Jump to content


 


Register a free account to unlock additional features at BleepingComputer.com
Welcome to BleepingComputer, a free community where people like yourself come together to discuss and learn how to use their computers. Using the site is easy and fun. As a guest, you can browse and view the various discussions in the forums, but can not create a new topic or reply to an existing one unless you are logged in. Other benefits of registering an account are subscribing to topics and forums, creating a blog, and having no ads shown anywhere on the site.


Click here to Register a free account now! or read our Welcome Guide to learn how to use this site.

Photo

Mal/Packer Virus consumes cpu and opens popups


  • This topic is locked This topic is locked
64 replies to this topic

#1 peaksmm

peaksmm

  • Members
  • 32 posts
  • OFFLINE
  •  
  • Local time:07:01 AM

Posted 22 December 2015 - 03:52 PM

My system is infected with some kind of malware that seems to be network aware or activated by the browser.  It runs numerous instances of the following processes; PresentationHost.exe, MSIExec, Cmd.exe, dllhost.exe, Ctfmon,exe, msdtc.exe, notepad.exe, softwarereportertool.exe and possibly others.  The browsers self open windows for ads and who knows what behind the main search window.  These popups also interfere with shutdown.  I have run nuerous virus scans.  Sophos detected Mal/Packer and stated it was cleared. Subsequent scans by Sophos and other programs detect nothing although the problem remains. I don't know if its revelant, but I noticed that these processes are mentioned in the feature control set of the registry.  Please assist.  Thanks.Attached File  FRST.txt   39.2KB   6 downloadsAttached File  Addition.txt   42.65KB   3 downloads

Scan result of Farbar Recovery Scan Tool (FRST) (x86) Version:20-12-2015
Ran by Administrator (administrator) on YOUR-09DEDAFE33 (21-12-2015 17:10:06)
Running from C:\Documents and Settings\Administrator\Desktop
Loaded Profiles: Administrator (Available Profiles: 1 & Administrator)
Platform: Microsoft Windows XP Service Pack 3 (X86) Language: English (United States)
Internet Explorer Version 8 (Default browser: IE)
Boot Mode: Safe Mode (with Networking)
Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/

==================== Processes (Whitelisted) =================

(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)

(Microsoft Corporation) C:\Program Files\Windows Defender\MsMpEng.exe
(Microsoft Corporation) C:\WINDOWS\system32\dllhost.exe
(Microsoft Corporation) C:\WINDOWS\system32\taskmgr.exe
(Microsoft Corporation) C:\WINDOWS\system32\PresentationHost.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
(Microsoft Corporation) C:\WINDOWS\system32\dllhost.exe
(Microsoft Corporation) C:\WINDOWS\system32\msiexec.exe
(Microsoft Corporation) C:\WINDOWS\system32\msiexec.exe
(Microsoft Corporation) C:\WINDOWS\system32\msiexec.exe
(Microsoft Corporation) C:\WINDOWS\system32\dllhost.exe
(Microsoft Corporation) C:\WINDOWS\system32\dllhost.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
(Microsoft Corporation) C:\WINDOWS\system32\cmd.exe
(Microsoft Corporation) C:\WINDOWS\system32\cmd.exe


==================== Registry (Whitelisted) ===========================

(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)

HKLM\...\Run: [SynTPStart] => C:\Program Files\Synaptics\SynTP\SynTPStart.exe [102400 2007-09-15] (Synaptics, Inc.)
HKLM\...\Run: [Cpqset] => C:\Program Files\HPQ\Default Settings\cpqset.exe [40960 2006-02-22] ()
HKLM\...\Run: [MSConfig] => C:\WINDOWS\pchealth\helpctr\Binaries\MSCONFIG.EXE [169984 2008-04-13] (Microsoft Corporation)
HKLM\...\Run: [QuickTime Task] => C:\Program Files\QuickTime\qttask.exe [421888 2010-09-08] (Apple Inc.)
Winlogon\Notify\WgaLogon:
HKLM\...\Policies\Explorer: [NoCDBurning] 0
HKU\S-1-5-21-2740428291-721650609-345291581-500\...\Run: [QuickTime Task] => C:\Program Files\QuickTime\qttask.exe [421888 2010-09-08] (Apple Inc.)
HKU\S-1-5-21-2740428291-721650609-345291581-500\...\Run: [CCleaner Monitoring] => C:\Program Files\CCleaner\CCleaner.exe [6602152 2015-11-16] (Piriform Ltd)
ShellExecuteHooks: Microsoft AntiMalware ShellExecuteHook - {091EB208-39DD-417D-A5DD-7E2C2D8FB9CB} - C:\Program Files\Windows Defender\MpShHook.dll [83224 2006-11-03] (Microsoft Corporation)

==================== Internet (Whitelisted) ====================

(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)

Tcpip\Parameters: [DhcpNameServer] 192.168.0.1
Tcpip\..\Interfaces\{3A76385A-4B35-4E94-AEDA-C41C6BDC84F4}: [DhcpNameServer] 192.168.0.1

Internet Explorer:
==================
HKLM\SOFTWARE\Policies\Microsoft\Internet Explorer: Restriction <======= ATTENTION
HKU\S-1-5-21-2740428291-721650609-345291581-500\SOFTWARE\Policies\Microsoft\Internet Explorer: Restriction <======= ATTENTION
HKU\.DEFAULT\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
HKU\S-1-5-21-2740428291-721650609-345291581-500\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
SearchScopes: HKLM -> DefaultScope value is missing
SearchScopes: HKLM -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = hxxp://www.bing.com/search
BHO: HP Print Enhancer -> {0347C33E-8762-4905-BF09-768834316C61} -> C:\Program Files\HP\Digital Imaging\Smart Web Printing\hpswp_printenhancer.dll [2009-05-21] (Hewlett-Packard Co.)
BHO: AcroIEHlprObj Class -> {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} -> C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll [2003-11-03] (Adobe Systems Incorporated)
BHO: No Name -> {5CA3D70E-1895-11CF-8E15-001234567890} -> No File
BHO: Java™ Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files\Java\jre7\bin\ssv.dll [2014-12-18] (Oracle Corporation)
BHO: No Name -> {A8F38D8D-E480-4D52-B7A2-731BB6995FDD} -> __BHODemonDisabled => No File
BHO: Google Toolbar Helper -> {AA58ED58-01DD-4d91-8333-CF10577473F7} -> c:\program files\google\googletoolbar2.dll [2006-02-14] (Google Inc.)
BHO: Java™ Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files\Java\jre7\bin\jp2ssv.dll [2014-12-18] (Oracle Corporation)
BHO: HP Smart BHO Class -> {FFFFFFFF-CF4E-4F2B-BDC2-0E72E116A856} -> C:\Program Files\HP\Digital Imaging\Smart Web Printing\hpswp_BHO.dll [2009-05-21] (Hewlett-Packard Co.)
Toolbar: HKLM - &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll [2006-02-14] (Google Inc.)
Toolbar: HKU\S-1-5-21-2740428291-721650609-345291581-500 -> No Name - {C4069E3A-68F1-403E-B40E-20066696354B} - No File
Toolbar: HKU\S-1-5-21-2740428291-721650609-345291581-500 -> &Google - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll [2006-02-14] (Google Inc.)
DPF: {17492023-C23A-453E-A040-C7C580BBF700} hxxp://go.microsoft.com/fwlink/?linkid=39204
DPF: {7530BFB8-7293-4D34-9923-61A11451AFC5} hxxp://download.eset.com/special/eos/OnlineScanner.cab
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} hxxp://java.sun.com/update/1.7.0/jinstall-1_7_0_45-windows-i586.cab
DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} hxxp://fpdownload.macromedia.com/get/flashplayer/current/ultrashim.cab
DPF: {CAFEEFAC-0015-0000-0006-ABCDEFFEDCBA}
DPF: {CAFEEFAC-0015-0000-0015-ABCDEFFEDCBA}
DPF: {CAFEEFAC-0016-0000-0010-ABCDEFFEDCBA}
DPF: {CAFEEFAC-0017-0000-0025-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.7.0/jinstall-1_7_0_25-windows-i586.cab
DPF: {CAFEEFAC-0017-0000-0045-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.7.0/jinstall-1_7_0_45-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.7.0/jinstall-1_7_0_45-windows-i586.cab
DPF: {E06E2E99-0AA1-11D4-ABA6-0060082AA75C}
DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} hxxp://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
Handler: ms-itss - {0A9007C0-4076-11D3-8789-0000F8105754} - C:\Program Files\Common Files\Microsoft Shared\Information Retrieval\msitss.dll [2001-06-20] (Microsoft Corporation)

FireFox:
========
FF Plugin: @adobe.com/FlashPlayer -> C:\WINDOWS\system32\Macromed\Flash\NPSWF32_19_0_0_185.dll [2015-09-27] ()
FF Plugin: @Apple.com/iTunes,version=1.0 -> C:\Program Files\iTunes\Mozilla Plugins\npitunes.dll [2010-09-22] ()
FF Plugin: @java.com/DTPlugin,version=10.75.2 -> C:\Program Files\Java\jre7\bin\dtplugin\npDeployJava1.dll [2014-12-18] (Oracle Corporation)
FF Plugin: @java.com/JavaPlugin,version=10.75.2 -> C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll [2014-12-18] (Oracle Corporation)
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files\Microsoft Silverlight\5.1.30514.0\npctrl.dll [2014-05-13] ( Microsoft Corporation)
FF Plugin: @microsoft.com/WPF,version=3.5 -> c:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll [2008-07-29] (Microsoft Corporation)
FF Plugin: @real.com/nppl3260;version=6.0.11.2852 -> C:\Program Files\Real\RealPlayer\Netscape6\nppl3260.dll [2007-11-11] (RealNetworks, Inc.)
FF Plugin: @real.com/nprjplug;version=1.0.2.2910 -> C:\Program Files\Real\RealPlayer\Netscape6\nprjplug.dll [2007-11-11] (RealNetworks, Inc.)
FF Plugin: @real.com/nprpjplug;version=6.0.12.1662 -> C:\Program Files\Real\RealPlayer\Netscape6\nprpjplug.dll [2007-11-11] (RealNetworks, Inc.)
FF Plugin: @RIM.com/WebSLLauncher,version=1.0 -> C:\Program Files\Common Files\Research In Motion\BBWebSLLauncher\NPWebSLLauncher.dll [2011-06-27] ()
FF Plugin: @tools.google.com/Google Update;version=3 -> C:\Program Files\Google\Update\1.3.29.1\npGoogleUpdate3.dll [2015-12-02] (Google Inc.)
FF Plugin: @tools.google.com/Google Update;version=9 -> C:\Program Files\Google\Update\1.3.29.1\npGoogleUpdate3.dll [2015-12-02] (Google Inc.)
FF HKLM\...\Firefox\Extensions: [{20a82645-c095-46ed-80e3-08825760534b}] - c:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension
FF Extension: Microsoft .NET Framework Assistant - c:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension [2011-12-05] [not signed]
FF HKLM\...\Firefox\Extensions: [smartwebprinting@hp.com] - C:\Program Files\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3
FF Extension: HP Smart Web Printing - C:\Program Files\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3 [2014-02-25] [not signed]

Chrome:
=======
CHR Profile: C:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\User Data\Default
CHR Extension: (Google Slides) - C:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\aapocclcgogkmnckokdopfmhonfmgoek [2015-12-15]
CHR Extension: (Google Docs) - C:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2015-12-15]
CHR Extension: (Google Drive) - C:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2015-12-15]
CHR Extension: (YouTube) - C:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2015-12-15]
CHR Extension: (Google Search) - C:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2015-12-15]
CHR Extension: (Google Sheets) - C:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\felcaaldnbdncclmgdcncolpebgiejap [2015-12-15]
CHR Extension: (Google Docs Offline) - C:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2015-12-15]
CHR Extension: (Chrome Web Store Payments) - C:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2015-12-15]
CHR Extension: (Gmail) - C:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2015-12-15]

==================== Services (Whitelisted) ========================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

S2 6to4; C:\WINDOWS\System32\6to4svc.dll [100864 2010-02-11] (Microsoft Corporation)
S3 hpqcxs08; C:\Program Files\HP\Digital Imaging\bin\hpqcxs08.dll [248832 2009-05-21] (Hewlett-Packard Co.) [File not signed]
S2 hpqddsvc; C:\Program Files\HP\Digital Imaging\bin\hpqddsvc.dll [133120 2009-05-21] (Hewlett-Packard Co.) [File not signed]
S2 hpqwmiex; C:\Program Files\Hewlett-Packard\Shared\hpqwmiex.exe [135168 2006-03-15] (Hewlett-Packard Development Company, L.P.) [File not signed]
S2 HPSLPSVC; C:\Program Files\HP\Digital Imaging\bin\HPSLPSVC32.DLL [660992 2009-05-21] (Hewlett-Packard Co.) [File not signed]
S3 IDriverT; C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe [69632 2005-04-04] (Macrovision Corporation) [File not signed]
S3 LightScribeService; C:\Program Files\Common Files\LightScribe\LSSrvc.exe [73728 2006-02-17] (Hewlett-Packard Company) [File not signed]
S2 MBAMService; C:\Program Files\Malwarebytes Anti-Malware\mbamservice.exe [1135416 2015-10-05] (Malwarebytes)
S2 Net Driver HPZ12; C:\WINDOWS\system32\HPZinw12.dll [44032 2010-08-06] (Hewlett-Packard) [File not signed]
S2 Pml Driver HPZ12; C:\WINDOWS\system32\HPZipm12.dll [53760 2010-08-06] (Hewlett-Packard) [File not signed]
R2 WinDefend; C:\Program Files\Windows Defender\MsMpEng.exe [13592 2006-11-03] (Microsoft Corporation)

===================== Drivers (Whitelisted) ==========================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

S4 abp480n5; C:\WINDOWS\system32\DRIVERS\ABP480N5.SYS [23552 2001-08-18] (Microsoft Corporation)
S3 AdfuUd; C:\WINDOWS\System32\Drivers\AdfuUd.sys [12634 2004-09-16] () [File not signed]
R3 BCM43XX; C:\WINDOWS\System32\DRIVERS\bcmwl5.sys [1391104 2008-10-23] (Broadcom Corporation)
S3 BTWUSB; C:\WINDOWS\System32\Drivers\btwusb.sys [57096 2006-03-02] (Broadcom Corporation.) [File not signed]
S1 eabfiltr; C:\WINDOWS\System32\DRIVERS\eabfiltr.sys [7808 2005-09-19] (Hewlett-Packard Development Company, L.P.)
S3 eabusb; C:\WINDOWS\System32\DRIVERS\eabusb.sys [5760 2005-09-19] (Hewlett-Packard Development Company, L.P.)
S3 HdAudAddService; C:\WINDOWS\System32\drivers\CHDAud.sys [630272 2007-05-01] (Conexant Systems Inc.)
S3 HPZid412; C:\WINDOWS\System32\DRIVERS\HPZid412.sys [49920 2008-10-28] (HP)
S3 HPZipr12; C:\WINDOWS\System32\DRIVERS\HPZipr12.sys [16496 2008-10-28] (HP)
S3 HPZius12; C:\WINDOWS\System32\DRIVERS\HPZius12.sys [21568 2008-10-28] (HP)
S3 HSFHWAZL; C:\WINDOWS\System32\DRIVERS\HSFHWAZL.sys [201600 2005-08-22] (Conexant Systems, Inc.)
S3 HSF_DPV; C:\WINDOWS\System32\DRIVERS\HSF_DPV.sys [1035008 2005-08-22] (Conexant Systems, Inc.)
S3 MBAMProtector; C:\WINDOWS\system32\drivers\mbam.sys [23256 2015-10-05] (Malwarebytes)
R0 PxHelp20; C:\WINDOWS\System32\Drivers\PxHelp20.sys [36624 2007-02-22] (Sonic Solutions) [File not signed]
S3 rtl8139; C:\WINDOWS\System32\DRIVERS\RTL8139.SYS [20992 2004-08-04] (Realtek Semiconductor Corporation)
S3 SANDRA; C:\Program Files\SiSoftware\SiSoftware Sandra Lite 2014.RTM\WNt500x86\Sandra.sys [23112 2009-08-07] (SiSoftware)
R1 ssrtln; C:\WINDOWS\System32\drivers\ssrtln.sys [23545 2005-05-13] (Sonic Solutions) [File not signed]
R1 Tcpip6; C:\WINDOWS\System32\DRIVERS\tcpip6.sys [226880 2010-02-11] (Microsoft Corporation)
S3 USB_RNDIS_XP; C:\WINDOWS\System32\DRIVERS\usb8023.sys [12928 2013-02-11] (Microsoft Corporation)
S3 WinRing0_1_0_1; C:\Program Files\Setfsb\WinRing0.sys [14672 2015-11-29] (OpenLibSys.org)
S3 catchme; \??\C:\ComboFix\catchme.sys [X]
S3 cpuz138; \??\C:\DOCUME~1\1\LOCALS~1\Temp\cpuz138\cpuz138_x32.sys [X]
S3 motccgp; system32\DRIVERS\motccgp.sys [X]
S3 motccgpfl; system32\DRIVERS\motccgpfl.sys [X]
S3 MotDev; system32\DRIVERS\motodrv.sys [X]
S3 motmodem; system32\DRIVERS\motmodem.sys [X]
U5 ScsiPort; C:\WINDOWS\system32\drivers\scsiport.sys [96384 2008-04-13] (Microsoft Corporation)
U3 TlntSvr; no ImagePath

==================== NetSvcs (Whitelisted) ===================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)


==================== One Month Created files and folders ========

(If an entry is included in the fixlist, the file/folder will be moved.)

2015-12-21 17:10 - 2015-12-21 17:10 - 00015345 _____ C:\Documents and Settings\Administrator\Desktop\FRST.txt
2015-12-21 17:09 - 2015-12-21 17:10 - 00000000 ____D C:\FRST
2015-12-21 17:06 - 2015-12-21 15:44 - 01721344 _____ (Farbar) C:\Documents and Settings\Administrator\Desktop\FRST.exe
2015-12-21 14:43 - 2015-12-21 14:43 - 00000000 ____D C:\WINDOWS\LastGood
2015-12-21 14:42 - 2015-12-21 17:06 - 00096518 _____ C:\WINDOWS\ntbtlog.txt
2015-12-21 13:29 - 2015-12-21 13:29 - 00000000 ____D C:\Documents and Settings\Administrator\Local Settings\Application Data\Deployment
2015-12-21 13:27 - 2015-12-21 13:27 - 00000000 ____D C:\Documents and Settings\1\Local Settings\Application Data\Deployment
2015-12-16 20:21 - 2015-12-16 20:21 - 00002656 _____ C:\Documents and Settings\Administrator\My Documents\MSIExec Options Syntax.txt
2015-12-16 20:09 - 2015-12-16 20:09 - 00000000 ____D C:\Documents and Settings\Administrator\Local Settings\Application Data\Sun
2015-12-16 20:08 - 2015-12-16 20:08 - 00000000 ____D C:\Documents and Settings\Administrator\Application Data\Sun
2015-12-16 18:34 - 2015-12-16 20:26 - 00000000 ____D C:\Documents and Settings\Administrator\Desktop\mbar
2015-12-16 18:05 - 2015-12-21 14:02 - 00162010 _____ C:\Documents and Settings\Administrator\Desktop\DIAG_MATS_NETWORK_global.DiagCab
2015-12-16 17:45 - 2015-12-16 17:45 - 00000000 __HDC C:\WINDOWS\$NtUninstallKB942288-v3$
2015-12-16 17:26 - 2015-12-21 15:12 - 00000664 _____ C:\Documents and Settings\Administrator\Local Settings\Application Data\d3d9caps.dat
2015-12-16 16:57 - 2015-12-16 17:48 - 00001013 _____ C:\Documents and Settings\Administrator\Desktop\Install Kaspersky Security Scan version 15.0.0.740.lnk
2015-12-16 16:53 - 2015-12-16 17:48 - 00000000 ____D C:\Documents and Settings\All Users\Kaspersky Lab Setup Files
2015-12-15 17:21 - 2015-12-15 17:21 - 00043845 _____ C:\Documents and Settings\1\Desktop\Hijacklog.txt
2015-12-15 16:14 - 2015-12-15 16:14 - 00002174 _____ C:\Documents and Settings\Administrator\Desktop\ESETonline.txt
2015-12-15 14:20 - 2015-12-15 14:20 - 00000000 ____D C:\Program Files\ESET
2015-12-15 14:07 - 2015-12-15 14:07 - 00000000 ____D C:\Documents and Settings\Administrator\Start Menu\Programs\Google Chrome
2015-12-15 13:25 - 2015-12-15 16:19 - 00004204 _____ C:\Documents and Settings\Administrator\Desktop\Rkill.txt
2015-12-15 11:33 - 2013-10-29 12:59 - 14024704 _____ C:\Documents and Settings\Administrator\Application Data\Sandra.mdb
2015-12-14 16:14 - 2015-12-14 16:14 - 00000000 ____D C:\Documents and Settings\Administrator\Application Data\Real
2015-12-14 15:21 - 2015-12-14 15:21 - 00388608 _____ (Trend Micro Inc.) C:\Documents and Settings\1\Desktop\HijackThis.exe
2015-12-14 15:16 - 2015-12-16 21:18 - 00000000 ____D C:\Program Files\trend micro
2015-12-14 15:16 - 2015-12-14 15:17 - 00000000 ____D C:\rsit
2015-12-14 15:16 - 2015-12-14 15:16 - 01107968 _____ C:\Documents and Settings\1\Desktop\RSIT.exe
2015-12-14 12:21 - 2015-12-21 15:31 - 00002465 _____ C:\Documents and Settings\All Users\Desktop\Sophos Virus Removal Tool.lnk
2015-12-14 12:21 - 2015-12-14 12:21 - 00000000 ____D C:\Documents and Settings\All Users\Start Menu\Programs\Sophos
2015-12-14 12:21 - 2015-12-14 12:21 - 00000000 ____D C:\Documents and Settings\All Users\Application Data\Sophos
2015-12-14 12:20 - 2015-12-14 12:20 - 00000000 ____D C:\Program Files\Sophos
2015-12-14 11:56 - 2015-12-14 12:09 - 140544928 _____ (Sophos Limited) C:\Documents and Settings\1\Desktop\Sophos Virus Removal Tool.exe
2015-12-14 11:53 - 2015-12-14 11:53 - 00001799 _____ C:\Documents and Settings\1\Desktop\JRT.txt
2015-12-14 11:46 - 2015-12-14 11:46 - 01599336 _____ (Malwarebytes) C:\Documents and Settings\1\Desktop\JRT.exe
2015-12-14 11:40 - 2015-12-15 17:57 - 00000000 ____D C:\AdwCleaner
2015-12-14 11:39 - 2015-12-14 11:39 - 01740288 _____ C:\Documents and Settings\1\Desktop\AdwCleaner.exe
2015-12-14 11:30 - 2015-12-14 12:16 - 00001686 _____ C:\Documents and Settings\1\Desktop\Rkill.txt
2015-12-14 10:54 - 2015-12-16 20:26 - 00000000 ____D C:\Documents and Settings\All Users\Application Data\Malwarebytes' Anti-Malware (portable)
2015-12-14 10:52 - 2015-12-14 11:29 - 00000000 ____D C:\Documents and Settings\1\Desktop\mbar
2015-12-14 10:51 - 2015-12-14 10:51 - 00004212 _____ C:\Documents and Settings\1\Desktop\FSS.txt
2015-12-14 10:49 - 2015-12-14 10:49 - 00415744 _____ (Farbar) C:\Documents and Settings\1\Desktop\FSS.exe
2015-12-14 09:27 - 2015-12-16 19:51 - 00170200 _____ (Malwarebytes) C:\WINDOWS\system32\Drivers\MBAMSwissArmy.sys
2015-12-14 09:24 - 2015-12-16 19:51 - 00121560 _____ (Malwarebytes) C:\WINDOWS\system32\Drivers\mbamchameleon.sys
2015-12-14 09:24 - 2015-12-14 09:24 - 00000777 _____ C:\Documents and Settings\All Users\Desktop\Malwarebytes Anti-Malware.lnk
2015-12-14 09:24 - 2015-12-14 09:24 - 00000000 ____D C:\Program Files\Malwarebytes Anti-Malware
2015-12-14 09:24 - 2015-12-14 09:24 - 00000000 ____D C:\Documents and Settings\All Users\Start Menu\Programs\Malwarebytes Anti-Malware
2015-12-14 09:24 - 2015-10-05 09:50 - 00023256 _____ (Malwarebytes) C:\WINDOWS\system32\Drivers\mbam.sys
2015-12-14 09:21 - 2015-12-14 09:23 - 00030651 _____ C:\Documents and Settings\1\Desktop\MTB.txt
2015-12-14 09:16 - 2015-12-14 09:16 - 00001048 _____ C:\Documents and Settings\1\Desktop\checkup.txt
2015-12-14 09:09 - 2015-12-14 09:09 - 02032072 _____ (Bleeping Computer, LLC) C:\Documents and Settings\1\Desktop\rkill.exe
2015-12-14 09:08 - 2015-12-14 09:08 - 00891392 _____ (Farbar) C:\Documents and Settings\1\Desktop\MiniToolBox.exe
2015-12-14 09:06 - 2015-12-14 09:08 - 16563352 _____ (Malwarebytes Corp.) C:\Documents and Settings\1\Desktop\mbar-1.09.3.1001-Anit-Root Kit.exe
2015-12-14 08:59 - 2015-12-14 09:01 - 22908888 _____ (Malwarebytes ) C:\Documents and Settings\1\Desktop\mbam-setup.exe
2015-12-14 08:57 - 2015-12-14 08:57 - 00852771 _____ C:\Documents and Settings\1\Desktop\SecurityCheck.exe
2015-12-08 15:55 - 2015-12-14 15:26 - 00001324 _____ C:\Documents and Settings\1\Local Settings\Application Data\d3d9caps.dat
2015-12-08 15:28 - 2015-12-08 15:29 - 00000000 ___HD C:\Documents and Settings\All Users\Application Data\{FB62659C-5547-4284-846F-24B4EEDF86F7}
2015-12-03 04:44 - 2015-12-03 04:44 - 00014336 _____ C:\Documents and Settings\1\My Documents\Rewards and Giftcard Notes.xls
2015-12-03 02:45 - 2015-12-03 02:45 - 00000000 ____D C:\Documents and Settings\1\Application Data\RoboForm
2015-12-03 02:41 - 2015-12-03 02:41 - 00000000 ____D C:\Documents and Settings\All Users\Application Data\RoboForm
2015-12-03 02:40 - 2015-12-13 19:41 - 00000000 ____D C:\Documents and Settings\1\My Documents\My RoboForm Data
2015-12-02 20:53 - 2015-12-02 20:53 - 00000000 ____D C:\Documents and Settings\All Users\Start Menu\Programs\CCleaner
2015-12-01 01:32 - 2015-12-09 07:35 - 14024704 _____ C:\Documents and Settings\1\Application Data\Sandra.mdb
2015-12-01 01:32 - 2010-06-02 04:55 - 00527192 _____ (Microsoft Corporation) C:\WINDOWS\system32\XAudio2_7.dll
2015-12-01 01:32 - 2010-06-02 04:55 - 00239960 _____ (Microsoft Corporation) C:\WINDOWS\system32\xactengine3_7.dll
2015-12-01 01:32 - 2010-06-02 04:55 - 00074072 _____ (Microsoft Corporation) C:\WINDOWS\system32\XAPOFX1_5.dll
2015-12-01 01:32 - 2010-05-26 11:41 - 02106216 _____ (Microsoft Corporation) C:\WINDOWS\system32\D3DCompiler_43.dll
2015-12-01 01:32 - 2010-05-26 11:41 - 01998168 _____ (Microsoft Corporation) C:\WINDOWS\system32\D3DX9_43.dll
2015-12-01 01:32 - 2010-05-26 11:41 - 01868128 _____ (Microsoft Corporation) C:\WINDOWS\system32\d3dcsx_43.dll
2015-12-01 01:32 - 2010-05-26 11:41 - 00470880 _____ (Microsoft Corporation) C:\WINDOWS\system32\d3dx10_43.dll
2015-12-01 01:32 - 2010-05-26 11:41 - 00248672 _____ (Microsoft Corporation) C:\WINDOWS\system32\d3dx11_43.dll
2015-12-01 01:32 - 2010-02-04 10:01 - 00528216 _____ (Microsoft Corporation) C:\WINDOWS\system32\XAudio2_6.dll
2015-12-01 01:32 - 2010-02-04 10:01 - 00238936 _____ (Microsoft Corporation) C:\WINDOWS\system32\xactengine3_6.dll
2015-12-01 01:32 - 2010-02-04 10:01 - 00074072 _____ (Microsoft Corporation) C:\WINDOWS\system32\XAPOFX1_4.dll
2015-12-01 01:32 - 2010-02-04 10:01 - 00022360 _____ (Microsoft Corporation) C:\WINDOWS\system32\X3DAudio1_7.dll
2015-12-01 01:32 - 2009-09-04 17:44 - 00515416 _____ (Microsoft Corporation) C:\WINDOWS\system32\XAudio2_5.dll
2015-12-01 01:32 - 2009-09-04 17:44 - 00238936 _____ (Microsoft Corporation) C:\WINDOWS\system32\xactengine3_5.dll
2015-12-01 01:32 - 2009-09-04 17:44 - 00069464 _____ (Microsoft Corporation) C:\WINDOWS\system32\XAPOFX1_3.dll
2015-12-01 01:32 - 2009-09-04 17:29 - 05501792 _____ (Microsoft Corporation) C:\WINDOWS\system32\d3dcsx_42.dll
2015-12-01 01:32 - 2009-09-04 17:29 - 01974616 _____ (Microsoft Corporation) C:\WINDOWS\system32\D3DCompiler_42.dll
2015-12-01 01:32 - 2009-09-04 17:29 - 01892184 _____ (Microsoft Corporation) C:\WINDOWS\system32\D3DX9_42.dll
2015-12-01 01:32 - 2009-09-04 17:29 - 00453456 _____ (Microsoft Corporation) C:\WINDOWS\system32\d3dx10_42.dll
2015-12-01 01:32 - 2009-09-04 17:29 - 00235344 _____ (Microsoft Corporation) C:\WINDOWS\system32\d3dx11_42.dll
2015-12-01 01:32 - 2009-03-16 14:18 - 00517448 _____ (Microsoft Corporation) C:\WINDOWS\system32\XAudio2_4.dll
2015-12-01 01:32 - 2009-03-16 14:18 - 00235352 _____ (Microsoft Corporation) C:\WINDOWS\system32\xactengine3_4.dll
2015-12-01 01:32 - 2009-03-16 14:18 - 00022360 _____ (Microsoft Corporation) C:\WINDOWS\system32\X3DAudio1_6.dll
2015-12-01 01:32 - 2009-03-09 15:27 - 04178264 _____ (Microsoft Corporation) C:\WINDOWS\system32\D3DX9_41.dll
2015-12-01 01:32 - 2009-03-09 15:27 - 01846632 _____ (Microsoft Corporation) C:\WINDOWS\system32\D3DCompiler_41.dll
2015-12-01 01:32 - 2009-03-09 15:27 - 00453456 _____ (Microsoft Corporation) C:\WINDOWS\system32\d3dx10_41.dll
2015-12-01 01:32 - 2008-10-27 10:04 - 00514384 _____ (Microsoft Corporation) C:\WINDOWS\system32\XAudio2_3.dll
2015-12-01 01:32 - 2008-10-27 10:04 - 00235856 _____ (Microsoft Corporation) C:\WINDOWS\system32\xactengine3_3.dll
2015-12-01 01:32 - 2008-10-27 10:04 - 00070992 _____ (Microsoft Corporation) C:\WINDOWS\system32\XAPOFX1_2.dll
2015-12-01 01:32 - 2008-10-27 10:04 - 00023376 _____ (Microsoft Corporation) C:\WINDOWS\system32\X3DAudio1_5.dll
2015-12-01 01:32 - 2008-10-10 04:52 - 04379984 _____ (Microsoft Corporation) C:\WINDOWS\system32\D3DX9_40.dll
2015-12-01 01:32 - 2008-10-10 04:52 - 02036576 _____ (Microsoft Corporation) C:\WINDOWS\system32\D3DCompiler_40.dll
2015-12-01 01:32 - 2008-10-10 04:52 - 00452440 _____ (Microsoft Corporation) C:\WINDOWS\system32\d3dx10_40.dll
2015-12-01 01:32 - 2008-07-31 10:41 - 00238088 _____ (Microsoft Corporation) C:\WINDOWS\system32\xactengine3_2.dll
2015-12-01 01:32 - 2008-07-31 10:41 - 00068616 _____ (Microsoft Corporation) C:\WINDOWS\system32\XAPOFX1_1.dll
2015-12-01 01:32 - 2008-07-31 10:40 - 00509448 _____ (Microsoft Corporation) C:\WINDOWS\system32\XAudio2_2.dll
2015-12-01 01:32 - 2008-07-10 11:01 - 00467984 _____ (Microsoft Corporation) C:\WINDOWS\system32\d3dx10_39.dll
2015-12-01 01:32 - 2008-07-10 11:00 - 03851784 _____ (Microsoft Corporation) C:\WINDOWS\system32\D3DX9_39.dll
2015-12-01 01:32 - 2008-07-10 11:00 - 01493528 _____ (Microsoft Corporation) C:\WINDOWS\system32\D3DCompiler_39.dll
2015-12-01 01:32 - 2008-05-30 14:19 - 00507400 _____ (Microsoft Corporation) C:\WINDOWS\system32\XAudio2_1.dll
2015-12-01 01:32 - 2008-05-30 14:18 - 00238088 _____ (Microsoft Corporation) C:\WINDOWS\system32\xactengine3_1.dll
2015-12-01 01:32 - 2008-05-30 14:17 - 00065032 _____ (Microsoft Corporation) C:\WINDOWS\system32\XAPOFX1_0.dll
2015-12-01 01:32 - 2008-05-30 14:17 - 00025608 _____ (Microsoft Corporation) C:\WINDOWS\system32\X3DAudio1_4.dll
2015-12-01 01:32 - 2008-05-30 14:11 - 03850760 _____ (Microsoft Corporation) C:\WINDOWS\system32\D3DX9_38.dll
2015-12-01 01:32 - 2008-05-30 14:11 - 01491992 _____ (Microsoft Corporation) C:\WINDOWS\system32\D3DCompiler_38.dll
2015-12-01 01:32 - 2008-05-30 14:11 - 00467984 _____ (Microsoft Corporation) C:\WINDOWS\system32\d3dx10_38.dll
2015-12-01 01:32 - 2008-03-05 16:03 - 00479752 _____ (Microsoft Corporation) C:\WINDOWS\system32\XAudio2_0.dll
2015-12-01 01:32 - 2008-03-05 16:03 - 00238088 _____ (Microsoft Corporation) C:\WINDOWS\system32\xactengine3_0.dll
2015-12-01 01:32 - 2008-03-05 16:00 - 00025608 _____ (Microsoft Corporation) C:\WINDOWS\system32\X3DAudio1_3.dll
2015-12-01 01:32 - 2008-03-05 15:56 - 03786760 _____ (Microsoft Corporation) C:\WINDOWS\system32\D3DX9_37.dll
2015-12-01 01:32 - 2008-03-05 15:56 - 01420824 _____ (Microsoft Corporation) C:\WINDOWS\system32\D3DCompiler_37.dll
2015-12-01 01:32 - 2008-02-05 23:07 - 00462864 _____ (Microsoft Corporation) C:\WINDOWS\system32\d3dx10_37.dll
2015-12-01 01:32 - 2007-10-22 03:39 - 00267272 _____ (Microsoft Corporation) C:\WINDOWS\system32\xactengine2_10.dll
2015-12-01 01:32 - 2007-10-22 03:37 - 00017928 _____ (Microsoft Corporation) C:\WINDOWS\system32\X3DAudio1_2.dll
2015-12-01 01:32 - 2007-10-12 15:14 - 03734536 _____ (Microsoft Corporation) C:\WINDOWS\system32\d3dx9_36.dll
2015-12-01 01:32 - 2007-10-12 15:14 - 01374232 _____ (Microsoft Corporation) C:\WINDOWS\system32\D3DCompiler_36.dll
2015-12-01 01:32 - 2007-10-02 09:56 - 00444776 _____ (Microsoft Corporation) C:\WINDOWS\system32\d3dx10_36.dll
2015-12-01 01:32 - 2007-07-20 00:57 - 00267112 _____ (Microsoft Corporation) C:\WINDOWS\system32\xactengine2_9.dll
2015-12-01 01:32 - 2007-07-19 18:14 - 03727720 _____ (Microsoft Corporation) C:\WINDOWS\system32\d3dx9_35.dll
2015-12-01 01:32 - 2007-07-19 18:14 - 01358192 _____ (Microsoft Corporation) C:\WINDOWS\system32\D3DCompiler_35.dll
2015-12-01 01:32 - 2007-07-19 18:14 - 00444776 _____ (Microsoft Corporation) C:\WINDOWS\system32\d3dx10_35.dll
2015-12-01 01:32 - 2007-06-20 20:46 - 00266088 _____ (Microsoft Corporation) C:\WINDOWS\system32\xactengine2_8.dll
2015-12-01 01:32 - 2007-05-16 16:45 - 03497832 _____ (Microsoft Corporation) C:\WINDOWS\system32\d3dx9_34.dll
2015-12-01 01:32 - 2007-05-16 16:45 - 01124720 _____ (Microsoft Corporation) C:\WINDOWS\system32\D3DCompiler_34.dll
2015-12-01 01:32 - 2007-05-16 16:45 - 00443752 _____ (Microsoft Corporation) C:\WINDOWS\system32\d3dx10_34.dll
2015-12-01 01:32 - 2007-04-04 18:55 - 00261480 _____ (Microsoft Corporation) C:\WINDOWS\system32\xactengine2_7.dll
2015-12-01 01:32 - 2007-04-04 18:53 - 00081768 _____ (Microsoft Corporation) C:\WINDOWS\system32\xinput1_3.dll
2015-12-01 01:32 - 2007-03-15 16:57 - 00443752 _____ (Microsoft Corporation) C:\WINDOWS\system32\d3dx10_33.dll
2015-12-01 01:32 - 2007-03-12 16:42 - 03495784 _____ (Microsoft Corporation) C:\WINDOWS\system32\d3dx9_33.dll
2015-12-01 01:32 - 2007-03-12 16:42 - 01123696 _____ (Microsoft Corporation) C:\WINDOWS\system32\D3DCompiler_33.dll
2015-12-01 01:32 - 2007-03-05 12:42 - 00015128 _____ (Microsoft Corporation) C:\WINDOWS\system32\x3daudio1_1.dll
2015-12-01 01:32 - 2007-01-24 15:27 - 00255848 _____ (Microsoft Corporation) C:\WINDOWS\system32\xactengine2_6.dll
2015-12-01 01:32 - 2006-12-08 12:02 - 00251672 _____ (Microsoft Corporation) C:\WINDOWS\system32\xactengine2_5.dll
2015-12-01 01:32 - 2006-11-29 13:06 - 03426072 _____ (Microsoft Corporation) C:\WINDOWS\system32\d3dx9_32.dll
2015-12-01 01:32 - 2006-09-28 16:05 - 02414360 _____ (Microsoft Corporation) C:\WINDOWS\system32\d3dx9_31.dll
2015-12-01 01:32 - 2006-09-28 16:05 - 00237848 _____ (Microsoft Corporation) C:\WINDOWS\system32\xactengine2_4.dll
2015-12-01 01:32 - 2006-07-28 09:30 - 00236824 _____ (Microsoft Corporation) C:\WINDOWS\system32\xactengine2_3.dll
2015-12-01 01:32 - 2006-07-28 09:30 - 00062744 _____ (Microsoft Corporation) C:\WINDOWS\system32\xinput1_2.dll
2015-12-01 01:32 - 2006-05-31 07:24 - 00230168 _____ (Microsoft Corporation) C:\WINDOWS\system32\xactengine2_2.dll
2015-12-01 01:32 - 2006-03-31 12:40 - 02388176 _____ (Microsoft Corporation) C:\WINDOWS\system32\d3dx9_30.dll
2015-12-01 01:32 - 2006-03-31 12:39 - 00229584 _____ (Microsoft Corporation) C:\WINDOWS\system32\xactengine2_1.dll
2015-12-01 01:32 - 2006-03-31 12:39 - 00062672 _____ (Microsoft Corporation) C:\WINDOWS\system32\xinput1_1.dll
2015-12-01 01:32 - 2006-02-03 08:43 - 02332368 _____ (Microsoft Corporation) C:\WINDOWS\system32\d3dx9_29.dll
2015-12-01 01:32 - 2006-02-03 08:42 - 00230096 _____ (Microsoft Corporation) C:\WINDOWS\system32\xactengine2_0.dll
2015-12-01 01:32 - 2006-02-03 08:41 - 00014032 _____ (Microsoft Corporation) C:\WINDOWS\system32\x3daudio1_0.dll
2015-12-01 01:32 - 2005-12-05 18:09 - 02323664 _____ (Microsoft Corporation) C:\WINDOWS\system32\d3dx9_28.dll
2015-12-01 01:32 - 2005-12-05 18:07 - 00061136 _____ (Microsoft Corporation) C:\WINDOWS\system32\xinput9_1_0.dll
2015-12-01 01:32 - 2005-07-22 19:59 - 02319568 _____ (Microsoft Corporation) C:\WINDOWS\system32\d3dx9_27.dll
2015-12-01 01:31 - 2005-05-26 15:34 - 02297552 _____ (Microsoft Corporation) C:\WINDOWS\system32\d3dx9_26.dll
2015-12-01 01:31 - 2005-03-18 17:19 - 02337488 _____ (Microsoft Corporation) C:\WINDOWS\system32\d3dx9_25.dll
2015-12-01 01:31 - 2005-02-05 19:45 - 02222800 _____ (Microsoft Corporation) C:\WINDOWS\system32\d3dx9_24.dll
2015-12-01 01:26 - 2015-12-01 01:26 - 00001022 _____ C:\Documents and Settings\All Users\Desktop\SiSoftware Sandra Lite 2014.RTM.lnk
2015-12-01 01:26 - 2015-12-01 01:26 - 00000000 ____D C:\Documents and Settings\All Users\Start Menu\Programs\SiSoftware
2015-12-01 01:25 - 2015-12-01 01:25 - 00000000 ____D C:\Program Files\SiSoftware
2015-12-01 00:19 - 2015-12-01 00:19 - 00000598 _____ C:\Documents and Settings\1\Desktop\Shortcut to setfsb.exe.lnk
2015-11-30 10:45 - 2015-11-30 10:45 - 00181357 _____ C:\Documents and Settings\1\My Documents\(BPB Exclusive) Valve Filter VF-1 FREE LICENSE.pdf
2015-11-29 01:13 - 2015-12-01 00:49 - 00000000 ____D C:\Program Files\Setfsb
2015-11-29 01:12 - 2015-11-29 01:12 - 00000000 ____D C:\Documents and Settings\1\My Documents\New Folder
2015-11-29 01:07 - 2015-11-29 01:08 - 00223726 _____ C:\Documents and Settings\1\Desktop\setfsb_2_2_134_98 (1).zip
2015-11-21 05:52 - 2015-11-21 05:52 - 00000717 _____ C:\Documents and Settings\All Users\Desktop\CPUID CPU-Z.lnk
2015-11-21 05:52 - 2015-11-21 05:52 - 00000000 ____D C:\Program Files\CPUID
2015-11-21 05:52 - 2015-11-21 05:52 - 00000000 ____D C:\Documents and Settings\All Users\Start Menu\Programs\CPUID

==================== One Month Modified files and folders ========

(If an entry is included in the fixlist, the file/folder will be moved.)

2015-12-21 17:10 - 2013-05-18 05:13 - 00000000 ____D C:\Documents and Settings\Administrator\Local Settings\Temp
2015-12-21 17:10 - 2006-05-09 05:35 - 00000000 ____D C:\WINDOWS
2015-12-21 15:49 - 2006-03-27 12:00 - 00001158 _____ C:\WINDOWS\system32\wpa.dbl
2015-12-21 15:31 - 2015-07-03 22:30 - 00000330 ____H C:\WINDOWS\Tasks\MP Scheduled Scan.job
2015-12-21 15:28 - 2013-05-18 05:13 - 00000178 ___SH C:\Documents and Settings\Administrator\ntuser.ini
2015-12-21 14:28 - 2013-05-14 02:05 - 00000000 ____D C:\Program Files\CCleaner
2015-12-21 14:00 - 2013-05-18 05:13 - 00000000 ____D C:\Documents and Settings\Administrator
2015-12-21 13:27 - 2006-08-17 05:52 - 00000178 ___SH C:\Documents and Settings\1\ntuser.ini
2015-12-21 13:27 - 2006-08-17 05:52 - 00000000 ____D C:\Documents and Settings\1\Local Settings\Temp
2015-12-21 13:27 - 2006-05-09 07:40 - 00000178 ___SH C:\Documents and Settings\LocalService\ntuser.ini
2015-12-21 13:27 - 2006-03-27 12:00 - 00000006 ____H C:\WINDOWS\Tasks\SA.DAT
2015-12-21 13:23 - 2012-12-30 17:30 - 00000414 ____H C:\WINDOWS\Tasks\User_Feed_Synchronization-{F7405781-D735-43C3-BEA3-06C346D0BF27}.job
2015-12-21 13:22 - 2006-03-27 10:59 - 00000710 _____ C:\WINDOWS\win.ini
2015-12-21 13:22 - 2006-03-27 10:53 - 00000327 ___SH C:\boot.ini
2015-12-21 13:22 - 2006-03-27 02:50 - 00000256 _____ C:\WINDOWS\system.ini
2015-12-21 13:18 - 2014-03-10 07:17 - 00000214 _____ C:\WINDOWS\Tasks\Microsoft Windows XP End of Service Notification Logon.job
2015-12-21 13:18 - 2014-03-06 17:29 - 00000514 _____ C:\WINDOWS\Tasks\Amazon Music Helper.job
2015-12-21 13:18 - 2013-06-26 15:28 - 00000882 _____ C:\WINDOWS\Tasks\GoogleUpdateTaskMachineCore.job
2015-12-16 21:37 - 2013-05-18 05:13 - 00000000 ____D C:\Documents and Settings\Administrator\Local Settings\Application Data\Google
2015-12-16 20:21 - 2013-05-18 05:13 - 00000000 ___RD C:\Documents and Settings\Administrator\My Documents
2015-12-16 17:45 - 2006-05-09 05:35 - 00000000 _RSHD C:\WINDOWS\system32\dllcache
2015-12-16 17:45 - 2006-05-09 05:35 - 00000000 ___HD C:\WINDOWS\inf
2015-12-16 17:29 - 2013-06-17 16:11 - 00000000 ____D C:\Documents and Settings\NetworkService\Local Settings\temp
2015-12-16 16:53 - 2006-05-09 05:35 - 00000000 ____D C:\Documents and Settings\All Users
2015-12-15 16:34 - 2006-05-09 07:40 - 00000000 ____D C:\Documents and Settings\LocalService\Local Settings\Temp
2015-12-15 15:59 - 2008-09-03 07:16 - 00000000 ____D C:\Documents and Settings\1\My Documents\My Downloads
2015-12-15 13:56 - 2006-05-09 07:40 - 00000178 ___SH C:\Documents and Settings\NetworkService\ntuser.ini
2015-12-15 11:33 - 2013-05-18 05:13 - 00046176 _____ C:\Documents and Settings\Administrator\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2015-12-14 15:06 - 2013-06-26 15:28 - 00000886 _____ C:\WINDOWS\Tasks\GoogleUpdateTaskMachineUA.job
2015-12-14 14:53 - 2014-04-03 15:13 - 00000506 _____ C:\WINDOWS\Tasks\G2MUpdateTask-S-1-5-21-2740428291-721650609-345291581-1006.job
2015-12-14 14:35 - 2015-05-30 16:32 - 00000602 _____ C:\WINDOWS\Tasks\G2MUploadTask-S-1-5-21-2740428291-721650609-345291581-1006.job
2015-12-14 10:09 - 2010-06-14 16:52 - 00000000 __HDC C:\WINDOWS\$NtUninstallKB981349$
2015-12-13 20:17 - 2013-07-15 02:07 - 00000000 ____D C:\WINDOWS\system32\MRT
2015-12-13 20:08 - 2007-06-12 23:11 - 137798368 _____ (Microsoft Corporation) C:\WINDOWS\system32\MRT.exe
2015-12-13 19:47 - 2014-04-14 15:47 - 00000147 _____ C:\Documents and Settings\NetworkService\Application Data\WB.CFG
2015-12-13 19:24 - 2013-06-26 15:29 - 00001813 _____ C:\Documents and Settings\All Users\Desktop\Google Chrome.lnk
2015-12-09 07:35 - 2012-05-12 15:58 - 00002137 _____ C:\Documents and Settings\1\Desktop\iTunes.lnk
2015-12-08 11:45 - 2006-08-17 05:52 - 00000000 ___RD C:\Documents and Settings\1\My Documents
2015-12-03 03:29 - 2006-12-12 23:32 - 00002477 _____ C:\Documents and Settings\All Users\Start Menu\Programs\Microsoft Excel.lnk
2015-12-03 02:12 - 2015-05-27 10:23 - 00000000 ____D C:\Program Files\E-TRADE Pro
2015-12-02 13:25 - 2009-11-03 05:01 - 00247976 ____N (Microsoft Corporation) C:\WINDOWS\system32\MpSigStub.exe
2015-12-01 01:32 - 2006-05-09 05:35 - 00000000 ____D C:\WINDOWS\system32\DirectX

==================== Files in the root of some directories =======

2015-12-15 11:33 - 2013-10-29 12:59 - 14024704 _____ () C:\Documents and Settings\Administrator\Application Data\Sandra.mdb
2013-05-18 05:13 - 2006-05-09 08:33 - 0000000 _____ () C:\Documents and Settings\Administrator\Local Settings\Application Data\AtStart.txt
2015-12-16 17:26 - 2015-12-21 15:12 - 0000664 _____ () C:\Documents and Settings\Administrator\Local Settings\Application Data\d3d9caps.dat
2013-05-18 05:13 - 2006-05-09 08:33 - 0000000 _____ () C:\Documents and Settings\Administrator\Local Settings\Application Data\DSwitch.txt
2013-05-18 05:13 - 2006-05-09 07:41 - 0000128 _____ () C:\Documents and Settings\Administrator\Local Settings\Application Data\fusioncache.dat
2013-05-18 05:13 - 2006-05-09 08:33 - 0000000 _____ () C:\Documents and Settings\Administrator\Local Settings\Application Data\QSwitch.txt
2006-03-27 11:24 - 2014-12-26 14:38 - 0016058 _____ () C:\Documents and Settings\All Users\Application Data\hpzinstall.log

==================== Bamital & volsnap =================

(There is no automatic fix for files that do not pass verification.)

C:\WINDOWS\explorer.exe => File is digitally signed
C:\WINDOWS\system32\winlogon.exe => File is digitally signed
C:\WINDOWS\system32\svchost.exe => File is digitally signed
C:\WINDOWS\system32\services.exe => File is digitally signed
C:\WINDOWS\system32\User32.dll => File is digitally signed
C:\WINDOWS\system32\userinit.exe => File is digitally signed
C:\WINDOWS\system32\rpcss.dll => File is digitally signed
C:\WINDOWS\system32\dnsapi.dll => File is digitally signed
C:\WINDOWS\system32\Drivers\volsnap.sys => File is digitally signed

==================== End of FRST.txt ============================
Additional scan result of Farbar Recovery Scan Tool (x86) Version:20-12-2015
Ran by Administrator (2015-12-21 17:11:52)
Running from C:\Documents and Settings\Administrator\Desktop
Microsoft Windows XP Service Pack 3 (X86) (2006-08-17 10:52:00)
Boot Mode: Safe Mode (with Networking)
==========================================================


==================== Accounts: =============================

1 (S-1-5-21-2740428291-721650609-345291581-1006 - Administrator - Enabled) => %SystemDrive%\Documents and Settings\1
Administrator (S-1-5-21-2740428291-721650609-345291581-500 - Administrator - Enabled) => %SystemDrive%\Documents and Settings\Administrator
ASPNET (S-1-5-21-2740428291-721650609-345291581-1004 - Limited - Enabled)
Guest (S-1-5-21-2740428291-721650609-345291581-501 - Limited - Enabled)
HelpAssistant (S-1-5-21-2740428291-721650609-345291581-1005 - Limited - Disabled)
SUPPORT_388945a0 (S-1-5-21-2740428291-721650609-345291581-1002 - Limited - Disabled)

==================== Security Center ========================

(If an entry is included in the fixlist, it will be removed.)


==================== Installed Programs ======================

(Only the adware programs with "Hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.)

