Jump to content


 


Register a free account to unlock additional features at BleepingComputer.com
Welcome to BleepingComputer, a free community where people like yourself come together to discuss and learn how to use their computers. Using the site is easy and fun. As a guest, you can browse and view the various discussions in the forums, but can not create a new topic or reply to an existing one unless you are logged in. Other benefits of registering an account are subscribing to topics and forums, creating a blog, and having no ads shown anywhere on the site.


Click here to Register a free account now! or read our Welcome Guide to learn how to use this site.

Photo

Infected with Total Security Rogue


  • This topic is locked This topic is locked
14 replies to this topic

#1 I_am_CanadianEh?

I_am_CanadianEh?

  • Members
  • 489 posts
  • OFFLINE
  •  
  • Gender:Male
  • Local time:07:38 PM

Posted 16 September 2009 - 10:19 PM

Well...it finally happened. :(

I arm myself with a solid firewall/antivirus/startup monitor and careful surfing habits. My darling wife wanted to see some trailer of a new movie coming out and she probably was asked to: "please download this codec or something" to see the trailer....BAD MOVE! :)

Got stung with the Total Security Rogue (TSC.exe)

The good news is that Zonealarm blocked a lot of it but some crap still came through.

Here's the history. I started out by logging into my account.

1) Malwarebyte's Initial Cleaning

- found a few files and cleaned them all

Malwarebytes' Anti-Malware 1.41
Database version: 2813
Windows 6.0.6002 Service Pack 2

9/16/2009 9:27:24 PM
mbam-log-2009-09-16 (21-27-24).txt

Scan type: Full Scan (C:\|D:\|)
Objects scanned: 215651
Time elapsed: 45 minute(s), 21 second(s)

Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 3
Registry Values Infected: 0
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 3

Memory Processes Infected:
(No malicious items detected)

Memory Modules Infected:
(No malicious items detected)

Registry Keys Infected:
HKEY_CLASSES_ROOT\CLSID\{35a5b43b-cb8a-49ca-a9f4-d3b308d2e3cc} (Trojan.FakeAlert) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{35a5b43b-cb8a-49ca-a9f4-d3b308d2e3cc} (Trojan.FakeAlert) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{35a5b43b-cb8a-49ca-a9f4-d3b308d2e3cc} (Trojan.FakeAlert) -> Quarantined and deleted successfully.

Registry Values Infected:
(No malicious items detected)

Registry Data Items Infected:
(No malicious items detected)

Folders Infected:
(No malicious items detected)

Files Infected:
C:\Windows\System32\iehelpmod.dll (Trojan.FakeAlert) -> Quarantined and deleted successfully.
C:\Users\elva\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\9D815BB4\Soft_71[1].exe (Rogue.Installer) -> Quarantined and deleted successfully.
C:\Users\elva\Desktop\Total Security.lnk (Rogue.TotalSecurity) -> Quarantined and deleted successfully.

It asked me to reboot which I did.

2) Second scan with Malwarebytes' turned up clean.

3) Rebooted into safe mode and scanned with SUPERAntispyware - had a few unrelated tracking cookies (which I always do) and cleaned those out. But no TSC files/registry items.

Then, I logged in to my wife's account. The fake Security centre came up as well as some icons in my system tray. Also, a Firewall alert came up asking me if I should allow TSC.exe to prevent MBAM from running a startup. I obviously blocked this. Zonealarm also blocked many things when TSC tried to make it's bed on my comp. Thus, I didn't have all the symptoms of this infection.

Ran Process Explorer and killed the TSC.exe task. The system tray icons went away.
Scanned with MBAM and it found 1 item.

Malwarebytes' Anti-Malware 1.41
Database version: 2813
Windows 6.0.6002 Service Pack 2

9/16/2009 10:08:11 PM
mbam-log-2009-09-16 (22-08-11).txt

Scan type: Quick Scan
Objects scanned: 107816
Time elapsed: 4 minute(s), 21 second(s)

Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 1
Registry Values Infected: 0
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 0

Memory Processes Infected:
(No malicious items detected)

Memory Modules Infected:
(No malicious items detected)

Registry Keys Infected:
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{35a5b43b-cb8a-49ca-a9f4-d3b308d2e3cc} (Trojan.FakeAlert) -> Quarantined and deleted successfully.

Registry Values Infected:
(No malicious items detected)

Registry Data Items Infected:
(No malicious items detected)

Folders Infected:
(No malicious items detected)

Files Infected:
(No malicious items detected)

Then, scanned with Windows Defender...found nothing.

Deleted a scheduled TSC task listed in WinPatrol.
Deleted the TS folder on C:\Program Folders and the contained TSC.exe file.
Deleted the TS folder in the Start Menu.

Finally, I realized that my System Restore was disabled by Group Policy...yeah, right! Found instructions on the web to re-enable using a registry tweak to delete some keys in the HKLM\Policies\Microsoft\Windows NT\SystemRestore location.

Below is my DDS log and my RootRepeal log. Please give it a look over to see if I'm all clean.

Thanks a bunch! :(

DDS.TXT


DDS (Ver_09-07-30.01) - NTFSx86
Run by elva at 22:42:24.27 on Wed 09/16/2009
Internet Explorer: 8.0.6001.18813 BrowserJavaVersion: 1.6.0_16
Microsoft® Windows Vista™ Home Premium 6.0.6002.2.1252.1.1033.18.3069.2039 [GMT -4:00]

SP: ZoneAlarm Pro Anti-Spyware *disabled* (Updated) {F245A209-1085-48B4-B927-35D56015EC60}
SP: Windows Defender *disabled* (Updated) {D68DDC3A-831F-4FAE-9E44-DA132C1ACF46}
SP: SUPERAntiSpyware *disabled* (Updated) {222A897C-5018-402e-943F-7E7AC8560DA7}
FW: ZoneAlarm Pro Firewall *enabled* {829BDA32-94B3-44F4-8446-F8FCFF809F8B}

============== Running Processes ===============

C:\Windows\system32\wininit.exe
C:\Windows\system32\lsm.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\svchost.exe -k rpcss
C:\Windows\system32\Ati2evxx.exe
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\system32\svchost.exe -k GPSvcGroup
C:\Windows\system32\SLsvc.exe
C:\Windows\system32\svchost.exe -k LocalService
C:\Windows\system32\svchost.exe -k NetworkService
C:\Windows\System32\ZoneLabs\vsmon.exe
C:\Windows\system32\Ati2evxx.exe
C:\Windows\System32\spoolsv.exe
C:\Program Files\Avira\AntiVir Desktop\sched.exe
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
C:\Windows\system32\Dwm.exe
C:\Windows\system32\taskeng.exe
C:\Program Files\Common Files\Acronis\Schedule2\schedul2.exe
C:\Program Files\Avira\AntiVir Desktop\avguard.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Microsoft Small Business\Business Contact Manager\BcmSqlStartupSvc.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Program Files\Diskeeper Corporation\Diskeeper\DkService.exe
C:\Windows\system32\svchost.exe -k hpdevmgmt
C:\Program Files\Intel\Intel Matrix Storage Manager\Iaantmon.exe
C:\Windows\System32\svchost.exe -k HPZ12
C:\Program Files\CDBurnerXP\NMSAccessU.exe
C:\Windows\System32\svchost.exe -k HPZ12
C:\Windows\Explorer.EXE
C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted
c:\Program Files\Microsoft SQL Server\90\Shared\sqlbrowser.exe
c:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe
C:\Windows\system32\svchost.exe -k imgsvc
C:\Program Files\TomTom HOME 2\TomTomHOMEService.exe
C:\Windows\System32\svchost.exe -k WerSvcGroup
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
C:\Windows\system32\SearchIndexer.exe
C:\Windows\system32\WUDFHost.exe
C:\Program Files\HP\HP Software Update\hpwuSchd2.exe
C:\Program Files\NoteBurner\VTBurnerGUI.exe
C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
C:\Program Files\BillP Studios\WinPatrol\WinPatrol.exe
C:\Program Files\Acronis\TrueImageHome\TrueImageMonitor.exe
C:\Program Files\Acronis\TrueImageHome\TimounterMonitor.exe
C:\Program Files\Common Files\Acronis\Schedule2\schedhlp.exe
C:\Windows\sttray.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Avira\AntiVir Desktop\avgnt.exe
C:\Program Files\Java\jre6\bin\jusched.exe
C:\Program Files\Avira\AntiVir Desktop\avmailc.exe
C:\Program Files\Avira\AntiVir Desktop\AVWEBGRD.EXE
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe
C:\Windows\system32\taskeng.exe
C:\Windows\System32\mobsync.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\Windows Media Player\wmpnscfg.exe
C:\Program Files\Windows Media Player\wmpnetwk.exe
C:\Windows\system32\vssvc.exe
C:\Windows\System32\svchost.exe -k swprv
C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE
C:\Windows\system32\SearchFilterHost.exe
C:\Windows\system32\SearchProtocolHost.exe
C:\Users\elva\Desktop\dds.scr
C:\Windows\system32\wbem\wmiprvse.exe

============== Pseudo HJT Report ===============

uStart Page = hxxp://login.live.com/login.srf?id=2&svc=mail&cbid=24325&msppjph=1&tw=900&fs=1&lc=1033&_lang=EN
BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelperShim.dll
BHO: Google Toolbar Helper: {aa58ed58-01dd-4d91-8333-cf10577473f7} - c:\program files\google\google toolbar\GoogleToolbar_32.dll
BHO: Google Toolbar Notifier BHO: {af69de43-7d58-4638-b6fa-ce66b5ad205d} - c:\program files\google\googletoolbarnotifier\5.2.4204.1700\swg.dll
BHO: Google Dictionary Compression sdch: {c84d72fe-e17d-4195-bb24-76c02e2e7c4e} - c:\program files\google\google toolbar\component\fastsearch_B7C5AC242193BB3E.dll
BHO: Java™ Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll
BHO: Cooliris Plug-In for Internet Explorer: {eaee5c74-6d0d-4aca-9232-0da4a7b866ba} - c:\program files\piclensie\cooliris.dll
TB: Google Toolbar: {2318c2b1-4965-11d4-9b18-009027a5cd4f} - c:\program files\google\google toolbar\GoogleToolbar_32.dll
uRun: [swg] "c:\program files\google\googletoolbarnotifier\GoogleToolbarNotifier.exe"
mRun: [HP Software Update] c:\program files\hp\hp software update\HPWuSchd2.exe
mRun: [NoteBurner] c:\program files\noteburner\VTBurnerGUI.exe /silence
mRun: [ZoneAlarm Client] "c:\program files\zone labs\zonealarm\zlclient.exe"
mRun: [WinPatrol] c:\program files\billp studios\winpatrol\winpatrol.exe -expressboot
mRun: [TrueImageMonitor.exe] c:\program files\acronis\trueimagehome\TrueImageMonitor.exe
mRun: [AcronisTimounterMonitor] c:\program files\acronis\trueimagehome\TimounterMonitor.exe
mRun: [Acronis Scheduler2 Service] "c:\program files\common files\acronis\schedule2\schedhlp.exe"
mRun: [SigmatelSysTrayApp] sttray.exe
mRun: [Google Quick Search Box] "c:\program files\google\quick search box\GoogleQuickSearchBox.exe" /autorun
mRun: [iTunesHelper] "c:\program files\itunes\iTunesHelper.exe"
mRun: [avgnt] "c:\program files\avira\antivir desktop\avgnt.exe" /min -nosplash
mRun: [SunJavaUpdateSched] "c:\program files\java\jre6\bin\jusched.exe"
mRun: [Malwarebytes Anti-Malware (reboot)] "c:\program files\malwarebytes' anti-malware\mbam.exe" /runcleanupscript
mPolicies-explorer: BindDirectlyToPropertySetStorage = 0 (0x0)
mPolicies-system: EnableLUA = 0 (0x0)
mPolicies-system: EnableUIADesktopToggle = 0 (0x0)
IE: E&xport to Microsoft Excel - c:\progra~1\micros~2\office12\EXCEL.EXE/3000
IE: {3437D640-C91A-458f-89F5-B9095EA4C28B} - {04F93351-81D2-4484-9982-0D55DEFFFAE6} - c:\program files\piclensie\cooliris.dll
IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~1\micros~2\office12\REFIEBAR.DLL
LSP: c:\program files\avira\antivir desktop\avsda.dll
DPF: {166B1BCA-3F9C-11CF-8075-444553540000} - hxxp://download.macromedia.com/pub/shockwave/cabs/director/sw.cab
DPF: {233C1507-6A77-46A4-9443-F871F945D258} - hxxp://download.macromedia.com/pub/shockwave/cabs/director/sw.cab
DPF: {49312E18-AA92-4CC2-BB97-55DEA7BCADD6} - hxxp://support.dell.com/systemprofiler/SysProExe.CAB
DPF: {7530BFB8-7293-4D34-9923-61A11451AFC5} - hxxp://download.eset.com/special/eos/OnlineScanner.cab
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_16-windows-i586.cab
DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} - hxxp://fpdownload.macromedia.com/get/flashplayer/current/polarbear/ultrashim.cab
DPF: {CAFEEFAC-0016-0000-0016-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_16-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_16-windows-i586.cab
DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} - hxxp://fpdownload2.macromedia.com/get/flashplayer/current/swflash.cab
DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - hxxp://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
Handler: belarc - {6318E0AB-2E93-11D1-B8ED-00608CC9A71F} - c:\program files\belarc\advisor\system\BAVoilaX.dll
Notify: !SASWinLogon - c:\program files\superantispyware\SASWINLO.DLL
SEH: SABShellExecuteHook Class: {5ae067d3-9afb-48e0-853a-ebb7f4a000da} - c:\program files\superantispyware\SASSEH.DLL

================= FIREFOX ===================

FF - ProfilePath - c:\users\elva\appdata\roaming\mozilla\firefox\profiles\udd33exj.default\
FF - prefs.js: browser.search.defaulturl - hxxp://www.google.com/search?lr=&ie=UTF-8&oe=UTF-8&q=
FF - prefs.js: browser.search.selectedEngine - Google
FF - prefs.js: browser.startup.homepage - hxxp://login.live.com/login.srf?id=2&svc=mail&cbid=24325&msppjph=1&tw=900&fs=1&lc=1033&_lang=EN
FF - component: c:\users\elva\appdata\roaming\mozilla\firefox\profiles\udd33exj.default\extensions\piclens@cooliris.com\components\coolirisstub.dll
FF - plugin: c:\program files\microsoft\office live\npOLW.dll
FF - plugin: c:\users\elva\appdata\roaming\mozilla\firefox\profiles\udd33exj.default\extensions\piclens@cooliris.com\plugins\npcoolirisplugin.dll
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\microsoft.net\framework\v3.5\windows presentation foundation\dotnetassistantextension\
FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0016-ABCDEFFEDCBA}

---- FIREFOX POLICIES ----
c:\program files\mozilla firefox\greprefs\all.js - pref("media.enforce_same_site_origin", false);
c:\program files\mozilla firefox\greprefs\all.js - pref("media.cache_size", 51200);
c:\program files\mozilla firefox\greprefs\all.js - pref("media.ogg.enabled", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("media.wave.enabled", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("media.autoplay.enabled", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("browser.urlbar.autocomplete.enabled", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("capability.policy.mailnews.*.wholeText", "noAccess");
c:\program files\mozilla firefox\greprefs\all.js - pref("dom.storage.default_quota", 5120);
c:\program files\mozilla firefox\greprefs\all.js - pref("content.sink.event_probe_rate", 3);
c:\program files\mozilla firefox\greprefs\all.js - pref("network.http.prompt-temp-redirect", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("layout.css.dpi", -1);
c:\program files\mozilla firefox\greprefs\all.js - pref("layout.css.devPixelsPerPx", -1);
c:\program files\mozilla firefox\greprefs\all.js - pref("gestures.enable_single_finger_input", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("dom.max_chrome_script_run_time", 0);
c:\program files\mozilla firefox\greprefs\all.js - pref("network.tcp.sendbuffer", 131072);
c:\program files\mozilla firefox\greprefs\all.js - pref("geo.enabled", true);
c:\program files\mozilla firefox\greprefs\security-prefs.js - pref("security.remember_cert_checkbox_default_setting", true);
c:\program files\mozilla firefox\defaults\pref\firefox-branding.js - pref("browser.search.param.yahoo-fr", "moz35");
c:\program files\mozilla firefox\defaults\pref\firefox-branding.js - pref("browser.search.param.yahoo-fr-cjkt", "moz35");
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("extensions.blocklist.level", 2);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.urlbar.restrict.typed", "~");
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.urlbar.default.behavior", 0);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.history", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.formdata", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.passwords", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.downloads", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.cookies", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.cache", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.sessions", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.offlineApps", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.siteSettings", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.history", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.formdata", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.passwords", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.downloads", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.cookies", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.cache", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.sessions", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.offlineApps", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.siteSettings", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.sanitize.migrateFx3Prefs", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.ssl_override_behavior", 2);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("security.alternate_certificate_error_page", "certerror");
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.privatebrowsing.autostart", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.privatebrowsing.dont_prompt_on_enter", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("geo.wifi.uri", "https://www.google.com/loc/json");

============= SERVICES / DRIVERS ===============

R0 ntcdrdrv;ntcdrdrv;c:\windows\system32\drivers\ntcdrdrv.sys [2009-6-19 13440]
R0 snapman380;Acronis Snapshots Manager (Build 380);c:\windows\system32\drivers\snman380.sys [2009-6-20 134272]
R0 tdrpman174;Acronis Try&Decide and Restore Points filter (build 174);c:\windows\system32\drivers\tdrpm174.sys [2009-6-20 971552]
R1 SASDIFSV;SASDIFSV;c:\program files\superantispyware\sasdifsv.sys [2009-5-26 9968]
R1 SASKUTIL;SASKUTIL;c:\program files\superantispyware\SASKUTIL.SYS [2009-5-26 74480]
R2 AntiVirMailService;Avira AntiVir MailGuard;c:\program files\avira\antivir desktop\avmailc.exe [2009-8-6 194817]
R2 AntiVirSchedulerService;Avira AntiVir Scheduler;c:\program files\avira\antivir desktop\sched.exe [2009-8-6 108289]
R2 AntiVirWebService;Avira AntiVir WebGuard;c:\program files\avira\antivir desktop\avwebgrd.exe [2009-8-6 434945]
R2 BcmSqlStartupSvc;Business Contact Manager SQL Server Startup Service;c:\program files\microsoft small business\business contact manager\BcmSqlStartupSvc.exe [2008-1-11 30312]
R2 TomTomHOMEService;TomTomHOMEService;c:\program files\tomtom home 2\TomTomHOMEService.exe [2009-8-27 92008]
R2 wlidsvc;Windows Live ID Sign-in Assistant;c:\program files\common files\microsoft shared\windows live\WLIDSVC.EXE [2009-3-30 1533808]
R3 VST_DPV;VST_DPV;c:\windows\system32\drivers\VSTDPV3.SYS [2006-11-2 987648]
R3 VSTHWBS2;VSTHWBS2;c:\windows\system32\drivers\VSTBS23.SYS [2006-11-2 251904]
S2 AcronisOSSReinstallSvc;Acronis OS Selector Reinstall Service;c:\program files\common files\acronis\acronis disk director\oss_reinstall_svc.exe [2007-2-22 2217416]
S3 MSSQL$MSSMLBIZ;SQL Server (MSSMLBIZ);c:\program files\microsoft sql server\mssql.1\mssql\binn\sqlservr.exe [2008-11-24 29263712]
S3 PSI;PSI;c:\windows\system32\drivers\psi_mf.sys [2009-6-17 12648]
S3 SASENUM;SASENUM;c:\program files\superantispyware\SASENUM.SYS [2009-5-26 7408]

============== File Associations ===============

regfile\shell\edit\command=%SystemRoot%\system32\notepad.exe "%1"

=============== Created Last 30 ================

2009-09-16 09:43 <DIR> --d----- c:\program files\common files\TSUninstall
2009-09-08 21:22 302,592 a------- c:\windows\system32\wlansec.dll
2009-09-08 21:22 293,376 a------- c:\windows\system32\wlanmsm.dll
2009-09-08 21:22 127,488 a------- c:\windows\system32\L2SecHC.dll
2009-09-08 21:22 2,501,921 a------- c:\windows\system32\wlan.tmf
2009-09-08 21:22 513,536 a------- c:\windows\system32\wlansvc.dll
2009-09-08 21:22 65,024 a------- c:\windows\system32\wlanapi.dll
2009-09-01 21:17 28,672 a------- c:\windows\system32\Apphlpdm.dll
2009-09-01 21:17 4,240,384 a------- c:\windows\system32\GameUXLegacyGDFs.dll
2009-08-26 08:45 2,048 a------- c:\windows\system32\tzres.dll
2009-08-21 20:40 <DIR> --d----- c:\users\elva\appdata\roaming\HpUpdate
2009-08-19 10:05 <DIR> --d----- c:\programdata\Canneverbe Limited
2009-08-19 10:05 <DIR> --d----- c:\progra~2\Canneverbe Limited

==================== Find3M ====================

2009-09-16 22:00 414,243 a---h--- c:\windows\system32\drivers\vsconfig.xml
2009-09-10 14:54 38,224 a------- c:\windows\system32\drivers\mbamswissarmy.sys
2009-09-10 14:53 19,160 a------- c:\windows\system32\drivers\mbam.sys
2009-08-28 22:30 173,056 a------- c:\windows\apppatch\AcXtrnal.dll
2009-08-28 22:30 458,752 a------- c:\windows\apppatch\AcSpecfc.dll
2009-08-28 22:30 2,159,616 a------- c:\windows\apppatch\AcGenral.dll
2009-08-28 22:30 542,720 a------- c:\windows\apppatch\AcLayers.dll
2009-08-14 12:27 904,776 a------- c:\windows\system32\drivers\tcpip.sys
2009-08-14 11:53 17,920 a------- c:\windows\system32\netevent.dll
2009-08-14 09:49 9,728 a------- c:\windows\system32\TCPSVCS.EXE
2009-08-14 09:49 17,920 a------- c:\windows\system32\ROUTE.EXE
2009-08-14 09:49 11,264 a------- c:\windows\system32\MRINFO.EXE
2009-08-14 09:49 27,136 a------- c:\windows\system32\NETSTAT.EXE
2009-08-14 09:49 19,968 a------- c:\windows\system32\ARP.EXE
2009-08-14 09:49 8,704 a------- c:\windows\system32\HOSTNAME.EXE
2009-08-14 09:49 10,240 a------- c:\windows\system32\finger.exe
2009-08-14 09:48 30,720 a------- c:\windows\system32\drivers\tcpipreg.sys
2009-08-14 09:48 105,984 a------- c:\windows\system32\netiohlp.dll
2009-08-11 22:32 411,368 a------- c:\windows\system32\deploytk.dll
2009-08-06 22:56 55,656 a------- c:\windows\system32\drivers\avgntflt.sys
2009-07-30 15:24 24,128,512 a------- c:\windows\system32\imageres.dll
2009-07-21 17:52 915,456 a------- c:\windows\system32\wininet.dll
2009-07-21 17:47 109,056 a------- c:\windows\system32\iesysprep.dll
2009-07-21 17:47 71,680 a------- c:\windows\system32\iesetup.dll
2009-07-21 16:13 133,632 a------- c:\windows\system32\ieUnatt.exe
2009-07-17 09:54 71,680 a------- c:\windows\system32\atl.dll
2009-07-15 08:40 8,147,456 a------- c:\windows\system32\wmploc.DLL
2009-07-15 08:39 313,344 a------- c:\windows\system32\wmpdxm.dll
2009-07-15 08:39 4,096 a------- c:\windows\system32\dxmasf.dll
2009-07-15 08:39 7,680 a------- c:\windows\system32\spwmp.dll
2009-07-07 12:20 3,076 a------- c:\windows\system32\tmp.reg
2009-06-22 16:55 413,696 a------- c:\windows\system32\wrap_oal.dll
2009-06-22 16:55 110,592 a------- c:\windows\system32\OpenAL32.dll
2009-06-20 22:41 143,360 a------- c:\windows\inf\infstrng.dat
2009-06-20 22:41 86,016 a------- c:\windows\inf\infstor.dat
2009-06-20 22:41 51,200 a------- c:\windows\inf\infpub.dat
2009-06-20 22:37 665,600 a------- c:\windows\inf\drvindex.dat
2009-06-19 21:38 174 a--sh--- c:\program files\desktop.ini
2009-06-19 21:24 101,888 a------- c:\windows\system32\ifxcardm.dll
2009-06-19 21:24 82,432 a------- c:\windows\system32\axaltocm.dll
2009-06-19 12:13 272,896 a------- c:\windows\system32\polstore.dll
2009-06-19 12:13 61,440 a------- c:\windows\system32\winipsec.dll
2009-06-19 11:29 2,034,688 a------- c:\windows\system32\win32k.sys
2009-06-19 11:21 52,736 a------- c:\windows\apppatch\iebrshim.dll
2009-06-19 11:20 2,048 a------- c:\windows\system32\msxml3r.dll
2009-06-19 11:13 623,616 a------- c:\windows\system32\localspl.dll
2009-06-19 11:04 6,656 a------- c:\windows\system32\kbd106n.dll
2009-06-19 10:58 37,888 a------- c:\windows\system32\printcom.dll
2009-06-19 10:58 14,848 a------- c:\windows\system32\wshrm.dll
2009-06-19 10:54 84,480 a------- c:\windows\system32\INETRES.dll
2009-06-19 10:53 784,896 a------- c:\windows\system32\rpcrt4.dll
2009-06-19 10:49 2,048 a------- c:\windows\system32\msxml6r.dll
2009-06-19 10:26 1,524,736 a------- c:\windows\system32\wucltux.dll
2009-06-19 10:26 83,456 a------- c:\windows\system32\wudriver.dll
2009-06-19 10:26 162,064 a------- c:\windows\system32\wuwebv.dll
2009-06-19 10:26 31,232 a------- c:\windows\system32\wuapp.exe
2009-06-19 10:15 116,842 a------- c:\windows\hpqins00.dat
2009-06-19 10:06 149,022 a------- c:\windows\hpoins19.dat
2006-11-02 08:42 287,440 a------- c:\windows\inf\perflib\0409\perfi.dat
2006-11-02 08:42 287,440 a------- c:\windows\inf\perflib\0409\perfh.dat
2006-11-02 08:42 30,674 a------- c:\windows\inf\perflib\0409\perfd.dat
2006-11-02 08:42 30,674 a------- c:\windows\inf\perflib\0409\perfc.dat
2006-11-02 05:20 287,440 a------- c:\windows\inf\perflib\0000\perfi.dat
2006-11-02 05:20 287,440 a------- c:\windows\inf\perflib\0000\perfh.dat
2006-11-02 05:20 30,674 a------- c:\windows\inf\perflib\0000\perfd.dat
2006-11-02 05:20 30,674 a------- c:\windows\inf\perflib\0000\perfc.dat

============= FINISH: 22:43:10.03 ===============

ROOTREPEAL LOG.

ROOTREPEAL © AD, 2007-2009
==================================================
Scan Start Time: 2009/09/16 22:44
Program Version: Version 1.3.5.0
Windows Version: Windows Vista SP2
==================================================

Drivers
-------------------
Name: dump_iaStor.sys
Image Path: C:\Windows\System32\Drivers\dump_iaStor.sys
Address: 0x8DC00000 Size: 819200 File Visible: No Signed: -
Status: -

Name: PROCEXP113.SYS
Image Path: C:\Windows\system32\Drivers\PROCEXP113.SYS
Address: 0x9B1DD000 Size: 9728 File Visible: No Signed: -
Status: -

Name: rootrepeal.sys
Image Path: C:\Windows\system32\drivers\rootrepeal.sys
Address: 0x9B1E8000 Size: 49152 File Visible: No Signed: -
Status: -

Hidden/Locked Files
-------------------
Path: C:\Windows\Internet Logs\BACKUP.RDB
Status: Could not get file information (Error 0xc0000008)

Path: c:\windows\internet logs\fwpktlog.txt
Status: Allocation size mismatch (API: 16384, Raw: 4096)

Path: C:\Windows\winsxs\Catalogs\x86_policy.8.0.microsoft.vc80.crt_1fc8b3b9a1e18e3b_8.0.50727.762_none_9193a620671dde41.cat
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\Catalogs\x86_policy.8.0.microsoft.vc80.mfcloc_1fc8b3b9a1e18e3b_8.0.50727.42_none_58843c41d2730d3f.cat
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\Catalogs\x86_policy.8.0.microsoft.vc80.atl_1fc8b3b9a1e18e3b_8.0.50727.4053_none_4ddfc6cd11929a02.cat
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\Catalogs\x86_microsoft.vc80.atl_1fc8b3b9a1e18e3b_8.0.50727.762_none_11ecb0ab9b2caf3c.cat
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\Catalogs\x86_policy.9.0.microsoft.vc90.mfcloc_1fc8b3b9a1e18e3b_9.0.30729.1_none_818f59bf601aa775.cat
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\Catalogs\x86_policy.9.0.microsoft.vc90.openmp_1fc8b3b9a1e18e3b_9.0.21022.8_none_7ab8cc63a6e4c2a3.cat
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\Catalogs\x86_microsoft.vc90.mfc_1fc8b3b9a1e18e3b_9.0.30729.1_none_dcc7eae99ad0d9cf.cat
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\Catalogs\x86_microsoft.vc80.crt_1fc8b3b9a1e18e3b_8.0.50727.762_none_10b2f55f9bffb8f8.cat
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\Catalogs\x86_microsoft.vc80.atl_1fc8b3b9a1e18e3b_8.0.50727.42_none_dc990e4797f81af1.cat
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\Catalogs\x86_microsoft.vc80.debugcrt_1fc8b3b9a1e18e3b_8.0.50727.42_none_ef74ff32550b5bf0.cat
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\Catalogs\x86_policy.8.0.microsoft.vc80.mfcloc_1fc8b3b9a1e18e3b_8.0.50727.91_none_588445e3d272feb1.cat
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\Catalogs\x86_policy.8.0.microsoft.vc80.openmp_1fc8b3b9a1e18e3b_8.0.50727.42_none_7658964504b9f3b6.cat
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\Catalogs\x86_policy.8.0.microsoft.vc80.crt_1fc8b3b9a1e18e3b_8.0.50727.91_none_5c400d5e63e93b68.cat
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\Catalogs\x86_policy.4.20.microsoft.msxml2_6bd6b9abf345378f_4.20.9870.0_none_a6dea5dc0ea08098.cat
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\Catalogs\x86_microsoft.vc80.mfcloc_1fc8b3b9a1e18e3b_8.0.50727.762_none_43efccf17831d131.cat
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\Catalogs\x86_policy.9.0.microsoft.vc90.atl_1fc8b3b9a1e18e3b_9.0.30729.4148_none_f0efb442f8a0f46c.cat
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\Catalogs\x86_policy.9.0.microsoft.vc90.atl_1fc8b3b9a1e18e3b_9.0.30729.1_none_81c25f21d3d46d84.cat
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\Catalogs\x86_policy.8.0.microsoft.vc80.debugmfc_1fc8b3b9a1e18e3b_8.0.50727.42_none_3389d53e5a2d10c0.cat
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\Catalogs\x86_policy.8.0.microsoft.vc80.crt_1fc8b3b9a1e18e3b_8.0.50727.42_none_5c4003bc63e949f6.cat
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\Catalogs\x86_microsoft.vc80.atl_1fc8b3b9a1e18e3b_8.0.50727.4053_none_d1c738ec43578ea1.cat
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\Catalogs\x86_microsoft.vc80.mfcloc_1fc8b3b9a1e18e3b_8.0.50727.42_none_0e9c2a8d74fd3ce6.cat
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\Catalogs\x86_microsoft.vc90.mfcloc_1fc8b3b9a1e18e3b_9.0.30729.1_none_da4695fc507e16e1.cat
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\Catalogs\x86_microsoft.vc90.openmp_1fc8b3b9a1e18e3b_9.0.21022.8_none_ecdf8c290e547f39.cat
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\Catalogs\x86_policy.9.0.microsoft.vc90.crt_1fc8b3b9a1e18e3b_9.0.30729.1_none_8550c6b5d18a9128.cat
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\Catalogs\amd64_policy.8.0.microsoft.vc80.crt_1fc8b3b9a1e18e3b_8.0.50727.762_none_49e66f4952a1b53b.cat
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\Catalogs\x86_microsoft.vc80.openmp_1fc8b3b9a1e18e3b_8.0.50727.42_none_45e008191e507087.cat
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\Catalogs\x86_microsoft.vc90.atl_1fc8b3b9a1e18e3b_9.0.30729.1_none_e29d1181971ae11e.cat
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\Catalogs\x86_microsoft.vc80.mfc_1fc8b3b9a1e18e3b_8.0.50727.42_none_d6c3e7af9bae13a2.cat
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\Catalogs\x86_policy.9.0.microsoft.vc90.mfc_1fc8b3b9a1e18e3b_9.0.30729.1_none_7dd1e0ebd6590e0b.cat
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\Catalogs\x86_microsoft.vc90.atl_1fc8b3b9a1e18e3b_9.0.30729.4148_none_51ca66a2bbe76806.cat
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\Catalogs\x86_policy.9.0.microsoft.vc90.crt_1fc8b3b9a1e18e3b_9.0.21022.8_none_60a5df56e60dc5df.cat
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\Catalogs\x86_microsoft.vc90.crt_1fc8b3b9a1e18e3b_9.0.30729.1_none_e163563597edeada.cat
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\Catalogs\x86_microsoft.vc80.crt_1fc8b3b9a1e18e3b_8.0.50727.91_none_db5f5c9d98cb161f.cat
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\Catalogs\x86_policy.8.0.microsoft.vc80.atl_1fc8b3b9a1e18e3b_8.0.50727.762_none_8e053e8c6967ba9d.cat
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\Catalogs\x86_microsoft.vc90.crt_1fc8b3b9a1e18e3b_9.0.21022.8_none_bcb86ed6ac711f91.cat
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\Catalogs\x86_policy.8.0.microsoft.vc80.mfc_1fc8b3b9a1e18e3b_8.0.50727.42_none_54c11df268b7c6d9.cat
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\Catalogs\x86_policy.8.0.microsoft.vc80.mfcloc_1fc8b3b9a1e18e3b_8.0.50727.762_none_8dd7dea5d5a7a18a.cat
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\Catalogs\x86_policy.8.0.microsoft.vc80.mfc_1fc8b3b9a1e18e3b_8.0.50727.762_none_8a14c0566bec5b24.cat
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\Catalogs\x86_microsoft.vc80.crt_1fc8b3b9a1e18e3b_8.0.50727.42_none_db5f52fb98cb24ad.cat
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\Catalogs\x86_microsoft.msxml2r_6bd6b9abf345378f_4.1.0.0_none_3658456fda6654f6.cat
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\Catalogs\x86_policy.8.0.microsoft.vc80.debugcrt_1fc8b3b9a1e18e3b_8.0.50727.42_none_3825408a574a21cb.cat
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\Catalogs\x86_policy.8.0.microsoft.vc80.mfc_1fc8b3b9a1e18e3b_8.0.50727.91_none_54c1279468b7b84b.cat
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\Catalogs\x86_microsoft.vc80.mfcloc_1fc8b3b9a1e18e3b_8.0.50727.91_none_0e9c342f74fd2e58.cat
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\Catalogs\x86_microsoft.vc80.atl_1fc8b3b9a1e18e3b_8.0.50727.91_none_dc9917e997f80c63.cat
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\Catalogs\x86_microsoft.vc80.mfc_1fc8b3b9a1e18e3b_8.0.50727.762_none_0c178a139ee2a7ed.cat
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\Catalogs\x86_microsoft.msxml2_6bd6b9abf345378f_4.1.0.0_none_6c030d6fdc86522c.cat
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\Catalogs\x86_microsoft.msxml2r_6bd6b9abf345378f_4.1.1.0_none_365945b9da656e4d.cat
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\Catalogs\x86_policy.8.0.microsoft.vc80.atl_1fc8b3b9a1e18e3b_8.0.50727.91_none_58b1a5ca663317c4.cat
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\Catalogs\x86_policy.4.1.microsoft.msxml2r_6bd6b9abf345378f_4.1.1.0_none_8b7b15c031cda6db.cat
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\Catalogs\x86_microsoft.vc80.mfc_1fc8b3b9a1e18e3b_8.0.50727.91_none_d6c3f1519bae0514.cat
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\Catalogs\x86_microsoft.msxml2_6bd6b9abf345378f_4.20.9870.0_none_b7e00e6c7b30b69b.cat
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\Catalogs\x86_microsoft.vc80.debugmfc_1fc8b3b9a1e18e3b_8.0.50727.42_none_f455012451df8b23.cat
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\Catalogs\x86_policy.8.0.microsoft.vc80.atl_1fc8b3b9a1e18e3b_8.0.50727.42_none_58b19c2866332652.cat
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\Catalogs\amd64_microsoft.vc80.crt_1fc8b3b9a1e18e3b_8.0.50727.762_none_c905be8887838ff2.cat
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\x86_microsoft-windows-d..pwindowmanager-core_31bf3856ad364e35_6.0.6002.18005_none_8f8f0d20ba53c683\MICROS~1.XRM
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\x86_microsoft-windows-ie-internetexplorer_31bf3856ad364e35_6.0.6001.18000_none_2f62000919fe80c9\WINDOW~1.WAV
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\x86_microsoft-windows-ie-internetexplorer_31bf3856ad364e35_6.0.6001.18000_none_2f62000919fe80c9\WINDOW~4.WAV
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\x86_microsoft-windows-ie-internetexplorer_31bf3856ad364e35_6.0.6001.18000_none_2f62000919fe80c9\WINDOW~3.WAV
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\x86_microsoft-windows-ie-internetexplorer_31bf3856ad364e35_6.0.6002.18005_none_314d791517204c15\WINDOW~1.WAV
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\x86_microsoft-windows-ie-internetexplorer_31bf3856ad364e35_6.0.6002.18005_none_314d791517204c15\WINDOW~4.WAV
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\x86_microsoft-windows-ie-internetexplorer_31bf3856ad364e35_6.0.6002.18005_none_314d791517204c15\WINDOW~3.WAV
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\x86_microsoft-windows-ie-internetexplorer_31bf3856ad364e35_8.0.6001.18702_none_124d22632fc9f126\WINDOW~1.WAV
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\x86_microsoft-windows-ie-internetexplorer_31bf3856ad364e35_8.0.6001.18702_none_124d22632fc9f126\WINDOW~4.WAV
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\x86_microsoft-windows-ie-internetexplorer_31bf3856ad364e35_8.0.6001.18702_none_124d22632fc9f126\WINDOW~3.WAV
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\x86_microsoft-windows-ie-internetexplorer_31bf3856ad364e35_8.0.6001.18813_none_124354a72fd12395\WINDOW~1.WAV
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\x86_microsoft-windows-ie-internetexplorer_31bf3856ad364e35_8.0.6001.18813_none_124354a72fd12395\WINDOW~4.WAV
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\x86_microsoft-windows-ie-internetexplorer_31bf3856ad364e35_8.0.6001.18813_none_124354a72fd12395\WINDOW~3.WAV
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\x86_microsoft-windows-ie-internetexplorer_31bf3856ad364e35_8.0.6001.22903_none_12d7c15e48e6a76e\WINDOW~1.WAV
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\x86_microsoft-windows-ie-internetexplorer_31bf3856ad364e35_8.0.6001.22903_none_12d7c15e48e6a76e\WINDOW~4.WAV
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\x86_microsoft-windows-ie-internetexplorer_31bf3856ad364e35_8.0.6001.22903_none_12d7c15e48e6a76e\WINDOW~3.WAV
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\x86_microsoft-windows-slc-component-sku-ocur_31bf3856ad364e35_6.0.6002.18005_none_1a3913896b7e0bf6\SECURI~3.XRM
Status: Locked to the Windows API!

Path: c:\windows\winsxs\x86_microsoft-windows-slc-component-sku-ocur_31bf3856ad364e35_6.0.6002.18005_none_1a3913896b7e0bf6\security-licensing-slc-component-sku-ocur-ppdlic.xrm-ms
Status: Allocation size mismatch (API: 16384, Raw: 4096)

Path: C:\Windows\winsxs\x86_microsoft-windows-slc-component-sku-ocur_31bf3856ad364e35_6.0.6002.18005_none_1a3913896b7e0bf6\SECURI~2.XRM
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\x86_netfx-aspnet_mof_b03f5f7f11d50a3a_6.0.6000.16720_none_a54ef540d05f91fc\ASPNET~1.UNI
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\x86_netfx-aspnet_mof_b03f5f7f11d50a3a_6.0.6000.20883_none_8e870be4ea01d6ef\ASPNET~1.UNI
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\x86_netfx-aspnet_mof_b03f5f7f11d50a3a_6.0.6001.18111_none_a529d9f6d0b19e9d\ASPNET~1.UNI
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\x86_netfx-aspnet_mof_b03f5f7f11d50a3a_6.0.6001.22230_none_8e5e4a92ea5717b0\ASPNET~1.UNI
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\x86_netfx-aspnet_webadmin_appconfig_b03f5f7f11d50a3a_6.0.6000.16720_none_4ef4fbb8699d6b09\CREATE~1.ASP
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\x86_netfx-aspnet_webadmin_appconfig_b03f5f7f11d50a3a_6.0.6000.16720_none_4ef4fbb8699d6b09\DEFINE~1.ASP
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\x86_netfx-aspnet_webadmin_appconfig_b03f5f7f11d50a3a_6.0.6000.16720_none_4ef4fbb8699d6b09\MANAGE~1.ASP
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\x86_netfx-aspnet_webadmin_appconfig_b03f5f7f11d50a3a_6.0.6000.20883_none_382d125c833faffc\CREATE~1.ASP
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\x86_netfx-aspnet_webadmin_appconfig_b03f5f7f11d50a3a_6.0.6000.20883_none_382d125c833faffc\DEFINE~1.ASP
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\x86_netfx-aspnet_webadmin_appconfig_b03f5f7f11d50a3a_6.0.6000.20883_none_382d125c833faffc\MANAGE~1.ASP
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\x86_netfx-aspnet_webadmin_appconfig_b03f5f7f11d50a3a_6.0.6001.18111_none_4ecfe06e69ef77aa\CREATE~1.ASP
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\x86_netfx-aspnet_webadmin_appconfig_b03f5f7f11d50a3a_6.0.6001.18111_none_4ecfe06e69ef77aa\DEFINE~1.ASP
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\x86_netfx-aspnet_webadmin_appconfig_b03f5f7f11d50a3a_6.0.6001.18111_none_4ecfe06e69ef77aa\MANAGE~1.ASP
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\x86_netfx-aspnet_webadmin_permissions_b03f5f7f11d50a3a_6.0.6000.16720_none_950a4e2fda3ee0ba\CREATE~1.ASP
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\x86_netfx-aspnet_webadmin_permissions_b03f5f7f11d50a3a_6.0.6000.16720_none_950a4e2fda3ee0ba\MANAGE~1.ASP
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\x86_netfx-aspnet_webadmin_permissions_b03f5f7f11d50a3a_6.0.6000.20883_none_7e4264d3f3e125ad\CREATE~1.ASP
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\x86_netfx-aspnet_webadmin_permissions_b03f5f7f11d50a3a_6.0.6000.20883_none_7e4264d3f3e125ad\MANAGE~1.ASP
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\x86_netfx-aspnet_webadmin_permissions_b03f5f7f11d50a3a_6.0.6001.18111_none_94e532e5da90ed5b\CREATE~1.ASP
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\x86_netfx-aspnet_webadmin_permissions_b03f5f7f11d50a3a_6.0.6001.18111_none_94e532e5da90ed5b\MANAGE~1.ASP
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\x86_netfx-aspnet_webadmin_permissions_b03f5f7f11d50a3a_6.0.6001.22230_none_7e19a381f436666e\CREATE~1.ASP
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\x86_netfx-aspnet_webadmin_permissions_b03f5f7f11d50a3a_6.0.6001.22230_none_7e19a381f436666e\MANAGE~1.ASP
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\x86_netfx-aspnet_webadmin_perm_res_b03f5f7f11d50a3a_6.0.6000.16720_none_4cb2b120b7498755\CREATE~1.RES
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\x86_netfx-aspnet_webadmin_perm_res_b03f5f7f11d50a3a_6.0.6000.16720_none_4cb2b120b7498755\MANAGE~1.RES
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\x86_netfx-aspnet_webadmin_perm_res_b03f5f7f11d50a3a_6.0.6000.20883_none_35eac7c4d0ebcc48\CREATE~1.RES
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\x86_netfx-aspnet_webadmin_perm_res_b03f5f7f11d50a3a_6.0.6000.20883_none_35eac7c4d0ebcc48\MANAGE~1.RES
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\x86_netfx-aspnet_webadmin_perm_res_b03f5f7f11d50a3a_6.0.6001.18111_none_4c8d95d6b79b93f6\CREATE~1.RES
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\x86_netfx-aspnet_webadmin_perm_res_b03f5f7f11d50a3a_6.0.6001.18111_none_4c8d95d6b79b93f6\MANAGE~1.RES
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\x86_netfx-aspnet_webadmin_perm_res_b03f5f7f11d50a3a_6.0.6001.22230_none_35c20672d1410d09\CREATE~1.RES
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\x86_netfx-aspnet_webadmin_perm_res_b03f5f7f11d50a3a_6.0.6001.22230_none_35c20672d1410d09\MANAGE~1.RES
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\x86_netfx-aspnet_webadmin_providers_b03f5f7f11d50a3a_6.0.6000.16720_none_7325c867d7281910\CHOOSE~1.ASP
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\x86_netfx-aspnet_webadmin_providers_b03f5f7f11d50a3a_6.0.6000.16720_none_7325c867d7281910\MANAGE~1.ASP
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\x86_netfx-aspnet_webadmin_providers_b03f5f7f11d50a3a_6.0.6000.16720_none_7325c867d7281910\MANAGE~2.ASP
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\x86_netfx-aspnet_webadmin_providers_b03f5f7f11d50a3a_6.0.6000.20883_none_5c5ddf0bf0ca5e03\CHOOSE~1.ASP
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\x86_netfx-aspnet_webadmin_providers_b03f5f7f11d50a3a_6.0.6000.20883_none_5c5ddf0bf0ca5e03\MANAGE~1.ASP
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\x86_netfx-aspnet_webadmin_providers_b03f5f7f11d50a3a_6.0.6000.20883_none_5c5ddf0bf0ca5e03\MANAGE~2.ASP
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\x86_netfx-aspnet_webadmin_providers_b03f5f7f11d50a3a_6.0.6001.18111_none_7300ad1dd77a25b1\CHOOSE~1.ASP
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\x86_netfx-aspnet_webadmin_providers_b03f5f7f11d50a3a_6.0.6001.18111_none_7300ad1dd77a25b1\MANAGE~1.ASP
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\x86_netfx-aspnet_webadmin_providers_b03f5f7f11d50a3a_6.0.6001.18111_none_7300ad1dd77a25b1\MANAGE~2.ASP
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\x86_netfx-aspnet_webadmin_secur_res_b03f5f7f11d50a3a_6.0.6000.16720_none_c39efe8a3f927437\SETUPA~1.RES
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\x86_netfx-aspnet_webadmin_secur_res_b03f5f7f11d50a3a_6.0.6000.20883_none_acd7152e5934b92a\SETUPA~1.RES
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\x86_netfx-aspnet_webadmin_secur_res_b03f5f7f11d50a3a_6.0.6001.18111_none_c379e3403fe480d8\SETUPA~1.RES
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\x86_netfx-aspnet_webadmin_secur_res_b03f5f7f11d50a3a_6.0.6001.22230_none_acae53dc5989f9eb\SETUPA~1.RES
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\x86_netfx-aspnet_webadmin_users_res_b03f5f7f11d50a3a_6.0.6000.16720_none_b103fb905f6db0d9\MANAGE~1.RES
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\x86_netfx-aspnet_webadmin_users_res_b03f5f7f11d50a3a_6.0.6000.20883_none_9a3c1234790ff5cc\MANAGE~1.RES
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\x86_netfx-aspnet_webadmin_users_res_b03f5f7f11d50a3a_6.0.6001.18111_none_b0dee0465fbfbd7a\MANAGE~1.RES
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\x86_netfx-aspnet_webmintrust_config_b03f5f7f11d50a3a_6.0.6000.16720_none_e2c358ab062e054b\WEB_MI~1.CON
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\x86_netfx-aspnet_webmintrust_config_b03f5f7f11d50a3a_6.0.6000.20883_none_cbfb6f4f1fd04a3e\WEB_MI~1.CON
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\x86_netfx-config_files_.._gacutil_exe_config_31bf3856ad364e35_6.0.6000.16720_none_9b01a5fdd9371aff\GACUTI~1.CON
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\x86_netfx-config_files_.._gacutil_exe_config_31bf3856ad364e35_6.0.6000.20883_none_9b4d641ef282ae74\GACUTI~1.CON
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\x86_netfx-config_files_.._gacutil_exe_config_31bf3856ad364e35_6.0.6001.18111_none_9cf3b4d9d654a956\GACUTI~1.CON
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\x86_netfx-config_files_.._gacutil_exe_config_31bf3856ad364e35_6.0.6001.22230_none_9d66b182ef8367ab\GACUTI~1.CON
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\x86_netfx-aspnet_webadmin_providers_b03f5f7f11d50a3a_6.0.6001.22230_none_5c351db9f11f9ec4\CHOOSE~1.ASP
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\x86_netfx-aspnet_webadmin_providers_b03f5f7f11d50a3a_6.0.6001.22230_none_5c351db9f11f9ec4\MANAGE~1.ASP
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\x86_netfx-aspnet_webadmin_providers_b03f5f7f11d50a3a_6.0.6001.22230_none_5c351db9f11f9ec4\MANAGE~2.ASP
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\x86_netfx-aspnet_webadmin_roles_b03f5f7f11d50a3a_6.0.6001.18111_none_75c874a9a137a5f0\MANAGE~2.ASP
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\x86_netfx-aspnet_webadmin_users_res_b03f5f7f11d50a3a_6.0.6001.22230_none_9a1350e27965368d\MANAGE~1.RES
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\x86_netfx-aspnet_webevent_sqlprov_b03f5f7f11d50a3a_6.0.6001.18111_none_a335242e0936a3fd\INSTAL~1.SQL
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\x86_netfx-aspnet_webevent_sqlprov_b03f5f7f11d50a3a_6.0.6001.18111_none_a335242e0936a3fd\UNINST~1.SQL
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\x86_netfx-aspnet_webmintrust_config_b03f5f7f11d50a3a_6.0.6001.18111_none_e29e3d61068011ec\WEB_MI~1.CON
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\x86_presentationcore_31bf3856ad364e35_6.0.6002.18005_none_ae1c8b4b8d1614c8\PRESEN~1.CON
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\x86_policy.1.2.microsof..op.security.azroles_31bf3856ad364e35_6.0.6000.16386_none_ea83414c2e75b887\Microsoft.Interop.Security.AzRoles.config
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\x86_netfx-aspnet_webevent_sqlprov_b03f5f7f11d50a3a_6.0.6001.22230_none_8c6994ca22dc1d10\INSTAL~1.SQL
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\x86_netfx-aspnet_webevent_sqlprov_b03f5f7f11d50a3a_6.0.6001.22230_none_8c6994ca22dc1d10\UNINST~1.SQL
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\x86_netfx-aspnet_webmedtrust_config_b03f5f7f11d50a3a_6.0.6000.16720_none_2c88b9b71ca44e71\WEB_ME~1.CON
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\x86_netfx-aspnet_webmedtrust_config_b03f5f7f11d50a3a_6.0.6000.20883_none_15c0d05b36469364\WEB_ME~1.CON
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\x86_netfx-aspnet_webmedtrust_config_b03f5f7f11d50a3a_6.0.6001.18111_none_2c639e6d1cf65b12\WEB_ME~1.CON
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\x86_netfx-aspnet_webmedtrust_config_b03f5f7f11d50a3a_6.0.6001.22230_none_15980f09369bd425\WEB_ME~1.CON
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\x86_netfx-aspnet_webadmin_roles_b03f5f7f11d50a3a_6.0.6001.22230_none_5efce545badd1f03\MANAGE~2.ASP
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\x86_netfx-aspnet_webadmin_roles_res_b03f5f7f11d50a3a_6.0.6000.16720_none_87d39b55197883e6\MANAGE~1.RES
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\x86_netfx-aspnet_webadmin_roles_res_b03f5f7f11d50a3a_6.0.6000.16720_none_87d39b55197883e6\MANAGE~2.RES
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\x86_netfx-aspnet_webadmin_roles_res_b03f5f7f11d50a3a_6.0.6000.20883_none_710bb1f9331ac8d9\MANAGE~1.RES
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\x86_netfx-aspnet_webadmin_roles_res_b03f5f7f11d50a3a_6.0.6000.20883_none_710bb1f9331ac8d9\MANAGE~2.RES
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\x86_netfx-aspnet_webadmin_roles_res_b03f5f7f11d50a3a_6.0.6001.18111_none_87ae800b19ca9087\MANAGE~1.RES
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\x86_netfx-aspnet_webadmin_roles_res_b03f5f7f11d50a3a_6.0.6001.18111_none_87ae800b19ca9087\MANAGE~2.RES
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\x86_netfx-aspnet_webadmin_roles_res_b03f5f7f11d50a3a_6.0.6001.22230_none_70e2f0a73370099a\MANAGE~1.RES
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\x86_netfx-aspnet_webadmin_roles_res_b03f5f7f11d50a3a_6.0.6001.22230_none_70e2f0a73370099a\MANAGE~2.RES
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\x86_netfx-aspnet_webadmin_security_b03f5f7f11d50a3a_6.0.6000.16720_none_62b207ce0c996d96\SETUPA~1.ASP
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\x86_netfx-aspnet_webadmin_security_b03f5f7f11d50a3a_6.0.6000.20883_none_4bea1e72263bb289\SETUPA~1.ASP
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\x86_netfx-aspnet_webadmin_security_b03f5f7f11d50a3a_6.0.6001.18111_none_628cec840ceb7a37\SETUPA~1.ASP
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\x86_netfx-aspnet_webadmin_security_b03f5f7f11d50a3a_6.0.6001.22230_none_4bc15d202690f34a\SETUPA~1.ASP
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\x86_netfx-aspnet_webadmin_help_b03f5f7f11d50a3a_6.0.6001.22230_none_659fa2cdd3687d81\WEBADM~2.ASP
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\x86_netfx-aspnet_webadmin_help_b03f5f7f11d50a3a_6.0.6001.22230_none_659fa2cdd3687d81\WEBADM~3.ASP
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\x86_netfx-aspnet_webadmin_help_b03f5f7f11d50a3a_6.0.6001.22230_none_659fa2cdd3687d81\WEBADM~4.ASP
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\x86_netfx-aspnet_webadmin_help_b03f5f7f11d50a3a_6.0.6001.22230_none_659fa2cdd3687d81\WEBB00~1.ASP
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\x86_netfx-aspnet_webadmin_images_b03f5f7f11d50a3a_6.0.6000.16720_none_aee54cea18c2ca82\ASPX_F~1.GIF
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\x86_netfx-aspnet_webadmin_images_b03f5f7f11d50a3a_6.0.6000.16720_none_aee54cea18c2ca82\DESELE~1.GIF
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\x86_netfx-aspnet_webadmin_images_b03f5f7f11d50a3a_6.0.6000.16720_none_aee54cea18c2ca82\GRADIE~1.GIF
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\x86_netfx-aspnet_webadmin_images_b03f5f7f11d50a3a_6.0.6000.16720_none_aee54cea18c2ca82\GRADIE~2.GIF
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\x86_netfx-aspnet_webadmin_images_b03f5f7f11d50a3a_6.0.6000.16720_none_aee54cea18c2ca82\HEADER~1.GIF
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\x86_netfx-aspnet_webadmin_images_b03f5f7f11d50a3a_6.0.6000.16720_none_aee54cea18c2ca82\REQUIR~1.GIF
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\x86_netfx-aspnet_webadmin_images_b03f5f7f11d50a3a_6.0.6000.16720_none_aee54cea18c2ca82\SECURI~1.JPG
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\x86_netfx-aspnet_webadmin_images_b03f5f7f11d50a3a_6.0.6000.16720_none_aee54cea18c2ca82\SELECT~2.GIF
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\x86_netfx-aspnet_webadmin_images_b03f5f7f11d50a3a_6.0.6000.16720_none_aee54cea18c2ca82\SELECT~3.GIF
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\x86_netfx-aspnet_webadmin_images_b03f5f7f11d50a3a_6.0.6000.16720_none_aee54cea18c2ca82\UNSELE~1.GIF
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\x86_netfx-aspnet_webadmin_images_b03f5f7f11d50a3a_6.0.6000.16720_none_aee54cea18c2ca82\UNSELE~2.GIF
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\x86_netfx-aspnet_webadmin_images_b03f5f7f11d50a3a_6.0.6000.20883_none_981d638e32650f75\ASPX_F~1.GIF
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\x86_netfx-aspnet_webadmin_images_b03f5f7f11d50a3a_6.0.6000.20883_none_981d638e32650f75\DESELE~1.GIF
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\x86_netfx-aspnet_webadmin_images_b03f5f7f11d50a3a_6.0.6000.20883_none_981d638e32650f75\GRADIE~1.GIF
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\x86_netfx-aspnet_webadmin_images_b03f5f7f11d50a3a_6.0.6000.20883_none_981d638e32650f75\GRADIE~2.GIF
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\x86_netfx-aspnet_webadmin_images_b03f5f7f11d50a3a_6.0.6000.20883_none_981d638e32650f75\HEADER~1.GIF
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\x86_netfx-aspnet_webadmin_images_b03f5f7f11d50a3a_6.0.6000.20883_none_981d638e32650f75\REQUIR~1.GIF
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\x86_netfx-aspnet_webadmin_images_b03f5f7f11d50a3a_6.0.6000.20883_none_981d638e32650f75\SECURI~1.JPG
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\x86_netfx-aspnet_webadmin_images_b03f5f7f11d50a3a_6.0.6000.20883_none_981d638e32650f75\SELECT~2.GIF
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\x86_netfx-aspnet_webadmin_images_b03f5f7f11d50a3a_6.0.6000.20883_none_981d638e32650f75\SELECT~3.GIF
Status: Locked to the Windows API!

Path: C:\Windows\winsxs\x86_Processes
-------------------
Path: System
PID: 4 Status: Locked to the Windows API!

Path: C:\Windows\System32\audiodg.exe
PID: 1448 Status: Locked to the Windows API!

