e c4 70 76 b6 05 c5 1c a0 38 1f 53 46 03 c1 87 03 f3 6f 0d 2e 62 b1 5a a3 f9 19 39 d9 bd 00 00 00 00 0e 80 00 00 00 02 00 00 20 00 00 00 e5 a6 ac 94 e0 81 ff 2e ea f7 70 15 78 e5 80 af 19 a1 7d ba 7e a1 d6 89 aa ec 05 8c aa c0 41 d8 50 00 00 00 4d a2 2e d0 03 d9 26 33 f0 af 8a 7c d5 c8 5a 10 06 80 09 31 1b 82 fa 2f da 21 5d 9d 52 0a 00 42 3b 3a d8 8a 3a b8 d9 2f 48 73 12 0d 09 1f cb fe 34 e2 0f 5b 9e fc 3f 65 7c f7 7d f2 8b a2 e3 46 de 6f 36 1c f3 10 18 18 4b 31 c3 b4 be fb 94 6b 40 00 00 00 64 94 69 f0 87 75 13 5a 17 a4 5e d4 73 08 af 6c 76 eb cd f7 aa 00 3c 49 91 3d c5 98 83 1d d5 59 10 c5 9d 94 f3 0f aa b2 ec 09 71 cc a3 01 36 35 cd 7c 93 97 fb 57 80 cb d8 5e 00 43 b3 86 70 a6 (REG_BINARY)

"D54147DB1C362F0995D2B42EA73FA59BA45E4737B1"=01 00 00 00 d0 8c 9d df 01 15 d1 11 8c 7a 00 c0 4f c2 97 eb 01 00 00 00 c2 cf 8c 3a d2 c3 42 44 b9 f0 64 2f 97 f2 c7 d7 00 00 00 00 02 00 00 00 00 00 10 66 00 00 00 01 00 00 20 00 00 00 7a 6f 32 2a 20 23 f8 a3 ec c2 08 66 2b 2f b6 0b ee dd 41 bb c0 4a ee 03 a5 49 5c 41 12 9c f6 7f 00 00 00 00 0e 80 00 00 00 02 00 00 20 00 00 00 a3 61 83 a5 f6 2b 13 31 97 8a c1 11 ef ff 95 d7 4f fc 4d 48 d3 85 7e 96 d5 fc f4 b5 68 c7 e7 a0 50 00 00 00 a1 61 42 92 20 04 79 7e 9d 66 6b af ea b2 e7 1c d7 cc 2b ef 87 f8 da 0b 5a 5e 22 fe 8f 8b d3 79 6a 3d e2 14 26 3d 05 e9 43 c0 ac 33 45 f5 96 01 99 57 4b ff 80 cc 59 1d 46 f7 41 b4 6d 1a ea f5 f8 99 27 e9 33 27 f5 ad c1 44 22 ce c9 4d 70 b0 40 00 00 00 2c 1e b1 e0 00 4e 92 23 93 1e fa 83 1b b9 9f fe d4 0d 7a 7b 2d 9e 54 d5 5a b5 ff 89 c4 42 ba eb 26 fc 28 63 1f d0 1d db 91 dc de 4c 90 0a 97 35 94 61 a9 53 27 24 fd a3 a6 38 f5 3b 53 ba 42 c0 (REG_BINARY)

"151C5B278B9543FD3F7C057F70B7CF8B2318C31EEF"=01 00 00 00 d0 8c 9d df 01 15 d1 11 8c 7a 00 c0 4f c2 97 eb 01 00 00 00 f2 ea f7 4b 1c ee c3 40 9c 25 6d b7 04 75 e9 d4 00 00 00 00 02 00 00 00 00 00 10 66 00 00 00 01 00 00 20 00 00 00 54 eb b9 e4 2c c5 1c f7 fb f2 47 c9 23 54 d0 e0 82 92 73 d8 ae a1 29 3a 25 32 17 a5 9c 13 2b 1f 00 00 00 00 0e 80 00 00 00 02 00 00 20 00 00 00 84 e7 1f 87 44 77 5f 71 46 ca 0e d6 b2 90 9b 61 3b 4b 25 06 0a 61 ca 69 c4 86 df 93 cc 3c 5a 5e 40 01 00 00 15 28 9a ed 38 5b 19 d8 b2 d9 5f 3e a3 ac 59 c0 86 a1 a2 a9 0d 57 2b 76 8b f9 8f 88 82 fc 27 79 94 27 f4 72 86 61 e6 58 27 93 d2 3d 18 f2 33 6f 44 54 53 6f a5 3e fb 61 94 64 14 03 93 91 c0 0f 49 54 cc 57 c4 09 72 cf 61 29 5e fd 6d 3d 6d a8 08 b0 0b 01 c0 01 a7 55 a3 90 42 25 95 0f 3c 32 2e e7 ee e6 ef dc e9 2b 0e 79 40 6f e2 83 89 24 d8 9b ee 32 76 e3 44 f0 8e 5f d1 99 69 e0 69 07 1a a5 92 41 91 32 90 15 5f 16 65 2f a3 eb 11 c7 97 24 45 8e d8 5f f9 1e 80 86 c5 77 1f 41 78 5e c9 78 c1 dd db 2a 31 9b a3 c9 7d 2d fc 37 a7 a2 a2 a9 ff d3 04 fd c5 f7 3d 3d 9e 7f bd e6 54 c7 93 56 d8 (REG_BINARY)

"C410D75D9FAB47D9ED29D3544E241F537DA1B3D93D"=01 00 00 00 d0 8c 9d df 01 15 d1 11 8c 7a 00 c0 4f c2 97 eb 01 00 00 00 c2 cf 8c 3a d2 c3 42 44 b9 f0 64 2f 97 f2 c7 d7 00 00 00 00 02 00 00 00 00 00 10 66 00 00 00 01 00 00 20 00 00 00 43 e6 cb 62 cf 7f 65 bb d6 56 7b 1f bc b1 dc 7b 13 ea 81 7c 09 77 77 ca 56 40 ff 22 0e e9 44 78 00 00 00 00 0e 80 00 00 00 02 00 00 20 00 00 00 74 d8 aa 02 1a be 8f 14 57 9a 35 04 11 e2 93 0d 0f ab ad a6 21 72 35 4a 07 83 fb 1a 30 4c ab 3b 50 00 00 00 b4 67 80 28 fc 3c b1 dc 3a 59 d9 48 79 9d d6 a0 77 c4 6b e5 55 b2 3a 6d 06 e6 6c 8c 79 f0 2a c9 5e 2d 5d 33 ad b7 14 f0 92 45 17 3b f8 d8 b5 16 80 f4 c3 a2 df 48 5d 03 8c 01 82 21 30 45 8e 58 cd 3e 21 3c f3 b6 d8 a5 89 1e 18 e0 5e d1 5b e2 40 00 00 00 0e 0f 7e fe a3 55 f5 ae 2e 80 db 45 4a 5b a2 da 72 17 e4 4c 0e 9d fb f4 af b6 f5 5c 64 61 3a eb a2 81 e2 6a 0b 34 c7 7b 09 bc 52 b3 8d af ac 64 00 3f 94 c8 2d a9 ec f0 7c d0 d3 26 c4 13 42 23 (REG_BINARY)

"02043DC0EE6FA30DA5C5225FA57DCD4F6DEFFF4CE0"=01 00 00 00 d0 8c 9d df 01 15 d1 11 8c 7a 00 c0 4f c2 97 eb 01 00 00 00 c2 cf 8c 3a d2 c3 42 44 b9 f0 64 2f 97 f2 c7 d7 00 00 00 00 02 00 00 00 00 00 10 66 00 00 00 01 00 00 20 00 00 00 a9 cc 21 dc ae b6 fe 02 8d d5 62 a1 aa 52 25 38 4c 4f 4b f9 ec 59 de 5e c7 2b 3b e6 d4 34 82 1d 00 00 00 00 0e 80 00 00 00 02 00 00 20 00 00 00 7b 21 d0 5a d6 c8 25 be 5a d3 4b 1e ae 41 75 45 b9 7b a6 20 02 ca 77 8e e8 9d 51 7d 79 f1 39 1f 60 00 00 00 3a 34 3f 65 e2 de 00 26 42 3c a3 32 37 94 12 b7 db 76 a3 c4 c2 63 f0 4c df 2d 9b 3b b1 68 33 d6 bf ca 2a 18 0c d1 00 44 fb 65 c0 8f 16 7a 0f 54 5a e6 83 b0 d3 8e 86 16 ed cc fa e4 18 6d 27 93 2d b1 6a eb 2a 38 73 4e 33 60 b4 d1 f8 fc 4f 8e a7 c7 59 06 52 e1 cd a5 f2 e7 db 77 8c 90 52 96 40 00 00 00 db 28 ea 44 58 3c 52 a0 d7 da d0 f7 42 29 4b 22 f6 c5 66 1a aa 8a b7 8f dd 3d 56 d2 b8 9d 15 99 ad af f1 44 9f f5 93 40 96 cc 86 8e f5 1f f5 ca 65 b6 58 5d c1 ff 2c ce 8a fa 6e 30 9d cc ff 3b (REG_BINARY)

"47DC317DB95F9F35009E68790B029F6EC48636461C"=01 00 00 00 d0 8c 9d df 01 15 d1 11 8c 7a 00 c0 4f c2 97 eb 01 00 00 00 04 ae 72 13 3a 84 f1 4a 99 2f 70 e7 3b 78 23 f2 00 00 00 00 02 00 00 00 00 00 10 66 00 00 00 01 00 00 20 00 00 00 98 73 4d 85 df 0c f0 a4 53 df e3 cd 88 05 76 a7 2c ae 27 b1 11 9e 45 7e a5 2b b2 87 af 06 06 1a 00 00 00 00 0e 80 00 00 00 02 00 00 20 00 00 00 25 35 44 7c 2e b5 c4 80 5f a5 45 2c d7 7a cb 4e ca 60 ff 89 71 08 a4 ef a6 3b ff ea e4 28 ac c9 10 01 00 00 0c e1 7d 34 6a dd 70 03 7a e3 34 2e 20 b0 4f 4b f1 79 21 c7 a9 59 0a b6 21 a5 37 38 79 36 7c 77 8a ea 0b 9d ff 2d 98 a7 30 df 4c c1 89 01 aa e8 ed 83 f0 9b b2 1d c5 b6 f2 65 25 ce 23 c7 b1 9f 34 20 82 28 83 8a 63 40 bf 8a f4 d6 ef 61 4b 8a e8 fc 3e e0 2f 36 05 68 47 c3 2f c7 ea 7d df 8c 58 35 49 ab 69 94 0f ca 1e 8c 6e 67 68 a9 20 e5 3b 71 66 a1 0e fb 00 5b 6c 7a 9e 8d 7a 79 4f 3e 57 04 01 85 af 3b 7b 97 13 81 32 75 47 b4 9f 20 11 70 b0 2a 4e 4b 3c af a6 5b 3e 8e d0 68 6c 43 e5 e9 71 55 c8 6d 4b 37 ee d2 83 fc 4f 17 46 1d 42 73 e6 58 97 3b d4 55 ba c1 ce 2e cc 40 53 cf be b1 ff (REG_BINARY)

"CA1AF6DCC6287BCEA721C0EEC4B388720F0B7B83EC"=01 00 00 00 d0 8c 9d df 01 15 d1 11 8c 7a 00 c0 4f c2 97 eb 01 00 00 00 8a 69 ec 29 91 60 0d 43 a0 7d b6 52 26 80 0a 9b 00 00 00 00 02 00 00 00 00 00 10 66 00 00 00 01 00 00 20 00 00 00 9e 92 c5 3b 78 52 6c e3 3d 3d b1 7c 62 d6 7c c2 cf 8f 8c 9e c0 3e 90 68 9f 47 65 2d 09 4e 3a 52 00 00 00 00 0e 80 00 00 00 02 00 00 20 00 00 00 17 e3 ac 32 09 4c e6 55 d9 30 a5 68 c6 51 22 b5 16 f2 36 73 47 35 95 ed d6 e4 a5 0b 79 20 39 8d 80 00 00 00 ed b2 85 bb ef 58 bc b0 fb bc 5b c9 58 df 6e b5 94 4f 37 07 23 59 5c d7 65 e4 59 9c f6 c9 cc c5 aa 2c b1 7c d0 c6 0a 6a 06 4b 00 28 bb 76 bb e1 c3 64 44 0f b8 1b 6b 57 d7 8e f7 c2 4c 99 bd 5c 97 d3 7f 69 e3 91 3d 56 85 d5 3d fe 6c d1 03 3a c1 08 19 05 1e 61 6e ad ca 2c d4 3c bb 96 22 99 2b ec 0c cc b5 fe a3 f4 7a fc fe 6a 54 c6 c4 6f e1 94 bc 0d 1a bb 77 47 4a 10 57 00 8a 9e 1f 1a 40 00 00 00 7f 91 84 55 db 3e 4e 7b ca 74 94 18 47 e7 67 f5 05 1f 52 9e 2e d5 60 0f f5 81 84 77 9d 01 30 34 48 ad 1b 20 c6 f4 d9 ed 6d 4e 6d 63 65 3d 13 a0 ed ef b1 40 80 33 ec 96 db 3e ec 33 b7 6c 5f (REG_BINARY)

"BBF96385C514B28DA9DAFBB609FF775CC344709DD7"=01 00 00 00 d0 8c 9d df 01 15 d1 11 8c 7a 00 c0 4f c2 97 eb 01 00 00 00 c2 cf 8c 3a d2 c3 42 44 b9 f0 64 2f 97 f2 c7 d7 00 00 00 00 02 00 00 00 00 00 10 66 00 00 00 01 00 00 20 00 00 00 6a 55 a8 c0 4b 2c a5 d6 11 d8 e6 a3 52 b1 9c 42 7f 6a 8f f4 b2 52 37 cd 50 cc e8 40 28 49 27 c2 00 00 00 00 0e 80 00 00 00 02 00 00 20 00 00 00 9b 7b 36 4e 0a 39 8e 12 87 43 6c c7 00 de 45 16 a4 20 71 0e ae 61 41 d1 93 ac 9f b2 d8 92 e3 6d b0 00 00 00 9b df e2 c3 24 ff 44 0c 3e c5 0d 67 f4 ec 6b 95 a6 88 24 b2 dd b2 69 1c 13 44 ad 43 eb f1 e0 68 13 f5 7c 1e 64 84 25 17 4b ad fb 5d 60 47 55 3f 35 84 72 b2 a0 04 2c 77 f2 11 a6 90 7e 61 3e f8 65 4f f8 0e d4 76 06 ab ee 69 47 e0 76 9f 5f 48 85 79 45 c4 9c f5 64 d1 cb 76 c8 67 e3 ae 59 e8 7f 1f 5d 6d 69 d0 f1 9d be f2 ea 0b 4e 4b 49 c8 93 f7 94 b5 56 28 ab 01 ca 11 aa 34 09 fc dd c1 de 2c 38 8d 89 43 9d ca d4 d6 9b f1 36 ed 2e bb 30 7b 3e b6 15 a8 f3 49 4b e7 bf 39 8b 9d 75 e5 0d 45 d0 7b 18 32 52 9f 99 28 c8 6a c7 01 71 dc 40 00 00 00 63 24 06 80 c4 aa 50 26 e5 e2 2a 1b dc 49 a2 (REG_BINARY)

"C18721EFAB6878A8513E6AF97B2C1BA38FAABA5025"=01 00 00 00 d0 8c 9d df 01 15 d1 11 8c 7a 00 c0 4f c2 97 eb 01 00 00 00 c2 cf 8c 3a d2 c3 42 44 b9 f0 64 2f 97 f2 c7 d7 00 00 00 00 02 00 00 00 00 00 10 66 00 00 00 01 00 00 20 00 00 00 61 bb 07 e8 01 2c 97 58 34 f5 80 ac a2 12 e8 a2 95 9a 16 2e 77 62 87 95 2e 33 93 d4 68 51 a5 bb 00 00 00 00 0e 80 00 00 00 02 00 00 20 00 00 00 bc d5 f0 6f e8 9c ba 45 9c a7 38 68 f0 f0 d4 bb b8 61 b2 f9 8d 2e f6 a2 fd e2 25 af 45 75 0f 65 60 00 00 00 61 92 95 a3 db 30 9f 82 70 45 e6 92 95 4f 64 97 1e a7 30 85 15 2b a0 ee 81 76 91 4b 94 18 2e db 16 bd 90 06 2a 3b 07 3a 6d bc 8d c7 94 8f 4e 37 dc 54 a2 cc 62 5e be e6 39 32 33 d1 1d 55 a4 da fe 68 19 0b 1d 39 b3 91 05 d2 a7 05 06 f9 5d 15 22 9d 9a 45 63 1c d7 12 3d 0d 9c 95 c8 11 a0 cc 40 00 00 00 92 92 0b 9c 92 34 84 52 c7 6c 9d 04 37 19 5b 98 12 fb 13 28 c5 79 75 cf be fa af 1b 3f 7c ce 6a f9 bd 51 40 5e 95 b2 e4 29 f3 3c bc dd e8 b2 39 ad 7c a0 57 a7 45 e1 0e ef d4 03 6e eb 32 0f 74 (REG_BINARY)

"FEC428075B736AFF62839D75417AB78E124D623E1E"=01 00 00 00 d0 8c 9d df 01 15 d1 11 8c 7a 00 c0 4f c2 97 eb 01 00 00 00 c2 cf 8c 3a d2 c3 42 44 b9 f0 64 2f 97 f2 c7 d7 00 00 00 00 02 00 00 00 00 00 10 66 00 00 00 01 00 00 20 00 00 00 18 8b 8b ff f1 cf dc d4 eb 38 27 48 0e 01 cd 22 6d ff 9c c6 5c b6 f4 aa e7 2e 82 a4 d8 b7 11 e6 00 00 00 00 0e 80 00 00 00 02 00 00 20 00 00 00 47 4f 9c 26 47 34 d3 96 42 06 f9 30 3f f8 df 3d 8f 36 fb ff bd 6a 2b 98 78 0d ef 0f c0 f1 e0 25 60 00 00 00 86 05 be f8 83 ad ba 2c 82 47 2d 81 94 2d b7 a9 ea 36 2d 5e 10 58 16 32 3c 33 c4 84 d1 bc 2c 0a cc 5e a9 2a 67 6e 5d 2d a0 b6 4c 02 70 6d ca 72 89 39 3b 83 df 22 a0 b1 ce 90 85 13 32 80 7d ef c8 57 b1 b5 e9 a1 fb a4 f3 6f be e4 00 e5 36 7b b8 e6 4c f9 8b d9 51 7a 77 5b b6 b4 bc fa 9d f0 40 00 00 00 93 d1 5c 62 a1 f8 cb 38 b1 5a a3 c0 a8 bc 86 f0 6c 11 7e 74 fe dc 0f a5 d4 5c 4f cc b5 c0 1b df 3b 35 70 3a 8a a9 93 fd 67 05 20 5c 5d 59 24 26 c3 d3 30 3d 97 fd e0 ea 23 4d 6b 76 77 6a 79 3e (REG_BINARY)

"7AA84842A4E0DAC7EEA7E524E2442BDEFC9A089BD7"=01 00 00 00 d0 8c 9d df 01 15 d1 11 8c 7a 00 c0 4f c2 97 eb 01 00 00 00 8e d5 05 4b 23 8e 0e 48 9e 87 56 5a b7 3a ed 67 00 00 00 00 02 00 00 00 00 00 10 66 00 00 00 01 00 00 20 00 00 00 3c 2c 58 82 9f db e9 e7 7f 01 ac 69 6b c3 17 0f 29 cd 55 9c 87 6e 5e d2 94 37 8d 29 b0 4e b6 34 00 00 00 00 0e 80 00 00 00 02 00 00 20 00 00 00 c3 ff 0d ed 14 6d 94 74 c8 d6 4a fa 38 f1 c3 3d 50 96 95 d0 3d d5 8f 77 93 98 84 d9 91 d8 fa 9b c0 03 00 00 7b 14 d2 7e 0d 76 cd 6d c1 23 4b f5 56 82 fd b8 16 89 18 03 d6 63 e5 37 e6 08 e9 4c 30 1f c6 64 c4 4b 73 b3 be ee a8 37 93 58 d3 4c 12 be 65 99 4e fc f2 2f fa 42 3d b1 5b 13 df f7 1b 1f d4 f2 3b 7d 40 ea b7 63 d7 5e c1 a5 6a d8 6e 66 d8 cb b8 ee ac 5d 79 96 63 f9 64 38 91 ab a8 2d 76 a2 48 69 fe 9b de 81 45 11 16 60 21 b0 5e 2a d4 e9 16 a9 b6 0a 8c 2f c8 12 56 f8 3f 66 fd 53 84 cd 35 5b b9 94 81 d1 83 25 4c 58 91 a2 31 a0 56 7b 3d 96 a7 9b 43 9a b4 a0 82 d4 00 40 a9 af f9 99 e5 05 80 4e 33 8f 07 7c 07 56 ce b4 6b e5 94 c4 fb f1 5b 7a ed 9e 66 dc e7 3b e3 e6 1e 4f 66 a2 3f 8c 70 (REG_BINARY)

"942AAC68E084290B6F96F526CE78F25AE4DB7E4EA7"=01 00 00 00 d0 8c 9d df 01 15 d1 11 8c 7a 00 c0 4f c2 97 eb 01 00 00 00 c2 cf 8c 3a d2 c3 42 44 b9 f0 64 2f 97 f2 c7 d7 00 00 00 00 02 00 00 00 00 00 10 66 00 00 00 01 00 00 20 00 00 00 d3 f8 97 d5 88 56 96 73 44 1e bc 7c 28 62 e4 78 89 a9 94 e8 ab 10 56 3c a0 61 4f c4 ff a2 98 a5 00 00 00 00 0e 80 00 00 00 02 00 00 20 00 00 00 34 df 25 8a d1 9c 7a 21 be d9 d0 c0 19 6a 39 28 78 e7 ba e9 b5 e7 00 77 f8 ca 93 3b f1 d9 1f 2e 50 00 00 00 08 b0 84 fe bb ac 44 ec 12 cb 87 aa 26 32 88 75 cf bd 8d 90 05 e5 92 08 4a de 4b 94 e4 dc 70 24 78 83 06 fb 5f 30 a7 65 8f a5 91 83 20 6d 43 d5 cf f5 83 d6 4b e8 09 ae 7e 10 31 16 42 7d 23 3e 57 e5 f6 4f cc f0 39 d7 f0 ab e4 d4 32 7a d7 29 40 00 00 00 9c cc 79 10 69 a0 df c8 5d 9d 54 5a 6c 2f 2b 19 f8 92 2c 50 84 2f 8b 47 fe 43 32 d5 0b 21 ae 18 2e 5e b6 fa f7 43 45 5b f0 4e 08 0a 77 32 34 a8 98 66 81 d9 bf 36 9f 2c 4f ad c0 60 82 c7 c8 5a (REG_BINARY)

