Jump to content


 


Register a free account to unlock additional features at BleepingComputer.com
Welcome to BleepingComputer, a free community where people like yourself come together to discuss and learn how to use their computers. Using the site is easy and fun. As a guest, you can browse and view the various discussions in the forums, but can not create a new topic or reply to an existing one unless you are logged in. Other benefits of registering an account are subscribing to topics and forums, creating a blog, and having no ads shown anywhere on the site.


Click here to Register a free account now! or read our Welcome Guide to learn how to use this site.

Photo

malicious website blocked - 48.dnsqa.me domain


  • This topic is locked This topic is locked
12 replies to this topic

#1 bgonzo

bgonzo

  • Members
  • 6 posts
  • OFFLINE
  •  
  • Local time:05:14 PM

Posted 02 December 2015 - 09:21 PM

I'm new to this forum and I'm looking for help with what I believe is malware on my computer.  I installed Malwarebytes, which cleaned up most of the problems, but I'm still getting notices from Malwarebytes  saying that it has blocked a malicious site with domain name 48.dnsqa.me  (I attached the popup)

 

Any idea which malware is causing this?  What is my best course of action to remove?



BC AdBot (Login to Remove)

 


#2 bgonzo

bgonzo
  • Topic Starter

  • Members
  • 6 posts
  • OFFLINE
  •  
  • Local time:05:14 PM

Posted 02 December 2015 - 09:30 PM

I'm new to this forum and looking for help removing what I believe is malware on my computer.  I installed Malwarebytes free trail, which cleaned up the majority of my problems, but I'm still getting notices while using Internet explorer saying "Malicious website Blocked" with domain 48.dnsqa.me

 

any idea what malware this might be?  And more importantly, best course of action to remove?

 

I've attached screenshot of Malwarebytes notice if it helps.

Attached Files



#3 nasdaq

nasdaq

  • Malware Response Team
  • 38,922 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Montreal, QC. Canada
  • Local time:07:14 PM

Posted 03 December 2015 - 09:59 AM

Hello, Welcome to BleepingComputer.
I'm nasdaq and will be helping you.

If you can please print this topic it will make it easier for you to follow the instructions and complete all of the necessary steps in the order listed.
===

Please download AdwCleaner by Xplode onto your Desktop.
  • Close all open programs and internet browsers.
  • Double click on AdwCleaner.exe to run the tool.
  • Click the Scan button and wait for the process to complete.
  • Click the LogFile button and the report will open in Notepad.
IMPORTANT
  • If you click the Clean button all items listed in the report will be removed.
If you find some false positive items or programs that you wish to keep, Close the AdwCleaner windows.
  • Close all open programs and internet browsers.
  • Double click on AdwCleaner.exe to run the tool.
  • Click the Scan button and wait for the process to complete.
  • Check off the element(s) you wish to keep.
  • Click on the Clean button follow the prompts.
  • A log file will automatically open after the scan has finished.
  • Please post the content of that log file with your next answer.
  • You can find the log file at C:\AdwCleanerCx.txt (x is a number).
===


Download the version of this tool for your operating system.
Farbar Recovery Scan Tool (64 bit)
Farbar Recovery Scan Tool (32 bit)
and save it to a folder on your computer's Desktop.
Double-click to run it. When the tool opens click Yes to disclaimer.
Press Scan button.
It will make a log (FRST.txt) in the same directory the tool is run. Please copy and paste it to your reply.
The first time the tool is run, it makes also another log (Addition.txt). Please attach it to your reply.

How to attach a file to your reply:
In the Reply section in the bottom of the topic Click the "more reply Options" button.
attachlogs.png

Attach the file.
Select the "Choose a File" navigate to the location of the File.
Click the file you wish to Attach.

Click the Add reply button.
===


How is the computer running now?
Wait for further instructions.

#4 bgonzo

bgonzo
  • Topic Starter

  • Members
  • 6 posts
  • OFFLINE
  •  
  • Local time:05:14 PM

Posted 04 December 2015 - 07:47 PM

Thank you for your reply.

 

I have attached all of the requested information

 

 

Attached Files



#5 nasdaq

nasdaq

  • Malware Response Team
  • 38,922 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Montreal, QC. Canada
  • Local time:07:14 PM

Posted 05 December 2015 - 11:31 AM

Run the AdwCleaner tool and remove these items.

Key Found : HKCU\Software\tstamptoken
Key Found : HKCU\Software\AppDataLow\Software\adawarebp


==

Press the windows key Windows_Logo_key.gif+ r on your keyboard at the same time. This will open the RUN BOX.
Type Notepad and and click the OK key.
Please copy the entire contents of the code box below to the a new file.
 
start

CreateRestorePoint:
EmptyTemp:
CloseProcesses:

HKLM\...\Run: [] => [X]
Winlogon\Notify\SDWinLogon-x32: SDWinLogon.dll [X]
GroupPolicy: Restriction - Chrome <======= ATTENTION
CHR HKLM\SOFTWARE\Policies\Google: Restriction <======= ATTENTION
HKLM\SOFTWARE\Policies\Microsoft\Internet Explorer: Restriction <======= ATTENTION
HKU\S-1-5-21-712811262-1525229126-99551323-1000\SOFTWARE\Policies\Microsoft\Internet Explorer: Restriction <======= ATTENTION
Toolbar: HKU\S-1-5-21-712811262-1525229126-99551323-1000 -> No Name - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - No File
FF Plugin: @microsoft.com/GENUINE -> disabled [No File]
FF Plugin-x32: @microsoft.com/GENUINE -> disabled [No File]
FF Plugin-x32: @TrendMicro.com/FFExtension -> C:\Program Files\Trend Micro\Titanium\UIFramework\Toolbar\firefoxextension\components\npToolbarChrome.dll [No File]
CHR HKLM-x32\...\Chrome\Extension: [gomekmidlodglbbmalcneegieacbdmki] - C:\Program Files\AVAST Software\Avast\WebRep\Chrome\aswWebRepChrome.crx [2010-01-21
CHR HKLM-x32\...\Chrome\Extension: [heoldelcflnigdllmlopiefhkkobendj] - <no Path/update_url>
S4 IDriverT; "C:\Program Files (x86)\Common Files\InstallShield\Driver\1150\Intel 32\IDriverT.exe" [X]
Task: {0257A63C-0C9B-4135-BA6B-0C6503031185} - System32\Tasks\WKOEHUFYR => C:\ProgramData\688bac24d8294ddc9b97a10de5058423\688bac24d8294ddc9b97a10de5058423.exe <==== ATTENTION
Task: {7FCE4AE0-9A30-4DDE-8F28-A363C30BBE45} - \HDNINSTSCHD -> No File <==== ATTENTION
C:\ProgramData\688bac24d8294ddc9b97a10de5058423

End
Save the file as fixlist.txt in the same folder where the Farbar tool is running from.
The location is listed in the 3rd line of the Farbar log you have submitted.

Run FRST and click Fix only once and wait.

Restart the computer normally to reset the registry.

The tool will create a log (Fixlog.txt) please post it to your reply.
===

Reset Internet Explorer:
Menu > Tools > Internet Options > Advanced Tab.
Click the Reset button on the bottom of the pane.
Click the Apply button.
Close IE.


Clean the Internet Explorer Cache.
https://kb.wisc.edu/page.php?id=15141

For IE 10, 11 follow the following instructions.
http://refreshyourcache.com/en/internet-explorer-11/
===

How to clear cache and browsing history with Microsoft Edge
http://www.techulator.com/resources/14556-How-to-clear-cache-and-browsing-history-with-Microsoft-Edge.aspx


How is the computer running now?

#6 bgonzo

bgonzo
  • Topic Starter

  • Members
  • 6 posts
  • OFFLINE
  •  
  • Local time:05:14 PM

Posted 06 December 2015 - 01:36 PM

Thanks for your help.  here is the file you requested.

 

 

 

 

 

Fix result of Farbar Recovery Scan Tool (x64) Version:05-12-2015
Ran by Alyssa Gehring (2015-12-02 23:09:22) Run:2
Running from C:\Users\Alyssa Gehring\Desktop\malware
Loaded Profiles: Alyssa Gehring (Available Profiles: Alyssa Gehring)
Boot Mode: Normal
==============================================

fixlist content:
*****************
start

CreateRestorePoint:
EmptyTemp:
CloseProcesses:

HKLM\...\Run: [] => [X]
Winlogon\Notify\SDWinLogon-x32: SDWinLogon.dll [X]
GroupPolicy: Restriction - Chrome <======= ATTENTION
CHR HKLM\SOFTWARE\Policies\Google: Restriction <======= ATTENTION
HKLM\SOFTWARE\Policies\Microsoft\Internet Explorer: Restriction <======= ATTENTION
HKU\S-1-5-21-712811262-1525229126-99551323-1000\SOFTWARE\Policies\Microsoft\Internet Explorer: Restriction <======= ATTENTION
Toolbar: HKU\S-1-5-21-712811262-1525229126-99551323-1000 -> No Name - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - No File
FF Plugin: @microsoft.com/GENUINE -> disabled [No File]
FF Plugin-x32: @microsoft.com/GENUINE -> disabled [No File]
FF Plugin-x32: @TrendMicro.com/FFExtension -> C:\Program Files\Trend Micro\Titanium\UIFramework\Toolbar\firefoxextension\components\npToolbarChrome.dll [No File]
CHR HKLM-x32\...\Chrome\Extension: [gomekmidlodglbbmalcneegieacbdmki] - C:\Program Files\AVAST Software\Avast\WebRep\Chrome\aswWebRepChrome.crx [2010-01-21
CHR HKLM-x32\...\Chrome\Extension: [heoldelcflnigdllmlopiefhkkobendj] - <no Path/update_url>
S4 IDriverT; "C:\Program Files (x86)\Common Files\InstallShield\Driver\1150\Intel 32\IDriverT.exe" [X]
Task: {0257A63C-0C9B-4135-BA6B-0C6503031185} - System32\Tasks\WKOEHUFYR => C:\ProgramData\688bac24d8294ddc9b97a10de5058423\688bac24d8294ddc9b97a10de5058423.exe <==== ATTENTION
Task: {7FCE4AE0-9A30-4DDE-8F28-A363C30BBE45} - \HDNINSTSCHD -> No File <==== ATTENTION
C:\ProgramData\688bac24d8294ddc9b97a10de5058423

End

*****************

Restore point was successfully created.
Processes closed successfully.
HKLM\Software\Microsoft\Windows\CurrentVersion\Run\\ => value not found.
HKLM\Software\Wow6432Node\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\SDWinLogon => key not found.
"C:\windows\system32\GroupPolicy\Machine" => not found.
HKLM\SOFTWARE\Policies\Google => key not found.
HKLM\SOFTWARE\Policies\Microsoft\Internet Explorer => key not found.
HKU\S-1-5-21-712811262-1525229126-99551323-1000\SOFTWARE\Policies\Microsoft\Internet Explorer => key not found.
HKU\S-1-5-21-712811262-1525229126-99551323-1000\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\\{2318C2B1-4965-11D4-9B18-009027A5CD4F} => value not found.
HKCR\CLSID\{2318C2B1-4965-11D4-9B18-009027A5CD4F} => key not found.
HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE => key not found.
HKLM\Software\Wow6432Node\MozillaPlugins\@microsoft.com/GENUINE => key not found.
HKLM\Software\Wow6432Node\MozillaPlugins\@TrendMicro.com/FFExtension => key not found.
HKLM\SOFTWARE\Wow6432Node\Google\Chrome\Extensions\gomekmidlodglbbmalcneegieacbdmki => key not found.
HKLM\SOFTWARE\Wow6432Node\Google\Chrome\Extensions\heoldelcflnigdllmlopiefhkkobendj => key not found.
IDriverT => service not found.
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{0257A63C-0C9B-4135-BA6B-0C6503031185} => key not found.
C:\windows\System32\Tasks\WKOEHUFYR => not found.
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\WKOEHUFYR => key not found.
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{7FCE4AE0-9A30-4DDE-8F28-A363C30BBE45} => key not found.
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\HDNINSTSCHD => key not found.
"C:\ProgramData\688bac24d8294ddc9b97a10de5058423" => not found.
EmptyTemp: => 88.3 MB temporary data Removed.

The system needed a reboot.

==== End of Fixlog 23:10:39 ====



#7 nasdaq

nasdaq

  • Malware Response Team
  • 38,922 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Montreal, QC. Canada
  • Local time:07:14 PM

Posted 07 December 2015 - 08:20 AM

Any remaining issues?

If all is well.

To learn more about how to protect yourself while on the internet read this little guide best security practices keep safe.
http://www.bleepingcomputer.com/forums/t/407147/answers-to-common-security-questions-best-practices/
===

#8 bgonzo

bgonzo
  • Topic Starter

  • Members
  • 6 posts
  • OFFLINE
  •  
  • Local time:05:14 PM

Posted 08 December 2015 - 09:01 PM

All the Pop-ups seem to be fixed, but the browser is still running a little slow at times.  Also, the computer does keep the correct time. I'm not sure if this is related to the Malware.

 

I really do appreciate your help. 

I am very impressed with the tools and how good you guys are at figuring this stuff out.  I'd like to know more about how to use them.  Are there any good tutorials on this site

 

I re-ran the tools and attached the new files for you to review if you don't mind.

Attached Files



#9 nasdaq

nasdaq

  • Malware Response Team
  • 38,922 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Montreal, QC. Canada
  • Local time:07:14 PM

Posted 09 December 2015 - 09:59 AM

I am very impressed with the tools and how good you guys are at figuring this stuff out. I'd like to know more about how to use them. Are there any good tutorials on this site

Do the required training.
Start here and follow the instructions.
http://www.bleepingcomputer.com/forums/t/145165/getting-started-on-the-exercises/
===



Please run the AdwCleaner tool and remove that entry.

Key Found : HKCU\Software\AppDataLow\Software\adawarebp

===

Press the windows key Windows_Logo_key.gif+ r on your keyboard at the same time. This will open the RUN BOX.
Type Notepad and and click the OK key.
Please copy the entire contents of the code box below to the a new file.


start

CreateRestorePoint:
EmptyTemp:
CloseProcesses:

Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} -  No File
CHR HKLM-x32\...\Chrome\Extension: [gomekmidlodglbbmalcneegieacbdmki] - C:\Program Files\AVAST Software\Avast\WebRep\Chrome\aswWebRepChrome.crx [2010-01-21]
Task: {0257A63C-0C9B-4135-BA6B-0C6503031185} - System32\Tasks\WKOEHUFYR => C:\ProgramData\688bac24d8294ddc9b97a10de5058423\688bac24d8294ddc9b97a10de5058423.exe <==== ATTENTION
Task: {7FCE4AE0-9A30-4DDE-8F28-A363C30BBE45} - \HDNINSTSCHD -> No File <==== ATTENTION
C:\ProgramData\688bac24d8294ddc9b97a10de5058423\688bac24d8294ddc9b97a10de5058423.exe

End
Save the file as fixlist.txt in the same folder where the Farbar tool is running from.
The location is listed in the 3rd line of the Farbar log you have submitted.

Run FRST and click Fix only once and wait.

Restart the computer normally to reset the registry.

The tool will create a log (Fixlog.txt) please post it to your reply.
===

Please download SystemLook from one of the links below and save it to your Desktop.
Download Mirror #1
Download Mirror #2


If your operating system is 64 bit download this tool:
SystemLook_x64.exe
  • Double-click SystemLook.exe
  • to run it.
  • Copy and paste the content
  • of the following bold text into the main textfield:
    :reg
    HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks /sub
    HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree /sub
  • Click the Look button to start the scan.
  • When finished, a notepad window will open with the results of the scan. Please post this log in your next reply.
  • Note: The log can also be found on your Desktop entitled SystemLook.txt.
===

#10 bgonzo

bgonzo
  • Topic Starter

  • Members
  • 6 posts
  • OFFLINE
  •  
  • Local time:05:14 PM

Posted 09 December 2015 - 09:31 PM

Thanks again. 
 
Here are the files you requested.

SystemLook 30.07.11 by jpshortstuff
Log created at 21:14 on 07/12/2015 by Alyssa Gehring
Administrator - Elevation successful

========== reg ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks]
(No values found)

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{044A6734-E90E-4F8F-B357-B2DC8AB3B5EC}]
"Path"="\Microsoft\Windows\Time Synchronization\SynchronizeTime"
"Triggers"=15 00 00 00 00 00 00 00 01 12 72 fb fe 07 00 00 00 e8 e6 37 9d ef c4 01 00 12 72 fb fe 07 00 00 ff ff ff ff ff ff ff ff e0 21 42 03 48 48 48 48 df dc 78 36 48 48 48 48 00 48 48 48 48 48 48 48 00 48 48 48 48 48 48 48 05 00 00 00 48 48 48 48 0c 00 00 00 48 48 48 48 01 01 00 00 00 00 00 05 13 00 00 00 48 48 48 48 00 00 00 00 48 48 48 48 00 00 00 00 48 48 48 48 dd dd 00 00 00 00 00 00 01 12 72 fb fe 07 00 00 00 e8 e6 37 9d ef c4 01 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ff ff ff ff 02 00 00 00 01 00 01 00 00 00 00 00 00 01 00 00 01 00 00 00 00 00 00 00 00 00 00 00 (REG_BINARY)
"DynamicInfo"=03 00 00 00 2d 35 04 2d 41 04 ca 01 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 (REG_BINARY)
"Hash"=17 d3 bd 88 4b e1 ea d4 b4 b3 2c c4 6d 07 07 e4 68 68 8a 3f cd e1 83 55 73 bf 3a 39 2d 0b f6 5a (REG_BINARY)

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{088482FA-65B8-4E17-9ABF-1DCD48E8D373}]
"Path"="\Microsoft\Windows\Tcpip\IpAddressConflict1"
"Triggers"=15 00 00 00 00 00 00 00 00 1c 24 fb fe 07 00 00 00 00 00 00 00 00 00 00 00 1c 24 fb fe 07 00 00 ff ff ff ff ff ff ff ff 38 a1 40 03 48 48 48 48 e9 9d 60 08 48 48 48 48 00 48 48 48 48 48 48 48 00 48 48 48 48 48 48 48 04 00 00 00 48 48 48 48 10 00 00 00 48 48 48 48 01 02 00 00 00 00 00 05 20 00 00 00 21 02 00 00 00 00 00 00 48 48 48 48 38 00 00 00 48 48 48 48 58 02 00 00 10 0e 00 00 80 f4 03 00 ff ff ff ff 07 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 cc cc 00 00 00 00 00 00 00 1c 24 fb fe 07 00 00 00 00 00 00 00 00 00 00 00 1c 24 fb fe 07 00 00 ff ff ff ff ff ff ff ff 00 00 00 00 ff ff ff ff 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 01 01 00 00 00 00 00 05 20 00 00 00 00 00 00 00 8d 00 00 00 00 00 00 00 3c 00 51 00 75 00 65 00 72 00 79 00 4c 00 69 00 73 00 74 00 3e 00 3c 00 51 00 75 00 65 00 72 00 79 00 20 00 49 00 64 00 3d 00 22 00 30 00 22 00 20 00 50 00 61 00 74 00 68 00 3d 00 22 00 53 00 79 00 73 00 74 00 65 00 6d 00 22 00 3e (REG_BINARY)
"DynamicInfo"=03 00 00 00 8d 96 06 2d 41 04 ca 01 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 (REG_BINARY)
"Hash"=ce f4 fd 5d a0 44 59 b6 0c 16 3c d7 1d 53 80 78 a6 01 ef 7e e0 58 32 ce cd 2d d7 9d 52 13 af 22 (REG_BINARY)

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{098A7198-0DED-43E1-B050-831FAA9E7433}]
"Path"="\Microsoft\Windows\Setup\GWXTriggers\MachineUnlock-5d"
"Hash"=ff 14 8c 56 4a 75 e1 68 99 50 b6 5b 77 97 0a 9c cb 32 72 b2 d1 3b 10 42 9a 89 a6 9c d2 0e 22 99 (REG_BINARY)
"Triggers"=15 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ff ff ff ff ff ff ff ff c8 a1 40 00 48 48 48 48 2d 5b 8f 0e 48 48 48 48 00 48 48 48 48 48 48 48 00 48 48 48 48 48 48 48 05 00 00 00 48 48 48 48 0c 00 00 00 48 48 48 48 01 01 00 00 00 00 00 05 04 00 00 00 48 48 48 48 00 00 00 00 48 48 48 48 38 00 00 00 48 48 48 48 00 00 00 00 ff ff ff ff 00 00 00 00 ff ff ff ff 07 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 77 77 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ff ff ff ff ff ff ff ff 0a 00 00 00 ff ff ff ff 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 01 00 65 00 72 00 73 00 5c 00 4c 00 6f 00 67 00 08 00 00 00 2d 00 35 00 01 48 48 48 48 48 48 48 (REG_BINARY)
"DynamicInfo"=03 00 00 00 57 4e a6 9b 65 31 d1 01 0b f0 82 54 65 31 d1 01 24 13 04 80 00 00 00 00 (REG_BINARY)

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{09F06BFE-A3C8-40E3-846A-6E6F4000C238}]
"Path"="\Microsoft\Windows\Tcpip\IpAddressConflict2"
"Triggers"=15 00 00 00 00 00 00 00 01 12 72 fb fe 07 00 00 80 29 4e 12 96 38 c6 01 00 1c 24 fb fe 07 00 00 ff ff ff ff ff ff ff ff 38 a1 40 03 48 48 48 48 a2 01 fc 43 48 48 48 48 00 48 48 48 48 48 48 48 00 48 48 48 48 48 48 48 04 00 00 00 48 48 48 48 10 00 00 00 48 48 48 48 01 02 00 00 00 00 00 05 20 00 00 00 21 02 00 00 00 00 00 00 48 48 48 48 38 00 00 00 48 48 48 48 58 02 00 00 10 0e 00 00 80 f4 03 00 ff ff ff ff 07 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 75 00 70 00 00 00 00 00 00 00 00 00 cc cc 00 00 00 00 00 00 01 12 72 fb fe 07 00 00 80 29 4e 12 96 38 c6 01 00 1c 24 fb fe 07 00 00 ff ff ff ff ff ff ff ff 00 00 00 00 ff ff ff ff 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 01 01 00 00 00 00 00 05 20 00 00 00 00 00 00 00 8d 00 00 00 00 00 00 00 3c 00 51 00 75 00 65 00 72 00 79 00 4c 00 69 00 73 00 74 00 3e 00 3c 00 51 00 75 00 65 00 72 00 79 00 20 00 49 00 64 00 3d 00 22 00 30 00 22 00 20 00 50 00 61 00 74 00 68 00 3d 00 22 00 53 00 79 00 73 00 74 00 65 00 6d 00 22 00 3e (REG_BINARY)
"DynamicInfo"=03 00 00 00 8d 96 06 2d 41 04 ca 01 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 (REG_BINARY)
"Hash"=4d 3c 72 ee 9b 73 1b fc fc 70 22 53 1b 28 70 de f2 8f f1 3f f8 e0 f0 89 00 3e 02 aa 0f 40 c0 5d (REG_BINARY)

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{0FA766DD-932B-4084-A9FF-79AE4A44089D}]
"Path"="\Microsoft\Windows\Media Center\PvrRecoveryTask"
"Hash"=f1 8e 7e 60 32 25 b0 86 ae 16 05 b0 ed da 4e 41 a1 1a 69 40 f8 c5 05 83 c5 66 54 6d 47 53 db f9 (REG_BINARY)
"Triggers"=15 00 00 00 00 00 00 00 00 ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff 00 ff ff ff ff ff ff ff 00 00 00 00 00 00 00 00 00 05 42 02 48 48 48 48 31 c9 dc aa 48 48 48 48 00 48 48 48 48 48 48 48 00 48 48 48 48 48 48 48 05 00 00 00 48 48 48 48 0c 00 00 00 48 48 48 48 01 01 00 00 00 00 00 05 14 00 00 00 48 48 48 48 00 00 00 00 48 48 48 48 00 00 00 00 48 48 48 48 (REG_BINARY)
"DynamicInfo"=03 00 00 00 4c e7 6d e6 c9 e9 cb 01 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 (REG_BINARY)

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{18DA0B84-C309-45EF-8C8A-97A1DC113FE8}]
"Path"="\Microsoft\Windows\DiskDiagnostic\Microsoft-Windows-DiskDiagnosticDataCollector"
"Hash"=96 15 d0 2c 18 c2 e2 0a 2c 5d 63 73 1d 41 43 f4 9c d1 73 a5 c6 e0 95 84 ea 1a 72 dc 9a 6c ff 48 (REG_BINARY)
"Triggers"=15 00 00 00 00 00 00 00 01 2e a3 01 00 00 00 00 00 68 b6 94 02 d0 c3 01 00 2e a3 01 00 00 00 00 ff ff ff ff ff ff ff ff 52 21 82 02 48 48 48 48 8a ce fd 74 48 48 48 48 00 48 48 48 48 48 48 48 00 48 48 48 48 48 48 48 05 00 00 00 48 48 48 48 0c 00 00 00 48 48 48 48 01 01 00 00 00 00 00 05 12 00 00 00 48 48 48 48 00 00 00 00 48 48 48 48 00 00 00 00 48 48 48 48 dd dd 00 00 00 00 00 00 01 2e a3 01 00 00 00 00 00 68 b6 94 02 d0 c3 01 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ff ff ff ff 02 00 00 00 02 00 01 00 00 00 00 00 00 01 00 00 01 00 00 00 00 00 00 00 00 00 00 00 (REG_BINARY)
"DynamicInfo"=03 00 00 00 c4 bb ba e0 c9 e9 cb 01 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 (REG_BINARY)