SSDT
-------------------
#: 021 Function Name: NtAlpcConnectPort
Status: Hooked by "C:\Windows\system32\DRIVERS\vsdatant.sys" at address 0x8f22a416

#: 054 Function Name: NtConnectPort
Status: Hooked by "C:\Windows\system32\DRIVERS\vsdatant.sys" at address 0x8f229fc8

#: 060 Function Name: NtCreateFile
Status: Hooked by "C:\Windows\system32\DRIVERS\vsdatant.sys" at address 0x8f226f04

#: 064 Function Name: NtCreateKey
Status: Hooked by "C:\Windows\system32\DRIVERS\vsdatant.sys" at address 0x8f23dbe6

#: 071 Function Name: NtCreatePort
Status: Hooked by "C:\Windows\system32\DRIVERS\vsdatant.sys" at address 0x8f22a8c2

#: 072 Function Name: NtCreateProcess
Status: Hooked by "C:\Windows\system32\DRIVERS\vsdatant.sys" at address 0x8f23b8aa

#: 073 Function Name: NtCreateProcessEx
Status: Hooked by "C:\Windows\system32\DRIVERS\vsdatant.sys" at address 0x8f23bac4

#: 075 Function Name: NtCreateSection
Status: Hooked by "C:\Windows\system32\DRIVERS\vsdatant.sys" at address 0x8f240012

#: 078 Function Name: NtCreateThread
Status: Hooked by "<unknown>" at address 0x9751471c

#: 115 Function Name: NtCreateWaitablePort
Status: Hooked by "C:\Windows\system32\DRIVERS\vsdatant.sys" at address 0x8f22a96a

#: 122 Function Name: NtDeleteFile
Status: Hooked by "C:\Windows\system32\DRIVERS\vsdatant.sys" at address 0x8f227632

#: 123 Function Name: NtDeleteKey
Status: Hooked by "C:\Windows\system32\DRIVERS\vsdatant.sys" at address 0x8f23eb12

#: 126 Function Name: NtDeleteValueKey
Status: Hooked by "C:\Windows\system32\DRIVERS\vsdatant.sys" at address 0x8f23e6b0

#: 129 Function Name: NtDuplicateObject
Status: Hooked by "C:\Windows\system32\DRIVERS\vsdatant.sys" at address 0x8f23b2aa

#: 165 Function Name: NtLoadDriver
Status: Hooked by "C:\Windows\system32\DRIVERS\vsdatant.sys" at address 0x8f2233e4

#: 166 Function Name: NtLoadKey
Status: Hooked by "C:\Windows\system32\DRIVERS\vsdatant.sys" at address 0x8f23f250

#: 167 Function Name: NtLoadKey2
Status: Hooked by "C:\Windows\system32\DRIVERS\vsdatant.sys" at address 0x8f23f2c8

#: 168 Function Name: NtLoadKeyEx
Status: Hooked by "C:\Windows\system32\DRIVERS\vsdatant.sys" at address 0x8f23f3b8

#: 177 Function Name: NtMapViewOfSection
Status: Hooked by "C:\Windows\system32\DRIVERS\vsdatant.sys" at address 0x8f240264

#: 186 Function Name: NtOpenFile
Status: Hooked by "C:\Windows\system32\DRIVERS\vsdatant.sys" at address 0x8f2273f2

#: 194 Function Name: NtOpenProcess
Status: Hooked by "<unknown>" at address 0x97514708

#: 201 Function Name: NtOpenThread
Status: Hooked by "<unknown>" at address 0x9751470d

#: 267 Function Name: NtRenameKey
Status: Hooked by "C:\Windows\system32\DRIVERS\vsdatant.sys" at address 0x8f23fa8a

#: 268 Function Name: NtReplaceKey
Status: Hooked by "C:\Windows\system32\DRIVERS\vsdatant.sys" at address 0x8f23f430

#: 276 Function Name: NtRequestWaitReplyPort
Status: Hooked by "C:\Windows\system32\DRIVERS\vsdatant.sys" at address 0x8f229c46

#: 280 Function Name: NtRestoreKey
Status: Hooked by "C:\Windows\system32\DRIVERS\vsdatant.sys" at address 0x8f23f8c8

#: 286 Function Name: NtSecureConnectPort
Status: Hooked by "C:\Windows\system32\DRIVERS\vsdatant.sys" at address 0x8f22a1e0

#: 301 Function Name: NtSetInformationFile
Status: Hooked by "C:\Windows\system32\DRIVERS\vsdatant.sys" at address 0x8f22785e

#: 317 Function Name: NtSetSystemInformation
Status: Hooked by "C:\Windows\system32\DRIVERS\vsdatant.sys" at address 0x8f222f04

#: 324 Function Name: NtSetValueKey
Status: Hooked by "C:\Windows\system32\DRIVERS\vsdatant.sys" at address 0x8f23e15a

#: 332 Function Name: NtSystemDebugControl
Status: Hooked by "C:\Windows\system32\DRIVERS\vsdatant.sys" at address 0x8f23c29e

#: 334 Function Name: NtTerminateProcess
Status: Hooked by "<unknown>" at address 0x97514717

#: 342 Function Name: NtUnloadDriver
Status: Hooked by "C:\Windows\system32\DRIVERS\vsdatant.sys" at address 0x8f22365c

#: 383 Function Name: NtCreateUserProcess
Status: Hooked by "C:\Windows\system32\DRIVERS\vsdatant.sys" at address 0x8f23bce2

Stealth Objects
-------------------
Object: Hidden Module [Name: imageres.dll]
Process: Explorer.EXE (PID: 2824) Address: 0x660d0000 Size: 24129536

Shadow SSDT
-------------------
#: 479 Function Name: NtUserMessageCall
Status: Hooked by "C:\Windows\system32\DRIVERS\vsdatant.sys" at address 0x8f22917e

#: 497 Function Name: NtUserPostMessage
Status: Hooked by "C:\Windows\system32\DRIVERS\vsdatant.sys" at address 0x8f2291f2

#: 498 Function Name: NtUserPostThreadMessage
Status: Hooked by "C:\Windows\system32\DRIVERS\vsdatant.sys" at address 0x8f22927a

#: 511 Function Name: NtUserRegisterUserApiHook
Status: Hooked by "C:\Windows\system32\DRIVERS\vsdatant.sys" at address 0x8f223f50

#: 513 Function Name: NtUserRegisterRawInputDevices
Status: Hooked by "C:\Windows\system32\DRIVERS\vsdatant.sys" at address 0x8f22827e

#: 525 Function Name: NtUserSendInput
Status: Hooked by "C:\Windows\system32\DRIVERS\vsdatant.sys" at address 0x8f229432

#: 573 Function Name: NtUserSetWindowsHookEx
Status: Hooked by "C:\Windows\system32\DRIVERS\vsdatant.sys" at address 0x8f223b92

#: 576 Function Name: NtUserSetWinEventHook
Status: Hooked by "C:\Windows\system32\DRIVERS\vsdatant.sys" at address 0x8f223de8

==EOF==

BC AdBot (Login to Remove)

 


#2 schrauber

schrauber

    Mr.Mechanic


  • Malware Response Team
  • 24,794 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Munich,Germany
  • Local time:01:38 AM

Posted 02 October 2009 - 11:20 AM

Hello and welcome to Bleeping Computer

We apologize for the delay in responding to your request for help. Here at Bleeping Computer we get overwhelmed at times, and we are trying our best to keep up. Please note that your topic was not intentionally overlooked. Our mission is to help everyone in need, but sometimes it takes just a little longer to get to every request for help. No one is ignored here.

If you have since resolved the original problem you were having, we would appreciate you letting us know. If not please perform the following steps below so we can have a look at the current condition of your machine.

If you have not done so, include a clear description of the problems you're having, along with any steps you may have performed so far.

Upon completing the steps below another staff member will review and take the steps necessary with you to get your machine back in working order clean and free of malware.

If you have already posted a DDS log, please do so again, as your situation may have changed.
Use the 'Add Reply' and add the new log to this thread.


Thanks and again sorry for the delay.

We need to see some information about what is happening in your machine. Please perform the following scan:
  • Download DDS by sUBs from one of the following links. Save it to your desktop.
  • Double click on the DDS icon, allow it to run.
  • A small box will open, with an explaination about the tool. No input is needed, the scan is running.
  • Notepad will open with the results.
  • Follow the instructions that pop up for posting the results.
  • Close the program window, and delete the program from your desktop.
Please note: You may have to disable any script protection running if the scan fails to run. After downloading the tool, disconnect from the internet and disable all antivirus protection. Run the scan, enable your A/V and reconnect to the internet.

Information on A/V control HERE
regards,
schrauber

Posted Image
Posted Image

If I've not posted back within 48 hrs., feel free to send a PM with your topic link. Thank you!

If I have helped you then please consider donating to continue the fight against malware Posted Image

#3 I_am_CanadianEh?

I_am_CanadianEh?
  • Topic Starter

  • Members
  • 489 posts
  • OFFLINE
  •  
  • Gender:Male
  • Local time:07:38 PM

Posted 03 October 2009 - 11:10 AM

Hi, thanks for getting back to me! :(

I think all my problems are gone. I was infected with Total Security Centre Rogue, notably the tsc.exe process.
Look in my 1st post for full details.

Note, that I had to run MBAM a few times on several user accounts to get "all" of it.

Here is my latest DDS log

DDS.txt


DDS (Ver_09-09-29.01) - NTFSx86
Run by elva at 11:58:49.75 on Sat 10/03/2009
Internet Explorer: 8.0.6001.18813 BrowserJavaVersion: 1.6.0_16
Microsoft® Windows Vista™ Home Premium 6.0.6002.2.1252.1.1033.18.3069.2165 [GMT -4:00]

SP: Windows Defender *disabled* (Updated) {D68DDC3A-831F-4FAE-9E44-DA132C1ACF46}
SP: SUPERAntiSpyware *disabled* (Updated) {222A897C-5018-402e-943F-7E7AC8560DA7}

============== Running Processes ===============

C:\Windows\system32\wininit.exe
C:\Windows\system32\lsm.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\svchost.exe -k rpcss
C:\Windows\system32\Ati2evxx.exe
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\system32\svchost.exe -k GPSvcGroup
C:\Windows\system32\SLsvc.exe
C:\Windows\system32\svchost.exe -k LocalService
C:\Program Files\Windows SteadyState\SCTSvc.exe
C:\Windows\system32\svchost.exe -k NetworkService
C:\Windows\System32\ZoneLabs\vsmon.exe
C:\Windows\system32\Ati2evxx.exe
C:\Windows\System32\spoolsv.exe
C:\Program Files\Avira\AntiVir Desktop\sched.exe
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
C:\Program Files\Common Files\Acronis\Schedule2\schedul2.exe
C:\Windows\system32\Dwm.exe
C:\Program Files\Avira\AntiVir Desktop\avguard.exe
C:\Windows\system32\taskeng.exe
C:\Windows\Explorer.EXE
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Microsoft Small Business\Business Contact Manager\BcmSqlStartupSvc.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Program Files\Diskeeper Corporation\Diskeeper\DkService.exe
C:\Program Files\HP\HP Software Update\hpwuSchd2.exe
C:\Program Files\NoteBurner\VTBurnerGUI.exe
C:\Program Files\BillP Studios\WinPatrol\WinPatrol.exe
C:\Windows\system32\svchost.exe -k hpdevmgmt
C:\Program Files\Intel\Intel Matrix Storage Manager\Iaantmon.exe
C:\Program Files\Acronis\TrueImageHome\TrueImageMonitor.exe
C:\Program Files\Acronis\TrueImageHome\TimounterMonitor.exe
C:\Program Files\Common Files\Acronis\Schedule2\schedhlp.exe
C:\Windows\sttray.exe
C:\Windows\System32\svchost.exe -k HPZ12
C:\Program Files\Java\jre6\bin\jusched.exe
C:\Program Files\CDBurnerXP\NMSAccessU.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Avira\AntiVir Desktop\avgnt.exe
C:\Windows\System32\svchost.exe -k HPZ12
C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted
c:\Program Files\Microsoft SQL Server\90\Shared\sqlbrowser.exe
C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
c:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe
C:\Program Files\Windows Media Player\wmpnscfg.exe
C:\Windows\system32\svchost.exe -k imgsvc
C:\Program Files\TomTom HOME 2\TomTomHOMEService.exe
C:\Windows\System32\svchost.exe -k WerSvcGroup
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
C:\Windows\system32\SearchIndexer.exe
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe
C:\Program Files\Avira\AntiVir Desktop\avmailc.exe
C:\Program Files\Avira\AntiVir Desktop\AVWEBGRD.EXE
C:\Windows\system32\taskeng.exe
C:\Program Files\Windows Media Player\wmpnetwk.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Windows\system32\SearchProtocolHost.exe
C:\Windows\system32\SearchFilterHost.exe
C:\Windows\system32\SearchProtocolHost.exe
C:\Users\elva\Desktop\dds.scr
C:\Windows\system32\wbem\wmiprvse.exe

============== Pseudo HJT Report ===============

uStart Page = hxxp://login.live.com/login.srf?id=2&svc=mail&cbid=24325&msppjph=1&tw=900&fs=1&lc=1033&_lang=EN
BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelperShim.dll
BHO: Google Toolbar Helper: {aa58ed58-01dd-4d91-8333-cf10577473f7} - c:\program files\google\google toolbar\GoogleToolbar_32.dll
BHO: Google Toolbar Notifier BHO: {af69de43-7d58-4638-b6fa-ce66b5ad205d} - c:\program files\google\googletoolbarnotifier\5.2.4204.1700\swg.dll
BHO: Google Dictionary Compression sdch: {c84d72fe-e17d-4195-bb24-76c02e2e7c4e} - c:\program files\google\google toolbar\component\fastsearch_B7C5AC242193BB3E.dll
BHO: Java™ Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll
BHO: Cooliris Plug-In for Internet Explorer: {eaee5c74-6d0d-4aca-9232-0da4a7b866ba} - c:\program files\piclensie\cooliris.dll
TB: Google Toolbar: {2318c2b1-4965-11d4-9b18-009027a5cd4f} - c:\program files\google\google toolbar\GoogleToolbar_32.dll
uRun: [swg] "c:\program files\google\googletoolbarnotifier\GoogleToolbarNotifier.exe"
uRun: [WMPNSCFG] c:\program files\windows media player\WMPNSCFG.exe
mRun: [HP Software Update] c:\program files\hp\hp software update\HPWuSchd2.exe
mRun: [NoteBurner] c:\program files\noteburner\VTBurnerGUI.exe /silence
mRun: [WinPatrol] c:\program files\billp studios\winpatrol\winpatrol.exe -expressboot
mRun: [TrueImageMonitor.exe] c:\program files\acronis\trueimagehome\TrueImageMonitor.exe
mRun: [AcronisTimounterMonitor] c:\program files\acronis\trueimagehome\TimounterMonitor.exe
mRun: [Acronis Scheduler2 Service] "c:\program files\common files\acronis\schedule2\schedhlp.exe"
mRun: [SigmatelSysTrayApp] sttray.exe
mRun: [Google Quick Search Box] "c:\program files\google\quick search box\GoogleQuickSearchBox.exe" /autorun
mRun: [SunJavaUpdateSched] "c:\program files\java\jre6\bin\jusched.exe"
mRun: [Malwarebytes Anti-Malware (reboot)] "c:\program files\malwarebytes' anti-malware\mbam.exe" /runcleanupscript
mRun: [iTunesHelper] "c:\program files\itunes\iTunesHelper.exe"
mRun: [avgnt] "c:\program files\avira\antivir desktop\avgnt.exe" /min -nosplash
mRun: [ZoneAlarm Client] "c:\program files\zone labs\zonealarm\zlclient.exe"
mPolicies-explorer: BindDirectlyToPropertySetStorage = 0 (0x0)
mPolicies-system: EnableLUA = 0 (0x0)
mPolicies-system: EnableUIADesktopToggle = 0 (0x0)
mPolicies-system: HideFastUserSwitching = 1 (0x1)
IE: E&xport to Microsoft Excel - c:\progra~1\micros~2\office12\EXCEL.EXE/3000
IE: {3437D640-C91A-458f-89F5-B9095EA4C28B} - {04F93351-81D2-4484-9982-0D55DEFFFAE6} - c:\program files\piclensie\cooliris.dll
IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~1\micros~2\office12\REFIEBAR.DLL
LSP: c:\program files\avira\antivir desktop\avsda.dll
DPF: {3860DD98-0549-4D50-AA72-5D17D200EE10} - hxxp://cdn.scan.onecare.live.com/resource/download/scanner/en-us/wlscctrl2.cab
DPF: {49312E18-AA92-4CC2-BB97-55DEA7BCADD6} - hxxp://support.dell.com/systemprofiler/SysProExe.CAB
DPF: {7530BFB8-7293-4D34-9923-61A11451AFC5} - hxxp://download.eset.com/special/eos/OnlineScanner.cab
DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} - hxxp://fpdownload.macromedia.com/get/flashplayer/current/polarbear/ultrashim.cab
DPF: {BB21F850-63F4-4EC9-BF9D-565BD30C9AE9} - hxxp://ax.emsisoft.com/asquared.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_16-windows-i586.cab
DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} - hxxp://fpdownload2.macromedia.com/get/flashplayer/current/swflash.cab
DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - hxxp://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
Handler: belarc - {6318E0AB-2E93-11D1-B8ED-00608CC9A71F} - c:\program files\belarc\advisor\system\BAVoilaX.dll
Notify: !SASWinLogon - c:\program files\superantispyware\SASWINLO.DLL
SEH: SABShellExecuteHook Class: {5ae067d3-9afb-48e0-853a-ebb7f4a000da} - c:\program files\superantispyware\SASSEH.DLL

================= FIREFOX ===================

FF - ProfilePath - c:\users\elva\appdata\roaming\mozilla\firefox\profiles\udd33exj.default\
FF - prefs.js: browser.search.defaulturl - hxxp://www.google.com/search?lr=&ie=UTF-8&oe=UTF-8&q=
FF - prefs.js: browser.search.selectedEngine - Google
FF - prefs.js: browser.startup.homepage - hxxp://login.live.com/login.srf?id=2&svc=mail&cbid=24325&msppjph=1&tw=900&fs=1&lc=1033&_lang=EN
FF - component: c:\users\elva\appdata\roaming\mozilla\firefox\profiles\udd33exj.default\extensions\piclens@cooliris.com\components\coolirisstub.dll
FF - plugin: c:\program files\microsoft\office live\npOLW.dll
FF - plugin: c:\users\elva\appdata\roaming\mozilla\firefox\profiles\udd33exj.default\extensions\piclens@cooliris.com\plugins\npcoolirisplugin.dll
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\microsoft.net\framework\v3.5\windows presentation foundation\dotnetassistantextension\
FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0016-ABCDEFFEDCBA}

============= SERVICES / DRIVERS ===============

R0 ntcdrdrv;ntcdrdrv;c:\windows\system32\drivers\ntcdrdrv.sys [2009-6-19 13440]
R0 tdrpman228;Acronis Try&Decide and Restore Points filter (build 228);c:\windows\system32\drivers\tdrpm228.sys [2009-9-30 902592]
R1 SASDIFSV;SASDIFSV;c:\program files\superantispyware\sasdifsv.sys [2009-5-26 9968]
R1 SASKUTIL;SASKUTIL;c:\program files\superantispyware\SASKUTIL.SYS [2009-5-26 74480]
R2 AntiVirMailService;Avira AntiVir MailGuard;c:\program files\avira\antivir desktop\avmailc.exe [2009-8-6 194817]
R2 AntiVirSchedulerService;Avira AntiVir Scheduler;c:\program files\avira\antivir desktop\sched.exe [2009-8-6 108289]
R2 AntiVirWebService;Avira AntiVir WebGuard;c:\program files\avira\antivir desktop\avwebgrd.exe [2009-8-6 434945]
R2 BcmSqlStartupSvc;Business Contact Manager SQL Server Startup Service;c:\program files\microsoft small business\business contact manager\BcmSqlStartupSvc.exe [2008-1-11 30312]
R2 TomTomHOMEService;TomTomHOMEService;c:\program files\tomtom home 2\TomTomHOMEService.exe [2009-8-27 92008]
R2 Windows SteadyState;Windows SteadyState Service;c:\program files\windows steadystate\SCTSvc.exe [2008-5-30 115728]
R2 wlidsvc;Windows Live ID Sign-in Assistant;c:\program files\common files\microsoft shared\windows live\WLIDSVC.EXE [2009-3-30 1533808]
R3 VST_DPV;VST_DPV;c:\windows\system32\drivers\VSTDPV3.SYS [2006-11-2 987648]
R3 VSTHWBS2;VSTHWBS2;c:\windows\system32\drivers\VSTBS23.SYS [2006-11-2 251904]
S2 AcronisOSSReinstallSvc;Acronis OS Selector Reinstall Service;c:\program files\common files\acronis\acronis disk director\oss_reinstall_svc.exe [2009-9-22 2131136]
S3 MSSQL$MSSMLBIZ;SQL Server (MSSMLBIZ);c:\program files\microsoft sql server\mssql.1\mssql\binn\sqlservr.exe [2008-11-24 29263712]
S3 PSI;PSI;c:\windows\system32\drivers\psi_mf.sys [2009-6-17 12648]
S3 SASENUM;SASENUM;c:\program files\superantispyware\SASENUM.SYS [2009-5-26 7408]

=============== Created Last 30 ================

2009-09-30 23:09 16,568,832 a------- c:\windows\system32\imageres.dll
2009-09-30 22:40 1,238,408 a------- c:\windows\system32\zpeng25.dll
2009-09-30 22:40 418,006 a---h--- c:\windows\system32\drivers\vsconfig.xml
2009-09-30 22:40 443,080 a------- c:\windows\system32\drivers\vsdatant.sys
2009-09-30 22:40 <DIR> --d----- c:\windows\system32\ZoneLabs
2009-09-30 22:40 <DIR> --d----- c:\program files\Zone Labs
2009-09-30 22:39 <DIR> --d----- c:\programdata\CheckPoint
2009-09-30 22:39 <DIR> --d----- c:\progra~2\CheckPoint
2009-09-30 22:39 <DIR> --d----- c:\windows\Internet Logs
2009-09-30 22:37 <DIR> --d----- c:\program files\Windows SteadyState
2009-09-30 20:29 902,592 a------- c:\windows\system32\drivers\tdrpm228.sys
2009-09-30 20:29 138,208 a------- c:\windows\system32\drivers\snapman.sys
2009-09-30 20:29 <DIR> --dshr-- C:\bootwiz
2009-09-29 21:50 102 a------- c:\windows\asquared.ini
2009-09-28 21:40 <DIR> --d----- c:\program files\iPod
2009-09-28 21:40 <DIR> --d----- c:\program files\iTunes
2009-09-22 21:49 <DIR> --d----- c:\program files\Microsoft Windows 7 Upgrade Advisor
2009-09-20 20:43 107,368 a------- c:\windows\system32\GEARAspi.dll
2009-09-20 20:43 26,600 a------- c:\windows\system32\drivers\GEARAspiWDM.sys
2009-09-20 20:42 <DIR> --d----- c:\programdata\{755AC846-7372-4AC8-8550-C52491DAA8BD}
2009-09-20 20:42 <DIR> --d----- c:\progra~2\{755AC846-7372-4AC8-8550-C52491DAA8BD}
2009-09-08 21:22 302,592 a------- c:\windows\system32\wlansec.dll
2009-09-08 21:22 293,376 a------- c:\windows\system32\wlanmsm.dll
2009-09-08 21:22 127,488 a------- c:\windows\system32\L2SecHC.dll
2009-09-08 21:22 2,501,921 a------- c:\windows\system32\wlan.tmf
2009-09-08 21:22 513,536 a------- c:\windows\system32\wlansvc.dll
2009-09-08 21:22 65,024 a------- c:\windows\system32\wlanapi.dll
2009-09-05 01:54 94,208 a------- c:\windows\system32\QuickTimeVR.qtx
2009-09-05 01:54 69,632 a------- c:\windows\system32\QuickTime.qts

==================== Find3M ====================

2009-09-30 22:40 143,360 a------- c:\windows\inf\infstrng.dat
2009-09-30 22:40 51,200 a------- c:\windows\inf\infpub.dat
2009-09-30 22:40 86,016 a------- c:\windows\inf\infstor.dat
2009-09-10 14:54 38,224 a------- c:\windows\system32\drivers\mbamswissarmy.sys
2009-09-10 14:53 19,160 a------- c:\windows\system32\drivers\mbam.sys
2009-08-28 22:30 173,056 a------- c:\windows\apppatch\AcXtrnal.dll
2009-08-28 22:30 458,752 a------- c:\windows\apppatch\AcSpecfc.dll
2009-08-28 22:30 2,159,616 a------- c:\windows\apppatch\AcGenral.dll
2009-08-28 22:30 542,720 a------- c:\windows\apppatch\AcLayers.dll
2009-08-28 20:27 4,240,384 a------- c:\windows\system32\GameUXLegacyGDFs.dll
2009-08-28 20:14 28,672 a------- c:\windows\system32\Apphlpdm.dll
2009-08-14 12:27 904,776 a------- c:\windows\system32\drivers\tcpip.sys
2009-08-14 11:53 17,920 a------- c:\windows\system32\netevent.dll
2009-08-14 09:49 9,728 a------- c:\windows\system32\TCPSVCS.EXE
2009-08-14 09:49 17,920 a------- c:\windows\system32\ROUTE.EXE
2009-08-14 09:49 11,264 a------- c:\windows\system32\MRINFO.EXE
2009-08-14 09:49 27,136 a------- c:\windows\system32\NETSTAT.EXE
2009-08-14 09:49 19,968 a------- c:\windows\system32\ARP.EXE
2009-08-14 09:49 8,704 a------- c:\windows\system32\HOSTNAME.EXE
2009-08-14 09:49 10,240 a------- c:\windows\system32\finger.exe
2009-08-14 09:48 30,720 a------- c:\windows\system32\drivers\tcpipreg.sys
2009-08-14 09:48 105,984 a------- c:\windows\system32\netiohlp.dll
2009-08-11 22:32 411,368 a------- c:\windows\system32\deploytk.dll
2009-08-06 22:56 55,656 a------- c:\windows\system32\drivers\avgntflt.sys
2009-07-21 17:52 915,456 a------- c:\windows\system32\wininet.dll
2009-07-21 17:47 109,056 a------- c:\windows\system32\iesysprep.dll
2009-07-21 17:47 71,680 a------- c:\windows\system32\iesetup.dll
2009-07-21 16:13 133,632 a------- c:\windows\system32\ieUnatt.exe
2009-07-17 09:54 71,680 a------- c:\windows\system32\atl.dll
2009-07-15 08:40 8,147,456 a------- c:\windows\system32\wmploc.DLL
2009-07-15 08:39 313,344 a------- c:\windows\system32\wmpdxm.dll
2009-07-15 08:39 4,096 a------- c:\windows\system32\dxmasf.dll
2009-07-15 08:39 7,680 a------- c:\windows\system32\spwmp.dll
2009-07-07 12:20 3,076 a------- c:\windows\system32\tmp.reg
2009-06-20 22:37 665,600 a------- c:\windows\inf\drvindex.dat
2009-06-19 21:38 174 a--sh--- c:\program files\desktop.ini
2006-11-02 08:42 287,440 a------- c:\windows\inf\perflib\0409\perfi.dat
2006-11-02 08:42 287,440 a------- c:\windows\inf\perflib\0409\perfh.dat
2006-11-02 08:42 30,674 a------- c:\windows\inf\perflib\0409\perfd.dat
2006-11-02 08:42 30,674 a------- c:\windows\inf\perflib\0409\perfc.dat
2006-11-02 05:20 287,440 a------- c:\windows\inf\perflib\0000\perfi.dat
2006-11-02 05:20 287,440 a------- c:\windows\inf\perflib\0000\perfh.dat
2006-11-02 05:20 30,674 a------- c:\windows\inf\perflib\0000\perfd.dat
2006-11-02 05:20 30,674 a------- c:\windows\inf\perflib\0000\perfc.dat
2009-06-24 13:52 16,384 a--sh--- c:\windows\serviceprofiles\networkservice\appdata\local\microsoft\windows\history\history.ie5\index.dat
2009-06-24 13:52 32,768 a--sh--- c:\windows\serviceprofiles\networkservice\appdata\local\microsoft\windows\temporary internet files\content.ie5\index.dat
2009-06-24 13:52 16,384 a--sh--- c:\windows\serviceprofiles\networkservice\appdata\roaming\microsoft\windows\cookies\index.dat
2009-06-24 13:52 245,760 a--sh--- c:\windows\serviceprofiles\networkservice\appdata\roaming\microsoft\windows\ietldcache\index.dat
2009-06-20 14:50 23 a--sh--- c:\windows\system32\edacded0.dat
2009-06-28 14:47 16,384 a--sh--- c:\windows\system32\migwiz\%appdata%\microsoft\windows\ietldcache\index.dat

============= FINISH: 12:00:01.96 ===============

The ATTACH.txt log is attached here in a zip file.

Thanks again. :(

#4 schrauber

schrauber

    Mr.Mechanic


  • Malware Response Team
  • 24,794 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Munich,Germany
  • Local time:01:38 AM

Posted 05 October 2009 - 10:59 AM

Hello, I_am_CandianEh? and again
Welcome to the Bleeping Computer Forums. My name is Thomas (Tom is fine), and I will be helping you fixing your problems.

If you do not make a reply in 5 days, we will have to close your topic.

You may want to keep the link to this topic in your favourites. Alternatively, you can click the Posted Image button at the top bar of this topic and Track this Topic. The topics you are tracking can be found here.

Please take note of some guidelines for this fix:
  • Refrain from making any changes to your computer including installing/uninstall programs, deleting files, modifying the registry, and running scanners or tools. Doing so could cause changes to the directions I have to give you and prolong the time required. Further more, you should not be taking any advice relating to this computer from any other source throughout the course of this fix.
  • If you do not understand any step(s) provided, please do not hesitate to ask before continuing. I would much rather clarify instructions or explain them differently than have something important broken.
  • Even if things appear to be better, it might not mean we are finished. Please continue to follow my instructions and reply back until I give you the "all clean". We do not want to clean you part-way, only to have the system re-infect itself.
  • Please reply using the Posted Image button in the lower right hand corner of your screen. Do not start a new topic. The logs that you post should be pasted directly into the reply. Only attach them if requested or if they do not fit into the post.
  • Old topics are closed after 3 days with no reply, and working topics are closed after 5 days. If for any reason you cannot complete instructions within that time, that's fine, just post back here so that we know you're still here.
  • Please set your system to show all files.
    Click Start, open My Computer, select the Tools menu and click Folder Options.
    Select the View Tab. Under the Hidden files and folders heading, select Show hidden files and folders.
    Uncheck: Hide file extensions for known file types
    Uncheck the Hide protected operating system files (recommended) option.
    Click Yes to confirm.






Step 1
  • Download random's system information tool (RSIT) by random/random from here and save it to your desktop.
  • Double click on RSIT.exe to run RSIT.
  • Click Continue at the disclaimer screen.
  • Once it has finished, two logs will open. Please post the contents of both log.txt (<info.txt (<






Step 2

Please download GMER from one of the following locations and save it to your desktop:
  • Main Mirror
    This version will download a randomly named file (Recommended)
  • Zipped Mirror
    This version will download a zip file you will need to extract first. If you use this mirror, please extract the zip file to your desktop.
  • Disconnect from the Internet and close all running programs.
  • Temporarily disable any real-time active protection so your security programs will not conflict with gmer's driver.
  • Double-click on the randomly named GMER file (i.e. n7gmo46c.exe) and allow the gmer.sys driver to load if asked.
  • Note: If you downloaded the zipped version, extract the file to its own folder such as C:\gmer and then double-click on gmer.exe.

    Posted Image
  • GMER will open to the Rootkit/Malware tab and perform an automatic quick scan when first run. (do not use the computer while the scan is in progress)
  • If you receive a WARNING!!! about rootkit activity and are asked to fully scan your system...click NO.
  • Now click the Scan button. If you see a rootkit warning window, click OK.
  • When the scan is finished, click the Save... button to save the scan results to your Desktop. Save the file as gmer.log.
  • Click the Copy button and paste the results into your next reply.
  • Exit GMER and re-enable all active protection when done.
-- If you encounter any problems, try running GMER in Safe Mode.








Step 3

Please do an online scan with Kaspersky WebScanner

Click on Kaspersky Online Scanner

You will be prompted to install an ActiveX component from Kaspersky, Click Yes.
  • The program will launch and then begin downloading the latest definition files:
  • Once the files have been downloaded click on NEXT
  • Now click on Scan Settings
  • In the scan settings make that the following are selected:
    • Scan using the following Anti-Virus database:
    Extended (if available otherwise Standard)
    • Scan Options:
    Scan Archives
    Scan Mail Bases
  • Click OK
  • Now under select a target to scan:Select My Computer
  • This will program will start and scan your system.
  • The scan will take a while so be patient and let it run.
  • Once the scan is complete it will display if your system has been infected.
    • Now click on the Save as Text button:
  • Save the file to your desktop.
  • Copy and paste that information in your next post.






Please post back with:
  • Both RSIT-Logfiles
  • Gmer-Logfile
  • Kaspersky-Logfile

regards,
schrauber

Posted Image
Posted Image

If I've not posted back within 48 hrs., feel free to send a PM with your topic link. Thank you!

If I have helped you then please consider donating to continue the fight against malware Posted Image

#5 I_am_CanadianEh?

I_am_CanadianEh?
  • Topic Starter

  • Members
  • 489 posts
  • OFFLINE
  •  
  • Gender:Male
  • Local time:07:38 PM

Posted 05 October 2009 - 09:47 PM

Hi Tom,
If you don't mind, I will post the Kaspersky log tomorrow, OK?

My logs will probably take several posts, so bear with me.

Here is the LOG.txt file from RSIT.

Logfile of random's system information tool 1.06 (written by random/random)
Run by elva at 2009-10-05 21:03:17
Microsoft® Windows Vista™ Home Premium Service Pack 2
System drive C: has 50 GB (60%) free of 83 GB
Total RAM: 3069 MB (67% free)

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 9:03:24 PM, on 10/5/2009
Platform: Windows Vista SP2 (WinNT 6.00.1906)
MSIE: Internet Explorer v8.00 (8.00.6001.18813)
Boot mode: Normal

Running processes:
C:\Windows\system32\Dwm.exe
C:\Windows\system32\taskeng.exe
C:\Windows\Explorer.EXE
C:\Program Files\HP\HP Software Update\hpwuSchd2.exe
C:\Program Files\NoteBurner\VTBurnerGUI.exe
C:\Program Files\BillP Studios\WinPatrol\WinPatrol.exe
C:\Program Files\Acronis\TrueImageHome\TrueImageMonitor.exe
C:\Program Files\Acronis\TrueImageHome\TimounterMonitor.exe
C:\Program Files\Common Files\Acronis\Schedule2\schedhlp.exe
C:\Windows\sttray.exe
C:\Program Files\Java\jre6\bin\jusched.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Avira\AntiVir Desktop\avgnt.exe
C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
C:\Program Files\Windows Media Player\wmpnscfg.exe
C:\Windows\system32\SearchFilterHost.exe
C:\Windows\system32\SearchProtocolHost.exe
C:\Users\elva\Desktop\RSIT.exe
C:\Program Files\Trend Micro\HijackThis\elva.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://login.live.com/login.srf?id=2&s...33&_lang=EN
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.2.4204.1700\swg.dll
O2 - BHO: Google Dictionary Compression sdch - {C84D72FE-E17D-4195-BB24-76C02E2E7C4E} - C:\Program Files\Google\Google Toolbar\Component\fastsearch_B7C5AC242193BB3E.dll
O2 - BHO: Java™ Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: Cooliris Plug-In for Internet Explorer - {EAEE5C74-6D0D-4aca-9232-0DA4A7B866BA} - C:\Program Files\PicLensIE\cooliris.dll
O3 - Toolbar: Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll
O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
O4 - HKLM\..\Run: [NoteBurner] C:\Program Files\NoteBurner\VTBurnerGUI.exe /silence
O4 - HKLM\..\Run: [WinPatrol] C:\Program Files\BillP Studios\WinPatrol\winpatrol.exe -expressboot
O4 - HKLM\..\Run: [TrueImageMonitor.exe] C:\Program Files\Acronis\TrueImageHome\TrueImageMonitor.exe
O4 - HKLM\..\Run: [AcronisTimounterMonitor] C:\Program Files\Acronis\TrueImageHome\TimounterMonitor.exe
O4 - HKLM\..\Run: [Acronis Scheduler2 Service] "C:\Program Files\Common Files\Acronis\Schedule2\schedhlp.exe"
O4 - HKLM\..\Run: [SigmatelSysTrayApp] sttray.exe
O4 - HKLM\..\Run: [Google Quick Search Box] "C:\Program Files\Google\Quick Search Box\GoogleQuickSearchBox.exe" /autorun
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
O4 - HKLM\..\Run: [Malwarebytes Anti-Malware (reboot)] "C:\Program Files\Malwarebytes' Anti-Malware\mbam.exe" /runcleanupscript
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [avgnt] "C:\Program Files\Avira\AntiVir Desktop\avgnt.exe" /min -nosplash
O4 - HKLM\..\Run: [ZoneAlarm Client] "C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe"
O4 - HKCU\..\Run: [swg] "C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe"
O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'NETWORK SERVICE')
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
O9 - Extra button: Launch Cooliris - {3437D640-C91A-458f-89F5-B9095EA4C28B} - C:\Program Files\PicLensIE\cooliris.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
O13 - Gopher Prefix:
O16 - DPF: {3860DD98-0549-4D50-AA72-5D17D200EE10} (Windows Live OneCare safety scanner control) - http://cdn.scan.onecare.live.com/resource/...s/wlscctrl2.cab
O16 - DPF: {49312E18-AA92-4CC2-BB97-55DEA7BCADD6} (WMI Class) - http://support.dell.com/systemprofiler/SysProExe.CAB
O16 - DPF: {7530BFB8-7293-4D34-9923-61A11451AFC5} (OnlineScanner Control) - http://download.eset.com/special/eos/OnlineScanner.cab
O16 - DPF: {BB21F850-63F4-4EC9-BF9D-565BD30C9AE9} (a-squared Scanner) - http://ax.emsisoft.com/asquared.cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/flas...ent/swflash.cab
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.DLL
O23 - Service: Acronis OS Selector Reinstall Service (AcronisOSSReinstallSvc) - Unknown owner - C:\Program Files\Common Files\Acronis\Acronis Disk Director\oss_reinstall_svc.exe
O23 - Service: Acronis Scheduler2 Service (AcrSch2Svc) - Acronis - C:\Program Files\Common Files\Acronis\Schedule2\schedul2.exe
O23 - Service: Avira AntiVir MailGuard (AntiVirMailService) - Avira GmbH - C:\Program Files\Avira\AntiVir Desktop\avmailc.exe
O23 - Service: Avira AntiVir Scheduler (AntiVirSchedulerService) - Avira GmbH - C:\Program Files\Avira\AntiVir Desktop\sched.exe
O23 - Service: Avira AntiVir Guard (AntiVirService) - Avira GmbH - C:\Program Files\Avira\AntiVir Desktop\avguard.exe
O23 - Service: Avira AntiVir WebGuard (AntiVirWebService) - Avira GmbH - C:\Program Files\Avira\AntiVir Desktop\AVWEBGRD.EXE
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: Ati External Event Utility - ATI Technologies Inc. - C:\Windows\system32\Ati2evxx.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: Diskeeper - Diskeeper Corporation - C:\Program Files\Diskeeper Corporation\Diskeeper\DkService.exe
O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: Intel® Matrix Storage Event Monitor (IAANTMON) - Intel Corporation - C:\Program Files\Intel\Intel Matrix Storage Manager\Iaantmon.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: NMSAccessU - Unknown owner - C:\Program Files\CDBurnerXP\NMSAccessU.exe
O23 - Service: TomTomHOMEService - TomTom - C:\Program Files\TomTom HOME 2\TomTomHOMEService.exe
O23 - Service: TrueVector Internet Monitor (vsmon) - Check Point Software Technologies LTD - C:\Windows\System32\ZoneLabs\vsmon.exe

--
End of file - 8022 bytes

======Scheduled tasks folder======

C:\Windows\tasks\User_Feed_Synchronization-{90901671-65A7-44EA-AD6C-A31DC88F5AC5}.job

======Registry dump======

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{18DF081C-E8AD-4283-A596-FA578C2EBDC3}]
Adobe PDF Link Helper - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll [2009-02-27 75128]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AA58ED58-01DD-4d91-8333-CF10577473F7}]
Google Toolbar Helper - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll [2009-08-26 256112]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AF69DE43-7D58-4638-B6FA-CE66B5AD205D}]
Google Toolbar Notifier BHO - C:\Program Files\Google\GoogleToolbarNotifier\5.2.4204.1700\swg.dll [2009-08-26 761840]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{C84D72FE-E17D-4195-BB24-76C02E2E7C4E}]
Google Dictionary Compression sdch - C:\Program Files\Google\Google Toolbar\Component\fastsearch_B7C5AC242193BB3E.dll [2009-08-26 458736]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
Java™ Plug-In 2 SSV Helper - C:\Program Files\Java\jre6\bin\jp2ssv.dll [2009-08-11 41760]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{EAEE5C74-6D0D-4aca-9232-0DA4A7B866BA}]
C:\Program Files\PicLensIE\cooliris.dll [2009-07-16 4700128]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
{2318C2B1-4965-11d4-9B18-009027A5CD4F} - Google Toolbar - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll [2009-08-26 256112]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"HP Software Update"=C:\Program Files\HP\HP Software Update\HPWuSchd2.exe [2006-12-10 49152]
"NoteBurner"=C:\Program Files\NoteBurner\VTBurnerGUI.exe [2009-07-01 5668864]
"WinPatrol"=C:\Program Files\BillP Studios\WinPatrol\winpatrol.exe [2009-07-27 341312]
"TrueImageMonitor.exe"=C:\Program Files\Acronis\TrueImageHome\TrueImageMonitor.exe [2009-06-22 4355464]
"AcronisTimounterMonitor"=C:\Program Files\Acronis\TrueImageHome\TimounterMonitor.exe [2009-06-22 960568]
"Acronis Scheduler2 Service"=C:\Program Files\Common Files\Acronis\Schedule2\schedhlp.exe [2009-06-22 377248]
"SigmatelSysTrayApp"=C:\Windows\sttray.exe [2007-01-12 303104]
"Google Quick Search Box"=C:\Program Files\Google\Quick Search Box\GoogleQuickSearchBox.exe [2009-06-24 68592]
"SunJavaUpdateSched"=C:\Program Files\Java\jre6\bin\jusched.exe [2009-08-11 149280]
"Malwarebytes Anti-Malware (reboot)"=C:\Program Files\Malwarebytes' Anti-Malware\mbam.exe [2009-09-10 1312080]
"iTunesHelper"=C:\Program Files\iTunes\iTunesHelper.exe [2009-09-21 305440]
"avgnt"=C:\Program Files\Avira\AntiVir Desktop\avgnt.exe [2009-03-02 209153]
"ZoneAlarm Client"=C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe [2009-09-23 1011080]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"swg"=C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe [2009-06-24 39408]
"WMPNSCFG"=C:\Program Files\Windows Media Player\WMPNSCFG.exe [2008-01-19 202240]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\!SASWinLogon]
C:\Program Files\SUPERAntiSpyware\SASWINLO.DLL [2009-09-05 548352]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"=C:\Program Files\SUPERAntiSpyware\SASSEH.DLL [2008-05-13 77824]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Windows SteadyState]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\vsmon]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\Windows SteadyState]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\WudfPf]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\WudfRd]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\WudfSvc]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\WudfUsbccidDriver]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"EnableLUA"=0
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=0
"undockwithoutlogon"=1
"EnableUIADesktopToggle"=0
"HideFastUserSwitching"=1

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDriveTypeAutoRun"=145

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"BindDirectlyToPropertySetStorage"=

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]

======File associations======

.js - edit - C:\Windows\System32\Notepad.exe %1
.js - open - C:\Windows\System32\WScript.exe "%1" %*

======List of files/folders created in the last 1 months======

2009-10-05 21:03:17 ----D---- C:\rsit
2009-09-30 23:09:56 ----A---- C:\Windows\system32\imageres.dll
2009-09-30 22:40:29 ----A---- C:\Windows\system32\vsregexp.dll
2009-09-30 22:40:28 ----A---- C:\Windows\system32\zlcommdb.dll
2009-09-30 22:40:28 ----A---- C:\Windows\system32\zlcomm.dll
2009-09-30 22:40:25 ----A---- C:\Windows\system32\zpeng25.dll
2009-09-30 22:40:25 ----A---- C:\Windows\system32\vsxml.dll
2009-09-30 22:40:25 ----A---- C:\Windows\system32\vswmi.dll
2009-09-30 22:40:24 ----A---- C:\Windows\system32\vspubapi.dll
2009-09-30 22:40:24 ----A---- C:\Windows\system32\vsmonapi.dll
2009-09-30 22:40:24 ----A---- C:\Windows\system32\vsdata.dll
2009-09-30 22:40:11 ----D---- C:\Windows\system32\ZoneLabs
2009-09-30 22:40:11 ----D---- C:\Program Files\Zone Labs
2009-09-30 22:39:36 ----D---- C:\ProgramData\CheckPoint
2009-09-30 22:39:34 ----D---- C:\Windows\Internet Logs
2009-09-30 22:39:34 ----A---- C:\Windows\system32\vsutil.dll
2009-09-30 22:39:34 ----A---- C:\Windows\system32\vsinit.dll
2009-09-30 22:37:33 ----D---- C:\Program Files\Windows SteadyState
2009-09-30 20:29:44 ----RSHD---- C:\bootwiz
2009-09-29 21:50:14 ----A---- C:\Windows\asquared.ini
2009-09-28 21:40:54 ----D---- C:\Program Files\iPod
2009-09-28 21:40:51 ----D---- C:\Program Files\iTunes
2009-09-22 21:49:55 ----D---- C:\Program Files\Microsoft Windows 7 Upgrade Advisor
2009-09-21 23:13:32 ----D---- C:\Program Files\Windows Live Safety Center
2009-09-20 20:43:10 ----A---- C:\Windows\system32\GEARAspi.dll
2009-09-20 20:42:34 ----D---- C:\ProgramData\{755AC846-7372-4AC8-8550-C52491DAA8BD}
2009-09-20 20:41:00 ----D---- C:\Program Files\QuickTime
2009-09-16 22:54:05 ----A---- C:\RootRepeal report 09-16-09 (22-54-05).txt
2009-09-08 21:23:42 ----A---- C:\Windows\system32\jscript.dll
2009-09-08 21:23:26 ----A---- C:\Windows\system32\netiohlp.dll
2009-09-08 21:23:25 ----A---- C:\Windows\system32\TCPSVCS.EXE
2009-09-08 21:23:25 ----A---- C:\Windows\system32\ROUTE.EXE
2009-09-08 21:23:25 ----A---- C:\Windows\system32\NETSTAT.EXE
2009-09-08 21:23:25 ----A---- C:\Windows\system32\netevent.dll
2009-09-08 21:23:25 ----A---- C:\Windows\system32\MRINFO.EXE
2009-09-08 21:23:25 ----A---- C:\Windows\system32\HOSTNAME.EXE
2009-09-08 21:23:25 ----A---- C:\Windows\system32\finger.exe
2009-09-08 21:23:25 ----A---- C:\Windows\system32\ARP.EXE
2009-09-08 21:23:02 ----A---- C:\Windows\system32\WMVCORE.DLL
2009-09-08 21:23:01 ----A---- C:\Windows\system32\mf.dll
2009-09-08 21:22:59 ----A---- C:\Windows\system32\wlansec.dll
2009-09-08 21:22:59 ----A---- C:\Windows\system32\wlanmsm.dll
2009-09-08 21:22:59 ----A---- C:\Windows\system32\L2SecHC.dll
2009-09-08 21:22:58 ----A---- C:\Windows\system32\wlansvc.dll
2009-09-08 21:22:58 ----A---- C:\Windows\system32\wlanapi.dll

======List of files/folders modified in the last 1 months======

2009-10-05 21:03:24 ----D---- C:\Windows\Prefetch
2009-10-05 21:03:21 ----D---- C:\Windows\Temp
2009-10-05 14:30:55 ----SHD---- C:\System Volume Information
2009-10-05 13:50:09 ----D---- C:\Windows\System32
2009-10-05 13:50:09 ----D---- C:\Windows\inf
2009-10-05 13:50:09 ----A---- C:\Windows\system32\PerfStringBackup.INI
2009-10-03 23:43:27 ----D---- C:\Program Files\Mozilla Firefox
2009-10-03 22:18:21 ----D---- C:\Windows
2009-10-03 16:30:11 ----D---- C:\Program Files\CDBurnerXP
2009-10-03 13:01:39 ----D---- C:\Windows\system32\drivers
2009-10-01 23:28:06 ----AD---- C:\ProgramData\TEMP
2009-09-30 23:00:29 ----D---- C:\Program Files\SpywareBlaster
2009-09-30 22:40:23 ----D---- C:\Windows\system32\catroot
2009-09-30 22:40:11 ----RD---- C:\Program Files
2009-09-30 22:39:36 ----HD---- C:\ProgramData
2009-09-30 22:37:38 ----SHD---- C:\Windows\Installer
2009-09-30 22:37:34 ----SD---- C:\ProgramData\Microsoft
2009-09-30 21:03:26 ----D---- C:\Program Files\Common Files\Acronis
2009-09-30 21:03:24 ----D---- C:\Program Files\Acronis
2009-09-30 20:53:54 ----D---- C:\ProgramData\Acronis
2009-09-30 20:30:05 ----D---- C:\Windows\winsxs
2009-09-29 21:46:34 ----SD---- C:\Windows\Downloaded Program Files
2009-09-29 21:40:31 ----D---- C:\ProgramData\ZoomBrowser
2009-09-28 21:40:53 ----D---- C:\Program Files\Common Files\Apple
2009-09-25 19:25:50 ----D---- C:\Windows\system32\catroot2
2009-09-21 21:17:46 ----D---- C:\Program Files\Common Files
2009-09-20 20:43:10 ----DC---- C:\Windows\system32\DRVSTORE
2009-09-20 20:33:13 ----D---- C:\Program Files\Autoruns
2009-09-18 22:21:28 ----D---- C:\Program Files\SUPERAntiSpyware
2009-09-16 22:25:43 ----D---- C:\Windows\Tasks
2009-09-16 21:40:48 ----D---- C:\Windows\system32\LogFiles
2009-09-16 20:35:41 ----D---- C:\Windows\system32\WDI
2009-09-16 09:43:43 ----D---- C:\Windows\system32\Tasks
2009-09-11 20:55:40 ----D---- C:\Windows\Debug
2009-09-10 21:38:42 ----D---- C:\Program Files\Malwarebytes' Anti-Malware
2009-09-09 07:51:59 ----D---- C:\Windows\rescache
2009-09-08 21:28:46 ----D---- C:\Program Files\Microsoft Silverlight
2009-09-08 21:27:59 ----D---- C:\Windows\system32\en-US
2009-09-08 21:24:48 ----D---- C:\Program Files\Windows Mail
2009-09-08 21:24:30 ----D---- C:\ProgramData\Microsoft Help
2009-09-08 21:24:00 ----D---- C:\Windows\ehome

======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R1 avgio;avgio; \??\C:\Program Files\Avira\AntiVir Desktop\avgio.sys [2009-02-13 11608]
R1 avipbb;avipbb; C:\Windows\system32\DRIVERS\avipbb.sys [2009-03-30 96104]
R1 SASDIFSV;SASDIFSV; \??\C:\Program Files\SUPERAntiSpyware\SASDIFSV.SYS [2009-05-26 9968]
R1 SASKUTIL;SASKUTIL; \??\C:\Program Files\SUPERAntiSpyware\SASKUTIL.sys [2009-08-06 74480]
R1 ssmdrv;ssmdrv; C:\Windows\system32\DRIVERS\ssmdrv.sys [2009-05-11 28520]
R1 Vsdatant;Zone Alarm Firewall Driver; C:\Windows\system32\DRIVERS\vsdatant.sys [2009-09-23 443080]
R2 avgntflt;avgntflt; C:\Windows\system32\DRIVERS\avgntflt.sys [2009-08-06 55656]
R2 tifsfilter;Acronis True Image FS Filter; C:\Windows\system32\DRIVERS\tifsfilt.sys [2009-06-20 44704]
R3 atikmdag;atikmdag; C:\Windows\system32\DRIVERS\atikmdag.sys [2009-02-04 4303360]
R3 E100B;Intel® PRO Network Connection Driver; C:\Windows\system32\DRIVERS\e100b325.sys [2007-11-16 165496]
R3 GEARAspiWDM;GEAR ASPI Filter Driver; C:\Windows\system32\DRIVERS\GEARAspiWDM.sys [2009-05-18 26600]
R3 STHDA;SigmaTel High Definition Audio CODEC; C:\Windows\system32\drivers\stwrt.sys [2007-01-12 647680]
R3 VST_DPV;VST_DPV; C:\Windows\system32\DRIVERS\VSTDPV3.SYS [2006-11-02 987648]
R3 VSTHWBS2;VSTHWBS2; C:\Windows\system32\DRIVERS\VSTBS23.SYS [2006-11-02 251904]
R3 winachsf;winachsf; C:\Windows\system32\DRIVERS\VSTCNXT3.SYS [2006-11-02 654336]
S3 Dot4;MS IEEE-1284.4 Driver; C:\Windows\system32\DRIVERS\Dot4.sys [2008-01-19 131584]
S3 Dot4Print;Print Class Driver for IEEE-1284.4; C:\Windows\system32\DRIVERS\Dot4Prt.sys [2008-01-19 16384]
S3 dot4usb;MS Dot4USB Filter Dot4USB Filter; C:\Windows\system32\DRIVERS\dot4usb.sys [2008-01-19 36864]
S3 drmkaud;Microsoft Kernel DRM Audio Descrambler; C:\Windows\system32\drivers\drmkaud.sys [2008-01-19 5632]
S3 HdAudAddService;Microsoft 1.1 UAA Function Driver for High Definition Audio Service; C:\Windows\system32\drivers\HdAudio.sys [2006-11-02 235520]
S3 MSKSSRV;Microsoft Streaming Service Proxy; C:\Windows\system32\drivers\MSKSSRV.sys [2008-01-19 8192]
S3 MSPCLOCK;Microsoft Streaming Clock Proxy; C:\Windows\system32\drivers\MSPCLOCK.sys [2008-01-19 5888]
S3 MSPQM;Microsoft Streaming Quality Manager Proxy; C:\Windows\system32\drivers\MSPQM.sys [2008-01-19 5504]
S3 MSTEE;Microsoft Streaming Tee/Sink-to-Sink Converter; C:\Windows\system32\drivers\MSTEE.sys [2008-01-19 6016]
S3 PSI;PSI; C:\Windows\system32\DRIVERS\psi_mf.sys [2009-06-17 12648]
S3 R300;R300; C:\Windows\system32\DRIVERS\atikmdag.sys [2009-02-04 4303360]
S3 SASENUM;SASENUM; \??\C:\Program Files\SUPERAntiSpyware\SASENUM.SYS [2009-05-26 7408]
S3 StarOpen;StarOpen; C:\Windows\system32\drivers\StarOpen.sys [2009-09-28 7168]
S3 usbscan;USB Scanner Driver; C:\Windows\system32\DRIVERS\usbscan.sys [2008-01-19 35328]
S3 vsdatant7;vsdatant7; C:\Windows\System32\drivers\vsdatant.win7.sys []
S3 WpdUsb;WpdUsb; C:\Windows\system32\DRIVERS\wpdusb.sys [2008-01-19 39936]
S3 WUDFRd;WUDFRd; C:\Windows\system32\DRIVERS\WUDFRd.sys [2008-01-19 83328]
S4 WmiAcpi;Microsoft Windows Management Interface for ACPI; C:\Windows\system32\drivers\wmiacpi.sys [2006-11-02 11264]

======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R2 AcrSch2Svc;Acronis Scheduler2 Service; C:\Program Files\Common Files\Acronis\Schedule2\schedul2.exe [2009-06-22 618944]
R2 AntiVirMailService;Avira AntiVir MailGuard; C:\Program Files\Avira\AntiVir Desktop\avmailc.exe [2009-05-11 194817]
R2 AntiVirSchedulerService;Avira AntiVir Scheduler; C:\Program Files\Avira\AntiVir Desktop\sched.exe [2009-05-13 108289]
R2 AntiVirService;Avira AntiVir Guard; C:\Program Files\Avira\AntiVir Desktop\avguard.exe [2009-08-06 185089]
R2 AntiVirWebService;Avira AntiVir WebGuard; C:\Program Files\Avira\AntiVir Desktop\AVWEBGRD.EXE [2009-05-12 434945]
R2 Apple Mobile Device;Apple Mobile Device; C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe [2009-05-29 144712]
R2 Ati External Event Utility;Ati External Event Utility; C:\Windows\system32\Ati2evxx.exe [2009-02-04 729088]
R2 BcmSqlStartupSvc;Business Contact Manager SQL Server Startup Service; C:\Program Files\Microsoft Small Business\Business Contact Manager\BcmSqlStartupSvc.exe [2008-01-11 30312]
R2 Bonjour Service;Bonjour Service; C:\Program Files\Bonjour\mDNSResponder.exe [2008-12-12 238888]
R2 Diskeeper;Diskeeper; C:\Program Files\Diskeeper Corporation\Diskeeper\DkService.exe [2009-04-17 1349912]
R2 hpqddsvc;HP CUE DeviceDiscovery Service; C:\Windows\system32\svchost.exe [2008-01-19 21504]
R2 IAANTMON;Intel® Matrix Storage Event Monitor; C:\Program Files\Intel\Intel Matrix Storage Manager\Iaantmon.exe [2007-10-03 358936]
R2 Net Driver HPZ12;Net Driver HPZ12; C:\Windows\System32\svchost.exe [2008-01-19 21504]
R2 NMSAccessU;NMSAccessU; C:\Program Files\CDBurnerXP\NMSAccessU.exe [2008-10-20 71096]
R2 Pml Driver HPZ12;Pml Driver HPZ12; C:\Windows\System32\svchost.exe [2008-01-19 21504]
R2 SQLBrowser;SQL Server Browser; c:\Program Files\Microsoft SQL Server\90\Shared\sqlbrowser.exe [2008-11-24 239968]
R2 SQLWriter;SQL Server VSS Writer; c:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe [2008-11-24 87904]
R2 TomTomHOMEService;TomTomHOMEService; C:\Program Files\TomTom HOME 2\TomTomHOMEService.exe [2009-08-27 92008]
R2 vsmon;TrueVector Internet Monitor; C:\Windows\System32\ZoneLabs\vsmon.exe [2009-09-23 2383728]
R2 Windows SteadyState;Windows SteadyState Service; C:\Program Files\Windows SteadyState\SCTSvc.exe [2008-05-30 115728]
R2 wlidsvc;Windows Live ID Sign-in Assistant; C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE [2009-03-30 1533808]
R3 hpqcxs08;hpqcxs08; C:\Windows\system32\svchost.exe [2008-01-19 21504]
R3 iPod Service;iPod Service; C:\Program Files\iPod\bin\iPodService.exe [2009-09-21 545568]
S2 AcronisOSSReinstallSvc;Acronis OS Selector Reinstall Service; C:\Program Files\Common Files\Acronis\Acronis Disk Director\oss_reinstall_svc.exe [2009-09-22 2131136]
S3 gusvc;Google Software Updater; C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe [2009-06-24 182768]
S3 MSSQL$MSSMLBIZ;SQL Server (MSSMLBIZ); c:\Program Files\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\sqlservr.exe [2008-11-24 29263712]
S3 odserv;Microsoft Office Diagnostics Service; C:\Program Files\Common Files\Microsoft Shared\OFFICE12\ODSERV.EXE [2008-11-04 441712]
S3 ose;Office Source Engine; C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2006-10-26 145184]
S4 MSSQLServerADHelper;SQL Server Active Directory Helper; c:\Program Files\Microsoft SQL Server\90\Shared\sqladhlp90.exe [2008-11-24 45408]