"9BC240B202D6B8D28B653AAA76A47E5AA8DFD07442"=01 00 00 00 d0 8c 9d df 01 15 d1 11 8c 7a 00 c0 4f c2 97 eb 01 00 00 00 c2 cf 8c 3a d2 c3 42 44 b9 f0 64 2f 97 f2 c7 d7 00 00 00 00 02 00 00 00 00 00 10 66 00 00 00 01 00 00 20 00 00 00 c4 ae 0f d2 7d 87 f7 bc 5d cf 59 dd 95 71 39 37 8b 74 71 82 f7 a8 16 ad d0 0f f2 fc c9 ef d3 9e 00 00 00 00 0e 80 00 00 00 02 00 00 20 00 00 00 e2 cb 19 ab 16 fa a5 4d 5c 19 58 8e 0c 42 1f 7d 6c 50 c4 4e 19 45 2c 12 18 85 72 28 04 e0 0b 5a 50 00 00 00 00 33 b9 7d 6c 72 50 65 be 4e 13 96 34 c3 29 82 07 94 19 20 f0 9d 9f f4 9d f9 82 40 33 cb 28 7a ee 8f 72 49 e9 9a 03 ad 79 ea b1 50 aa 9a 89 42 b5 cc 82 2c c0 e2 76 20 1a 89 8f 38 84 f2 09 e3 ee 2d df 88 c8 cc 85 9c 39 5d 4b b0 1b 4b 12 00 40 00 00 00 9c 69 9d 08 5c cd ab 1f b8 54 4e 4d cf 56 6b 72 60 12 ec 9a f3 7c e2 3c b4 3a cc 8f b2 7b 33 33 a6 a5 d9 1e a3 52 49 dc a2 eb 44 a4 34 2a db f3 2c 9a 30 bb 19 6b ae 41 b8 2f da bc 5c fc e3 c5 (REG_BINARY)

"CC789E0CC6B535DAA1EEA742F205F55F60ABB7504D"=01 00 00 00 d0 8c 9d df 01 15 d1 11 8c 7a 00 c0 4f c2 97 eb 01 00 00 00 c2 cf 8c 3a d2 c3 42 44 b9 f0 64 2f 97 f2 c7 d7 00 00 00 00 02 00 00 00 00 00 10 66 00 00 00 01 00 00 20 00 00 00 e9 2c b4 48 94 0f d7 87 da f2 e6 6f c9 75 3a b9 99 01 c4 94 66 40 70 21 08 42 0c 11 de 8c 75 01 00 00 00 00 0e 80 00 00 00 02 00 00 20 00 00 00 36 e6 09 05 17 e5 a6 c6 ce c5 6a 87 8b 95 16 4c cb 5c 03 97 5f 95 7b ab 29 27 02 5c cd b8 fa 89 50 00 00 00 6e c8 df 78 b0 ef 7a 27 39 f6 d5 87 6d a0 96 ae 2f 26 06 77 7d d8 c4 f5 87 38 47 93 7d 1d 83 fa 46 b1 e5 be 72 5f 8f 6b ae d6 52 66 98 c4 26 1e 7a 3c d1 7b 06 1c 14 96 44 27 4b 76 28 cc 6e 8c 24 44 88 b1 1d 29 91 be 7f b4 12 c5 26 b4 47 e5 40 00 00 00 26 f0 90 9d 0e 4b 20 49 fe 20 1d 7d ad 1b c8 87 6e 02 af b2 e5 37 11 8c 51 70 a4 78 c6 11 8c 7c 6e 23 88 33 1c de cc 8d a6 3a b9 76 7d dd c8 21 46 3e 1c 09 1e 6d 9c 8f 6b e5 2e df 47 82 8c ec (REG_BINARY)

"4A245A629AAFE61C2397B17960D4364F640ED662BC"=01 00 00 00 d0 8c 9d df 01 15 d1 11 8c 7a 00 c0 4f c2 97 eb 01 00 00 00 04 ae 72 13 3a 84 f1 4a 99 2f 70 e7 3b 78 23 f2 00 00 00 00 02 00 00 00 00 00 10 66 00 00 00 01 00 00 20 00 00 00 17 85 d8 4f 0d 93 73 88 79 2a ae 80 0c 9a 78 8f 5e 80 6d 7a 94 40 53 9a 5d 66 83 72 5c 9d 1e 16 00 00 00 00 0e 80 00 00 00 02 00 00 20 00 00 00 89 6a 52 8f f9 a4 b7 47 e5 ad 56 0c 31 58 30 cf 1c 8c be f6 ed ad e0 e0 05 ef 76 d8 70 83 80 cb 60 00 00 00 2a 70 34 87 87 05 19 00 c8 70 c4 31 32 1c db e5 aa d3 d5 fe 6d ef 61 5c 69 01 a0 90 b1 5b f3 db c0 55 59 43 2d 00 6e 1d a9 0c ad de 14 09 34 fd 18 ac 23 60 76 96 c9 ac d9 09 5d 85 53 6a 3c 8d 20 0d b7 29 fa f1 19 ad 12 95 b4 72 03 21 57 2a 36 ac d1 fd 99 6c 7f c4 26 8c 55 0b 8b 07 b1 6b 40 00 00 00 d3 44 31 ff c8 4e 12 f5 ed 15 3d 3b 48 71 21 bd 98 a2 3a 04 48 dd ef e3 e6 91 49 92 cb 8b ec d3 e7 04 96 b4 4b c1 ff 92 bb a5 c8 1b 2e 9e 29 93 21 55 8e 16 0c 6c b5 d3 03 fc 63 77 e2 55 b9 d4 (REG_BINARY)

"94A17B8D29DF1B9AFE779145FA10E6F97EF9A458A1"=01 00 00 00 d0 8c 9d df 01 15 d1 11 8c 7a 00 c0 4f c2 97 eb 01 00 00 00 fa a3 72 49 a9 04 8c 41 b0 23 5e 0b 9e 7a ce 75 00 00 00 00 02 00 00 00 00 00 10 66 00 00 00 01 00 00 20 00 00 00 b8 84 1c af 0c 14 db 35 da 21 8f e0 8c 7e 0c 45 f9 15 08 f7 dc cf 25 5c eb 09 9c 36 0b 5f 3b 4e 00 00 00 00 0e 80 00 00 00 02 00 00 20 00 00 00 fd c6 38 89 75 8c 8a 5a cd a9 7e 32 92 33 dd df 03 56 2c c3 9a dd 38 15 bc 15 01 60 1b a4 a6 6e 20 01 00 00 d4 61 6f 6d a5 19 e4 b6 ce a3 eb e2 44 ad c2 26 90 4f 5d 70 3b 5b e2 2f e1 65 e7 18 2a b6 a5 b4 c1 c4 ac 1f 07 7c c5 e2 4e f5 9b e7 35 71 42 8f c7 01 3a 8c f4 54 76 d7 75 24 20 cc bf 15 b9 9f 3b 4d 6a 9a 78 db e2 c0 25 a8 b3 6c 4c 0a 05 d3 23 9a 95 73 ca a0 7f 8c 81 99 4b 01 49 3e 86 8d 97 e9 6b ac be ad 79 99 54 80 98 8f 8e 3e cf 15 65 5d 98 ce cd 74 74 7a 16 8c 7d 71 e3 78 0f 63 a4 35 0c 42 ed 18 ab d2 00 13 3b f1 3a cf 1f b9 db c3 02 ad 17 fa 3c 3a 67 a3 4f 0a c4 d1 bd 27 25 08 4d 1e 38 66 e0 80 95 eb ca 61 4b ce d1 a3 2d ee 54 47 ab ee c4 49 08 66 1f 3d 84 e4 8b 78 14 bc 55 (REG_BINARY)

"B37488662C45CF4DFCB20FF8F84774C88542645653"=01 00 00 00 d0 8c 9d df 01 15 d1 11 8c 7a 00 c0 4f c2 97 eb 01 00 00 00 fa a3 72 49 a9 04 8c 41 b0 23 5e 0b 9e 7a ce 75 00 00 00 00 02 00 00 00 00 00 10 66 00 00 00 01 00 00 20 00 00 00 6f a9 4e d1 5a df a6 7d 55 09 3a 64 19 95 26 30 ab a5 ae f6 43 14 e4 09 2b 1b c0 96 7b e0 45 19 00 00 00 00 0e 80 00 00 00 02 00 00 20 00 00 00 59 fb 5e cb 86 d6 bd 32 8b 86 73 e2 7c 01 ac 1c 7e 09 a0 d7 6f 10 43 49 a1 17 fe ce 2f ad 41 b0 90 00 00 00 46 70 42 ae b6 3c 05 48 48 aa aa d4 87 dc 9b 7a 8f 76 7f c8 f1 0c 51 a6 d6 9c 02 05 18 c1 67 e1 44 b9 8b d4 71 b3 9f ee 4e a1 94 92 f2 84 df f4 67 be 97 90 c2 17 e2 b8 b0 f5 b8 eb 28 87 79 98 cf 27 ee e7 64 c8 47 fb 62 c8 ee 85 c9 63 5f de 2d 15 7c e4 a1 86 39 c2 c6 c5 20 e1 b2 28 c4 0d f1 d7 9b 8b e6 01 6f ec 90 13 8f 71 d8 e4 33 42 8d 30 c6 03 61 b1 31 c0 2a 4a 97 59 fd ea 4a fd 61 d5 70 65 b1 2f 64 96 f1 c1 c6 fb e9 e3 98 2f 40 00 00 00 95 50 f7 76 d7 21 e4 f4 a4 73 d1 83 e2 54 0e 4c 39 d6 63 e2 57 b3 0c bc 42 46 8f 2c 20 21 5d ba bf bc 2f e2 60 f9 b1 72 8e 55 87 49 bc a8 d0 (REG_BINARY)

"D5D8F7CEF4CBF3FB159FC54BF4757083D0002B144E"=01 00 00 00 d0 8c 9d df 01 15 d1 11 8c 7a 00 c0 4f c2 97 eb 01 00 00 00 af 7e a6 54 98 6f a9 42 bc b9 44 ea 4d bc 04 d3 00 00 00 00 02 00 00 00 00 00 10 66 00 00 00 01 00 00 20 00 00 00 eb ee b5 f6 41 8d 98 da de 3d 8a 53 03 f9 49 b1 10 94 f6 bc 73 d3 22 1a c2 cb 53 a9 14 79 8f 52 00 00 00 00 0e 80 00 00 00 02 00 00 20 00 00 00 d8 00 73 79 04 19 c8 d3 7f 3d 74 cc b6 8c e1 c8 78 92 a7 eb 3a 8c 87 04 0b 11 ce 78 fa a7 26 54 60 00 00 00 32 c4 c3 93 4e 24 ca 0a 2f 78 30 b7 0a 2e 16 da a4 01 55 95 c0 71 bc 2c 91 d4 df f1 aa c8 1b 00 06 dd dd 46 67 48 b8 be 32 0b fa f2 99 03 4e 46 29 87 3a d0 6f da e7 fc f9 1e cb 03 cd f1 30 41 5a 16 29 92 16 9e 17 9e 60 89 d1 c3 33 8e ef f1 e8 a2 01 63 74 af fa 1f 9e 44 51 cd 27 eb f3 aa 40 00 00 00 25 da 20 6c 88 b8 fd d4 5d 64 97 8f 2b 7f 1e d8 2e 9a c3 fa 67 15 33 0f 02 23 d1 69 3c 75 e1 10 95 5f 20 31 6d 0f 8d ba f0 8b 74 32 cc 3a f8 b7 5a 89 c2 c4 1e 3a 52 f0 3d f9 96 43 b5 13 eb 9b (REG_BINARY)

"25BF81B879AFDE75D14AA3BF8FD8EB93EF505851E2"=01 00 00 00 d0 8c 9d df 01 15 d1 11 8c 7a 00 c0 4f c2 97 eb 01 00 00 00 af 7e a6 54 98 6f a9 42 bc b9 44 ea 4d bc 04 d3 00 00 00 00 02 00 00 00 00 00 10 66 00 00 00 01 00 00 20 00 00 00 97 e4 0e 31 08 40 d2 28 51 12 ac 0f 20 79 ef e9 63 6e 80 e9 79 df 12 ae 2b 80 aa 86 00 3c 33 45 00 00 00 00 0e 80 00 00 00 02 00 00 20 00 00 00 90 93 38 66 e5 a6 f1 a0 64 f1 a6 59 1f b2 27 ac c8 9e 8e 5f f0 71 28 3c 32 78 b3 0a 9d e3 ee 93 60 00 00 00 f8 57 27 77 6f 5d ae 5a 6e d6 4d 3f 30 af 26 63 e6 04 3d d6 91 18 f7 32 5b f5 50 62 d8 63 89 60 f4 90 c7 af bf 69 27 41 4a da 61 51 e1 ba 1f 92 27 1a 82 d1 ed 64 d3 8e 6d 7e e0 dc 05 a5 41 c2 28 b9 cf c8 e4 7f fe 53 68 86 e3 c5 8c 2d a8 11 0e 02 ef 4e 73 1b 76 c7 45 4b 2f 84 02 5f 35 99 40 00 00 00 39 45 b7 1c da 6b ca 3c 5d da 60 45 af c7 b1 b3 51 d0 ad 8c 89 5b b3 0d d3 ee a0 f8 29 d5 f6 da 6f 73 f0 38 9f a9 e8 ee e5 97 96 1b d5 d9 10 bd 8a 00 35 7a 09 85 53 08 94 c8 8d ed 8f 05 5c 63 (REG_BINARY)

"447259CD65F314BE302A4F150B744569A4FC4D9B79"=01 00 00 00 d0 8c 9d df 01 15 d1 11 8c 7a 00 c0 4f c2 97 eb 01 00 00 00 af 7e a6 54 98 6f a9 42 bc b9 44 ea 4d bc 04 d3 00 00 00 00 02 00 00 00 00 00 10 66 00 00 00 01 00 00 20 00 00 00 bd 67 42 30 24 cc 51 1e 98 3a 57 0a 5d 37 98 48 2d f5 01 59 02 f9 78 f8 9b 84 74 59 ff 2e ca ee 00 00 00 00 0e 80 00 00 00 02 00 00 20 00 00 00 4b 95 2e b5 10 bc e5 d3 17 9d 24 b3 26 94 c4 d7 7a d7 30 41 84 c7 e9 05 eb c1 3d aa c9 09 39 70 60 00 00 00 f7 0e 65 b3 47 a7 a7 7f 3b 65 9a bb 39 d3 e9 db 87 02 e3 3e 38 43 b3 19 d0 2e 5d 68 c8 a6 a4 1d df 4e 7b af a6 39 05 6c cd 21 a9 e9 3d 61 15 f3 fd 70 0f 80 d2 c4 3b 32 40 94 22 99 17 94 eb 4a ee d1 61 2b 46 83 9a b7 d7 24 1c 92 fd ae 47 c9 78 7e ec be 79 40 25 76 f5 d1 4c 29 03 39 31 00 40 00 00 00 50 19 2b 15 e0 07 d5 20 05 8f e2 6b 55 4a c1 62 a3 27 0f 75 5e 6d 70 b7 1e 79 99 82 08 fe cb 5b 7f 55 47 b5 d4 53 7f 01 ce 6f 6e 14 45 89 14 05 23 90 f3 87 87 d9 22 f3 4f 12 bc 4e 3f d6 53 c9 (REG_BINARY)

"E6F0BDB3AD91C56FBBB0F48F69EEA9133740617B0C"=01 00 00 00 d0 8c 9d df 01 15 d1 11 8c 7a 00 c0 4f c2 97 eb 01 00 00 00 af 7e a6 54 98 6f a9 42 bc b9 44 ea 4d bc 04 d3 00 00 00 00 02 00 00 00 00 00 10 66 00 00 00 01 00 00 20 00 00 00 78 9a cd 46 bb de 45 9d 84 90 83 fb 87 bf 5b 0b 38 6c 71 7a 84 a7 92 51 d9 45 4b e6 e4 ae e8 ee 00 00 00 00 0e 80 00 00 00 02 00 00 20 00 00 00 45 ae 78 b1 b9 79 c0 42 17 81 a4 61 51 28 ec f3 14 4f 5c c5 36 6d cc 31 ef 15 7d 6b f7 70 6d 38 60 00 00 00 4e da 3d ed f4 c6 66 71 6e 92 11 d7 de 2f 6d 8d de 53 16 67 10 0f af 2d bb 69 89 b9 6c 9d 58 fe af 42 16 54 18 15 9f f1 22 9c c2 2c 15 10 85 48 a8 a5 5d d9 f3 99 4c c3 c9 8d 33 6c 6e c3 9b 13 91 66 86 c3 5b ac 4c d4 2e 50 93 f5 91 09 de 92 2d 4e e6 52 a3 b6 e9 d3 6f e2 05 36 c0 c7 eb 3c 40 00 00 00 dd f8 67 a3 67 ea bd 16 40 02 34 f2 bb aa 96 b9 3a 88 2e 65 37 a3 8a a2 67 df b6 1e f0 0f 8f df 5f 6e 5e 20 31 d7 44 db e4 ee 6f a4 e3 72 c7 67 d1 ce 01 15 43 56 fe 97 50 b2 d2 96 2b 6a d2 fa (REG_BINARY)

"0D6FAE7C2B35388ECCDFE4C2A2E9437F457B9E37FF"=01 00 00 00 d0 8c 9d df 01 15 d1 11 8c 7a 00 c0 4f c2 97 eb 01 00 00 00 fa a3 72 49 a9 04 8c 41 b0 23 5e 0b 9e 7a ce 75 00 00 00 00 02 00 00 00 00 00 10 66 00 00 00 01 00 00 20 00 00 00 b7 0e a5 02 03 2e c6 86 a0 1b 03 60 d2 9e b1 47 5a c6 89 02 ae e0 53 1a dc f0 06 7e bb 84 8e 88 00 00 00 00 0e 80 00 00 00 02 00 00 20 00 00 00 e8 e5 6b 9f e2 58 05 32 d7 6b c2 e9 b8 d6 63 17 23 4c 00 e5 8a dd e5 45 14 c7 e2 cc b8 ed ce 40 b0 02 00 00 7d 7b 33 da 59 20 9d 1f 99 a4 fa 4b 83 f6 ef 19 f0 02 da 8a c0 b9 bb 7c 65 d4 37 0e 76 94 d8 22 06 f4 0d 36 d1 b9 8a 1d 64 ef 01 6a 0a 4d 56 68 a4 fa 43 29 ff bf 29 88 91 72 12 3b bb 06 55 e5 3d 92 1f 15 5f 86 23 0f eb cb d9 a9 c8 8b df c0 b5 31 96 cb 7e d5 a2 eb 1c d7 94 bc e2 1b fb 73 91 05 55 e8 d1 c7 ba 25 52 2e 5f 1e c5 60 2d 60 5b 3e 4c 7a e9 fd a4 d3 30 50 df 57 d9 2e e7 0e 7d 70 3b 38 37 5a c6 96 d8 53 2a 29 cc a3 67 ad d0 13 88 20 f0 f2 f7 98 fb 7f 00 a1 f9 fe b1 98 0b 92 0b 62 34 e6 c7 ea 06 4a 58 1d 26 5a b4 99 e6 c0 09 b3 a1 4e 8f 44 b9 a4 9b a5 f8 88 5d ea 86 37 2f (REG_BINARY)

Posted

"F0169FC51E57A67BD4F6AF9381526773AD249C1B41"=01 00 00 00 d0 8c 9d df 01 15 d1 11 8c 7a 00 c0 4f c2 97 eb 01 00 00 00 af 7e a6 54 98 6f a9 42 bc b9 44 ea 4d bc 04 d3 00 00 00 00 02 00 00 00 00 00 10 66 00 00 00 01 00 00 20 00 00 00 af 34 e8 b8 b2 92 f2 69 c8 e8 a4 c7 e5 45 34 66 f6 3b 2d 10 9a 97 a9 7c c4 a4 4e e0 6e a6 74 a7 00 00 00 00 0e 80 00 00 00 02 00 00 20 00 00 00 80 00 20 ad d0 91 14 bb 2d 59 2f 0c 50 70 26 1f 0b eb e0 80 df 91 4f ff 85 ed 45 fb 55 de bd 8b 60 00 00 00 25 d1 71 5d 05 4f dd d0 be c3 b6 0d cd 22 58 ac d7 2f 46 2f 0f 65 99 0e 16 e2 db 8e 65 1a cc 9c 2b 5e 21 a1 37 56 a1 07 58 fa d3 25 b7 54 c5 5e eb 0d 12 15 25 67 c1 f1 f9 8e 35 4d 61 9e 1e c1 04 d4 e4 cf 36 8a aa 5f c4 0b 34 61 3a 0b 56 15 a1 9a ee 41 8a e1 45 53 8a 55 ee 69 db 8d 3e 73 40 00 00 00 fd 56 c6 fd ac b9 7e be 58 64 2c ae 9c 6c 63 d3 e3 66 50 34 ff 2d df db 83 b8 ce ab b4 a7 84 d4 8b ae a4 7f ca 48 5e ba e0 cc 45 15 62 b1 f1 ad 5a b2 f8 15 a7 d8 b6 f8 d8 53 3d c3 0f 1e e0 6c (REG_BINARY)

"88DAF2A867C7432E10C8970C65572E6ED91593CDBC"=01 00 00 00 d0 8c 9d df 01 15 d1 11 8c 7a 00 c0 4f c2 97 eb 01 00 00 00 af 7e a6 54 98 6f a9 42 bc b9 44 ea 4d bc 04 d3 00 00 00 00 02 00 00 00 00 00 10 66 00 00 00 01 00 00 20 00 00 00 e5 d7 e2 96 8e d9 43 05 e9 7c 28 f2 ce e6 aa 57 e1 b0 05 9b cc 24 e5 b3 89 58 4a de c7 8d b7 49 00 00 00 00 0e 80 00 00 00 02 00 00 20 00 00 00 50 c1 e4 f1 c4 9b 2f de d4 94 17 58 b0 eb 12 59 41 6f 9c 8e b9 89 db 6c 12 99 50 ab 22 ab 9f 20 60 00 00 00 16 56 53 4d 2b 72 d8 6d 2d 7f 5c ca 27 f1 64 a0 30 1c 7e 52 9b d0 28 35 99 c5 4c 41 b7 a2 e6 b4 b7 e9 f4 3f 57 f6 a4 0d 00 e9 a3 4f 26 53 58 bd 8e d2 f0 fb 13 b3 b5 64 68 93 d1 20 e1 1f 67 2c 29 6e fe 42 0e 9b 34 23 4e fa 15 f0 b8 30 5c 7e 87 fe e9 a8 2d 1c 38 77 4c b6 4b 7b 44 10 cc a0 40 00 00 00 60 81 07 c5 fb eb 7b 0d 01 c9 35 ba 3e a4 ad 83 54 e3 7c 49 f5 28 3d 3f ca b7 0f bc 4e 6b e0 2e 2c 14 86 29 68 d4 53 b5 c9 6f 79 71 62 46 9a eb 58 27 94 31 55 16 bd 8e 25 fc 4d bc 53 17 c4 f6 (REG_BINARY)

