Jump to content


 


Register a free account to unlock additional features at BleepingComputer.com
Welcome to BleepingComputer, a free community where people like yourself come together to discuss and learn how to use their computers. Using the site is easy and fun. As a guest, you can browse and view the various discussions in the forums, but can not create a new topic or reply to an existing one unless you are logged in. Other benefits of registering an account are subscribing to topics and forums, creating a blog, and having no ads shown anywhere on the site.


Click here to Register a free account now! or read our Welcome Guide to learn how to use this site.

Photo

Odd Registry Entry


  • Please log in to reply
15 replies to this topic

#1 Fireboss

Fireboss

  • Members
  • 9 posts
  • OFFLINE
  •  
  • Local time:05:34 AM

Posted 10 May 2012 - 10:20 AM

I'm not sure exactly what this is and I thought I'd seen most things. I ran CCleaner to dump trash and look at dead registry stuff. It turned up a set of keys on the file extensions section.
HKEY_USERS\S-1-5-21-855532508-2575135443-669711276-1003\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.灪g￾￿ꕅ癹ꕅ癹圮ᆊ㧎覬除h벬h鈘h
HKEY_USERS\S-1-5-21-855532508-2575135443-669711276-1003\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.灪g圮寊菨�Đ
HKEY_USERS\S-1-5-21-855532508-2575135443-669711276-1003\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.獰楰慭敧ꐀᦁ￾￿ꕅ癹ꕅ癹圮ᆊ㜖覬鎜h벬h轐h
HKEY_USERS\S-1-5-21-855532508-2575135443-669711276-1003\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.獰楰慭敧＀￿ꕅ癊ꕅ癊圮垯ޥ捾Đ
HKEY_USERS\S-1-5-21-855532508-2575135443-669711276-1003\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.獰楰慭敧＀￿ꕅ癹ꕅ癹圮ન怡䅙Đ
HKEY_USERS\S-1-5-21-855532508-2575135443-669711276-1003\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.獰楰慭敧＀￿ꕅ癹ꕅ癹圮ᆊ㵪覬Đ
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.獰楰慭敧攀癫鮗￾￿ꕅ癨ꕅ癨圮樳楔ᨸĐ

None of the keys has a value assigned which is why CCleaner listed them as dead keys.
Malwarebytes finds nothing
Zone Alarm's security package sees nothing
I dumped the last key name into Google and it returned this link
http://www.google.com/url?sa=t&rct=j&q=.%E7%8D%B0%E6%A5%B0%E6%85%AD%E6%95%A7%E6%94%80%E7%99%AB%EE%85%8F%E9%AE%97%EF%BF%BE%EF%BF%BF%EA%95%85%E7%99%A8%EA%95%85%E7%99%A8%E5%9C%AE%E6%A8%B3%E6%A5%94%E1%A8%B8%C4%91&source=web&cd=1&ved=0CCQQFjAA&url=http%3A%2F%2Flekythos.library.ucy.ac.cy%2Fbitstream%2Fhandle%2F10797%2F1315%2F430a_Evagoras_Pallikaridis.mp3%3Fsequence%3D1&ei=HderT4epMMry2QXAgLmmAg&usg=AFQjCNHK-_wyp1_gb5ToNHR_yMdhmZyfRw&cad=rja
Which asks if I want to open this mp3 file. I didn't of course. Another led to some kind of video file in Bulgaria.

Google translate says it's Italian but it translates to gibberish.

I've had no indication of system slow down or had any crashes.

CCleaner found these before and deleted them but they are back so obviously something is putting them there. The question is what? I ran the Mini Toolbox but saw nothing in that log either. I can post it if you wish.

Any Ideas?

BC AdBot (Login to Remove)

 


#2 dev00790

dev00790

    Bleeping Chocoholic


  • Members
  • 5,037 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:UK
  • Local time:10:34 AM

Posted 10 May 2012 - 07:02 PM

Hello,

I will be helping you with your problems

Some points for you to keep in mind while I am helping you to make things go easier and faster for both of us

  • Please do NOT run any tools unless instructed to do so.
    • We ask you to run different tools in a specific order to ensure the malware is completely removed from your machine, and running any additional tools may detect false positives, interfere with our tools, or cause unforeseen damage or system instability.
  • Please do not attach logs or use code boxes, just copy and paste the text.
    • Due to the high volume of logs we receive it helps to receive everything in the same format, and code boxes make the logs very difficult to read. Also, attachments require us to download and open the reports when it is easier to just read the reports in your post.
  • Please read every post completely before doing anything.
    • Pay special attention to the NOTE: lines, these entries identify an individual issue or important step in the cleanup process.
  • Please provide feedback about your experience as we go.
    • A short statement describing how the computer is working helps us understand where to go next, for example: I am still getting redirected, the computer is running normally, etc. Please do not describe the computer as "the same", this requires the extra step of looking back at your previous post.

NOTE: At the top of your post, click on the Watch Topic Button, select Immediate Notification, and click on Proceed. This will send you an e-mail as soon as I reply to your topic, allowing us to resolve the issue faster.

NOTE: Backup any files that cannot be replaced. Removing malware can be unpredictable and this step can save a lot of hartaches if things don't go as planed. You can put them on a CD/DVD, external drive or a pen drive, anywhere except on the computer.

NOTE: It is good practice to copy and paste the instructions into notepad and print them in case it is necessary for you to go offline during the cleanup process. To open notepad, navigate to Start Menu > All Programs > Accessories > Notepad. Please remember to copy the entire post so you do not miss any instructions.

----------------------------------------------

Please do the following:

Step 1

Download Security Check by screen317 from here.
  • Save it to your Desktop.
  • Double click SecurityCheck.exe and follow the onscreen instructions inside of the black box.
  • A Notepad document should open automatically called checkup.txt; please post the contents of that document in your next reply.


Step 2

Please download Farbar Service Scanner to your Desktop and run it on the computer with the issue.
  • Make sure the following options are checked:
    • Internet Services
    • Windows Firewall
    • System Restore
    • Security Center/Action Center
    • Windows Update
    • Windows Defender
  • Press "Scan".
  • It will create a log (FSS.txt) in the same directory the tool is run.
  • Please copy and paste the log to your reply.


Step 3

Please download MiniToolBox, save it to your desktop and run it.

Checkmark the following checkboxes:
  • Flush DNS
  • Report IE Proxy Settings
  • Reset IE Proxy Settings
  • Report FF Proxy Settings
  • Reset FF Proxy Settings
  • List content of Hosts
  • List IP configuration
  • List Winsock Entries
  • List last 10 Event Viewer log
  • List Installed Programs
  • List Devices
  • List Users, Partitions and Memory size.
  • List Minidump Files
Click Go and post the result (Result.txt). A copy of Result.txt will be saved in the same directory the tool is run.

Note: When using "Reset FF Proxy Settings" option Firefox should be closed.


Step 4

Download Malwarebytes' Anti-Malware (aka MBAM): https://www.bleepingcomputer.com/download/malwarebytes-anti-malware/ to your desktop.

  • Double-click mbam-setup.exe and follow the prompts to install the program.
  • At the end, be sure a checkmark is placed next to Update Malwarebytes'
    Anti-Malware
    and Launch Malwarebytes' Anti-Malware, then click Finish.
  • If an update is found, it will download and install the latest version.
  • Once the program has loaded, select Perform quick scan, then click Scan.
  • When the scan is complete, click OK, then Show Results to view the results.
  • Be sure that everything is checked, and click Remove Selected.
  • When completed, a log will open in Notepad.
  • Post the log back here.

Note: Be sure to restart the computer.

The log can also be found here:
C:\Documents and Settings\Username\Application Data\Malwarebytes\Malwarebytes' Anti-Malware\Logs\log-date.txt
Or at C:\Program Files\Malwarebytes' Anti-Malware\Logs\log-date.txt

Regards, dev00790

---------------------------------------

Marge: "Homer, the plant called. They said if you don't show up tomorrow don't bother showing up on Monday." Homer: "Woo-hoo! Four-day weekend!"I do not reply to Private Messages (PMs) asking for assistance - please use the forums instead. If I have been helping you, and I have not replied to your latest post in 48 hours please send me a PM. My Blog


#3 Fireboss

Fireboss
  • Topic Starter

  • Members
  • 9 posts
  • OFFLINE
  •  
  • Local time:05:34 AM

Posted 11 May 2012 - 06:27 AM

Good morning,
The system has been running as usual since my post though I've not used it for anything significant. Two things I noted
1) Although CCleaner deleted those registry entries as before i checked this morning and found two different keys:
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.灪g圮攍肖Đ
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.灪g圮攍肖Đ

2) the installed programs list shows Grabee. That's a broken install that I can't seem to make go away. IT won't uninstall and lately when I install new programs I get a "Another install is in progress..." If I work around that warning (kill the installer process) the install says "an install for Grabee is pending . . ." then allows me to continue. I contacted the company about the issue but haven't received an answer yet.


Here are the requested logs.

Results of screen317's Security Check version 0.99.32
Windows 7 x64 (UAC is disabled!)
Internet Explorer 9
``````````````````````````````
Antivirus/Firewall Check:

Windows Firewall Disabled!
ZoneAlarm Antivirus
ZoneAlarm Firewall
ZoneAlarm Extreme Security
ZoneAlarm Security
ZoneAlarm DataLock
WMI entry may not exist for antivirus; attempting automatic update.
```````````````````````````````
Anti-malware/Other Utilities Check:

Spybot - Search & Destroy
Java™ 6 Update 31
Adobe Reader 9 Adobe Reader out of date!
Mozilla Firefox (12.0.)
````````````````````````````````
Process Check:
objlist.exe by Laurent

Spybot Teatimer.exe is disabled!
CheckPoint ZoneAlarm vsmon.exe
CheckPoint ZoneAlarm zatray.exe
``````````End of Log````````````

=====================================================================
Farbar Service Scanner Version: 08-05-2012
Ran by Chief (administrator) on 11-05-2012 at 05:54:50
Running from "C:\Users\Chief\Desktop"
Microsoft Windows 7 Home Premium Service Pack 1 (X64)
Boot Mode: Normal
****************************************************************

Internet Services:
============

Connection Status:
==============
Localhost is blocked.
LAN connected.
Google IP is accessible.
Yahoo IP is accessible.


Windows Firewall:
=============

Firewall Disabled Policy:
==================
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
"EnableFirewall"=DWORD:0
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"EnableFirewall"=DWORD:0
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\PublicProfile]
"EnableFirewall"=DWORD:0


System Restore:
============

System Restore Disabled Policy:
========================


Action Center:
============

Windows Update:
============

Windows Autoupdate Disabled Policy:
============================


Windows Defender:
==============

File Check:
========
C:\Windows\System32\nsisvc.dll => MD5 is legit
C:\Windows\System32\drivers\nsiproxy.sys => MD5 is legit
C:\Windows\System32\dhcpcore.dll => MD5 is legit
C:\Windows\System32\drivers\afd.sys => MD5 is legit
C:\Windows\System32\drivers\tdx.sys => MD5 is legit
C:\Windows\System32\Drivers\tcpip.sys
[2012-05-10 17:12] - [2012-03-30 06:35] - 1918320 ____A (Microsoft Corporation) ACB82BDA8F46C84F465C1AFA517DC4B9

C:\Windows\System32\dnsrslvr.dll => MD5 is legit
C:\Windows\System32\mpssvc.dll => MD5 is legit
C:\Windows\System32\bfe.dll => MD5 is legit
C:\Windows\System32\drivers\mpsdrv.sys => MD5 is legit
C:\Windows\System32\SDRSVC.dll => MD5 is legit
C:\Windows\System32\vssvc.exe => MD5 is legit
C:\Windows\System32\wscsvc.dll => MD5 is legit
C:\Windows\System32\wbem\WMIsvc.dll => MD5 is legit
C:\Windows\System32\wuaueng.dll => MD5 is legit
C:\Windows\System32\qmgr.dll => MD5 is legit
C:\Windows\System32\es.dll => MD5 is legit
C:\Windows\System32\cryptsvc.dll => MD5 is legit
C:\Program Files\Windows Defender\MpSvc.dll => MD5 is legit
C:\Windows\System32\svchost.exe => MD5 is legit
C:\Windows\System32\rpcss.dll => MD5 is legit


**** End of log ****


=============================================================
MiniToolBox by Farbar Version: 18-01-2012
Ran by Chief (administrator) on 11-05-2012 at 05:59:38
Microsoft Windows 7 Home Premium Service Pack 1 (X64)
Boot Mode: Normal
***************************************************************************

========================= Flush DNS: ===================================

Windows IP Configuration

Successfully flushed the DNS Resolver Cache.

========================= IE Proxy Settings: ==============================

Proxy is not enabled.
No Proxy Server is set.

"Reset IE Proxy Settings": IE Proxy Settings were reset.

========================= FF Proxy Settings: ==============================


"Reset FF Proxy Settings": Firefox Proxy settings were reset.