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{1DEC0920-1F37-47B6-B678-880E3DB2EB4E}]
"Path"="\Microsoft\Windows\SideShow\SessionAgent"
"Hash"=db c0 65 69 54 55 f1 65 21 c1 f2 cc b4 fb a7 17 57 c5 3f c6 d3 8c 9b 87 fe 41 bf 26 f2 86 e1 59 (REG_BINARY)
"Triggers"=15 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ff ff ff ff ff ff ff ff 00 85 00 02 48 48 48 48 3d 09 f3 7d 48 48 48 48 00 48 48 48 48 48 48 48 00 48 48 48 48 48 48 48 04 00 00 00 48 48 48 48 10 00 00 00 48 48 48 48 01 02 00 00 00 00 00 05 20 00 00 00 21 02 00 00 00 00 00 00 48 48 48 48 38 00 00 00 48 48 48 48 00 00 00 00 ff ff ff ff 00 00 00 00 ff ff ff ff 07 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 aa aa 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ff ff ff ff ff ff ff ff 0f 00 00 00 ff ff ff ff 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 01 00 f5 00 00 00 00 00 05 00 00 00 00 00 00 00 01 48 48 48 48 48 48 48 (REG_BINARY)
"DynamicInfo"=03 00 00 00 7e de 9c e1 c9 e9 cb 01 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 (REG_BINARY)

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{1E559FB1-2EE1-4699-8DAA-145F8A11C1D6}]
"Path"="\Microsoft\Windows\Setup\GWXTriggers\Logon-5d"
"Hash"=e9 8f 29 6c 43 72 11 9d f3 a1 89 df 8d d2 2e 9b ea c0 55 b3 3f 2b 75 2f 9f af 74 98 1c 8f bc b1 (REG_BINARY)
"Triggers"=15 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ff ff ff ff ff ff ff ff c8 a1 40 00 48 48 48 48 53 7d 3c c8 48 48 48 48 00 48 48 48 48 48 48 48 00 48 48 48 48 48 48 48 05 00 00 00 48 48 48 48 0c 00 00 00 48 48 48 48 01 01 00 00 00 00 00 05 04 00 00 00 48 48 48 48 00 00 00 00 48 48 48 48 38 00 00 00 48 48 48 48 00 00 00 00 ff ff ff ff 00 00 00 00 ff ff ff ff 07 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 47 00 24 00 00 00 00 00 00 00 00 00 aa aa 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ff ff ff ff ff ff ff ff 1e 00 00 00 ff ff ff ff 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 01 00 65 00 72 00 2e 00 65 00 78 00 65 00 00 00 01 48 48 48 48 48 48 48 (REG_BINARY)
"DynamicInfo"=03 00 00 00 f3 d6 7d 9b 65 31 d1 01 45 ca 44 84 65 31 d1 01 24 13 04 80 00 00 00 00 (REG_BINARY)

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{1F7B7221-AE8F-44F3-BA82-F7D260F51964}]
"Path"="\Microsoft\Windows\Task Manager\Interactive"
"Triggers"=15 00 00 00 00 00 00 00 00 ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff 00 ff ff ff ff ff ff ff 00 00 00 00 00 00 00 00 00 85 c0 02 48 48 48 48 19 d7 d4 58 48 48 48 48 00 48 48 48 48 48 48 48 00 48 48 48 48 48 48 48 05 00 00 00 48 48 48 48 0c 00 00 00 48 48 48 48 01 01 00 00 00 00 00 05 04 00 00 00 48 48 48 48 00 00 00 00 48 48 48 48 38 00 00 00 48 48 48 48 00 00 00 00 ff ff ff ff 00 00 00 00 ff ff ff ff 05 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 75 00 70 00 00 00 00 00 00 00 00 00 (REG_BINARY)
"DynamicInfo"=03 00 00 00 ee f7 08 2d 41 04 ca 01 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 (REG_BINARY)
"Hash"=89 de 49 d1 46 b9 da 8a 3f 68 6f 98 cc 96 57 67 af cd 97 16 b0 8a 2f c6 51 05 dc 7b 0d dd c5 19 (REG_BINARY)

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{221DE1C1-46D7-4C8B-A009-40A3B2A682DF}]
"Path"="\Microsoft\Windows\Media Center\ReindexSearchRoot"
"Hash"=59 50 0d ac 2b 3d f2 4d d8 eb d0 96 b0 81 79 6c e1 5a 4d 69 9d e7 f0 5b 53 c2 49 61 2f 21 a9 74 (REG_BINARY)
"Triggers"=15 00 00 00 00 00 00 00 00 ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff 00 ff ff ff ff ff ff ff 00 00 00 00 00 00 00 00 00 21 42 02 48 48 48 48 e1 7c f5 63 48 48 48 48 00 48 48 48 48 48 48 48 00 48 48 48 48 48 48 48 05 00 00 00 48 48 48 48 0c 00 00 00 48 48 48 48 01 01 00 00 00 00 00 05 12 00 00 00 48 48 48 48 00 00 00 00 48 48 48 48 00 00 00 00 48 48 48 48 (REG_BINARY)
"DynamicInfo"=03 00 00 00 5d 3d d9 e4 c9 e9 cb 01 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 (REG_BINARY)

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{2470470F-2634-478E-B181-571E98A789BB}]
"Path"="\Microsoft\Windows\Multimedia\SystemSoundsService"
"Triggers"=15 00 00 00 00 00 00 00 00 1c 24 fb fe 07 00 00 00 00 00 00 00 00 00 00 00 1c 24 fb fe 07 00 00 ff ff ff ff ff ff ff ff 00 85 40 02 48 48 48 48 9d 35 12 e9 48 48 48 48 00 48 48 48 48 48 48 48 00 48 48 48 48 48 48 48 04 00 00 00 48 48 48 48 10 00 00 00 48 48 48 48 01 02 00 00 00 00 00 05 20 00 00 00 21 02 00 00 00 00 00 00 48 48 48 48 38 00 00 00 48 48 48 48 00 00 00 00 ff ff ff ff 00 00 00 00 ff ff ff ff 07 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 75 00 70 00 00 00 00 00 00 00 00 00 aa aa 00 00 00 00 00 00 00 1c 24 fb fe 07 00 00 00 00 00 00 00 00 00 00 00 1c 24 fb fe 07 00 00 ff ff ff ff ff ff ff ff 00 00 00 00 ff ff ff ff 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 01 00 00 00 00 00 00 00 00 00 00 00 03 00 00 00 01 48 48 48 48 48 48 48 (REG_BINARY)
"DynamicInfo"=03 00 00 00 2b 2a f1 2c 41 04 ca 01 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 (REG_BINARY)
"Hash"=fd 7b 51 b9 fb 6d dd 39 37 4c 58 66 90 f9 e9 34 ee 65 eb 22 fd 61 53 1b 54 08 b2 05 91 03 1c e2 (REG_BINARY)

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{25FF54D9-FD24-4392-AA5D-9C8DC305E2F7}]
"Path"="\{5E242C37-C240-49A2-B3EC-2A729CF1A930}"
"Hash"=80 12 81 ff 84 76 8b c5 24 a2 38 d1 1f 21 54 b6 aa d0 82 78 9a a4 d5 85 e8 79 af 33 ff da 74 82 (REG_BINARY)
"Triggers"=15 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ff ff ff ff ff ff ff ff 28 21 41 00 48 48 48 48 96 fc 08 b5 48 48 48 48 00 48 48 48 48 48 48 48 00 48 48 48 48 48 48 48 01 00 00 00 48 48 48 48 1c 00 00 00 48 48 48 48 01 05 00 00 00 00 00 05 15 00 00 00 fe a2 7c 2a 46 26 e9 5a 5b 08 ef 05 e8 03 00 00 48 48 48 48 3a 00 00 00 48 48 48 48 41 00 6c 00 79 00 73 00 73 00 61 00 47 00 65 00 68 00 72 00 69 00 6e 00 67 00 5c 00 41 00 6c 00 79 00 73 00 73 00 61 00 20 00 47 00 65 00 68 00 72 00 69 00 6e 00 67 00 00 00 48 48 48 48 48 48 38 00 00 00 48 48 48 48 58 02 00 00 10 0e 00 00 80 f4 03 00 ff ff ff ff 07 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 88 88 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ff ff ff ff ff ff ff ff 00 00 00 00 ff ff ff ff 00 00 00 00 00 00 00 00 00 00 00 00 00 07 00 00 01 00 64 00 6c 00 6c 00 2c 00 2d 00 35 00 30 00 (REG_BINARY)
"DynamicInfo"=03 00 00 00 af 98 0e ed 12 4f d0 01 50 1f 10 ed 12 4f d0 01 00 00 00 00 00 00 00 00 (REG_BINARY)

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{28011108-68DF-4C73-B91B-57427D501BBA}]
"Path"="\Microsoft\Windows\Active Directory Rights Management Services Client\AD RMS Rights Policy Template Management (Manual)"
"Triggers"=15 00 00 00 00 00 00 00 00 1c 24 fb fe 07 00 00 00 00 00 00 00 00 00 00 00 1c 24 fb fe 07 00 00 ff ff ff ff ff ff ff ff f8 85 40 02 48 48 48 48 ce 52 ba aa 48 48 48 48 00 48 48 48 48 48 48 48 00 48 48 48 48 48 48 48 05 00 00 00 48 48 48 48 0c 00 00 00 48 48 48 48 01 01 00 00 00 00 00 01 00 00 00 00 48 48 48 48 00 00 00 00 48 48 48 48 38 00 00 00 48 48 48 48 58 02 00 00 10 0e 00 00 10 0e 00 00 ff ff ff ff 07 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 aa aa 00 00 00 00 00 00 00 1c 24 fb fe 07 00 00 00 00 00 00 00 00 00 00 00 1c 24 fb fe 07 00 00 ff ff ff ff ff ff ff ff 10 0e 00 00 ff ff ff ff 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 03 00 00 00 01 48 48 48 48 48 48 48 (REG_BINARY)
"DynamicInfo"=03 00 00 00 8b 8b f3 2c 41 04 ca 01 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 (REG_BINARY)
"Hash"=62 05 0c 0d 7c 47 49 98 41 4f a2 c4 7e 4d 34 6e ce 62 8d 7d 97 4f 37 7e e3 b8 ae 2e 60 98 2e e3 (REG_BINARY)

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{2B2234B1-38C4-45C1-89AF-F7830EF4C868}]
"Path"="\Microsoft\Windows\Media Center\ConfigureInternetTimeService"
"Hash"=1a 61 fb 30 46 f2 f7 71 f4 36 b6 6e de c9 ee c6 e1 e9 e3 f2 19 aa 42 24 49 59 28 e6 bc 34 7b ee (REG_BINARY)
"Triggers"=15 00 00 00 00 00 00 00 00 ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff 00 ff ff ff ff ff ff ff 00 00 00 00 00 00 00 00 00 21 42 02 48 48 48 48 33 4e c6 99 48 48 48 48 00 48 48 48 48 48 48 48 00 48 48 48 48 48 48 48 05 00 00 00 48 48 48 48 0c 00 00 00 48 48 48 48 01 01 00 00 00 00 00 05 12 00 00 00 48 48 48 48 00 00 00 00 48 48 48 48 00 00 00 00 48 48 48 48 (REG_BINARY)
"DynamicInfo"=03 00 00 00 2b c1 39 e4 c9 e9 cb 01 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 (REG_BINARY)

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{2F57269B-1E09-4E2D-AB1E-B0FDAC7D279C}]
"Path"="\Microsoft\Windows\WindowsBackup\ConfigNotification"
"Triggers"=15 00 00 00 00 00 00 00 01 7e a6 01 00 00 00 00 00 50 d5 04 e3 8e cb 01 00 7e a6 01 00 00 00 00 ff ff ff ff ff ff ff ff 48 21 02 02 48 48 48 48 62 6a 99 87 48 48 48 48 00 48 48 48 48 48 48 48 00 48 48 48 48 48 48 48 05 00 00 00 48 48 48 48 0c 00 00 00 48 48 48 48 01 01 00 00 00 00 00 05 13 00 00 00 48 48 48 48 00 00 00 00 48 48 48 48 38 00 00 00 48 48 48 48 00 00 00 00 ff ff ff ff 80 f4 03 00 ff ff ff ff 07 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 72 00 00 00 00 00 00 00 00 00 00 00 dd dd 00 00 00 00 00 00 01 7e a6 01 00 00 00 00 00 50 d5 04 e3 8e cb 01 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ff ff ff ff 01 00 00 00 01 00 00 00 00 00 00 00 00 01 00 00 01 00 00 00 00 00 00 00 00 00 00 00 (REG_BINARY)
"DynamicInfo"=03 00 00 00 4e 59 0b 2d 41 04 ca 01 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 (REG_BINARY)
"Hash"=9d 84 39 90 45 bf 98 66 89 69 a2 64 c2 a5 71 f2 50 9f 22 71 45 b2 ac 6c 74 fe 8e 17 41 a3 7a 8c (REG_BINARY)

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{2F70EC75-51D6-438E-A0BE-EAE9C04234BE}]
"Path"="\Microsoft\Windows\Media Center\ehDRMInit"
"Hash"=9b 2b ff 88 25 66 9b 3c 37 27 48 41 8c c0 eb 39 c7 19 bd ae bc d6 76 cc 7b 39 e1 02 26 01 a0 bf (REG_BINARY)
"Triggers"=15 00 00 00 00 00 00 00 00 ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff 00 ff ff ff ff ff ff ff 00 00 00 00 00 00 00 00 00 21 42 02 48 48 48 48 e8 dd c7 3b 48 48 48 48 00 48 48 48 48 48 48 48 00 48 48 48 48 48 48 48 05 00 00 00 48 48 48 48 0c 00 00 00 48 48 48 48 01 01 00 00 00 00 00 05 13 00 00 00 48 48 48 48 00 00 00 00 48 48 48 48 00 00 00 00 48 48 48 48 (REG_BINARY)
"DynamicInfo"=03 00 00 00 7e e0 c9 e3 c9 e9 cb 01 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 (REG_BINARY)

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{2F9EEE9D-35EC-49C7-A66A-6052F65BEB60}]
"Path"="\Microsoft\Windows\Media Center\RecordingRestart"
"Hash"=f5 fe 54 70 24 9e a9 5d e2 cb 01 d9 fa 91 0f b3 19 57 ed 0f b0 f9 e0 32 08 a3 70 81 a0 57 aa 08 (REG_BINARY)
"Triggers"=15 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ff ff ff ff ff ff ff ff 60 05 02 02 48 48 48 48 3e 01 cf af 48 48 48 48 00 48 48 48 48 48 48 48 00 48 48 48 48 48 48 48 05 00 00 00 48 48 48 48 0c 00 00 00 48 48 48 48 01 01 00 00 00 00 00 05 14 00 00 00 48 48 48 48 00 00 00 00 48 48 48 48 38 00 00 00 48 48 48 48 00 00 00 00 ff ff ff ff 80 f4 03 00 ff ff ff ff 06 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ff ff 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ff ff ff ff ff ff ff ff 00 00 00 00 ff ff ff ff 00 00 00 00 00 00 00 00 00 00 00 00 00 07 00 00 01 ff 38 01 00 00 00 00 05 00 00 00 00 00 00 00 (REG_BINARY)
"DynamicInfo"=03 00 00 00 36 f6 6b e2 c9 e9 cb 01 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 (REG_BINARY)

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{304CE3F4-C2D2-459B-957F-BF9B51BA823F}]
"Path"="\Microsoft\Windows\Setup\gwx\refreshgwxconfigandcontent"
"Hash"=6d ae bd c0 bc 37 f8 0d 4a 7b eb 38 4c 9c a7 05 a0 ad e5 9f e4 24 f5 b8 4c f1 0a 66 64 6d be bf (REG_BINARY)
"Triggers"=15 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 a2 cb 01 00 00 00 00 ff ff ff ff ff ff ff ff c0 21 42 03 48 48 48 48 70 62 5d af 48 48 48 48 00 48 48 48 48 48 48 48 00 48 48 48 48 48 48 48 05 00 00 00 48 48 48 48 0c 00 00 00 48 48 48 48 01 01 00 00 00 00 00 05 12 00 00 00 48 48 48 48 00 00 00 00 48 48 48 48 38 00 00 00 48 48 48 48 00 00 00 00 ff ff ff ff 00 00 00 00 ff ff ff ff 07 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 dd dd 00 00 00 00 00 00 01 a2 cb 01 00 00 00 00 00 20 16 76 a6 46 ce 01 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ff ff ff ff 01 00 00 00 01 00 00 00 00 00 00 00 00 01 00 00 01 00 00 00 80 51 01 00 00 00 00 00 88 88 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ff ff ff ff ff ff ff ff 00 00 00 00 ff ff ff ff 00 00 00 00 00 00 00 00 00 00 00 00 00 07 00 00 01 d9 ca 01 00 (REG_BINARY)
"DynamicInfo"=03 00 00 00 33 af a4 16 1f 24 d1 01 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 (REG_BINARY)

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{3089006A-9FDB-4777-A1F5-4DE44CA32C13}]
"Path"="\Microsoft\Windows\Media Center\OCURActivate"
"Hash"=21 f0 c7 10 01 fd ad 40 60 d1 34 f2 91 4f 03 6d 1d aa 81 4d 9c f6 20 6b 8b be a1 d0 9a c5 12 5b (REG_BINARY)
"Triggers"=15 00 00 00 00 00 00 00 00 ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff 00 ff ff ff ff ff ff ff 00 00 00 00 00 00 00 00 00 21 42 02 48 48 48 48 c7 42 2e af 48 48 48 48 00 48 48 48 48 48 48 48 00 48 48 48 48 48 48 48 05 00 00 00 48 48 48 48 0c 00 00 00 48 48 48 48 01 01 00 00 00 00 00 05 12 00 00 00 48 48 48 48 00 00 00 00 48 48 48 48 00 00 00 00 48 48 48 48 (REG_BINARY)
"DynamicInfo"=03 00 00 00 98 e3 97 e3 c9 e9 cb 01 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 (REG_BINARY)

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{3341F5D4-4C5F-4439-82FB-9B6B73E1835A}]
"Path"="\Adobe Flash Player Updater"
"Hash"=3a 3f f8 b3 6c 03 49 b6 31 73 36 8f 7d a6 91 2b 67 91 cd 7e 60 51 d9 6f bf dd 23 8a 42 a5 b8 33 (REG_BINARY)
"Triggers"=15 00 00 00 00 00 00 00 01 45 15 01 00 00 00 00 00 60 21 35 bc 53 bf 01 00 45 15 01 00 00 00 00 ff ff ff ff ff ff ff ff 28 21 62 00 48 48 48 48 f3 ba b5 68 48 48 48 48 00 48 48 48 48 48 48 48 00 48 48 48 48 48 48 48 05 00 00 00 48 48 48 48 0c 00 00 00 48 48 48 48 01 01 00 00 00 00 00 05 12 00 00 00 48 48 48 48 00 00 00 00 48 48 48 48 38 00 00 00 48 48 48 48 58 02 00 00 10 0e 00 00 80 f4 03 00 ff ff ff ff 09 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 dd dd 00 00 00 00 00 00 01 45 15 01 00 00 00 00 00 60 21 35 bc 53 bf 01 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 10 0e 00 00 80 51 01 00 ff ff ff ff 01 00 00 00 01 00 00 00 00 00 00 00 00 01 00 00 01 00 00 00 00 00 00 00 00 00 00 00 (REG_BINARY)
"DynamicInfo"=03 00 00 00 79 be dd f1 0e 11 cd 01 3d 8b 32 e1 67 31 d1 01 00 00 00 00 00 00 00 00 (REG_BINARY)

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{361B4002-7C44-466D-A7FB-3850FA6835BE}]
"Path"="\{B300C4A2-060B-476F-B780-03EB7ED2234E}"
"Hash"=d8 bc cc 54 36 04 50 61 44 06 9b 2f 4e a0 cc ed 4d 4c 8b 55 3c 6a 5d 3a bf 9c 6e 49 2b 2b 33 44 (REG_BINARY)
"Triggers"=15 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ff ff ff ff ff ff ff ff 08 a1 40 00 48 48 48 48 4a 40 9f df 48 48 48 48 00 48 48 48 48 48 48 48 00 48 48 48 48 48 48 48 04 00 00 00 48 48 48 48 10 00 00 00 48 48 48 48 01 02 00 00 00 00 00 05 20 00 00 00 21 02 00 00 00 00 00 00 48 48 48 48 38 00 00 00 48 48 48 48 58 02 00 00 10 0e 00 00 80 f4 03 00 ff ff ff ff 07 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 88 88 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ff ff ff ff ff ff ff ff 00 00 00 00 ff ff ff ff 00 00 00 00 00 00 00 00 00 00 00 00 00 07 00 00 01 00 64 00 6c 00 6c 00 2c 00 2d 00 35 00 30 00 (REG_BINARY)
"DynamicInfo"=03 00 00 00 37 2b c0 28 1d 3a cd 01 37 2b c0 28 1d 3a cd 01 00 00 00 00 00 00 00 00 (REG_BINARY)

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{39B45D1C-E533-4E8E-91E7-3E0BB937BAC9}]
"Path"="\Microsoft\Windows\Media Center\StartRecording"
"Hash"=6f 32 51 47 5e 85 5f e3 1a 51 98 93 a6 24 48 82 46 e7 17 75 f8 5e 8a 3f f3 d3 b1 55 d2 68 5f 76 (REG_BINARY)
"Triggers"=15 00 00 00 00 00 00 00 00 ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff 00 ff ff ff ff ff ff ff 00 00 00 00 00 00 00 00 48 07 42 02 48 48 48 48 fb 7b 73 cb 48 48 48 48 00 48 48 48 48 48 48 48 00 48 48 48 48 48 48 48 05 00 00 00 48 48 48 48 0c 00 00 00 48 48 48 48 01 01 00 00 00 00 00 05 14 00 00 00 48 48 48 48 00 00 00 00 48 48 48 48 38 00 00 00 48 48 48 48 58 02 00 00 10 0e 00 00 80 f4 03 00 ff ff ff ff 07 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 (REG_BINARY)
"DynamicInfo"=03 00 00 00 c0 59 88 98 8d dc cc 01 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 (REG_BINARY)

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{3DC7AD2C-5C3A-4B28-A174-782039D3EA85}]
"Path"="\Microsoft\Windows\Media Center\RegisterSearch"
"Hash"=3c 0b 66 d6 46 86 76 68 27 85 0b 14 9b 5a fb 54 42 20 67 3b 5b 4d 47 cb 55 56 ef 2c 86 8e 23 81 (REG_BINARY)
"Triggers"=15 00 00 00 00 00 00 00 00 ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff 00 ff ff ff ff ff ff ff 00 00 00 00 00 00 00 00 00 21 42 02 48 48 48 48 a9 a3 fb 23 48 48 48 48 00 48 48 48 48 48 48 48 00 48 48 48 48 48 48 48 05 00 00 00 48 48 48 48 0c 00 00 00 48 48 48 48 01 01 00 00 00 00 00 05 12 00 00 00 48 48 48 48 00 00 00 00 48 48 48 48 00 00 00 00 48 48 48 48 (REG_BINARY)
"DynamicInfo"=03 00 00 00 d1 80 70 e4 c9 e9 cb 01 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 (REG_BINARY)

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{408CB1DC-A2E0-443B-85EF-EB1476301C74}]
"Path"="\Microsoft\Windows\Setup\GWXTriggers\OutOfSleep-5d"
"Hash"=3f 28 03 71 5b e7 ad 45 79 97 a9 61 cc e0 66 09 b9 c6 09 54 da 06 92 71 ea b2 f4 e0 be 37 b4 59 (REG_BINARY)
"Triggers"=15 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ff ff ff ff ff ff ff ff c8 a1 40 00 48 48 48 48 02 c8 cb 4b 48 48 48 48 00 48 48 48 48 48 48 48 00 48 48 48 48 48 48 48 05 00 00 00 48 48 48 48 0c 00 00 00 48 48 48 48 01 01 00 00 00 00 00 05 04 00 00 00 48 48 48 48 00 00 00 00 48 48 48 48 38 00 00 00 48 48 48 48 00 00 00 00 ff ff ff ff 00 00 00 00 ff ff ff ff 07 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 cc cc 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ff ff ff ff ff ff ff ff 0a 00 00 00 ff ff ff ff 00 00 00 00 00 00 00 00 00 00 00 00 00 07 00 00 01 01 00 00 00 00 00 05 12 00 00 00 00 03 14 00 ab 00 00 00 00 00 00 00 3c 00 51 00 75 00 65 00 72 00 79 00 4c 00 69 00 73 00 74 00 3e 00 3c 00 51 00 75 00 65 00 72 00 79 00 20 00 49 00 64 00 3d 00 22 00 30 00 22 00 20 00 50 00 61 00 74 00 68 00 3d 00 22 00 53 00 79 00 73 00 74 00 65 00 6d 00 22 00 3e (REG_BINARY)
"DynamicInfo"=03 00 00 00 78 72 ad 9b 65 31 d1 01 a9 8b 73 58 65 31 d1 01 00 00 00 00 00 00 00 00 (REG_BINARY)