-----------------EOF-----------------


INFO.txt from RSIT Tool

info.txt logfile of random's system information tool 1.06 2009-10-05 21:03:26

======Uninstall list======

-->MsiExec.exe /I{403EF592-953B-4794-BCEF-ECAB835C2095}
32 Bit HP CIO Components Installer-->MsiExec.exe /I{2614F54E-A828-49FA-93BA-45A3F756BFAA}
Acronis Disk Director Suite-->MsiExec.exe /X{2300EE96-0A41-4FAB-BD03-989EC44577A0}
Acronis True Image Home-->MsiExec.exe /X{D1E0E859-F46D-4708-A41D-ED90C0C1822A}
Adobe Flash Player 10 ActiveX-->C:\Windows\system32\Macromed\Flash\uninstall_activeX.exe
Adobe Flash Player 10 Plugin-->C:\Windows\system32\Macromed\Flash\uninstall_plugin.exe
Adobe Reader 9.1.3-->MsiExec.exe /I{AC76BA86-7AD7-1033-7B44-A91000000001}
Adobe Shockwave Player 11.5-->"C:\Windows\system32\Adobe\Shockwave 11\uninstaller.exe"
Apple Application Support-->MsiExec.exe /I{0C34B801-6AEC-4667-B053-03A67E2D0415}
Apple Mobile Device Support-->MsiExec.exe /I{AADEA55D-C834-4BCB-98A3-4B8D1C18F4EE}
Apple Software Update-->MsiExec.exe /I{6956856F-B6B3-4BE0-BA0B-8F495BE32033}
Avira AntiVir Premium-->C:\Program Files\Avira\AntiVir Desktop\setup.exe /REMOVE
Belarc Advisor 8.1-->"C:\PROGRA~1\Belarc\Advisor\Uninstall.exe" "C:\PROGRA~1\Belarc\Advisor\INSTALL.LOG"
Bonjour-->MsiExec.exe /I{07287123-B8AC-41CE-8346-3D777245C35B}
Business Contact Manager for Outlook 2007 SP2-->"C:\Program Files\Microsoft Small Business\Business Contact Manager\SetupBootstrap\Setup.exe" /remove {B32C4059-6E7A-41EF-AD20-56DF1872B923}
Business Contact Manager for Outlook 2007 SP2-->MsiExec.exe /X{B32C4059-6E7A-41EF-AD20-56DF1872B923}
Canon G.726 WMP-Decoder-->"C:\Program Files\Common Files\Canon\UIW\1.0.0.0\Uninst.exe" "C:\Program Files\Canon\G726Decoder\G726DecUnInstall.ini"
Canon MovieEdit Task for ZoomBrowser EX-->"C:\Program Files\Common Files\Canon\UIW\1.0.0.0\Uninst.exe" "C:\Program Files\Canon\ZoomBrowser EX\Program\MVWUninst.ini"
Canon RAW Image Task for ZoomBrowser EX-->"C:\Program Files\Common Files\Canon\UIW\1.0.0.0\Uninst.exe" "C:\Program Files\Canon\RAW Image Task\Uninst.ini"
Canon Utilities CameraWindow DC_DV 6 for ZoomBrowser EX-->"C:\Program Files\Common Files\Canon\UIW\1.5.0.0\Uninst.exe" "C:\Program Files\Canon\CameraWindow\CameraWindowDVC6\Uninst.ini"
Canon Utilities CameraWindow DC-->"C:\Program Files\Common Files\Canon\UIW\1.5.0.0\Uninst.exe" "C:\Program Files\Canon\CameraWindow\CameraWindowDC\Uninst.ini"
Canon Utilities CameraWindow-->"C:\Program Files\Common Files\Canon\UIW\1.5.0.0\Uninst.exe" "C:\Program Files\Canon\CameraWindow\CameraWindowLauncher\Uninst.ini"
Canon Utilities EOS Utility-->"C:\Program Files\Common Files\Canon\UIW\1.0.0.0\Uninst.exe" "C:\Program Files\Canon\EOS Utility\Uninst.ini"
Canon Utilities MyCamera DC-->"C:\Program Files\Common Files\Canon\UIW\1.5.0.0\Uninst.exe" "C:\Program Files\Canon\CameraWindow\MyCameraDC\Uninst.ini"
Canon Utilities MyCamera-->"C:\Program Files\Common Files\Canon\UIW\1.5.0.0\Uninst.exe" "C:\Program Files\Canon\CameraWindow\MyCamera\Uninst.ini"
Canon Utilities PhotoStitch-->"C:\Program Files\Common Files\Canon\UIW\1.3.0.0\Uninst.exe" "C:\Program Files\Canon\PhotoStitch\Uninst.ini"
Canon Utilities RemoteCapture DC-->"C:\Program Files\Common Files\Canon\UIW\1.5.0.0\Uninst.exe" "C:\Program Files\Canon\CameraWindow\RemoteCaptureDC\Uninst.ini"
Canon Utilities RemoteCapture Task for ZoomBrowser EX-->"C:\Program Files\Common Files\Canon\UIW\1.5.0.0\Uninst.exe" "C:\Program Files\Canon\CameraWindow\RemoteCaptureTask DC\Uninst.ini"
Canon Utilities ZoomBrowser EX-->"C:\Program Files\Common Files\Canon\UIW\1.5.0.0\Uninst.exe" "C:\Program Files\Canon\ZoomBrowser EX\Program\Uninst.ini"
Canon ZoomBrowser EX Memory Card Utility-->"C:\Program Files\Common Files\Canon\UIW\1.5.0.0\Uninst.exe" "C:\Program Files\Canon\ZoomBrowser EX MCU\Uninst.ini"
Catalyst Control Center - Branding-->MsiExec.exe /I{D3B1C799-CB73-42DE-BA0F-2344793A095C}
CCleaner (remove only)-->"C:\Program Files\CCleaner\uninst.exe"
CDBurnerXP-->"C:\Program Files\CDBurnerXP\unins000.exe"
CodeStuff Starter-->"C:\Program Files\CodeStuff\Starter\unStarter.exe"
Cooliris for Internet Explorer-->MsiExec.exe /I{28114F32-A828-3B57-802B-1F300B0948C7}
Darkness Within: In Pursuit of Loath Nolder 1.00-->"C:\Program Files\Darkness Within\unins000.exe"
Debugging Tools for Windows (x86)-->MsiExec.exe /I{300A2961-B2B5-4889-9CB9-5C2A570D08AD}
Diskeeper 2009 Professional-->MsiExec.exe /X{0B885087-DDD3-49F3-A003-463A5BE81A9D}
ERUNT 1.1j-->"C:\Program Files\ERUNT\unins000.exe"
ESET Online Scanner v3-->C:\Program Files\ESET\ESET Online Scanner\OnlineScannerUninstaller.exe
EVEREST Home Edition v2.20-->"C:\Program Files\Lavalys\EVEREST Home Edition\unins000.exe"
Free YouTube to Mp3 Converter version 3.1-->"C:\Program Files\DVDVideoSoft\Free YouTube to Mp3 Converter\unins000.exe"
Google Toolbar for Internet Explorer-->"C:\Program Files\Google\Google Toolbar\Component\GoogleToolbarManager_E582EA556D8DE101.exe" /uninstall
Google Toolbar for Internet Explorer-->MsiExec.exe /I{18455581-E099-4BA8-BC6B-F34B2F06600C}
HijackThis 2.0.2-->"C:\Program Files\Trend Micro\HijackThis\HijackThis.exe" /uninstall
Hotfix for Microsoft .NET Framework 3.5 SP1 (KB953595)-->C:\Windows\system32\msiexec.exe /package {CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9} /uninstall /qb+ REBOOTPROMPT=""
Hotfix for Microsoft .NET Framework 3.5 SP1 (KB958484)-->C:\Windows\system32\msiexec.exe /package {CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9} /uninstall {A7EEA2F2-BFCD-4A54-A575-7B81A786E658} /qb+ REBOOTPROMPT=""
HP Imaging Device Functions 8.0-->C:\Program Files\HP\Digital Imaging\DeviceManagement\hpzscr01.exe -datfile hpqbud01.dat
HP OCR Software 8.0-->C:\Program Files\HP\Digital Imaging\OCR\hpzscr01.exe -datfile hpqbud11.dat
HP Photosmart Essential-->MsiExec.exe /X{EB21A812-671B-4D08-B974-2A347F0D8F70}
HP Photosmart, Officejet, PSC and Deskjet All-In-One Driver Software 8.0.B-->C:\Program Files\HP\Digital Imaging\{C916D86C-AB76-49c7-B0E4-A946E0FD9BC2}\setup\hpzscr01.exe -datfile hposcr19.dat -onestop -showdisconnect -forcereboot
HP Print Diagnostic Utility-->MsiExec.exe /I{E14B8A08-42B3-4676-9E91-1D39F8158DA1}
HP Product Assistant-->MsiExec.exe /I{36FDBE6E-6684-462B-AE98-9A39A1B200CC}
HP Solution Center 8.0-->C:\Program Files\HP\Digital Imaging\eSupport\hpzscr01.exe -datfile hpqbud05.dat
HP Update-->MsiExec.exe /X{25771101-7948-4591-ABF3-B1ECE7A7F45F}
ImgBurn-->"C:\Program Files\ImgBurn\uninstall.exe"
Intel® Matrix Storage Manager-->C:\Windows\System32\Imsmudlg.exe
Intel® Network Connections 14.0.40.0-->MsiExec.exe /i{888019C0-54D4-40C2-9274-27B9DAB17017} ARPREMOVE=1
Intel® Network Connections 14.0.40.0-->MsiExec.exe /i{888019C0-54D4-40C2-9274-27B9DAB17017} ARPREMOVE=1
iTunes-->MsiExec.exe /I{DA34FE93-5DC5-48E0-ACC8-A5389E05BB51}
Java™ 6 Update 16-->MsiExec.exe /X{26A24AE4-039D-4CA4-87B4-2F83216016FF}
jv16 PowerTools 2009-->"C:\Program Files\jv16 PowerTools 2009\unins000.exe"
KeePass Password Safe 2.08-->"C:\Program Files\KeePass Password Safe 2\unins000.exe"
LifeWare 3.0-->"C:\Program Files\LifeWare\uninstall.exe"
LogonStudio Vista-->C:\PROGRA~1\Stardock\OBJECT~1\LOGONS~1\UNWISE.EXE C:\PROGRA~1\Stardock\OBJECT~1\LOGONS~1\INSTALL.LOG
Malwarebytes' Anti-Malware-->"C:\Program Files\Malwarebytes' Anti-Malware\unins000.exe"
Microsoft .NET Framework 3.5 SP1-->c:\Windows\Microsoft.NET\Framework\v3.5\Microsoft .NET Framework 3.5 SP1\setup.exe
Microsoft .NET Framework 3.5 SP1-->MsiExec.exe /I{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}
Microsoft Office 2003 Web Components-->MsiExec.exe /I{90A40409-6000-11D3-8CFE-0150048383C9}
Microsoft Office 2007 Primary Interop Assemblies-->MsiExec.exe /X{50120000-1105-0000-0000-0000000FF1CE}
Microsoft Office 2007 Service Pack 2 (SP2)-->msiexec /package {90120000-0015-0409-0000-0000000FF1CE} /uninstall {2FC4457D-409E-466F-861F-FB0CB796B53E}
Microsoft Office 2007 Service Pack 2 (SP2)-->msiexec /package {90120000-0016-0409-0000-0000000FF1CE} /uninstall {2FC4457D-409E-466F-861F-FB0CB796B53E}
Microsoft Office 2007 Service Pack 2 (SP2)-->msiexec /package {90120000-0018-0409-0000-0000000FF1CE} /uninstall {2FC4457D-409E-466F-861F-FB0CB796B53E}
Microsoft Office 2007 Service Pack 2 (SP2)-->msiexec /package {90120000-0019-0409-0000-0000000FF1CE} /uninstall {2FC4457D-409E-466F-861F-FB0CB796B53E}
Microsoft Office 2007 Service Pack 2 (SP2)-->msiexec /package {90120000-001A-0409-0000-0000000FF1CE} /uninstall {2FC4457D-409E-466F-861F-FB0CB796B53E}
Microsoft Office 2007 Service Pack 2 (SP2)-->msiexec /package {90120000-001B-0409-0000-0000000FF1CE} /uninstall {2FC4457D-409E-466F-861F-FB0CB796B53E}
Microsoft Office 2007 Service Pack 2 (SP2)-->msiexec /package {90120000-006E-0409-0000-0000000FF1CE} /uninstall {DE5A002D-8122-4278-A7EE-3121E7EA254E}
Microsoft Office 2007 Service Pack 2 (SP2)-->msiexec /package {90120000-0115-0409-0000-0000000FF1CE} /uninstall {DE5A002D-8122-4278-A7EE-3121E7EA254E}
Microsoft Office 2007 Service Pack 2 (SP2)-->msiexec /package {90120000-0117-0409-0000-0000000FF1CE} /uninstall {2FC4457D-409E-466F-861F-FB0CB796B53E}
Microsoft Office 2007 Service Pack 2 (SP2)-->msiexec /package {91120000-0014-0000-0000-0000000FF1CE} /uninstall {0B36C6D6-F5D8-4EAF-BF94-4376A230AD5B}
Microsoft Office Access MUI (English) 2007-->MsiExec.exe /X{90120000-0015-0409-0000-0000000FF1CE}
Microsoft Office Access Setup Metadata MUI (English) 2007-->MsiExec.exe /X{90120000-0117-0409-0000-0000000FF1CE}
Microsoft Office Excel MUI (English) 2007-->MsiExec.exe /X{90120000-0016-0409-0000-0000000FF1CE}
Microsoft Office Live Add-in 1.4-->MsiExec.exe /I{AE3CF174-872C-46C6-B9F6-C0593F3BC7B8}
Microsoft Office Outlook MUI (English) 2007-->MsiExec.exe /X{90120000-001A-0409-0000-0000000FF1CE}
Microsoft Office PowerPoint MUI (English) 2007-->MsiExec.exe /X{90120000-0018-0409-0000-0000000FF1CE}
Microsoft Office Professional 2007-->"C:\Program Files\Common Files\Microsoft Shared\OFFICE12\Office Setup Controller\setup.exe" /uninstall PROR /dll OSETUP.DLL
Microsoft Office Professional 2007-->MsiExec.exe /X{91120000-0014-0000-0000-0000000FF1CE}
Microsoft Office Proof (English) 2007-->MsiExec.exe /X{90120000-001F-0409-0000-0000000FF1CE}
Microsoft Office Proof (French) 2007-->MsiExec.exe /X{90120000-001F-040C-0000-0000000FF1CE}
Microsoft Office Proof (Spanish) 2007-->MsiExec.exe /X{90120000-001F-0C0A-0000-0000000FF1CE}
Microsoft Office Proofing (English) 2007-->MsiExec.exe /X{90120000-002C-0409-0000-0000000FF1CE}
Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)-->msiexec /package {90120000-001F-0409-0000-0000000FF1CE} /uninstall {ABDDE972-355B-4AF1-89A8-DA50B7B5C045}
Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)-->msiexec /package {90120000-001F-040C-0000-0000000FF1CE} /uninstall {F580DDD5-8D37-4998-968E-EBB76BB86787}
Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)-->msiexec /package {90120000-001F-0C0A-0000-0000000FF1CE} /uninstall {187308AB-5FA7-4F14-9AB9-D290383A10D9}
Microsoft Office Publisher MUI (English) 2007-->MsiExec.exe /X{90120000-0019-0409-0000-0000000FF1CE}
Microsoft Office Shared MUI (English) 2007-->MsiExec.exe /X{90120000-006E-0409-0000-0000000FF1CE}
Microsoft Office Shared Setup Metadata MUI (English) 2007-->MsiExec.exe /X{90120000-0115-0409-0000-0000000FF1CE}
Microsoft Office Small Business Connectivity Components-->MsiExec.exe /X{A939D341-5A04-4E0A-BB55-3E65B386432D}
Microsoft Office Word MUI (English) 2007-->MsiExec.exe /X{90120000-001B-0409-0000-0000000FF1CE}
Microsoft Save as PDF or XPS Add-in for 2007 Microsoft Office programs-->MsiExec.exe /X{90120000-00B2-0409-0000-0000000FF1CE}
Microsoft Silverlight-->MsiExec.exe /X{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}
Microsoft SQL Server 2005 Express Edition (MSSMLBIZ)-->MsiExec.exe /I{2AFFFDD7-ED85-4A90-8C52-5DA9EBDC9B8F}
Microsoft SQL Server 2005-->"c:\Program Files\Microsoft SQL Server\90\Setup Bootstrap\ARPWrapper.exe" /Remove
Microsoft SQL Server Native Client-->MsiExec.exe /I{BD68F46D-8A82-4664-8E68-F87C55BDEFD4}
Microsoft SQL Server Setup Support Files (English)-->MsiExec.exe /X{53F5C3EE-05ED-4830-994B-50B2F0D50FCE}
Microsoft SQL Server VSS Writer-->MsiExec.exe /I{56B4002F-671C-49F4-984C-C760FE3806B5}
Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053-->MsiExec.exe /X{770657D0-A123-3C07-8E44-1C83EC895118}
Microsoft Visual C++ 2005 Redistributable-->MsiExec.exe /X{A49F249F-0C91-497F-86DF-B2585E8E76B7}
Microsoft Visual C++ 2008 ATL Update kb973924 - x86 9.0.30729.4148-->MsiExec.exe /X{002D9D5E-29BA-3E6D-9BC4-3D7D6DBC735C}
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17-->MsiExec.exe /X{9A25302D-30C0-39D9-BD6F-21E6EC160475}
MixMeister BPM Analyzer 1.0-->"C:\Program Files\MixMeister BPM Analyzer\unins000.exe"
Mozilla Firefox (3.5.3)-->C:\Program Files\Mozilla Firefox\uninstall\helper.exe
MSXML 4.0 SP2 (KB954430)-->MsiExec.exe /I{86493ADD-824D-4B8E-BD72-8C5DCDC52A71}
Next Life US 1.2.16-->"C:\Program Files\The Adventure Company\Next Life\unins000.exe"
NoteBurner 2.30-->"C:\Program Files\NoteBurner\unins000.exe"
OpenAL-->"C:\Program Files\OpenAL\Oalinst.exe" /U
Print Server-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{E6FCE5FA-B7B7-4B7E-B4FB-A8929BC3FB0F}\Setup.exe" -uninst
QuickTime-->MsiExec.exe /I{A429C2AE-EBF1-4F81-A221-1C115CAADDAD}
Real Alternative 1.9.0-->"C:\Program Files\Real Alternative\unins000.exe"
Revo Uninstaller 1.83-->C:\Program Files\VS Revo Group\Revo Uninstaller\uninst.exe
Secunia PSI-->"C:\Program Files\Secunia\PSI\uninstall.exe"
Security Update for 2007 Microsoft Office System (KB969559)-->msiexec /package {91120000-0014-0000-0000-0000000FF1CE} /uninstall {69F52148-9BF6-4CDC-BF76-103DEAF3DD08}
Security Update for 2007 Microsoft Office System (KB969679)-->msiexec /package {91120000-0014-0000-0000-0000000FF1CE} /uninstall {C66E4A6C-6E07-4C63-8CCD-2493B5087C73}
Security Update for Microsoft Office Excel 2007 (KB969682)-->msiexec /package {91120000-0014-0000-0000-0000000FF1CE} /uninstall {C03803BD-745A-46F8-8557-817DED578780}
Security Update for Microsoft Office PowerPoint 2007 (KB957789)-->msiexec /package {91120000-0014-0000-0000-0000000FF1CE} /uninstall {7559E742-FF9F-4FAE-B279-008ED296CB4D}
Security Update for Microsoft Office Publisher 2007 (KB969693)-->msiexec /package {91120000-0014-0000-0000-0000000FF1CE} /uninstall {7BE67088-1EB3-4569-8E75-DDAFBF61BC4E}
Security Update for Microsoft Office system 2007 (KB969613)-->msiexec /package {91120000-0014-0000-0000-0000000FF1CE} /uninstall {5ECEB317-CBE9-4E08-AB10-756CB6F0FB6C}
Security Update for Microsoft Office Word 2007 (KB969604)-->msiexec /package {91120000-0014-0000-0000-0000000FF1CE} /uninstall {CF3D6499-709C-43D0-8908-BC5652656050}
SigmaTel Audio-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\10\01\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{A462213D-EED4-42C2-9A60-7BDD4D4B0B17}\setup.exe" -l0x9 -remove -removeonly
Spelling Dictionaries Support For Adobe Reader 9-->MsiExec.exe /I{AC76BA86-7AD7-5464-3428-900000000004}
SpywareBlaster 4.2-->"C:\Program Files\SpywareBlaster\unins000.exe"
SUPERAntiSpyware Free Edition-->MsiExec.exe /X{CDDCBBF1-2703-46BC-938B-BCC81A1EEAAA}
TomTom HOME 2.7.2.1825-->C:\Program Files\TomTom HOME 2\Uninstall TomTom HOME.exe
TomTom HOME Visual Studio Merge Modules-->MsiExec.exe /I{8F3C31C5-9C3A-4AA8-8EFA-71290A7AD533}
Uninstall 1.0.0.1-->"C:\Program Files\Common Files\DVDVideoSoft\unins000.exe"
Unlocker 1.8.7-->C:\Program Files\Unlocker\uninst.exe
Update for 2007 Microsoft Office System (KB967642)-->msiexec /package {91120000-0014-0000-0000-0000000FF1CE} /uninstall {C444285D-5E4F-48A4-91DD-47AAAA68E92D}
Update for Microsoft .NET Framework 3.5 SP1 (KB963707)-->C:\Windows\system32\msiexec.exe /package {CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9} /uninstall {B2AE9C82-DC7B-3641-BFC8-87275C4F3607} /qb+ REBOOTPROMPT=""
Update for Microsoft Office 2007 Help for Common Features (KB963673)-->msiexec /package {90120000-006E-0409-0000-0000000FF1CE} /uninstall {AB365889-0395-4FAD-B702-CA5985D53D42}
Update for Microsoft Office Access 2007 Help (KB963663)-->msiexec /package {90120000-0015-0409-0000-0000000FF1CE} /uninstall {6B76A18A-AA1E-42AB-A7AD-6C84BBB43987}
Update for Microsoft Office Excel 2007 Help (KB963678)-->msiexec /package {90120000-0016-0409-0000-0000000FF1CE} /uninstall {199DF7B6-169C-448C-B511-1054101BE9C9}
Update for Microsoft Office Outlook 2007 (KB969907)-->msiexec /package {91120000-0014-0000-0000-0000000FF1CE} /uninstall {74F98B24-AFBD-4800-9BD6-87D349B5C462}
Update for Microsoft Office Outlook 2007 Help (KB963677)-->msiexec /package {90120000-001A-0409-0000-0000000FF1CE} /uninstall {0451F231-E3E3-4943-AB9F-58EB96171784}
Update for Microsoft Office Powerpoint 2007 Help (KB963669)-->msiexec /package {90120000-0018-0409-0000-0000000FF1CE} /uninstall {397B1D4F-ED7B-4ACA-A637-43B670843876}
Update for Microsoft Office Publisher 2007 Help (KB963667)-->msiexec /package {90120000-0019-0409-0000-0000000FF1CE} /uninstall {2E40DE55-B289-4C8B-8901-5D369B16814F}
Update for Microsoft Office Script Editor Help (KB963671)-->msiexec /package {90120000-006E-0409-0000-0000000FF1CE} /uninstall {CD11C6A2-FFC6-4271-8EAB-79C3582F505C}
Update for Microsoft Office Word 2007 Help (KB963665)-->msiexec /package {90120000-001B-0409-0000-0000000FF1CE} /uninstall {80E762AA-C921-4839-9D7D-DB62A72C0726}
Update for Outlook 2007 Junk Email Filter (kb973514)-->msiexec /package {91120000-0014-0000-0000-0000000FF1CE} /uninstall {03B11C77-336F-43B4-9B43-79890BA84504}
Windows 7 Upgrade Advisor Beta-->MsiExec.exe /I{4394DC3A-5DAC-4C80-A86E-FF462D0AD653}
Windows Installer Clean Up-->MsiExec.exe /X{121634B0-2F4B-11D3-ADA3-00C04F52DD52}
Windows Live ID Sign-in Assistant-->MsiExec.exe /X{10A44844-4465-456E-8C97-80BDD4F68845}
Windows Live OneCare safety scanner-->"C:\Program Files\Windows Live Safety Center\UnInstall.exe"
Windows Live OneCare safety scanner-->MsiExec.exe /X{FE0646A7-19D0-41B4-A2BB-2C35D644270D}
Windows Media Player Firefox Plugin-->MsiExec.exe /I{69FDFBB6-351D-4B8C-89D8-867DC9D0A2A4}
Windows Resource Kit Tools - SubInAcl.exe-->MsiExec.exe /X{D3EE034D-5B92-4A55-AA02-2E6D0A6A96EE}
Windows SteadyState-->MsiExec.exe /X{D3880A64-6112-47b7-8BFE-70EEA07B43E0}
WinPatrol 2009-->C:\PROGRA~1\BILLPS~1\WINPAT~1\Setup.exe /remove /q0
WinRAR archiver-->C:\Program Files\WinRAR\uninstall.exe
ZoneAlarm Pro-->C:\Program Files\Zone Labs\ZoneAlarm\zauninst.exe

Hosts File Missing
======Security center information======

AS: Windows Defender (disabled)
AS: SUPERAntiSpyware (disabled)

======System event log======

Computer Name: Dell5150
Event Code: 4376
Message: Servicing has required reboot to complete the operation of setting package KB948609(Update) into Installed(Installed) state
Record Number: 29255
Source Name: Microsoft-Windows-Servicing
Time Written: 20090620012626.000000-000
Event Type: Warning
User: Dell5150\Administrator

Computer Name: Dell5150
Event Code: 4376
Message: Servicing has required reboot to complete the operation of setting package KB948609(Update) into Installed(Installed) state
Record Number: 29254
Source Name: Microsoft-Windows-Servicing
Time Written: 20090620012626.000000-000
Event Type: Warning
User: Dell5150\Administrator

Computer Name: Dell5150
Event Code: 4376
Message: Servicing has required reboot to complete the operation of setting package KB948609(Update) into Install Requested(Install Requested) state
Record Number: 29253
Source Name: Microsoft-Windows-Servicing
Time Written: 20090620012626.000000-000
Event Type: Warning
User: Dell5150\Administrator

Computer Name: Dell5150
Event Code: 4376
Message: Servicing has required reboot to complete the operation of setting package KB948609(Update) into Install Requested(Install Requested) state
Record Number: 29209
Source Name: Microsoft-Windows-Servicing
Time Written: 20090620012626.000000-000
Event Type: Warning
User: Dell5150\Administrator

Computer Name: Dell5150
Event Code: 4376
Message: Servicing has required reboot to complete the operation of setting package KB948609(Update) into Install Requested(Install Requested) state
Record Number: 29206
Source Name: Microsoft-Windows-Servicing
Time Written: 20090620012626.000000-000
Event Type: Warning
User: Dell5150\Administrator

=====Application event log=====

Computer Name: Dell5150
Event Code: 63
Message: A provider, Ncs2, has been registered in the Windows Management Instrumentation namespace Root\IntelNCS2 to use the LocalSystem account. This account is privileged and the provider may cause a security violation if it does not correctly impersonate user requests.
Record Number: 235
Source Name: Microsoft-Windows-WMI
Time Written: 20090619033602.000000-000
Event Type: Warning
User: Dell5150\tim

Computer Name: Dell5150
Event Code: 63
Message: A provider, Ncs2, has been registered in the Windows Management Instrumentation namespace Root\IntelNCS2 to use the LocalSystem account. This account is privileged and the provider may cause a security violation if it does not correctly impersonate user requests.
Record Number: 234
Source Name: Microsoft-Windows-WMI
Time Written: 20090619033602.000000-000
Event Type: Warning
User: Dell5150\tim

Computer Name: Dell5150
Event Code: 63
Message: A provider, Ncs2, has been registered in the Windows Management Instrumentation namespace Root\IntelNCS2 to use the LocalSystem account. This account is privileged and the provider may cause a security violation if it does not correctly impersonate user requests.
Record Number: 233
Source Name: Microsoft-Windows-WMI
Time Written: 20090619033602.000000-000
Event Type: Warning
User: Dell5150\tim

Computer Name: Dell5150
Event Code: 1530
Message: Windows detected your registry file is still in use by other applications or services. The file will be unloaded now. The applications or services that hold your registry file may not function properly afterwards.

DETAIL -
1 user registry handles leaked from \Registry\User\S-1-5-21-18389391-2786244900-556239492-1000:
Process 548 (\Device\HarddiskVolume1\Windows\System32\winlogon.exe) has opened key \REGISTRY\USER\S-1-5-21-18389391-2786244900-556239492-1000

Record Number: 69
Source Name: Microsoft-Windows-User Profiles Service
Time Written: 20090619032417.000000-000
Event Type: Warning
User: NT AUTHORITY\SYSTEM

Computer Name: Dell5150
Event Code: 1008
Message: The Windows Search Service is attempting to remove the old catalog.

Record Number: 23
Source Name: Microsoft-Windows-Search
Time Written: 20090619030736.000000-000
Event Type: Warning
User:

=====Security event log=====

Computer Name: 26L2233B2-11
Event Code: 4648
Message: A logon was attempted using explicit credentials.

Subject:
Security ID: S-1-5-18
Account Name: 26L2233B2-11$
Account Domain: WORKGROUP
Logon ID: 0x3e7
Logon GUID: {00000000-0000-0000-0000-000000000000}

Account Whose Credentials Were Used:
Account Name: SYSTEM
Account Domain: NT AUTHORITY
Logon GUID: {00000000-0000-0000-0000-000000000000}

Target Server:
Target Server Name: localhost
Additional Information: localhost

Process Information:
Process ID: 0x1fc
Process Name: C:\Windows\System32\services.exe

Network Information:
Network Address: -
Port: -

This event is generated when a process attempts to log on an account by explicitly specifying that account’s credentials. This most commonly occurs in batch-type configurations such as scheduled tasks, or when using the RUNAS command.
Record Number: 5
Source Name: Microsoft-Windows-Security-Auditing
Time Written: 20090619060310.432397-000
Event Type: Audit Success
User:

Computer Name: 26L2233B2-11
Event Code: 4902
Message: The Per-user audit policy table was created.

Number of Elements: 0
Policy ID: 0x4c488
Record Number: 4
Source Name: Microsoft-Windows-Security-Auditing
Time Written: 20090619060308.591585-000
Event Type: Audit Success
User:

Computer Name: 26L2233B2-11
Event Code: 4624
Message: An account was successfully logged on.

Subject:
Security ID: S-1-0-0
Account Name: -
Account Domain: -
Logon ID: 0x0

Logon Type: 0

New Logon:
Security ID: S-1-5-18
Account Name: SYSTEM
Account Domain: NT AUTHORITY
Logon ID: 0x3e7
Logon GUID: {00000000-0000-0000-0000-000000000000}

Process Information:
Process ID: 0x4
Process Name:

Network Information:
Workstation Name: -
Source Network Address: -
Source Port: -

Detailed Authentication Information:
Logon Process: -
Authentication Package: -
Transited Services: -
Package Name (NTLM only): -
Key Length: 0

This event is generated when a logon session is created. It is generated on the computer that was accessed.

The subject fields indicate the account on the local system which requested the logon. This is most commonly a service such as the Server service, or a local process such as Winlogon.exe or Services.exe.

The logon type field indicates the kind of logon that occurred. The most common types are 2 (interactive) and 3 (network).

The New Logon fields indicate the account for whom the new logon was created, i.e. the account that was logged on.

The network fields indicate where a remote logon request originated. Workstation name is not always available and may be left blank in some cases.

The authentication information fields provide detailed information about this specific logon request.
- Logon GUID is a unique identifier that can be used to correlate this event with a KDC event.
- Transited services indicate which intermediate services have participated in this logon request.
- Package name indicates which sub-protocol was used among the NTLM protocols.
- Key length indicates the length of the generated session key. This will be 0 if no session key was requested.
Record Number: 3
Source Name: Microsoft-Windows-Security-Auditing
Time Written: 20090619060307.842780-000
Event Type: Audit Success
User:

Computer Name: 26L2233B2-11
Event Code: 4608
Message: Windows is starting up.

This event is logged when LSASS.EXE starts and the auditing subsystem is initialized.
Record Number: 2
Source Name: Microsoft-Windows-Security-Auditing
Time Written: 20090619060307.842780-000
Event Type: Audit Success
User:

Computer Name: 26L2233B2-11
Event Code: 4647
Message: User initiated logoff:

Subject:
Security ID: S-1-5-21-2152478756-3922319563-605102323-500
Account Name: Administrator
Account Domain: 26L2233B2-11
Logon ID: 0x8496a

This event is generated when a logoff is initiated but the token reference count is not zero and the logon session cannot be destroyed. No further user-initiated activity can occur. This event can be interpreted as a logoff event.
Record Number: 1
Source Name: Microsoft-Windows-Security-Auditing
Time Written: 20061102130954.400000-000
Event Type: Audit Success
User:

======Environment variables======

"ComSpec"=%SystemRoot%\system32\cmd.exe
"FP_NO_HOST_CHECK"=NO
"OS"=Windows_NT
"Path"=%CommonProgramFiles%\Microsoft Shared\Windows Live;%SystemRoot%\system32;%SystemRoot%;%SystemRoot%\System32\Wbem;C:\Program Files\ATI Technologies\ATI.ACE\Core-Static;C:\Program Files\Intel\DMIX;c:\Program Files\Microsoft SQL Server\90\Tools\binn\;C:\PROGRA~1\DISKEE~1\DISKEE~1\;C:\Program Files\QuickTime\QTSystem\;C:\Program Files\Common Files\Acronis\SnapAPI\
"PATHEXT"=.COM;.EXE;.BAT;.CMD;.VBS;.VBE;.JS;.JSE;.WSF;.WSH;.MSC
"PROCESSOR_ARCHITECTURE"=x86
"TEMP"=%SystemRoot%\TEMP
"TMP"=%SystemRoot%\TEMP
"USERNAME"=SYSTEM
"windir"=%SystemRoot%
"PROCESSOR_LEVEL"=15
"PROCESSOR_IDENTIFIER"=x86 Family 15 Model 4 Stepping 4, GenuineIntel
"PROCESSOR_REVISION"=0404
"NUMBER_OF_PROCESSORS"=2
"tvdumpflags"=8
"CLASSPATH"=.;C:\Program Files\Java\jre6\lib\ext\QTJava.zip
"QTJAVA"=C:\Program Files\Java\jre6\lib\ext\QTJava.zip
"SCTPath"=C:\Program Files\Windows SteadyState\

-----------------EOF-----------------

#6 I_am_CanadianEh?

I_am_CanadianEh?
  • Topic Starter

  • Members
  • 489 posts
  • OFFLINE
  •  
  • Gender:Male
  • Local time:07:38 PM

Posted 05 October 2009 - 09:53 PM

Tom,
My logs are too long for one post, but when I try to add a new reply it simply tags on to my existing one and I run out of space. I cannot start a new reply. Help!

#7 I_am_CanadianEh?

I_am_CanadianEh?
  • Topic Starter

  • Members
  • 489 posts
  • OFFLINE
  •  
  • Gender:Male
  • Local time:07:38 PM

Posted 05 October 2009 - 09:55 PM

1st part of GMER.log

GMER 1.0.15.15125 - http://www.gmer.net
Rootkit scan 2009-10-05 21:49:32
Windows 6.0.6002 Service Pack 2
Running: g15ptnom.exe; Driver: C:\Users\elva\AppData\Local\Temp\awdyapoc.sys


---- System - GMER 1.0.15 ----

SSDT \SystemRoot\system32\DRIVERS\vsdatant.sys (ZoneAlarm Firewalling Driver/Check Point Software Technologies LTD) ZwAlpcConnectPort [0x8F832D9A]
SSDT \SystemRoot\system32\DRIVERS\vsdatant.sys (ZoneAlarm Firewalling Driver/Check Point Software Technologies LTD) ZwAlpcCreatePort [0x8F833638]
SSDT \SystemRoot\system32\DRIVERS\vsdatant.sys (ZoneAlarm Firewalling Driver/Check Point Software Technologies LTD) ZwConnectPort [0x8F832820]
SSDT \SystemRoot\system32\DRIVERS\vsdatant.sys (ZoneAlarm Firewalling Driver/Check Point Software Technologies LTD) ZwCreateFile [0x8F82BEF4]
SSDT \SystemRoot\system32\DRIVERS\vsdatant.sys (ZoneAlarm Firewalling Driver/Check Point Software Technologies LTD) ZwCreateKey [0x8F84A606]
SSDT \SystemRoot\system32\DRIVERS\vsdatant.sys (ZoneAlarm Firewalling Driver/Check Point Software Technologies LTD) ZwCreatePort [0x8F8332E0]
SSDT \SystemRoot\system32\DRIVERS\vsdatant.sys (ZoneAlarm Firewalling Driver/Check Point Software Technologies LTD) ZwCreateProcess [0x8F846A80]
SSDT \SystemRoot\system32\DRIVERS\vsdatant.sys (ZoneAlarm Firewalling Driver/Check Point Software Technologies LTD) ZwCreateProcessEx [0x8F846E9C]
SSDT \SystemRoot\system32\DRIVERS\vsdatant.sys (ZoneAlarm Firewalling Driver/Check Point Software Technologies LTD) ZwCreateSection [0x8F84E940]
SSDT 9967D1C4 ZwCreateThread
SSDT \SystemRoot\system32\DRIVERS\vsdatant.sys (ZoneAlarm Firewalling Driver/Check Point Software Technologies LTD) ZwCreateWaitablePort [0x8F833432]
SSDT \SystemRoot\system32\DRIVERS\vsdatant.sys (ZoneAlarm Firewalling Driver/Check Point Software Technologies LTD) ZwDeleteFile [0x8F82CD2A]
SSDT \SystemRoot\system32\DRIVERS\vsdatant.sys (ZoneAlarm Firewalling Driver/Check Point Software Technologies LTD) ZwDeleteKey [0x8F84BFE0]
SSDT \SystemRoot\system32\DRIVERS\vsdatant.sys (ZoneAlarm Firewalling Driver/Check Point Software Technologies LTD) ZwDeleteValueKey [0x8F84B8E2]
SSDT \SystemRoot\system32\DRIVERS\vsdatant.sys (ZoneAlarm Firewalling Driver/Check Point Software Technologies LTD) ZwDuplicateObject [0x8F8458D6]
SSDT \SystemRoot\system32\DRIVERS\vsdatant.sys (ZoneAlarm Firewalling Driver/Check Point Software Technologies LTD) ZwLoadDriver [0x8F82535A]
SSDT \SystemRoot\system32\DRIVERS\vsdatant.sys (ZoneAlarm Firewalling Driver/Check Point Software Technologies LTD) ZwLoadKey [0x8F84C9B2]
SSDT \SystemRoot\system32\DRIVERS\vsdatant.sys (ZoneAlarm Firewalling Driver/Check Point Software Technologies LTD) ZwLoadKey2 [0x8F84CBE4]
SSDT \SystemRoot\system32\DRIVERS\vsdatant.sys (ZoneAlarm Firewalling Driver/Check Point Software Technologies LTD) ZwLoadKeyEx [0x8F84D07E]
SSDT \SystemRoot\system32\DRIVERS\vsdatant.sys (ZoneAlarm Firewalling Driver/Check Point Software Technologies LTD) ZwMapViewOfSection [0x8F84ECF0]
SSDT \SystemRoot\system32\DRIVERS\vsdatant.sys (ZoneAlarm Firewalling Driver/Check Point Software Technologies LTD) ZwOpenFile [0x8F82C872]
SSDT 9967D1B0 ZwOpenProcess
SSDT 9967D1B5 ZwOpenThread
SSDT \SystemRoot\system32\DRIVERS\vsdatant.sys (ZoneAlarm Firewalling Driver/Check Point Software Technologies LTD) ZwProtectVirtualMemory [0x8F85B792]
SSDT \SystemRoot\system32\DRIVERS\vsdatant.sys (ZoneAlarm Firewalling Driver/Check Point Software Technologies LTD) ZwRenameKey [0x8F84DDF0]
SSDT \SystemRoot\system32\DRIVERS\vsdatant.sys (ZoneAlarm Firewalling Driver/Check Point Software Technologies LTD) ZwReplaceKey [0x8F84D33C]
SSDT \SystemRoot\system32\DRIVERS\vsdatant.sys (ZoneAlarm Firewalling Driver/Check Point Software Technologies LTD) ZwRequestWaitReplyPort [0x8F8323C4]
SSDT \SystemRoot\system32\DRIVERS\vsdatant.sys (ZoneAlarm Firewalling Driver/Check Point Software Technologies LTD) ZwRestoreKey [0x8F84DA3C]
SSDT \SystemRoot\system32\DRIVERS\vsdatant.sys (ZoneAlarm Firewalling Driver/Check Point Software Technologies LTD) ZwSecureConnectPort [0x8F832AD2]
SSDT \SystemRoot\system32\DRIVERS\vsdatant.sys (ZoneAlarm Firewalling Driver/Check Point Software Technologies LTD) ZwSetInformationFile [0x8F82D128]
SSDT \SystemRoot\system32\DRIVERS\vsdatant.sys (ZoneAlarm Firewalling Driver/Check Point Software Technologies LTD) ZwSetInformationObject [0x8F85B662]
SSDT \SystemRoot\system32\DRIVERS\vsdatant.sys (ZoneAlarm Firewalling Driver/Check Point Software Technologies LTD) ZwSetSystemInformation [0x8F824A2A]
SSDT \SystemRoot\system32\DRIVERS\vsdatant.sys (ZoneAlarm Firewalling Driver/Check Point Software Technologies LTD) ZwSetValueKey [0x8F84B012]
SSDT \SystemRoot\system32\DRIVERS\vsdatant.sys (ZoneAlarm Firewalling Driver/Check Point Software Technologies LTD) ZwSystemDebugControl [0x8F847B74]
SSDT 9967D1BF ZwTerminateProcess
SSDT \SystemRoot\system32\DRIVERS\vsdatant.sys (ZoneAlarm Firewalling Driver/Check Point Software Technologies LTD) ZwUnloadDriver [0x8F8257A0]
SSDT \SystemRoot\system32\DRIVERS\vsdatant.sys (ZoneAlarm Firewalling Driver/Check Point Software Technologies LTD) ZwCreateUserProcess [0x8F847304]

---- Kernel code sections - GMER 1.0.15 ----

.text ntkrnlpa.exe!KeSetEvent + 13D 81CAD880 8 Bytes [9A, 2D, 83, 8F, 38, 36, 83, ...]
.text ntkrnlpa.exe!KeSetEvent + 1C1 81CAD904 4 Bytes [20, 28, 83, 8F]
.text ntkrnlpa.exe!KeSetEvent + 1D9 81CAD91C 4 Bytes [F4, BE, 82, 8F]
.text ntkrnlpa.exe!KeSetEvent + 1E9 81CAD92C 4 Bytes JMP 0670DFB2
.text ntkrnlpa.exe!KeSetEvent + 205 81CAD948 12 Bytes [E0, 32, 83, 8F, 80, 6A, 84, ...]
.text ...

---- User IAT/EAT - GMER 1.0.15 ----

IAT C:\Windows\Explorer.EXE[2376] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdiplusShutdown] [74BB7817] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6002.18005_none_9e50b396ca17ae07\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT C:\Windows\Explorer.EXE[2376] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipCloneImage] [74C0A86D] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6002.18005_none_9e50b396ca17ae07\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT C:\Windows\Explorer.EXE[2376] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipDrawImageRectI] [74BBBB22] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6002.18005_none_9e50b396ca17ae07\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT C:\Windows\Explorer.EXE[2376] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipSetInterpolationMode] [74BAF695] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6002.18005_none_9e50b396ca17ae07\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT C:\Windows\Explorer.EXE[2376] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdiplusStartup] [74BB75E9] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6002.18005_none_9e50b396ca17ae07\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT C:\Windows\Explorer.EXE[2376] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipCreateFromHDC] [74BAE7CA] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6002.18005_none_9e50b396ca17ae07\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT C:\Windows\Explorer.EXE[2376] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipCreateBitmapFromStreamICM] [74BE8395] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6002.18005_none_9e50b396ca17ae07\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT C:\Windows\Explorer.EXE[2376] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipCreateBitmapFromStream] [74BBDA60] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6002.18005_none_9e50b396ca17ae07\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT C:\Windows\Explorer.EXE[2376] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipGetImageHeight] [74BAFFFA] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6002.18005_none_9e50b396ca17ae07\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT C:\Windows\Explorer.EXE[2376] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipGetImageWidth] [74BAFF61] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6002.18005_none_9e50b396ca17ae07\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT C:\Windows\Explorer.EXE[2376] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipDisposeImage] [74BA71CF] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6002.18005_none_9e50b396ca17ae07\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT C:\Windows\Explorer.EXE[2376] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipLoadImageFromFileICM] [74C3CAE2] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6002.18005_none_9e50b396ca17ae07\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT C:\Windows\Explorer.EXE[2376] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipLoadImageFromFile] [74BDC8D8] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6002.18005_none_9e50b396ca17ae07\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT C:\Windows\Explorer.EXE[2376] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipDeleteGraphics] [74BAD968] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6002.18005_none_9e50b396ca17ae07\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT C:\Windows\Explorer.EXE[2376] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipFree] [74BA6853] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6002.18005_none_9e50b396ca17ae07\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT C:\Windows\Explorer.EXE[2376] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipAlloc] [74BA687E] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6002.18005_none_9e50b396ca17ae07\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT C:\Windows\Explorer.EXE[2376] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipSetCompositingMode] [74BB2AD1] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6002.18005_none_9e50b396ca17ae07\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)

---- Devices - GMER 1.0.15 ----

Device Ntfs.sys (NT File System Driver/Microsoft Corporation)

AttachedDevice tdrpm228.sys (Acronis Try&Decide Volume Filter Driver/Acronis)

Device fastfat.SYS (Fast FAT File System Driver/Microsoft Corporation)
Device volmgr.sys (Volume Manager Driver/Microsoft Corporation)

AttachedDevice fltmgr.sys (Microsoft Filesystem Filter Manager/Microsoft Corporation)

Device pci.sys (NT Plug and Play PCI Enumerator/Microsoft Corporation)

---- Registry - GMER 1.0.15 ----

Reg HKLM\SOFTWARE\Classes\.3g2@ QuickTime.3g2
Reg HKLM\SOFTWARE\Classes\.3g2@Content Type video/3gpp2
Reg HKLM\SOFTWARE\Classes\.3g2@QuickTime.bak
Reg HKLM\SOFTWARE\Classes\.3g2\OpenWithProgIds
Reg HKLM\SOFTWARE\Classes\.3g2\OpenWithProgIds@QuickTime.3g2
Reg HKLM\SOFTWARE\Classes\.3gp@ QuickTime.3gp
Reg HKLM\SOFTWARE\Classes\.3gp@Content Type video/3gpp
Reg HKLM\SOFTWARE\Classes\.3gp@QuickTime.bak
Reg HKLM\SOFTWARE\Classes\.3gp\OpenWithProgIds
Reg HKLM\SOFTWARE\Classes\.3gp\OpenWithProgIds@QuickTime.3gp
Reg HKLM\SOFTWARE\Classes\.3gp2@ QuickTime.3gp2
Reg HKLM\SOFTWARE\Classes\.3gp2@Content Type video/3gpp2
Reg HKLM\SOFTWARE\Classes\.3gp2@QuickTime.bak
Reg HKLM\SOFTWARE\Classes\.3gp2\OpenWithProgIds
Reg HKLM\SOFTWARE\Classes\.3gp2\OpenWithProgIds@QuickTime.3gp2
Reg HKLM\SOFTWARE\Classes\.3gpp@ QuickTime.3gpp
Reg HKLM\SOFTWARE\Classes\.3gpp@Content Type video/3gpp
Reg HKLM\SOFTWARE\Classes\.3gpp@QuickTime.bak
Reg HKLM\SOFTWARE\Classes\.3gpp\OpenWithProgIds
Reg HKLM\SOFTWARE\Classes\.3gpp\OpenWithProgIds@QuickTime.3gpp
Reg HKLM\SOFTWARE\Classes\.aa@Content Type audio/audible
Reg HKLM\SOFTWARE\Classes\.aa@PerceivedType audio
Reg HKLM\SOFTWARE\Classes\.aa\OpenWithList
Reg HKLM\SOFTWARE\Classes\.aa\OpenWithList\iTunes.exe
Reg HKLM\SOFTWARE\Classes\.aa\OpenWithList\iTunes.exe@
Reg HKLM\SOFTWARE\Classes\.aa\OpenWithProgIds
Reg HKLM\SOFTWARE\Classes\.aa\OpenWithProgIds@
Reg HKLM\SOFTWARE\Classes\.aa\OpenWithProgIds@iTunes.aa
Reg HKLM\SOFTWARE\Classes\.aac@ QuickTime.aac
Reg HKLM\SOFTWARE\Classes\.aac@Content Type audio/aac
Reg HKLM\SOFTWARE\Classes\.aac@QuickTime.bak
Reg HKLM\SOFTWARE\Classes\.aac\OpenWithProgIds
Reg HKLM\SOFTWARE\Classes\.aac\OpenWithProgIds@QuickTime.aac
Reg HKLM\SOFTWARE\Classes\.aax@Content Type audio/vnd.audible.aax
Reg HKLM\SOFTWARE\Classes\.aax@PerceivedType audio
Reg HKLM\SOFTWARE\Classes\.aax\OpenWithList
Reg HKLM\SOFTWARE\Classes\.aax\OpenWithList\iTunes.exe
Reg HKLM\SOFTWARE\Classes\.aax\OpenWithList\iTunes.exe@
Reg HKLM\SOFTWARE\Classes\.aax\OpenWithProgIds
Reg HKLM\SOFTWARE\Classes\.aax\OpenWithProgIds@
Reg HKLM\SOFTWARE\Classes\.aax\OpenWithProgIds@iTunes.aax
Reg HKLM\SOFTWARE\Classes\.ac3@ QuickTime.ac3
Reg HKLM\SOFTWARE\Classes\.ac3@Content Type audio/ac3
Reg HKLM\SOFTWARE\Classes\.ac3@QuickTime.bak
Reg HKLM\SOFTWARE\Classes\.ac3\OpenWithProgIds
Reg HKLM\SOFTWARE\Classes\.ac3\OpenWithProgIds@QuickTime.ac3
Reg HKLM\SOFTWARE\Classes\.adts@ QuickTime.adts
Reg HKLM\SOFTWARE\Classes\.adts@Content Type audio/aac
Reg HKLM\SOFTWARE\Classes\.adts@QuickTime.bak
Reg HKLM\SOFTWARE\Classes\.adts\OpenWithProgIds
Reg HKLM\SOFTWARE\Classes\.adts\OpenWithProgIds@QuickTime.adts
Reg HKLM\SOFTWARE\Classes\.amc@ QuickTime.amc
Reg HKLM\SOFTWARE\Classes\.amc@Content Type application/x-mpeg
Reg HKLM\SOFTWARE\Classes\.amc@QuickTime.bak
Reg HKLM\SOFTWARE\Classes\.amc\OpenWithProgIds
Reg HKLM\SOFTWARE\Classes\.amc\OpenWithProgIds@QuickTime.amc
Reg HKLM\SOFTWARE\Classes\.AMR\OpenWithProgIds
Reg HKLM\SOFTWARE\Classes\.AMR\OpenWithProgIds@QuickTime.AMR
Reg HKLM\SOFTWARE\Classes\.bwf\OpenWithProgIds
Reg HKLM\SOFTWARE\Classes\.bwf\OpenWithProgIds@QuickTime.bwf
Reg HKLM\SOFTWARE\Classes\.caf@
Reg HKLM\SOFTWARE\Classes\.caf@Content Type audio/x-caf
Reg HKLM\SOFTWARE\Classes\.caf\OpenWithProgIds
Reg HKLM\SOFTWARE\Classes\.caf\OpenWithProgIds@QuickTime.caf
Reg HKLM\SOFTWARE\Classes\.cdda@
Reg HKLM\SOFTWARE\Classes\.cdda@Content Type audio/aiff
Reg HKLM\SOFTWARE\Classes\.cdda\OpenWithList
Reg HKLM\SOFTWARE\Classes\.cdda\OpenWithList\iTunes.exe
Reg HKLM\SOFTWARE\Classes\.cdda\OpenWithList\iTunes.exe@
Reg HKLM\SOFTWARE\Classes\.cdda\OpenWithProgIds
Reg HKLM\SOFTWARE\Classes\.cdda\OpenWithProgIds@QuickTime.cdda
Reg HKLM\SOFTWARE\Classes\.cdda\OpenWithProgIds@
Reg HKLM\SOFTWARE\Classes\.cdda\OpenWithProgIds@iTunes.cdda
Reg HKLM\SOFTWARE\Classes\.cel\OpenWithProgIds
Reg HKLM\SOFTWARE\Classes\.cel\OpenWithProgIds@QuickTime.cel
Reg HKLM\SOFTWARE\Classes\.csproj\PersistentHandler
Reg HKLM\SOFTWARE\Classes\.csproj\PersistentHandler@ {7E9D8D44-6926-426F-AA2B-217A819A5CCE}
Reg HKLM\SOFTWARE\Classes\.dif@ QuickTime.dif
Reg HKLM\SOFTWARE\Classes\.dif@Content Type video/x-dv
Reg HKLM\SOFTWARE\Classes\.dif@QuickTime.bak
Reg HKLM\SOFTWARE\Classes\.dif\OpenWithProgIds
Reg HKLM\SOFTWARE\Classes\.dif\OpenWithProgIds@QuickTime.dif
Reg HKLM\SOFTWARE\Classes\.dv@ QuickTime.dv
Reg HKLM\SOFTWARE\Classes\.dv@Content Type video/x-dv
Reg HKLM\SOFTWARE\Classes\.dv@QuickTime.bak
Reg HKLM\SOFTWARE\Classes\.dv\OpenWithProgIds
Reg HKLM\SOFTWARE\Classes\.dv\OpenWithProgIds@QuickTime.dv
Reg HKLM\SOFTWARE\Classes\.flc\OpenWithProgIds
Reg HKLM\SOFTWARE\Classes\.flc\OpenWithProgIds@QuickTime.flc
Reg HKLM\SOFTWARE\Classes\.fli\OpenWithProgIds
Reg HKLM\SOFTWARE\Classes\.fli\OpenWithProgIds@QuickTime.fli
Reg HKLM\SOFTWARE\Classes\.gsm@
Reg HKLM\SOFTWARE\Classes\.gsm@Content Type audio/x-gsm
Reg HKLM\SOFTWARE\Classes\.gsm\OpenWithProgIds
Reg HKLM\SOFTWARE\Classes\.gsm\OpenWithProgIds@QuickTime.gsm
Reg HKLM\SOFTWARE\Classes\.ipa@ iTunes.ipa
Reg HKLM\SOFTWARE\Classes\.ipa@Content Type application/x-itunes-ipa
Reg HKLM\SOFTWARE\Classes\.ipa\OpenWithList
Reg HKLM\SOFTWARE\Classes\.ipa\OpenWithList\iTunes.exe
Reg HKLM\SOFTWARE\Classes\.ipa\OpenWithList\iTunes.exe@
Reg HKLM\SOFTWARE\Classes\.ipa\OpenWithProgids
Reg HKLM\SOFTWARE\Classes\.ipa\OpenWithProgids@iTunes.ipa
Reg HKLM\SOFTWARE\Classes\.ipg@ iTunes.ipg
Reg HKLM\SOFTWARE\Classes\.ipg@Content Type application/x-itunes-ipg
Reg HKLM\SOFTWARE\Classes\.ipg\OpenWithList
Reg HKLM\SOFTWARE\Classes\.ipg\OpenWithList\iTunes.exe
Reg HKLM\SOFTWARE\Classes\.ipg\OpenWithList\iTunes.exe@
Reg HKLM\SOFTWARE\Classes\.ipg\OpenWithProgids
Reg HKLM\SOFTWARE\Classes\.ipg\OpenWithProgids@iTunes.ipg
Reg HKLM\SOFTWARE\Classes\.ipsw@ iTunes.ipsw
Reg HKLM\SOFTWARE\Classes\.ipsw@Content Type application/x-itunes-ipsw
Reg HKLM\SOFTWARE\Classes\.ipsw\OpenWithList
Reg HKLM\SOFTWARE\Classes\.ipsw\OpenWithList\iTunes.exe
Reg HKLM\SOFTWARE\Classes\.ipsw\OpenWithList\iTunes.exe@
Reg HKLM\SOFTWARE\Classes\.ipsw\OpenWithProgids
Reg HKLM\SOFTWARE\Classes\.ipsw\OpenWithProgids@iTunes.ipsw
Reg HKLM\SOFTWARE\Classes\.itb\OpenWithProgids
Reg HKLM\SOFTWARE\Classes\.itb\OpenWithProgids@iTunes.itb
Reg HKLM\SOFTWARE\Classes\.itdb@ iTunes.itdb
Reg HKLM\SOFTWARE\Classes\.itdb\OpenWithList
Reg HKLM\SOFTWARE\Classes\.itdb\OpenWithList\iTunes.exe
Reg HKLM\SOFTWARE\Classes\.itdb\OpenWithList\iTunes.exe@
Reg HKLM\SOFTWARE\Classes\.itdb\OpenWithProgids
Reg HKLM\SOFTWARE\Classes\.itdb\OpenWithProgids@iTunes.itdb
Reg HKLM\SOFTWARE\Classes\.ite@ iTunes.ite
Reg HKLM\SOFTWARE\Classes\.ite@Content Type application/x-itunes-ite
Reg HKLM\SOFTWARE\Classes\.ite\OpenWithList
Reg HKLM\SOFTWARE\Classes\.ite\OpenWithList\iTunes.exe
Reg HKLM\SOFTWARE\Classes\.ite\OpenWithList\iTunes.exe@
Reg HKLM\SOFTWARE\Classes\.ite\OpenWithProgids
Reg HKLM\SOFTWARE\Classes\.ite\OpenWithProgids@iTunes.ite
Reg HKLM\SOFTWARE\Classes\.itl@ iTunes.itl
Reg HKLM\SOFTWARE\Classes\.itl\OpenWithList
Reg HKLM\SOFTWARE\Classes\.itl\OpenWithList\iTunes.exe
Reg HKLM\SOFTWARE\Classes\.itl\OpenWithList\iTunes.exe@
Reg HKLM\SOFTWARE\Classes\.itl\OpenWithProgIds
Reg HKLM\SOFTWARE\Classes\.itl\OpenWithProgIds@
Reg HKLM\SOFTWARE\Classes\.itl\OpenWithProgIds@iTunes.itl
Reg HKLM\SOFTWARE\Classes\.itlp@ iTunes.itlp
Reg HKLM\SOFTWARE\Classes\.itlp@Content Type application/x-itunes-itlp
Reg HKLM\SOFTWARE\Classes\.itlp\OpenWithList
Reg HKLM\SOFTWARE\Classes\.itlp\OpenWithList\iTunes.exe
Reg HKLM\SOFTWARE\Classes\.itlp\OpenWithList\iTunes.exe@
Reg HKLM\SOFTWARE\Classes\.itlp\OpenWithProgids
Reg HKLM\SOFTWARE\Classes\.itlp\OpenWithProgids@iTunes.itlp
Reg HKLM\SOFTWARE\Classes\.itms@PerceivedType text
Reg HKLM\SOFTWARE\Classes\.itms@ iTunes.itms
Reg HKLM\SOFTWARE\Classes\.itms@Content Type application/x-itunes-itms
Reg HKLM\SOFTWARE\Classes\.itms\OpenWithList
Reg HKLM\SOFTWARE\Classes\.itms\OpenWithList\iTunes.exe
Reg HKLM\SOFTWARE\Classes\.itms\OpenWithList\iTunes.exe@
Reg HKLM\SOFTWARE\Classes\.itms\OpenWithProgIds
Reg HKLM\SOFTWARE\Classes\.itms\OpenWithProgIds@
Reg HKLM\SOFTWARE\Classes\.itms\OpenWithProgIds@iTunes.itms
Reg HKLM\SOFTWARE\Classes\.itpc@Content Type application/x-itunes-itpc
Reg HKLM\SOFTWARE\Classes\.itpc@ iTunes.itpc
Reg HKLM\SOFTWARE\Classes\.itpc@PerceivedType text
Reg HKLM\SOFTWARE\Classes\.itpc\OpenWithList
Reg HKLM\SOFTWARE\Classes\.itpc\OpenWithList\iTunes.exe
Reg HKLM\SOFTWARE\Classes\.itpc\OpenWithList\iTunes.exe@
Reg HKLM\SOFTWARE\Classes\.itpc\OpenWithProgIds
Reg HKLM\SOFTWARE\Classes\.itpc\OpenWithProgIds@
Reg HKLM\SOFTWARE\Classes\.itpc\OpenWithProgIds@iTunes.itpc
Reg HKLM\SOFTWARE\Classes\.jar@ jarfile
Reg HKLM\SOFTWARE\Classes\.jnlp@ JNLPFile
Reg HKLM\SOFTWARE\Classes\.jnlp@Content Type application/x-java-jnlp-file
Reg HKLM\SOFTWARE\Classes\.jp2\OpenWithProgIds
Reg HKLM\SOFTWARE\Classes\.jp2\OpenWithProgIds@QuickTime.jp2
Reg HKLM\SOFTWARE\Classes\.kar\OpenWithProgIds
Reg HKLM\SOFTWARE\Classes\.kar\OpenWithProgIds@QuickTime.kar
Reg HKLM\SOFTWARE\Classes\.m15\OpenWithProgIds
Reg HKLM\SOFTWARE\Classes\.m15\OpenWithProgIds@QuickTime.m15
Reg HKLM\SOFTWARE\Classes\.m1a\OpenWithProgIds
Reg HKLM\SOFTWARE\Classes\.m1a\OpenWithProgIds@QuickTime.m1a
Reg HKLM\SOFTWARE\Classes\.m1s\OpenWithProgIds
Reg HKLM\SOFTWARE\Classes\.m1s\OpenWithProgIds@QuickTime.m1s
Reg HKLM\SOFTWARE\Classes\.m3u8@Content Type audio/x-mpegurl
Reg HKLM\SOFTWARE\Classes\.m3u8@PerceivedType text
Reg HKLM\SOFTWARE\Classes\.m3u8\OpenWithList
Reg HKLM\SOFTWARE\Classes\.m3u8\OpenWithList\iTunes.exe
Reg HKLM\SOFTWARE\Classes\.m3u8\OpenWithList\iTunes.exe@
Reg HKLM\SOFTWARE\Classes\.m3u8\OpenWithProgIds
Reg HKLM\SOFTWARE\Classes\.m3u8\OpenWithProgIds@
Reg HKLM\SOFTWARE\Classes\.m3u8\OpenWithProgIds@iTunes.m3u8
Reg HKLM\SOFTWARE\Classes\.m3url\OpenWithProgIds
Reg HKLM\SOFTWARE\Classes\.m3url\OpenWithProgIds@QuickTime.m3url
Reg HKLM\SOFTWARE\Classes\.m4a@
Reg HKLM\SOFTWARE\Classes\.m4a@Content Type audio/m4a
Reg HKLM\SOFTWARE\Classes\.m4a@PerceivedType audio
Reg HKLM\SOFTWARE\Classes\.m4a\OpenWithList
Reg HKLM\SOFTWARE\Classes\.m4a\OpenWithList@
Reg HKLM\SOFTWARE\Classes\.m4a\OpenWithList\iTunes.exe
Reg HKLM\SOFTWARE\Classes\.m4a\OpenWithList\iTunes.exe@
Reg HKLM\SOFTWARE\Classes\.m4a\OpenWithProgIds
Reg HKLM\SOFTWARE\Classes\.m4a\OpenWithProgIds@QuickTime.m4a
Reg HKLM\SOFTWARE\Classes\.m4a\OpenWithProgIds@
Reg HKLM\SOFTWARE\Classes\.m4a\OpenWithProgIds@iTunes.m4a
Reg HKLM\SOFTWARE\Classes\.m4b@
Reg HKLM\SOFTWARE\Classes\.m4b@Content Type audio/m4b
Reg HKLM\SOFTWARE\Classes\.m4b@PerceivedType audio
Reg HKLM\SOFTWARE\Classes\.m4b\OpenWithList
Reg HKLM\SOFTWARE\Classes\.m4b\OpenWithList\iTunes.exe
Reg HKLM\SOFTWARE\Classes\.m4b\OpenWithList\iTunes.exe@
Reg HKLM\SOFTWARE\Classes\.m4b\OpenWithProgIds
Reg HKLM\SOFTWARE\Classes\.m4b\OpenWithProgIds@QuickTime.m4b
Reg HKLM\SOFTWARE\Classes\.m4b\OpenWithProgIds@
Reg HKLM\SOFTWARE\Classes\.m4b\OpenWithProgIds@iTunes.m4b
Reg HKLM\SOFTWARE\Classes\.m4p@
Reg HKLM\SOFTWARE\Classes\.m4p@Content Type audio/m4p
Reg HKLM\SOFTWARE\Classes\.m4p@PerceivedType audio
Reg HKLM\SOFTWARE\Classes\.m4p\OpenWithList
Reg HKLM\SOFTWARE\Classes\.m4p\OpenWithList@
Reg HKLM\SOFTWARE\Classes\.m4p\OpenWithList\iTunes.exe
Reg HKLM\SOFTWARE\Classes\.m4p\OpenWithList\iTunes.exe@
Reg HKLM\SOFTWARE\Classes\.m4p\OpenWithProgIds
Reg HKLM\SOFTWARE\Classes\.m4p\OpenWithProgIds@QuickTime.m4p
Reg HKLM\SOFTWARE\Classes\.m4p\OpenWithProgIds@
Reg HKLM\SOFTWARE\Classes\.m4p\OpenWithProgIds@iTunes.m4p
Reg HKLM\SOFTWARE\Classes\.m4r@Content Type audio/x-m4r
Reg HKLM\SOFTWARE\Classes\.m4r@PerceivedType audio
Reg HKLM\SOFTWARE\Classes\.m4r@ iTunes.m4r
Reg HKLM\SOFTWARE\Classes\.m4r\OpenWithList
Reg HKLM\SOFTWARE\Classes\.m4r\OpenWithList@
Reg HKLM\SOFTWARE\Classes\.m4r\OpenWithList\iTunes.exe
Reg HKLM\SOFTWARE\Classes\.m4r\OpenWithList\iTunes.exe@
Reg HKLM\SOFTWARE\Classes\.m4r\OpenWithProgIds
Reg HKLM\SOFTWARE\Classes\.m4r\OpenWithProgIds@
Reg HKLM\SOFTWARE\Classes\.m4r\OpenWithProgIds@iTunes.m4r
Reg HKLM\SOFTWARE\Classes\.m4v@
Reg HKLM\SOFTWARE\Classes\.m4v@Content Type video/x-m4v
Reg HKLM\SOFTWARE\Classes\.m4v@PerceivedType video
Reg HKLM\SOFTWARE\Classes\.m4v\OpenWithList
Reg HKLM\SOFTWARE\Classes\.m4v\OpenWithList@
Reg HKLM\SOFTWARE\Classes\.m4v\OpenWithList\iTunes.exe
Reg HKLM\SOFTWARE\Classes\.m4v\OpenWithList\iTunes.exe@
Reg HKLM\SOFTWARE\Classes\.m4v\OpenWithProgIds
Reg HKLM\SOFTWARE\Classes\.m4v\OpenWithProgIds@QuickTime.m4v
Reg HKLM\SOFTWARE\Classes\.m4v\OpenWithProgIds@
Reg HKLM\SOFTWARE\Classes\.m4v\OpenWithProgIds@iTunes.m4v
Reg HKLM\SOFTWARE\Classes\.m75\OpenWithProgIds
Reg HKLM\SOFTWARE\Classes\.m75\OpenWithProgIds@QuickTime.m75
Reg HKLM\SOFTWARE\Classes\.mac@ QuickTime.mac
Reg HKLM\SOFTWARE\Classes\.mac@Content Type image/x-macpaint
Reg HKLM\SOFTWARE\Classes\.mac@QuickTime.bak
Reg HKLM\SOFTWARE\Classes\.mac\OpenWithProgIds
Reg HKLM\SOFTWARE\Classes\.mac\OpenWithProgIds@QuickTime.mac
Reg HKLM\SOFTWARE\Classes\.mp4@ QuickTime.mp4
Reg HKLM\SOFTWARE\Classes\.mp4@Content Type video/mp4
Reg HKLM\SOFTWARE\Classes\.mp4@QuickTime.bak
Reg HKLM\SOFTWARE\Classes\.mp4\OpenWithProgIds
Reg HKLM\SOFTWARE\Classes\.mp4\OpenWithProgIds@QuickTime.mp4
Reg HKLM\SOFTWARE\Classes\.mpm\OpenWithProgIds
Reg HKLM\SOFTWARE\Classes\.mpm\OpenWithProgIds@QuickTime.mpm
Reg HKLM\SOFTWARE\Classes\.mpv\OpenWithProgIds
Reg HKLM\SOFTWARE\Classes\.mpv\OpenWithProgIds@QuickTime.mpv
Reg HKLM\SOFTWARE\Classes\.mqv@ QuickTime.mqv
Reg HKLM\SOFTWARE\Classes\.mqv@Content Type video/quicktime
Reg HKLM\SOFTWARE\Classes\.mqv@QuickTime.bak
Reg HKLM\SOFTWARE\Classes\.mqv\OpenWithProgIds
Reg HKLM\SOFTWARE\Classes\.mqv\OpenWithProgIds@QuickTime.mqv
Reg HKLM\SOFTWARE\Classes\.pcast@Content Type application/x-podcast
Reg HKLM\SOFTWARE\Classes\.pcast@ iTunes.pcast
Reg HKLM\SOFTWARE\Classes\.pcast@PerceivedType text
Reg HKLM\SOFTWARE\Classes\.pcast\OpenWithList
Reg HKLM\SOFTWARE\Classes\.pcast\OpenWithList\iTunes.exe
Reg HKLM\SOFTWARE\Classes\.pcast\OpenWithList\iTunes.exe@
Reg HKLM\SOFTWARE\Classes\.pcast\OpenWithProgIds
Reg HKLM\SOFTWARE\Classes\.pcast\OpenWithProgIds@
Reg HKLM\SOFTWARE\Classes\.pcast\OpenWithProgIds@iTunes.pcast
Reg HKLM\SOFTWARE\Classes\.pct@ QuickTime.pct
Reg HKLM\SOFTWARE\Classes\.pct@Content Type image/pict
Reg HKLM\SOFTWARE\Classes\.pct@QuickTime.bak
Reg HKLM\SOFTWARE\Classes\.pct\OpenWithProgIds
Reg HKLM\SOFTWARE\Classes\.pct\OpenWithProgIds@QuickTime.pct
Reg HKLM\SOFTWARE\Classes\.pict@ QuickTime.pict
Reg HKLM\SOFTWARE\Classes\.pict@Content Type image/pict
Reg HKLM\SOFTWARE\Classes\.pict@QuickTime.bak
Reg HKLM\SOFTWARE\Classes\.pict\OpenWithProgIds
Reg HKLM\SOFTWARE\Classes\.pict\OpenWithProgIds@QuickTime.pict
Reg HKLM\SOFTWARE\Classes\.plist@ QuickTimePreferences
Reg HKLM\SOFTWARE\Classes\.pls@PerceivedType text
Reg HKLM\SOFTWARE\Classes\.pls@Content Type audio/scpls
Reg HKLM\SOFTWARE\Classes\.pls\OpenWithList
Reg HKLM\SOFTWARE\Classes\.pls\OpenWithList@
Reg HKLM\SOFTWARE\Classes\.pls\OpenWithList\iTunes.exe
Reg HKLM\SOFTWARE\Classes\.pls\OpenWithList\iTunes.exe@
Reg HKLM\SOFTWARE\Classes\.pls\OpenWithProgIds
Reg HKLM\SOFTWARE\Classes\.pls\OpenWithProgIds@
Reg HKLM\SOFTWARE\Classes\.pls\OpenWithProgIds@iTunes.pls
Reg HKLM\SOFTWARE\Classes\.pnt@ QuickTime.pnt
Reg HKLM\SOFTWARE\Classes\.pnt@Content Type image/x-macpaint
Reg HKLM\SOFTWARE\Classes\.pnt@QuickTime.bak
Reg HKLM\SOFTWARE\Classes\.pnt\OpenWithProgIds
Reg HKLM\SOFTWARE\Classes\.pnt\OpenWithProgIds@QuickTime.pnt
Reg HKLM\SOFTWARE\Classes\.pntg@ QuickTime.pntg
Reg HKLM\SOFTWARE\Classes\.pntg@Content Type image/x-macpaint
Reg HKLM\SOFTWARE\Classes\.pntg@QuickTime.bak
Reg HKLM\SOFTWARE\Classes\.pntg\OpenWithProgIds
Reg HKLM\SOFTWARE\Classes\.pntg\OpenWithProgIds@QuickTime.pntg
Reg HKLM\SOFTWARE\Classes\.qcp\OpenWithProgIds
Reg HKLM\SOFTWARE\Classes\.qcp\OpenWithProgIds@QuickTime.qcp
Reg HKLM\SOFTWARE\Classes\.qht@ QuickTime.qht
Reg HKLM\SOFTWARE\Classes\.qht@Content Type text/x-html-insertion
Reg HKLM\SOFTWARE\Classes\.qht@QuickTime.bak
Reg HKLM\SOFTWARE\Classes\.qht\OpenWithProgIds
Reg HKLM\SOFTWARE\Classes\.qht\OpenWithProgIds@QuickTime.qht
Reg HKLM\SOFTWARE\Classes\.qhtm@ QuickTime.qhtm
Reg HKLM\SOFTWARE\Classes\.qhtm@Content Type text/x-html-insertion
Reg HKLM\SOFTWARE\Classes\.qhtm@QuickTime.bak
Reg HKLM\SOFTWARE\Classes\.qhtm\OpenWithProgIds
Reg HKLM\SOFTWARE\Classes\.qhtm\OpenWithProgIds@QuickTime.qhtm
Reg HKLM\SOFTWARE\Classes\.qpa@ QuickTimePlayerAddition
Reg HKLM\SOFTWARE\Classes\.qt@ QuickTime.qt
Reg HKLM\SOFTWARE\Classes\.qt@Content Type video/quicktime
Reg HKLM\SOFTWARE\Classes\.qt\OpenWithProgIds
Reg HKLM\SOFTWARE\Classes\.qt\OpenWithProgIds@QuickTime.qt
Reg HKLM\SOFTWARE\Classes\.qti@ QuickTime.qti
Reg HKLM\SOFTWARE\Classes\.qti@Content Type image/x-quicktime
Reg HKLM\SOFTWARE\Classes\.qti@QuickTime.bak
Reg HKLM\SOFTWARE\Classes\.qti\OpenWithProgIds
Reg HKLM\SOFTWARE\Classes\.qti\OpenWithProgIds@QuickTime.qti
Reg HKLM\SOFTWARE\Classes\.qtif@ QuickTime.qtif
Reg HKLM\SOFTWARE\Classes\.qtif@Content Type image/x-quicktime
Reg HKLM\SOFTWARE\Classes\.qtif@QuickTime.bak
Reg HKLM\SOFTWARE\Classes\.qtif\OpenWithProgIds
Reg HKLM\SOFTWARE\Classes\.qtif\OpenWithProgIds@QuickTime.qtif
Reg HKLM\SOFTWARE\Classes\.qtl@ QuickTime.qtl
Reg HKLM\SOFTWARE\Classes\.qtl@Content Type application/x-quicktimeplayer
Reg HKLM\SOFTWARE\Classes\.qtl\OpenWithProgIds
Reg HKLM\SOFTWARE\Classes\.qtl\OpenWithProgIds@QuickTime.qtl
Reg HKLM\SOFTWARE\Classes\.qtp@ QuickTimePreferences
Reg HKLM\SOFTWARE\Classes\.qtr@ QuickTimeResources
Reg HKLM\SOFTWARE\Classes\.qts@ QuickTimeSystem
Reg HKLM\SOFTWARE\Classes\.qtx@ QuickTimeExtension
Reg HKLM\SOFTWARE\Classes\.rgb\OpenWithProgIds
Reg HKLM\SOFTWARE\Classes\.rgb\OpenWithProgIds@QuickTime.rgb
Reg HKLM\SOFTWARE\Classes\.rmp@Content Type application/vnd.rn-rn_music_package
Reg HKLM\SOFTWARE\Classes\.rmp\OpenWithList
Reg HKLM\SOFTWARE\Classes\.rmp\OpenWithList\iTunes.exe
Reg HKLM\SOFTWARE\Classes\.rmp\OpenWithList\iTunes.exe@
Reg HKLM\SOFTWARE\Classes\.rmp\OpenWithProgIds
Reg HKLM\SOFTWARE\Classes\.rmp\OpenWithProgIds@
Reg HKLM\SOFTWARE\Classes\.rmp\OpenWithProgIds@iTunes.rmp
Reg HKLM\SOFTWARE\Classes\.rts\OpenWithProgIds
Reg HKLM\SOFTWARE\Classes\.rts\OpenWithProgIds@QuickTime.rts
Reg HKLM\SOFTWARE\Classes\.rtsp\OpenWithProgIds
Reg HKLM\SOFTWARE\Classes\.rtsp\OpenWithProgIds@QuickTime.rtsp
Reg HKLM\SOFTWARE\Classes\.sd2@ QuickTime.sd2
Reg HKLM\SOFTWARE\Classes\.sd2@Content Type audio/x-sd2
Reg HKLM\SOFTWARE\Classes\.sd2@QuickTime.bak
Reg HKLM\SOFTWARE\Classes\.sd2\OpenWithProgIds
Reg HKLM\SOFTWARE\Classes\.sd2\OpenWithProgIds@QuickTime.sd2
Reg HKLM\SOFTWARE\Classes\.sdp@
Reg HKLM\SOFTWARE\Classes\.sdp@Content Type application/sdp
Reg HKLM\SOFTWARE\Classes\.sdp\OpenWithProgIds
Reg HKLM\SOFTWARE\Classes\.sdp\OpenWithProgIds@QuickTime.sdp
Reg HKLM\SOFTWARE\Classes\.sdv\OpenWithProgIds
Reg HKLM\SOFTWARE\Classes\.sdv\OpenWithProgIds@QuickTime.sdv
Reg HKLM\SOFTWARE\Classes\.sgi\OpenWithProgIds
Reg HKLM\SOFTWARE\Classes\.sgi\OpenWithProgIds@QuickTime.sgi
Reg HKLM\SOFTWARE\Classes\.smf\OpenWithProgIds
Reg HKLM\SOFTWARE\Classes\.smf\OpenWithProgIds@QuickTime.smf
Reg HKLM\SOFTWARE\Classes\.smi\OpenWithProgIds
Reg HKLM\SOFTWARE\Classes\.smi\OpenWithProgIds@QuickTime.smi
Reg HKLM\SOFTWARE\Classes\.smil\OpenWithProgIds
Reg HKLM\SOFTWARE\Classes\.smil\OpenWithProgIds@QuickTime.smil
Reg HKLM\SOFTWARE\Classes\.sml\OpenWithProgIds
Reg HKLM\SOFTWARE\Classes\.sml\OpenWithProgIds@QuickTime.sml
Reg HKLM\SOFTWARE\Classes\.swa\OpenWithProgIds
Reg HKLM\SOFTWARE\Classes\.swa\OpenWithProgIds@QuickTime.swa
Reg HKLM\SOFTWARE\Classes\.targa\OpenWithProgIds
Reg HKLM\SOFTWARE\Classes\.targa\OpenWithProgIds@QuickTime.targa
Reg HKLM\SOFTWARE\Classes\.tga\OpenWithProgIds
Reg HKLM\SOFTWARE\Classes\.tga\OpenWithProgIds@QuickTime.tga
Reg HKLM\SOFTWARE\Classes\.tib@ tibfile
Reg HKLM\SOFTWARE\Classes\.tis@ tisfile
Reg HKLM\SOFTWARE\Classes\.ulw\OpenWithProgIds
Reg HKLM\SOFTWARE\Classes\.ulw\OpenWithProgIds@QuickTime.ulw
Reg HKLM\SOFTWARE\Classes\.vbproj\PersistentHandler
Reg HKLM\SOFTWARE\Classes\.vbproj\PersistentHandler@ {7E9D8D44-6926-426F-AA2B-217A819A5CCE}
Reg HKLM\SOFTWARE\Classes\.vfw\OpenWithProgIds
Reg HKLM\SOFTWARE\Classes\.vfw\OpenWithProgIds@QuickTime.vfw
Reg HKLM\SOFTWARE\Classes\.wave@Content Type audio/wav
Reg HKLM\SOFTWARE\Classes\.wave@PerceivedType audio
Reg HKLM\SOFTWARE\Classes\.wave\OpenWithList
Reg HKLM\SOFTWARE\Classes\.wave\OpenWithList\iTunes.exe
Reg HKLM\SOFTWARE\Classes\.wave\OpenWithList\iTunes.exe@
Reg HKLM\SOFTWARE\Classes\.wave\OpenWithProgIds
Reg HKLM\SOFTWARE\Classes\.wave\OpenWithProgIds@
Reg HKLM\SOFTWARE\Classes\.wave\OpenWithProgIds@iTunes.wave