Hosts file not detected in the default directory
========================= IP Configuration: ================================

Intel® 82578DC Gigabit Network Connection = Local Area Connection (Connected)


# ----------------------------------
# IPv4 Configuration
# ----------------------------------
pushd interface ipv4

reset
set global defaultcurhoplimit=64 icmpredirects=enabled taskoffload=enabled
add address name="Local Area Connection* 6-Zone Alarm Firewall Driver-0000" address=192.168.17.1 mask=255.255.255.0


popd
# End of IPv4 configuration



Windows IP Configuration

Host Name . . . . . . . . . . . . : Athena
Primary Dns Suffix . . . . . . . :
Node Type . . . . . . . . . . . . : Hybrid
IP Routing Enabled. . . . . . . . : No
WINS Proxy Enabled. . . . . . . . : No

Ethernet adapter Local Area Connection:

Connection-specific DNS Suffix . :
Description . . . . . . . . . . . : Intel® 82578DC Gigabit Network Connection
Physical Address. . . . . . . . . : 90-FB-A6-46-D2-22
DHCP Enabled. . . . . . . . . . . : Yes
Autoconfiguration Enabled . . . . : Yes
Link-local IPv6 Address . . . . . : fe80::64fb:5600:6286:342d%10(Preferred)
IPv4 Address. . . . . . . . . . . : 192.168.123.207(Preferred)
Subnet Mask . . . . . . . . . . . : 255.255.255.0
Lease Obtained. . . . . . . . . . : Friday, May 11, 2012 5:50:13 AM
Lease Expires . . . . . . . . . . : Saturday, May 12, 2012 5:50:12 AM
Default Gateway . . . . . . . . . : 192.168.123.254
DHCP Server . . . . . . . . . . . : 192.168.123.254
DHCPv6 IAID . . . . . . . . . . . : 194050982
DHCPv6 Client DUID. . . . . . . . : 00-01-00-01-12-EB-F1-D9-90-FB-A6-46-D2-22
DNS Servers . . . . . . . . . . . : 208.180.83.133
208.180.42.68
192.168.123.254
NetBIOS over Tcpip. . . . . . . . : Enabled

Tunnel adapter isatap.{E4359504-09E0-47ED-BDEA-7F176BD98D14}:

Media State . . . . . . . . . . . : Media disconnected
Connection-specific DNS Suffix . :
Description . . . . . . . . . . . : Microsoft ISATAP Adapter
Physical Address. . . . . . . . . : 00-00-00-00-00-00-00-E0
DHCP Enabled. . . . . . . . . . . : No
Autoconfiguration Enabled . . . . : Yes

Tunnel adapter Teredo Tunneling Pseudo-Interface:

Connection-specific DNS Suffix . :
Description . . . . . . . . . . . : Teredo Tunneling Pseudo-Interface
Physical Address. . . . . . . . . : 00-00-00-00-00-00-00-E0
DHCP Enabled. . . . . . . . . . . : No
Autoconfiguration Enabled . . . . : Yes
IPv6 Address. . . . . . . . . . . : 2001:0:4137:9e76:2cf4:3804:3f57:8430(Preferred)
Link-local IPv6 Address . . . . . : fe80::2cf4:3804:3f57:8430%12(Preferred)
Default Gateway . . . . . . . . . : ::
NetBIOS over Tcpip. . . . . . . . : Disabled
Server: rdns-lbbk-a.suddenlink.net
Address: 208.180.83.133

Name: google.com
Addresses: 74.125.227.67
74.125.227.68
74.125.227.69
74.125.227.70
74.125.227.71
74.125.227.72
74.125.227.73
74.125.227.78
74.125.227.64
74.125.227.65
74.125.227.66


Pinging google.com [74.125.227.100] with 32 bytes of data:
Reply from 74.125.227.100: bytes=32 time=22ms TTL=55
Reply from 74.125.227.100: bytes=32 time=16ms TTL=55

Ping statistics for 74.125.227.100:
Packets: Sent = 2, Received = 2, Lost = 0 (0% loss),
Approximate round trip times in milli-seconds:
Minimum = 16ms, Maximum = 22ms, Average = 19ms
Server: rdns-lbbk-a.suddenlink.net
Address: 208.180.83.133

Name: yahoo.com
Addresses: 98.139.183.24
209.191.122.70
72.30.38.140


Pinging yahoo.com [209.191.122.70] with 32 bytes of data:
Reply from 209.191.122.70: bytes=32 time=18ms TTL=55
Reply from 209.191.122.70: bytes=32 time=17ms TTL=55

Ping statistics for 209.191.122.70:
Packets: Sent = 2, Received = 2, Lost = 0 (0% loss),
Approximate round trip times in milli-seconds:
Minimum = 17ms, Maximum = 18ms, Average = 17ms
Server: rdns-lbbk-a.suddenlink.net
Address: 208.180.83.133

Name: bleepingcomputer.com
Address: 208.43.87.2


Pinging bleepingcomputer.com [208.43.87.2] with 32 bytes of data:
Reply from 208.43.87.2: Destination host unreachable.
Reply from 208.43.87.2: Destination host unreachable.

Ping statistics for 208.43.87.2:
Packets: Sent = 2, Received = 2, Lost = 0 (0% loss),

Pinging 127.0.0.1 with 32 bytes of data:
Request timed out.
Request timed out.

Ping statistics for 127.0.0.1:
Packets: Sent = 2, Received = 0, Lost = 2 (100% loss),
===========================================================================
Interface List
10...90 fb a6 46 d2 22 ......Intel® 82578DC Gigabit Network Connection
1...........................Software Loopback Interface 1
11...00 00 00 00 00 00 00 e0 Microsoft ISATAP Adapter
12...00 00 00 00 00 00 00 e0 Teredo Tunneling Pseudo-Interface
===========================================================================

IPv4 Route Table
===========================================================================
Active Routes:
Network Destination Netmask Gateway Interface Metric
0.0.0.0 0.0.0.0 192.168.123.254 192.168.123.207 10
127.0.0.0 255.0.0.0 On-link 127.0.0.1 306
127.0.0.1 255.255.255.255 On-link 127.0.0.1 306
127.255.255.255 255.255.255.255 On-link 127.0.0.1 306
192.168.123.0 255.255.255.0 On-link 192.168.123.207 266
192.168.123.207 255.255.255.255 On-link 192.168.123.207 266
192.168.123.255 255.255.255.255 On-link 192.168.123.207 266
224.0.0.0 240.0.0.0 On-link 127.0.0.1 306
224.0.0.0 240.0.0.0 On-link 192.168.123.207 266
255.255.255.255 255.255.255.255 On-link 127.0.0.1 306
255.255.255.255 255.255.255.255 On-link 192.168.123.207 266
===========================================================================
Persistent Routes:
None

IPv6 Route Table
===========================================================================
Active Routes:
If Metric Network Destination Gateway
12 58 ::/0 On-link
1 306 ::1/128 On-link
12 58 2001::/32 On-link
12 306 2001:0:4137:9e76:2cf4:3804:3f57:8430/128
On-link
10 266 fe80::/64 On-link
12 306 fe80::/64 On-link
12 306 fe80::2cf4:3804:3f57:8430/128
On-link
10 266 fe80::64fb:5600:6286:342d/128
On-link
1 306 ff00::/8 On-link
12 306 ff00::/8 On-link
10 266 ff00::/8 On-link
===========================================================================
Persistent Routes:
None
========================= Winsock entries =====================================

Catalog5 01 C:\Windows\SysWOW64\NLAapi.dll [52224] (Microsoft Corporation)
Catalog5 02 C:\Windows\SysWOW64\napinsp.dll [52224] (Microsoft Corporation)
Catalog5 03 C:\Windows\SysWOW64\pnrpnsp.dll [65024] (Microsoft Corporation)
Catalog5 04 C:\Windows\SysWOW64\pnrpnsp.dll [65024] (Microsoft Corporation)
Catalog5 05 C:\Windows\SysWOW64\mswsock.dll [232448] (Microsoft Corporation)
Catalog5 06 C:\Windows\SysWOW64\winrnr.dll [20992] (Microsoft Corporation)
Catalog5 07 C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WLIDNSP.DLL [145280] (Microsoft Corp.)
Catalog5 08 C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WLIDNSP.DLL [145280] (Microsoft Corp.)
Catalog9 01 C:\Windows\SysWOW64\mswsock.dll [232448] (Microsoft Corporation)
Catalog9 02 C:\Windows\SysWOW64\mswsock.dll [232448] (Microsoft Corporation)
Catalog9 03 C:\Windows\SysWOW64\mswsock.dll [232448] (Microsoft Corporation)
Catalog9 04 C:\Windows\SysWOW64\mswsock.dll [232448] (Microsoft Corporation)
Catalog9 05 C:\Windows\SysWOW64\mswsock.dll [232448] (Microsoft Corporation)
Catalog9 06 C:\Windows\SysWOW64\mswsock.dll [232448] (Microsoft Corporation)
Catalog9 07 C:\Windows\SysWOW64\mswsock.dll [232448] (Microsoft Corporation)
Catalog9 08 C:\Windows\SysWOW64\mswsock.dll [232448] (Microsoft Corporation)
Catalog9 09 C:\Windows\SysWOW64\mswsock.dll [232448] (Microsoft Corporation)
Catalog9 10 C:\Windows\SysWOW64\mswsock.dll [232448] (Microsoft Corporation)
x64-Catalog5 01 C:\Windows\System32\NLAapi.dll [70656] (Microsoft Corporation)
x64-Catalog5 02 C:\Windows\System32\napinsp.dll [68096] (Microsoft Corporation)
x64-Catalog5 03 C:\Windows\System32\pnrpnsp.dll [86016] (Microsoft Corporation)
x64-Catalog5 04 C:\Windows\System32\pnrpnsp.dll [86016] (Microsoft Corporation)
x64-Catalog5 05 C:\Windows\System32\mswsock.dll [326144] (Microsoft Corporation)
x64-Catalog5 06 C:\Windows\System32\winrnr.dll [28672] (Microsoft Corporation)
x64-Catalog5 07 C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDNSP.DLL [171392] (Microsoft Corp.)
x64-Catalog5 08 C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDNSP.DLL [171392] (Microsoft Corp.)
x64-Catalog9 01 C:\Windows\System32\mswsock.dll [326144] (Microsoft Corporation)
x64-Catalog9 02 C:\Windows\System32\mswsock.dll [326144] (Microsoft Corporation)
x64-Catalog9 03 C:\Windows\System32\mswsock.dll [326144] (Microsoft Corporation)
x64-Catalog9 04 C:\Windows\System32\mswsock.dll [326144] (Microsoft Corporation)
x64-Catalog9 05 C:\Windows\System32\mswsock.dll [326144] (Microsoft Corporation)
x64-Catalog9 06 C:\Windows\System32\mswsock.dll [326144] (Microsoft Corporation)
x64-Catalog9 07 C:\Windows\System32\mswsock.dll [326144] (Microsoft Corporation)
x64-Catalog9 08 C:\Windows\System32\mswsock.dll [326144] (Microsoft Corporation)
x64-Catalog9 09 C:\Windows\System32\mswsock.dll [326144] (Microsoft Corporation)
x64-Catalog9 10 C:\Windows\System32\mswsock.dll [326144] (Microsoft Corporation)

========================= Event log errors: ===============================

Application errors:
==================
Error: (05/10/2012 10:19:33 PM) (Source: MsiInstaller) (User: Chief)Chief
Description: Product: Microsoft Silverlight -- Error 1704. An installation for GrabBee is currently suspended. You must undo the changes made by that installation to continue. Do you want to undo those changes?

Error: (05/10/2012 08:53:00 AM) (Source: Microsoft-Windows-CAPI2) (User: )
Description: Cryptographic Services failed while processing the OnIdentity() call in the System Writer Object.

Details:
AddLegacyDriverFiles: Unable to back up image of binary VMware kbd.

System Error:
The system cannot find the file specified.
.

Error: (05/08/2012 09:42:44 AM) (Source: MsiInstaller) (User: Chief)Chief
Description: Product: VCOrganizer -- Error 1704. An installation for GrabBee is currently suspended. You must undo the changes made by that installation to continue. Do you want to undo those changes?

Error: (05/08/2012 09:24:21 AM) (Source: MsiInstaller) (User: Chief)Chief
Description: Product: VCOrganizer -- Error 1500. Another installation is in progress. You must complete that installation before continuing this one.

Error: (05/08/2012 09:24:20 AM) (Source: MsiInstaller) (User: Chief)Chief
Description: Product: VCOrganizer -- Error 1500. Another installation is in progress. You must complete that installation before continuing this one.

Error: (05/08/2012 09:24:19 AM) (Source: MsiInstaller) (User: Chief)Chief
Description: Product: VCOrganizer -- Error 1500. Another installation is in progress. You must complete that installation before continuing this one.

Error: (05/08/2012 09:24:19 AM) (Source: MsiInstaller) (User: Chief)Chief
Description: Product: VCOrganizer -- Error 1500. Another installation is in progress. You must complete that installation before continuing this one.

Error: (05/08/2012 08:50:28 AM) (Source: MsiInstaller) (User: Chief)Chief
Description: Product: VCOrganizer -- Error 1704. An installation for GrabBee is currently suspended. You must undo the changes made by that installation to continue. Do you want to undo those changes?

Error: (05/01/2012 05:30:13 PM) (Source: Application Error) (User: )
Description: Faulting application name: PDFPlus.exe, version: 10.0.0.1, time stamp: 0x4a825db2
Faulting module name: PDFPlus.exe, version: 10.0.0.1, time stamp: 0x4a825db2
Exception code: 0xc0000005
Fault offset: 0x00057824
Faulting process id: 0x14a4
Faulting application start time: 0xPDFPlus.exe0
Faulting application path: PDFPlus.exe1
Faulting module path: PDFPlus.exe2
Report Id: PDFPlus.exe3

Error: (04/30/2012 02:21:42 PM) (Source: MsiInstaller) (User: Chief)Chief
Description: Product: VCOrganizer -- Error 1500. Another installation is in progress. You must complete that installation before continuing this one.


System errors:
=============
Error: (05/11/2012 05:51:04 AM) (Source: Microsoft-Windows-DNS-Client) (User: NETWORK SERVICE)
Description: There was an error while attempting to read the local hosts file.

Error: (05/11/2012 05:51:04 AM) (Source: Microsoft-Windows-DNS-Client) (User: NETWORK SERVICE)
Description: There was an error while attempting to read the local hosts file.

Error: (05/11/2012 05:51:00 AM) (Source: Service Control Manager) (User: )
Description: The following boot-start or system-start driver(s) failed to load:
kl2
StarOpen

Error: (05/11/2012 05:50:16 AM) (Source: Microsoft-Windows-DNS-Client) (User: NETWORK SERVICE)
Description: There was an error while attempting to read the local hosts file.

Error: (05/11/2012 05:50:15 AM) (Source: Microsoft-Windows-DNS-Client) (User: NETWORK SERVICE)
Description: There was an error while attempting to read the local hosts file.

Error: (05/11/2012 05:49:57 AM) (Source: Application Popup) (User: )
Description: \SystemRoot\SysWow64\Drivers\StarOpen.SYS has been blocked from loading due to incompatibility with this system. Please contact your software vendor for a compatible version of the driver.