32 Bit HP CIO Components Installer (Version: 7.1.8 - Hewlett-Packard) Hidden
5 Card Slingo from Hewlett-Packard Laptops (remove only) (HKLM\...\5DE4D54F-AA79-43A4-9C8A-C173E7E2B025) (Version: - WildTangent)
7-Zip 4.42 (HKLM\...\7-Zip) (Version: - )
Adobe Acrobat - Reader 6.0.2 Update (HKLM\...\{AC76BA86-0000-0000-0000-6028747ADE01}) (Version: 6.0.2 - Adobe Systems)
Adobe Acrobat and Reader 6.0.3 Update (HKLM\...\{AC76BA86-0000-7EC8-7489-000000000603}) (Version: 6.0.3 - Adobe Systems)
Adobe Acrobat and Reader 6.0.4 Update (HKLM\...\{AC76BA86-0000-7EC8-7489-000000000604}) (Version: 6.0.4 - Adobe Systems)
Adobe Acrobat and Reader 6.0.5 Update (HKLM\...\{AC76BA86-0000-7EC8-7489-000000000605}) (Version: 6.0.5 - Adobe Systems)
Adobe Acrobat and Reader 6.0.6 Update (HKLM\...\{AC76BA86-0000-7EC8-7489-000000000606}) (Version: 6.0.6 - Adobe Systems)
Adobe Flash Player 19 ActiveX (HKLM\...\Adobe Flash Player ActiveX) (Version: 19.0.0.245 - Adobe Systems Incorporated)
Adobe Flash Player 19 NPAPI (HKLM\...\Adobe Flash Player NPAPI) (Version: 19.0.0.185 - Adobe Systems Incorporated)
Adobe Flash Player 19 PPAPI (HKLM\...\Adobe Flash Player PPAPI) (Version: 19.0.0.185 - Adobe Systems Incorporated)
Adobe Reader 6.0.1 (HKLM\...\{AC76BA86-7AD7-1033-7B44-A00000000001}) (Version: 006.000.001 - Adobe Systems Incorporated)
Apple Application Support (HKLM\...\{A83279FD-CA4B-4206-9535-90974DE76654}) (Version: 2.1.5 - Apple Inc.)
Apple Mobile Device Support (HKLM\...\{CCA1EEA3-555E-4D05-AC46-4B49C6C5D887}) (Version: 3.2.0.47 - Apple Inc.)
Apple Software Update (HKLM\...\{789A5B64-9DD9-4BA5-915A-F0FC0A1B7BFE}) (Version: 2.1.3.127 - Apple Inc.)
AutoUpdate (HKLM\...\{18D10072035C4515918F7E37EAFAACFC}) (Version: 1.1 - )
Avanquest update (HKLM\...\{76E41F43-59D2-4F30-BA42-9A762EE1E8DE}) (Version: 1.25 - Avanquest Software)
BlackBerry Desktop Software 4.3 (HKLM\...\BlackBerry_{3AE87269-BD57-4A58-B13D-FC67664BCFB8}) (Version: 4.3.0.17 - Research In Motion Ltd.)
BlackBerry Desktop Software 4.3 (Version: 4.3.0.17 - Research In Motion Ltd.) Hidden
BlackBerry Device Software Updater (HKLM\...\{12BAA98C-F8DD-4BC9-BBE6-1C8463114197}) (Version: 6.0.1.37 - Research In Motion Ltd)
BlackBerry v4.2.1 for the 8100 Series Wireless Handheld (HKLM\...\{DD7C1079-A2CC-48FB-8208-1EE38C8C2FBA}) (Version: 4.2.1.107 (Platform 2.3.0.83) - Research In Motion Ltd.)
Blackhawk Striker 2 from Hewlett-Packard Laptops (remove only) (HKLM\...\384E0BF4-1E1F-45A6-B60E-42144A3F15CD) (Version: - WildTangent)
Boggle Supreme from Hewlett-Packard Laptops (remove only) (HKLM\...\5658FB14-16A4-4DAE-946B-1457BE31572E) (Version: - WildTangent)
Bounce Symphony from Hewlett-Packard Laptops (remove only) (HKLM\...\7A940E33-6993-404B-ABA6-ED62E8FBE615) (Version: - WildTangent)
BufferChm (Version: 130.0.331.000 - Hewlett-Packard) Hidden
C4700 (Version: 130.0.373.000 - Hewlett-Packard) Hidden
Cablenut 4.08 (HKLM\...\Cablenut) (Version: - )
CCleaner (HKLM\...\CCleaner) (Version: 5.12 - Piriform)
Citrix Online Launcher (HKLM\...\{F17C3DC2-2ACA-4B0E-BDBF-ACE61B14E7CD}) (Version: 1.0.183 - Citrix)
CleanUp! (HKLM\...\CleanUp!) (Version: - )
Compatibility Pack for the 2007 Office system (HKLM\...\{90120000-0020-0409-0000-0000000FF1CE}) (Version: 12.0.6514.5001 - Microsoft Corporation)
Conexant HD Audio (HKLM\...\CNXT_HDAUDIO) (Version: 3.40.0.50 - Conexant)
CPUID CPU-Z 1.74 (HKLM\...\CPUID CPU-Z_is1) (Version: - )
Crusader No Remorse (HKLM\...\{2AEA735F-B393-4D89-93EF-5849CB72B4A3}) (Version: 1.0.0.2 - Electronic Arts)
Crystal Maze from Hewlett-Packard Laptops (remove only) (HKLM\...\E94C7046-2F7D-4D4D-B76F-C412DCCEAAC2) (Version: - WildTangent)
Customer Experience Enhancement (HKLM\...\InstallShield_{23012310-3E05-46A5-88A9-C6CBCABCAC79}) (Version: Customer Experience Enhancement -1.0.0.1680 - Hewlett-Packard)
Customer Experience Enhancement (Version: Customer Experience Enhancement -1.0.0.1680 - Hewlett-Packard) Hidden
Destinations (Version: 130.0.0.0 - Hewlett-Packard) Hidden
DeviceDiscovery (Version: 130.0.372.000 - Hewlett-Packard) Hidden
DivX Codec (HKLM\...\{7B63B2922B174135AFC0E1377DD81EC2}) (Version: 6.8.3 - DivX, Inc.)
DivX Converter (HKLM\...\{B13A7C41581B411290FBC0395694E2A9}) (Version: 6.6.1 - DivX, Inc.)
EPSON Printer Software (HKLM\...\EPSON Printer and Utilities) (Version: - )
ESET Online Scanner v3 (HKLM\...\ESET Online Scanner) (Version: - )
E-TRADE Pro 1.06 (HKLM\...\4285-0367-3118-9779) (Version: 1.06 - E*TRADE Financial)
FATE from Hewlett-Packard Laptops (remove only) (HKLM\...\6ECB6EE6-92E1-4525-AF3B-3CE51A7C5F89) (Version: - WildTangent)
Flip Words from Hewlett-Packard Laptops (remove only) (HKLM\...\F2566CC2-D4C4-44ED-A838-3F8288D8D3FE) (Version: - WildTangent)
Free eXPert PDF Reader (HKLM\...\{C2B5A2E5-51F8-4883-AF40-6A17902DAFEA}) (Version: 9.0.180.0 - Visagesoft)
Google Chrome (HKLM\...\Google Chrome) (Version: 47.0.2526.80 - Google Inc.)
Google Update Helper (Version: 1.3.25.11 - Google Inc.) Hidden
Google Update Helper (Version: 1.3.29.1 - Google Inc.) Hidden
GPBaseService2 (Version: 130.0.371.000 - Hewlett-Packard) Hidden
HDAUDIO Soft Data Fax Modem with SmartCP (HKLM\...\CNXT_MODEM_HDAUDIO_CPL30A5m) (Version: - )
HP DVD Play 2.1 (HKLM\...\{45D707E9-F3C4-11D9-A373-0050BAE317E1}) (Version: - )
HP Game Console and games (HKLM\...\HP Game Console) (Version: - WildTangent)
HP Help and Support (HKLM\...\{A93C4E94-1005-489D-BEAA-B873C1AA6CFC}) (Version: 4.2.0006 - HPQ)
HP Imaging Device Functions 13.0 (HKLM\...\HP Imaging Device Functions) (Version: 13.0 - HP)
HP Photosmart C4700 All-In-One Driver Software 13.0 Rel .6 (HKLM\...\{2012D762-5DCA-455A-B5FE-EDF79BC93E18}) (Version: 13.0 - HP)
HP Print Projects 1.0 (HKLM\...\HP Print Projects) (Version: 1.0 - HP)
HP Quick Launch Buttons 6.00 E2 (HKLM\...\{34D2AB40-150D-475D-AE32-BD23FB5EE355}) (Version: 6.00 E2 - Hewlett-Packard Company)
HP Smart Web Printing 4.5 (HKLM\...\HP Smart Web Printing) (Version: 4.5 - HP)
HP Solution Center 13.0 (HKLM\...\HP Solution Center & Imaging Support Tools) (Version: 13.0 - HP)
HP Update (HKLM\...\{2EFA4E4C-7B5F-48F7-A1C0-1AA882B7A9C3}) (Version: 5.003.001.001 - Hewlett-Packard)
HP User Guides 0019 (HKLM\...\{E74E3D81-773B-4DCF-B706-50236F80BD81}) (Version: 1.00.0003 - Hewlett-Packard)
HP User Guides--System Recovery (HKLM\...\{BC96BBA7-C634-460E-AD18-A0A994213F80}) (Version: 1.00.0001 - Hewlett-Packard)
HP Wireless Assistant 2.00 E1 (HKLM\...\{4302B2DD-D958-40E3-BAF3-B07FFE1978CE}) (Version: 2.00 E1 - Hewlett-Packard Company)
hpPrintProjects (Version: 130.0.303.000 - Hewlett-Packard) Hidden
HPProductAssistant (Version: 130.0.371.000 - Hewlett-Packard) Hidden
HpSdpAppCoreApp (Version: 3.00.0000 - Hewlett-Packard) Hidden
hpWLPGInstaller (Version: 130.0.303.000 - Hewlett-Packard) Hidden
Insaniquarium Deluxe from Hewlett-Packard Laptops (remove only) (HKLM\...\0E5266B4-9069-401A-93AE-5FF9F1712016) (Version: - WildTangent)
Intel® Graphics Media Accelerator Driver (HKLM\...\{8A708DD8-A5E6-11D4-A706-000629E95E20}) (Version: 6.14.10.4543 - )
Intel® Network Connections Drivers (HKLM\...\PROSet) (Version: - )
iTunes (HKLM\...\{2CE5A2E7-3437-4CE7-BCF4-85ED6EEFF9E4}) (Version: 10.0.1.22 - Apple Inc.)
Java 7 Update 71 (HKLM\...\{26A24AE4-039D-4CA4-87B4-2F03217071FF}) (Version: 7.0.710 - Oracle)
Jewel Quest from Hewlett-Packard Laptops (remove only) (HKLM\...\4C061F83-EE92-445A-A03F-184B0BD59242) (Version: - WildTangent)
Lemonade Tycoon 2 from Hewlett-Packard Laptops (remove only) (HKLM\...\E90E3AE9-73E4-4E5C-BB0F-673989A808D0) (Version: - WildTangent)
Lexibox Deluxe from Hewlett-Packard Laptops (remove only) (HKLM\...\5758A0E8-A112-4A1D-82EC-EC72F7F16B88) (Version: - WildTangent)
LightScribe 1.4.74.1 (Version: 1.4.74.1 - hxxp://www.lightscribe.com) Hidden
Mah Jong Quest from Hewlett-Packard Laptops (remove only) (HKLM\...\E76A7EFF-7758-49EE-B3FA-9699830A2D6B) (Version: - WildTangent)
Malwarebytes Anti-Malware version 2.2.0.1024 (HKLM\...\Malwarebytes Anti-Malware_is1) (Version: 2.2.0.1024 - Malwarebytes)
Microsoft .NET Framework 1.1 (HKLM\...\Microsoft .NET Framework 1.1 (1033)) (Version: - )
Microsoft .NET Framework 1.1 Security Update (KB2833941) (HKLM\...\M2833941) (Version: - )
Microsoft .NET Framework 1.1 Security Update (KB979906) (HKLM\...\M979906) (Version: - )
Microsoft .NET Framework 2.0 Service Pack 2 (HKLM\...\{C09FB3CD-3D0C-3F2D-899A-6A1D67F2073F}) (Version: 2.2.30729 - Microsoft Corporation)
Microsoft .NET Framework 3.0 Service Pack 2 (HKLM\...\{A3051CD0-2F64-3813-A88D-B8DCCDE8F8C7}) (Version: 3.2.30729 - Microsoft Corporation)
Microsoft .NET Framework 3.5 SP1 (HKLM\...\Microsoft .NET Framework 3.5 SP1) (Version: - Microsoft Corporation)
Microsoft .NET Framework 4 Client Profile (HKLM\...\Microsoft .NET Framework 4 Client Profile) (Version: 4.0.30319 - Microsoft Corporation)
Microsoft Base Smart Card Cryptographic Service Provider Package (HKLM\...\KB909520) (Version: - Microsoft Corporation)
Microsoft Compression Client Pack 1.0 for Windows XP (HKLM\...\MSCompPackV1) (Version: 1 - Microsoft Corporation)
Microsoft Money 2006 (HKLM\...\Money2006b) (Version: 15 - Microsoft)
Microsoft Office 2000 Professional (HKLM\...\{00010409-78E1-11D2-B60F-006097C998E7}) (Version: 9.00.2720 - Microsoft Corporation)
Microsoft Office Standard Edition 2003 (HKLM\...\{91120409-6000-11D3-8CFE-0150048383C9}) (Version: 11.0.5614.0 - Microsoft Corporation)
Microsoft Office Word Viewer 2003 (HKLM\...\{90850409-6000-11D3-8CFE-0150048383C9}) (Version: 11.0.8173.0 - Microsoft Corporation)
Microsoft Silverlight (HKLM\...\{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}) (Version: 5.1.30514.0 - Microsoft Corporation)
Microsoft User-Mode Driver Framework Feature Pack 1.0 (HKLM\...\Wudf01000) (Version: - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM\...\{837b34e3-7c30-493c-8f6a-2b0f04e2912c}) (Version: 8.0.59193 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 (HKLM\...\{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}) (Version: 9.0.30729.4148 - Microsoft Corporation)
Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 (HKLM\...\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Works (HKLM\...\{416D80BA-6F6D-4672-B7CF-F54DA2F80B44}) (Version: 08.04.0623 - Microsoft Corporation)
MotoHelper MergeModules (Version: 1.2.0 - Motorola) Hidden
Motorola Phone Tools (HKLM\...\{BAD8CA9C-77C0-4663-B00B-A8D3B13C341B}) (Version: 4.3.6c 10-23-2006 - Avanquest Software)
Motorola Phone Tools (Version: 4.30 - BVRP Software) Hidden
Mototools Software Update (HKLM\...\{1C23A809-EE16-453B-8CD6-94443B917839}) (Version: 3.4.6 - Motorola)
MSXML 4.0 SP2 (KB927978) (HKLM\...\{37477865-A3F1-4772-AD43-AAFC6BCFF99F}) (Version: 4.20.9841.0 - Microsoft Corporation)
MSXML 4.0 SP2 (KB936181) (HKLM\...\{C04E32E0-0416-434D-AFB9-6969D703A9EF}) (Version: 4.20.9848.0 - Microsoft Corporation)
MSXML 4.0 SP2 (KB954430) (HKLM\...\{86493ADD-824D-4B8E-BD72-8C5DCDC52A71}) (Version: 4.20.9870.0 - Microsoft Corporation)
MSXML 4.0 SP2 (KB973688) (HKLM\...\{F662A8E6-F4DC-41A2-901E-8C11F044BDEC}) (Version: 4.20.9876.0 - Microsoft Corporation)
muvee autoProducer 4.5 (HKLM\...\{286F29AF-0BE2-4D5F-AB17-B7631A810553}) (Version: 4.50.050 - muvee Technologies)
NetWaiting (HKLM\...\{3F92ABBB-6BBF-11D5-B229-002078017FBF}) (Version: 2.5.28 - BVRP Software, Inc)
Network (Version: 130.0.374.000 - Hewlett-Packard) Hidden
Oasis from Hewlett-Packard Laptops (remove only) (HKLM\...\E332F38A-75F6-4EF2-88CC-246E8A1CB5D7) (Version: - WildTangent)
Office 2003 Trial Assistant (HKLM\...\{47D2103B-FD51-4017-9C20-DD408B17D726}) (Version: 1.0.0 - Microsoft)
Optimum App for Laptop 1.70 (HKLM\...\{6082AB31-92B1-4832-AC89-3B2E6D8C14FE}) (Version: 1.70 - Cablevision)
Origin (HKLM\...\Origin) (Version: 9.7.2.53208 - Electronic Arts, Inc.)
P@H-Protocol (HKLM\...\{CF594DB8-CFB0-45B4-86DA-8BB4AC0941F8}) (Version: 3.0.7.0 - Valassis)
PDF Creator (HKLM\...\PDF Creator) (Version: - )
Polar Bowler from Hewlett-Packard Laptops (remove only) (HKLM\...\7F8C5718-1BA9-4AAE-96D2-2B04D05F2D54) (Version: - WildTangent)
Polar Golfer from Hewlett-Packard Laptops (remove only) (HKLM\...\D2E44AA4-8665-4490-A6C9-2D0744B47B27) (Version: - WildTangent)
PS_AIO_06_C4700_SW_Min (Version: 130.0.373.000 - Hewlett-Packard) Hidden
Puzzle Express from Hewlett-Packard Laptops (remove only) (HKLM\...\EF860173-4FB7-4DE1-8BE8-5400F05A0DC5) (Version: - WildTangent)
Quicken 2006 (HKLM\...\{2818095F-FB6C-42C8-827E-0A406CC9AFF5}) (Version: 15.1.4.5 - Intuit)
QuickTime (HKLM\...\{E7004147-2CCA-431C-AA05-2AB166B9785D}) (Version: 7.68.75.0 - Apple Inc.)
RealPlayer (HKLM\...\RealPlayer 6.0) (Version: - RealNetworks)
ReOrganize! (HKLM\...\ReOrganize_is1) (Version: 2.3.1 - Oliver Frietsch)
Scan (Version: 13.0.0.0 - Hewlett-Packard) Hidden
SCRABBLE from Hewlett-Packard Laptops (remove only) (HKLM\...\103EFD47-9F2C-4490-95DD-AE6C442AFB92) (Version: - WildTangent)
SimCity 2000 Special Edition (HKLM\...\{59D2C751-F7BE-4E9F-9C8C-1F16013802C7}) (Version: 2.0.0.1 - Electronic Arts)
SiSoftware Sandra Lite 2014.RTM (HKLM\...\{C3113E55-7BCB-4de3-8EBF-60E6CE6B2396}_is1) (Version: 20.10.2014.2 - SiSoftware)
Slingo Deluxe from Hewlett-Packard Laptops (remove only) (HKLM\...\C264D692-8E15-4141-96A2-5621332E5DD0) (Version: - WildTangent)
Slyder from Hewlett-Packard Laptops (remove only) (HKLM\...\B0202B33-E73D-4FCD-AC88-0B2971AFC116) (Version: - WildTangent)
SmartAudio (HKLM\...\{AEF7A12C-CD9B-4773-8AD1-6916138CA7EA}) (Version: 1.3.7 - CONEXANT)
SmartWebPrinting (Version: 130.0.373.000 - Hewlett-Packard) Hidden
Snowboard SuperJam (HKLM\...\DED8E2B5-BA9F-448F-84E8-0AEF79876F95) (Version: 10/14/2005 02:33 PM - WildTangent)
SolutionCenter (Version: 130.0.373.000 - Hewlett-Packard) Hidden
Sonic Audio Module (HKLM\...\{AB708C9B-97C8-4AC9-899B-DBF226AC9382}) (Version: 2.0.4 - Sonic Solutions)
Sonic Copy Module (HKLM\...\{B12665F4-4E93-4AB4-B7FC-37053B524629}) (Version: 2.0.4 - Sonic Solutions)
Sonic Data Module (HKLM\...\{075473F5-846A-448B-BCB3-104AA1760205}) (Version: 2.0.4 - Sonic Solutions)
Sonic Express Labeler (HKLM\...\{6675CA7F-E51B-4F6A-99D4-F8F0124C6EAA}) (Version: 2.0.0 - Sonic Solutions)
Sonic MyDVD Plus (HKLM\...\{21657574-BD54-48A2-9450-EB03B2C7FC29}) (Version: 6.2.0 - Sonic Solutions)
Sonic Update Manager (HKLM\...\{30465B6C-B53F-49A1-9EBA-A3F187AD502E}) (Version: 3.0.0 - Sonic Solutions)
Sophos Virus Removal Tool (HKLM\...\{B829E117-D072-41EA-9606-9826A38D34C1}) (Version: 2.5.5 - Sophos Limited)
Spybot - Search & Destroy (HKLM\...\{B4092C6D-E886-4CB2-BA68-FE5A88D31DE6}_is1) (Version: 1.6.2 - Safer Networking Limited)
Status (Version: 130.0.373.000 - Hewlett-Packard) Hidden
Super Granny from Hewlett-Packard Laptops (remove only) (HKLM\...\7ED8A70C-9597-40BE-AEA0-0573182F1F51) (Version: - WildTangent)
Synaptics Pointing Device Driver (HKLM\...\SynTPDeinstKey) (Version: 10.0.13.2 - Synaptics)
Texas Instruments PCIxx21/x515/xx12 drivers. (HKLM\...\InstallShield_{7B6CF9EB-CB2B-4A1A-81A9-BE1A9044690A}) (Version: 1.15.0000 - Texas Instruments Inc.)
TIPCI (Version: 1.15.0000 - Texas Instruments Inc.) Hidden
Toolbox (Version: 130.0.648.000 - Hewlett-Packard) Hidden
TourSetup (HKLM\...\{A01FC76F-CC09-4658-9E37-5C2F635EE708}) (Version: 1.0.0 - Microsoft)
Tradewinds from Hewlett-Packard Laptops (remove only) (HKLM\...\1C3FDBBA-EBF7-4CDB-AD8A-A1125734AF86) (Version: - WildTangent)
TrayApp (Version: 130.0.376.000 - Hewlett-Packard) Hidden
Unload (Version: 6.0.0 - Hewlett-Packard) Hidden
VoiceOver Kit (HKLM\...\{FB26A501-6BA6-459B-89AA-9736730752FB}) (Version: 1.30.128.0 - Apple Inc.)
WebEx (HKLM\...\ActiveTouchMeetingClient) (Version: - WebEx Communications, Inc)
WebFldrs XP (Version: 9.50.7523 - Microsoft Corporation) Hidden
WebReg (Version: 130.0.132.017 - Hewlett-Packard) Hidden
WebWasher (HKLM\...\WebWasher) (Version: 3.4 - webwasher.com AG)
Windows Backup Utility (HKLM\...\{76EFFC7C-17A6-479D-9E47-8E658C1695AE}) (Version: 5.1 - Microsoft Corporation)
Windows Defender (HKLM\...\{A06275F4-324B-4E85-95E6-87B2CD729401}) (Version: 1.1.1593.0 - Microsoft Corporation)
Windows Genuine Advantage Validation Tool (KB892130) (HKLM\...\KB892130) (Version: - Microsoft Corporation)
Windows Genuine Advantage Validation Tool (KB892130) (HKLM\...\WGA) (Version: 1.7.0069.2 - Microsoft Corporation)
Windows Internet Explorer 8 (HKLM\...\ie8) (Version: 20090308.140743 - Microsoft Corporation)
Windows Management Framework Core (HKLM\...\KB968930) (Version: - Microsoft Corporation)
Windows Media Format 11 runtime (HKLM\...\Windows Media Format Runtime) (Version: - )
Windows Media Player 11 (HKLM\...\Windows Media Player) (Version: - )
Windows XP Service Pack 3 (HKLM\...\Windows XP Service Pack) (Version: 20080414.031525 - Microsoft Corporation)
Wing Commander III (HKLM\...\{F96B9930-E22A-44D6-81B5-6C8E92C21B4B}) (Version: 2.0.0.2 - Electronic Arts)
Wireless Home Network Setup (HKLM\...\{09D8492A-C8E2-421E-927D-46800FB327A3}) (Version: 1.1.154.1 - Hewlett-Packard)
Zuma Deluxe from Hewlett-Packard Laptops (remove only) (HKLM\...\074EEF5F-3BE8-4112-B253-C5D6CDE2924C) (Version: - WildTangent)
Zumas Revenge (HKLM\...\{0B153CAB-792B-4CA2-B2A5-AB0BBAF2FFA9}) (Version: 1.0.5.600 - PopCap Games)

==================== Custom CLSID (Whitelisted): ==========================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

CustomCLSID: HKU\S-1-5-21-2740428291-721650609-345291581-500_Classes\CLSID\{037FB476-15E0-4ED1-B11A-E420B750B1A8}\localserver32 -> C:\Program Files\Common Files\InstallShield\UpdateService\agent.exe (Macrovision Corporation)
CustomCLSID: HKU\S-1-5-21-2740428291-721650609-345291581-500_Classes\CLSID\{2837E0FE-686B-4CB0-BE53-0EA097EAF71B}\InprocServer32 -> C:\WINDOWS\Downloaded Program Files\isusweb.dll (Macrovision Corporation)
CustomCLSID: HKU\S-1-5-21-2740428291-721650609-345291581-500_Classes\CLSID\{5AFAFE48-7107-4FE5-B21A-86A4254541DD}\localserver32 -> C:\Program Files\Common Files\InstallShield\UpdateService\agent.exe (Macrovision Corporation)
CustomCLSID: HKU\S-1-5-21-2740428291-721650609-345291581-500_Classes\CLSID\{5B7524C8-2446-40E9-9474-94A779DBA224}\InprocServer32 -> C:\WINDOWS\Downloaded Program Files\isusweb.dll (Macrovision Corporation)
CustomCLSID: HKU\S-1-5-21-2740428291-721650609-345291581-500_Classes\CLSID\{621D3650-F1D3-414C-97F9-03A02B211261}\localserver32 -> C:\Program Files\Common Files\InstallShield\UpdateService\ISDM.exe (Macrovision Corporation)
CustomCLSID: HKU\S-1-5-21-2740428291-721650609-345291581-500_Classes\CLSID\{623E415A-22EF-4DAA-A2FF-E68E77A673C9}\localserver32 -> C:\Program Files\Common Files\InstallShield\UpdateService\ISDM.exe (Macrovision Corporation)
CustomCLSID: HKU\S-1-5-21-2740428291-721650609-345291581-500_Classes\CLSID\{885BB46A-3F1E-44C3-A01B-A7D9260CC98B}\InprocServer32 -> C:\WINDOWS\Downloaded Program Files\dwusplay.dll (InstallShield Software Corporation)
CustomCLSID: HKU\S-1-5-21-2740428291-721650609-345291581-500_Classes\CLSID\{915C2CEB-216B-4B7C-89E4-9ED3512D58D9}\localserver32 -> C:\Program Files\Common Files\InstallShield\UpdateService\ISDM.exe (Macrovision Corporation)
CustomCLSID: HKU\S-1-5-21-2740428291-721650609-345291581-500_Classes\CLSID\{92C5E738-7372-4CD6-BE57-15833624EBF3}\localserver32 -> C:\Program Files\Common Files\InstallShield\UpdateService\ISDM.exe (Macrovision Corporation)
CustomCLSID: HKU\S-1-5-21-2740428291-721650609-345291581-500_Classes\CLSID\{9CAAD2EA-177B-4D07-871F-47255B5D30F3}\localserver32 -> C:\Program Files\Common Files\InstallShield\UpdateService\ISDM.exe (Macrovision Corporation)
CustomCLSID: HKU\S-1-5-21-2740428291-721650609-345291581-500_Classes\CLSID\{B391A1DB-28C8-4506-A43C-5BD6051F16BA}\localserver32 -> C:\Program Files\Common Files\InstallShield\UpdateService\ISDM.exe (Macrovision Corporation)
CustomCLSID: HKU\S-1-5-21-2740428291-721650609-345291581-500_Classes\CLSID\{E42CE23D-69F9-480A-A15F-BFF5E4D170C3}\localserver32 -> C:\Program Files\Common Files\InstallShield\UpdateService\agent.exe (Macrovision Corporation)
CustomCLSID: HKU\S-1-5-21-2740428291-721650609-345291581-500_Classes\CLSID\{E50C953D-311A-481B-8F8D-C55E65AF7417}\localserver32 -> C:\Program Files\Common Files\InstallShield\UpdateService\ISDM.exe (Macrovision Corporation)
CustomCLSID: HKU\S-1-5-21-2740428291-721650609-345291581-500_Classes\CLSID\{E9880553-B8A7-4960-A668-95C68BED571E}\InprocServer32 -> C:\WINDOWS\Downloaded Program Files\isusweb.dll (Macrovision Corporation)
CustomCLSID: HKU\S-1-5-21-2740428291-721650609-345291581-500_Classes\CLSID\{E9A93328-79D4-4AED-A778-146E7191F8BC}\localserver32 -> C:\Program Files\Common Files\InstallShield\UpdateService\ISDM.exe (Macrovision Corporation)
CustomCLSID: HKU\S-1-5-21-2740428291-721650609-345291581-500_Classes\CLSID\{F1522EC1-F84F-4CE2-A38C-F9384B0DFD41}\localserver32 -> C:\Program Files\Common Files\InstallShield\UpdateService\agent.exe (Macrovision Corporation)
CustomCLSID: HKU\S-1-5-21-2740428291-721650609-345291581-500_Classes\CLSID\{FFF2D28F-E4EE-44D9-8104-8E71556757F6}\localserver32 -> C:\Program Files\Common Files\InstallShield\UpdateService\agent.exe (Macrovision Corporation)

==================== Restore Points =========================

ATTENTION: System Restore is disabled
Could not list restore points
Check "winmgmt" service or repair WMI.


==================== Hosts content: ===============================

(If needed Hosts: directive could be included in the fixlist to reset Hosts.)

2013-06-17 16:03 - 2013-06-17 16:05 - 00000027 ____A C:\WINDOWS\system32\Drivers\etc\hosts

127.0.0.1 localhost

==================== Scheduled Tasks (Whitelisted) =============

(If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.)

Task: C:\WINDOWS\Tasks\Amazon Music Helper.job => C:\Documents and Settings\1\Local Settings\Application Data\Amazon Cloud Player\Amazon Music Helper.exe <==== ATTENTION
Task: C:\WINDOWS\Tasks\Critical Battery Alarm Program.job =>
Task: C:\WINDOWS\Tasks\G2MUpdateTask-S-1-5-21-2740428291-721650609-345291581-1006.job => C:\Program Files\Citrix\GoToMeeting\4062\g2mupdate.exe
Task: C:\WINDOWS\Tasks\G2MUploadTask-S-1-5-21-2740428291-721650609-345291581-1006.job => C:\Program Files\Citrix\GoToMeeting\4062\g2mupload.exe
Task: C:\WINDOWS\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files\Google\Update\GoogleUpdate.exe
Task: C:\WINDOWS\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files\Google\Update\GoogleUpdate.exe
Task: C:\WINDOWS\Tasks\Microsoft Windows XP End of Service Notification Logon.job => C:\WINDOWS\system32\xp_eos.exe
Task: C:\WINDOWS\Tasks\Microsoft Windows XP End of Service Notification Monthly.job => C:\WINDOWS\system32\xp_eos.exe
Task: C:\WINDOWS\Tasks\MP Scheduled Scan.job => C:\Program Files\Windows Defender\MpCmdRun.exe
Task: C:\WINDOWS\Tasks\User_Feed_Synchronization-{F7405781-D735-43C3-BEA3-06C346D0BF27}.job => C:\WINDOWS\system32\msfeedssync.exe

==================== Shortcuts =============================

(The entries could be listed to be restored or removed.)

==================== Loaded Modules (Whitelisted) ==============

2005-08-30 06:54 - 2013-01-02 01:49 - 01292288 _____ () C:\WINDOWS\system32\QUARTZ.dll
2006-05-13 23:23 - 2006-05-13 23:23 - 00138752 _____ () C:\Program Files\7-Zip\7-zip.dll
2004-08-04 16:00 - 2008-04-13 19:11 - 00059904 _____ () C:\WINDOWS\system32\devenum.dll
2004-08-04 16:00 - 2008-04-13 19:11 - 00014336 _____ () C:\WINDOWS\system32\msdmo.dll
2015-12-13 19:24 - 2015-12-04 16:32 - 16573256 _____ () C:\Program Files\Google\Chrome\Application\47.0.2526.80\PepperFlash\pepflashplayer.dll

==================== Alternate Data Streams (Whitelisted) =========

(If an entry is included in the fixlist, only the ADS will be removed.)


==================== Safe Mode (Whitelisted) ===================

(If an entry is included in the fixlist, it will be removed from the registry. The "AlternateShell" value will be restored.)

HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\mbamchameleon => ""="Driver"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys => ""="Driver"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\mbamchameleon => ""="Driver"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\nm => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\nm.sys => ""="Driver"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\Wdf01000.sys => ""="Driver"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Option => "OptionValue"="2"

==================== EXE Association (Whitelisted) ===============

(If an entry is included in the fixlist, the registry item will be restored to default or removed.)


==================== Internet Explorer trusted/restricted ===============

(If an entry is included in the fixlist, it will be removed from the registry.)

IE restricted site: HKU\.DEFAULT\...\007guard.com -> install.007guard.com
IE restricted site: HKU\.DEFAULT\...\008i.com -> 008i.com
IE restricted site: HKU\.DEFAULT\...\008k.com -> www.008k.com
IE restricted site: HKU\.DEFAULT\...\00hq.com -> www.00hq.com
IE restricted site: HKU\.DEFAULT\...\010402.com -> 010402.com
IE restricted site: HKU\.DEFAULT\...\032439.com -> 80gw6ry3i3x3qbrkwhxhw.032439.com
IE restricted site: HKU\.DEFAULT\...\0scan.com -> www.0scan.com
IE restricted site: HKU\.DEFAULT\...\1-2005-search.com -> www.1-2005-search.com
IE restricted site: HKU\.DEFAULT\...\1-domains-registrations.com -> www.1-domains-registrations.com
IE restricted site: HKU\.DEFAULT\...\1000gratisproben.com -> www.1000gratisproben.com
IE restricted site: HKU\.DEFAULT\...\1001namen.com -> www.1001namen.com
IE restricted site: HKU\.DEFAULT\...\100888290cs.com -> mir.100888290cs.com
IE restricted site: HKU\.DEFAULT\...\100sexlinks.com -> www.100sexlinks.com
IE restricted site: HKU\.DEFAULT\...\10sek.com -> www.10sek.com
IE restricted site: HKU\.DEFAULT\...\12-26.net -> user1.12-26.net
IE restricted site: HKU\.DEFAULT\...\12-27.net -> user1.12-27.net
IE restricted site: HKU\.DEFAULT\...\123haustiereundmehr.com -> www.123haustiereundmehr.com
IE restricted site: HKU\.DEFAULT\...\123simsen.com -> www.123simsen.com
IE restricted site: HKU\.DEFAULT\...\123topsearch.com -> www.123topsearch.com
IE restricted site: HKU\.DEFAULT\...\125sms.co.uk -> www.125sms.co.uk

There are 5205 more sites.


==================== Other Areas ============================

(Currently there is no automatic fix for this section.)

HKU\S-1-5-21-2740428291-721650609-345291581-500\Control Panel\Desktop\\Wallpaper -> C:\WINDOWS\Digicode.bmp
DNS Servers: 192.168.0.1

==================== MSCONFIG/TASK MANAGER disabled items ==

(Currently there is no automatic fix for this section.)

MSCONFIG\startupreg: Amazon Cloud Player => "C:\Documents and Settings\1\Local Settings\Application Data\Amazon Cloud Player\Amazon Music Helper.exe"
MSCONFIG\startupreg: APSDaemon => "C:\Program Files\Common Files\Apple\Apple Application Support\APSDaemon.exe"
MSCONFIG\startupreg: BluetoothAuthenticationAgent => rundll32.exe bthprops.cpl,,BluetoothAuthenticationAgent
MSCONFIG\startupreg: ISUSPM Startup => "C:\Program Files\Common Files\InstallShield\UpdateService\ISUSPM.exe" -startup
MSCONFIG\startupreg: iTunesHelper => "C:\Program Files\iTunes\iTunesHelper.exe"
MSCONFIG\startupreg: QuickTime Task => "C:\Program Files\QuickTime\qttask.exe" -atboottime
MSCONFIG\startupreg: RoboForm => "C:\Program Files\Siber Systems\AI RoboForm\RoboTaskBarIcon.exe"
MSCONFIG\startupreg: SunJavaUpdateSched => C:\Program Files\Common Files\Java\Java Update\jusched.exe

==================== FirewallRules (Whitelisted) ===============

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

DomainProfile\AuthorizedApplications: [C:\Documents and Settings\1\Local Settings\Temp\7zS3DF3\setup\hpznui01.exe] => Enabled:hpznui01.exe
DomainProfile\AuthorizedApplications: [C:\Program Files\Hp\Digital Imaging\{68550918-63B5-4762-85CB-3C160AA4B213}\setup\hpznui01.exe] => Enabled:hpznui01.exe
DomainProfile\AuthorizedApplications: [E:\setup\hpznui01.exe] => Enabled:hpznui01.exe
DomainProfile\AuthorizedApplications: [C:\Program Files\Hp\Digital Imaging\bin\hpqtra08.exe] => Enabled:hpqtra08.exe
DomainProfile\AuthorizedApplications: [C:\Program Files\Hp\Digital Imaging\bin\hpqste08.exe] => Enabled:hpqste08.exe
DomainProfile\AuthorizedApplications: [C:\Program Files\Hp\Digital Imaging\bin\hposid01.exe] => Enabled:hposid01.exe
DomainProfile\AuthorizedApplications: [C:\Program Files\Hp\Digital Imaging\bin\hpqkygrp.exe] => Enabled:hpqkygrp.exe
DomainProfile\AuthorizedApplications: [C:\Program Files\Hp\Digital Imaging\bin\hpfcCopy.exe] => Enabled:hpfccopy.exe
DomainProfile\AuthorizedApplications: [C:\Program Files\Hp\Digital Imaging\bin\hpoews01.exe] => Enabled:hpoews01.exe
DomainProfile\AuthorizedApplications: [C:\Program Files\Hp\Digital Imaging\bin\hpiscnapp.exe] => Enabled:hpiscnapp.exe
DomainProfile\AuthorizedApplications: [C:\Program Files\Common Files\HP\Digital Imaging\Bin\hpqPhotoCrm.exe] => Enabled:hpqphotocrm.exe
DomainProfile\AuthorizedApplications: [C:\Program Files\Hp\Digital Imaging\bin\hpqgplgtupl.exe] => Enabled:hpqgplgtupl.exe
DomainProfile\AuthorizedApplications: [C:\Program Files\Hp\Digital Imaging\bin\hpqgpc01.exe] => Enabled:hpqgpc01.exe
DomainProfile\AuthorizedApplications: [C:\Program Files\Hp\HP Software Update\HPWUCli.exe] => Enabled:hpwucli.exe
DomainProfile\AuthorizedApplications: [C:\Program Files\Hp\Digital Imaging\smart web printing\SmartWebPrintExe.exe] => Enabled:smartwebprintexe.exe
DomainProfile\AuthorizedApplications: [C:\Program Files\Hp\Digital Imaging\{2012D762-5DCA-455A-B5FE-EDF79BC93E18}\setup\hpznui01.exe] => Enabled:hpznui01.exe
StandardProfile\AuthorizedApplications: [C:\Documents and Settings\1\Application Data\Sun\Java\Deployment\cache\javaws\http\D12.153.224.167\P80\DMbalicli_alt2\RNjdic-windows.jar\IeEmbed.exe] => Enabled:JDesktop Integration Components binary
StandardProfile\AuthorizedApplications: [C:\WINDOWS\system32\fxsclnt.exe] => Disabled:Microsoft Fax Console
StandardProfile\AuthorizedApplications: [C:\Program Files\Java\jre6\bin\javaw.exe] => Enabled:Java™ Platform SE binary
StandardProfile\AuthorizedApplications: [C:\WINDOWS\Network Diagnostic\xpnetdiag.exe] => Disabled:@xpsp3res.dll,-20000
StandardProfile\AuthorizedApplications: [C:\WINDOWS\system32\sessmgr.exe] => Disabled:@xpsp2res.dll,-22019
StandardProfile\AuthorizedApplications: [C:\Program Files\LimeWire\LimeWire.exe] => Disabled:LimeWire
StandardProfile\AuthorizedApplications: [C:\Program Files\Java\jre7\bin\javaw.exe] => Enabled:Java™ Platform SE binary
StandardProfile\AuthorizedApplications: [C:\Program Files\Common Files\Apple\Apple Application Support\WebKit2WebProcess.exe] => Disabled:WebKit
StandardProfile\AuthorizedApplications: [C:\Program Files\iTunes\iTunes.exe] => Enabled:iTunes
StandardProfile\AuthorizedApplications: [C:\Program Files\Hp\Digital Imaging\{68550918-63B5-4762-85CB-3C160AA4B213}\setup\hpznui01.exe] => Enabled:hpznui01.exe
StandardProfile\AuthorizedApplications: [E:\setup\hpznui01.exe] => Enabled:hpznui01.exe
StandardProfile\AuthorizedApplications: [C:\Program Files\Hp\Digital Imaging\bin\hpqtra08.exe] => Enabled:hpqtra08.exe
StandardProfile\AuthorizedApplications: [C:\Program Files\Hp\Digital Imaging\bin\hpqste08.exe] => Enabled:hpqste08.exe
StandardProfile\AuthorizedApplications: [C:\Program Files\Hp\Digital Imaging\bin\hposid01.exe] => Enabled:hposid01.exe
StandardProfile\AuthorizedApplications: [C:\Program Files\Hp\Digital Imaging\bin\hpqkygrp.exe] => Enabled:hpqkygrp.exe
StandardProfile\AuthorizedApplications: [C:\Program Files\Hp\Digital Imaging\bin\hpfcCopy.exe] => Enabled:hpfccopy.exe
StandardProfile\AuthorizedApplications: [C:\Program Files\Hp\Digital Imaging\bin\hpoews01.exe] => Enabled:hpoews01.exe
StandardProfile\AuthorizedApplications: [C:\Program Files\Hp\Digital Imaging\bin\hpiscnapp.exe] => Enabled:hpiscnapp.exe
StandardProfile\AuthorizedApplications: [C:\Program Files\Common Files\HP\Digital Imaging\Bin\hpqPhotoCrm.exe] => Enabled:hpqphotocrm.exe
StandardProfile\AuthorizedApplications: [C:\Program Files\Hp\Digital Imaging\bin\hpqgplgtupl.exe] => Enabled:hpqgplgtupl.exe
StandardProfile\AuthorizedApplications: [C:\Program Files\Hp\Digital Imaging\bin\hpqgpc01.exe] => Enabled:hpqgpc01.exe
StandardProfile\AuthorizedApplications: [C:\Program Files\Hp\HP Software Update\HPWUCli.exe] => Enabled:hpwucli.exe
StandardProfile\AuthorizedApplications: [C:\Program Files\Hp\Digital Imaging\smart web printing\SmartWebPrintExe.exe] => Enabled:smartwebprintexe.exe
StandardProfile\AuthorizedApplications: [C:\Program Files\Google\Chrome\Application\chrome.exe] => Disabled:Google Chrome
StandardProfile\AuthorizedApplications: [C:\Program Files\Origin Games\Crusader No Remorse\data\Game\DOSBox\DOSBox.exe] => Enabled:Crusader No Remorse
StandardProfile\AuthorizedApplications: [C:\Program Files\Origin Games\Wing Commander III\Game\Game\DOSBox\DOSBox.exe] => Enabled:Wing Commander III
StandardProfile\AuthorizedApplications: [C:\Program Files\Origin Games\SimCity 2000 SE\Game\Game\DOSBox\DOSBox.exe] => Enabled:SimCity 2000 Special Edition
StandardProfile\AuthorizedApplications: [C:\Program Files\Hp\Digital Imaging\{2012D762-5DCA-455A-B5FE-EDF79BC93E18}\setup\hpznui01.exe] => Enabled:hpznui01.exe
StandardProfile\AuthorizedApplications: [C:\Program Files\Java\jre7\bin\jp2launcher.exe] => Enabled:Java™ Platform SE binary
StandardProfile\AuthorizedApplications: [C:\Program Files\E-TRADE Pro\jre\bin\java.exe] => Enabled:Java™ Platform SE binary
DomainProfile\GloballyOpenPorts: [139:TCP] => Enabled:@xpsp2res.dll,-22004
DomainProfile\GloballyOpenPorts: [445:TCP] => Enabled:@xpsp2res.dll,-22005
DomainProfile\GloballyOpenPorts: [137:UDP] => Enabled:@xpsp2res.dll,-22001
DomainProfile\GloballyOpenPorts: [138:UDP] => Enabled:@xpsp2res.dll,-22002
DomainProfile\GloballyOpenPorts: [427:TCP] => :LocalSubNet:Enabled:SLP_Port(427)_TCP
DomainProfile\GloballyOpenPorts: [427:UDP] => :LocalSubNet:Enabled:SLP_Port(427)_UDP
StandardProfile\GloballyOpenPorts: [1900:UDP] => :LocalSubNet:Enabled:@xpsp2res.dll,-22007
StandardProfile\GloballyOpenPorts: [2869:TCP] => :LocalSubNet:Enabled:@xpsp2res.dll,-22008
StandardProfile\GloballyOpenPorts: [139:TCP] => :LocalSubNet:Enabled:@xpsp2res.dll,-22004
StandardProfile\GloballyOpenPorts: [445:TCP] => :LocalSubNet:Enabled:@xpsp2res.dll,-22005
StandardProfile\GloballyOpenPorts: [137:UDP] => :LocalSubNet:Enabled:@xpsp2res.dll,-22001
StandardProfile\GloballyOpenPorts: [138:UDP] => :LocalSubNet:Enabled:@xpsp2res.dll,-22002
StandardProfile\GloballyOpenPorts: [427:TCP] => :LocalSubNet:Enabled:SLP_Port(427)_TCP
StandardProfile\GloballyOpenPorts: [427:UDP] => :LocalSubNet:Enabled:SLP_Port(427)_UDP
StandardProfile\GloballyOpenPorts: [5985:TCP] => Disabled:Windows Remote Management

==================== Faulty Device Manager Devices =============

Could not list Devices. Check "winmgmt" service or repair WMI.


==================== Event log errors: =========================

Application errors:
==================
Error: (12/16/2015 05:39:28 PM) (Source: MsiInstaller) (EventID: 1008) (User: YOUR-09DEDAFE33)
Description: The installation of C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\{6E43D366-DEF1-44DB-B4C0-D06956B8C9D8}\ki69.msi is not permitted due to an error in software restriction policy processing. The object cannot be trusted.

Error: (12/16/2015 05:19:39 PM) (Source: MsiInstaller) (EventID: 1008) (User: YOUR-09DEDAFE33)
Description: The installation of C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\{947CBB51-1F1B-415F-BED9-F4B90F10953C}\ki7.msi is not permitted due to an error in software restriction policy processing. The object cannot be trusted.

Error: (12/16/2015 04:59:50 PM) (Source: MsiInstaller) (EventID: 1008) (User: YOUR-09DEDAFE33)
Description: The installation of C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\{751E8B0B-8F70-4BC0-8435-8639E050D487}\ki295.msi is not permitted due to an error in software restriction policy processing. The object cannot be trusted.

Error: (12/16/2015 09:08:28 AM) (Source: crypt32) (EventID: 8) (User: )
Description: Failed auto update retrieval of third-party root list sequence number from: <http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootseq.txt> with error: This network connection does not exist.

Error: (12/16/2015 09:08:28 AM) (Source: crypt32) (EventID: 8) (User: )
Description: Failed auto update retrieval of third-party root list sequence number from: <http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootseq.txt> with error: This network connection does not exist.

Error: (12/16/2015 09:08:20 AM) (Source: crypt32) (EventID: 8) (User: )
Description: Failed auto update retrieval of third-party root list sequence number from: <http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootseq.txt> with error: This network connection does not exist.

Error: (12/16/2015 09:08:20 AM) (Source: crypt32) (EventID: 8) (User: )
Description: Failed auto update retrieval of third-party root list sequence number from: <http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootseq.txt> with error: The server name or address could not be resolved

Error: (12/15/2015 04:26:40 PM) (Source: EventSystem) (EventID: 4609) (User: )
Description: The COM+ Event System detected a bad return code during its internal processing. HRESULT was 80070422 from line 44 of d:\comxp_sp3\com\com1x\src\events\tier1\eventsystemobj.cpp. Please contact Microsoft Product Support Services to report this error.

Error: (12/15/2015 04:26:40 PM) (Source: EventSystem) (EventID: 4609) (User: )
Description: The COM+ Event System detected a bad return code during its internal processing. HRESULT was 80070422 from line 44 of d:\comxp_sp3\com\com1x\src\events\tier1\eventsystemobj.cpp. Please contact Microsoft Product Support Services to report this error.

Error: (12/15/2015 12:57:42 PM) (Source: MPSampleSubmission) (EventID: 5000) (User: )
Description: EventType mptelemetry, P1 8007043c, P2 updateservicemanager-_get_services, P3 fallbackcheck, P4 1.1.1593.0, P5 mpsigdwn.dll, P6 1.1.1593.0, P7 windows defender, P8 NIL, P9 mptelemetry0, P10 mptelemetry1.


System errors:
=============
Error: (12/21/2015 05:13:04 PM) (Source: DCOM) (EventID: 10005) (User: YOUR-09DEDAFE33)
Description: DCOM got error "%%1058" attempting to start the service winmgmt with arguments ""
in order to run the server:
{8BC3F05E-D86B-11D0-A075-00C04FB68820}

Error: (12/21/2015 05:11:55 PM) (Source: DCOM) (EventID: 10005) (User: YOUR-09DEDAFE33)
Description: DCOM got error "%%1058" attempting to start the service winmgmt with arguments ""
in order to run the server:
{8BC3F05E-D86B-11D0-A075-00C04FB68820}

Error: (12/21/2015 05:11:53 PM) (Source: DCOM) (EventID: 10005) (User: YOUR-09DEDAFE33)
Description: DCOM got error "%%1058" attempting to start the service winmgmt with arguments ""
in order to run the server:
{8BC3F05E-D86B-11D0-A075-00C04FB68820}

Error: (12/21/2015 05:11:53 PM) (Source: DCOM) (EventID: 10005) (User: YOUR-09DEDAFE33)
Description: DCOM got error "%%1058" attempting to start the service winmgmt with arguments ""
in order to run the server:
{8BC3F05E-D86B-11D0-A075-00C04FB68820}

Error: (12/21/2015 05:11:53 PM) (Source: DCOM) (EventID: 10005) (User: YOUR-09DEDAFE33)
Description: DCOM got error "%%1058" attempting to start the service winmgmt with arguments ""
in order to run the server:
{8BC3F05E-D86B-11D0-A075-00C04FB68820}

Error: (12/21/2015 05:06:26 PM) (Source: DCOM) (EventID: 10005) (User: YOUR-09DEDAFE33)
Description: DCOM got error "%%1058" attempting to start the service winmgmt with arguments ""
in order to run the server:
{8BC3F05E-D86B-11D0-A075-00C04FB68820}

Error: (12/21/2015 05:06:26 PM) (Source: DCOM) (EventID: 10005) (User: YOUR-09DEDAFE33)
Description: DCOM got error "%%1058" attempting to start the service winmgmt with arguments ""
in order to run the server:
{8BC3F05E-D86B-11D0-A075-00C04FB68820}

Error: (12/21/2015 05:05:50 PM) (Source: DCOM) (EventID: 10005) (User: YOUR-09DEDAFE33)
Description: DCOM got error "%%1058" attempting to start the service StiSvc with arguments ""
in order to run the server:
{A1F4E726-8CF1-11D1-BF92-0060081ED811}

Error: (12/21/2015 03:49:14 PM) (Source: DCOM) (EventID: 10005) (User: NT AUTHORITY)
Description: DCOM got error "%%1058" attempting to start the service winmgmt with arguments ""
in order to run the server:
{8BC3F05E-D86B-11D0-A075-00C04FB68820}

Error: (12/21/2015 03:49:09 PM) (Source: DCOM) (EventID: 10005) (User: NT AUTHORITY)
Description: DCOM got error "%%1058" attempting to start the service winmgmt with arguments ""
in order to run the server:
{8BC3F05E-D86B-11D0-A075-00C04FB68820}


==================== Memory info ===========================

Processor: Intel® Celeron® M CPU 410 @ 1.46GHz
Percentage of memory in use: 50%
Total physical RAM: 2038.05 MB
Available physical RAM: 1016.85 MB
Total Virtual: 1887.73 MB
Available Virtual: 992.18 MB

==================== Drives ================================

Drive c: () (Fixed) (Total:47.86 GB) (Free:10.99 GB) NTFS ==>[drive with boot components (Windows XP)]
Drive d: (PRESARIO_RP) (Fixed) (Total:8.01 GB) (Free:0.96 GB) FAT32 ==>[drive with boot components (Windows XP)]

==================== MBR & Partition Table ==================

========================================================
Disk: 0 (Size: 55.9 GB) (Disk ID: 4D384D37)
Partition 1: (Active) - (Size=47.9 GB) - (Type=07 NTFS)
Partition 2: (Not Active) - (Size=8 GB) - (Type=0C)

==================== End of Addition.txt ============================

Edited by Oh My!, 25 December 2015 - 10:41 AM.


BC AdBot (Login to Remove)

 


#2 Oh My!

Oh My!

    Adware and Spyware and Malware.....


  • Malware Response Instructor
  • 37,769 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:California
  • Local time:05:01 AM

Posted 25 December 2015 - 11:00 AM

Greetings peaksmm and :welcome: to BleepingComputer's Virus/Trojan/Spyware/Malware Removal forum.

My name is Oh My! and I am here to help you! Now that we are "friends" please call me Gary.

If you would allow me to call you by your first name I would prefer to do that.

===================================================

Ground Rules:
  • First, I would like to inform you that most of us here at Bleeping Computer offer our expert assistance out of the goodness of our hearts. Please try to match our commitment to you with your patience toward us. If this was easy we would never have met.
  • Please do not run any tools or take any steps other than those I will provide for you while we work on your computer together. I need to be certain about the state of your computer in order to provide appropriate and effective steps for you to take. Most often "well intentioned" (and usually panic driven!) independent efforts can make things much worse for both of us. If at any point you would prefer to take your own steps please let me know, I will not be offended. I would be happy to focus on the many others who are waiting in line for assistance.
  • Please perform all steps in the order they are listed in each set of instructions. Some steps may be a bit complicated. If things are not clear, be sure to stop and let me know. We need to work on this together with confidence.
  • Please copy and paste all logs into your post unless directed otherwise. Please do not re-run any programs I suggest. If you encounter problems simply stop and tell me.
  • When you post your reply, use the Replytopic.jpg button instead.
  • In the upper right hand corner of the topic you will see the Followtopic.jpg button. Click on this then choose Immediate E-Mail notification and then Proceed and you will be sent an email once I have posted a response.
  • If you do not reply to your topic after 5 days we assume it has been abandoned and I will close it.
  • When your computer is clean I will alert you of such. I will also provide for you detailed information about how you can combat future infections.
  • I would like to remind you to make no further changes to your computer unless I direct you to do so.
===================================================

Now that I am assisting you, you can expect that I will be very responsive to your situation. If you are able, I would request you check this thread at least once per day so that we can try to resolve your issues effectively and efficiently. If you are going to be delayed please be considerate and post that information so that I know you are still with me. Unfortunately, there are many people waiting to be assisted and not enough of us at BleepingComputer to go around. I appreciate your understanding and diligence.

Thank you for your patience thus far.

Please do this.