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{40C96928-DA37-4572-9E97-2827E8050FDC}]
"Path"="\Microsoft\Windows\Windows Activation Technologies\ValidationTaskDeadline"
"Hash"=9b e4 a8 7b 8b a6 7a e0 1f 65 ff fa 0d 84 81 b2 7d 44 0a 7a 97 fa 95 b7 76 87 43 d5 ca 70 dc 00 (REG_BINARY)
"Triggers"=15 00 00 00 00 00 00 00 00 ff a0 01 00 00 00 00 80 64 2a 96 a9 98 d0 01 00 ff a0 01 00 00 00 00 ff ff ff ff ff ff ff ff c8 21 c2 02 48 48 48 48 58 98 6b 13 48 48 48 48 00 48 48 48 48 48 48 48 00 48 48 48 48 48 48 48 05 00 00 00 48 48 48 48 0c 00 00 00 48 48 48 48 01 01 00 00 00 00 00 05 13 00 00 00 48 48 48 48 00 00 00 00 48 48 48 48 38 00 00 00 48 48 48 48 00 00 00 00 ff ff ff ff 00 00 00 00 ff ff ff ff 07 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 dd dd 00 00 00 00 00 00 00 ff a0 01 00 00 00 00 80 64 2a 96 a9 98 d0 01 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ff ff ff ff 01 00 00 00 5a 00 00 00 00 00 00 00 00 01 00 00 01 00 00 00 00 00 00 00 00 00 00 00 (REG_BINARY)
"DynamicInfo"=03 00 00 00 6b c5 fa 10 e1 c5 cc 01 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 (REG_BINARY)

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{41CDF12D-485B-46DE-8F7F-86992A1A75D5}]
"Path"="\Microsoft\Windows\Setup\GWXTriggers\Telemetry-4xd"
"Hash"=23 ec 8e 60 a3 9f db a4 a0 b0 b1 f6 12 ff a6 94 9b 1b c2 b7 e0 de 96 cf b7 dc 28 21 ee 37 98 41 (REG_BINARY)
"Triggers"=15 00 00 00 00 00 00 00 01 7e a6 01 00 00 00 00 00 20 16 76 a6 46 ce 01 00 7e a6 01 00 00 00 00 ff ff ff ff ff ff ff ff c8 a1 40 00 48 48 48 48 68 6e 63 bb 48 48 48 48 00 48 48 48 48 48 48 48 00 48 48 48 48 48 48 48 05 00 00 00 48 48 48 48 0c 00 00 00 48 48 48 48 01 01 00 00 00 00 00 05 04 00 00 00 48 48 48 48 00 00 00 00 48 48 48 48 38 00 00 00 48 48 48 48 00 00 00 00 ff ff ff ff 00 00 00 00 ff ff ff ff 07 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 dd dd 00 00 00 00 00 00 01 7e a6 01 00 00 00 00 00 20 16 76 a6 46 ce 01 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 c0 a8 00 00 80 51 01 00 ff ff ff ff 01 00 00 00 01 00 00 00 00 00 00 00 00 01 00 00 01 00 00 00 c0 a8 00 00 00 00 00 00 (REG_BINARY)
"DynamicInfo"=03 00 00 00 f7 6d ba 9c 65 31 d1 01 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 (REG_BINARY)

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{41DF318B-03A0-41AD-9F4B-0D16A583EAD8}]
"Path"="\Microsoft\Windows\Wininet\CacheTask"
"Hash"=b4 00 15 c2 e0 3a 44 73 c9 32 84 b4 a7 9d 0d 10 02 0c 19 1c 69 d3 4b 60 d8 9b 92 d8 94 2a 01 fc (REG_BINARY)
"Triggers"=15 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ff ff ff ff ff ff ff ff 00 85 40 02 48 48 48 48 14 f9 66 a5 48 48 48 48 00 48 48 48 48 48 48 48 00 48 48 48 48 48 48 48 04 00 00 00 48 48 48 48 10 00 00 00 48 48 48 48 01 02 00 00 00 00 00 05 20 00 00 00 21 02 00 00 00 00 00 00 48 48 48 48 38 00 00 00 48 48 48 48 00 00 00 00 ff ff ff ff 00 00 00 00 ff ff ff ff 07 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 aa aa 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ff ff ff ff ff ff ff ff 00 00 00 00 ff ff ff ff 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 01 00 61 00 73 00 6b 00 00 00 00 00 00 00 00 00 01 48 48 48 48 48 48 48 (REG_BINARY)
"DynamicInfo"=03 00 00 00 a5 5c b0 93 dd 9e ce 01 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 (REG_BINARY)

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{47536D45-EEEC-4BDC-8183-A4DC1F8DA9E4}]
"Path"="\Microsoft\Windows\Customer Experience Improvement Program\UsbCeip"
"Triggers"=15 00 00 00 00 00 00 00 01 12 72 fb fe 07 00 00 00 9c 9e e0 73 a6 c8 01 00 12 72 fb fe 07 00 00 ff ff ff ff ff ff ff ff 70 21 c2 02 48 48 48 48 63 25 1b 5d 48 48 48 48 00 48 48 48 48 48 48 48 00 48 48 48 48 48 48 48 05 00 00 00 48 48 48 48 0c 00 00 00 48 48 48 48 01 01 00 00 00 00 00 05 13 00 00 00 48 48 48 48 00 00 00 00 48 48 48 48 38 00 00 00 48 48 48 48 00 00 00 00 ff ff ff ff 80 f4 03 00 ff ff ff ff 07 00 00 00 8c 0a 00 00 01 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 75 00 70 00 00 00 00 00 00 00 00 00 dd dd 00 00 00 00 00 00 01 12 72 fb fe 07 00 00 00 9c 9e e0 73 a6 c8 01 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ff ff ff ff 01 00 00 00 03 00 00 00 00 00 00 00 00 01 00 00 01 00 00 00 00 00 00 00 00 00 00 00 (REG_BINARY)
"DynamicInfo"=03 00 00 00 ae ba 0d 2d 41 04 ca 01 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 (REG_BINARY)
"Hash"=ae 18 62 ba 40 99 24 24 8d c1 73 6d 23 e3 27 b7 15 40 18 fc 40 a4 da 69 5b c7 77 d1 13 5a 52 44 (REG_BINARY)

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{486D715E-6AA2-44CF-BC48-B6990CBB53C6}]
"Path"="\Microsoft\Windows\Shell\WindowsParentalControlsMigration"
"Triggers"=15 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ff ff ff ff ff ff ff ff 40 05 82 03 48 48 48 48 79 f2 19 6c 48 48 48 48 00 48 48 48 48 48 48 48 00 48 48 48 48 48 48 48 05 00 00 00 48 48 48 48 0c 00 00 00 48 48 48 48 01 01 00 00 00 00 00 05 12 00 00 00 48 48 48 48 00 00 00 00 48 48 48 48 38 00 00 00 48 48 48 48 00 00 00 00 ff ff ff ff 00 00 00 00 ff ff ff ff 07 00 00 00 3c 00 00 00 01 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 75 00 70 00 00 00 00 00 00 00 00 00 aa aa 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ff ff ff ff ff ff ff ff 01 00 00 00 ff ff ff ff 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 01 00 41 00 3b 00 3b 00 3b 00 42 00 41 00 29 00 01 48 48 48 48 48 48 48 (REG_BINARY)
"DynamicInfo"=03 00 00 00 ac af fa 2c 41 04 ca 01 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 (REG_BINARY)
"Hash"=6d 5d 71 fc d9 af 69 de 33 a5 e4 7e 6d e8 94 ca d1 5a 01 09 44 b2 ef 58 c0 72 c7 f6 1e db 87 e8 (REG_BINARY)

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{4C8B01A2-11FF-4C41-848F-508EF4F00CF7}]
"Path"="\Microsoft\Windows\TextServicesFramework\MsCtfMonitor"
"Triggers"=15 00 00 00 00 00 00 00 00 16 24 fb fe 07 00 00 00 00 00 00 00 00 00 00 00 16 24 fb fe 07 00 00 ff ff ff ff ff ff ff ff 00 85 c0 02 48 48 48 48 e7 74 f3 14 48 48 48 48 00 48 48 48 48 48 48 48 00 48 48 48 48 48 48 48 04 00 00 00 48 48 48 48 10 00 00 00 48 48 48 48 01 02 00 00 00 00 00 05 20 00 00 00 21 02 00 00 00 00 00 00 48 48 48 48 38 00 00 00 48 48 48 48 00 00 00 00 ff ff ff ff 00 00 00 00 ff ff ff ff 07 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 75 00 70 00 00 00 00 00 00 00 00 00 aa aa 00 00 00 00 00 00 00 16 24 fb fe 07 00 00 00 00 00 00 00 00 00 00 00 16 24 fb fe 07 00 00 ff ff ff ff ff ff ff ff 00 00 00 00 ff ff ff ff 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 01 00 00 00 00 00 00 00 00 00 00 00 03 00 00 00 01 48 48 48 48 48 48 48 (REG_BINARY)
"DynamicInfo"=03 00 00 00 0c 11 fd 2c 41 04 ca 01 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 (REG_BINARY)
"Hash"=f7 cc b3 90 21 e7 e2 45 ca dc d7 5e 42 61 02 52 20 87 dd 3a c9 1a f7 d4 38 7d 8d 70 ed 6d da b4 (REG_BINARY)

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{4CCD2E7C-8D0C-4947-A9C3-B2C0CAEB1CD8}]
"Path"="\{985637B0-E12F-4CC0-BEB9-D7F49605D2E9}"
"Hash"=c3 e3 60 92 1b 7e d5 e7 b9 93 bd 71 65 e9 6e 08 08 01 2b dd cb 2e 8b ed 48 6b 3d 89 00 8a 40 e9 (REG_BINARY)
"Triggers"=15 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ff ff ff ff ff ff ff ff 08 a1 40 00 48 48 48 48 9f a2 e7 2a 48 48 48 48 00 48 48 48 48 48 48 48 00 48 48 48 48 48 48 48 04 00 00 00 48 48 48 48 10 00 00 00 48 48 48 48 01 02 00 00 00 00 00 05 20 00 00 00 21 02 00 00 00 00 00 00 48 48 48 48 38 00 00 00 48 48 48 48 58 02 00 00 10 0e 00 00 80 f4 03 00 ff ff ff ff 07 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 88 88 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ff ff ff ff ff ff ff ff 00 00 00 00 ff ff ff ff 00 00 00 00 00 00 00 00 00 00 00 00 00 07 00 00 01 00 64 00 6c 00 6c 00 2c 00 2d 00 35 00 30 00 (REG_BINARY)
"DynamicInfo"=03 00 00 00 e5 01 9a 61 15 f3 ce 01 6b 1c a0 61 15 f3 ce 01 00 00 00 00 00 00 00 00 (REG_BINARY)

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{5A40E926-9E86-4B89-9CFD-B12311724371}]
"Path"="\Microsoft\Windows\UPnP\UPnPHostConfig"
"Triggers"=15 00 00 00 00 00 00 00 00 ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff 00 ff ff ff ff ff ff ff 00 00 00 00 00 00 00 00 10 21 42 02 48 48 48 48 11 e4 77 27 48 48 48 48 00 48 48 48 48 48 48 48 00 48 48 48 48 48 48 48 05 00 00 00 48 48 48 48 0c 00 00 00 48 48 48 48 01 01 00 00 00 00 00 05 12 00 00 00 48 48 48 48 00 00 00 00 48 48 48 48 00 00 00 00 48 48 48 48 (REG_BINARY)
"DynamicInfo"=03 00 00 00 6f 7d 12 2d 41 04 ca 01 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 (REG_BINARY)
"Hash"=6a 0c 38 92 08 12 da be f6 1f ed 20 83 d1 4e 9e 08 5c db d0 f5 45 9b 31 59 f0 f4 50 4c c8 b4 b0 (REG_BINARY)

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{5B42DD9C-5A26-4F27-BB95-34603F0997E5}]
"Path"="\Microsoft\Windows\Shell\WindowsParentalControls"
"Triggers"=15 00 00 00 00 00 00 00 00 16 24 fb fe 07 00 00 00 00 00 00 00 00 00 00 00 16 24 fb fe 07 00 00 ff ff ff ff ff ff ff ff 40 85 80 02 48 48 48 48 e1 49 b4 c1 48 48 48 48 00 48 48 48 48 48 48 48 00 48 48 48 48 48 48 48 05 00 00 00 48 48 48 48 0c 00 00 00 48 48 48 48 01 01 00 00 00 00 00 05 0b 00 00 00 48 48 48 48 00 00 00 00 48 48 48 48 38 00 00 00 48 48 48 48 00 00 00 00 ff ff ff ff 00 00 00 00 ff ff ff ff 07 00 00 00 3c 00 00 00 05 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 75 00 70 00 00 00 00 00 00 00 00 00 aa aa 00 00 00 00 00 00 00 16 24 fb fe 07 00 00 00 00 00 00 00 00 00 00 00 16 24 fb fe 07 00 00 ff ff ff ff ff ff ff ff 01 00 00 00 ff ff ff ff 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 03 00 00 00 01 48 48 48 48 48 48 48 (REG_BINARY)
"DynamicInfo"=03 00 00 00 0c 11 fd 2c 41 04 ca 01 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 (REG_BINARY)
"Hash"=88 65 11 e7 de e4 f4 47 b2 f7 04 a0 40 46 bb 94 2b d9 bd a7 61 52 a1 2b b0 ae 3d 9b 56 c6 aa f5 (REG_BINARY)

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{5C0AEEEA-C154-45BE-8499-BEA5F11BAFF6}]
"Path"="\Microsoft\Windows\Defrag\ScheduledDefrag"
"Triggers"=15 00 00 00 00 00 00 00 01 12 72 fb fe 07 00 00 00 e8 e6 37 9d ef c4 01 00 12 72 fb fe 07 00 00 ff ff ff ff ff ff ff ff 7e 21 42 03 48 48 48 48 b2 7e 59 fe 48 48 48 48 00 48 48 48 48 48 48 48 00 48 48 48 48 48 48 48 05 00 00 00 48 48 48 48 0c 00 00 00 48 48 48 48 01 01 00 00 00 00 00 05 12 00 00 00 48 48 48 48 00 00 00 00 48 48 48 48 38 00 00 00 48 48 48 48 b4 00 00 00 80 3a 09 00 80 f4 03 00 ff ff ff ff 07 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 dd dd 00 00 00 00 00 00 01 12 72 fb fe 07 00 00 00 e8 e6 37 9d ef c4 01 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ff ff ff ff 02 00 00 00 01 00 08 00 00 00 00 00 00 01 00 00 01 00 00 00 20 1c 00 00 00 00 00 00 (REG_BINARY)
"DynamicInfo"=03 00 00 00 2f 40 17 2d 41 04 ca 01 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 (REG_BINARY)
"Hash"=83 6a 0f 9a 79 43 22 0e 6e 69 d4 60 79 28 f3 8f 05 27 87 b2 76 05 a9 c5 cd 19 df 80 80 48 90 ce (REG_BINARY)

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{5E15C04F-8ACE-499C-80BB-3A915B0F2DAB}]
"Path"="\Microsoft\Windows\Media Center\PBDADiscoveryW1"
"Hash"=ed 6c 3a f7 7b c3 25 14 d0 e4 a4 61 15 fb 37 72 42 e6 0f de 46 f8 ff 37 85 af 62 4b 20 46 26 91 (REG_BINARY)
"Triggers"=15 00 00 00 00 00 00 00 00 ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff 00 ff ff ff ff ff ff ff 00 00 00 00 00 00 00 00 40 05 42 02 48 48 48 48 20 23 1f ce 48 48 48 48 00 48 48 48 48 48 48 48 00 48 48 48 48 48 48 48 05 00 00 00 48 48 48 48 0c 00 00 00 48 48 48 48 01 01 00 00 00 00 00 05 12 00 00 00 48 48 48 48 00 00 00 00 48 48 48 48 38 00 00 00 48 48 48 48 00 00 00 00 ff ff ff ff 10 0e 00 00 ff ff ff ff 07 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 (REG_BINARY)
"DynamicInfo"=03 00 00 00 4c 68 84 e7 c9 e9 cb 01 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 (REG_BINARY)

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{5F5A18EB-DC73-4E45-A11C-B59043598412}]
"Path"="\Microsoft\Windows\CertificateServicesClient\SystemTask"
"Triggers"=15 00 00 00 00 00 00 00 00 1c 24 fb fe 07 00 00 00 00 00 00 00 00 00 00 00 1c 24 fb fe 07 00 00 ff ff ff ff ff ff ff ff c0 05 42 02 48 48 48 48 4e 9f 42 ce 48 48 48 48 00 48 48 48 48 48 48 48 00 48 48 48 48 48 48 48 05 00 00 00 48 48 48 48 0c 00 00 00 48 48 48 48 01 01 00 00 00 00 00 05 12 00 00 00 48 48 48 48 00 00 00 00 48 48 48 48 38 00 00 00 48 48 48 48 00 00 00 00 ff ff ff ff 00 00 00 00 ff ff ff ff 07 00 00 00 3c 00 00 00 05 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 75 00 70 00 00 00 00 00 00 00 00 00 cc cc 00 00 00 00 00 00 00 1c 24 fb fe 07 00 00 00 00 00 00 00 00 00 00 00 1c 24 fb fe 07 00 00 ff ff ff ff ff ff ff ff 00 00 00 00 ff ff ff ff 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 01 01 00 00 00 00 00 05 20 00 00 00 00 00 00 00 1b 01 00 00 00 00 00 00 3c 00 51 00 75 00 65 00 72 00 79 00 4c 00 69 00 73 00 74 00 3e 00 0a 00 20 00 20 00 20 00 20 00 20 00 20 00 20 00 20 00 20 00 20 00 20 00 20 00 20 00 20 00 20 00 20 00 3c 00 51 00 75 00 65 00 72 00 79 00 20 00 49 00 64 00 3d 00 22 (REG_BINARY)
"DynamicInfo"=03 00 00 00 c8 bd db 2c 41 04 ca 01 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 (REG_BINARY)
"Hash"=5f 17 41 f0 e3 67 3a ee 6b 7d 98 3c db 71 8c 34 64 0a 8c 20 b8 d2 f6 27 b7 aa 49 1c 12 f1 63 58 (REG_BINARY)

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{61097539-54C8-46CF-A778-E22A51CC5E25}]
"Path"="\Microsoft\Windows\WindowsBackup\AutomaticBackup"
"Hash"=0a 08 39 dc 8f 54 b6 13 76 b4 35 fc 1d 72 f1 50 e2 b2 43 74 ee 4e fb ef 6c bf 34 cd 30 bc 5e 81 (REG_BINARY)
"Triggers"=15 00 00 00 00 00 00 00 01 2f cc 01 00 00 00 00 00 78 56 4e 58 30 d1 01 00 2f cc 01 00 00 00 00 ff ff ff ff ff ff ff ff 40 05 42 01 48 48 48 48 8d 23 bf 2d 48 48 48 48 00 48 48 48 48 48 48 48 00 48 48 48 48 48 48 48 05 00 00 00 48 48 48 48 0c 00 00 00 48 48 48 48 01 01 00 00 00 00 00 05 12 00 00 00 48 48 48 48 00 00 00 00 48 48 48 48 38 00 00 00 48 48 48 48 58 02 00 00 10 0e 00 00 80 f4 03 00 ff ff ff ff 07 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 dd dd 00 00 00 00 00 00 01 2f cc 01 00 00 00 00 00 78 56 4e 58 30 d1 01 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ff ff ff ff 02 00 00 00 01 00 01 00 00 00 00 00 00 01 00 00 01 00 00 00 00 00 00 00 00 00 00 00 (REG_BINARY)
"DynamicInfo"=03 00 00 00 14 39 76 2d 8e 30 d1 01 9f 48 ab 96 66 31 d1 01 00 00 00 00 00 00 00 00 (REG_BINARY)

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{613612BA-897D-44CE-8DC1-8FC283F9FD51}]
"Path"="\Microsoft\Windows\Active Directory Rights Management Services Client\AD RMS Rights Policy Template Management (Automated)"
"Triggers"=15 00 00 00 00 00 00 00 00 1c 24 fb fe 07 00 00 00 00 00 00 00 00 00 00 00 12 72 fb fe 07 00 00 ff ff ff ff ff ff ff ff c8 85 00 02 48 48 48 48 4f 48 2a b2 48 48 48 48 00 48 48 48 48 48 48 48 00 48 48 48 48 48 48 48 05 00 00 00 48 48 48 48 0c 00 00 00 48 48 48 48 01 01 00 00 00 00 00 01 00 00 00 00 48 48 48 48 00 00 00 00 48 48 48 48 38 00 00 00 48 48 48 48 58 02 00 00 10 0e 00 00 10 0e 00 00 ff ff ff ff 07 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 dd dd 00 00 00 00 00 00 01 12 72 fb fe 07 00 00 00 78 18 25 ab 03 c7 01 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ff ff ff ff 01 00 00 00 01 00 00 00 00 00 00 00 00 01 00 00 01 00 00 00 10 0e 00 00 00 00 00 00 aa aa 00 00 00 00 00 00 00 1c 24 fb fe 07 00 00 00 00 00 00 00 00 00 00 00 1c 24 fb fe 07 00 00 ff ff ff ff ff ff ff ff 10 0e 00 00 ff ff ff ff 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 01 00 00 00 00 (REG_BINARY)
"DynamicInfo"=03 00 00 00 6d 72 ff 2c 41 04 ca 01 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 (REG_BINARY)
"Hash"=5f ea 8c 5d 59 0e 39 1f 05 dc 6b f1 82 ee 76 fa 80 be 1e c0 3c 9f 02 43 9f 1a 61 9a 1d 37 1c bb (REG_BINARY)

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{654B0B50-030E-478D-8CBF-A854332258BD}]
"Path"="\Microsoft\Windows\Media Center\DispatchRecoveryTasks"
"Hash"=78 0d ba ba 61 5f a6 79 f8 13 3b e5 9b 1a 9f 73 b1 1e 21 dd 46 6c 8d 14 4d f6 26 12 26 2e b8 0d (REG_BINARY)
"Triggers"=15 00 00 00 00 00 00 00 00 ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff 00 ff ff ff ff ff ff ff 00 00 00 00 00 00 00 00 08 05 42 02 48 48 48 48 fc 88 cf dd 48 48 48 48 00 48 48 48 48 48 48 48 00 48 48 48 48 48 48 48 05 00 00 00 48 48 48 48 0c 00 00 00 48 48 48 48 01 01 00 00 00 00 00 05 12 00 00 00 48 48 48 48 00 00 00 00 48 48 48 48 38 00 00 00 48 48 48 48 00 00 00 00 ff ff ff ff 80 f4 03 00 ff ff ff ff 07 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 (REG_BINARY)
"DynamicInfo"=03 00 00 00 aa bc 46 e5 c9 e9 cb 01 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 (REG_BINARY)

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{6738BA6E-EA75-4B6B-B8B8-71F0336DD8EF}]
"Path"="\Microsoft\Windows\User Profile Service\HiveUploadTask"
"Triggers"=15 00 00 00 00 00 00 00 01 12 72 fb fe 07 00 00 00 40 6a 60 06 e9 c7 01 00 12 72 fb fe 07 00 00 ff ff ff ff ff ff ff ff c2 21 02 02 48 48 48 48 0c 2a d3 b9 48 48 48 48 00 48 48 48 48 48 48 48 00 48 48 48 48 48 48 48 05 00 00 00 48 48 48 48 0c 00 00 00 48 48 48 48 01 01 00 00 00 00 00 05 12 00 00 00 48 48 48 48 00 00 00 00 48 48 48 48 38 00 00 00 48 48 48 48 58 02 00 00 20 1c 00 00 80 f4 03 00 ff ff ff ff 07 00 00 00 78 00 00 00 03 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 dd dd 00 00 00 00 00 00 01 12 72 fb fe 07 00 00 00 40 6a 60 06 e9 c7 01 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 c0 a8 00 00 00 00 00 00 ff ff ff ff 00 00 00 00 00 00 00 00 00 00 00 00 00 01 00 00 01 00 00 00 10 0e 00 00 00 00 00 00 (REG_BINARY)
"DynamicInfo"=03 00 00 00 b9 72 83 2e 41 04 ca 01 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 (REG_BINARY)
"Hash"=22 73 52 40 f6 34 af 52 eb 49 6c ac 7f 58 e8 5d 9e d7 af 87 6a d3 1d 5a e4 c1 f5 7c 23 4e 57 28 (REG_BINARY)

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{6885E303-EFC1-40B2-A204-B13E2FD573E3}]
"Path"="\Microsoft\Windows\Media Center\PeriodicScanRetry"
"Hash"=8e 69 11 ca 59 c4 5f 2e e0 bf 63 45 3d cd 58 0b 28 5e 92 ce 1b fe 45 89 f9 56 d6 7c 57 f7 5e a3 (REG_BINARY)
"Triggers"=15 00 00 00 00 00 00 00 01 3f 39 01 00 00 00 00 00 6e cf fe 35 d4 c6 01 01 00 00 00 00 00 00 00 00 6e cf fe 35 d4 c6 01 30 21 02 02 48 48 48 48 89 0e 44 13 48 48 48 48 00 48 48 48 48 48 48 48 00 48 48 48 48 48 48 48 05 00 00 00 48 48 48 48 0c 00 00 00 48 48 48 48 01 01 00 00 00 00 00 05 14 00 00 00 48 48 48 48 00 00 00 00 48 48 48 48 38 00 00 00 48 48 48 48 00 00 00 00 ff ff ff ff 80 f4 03 00 ff ff ff ff 07 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 2e 00 45 00 00 00 00 00 00 00 00 00 dd dd 00 00 00 00 00 00 01 3f 39 01 00 00 00 00 00 6e cf fe 35 d4 c6 01 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ff ff ff ff 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 01 00 00 00 00 00 00 00 00 00 00 00 (REG_BINARY)
"DynamicInfo"=03 00 00 00 b5 f3 a5 e5 c9 e9 cb 01 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 (REG_BINARY)