Error: (05/10/2012 10:13:57 PM) (Source: Microsoft-Windows-DNS-Client) (User: NETWORK SERVICE)
Description: There was an error while attempting to read the local hosts file.

Error: (05/10/2012 10:13:54 PM) (Source: Microsoft-Windows-DNS-Client) (User: NETWORK SERVICE)
Description: There was an error while attempting to read the local hosts file.

Error: (05/10/2012 10:13:51 PM) (Source: Service Control Manager) (User: )
Description: The following boot-start or system-start driver(s) failed to load:
kl2
StarOpen

Error: (05/10/2012 10:13:30 PM) (Source: Microsoft-Windows-DNS-Client) (User: NETWORK SERVICE)
Description: There was an error while attempting to read the local hosts file.


Microsoft Office Sessions:
=========================
Error: (04/09/2012 05:15:27 PM) (Source: Microsoft Office 12 Sessions)(User: )
Description: ID: 1, Application Name: Microsoft Office Excel, Application Version: 12.0.6654.5003, Microsoft Office Version: 12.0.6612.1000. This session lasted 371477 seconds with 300 seconds of active time. This session ended with a crash.

Error: (03/24/2012 00:22:33 PM) (Source: Microsoft Office 12 Sessions)(User: )
Description: ID: 1, Application Name: Microsoft Office Excel, Application Version: 12.0.6654.5003, Microsoft Office Version: 12.0.6612.1000. This session lasted 541 seconds with 0 seconds of active time. This session ended with a crash.

Error: (09/12/2011 01:25:03 PM) (Source: Microsoft Office 12 Sessions)(User: )
Description: ID: 1, Application Name: Microsoft Office Excel, Application Version: 12.0.6557.5000, Microsoft Office Version: 12.0.6425.1000. This session lasted 134 seconds with 120 seconds of active time. This session ended with a crash.

Error: (08/15/2011 01:23:44 PM) (Source: Microsoft Office 12 Sessions)(User: )
Description: ID: 6, Application Name: Microsoft Office Outlook, Application Version: 12.0.6557.5001, Microsoft Office Version: 12.0.6425.1000. This session lasted 9259 seconds with 540 seconds of active time. This session ended with a crash.

Error: (01/25/2011 10:11:47 AM) (Source: Microsoft Office 12 Sessions)(User: )
Description: ID: 6, Application Name: Microsoft Office Outlook, Application Version: 12.0.6550.5003, Microsoft Office Version: 12.0.6425.1000. This session lasted 69010 seconds with 1140 seconds of active time. This session ended with a crash.

Error: (01/20/2011 03:49:43 PM) (Source: Microsoft Office 12 Sessions)(User: )
Description: ID: 6, Application Name: Microsoft Office Outlook, Application Version: 12.0.6550.5003, Microsoft Office Version: 12.0.6425.1000. This session lasted 429912 seconds with 9720 seconds of active time. This session ended with a crash.


=========================== Installed Programs ============================

Update for Microsoft Office 2007 (KB2508958)
7-Zip 4.65 (x64 edition) (Version: 4.65.00.0)
Acrobat.com (Version: 1.6.65)
AcronisTrueImageHome 2011 (Version: 14.0.6942)
Adobe AIR (Version: 2.5.1.17730)
Adobe Flash Player 10 ActiveX (Version: 10.1.102.64)
Adobe Flash Player 11 Plugin 64-bit (Version: 11.2.202.233)
Adobe Reader 9.5.1 MUI (Version: 9.5.1)
Advanced IP Scanner (Version: 2.1.200)
Advertising Center (Version: 0.0.0.2)
AIO Captivate Toolbox (Version: 2.5.0)
AMD64Bit (Version: 1.00.0000)
Android SDK Tools (Version: 0.7)
ASAP Utilities (Version: 4.8.0)
Audacity 1.3.13 (Unicode)
Avery Wizard 3.1 (Version: 3.1.5)
Backup Manager Advance (Version: 2.0.2.19)
Brother MFL-Pro Suite MFC-9840CDW (Version: 1.0.1.0)
CCleaner (Version: 3.18)
Cisco Connect (Version: 1.3.11006.1)
Common (Version: 14.0.0.342)
Compatibility Pack for the 2007 Office system (Version: 12.0.6612.1000)
Contents (Version: 14.0.0.342)
Corel Direct DiscRecorder 3.5 (Version: 3.5)
Corel DVD Copy 6 (Version: 6.0)
Corel DVD MovieFactory 7 (Version: 7.0.0)
Corel KPT Collection (Version: 1.00.0000)
Corel PaintShop Pro X4 (Version: 14.0.0.345)
Corel PaintShop Pro X4 (Version: 14.1.0.5)
Corel VideoStudio Pro X4 (Version: 14.2.0.23)
CryptoTerm 1.5 (Version: 1.5)
D3DX10 (Version: 15.4.2368.0902)
Dan Elwell's Broadband Speed Test (Version: Dan Elwell's Broadband Speed Test (version 3))
Data Lifeguard Diagnostic for Windows 1.22
Dell Driver Download Manager (Version: 3.0.0.0)
DeviceIO (Version: 14.0.0.342)
Droid Explorer 0.8.7.2 (x64) (Version: 0.8.7.2)
Dropbox (Version: 1.2.52)
DVD Copy (Version: 6.0)
erLT (Version: 1.20.138.34)
FFmpeg v0.6.2 for Audacity
File Property Edit Pro
FinalTorrent 2011
FreeFileSync v4.2 (Version: 4.2)
Gateway InfoCentre (Version: 3.02.3000)
Gateway MyBackup (Version: 2.0.2.19)
Gateway Photo Frame 4.2.3.10 (Version: 4.2.3.10)
Gateway Recovery Management (Version: 4.05.3005)
Gateway Registration (Version: 1.02.3006)
Gateway ScreenSaver (Version: 1.1.0812)
Gateway Updater (Version: 1.01.3017)
Golden Rule Standard 14.4 (Version: 14.4)
GrabBee (Version: 1.0.7.6)
ICA (Version: 1.6.1.263)
ICA (Version: 14.0.0.342)
ICA (Version: 14.0.0.345)
Identity Card (Version: 1.00.3002)
ImagXpress (Version: 7.0.74.0)
Intel® Control Center (Version: 1.2.1.1007)
Intel® Management Engine Components (Version: 6.0.0.1179)
Intel® Network Connections 16.1.53.0 (Version: 16.1.53.0)
Intel® Rapid Storage Technology (Version: 10.1.0.1008)
InterVideo DiscLabel
InterVideo WinDVD 8 (Version: 8.0-B8.557)
IPM_PSP_CL (Version: 1.00.0000)
IPM_PSP_COM (Version: 1.00.0000)
IPM_PSP_COM (Version: 14.0.0.345)
IPM_VS_Pro (Version: 13.0)
ISCOM (Version: 14.0.0.342)
ISO Recorder (Version: 3.1.0)
Java Auto Updater (Version: 2.0.7.1)
Java™ 6 Update 31 (Version: 6.0.310)
Java™ 7 (64-bit) (Version: 7.0.0)
Java™ SE Development Kit 7 (64-bit) (Version: 1.7.0.0)
JMicron JMB36X Driver (Version: 1.00.0000)
LADSPA_plugins-win-0.4.15
LAME v3.98.3 for Audacity
LAN Speed Test (Version: 2.0.8)
LeKuSoft DVD Ripper 5.2
Link Shell Extension
LWS Twitter (Version: 13.00.1216.0)
Magic Bullet PhotoLooks for PaintShop Photo Pro (Version: 1.1)
Malwarebytes Anti-Malware version 1.61.0.1400 (Version: 1.61.0.1400)
MediaFace Online Plugins Service
Microsoft .NET Framework 4 Client Profile (Version: 4.0.30319)
Microsoft .NET Framework 4 Extended (Version: 4.0.30319)
Microsoft Access 2000 SR-1 Runtime (Version: 9.00.9327)
Microsoft Application Error Reporting (Version: 12.0.6015.5000)
Microsoft Corporation (Version: 9.1.0.0)
Microsoft LifeCam (Version: 3.60.253.0)
Microsoft Office 2003 Web Components (Version: 12.0.6213.1000)
Microsoft Office 2007 Service Pack 3 (SP3)
Microsoft Office Access Runtime (English) 2007 (Version: 12.0.6612.1000)
Microsoft Office Excel MUI (English) 2007 (Version: 12.0.6612.1000)
Microsoft Office File Validation Add-In (Version: 14.0.5130.5003)
Microsoft Office Office 64-bit Components 2007 (Version: 12.0.6612.1000)
Microsoft Office Outlook MUI (English) 2007 (Version: 12.0.6612.1000)
Microsoft Office PowerPoint MUI (English) 2007 (Version: 12.0.6612.1000)
Microsoft Office PowerPoint Viewer 2007 (English) (Version: 12.0.6612.1000)
Microsoft Office Proof (English) 2007 (Version: 12.0.6612.1000)
Microsoft Office Proof (French) 2007 (Version: 12.0.6612.1000)
Microsoft Office Proof (Spanish) 2007 (Version: 12.0.6612.1000)
Microsoft Office Proofing (English) 2007 (Version: 12.0.4518.1014)
Microsoft Office Proofing Tools 2007 Service Pack 3 (SP3)
Microsoft Office Shared 64-bit MUI (English) 2007 (Version: 12.0.6612.1000)
Microsoft Office Shared 64-bit Setup Metadata MUI (English) 2007 (Version: 12.0.6612.1000)
Microsoft Office Shared MUI (English) 2007 (Version: 12.0.6612.1000)
Microsoft Office Shared Setup Metadata MUI (English) 2007 (Version: 12.0.6612.1000)
Microsoft Office Standard 2007 (Version: 12.0.6612.1000)
Microsoft Office Word MUI (English) 2007 (Version: 12.0.6612.1000)
Microsoft Outlook Personal Folders Backup (Version: 1.10.0.0)
Microsoft Silverlight (Version: 4.1.10329.0)
Microsoft Visual C++ 2005 ATL Update kb973923 - x64 8.0.50727.4053 (Version: 8.0.50727.4053)
Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053 (Version: 8.0.50727.4053)
Microsoft Visual C++ 2005 Redistributable (Version: 8.0.56336)
Microsoft Visual C++ 2005 Redistributable (Version: 8.0.61001)
Microsoft Visual C++ 2005 Redistributable (x64) - KB2467175 (Version: 8.0.51011)
Microsoft Visual C++ 2005 Redistributable (x64) (Version: 8.0.56336)
Microsoft Visual C++ 2005 Redistributable (x64) (Version: 8.0.59192)
Microsoft Visual C++ 2005 Redistributable (x64) (Version: 8.0.61000)
Microsoft Visual C++ 2008 ATL Update kb973924 - x86 9.0.30729.4148 (Version: 9.0.30729.4148)
Microsoft Visual C++ 2008 Redistributable - KB2467174 - x86 9.0.30729.5570 (Version: 9.0.30729.5570)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.4148 (Version: 9.0.30729.4148)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 (Version: 9.0.30729.6161)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (Version: 9.0.30729)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 (Version: 9.0.30729.4148)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (Version: 9.0.30729.6161)
Microsoft Visual C++ 2010 x64 Redistributable - 10.0.40219 (Version: 10.0.40219)
Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 (Version: 10.0.40219)
MiniTool Partition Wizard Home Edition 5.2
Mozilla Firefox 12.0 (x86 en-US) (Version: 12.0)
Mozilla Maintenance Service (Version: 12.0)
MSVCRT (Version: 15.4.2862.0708)
MSXML 4.0 SP2 (KB954430) (Version: 4.20.9870.0)
MSXML 4.0 SP2 (KB973688) (Version: 4.20.9876.0)
MSXML 4.0 SP3 Parser (KB973685) (Version: 4.30.2107.0)
MSXML 4.0 SP3 Parser (Version: 4.30.2100.0)
Nero 9 Essentials
Nero ControlCenter (Version: 9.0.0.1)
Nero DiscSpeed (Version: 5.4.7.201)
Nero DiscSpeed Help (Version: 5.4.4.100)
Nero DriveSpeed (Version: 4.4.7.201)
Nero DriveSpeed Help (Version: 4.4.4.100)
Nero Express Help (Version: 9.4.9.100)
Nero InfoTool (Version: 6.4.7.201)
Nero InfoTool Help (Version: 6.4.4.100)
Nero Installer (Version: 4.4.8.1)
Nero Online Upgrade (Version: 1.3.0.0)
Nero StartSmart (Version: 9.4.11.209)
Nero StartSmart Help (Version: 9.4.11.208)
Nero StartSmart OEM (Version: 9.4.10.100)
NeroExpress (Version: 9.4.10.505)
neroxml (Version: 1.0.0)
NexusFont 2.5 (ver 2.5.5.1420)
nLite 1.4.9.1 (Version: 1.4.9.1)
Notepad++ (Version: 5.9.2)
Nuance OmniPage 17 (Version: 17.1.0000)
Nuance PaperPort 12 (Version: 12.1.0000)
Nuance PDF Viewer Plus (Version: 5.30.6481)
NVIDIA 3D Vision Driver 266.58 (Version: 266.58)
NVIDIA Control Panel 266.58 (Version: 266.58)
NVIDIA Graphics Driver 266.58 (Version: 266.58)
NVIDIA HD Audio Driver 1.1.13.1 (Version: 1.1.13.1)
NVIDIA Install Application (Version: 2.265.36.0)
NVIDIA PhysX (Version: 9.10.0514)
NVIDIA PhysX System Software 9.10.0514 (Version: 9.10.0514)
NVIDIA Stereoscopic 3D Driver (Version: 7.17.12.6658)
ODIR
PaperPort Image Printer 64-bit (Version: 1.00.0001)
ParetoLogic Data Recovery (Version: 1.1.0)
PSPPContent (Version: 1.00.0000)
PSPPContent (Version: 14.0.0.345)
PSPPHelp (Version: 14.0.0.345)
PSPPRO_DCRAW (Version: 13.0.0)
PSPPro64 (Version: 14.0.0.345)
PureHD (Version: 14.0.0.342)
Quicken 2010 (Version: 19.1.1.27)
QuickTime (Version: 7.55.90.70)
Realtek High Definition Audio Driver (Version: 6.0.1.5969)
ReNamer (Version: 5.50)
Replay Video Capture (Version: 4.2)
Replay Video Capture 6 (Version: 6.0.4)
RoboForm 7-7-4 (All Users) (Version: 7-7-4)
SalesOutlook (Version: 7.1)
SalesOutlook Crystal Runtime (Version: 11.5)
SAMSUNG USB Driver for Mobile Phones (Version: 1.3.450.0)
Scansoft PDF Professional
Setup (Version: 14.0.0.342)
Setup (Version: 14.0.0.345)
Share (Version: 14.0.0.342)
Share64 (Version: 14.0.0.342)
SmartControlCenterManager (Version: 1.0.22)
SmartSound Common Data (Version: 1.1.0)
SmartSound Quicktracks 5 (Version: 5.1.6)
SmartSound Quicktracks Plugin (Version: 3.0.5.0)
Spybot - Search & Destroy (Version: 1.6.2)
System Requirements Lab for Intel (Version: 4.4.24.0)
TurboTax 2009
TurboTax 2009 WinPerFedFormset (Version: 009.000.2163)
TurboTax 2009 WinPerReleaseEngine (Version: 009.000.0328)
TurboTax 2009 WinPerTaxSupport (Version: 009.000.0238)
TurboTax 2009 wrapper (Version: 009.000.0145)
TurboTax 2010
TurboTax 2010 WinPerFedFormset (Version: 010.000.5108)
TurboTax 2010 WinPerReleaseEngine (Version: 010.000.0501)
TurboTax 2010 WinPerTaxSupport (Version: 010.000.0219)
TurboTax 2010 wrapper (Version: 010.000.0157)
TurboTax 2011
TurboTax 2011 WinPerFedFormset (Version: 011.000.2999)
TurboTax 2011 WinPerReleaseEngine (Version: 011.000.0495)
TurboTax 2011 WinPerTaxSupport (Version: 011.000.0214)
TurboTax 2011 wrapper (Version: 011.000.0121)
Update for 2007 Microsoft Office System (KB967642)
Update for Microsoft .NET Framework 4 Client Profile (KB2468871) (Version: 1)
Update for Microsoft .NET Framework 4 Client Profile (KB2473228) (Version: 1)
Update for Microsoft .NET Framework 4 Client Profile (KB2533523) (Version: 1)
Update for Microsoft .NET Framework 4 Client Profile (KB2600217) (Version: 1)
Update for Microsoft .NET Framework 4 Extended (KB2468871) (Version: 1)
Update for Microsoft .NET Framework 4 Extended (KB2533523) (Version: 1)
Update for Microsoft .NET Framework 4 Extended (KB2600217) (Version: 1)
Update for Microsoft Office 2007 Help for Common Features (KB963673)
Update for Microsoft Office Excel 2007 Help (KB963678)
Update for Microsoft Office Outlook 2007 Help (KB963677)
Update for Microsoft Office Outlook 2007 Junk Email Filter (KB2598290) 32-Bit Edition
Update for Microsoft Office Powerpoint 2007 Help (KB963669)
Update for Microsoft Office Script Editor Help (KB963671)
Update for Microsoft Office Word 2007 Help (KB963665)
USB Video/Audio Device Driver (Version: 1.00.0000)
USDigital DiscStudio (Version: 2.0.2.83)
VC 9.0 Runtime (Version: 1.0.0)
VCOrganizer (Version: 5.50)
VIO (Version: 14.0.0.342)
VLC media player 1.1.10 (Version: 1.1.10)
VSClassic (Version: 14.0.0.342)
VSPro (Version: 14.0.0.342)
WavePad Sound Editor
WebEx
Welcome Center (Version: 1.00.3008)
Windows Live Communications Platform (Version: 15.4.3502.0922)
Windows Live Essentials (Version: 15.4.3502.0922)
Windows Live Essentials (Version: 15.4.3555.0308)
Windows Live ID Sign-in Assistant (Version: 7.250.4232.0)
Windows Live Installer (Version: 15.4.3502.0922)
Windows Live Language Selector (Version: 15.4.3555.0308)
Windows Live PIMT Platform (Version: 15.4.3508.1109)
Windows Live SOXE (Version: 15.4.3502.0922)
Windows Live SOXE Definitions (Version: 15.4.3502.0922)
Windows Live UX Platform (Version: 15.4.3502.0922)
Windows Live UX Platform Language Pack (Version: 15.4.3508.1109)
Windows Live Writer (Version: 15.4.3502.0922)
Windows Live Writer Resources (Version: 15.4.3502.0922)
Windows Media Encoder 9 Series
Windows Media Encoder 9 Series (Version: 9.00.2980)
Windows Media Player Firefox Plugin (Version: 1.0.0.8)
Windows Mobile Device Center (Version: 6.1.6965.0)
Windows Support Tools (Version: 5.2.3790.3959)
WinRAR archiver
ZoneAlarm Antivirus (Version: 10.1.079.000)
ZoneAlarm DataLock (Version: 10.1.079.000)
ZoneAlarm Extreme Security (Version: 10.1.079.000)
ZoneAlarm Firewall (Version: 10.1.079.000)
ZoneAlarm Security (Version: 10.1.079.000)