"05EDD52A1C47828E32194CA52DA6C380C12E3619F4"=01 00 00 00 d0 8c 9d df 01 15 d1 11 8c 7a 00 c0 4f c2 97 eb 01 00 00 00 af 7e a6 54 98 6f a9 42 bc b9 44 ea 4d bc 04 d3 00 00 00 00 02 00 00 00 00 00 10 66 00 00 00 01 00 00 20 00 00 00 d1 d0 92 20 a6 09 11 13 91 e6 5e 28 3d 41 63 36 e9 80 38 48 9b f9 74 c5 32 2d d9 ae ae 36 c1 dd 00 00 00 00 0e 80 00 00 00 02 00 00 20 00 00 00 f0 74 5a 7b 06 fd 4e 3b bf ec a6 ea 21 25 94 c4 ad ea 29 cc 17 5f 05 f2 23 57 3f a4 6a 36 aa 91 60 00 00 00 08 bd 1c 4c 93 45 f8 f3 1a f3 28 aa b2 42 a1 89 bc 79 19 8b 34 6e c0 f5 3b 91 cc 5d 5b 27 0d 5a 14 93 7d 77 2b 81 c3 0a 42 61 40 31 b6 af 7f e1 67 91 dc a8 b4 c1 59 2b 71 50 c6 43 6b 70 71 b1 9e 30 a0 f8 f5 91 5e 0e 29 26 2e c5 ac 30 2f d4 75 0a 35 07 c1 47 eb ad 02 e9 61 da b2 06 a7 8b 40 00 00 00 e0 5c 49 4d 2e 96 ed 82 40 7f d3 2d af ec 95 b2 e6 92 99 5f 3f 15 73 e0 32 df c4 79 e5 82 73 77 90 3b ac 35 55 8c fb 8a 7d 3e 4c ca 2e ac 72 b7 54 81 6e 90 60 23 68 91 b8 13 bc 58 6f 95 7b 17 (REG_BINARY)

"2D9243EE5A78DDC0CEA68060732D25A695B01747C1"=01 00 00 00 d0 8c 9d df 01 15 d1 11 8c 7a 00 c0 4f c2 97 eb 01 00 00 00 8e d5 05 4b 23 8e 0e 48 9e 87 56 5a b7 3a ed 67 00 00 00 00 02 00 00 00 00 00 10 66 00 00 00 01 00 00 20 00 00 00 ae ec c5 d4 a2 20 71 05 d9 48 83 e7 da 39 77 15 45 7a 32 32 f0 43 89 7d 7e 92 9d 0b 2c f9 f1 99 00 00 00 00 0e 80 00 00 00 02 00 00 20 00 00 00 69 fe 3b 9d 0f 56 d4 be 92 80 4c b4 6e 24 6f 55 8d 7d 0c c8 0b 10 82 4d f0 11 db 27 24 91 cd c3 80 00 00 00 84 ea cc 49 b3 82 24 9e a2 08 7b 08 8f b6 a4 3c 30 35 6f dc 47 ee fc 06 9d b4 d2 15 6e 16 15 2f 10 e7 65 b0 23 a6 eb d1 91 2f dc dd cc 2e 76 e4 a7 01 7f 4e 77 12 96 94 51 07 d0 ac 3a 9c c8 2d 65 40 9a dd d5 aa 65 fa 67 6f c4 88 12 89 c3 93 e7 52 8c d0 a0 79 10 44 e8 a2 e0 50 76 63 fb 47 40 7c 4f 84 22 3b 47 3d 96 8a 0d 05 51 8d 86 a2 10 ae e1 81 ff e2 95 f9 1a 4d 5c db 65 88 38 11 40 00 00 00 ac 9b 4d 09 09 7a 56 3a e6 a5 58 0d 27 80 c3 3d 1f 3f 38 bc dd 4c 53 ab 2f 7f 26 dc 59 7f 09 c5 14 47 8a e7 06 3d 2b 16 ba c3 8c 6a be cf 72 45 11 e8 46 19 68 85 f6 f6 4d a3 e8 34 30 14 b6 (REG_BINARY)

"DE38A809115A60CFBB28C98C7C7F72BD58C4F47C4F"=01 00 00 00 d0 8c 9d df 01 15 d1 11 8c 7a 00 c0 4f c2 97 eb 01 00 00 00 f2 ea f7 4b 1c ee c3 40 9c 25 6d b7 04 75 e9 d4 00 00 00 00 02 00 00 00 00 00 10 66 00 00 00 01 00 00 20 00 00 00 46 3a 28 be 04 b6 16 58 d9 c7 8b 0d 7f f2 cd 1b 97 8b a0 f8 00 e1 1e a3 5a 3c 96 9f 6d 3f 25 e0 00 00 00 00 0e 80 00 00 00 02 00 00 20 00 00 00 83 e4 ba f0 d6 1d cc ea b7 9f 9d e4 00 5b 7d 97 99 0e 7c 5e 0e 44 58 a1 04 35 7f bb a3 a3 a6 ed 60 00 00 00 b8 cc 5f 91 66 d9 0e e7 0d f2 99 94 47 6e a8 ac 77 f6 b0 78 e3 62 d3 33 5e 6e 65 83 fa 93 34 b3 1b f9 f6 92 61 ea 8b 80 9a 58 4a 8f 6b 91 2a 12 84 f0 99 fe 41 1b 95 c9 f7 51 fe 98 38 0c 7b ad 3f b7 1d e5 7f 9d ad 92 e0 f5 a7 91 b8 1e 0d 30 e7 36 c9 56 00 4f 8e 9a bf 37 67 76 b7 8a 35 4f 40 00 00 00 28 96 ae 84 6a f2 97 35 c4 a7 9a 74 3d 6d 69 23 82 07 f2 62 49 0d 20 b2 d4 e3 b0 d5 c4 5c e7 bb d2 e4 56 f9 ee 23 c7 2b c5 1e 57 84 2d 3f a2 03 22 c6 68 e6 18 fc 7e b8 1a 5b a2 9a 4d 78 bb 82 (REG_BINARY)

"915B07A2BAC07D1998162388E3347747A4B4B4A483"=01 00 00 00 d0 8c 9d df 01 15 d1 11 8c 7a 00 c0 4f c2 97 eb 01 00 00 00 af 7e a6 54 98 6f a9 42 bc b9 44 ea 4d bc 04 d3 00 00 00 00 02 00 00 00 00 00 10 66 00 00 00 01 00 00 20 00 00 00 3e a4 0f 3a e4 2d 02 f2 95 ca 6c 4b 26 6f 07 3f 50 cb 4d 1a 05 1c 9e 5b 47 32 59 73 db c4 2d d0 00 00 00 00 0e 80 00 00 00 02 00 00 20 00 00 00 82 72 08 c4 7b 9c e4 44 62 54 2c b2 20 1e 4b cd e5 d5 4b 80 67 de 45 4f 0b 46 9b b2 1e cf 52 81 60 00 00 00 7b 98 24 87 d3 06 d6 9e 98 dd dc fb be f6 f4 f2 2a ac 79 4f 9b 87 b6 4b 24 eb 61 b3 73 fb 58 c5 a1 87 65 0d d8 5e e0 ba 31 57 cd c4 4b 4b cf df 7f d5 bd de 74 1b 07 01 52 cd 71 85 c1 4a a9 52 32 ab 6a 11 d7 9f fd 19 ba 9b 06 1e 07 79 ef bf 5c f0 c3 3e 1d ca 26 f3 9e 1e fe 40 71 84 68 a1 40 00 00 00 24 21 12 84 81 12 66 46 8c 0e 07 54 22 c6 da 5e f1 55 49 a9 8e e5 a8 b0 a4 51 25 7e 6b c1 82 bc 2d 0a 5c c8 d4 99 be 64 e6 5a fd 66 93 dd 53 f7 8a de 2d fe 32 39 e3 84 01 10 b3 9a f3 0f 72 6c (REG_BINARY)

"3BC25C35155E4E1FA00056CE58A9268C05EF55D0FE"=01 00 00 00 d0 8c 9d df 01 15 d1 11 8c 7a 00 c0 4f c2 97 eb 01 00 00 00 af 7e a6 54 98 6f a9 42 bc b9 44 ea 4d bc 04 d3 00 00 00 00 02 00 00 00 00 00 10 66 00 00 00 01 00 00 20 00 00 00 e1 62 6f c2 7b 59 ac 2b aa 4c 63 9b 52 d6 2a d1 a5 10 f9 2c 46 e7 d5 b9 41 67 e2 d2 be bd 50 34 00 00 00 00 0e 80 00 00 00 02 00 00 20 00 00 00 c3 42 5a d9 0d 20 ce 48 2c 4a b1 3f 8a 5f c0 77 4c 5e ee 5a 94 ea 30 a9 11 43 aa a9 98 20 11 9c 60 00 00 00 42 a3 ca 90 58 22 82 4c 24 8d e7 09 7b 4d c8 74 ca eb 48 18 a2 8d cc 85 ba c3 e5 82 3e 01 5b 53 8d 41 13 39 ec ad 82 f1 23 86 7a 01 31 69 73 43 40 62 83 5a b5 6b 47 f7 58 84 70 eb 8c 9c ea 23 a5 ae 07 62 0f 7b c2 35 ce 9a b5 6f 60 d0 5a 0e 62 5a 35 2c 23 5f 63 df 54 3e ef c4 99 d9 74 91 40 00 00 00 14 4d 97 65 9d 0f c6 b0 f1 14 06 22 39 62 f2 79 80 5b 05 ea ed 45 70 3d 54 87 fe e6 7c 4a 7d 9f 8a 1e b1 01 a8 0e 8d 82 d9 63 d1 f9 81 7d bc ce 77 c3 f5 53 3f 4e e5 f9 74 2b 2c 84 e4 76 84 92 (REG_BINARY)

"7D5C9CE3BD4114A8CE61D594F3C51623E542AF75E6"=01 00 00 00 d0 8c 9d df 01 15 d1 11 8c 7a 00 c0 4f c2 97 eb 01 00 00 00 af 7e a6 54 98 6f a9 42 bc b9 44 ea 4d bc 04 d3 00 00 00 00 02 00 00 00 00 00 10 66 00 00 00 01 00 00 20 00 00 00 f7 a5 cd 6b d6 25 b0 3d 0f 50 92 02 8c fc 9f a8 f4 f9 ed 95 99 a6 1d c1 e8 b7 a3 a5 c0 21 ef 78 00 00 00 00 0e 80 00 00 00 02 00 00 20 00 00 00 f1 18 20 ba fd 0a 55 2f 7f 11 29 8c 59 d4 6b 60 a0 1b d3 a7 f5 7a 1d 7c 75 99 c0 ca fc 2c 6c 60 50 00 00 00 aa 07 46 80 0b 81 9d 56 2f 43 99 ac cb 98 12 9c f1 03 9c 05 3c 7d b5 5e f3 2a 0f bc 19 2c a1 8d eb f0 64 36 bd 05 47 5d 16 9a 08 72 7a 5c c8 df 91 62 ec ac 31 1f 29 1a b9 d1 b8 3c bf 38 94 2c 51 72 ce 80 9a f5 d9 81 bd 2d e6 02 d4 b9 9e 33 40 00 00 00 05 4e 22 84 be db 7c 0c b2 37 70 27 8e e2 16 fa 3e ec de c5 03 0d 73 29 92 b7 50 94 6c 61 14 d6 ca 90 a2 27 ed 36 4a 26 d4 f2 ab eb 9b 8e c1 7f 42 a4 78 b1 e4 18 59 2b c8 71 cf 5f 74 4a 36 d6 (REG_BINARY)

"3AE4650B05C9544EB1EC8EA9B4BED0E7B41B06EDBD"=01 00 00 00 d0 8c 9d df 01 15 d1 11 8c 7a 00 c0 4f c2 97 eb 01 00 00 00 af 7e a6 54 98 6f a9 42 bc b9 44 ea 4d bc 04 d3 00 00 00 00 02 00 00 00 00 00 10 66 00 00 00 01 00 00 20 00 00 00 6f 0f ef d1 d8 7d dc 35 69 e7 86 b9 9c 8c 9c ff 66 5d 1d b4 3b b7 f5 8f dd 50 c0 af 11 99 d4 73 00 00 00 00 0e 80 00 00 00 02 00 00 20 00 00 00 1d 23 7d 7c d4 47 fd 59 e8 b2 94 1f 9b ec 95 db 97 1b 4a fe df 8d 80 d9 e6 9b 9d ac 9c b8 b5 9b 40 00 00 00 47 2f 19 36 9c 6a f1 42 90 1a ed 76 85 23 b3 b5 98 40 78 a5 79 2c 1b f9 f7 b7 63 df af 01 2e 59 ad 9e 3c f1 00 11 5b 27 62 1c 2a db 1d 56 9b 23 30 a8 40 0e 7f a8 fd 0f ff 12 be 19 d7 63 9e ed 40 00 00 00 ec 3d 0b c1 6d f1 ec a4 a6 c1 67 03 5d 36 1f 0f 58 4e 70 c9 5e ef 21 6e 4f 90 65 30 5c 98 1d a0 b6 e2 0e 20 5a 55 ba 0a d8 4a 05 c0 5e 86 ea 46 70 26 d9 dc bb d8 b3 72 c1 07 f9 75 03 39 6d 97 (REG_BINARY)

"2B5D9B7FEC2D58A6C20F022454BDC0719314356E3C"=01 00 00 00 d0 8c 9d df 01 15 d1 11 8c 7a 00 c0 4f c2 97 eb 01 00 00 00 04 ae 72 13 3a 84 f1 4a 99 2f 70 e7 3b 78 23 f2 00 00 00 00 02 00 00 00 00 00 10 66 00 00 00 01 00 00 20 00 00 00 95 f9 d1 2e d9 c3 8b 73 a8 b0 79 34 eb 10 2b 3c 02 0f c3 c2 36 85 56 8f 1b c2 74 87 11 54 4f 51 00 00 00 00 0e 80 00 00 00 02 00 00 20 00 00 00 77 f4 e3 d1 5e b0 77 f6 71 04 74 e5 ac 35 9a 43 c0 5d b0 78 51 12 e8 bb a9 f9 ee ca e6 7e 24 b5 80 00 00 00 d9 ff 6f f2 3d 9f e3 2e a9 ed 8e c9 26 ba 99 98 b5 dd f3 8c 90 4b 86 66 e5 93 c4 50 9e e4 3a fa 9e 1d 52 4f 0c 53 e2 9d 32 8c 8c 3f da 70 a7 ee 47 30 9b bf 20 b2 03 73 90 bb a3 07 5c 6f 99 d8 58 95 cd a9 f1 27 32 cb 93 2f 7a 21 62 3f 1a 03 96 b4 d1 cd 7b f3 4f fe 74 93 29 5b 39 73 c6 fe 11 26 f2 0f 98 b6 d7 15 4f 11 50 e3 85 c1 cf 37 bd be 18 1f 00 4c d8 92 55 6b d6 20 ee 94 a7 b0 40 00 00 00 71 0b 57 97 99 5d eb 4b 66 41 d0 24 71 f3 13 ee b4 a4 a7 10 0d 5b 27 72 d8 8f fe 80 a5 8b 4d 25 ae e6 85 f8 fc da fb ee 46 68 3b a0 0a 37 1a 73 0e cd 26 0a 07 b5 12 01 78 20 a9 bd b0 68 d4 (REG_BINARY)

"F1E2945585FB1D924A01AF0BBECA1AB77310173B1E"=01 00 00 00 d0 8c 9d df 01 15 d1 11 8c 7a 00 c0 4f c2 97 eb 01 00 00 00 fa a3 72 49 a9 04 8c 41 b0 23 5e 0b 9e 7a ce 75 00 00 00 00 02 00 00 00 00 00 10 66 00 00 00 01 00 00 20 00 00 00 3a 4e 7d 86 b7 7a 23 3a 8a 50 87 b4 79 e6 d9 ff bb 4c e8 54 5c 28 8c e5 18 b0 24 c3 d9 98 48 c9 00 00 00 00 0e 80 00 00 00 02 00 00 20 00 00 00 b8 fe c9 95 13 be e1 25 da b0 0b 9f 83 4b 9b 57 77 08 04 ad 5e a5 7d 1e 15 81 40 8e 7e 4f 8b b6 a0 00 00 00 d2 f9 0a e5 b0 ed f1 cc 28 fa a6 2e 25 3b cc 07 1a 02 b3 0f 25 ad 0f bb 30 7d a6 9a 67 1b c7 52 9e 8a a7 85 d0 dc 3a 4e 39 c9 fc f4 db 8e 6e 14 d3 63 ce 52 4f 26 9c 24 be ea 85 6f bb a2 bd 77 8f ef 46 f3 1f 12 fb 87 6b cc 77 ef fc 8a 37 5c 21 b0 2f dd 5d 08 a2 68 3f a0 6c 20 43 30 1f 49 97 0e b4 77 22 f1 17 8f db 04 9e 4e ab 70 38 dd 27 9d 2a 98 22 f2 9e 05 83 83 04 c6 fa 45 cf 4a f2 18 bf 15 73 b9 0d 7e d8 81 ae 34 75 4f 46 4d e6 c5 5f 4e 3c ea ce f4 32 b9 70 ae da f6 7e ea 40 00 00 00 58 36 19 3b d9 c0 70 12 98 af 4a 9a 1f 0a f6 d0 c9 b3 3c b6 ec 9f 73 65 67 13 16 28 aa 9a f6 (REG_BINARY)

"3A1A5DAC28DF0ACB8FFB59A5115A14F42A714E0E2B"=01 00 00 00 d0 8c 9d df 01 15 d1 11 8c 7a 00 c0 4f c2 97 eb 01 00 00 00 af 7e a6 54 98 6f a9 42 bc b9 44 ea 4d bc 04 d3 00 00 00 00 02 00 00 00 00 00 10 66 00 00 00 01 00 00 20 00 00 00 d8 5b 3c 5f 1d da 33 a9 c8 7e 84 a8 67 e0 89 71 86 5d d0 09 99 a9 19 5e 17 65 cd cf 27 ac 10 bc 00 00 00 00 0e 80 00 00 00 02 00 00 20 00 00 00 b9 81 5e 6b eb fe f2 8f 46 58 6c cd 16 a6 7b 58 e2 e6 79 be 45 19 83 c6 42 9b 02 99 69 bd 19 10 50 00 00 00 c5 28 71 b8 5b 78 d3 00 c8 73 fb c0 ed 76 24 21 70 e5 a5 9a ae d9 33 7b bd 34 1f a5 ba a8 0c 42 62 20 76 21 dd 23 31 0f 38 87 ab e7 dc 70 0f 5e 6b 01 69 40 89 b5 3f f6 39 d0 fd 25 23 6b b6 dc 5b 56 02 0c af fe 33 32 22 cd d9 46 0e 48 16 e8 40 00 00 00 3a f9 76 72 5a 14 63 60 79 36 32 9e 5d 10 25 44 fc 85 47 1b 5c 1e 24 4d d1 b8 68 cc 58 4b 4a 6b b4 07 3e fa 1c 1c 3d 9b 75 f3 5e 33 d5 91 b7 2b 10 5a a3 5c 2f 99 80 bf 66 cf 95 f9 0c 0a 59 89 (REG_BINARY)

"32259F446D4B75F2968EE3A1FD0C9653CFBA85BFC0"=01 00 00 00 d0 8c 9d df 01 15 d1 11 8c 7a 00 c0 4f c2 97 eb 01 00 00 00 af 7e a6 54 98 6f a9 42 bc b9 44 ea 4d bc 04 d3 00 00 00 00 02 00 00 00 00 00 10 66 00 00 00 01 00 00 20 00 00 00 e4 ba f7 e5 22 21 6d 04 e9 e7 2d d9 a8 aa 88 b6 39 35 02 bb e4 be 77 8e f7 20 09 02 26 9b cc b1 00 00 00 00 0e 80 00 00 00 02 00 00 20 00 00 00 6e df b0 49 40 0d 3c c8 c5 7a 45 eb 2b d6 72 b5 7c 6d 24 53 2e e7 5c 06 6d 4f 00 70 7b ce a2 ea 40 00 00 00 8e 57 5f 44 c0 9d 8f 08 2e ee fb 76 f7 9d 43 af 09 2c 6c 95 c4 5f 76 16 e8 93 d6 cc 24 dc 74 6d 08 ff 2c 51 04 d9 10 a3 aa 09 af b4 91 b9 f5 78 0b 8a 50 7a 0b 48 36 c1 66 5b f2 1e 4a 5b 8f 1d 40 00 00 00 9e 88 da 67 39 d2 f9 6f f3 b0 42 c7 7c 98 74 c9 b4 b6 b9 f1 de cb 0f 2a 0c 41 8a 51 e0 4a 29 29 1d 54 0e 1c 73 82 fa d8 20 be 05 38 3c 03 5a 8a 76 e2 c1 14 1d f0 90 c8 9b 0e 9a 76 6b a1 05 fa (REG_BINARY)

"9700E94438D3AEAA6D6955EDB5B6FC4EBDE8A11D57"=01 00 00 00 d0 8c 9d df 01 15 d1 11 8c 7a 00 c0 4f c2 97 eb 01 00 00 00 8a 69 ec 29 91 60 0d 43 a0 7d b6 52 26 80 0a 9b 00 00 00 00 02 00 00 00 00 00 10 66 00 00 00 01 00 00 20 00 00 00 00 6f 5a ed 4c 7c 4e 93 0b df 55 9a e2 65 b0 9a 70 51 51 8d 8f 7a 0b ff 96 14 41 18 bf 7b 4e 5e 00 00 00 00 0e 80 00 00 00 02 00 00 20 00 00 00 23 e5 20 f3 05 90 9b 04 f0 46 c4 21 fa 04 fe 93 76 c5 e9 b2 b4 3c 4f e2 ca a5 ee 3b 73 da 0d cd 50 00 00 00 cf 1e a6 4b f5 3b 3e bd f1 0b 24 3b 42 6f 75 f5 87 c2 98 b2 3d 68 16 38 72 df d9 40 94 99 9c 4d e5 56 4a a6 ff a4 72 3a 58 80 be d0 42 fd 29 bd af e8 6f 2f 57 ca 3f 65 40 46 ee ed 60 54 58 d1 80 66 a0 57 17 53 08 9f 25 36 bf 01 a7 34 05 da 40 00 00 00 60 4a 02 44 24 a6 b8 b0 98 10 5a fd 25 18 ec 03 78 0e 61 0b 12 fa 88 b0 7a 2d 66 54 0e 54 66 d2 39 98 65 00 61 73 df d1 d4 36 6c be 4d c4 16 d7 82 e7 63 96 58 f3 83 41 a3 4b a9 f6 bf 9a fc aa (REG_BINARY)