===================================================

Farbar's Recovery Scan Tool - Run Fix in Normal or Safe Mode

--------------------
  • Press the Windows key Windows_Logo_key.gif + r on your keyboard at the same time. Type in notepad and press Enter
  • Please copy and paste the contents of the below code box into the open notepad and save it to your desktop (<<<Important) as fixlist.txt
CreateRestorePoint:
CloseProcesses:
HKLM\SOFTWARE\Policies\Microsoft\Internet Explorer: Restriction <======= ATTENTION
HKU\S-1-5-21-2740428291-721650609-345291581-500\SOFTWARE\Policies\Microsoft\Internet Explorer: Restriction <======= ATTENTION
SearchScopes: HKLM -> DefaultScope value is missing
BHO: No Name -> {5CA3D70E-1895-11CF-8E15-001234567890} -> No File
BHO: No Name -> {A8F38D8D-E480-4D52-B7A2-731BB6995FDD} -> __BHODemonDisabled => No File
Toolbar: HKU\S-1-5-21-2740428291-721650609-345291581-500 -> No Name - {C4069E3A-68F1-403E-B40E-20066696354B} - No File
DPF: {17492023-C23A-453E-A040-C7C580BBF700} hxxp://go.microsoft.com/fwlink/?linkid=39204
DPF: {7530BFB8-7293-4D34-9923-61A11451AFC5} hxxp://download.eset.com/special/eos/OnlineScanner.cab
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} hxxp://java.sun.com/update/1.7.0/jinstall-1_7_0_45-windows-i586.cab
DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} hxxp://fpdownload.macromedia.com/get/flashplayer/current/ultrashim.cab
DPF: {CAFEEFAC-0015-0000-0006-ABCDEFFEDCBA}
DPF: {CAFEEFAC-0015-0000-0015-ABCDEFFEDCBA}
DPF: {CAFEEFAC-0016-0000-0010-ABCDEFFEDCBA}
DPF: {CAFEEFAC-0017-0000-0025-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.7.0/jinstall-1_7_0_25-windows-i586.cab
DPF: {CAFEEFAC-0017-0000-0045-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.7.0/jinstall-1_7_0_45-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.7.0/jinstall-1_7_0_45-windows-i586.cab
DPF: {E06E2E99-0AA1-11D4-ABA6-0060082AA75C}
DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} hxxp://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
S3 catchme; \??\C:\ComboFix\catchme.sys [X]
S3 cpuz138; \??\C:\DOCUME~1\1\LOCALS~1\Temp\cpuz138\cpuz138_x32.sys [X]
S3 motccgp; system32\DRIVERS\motccgp.sys [X]
S3 motccgpfl; system32\DRIVERS\motccgpfl.sys [X]
S3 MotDev; system32\DRIVERS\motodrv.sys [X]
S3 motmodem; system32\DRIVERS\motmodem.sys [X]
U3 TlntSvr; no ImagePath
2015-12-08 15:28 - 2015-12-08 15:29 - 00000000 ___HD C:\Documents and Settings\All Users\Application Data\{FB62659C-5547-4284-846F-24B4EEDF86F7}
Task: C:\WINDOWS\Tasks\Critical Battery Alarm Program.job =>
CMD: ipconfig /flushdns
CMD: netsh winsock reset
CMD: ipconfig /release
CMD: ipconfig /renew
emptytemp:
  • Launch FRST and press the Fix button just once and wait, the program will automatically launch fixlist.txt.
  • The tool will create a log on the desktop called Fixlog.txt. Please copy and paste the contents of the file in your reply.
===================================================

ComboFix Windows XP

--------------------

For a more detailed explanation on running Combofix and the prompts you will be following please see here.
  • Please download ComboFix from one of these locations and save it to your desktop:

Bleepingcomputer

ForoSpyware

  • Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools. (Click on this link to see a list of programs that should be disabled. The list is not all inclusive.)
  • Note: If after disabling Combofix warns you an Antivirus program is still running ignore the warning and run Combofix.
  • Double click on Combofix.exe and follow the prompts.
  • As part of it's process, ComboFix will check to see if the Microsoft Windows Recovery Console is installed. With malware infections being as they are today, it's strongly recommended to have this pre-installed on your machine before doing any malware removal. It will allow you to boot up into a special recovery/repair mode that will allow us to more easily help you should your computer have a problem after an attempted removal of malware.
  • Follow the prompts to allow ComboFix to download and install the Microsoft Windows Recovery Console, and when prompted, agree to the End-User License Agreement to install the Microsoft Windows Recovery Console.
  • Note: If the Microsoft Windows Recovery Console is already installed, or if you are running Vista/Windows 7, ComboFix will skip the below Recovery Console pop ups and continue its malware removal procedure.

Query_RC.gif

  • Once the Microsoft Windows Recovery Console is installed using ComboFix, you should see the following message:

RC_successful.gif

  • Click on Yes, to continue scanning for malware
----------

Note #1: Often times it may appear as if ComboFix has stopped working. To verify it is still running please do one of the following below. If, based on the below, you have concluded ComboFix has stopped running please stop and advise me.
  • Check your computer clock. If it is still running then so is ComboFix
  • Open Task Manager and select the Applications Tab. If the status of AutoScan is Running, then ComboFix is running
  • Open Task Manager and select the Processes Tab. Under Image Name look for files ending in .3xe. If there are fluctuating numbers under CPU and Mem Usage then ComboFix is running
Note #2: If you receive the following error "Illegal operation attempted on a registery key that has been marked for deletion" please just restart your computer to resolve this issue

----------

If Combofix fails to run properly using the above instructions please attempt the following:
  • Right click on the Combofix icon on your desktop and select Delete
  • Download a new copy but rename it to freshcopy.exe first, then save it to your desktop
  • Now download RKill.exe (or RKill renamed as iExplore.exe if the first one doesn't work properly) and save it to your desktop
  • Restart your computer in Safe Mode
  • Right click on RKill (or iExplore) and select Run as Administrator. If you are using Windows XP simply double click the icon
  • A black DOS screen should flash and disappear. If not, try to launch the program with the second file. If neither works please stop and let me know
  • When RKill is finished running you will be presented with a text file and a copy will be saved on your desktop. Copy and paste the contents of this report in your reply
  • Do not reboot your computer
  • Double click the freshcopy.exe icon (renamed Combofix file)
  • When finished, it will produce a log. Please copy and paste the C:\Combofix.txt log information in your next reply
  • If you disabled your antivirus please enable it again. If you uninstalled it please wait for instructions to reinstall it
===================================================

System Summary Information

--------------------
  • Press the windows key Windows_Logo_key.gif + r on your keyboard at the same time
  • Type msinfo32 and press Enter
  • Left click on System Summary
  • Click File, Save, and name the file Summary
  • Zip and attach the file to your reply
===================================================

Things I would like to see in your next reply. Please be sure to copy and paste any requested log information unless you are asked to attach it. :thumbsup2:
  • Fixlog
  • Combofix log
  • System Summary Information
  • Update on computer performance

Gary
 
If I do not reply within 24 hours please send me a Personal Message.

"Lord, to whom would we go? You have the words that give eternal life. We believe, and we know you are the Holy One of God."

#3 peaksmm

peaksmm
  • Topic Starter

  • Members
  • 32 posts
  • OFFLINE
  •  
  • Local time:07:01 AM

Posted 26 December 2015 - 03:34 PM

Hi Gary. Thank you for responding to my request for help. You may call me Tom. I was able complete your instructions using FRST and Combofix but not msinfo32. Their logs will follow this message. Msinfo32 made the hard drive spin a bit but did not display a log or summary screen. Presently, my computer is freed from all those excess processes,no more PresentationHost, MSIE, Cmd, etc., however wireless network connection, file search functions do not work stating that I may need to run setup. There may be other functions not operating. I am writing you from another system with an operating internet connection. Please advise me as to how to proceed. Thank you.


Fix result of Farbar Recovery Scan Tool (x86) Version:20-12-2015
Ran by Administrator (2015-12-26 13:08:13) Run:1
Running from C:\Documents and Settings\Administrator\Desktop
Loaded Profiles: Administrator (Available Profiles: 1 & Administrator)
Boot Mode: Safe Mode (with Networking)

==============================================

fixlist content:
*****************
CreateRestorePoint:
CloseProcesses:
HKLM\SOFTWARE\Policies\Microsoft\Internet Explorer: Restriction <======= ATTENTION
HKU\S-1-5-21-2740428291-721650609-345291581-500\SOFTWARE\Policies\Microsoft\Internet Explorer: Restriction <======= ATTENTION
SearchScopes: HKLM -> DefaultScope value is missing
BHO: No Name -> {5CA3D70E-1895-11CF-8E15-001234567890} -> No File
BHO: No Name -> {A8F38D8D-E480-4D52-B7A2-731BB6995FDD} -> __BHODemonDisabled => No File
Toolbar: HKU\S-1-5-21-2740428291-721650609-345291581-500 -> No Name - {C4069E3A-68F1-403E-B40E-20066696354B} - No File
DPF: {17492023-C23A-453E-A040-C7C580BBF700} hxxp://go.microsoft.com/fwlink/?linkid=39204
DPF: {7530BFB8-7293-4D34-9923-61A11451AFC5} hxxp://download.eset.com/special/eos/OnlineScanner.cab
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} hxxp://java.sun.com/update/1.7.0/jinstall-1_7_0_45-windows-i586.cab
DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} hxxp://fpdownload.macromedia.com/get/flashplayer/current/ultrashim.cab
DPF: {CAFEEFAC-0015-0000-0006-ABCDEFFEDCBA}
DPF: {CAFEEFAC-0015-0000-0015-ABCDEFFEDCBA}
DPF: {CAFEEFAC-0016-0000-0010-ABCDEFFEDCBA}
DPF: {CAFEEFAC-0017-0000-0025-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.7.0/jinstall-1_7_0_25-windows-i586.cab
DPF: {CAFEEFAC-0017-0000-0045-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.7.0/jinstall-1_7_0_45-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.7.0/jinstall-1_7_0_45-windows-i586.cab
DPF: {E06E2E99-0AA1-11D4-ABA6-0060082AA75C}
DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} hxxp://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
S3 catchme; \??\C:\ComboFix\catchme.sys [X]
S3 cpuz138; \??\C:\DOCUME~1\1\LOCALS~1\Temp\cpuz138\cpuz138_x32.sys [X]
S3 motccgp; system32\DRIVERS\motccgp.sys [X]
S3 motccgpfl; system32\DRIVERS\motccgpfl.sys [X]
S3 MotDev; system32\DRIVERS\motodrv.sys [X]
S3 motmodem; system32\DRIVERS\motmodem.sys [X]
U3 TlntSvr; no ImagePath
2015-12-08 15:28 - 2015-12-08 15:29 - 00000000 ___HD C:\Documents and Settings\All Users\Application Data\{FB62659C-5547-4284-846F-24B4EEDF86F7}
Task: C:\WINDOWS\Tasks\Critical Battery Alarm Program.job =>
CMD: ipconfig /flushdns
CMD: netsh winsock reset
CMD: ipconfig /release
CMD: ipconfig /renew
emptytemp:
*****************

Error: Restore point can only be created in normal mode.
Processes closed successfully.
"HKLM\SOFTWARE\Policies\Microsoft\Internet Explorer" => key removed successfully.
"HKU\S-1-5-21-2740428291-721650609-345291581-500\SOFTWARE\Policies\Microsoft\Internet Explorer" => key removed successfully.
HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\DefaultScope => value restored successfully
"HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{5CA3D70E-1895-11CF-8E15-001234567890}" => key removed successfully.

#4 peaksmm

peaksmm
  • Topic Starter

  • Members
  • 32 posts
  • OFFLINE
  •  
  • Local time:07:01 AM

Posted 26 December 2015 - 03:47 PM

And.....