========================= Devices: ================================

Name: kl2
Description: kl2
Class Guid: {8ECC055D-047F-11D1-A537-0000F8753ED1}
Manufacturer:
Service: kl2
Problem: : This device is not present, is not working properly, or does not have all its drivers installed. (Code 24)
Resolution: The device is installed incorrectly. The problem could be a hardware failure, or a new driver might be needed.
Devices stay in this state if they have been prepared for removal.
After you remove the device, this error disappears.Remove the device, and this error should be resolved.


========================= Memory info: ===================================

Percentage of memory in use: 22%
Total physical RAM: 8119.09 MB
Available physical RAM: 6325.91 MB
Total Pagefile: 16236.38 MB
Available Pagefile: 14263.93 MB
Total Virtual: 4095.88 MB
Available Virtual: 3958.63 MB

========================= Partitions: =====================================

1 Drive a: (Data) (Network) (Total:3725.92 GB) (Free:3306.4 GB) NTFS
2 Drive c: (Gateway) (Fixed) (Total:915.41 GB) (Free:846.75 GB) NTFS
7 Drive h: () (Removable) (Total:7.45 GB) (Free:6.94 GB) FAT32
9 Drive j: (Lexar) (Removable) (Total:7.45 GB) (Free:7.06 GB) FAT32
10 Drive k: (Data) (Network) (Total:3725.92 GB) (Free:3306.4 GB) NTFS
11 Drive l: (Data) (Network) (Total:3725.92 GB) (Free:3306.4 GB) NTFS
12 Drive m: (Media) (Network) (Total:3725.92 GB) (Free:3306.4 GB) NTFS
13 Drive p: (Data) (Network) (Total:3725.92 GB) (Free:3306.4 GB) NTFS
14 Drive s: (Media) (Network) (Total:3725.92 GB) (Free:3306.4 GB) NTFS
15 Drive x: (Xavm) (Network) (Total:3725.92 GB) (Free:3306.4 GB) NTFS
16 Drive z: (Xavm) (Network) (Total:3725.92 GB) (Free:3306.4 GB) NTFS

========================= Users: ========================================

User accounts for \\ATHENA

Administrator Chief Guest

========================= Minidump Files ==================================

No minidump file found

**** End of log ****



============================================================
Malwarebytes Anti-Malware 1.61.0.1400
www.malwarebytes.org

Database version: v2012.05.11.02

Windows 7 Service Pack 1 x64 NTFS
Internet Explorer 9.0.8112.16421
Chief :: ATHENA [administrator]

5/11/2012 6:03:06 AM
mbam-log-2012-05-11 (06-03-06).txt

Scan type: Quick scan
Scan options enabled: Memory | Startup | Registry | File System | Heuristics/Extra | Heuristics/Shuriken | PUP | PUM
Scan options disabled: P2P
Objects scanned: 240062
Time elapsed: 5 minute(s), 14 second(s)

Memory Processes Detected: 0
(No malicious items detected)

Memory Modules Detected: 0
(No malicious items detected)

Registry Keys Detected: 0
(No malicious items detected)

Registry Values Detected: 0
(No malicious items detected)

Registry Data Items Detected: 0
(No malicious items detected)

Folders Detected: 0
(No malicious items detected)

Files Detected: 0
(No malicious items detected)

(end)

#4 dev00790

dev00790

    Bleeping Chocoholic


  • Members
  • 5,037 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:UK
  • Local time:10:34 AM

Posted 11 May 2012 - 07:14 AM

<ignore>

Edited by dev00790, 11 May 2012 - 06:05 PM.

Regards, dev00790

---------------------------------------

Marge: "Homer, the plant called. They said if you don't show up tomorrow don't bother showing up on Monday." Homer: "Woo-hoo! Four-day weekend!"I do not reply to Private Messages (PMs) asking for assistance - please use the forums instead. If I have been helping you, and I have not replied to your latest post in 48 hours please send me a PM. My Blog


#5 dev00790

dev00790

    Bleeping Chocoholic


  • Members
  • 5,037 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:UK
  • Local time:10:34 AM

Posted 11 May 2012 - 06:21 PM

Hi

Please do the following next:

Step 1

Please download the TDSS Rootkit Removing Tool (TDSSKiller.exe) and save it to your Desktop. <-Important!!!
  • Double-click on TDSSKiller.exe on yourr desktop to run the tool for known TDSS variants.
    Vista/Windows 7 users right-click and select Run As Administrator.
  • If TDSSKiller does not run, try renaming it.
  • To do this, right-click on TDSSKiller.exe, select Rename and give it a random name with the .com file extension (i.e. 123abc.com). If you do not see the file extension, please refer to How to change the file extension.
  • Click on change parameters
  • Check the boxes next to Verify file digital signatures and Detect TDLFS file system, then click OK.
  • Click the Start Scan button.
  • Do not use the computer during the scan
  • If the scan completes with nothing found, click Close to exit.
  • If malicious objects are found, they will show in the Scan results - Select action for found objects and offer three options.
  • Ensure Cure (default) is selected, then click Continue > Reboot now to finish the cleaning process.
    Note: If Cure is not an option, Skip instead, do not choose Delete unless instructed.
  • A log file named TDSSKiller_version_date_time_log.txt (i.e. TDSSKiller.2.4.0.0_27.07.2010_09.o7.26_log.txt) will be created and saved to the root directory (usually Local Disk C:).
  • Copy and paste the contents of that file in your next reply.


Step 2

I'd like us to scan your machine with ESET Online Scanner:

Note: You can use either Internet Explorer or Mozilla FireFox for this scan. You will however need to disable your current installed Anti-Virus, how to do so can be read here.

Note: Vista/Windows 7 users: You will need to to right-click on the either the IE or FF icon in the Start Menu or Quick Launch Bar on the Taskbar and select Run as Administrator from the context menu.

  • Hold down Control and click on this link to open ESET OnlineScan in a new window.
  • Click the Posted Image button.
  • For alternate browsers only: (Microsoft Internet Explorer users can skip these steps)
    • Click on esetsmartinstaller_enu.exe to download the ESET Smart Installer. Save it to your desktop.
    • Double click on the Posted Image
      icon on your desktop.
  • Check "YES, I accept the Terms of Use."
  • Click the Start button.
  • Accept any security warnings from your browser.
  • Under scan settings, check "Scan Archives" and "Remove found threats"
  • Click Advanced settings and select the following:
    • Scan potentially unwanted applications
    • Scan for potentially unsafe applications
    • Enable Anti-Stealth technology
  • ESET will then download updates for itself, install itself, and begin scanning your computer. Please be patient as this can take some time.
  • When the scan completes, click List Threats
  • Click Export, and save the file to your desktop using a unique name, such as ESETScan. Include the contents of this report in your next reply.
  • On ESET: Click the Back button, then the Finish button.
Note: Do not forget to re-enable your Anti-Virus application after running the above scan!

Step 3

How is the computer running now?

Regards, dev00790

---------------------------------------

Marge: "Homer, the plant called. They said if you don't show up tomorrow don't bother showing up on Monday." Homer: "Woo-hoo! Four-day weekend!"I do not reply to Private Messages (PMs) asking for assistance - please use the forums instead. If I have been helping you, and I have not replied to your latest post in 48 hours please send me a PM. My Blog


#6 Fireboss

Fireboss
  • Topic Starter

  • Members
  • 9 posts
  • OFFLINE
  •  
  • Local time:05:34 AM

Posted 12 May 2012 - 05:51 PM

Good afternoon/evening.

TDSKiller found nothing

ESET found one item
C:\Users\Chief\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\51\7ca274f3-30dd1755 Java/Exploit.CVE-2012-0507.AM trojan deleted - quarantined

It was actually removed not just quarantined.

The computer never showed significant signs of slowing down or interfering with work. I had noticed that accessing my server seemed slower but I had originally put that down to the server being old. It seems faster now but I could be imagining it. I'll know better in the morning after both have been relatively idle for the night.

I just checked the registry and now I have four of those keys. The two new ones were probably generated when I restarted.

Next :P

#7 dev00790

dev00790

    Bleeping Chocoholic


  • Members
  • 5,037 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:UK
  • Local time:10:34 AM

Posted 13 May 2012 - 11:46 AM

Hi

Please do the following next:

Step 1

Clear the Java cache

Clearing the Java Plug-in cache forces the browser to load the latest versions of web pages and programs.

To clear the Java Plug-in cache:

  • Click Start > Control Panel.
  • Double-click the Java icon in the control panel. The Java Control Panel appears.
  • Click Settings under Temporary Internet Files.The Temporary Files Settings dialog box appears.
  • Click Delete Files. The Delete Temporary Files dialog box appears.
  • Click OK on Delete Temporary Files window.
    Note: This deletes all the Downloaded Applications and Applets from the cache.
  • Click OK on Temporary Files Settings window.
    Note: If you want to delete a specific application and applet from the cache, click on View Application and View Applet options respectively.