"D7883309B1B98AFBAD651E958876B1E5C1C454E29E"=01 00 00 00 d0 8c 9d df 01 15 d1 11 8c 7a 00 c0 4f c2 97 eb 01 00 00 00 8a 69 ec 29 91 60 0d 43 a0 7d b6 52 26 80 0a 9b 00 00 00 00 02 00 00 00 00 00 10 66 00 00 00 01 00 00 20 00 00 00 14 03 e4 af ae 21 b4 95 da a6 cd 1d ba 00 fc 34 6a d4 d9 88 88 ad fe 7a 16 68 ce 96 3d d1 f4 b0 00 00 00 00 0e 80 00 00 00 02 00 00 20 00 00 00 69 ef ed 60 58 72 30 ba 85 c4 85 64 ee 55 a4 7e b4 3e 3f 16 01 c5 bf 28 83 10 12 0e 86 c1 49 91 60 00 00 00 56 ec df 7e 31 90 9a 8e 78 fc 9d aa 28 bb 55 88 86 fd 74 5d 37 2e 37 11 e2 b9 39 f1 87 98 8b 60 84 39 4e 26 a2 93 8d bb 7f 4d 76 8c 06 f3 79 12 c4 0e fd 6c 3b fa 81 45 5d 52 d9 6a cc ef 8d 46 26 39 c7 0c c0 b9 34 17 9f d6 37 02 16 ca bd 7f 04 ae 7e 73 02 d9 a2 ed b8 95 e9 94 dc f1 f3 66 40 00 00 00 20 80 7e c4 9e ac 76 b7 bb 0a a9 94 4f 2e d8 36 1e 40 2d 52 82 4c 27 52 aa 44 6a 58 14 f7 29 55 bb 9e 3e a2 86 75 08 da 9c 56 07 b6 6e 3b 82 7a 3a d8 37 77 ca ab 60 95 8e 05 88 ba 36 a6 08 f3 (REG_BINARY)

"4DE4260E881842D72B0374C044DFA586D1BCD14B77"=01 00 00 00 d0 8c 9d df 01 15 d1 11 8c 7a 00 c0 4f c2 97 eb 01 00 00 00 8a 69 ec 29 91 60 0d 43 a0 7d b6 52 26 80 0a 9b 00 00 00 00 02 00 00 00 00 00 10 66 00 00 00 01 00 00 20 00 00 00 8d dd 29 f7 7a 5b 9a c9 f8 02 bb f6 a7 a4 2d f4 9b 12 9f 35 71 2d 86 e2 80 03 db db f7 d5 2e 92 00 00 00 00 0e 80 00 00 00 02 00 00 20 00 00 00 52 d6 34 41 23 2b 3e 80 26 68 46 db e2 0d db dd b2 a3 aa e9 bb f6 c4 23 ee 53 4e 9a d1 88 12 fd 50 00 00 00 ba 79 5c 6a ba 36 cd 94 a3 d8 7b 7d 7c 5b 3f 18 29 c1 6c fe 30 aa 4f 76 a9 fa 33 ac 9a 35 e4 33 06 2e cd 34 58 06 81 4d ac 5c da 09 c2 a9 11 31 a3 19 20 e0 36 8c 44 46 76 1d 3a f0 8a 1c 19 5d e1 84 ad 25 e1 fa 5f 3f b9 a9 0c af 6f f0 d1 5e 40 00 00 00 79 36 08 fc bc c3 2e 90 22 4d e7 de 18 08 f2 e9 13 a8 5b 86 30 c6 70 d8 4b ff 3f df e9 fd 19 8c 8a b9 bf 07 c7 0e b8 af 6f 7f ed 76 05 8e ed 36 05 72 67 a2 56 1b 8d 8f 2e ce 0b 44 0f 11 9e 9b (REG_BINARY)

"C91CD10AED922E47D5EA6AAFFD08F901D0651F6A49"=01 00 00 00 d0 8c 9d df 01 15 d1 11 8c 7a 00 c0 4f c2 97 eb 01 00 00 00 8a 69 ec 29 91 60 0d 43 a0 7d b6 52 26 80 0a 9b 00 00 00 00 02 00 00 00 00 00 10 66 00 00 00 01 00 00 20 00 00 00 c3 08 1a 0a 83 27 f8 0c 5e 6e d9 56 42 b3 cb 7c 1b e4 cf 8a 52 e1 f4 27 71 6b e6 77 c1 ce 18 0b 00 00 00 00 0e 80 00 00 00 02 00 00 20 00 00 00 ed 90 89 dc 0a 52 25 e5 a2 59 57 42 c5 57 f8 af f6 a9 d6 43 ab 83 4e 48 aa c8 99 90 e4 5c eb 4c 70 00 00 00 a0 71 1c 17 8a 3e a6 56 15 55 e9 ce c3 be 68 6d 7e 87 8f 8e 89 2b a4 d0 e4 6e 8f 64 44 cb b6 b9 30 8f a9 c3 af f6 73 38 43 d1 58 13 4d 75 d6 ca 29 8f 53 da 59 03 5d 83 6b b4 b4 c1 3e 29 ef 67 96 34 a3 2a c5 fb 78 53 6e cd 86 fc 82 16 70 a3 af f5 cd bd 50 af a7 42 bb 01 81 5d 71 84 ca 3b d3 1e 24 0c 7d 99 d7 d9 d7 39 c1 67 69 fb b7 7e 40 00 00 00 80 f8 50 53 f0 a6 50 d1 14 a5 d7 86 96 8e dc 13 fb ad d2 64 b0 e8 fa f4 00 f4 d4 dc cc 18 9a 93 50 85 c5 9c cc 24 a5 64 33 d5 28 1a a9 e3 a9 5d 00 63 a8 b6 26 bd 34 d5 a5 75 8d ee ca 6b 7c a5 (REG_BINARY)

"FFFA2924C66AF231499B3841AA2DC74100601BE434"=01 00 00 00 d0 8c 9d df 01 15 d1 11 8c 7a 00 c0 4f c2 97 eb 01 00 00 00 8a 69 ec 29 91 60 0d 43 a0 7d b6 52 26 80 0a 9b 00 00 00 00 02 00 00 00 00 00 10 66 00 00 00 01 00 00 20 00 00 00 5e ea 30 bb cf 6e f7 46 11 bd 0e 0b 58 78 f8 e8 92 55 2d 7b 06 9a 33 af 98 b7 ac 5e 94 51 20 35 00 00 00 00 0e 80 00 00 00 02 00 00 20 00 00 00 37 8c 98 95 a3 fb 5a 5c 22 2c 0e 89 3d 92 12 e4 b5 03 9c 0a 3f 28 41 e1 c4 75 ad 4b 4d 04 3b 0c 40 00 00 00 22 76 18 1e 40 6a 49 96 fb 1a fc 33 08 55 f6 df 55 39 af ae 17 93 d5 ff 50 3e 24 47 17 f8 4f 3b 32 a3 de d9 3c ec d0 66 74 8e f7 16 65 37 ae fb 2a 8d 85 3b 19 08 6b fd bd af 0f 1e 75 18 29 b6 40 00 00 00 30 90 f4 63 06 89 41 d5 b5 d1 f5 20 49 a3 6c c2 fc f4 aa cb 23 ad 45 09 fa b1 4b cb 63 58 d9 41 0b e8 1e 05 4e fa c0 02 fd 86 67 4b e4 d7 9f e3 30 1e 63 cb b4 74 7f 80 dc 91 f6 00 32 97 27 a9 (REG_BINARY)

"C9062DEE7E3AAD85824A03114AAB249397521F3DA5"=01 00 00 00 d0 8c 9d df 01 15 d1 11 8c 7a 00 c0 4f c2 97 eb 01 00 00 00 8a 69 ec 29 91 60 0d 43 a0 7d b6 52 26 80 0a 9b 00 00 00 00 02 00 00 00 00 00 10 66 00 00 00 01 00 00 20 00 00 00 ff ab ee d2 25 e1 51 bd f6 f4 e0 d7 c2 44 14 cf c4 19 c6 d8 ab af 46 8d 2b 6a b6 ae 10 6a 65 c4 00 00 00 00 0e 80 00 00 00 02 00 00 20 00 00 00 b9 8d 71 a1 c5 bf f7 b7 2f ba 48 86 0c 4a 71 5f 83 1e 18 f1 34 c1 03 71 64 70 95 71 b0 06 e4 4d 60 00 00 00 dd 85 b0 85 6a e8 7d d8 95 05 e9 7d 47 75 39 9e 92 5b b6 fc bf 4e 73 69 d6 c4 88 20 81 ae a0 20 97 34 b6 d8 4a cc 12 75 c2 a9 4a 48 49 ae 33 00 f3 50 97 9f 85 a0 2f 5b 07 80 1f ab b2 8f b2 39 40 bc 76 ba 56 ce d5 ae c3 b3 67 e6 46 f7 9e d2 2e e2 99 b0 15 41 3f 47 a2 af bf ad d2 1b f6 fa 40 00 00 00 7b 78 79 97 fd 98 a5 05 04 56 da 8f 1a 11 85 13 76 7f c6 0c 56 8b b9 77 56 c6 da b1 fc ab 2a 85 ba 80 02 d5 b5 41 af 42 74 3f 41 7a f4 9f e5 38 0c 78 d4 4e a9 8c b0 db 00 80 0f 2e 19 ea 21 a8 (REG_BINARY)

"E3215E5922E11C5E0CFEFF708CF1E85CCC929AF55F"=01 00 00 00 d0 8c 9d df 01 15 d1 11 8c 7a 00 c0 4f c2 97 eb 01 00 00 00 8a 69 ec 29 91 60 0d 43 a0 7d b6 52 26 80 0a 9b 00 00 00 00 02 00 00 00 00 00 10 66 00 00 00 01 00 00 20 00 00 00 00 ca 71 17 79 f2 2c ac 95 7f ca ce dd ee 9d 1f 44 49 32 f8 1d 5d 50 91 b3 fe f5 6a ca 9a 91 6d 00 00 00 00 0e 80 00 00 00 02 00 00 20 00 00 00 99 72 cc 05 8f 55 20 6f 94 61 d1 bc 14 1e 8d f5 06 8d 5a 21 8f 79 e2 96 50 2d 3b ac 9e 44 ee 7b 60 00 00 00 8f 70 92 67 6f dc dd f7 4f 10 9c 9b b6 d1 69 66 70 34 94 3a 00 89 80 e5 fa 16 38 3f 76 da 89 77 73 85 c2 5c 70 9c 80 ec 15 b2 29 10 55 89 c3 64 5e d9 70 1d b8 32 8c ca 11 92 68 b3 b5 2b 07 e6 bf ed 6c a3 35 20 74 34 45 04 26 0e 7b 04 cb 79 45 96 8a 0d 2b 64 2c a7 46 92 76 8f 6b c0 ca 3f 40 00 00 00 62 7c 96 54 4c 7f bc 9a 05 0b 51 5b ce 3f 74 1d 67 1b 46 4e 9b bb 41 26 b7 31 f9 34 74 27 c6 67 c6 c7 ac 7e bb 51 99 50 c2 0c 1a 11 6f 74 46 16 24 af 42 11 47 7b 7d 51 c5 0a 96 e9 c1 62 55 f2 (REG_BINARY)

"33802FC307D8BE3623706BFBC50FF360E14E9A93F4"=01 00 00 00 d0 8c 9d df 01 15 d1 11 8c 7a 00 c0 4f c2 97 eb 01 00 00 00 8a 69 ec 29 91 60 0d 43 a0 7d b6 52 26 80 0a 9b 00 00 00 00 02 00 00 00 00 00 10 66 00 00 00 01 00 00 20 00 00 00 3d eb e4 1e 32 9d 08 59 87 c6 61 c1 1d aa 33 f1 fb 06 8a a2 ad c8 20 55 d9 c9 7b 33 58 b9 59 d0 00 00 00 00 0e 80 00 00 00 02 00 00 20 00 00 00 a6 f4 42 1a e1 7a 28 95 d7 35 dd 6d 61 7c 66 48 f1 71 5f 5d 95 a1 13 46 bd 4a b5 09 e3 17 44 85 50 00 00 00 61 cb 1a 0c 0b 5a 94 5c 50 be 76 df a6 f3 2f 7f 64 32 f1 d6 e9 fa f0 9e ad ab 8b e8 cc 86 fe ce 38 85 e4 15 74 20 30 27 39 9d 0c fe aa cc 80 4a b5 94 a1 0f 16 ff a3 fd 85 96 a0 8b 1d 65 a0 8a 80 39 bc 82 92 8a 2c 17 a7 73 d5 f8 37 92 48 b6 40 00 00 00 ab bd 13 51 4a 24 03 64 0f 09 b7 6b c8 87 2f e2 66 86 a0 fa f0 e3 c7 ce 5c 23 42 21 77 53 8b 09 89 92 b6 0b a9 73 8a 67 f2 cc e3 6b d0 ee c7 fb b9 82 12 ea dd af 29 39 f5 f1 6b 60 d9 9d 19 cc (REG_BINARY)

"D43FA22B8ACC593CE9F35BFB24153E1252BA2D904F"=01 00 00 00 d0 8c 9d df 01 15 d1 11 8c 7a 00 c0 4f c2 97 eb 01 00 00 00 8a 69 ec 29 91 60 0d 43 a0 7d b6 52 26 80 0a 9b 00 00 00 00 02 00 00 00 00 00 10 66 00 00 00 01 00 00 20 00 00 00 78 60 a1 94 7b 27 f1 44 2a 94 46 70 0a 99 9d e4 4b 66 57 36 67 7b f5 4d 8c 5d 76 53 f5 16 0d 87 00 00 00 00 0e 80 00 00 00 02 00 00 20 00 00 00 83 68 05 4f 2b 8f 2c cd 7a 34 7e f1 02 7b 76 94 bd 60 4d 19 e2 8c ba 93 43 2d 24 00 dc c5 26 e9 50 00 00 00 09 4e e6 c6 73 a4 af 7d 15 eb 2e c7 2b dc 7d 55 6f 49 1e 65 f6 2f 62 dc 6b 01 4b 36 0d ad 20 0c 2f bd b4 c6 75 bc 06 88 9d e5 9a f7 bb 5a 31 af 67 c0 83 b8 a7 cb 92 e8 b5 49 27 3f a4 3d 2e a7 60 27 26 5b 3e e0 93 e4 f6 af 81 7e 06 c9 d0 bf 40 00 00 00 68 69 09 cf da ec 21 39 6f 9f 6c ca 06 ca 68 6b 63 3e 17 ef 3f b8 bb 65 ff f5 37 72 17 e8 19 f5 4e f8 ed b9 fe b6 46 a0 ff 4c 66 94 6c d9 27 07 92 07 27 c4 49 d3 74 d3 96 eb eb ff b1 da 14 40 (REG_BINARY)

"E1A9A82E434C82B6EAE2CE82465ED147531791504A"=01 00 00 00 d0 8c 9d df 01 15 d1 11 8c 7a 00 c0 4f c2 97 eb 01 00 00 00 8a 69 ec 29 91 60 0d 43 a0 7d b6 52 26 80 0a 9b 00 00 00 00 02 00 00 00 00 00 10 66 00 00 00 01 00 00 20 00 00 00 c9 26 79 dc b9 8d 1d d3 a0 6d 93 c9 41 db c6 69 ff a2 83 75 3a 40 33 54 e8 b8 0e 6e f2 fa 79 f7 00 00 00 00 0e 80 00 00 00 02 00 00 20 00 00 00 9e b7 41 7b ad 87 65 90 6b 46 ac 59 f1 37 e5 37 6e 1e 56 21 8e f4 e1 20 66 bc bf da fc 02 67 14 70 00 00 00 f1 46 75 06 c3 b9 79 cb 33 c6 7e 44 6e 7f e1 4c 13 74 0a 0c a8 05 96 5c 6e 49 29 5b 11 7c 48 23 61 55 1c 34 5e 93 2f 3d f1 f4 be b3 76 fd 05 92 d6 13 c1 ad 96 e4 57 b2 75 7a 7d 66 94 8e 96 af 14 7e a5 56 64 6c c1 96 64 10 9d 86 f0 9f ba 4f 0f be c3 f5 7c 35 b5 88 a5 a4 09 bd d1 56 04 43 2c 41 e0 19 f1 45 bd 66 c3 33 db 50 5f af e2 d6 40 00 00 00 c3 c9 41 98 61 75 9a 00 c4 04 64 97 64 5f ed cd 0c 16 e0 55 49 1d 7d 7b 2e 0e 39 c7 7b 7c d1 d6 6a 99 cd 10 b3 f0 5e 07 13 73 48 26 68 24 9a 2c 62 a9 c5 9a 8c 9b d9 e2 6e 2b 1b 34 cc da 66 7d (REG_BINARY)

"F6145C3E79E007DFBA4DFD252BD4D96C53A98EE3BD"=01 00 00 00 d0 8c 9d df 01 15 d1 11 8c 7a 00 c0 4f c2 97 eb 01 00 00 00 8a 69 ec 29 91 60 0d 43 a0 7d b6 52 26 80 0a 9b 00 00 00 00 02 00 00 00 00 00 10 66 00 00 00 01 00 00 20 00 00 00 b0 33 cc 66 75 f4 17 74 b7 1e 65 41 f9 79 7e 94 20 f9 38 fb 8e 67 56 c7 3c c2 f0 c8 ce 0d 5a 5c 00 00 00 00 0e 80 00 00 00 02 00 00 20 00 00 00 21 e1 b8 e0 71 f1 4c a0 0c 70 93 2a 36 4d c0 95 11 8e 12 68 7f b3 31 bb b1 05 c7 81 04 81 48 b8 60 00 00 00 a7 c5 81 d5 f6 a7 07 f6 ee 33 39 1f 7b 4c 30 20 43 33 54 fe 38 e7 69 f3 e0 c3 38 b4 be ee 80 c7 f9 fa d0 e3 4e 72 f8 57 58 54 f7 eb 1d 41 e8 68 66 74 9f 27 4f ec a0 0d ba db cd bf 24 78 42 c8 99 49 10 48 1b ca 56 f4 55 15 61 dd 5a 78 82 c2 f2 36 91 7a 7f fd 86 c9 ca ab 70 4c 9e e3 fe f8 40 00 00 00 c5 ae 89 e5 f2 c6 d4 0a b0 4b 26 3d 0d 16 a9 68 25 b2 6c 01 39 73 80 4a f5 16 48 f5 7d 6d c4 e2 8b af ab 83 05 97 d3 4d 1d 84 9d de 7d 08 e4 ef 4c 24 7d 9a 9f 85 71 2e fb da e4 ba 32 6a eb 6b (REG_BINARY)

"74CF5A55DE86BEC85988D7B5023A29D5DED8AF02EA"=01 00 00 00 d0 8c 9d df 01 15 d1 11 8c 7a 00 c0 4f c2 97 eb 01 00 00 00 8a 69 ec 29 91 60 0d 43 a0 7d b6 52 26 80 0a 9b 00 00 00 00 02 00 00 00 00 00 10 66 00 00 00 01 00 00 20 00 00 00 b4 51 b2 f8 20 cd 16 6c 10 e6 60 a5 a8 fb 82 b4 ce 15 84 14 c5 af 35 5c f6 d2 d5 6f f0 cc d3 9d 00 00 00 00 0e 80 00 00 00 02 00 00 20 00 00 00 03 ac c7 28 ba b9 b6 06 7d 3e 67 b7 59 da ce ab cd 86 9b d2 9f cf aa 8a f9 e5 6c 27 6b 84 3e f2 70 00 00 00 db 13 20 d2 ab b6 1b 64 c4 92 e5 a1 a9 20 5b b1 f1 7d e8 d2 d6 97 4d 1e 65 b2 13 12 85 d1 b7 79 93 64 bf e6 f1 e3 26 b8 7d 29 c0 6a ee ea ad 00 73 d2 8c e2 cb 5d 8d 36 4f 9e 18 d2 2a 2a f5 9c ea 2e b3 6b f9 3d 2f 16 ee 72 85 a0 79 15 39 16 b9 b7 c3 9d 1f dc 3b 3f 6e 47 eb 86 f0 5a f7 6e c1 00 18 d4 39 9c 4f 12 6a b8 a1 3f e8 dd 46 da 40 00 00 00 3e cf 30 9e ad 3f 7d ac 6a 35 88 bd e8 79 b6 3b d0 8b 06 9c d4 6a cf 81 14 b3 3c c0 59 cf 4d e0 db 0a 1b 5f f5 eb 51 b0 79 c5 84 c0 c6 e8 55 d8 5d 56 bf dc ff 4e 82 4a f4 9a e1 72 ec 7b ca 15 (REG_BINARY)

"4609967E23E6BA2CCA5C6B292E54CD8484EA0867BC"=01 00 00 00 d0 8c 9d df 01 15 d1 11 8c 7a 00 c0 4f c2 97 eb 01 00 00 00 f2 ea f7 4b 1c ee c3 40 9c 25 6d b7 04 75 e9 d4 00 00 00 00 02 00 00 00 00 00 10 66 00 00 00 01 00 00 20 00 00 00 58 a9 dc aa 12 e8 c1 eb aa 11 69 21 b0 52 ab 80 69 4e f5 8e 5c 20 72 d4 13 c5 1e 73 ce 8e 61 46 00 00 00 00 0e 80 00 00 00 02 00 00 20 00 00 00 91 95 03 2a fa 31 f1 cf ec bf 3e fc 81 8e 09 df e8 98 22 31 88 1d 08 4b 64 f1 a9 d9 64 42 9a f7 60 00 00 00 56 79 06 1c c8 36 02 c9 2f c5 58 53 b9 8d 19 37 bb 48 b0 70 3f 63 83 eb b4 35 8e bb 65 d9 ec 3b 53 d9 1b 24 97 49 55 d0 d7 f8 59 7c 98 43 a5 8a 17 e4 52 a7 99 1c d1 ba 3f 0d 72 01 e7 bb 5d 04 04 df be 08 c5 4d d5 f7 11 31 57 5d b8 f4 b1 46 22 54 4e cb 69 9b c8 6e d5 ae a6 03 7e fe dd a8 40 00 00 00 17 92 be bb 1b 52 39 c8 0d 1c f6 dc b0 00 d0 59 90 f2 1e 28 71 50 33 0b 55 0e ed f3 45 be 19 a1 6d f0 fb c1 6a 21 be 2d 4f 91 bb a8 fe af 92 59 ef 4c 3d e5 b8 3f a8 cc b5 c4 05 6e 7b 88 75 11 (REG_BINARY)

"0CE5F1B4C5BC1884C7FE398173D12A11DBA732E54A"=01 00 00 00 d0 8c 9d df 01 15 d1 11 8c 7a 00 c0 4f c2 97 eb 01 00 00 00 fa a3 72 49 a9 04 8c 41 b0 23 5e 0b 9e 7a ce 75 00 00 00 00 02 00 00 00 00 00 10 66 00 00 00 01 00 00 20 00 00 00 75 24 67 41 0d 05 de 2d 52 31 ef e9 a3 9e ee 1c 94 3b 76 91 1b ed e6 d2 57 73 0f 87 37 a0 a2 2b 00 00 00 00 0e 80 00 00 00 02 00 00 20 00 00 00 5d e5 38 8b 43 a5 ab 15 d0 65 3a dd 24 31 12 7c 34 bf 6f 0c cc e8 eb 3c b8 f5 b1 2d 5f c6 dc 43 e0 00 00 00 6d 6e a1 01 c2 1c 9d ef e1 65 bd 41 36 3e 8f cc 30 38 91 e0 35 a5 6b a2 1c 7d cc 20 9b 67 31 98 18 81 3f 04 53 00 c0 4c 94 f8 47 53 b1 73 04 73 dc 85 e2 1d 0d ed 25 95 26 b1 0b 77 f1 45 1f b5 a2 ad 1e 8a 12 35 d0 7b c4 53 35 fd 3a 0a 85 e7 13 52 a7 65 75 44 1c 47 00 0a a8 0b b4 90 8b b1 5d 7f 7e 83 67 fc b0 b4 01 88 78 b7 90 33 f1 30 c5 30 b0 d0 b2 68 c9 d8 0e d5 a8 98 54 55 a3 71 05 20 5a a2 0c 92 e5 81 0b 6e 06 c8 21 97 b9 51 6e 84 b4 d8 f2 fd 9e 31 fd a6 c1 03 9c 0d bd 77 33 8a e9 af 99 9b 65 95 36 01 96 ae 90 f5 a8 07 30 a7 15 c3 37 5d 92 ae 41 d4 99 4a 15 c3 51 1d 64 27 f1 (REG_BINARY)