ComboFix 15-12-24.01 - Administrator 12/26/2015 13:15:05.2.1 - x86 NETWORK
Running from: c:\documents and settings\Administrator\Desktop\ComboFix.exe
.
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\windows\$msi31uninstall_kb893803v2$
c:\windows\$msi31uninstall_kb893803v2$\msi.dll
c:\windows\$msi31uninstall_kb893803v2$\msiexec.exe
c:\windows\$msi31uninstall_kb893803v2$\msihnd.dll
c:\windows\$msi31uninstall_kb893803v2$\msimsg.dll
c:\windows\$msi31uninstall_kb893803v2$\msisip.dll
c:\windows\$msi31uninstall_kb893803v2$\reg00013
c:\windows\$msi31uninstall_kb893803v2$\reg00014
c:\windows\$msi31uninstall_kb893803v2$\reg00015
c:\windows\$msi31uninstall_kb893803v2$\reg00016
c:\windows\$msi31uninstall_kb893803v2$\reg00017
c:\windows\$msi31uninstall_kb893803v2$\reg00018
c:\windows\$msi31uninstall_kb893803v2$\reg00019
c:\windows\$msi31uninstall_kb893803v2$\reg00020
c:\windows\$msi31uninstall_kb893803v2$\reg00021
c:\windows\$msi31uninstall_kb893803v2$\reg00022
c:\windows\$msi31uninstall_kb893803v2$\reg00023
c:\windows\$msi31uninstall_kb893803v2$\reg00024
c:\windows\$msi31uninstall_kb893803v2$\reg00025
c:\windows\$msi31uninstall_kb893803v2$\reg00026
c:\windows\$msi31uninstall_kb893803v2$\reg00027
c:\windows\$msi31uninstall_kb893803v2$\reg00028
c:\windows\$msi31uninstall_kb893803v2$\reg00029
c:\windows\$msi31uninstall_kb893803v2$\reg00030
c:\windows\$msi31uninstall_kb893803v2$\reg00031
c:\windows\$msi31uninstall_kb893803v2$\reg00032
c:\windows\$msi31uninstall_kb893803v2$\reg00033
c:\windows\$msi31uninstall_kb893803v2$\reg00034
c:\windows\$msi31uninstall_kb893803v2$\reg00035
c:\windows\$msi31uninstall_kb893803v2$\reg00036
c:\windows\$msi31uninstall_kb893803v2$\reg00037
c:\windows\$msi31uninstall_kb893803v2$\reg00038
c:\windows\$msi31uninstall_kb893803v2$\reg00039
c:\windows\$msi31uninstall_kb893803v2$\reg00040
c:\windows\$msi31uninstall_kb893803v2$\reg00041
c:\windows\$msi31uninstall_kb893803v2$\reg00042
c:\windows\$msi31uninstall_kb893803v2$\reg00043
c:\windows\$msi31uninstall_kb893803v2$\reg00044
c:\windows\$msi31uninstall_kb893803v2$\reg00045
c:\windows\$msi31uninstall_kb893803v2$\reg00046
c:\windows\$msi31uninstall_kb893803v2$\reg00047
c:\windows\$msi31uninstall_kb893803v2$\reg00048
c:\windows\$msi31uninstall_kb893803v2$\reg00051
c:\windows\$msi31uninstall_kb893803v2$\reg00052
c:\windows\$msi31uninstall_kb893803v2$\reg00053
c:\windows\$msi31uninstall_kb893803v2$\reg00054
c:\windows\$msi31uninstall_kb893803v2$\reg00055
c:\windows\$msi31uninstall_kb893803v2$\reg00056
c:\windows\$msi31uninstall_kb893803v2$\reg00057
c:\windows\$msi31uninstall_kb893803v2$\reg00058
c:\windows\$msi31uninstall_kb893803v2$\reg00059
c:\windows\$msi31uninstall_kb893803v2$\reg00060
c:\windows\$msi31uninstall_kb893803v2$\reg00061
c:\windows\$msi31uninstall_kb893803v2$\reg00062
c:\windows\$msi31uninstall_kb893803v2$\reg00063
c:\windows\$msi31uninstall_kb893803v2$\reg00064
c:\windows\$msi31uninstall_kb893803v2$\reg00065
c:\windows\$msi31uninstall_kb893803v2$\reg00066
c:\windows\$msi31uninstall_kb893803v2$\reg00067
c:\windows\$msi31uninstall_kb893803v2$\reg00068
c:\windows\$msi31uninstall_kb893803v2$\reg00069
c:\windows\$msi31uninstall_kb893803v2$\reg00070
c:\windows\$msi31uninstall_kb893803v2$\reg00071
c:\windows\$msi31uninstall_kb893803v2$\reg00072
c:\windows\$msi31uninstall_kb893803v2$\reg00073
c:\windows\$msi31uninstall_kb893803v2$\reg00074
c:\windows\$msi31uninstall_kb893803v2$\reg00075
c:\windows\$msi31uninstall_kb893803v2$\reg00076
c:\windows\$msi31uninstall_kb893803v2$\reg00077
c:\windows\$msi31uninstall_kb893803v2$\reg00078
c:\windows\$msi31uninstall_kb893803v2$\reg00079
c:\windows\$msi31uninstall_kb893803v2$\reg00080
c:\windows\$msi31uninstall_kb893803v2$\reg00081
c:\windows\$msi31uninstall_kb893803v2$\reg00082
c:\windows\$msi31uninstall_kb893803v2$\reg00083
c:\windows\$msi31uninstall_kb893803v2$\reg00084
c:\windows\$msi31uninstall_kb893803v2$\reg00085
c:\windows\$msi31uninstall_kb893803v2$\reg00086
c:\windows\$msi31uninstall_kb893803v2$\reg00087
c:\windows\$msi31uninstall_kb893803v2$\reg00088
c:\windows\$msi31uninstall_kb893803v2$\reg00089
c:\windows\$msi31uninstall_kb893803v2$\reg00090
c:\windows\$msi31uninstall_kb893803v2$\reg00091
c:\windows\$msi31uninstall_kb893803v2$\reg00092
c:\windows\$msi31uninstall_kb893803v2$\reg00093
c:\windows\$msi31uninstall_kb893803v2$\reg00094
c:\windows\$msi31uninstall_kb893803v2$\reg00095
c:\windows\$msi31uninstall_kb893803v2$\reg00096
c:\windows\$msi31uninstall_kb893803v2$\reg00097
c:\windows\$msi31uninstall_kb893803v2$\reg00098
c:\windows\$msi31uninstall_kb893803v2$\reg00099
c:\windows\$msi31uninstall_kb893803v2$\reg00100
c:\windows\$msi31uninstall_kb893803v2$\reg00101
c:\windows\$msi31uninstall_kb893803v2$\reg00102
c:\windows\$msi31uninstall_kb893803v2$\reg00103
c:\windows\$msi31uninstall_kb893803v2$\reg00104
c:\windows\$msi31uninstall_kb893803v2$\reg00105
c:\windows\$msi31uninstall_kb893803v2$\reg00106
c:\windows\$msi31uninstall_kb893803v2$\reg00107
c:\windows\$msi31uninstall_kb893803v2$\reg00108
c:\windows\$msi31uninstall_kb893803v2$\reg00109
c:\windows\$msi31uninstall_kb893803v2$\reg00110
c:\windows\$msi31uninstall_kb893803v2$\reg00111
c:\windows\$msi31uninstall_kb893803v2$\reg00112
c:\windows\$msi31uninstall_kb893803v2$\reg00113
c:\windows\$msi31uninstall_kb893803v2$\reg00114
c:\windows\$msi31uninstall_kb893803v2$\reg00115
c:\windows\$msi31uninstall_kb893803v2$\reg00116
c:\windows\$msi31uninstall_kb893803v2$\spuninst\spuninst.exe
c:\windows\$msi31uninstall_kb893803v2$\spuninst\spuninst.inf
c:\windows\$msi31uninstall_kb893803v2$\spuninst\spuninst.txt
c:\windows\$msi31uninstall_kb893803v2$\spuninst\updspapi.dll
c:\windows\system32\drivers\etc\hosts.ics
.
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
-------\Legacy_WINRING0_1_0_1
-------\Service_WinRing0_1_0_1
.
.
((((((((((((((((((((((((( Files Created from 2015-11-26 to 2015-12-26 )))))))))))))))))))))))))))))))
.
.
2015-12-21 22:09 . 2015-12-26 18:08 -------- d-----w- C:\FRST
2015-12-21 18:29 . 2015-12-21 18:29 -------- d-----w- c:\documents and settings\Administrator\Local Settings\Application Data\Deployment
2015-12-17 01:09 . 2015-12-17 01:09 -------- d-----w- c:\documents and settings\Administrator\Local Settings\Application Data\Sun
2015-12-16 21:53 . 2015-12-21 22:24 -------- d-----w- c:\documents and settings\All Users\Kaspersky Lab Setup Files
2015-12-16 18:06 . 2015-12-16 18:06 62576 ----a-w- c:\documents and settings\All Users\Application Data\Microsoft\Windows Defender\Definition Updates\{349231DF-9815-4E9F-AADF-C978A22B744C}\offreg.1244.dll
2015-12-15 19:20 . 2015-12-15 19:20 -------- d-----w- c:\program files\ESET
2015-12-14 20:16 . 2015-12-17 02:18 -------- d-----w- c:\program files\trend micro
2015-12-14 20:16 . 2015-12-14 20:17 -------- d-----w- C:\rsit
2015-12-14 17:21 . 2015-12-14 17:21 -------- d-----w- c:\documents and settings\All Users\Application Data\Sophos
2015-12-14 17:20 . 2015-12-14 17:20 -------- d-----w- c:\program files\Sophos
2015-12-14 16:40 . 2015-12-15 22:57 -------- d-----w- C:\AdwCleaner
2015-12-14 15:54 . 2015-12-17 01:26 -------- d-----w- c:\documents and settings\All Users\Application Data\Malwarebytes' Anti-Malware (portable)
2015-12-14 14:27 . 2015-12-17 00:51 170200 ----a-w- c:\windows\system32\drivers\MBAMSwissArmy.sys
2015-12-14 14:24 . 2015-12-17 00:51 121560 ----a-w- c:\windows\system32\drivers\mbamchameleon.sys
2015-12-14 14:24 . 2015-12-14 14:24 -------- d-----w- c:\program files\Malwarebytes Anti-Malware
2015-12-14 14:24 . 2015-10-05 14:50 23256 ----a-w- c:\windows\system32\drivers\mbam.sys
2015-12-14 01:17 . 2015-10-29 09:46 8991856 ----a-w- c:\documents and settings\All Users\Application Data\Microsoft\Windows Defender\Definition Updates\{349231DF-9815-4E9F-AADF-C978A22B744C}\mpengine.dll
2015-12-08 20:28 . 2015-12-08 20:29 -------- d--h--w- c:\documents and settings\All Users\Application Data\{FB62659C-5547-4284-846F-24B4EEDF86F7}
2015-12-03 07:41 . 2015-12-03 07:41 -------- d-----w- c:\documents and settings\All Users\Application Data\RoboForm
2015-12-01 06:31 . 2005-05-26 20:34 2297552 ----a-w- c:\windows\system32\d3dx9_26.dll
2015-12-01 06:26 . 2015-12-16 21:56 -------- d-----w- c:\windows\Logs
2015-12-01 06:25 . 2015-12-01 06:25 -------- d-----w- c:\program files\SiSoftware
2015-11-29 06:13 . 2015-12-01 05:49 -------- d-----w- c:\program files\Setfsb
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2015-12-02 18:25 . 2009-11-03 10:01 247976 ------w- c:\windows\system32\MpSigStub.exe
2015-11-15 23:52 . 2012-10-06 21:05 780488 ----a-w- c:\windows\system32\FlashPlayerApp.exe
2015-11-15 23:52 . 2012-10-06 21:05 142536 ----a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
2015-10-29 09:46 . 2006-11-04 08:52 8991856 ----a-w- c:\documents and settings\All Users\Application Data\Microsoft\Windows Defender\Definition Updates\Backup\mpengine.dll
2015-09-28 04:56 . 2015-09-28 04:56 19375304 ----a-w- c:\windows\system32\FlashPlayerInstaller.exe
.
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2010-09-08 421888]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SynTPStart"="c:\program files\Synaptics\SynTP\SynTPStart.exe" [2007-09-15 102400]
"Cpqset"="c:\program files\HPQ\Default Settings\cpqset.exe" [2006-02-22 40960]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2010-09-08 421888]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\WgaLogon]
[BU]
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\12144754.sys]
@=""
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\hitmanpro37]
@=""
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\hitmanpro37.sys]
@=""
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\HitmanPro37Crusader]
@=""
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\HitmanPro37CrusaderBoot]
@=""
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\mbamchameleon]
@="Driver"
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys]
@="Driver"
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WinDefend]
@="Service"
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Amazon Cloud Player]
2014-01-14 19:46 3140608 ----a-w- c:\documents and settings\1\Local Settings\Application Data\Amazon Cloud Player\Amazon Music Helper.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\APSDaemon]
2011-09-27 12:22 59240 ----a-w- c:\program files\Common Files\Apple\Apple Application Support\APSDaemon.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\BluetoothAuthenticationAgent]
2008-04-14 00:12 110592 ----a-w- c:\windows\system32\bthprops.cpl
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ISUSPM Startup]
2005-08-11 23:30 249856 ----a-w- c:\program files\Common Files\InstallShield\UpdateService\ISUSPM.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\iTunesHelper]
2010-09-24 06:10 421160 ----a-w- c:\program files\iTunes\iTunesHelper.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
2010-09-08 16:17 421888 ----a-w- c:\program files\QuickTime\QTTask.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
2014-12-18 23:06 271744 ----a-w- c:\program files\Common Files\Java\Java Update\jusched.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"Themes"=2 (0x2)
"iPod Service"=3 (0x3)
"FastUserSwitchingCompatibility"=3 (0x3)
"Apple Mobile Device"=2 (0x2)
"BthServ"=2 (0x2)
"AppMgmt"=3 (0x3)
"ALG"=3 (0x3)
"SysmonLog"=3 (0x3)
"xmlprov"=3 (0x3)
"Nla"=3 (0x3)
"mnmsrvc"=3 (0x3)
"Netlogon"=3 (0x3)
"SwPrv"=3 (0x3)
"dmadmin"=3 (0x3)
"dmserver"=3 (0x3)
"CiSvc"=3 (0x3)
"helpsvc"=2 (0x2)
"HidServ"=2 (0x2)
"MSDTC"=3 (0x3)
"TrkWks"=2 (0x2)
"ClipSrv"=3 (0x3)
"COMSysApp"=3 (0x3)
"EventSystem"=3 (0x3)
"Dot3svc"=3 (0x3)
"winmgmt"=2 (0x2)
"MSIServer"=2 (0x2)
"stisvc"=2 (0x2)
"SharedAccess"=2 (0x2)
"VSS"=3 (0x3)
"upnphost"=3 (0x3)
"UPS"=3 (0x3)
"TermService"=3 (0x3)
"TapiSrv"=3 (0x3)
"srservice"=2 (0x2)
"SCardSvr"=3 (0x3)
"wscsvc"=2 (0x2)
"seclogon"=2 (0x2)
"NtmsSvc"=3 (0x3)
"RasAuto"=3 (0x3)
"RSVP"=3 (0x3)
"RDSessMgr"=3 (0x3)
"Browser"=3 (0x3)
"WebClient"=2 (0x2)
"LmHosts"=2 (0x2)
"PolicyAgent"=2 (0x2)
"ERSvc"=2 (0x2)
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-]
"TkBellExe"="c:\program files\Common Files\Real\Update_OB\realsched.exe" -osboot
"SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe"
"ISUSPM Startup"="c:\program files\Common Files\InstallShield\UpdateService\ISUSPM.exe" -startup
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe"
"igfxtray"=c:\windows\system32\igfxtray.exe
"igfxpers"=c:\windows\system32\igfxpers.exe
"hpWirelessAssistant"=c:\program files\hpq\HP Wireless Assistant\HP Wireless Assistant.exe
"SynTPEnh"=c:\program files\Synaptics\SynTP\SynTPEnh.exe
"igfxhkcmd"=c:\windows\system32\hkcmd.exe
"RIMBBLaunchAgent.exe"=c:\program files\Common Files\Research In Motion\USB Drivers\RIMBBLaunchAgent.exe
"HP Software Update"=c:\program files\Hp\HP Software Update\HPWuSchd2.exe
"High Definition Audio Property Page Shortcut"=CHDAudPropShortcut.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001
.
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"c:\\WINDOWS\\system32\\fxsclnt.exe"=
"c:\\WINDOWS\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\WINDOWS\\system32\\sessmgr.exe"=
"c:\\Program Files\\Java\\jre7\\bin\\javaw.exe"=
"c:\\Program Files\\Common Files\\Apple\\Apple Application Support\\WebKit2WebProcess.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
"c:\\Program Files\\Hp\\Digital Imaging\\bin\\hpqtra08.exe"=
"c:\\Program Files\\Hp\\Digital Imaging\\bin\\hpqste08.exe"=
"c:\\Program Files\\Hp\\Digital Imaging\\bin\\hposid01.exe"=
"c:\\Program Files\\Hp\\Digital Imaging\\bin\\hpqkygrp.exe"=
"c:\\Program Files\\Hp\\Digital Imaging\\bin\\hpfcCopy.exe"=
"c:\\Program Files\\Hp\\Digital Imaging\\bin\\hpoews01.exe"=
"c:\\Program Files\\Hp\\Digital Imaging\\bin\\hpiscnapp.exe"=
"c:\\Program Files\\Common Files\\HP\\Digital Imaging\\Bin\\hpqPhotoCrm.exe"=
"c:\\Program Files\\Hp\\Digital Imaging\\bin\\hpqgplgtupl.exe"=
"c:\\Program Files\\Hp\\Digital Imaging\\bin\\hpqgpc01.exe"=
"c:\\Program Files\\Hp\\HP Software Update\\HPWUCli.exe"=
"c:\\Program Files\\Hp\\Digital Imaging\\smart web printing\\SmartWebPrintExe.exe"=
"c:\\Program Files\\Google\\Chrome\\Application\\chrome.exe"=
"c:\\Program Files\\Origin Games\\Crusader No Remorse\\data\\Game\\DOSBox\\DOSBox.exe"=
"c:\\Program Files\\Origin Games\\Wing Commander III\\Game\\Game\\DOSBox\\DOSBox.exe"=
"c:\\Program Files\\Origin Games\\SimCity 2000 SE\\Game\\Game\\DOSBox\\DOSBox.exe"=
"c:\\Program Files\\Hp\\Digital Imaging\\{2012D762-5DCA-455A-B5FE-EDF79BC93E18}\\setup\\hpznui01.exe"=
"c:\\Program Files\\Java\\jre7\\bin\\jp2launcher.exe"=
"c:\\Program Files\\E-TRADE Pro\\jre\\bin\\java.exe"=
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"5985:TCP"= 5985:TCP:*:Disabled:Windows Remote Management
.
R2 MBAMService;MBAMService;c:\program files\Malwarebytes Anti-Malware\mbamservice.exe [2015-10-05 1135416]
R3 cpuz138;cpuz138;c:\docume~1\1\LOCALS~1\Temp\cpuz138\cpuz138_x32.sys [x]
R3 motccgp;Motorola USB Composite Device Driver;c:\windows\system32\DRIVERS\motccgp.sys [x]
R3 motccgpfl;MotCcgpFlService;c:\windows\system32\DRIVERS\motccgpfl.sys [x]
R3 MotDev;Motorola Inc. USB Device;c:\windows\system32\DRIVERS\motodrv.sys [x]
S2 WinDefend;Windows Defender;c:\program files\Windows Defender\MsMpEng.exe [2006-11-03 13592]
S3 MBAMProtector;MBAMProtector;c:\windows\system32\drivers\mbam.sys [2015-10-05 23256]
.
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
HPZ12 REG_MULTI_SZ Pml Driver HPZ12 Net Driver HPZ12
HPService REG_MULTI_SZ HPSLPSVC
hpdevmgmt REG_MULTI_SZ hpqcxs08 hpqddsvc
.
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{8A69D345-D564-463c-AFF1-A69D9E530F96}]
2015-12-14 00:23 1000264 ----a-w- c:\program files\Google\Chrome\Application\47.0.2526.80\Installer\chrmstp.exe
.
Contents of the 'Scheduled Tasks' folder
.
2015-12-26 c:\windows\Tasks\Amazon Music Helper.job
- c:\documents and settings\1\Local Settings\Application Data\Amazon Cloud Player\Amazon Music Helper.exe [2014-03-06 19:46]
.
2015-12-23 c:\windows\Tasks\G2MUpdateTask-S-1-5-21-2740428291-721650609-345291581-1006.job
- c:\program files\Citrix\GoToMeeting\4062\g2mupdate.exe [2015-12-08 03:35]
.
2015-12-23 c:\windows\Tasks\G2MUploadTask-S-1-5-21-2740428291-721650609-345291581-1006.job
- c:\program files\Citrix\GoToMeeting\4062\g2mupload.exe [2015-12-08 03:35]
.
2015-12-26 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2013-06-26 01:51]
.
2015-12-23 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2013-06-26 01:51]
.
2015-12-26 c:\windows\Tasks\Microsoft Windows XP End of Service Notification Logon.job
- c:\windows\system32\xp_eos.exe [2014-03-07 01:59]
.
2015-10-08 c:\windows\Tasks\Microsoft Windows XP End of Service Notification Monthly.job
- c:\windows\system32\xp_eos.exe [2014-03-07 01:59]
.
2015-12-26 c:\windows\Tasks\MP Scheduled Scan.job
- c:\program files\Windows Defender\MpCmdRun.exe [2006-11-03 23:20]
.
2015-12-26 c:\windows\Tasks\User_Feed_Synchronization-{F7405781-D735-43C3-BEA3-06C346D0BF27}.job
- c:\windows\system32\msfeedssync.exe [2007-08-13 08:31]
.
.
------- Supplementary Scan -------
.
uStart Page = hxxp://google.com/
uInternet Settings,ProxyOverride = 192.168.*.*
IE: &Google Search - c:\program files\google\GoogleToolbar2.dll/cmsearch.html
IE: &Translate English Word - c:\program files\google\GoogleToolbar2.dll/cmwordtrans.html
IE: Add to filterlist (WebWasher) - http://-Web.Washer-/ie_add
IE: Backward Links - c:\program files\google\GoogleToolbar2.dll/cmbacklinks.html
IE: Cached Snapshot of Page - c:\program files\google\GoogleToolbar2.dll/cmcache.html
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~4\OFFICE11\EXCEL.EXE/3000
IE: Similar Pages - c:\program files\google\GoogleToolbar2.dll/cmsimilar.html
IE: Translate Page into English - c:\program files\google\GoogleToolbar2.dll/cmtrans.html
Trusted Zone: etrade.com\us
Trusted Zone: wallst.com\www.etrade
.
- - - - ORPHANS REMOVED - - - -
.
MSConfigStartUp-RoboForm - c:\program files\Siber Systems\AI RoboForm\RoboTaskBarIcon.exe
AddRemove-PDF Writer Packages - c:\documents and settings\1\Application Data\0D0S1L2Z1P1B0T1P1B2Z\PDF Writer Packages\uninstaller.exe
.
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2015-12-26 13:24
Windows 5.1.2600 Service Pack 3 NTFS
.
scanning hidden processes ...
.
scanning hidden autostart entries ...
.
HKLM\Software\Microsoft\Windows\CurrentVersion\Run
Cpqset = c:\program files\HPQ\Default Settings\cpqset.exe?????? ???@???????????????@? ????O??????(?@???????@
.
scanning hidden files ...
.
scan completed successfully
hidden files: 0
.
**************************************************************************
.
--------------------- LOCKED REGISTRY KEYS ---------------------
.
[HKEY_USERS\S-1-5-21-1078081533-484763869-725345543-1003_Classes\CLSID\{7BFEACB2-97F5-4DC7-92E0-E69ED4C37C43}\InprocServer32]
@Denied: (C D 2 3 6) (Everyone)
@Allowed: (Read) (S-1-5-21-2740428291-721650609-345291581-1006)
"ThreadingModel"="Apartment"
@="c:\\Documents and Settings\\All Users\\Application Data\\{FB62659C-5547-4284-846F-24B4EEDF86F7}\\wshelper.dll"
.
[HKEY_USERS\S-1-5-21-1078081533-484763869-725345543-1003_Classes\Drive\ShellEx\FolderExtensions\{7BFEACB2-97F5-4DC7-92E0-E69ED4C37C43}]
@Denied: (C D 2 3 6) (Everyone)
@Allowed: (Read) (S-1-5-21-2740428291-721650609-345291581-1006)
"DriveMask"=dword:ffffffff
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{01B90D9A-8209-47F7-9C52-E1244BF50CED}\Containers\{22383CF1-ED17-4E2E-AF17-D85B8F6B30D0}\0]
@DACL=(02 0000)
"Position"=dword:00000000
"Pattern"=hex:44,00,65,00,73,00,63,00,72,00,69,00,70,00,74,00,69,00,6f,00,6e,
00
"Mask"=hex:ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{01B90D9A-8209-47F7-9C52-E1244BF50CED}\Containers\{BB5ACC38-F216-4CEC-A6C5-5F6E739763A9}]
@DACL=(02 0000)
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{01B90D9A-8209-47F7-9C52-E1244BF50CED}\InProcServer32]
@DACL=(02 0000)
@="windowscodecsext.dll"
"ThreadingModel"="Apartment"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{01CBCF66-A9CA-4449-84DE-7F321232BBC7}]
@DACL=(02 0000)
@="html persistent handler for mapi email"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{02266525-0C89-4E67-9976-3BE0354A29BA}]
@DACL=(02 0000)
@="GW65x ConnectorManager Class"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{0289a7c5-91bf-4547-81ae-fec91a89dec5}]
@DACL=(02 0000)
@="Microsoft Windows Remote Shell Host"
"AppId"=expand:"{3e5ca495-8d6a-4d1f-ad99-177b426c8b8e}"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{03012959-F4F6-44D7-9D09-DAA087A9DB57}]
@DACL=(02 0000)
"Version"="1.0.0.0"
"SpecVersion"="1.0.0.0"
"Vendor"="{F0E749CA-EDEF-4589-A73A-EE0E626A2A2B}"
"MetadataFormat"="{4FAB0914-E129-4087-A1D1-BC812D45A7B5}"
"RequiresFullStream"=dword:00000000
"SupportsPadding"=dword:00000000
"Author"="Microsoft"
"FriendlyName"="IPTC Reader"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{03219e78-5bc3-44d1-b92e-f63d89cc6526}]
@DACL=(02 0000)
@="XAudio2"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{0368BFF0-9870-11D0-94AB-0080C74C7E95}]
@DACL=(02 0000)
@="AMtoolbar Class"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{037FB476-15E0-4ED1-B11A-E420B750B1A8}]
@DACL=(02 0000)
@SACL=
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{03ACC284-B757-4B8F-9951-86E600D2CD06}]
@DACL=(02 0000)
@SACL=
@="PrivateKey Class"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{03be3ac4-84b7-4e0e-a78d-d3524e60395a}]
@DACL=(02 0000)
@SACL=
@="WMVideo Advanced Decoder DMO"
"Merit"=dword:00800001
"WMSDKMerit"=dword:00000100
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{03ca98d6-ff5d-49b8-abc6-03dd84127020}]
@DACL=(02 0000)
@="%BITS_CLASS_2_5_NAME%"
"AppID"="{69AD4AEE-51BE-439b-A92C-86AE490E8B30}"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{03D389AE-0455-4504-8768-C6027F3FB7EB}]
@DACL=(02 0000)
@SACL=
@="TravelPhotoTrans Class"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{03EC05EA-C2A7-49A8-971F-580D5891F2FB}]
@DACL=(02 0000)
@SACL=
@="CyberLink Audio Decoder"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{047DEC5A-95C1-4C86-827F-7B8C92EBA67A}]
@DACL=(02 0000)
@="PSFactoryBuffer"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{0482E074-C5B7-101A-82E0-08002B36A333}\PersistentHandler]
@DACL=(02 0000)
@="{098f2470-bae0-11cd-b579-08002b30bfeb}"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{04B55BC3-33DE-4d79-94EC-830CDF96CC82}]
@DACL=(02 0000)
@="WMPlayer ContentPropPage Class"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{050DA15F-9F13-11D0-9CE5-00C04FC9BCC4}]
@DACL=(02 0000)
@="NWLink Configuration Notify Object"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{05589FA1-C356-11CE-BF01-00AA0055595A}]
@DACL=(02 0000)
@="ActiveMovieControl Object"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{0562F29E-2C93-4F39-A6D6-EA05F1E714FC}]
@DACL=(02 0000)
@="CDVB_EIT"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{05AF94D8-7174-4CD2-BE4A-4124B80EE4B8}]
@DACL=(02 0000)
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{05BDC38E-5493-487a-A7FF-8CF2246ABC13}]
@DACL=(02 0000)
@="IE Background Task Scheduler"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{063D34A4-BF84-4B8D-B699-E8CA06504DDE}]
@DACL=(02 0000)
@="ItunesService Class"
"AppID"="{250DD19F-6E7F-4BA3-9E1B-69E6CDC52F30}"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{067B4B81-B1EC-489f-B111-940EBDC44EBE}]
@DACL=(02 0000)
@="WMDM CE Device Service Provider"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{06849E9F-C8D7-4D59-B87D-784B7D6BE0B3}]
@DACL=(02 0000)
@="AcroIEHlprObj Class"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{06E360F7-7F54-4689-9605-4358A1017F24}]
@DACL=(02 0000)
@="OverlayCallback Class"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{06EEE834-461C-42c2-8DCF-1502B527B1F9}]
@DACL=(02 0000)
@="URL Shortcut PropSetStorage Mapping"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{074b110f-7f58-4743-aea5-12f15b5074ed}]
@DACL=(02 0000)
@="XACT Engine"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{076C2A6C-F78F-4C46-A723-3583E70876EA}]
@DACL=(02 0000)
"Version"="1.0.0.0"
"SpecVersion"="1.0.0.0"
"Vendor"="{F0E749CA-EDEF-4589-A73A-EE0E626A2A2B}"
"MetadataFormat"="{7B08A675-91AA-481B-A798-4DA94908613B}"
"RequiresFullStream"=dword:00000000
"SupportsPadding"=dword:00000000
"Author"="Microsoft"
"FriendlyName"="XMP Alt Writer"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{079AA557-4A18-424A-8EEE-E39F0A8D41B9}]
@DACL=(02 0000)
@="SAX XML Reader"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{07A774A0-6047-11D1-BA20-006097D2898E}]
@DACL=(02 0000)
@="Logagent Class"
"AppID"="{F808DF63-6049-11D1-BA20-006097D2898E}"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{07C45BB1-4A8C-4642-A1F5-237E7215FF66}]
@DACL=(02 0000)
@="IE Microsoft BrowserBand"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{07F48D44-F1F0-490B-96CD-EE8841D1F409}]
@DACL=(02 0000)
@SACL=
@="Detective Class"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{083863F1-70DE-11d0-BD40-00A0C911CE86}\Instance\CLSID_DivXDeux]
@DACL=(02 0000)
@SACL=
"FriendlyName"="DivX Decoder Filter"
"CLSID"="{78766964-0000-0010-8000-00AA00389B71}"
"FilterData"=hex:02,00,00,00,00,00,80,00,02,00,00,00,00,00,00,00,30,70,69,33,
00,00,00,00,00,00,00,00,0e,00,00,00,00,00,00,00,00,00,00,00,30,74,79,33,00,\
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{083863F1-70DE-11d0-BD40-00A0C911CE86}\Instance\{00A95963-3BE5-48C0-AD9F-3356D67EA09D}]
@DACL=(02 0000)
"FriendlyName"="Subtitle Mixer"
"CLSID"="{00A95963-3BE5-48C0-AD9F-3356D67EA09D}"
"FilterData"=hex:02,00,00,00,0a,00,80,00,03,00,00,00,00,00,00,00,30,70,69,33,
00,00,00,00,00,00,00,00,08,00,00,00,00,00,00,00,00,00,00,00,30,74,79,33,00,\
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{083863F1-70DE-11d0-BD40-00A0C911CE86}\Instance\{03EC05EA-C2A7-49A8-971F-580D5891F2FB}]
@DACL=(02 0000)
@SACL=
"FriendlyName"="CyberLink Audio Decoder"
"CLSID"="{03EC05EA-C2A7-49A8-971F-580D5891F2FB}"
"FilterData"=hex:02,00,00,00,00,10,60,00,02,00,00,00,00,00,00,00,30,70,69,33,
00,00,00,00,00,00,00,00,1a,00,00,00,00,00,00,00,00,00,00,00,30,74,79,33,00,\
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{083863F1-70DE-11d0-BD40-00A0C911CE86}\Instance\{07167665-5011-11CF-BF33-00AA0055595A}]
@DACL=(02 0000)
"FriendlyName"="Full Screen Renderer"
"CLSID"="{07167665-5011-11CF-BF33-00AA0055595A}"
"FilterData"=hex:02,00,00,00,00,00,20,00,01,00,00,00,00,00,00,00,30,70,69,33,
02,00,00,00,00,00,00,00,01,00,00,00,00,00,00,00,00,00,00,00,30,74,79,33,00,\
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{083863F1-70DE-11d0-BD40-00A0C911CE86}\Instance\{1643E180-90F5-11CE-97D5-00AA0055595A}]
@DACL=(02 0000)
"FriendlyName"="Color Space Converter"
"CLSID"="{1643E180-90F5-11CE-97D5-00AA0055595A}"
"FilterData"=hex:02,00,00,00,01,00,40,00,02,00,00,00,00,00,00,00,30,70,69,33,
00,00,00,00,00,00,00,00,06,00,00,00,00,00,00,00,00,00,00,00,30,74,79,33,00,\
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{083863F1-70DE-11d0-BD40-00A0C911CE86}\Instance\{187463A0-5BB7-11D3-ACBE-0080C75E246E}]
@DACL=(02 0000)
"FriendlyName"="WM ASF Reader"
"CLSID"="{187463A0-5BB7-11D3-ACBE-0080C75E246E}"
"FilterData"=hex:02,00,00,00,00,00,40,00,00,00,00,00,00,00,00,00
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{083863F1-70DE-11d0-BD40-00A0C911CE86}\Instance\{1A56451B-1315-4012-861E-8587333DD631}]
@DACL=(02 0000)
"FriendlyName"="Screen Capture filter"
"CLSID"="{1A56451B-1315-4012-861E-8587333DD631}"
"FilterData"=hex:02,00,00,00,00,00,20,00,01,00,00,00,00,00,00,00,30,70,69,33,
08,00,00,00,00,00,00,00,01,00,00,00,00,00,00,00,00,00,00,00,30,74,79,33,00,\
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{083863F1-70DE-11d0-BD40-00A0C911CE86}\Instance\{1B544C20-FD0B-11CE-8C63-00AA0044B51E}]
@DACL=(02 0000)
"FriendlyName"="AVI Splitter"
"CLSID"="{1B544C20-FD0B-11CE-8C63-00AA0044B51E}"
"FilterData"=hex:02,00,00,00,00,00,60,00,02,00,00,00,00,00,00,00,30,70,69,33,
00,00,00,00,00,00,00,00,01,00,00,00,00,00,00,00,00,00,00,00,30,74,79,33,00,\
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{083863F1-70DE-11d0-BD40-00A0C911CE86}\Instance\{1DA08500-9EDC-11CF-BC10-00AA00AC74F6}]
@DACL=(02 0000)
"FriendlyName"="VGA 16 Color Ditherer"
"CLSID"="{1DA08500-9EDC-11CF-BC10-00AA00AC74F6}"
"FilterData"=hex:02,00,00,00,00,00,40,00,02,00,00,00,00,00,00,00,30,70,69,33,
00,00,00,00,00,00,00,00,01,00,00,00,00,00,00,00,00,00,00,00,30,74,79,33,00,\
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{083863F1-70DE-11d0-BD40-00A0C911CE86}\Instance\{20D09D9A-4AE0-41D4-B8E5-9BEC7850627D}]
@DACL=(02 0000)
@SACL=
"FriendlyName"="CyberLink TimeStretch Filter"
"CLSID"="{20D09D9A-4AE0-41D4-B8E5-9BEC7850627D}"
"FilterData"=hex:02,00,00,00,00,00,20,00,02,00,00,00,00,00,00,00,30,70,69,33,
00,00,00,00,00,00,00,00,01,00,00,00,00,00,00,00,00,00,00,00,30,74,79,33,00,\
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{083863F1-70DE-11d0-BD40-00A0C911CE86}\Instance\{26C48DC0-F148-4A70-B252-3F8AE0188EBF}]
@DACL=(02 0000)
@SACL=
"FriendlyName"="Sonic DirectShow Tap"
"CLSID"="{26C48DC0-F148-4A70-B252-3F8AE0188EBF}"
"FilterData"=hex:02,00,00,00,00,00,20,00,02,00,00,00,00,00,00,00,30,70,69,33,
00,00,00,00,00,00,00,00,02,00,00,00,00,00,00,00,00,00,00,00,30,74,79,33,00,\
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{083863F1-70DE-11d0-BD40-00A0C911CE86}\Instance\{2BE4D120-6F2E-4B3A-B0BD-E880917238DC}]
@DACL=(02 0000)
@SACL=
"FriendlyName"="MainConcept MPEG Splitter"
"CLSID"="{2BE4D120-6F2E-4B3A-B0BD-E880917238DC}"
"FilterData"=hex:02,00,00,00,fe,ff,5f,00,03,00,00,00,00,00,00,00,30,70,69,33,
00,00,00,00,00,00,00,00,08,00,00,00,00,00,00,00,00,00,00,00,30,74,79,33,00,\
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{083863F1-70DE-11d0-BD40-00A0C911CE86}\Instance\{2BE4D130-6F2E-4B3A-B0BD-E880917238DC}]
@DACL=(02 0000)
@SACL=
"FriendlyName"="MainConcept MPEG Audio Decoder"
"CLSID"="{2BE4D130-6F2E-4B3A-B0BD-E880917238DC}"
"FilterData"=hex:02,00,00,00,00,00,60,00,02,00,00,00,00,00,00,00,30,70,69,33,
00,00,00,00,00,00,00,00,09,00,00,00,00,00,00,00,00,00,00,00,30,74,79,33,00,\
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{083863F1-70DE-11d0-BD40-00A0C911CE86}\Instance\{2BE4D140-6F2E-4B3A-B0BD-E880917238DC}]
@DACL=(02 0000)
@SACL=
"FriendlyName"="MainConcept MPEG Video Decoder"
"CLSID"="{2BE4D140-6F2E-4B3A-B0BD-E880917238DC}"
"FilterData"=hex:02,00,00,00,00,00,60,00,02,00,00,00,00,00,00,00,30,70,69,33,
00,00,00,00,00,00,00,00,04,00,00,00,00,00,00,00,00,00,00,00,30,74,79,33,00,\
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{083863F1-70DE-11d0-BD40-00A0C911CE86}\Instance\{301056D0-6DFF-11D2-9EEB-006008039E37}]
@DACL=(02 0000)
"FriendlyName"="MJPEG Decompressor"
"CLSID"="{301056D0-6DFF-11D2-9EEB-006008039E37}"
"FilterData"=hex:02,00,00,00,00,00,60,00,02,00,00,00,00,00,00,00,30,70,69,33,
00,00,00,00,00,00,00,00,01,00,00,00,00,00,00,00,00,00,00,00,30,74,79,33,00,\
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{083863F1-70DE-11d0-BD40-00A0C911CE86}\Instance\{336475D0-942A-11CE-A870-00AA002FEAB5}]
@DACL=(02 0000)
"FriendlyName"="MPEG-1 Stream Splitter"
"CLSID"="{336475D0-942A-11CE-A870-00AA002FEAB5}"
"FilterData"=hex:02,00,00,00,00,00,60,00,03,00,00,00,00,00,00,00,30,70,69,33,
00,00,00,00,00,00,00,00,04,00,00,00,00,00,00,00,00,00,00,00,30,74,79,33,00,\
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{083863F1-70DE-11d0-BD40-00A0C911CE86}\Instance\{33FACFE0-A9BE-11D0-A520-00A0D10129C0}]
@DACL=(02 0000)
"FriendlyName"="SAMI (CC) Parser"
"CLSID"="{33FACFE0-A9BE-11D0-A520-00A0D10129C0}"
"FilterData"=hex:02,00,00,00,00,00,40,00,02,00,00,00,00,00,00,00,30,70,69,33,
00,00,00,00,00,00,00,00,01,00,00,00,00,00,00,00,00,00,00,00,30,74,79,33,00,\
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{083863F1-70DE-11d0-BD40-00A0C911CE86}\Instance\{3C931142-245B-4A79-ABC3-044E287BB468}]
@DACL=(02 0000)
@SACL=
"FriendlyName"="Sonic MPEG Audio Decoder"
"CLSID"="{3C931142-245B-4A79-ABC3-044E287BB468}"
"FilterData"=hex:02,00,00,00,00,00,20,00,02,00,00,00,00,00,00,00,30,70,69,33,
00,00,00,00,00,00,00,00,08,00,00,00,00,00,00,00,00,00,00,00,30,74,79,33,00,\
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{083863F1-70DE-11d0-BD40-00A0C911CE86}\Instance\{3E1434A3-1303-4F14-9762-40B97A6C136D}]
@DACL=(02 0000)
@SACL=
"FriendlyName"="muvee HXImage Filter"
"CLSID"="{3E1434A3-1303-4F14-9762-40B97A6C136D}"
"FilterData"=hex:02,00,00,00,00,00,20,00,02,00,00,00,00,00,00,00,30,70,69,33,
00,00,00,00,00,00,00,00,01,00,00,00,00,00,00,00,00,00,00,00,30,74,79,33,00,\
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{083863F1-70DE-11d0-BD40-00A0C911CE86}\Instance\{429075DD-2586-4B9B-A752-F5E6066A9659}]
@DACL=(02 0000)
@SACL=
"FriendlyName"="RTStreamSink"
"CLSID"="{429075DD-2586-4B9B-A752-F5E6066A9659}"
"FilterData"=hex:02,00,00,00,00,00,20,00,01,00,00,00,00,00,00,00,30,70,69,33,
00,00,00,00,00,00,00,00,01,00,00,00,00,00,00,00,00,00,00,00,30,74,79,33,00,\
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{083863F1-70DE-11d0-BD40-00A0C911CE86}\Instance\{48025243-2D39-11CE-875D-00608CB78066}]
@DACL=(02 0000)
"FriendlyName"="Internal Script Command Renderer"
"CLSID"="{48025243-2D39-11CE-875D-00608CB78066}"
"FilterData"=hex:02,00,00,00,01,00,80,00,01,00,00,00,00,00,00,00,30,70,69,33,
02,00,00,00,00,00,00,00,02,00,00,00,00,00,00,00,00,00,00,00,30,74,79,33,00,\
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{083863F1-70DE-11d0-BD40-00A0C911CE86}\Instance\{4A2286E0-7BEF-11CE-9BD9-0000E202599C}]
@DACL=(02 0000)
"FriendlyName"="MPEG Audio Decoder"
"CLSID"="{4A2286E0-7BEF-11CE-9BD9-0000E202599C}"
"FilterData"=hex:02,00,00,00,01,00,68,03,02,00,00,00,00,00,00,00,30,70,69,33,
00,00,00,00,00,00,00,00,03,00,00,00,00,00,00,00,00,00,00,00,30,74,79,33,00,\
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{083863F1-70DE-11d0-BD40-00A0C911CE86}\Instance\{51B4ABF3-748F-4E3B-A276-C828330E926A}]
@DACL=(02 0000)
"FriendlyName"="Video Mixing Renderer 9"
"CLSID"="{51B4ABF3-748F-4E3B-A276-C828330E926A}"
"FilterData"=hex:02,00,00,00,00,00,20,00,01,00,00,00,00,00,00,00,30,70,69,33,
02,00,00,00,00,00,00,00,01,00,00,00,00,00,00,00,00,00,00,00,30,74,79,33,00,\
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{083863F1-70DE-11d0-BD40-00A0C911CE86}\Instance\{52780691-D7F8-4335-B38E-EC40280EDC57}]
@DACL=(02 0000)
"FriendlyName"="Subtitle Parser"
"CLSID"="{52780691-D7F8-4335-B38E-EC40280EDC57}"
"FilterData"=hex:02,00,00,00,00,00,60,00,02,00,00,00,00,00,00,00,30,70,69,33,
00,00,00,00,00,00,00,00,01,00,00,00,00,00,00,00,00,00,00,00,30,74,79,33,00,\
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{083863F1-70DE-11d0-BD40-00A0C911CE86}\Instance\{631C66E1-B5F3-48AD-9B8B-448728CB427A}]
@DACL=(02 0000)
@SACL=
"FriendlyName"="CyberLink Demultiplexer (HP_QP2005)"
"CLSID"="{631C66E1-B5F3-48AD-9B8B-448728CB427A}"
"FilterData"=hex:02,00,00,00,00,00,60,00,01,00,00,00,00,00,00,00,30,70,69,33,
00,00,00,00,00,00,00,00,02,00,00,00,00,00,00,00,00,00,00,00,30,74,79,33,00,\
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{083863F1-70DE-11d0-BD40-00A0C911CE86}\Instance\{6A08CF80-0E18-11CF-A24D-0020AFD79767}]
@DACL=(02 0000)
"FriendlyName"="ACM Wrapper"
"CLSID"="{6A08CF80-0E18-11CF-A24D-0020AFD79767}"
"FilterData"=hex:02,00,00,00,00,00,60,00,02,00,00,00,00,00,00,00,30,70,69,33,
00,00,00,00,00,00,00,00,01,00,00,00,00,00,00,00,00,00,00,00,30,74,79,33,00,\
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{083863F1-70DE-11d0-BD40-00A0C911CE86}\Instance\{6BC1CFFA-8FC1-4261-AC22-CFB4CC38DB50}]
@DACL=(02 0000)
"FriendlyName"="Video Renderer"
"CLSID"="{6BC1CFFA-8FC1-4261-AC22-CFB4CC38DB50}"
"FilterData"=hex:02,00,00,00,01,00,80,00,01,00,00,00,00,00,00,00,30,70,69,33,
02,00,00,00,00,00,00,00,01,00,00,00,00,00,00,00,00,00,00,00,30,74,79,33,00,\
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{083863F1-70DE-11d0-BD40-00A0C911CE86}\Instance\{6E1E5E54-C586-4F67-BBE0-62617C1F488D}]
@DACL=(02 0000)
@SACL=
"FriendlyName"="Sonic Audio Depth Converter"
"CLSID"="{6E1E5E54-C586-4F67-BBE0-62617C1F488D}"
"FilterData"=hex:02,00,00,00,00,00,20,00,02,00,00,00,00,00,00,00,30,70,69,33,
00,00,00,00,00,00,00,00,01,00,00,00,00,00,00,00,00,00,00,00,30,74,79,33,00,\
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{083863F1-70DE-11d0-BD40-00A0C911CE86}\Instance\{6F26A6CD-967B-47FD-874A-7AED2C9D25A2}]
@DACL=(02 0000)
"FriendlyName"="Video Port Manager"
"CLSID"="{6F26A6CD-967B-47FD-874A-7AED2C9D25A2}"
"FilterData"=hex:02,00,00,00,00,00,60,00,03,00,00,00,00,00,00,00,30,70,69,33,
00,00,00,00,00,00,00,00,01,00,00,00,00,00,00,00,00,00,00,00,30,74,79,33,00,\
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{083863F1-70DE-11d0-BD40-00A0C911CE86}\Instance\{70E102B0-5556-11CE-97C0-00AA0055595A}]
@DACL=(02 0000)
"FriendlyName"="Video Renderer"
"CLSID"="{70E102B0-5556-11CE-97C0-00AA0055595A}"
"FilterData"=hex:02,00,00,00,00,00,40,00,01,00,00,00,00,00,00,00,30,70,69,33,
02,00,00,00,00,00,00,00,01,00,00,00,00,00,00,00,00,00,00,00,30,74,79,33,00,\
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{083863F1-70DE-11d0-BD40-00A0C911CE86}\Instance\{75D10B02-EDDC-444B-9FDC-511FD07E5C6F}]
@DACL=(02 0000)
@SACL=
"FriendlyName"="QuickTimeRenderer Filter"
"CLSID"="{75D10B02-EDDC-444B-9FDC-511FD07E5C6F}"
"FilterData"=hex:02,00,00,00,00,00,20,00,01,00,00,00,00,00,00,00,30,70,69,33,
00,00,00,00,00,00,00,00,01,00,00,00,00,00,00,00,00,00,00,00,30,74,79,33,00,\
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{083863F1-70DE-11d0-BD40-00A0C911CE86}\Instance\{78766964-0000-0010-8000-00AA00389B71}]
@DACL=(02 0000)
"FriendlyName"="DivX Decoder Filter"
"CLSID"="{78766964-0000-0010-8000-00AA00389B71}"
"FilterData"=hex:02,00,00,00,00,00,80,ff,02,00,00,00,00,00,00,00,30,70,69,33,
00,00,00,00,00,00,00,00,14,00,00,00,00,00,00,00,00,00,00,00,30,74,79,33,00,\
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{083863F1-70DE-11d0-BD40-00A0C911CE86}\Instance\{79A00187-F159-4B89-981B-F81D51504201}]
@DACL=(02 0000)
"FriendlyName"="DivXAntiFreeze"
"CLSID"="{79A00187-F159-4B89-981B-F81D51504201}"
"FilterData"=hex:02,00,00,00,01,00,80,00,02,00,00,00,00,00,00,00,30,70,69,33,
00,00,00,00,00,00,00,00,01,00,00,00,00,00,00,00,00,00,00,00,30,74,79,33,00,\
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{083863F1-70DE-11d0-BD40-00A0C911CE86}\Instance\{7C23220E-55BB-11D3-8B16-00C04FB6BD3D}]
@DACL=(02 0000)
"FriendlyName"="WM ASF Writer"
"CLSID"="{7C23220E-55BB-11D3-8B16-00C04FB6BD3D}"
"FilterData"=hex:02,00,00,00,00,00,40,00,00,00,00,00,00,00,00,00
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{083863F1-70DE-11d0-BD40-00A0C911CE86}\Instance\{85516702-9C45-4A9C-861B-BC4492D355DC}]
@DACL=(02 0000)
"FriendlyName"="DivX Demux"
"CLSID"="{85516702-9C45-4A9C-861B-BC4492D355DC}"
"FilterData"=hex:02,00,00,00,00,00,60,00,01,00,00,00,00,00,00,00,30,70,69,33,
00,00,00,00,00,00,00,00,01,00,00,00,00,00,00,00,00,00,00,00,30,74,79,33,00,\
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{083863F1-70DE-11d0-BD40-00A0C911CE86}\Instance\{949DCA39-87F9-44EF-9E57-E0FC43005F79}]
@DACL=(02 0000)
@SACL=
"FriendlyName"="CyberLink Line21 Decoder Filter"
"CLSID"="{949DCA39-87F9-44EF-9E57-E0FC43005F79}"
"FilterData"=hex:02,00,00,00,00,00,20,00,02,00,00,00,00,00,00,00,30,70,69,33,
08,00,00,00,00,00,00,00,02,00,00,00,00,00,00,00,00,00,00,00,30,74,79,33,00,\
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{083863F1-70DE-11d0-BD40-00A0C911CE86}\Instance\{998F5F68-9134-4D96-BC12-075A63D5CF3B}]
@DACL=(02 0000)
@SACL=
"FriendlyName"="Sonic MPEG Video Decoder"
"CLSID"="{998F5F68-9134-4D96-BC12-075A63D5CF3B}"
"FilterData"=hex:02,00,00,00,00,00,20,00,03,00,00,00,00,00,00,00,30,70,69,33,
00,00,00,00,00,00,00,00,03,00,00,00,00,00,00,00,00,00,00,00,30,74,79,33,00,\
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{083863F1-70DE-11d0-BD40-00A0C911CE86}\Instance\{A888DF60-1E90-11CF-AC98-00AA004C0FA9}]
@DACL=(02 0000)
"FriendlyName"="AVI Draw"
"CLSID"="{A888DF60-1E90-11CF-AC98-00AA004C0FA9}"
"FilterData"=hex:02,00,00,00,64,00,60,00,0a,00,00,00,00,00,00,00,30,70,69,33,
00,00,00,00,00,00,00,00,01,00,00,00,00,00,00,00,00,00,00,00,30,74,79,33,00,\
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{083863F1-70DE-11d0-BD40-00A0C911CE86}\Instance\{AA478720-468A-41AB-9D97-263B6580FE8C}]
@DACL=(02 0000)
@SACL=
"FriendlyName"="muvee Video Analyser"
"CLSID"="{AA478720-468A-41AB-9D97-263B6580FE8C}"
"FilterData"=hex:02,00,00,00,00,00,20,00,01,00,00,00,00,00,00,00,30,70,69,33,
00,00,00,00,00,00,00,00,01,00,00,00,00,00,00,00,00,00,00,00,30,74,79,33,00,\
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{083863F1-70DE-11d0-BD40-00A0C911CE86}\Instance\{AA478722-468A-41AB-9D97-263B6580FE8C}]
@DACL=(02 0000)
@SACL=
"FriendlyName"="muvee Music Analyser"
"CLSID"="{AA478722-468A-41AB-9D97-263B6580FE8C}"
"FilterData"=hex:02,00,00,00,00,00,20,00,01,00,00,00,00,00,00,00,30,70,69,33,
00,00,00,00,00,00,00,00,01,00,00,00,00,00,00,00,00,00,00,00,30,74,79,33,00,\
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{083863F1-70DE-11d0-BD40-00A0C911CE86}\Instance\{AA59CBFA-F731-49E9-BE78-08665F339EFC}]
@DACL=(02 0000)
"FriendlyName"="Bicubic Video Resizer"
"CLSID"="{AA59CBFA-F731-49E9-BE78-08665F339EFC}"
"FilterData"=hex:02,00,00,00,02,00,80,00,02,00,00,00,00,00,00,00,30,70,69,33,
00,00,00,00,00,00,00,00,01,00,00,00,00,00,00,00,00,00,00,00,30,74,79,33,00,\
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{083863F1-70DE-11d0-BD40-00A0C911CE86}\Instance\{BA11F969-397A-4146-AC96-236C3D76711D}]
@DACL=(02 0000)
"FriendlyName"="DivX Subtitle Decoder"
"CLSID"="{BA11F969-397A-4146-AC96-236C3D76711D}"
"FilterData"=hex:02,00,00,00,00,00,60,00,02,00,00,00,00,00,00,00,30,70,69,33,
00,00,00,00,00,00,00,00,02,00,00,00,00,00,00,00,00,00,00,00,30,74,79,33,00,\
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{083863F1-70DE-11d0-BD40-00A0C911CE86}\Instance\{BF3F7EF3-8527-4145-BE10-63F8C0DE6ABB}]
@DACL=(02 0000)
@SACL=
"FriendlyName"="QuickTime Source Filter"
"CLSID"="{BF3F7EF3-8527-4145-BE10-63F8C0DE6ABB}"
"FilterData"=hex:02,00,00,00,00,00,20,00,01,00,00,00,00,00,00,00,30,70,69,33,
08,00,00,00,00,00,00,00,01,00,00,00,00,00,00,00,00,00,00,00,30,74,79,33,00,\
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{083863F1-70DE-11d0-BD40-00A0C911CE86}\Instance\{C1F400A0-3F08-11D3-9F0B-006008039E37}]
@DACL=(02 0000)
"FriendlyName"="SampleGrabber"
"CLSID"="{C1F400A0-3F08-11D3-9F0B-006008039E37}"
"FilterData"=hex:02,00,00,00,00,00,20,00,02,00,00,00,00,00,00,00,30,70,69,33,
00,00,00,00,00,00,00,00,01,00,00,00,00,00,00,00,00,00,00,00,30,74,79,33,00,\
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{083863F1-70DE-11d0-BD40-00A0C911CE86}\Instance\{C1F400A4-3F08-11D3-9F0B-006008039E37}]
@DACL=(02 0000)
"FriendlyName"="Null Renderer"
"CLSID"="{C1F400A4-3F08-11D3-9F0B-006008039E37}"
"FilterData"=hex:02,00,00,00,00,00,20,00,01,00,00,00,00,00,00,00,30,70,69,33,
02,00,00,00,00,00,00,00,01,00,00,00,00,00,00,00,00,00,00,00,30,74,79,33,00,\
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{083863F1-70DE-11d0-BD40-00A0C911CE86}\Instance\{C666E115-BB62-4027-A113-82D643FE2D99}]
@DACL=(02 0000)
"FriendlyName"="MPEG-2 Sections and Tables"
"CLSID"="{C666E115-BB62-4027-A113-82D643FE2D99}"
"FilterData"=hex:02,00,00,00,ff,ff,5f,00,01,00,00,00,00,00,00,00,30,70,69,33,
00,00,00,00,00,00,00,00,01,00,00,00,00,00,00,00,00,00,00,00,30,74,79,33,00,\
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{083863F1-70DE-11d0-BD40-00A0C911CE86}\Instance\{C81C8C5A-B354-4DEB-96D3-8BD8D0C8ABD0}]
@DACL=(02 0000)
@SACL=
"FriendlyName"="CyberLink Video/SP Decoder"
"CLSID"="{C81C8C5A-B354-4DEB-96D3-8BD8D0C8ABD0}"
"FilterData"=hex:02,00,00,00,00,20,60,00,05,00,00,00,00,00,00,00,30,70,69,33,
00,00,00,00,00,00,00,00,05,00,00,00,00,00,00,00,00,00,00,00,30,74,79,33,00,\
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{083863F1-70DE-11d0-BD40-00A0C911CE86}\Instance\{CEF4D40F-ACA5-40BA-8F3B-161A594A1A39}]
@DACL=(02 0000)
"FriendlyName"="RealPlayer Audio Filter"
"CLSID"="{CEF4D40F-ACA5-40BA-8F3B-161A594A1A39}"
"FilterData"=hex:02,00,00,00,00,00,20,00,02,00,00,00,00,00,00,00,30,70,69,33,
00,00,00,00,00,00,00,00,01,00,00,00,00,00,00,00,00,00,00,00,30,74,79,33,00,\
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{083863F1-70DE-11d0-BD40-00A0C911CE86}\Instance\{CF49D4E0-1115-11CE-B03A-0020AF0BA770}]
@DACL=(02 0000)
"FriendlyName"="AVI Decompressor"
"CLSID"="{CF49D4E0-1115-11CE-B03A-0020AF0BA770}"
"FilterData"=hex:02,00,00,00,00,00,60,00,02,00,00,00,00,00,00,00,30,70,69,33,
00,00,00,00,00,00,00,00,01,00,00,00,00,00,00,00,00,00,00,00,30,74,79,33,00,\
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{083863F1-70DE-11d0-BD40-00A0C911CE86}\Instance\{D12B5396-C8EF-4D6D-B540-0F0FF6A9F2CC}]
@DACL=(02 0000)
@SACL=
"FriendlyName"="CyberLink Video Effect"
"CLSID"="{D12B5396-C8EF-4D6D-B540-0F0FF6A9F2CC}"
"FilterData"=hex:02,00,00,00,00,00,20,00,02,00,00,00,00,00,00,00,30,70,69,33,
00,00,00,00,00,00,00,00,01,00,00,00,00,00,00,00,00,00,00,00,30,74,79,33,00,\
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{083863F1-70DE-11d0-BD40-00A0C911CE86}\Instance\{D3588AB0-0781-11CE-B03A-0020AF0BA770}]
@DACL=(02 0000)
"FriendlyName"="AVI/WAV File Source"
"CLSID"="{D3588AB0-0781-11CE-B03A-0020AF0BA770}"
"FilterData"=hex:02,00,00,00,00,00,40,00,02,00,00,00,00,00,00,00,30,70,69,33,
0d,00,00,00,00,00,00,00,01,00,00,00,00,00,00,00,00,00,00,00,30,74,79,33,00,\
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{083863F1-70DE-11d0-BD40-00A0C911CE86}\Instance\{D3CD7858-971A-4838-ACEC-40CA5D529DC8}]
@DACL=(02 0000)
"FriendlyName"="Morgan Stream Switcher"
"CLSID"="{D3CD7858-971A-4838-ACEC-40CA5D529DC8}"
"FilterData"=hex:02,00,00,00,03,00,80,00,02,00,00,00,00,00,00,00,30,70,69,33,
04,00,00,00,00,00,00,00,01,00,00,00,00,00,00,00,00,00,00,00,30,74,79,33,00,\
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{083863F1-70DE-11d0-BD40-00A0C911CE86}\Instance\{D51BD5A0-7548-11CF-A520-0080C77EF58A}]
@DACL=(02 0000)
"FriendlyName"="QuickTime Movie Parser"
"CLSID"="{D51BD5A0-7548-11CF-A520-0080C77EF58A}"
"FilterData"=hex:02,00,00,00,00,00,60,00,02,00,00,00,00,00,00,00,30,70,69,33,
00,00,00,00,00,00,00,00,01,00,00,00,00,00,00,00,00,00,00,00,30,74,79,33,00,\
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{083863F1-70DE-11d0-BD40-00A0C911CE86}\Instance\{D51BD5A1-7548-11CF-A520-0080C77EF58A}]
@DACL=(02 0000)
"FriendlyName"="Wave Parser"
"CLSID"="{D51BD5A1-7548-11CF-A520-0080C77EF58A}"
"FilterData"=hex:02,00,00,00,00,00,40,00,02,00,00,00,00,00,00,00,30,70,69,33,
00,00,00,00,00,00,00,00,03,00,00,00,00,00,00,00,00,00,00,00,30,74,79,33,00,\
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{083863F1-70DE-11d0-BD40-00A0C911CE86}\Instance\{D51BD5A2-7548-11CF-A520-0080C77EF58A}]
@DACL=(02 0000)
"FriendlyName"="MIDI Parser"
"CLSID"="{D51BD5A2-7548-11CF-A520-0080C77EF58A}"
"FilterData"=hex:02,00,00,00,00,00,40,00,02,00,00,00,00,00,00,00,30,70,69,33,
00,00,00,00,00,00,00,00,01,00,00,00,00,00,00,00,00,00,00,00,30,74,79,33,00,\
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{083863F1-70DE-11d0-BD40-00A0C911CE86}\Instance\{D51BD5A3-7548-11CF-A520-0080C77EF58A}]
@DACL=(02 0000)
"FriendlyName"="Multi-file Parser"
"CLSID"="{D51BD5A3-7548-11CF-A520-0080C77EF58A}"
"FilterData"=hex:02,00,00,00,00,00,40,00,02,00,00,00,00,00,00,00,30,70,69,33,
00,00,00,00,00,00,00,00,01,00,00,00,00,00,00,00,00,00,00,00,30,74,79,33,00,\
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{083863F1-70DE-11d0-BD40-00A0C911CE86}\Instance\{D51BD5A5-7548-11CF-A520-0080C77EF58A}]
@DACL=(02 0000)
"FriendlyName"="File stream renderer"
"CLSID"="{D51BD5A5-7548-11CF-A520-0080C77EF58A}"
"FilterData"=hex:02,00,00,00,00,00,40,00,02,00,00,00,00,00,00,00,30,70,69,33,
00,00,00,00,00,00,00,00,01,00,00,00,00,00,00,00,00,00,00,00,30,74,79,33,00,\
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{083863F1-70DE-11d0-BD40-00A0C911CE86}\Instance\{DCD6EADC-EE69-47DD-B934-95573296039C}]
@DACL=(02 0000)
"FriendlyName"="Nero DVD Decoder"
"CLSID"="{DCD6EADC-EE69-47DD-B934-95573296039C}"
"FilterData"=hex:02,00,00,00,00,00,60,00,03,00,00,00,00,00,00,00,30,70,69,33,
00,00,00,00,00,00,00,00,02,00,00,00,00,00,00,00,00,00,00,00,30,74,79,33,00,\
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{083863F1-70DE-11d0-BD40-00A0C911CE86}\Instance\{DF5B1476-5C72-42BA-98DD-AFA6A812A3B3}]
@DACL=(02 0000)
@SACL=
"FriendlyName"="Sonic MPEG Splitter"
"CLSID"="{DF5B1476-5C72-42BA-98DD-AFA6A812A3B3}"
"FilterData"=hex:02,00,00,00,00,00,20,00,03,00,00,00,00,00,00,00,30,70,69,33,
00,00,00,00,00,00,00,00,05,00,00,00,00,00,00,00,00,00,00,00,30,74,79,33,00,\
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{083863F1-70DE-11d0-BD40-00A0C911CE86}\Instance\{E2BD78F2-79A2-413D-A052-EE2E91B9D821}]
@DACL=(02 0000)
"FriendlyName"="Subtitle Dest"
"CLSID"="{E2BD78F2-79A2-413D-A052-EE2E91B9D821}"
"FilterData"=hex:02,00,00,00,00,00,20,00,02,00,00,00,00,00,00,00,30,70,69,33,
00,00,00,00,00,00,00,00,01,00,00,00,00,00,00,00,00,00,00,00,30,74,79,33,00,\
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{083863F1-70DE-11d0-BD40-00A0C911CE86}\Instance\{E339D44A-9819-4CDC-876C-0F563EEAF757}]
@DACL=(02 0000)
@SACL=
"FriendlyName"="CyberLink DVD Navigator"
"CLSID"="{E339D44A-9819-4CDC-876C-0F563EEAF757}"
"FilterData"=hex:02,00,00,00,00,00,60,00,03,00,00,00,00,00,00,00,30,70,69,33,
08,00,00,00,00,00,00,00,01,00,00,00,00,00,00,00,00,00,00,00,30,74,79,33,00,\
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{083863F1-70DE-11d0-BD40-00A0C911CE86}\Instance\{E4206432-01A1-4BEE-B3E1-3702C8EDC574}]
@DACL=(02 0000)
"FriendlyName"="Line 21 Decoder 2"
"CLSID"="{E4206432-01A1-4BEE-B3E1-3702C8EDC574}"
"FilterData"=hex:02,00,00,00,02,00,60,00,02,00,00,00,00,00,00,00,30,70,69,33,
00,00,00,00,00,00,00,00,01,00,00,00,00,00,00,00,00,00,00,00,30,74,79,33,00,\
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{083863F1-70DE-11d0-BD40-00A0C911CE86}\Instance\{E436EBB5-524F-11CE-9F53-0020AF0BA770}]
@DACL=(02 0000)
"FriendlyName"="File Source (Async.)"
"CLSID"="{E436EBB5-524F-11CE-9F53-0020AF0BA770}"
"FilterData"=hex:02,00,00,00,00,00,40,00,01,00,00,00,00,00,00,00,30,70,69,33,
08,00,00,00,00,00,00,00,01,00,00,00,00,00,00,00,00,00,00,00,30,74,79,33,00,\
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{083863F1-70DE-11d0-BD40-00A0C911CE86}\Instance\{E436EBB6-524F-11CE-9F53-0020AF0BA770}]
@DACL=(02 0000)
"FriendlyName"="File Source (URL)"
"CLSID"="{E436EBB6-524F-11CE-9F53-0020AF0BA770}"
"FilterData"=hex:02,00,00,00,00,00,40,00,01,00,00,00,00,00,00,00,30,70,69,33,
08,00,00,00,00,00,00,00,01,00,00,00,00,00,00,00,00,00,00,00,30,74,79,33,00,\
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{083863F1-70DE-11d0-BD40-00A0C911CE86}\Instance\{E913D868-2959-42D5-9287-923D31666474}]
@DACL=(02 0000)
@SACL=
"FriendlyName"="QuickTime Encoder"
"CLSID"="{E913D868-2959-42D5-9287-923D31666474}"
"FilterData"=hex:02,00,00,00,00,00,20,00,01,00,00,00,00,00,00,00,30,70,69,33,
00,00,00,00,00,00,00,00,01,00,00,00,00,00,00,00,00,00,00,00,30,74,79,33,00,\
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{083863F1-70DE-11d0-BD40-00A0C911CE86}\Instance\{ECFBE6E0-1AC8-11D4-8501-00A0CC5D1F63}]
@DACL=(02 0000)
"FriendlyName"="WMplug"
"CLSID"="{ECFBE6E0-1AC8-11D4-8501-00A0CC5D1F63}"
"FilterData"=hex:02,00,00,00,f4,01,90,00,02,00,00,00,00,00,00,00,30,70,69,33,
00,00,00,00,00,00,00,00,01,00,00,00,00,00,00,00,00,00,00,00,30,74,79,33,00,\
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{083863F1-70DE-11d0-BD40-00A0C911CE86}\Instance\{F5FB18CC-1A99-454F-9B18-A98D686B0CDB}]
@DACL=(02 0000)
@SACL=
"FriendlyName"="CyberLink AudioCD Filter"
"CLSID"="{F5FB18CC-1A99-454F-9B18-A98D686B0CDB}"
"FilterData"=hex:02,00,00,00,00,00,60,00,01,00,00,00,00,00,00,00,30,70,69,33,
08,00,00,00,00,00,00,00,02,00,00,00,00,00,00,00,00,00,00,00,30,74,79,33,00,\
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{083863F1-70DE-11d0-BD40-00A0C911CE86}\Instance\{FDFE9681-74A3-11D0-AFA7-00AA00B67A42}]
@DACL=(02 0000)
"FriendlyName"="QT Decompressor"
"CLSID"="{FDFE9681-74A3-11D0-AFA7-00AA00B67A42}"
"FilterData"=hex:02,00,00,00,00,00,60,00,02,00,00,00,00,00,00,00,30,70,69,33,
00,00,00,00,00,00,00,00,04,00,00,00,00,00,00,00,00,00,00,00,30,74,79,33,00,\
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{083863F1-70DE-11d0-BD40-00A0C911CE86}\Instance\{FEB50740-7BEF-11CE-9BD9-0000E202599C}]
@DACL=(02 0000)
"FriendlyName"="MPEG Video Decoder"
"CLSID"="{FEB50740-7BEF-11CE-9BD9-0000E202599C}"
"FilterData"=hex:02,00,00,00,01,00,00,40,02,00,00,00,00,00,00,00,30,70,69,33,
00,00,00,00,00,00,00,00,02,00,00,00,00,00,00,00,00,00,00,00,30,74,79,33,00,\
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{08a99e2f-6d6d-4b80-af5a-baf2bcbe4cb9}]
@DACL=(02 0000)
@="PropVariantCollection Class"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{08B0E5C0-4FCB-11CF-AAA5-00401C608501}]
@DACL=(02 0000)
@SACL=
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{090A8723-05E7-4648-B4B8-8FC23000E907}]
@DACL=(02 0000)
@SACL=
@="CyberLink Audio Misc. Property Page"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{0977d092-2d95-4e43-8d42-9ddcc2545ed5}]
@DACL=(02 0000)
@="XACT Engine"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{098870b6-39ea-480b-b8b5-dd0167c4db59}]
@DACL=(02 0000)
@="IE OpenService Manager"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{0990EDE2-3498-43D0-971D-D5321C893210}]
@DACL=(02 0000)
@SACL=
@="CLSetting Class"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{09DBBC77-588F-4517-A485-74A29759F54C}]
@DACL=(02 0000)
@="PSFactoryBuffer"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{0a402d70-1f10-4ae7-bec9-286a98240695}]
@DACL=(02 0000)
@="WinFX Bootstrapper for .application"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{0A4286EA-E355-44FB-8086-AF3DF7645BD9}]
@DACL=(02 0000)
@="&Windows Media Player"
"LocalizedString"="@c:\\PROGRA~1\\WINDOW~1\\wmpband.dll,-101"
"MenuText"="@c:\\PROGRA~1\\WINDOW~1\\wmpband.dll,-101"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{0A886F29-465A-4aea-8B8E-BE926BFAE83E}]
@DACL=(02 0000)
@="EapQecMessenger"
"ThreadingModel"="Free"
"AppID"="{0A886F29-465A-4aea-8B8E-BE926BFAE83E}"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{0aa000aa-f404-11d9-bd7a-0010dc4f8f81}]
@DACL=(02 0000)
@="XACT Engine"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{0AA02E8D-F851-4CB0-9F64-BBA9BE7A983D}]
@DACL=(02 0000)
@="AlchemyVis Class"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{0ABE7426-0498-4E66-892B-4BD914DC8049}]
@DACL=(02 0000)
@SACL=
@="MVAppInfo Class"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{0AE89F03-C538-4471-9B12-A8E8EF246A0D}]
@Class="REG_SZ"
@DACL=(02 0000)
@SACL=
@="PSFactoryBuffer"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{0af10cec-2ecd-4b92-9581-34f6ae0637f3}]
@DACL=(02 0000)
@="PortableDeviceManager Class"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{0B5A7836-4C16-4560-90B2-0F5DAF6D6D1B}]
@DACL=(02 0000)
@="FormHost Class"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{0b6d74fe-ad29-4c92-ac06-f06bc2f238a7}]
@DACL=(02 0000)
@="Microsoft Feeds Request"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{0b91a74b-ad7c-4a9d-b563-29eef9167172}]
@DACL=(02 0000)
@="WpdSerializer Class"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{0c15d503-d017-47ce-9016-7b3f978721cc}]
@DACL=(02 0000)
@="PortableDeviceValues Class"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{0C9298FF-4F28-4B5F-AB4A-B93925686D87}]
@DACL=(02 0000)
@SACL=
@="BlurTransition Class"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{0CD7A5C0-9F37-11CE-AE65-08002B2E1262}\PersistentHandler]
@DACL=(02 0000)
@SACL=
@="{098f2470-bae0-11cd-b579-08002b30bfeb}"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{0E25DC18-9F5E-48B1-80B3-D124E81B773B}]
@DACL=(02 0000)
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{0E50C9F8-ADBF-4A46-B082-159C78DAFBF9}]
@DACL=(02 0000)
@SACL=
@="QuakeEffect Class"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{0E806791-0204-4FED-8E31-A57D3F54C75B}]
@DACL=(02 0000)
@SACL=
@="MVTextAcid Class"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{0EB70964-9577-423C-954C-5F6DE27E8EB3}]
@DACL=(02 0000)
@SACL=
@="MotionBlur Class"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{0F152611-115F-49ad-9048-A3EA9405D12E}]
@DACL=(02 0000)
@SACL=
@="TimelineCtrl Class"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{0F3F9F91-C838-415E-A4F3-3E828CA445E0}]
@DACL=(02 0000)
@="FaxDocument Class"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{0F94C4A3-27D2-43B9-A7A7-09B122109764}]
@DACL=(02 0000)
@SACL=
@="MVTextSlideShowSepia Class"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{0FDD7594-0D2B-4125-826C-657214228353}]
@DACL=(02 0000)
@SACL=
@="MVTextSmoky Class"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{0FDF6D6B-D672-463B-846E-C6FF49109662}]
@DACL=(02 0000)
@="RealPlayer Download Handler"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{10BCEB99-FAAC-4080-B2FA-D07CD671EEF2}]
@DACL=(02 0000)
@="IE Recovery Store"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{11016101-E366-4D22-BC06-4ADA335C892B}]
@DACL=(02 0000)
@="IE History and Feeds Shell Data Source for Windows Search"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{110A3202-5A79-11d3-8D78-444553540000}]
@DACL=(02 0000)
@="WMDMLogger Class"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{1138472b-d187-44e9-81f2-ae1b0e7785f1}]
@DACL=(02 0000)
@="XACT Engine"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{114F5598-0B22-40A0-86A1-C83EA495ADBD}]
@DACL=(02 0000)
"ContainerFormat"="{1F8A5601-7D4D-4CBD-9C82-1BC8D4EEB9A5}"
"Vendor"="{F0E749CA-EDEF-4589-A73A-EE0E626A2A2B}"
"Version"="1.0.0.0"
"SpecVersion"="1.0.0.0"
"ColorManagementVersion"="1.0.0.0"
"MimeTypes"="image/gif"
"FileExtensions"=".gif"
"SupportAnimation"=dword:00000001
"SupportChromakey"=dword:00000001
"SupportLossless"=dword:00000001
"SupportMultiframe"=dword:00000001
"Author"="Microsoft"
"FriendlyName"="GIF Encoder"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{122EC645-CD7E-44D8-B186-2C8C20C3B50F}]
@DACL=(02 0000)
"Version"="1.0.0.0"
"SpecVersion"="1.0.0.0"
"Vendor"="{F0E749CA-EDEF-4589-A73A-EE0E626A2A2B}"
"MetadataFormat"="{ED686F8E-681F-4C8B-BD41-A8ADDBF6B3FC}"
"RequiresFullStream"=dword:00000001
"SupportsPadding"=dword:00000001
"Author"="Microsoft"
"FriendlyName"="Interop Writer"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{1249B20C-5DD0-44FE-B0B3-8F92C8E6D080}]
@DACL=(02 0000)
"Version"="1.0.0.0"
"SpecVersion"="1.0.0.0"
"Vendor"="{F0E749CA-EDEF-4589-A73A-EE0E626A2A2B}"
"MetadataFormat"="{4FAB0914-E129-4087-A1D1-BC812D45A7B5}"
"FixedSize"=dword:00000001
"SupportsPadding"=dword:00000001
"RequiresFullStream"=dword:00000000