Step 2

Please delete the current version of Farbar's service scanner, and then download the latest one:

Please download Farbar Service Scanner to your Desktop and run it on the computer with the issue.
  • Make sure the following options are checked:
    • Internet Services
    • Windows Firewall
    • System Restore
    • Security Center/Action Center
    • Windows Update
    • Windows Defender
  • Press "Scan".
  • It will create a log (FSS.txt) in the same directory the tool is run.
  • Please copy and paste the log to your reply.


Step 3

Please download SUPERAntiSpyware Free to your desktop

  • Double-click SUPERAntiSypware.exe and use the default settings for installation.
    For instructions with screenshots, please refer to the How to use SUPERAntiSpyware to scan and remove malware from your computer Guide.
  • An icon will be created on your desktop. Double-click that icon to launch the program.
  • If it will not start, go to Start > All Programs > SUPERAntiSpyware and click on Alternate Start.
  • If asked to update the program definitions, click "Yes". If not, update the definitions before scanning by selecting "Check for Updates". (If you encounter any problems while downloading the updates, manually download them from here. Double-click on the hyperlink for Download Installer and save SASDEFINITIONS.EXE to your desktop. Then double-click on SASDEFINITIONS.EXE to install the definitions.)

  • In the Main Menu, click the Preferences... button.
  • Click the "General and Startup" tab, and under Start-up Options, make sure "Start SUPERAntiSpyware when Windows starts" box is unchecked.
  • Click the "Scanning Control" tab, and under Scanner Options, make sure the following are checked (leave all other options as they are set):
    • Close browsers before scanning.
    • Scan for tracking cookies.
    • Terminate memory threats before quarantining.
  • Click the "Close" button to leave the Control Center screen.

Now boot your computer into Safe Mode.

  • Back on the main screen, under "Select Scan Type" check the box for Complete Scan.
  • Make sure that Enable Rescue Scan is not checked.
  • Click the Scan your computer... button.
  • After the scan is complete, a Scan Summary box will appear with potentially harmful items that were detected. Click "OK".
  • Make sure everything has a checkmark next to it and click "Next".
  • A notification will appear that "Quarantine and Removal is Complete". Click "OK" and then click the "Finish" button to return to the main menu.
  • If asked if you want to reboot, click "Yes" and reboot normally.

Boot your computer normally if you have not already done so.

To retrieve the scan log after reboot, launch SUPERAntiSpyware again.
  • Click the View Scan Logs button at the bottom.
  • This will open the Scanner Logs Window.
  • Click on the log to highlight it and then click on View Selected Log to open it.
  • Copy and paste the scan log results in your next reply.
Note: Some types of malware will disable security tools. If SUPERAntiSpyware will not install, please refer to these instructions for using the SUPERAntiSpyware Installer. If SUPERAntiSpyware is already installed but will not run, then follow the instructions for using RUNSAS.EXE to launch the program.


Step 4

How is the computer running now?

Regards, dev00790

---------------------------------------

Marge: "Homer, the plant called. They said if you don't show up tomorrow don't bother showing up on Monday." Homer: "Woo-hoo! Four-day weekend!"I do not reply to Private Messages (PMs) asking for assistance - please use the forums instead. If I have been helping you, and I have not replied to your latest post in 48 hours please send me a PM. My Blog


#8 Fireboss

Fireboss
  • Topic Starter

  • Members
  • 9 posts
  • OFFLINE
  •  
  • Local time:05:34 AM

Posted 13 May 2012 - 11:10 PM

Cleared the cache

Farbar Service Scanner Version: 11-05-2012
Ran by Chief (administrator) on 13-05-2012 at 18:38:00
Running from "C:\Users\Chief\Desktop"
Microsoft Windows 7 Home Premium Service Pack 1 (X64)
Boot Mode: Normal
****************************************************************

Internet Services:
============

Connection Status:
==============
Localhost is blocked.
LAN connected.
Google IP is accessible.
Yahoo IP is accessible.


Windows Firewall:
=============

Firewall Disabled Policy:
==================
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
"EnableFirewall"=DWORD:0
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"EnableFirewall"=DWORD:0
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\PublicProfile]
"EnableFirewall"=DWORD:0


System Restore:
============

System Restore Disabled Policy:
========================


Action Center:
============

Windows Update:
============

Windows Autoupdate Disabled Policy:
============================


Windows Defender:
==============

File Check:
========
C:\Windows\System32\nsisvc.dll => MD5 is legit
C:\Windows\System32\drivers\nsiproxy.sys => MD5 is legit
C:\Windows\System32\dhcpcore.dll => MD5 is legit
C:\Windows\System32\drivers\afd.sys => MD5 is legit
C:\Windows\System32\drivers\tdx.sys => MD5 is legit
C:\Windows\System32\Drivers\tcpip.sys => MD5 is legit
C:\Windows\System32\dnsrslvr.dll => MD5 is legit
C:\Windows\System32\mpssvc.dll => MD5 is legit
C:\Windows\System32\bfe.dll => MD5 is legit
C:\Windows\System32\drivers\mpsdrv.sys => MD5 is legit
C:\Windows\System32\SDRSVC.dll => MD5 is legit
C:\Windows\System32\vssvc.exe => MD5 is legit
C:\Windows\System32\wscsvc.dll => MD5 is legit
C:\Windows\System32\wbem\WMIsvc.dll => MD5 is legit
C:\Windows\System32\wuaueng.dll => MD5 is legit
C:\Windows\System32\qmgr.dll => MD5 is legit
C:\Windows\System32\es.dll => MD5 is legit
C:\Windows\System32\cryptsvc.dll => MD5 is legit
C:\Program Files\Windows Defender\MpSvc.dll => MD5 is legit
C:\Windows\System32\svchost.exe => MD5 is legit
C:\Windows\System32\rpcss.dll => MD5 is legit


**** End of log ****

SUPERAntiSpyware Scan Log
http://www.superantispyware.com

Generated 05/13/2012 at 07:39 PM

Application Version : 5.0.1148

Core Rules Database Version : 8590
Trace Rules Database Version: 6402

Scan type : Complete Scan
Total Scan Time : 00:50:26

Operating System Information
Windows 7 Home Premium 64-bit, Service Pack 1 (Build 6.01.7601)
UAC Off - Administrator

Memory items scanned : 332
Memory threats detected : 0
Registry items scanned : 68579
Registry threats detected : 0
File items scanned : 77463
File threats detected : 10

Adware.Tracking Cookie
.mlbam.112.2o7.net [ C:\USERS\CHIEF\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\HSY7WO0V.DEFAULT\COOKIES.SQLITE ]
.kaspersky.122.2o7.net [ C:\USERS\CHIEF\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\HSY7WO0V.DEFAULT\COOKIES.SQLITE ]
.eset.122.2o7.net [ C:\USERS\CHIEF\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\HSY7WO0V.DEFAULT\COOKIES.SQLITE ]
.stats.paypal.com [ C:\USERS\CHIEF\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\HSY7WO0V.DEFAULT\COOKIES.SQLITE ]
.imrworldwide.com [ C:\USERS\CHIEF\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\HSY7WO0V.DEFAULT\COOKIES.SQLITE ]
.imrworldwide.com [ C:\USERS\CHIEF\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\HSY7WO0V.DEFAULT\COOKIES.SQLITE ]
.getclicky.com [ C:\USERS\CHIEF\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\HSY7WO0V.DEFAULT\COOKIES.SQLITE ]
.static.getclicky.com [ C:\USERS\CHIEF\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\HSY7WO0V.DEFAULT\COOKIES.SQLITE ]
in.getclicky.com [ C:\USERS\CHIEF\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\HSY7WO0V.DEFAULT\COOKIES.SQLITE ]
.usatoday1.112.2o7.net [ C:\USERS\CHIEF\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\HSY7WO0V.DEFAULT\COOKIES.SQLITE ]


Checked the registry and the four foreign language keys are still there. I didn't dump them as you said not to do anything you didn't ask.

I'm still getting the pending install error that shows in one of the earlier logs but there's nothing in the install queue.
Other than that and still not knowing where those keys came from everything is fine.
Next

#9 dev00790

dev00790

    Bleeping Chocoholic


  • Members
  • 5,037 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:UK
  • Local time:10:34 AM

Posted 15 May 2012 - 07:14 PM

Hi

Step 1

Error: (05/08/2012 09:42:44 AM) (Source: MsiInstaller) (User: Chief)Chief
Description: Product: VCOrganizer -- Error 1704. An installation for GrabBee is currently suspended. You must undo the changes made by that installation to continue. Do you want to undo those changes?


I'm still getting the pending install error that shows in one of the earlier logs but there's nothing in the install queue.

Please uninstall VCOrganizer via Control Panel > Programs and Features
Restart the computer.

Does this solve the problem?

Step 2

Some of the symbols seem to be chinese characters / symbols, which appear to be words when translated, but garbage in meaning.

Please do the following:

Please download MiniRegTool.zip and unzip it.
Please download MiniRegTool64.zip and unzip it.
  • Run the tool.
  • Copy and paste the following into the edit box:


    HKEY_USERS\S-1-5-21-855532508-2575135443-669711276-1003\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts
    HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts
  • Check the Query Keys radio button.
  • Press Go button and post the result.

Regards, dev00790

---------------------------------------

Marge: "Homer, the plant called. They said if you don't show up tomorrow don't bother showing up on Monday." Homer: "Woo-hoo! Four-day weekend!"I do not reply to Private Messages (PMs) asking for assistance - please use the forums instead. If I have been helping you, and I have not replied to your latest post in 48 hours please send me a PM. My Blog


#10 Fireboss

Fireboss
  • Topic Starter

  • Members
  • 9 posts
  • OFFLINE
  •  
  • Local time:05:34 AM

Posted 16 May 2012 - 04:26 PM

I had already uninstalled and reinstalled VCO and that did allow me to bypass the pending installation error but the error still exists. My research indicates that it's been a rare but recurring issues with Windows 7 since it before it was released. I suspect I'm going to have to simply pick every GrabBee referenced key out of the registry one at a time as the company seems unwilling to help. Unless there's some reg utility that will do it that I'm not aware of.


Ran Minreg64
MiniRegTool by Farbar
Ran by Chief (administrator) on 2012-05-16 at 16:18:03

=================================================

[HKEY_USERS\S-1-5-21-855532508-2575135443-669711276-1003\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts]

[HKEY_USERS\S-1-5-21-855532508-2575135443-669711276-1003\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.001]

[HKEY_USERS\S-1-5-21-855532508-2575135443-669711276-1003\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.002]

[HKEY_USERS\S-1-5-21-855532508-2575135443-669711276-1003\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.003]

[HKEY_USERS\S-1-5-21-855532508-2575135443-669711276-1003\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.3fr]

[HKEY_USERS\S-1-5-21-855532508-2575135443-669711276-1003\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.3g2]

[HKEY_USERS\S-1-5-21-855532508-2575135443-669711276-1003\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.3gp]

[HKEY_USERS\S-1-5-21-855532508-2575135443-669711276-1003\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.3gp2]

[HKEY_USERS\S-1-5-21-855532508-2575135443-669711276-1003\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.3gpp]

[HKEY_USERS\S-1-5-21-855532508-2575135443-669711276-1003\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.7z]

[HKEY_USERS\S-1-5-21-855532508-2575135443-669711276-1003\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.AAC]

[HKEY_USERS\S-1-5-21-855532508-2575135443-669711276-1003\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.act]

[HKEY_USERS\S-1-5-21-855532508-2575135443-669711276-1003\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.ADT]

[HKEY_USERS\S-1-5-21-855532508-2575135443-669711276-1003\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.ADTS]

[HKEY_USERS\S-1-5-21-855532508-2575135443-669711276-1003\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.ai]

[HKEY_USERS\S-1-5-21-855532508-2575135443-669711276-1003\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.aif]

[HKEY_USERS\S-1-5-21-855532508-2575135443-669711276-1003\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.aifc]

[HKEY_USERS\S-1-5-21-855532508-2575135443-669711276-1003\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.aiff]

[HKEY_USERS\S-1-5-21-855532508-2575135443-669711276-1003\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.air]

[HKEY_USERS\S-1-5-21-855532508-2575135443-669711276-1003\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.amr]

[HKEY_USERS\S-1-5-21-855532508-2575135443-669711276-1003\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.ape]

[HKEY_USERS\S-1-5-21-855532508-2575135443-669711276-1003\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.apk]

[HKEY_USERS\S-1-5-21-855532508-2575135443-669711276-1003\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.application]

[HKEY_USERS\S-1-5-21-855532508-2575135443-669711276-1003\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.arw]

[HKEY_USERS\S-1-5-21-855532508-2575135443-669711276-1003\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.asd]

[HKEY_USERS\S-1-5-21-855532508-2575135443-669711276-1003\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.asf]

[HKEY_USERS\S-1-5-21-855532508-2575135443-669711276-1003\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.asx]

[HKEY_USERS\S-1-5-21-855532508-2575135443-669711276-1003\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.au]

[HKEY_USERS\S-1-5-21-855532508-2575135443-669711276-1003\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.avi]

[HKEY_USERS\S-1-5-21-855532508-2575135443-669711276-1003\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.backup]

[HKEY_USERS\S-1-5-21-855532508-2575135443-669711276-1003\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.bak]

[HKEY_USERS\S-1-5-21-855532508-2575135443-669711276-1003\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.bas]

[HKEY_USERS\S-1-5-21-855532508-2575135443-669711276-1003\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.bat]

[HKEY_USERS\S-1-5-21-855532508-2575135443-669711276-1003\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.BMP]

[HKEY_USERS\S-1-5-21-855532508-2575135443-669711276-1003\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.bz2]

[HKEY_USERS\S-1-5-21-855532508-2575135443-669711276-1003\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.cab]

[HKEY_USERS\S-1-5-21-855532508-2575135443-669711276-1003\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.cal]

[HKEY_USERS\S-1-5-21-855532508-2575135443-669711276-1003\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.cals]