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{72DB7465-BC54-491B-A92A-4637A28C9BBF}]
"Path"="\Microsoft\Windows\AppID\VerifiedPublisherCertStoreCheck"
"Triggers"=15 00 00 00 00 00 00 00 00 16 24 fb fe 07 00 00 00 00 00 00 00 00 00 00 00 16 24 fb fe 07 00 00 ff ff ff ff ff ff ff ff 7e 11 02 02 48 48 48 48 21 8d 22 db 48 48 48 48 00 48 48 48 48 48 48 48 00 48 48 48 48 48 48 48 05 00 00 00 48 48 48 48 0c 00 00 00 48 48 48 48 01 01 00 00 00 00 00 05 13 00 00 00 48 48 48 48 00 00 00 00 48 48 48 48 38 00 00 00 48 48 48 48 b4 00 00 00 70 43 01 00 80 f4 03 00 ff ff ff ff 0a 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 75 00 70 00 00 00 00 00 00 00 00 00 ff ff 00 00 00 00 00 00 00 16 24 fb fe 07 00 00 00 00 00 00 00 00 00 00 00 16 24 fb fe 07 00 00 ff ff ff ff ff ff ff ff 08 07 00 00 ff ff ff ff 80 51 01 00 00 00 00 00 00 00 00 00 00 00 00 00 01 00 00 00 00 00 00 00 00 00 00 00 03 00 00 00 (REG_BINARY)
"DynamicInfo"=03 00 00 00 29 1f de 2c 41 04 ca 01 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 (REG_BINARY)
"Hash"=a8 55 9f 6c cc a2 df 09 f1 22 5f 5d cf f6 7d 8c 6f f1 24 fc 5f 85 dc df 7f 19 1d c7 cf 13 ea de (REG_BINARY)

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{7497269B-A749-417A-B590-51B7AEF07070}]
"Path"="\Microsoft\Windows\Media Center\mcupdate_scheduled"
"Hash"=1d 1c 07 fe f6 a1 50 bb 2f 3a 40 68 7a 0d 0d 69 ed b3 4a 7e 8b 5f fd f5 cf c9 4f 56 04 68 37 f0 (REG_BINARY)
"Triggers"=15 00 00 00 00 00 00 00 00 ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff 00 ff ff ff ff ff ff ff 00 00 00 00 00 00 00 00 58 07 42 02 48 48 48 48 36 91 21 eb 48 48 48 48 00 48 48 48 48 48 48 48 00 48 48 48 48 48 48 48 05 00 00 00 48 48 48 48 0c 00 00 00 48 48 48 48 01 01 00 00 00 00 00 05 14 00 00 00 48 48 48 48 00 00 00 00 48 48 48 48 38 00 00 00 48 48 48 48 58 02 00 00 10 0e 00 00 80 f4 03 00 ff ff ff ff 07 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 2e 00 45 00 00 00 00 00 00 00 00 00 (REG_BINARY)
"DynamicInfo"=03 00 00 00 d2 21 df 0b 8e dc cc 01 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 (REG_BINARY)

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{753C47AE-EC5E-44B3-95A9-2C8E553F0E39}]
"Path"="\Microsoft\Windows\Windows Media Sharing\UpdateLibrary"
"Triggers"=15 00 00 00 00 00 00 00 00 16 24 fb fe 07 00 00 00 00 00 00 00 00 00 00 00 16 24 fb fe 07 00 00 ff ff ff ff ff ff ff ff 40 85 40 02 48 48 48 48 ec 26 cb 6d 48 48 48 48 00 48 48 48 48 48 48 48 00 48 48 48 48 48 48 48 05 00 00 00 48 48 48 48 0c 00 00 00 48 48 48 48 01 01 00 00 00 00 00 05 0b 00 00 00 48 48 48 48 00 00 00 00 48 48 48 48 00 00 00 00 48 48 48 48 cc cc 00 00 00 00 00 00 00 16 24 fb fe 07 00 00 00 00 00 00 00 00 00 00 00 16 24 fb fe 07 00 00 ff ff ff ff ff ff ff ff 00 00 00 00 ff ff ff ff 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 01 01 00 00 00 00 00 05 20 00 00 00 00 00 00 00 1e 01 00 00 00 00 00 00 3c 00 51 00 75 00 65 00 72 00 79 00 4c 00 69 00 73 00 74 00 3e 00 0a 00 20 00 20 00 20 00 20 00 20 00 20 00 20 00 20 00 20 00 20 00 20 00 20 00 20 00 20 00 3c 00 51 00 75 00 65 00 72 00 79 00 0a 00 20 00 20 00 20 00 20 00 20 00 20 00 20 00 20 00 20 00 20 00 20 00 20 00 20 00 20 00 20 00 20 00 20 00 20 00 49 00 64 00 3d 00 22 00 30 00 22 00 0a 00 20 00 20 00 20 00 20 00 20 00 20 00 20 00 20 00 20 (REG_BINARY)
"DynamicInfo"=03 00 00 00 7a 35 88 2e 41 04 ca 01 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 (REG_BINARY)
"Hash"=72 a5 68 3a 40 fa a2 91 aa 33 cc 4d d7 1a 02 e9 e6 91 d7 c5 a7 ba 21 3b 81 7c 75 9f 7d 4e 24 be (REG_BINARY)

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{7663A1BE-1F45-4C7B-84E1-611A29336DC3}]
"Path"="\Microsoft\Windows\Windows Activation Technologies\ValidationTask"
"Hash"=18 90 93 fc 64 79 ef 2a 5d 4e 0b ed ff 7e 8a 76 c0 64 e4 67 0b f0 e1 48 3e b1 fc 98 ff 89 5a 84 (REG_BINARY)
"Triggers"=15 00 00 00 00 00 00 00 00 ff a0 01 00 00 00 00 80 e4 08 ee cd 90 d0 01 00 ff a0 01 00 00 00 00 ff ff ff ff ff ff ff ff c2 21 c2 02 48 48 48 48 2b a3 0c 60 48 48 48 48 00 48 48 48 48 48 48 48 00 48 48 48 48 48 48 48 05 00 00 00 48 48 48 48 0c 00 00 00 48 48 48 48 01 01 00 00 00 00 00 05 13 00 00 00 48 48 48 48 00 00 00 00 48 48 48 48 38 00 00 00 48 48 48 48 2c 01 00 00 f0 20 0d 00 00 00 00 00 ff ff ff ff 07 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 dd dd 00 00 00 00 00 00 00 ff a0 01 00 00 00 00 80 e4 08 ee cd 90 d0 01 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ff ff ff ff 01 00 00 00 5a 00 00 00 00 00 00 00 00 01 00 00 01 00 00 00 00 00 00 00 00 00 00 00 (REG_BINARY)
"DynamicInfo"=03 00 00 00 ea 3f f1 10 e1 c5 cc 01 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 (REG_BINARY)

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{78DC1F46-38AD-496D-830A-0A35D382C696}]
"Path"="\Microsoft\Windows\Media Center\OCURDiscovery"
"Hash"=1f c0 92 67 7f a5 81 a6 f0 d9 01 7d 0f 02 e7 46 81 a0 da 6b 0a f0 ee f0 e2 04 e9 2d 16 05 75 7a (REG_BINARY)
"Triggers"=15 00 00 00 00 00 00 00 00 ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff 00 ff ff ff ff ff ff ff 00 00 00 00 00 00 00 00 00 21 42 02 48 48 48 48 5c 36 cf 06 48 48 48 48 00 48 48 48 48 48 48 48 00 48 48 48 48 48 48 48 05 00 00 00 48 48 48 48 0c 00 00 00 48 48 48 48 01 01 00 00 00 00 00 05 12 00 00 00 48 48 48 48 00 00 00 00 48 48 48 48 00 00 00 00 48 48 48 48 (REG_BINARY)
"DynamicInfo"=03 00 00 00 6c 88 31 e3 c9 e9 cb 01 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 (REG_BINARY)

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{7AFCC0CA-7121-422A-AB45-B0E8D599FF08}]
"Path"="\Microsoft\Windows\CertificateServicesClient\UserTask"
"Triggers"=15 00 00 00 00 00 00 00 00 1c 24 fb fe 07 00 00 00 00 00 00 00 00 00 00 00 1c 24 fb fe 07 00 00 ff ff ff ff ff ff ff ff c0 85 40 02 48 48 48 48 96 52 81 fa 48 48 48 48 00 48 48 48 48 48 48 48 00 48 48 48 48 48 48 48 05 00 00 00 48 48 48 48 0c 00 00 00 48 48 48 48 01 01 00 00 00 00 00 05 04 00 00 00 48 48 48 48 00 00 00 00 48 48 48 48 38 00 00 00 48 48 48 48 00 00 00 00 ff ff ff ff 00 00 00 00 ff ff ff ff 07 00 00 00 3c 00 00 00 05 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 cc cc 00 00 00 00 00 00 00 1c 24 fb fe 07 00 00 00 00 00 00 00 00 00 00 00 1c 24 fb fe 07 00 00 ff ff ff ff ff ff ff ff 00 00 00 00 ff ff ff ff 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 01 01 00 00 00 00 00 05 20 00 00 00 00 00 00 00 a5 00 00 00 00 00 00 00 3c 00 51 00 75 00 65 00 72 00 79 00 4c 00 69 00 73 00 74 00 3e 00 3c 00 51 00 75 00 65 00 72 00 79 00 20 00 49 00 64 00 3d 00 22 00 30 00 22 00 20 00 50 00 61 00 74 00 68 00 3d 00 22 00 53 00 79 00 73 00 74 00 65 00 6d 00 22 00 3e (REG_BINARY)
"DynamicInfo"=03 00 00 00 6d 72 ff 2c 41 04 ca 01 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 (REG_BINARY)
"Hash"=db 89 fe 61 b3 8c f5 41 d5 84 c3 46 12 b8 56 a8 25 ef 9a 28 77 79 f0 cc bf aa 95 a0 18 3e 87 81 (REG_BINARY)

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{81540B9F-B5BF-47EB-9C95-BE195BF2C664}]
"Path"="\Microsoft\Windows\NetTrace\GatherNetworkInfo"
"Triggers"=15 00 00 00 00 00 00 00 00 ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff 00 ff ff ff ff ff ff ff 00 00 00 00 00 00 00 00 00 85 40 03 48 48 48 48 a3 1c 71 3a 48 48 48 48 00 48 48 48 48 48 48 48 00 48 48 48 48 48 48 48 04 00 00 00 48 48 48 48 10 00 00 00 48 48 48 48 01 02 00 00 00 00 00 05 20 00 00 00 21 02 00 00 00 00 00 00 48 48 48 48 38 00 00 00 48 48 48 48 00 00 00 00 ff ff ff ff 80 f4 03 00 ff ff ff ff 07 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 75 00 70 00 00 00 00 00 00 00 00 00 (REG_BINARY)
"DynamicInfo"=03 00 00 00 1c df 98 2e 41 04 ca 01 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 (REG_BINARY)
"Hash"=9e 15 41 71 40 8f 80 e0 d5 ce b4 d8 f7 75 75 8b 34 5b 3f d7 05 ad 0b 30 58 b1 73 28 70 be 80 7f (REG_BINARY)

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{826007B3-58BC-4266-AD84-BE5432535075}]
"Path"="\Microsoft\Windows\Application Experience\Microsoft Compatibility Appraiser"
"Hash"=12 5a c9 d3 22 ec eb 8e 92 9f be 2a 6c 24 ef 56 49 a4 a9 1a b9 fa 26 84 69 ca 74 eb 6b d1 5b 3e (REG_BINARY)
"Triggers"=15 00 00 00 00 00 00 00 01 7e a6 01 00 00 00 00 00 b8 94 f1 8d 62 cf 01 00 7e a6 01 00 00 00 00 ff ff ff ff ff ff ff ff c8 21 42 02 48 48 48 48 c2 31 36 a2 48 48 48 48 00 48 48 48 48 48 48 48 00 48 48 48 48 48 48 48 05 00 00 00 48 48 48 48 0c 00 00 00 48 48 48 48 01 01 00 00 00 00 00 05 12 00 00 00 48 48 48 48 00 00 00 00 48 48 48 48 38 00 00 00 48 48 48 48 00 00 00 00 ff ff ff ff 00 46 05 00 ff ff ff ff 07 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 dd dd 00 00 00 00 00 00 01 7e a6 01 00 00 00 00 00 b8 94 f1 8d 62 cf 01 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ff ff ff ff 01 00 00 00 01 00 00 00 00 00 00 00 00 01 00 00 01 00 00 00 20 1c 00 00 00 00 00 00 (REG_BINARY)
"DynamicInfo"=03 00 00 00 cc 2c 69 16 1f 24 d1 01 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 (REG_BINARY)

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{8602EA65-3194-4492-AA3C-B891DE69B2BF}]
"Path"="\Microsoft\Windows\Media Center\SqlLiteRecoveryTask"
"Hash"=05 82 c3 dc 8e 70 bc 6f ae eb 50 0e b4 3e eb b0 3b 2d 60 7b 40 b6 1b 59 c0 bc 46 29 2f 5b e4 2a (REG_BINARY)
"Triggers"=15 00 00 00 00 00 00 00 00 ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff 00 ff ff ff ff ff ff ff 00 00 00 00 00 00 00 00 00 05 42 02 48 48 48 48 bb 35 3c 89 48 48 48 48 00 48 48 48 48 48 48 48 00 48 48 48 48 48 48 48 05 00 00 00 48 48 48 48 0c 00 00 00 48 48 48 48 01 01 00 00 00 00 00 05 14 00 00 00 48 48 48 48 00 00 00 00 48 48 48 48 00 00 00 00 48 48 48 48 (REG_BINARY)
"DynamicInfo"=03 00 00 00 b7 7f cf e6 c9 e9 cb 01 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 (REG_BINARY)

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{8A7266F3-52B8-40CA-B529-37023ABBFDC8}]
"Path"="\AVAST Software\Avast settings backup"
"Hash"=3b 39 7a 83 d5 b0 62 04 42 91 45 2f a6 1e 59 71 22 ad f3 35 c6 fd 01 d2 05 13 27 09 94 ad d2 da (REG_BINARY)
"Triggers"=15 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ff ff ff ff ff ff ff ff 48 21 42 00 48 48 48 48 b8 1d 59 1a 48 48 48 48 00 48 48 48 48 48 48 48 00 48 48 48 48 48 48 48 05 00 00 00 48 48 48 48 0c 00 00 00 48 48 48 48 01 01 00 00 00 00 00 05 12 00 00 00 48 48 48 48 00 00 00 00 48 48 48 48 38 00 00 00 48 48 48 48 58 02 00 00 10 0e 00 00 80 f4 03 00 ff ff ff ff 07 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ff ff 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ff ff ff ff ff ff ff ff 00 00 00 00 ff ff ff ff 00 00 00 00 00 00 00 00 00 00 00 00 00 07 00 00 01 00 d1 01 00 00 00 00 05 00 00 00 00 00 00 00 dd dd 00 00 00 00 00 00 00 89 d1 01 00 00 00 00 00 4c 19 c1 2e 32 d1 01 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ff ff ff ff 01 00 00 00 01 00 00 00 00 00 00 00 00 01 00 00 01 (REG_BINARY)
"DynamicInfo"=03 00 00 00 db 54 cc 3f 89 2d d1 01 65 e8 c7 6f 65 31 d1 01 00 00 00 00 00 00 00 00 (REG_BINARY)

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{8C18F494-17CA-4950-A9A0-9DDFB9186EBC}]
"Path"="\Microsoft\Windows\Media Center\ActivateWindowsSearch"
"Hash"=44 09 79 39 8f 3a b4 18 f9 0b 93 dc 0d d9 70 70 f5 ef 23 37 86 0a b4 27 75 20 2e f7 1d 70 b9 e9 (REG_BINARY)
"Triggers"=15 00 00 00 00 00 00 00 00 ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff 00 ff ff ff ff ff ff ff 00 00 00 00 00 00 00 00 00 21 42 02 48 48 48 48 90 39 64 9f 48 48 48 48 00 48 48 48 48 48 48 48 00 48 48 48 48 48 48 48 05 00 00 00 48 48 48 48 0c 00 00 00 48 48 48 48 01 01 00 00 00 00 00 05 12 00 00 00 48 48 48 48 00 00 00 00 48 48 48 48 00 00 00 00 48 48 48 48 (REG_BINARY)
"DynamicInfo"=03 00 00 00 a3 9b 0d e5 c9 e9 cb 01 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 (REG_BINARY)

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{8C71E3B5-F23A-4F19-A471-8BCBD42A02B6}]
"Path"="\Microsoft\Windows\Media Center\mcupdate"
"Hash"=d2 3b 78 87 df d9 27 fa 2b 59 e8 0b 7e 06 0f a8 0c aa a1 e8 31 53 b4 05 3e f4 9f 21 0f fa 35 c6 (REG_BINARY)
"Triggers"=15 00 00 00 00 00 00 00 00 ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff 00 ff ff ff ff ff ff ff 00 00 00 00 00 00 00 00 60 05 42 02 48 48 48 48 a5 48 69 7f 48 48 48 48 00 48 48 48 48 48 48 48 00 48 48 48 48 48 48 48 05 00 00 00 48 48 48 48 0c 00 00 00 48 48 48 48 01 01 00 00 00 00 00 05 14 00 00 00 48 48 48 48 00 00 00 00 48 48 48 48 38 00 00 00 48 48 48 48 00 00 00 00 ff ff ff ff 80 f4 03 00 ff ff ff ff 06 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 (REG_BINARY)
"DynamicInfo"=03 00 00 00 e5 64 32 e6 c9 e9 cb 01 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 (REG_BINARY)

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{906454C7-40A1-496A-9967-A22BB51BB481}]
"Path"="\Microsoft\Windows\Media Center\MediaCenterRecoveryTask"
"Hash"=eb 51 42 14 b7 fd 8b cd f4 4b 13 e0 11 17 53 73 48 e0 99 e5 cc 33 a1 5a 47 0c 6c 60 fe 50 46 7d (REG_BINARY)
"Triggers"=15 00 00 00 00 00 00 00 00 ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff 00 ff ff ff ff ff ff ff 00 00 00 00 00 00 00 00 00 05 42 02 48 48 48 48 68 de b3 74 48 48 48 48 00 48 48 48 48 48 48 48 00 48 48 48 48 48 48 48 05 00 00 00 48 48 48 48 0c 00 00 00 48 48 48 48 01 01 00 00 00 00 00 05 12 00 00 00 48 48 48 48 00 00 00 00 48 48 48 48 00 00 00 00 48 48 48 48 (REG_BINARY)
"DynamicInfo"=03 00 00 00 83 79 33 e7 c9 e9 cb 01 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 (REG_BINARY)

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{9435F817-FED2-454E-88CD-7F78FDA62C48}]
"Path"="\Microsoft\Windows\WDI\ResolutionHost"
"Triggers"=15 00 00 00 00 00 00 00 00 ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff 00 ff ff ff ff ff ff ff 00 00 00 00 00 00 00 00 00 85 c0 03 48 48 48 48 9d 84 f4 70 48 48 48 48 00 48 48 48 48 48 48 48 00 48 48 48 48 48 48 48 05 00 00 00 48 48 48 48 0c 00 00 00 48 48 48 48 01 01 00 00 00 00 00 05 04 00 00 00 48 48 48 48 00 00 00 00 48 48 48 48 38 00 00 00 48 48 48 48 00 00 00 00 ff ff ff ff 00 00 00 00 ff ff ff ff 0a 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 75 00 70 00 00 00 00 00 00 00 00 00 (REG_BINARY)
"DynamicInfo"=03 00 00 00 7c 40 9b 2e 41 04 ca 01 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 (REG_BINARY)
"Hash"=76 78 f2 83 cd 52 82 77 95 1d 59 55 d0 03 19 dc 3e 40 4f 5d 6a d8 e0 80 6b 80 dc 78 1e 71 81 ca (REG_BINARY)

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{9436B5C3-B6CD-43C7-87F6-11B7B4937DCF}]
"Path"="\McAfee Remediation (Prepare)"
"Hash"=98 7c 66 26 57 76 d4 e2 06 c8 5a 68 32 ee b3 85 08 07 46 05 bc a3 8c 44 36 15 40 65 03 7f ba 97 (REG_BINARY)
"Triggers"=15 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ff ff ff ff ff ff ff ff 38 a1 40 01 48 48 48 48 22 75 f7 6b 48 48 48 48 00 48 48 48 48 48 48 48 00 48 48 48 48 48 48 48 04 00 00 00 48 48 48 48 10 00 00 00 48 48 48 48 01 02 00 00 00 00 00 05 20 00 00 00 20 02 00 00 00 00 00 00 48 48 48 48 38 00 00 00 48 48 48 48 58 02 00 00 10 0e 00 00 80 f4 03 00 ff ff ff ff 07 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 88 88 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ff ff ff ff ff ff ff ff 10 0e 00 00 ff ff ff ff 10 0e 00 00 00 00 00 00 00 00 00 00 00 07 00 00 01 00 69 00 63 00 65 00 3a 00 00 00 35 00 30 00 (REG_BINARY)
"DynamicInfo"=03 00 00 00 f1 06 24 df 54 d0 d0 01 fe 1a 0f f0 26 d1 d0 01 00 00 00 00 00 00 00 00 (REG_BINARY)

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{982D925F-43A4-47BC-BB18-92B368796A4D}]
"Path"="\Apple\AppleSoftwareUpdate"
"Hash"=89 a5 b4 16 f6 fb 85 0c 73 9b f7 3e 0c 08 29 e4 e1 54 09 82 a0 5e fb a7 18 1e b5 3f 84 40 d5 e2 (REG_BINARY)
"Triggers"=15 00 00 00 00 00 00 00 01 2b de 01 00 00 00 00 00 5c 1d 93 7e c4 cc 01 00 2b de 01 00 00 00 00 ff ff ff ff ff ff ff ff 78 a1 40 00 48 48 48 48 5c ac 09 61 48 48 48 48 00 48 48 48 48 48 48 48 00 48 48 48 48 48 48 48 04 00 00 00 48 48 48 48 10 00 00 00 48 48 48 48 01 02 00 00 00 00 00 05 20 00 00 00 21 02 00 00 00 00 00 00 48 48 48 48 38 00 00 00 48 48 48 48 58 02 00 00 10 0e 00 00 80 f4 03 00 ff ff ff ff 07 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 dd dd 00 00 00 00 00 00 01 2b de 01 00 00 00 00 00 5c 1d 93 7e c4 cc 01 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ff ff ff ff 02 00 00 00 01 00 02 00 00 00 00 00 00 01 00 00 01 00 00 00 00 00 00 00 00 00 00 00 (REG_BINARY)
"DynamicInfo"=03 00 00 00 11 89 23 94 c6 c4 cc 01 f7 80 77 d2 66 31 d1 01 00 00 00 00 00 00 00 00 (REG_BINARY)

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{994C86AD-A929-4B2C-88A0-4E25A107A029}]
"Path"="\Microsoft\Windows\SystemRestore\SR"
"Triggers"=15 00 00 00 00 00 00 00 00 1c 24 fb fe 07 00 00 00 00 00 00 00 00 00 00 00 12 72 fb fe 07 00 00 ff ff ff ff ff ff ff ff 52 21 42 02 48 48 48 48 ed d0 74 1f 48 48 48 48 00 48 48 48 48 48 48 48 00 48 48 48 48 48 48 48 05 00 00 00 48 48 48 48 0c 00 00 00 48 48 48 48 01 01 00 00 00 00 00 05 12 00 00 00 48 48 48 48 00 00 00 00 48 48 48 48 38 00 00 00 48 48 48 48 58 02 00 00 70 43 01 00 80 f4 03 00 ff ff ff ff 07 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 22 00 20 00 00 00 00 00 00 00 00 00 dd dd 00 00 00 00 00 00 01 12 72 fb fe 07 00 00 00 80 e1 01 74 70 c5 01 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ff ff ff ff 01 00 00 00 01 00 00 00 00 00 00 00 00 01 00 00 01 00 00 00 00 00 00 00 00 00 00 00 ff ff 00 00 00 00 00 00 00 1c 24 fb fe 07 00 00 00 00 00 00 00 00 00 00 00 1c 24 fb fe 07 00 00 ff ff ff ff ff ff ff ff 08 07 00 00 ff ff ff ff 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 01 00 00 00 00 (REG_BINARY)
"DynamicInfo"=03 00 00 00 e9 e1 e2 2c 41 04 ca 01 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 (REG_BINARY)
"Hash"=a2 28 1a 82 81 4b 04 bf 0a e2 44 19 91 c4 82 c4 85 9e a3 bf f1 9e 69 5d 72 cd f0 b8 e2 5a 48 1c (REG_BINARY)

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{9979CB83-103A-4105-9E5D-C74B0AF6D198}]
"Path"="\Microsoft\Windows\CertificateServicesClient\UserTask-Roam"
"Triggers"=15 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ff ff ff ff ff ff ff ff 90 85 00 02 48 48 48 48 24 a4 c7 d0 48 48 48 48 00 48 48 48 48 48 48 48 00 48 48 48 48 48 48 48 05 00 00 00 48 48 48 48 0c 00 00 00 48 48 48 48 01 01 00 00 00 00 00 05 04 00 00 00 48 48 48 48 00 00 00 00 48 48 48 48 38 00 00 00 48 48 48 48 00 00 00 00 ff ff ff ff 00 00 00 00 ff ff ff ff 07 00 00 00 3c 00 00 00 05 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 77 77 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ff ff ff ff ff ff ff ff 00 00 00 00 ff ff ff ff 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 01 ff ff ff 02 00 00 00 01 00 10 00 00 00 00 00 07 00 00 00 00 00 00 00 01 48 48 48 48 48 48 48 77 77 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ff ff ff ff ff ff ff ff 00 00 00 00 ff ff ff ff 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 01 66 53 00 00 (REG_BINARY)
"DynamicInfo"=03 00 00 00 dc a1 9d 2e 41 04 ca 01 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 (REG_BINARY)
"Hash"=f2 ce 6a b8 c2 2d cf 17 80 14 18 67 45 5a 46 fa 6d 08 f0 8c 5b 5d 48 20 02 37 2e 5f de 05 9b 43 (REG_BINARY)