"Author"="Microsoft"
"FriendlyName"="IPTC Writer"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{127698e4-e730-4e5c-a2b1-21490a70c8a1}]
@DACL=(02 0000)
@="CEnroll Class"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{12DA6D0B-021F-4d79-8794-64145F503CA5}]
@DACL=(02 0000)
@="EAP Quarantine Enforcement Client Callback Component"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{13639463-00DB-4646-803D-528026140D88}]
@DACL=(02 0000)
@="UpdateCollection Class"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{1510FB87-5676-40B9-A227-5D0B66866F81}]
@DACL=(02 0000)
@="PSFactoryBuffer"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{164037BB-7C2B-43DB-8B61-AF18D7401EB5}]
@DACL=(02 0000)
@="CPAT"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{1765E14E-1BD4-462E-B6B1-590BF1262AC6}]
@DACL=(02 0000)
"Version"="1.0.0.0"
"SpecVersion"="1.0.0.0"
"Vendor"="{F0E749CA-EDEF-4589-A73A-EE0E626A2A2B}"
"MetadataFormat"="{BB5ACC38-F216-4CEC-A6C5-5F6E739763A9}"
"RequiresFullStream"=dword:00000000
"SupportsPadding"=dword:00000001
"Author"="Microsoft"
"FriendlyName"="XMP Writer"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{18C628EE-962A-11D2-8D08-00A0C9441E20}]
@DACL=(02 0000)
@="Xml2Dex Class"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{19916E01-B44E-4e31-94A4-4696DF46157B}]
@DACL=(02 0000)
@="InformationCardSigninHelper Class"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{1A34F5C1-4A5A-46DC-B644-1F4567E7A676}]
@DACL=(02 0000)
"ContainerFormat"="{19E4A5AA-5662-4FC5-A0C0-1758028E1057}"
"Vendor"="{F0E749CA-EDEF-4589-A73A-EE0E626A2A2B}"
"Version"="1.0.0.0"
"SpecVersion"="1.0.0.0"
"ColorManagementVersion"="1.0.0.0"
"MimeTypes"="image/jpeg,image/jpe,image/jpg"
"FileExtensions"=".jpeg,.jpe,.jpg,.jfif,.exif"
"SupportAnimation"=dword:00000000
"SupportChromakey"=dword:00000000
"SupportLossless"=dword:00000000
"SupportMultiframe"=dword:00000000
"Author"="Microsoft"
"FriendlyName"="JPEG Encoder"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{1A3F11DC-B514-4B17-8C5F-2154513852F1}]
@DACL=(02 0000)
"Vendor"="{F0E749CA-EDEF-4589-A73A-EE0E626A2A2B}"
"Version"="1.0.0.0"
"SpecVersion"="1.0.0.0"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{1A56451B-1315-4012-861E-8587333DD631}]
@DACL=(02 0000)
@SACL=
@="WMEnc Screen Capture Filter"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{1a6fe369-f28c-4ad9-a3e6-2bcb50807cf1}]
@DACL=(02 0000)
@="Developer Tools"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{1ADD57B8-A7A9-4518-B9B5-862590FF9EB4}]
@DACL=(02 0000)
@SACL=
@="DivX Decoder Filter Help Page"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{1bae8be7-8434-f24e-bb7f-0beb28e317db}]
@DACL=(02 0000)
@SACL=
@="Photo2 Class"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{1BF18D30-223C-4E0F-9074-C78C1256FD43}]
@DACL=(02 0000)
@="Windows Media Player WMEncAdvancedStreamEdit Class"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{1C1EDB47-CE22-4bbb-B608-77B48F83C823}]
@DACL=(02 0000)
@="IE Fade Task"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{1D1237A0-6CD6-11d2-96BA-00104B242E64}]
@DACL=(02 0000)
@="ppDSFile Class"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{1D1C9F59-FD73-49ae-A7A4-4A5DB5F64AC9}]
@DACL=(02 0000)
@="Absolute Mode Touchpad Category"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{1D1F0730-0748-4b5f-81DF-865694BD07AC}]
@DACL=(02 0000)
@="IE OrderListExport"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{1DD02726-012D-48e7-80E1-BA8E00A20ECB}]
@DACL=(02 0000)
@SACL=
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{1E198087-59CC-4932-99FB-F5083DC2E714}]
@DACL=(02 0000)
@="CDVB_BAT"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{1E680528-EBD9-4F0F-AD2F-B01ED04EE903}]
@DACL=(02 0000)
@SACL=
@="RotateResize Class"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{1E807E5C-521F-465E-AF4E-267AAD50B3AC}]
@DACL=(02 0000)
@="HPHubSearch Class"
"AppID"="{5F2F4FF3-9F5E-4774-AF1C-401626772B9D}"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{1EE42F7A-18BB-42EF-A06E-C31A8337AE59}]
@DACL=(02 0000)
@="CPMT"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{1f1b577e-5e5a-4e8a-ba73-c657ea8e8598}]
@DACL=(02 0000)
@="XACT Engine"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{1f1f4e1a-2252-4063-84bb-eee75f8856d5}]
@DACL=(02 0000)
@="WMA Voice Encoder DMO"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{1F7D1BE9-7A50-40b6-A605-C4F3696F49C0}]
@DACL=(02 0000)
@="ThirdPartyEapDispatcherPeerConfig"
"AppID"="{1F7D1BE9-7A50-40B6-A605-C4F3696F49C0}"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{1F7E6C6D-C3F8-4c80-8D77-C4825ABBE5CF}]
@DACL=(02 0000)
@="SpnMdrWrdBrk Class"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{1F87137D-0E7C-44d5-8C73-4EFFB68962F2}]
@DACL=(02 0000)
"AppId"="{1F87137D-0E7C-44D5-8C73-4EFFB68962F2}"
@="Microsoft WMI Provider Subsystem Secured Host"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{1ff1dc5d-d5c9-479b-be9b-5ef8fee7fb0c}]
@DACL=(02 0000)
@SACL=
@="Surfboard Shim Doc Object View"
"BrowseInplace"=""
"DocObject"=""
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{203b1eed-db9f-40fb-87bd-1990982017d2}]
@DACL=(02 0000)
@="WMSDK NamespaceFactory Class"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{205D7A97-F16D-4691-86EF-F3075DCCA57D}]
@DACL=(02 0000)
@="IE Menu Desk Bar"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{2060435E-AB52-49E1-A2EA-5D31645887CF}]
@DACL=(02 0000)
@="Synaptics Device Control"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{206D8F65-689B-40D0-8F07-8D974CD8884B}]
@DACL=(02 0000)
@="Synaptics Display Control"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{20D09D9A-4AE0-41D4-B8E5-9BEC7850627D}]
@DACL=(02 0000)
@SACL=
@="CyberLink TimeStretch Filter"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{2139e6da-c341-4774-9ac3-b4e026347f64}]
@DACL=(02 0000)
@="AudioVolumeMeter"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{21569614-B795-46b1-85F4-E737A8DC09AD}]
@DACL=(02 0000)
@SACL=
@="Shell Search Band"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{2179C5D3-EBFF-11CF-B6FD-00AA00B4E220}]
@DACL=(02 0000)
@="Microsoft NetShow Player"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{2183DACA-D0BF-4a31-97F7-B87618A81955}]
@DACL=(02 0000)
@="IE Shared Task Scheduler"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{224E833B-2CC6-42D9-AE39-90B6A38A4FA2}]
@DACL=(02 0000)
@="RealPlayer SMIL Download Handler"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{22826D59-929D-4FE8-BE38-87C9A24F88D5}]
@DACL=(02 0000)
@SACL=
@="Vibrate Class"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{22A85CE1-F011-4231-B9E4-7E7A0438F71B}]
@DACL=(02 0000)
@SACL=
@="Utilities Class"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{22BDC741-73F0-41DB-9463-E343DEF3E376}]
@DACL=(02 0000)
@="PSFactoryBuffer"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{22C21F93-7DDB-411C-9B17-C5B7BD064ABC}]
@DACL=(02 0000)
"Version"="1.0.0.0"
"SpecVersion"="1.0.0.0"
"Vendor"="{F0E749CA-EDEF-4589-A73A-EE0E626A2A2B}"
"MetadataFormat"="{22383CF1-ED17-4E2E-AF17-D85B8F6B30D0}"
"RequiresFullStream"=dword:00000000
"SupportsPadding"=dword:00000000
"Author"="Microsoft"
"FriendlyName"="XMP Struct Writer"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{22D6F312-B0F6-11D0-94AB-0080C74C7E95}]
@DACL=(02 0000)
@="Windows Media Player"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{23170F69-40C1-278A-1000-000100020000}]
@DACL=(02 0000)
@="7-Zip Shell Extension"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{2318C2B1-4965-11d4-9B18-009027A5CD4F}]
@DACL=(02 0000)
@="&Google"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{23243955-6E6B-44A2-BCD5-9597F6C25F99}]
@DACL=(02 0000)
@SACL=
@="UnloadableCamera Class"
"AppID"=""
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{23f891a4-572b-474a-86da-66cdd3d1ac2e}]
@DACL=(02 0000)
@="G2M Session Decoder"
"MERIT"=dword:00600000
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{248AFB1A-27C4-4A30-BF45-6544146648BC}]
@DACL=(02 0000)
@="SynDisplay Class"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{248d8a3b-6256-44d3-a018-2ac96c459f47}]
@DACL=(02 0000)
@="XACT Engine"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{24FF4FDC-1D9F-4195-8C79-0DA39248FF48}]
@DACL=(02 0000)
@="Quarantine Private SHA Binding class"
"AppID"="{B292921D-AF50-400c-9B75-0C57A7F29BA1}"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{25336920-03F9-11CF-8FD0-00AA00686F13}\InProcServer32\7.0.3300.0]
@DACL=(02 0000)
@="c:\\WINDOWS\\system32\\mshtml.dll"
"Assembly"="Microsoft.mshtml, Version=7.0.3300.0, Culture=neutral, PublicKeyToken=b03f5f7f11d50a3a"
"Class"="mshtml.HTMLDocumentClass"
"RuntimeVersion"="v1.0.3705"
"ThreadingModel"="Apartment"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{25336920-03F9-11CF-8FD0-00AA00686F13}\PersistentHandler]
@DACL=(02 0000)
@SACL=
@="{eec97550-47a9-11cf-b952-00aa0051fe20}"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{25336920-03F9-11CF-8FD0-00AA00686F13}\TypeLib]
@DACL=(02 0000)
@="{3050f1c5-98b5-11cf-bb82-00aa00bdce0b}"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{2559a1f6-21d7-11d4-bdaf-00c04f60b9f0}\DefaultIcon]
@DACL=(02 0000)
@SACL=
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{25BAAD81-3560-11D3-8471-00C04F79DBC0}]
@DACL=(02 0000)
@="MediaDevMgr Class"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{26120A0E-7A28-4B31-B179-EE56006D3F54}]
@DACL=(02 0000)
@SACL=
@="Vacation5_GlobalEffect Class"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{267805F1-3641-4FB8-B6BD-185C5D11437C}]
@DACL=(02 0000)
@SACL=
@="MVTextChaplinesque Class"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{2692A9D5-61DF-46D5-A5A1-A6CCA921D578}]
@DACL=(02 0000)
@="ASUController Class"
"AppID"="{6A070EEA-E3F8-411E-9D3A-F3814ED6D1A8}"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{26C48DC0-F148-4A70-B252-3F8AE0188EBF}]
@DACL=(02 0000)
@SACL=
@="DirectShow Tap"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{26D32566-760A-40A2-AA82-A40366528916}]
@DACL=(02 0000)
@="WUPublishedAppInstallorElevator Class"
"AppID"="{e30984f1-b02b-4c27-a40f-23d11b8c1212}"
"LocalizedString"="@c:\\WINDOWS\\system32\\wuapi.dll,-63513"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{276525ED-260A-476F-A9B7-B4FF95CEFC01}]
@DACL=(02 0000)
@SACL=
@="Dither Class"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{27949969-876A-41D7-9447-568F6A35A4DC}]
@DACL=(02 0000)
"ContainerFormat"="{1B7CFAF4-713F-473C-BBCD-6137425FAEAF}"
"Vendor"="{F0E749CA-EDEF-4589-A73A-EE0E626A2A2B}"
"Version"="1.0.0.0"
"SpecVersion"="1.0.0.0"
"ColorManagementVersion"="1.0.0.0"
"MimeTypes"="image/png"
"FileExtensions"=".png"
"SupportAnimation"=dword:00000000
"SupportChromakey"=dword:00000001
"SupportLossless"=dword:00000001
"SupportMultiframe"=dword:00000000
"Author"="Microsoft"
"FriendlyName"="PNG Encoder"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{27B86B53-3839-4441-8D0D-71BA9EE8347B}]
@DACL=(02 0000)
@="CDVB_TOT"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{28013E71-63F0-4427-9D98-EDAAC5C56C50}]
@DACL=(02 0000)
@="CDVB_DIT"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{28cddbc0-0ae2-11ce-a29a-00aa004a1a72}\AutoConvertTo]
@DACL=(02 0000)
@="{ED276879-C98B-11D1-A75F-00C04FB9667B}"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{2933BF90-7B36-11d2-B20E-00C04F983E60}\InProcServer32]
@DACL=(02 0000)
@="c:\\WINDOWS\\system32\\msxml3.dll"
"ThreadingModel"="Both"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{2933BF90-7B36-11d2-B20E-00C04F983E60}\ProgID]
@DACL=(02 0000)
@="Microsoft.XMLDOM.1.0"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{2933BF90-7B36-11d2-B20E-00C04F983E60}\Version]
@DACL=(02 0000)
@="1.0"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{2933BF90-7B36-11d2-B20E-00C04F983E60}\VersionIndependentProgID]
@DACL=(02 0000)
@="Microsoft.XMLDOM"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{2933BF91-7B36-11D2-B20E-00C04F983E60}]
@DACL=(02 0000)
@="Free Threaded XML DOM Document"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{2933BF94-7B36-11D2-B20E-00C04F983E60}]
@DACL=(02 0000)
@="XSL Template"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{295789F0-0949-11D1-B90C-00AA004AB12A}]
@DACL=(02 0000)
@="ATM LAN Emulation Configuration Notify Object"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{2A2699C5-775A-42e9-BF4A-A36FE41BA4CB}]
@DACL=(02 0000)
@="TCPIProp Class"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{2A833A93-6641-11D3-B5FE-00104B0A87C2}]
@DACL=(02 0000)
@="Synaptics Absolute Mode Touchpad Class"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{2AFA62E2-5548-11D1-A6E1-006097C4E476}]
@DACL=(02 0000)
@="ppDSApp Class"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{2B46E70F-CDA7-473E-89F6-DC9630A2390B}]
@DACL=(02 0000)
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{2B7E6AA9-C4FA-4951-815B-4AFE39D81453}]
@DACL=(02 0000)
@="MessengerProxy"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{2BE4D120-6F2E-4B3A-B0BD-E880917238DC}]
@DACL=(02 0000)
@SACL=
@="MainConcept MPEG Splitter"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{2BE4D128-6F2E-4B3A-B0BD-E880917238DC}]
@DACL=(02 0000)
@SACL=
@="MainConcept MPEG Splitter Property Page"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{2BE4D130-6F2E-4B3A-B0BD-E880917238DC}]
@DACL=(02 0000)
@SACL=
@="MainConcept MPEG Audio Decoder"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{2BE4D138-6F2E-4B3A-B0BD-E880917238DC}]
@DACL=(02 0000)
@SACL=
@="MainConcept MPEG Audio Property Page"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{2BE4D140-6F2E-4B3A-B0BD-E880917238DC}]
@DACL=(02 0000)
@SACL=
@="MainConcept MPEG Video Decoder"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{2BE4D148-6F2E-4B3A-B0BD-E880917238DC}]
@DACL=(02 0000)
@SACL=
@="MainConcept MPEG Video Property Page"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{2C4F407E-2E54-4B5E-B1BE-FD1B770C75EC}]
@DACL=(02 0000)
@SACL=
@="SpeedText Class"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{2C676B7B-796E-4C59-8209-4D0473E32A17}]
@DACL=(02 0000)
@SACL=
@="WMEncSourceSink"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{2D11CF10-4FE0-45B2-88DF-6FFBF92BE9AB}]
@DACL=(02 0000)
@="WaitDialog"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{2DCD271D-3755-4A39-A34E-54998F91B58D}]
@DACL=(02 0000)
@SACL=
@="CyberLink Audio Property Page"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{2E31FCBF-FDF1-4518-904C-28B3E005965C}]
@DACL=(02 0000)
@SACL=
@="VideoThumbnail Class"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{2E71FD0F-AAB1-42c0-9146-6D2C4EDCF07D}]
@DACL=(02 0000)
@SACL=
@="SearchAssistantOC"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{2eeb4adf-4578-4d10-bca7-bb955f56320a}]
@DACL=(02 0000)
@SACL=
@="WMAudio Decoder DMO"
"Merit"=dword:00800800
"WMSDKMerit"=dword:00000100
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{2F2F1F96-2BC1-4b1c-BE28-EA3774F4676A}]
@DACL=(02 0000)
@SACL=
@="Shell Name Space"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{2F542A2E-EDC9-4BF7-8CB1-87C9919F7F93}]
@DACL=(02 0000)
@="RealPlayer RAM Download Handler"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{2F603045-309F-11CF-9774-0020AFD0CFF6}]
@DACL=(02 0000)
@SACL=
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{2FB21955-33A2-46A0-8F60-B475DC33FD5A}]
@Class="REG_SZ"
@DACL=(02 0000)
@="PSFactoryBuffer"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{2FD674A5-FE4D-4BF6-AD25-83225CDED113}]
@DACL=(02 0000)
@="CTSDT"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{2FEB9591-50CF-11D1-A6DF-006097C4E476}]
@DACL=(02 0000)
@="ppDSMeta Class"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{3028902F-6374-48b2-8DC6-9725E775B926}]
@DACL=(02 0000)
@="IE AutoComplete"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{3050F391-98B5-11CF-BB82-00AA00BDCE0B}\InProcServer32\7.0.3300.0]
@DACL=(02 0000)
@="c:\\WINDOWS\\system32\\mshtml.dll"
"Assembly"="Microsoft.mshtml, Version=7.0.3300.0, Culture=neutral, PublicKeyToken=b03f5f7f11d50a3a"
"Class"="mshtml.HTMLWindowProxyClass"
"RuntimeVersion"="v1.0.3705"
"ThreadingModel"="Apartment"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{3050f4d8-98B5-11CF-BB82-00AA00BDCE0B}\PersistentHandler]
@DACL=(02 0000)
@="{eec97550-47a9-11cf-b952-00aa0051fe20}"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{3050f667-98b5-11cf-bb82-00aa00bdce0b}\InProcServer32\7.0.3300.0]
@DACL=(02 0000)
@="c:\\WINDOWS\\system32\\mshtml.dll"
"Assembly"="Microsoft.mshtml, Version=7.0.3300.0, Culture=neutral, PublicKeyToken=b03f5f7f11d50a3a"
"Class"="mshtml.HTMLPopupClass"
"RuntimeVersion"="v1.0.3705"
"ThreadingModel"="Apartment"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{3050f819-98b5-11cf-bb82-00aa00bdce0b}\InprocServer32\7.0.3300.0]
@DACL=(02 0000)
@="c:\\WINDOWS\\system32\\mshtml.dll"
"Assembly"="Microsoft.mshtml, Version=7.0.3300.0, Culture=neutral, PublicKeyToken=b03f5f7f11d50a3a"
"Class"="mshtml.HtmlDlgSafeHelperClass"
"RuntimeVersion"="v1.0.3705"
"ThreadingModel"="Apartment"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{30510483-98B5-11CF-BB82-00AA00BDCE0B}]
@DACL=(02 0000)
@="Microsoft HTML Element Context Stream"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{310E42A0-F913-11D4-887C-006008DC5C26}]
@DACL=(02 0000)
@SACL=
@="DivX Decoder Filter Properties Page"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{3124C396-FB13-4836-A6AD-1317F1713688}]
@DACL=(02 0000)
@="SAX XML Reader 3.0"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{317E92FC-1679-46FD-A0B5-F08914DD8623}]
@DACL=(02 0000)
@="InstallationAgent Class"
"AppID"="{B366DEBE-645B-43A5-B865-DDD82C345492}"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{317F3AA1-A5F5-4310-9401-BAE5DAC386C6}]
@DACL=(02 0000)
@="text persistent handler for mapi email"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{31C48C31-70B0-11d1-A708-006097C4E476}]
@DACL=(02 0000)
@="ppDSClip Class"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{31C48C32-70B0-11d1-A708-006097C4E476}]
@DACL=(02 0000)
@="ppDSDetl Class"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{31DCBC0C-20D8-40b0-A409-F4474A942358}]
@DACL=(02 0000)
@="TcpiObj Class"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{31E0DFD7-2621-11D1-AFD7-006097C9A284}]
@DACL=(02 0000)
@="HtmlHelp Class"
"AppID"="{31E0DFC1-2621-11D1-AFD7-006097C9A284}"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{32374F0E-85D3-4408-9BD0-887E3EEAE7F0}]
@DACL=(02 0000)
@="IE JScript Profiler Core"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{3267B428-C5EF-44E6-9800-4009670132F7}]
@DACL=(02 0000)
@SACL=
@="CDeviceUtils Object"
"AppID"="{1DCFDF9F-1241-4B40-9B01-B447643E15E1}"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{32BAED44-34B5-11D3-9315-00C04F72D6CF}]
@DACL=(02 0000)
@="MSSCP Class"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{32C5A81F-27C0-4E66-A894-786F646F1236}]
@DACL=(02 0000)
@="PSFactoryBuffer"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{32E26FD9-F435-4A20-A561-35D4B987CFDC}]
@DACL=(02 0000)
@="WebexUCFObject Class"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{3314B715-90BD-41B4-8872-165913E9C36B}]
@DACL=(02 0000)
@SACL=
@="CDateShifter Object"
"AppID"="{1DCFDF9F-1241-4B40-9B01-B447643E15E1}"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{3338A2DD-8C8E-4AC8-94E8-FD248849D77F}]
@DACL=(02 0000)
@="GoogleBarControl2 Class"
"AppID"="{1F7595F7-05C5-489E-BB9F-6BA11ECD0CA0}"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{33441DE2-5536-44B1-8A39-4D9DE5766AD3}]
@DACL=(02 0000)
@SACL=
@="Christmas04_2Text Class"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{3401D2BA-3644-4D6B-BC7A-DDF7532E250D}]
@DACL=(02 0000)
@SACL=
@="CyberLink Audio Renderer"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{343e68e6-8f82-4a8d-a2da-6e9a944b378c}]
@DACL=(02 0000)
@="XACT Engine"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{34a3d570-67d9-4265-a9ee-8c3fa3dfeccf}]
@DACL=(02 0000)
@="TravelLog"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{351341BD-C1F4-4F0E-B77A-3DF69FE43D79}]
@DACL=(02 0000)
@SACL=
@="ChaplinesqueText Class"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{35298344-96A6-45E7-9B6B-62ECC6E09920}]
@DACL=(02 0000)
@="PSFactoryBuffer"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{354F7156-A4F6-47F5-A028-FE2000E92132}]
@Class="REG_SZ"
@DACL=(02 0000)
@="PSFactoryBuffer"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{35786D3C-B075-49b9-88DD-029876E11C01}]
@DACL=(02 0000)
@="Portable Devices"
"LocalizedString"=expand:"@%SystemRoot%\\System32\\WPDShextRes.dll,-510"
"InfoTip"=expand:"@%SystemRoot%\\System32\\WPDShextRes.dll,-512"
"RunAs"=expand:"Interactive User"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{363F1015-FD5F-4ba8-AC58-29634F378A42}]
@DACL=(02 0000)
@="EngUKWrdBrk Class"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{3669336D-51B1-43D9-961D-D2D17FF3B567}]
@DACL=(02 0000)
@SACL=
@=""
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{368F81BC-9439-41A8-B532-39C8D7E7D147}]
@DACL=(02 0000)
@="ItunesDevices Class"
"AppID"="{250DD19F-6E7F-4BA3-9E1B-69E6CDC52F30}"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{3697790B-223B-484E-9925-C4869218F17A}]
@DACL=(02 0000)
"Version"="1.0.0.0"
"SpecVersion"="1.0.0.0"
"Vendor"="{F0E749CA-EDEF-4589-A73A-EE0E626A2A2B}"
"MetadataFormat"="{7134AB8A-9351-44AD-AF62-448DB6B502EC}"
"RequiresFullStream"=dword:00000001
"SupportsPadding"=dword:00000001
"Author"="Microsoft"
"FriendlyName"="Gps Reader"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{372E5402-BDA5-428d-88CE-187BCF91A343}]
@DACL=(02 0000)
@="HPSIProductUrlCollection Class"
"AppID"="{5F2F4FF3-9F5E-4774-AF1C-401626772B9D}"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{373984C9-B845-449B-91E7-45AC83036ADE}]
@DACL=(02 0000)
@="XML Schema Cache"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{379E501F-B231-11D1-ADC1-00805FC752D8}]
@DACL=(02 0000)
@="MsxmlIsland"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{37de7045-5056-456f-8409-c871e0f8b0e0}]
@DACL=(02 0000)
@="Trun Gateway Protocol Class"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{381DDA3C-9CE9-4834-A23E-1F98F8FC52BE}]
@DACL=(02 0000)
"ContainerFormat"="{1F8A5601-7D4D-4CBD-9C82-1BC8D4EEB9A5}"
"Vendor"="{F0E749CA-EDEF-4589-A73A-EE0E626A2A2B}"
"Version"="1.0.0.0"
"SpecVersion"="1.0.0.0"
"ColorManagementVersion"="1.0.0.0"
"MimeTypes"="image/gif"
"FileExtensions"=".gif"
"SupportAnimation"=dword:00000001
"SupportChromakey"=dword:00000001
"SupportLossless"=dword:00000001
"SupportMultiframe"=dword:00000001
"Author"="Microsoft"
"FriendlyName"="GIF Decoder"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{385A91BC-1E8A-4e4a-A7A6-F4FC1E6CA1BD}\Version]
@DACL=(02 0000)
@="1.1"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{3882134d-14cf-4220-9cb4-435f86d83f60}]
@DACL=(02 0000)
@="PortableDeviceValuesCollection Class"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{389EA17B-5078-4CDE-B6EF-25C15175C751}]
@DACL=(02 0000)
"ContainerFormat"="{1B7CFAF4-713F-473C-BBCD-6137425FAEAF}"
"Vendor"="{F0E749CA-EDEF-4589-A73A-EE0E626A2A2B}"
"Version"="1.0.0.0"
"SpecVersion"="1.0.0.0"
"ColorManagementVersion"="1.0.0.0"
"MimeTypes"="image/png"
"FileExtensions"=".png"
"SupportAnimation"=dword:00000000
"SupportChromakey"=dword:00000001
"SupportLossless"=dword:00000001
"SupportMultiframe"=dword:00000000
"Author"="Microsoft"
"FriendlyName"="PNG Decoder"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{38B22A43-49A8-45ab-BEB7-9137A488B1D3}]
@DACL=(02 0000)
@="Quarantine Private QA Management class"
"AppID"="{B292921D-AF50-400c-9B75-0C57A7F29BA1}"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{38EE5CEE-4B62-11D3-854F-00A0C9C898E7}]
@DACL=(02 0000)
@="MSWebDVD Class"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{395BF287-6477-495f-8427-2C09A23C3248}]
@DACL=(02 0000)
@SACL=
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{39A2C2A6-4778-11D2-9BDB-204C4F4F5020}]
@DACL=(02 0000)
@="DirectControl Class"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{39A2C2A9-4778-11D2-9BDB-204C4F4F5020}]
@DACL=(02 0000)
@="DirectContainer Class"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{3a2495ce-31d0-435b-8ccf-e9f0843fd960}]
@DACL=(02 0000)
@="XACT Engine"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{3B46067C-FD87-49B6-8DDD-12F0D687035F}]
@DACL=(02 0000)
@="RealPlayer Playback Handler"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{3B5E0503-DE28-4BE8-919C-76E0E894A3C2}]
@DACL=(02 0000)
@="RealPlayer RNX Download Handler"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{3b80ee2a-b0f5-4780-9e30-90cb39685b03}]
@DACL=(02 0000)
@="XACT Engine"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{3BC4F3A1-652A-11D1-B4D4-00C04FC2DB8D}]
@DACL=(02 0000)
@="Microsoft Index Server Administration Object"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{3BC4F3A3-652A-11D1-B4D4-00C04FC2DB8D}]
@DACL=(02 0000)
@="Microsoft Index Server Catalog Administration Object"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{3BC4F3A7-652A-11D1-B4D4-00C04FC2DB8D}]
@DACL=(02 0000)
@="Microsoft Index Server Scope Administration Object"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{3C4BA286-B8BB-4384-8EBA-39A49C3FE59A}]
@DACL=(02 0000)
@SACL=
@="MediaSource Class"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{3C4F3BE3-47EB-101B-A3C9-08002B2F49FB}]
@DACL=(02 0000)
@="Common Dialog Font Property Page Object"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{3C4F3BE5-47EB-101B-A3C9-08002B2F49FB}]
@DACL=(02 0000)
@="Common Dialog Print Property Page Object"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{3C4F3BE7-47EB-101B-A3C9-08002B2F49FB}]
@DACL=(02 0000)
@="Common Dialog Help Property Page Object"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{3C931142-245B-4A79-ABC3-044E287BB468}]
@DACL=(02 0000)
@SACL=
@="Sonic MPEG Audio Decoder"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{3D5EF619-F606-4FAA-97C0-222B7DCA05EC}]
@DACL=(02 0000)
@="MyDVDAPHandler Class"
"AppID"="{E03E4D6B-DFF0-4A60-BB87-D0B2C12CFEAF}"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{3D813DFE-6C91-4A4E-8F41-04346A841D9C}]
@DACL=(02 0000)
@="MXXMLWriter 3.0"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{3D96ED94-5D75-4165-9E1F-1A642C7BA316}]
@DACL=(02 0000)
@="Windows Media Player WMEncTextInputSource Class"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{3DA2AA3E-3D96-11D2-9BD2-204C4F4F5020}]
@DACL=(02 0000)
@="AsyncMHandler Class"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{3DAB988E-F65B-499D-BED4-435B14EEF6E0}]
@DACL=(02 0000)
@SACL=
@="Runclose Property Page"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{3DC2E31C-371A-4bd3-9A27-CDF57CE604CF}]
@DACL=(02 0000)
@SACL=
@="MSN Money Charting"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{3E1434A3-1303-4F14-9762-40B97A6C136D}]
@DACL=(02 0000)
@SACL=
@="muvee HXImage Filter"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{3E669F1D-9C23-11d1-9053-00C04FD9189D}\Implemented Categories]
@DACL=(02 0000)
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{3e71f26d-136f-4545-813f-35276024b705}]
@DACL=(02 0000)
@="XML Feed Subscribe Dialog"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{3E784A01-F3AE-4DC0-9354-9526B9370EBA}]
@DACL=(02 0000)
@="SAXAttributes 3.0"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{3eda9b49-2085-498b-9bb2-39a6778493de}]
@DACL=(02 0000)
@="XAudio2"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{3EDD01C5-E428-4C5F-945D-00D9949118D9}]
@DACL=(02 0000)
@="ProgressBar Class"
"AppID"="{DFBF6E48-5D65-4C3A-BBDA-5871CAFED233}"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{3F156A66-3796-4043-96A7-F3423B81C86D}]
@DACL=(02 0000)
@="HPCookie Class"
"AppID"="{5F2F4FF3-9F5E-4774-AF1C-401626772B9D}"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{3F69F351-0379-11D2-A484-00C04F8EFB69}\Implemented Categories]
@DACL=(02 0000)
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{4003191F-71FF-49A2-B591-05C606FADB8B}]
@DACL=(02 0000)
@="WMPlayer MusicPropPage Class"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{405DE7C0-E7DD-11D2-92C5-00C0F01F77C1}]
@DACL=(02 0000)
@="AutoStream Class"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{41926230-C58D-4e03-A96B-7121A9B5BB48}]
@DACL=(02 0000)
@="IE Packed Property Storage Object"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{41B21542-2055-4212-A6F2-395CD109B14B}]
@DACL=(02 0000)
"InstanceID"="{41B21542-2055-4212-A6F2-76-1005841775-ST12OI+1-DDT+0-EULA+1-ST12APP+1395CD109B14B}"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{4200E758-83F9-4843-9971-6B5A6446AB93}]
@DACL=(02 0000)
@SACL=
@="CDeviceList Object"
"AppID"="{1DCFDF9F-1241-4B40-9B01-B447643E15E1}"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{424B71AF-0695-11D2-A484-00C04F8EFB69}\Implemented Categories]
@DACL=(02 0000)
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{424FFED7-6BD1-414C-88D8-3BB3A5EC7404}]
@DACL=(02 0000)
@SACL=
@="CapturerCtrl Class"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{429075DD-2586-4B9B-A752-F5E6066A9659}]
@DACL=(02 0000)
@SACL=
@="RTStreamSink"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{42C419BE-9376-4b71-B8B3-335507A52569}]
@DACL=(02 0000)
@="HPSIProductCollection Class"
"AppID"="{5F2F4FF3-9F5E-4774-AF1C-401626772B9D}"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{43324B33-A78F-480F-9111-9638AACCC832}]
@DACL=(02 0000)
"Version"="1.0.0.0"
"SpecVersion"="1.0.0.0"
"Vendor"="{F0E749CA-EDEF-4589-A73A-EE0E626A2A2B}"
"MetadataFormat"="{79007028-268D-45D6-A3C2-354E6A504BC9}"
"RequiresFullStream"=dword:00000000
"FixedSize"=dword:00000001
"Author"="Microsoft"
"FriendlyName"="App0 Reader"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{4352D88A-78AA-45D6-D12F-0020AFC36E79}]
@Class="MS"
@DACL=(02 0000)
@="Microsoft Office 2000 Professional"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{4356b08e-ecb5-43d1-8e9f-7bef4fc960fe}]
@DACL=(02 0000)
@="Manage Add-ons Admin Broker"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{43886CD5-6529-41c4-A707-7B3C92C05E68}]
@DACL=(02 0000)
@="IE Navigation Bar"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{43B36225-3A02-4097-87F2-B8D89ED5CE02}]
@DACL=(02 0000)
@="Citrix GoToMeeting Video Streaming Helper"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{43F8F289-7A20-11D0-8F06-00C04FC295E1}]
@DACL=(02 0000)
@="CEnroll Class"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{44121072-A222-48f2-A58A-6D9AD51EBBE9}]
@DACL=(02 0000)
@="Windows XPS Document Thumbnail Handler"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{447EDBE5-0080-4036-A0BB-7B84C58C604F}]
@DACL=(02 0000)
@="IEDataObjectWrapper"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{44C76ECD-F7FA-411c-9929-1B77BA77F524}]
@DACL=(02 0000)
@="IE Menu Site"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{44CCBCEB-BA7E-4C99-A078-9F683832D493}]
@DACL=(02 0000)
@="RealPlayer RMP Download Handler"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{44EC053A-400F-11D0-9DCD-00A0C90391D3}]
@DACL=(02 0000)
@="Registrar Class"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{4516CEE1-97DA-4030-A444-2D8E296B96B6}]
@DACL=(02 0000)
@="IE Property Store Over Property Set Storage"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{45670FA8-ED97-4F44-BC93-305082590BFB}]
@DACL=(02 0000)
@="Windows XPS Document Metadata Handler"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{466B7B30-E1A1-4DDB-A63E-5AF5324A135C}]
@DACL=(02 0000)
@SACL=
@="Plugin Class"
"AppID"="{E64B9750-B96E-48E0-B698-0A2E0F638256}"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{46754C1C-1AEC-4EDC-A735-527FAEDB28F2}]
@DACL=(02 0000)
@SACL=
@="EdgeEffect Class"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{477A3783-2D4D-11D3-B244-444553540000}]
@DACL=(02 0000)
@="EncodeMP3Mem2 Class"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{477A3785-2D4D-11D3-B244-444553540000}]
@DACL=(02 0000)
@="QueryWavFile2 Class"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{477A3787-2D4D-11D3-B244-444553540000}]
@DACL=(02 0000)
@="QueryMPEGAudioFile2 Class"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{477A3789-2D4D-11D3-B244-444553540000}]
@DACL=(02 0000)
@="MP3Encoder3 Class"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{479CF9A8-1A3D-40F3-A44C-331AE3AD2FC9}]
@DACL=(02 0000)
@SACL=
@="QuickTimeSink Filter Audio Properties"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{47f59200-8783-11d2-8343-00a0c945a819}]
@DACL=(02 0000)
@SACL=
@="RFXInstMgr Class"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{480C8E9E-3EB1-4EFE-A701-E0418D0BDB42}]
@DACL=(02 0000)
@SACL=
@="BlurEffect Class"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{48123BC4-99D9-11D1-A6B3-00C04FD91555}]
@DACL=(02 0000)
@="XML Document"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{48EF620C-07E8-45B1-9BEF-34F35644DA44}]
@DACL=(02 0000)
@SACL=
@="MVTextTypewriter Class"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{49280074-3580-4875-9D27-3DF3BC42F686}]
@DACL=(02 0000)
@SACL=
@="Audio Decoder Property Page"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{498B0949-BBE9-4072-98BE-6CCAEB79DC6F}]
@DACL=(02 0000)
@="SmartRenderEngine Class"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{49FC0185-4B32-11d1-A40E-00600831F336}]
@DACL=(02 0000)
@="DSDisplayPanel Class"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{4A65D267-1539-4BD1-921D-1C49B3E58EB7}]
@DACL=(02 0000)
@="SnapInFailureReporter"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{4B428940-263C-11D1-A520-000000000000}\InprocServer32]
@DACL=(02 0000)
@="c:\\WINDOWS\\system32\\wmpasf.dll"
"ThreadingModel"="Both"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{4B59AFCC-B8C3-408A-B670-89E5FAB6FDA7}]
@DACL=(02 0000)
"Version"="1.0.0.0"
"SpecVersion"="1.0.0.0"
"Vendor"="{F0E749CA-EDEF-4589-A73A-EE0E626A2A2B}"
"MetadataFormat"="{568D8936-C0A9-4923-905D-DF2B38238FBC}"
"FixedSize"=dword:00000001
"SupportsPadding"=dword:00000000
"RequiresFullStream"=dword:00000000
"Author"="Microsoft"
"FriendlyName"="Chunk tEXt Reader"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{4b6657e4-b973-46cd-9bb3-6e5ebd82448f}]
@DACL=(02 0000)
@="PortableDeviceWMDRM Class"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{4B66DD3F-2E6E-4F7C-B38C-E32608820825}]
@DACL=(02 0000)
@="VSPMgr Class"
"AppID"="{4848DD90-EDA2-461F-8FE9-B47A067A5225}"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{4B78D326-D922-44f9-AF2A-07805C2A3560}]
@DACL=(02 0000)
@="IE Menu Band"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{4BB0DF0A-DF9C-4F0A-BB11-A036EF0E4850}]
@DACL=(02 0000)
@SACL=
@="IShareDevice Class"
"AppID"=""
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{4BCC3139-A650-46B7-B017-52BE66D2FF4B}]
@DACL=(02 0000)
@SACL=
@="CyberLink RC Engine V3"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{4BDB35AC-F955-43DD-932C-C7DDF084E12F}]
@DACL=(02 0000)
@SACL=
@="MVStyleInfo Class"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{4BDD6232-2E55-4A1F-AAAD-961D76F439BA}]
@Class="REG_SZ"
@DACL=(02 0000)
@="PSFactoryBuffer"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{4BE1F202-E872-4127-8E3F-A24A4A021203}]
@DACL=(02 0000)
@SACL=
@="hpqWmiEvents Class"
"AppID"="{0018752E-7735-4B30-9DA9-4A01F024F270}"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{4C2D6B0F-CA59-488F-99B4-F371BC57860E}]
@DACL=(02 0000)
@SACL=
@="Display Class"
"AppID"="{BAADDB7E-306C-4D05-B48B-639340EBBBEA}"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{4c5e637a-16c7-4de3-9c46-5ed22181962d}]
@DACL=(02 0000)
@="XAudio2"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{4C6470A6-3F91-4f41-850B-DB9BCD074537}]
@DACL=(02 0000)
@="Microsoft Feeds Background Sync Component"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{4c9b6dde-6809-46e6-a278-9b6a97588670}]
@DACL=(02 0000)
@="XAudio2"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{4cadfae1-5512-456a-9d65-5b5e7e9ca9a3}]
@DACL=(02 0000)
@="PortableDeviceClassExtension Class"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{4CB43D7F-7EEE-4906-8698-60DA1C38F2FE}]
@DACL=(02 0000)
@="UpdateSession Class"
"AppID"="{B366DEBE-645B-43A5-B865-DDD82C345492}"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{4D3FDFD4-63B1-48E7-B946-0A7DADDA5B76}]
@DACL=(02 0000)
@SACL=
@="MVTextFlashesOfColor Class"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{4D50EBC1-F054-4110-8D92-700E630361A6}]
@DACL=(02 0000)
@="RPHttpPlugProt Class"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{4D796619-AEDC-40FF-B225-2824230B9CCB}]
@DACL=(02 0000)
@SACL=
@="QuickCheck Class"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{4DD441AD-526D-4A77-9F1B-9841ED802FB0}]
@DACL=(02 0000)
@="SAXAttributes"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{4DFED3F9-B794-4d3c-973B-DDA1C28105A9}]
@DACL=(02 0000)
@="Private Profile Object"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{4eb2f086-c818-447e-b32c-c51ce2b30d31}]
@DACL=(02 0000)
@="Microsoft RDP Client Control"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{4eb89ff4-7f78-4a0f-8b8d-2bf02e94e4b2}]
@DACL=(02 0000)
@="Microsoft Terminal Services Client Control (redist)"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{4EDCB26C-D24C-4e72-AF07-B576699AC0DE}]
@DACL=(02 0000)
@="Microsoft Terminal Services Client Control (redist)"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{4F695794-BFCF-48B0-A323-F874F9BD45F2}]
@DACL=(02 0000)
@="Windows Media Player WMEncFileTransferSource Class"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{50040C1D-BDBF-4924-B873-F14D6C5BFD66}]
@DACL=(02 0000)
@="MediaDevMgrClassFactory Class"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{50156BF7-5EBF-480F-B916-DC8B54BC60F9}]
@DACL=(02 0000)
@SACL=
@="CyberLink Audio Property Page"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{506D89AE-909A-44f7-9444-ABD575896E35}]
@DACL=(02 0000)
@="DxtAlphaSetter Class"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{509C4001-13C5-11D5-8F2A-0080C84E9C39}]
@Class="REG_SZ"
@DACL=(02 0000)
@SACL=
@="PSFactoryBuffer"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{50D42F09-ECD1-4B41-B65D-DA1FDAA75663}]
@DACL=(02 0000)
"Version"="1.0.0.0"
"SpecVersion"="1.0.0.0"
"Vendor"="{F0E749CA-EDEF-4589-A73A-EE0E626A2A2B}"
"MetadataFormat"="{58A2E128-2DB9-4E57-BB14-5177891ED331}"
"RequiresFullStream"=dword:00000001
"SupportsPadding"=dword:00000001
"Author"="Microsoft"
"FriendlyName"="SubIFD Reader"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{50F16B26-467E-11D1-8271-00C04FC3183B}]
@DACL=(02 0000)
@="Preview Class"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{51B3B655-7E45-4494-9983-4BACF0E0A834}]
@DACL=(02 0000)
@="HPSimpleProductCollection Class"
"AppID"="{5F2F4FF3-9F5E-4774-AF1C-401626772B9D}"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{51B8E419-B532-49F5-9E77-F62D1A147660}]
@DACL=(02 0000)
@SACL=
@="IZoneList"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{5210f8e4-b0bb-47c3-a8d9-7b2282cc79ed}]
@DACL=(02 0000)
@SACL=
@="WMAPro over S/PDIF DMO"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{525609F4-D232-11D0-B76F-00C04FC9BCC4}]
@DACL=(02 0000)
@="AppleTalk Configuration Notify Object"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{528d46b3-3a4b-4b13-bf74-d9cbd7306e07}]
@DACL=(02 0000)
@="XML Feed Document"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{52a2aaae-085d-4187-97ea-8c30db990436}]
@DACL=(02 0000)
@SACL=
@="HHCtrl Object"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{52e4e90a-f4af-460a-9e60-fdfb86c9dd5d}]
@DACL=(02 0000)
@="Windows Media Player WMEncoder Class"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{53362C32-A296-4F2D-A2F8-FD984D08340B}\Version]
@DACL=(02 0000)
@="1.0"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{5349B405-C992-4A4D-8EB8-5D237C5A0623}]
@DACL=(02 0000)
@="GoogleBarControl Class"
"AppID"="{1F7595F7-05C5-489E-BB9F-6BA11ECD0CA0}"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{53510d24-57eb-4713-9afb-e6e60530b87e}]
@DACL=(02 0000)
@="IE RSS Feeds Tasks"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{53BA84DF-97F6-448D-8DCD-BA16D7C5215C}]
@DACL=(02 0000)
@SACL=
@="Chaplinesque Class"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{540D8A8B-1C3F-4E32-8132-530F6A502090}\Implemented Categories]
@DACL=(02 0000)
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{54660448-8CA0-416D-A2FF-849ADFC2A0EA}]
@DACL=(02 0000)
@SACL=
@="CyberLink DVD Navigator Property Page"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{54702535-2606-11D1-999C-0000F8756A10}\Implemented Categories]
@DACL=(02 0000)
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{54b68bc7-3a45-416b-a8c9-19bf19ec1df5}]
@DACL=(02 0000)
@="XACT Engine"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{54BA1E8F-818D-407F-949D-BAE1692C5C18}]
@DACL=(02 0000)
@SACL=
@="Attribute Class"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{54CE37E0-9834-41ae-9896-4DAB69DC022B}]
@DACL=(02 0000)
@="Microsoft Terminal Services Client Control (redist)"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{550DDA30-0541-11D2-9CA9-0060B0EC3D39}]
@DACL=(02 0000)
@="XML Data Source Object"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{553858A7-4922-4e7e-B1C1-97140C1C16EF}]
@DACL=(02 0000)
@="IE Component Categories cache daemon"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{5569e7f5-424b-4b93-89ca-79d17924689a}]
@DACL=(02 0000)
@="Windows Media Player Plug-in Registrar"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{55b70dec-4b3b-4e26-ae9c-9e8d131843a1}]
@DACL=(02 0000)
@="Microsoft Feeds Background Task Scheduling"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{566A2EFF-5651-4020-AC1A-EB48E4571EA3}]
@DACL=(02 0000)
@="Windows Media SDK HTTP Source Plugin"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{56DC1747-9BFB-479A-A2DB-E56C04588D83}]
@DACL=(02 0000)
@SACL=
@="WriterCtrl Class"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{57C06EAA-8784-11D0-83D4-00A0C911E5DF}]
@DACL=(02 0000)
@="Microsoft Client Configuration Notify Object"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{5897C539-6B62-40AD-A630-A349FFEF9731}]
@DACL=(02 0000)
@SACL=
@="WaterColourize Class"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{58AD93D5-0845-4834-B625-C4966DE9F72F}]
@DACL=(02 0000)
@SACL=
@="CProgressCallback Object"
"AppID"="{1DCFDF9F-1241-4B40-9B01-B447643E15E1}"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{593D79E0-F455-44C6-9DBF-1F008B1A5DB1}]
@DACL=(02 0000)
@SACL=
@="CyberLink DVD Navigator State"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{59803D7B-D6E4-4B89-864E-626EBB587BF4}]
@DACL=(02 0000)
@="MyDVDComm Class"
"AppID"="{E03E4D6B-DFF0-4A60-BB87-D0B2C12CFEAF}"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{5A41EFA3-6C01-43DC-8C49-110151B36C70}]
@DACL=(02 0000)
@SACL=
@="Line 21 Decoder Text Output"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{5a508685-a254-4fba-9b82-9a24b00306af}]
@DACL=(02 0000)
@="XAudio2"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{5AFAFE48-7107-4FE5-B21A-86A4254541DD}]
@DACL=(02 0000)
@SACL=
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{5B035261-40F9-11D1-AAEC-00805FC1270E}]
@DACL=(02 0000)
@="Network Configuration Component Object"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{5BAF654A-5A07-4264-A255-9FF54C7151E7}]
@DACL=(02 0000)
@="UpdateDownloader Class"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{5BEDF7DE-98CF-11D0-B255-00C04FC9E292}]
@DACL=(02 0000)
@="NWLink Client Configuration Notify Object"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{5C140836-43DE-11d3-847D-00C04F79DBC0}]
@DACL=(02 0000)
@="SCPTRANS Class"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{5C5C1935-0235-4434-80BC-251BC1EC39C6}]
@DACL=(02 0000)
"Version"="1.0.0.0"
"SpecVersion"="1.0.0.0"
"Vendor"="{F0E749CA-EDEF-4589-A73A-EE0E626A2A2B}"
"MetadataFormat"="{16100D66-8570-4BB9-B92D-FDA4B23ECE67}"
"RequiresFullStream"=dword:00000000
"SupportsPadding"=dword:00000000
"Author"="Microsoft"
"FriendlyName"="IRB Writer"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{5C85DCB0-F967-11D0-81ED-00C04FC99D4C}]
@DACL=(02 0000)
@="ppDShowNet Class"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{5CA3D70E-1895-11CF-8E15-001234567890}]
@DACL=(02 0000)
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{5D89D319-9BF6-4B2E-8748-72941E6633EE}]
@DACL=(02 0000)
@="Destroy Class"
"AppID"="{DFBF6E48-5D65-4C3A-BBDA-5871CAFED233}"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{6038EF75-ABFC-4e59-AB6F-12D397F6568D}]
@DACL=(02 0000)
@="IE Microsoft History AutoComplete List"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{60a90a2f-858d-42af-8929-82be9d99e8a1}]
@DACL=(02 0000)
@="UIAutomationCrossBitnessHook32 Class"
"AppID"="{60a90a2f-858d-42af-8929-82be9d99e8a1}"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{60A9863A-11FD-4080-850E-A8E184FC3A3C}]
@DACL=(02 0000)
@SACL=
@="Signer Class"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{60C70E11-2B08-4798-B366-C8450CDA7B1A}]
@DACL=(02 0000)
@SACL=
@="SYMLCEng Class"
"AppID"="{E39D1C81-7E76-4d84-9F25-E2CC76EC050B}"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{6214E226-594F-4AB2-AD56-B7047D9E18C6}]
@DACL=(02 0000)
@SACL=
@="CyberLink Device Dector"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{629cf0de-3ecc-41e7-9926-f7e43eebec51}]
@DACL=(02 0000)
@="AudioReverb"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{62AD397F-19EB-47F5-8A31-06D544E7E0A4}]
@DACL=(02 0000)
@SACL=
@="CyberLink AudioCD Property Page"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{62DDEB79-15B2-41E3-8834-D3B80493887A}]
@DACL=(02 0000)
@SACL=
@="HPInfo Class"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{631C66E1-B5F3-48AD-9B8B-448728CB427A}]
@DACL=(02 0000)
@SACL=
@="CyberLink Demultiplexer (HP_QP2005)"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{63A865AB-859E-4f15-8AEC-77FC615653D9}]
@DACL=(02 0000)
@="WMPlayer FileFormatPropPage Class"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{63B01F2F-AF5F-4C65-8A74-86C66A38F8D0}]
@DACL=(02 0000)
@SACL=
@="Rotate Class"
"AppID"="{BAADDB7E-306C-4D05-B48B-639340EBBBEA}"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{63D853E0-0154-4133-9F58-CC8255ECA98B}]
@DACL=(02 0000)
@SACL=
@="AffineTransform Class"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{63F8AA94-E2B9-11D0-ADF6-00C04FB66DAD}\InprocServer32]
@DACL=(02 0000)
@="c:\\WINDOWS\\system32\\wmpasf.dll"
"ThreadingModel"="Both"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{63FA5E69-87FE-432d-8F62-9D7A3D7D09C3}]
@DACL=(02 0000)
@="WMPlayer VideoPerfPropPage Class"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{640167b4-59b0-47a6-b335-a6b3c0695aea}]
@DACL=(02 0000)
@="Portable Media Devices"
"LocalizedString"=expand:"@%SystemRoot%\\system32\\Audiodev.dll,-510"
"InfoTip"=expand:"@%SystemRoot%\\system32\\Audiodev.dll,-512"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{640999A0-A946-11D0-A520-000000000000}\InprocServer32]
@DACL=(02 0000)
@="c:\\WINDOWS\\system32\\wmpasf.dll"
"ThreadingModel"="Both"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{640999A1-A946-11D0-A520-000000000000}\InprocServer32]
@DACL=(02 0000)
@="c:\\WINDOWS\\system32\\wmpasf.dll"
"ThreadingModel"="Both"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{640999A2-A946-11D0-A520-000000000000}\InprocServer32]
@DACL=(02 0000)
@="c:\\WINDOWS\\system32\\wmpasf.dll"
"ThreadingModel"="Both"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{6414512B-B978-451D-A0D8-FCFDF33E833C}]
@DACL=(02 0000)
@="WUWebControl Class"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{645FF040-5081-101B-9F08-00AA002F954E}\Shell]
@DACL=(02 0000)
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{64D8A8E0-80A2-11d2-8CF3-00A0C9441E20}]
@DACL=(02 0000)
@="RenderEngine Class"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{650503CF-9108-4DDC-A2CE-6C2341E1C582}]
@DACL=(02 0000)
@="WebProxy Class"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{65104D73-BA60-4160-A95A-4B4782E7AA62}]
@DACL=(02 0000)
@SACL=
@="Chain Class"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{656FAD09-4DE3-4c34-9600-0928C855FD7A}]
@DACL=(02 0000)
@SACL=
@="AxTaskList Class"
"AppID"=""
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{65d822a4-4799-42c6-9b18-d26cf66dd320}]
@DACL=(02 0000)
@="XACT Engine"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{65E88FD4-F43F-461F-99E9-DA242453349D}]
@DACL=(02 0000)
@SACL=
@="IPort"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{674D3E3D-A1A8-11D0-A886-00C04FC99C9C}]
@DACL=(02 0000)
@="ATMUNI Call Manager Configuration Notify Object"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{6754145F-EA9E-4127-B5A9-736B4EC44D14}]
@DACL=(02 0000)
@SACL=
@="UTF8 Class"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{67841b03-c689-4188-ad3f-4c9ebeec710b}]
@DACL=(02 0000)
@SACL=
@="WM Speech Encoder DMO"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{67E76F1D-BDE2-4052-913C-2752366192D2}]
@DACL=(02 0000)
@="RealNetworks Scheduler"
"AppID"="{9E6AF5D5-3516-41c0-91C7-6460D2362198}"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{6876F94D-1237-402D-BABD-DB80D226F1FC}]
@DACL=(02 0000)
@="TWC Class"
"AppID"="{A019B71E-8FF7-4704-A894-3D6B695C73AC}"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{68961B23-E3E2-4D7C-9072-6363436C1B25}\ClassData]
@DACL=(02 0000)
@SACL=
"DefMfg"="Hewlett-Packard"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{699745C2-5066-4B82-A8E3-D40478DBEC8C}]
@DACL=(02 0000)
"Version"="1.0.0.0"
"SpecVersion"="1.0.0.0"
"Vendor"="{F0E749CA-EDEF-4589-A73A-EE0E626A2A2B}"
"MetadataFormat"="{A45E592F-9078-4A7C-ADB5-4EDC4FD61B1F}"
"FixedSize"=dword:00000001
"Author"="Microsoft"
"FriendlyName"="Unknown Reader"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{69A597A0-D1B6-11D4-8297-0050BAC1E668}]
@DACL=(02 0000)
@SACL=
@="CyberLink PSI Property Page"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{69BE8BB4-D66D-47C8-865A-ED1589433782}]
@DACL=(02 0000)
"ContainerFormat"="{0AF1D87E-FCFE-4188-BDEB-A7906471CBE3}"
"Vendor"="{F0E749CA-EDEF-4589-A73A-EE0E626A2A2B}"
"Version"="1.0.0.0"
"SpecVersion"="1.0.0.0"
"ColorManagementVersion"="1.0.0.0"
"MimeTypes"="image/bmp"
"FileExtensions"=".bmp,.dib,.rle"
"SupportAnimation"=dword:00000000
"SupportChromakey"=dword:00000000
"SupportLossless"=dword:00000001
"SupportMultiframe"=dword:00000000
"Author"="Microsoft"
"FriendlyName"="BMP Encoder"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{6A6F4B83-45C5-4ca9-BDD9-0D81C12295E4}]
@DACL=(02 0000)
@="Microsoft Terminal Services Client Control (redist)"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{6a93130e-1d53-41d1-a9cf-e758800bb179}]
@DACL=(02 0000)
@="AudioReverb"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{6AE29350-321B-42be-BBE5-12FB5270C0DE}]
@DACL=(02 0000)
@="Microsoft RDP Client Control"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{6B00963C-E4EB-41c8-A0D3-92B6CF7AF951}]
@DACL=(02 0000)
@="Microsoft RAS Enforcement Client Callback Component"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{6B13B293-30FD-4abb-8E41-29B1F88297E2}]
@DACL=(02 0000)
@="Windows Media Player OCXGeneralPropPage Class"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{6B462062-7CBF-400D-9FDB-813DD10F2778}]
@DACL=(02 0000)
"ContainerFormat"="{0AF1D87E-FCFE-4188-BDEB-A7906471CBE3}"
"Vendor"="{F0E749CA-EDEF-4589-A73A-EE0E626A2A2B}"
"Version"="1.0.0.0"
"SpecVersion"="1.0.0.0"
"ColorManagementVersion"="1.0.0.0"
"MimeTypes"="image/bmp"
"FileExtensions"=".bmp,.dib,.rle"
"SupportAnimation"=dword:00000000
"SupportChromakey"=dword:00000000
"SupportLossless"=dword:00000001
"SupportMultiframe"=dword:00000000
"Author"="Microsoft"
"FriendlyName"="BMP Decoder"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{6B4ECC4F-16D1-4474-94AB-5A763F2A54AE}]
@DACL=(02 0000)
@="IE Tracking Shell Menu"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{6B6D0800-9ADA-11D0-A520-00A0D10129C0}\InprocServer32]
@DACL=(02 0000)
@="c:\\WINDOWS\\system32\\wmpasf.dll"
"ThreadingModel"="Both"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{6BD2A052-14AF-462E-BEA9-534BDFBB5521}]
@DACL=(02 0000)
@SACL=
@="AngelicText Class"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{6BF52A52-394A-11d3-B153-00C04F79FAA6}]
@DACL=(02 0000)
@="Windows Media Player"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{6CEA2FA8-43E1-4554-87E7-C290E0A2EC39}]
@DACL=(02 0000)
@SACL=
@="CInstantShareDevice Object"
"AppID"="{1DCFDF9F-1241-4B40-9B01-B447643E15E1}"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{6CF48EF8-44CD-45d2-8832-A16EA016311B}]
@DACL=(02 0000)
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{6D68D1DE-D432-4B0F-923A-091183A9BDA7}]
@DACL=(02 0000)
"Version"="1.0.0.0"
"SpecVersion"="1.0.0.0"
"Vendor"="{F0E749CA-EDEF-4589-A73A-EE0E626A2A2B}"
"MetadataFormat"="{63E8DF02-EB6C-456C-A224-B25E794FD648}"
"RequiresFullStream"=dword:00000000
"SupportsPadding"=dword:00000000
"Author"="Microsoft"
"FriendlyName"="XMP Seq Writer"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{6E1E5E54-C586-4F67-BBE0-62617C1F488D}]
@DACL=(02 0000)
@SACL=
@="Sonic Audio Depth Converter"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{6e29fabf-9977-42d1-8d0e-ca7e61ad87e6}]
@DACL=(02 0000)
@="UIAutomation Registrar Class"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{6E65CBC0-926D-11D0-8E27-00C04FC99DCF}]
@DACL=(02 0000)
@="Dial-Up Client Configuration Notify Object"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{6E65CBC1-926D-11D0-8E27-00C04FC99DCF}]
@DACL=(02 0000)
@="Dial-Up Server Configuration Notify Object"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{6E65CBC3-926D-11D0-8E27-00C04FC99DCF}]
@DACL=(02 0000)
@="NdisWan Configuration Notify Object"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{6E65CBC4-926D-11D0-8E27-00C04FC99DCF}]
@DACL=(02 0000)
@="PPTP Configuration Configuration Notify Object"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{6E65CBC5-926D-11D0-8E27-00C04FC99DCF}]
@DACL=(02 0000)
@="Steelhead Router Configuration Notify Object"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{6E65CBC6-926D-11D0-8E27-00C04FC99DCF}]
@DACL=(02 0000)
@="L2TP Configuration Configuration Notify Object"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{6efeae9e-014c-436a-8aac-35da9535adc0}]
@DACL=(02 0000)
@="Windows Media Player InputCollection Class"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{6F13DD2E-EBEE-4DD5-A72E-850B2087F5DD}]
@DACL=(02 0000)
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{6f237df9-9ddb-47ad-b218-400d54c286ad}]
@DACL=(02 0000)
@="IE Property Adapter Over Property Store"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{6f6ea3a9-2cf5-41cf-91c1-2170b1540063}]
@DACL=(02 0000)
@="AudioReverb"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{6F8DAE82-43A2-47AA-B0E7-47B7E82F705F}]
@DACL=(02 0000)
@SACL=
@="WMEncSourcePluginWrapper"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{6FDDC324-4E03-4BFE-B185-3D77768DC901}]
@DACL=(02 0000)
"Author"="Microsoft"
"FriendlyName"="1bpp Indexed"
"ChannelCount"=dword:00000001
"BitLength"=dword:00000001
"ColorProfile"="sRGB Color Space Profile.icm"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{6FDDC324-4E03-4BFE-B185-3D77768DC902}]
@DACL=(02 0000)
"Author"="Microsoft"
"FriendlyName"="2bpp Indexed"
"ChannelCount"=dword:00000001
"BitLength"=dword:00000002
"ColorProfile"="sRGB Color Space Profile.icm"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{6FDDC324-4E03-4BFE-B185-3D77768DC903}]
@DACL=(02 0000)
"Author"="Microsoft"
"FriendlyName"="4bpp Indexed"
"ChannelCount"=dword:00000001
"BitLength"=dword:00000004
"ColorProfile"="sRGB Color Space Profile.icm"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{6FDDC324-4E03-4BFE-B185-3D77768DC904}]
@DACL=(02 0000)
"Author"="Microsoft"
"FriendlyName"="8bpp Indexed"
"ChannelCount"=dword:00000001
"BitLength"=dword:00000008
"ColorProfile"="sRGB Color Space Profile.icm"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{6FDDC324-4E03-4BFE-B185-3D77768DC905}]
@DACL=(02 0000)
"Author"="Microsoft"
"FriendlyName"="Black and White"
"ChannelCount"=dword:00000001
"BitLength"=dword:00000001
"ColorProfile"="sRGB Color Space Profile.icm"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{6FDDC324-4E03-4BFE-B185-3D77768DC906}]
@DACL=(02 0000)
"Author"="Microsoft"
"FriendlyName"="2bpp Gray"
"ChannelCount"=dword:00000001
"BitLength"=dword:00000002
"ColorProfile"="sRGB Color Space Profile.icm"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{6FDDC324-4E03-4BFE-B185-3D77768DC907}]
@DACL=(02 0000)
"Author"="Microsoft"
"FriendlyName"="4bpp Gray"
"ChannelCount"=dword:00000001
"BitLength"=dword:00000004
"ColorProfile"="sRGB Color Space Profile.icm"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{6FDDC324-4E03-4BFE-B185-3D77768DC908}]
@DACL=(02 0000)
"Author"="Microsoft"
"FriendlyName"="8bpp Gray"
"ChannelCount"=dword:00000001
"BitLength"=dword:00000008
"ColorProfile"="sRGB Color Space Profile.icm"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{6FDDC324-4E03-4BFE-B185-3D77768DC909}]
@DACL=(02 0000)
"Author"="Microsoft"
"FriendlyName"="16bpp RGB555"
"ChannelCount"=dword:00000003
"BitLength"=dword:00000010
"ColorProfile"="sRGB Color Space Profile.icm"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{6FDDC324-4E03-4BFE-B185-3D77768DC90A}]
@DACL=(02 0000)
"Author"="Microsoft"
"FriendlyName"="16bpp RGB565"
"ChannelCount"=dword:00000003
"BitLength"=dword:00000010
"ColorProfile"="sRGB Color Space Profile.icm"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{6FDDC324-4E03-4BFE-B185-3D77768DC90B}]
@DACL=(02 0000)
"Author"="Microsoft"
"FriendlyName"="16bpp Gray"
"ChannelCount"=dword:00000001
"BitLength"=dword:00000010
"ColorProfile"="sRGB Color Space Profile.icm"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{6FDDC324-4E03-4BFE-B185-3D77768DC90C}]
@DACL=(02 0000)
"Author"="Microsoft"
"FriendlyName"="24bpp BGR"
"ChannelCount"=dword:00000003
"BitLength"=dword:00000018
"ColorProfile"="sRGB Color Space Profile.icm"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{6FDDC324-4E03-4BFE-B185-3D77768DC90D}]
@DACL=(02 0000)
"Author"="Microsoft"
"FriendlyName"="24bpp RGB"
"ChannelCount"=dword:00000003
"BitLength"=dword:00000018
"ColorProfile"="sRGB Color Space Profile.icm"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{6FDDC324-4E03-4BFE-B185-3D77768DC90E}]
@D