[HKEY_USERS\S-1-5-21-855532508-2575135443-669711276-1003\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.cda]

[HKEY_USERS\S-1-5-21-855532508-2575135443-669711276-1003\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.cfg]

[HKEY_USERS\S-1-5-21-855532508-2575135443-669711276-1003\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.cgm]

[HKEY_USERS\S-1-5-21-855532508-2575135443-669711276-1003\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.clp]

[HKEY_USERS\S-1-5-21-855532508-2575135443-669711276-1003\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.cmx]

[HKEY_USERS\S-1-5-21-855532508-2575135443-669711276-1003\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.contact]

[HKEY_USERS\S-1-5-21-855532508-2575135443-669711276-1003\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.cpl]

[HKEY_USERS\S-1-5-21-855532508-2575135443-669711276-1003\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.cr2]

[HKEY_USERS\S-1-5-21-855532508-2575135443-669711276-1003\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.crw]

[HKEY_USERS\S-1-5-21-855532508-2575135443-669711276-1003\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.css]

[HKEY_USERS\S-1-5-21-855532508-2575135443-669711276-1003\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.csv]

[HKEY_USERS\S-1-5-21-855532508-2575135443-669711276-1003\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.ct]

[HKEY_USERS\S-1-5-21-855532508-2575135443-669711276-1003\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.cur]

[HKEY_USERS\S-1-5-21-855532508-2575135443-669711276-1003\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.cut]

[HKEY_USERS\S-1-5-21-855532508-2575135443-669711276-1003\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.dart]

[HKEY_USERS\S-1-5-21-855532508-2575135443-669711276-1003\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.dat]

[HKEY_USERS\S-1-5-21-855532508-2575135443-669711276-1003\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.db]

[HKEY_USERS\S-1-5-21-855532508-2575135443-669711276-1003\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.dcr]

[HKEY_USERS\S-1-5-21-855532508-2575135443-669711276-1003\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.dct]

[HKEY_USERS\S-1-5-21-855532508-2575135443-669711276-1003\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.dcx]

[HKEY_USERS\S-1-5-21-855532508-2575135443-669711276-1003\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.dib]

[HKEY_USERS\S-1-5-21-855532508-2575135443-669711276-1003\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.dic]

[HKEY_USERS\S-1-5-21-855532508-2575135443-669711276-1003\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.dll]

[HKEY_USERS\S-1-5-21-855532508-2575135443-669711276-1003\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.DMP]

[HKEY_USERS\S-1-5-21-855532508-2575135443-669711276-1003\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.dng]

[HKEY_USERS\S-1-5-21-855532508-2575135443-669711276-1003\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.doc]

[HKEY_USERS\S-1-5-21-855532508-2575135443-669711276-1003\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.docm]

[HKEY_USERS\S-1-5-21-855532508-2575135443-669711276-1003\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.docx]

[HKEY_USERS\S-1-5-21-855532508-2575135443-669711276-1003\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.dot]

[HKEY_USERS\S-1-5-21-855532508-2575135443-669711276-1003\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.dotm]

[HKEY_USERS\S-1-5-21-855532508-2575135443-669711276-1003\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.dotx]

[HKEY_USERS\S-1-5-21-855532508-2575135443-669711276-1003\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.drw]

[HKEY_USERS\S-1-5-21-855532508-2575135443-669711276-1003\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.dss]

[HKEY_USERS\S-1-5-21-855532508-2575135443-669711276-1003\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.dvf]

[HKEY_USERS\S-1-5-21-855532508-2575135443-669711276-1003\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.DVR]

[HKEY_USERS\S-1-5-21-855532508-2575135443-669711276-1003\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.DVR-MS]

[HKEY_USERS\S-1-5-21-855532508-2575135443-669711276-1003\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.dvs]

[HKEY_USERS\S-1-5-21-855532508-2575135443-669711276-1003\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.dwfx]

[HKEY_USERS\S-1-5-21-855532508-2575135443-669711276-1003\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.easmx]

[HKEY_USERS\S-1-5-21-855532508-2575135443-669711276-1003\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.edrwx]

[HKEY_USERS\S-1-5-21-855532508-2575135443-669711276-1003\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.emf]

[HKEY_USERS\S-1-5-21-855532508-2575135443-669711276-1003\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.eml]

[HKEY_USERS\S-1-5-21-855532508-2575135443-669711276-1003\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.eprtx]

[HKEY_USERS\S-1-5-21-855532508-2575135443-669711276-1003\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.eps]

[HKEY_USERS\S-1-5-21-855532508-2575135443-669711276-1003\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.erf]

[HKEY_USERS\S-1-5-21-855532508-2575135443-669711276-1003\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.evtx]

[HKEY_USERS\S-1-5-21-855532508-2575135443-669711276-1003\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.exe]

[HKEY_USERS\S-1-5-21-855532508-2575135443-669711276-1003\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.flac]

[HKEY_USERS\S-1-5-21-855532508-2575135443-669711276-1003\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.flv]

[HKEY_USERS\S-1-5-21-855532508-2575135443-669711276-1003\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.fon]

[HKEY_USERS\S-1-5-21-855532508-2575135443-669711276-1003\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.fpx]

[HKEY_USERS\S-1-5-21-855532508-2575135443-669711276-1003\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.gadget]

[HKEY_USERS\S-1-5-21-855532508-2575135443-669711276-1003\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.gif]

[HKEY_USERS\S-1-5-21-855532508-2575135443-669711276-1003\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.gsm]

[HKEY_USERS\S-1-5-21-855532508-2575135443-669711276-1003\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.gz]

[HKEY_USERS\S-1-5-21-855532508-2575135443-669711276-1003\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.hdp]

[HKEY_USERS\S-1-5-21-855532508-2575135443-669711276-1003\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.hdr]

[HKEY_USERS\S-1-5-21-855532508-2575135443-669711276-1003\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.hgl]

[HKEY_USERS\S-1-5-21-855532508-2575135443-669711276-1003\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.hosts]

[HKEY_USERS\S-1-5-21-855532508-2575135443-669711276-1003\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.hpg]

[HKEY_USERS\S-1-5-21-855532508-2575135443-669711276-1003\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.htm]

[HKEY_USERS\S-1-5-21-855532508-2575135443-669711276-1003\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.html]

[HKEY_USERS\S-1-5-21-855532508-2575135443-669711276-1003\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.ico]

[HKEY_USERS\S-1-5-21-855532508-2575135443-669711276-1003\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.iff]

[HKEY_USERS\S-1-5-21-855532508-2575135443-669711276-1003\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.img]

[HKEY_USERS\S-1-5-21-855532508-2575135443-669711276-1003\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.ini]

[HKEY_USERS\S-1-5-21-855532508-2575135443-669711276-1003\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.iso]

[HKEY_USERS\S-1-5-21-855532508-2575135443-669711276-1003\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.j2c]

[HKEY_USERS\S-1-5-21-855532508-2575135443-669711276-1003\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.j2k]

[HKEY_USERS\S-1-5-21-855532508-2575135443-669711276-1003\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.jar]

[HKEY_USERS\S-1-5-21-855532508-2575135443-669711276-1003\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.jbf]

[HKEY_USERS\S-1-5-21-855532508-2575135443-669711276-1003\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.jfif]

[HKEY_USERS\S-1-5-21-855532508-2575135443-669711276-1003\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.jif]

[HKEY_USERS\S-1-5-21-855532508-2575135443-669711276-1003\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.jns]

[HKEY_USERS\S-1-5-21-855532508-2575135443-669711276-1003\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.jp2]

[HKEY_USERS\S-1-5-21-855532508-2575135443-669711276-1003\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.jpc]

[HKEY_USERS\S-1-5-21-855532508-2575135443-669711276-1003\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.jpe]

[HKEY_USERS\S-1-5-21-855532508-2575135443-669711276-1003\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.jpeg]

[HKEY_USERS\S-1-5-21-855532508-2575135443-669711276-1003\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.jpg]

[HKEY_USERS\S-1-5-21-855532508-2575135443-669711276-1003\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.jps]

[HKEY_USERS\S-1-5-21-855532508-2575135443-669711276-1003\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.jpx]

[HKEY_USERS\S-1-5-21-855532508-2575135443-669711276-1003\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.jtx]

[HKEY_USERS\S-1-5-21-855532508-2575135443-669711276-1003\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.k25]

[HKEY_USERS\S-1-5-21-855532508-2575135443-669711276-1003\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.kdc]

[HKEY_USERS\S-1-5-21-855532508-2575135443-669711276-1003\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.library-ms]

[HKEY_USERS\S-1-5-21-855532508-2575135443-669711276-1003\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.LIC]

[HKEY_USERS\S-1-5-21-855532508-2575135443-669711276-1003\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.lnk]

[HKEY_USERS\S-1-5-21-855532508-2575135443-669711276-1003\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.log]

[HKEY_USERS\S-1-5-21-855532508-2575135443-669711276-1003\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.m1v]

[HKEY_USERS\S-1-5-21-855532508-2575135443-669711276-1003\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.M2T]

[HKEY_USERS\S-1-5-21-855532508-2575135443-669711276-1003\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.M2TS]

[HKEY_USERS\S-1-5-21-855532508-2575135443-669711276-1003\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.M2V]

[HKEY_USERS\S-1-5-21-855532508-2575135443-669711276-1003\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.m3u]

[HKEY_USERS\S-1-5-21-855532508-2575135443-669711276-1003\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.m4a]

[HKEY_USERS\S-1-5-21-855532508-2575135443-669711276-1003\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.m4b]

[HKEY_USERS\S-1-5-21-855532508-2575135443-669711276-1003\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.m4p]

[HKEY_USERS\S-1-5-21-855532508-2575135443-669711276-1003\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.m4v]

[HKEY_USERS\S-1-5-21-855532508-2575135443-669711276-1003\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.mac]

[HKEY_USERS\S-1-5-21-855532508-2575135443-669711276-1003\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.max]

[HKEY_USERS\S-1-5-21-855532508-2575135443-669711276-1003\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.md5]

[HKEY_USERS\S-1-5-21-855532508-2575135443-669711276-1003\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.mef]

[HKEY_USERS\S-1-5-21-855532508-2575135443-669711276-1003\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.mfo]

[HKEY_USERS\S-1-5-21-855532508-2575135443-669711276-1003\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.mht]

[HKEY_USERS\S-1-5-21-855532508-2575135443-669711276-1003\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.mhtml]

[HKEY_USERS\S-1-5-21-855532508-2575135443-669711276-1003\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.mid]

[HKEY_USERS\S-1-5-21-855532508-2575135443-669711276-1003\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.midi]

[HKEY_USERS\S-1-5-21-855532508-2575135443-669711276-1003\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.MOD]

[HKEY_USERS\S-1-5-21-855532508-2575135443-669711276-1003\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.moh]

[HKEY_USERS\S-1-5-21-855532508-2575135443-669711276-1003\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.mos]

[HKEY_USERS\S-1-5-21-855532508-2575135443-669711276-1003\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.mov]

[HKEY_USERS\S-1-5-21-855532508-2575135443-669711276-1003\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.mp2]

[HKEY_USERS\S-1-5-21-855532508-2575135443-669711276-1003\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.mp2v]

[HKEY_USERS\S-1-5-21-855532508-2575135443-669711276-1003\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.mp3]

[HKEY_USERS\S-1-5-21-855532508-2575135443-669711276-1003\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.mp4]

[HKEY_USERS\S-1-5-21-855532508-2575135443-669711276-1003\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.mp4v]

[HKEY_USERS\S-1-5-21-855532508-2575135443-669711276-1003\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.mpa]

[HKEY_USERS\S-1-5-21-855532508-2575135443-669711276-1003\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.mpc]

[HKEY_USERS\S-1-5-21-855532508-2575135443-669711276-1003\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.mpe]

[HKEY_USERS\S-1-5-21-855532508-2575135443-669711276-1003\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.mpeg]

[HKEY_USERS\S-1-5-21-855532508-2575135443-669711276-1003\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.mpg]

[HKEY_USERS\S-1-5-21-855532508-2575135443-669711276-1003\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.mpga]

[HKEY_USERS\S-1-5-21-855532508-2575135443-669711276-1003\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.mpo]

[HKEY_USERS\S-1-5-21-855532508-2575135443-669711276-1003\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.mpv2]

[HKEY_USERS\S-1-5-21-855532508-2575135443-669711276-1003\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.mrw]

[HKEY_USERS\S-1-5-21-855532508-2575135443-669711276-1003\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.msc]

[HKEY_USERS\S-1-5-21-855532508-2575135443-669711276-1003\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.msg]

[HKEY_USERS\S-1-5-21-855532508-2575135443-669711276-1003\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.msi]

[HKEY_USERS\S-1-5-21-855532508-2575135443-669711276-1003\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.msp]

[HKEY_USERS\S-1-5-21-855532508-2575135443-669711276-1003\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.msv]

[HKEY_USERS\S-1-5-21-855532508-2575135443-669711276-1003\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.MTS]

[HKEY_USERS\S-1-5-21-855532508-2575135443-669711276-1003\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.nef]

[HKEY_USERS\S-1-5-21-855532508-2575135443-669711276-1003\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.nrw]

[HKEY_USERS\S-1-5-21-855532508-2575135443-669711276-1003\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.ocx]

[HKEY_USERS\S-1-5-21-855532508-2575135443-669711276-1003\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.odt]

[HKEY_USERS\S-1-5-21-855532508-2575135443-669711276-1003\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.orf]

[HKEY_USERS\S-1-5-21-855532508-2575135443-669711276-1003\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.otf]

[HKEY_USERS\S-1-5-21-855532508-2575135443-669711276-1003\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.oxt]

[HKEY_USERS\S-1-5-21-855532508-2575135443-669711276-1003\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.pbm]

[HKEY_USERS\S-1-5-21-855532508-2575135443-669711276-1003\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.pcd]

[HKEY_USERS\S-1-5-21-855532508-2575135443-669711276-1003\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.pct]

[HKEY_USERS\S-1-5-21-855532508-2575135443-669711276-1003\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.pcx]