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{A35BB7A6-5F0C-4C9F-8450-2B3BED532D51}]
"Path"="\Microsoft\Windows\WindowsColorSystem\Calibration Loader"
"Triggers"=15 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ff ff ff ff ff ff ff ff 00 91 00 02 48 48 48 48 a3 4b 56 be 48 48 48 48 00 48 48 48 48 48 48 48 00 48 48 48 48 48 48 48 04 00 00 00 48 48 48 48 10 00 00 00 48 48 48 48 01 02 00 00 00 00 00 05 20 00 00 00 21 02 00 00 00 00 00 00 48 48 48 48 38 00 00 00 48 48 48 48 00 00 00 00 ff ff ff ff 00 00 00 00 ff ff ff ff 07 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 75 00 70 00 00 00 00 00 00 00 00 00 aa aa 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ff ff ff ff ff ff ff ff 00 00 00 00 ff ff ff ff 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 01 00 41 00 3b 00 3b 00 3b 00 42 00 41 00 29 00 01 48 48 48 48 48 48 48 77 77 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ff ff ff ff ff ff ff ff 00 00 00 00 ff ff ff ff 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 01 00 2d 00 65 00 6e 00 65 00 72 00 67 (REG_BINARY)
"DynamicInfo"=03 00 00 00 cd d3 01 2d 41 04 ca 01 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 (REG_BINARY)
"Hash"=1c 5e 72 cb 82 1b 89 10 81 91 ac 5b 7f d3 15 7b 5c ce 04 74 ed d4 4c 9d 1c ec 81 97 87 f2 88 ab (REG_BINARY)

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{A48CABBF-24C8-4B87-B00F-9261807C3B43}]
"Path"="\Microsoft\Windows\AppID\PolicyConverter"
"Triggers"=15 00 00 00 00 00 00 00 00 ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff 00 ff ff ff ff ff ff ff 00 00 00 00 00 00 00 00 40 11 02 02 48 48 48 48 34 98 01 7a 48 48 48 48 00 48 48 48 48 48 48 48 00 48 48 48 48 48 48 48 05 00 00 00 48 48 48 48 0c 00 00 00 48 48 48 48 01 01 00 00 00 00 00 05 13 00 00 00 48 48 48 48 00 00 00 00 48 48 48 48 00 00 00 00 48 48 48 48 (REG_BINARY)
"DynamicInfo"=03 00 00 00 d6 01 7b 2f 41 04 ca 01 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 (REG_BINARY)
"Hash"=c6 45 bb 8f 8d 8c 5d e3 ea 7a 89 3d 78 5b d9 5f c0 6f a4 d7 81 07 45 fe 4e 78 e3 92 00 9f ff b8 (REG_BINARY)

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{A4DAFE3D-2E85-4F1A-B354-9A793DB63613}]
"Path"="\Microsoft\Windows\Media Center\InstallPlayReady"
"Hash"=fa 87 21 3d e1 2b 49 7a 78 7f 46 a1 86 33 43 d4 c9 57 8e 30 57 05 73 91 84 54 df 05 28 61 03 10 (REG_BINARY)
"Triggers"=15 00 00 00 00 00 00 00 00 ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff 00 ff ff ff ff ff ff ff 00 00 00 00 00 00 00 00 00 05 42 02 48 48 48 48 4a 08 cf b1 48 48 48 48 00 48 48 48 48 48 48 48 00 48 48 48 48 48 48 48 05 00 00 00 48 48 48 48 0c 00 00 00 48 48 48 48 01 01 00 00 00 00 00 05 12 00 00 00 48 48 48 48 00 00 00 00 48 48 48 48 00 00 00 00 48 48 48 48 (REG_BINARY)
"DynamicInfo"=03 00 00 00 b7 7d a2 e4 c9 e9 cb 01 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 (REG_BINARY)

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{A6AF9377-77CE-47AB-AD7D-EC32CAD0C82D}]
"Path"="\Microsoft\Windows\Location\Notifications"
"Triggers"=15 00 00 00 00 00 00 00 00 16 24 fb fe 07 00 00 00 00 00 00 00 00 00 00 00 16 24 fb fe 07 00 00 ff ff ff ff ff ff ff ff 00 85 40 02 48 48 48 48 df dd 79 76 48 48 48 48 00 48 48 48 48 48 48 48 00 48 48 48 48 48 48 48 05 00 00 00 48 48 48 48 0c 00 00 00 48 48 48 48 01 01 00 00 00 00 00 05 0b 00 00 00 48 48 48 48 00 00 00 00 48 48 48 48 38 00 00 00 48 48 48 48 00 00 00 00 ff ff ff ff 00 00 00 00 ff ff ff ff 07 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 cc cc 00 00 00 00 00 00 00 16 24 fb fe 07 00 00 00 00 00 00 00 00 00 00 00 16 24 fb fe 07 00 00 ff ff ff ff ff ff ff ff 00 00 00 00 ff ff ff ff 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 01 01 00 00 00 00 00 05 20 00 00 00 00 00 00 00 a4 00 00 00 00 00 00 00 3c 00 51 00 75 00 65 00 72 00 79 00 4c 00 69 00 73 00 74 00 3e 00 3c 00 51 00 75 00 65 00 72 00 79 00 20 00 49 00 64 00 3d 00 22 00 30 00 22 00 20 00 50 00 61 00 74 00 68 00 3d 00 22 00 41 00 70 00 70 00 6c 00 69 00 63 00 61 00 74 (REG_BINARY)
"DynamicInfo"=03 00 00 00 d6 01 7b 2f 41 04 ca 01 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 (REG_BINARY)
"Hash"=e2 ee c5 dc 63 8b 16 a8 dc f4 e8 3a 35 14 f2 8d c7 ff b5 ca 04 85 41 76 d2 52 d9 09 5c 29 b3 43 (REG_BINARY)

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{AC4E5ACF-89F7-4220-BA21-81EE183975E2}]
"Path"="\Microsoft\Windows\Application Experience\AitAgent"
"Triggers"=15 00 00 00 00 00 00 00 01 12 72 fb fe 07 00 00 00 04 c5 1f 53 09 c8 01 00 12 72 fb fe 07 00 00 ff ff ff ff ff ff ff ff 7e 21 42 02 48 48 48 48 27 74 d5 37 48 48 48 48 00 48 48 48 48 48 48 48 00 48 48 48 48 48 48 48 05 00 00 00 48 48 48 48 0c 00 00 00 48 48 48 48 01 01 00 00 00 00 00 05 12 00 00 00 48 48 48 48 00 00 00 00 48 48 48 48 38 00 00 00 48 48 48 48 b4 00 00 00 60 35 01 00 80 f4 03 00 ff ff ff ff 09 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 dd dd 00 00 00 00 00 00 01 12 72 fb fe 07 00 00 00 04 c5 1f 53 09 c8 01 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ff ff ff ff 01 00 00 00 01 00 00 00 00 00 00 00 00 01 00 00 01 00 00 00 00 00 00 00 00 00 00 00 (REG_BINARY)
"DynamicInfo"=03 00 00 00 57 87 84 2f 41 04 ca 01 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 (REG_BINARY)
"Hash"=9a 13 ff 7f b5 4c 92 12 aa c3 66 3a ee 28 89 a6 af b0 ba 68 98 ab c3 f9 a8 11 e6 21 69 87 b8 33 (REG_BINARY)

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{AC668097-4D6B-4093-AC14-014C09DBF820}]
"Path"="\Microsoft\Windows\Ras\MobilityManager"
"Triggers"=15 00 00 00 00 00 00 00 00 16 24 fb fe 07 00 00 00 00 00 00 00 00 00 00 00 16 24 fb fe 07 00 00 ff ff ff ff ff ff ff ff 40 05 42 02 48 48 48 48 47 16 ff 88 48 48 48 48 00 48 48 48 48 48 48 48 00 48 48 48 48 48 48 48 05 00 00 00 48 48 48 48 0c 00 00 00 48 48 48 48 01 01 00 00 00 00 00 05 13 00 00 00 48 48 48 48 00 00 00 00 48 48 48 48 00 00 00 00 48 48 48 48 cc cc 00 00 00 00 00 00 00 16 24 fb fe 07 00 00 00 00 00 00 00 00 00 00 00 16 24 fb fe 07 00 00 ff ff ff ff ff ff ff ff 00 00 00 00 ff ff ff ff 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 01 01 00 00 00 00 00 05 20 00 00 00 00 00 00 00 2a 01 00 00 00 00 00 00 3c 00 51 00 75 00 65 00 72 00 79 00 4c 00 69 00 73 00 74 00 3e 00 0a 00 20 00 20 00 20 00 20 00 20 00 20 00 20 00 20 00 20 00 20 00 20 00 20 00 20 00 20 00 3c 00 51 00 75 00 65 00 72 00 79 00 0a 00 20 00 20 00 20 00 20 00 20 00 20 00 20 00 20 00 20 00 20 00 20 00 20 00 20 00 20 00 20 00 20 00 20 00 20 00 49 00 64 00 3d 00 22 00 30 00 22 00 0a 00 20 00 20 00 20 00 20 00 20 00 20 00 20 00 20 00 20 (REG_BINARY)
"DynamicInfo"=03 00 00 00 98 cf 92 2f 41 04 ca 01 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 (REG_BINARY)
"Hash"=47 2f 2f 6e 40 d8 84 58 d9 2b 94 6c 81 ba 92 25 d6 3c 0b d0 45 fb ab 63 ca ef 19 04 bc 35 ba 73 (REG_BINARY)

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{AD9075CB-BD47-46AE-A82F-B12F3B27D613}]
"Path"="\Microsoft\Windows\Setup\gwx\launchtrayprocess"
"Hash"=93 e3 02 85 fe f8 9b 0b 17 03 bb 0f ba b5 2a cd a7 98 4e b3 2e 5d 35 ce 5e ac 8b 9b 19 fb d1 93 (REG_BINARY)
"Triggers"=15 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ff ff ff ff ff ff ff ff 40 85 40 02 48 48 48 48 9f 7d 6b 40 48 48 48 48 00 48 48 48 48 48 48 48 00 48 48 48 48 48 48 48 05 00 00 00 48 48 48 48 0c 00 00 00 48 48 48 48 01 01 00 00 00 00 00 05 04 00 00 00 48 48 48 48 00 00 00 00 48 48 48 48 38 00 00 00 48 48 48 48 00 00 00 00 ff ff ff ff 00 00 00 00 ff ff ff ff 06 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 aa aa 00 00 00 00 00 00 01 a2 cb 01 00 00 00 00 00 20 16 76 a6 46 ce 01 00 00 00 00 00 00 00 00 ff ff ff ff ff ff ff ff 0f 00 00 00 ff ff ff ff 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 01 00 6f 00 72 00 2e 00 65 00 78 00 65 00 00 00 01 48 48 48 48 48 48 48 88 88 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ff ff ff ff ff ff ff ff 00 00 00 00 ff ff ff ff 00 00 00 00 00 00 00 00 00 00 00 00 00 07 00 00 01 d9 ca 01 00 00 00 00 28 d8 bd 01 00 (REG_BINARY)
"DynamicInfo"=03 00 00 00 4f 3e 9c 17 1f 24 d1 01 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 (REG_BINARY)

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{AE17005F-9E60-4C41-A422-1F1D2539F1F9}]
"Path"="\Microsoft\Windows\Media Center\PvrScheduleTask"
"Hash"=69 5a c2 68 a4 41 27 3a aa c4 3b 4c 25 e8 63 c3 54 d8 40 0f f3 72 37 31 73 43 cd 29 a2 2a 2c ef (REG_BINARY)
"Triggers"=15 00 00 00 00 00 00 00 00 ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff 00 ff ff ff ff ff ff ff 00 00 00 00 00 00 00 00 00 05 42 02 48 48 48 48 3a 1b 96 c3 48 48 48 48 00 48 48 48 48 48 48 48 00 48 48 48 48 48 48 48 05 00 00 00 48 48 48 48 0c 00 00 00 48 48 48 48 01 01 00 00 00 00 00 05 14 00 00 00 48 48 48 48 00 00 00 00 48 48 48 48 00 00 00 00 48 48 48 48 (REG_BINARY)
"DynamicInfo"=03 00 00 00 9d 7c 01 e7 c9 e9 cb 01 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 (REG_BINARY)

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{B0CBAB43-44FC-469B-A4CE-87426761FDCE}]
"Path"="\Microsoft\Windows\PerfTrack\BackgroundConfigSurveyor"
"Triggers"=15 00 00 00 00 00 00 00 00 1c 24 fb fe 07 00 00 00 00 00 00 00 00 00 00 00 1c 24 fb fe 07 00 00 ff ff ff ff ff ff ff ff 10 21 82 02 48 48 48 48 03 d6 15 89 48 48 48 48 00 48 48 48 48 48 48 48 00 48 48 48 48 48 48 48 05 00 00 00 48 48 48 48 0c 00 00 00 48 48 48 48 01 01 00 00 00 00 00 05 13 00 00 00 48 48 48 48 00 00 00 00 48 48 48 48 00 00 00 00 48 48 48 48 ee ee 00 00 00 00 00 00 00 1c 24 fb fe 07 00 00 00 00 00 00 00 00 00 00 00 1c 24 fb fe 07 00 00 ff ff ff ff ff ff ff ff 00 00 00 00 ff ff ff ff 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 01 00 00 00 00 00 00 00 00 00 00 00 03 00 00 00 dd dd 00 00 00 00 00 00 01 12 72 fb fe 07 00 00 00 78 ba 3f 01 c2 c8 01 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ff ff ff ff 01 00 00 00 01 00 00 00 00 00 00 00 00 01 00 00 01 00 00 00 00 00 00 00 00 00 00 00 (REG_BINARY)
"DynamicInfo"=03 00 00 00 f9 30 95 2f 41 04 ca 01 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 (REG_BINARY)
"Hash"=8a 4b c3 fb 22 e9 43 ed e5 a9 84 56 cc af 34 53 d4 dd d6 13 d1 a3 26 50 17 96 7a bc 8c 77 9e 7d (REG_BINARY)

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{B25A0EF1-F72A-493E-9813-9E77F70F8C30}]
"Path"="\Microsoft\Windows\SideShow\GadgetManager"
"Hash"=2b 16 a8 3d 35 90 8a 64 e8 98 f2 74 33 28 c1 6c bc 44 de 6c 67 af 39 2d 6b 0f 19 ae 00 82 9a 72 (REG_BINARY)
"Triggers"=15 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ff ff ff ff ff ff ff ff 00 91 40 02 48 48 48 48 63 de f7 f2 48 48 48 48 00 48 48 48 48 48 48 48 00 48 48 48 48 48 48 48 04 00 00 00 48 48 48 48 10 00 00 00 48 48 48 48 01 02 00 00 00 00 00 05 20 00 00 00 21 02 00 00 00 00 00 00 48 48 48 48 38 00 00 00 48 48 48 48 00 00 00 00 ff ff ff ff 80 f4 03 00 ff ff ff ff 07 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 aa aa 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ff ff ff ff ff ff ff ff 00 00 00 00 ff ff ff ff 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ff 38 01 00 00 00 00 05 00 00 00 00 00 00 00 01 48 48 48 48 48 48 48 (REG_BINARY)
"DynamicInfo"=03 00 00 00 64 db ce e1 c9 e9 cb 01 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 (REG_BINARY)

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{B2F37559-8B00-4290-AA56-5DD5656D0DF2}]
"Path"="\Microsoft\Windows\Media Center\PBDADiscovery"
"Hash"=fd 76 0a b1 6d 28 46 c5 bf b2 35 57 93 44 99 a5 25 d5 fc ec 62 4a d0 83 fd 21 dd e1 32 6f ae 9d (REG_BINARY)
"Triggers"=15 00 00 00 00 00 00 00 00 ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff 00 ff ff ff ff ff ff ff 00 00 00 00 00 00 00 00 00 21 42 02 48 48 48 48 4a c2 92 24 48 48 48 48 00 48 48 48 48 48 48 48 00 48 48 48 48 48 48 48 05 00 00 00 48 48 48 48 0c 00 00 00 48 48 48 48 01 01 00 00 00 00 00 05 12 00 00 00 48 48 48 48 00 00 00 00 48 48 48 48 00 00 00 00 48 48 48 48 (REG_BINARY)
"DynamicInfo"=03 00 00 00 b3 e6 65 e3 c9 e9 cb 01 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 (REG_BINARY)

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{B86D9031-325A-4603-91DF-B7C56E8D0BC5}]
"Path"="\Microsoft\Windows\Setup\gwx\refreshgwxcontent"
"Hash"=5e b8 9f 17 1f fd 3c 8e dd de 4f bd d5 49 5b 9f 9b d4 cf f2 4e 79 2b 01 01 08 d2 83 2b 60 79 fa (REG_BINARY)
"Triggers"=15 00 00 00 00 00 00 00 00 ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff 00 ff ff ff ff ff ff ff 00 00 00 00 00 00 00 00 c0 21 42 03 48 48 48 48 cd b5 bf a9 48 48 48 48 00 48 48 48 48 48 48 48 00 48 48 48 48 48 48 48 05 00 00 00 48 48 48 48 0c 00 00 00 48 48 48 48 01 01 00 00 00 00 00 05 12 00 00 00 48 48 48 48 00 00 00 00 48 48 48 48 38 00 00 00 48 48 48 48 00 00 00 00 ff ff ff ff 00 00 00 00 ff ff ff ff 06 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 (REG_BINARY)
"DynamicInfo"=03 00 00 00 e4 a5 3a 17 1f 24 d1 01 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 (REG_BINARY)

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{BB830F6B-2196-48E6-84F0-94B82980C34A}]
"Path"="\avast! Emergency Update"
"Hash"=14 90 66 c6 8b fb 68 20 0c 8c 4f b7 2f 2d 23 fe f3 93 8b c8 e5 c5 5c d9 3f a1 81 67 9c 13 79 be (REG_BINARY)
"Triggers"=15 00 00 00 00 00 00 00 00 6a 9e 01 00 00 00 00 80 8e 3f 51 66 31 d1 01 00 6a 9e 01 00 00 00 00 ff ff ff ff ff ff ff ff 38 21 c2 00 48 48 48 48 e7 9e f7 3b 48 48 48 48 00 48 48 48 48 48 48 48 00 48 48 48 48 48 48 48 05 00 00 00 48 48 48 48 0c 00 00 00 48 48 48 48 01 01 00 00 00 00 00 05 12 00 00 00 48 48 48 48 00 00 00 00 48 48 48 48 38 00 00 00 48 48 48 48 58 02 00 00 10 0e 00 00 80 f4 03 00 ff ff ff ff 0a 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 dd dd 00 00 00 00 00 00 00 6a 9e 01 00 00 00 00 80 c0 81 1b cd 31 d1 01 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 c0 a8 00 00 80 51 01 00 ff ff ff ff 01 00 00 00 01 00 00 00 00 00 00 00 00 01 00 00 01 00 00 00 00 00 00 00 00 00 00 00 aa aa 00 00 00 00 00 00 00 6a 9e 01 00 00 00 00 80 e0 4c 86 68 31 d1 01 00 00 00 00 00 00 00 00 ff ff ff ff ff ff ff ff f0 00 00 00 ff ff ff ff 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 01 00 63 00 6b (REG_BINARY)
"DynamicInfo"=03 00 00 00 ce a3 d6 86 68 31 d1 01 35 a7 d0 51 66 31 d1 01 24 13 04 80 00 00 00 00 (REG_BINARY)

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{BE669C13-8165-4536-96D0-6D6C39292AAE}]
"Path"="\Microsoft\Windows\Diagnosis\Scheduled"
"Triggers"=15 00 00 00 00 00 00 00 01 12 72 fb fe 07 00 00 00 68 b6 94 02 d0 c3 01 00 12 72 fb fe 07 00 00 ff ff ff ff ff ff ff ff 72 89 c0 03 48 48 48 48 ab 8c 36 e4 48 48 48 48 00 48 48 48 48 48 48 48 00 48 48 48 48 48 48 48 05 00 00 00 48 48 48 48 0c 00 00 00 48 48 48 48 01 01 00 00 00 00 00 05 04 00 00 00 48 48 48 48 00 00 00 00 48 48 48 48 38 00 00 00 48 48 48 48 58 02 00 00 80 70 00 00 80 f4 03 00 ff ff ff ff 07 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 dd dd 00 00 00 00 00 00 01 12 72 fb fe 07 00 00 00 68 b6 94 02 d0 c3 01 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ff ff ff ff 02 00 00 00 01 00 01 00 00 00 00 00 00 01 00 00 01 00 00 00 00 00 00 00 00 00 00 00 (REG_BINARY)
"DynamicInfo"=03 00 00 00 41 9a dc 2f 41 04 ca 01 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 (REG_BINARY)
"Hash"=82 eb d6 01 08 50 0f cd 35 7b f2 8c ce 59 52 ef b6 ff 94 3b 38 e8 25 0a 3a f3 45 07 c6 16 2f ae (REG_BINARY)

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{BEF69F7E-C8C8-4DB4-9D87-0BA0AE3EBC27}]
"Path"="\Microsoft\Windows\Setup\GWXTriggers\OutOfIdle-5d"
"Hash"=0a ad 37 95 39 15 b7 07 8c 1c c3 8d 48 e2 a4 4e e8 62 2f d3 dd 60 73 88 b5 05 fb 63 62 63 71 0a (REG_BINARY)
"Triggers"=15 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ff ff ff ff ff ff ff ff c8 a1 40 00 48 48 48 48 55 00 11 81 48 48 48 48 00 48 48 48 48 48 48 48 00 48 48 48 48 48 48 48 05 00 00 00 48 48 48 48 0c 00 00 00 48 48 48 48 01 01 00 00 00 00 00 05 04 00 00 00 48 48 48 48 00 00 00 00 48 48 48 48 38 00 00 00 48 48 48 48 00 00 00 00 ff ff ff ff 00 00 00 00 ff ff ff ff 07 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ee ee 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ff ff ff ff ff ff ff ff 00 00 00 00 ff ff ff ff 00 00 00 00 00 00 00 00 00 00 00 00 00 07 00 00 01 da a5 01 00 00 00 00 28 d6 83 07 00 00 00 00 (REG_BINARY)
"DynamicInfo"=03 00 00 00 5c 62 9f 99 65 31 d1 01 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 (REG_BINARY)

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{C00F6A8D-2765-4105-B37F-A8C4CEAD65C9}]
"Path"="\Microsoft\Windows Defender\MpIdleTask"
"Hash"=12 2c f5 7c b5 93 0e 95 51 99 40 3a c9 47 0b a1 e9 ab 8d 36 06 aa 72 63 0c b6 7d 6d c8 d0 97 a3 (REG_BINARY)
"Triggers"=15 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ff ff ff ff ff ff ff ff 3e 21 c2 03 48 48 48 48 0f 52 48 91 48 48 48 48 00 48 48 48 48 48 48 48 00 48 48 48 48 48 48 48 05 00 00 00 48 48 48 48 0c 00 00 00 48 48 48 48 01 01 00 00 00 00 00 05 12 00 00 00 48 48 48 48 00 00 00 00 48 48 48 48 38 00 00 00 48 48 48 48 3c 00 00 00 00 00 00 00 80 f4 03 00 ff ff ff ff 07 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ee ee 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ff ff ff ff ff ff ff ff 00 00 00 00 ff ff ff ff 00 00 00 00 00 00 00 00 00 00 00 00 00 07 00 00 01 ff 38 01 00 00 00 00 05 00 00 00 00 00 00 00 (REG_BINARY)
"DynamicInfo"=03 00 00 00 f3 fc d5 a4 cf 6c d0 01 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 (REG_BINARY)

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{C016366B-7126-46CA-B36B-592A3D95A60B}]
"Path"="\Microsoft\Windows\Customer Experience Improvement Program\Consolidator"
"Triggers"=15 00 00 00 00 00 00 00 01 12 72 fb fe 07 00 00 00 c0 5b 5d c3 d0 c3 01 00 12 72 fb fe 07 00 00 ff ff ff ff ff ff ff ff 40 21 42 02 48 48 48 48 f3 fe 73 0b 48 48 48 48 00 48 48 48 48 48 48 48 00 48 48 48 48 48 48 48 05 00 00 00 48 48 48 48 0c 00 00 00 48 48 48 48 01 01 00 00 00 00 00 05 12 00 00 00 48 48 48 48 00 00 00 00 48 48 48 48 00 00 00 00 48 48 48 48 dd dd 00 00 00 00 00 00 01 12 72 fb fe 07 00 00 00 c0 5b 5d c3 d0 c3 01 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 30 0b 01 00 00 00 00 00 ff ff ff ff 00 00 00 00 00 00 00 00 00 00 00 00 00 01 00 00 01 00 00 00 00 00 00 00 00 00 00 00 (REG_BINARY)
"DynamicInfo"=03 00 00 00 02 5d e1 2f 41 04 ca 01 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 (REG_BINARY)
"Hash"=55 5c d3 77 ba 0a 05 32 a5 63 0e be 96 ae 9d b1 84 3e 64 2b 2a 15 ba 07 c4 0c 8b 67 be 00 e8 7f (REG_BINARY)