#5 peaksmm

peaksmm
  • Topic Starter

  • Members
  • 32 posts
  • OFFLINE
  •  
  • Local time:07:01 AM

Posted 26 December 2015 - 03:50 PM

AND....


ACL=(02 0000)
"Author"="Microsoft"
"FriendlyName"="32bpp BGR"
"ChannelCount"=dword:00000003
"BitLength"=dword:00000020
"ColorProfile"="sRGB Color Space Profile.icm"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{6FDDC324-4E03-4BFE-B185-3D77768DC90F}]
@DACL=(02 0000)
"Author"="Microsoft"
"FriendlyName"="32bpp BGRA"
"ChannelCount"=dword:00000004
"BitLength"=dword:00000020
"ColorProfile"="sRGB Color Space Profile.icm"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{6FDDC324-4E03-4BFE-B185-3D77768DC910}]
@DACL=(02 0000)
"Author"="Microsoft"
"FriendlyName"="32bpp pBGRA"
"ChannelCount"=dword:00000004
"BitLength"=dword:00000020
"ColorProfile"="sRGB Color Space Profile.icm"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{6FDDC324-4E03-4BFE-B185-3D77768DC911}]
@DACL=(02 0000)
"Author"="Microsoft"
"FriendlyName"="32bpp Gray float"
"ChannelCount"=dword:00000001
"BitLength"=dword:00000020
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{6FDDC324-4E03-4BFE-B185-3D77768DC912}]
@DACL=(02 0000)
"Author"="Microsoft"
"FriendlyName"="48bpp RGB fixed"
"ChannelCount"=dword:00000003
"BitLength"=dword:00000030
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{6FDDC324-4E03-4BFE-B185-3D77768DC913}]
@DACL=(02 0000)
"Author"="Microsoft"
"FriendlyName"="16bpp Gray fixed"
"ChannelCount"=dword:00000001
"BitLength"=dword:00000010
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{6FDDC324-4E03-4BFE-B185-3D77768DC914}]
@DACL=(02 0000)
"Author"="Microsoft"
"FriendlyName"="32bpp RGB101010"
"ChannelCount"=dword:00000003
"BitLength"=dword:00000020
"ColorProfile"="sRGB Color Space Profile.icm"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{6FDDC324-4E03-4BFE-B185-3D77768DC915}]
@DACL=(02 0000)
"Author"="Microsoft"
"FriendlyName"="48bpp RGB"
"ChannelCount"=dword:00000003
"BitLength"=dword:00000030
"ColorProfile"="sRGB Color Space Profile.icm"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{6FDDC324-4E03-4BFE-B185-3D77768DC916}]
@DACL=(02 0000)
"Author"="Microsoft"
"FriendlyName"="64bpp RGBA"
"ChannelCount"=dword:00000004
"BitLength"=dword:00000040
"ColorProfile"="sRGB Color Space Profile.icm"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{6FDDC324-4E03-4BFE-B185-3D77768DC917}]
@DACL=(02 0000)
"Author"="Microsoft"
"FriendlyName"="64bpp pRGBA"
"ChannelCount"=dword:00000004
"BitLength"=dword:00000040
"ColorProfile"="sRGB Color Space Profile.icm"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{6FDDC324-4E03-4BFE-B185-3D77768DC918}]
@DACL=(02 0000)
"Author"="Microsoft"
"FriendlyName"="96bpp RGB fixed"
"ChannelCount"=dword:00000003
"BitLength"=dword:00000060
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{6FDDC324-4E03-4BFE-B185-3D77768DC919}]
@DACL=(02 0000)
"Author"="Microsoft"
"FriendlyName"="128bpp RGBA float"
"ChannelCount"=dword:00000004
"BitLength"=dword:00000080
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{6FDDC324-4E03-4BFE-B185-3D77768DC91A}]
@DACL=(02 0000)
"Author"="Microsoft"
"FriendlyName"="128bpp pRGBA float"
"ChannelCount"=dword:00000004
"BitLength"=dword:00000080
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{6FDDC324-4E03-4BFE-B185-3D77768DC91B}]
@DACL=(02 0000)
"Author"="Microsoft"
"FriendlyName"="128bpp RGB float"
"ChannelCount"=dword:00000003
"BitLength"=dword:00000080
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{6FDDC324-4E03-4BFE-B185-3D77768DC91C}]
@DACL=(02 0000)
"Author"="Microsoft"
"FriendlyName"="32bpp CMYK"
"ColorProfile"="RSWOP.ICM"
"ChannelCount"=dword:00000004
"BitLength"=dword:00000020
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{6FDDC324-4E03-4BFE-B185-3D77768DC91D}]
@DACL=(02 0000)
"Author"="Microsoft"
"FriendlyName"="64bpp RGBA fixed"
"ChannelCount"=dword:00000004
"BitLength"=dword:00000040
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{6FDDC324-4E03-4BFE-B185-3D77768DC91E}]
@DACL=(02 0000)
"Author"="Microsoft"
"FriendlyName"="128bpp RGBA fixed"
"ChannelCount"=dword:00000004
"BitLength"=dword:00000080
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{6FDDC324-4E03-4BFE-B185-3D77768DC91F}]
@DACL=(02 0000)
"Author"="Microsoft"
"FriendlyName"="64bpp CMYK"
"ColorProfile"="RSWOP.ICM"
"ChannelCount"=dword:00000004
"BitLength"=dword:00000040
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{6FDDC324-4E03-4BFE-B185-3D77768DC920}]
@DACL=(02 0000)
"Author"="Microsoft"
"FriendlyName"="24bpp 3 Channels"
"ColorProfile"="sRGB Color Space Profile.icm"
"ChannelCount"=dword:00000003
"BitLength"=dword:00000018
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{6FDDC324-4E03-4BFE-B185-3D77768DC921}]
@DACL=(02 0000)
"Author"="Microsoft"
"FriendlyName"="32bpp 4 Channels"
"ColorProfile"="RSWOP.ICM"
"ChannelCount"=dword:00000004
"BitLength"=dword:00000020
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{6FDDC324-4E03-4BFE-B185-3D77768DC922}]
@DACL=(02 0000)
"Author"="Microsoft"
"FriendlyName"="40bpp 5 Channels"
"ColorProfile"="RSWOP.ICM"
"ChannelCount"=dword:00000005
"BitLength"=dword:00000028
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{6FDDC324-4E03-4BFE-B185-3D77768DC923}]
@DACL=(02 0000)
"Author"="Microsoft"
"FriendlyName"="48bpp 6 Channels"
"ColorProfile"="RSWOP.ICM"
"ChannelCount"=dword:00000006
"BitLength"=dword:00000030
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{6FDDC324-4E03-4BFE-B185-3D77768DC924}]
@DACL=(02 0000)
"Author"="Microsoft"
"FriendlyName"="56bpp 7 Channels"
"ColorProfile"="RSWOP.ICM"
"ChannelCount"=dword:00000007
"BitLength"=dword:00000038
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{6FDDC324-4E03-4BFE-B185-3D77768DC925}]
@DACL=(02 0000)
"Author"="Microsoft"
"FriendlyName"="64bpp 8 Channels"
"ColorProfile"="RSWOP.ICM"
"ChannelCount"=dword:00000008
"BitLength"=dword:00000040
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{6FDDC324-4E03-4BFE-B185-3D77768DC926}]
@DACL=(02 0000)
"Author"="Microsoft"
"FriendlyName"="48bpp 3 Channels"
"ColorProfile"="RSWOP.ICM"
"ChannelCount"=dword:00000003
"BitLength"=dword:00000030
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{6FDDC324-4E03-4BFE-B185-3D77768DC927}]
@DACL=(02 0000)
"Author"="Microsoft"
"FriendlyName"="64bpp 4 Channels"
"ColorProfile"="RSWOP.ICM"
"ChannelCount"=dword:00000004
"BitLength"=dword:00000040
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{6FDDC324-4E03-4BFE-B185-3D77768DC928}]
@DACL=(02 0000)
"Author"="Microsoft"
"FriendlyName"="80bpp 5 Channels"
"ColorProfile"="RSWOP.ICM"
"ChannelCount"=dword:00000005
"BitLength"=dword:00000050
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{6FDDC324-4E03-4BFE-B185-3D77768DC929}]
@DACL=(02 0000)
"Author"="Microsoft"
"FriendlyName"="96bpp 6 Channels"
"ColorProfile"="RSWOP.ICM"
"ChannelCount"=dword:00000006
"BitLength"=dword:00000060
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{6FDDC324-4E03-4BFE-B185-3D77768DC92A}]
@DACL=(02 0000)
"Author"="Microsoft"
"FriendlyName"="112bpp 7 Channels"
"ColorProfile"="RSWOP.ICM"
"ChannelCount"=dword:00000007
"BitLength"=dword:00000070
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{6FDDC324-4E03-4BFE-B185-3D77768DC92B}]
@DACL=(02 0000)
"Author"="Microsoft"
"FriendlyName"="128bpp 8 Channels"
"ColorProfile"="RSWOP.ICM"
"ChannelCount"=dword:00000008
"BitLength"=dword:00000080
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{6FDDC324-4E03-4BFE-B185-3D77768DC92C}]
@DACL=(02 0000)
"Author"="Microsoft"
"FriendlyName"="40bpp CMYK with Alpha"
"ColorProfile"="RSWOP.ICM"
"ChannelCount"=dword:00000005
"BitLength"=dword:00000028
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{6FDDC324-4E03-4BFE-B185-3D77768DC92D}]
@DACL=(02 0000)
"Author"="Microsoft"
"FriendlyName"="80bpp CMYK with Alpha"
"ColorProfile"="RSWOP.ICM"
"ChannelCount"=dword:00000005
"BitLength"=dword:00000050
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{6FDDC324-4E03-4BFE-B185-3D77768DC92E}]
@DACL=(02 0000)
"Author"="Microsoft"
"FriendlyName"="32bpp 3 Channels with Alpha"
"ColorProfile"="sRGB Color Space Profile.icm"
"ChannelCount"=dword:00000004
"BitLength"=dword:00000020
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{6FDDC324-4E03-4BFE-B185-3D77768DC92F}]
@DACL=(02 0000)
"Author"="Microsoft"
"FriendlyName"="40bpp 4 Channels with Alpha"
"ColorProfile"="RSWOP.ICM"
"ChannelCount"=dword:00000005
"BitLength"=dword:00000028
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{6FDDC324-4E03-4BFE-B185-3D77768DC930}]
@DACL=(02 0000)
"Author"="Microsoft"
"FriendlyName"="48bpp 5 Channels with Alpha"
"ColorProfile"="RSWOP.ICM"
"ChannelCount"=dword:00000006
"BitLength"=dword:00000030
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{6FDDC324-4E03-4BFE-B185-3D77768DC931}]
@DACL=(02 0000)
"Author"="Microsoft"
"FriendlyName"="56bpp 6 Channels with Alpha"
"ColorProfile"="RSWOP.ICM"
"ChannelCount"=dword:00000007
"BitLength"=dword:00000038
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{6FDDC324-4E03-4BFE-B185-3D77768DC932}]
@DACL=(02 0000)
"Author"="Microsoft"
"FriendlyName"="64bpp 7 Channels with Alpha"
"ColorProfile"="RSWOP.ICM"
"ChannelCount"=dword:00000008
"BitLength"=dword:00000040
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{6FDDC324-4E03-4BFE-B185-3D77768DC933}]
@DACL=(02 0000)
"Author"="Microsoft"
"FriendlyName"="72bpp 8 Channels with Alpha"
"ColorProfile"="RSWOP.ICM"
"ChannelCount"=dword:00000009
"BitLength"=dword:00000048
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{6FDDC324-4E03-4BFE-B185-3D77768DC934}]
@DACL=(02 0000)
"Author"="Microsoft"
"FriendlyName"="64bpp 3 Channels with Alpha"
"ColorProfile"="sRGB Color Space Profile.icm"
"ChannelCount"=dword:00000004
"BitLength"=dword:00000040
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{6FDDC324-4E03-4BFE-B185-3D77768DC935}]
@DACL=(02 0000)
"Author"="Microsoft"
"FriendlyName"="80bpp 4 Channels with Alpha"
"ColorProfile"="RSWOP.ICM"
"ChannelCount"=dword:00000005
"BitLength"=dword:00000050
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{6FDDC324-4E03-4BFE-B185-3D77768DC936}]
@DACL=(02 0000)
"Author"="Microsoft"
"FriendlyName"="96bpp 5 Channels with Alpha"
"ColorProfile"="RSWOP.ICM"
"ChannelCount"=dword:00000006
"BitLength"=dword:00000060
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{6FDDC324-4E03-4BFE-B185-3D77768DC937}]
@DACL=(02 0000)
"Author"="Microsoft"
"FriendlyName"="112bpp 6 Channels with Alpha"
"ColorProfile"="RSWOP.ICM"
"ChannelCount"=dword:00000007
"BitLength"=dword:00000070
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{6FDDC324-4E03-4BFE-B185-3D77768DC938}]
@DACL=(02 0000)
"Author"="Microsoft"
"FriendlyName"="128bpp 7 Channels with Alpha"
"ColorProfile"="RSWOP.ICM"
"ChannelCount"=dword:00000008
"BitLength"=dword:00000080
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{6FDDC324-4E03-4BFE-B185-3D77768DC939}]
@DACL=(02 0000)
"Author"="Microsoft"
"FriendlyName"="144bpp 8 Channels with Alpha"
"ColorProfile"="RSWOP.ICM"
"ChannelCount"=dword:00000009
"BitLength"=dword:00000090
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{6FDDC324-4E03-4BFE-B185-3D77768DC93A}]
@DACL=(02 0000)
"Author"="Microsoft"
"FriendlyName"="64bpp RGBA half"
"ChannelCount"=dword:00000004
"BitLength"=dword:00000040
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{6FDDC324-4E03-4BFE-B185-3D77768DC93B}]
@DACL=(02 0000)
"Author"="Microsoft"
"FriendlyName"="48bpp RGB half"
"ChannelCount"=dword:00000003
"BitLength"=dword:00000030
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{6FDDC324-4E03-4BFE-B185-3D77768DC93D}]
@DACL=(02 0000)
"Author"="Microsoft"
"FriendlyName"="32bpp RGBE"
"ChannelCount"=dword:00000003
"BitLength"=dword:00000020
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{6FDDC324-4E03-4BFE-B185-3D77768DC93E}]
@DACL=(02 0000)
"Author"="Microsoft"
"FriendlyName"="16bpp Gray half"
"ChannelCount"=dword:00000001
"BitLength"=dword:00000010
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{6FDDC324-4E03-4BFE-B185-3D77768DC93F}]
@DACL=(02 0000)
"Author"="Microsoft"
"FriendlyName"="32bpp Gray fixed"
"ChannelCount"=dword:00000001
"BitLength"=dword:00000020
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{6FDDC324-4E03-4BFE-B185-3D77768DC940}]
@DACL=(02 0000)
"Author"="Microsoft"
"FriendlyName"="64bpp RGB fixed"
"ChannelCount"=dword:00000003
"BitLength"=dword:00000040
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{6FDDC324-4E03-4BFE-B185-3D77768DC941}]
@DACL=(02 0000)
"Author"="Microsoft"
"FriendlyName"="128bpp RGB fixed"
"ChannelCount"=dword:00000003
"BitLength"=dword:00000080
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{6FDDC324-4E03-4BFE-B185-3D77768DC942}]
@DACL=(02 0000)
"Author"="Microsoft"
"FriendlyName"="64bpp RGB half"
"ChannelCount"=dword:00000003
"BitLength"=dword:00000040
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{70F19422-7C80-4033-A4F9-2AADA5BB151A}]
@DACL=(02 0000)
@SACL=
@="CyberLink Audio PL2 Property Page"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{70f598e9-f4ab-495a-99e2-a7c4d3d89abf}]
@DACL=(02 0000)
@SACL=
@="WMAudio Encoder DMO"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{70f98452-3c38-4271-8e76-6f444852ebc8}]
@DACL=(02 0000)
@="PortableDeviceWiaCompat Class"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{7122A82D-E722-4AFC-AA87-EAA77D8CFCE1}]
@DACL=(02 0000)
@="Windows Media Player WMEnc5PointWavSource Class"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{7172D604-32E2-41d5-ABA0-6533DF0BD3D9}]
@DACL=(02 0000)
@="Device Class"
"AppID"="{5F2F4FF3-9F5E-4774-AF1C-401626772B9D}"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{7210ff00-0bcf-4dba-992a-80f60882922b}]
@DACL=(02 0000)
@="WinFX Bootstrapper for .xaml"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{723F8F32-213D-47E1-B412-688F305076AD}]
@DACL=(02 0000)
@="MultipleIconToaster Class"
"AppID"="{DFBF6E48-5D65-4C3A-BBDA-5871CAFED233}"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{724d43a1-0d85-11d4-9908-00400523e39a}]
@DACL=(02 0000)
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{727283A5-2269-4761-A81C-351B0D8DF364}]
@DACL=(02 0000)
@SACL=
@="CyberLink Audio CL Virtual Speaker Property Page"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{7285C18B-B3D3-4D96-8FDB-AA2E9DA61129}]
@DACL=(02 0000)
@="CDVB_NIT"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{728a21c5-3d9e-48d7-9810-864848f0f404}]
@DACL=(02 0000)
@="PortableDevice Class"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{72B624DF-AE11-4948-A65C-351EB0829419}]
@DACL=(02 0000)
"Version"="1.0.0.0"
"SpecVersion"="1.0.0.0"
"Vendor"="{F0E749CA-EDEF-4589-A73A-EE0E626A2A2B}"
"MetadataFormat"="{BB5ACC38-F216-4CEC-A6C5-5F6E739763A9}"
"RequiresFullStream"=dword:00000000
"SupportsPadding"=dword:00000001
"Author"="Microsoft"
"FriendlyName"="XMP Reader"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{72C97D74-7C3B-40AE-B77D-ABDB22EBA6FB}]
@DACL=(02 0000)
@="StringCollection Class"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{734d43a7-0d85-11d4-9908-00400523e39a}]
@DACL=(02 0000)
"f"=dword:565ff20c
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{737BC37A-80E9-446F-97A1-1004273545FB}]
@DACL=(02 0000)
@SACL=
@="CyberLink Audio TSXT Property Page"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{7390f3d8-0439-4c05-91e3-cf5cb290c3d0}]
@DACL=(02 0000)
@="Microsoft Terminal Services Client Control (redist)"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{73A0C1D7-6AC5-42E0-903B-2C9A205C60EB}]
@DACL=(02 0000)
@SACL=
@="IRuleList"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{73A4C9C1-D68D-11D0-98BF-00A0C90DC8D9}\PersistentHandler]
@DACL=(02 0000)
@="{098f2470-bae0-11cd-b579-08002b30bfeb}"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{73CFD649-CD48-4fd8-A272-2070EA56526B}]
@DACL=(02 0000)
@="IE BandProxy"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{73DA5D04-4347-45D3-A9DC-FAE9DDBE558D}]
@DACL=(02 0000)
@="CSectionList"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{7444C717-39BF-11D1-8CD9-00C04FC29D45}]
@DACL=(02 0000)
@="CryptPKO Class"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{7444C719-39BF-11D1-8CD9-00C04FC29D45}]
@DACL=(02 0000)
@="CryptSig Class"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{75847177-f077-4171-bd2c-a6bb2164fbd0}]
@DACL=(02 0000)
@="Private Profile Object"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{7584c670-2274-4efb-b00b-d6aaba6d3850}]
@DACL=(02 0000)
@="Microsoft Terminal Services Client Control (redist)"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{75D10B02-EDDC-444B-9FDC-511FD07E5C6F}]
@DACL=(02 0000)
@SACL=
@="QuickTimeRenderer Filter"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{760C4B83-E211-11D2-BF3E-00805FBE84A6}]
@DACL=(02 0000)
@="Windows Media Services DRM Storage object"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{7629CFA2-3FE5-101B-A3C9-08002B2F49FB}]
@DACL=(02 0000)
@="Common Dialog Open Property Page Object"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{7629CFA4-3FE5-101B-A3C9-08002B2F49FB}]
@DACL=(02 0000)
@="Common Dialog Color Property Page Object"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{7658F2A2-0A83-11d2-A484-00C04F8EFB69}\Implemented Categories]
@DACL=(02 0000)
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{766BF2AE-D650-11d1-9811-00C04FC31D2E}]
@DACL=(02 0000)
@="HomePage Class"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{7734D7CA-A810-4634-A32C-10F322EE0525}]
@DACL=(02 0000)
@="WildWebUI Class"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{777D0CFF-0375-43b9-8532-FB04A4903593}]
@DACL=(02 0000)
@="Windows Media Player Effects Activate"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{77c56bf4-18a1-42b0-88af-5072ce814949}]
@DACL=(02 0000)
@="XACT Engine"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{77F7F122-20B0-4117-A2FB-059D1FC88256}]
@DACL=(02 0000)
@="WPDServiceProvider Class"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{7835EAE8-BF14-49D1-93CE-533A407B2248}]
@DACL=(02 0000)
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{786A2CE2-916D-456F-BE64-FD2EBC57EA1E}]
@DACL=(02 0000)
@SACL=
@="MVTextPro Class"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{78766964-0000-0010-8000-00AA00389B71}]
@DACL=(02 0000)
@SACL=
@="DivX Decoder Filter"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{7886B467-66D4-4163-82BA-D9212FDB4CA8}]
@DACL=(02 0000)
@="Microsoft System Health Agent Callback Component"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{7888E5FE-6C66-4A34-B217-FA2292073F4A}]
@Class="REG_SZ"
@DACL=(02 0000)
@="PSFactoryBuffer"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{78AEE122-5292-4064-BC61-52B8B1C31E0E}]
@DACL=(02 0000)
@SACL=
@="PencilDrawing Class"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{78E61E52-0E57-4456-A2F2-517492BCBF8F}]
@DACL=(02 0000)
@SACL=
@="Store Class"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{7A61827D-D895-4699-8062-883B340055D6}]
@DACL=(02 0000)
@SACL=
@="MVTextVelvet Class"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{7A7FB085-6068-4898-8CCA-480A9187277C}]
@DACL=(02 0000)
@="iPodManager Class"
"AppID"="{250DD19F-6E7F-4BA3-9E1B-69E6CDC52F30}"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{7B19A919-A9D6-49E5-BD45-02C34E4E4CD5}]
@DACL=(02 0000)
"Version"="1.0.0.0"
"SpecVersion"="1.0.0.0"
"Vendor"="{F0E749CA-EDEF-4589-A73A-EE0E626A2A2B}"
"MetadataFormat"="{326556A2-F502-4354-9CC0-8E3F48EAF6B5}"
"RequiresFullStream"=dword:00000000
"SupportsPadding"=dword:00000000
"Author"="Microsoft"
"FriendlyName"="App13 Writer"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{7B8AD727-7812-4567-A323-3847051F3F05}]
@DACL=(02 0000)
@SACL=
@="GenericBlur Class"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{7bafb3b1-d8f4-4279-9253-27da423108de}]
@DACL=(02 0000)
@SACL=
@="WMV Screen decoder DMO"
"Merit"=dword:00800001
"WMSDKMerit"=dword:00000100
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{7BDC31F1-FF5D-4F00-AD3B-30A8C37C435B}]
@DACL=(02 0000)
@="HPSearchResults Class"
"AppID"="{5F2F4FF3-9F5E-4774-AF1C-401626772B9D}"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{7BF3AC5C-CC84-429A-ACA5-74D916AD6B8C}]
@DACL=(02 0000)
@SACL=
@="OID Class"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{7BFEACB2-97F5-4DC7-92E0-E69ED4C37C43}\InprocServer32]
@Denied: (C D 2 3 6) (Everyone)
"ThreadingModel"="Apartment"
@="c:\\Documents and Settings\\All Users\\Application Data\\{FB62659C-5547-4284-846F-24B4EEDF86F7}\\wshelper.dll"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{7CB359C5-570F-43c6-971F-1DB499EE57A1}]
@DACL=(02 0000)
@="WMPlayer PlaybackPropPage Class"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{7CCCACE3-3DEE-4659-93AA-19E6C38D8EEC}]
@DACL=(02 0000)
@="ServiceDiagnostics Class"
"AppID"="{250DD19F-6E7F-4BA3-9E1B-69E6CDC52F30}"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{7D4734E6-047E-41e2-AEAA-E763B4739DC4}]
@DACL=(02 0000)
@="WMP Play Folder As Playlist Launcher"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{7DE087A5-5DCB-4df7-BB12-0924AD8FBD9A}]
@DACL=(02 0000)
@="WSMan InternalAutomation Class"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{7E002E7C-1050-47DB-919A-8B7E09CA78F2}]
@DACL=(02 0000)
@SACL=
@="IntensityEffect Class"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{7e320092-596a-41b2-bbeb-175d10504eb6}]
@DACL=(02 0000)
@="WMVideo8 Encoder DMO"
"WMSDKMerit"=dword:00000100
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{7E3FCEA1-31B4-11D2-AE1F-0080C7337EA1}]
@DACL=(02 0000)
@="XML Viewer Moniker"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{7ED96837-96F0-4812-B211-F13C24117ED3}]
@DACL=(02 0000)
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{7EE0A24E-A8C6-46ae-A875-8E7C3D18AEAF}]
@DACL=(02 0000)
@="Favorites IFilter"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{7F12E753-FC71-43D7-A51D-92F35977ABB5}]
@DACL=(02 0000)
"Version"="1.0.0.0"
"SpecVersion"="1.0.0.0"
"Vendor"="{F0E749CA-EDEF-4589-A73A-EE0E626A2A2B}"
"MetadataFormat"="{63E8DF02-EB6C-456C-A224-B25E794FD648}"
"RequiresFullStream"=dword:00000000
"SupportsPadding"=dword:00000000
"Author"="Microsoft"
"FriendlyName"="XMP Seq Reader"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{7F368827-9516-11D0-83D9-00A0C911E5DF}]
@DACL=(02 0000)
@="Microsoft Server Configuration Notify Object"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{7F4824E8-21D1-4a62-BD34-AB670833DFB6}]
@DACL=(02 0000)
@SACL=
@="MSN Money Screener"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{7f5d25f8-78a5-49a8-a33c-2c0e11831c66}]
@DACL=(02 0000)
@="WMDRM Context"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{7F67036B-66F1-411A-AD85-759FB9C5B0DB}]
@DACL=(02 0000)
@SACL=
@="ShellViewRTF"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{7F73B8F6-C19C-11D0-AA66-00C04FC2EDDC}]
@DACL=(02 0000)
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{7FC51766-A96F-48BC-9C44-50AC6CC1FC2E}]
@DACL=(02 0000)
@SACL=
@="CPhotoDevice Object"
"AppID"="{1DCFDF9F-1241-4B40-9B01-B447643E15E1}"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{80A3E9B0-A246-11D3-BB8C-0090272FA362}]
@DACL=(02 0000)
@="EngUSWrdBrk Class"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{810E402F-056B-11D2-A484-00C04F8EFB69}\Implemented Categories]
@DACL=(02 0000)
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{81FA39E8-8C74-4D9D-98E1-1BB3E48F40E4}]
@DACL=(02 0000)
@SACL=
@="MVTextFiftiesTV Class"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{82435bdf-f7c1-4df9-8103-eeabebf3d6e1}]
@DACL=(02 0000)
@="WMDRM Content Enabler"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{82d353df-90bd-4382-8bc2-3f6192b76e34}]
@DACL=(02 0000)
@SACL=
@="WMVideo Decoder DMO"
"Merit"=dword:00800001
"WMSDKMerit"=dword:00000100
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{833E4010-AFF7-4AC3-AAC2-9F24C1457BCE}]
@DACL=(02 0000)
@="Help and Support Services: Service"
"AppID"="{833E4001-AFF7-4AC3-AAC2-9F24C1457BCE}"
"ThreadingModel"="Both"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{833E4012-AFF7-4AC3-AAC2-9F24C1457BCE}]
@DACL=(02 0000)
@="Help and Support Services: Package Updater"
"AppID"="{833E4001-AFF7-4AC3-AAC2-9F24C1457BCE}"
"ThreadingModel"="Both"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{83E66439-05D5-488C-A236-AA20E543D384}]
@DACL=(02 0000)
@SACL=
@="DivX Decoder Filter Quality Page"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{83FA6AF5-5751-4783-8CE6-3F8A3320E154}]
@DACL=(02 0000)
@SACL=
@="Cartoonize Class"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{847B4DF5-4B61-11D2-9BDB-204C4F4F5020}]
@DACL=(02 0000)
@="RadioView Class"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{84BC3190-3462-4043-8245-434EAE6C2288}]
@DACL=(02 0000)
@SACL=
@="CyberLink Line21 DecoderProperty Page"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{85074451-173D-4091-8648-C0E196BB363E}]
@DACL=(02 0000)
@="WSUS App Publisher"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{85516702-9C45-4A9C-861B-BC4492D355DC}]
@DACL=(02 0000)
@="DivX Demux"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{855B6281-563C-4462-8C6D-5326CA1D4FE4}]
@DACL=(02 0000)
@="Zone Class"
"AppID"="{73CFF131-CA3B-4654-9640-0F50B3ABA521}"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{86A9C2DD-E88C-4455-A2B7-CD3852716060}]
@DACL=(02 0000)
@="CDVB_RST"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{87099231-C7AF-11D0-B225-00C04FB6C2F5}]
@DACL=(02 0000)
@="FaxTiff Class"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{871C5380-42A0-1069-A2EA-08002B30309D}\shell\NoAddOns]
@DACL=(02 0000)
@="Start Without Add-ons"
"LegacyDisable"=""
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{871C5380-42A0-1069-A2EA-08002B30309D}\Shellex]
@DACL=(02 0000)
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{87255C51-CD7D-4506-B9AD-97606DAF53F3}]
@DACL=(02 0000)
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{874131cb-4ecc-443b-8948-746b89595d20}]
@DACL=(02 0000)
@SACL=
@="WMA Voice Decoder DMO"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{877BBEA5-90B6-41B5-930D-A4A0A7EA2E5A}]
@DACL=(02 0000)
@SACL=
@="CLMEI Property Page"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{87BB326B-E4A0-4de1-94F0-B9F41D0C6059}]
@DACL=(02 0000)
@="ThirdPartyEapDispatcherPeerRuntime"
"AppID"="{87BB326B-E4A0-4DE1-94F0-B9F41D0C6059}"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{87DB1ADA-AA39-11D1-829F-00A0C906B239}]
@DACL=(02 0000)
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{885BB46A-3F1E-44C3-A01B-A7D9260CC98B}\VersionIndependentProgID]
@DACL=(02 0000)
@SACL=
@="DWSetup.Player"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{88d96a05-f192-11d4-a65f-0040963251e5}]
@DACL=(02 0000)
@="XML DOM Document 6.0"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{88d96a06-f192-11d4-a65f-0040963251e5}]
@DACL=(02 0000)
@="Free Threaded XML DOM Document 6.0"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{88d96a07-f192-11d4-a65f-0040963251e5}]
@DACL=(02 0000)
@="XML Schema Cache 6.0"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{88d96a08-f192-11d4-a65f-0040963251e5}]
@DACL=(02 0000)
@="XSL Template 6.0"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{88d96a0a-f192-11d4-a65f-0040963251e5}]
@DACL=(02 0000)
@="XML HTTP 6.0"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{88d96a0b-f192-11d4-a65f-0040963251e5}]
@DACL=(02 0000)
@="Server XML HTTP 6.0"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{88d96a0c-f192-11d4-a65f-0040963251e5}]
@DACL=(02 0000)
@="SAX XML Reader 6.0"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{88d96a0e-f192-11d4-a65f-0040963251e5}]
@DACL=(02 0000)
@="SAXAttributes 6.0"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{88d96a0f-f192-11d4-a65f-0040963251e5}]
@DACL=(02 0000)
@="MXXMLWriter 6.0"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{88d96a10-f192-11d4-a65f-0040963251e5}]
@DACL=(02 0000)
@="MXHTMLWriter 6.0"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{88d96a11-f192-11d4-a65f-0040963251e5}]
@DACL=(02 0000)
@="MXNamespaceManager 6.0"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{89643D21-7B2A-11d1-8271-00A0C91F9CA0}]
@DACL=(02 0000)
@="adbanner Class"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{896E73F0-3851-11D3-AA54-00C04FD22F6C}]
@DACL=(02 0000)
@="MDServiceProvider Class"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{89A9F739-8F34-40e1-BCD3-62BABEAD3C6F}]
@DACL=(02 0000)
@SACL=
@="MSN Money QuickList"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{89BCB7A4-6119-101A-BCB7-00DD010655AF}]
@DACL=(02 0000)
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{89BCB7A5-6119-101A-BCB7-00DD010655AF}]
@DACL=(02 0000)
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{89BCB7A6-6119-101A-BCB7-00DD010655AF}]
@DACL=(02 0000)
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{89f11169-844a-4725-b7a5-c342c50431a7}]
@DACL=(02 0000)
@="WinFX Bootstrapper for .xbap"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{8A11B5FA-3C92-4E8B-8382-3C71B757D679}]
@DACL=(02 0000)
@="IE RSS Search Protocol Handler"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{8A1DC117-B953-4C39-B2CA-52211E03B19F}]
@DACL=(02 0000)
@SACL=
@="MVImageAnalyser Class"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{8A3F59E1-4994-11D1-A40D-00600831F336}]
@DACL=(02 0000)
@="DSStatusBar Class"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{8A6842BB-84DB-4EFA-99B9-06C850DF53FC}]
@DACL=(02 0000)
@="WMPlayer NetworkPropPage Class"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{8A734961-C4AA-4741-AC1E-791ACEBF5B39}]
@DACL=(02 0000)
@="WMP Shop Music Launcher"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{8AD9C840-044E-11D1-B3E9-00805F499D93}]
@DACL=(02 0000)
@="Java Plug-in 10.75.2"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{8ADE5386-8E9B-4F4C-ACF2-F0008706B238}]
@DACL=(02 0000)
"Version"="1.0.0.0"
"SpecVersion"="1.0.0.0"
"Vendor"="{F0E749CA-EDEF-4589-A73A-EE0E626A2A2B}"
"MetadataFormat"="{58A2E128-2DB9-4E57-BB14-5177891ED331}"
"RequiresFullStream"=dword:00000001
"SupportsPadding"=dword:00000001
"Author"="Microsoft"
"FriendlyName"="SubIFD Writer"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{8B4B437E-4CAB-4e83-89F6-7F9F7DF414EA}]
@DACL=(02 0000)
@="HostAuthenticatorApis"
"ThreadingModel"="Free"
"AppID"="{8B4B437E-4CAB-4e83-89F6-7F9F7DF414EA}"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{8bb7778b-645b-4475-9a73-1de3170bd3af}]
@DACL=(02 0000)
@="AudioReverb"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{8C3E4934-9FA4-4693-9253-A29A05F99186}]
@DACL=(02 0000)
@SACL=
@="SignedCode Class"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{8C482DCE-2644-4419-AEFF-189219F916B9}]
@DACL=(02 0000)
@="HostPeerApis"
"ThreadingModel"="Free"
"AppID"="{8C482DCE-2644-4419-AEFF-189219F916B9}"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{8C4EB103-516F-11D1-A6DF-006097C4E476}]
@DACL=(02 0000)
@="ppDSPropAdv Class"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{8C5889DC-6D8C-46D2-9948-B73BFEBBB723}]
@DACL=(02 0000)
@="WACom Class"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{8C9E8E1C-90F0-11D1-BA0F-00A0C906B239}]
@DACL=(02 0000)
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{8CBEED49-18A6-4D9C-8EF5-E4DD9AB04A83}]
@DACL=(02 0000)
@="Windows Media Player WMEncSourcePluginCommunicator Class"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{8CD34779-9F10-4f9b-ADFB-B3FAEABDAB5A}]
@DACL=(02 0000)
@=".url File Persistent Handler"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{8D670533-270B-4549-B19B-414FB9C6EBDB}]
@DACL=(02 0000)
@="MSDVDAdm Class"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{8DD448E6-C188-4aed-AF92-44956194EB1F}]
@DACL=(02 0000)
@="WMP Burn Audio CD Launcher"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{8E4E0EE2-4037-4616-A24F-D2E312FD2D81}]
@DACL=(02 0000)
@SACL=
@="PlayerCtrl Class"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{8E528C21-9D52-4030-BA92-3481227ADDD1}]
@DACL=(02 0000)
@="WMPlayer PrivacyPropPage Class"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{8E594310-16CA-4a00-932F-F70969F990C0}]
@DACL=(02 0000)
@="Quarantine System Health Agent Binding class"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{8E718888-423F-11D2-876E-00A0C9082467}]
@DACL=(02 0000)
@="Radio"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{8E71888A-423F-11D2-876E-00A0C9082467}]
@DACL=(02 0000)
@="RadioServer Class"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{8E989135-2736-4767-8160-EA3613F69D24}]
@DACL=(02 0000)
@="IEDropSourceWrapper"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{8EB0C7F5-DABE-4D5F-8432-AAB0A0DACF4B}]
@DACL=(02 0000)
@SACL=
@="CyberLink Audio Dolby Virtual Speaker Property Page"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{8F914656-9D0A-4EB2-9019-0BF96D8A9EE6}]
@DACL=(02 0000)
"Version"="1.0.0.0"
"SpecVersion"="1.0.0.0"
"Vendor"="{F0E749CA-EDEF-4589-A73A-EE0E626A2A2B}"
"MetadataFormat"="{537396C6-2D8A-4BB6-9BF8-2F0A8E2A3ADF}"
"RequiresFullStream"=dword:00000001
"SupportsPadding"=dword:00000001
"Author"="Microsoft"
"FriendlyName"="Ifd Reader"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{8FB6E404-9685-465C-A2EC-1AD0A8D2E181}]
@DACL=(02 0000)
@="CDVB_TDT"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{8fe85d00-4647-40b9-87e4-5eb8a52f4759}]
@DACL=(02 0000)
@="Developer Tools"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{9059f30f-4eb1-4bd2-9fdc-36f43a218f4a}]
@DACL=(02 0000)
@="Microsoft Terminal Services Client Control (redist)"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{91870674-DE84-4313-B07D-A387415BB4F5}]
@DACL=(02 0000)
@="ItlItlWrdBrk Class"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{92498132-4d1a-4297-9b78-9e2e4ba99c07}]
@DACL=(02 0000)
@="NSSManager Class"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{9271516F-F860-4a02-8F0C-BDAF8A5D13A4}]
@DACL=(02 0000)
@="Toolbar Extension for Executable"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{93073C40-0BA5-11d2-A484-00C04F8EFB69}\Implemented Categories]
@DACL=(02 0000)
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{93126582-5402-4DB1-A102-33D330BC9B69}]
@DACL=(02 0000)
@="Windows Media Player WMEnc5Point1WavSourcePropertyPage Class"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{9345312C-D098-4BB1-B2B2-D529EB995173}]
@DACL=(02 0000)
@="SynDevice Class"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{93852550-5403-4E1B-AF8C-5806F151B2F5}]
@DACL=(02 0000)
@="JScript Debugger IDE"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{93BDDC7A-F5EB-4C9D-9269-0EA374BB8BD8}]
@DACL=(02 0000)
@SACL=
@="DisplayActionByQLB Class"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{942bc614-676c-464e-b384-d3202aaa02da}]
@DACL=(02 0000)
@="INI Property Set Storage Handler"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{9443B89B-6564-496a-B19C-6C6D22709045}]
@DACL=(02 0000)
@="Quarantine Enforcement Client Binding class"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{944AD531-B09D-11CE-B59C-00AA006CB37D}]
@DACL=(02 0000)
@="PSFactoryBuffer"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{9456A480-E88B-43EA-9E73-0B2D9B71B1CA}]
@DACL=(02 0000)
"ContainerFormat"="{19E4A5AA-5662-4FC5-A0C0-1758028E1057}"
"Vendor"="{F0E749CA-EDEF-4589-A73A-EE0E626A2A2B}"
"Version"="1.0.0.0"
"SpecVersion"="1.0.0.0"
"ColorManagementVersion"="1.0.0.0"
"MimeTypes"="image/jpeg,image/jpe,image/jpg"
"FileExtensions"=".jpeg,.jpe,.jpg,.jfif,.exif"
"SupportAnimation"=dword:00000000
"SupportChromakey"=dword:00000000
"SupportLossless"=dword:00000000
"SupportMultiframe"=dword:00000000
"Author"="Microsoft"
"FriendlyName"="JPEG Decoder"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{949DCA39-87F9-44EF-9E57-E0FC43005F79}]
@DACL=(02 0000)
@SACL=
@="CyberLink Line21 Decoder Filter"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{94AFFFCC-6C05-4814-B123-A941105AA77F}]
@DACL=(02 0000)
@SACL=
@="SignedData Class"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{94c1affa-66e7-4961-9521-cfdef3128d4f}]
@DACL=(02 0000)
@="XACT Engine"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{94E03510-31B9-47a0-A44E-E932AC86BB17}]
@DACL=(02 0000)
@SACL=
@="Windows Media Player Device Autoplay"
"AppID"="{ED6BB178-B06A-47ad-98B3-6066E0CF0147}"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{95876EB0-90F0-11D1-BA0F-00A0C906B239}]
@DACL=(02 0000)
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{961C1130-89AD-11CF-88A1-00AA004B9986}]
@DACL=(02 0000)
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{96225a28-372f-7742-8530-fe3c1402e343}]
@DACL=(02 0000)
@SACL=
@="Wedding4 Class"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{962f5027-99be-4692-a468-85802cf8de61}]
@DACL=(02 0000)
@="XACT Engine"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{962FFCF3-965F-11D0-A881-00C04FC99C9C}]
@DACL=(02 0000)
@="AppleTalk Configuration Notify Object"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{9678f47f-2435-475c-b24a-4606f8161c16}]
@DACL=(02 0000)
@="Microsoft Windows WSMan Provider Host"
"AppId"=expand:"{3feb2f63-0eec-4b96-84ab-da1307e0117c}"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{9694E38A-E081-46ac-99A0-8743C909ACB6}]
@DACL=(02 0000)
@="html persistent handler for mapi email"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{96BEC059-2052-4e44-8E11-123ACDC936FE}]
@DACL=(02 0000)
@="WMDM Sync Property Page"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{97103AE5-6248-4E04-97B5-36663159967C}]
@DACL=(02 0000)
@="Windows Media Player WMEncTunerPropPage Class"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{971127BB-259F-48c2-BD75-5F97A3331551}]
@DACL=(02 0000)
@="Microsoft Terminal Services Client Control (redist)"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{975ABEDC-F64B-436d-ABFF-44B932459856}]
@DACL=(02 0000)
@="Windows Media Player OCXAdvancedPropPage Class"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{98042251-8C2B-4FC4-93E2-B1DB331EF5B9}]
@DACL=(02 0000)
@="WMPlayer AdvancedPropPage Class"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{986644D1-6A97-4C23-8BA7-CD67B11463E1}]
@DACL=(02 0000)
@SACL=
@="PicturePan Class"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{987BBF42-5500-46D6-BAF0-A825828BC4EF}]
@DACL=(02 0000)
@="Windows Media Player WMEncFileSource Class"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{989D1DC0-B162-11D1-B6EC-D27DDCF9A923}]
@DACL=(02 0000)
@="XML Script Engine"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{98E9DA52-5EED-4906-9CD5-0F842617CECB}]
@DACL=(02 0000)
@SACL=
@="SpeedWarp Class"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{98FF6D4B-6387-4b0a-8FBD-C5C4BB17B4F8}]
@DACL=(02 0000)
@="IE MRU AutoComplete List"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{998F5F68-9134-4D96-BC12-075A63D5CF3B}]
@DACL=(02 0000)
@SACL=
@="Sonic MPEG Video Decoder"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{9a096bb5-9dc3-4d1c-8526-c3cbf991ea4e}]
@DACL=(02 0000)
@="IE RSS Feeds Folder"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{9AD1F5EE-F01F-431D-8CAB-ECB08704D338}]
@DACL=(02 0000)
@SACL=
@="Compaq Modem Check"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{9AF6E7AE-D248-11D2-BFAA-00805F2392C0}]
@DACL=(02 0000)
@SACL=
@="Smi Class"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{9C042297-D1CD-4F0D-B1AB-9F48AD6A6DFF}]
@DACL=(02 0000)
@="SynAPI Class"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{9C2263B0-3E3C-11D2-9BD3-204C4F4F5020}]
@DACL=(02 0000)
@="RadioPlayer Class"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{9C502F01-0D36-4f16-8AC9-8693E0D84E44}]
@DACL=(02 0000)
@="WMPlayer CDBurnPropPage Class"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{9C5A57C9-6C2B-4EDF-98C4-1631E9CCAE4A}]
@DACL=(02 0000)
@SACL=
@="GradientFade Class"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{9c7a1728-b694-427a-94a2-a1b2c60f0360}]
@DACL=(02 0000)
@="ShdocvwBroker"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{9C9FDCAD-2949-433C-9EDC-1C7C823B7B83}]
@DACL=(02 0000)
@SACL=
@="MVTextCinema Class"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{9cab402c-1d37-44b4-886d-fa4f36170a4c}]
@DACL=(02 0000)
@="AudioReverb"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{9CB5172B-D600-46BA-AB77-77BB7E3A00D9}]
@DACL=(02 0000)
"Vendor"="{F0E749CA-EDEF-4589-A73A-EE0E626A2A2B}"
"Version"="1.0.0.0"
"Author"="Microsoft"
"FriendlyName"="Microsoft Windows Media Photo Pixel Format Converter"
"SpecVersion"="1.0.0.0"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{9CD2C438-F8EA-4E77-A6D2-9346EC389E01}]
@DACL=(02 0000)
@SACL=
@="MVTextFadeInOut Class"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{9D958C62-3954-4b44-8FAB-C4670C1DB4C2}]
@DACL=(02 0000)
@="IE Microsoft Shell Folder AutoComplete List"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{9E704F44-90F0-11D1-BA0F-00A0C906B239}]
@DACL=(02 0000)
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{9E7EA907-5810-4FCA-B817-CD0BBA8496FC}]
@DACL=(02 0000)
@SACL=
@="ExtendedProperty Class"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{9ED4692C-90F0-11D1-BA0F-00A0C906B239}]
@DACL=(02 0000)
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{9F49A07B-9221-4307-BFEB-E860C1F6962F}]
@DACL=(02 0000)
@SACL=
@="Vacation5Text Class"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{9F4D2FA2-54A1-11d1-8267-00A0C91F9CA0}]
@DACL=(02 0000)
@="gotobar Class"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{9FAE1230-74AC-4e33-B59C-4051BBEB0803}]
@DACL=(02 0000)
@="IE Thread Handshake"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A000154F-2AA9-4690-BB0D-2FBC3C8EFFF2}]
@DACL=(02 0000)
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A06B0DBC-8272-4D72-A366-B8090BBE1871}]
@DACL=(02 0000)
@="RealSearch"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A0717E52-8AC8-4dd9-8682-0B76775125E6}]
@DACL=(02 0000)
@="DivX Settings Manager"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A09CCA86-27BA-4F39-9053-121FA4DC08FC}]
@DACL=(02 0000)
"Version"="1.0.0.0"
"SpecVersion"="1.0.0.0"
"Vendor"="{F0E749CA-EDEF-4589-A73A-EE0E626A2A2B}"
"MetadataFormat"="{A45E592F-9078-4A7C-ADB5-4EDC4FD61B1F}"
"FixedSize"=dword:00000001
"Author"="Microsoft"
"FriendlyName"="Unknown Writer"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A1031BAF-3039-4dd6-BC5E-522F007DAF8B}]
@DACL=(02 0000)
@=""
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A1230201-1439-4E62-A414-190D0AC3D40E}]
@DACL=(02 0000)
@="PSFactoryBuffer"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A1A41E11-91DB-4461-95CD-0C02327FD934}]
@DACL=(02 0000)
@="RealPlayer Stream Handler"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{a220a2df-406f-4d68-9b62-995669ae0c92}]
@DACL=(02 0000)
@="Synaptics Packet Control"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A26CEC36-234C-4950-AE16-E34AACE71D0D}]
@DACL=(02 0000)
"Author"="Microsoft"
"ColorManagementVersion"="1.0.0.0"
"ContainerFormat"="{57A37CAA-367A-4540-916B-F183C5093A4B}"
"FileExtensions"=".wdp"
"FriendlyName"="WMPhoto Decoder"
"MimeTypes"="image/vnd.ms-photo"
"SpecVersion"="1.0.0.0"
"SupportAnimation"=dword:00000000
"SupportChromakey"=dword:00000000
"SupportLossless"=dword:00000001
"SupportMultiframe"=dword:00000001
"Vendor"="{F0E749CA-EDEF-4589-A73A-EE0E626A2A2B}"
"Version"="1.0.0.0"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A28D553A-A703-11D0-9CEC-00C04FC9BCC4}]
@DACL=(02 0000)
@="NetBEUI Configuration Notify Object"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A2DBE262-CDDF-4107-87B5-978EEC0533D3}]
@DACL=(02 0000)
@SACL=
@="MVTextInfo Class"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A2E3074F-6C3D-11D3-B653-00C04F79498E}]
@DACL=(02 0000)
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A38B883C-1682-497E-97B0-0A3A9E801682}]
@DACL=(02 0000)
"ManualSafeSave"="1"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A3DD4F92-658A-410F-84FD-6FBBBEF2FFFE}]
@DACL=(02 0000)
@="Internet Options"
"InfoTip"="@c:\\WINDOWS\\system32\\inetcpl.cpl,-4313"
"LocalizedString"="@c:\\WINDOWS\\system32\\inetcpl.cpl,-4312"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A3F2A195-0D11-463b-96BB-D2FF1B7490A1}]
@DACL=(02 0000)
@="MSDVDAdm Class"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A440BD76-CFE1-4D46-AB1F-15F238437A3D}]
@DACL=(02 0000)
@SACL=
@="EncryptedData Class"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A4741943-6C4B-4cf7-BF44-A0F4207D1330}]
@DACL=(02 0000)
@="IE Property Set Storage In Memory Object"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A489AA80-6F27-4C3A-895D-EAC0E45EC77B}]
@DACL=(02 0000)
@="HPStarter Class"
"AppID"="{5F2F4FF3-9F5E-4774-AF1C-401626772B9D}"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A55803CC-4D53-404c-8557-FD63DBA95D24}]
@DACL=(02 0000)
@="WPDShextAutoplay"
"AppID"="{A55803CC-4D53-404c-8557-FD63DBA95D24}"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A6A0F763-98D4-47D2-8B5B-A21B7A1D84F1}]
@DACL=(02 0000)
@SACL=
@="AnalyserCtrl Class"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A6B222AB-A5EA-4899-B230-084657EDDC7D}]
@DACL=(02 0000)
@="Browser Thread State"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A8792A31-F385-493C-A893-40F64EB45F6E}]
@Class="REG_SZ"
@DACL=(02 0000)
@="PSFactoryBuffer"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{a8b44381-6969-1b41-9c21-1121a64b113c}]
@DACL=(02 0000)
@SACL=
@="Vacation5 Class"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A8F38D8D-E480-4D52-B7A2-731BB6995FDD}]
@DACL=(02 0000)
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A907657F-6FDF-11D0-8EFB-00C04FD912B2}]
@DACL=(02 0000)
@="Microsoft TCP/IP Configuration Notify Object"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A931ABFB-473B-43B0-9EC4-69EB26B230F6}]
@DACL=(02 0000)
@SACL=
@="OverlayObject Class"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A972CE89-FCAF-4537-8E59-A1889590FB9E}]
@DACL=(02 0000)
@SACL=
@="CyberLink DVD Video Property"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A9738FF1-D821-4029-8932-BA5186AFB68C}]
@Class="REG_SZ"
@DACL=(02 0000)
@="PSFactoryBuffer"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A97BBEB0-2D4C-11D3-B244-444553540000}]
@DACL=(02 0000)
@="EncodeMP3File2 Class"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A98C8400-4181-11D1-A520-00A0D10129C0}\InprocServer32]
@DACL=(02 0000)
@="c:\\WINDOWS\\system32\\wmpasf.dll"
"ThreadingModel"="Both"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A996E48C-D3DC-4244-89F7-AFA33EC60679}]
@DACL=(02 0000)
@SACL=
@="Settings Class"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A9FC132B-096D-460B-B7D5-1DB0FAE0C062}]
@DACL=(02 0000)
@="RMGetLicense Class"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{AA0AF823-B0D0-40c7-AE77-F13B14D9FFAE}]
@DACL=(02 0000)
@="Toolbar Extension for Bands"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{AA160628-8775-46e3-837C-F7A2AE66E2F5}]
@DACL=(02 0000)
@="Quarantine SoH Protocol processor class"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{AA478720-468A-41AB-9D97-263B6580FE8C}]
@DACL=(02 0000)
@SACL=
@="muvee Video Analyser"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{AA478722-468A-41AB-9D97-263B6580FE8C}]
@DACL=(02 0000)
@SACL=
@="muvee Music Analyser"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{AA478751-468A-41ab-9D97-263B6580FE8C}]
@DACL=(02 0000)
@SACL=
@="DXTFlashEffect"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{AA478752-468A-41ab-9D97-263B6580FE8C}]
@DACL=(02 0000)
@SACL=
@="DXTFlashPropPage"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{AA478761-468A-41ab-9D97-263B6580FE8C}]
@DACL=(02 0000)
@SACL=
@="DXTImageOutEffect"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{AA478771-468A-41ab-9D97-263B6580FE8C}]
@DACL=(02 0000)
@SACL=
@="DXTTextOutEffect"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{AA478781-468A-41ab-9D97-263B6580FE8C}]
@DACL=(02 0000)
@SACL=
@="DShowHelpVarMCCtrl Class"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{AA478801-468A-41ab-9D97-263B6580FE8C}]
@DACL=(02 0000)
@SACL=
@="DShowHelpWMCtrl Class"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{AA58ED58-01DD-4d91-8333-CF10577473F7}]
@DACL=(02 0000)
@="Google Toolbar Helper"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{AA7E3C50-864C-4604-BC04-8B0B76E637F6}]
@DACL=(02 0000)
"SpecVersion"="1.0.0.0"
"Version"="1.0.0.0"
"Vendor"="{F0E749CA-EDEF-4589-A73A-EE0E626A2A2B}"
"MetadataFormat"="{326556A2-F502-4354-9CC0-8E3F48EAF6B5}"
"RequiresFullStream"=dword:00000000
"SupportsPadding"=dword:00000000
"Author"="Microsoft"
"FriendlyName"="App13 Reader"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{AA94DCC2-B8B0-4898-B835-000AABD74393}]
@DACL=(02 0000)
"Version"="1.0.0.0"
"SpecVersion"="1.0.0.0"
"Vendor"="{F0E749CA-EDEF-4589-A73A-EE0E626A2A2B}"
"MetadataFormat"="{7B08A675-91AA-481B-A798-4DA94908613B}"
"RequiresFullStream"=dword:00000000
"SupportsPadding"=dword:00000000
"Author"="Microsoft"
"FriendlyName"="XMP Alt Reader"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{AA9BB1E0-9FE2-11D0-B257-00C04FC9E292}]
@DACL=(02 0000)
@="DHCP Server Configuration Notify Object"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{AAA288BA-9A4C-45B0-95D7-94D524869DB5}]
@DACL=(02 0000)
@="WPDShServiceObj Class"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{AAC2B978-266D-48ae-AA28-60A3EBB872D0}]
@DACL=(02 0000)
@="IE RSS FeedFolder Tasks"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{AB1D8565-40E9-4616-984D-98465687E82C}]
@DACL=(02 0000)
@="Messenger Private Object"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{AB851B16-8E2C-472C-8DCE-D739F0EDB958}]
@DACL=(02 0000)
@SACL=
@="MVTextOverTheTopMusicVideo Class"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{ABC0DABE-565B-4a71-BB5D-B8D1CE1F8981}]
@DACL=(02 0000)
@="DeviceCollection Class"
"AppID"="{5F2F4FF3-9F5E-4774-AF1C-401626772B9D}"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{ABE3B9A4-257D-4B97-BD1A-294AF496222E}]
@DACL=(02 0000)
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{AC4CE3CB-E1C1-44CD-8215-5A1665509EC2}]
@DACL=(02 0000)
"Author"="Microsoft"
"ColorManagementVersion"="1.0.0.0"
"ContainerFormat"="{57A37CAA-367A-4540-916B-F183C5093A4B}"
"FileExtensions"=".wdp"
"FriendlyName"="WMPhoto Encoder"
"MimeTypes"="image/vnd.ms-photo"
"SpecVersion"="1.0.0.0"
"SupportAnimation"=dword:00000000
"SupportChromakey"=dword:00000000
"SupportLossless"=dword:00000001
"SupportMultiframe"=dword:00000001
"Vendor"="{F0E749CA-EDEF-4589-A73A-EE0E626A2A2B}"
"Version"="1.0.0.0"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{AC583A28-F947-433A-9D11-60E71AB7FC77}]
@DACL=(02 0000)
@SACL=
@="CyberLink TimeStretch Filter Property Page"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{AC5E8A54-357A-4E28-AD0E-6041FAABD3D5}]
@DACL=(02 0000)
@="QuickTimeVideoDecoderDMO Class"
"AppID"="{E8E074E8-B100-4F7A-B145-A971BD8C68E6}"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{AC757296-3522-4E11-9862-C17BE5A1767E}]
@DACL=(02 0000)
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{ACA97E00-0C7D-11d2-A484-00C04F8EFB69}\Implemented Categories]
@DACL=(02 0000)
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{ACADF079-CBCD-4032-83F2-FA47C4DB096F}]
@DACL=(02 0000)
@="CLicenseAgent Class"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{ACE52D03-E5CD-4b20-82FF-E71B11BEAE1D}]
@DACL=(02 0000)
@="Shell Name Space ListView"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{ace575fd-1fcf-4074-9401-ebab990fa9de}]
@DACL=(02 0000)
@="Microsoft RDP Client Control"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{AD0FB36E-C9FA-48D0-A7C5-0C5C723AC259}]
@DACL=(02 0000)
@SACL=
@="DetectiveText Class"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{ad763fa6-3b90-41ab-bd44-4f832beee55f}]
@DACL=(02 0000)
@="Windows Media Network Source Plugin"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{AE097EE9-9AB5-4999-95F7-200F862661F9}]
@DACL=(02 0000)
@="WUClientUIPlugin Class"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{AE1A5812-5230-11D1-A6E0-006097C4E476}]
@DACL=(02 0000)
@="ppDSView Class"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{AE1A5813-5230-11D1-A6E0-006097C4E476}]
@DACL=(02 0000)
@="ppDSOAdv Class"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{AE24FDAE-03C6-11D1-8B76-0080C744F389}\InProcServer32\7.0.3300.0]
@DACL=(02 0000)
@="c:\\WINDOWS\\system32\\mshtml.dll"
"Assembly"="Microsoft.mshtml, Version=7.0.3300.0, Culture=neutral, PublicKeyToken=b03f5f7f11d50a3a"
"Class"="mshtml.ScriptletClass"
"RuntimeVersion"="v1.0.3705"
"ThreadingModel"="Apartment"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{AE5B5C4A-4721-4077-B148-29591ECBF609}]
@DACL=(02 0000)
@SACL=
@="MooPlayer Class"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{ae90e550-0443-47fb-a001-4875648d4ed3}]
@DACL=(02 0000)
@="IE WebNavigatable Implementation"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{AE9472BF-B0C3-11D2-8D24-00A0C9441E20}]
@DACL=(02 0000)
@="GrfCache Class"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{AEE3E4A8-EF01-4024-A0F1-809D9B096E14}]
@DACL=(02 0000)
@="Windows Media Player Encoder Helper Class"
"AppID"="{A9D431C2-6D56-4727-9690-ADBE66B9184A}"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{AEE5645A-47FE-41FB-AD33-7BD0DCA8D2F5}]
@DACL=(02 0000)
@SACL=
@="MVTextValentine Class"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{AFB40FFD-B609-40A3-9828-F88BBE11E4E3}]
@DACL=(02 0000)
@="Server XML HTTP 3.0"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{AFBA6B42-5692-48EA-8141-DC517DCF0EF1}]
@DACL=(02 0000)
@="Server XML HTTP"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{AFD7F94B-1627-436c-80C8-B464AA21CAD3}]
@DACL=(02 0000)
@="WMPlayer SecurityPropPage Class"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{B019E3BF-E7E5-453C-A2E4-D2C18CA0866F}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\WINDOWS\\system32\\Macromed\\Flash\\FlashUtil32_19_0_0_245_ActiveX.exe,-101"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{B019E3BF-E7E5-453C-A2E4-D2C18CA0866F}\Elevation]
"Enabled"=dword:00000001
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{B019E3BF-E7E5-453C-A2E4-D2C18CA0866F}\LocalServer32]
@="c:\\WINDOWS\\system32\\Macromed\\Flash\\FlashUtil32_19_0_0_245_ActiveX.exe"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{B019E3BF-E7E5-453C-A2E4-D2C18CA0866F}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{B11212BD-A797-4459-B8A7-5C9E7F49E1D0}]
@DACL=(02 0000)
@="IE OLE Document Property Handler"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{B17E399C-0A73-1051-EA92-551B921DA804} ]
@DACL=(02 0000)
"data"="5aa1ca4e608f47d1b597d15de356f2b3"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{B1EBFC28-C9BD-47A2-8D33-B948769777A7}]
@DACL=(02 0000)
"Version"="1.0.0.0"
"SpecVersion"="1.0.0.0"
"Vendor"="{F0E749CA-EDEF-4589-A73A-EE0E626A2A2B}"
"MetadataFormat"="{537396C6-2D8A-4BB6-9BF8-2F0A8E2A3ADF}"
"RequiresFullStream"=dword:00000001
"SupportsPadding"=dword:00000001
"Author"="Microsoft"
"FriendlyName"="Ifd Writer"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{B2A7FD52-301F-4348-B93A-638C6DE49229}]
@DACL=(02 0000)
@="WMPSkinMngr Class"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{B31C5FAE-961F-415b-BAF0-E697A5178B94}]
@DACL=(02 0000)
@="IE Microsoft Multiple AutoComplete List Container"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{B32F4002-BB27-45FF-AF4F-06631C1E8DAD}]
@Class="REG_SZ"
@DACL=(02 0000)
@="PSFactoryBuffer"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{B33927D0-89E6-45D8-87C7-27F3DE3EFDE6}]
@DACL=(02 0000)
@="ItunesDevicePrefs Class"
"AppID"="{250DD19F-6E7F-4BA3-9E1B-69E6CDC52F30}"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{B3FD5602-EB0F-415E-9F32-75DA391D6BF9}]
@DACL=(02 0000)
@="ExecutivePlatform"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{B415BA29-CDC8-4202-89F8-A9046145DC70}]
@DACL=(02 0000)
@="Config Class"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{B45AFEC0-2AE6-11D1-859E-00C04FC9E292}]
@DACL=(02 0000)