#8 I_am_CanadianEh?

I_am_CanadianEh?
  • Topic Starter

  • Members
  • 489 posts
  • OFFLINE
  •  
  • Gender:Male
  • Local time:07:38 PM

Posted 05 October 2009 - 09:56 PM

GMER.log file continued:

Reg HKLM\SOFTWARE\Classes\AgControl.AgControl.3.0@ Microsoft Silverlight
Reg HKLM\SOFTWARE\Classes\AgControl.AgControl.3.0\CLSID
Reg HKLM\SOFTWARE\Classes\AgControl.AgControl.3.0\CLSID@ {DFEAF541-F3E1-4c24-ACAC-99C30715084A}
Reg HKLM\SOFTWARE\Classes\AppleSoftwareUpdate.ASUInstallHost@ ASUInstallHost Class
Reg HKLM\SOFTWARE\Classes\AppleSoftwareUpdate.ASUInstallHost\CLSID
Reg HKLM\SOFTWARE\Classes\AppleSoftwareUpdate.ASUInstallHost\CLSID@ {91A9E6A9-3935-4A37-AFBA-F0904B166364}
Reg HKLM\SOFTWARE\Classes\AppleSoftwareUpdate.ASUInstallHost\CurVer
Reg HKLM\SOFTWARE\Classes\AppleSoftwareUpdate.ASUInstallHost\CurVer@ AppleSoftwareUpdate.ASUInstallHost.1
Reg HKLM\SOFTWARE\Classes\AppleSoftwareUpdate.ASUInstallHost.1@ ASUInstallHost Class
Reg HKLM\SOFTWARE\Classes\AppleSoftwareUpdate.ASUInstallHost.1\CLSID
Reg HKLM\SOFTWARE\Classes\AppleSoftwareUpdate.ASUInstallHost.1\CLSID@ {91A9E6A9-3935-4A37-AFBA-F0904B166364}
Reg HKLM\SOFTWARE\Classes\AppleSoftwareUpdateAdmin.ASUTaskSched.1@ ASUTaskScheduler Class
Reg HKLM\SOFTWARE\Classes\AppleSoftwareUpdateAdmin.ASUTaskSched.1\CLSID
Reg HKLM\SOFTWARE\Classes\AppleSoftwareUpdateAdmin.ASUTaskSched.1\CLSID@ {BB46F03E-7CD2-489F-8F95-BB950F395FDB}
Reg HKLM\SOFTWARE\Classes\AppleSoftwareUpdateAdmin.ASUTaskSchedul@ ASUTaskScheduler Class
Reg HKLM\SOFTWARE\Classes\AppleSoftwareUpdateAdmin.ASUTaskSchedul\CLSID
Reg HKLM\SOFTWARE\Classes\AppleSoftwareUpdateAdmin.ASUTaskSchedul\CLSID@ {BB46F03E-7CD2-489F-8F95-BB950F395FDB}
Reg HKLM\SOFTWARE\Classes\AppleSoftwareUpdateAdmin.ASUTaskSchedul\CurVer
Reg HKLM\SOFTWARE\Classes\AppleSoftwareUpdateAdmin.ASUTaskSchedul\CurVer@ AppleSoftwareUpdateAdmin.ASUTaskSched.1
Reg HKLM\SOFTWARE\Classes\CDDBControlApple.CDDBAppleControl.1@ CDDBAppleControl Class
Reg HKLM\SOFTWARE\Classes\CDDBControlApple.CDDBAppleControl.1\CLSID
Reg HKLM\SOFTWARE\Classes\CDDBControlApple.CDDBAppleControl.1\CLSID@ {5bdb98cc-b3f5-4d33-9a91-cbc986bea087}
Reg HKLM\SOFTWARE\Classes\CDDBControlApple.CDDBAppleControl.1\Insertable
Reg HKLM\SOFTWARE\Classes\CDDBControlApple.CddbCacheManager@ CddbCacheManager Class
Reg HKLM\SOFTWARE\Classes\CDDBControlApple.CddbCacheManager\CLSID
Reg HKLM\SOFTWARE\Classes\CDDBControlApple.CddbCacheManager\CLSID@ {d4704c9e-adbf-411a-9ef2-87feb99ccf69}
Reg HKLM\SOFTWARE\Classes\CDDBControlApple.CddbCacheManager\CurVer
Reg HKLM\SOFTWARE\Classes\CDDBControlApple.CddbCacheManager\CurVer@ CDDBControlApple.CddbCacheManager.1
Reg HKLM\SOFTWARE\Classes\CDDBControlApple.CddbCacheManager.1@ CddbCacheManager Class
Reg HKLM\SOFTWARE\Classes\CDDBControlApple.CddbCacheManager.1\CLSID
Reg HKLM\SOFTWARE\Classes\CDDBControlApple.CddbCacheManager.1\CLSID@ {d4704c9e-adbf-411a-9ef2-87feb99ccf69}
Reg HKLM\SOFTWARE\Classes\CDDBControlApple.CDDBControl@ CDDBAppleControl Class
Reg HKLM\SOFTWARE\Classes\CDDBControlApple.CDDBControl\CLSID
Reg HKLM\SOFTWARE\Classes\CDDBControlApple.CDDBControl\CLSID@ {5bdb98cc-b3f5-4d33-9a91-cbc986bea087}
Reg HKLM\SOFTWARE\Classes\CDDBControlApple.CDDBControl\CurVer
Reg HKLM\SOFTWARE\Classes\CDDBControlApple.CDDBControl\CurVer@ CDDBControlApple.CDDBAppleControl.1
Reg HKLM\SOFTWARE\Classes\CDDBControlApple.CDDBControl2@ CDDBControl2 Class
Reg HKLM\SOFTWARE\Classes\CDDBControlApple.CDDBControl2\CLSID
Reg HKLM\SOFTWARE\Classes\CDDBControlApple.CDDBControl2\CLSID@ {08fd0f18-43ae-4969-aee1-02e12f19cc33}
Reg HKLM\SOFTWARE\Classes\CDDBControlApple.CDDBControl2.1@ CDDBControl2 Class
Reg HKLM\SOFTWARE\Classes\CDDBControlApple.CDDBControl2.1\CLSID
Reg HKLM\SOFTWARE\Classes\CDDBControlApple.CDDBControl2.1\CLSID@ {08fd0f18-43ae-4969-aee1-02e12f19cc33}
Reg HKLM\SOFTWARE\Classes\CDDBControlApple.CddbCredit@ CddbCredit Class
Reg HKLM\SOFTWARE\Classes\CDDBControlApple.CddbCredit\CLSID
Reg HKLM\SOFTWARE\Classes\CDDBControlApple.CddbCredit\CLSID@ {8bb882d5-de37-4630-84e9-cc4bd7c44cb1}
Reg HKLM\SOFTWARE\Classes\CDDBControlApple.CddbCredit\CurVer
Reg HKLM\SOFTWARE\Classes\CDDBControlApple.CddbCredit\CurVer@ CDDBControlApple.CddbCredit.1
Reg HKLM\SOFTWARE\Classes\CDDBControlApple.CddbCredit.1@ CddbCredit Class
Reg HKLM\SOFTWARE\Classes\CDDBControlApple.CddbCredit.1\CLSID
Reg HKLM\SOFTWARE\Classes\CDDBControlApple.CddbCredit.1\CLSID@ {8bb882d5-de37-4630-84e9-cc4bd7c44cb1}
Reg HKLM\SOFTWARE\Classes\CDDBControlApple.CddbDisc@ CddbDisc Class
Reg HKLM\SOFTWARE\Classes\CDDBControlApple.CddbDisc\CLSID
Reg HKLM\SOFTWARE\Classes\CDDBControlApple.CddbDisc\CLSID@ {2c079982-25c8-4edf-9840-21d863a4716c}
Reg HKLM\SOFTWARE\Classes\CDDBControlApple.CddbDisc\CurVer
Reg HKLM\SOFTWARE\Classes\CDDBControlApple.CddbDisc\CurVer@ CDDBControlApple.CddbDisc.1
Reg HKLM\SOFTWARE\Classes\CDDBControlApple.CddbDisc.1@ CddbDisc Class
Reg HKLM\SOFTWARE\Classes\CDDBControlApple.CddbDisc.1\CLSID
Reg HKLM\SOFTWARE\Classes\CDDBControlApple.CddbDisc.1\CLSID@ {2c079982-25c8-4edf-9840-21d863a4716c}
Reg HKLM\SOFTWARE\Classes\CDDBControlApple.CddbFullName.1@ CddbFullName Class
Reg HKLM\SOFTWARE\Classes\CDDBControlApple.CddbFullName.1\CLSID
Reg HKLM\SOFTWARE\Classes\CDDBControlApple.CddbFullName.1\CLSID@ {63338267-37c4-44cf-8e46-756fbe9c8fdc}
Reg HKLM\SOFTWARE\Classes\CDDBControlApple.CddbID3Tag@ CddbID3Tag Class
Reg HKLM\SOFTWARE\Classes\CDDBControlApple.CddbID3Tag\CLSID
Reg HKLM\SOFTWARE\Classes\CDDBControlApple.CddbID3Tag\CLSID@ {aef7e664-dc9b-48b2-8b35-5422d3f08c77}
Reg HKLM\SOFTWARE\Classes\CDDBControlApple.CddbID3Tag\CurVer
Reg HKLM\SOFTWARE\Classes\CDDBControlApple.CddbID3Tag\CurVer@ CDDBControlApple.CddbID3Tag.1
Reg HKLM\SOFTWARE\Classes\CDDBControlApple.CddbID3Tag.1@ CddbID3Tag Class
Reg HKLM\SOFTWARE\Classes\CDDBControlApple.CddbID3Tag.1\CLSID
Reg HKLM\SOFTWARE\Classes\CDDBControlApple.CddbID3Tag.1\CLSID@ {aef7e664-dc9b-48b2-8b35-5422d3f08c77}
Reg HKLM\SOFTWARE\Classes\CDDBControlApple.CddbID3TagManager@ CddbID3TagManager Class
Reg HKLM\SOFTWARE\Classes\CDDBControlApple.CddbID3TagManager\CLSID
Reg HKLM\SOFTWARE\Classes\CDDBControlApple.CddbID3TagManager\CLSID@ {e73e119c-be36-4693-8a47-88c16829008c}
Reg HKLM\SOFTWARE\Classes\CDDBControlApple.CddbID3TagManager\CurVer
Reg HKLM\SOFTWARE\Classes\CDDBControlApple.CddbID3TagManager\CurVer@ CDDBControlApple.CddbID3TagManager.1
Reg HKLM\SOFTWARE\Classes\CDDBControlApple.CddbID3TagManager.1@ CddbID3TagManager Class
Reg HKLM\SOFTWARE\Classes\CDDBControlApple.CddbID3TagManager.1\CLSID
Reg HKLM\SOFTWARE\Classes\CDDBControlApple.CddbID3TagManager.1\CLSID@ {e73e119c-be36-4693-8a47-88c16829008c}
Reg HKLM\SOFTWARE\Classes\CDDBControlApple.CddbSegment@ CddbSegment Class
Reg HKLM\SOFTWARE\Classes\CDDBControlApple.CddbSegment\CLSID
Reg HKLM\SOFTWARE\Classes\CDDBControlApple.CddbSegment\CLSID@ {24cdf6ea-0b88-4d7a-aaf0-2048f90c2e1c}
Reg HKLM\SOFTWARE\Classes\CDDBControlApple.CddbSegment\CurVer
Reg HKLM\SOFTWARE\Classes\CDDBControlApple.CddbSegment\CurVer@ CDDBControlApple.CddbSegment.1
Reg HKLM\SOFTWARE\Classes\CDDBControlApple.CddbSegment.1@ CddbSegment Class
Reg HKLM\SOFTWARE\Classes\CDDBControlApple.CddbSegment.1\CLSID
Reg HKLM\SOFTWARE\Classes\CDDBControlApple.CddbSegment.1\CLSID@ {24cdf6ea-0b88-4d7a-aaf0-2048f90c2e1c}
Reg HKLM\SOFTWARE\Classes\CDDBControlApple.CddbURL@ CddbURL Class
Reg HKLM\SOFTWARE\Classes\CDDBControlApple.CddbURL\CLSID
Reg HKLM\SOFTWARE\Classes\CDDBControlApple.CddbURL\CLSID@ {aa9c1a1e-b91a-424e-9e27-3f1967b707f1}
Reg HKLM\SOFTWARE\Classes\CDDBControlApple.CddbURL\CurVer
Reg HKLM\SOFTWARE\Classes\CDDBControlApple.CddbURL\CurVer@ CDDBControlApple.CddbURL.1
Reg HKLM\SOFTWARE\Classes\CDDBControlApple.CddbURL.1@ CddbURL Class
Reg HKLM\SOFTWARE\Classes\CDDBControlApple.CddbURL.1\CLSID
Reg HKLM\SOFTWARE\Classes\CDDBControlApple.CddbURL.1\CLSID@ {aa9c1a1e-b91a-424e-9e27-3f1967b707f1}
Reg HKLM\SOFTWARE\Classes\CDDBControlApple.CddbURLManager@ CddbURLManager Class
Reg HKLM\SOFTWARE\Classes\CDDBControlApple.CddbURLManager\CLSID
Reg HKLM\SOFTWARE\Classes\CDDBControlApple.CddbURLManager\CLSID@ {7312c0a0-a397-4a19-b432-9ac90c4466af}
Reg HKLM\SOFTWARE\Classes\CDDBControlApple.CddbURLManager\CurVer
Reg HKLM\SOFTWARE\Classes\CDDBControlApple.CddbURLManager\CurVer@ CDDBControlApple.CddbURLManager.1
Reg HKLM\SOFTWARE\Classes\CDDBControlApple.CddbURLManager.1@ CddbURLManager Class
Reg HKLM\SOFTWARE\Classes\CDDBControlApple.CddbURLManager.1\CLSID
Reg HKLM\SOFTWARE\Classes\CDDBControlApple.CddbURLManager.1\CLSID@ {7312c0a0-a397-4a19-b432-9ac90c4466af}
Reg HKLM\SOFTWARE\Classes\CDDBControlApple.CddbWMATag@ CddbWMATag Class
Reg HKLM\SOFTWARE\Classes\CDDBControlApple.CddbWMATag\CLSID
Reg HKLM\SOFTWARE\Classes\CDDBControlApple.CddbWMATag\CLSID@ {b4774192-c038-4350-986d-1bd91c20379a}
Reg HKLM\SOFTWARE\Classes\CDDBControlApple.CddbWMATag\CurVer
Reg HKLM\SOFTWARE\Classes\CDDBControlApple.CddbWMATag\CurVer@ CDDBControlApple.CddbWMATag.1
Reg HKLM\SOFTWARE\Classes\CDDBControlApple.CddbWMATag.1@ CddbWMATag Class
Reg HKLM\SOFTWARE\Classes\CDDBControlApple.CddbWMATag.1\CLSID
Reg HKLM\SOFTWARE\Classes\CDDBControlApple.CddbWMATag.1\CLSID@ {b4774192-c038-4350-986d-1bd91c20379a}
Reg HKLM\SOFTWARE\Classes\CDDBControlApple.FullName@ CddbFullName Class
Reg HKLM\SOFTWARE\Classes\CDDBControlApple.FullName\CLSID
Reg HKLM\SOFTWARE\Classes\CDDBControlApple.FullName\CLSID@ {63338267-37c4-44cf-8e46-756fbe9c8fdc}
Reg HKLM\SOFTWARE\Classes\CDDBControlApple.FullName\CurVer
Reg HKLM\SOFTWARE\Classes\CDDBControlApple.FullName\CurVer@ CDDBControlApple.CddbFullName.1
Reg HKLM\SOFTWARE\Classes\CWebTransport.CWebTransport@ CWebTransport Object
Reg HKLM\SOFTWARE\Classes\CWebTransport.CWebTransport\CLSID
Reg HKLM\SOFTWARE\Classes\CWebTransport.CWebTransport\CLSID@ {74870B39-2651-4A6C-A59B-2F66602FDC67}
Reg HKLM\SOFTWARE\Classes\CWebTransport.CWebTransport\CurVer
Reg HKLM\SOFTWARE\Classes\CWebTransport.CWebTransport\CurVer@ CWebTransport.CWebTransport.1.0
Reg HKLM\SOFTWARE\Classes\CWebTransport.CWebTransport.1.0@ CWebTransport Object
Reg HKLM\SOFTWARE\Classes\CWebTransport.CWebTransport.1.0\CLSID
Reg HKLM\SOFTWARE\Classes\CWebTransport.CWebTransport.1.0\CLSID@ {74870B39-2651-4A6C-A59B-2F66602FDC67}
Reg HKLM\SOFTWARE\Classes\daap@ URL:Digital Audio Access Protocol
Reg HKLM\SOFTWARE\Classes\daap@URL Protocol
Reg HKLM\SOFTWARE\Classes\daap\DefaultIcon
Reg HKLM\SOFTWARE\Classes\daap\DefaultIcon@ C:\Program Files\iTunes\iTunes.exe
Reg HKLM\SOFTWARE\Classes\daap\shell
Reg HKLM\SOFTWARE\Classes\daap\shell@
Reg HKLM\SOFTWARE\Classes\daap\shell\open
Reg HKLM\SOFTWARE\Classes\daap\shell\open@
Reg HKLM\SOFTWARE\Classes\daap\shell\open\command
Reg HKLM\SOFTWARE\Classes\daap\shell\open\command@ C:\Program Files\iTunes\iTunes.exe /url "%1"
Reg HKLM\SOFTWARE\Classes\DkDfrgCtl.DkDfrgCtl@ DkDfrgCtl Class
Reg HKLM\SOFTWARE\Classes\DkDfrgCtl.DkDfrgCtl\CLSID
Reg HKLM\SOFTWARE\Classes\DkDfrgCtl.DkDfrgCtl\CLSID@ {202D3AEF-2F0E-11D1-A1F6-0080C88593A5}
Reg HKLM\SOFTWARE\Classes\DkDfrgCtl.DkDfrgCtl\CurVer
Reg HKLM\SOFTWARE\Classes\DkDfrgCtl.DkDfrgCtl\CurVer@ DkDfrgCtl.DkDfrgCtl.1
Reg HKLM\SOFTWARE\Classes\DkDfrgCtl.DkDfrgCtl.1@ DkDfrgCtl Class
Reg HKLM\SOFTWARE\Classes\DkDfrgCtl.DkDfrgCtl.1\CLSID
Reg HKLM\SOFTWARE\Classes\DkDfrgCtl.DkDfrgCtl.1\CLSID@ {202D3AEF-2F0E-11D1-A1F6-0080C88593A5}
Reg HKLM\SOFTWARE\Classes\DkDfrgSnapin.DkDfrgSnapin@ DkDfrgSnapin Class
Reg HKLM\SOFTWARE\Classes\DkDfrgSnapin.DkDfrgSnapin\CLSID
Reg HKLM\SOFTWARE\Classes\DkDfrgSnapin.DkDfrgSnapin\CLSID@ {43668E21-2636-11D1-A1CE-0080C88593A5}
Reg HKLM\SOFTWARE\Classes\DkDfrgSnapin.DkDfrgSnapin\CurVer
Reg HKLM\SOFTWARE\Classes\DkDfrgSnapin.DkDfrgSnapin\CurVer@ DkDfrgSnapin.DkDfrgSnapin.1
Reg HKLM\SOFTWARE\Classes\DkDfrgSnapin.DkDfrgSnapin.1@ DkDfrgSnapin Class
Reg HKLM\SOFTWARE\Classes\DkDfrgSnapin.DkDfrgSnapin.1\CLSID
Reg HKLM\SOFTWARE\Classes\DkDfrgSnapin.DkDfrgSnapin.1\CLSID@ {43668E21-2636-11D1-A1CE-0080C88593A5}
Reg HKLM\SOFTWARE\Classes\DkDfrgSnapinAbout.1@ This is the snapin created on 10/30
Reg HKLM\SOFTWARE\Classes\DkDfrgSnapinAbout.1\CLSID
Reg HKLM\SOFTWARE\Classes\DkDfrgSnapinAbout.1\CLSID@ {B5C45061-2729-11D1-A1D7-0080C88593A5}
Reg HKLM\SOFTWARE\Classes\EhStorACT.EhStorACT.1\CLSID
Reg HKLM\SOFTWARE\Classes\EhStorACT.EhStorACT.1\CLSID@ {af076a15-2ece-4ad4-bb21-29f040e176d8}
Reg HKLM\SOFTWARE\Classes\EhStorShell.AutoplayHandler@ Autoplay Handler Class
Reg HKLM\SOFTWARE\Classes\EhStorShell.AutoplayHandler\CLSID
Reg HKLM\SOFTWARE\Classes\EhStorShell.AutoplayHandler\CLSID@ {36F54939-CD3B-4C73-92D5-F9A389ED631C}
Reg HKLM\SOFTWARE\Classes\EhStorShell.AutoplayHandler\CurVer
Reg HKLM\SOFTWARE\Classes\EhStorShell.AutoplayHandler\CurVer@ EhStorShell.AutoplayHandler.1
Reg HKLM\SOFTWARE\Classes\EhStorShell.AutoplayHandler.1@ Autoplay Handler Class
Reg HKLM\SOFTWARE\Classes\EhStorShell.AutoplayHandler.1\CLSID
Reg HKLM\SOFTWARE\Classes\EhStorShell.AutoplayHandler.1\CLSID@ {36F54939-CD3B-4C73-92D5-F9A389ED631C}
Reg HKLM\SOFTWARE\Classes\EhStorShell.ContextMenuHandler@ Enhanced Storage Context Menu Handler Class
Reg HKLM\SOFTWARE\Classes\EhStorShell.ContextMenuHandler\CLSID
Reg HKLM\SOFTWARE\Classes\EhStorShell.ContextMenuHandler\CLSID@ {2854F705-3548-414C-A113-93E27C808C85}
Reg HKLM\SOFTWARE\Classes\EhStorShell.ContextMenuHandler\CurVer
Reg HKLM\SOFTWARE\Classes\EhStorShell.ContextMenuHandler\CurVer@ EhStorShell.ContextMenuHandler.1
Reg HKLM\SOFTWARE\Classes\EhStorShell.ContextMenuHandler.1@ Enhanced Storage Context Menu Handler Class
Reg HKLM\SOFTWARE\Classes\EhStorShell.ContextMenuHandler.1\CLSID
Reg HKLM\SOFTWARE\Classes\EhStorShell.ContextMenuHandler.1\CLSID@ {2854F705-3548-414C-A113-93E27C808C85}
Reg HKLM\SOFTWARE\Classes\EhStorShell.EhStorFolder.1@ Enhanced Storage Folder Class
Reg HKLM\SOFTWARE\Classes\EhStorShell.EhStorFolder.1\CLSID
Reg HKLM\SOFTWARE\Classes\EhStorShell.EhStorFolder.1\CLSID@ {9113A02D-00A3-46B9-BC5F-9C04DADDD5D7}
Reg HKLM\SOFTWARE\Classes\EhStorShell.EnhancedStorageFolder@ Enhanced Storage Folder Class
Reg HKLM\SOFTWARE\Classes\EhStorShell.EnhancedStorageFolder\CLSID
Reg HKLM\SOFTWARE\Classes\EhStorShell.EnhancedStorageFolder\CLSID@ {9113A02D-00A3-46B9-BC5F-9C04DADDD5D7}
Reg HKLM\SOFTWARE\Classes\EhStorShell.EnhancedStorageFolder\CurVer
Reg HKLM\SOFTWARE\Classes\EhStorShell.EnhancedStorageFolder\CurVer@ EhStorShell.EhStorFolder.1
Reg HKLM\SOFTWARE\Classes\EhStorShell.IconOverlayHandler@ Enhanced Storage Icon Overlay Handler Class
Reg HKLM\SOFTWARE\Classes\EhStorShell.IconOverlayHandler\CLSID
Reg HKLM\SOFTWARE\Classes\EhStorShell.IconOverlayHandler\CLSID@ {D9144DCD-E998-4ECA-AB6A-DCD83CCBA16D}
Reg HKLM\SOFTWARE\Classes\EhStorShell.IconOverlayHandler\CurVer
Reg HKLM\SOFTWARE\Classes\EhStorShell.IconOverlayHandler\CurVer@ EhStorShell.IconOverlayHandler.1
Reg HKLM\SOFTWARE\Classes\EhStorShell.IconOverlayHandler.1@ Enhanced Storage Icon Overlay Handler Class
Reg HKLM\SOFTWARE\Classes\EhStorShell.IconOverlayHandler.1\CLSID
Reg HKLM\SOFTWARE\Classes\EhStorShell.IconOverlayHandler.1\CLSID@ {D9144DCD-E998-4ECA-AB6A-DCD83CCBA16D}
Reg HKLM\SOFTWARE\Classes\EhStorSilo.EhStorSilo.1\CLSID
Reg HKLM\SOFTWARE\Classes\EhStorSilo.EhStorSilo.1\CLSID@ {cb25220c-76c7-4fee-842b-f3383cd022bc}
Reg HKLM\SOFTWARE\Classes\EhStorSiloAction.EhStorSiloAction.1\CLSID
Reg HKLM\SOFTWARE\Classes\EhStorSiloAction.EhStorSiloAction.1\CLSID@ {886D29DD-B506-466B-9FBF-B44FF383FB3F}
Reg HKLM\SOFTWARE\Classes\EnumEhStorACT.EnumEhStorACT.1\CLSID
Reg HKLM\SOFTWARE\Classes\EnumEhStorACT.EnumEhStorACT.1\CLSID@ {fe841493-835c-4fa3-b6cc-b4b2d4719848}
Reg HKLM\SOFTWARE\Classes\ExportController.ExportControllerObje.1@ ExportControllerObject Class
Reg HKLM\SOFTWARE\Classes\ExportController.ExportControllerObje.1\CLSID
Reg HKLM\SOFTWARE\Classes\ExportController.ExportControllerObje.1\CLSID@ {72278E83-B0EF-4E49-9E10-6947602C1030}
Reg HKLM\SOFTWARE\Classes\ExportController.ExportControllerObject@ ExportControllerObject Class
Reg HKLM\SOFTWARE\Classes\ExportController.ExportControllerObject\CLSID
Reg HKLM\SOFTWARE\Classes\ExportController.ExportControllerObject\CLSID@ {72278E83-B0EF-4E49-9E10-6947602C1030}
Reg HKLM\SOFTWARE\Classes\ExportController.ExportControllerObject\CurVer
Reg HKLM\SOFTWARE\Classes\ExportController.ExportControllerObject\CurVer@ ExportController.ExportControllerObje.1
Reg HKLM\SOFTWARE\Classes\HPDeviceDetection2.Device@ Device Class
Reg HKLM\SOFTWARE\Classes\HPDeviceDetection2.Device\CLSID
Reg HKLM\SOFTWARE\Classes\HPDeviceDetection2.Device\CLSID@ {96C42B95-9B5A-4A2F-B1B4-B053AC661851}
Reg HKLM\SOFTWARE\Classes\HPDeviceDetection2.Device\CurVer
Reg HKLM\SOFTWARE\Classes\HPDeviceDetection2.Device\CurVer@ HPDeviceDetection2.Device.1
Reg HKLM\SOFTWARE\Classes\HPDeviceDetection2.Device.1@ Device Class
Reg HKLM\SOFTWARE\Classes\HPDeviceDetection2.Device.1\CLSID
Reg HKLM\SOFTWARE\Classes\HPDeviceDetection2.Device.1\CLSID@ {96C42B95-9B5A-4A2F-B1B4-B053AC661851}
Reg HKLM\SOFTWARE\Classes\HPDeviceDetection2.DeviceCollection@ DeviceCollection Class
Reg HKLM\SOFTWARE\Classes\HPDeviceDetection2.DeviceCollection\CLSID
Reg HKLM\SOFTWARE\Classes\HPDeviceDetection2.DeviceCollection\CLSID@ {1F84CA74-66D3-4C96-A85D-9D79993102D0}
Reg HKLM\SOFTWARE\Classes\HPDeviceDetection2.DeviceCollection\CurVer
Reg HKLM\SOFTWARE\Classes\HPDeviceDetection2.DeviceCollection\CurVer@ HPDeviceDetection2.DeviceCollection.1
Reg HKLM\SOFTWARE\Classes\HPDeviceDetection2.DeviceCollection.1@ DeviceCollection Class
Reg HKLM\SOFTWARE\Classes\HPDeviceDetection2.DeviceCollection.1\CLSID
Reg HKLM\SOFTWARE\Classes\HPDeviceDetection2.DeviceCollection.1\CLSID@ {1F84CA74-66D3-4C96-A85D-9D79993102D0}
Reg HKLM\SOFTWARE\Classes\HPDeviceDetection2.DeviceDetection@ DeviceDetection Class
Reg HKLM\SOFTWARE\Classes\HPDeviceDetection2.DeviceDetection\CLSID
Reg HKLM\SOFTWARE\Classes\HPDeviceDetection2.DeviceDetection\CLSID@ {35464AB0-7C53-4D87-837A-4633CDBF8A7F}
Reg HKLM\SOFTWARE\Classes\HPDeviceDetection2.DeviceDetection\CurVer
Reg HKLM\SOFTWARE\Classes\HPDeviceDetection2.DeviceDetection\CurVer@ HPDeviceDetection2.DeviceDetection.1
Reg HKLM\SOFTWARE\Classes\HPDeviceDetection2.DeviceDetection.1@ DeviceDetection Class
Reg HKLM\SOFTWARE\Classes\HPDeviceDetection2.DeviceDetection.1\CLSID
Reg HKLM\SOFTWARE\Classes\HPDeviceDetection2.DeviceDetection.1\CLSID@ {35464AB0-7C53-4D87-837A-4633CDBF8A7F}
Reg HKLM\SOFTWARE\Classes\HpeSupportDiags.HpRpsCollection@ HpRpsCollection Class
Reg HKLM\SOFTWARE\Classes\HpeSupportDiags.HpRpsCollection\CLSID
Reg HKLM\SOFTWARE\Classes\HpeSupportDiags.HpRpsCollection\CLSID@ {CB780DC0-601C-4AA1-9AD9-F871C389EAD8}
Reg HKLM\SOFTWARE\Classes\HpeSupportDiags.HpRpsCollection\CurVer
Reg HKLM\SOFTWARE\Classes\HpeSupportDiags.HpRpsCollection\CurVer@ HpeSupportDiags.HpRpsCollection.1
Reg HKLM\SOFTWARE\Classes\HpeSupportDiags.HpRpsCollection.1@ HpRpsCollection Class
Reg HKLM\SOFTWARE\Classes\HpeSupportDiags.HpRpsCollection.1\CLSID
Reg HKLM\SOFTWARE\Classes\HpeSupportDiags.HpRpsCollection.1\CLSID@ {CB780DC0-601C-4AA1-9AD9-F871C389EAD8}
Reg HKLM\SOFTWARE\Classes\HpeSupportDiags.HpRpsExecution@ HpRpsExecution Class
Reg HKLM\SOFTWARE\Classes\HpeSupportDiags.HpRpsExecution\CLSID
Reg HKLM\SOFTWARE\Classes\HpeSupportDiags.HpRpsExecution\CLSID@ {EF6A4A3C-0850-4DDD-A041-A52F65CD02F7}
Reg HKLM\SOFTWARE\Classes\HpeSupportDiags.HpRpsExecution\CurVer
Reg HKLM\SOFTWARE\Classes\HpeSupportDiags.HpRpsExecution\CurVer@ HpeSupportDiags.HpRpsExecution.1
Reg HKLM\SOFTWARE\Classes\HpeSupportDiags.HpRpsExecution.1@ HpRpsExecution Class
Reg HKLM\SOFTWARE\Classes\HpeSupportDiags.HpRpsExecution.1\CLSID
Reg HKLM\SOFTWARE\Classes\HpeSupportDiags.HpRpsExecution.1\CLSID@ {EF6A4A3C-0850-4DDD-A041-A52F65CD02F7}
Reg HKLM\SOFTWARE\Classes\HpeSupportDiags.HpRpsPackage@ HpRpsPackage Class
Reg HKLM\SOFTWARE\Classes\HpeSupportDiags.HpRpsPackage\CLSID
Reg HKLM\SOFTWARE\Classes\HpeSupportDiags.HpRpsPackage\CLSID@ {C4CD81C3-651C-47E2-9C1B-3B0E95CAA3A7}
Reg HKLM\SOFTWARE\Classes\HpeSupportDiags.HpRpsPackage\CurVer
Reg HKLM\SOFTWARE\Classes\HpeSupportDiags.HpRpsPackage\CurVer@ HpeSupportDiags.HpRpsPackage.1
Reg HKLM\SOFTWARE\Classes\HpeSupportDiags.HpRpsPackage.1@ HpRpsPackage Class
Reg HKLM\SOFTWARE\Classes\HpeSupportDiags.HpRpsPackage.1\CLSID
Reg HKLM\SOFTWARE\Classes\HpeSupportDiags.HpRpsPackage.1\CLSID@ {C4CD81C3-651C-47E2-9C1B-3B0E95CAA3A7}
Reg HKLM\SOFTWARE\Classes\HpeSupportDiags.HpRpsTransferContent@ HpRpsTransferContent Class
Reg HKLM\SOFTWARE\Classes\HpeSupportDiags.HpRpsTransferContent\CLSID
Reg HKLM\SOFTWARE\Classes\HpeSupportDiags.HpRpsTransferContent\CLSID@ {C52256D6-0498-4EF8-87C8-717AB9B5DF1E}
Reg HKLM\SOFTWARE\Classes\HpeSupportDiags.HpRpsTransferContent\CurVer
Reg HKLM\SOFTWARE\Classes\HpeSupportDiags.HpRpsTransferContent\CurVer@ HpeSupportDiags.HpRpsTransferContent.1
Reg HKLM\SOFTWARE\Classes\HpeSupportDiags.HpRpsTransferContent.1@ HpRpsTransferContent Class
Reg HKLM\SOFTWARE\Classes\HpeSupportDiags.HpRpsTransferContent.1\CLSID
Reg HKLM\SOFTWARE\Classes\HpeSupportDiags.HpRpsTransferContent.1\CLSID@ {C52256D6-0498-4EF8-87C8-717AB9B5DF1E}
Reg HKLM\SOFTWARE\Classes\HpeSupportDiags.HpRpsTransferContentC.1@ HpRpsTransferContentCollection Class
Reg HKLM\SOFTWARE\Classes\HpeSupportDiags.HpRpsTransferContentC.1\CLSID
Reg HKLM\SOFTWARE\Classes\HpeSupportDiags.HpRpsTransferContentC.1\CLSID@ {18F368D9-81D3-42A2-BA7B-030C74CD950F}
Reg HKLM\SOFTWARE\Classes\HpeSupportDiags.HpRpsTransferContentCollection@ HpRpsTransferContentCollection Class
Reg HKLM\SOFTWARE\Classes\HpeSupportDiags.HpRpsTransferContentCollection\CLSID
Reg HKLM\SOFTWARE\Classes\HpeSupportDiags.HpRpsTransferContentCollection\CLSID@ {18F368D9-81D3-42A2-BA7B-030C74CD950F}
Reg HKLM\SOFTWARE\Classes\HpeSupportDiags.HpRpsTransferContentCollection\CurVer
Reg HKLM\SOFTWARE\Classes\HpeSupportDiags.HpRpsTransferContentCollection\CurVer@ HpeSupportDiags.HpRpsTransferContentC.1
Reg HKLM\SOFTWARE\Classes\HpeSupportDiags.HpRpsTransferError@ HpRpsTransferError Class
Reg HKLM\SOFTWARE\Classes\HpeSupportDiags.HpRpsTransferError\CLSID
Reg HKLM\SOFTWARE\Classes\HpeSupportDiags.HpRpsTransferError\CLSID@ {1BEC97BA-0A1F-4286-8FB5-C951ABBF0B37}
Reg HKLM\SOFTWARE\Classes\HpeSupportDiags.HpRpsTransferError\CurVer
Reg HKLM\SOFTWARE\Classes\HpeSupportDiags.HpRpsTransferError\CurVer@ HpeSupportDiags.HpRpsTransferError.1
Reg HKLM\SOFTWARE\Classes\HpeSupportDiags.HpRpsTransferError.1@ HpRpsTransferError Class
Reg HKLM\SOFTWARE\Classes\HpeSupportDiags.HpRpsTransferError.1\CLSID
Reg HKLM\SOFTWARE\Classes\HpeSupportDiags.HpRpsTransferError.1\CLSID@ {1BEC97BA-0A1F-4286-8FB5-C951ABBF0B37}
Reg HKLM\SOFTWARE\Classes\HpeSupportDiags.HpRpsTransferFile@ HpRpsTransferFile Class
Reg HKLM\SOFTWARE\Classes\HpeSupportDiags.HpRpsTransferFile\CLSID
Reg HKLM\SOFTWARE\Classes\HpeSupportDiags.HpRpsTransferFile\CLSID@ {39817A90-5204-41E7-A1A3-17BB3F3DDF38}
Reg HKLM\SOFTWARE\Classes\HpeSupportDiags.HpRpsTransferFile\CurVer
Reg HKLM\SOFTWARE\Classes\HpeSupportDiags.HpRpsTransferFile\CurVer@ HpeSupportDiags.HpRpsTransferFile.1
Reg HKLM\SOFTWARE\Classes\HpeSupportDiags.HpRpsTransferFile.1@ HpRpsTransferFile Class
Reg HKLM\SOFTWARE\Classes\HpeSupportDiags.HpRpsTransferFile.1\CLSID
Reg HKLM\SOFTWARE\Classes\HpeSupportDiags.HpRpsTransferFile.1\CLSID@ {39817A90-5204-41E7-A1A3-17BB3F3DDF38}
Reg HKLM\SOFTWARE\Classes\HpeSupportDiags.HpRpsTransferFileCollection@ HpRpsTransferFileCollection Class
Reg HKLM\SOFTWARE\Classes\HpeSupportDiags.HpRpsTransferFileCollection\CLSID
Reg HKLM\SOFTWARE\Classes\HpeSupportDiags.HpRpsTransferFileCollection\CLSID@ {CB2D3AFF-5360-487A-BCB7-4EDFF8C274A0}
Reg HKLM\SOFTWARE\Classes\HpeSupportDiags.HpRpsTransferFileCollection\CurVer
Reg HKLM\SOFTWARE\Classes\HpeSupportDiags.HpRpsTransferFileCollection\CurVer@ HpeSupportDiags.HpRpsTransferFileCollection.1
Reg HKLM\SOFTWARE\Classes\HpeSupportDiags.HpRpsTransferFileCollection.1@ HpRpsTransferFileCollection Class
Reg HKLM\SOFTWARE\Classes\HpeSupportDiags.HpRpsTransferFileCollection.1\CLSID
Reg HKLM\SOFTWARE\Classes\HpeSupportDiags.HpRpsTransferFileCollection.1\CLSID@ {CB2D3AFF-5360-487A-BCB7-4EDFF8C274A0}
Reg HKLM\SOFTWARE\Classes\HpeSupportDiags.HpRpsTransferManager@ HpRpsTransferManager Class
Reg HKLM\SOFTWARE\Classes\HpeSupportDiags.HpRpsTransferManager\CLSID
Reg HKLM\SOFTWARE\Classes\HpeSupportDiags.HpRpsTransferManager\CLSID@ {9E7179CA-8D7A-4308-9DDD-8315696D3A54}
Reg HKLM\SOFTWARE\Classes\HpeSupportDiags.HpRpsTransferManager\CurVer
Reg HKLM\SOFTWARE\Classes\HpeSupportDiags.HpRpsTransferManager\CurVer@ HpeSupportDiags.HpRpsTransferManager.1
Reg HKLM\SOFTWARE\Classes\HpeSupportDiags.HpRpsTransferManager.1@ HpRpsTransferManager Class
Reg HKLM\SOFTWARE\Classes\HpeSupportDiags.HpRpsTransferManager.1\CLSID
Reg HKLM\SOFTWARE\Classes\HpeSupportDiags.HpRpsTransferManager.1\CLSID@ {9E7179CA-8D7A-4308-9DDD-8315696D3A54}
Reg HKLM\SOFTWARE\Classes\HpeSupportDiags.HpRpsTransferStatus@ HpRpsTransferStatus Class
Reg HKLM\SOFTWARE\Classes\HpeSupportDiags.HpRpsTransferStatus\CLSID
Reg HKLM\SOFTWARE\Classes\HpeSupportDiags.HpRpsTransferStatus\CLSID@ {64972A20-E28C-41CA-9ACD-0FD867EFD961}
Reg HKLM\SOFTWARE\Classes\HpeSupportDiags.HpRpsTransferStatus\CurVer
Reg HKLM\SOFTWARE\Classes\HpeSupportDiags.HpRpsTransferStatus\CurVer@ HpeSupportDiags.HpRpsTransferStatus.1
Reg HKLM\SOFTWARE\Classes\HpeSupportDiags.HpRpsTransferStatus.1@ HpRpsTransferStatus Class
Reg HKLM\SOFTWARE\Classes\HpeSupportDiags.HpRpsTransferStatus.1\CLSID
Reg HKLM\SOFTWARE\Classes\HpeSupportDiags.HpRpsTransferStatus.1\CLSID@ {64972A20-E28C-41CA-9ACD-0FD867EFD961}
Reg HKLM\SOFTWARE\Classes\HpeSupportDiags.RulesEngine2@ HpRulesEngine2 Class
Reg HKLM\SOFTWARE\Classes\HpeSupportDiags.RulesEngine2\CLSID
Reg HKLM\SOFTWARE\Classes\HpeSupportDiags.RulesEngine2\CLSID@ {A2C4560E-324C-47AF-8F7C-032E9374013E}
Reg HKLM\SOFTWARE\Classes\HpeSupportDiags.RulesEngine2\CurVer
Reg HKLM\SOFTWARE\Classes\HpeSupportDiags.RulesEngine2\CurVer@ HpeSupportDiags.RulesEngine2.1
Reg HKLM\SOFTWARE\Classes\HpeSupportDiags.RulesEngine2.1@ HpRulesEngine2 Class
Reg HKLM\SOFTWARE\Classes\HpeSupportDiags.RulesEngine2.1\CLSID
Reg HKLM\SOFTWARE\Classes\HpeSupportDiags.RulesEngine2.1\CLSID@ {A2C4560E-324C-47AF-8F7C-032E9374013E}
Reg HKLM\SOFTWARE\Classes\HpUpdate.HpuHistory@ HpuHistory Class
Reg HKLM\SOFTWARE\Classes\HpUpdate.HpuHistory\CLSID
Reg HKLM\SOFTWARE\Classes\HpUpdate.HpuHistory\CLSID@ {F67E3DA1-5425-4449-8E49-3789F6C5DCCC}
Reg HKLM\SOFTWARE\Classes\HpUpdate.HpuHistory\CurVer
Reg HKLM\SOFTWARE\Classes\HpUpdate.HpuHistory\CurVer@ HpUpdate.HpuHistory.1
Reg HKLM\SOFTWARE\Classes\HpUpdate.HpuHistory.1@ HpuHistory Class
Reg HKLM\SOFTWARE\Classes\HpUpdate.HpuHistory.1\CLSID
Reg HKLM\SOFTWARE\Classes\HpUpdate.HpuHistory.1\CLSID@ {F67E3DA1-5425-4449-8E49-3789F6C5DCCC}
Reg HKLM\SOFTWARE\Classes\HpUpdate.HpuHistoryPackage@ HpuHistoryPackage Class
Reg HKLM\SOFTWARE\Classes\HpUpdate.HpuHistoryPackage\CLSID
Reg HKLM\SOFTWARE\Classes\HpUpdate.HpuHistoryPackage\CLSID@ {04EFFB92-ABDC-4709-A4A5-CC8DD734810F}
Reg HKLM\SOFTWARE\Classes\HpUpdate.HpuHistoryPackage\CurVer
Reg HKLM\SOFTWARE\Classes\HpUpdate.HpuHistoryPackage\CurVer@ HpUpdate.HpuHistoryPackage.1
Reg HKLM\SOFTWARE\Classes\HpUpdate.HpuHistoryPackage.1@ HpuHistoryPackage Class
Reg HKLM\SOFTWARE\Classes\HpUpdate.HpuHistoryPackage.1\CLSID
Reg HKLM\SOFTWARE\Classes\HpUpdate.HpuHistoryPackage.1\CLSID@ {04EFFB92-ABDC-4709-A4A5-CC8DD734810F}
Reg HKLM\SOFTWARE\Classes\HpUpdate.HpuHistoryPackages@ HpuHistoryPackages Class
Reg HKLM\SOFTWARE\Classes\HpUpdate.HpuHistoryPackages\CLSID
Reg HKLM\SOFTWARE\Classes\HpUpdate.HpuHistoryPackages\CLSID@ {20FF051A-FA9F-44BF-946A-2747B4E1D9E4}
Reg HKLM\SOFTWARE\Classes\HpUpdate.HpuHistoryPackages\CurVer
Reg HKLM\SOFTWARE\Classes\HpUpdate.HpuHistoryPackages\CurVer@ HpUpdate.HpuHistoryPackages.1
Reg HKLM\SOFTWARE\Classes\HpUpdate.HpuHistoryPackages.1@ HpuHistoryPackages Class
Reg HKLM\SOFTWARE\Classes\HpUpdate.HpuHistoryPackages.1\CLSID
Reg HKLM\SOFTWARE\Classes\HpUpdate.HpuHistoryPackages.1\CLSID@ {20FF051A-FA9F-44BF-946A-2747B4E1D9E4}
Reg HKLM\SOFTWARE\Classes\HpUpdate.HpuPackage@ HpuPackage Class
Reg HKLM\SOFTWARE\Classes\HpUpdate.HpuPackage\CLSID
Reg HKLM\SOFTWARE\Classes\HpUpdate.HpuPackage\CLSID@ {426FD551-CF04-4661-AB8F-5C46B4B3EA63}
Reg HKLM\SOFTWARE\Classes\HpUpdate.HpuPackage\CurVer
Reg HKLM\SOFTWARE\Classes\HpUpdate.HpuPackage\CurVer@ HpUpdate.HpuPackage.1
Reg HKLM\SOFTWARE\Classes\HpUpdate.HpuPackage.1@ HpuPackage Class
Reg HKLM\SOFTWARE\Classes\HpUpdate.HpuPackage.1\CLSID
Reg HKLM\SOFTWARE\Classes\HpUpdate.HpuPackage.1\CLSID@ {426FD551-CF04-4661-AB8F-5C46B4B3EA63}
Reg HKLM\SOFTWARE\Classes\HpUpdate.HpuPackages@ HpuPackages Class
Reg HKLM\SOFTWARE\Classes\HpUpdate.HpuPackages\CLSID
Reg HKLM\SOFTWARE\Classes\HpUpdate.HpuPackages\CLSID@ {14160CD3-EC2D-4E01-9D3F-9F8F091B646D}
Reg HKLM\SOFTWARE\Classes\HpUpdate.HpuPackages\CurVer
Reg HKLM\SOFTWARE\Classes\HpUpdate.HpuPackages\CurVer@ HpUpdate.HpuPackages.1
Reg HKLM\SOFTWARE\Classes\HpUpdate.HpuPackages.1@ HpuPackages Class
Reg HKLM\SOFTWARE\Classes\HpUpdate.HpuPackages.1\CLSID
Reg HKLM\SOFTWARE\Classes\HpUpdate.HpuPackages.1\CLSID@ {14160CD3-EC2D-4E01-9D3F-9F8F091B646D}
Reg HKLM\SOFTWARE\Classes\HpUpdate.HpUpdate@ HpUpdate Class
Reg HKLM\SOFTWARE\Classes\HpUpdate.HpUpdate\CLSID
Reg HKLM\SOFTWARE\Classes\HpUpdate.HpUpdate\CLSID@ {A984F2E6-4987-40A1-AA4E-22AECAC00233}
Reg HKLM\SOFTWARE\Classes\HpUpdate.HpUpdate\CurVer
Reg HKLM\SOFTWARE\Classes\HpUpdate.HpUpdate\CurVer@ HpUpdate.HpUpdate.1
Reg HKLM\SOFTWARE\Classes\HpUpdate.HpUpdate.1@ HpUpdate Class
Reg HKLM\SOFTWARE\Classes\HpUpdate.HpUpdate.1\CLSID
Reg HKLM\SOFTWARE\Classes\HpUpdate.HpUpdate.1\CLSID@ {A984F2E6-4987-40A1-AA4E-22AECAC00233}
Reg HKLM\SOFTWARE\Classes\HPUpdate.HpuSettings@ HpuSettings Class
Reg HKLM\SOFTWARE\Classes\HPUpdate.HpuSettings\CLSID
Reg HKLM\SOFTWARE\Classes\HPUpdate.HpuSettings\CLSID@ {4E26764A-3522-4FB3-B432-EE710079C2B4}
Reg HKLM\SOFTWARE\Classes\HPUpdate.HpuSettings\CurVer
Reg HKLM\SOFTWARE\Classes\HPUpdate.HpuSettings\CurVer@ HPUpdate.HpuSettings.1
Reg HKLM\SOFTWARE\Classes\HPUpdate.HpuSettings.1@ HpuSettings Class
Reg HKLM\SOFTWARE\Classes\HPUpdate.HpuSettings.1\CLSID
Reg HKLM\SOFTWARE\Classes\HPUpdate.HpuSettings.1\CLSID@ {4E26764A-3522-4FB3-B432-EE710079C2B4}
Reg HKLM\SOFTWARE\Classes\HpUpdate.HpuStatus@ HpuStatus Class
Reg HKLM\SOFTWARE\Classes\HpUpdate.HpuStatus\CLSID
Reg HKLM\SOFTWARE\Classes\HpUpdate.HpuStatus\CLSID@ {68E61357-E767-4288-8F61-39EB10D709B7}
Reg HKLM\SOFTWARE\Classes\HpUpdate.HpuStatus\CurVer
Reg HKLM\SOFTWARE\Classes\HpUpdate.HpuStatus\CurVer@ HpUpdate.HpuStatus.1
Reg HKLM\SOFTWARE\Classes\HpUpdate.HpuStatus.1@ HpuStatus Class
Reg HKLM\SOFTWARE\Classes\HpUpdate.HpuStatus.1\CLSID
Reg HKLM\SOFTWARE\Classes\HpUpdate.HpuStatus.1\CLSID@ {68E61357-E767-4288-8F61-39EB10D709B7}
Reg HKLM\SOFTWARE\Classes\HWDeviceLogin.IDHWDevice@ Windows Live HW Device
Reg HKLM\SOFTWARE\Classes\HWDeviceLogin.IDHWDevice\CLSID
Reg HKLM\SOFTWARE\Classes\HWDeviceLogin.IDHWDevice\CLSID@ {1C109E4C-2F30-4EA3-A57A-A290877A2303}
Reg HKLM\SOFTWARE\Classes\HWDeviceLogin.IDHWDevice\CurVer
Reg HKLM\SOFTWARE\Classes\HWDeviceLogin.IDHWDevice\CurVer@ HWDeviceLogin.IDHWDevice.1
Reg HKLM\SOFTWARE\Classes\HWDeviceLogin.IDHWDevice.1@ Windows Live HW Device
Reg HKLM\SOFTWARE\Classes\HWDeviceLogin.IDHWDevice.1\CLSID
Reg HKLM\SOFTWARE\Classes\HWDeviceLogin.IDHWDevice.1\CLSID@ {1C109E4C-2F30-4EA3-A57A-A290877A2303}
Reg HKLM\SOFTWARE\Classes\IDBHO.IDBHOCtrl@ Windows Live Sign-in Control
Reg HKLM\SOFTWARE\Classes\IDBHO.IDBHOCtrl\CLSID
Reg HKLM\SOFTWARE\Classes\IDBHO.IDBHOCtrl\CLSID@ {D2517915-48CE-4286-970F-921E881B8C5C}
Reg HKLM\SOFTWARE\Classes\IDBHO.IDBHOCtrl\CurVer
Reg HKLM\SOFTWARE\Classes\IDBHO.IDBHOCtrl\CurVer@ IDBHO.IDBHOCtrl.1
Reg HKLM\SOFTWARE\Classes\IDBHO.IDBHOCtrl.1@ Windows Live Sign-in Control
Reg HKLM\SOFTWARE\Classes\IDBHO.IDBHOCtrl.1\CLSID
Reg HKLM\SOFTWARE\Classes\IDBHO.IDBHOCtrl.1\CLSID@ {D2517915-48CE-4286-970F-921E881B8C5C}
Reg HKLM\SOFTWARE\Classes\IDBHO.IDBrowserExtension@ Windows Live Sign-in Helper
Reg HKLM\SOFTWARE\Classes\IDBHO.IDBrowserExtension\CLSID
Reg HKLM\SOFTWARE\Classes\IDBHO.IDBrowserExtension\CLSID@ {9030D464-4C02-4ABF-8ECC-5164760863C6}
Reg HKLM\SOFTWARE\Classes\IDBHO.IDBrowserExtension\CurVer
Reg HKLM\SOFTWARE\Classes\IDBHO.IDBrowserExtension\CurVer@ IDBHO.IDBrowserExtension.1
Reg HKLM\SOFTWARE\Classes\IDBHO.IDBrowserExtension.1@ Windows Live Sign-in Helper
Reg HKLM\SOFTWARE\Classes\IDBHO.IDBrowserExtension.1\CLSID
Reg HKLM\SOFTWARE\Classes\IDBHO.IDBrowserExtension.1\CLSID@ {9030D464-4C02-4ABF-8ECC-5164760863C6}
Reg HKLM\SOFTWARE\Classes\IPodManager.IPodManagerUI.1@ IPodManagerUI Class
Reg HKLM\SOFTWARE\Classes\IPodManager.IPodManagerUI.1\CLSID
Reg HKLM\SOFTWARE\Classes\IPodManager.IPodManagerUI.1\CLSID@ {80EE9910-D470-4AED-AC5D-987046FDB574}
Reg HKLM\SOFTWARE\Classes\IPodService.iPodManager@ iPodManager Class
Reg HKLM\SOFTWARE\Classes\IPodService.iPodManager\CLSID
Reg HKLM\SOFTWARE\Classes\IPodService.iPodManager\CLSID@ {7A7FB085-6068-4898-8CCA-480A9187277C}
Reg HKLM\SOFTWARE\Classes\IPodService.iPodManager\CurVer
Reg HKLM\SOFTWARE\Classes\IPodService.iPodManager\CurVer@ IPodService.iPodManager.1
Reg HKLM\SOFTWARE\Classes\IPodService.iPodManager.1@ iPodManager Class
Reg HKLM\SOFTWARE\Classes\IPodService.iPodManager.1\CLSID
Reg HKLM\SOFTWARE\Classes\IPodService.iPodManager.1\CLSID@ {7A7FB085-6068-4898-8CCA-480A9187277C}
Reg HKLM\SOFTWARE\Classes\IpodService.ItunesDevicePrefs@ ItunesDevicePrefs Class
Reg HKLM\SOFTWARE\Classes\IpodService.ItunesDevicePrefs\CLSID
Reg HKLM\SOFTWARE\Classes\IpodService.ItunesDevicePrefs\CLSID@ {B33927D0-89E6-45D8-87C7-27F3DE3EFDE6}
Reg HKLM\SOFTWARE\Classes\IpodService.ItunesDevicePrefs\CurVer
Reg HKLM\SOFTWARE\Classes\IpodService.ItunesDevicePrefs\CurVer@ IpodService.ItunesDevicePrefs.1
Reg HKLM\SOFTWARE\Classes\IpodService.ItunesDevicePrefs.1@ ItunesDevicePrefs Class
Reg HKLM\SOFTWARE\Classes\IpodService.ItunesDevicePrefs.1\CLSID
Reg HKLM\SOFTWARE\Classes\IpodService.ItunesDevicePrefs.1\CLSID@ {B33927D0-89E6-45D8-87C7-27F3DE3EFDE6}
Reg HKLM\SOFTWARE\Classes\IpodService.ItunesDevices@ ItunesDevices Class
Reg HKLM\SOFTWARE\Classes\IpodService.ItunesDevices\CLSID
Reg HKLM\SOFTWARE\Classes\IpodService.ItunesDevices\CLSID@ {368F81BC-9439-41A8-B532-39C8D7E7D147}
Reg HKLM\SOFTWARE\Classes\IpodService.ItunesDevices\CurVer
Reg HKLM\SOFTWARE\Classes\IpodService.ItunesDevices\CurVer@ IpodService.ItunesDevices.1
Reg HKLM\SOFTWARE\Classes\IpodService.ItunesDevices.1@ ItunesDevices Class
Reg HKLM\SOFTWARE\Classes\IpodService.ItunesDevices.1\CLSID
Reg HKLM\SOFTWARE\Classes\IpodService.ItunesDevices.1\CLSID@ {368F81BC-9439-41A8-B532-39C8D7E7D147}
Reg HKLM\SOFTWARE\Classes\IpodService.ItunesService@ ItunesService Class
Reg HKLM\SOFTWARE\Classes\IpodService.ItunesService\CLSID
Reg HKLM\SOFTWARE\Classes\IpodService.ItunesService\CLSID@ {063D34A4-BF84-4B8D-B699-E8CA06504DDE}
Reg HKLM\SOFTWARE\Classes\IpodService.ItunesService\CurVer
Reg HKLM\SOFTWARE\Classes\IpodService.ItunesService\CurVer@ IpodService.ItunesService.1
Reg HKLM\SOFTWARE\Classes\IpodService.ItunesService.1@ ItunesService Class
Reg HKLM\SOFTWARE\Classes\IpodService.ItunesService.1\CLSID
Reg HKLM\SOFTWARE\Classes\IpodService.ItunesService.1\CLSID@ {063D34A4-BF84-4B8D-B699-E8CA06504DDE}
Reg HKLM\SOFTWARE\Classes\iPodService.ServiceDiagnostics@ ServiceDiagnostics Class
Reg HKLM\SOFTWARE\Classes\iPodService.ServiceDiagnostics\CLSID
Reg HKLM\SOFTWARE\Classes\iPodService.ServiceDiagnostics\CLSID@ {7CCCACE3-3DEE-4659-93AA-19E6C38D8EEC}
Reg HKLM\SOFTWARE\Classes\iPodService.ServiceDiagnostics\CurVer
Reg HKLM\SOFTWARE\Classes\iPodService.ServiceDiagnostics\CurVer@ iPodService.ServiceDiagnostics.1
Reg HKLM\SOFTWARE\Classes\iPodService.ServiceDiagnostics.1@ ServiceDiagnostics Class
Reg HKLM\SOFTWARE\Classes\iPodService.ServiceDiagnostics.1\CLSID
Reg HKLM\SOFTWARE\Classes\iPodService.ServiceDiagnostics.1\CLSID@ {7CCCACE3-3DEE-4659-93AA-19E6C38D8EEC}
Reg HKLM\SOFTWARE\Classes\IPodUpdaterExt.iPodUpdaterInterface@ iPodUpdaterInterface Class
Reg HKLM\SOFTWARE\Classes\IPodUpdaterExt.iPodUpdaterInterface\CLSID
Reg HKLM\SOFTWARE\Classes\IPodUpdaterExt.iPodUpdaterInterface\CLSID@ {F7A782D3-2DDD-4327-BB70-0D1D0F1E38B0}
Reg HKLM\SOFTWARE\Classes\IPodUpdaterExt.iPodUpdaterInterface\CurVer
Reg HKLM\SOFTWARE\Classes\IPodUpdaterExt.iPodUpdaterInterface\CurVer@ IPodUpdaterExt.iPodUpdaterInterface.1
Reg HKLM\SOFTWARE\Classes\IPodUpdaterExt.iPodUpdaterInterface.1@ iPodUpdaterInterface Class
Reg HKLM\SOFTWARE\Classes\IPodUpdaterExt.iPodUpdaterInterface.1\CLSID
Reg HKLM\SOFTWARE\Classes\IPodUpdaterExt.iPodUpdaterInterface.1\CLSID@ {F7A782D3-2DDD-4327-BB70-0D1D0F1E38B0}
Reg HKLM\SOFTWARE\Classes\ITDetector.iTunesDetector@ iTunesDetector Class
Reg HKLM\SOFTWARE\Classes\ITDetector.iTunesDetector\CLSID
Reg HKLM\SOFTWARE\Classes\ITDetector.iTunesDetector\CLSID@ {D719897A-B07A-4C0C-AEA9-9B663A28DFCB}
Reg HKLM\SOFTWARE\Classes\ITDetector.iTunesDetector\CurVer
Reg HKLM\SOFTWARE\Classes\ITDetector.iTunesDetector\CurVer@ ITDetector.iTunesDetector.1
Reg HKLM\SOFTWARE\Classes\ITDetector.iTunesDetector.1@ iTunesDetector Class
Reg HKLM\SOFTWARE\Classes\ITDetector.iTunesDetector.1\CLSID
Reg HKLM\SOFTWARE\Classes\ITDetector.iTunesDetector.1\CLSID@ {D719897A-B07A-4C0C-AEA9-9B663A28DFCB}
Reg HKLM\SOFTWARE\Classes\itms@ URL:iTunes Store Protocol
Reg HKLM\SOFTWARE\Classes\itms@AppUserModelID Apple.iTunes
Reg HKLM\SOFTWARE\Classes\itms@URL Protocol
Reg HKLM\SOFTWARE\Classes\itms\DefaultIcon
Reg HKLM\SOFTWARE\Classes\itms\DefaultIcon@ C:\Program Files\iTunes\iTunes.exe
Reg HKLM\SOFTWARE\Classes\itms\shell
Reg HKLM\SOFTWARE\Classes\itms\shell@
Reg HKLM\SOFTWARE\Classes\itms\shell\open
Reg HKLM\SOFTWARE\Classes\itms\shell\open@
Reg HKLM\SOFTWARE\Classes\itms\shell\open\command
Reg HKLM\SOFTWARE\Classes\itms\shell\open\command@ C:\Program Files\iTunes\iTunes.exe /url "%1"
Reg HKLM\SOFTWARE\Classes\itmss@ URL:iTunes Store Secure Protocol
Reg HKLM\SOFTWARE\Classes\itmss@AppUserModelID Apple.iTunes
Reg HKLM\SOFTWARE\Classes\itmss@URL Protocol
Reg HKLM\SOFTWARE\Classes\itmss\DefaultIcon
Reg HKLM\SOFTWARE\Classes\itmss\DefaultIcon@ C:\Program Files\iTunes\iTunes.exe
Reg HKLM\SOFTWARE\Classes\itmss\shell
Reg HKLM\SOFTWARE\Classes\itmss\shell@
Reg HKLM\SOFTWARE\Classes\itmss\shell\open
Reg HKLM\SOFTWARE\Classes\itmss\shell\open@
Reg HKLM\SOFTWARE\Classes\itmss\shell\open\command
Reg HKLM\SOFTWARE\Classes\itmss\shell\open\command@ C:\Program Files\iTunes\iTunes.exe /url "%1"
Reg HKLM\SOFTWARE\Classes\itpc@ URL:iTunes Podcast
Reg HKLM\SOFTWARE\Classes\itpc@AppUserModelID Apple.iTunes
Reg HKLM\SOFTWARE\Classes\itpc@URL Protocol
Reg HKLM\SOFTWARE\Classes\itpc\DefaultIcon
Reg HKLM\SOFTWARE\Classes\itpc\DefaultIcon@ C:\Program Files\iTunes\iTunes.exe
Reg HKLM\SOFTWARE\Classes\itpc\shell
Reg HKLM\SOFTWARE\Classes\itpc\shell@
Reg HKLM\SOFTWARE\Classes\itpc\shell\open
Reg HKLM\SOFTWARE\Classes\itpc\shell\open@
Reg HKLM\SOFTWARE\Classes\itpc\shell\open\command
Reg HKLM\SOFTWARE\Classes\itpc\shell\open\command@ C:\Program Files\iTunes\iTunes.exe /url "%1"
Reg HKLM\SOFTWARE\Classes\iTunes@ URL:iTunes Store Protocol
Reg HKLM\SOFTWARE\Classes\iTunes@AppUserModelID Apple.iTunes
Reg HKLM\SOFTWARE\Classes\iTunes@URL Protocol
Reg HKLM\SOFTWARE\Classes\iTunes\DefaultIcon
Reg HKLM\SOFTWARE\Classes\iTunes\DefaultIcon@ C:\Program Files\iTunes\iTunes.exe
Reg HKLM\SOFTWARE\Classes\iTunes\shell
Reg HKLM\SOFTWARE\Classes\iTunes\shell@
Reg HKLM\SOFTWARE\Classes\iTunes\shell\open
Reg HKLM\SOFTWARE\Classes\iTunes\shell\open@
Reg HKLM\SOFTWARE\Classes\iTunes\shell\open\command
Reg HKLM\SOFTWARE\Classes\iTunes\shell\open\command@ C:\Program Files\iTunes\iTunes.exe /url "%1"
Reg HKLM\SOFTWARE\Classes\iTunes.aa@ Audible Audio
Reg HKLM\SOFTWARE\Classes\iTunes.aa@FriendlyTypeName @C:\Program Files\iTunes\iTunes.Resources\iTunesRegistry.dll,-4
Reg HKLM\SOFTWARE\Classes\iTunes.aa@AppUserModelID Apple.iTunes
Reg HKLM\SOFTWARE\Classes\iTunes.aa\CurVer
Reg HKLM\SOFTWARE\Classes\iTunes.aa\CurVer@ iTunes.aa
Reg HKLM\SOFTWARE\Classes\iTunes.aa\DefaultIcon
Reg HKLM\SOFTWARE\Classes\iTunes.aa\DefaultIcon@ C:\Program Files\iTunes\iTunes.exe,-130
Reg HKLM\SOFTWARE\Classes\iTunes.aa\shell
Reg HKLM\SOFTWARE\Classes\iTunes.aa\shell@ play
Reg HKLM\SOFTWARE\Classes\iTunes.aa\shell\open
Reg HKLM\SOFTWARE\Classes\iTunes.aa\shell\open@ &Open
Reg HKLM\SOFTWARE\Classes\iTunes.aa\shell\open\command
Reg HKLM\SOFTWARE\Classes\iTunes.aa\shell\open\command@ "C:\Program Files\iTunes\iTunes.exe" /open "%L"
Reg HKLM\SOFTWARE\Classes\iTunes.aa\shell\play
Reg HKLM\SOFTWARE\Classes\iTunes.aa\shell\play@ &Play
Reg HKLM\SOFTWARE\Classes\iTunes.aa\shell\play\command
Reg HKLM\SOFTWARE\Classes\iTunes.aa\shell\play\command@ "C:\Program Files\iTunes\iTunes.exe" /play "%L"
Reg HKLM\SOFTWARE\Classes\iTunes.aax@ Audible Audio
Reg HKLM\SOFTWARE\Classes\iTunes.aax@FriendlyTypeName @C:\Program Files\iTunes\iTunes.Resources\iTunesRegistry.dll,-4
Reg HKLM\SOFTWARE\Classes\iTunes.aax@AppUserModelID Apple.iTunes
Reg HKLM\SOFTWARE\Classes\iTunes.aax\CurVer
Reg HKLM\SOFTWARE\Classes\iTunes.aax\CurVer@ iTunes.aax
Reg HKLM\SOFTWARE\Classes\iTunes.aax\DefaultIcon
Reg HKLM\SOFTWARE\Classes\iTunes.aax\DefaultIcon@ C:\Program Files\iTunes\iTunes.exe,-130
Reg HKLM\SOFTWARE\Classes\iTunes.aax\shell
Reg HKLM\SOFTWARE\Classes\iTunes.aax\shell@ play
Reg HKLM\SOFTWARE\Classes\iTunes.aax\shell\open
Reg HKLM\SOFTWARE\Classes\iTunes.aax\shell\open@ &Open
Reg HKLM\SOFTWARE\Classes\iTunes.aax\shell\open\command
Reg HKLM\SOFTWARE\Classes\iTunes.aax\shell\open\command@ "C:\Program Files\iTunes\iTunes.exe" /open "%L"
Reg HKLM\SOFTWARE\Classes\iTunes.aax\shell\play
Reg HKLM\SOFTWARE\Classes\iTunes.aax\shell\play@ &Play
Reg HKLM\SOFTWARE\Classes\iTunes.aax\shell\play\command
Reg HKLM\SOFTWARE\Classes\iTunes.aax\shell\play\command@ "C:\Program Files\iTunes\iTunes.exe" /play "%L"
Reg HKLM\SOFTWARE\Classes\iTunes.aif@ AIFF Audio File
Reg HKLM\SOFTWARE\Classes\iTunes.aif@FriendlyTypeName @C:\Program Files\iTunes\iTunes.Resources\iTunesRegistry.dll,-3
Reg HKLM\SOFTWARE\Classes\iTunes.aif@AppUserModelID Apple.iTunes
Reg HKLM\SOFTWARE\Classes\iTunes.aif\CurVer
Reg HKLM\SOFTWARE\Classes\iTunes.aif\CurVer@ iTunes.aif
Reg HKLM\SOFTWARE\Classes\iTunes.aif\DefaultIcon
Reg HKLM\SOFTWARE\Classes\iTunes.aif\DefaultIcon@ C:\Program Files\iTunes\iTunes.exe,-132
Reg HKLM\SOFTWARE\Classes\iTunes.aif\shell
Reg HKLM\SOFTWARE\Classes\iTunes.aif\shell@ play
Reg HKLM\SOFTWARE\Classes\iTunes.aif\shell\open
Reg HKLM\SOFTWARE\Classes\iTunes.aif\shell\open@ &Open
Reg HKLM\SOFTWARE\Classes\iTunes.aif\shell\open\command
Reg HKLM\SOFTWARE\Classes\iTunes.aif\shell\open\command@ "C:\Program Files\iTunes\iTunes.exe" /open "%L"
Reg HKLM\SOFTWARE\Classes\iTunes.aif\shell\play
Reg HKLM\SOFTWARE\Classes\iTunes.aif\shell\play@ &Play
Reg HKLM\SOFTWARE\Classes\iTunes.aif\shell\play\command
Reg HKLM\SOFTWARE\Classes\iTunes.aif\shell\play\command@ "C:\Program Files\iTunes\iTunes.exe" /play "%L"
Reg HKLM\SOFTWARE\Classes\iTunes.aif\shellex
Reg HKLM\SOFTWARE\Classes\iTunes.aif\shellex@
Reg HKLM\SOFTWARE\Classes\iTunes.aif\shellex\{8895b1c6-b41f-4c1c-a562-0d564250836f}
Reg HKLM\SOFTWARE\Classes\iTunes.aif\shellex\{8895b1c6-b41f-4c1c-a562-0d564250836f}@ {031EE060-67BC-460d-8847-E4A7C5E45A27}
Reg HKLM\SOFTWARE\Classes\iTunes.aifc@ AIFF Audio File
Reg HKLM\SOFTWARE\Classes\iTunes.aifc@FriendlyTypeName @C:\Program Files\iTunes\iTunes.Resources\iTunesRegistry.dll,-3
Reg HKLM\SOFTWARE\Classes\iTunes.aifc@AppUserModelID Apple.iTunes
Reg HKLM\SOFTWARE\Classes\iTunes.aifc\CurVer
Reg HKLM\SOFTWARE\Classes\iTunes.aifc\CurVer@ iTunes.aifc
Reg HKLM\SOFTWARE\Classes\iTunes.aifc\DefaultIcon
Reg HKLM\SOFTWARE\Classes\iTunes.aifc\DefaultIcon@ C:\Program Files\iTunes\iTunes.exe,-132
Reg HKLM\SOFTWARE\Classes\iTunes.aifc\shell
Reg HKLM\SOFTWARE\Classes\iTunes.aifc\shell@ play
Reg HKLM\SOFTWARE\Classes\iTunes.aifc\shell\open
Reg HKLM\SOFTWARE\Classes\iTunes.aifc\shell\open@ &Open
Reg HKLM\SOFTWARE\Classes\iTunes.aifc\shell\open\command
Reg HKLM\SOFTWARE\Classes\iTunes.aifc\shell\open\command@ "C:\Program Files\iTunes\iTunes.exe" /open "%L"
Reg HKLM\SOFTWARE\Classes\iTunes.aifc\shell\play
Reg HKLM\SOFTWARE\Classes\iTunes.aifc\shell\play@ &Play
Reg HKLM\SOFTWARE\Classes\iTunes.aifc\shell\play\command
Reg HKLM\SOFTWARE\Classes\iTunes.aifc\shell\play\command@ "C:\Program Files\iTunes\iTunes.exe" /play "%L"
Reg HKLM\SOFTWARE\Classes\iTunes.aifc\shellex
Reg HKLM\SOFTWARE\Classes\iTunes.aifc\shellex@
Reg HKLM\SOFTWARE\Classes\iTunes.aifc\shellex\{8895b1c6-b41f-4c1c-a562-0d564250836f}
Reg HKLM\SOFTWARE\Classes\iTunes.aifc\shellex\{8895b1c6-b41f-4c1c-a562-0d564250836f}@ {031EE060-67BC-460d-8847-E4A7C5E45A27}
Reg HKLM\SOFTWARE\Classes\iTunes.aiff@ AIFF Audio File
Reg HKLM\SOFTWARE\Classes\iTunes.aiff@FriendlyTypeName @C:\Program Files\iTunes\iTunes.Resources\iTunesRegistry.dll,-3
Reg HKLM\SOFTWARE\Classes\iTunes.aiff@AppUserModelID Apple.iTunes
Reg HKLM\SOFTWARE\Classes\iTunes.aiff\CurVer
Reg HKLM\SOFTWARE\Classes\iTunes.aiff\CurVer@ iTunes.aiff
Reg HKLM\SOFTWARE\Classes\iTunes.aiff\DefaultIcon
Reg HKLM\SOFTWARE\Classes\iTunes.aiff\DefaultIcon@ C:\Program Files\iTunes\iTunes.exe,-132