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{C223A541-0306-4585-B202-429E1EBFC287}]
"Path"="\OfficeSoftwareProtectionPlatform\SvcRestartTask"
"Hash"=c1 64 1b 3b e7 d4 4c 4a f3 4d b1 ea fb 52 99 8f 9a 8f 67 c2 85 a5 cf 68 5d 0a 7d b9 1a 77 3f b0 (REG_BINARY)
"Triggers"=15 00 00 00 00 00 00 00 01 2b 65 01 00 00 00 00 00 00 f2 32 fa cf c3 01 00 2b 65 01 00 00 00 00 ff ff ff ff ff ff ff ff 48 21 82 02 48 48 48 48 72 c5 a8 55 48 48 48 48 00 48 48 48 48 48 48 48 00 48 48 48 48 48 48 48 05 00 00 00 48 48 48 48 0c 00 00 00 48 48 48 48 01 01 00 00 00 00 00 05 14 00 00 00 48 48 48 48 00 00 00 00 48 48 48 48 38 00 00 00 48 48 48 48 58 02 00 00 10 0e 00 00 00 00 00 00 ff ff ff ff 07 00 00 00 3c 00 00 00 03 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 dd dd 00 00 00 00 00 00 01 2b 65 01 00 00 00 00 00 00 f2 32 fa cf c3 01 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ff ff ff ff 01 00 00 00 01 00 00 00 00 00 00 00 00 01 00 00 01 00 00 00 00 00 00 00 00 00 00 00 (REG_BINARY)
"DynamicInfo"=03 00 00 00 b5 c3 24 44 0b c4 cc 01 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 (REG_BINARY)

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{C3D76F7C-3704-41B7-BD4C-0394594453A2}]
"Path"="\Microsoft\Windows\Setup\GWXTriggers\Time-5d"
"Hash"=17 28 1c ed ac 0f f7 d6 3f b7 30 44 4e 1a 52 77 9d 8c b3 6a b0 9b e5 b5 d2 e5 7a 13 86 69 f8 78 (REG_BINARY)
"Triggers"=15 00 00 00 00 00 00 00 01 7e a6 01 00 00 00 00 00 20 16 76 a6 46 ce 01 00 7e a6 01 00 00 00 00 ff ff ff ff ff ff ff ff c8 a1 40 00 48 48 48 48 26 d4 84 1a 48 48 48 48 00 48 48 48 48 48 48 48 00 48 48 48 48 48 48 48 05 00 00 00 48 48 48 48 0c 00 00 00 48 48 48 48 01 01 00 00 00 00 00 05 04 00 00 00 48 48 48 48 00 00 00 00 48 48 48 48 38 00 00 00 48 48 48 48 00 00 00 00 ff ff ff ff 00 00 00 00 ff ff ff ff 07 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 dd dd 00 00 00 00 00 00 01 7e a6 01 00 00 00 00 00 20 16 76 a6 46 ce 01 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ff ff ff ff 01 00 00 00 01 00 00 00 00 00 00 00 00 01 00 00 01 00 00 00 80 51 01 00 00 00 00 00 (REG_BINARY)
"DynamicInfo"=03 00 00 00 16 87 ae 9c 65 31 d1 01 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 (REG_BINARY)

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{C3DAC4A5-6C14-4EB6-B392-BD959BF646DE}]
"Path"="\Microsoft\Windows\Media Center\UpdateRecordPath"
"Hash"=eb 28 22 5e 5a da d1 32 3f 85 64 3a be c3 15 b0 f6 f9 f1 5d 23 2f 4d a9 d5 60 85 f7 7d 31 38 8c (REG_BINARY)
"Triggers"=15 00 00 00 00 00 00 00 00 ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff 00 ff ff ff ff ff ff ff 00 00 00 00 00 00 00 00 00 21 42 02 48 48 48 48 2e 97 7b 9b 48 48 48 48 00 48 48 48 48 48 48 48 00 48 48 48 48 48 48 48 05 00 00 00 48 48 48 48 0c 00 00 00 48 48 48 48 01 01 00 00 00 00 00 05 12 00 00 00 48 48 48 48 00 00 00 00 48 48 48 48 00 00 00 00 48 48 48 48 (REG_BINARY)
"DynamicInfo"=03 00 00 00 45 c4 07 e4 c9 e9 cb 01 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 (REG_BINARY)

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{C46431A4-4CA4-4BB8-8ABD-5B0C629B626D}]
"Path"="\Microsoft\Windows\Application Experience\ProgramDataUpdater"
"Hash"=a1 ac 57 96 5b 3f 9a 2a 44 9e ae d1 8d 7c 3e da d8 a5 f2 95 ff 2d 07 2e 48 b8 ce 64 af 5d 84 ec (REG_BINARY)
"Triggers"=15 00 00 00 00 00 00 00 01 a2 cb 01 00 00 00 00 00 0c cf c5 39 63 cf 01 00 a2 cb 01 00 00 00 00 ff ff ff ff ff ff ff ff 7e 21 42 02 48 48 48 48 8e 08 76 9d 48 48 48 48 00 48 48 48 48 48 48 48 00 48 48 48 48 48 48 48 05 00 00 00 48 48 48 48 0c 00 00 00 48 48 48 48 01 01 00 00 00 00 00 05 12 00 00 00 48 48 48 48 00 00 00 00 48 48 48 48 38 00 00 00 48 48 48 48 b4 00 00 00 70 43 01 00 80 f4 03 00 ff ff ff ff 04 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 47 00 24 00 00 00 00 00 00 00 00 00 dd dd 00 00 00 00 00 00 01 a2 cb 01 00 00 00 00 00 0c cf c5 39 63 cf 01 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ff ff ff ff 01 00 00 00 01 00 00 00 00 00 00 00 00 01 00 00 01 00 00 00 20 1c 00 00 00 00 00 00 (REG_BINARY)
"DynamicInfo"=03 00 00 00 ea 45 5d 16 1f 24 d1 01 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 (REG_BINARY)

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{C8324912-7E67-45CB-88FB-FF2984FB7CDD}]
"Path"="\Microsoft\Windows Defender\MP Scheduled Scan"
"Hash"=29 c3 d8 26 1d 55 d7 d8 2a 79 d9 cf 94 ff d2 cb 84 72 e9 b3 14 de 7b 4c 09 a7 a9 9e 3d 5c ba 72 (REG_BINARY)
"Triggers"=15 00 00 00 00 00 00 00 01 60 8c 01 00 00 00 00 80 02 9e f4 0c 54 bf 01 01 60 8c 01 00 00 00 00 00 00 64 77 63 71 2f 02 52 21 c2 03 48 48 48 48 e7 46 d9 6e 48 48 48 48 00 48 48 48 48 48 48 48 00 48 48 48 48 48 48 48 05 00 00 00 48 48 48 48 0c 00 00 00 48 48 48 48 01 01 00 00 00 00 00 05 12 00 00 00 48 48 48 48 00 00 00 00 48 48 48 48 38 00 00 00 48 48 48 48 3c 00 00 00 40 38 00 00 80 f4 03 00 ff ff ff ff 07 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 dd dd 00 00 00 00 00 00 01 60 8c 01 00 00 00 00 80 02 9e f4 0c 54 bf 01 01 60 8c 01 00 00 00 00 00 00 64 77 63 71 2f 02 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ff ff ff ff 01 00 00 00 01 00 00 00 00 00 00 00 00 01 00 00 01 00 00 00 00 00 00 00 00 00 00 00 (REG_BINARY)
"DynamicInfo"=03 00 00 00 bb 57 e9 a7 cf 6c d0 01 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 (REG_BINARY)

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{CA4B8FF2-A4D2-4D88-A52E-3A5BDAF7F56E}]
"Path"="\Microsoft\Windows\Registry\RegIdleBackup"
"Triggers"=15 00 00 00 00 00 00 00 01 12 72 fb fe 07 00 00 00 c0 76 40 09 4c c8 01 00 12 72 fb fe 07 00 00 ff ff ff ff ff ff ff ff 4e 20 c2 02 48 48 48 48 c7 92 5c 29 48 48 48 48 00 48 48 48 48 48 48 48 00 48 48 48 48 48 48 48 05 00 00 00 48 48 48 48 0c 00 00 00 48 48 48 48 01 01 00 00 00 00 00 05 12 00 00 00 48 48 48 48 00 00 00 00 48 48 48 48 38 00 00 00 48 48 48 48 b4 00 00 00 70 43 01 00 00 00 00 00 ff ff ff ff 05 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 75 00 70 00 00 00 00 00 00 00 00 00 dd dd 00 00 00 00 00 00 01 12 72 fb fe 07 00 00 00 c0 76 40 09 4c c8 01 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ff ff ff ff 01 00 00 00 0a 00 00 00 00 00 00 00 00 01 00 00 01 00 00 00 10 0e 00 00 00 00 00 00 (REG_BINARY)
"DynamicInfo"=03 00 00 00 a8 1c 18 30 41 04 ca 01 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 (REG_BINARY)
"Hash"=ae 0d b2 f3 1a 30 b2 08 e0 c5 0e f6 4c 29 94 8a 82 86 12 ac 60 5c a8 f6 b3 e4 2f 51 ea 6c 09 e1 (REG_BINARY)

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{CB3D64BF-C0C9-45FF-BFB0-FF1A8F680186}]
"Path"="\Microsoft\Windows\RemoteAssistance\RemoteAssistanceTask"
"Triggers"=15 00 00 00 00 00 00 00 00 1c 24 fb fe 07 00 00 00 00 00 00 00 00 00 00 00 1c 24 fb fe 07 00 00 ff ff ff ff ff ff ff ff 28 11 c2 03 48 48 48 48 66 d8 94 b3 48 48 48 48 00 48 48 48 48 48 48 48 00 48 48 48 48 48 48 48 05 00 00 00 48 48 48 48 0c 00 00 00 48 48 48 48 01 01 00 00 00 00 00 05 12 00 00 00 48 48 48 48 00 00 00 00 48 48 48 48 38 00 00 00 48 48 48 48 58 02 00 00 10 0e 00 00 80 f4 03 00 ff ff ff ff 07 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 22 43 6f 6c 00 00 00 00 00 00 00 00 cc cc 00 00 00 00 00 00 00 1c 24 fb fe 07 00 00 00 00 00 00 00 00 00 00 00 1c 24 fb fe 07 00 00 ff ff ff ff ff ff ff ff 0f 00 00 00 ff ff ff ff 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 01 01 00 00 00 00 00 05 20 00 00 00 00 00 00 00 a5 00 00 00 00 00 00 00 3c 00 51 00 75 00 65 00 72 00 79 00 4c 00 69 00 73 00 74 00 3e 00 3c 00 51 00 75 00 65 00 72 00 79 00 20 00 49 00 64 00 3d 00 22 00 30 00 22 00 20 00 50 00 61 00 74 00 68 00 3d 00 22 00 53 00 79 00 73 00 74 00 65 00 6d 00 22 00 3e (REG_BINARY)
"DynamicInfo"=03 00 00 00 08 7e 1a 30 41 04 ca 01 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 (REG_BINARY)
"Hash"=40 f4 a1 b4 cb f3 46 72 0b 7a 18 6a ae 91 2f ce a1 fb e0 dd 82 f4 8f 51 fc b9 ad 1a 76 bf 25 25 (REG_BINARY)

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{CBAE4B96-C967-4F89-B8CB-AFA890E4DCFF}]
"Path"="\Microsoft\Windows\DiskDiagnostic\Microsoft-Windows-DiskDiagnosticResolver"
"Hash"=ac 67 df 7a 4b 9d 1c 87 13 c2 d6 2f d8 68 51 13 fb 77 49 de 03 81 1f 77 bb c4 b4 b0 6b 74 c2 da (REG_BINARY)
"Triggers"=15 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ff ff ff ff ff ff ff ff 00 85 80 03 48 48 48 48 1f ca cd 84 48 48 48 48 00 48 48 48 48 48 48 48 00 48 48 48 48 48 48 48 04 00 00 00 48 48 48 48 10 00 00 00 48 48 48 48 01 02 00 00 00 00 00 05 20 00 00 00 21 02 00 00 00 00 00 00 48 48 48 48 00 00 00 00 48 48 48 48 aa aa 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ff ff ff ff ff ff ff ff 00 00 00 00 ff ff ff ff 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 01 ff 38 01 00 00 00 00 05 00 00 00 00 00 00 00 01 48 48 48 48 48 48 48 (REG_BINARY)
"DynamicInfo"=03 00 00 00 aa b8 ec e0 c9 e9 cb 01 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 (REG_BINARY)

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{CD5E3BFD-6C44-4E50-AD92-34CAF3CEC5DC}]
"Path"="\Microsoft\Windows\Media Center\ObjectStoreRecoveryTask"
"Hash"=0d 7c e5 3b 5d ed f3 bb 73 8e 23 e6 af cf f4 82 9c 8a f0 a3 b1 17 9e fb 42 dd 3d af ed 86 58 33 (REG_BINARY)
"Triggers"=15 00 00 00 00 00 00 00 00 ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff 00 ff ff ff ff ff ff ff 00 00 00 00 00 00 00 00 00 05 42 02 48 48 48 48 07 35 81 f7 48 48 48 48 00 48 48 48 48 48 48 48 00 48 48 48 48 48 48 48 05 00 00 00 48 48 48 48 0c 00 00 00 48 48 48 48 01 01 00 00 00 00 00 05 14 00 00 00 48 48 48 48 00 00 00 00 48 48 48 48 00 00 00 00 48 48 48 48 (REG_BINARY)
"DynamicInfo"=03 00 00 00 32 e4 9f e6 c9 e9 cb 01 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 (REG_BINARY)

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{CEE64558-E1A7-4D9D-80A7-2001912BE5B5}]
"Path"="\Microsoft\Windows\MemoryDiagnostic\CorruptionDetector"
"Triggers"=15 00 00 00 00 00 00 00 00 1c 24 fb fe 07 00 00 00 00 00 00 00 00 00 00 00 1c 24 fb fe 07 00 00 ff ff ff ff ff ff ff ff 00 a0 c0 02 48 48 48 48 f1 d7 b9 29 48 48 48 48 00 48 48 48 48 48 48 48 00 48 48 48 48 48 48 48 04 00 00 00 48 48 48 48 10 00 00 00 48 48 48 48 01 02 00 00 00 00 00 05 20 00 00 00 21 02 00 00 00 00 00 00 48 48 48 48 00 00 00 00 48 48 48 48 cc cc 00 00 00 00 00 00 00 1c 24 fb fe 07 00 00 00 00 00 00 00 00 00 00 00 1c 24 fb fe 07 00 00 ff ff ff ff ff ff ff ff 00 00 00 00 ff ff ff ff 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 01 01 00 00 00 00 00 05 20 00 00 00 00 00 00 00 99 00 00 00 00 00 00 00 3c 00 51 00 75 00 65 00 72 00 79 00 4c 00 69 00 73 00 74 00 3e 00 3c 00 51 00 75 00 65 00 72 00 79 00 20 00 49 00 64 00 3d 00 22 00 30 00 22 00 20 00 50 00 61 00 74 00 68 00 3d 00 22 00 53 00 79 00 73 00 74 00 65 00 6d 00 22 00 3e 00 3c 00 53 00 65 00 6c 00 65 00 63 00 74 00 20 00 50 00 61 00 74 00 68 00 3d 00 22 00 53 00 79 00 73 00 74 00 65 00 6d 00 22 00 3e 00 2a 00 5b 00 53 00 79 00 73 00 74 (REG_BINARY)
"DynamicInfo"=03 00 00 00 68 df 1c 30 41 04 ca 01 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 (REG_BINARY)
"Hash"=39 d0 b0 4f 35 6d f6 65 0e 07 60 76 25 5c e2 6c e2 75 91 42 87 40 c7 59 24 1d 2b 1a ee 37 f6 12 (REG_BINARY)

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{D0250F3F-6480-484F-B719-42F659AC64D5}]
"Path"="\Microsoft\Windows\Windows Error Reporting\QueueReporting"
"Triggers"=15 00 00 00 00 00 00 00 00 16 24 fb fe 07 00 00 00 00 00 00 00 00 00 00 00 16 24 fb fe 07 00 00 ff ff ff ff ff ff ff ff 40 85 40 02 48 48 48 48 8a 15 4a 60 48 48 48 48 00 48 48 48 48 48 48 48 00 48 48 48 48 48 48 48 04 00 00 00 48 48 48 48 10 00 00 00 48 48 48 48 01 02 00 00 00 00 00 05 20 00 00 00 21 02 00 00 00 00 00 00 48 48 48 48 38 00 00 00 48 48 48 48 00 00 00 00 ff ff ff ff 80 f4 03 00 ff ff ff ff 05 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 75 00 70 00 00 00 00 00 00 00 00 00 aa aa 00 00 00 00 00 00 00 16 24 fb fe 07 00 00 00 00 00 00 00 00 00 00 00 16 24 fb fe 07 00 00 ff ff ff ff ff ff ff ff 0c 03 00 00 ff ff ff ff 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 01 00 00 00 00 00 00 00 00 00 00 00 03 00 00 00 01 48 48 48 48 48 48 48 (REG_BINARY)
"DynamicInfo"=03 00 00 00 2d 35 04 2d 41 04 ca 01 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 (REG_BINARY)
"Hash"=6e b7 d5 0a 0f 0e 81 3e f3 90 52 14 6b 2a b5 86 92 ed 68 d8 2e 0e 8e 73 30 43 ec c9 33 4d 16 d1 (REG_BINARY)

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{D4466EA0-05E5-4309-AB5F-B031CEEF128B}]
"Path"="\Microsoft\Windows\SideShow\SystemDataProviders"
"Hash"=8d fb 2a aa 49 e2 62 bc 3c a3 90 1d 44 15 20 79 d5 55 67 aa a6 37 74 3e 01 e3 4d f3 6a 5f b4 c7 (REG_BINARY)
"Triggers"=15 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ff ff ff ff ff ff ff ff 00 21 02 02 48 48 48 48 88 27 59 90 48 48 48 48 00 48 48 48 48 48 48 48 00 48 48 48 48 48 48 48 05 00 00 00 48 48 48 48 0c 00 00 00 48 48 48 48 01 01 00 00 00 00 00 05 13 00 00 00 48 48 48 48 00 00 00 00 48 48 48 48 38 00 00 00 48 48 48 48 00 00 00 00 ff ff ff ff 00 00 00 00 ff ff ff ff 07 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 aa aa 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ff ff ff ff ff ff ff ff 1e 00 00 00 ff ff ff ff 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 01 00 f5 00 00 00 00 00 05 00 00 00 00 00 00 00 01 48 48 48 48 48 48 48 (REG_BINARY)
"DynamicInfo"=03 00 00 00 92 c0 31 e1 c9 e9 cb 01 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 (REG_BINARY)

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{D70E791C-7C0E-40D4-B2DD-2AF7735C6633}]
"Path"="\Microsoft\Windows\Setup\gwx\refreshgwxconfig"
"Hash"=8e 3e 95 b1 b9 36 44 2e c6 97 e1 4e 29 bc dd 20 d6 c8 e7 6d 53 f0 fb 40 2c 41 50 64 33 37 49 23 (REG_BINARY)
"Triggers"=15 00 00 00 00 00 00 00 00 ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff 00 ff ff ff ff ff ff ff 00 00 00 00 00 00 00 00 c0 21 42 03 48 48 48 48 e5 4f 27 27 48 48 48 48 00 48 48 48 48 48 48 48 00 48 48 48 48 48 48 48 05 00 00 00 48 48 48 48 0c 00 00 00 48 48 48 48 01 01 00 00 00 00 00 05 12 00 00 00 48 48 48 48 00 00 00 00 48 48 48 48 38 00 00 00 48 48 48 48 00 00 00 00 ff ff ff ff 00 00 00 00 ff ff ff ff 06 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 47 00 24 00 00 00 00 00 00 00 00 00 (REG_BINARY)
"DynamicInfo"=03 00 00 00 c1 76 20 17 1f 24 d1 01 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 (REG_BINARY)

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{D7B6E81D-3CF4-432C-84D2-24213F4316E6}]
"Path"="\Microsoft\Windows\Autochk\Proxy"
"Triggers"=15 00 00 00 00 00 00 00 00 1c 24 fb fe 07 00 00 00 00 00 00 00 00 00 00 00 1c 24 fb fe 07 00 00 ff ff ff ff ff ff ff ff 42 21 42 02 48 48 48 48 b1 b1 ab 59 48 48 48 48 00 48 48 48 48 48 48 48 00 48 48 48 48 48 48 48 05 00 00 00 48 48 48 48 0c 00 00 00 48 48 48 48 01 01 00 00 00 00 00 05 13 00 00 00 48 48 48 48 00 00 00 00 48 48 48 48 38 00 00 00 48 48 48 48 58 02 00 00 80 33 e1 01 80 f4 03 00 ff ff ff ff 07 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ff ff 00 00 00 00 00 00 00 1c 24 fb fe 07 00 00 00 00 00 00 00 00 00 00 00 1c 24 fb fe 07 00 00 ff ff ff ff ff ff ff ff 08 07 00 00 ff ff ff ff 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 01 00 00 00 00 00 00 00 00 00 00 00 03 00 00 00 (REG_BINARY)
"DynamicInfo"=03 00 00 00 4a 43 e5 2c 41 04 ca 01 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 (REG_BINARY)
"Hash"=02 e6 03 f0 f0 b9 82 21 f0 70 dd 81 a8 8b 3d b6 7c e5 da 31 5b c5 68 42 37 32 f9 ee d1 5f 3f 79 (REG_BINARY)

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{DA3CE826-4A45-4CC3-B7C5-ABD4ED5E6A8D}]
"Path"="\{9BE1CFE5-2C71-40C1-A065-D3796C57E3BB}"
"Hash"=cb 8a dd 13 19 fd 9b a8 21 6b 91 0e 69 bb 1c 58 4f b9 d4 80 f4 52 cb 40 17 26 a3 0b 4a ff e2 6b (REG_BINARY)
"Triggers"=15 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ff ff ff ff ff ff ff ff 28 21 41 00 48 48 48 48 a8 6c 8c 47 48 48 48 48 00 48 48 48 48 48 48 48 00 48 48 48 48 48 48 48 01 00 00 00 48 48 48 48 1c 00 00 00 48 48 48 48 01 05 00 00 00 00 00 05 15 00 00 00 fe a2 7c 2a 46 26 e9 5a 5b 08 ef 05 e8 03 00 00 48 48 48 48 3a 00 00 00 48 48 48 48 41 00 6c 00 79 00 73 00 73 00 61 00 47 00 65 00 68 00 72 00 69 00 6e 00 67 00 5c 00 41 00 6c 00 79 00 73 00 73 00 61 00 20 00 47 00 65 00 68 00 72 00 69 00 6e 00 67 00 00 00 48 48 48 48 48 48 38 00 00 00 48 48 48 48 58 02 00 00 10 0e 00 00 80 f4 03 00 ff ff ff ff 07 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 88 88 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ff ff ff ff ff ff ff ff 00 00 00 00 ff ff ff ff 00 00 00 00 00 00 00 00 00 00 00 00 00 07 00 00 01 00 64 00 6c 00 6c 00 2c 00 2d 00 35 00 30 00 (REG_BINARY)
"DynamicInfo"=03 00 00 00 10 71 c8 d9 70 76 d0 01 b8 d2 c8 d9 70 76 d0 01 00 00 00 00 00 00 00 00 (REG_BINARY)

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{DA41DE71-8431-42FB-9DB0-EB64A961DEAD}]
"Path"="\Microsoft\Windows\Maintenance\WinSAT"
"Triggers"=15 00 00 00 00 00 00 00 01 f2 c4 01 00 00 00 00 00 28 3b a2 11 4c c8 01 00 f2 c4 01 00 00 00 00 ff ff ff ff ff ff ff ff 3a a1 00 03 48 48 48 48 61 f8 4c 36 48 48 48 48 00 48 48 48 48 48 48 48 00 48 48 48 48 48 48 48 04 00 00 00 48 48 48 48 10 00 00 00 48 48 48 48 01 02 00 00 00 00 00 05 20 00 00 00 20 02 00 00 00 00 00 00 48 48 48 48 38 00 00 00 48 48 48 48 00 00 00 00 ff ff ff ff 00 00 00 00 ff ff ff ff 07 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 dd dd 00 00 00 00 00 00 01 f2 c4 01 00 00 00 00 00 28 3b a2 11 4c c8 01 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ff ff ff ff 02 00 00 00 01 00 01 00 00 00 00 00 00 01 00 00 01 00 00 00 00 00 00 00 00 00 00 00 (REG_BINARY)
"DynamicInfo"=03 00 00 00 c9 40 1f 30 41 04 ca 01 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 (REG_BINARY)
"Hash"=aa 1f 58 fd 98 3a ff c5 9d af 92 3e bb cf e8 e2 77 86 d3 15 a5 60 d8 8c fc 4f c9 b0 43 08 1d fe (REG_BINARY)