@="Microsoft SAP Agent Notify Object"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{B475F925-E3F7-414C-8C72-1CEE64B9D8F6}]
@DACL=(02 0000)
@="PSFactoryBuffer"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{B4D85BBD-C1E6-4F2B-BF43-75CB28500A08}]
@DACL=(02 0000)
@="Windows Media Player TunerHelper Class"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{B4E721A0-6AC4-40E6-94FC-CBD0D4279B5E}]
@DACL=(02 0000)
@="HPSimpleProduct Class"
"AppID"="{5F2F4FF3-9F5E-4774-AF1C-401626772B9D}"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{B54E85D9-FE23-499F-8B88-6ACEA713752B}]
@DACL=(02 0000)
"ContainerFormat"="{163BCC30-E2E9-4F0B-961D-A3E9FDB788A3}"
"Vendor"="{F0E749CA-EDEF-4589-A73A-EE0E626A2A2B}"
"Version"="1.0.0.0"
"SpecVersion"="1.0.0.0"
"ColorManagementVersion"="1.0.0.0"
"MimeTypes"="image/tiff,image/tif"
"FileExtensions"=".tiff,.tif"
"SupportAnimation"=dword:00000000
"SupportChromakey"=dword:00000001
"SupportLossless"=dword:00000001
"SupportMultiframe"=dword:00000001
"Author"="Microsoft"
"FriendlyName"="TIFF Decoder"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{B54F3741-5B07-11cf-A4B0-00AA004A55E8}]
@DACL=(02 0000)
@="VB Script Language"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{B54F3741-5B07-11cf-A4B0-00AA004A55E8}\InprocServer32]
@DACL=(02 0000)
@="c:\\WINDOWS\\system32\\vbscript.dll"
"ThreadingModel"="Both"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{B54F3741-5B07-11cf-A4B0-00AA004A55E8}\OLEScript]
@DACL=(02 0000)
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{B54F3741-5B07-11cf-A4B0-00AA004A55E8}\ProgID]
@DACL=(02 0000)
@="VBScript"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{B54F3742-5B07-11cf-A4B0-00AA004A55E8}]
@DACL=(02 0000)
@="VB Script Language Authoring"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{B54F3742-5B07-11cf-A4B0-00AA004A55E8}\InprocServer32]
@DACL=(02 0000)
@="c:\\WINDOWS\\system32\\vbscript.dll"
"ThreadingModel"="Both"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{B54F3742-5B07-11cf-A4B0-00AA004A55E8}\OLEScript]
@DACL=(02 0000)
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{B54F3742-5B07-11cf-A4B0-00AA004A55E8}\ProgID]
@DACL=(02 0000)
@="VBScript Author"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{B54F3743-5B07-11cf-A4B0-00AA004A55E8}]
@DACL=(02 0000)
@="VBScript Language Encoding"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{B54F3743-5B07-11cf-A4B0-00AA004A55E8}\InprocServer32]
@DACL=(02 0000)
@="c:\\WINDOWS\\system32\\vbscript.dll"
"ThreadingModel"="Both"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{B54F3743-5B07-11cf-A4B0-00AA004A55E8}\OLEScript]
@DACL=(02 0000)
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{B54F3743-5B07-11cf-A4B0-00AA004A55E8}\ProgID]
@DACL=(02 0000)
@="VBScript.Encode"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{B578E5C8-BC99-4941-9543-33B024EC7334}]
@DACL=(02 0000)
@SACL=
@="CyberLink Audio CLVB Property Page"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{B58C2440-A1A3-11d1-B024-006097C9A284}]
@DACL=(02 0000)
@="MsoHelp Key Search Dialog"
"AppID"="{B58C2440-A1A3-11d1-B024-006097C9A284}"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{B58C2441-A1A3-11d1-B024-006097C9A284}]
@DACL=(02 0000)
@="MsoHelp AW Search Dialog"
"AppID"="{B58C2441-A1A3-11d1-B024-006097C9A284}"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{B5C8B898-0074-459F-B700-860D4651EA14}]
@DACL=(02 0000)
"Version"="1.0.0.0"
"SpecVersion"="1.0.0.0"
"Vendor"="{F0E749CA-EDEF-4589-A73A-EE0E626A2A2B}"
"MetadataFormat"="{ED686F8E-681F-4C8B-BD41-A8ADDBF6B3FC}"
"RequiresFullStream"=dword:00000001
"SupportsPadding"=dword:00000001
"Author"="Microsoft"
"FriendlyName"="Interop Reader"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{B5EBAFB9-253E-4A72-A744-0762D2685683}]
@DACL=(02 0000)
"Version"="1.0.0.0"
"SpecVersion"="1.0.0.0"
"Vendor"="{F0E749CA-EDEF-4589-A73A-EE0E626A2A2B}"
"MetadataFormat"="{568D8936-C0A9-4923-905D-DF2B38238FBC}"
"FixedSize"=dword:00000001
"SupportsPadding"=dword:00000000
"RequiresFullStream"=dword:00000000
"Author"="Microsoft"
"FriendlyName"="Chunk tEXt Writer"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{B6353564-96C4-11D2-8DDB-006097C9A2B2}\InprocServer32]
@DACL=(02 0000)
@="c:\\WINDOWS\\system32\\wmpasf.dll"
"ThreadingModel"="Both"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{B63C249D-7FA4-42a6-8AF1-D83AB0CE00B3}]
@DACL=(02 0000)
@="HPSIEnumeration Class"
"AppID"="{5F2F4FF3-9F5E-4774-AF1C-401626772B9D}"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{B678258C-76B9-48B6-8B6E-3265CA5986B7}]
@DACL=(02 0000)
@SACL=
@="Video Decoder Property Page"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{B69003B3-C55E-4b48-836C-BC5946FC3B28}]
@DACL=(02 0000)
@="Messenger Object"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{B699E5E8-67FF-4177-88B0-3684A3388BFB}]
@DACL=(02 0000)
@="UpdateSearcher Class"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{b802058a-464a-42db-bc10-b650d6f2586a}]
@DACL=(02 0000)
@="XAudio2"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{B911575B-0CA1-45F4-999E-B9FEE06A980D}]
@DACL=(02 0000)
@SACL=
@="AutoLevel Class"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{B9240A2E-EE1A-4E1F-AD76-6536F9D3B176}]
@DACL=(02 0000)
@="DVDRect Class"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{B9D1F320-C401-11D0-A520-000000000000}\InprocServer32]
@DACL=(02 0000)
@="c:\\WINDOWS\\system32\\wmpasf.dll"
"ThreadingModel"="Both"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{B9D1F321-C401-11D0-A520-000000000000}\InprocServer32]
@DACL=(02 0000)
@="c:\\WINDOWS\\system32\\wmpasf.dll"
"ThreadingModel"="Both"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{B9D1F322-C401-11D0-A520-000000000000}\InprocServer32]
@DACL=(02 0000)
@="c:\\WINDOWS\\system32\\wmpasf.dll"
"ThreadingModel"="Both"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{B9D1F323-C401-11D0-A520-000000000000}\InprocServer32]
@DACL=(02 0000)
@="c:\\WINDOWS\\system32\\wmpasf.dll"
"ThreadingModel"="Both"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{B9D1F324-C401-11D0-A520-000000000000}\InprocServer32]
@DACL=(02 0000)
@="c:\\WINDOWS\\system32\\wmpasf.dll"
"ThreadingModel"="Both"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{B9D1F325-C401-11D0-A520-000000000000}\InprocServer32]
@DACL=(02 0000)
@="c:\\WINDOWS\\system32\\wmpasf.dll"
"ThreadingModel"="Both"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{B9D1F32E-C401-11D0-A520-000000000000}\InprocServer32]
@DACL=(02 0000)
@="c:\\WINDOWS\\system32\\wmpasf.dll"
"ThreadingModel"="Both"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{BA11F969-397A-4146-AC96-236C3D76711D}]
@DACL=(02 0000)
@="DivX Subtitle Decoder"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{BA9BB214-D930-4206-8F8F-BF0F1EAA4A6B}]
@DACL=(02 0000)
@="PSFactoryBuffer"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{BAA94581-C092-425C-B4D3-7B5EE0BAC3C4}]
@DACL=(02 0000)
@="Windows Media Player WMEncProfile2 Class"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{BB314F91-A010-11d1-A75A-006097C4E476}]
@DACL=(02 0000)
@="ppDSMeta Class"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{BB44391D-6ABD-422f-9E2E-385C9DFF51FC}]
@DACL=(02 0000)
@="DxtCompositor Class"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{BBB0747F-15EF-497F-8356-BD7C4A802CC4}]
@DACL=(02 0000)
@SACL=
@="CyberLink Audio Dolby Headphone Property Page"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{BBBFCB14-3B21-491c-9E2A-B0F3D50F83FD}]
@DACL=(02 0000)
@=""
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{BBC40082-8ABB-4DDD-B1C6-4EE0A9A5DB52}]
@DACL=(02 0000)
@="WMPlayer PlaylistPropPage Class"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{BBEC4F81-C2BC-43a7-BD95-9738EE9B6CCA}]
@DACL=(02 0000)
@="WMPlayer DVDPropPage Class"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{BC08386A-9952-40CD-BA50-9541D64A4B4E}]
@Class="REG_SZ"
@DACL=(02 0000)
@="PSFactoryBuffer"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{BC20CB75-A981-460e-81D4-F06F61B59247}]
@DACL=(02 0000)
@="Messenger Extensions Manager Object"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{bc3e0fc6-2e0d-4c45-bc61-d9c328319bd8}]
@DACL=(02 0000)
@="XACT Engine"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{BC476F4C-D9D7-4100-8D4E-E043F6DEC409}]
@DACL=(02 0000)
@="Microsoft Browser Architecture"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{bcc782bc-6492-4c22-8c35-f5d72fe73c6e}]
@DACL=(02 0000)
@="XACT Engine"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{BCED617B-EC03-420b-8508-977DC7A686BD}]
@DACL=(02 0000)
@="WSMan Automation Class"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{BD5F415C-8DD5-48D4-9BF1-A854FAF291D1}]
@DACL=(02 0000)
@SACL=
@="SelectColor Class"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{BD70C020-2D24-11D0-9110-00004C752752}]
@DACL=(02 0000)
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{bf0eaea8-c122-11d2-94f4-00c04f72d8c4}]
@DACL=(02 0000)
@="WLBS Configuration Notify Object"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{BF27441E-CDCD-4659-AEBE-06F6E069714E}]
@DACL=(02 0000)
@SACL=
@="Screen Capture Filter Task Page"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{BF3F7EF3-8527-4145-BE10-63F8C0DE6ABB}]
@DACL=(02 0000)
@SACL=
@="QuickTime Source Filter"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{bf404da2-7d3b-11d3-b9e5-00c04f79e399}]
@DACL=(02 0000)
@="RstrProgress Class"
"AppID"="{4E5C175A-7DB9-11D3-B9E5-00C04F79E399}"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{BFAD62EE-9D54-4b2a-BF3B-76F90697BD2A}]
@DACL=(02 0000)
@="IE Shell Rebar BandSite"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{BFE18E9C-6D87-4450-B37C-E02F0B373803}]
@DACL=(02 0000)
@="AutomaticUpdates Class"
"AppID"="{B366DEBE-645B-43A5-B865-DDD82C345492}"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{C01B9BA0-BEA7-41BA-B604-D0A36F469133}]
@DACL=(02 0000)
@="SystemInformation Class"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{c0c56f46-29b1-44e9-9939-a32ce86867e2}]
@DACL=(02 0000)
@="AudioVolumeMeter"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{C0CD59AE-020D-11d1-81F2-00C04FC99D4C}]
@DACL=(02 0000)
@="ppDShowPlay Class"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{C1060E7E-7939-44A5-99C3-A6DCCD92AED0}]
@DACL=(02 0000)
@="PSFactoryBuffer"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{C1282A7B-9455-48dc-BBBB-46C2EB525AF5}]
@DACL=(02 0000)
@="WMPlayer VizResolutionPropPage Class"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{c15e6bf0-6351-4588-ac4f-ef7d5ec8c16e}]
@DACL=(02 0000)
@="WMPlayer LibraryPropPage Class"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{C17CABB2-D4A3-47D7-A557-339B2EFBD4F1}]
@DACL=(02 0000)
"Vendor"="{F0E749CA-EDEF-4589-A73A-EE0E626A2A2B}"
"FriendlyName"="N-Channel Format Converter"
"Version"="1.0.0.0"
"SpecVersion"="1.0.0.0"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{c18d5e87-12b4-46a3-ae40-67cf39bc6758}]
@DACL=(02 0000)
@="WinFX Bootstrapper for .xps"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{c1e3f122-a2ea-442c-854f-20d98f8357a1}]
@DACL=(02 0000)
@="AudioVolumeMeter"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{C21B45B8-5D76-4575-BA27-54823098C491}]
@DACL=(02 0000)
@="IE Microsoft Docking Bar Property Bag"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{C27BB47A-8823-4613-8C32-ADEBB5959985}]
@Class="REG_SZ"
@DACL=(02 0000)
@SACL=
@="PSFactoryBuffer"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{C287744F-F58B-4923-97F4-8E365EB60075}]
@DACL=(02 0000)
@SACL=
@="PortfolioManager Class"
"AppID"=""
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{C29401DD-DFA1-48EF-8558-FAA271C8E2C0}]
@DACL=(02 0000)
@SACL=
@="CCDataSync Class"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{c2c4f00a-720e-4389-aeb9-e9c4b0d93c6f}]
@DACL=(02 0000)
@="InformationCardElementBehaviorFactory Class"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{C2E88C2F-6F5B-4AAA-894B-55C847AD3A2D}]
@DACL=(02 0000)
@="WindowsUpdateAgentInfo Class"
"AppID"="{B366DEBE-645B-43A5-B865-DDD82C345492}"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{C3113E55-7BCB-4de3-8EBF-60E6CE6B4097}]
@DACL=(02 0000)
@="SiSoftware Sandra"
"LocalizedString"=expand:"@c:\\Program Files\\SiSoftware\\SiSoftware Sandra Lite 2014.RTM\\sandra.mui,-57344"
"InfoTip"=expand:"@c:\\Program Files\\SiSoftware\\SiSoftware Sandra Lite 2014.RTM\\sandra.mui,-59517"
"System.ApplicationName"="SiSoftware.Sandra"
"{305CA226-D286-468e-B848-2B2E8E697B74} 2"=dword:00000005
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{C330DE32-29C7-4cf2-9807-74BCB5486A37}]
@DACL=(02 0000)
@="Nap Client WMI Provider Class"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{C39E156D-F621-48CF-B0EE-9C47C430543B}]
@DACL=(02 0000)
@="Windows Media Player WMEncFileTransferSourcePropertyPage Class"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{C3BDF740-0B58-11d2-A484-00C04F8EFB69}\Implemented Categories]
@DACL=(02 0000)
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{C447080C-D0C3-48AE-B31E-BB3E93591C69}]
@DACL=(02 0000)
@SACL=
@="WMEnc DV Timecode Reader"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{C4A74417-EACF-4652-9D7B-EF1C043067E6}]
@DACL=(02 0000)
@="139b8196-71e4-4463-ab94-b79504c6acc0"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{C523F39F-9C83-11D3-9094-00104BD0D535}]
@DACL=(02 0000)
@="AcroAccess Class"
"AppID"="{C523F391-9C83-11D3-9094-00104BD0D535}"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{C5621364-87CC-4731-8947-929CAE75323E}]
@Class="REG_SZ"
@DACL=(02 0000)
@="PSFactoryBuffer"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{C5838ED9-78F2-4c47-8B6B-2ACF9FA16F44}]
@DACL=(02 0000)
@="RPMimeFilter Class"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{C59938DA-9B20-11D0-9CE3-00C04FC9BCC4}]
@DACL=(02 0000)
@="NWLink Configuration Notify Object"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{C5B19592-145E-11d3-9F04-006008039E37}]
@DACL=(02 0000)
@="DxtKey Class"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{c5efd803-50f8-43cd-9ab8-aafc1394c9e0}]
@DACL=(02 0000)
@="IE OpenService Activity Manager"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{C5FEAD51-277B-4863-85E2-1F898ED09070}]
@DACL=(02 0000)
@SACL=
@="OverlayGraphics Class"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{c60fae90-4183-4a3f-b2f7-ac1dc49b0e5c}]
@DACL=(02 0000)
@="XACT Engine"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{C6152B27-357E-41A5-94BC-45636C4291E8}]
@DACL=(02 0000)
@SACL=
@="FreezeDissolveTrans Class"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{C61BFCDF-2E0F-4AAD-A8D7-E06BAFEBCDFE}]
@DACL=(02 0000)
"ContainerFormat"="{A3A860C4-338F-4C17-919A-FBA4B5628F21}"
"Vendor"="{F0E749CA-EDEF-4589-A73A-EE0E626A2A2B}"
"Version"="1.0.0.0"
"SpecVersion"="1.0.0.0"
"ColorManagementVersion"="1.0.0.0"
"MimeTypes"="image/ico,image/x-icon"
"FileExtensions"=".ico,.icon"
"SupportAnimation"=dword:00000000
"SupportChromakey"=dword:00000001
"SupportLossless"=dword:00000001
"SupportMultiframe"=dword:00000001
"Author"="Microsoft"
"FriendlyName"="ICO Decoder"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{C666E115-BB62-4027-A113-82D643FE2D99}]
@DACL=(02 0000)
@="MPEG-2 Sections and Tables"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{C689490C-6C14-4925-9023-89D250DC6558}]
@DACL=(02 0000)
@SACL=
@="WaveEffect Class"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{C6A96E83-F5AF-4BD4-9BDD-7B18444F814F}]
@DACL=(02 0000)
@SACL=
@="RasDial Class"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{c6cc0d21-895d-49cc-98f1-d208cd71e047}]
@DACL=(02 0000)
@="Internet Explorer Settings Broker"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{C6F5B432-0DF1-4BD1-9C69-71E0EB23F671}]
@DACL=(02 0000)
@SACL=
@="GridDisplay Class"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{c7338b95-52b8-4542-aa79-42eb016c8c1c}]
@DACL=(02 0000)
@="AudioVolumeMeter"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{C7B6C04A-CBB5-11d0-BB4C-00C04FC2F410}]
@DACL=(02 0000)
@="IndexServer Simple Command Creator"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{C8059EB6-D2FC-4ecf-A15F-AF427F5E4DB6}]
@DACL=(02 0000)
@="Feeds Background Sync"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{C81C8C5A-B354-4DEB-96D3-8BD8D0C8ABD0}]
@DACL=(02 0000)
@SACL=
@="CyberLink Video/SP Decoder"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{C9A14CDA-C339-460B-9078-D4DEBCFABE91}]
@DACL=(02 0000)
"Version"="1.0.0.0"
"SpecVersion"="1.0.0.0"
"Vendor"="{F0E749CA-EDEF-4589-A73A-EE0E626A2A2B}"
"MetadataFormat"="{1C3C4F9D-B84A-467D-9493-36CFBD59EA57}"
"RequiresFullStream"=dword:00000001
"SupportsPadding"=dword:00000001
"Author"="Microsoft"
"FriendlyName"="Exif Writer"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{C9F2D874-8280-4C8C-999F-ED7FF97D353E}]
@DACL=(02 0000)
@SACL=
@="CyberLink Audio PL2X Property Page"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{C9FF26DC-6E81-4296-9B5A-1522AD66BB52}]
@DACL=(02 0000)
@SACL=
@="Video Decoder Property Page"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{CA1F27DD-4AF0-46c1-8CE5-54DEB2F8CF19}]
@DACL=(02 0000)
@="HPSIProduct Class"
"AppID"="{5F2F4FF3-9F5E-4774-AF1C-401626772B9D}"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{CA75B6AB-564D-419D-8A60-B796F05BB903}]
@DACL=(02 0000)
@SACL=
@="MVMediaData Class"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{CA81B096-1D6F-4635-956E-F08C0B2EC342}]
@DACL=(02 0000)
@="Windows Media Player WMEncImageSource Class"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{CA8A9780-280D-11CF-A24D-444553540000}\Control]
@DACL=(02 0000)
@SACL=
@=""
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{CA8A9780-280D-11CF-A24D-444553540000}\Implemented Categories]
@DACL=(02 0000)
@SACL=
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{CA8A9780-280D-11CF-A24D-444553540000}\InprocServer32]
@DACL=(02 0000)
@SACL=
@="c:\\PROGRA~1\\Adobe\\ACROBA~1.0\\Reader\\ActiveX\\pdf.ocx"
"ThreadingModel"="Apartment"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{CA8A9780-280D-11CF-A24D-444553540000}\MiscStatus]
@DACL=(02 0000)
@SACL=
@="0"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{CA8A9780-280D-11CF-A24D-444553540000}\ProgID]
@DACL=(02 0000)
@SACL=
@="PDF.PdfCtrl.6"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{CA8A9780-280D-11CF-A24D-444553540000}\ToolboxBitmap32]
@DACL=(02 0000)
@SACL=
@="c:\\PROGRA~1\\Adobe\\ACROBA~1.0\\Reader\\ActiveX\\pdf.ocx, 1"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{CA8A9780-280D-11CF-A24D-444553540000}\TypeLib]
@DACL=(02 0000)
@SACL=
@="{CA8A9783-280D-11CF-A24D-444553540000}"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{CA8A9780-280D-11CF-A24D-444553540000}\Version]
@DACL=(02 0000)
@SACL=
@="5.0"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{CA8A9780-280D-11CF-A24D-444553540000}\VersionIndependentProgID]
@DACL=(02 0000)
@SACL=
@="PDF.PdfCtrl"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{CA8A9784-280D-11CF-A24D-444553540000}]
@DACL=(02 0000)
@SACL=
@="Adobe Acrobat Control Property Page"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{cac1105f-619b-4d04-831a-44e1cbf12d57}]
@DACL=(02 0000)
@="AudioVolumeMeter"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{CACAF262-9370-4615-A13B-9F5539DA4C0A}]
@DACL=(02 0000)
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{CAFEEFAC-0017-0000-0075-ABCDEFFEDCBA}]
@DACL=(02 0000)
@="Java Plug-in 1.7.0_75"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{CAFEEFAC-0017-0000-0075-ABCDEFFEDCBB}]
@DACL=(02 0000)
@="Java Plug-in 1.7.0_75"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{CAFEEFAC-0017-0000-0075-ABCDEFFEDCBC}]
@DACL=(02 0000)
@="Java Plug-in 1.7.0_75"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{CAFEEFAC-0017-0000-FFFF-ABCDEFFEDCBA}]
@DACL=(02 0000)
@="Java Plug-in 1.7.0"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA}]
@DACL=(02 0000)
@="Java Plug-in 10.75.2"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{CB8C13E4-62B5-4C96-A48B-6BA6ACE39C76}]
@DACL=(02 0000)
"Version"="1.0.0.0"
"SpecVersion"="1.0.0.0"
"Vendor"="{F0E749CA-EDEF-4589-A73A-EE0E626A2A2B}"
"MetadataFormat"="{7134AB8A-9351-44AD-AF62-448DB6B502EC}"
"RequiresFullStream"=dword:00000001
"SupportsPadding"=dword:00000001
"Author"="Microsoft"
"FriendlyName"="Gps Writer"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{CC1101F2-79DC-11D2-8CE6-00A0C9441E20}]
@DACL=(02 0000)
@="MediaLocator Class"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{CC3D0210-9655-11d3-BA86-0000F80855E6}]
@DACL=(02 0000)
@SACL=
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{cc5bbec3-db4a-4bed-828d-08d78ee3e1ed}]
@DACL=(02 0000)
@="JScript Compact Profile (ECMA 327)"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{cd0d66ec-8057-43f5-acbd-66dfb36fd78c}]
@DACL=(02 0000)
@="XACT Engine"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{CD12A3CE-9C42-11D2-BEED-0060082F2054}]
@DACL=(02 0000)
@="ClientNetManager Class"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{CD3AFA70-B84F-48F0-9393-7EDC34128127}]
@DACL=(02 0000)
@="APPLICATION__X_MPLAYER2 Moniker Class"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{CD3AFA71-B84F-48F0-9393-7EDC34128127}]
@DACL=(02 0000)
@="APPLICATION__X_MS_WMZ Moniker Class"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{CD3AFA72-B84F-48F0-9393-7EDC34128127}]
@DACL=(02 0000)
@="AUDIO__AIFF Moniker Class"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{CD3AFA73-B84F-48F0-9393-7EDC34128127}]
@DACL=(02 0000)
@="AUDIO__BASIC Moniker Class"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{CD3AFA74-B84F-48F0-9393-7EDC34128127}]
@DACL=(02 0000)
@="AUDIO__MID Moniker Class"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{CD3AFA76-B84F-48F0-9393-7EDC34128127}]
@DACL=(02 0000)
@="AUDIO__MP3 Moniker Class"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{CD3AFA77-B84F-48F0-9393-7EDC34128127}]
@DACL=(02 0000)
@="AUDIO__MPEG Moniker Class"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{CD3AFA78-B84F-48F0-9393-7EDC34128127}]
@DACL=(02 0000)
@="AUDIO__MPEGURL Moniker Class"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{CD3AFA7A-B84F-48F0-9393-7EDC34128127}]
@DACL=(02 0000)
@="AUDIO__SCPLS Moniker Class"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{CD3AFA7B-B84F-48F0-9393-7EDC34128127}]
@DACL=(02 0000)
@="AUDIO__WAV Moniker Class"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{CD3AFA83-B84F-48F0-9393-7EDC34128127}]
@DACL=(02 0000)
@="AUDIO__X_MS_WAX Moniker Class"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{CD3AFA84-B84F-48F0-9393-7EDC34128127}]
@DACL=(02 0000)
@="AUDIO__X_MS_WMA Moniker Class"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{CD3AFA88-B84F-48F0-9393-7EDC34128127}]
@DACL=(02 0000)
@="VIDEO__AVI Moniker Class"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{CD3AFA89-B84F-48F0-9393-7EDC34128127}]
@DACL=(02 0000)
@="VIDEO__MPEG Moniker Class"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{CD3AFA8F-B84F-48F0-9393-7EDC34128127}]
@DACL=(02 0000)
@="VIDEO__X_MS_ASF Moniker Class"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{CD3AFA90-B84F-48F0-9393-7EDC34128127}]
@DACL=(02 0000)
@="VIDEO__X_MS_ASF_PLUGIN Moniker Class"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{CD3AFA92-B84F-48F0-9393-7EDC34128127}]
@DACL=(02 0000)
@="VIDEO__X_MS_WM Moniker Class"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{CD3AFA93-B84F-48F0-9393-7EDC34128127}]
@DACL=(02 0000)
@="VIDEO__X_MS_WMX Moniker Class"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{CD3AFA94-B84F-48F0-9393-7EDC34128127}]
@DACL=(02 0000)
@="VIDEO__X_MS_WMV Moniker Class"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{CD3AFA95-B84F-48F0-9393-7EDC34128127}]
@DACL=(02 0000)
@="VIDEO__X_MS_WVX Moniker Class"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{CD3AFA96-B84F-48F0-9393-7EDC34128127}]
@DACL=(02 0000)
@="APPLICATION__X_WMPLAYER Moniker Class"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{CDA8ACB0-8CF5-4F6C-9BA2-5931D40C8CAE}]
@DACL=(02 0000)
@="FaxServer Class"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{CE32ABF6-475D-41F6-BF82-D27F03E3D38B}]
@DACL=(02 0000)
@SACL=
@="HashedData Class"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{CE3FB1D1-02AE-4a5f-A6E9-D9F1B4073E6C}]
@DACL=(02 0000)
@="WMP Play As Playlist Launcher"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{CE872A99-09F9-441F-8E0B-679D648BE8CA}]
@DACL=(02 0000)
@="CGenericDescriptor"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{ce8dbe60-d37a-4bdd-ab3a-399e69489182}]
@DACL=(02 0000)
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{cecec95a-d894-491a-bee3-5e106fb59f2d}]
@DACL=(02 0000)
@="AudioReverb"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{CEF4D40F-ACA5-40BA-8F3B-161A594A1A39}]
@DACL=(02 0000)
@="RealPlayer Audio Filter"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{CF49D4E0-1115-11CE-B03A-0020AF0BA770}\Instance]
@DACL=(02 0000)
@SACL=
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{cfb16474-0a2e-48dc-88ce-8c0adb7e5e46}]
@DACL=(02 0000)
@="Windows Media Player Device Options Property Page"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{CFBDC6DC-5D60-4862-8383-4187A5F9AB2A}]
@DACL=(02 0000)
@SACL=
@="Wedding4Text Class"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{CFC399AF-D876-11D0-9C10-00C04FC99C8E}]
@DACL=(02 0000)
@="Msxml"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{CFCDA953-8BE4-11CF-B84B-0020AFBBCCFA}]
@DACL=(02 0000)
@="RealPlayer General Property Page"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{CFCDAA03-8BE4-11CF-B84B-0020AFBBCCFA}]
@DACL=(02 0000)
@="RealPlayer G2 Control"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{D049B20C-5DD0-44FE-B0B3-8F92C8E6D080}]
@DACL=(02 0000)
"Version"="1.0.0.0"
"SpecVersion"="1.0.0.0"
"Vendor"="{F0E749CA-EDEF-4589-A73A-EE0E626A2A2B}"
"MetadataFormat"="{243DCEE9-8703-40EE-8EF0-22A600B8058C}"
"RequiresFullStream"=dword:00000001
"FixedSize"=dword:00000001
"SupportsPadding"=dword:00000001
"Author"="Microsoft"
"FriendlyName"="Thumbnail Writer"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{D058BFC5-55D4-11D3-9A62-00C04F8EFB70}]
@DACL=(02 0000)
@SACL=
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{D058BFC9-55D4-11D3-9A62-00C04F8EFB70}]
@DACL=(02 0000)
@SACL=
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{d06df0d0-8518-441e-822f-5451d5c595b8}]
@DACL=(02 0000)
@="AudioReverb"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{D0703F55-6A4B-4B8F-9F93-7F2502F84492}]
@DACL=(02 0000)
@SACL=
@="Speed Class"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{D12B5396-C8EF-4D6D-B540-0F0FF6A9F2CC}]
@DACL=(02 0000)
@SACL=
@="CyberLink Video Effect"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{D169C14A-5148-4322-92C8-754FC9D018D8}]
@DACL=(02 0000)
@="rtf persistent handler for mapi email"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{d23b90d0-144f-46bd-841d-59e4eb19dc59}]
@DACL=(02 0000)
@SACL=
@="WMVideo9 Encoder DMO"
"WMSDKMerit"=dword:00000100
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{D2423620-51A0-11D2-9CAF-0060B0EC3D39}]
@DACL=(02 0000)
@="XML Parser"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{D24C7F41-2F44-11D3-92EF-00C0F01F77C1}]
@DACL=(02 0000)
@="AutoProto Class"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{D2E0FE7F-D23E-48E1-93C0-6FA8CC346474}]
@DACL=(02 0000)
@="UpdateInstaller Class"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{d2ea46a7-c2bf-426b-af24-e19c44456399}]
@DACL=(02 0000)
@="Microsoft RDP Client Control"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{d3332f02-3dd0-4de9-9aec-20d85c4111b6}]
@DACL=(02 0000)
@="XACT Engine"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{D413C502-3FAA-11D0-B254-444553540000}]
@DACL=(02 0000)
@="NPPAgent"
"AppID"="{D413C502-3FAA-11D0-B254-444553540000}"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{D41C1E5B-0566-4BB1-BE72-1A5407349CA6}]
@DACL=(02 0000)
@="VSPConnection Class"
"AppID"="{4848DD90-EDA2-461F-8FE9-B47A067A5225}"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{D4595BF8-1CA4-4ACB-9C15-4B3C29A765F3}]
@DACL=(02 0000)
@SACL=
@="OTTMusicVideoText Class"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{D4DCD3D7-B4C2-47D9-A6BF-B89BA396A4A3}]
@DACL=(02 0000)
"SpecVersion"="1.0.0.0"
"Version"="1.0.0.0"
"Vendor"="{F0E749CA-EDEF-4589-A73A-EE0E626A2A2B}"
"MetadataFormat"="{16100D66-8570-4BB9-B92D-FDA4B23ECE67}"
"RequiresFullStream"=dword:00000000
"SupportsPadding"=dword:00000000
"Author"="Microsoft"
"FriendlyName"="IRB Reader"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{D51BD5AE-7548-11CF-A520-0080C77EF58A}\InprocServer32]
@DACL=(02 0000)
@="c:\\WINDOWS\\system32\\wmpasf.dll"
"ThreadingModel"="Both"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{D5AB5662-131D-453D-88C8-9BBA87502ADE}]
@DACL=(02 0000)
@="Microsoft.ManagementConsole.Advanced.FrameworkSnapInFactory"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{D5E8041D-920F-45e9-B8FB-B1DEB82C6E5E}]
@DACL=(02 0000)
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{D6791A63-E7E2-4fee-BF52-5DED8E86E9B8}]
@DACL=(02 0000)
@="Portable Devices Menu"
"LocalizedString"=expand:"@%SystemRoot%\\System32\\WPDShextRes.dll,-511"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{d6afe216-3106-4e91-953f-ffa26064c8ee}]
@DACL=(02 0000)
@="Nap Config Write Class"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{D6D754B6-C211-4920-92EA-FD714A13246B}]
@DACL=(02 0000)
@="Toaster Class"
"AppID"="{DFBF6E48-5D65-4C3A-BBDA-5871CAFED233}"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{D73733C8-CC80-11D0-B225-00C04FB6C2F5}]
@DACL=(02 0000)
@="FaxServer Class"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{D77F3A48-31CA-40D3-8706-E6642782B260}]
@DACL=(02 0000)
@="ETProPlugin"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{D7F5802B-1E83-4795-8EEE-F5D4B2122C4F}]
@DACL=(02 0000)
@SACL=
@="CyberLink Audio CL Headphone Property Page"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{D830B35A-45D2-4828-83E9-2338DCB70620}]
@DACL=(02 0000)
@="WildWeb Class"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{D9403860-297F-4A49-BF9B-77898150A442}]
@DACL=(02 0000)
"Version"="1.0.0.0"
"SpecVersion"="1.0.0.0"
"Vendor"="{F0E749CA-EDEF-4589-A73A-EE0E626A2A2B}"
"MetadataFormat"="{1C3C4F9D-B84A-467D-9493-36CFBD59EA57}"
"RequiresFullStream"=dword:00000001
"SupportsPadding"=dword:00000001
"Author"="Microsoft"
"FriendlyName"="Exif Reader"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{DA4E3DA0-D07D-11d0-BD50-00A0C911CE86}\Instance\{A2E3074F-6C3D-11D3-B653-00C04F79498E}]
@DACL=(02 0000)
"FriendlyName"="BDA Transport Information Renderers"
"CLSID"="{A2E3074F-6C3D-11D3-B653-00C04F79498E}"
"Merit"=dword:00600000
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{DBB6B0E4-72C1-4245-8760-3E21AC20BA32}]
@DACL=(02 0000)
@SACL=
@="DiaphanousDrift Class"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{DC4A72BB-EABD-4549-89AD-860487024736}]
@DACL=(02 0000)
@SACL=
@="MVTextZoomInOut Class"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{DC62E83B-8C3C-4A4F-9407-B9665088DC3B}]
@DACL=(02 0000)
@="CDVB_ST"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{DC651A43-0720-4a2b-9971-BD2EF1329A3D}]
@DACL=(02 0000)
@="IE Component Categories conditional cache daemon"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{DCBCA92E-7DBE-4eda-8B7B-3AAEA4DD412B}]
@DACL=(02 0000)
@="Quarantine Private QEC Binding class"
"AppID"="{B292921D-AF50-400c-9B75-0C57A7F29BA1}"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{DD373F1A-7227-4e3c-9AFB-98C288CF1956}]
@DACL=(02 0000)
@="Quarantine EnforcementClient Connection class"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{DD75716E-B42E-4978-BB60-1497B92E30C4}]
@DACL=(02 0000)
@="text persistent handler for mapi email"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{DDE33513-774E-4BCD-AE79-02F4ADFE62FC}]
@DACL=(02 0000)
"Version"="1.0.0.0"
"SpecVersion"="1.0.0.0"
"Vendor"="{F0E749CA-EDEF-4589-A73A-EE0E626A2A2B}"
"MetadataFormat"="{8FD3DFC3-F951-492B-817F-69C2E6D9A5B0}"
"RequiresFullStream"=dword:00000000
"SupportsPadding"=dword:00000001
"Author"="Microsoft"
"FriendlyName"="App1 Reader"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{de2d022d-2480-43be-97f0-d1fa2cf98f4f}]
@DACL=(02 0000)
@="PropertyKeyCollection Class"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{DE75D012-7A65-11D2-8CEA-00A0C9441E20}]
@DACL=(02 0000)
@="DxtJpeg Class"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{DF2FCE13-25EC-45bb-9D4C-CECD47C2430C}]
@DACL=(02 0000)
@="CUri"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{DF5B1476-5C72-42BA-98DD-AFA6A812A3B3}]
@DACL=(02 0000)
@SACL=
@="Sonic Cinemaster MPEG Splitter"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{DF66AFC9-C61D-404a-B535-64FBF91D420F}]
@DACL=(02 0000)
@=""
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{DFD74844-990B-4410-9DA0-2848EFA85D14}]
@DACL=(02 0000)
@="WMPlayer ClipPropPage Class"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{E0B8F398-BB08-4298-87F0-34502693902E}]
@DACL=(02 0000)
@="Messenger Basic IM Object"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{E0C6335D-27F8-424B-A5C2-561291A902A0}]
@DACL=(02 0000)
@="SynPacket Class"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{E0F158E1-CB04-11d0-BD4E-00A0C911CE86}\Instance]
@DACL=(02 0000)
@SACL=
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{E137B0D0-7A93-11D2-8CEA-00A0C9441E20}]
@DACL=(02 0000)
@="DxtJpegPP Class"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{e17d4fc0-5564-11d1-83f2-00a0c90dc849}]
@DACL=(02 0000)
@="Search Results Folder"
"LocalizedString"=expand:"@%SystemRoot%\\system32\\SHELL32.dll,-30520"
"IntroText"=expand:"@%SystemRoot%\\system32\\SHELL32.dll,-31754"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{e180344b-ac83-4483-959e-18a5c56a5e19}]
@DACL=(02 0000)
@="AudioVolumeMeter"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{E1A1C814-FD09-4c9d-BB4A-0394B836A1F0}]
@DACL=(02 0000)
@SACL=
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{E20870E2-3AD1-4b64-87BE-5AD5F17A53F0}]
@DACL=(02 0000)
@="rtf persistent handler for mapi email"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{e21a7345-eb21-468e-be50-804db97cf708}]
@DACL=(02 0000)
@="XAudio2"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{E2A32F53-FCB1-4AAF-98E9-8E4BB843C91D}]
@DACL=(02 0000)
@SACL=
@="CyberLink Audio Renderer Property Page"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{E2B29223-3056-40F6-B7D5-1DBBCD8595E0}]
@DACL=(02 0000)
@SACL=
@="CyberLink Audio Pitch Shifting Property Page"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{E2E760C5-BF0D-4241-BFD6-6D0AAB648AC9}]
@DACL=(02 0000)
@="IE WS Change Notify"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{E339D44A-9819-4CDC-876C-0F563EEAF757}]
@DACL=(02 0000)
@SACL=
@="CyberLink DVD Navigator"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{E353A52E-ADD0-426D-A7D3-4D750940BF1F}]
@DACL=(02 0000)
@SACL=
@="MVTextBasic Class"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{E38FD381-6404-4041-B5E9-B2739258941F}]
@DACL=(02 0000)
@SACL=
@="Certificate Class"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{E3A3B1D9-5675-43c0-BF04-37BE11939FB7}]
@DACL=(02 0000)
@="Messenger Session Manager Object"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{E42CE23D-69F9-480A-A15F-BFF5E4D170C3}]
@DACL=(02 0000)
@SACL=
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{e46ae60e-ce50-ad44-bfb3-8dcc025b6890}]
@DACL=(02 0000)
@SACL=
@="Kids4 Class"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{E48B2549-D510-4A76-8A5F-FC126A6215F0}]
@DACL=(02 0000)
@="CLSID_AntiPhishingBrowserSolution"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{e48c5a3f-93ef-43bb-a092-2c7ceb946f27}]
@DACL=(02 0000)
@="AudioVolumeMeter"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{E522A82E-C231-4C26-A80A-3E23B874043C}]
@DACL=(02 0000)
@SACL=
@="Christmas04_2 Class"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{E569BDE7-A8DC-47F3-893F-FD2B31B3EEFD}]
@DACL=(02 0000)
@="Browser Application State"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{e5fae3b3-1ac8-4bd3-87e6-48eff509ddaa}]
@DACL=(02 0000)
@="Nap Certificate Relying Party class"
"AppID"="{B292921D-AF50-400c-9B75-0C57A7F29BA1}"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{E6BBD547-FDBD-48CA-A334-C9253176C831}]
@DACL=(02 0000)
@SACL=
@="MVTextPersonal Class"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{E6E73D20-0C8A-11d2-A484-00C04F8EFB69}\Implemented Categories]
@DACL=(02 0000)
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{E6EE9AAC-F76B-4947-8260-A9F136138E11}]
@DACL=(02 0000)
@="IE Shell Band Site Menu"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{E78DB56A-7A2E-4E2C-8A15-41AE37208778}]
@DACL=(02 0000)
@SACL=
@="QuickTimeSink Filter Video Properties"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{E7E79A30-4F2C-4FAB-8D00-394F2D6BBEBE}]
@DACL=(02 0000)
"Version"="1.0.0.0"
"SpecVersion"="1.0.0.0"
"Vendor"="{F0E749CA-EDEF-4589-A73A-EE0E626A2A2B}"
"MetadataFormat"="{833CCA5F-DCB7-4516-806F-6596AB26DCE4}"
"RequiresFullStream"=dword:00000000
"SupportsPadding"=dword:00000000
"Author"="Microsoft"
"FriendlyName"="XMP Bag Reader"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{E8140D53-6535-46a5-B8A1-DA6C571DA9B9}]
@DACL=(02 0000)
@="Quarantine SoH Protocol constructor class"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{E876339C-2984-41F8-A49A-F908555CE4C9}]
@DACL=(02 0000)
@="GDSControl Class"
"AppID"="{1F7595F7-05C5-489E-BB9F-6BA11ECD0CA0}"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{E88DCCE0-B7B3-11d1-A9F0-00AA0060FA31}\PersistentHandler]
@DACL=(02 0000)
@SACL=
@="{098f2470-bae0-11cd-b579-08002b30bfeb}"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{E913D868-2959-42D5-9287-923D31666474}]
@DACL=(02 0000)
@SACL=
@="QuickTime Encoder"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{E9348280-2D74-4933-BE25-73D946926795}]
@DACL=(02 0000)
@="DeviceEnum Class"
"AppID"="{5F2F4FF3-9F5E-4774-AF1C-401626772B9D}"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{e949da38-c39d-4460-8ea7-a39152c56836}]
@DACL=(02 0000)
@="PPPOE Configuration Configuration Notify Object"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{E96F5460-09CE-4f46-88B1-F4B6B4A8E252}]
@DACL=(02 0000)
@="Windows Media Player Transcode Files Cache Cleanup Handler"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{EA065AFC-5557-448C-AFD0-B3B33ECBCD67}]
@DACL=(02 0000)
@SACL=
@="RapidOverlay Class"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{EA084E0F-B62E-406E-B672-CE909626918B}]
@Class="REG_SZ"
@DACL=(02 0000)
@="PSFactoryBuffer"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{ea4a0a43-1c8f-4c7b-a4b1-28ecbd96ba8c}]
@DACL=(02 0000)
@="Nap Config Read class"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{EAC53287-4497-47fe-97E6-C46DE66679A2}]
@DACL=(02 0000)
@="FileCollection Class"
"AppID"="{E03E4D6B-DFF0-4A60-BB87-D0B2C12CFEAF}"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{eb082ba1-df8a-46be-82f3-35bf9e9be52f}]
@DACL=(02 0000)
@="Quarantine Agent Management class"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{EB5A92DC-943D-3642-8C45-3F54C667338A}]
@DACL=(02 0000)
@SACL=
@="Photo2Text Class"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{EC423914-6728-4D7B-94A8-8BB0BC869972}]
@DACL=(02 0000)
@SACL=
@="Wedding4_GlobalEffect Class"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{EC5AB487-13D8-4749-A7BD-F8B8F4A36989}]
@DACL=(02 0000)
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{ECC19750-C168-4C58-AC0E-48A6F52E3F5C}]
@DACL=(02 0000)
@SACL=
@="HalftoneEffect Class"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{ECC2CFE1-34B6-4D02-B2BF-ED8279529108}]
@DACL=(02 0000)
@SACL=
@="MVTextOldSlideShow Class"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{ECD0ECC6-DCA4-4013-A915-12355AB70999}]
@DACL=(02 0000)
@="MSWebDVD Class"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{ed72f0d2-b701-4c53-adc3-f2fb59946dd8}]
@DACL=(02 0000)
@="ProtectedModeAPI"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{ED822C8C-D6BE-4301-A631-0E1416BAD28F}]
@DACL=(02 0000)
"Version"="1.0.0.0"
"SpecVersion"="1.0.0.0"
"Vendor"="{F0E749CA-EDEF-4589-A73A-EE0E626A2A2B}"
"MetadataFormat"="{833CCA5F-DCB7-4516-806F-6596AB26DCE4}"
"RequiresFullStream"=dword:00000000
"SupportsPadding"=dword:00000000
"Author"="Microsoft"
"FriendlyName"="XMP Bag Writer"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{ED8C108E-4349-11D2-91A4-00C04F7969E8}]
@DACL=(02 0000)
@="XML HTTP Request"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{EE0BDDFA-8373-4cc4-85D8-0618E453187C}]
@DACL=(02 0000)
@="IE History Search Protocol Handler"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{EE366069-1832-420F-B381-0479AD066F19}]
@DACL=(02 0000)
"Version"="1.0.0.0"
"SpecVersion"="1.0.0.0"
"Vendor"="{F0E749CA-EDEF-4589-A73A-EE0E626A2A2B}"
"MetadataFormat"="{8FD3DFC3-F951-492B-817F-69C2E6D9A5B0}"
"RequiresFullStream"=dword:00000000
"SupportsPadding"=dword:00000001
"Author"="Microsoft"
"FriendlyName"="App1 Writer"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{EE4DA6A4-8C52-4a63-BBB8-97C93D7E1B6C}]
@DACL=(02 0000)
@="APPLICATION__X_MS_WMD Moniker Class"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{EF585A09-6616-45BB-BF02-2D12E195D318}]
@DACL=(02 0000)
@SACL=
@="OTTMusicVideo Class"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{EFC98D24-8686-4084-B28C-7507FA863BCD}]
@DACL=(02 0000)
@SACL=
@="CHpqLog Object"
"AppID"=""
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{F089B117-385B-419D-9B8A-042565DD7CC3}]
@DACL=(02 0000)
@="CCAT"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{F0B88DD5-0B9C-4B05-AA06-61CA6AAD5E07}]
@DACL=(02 0000)
@SACL=
@="MVTextSimpleMusicVideo Class"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{F0BA00A2-A4CC-4D1B-871F-8EA152BADBC6}]
@DACL=(02 0000)
@SACL=
@="FadeToColor Class"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{F0CB00CD-5A07-4D91-97F5-A8C92CDA93E4}]
@DACL=(02 0000)
@="RealOne Player Context Menu Class"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{F14E6B48-FBCA-4d32-BD79-7829D4F7E43B}]
@DACL=(02 0000)
@="FrnFrnWrdBrk Class"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{F1522EC1-F84F-4CE2-A38C-F9384B0DFD41}\VersionIndependentProgID]
@DACL=(02 0000)
@SACL=
@="DWUpdateService.ActivityLog"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{F1705B22-896D-11D4-A0E7-0050DA8D4924}]
@DACL=(02 0000)
@SACL=
@="muvee Document"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{F1B9284F-E9DC-4e68-9D7E-42362A59F0FD}]
@DACL=(02 0000)
@="WMP Add To Playlist Launcher"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{f1bd1079-9f01-4bdc-8036-f09b70095066}]
@DACL=(02 0000)
@="PSFactoryBuffer"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{F20D8ADA-A955-435D-8A49-707DAB401787}]
@DACL=(02 0000)
@SACL=
@="Unload Class"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{F2711899-88F0-4FF8-BE08-4881CEDAE28C}]
@DACL=(02 0000)
@SACL=
@="Angelic Class"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{F2CF5485-4E02-4f68-819C-B92DE9277049}]
@DACL=(02 0000)
@="&Links"
"MenuTextPUI"="@c:\\WINDOWS\\system32\\ieframe.dll.mui,-13138"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{F31D1897-7EFD-4647-8687-E05894E382AB}]
@DACL=(02 0000)
@SACL=
@="Runclose Control"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{F394BB1A-454C-426C-A5F9-7501FFED1FE6}]
@DACL=(02 0000)
@SACL=
@="Kids4Text Class"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{F3A12E08-EDE9-4160-8B51-334D982A9AD0}]
@DACL=(02 0000)
@SACL=
@="EnvelopedData Class"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{F3A614DC-ABE0-11d2-A441-00C04F795683}]
@DACL=(02 0000)
@="Messenger Object"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{F3C633A2-46C8-498E-8FBB-CC6F721BBCDE}]
@DACL=(02 0000)
"Version"="1.0.0.0"
"SpecVersion"="1.0.0.0"
"Vendor"="{F0E749CA-EDEF-4589-A73A-EE0E626A2A2B}"
"MetadataFormat"="{79007028-268D-45D6-A3C2-354E6A504BC9}"
"RequiresFullStream"=dword:00000000
"FixedSize"=dword:00000001
"Author"="Microsoft"
"FriendlyName"="App0 Writer"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{f414c260-6ac0-11cf-b6d1-00aa00bbbb58}]
@DACL=(02 0000)
@="JScript Language"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{f414c261-6ac0-11cf-b6d1-00aa00bbbb58}]
@DACL=(02 0000)
@="JScript Language Authoring"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{f414c262-6ac0-11cf-b6d1-00aa00bbbb58}]
@DACL=(02 0000)
@="JScript Language Encoding"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{F418EBA0-6A10-4482-AC2B-2D10C807073A}]
@DACL=(02 0000)
@="Synaptics API Control"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{f4769300-b949-4df9-b333-00d33932e9a6}]
@DACL=(02 0000)
@="AudioReverb"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{F4817E4B-04B6-11D3-8862-00C04F72F303}]
@Class="REG_SZ"
@DACL=(02 0000)
@SACL=
@="PSFactoryBuffer"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{f49772d7-2ffd-4766-8503-f83d3930e8bb}]
@DACL=(02 0000)
@="Microsoft Wireless Eapol Enforcement Client Callback Component"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{F4D36777-EAED-4cc5-9FE7-827BE5190B20}]
@DACL=(02 0000)
@="Microsoft Feeds Scheduler"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{f4f7d085-cd01-43f9-899d-179c6df5ddad}]
@DACL=(02 0000)
@="WinRM WMI Provider for User Profile"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{F5078F19-C551-11D3-89B9-0000F81FE221}]
@DACL=(02 0000)
@="XML Parser"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{F5078F27-C551-11D3-89B9-0000F81FE221}]
@DACL=(02 0000)
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{F5078F31-C551-11D3-89B9-0000F81FE221}]
@DACL=(02 0000)
@="XML Parser 3.0"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{F5078F32-C551-11D3-89B9-0000F81FE221}]
@DACL=(02 0000)
@="XML DOM Document 3.0"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{F5078F33-C551-11D3-89B9-0000F81FE221}]
@DACL=(02 0000)
@="Free Threaded XML DOM Document 3.0"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{F5078F34-C551-11D3-89B9-0000F81FE221}]
@DACL=(02 0000)
@="XML Schema Cache 3.0"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{F5078F35-C551-11D3-89B9-0000F81FE221}]
@DACL=(02 0000)
@="XML HTTP 3.0"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{F5078F36-C551-11D3-89B9-0000F81FE221}]
@DACL=(02 0000)
@="XSL Template 3.0"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{F5078F37-C551-11D3-89B9-0000F81FE221}]
@DACL=(02 0000)
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{F5078F39-C551-11D3-89B9-0000F81FE221}]
@DACL=(02 0000)
@="XML Data Source Object 3.0"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{F5078F3F-C551-11D3-89B9-0000F81FE221}]
@DACL=(02 0000)
@="XML Moniker 3.0"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{F5078F40-C551-11D3-89B9-0000F81FE221}]
@DACL=(02 0000)
@="XML Document 3.0"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{F5078F41-C551-11D3-89B9-0000F81FE221}]
@DACL=(02 0000)
@="XML Island 3.0"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{F5539356-2F02-40D4-999E-FA61F45FE12E}]
@DACL=(02 0000)
@SACL=
@="hpqCallBiosEx Class"
"AppID"="{0018752E-7735-4B30-9DA9-4A01F024F270}"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{f5ca7b34-8055-42c0-b836-216129eb7e30}]
@DACL=(02 0000)
@="AudioVolumeMeter"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{F5FB18CC-1A99-454F-9B18-A98D686B0CDB}]
@DACL=(02 0000)
@SACL=
@="CyberLink AudioCD Filter"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{F62D062C-4732-44D2-BD62-124B8AE1657C}]
@DACL=(02 0000)
@="WMPlayer PluginsPropPage Class"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{F6D90F11-9C73-11D3-B32E-00C04F990BB4}]
@DACL=(02 0000)
@="XML DOM Document"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{F6D90F12-9C73-11D3-B32E-00C04F990BB4}]
@DACL=(02 0000)
@="Free Threaded XML DOM Document"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{F6D90F14-9C73-11D3-B32E-00C04F990BB4}]
@DACL=(02 0000)
@="XML Data Source Object"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{F6D90F16-9C73-11D3-B32E-00C04F990BB4}]
@DACL=(02 0000)
@="XML HTTP"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{F6E3DA91-1220-4fb3-85EC-CF494D9FF7DD}]
@DACL=(02 0000)
@SACL=
@="MPEG2Thumbnail Class"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{F73C1438-71B4-4D91-AD13-1F889A03AC67}]
@DACL=(02 0000)
@="PSFactoryBuffer"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{f7ffe0a0-a4f5-44b5-949e-15ed2bc66f9d}]
@DACL=(02 0000)
@SACL=
@="MSScreen 9 encoder DMO"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{F83DAC1C-9BB9-4f2b-B619-09819DA81B0E}]
@DACL=(02 0000)
@="IE Registry Tree Options Utility"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{F87DFE9D-5908-43BB-AB0B-B5F624C07582}]
@DACL=(02 0000)
@SACL=
@="DiscoLightEffect Class"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{F8D253D9-89A4-4daa-87B6-1168369F0B21}]
@DACL=(02 0000)
@="UpdateServiceManager Class"
"AppID"="{B366DEBE-645B-43A5-B865-DDD82C345492}"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{F9043C85-F6F2-101A-A3C9-08002B2F49FB}]
@DACL=(02 0000)
@="Microsoft Common Dialog Control, version 6.0"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{F91D96C7-8509-4D0B-AB26-A0DD10904BB7}]
@DACL=(02 0000)
@="CMpeg2Stream"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{F979439C-48B7-4525-AB0E-EEE06439227A}]
@DACL=(02 0000)
@="Windows Media Player WMEncPrivatePluginConnector Class"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{F9AE8980-7E52-11d0-8964-00C04FD611D7}]
@DACL=(02 0000)
@="MSIDXS"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{F9AE8981-7E52-11d0-8964-00C04FD611D7}]
@DACL=(02 0000)
@="MSIDXS ErrorLookup"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{F9F4D292-87F5-4E2D-98A1-590391932490}]
@DACL=(02 0000)
@="Windows Media Player WMEncBasicEdit Class"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{FAB24754-0440-439b-A223-B1D360062D1D}]
@DACL=(02 0000)
@="Dhcp Quarantine Enforcement Client Callback Component"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{fac23f48-31f5-45a8-b49b-5225d61401aa}]
@DACL=(02 0000)
@="XAudio2"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{FAC3CBF6-8697-43d0-BAB9-DCD1FCE19D75}]
@DACL=(02 0000)
@="IE User Assist"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{FADE020C-B6CB-400b-B794-5A51C9A5F6D0}]
@DACL=(02 0000)
@="IE Microsoft CommBand"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{FAE3D380-FEA4-4623-8C75-C6B61110B681}]
@DACL=(02 0000)
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{faeb54c4-f66f-4806-83a0-805299f5e3ad}]
@DACL=(02 0000)
@="Microsoft Feeds Manager (scripting)"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{FB012959-F4F6-44D7-9D09-DAA087A9DB57}]
@DACL=(02 0000)
"Version"="1.0.0.0"
"SpecVersion"="1.0.0.0"
"Vendor"="{F0E749CA-EDEF-4589-A73A-EE0E626A2A2B}"
"MetadataFormat"="{243DCEE9-8703-40EE-8EF0-22A600B8058C}"
"RequiresFullStream"=dword:00000001
"SupportsPadding"=dword:00000001
"Author"="Microsoft"
"FriendlyName"="Thumbnail Reader"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{FB7199AB-79BF-11d2-8D94-0000F875C541}]
@DACL=(02 0000)
@="Messenger Application"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{FB74F625-7D25-4455-B840-7B870B5B9322}]
@DACL=(02 0000)
@="Windows Media SDK MSB Source Plugin"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{FBAB033B-CDD0-4C5E-81AB-AEA575CD1338}]
@DACL=(02 0000)
@SACL=
@="Certificates Class"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{FBE9EC50-DC42-404F-8CC9-2ACCCAAEE26B}]
@DACL=(02 0000)
@="CDVB_SIT"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{FBF23B40-E3F0-101B-8488-00AA003E56F8}\Elevation]
@DACL=(02 0000)
"Enabled"=dword:00000001
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{FBF23B40-E3F0-101B-8488-00AA003E56F8}\PersistentHandler]
@DACL=(02 0000)
@SACL=
@="{5e941d80-bf96-11cd-b579-08002b30bfeb}"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{FBF23B40-E3F0-101B-8488-00AA003E56F8}\shellex]
@DACL=(02 0000)
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{FC220AD8-A72A-4EE8-926E-0B7AD152A020}]
@DACL=(02 0000)
@="MXXMLWriter"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{FC6703A7-5B7E-4f58-BE6D-2693AA3906AE}]
@DACL=(02 0000)
@="HP Content Update"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{FD1ECB11-FAC0-4536-A53D-B6F097BC7D33}]
@DACL=(02 0000)
@="CDVB_SDT"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{FD4FE808-1020-45B8-8228-0F55A15DBD6E}]
@DACL=(02 0000)
@SACL=
@="SlidingFrame Class"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{fd589b7c-7ce0-11d3-b9e5-00c04f79e399}]
@DACL=(02 0000)
@="System Restore Wrapper"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{FD5CD8B1-6FE0-44F3-BBFB-65E3655B096E}\ProgId]
@DACL=(02 0000)
@="Microsoft.Aspnet.Snapin.AspNetManagementUtility.2"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{FD7F26E3-9788-4070-BEEC-4EAECBCDDA60}]
@DACL=(02 0000)
@="IE JScript Profiler Core"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{FDC7A535-4070-4B92-A0EA-D9994BCC0DC5}]
@DACL=(02 0000)
@="IERPCtl Class"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{FDE7673D-2E19-4145-8376-BBD58C4BC7BA}]
@DACL=(02 0000)
@="IE Custom MRU AutoCompleted List"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{FE6B11C3-C72E-4061-86C6-9D163121F229}]
@DACL=(02 0000)
@="Microsoft Feeds Manager"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{FEC96C47-4FF2-4809-AFD2-EBDC87F1D3E8}]
@DACL=(02 0000)
@SACL=
@="ThresholdedDrift Class"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{fecd606e-7161-4cbc-a868-4703867823ea}]
@DACL=(02 0000)
@="WMDM Transcode Property Page"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{ff258fc0-99b1-4297-b857-539ad9bc13ed}]
@DACL=(02 0000)
@="Cert Enrollment Class"
"AppID"="{46298684-0fd3-47f3-94b3-65650c65b36a}"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{ff48dba4-60ef-4201-aa87-54103eef594e}]
@DACL=(02 0000)
@="UIAutomation Client Central Class"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{FF5F0C18-9858-4E17-AB0F-502D20FBA8DC}]
@DACL=(02 0000)
@SACL=
@="MVTextFire Class"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{ffd90217-f7c2-4434-9ee1-6f1b530db20f}]
@DACL=(02 0000)
@="XML Feed Moniker"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{FFF2D28F-E4EE-44D9-8104-8E71556757F6}\VersionIndependentProgID]
@DACL=(02 0000)
@SACL=
@="DWUpdateService.Agent"
.
[HKEY_LOCAL_MACHINE\software\Classes\Drive\shellex\FolderExtensions\{7BFEACB2-97F5-4DC7-92E0-E69ED4C37C43}]
@Denied: (C D 2 3 6) (Everyone)
"DriveMask"=dword:ffffffff
.
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{299817DA-1FAC-4CE2-8F48-A108237013BD}]
@Denied: (A 2) (Everyone)
@="IFlashBroker6"
.
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{299817DA-1FAC-4CE2-8F48-A108237013BD}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{299817DA-1FAC-4CE2-8F48-A108237013BD}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
--------------------- DLLs Loaded Under Running Processes ---------------------
.
- - - - - - - > 'explorer.exe'(652)
c:\windows\system32\WININET.dll
c:\documents and settings\All Users\Application Data\{FB62659C-5547-4284-846F-24B4EEDF86F7}\wshelper.dll
c:\windows\system32\msi.dll
c:\windows\system32\ieframe.dll
c:\windows\system32\webcheck.dll
.
------------------------ Other Running Processes ------------------------
.
c:\program files\Hewlett-Packard\Shared\hpqwmiex.exe
c:\\?\c:\windows\system32\WBEM\WMIADAP.EXE
.
**************************************************************************
.
Completion time: 2015-12-26 13:29:19 - machine was rebooted
ComboFix-quarantined-files.txt 2015-12-26 18:29
ComboFix2.txt 2013-06-17 21:11
.
Pre-Run: 11,787,677,696 bytes free
Post-Run: 9,759,465,472 bytes free
.
- - End Of File - - F72EA4BC24193219B0AF4E31703E9AB0
665277635DC8BA83DEAE12EADEDB75A0