"04E550A815712535D3C4C3F8FDAFC1E8A95B3E8D37"=01 00 00 00 d0 8c 9d df 01 15 d1 11 8c 7a 00 c0 4f c2 97 eb 01 00 00 00 8e d5 05 4b 23 8e 0e 48 9e 87 56 5a b7 3a ed 67 00 00 00 00 02 00 00 00 00 00 10 66 00 00 00 01 00 00 20 00 00 00 d4 d0 c9 00 b3 4d bf 42 ea c9 f6 ff bd b4 5c a6 e8 c6 e6 97 68 a9 09 62 9a 0d 53 82 90 f4 2d ad 00 00 00 00 0e 80 00 00 00 02 00 00 20 00 00 00 89 dc b1 94 49 aa 1b cf 12 71 f7 8f 86 00 cd fb d7 0f 3c 98 2b 9e fc 80 01 ef 9a af 90 d1 dc d0 60 00 00 00 4f e8 25 06 e3 cd 6a ce 24 6c 4d 20 75 61 fe 29 61 1b f6 3e 89 bc 6b a0 6a d8 17 0b 93 bb b1 13 09 e2 1a 2b d0 e3 7f d8 aa d2 99 ae dc 4c 9b fd 62 9c dd b2 78 7e 51 4d c1 d7 e8 88 9a 1f 5e 48 f0 c2 a9 74 29 60 9e 29 5a 39 8e bc 1c 33 31 d6 7b 23 1f f7 ea 9f 75 b2 18 bf c0 ab dd 6f e0 f1 40 00 00 00 97 4d 1a e0 ac db 26 40 f6 5d 94 39 a9 70 3b 05 86 54 fa 1c f6 ac 89 1a 24 65 73 bb 72 ed 61 c7 53 16 f8 0c 75 4f 6e ab 4c 62 58 9b 56 ca c6 10 81 7a cd 1d c5 ac 7c e1 de c6 cd f8 11 cb e9 f5 (REG_BINARY)

"C625BBF0A44848A848212DEBB4F79650F0F01E6EF0"=01 00 00 00 d0 8c 9d df 01 15 d1 11 8c 7a 00 c0 4f c2 97 eb 01 00 00 00 f2 ea f7 4b 1c ee c3 40 9c 25 6d b7 04 75 e9 d4 00 00 00 00 02 00 00 00 00 00 10 66 00 00 00 01 00 00 20 00 00 00 ee 28 c3 7a 9c d2 d9 e8 dc 0f 77 1b 90 c5 1d 7e c5 a3 21 6b e1 46 be ab 1c e4 9d ef 67 c0 89 60 00 00 00 00 0e 80 00 00 00 02 00 00 20 00 00 00 90 ae a3 99 c6 28 bb 18 b7 2f 2d 9c f5 97 aa d9 9d 85 99 78 db 61 8b b0 a9 19 15 08 83 ee 9e 31 40 00 00 00 bc bb 80 41 7c 1a 71 10 96 c0 19 af 55 52 cb a4 58 9f be 0b 6c b7 02 ad 7f c7 2c a2 d4 e5 dc 4b 69 fe 9d f0 3f 53 45 2d 8c 6d 4e b7 3e 1a 3b 97 2e 3d 06 50 3f 57 8d bb 63 58 29 f1 3c bf a4 98 40 00 00 00 ef ed b5 a2 f3 2d 91 09 12 d0 29 b7 87 22 80 67 62 5f 25 f3 98 cd 67 33 e8 4d a3 2b ac fd 20 28 32 60 a3 57 0a e1 ff 91 1b 8f 7d a6 53 fa e7 b4 a3 7c 7a 8b 5a 69 e7 1f ec 3e ff 35 53 f3 3d 97 (REG_BINARY)

"B8CB6B3DE866F2FD1F17996FEE01CEC4748A03E810"=01 00 00 00 d0 8c 9d df 01 15 d1 11 8c 7a 00 c0 4f c2 97 eb 01 00 00 00 f2 ea f7 4b 1c ee c3 40 9c 25 6d b7 04 75 e9 d4 00 00 00 00 02 00 00 00 00 00 10 66 00 00 00 01 00 00 20 00 00 00 2e 5d f1 3c 8a db 92 24 9e f9 28 db 89 77 1d 47 d1 20 37 48 af 41 7d e7 ca e0 2c 2e 8b ac 93 0e 00 00 00 00 0e 80 00 00 00 02 00 00 20 00 00 00 5e 80 0b b9 98 75 53 5c 56 05 ad bb 48 fb 6b a1 ab bd 37 75 ef 8a 14 ea 4a dd 71 8c f2 05 87 b0 50 00 00 00 97 69 6a 40 b0 7c d0 7e 88 33 07 7a d9 34 cc cd 5f 8e 30 61 ad f5 72 b3 af bb ec bd fd 74 76 0d 7b 6d 8d e7 a8 ff f4 09 56 c0 69 52 fb e3 12 07 1d d4 a5 4c 3d 46 3e f2 9e 3b 06 cb fc e3 df ef dc d1 31 36 82 9e 62 e4 62 37 13 ff 75 9d 2b 02 40 00 00 00 21 c8 eb f2 a0 93 a8 a6 de 55 c9 63 ed 0f 87 f0 3e 77 ef 42 a3 35 5a 2d d0 97 87 1f 1b a2 d3 8e 3c 55 77 00 17 09 37 c5 c0 e5 a2 d7 88 3a 06 8d 85 b4 0e d5 ab 29 3c 8a af bc ca 2a d9 df f9 55 (REG_BINARY)

"A6EB104D7914E611C8994C43DD7044A32569CD0EFF"=01 00 00 00 d0 8c 9d df 01 15 d1 11 8c 7a 00 c0 4f c2 97 eb 01 00 00 00 f2 ea f7 4b 1c ee c3 40 9c 25 6d b7 04 75 e9 d4 00 00 00 00 02 00 00 00 00 00 10 66 00 00 00 01 00 00 20 00 00 00 3c 4a ed 13 33 41 f1 85 2f 2f ea 2e ec 34 77 d4 19 81 5a bc 2c 0f e1 fb 45 16 a8 d5 26 07 50 18 00 00 00 00 0e 80 00 00 00 02 00 00 20 00 00 00 ff 25 5a 5a bf 12 d5 2c ab 7b cd f1 7b 91 d4 7f e7 6e 09 81 b6 4c 1c 69 3c e5 5b 6a f6 d3 16 e2 50 00 00 00 bf 9e d8 02 49 8d 7d 34 f7 59 55 e2 8a da 8a 9c 16 e1 51 07 d8 8f ac 19 b2 71 db 07 d6 f2 1f c3 28 e0 76 41 75 7e a2 5b b5 fc 85 c6 c7 87 a0 b1 98 fb 95 c0 d8 62 dd b2 d6 11 37 0f 7d 7c c7 28 c0 40 1f 84 d9 75 ad d4 55 ce 39 26 06 bf 19 56 40 00 00 00 a6 3c bc 81 7e eb f0 65 54 4c e1 f1 7c 73 ec 59 dd 9c e9 8d 6b d6 9f 22 34 c7 04 9a b5 c5 b9 ce 57 55 76 4f 7e 95 38 35 66 38 cc a1 ac b5 d6 27 df fa 76 43 f4 22 5f 35 7b 80 f5 d1 c8 34 ef 06 (REG_BINARY)

"9B0711DD64BFAFDB50CE97C460B59EBF89920695DE"=01 00 00 00 d0 8c 9d df 01 15 d1 11 8c 7a 00 c0 4f c2 97 eb 01 00 00 00 f2 ea f7 4b 1c ee c3 40 9c 25 6d b7 04 75 e9 d4 00 00 00 00 02 00 00 00 00 00 10 66 00 00 00 01 00 00 20 00 00 00 21 d8 7b e5 86 27 cc ec 8f cd ee 9c b6 7a 6a 54 9c 45 bc be 21 d7 98 94 4a 77 de 01 ed 4d 50 05 00 00 00 00 0e 80 00 00 00 02 00 00 20 00 00 00 04 a6 a3 9c 14 f1 4e b5 42 2b b2 a8 83 41 3a 6a 24 3e 62 9d 0f e7 2c e5 ab 84 88 dc e1 85 f6 80 50 00 00 00 97 81 1a 71 f9 6d 18 23 15 4f 00 c7 00 60 63 3d b7 19 65 19 66 3f 5a 70 dc 81 69 7d 2c 31 52 01 39 38 b9 a3 db a2 1a bd 06 6a 3c ac 4b b8 a0 af 03 f3 c8 27 ac 41 8c 68 41 d8 6e 37 cf 77 fd c9 56 6b bd f5 38 22 cc 0d a8 42 22 62 ba 3d 9c 1b 40 00 00 00 0c 12 d4 7f 37 8a be 8f b5 b1 d3 25 c2 2d eb b6 10 0e 32 47 eb 80 d7 3f e8 75 14 20 dd 6e 63 05 08 3d 01 e9 ef af d3 7e 28 57 5e 75 30 ec ef d8 3a ac b3 4a 5b 3d 7d 5a b4 ac f1 78 4e f5 9c 02 (REG_BINARY)

"9220068F01E11F7898C5DB3230434E7A7B99260DAC"=01 00 00 00 d0 8c 9d df 01 15 d1 11 8c 7a 00 c0 4f c2 97 eb 01 00 00 00 f2 ea f7 4b 1c ee c3 40 9c 25 6d b7 04 75 e9 d4 00 00 00 00 02 00 00 00 00 00 10 66 00 00 00 01 00 00 20 00 00 00 3c 9e 64 9e a1 d8 ed 45 53 c4 70 15 b4 a3 01 d4 65 a1 ee 8d 9d 96 85 63 d0 2c 0f 9d d2 94 41 a9 00 00 00 00 0e 80 00 00 00 02 00 00 20 00 00 00 c9 dd 3b bc d0 14 0d af ff a0 0f 57 90 c4 8f 43 a6 1a 04 11 30 89 cb 27 2c 3f 69 b3 92 81 81 e3 60 00 00 00 15 2a 48 0a 01 24 54 42 a4 12 7c 59 a2 96 43 f1 61 c1 f5 3f fd 23 73 bd 7a 57 51 7b 51 4d dc 74 88 f2 4d d3 f1 a0 56 9d 49 8a 29 a4 3b 92 d1 3e 97 81 5a 9b a1 93 18 70 aa a7 6c 4a ab fb 09 63 6c 2f 2c 07 4c e6 66 4f fc 92 75 47 bc d2 13 cc 0c eb df 8c d3 56 bb e6 40 0d 68 3c 90 8d cc b3 40 00 00 00 19 d6 23 4e 6c 31 ff c9 f8 5f a8 60 0d 65 e9 37 e8 56 e3 b3 43 34 43 e9 0f 7f 5c 48 ac f0 72 2c 0b fc 6e 05 46 42 ee a9 10 cd e1 55 dc c1 4c 20 73 70 cc 06 47 c7 b2 81 99 12 c4 c3 f2 1f c5 b7 (REG_BINARY)

"1D850C0E1C604DE03CB4CC154F67A2CFCE11681BBF"=01 00 00 00 d0 8c 9d df 01 15 d1 11 8c 7a 00 c0 4f c2 97 eb 01 00 00 00 f2 ea f7 4b 1c ee c3 40 9c 25 6d b7 04 75 e9 d4 00 00 00 00 02 00 00 00 00 00 10 66 00 00 00 01 00 00 20 00 00 00 5f d9 89 9f a4 a9 f7 b8 fa 9c 56 99 be b0 50 12 7d 13 87 0d 58 bf e1 2f 8d b0 c5 bc 18 9c 31 ce 00 00 00 00 0e 80 00 00 00 02 00 00 20 00 00 00 df b8 00 76 90 76 5a cc a6 20 66 b3 cd 7d 5b 68 0b 0e 19 2b ee e6 90 b3 95 1a 0b 35 f5 b4 12 b3 60 00 00 00 31 5e 78 84 77 28 0c ee b6 fc 70 00 55 c6 e3 62 eb 1c 3c 8a 13 b2 58 4d cd 55 0a 90 42 ee 9a cf 52 2c 98 a5 ee 59 29 9c 8d 1e fa b5 75 84 8f 5c 1e ed 9e 2a 6a 07 7b 94 7f 6b 25 86 20 36 2e b5 49 ed 3e c1 dd a9 1d 09 60 d6 82 cd 92 ec 8f a8 2f 6d e6 85 33 5b f1 29 3f 8b d7 f7 a4 19 1d 0d 40 00 00 00 0b 33 ed e8 23 95 ec f3 61 0c ac 71 96 f2 a7 8d 28 99 df 9b 33 1d a7 78 56 64 7c 6f a6 4f b2 5b 94 8d c3 50 fd 7c 45 17 5a 68 64 70 93 07 ba 54 0f 03 81 41 81 51 ba 05 9c 3e d3 10 9d 9b 72 37 (REG_BINARY)

"95EC8654092CE24121C49BFC33AC064C32236A1837"=01 00 00 00 d0 8c 9d df 01 15 d1 11 8c 7a 00 c0 4f c2 97 eb 01 00 00 00 8e d5 05 4b 23 8e 0e 48 9e 87 56 5a b7 3a ed 67 00 00 00 00 02 00 00 00 00 00 10 66 00 00 00 01 00 00 20 00 00 00 13 f5 f5 36 97 09 8f 7e a0 d5 f0 54 34 ea 23 e5 0b 07 dd 92 c7 b9 07 f0 95 81 db 39 41 15 28 e8 00 00 00 00 0e 80 00 00 00 02 00 00 20 00 00 00 35 58 70 99 f6 88 f1 37 f3 97 70 1e 53 3a bf bc 76 d7 09 bd d9 8d 37 ad f7 86 a7 b7 9e 60 af 8c c0 00 00 00 a1 b5 d8 87 94 44 11 fc 20 7d 94 a4 d0 61 8f 9b b4 4f 85 9f 3b 0c 84 9c 9b b4 3f e5 81 b9 35 2a 70 92 e2 cc 4a 0c 25 23 fe d1 84 e7 48 8f cd 90 c6 0e 85 08 e7 6a 07 47 4d 48 cc b5 72 83 9e cd e6 c8 8f 8d b5 fe f6 63 af 83 b1 b7 b1 d7 d4 49 94 9d b3 9b 16 0f 74 7b 1c 2c 80 bb 7a 7d 66 08 63 c8 20 f7 7f 43 0e 0f 47 b8 9e 5f 6a b7 9f 29 19 f5 2f 71 26 2c 45 10 9e 45 a4 86 d4 de e4 a4 ff 96 92 2c 17 35 48 cf 34 9c d8 90 97 a0 c5 3e fd 86 28 f5 70 67 13 61 7e c1 32 5b f4 90 35 c8 2e f6 36 e6 d3 2d f5 35 b5 d9 92 a7 da 62 b4 bb 2c 71 11 43 0b 11 90 96 36 ab 72 c3 bd 8b 5e c1 40 00 00 (REG_BINARY)

Posted

OTL logfile created on: 2/5/2013 12:01:27 PM - Run 3

OTL by OldTimer - Version 3.2.69.0 Folder = C:\Users\Deb\Desktop

64bit- Home Premium Edition Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation

Internet Explorer (Version = 8.0.7601.17514)

Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

 

3.97 Gb Total Physical Memory | 2.09 Gb Available Physical Memory | 52.60% Memory free

7.93 Gb Paging File | 5.85 Gb Available in Paging File | 73.71% Paging File free

Paging file location(s): ?:\pagefile.sys [binary data]

 

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)

Drive C: | 116.44 Gb Total Space | 26.65 Gb Free Space | 22.88% Space Free | Partition Type: NTFS

Drive D: | 337.60 Gb Total Space | 87.33 Gb Free Space | 25.87% Space Free | Partition Type: NTFS

 

Computer Name: DEB-PC | User Name: Deb | Logged in as Administrator.

Boot Mode: Normal | Scan Mode: Current user | Quick Scan | Include 64bit Scans

Company Name Whitelist: On | Skip Microsoft Files: On | No Company Name Whitelist: On | File Age = 30 Days

 

========== Processes (SafeList) ==========

 

PRC - C:\Users\Deb\Desktop\OTL.exe (OldTimer Tools)

PRC - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe (Adobe Systems Incorporated)

PRC - C:\Program Files (x86)\Real\RealPlayer\Update\realsched.exe (RealNetworks, Inc.)

PRC - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbarUser_32.exe (Google Inc.)

PRC - C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe (Avira Operations GmbH & Co. KG)

PRC - C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe (Avira Operations GmbH & Co. KG)

PRC - C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe (Avira Operations GmbH & Co. KG)

PRC - C:\Program Files (x86)\RealNetworks\RealDownloader\rndlresolversvc.exe ()

PRC - C:\Users\Deb\AppData\Local\Akamai\netsession_win.exe (Akamai Technologies, Inc.)

PRC - C:\Program Files (x86)\lg_fwupdate\fwupdate.exe (BitLeader)

PRC - C:\Program Files (x86)\Kodak\AiO\Center\EKAiOHostService.exe (Eastman Kodak Company)

PRC - C:\Program Files (x86)\Common Files\ArcSoft\esinter\Bin\eservutil.exe (ArcSoft Inc.)

PRC - C:\Program Files (x86)\Pando Networks\Pando\Pando.exe (Pando Networks)

PRC - C:\Program Files (x86)\AWS\WeatherBug\Weather.exe (AWS Convergence Technologies, Inc.)

PRC - C:\Windows\AsScrPro.exe (ASUS)

PRC - C:\Program Files (x86)\ASUS\Wireless Console 3\wcourier.exe ()

PRC - C:\Windows\SysWOW64\Fast Boot\FastBootAgent.exe (ASUSTeK Computer Inc.)

PRC - C:\Program Files (x86)\ASUS\ControlDeck\ControlDeckStartUp.exe ()

PRC - C:\Program Files (x86)\ASUS\ATK Hotkey\HControl.exe (ASUS)

PRC - C:\Program Files (x86)\ASUS\ATKOSD2\ATKOSD2.exe (ASUS)

PRC - C:\Program Files (x86)\ASUS\ASUS Data Security Manager\ADSMTray.exe (ASUSTek Computer Inc.)

PRC - C:\Program Files (x86)\ASUS\ATK Hotkey\HControlUser.exe (ASUS)

PRC - C:\Program Files (x86)\ASUS\ATK Hotkey\ATKOSD.exe (ASUS)

PRC - C:\Program Files (x86)\ASUS\ATK Hotkey\AsLdrSrv.exe (ASUS)

PRC - C:\Program Files (x86)\ASUS\SmartLogon\sensorsrv.exe (ASUS)

PRC - C:\Program Files (x86)\ASUS\ATK Media\DMedia.exe (ASUS)

PRC - C:\Program Files (x86)\ASUS\ATK Hotkey\WDC.exe (ASUS)

PRC - C:\Program Files (x86)\Yahoo!\SoftwareUpdate\YahooAUService.exe (Yahoo! Inc.)

PRC - C:\Program Files (x86)\ASUS\ATK Hotkey\KBFiltr.exe (ASUS)

PRC - C:\Program Files (x86)\ASUS\ATK Hotkey\Atouch64.exe ()

PRC - C:\Program Files (x86)\ASUS\ASUS Data Security Manager\ADSMSrv.exe (ASUSTek Computer Inc.)

PRC - C:\Program Files (x86)\ASUS\ASUS Live Update\ALU.exe ()

PRC - C:\Program Files (x86)\Webroot\Washer\WasherSvc.exe (Webroot Software, Inc.)

PRC - C:\Program Files (x86)\Webroot\Washer\wwDisp.exe (Webroot Software, Inc.)

PRC - C:\Program Files\ATKGFNEX\GFNEXSrv.exe ()

PRC - C:\Sierra\Planner\PLNRnote.exe (Sierra Online)

 

 

========== Modules (No Company Name) ==========

 

MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\PresentationFramewo#\d7d20811a7ce7cc589153648cbb1ce5c\PresentationFramework.Aero.ni.dll ()

MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\PresentationFramewo#\ff7c9a4f41f7cccc47e696c11b9f8469\PresentationFramework.ni.dll ()

MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\PresentationCore\19b3d17c3ce0e264c4fb62028161adf7\PresentationCore.ni.dll ()

MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\WindowsBase\cf827fe7bc99d9bcf0ba3621054ef527\WindowsBase.ni.dll ()

MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\System\369f8bdca364e2b4936d18dea582912c\System.ni.dll ()

MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\mscorlib\7150b9136fad5b79e88f6c7f9d3d2c39\mscorlib.ni.dll ()

MOD - C:\Program Files (x86)\ASUS\Wireless Console 3\wcourier.exe ()

MOD - C:\Program Files (x86)\ASUS\ControlDeck\ControlDeckStartUp.exe ()

MOD - C:\Program Files (x86)\ASUS\VirtualCamera\virtualCamera.ax ()

MOD - C:\Program Files (x86)\ASUS\ASUS Live Update\ALU.exe ()

MOD - C:\Program Files (x86)\Webroot\Washer\Languages\English.dll ()

MOD - C:\Program Files (x86)\ASUS\ASUS Data Security Manager\ShlExt\x86\OverlayIconShlExt.dll ()

MOD - C:\Program Files (x86)\ASUS\ASUS Data Security Manager\ShlExt\x86\OverlayIconShlExt1.dll ()

 

 

========== Services (SafeList) ==========

 

SRV:64bit: - (wlcrasvc) -- C:\Program Files\Windows Live\Mesh\wlcrasvc.exe (Microsoft Corporation)

SRV:64bit: - (WinDefend) -- C:\Program Files\Windows Defender\MpSvc.dll (Microsoft Corporation)

SRV:64bit: - (ATKGFNEXSrv) -- C:\Program Files\ATKGFNEX\GFNEXSrv.exe ()

SRV - (AdobeFlashPlayerUpdateSvc) -- C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe (Adobe Systems Incorporated)

SRV - (AdobeARMservice) -- C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe (Adobe Systems Incorporated)

SRV - (FBDiskOptimizer) -- C:\Program Files (x86)\FixBee\FBDefragSrv64.exe (FixBee., (www.fixbee.com))

SRV - (AntiVirSchedulerService) -- C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe (Avira Operations GmbH & Co. KG)

SRV - (AntiVirService) -- C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe (Avira Operations GmbH & Co. KG)

SRV - (RealNetworks Downloader Resolver Service) -- C:\Program Files (x86)\RealNetworks\RealDownloader\rndlresolversvc.exe ()

SRV - (Akamai) -- c:\program files (x86)\common files\akamai/netsession_win_ce5ba24.dll ()

SRV - (Kodak AiO Network Discovery Service) -- C:\Program Files (x86)\Kodak\AiO\Center\EKAiOHostService.exe (Eastman Kodak Company)

SRV - (ADExchange) -- C:\Program Files (x86)\Common Files\ArcSoft\esinter\Bin\eservutil.exe (ArcSoft Inc.)