Reg HKLM\SOFTWARE\Classes\iTunes.aiff\shell
Reg HKLM\SOFTWARE\Classes\iTunes.aiff\shell@ play
Reg HKLM\SOFTWARE\Classes\iTunes.aiff\shell\open
Reg HKLM\SOFTWARE\Classes\iTunes.aiff\shell\open@ &Open
Reg HKLM\SOFTWARE\Classes\iTunes.aiff\shell\open\command
Reg HKLM\SOFTWARE\Classes\iTunes.aiff\shell\open\command@ "C:\Program Files\iTunes\iTunes.exe" /open "%L"
Reg HKLM\SOFTWARE\Classes\iTunes.aiff\shell\play
Reg HKLM\SOFTWARE\Classes\iTunes.aiff\shell\play@ &Play
Reg HKLM\SOFTWARE\Classes\iTunes.aiff\shell\play\command
Reg HKLM\SOFTWARE\Classes\iTunes.aiff\shell\play\command@ "C:\Program Files\iTunes\iTunes.exe" /play "%L"
Reg HKLM\SOFTWARE\Classes\iTunes.aiff\shellex
Reg HKLM\SOFTWARE\Classes\iTunes.aiff\shellex@
Reg HKLM\SOFTWARE\Classes\iTunes.aiff\shellex\{8895b1c6-b41f-4c1c-a562-0d564250836f}
Reg HKLM\SOFTWARE\Classes\iTunes.aiff\shellex\{8895b1c6-b41f-4c1c-a562-0d564250836f}@ {031EE060-67BC-460d-8847-E4A7C5E45A27}
Reg HKLM\SOFTWARE\Classes\iTunes.Application@ iTunes Class
Reg HKLM\SOFTWARE\Classes\iTunes.Application\CLSID
Reg HKLM\SOFTWARE\Classes\iTunes.Application\CLSID@ {DC0C2640-1415-4644-875C-6F4D769839BA}
Reg HKLM\SOFTWARE\Classes\iTunes.Application\CurVer
Reg HKLM\SOFTWARE\Classes\iTunes.Application\CurVer@ iTunes.Application.1
Reg HKLM\SOFTWARE\Classes\iTunes.Application.1@ iTunes Class
Reg HKLM\SOFTWARE\Classes\iTunes.Application.1\CLSID
Reg HKLM\SOFTWARE\Classes\iTunes.Application.1\CLSID@ {DC0C2640-1415-4644-875C-6F4D769839BA}
Reg HKLM\SOFTWARE\Classes\iTunes.AssocProtocol.daap@ URL:Digital Audio Access Protocol
Reg HKLM\SOFTWARE\Classes\iTunes.AssocProtocol.daap@URL Protocol
Reg HKLM\SOFTWARE\Classes\iTunes.AssocProtocol.daap@FriendlyTypeName @C:\Program Files\iTunes\iTunes.Resources\iTunesRegistry.dll,102
Reg HKLM\SOFTWARE\Classes\iTunes.AssocProtocol.daap\DefaultIcon
Reg HKLM\SOFTWARE\Classes\iTunes.AssocProtocol.daap\DefaultIcon@ C:\Program Files\iTunes\iTunes.exe
Reg HKLM\SOFTWARE\Classes\iTunes.AssocProtocol.daap\shell
Reg HKLM\SOFTWARE\Classes\iTunes.AssocProtocol.daap\shell\open
Reg HKLM\SOFTWARE\Classes\iTunes.AssocProtocol.daap\shell\open\command
Reg HKLM\SOFTWARE\Classes\iTunes.AssocProtocol.daap\shell\open\command@ C:\Program Files\iTunes\iTunes.exe /url "%1"
Reg HKLM\SOFTWARE\Classes\iTunes.AssocProtocol.itms@ URL:Digital Audio Access Protocol
Reg HKLM\SOFTWARE\Classes\iTunes.AssocProtocol.itms@URL Protocol
Reg HKLM\SOFTWARE\Classes\iTunes.AssocProtocol.itms@FriendlyTypeName @C:\Program Files\iTunes\iTunes.Resources\iTunesRegistry.dll,100
Reg HKLM\SOFTWARE\Classes\iTunes.AssocProtocol.itms\DefaultIcon
Reg HKLM\SOFTWARE\Classes\iTunes.AssocProtocol.itms\DefaultIcon@ C:\Program Files\iTunes\iTunes.exe
Reg HKLM\SOFTWARE\Classes\iTunes.AssocProtocol.itms\shell
Reg HKLM\SOFTWARE\Classes\iTunes.AssocProtocol.itms\shell\open
Reg HKLM\SOFTWARE\Classes\iTunes.AssocProtocol.itms\shell\open\command
Reg HKLM\SOFTWARE\Classes\iTunes.AssocProtocol.itms\shell\open\command@ C:\Program Files\iTunes\iTunes.exe /url "%1"
Reg HKLM\SOFTWARE\Classes\iTunes.AssocProtocol.itmss@ URL:Digital Audio Access Protocol
Reg HKLM\SOFTWARE\Classes\iTunes.AssocProtocol.itmss@URL Protocol
Reg HKLM\SOFTWARE\Classes\iTunes.AssocProtocol.itmss@FriendlyTypeName @C:\Program Files\iTunes\iTunes.Resources\iTunesRegistry.dll,101
Reg HKLM\SOFTWARE\Classes\iTunes.AssocProtocol.itmss\DefaultIcon
Reg HKLM\SOFTWARE\Classes\iTunes.AssocProtocol.itmss\DefaultIcon@ C:\Program Files\iTunes\iTunes.exe
Reg HKLM\SOFTWARE\Classes\iTunes.AssocProtocol.itmss\shell
Reg HKLM\SOFTWARE\Classes\iTunes.AssocProtocol.itmss\shell\open
Reg HKLM\SOFTWARE\Classes\iTunes.AssocProtocol.itmss\shell\open\command
Reg HKLM\SOFTWARE\Classes\iTunes.AssocProtocol.itmss\shell\open\command@ C:\Program Files\iTunes\iTunes.exe /url "%1"
Reg HKLM\SOFTWARE\Classes\iTunes.AssocProtocol.itpc@ URL:Digital Audio Access Protocol
Reg HKLM\SOFTWARE\Classes\iTunes.AssocProtocol.itpc@URL Protocol
Reg HKLM\SOFTWARE\Classes\iTunes.AssocProtocol.itpc@FriendlyTypeName @C:\Program Files\iTunes\iTunes.Resources\iTunesRegistry.dll,103
Reg HKLM\SOFTWARE\Classes\iTunes.AssocProtocol.itpc\DefaultIcon
Reg HKLM\SOFTWARE\Classes\iTunes.AssocProtocol.itpc\DefaultIcon@ C:\Program Files\iTunes\iTunes.exe
Reg HKLM\SOFTWARE\Classes\iTunes.AssocProtocol.itpc\shell
Reg HKLM\SOFTWARE\Classes\iTunes.AssocProtocol.itpc\shell\open
Reg HKLM\SOFTWARE\Classes\iTunes.AssocProtocol.itpc\shell\open\command
Reg HKLM\SOFTWARE\Classes\iTunes.AssocProtocol.itpc\shell\open\command@ C:\Program Files\iTunes\iTunes.exe /url "%1"
Reg HKLM\SOFTWARE\Classes\iTunes.AssocProtocol.pcast@ URL:iTunes Podcast
Reg HKLM\SOFTWARE\Classes\iTunes.AssocProtocol.pcast@URL Protocol
Reg HKLM\SOFTWARE\Classes\iTunes.AssocProtocol.pcast@FriendlyTypeName @C:\Program Files\iTunes\iTunes.Resources\iTunesRegistry.dll,104
Reg HKLM\SOFTWARE\Classes\iTunes.AssocProtocol.pcast\DefaultIcon
Reg HKLM\SOFTWARE\Classes\iTunes.AssocProtocol.pcast\DefaultIcon@ C:\Program Files\iTunes\iTunes.exe
Reg HKLM\SOFTWARE\Classes\iTunes.AssocProtocol.pcast\shell
Reg HKLM\SOFTWARE\Classes\iTunes.AssocProtocol.pcast\shell\open
Reg HKLM\SOFTWARE\Classes\iTunes.AssocProtocol.pcast\shell\open\command
Reg HKLM\SOFTWARE\Classes\iTunes.AssocProtocol.pcast\shell\open\command@ C:\Program Files\iTunes\iTunes.exe /url "%1"
Reg HKLM\SOFTWARE\Classes\iTunes.BurnCD@
Reg HKLM\SOFTWARE\Classes\iTunes.BurnCD\shell
Reg HKLM\SOFTWARE\Classes\iTunes.BurnCD\shell@
Reg HKLM\SOFTWARE\Classes\iTunes.BurnCD\shell\burn
Reg HKLM\SOFTWARE\Classes\iTunes.BurnCD\shell\burn@ Create a CD
Reg HKLM\SOFTWARE\Classes\iTunes.BurnCD\shell\burn\command
Reg HKLM\SOFTWARE\Classes\iTunes.BurnCD\shell\burn\command@ "C:\Program Files\iTunes\iTunes.exe" /AutoPlayBurn "%L"
Reg HKLM\SOFTWARE\Classes\iTunes.cda@ Audio CD Track
Reg HKLM\SOFTWARE\Classes\iTunes.cda@FriendlyTypeName @C:\Program Files\iTunes\iTunes.Resources\iTunesRegistry.dll,-5
Reg HKLM\SOFTWARE\Classes\iTunes.cda@AppUserModelID Apple.iTunes
Reg HKLM\SOFTWARE\Classes\iTunes.cda\CurVer
Reg HKLM\SOFTWARE\Classes\iTunes.cda\CurVer@ iTunes.cda
Reg HKLM\SOFTWARE\Classes\iTunes.cda\DefaultIcon
Reg HKLM\SOFTWARE\Classes\iTunes.cda\DefaultIcon@ C:\Program Files\iTunes\iTunes.exe,-256
Reg HKLM\SOFTWARE\Classes\iTunes.cda\shell
Reg HKLM\SOFTWARE\Classes\iTunes.cda\shell@ play
Reg HKLM\SOFTWARE\Classes\iTunes.cda\shell\open
Reg HKLM\SOFTWARE\Classes\iTunes.cda\shell\open@ &Open
Reg HKLM\SOFTWARE\Classes\iTunes.cda\shell\open\command
Reg HKLM\SOFTWARE\Classes\iTunes.cda\shell\open\command@ "C:\Program Files\iTunes\iTunes.exe" /open "%L"
Reg HKLM\SOFTWARE\Classes\iTunes.cda\shell\play
Reg HKLM\SOFTWARE\Classes\iTunes.cda\shell\play@ &Play
Reg HKLM\SOFTWARE\Classes\iTunes.cda\shell\play\command
Reg HKLM\SOFTWARE\Classes\iTunes.cda\shell\play\command@ "C:\Program Files\iTunes\iTunes.exe" /play "%L"
Reg HKLM\SOFTWARE\Classes\iTunes.cdda@ Audio CD Track
Reg HKLM\SOFTWARE\Classes\iTunes.cdda@FriendlyTypeName @C:\Program Files\iTunes\iTunes.Resources\iTunesRegistry.dll,-5
Reg HKLM\SOFTWARE\Classes\iTunes.cdda@AppUserModelID Apple.iTunes
Reg HKLM\SOFTWARE\Classes\iTunes.cdda\CurVer
Reg HKLM\SOFTWARE\Classes\iTunes.cdda\CurVer@ iTunes.cdda
Reg HKLM\SOFTWARE\Classes\iTunes.cdda\DefaultIcon
Reg HKLM\SOFTWARE\Classes\iTunes.cdda\DefaultIcon@ C:\Program Files\iTunes\iTunes.exe,-256
Reg HKLM\SOFTWARE\Classes\iTunes.cdda\shell
Reg HKLM\SOFTWARE\Classes\iTunes.cdda\shell@ play
Reg HKLM\SOFTWARE\Classes\iTunes.cdda\shell\open
Reg HKLM\SOFTWARE\Classes\iTunes.cdda\shell\open@ &Open
Reg HKLM\SOFTWARE\Classes\iTunes.cdda\shell\open\command
Reg HKLM\SOFTWARE\Classes\iTunes.cdda\shell\open\command@ "C:\Program Files\iTunes\iTunes.exe" /open "%L"
Reg HKLM\SOFTWARE\Classes\iTunes.cdda\shell\play
Reg HKLM\SOFTWARE\Classes\iTunes.cdda\shell\play@ &Play
Reg HKLM\SOFTWARE\Classes\iTunes.cdda\shell\play\command
Reg HKLM\SOFTWARE\Classes\iTunes.cdda\shell\play\command@ "C:\Program Files\iTunes\iTunes.exe" /play "%L"
Reg HKLM\SOFTWARE\Classes\iTunes.ImportSongsOnCD@
Reg HKLM\SOFTWARE\Classes\iTunes.ImportSongsOnCD\shell
Reg HKLM\SOFTWARE\Classes\iTunes.ImportSongsOnCD\shell@
Reg HKLM\SOFTWARE\Classes\iTunes.ImportSongsOnCD\shell\import
Reg HKLM\SOFTWARE\Classes\iTunes.ImportSongsOnCD\shell\import@ Import songs
Reg HKLM\SOFTWARE\Classes\iTunes.ImportSongsOnCD\shell\import\command
Reg HKLM\SOFTWARE\Classes\iTunes.ImportSongsOnCD\shell\import\command@ "C:\Program Files\iTunes\iTunes.exe" /AutoPlayImportSongs "%L"
Reg HKLM\SOFTWARE\Classes\iTunes.ipa@ Apple Device Application File
Reg HKLM\SOFTWARE\Classes\iTunes.ipa@FriendlyTypeName @C:\Program Files\iTunes\iTunes.Resources\iTunesRegistry.dll,-203
Reg HKLM\SOFTWARE\Classes\iTunes.ipa@AppUserModelID Apple.iTunes
Reg HKLM\SOFTWARE\Classes\iTunes.ipa\CurVer
Reg HKLM\SOFTWARE\Classes\iTunes.ipa\CurVer@ iTunes.ipa
Reg HKLM\SOFTWARE\Classes\iTunes.ipa\DefaultIcon
Reg HKLM\SOFTWARE\Classes\iTunes.ipa\DefaultIcon@ C:\Program Files\iTunes\iTunes.exe,-166
Reg HKLM\SOFTWARE\Classes\iTunes.ipa\shell
Reg HKLM\SOFTWARE\Classes\iTunes.ipa\shell@ open
Reg HKLM\SOFTWARE\Classes\iTunes.ipa\shell\open
Reg HKLM\SOFTWARE\Classes\iTunes.ipa\shell\open@ &Open
Reg HKLM\SOFTWARE\Classes\iTunes.ipa\shell\open\command
Reg HKLM\SOFTWARE\Classes\iTunes.ipa\shell\open\command@ "C:\Program Files\iTunes\iTunes.exe" /open "%L"
Reg HKLM\SOFTWARE\Classes\iTunes.ipg@ iPod Game File
Reg HKLM\SOFTWARE\Classes\iTunes.ipg@FriendlyTypeName @C:\Program Files\iTunes\iTunes.Resources\iTunesRegistry.dll,-200
Reg HKLM\SOFTWARE\Classes\iTunes.ipg@AppUserModelID Apple.iTunes
Reg HKLM\SOFTWARE\Classes\iTunes.ipg\CurVer
Reg HKLM\SOFTWARE\Classes\iTunes.ipg\CurVer@ iTunes.ipg
Reg HKLM\SOFTWARE\Classes\iTunes.ipg\DefaultIcon
Reg HKLM\SOFTWARE\Classes\iTunes.ipg\DefaultIcon@ C:\Program Files\iTunes\iTunes.exe,-162
Reg HKLM\SOFTWARE\Classes\iTunes.ipg\shell
Reg HKLM\SOFTWARE\Classes\iTunes.ipg\shell@ play
Reg HKLM\SOFTWARE\Classes\iTunes.ipg\shell\open
Reg HKLM\SOFTWARE\Classes\iTunes.ipg\shell\open@ &Open
Reg HKLM\SOFTWARE\Classes\iTunes.ipg\shell\open\command
Reg HKLM\SOFTWARE\Classes\iTunes.ipg\shell\open\command@ "C:\Program Files\iTunes\iTunes.exe" /open "%L"
Reg HKLM\SOFTWARE\Classes\iTunes.ipg\shell\play
Reg HKLM\SOFTWARE\Classes\iTunes.ipg\shell\play@ &Play
Reg HKLM\SOFTWARE\Classes\iTunes.ipg\shell\play\command
Reg HKLM\SOFTWARE\Classes\iTunes.ipg\shell\play\command@ "C:\Program Files\iTunes\iTunes.exe" /play "%L"
Reg HKLM\SOFTWARE\Classes\iTunes.ipsw@ Apple Device Software Update File
Reg HKLM\SOFTWARE\Classes\iTunes.ipsw@FriendlyTypeName @C:\Program Files\iTunes\iTunes.Resources\iTunesRegistry.dll,-201
Reg HKLM\SOFTWARE\Classes\iTunes.ipsw@AppUserModelID Apple.iTunes
Reg HKLM\SOFTWARE\Classes\iTunes.ipsw\CurVer
Reg HKLM\SOFTWARE\Classes\iTunes.ipsw\CurVer@ iTunes.ipsw
Reg HKLM\SOFTWARE\Classes\iTunes.ipsw\DefaultIcon
Reg HKLM\SOFTWARE\Classes\iTunes.ipsw\DefaultIcon@ C:\Program Files\iTunes\iTunes.exe,-163
Reg HKLM\SOFTWARE\Classes\iTunes.ipsw\shell
Reg HKLM\SOFTWARE\Classes\iTunes.ipsw\shell@ open
Reg HKLM\SOFTWARE\Classes\iTunes.ipsw\shell\open
Reg HKLM\SOFTWARE\Classes\iTunes.ipsw\shell\open@ &Open
Reg HKLM\SOFTWARE\Classes\iTunes.ipsw\shell\open\command
Reg HKLM\SOFTWARE\Classes\iTunes.ipsw\shell\open\command@ "C:\Program Files\iTunes\iTunes.exe" /open "%L"
Reg HKLM\SOFTWARE\Classes\iTunes.itdb@ iTunes Database File
Reg HKLM\SOFTWARE\Classes\iTunes.itdb@FriendlyTypeName @C:\Program Files\iTunes\iTunes.Resources\iTunesRegistry.dll,-206
Reg HKLM\SOFTWARE\Classes\iTunes.itdb@AppUserModelID Apple.iTunes2
Reg HKLM\SOFTWARE\Classes\iTunes.itdb\CurVer
Reg HKLM\SOFTWARE\Classes\iTunes.itdb\CurVer@ iTunes.itdb
Reg HKLM\SOFTWARE\Classes\iTunes.itdb\DefaultIcon
Reg HKLM\SOFTWARE\Classes\iTunes.itdb\DefaultIcon@ C:\Program Files\iTunes\iTunes.exe,-145
Reg HKLM\SOFTWARE\Classes\iTunes.itdb\shell
Reg HKLM\SOFTWARE\Classes\iTunes.itdb\shell@ open
Reg HKLM\SOFTWARE\Classes\iTunes.itdb\shell\open
Reg HKLM\SOFTWARE\Classes\iTunes.itdb\shell\open@ &Open
Reg HKLM\SOFTWARE\Classes\iTunes.itdb\shell\open\command
Reg HKLM\SOFTWARE\Classes\iTunes.itdb\shell\open\command@ "C:\Program Files\iTunes\iTunes.exe" /open "%L"
Reg HKLM\SOFTWARE\Classes\iTunes.ite@ iTunes Extras
Reg HKLM\SOFTWARE\Classes\iTunes.ite@FriendlyTypeName @C:\Program Files\iTunes\iTunes.Resources\iTunesRegistry.dll,-208
Reg HKLM\SOFTWARE\Classes\iTunes.ite@AppUserModelID Apple.iTunes
Reg HKLM\SOFTWARE\Classes\iTunes.ite\CurVer
Reg HKLM\SOFTWARE\Classes\iTunes.ite\CurVer@ iTunes.ite
Reg HKLM\SOFTWARE\Classes\iTunes.ite\DefaultIcon
Reg HKLM\SOFTWARE\Classes\iTunes.ite\DefaultIcon@ C:\Program Files\iTunes\iTunes.exe,-167
Reg HKLM\SOFTWARE\Classes\iTunes.ite\shell
Reg HKLM\SOFTWARE\Classes\iTunes.ite\shell@ open
Reg HKLM\SOFTWARE\Classes\iTunes.ite\shell\open
Reg HKLM\SOFTWARE\Classes\iTunes.ite\shell\open@ &Open
Reg HKLM\SOFTWARE\Classes\iTunes.ite\shell\open\command
Reg HKLM\SOFTWARE\Classes\iTunes.ite\shell\open\command@ "C:\Program Files\iTunes\iTunes.exe" /open "%L"
Reg HKLM\SOFTWARE\Classes\iTunes.itl@ iTunes Music Database File
Reg HKLM\SOFTWARE\Classes\iTunes.itl@FriendlyTypeName @C:\Program Files\iTunes\iTunes.Resources\iTunesRegistry.dll,-6
Reg HKLM\SOFTWARE\Classes\iTunes.itl@AppUserModelID Apple.iTunes
Reg HKLM\SOFTWARE\Classes\iTunes.itl\CurVer
Reg HKLM\SOFTWARE\Classes\iTunes.itl\CurVer@ iTunes.itl
Reg HKLM\SOFTWARE\Classes\iTunes.itl\DefaultIcon
Reg HKLM\SOFTWARE\Classes\iTunes.itl\DefaultIcon@ C:\Program Files\iTunes\iTunes.exe,-145
Reg HKLM\SOFTWARE\Classes\iTunes.itl\shell
Reg HKLM\SOFTWARE\Classes\iTunes.itl\shell@ play
Reg HKLM\SOFTWARE\Classes\iTunes.itl\shell\open
Reg HKLM\SOFTWARE\Classes\iTunes.itl\shell\open@ &Open
Reg HKLM\SOFTWARE\Classes\iTunes.itl\shell\open\command
Reg HKLM\SOFTWARE\Classes\iTunes.itl\shell\open\command@ "C:\Program Files\iTunes\iTunes.exe" /open "%L"
Reg HKLM\SOFTWARE\Classes\iTunes.itl\shell\play
Reg HKLM\SOFTWARE\Classes\iTunes.itl\shell\play@ &Play
Reg HKLM\SOFTWARE\Classes\iTunes.itl\shell\play\command
Reg HKLM\SOFTWARE\Classes\iTunes.itl\shell\play\command@ "C:\Program Files\iTunes\iTunes.exe" /open "%L"
Reg HKLM\SOFTWARE\Classes\iTunes.itlp@
Reg HKLM\SOFTWARE\Classes\iTunes.itlp@AppUserModelID Apple.iTunes
Reg HKLM\SOFTWARE\Classes\iTunes.itlp\CurVer
Reg HKLM\SOFTWARE\Classes\iTunes.itlp\CurVer@ iTunes.itlp
Reg HKLM\SOFTWARE\Classes\iTunes.itlp\DefaultIcon
Reg HKLM\SOFTWARE\Classes\iTunes.itlp\DefaultIcon@ C:\Program Files\iTunes\iTunes.exe,-168
Reg HKLM\SOFTWARE\Classes\iTunes.itlp\shell
Reg HKLM\SOFTWARE\Classes\iTunes.itlp\shell@ open
Reg HKLM\SOFTWARE\Classes\iTunes.itlp\shell\open
Reg HKLM\SOFTWARE\Classes\iTunes.itlp\shell\open@ &Open
Reg HKLM\SOFTWARE\Classes\iTunes.itlp\shell\open\command
Reg HKLM\SOFTWARE\Classes\iTunes.itlp\shell\open\command@ "C:\Program Files\iTunes\iTunes.exe" /open "%L"
Reg HKLM\SOFTWARE\Classes\iTunes.itms@ iTunes Music Store URL
Reg HKLM\SOFTWARE\Classes\iTunes.itms@FriendlyTypeName @C:\Program Files\iTunes\iTunes.Resources\iTunesRegistry.dll,-16
Reg HKLM\SOFTWARE\Classes\iTunes.itms@AppUserModelID Apple.iTunes
Reg HKLM\SOFTWARE\Classes\iTunes.itms\CurVer
Reg HKLM\SOFTWARE\Classes\iTunes.itms\CurVer@ iTunes.itms
Reg HKLM\SOFTWARE\Classes\iTunes.itms\DefaultIcon
Reg HKLM\SOFTWARE\Classes\iTunes.itms\DefaultIcon@ C:\Program Files\iTunes\iTunes.exe,-161
Reg HKLM\SOFTWARE\Classes\iTunes.itms\shell
Reg HKLM\SOFTWARE\Classes\iTunes.itms\shell@ play
Reg HKLM\SOFTWARE\Classes\iTunes.itms\shell\open
Reg HKLM\SOFTWARE\Classes\iTunes.itms\shell\open@ &Open
Reg HKLM\SOFTWARE\Classes\iTunes.itms\shell\open\command
Reg HKLM\SOFTWARE\Classes\iTunes.itms\shell\open\command@ "C:\Program Files\iTunes\iTunes.exe" /open "%L"
Reg HKLM\SOFTWARE\Classes\iTunes.itms\shell\play
Reg HKLM\SOFTWARE\Classes\iTunes.itms\shell\play@ &Play
Reg HKLM\SOFTWARE\Classes\iTunes.itms\shell\play\command
Reg HKLM\SOFTWARE\Classes\iTunes.itms\shell\play\command@ "C:\Program Files\iTunes\iTunes.exe" /open "%L"
Reg HKLM\SOFTWARE\Classes\iTunes.itpc@FriendlyTypeName @C:\Program Files\iTunes\iTunes.Resources\iTunesRegistry.dll,-17
Reg HKLM\SOFTWARE\Classes\iTunes.itpc@AppUserModelID Apple.iTunes
Reg HKLM\SOFTWARE\Classes\iTunes.itpc@ Podcast Subscription File
Reg HKLM\SOFTWARE\Classes\iTunes.itpc\CurVer
Reg HKLM\SOFTWARE\Classes\iTunes.itpc\CurVer@ iTunes.itpc
Reg HKLM\SOFTWARE\Classes\iTunes.itpc\DefaultIcon
Reg HKLM\SOFTWARE\Classes\iTunes.itpc\DefaultIcon@ C:\Program Files\iTunes\iTunes.exe,-148
Reg HKLM\SOFTWARE\Classes\iTunes.itpc\shell
Reg HKLM\SOFTWARE\Classes\iTunes.itpc\shell@ play
Reg HKLM\SOFTWARE\Classes\iTunes.itpc\shell\open
Reg HKLM\SOFTWARE\Classes\iTunes.itpc\shell\open@ &Open
Reg HKLM\SOFTWARE\Classes\iTunes.itpc\shell\open\command
Reg HKLM\SOFTWARE\Classes\iTunes.itpc\shell\open\command@ "C:\Program Files\iTunes\iTunes.exe" /open "%L"
Reg HKLM\SOFTWARE\Classes\iTunes.itpc\shell\play
Reg HKLM\SOFTWARE\Classes\iTunes.itpc\shell\play@ &Play
Reg HKLM\SOFTWARE\Classes\iTunes.itpc\shell\play\command
Reg HKLM\SOFTWARE\Classes\iTunes.itpc\shell\play\command@ "C:\Program Files\iTunes\iTunes.exe" /open "%L"
Reg HKLM\SOFTWARE\Classes\iTunes.m3u@ M3U Audio Playlist
Reg HKLM\SOFTWARE\Classes\iTunes.m3u@FriendlyTypeName @C:\Program Files\iTunes\iTunes.Resources\iTunesRegistry.dll,-7
Reg HKLM\SOFTWARE\Classes\iTunes.m3u@AppUserModelID Apple.iTunes
Reg HKLM\SOFTWARE\Classes\iTunes.m3u\CurVer
Reg HKLM\SOFTWARE\Classes\iTunes.m3u\CurVer@ iTunes.m3u
Reg HKLM\SOFTWARE\Classes\iTunes.m3u\DefaultIcon
Reg HKLM\SOFTWARE\Classes\iTunes.m3u\DefaultIcon@ C:\Program Files\iTunes\iTunes.exe,-149
Reg HKLM\SOFTWARE\Classes\iTunes.m3u\shell
Reg HKLM\SOFTWARE\Classes\iTunes.m3u\shell@ play
Reg HKLM\SOFTWARE\Classes\iTunes.m3u\shell\open
Reg HKLM\SOFTWARE\Classes\iTunes.m3u\shell\open@ &Open
Reg HKLM\SOFTWARE\Classes\iTunes.m3u\shell\open\command
Reg HKLM\SOFTWARE\Classes\iTunes.m3u\shell\open\command@ "C:\Program Files\iTunes\iTunes.exe" /open "%L"
Reg HKLM\SOFTWARE\Classes\iTunes.m3u\shell\play
Reg HKLM\SOFTWARE\Classes\iTunes.m3u\shell\play@ &Play
Reg HKLM\SOFTWARE\Classes\iTunes.m3u\shell\play\command
Reg HKLM\SOFTWARE\Classes\iTunes.m3u\shell\play\command@ "C:\Program Files\iTunes\iTunes.exe" /play "%L"
Reg HKLM\SOFTWARE\Classes\iTunes.m3u8@ M3U Audio Playlist (UTF-8)
Reg HKLM\SOFTWARE\Classes\iTunes.m3u8@FriendlyTypeName @C:\Program Files\iTunes\iTunes.Resources\iTunesRegistry.dll,-205
Reg HKLM\SOFTWARE\Classes\iTunes.m3u8@AppUserModelID Apple.iTunes
Reg HKLM\SOFTWARE\Classes\iTunes.m3u8\CurVer
Reg HKLM\SOFTWARE\Classes\iTunes.m3u8\CurVer@ iTunes.m3u8
Reg HKLM\SOFTWARE\Classes\iTunes.m3u8\DefaultIcon
Reg HKLM\SOFTWARE\Classes\iTunes.m3u8\DefaultIcon@ C:\Program Files\iTunes\iTunes.exe,-149
Reg HKLM\SOFTWARE\Classes\iTunes.m3u8\shell
Reg HKLM\SOFTWARE\Classes\iTunes.m3u8\shell@ play
Reg HKLM\SOFTWARE\Classes\iTunes.m3u8\shell\open
Reg HKLM\SOFTWARE\Classes\iTunes.m3u8\shell\open@ &Open
Reg HKLM\SOFTWARE\Classes\iTunes.m3u8\shell\open\command
Reg HKLM\SOFTWARE\Classes\iTunes.m3u8\shell\open\command@ "C:\Program Files\iTunes\iTunes.exe" /open "%L"
Reg HKLM\SOFTWARE\Classes\iTunes.m3u8\shell\play
Reg HKLM\SOFTWARE\Classes\iTunes.m3u8\shell\play@ &Play
Reg HKLM\SOFTWARE\Classes\iTunes.m3u8\shell\play\command
Reg HKLM\SOFTWARE\Classes\iTunes.m3u8\shell\play\command@ "C:\Program Files\iTunes\iTunes.exe" /play "%L"
Reg HKLM\SOFTWARE\Classes\iTunes.m4a@ MPEG-4 Audio File
Reg HKLM\SOFTWARE\Classes\iTunes.m4a@FriendlyTypeName @C:\Program Files\iTunes\iTunes.Resources\iTunesRegistry.dll,-1
Reg HKLM\SOFTWARE\Classes\iTunes.m4a@AppUserModelID Apple.iTunes
Reg HKLM\SOFTWARE\Classes\iTunes.m4a\CurVer
Reg HKLM\SOFTWARE\Classes\iTunes.m4a\CurVer@ iTunes.m4a
Reg HKLM\SOFTWARE\Classes\iTunes.m4a\DefaultIcon
Reg HKLM\SOFTWARE\Classes\iTunes.m4a\DefaultIcon@ C:\Program Files\iTunes\iTunes.exe,-141
Reg HKLM\SOFTWARE\Classes\iTunes.m4a\shell
Reg HKLM\SOFTWARE\Classes\iTunes.m4a\shell@ play
Reg HKLM\SOFTWARE\Classes\iTunes.m4a\shell\open
Reg HKLM\SOFTWARE\Classes\iTunes.m4a\shell\open@ &Open
Reg HKLM\SOFTWARE\Classes\iTunes.m4a\shell\open\command
Reg HKLM\SOFTWARE\Classes\iTunes.m4a\shell\open\command@ "C:\Program Files\iTunes\iTunes.exe" /open "%L"
Reg HKLM\SOFTWARE\Classes\iTunes.m4a\shell\play
Reg HKLM\SOFTWARE\Classes\iTunes.m4a\shell\play@ &Play
Reg HKLM\SOFTWARE\Classes\iTunes.m4a\shell\play\command
Reg HKLM\SOFTWARE\Classes\iTunes.m4a\shell\play\command@ "C:\Program Files\iTunes\iTunes.exe" /play "%L"
Reg HKLM\SOFTWARE\Classes\iTunes.m4a\shellex
Reg HKLM\SOFTWARE\Classes\iTunes.m4a\shellex@
Reg HKLM\SOFTWARE\Classes\iTunes.m4a\shellex\{8895b1c6-b41f-4c1c-a562-0d564250836f}
Reg HKLM\SOFTWARE\Classes\iTunes.m4a\shellex\{8895b1c6-b41f-4c1c-a562-0d564250836f}@ {031EE060-67BC-460d-8847-E4A7C5E45A27}
Reg HKLM\SOFTWARE\Classes\iTunes.m4b@ MPEG-4 Audio File (Protected)
Reg HKLM\SOFTWARE\Classes\iTunes.m4b@FriendlyTypeName @C:\Program Files\iTunes\iTunes.Resources\iTunesRegistry.dll,-2
Reg HKLM\SOFTWARE\Classes\iTunes.m4b@AppUserModelID Apple.iTunes
Reg HKLM\SOFTWARE\Classes\iTunes.m4b\CurVer
Reg HKLM\SOFTWARE\Classes\iTunes.m4b\CurVer@ iTunes.m4b
Reg HKLM\SOFTWARE\Classes\iTunes.m4b\DefaultIcon
Reg HKLM\SOFTWARE\Classes\iTunes.m4b\DefaultIcon@ C:\Program Files\iTunes\iTunes.exe,-143
Reg HKLM\SOFTWARE\Classes\iTunes.m4b\shell
Reg HKLM\SOFTWARE\Classes\iTunes.m4b\shell@ play
Reg HKLM\SOFTWARE\Classes\iTunes.m4b\shell\open
Reg HKLM\SOFTWARE\Classes\iTunes.m4b\shell\open@ &Open
Reg HKLM\SOFTWARE\Classes\iTunes.m4b\shell\open\command
Reg HKLM\SOFTWARE\Classes\iTunes.m4b\shell\open\command@ "C:\Program Files\iTunes\iTunes.exe" /open "%L"
Reg HKLM\SOFTWARE\Classes\iTunes.m4b\shell\play
Reg HKLM\SOFTWARE\Classes\iTunes.m4b\shell\play@ &Play
Reg HKLM\SOFTWARE\Classes\iTunes.m4b\shell\play\command
Reg HKLM\SOFTWARE\Classes\iTunes.m4b\shell\play\command@ "C:\Program Files\iTunes\iTunes.exe" /play "%L"
Reg HKLM\SOFTWARE\Classes\iTunes.m4p@ MPEG-4 Audio File (Protected)
Reg HKLM\SOFTWARE\Classes\iTunes.m4p@FriendlyTypeName @C:\Program Files\iTunes\iTunes.Resources\iTunesRegistry.dll,-2
Reg HKLM\SOFTWARE\Classes\iTunes.m4p@AppUserModelID Apple.iTunes
Reg HKLM\SOFTWARE\Classes\iTunes.m4p\CurVer
Reg HKLM\SOFTWARE\Classes\iTunes.m4p\CurVer@ iTunes.m4p
Reg HKLM\SOFTWARE\Classes\iTunes.m4p\DefaultIcon
Reg HKLM\SOFTWARE\Classes\iTunes.m4p\DefaultIcon@ C:\Program Files\iTunes\iTunes.exe,-143
Reg HKLM\SOFTWARE\Classes\iTunes.m4p\shell
Reg HKLM\SOFTWARE\Classes\iTunes.m4p\shell@ play
Reg HKLM\SOFTWARE\Classes\iTunes.m4p\shell\open
Reg HKLM\SOFTWARE\Classes\iTunes.m4p\shell\open@ &Open
Reg HKLM\SOFTWARE\Classes\iTunes.m4p\shell\open\command
Reg HKLM\SOFTWARE\Classes\iTunes.m4p\shell\open\command@ "C:\Program Files\iTunes\iTunes.exe" /open "%L"
Reg HKLM\SOFTWARE\Classes\iTunes.m4p\shell\play
Reg HKLM\SOFTWARE\Classes\iTunes.m4p\shell\play@ &Play
Reg HKLM\SOFTWARE\Classes\iTunes.m4p\shell\play\command
Reg HKLM\SOFTWARE\Classes\iTunes.m4p\shell\play\command@ "C:\Program Files\iTunes\iTunes.exe" /play "%L"
Reg HKLM\SOFTWARE\Classes\iTunes.m4r@ Ringtone
Reg HKLM\SOFTWARE\Classes\iTunes.m4r@FriendlyTypeName @C:\Program Files\iTunes\iTunes.Resources\iTunesRegistry.dll,-202
Reg HKLM\SOFTWARE\Classes\iTunes.m4r@AppUserModelID Apple.iTunes
Reg HKLM\SOFTWARE\Classes\iTunes.m4r\CurVer
Reg HKLM\SOFTWARE\Classes\iTunes.m4r\CurVer@ iTunes.m4r
Reg HKLM\SOFTWARE\Classes\iTunes.m4r\DefaultIcon
Reg HKLM\SOFTWARE\Classes\iTunes.m4r\DefaultIcon@ C:\Program Files\iTunes\iTunes.exe,-164
Reg HKLM\SOFTWARE\Classes\iTunes.m4r\shell
Reg HKLM\SOFTWARE\Classes\iTunes.m4r\shell@ play
Reg HKLM\SOFTWARE\Classes\iTunes.m4r\shell\open
Reg HKLM\SOFTWARE\Classes\iTunes.m4r\shell\open@ &Open
Reg HKLM\SOFTWARE\Classes\iTunes.m4r\shell\open\command
Reg HKLM\SOFTWARE\Classes\iTunes.m4r\shell\open\command@ "C:\Program Files\iTunes\iTunes.exe" /open "%L"
Reg HKLM\SOFTWARE\Classes\iTunes.m4r\shell\play
Reg HKLM\SOFTWARE\Classes\iTunes.m4r\shell\play@ &Play
Reg HKLM\SOFTWARE\Classes\iTunes.m4r\shell\play\command
Reg HKLM\SOFTWARE\Classes\iTunes.m4r\shell\play\command@ "C:\Program Files\iTunes\iTunes.exe" /play "%L"
Reg HKLM\SOFTWARE\Classes\iTunes.m4v@FriendlyTypeName @C:\Program Files\iTunes\iTunes.Resources\iTunesRegistry.dll,-19
Reg HKLM\SOFTWARE\Classes\iTunes.m4v@AppUserModelID Apple.iTunes
Reg HKLM\SOFTWARE\Classes\iTunes.m4v@ MPEG-4 Video File
Reg HKLM\SOFTWARE\Classes\iTunes.m4v\CurVer
Reg HKLM\SOFTWARE\Classes\iTunes.m4v\CurVer@ iTunes.m4v
Reg HKLM\SOFTWARE\Classes\iTunes.m4v\DefaultIcon
Reg HKLM\SOFTWARE\Classes\iTunes.m4v\DefaultIcon@ C:\Program Files\iTunes\iTunes.exe,-141
Reg HKLM\SOFTWARE\Classes\iTunes.m4v\shell
Reg HKLM\SOFTWARE\Classes\iTunes.m4v\shell@ play
Reg HKLM\SOFTWARE\Classes\iTunes.m4v\shell\open
Reg HKLM\SOFTWARE\Classes\iTunes.m4v\shell\open@ &Open
Reg HKLM\SOFTWARE\Classes\iTunes.m4v\shell\open\command
Reg HKLM\SOFTWARE\Classes\iTunes.m4v\shell\open\command@ "C:\Program Files\iTunes\iTunes.exe" /open "%L"
Reg HKLM\SOFTWARE\Classes\iTunes.m4v\shell\play
Reg HKLM\SOFTWARE\Classes\iTunes.m4v\shell\play@ &Play
Reg HKLM\SOFTWARE\Classes\iTunes.m4v\shell\play\command
Reg HKLM\SOFTWARE\Classes\iTunes.m4v\shell\play\command@ "C:\Program Files\iTunes\iTunes.exe" /play "%L"
Reg HKLM\SOFTWARE\Classes\iTunes.m4v\shellex
Reg HKLM\SOFTWARE\Classes\iTunes.m4v\shellex@
Reg HKLM\SOFTWARE\Classes\iTunes.m4v\shellex\{8895b1c6-b41f-4c1c-a562-0d564250836f}
Reg HKLM\SOFTWARE\Classes\iTunes.m4v\shellex\{8895b1c6-b41f-4c1c-a562-0d564250836f}@ {031EE060-67BC-460d-8847-E4A7C5E45A27}
Reg HKLM\SOFTWARE\Classes\iTunes.mov@ Movie File
Reg HKLM\SOFTWARE\Classes\iTunes.mov@FriendlyTypeName @C:\Program Files\iTunes\iTunes.Resources\iTunesRegistry.dll,-8
Reg HKLM\SOFTWARE\Classes\iTunes.mov@AppUserModelID Apple.iTunes
Reg HKLM\SOFTWARE\Classes\iTunes.mov\CurVer
Reg HKLM\SOFTWARE\Classes\iTunes.mov\CurVer@ iTunes.mov
Reg HKLM\SOFTWARE\Classes\iTunes.mov\DefaultIcon
Reg HKLM\SOFTWARE\Classes\iTunes.mov\DefaultIcon@ C:\Program Files\iTunes\iTunes.exe,-135
Reg HKLM\SOFTWARE\Classes\iTunes.mov\shell
Reg HKLM\SOFTWARE\Classes\iTunes.mov\shell@ play
Reg HKLM\SOFTWARE\Classes\iTunes.mov\shell\open
Reg HKLM\SOFTWARE\Classes\iTunes.mov\shell\open@ &Open
Reg HKLM\SOFTWARE\Classes\iTunes.mov\shell\open\command
Reg HKLM\SOFTWARE\Classes\iTunes.mov\shell\open\command@ "C:\Program Files\iTunes\iTunes.exe" /open "%L"
Reg HKLM\SOFTWARE\Classes\iTunes.mov\shell\play
Reg HKLM\SOFTWARE\Classes\iTunes.mov\shell\play@ &Play
Reg HKLM\SOFTWARE\Classes\iTunes.mov\shell\play\command
Reg HKLM\SOFTWARE\Classes\iTunes.mov\shell\play\command@ "C:\Program Files\iTunes\iTunes.exe" /play "%L"
Reg HKLM\SOFTWARE\Classes\iTunes.mov\shellex
Reg HKLM\SOFTWARE\Classes\iTunes.mov\shellex@
Reg HKLM\SOFTWARE\Classes\iTunes.mov\shellex\{8895b1c6-b41f-4c1c-a562-0d564250836f}
Reg HKLM\SOFTWARE\Classes\iTunes.mov\shellex\{8895b1c6-b41f-4c1c-a562-0d564250836f}@ {031EE060-67BC-460d-8847-E4A7C5E45A27}
Reg HKLM\SOFTWARE\Classes\iTunes.mp2@ MPEG Layer 2 Audio
Reg HKLM\SOFTWARE\Classes\iTunes.mp2@FriendlyTypeName @C:\Program Files\iTunes\iTunes.Resources\iTunesRegistry.dll,-9
Reg HKLM\SOFTWARE\Classes\iTunes.mp2@AppUserModelID Apple.iTunes
Reg HKLM\SOFTWARE\Classes\iTunes.mp2\CurVer
Reg HKLM\SOFTWARE\Classes\iTunes.mp2\CurVer@ iTunes.mp2
Reg HKLM\SOFTWARE\Classes\iTunes.mp2\DefaultIcon
Reg HKLM\SOFTWARE\Classes\iTunes.mp2\DefaultIcon@ C:\Program Files\iTunes\iTunes.exe,-137
Reg HKLM\SOFTWARE\Classes\iTunes.mp2\shell
Reg HKLM\SOFTWARE\Classes\iTunes.mp2\shell@ play
Reg HKLM\SOFTWARE\Classes\iTunes.mp2\shell\open
Reg HKLM\SOFTWARE\Classes\iTunes.mp2\shell\open@ &Open
Reg HKLM\SOFTWARE\Classes\iTunes.mp2\shell\open\command
Reg HKLM\SOFTWARE\Classes\iTunes.mp2\shell\open\command@ "C:\Program Files\iTunes\iTunes.exe" /open "%L"
Reg HKLM\SOFTWARE\Classes\iTunes.mp2\shell\play
Reg HKLM\SOFTWARE\Classes\iTunes.mp2\shell\play@ &Play
Reg HKLM\SOFTWARE\Classes\iTunes.mp2\shell\play\command
Reg HKLM\SOFTWARE\Classes\iTunes.mp2\shell\play\command@ "C:\Program Files\iTunes\iTunes.exe" /play "%L"
Reg HKLM\SOFTWARE\Classes\iTunes.mp3@ MPEG Layer 3 Audio
Reg HKLM\SOFTWARE\Classes\iTunes.mp3@FriendlyTypeName @C:\Program Files\iTunes\iTunes.Resources\iTunesRegistry.dll,-10
Reg HKLM\SOFTWARE\Classes\iTunes.mp3@AppUserModelID Apple.iTunes
Reg HKLM\SOFTWARE\Classes\iTunes.mp3\CurVer
Reg HKLM\SOFTWARE\Classes\iTunes.mp3\CurVer@ iTunes.mp3
Reg HKLM\SOFTWARE\Classes\iTunes.mp3\DefaultIcon
Reg HKLM\SOFTWARE\Classes\iTunes.mp3\DefaultIcon@ C:\Program Files\iTunes\iTunes.exe,-129
Reg HKLM\SOFTWARE\Classes\iTunes.mp3\shell
Reg HKLM\SOFTWARE\Classes\iTunes.mp3\shell@ play
Reg HKLM\SOFTWARE\Classes\iTunes.mp3\shell\open
Reg HKLM\SOFTWARE\Classes\iTunes.mp3\shell\open@ &Open
Reg HKLM\SOFTWARE\Classes\iTunes.mp3\shell\open\command
Reg HKLM\SOFTWARE\Classes\iTunes.mp3\shell\open\command@ "C:\Program Files\iTunes\iTunes.exe" /open "%L"
Reg HKLM\SOFTWARE\Classes\iTunes.mp3\shell\play
Reg HKLM\SOFTWARE\Classes\iTunes.mp3\shell\play@ &Play
Reg HKLM\SOFTWARE\Classes\iTunes.mp3\shell\play\command
Reg HKLM\SOFTWARE\Classes\iTunes.mp3\shell\play\command@ "C:\Program Files\iTunes\iTunes.exe" /play "%L"
Reg HKLM\SOFTWARE\Classes\iTunes.mp3\shellex
Reg HKLM\SOFTWARE\Classes\iTunes.mp3\shellex@
Reg HKLM\SOFTWARE\Classes\iTunes.mp3\shellex\{8895b1c6-b41f-4c1c-a562-0d564250836f}
Reg HKLM\SOFTWARE\Classes\iTunes.mp3\shellex\{8895b1c6-b41f-4c1c-a562-0d564250836f}@ {031EE060-67BC-460d-8847-E4A7C5E45A27}
Reg HKLM\SOFTWARE\Classes\iTunes.mpeg@ MPEG File
Reg HKLM\SOFTWARE\Classes\iTunes.mpeg@FriendlyTypeName @C:\Program Files\iTunes\iTunes.Resources\iTunesRegistry.dll,-11
Reg HKLM\SOFTWARE\Classes\iTunes.mpeg@AppUserModelID Apple.iTunes
Reg HKLM\SOFTWARE\Classes\iTunes.mpeg\CurVer
Reg HKLM\SOFTWARE\Classes\iTunes.mpeg\CurVer@ iTunes.mpeg
Reg HKLM\SOFTWARE\Classes\iTunes.mpeg\DefaultIcon
Reg HKLM\SOFTWARE\Classes\iTunes.mpeg\DefaultIcon@ C:\Program Files\iTunes\iTunes.exe,-133
Reg HKLM\SOFTWARE\Classes\iTunes.mpeg\shell
Reg HKLM\SOFTWARE\Classes\iTunes.mpeg\shell@ play
Reg HKLM\SOFTWARE\Classes\iTunes.mpeg\shell\open
Reg HKLM\SOFTWARE\Classes\iTunes.mpeg\shell\open@ &Open
Reg HKLM\SOFTWARE\Classes\iTunes.mpeg\shell\open\command
Reg HKLM\SOFTWARE\Classes\iTunes.mpeg\shell\open\command@ "C:\Program Files\iTunes\iTunes.exe" /open "%L"
Reg HKLM\SOFTWARE\Classes\iTunes.mpeg\shell\play
Reg HKLM\SOFTWARE\Classes\iTunes.mpeg\shell\play@ &Play
Reg HKLM\SOFTWARE\Classes\iTunes.mpeg\shell\play\command
Reg HKLM\SOFTWARE\Classes\iTunes.mpeg\shell\play\command@ "C:\Program Files\iTunes\iTunes.exe" /play "%L"
Reg HKLM\SOFTWARE\Classes\iTunes.mpeg\shellex
Reg HKLM\SOFTWARE\Classes\iTunes.mpeg\shellex@
Reg HKLM\SOFTWARE\Classes\iTunes.mpeg\shellex\{8895b1c6-b41f-4c1c-a562-0d564250836f}
Reg HKLM\SOFTWARE\Classes\iTunes.mpeg\shellex\{8895b1c6-b41f-4c1c-a562-0d564250836f}@ {031EE060-67BC-460d-8847-E4A7C5E45A27}
Reg HKLM\SOFTWARE\Classes\iTunes.mpg@ MPEG File
Reg HKLM\SOFTWARE\Classes\iTunes.mpg@FriendlyTypeName @C:\Program Files\iTunes\iTunes.Resources\iTunesRegistry.dll,-11
Reg HKLM\SOFTWARE\Classes\iTunes.mpg@AppUserModelID Apple.iTunes
Reg HKLM\SOFTWARE\Classes\iTunes.mpg\CurVer
Reg HKLM\SOFTWARE\Classes\iTunes.mpg\CurVer@ iTunes.mpg
Reg HKLM\SOFTWARE\Classes\iTunes.mpg\DefaultIcon
Reg HKLM\SOFTWARE\Classes\iTunes.mpg\DefaultIcon@ C:\Program Files\iTunes\iTunes.exe,-133
Reg HKLM\SOFTWARE\Classes\iTunes.mpg\shell
Reg HKLM\SOFTWARE\Classes\iTunes.mpg\shell@ play
Reg HKLM\SOFTWARE\Classes\iTunes.mpg\shell\open
Reg HKLM\SOFTWARE\Classes\iTunes.mpg\shell\open@ &Open
Reg HKLM\SOFTWARE\Classes\iTunes.mpg\shell\open\command
Reg HKLM\SOFTWARE\Classes\iTunes.mpg\shell\open\command@ "C:\Program Files\iTunes\iTunes.exe" /open "%L"
Reg HKLM\SOFTWARE\Classes\iTunes.mpg\shell\play
Reg HKLM\SOFTWARE\Classes\iTunes.mpg\shell\play@ &Play
Reg HKLM\SOFTWARE\Classes\iTunes.mpg\shell\play\command
Reg HKLM\SOFTWARE\Classes\iTunes.mpg\shell\play\command@ "C:\Program Files\iTunes\iTunes.exe" /play "%L"
Reg HKLM\SOFTWARE\Classes\iTunes.mpg\shellex
Reg HKLM\SOFTWARE\Classes\iTunes.mpg\shellex@
Reg HKLM\SOFTWARE\Classes\iTunes.mpg\shellex\{8895b1c6-b41f-4c1c-a562-0d564250836f}
Reg HKLM\SOFTWARE\Classes\iTunes.mpg\shellex\{8895b1c6-b41f-4c1c-a562-0d564250836f}@ {031EE060-67BC-460d-8847-E4A7C5E45A27}
Reg HKLM\SOFTWARE\Classes\iTunes.pcast@FriendlyTypeName @C:\Program Files\iTunes\iTunes.Resources\iTunesRegistry.dll,-18
Reg HKLM\SOFTWARE\Classes\iTunes.pcast@AppUserModelID Apple.iTunes
Reg HKLM\SOFTWARE\Classes\iTunes.pcast@ Podcast Subscription File
Reg HKLM\SOFTWARE\Classes\iTunes.pcast\CurVer
Reg HKLM\SOFTWARE\Classes\iTunes.pcast\CurVer@ iTunes.pcast
Reg HKLM\SOFTWARE\Classes\iTunes.pcast\DefaultIcon
Reg HKLM\SOFTWARE\Classes\iTunes.pcast\DefaultIcon@ C:\Program Files\iTunes\iTunes.exe,-148
Reg HKLM\SOFTWARE\Classes\iTunes.pcast\shell
Reg HKLM\SOFTWARE\Classes\iTunes.pcast\shell@ play
Reg HKLM\SOFTWARE\Classes\iTunes.pcast\shell\open
Reg HKLM\SOFTWARE\Classes\iTunes.pcast\shell\open@ &Open
Reg HKLM\SOFTWARE\Classes\iTunes.pcast\shell\open\command
Reg HKLM\SOFTWARE\Classes\iTunes.pcast\shell\open\command@ "C:\Program Files\iTunes\iTunes.exe" /open "%L"
Reg HKLM\SOFTWARE\Classes\iTunes.pcast\shell\play
Reg HKLM\SOFTWARE\Classes\iTunes.pcast\shell\play@ &Play
Reg HKLM\SOFTWARE\Classes\iTunes.pcast\shell\play\command
Reg HKLM\SOFTWARE\Classes\iTunes.pcast\shell\play\command@ "C:\Program Files\iTunes\iTunes.exe" /open "%L"
Reg HKLM\SOFTWARE\Classes\iTunes.PlaySongsOnCD@
Reg HKLM\SOFTWARE\Classes\iTunes.PlaySongsOnCD\shell
Reg HKLM\SOFTWARE\Classes\iTunes.PlaySongsOnCD\shell@
Reg HKLM\SOFTWARE\Classes\iTunes.PlaySongsOnCD\shell\play
Reg HKLM\SOFTWARE\Classes\iTunes.PlaySongsOnCD\shell\play@ Play audio CD
Reg HKLM\SOFTWARE\Classes\iTunes.PlaySongsOnCD\shell\play\command
Reg HKLM\SOFTWARE\Classes\iTunes.PlaySongsOnCD\shell\play\command@ "C:\Program Files\iTunes\iTunes.exe" /playCD "%L"
Reg HKLM\SOFTWARE\Classes\iTunes.pls@ PLS Audio Playlist
Reg HKLM\SOFTWARE\Classes\iTunes.pls@FriendlyTypeName @C:\Program Files\iTunes\iTunes.Resources\iTunesRegistry.dll,-12
Reg HKLM\SOFTWARE\Classes\iTunes.pls@AppUserModelID Apple.iTunes
Reg HKLM\SOFTWARE\Classes\iTunes.pls\CurVer
Reg HKLM\SOFTWARE\Classes\iTunes.pls\CurVer@ iTunes.pls
Reg HKLM\SOFTWARE\Classes\iTunes.pls\DefaultIcon
Reg HKLM\SOFTWARE\Classes\iTunes.pls\DefaultIcon@ C:\Program Files\iTunes\iTunes.exe,-149
Reg HKLM\SOFTWARE\Classes\iTunes.pls\shell
Reg HKLM\SOFTWARE\Classes\iTunes.pls\shell@ play
Reg HKLM\SOFTWARE\Classes\iTunes.pls\shell\open
Reg HKLM\SOFTWARE\Classes\iTunes.pls\shell\open@ &Open
Reg HKLM\SOFTWARE\Classes\iTunes.pls\shell\open\command
Reg HKLM\SOFTWARE\Classes\iTunes.pls\shell\open\command@ "C:\Program Files\iTunes\iTunes.exe" /open "%L"
Reg HKLM\SOFTWARE\Classes\iTunes.pls\shell\play
Reg HKLM\SOFTWARE\Classes\iTunes.pls\shell\play@ &Play
Reg HKLM\SOFTWARE\Classes\iTunes.pls\shell\play\command
Reg HKLM\SOFTWARE\Classes\iTunes.pls\shell\play\command@ "C:\Program Files\iTunes\iTunes.exe" /play "%L"
Reg HKLM\SOFTWARE\Classes\iTunes.rmp@ RealJukebox Music Package
Reg HKLM\SOFTWARE\Classes\iTunes.rmp@FriendlyTypeName @C:\Program Files\iTunes\iTunes.Resources\iTunesRegistry.dll,-13
Reg HKLM\SOFTWARE\Classes\iTunes.rmp@AppUserModelID Apple.iTunes
Reg HKLM\SOFTWARE\Classes\iTunes.rmp\CurVer
Reg HKLM\SOFTWARE\Classes\iTunes.rmp\CurVer@ iTunes.rmp
Reg HKLM\SOFTWARE\Classes\iTunes.rmp\DefaultIcon
Reg HKLM\SOFTWARE\Classes\iTunes.rmp\DefaultIcon@ C:\Program Files\iTunes\iTunes.exe,-148
Reg HKLM\SOFTWARE\Classes\iTunes.rmp\shell
Reg HKLM\SOFTWARE\Classes\iTunes.rmp\shell@ play
Reg HKLM\SOFTWARE\Classes\iTunes.rmp\shell\open
Reg HKLM\SOFTWARE\Classes\iTunes.rmp\shell\open@ &Open
Reg HKLM\SOFTWARE\Classes\iTunes.rmp\shell\open\command
Reg HKLM\SOFTWARE\Classes\iTunes.rmp\shell\open\command@ "C:\Program Files\iTunes\iTunes.exe" /open "%L"
Reg HKLM\SOFTWARE\Classes\iTunes.rmp\shell\play
Reg HKLM\SOFTWARE\Classes\iTunes.rmp\shell\play@ &Play
Reg HKLM\SOFTWARE\Classes\iTunes.rmp\shell\play\command
Reg HKLM\SOFTWARE\Classes\iTunes.rmp\shell\play\command@ "C:\Program Files\iTunes\iTunes.exe" /play "%L"
Reg HKLM\SOFTWARE\Classes\iTunes.ShowSongsOnCD@
Reg HKLM\SOFTWARE\Classes\iTunes.ShowSongsOnCD\shell
Reg HKLM\SOFTWARE\Classes\iTunes.ShowSongsOnCD\shell@
Reg HKLM\SOFTWARE\Classes\iTunes.ShowSongsOnCD\shell\showsongs
Reg HKLM\SOFTWARE\Classes\iTunes.ShowSongsOnCD\shell\showsongs@ Show songs
Reg HKLM\SOFTWARE\Classes\iTunes.ShowSongsOnCD\shell\showsongs\command
Reg HKLM\SOFTWARE\Classes\iTunes.ShowSongsOnCD\shell\showsongs\command@ "C:\Program Files\iTunes\iTunes.exe" /AutoPlayShowSongs "%L"
Reg HKLM\SOFTWARE\Classes\iTunes.wav@ WAVE Audio File
Reg HKLM\SOFTWARE\Classes\iTunes.wav@FriendlyTypeName @C:\Program Files\iTunes\iTunes.Resources\iTunesRegistry.dll,-15
Reg HKLM\SOFTWARE\Classes\iTunes.wav@AppUserModelID Apple.iTunes
Reg HKLM\SOFTWARE\Classes\iTunes.wav\CurVer
Reg HKLM\SOFTWARE\Classes\iTunes.wav\CurVer@ iTunes.wav
Reg HKLM\SOFTWARE\Classes\iTunes.wav\DefaultIcon
Reg HKLM\SOFTWARE\Classes\iTunes.wav\DefaultIcon@ C:\Program Files\iTunes\iTunes.exe,-134
Reg HKLM\SOFTWARE\Classes\iTunes.wav\shell
Reg HKLM\SOFTWARE\Classes\iTunes.wav\shell@ play
Reg HKLM\SOFTWARE\Classes\iTunes.wav\shell\open
Reg HKLM\SOFTWARE\Classes\iTunes.wav\shell\open@ &Open
Reg HKLM\SOFTWARE\Classes\iTunes.wav\shell\open\command
Reg HKLM\SOFTWARE\Classes\iTunes.wav\shell\open\command@ "C:\Program Files\iTunes\iTunes.exe" /open "%L"
Reg HKLM\SOFTWARE\Classes\iTunes.wav\shell\play
Reg HKLM\SOFTWARE\Classes\iTunes.wav\shell\play@ &Play
Reg HKLM\SOFTWARE\Classes\iTunes.wav\shell\play\command
Reg HKLM\SOFTWARE\Classes\iTunes.wav\shell\play\command@ "C:\Program Files\iTunes\iTunes.exe" /play "%L"
Reg HKLM\SOFTWARE\Classes\iTunes.wav\shellex
Reg HKLM\SOFTWARE\Classes\iTunes.wav\shellex@
Reg HKLM\SOFTWARE\Classes\iTunes.wav\shellex\{8895b1c6-b41f-4c1c-a562-0d564250836f}
Reg HKLM\SOFTWARE\Classes\iTunes.wav\shellex\{8895b1c6-b41f-4c1c-a562-0d564250836f}@ {031EE060-67BC-460d-8847-E4A7C5E45A27}
Reg HKLM\SOFTWARE\Classes\iTunes.wave@ WAVE Audio File
Reg HKLM\SOFTWARE\Classes\iTunes.wave@FriendlyTypeName @C:\Program Files\iTunes\iTunes.Resources\iTunesRegistry.dll,-15
Reg HKLM\SOFTWARE\Classes\iTunes.wave@AppUserModelID Apple.iTunes
Reg HKLM\SOFTWARE\Classes\iTunes.wave\CurVer
Reg HKLM\SOFTWARE\Classes\iTunes.wave\CurVer@ iTunes.wave
Reg HKLM\SOFTWARE\Classes\iTunes.wave\DefaultIcon
Reg HKLM\SOFTWARE\Classes\iTunes.wave\DefaultIcon@ C:\Program Files\iTunes\iTunes.exe,-134
Reg HKLM\SOFTWARE\Classes\iTunes.wave\shell
Reg HKLM\SOFTWARE\Classes\iTunes.wave\shell@ play
Reg HKLM\SOFTWARE\Classes\iTunes.wave\shell\open
Reg HKLM\SOFTWARE\Classes\iTunes.wave\shell\open@ &Open
Reg HKLM\SOFTWARE\Classes\iTunes.wave\shell\open\command
Reg HKLM\SOFTWARE\Classes\iTunes.wave\shell\open\command@ "C:\Program Files\iTunes\iTunes.exe" /open "%L"
Reg HKLM\SOFTWARE\Classes\iTunes.wave\shell\play
Reg HKLM\SOFTWARE\Classes\iTunes.wave\shell\play@ &Play
Reg HKLM\SOFTWARE\Classes\iTunes.wave\shell\play\command
Reg HKLM\SOFTWARE\Classes\iTunes.wave\shell\play\command@ "C:\Program Files\iTunes\iTunes.exe" /play "%L"
Reg HKLM\SOFTWARE\Classes\iTunes.wave\shellex
Reg HKLM\SOFTWARE\Classes\iTunes.wave\shellex@
Reg HKLM\SOFTWARE\Classes\iTunes.wave\shellex\{8895b1c6-b41f-4c1c-a562-0d564250836f}
Reg HKLM\SOFTWARE\Classes\iTunes.wave\shellex\{8895b1c6-b41f-4c1c-a562-0d564250836f}@ {031EE060-67BC-460d-8847-E4A7C5E45A27}
Reg HKLM\SOFTWARE\Classes\iTunesAddIn.CalendarHelper@ CalendarHelper Class
Reg HKLM\SOFTWARE\Classes\iTunesAddIn.CalendarHelper\CLSID
Reg HKLM\SOFTWARE\Classes\iTunesAddIn.CalendarHelper\CLSID@ {0A25C695-3765-4B37-9455-4B1C113C2C04}
Reg HKLM\SOFTWARE\Classes\iTunesAddIn.CalendarHelper\CurVer
Reg HKLM\SOFTWARE\Classes\iTunesAddIn.CalendarHelper\CurVer@ iTunesAddIn.CalendarHelper.1
Reg HKLM\SOFTWARE\Classes\iTunesAddIn.CalendarHelper.1@ CalendarHelper Class
Reg HKLM\SOFTWARE\Classes\iTunesAddIn.CalendarHelper.1\CLSID
Reg HKLM\SOFTWARE\Classes\iTunesAddIn.CalendarHelper.1\CLSID@ {0A25C695-3765-4B37-9455-4B1C113C2C04}
Reg HKLM\SOFTWARE\Classes\iTunesAdmin.iTunesAdmin@ iTunesAdmin Class
Reg HKLM\SOFTWARE\Classes\iTunesAdmin.iTunesAdmin\CLSID
Reg HKLM\SOFTWARE\Classes\iTunesAdmin.iTunesAdmin\CLSID@ {20ADDA11-8287-44D0-8C63-27CDA87ACC46}
Reg HKLM\SOFTWARE\Classes\iTunesAdmin.iTunesAdmin\CurVer
Reg HKLM\SOFTWARE\Classes\iTunesAdmin.iTunesAdmin\CurVer@ iTunesAdmin.iTunesAdmin.1
Reg HKLM\SOFTWARE\Classes\iTunesAdmin.iTunesAdmin.1@ iTunesAdmin Class
Reg HKLM\SOFTWARE\Classes\iTunesAdmin.iTunesAdmin.1\CLSID
Reg HKLM\SOFTWARE\Classes\iTunesAdmin.iTunesAdmin.1\CLSID@ {20ADDA11-8287-44D0-8C63-27CDA87ACC46}
Reg HKLM\SOFTWARE\Classes\iTunesAdmin.iTunesAdminAudible@ iTunesAdminAudible Class
Reg HKLM\SOFTWARE\Classes\iTunesAdmin.iTunesAdminAudible\CLSID
Reg HKLM\SOFTWARE\Classes\iTunesAdmin.iTunesAdminAudible\CLSID@ {6C2589C3-96F8-4863-A511-9C33EB2C7E2A}
Reg HKLM\SOFTWARE\Classes\iTunesAdmin.iTunesAdminAudible\CurVer
Reg HKLM\SOFTWARE\Classes\iTunesAdmin.iTunesAdminAudible\CurVer@ iTunesAdmin.iTunesAdminAudible.1
Reg HKLM\SOFTWARE\Classes\iTunesAdmin.iTunesAdminAudible.1@ iTunesAdminAudible Class
Reg HKLM\SOFTWARE\Classes\iTunesAdmin.iTunesAdminAudible.1\CLSID
Reg HKLM\SOFTWARE\Classes\iTunesAdmin.iTunesAdminAudible.1\CLSID@ {6C2589C3-96F8-4863-A511-9C33EB2C7E2A}
Reg HKLM\SOFTWARE\Classes\iTunesAdmin.iTunesAdminEnableAutoRun@ iTunesAdminEnableAutoRun Class
Reg HKLM\SOFTWARE\Classes\iTunesAdmin.iTunesAdminEnableAutoRun\CLSID
Reg HKLM\SOFTWARE\Classes\iTunesAdmin.iTunesAdminEnableAutoRun\CLSID@ {B8DF592B-DE05-49f5-BB21-084F548F12A9}
Reg HKLM\SOFTWARE\Classes\iTunesAdmin.iTunesAdminEnableAutoRun\CurVer
Reg HKLM\SOFTWARE\Classes\iTunesAdmin.iTunesAdminEnableAutoRun\CurVer@ iTunesAdmin.iTunesAdminEnableAutoRun.1
Reg HKLM\SOFTWARE\Classes\iTunesAdmin.iTunesAdminEnableAutoRun.1@ iTunesAdminEnableAutoRun Class
Reg HKLM\SOFTWARE\Classes\iTunesAdmin.iTunesAdminEnableAutoRun.1\CLSID
Reg HKLM\SOFTWARE\Classes\iTunesAdmin.iTunesAdminEnableAutoRun.1\CLSID@ {B8DF592B-DE05-49f5-BB21-084F548F12A9}
Reg HKLM\SOFTWARE\Classes\iTunesAdmin.iTunesAdminInstallTalkBackVoiceKit@ iTunesAdminInstallTalkBackVoiceKit Class
Reg HKLM\SOFTWARE\Classes\iTunesAdmin.iTunesAdminInstallTalkBackVoiceKit\CLSID
Reg HKLM\SOFTWARE\Classes\iTunesAdmin.iTunesAdminInstallTalkBackVoiceKit\CLSID@ {E9D58BF1-0070-4fcd-B722-A0EE5A3ABCD6}
Reg HKLM\SOFTWARE\Classes\iTunesAdmin.iTunesAdminInstallTalkBackVoiceKit\CurVer
Reg HKLM\SOFTWARE\Classes\iTunesAdmin.iTunesAdminInstallTalkBackVoiceKit\CurVer@ iTunesAdmin.iTunesAdminInstallTalkBackVoiceKit.1
Reg HKLM\SOFTWARE\Classes\iTunesAdmin.iTunesAdminInstallTalkBackVoiceKit.1@ iTunesAdminInstallTalkBackVoiceKit Class
Reg HKLM\SOFTWARE\Classes\iTunesAdmin.iTunesAdminInstallTalkBackVoiceKit.1\CLSID
Reg HKLM\SOFTWARE\Classes\iTunesAdmin.iTunesAdminInstallTalkBackVoiceKit.1\CLSID@ {E9D58BF1-0070-4fcd-B722-A0EE5A3ABCD6}
Reg HKLM\SOFTWARE\Classes\iTunesAdmin.iTunesAdminParentalControls@ iTunesAdminParentalControls Class
Reg HKLM\SOFTWARE\Classes\iTunesAdmin.iTunesAdminParentalControls\CLSID
Reg HKLM\SOFTWARE\Classes\iTunesAdmin.iTunesAdminParentalControls\CLSID@ {08A6AF6A-8FF2-4a3b-BECF-C2FAC8630BBF}
Reg HKLM\SOFTWARE\Classes\iTunesAdmin.iTunesAdminParentalControls\CurVer
Reg HKLM\SOFTWARE\Classes\iTunesAdmin.iTunesAdminParentalControls\CurVer@ iTunesAdmin.iTunesAdminParentalControls.1
Reg HKLM\SOFTWARE\Classes\iTunesAdmin.iTunesAdminParentalControls.1@ iTunesAdminParentalControls Class
Reg HKLM\SOFTWARE\Classes\iTunesAdmin.iTunesAdminParentalControls.1\CLSID
Reg HKLM\SOFTWARE\Classes\iTunesAdmin.iTunesAdminParentalControls.1\CLSID@ {08A6AF6A-8FF2-4a3b-BECF-C2FAC8630BBF}
Reg HKLM\SOFTWARE\Classes\iTunesAdmin.iTunesAdminRepairIPodSW@ iTunesAdminRepairIPodSW Class
Reg HKLM\SOFTWARE\Classes\iTunesAdmin.iTunesAdminRepairIPodSW\CLSID
Reg HKLM\SOFTWARE\Classes\iTunesAdmin.iTunesAdminRepairIPodSW\CLSID@ {62A560B8-09DB-4cc6-AE1B-9D8F7ADDB8F3}
Reg HKLM\SOFTWARE\Classes\iTunesAdmin.iTunesAdminRepairIPodSW\CurVer
Reg HKLM\SOFTWARE\Classes\iTunesAdmin.iTunesAdminRepairIPodSW\CurVer@ iTunesAdmin.iTunesAdminRepairIPodSW.1
Reg HKLM\SOFTWARE\Classes\iTunesAdmin.iTunesAdminRepairIPodSW.1@ iTunesAdminRepairIPodSW Class
Reg HKLM\SOFTWARE\Classes\iTunesAdmin.iTunesAdminRepairIPodSW.1\CLSID
Reg HKLM\SOFTWARE\Classes\iTunesAdmin.iTunesAdminRepairIPodSW.1\CLSID@ {62A560B8-09DB-4cc6-AE1B-9D8F7ADDB8F3}
Reg HKLM\SOFTWARE\Classes\iTunesPhotoProcessor.PhotoProcessor@ iTunesPhotoProcessor Class
Reg HKLM\SOFTWARE\Classes\iTunesPhotoProcessor.PhotoProcessor\CLSID
Reg HKLM\SOFTWARE\Classes\iTunesPhotoProcessor.PhotoProcessor\CLSID@ {FCBE4037-7B1F-4A30-98F0-BB68C95176DA}
Reg HKLM\SOFTWARE\Classes\iTunesPhotoProcessor.PhotoProcessor\CurVer
Reg HKLM\SOFTWARE\Classes\iTunesPhotoProcessor.PhotoProcessor\CurVer@ iTunesPhotoProcessor.PhotoProcessor.1
Reg HKLM\SOFTWARE\Classes\iTunesPhotoProcessor.PhotoProcessor.1@ iTunesPhotoProcessor Class
Reg HKLM\SOFTWARE\Classes\iTunesPhotoProcessor.PhotoProcessor.1\CLSID
Reg HKLM\SOFTWARE\Classes\iTunesPhotoProcessor.PhotoProcessor.1\CLSID@