[HKEY_USERS\S-1-5-21-855532508-2575135443-669711276-1003\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.pdf]

[HKEY_USERS\S-1-5-21-855532508-2575135443-669711276-1003\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.pef]

[HKEY_USERS\S-1-5-21-855532508-2575135443-669711276-1003\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.pgl]

[HKEY_USERS\S-1-5-21-855532508-2575135443-669711276-1003\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.pgm]

[HKEY_USERS\S-1-5-21-855532508-2575135443-669711276-1003\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.pic]

[HKEY_USERS\S-1-5-21-855532508-2575135443-669711276-1003\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.pict]

[HKEY_USERS\S-1-5-21-855532508-2575135443-669711276-1003\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.pit]

[HKEY_USERS\S-1-5-21-855532508-2575135443-669711276-1003\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.Png]

[HKEY_USERS\S-1-5-21-855532508-2575135443-669711276-1003\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.pns]

[HKEY_USERS\S-1-5-21-855532508-2575135443-669711276-1003\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.pot]

[HKEY_USERS\S-1-5-21-855532508-2575135443-669711276-1003\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.potm]

[HKEY_USERS\S-1-5-21-855532508-2575135443-669711276-1003\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.potx]

[HKEY_USERS\S-1-5-21-855532508-2575135443-669711276-1003\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.ppam]

[HKEY_USERS\S-1-5-21-855532508-2575135443-669711276-1003\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.ppm]

[HKEY_USERS\S-1-5-21-855532508-2575135443-669711276-1003\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.ppsm]

[HKEY_USERS\S-1-5-21-855532508-2575135443-669711276-1003\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.ppsx]

[HKEY_USERS\S-1-5-21-855532508-2575135443-669711276-1003\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.ppt]

[HKEY_USERS\S-1-5-21-855532508-2575135443-669711276-1003\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.pptm]

[HKEY_USERS\S-1-5-21-855532508-2575135443-669711276-1003\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.pptx]

[HKEY_USERS\S-1-5-21-855532508-2575135443-669711276-1003\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.ps]

[HKEY_USERS\S-1-5-21-855532508-2575135443-669711276-1003\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.ps1xml]

[HKEY_USERS\S-1-5-21-855532508-2575135443-669711276-1003\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.psd]

[HKEY_USERS\S-1-5-21-855532508-2575135443-669711276-1003\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.psp]

[HKEY_USERS\S-1-5-21-855532508-2575135443-669711276-1003\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.pspimage]

[HKEY_USERS\S-1-5-21-855532508-2575135443-669711276-1003\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.pst]

[HKEY_USERS\S-1-5-21-855532508-2575135443-669711276-1003\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.QDF]

[HKEY_USERS\S-1-5-21-855532508-2575135443-669711276-1003\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.QDF-backup]

[HKEY_USERS\S-1-5-21-855532508-2575135443-669711276-1003\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.QFX]

[HKEY_USERS\S-1-5-21-855532508-2575135443-669711276-1003\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.ra]

[HKEY_USERS\S-1-5-21-855532508-2575135443-669711276-1003\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.raf]

[HKEY_USERS\S-1-5-21-855532508-2575135443-669711276-1003\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.ram]

[HKEY_USERS\S-1-5-21-855532508-2575135443-669711276-1003\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.rar]

[HKEY_USERS\S-1-5-21-855532508-2575135443-669711276-1003\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.ras]

[HKEY_USERS\S-1-5-21-855532508-2575135443-669711276-1003\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.raw]

[HKEY_USERS\S-1-5-21-855532508-2575135443-669711276-1003\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.rcd]

[HKEY_USERS\S-1-5-21-855532508-2575135443-669711276-1003\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.rec]

[HKEY_USERS\S-1-5-21-855532508-2575135443-669711276-1003\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.reg]

[HKEY_USERS\S-1-5-21-855532508-2575135443-669711276-1003\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.rfo]

[HKEY_USERS\S-1-5-21-855532508-2575135443-669711276-1003\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.rif]

[HKEY_USERS\S-1-5-21-855532508-2575135443-669711276-1003\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.riff]

[HKEY_USERS\S-1-5-21-855532508-2575135443-669711276-1003\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.rle]

[HKEY_USERS\S-1-5-21-855532508-2575135443-669711276-1003\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.rm]

[HKEY_USERS\S-1-5-21-855532508-2575135443-669711276-1003\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.rmi]

[HKEY_USERS\S-1-5-21-855532508-2575135443-669711276-1003\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.rmj]

[HKEY_USERS\S-1-5-21-855532508-2575135443-669711276-1003\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.rtf]

[HKEY_USERS\S-1-5-21-855532508-2575135443-669711276-1003\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.rw2]

[HKEY_USERS\S-1-5-21-855532508-2575135443-669711276-1003\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.scf]

[HKEY_USERS\S-1-5-21-855532508-2575135443-669711276-1003\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.sct]

[HKEY_USERS\S-1-5-21-855532508-2575135443-669711276-1003\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.search-ms]

[HKEY_USERS\S-1-5-21-855532508-2575135443-669711276-1003\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.sh]

[HKEY_USERS\S-1-5-21-855532508-2575135443-669711276-1003\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.shn]

[HKEY_USERS\S-1-5-21-855532508-2575135443-669711276-1003\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.shtml]

[HKEY_USERS\S-1-5-21-855532508-2575135443-669711276-1003\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.sldm]

[HKEY_USERS\S-1-5-21-855532508-2575135443-669711276-1003\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.sldx]

[HKEY_USERS\S-1-5-21-855532508-2575135443-669711276-1003\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.snd]

[HKEY_USERS\S-1-5-21-855532508-2575135443-669711276-1003\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.spx]

[HKEY_USERS\S-1-5-21-855532508-2575135443-669711276-1003\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.sr2]

[HKEY_USERS\S-1-5-21-855532508-2575135443-669711276-1003\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.srf]

[HKEY_USERS\S-1-5-21-855532508-2575135443-669711276-1003\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.sri.ogg]

[HKEY_USERS\S-1-5-21-855532508-2575135443-669711276-1003\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.SSDP//uuid:7bcfda84-5de3-4191-b1a1-00000000047d]

[HKEY_USERS\S-1-5-21-855532508-2575135443-669711276-1003\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.svg]

[HKEY_USERS\S-1-5-21-855532508-2575135443-669711276-1003\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.svgz]

[HKEY_USERS\S-1-5-21-855532508-2575135443-669711276-1003\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.sys]

[HKEY_USERS\S-1-5-21-855532508-2575135443-669711276-1003\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.tar]

[HKEY_USERS\S-1-5-21-855532508-2575135443-669711276-1003\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.tax2010]

[HKEY_USERS\S-1-5-21-855532508-2575135443-669711276-1003\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.tax2011]

[HKEY_USERS\S-1-5-21-855532508-2575135443-669711276-1003\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.tdb]

[HKEY_USERS\S-1-5-21-855532508-2575135443-669711276-1003\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.tga]

[HKEY_USERS\S-1-5-21-855532508-2575135443-669711276-1003\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.tif]

[HKEY_USERS\S-1-5-21-855532508-2575135443-669711276-1003\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.tiff]

[HKEY_USERS\S-1-5-21-855532508-2575135443-669711276-1003\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.torrent]

[HKEY_USERS\S-1-5-21-855532508-2575135443-669711276-1003\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.TS]

[HKEY_USERS\S-1-5-21-855532508-2575135443-669711276-1003\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.ttc]

[HKEY_USERS\S-1-5-21-855532508-2575135443-669711276-1003\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.ttf]

[HKEY_USERS\S-1-5-21-855532508-2575135443-669711276-1003\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.TTS]

[HKEY_USERS\S-1-5-21-855532508-2575135443-669711276-1003\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.txt]

[HKEY_USERS\S-1-5-21-855532508-2575135443-669711276-1003\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.ufo]

[HKEY_USERS\S-1-5-21-855532508-2575135443-669711276-1003\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.url]

[HKEY_USERS\S-1-5-21-855532508-2575135443-669711276-1003\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.vcf]

[HKEY_USERS\S-1-5-21-855532508-2575135443-669711276-1003\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.vmcx]

[HKEY_USERS\S-1-5-21-855532508-2575135443-669711276-1003\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.vob]

[HKEY_USERS\S-1-5-21-855532508-2575135443-669711276-1003\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.voc]

[HKEY_USERS\S-1-5-21-855532508-2575135443-669711276-1003\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.vox]

[HKEY_USERS\S-1-5-21-855532508-2575135443-669711276-1003\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.VSP]

[HKEY_USERS\S-1-5-21-855532508-2575135443-669711276-1003\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.wav]

[HKEY_USERS\S-1-5-21-855532508-2575135443-669711276-1003\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.wax]

[HKEY_USERS\S-1-5-21-855532508-2575135443-669711276-1003\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.wbk]

[HKEY_USERS\S-1-5-21-855532508-2575135443-669711276-1003\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.wbm]

[HKEY_USERS\S-1-5-21-855532508-2575135443-669711276-1003\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.wbmp]

[HKEY_USERS\S-1-5-21-855532508-2575135443-669711276-1003\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.wdp]

[HKEY_USERS\S-1-5-21-855532508-2575135443-669711276-1003\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.webp]

[HKEY_USERS\S-1-5-21-855532508-2575135443-669711276-1003\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.wm]

[HKEY_USERS\S-1-5-21-855532508-2575135443-669711276-1003\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.wma]

[HKEY_USERS\S-1-5-21-855532508-2575135443-669711276-1003\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.wmd]

[HKEY_USERS\S-1-5-21-855532508-2575135443-669711276-1003\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.wmf]

[HKEY_USERS\S-1-5-21-855532508-2575135443-669711276-1003\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.wms]

[HKEY_USERS\S-1-5-21-855532508-2575135443-669711276-1003\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.wmv]

[HKEY_USERS\S-1-5-21-855532508-2575135443-669711276-1003\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.wmx]

[HKEY_USERS\S-1-5-21-855532508-2575135443-669711276-1003\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.wmz]

[HKEY_USERS\S-1-5-21-855532508-2575135443-669711276-1003\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.wpg]

[HKEY_USERS\S-1-5-21-855532508-2575135443-669711276-1003\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.wpl]

[HKEY_USERS\S-1-5-21-855532508-2575135443-669711276-1003\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.wpost]

[HKEY_USERS\S-1-5-21-855532508-2575135443-669711276-1003\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.wpp]

[HKEY_USERS\S-1-5-21-855532508-2575135443-669711276-1003\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.wps]

[HKEY_USERS\S-1-5-21-855532508-2575135443-669711276-1003\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.WTV]

[HKEY_USERS\S-1-5-21-855532508-2575135443-669711276-1003\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.wv]

[HKEY_USERS\S-1-5-21-855532508-2575135443-669711276-1003\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.wvx]

[HKEY_USERS\S-1-5-21-855532508-2575135443-669711276-1003\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.x3f]

[HKEY_USERS\S-1-5-21-855532508-2575135443-669711276-1003\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.xht]

[HKEY_USERS\S-1-5-21-855532508-2575135443-669711276-1003\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.xhtml]

[HKEY_USERS\S-1-5-21-855532508-2575135443-669711276-1003\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.xla]

[HKEY_USERS\S-1-5-21-855532508-2575135443-669711276-1003\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.xlam]

[HKEY_USERS\S-1-5-21-855532508-2575135443-669711276-1003\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.xls]

[HKEY_USERS\S-1-5-21-855532508-2575135443-669711276-1003\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.xlsb]

[HKEY_USERS\S-1-5-21-855532508-2575135443-669711276-1003\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.xlsm]

[HKEY_USERS\S-1-5-21-855532508-2575135443-669711276-1003\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.xlsx]

[HKEY_USERS\S-1-5-21-855532508-2575135443-669711276-1003\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.xlt]

[HKEY_USERS\S-1-5-21-855532508-2575135443-669711276-1003\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.xltm]

[HKEY_USERS\S-1-5-21-855532508-2575135443-669711276-1003\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.xltx]

[HKEY_USERS\S-1-5-21-855532508-2575135443-669711276-1003\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.xml]

[HKEY_USERS\S-1-5-21-855532508-2575135443-669711276-1003\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.xps]

[HKEY_USERS\S-1-5-21-855532508-2575135443-669711276-1003\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.xsl]

[HKEY_USERS\S-1-5-21-855532508-2575135443-669711276-1003\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.zip]

[HKEY_USERS\S-1-5-21-855532508-2575135443-669711276-1003\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.?g???]

[HKEY_USERS\S-1-5-21-855532508-2575135443-669711276-1003\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.?g???]

[HKEY_USERS\S-1-5-21-855532508-2575135443-669711276-1003\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.?g????]

[HKEY_USERS\S-1-5-21-855532508-2575135443-669711276-1003\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.?g????]

[HKEY_USERS\S-1-5-21-855532508-2575135443-669711276-1003\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.?g????????]