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{DD9F510C-95F4-499A-90C8-BAC5BC372FF4}]
"Path"="\Microsoft\Windows\SoftwareProtectionPlatform\SvcRestartTask"
"Triggers"=15 00 00 00 00 00 00 00 01 12 72 fb fe 07 00 00 00 00 f2 32 fa cf c3 01 00 12 72 fb fe 07 00 00 ff ff ff ff ff ff ff ff 40 21 82 02 48 48 48 48 21 7b 8e 98 48 48 48 48 00 48 48 48 48 48 48 48 00 48 48 48 48 48 48 48 05 00 00 00 48 48 48 48 0c 00 00 00 48 48 48 48 01 01 00 00 00 00 00 05 14 00 00 00 48 48 48 48 00 00 00 00 48 48 48 48 38 00 00 00 48 48 48 48 00 00 00 00 ff ff ff ff 00 00 00 00 ff ff ff ff 07 00 00 00 3c 00 00 00 03 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 dd dd 00 00 00 00 00 00 01 12 72 fb fe 07 00 00 00 00 f2 32 fa cf c3 01 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ff ff ff ff 01 00 00 00 01 00 00 00 00 00 00 00 00 01 00 00 01 00 00 00 00 00 00 00 00 00 00 00 (REG_BINARY)
"DynamicInfo"=03 00 00 00 29 a2 21 30 41 04 ca 01 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 (REG_BINARY)
"Hash"=fd 59 aa 8f a7 e6 d6 c6 81 94 51 35 c9 9b ce ac 82 f3 db 23 b0 37 25 3c 8d ad 16 17 f5 c5 e4 25 (REG_BINARY)

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{DF6974F8-A3EA-48C6-A2E0-2D4320EC2FAA}]
"Path"="\Microsoft\Windows Live\SOXE\Extractor Definitions Update Task"
"Hash"=7c 90 be 8c 4e 06 8c 33 54 be 87 29 c0 25 d9 f6 d5 59 f1 0f d5 7c cc d0 06 5b 51 d0 bc ad c0 8e (REG_BINARY)
"Triggers"=15 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 20 a3 01 00 00 00 00 ff ff ff ff ff ff ff ff f8 a1 40 00 48 48 48 48 0e 09 07 c6 48 48 48 48 00 48 48 48 48 48 48 48 00 48 48 48 48 48 48 48 05 00 00 00 48 48 48 48 0c 00 00 00 48 48 48 48 01 01 00 00 00 00 00 05 04 00 00 00 48 48 48 48 00 00 00 00 48 48 48 48 38 00 00 00 48 48 48 48 58 02 00 00 10 0e 00 00 10 0e 00 00 ff ff ff ff 07 00 00 00 10 0e 00 00 01 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 dd dd 00 00 00 00 00 00 01 20 a3 01 00 00 00 00 00 63 8f 47 26 c9 ca 01 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ff ff ff ff 01 00 00 00 07 00 00 00 00 00 00 00 00 01 00 00 01 00 00 00 80 3a 09 00 00 00 00 00 aa aa 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ff ff ff ff ff ff ff ff 84 03 00 00 ff ff ff ff 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 01 00 a3 01 00 (REG_BINARY)
"DynamicInfo"=03 00 00 00 19 59 cb a1 cb e9 cb 01 b5 45 48 77 67 31 d1 01 24 13 04 80 00 00 00 00 (REG_BINARY)

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{DFB1F8D3-6B27-408F-9F9F-F043E7876CD4}]
"Path"="\WPD\SqmUpload_S-1-5-21-712811262-1525229126-99551323-1000"
"Hash"=34 db db 64 36 0b d3 c1 fd b0 65 26 70 47 02 10 3d e4 9d 24 57 09 1d 00 c6 97 2b c7 0c 32 77 32 (REG_BINARY)
"Triggers"=15 00 00 00 00 00 00 00 01 88 d6 01 00 00 00 00 00 a0 ab d5 6d 4c c8 01 01 88 d6 01 00 00 00 00 00 80 d8 fc ad 84 d0 01 d2 21 c1 02 48 48 48 48 ac af 6a b7 48 48 48 48 00 48 48 48 48 48 48 48 00 48 48 48 48 48 48 48 01 00 00 00 48 48 48 48 1c 00 00 00 48 48 48 48 01 05 00 00 00 00 00 05 15 00 00 00 fe a2 7c 2a 46 26 e9 5a 5b 08 ef 05 e8 03 00 00 48 48 48 48 3a 00 00 00 48 48 48 48 41 00 6c 00 79 00 73 00 73 00 61 00 47 00 65 00 68 00 72 00 69 00 6e 00 67 00 5c 00 41 00 6c 00 79 00 73 00 73 00 61 00 20 00 47 00 65 00 68 00 72 00 69 00 6e 00 67 00 00 00 48 48 48 48 48 48 38 00 00 00 48 48 48 48 58 02 00 00 70 43 01 00 84 03 00 00 ff ff ff ff 07 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 dd dd 00 00 00 00 00 00 01 88 d6 01 00 00 00 00 00 a0 ab d5 6d 4c c8 01 01 88 d6 01 00 00 00 00 00 80 d8 fc ad 84 d0 01 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ff ff ff ff 01 00 00 00 01 00 00 00 00 00 00 00 00 01 00 00 01 (REG_BINARY)
"DynamicInfo"=03 00 00 00 19 45 38 70 1e 24 d1 01 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 (REG_BINARY)

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{E22A8667-F75B-4BA9-BA46-067ED4429DE8}]
"Path"="\Microsoft\Windows\Windows Filtering Platform\BfeOnServiceStartTypeChange"
"Triggers"=15 00 00 00 00 00 00 00 00 1c 24 fb fe 07 00 00 00 00 00 00 00 00 00 00 00 1c 24 fb fe 07 00 00 ff ff ff ff ff ff ff ff 00 10 c2 02 48 48 48 48 17 0f 4f 6e 48 48 48 48 00 48 48 48 48 48 48 48 00 48 48 48 48 48 48 48 05 00 00 00 48 48 48 48 0c 00 00 00 48 48 48 48 01 01 00 00 00 00 00 05 12 00 00 00 48 48 48 48 00 00 00 00 48 48 48 48 38 00 00 00 48 48 48 48 00 00 00 00 ff ff ff ff 80 f4 03 00 ff ff ff ff 07 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 cc cc 00 00 00 00 00 00 00 1c 24 fb fe 07 00 00 00 00 00 00 00 00 00 00 00 1c 24 fb fe 07 00 00 ff ff ff ff ff ff ff ff 00 00 00 00 ff ff ff ff 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 01 01 00 00 00 00 00 05 20 00 00 00 00 00 00 00 d3 00 00 00 00 00 00 00 3c 00 51 00 75 00 65 00 72 00 79 00 4c 00 69 00 73 00 74 00 3e 00 3c 00 51 00 75 00 65 00 72 00 79 00 20 00 49 00 64 00 3d 00 22 00 30 00 22 00 20 00 50 00 61 00 74 00 68 00 3d 00 22 00 53 00 79 00 73 00 74 00 65 00 6d 00 22 00 3e (REG_BINARY)
"DynamicInfo"=03 00 00 00 29 a2 21 30 41 04 ca 01 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 (REG_BINARY)
"Hash"=cd 35 89 98 7e 9b 5e 1e 6b 4e ec 84 9a 5a db be ec ea 05 cb 35 bb 86 b0 7a c6 6c 40 29 eb 0d 6d (REG_BINARY)

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{E24BA793-EB0B-4229-978C-A777293D9AFF}]
"Path"="\Adobe Acrobat Update Task"
"Hash"=c2 85 a9 b0 9b 79 a1 03 24 35 d9 8e c1 b1 73 0e 53 03 6e aa 7a 11 1f 23 7c 08 14 23 c7 07 71 b8 (REG_BINARY)
"Triggers"=15 00 00 00 00 00 00 00 01 00 c3 01 00 00 00 00 00 3e c4 58 af 8e ce 01 01 00 c3 01 00 00 00 00 00 c0 66 25 db f8 dd 01 78 a1 40 00 48 48 48 48 f8 b5 c7 3f 48 48 48 48 00 48 48 48 48 48 48 48 00 48 48 48 48 48 48 48 05 00 00 00 48 48 48 48 0c 00 00 00 48 48 48 48 01 01 00 00 00 00 00 05 04 00 00 00 48 48 48 48 00 00 00 00 48 48 48 48 38 00 00 00 48 48 48 48 58 02 00 00 10 0e 00 00 80 f4 03 00 ff ff ff ff 07 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 65 00 73 00 00 00 00 00 00 00 00 00 aa aa 00 00 00 00 00 00 01 00 c3 01 00 00 00 00 00 3e c4 58 af 8e ce 01 01 00 c3 01 00 00 00 00 00 c0 66 25 db f8 dd 01 d0 02 00 00 ff ff ff ff 38 31 00 00 00 00 00 00 00 00 00 00 00 00 00 00 01 08 14 23 c7 07 71 b8 01 00 00 00 00 00 00 00 01 48 48 48 48 48 48 48 (REG_BINARY)
"DynamicInfo"=03 00 00 00 e4 6b 60 ea 20 24 d1 01 db bd fa 0b 67 31 d1 01 24 13 04 80 00 00 00 00 (REG_BINARY)

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{E3163C33-301D-4730-A266-5518C5ED3967}]
"Path"="\Microsoft\Windows\Bluetooth\UninstallDeviceTask"
"Triggers"=15 00 00 00 00 00 00 00 00 ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff 00 ff ff ff ff ff ff ff 00 00 00 00 00 00 00 00 10 05 42 02 48 48 48 48 0d 99 df d7 48 48 48 48 00 48 48 48 48 48 48 48 00 48 48 48 48 48 48 48 05 00 00 00 48 48 48 48 0c 00 00 00 48 48 48 48 01 01 00 00 00 00 00 05 12 00 00 00 48 48 48 48 00 00 00 00 48 48 48 48 00 00 00 00 48 48 48 48 (REG_BINARY)
"DynamicInfo"=03 00 00 00 89 03 24 30 41 04 ca 01 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 (REG_BINARY)
"Hash"=90 a6 90 3c 07 9d e7 96 e0 b7 2c 7c 3b 74 0e a1 ad 65 58 83 df 0a c5 46 8e 3e b7 03 11 b7 e7 f7 (REG_BINARY)

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{E601E35F-CA2E-4D5B-B924-391C466BAEE3}]
"Path"="\Microsoft\Windows\Setup\GWXTriggers\refreshgwxconfig-B"
"Hash"=c6 42 24 6b 75 50 47 15 57 f2 30 ed 85 7f 8f 04 a6 3a 0c bc cc 0f 9b c4 e2 f1 1d 02 ec 14 6b ce (REG_BINARY)
"Triggers"=15 00 00 00 00 00 00 00 01 7e a6 01 00 00 00 00 00 20 16 76 a6 46 ce 01 00 7e a6 01 00 00 00 00 ff ff ff ff ff ff ff ff c8 21 42 01 48 48 48 48 ec de d0 df 48 48 48 48 00 48 48 48 48 48 48 48 00 48 48 48 48 48 48 48 05 00 00 00 48 48 48 48 0c 00 00 00 48 48 48 48 01 01 00 00 00 00 00 05 12 00 00 00 48 48 48 48 00 00 00 00 48 48 48 48 38 00 00 00 48 48 48 48 00 00 00 00 ff ff ff ff 00 00 00 00 ff ff ff ff 07 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 dd dd 00 00 00 00 00 00 01 7e a6 01 00 00 00 00 00 20 16 76 a6 46 ce 01 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 c0 a8 00 00 80 51 01 00 ff ff ff ff 01 00 00 00 01 00 00 00 00 00 00 00 00 01 00 00 01 00 00 00 c0 a8 00 00 00 00 00 00 (REG_BINARY)
"DynamicInfo"=03 00 00 00 fc 04 f7 9d 65 31 d1 01 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 (REG_BINARY)

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{EACA24FF-236C-401D-A1E7-B3D5267B8A50}]
"Path"="\Microsoft\Windows\RAC\RacTask"
"Triggers"=15 00 00 00 00 00 00 00 00 1c 24 fb fe 07 00 00 00 00 00 00 00 00 00 00 00 1c 24 fb fe 07 00 00 ff ff ff ff ff ff ff ff 40 21 c2 02 48 48 48 48 e9 c5 e8 7d 48 48 48 48 00 48 48 48 48 48 48 48 00 48 48 48 48 48 48 48 05 00 00 00 48 48 48 48 0c 00 00 00 48 48 48 48 01 01 00 00 00 00 00 05 13 00 00 00 48 48 48 48 00 00 00 00 48 48 48 48 38 00 00 00 48 48 48 48 00 00 00 00 ff ff ff ff 00 00 00 00 ff ff ff ff 07 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 cc cc 00 00 00 00 00 00 00 1c 24 fb fe 07 00 00 00 00 00 00 00 00 00 00 00 1c 24 fb fe 07 00 00 ff ff ff ff ff ff ff ff 00 00 00 00 ff ff ff ff 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 01 01 00 00 00 00 00 05 20 00 00 00 00 00 00 00 a8 00 00 00 00 00 00 00 3c 00 51 00 75 00 65 00 72 00 79 00 4c 00 69 00 73 00 74 00 3e 00 3c 00 51 00 75 00 65 00 72 00 79 00 20 00 49 00 64 00 3d 00 22 00 30 00 22 00 20 00 50 00 61 00 74 00 68 00 3d 00 22 00 41 00 70 00 70 00 6c 00 69 00 63 00 61 00 74 (REG_BINARY)
"DynamicInfo"=03 00 00 00 89 03 24 30 41 04 ca 01 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 (REG_BINARY)
"Hash"=e5 98 79 e1 ff 87 cb 7d 11 14 26 64 c9 19 e0 ad f6 1f 5a 96 87 d6 97 c3 f1 c2 04 fa 4c 56 e3 03 (REG_BINARY)

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{EB02381F-D652-4B1C-894A-712498C62C51}]
"Path"="\Microsoft\Windows\MUI\LPRemove"
"Triggers"=15 00 00 00 00 00 00 00 00 1c 24 fb fe 07 00 00 00 00 00 00 00 00 00 00 00 1c 24 fb fe 07 00 00 ff ff ff ff ff ff ff ff 12 21 42 03 48 48 48 48 9b 41 d2 d8 48 48 48 48 00 48 48 48 48 48 48 48 00 48 48 48 48 48 48 48 05 00 00 00 48 48 48 48 0c 00 00 00 48 48 48 48 01 01 00 00 00 00 00 05 12 00 00 00 48 48 48 48 00 00 00 00 48 48 48 48 38 00 00 00 48 48 48 48 58 02 00 00 ff ff ff ff 90 7e 00 00 ff ff ff ff 07 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ff ff 00 00 00 00 00 00 00 1c 24 fb fe 07 00 00 00 00 00 00 00 00 00 00 00 1c 24 fb fe 07 00 00 ff ff ff ff ff ff ff ff dc 05 00 00 ff ff ff ff 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 01 00 00 00 00 00 00 00 00 00 00 00 03 00 00 00 (REG_BINARY)
"DynamicInfo"=03 00 00 00 4a 43 e5 2c 41 04 ca 01 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 (REG_BINARY)
"Hash"=47 d4 5b 03 1c 19 94 b3 9c 49 ef 36 d6 fe 80 fb ec 11 1f 7d 6e f3 e2 82 47 6e f5 d7 7e 09 7d ab (REG_BINARY)

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{F4098BC1-256E-4683-B776-F935A8F26876}]
"Path"="\Microsoft\Windows\Media Center\PBDADiscoveryW2"
"Hash"=d2 b5 29 26 9e 9c d0 c8 e7 77 50 6b 13 cb c3 b9 ec 13 3a dc fa 21 60 d0 3b 79 56 63 c6 d1 4d 51 (REG_BINARY)
"Triggers"=15 00 00 00 00 00 00 00 00 ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff 00 ff ff ff ff ff ff ff 00 00 00 00 00 00 00 00 40 05 42 02 48 48 48 48 21 57 27 bb 48 48 48 48 00 48 48 48 48 48 48 48 00 48 48 48 48 48 48 48 05 00 00 00 48 48 48 48 0c 00 00 00 48 48 48 48 01 01 00 00 00 00 00 05 12 00 00 00 48 48 48 48 00 00 00 00 48 48 48 48 38 00 00 00 48 48 48 48 00 00 00 00 ff ff ff ff 10 0e 00 00 ff ff ff ff 07 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 (REG_BINARY)
"DynamicInfo"=03 00 00 00 32 65 b6 e7 c9 e9 cb 01 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 (REG_BINARY)

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{F73EEEE3-13AA-4CC7-9EA1-4B6092DED721}]
"Path"="\Microsoft\Windows\MobilePC\HotStart"
"Hash"=06 51 bf 3b 99 23 f8 0b e8 b5 0e 25 3e 84 3a 95 b0 cf b7 eb 97 a3 ee 4e 7c 95 5b 54 3d d1 90 e9 (REG_BINARY)
"Triggers"=15 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ff ff ff ff ff ff ff ff 40 85 40 02 48 48 48 48 7e 9b 65 8c 48 48 48 48 00 48 48 48 48 48 48 48 00 48 48 48 48 48 48 48 05 00 00 00 48 48 48 48 0c 00 00 00 48 48 48 48 01 01 00 00 00 00 00 05 0b 00 00 00 48 48 48 48 00 00 00 00 48 48 48 48 38 00 00 00 48 48 48 48 00 00 00 00 ff ff ff ff 00 00 00 00 ff ff ff ff 07 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 aa aa 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ff ff ff ff ff ff ff ff 00 00 00 00 ff ff ff ff 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 01 ff 38 01 00 00 00 00 05 00 00 00 00 00 00 00 01 48 48 48 48 48 48 48 (REG_BINARY)
"DynamicInfo"=03 00 00 00 64 5c e5 e2 c9 e9 cb 01 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 (REG_BINARY)

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{F77498FD-76A5-416F-8D11-2A785E9FD064}]
"Path"="\Microsoft\Windows\SideShow\AutoWake"
"Hash"=f1 f3 64 7b 90 ef 32 06 99 c2 a4 cc 87 75 53 d0 af 5f bc 91 cc a7 3e c5 d2 1d 2c 69 ab a9 7b e7 (REG_BINARY)
"Triggers"=15 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ff ff ff ff ff ff ff ff 00 21 02 02 48 48 48 48 1c e1 e0 52 48 48 48 48 00 48 48 48 48 48 48 48 00 48 48 48 48 48 48 48 05 00 00 00 48 48 48 48 0c 00 00 00 48 48 48 48 01 01 00 00 00 00 00 05 13 00 00 00 48 48 48 48 00 00 00 00 48 48 48 48 38 00 00 00 48 48 48 48 00 00 00 00 ff ff ff ff 00 00 00 00 ff ff ff ff 07 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 aa aa 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ff ff ff ff ff ff ff ff 3c 00 00 00 ff ff ff ff 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 01 ff 38 01 00 00 00 00 05 00 00 00 00 00 00 00 01 48 48 48 48 48 48 48 (REG_BINARY)
"DynamicInfo"=03 00 00 00 d8 1e 66 e1 c9 e9 cb 01 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 (REG_BINARY)

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{FA2BC0A6-8D4B-458A-85C8-2B8C72487513}]
"Path"="\Microsoft\Windows\MemoryDiagnostic\DecompressionFailureDetector"
"Triggers"=15 00 00 00 00 00 00 00 00 1c 24 fb fe 07 00 00 00 00 00 00 00 00 00 00 00 1c 24 fb fe 07 00 00 ff ff ff ff ff ff ff ff 00 a0 c0 02 48 48 48 48 aa 4e 8b 9d 48 48 48 48 00 48 48 48 48 48 48 48 00 48 48 48 48 48 48 48 04 00 00 00 48 48 48 48 10 00 00 00 48 48 48 48 01 02 00 00 00 00 00 05 20 00 00 00 21 02 00 00 00 00 00 00 48 48 48 48 00 00 00 00 48 48 48 48 cc cc 00 00 00 00 00 00 00 1c 24 fb fe 07 00 00 00 00 00 00 00 00 00 00 00 1c 24 fb fe 07 00 00 ff ff ff ff ff ff ff ff 00 00 00 00 ff ff ff ff 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 01 01 00 00 00 00 00 05 20 00 00 00 00 00 00 00 f4 00 00 00 00 00 00 00 3c 00 51 00 75 00 65 00 72 00 79 00 4c 00 69 00 73 00 74 00 3e 00 3c 00 51 00 75 00 65 00 72 00 79 00 20 00 49 00 64 00 3d 00 22 00 30 00 22 00 20 00 50 00 61 00 74 00 68 00 3d 00 22 00 4d 00 69 00 63 00 72 00 6f 00 73 00 6f 00 66 00 74 00 2d 00 57 00 69 00 6e 00 64 00 6f 00 77 00 73 00 2d 00 4b 00 65 00 72 00 6e 00 65 00 6c 00 2d 00 53 00 74 00 6f 00 72 00 65 00 4d 00 67 00 72 00 2f 00 4f 00 70 (REG_BINARY)
"DynamicInfo"=03 00 00 00 e9 64 26 30 41 04 ca 01 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 (REG_BINARY)
"Hash"=cb b1 2f 1e d1 29 86 18 18 01 a3 65 a6 f7 50 01 d3 1d 2b b3 cf 74 41 ba 85 41 89 42 67 d4 cc 42 (REG_BINARY)

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{FB1544A9-507B-4665-A8B3-8E28DF42FF0A}]
"Path"="\Microsoft\Windows\WindowsBackup\Windows Backup Monitor"
"Hash"=9f 4e 57 40 cf 26 51 cc 44 b3 7a 21 36 82 59 c0 ce 9c 1c 41 40 f9 a1 74 79 4c bb 65 08 67 75 1b (REG_BINARY)
"Triggers"=15 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 2f cc 01 00 00 00 00 ff ff ff ff ff ff ff ff 40 a1 40 03 48 48 48 48 4d 5a 71 52 48 48 48 48 00 48 48 48 48 48 48 48 00 48 48 48 48 48 48 48 04 00 00 00 48 48 48 48 10 00 00 00 48 48 48 48 01 02 00 00 00 00 00 05 20 00 00 00 21 02 00 00 00 00 00 00 48 48 48 48 00 00 00 00 48 48 48 48 dd dd 00 00 00 00 00 00 01 2f cc 01 00 00 00 00 00 90 1e 77 c8 86 c5 01 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ff ff ff ff 01 00 00 00 01 00 00 00 00 00 00 00 00 01 00 00 01 00 00 00 00 00 00 00 00 00 00 00 aa aa 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ff ff ff ff ff ff ff ff 2c 01 00 00 ff ff ff ff 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 01 00 69 00 63 00 65 00 3a 00 00 00 00 00 00 00 01 48 48 48 48 48 48 48 77 77 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ff ff ff ff ff (REG_BINARY)
"DynamicInfo"=03 00 00 00 ef fe 48 2d 8e 30 d1 01 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 (REG_BINARY)

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{FB3C354D-297A-4EB2-9B58-090F6361906B}]
"Path"="\Microsoft\Windows\Power Efficiency Diagnostics\AnalyzeSystem"
"Triggers"=15 00 00 00 00 00 00 00 01 12 72 fb fe 07 00 00 00 30 11 8b 3b 4c c8 01 00 12 72 fb fe 07 00 00 ff ff ff ff ff ff ff ff 42 21 42 02 48 48 48 48 d8 d9 93 2b 48 48 48 48 00 48 48 48 48 48 48 48 00 48 48 48 48 48 48 48 05 00 00 00 48 48 48 48 0c 00 00 00 48 48 48 48 01 01 00 00 00 00 00 05 12 00 00 00 48 48 48 48 00 00 00 00 48 48 48 48 38 00 00 00 48 48 48 48 2c 01 00 00 20 1c 00 00 2c 01 00 00 ff ff ff ff 07 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 75 00 70 00 00 00 00 00 00 00 00 00 dd dd 00 00 00 00 00 00 01 12 72 fb fe 07 00 00 00 30 11 8b 3b 4c c8 01 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ff ff ff ff 01 00 00 00 0e 00 00 00 00 00 00 00 00 01 00 00 01 00 00 00 80 70 00 00 00 00 00 00 (REG_BINARY)
"DynamicInfo"=03 00 00 00 aa 27 2b 30 41 04 ca 01 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 (REG_BINARY)
"Hash"=94 23 b2 65 cb ab 42 6f 81 67 2f 08 4e 7d 98 66 f6 85 d9 83 b6 22 24 71 2f f0 db c4 ff ef e3 74 (REG_BINARY)

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{FDD56C73-F0D5-41B6-B767-6EFFD7966428}]
"Path"="\Microsoft\Windows\Customer Experience Improvement Program\KernelCeipTask"
"Triggers"=15 00 00 00 00 00 00 00 01 12 72 fb fe 07 00 00 00 2c 71 03 e3 0b c9 01 00 12 72 fb fe 07 00 00 ff ff ff ff ff ff ff ff 52 21 c2 02 48 48 48 48 d3 fa 1a b0 48 48 48 48 00 48 48 48 48 48 48 48 00 48 48 48 48 48 48 48 05 00 00 00 48 48 48 48 0c 00 00 00 48 48 48 48 01 01 00 00 00 00 00 05 13 00 00 00 48 48 48 48 00 00 00 00 48 48 48 48 38 00 00 00 48 48 48 48 b4 00 00 00 10 ef 00 00 80 f4 03 00 ff ff ff ff 07 00 00 00 8c 0a 00 00 01 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 80 00 00 00 00 00 dd dd 00 00 00 00 00 00 01 12 72 fb fe 07 00 00 00 2c 71 03 e3 0b c9 01 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ff ff ff ff 02 00 00 00 01 00 10 00 00 00 00 00 00 01 00 00 01 00 00 00 00 00 00 00 00 00 00 00 (REG_BINARY)
"DynamicInfo"=03 00 00 00 aa 27 2b 30 41 04 ca 01 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 (REG_BINARY)
"Hash"=ae b0 3f 1b c1 69 23 6f 2c 3b f0 19 f9 d9 ed 3c 21 3d 1e 4a 56 8f 8c 67 f1 fc 3f 2e c0 86 49 a6 (REG_BINARY)