#9 I_am_CanadianEh?

I_am_CanadianEh?
  • Topic Starter

  • Members
  • 489 posts
  • OFFLINE
  •  
  • Gender:Male
  • Local time:07:38 PM

Posted 05 October 2009 - 09:58 PM

This should be the rest of the GMER.log :(

GMER.log cont.

Reg HKLM\SOFTWARE\Classes\jarfile@ Executable Jar File
Reg HKLM\SOFTWARE\Classes\jarfile\shell
Reg HKLM\SOFTWARE\Classes\jarfile\shell\open
Reg HKLM\SOFTWARE\Classes\jarfile\shell\open\command
Reg HKLM\SOFTWARE\Classes\jarfile\shell\open\command@ "C:\Program Files\Java\jre6\bin\javaw.exe" -jar "%1" %*
Reg HKLM\SOFTWARE\Classes\JavaPlugin\CLSID
Reg HKLM\SOFTWARE\Classes\JavaPlugin\CLSID@ {CAFEEFAC-0016-0000-0016-ABCDEFFEDCBA}
Reg HKLM\SOFTWARE\Classes\JavaPlugin.160_16\CLSID
Reg HKLM\SOFTWARE\Classes\JavaPlugin.160_16\CLSID@ {5852F5ED-8BF4-11D4-A245-0080C6F74284}
Reg HKLM\SOFTWARE\Classes\JavaPlugin.FamilyVersionSupport\CLSID
Reg HKLM\SOFTWARE\Classes\JavaPlugin.FamilyVersionSupport\CLSID@ {761497BB-D6F0-462C-B6EB-D4DAF1D92D43}
Reg HKLM\SOFTWARE\Classes\JavaWebStart.isInstalled@ isInstalled Class
Reg HKLM\SOFTWARE\Classes\JavaWebStart.isInstalled\CLSID
Reg HKLM\SOFTWARE\Classes\JavaWebStart.isInstalled\CLSID@ {5852F5ED-8BF4-11D4-A245-0080C6F74284}
Reg HKLM\SOFTWARE\Classes\JavaWebStart.isInstalled\CurVer
Reg HKLM\SOFTWARE\Classes\JavaWebStart.isInstalled\CurVer@ JavaWebStart.isInstalled.1.6.0.0
Reg HKLM\SOFTWARE\Classes\JavaWebStart.isInstalled.1.6.0.0@ isInstalled Class
Reg HKLM\SOFTWARE\Classes\JavaWebStart.isInstalled.1.6.0.0\CLSID
Reg HKLM\SOFTWARE\Classes\JavaWebStart.isInstalled.1.6.0.0\CLSID@ {5852F5ED-8BF4-11D4-A245-0080C6F74284}
Reg HKLM\SOFTWARE\Classes\JNLPFile@ JNLP File
Reg HKLM\SOFTWARE\Classes\JNLPFile\Shell
Reg HKLM\SOFTWARE\Classes\JNLPFile\Shell\Open
Reg HKLM\SOFTWARE\Classes\JNLPFile\Shell\Open@ &Launch
Reg HKLM\SOFTWARE\Classes\JNLPFile\Shell\Open\Command
Reg HKLM\SOFTWARE\Classes\JNLPFile\Shell\Open\Command@ "C:\Program Files\Java\jre6\bin\javaws.exe" "%1"
Reg HKLM\SOFTWARE\Classes\LogicalDevice.IDLogicalDevice@ Windows Live Logical Device
Reg HKLM\SOFTWARE\Classes\LogicalDevice.IDLogicalDevice\CLSID
Reg HKLM\SOFTWARE\Classes\LogicalDevice.IDLogicalDevice\CLSID@ {B9F1D9B8-1DA6-4F17-962F-69EC82EA2704}
Reg HKLM\SOFTWARE\Classes\LogicalDevice.IDLogicalDevice\CurVer
Reg HKLM\SOFTWARE\Classes\LogicalDevice.IDLogicalDevice\CurVer@ LogicalDevice.IDLogicalDevice.1
Reg HKLM\SOFTWARE\Classes\LogicalDevice.IDLogicalDevice.1@ Windows Live Logical Device
Reg HKLM\SOFTWARE\Classes\LogicalDevice.IDLogicalDevice.1\CLSID
Reg HKLM\SOFTWARE\Classes\LogicalDevice.IDLogicalDevice.1\CLSID@ {B9F1D9B8-1DA6-4F17-962F-69EC82EA2704}
Reg HKLM\SOFTWARE\Classes\Microsoft.wlsc.Core@ Windows Live OneCare safety scanner Core Module
Reg HKLM\SOFTWARE\Classes\Microsoft.wlsc.Core\CLSID
Reg HKLM\SOFTWARE\Classes\Microsoft.wlsc.Core\CLSID@ {55265A35-B335-44FE-BFB4-854E3461004D}
Reg HKLM\SOFTWARE\Classes\Microsoft.wlsc.Core\CurVer
Reg HKLM\SOFTWARE\Classes\Microsoft.wlsc.Core\CurVer@ Microsoft.wlsc.Core.1
Reg HKLM\SOFTWARE\Classes\Microsoft.wlsc.Core.1@ Windows Live OneCare safety scanner Core Module
Reg HKLM\SOFTWARE\Classes\Microsoft.wlsc.Core.1\CLSID
Reg HKLM\SOFTWARE\Classes\Microsoft.wlsc.Core.1\CLSID@ {55265A35-B335-44FE-BFB4-854E3461004D}
Reg HKLM\SOFTWARE\Classes\Microsoft.wlsc.Scanner.Defrag@ Windows Live OneCare safety scanner Disk Fragmentation Scanner
Reg HKLM\SOFTWARE\Classes\Microsoft.wlsc.Scanner.Defrag\CLSID
Reg HKLM\SOFTWARE\Classes\Microsoft.wlsc.Scanner.Defrag\CLSID@ {A4123DCA-30C3-4DD6-9B50-4D395813BE5A}
Reg HKLM\SOFTWARE\Classes\Microsoft.wlsc.Scanner.Defrag\CurVer
Reg HKLM\SOFTWARE\Classes\Microsoft.wlsc.Scanner.Defrag\CurVer@ Microsoft.wlsc.Scanner.Defrag.1
Reg HKLM\SOFTWARE\Classes\Microsoft.wlsc.Scanner.Defrag.1@ Windows Live OneCare safety scanner Disk Fragmentation Scanner
Reg HKLM\SOFTWARE\Classes\Microsoft.wlsc.Scanner.Defrag.1\CLSID
Reg HKLM\SOFTWARE\Classes\Microsoft.wlsc.Scanner.Defrag.1\CLSID@ {A4123DCA-30C3-4DD6-9B50-4D395813BE5A}
Reg HKLM\SOFTWARE\Classes\Microsoft.wlsc.Scanner.DiskHealth@ Windows Live OneCare safety scanner Disk Health Scanner
Reg HKLM\SOFTWARE\Classes\Microsoft.wlsc.Scanner.DiskHealth\CLSID
Reg HKLM\SOFTWARE\Classes\Microsoft.wlsc.Scanner.DiskHealth\CLSID@ {5134461D-7247-42CF-90DF-EBE7B8E207EC}
Reg HKLM\SOFTWARE\Classes\Microsoft.wlsc.Scanner.DiskHealth\CurVer
Reg HKLM\SOFTWARE\Classes\Microsoft.wlsc.Scanner.DiskHealth\CurVer@ Microsoft.wlsc.Scanner.DiskHealth.1
Reg HKLM\SOFTWARE\Classes\Microsoft.wlsc.Scanner.DiskHealth.1@ Windows Live OneCare safety scanner Disk Health Scanner
Reg HKLM\SOFTWARE\Classes\Microsoft.wlsc.Scanner.DiskHealth.1\CLSID
Reg HKLM\SOFTWARE\Classes\Microsoft.wlsc.Scanner.DiskHealth.1\CLSID@ {5134461D-7247-42CF-90DF-EBE7B8E207EC}
Reg HKLM\SOFTWARE\Classes\Microsoft.wlsc.Scanner.NetSafety@ Windows Live OneCare safety scanner Network Scanner
Reg HKLM\SOFTWARE\Classes\Microsoft.wlsc.Scanner.NetSafety\CLSID
Reg HKLM\SOFTWARE\Classes\Microsoft.wlsc.Scanner.NetSafety\CLSID@ {88627655-CA82-4095-B972-31BE3EA352AA}
Reg HKLM\SOFTWARE\Classes\Microsoft.wlsc.Scanner.NetSafety\CurVer
Reg HKLM\SOFTWARE\Classes\Microsoft.wlsc.Scanner.NetSafety\CurVer@ Microsoft.wlsc.Scanner.NetSafety.1
Reg HKLM\SOFTWARE\Classes\Microsoft.wlsc.Scanner.NetSafety.1@ Windows Live OneCare safety scanner Network Scanner
Reg HKLM\SOFTWARE\Classes\Microsoft.wlsc.Scanner.NetSafety.1\CLSID
Reg HKLM\SOFTWARE\Classes\Microsoft.wlsc.Scanner.NetSafety.1\CLSID@ {88627655-CA82-4095-B972-31BE3EA352AA}
Reg HKLM\SOFTWARE\Classes\Microsoft.wlsc.Scanner.PlatformInfo@ Windows Live OneCare safety scanner Platform Info Scanner
Reg HKLM\SOFTWARE\Classes\Microsoft.wlsc.Scanner.PlatformInfo\CLSID
Reg HKLM\SOFTWARE\Classes\Microsoft.wlsc.Scanner.PlatformInfo\CLSID@ {5E7FBD8F-7AEA-4E7C-81E1-E8F660A80379}
Reg HKLM\SOFTWARE\Classes\Microsoft.wlsc.Scanner.PlatformInfo\CurVer
Reg HKLM\SOFTWARE\Classes\Microsoft.wlsc.Scanner.PlatformInfo\CurVer@ Microsoft.wlsc.Scanner.PlatformInfo.1
Reg HKLM\SOFTWARE\Classes\Microsoft.wlsc.Scanner.PlatformInfo.1@ Windows Live OneCare safety scanner Platform Info Scanner
Reg HKLM\SOFTWARE\Classes\Microsoft.wlsc.Scanner.PlatformInfo.1\CLSID
Reg HKLM\SOFTWARE\Classes\Microsoft.wlsc.Scanner.PlatformInfo.1\CLSID@ {5E7FBD8F-7AEA-4E7C-81E1-E8F660A80379}
Reg HKLM\SOFTWARE\Classes\Microsoft.wlsc.Scanner.RegCleaner@ Windows Live OneCare safety scanner Registry Scanner
Reg HKLM\SOFTWARE\Classes\Microsoft.wlsc.Scanner.RegCleaner\CLSID
Reg HKLM\SOFTWARE\Classes\Microsoft.wlsc.Scanner.RegCleaner\CLSID@ {9E5B9899-39DD-4225-B2E8-C3FD1DA67079}
Reg HKLM\SOFTWARE\Classes\Microsoft.wlsc.Scanner.RegCleaner\CurVer
Reg HKLM\SOFTWARE\Classes\Microsoft.wlsc.Scanner.RegCleaner\CurVer@ Microsoft.wlsc.Scanner.RegCleaner.1
Reg HKLM\SOFTWARE\Classes\Microsoft.wlsc.Scanner.RegCleaner.1@ Windows Live OneCare safety scanner Registry Scanner
Reg HKLM\SOFTWARE\Classes\Microsoft.wlsc.Scanner.RegCleaner.1\CLSID
Reg HKLM\SOFTWARE\Classes\Microsoft.wlsc.Scanner.RegCleaner.1\CLSID@ {9E5B9899-39DD-4225-B2E8-C3FD1DA67079}
Reg HKLM\SOFTWARE\Classes\NsEngine.NsEngineIfaastMeas.1@ NsEngineIfaastMeas
Reg HKLM\SOFTWARE\Classes\NsEngine.NsEngineIfaastMeas.1\CLSID
Reg HKLM\SOFTWARE\Classes\NsEngine.NsEngineIfaastMeas.1\CLSID@ {280D6945-4777-430A-AFE3-0C82BE1B163A}
Reg HKLM\SOFTWARE\Classes\NsEngine.NsEngineIfaastMeasM.1@ NsEngineIfaastMeasM
Reg HKLM\SOFTWARE\Classes\NsEngine.NsEngineIfaastMeasM.1\CLSID
Reg HKLM\SOFTWARE\Classes\NsEngine.NsEngineIfaastMeasM.1\CLSID@ {78C85B36-6B35-4D37-8745-0295D938C79C}
Reg HKLM\SOFTWARE\Classes\NsFatEngine.NsFatBootOptimization.1@ NsFatBootOptimization
Reg HKLM\SOFTWARE\Classes\NsFatEngine.NsFatBootOptimization.1\CLSID
Reg HKLM\SOFTWARE\Classes\NsFatEngine.NsFatBootOptimization.1\CLSID@ {03304BDE-5112-4B86-98A5-28C662A5B8AD}
Reg HKLM\SOFTWARE\Classes\NsFatEngine.NsFatEngineAnalysis.1@ NsFatEngineAnalysis
Reg HKLM\SOFTWARE\Classes\NsFatEngine.NsFatEngineAnalysis.1\CLSID
Reg HKLM\SOFTWARE\Classes\NsFatEngine.NsFatEngineAnalysis.1\CLSID@ {575AC25F-EB22-4D44-97EC-79D00C29EC1C}
Reg HKLM\SOFTWARE\Classes\NsFatEngine.NsFatEngineManual.1@ NsFatEngineManual
Reg HKLM\SOFTWARE\Classes\NsFatEngine.NsFatEngineManual.1\CLSID
Reg HKLM\SOFTWARE\Classes\NsFatEngine.NsFatEngineManual.1\CLSID@ {15F6D01D-ABB7-4D4B-BD71-0919FE0F2D15}
Reg HKLM\SOFTWARE\Classes\NsFatEngine.NsFatEngineStd.1@ NsFatEngineStd
Reg HKLM\SOFTWARE\Classes\NsFatEngine.NsFatEngineStd.1\CLSID
Reg HKLM\SOFTWARE\Classes\NsFatEngine.NsFatEngineStd.1\CLSID@ {2C50CE85-5C1C-4C85-83B7-FD0B3261B479}
Reg HKLM\SOFTWARE\Classes\NsFatEngine.NsFatFSConsolidate.1@ NsFatFSConsolidate
Reg HKLM\SOFTWARE\Classes\NsFatEngine.NsFatFSConsolidate.1\CLSID
Reg HKLM\SOFTWARE\Classes\NsFatEngine.NsFatFSConsolidate.1\CLSID@ {5B96789B-67C6-46A4-A62D-C78994E5A27F}
Reg HKLM\SOFTWARE\Classes\NsFatEngine.NsFatSSDAnalysis.1@ NsFatSSDAnalysis
Reg HKLM\SOFTWARE\Classes\NsFatEngine.NsFatSSDAnalysis.1\CLSID
Reg HKLM\SOFTWARE\Classes\NsFatEngine.NsFatSSDAnalysis.1\CLSID@ {DDB04B89-76D1-4BF2-87B1-90607BDC58A6}
Reg HKLM\SOFTWARE\Classes\NsFatEngine.NsFatSSDAnalysisM.1@ NsFatSSDAnalysisM
Reg HKLM\SOFTWARE\Classes\NsFatEngine.NsFatSSDAnalysisM.1\CLSID
Reg HKLM\SOFTWARE\Classes\NsFatEngine.NsFatSSDAnalysisM.1\CLSID@ {55853C2B-4D03-4C7E-B832-043AE6DAC3C0}
Reg HKLM\SOFTWARE\Classes\NsFatEngine.NsFatSSDdefrag.1@ NsFatSSDdefrag
Reg HKLM\SOFTWARE\Classes\NsFatEngine.NsFatSSDdefrag.1\CLSID
Reg HKLM\SOFTWARE\Classes\NsFatEngine.NsFatSSDdefrag.1\CLSID@ {EBFBC66D-6C2C-4297-9F55-5B00BD701B1C}
Reg HKLM\SOFTWARE\Classes\NsFatEngine.NsFatSSDdefragM.1@ NsFatSSDdefragM
Reg HKLM\SOFTWARE\Classes\NsFatEngine.NsFatSSDdefragM.1\CLSID
Reg HKLM\SOFTWARE\Classes\NsFatEngine.NsFatSSDdefragM.1\CLSID@ {2E24D811-1E89-436B-87FE-1E2D1A38F934}
Reg HKLM\SOFTWARE\Classes\NsNtfsDirConsolidate.NsNtfsDirConsolidate.1@ NsNtfsDirConsolidate
Reg HKLM\SOFTWARE\Classes\NsNtfsDirConsolidate.NsNtfsDirConsolidate.1\CLSID
Reg HKLM\SOFTWARE\Classes\NsNtfsDirConsolidate.NsNtfsDirConsolidate.1\CLSID@ {30964884-3C83-4C2C-90BF-2043F4354A91}
Reg HKLM\SOFTWARE\Classes\NsNtfsEngine.NsFatAutoAnalysis.1@ NsFatAutoAnalysis
Reg HKLM\SOFTWARE\Classes\NsNtfsEngine.NsFatAutoAnalysis.1\CLSID
Reg HKLM\SOFTWARE\Classes\NsNtfsEngine.NsFatAutoAnalysis.1\CLSID@ {F3A52F1E-2BDF-4C0A-B846-E27204A50B98}
Reg HKLM\SOFTWARE\Classes\NsNtfsEngine.NsFatPartialDefrag.1@ NsFatPartialDefrag
Reg HKLM\SOFTWARE\Classes\NsNtfsEngine.NsFatPartialDefrag.1\CLSID
Reg HKLM\SOFTWARE\Classes\NsNtfsEngine.NsFatPartialDefrag.1\CLSID@ {6B05BD42-8A9D-4ED6-88F1-8DF808CC212E}
Reg HKLM\SOFTWARE\Classes\NsNtfsEngine.NsNtfsBootOptimization.1@ NsNtfsBootOptimization
Reg HKLM\SOFTWARE\Classes\NsNtfsEngine.NsNtfsBootOptimization.1\CLSID
Reg HKLM\SOFTWARE\Classes\NsNtfsEngine.NsNtfsBootOptimization.1\CLSID@ {E361218C-76B1-4F08-B57B-1BC1445FA8EA}
Reg HKLM\SOFTWARE\Classes\NsNtfsEngine.NsNtfsEngineAnalysis.1@ NsNtfsEngineAnalysis
Reg HKLM\SOFTWARE\Classes\NsNtfsEngine.NsNtfsEngineAnalysis.1\CLSID
Reg HKLM\SOFTWARE\Classes\NsNtfsEngine.NsNtfsEngineAnalysis.1\CLSID@ {A7580D67-E8AB-4304-A291-FEA4FE6F668F}
Reg HKLM\SOFTWARE\Classes\NsNtfsEngine.NsNtfsEngineFragShield.1@ NsNtfsEngineFragShield
Reg HKLM\SOFTWARE\Classes\NsNtfsEngine.NsNtfsEngineFragShield.1\CLSID
Reg HKLM\SOFTWARE\Classes\NsNtfsEngine.NsNtfsEngineFragShield.1\CLSID@ {3F8B67A5-8A0D-4E9F-B503-24159E790299}
Reg HKLM\SOFTWARE\Classes\NsNtfsEngine.NsNtfsEngineIfaast.1@ NsNtfsEngineIfaast
Reg HKLM\SOFTWARE\Classes\NsNtfsEngine.NsNtfsEngineIfaast.1\CLSID
Reg HKLM\SOFTWARE\Classes\NsNtfsEngine.NsNtfsEngineIfaast.1\CLSID@ {431EE571-3CCA-458A-9D7F-75E0492D1264}
Reg HKLM\SOFTWARE\Classes\NsNtfsEngine.NsNtfsEngineManual.1@ NsNtfsEngineStd
Reg HKLM\SOFTWARE\Classes\NsNtfsEngine.NsNtfsEngineManual.1\CLSID
Reg HKLM\SOFTWARE\Classes\NsNtfsEngine.NsNtfsEngineManual.1\CLSID@ {99AB38E0-3607-453D-8DB6-3CC7DF37A119}
Reg HKLM\SOFTWARE\Classes\NsNtfsEngine.NsNtfsEngineStd.1@ NsNtfsEngineStd
Reg HKLM\SOFTWARE\Classes\NsNtfsEngine.NsNtfsEngineStd.1\CLSID
Reg HKLM\SOFTWARE\Classes\NsNtfsEngine.NsNtfsEngineStd.1\CLSID@ {3876CE20-690F-4642-96F6-B5F7A3E14689}
Reg HKLM\SOFTWARE\Classes\NsNtfsEngine.NsNtfsEngineTve.1@ NsNtfsEngineTve
Reg HKLM\SOFTWARE\Classes\NsNtfsEngine.NsNtfsEngineTve.1\CLSID
Reg HKLM\SOFTWARE\Classes\NsNtfsEngine.NsNtfsEngineTve.1\CLSID@ {934F3116-CF63-46F5-8814-4B5F29D5A298}
Reg HKLM\SOFTWARE\Classes\NsNtfsEngine.NsNtfsEngineTvem.1@ NsNtfsEngineTvem
Reg HKLM\SOFTWARE\Classes\NsNtfsEngine.NsNtfsEngineTvem.1\CLSID
Reg HKLM\SOFTWARE\Classes\NsNtfsEngine.NsNtfsEngineTvem.1\CLSID@ {2F8CDCBA-5C06-4928-B0E4-16522D2D1A4A}
Reg HKLM\SOFTWARE\Classes\NsNtfsEngine.NsNtfsFSConsolidate.1@ NsNtfsFSConsolidate
Reg HKLM\SOFTWARE\Classes\NsNtfsEngine.NsNtfsFSConsolidate.1\CLSID
Reg HKLM\SOFTWARE\Classes\NsNtfsEngine.NsNtfsFSConsolidate.1\CLSID@ {B8715D46-E3C9-466B-BB16-844B64B542D9}
Reg HKLM\SOFTWARE\Classes\NsNtfsEngine.NsNtfsPartialDefrag.1@ NsNtfsPartialDefrag
Reg HKLM\SOFTWARE\Classes\NsNtfsEngine.NsNtfsPartialDefrag.1\CLSID
Reg HKLM\SOFTWARE\Classes\NsNtfsEngine.NsNtfsPartialDefrag.1\CLSID@ {C850B228-7D8A-4551-BF81-5A2D7969ABD1}
Reg HKLM\SOFTWARE\Classes\NsNtfsEngine.NsNtfsSSDAnalysis.1@ NsNtfsSSDAnalysis
Reg HKLM\SOFTWARE\Classes\NsNtfsEngine.NsNtfsSSDAnalysis.1\CLSID
Reg HKLM\SOFTWARE\Classes\NsNtfsEngine.NsNtfsSSDAnalysis.1\CLSID@ {0A006559-94BC-495F-A7C7-F74BF4187B57}
Reg HKLM\SOFTWARE\Classes\NsNtfsEngine.NsNtfsSSDAnalysisM.1@ NsNtfsSSDAnalysisM
Reg HKLM\SOFTWARE\Classes\NsNtfsEngine.NsNtfsSSDAnalysisM.1\CLSID
Reg HKLM\SOFTWARE\Classes\NsNtfsEngine.NsNtfsSSDAnalysisM.1\CLSID@ {C9EC9731-8EE1-49EB-983D-BD411B1BF6AB}
Reg HKLM\SOFTWARE\Classes\NsNtfsEngine.NsNtfsSSDdefrag.1@ NsNtfsSSDdefrag
Reg HKLM\SOFTWARE\Classes\NsNtfsEngine.NsNtfsSSDdefrag.1\CLSID
Reg HKLM\SOFTWARE\Classes\NsNtfsEngine.NsNtfsSSDdefrag.1\CLSID@ {5147CBC0-4C52-4F36-ACE5-9E2C5FCA51B0}
Reg HKLM\SOFTWARE\Classes\NsNtfsEngine.NsNtfsSSDdefragM.1@ NsNtfsSSDdefragM
Reg HKLM\SOFTWARE\Classes\NsNtfsEngine.NsNtfsSSDdefragM.1\CLSID
Reg HKLM\SOFTWARE\Classes\NsNtfsEngine.NsNtfsSSDdefragM.1\CLSID@ {7076850A-DB0B-4659-BE9F-C25E0F53D136}
Reg HKLM\SOFTWARE\Classes\NsNtfsEngine.NsNtfsTVE_Ex.1@ NsNtfsTVE_Ex
Reg HKLM\SOFTWARE\Classes\NsNtfsEngine.NsNtfsTVE_Ex.1\CLSID
Reg HKLM\SOFTWARE\Classes\NsNtfsEngine.NsNtfsTVE_Ex.1\CLSID@ {DB9C05FB-3E71-40D2-8C04-3ADEE5E74400}
Reg HKLM\SOFTWARE\Classes\NsNtfsEngine.NsNtfsTVE_ExM.1@ NsNtfsTVE_ExM
Reg HKLM\SOFTWARE\Classes\NsNtfsEngine.NsNtfsTVE_ExM.1\CLSID
Reg HKLM\SOFTWARE\Classes\NsNtfsEngine.NsNtfsTVE_ExM.1\CLSID@ {B12F91C9-5E75-4A6A-94B6-31F6EA3C2C2C}
Reg HKLM\SOFTWARE\Classes\NsNtfsFreespaceConsolidate.NsNtfsFreespaceConsolidate.1@ NsNtfsFreespaceConsolidate
Reg HKLM\SOFTWARE\Classes\NsNtfsFreespaceConsolidate.NsNtfsFreespaceConsolidate.1\CLSID
Reg HKLM\SOFTWARE\Classes\NsNtfsFreespaceConsolidate.NsNtfsFreespaceConsolidate.1\CLSID@ {D04E57B4-CFFF-4DAA-B283-03019FFF41A6}
Reg HKLM\SOFTWARE\Classes\NsNtfsLoFsEngine.NsNtfsLoFsEngine.1@ NsNtfsLoFsEngine
Reg HKLM\SOFTWARE\Classes\NsNtfsLoFsEngine.NsNtfsLoFsEngine.1\CLSID
Reg HKLM\SOFTWARE\Classes\NsNtfsLoFsEngine.NsNtfsLoFsEngine.1\CLSID@ {F064C75D-D3E9-43D4-AD5A-D4D6F97739D5}
Reg HKLM\SOFTWARE\Classes\OutlookChangeNotifier.Connect@ Connect Class
Reg HKLM\SOFTWARE\Classes\OutlookChangeNotifier.Connect\CLSID
Reg HKLM\SOFTWARE\Classes\OutlookChangeNotifier.Connect\CLSID@ {12E6A993-AE52-4F99-8B89-41F985E6C952}
Reg HKLM\SOFTWARE\Classes\OutlookChangeNotifier.Connect\CurVer
Reg HKLM\SOFTWARE\Classes\OutlookChangeNotifier.Connect\CurVer@ OutlookChangeNotifier.Connect.1
Reg HKLM\SOFTWARE\Classes\OutlookChangeNotifier.Connect.1@ Connect Class
Reg HKLM\SOFTWARE\Classes\OutlookChangeNotifier.Connect.1\CLSID
Reg HKLM\SOFTWARE\Classes\OutlookChangeNotifier.Connect.1\CLSID@ {12E6A993-AE52-4F99-8B89-41F985E6C952}
Reg HKLM\SOFTWARE\Classes\pcast@ URL:iTunes Podcast
Reg HKLM\SOFTWARE\Classes\pcast@AppUserModelID Apple.iTunes
Reg HKLM\SOFTWARE\Classes\pcast@URL Protocol
Reg HKLM\SOFTWARE\Classes\pcast\DefaultIcon
Reg HKLM\SOFTWARE\Classes\pcast\DefaultIcon@ C:\Program Files\iTunes\iTunes.exe
Reg HKLM\SOFTWARE\Classes\pcast\shell
Reg HKLM\SOFTWARE\Classes\pcast\shell@
Reg HKLM\SOFTWARE\Classes\pcast\shell\open
Reg HKLM\SOFTWARE\Classes\pcast\shell\open@
Reg HKLM\SOFTWARE\Classes\pcast\shell\open\command
Reg HKLM\SOFTWARE\Classes\pcast\shell\open\command@ C:\Program Files\iTunes\iTunes.exe /url "%1"
Reg HKLM\SOFTWARE\Classes\QTOLibrary.QTMatrix.1@ QTMatrix Class
Reg HKLM\SOFTWARE\Classes\QTOLibrary.QTMatrix.1\CLSID
Reg HKLM\SOFTWARE\Classes\QTOLibrary.QTMatrix.1\CLSID@ {A882BDEE-BD01-4B16-9EAF-04B74A43DF7C}
Reg HKLM\SOFTWARE\Classes\QTUIPanelControl.PropPanelControl@ PropPanelControl Class
Reg HKLM\SOFTWARE\Classes\QTUIPanelControl.PropPanelControl\CLSID
Reg HKLM\SOFTWARE\Classes\QTUIPanelControl.PropPanelControl\CLSID@ {27A59F19-C5CC-4B51-A6CA-A1DEBF81F022}
Reg HKLM\SOFTWARE\Classes\QTUIPanelControl.PropPanelControl\CurVer
Reg HKLM\SOFTWARE\Classes\QTUIPanelControl.PropPanelControl\CurVer@ QTUIPanelControl.PropPanelControl.1
Reg HKLM\SOFTWARE\Classes\QTUIPanelControl.PropPanelControl.1@ PropPanelControl Class
Reg HKLM\SOFTWARE\Classes\QTUIPanelControl.PropPanelControl.1\CLSID
Reg HKLM\SOFTWARE\Classes\QTUIPanelControl.PropPanelControl.1\CLSID@ {27A59F19-C5CC-4B51-A6CA-A1DEBF81F022}
Reg HKLM\SOFTWARE\Classes\QuickTime.3g2@ 3GPP2 Movie
Reg HKLM\SOFTWARE\Classes\QuickTime.3g2\DefaultIcon
Reg HKLM\SOFTWARE\Classes\QuickTime.3g2\DefaultIcon@ C:\Program Files\QuickTime\QuickTimePlayer.exe,-163
Reg HKLM\SOFTWARE\Classes\QuickTime.3g2\shell
Reg HKLM\SOFTWARE\Classes\QuickTime.3g2\shell@ open
Reg HKLM\SOFTWARE\Classes\QuickTime.3g2\shell\open
Reg HKLM\SOFTWARE\Classes\QuickTime.3g2\shell\open\command
Reg HKLM\SOFTWARE\Classes\QuickTime.3g2\shell\open\command@ C:\Program Files\QuickTime\QuickTimePlayer.exe "%1"
Reg HKLM\SOFTWARE\Classes\QuickTime.3gp@ 3GPP Movie
Reg HKLM\SOFTWARE\Classes\QuickTime.3gp\DefaultIcon
Reg HKLM\SOFTWARE\Classes\QuickTime.3gp\DefaultIcon@ C:\Program Files\QuickTime\QuickTimePlayer.exe,-162
Reg HKLM\SOFTWARE\Classes\QuickTime.3gp\shell
Reg HKLM\SOFTWARE\Classes\QuickTime.3gp\shell@ open
Reg HKLM\SOFTWARE\Classes\QuickTime.3gp\shell\open
Reg HKLM\SOFTWARE\Classes\QuickTime.3gp\shell\open\command
Reg HKLM\SOFTWARE\Classes\QuickTime.3gp\shell\open\command@ C:\Program Files\QuickTime\QuickTimePlayer.exe "%1"
Reg HKLM\SOFTWARE\Classes\QuickTime.3gp2@ 3GPP2 Movie
Reg HKLM\SOFTWARE\Classes\QuickTime.3gp2\DefaultIcon
Reg HKLM\SOFTWARE\Classes\QuickTime.3gp2\DefaultIcon@ C:\Program Files\QuickTime\QuickTimePlayer.exe,-163
Reg HKLM\SOFTWARE\Classes\QuickTime.3gp2\shell
Reg HKLM\SOFTWARE\Classes\QuickTime.3gp2\shell@ open
Reg HKLM\SOFTWARE\Classes\QuickTime.3gp2\shell\open
Reg HKLM\SOFTWARE\Classes\QuickTime.3gp2\shell\open\command
Reg HKLM\SOFTWARE\Classes\QuickTime.3gp2\shell\open\command@ C:\Program Files\QuickTime\QuickTimePlayer.exe "%1"
Reg HKLM\SOFTWARE\Classes\QuickTime.3gpp@ 3GPP Movie
Reg HKLM\SOFTWARE\Classes\QuickTime.3gpp\DefaultIcon
Reg HKLM\SOFTWARE\Classes\QuickTime.3gpp\DefaultIcon@ C:\Program Files\QuickTime\QuickTimePlayer.exe,-162
Reg HKLM\SOFTWARE\Classes\QuickTime.3gpp\shell
Reg HKLM\SOFTWARE\Classes\QuickTime.3gpp\shell@ open
Reg HKLM\SOFTWARE\Classes\QuickTime.3gpp\shell\open
Reg HKLM\SOFTWARE\Classes\QuickTime.3gpp\shell\open\command
Reg HKLM\SOFTWARE\Classes\QuickTime.3gpp\shell\open\command@ C:\Program Files\QuickTime\QuickTimePlayer.exe "%1"
Reg HKLM\SOFTWARE\Classes\QuickTime.aac\DefaultIcon
Reg HKLM\SOFTWARE\Classes\QuickTime.aac\DefaultIcon@ C:\Program Files\QuickTime\QuickTimePlayer.exe,-130
Reg HKLM\SOFTWARE\Classes\QuickTime.aac\shell
Reg HKLM\SOFTWARE\Classes\QuickTime.aac\shell@ open
Reg HKLM\SOFTWARE\Classes\QuickTime.aac\shell\open
Reg HKLM\SOFTWARE\Classes\QuickTime.aac\shell\open\command
Reg HKLM\SOFTWARE\Classes\QuickTime.aac\shell\open\command@ C:\Program Files\QuickTime\QuickTimePlayer.exe "%1"
Reg HKLM\SOFTWARE\Classes\QuickTime.ac3@ AC3 Audio
Reg HKLM\SOFTWARE\Classes\QuickTime.ac3\DefaultIcon
Reg HKLM\SOFTWARE\Classes\QuickTime.ac3\DefaultIcon@ C:\Program Files\QuickTime\QuickTimePlayer.exe,-130
Reg HKLM\SOFTWARE\Classes\QuickTime.ac3\shell
Reg HKLM\SOFTWARE\Classes\QuickTime.ac3\shell@ open
Reg HKLM\SOFTWARE\Classes\QuickTime.ac3\shell\open
Reg HKLM\SOFTWARE\Classes\QuickTime.ac3\shell\open\command
Reg HKLM\SOFTWARE\Classes\QuickTime.ac3\shell\open\command@ C:\Program Files\QuickTime\QuickTimePlayer.exe "%1"
Reg HKLM\SOFTWARE\Classes\QuickTime.adts\DefaultIcon
Reg HKLM\SOFTWARE\Classes\QuickTime.adts\DefaultIcon@ C:\Program Files\QuickTime\QuickTimePlayer.exe,-130
Reg HKLM\SOFTWARE\Classes\QuickTime.adts\shell
Reg HKLM\SOFTWARE\Classes\QuickTime.adts\shell@ open
Reg HKLM\SOFTWARE\Classes\QuickTime.adts\shell\open
Reg HKLM\SOFTWARE\Classes\QuickTime.adts\shell\open\command
Reg HKLM\SOFTWARE\Classes\QuickTime.adts\shell\open\command@ C:\Program Files\QuickTime\QuickTimePlayer.exe "%1"
Reg HKLM\SOFTWARE\Classes\QuickTime.aif@ AIFF Audio
Reg HKLM\SOFTWARE\Classes\QuickTime.aif\DefaultIcon
Reg HKLM\SOFTWARE\Classes\QuickTime.aif\DefaultIcon@ C:\Program Files\QuickTime\QuickTimePlayer.exe,-131
Reg HKLM\SOFTWARE\Classes\QuickTime.aif\shell
Reg HKLM\SOFTWARE\Classes\QuickTime.aif\shell@ open
Reg HKLM\SOFTWARE\Classes\QuickTime.aif\shell\open
Reg HKLM\SOFTWARE\Classes\QuickTime.aif\shell\open\command
Reg HKLM\SOFTWARE\Classes\QuickTime.aif\shell\open\command@ C:\Program Files\QuickTime\QuickTimePlayer.exe "%1"
Reg HKLM\SOFTWARE\Classes\QuickTime.aifc@ AIFF Audio
Reg HKLM\SOFTWARE\Classes\QuickTime.aifc\DefaultIcon
Reg HKLM\SOFTWARE\Classes\QuickTime.aifc\DefaultIcon@ C:\Program Files\QuickTime\QuickTimePlayer.exe,-131
Reg HKLM\SOFTWARE\Classes\QuickTime.aifc\shell
Reg HKLM\SOFTWARE\Classes\QuickTime.aifc\shell@ open
Reg HKLM\SOFTWARE\Classes\QuickTime.aifc\shell\open
Reg HKLM\SOFTWARE\Classes\QuickTime.aifc\shell\open\command
Reg HKLM\SOFTWARE\Classes\QuickTime.aifc\shell\open\command@ C:\Program Files\QuickTime\QuickTimePlayer.exe "%1"
Reg HKLM\SOFTWARE\Classes\QuickTime.aiff@ AIFF Audio
Reg HKLM\SOFTWARE\Classes\QuickTime.aiff\DefaultIcon
Reg HKLM\SOFTWARE\Classes\QuickTime.aiff\DefaultIcon@ C:\Program Files\QuickTime\QuickTimePlayer.exe,-131
Reg HKLM\SOFTWARE\Classes\QuickTime.aiff\shell
Reg HKLM\SOFTWARE\Classes\QuickTime.aiff\shell@ open
Reg HKLM\SOFTWARE\Classes\QuickTime.aiff\shell\open
Reg HKLM\SOFTWARE\Classes\QuickTime.aiff\shell\open\command
Reg HKLM\SOFTWARE\Classes\QuickTime.aiff\shell\open\command@ C:\Program Files\QuickTime\QuickTimePlayer.exe "%1"
Reg HKLM\SOFTWARE\Classes\QuickTime.amc@ AMC Movie
Reg HKLM\SOFTWARE\Classes\QuickTime.amc\DefaultIcon
Reg HKLM\SOFTWARE\Classes\QuickTime.amc\DefaultIcon@ C:\Program Files\QuickTime\QuickTimePlayer.exe,-164
Reg HKLM\SOFTWARE\Classes\QuickTime.amc\shell
Reg HKLM\SOFTWARE\Classes\QuickTime.amc\shell@ open
Reg HKLM\SOFTWARE\Classes\QuickTime.amc\shell\open
Reg HKLM\SOFTWARE\Classes\QuickTime.amc\shell\open\command
Reg HKLM\SOFTWARE\Classes\QuickTime.amc\shell\open\command@ C:\Program Files\QuickTime\QuickTimePlayer.exe "%1"
Reg HKLM\SOFTWARE\Classes\QuickTime.AMR@ AMR Audio
Reg HKLM\SOFTWARE\Classes\QuickTime.AMR\DefaultIcon
Reg HKLM\SOFTWARE\Classes\QuickTime.AMR\DefaultIcon@ C:\Program Files\QuickTime\QuickTimePlayer.exe,-162
Reg HKLM\SOFTWARE\Classes\QuickTime.AMR\shell
Reg HKLM\SOFTWARE\Classes\QuickTime.AMR\shell@ open
Reg HKLM\SOFTWARE\Classes\QuickTime.AMR\shell\open
Reg HKLM\SOFTWARE\Classes\QuickTime.AMR\shell\open\command
Reg HKLM\SOFTWARE\Classes\QuickTime.AMR\shell\open\command@ C:\Program Files\QuickTime\QuickTimePlayer.exe "%1"
Reg HKLM\SOFTWARE\Classes\QuickTime.au@ AU Audio
Reg HKLM\SOFTWARE\Classes\QuickTime.au\DefaultIcon
Reg HKLM\SOFTWARE\Classes\QuickTime.au\DefaultIcon@ C:\Program Files\QuickTime\QuickTimePlayer.exe,-132
Reg HKLM\SOFTWARE\Classes\QuickTime.au\shell
Reg HKLM\SOFTWARE\Classes\QuickTime.au\shell@ open
Reg HKLM\SOFTWARE\Classes\QuickTime.au\shell\open
Reg HKLM\SOFTWARE\Classes\QuickTime.au\shell\open\command
Reg HKLM\SOFTWARE\Classes\QuickTime.au\shell\open\command@ C:\Program Files\QuickTime\QuickTimePlayer.exe "%1"
Reg HKLM\SOFTWARE\Classes\QuickTime.avi@ Microsoft Video
Reg HKLM\SOFTWARE\Classes\QuickTime.avi\DefaultIcon
Reg HKLM\SOFTWARE\Classes\QuickTime.avi\DefaultIcon@ C:\Program Files\QuickTime\QuickTimePlayer.exe,-133
Reg HKLM\SOFTWARE\Classes\QuickTime.avi\shell
Reg HKLM\SOFTWARE\Classes\QuickTime.avi\shell@ open
Reg HKLM\SOFTWARE\Classes\QuickTime.avi\shell\open
Reg HKLM\SOFTWARE\Classes\QuickTime.avi\shell\open\command
Reg HKLM\SOFTWARE\Classes\QuickTime.avi\shell\open\command@ C:\Program Files\QuickTime\QuickTimePlayer.exe "%1"
Reg HKLM\SOFTWARE\Classes\QuickTime.bmp@ Windows BMP Image
Reg HKLM\SOFTWARE\Classes\QuickTime.bmp\DefaultIcon
Reg HKLM\SOFTWARE\Classes\QuickTime.bmp\DefaultIcon@ C:\Program Files\QuickTime\PictureViewer.exe,-131
Reg HKLM\SOFTWARE\Classes\QuickTime.bmp\shell
Reg HKLM\SOFTWARE\Classes\QuickTime.bmp\shell@ open
Reg HKLM\SOFTWARE\Classes\QuickTime.bmp\shell\open
Reg HKLM\SOFTWARE\Classes\QuickTime.bmp\shell\open\command
Reg HKLM\SOFTWARE\Classes\QuickTime.bmp\shell\open\command@ C:\Program Files\QuickTime\PictureViewer.exe "%1"
Reg HKLM\SOFTWARE\Classes\QuickTime.bwf@ WAV Audio
Reg HKLM\SOFTWARE\Classes\QuickTime.bwf\DefaultIcon
Reg HKLM\SOFTWARE\Classes\QuickTime.bwf\DefaultIcon@ C:\Program Files\QuickTime\QuickTimePlayer.exe,-130
Reg HKLM\SOFTWARE\Classes\QuickTime.bwf\shell
Reg HKLM\SOFTWARE\Classes\QuickTime.bwf\shell@ open
Reg HKLM\SOFTWARE\Classes\QuickTime.bwf\shell\open
Reg HKLM\SOFTWARE\Classes\QuickTime.bwf\shell\open\command
Reg HKLM\SOFTWARE\Classes\QuickTime.bwf\shell\open\command@ C:\Program Files\QuickTime\QuickTimePlayer.exe "%1"
Reg HKLM\SOFTWARE\Classes\QuickTime.caf@ CAF Audio
Reg HKLM\SOFTWARE\Classes\QuickTime.caf\DefaultIcon
Reg HKLM\SOFTWARE\Classes\QuickTime.caf\DefaultIcon@ C:\Program Files\QuickTime\QuickTimePlayer.exe,-130
Reg HKLM\SOFTWARE\Classes\QuickTime.caf\shell
Reg HKLM\SOFTWARE\Classes\QuickTime.caf\shell@ open
Reg HKLM\SOFTWARE\Classes\QuickTime.caf\shell\open
Reg HKLM\SOFTWARE\Classes\QuickTime.caf\shell\open\command
Reg HKLM\SOFTWARE\Classes\QuickTime.caf\shell\open\command@ C:\Program Files\QuickTime\QuickTimePlayer.exe "%1"
Reg HKLM\SOFTWARE\Classes\QuickTime.cdda@ AIFF Audio
Reg HKLM\SOFTWARE\Classes\QuickTime.cdda\DefaultIcon
Reg HKLM\SOFTWARE\Classes\QuickTime.cdda\DefaultIcon@ C:\Program Files\QuickTime\QuickTimePlayer.exe,-130
Reg HKLM\SOFTWARE\Classes\QuickTime.cdda\shell
Reg HKLM\SOFTWARE\Classes\QuickTime.cdda\shell@ open
Reg HKLM\SOFTWARE\Classes\QuickTime.cdda\shell\open
Reg HKLM\SOFTWARE\Classes\QuickTime.cdda\shell\open\command
Reg HKLM\SOFTWARE\Classes\QuickTime.cdda\shell\open\command@ C:\Program Files\QuickTime\QuickTimePlayer.exe "%1"
Reg HKLM\SOFTWARE\Classes\QuickTime.cel@ FLC Animation
Reg HKLM\SOFTWARE\Classes\QuickTime.cel\DefaultIcon
Reg HKLM\SOFTWARE\Classes\QuickTime.cel\DefaultIcon@ C:\Program Files\QuickTime\QuickTimePlayer.exe,-130
Reg HKLM\SOFTWARE\Classes\QuickTime.cel\shell
Reg HKLM\SOFTWARE\Classes\QuickTime.cel\shell@ open
Reg HKLM\SOFTWARE\Classes\QuickTime.cel\shell\open
Reg HKLM\SOFTWARE\Classes\QuickTime.cel\shell\open\command
Reg HKLM\SOFTWARE\Classes\QuickTime.cel\shell\open\command@ C:\Program Files\QuickTime\QuickTimePlayer.exe "%1"
Reg HKLM\SOFTWARE\Classes\QuickTime.dib@ Windows BMP Image
Reg HKLM\SOFTWARE\Classes\QuickTime.dib\DefaultIcon
Reg HKLM\SOFTWARE\Classes\QuickTime.dib\DefaultIcon@ C:\Program Files\QuickTime\PictureViewer.exe,-131
Reg HKLM\SOFTWARE\Classes\QuickTime.dib\shell
Reg HKLM\SOFTWARE\Classes\QuickTime.dib\shell@ open
Reg HKLM\SOFTWARE\Classes\QuickTime.dib\shell\open
Reg HKLM\SOFTWARE\Classes\QuickTime.dib\shell\open\command
Reg HKLM\SOFTWARE\Classes\QuickTime.dib\shell\open\command@ C:\Program Files\QuickTime\PictureViewer.exe "%1"
Reg HKLM\SOFTWARE\Classes\QuickTime.dif@ DV Movie
Reg HKLM\SOFTWARE\Classes\QuickTime.dif\DefaultIcon
Reg HKLM\SOFTWARE\Classes\QuickTime.dif\DefaultIcon@ C:\Program Files\QuickTime\QuickTimePlayer.exe,-134
Reg HKLM\SOFTWARE\Classes\QuickTime.dif\shell
Reg HKLM\SOFTWARE\Classes\QuickTime.dif\shell@ open
Reg HKLM\SOFTWARE\Classes\QuickTime.dif\shell\open
Reg HKLM\SOFTWARE\Classes\QuickTime.dif\shell\open\command
Reg HKLM\SOFTWARE\Classes\QuickTime.dif\shell\open\command@ C:\Program Files\QuickTime\QuickTimePlayer.exe "%1"
Reg HKLM\SOFTWARE\Classes\QuickTime.dv@ DV Movie
Reg HKLM\SOFTWARE\Classes\QuickTime.dv\DefaultIcon
Reg HKLM\SOFTWARE\Classes\QuickTime.dv\DefaultIcon@ C:\Program Files\QuickTime\QuickTimePlayer.exe,-134
Reg HKLM\SOFTWARE\Classes\QuickTime.dv\shell
Reg HKLM\SOFTWARE\Classes\QuickTime.dv\shell@ open
Reg HKLM\SOFTWARE\Classes\QuickTime.dv\shell\open
Reg HKLM\SOFTWARE\Classes\QuickTime.dv\shell\open\command
Reg HKLM\SOFTWARE\Classes\QuickTime.dv\shell\open\command@ C:\Program Files\QuickTime\QuickTimePlayer.exe "%1"
Reg HKLM\SOFTWARE\Classes\QuickTime.flc@ FLC Animation
Reg HKLM\SOFTWARE\Classes\QuickTime.flc\DefaultIcon
Reg HKLM\SOFTWARE\Classes\QuickTime.flc\DefaultIcon@ C:\Program Files\QuickTime\QuickTimePlayer.exe,-135
Reg HKLM\SOFTWARE\Classes\QuickTime.flc\shell
Reg HKLM\SOFTWARE\Classes\QuickTime.flc\shell@ open
Reg HKLM\SOFTWARE\Classes\QuickTime.flc\shell\open
Reg HKLM\SOFTWARE\Classes\QuickTime.flc\shell\open\command
Reg HKLM\SOFTWARE\Classes\QuickTime.flc\shell\open\command@ C:\Program Files\QuickTime\QuickTimePlayer.exe "%1"
Reg HKLM\SOFTWARE\Classes\QuickTime.fli@ FLC Animation
Reg HKLM\SOFTWARE\Classes\QuickTime.fli\DefaultIcon
Reg HKLM\SOFTWARE\Classes\QuickTime.fli\DefaultIcon@ C:\Program Files\QuickTime\QuickTimePlayer.exe,-135
Reg HKLM\SOFTWARE\Classes\QuickTime.fli\shell
Reg HKLM\SOFTWARE\Classes\QuickTime.fli\shell@ open
Reg HKLM\SOFTWARE\Classes\QuickTime.fli\shell\open
Reg HKLM\SOFTWARE\Classes\QuickTime.fli\shell\open\command
Reg HKLM\SOFTWARE\Classes\QuickTime.fli\shell\open\command@ C:\Program Files\QuickTime\QuickTimePlayer.exe "%1"
Reg HKLM\SOFTWARE\Classes\QuickTime.gif@ GIF Image
Reg HKLM\SOFTWARE\Classes\QuickTime.gif\DefaultIcon
Reg HKLM\SOFTWARE\Classes\QuickTime.gif\DefaultIcon@ C:\Program Files\QuickTime\QuickTimePlayer.exe,-136
Reg HKLM\SOFTWARE\Classes\QuickTime.gif\shell
Reg HKLM\SOFTWARE\Classes\QuickTime.gif\shell@ open
Reg HKLM\SOFTWARE\Classes\QuickTime.gif\shell\open
Reg HKLM\SOFTWARE\Classes\QuickTime.gif\shell\open\command
Reg HKLM\SOFTWARE\Classes\QuickTime.gif\shell\open\command@ C:\Program Files\QuickTime\QuickTimePlayer.exe "%1"
Reg HKLM\SOFTWARE\Classes\QuickTime.gsm@ GSM Audio
Reg HKLM\SOFTWARE\Classes\QuickTime.gsm\DefaultIcon
Reg HKLM\SOFTWARE\Classes\QuickTime.gsm\DefaultIcon@ C:\Program Files\QuickTime\QuickTimePlayer.exe,-130
Reg HKLM\SOFTWARE\Classes\QuickTime.gsm\shell
Reg HKLM\SOFTWARE\Classes\QuickTime.gsm\shell@ open
Reg HKLM\SOFTWARE\Classes\QuickTime.gsm\shell\open
Reg HKLM\SOFTWARE\Classes\QuickTime.gsm\shell\open\command
Reg HKLM\SOFTWARE\Classes\QuickTime.gsm\shell\open\command@ C:\Program Files\QuickTime\QuickTimePlayer.exe "%1"
Reg HKLM\SOFTWARE\Classes\QuickTime.jp2@ JPEG 2000 Image
Reg HKLM\SOFTWARE\Classes\QuickTime.jp2\DefaultIcon
Reg HKLM\SOFTWARE\Classes\QuickTime.jp2\DefaultIcon@ C:\Program Files\QuickTime\PictureViewer.exe,-143
Reg HKLM\SOFTWARE\Classes\QuickTime.jp2\shell
Reg HKLM\SOFTWARE\Classes\QuickTime.jp2\shell@ open
Reg HKLM\SOFTWARE\Classes\QuickTime.jp2\shell\open
Reg HKLM\SOFTWARE\Classes\QuickTime.jp2\shell\open\command
Reg HKLM\SOFTWARE\Classes\QuickTime.jp2\shell\open\command@ C:\Program Files\QuickTime\PictureViewer.exe "%1"
Reg HKLM\SOFTWARE\Classes\QuickTime.jpe@ JPEG Image
Reg HKLM\SOFTWARE\Classes\QuickTime.jpe\DefaultIcon
Reg HKLM\SOFTWARE\Classes\QuickTime.jpe\DefaultIcon@ C:\Program Files\QuickTime\PictureViewer.exe,-130
Reg HKLM\SOFTWARE\Classes\QuickTime.jpe\shell
Reg HKLM\SOFTWARE\Classes\QuickTime.jpe\shell@ open
Reg HKLM\SOFTWARE\Classes\QuickTime.jpe\shell\open
Reg HKLM\SOFTWARE\Classes\QuickTime.jpe\shell\open\command
Reg HKLM\SOFTWARE\Classes\QuickTime.jpe\shell\open\command@ C:\Program Files\QuickTime\PictureViewer.exe "%1"
Reg HKLM\SOFTWARE\Classes\QuickTime.jpeg@ JPEG Image
Reg HKLM\SOFTWARE\Classes\QuickTime.jpeg\DefaultIcon
Reg HKLM\SOFTWARE\Classes\QuickTime.jpeg\DefaultIcon@ C:\Program Files\QuickTime\PictureViewer.exe,-133
Reg HKLM\SOFTWARE\Classes\QuickTime.jpeg\shell
Reg HKLM\SOFTWARE\Classes\QuickTime.jpeg\shell@ open
Reg HKLM\SOFTWARE\Classes\QuickTime.jpeg\shell\open
Reg HKLM\SOFTWARE\Classes\QuickTime.jpeg\shell\open\command
Reg HKLM\SOFTWARE\Classes\QuickTime.jpeg\shell\open\command@ C:\Program Files\QuickTime\PictureViewer.exe "%1"
Reg HKLM\SOFTWARE\Classes\QuickTime.jpg@ JPEG Image
Reg HKLM\SOFTWARE\Classes\QuickTime.jpg\DefaultIcon
Reg HKLM\SOFTWARE\Classes\QuickTime.jpg\DefaultIcon@ C:\Program Files\QuickTime\PictureViewer.exe,-133
Reg HKLM\SOFTWARE\Classes\QuickTime.jpg\shell
Reg HKLM\SOFTWARE\Classes\QuickTime.jpg\shell@ open
Reg HKLM\SOFTWARE\Classes\QuickTime.jpg\shell\open
Reg HKLM\SOFTWARE\Classes\QuickTime.jpg\shell\open\command
Reg HKLM\SOFTWARE\Classes\QuickTime.jpg\shell\open\command@ C:\Program Files\QuickTime\PictureViewer.exe "%1"
Reg HKLM\SOFTWARE\Classes\QuickTime.kar@ MIDI
Reg HKLM\SOFTWARE\Classes\QuickTime.kar\DefaultIcon
Reg HKLM\SOFTWARE\Classes\QuickTime.kar\DefaultIcon@ C:\Program Files\QuickTime\QuickTimePlayer.exe,-130
Reg HKLM\SOFTWARE\Classes\QuickTime.kar\shell
Reg HKLM\SOFTWARE\Classes\QuickTime.kar\shell@ open
Reg HKLM\SOFTWARE\Classes\QuickTime.kar\shell\open
Reg HKLM\SOFTWARE\Classes\QuickTime.kar\shell\open\command
Reg HKLM\SOFTWARE\Classes\QuickTime.kar\shell\open\command@ C:\Program Files\QuickTime\QuickTimePlayer.exe "%1"
Reg HKLM\SOFTWARE\Classes\QuickTime.m15@ MPEG video/audio stream
Reg HKLM\SOFTWARE\Classes\QuickTime.m15\DefaultIcon
Reg HKLM\SOFTWARE\Classes\QuickTime.m15\DefaultIcon@ C:\Program Files\QuickTime\QuickTimePlayer.exe,-130
Reg HKLM\SOFTWARE\Classes\QuickTime.m15\shell
Reg HKLM\SOFTWARE\Classes\QuickTime.m15\shell@ open
Reg HKLM\SOFTWARE\Classes\QuickTime.m15\shell\open
Reg HKLM\SOFTWARE\Classes\QuickTime.m15\shell\open\command
Reg HKLM\SOFTWARE\Classes\QuickTime.m15\shell\open\command@ C:\Program Files\QuickTime\QuickTimePlayer.exe "%1"
Reg HKLM\SOFTWARE\Classes\QuickTime.m1a@ MPEG video/audio stream
Reg HKLM\SOFTWARE\Classes\QuickTime.m1a\DefaultIcon
Reg HKLM\SOFTWARE\Classes\QuickTime.m1a\DefaultIcon@ C:\Program Files\QuickTime\QuickTimePlayer.exe,-130
Reg HKLM\SOFTWARE\Classes\QuickTime.m1a\shell
Reg HKLM\SOFTWARE\Classes\QuickTime.m1a\shell@ open
Reg HKLM\SOFTWARE\Classes\QuickTime.m1a\shell\open
Reg HKLM\SOFTWARE\Classes\QuickTime.m1a\shell\open\command
Reg HKLM\SOFTWARE\Classes\QuickTime.m1a\shell\open\command@ C:\Program Files\QuickTime\QuickTimePlayer.exe "%1"
Reg HKLM\SOFTWARE\Classes\QuickTime.m1s@ MPEG video/audio stream
Reg HKLM\SOFTWARE\Classes\QuickTime.m1s\DefaultIcon
Reg HKLM\SOFTWARE\Classes\QuickTime.m1s\DefaultIcon@ C:\Program Files\QuickTime\QuickTimePlayer.exe,-130
Reg HKLM\SOFTWARE\Classes\QuickTime.m1s\shell
Reg HKLM\SOFTWARE\Classes\QuickTime.m1s\shell@ open
Reg HKLM\SOFTWARE\Classes\QuickTime.m1s\shell\open
Reg HKLM\SOFTWARE\Classes\QuickTime.m1s\shell\open\command
Reg HKLM\SOFTWARE\Classes\QuickTime.m1s\shell\open\command@ C:\Program Files\QuickTime\QuickTimePlayer.exe "%1"
Reg HKLM\SOFTWARE\Classes\QuickTime.m1v@ MPEG video/audio stream
Reg HKLM\SOFTWARE\Classes\QuickTime.m1v\DefaultIcon
Reg HKLM\SOFTWARE\Classes\QuickTime.m1v\DefaultIcon@ C:\Program Files\QuickTime\QuickTimePlayer.exe,-130
Reg HKLM\SOFTWARE\Classes\QuickTime.m1v\shell
Reg HKLM\SOFTWARE\Classes\QuickTime.m1v\shell@ open
Reg HKLM\SOFTWARE\Classes\QuickTime.m1v\shell\open
Reg HKLM\SOFTWARE\Classes\QuickTime.m1v\shell\open\command
Reg HKLM\SOFTWARE\Classes\QuickTime.m1v\shell\open\command@ C:\Program Files\QuickTime\QuickTimePlayer.exe "%1"
Reg HKLM\SOFTWARE\Classes\QuickTime.m3u@ SMIL
Reg HKLM\SOFTWARE\Classes\QuickTime.m3u\DefaultIcon
Reg HKLM\SOFTWARE\Classes\QuickTime.m3u\DefaultIcon@ C:\Program Files\QuickTime\QuickTimePlayer.exe,-130
Reg HKLM\SOFTWARE\Classes\QuickTime.m3u\shell
Reg HKLM\SOFTWARE\Classes\QuickTime.m3u\shell@ open
Reg HKLM\SOFTWARE\Classes\QuickTime.m3u\shell\open
Reg HKLM\SOFTWARE\Classes\QuickTime.m3u\shell\open\command
Reg HKLM\SOFTWARE\Classes\QuickTime.m3u\shell\open\command@ C:\Program Files\QuickTime\QuickTimePlayer.exe "%1"
Reg HKLM\SOFTWARE\Classes\QuickTime.m3url@ SMIL
Reg HKLM\SOFTWARE\Classes\QuickTime.m3url\DefaultIcon
Reg HKLM\SOFTWARE\Classes\QuickTime.m3url\DefaultIcon@ C:\Program Files\QuickTime\QuickTimePlayer.exe,-130
Reg HKLM\SOFTWARE\Classes\QuickTime.m3url\shell
Reg HKLM\SOFTWARE\Classes\QuickTime.m3url\shell@ open
Reg HKLM\SOFTWARE\Classes\QuickTime.m3url\shell\open
Reg HKLM\SOFTWARE\Classes\QuickTime.m3url\shell\open\command
Reg HKLM\SOFTWARE\Classes\QuickTime.m3url\shell\open\command@ C:\Program Files\QuickTime\QuickTimePlayer.exe "%1"
Reg HKLM\SOFTWARE\Classes\QuickTime.m4a@ AAC audio
Reg HKLM\SOFTWARE\Classes\QuickTime.m4a\DefaultIcon
Reg HKLM\SOFTWARE\Classes\QuickTime.m4a\DefaultIcon@ C:\Program Files\QuickTime\QuickTimePlayer.exe,-137
Reg HKLM\SOFTWARE\Classes\QuickTime.m4a\shell
Reg HKLM\SOFTWARE\Classes\QuickTime.m4a\shell@ open
Reg HKLM\SOFTWARE\Classes\QuickTime.m4a\shell\open
Reg HKLM\SOFTWARE\Classes\QuickTime.m4a\shell\open\command
Reg HKLM\SOFTWARE\Classes\QuickTime.m4a\shell\open\command@ C:\Program Files\QuickTime\QuickTimePlayer.exe "%1"
Reg HKLM\SOFTWARE\Classes\QuickTime.m4b@ AAC audio book
Reg HKLM\SOFTWARE\Classes\QuickTime.m4b\DefaultIcon
Reg HKLM\SOFTWARE\Classes\QuickTime.m4b\DefaultIcon@ C:\Program Files\QuickTime\QuickTimePlayer.exe,-137
Reg HKLM\SOFTWARE\Classes\QuickTime.m4b\shell
Reg HKLM\SOFTWARE\Classes\QuickTime.m4b\shell@ open
Reg HKLM\SOFTWARE\Classes\QuickTime.m4b\shell\open
Reg HKLM\SOFTWARE\Classes\QuickTime.m4b\shell\open\command
Reg HKLM\SOFTWARE\Classes\QuickTime.m4b\shell\open\command@ C:\Program Files\QuickTime\QuickTimePlayer.exe "%1"
Reg HKLM\SOFTWARE\Classes\QuickTime.m4p@ AAC audio (protected)
Reg HKLM\SOFTWARE\Classes\QuickTime.m4p\DefaultIcon
Reg HKLM\SOFTWARE\Classes\QuickTime.m4p\DefaultIcon@ C:\Program Files\QuickTime\QuickTimePlayer.exe,-137
Reg HKLM\SOFTWARE\Classes\QuickTime.m4p\shell
Reg HKLM\SOFTWARE\Classes\QuickTime.m4p\shell@ open
Reg HKLM\SOFTWARE\Classes\QuickTime.m4p\shell\open
Reg HKLM\SOFTWARE\Classes\QuickTime.m4p\shell\open\command
Reg HKLM\SOFTWARE\Classes\QuickTime.m4p\shell\open\command@ C:\Program Files\QuickTime\QuickTimePlayer.exe "%1"
Reg HKLM\SOFTWARE\Classes\QuickTime.m4v@ MPEG-4 video
Reg HKLM\SOFTWARE\Classes\QuickTime.m4v\DefaultIcon
Reg HKLM\SOFTWARE\Classes\QuickTime.m4v\DefaultIcon@ C:\Program Files\QuickTime\QuickTimePlayer.exe,-137
Reg HKLM\SOFTWARE\Classes\QuickTime.m4v\shell
Reg HKLM\SOFTWARE\Classes\QuickTime.m4v\shell@ open
Reg HKLM\SOFTWARE\Classes\QuickTime.m4v\shell\open
Reg HKLM\SOFTWARE\Classes\QuickTime.m4v\shell\open\command
Reg HKLM\SOFTWARE\Classes\QuickTime.m4v\shell\open\command@ C:\Program Files\QuickTime\QuickTimePlayer.exe "%1"
Reg HKLM\SOFTWARE\Classes\QuickTime.m75@ MPEG video/audio stream
Reg HKLM\SOFTWARE\Classes\QuickTime.m75\DefaultIcon
Reg HKLM\SOFTWARE\Classes\QuickTime.m75\DefaultIcon@ C:\Program Files\QuickTime\QuickTimePlayer.exe,-130
Reg HKLM\SOFTWARE\Classes\QuickTime.m75\shell
Reg HKLM\SOFTWARE\Classes\QuickTime.m75\shell@ open
Reg HKLM\SOFTWARE\Classes\QuickTime.m75\shell\open
Reg HKLM\SOFTWARE\Classes\QuickTime.m75\shell\open\command
Reg HKLM\SOFTWARE\Classes\QuickTime.m75\shell\open\command@ C:\Program Files\QuickTime\QuickTimePlayer.exe "%1"
Reg HKLM\SOFTWARE\Classes\QuickTime.mac@ MacPaint Image
Reg HKLM\SOFTWARE\Classes\QuickTime.mac\DefaultIcon
Reg HKLM\SOFTWARE\Classes\QuickTime.mac\DefaultIcon@ C:\Program Files\QuickTime\PictureViewer.exe,-134
Reg HKLM\SOFTWARE\Classes\QuickTime.mac\shell
Reg HKLM\SOFTWARE\Classes\QuickTime.mac\shell@ open
Reg HKLM\SOFTWARE\Classes\QuickTime.mac\shell\open
Reg HKLM\SOFTWARE\Classes\QuickTime.mac\shell\open\command
Reg HKLM\SOFTWARE\Classes\QuickTime.mac\shell\open\command@ C:\Program Files\QuickTime\PictureViewer.exe "%1"
Reg HKLM\SOFTWARE\Classes\QuickTime.mid@ MIDI
Reg HKLM\SOFTWARE\Classes\QuickTime.mid\DefaultIcon
Reg HKLM\SOFTWARE\Classes\QuickTime.mid\DefaultIcon@ C:\Program Files\QuickTime\QuickTimePlayer.exe,-142
Reg HKLM\SOFTWARE\Classes\QuickTime.mid\shell
Reg HKLM\SOFTWARE\Classes\QuickTime.mid\shell@ open
Reg HKLM\SOFTWARE\Classes\QuickTime.mid\shell\open
Reg HKLM\SOFTWARE\Classes\QuickTime.mid\shell\open\command
Reg HKLM\SOFTWARE\Classes\QuickTime.mid\shell\open\command@ C:\Program Files\QuickTime\QuickTimePlayer.exe "%1"
Reg HKLM\SOFTWARE\Classes\QuickTime.midi@ MIDI
Reg HKLM\SOFTWARE\Classes\QuickTime.midi\DefaultIcon
Reg HKLM\SOFTWARE\Classes\QuickTime.midi\DefaultIcon@ C:\Program Files\QuickTime\QuickTimePlayer.exe,-130
Reg HKLM\SOFTWARE\Classes\QuickTime.midi\shell
Reg HKLM\SOFTWARE\Classes\QuickTime.midi\shell@ open
Reg HKLM\SOFTWARE\Classes\QuickTime.midi\shell\open
Reg HKLM\SOFTWARE\Classes\QuickTime.midi\shell\open\command