[HKEY_USERS\S-1-5-21-855532508-2575135443-669711276-1003\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\DDECache]

[HKEY_USERS\S-1-5-21-855532508-2575135443-669711276-1003\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\Directory]

[HKEY_USERS\S-1-5-21-855532508-2575135443-669711276-1003\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\OpenWithList]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.001]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.002]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.003]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.3fr]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.3g2]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.3gp]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.3gp2]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.3gpp]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.7z]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.AAC]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.act]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.ADT]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.ADTS]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.ai]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.aif]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.aifc]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.aiff]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.air]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.amr]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.ape]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.apk]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.application]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.arw]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.asd]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.asf]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.asx]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.au]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.avi]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.backup]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.bak]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.bas]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.bat]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.BMP]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.bz2]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.cab]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.cal]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.cals]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.cda]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.cfg]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.cgm]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.clp]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.cmx]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.contact]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.cpl]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.cr2]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.crw]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.css]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.csv]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.ct]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.cur]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.cut]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.dart]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.dat]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.db]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.dcr]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.dct]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.dcx]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.dib]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.dic]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.dll]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.DMP]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.dng]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.doc]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.docm]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.docx]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.dot]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.dotm]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.dotx]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.drw]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.dss]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.dvf]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.DVR]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.DVR-MS]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.dvs]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.dwfx]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.easmx]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.edrwx]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.emf]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.eml]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.eprtx]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.eps]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.erf]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.evtx]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.exe]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.flac]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.flv]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.fon]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.fpx]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.gadget]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.gif]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.gsm]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.gz]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.hdp]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.hdr]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.hgl]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.hosts]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.hpg]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.htm]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.html]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.ico]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.iff]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.img]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.ini]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.iso]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.j2c]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.j2k]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.jar]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.jbf]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.jfif]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.jif]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.jns]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.jp2]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.jpc]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.jpe]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.jpeg]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.jpg]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.jps]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.jpx]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.jtx]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.k25]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.kdc]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.library-ms]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.LIC]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.lnk]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.log]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.m1v]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.M2T]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.M2TS]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.M2V]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.m3u]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.m4a]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.m4b]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.m4p]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.m4v]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.mac]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.max]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.md5]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.mef]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.mfo]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.mht]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.mhtml]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.mid]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.midi]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.MOD]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.moh]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.mos]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.mov]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.mp2]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.mp2v]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.mp3]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.mp4]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.mp4v]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.mpa]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.mpc]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.mpe]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.mpeg]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.mpg]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.mpga]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.mpo]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.mpv2]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.mrw]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.msc]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.msg]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.msi]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.msp]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.msv]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.MTS]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.nef]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.nrw]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.ocx]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.odt]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.orf]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.otf]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.oxt]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.pbm]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.pcd]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.pct]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.pcx]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.pdf]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.pef]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.pgl]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.pgm]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.pic]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.pict]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.pit]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.Png]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.pns]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.pot]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.potm]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.potx]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.ppam]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.ppm]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.ppsm]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.ppsx]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.ppt]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.pptm]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.pptx]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.ps]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.ps1xml]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.psd]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.psp]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.pspimage]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.pst]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.QDF]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.QDF-backup]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.QFX]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.ra]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.raf]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.ram]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.rar]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.ras]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.raw]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.rcd]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.rec]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.reg]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.rfo]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.rif]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.riff]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.rle]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.rm]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.rmi]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.rmj]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.rtf]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.rw2]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.scf]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.sct]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.search-ms]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.sh]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.shn]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.shtml]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.sldm]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.sldx]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.snd]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.spx]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.sr2]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.srf]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.sri.ogg]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.SSDP//uuid:7bcfda84-5de3-4191-b1a1-00000000047d]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.svg]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.svgz]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.sys]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.tar]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.tax2010]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.tax2011]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.tdb]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.tga]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.tif]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.tiff]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.torrent]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.TS]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.ttc]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.ttf]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.TTS]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.txt]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.ufo]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.url]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.vcf]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.vmcx]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.vob]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.voc]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.vox]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.VSP]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.wav]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.wax]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.wbk]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.wbm]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.wbmp]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.wdp]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.webp]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.wm]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.wma]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.wmd]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.wmf]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.wms]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.wmv]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.wmx]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.wmz]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.wpg]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.wpl]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.wpost]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.wpp]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.wps]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.WTV]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.wv]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.wvx]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.x3f]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.xht]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.xhtml]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.xla]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.xlam]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.xls]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.xlsb]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.xlsm]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.xlsx]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.xlt]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.xltm]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.xltx]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.xml]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.xps]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.xsl]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.zip]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.?g???]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.?g???]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.?g????]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.?g????]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.?g????????]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\DDECache]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\Directory]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\OpenWithList]


Here ya go!
Fred

#11 dev00790

dev00790

    Bleeping Chocoholic


  • Members
  • 5,037 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:UK
  • Local time:10:34 AM

Posted 17 May 2012 - 06:05 PM

Hi,

Lets try to uninstall Grabee another way. Also the java software you have installed is outdated. We'll uninstall that also, then I'll let you know

Step 1

Uninstalling Programs Using Revo Uninstaller Free

Revo Uninstaller is more thorough in deleting programs on your computer than using the "Add / Remove Programs" / "Programs and Features" option in Windows.
Since it is a more powerful tool, please be sure to follow the instructions carefully.

Please note there is a chance when you look for this program to uninstall through Revo it might not be listed because of the previous uninstall.
If that is the case simply stop and let me know.

  • Please download and install Revo Uninstaller Free
  • Double click Revo Uninstaller to run it.
  • From the list of programs double click on the listed program(s), or anything similar, to remove it

    GrabBee (Version: 1.0.7.6)
    
  • When prompted if you want to uninstall click Yes.
  • Be sure the Moderate option is selected then click Next.
  • The program will run, If prompted again click Yes
  • When the built-in uninstaller is finished click on Next
  • Once the program has searched for leftovers click Next.
  • Check the items in bold only on the list then click Delete. You may have to expand some folders by clicking the "+" mark.
  • When prompted click on Yes and then on Next.
  • Put a check on any folders that are found and select Delete
  • When prompted select Yes then Next
  • Once done click Finish.
  • Restart your computer


Step 2


Important Note: Your version of Java is out of date. Older versions have vulnerabilities that malicious sites can use to exploit and infect your system.

Please follow these steps to remove older version Java components and update:
  • Download the latest version of Java Runtime Environment (JRE) Version 6 and save it to your desktop.
  • Select your Platform.
  • Under Which should I choose?, check the box for Windows Offline Installation and save the file to your desktop.
  • Close any programs you may have running - especially your web browser.
Go to Posted Image > Control Panel, double-click on Add/Remove Programs or Programs and Features in Vista/Windows 7 and remove all older versions of Java.
  • Check (highlight) any item with Java Runtime Environment (JRE or J2SE) or Java in the name.
  • Click the Remove or Change/Remove button and follow the onscreen instructions for the Java uninstaller.
  • Repeat as many times as necessary to remove each Java versions.
  • Reboot your computer once all Java components are removed.
  • Then from your desktop double-click on jre-6u32-windows-i586.exe (or jre-6u32-windows-x64.exe for 64-bit) to install the newest version.
  • If using Windows 7 or Vista and the installer refuses to launch due to insufficient user permissions, then Run As Administrator.
  • When the Java Setup - Welcome window opens, click the Install > button.
  • If offered to install a Toolbar, just uncheck the box before continuing unless you want it.
  • The McAfee Security Scan Plus tool is installed by default unless you uncheck the McAfee installation box when updating Java.
-- Java is updated frequently. If you want to be automatically notified of future updates, just turn on the Java Automatic Update feature and you will not have to remember to update when Java releases a new version.

Note: The Java Quick Starter (JQS.exe) adds a service to improve the initial startup time of Java applets and applications but it's not necessary.
To disable the JQS service if you don't want to use it:
  • Go to Start > Control Panel > Java > Advanced > Miscellaneous and uncheck the box for Java Quick Starter.
  • Click Ok and reboot your computer.

Step 3

How is your computer running now?


Regards, dev00790

---------------------------------------

Marge: "Homer, the plant called. They said if you don't show up tomorrow don't bother showing up on Monday." Homer: "Woo-hoo! Four-day weekend!"I do not reply to Private Messages (PMs) asking for assistance - please use the forums instead. If I have been helping you, and I have not replied to your latest post in 48 hours please send me a PM. My Blog


#12 dev00790

dev00790

    Bleeping Chocoholic


  • Members
  • 5,037 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:UK
  • Local time:10:34 AM

Posted 20 May 2012 - 06:21 AM

Hi

Are you still with me?

Regards, dev00790

---------------------------------------

Marge: "Homer, the plant called. They said if you don't show up tomorrow don't bother showing up on Monday." Homer: "Woo-hoo! Four-day weekend!"I do not reply to Private Messages (PMs) asking for assistance - please use the forums instead. If I have been helping you, and I have not replied to your latest post in 48 hours please send me a PM. My Blog


#13 Fireboss

Fireboss
  • Topic Starter

  • Members
  • 9 posts
  • OFFLINE
  •  
  • Local time:05:34 AM

Posted 20 May 2012 - 09:34 AM

Yes sorry, Yesterday was oddly busy and I forgot to reply.

I ran Revo. It didn't say it couldn't find the install information as Windows had done. The uninstall process seemed to work as designed and it finally said uninstall was complete. I moved on to the Java removal and reinstall and completed that as well.
I restarted and ran CCleaner to peak at the registry leftovers. Instead of two foreign language entries I found these again inthe unused file extension list.
HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.灪g圮孡쥊̧Đ
HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.灪g圮孡쳊̧Đ
HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.灪g圮攍肖Đ
HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.灪g圮攍肖Đ
HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.灪gꕅ癞ꕅ癞圮奈撋찬Đ
HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.灪gꕅ癞ꕅ癞圮奈礋찬Đ
HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.灪gꕅ癞ꕅ癞圮姽�財Đ

I had not deleted the two that I told you about last time, so in effect there were five new entries. I restarted a couple of times during the GrabBee and Java removal processes and since these tend to appear after restart I suspect that's when they were added.

This morning I searched my C:\ for GrabBee (and later videohome the company writing the software)references and found all of the directories still there. This is the first time I've had Revo fail to zap something and my curiosity led me to run a quick registry search for for those items and found that, as far as I could tell, none had been deleted. At this point I manually deleted the files and directories from the drive then did the same for somewhere around 24 registry entries - mostly pointers to their directories and dlls. CCleaner then dumped the dead install links for Java and the foreign keys shown above. I restarted and everything is clean now, no GrabBee mentions and no foreign language keys.

I haven't tried to install anything so I don't know for sure if the "pending install" error is still there bur I have to update my backup software today so depending on how that installer acts I may find out then.

Edited by Fireboss, 20 May 2012 - 09:41 AM.


#14 dev00790

dev00790

    Bleeping Chocoholic


  • Members
  • 5,037 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:UK
  • Local time:10:34 AM

Posted 20 May 2012 - 06:11 PM

Hi

Be careful when editing the registry - it is very easy to end up with an unbootable computer if a mistake is made.

Also I forgot to mention, since a Trojan was found..

ESET found one item
C:\Users\Chief\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\51\7ca274f3-30dd1755 Java/Exploit.CVE-2012-0507.AM trojan deleted - quarantined


IMPORTANT NOTE: One or more of the identified infections is a backdoor Trojan.

Backdoor Trojans, Botnets, and IRCBots are very dangerous because they compromise system integrity by making changes that allow it to be used by the attacker for malicious purposes.
They can disable your anti-virus and security tools to prevent detection and removal. Remote attackers use backdoors as a means of accessing and taking control of a computer that bypasses security mechanisms.
This type of exploit allows them to steal sensitive information like passwords, personal and financial data which is then sent back to the hacker.
Read Danger: Remote Access Trojans.

You should disconnect the computer from the Internet and from any networked computers until it is cleaned. If your computer was used for online banking, paying bills, has credit card information or other sensitive data on it, all passwords should be changed immediately to include those used for taxes, email, eBay, paypal and any other online activities.
You should consider them to be compromised and change passwords from a clean computer, not the infected one. If not, an attacker may get the new passwords and transaction information.
Banking and credit card institutions should be notified immediately of the possible security breach. Failure to notify your financial institution and local law enforcement can result in refusal to reimburse funds lost due to fraud or similar criminal activity.
If using a router, you need to reset it with a strong logon/password before connecting again.

Although the infection has been identified and may be removed, your machine has likely been compromised and there is no way to be sure the computer can ever be trusted again. It is dangerous and incorrect to assume the computer is secure even if the malware appears to have been removed.
In some instances an infection may have caused so much damage to your system that it cannot be successfully cleaned or repaired. The malware may leave so many remnants behind that security tools cannot find them.
Many experts in the security community believe that once infected with this type of malware, the best course of action is to wipe the drive clean, reformat and reinstall the OS. Please read:

Whenever a system has been compromised by a backdoor payload, it is impossible to know if or how much the backdoor has been used to affect your system...There are only a few ways to return a compromised system to a confident security configuration. These include:
Reimaging the system
Restoring the entire system using a full system backup from before the backdoor infection
Reformatting and reinstalling the system

Backdoors and What They Mean to You

This is what Jesper M. Johansson, Security Program Manager at Microsoft TechNet has to say:

The only way to clean a compromised system is to flatten and rebuild. That's right. If you have a system that has been completely compromised, the only thing you can do is to flatten the system (reformat the system disk) and rebuild it from scratch (reinstall Windows and your applications).

Help: I Got Hacked. Now What Do I Do?.

We will do our best to clean the computer of any infections seen on the log.
However, because of the nature of this Trojan, I cannot offer a total
guarantee that there are no remnants left in the system, or that the
computer will be trustworthy.

Many security experts believe that once infected with this type of Trojan,
the best course of action is to reformat and reinstall the Operating System.
Making this decision is based on what the computer is used for, and what
information can be accessed from it.

Knowing the above, do you wish to proceed with cleaning the malware from the computer?

Regards, dev00790

---------------------------------------

Marge: "Homer, the plant called. They said if you don't show up tomorrow don't bother showing up on Monday." Homer: "Woo-hoo! Four-day weekend!"I do not reply to Private Messages (PMs) asking for assistance - please use the forums instead. If I have been helping you, and I have not replied to your latest post in 48 hours please send me a PM. My Blog


#15 Fireboss

Fireboss
  • Topic Starter

  • Members
  • 9 posts
  • OFFLINE
  •  
  • Local time:05:34 AM

Posted 22 May 2012 - 10:26 AM

I should have said earlier that I'm not a novice having been an IT admin for a few years and reaching back to early Wang systems and Novell before thin clients and Windows server so I am aware of the dangers of registry tampering. Knowing what I don't know leads me to ask for help as I did in this case and it is much appreciated.

Having read through the links I'd be pretty silly to trust the installation. Since I don't know when the infection occurred though presumably March or after and since I was gone some of that time April is most likely I'd need a system image from Feb and I don't have that. A server issue dumped my backups so I'll have to clean reinstall which is best anyway. I keep data off the system drive except quicken which raises a fuss when I tried to do it, so it's simply a question of setting a day aside to do it.

Thanks for your help. I think I can take it from here. . . Let's see, format C: :P




0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users