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{FEE260EE-1DA0-4F59-A059-3A9090F5C233}]
"Path"="\McAfeeLogon"
"Hash"=eb 0e 73 3d 18 b0 78 0e 75 1d 36 b3 e5 76 d5 fc f6 16 a0 35 72 fb 85 b4 10 bd b1 1e ca 18 b2 3b (REG_BINARY)
"Triggers"=15 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ff ff ff ff ff ff ff ff 40 85 40 00 48 48 48 48 e0 e7 53 26 48 48 48 48 00 48 48 48 48 48 48 48 00 48 48 48 48 48 48 48 04 00 00 00 48 48 48 48 10 00 00 00 48 48 48 48 01 02 00 00 00 00 00 05 20 00 00 00 21 02 00 00 00 00 00 00 48 48 48 48 38 00 00 00 48 48 48 48 58 02 00 00 10 0e 00 00 00 00 00 00 ff ff ff ff 07 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 aa aa 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ff ff ff ff ff ff ff ff 3c 00 00 00 ff ff ff ff 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 01 74 16 84 4c 70 a8 58 01 00 00 00 35 00 30 00 01 48 48 48 48 48 48 48 (REG_BINARY)
"DynamicInfo"=03 00 00 00 a7 1b 88 bf 1e 24 d1 01 58 b0 30 96 65 31 d1 01 01 13 04 00 00 00 00 00 (REG_BINARY)


[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree]
(No values found)

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Adobe Acrobat Update Task]
"Id"="{E24BA793-EB0B-4229-978C-A777293D9AFF}"
"Index"= 0x0000000002 (2)

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Adobe Flash Player Updater]
"Id"="{3341F5D4-4C5F-4439-82FB-9B6B73E1835A}"
"Index"= 0x0000000003 (3)

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Apple]
(No values found)

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Apple\AppleSoftwareUpdate]
"Id"="{982D925F-43A4-47BC-BB18-92B368796A4D}"
"Index"= 0x0000000003 (3)

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\AVAST Software]
(No values found)

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\AVAST Software\Avast settings backup]
"Id"="{8A7266F3-52B8-40CA-B529-37023ABBFDC8}"
"Index"= 0x0000000001 (1)

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\avast! Emergency Update]
"Id"="{BB830F6B-2196-48E6-84F0-94B82980C34A}"
"Index"= 0x0000000002 (2)

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\McAfee Remediation (Prepare)]
"Id"="{9436B5C3-B6CD-43C7-87F6-11B7B4937DCF}"
"Index"= 0x0000000003 (3)

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\McAfeeLogon]
"Id"="{FEE260EE-1DA0-4F59-A059-3A9090F5C233}"
"Index"= 0x0000000002 (2)

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft]
(No values found)

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows]
(No values found)

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\Active Directory Rights Management Services Client]
(No values found)

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\Active Directory Rights Management Services Client\AD RMS Rights Policy Template Management (Automated)]
"Id"="{613612BA-897D-44CE-8DC1-8FC283F9FD51}"
"Index"= 0x0000000002 (2)

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\Active Directory Rights Management Services Client\AD RMS Rights Policy Template Management (Manual)]
"Id"="{28011108-68DF-4C73-B91B-57427D501BBA}"
"Index"= 0x0000000002 (2)

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\AppID]
(No values found)

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\AppID\PolicyConverter]
"Id"="{A48CABBF-24C8-4B87-B00F-9261807C3B43}"
"Index"= 0x0000000003 (3)

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\AppID\VerifiedPublisherCertStoreCheck]
"Id"="{72DB7465-BC54-491B-A92A-4637A28C9BBF}"
"Index"= 0x0000000001 (1)

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\Application Experience]
(No values found)

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\Application Experience\AitAgent]
"Id"="{AC4E5ACF-89F7-4220-BA21-81EE183975E2}"
"Index"= 0x0000000003 (3)

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\Application Experience\Microsoft Compatibility Appraiser]
"Id"="{826007B3-58BC-4266-AD84-BE5432535075}"
"Index"= 0x0000000003 (3)

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\Application Experience\ProgramDataUpdater]
"Id"="{C46431A4-4CA4-4BB8-8ABD-5B0C629B626D}"
"Index"= 0x0000000003 (3)

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\Autochk]
(No values found)

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\Autochk\Proxy]
"Id"="{D7B6E81D-3CF4-432C-84D2-24213F4316E6}"
"Index"= 0x0000000001 (1)

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\Bluetooth]
(No values found)

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\Bluetooth\UninstallDeviceTask]
"Id"="{E3163C33-301D-4730-A266-5518C5ED3967}"
"Index"= 0x0000000003 (3)

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\CertificateServicesClient]
(No values found)

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\CertificateServicesClient\SystemTask]
"Id"="{5F5A18EB-DC73-4E45-A11C-B59043598412}"
"Index"= 0x0000000001 (1)

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\CertificateServicesClient\UserTask]
"Id"="{7AFCC0CA-7121-422A-AB45-B0E8D599FF08}"
"Index"= 0x0000000002 (2)

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\CertificateServicesClient\UserTask-Roam]
"Id"="{9979CB83-103A-4105-9E5D-C74B0AF6D198}"
"Index"= 0x0000000003 (3)

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\Customer Experience Improvement Program]
(No values found)

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\Customer Experience Improvement Program\Consolidator]
"Id"="{C016366B-7126-46CA-B36B-592A3D95A60B}"
"Index"= 0x0000000003 (3)

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\Customer Experience Improvement Program\KernelCeipTask]
"Id"="{FDD56C73-F0D5-41B6-B767-6EFFD7966428}"
"Index"= 0x0000000003 (3)

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\Customer Experience Improvement Program\OptinNotification]
"Id"="{A132EB1D-A1EA-48EF-8B69-9358EADF5BD3}"
"Index"= 0x0000000000 (0)

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\Customer Experience Improvement Program\UsbCeip]
"Id"="{47536D45-EEEC-4BDC-8183-A4DC1F8DA9E4}"
"Index"= 0x0000000003 (3)

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\Defrag]
(No values found)

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\Defrag\ScheduledDefrag]
"Id"="{5C0AEEEA-C154-45BE-8499-BEA5F11BAFF6}"
"Index"= 0x0000000003 (3)

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\Diagnosis]
(No values found)

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\Diagnosis\Scheduled]
"Id"="{BE669C13-8165-4536-96D0-6D6C39292AAE}"
"Index"= 0x0000000003 (3)

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\DiskDiagnostic]
(No values found)

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\DiskDiagnostic\Microsoft-Windows-DiskDiagnosticDataCollector]
"Id"="{18DA0B84-C309-45EF-8C8A-97A1DC113FE8}"
"Index"= 0x0000000003 (3)

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\DiskDiagnostic\Microsoft-Windows-DiskDiagnosticResolver]
"Id"="{CBAE4B96-C967-4F89-B8CB-AFA890E4DCFF}"
"Index"= 0x0000000002 (2)

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\Location]
(No values found)

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\Location\Notifications]
"Id"="{A6AF9377-77CE-47AB-AD7D-EC32CAD0C82D}"
"Index"= 0x0000000003 (3)

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\Maintenance]
(No values found)

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\Maintenance\WinSAT]
"Id"="{DA41DE71-8431-42FB-9DB0-EB64A961DEAD}"
"Index"= 0x0000000003 (3)

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\Media Center]
(No values found)

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\Media Center\ActivateWindowsSearch]
"Id"="{8C18F494-17CA-4950-A9A0-9DDFB9186EBC}"
"Index"= 0x0000000003 (3)

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\Media Center\ConfigureInternetTimeService]
"Id"="{2B2234B1-38C4-45C1-89AF-F7830EF4C868}"
"Index"= 0x0000000003 (3)

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\Media Center\DispatchRecoveryTasks]
"Id"="{654B0B50-030E-478D-8CBF-A854332258BD}"
"Index"= 0x0000000003 (3)

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\Media Center\ehDRMInit]
"Id"="{2F70EC75-51D6-438E-A0BE-EAE9C04234BE}"
"Index"= 0x0000000003 (3)

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\Media Center\InstallPlayReady]
"Id"="{A4DAFE3D-2E85-4F1A-B354-9A793DB63613}"
"Index"= 0x0000000003 (3)

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\Media Center\mcupdate]
"Id"="{8C71E3B5-F23A-4F19-A471-8BCBD42A02B6}"
"Index"= 0x0000000003 (3)

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\Media Center\mcupdate_scheduled]
"Id"="{7497269B-A749-417A-B590-51B7AEF07070}"
"Index"= 0x0000000003 (3)

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\Media Center\MediaCenterRecoveryTask]
"Id"="{906454C7-40A1-496A-9967-A22BB51BB481}"
"Index"= 0x0000000003 (3)

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\Media Center\ObjectStoreRecoveryTask]
"Id"="{CD5E3BFD-6C44-4E50-AD92-34CAF3CEC5DC}"
"Index"= 0x0000000003 (3)

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\Media Center\OCURActivate]
"Id"="{3089006A-9FDB-4777-A1F5-4DE44CA32C13}"
"Index"= 0x0000000003 (3)

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\Media Center\OCURDiscovery]
"Id"="{78DC1F46-38AD-496D-830A-0A35D382C696}"
"Index"= 0x0000000003 (3)

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\Media Center\PBDADiscovery]
"Id"="{B2F37559-8B00-4290-AA56-5DD5656D0DF2}"
"Index"= 0x0000000003 (3)

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\Media Center\PBDADiscoveryW1]
"Id"="{5E15C04F-8ACE-499C-80BB-3A915B0F2DAB}"
"Index"= 0x0000000003 (3)

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\Media Center\PBDADiscoveryW2]
"Id"="{F4098BC1-256E-4683-B776-F935A8F26876}"
"Index"= 0x0000000003 (3)

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\Media Center\PeriodicScanRetry]
"Id"="{6885E303-EFC1-40B2-A204-B13E2FD573E3}"
"Index"= 0x0000000003 (3)

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\Media Center\PvrRecoveryTask]
"Id"="{0FA766DD-932B-4084-A9FF-79AE4A44089D}"
"Index"= 0x0000000003 (3)

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\Media Center\PvrScheduleTask]
"Id"="{AE17005F-9E60-4C41-A422-1F1D2539F1F9}"
"Index"= 0x0000000003 (3)

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\Media Center\RecordingRestart]
"Id"="{2F9EEE9D-35EC-49C7-A66A-6052F65BEB60}"
"Index"= 0x0000000001 (1)

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\Media Center\RegisterSearch]
"Id"="{3DC7AD2C-5C3A-4B28-A174-782039D3EA85}"
"Index"= 0x0000000003 (3)

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\Media Center\ReindexSearchRoot]
"Id"="{221DE1C1-46D7-4C8B-A009-40A3B2A682DF}"
"Index"= 0x0000000003 (3)

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\Media Center\SqlLiteRecoveryTask]
"Id"="{8602EA65-3194-4492-AA3C-B891DE69B2BF}"
"Index"= 0x0000000003 (3)

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\Media Center\StartRecording]
"Id"="{39B45D1C-E533-4E8E-91E7-3E0BB937BAC9}"
"Index"= 0x0000000003 (3)

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\Media Center\UpdateRecordPath]
"Id"="{C3DAC4A5-6C14-4EB6-B392-BD959BF646DE}"
"Index"= 0x0000000003 (3)

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\MemoryDiagnostic]
(No values found)

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\MemoryDiagnostic\CorruptionDetector]
"Id"="{CEE64558-E1A7-4D9D-80A7-2001912BE5B5}"
"Index"= 0x0000000003 (3)

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\MemoryDiagnostic\DecompressionFailureDetector]
"Id"="{FA2BC0A6-8D4B-458A-85C8-2B8C72487513}"
"Index"= 0x0000000003 (3)

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\MemoryDiagnostic\MemUsageTask]
"Id"="{C4375D81-FA72-45AC-85F2-3B86A11CCC7D}"
"Index"= 0x0000000000 (0)

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\MobilePC]
(No values found)

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\MobilePC\HotStart]
"Id"="{F73EEEE3-13AA-4CC7-9EA1-4B6092DED721}"
"Index"= 0x0000000002 (2)

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\MUI]
(No values found)

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\MUI\LPRemove]
"Id"="{EB02381F-D652-4B1C-894A-712498C62C51}"
"Index"= 0x0000000001 (1)

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\Multimedia]
(No values found)

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\Multimedia\SystemSoundsService]
"Id"="{2470470F-2634-478E-B181-571E98A789BB}"
"Index"= 0x0000000002 (2)

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\NetTrace]
(No values found)

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\NetTrace\GatherNetworkInfo]
"Id"="{81540B9F-B5BF-47EB-9C95-BE195BF2C664}"
"Index"= 0x0000000003 (3)

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\NetworkAccessProtection]
(No values found)

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\NetworkAccessProtection\NAPStatus UI]
"Id"="{00BB5F5C-4A20-4FD6-8900-4699F989BF01}"
"Index"= 0x0000000000 (0)

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\PerfTrack]
(No values found)

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\PerfTrack\BackgroundConfigSurveyor]
"Id"="{B0CBAB43-44FC-469B-A4CE-87426761FDCE}"
"Index"= 0x0000000003 (3)

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\PLA]
(No values found)

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\PLA\System]
(No values found)

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\PLA\System\ConvertLogEntries]
"Id"="{600F3312-A477-448A-936D-EB2DF977300B}"
"Index"= 0x0000000000 (0)

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\Power Efficiency Diagnostics]
(No values found)

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\Power Efficiency Diagnostics\AnalyzeSystem]
"Id"="{FB3C354D-297A-4EB2-9B58-090F6361906B}"
"Index"= 0x0000000003 (3)

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\RAC]
(No values found)

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\RAC\RACAgent]
"Id"="{7F9C951C-D364-4B70-8D07-D2C9B7F76E35}"
"Index"= 0x0000000000 (0)

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\RAC\RacTask]
"Id"="{EACA24FF-236C-401D-A1E7-B3D5267B8A50}"
"Index"= 0x0000000003 (3)

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\Ras]
(No values found)

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\Ras\MobilityManager]
"Id"="{AC668097-4D6B-4093-AC14-014C09DBF820}"
"Index"= 0x0000000003 (3)

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\Registry]
(No values found)

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\Registry\RegIdleBackup]
"Id"="{CA4B8FF2-A4D2-4D88-A52E-3A5BDAF7F56E}"
"Index"= 0x0000000003 (3)

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\RemoteAssistance]
(No values found)

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\RemoteAssistance\RemoteAssistanceTask]
"Id"="{CB3D64BF-C0C9-45FF-BFB0-FF1A8F680186}"
"Index"= 0x0000000003 (3)

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\Setup]
(No values found)

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\Setup\gwx]
(No values found)

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\Setup\gwx\launchtrayprocess]
"Id"="{AD9075CB-BD47-46AE-A82F-B12F3B27D613}"
"Index"= 0x0000000002 (2)

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\Setup\gwx\refreshgwxconfig]
"Id"="{D70E791C-7C0E-40D4-B2DD-2AF7735C6633}"
"Index"= 0x0000000003 (3)

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\Setup\gwx\refreshgwxconfigandcontent]
"Id"="{304CE3F4-C2D2-459B-957F-BF9B51BA823F}"
"Index"= 0x0000000003 (3)

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\Setup\gwx\refreshgwxcontent]
"Id"="{B86D9031-325A-4603-91DF-B7C56E8D0BC5}"
"Index"= 0x0000000003 (3)

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\Setup\GWXTriggers]
(No values found)

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\Setup\GWXTriggers\Logon-5d]
"Id"="{1E559FB1-2EE1-4699-8DAA-145F8A11C1D6}"
"Index"= 0x0000000002 (2)

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\Setup\GWXTriggers\MachineUnlock-5d]
"Id"="{098A7198-0DED-43E1-B050-831FAA9E7433}"
"Index"= 0x0000000003 (3)

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\Setup\GWXTriggers\OutOfIdle-5d]
"Id"="{BEF69F7E-C8C8-4DB4-9D87-0BA0AE3EBC27}"
"Index"= 0x0000000003 (3)

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\Setup\GWXTriggers\OutOfSleep-5d]
"Id"="{408CB1DC-A2E0-443B-85EF-EB1476301C74}"
"Index"= 0x0000000003 (3)

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\Setup\GWXTriggers\refreshgwxconfig-B]
"Id"="{E601E35F-CA2E-4D5B-B924-391C466BAEE3}"
"Index"= 0x0000000003 (3)

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\Setup\GWXTriggers\Telemetry-4xd]
"Id"="{41CDF12D-485B-46DE-8F7F-86992A1A75D5}"
"Index"= 0x0000000003 (3)

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\Setup\GWXTriggers\Time-5d]
"Id"="{C3D76F7C-3704-41B7-BD4C-0394594453A2}"
"Index"= 0x0000000003 (3)

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\Shell]
(No values found)

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\Shell\CrawlStartPages]
"Id"="{B936B1AF-0C7E-4C4D-84F1-CF67453259A1}"
"Index"= 0x0000000000 (0)

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\Shell\WindowsParentalControls]
"Id"="{5B42DD9C-5A26-4F27-BB95-34603F0997E5}"
"Index"= 0x0000000002 (2)

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\Shell\WindowsParentalControlsMigration]
"Id"="{486D715E-6AA2-44CF-BC48-B6990CBB53C6}"
"Index"= 0x0000000002 (2)

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\SideShow]
(No values found)

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\SideShow\AutoWake]
"Id"="{F77498FD-76A5-416F-8D11-2A785E9FD064}"
"Index"= 0x0000000002 (2)

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\SideShow\GadgetManager]
"Id"="{B25A0EF1-F72A-493E-9813-9E77F70F8C30}"
"Index"= 0x0000000002 (2)

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\SideShow\SessionAgent]
"Id"="{1DEC0920-1F37-47B6-B678-880E3DB2EB4E}"
"Index"= 0x0000000002 (2)

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\SideShow\SystemDataProviders]
"Id"="{D4466EA0-05E5-4309-AB5F-B031CEEF128B}"
"Index"= 0x0000000002 (2)

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\SoftwareProtectionPlatform]
(No values found)

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\SoftwareProtectionPlatform\SvcRestartTask]
"Id"="{DD9F510C-95F4-499A-90C8-BAC5BC372FF4}"
"Index"= 0x0000000003 (3)

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\SystemRestore]
(No values found)

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\SystemRestore\SR]
"Id"="{994C86AD-A929-4B2C-88A0-4E25A107A029}"
"Index"= 0x0000000001 (1)

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\Task Manager]
(No values found)

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\Task Manager\Interactive]
"Id"="{1F7B7221-AE8F-44F3-BA82-F7D260F51964}"
"Index"= 0x0000000003 (3)

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\Tcpip]
(No values found)

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\Tcpip\IpAddressConflict1]
"Id"="{088482FA-65B8-4E17-9ABF-1DCD48E8D373}"
"Index"= 0x0000000003 (3)

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\Tcpip\IpAddressConflict2]
"Id"="{09F06BFE-A3C8-40E3-846A-6E6F4000C238}"
"Index"= 0x0000000003 (3)

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\TextServicesFramework]
(No values found)

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\TextServicesFramework\MsCtfMonitor]
"Id"="{4C8B01A2-11FF-4C41-848F-508EF4F00CF7}"
"Index"= 0x0000000002 (2)

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\Time Synchronization]
(No values found)

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\Time Synchronization\SynchronizeTime]
"Id"="{044A6734-E90E-4F8F-B357-B2DC8AB3B5EC}"
"Index"= 0x0000000003 (3)

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\UPnP]
(No values found)

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\UPnP\UPnPHostConfig]
"Id"="{5A40E926-9E86-4B89-9CFD-B12311724371}"
"Index"= 0x0000000003 (3)

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\User Profile Service]
(No values found)

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\User Profile Service\HiveUploadTask]
"Id"="{6738BA6E-EA75-4B6B-B8B8-71F0336DD8EF}"
"Index"= 0x0000000003 (3)

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\WDI]
(No values found)

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\WDI\ResolutionHost]
"Id"="{9435F817-FED2-454E-88CD-7F78FDA62C48}"
"Index"= 0x0000000003 (3)

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\Windows Activation Technologies]
(No values found)

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\Windows Activation Technologies\ValidationTask]
"Id"="{7663A1BE-1F45-4C7B-84E1-611A29336DC3}"
"Index"= 0x0000000003 (3)

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\Windows Activation Technologies\ValidationTaskDeadline]
"Id"="{40C96928-DA37-4572-9E97-2827E8050FDC}"
"Index"= 0x0000000003 (3)

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\Windows Error Reporting]
(No values found)

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\Windows Error Reporting\QueueReporting]
"Id"="{D0250F3F-6480-484F-B719-42F659AC64D5}"
"Index"= 0x0000000002 (2)

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\Windows Filtering Platform]
(No values found)

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\Windows Filtering Platform\BfeOnServiceStartTypeChange]
"Id"="{E22A8667-F75B-4BA9-BA46-067ED4429DE8}"
"Index"= 0x0000000003 (3)

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\Windows Media Sharing]
(No values found)

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\Windows Media Sharing\UpdateLibrary]
"Id"="{753C47AE-EC5E-44B3-95A9-2C8E553F0E39}"
"Index"= 0x0000000003 (3)

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\WindowsBackup]
(No values found)

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\WindowsBackup\AutomaticBackup]
"Id"="{61097539-54C8-46CF-A778-E22A51CC5E25}"
"Index"= 0x0000000003 (3)

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\WindowsBackup\ConfigNotification]
"Id"="{2F57269B-1E09-4E2D-AB1E-B0FDAC7D279C}"
"Index"= 0x0000000003 (3)

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\WindowsBackup\Windows Backup Monitor]
"Id"="{FB1544A9-507B-4665-A8B3-8E28DF42FF0A}"
"Index"= 0x0000000002 (2)

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\WindowsColorSystem]
(No values found)

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\WindowsColorSystem\Calibration Loader]
"Id"="{A35BB7A6-5F0C-4C9F-8450-2B3BED532D51}"
"Index"= 0x0000000002 (2)

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\Wininet]
(No values found)

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\Wininet\CacheTask]
"Id"="{41DF318B-03A0-41AD-9F4B-0D16A583EAD8}"
"Index"= 0x0000000002 (2)

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows Defender]
(No values found)

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows Defender\MP Scheduled Scan]
"Id"="{C8324912-7E67-45CB-88FB-FF2984FB7CDD}"
"Index"= 0x0000000003 (3)

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows Defender\MpIdleTask]
"Id"="{C00F6A8D-2765-4105-B37F-A8C4CEAD65C9}"
"Index"= 0x0000000003 (3)

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows Live]
(No values found)

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows Live\SOXE]
(No values found)

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows Live\SOXE\Extractor Definitions Update Task]
"Id"="{DF6974F8-A3EA-48C6-A2E0-2D4320EC2FAA}"
"Index"= 0x0000000002 (2)

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\OfficeSoftwareProtectionPlatform]
(No values found)

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\OfficeSoftwareProtectionPlatform\SvcRestartTask]
"Id"="{C223A541-0306-4585-B202-429E1EBFC287}"
"Index"= 0x0000000003 (3)

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Safer-Networking]
(No values found)

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Safer-Networking\Spybot - Search and Destroy]
(No values found)

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\WPD]
(No values found)

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\WPD\SqmUpload_S-1-5-21-712811262-1525229126-99551323-1000]
"Id"="{DFB1F8D3-6B27-408F-9F9F-F043E7876CD4}"
"Index"= 0x0000000003 (3)

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\{5E242C37-C240-49A2-B3EC-2A729CF1A930}]
"Id"="{25FF54D9-FD24-4392-AA5D-9C8DC305E2F7}"
"Index"= 0x0000000003 (3)

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\{985637B0-E12F-4CC0-BEB9-D7F49605D2E9}]
"Id"="{4CCD2E7C-8D0C-4947-A9C3-B2C0CAEB1CD8}"
"Index"= 0x0000000003 (3)

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\{9BE1CFE5-2C71-40C1-A065-D3796C57E3BB}]
"Id"="{DA3CE826-4A45-4CC3-B7C5-ABD4ED5E6A8D}"
"Index"= 0x0000000003 (3)

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\{B300C4A2-060B-476F-B780-03EB7ED2234E}]
"Id"="{361B4002-7C44-466D-A7FB-3850FA6835BE}"
"Index"= 0x0000000003 (3)


-= EOF =-

Attached Files


Edited by nasdaq, 10 December 2015 - 08:58 AM.
Systemlook file posted


#11 nasdaq

nasdaq

  • Malware Response Team
  • 38,922 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Montreal, QC. Canada
  • Local time:07:14 PM

Posted 10 December 2015 - 09:07 AM

The keys are clean.

Any remaining issues with this computer?

#12 nasdaq

nasdaq

  • Malware Response Team
  • 38,922 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Montreal, QC. Canada
  • Local time:07:14 PM

Posted 16 December 2015 - 11:24 AM

Are you still with me?

#13 nasdaq

nasdaq

  • Malware Response Team
  • 38,922 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Montreal, QC. Canada
  • Local time:07:14 PM

Posted 22 December 2015 - 01:27 PM

Due to the lack of feedback, this topic is now closed.

In the event you still have problems, please send me or any Moderator a Private Message and ask them to reopen this topic within the next 5 days.

Please include a link to your topic in the Private Message. Thank you.




0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users