Reg HKLM\SOFTWARE\Classes\QuickTime.midi\shell\open\command@ C:\Program Files\QuickTime\QuickTimePlayer.exe "%1"
Reg HKLM\SOFTWARE\Classes\QuickTime.mov@ QuickTime Movie
Reg HKLM\SOFTWARE\Classes\QuickTime.mov\DefaultIcon
Reg HKLM\SOFTWARE\Classes\QuickTime.mov\DefaultIcon@ C:\Program Files\QuickTime\QuickTimePlayer.exe,-137
Reg HKLM\SOFTWARE\Classes\QuickTime.mov\shell
Reg HKLM\SOFTWARE\Classes\QuickTime.mov\shell@ open
Reg HKLM\SOFTWARE\Classes\QuickTime.mov\shell\open
Reg HKLM\SOFTWARE\Classes\QuickTime.mov\shell\open\command
Reg HKLM\SOFTWARE\Classes\QuickTime.mov\shell\open\command@ C:\Program Files\QuickTime\QuickTimePlayer.exe "%1"
Reg HKLM\SOFTWARE\Classes\QuickTime.mp2@ MPEG video/audio stream
Reg HKLM\SOFTWARE\Classes\QuickTime.mp2\DefaultIcon
Reg HKLM\SOFTWARE\Classes\QuickTime.mp2\DefaultIcon@ C:\Program Files\QuickTime\QuickTimePlayer.exe,-130
Reg HKLM\SOFTWARE\Classes\QuickTime.mp2\shell
Reg HKLM\SOFTWARE\Classes\QuickTime.mp2\shell@ open
Reg HKLM\SOFTWARE\Classes\QuickTime.mp2\shell\open
Reg HKLM\SOFTWARE\Classes\QuickTime.mp2\shell\open\command
Reg HKLM\SOFTWARE\Classes\QuickTime.mp2\shell\open\command@ C:\Program Files\QuickTime\QuickTimePlayer.exe "%1"
Reg HKLM\SOFTWARE\Classes\QuickTime.mp3@ MPEG Layer-3 Audio
Reg HKLM\SOFTWARE\Classes\QuickTime.mp3\DefaultIcon
Reg HKLM\SOFTWARE\Classes\QuickTime.mp3\DefaultIcon@ C:\Program Files\QuickTime\QuickTimePlayer.exe,-130
Reg HKLM\SOFTWARE\Classes\QuickTime.mp3\shell
Reg HKLM\SOFTWARE\Classes\QuickTime.mp3\shell@ open
Reg HKLM\SOFTWARE\Classes\QuickTime.mp3\shell\open
Reg HKLM\SOFTWARE\Classes\QuickTime.mp3\shell\open\command
Reg HKLM\SOFTWARE\Classes\QuickTime.mp3\shell\open\command@ C:\Program Files\QuickTime\QuickTimePlayer.exe "%1"
Reg HKLM\SOFTWARE\Classes\QuickTime.mp4@ MPEG-4 Movie
Reg HKLM\SOFTWARE\Classes\QuickTime.mp4\DefaultIcon
Reg HKLM\SOFTWARE\Classes\QuickTime.mp4\DefaultIcon@ C:\Program Files\QuickTime\QuickTimePlayer.exe,-143
Reg HKLM\SOFTWARE\Classes\QuickTime.mp4\shell
Reg HKLM\SOFTWARE\Classes\QuickTime.mp4\shell@ open
Reg HKLM\SOFTWARE\Classes\QuickTime.mp4\shell\open
Reg HKLM\SOFTWARE\Classes\QuickTime.mp4\shell\open\command
Reg HKLM\SOFTWARE\Classes\QuickTime.mp4\shell\open\command@ C:\Program Files\QuickTime\QuickTimePlayer.exe "%1"
Reg HKLM\SOFTWARE\Classes\QuickTime.mpa@ MPEG video/audio stream
Reg HKLM\SOFTWARE\Classes\QuickTime.mpa\DefaultIcon
Reg HKLM\SOFTWARE\Classes\QuickTime.mpa\DefaultIcon@ C:\Program Files\QuickTime\QuickTimePlayer.exe,-130
Reg HKLM\SOFTWARE\Classes\QuickTime.mpa\shell
Reg HKLM\SOFTWARE\Classes\QuickTime.mpa\shell@ open
Reg HKLM\SOFTWARE\Classes\QuickTime.mpa\shell\open
Reg HKLM\SOFTWARE\Classes\QuickTime.mpa\shell\open\command
Reg HKLM\SOFTWARE\Classes\QuickTime.mpa\shell\open\command@ C:\Program Files\QuickTime\QuickTimePlayer.exe "%1"
Reg HKLM\SOFTWARE\Classes\QuickTime.mpeg@ MPEG video/audio stream
Reg HKLM\SOFTWARE\Classes\QuickTime.mpeg\DefaultIcon
Reg HKLM\SOFTWARE\Classes\QuickTime.mpeg\DefaultIcon@ C:\Program Files\QuickTime\QuickTimePlayer.exe,-130
Reg HKLM\SOFTWARE\Classes\QuickTime.mpeg\shell
Reg HKLM\SOFTWARE\Classes\QuickTime.mpeg\shell@ open
Reg HKLM\SOFTWARE\Classes\QuickTime.mpeg\shell\open
Reg HKLM\SOFTWARE\Classes\QuickTime.mpeg\shell\open\command
Reg HKLM\SOFTWARE\Classes\QuickTime.mpeg\shell\open\command@ C:\Program Files\QuickTime\QuickTimePlayer.exe "%1"
Reg HKLM\SOFTWARE\Classes\QuickTime.mpg@ MPEG video/audio stream
Reg HKLM\SOFTWARE\Classes\QuickTime.mpg\DefaultIcon
Reg HKLM\SOFTWARE\Classes\QuickTime.mpg\DefaultIcon@ C:\Program Files\QuickTime\QuickTimePlayer.exe,-130
Reg HKLM\SOFTWARE\Classes\QuickTime.mpg\shell
Reg HKLM\SOFTWARE\Classes\QuickTime.mpg\shell@ open
Reg HKLM\SOFTWARE\Classes\QuickTime.mpg\shell\open
Reg HKLM\SOFTWARE\Classes\QuickTime.mpg\shell\open\command
Reg HKLM\SOFTWARE\Classes\QuickTime.mpg\shell\open\command@ C:\Program Files\QuickTime\QuickTimePlayer.exe "%1"
Reg HKLM\SOFTWARE\Classes\QuickTime.mpm@ MPEG video/audio stream
Reg HKLM\SOFTWARE\Classes\QuickTime.mpm\DefaultIcon
Reg HKLM\SOFTWARE\Classes\QuickTime.mpm\DefaultIcon@ C:\Program Files\QuickTime\QuickTimePlayer.exe,-130
Reg HKLM\SOFTWARE\Classes\QuickTime.mpm\shell
Reg HKLM\SOFTWARE\Classes\QuickTime.mpm\shell@ open
Reg HKLM\SOFTWARE\Classes\QuickTime.mpm\shell\open
Reg HKLM\SOFTWARE\Classes\QuickTime.mpm\shell\open\command
Reg HKLM\SOFTWARE\Classes\QuickTime.mpm\shell\open\command@ C:\Program Files\QuickTime\QuickTimePlayer.exe "%1"
Reg HKLM\SOFTWARE\Classes\QuickTime.mpv@ MPEG video/audio stream
Reg HKLM\SOFTWARE\Classes\QuickTime.mpv\DefaultIcon
Reg HKLM\SOFTWARE\Classes\QuickTime.mpv\DefaultIcon@ C:\Program Files\QuickTime\QuickTimePlayer.exe,-130
Reg HKLM\SOFTWARE\Classes\QuickTime.mpv\shell
Reg HKLM\SOFTWARE\Classes\QuickTime.mpv\shell@ open
Reg HKLM\SOFTWARE\Classes\QuickTime.mpv\shell\open
Reg HKLM\SOFTWARE\Classes\QuickTime.mpv\shell\open\command
Reg HKLM\SOFTWARE\Classes\QuickTime.mpv\shell\open\command@ C:\Program Files\QuickTime\QuickTimePlayer.exe "%1"
Reg HKLM\SOFTWARE\Classes\QuickTime.mqv@ QuickTime Movie
Reg HKLM\SOFTWARE\Classes\QuickTime.mqv\DefaultIcon
Reg HKLM\SOFTWARE\Classes\QuickTime.mqv\DefaultIcon@ C:\Program Files\QuickTime\QuickTimePlayer.exe,-130
Reg HKLM\SOFTWARE\Classes\QuickTime.mqv\shell
Reg HKLM\SOFTWARE\Classes\QuickTime.mqv\shell@ open
Reg HKLM\SOFTWARE\Classes\QuickTime.mqv\shell\open
Reg HKLM\SOFTWARE\Classes\QuickTime.mqv\shell\open\command
Reg HKLM\SOFTWARE\Classes\QuickTime.mqv\shell\open\command@ C:\Program Files\QuickTime\QuickTimePlayer.exe "%1"
Reg HKLM\SOFTWARE\Classes\QuickTime.pct@ PICT Image
Reg HKLM\SOFTWARE\Classes\QuickTime.pct\DefaultIcon
Reg HKLM\SOFTWARE\Classes\QuickTime.pct\DefaultIcon@ C:\Program Files\QuickTime\PictureViewer.exe,-136
Reg HKLM\SOFTWARE\Classes\QuickTime.pct\shell
Reg HKLM\SOFTWARE\Classes\QuickTime.pct\shell@ open
Reg HKLM\SOFTWARE\Classes\QuickTime.pct\shell\open
Reg HKLM\SOFTWARE\Classes\QuickTime.pct\shell\open\command
Reg HKLM\SOFTWARE\Classes\QuickTime.pct\shell\open\command@ C:\Program Files\QuickTime\PictureViewer.exe "%1"
Reg HKLM\SOFTWARE\Classes\QuickTime.pic@ PICT Image
Reg HKLM\SOFTWARE\Classes\QuickTime.pic\DefaultIcon
Reg HKLM\SOFTWARE\Classes\QuickTime.pic\DefaultIcon@ C:\Program Files\QuickTime\PictureViewer.exe,-136
Reg HKLM\SOFTWARE\Classes\QuickTime.pic\shell
Reg HKLM\SOFTWARE\Classes\QuickTime.pic\shell@ open
Reg HKLM\SOFTWARE\Classes\QuickTime.pic\shell\open
Reg HKLM\SOFTWARE\Classes\QuickTime.pic\shell\open\command
Reg HKLM\SOFTWARE\Classes\QuickTime.pic\shell\open\command@ C:\Program Files\QuickTime\PictureViewer.exe "%1"
Reg HKLM\SOFTWARE\Classes\QuickTime.pict@ PICT Image
Reg HKLM\SOFTWARE\Classes\QuickTime.pict\DefaultIcon
Reg HKLM\SOFTWARE\Classes\QuickTime.pict\DefaultIcon@ C:\Program Files\QuickTime\PictureViewer.exe,-136
Reg HKLM\SOFTWARE\Classes\QuickTime.pict\shell
Reg HKLM\SOFTWARE\Classes\QuickTime.pict\shell@ open
Reg HKLM\SOFTWARE\Classes\QuickTime.pict\shell\open
Reg HKLM\SOFTWARE\Classes\QuickTime.pict\shell\open\command
Reg HKLM\SOFTWARE\Classes\QuickTime.pict\shell\open\command@ C:\Program Files\QuickTime\PictureViewer.exe "%1"
Reg HKLM\SOFTWARE\Classes\QuickTime.png@ PNG Image
Reg HKLM\SOFTWARE\Classes\QuickTime.png\DefaultIcon
Reg HKLM\SOFTWARE\Classes\QuickTime.png\DefaultIcon@ C:\Program Files\QuickTime\PictureViewer.exe,-137
Reg HKLM\SOFTWARE\Classes\QuickTime.png\shell
Reg HKLM\SOFTWARE\Classes\QuickTime.png\shell@ open
Reg HKLM\SOFTWARE\Classes\QuickTime.png\shell\open
Reg HKLM\SOFTWARE\Classes\QuickTime.png\shell\open\command
Reg HKLM\SOFTWARE\Classes\QuickTime.png\shell\open\command@ C:\Program Files\QuickTime\PictureViewer.exe "%1"
Reg HKLM\SOFTWARE\Classes\QuickTime.pnt@ MacPaint Image
Reg HKLM\SOFTWARE\Classes\QuickTime.pnt\DefaultIcon
Reg HKLM\SOFTWARE\Classes\QuickTime.pnt\DefaultIcon@ C:\Program Files\QuickTime\PictureViewer.exe,-130
Reg HKLM\SOFTWARE\Classes\QuickTime.pnt\shell
Reg HKLM\SOFTWARE\Classes\QuickTime.pnt\shell@ open
Reg HKLM\SOFTWARE\Classes\QuickTime.pnt\shell\open
Reg HKLM\SOFTWARE\Classes\QuickTime.pnt\shell\open\command
Reg HKLM\SOFTWARE\Classes\QuickTime.pnt\shell\open\command@ C:\Program Files\QuickTime\PictureViewer.exe "%1"
Reg HKLM\SOFTWARE\Classes\QuickTime.pntg@ MacPaint Image
Reg HKLM\SOFTWARE\Classes\QuickTime.pntg\DefaultIcon
Reg HKLM\SOFTWARE\Classes\QuickTime.pntg\DefaultIcon@ C:\Program Files\QuickTime\PictureViewer.exe,-134
Reg HKLM\SOFTWARE\Classes\QuickTime.pntg\shell
Reg HKLM\SOFTWARE\Classes\QuickTime.pntg\shell@ open
Reg HKLM\SOFTWARE\Classes\QuickTime.pntg\shell\open
Reg HKLM\SOFTWARE\Classes\QuickTime.pntg\shell\open\command
Reg HKLM\SOFTWARE\Classes\QuickTime.pntg\shell\open\command@ C:\Program Files\QuickTime\PictureViewer.exe "%1"
Reg HKLM\SOFTWARE\Classes\QuickTime.psd@ Photoshop Image
Reg HKLM\SOFTWARE\Classes\QuickTime.psd\DefaultIcon
Reg HKLM\SOFTWARE\Classes\QuickTime.psd\DefaultIcon@ C:\Program Files\QuickTime\PictureViewer.exe,-135
Reg HKLM\SOFTWARE\Classes\QuickTime.psd\shell
Reg HKLM\SOFTWARE\Classes\QuickTime.psd\shell@ open
Reg HKLM\SOFTWARE\Classes\QuickTime.psd\shell\open
Reg HKLM\SOFTWARE\Classes\QuickTime.psd\shell\open\command
Reg HKLM\SOFTWARE\Classes\QuickTime.psd\shell\open\command@ C:\Program Files\QuickTime\PictureViewer.exe "%1"
Reg HKLM\SOFTWARE\Classes\QuickTime.qcp@ QCP Audio
Reg HKLM\SOFTWARE\Classes\QuickTime.qcp\DefaultIcon
Reg HKLM\SOFTWARE\Classes\QuickTime.qcp\DefaultIcon@ C:\Program Files\QuickTime\QuickTimePlayer.exe,-130
Reg HKLM\SOFTWARE\Classes\QuickTime.qcp\shell
Reg HKLM\SOFTWARE\Classes\QuickTime.qcp\shell@ open
Reg HKLM\SOFTWARE\Classes\QuickTime.qcp\shell\open
Reg HKLM\SOFTWARE\Classes\QuickTime.qcp\shell\open\command
Reg HKLM\SOFTWARE\Classes\QuickTime.qcp\shell\open\command@ C:\Program Files\QuickTime\QuickTimePlayer.exe "%1"
Reg HKLM\SOFTWARE\Classes\QuickTime.qht\DefaultIcon
Reg HKLM\SOFTWARE\Classes\QuickTime.qht\DefaultIcon@ C:\Program Files\QuickTime\QuickTimePlayer.exe,-130
Reg HKLM\SOFTWARE\Classes\QuickTime.qht\shell
Reg HKLM\SOFTWARE\Classes\QuickTime.qht\shell@ open
Reg HKLM\SOFTWARE\Classes\QuickTime.qht\shell\open
Reg HKLM\SOFTWARE\Classes\QuickTime.qht\shell\open\command
Reg HKLM\SOFTWARE\Classes\QuickTime.qht\shell\open\command@ C:\Program Files\QuickTime\QuickTimePlayer.exe "%1"
Reg HKLM\SOFTWARE\Classes\QuickTime.qhtm\DefaultIcon
Reg HKLM\SOFTWARE\Classes\QuickTime.qhtm\DefaultIcon@ C:\Program Files\QuickTime\QuickTimePlayer.exe,-130
Reg HKLM\SOFTWARE\Classes\QuickTime.qhtm\shell
Reg HKLM\SOFTWARE\Classes\QuickTime.qhtm\shell@ open
Reg HKLM\SOFTWARE\Classes\QuickTime.qhtm\shell\open
Reg HKLM\SOFTWARE\Classes\QuickTime.qhtm\shell\open\command
Reg HKLM\SOFTWARE\Classes\QuickTime.qhtm\shell\open\command@ C:\Program Files\QuickTime\QuickTimePlayer.exe "%1"
Reg HKLM\SOFTWARE\Classes\QuickTime.qt@ QuickTime Movie
Reg HKLM\SOFTWARE\Classes\QuickTime.qt\DefaultIcon
Reg HKLM\SOFTWARE\Classes\QuickTime.qt\DefaultIcon@ C:\Program Files\QuickTime\QuickTimePlayer.exe,-137
Reg HKLM\SOFTWARE\Classes\QuickTime.qt\shell
Reg HKLM\SOFTWARE\Classes\QuickTime.qt\shell@ open
Reg HKLM\SOFTWARE\Classes\QuickTime.qt\shell\open
Reg HKLM\SOFTWARE\Classes\QuickTime.qt\shell\open\command
Reg HKLM\SOFTWARE\Classes\QuickTime.qt\shell\open\command@ C:\Program Files\QuickTime\QuickTimePlayer.exe "%1"
Reg HKLM\SOFTWARE\Classes\QuickTime.QTElementBehavior@ QuickTime Element Behavior
Reg HKLM\SOFTWARE\Classes\QuickTime.QTElementBehavior\CLSID
Reg HKLM\SOFTWARE\Classes\QuickTime.QTElementBehavior\CLSID@ {CB927D12-4FF7-4A9E-A169-56E4B8A75598}
Reg HKLM\SOFTWARE\Classes\QuickTime.QTElementBehavior\CurVer
Reg HKLM\SOFTWARE\Classes\QuickTime.QTElementBehavior\CurVer@ QuickTime.QTElementBehavior.1
Reg HKLM\SOFTWARE\Classes\QuickTime.QTElementBehavior.1@ QuickTime Element Behavior
Reg HKLM\SOFTWARE\Classes\QuickTime.QTElementBehavior.1\CLSID
Reg HKLM\SOFTWARE\Classes\QuickTime.QTElementBehavior.1\CLSID@ {CB927D12-4FF7-4A9E-A169-56E4B8A75598}
Reg HKLM\SOFTWARE\Classes\QuickTime.qti@ QuickTime Image
Reg HKLM\SOFTWARE\Classes\QuickTime.qti\DefaultIcon
Reg HKLM\SOFTWARE\Classes\QuickTime.qti\DefaultIcon@ C:\Program Files\QuickTime\PictureViewer.exe,-138
Reg HKLM\SOFTWARE\Classes\QuickTime.qti\shell
Reg HKLM\SOFTWARE\Classes\QuickTime.qti\shell@ open
Reg HKLM\SOFTWARE\Classes\QuickTime.qti\shell\open
Reg HKLM\SOFTWARE\Classes\QuickTime.qti\shell\open\command
Reg HKLM\SOFTWARE\Classes\QuickTime.qti\shell\open\command@ C:\Program Files\QuickTime\PictureViewer.exe "%1"
Reg HKLM\SOFTWARE\Classes\QuickTime.qtif@ QuickTime Image
Reg HKLM\SOFTWARE\Classes\QuickTime.qtif\DefaultIcon
Reg HKLM\SOFTWARE\Classes\QuickTime.qtif\DefaultIcon@ C:\Program Files\QuickTime\PictureViewer.exe,-138
Reg HKLM\SOFTWARE\Classes\QuickTime.qtif\shell
Reg HKLM\SOFTWARE\Classes\QuickTime.qtif\shell@ open
Reg HKLM\SOFTWARE\Classes\QuickTime.qtif\shell\open
Reg HKLM\SOFTWARE\Classes\QuickTime.qtif\shell\open\command
Reg HKLM\SOFTWARE\Classes\QuickTime.qtif\shell\open\command@ C:\Program Files\QuickTime\PictureViewer.exe "%1"
Reg HKLM\SOFTWARE\Classes\QuickTime.qtl@ QuickTime Movie
Reg HKLM\SOFTWARE\Classes\QuickTime.qtl\DefaultIcon
Reg HKLM\SOFTWARE\Classes\QuickTime.qtl\DefaultIcon@ C:\Program Files\QuickTime\QuickTimePlayer.exe,-137
Reg HKLM\SOFTWARE\Classes\QuickTime.qtl\shell
Reg HKLM\SOFTWARE\Classes\QuickTime.qtl\shell@ open
Reg HKLM\SOFTWARE\Classes\QuickTime.qtl\shell\open
Reg HKLM\SOFTWARE\Classes\QuickTime.qtl\shell\open\command
Reg HKLM\SOFTWARE\Classes\QuickTime.qtl\shell\open\command@ C:\Program Files\QuickTime\QuickTimePlayer.exe "%1"
Reg HKLM\SOFTWARE\Classes\QuickTime.QuickTime.9@ QuickTime Control Object
Reg HKLM\SOFTWARE\Classes\QuickTime.QuickTime.9\CLSID
Reg HKLM\SOFTWARE\Classes\QuickTime.QuickTime.9\CLSID@ {4063BE15-3B08-470D-A0D5-B37161CFFD69}
Reg HKLM\SOFTWARE\Classes\QuickTime.QuickTime.9\NotInsertable
Reg HKLM\SOFTWARE\Classes\QuickTime.rgb@ SGI Image
Reg HKLM\SOFTWARE\Classes\QuickTime.rgb\DefaultIcon
Reg HKLM\SOFTWARE\Classes\QuickTime.rgb\DefaultIcon@ C:\Program Files\QuickTime\PictureViewer.exe,-130
Reg HKLM\SOFTWARE\Classes\QuickTime.rgb\shell
Reg HKLM\SOFTWARE\Classes\QuickTime.rgb\shell@ open
Reg HKLM\SOFTWARE\Classes\QuickTime.rgb\shell\open
Reg HKLM\SOFTWARE\Classes\QuickTime.rgb\shell\open\command
Reg HKLM\SOFTWARE\Classes\QuickTime.rgb\shell\open\command@ C:\Program Files\QuickTime\PictureViewer.exe "%1"
Reg HKLM\SOFTWARE\Classes\QuickTime.rts@ Real Time Streaming Protocol
Reg HKLM\SOFTWARE\Classes\QuickTime.rts\DefaultIcon
Reg HKLM\SOFTWARE\Classes\QuickTime.rts\DefaultIcon@ C:\Program Files\QuickTime\QuickTimePlayer.exe,-130
Reg HKLM\SOFTWARE\Classes\QuickTime.rts\shell
Reg HKLM\SOFTWARE\Classes\QuickTime.rts\shell@ open
Reg HKLM\SOFTWARE\Classes\QuickTime.rts\shell\open
Reg HKLM\SOFTWARE\Classes\QuickTime.rts\shell\open\command
Reg HKLM\SOFTWARE\Classes\QuickTime.rts\shell\open\command@ C:\Program Files\QuickTime\QuickTimePlayer.exe "%1"
Reg HKLM\SOFTWARE\Classes\QuickTime.rtsp@ Real Time Streaming Protocol
Reg HKLM\SOFTWARE\Classes\QuickTime.rtsp\DefaultIcon
Reg HKLM\SOFTWARE\Classes\QuickTime.rtsp\DefaultIcon@ C:\Program Files\QuickTime\QuickTimePlayer.exe,-130
Reg HKLM\SOFTWARE\Classes\QuickTime.rtsp\shell
Reg HKLM\SOFTWARE\Classes\QuickTime.rtsp\shell@ open
Reg HKLM\SOFTWARE\Classes\QuickTime.rtsp\shell\open
Reg HKLM\SOFTWARE\Classes\QuickTime.rtsp\shell\open\command
Reg HKLM\SOFTWARE\Classes\QuickTime.rtsp\shell\open\command@ C:\Program Files\QuickTime\QuickTimePlayer.exe "%1"
Reg HKLM\SOFTWARE\Classes\QuickTime.sd2@ Sound Designer 2
Reg HKLM\SOFTWARE\Classes\QuickTime.sd2\DefaultIcon
Reg HKLM\SOFTWARE\Classes\QuickTime.sd2\DefaultIcon@ C:\Program Files\QuickTime\QuickTimePlayer.exe,-138
Reg HKLM\SOFTWARE\Classes\QuickTime.sd2\shell
Reg HKLM\SOFTWARE\Classes\QuickTime.sd2\shell@ open
Reg HKLM\SOFTWARE\Classes\QuickTime.sd2\shell\open
Reg HKLM\SOFTWARE\Classes\QuickTime.sd2\shell\open\command
Reg HKLM\SOFTWARE\Classes\QuickTime.sd2\shell\open\command@ C:\Program Files\QuickTime\QuickTimePlayer.exe "%1"
Reg HKLM\SOFTWARE\Classes\QuickTime.sdp@ Session Description Protocol
Reg HKLM\SOFTWARE\Classes\QuickTime.sdp\DefaultIcon
Reg HKLM\SOFTWARE\Classes\QuickTime.sdp\DefaultIcon@ C:\Program Files\QuickTime\QuickTimePlayer.exe,-130
Reg HKLM\SOFTWARE\Classes\QuickTime.sdp\shell
Reg HKLM\SOFTWARE\Classes\QuickTime.sdp\shell@ open
Reg HKLM\SOFTWARE\Classes\QuickTime.sdp\shell\open
Reg HKLM\SOFTWARE\Classes\QuickTime.sdp\shell\open\command
Reg HKLM\SOFTWARE\Classes\QuickTime.sdp\shell\open\command@ C:\Program Files\QuickTime\QuickTimePlayer.exe "%1"
Reg HKLM\SOFTWARE\Classes\QuickTime.sdv@ 3GPP Movie
Reg HKLM\SOFTWARE\Classes\QuickTime.sdv\DefaultIcon
Reg HKLM\SOFTWARE\Classes\QuickTime.sdv\DefaultIcon@ C:\Program Files\QuickTime\QuickTimePlayer.exe,-162
Reg HKLM\SOFTWARE\Classes\QuickTime.sdv\shell
Reg HKLM\SOFTWARE\Classes\QuickTime.sdv\shell@ open
Reg HKLM\SOFTWARE\Classes\QuickTime.sdv\shell\open
Reg HKLM\SOFTWARE\Classes\QuickTime.sdv\shell\open\command
Reg HKLM\SOFTWARE\Classes\QuickTime.sdv\shell\open\command@ C:\Program Files\QuickTime\QuickTimePlayer.exe "%1"
Reg HKLM\SOFTWARE\Classes\QuickTime.sgi@ SGI Image
Reg HKLM\SOFTWARE\Classes\QuickTime.sgi\DefaultIcon
Reg HKLM\SOFTWARE\Classes\QuickTime.sgi\DefaultIcon@ C:\Program Files\QuickTime\PictureViewer.exe,-139
Reg HKLM\SOFTWARE\Classes\QuickTime.sgi\shell
Reg HKLM\SOFTWARE\Classes\QuickTime.sgi\shell@ open
Reg HKLM\SOFTWARE\Classes\QuickTime.sgi\shell\open
Reg HKLM\SOFTWARE\Classes\QuickTime.sgi\shell\open\command
Reg HKLM\SOFTWARE\Classes\QuickTime.sgi\shell\open\command@ C:\Program Files\QuickTime\PictureViewer.exe "%1"
Reg HKLM\SOFTWARE\Classes\QuickTime.smf@ MIDI
Reg HKLM\SOFTWARE\Classes\QuickTime.smf\DefaultIcon
Reg HKLM\SOFTWARE\Classes\QuickTime.smf\DefaultIcon@ C:\Program Files\QuickTime\QuickTimePlayer.exe,-130
Reg HKLM\SOFTWARE\Classes\QuickTime.smf\shell
Reg HKLM\SOFTWARE\Classes\QuickTime.smf\shell@ open
Reg HKLM\SOFTWARE\Classes\QuickTime.smf\shell\open
Reg HKLM\SOFTWARE\Classes\QuickTime.smf\shell\open\command
Reg HKLM\SOFTWARE\Classes\QuickTime.smf\shell\open\command@ C:\Program Files\QuickTime\QuickTimePlayer.exe "%1"
Reg HKLM\SOFTWARE\Classes\QuickTime.smi@ SMIL
Reg HKLM\SOFTWARE\Classes\QuickTime.smi\DefaultIcon
Reg HKLM\SOFTWARE\Classes\QuickTime.smi\DefaultIcon@ C:\Program Files\QuickTime\QuickTimePlayer.exe,-141
Reg HKLM\SOFTWARE\Classes\QuickTime.smi\shell
Reg HKLM\SOFTWARE\Classes\QuickTime.smi\shell@ open
Reg HKLM\SOFTWARE\Classes\QuickTime.smi\shell\open
Reg HKLM\SOFTWARE\Classes\QuickTime.smi\shell\open\command
Reg HKLM\SOFTWARE\Classes\QuickTime.smi\shell\open\command@ C:\Program Files\QuickTime\QuickTimePlayer.exe "%1"
Reg HKLM\SOFTWARE\Classes\QuickTime.smil@ SMIL
Reg HKLM\SOFTWARE\Classes\QuickTime.smil\DefaultIcon
Reg HKLM\SOFTWARE\Classes\QuickTime.smil\DefaultIcon@ C:\Program Files\QuickTime\QuickTimePlayer.exe,-130
Reg HKLM\SOFTWARE\Classes\QuickTime.smil\shell
Reg HKLM\SOFTWARE\Classes\QuickTime.smil\shell@ open
Reg HKLM\SOFTWARE\Classes\QuickTime.smil\shell\open
Reg HKLM\SOFTWARE\Classes\QuickTime.smil\shell\open\command
Reg HKLM\SOFTWARE\Classes\QuickTime.smil\shell\open\command@ C:\Program Files\QuickTime\QuickTimePlayer.exe "%1"
Reg HKLM\SOFTWARE\Classes\QuickTime.sml@ SMIL
Reg HKLM\SOFTWARE\Classes\QuickTime.sml\DefaultIcon
Reg HKLM\SOFTWARE\Classes\QuickTime.sml\DefaultIcon@ C:\Program Files\QuickTime\QuickTimePlayer.exe,-130
Reg HKLM\SOFTWARE\Classes\QuickTime.sml\shell
Reg HKLM\SOFTWARE\Classes\QuickTime.sml\shell@ open
Reg HKLM\SOFTWARE\Classes\QuickTime.sml\shell\open
Reg HKLM\SOFTWARE\Classes\QuickTime.sml\shell\open\command
Reg HKLM\SOFTWARE\Classes\QuickTime.sml\shell\open\command@ C:\Program Files\QuickTime\QuickTimePlayer.exe "%1"
Reg HKLM\SOFTWARE\Classes\QuickTime.snd@ AU Audio
Reg HKLM\SOFTWARE\Classes\QuickTime.snd\DefaultIcon
Reg HKLM\SOFTWARE\Classes\QuickTime.snd\DefaultIcon@ C:\Program Files\QuickTime\QuickTimePlayer.exe,-130
Reg HKLM\SOFTWARE\Classes\QuickTime.snd\shell
Reg HKLM\SOFTWARE\Classes\QuickTime.snd\shell@ open
Reg HKLM\SOFTWARE\Classes\QuickTime.snd\shell\open
Reg HKLM\SOFTWARE\Classes\QuickTime.snd\shell\open\command
Reg HKLM\SOFTWARE\Classes\QuickTime.snd\shell\open\command@ C:\Program Files\QuickTime\QuickTimePlayer.exe "%1"
Reg HKLM\SOFTWARE\Classes\QuickTime.swa@ MPEG Layer-3 Audio
Reg HKLM\SOFTWARE\Classes\QuickTime.swa\DefaultIcon
Reg HKLM\SOFTWARE\Classes\QuickTime.swa\DefaultIcon@ C:\Program Files\QuickTime\QuickTimePlayer.exe,-130
Reg HKLM\SOFTWARE\Classes\QuickTime.swa\shell
Reg HKLM\SOFTWARE\Classes\QuickTime.swa\shell@ open
Reg HKLM\SOFTWARE\Classes\QuickTime.swa\shell\open
Reg HKLM\SOFTWARE\Classes\QuickTime.swa\shell\open\command
Reg HKLM\SOFTWARE\Classes\QuickTime.swa\shell\open\command@ C:\Program Files\QuickTime\QuickTimePlayer.exe "%1"
Reg HKLM\SOFTWARE\Classes\QuickTime.targa@ Truevision TGA Image
Reg HKLM\SOFTWARE\Classes\QuickTime.targa\DefaultIcon
Reg HKLM\SOFTWARE\Classes\QuickTime.targa\DefaultIcon@ C:\Program Files\QuickTime\PictureViewer.exe,-130
Reg HKLM\SOFTWARE\Classes\QuickTime.targa\shell
Reg HKLM\SOFTWARE\Classes\QuickTime.targa\shell@ open
Reg HKLM\SOFTWARE\Classes\QuickTime.targa\shell\open
Reg HKLM\SOFTWARE\Classes\QuickTime.targa\shell\open\command
Reg HKLM\SOFTWARE\Classes\QuickTime.targa\shell\open\command@ C:\Program Files\QuickTime\PictureViewer.exe "%1"
Reg HKLM\SOFTWARE\Classes\QuickTime.tga@ Truevision TGA Image
Reg HKLM\SOFTWARE\Classes\QuickTime.tga\DefaultIcon
Reg HKLM\SOFTWARE\Classes\QuickTime.tga\DefaultIcon@ C:\Program Files\QuickTime\PictureViewer.exe,-140
Reg HKLM\SOFTWARE\Classes\QuickTime.tga\shell
Reg HKLM\SOFTWARE\Classes\QuickTime.tga\shell@ open
Reg HKLM\SOFTWARE\Classes\QuickTime.tga\shell\open
Reg HKLM\SOFTWARE\Classes\QuickTime.tga\shell\open\command
Reg HKLM\SOFTWARE\Classes\QuickTime.tga\shell\open\command@ C:\Program Files\QuickTime\PictureViewer.exe "%1"
Reg HKLM\SOFTWARE\Classes\QuickTime.tif@ TIFF Image
Reg HKLM\SOFTWARE\Classes\QuickTime.tif\DefaultIcon
Reg HKLM\SOFTWARE\Classes\QuickTime.tif\DefaultIcon@ C:\Program Files\QuickTime\PictureViewer.exe,-141
Reg HKLM\SOFTWARE\Classes\QuickTime.tif\shell
Reg HKLM\SOFTWARE\Classes\QuickTime.tif\shell@ open
Reg HKLM\SOFTWARE\Classes\QuickTime.tif\shell\open
Reg HKLM\SOFTWARE\Classes\QuickTime.tif\shell\open\command
Reg HKLM\SOFTWARE\Classes\QuickTime.tif\shell\open\command@ C:\Program Files\QuickTime\PictureViewer.exe "%1"
Reg HKLM\SOFTWARE\Classes\QuickTime.tiff@ TIFF Image
Reg HKLM\SOFTWARE\Classes\QuickTime.tiff\DefaultIcon
Reg HKLM\SOFTWARE\Classes\QuickTime.tiff\DefaultIcon@ C:\Program Files\QuickTime\PictureViewer.exe,-141
Reg HKLM\SOFTWARE\Classes\QuickTime.tiff\shell
Reg HKLM\SOFTWARE\Classes\QuickTime.tiff\shell@ open
Reg HKLM\SOFTWARE\Classes\QuickTime.tiff\shell\open
Reg HKLM\SOFTWARE\Classes\QuickTime.tiff\shell\open\command
Reg HKLM\SOFTWARE\Classes\QuickTime.tiff\shell\open\command@ C:\Program Files\QuickTime\PictureViewer.exe "%1"
Reg HKLM\SOFTWARE\Classes\QuickTime.ulw@ AU Audio
Reg HKLM\SOFTWARE\Classes\QuickTime.ulw\DefaultIcon
Reg HKLM\SOFTWARE\Classes\QuickTime.ulw\DefaultIcon@ C:\Program Files\QuickTime\QuickTimePlayer.exe,-132
Reg HKLM\SOFTWARE\Classes\QuickTime.ulw\shell
Reg HKLM\SOFTWARE\Classes\QuickTime.ulw\shell@ open
Reg HKLM\SOFTWARE\Classes\QuickTime.ulw\shell\open
Reg HKLM\SOFTWARE\Classes\QuickTime.ulw\shell\open\command
Reg HKLM\SOFTWARE\Classes\QuickTime.ulw\shell\open\command@ C:\Program Files\QuickTime\QuickTimePlayer.exe "%1"
Reg HKLM\SOFTWARE\Classes\QuickTime.vfw@ Microsoft Video
Reg HKLM\SOFTWARE\Classes\QuickTime.vfw\DefaultIcon
Reg HKLM\SOFTWARE\Classes\QuickTime.vfw\DefaultIcon@ C:\Program Files\QuickTime\QuickTimePlayer.exe,-133
Reg HKLM\SOFTWARE\Classes\QuickTime.vfw\shell
Reg HKLM\SOFTWARE\Classes\QuickTime.vfw\shell@ open
Reg HKLM\SOFTWARE\Classes\QuickTime.vfw\shell\open
Reg HKLM\SOFTWARE\Classes\QuickTime.vfw\shell\open\command
Reg HKLM\SOFTWARE\Classes\QuickTime.vfw\shell\open\command@ C:\Program Files\QuickTime\QuickTimePlayer.exe "%1"
Reg HKLM\SOFTWARE\Classes\QuickTime.wav@ WAV Audio
Reg HKLM\SOFTWARE\Classes\QuickTime.wav\DefaultIcon
Reg HKLM\SOFTWARE\Classes\QuickTime.wav\DefaultIcon@ C:\Program Files\QuickTime\QuickTimePlayer.exe,-139
Reg HKLM\SOFTWARE\Classes\QuickTime.wav\shell
Reg HKLM\SOFTWARE\Classes\QuickTime.wav\shell@ open
Reg HKLM\SOFTWARE\Classes\QuickTime.wav\shell\open
Reg HKLM\SOFTWARE\Classes\QuickTime.wav\shell\open\command
Reg HKLM\SOFTWARE\Classes\QuickTime.wav\shell\open\command@ C:\Program Files\QuickTime\QuickTimePlayer.exe "%1"
Reg HKLM\SOFTWARE\Classes\QuickTimeCheckObject.QuickTimeCheck@ QuickTimeCheck Class
Reg HKLM\SOFTWARE\Classes\QuickTimeCheckObject.QuickTimeCheck\CLSID
Reg HKLM\SOFTWARE\Classes\QuickTimeCheckObject.QuickTimeCheck\CLSID@ {DE4AF3B0-F4D4-11D3-B41A-0050DA2E6C21}
Reg HKLM\SOFTWARE\Classes\QuickTimeCheckObject.QuickTimeCheck\CurVer
Reg HKLM\SOFTWARE\Classes\QuickTimeCheckObject.QuickTimeCheck\CurVer@ QuickTimeCheckObject.QuickTimeCheck.1
Reg HKLM\SOFTWARE\Classes\QuickTimeCheckObject.QuickTimeCheck.1@ QuickTimeCheck Class
Reg HKLM\SOFTWARE\Classes\QuickTimeCheckObject.QuickTimeCheck.1\CLSID
Reg HKLM\SOFTWARE\Classes\QuickTimeCheckObject.QuickTimeCheck.1\CLSID@ {DE4AF3B0-F4D4-11D3-B41A-0050DA2E6C21}
Reg HKLM\SOFTWARE\Classes\QuickTimeExtension@ QuickTime Extension
Reg HKLM\SOFTWARE\Classes\QuickTimeExtension\DefaultIcon
Reg HKLM\SOFTWARE\Classes\QuickTimeExtension\DefaultIcon@ C:\Program Files\QuickTime\QTSystem\QuickTime.qts,-101
Reg HKLM\SOFTWARE\Classes\QuickTimeMIME.3g2\CLSID
Reg HKLM\SOFTWARE\Classes\QuickTimeMIME.3g2\CLSID@ {4063BE15-3B08-470D-A0D5-B37161CFFD69}
Reg HKLM\SOFTWARE\Classes\QuickTimeMIME.3gp\CLSID
Reg HKLM\SOFTWARE\Classes\QuickTimeMIME.3gp\CLSID@ {4063BE15-3B08-470D-A0D5-B37161CFFD69}
Reg HKLM\SOFTWARE\Classes\QuickTimeMIME.aac\CLSID
Reg HKLM\SOFTWARE\Classes\QuickTimeMIME.aac\CLSID@ {4063BE15-3B08-470D-A0D5-B37161CFFD69}
Reg HKLM\SOFTWARE\Classes\QuickTimeMIME.ac3\CLSID
Reg HKLM\SOFTWARE\Classes\QuickTimeMIME.ac3\CLSID@ {4063BE15-3B08-470D-A0D5-B37161CFFD69}
Reg HKLM\SOFTWARE\Classes\QuickTimeMIME.aiff\CLSID
Reg HKLM\SOFTWARE\Classes\QuickTimeMIME.aiff\CLSID@ {4063BE15-3B08-470D-A0D5-B37161CFFD69}
Reg HKLM\SOFTWARE\Classes\QuickTimeMIME.amc\CLSID
Reg HKLM\SOFTWARE\Classes\QuickTimeMIME.amc\CLSID@ {4063BE15-3B08-470D-A0D5-B37161CFFD69}
Reg HKLM\SOFTWARE\Classes\QuickTimeMIME.AMR\CLSID
Reg HKLM\SOFTWARE\Classes\QuickTimeMIME.AMR\CLSID@ {4063BE15-3B08-470D-A0D5-B37161CFFD69}
Reg HKLM\SOFTWARE\Classes\QuickTimeMIME.au\CLSID
Reg HKLM\SOFTWARE\Classes\QuickTimeMIME.au\CLSID@ {4063BE15-3B08-470D-A0D5-B37161CFFD69}
Reg HKLM\SOFTWARE\Classes\QuickTimeMIME.caf\CLSID
Reg HKLM\SOFTWARE\Classes\QuickTimeMIME.caf\CLSID@ {4063BE15-3B08-470D-A0D5-B37161CFFD69}
Reg HKLM\SOFTWARE\Classes\QuickTimeMIME.flc\CLSID
Reg HKLM\SOFTWARE\Classes\QuickTimeMIME.flc\CLSID@ {4063BE15-3B08-470D-A0D5-B37161CFFD69}
Reg HKLM\SOFTWARE\Classes\QuickTimeMIME.gsm\CLSID
Reg HKLM\SOFTWARE\Classes\QuickTimeMIME.gsm\CLSID@ {4063BE15-3B08-470D-A0D5-B37161CFFD69}
Reg HKLM\SOFTWARE\Classes\QuickTimeMIME.jp2\CLSID
Reg HKLM\SOFTWARE\Classes\QuickTimeMIME.jp2\CLSID@ {4063BE15-3B08-470D-A0D5-B37161CFFD69}
Reg HKLM\SOFTWARE\Classes\QuickTimeMIME.m4a\CLSID
Reg HKLM\SOFTWARE\Classes\QuickTimeMIME.m4a\CLSID@ {4063BE15-3B08-470D-A0D5-B37161CFFD69}
Reg HKLM\SOFTWARE\Classes\QuickTimeMIME.m4b\CLSID
Reg HKLM\SOFTWARE\Classes\QuickTimeMIME.m4b\CLSID@ {4063BE15-3B08-470D-A0D5-B37161CFFD69}
Reg HKLM\SOFTWARE\Classes\QuickTimeMIME.m4p\CLSID
Reg HKLM\SOFTWARE\Classes\QuickTimeMIME.m4p\CLSID@ {4063BE15-3B08-470D-A0D5-B37161CFFD69}
Reg HKLM\SOFTWARE\Classes\QuickTimeMIME.m4v\CLSID
Reg HKLM\SOFTWARE\Classes\QuickTimeMIME.m4v\CLSID@ {4063BE15-3B08-470D-A0D5-B37161CFFD69}
Reg HKLM\SOFTWARE\Classes\QuickTimeMIME.mid\CLSID
Reg HKLM\SOFTWARE\Classes\QuickTimeMIME.mid\CLSID@ {4063BE15-3B08-470D-A0D5-B37161CFFD69}
Reg HKLM\SOFTWARE\Classes\QuickTimeMIME.mov\CLSID
Reg HKLM\SOFTWARE\Classes\QuickTimeMIME.mov\CLSID@ {4063BE15-3B08-470D-A0D5-B37161CFFD69}
Reg HKLM\SOFTWARE\Classes\QuickTimeMIME.mp4\CLSID
Reg HKLM\SOFTWARE\Classes\QuickTimeMIME.mp4\CLSID@ {4063BE15-3B08-470D-A0D5-B37161CFFD69}
Reg HKLM\SOFTWARE\Classes\QuickTimeMIME.mpeg\CLSID
Reg HKLM\SOFTWARE\Classes\QuickTimeMIME.mpeg\CLSID@ {4063BE15-3B08-470D-A0D5-B37161CFFD69}
Reg HKLM\SOFTWARE\Classes\QuickTimeMIME.pict\CLSID
Reg HKLM\SOFTWARE\Classes\QuickTimeMIME.pict\CLSID@ {4063BE15-3B08-470D-A0D5-B37161CFFD69}
Reg HKLM\SOFTWARE\Classes\QuickTimeMIME.png\CLSID
Reg HKLM\SOFTWARE\Classes\QuickTimeMIME.png\CLSID@ {4063BE15-3B08-470D-A0D5-B37161CFFD69}
Reg HKLM\SOFTWARE\Classes\QuickTimeMIME.pntg\CLSID
Reg HKLM\SOFTWARE\Classes\QuickTimeMIME.pntg\CLSID@ {4063BE15-3B08-470D-A0D5-B37161CFFD69}
Reg HKLM\SOFTWARE\Classes\QuickTimeMIME.qcp\CLSID
Reg HKLM\SOFTWARE\Classes\QuickTimeMIME.qcp\CLSID@ {4063BE15-3B08-470D-A0D5-B37161CFFD69}
Reg HKLM\SOFTWARE\Classes\QuickTimeMIME.qtif\CLSID
Reg HKLM\SOFTWARE\Classes\QuickTimeMIME.qtif\CLSID@ {4063BE15-3B08-470D-A0D5-B37161CFFD69}
Reg HKLM\SOFTWARE\Classes\QuickTimeMIME.rtsp\CLSID
Reg HKLM\SOFTWARE\Classes\QuickTimeMIME.rtsp\CLSID@ {4063BE15-3B08-470D-A0D5-B37161CFFD69}
Reg HKLM\SOFTWARE\Classes\QuickTimeMIME.sdp\CLSID
Reg HKLM\SOFTWARE\Classes\QuickTimeMIME.sdp\CLSID@ {4063BE15-3B08-470D-A0D5-B37161CFFD69}
Reg HKLM\SOFTWARE\Classes\QuickTimeMIME.sdv\CLSID
Reg HKLM\SOFTWARE\Classes\QuickTimeMIME.sdv\CLSID@ {4063BE15-3B08-470D-A0D5-B37161CFFD69}
Reg HKLM\SOFTWARE\Classes\QuickTimeMIME.sgi\CLSID
Reg HKLM\SOFTWARE\Classes\QuickTimeMIME.sgi\CLSID@ {4063BE15-3B08-470D-A0D5-B37161CFFD69}
Reg HKLM\SOFTWARE\Classes\QuickTimeMIME.targa\CLSID
Reg HKLM\SOFTWARE\Classes\QuickTimeMIME.targa\CLSID@ {4063BE15-3B08-470D-A0D5-B37161CFFD69}
Reg HKLM\SOFTWARE\Classes\QuickTimeMIME.tif\CLSID
Reg HKLM\SOFTWARE\Classes\QuickTimeMIME.tif\CLSID@ {4063BE15-3B08-470D-A0D5-B37161CFFD69}
Reg HKLM\SOFTWARE\Classes\QuickTimeMIME.wav\CLSID
Reg HKLM\SOFTWARE\Classes\QuickTimeMIME.wav\CLSID@ {4063BE15-3B08-470D-A0D5-B37161CFFD69}
Reg HKLM\SOFTWARE\Classes\QuickTimePlayerAddition@ QuickTime Player Addition
Reg HKLM\SOFTWARE\Classes\QuickTimePlayerAddition\DefaultIcon
Reg HKLM\SOFTWARE\Classes\QuickTimePlayerAddition\DefaultIcon@ C:\Program Files\QuickTime\QuickTimePlayer.exe,-140
Reg HKLM\SOFTWARE\Classes\QuickTimePlayerLib.QTRefMovie@ QTRefMovie Class
Reg HKLM\SOFTWARE\Classes\QuickTimePlayerLib.QTRefMovie\CLSID
Reg HKLM\SOFTWARE\Classes\QuickTimePlayerLib.QTRefMovie\CLSID@ {F7C41927-9415-4121-95D0-CBCC2202DA82}
Reg HKLM\SOFTWARE\Classes\QuickTimePlayerLib.QTRefMovie\CurVer
Reg HKLM\SOFTWARE\Classes\QuickTimePlayerLib.QTRefMovie\CurVer@ QuickTimePlayerLib.QTRefMovie.1
Reg HKLM\SOFTWARE\Classes\QuickTimePlayerLib.QTRefMovie.1@ QTRefMovie Class
Reg HKLM\SOFTWARE\Classes\QuickTimePlayerLib.QTRefMovie.1\CLSID
Reg HKLM\SOFTWARE\Classes\QuickTimePlayerLib.QTRefMovie.1\CLSID@ {F7C41927-9415-4121-95D0-CBCC2202DA82}
Reg HKLM\SOFTWARE\Classes\QuickTimePlayerLib.QTRefMovieDescriptor@ QTRefMovieDescriptor Class
Reg HKLM\SOFTWARE\Classes\QuickTimePlayerLib.QTRefMovieDescriptor\CLSID
Reg HKLM\SOFTWARE\Classes\QuickTimePlayerLib.QTRefMovieDescriptor\CLSID@ {7CAB7C36-4989-445D-9D74-DFF79A3C85FA}
Reg HKLM\SOFTWARE\Classes\QuickTimePlayerLib.QTRefMovieDescriptor\CurVer
Reg HKLM\SOFTWARE\Classes\QuickTimePlayerLib.QTRefMovieDescriptor\CurVer@ QuickTimePlayerLib.QTRefMovieDescriptor.1
Reg HKLM\SOFTWARE\Classes\QuickTimePlayerLib.QTRefMovieDescriptor.1@ QTRefMovieDescriptor Class
Reg HKLM\SOFTWARE\Classes\QuickTimePlayerLib.QTRefMovieDescriptor.1\CLSID
Reg HKLM\SOFTWARE\Classes\QuickTimePlayerLib.QTRefMovieDescriptor.1\CLSID@ {7CAB7C36-4989-445D-9D74-DFF79A3C85FA}
Reg HKLM\SOFTWARE\Classes\QuickTimePlayerLib.QuickTimePlayerApp@ QuickTimePlayerApp Class
Reg HKLM\SOFTWARE\Classes\QuickTimePlayerLib.QuickTimePlayerApp\CLSID
Reg HKLM\SOFTWARE\Classes\QuickTimePlayerLib.QuickTimePlayerApp\CLSID@ {D97F7D8D-7610-4271-82C8-61A91BD796D1}
Reg HKLM\SOFTWARE\Classes\QuickTimePlayerLib.QuickTimePlayerApp\CurVer
Reg HKLM\SOFTWARE\Classes\QuickTimePlayerLib.QuickTimePlayerApp\CurVer@ QuickTimePlayerLib.QuickTimePlayerApp.1
Reg HKLM\SOFTWARE\Classes\QuickTimePlayerLib.QuickTimePlayerApp.1@ QuickTimePlayerApp Class
Reg HKLM\SOFTWARE\Classes\QuickTimePlayerLib.QuickTimePlayerApp.1\CLSID
Reg HKLM\SOFTWARE\Classes\QuickTimePlayerLib.QuickTimePlayerApp.1\CLSID@ {D97F7D8D-7610-4271-82C8-61A91BD796D1}
Reg HKLM\SOFTWARE\Classes\QuickTimePreferences@ QuickTime Preferences
Reg HKLM\SOFTWARE\Classes\QuickTimePreferences\DefaultIcon
Reg HKLM\SOFTWARE\Classes\QuickTimePreferences\DefaultIcon@ C:\Program Files\QuickTime\QTSystem\QuickTime.qts,-102
Reg HKLM\SOFTWARE\Classes\QuickTimeResources@ QuickTime Resources
Reg HKLM\SOFTWARE\Classes\QuickTimeResources\DefaultIcon
Reg HKLM\SOFTWARE\Classes\QuickTimeResources\DefaultIcon@ C:\Program Files\QuickTime\QTSystem\QuickTime.qts,-105
Reg HKLM\SOFTWARE\Classes\QuickTimeSystem@ QuickTime
Reg HKLM\SOFTWARE\Classes\QuickTimeSystem\DefaultIcon
Reg HKLM\SOFTWARE\Classes\QuickTimeSystem\DefaultIcon@ C:\Program Files\QuickTime\QTSystem\QuickTime.qts,-100
Reg HKLM\SOFTWARE\Classes\SCTEngine.DiskProtection\CLSID@ {837B8D04-E311-475E-8D56-3F7020DAD4B4}
Reg HKLM\SOFTWARE\Classes\SCTEngine.DiskProtection\CurVer@ SCTEngine.DiskProtection.1
Reg HKLM\SOFTWARE\Classes\SCTEngine.DiskProtection.1\CLSID@ {837B8D04-E311-475E-8D56-3F7020DAD4B4}
Reg HKLM\SOFTWARE\Classes\SCTEngine.Preset\CLSID@ {05d6000c-b38e-11da-bde5-0014224df592}
Reg HKLM\SOFTWARE\Classes\SCTEngine.Preset\CurVer@ SCTEngine.Preset.1
Reg HKLM\SOFTWARE\Classes\SCTEngine.Preset.1\CLSID@ {05d6000c-b38e-11da-bde5-0014224df592}
Reg HKLM\SOFTWARE\Classes\SCTEngine.PresetManager\CLSID@ {05d60004-b38e-11da-bde5-0014224df592}
Reg HKLM\SOFTWARE\Classes\SCTEngine.PresetManager\CurVer@ SCTEngine.PresetManager.1
Reg HKLM\SOFTWARE\Classes\SCTEngine.PresetManager.1\CLSID@ {05d60004-b38e-11da-bde5-0014224df592}
Reg HKLM\SOFTWARE\Classes\SCTEngine.Presets\CLSID@ {05d60008-b38e-11da-bde5-0014224df592}
Reg HKLM\SOFTWARE\Classes\SCTEngine.Presets\CurVer@ SCTEngine.Presets.1
Reg HKLM\SOFTWARE\Classes\SCTEngine.Presets.1\CLSID@ {05d60008-b38e-11da-bde5-0014224df592}
Reg HKLM\SOFTWARE\Classes\SCTEngine.SecuritySettings\CLSID@ {4D611F01-CE60-409E-8962-215E9EE91F6F}
Reg HKLM\SOFTWARE\Classes\SCTEngine.SecuritySettings\CurVer@ SCTEngine.SecuritySettings.1
Reg HKLM\SOFTWARE\Classes\SCTEngine.SecuritySettings.1\CLSID@ {4D611F01-CE60-409E-8962-215E9EE91F6F}
Reg HKLM\SOFTWARE\Classes\SCTEngine.SoftwareUpdates\CLSID@ {ABBF4B05-C9E5-4DBB-9A8B-7F2C24B266F5}
Reg HKLM\SOFTWARE\Classes\SCTEngine.SoftwareUpdates\CurVer@ SCTEngine.SoftwareUpdates.1
Reg HKLM\SOFTWARE\Classes\SCTEngine.SoftwareUpdates.1\CLSID@ {ABBF4B05-C9E5-4DBB-9A8B-7F2C24B266F5}
Reg HKLM\SOFTWARE\Classes\SCTEngine.SubSystem\CLSID@ {A541B541-F316-4666-84E9-D417A99F5AE3}
Reg HKLM\SOFTWARE\Classes\SCTEngine.SubSystem\CurVer@ SCTEngine.SubSystem.1
Reg HKLM\SOFTWARE\Classes\SCTEngine.SubSystem.1\CLSID@ {A541B541-F316-4666-84E9-D417A99F5AE3}
Reg HKLM\SOFTWARE\Classes\SCTEngine.UserPictures\CLSID@ {05d60014-b38e-11da-bde5-0014224df592}
Reg HKLM\SOFTWARE\Classes\SCTEngine.UserPictures\CurVer@ SCTEngine.UserPictures.1
Reg HKLM\SOFTWARE\Classes\SCTEngine.UserPictures.1\CLSID@ {05d60014-b38e-11da-bde5-0014224df592}
Reg HKLM\SOFTWARE\Classes\SCTEngine.UserProfile\CLSID@ {05d60010-b38e-11da-bde5-0014224df592}
Reg HKLM\SOFTWARE\Classes\SCTEngine.UserProfile\CurVer@ SCTEngine.UserProfile.1
Reg HKLM\SOFTWARE\Classes\SCTEngine.UserProfile.1\CLSID@ {05d60010-b38e-11da-bde5-0014224df592}
Reg HKLM\SOFTWARE\Classes\SCTEngine.UserProfileManager\CLSID@ {6AF5E271-9458-4D95-91B5-BD267B5B1DD3}
Reg HKLM\SOFTWARE\Classes\SCTEngine.UserProfileManager\CurVer@ SCTEngine.UserProfileManager.1
Reg HKLM\SOFTWARE\Classes\SCTEngine.UserProfileManager.1\CLSID@ {6AF5E271-9458-4D95-91B5-BD267B5B1DD3}
Reg HKLM\SOFTWARE\Classes\SCTEngine.UserProfiles\CLSID@ {A9939608-76FD-4F13-9FB0-3EBDE37D9F7D}
Reg HKLM\SOFTWARE\Classes\SCTEngine.UserProfiles\CurVer@ SCTEngine.UserProfiles.1
Reg HKLM\SOFTWARE\Classes\SCTEngine.UserProfiles.1\CLSID@ {A9939608-76FD-4F13-9FB0-3EBDE37D9F7D}
Reg HKLM\SOFTWARE\Classes\SCTSvc.SCTSvcObj\CLSID@ {D586A8A2-36D7-4a24-A24E-506562E0BBF0}
Reg HKLM\SOFTWARE\Classes\SCTSvc.SCTSvcObj\CurVer@ SCTSvc.SCTSvcObj.1
Reg HKLM\SOFTWARE\Classes\SCTSvc.SCTSvcObj.1\CLSID@ {D586A8A2-36D7-4a24-A24E-506562E0BBF0}
Reg HKLM\SOFTWARE\Classes\search@ Windows Search Protocol
Reg HKLM\SOFTWARE\Classes\search@URL Protocol
Reg HKLM\SOFTWARE\Classes\search@FriendlyTypeName @%SystemRoot%\explorer.exe,-6010
Reg HKLM\SOFTWARE\Classes\search\shell
Reg HKLM\SOFTWARE\Classes\search\shell\open
Reg HKLM\SOFTWARE\Classes\search\shell\open@ExplorerFlags 18
Reg HKLM\SOFTWARE\Classes\search\shell\open\command
Reg HKLM\SOFTWARE\Classes\search\shell\open\command@ %SystemRoot%\Explorer.exe /separate,/idlist,%I,%L
Reg HKLM\SOFTWARE\Classes\search\shell\open\command@DelegateExecute {90b9bce2-b6db-4fd3-8451-35917ea1081b}
Reg HKLM\SOFTWARE\Classes\ShellExecuteHook.SABShellExecuteHook@ SABShellExecuteHook Class
Reg HKLM\SOFTWARE\Classes\ShellExecuteHook.SABShellExecuteHook\CLSID
Reg HKLM\SOFTWARE\Classes\ShellExecuteHook.SABShellExecuteHook\CLSID@ {5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}
Reg HKLM\SOFTWARE\Classes\ShellExecuteHook.SABShellExecuteHook\CurVer
Reg HKLM\SOFTWARE\Classes\ShellExecuteHook.SABShellExecuteHook\CurVer@ ShellExecuteHook.SABShellExecuteHook.1
Reg HKLM\SOFTWARE\Classes\ShellExecuteHook.SABShellExecuteHook.1@ SABShellExecuteHook Class
Reg HKLM\SOFTWARE\Classes\ShellExecuteHook.SABShellExecuteHook.1\CLSID
Reg HKLM\SOFTWARE\Classes\ShellExecuteHook.SABShellExecuteHook.1\CLSID@ {5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}
Reg HKLM\SOFTWARE\Classes\SoftwareUpdate.ASUController@ ASUController Class
Reg HKLM\SOFTWARE\Classes\SoftwareUpdate.ASUController\CLSID
Reg HKLM\SOFTWARE\Classes\SoftwareUpdate.ASUController\CLSID@ {2692A9D5-61DF-46D5-A5A1-A6CCA921D578}
Reg HKLM\SOFTWARE\Classes\SoftwareUpdate.ASUController\CurVer
Reg HKLM\SOFTWARE\Classes\SoftwareUpdate.ASUController\CurVer@ SoftwareUpdate.ASUController.1
Reg HKLM\SOFTWARE\Classes\SoftwareUpdate.ASUController.1@ ASUController Class
Reg HKLM\SOFTWARE\Classes\SoftwareUpdate.ASUController.1\CLSID
Reg HKLM\SOFTWARE\Classes\SoftwareUpdate.ASUController.1\CLSID@ {2692A9D5-61DF-46D5-A5A1-A6CCA921D578}
Reg HKLM\SOFTWARE\Classes\SUPERAntiSpywareContextMenuExt.SASCon.1@ SASContextMenu Class
Reg HKLM\SOFTWARE\Classes\SUPERAntiSpywareContextMenuExt.SASCon.1\CLSID
Reg HKLM\SOFTWARE\Classes\SUPERAntiSpywareContextMenuExt.SASCon.1\CLSID@ {CA8ACAFA-5FBB-467B-B348-90DD488DE003}
Reg HKLM\SOFTWARE\Classes\SUPERAntiSpywareContextMenuExt.SASConte@ SASContextMenu Class
Reg HKLM\SOFTWARE\Classes\SUPERAntiSpywareContextMenuExt.SASConte\CLSID
Reg HKLM\SOFTWARE\Classes\SUPERAntiSpywareContextMenuExt.SASConte\CLSID@ {CA8ACAFA-5FBB-467B-B348-90DD488DE003}
Reg HKLM\SOFTWARE\Classes\SUPERAntiSpywareContextMenuExt.SASConte\CurVer
Reg HKLM\SOFTWARE\Classes\SUPERAntiSpywareContextMenuExt.SASConte\CurVer@ SUPERAntiSpywareContextMenuExt.SASCon.1
Reg HKLM\SOFTWARE\Classes\tib@URL Protocol
Reg HKLM\SOFTWARE\Classes\tib\shell
Reg HKLM\SOFTWARE\Classes\tib\shell\open
Reg HKLM\SOFTWARE\Classes\tib\shell\open\command
Reg HKLM\SOFTWARE\Classes\tib\shell\open\command@ C:\Program Files\Acronis\TrueImageHome\AcronisTibUrlHandler.exe "%1"
Reg HKLM\SOFTWARE\Classes\tibfile@ Acronis True Image Backup Archive
Reg HKLM\SOFTWARE\Classes\tibfile\CLSID
Reg HKLM\SOFTWARE\Classes\tibfile\CLSID@ {C539A15B-3AF9-4c92-B771-50CB78F5C751}
Reg HKLM\SOFTWARE\Classes\tibfile\DefaultIcon
Reg HKLM\SOFTWARE\Classes\tibfile\DefaultIcon@ C:\Program Files\Acronis\TrueImageHome\tishell.dll,-4
Reg HKLM\SOFTWARE\Classes\tibfile\Shell
Reg HKLM\SOFTWARE\Classes\tibfile\Shell\open
Reg HKLM\SOFTWARE\Classes\tibfile\Shell\open@
Reg HKLM\SOFTWARE\Classes\tibfile\Shell\open\command
Reg HKLM\SOFTWARE\Classes\tibfile\Shell\open\command@ explorer /idlist,%I,%L
Reg HKLM\SOFTWARE\Classes\tibfile\Shell\open\ddeexec
Reg HKLM\SOFTWARE\Classes\tibfile\Shell\open\ddeexec@ [ViewFolder("%l", %I, %S)]
Reg HKLM\SOFTWARE\Classes\tibfile\Shell\open\ddeexec@NoActivateHandler
Reg HKLM\SOFTWARE\Classes\tibfile\Shell\open\ddeexec\application
Reg HKLM\SOFTWARE\Classes\tibfile\Shell\open\ddeexec\application@ Folders
Reg HKLM\SOFTWARE\Classes\tibfile\Shell\open\ddeexec\ifexec
Reg HKLM\SOFTWARE\Classes\tibfile\Shell\open\ddeexec\ifexec@ []
Reg HKLM\SOFTWARE\Classes\tibfile\Shell\open\ddeexec\topic
Reg HKLM\SOFTWARE\Classes\tibfile\Shell\open\ddeexec\topic@ AppProperties
Reg HKLM\SOFTWARE\Classes\tibfile\ShellEx
Reg HKLM\SOFTWARE\Classes\tibfile\ShellEx\ContextMenuHandlers
Reg HKLM\SOFTWARE\Classes\tibfile\ShellEx\ContextMenuHandlers\{C539A15A-3AF9-4c92-B771-50CB78F5C751}
Reg HKLM\SOFTWARE\Classes\tibfile\ShellEx\ContextMenuHandlers\{C539A15A-3AF9-4c92-B771-50CB78F5C751}@
Reg HKLM\SOFTWARE\Classes\tisfile@ Acronis True Image Script
Reg HKLM\SOFTWARE\Classes\tisfile\DefaultIcon
Reg HKLM\SOFTWARE\Classes\tisfile\DefaultIcon@ C:\Program Files\Common Files\Acronis\TrueImageHome\TrueImageHomeService.exe,1