SRV - (FLEXnet Licensing Service) -- C:\Program Files (x86)\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe (Macrovision Europe Ltd.)

SRV - (clr_optimization_v4.0.30319_32) -- C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe (Microsoft Corporation)

SRV - (SwitchBoard) -- C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe (Adobe Systems Incorporated)

SRV - (FastBootAgent) -- C:\Windows\SysWOW64\Fast Boot\FastBootAgent.exe (ASUSTeK Computer Inc.)

SRV - (ASLDRService) -- C:\Program Files (x86)\ASUS\ATK Hotkey\AsLdrSrv.exe (ASUS)

SRV - (clr_optimization_v2.0.50727_32) -- C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe (Microsoft Corporation)

SRV - (YahooAUService) -- C:\Program Files (x86)\Yahoo!\SoftwareUpdate\YahooAUService.exe (Yahoo! Inc.)

SRV - (ADSMService) -- C:\Program Files (x86)\ASUS\ASUS Data Security Manager\ADSMSrv.exe (ASUSTek Computer Inc.)

SRV - (wwEngineSvc) -- C:\Program Files (x86)\Webroot\Washer\WasherSvc.exe (Webroot Software, Inc.)

SRV - (Crypkey License) -- C:\Windows\SysWow64\Crypserv.exe (Kenonic Controls Ltd.)

 

 

========== Driver Services (SafeList) ==========

 

DRV:64bit: - (avipbb) -- C:\Windows\SysNative\drivers\avipbb.sys (Avira Operations GmbH & Co. KG)

DRV:64bit: - (avgntflt) -- C:\Windows\SysNative\drivers\avgntflt.sys (Avira Operations GmbH & Co. KG)

DRV:64bit: - (avkmgr) -- C:\Windows\SysNative\drivers\avkmgr.sys (Avira Operations GmbH & Co. KG)

DRV:64bit: - (PCWinSoft) -- C:\Windows\SysNative\drivers\scrcamnetdriver_x64.sys (Windows ® Server 2003 DDK provider)

DRV:64bit: - (fssfltr) -- C:\Windows\SysNative\drivers\fssfltr.sys (Microsoft Corporation)

DRV:64bit: - (Fs_Rec) -- C:\Windows\SysNative\drivers\fs_rec.sys (Microsoft Corporation)

DRV:64bit: - (DigiartyVirtualCDBus) -- C:\Windows\SysNative\drivers\DigiartyVirtualCDBus.sys (Digiarty Software, Inc.)

DRV:64bit: - (athr) -- C:\Windows\SysNative\drivers\athrx.sys (Atheros Communications, Inc.)

DRV:64bit: - (AnyDVD) -- C:\Windows\SysNative\drivers\AnyDVD.sys (SlySoft, Inc.)

DRV:64bit: - (amdsata) -- C:\Windows\SysNative\drivers\amdsata.sys (Advanced Micro Devices)

DRV:64bit: - (amdxata) -- C:\Windows\SysNative\drivers\amdxata.sys (Advanced Micro Devices)

DRV:64bit: - (igfx) -- C:\Windows\SysNative\drivers\igdkmd64.sys (Intel Corporation)

DRV:64bit: - (FARMNTIO) -- C:\Windows\SysNative\drivers\FarMntIo.sys ()

DRV:64bit: - (ElbyCDIO) -- C:\Windows\SysNative\drivers\ElbyCDIO.sys (Elaborate Bytes AG)

DRV:64bit: - (HpSAMD) -- C:\Windows\SysNative\drivers\HpSAMD.sys (Hewlett-Packard Company)

DRV:64bit: - (TsUsbFlt) -- C:\Windows\SysNative\drivers\TsUsbFlt.sys (Microsoft Corporation)

DRV:64bit: - (AsDsm) -- C:\Windows\SysNative\drivers\AsDsm.sys (ASUSTek Computer Inc)

DRV:64bit: - (L1E) -- C:\Windows\SysNative\drivers\L1E62x64.sys (Atheros Communications, Inc.)

DRV:64bit: - (kbfiltr) -- C:\Windows\SysNative\drivers\kbfiltr.sys ( )

DRV:64bit: - (amdsbs) -- C:\Windows\SysNative\drivers\amdsbs.sys (AMD Technologies Inc.)

DRV:64bit: - (LSI_SAS2) -- C:\Windows\SysNative\drivers\lsi_sas2.sys (LSI Corporation)

DRV:64bit: - (stexstor) -- C:\Windows\SysNative\drivers\stexstor.sys (Promise Technology)

DRV:64bit: - (StillCam) -- C:\Windows\SysNative\drivers\serscan.sys (Microsoft Corporation)

DRV:64bit: - (VIAHdAudAddService) -- C:\Windows\SysNative\drivers\viahduaa.sys (VIA Technologies, Inc.)

DRV:64bit: - (ETD) -- C:\Windows\SysNative\drivers\ETD.sys (ELAN Microelectronic Corp.)

DRV:64bit: - (lullaby) -- C:\Windows\SysNative\drivers\lullaby.sys (Windows ® Win 7 DDK provider)

DRV:64bit: - (SiSGbeLH) -- C:\Windows\SysNative\drivers\SiSG664.sys (Silicon Integrated Systems Corp.)

DRV:64bit: - (ebdrv) -- C:\Windows\SysNative\drivers\evbda.sys (Broadcom Corporation)

DRV:64bit: - (b06bdrv) -- C:\Windows\SysNative\drivers\bxvbda.sys (Broadcom Corporation)

DRV:64bit: - (b57nd60a) -- C:\Windows\SysNative\drivers\b57nd60a.sys (Broadcom Corporation)

DRV:64bit: - (hcw85cir) -- C:\Windows\SysNative\drivers\hcw85cir.sys (Hauppauge Computer Works, Inc.)

DRV:64bit: - (iaStor) -- C:\Windows\SysNative\drivers\iaStor.sys (Intel Corporation)

DRV:64bit: - (AmUStor) -- C:\Windows\SysNative\drivers\AmUStor.sys (Alcor Micro, Corp.)

DRV:64bit: - (SNP2UVC) -- C:\Windows\SysNative\drivers\snp2uvc.sys ()

DRV:64bit: - (MTsensor) -- C:\Windows\SysNative\drivers\ATK64AMD.sys (ASUS)

DRV:64bit: - (WimFltr) -- C:\Windows\SysNative\drivers\WimFltr.sys (Microsoft Corporation)

DRV:64bit: - (ASMMAP64) -- C:\Program Files\ATKGFNEX\ASMMAP64.sys ()

DRV:64bit: - (SCDEmu) -- C:\Windows\SysNative\drivers\scdemu.sys (PowerISO Computing, Inc.)

DRV - (AnyDVD) -- C:\Windows\SysWOW64\drivers\AnyDVD.sys (SlySoft, Inc.)

DRV - (WIMMount) -- C:\Windows\SysWOW64\drivers\wimmount.sys (Microsoft Corporation)

DRV - (NetworkX) -- C:\Windows\SysWOW64\Ckldrv.sys ()

 

 

========== Standard Registry (SafeList) ==========

 

 

========== Internet Explorer ==========

 

IE:64bit: - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page =

IE:64bit: - HKLM\..\SearchScopes,DefaultScope = {6A1806CD-94D4-4689-BA73-E35EA1EA9990}

IE:64bit: - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}&FORM=IE8SRC

IE:64bit: - HKLM\..\SearchScopes\{6A1806CD-94D4-4689-BA73-E35EA1EA9990}: "URL" = http://www.google.com/search?q={searchTerms}&rls=com.microsoft:{language}:{referrer:source?}&ie={inputEncoding}&oe={outputEncoding}&sourceid=ie7

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = about:blank

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = about:blank

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Search Bar = http://www.google.com

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Default_Page_URL =

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = about:blank

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,Default_Search_URL = http://www.google.com/

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,Search Bar =

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,Search Page =

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,Start Default_Page_URL =

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,Start Page =

IE - HKLM\..\SearchScopes,Backup.Old.DefaultScope = {6A1806CD-94D4-4689-BA73-E35EA1EA9990}

IE - HKLM\..\SearchScopes,DefaultScope =

IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}&FORM=IE8SRC

IE - HKLM\..\SearchScopes\{afdbddaa-5d3f-42ee-b79c-185a7020515b}: "URL" = http://www.google.com/search?q={searchTerms}&rls=com.microsoft:{language}:{referrer:source?}&ie={inputEncoding}&oe={outputEncoding}&sourceid=ie7

IE - HKLM\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

 

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Backup.Old.Start Page = http://www.google.com/ig

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL = http://www.google.com

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = about:blank

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Bar = http://www.google.com

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Default_Page_URL =

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page =

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = http://www.msn.com/

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = en-us

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = D6 0A A2 81 91 98 CB 01 [binary data]

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Restore =

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Search,Default_Search_URL = http://www.google.com/

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Search,Search Bar =

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Search,Search Page =

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Search,Start Default_Page_URL =

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Search,Start Page =

IE - HKCU\..\SearchScopes,Backup.Old.DefaultScope = {6A1806CD-94D4-4689-BA73-E35EA1EA9990}

IE - HKCU\..\SearchScopes,DefaultScope = {6A1806CD-94D4-4689-BA73-E35EA1EA9990}

IE - HKCU\..\SearchScopes\{0169E633-8781-F882-9BC7-7B014AE4DE4E}: "URL" = http://www.bing.com/search?q={searchTerms}&pc=Z206&form=ZGAIDF&install_date=20111005&iesrc={referrer:source}

IE - HKCU\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}&src=IE-SearchBox&FORM=IE8SRC

IE - HKCU\..\SearchScopes\{4A7BC363-1B1A-469A-8A9F-B08D6190106D}: "URL" = http://search.yahoo.com/search?fr=chr-greentree_ie&ei=utf-8&type=685749&p={searchTerms}

IE - HKCU\..\SearchScopes\{63EA0726-C83D-C02E-CF27-0160BA4048EB}: "URL" = http://www.bing.com/search?q={searchTerms}&pc=ZUGO&form=ZGAIDF

IE - HKCU\..\SearchScopes\{6A1806CD-94D4-4689-BA73-E35EA1EA9990}: "URL" = http://www.google.com/search?q={searchTerms}&rls=com.microsoft:{language}:{referrer:source?}&ie={inputEncoding}&oe={outputEncoding}&sourceid=ie7&rlz=1I7ADRA_enUS409

IE - HKCU\..\SearchScopes\{7B778A05-D20F-5F8F-66DF-EA2ADE1B9C35}: "URL" = http://www.bing.com/search?q={searchTerms}&pc=ZUGO&form=ZGAIDF

IE - HKCU\..\SearchScopes\{7C19EC30-6FAD-B9F6-82AA-0C5189279B17}: "URL" = http://www.google.com/search?q={searchTerms}&rls=com.microsoft:{language}:{referrer:source?}&ie={inputEncoding}&oe={outputEncoding}&sourceid=ie7&rlz=1I7ADRA_enUS409

IE - HKCU\..\SearchScopes\{afdbddaa-5d3f-42ee-b79c-185a7020515b}: "URL" = http://www.google.com/search?q={searchTerms}&rls=com.microsoft:{language}:{referrer:source?}&ie={inputEncoding}&oe={outputEncoding}&sourceid=ie7&rlz=1I7ADRA_enUS409

IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = 127.0.0.1:9421;<local>

 

 

========== FireFox ==========

 

FF:64bit: - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: disabled File not found

FF - HKLM\Software\MozillaPlugins\@java.com/DTPlugin,version=1.6.0_37: C:\Windows\SysWOW64\npdeployJava1.dll (Sun Microsystems, Inc.)

FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin: C:\Program Files (x86)\Java\jre6\bin\plugin2\npjp2.dll (Sun Microsystems, Inc.)

FF - HKLM\Software\MozillaPlugins\@messenger.yahoo.com/YahooMessengerStatePlugin;version=1.0.0.6: C:\Program Files (x86)\Yahoo!\Shared\npYState.dll (Yahoo! Inc.)

FF - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: disabled File not found

FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: C:\Program Files (x86)\Microsoft Silverlight\4.1.10329.0\npctrl.dll ( Microsoft Corporation)

FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3502.0922: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)

FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3508.1109: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)

FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3538.0513: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)

FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3555.0308: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)

FF - HKLM\Software\MozillaPlugins\@real.com/nppl3260;version=16.0.0.282: c:\program files (x86)\real\realplayer\Netscape6\nppl3260.dll (RealNetworks, Inc.)

FF - HKLM\Software\MozillaPlugins\@real.com/nprndlchromebrowserrecordext;version=1.3.0: C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\MozillaPlugins\nprndlchromebrowserrecordext.dll (RealNetworks, Inc.)

FF - HKLM\Software\MozillaPlugins\@real.com/nprndlhtml5videoshim;version=1.3.0: C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\MozillaPlugins\nprndlhtml5videoshim.dll (RealNetworks, Inc.)

FF - HKLM\Software\MozillaPlugins\@real.com/nprndlpepperflashvideoshim;version=1.3.0: C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\MozillaPlugins\nprndlpepperflashvideoshim.dll (RealNetworks, Inc.)

FF - HKLM\Software\MozillaPlugins\@real.com/nprpplugin;version=16.0.0.282: c:\program files (x86)\real\realplayer\Netscape6\nprpplugin.dll (RealPlayer)

FF - HKLM\Software\MozillaPlugins\@realnetworks.com/npdlplugin;version=1: C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\npdlplugin.dll (RealDownloader)

FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Program Files (x86)\Google\Update\1.3.21.123\npGoogleUpdate3.dll (Google Inc.)

FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Program Files (x86)\Google\Update\1.3.21.123\npGoogleUpdate3.dll (Google Inc.)

FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files (x86)\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)

 

FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\smartwebprinting@hp.com: C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3 [2012/05/28 07:33:53 | 000,000,000 | ---D | M]

FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{ABDE892B-13A8-4d1b-88E6-365A6E755758}: C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\Firefox\Ext

FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{97E22097-9A2F-45b1-8DAF-36AD648C7EF4}: C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\Firefox\Ext

FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{34712C68-7391-4c47-94F3-8F88D49AD632}: C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\Firefox\Ext\ [2012/12/18 08:19:49 | 000,000,000 | ---D | M]

FF - HKEY_CURRENT_USER\software\mozilla\Firefox\Extensions\\smartwebprinting@hp.com: C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3 [2012/05/28 07:33:53 | 000,000,000 | ---D | M]

 

[2013/02/01 05:54:32 | 000,000,000 | ---D | M] (No name found) -- C:\Program Files (x86)\Mozilla Firefox\extensions

 

========== Chrome ==========

 

CHR - plugin: Babylon Translator (Enabled) = dhkplhfnhceodhffomolpfigojocbpcb\1.4_0

CHR - plugin: Error reading preferences file

CHR - Extension: No name found = C:\Users\Deb\AppData\Local\Google\Chrome\User Data\Default\Extensions\bbjciahceamgodcoidkjpchnokgfpphh\1.0_0\

CHR - Extension: No name found = C:\Users\Deb\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.5_1\

CHR - Extension: No name found = C:\Users\Deb\AppData\Local\Google\Chrome\User Data\Default\Extensions\cjpglkicenollcignonpgiafdgfeehoj\4.0_0\

CHR - Extension: No name found = C:\Users\Deb\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf\0.0.0.19_1\

CHR - Extension: No name found = C:\Users\Deb\AppData\Local\Google\Chrome\User Data\Default\Extensions\dhkplhfnhceodhffomolpfigojocbpcb\1.4_0\

CHR - Extension: No name found = C:\Users\Deb\AppData\Local\Google\Chrome\User Data\Default\Extensions\fpcpcabjajdjmbkfinphfdflfipmalnj\1.0_0\

CHR - Extension: No name found = C:\Users\Deb\AppData\Local\Google\Chrome\User Data\Default\Extensions\idhngdhcfkoamngbedgpaokgjbnpdiji\1.3.0_0\

CHR - Extension: No name found = C:\Users\Deb\AppData\Local\Google\Chrome\User Data\Default\Extensions\ihflimipbcaljfnojhhknppphnnciiif\1.6.0_0\

CHR - Extension: No name found = C:\Users\Deb\AppData\Local\Google\Chrome\User Data\Default\Extensions\ihflimipbcaljfnojhhknppphnnciiif\1.6.0_0\facemoods\

CHR - Extension: No name found = C:\Users\Deb\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia\7_1\

 

O1 HOSTS File: ([2009/06/10 15:00:26 | 000,000,824 | ---- | M]) - C:\Windows\SysNative\drivers\etc\hosts

O2:64bit: - BHO: (SnagIt Toolbar Loader) - {00C6482D-C502-44C8-8409-FCE54AD9C208} - C:\Program Files (x86)\TechSmith\Snagit 10\DLLx64\SnagitBHO64.dll (TechSmith Corporation)

O2:64bit: - BHO: (Google Toolbar Helper) - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll (Google Inc.)

O2:64bit: - BHO: (Google Toolbar Notifier BHO) - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.7.8313.1002\swg64.dll (Google Inc.)

O2 - BHO: (SnagIt Toolbar Loader) - {00C6482D-C502-44C8-8409-FCE54AD9C208} - C:\Program Files (x86)\TechSmith\Snagit 10\SnagitBHO.dll (TechSmith Corporation)

O2 - BHO: (&Yahoo! Toolbar Helper) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\Program Files (x86)\Yahoo!\Companion\Installs\cpn0\yt.dll (Yahoo! Inc.)

O2 - BHO: (RealNetworks Download and Record Plugin for Internet Explorer) - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\IE\rndlbrowserrecordplugin.dll (RealDownloader)

O2 - BHO: (Java Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre6\bin\ssv.dll (Sun Microsystems, Inc.)

O2 - BHO: (no name) - {9D425283-D487-4337-BAB6-AB8354A81457} - No CLSID value found.

O2 - BHO: (Google Toolbar Notifier BHO) - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files (x86)\Google\GoogleToolbarNotifier\5.7.8313.1002\swg.dll (Google Inc.)

O2 - BHO: (IeMonitorBho Class) - {bf00e119-21a3-4fd1-b178-3b8537e75c92} - C:\Program Files (x86)\Megaupload\Mega Manager\MegaIEMn.dll (Megaupload Limited)

O2 - BHO: (SingleInstance Class) - {FDAD4DA1-61A2-4FD8-9C17-86F7AC245081} - C:\Program Files (x86)\Yahoo!\Companion\Installs\cpn0\YTSingleInstance.dll (Yahoo! Inc)

O3:64bit: - HKLM\..\Toolbar: (Google Toolbar) - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll (Google Inc.)

O3:64bit: - HKLM\..\Toolbar: (Snagit) - {8FF5E183-ABDE-46EB-B09E-D2AAB95CABE3} - C:\Program Files (x86)\TechSmith\Snagit 10\DLLx64\SnagitIEAddin64.dll (TechSmith Corporation)

O3:64bit: - HKLM\..\Toolbar: (no name) - Locked - No CLSID value found.

O3 - HKLM\..\Toolbar: (Snagit) - {8FF5E183-ABDE-46EB-B09E-D2AAB95CABE3} - C:\Program Files (x86)\TechSmith\Snagit 10\SnagitIEAddin.dll (TechSmith Corporation)

O3 - HKLM\..\Toolbar: (no name) - {9D425283-D487-4337-BAB6-AB8354A81457} - No CLSID value found.

O3 - HKLM\..\Toolbar: (Yahoo! Toolbar) - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files (x86)\Yahoo!\Companion\Installs\cpn0\yt.dll (Yahoo! Inc.)

O3 - HKLM\..\Toolbar: (no name) - Locked - No CLSID value found.

O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {22E03916-85C5-44B0-8DC9-1830C11238D9} - No CLSID value found.

O3:64bit: - HKCU\..\Toolbar\WebBrowser: (Google Toolbar) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll (Google Inc.)

O4:64bit: - HKLM..\Run: [AmIcoSinglun64] C:\Program Files (x86)\AmIcoSingLun\AmIcoSinglun64.exe (AlcorMicro Co., Ltd.)

O4:64bit: - HKLM..\Run: [EKAIO2StatusMonitor] C:\Windows\SysNative\spool\drivers\x64\3\EKAiO2MUI.exe (Eastman Kodak Company)

O4:64bit: - HKLM..\Run: [ETDWare] C:\Program Files\Elantech\ETDCtrl.exe (ELAN Microelectronic Corp.)

O4:64bit: - HKLM..\Run: [HotKeysCmds] C:\Windows\SysNative\hkcmd.exe (Intel Corporation)

O4:64bit: - HKLM..\Run: [igfxTray] C:\Windows\SysNative\igfxtray.exe (Intel Corporation)

O4:64bit: - HKLM..\Run: [Persistence] C:\Windows\SysNative\igfxpers.exe (Intel Corporation)

O4 - HKLM..\Run: [] File not found

O4 - HKLM..\Run: [AdobeCS5ServiceManager] C:\Program Files (x86)\Common Files\Adobe\CS5ServiceManager\CS5ServiceManager.exe (Adobe Systems Incorporated)

O4 - HKLM..\Run: [ATKMEDIA] C:\Program Files (x86)\ASUS\ATK Media\DMedia.exe (ASUS)

O4 - HKLM..\Run: [ATKOSD2] C:\Program Files (x86)\ASUS\ATKOSD2\ATKOSD2.exe (ASUS)

O4 - HKLM..\Run: [avgnt] C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe (Avira Operations GmbH & Co. KG)

O4 - HKLM..\Run: [Conime] %windir%\system32\conime.exe File not found

O4 - HKLM..\Run: [HControlUser] C:\Program Files (x86)\ASUS\ATK Hotkey\HControlUser.exe (ASUS)

O4 - HKLM..\Run: [HDAudDeck] C:\Program Files (x86)\VIA\VIAudioi\VDeck\VDeck.exe (VIA)

O4 - HKLM..\Run: [LGODDFU] C:\Program Files (x86)\lg_fwupdate\lgfw.exe (Bitleader)

O4 - HKLM..\Run: [switchBoard] C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe (Adobe Systems Incorporated)

O4 - HKLM..\Run: [TkBellExe] c:\program files (x86)\real\realplayer\Update\realsched.exe (RealNetworks, Inc.)

O4 - HKLM..\Run: [updateLBPShortCut] C:\Program Files (x86)\CyberLink\LabelPrint\MUITransfer\MUIStartMenu.exe (CyberLink Corp.)

O4 - HKCU..\Run: [] File not found

O4 - HKCU..\Run: [Akamai NetSession Interface] C:\Users\Deb\AppData\Local\Akamai\netsession_win.exe (Akamai Technologies, Inc.)

O4 - HKCU..\Run: [MimarSinan Rubber Ducky Update Setup for All Users] C:\ProgramData\{C357FF4B-BB69-4DC2-9869-55F052974DA8}\Rubber Ducky.exe (MimarSinan International )

O4 - HKCU..\Run: [Pando] C:\Program Files (x86)\Pando Networks\Pando\pando.exe (Pando Networks)

O4 - HKCU..\Run: [Weather] C:\Program Files (x86)\AWS\WeatherBug\Weather.exe (AWS Convergence Technologies, Inc.)

O4 - HKCU..\Run: [Window Washer] C:\Program Files (x86)\Webroot\Washer\wwDisp.exe (Webroot Software, Inc.)

O4 - Startup: C:\Users\Deb\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\ERUNT AutoBackup.lnk = C:\Program Files (x86)\ERUNT\AUTOBACK.EXE ()

O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Activities present

O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktop = 1

O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktopChanges = 1

O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 5

O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3

O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: PromptOnSecureDesktop = 0

O8:64bit: - Extra context menu item: Append Link Target to Existing PDF - res://C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIEAppendSelLinks.html File not found

O8:64bit: - Extra context menu item: Append to Existing PDF - res://C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIEAppend.html File not found

O8:64bit: - Extra context menu item: Convert Link Target to Adobe PDF - res://C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIECaptureSelLinks.html File not found

O8:64bit: - Extra context menu item: Convert to Adobe PDF - res://C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIECapture.html File not found

O8:64bit: - Extra context menu item: Download with Mipony - C:\Program Files (x86)\MiPony\Browser\IEContext.htm ()

O8 - Extra context menu item: Append Link Target to Existing PDF - res://C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIEAppendSelLinks.html File not found

O8 - Extra context menu item: Append to Existing PDF - res://C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIEAppend.html File not found

O8 - Extra context menu item: Convert Link Target to Adobe PDF - res://C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIECaptureSelLinks.html File not found

O8 - Extra context menu item: Convert to Adobe PDF - res://C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIECapture.html File not found

O8 - Extra context menu item: Download with Mipony - C:\Program Files (x86)\MiPony\Browser\IEContext.htm ()

O9:64bit: - Extra Button: Add to VideoGet - {88CFA58B-A63F-4A94-9C54-0C7A58E3333E} - C:\Program Files (x86)\Nuclear Coffee\VideoGet\Plugins\VideoGet_IE_x64.dll ()

O9:64bit: - Extra 'Tools' menuitem : Add to &VideoGet - {88CFA58B-A63F-4A94-9C54-0C7A58E3333E} - C:\Program Files (x86)\Nuclear Coffee\VideoGet\Plugins\VideoGet_IE_x64.dll ()

O1364bit: - gopher Prefix: missing

O13 - gopher Prefix: missing

O16:64bit: - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} Reg Error: Key error. (Reg Error: Key error.)

O16 - DPF: {0D41B8C5-2599-4893-8183-00195EC8D5F9} http://support.asus.com/select/asusTek_sys_ctrl3.cab (asusTek_sysctrl Class)

O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} http://download.microsoft.com/download/E/5/6/E5611B10-0D6D-4117-8430-A67417AA88CD/LegitCheckControl.cab (Windows Genuine Advantage Validation Tool)

O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-1_6_0_37-windows-i586.cab (Java Plug-in 1.6.0_37)

O16 - DPF: {CAFEEFAC-0016-0000-0037-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-1_6_0_37-windows-i586.cab (Java Plug-in 1.6.0_37)

O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-1_6_0_37-windows-i586.cab (Java Plug-in 1.6.0_37)

O16 - DPF: {D71F9A27-723E-4B8B-B428-B725E47CBA3E} http://imikimi.com/download/imikimi_plugin_0.5.1.cab (Imikimi_activex_plugin Control)

O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab (Reg Error: Key error.)

O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.2.1

O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{FFE16A46-948F-4F90-964E-E3E86D151408}: DhcpNameServer = 192.168.2.1

O18:64bit: - Protocol\Handler\grooveLocalGWS - No CLSID value found

O18:64bit: - Protocol\Handler\livecall - No CLSID value found

O18:64bit: - Protocol\Handler\ms-help - No CLSID value found

O18:64bit: - Protocol\Handler\ms-itss - No CLSID value found

O18:64bit: - Protocol\Handler\msnim - No CLSID value found

O18:64bit: - Protocol\Handler\wlmailhtml - No CLSID value found

O18:64bit: - Protocol\Handler\wlpg - No CLSID value found

O20:64bit: - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)

O20:64bit: - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\SysNative\userinit.exe (Microsoft Corporation)

O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\SysWow64\explorer.exe (Microsoft Corporation)

O20 - HKLM Winlogon: UserInit - (C:\Windows\System32\userinit.exe) - C:\Windows\SysWOW64\userinit.exe (Microsoft Corporation)

O20:64bit: - Winlogon\Notify\igfxcui: DllName - (igfxdev.dll) - C:\Windows\SysNative\igfxdev.dll (Intel Corporation)

O21:64bit: - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.

O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.

O28:64bit: - HKLM ShellExecuteHooks: {AEB6717E-7E19-11d0-97EE-00C04FD91972} - No CLSID value found.

O32 - HKLM CDRom: AutoRun - 1

O34 - HKLM BootExecute: (autocheck autochk *)

O35:64bit: - HKLM\..comfile [open] -- "%1" %*

O35:64bit: - HKLM\..exefile [open] -- "%1" %*

O35 - HKLM\..comfile [open] -- "%1" %*

O35 - HKLM\..exefile [open] -- "%1" %*

O37:64bit: - HKLM\...com [@ = comfile] -- "%1" %*

O37:64bit: - HKLM\...exe [@ = exefile] -- "%1" %*

O37 - HKLM\...com [@ = comfile] -- "%1" %*

O37 - HKLM\...exe [@ = exefile] -- "%1" %*

O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)

O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2)

O38 - SubSystems\\Windows: (ServerDll=sxssrv,4)

 

========== Files/Folders - Created Within 30 Days ==========

 

[2013/02/05 06:42:20 | 000,000,000 | ---D | C] -- C:\Users\Deb\AppData\Local\{E3756A3F-B05C-4224-9CBD-BBAE953FF279}

[2013/02/05 05:04:05 | 000,602,112 | ---- | C] (OldTimer Tools) -- C:\Users\Deb\Desktop\OTL.exe

[2013/02/05 04:52:48 | 000,000,000 | ---D | C] -- C:\_OTL

[2013/02/05 04:37:03 | 000,000,000 | ---D | C] -- C:\Windows\ERDNT

[2013/02/05 04:35:05 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ERUNT

[2013/02/05 04:35:05 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\ERUNT

[2013/02/05 04:33:08 | 000,791,393 | ---- | C] (Lars Hederer ) -- C:\Users\Deb\Desktop\erunt-setup.exe

[2013/02/04 18:41:45 | 000,000,000 | ---D | C] -- C:\Users\Deb\AppData\Local\{FE96027B-A669-40AD-99A0-36E5122AF23F}

[2013/02/03 04:21:30 | 000,000,000 | ---D | C] -- C:\Users\Deb\AppData\Local\{57F1C703-D27F-4A5F-BE56-3776BC2A973E}

[2013/02/02 09:31:42 | 000,000,000 | ---D | C] -- C:\Users\Deb\AppData\Roaming\ArcticLine

[2013/02/02 09:31:06 | 000,000,000 | R--D | C] -- C:\Users\Deb\Desktop\OTL

[2013/02/02 09:17:19 | 000,000,000 | ---D | C] -- C:\Users\Deb\AppData\Local\{EDD7F6B1-436A-4ABD-832B-59ECF22C6960}

[2013/02/01 17:25:46 | 000,000,000 | ---D | C] -- C:\Users\Deb\AppData\Local\{42234831-8B08-43B1-96A6-6045FEE150A9}

[2013/02/01 07:38:01 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes' Anti-Malware

[2013/02/01 07:37:59 | 000,024,176 | ---- | C] (Malwarebytes Corporation) -- C:\Windows\SysNative\drivers\mbam.sys

[2013/02/01 07:36:21 | 010,156,344 | ---- | C] (Malwarebytes Corporation ) -- C:\Users\Deb\Desktop\mbam-setup-1.70.0.1100.exe

[2013/02/01 05:25:08 | 000,000,000 | ---D | C] -- C:\Users\Deb\AppData\Local\{95CF7132-8491-4CD2-9E5E-97B82B87D47A}

[2013/01/31 10:01:41 | 000,000,000 | ---D | C] -- C:\Users\Deb\AppData\Local\{5047659E-C3FF-4879-99C3-07F8CA609FA6}

[2013/01/31 08:33:24 | 000,000,000 | ---D | C] -- C:\Users\Deb\AppData\Local\{0287C327-9C05-46BF-B7A1-9086769A2D0C}

[2013/01/30 08:59:26 | 000,000,000 | ---D | C] -- C:\Users\Deb\AppData\Local\{0731825A-EC4A-41FA-8E38-BAD4E1A1B061}

[2013/01/29 08:42:50 | 000,000,000 | ---D | C] -- C:\Users\Deb\AppData\Local\{553FB952-2015-4903-A09D-4F0E26A63C5E}

[2013/01/28 08:41:45 | 000,000,000 | ---D | C] -- C:\Users\Deb\AppData\Local\{A1A41F13-03AE-4BBA-A4E2-D4A593DF6E31}

[2013/01/27 09:26:47 | 000,000,000 | ---D | C] -- C:\Users\Deb\AppData\Roaming\Malwarebytes

[2013/01/27 09:26:20 | 000,000,000 | ---D | C] -- C:\ProgramData\Malwarebytes

[2013/01/27 09:26:16 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Malwarebytes' Anti-Malware

[2013/01/27 09:25:33 | 000,000,000 | ---D | C] -- C:\Users\Deb\AppData\Local\Programs

[2013/01/27 08:40:52 | 000,000,000 | ---D | C] -- C:\Users\Deb\AppData\Local\{E65F738D-9443-4971-9352-F66A692643C4}

[2013/01/24 19:47:50 | 000,000,000 | ---D | C] -- C:\Users\Deb\AppData\Local\{740A36B2-621C-4272-845E-DF12E99C78C1}

[2013/01/24 07:47:23 | 000,000,000 | ---D | C] -- C:\Users\Deb\AppData\Local\{6B52BFC3-84B8-4BC2-896D-8D8E04863DC9}

[2013/01/20 09:13:03 | 000,000,000 | ---D | C] -- C:\Users\Deb\AppData\Local\{E2E3FE0B-6FBE-4A1E-AF47-BD5041A3624B}

[2013/01/19 21:08:46 | 000,000,000 | ---D | C] -- C:\Users\Deb\AppData\Local\{B966D18E-7F69-47D5-8401-8BA6A11669E6}

[2013/01/19 19:33:46 | 000,000,000 | ---D | C] -- C:\Program Files\Microsoft Security Client

[2013/01/19 09:51:27 | 000,000,000 | ---D | C] -- C:\Users\Deb\AppData\Roaming\Anvisoft

[2013/01/19 09:51:15 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\anvisoft

[2013/01/19 09:51:13 | 000,000,000 | ---D | C] -- C:\ProgramData\Anvisoft

[2013/01/19 05:54:49 | 000,000,000 | ---D | C] -- C:\Users\Deb\AppData\Roaming\FixBee

[2013/01/19 05:54:49 | 000,000,000 | ---D | C] -- C:\ProgramData\FixBee

[2013/01/18 21:07:46 | 000,000,000 | ---D | C] -- C:\Users\Deb\AppData\Local\{2E3324BA-5C42-4324-A5C6-7336F189E63C}

[2013/01/18 14:39:02 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\FixBee Disk Optimizer

[2013/01/18 14:38:59 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\FixBee

[2013/01/18 14:38:56 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\SRToolbar

[2013/01/18 09:07:11 | 000,000,000 | ---D | C] -- C:\Users\Deb\AppData\Local\{8EC434FA-420B-47B7-9554-BD9441DB3FFE}

[2013/01/18 08:14:08 | 000,000,000 | ---D | C] -- C:\Windows\pss

[2013/01/17 19:55:16 | 000,000,000 | ---D | C] -- C:\Users\Deb\AppData\Roaming\WinRAR

[2013/01/17 19:55:15 | 000,000,000 | ---D | C] -- C:\Users\Deb\AppData\Local\DownTango

[2013/01/17 19:55:13 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\DownTango

[2013/01/17 09:06:14 | 000,000,000 | ---D | C] -- C:\Users\Deb\AppData\Local\{2CA50C82-3F07-4F48-9707-A62F0F77B23D}

[2013/01/16 17:48:37 | 000,000,000 | ---D | C] -- C:\Users\Deb\AppData\Local\{4A67868C-A839-44EC-B25E-87C83532E0DF}

[2013/01/16 07:05:52 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\EaseUS Data Recovery Wizard 5.6.5

[2013/01/16 05:48:02 | 000,000,000 | ---D | C] -- C:\Users\Deb\AppData\Local\{18C7CAE6-2D57-42B1-B823-8C0E23BBA00C}

[2013/01/15 09:13:53 | 000,000,000 | ---D | C] -- C:\Users\Deb\AppData\Local\{D8C64BCE-62CF-4985-90EC-1082D4CA5EF3}

[2013/01/14 15:29:14 | 000,000,000 | ---D | C] -- C:\Users\Deb\AppData\Local\{E3C4DD56-2019-4342-B117-6974C6D81EEC}

[2013/01/13 04:56:07 | 000,000,000 | ---D | C] -- C:\Users\Deb\AppData\Local\{1E9789FD-D1E5-4F0A-8197-3C96A6246FC6}

[2013/01/12 10:29:12 | 000,000,000 | ---D | C] -- C:\Users\Deb\Desktop\Good_morning!

[2013/01/12 08:22:48 | 000,000,000 | ---D | C] -- C:\Users\Deb\AppData\Local\{D5C04CAA-7B0D-46DC-A43D-5A8934F1A00A}

[2013/01/11 16:37:46 | 000,000,000 | ---D | C] -- C:\Users\Deb\AppData\Local\{86AE18EA-D2D7-4F78-A316-559CD87554C6}

[2013/01/11 04:37:23 | 000,000,000 | ---D | C] -- C:\Users\Deb\AppData\Local\{38263396-8971-473D-9686-D9E0B043A04E}

[2013/01/10 07:19:53 | 000,000,000 | ---D | C] -- C:\Users\Deb\AppData\Local\{66363DFD-6584-42C3-ABF6-26DF6393D0A3}

[2013/01/09 08:03:43 | 000,000,000 | ---D | C] -- C:\Users\Deb\AppData\Local\{21D7C0B8-0255-4EBE-95C2-63E2609F7963}

[2013/01/08 07:54:44 | 000,000,000 | ---D | C] -- C:\Users\Deb\AppData\Local\{08D71E41-6BCB-4D7E-8115-90912FEFFEDF}

[2013/01/07 06:58:03 | 000,000,000 | ---D | C] -- C:\Users\Deb\AppData\Local\{AC76A610-688C-47B5-9263-19DF34042B56}

[2008/08/11 22:45:20 | 000,155,648 | ---- | C] (ASUS) -- C:\Program Files (x86)\Common Files\MSIactionall.dll

[1 C:\Windows\SysWow64\*.tmp files -> C:\Windows\SysWow64\*.tmp -> ]

[1 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ]

 

========== Files - Modified Within 30 Days ==========

 

[2013/02/05 11:54:10 | 000,000,803 | ---- | M] () -- C:\Users\Deb\Desktop\fixme.zip

[2013/02/05 11:50:00 | 000,002,098 | ---- | M] () -- C:\Users\Deb\Desktop\FIXME.reg

[2013/02/05 11:35:00 | 000,000,830 | ---- | M] () -- C:\Windows\tasks\Adobe Flash Player Updater.job

[2013/02/05 11:35:00 | 000,000,314 | ---- | M] () -- C:\Windows\tasks\PrintProjects Communicator.job

[2013/02/05 11:23:54 | 000,000,780 | ---- | M] () -- C:\Users\Deb\Desktop\System Look.lnk

[2013/02/05 11:10:00 | 000,000,892 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineUA.job

[2013/02/05 10:10:00 | 000,000,888 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineCore.job

[2013/02/05 09:49:10 | 000,010,240 | -H-- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0

[2013/02/05 09:49:10 | 000,010,240 | -H-- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0

[2013/02/05 09:44:25 | 000,165,376 | ---- | M] () -- C:\Users\Deb\Desktop\SystemLook_x64.exe

[2013/02/05 08:34:00 | 000,000,490 | ---- | M] () -- C:\Windows\tasks\03-31-2011_103440.job

[2013/02/05 06:19:40 | 000,792,550 | ---- | M] () -- C:\Windows\SysNative\PerfStringBackup.INI

[2013/02/05 06:19:40 | 000,669,298 | ---- | M] () -- C:\Windows\SysNative\perfh009.dat

[2013/02/05 06:19:40 | 000,125,452 | ---- | M] () -- C:\Windows\SysNative\perfc009.dat

[2013/02/05 06:18:27 | 000,000,344 | ---- | M] () -- C:\Windows\lgfwup.ini

[2013/02/05 06:15:07 | 000,067,584 | --S- | M] () -- C:\Windows\bootstat.dat

[2013/02/05 06:15:00 | 3193,765,888 | -HS- | M] () -- C:\hiberfil.sys

[2013/02/05 05:34:34 | 000,602,112 | ---- | M] (OldTimer Tools) -- C:\Users\Deb\Desktop\OTL.exe

[2013/02/05 04:46:09 | 000,001,110 | ---- | M] () -- C:\Users\Deb\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\ERUNT AutoBackup.lnk

[2013/02/05 04:45:53 | 000,000,930 | ---- | M] () -- C:\Users\Deb\Desktop\NTREGOPT.lnk

[2013/02/05 04:45:53 | 000,000,911 | ---- | M] () -- C:\Users\Deb\Desktop\ERUNT.lnk

[2013/02/05 04:33:09 | 000,791,393 | ---- | M] (Lars Hederer ) -- C:\Users\Deb\Desktop\erunt-setup.exe

[2013/02/05 04:30:17 | 000,000,048 | ---- | M] () -- C:\Windows\wininit.ini

[2013/02/01 07:38:01 | 000,001,115 | ---- | M] () -- C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk

[2013/02/01 07:36:25 | 010,156,344 | ---- | M] (Malwarebytes Corporation ) -- C:\Users\Deb\Desktop\mbam-setup-1.70.0.1100.exe

[2013/01/20 06:30:57 | 000,010,841 | ---- | M] () -- C:\Users\Deb\Documents\paisley.pat

[2013/01/18 14:39:04 | 000,000,997 | ---- | M] () -- C:\Users\Deb\Application Data\Microsoft\Internet Explorer\Quick Launch\FixBee Disk Optimizer.lnk

[2013/01/18 14:39:03 | 000,002,057 | ---- | M] () -- C:\Users\Public\Desktop\FixBee Disk Optimizer.lnk

[2013/01/18 09:41:22 | 000,001,056 | ---- | M] () -- C:\prefs.js

[2013/01/17 19:55:01 | 000,000,000 | ---- | M] () -- C:\end

[2013/01/17 19:54:59 | 000,000,000 | ---- | M] () -- C:\extensions.sqlite

[2013/01/17 19:53:11 | 000,002,236 | ---- | M] () -- C:\Users\Deb\Application Data\Microsoft\Internet Explorer\Quick Launch\Snagit 10.lnk

[2013/01/17 19:53:11 | 000,001,897 | ---- | M] () -- C:\Users\Deb\Application Data\Microsoft\Internet Explorer\Quick Launch\TOSHIBA DVD PLAYER.lnk

[2013/01/17 19:53:11 | 000,001,448 | ---- | M] () -- C:\Users\Deb\Application Data\Microsoft\Internet Explorer\Quick Launch\Wondershare DVD Slideshow Builder Standard.lnk

[2013/01/17 19:53:11 | 000,001,385 | ---- | M] () -- C:\Users\Deb\Application Data\Microsoft\Internet Explorer\Quick Launch\Wondershare Photo Collage Studio.lnk

[2013/01/17 19:53:11 | 000,001,319 | ---- | M] () -- C:\Users\Deb\Application Data\Microsoft\Internet Explorer\Quick Launch\Picture Collage Maker.lnk

[2013/01/17 19:53:11 | 000,001,303 | ---- | M] () -- C:\Users\Deb\Application Data\Microsoft\Internet Explorer\Quick Launch\Yahoo! Messenger.lnk

[2013/01/17 19:53:11 | 000,001,279 | ---- | M] () -- C:\Users\Deb\Application Data\Microsoft\Internet Explorer\Quick Launch\Pixpedia Publisher.lnk

[2013/01/17 19:53:11 | 000,001,213 | ---- | M] () -- C:\Users\Deb\Application Data\Microsoft\Internet Explorer\Quick Launch\WinX DVD Copy Pro.lnk

[2013/01/17 19:53:11 | 000,001,085 | ---- | M] () -- C:\Users\Deb\Application Data\Microsoft\Internet Explorer\Quick Launch\XnView.lnk

[2013/01/17 19:53:11 | 000,000,955 | ---- | M] () -- C:\Users\Deb\Application Data\Microsoft\Internet Explorer\Quick Launch\Spyware Terminator.lnk

[2013/01/17 19:53:11 | 000,000,859 | ---- | M] () -- C:\Users\Deb\Application Data\Microsoft\Internet Explorer\Quick Launch\Xara3D6.lnk

[2013/01/17 19:53:11 | 000,000,859 | ---- | M] () -- C:\Users\Deb\Application Data\Microsoft\Internet Explorer\Quick Launch\RegistryBooster.lnk

[2013/01/17 19:53:11 | 000,000,426 | ---- | M] () -- C:\Users\Deb\Application Data\Microsoft\Internet Explorer\Quick Launch\Shows Desktop.lnk

[2013/01/17 19:53:11 | 000,000,408 | ---- | M] () -- C:\Users\Deb\Application Data\Microsoft\Internet Explorer\Quick Launch\Window Switcher.lnk

[2013/01/17 19:53:10 | 000,002,825 | ---- | M] () -- C:\Users\Deb\Application Data\Microsoft\Internet Explorer\Quick Launch\Jasc Paint Shop Pro 9.lnk

[2013/01/17 19:53:10 | 000,002,813 | ---- | M] () -- C:\Users\Deb\Application Data\Microsoft\Internet Explorer\Quick Launch\Jasc Paint Shop Pro 9 (1).lnk

[2013/01/17 19:53:10 | 000,002,381 | ---- | M] () -- C:\Users\Deb\Application Data\Microsoft\Internet Explorer\Quick Launch\Google Chrome.lnk

[2013/01/17 19:53:10 | 000,002,300 | ---- | M] () -- C:\Users\Deb\Application Data\Microsoft\Internet Explorer\Quick Launch\mediAvatar Photo to Flash.lnk

[2013/01/17 19:53:10 | 000,002,116 | ---- | M] () -- C:\Users\Deb\Application Data\Microsoft\Internet Explorer\Quick Launch\Nero Express.lnk

[2013/01/17 19:53:10 | 000,001,579 | ---- | M] () -- C:\Users\Deb\Application Data\Microsoft\Internet Explorer\Quick Launch\Launch Internet Explorer Browser.lnk

[2013/01/17 19:53:10 | 000,001,315 | ---- | M] () -- C:\Users\Deb\Application Data\Microsoft\Internet Explorer\Quick Launch\Free GMT AVI to DVD.lnk