---- EOF - GMER 1.0.15 ----

#10 I_am_CanadianEh?

I_am_CanadianEh?
  • Topic Starter

  • Members
  • 489 posts
  • OFFLINE
  •  
  • Gender:Male
  • Local time:07:38 PM

Posted 05 October 2009 - 10:00 PM

In case you didn't catch it, the Kaspersky lab, I will send tomorrow. It's getting quite late.....time for bed. :(

#11 I_am_CanadianEh?

I_am_CanadianEh?
  • Topic Starter

  • Members
  • 489 posts
  • OFFLINE
  •  
  • Gender:Male
  • Local time:07:38 PM

Posted 06 October 2009 - 08:09 PM

Here's the Kaspersky lab.

The one object it found is a false positive, since I installed this program myself.

Tuesday, October 6, 2009
Operating system: Microsoft Windows Vista Home Premium Edition, 32-bit Service Pack 2 (build 6002)
Kaspersky Online Scanner version: 7.0.26.13
Last database update: Tuesday, October 06, 2009 23:07:29
Records in database: 2924226


Scan settings
scan using the following database extended
Scan archives yes
Scan e-mail databases yes

Scan area My Computer
A:\
C:\
D:\
E:\
F:\
G:\
H:\

Scan statistics
Objects scanned 102916
Threats found 1
Infected objects found 1
Suspicious objects found 0
Scan duration 01:23:05

File name Threat Threats count
C:\Program Files\RegScanner\RegScanner.exe Infected: not-a-virus:PSWTool.Win32.ProductKey.am 1

Selected area has been scanned.

#12 schrauber

schrauber

    Mr.Mechanic


  • Malware Response Team
  • 24,794 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Munich,Germany
  • Local time:01:38 AM

Posted 07 October 2009 - 10:53 AM

Hi,


Everything looks clean :(


  • Download OTC to your desktop and run it
  • Click Yes to beginning the Cleanup process and remove these components, including this application.
  • You will be asked to reboot the machine to finish the Cleanup process. Choose Yes.






Your machine appears to be clean, please take the time to read below on how to secure the machine and take the necessary steps to keep it Clean :(

Hiding Hidden Files
Please set your system to hide all hidden files.
Click Start, open My Computer, select the Tools menu and click Folder Options.
Select the View Tab. Under the Hidden files and folders heading, uncheck Show hidden files and folders.
Check: Hide file extensions for known file types
Check the Hide protected operating system files (recommended) option.
Click Yes to confirm.

Purging System Restore Points
Now you should Set a New Restore Point to prevent possible reinfection from an old one. Some of the malware you picked up could have been saved in System Restore. Since System Restore is a protected directory, your tools can not access it to delete these bad files which sometimes can reinfect your system. Setting a new restore point AFTER cleaning your system will help prevent this and enable your computer to "roll-back" to a clean working state.

The easiest and safest way to do this is:
  • Go to Start > Programs > Accessories > System Tools and click "System Restore".
  • Choose the radio button marked "Create a Restore Point" on the first screen then click "Next". Give the R.P. a name then click "Create". The new point will be stamped with the current date and time. Keep a log of this so you can find it easily should you need to use System Restore.
  • Then go to Start > Run and type: Cleanmgr
  • Click "OK".
  • Click the "More Options" Tab.
  • Click "Clean Up" in the System Restore section to remove all previous restore points except the newly created one.
One of the most common questions found when cleaning Spyware or other Malware is "how did my machine get infected?". There are a variety of reasons, but the most common ones are that you are going to sites that you are not practicing Safe Internet, you are not running the proper security software, and that your computer's security settings are set too low.

Below I have outlined a series of categories that outline how you can increase the security of your computer so that you will not be infected again in the future.


Practice Safe Internet

One of the main reasons people get infected in the first place is that they are not practicing Safe Internet. You practice Safe Internet when you educate yourself on how to properly use the Internet through the use of security tools and good practice. Knowing how you can get infected and what types of files and sites to avoid will be the most crucial step in keeping your computer malware free. The reality is that the majority of people who are infected with malware are ones who click on things they shouldn't be clicking on. Whether these things are files or sites it doesn't really matter. If something is out to get you, and you click on it, it most likely will. Below are a list of simple precautions to take to keep your computer clean and running securely:
  • If you receive an attachment from someone you do not know, DO NOT OPEN IT! Simple as that. Opening attachments from people you do not know is a very common method for viruses or worms to infect your computer.

  • If you receive an attachment and it ends with a .exe, .com, .bat, or .pif do not open the attachment unless you know for a fact that it is clean. For the casual computer user, you will almost never receive a valid attachment of this type.

  • If you receive an attachment from someone you know, and it looks suspicious, then it probably is. The email could be from someone you know infected with a malware that is trying to infect everyone in their address book.

  • If you are browsing the Internet and a popup appears saying that you are infected, ignore it!. These are, as far as I am concerned, scams that are being used to scare you into purchasing a piece of software. For an example of these types of popups, or Foistware, you should read this article: Foistware, And how to avoid it.

    There are also programs that disguise themselves as Anti-Spyware or security products but are instead scams. For a list of these types of programs we recommend you visit this link: Rogue/Suspect Anti-Spyware Products & Web Sites

  • Another tactic to fool you on the web is when a site displays a popup that looks like a normal Windows message or alert. When you click on them, though, they instead bring you to another site that is trying to push a product on you. We suggest that you close these windows by clicking on the X instead of the OK button. Alternatively, you can check to see if it's a real alert by right-clicking on the window. If there is a menu that comes up saying Add to Favorites... you know it's a fake.

  • Do not go to adult sites. I know this may bother some of you, but the fact is that a large amount of malware is pushed through these types of sites. I am not saying all adult sites do this, but a lot do.

  • When using an Instant Messaging program be cautious about clicking on links people send to you. It is not uncommon for infections to send a message to everyone in the infected person's contact list that contains a link to an infection. Instead when you receive a message that contains a link, message back to the person asking if it is legit before you click on it.

  • Stay away from Warez and Crack sites! In addition to the obvious copyright issues, the downloads from these sites are typically overrun with infections.

  • Be careful of what you download off of web sites and Peer-2-Peer networks. Some sites disguise malware as legitimate software to trick you into installing them and Peer-2-Peer networks are crawling with it. If you want to download a piece of software a from a site, and are not sure if they are legitimate, you can use McAfee Siteadvisor to look up info on the site.

  • DO NOT INSTALL any software without first reading the End User License Agreement, otherwise known as the EULA. A tactic that some developers use is to offer their software for free, but have spyware and other programs you do not want bundled with it. This is where they make their money. By reading the agreement there is a good chance you can spot this and not install the software.
Visit Microsoft's Windows Update Site Frequently

It is important that you visit http://www.windowsupdate.com regularly. This will ensure your computer has always the latest security updates available installed on your computer. If there are new updates to install, install them immediately, reboot your computer, and revisit the site until there are no more critical updates.


Make Internet Explorer 7 more secure
  • From within Internet Explorer click on the Tools menu and then click on Options.
  • Click once on the Security tab
  • Click once on the Internet icon so it becomes highlighted.
  • Click once on the Custom Level button.
    • Change the Download signed ActiveX controls to Prompt
    • Change the Download unsigned ActiveX controls to Disable
    • Change the Initialize and script ActiveX controls not marked as safe to Disable
    • Change the Installation of desktop items to Prompt
    • Change the Launching programs and files in an IFRAME to Prompt
    • Change the Navigate sub-frames across different domains to Prompt
    • When all these settings have been made, click on the OK button.
    • If it prompts you as to whether or not you want to save the settings, press the Yes button.
  • Next press the Apply button and then the OK to exit the Internet Properties page.
Update your AntiVirus Software

It is imperative that you update your Antivirus software at least once a week (Even more if you wish). If you do not update your antivirus software then it will not be able to catch any of the new variants that may come out. If you use a commercial antivirus program you must make sure you keep renewing your subscription. Otherwise, once your subscription runs out, you may not be able to update the programs virus definitions.


Make sure your applications have all of their updates

It is also possible for other programs on your computer to have security vulnerability that can allow malware to infect you. Therefore, it is also a good idea to check for the latest versions of commonly installed applications that are regularly patched to fix vulnerabilities. You can check these by visiting Secunia Software Inspector and Calendar of Updates.



Follow this list and your potential for being infected again will reduce dramatically.
regards,
schrauber

Posted Image
Posted Image

If I've not posted back within 48 hrs., feel free to send a PM with your topic link. Thank you!

If I have helped you then please consider donating to continue the fight against malware Posted Image

#13 I_am_CanadianEh?

I_am_CanadianEh?
  • Topic Starter

  • Members
  • 489 posts
  • OFFLINE
  •  
  • Gender:Male
  • Local time:07:38 PM

Posted 07 October 2009 - 09:04 PM

Very comprehensive....a wealth of advice!! :(
Thanks, for all your help. :(

#14 schrauber

schrauber

    Mr.Mechanic


  • Malware Response Team
  • 24,794 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Munich,Germany
  • Local time:01:38 AM

Posted 08 October 2009 - 11:41 AM

You're welcome :(.
regards,
schrauber

Posted Image
Posted Image

If I've not posted back within 48 hrs., feel free to send a PM with your topic link. Thank you!

If I have helped you then please consider donating to continue the fight against malware Posted Image

#15 Farbar

Farbar

    Just Curious


  • Security Developer
  • 21,719 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:The Netherlands
  • Local time:02:38 AM

Posted 08 October 2009 - 11:44 AM

This thread will now be closed since the issue seems to be resolved.

If you need this topic reopened, please send me a PM and I will reopen it for you.

If you should have a new issue, please start a new topic.




0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users