[2013/01/17 19:53:10 | 000,001,238 | ---- | M] () -- C:\Users\Deb\Application Data\Microsoft\Internet Explorer\Quick Launch\Game Booster.lnk

[2013/01/17 19:53:10 | 000,001,145 | ---- | M] () -- C:\Users\Deb\Application Data\Microsoft\Internet Explorer\Quick Launch\MiPony.lnk

[2013/01/17 19:53:10 | 000,001,109 | ---- | M] () -- C:\Users\Deb\Application Data\Microsoft\Internet Explorer\Quick Launch\NeoPaint.lnk

[2013/01/17 19:53:10 | 000,001,006 | ---- | M] () -- C:\Users\Deb\Application Data\Microsoft\Internet Explorer\Quick Launch\GOM Player.lnk

[2013/01/17 19:53:10 | 000,000,859 | ---- | M] () -- C:\Users\Deb\Application Data\Microsoft\Internet Explorer\Quick Launch\Opera.lnk

[2013/01/17 19:53:10 | 000,000,859 | ---- | M] () -- C:\Users\Deb\Application Data\Microsoft\Internet Explorer\Quick Launch\Log Analysis - Sax2.lnk

[2013/01/17 19:53:10 | 000,000,859 | ---- | M] () -- C:\Users\Deb\Application Data\Microsoft\Internet Explorer\Quick Launch\Intrusion Detection System - Sax2.lnk

[2013/01/17 19:53:09 | 000,002,231 | ---- | M] () -- C:\Users\Deb\Application Data\Microsoft\Internet Explorer\Quick Launch\Corel Paint Shop Pro X.lnk

[2013/01/17 19:53:09 | 000,001,498 | ---- | M] () -- C:\Users\Deb\Application Data\Microsoft\Internet Explorer\Quick Launch\Batch Photo Watermarker.lnk

[2013/01/17 19:53:09 | 000,001,362 | ---- | M] () -- C:\Users\Deb\Application Data\Microsoft\Internet Explorer\Quick Launch\ConvertXtoDVD 4.lnk

[2013/01/17 19:53:09 | 000,001,265 | ---- | M] () -- C:\Users\Deb\Application Data\Microsoft\Internet Explorer\Quick Launch\FoxTab AVI Converter.lnk

[2013/01/17 19:53:09 | 000,001,259 | ---- | M] () -- C:\Users\Deb\Application Data\Microsoft\Internet Explorer\Quick Launch\Free Easy Burner.lnk

[2013/01/17 19:53:09 | 000,001,221 | ---- | M] () -- C:\Users\Deb\Application Data\Microsoft\Internet Explorer\Quick Launch\FinalTorrent.lnk

[2013/01/17 19:53:09 | 000,001,214 | ---- | M] () -- C:\Users\Deb\Application Data\Microsoft\Internet Explorer\Quick Launch\easyQuizzy.lnk

[2013/01/17 19:53:09 | 000,001,149 | ---- | M] () -- C:\Users\Deb\Application Data\Microsoft\Internet Explorer\Quick Launch\DVD Shrink 3.2.lnk

[2013/01/17 19:53:09 | 000,001,149 | ---- | M] () -- C:\Users\Deb\Application Data\Microsoft\Internet Explorer\Quick Launch\BatchInpaint.lnk

[2013/01/17 19:53:09 | 000,001,119 | ---- | M] () -- C:\Users\Deb\Application Data\Microsoft\Internet Explorer\Quick Launch\CollageIt.lnk

[2013/01/17 19:53:08 | 000,002,584 | ---- | M] () -- C:\Users\Deb\Application Data\Microsoft\Internet Explorer\Quick Launch\Aiseesoft Total Media Converter.lnk

[2013/01/17 19:53:08 | 000,002,344 | ---- | M] () -- C:\Users\Deb\Application Data\Microsoft\Internet Explorer\Quick Launch\Adobe Digital Editions.lnk

[2013/01/17 19:53:08 | 000,002,325 | ---- | M] () -- C:\Users\Deb\Application Data\Microsoft\Internet Explorer\Quick Launch\4Media Photo Slideshow Maker.lnk

[2013/01/17 19:53:08 | 000,002,269 | ---- | M] () -- C:\Users\Deb\Application Data\Microsoft\Internet Explorer\Quick Launch\4Media Ringtone Maker.lnk

[2013/01/17 19:53:08 | 000,001,254 | ---- | M] () -- C:\Users\Deb\Application Data\Microsoft\Internet Explorer\Quick Launch\AnyPic Image Resizer Pro.lnk

[2013/01/17 19:53:08 | 000,000,859 | ---- | M] () -- C:\Users\Deb\Application Data\Microsoft\Internet Explorer\Quick Launch\Ashampoo Burning Studio 2010 Advanced.lnk

[2013/01/17 19:24:50 | 000,045,169 | ---- | M] () -- C:\Users\Deb\Desktop\PolkaDot_Baby_Blanket.pdf

[2013/01/11 04:33:21 | 005,620,584 | ---- | M] () -- C:\Windows\SysNative\FNTCACHE.DAT

[2013/01/10 07:42:38 | 000,786,766 | ---- | M] () -- C:\Windows\SysWow64\PerfStringBackup.INI

[1 C:\Windows\SysWow64\*.tmp files -> C:\Windows\SysWow64\*.tmp -> ]

[1 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ]

 

========== Files Created - No Company Name ==========

 

[2013/02/05 11:57:15 | 000,002,098 | ---- | C] () -- C:\Users\Deb\Desktop\FIXME.reg

[2013/02/05 11:54:10 | 000,000,803 | ---- | C] () -- C:\Users\Deb\Desktop\fixme.zip

[2013/02/05 11:23:54 | 000,000,780 | ---- | C] () -- C:\Users\Deb\Desktop\System Look.lnk

[2013/02/05 09:44:23 | 000,165,376 | ---- | C] () -- C:\Users\Deb\Desktop\SystemLook_x64.exe

[2013/02/05 04:46:09 | 000,001,110 | ---- | C] () -- C:\Users\Deb\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\ERUNT AutoBackup.lnk

[2013/02/05 04:35:05 | 000,000,930 | ---- | C] () -- C:\Users\Deb\Desktop\NTREGOPT.lnk

[2013/02/05 04:35:05 | 000,000,911 | ---- | C] () -- C:\Users\Deb\Desktop\ERUNT.lnk

[2013/02/05 04:30:17 | 000,000,048 | ---- | C] () -- C:\Windows\wininit.ini

[2013/02/01 07:38:01 | 000,001,115 | ---- | C] () -- C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk

[2013/01/20 06:30:57 | 000,010,841 | ---- | C] () -- C:\Users\Deb\Documents\paisley.pat

[2013/01/18 14:39:04 | 000,000,997 | ---- | C] () -- C:\Users\Deb\Application Data\Microsoft\Internet Explorer\Quick Launch\FixBee Disk Optimizer.lnk

[2013/01/18 14:39:03 | 000,002,057 | ---- | C] () -- C:\Users\Public\Desktop\FixBee Disk Optimizer.lnk

[2013/01/17 19:54:59 | 000,000,000 | ---- | C] () -- C:\extensions.sqlite

[2013/01/17 19:54:50 | 000,000,000 | ---- | C] () -- C:\end

[2013/01/17 19:53:13 | 000,015,360 | ---- | C] () -- C:\Windows\Launcher.exe

[2013/01/17 19:24:49 | 000,045,169 | ---- | C] () -- C:\Users\Deb\Desktop\PolkaDot_Baby_Blanket.pdf

[2012/08/20 09:46:35 | 000,384,844 | ---- | C] () -- C:\Users\Deb\AppData\Local\funmoods-speeddial.crx

[2012/08/12 08:45:52 | 000,004,470 | ---- | C] () -- C:\Users\Deb\pspbrwse.jbf

[2012/04/06 14:07:58 | 000,000,344 | ---- | C] () -- C:\Windows\lgfwup.ini

[2011/11/27 07:09:54 | 000,161,694 | ---- | C] () -- C:\Windows\Animated Wallpaper Maker Uninstaller.exe

[2011/11/13 13:30:25 | 000,000,288 | ---- | C] () -- C:\Windows\ODBC.INI

[2011/11/13 13:30:24 | 000,001,644 | ---- | C] () -- C:\Windows\ODBCINST.INI

[2011/10/05 08:31:08 | 000,000,038 | ---- | C] () -- C:\Windows\avisplitter.ini

[2011/10/05 08:31:07 | 000,650,752 | ---- | C] () -- C:\Windows\SysWow64\xvidcore.dll

[2011/10/05 08:31:07 | 000,243,200 | ---- | C] () -- C:\Windows\SysWow64\xvidvfw.dll

[2011/09/28 04:49:43 | 000,087,040 | ---- | C] () -- C:\Windows\UnGins.exe

[2011/08/15 12:34:07 | 000,044,544 | ---- | C] () -- C:\Windows\SysWow64\gif89.dll

[2011/08/15 12:33:54 | 000,000,285 | ---- | C] () -- C:\Windows\SIERRA.INI

[2011/08/15 04:20:07 | 000,007,597 | ---- | C] () -- C:\Users\Deb\AppData\Local\Resmon.ResmonCfg

[2011/08/06 03:20:57 | 000,161,807 | ---- | C] () -- C:\Windows\Animated Screensaver Maker Uninstaller.exe

[2011/07/11 13:27:17 | 000,026,000 | ---- | C] () -- C:\Windows\SysWow64\PteVideo.dll

[2011/07/01 06:16:12 | 000,000,069 | ---- | C] () -- C:\Windows\NeroDigital.ini

[2011/05/21 03:16:40 | 000,162,598 | ---- | C] () -- C:\Windows\DP Animation Maker Uninstaller.exe

[2011/04/23 06:19:51 | 000,027,648 | R--- | C] () -- C:\Windows\Setup_ck.exe

[2011/04/23 06:19:51 | 000,024,608 | ---- | C] () -- C:\Windows\SysWow64\Ckldrv.sys

[2011/04/23 06:19:51 | 000,018,432 | ---- | C] () -- C:\Windows\Setup_ck.dll

[2011/04/23 06:19:51 | 000,011,776 | ---- | C] () -- C:\Windows\Ckrfresh.exe

[2011/04/20 09:44:49 | 000,000,368 | ---- | C] () -- C:\Users\Deb\AppData\Roaming\wklnhst.dat

[2011/03/23 16:54:15 | 000,786,766 | ---- | C] () -- C:\Windows\SysWow64\PerfStringBackup.INI

[2011/03/18 16:13:04 | 000,000,042 | ---- | C] () -- C:\Windows\PCSPATS.DAT

[2011/02/19 19:42:30 | 000,000,091 | ---- | C] () -- C:\Windows\Crypkey.ini

[2010/12/21 10:06:03 | 000,000,069 | ---- | C] () -- C:\Users\Deb\AppData\Roaming\IncrediMail Collection ManagerIcm.ini

[2010/12/19 11:55:26 | 000,001,057 | ---- | C] () -- C:\Users\Deb\AppData\Roaming\vso_ts_preview.xml

[2010/12/15 12:16:53 | 000,035,840 | ---- | C] () -- C:\Users\Deb\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini

[2010/12/15 11:14:41 | 000,000,080 | -HS- | C] () -- C:\ProgramData\.zreglib

[2010/12/11 13:35:07 | 019,985,265 | ---- | C] () -- C:\ProgramData\vlc-1.1.5-win32.exe

[2009/04/08 11:31:56 | 000,106,496 | ---- | C] () -- C:\Program Files (x86)\Common Files\CPInstallAction.dll

[2009/03/27 10:14:04 | 000,033,940 | ---- | C] () -- C:\Users\Deb\qotw.jpg

[2009/03/22 13:46:48 | 000,016,769 | ---- | C] () -- C:\Users\Deb\flowers.PLC

[2009/03/03 11:32:32 | 000,705,558 | ---- | C] () -- C:\Users\Deb\QBD_-_LaceBorderNFramesScripts.zip

[2009/02/16 19:30:54 | 000,658,608 | ---- | C] () -- C:\Program Files (x86)\MagicDVDRipper.exe

[2009/02/09 11:56:30 | 000,313,344 | ---- | C] () -- C:\Program Files (x86)\hjsplit.exe

[2009/01/18 08:46:29 | 000,001,024 | ---- | C] () -- C:\Users\Deb\.rnd

[2008/05/22 09:35:54 | 000,051,962 | ---- | C] () -- C:\Program Files (x86)\Common Files\banner.jpg

[2006/11/02 06:50:50 | 000,000,174 | -HS- | C] () -- C:\Program Files (x86)\desktop (1).ini

 

========== ZeroAccess Check ==========

 

[2011/07/03 14:29:46 | 000,000,000 | ---D | M] -- C:\$Recycle.bin\S-1-5-21-4070860634-2794675311-1628887733-1000\$ROXZ5D7\L

[2009/07/13 22:55:00 | 000,000,227 | RHS- | M] () -- C:\Windows\assembly\Desktop.ini

 

[HKEY_CURRENT_USER\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] /64

 

[HKEY_CURRENT_USER\Software\Classes\Wow6432node\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]

 

[HKEY_CURRENT_USER\Software\Classes\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32] /64

 

[HKEY_CURRENT_USER\Software\Classes\Wow6432node\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32]

 

[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] /64

"" = C:\Windows\SysNative\shell32.dll -- [2012/06/08 23:43:10 | 014,172,672 | ---- | M] (Microsoft Corporation)

"ThreadingModel" = Apartment

 

[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]

"" = %SystemRoot%\system32\shell32.dll -- [2012/06/08 22:41:00 | 012,873,728 | ---- | M] (Microsoft Corporation)

"ThreadingModel" = Apartment

 

[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32] /64

"" = C:\Windows\SysNative\wbem\fastprox.dll -- [2009/07/13 19:40:51 | 000,909,312 | ---- | M] (Microsoft Corporation)

"ThreadingModel" = Free

 

[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32]

"" = %systemroot%\system32\wbem\fastprox.dll -- [2010/11/20 06:19:02 | 000,606,208 | ---- | M] (Microsoft Corporation)

"ThreadingModel" = Free

 

[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32] /64

"" = C:\Windows\SysNative\wbem\wbemess.dll -- [2009/07/13 19:41:56 | 000,505,856 | ---- | M] (Microsoft Corporation)

"ThreadingModel" = Both

 

[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32]

 

========== LOP Check ==========

 

[2011/04/27 17:18:59 | 000,000,000 | -HSD | M] -- C:\Users\Deb\AppData\Roaming\.#

[2012/03/30 12:58:05 | 000,000,000 | ---D | M] -- C:\Users\Deb\AppData\Roaming\4Media

[2013/01/19 19:38:06 | 000,000,000 | ---D | M] -- C:\Users\Deb\AppData\Roaming\Anvisoft

[2011/07/03 04:19:51 | 000,000,000 | ---D | M] -- C:\Users\Deb\AppData\Roaming\AnyPic Image Converter

[2011/05/08 10:59:39 | 000,000,000 | ---D | M] -- C:\Users\Deb\AppData\Roaming\AnyPic Image Resizer Pro

[2013/02/02 09:31:42 | 000,000,000 | ---D | M] -- C:\Users\Deb\AppData\Roaming\ArcticLine

[2012/01/09 07:02:50 | 000,000,000 | ---D | M] -- C:\Users\Deb\AppData\Roaming\Ashampoo

[2011/11/14 13:03:49 | 000,000,000 | ---D | M] -- C:\Users\Deb\AppData\Roaming\BlitzCards

[2011/06/21 08:31:19 | 000,000,000 | ---D | M] -- C:\Users\Deb\AppData\Roaming\Byngo

[2011/06/27 14:30:19 | 000,000,000 | ---D | M] -- C:\Users\Deb\AppData\Roaming\calibre

[2011/11/19 09:21:55 | 000,000,000 | ---D | M] -- C:\Users\Deb\AppData\Roaming\chc.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1

[2011/10/28 05:57:48 | 000,000,000 | ---D | M] -- C:\Users\Deb\AppData\Roaming\Digiarty

[2010/12/17 12:55:31 | 000,000,000 | ---D | M] -- C:\Users\Deb\AppData\Roaming\DVDVideoSoft

[2011/03/28 05:24:17 | 000,000,000 | ---D | M] -- C:\Users\Deb\AppData\Roaming\Engelmann Media

[2011/02/02 14:12:43 | 000,000,000 | ---D | M] -- C:\Users\Deb\AppData\Roaming\FinalTorrent

[2013/01/19 19:48:35 | 000,000,000 | ---D | M] -- C:\Users\Deb\AppData\Roaming\FixBee

[2012/03/30 12:58:05 | 000,000,000 | ---D | M] -- C:\Users\Deb\AppData\Roaming\FreeBurner

[2011/02/01 19:03:46 | 000,000,000 | ---D | M] -- C:\Users\Deb\AppData\Roaming\gmt_free_avi_to_dvd

[2010/12/10 13:18:51 | 000,000,000 | ---D | M] -- C:\Users\Deb\AppData\Roaming\HiYo

[2010/12/11 20:29:08 | 000,000,000 | ---D | M] -- C:\Users\Deb\AppData\Roaming\ImageBadger

[2010/12/21 10:06:03 | 000,000,000 | ---D | M] -- C:\Users\Deb\AppData\Roaming\IncrediMail Collection Manager

[2011/04/23 05:54:59 | 000,000,000 | ---D | M] -- C:\Users\Deb\AppData\Roaming\IObit

[2010/12/15 10:02:00 | 000,000,000 | ---D | M] -- C:\Users\Deb\AppData\Roaming\Jasc

[2011/04/10 04:32:43 | 000,000,000 | ---D | M] -- C:\Users\Deb\AppData\Roaming\Leawo

[2011/12/25 05:54:56 | 000,000,000 | ---D | M] -- C:\Users\Deb\AppData\Roaming\LifeSniffer

[2011/04/03 05:29:09 | 000,000,000 | ---D | M] -- C:\Users\Deb\AppData\Roaming\mediAvatar

[2011/12/14 16:38:12 | 000,000,000 | ---D | M] -- C:\Users\Deb\AppData\Roaming\Mipony

[2011/02/18 17:55:10 | 000,000,000 | ---D | M] -- C:\Users\Deb\AppData\Roaming\Mobipocket

[2011/04/10 04:32:43 | 000,000,000 | ---D | M] -- C:\Users\Deb\AppData\Roaming\Moyea

[2011/12/03 06:19:44 | 000,000,000 | ---D | M] -- C:\Users\Deb\AppData\Roaming\Nik Software

[2012/10/12 05:02:38 | 000,000,000 | ---D | M] -- C:\Users\Deb\AppData\Roaming\Nuclear Coffee

[2012/04/08 06:07:10 | 000,000,000 | ---D | M] -- C:\Users\Deb\AppData\Roaming\PearlMountain

[2011/04/27 18:09:56 | 000,000,000 | ---D | M] -- C:\Users\Deb\AppData\Roaming\PearlMountainSoft

[2011/01/18 15:25:42 | 000,000,000 | ---D | M] -- C:\Users\Deb\AppData\Roaming\Pixpedia Publisher

[2012/10/12 14:11:08 | 000,000,000 | ---D | M] -- C:\Users\Deb\AppData\Roaming\PlayFirst

[2011/04/10 04:32:43 | 000,000,000 | ---D | M] -- C:\Users\Deb\AppData\Roaming\PPT2DVD

[2011/10/05 08:54:49 | 000,000,000 | ---D | M] -- C:\Users\Deb\AppData\Roaming\QuizResultsAnalyzer.E7BED6E5DDA59983786DD72EBFA46B1598278E07.1

[2012/08/20 09:46:30 | 000,000,000 | ---D | M] -- C:\Users\Deb\AppData\Roaming\SendSpace

[2011/06/14 07:04:49 | 000,000,000 | ---D | M] -- C:\Users\Deb\AppData\Roaming\Softplicity

[2011/11/12 22:18:28 | 000,000,000 | ---D | M] -- C:\Users\Deb\AppData\Roaming\Solveig Multimedia

[2012/05/30 10:37:07 | 000,000,000 | ---D | M] -- C:\Users\Deb\AppData\Roaming\Temp

[2010/12/28 12:10:38 | 000,000,000 | ---D | M] -- C:\Users\Deb\AppData\Roaming\Template

[2011/10/15 13:45:53 | 000,000,000 | ---D | M] -- C:\Users\Deb\AppData\Roaming\Thinstall

[2011/08/01 17:33:44 | 000,000,000 | ---D | M] -- C:\Users\Deb\AppData\Roaming\Tibo Software

[2011/04/06 14:52:04 | 000,000,000 | ---D | M] -- C:\Users\Deb\AppData\Roaming\Titanium Gears

[2012/06/06 06:39:18 | 000,000,000 | ---D | M] -- C:\Users\Deb\AppData\Roaming\Visan

[2011/04/20 06:00:25 | 000,000,000 | ---D | M] -- C:\Users\Deb\AppData\Roaming\visualsearchpony.com

[2010/12/19 11:56:10 | 000,000,000 | ---D | M] -- C:\Users\Deb\AppData\Roaming\Vso

[2010/12/10 13:55:37 | 000,000,000 | ---D | M] -- C:\Users\Deb\AppData\Roaming\WeatherBug

[2010/12/10 13:26:42 | 000,000,000 | ---D | M] -- C:\Users\Deb\AppData\Roaming\Windows Live Writer

[2012/01/30 08:02:39 | 000,000,000 | ---D | M] -- C:\Users\Deb\AppData\Roaming\XnView

 

========== Purity Check ==========

 

 

 

========== Alternate Data Streams ==========

 

@Alternate Data Stream - 127 bytes -> C:\ProgramData\TEMP:22741C1F

@Alternate Data Stream - 118 bytes -> C:\ProgramData\TEMP:A31FAD21

< End of report >

Posted

Malwarebytes Anti-Malware 1.70.0.1100

www.malwarebytes.org

Database version: v2013.02.01.05

Windows 7 Service Pack 1 x64 NTFS

Internet Explorer 8.0.7601.17514

Deb :: DEB-PC [administrator]

2/5/2013 12:19:41 PM

mbam-log-2013-02-05 (12-19-41).txt

Scan type: Quick scan

Scan options enabled: Memory | Startup | Registry | File System | Heuristics/Extra | Heuristics/Shuriken | PUP | PUM

Scan options disabled: P2P

Objects scanned: 224280

Time elapsed: 5 minute(s), 43 second(s)

Memory Processes Detected: 0

(No malicious items detected)

Memory Modules Detected: 0

(No malicious items detected)

Registry Keys Detected: 0

(No malicious items detected)

Registry Values Detected: 0

(No malicious items detected)

Registry Data Items Detected: 0

(No malicious items detected)

Folders Detected: 0

(No malicious items detected)

Files Detected: 0

(No malicious items detected)

(end)

Join the conversation

You can post now and register later. If you have an account, sign in now to post with your account.

Guest
Reply to this topic...

×   Pasted as rich text.   Paste as plain text instead

  Only 75 emoji are allowed.

×   Your link has been automatically embedded.   Display as a link instead

×   Your previous content has been restored.   Clear editor

×   You cannot paste images directly. Upload or insert images from URL.


×
×
  • Create New...