#6 Oh My!

Oh My!

    Adware and Spyware and Malware.....


  • Malware Response Instructor
  • 37,769 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:California
  • Local time:05:01 AM

Posted 26 December 2015 - 03:53 PM

Hi Tom, nice to meet you. Could you double check the Fixlog report and see if there is more to it than was posted in Post #3. That is only a partial report.
Gary
 
If I do not reply within 24 hours please send me a Personal Message.

"Lord, to whom would we go? You have the words that give eternal life. We believe, and we know you are the Holy One of God."

#7 peaksmm

peaksmm
  • Topic Starter

  • Members
  • 32 posts
  • OFFLINE
  •  
  • Local time:07:01 AM

Posted 26 December 2015 - 04:13 PM

Sorry Gary, that's all there is to the fixlog file. I had trouble posting the ComboFixlog file as it seems to be to big to post and the server seemed to timeout. I should also mention that there are now to unnamed file folder icons on my desktop that appear empty but do not show up in Administrator Safe Mode.

#8 Oh My!

Oh My!

    Adware and Spyware and Malware.....


  • Malware Response Instructor
  • 37,769 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:California
  • Local time:05:01 AM

Posted 26 December 2015 - 04:22 PM

Thanks. I would like you to run the FRST fix again and see if we get a more lengthy report. Yes, you have a lot of audio related registry entries and that is why the log was so long.
Gary
 
If I do not reply within 24 hours please send me a Personal Message.

"Lord, to whom would we go? You have the words that give eternal life. We believe, and we know you are the Holy One of God."

#9 peaksmm

peaksmm
  • Topic Starter

  • Members
  • 32 posts
  • OFFLINE
  •  
  • Local time:07:01 AM

Posted 26 December 2015 - 04:44 PM

Okay, here is the log of the second run.


Fix result of Farbar Recovery Scan Tool (x86) Version:20-12-2015
Ran by 1 (2015-12-26 16:36:37) Run:2
Running from C:\Documents and Settings\1\Desktop
Loaded Profiles: 1 (Available Profiles: 1 & Administrator)
Boot Mode: Normal

==============================================

fixlist content:
*****************
CreateRestorePoint:
CloseProcesses:
HKLM\SOFTWARE\Policies\Microsoft\Internet Explorer: Restriction <======= ATTENTION
HKU\S-1-5-21-2740428291-721650609-345291581-500\SOFTWARE\Policies\Microsoft\Internet Explorer: Restriction <======= ATTENTION
SearchScopes: HKLM -> DefaultScope value is missing
BHO: No Name -> {5CA3D70E-1895-11CF-8E15-001234567890} -> No File
BHO: No Name -> {A8F38D8D-E480-4D52-B7A2-731BB6995FDD} -> __BHODemonDisabled => No File
Toolbar: HKU\S-1-5-21-2740428291-721650609-345291581-500 -> No Name - {C4069E3A-68F1-403E-B40E-20066696354B} - No File
DPF: {17492023-C23A-453E-A040-C7C580BBF700} hxxp://go.microsoft.com/fwlink/?linkid=39204
DPF: {7530BFB8-7293-4D34-9923-61A11451AFC5} hxxp://download.eset.com/special/eos/OnlineScanner.cab
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} hxxp://java.sun.com/update/1.7.0/jinstall-1_7_0_45-windows-i586.cab
DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} hxxp://fpdownload.macromedia.com/get/flashplayer/current/ultrashim.cab
DPF: {CAFEEFAC-0015-0000-0006-ABCDEFFEDCBA}
DPF: {CAFEEFAC-0015-0000-0015-ABCDEFFEDCBA}
DPF: {CAFEEFAC-0016-0000-0010-ABCDEFFEDCBA}
DPF: {CAFEEFAC-0017-0000-0025-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.7.0/jinstall-1_7_0_25-windows-i586.cab
DPF: {CAFEEFAC-0017-0000-0045-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.7.0/jinstall-1_7_0_45-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.7.0/jinstall-1_7_0_45-windows-i586.cab
DPF: {E06E2E99-0AA1-11D4-ABA6-0060082AA75C}
DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} hxxp://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
S3 catchme; \??\C:\ComboFix\catchme.sys [X]
S3 cpuz138; \??\C:\DOCUME~1\1\LOCALS~1\Temp\cpuz138\cpuz138_x32.sys [X]
S3 motccgp; system32\DRIVERS\motccgp.sys [X]
S3 motccgpfl; system32\DRIVERS\motccgpfl.sys [X]
S3 MotDev; system32\DRIVERS\motodrv.sys [X]
S3 motmodem; system32\DRIVERS\motmodem.sys [X]
U3 TlntSvr; no ImagePath
2015-12-08 15:28 - 2015-12-08 15:29 - 00000000 ___HD C:\Documents and Settings\All Users\Application Data\{FB62659C-5547-4284-846F-24B4EEDF86F7}
Task: C:\WINDOWS\Tasks\Critical Battery Alarm Program.job =>
CMD: ipconfig /flushdns
CMD: netsh winsock reset
CMD: ipconfig /release
CMD: ipconfig /renew
emptytemp:
*****************

Error: (0) Failed to create a restore point.
Processes closed successfully.
"HKLM\SOFTWARE\Policies\Microsoft\Internet Explorer" => key removed successfully.
HKU\S-1-5-21-2740428291-721650609-345291581-500\SOFTWARE\Policies\Microsoft\Internet Explorer => key not found.
HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\DefaultScope => value restored successfully
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{5CA3D70E-1895-11CF-8E15-001234567890} => key not found.
"HKCR\CLSID\{5CA3D70E-1895-11CF-8E15-001234567890}" => key removed successfully.
"HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{A8F38D8D-E480-4D52-B7A2-731BB6995FDD}" => key removed successfully.
"HKCR\CLSID\{A8F38D8D-E480-4D52-B7A2-731BB6995FDD}" => key removed successfully.
HKU\S-1-5-21-2740428291-721650609-345291581-500\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\\{C4069E3A-68F1-403E-B40E-20066696354B} => value not found.
HKCR\CLSID\{C4069E3A-68F1-403E-B40E-20066696354B} => key not found.
"HKLM\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{17492023-C23A-453E-A040-C7C580BBF700}" => key removed successfully.
"HKCR\CLSID\{17492023-C23A-453E-A040-C7C580BBF700}" => key removed successfully.
"HKLM\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{7530BFB8-7293-4D34-9923-61A11451AFC5}" => key removed successfully.
"HKCR\CLSID\{7530BFB8-7293-4D34-9923-61A11451AFC5}" => key removed successfully.
"HKLM\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{8AD9C840-044E-11D1-B3E9-00805F499D93}" => key removed successfully.
HKCR\CLSID\{8AD9C840-044E-11D1-B3E9-00805F499D93} => key could not remove.
"HKLM\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{8FFBE65D-2C9C-4669-84BD-5829DC0B603C}" => key removed successfully.
HKCR\CLSID\{8FFBE65D-2C9C-4669-84BD-5829DC0B603C} => key not found.
"HKLM\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{CAFEEFAC-0015-0000-0006-ABCDEFFEDCBA}" => key removed successfully.
"HKCR\CLSID\{CAFEEFAC-0015-0000-0006-ABCDEFFEDCBA}" => key removed successfully.
"HKLM\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{CAFEEFAC-0015-0000-0015-ABCDEFFEDCBA}" => key removed successfully.
"HKCR\CLSID\{CAFEEFAC-0015-0000-0015-ABCDEFFEDCBA}" => key removed successfully.
"HKLM\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{CAFEEFAC-0016-0000-0010-ABCDEFFEDCBA}" => key removed successfully.
"HKCR\CLSID\{CAFEEFAC-0016-0000-0010-ABCDEFFEDCBA}" => key removed successfully.
"HKLM\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{CAFEEFAC-0017-0000-0025-ABCDEFFEDCBA}" => key removed successfully.
"HKCR\CLSID\{CAFEEFAC-0017-0000-0025-ABCDEFFEDCBA}" => key removed successfully.
"HKLM\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{CAFEEFAC-0017-0000-0045-ABCDEFFEDCBA}" => key removed successfully.
"HKCR\CLSID\{CAFEEFAC-0017-0000-0045-ABCDEFFEDCBA}" => key removed successfully.
"HKLM\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA}" => key removed successfully.
HKCR\CLSID\{CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} => key could not remove.
"HKLM\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{E06E2E99-0AA1-11D4-ABA6-0060082AA75C}" => key removed successfully.
HKCR\CLSID\{E06E2E99-0AA1-11D4-ABA6-0060082AA75C} => key not found.
"HKLM\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{E2883E8F-472F-4FB0-9522-AC9BF37916A7}" => key removed successfully.
HKCR\CLSID\{E2883E8F-472F-4FB0-9522-AC9BF37916A7} => key not found.
catchme => service removed successfully.
cpuz138 => service removed successfully.
motccgp => service removed successfully.
motccgpfl => service removed successfully.
MotDev => service removed successfully.
motmodem => service removed successfully.
TlntSvr => service removed successfully.

"C:\Documents and Settings\All Users\Application Data\{FB62659C-5547-4284-846F-24B4EEDF86F7}" folder move:

Could not move "C:\Documents and Settings\All Users\Application Data\{FB62659C-5547-4284-846F-24B4EEDF86F7}" => Scheduled to move on reboot.

Task: C:\WINDOWS\Tasks\Critical Battery Alarm Program.job => => not found.

========= ipconfig /flushdns =========



Windows IP Configuration



Successfully flushed the DNS Resolver Cache.


========= End of CMD: =========


========= netsh winsock reset =========


WARNING: Could not obtain host information from machine: [YOUR-09DEDAFE33]. Some commands may not be available.
Class not registered


Sucessfully reset the Winsock Catalog.
You must restart the machine in order to complete the reset.


========= End of CMD: =========


========= ipconfig /release =========



Windows IP Configuration



IP Address for adapter Wireless Network Connection has already been released.

No operation can be performed on Local Area Connection while it has its media disconnected.


========= End of CMD: =========


========= ipconfig /renew =========



Windows IP Configuration



An error occurred while renewing interface Wireless Network Connection : unable to contact your DHCP server. Request has timed out.

No operation can be performed on Local Area Connection while it has its media disconnected.


========= End of CMD: =========

EmptyTemp: => 31.2 MB temporary data Removed.

Result of scheduled files to move (Boot Mode: Normal) (Date&Time: 2015-12-26 16:39:13)

C:\Documents and Settings\All Users\Application Data\{FB62659C-5547-4284-846F-24B4EEDF86F7} => is moved successfully

==== End of Fixlog 16:39:13 ====

#10 Oh My!

Oh My!

    Adware and Spyware and Malware.....


  • Malware Response Instructor
  • 37,769 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:California
  • Local time:05:01 AM

Posted 26 December 2015 - 05:00 PM

Thanks Tom. Please do this.

===================================================

Farbar's Service Scanner

--------------------
  • Please download Farbar Service Scanner, save it to your desktop, and run it.
  • Make sure the following options are checked:

Internet Services
Windows Firewall
System Restore
Security Center/Action Center
Windows Update
Windows Defender
Other Services

  • Press Scan
  • It will create a log (FSS.txt) in the same directory the tool is run.
  • Please copy and paste the log to your reply.
===================================================

Farbar's MiniToolBox

--------------------
  • Please download MiniToolBox, save it to your desktop
  • Please close any Firefox browsers you may have open
  • Double click the icon to launch the program
  • Make sure only the following options are checked:

Flush DNS
Report IE Proxy Settings
Reset IE Proxy Settings
Report FF Proxy Settings
Reset FF Proxy Settings
List content of Hosts
List IP configuration
List Winsock Entries
List last 10 Event Viewer Errors
List Installed Programs
List Devices - >>>>Only Problems <<<<
List Users, Partitions and Memory size
List Minidump Files

  • Click Go and once the scan is completed a Result.txt Notepad document will open on your desktop
  • Please copy and paste the contents in your reply
===================================================

Things I would like to see in your next reply. Please be sure to copy and paste any requested log information unless you are asked to attach it. :thumbsup2:
  • FSS.txt
  • Result.txt

Gary
 
If I do not reply within 24 hours please send me a Personal Message.

"Lord, to whom would we go? You have the words that give eternal life. We believe, and we know you are the Holy One of God."

#11 peaksmm

peaksmm
  • Topic Starter

  • Members
  • 32 posts
  • OFFLINE
  •  
  • Local time:07:01 AM

Posted 26 December 2015 - 05:23 PM

Completed. Here are the logs...

Farbar Service Scanner Version: 10-06-2014
Ran by 1 (administrator) on 26-12-2015 at 17:11:35
Running from "C:\Documents and Settings\1\Desktop"
Microsoft Windows XP Service Pack 3 (X86)
Boot Mode: Normal
****************************************************************

Internet Services:
============

Connection Status:
==============
Localhost is accessible.
LAN connected.
Attempt to access Google IP returned error. Google IP is unreachable
Attempt to access Google.com returned error: Other errors
Attempt to access Yahoo.com returned error: Other errors


Windows Firewall:
=============

Firewall Disabled Policy:
==================


System Restore:
============
Srservice Service is not running. Checking service configuration:
The start type of Srservice service is OK.
The ImagePath of Srservice service is OK.
The ServiceDll of Srservice service is OK.


System Restore Disabled Policy:
========================


Security Center:
============


Windows Update:
============
EventSystem Service is not running. Checking service configuration:
The start type of EventSystem service is set to Disabled. The default start type is 3.
The ImagePath of EventSystem: "C:\WINDOWS\system32\svchost.exe -k netsvcs".
The ServiceDll of EventSystem: "C:\WINDOWS\system32\es.dll".


Windows Autoupdate Disabled Policy:
============================


Other Services:
==============


File Check:
========
C:\WINDOWS\system32\dhcpcsvc.dll => File is digitally signed
C:\WINDOWS\system32\Drivers\afd.sys => File is digitally signed
C:\WINDOWS\system32\Drivers\netbt.sys => File is digitally signed
C:\WINDOWS\system32\Drivers\tcpip.sys => File is digitally signed
C:\WINDOWS\system32\Drivers\ipsec.sys => File is digitally signed
C:\WINDOWS\system32\dnsrslvr.dll => File is digitally signed
C:\WINDOWS\system32\ipnathlp.dll => File is digitally signed
C:\WINDOWS\system32\netman.dll => File is digitally signed
C:\WINDOWS\system32\wbem\WMIsvc.dll => File is digitally signed
C:\WINDOWS\system32\srsvc.dll => File is digitally signed
C:\WINDOWS\system32\Drivers\sr.sys => File is digitally signed
C:\WINDOWS\system32\wscsvc.dll => File is digitally signed
C:\WINDOWS\system32\wbem\WMIsvc.dll => File is digitally signed
C:\WINDOWS\system32\wuauserv.dll => File is digitally signed
C:\WINDOWS\system32\qmgr.dll => File is digitally signed
C:\WINDOWS\system32\es.dll => File is digitally signed
C:\WINDOWS\system32\cryptsvc.dll => File is digitally signed
C:\WINDOWS\system32\svchost.exe => File is digitally signed
C:\WINDOWS\system32\rpcss.dll => File is digitally signed
C:\WINDOWS\system32\services.exe => File is digitally signed

Extra List:
=======
Bridge(12) BridgeMP(11) Gpc(6) IPSec(4) NetBT(5) PSched(13) RFCOMM(10) Tcpip(3) Tcpip6(14)
0x0E0000000400000001000000020000000300000008000000090000000500000006000000070000000A0000000B0000000C0000000D0000000E000000
IpSec Tag value is correct.

**** End of log ****

And ....

MiniToolBox by Farbar Version: 02-11-2015
Ran by 1 (administrator) on 26-12-2015 at 17:14:36
Running from "C:\Documents and Settings\1\Desktop"
Microsoft Windows XP Service Pack 3 (X86)
Model: Manufacturer:
Boot Mode: Normal
***************************************************************************

========================= Flush DNS: ===================================


Windows IP Configuration



Successfully flushed the DNS Resolver Cache.


========================= IE Proxy Settings: ==============================

Proxy is not enabled.
No Proxy Server is set.

"Reset IE Proxy Settings": IE Proxy Settings were reset.
========================= Hosts content: =================================
127.0.0.1 localhost
========================= IP Configuration: ================================


WARNING: Could not obtain host information from machine: [YOUR-09DEDAFE33]. Some commands may not be available.
Class not registered



# ----------------------------------
# Interface IP Configuration
# ----------------------------------
pushd interface ip



popd
# End of interface IP configuration




Windows IP Configuration



Host Name . . . . . . . . . . . . : your-09dedafe33

Primary Dns Suffix . . . . . . . :

Node Type . . . . . . . . . . . . : Peer-Peer

IP Routing Enabled. . . . . . . . : No

WINS Proxy Enabled. . . . . . . . : No



Ethernet adapter Wireless Network Connection:



Connection-specific DNS Suffix . :

Description . . . . . . . . . . . : Broadcom 802.11b/g WLAN

Physical Address. . . . . . . . . : 00-14-A5-B2-1B-40

Dhcp Enabled. . . . . . . . . . . : Yes

Autoconfiguration Enabled . . . . : Yes

Autoconfiguration IP Address. . . : 169.254.241.212

Subnet Mask . . . . . . . . . . . : 255.255.0.0

IP Address. . . . . . . . . . . . : fe80::214:a5ff:feb2:1b40%4

Default Gateway . . . . . . . . . :

DNS Servers . . . . . . . . . . . : fec0:0:0:ffff::1%2

fec0:0:0:ffff::2%2

fec0:0:0:ffff::3%2



Ethernet adapter Local Area Connection:



Media State . . . . . . . . . . . : Media disconnected

Description . . . . . . . . . . . : Intel® PRO/100 VE Network Connection

Physical Address. . . . . . . . . : 00-16-D4-35-41-AF



Tunnel adapter Teredo Tunneling Pseudo-Interface:



Connection-specific DNS Suffix . :

Description . . . . . . . . . . . : Teredo Tunneling Pseudo-Interface

Physical Address. . . . . . . . . : FF-FF-FF-FF-FF-FF-FF-FF

Dhcp Enabled. . . . . . . . . . . : No

IP Address. . . . . . . . . . . . : fe80::ffff:ffff:fffd%6

Default Gateway . . . . . . . . . :

NetBIOS over Tcpip. . . . . . . . : Disabled



Tunnel adapter Automatic Tunneling Pseudo-Interface:



Connection-specific DNS Suffix . :

Description . . . . . . . . . . . : Automatic Tunneling Pseudo-Interface

Physical Address. . . . . . . . . : A9-FE-F1-D4

Dhcp Enabled. . . . . . . . . . . : No

IP Address. . . . . . . . . . . . : fe80::5efe:169.254.241.212%2

Default Gateway . . . . . . . . . :

DNS Servers . . . . . . . . . . . : fec0:0:0:ffff::1%2

fec0:0:0:ffff::2%2

fec0:0:0:ffff::3%2

NetBIOS over Tcpip. . . . . . . . : Disabled

Server: UnKnown
Address: 127.0.0.1

Ping request could not find host google.com. Please check the name and try again.

Server: UnKnown
Address: 127.0.0.1

Ping request could not find host yahoo.com. Please check the name and try again.



Pinging 127.0.0.1 with 32 bytes of data:



Reply from 127.0.0.1: bytes=32 time<1ms TTL=128

Reply from 127.0.0.1: bytes=32 time<1ms TTL=128



Ping statistics for 127.0.0.1:

Packets: Sent = 2, Received = 2, Lost = 0 (0% loss),

Approximate round trip times in milli-seconds:

Minimum = 0ms, Maximum = 0ms, Average = 0ms

===========================================================================
Interface List
0x1 ........................... MS TCP Loopback interface
0x2 ...00 14 a5 b2 1b 40 ...... Broadcom 802.11b/g WLAN - Packet Scheduler Miniport
0x3 ...00 16 d4 35 41 af ...... Intel® PRO/100 VE Network Connection - Packet Scheduler Miniport
===========================================================================
===========================================================================
Active Routes:
Network Destination Netmask Gateway Interface Metric
127.0.0.0 255.0.0.0 127.0.0.1 127.0.0.1 1
169.254.0.0 255.255.0.0 169.254.241.212 169.254.241.212 25
169.254.241.212 255.255.255.255 127.0.0.1 127.0.0.1 25
169.254.255.255 255.255.255.255 169.254.241.212 169.254.241.212 25
224.0.0.0 240.0.0.0 169.254.241.212 169.254.241.212 25
255.255.255.255 255.255.255.255 169.254.241.212 169.254.241.212 1
255.255.255.255 255.255.255.255 169.254.241.212 3 1
===========================================================================
Persistent Routes:
None
========================= Winsock entries =====================================

Catalog5 01 C:\WINDOWS\system32\mswsock.dll [245248] (Microsoft Corporation)
Catalog5 02 C:\WINDOWS\system32\winrnr.dll [16896] (Microsoft Corporation)
Catalog5 03 C:\WINDOWS\system32\mswsock.dll [245248] (Microsoft Corporation)
Catalog5 04 C:\WINDOWS\system32\wshbth.dll [108032] (Microsoft Corporation)
Catalog9 01 C:\WINDOWS\system32\mswsock.dll [245248] (Microsoft Corporation)
Catalog9 02 C:\WINDOWS\system32\mswsock.dll [245248] (Microsoft Corporation)
Catalog9 03 C:\WINDOWS\system32\mswsock.dll [245248] (Microsoft Corporation)
Catalog9 04 C:\WINDOWS\system32\mswsock.dll [245248] (Microsoft Corporation)
Catalog9 05 C:\WINDOWS\system32\mswsock.dll [245248] (Microsoft Corporation)
Catalog9 06 C:\WINDOWS\system32\mswsock.dll [245248] (Microsoft Corporation)
Catalog9 07 C:\WINDOWS\system32\mswsock.dll [245248] (Microsoft Corporation)
Catalog9 08 C:\WINDOWS\system32\mswsock.dll [245248] (Microsoft Corporation)
Catalog9 09 C:\WINDOWS\system32\mswsock.dll [245248] (Microsoft Corporation)
Catalog9 10 C:\WINDOWS\system32\mswsock.dll [245248] (Microsoft Corporation)
Catalog9 11 C:\WINDOWS\system32\mswsock.dll [245248] (Microsoft Corporation)
Catalog9 12 C:\WINDOWS\system32\mswsock.dll [245248] (Microsoft Corporation)
Catalog9 13 C:\WINDOWS\system32\mswsock.dll [245248] (Microsoft Corporation)
Catalog9 14 C:\WINDOWS\system32\mswsock.dll [245248] (Microsoft Corporation)
Catalog9 15 C:\WINDOWS\system32\mswsock.dll [245248] (Microsoft Corporation)
Catalog9 16 C:\WINDOWS\system32\mswsock.dll [245248] (Microsoft Corporation)
Catalog9 17 C:\WINDOWS\system32\mswsock.dll [245248] (Microsoft Corporation)
Catalog9 18 C:\WINDOWS\system32\mswsock.dll [245248] (Microsoft Corporation)
Catalog9 19 C:\WINDOWS\system32\mswsock.dll [245248] (Microsoft Corporation)
Catalog9 20 C:\WINDOWS\system32\mswsock.dll [245248] (Microsoft Corporation)
Catalog9 21 C:\WINDOWS\system32\mswsock.dll [245248] (Microsoft Corporation)
Catalog9 22 C:\WINDOWS\system32\mswsock.dll [245248] (Microsoft Corporation)
Catalog9 23 C:\WINDOWS\system32\mswsock.dll [245248] (Microsoft Corporation)
Catalog9 24 C:\WINDOWS\system32\mswsock.dll [245248] (Microsoft Corporation)
Catalog9 25 C:\WINDOWS\system32\mswsock.dll [245248] (Microsoft Corporation)
Catalog9 26 C:\WINDOWS\system32\mswsock.dll [245248] (Microsoft Corporation)
Catalog9 27 C:\WINDOWS\system32\mswsock.dll [245248] (Microsoft Corporation)
Catalog9 28 C:\WINDOWS\system32\mswsock.dll [245248] (Microsoft Corporation)
Catalog9 29 C:\WINDOWS\system32\mswsock.dll [245248] (Microsoft Corporation)
Catalog9 30 C:\WINDOWS\system32\mswsock.dll [245248] (Microsoft Corporation)
Catalog9 31 C:\WINDOWS\system32\mswsock.dll [245248] (Microsoft Corporation)
Catalog9 32 C:\WINDOWS\system32\mswsock.dll [245248] (Microsoft Corporation)
Catalog9 33 C:\WINDOWS\system32\mswsock.dll [245248] (Microsoft Corporation)
Catalog9 34 C:\WINDOWS\system32\rsvpsp.dll [92672] (Microsoft Corporation)
Catalog9 35 C:\WINDOWS\system32\rsvpsp.dll [92672] (Microsoft Corporation)

========================= Event log errors: ===============================

Application errors:
==================
Error: (12/26/2015 04:39:10 PM) (Source: VSS) (User: )
Description: Volume Shadow Copy Service error: Unexpected error calling routine CoCreateInstance. hr = 0x80040206.

Error: (12/26/2015 04:39:10 PM) (Source: EventSystem) (User: )
Description: The COM+ Event System detected a bad return code during its internal processing. HRESULT was 80070422 from line 44 of d:\comxp_sp3\com\com1x\src\events\tier1\eventsystemobj.cpp. Please contact Microsoft Product Support Services to report this error.

Error: (12/26/2015 04:13:26 PM) (Source: VSS) (User: )
Description: Volume Shadow Copy Service error: Unexpected error calling routine CoCreateInstance. hr = 0x80040206.

Error: (12/26/2015 04:13:26 PM) (Source: EventSystem) (User: )
Description: The COM+ Event System detected a bad return code during its internal processing. HRESULT was 80070422 from line 44 of d:\comxp_sp3\com\com1x\src\events\tier1\eventsystemobj.cpp. Please contact Microsoft Product Support Services to report this error.

Error: (12/26/2015 01:55:22 PM) (Source: VSS) (User: )
Description: Volume Shadow Copy Service error: Unexpected error calling routine CoCreateInstance. hr = 0x80040206.

Error: (12/26/2015 01:55:22 PM) (Source: EventSystem) (User: )
Description: The COM+ Event System detected a bad return code during its internal processing. HRESULT was 80070422 from line 44 of d:\comxp_sp3\com\com1x\src\events\tier1\eventsystemobj.cpp. Please contact Microsoft Product Support Services to report this error.

Error: (12/26/2015 01:39:32 PM) (Source: VSS) (User: )
Description: Volume Shadow Copy Service error: Unexpected error calling routine CoCreateInstance. hr = 0x80040206.

Error: (12/26/2015 01:39:32 PM) (Source: EventSystem) (User: )
Description: The COM+ Event System detected a bad return code during its internal processing. HRESULT was 80070422 from line 44 of d:\comxp_sp3\com\com1x\src\events\tier1\eventsystemobj.cpp. Please contact Microsoft Product Support Services to report this error.

Error: (12/26/2015 01:24:17 PM) (Source: VSS) (User: )
Description: Volume Shadow Copy Service error: Unexpected error calling routine CoCreateInstance. hr = 0x80040206.

Error: (12/26/2015 01:24:17 PM) (Source: EventSystem) (User: )
Description: The COM+ Event System detected a bad return code during its internal processing. HRESULT was 80070422 from line 44 of d:\comxp_sp3\com\com1x\src\events\tier1\eventsystemobj.cpp. Please contact Microsoft Product Support Services to report this error.


System errors:
=============
Error: (12/26/2015 05:14:37 PM) (Source: Service Control Manager) (User: )
Description: The Remote Access Connection Manager service depends on the Telephony service which failed to start because of the following error:
%%1058

Error: (12/26/2015 05:14:37 PM) (Source: Service Control Manager) (User: )
Description: The Remote Access Connection Manager service depends on the Telephony service which failed to start because of the following error:
%%1058

Error: (12/26/2015 05:05:16 PM) (Source: Service Control Manager) (User: )
Description: The Remote Access Connection Manager service depends on the Telephony service which failed to start because of the following error:
%%1058

Error: (12/26/2015 04:41:10 PM) (Source: DCOM) (User: YOUR-09DEDAFE33)
Description: DCOM got error "%%1058" attempting to start the service StiSvc with arguments ""
in order to run the server:
{A1F4E726-8CF1-11D1-BF92-0060081ED811}

Error: (12/26/2015 04:41:02 PM) (Source: DCOM) (User: YOUR-09DEDAFE33)
Description: DCOM got error "%%1058" attempting to start the service StiSvc with arguments ""
in order to run the server:
{A1F4E726-8CF1-11D1-BF92-0060081ED811}

Error: (12/26/2015 04:39:52 PM) (Source: Service Control Manager) (User: )
Description: The Remote Access Connection Manager service depends on the Telephony service which failed to start because of the following error:
%%1058

Error: (12/26/2015 04:39:27 PM) (Source: DCOM) (User: NT AUTHORITY)
Description: DCOM got error "%%1058" attempting to start the service EventSystem with arguments ""
in order to run the server:
{1BE1F766-5536-11D1-B726-00C04FB926AF}

Error: (12/26/2015 04:39:14 PM) (Source: Service Control Manager) (User: )
Description: The Remote Access Connection Manager service depends on the Telephony service which failed to start because of the following error:
%%1058

Error: (12/26/2015 04:39:14 PM) (Source: Service Control Manager) (User: )
Description: The Remote Access Connection Manager service depends on the Telephony service which failed to start because of the following error:
%%1058

Error: (12/26/2015 04:39:12 PM) (Source: Service Control Manager) (User: )
Description: The System Restore Service service terminated with the following error:
%%1359


Microsoft Office Sessions:
=========================
Error: (12/26/2015 04:39:10 PM) (Source: VSS)(User: )
Description: CoCreateInstance0x80040206

Error: (12/26/2015 04:39:10 PM) (Source: EventSystem)(User: )
Description: d:\comxp_sp3\com\com1x\src\events\tier1\eventsystemobj.cpp4480070422

Error: (12/26/2015 04:13:26 PM) (Source: VSS)(User: )
Description: CoCreateInstance0x80040206

Error: (12/26/2015 04:13:26 PM) (Source: EventSystem)(User: )
Description: d:\comxp_sp3\com\com1x\src\events\tier1\eventsystemobj.cpp4480070422

Error: (12/26/2015 01:55:22 PM) (Source: VSS)(User: )
Description: CoCreateInstance0x80040206

Error: (12/26/2015 01:55:22 PM) (Source: EventSystem)(User: )
Description: d:\comxp_sp3\com\com1x\src\events\tier1\eventsystemobj.cpp4480070422

Error: (12/26/2015 01:39:32 PM) (Source: VSS)(User: )
Description: CoCreateInstance0x80040206

Error: (12/26/2015 01:39:32 PM) (Source: EventSystem)(User: )
Description: d:\comxp_sp3\com\com1x\src\events\tier1\eventsystemobj.cpp4480070422

Error: (12/26/2015 01:24:17 PM) (Source: VSS)(User: )
Description: CoCreateInstance0x80040206

Error: (12/26/2015 01:24:17 PM) (Source: EventSystem)(User: )
Description: d:\comxp_sp3\com\com1x\src\events\tier1\eventsystemobj.cpp4480070422


=========================== Installed Programs ============================

32 Bit HP CIO Components Installer (HKLM\...\{A80FA752-C491-4ED9-ABF0-4278563160B2}) (Version: 7.1.8 - Hewlett-Packard) Hidden
5 Card Slingo from Hewlett-Packard Laptops (remove only) (HKLM\...\5DE4D54F-AA79-43A4-9C8A-C173E7E2B025) (Version: - WildTangent)
7-Zip 4.42 (HKLM\...\7-Zip) (Version: - )
Adobe Acrobat - Reader 6.0.2 Update (HKLM\...\{AC76BA86-0000-0000-0000-6028747ADE01}) (Version: 6.0.2 - Adobe Systems)
Adobe Acrobat and Reader 6.0.3 Update (HKLM\...\{AC76BA86-0000-7EC8-7489-000000000603}) (Version: 6.0.3 - Adobe Systems)
Adobe Acrobat and Reader 6.0.4 Update (HKLM\...\{AC76BA86-0000-7EC8-7489-000000000604}) (Version: 6.0.4 - Adobe Systems)
Adobe Acrobat and Reader 6.0.5 Update (HKLM\...\{AC76BA86-0000-7EC8-7489-000000000605}) (Version: 6.0.5 - Adobe Systems)
Adobe Acrobat and Reader 6.0.6 Update (HKLM\...\{AC76BA86-0000-7EC8-7489-000000000606}) (Version: 6.0.6 - Adobe Systems)
Adobe Flash Player 19 ActiveX (HKLM\...\Adobe Flash Player ActiveX) (Version: 19.0.0.245 - Adobe Systems Incorporated)
Adobe Flash Player 19 NPAPI (HKLM\...\Adobe Flash Player NPAPI) (Version: 19.0.0.185 - Adobe Systems Incorporated)
Adobe Flash Player 19 PPAPI (HKLM\...\Adobe Flash Player PPAPI) (Version: 19.0.0.185 - Adobe Systems Incorporated)
Adobe Reader 6.0.1 (HKLM\...\{AC76BA86-7AD7-1033-7B44-A00000000001}) (Version: 006.000.001 - Adobe Systems Incorporated)
Amazon Cloud Player (HKCU\...\Amazon Amazon Cloud Player) (Version: 2.3.0.422 - Amazon Services LLC)
Apple Application Support (HKLM\...\{A83279FD-CA4B-4206-9535-90974DE76654}) (Version: 2.1.5 - Apple Inc.)
Apple Mobile Device Support (HKLM\...\{CCA1EEA3-555E-4D05-AC46-4B49C6C5D887}) (Version: 3.2.0.47 - Apple Inc.)
Apple Software Update (HKLM\...\{789A5B64-9DD9-4BA5-915A-F0FC0A1B7BFE}) (Version: 2.1.3.127 - Apple Inc.)
AutoUpdate (HKLM\...\{18D10072035C4515918F7E37EAFAACFC}) (Version: 1.1 - )
Avanquest update (HKLM\...\{76E41F43-59D2-4F30-BA42-9A762EE1E8DE}) (Version: 1.25 - Avanquest Software)
BlackBerry Desktop Software 4.3 (HKLM\...\{3AE87269-BD57-4A58-B13D-FC67664BCFB8}) (Version: 4.3.0.17 - Research In Motion Ltd.) Hidden
BlackBerry Desktop Software 4.3 (HKLM\...\BlackBerry_{3AE87269-BD57-4A58-B13D-FC67664BCFB8}) (Version: 4.3.0.17 - Research In Motion Ltd.)
BlackBerry Device Software Updater (HKLM\...\{12BAA98C-F8DD-4BC9-BBE6-1C8463114197}) (Version: 6.0.1.37 - Research In Motion Ltd)
BlackBerry v4.2.1 for the 8100 Series Wireless Handheld (HKLM\...\{DD7C1079-A2CC-48FB-8208-1EE38C8C2FBA}) (Version: 4.2.1.107 (Platform 2.3.0.83) - Research In Motion Ltd.)
Blackhawk Striker 2 from Hewlett-Packard Laptops (remove only) (HKLM\...\384E0BF4-1E1F-45A6-B60E-42144A3F15CD) (Version: - WildTangent)
Boggle Supreme from Hewlett-Packard Laptops (remove only) (HKLM\...\5658FB14-16A4-4DAE-946B-1457BE31572E) (Version: - WildTangent)
Bounce Symphony from Hewlett-Packard Laptops (remove only) (HKLM\...\7A940E33-6993-404B-ABA6-ED62E8FBE615) (Version: - WildTangent)
BufferChm (HKLM\...\{2EEA7AA4-C203-4b90-A34F-19FB7EF1C81C}) (Version: 130.0.331.000 - Hewlett-Packard) Hidden
C4700 (HKLM\...\{A55F4F9F-CCA8-4732-AA1F-0390A4A50947}) (Version: 130.0.373.000 - Hewlett-Packard) Hidden
Cablenut 4.08 (HKLM\...\Cablenut) (Version: - )
CCleaner (HKLM\...\CCleaner) (Version: 5.12 - Piriform)
Citrix Online Launcher (HKLM\...\{F17C3DC2-2ACA-4B0E-BDBF-ACE61B14E7CD}) (Version: 1.0.183 - Citrix)
CleanUp! (HKLM\...\CleanUp!) (Version: - )
Compatibility Pack for the 2007 Office system (HKLM\...\{90120000-0020-0409-0000-0000000FF1CE}) (Version: 12.0.6514.5001 - Microsoft Corporation)
Conexant HD Audio (HKLM\...\CNXT_HDAUDIO) (Version: 3.40.0.50 - Conexant)
CPUID CPU-Z 1.74 (HKLM\...\CPUID CPU-Z_is1) (Version: - )
Crusader No Remorse (HKLM\...\{2AEA735F-B393-4D89-93EF-5849CB72B4A3}) (Version: 1.0.0.2 - Electronic Arts)
Crystal Maze from Hewlett-Packard Laptops (remove only) (HKLM\...\E94C7046-2F7D-4D4D-B76F-C412DCCEAAC2) (Version: - WildTangent)
Customer Experience Enhancement (HKLM\...\{23012310-3E05-46A5-88A9-C6CBCABCAC79}) (Version: Customer Experience Enhancement -1.0.0.1680 - Hewlett-Packard) Hidden
Customer Experience Enhancement (HKLM\...\InstallShield_{23012310-3E05-46A5-88A9-C6CBCABCAC79}) (Version: Customer Experience Enhancement -1.0.0.1680 - Hewlett-Packard)
Destinations (HKLM\...\{BD7204BA-DD64-499E-9B55-6A282CDF4FA4}) (Version: 130.0.0.0 - Hewlett-Packard) Hidden
DeviceDiscovery (HKLM\...\{21A2F5EE-1DC5-488A-BE7E-E526F8C61488}) (Version: 130.0.372.000 - Hewlett-Packard) Hidden
DivX Codec (HKLM\...\{7B63B2922B174135AFC0E1377DD81EC2}) (Version: 6.8.3 - DivX, Inc.)
DivX Converter (HKLM\...\{B13A7C41581B411290FBC0395694E2A9}) (Version: 6.6.1 - DivX, Inc.)
EPSON Printer Software (HKLM\...\EPSON Printer and Utilities) (Version: - )
ESET Online Scanner v3 (HKLM\...\ESET Online Scanner) (Version: - )
E-TRADE Pro 1.06 (HKLM\...\4285-0367-3118-9779) (Version: 1.06 - E*TRADE Financial)
FATE from Hewlett-Packard Laptops (remove only) (HKLM\...\6ECB6EE6-92E1-4525-AF3B-3CE51A7C5F89) (Version: - WildTangent)
Flip Words from Hewlett-Packard Laptops (remove only) (HKLM\...\F2566CC2-D4C4-44ED-A838-3F8288D8D3FE) (Version: - WildTangent)
Free eXPert PDF Reader (HKLM\...\{C2B5A2E5-51F8-4883-AF40-6A17902DAFEA}) (Version: 9.0.180.0 - Visagesoft)
Google Chrome (HKLM\...\Google Chrome) (Version: 47.0.2526.80 - Google Inc.)
Google Update Helper (HKLM\...\{60EC980A-BDA2-4CB6-A427-B07A5498B4CA}) (Version: 1.3.29.1 - Google Inc.) Hidden
Google Update Helper (HKLM\...\{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}) (Version: 1.3.25.11 - Google Inc.) Hidden
GoToMeeting 7.7.0.4062 (HKCU\...\GoToMeeting) (Version: 7.7.0.4062 - CitrixOnline)
GPBaseService2 (HKLM\...\{63FF21C9-A810-464F-B60A-3111747B1A6D}) (Version: 130.0.371.000 - Hewlett-Packard) Hidden
HDAUDIO Soft Data Fax Modem with SmartCP (HKLM\...\CNXT_MODEM_HDAUDIO_CPL30A5m) (Version: - )
HP DVD Play 2.1 (HKLM\...\{45D707E9-F3C4-11D9-A373-0050BAE317E1}) (Version: - )
HP Game Console and games (HKLM\...\HP Game Console) (Version: - WildTangent)
HP Help and Support (HKLM\...\{A93C4E94-1005-489D-BEAA-B873C1AA6CFC}) (Version: 4.2.0006 - HPQ)
HP Imaging Device Functions 13.0 (HKLM\...\HP Imaging Device Functions) (Version: 13.0 - HP)
HP Photosmart C4700 All-In-One Driver Software 13.0 Rel .6 (HKLM\...\{2012D762-5DCA-455A-B5FE-EDF79BC93E18}) (Version: 13.0 - HP)
HP Print Projects 1.0 (HKLM\...\HP Print Projects) (Version: 1.0 - HP)
HP Quick Launch Buttons 6.00 E2 (HKLM\...\{34D2AB40-150D-475D-AE32-BD23FB5EE355}) (Version: 6.00 E2 - Hewlett-Packard Company)
HP Smart Web Printing 4.5 (HKLM\...\HP Smart Web Printing) (Version: 4.5 - HP)
HP Solution Center 13.0 (HKLM\...\HP Solution Center & Imaging Support Tools) (Version: 13.0 - HP)
HP Update (HKLM\...\{2EFA4E4C-7B5F-48F7-A1C0-1AA882B7A9C3}) (Version: 5.003.001.001 - Hewlett-Packard)
HP User Guides 0019 (HKLM\...\{E74E3D81-773B-4DCF-B706-50236F80BD81}) (Version: 1.00.0003 - Hewlett-Packard)
HP User Guides--System Recovery (HKLM\...\{BC96BBA7-C634-460E-AD18-A0A994213F80}) (Version: 1.00.0001 - Hewlett-Packard)
HP Wireless Assistant 2.00 E1 (HKLM\...\{4302B2DD-D958-40E3-BAF3-B07FFE1978CE}) (Version: 2.00 E1 - Hewlett-Packard Company)
hpPrintProjects (HKLM\...\{C75CDBA2-3C86-481e-BD10-BDDA758F9DFF}) (Version: 130.0.303.000 - Hewlett-Packard) Hidden
HPProductAssistant (HKLM\...\{C43326F5-F135-4551-8270-7F7ABA0462E1}) (Version: 130.0.371.000 - Hewlett-Packard) Hidden
HpSdpAppCoreApp (HKLM\...\{DB518BA6-CB74-4EB6-9ABD-880B6D6E1F38}) (Version: 3.00.0000 - Hewlett-Packard) Hidden
hpWLPGInstaller (HKLM\...\{07FB17D8-7DB6-4F06-80C4-8BE1719CB6A1}) (Version: 130.0.303.000 - Hewlett-Packard) Hidden
Insaniquarium Deluxe from Hewlett-Packard Laptops (remove only) (HKLM\...\0E5266B4-9069-401A-93AE-5FF9F1712016) (Version: - WildTangent)
Intel® Graphics Media Accelerator Driver (HKLM\...\{8A708DD8-A5E6-11D4-A706-000629E95E20}) (Version: 6.14.10.4543 - )
Intel® Network Connections Drivers (HKLM\...\PROSet) (Version: - )
iTunes (HKLM\...\{2CE5A2E7-3437-4CE7-BCF4-85ED6EEFF9E4}) (Version: 10.0.1.22 - Apple Inc.)
Java 7 Update 71 (HKLM\...\{26A24AE4-039D-4CA4-87B4-2F03217071FF}) (Version: 7.0.710 - Oracle)
Java Auto Updater (HKLM\...\{4A03706F-666A-4037-7777-5F2748764D10}) (Version: 2.1.75.13 - Oracle, Inc.) Hidden
Jewel Quest from Hewlett-Packard Laptops (remove only) (HKLM\...\4C061F83-EE92-445A-A03F-184B0BD59242) (Version: - WildTangent)
Lemonade Tycoon 2 from Hewlett-Packard Laptops (remove only) (HKLM\...\E90E3AE9-73E4-4E5C-BB0F-673989A808D0) (Version: - WildTangent)
Lexibox Deluxe from Hewlett-Packard Laptops (remove only) (HKLM\...\5758A0E8-A112-4A1D-82EC-EC72F7F16B88) (Version: - WildTangent)
LightScribe 1.4.74.1 (HKLM\...\{D755C7A3-C03E-4460-8C00-AC6E55505FB5}) (Version: 1.4.74.1 - http://www.lightscribe.com) Hidden
Mah Jong Quest from Hewlett-Packard Laptops (remove only) (HKLM\...\E76A7EFF-7758-49EE-B3FA-9699830A2D6B) (Version: - WildTangent)
Malwarebytes Anti-Malware version 2.2.0.1024 (HKLM\...\Malwarebytes Anti-Malware_is1) (Version: 2.2.0.1024 - Malwarebytes)
Microsoft .NET Framework 1.1 (HKLM\...\Microsoft .NET Framework 1.1 (1033)) (Version: - )
Microsoft .NET Framework 1.1 Security Update (KB2833941) (HKLM\...\M2833941) (Version: - )
Microsoft .NET Framework 1.1 Security Update (KB979906) (HKLM\...\M979906) (Version: - )
Microsoft .NET Framework 2.0 Service Pack 2 (HKLM\...\{C09FB3CD-3D0C-3F2D-899A-6A1D67F2073F}) (Version: 2.2.30729 - Microsoft Corporation)
Microsoft .NET Framework 3.0 Service Pack 2 (HKLM\...\{A3051CD0-2F64-3813-A88D-B8DCCDE8F8C7}) (Version: 3.2.30729 - Microsoft Corporation)
Microsoft .NET Framework 3.5 SP1 (HKLM\...\Microsoft .NET Framework 3.5 SP1) (Version: - Microsoft Corporation)
Microsoft .NET Framework 4 Client Profile (HKLM\...\Microsoft .NET Framework 4 Client Profile) (Version: 4.0.30319 - Microsoft Corporation)
Microsoft Base Smart Card Cryptographic Service Provider Package (HKLM\...\KB909520) (Version: - Microsoft Corporation)
Microsoft Compression Client Pack 1.0 for Windows XP (HKLM\...\MSCompPackV1) (Version: 1 - Microsoft Corporation)
Microsoft Money 2006 (HKLM\...\Money2006b) (Version: 15 - Microsoft)
Microsoft Office 2000 Professional (HKLM\...\{00010409-78E1-11D2-B60F-006097C998E7}) (Version: 9.00.2720 - Microsoft Corporation)
Microsoft Office Standard Edition 2003 (HKLM\...\{91120409-6000-11D3-8CFE-0150048383C9}) (Version: 11.0.5614.0 - Microsoft Corporation)
Microsoft Office Word Viewer 2003 (HKLM\...\{90850409-6000-11D3-8CFE-0150048383C9}) (Version: 11.0.8173.0 - Microsoft Corporation)
Microsoft Silverlight (HKLM\...\{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}) (Version: 5.1.30514.0 - Microsoft Corporation)
Microsoft User-Mode Driver Framework Feature Pack 1.0 (HKLM\...\Wudf01000) (Version: - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM\...\{837b34e3-7c30-493c-8f6a-2b0f04e2912c}) (Version: 8.0.59193 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 (HKLM\...\{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}) (Version: 9.0.30729.4148 - Microsoft Corporation)
Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 (HKLM\...\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Works (HKLM\...\{416D80BA-6F6D-4672-B7CF-F54DA2F80B44}) (Version: 08.04.0623 - Microsoft Corporation)
MotoHelper MergeModules (HKLM\...\{94CAC2F1-C856-47F4-AF24-65A1E75AEDB9}) (Version: 1.2.0 - Motorola) Hidden
Motorola Phone Tools (HKLM\...\{BAD8CA9C-77C0-4663-B00B-A8D3B13C341B}) (Version: 4.3.6c 10-23-2006 - Avanquest Software)
Motorola Phone Tools (HKLM\...\{E8F728D0-C3F0-42EB-BBC2-C4A38A577CB1}) (Version: 4.30 - BVRP Software) Hidden
Mototools Software Update (HKLM\...\{1C23A809-EE16-453B-8CD6-94443B917839}) (Version: 3.4.6 - Motorola)
MSXML 4.0 SP2 (KB927978) (HKLM\...\{37477865-A3F1-4772-AD43-AAFC6BCFF99F}) (Version: 4.20.9841.0 - Microsoft Corporation)
MSXML 4.0 SP2 (KB936181) (HKLM\...\{C04E32E0-0416-434D-AFB9-6969D703A9EF}) (Version: 4.20.9848.0 - Microsoft Corporation)
MSXML 4.0 SP2 (KB954430) (HKLM\...\{86493ADD-824D-4B8E-BD72-8C5DCDC52A71}) (Version: 4.20.9870.0 - Microsoft Corporation)
MSXML 4.0 SP2 (KB973688) (HKLM\...\{F662A8E6-F4DC-41A2-901E-8C11F044BDEC}) (Version: 4.20.9876.0 - Microsoft Corporation)
muvee autoProducer 4.5 (HKLM\...\{286F29AF-0BE2-4D5F-AB17-B7631A810553}) (Version: 4.50.050 - muvee Technologies)
NetWaiting (HKLM\...\{3F92ABBB-6BBF-11D5-B229-002078017FBF}) (Version: 2.5.28 - BVRP Software, Inc)
Network (HKLM\...\{B2455727-ED8F-4643-8A6E-F4AB8DE3633D}) (Version: 130.0.374.000 - Hewlett-Packard) Hidden
Oasis from Hewlett-Packard Laptops (remove only) (HKLM\...\E332F38A-75F6-4EF2-88CC-246E8A1CB5D7) (Version: - WildTangent)
Office 2003 Trial Assistant (HKLM\...\{47D2103B-FD51-4017-9C20-DD408B17D726}) (Version: 1.0.0 - Microsoft)
Optimum App for Laptop 1.70 (HKLM\...\{6082AB31-92B1-4832-AC89-3B2E6D8C14FE}) (Version: 1.70 - Cablevision)
Origin (HKLM\...\Origin) (Version: 9.7.2.53208 - Electronic Arts, Inc.)
P@H-Protocol (HKLM\...\{CF594DB8-CFB0-45B4-86DA-8BB4AC0941F8}) (Version: 3.0.7.0 - Valassis)
PDF Creator (HKLM\...\PDF Creator) (Version: - )
Polar Bowler from Hewlett-Packard Laptops (remove only) (HKLM\...\7F8C5718-1BA9-4AAE-96D2-2B04D05F2D54) (Version: - WildTangent)
Polar Golfer from Hewlett-Packard Laptops (remove only) (HKLM\...\D2E44AA4-8665-4490-A6C9-2D0744B47B27) (Version: - WildTangent)
PS_AIO_06_C4700_SW_Min (HKLM\...\{E36F3199-C282-47CA-BAC7-2B77D247E760}) (Version: 130.0.373.000 - Hewlett-Packard) Hidden
Puzzle Express from Hewlett-Packard Laptops (remove only) (HKLM\...\EF860173-4FB7-4DE1-8BE8-5400F05A0DC5) (Version: - WildTangent)
Quicken 2006 (HKLM\...\{2818095F-FB6C-42C8-827E-0A406CC9AFF5}) (Version: 15.1.4.5 - Intuit)
QuickTime (HKLM\...\{E7004147-2CCA-431C-AA05-2AB166B9785D}) (Version: 7.68.75.0 - Apple Inc.)
RealPlayer (HKLM\...\RealPlayer 6.0) (Version: - RealNetworks)
ReOrganize! (HKLM\...\ReOrganize_is1) (Version: 2.3.1 - Oliver Frietsch)
Scan (HKLM\...\{0F367CA3-3B2F-43F9-A44A-25A8EE69E45D}) (Version: 13.0.0.0 - Hewlett-Packard) Hidden
SCRABBLE from Hewlett-Packard Laptops (remove only) (HKLM\...\103EFD47-9F2C-4490-95DD-AE6C442AFB92) (Version: - WildTangent)
SimCity 2000 Special Edition (HKLM\...\{59D2C751-F7BE-4E9F-9C8C-1F16013802C7}) (Version: 2.0.0.1 - Electronic Arts)
SiSoftware Sandra Lite 2014.RTM (HKLM\...\{C3113E55-7BCB-4de3-8EBF-60E6CE6B2396}_is1) (Version: 20.10.2014.2 - SiSoftware)
Slingo Deluxe from Hewlett-Packard Laptops (remove only) (HKLM\...\C264D692-8E15-4141-96A2-5621332E5DD0) (Version: - WildTangent)
Slyder from Hewlett-Packard Laptops (remove only) (HKLM\...\B0202B33-E73D-4FCD-AC88-0B2971AFC116) (Version: - WildTangent)
SmartAudio (HKLM\...\{AEF7A12C-CD9B-4773-8AD1-6916138CA7EA}) (Version: 1.3.7 - CONEXANT)
SmartWebPrinting (HKLM\...\{68A10D12-0D0F-4212-BDE6-D87FAD32A8FA}) (Version: 130.0.373.000 - Hewlett-Packard) Hidden
Snowboard SuperJam (HKLM\...\DED8E2B5-BA9F-448F-84E8-0AEF79876F95) (Version: 10/14/2005 02:33 PM - WildTangent)
SolutionCenter (HKLM\...\{4A70EF07-7F88-4434-BB61-D1DE8AE93DD4}) (Version: 130.0.373.000 - Hewlett-Packard) Hidden
Sonic Audio Module (HKLM\...\{AB708C9B-97C8-4AC9-899B-DBF226AC9382}) (Version: 2.0.4 - Sonic Solutions)
Sonic Copy Module (HKLM\...\{B12665F4-4E93-4AB4-B7FC-37053B524629}) (Version: 2.0.4 - Sonic Solutions)
Sonic Data Module (HKLM\...\{075473F5-846A-448B-BCB3-104AA1760205}) (Version: 2.0.4 - Sonic Solutions)
Sonic Express Labeler (HKLM\...\{6675CA7F-E51B-4F6A-99D4-F8F0124C6EAA}) (Version: 2.0.0 - Sonic Solutions)
Sonic MyDVD Plus (HKLM\...\{21657574-BD54-48A2-9450-EB03B2C7FC29}) (Version: 6.2.0 - Sonic Solutions)
Sonic Update Manager (HKLM\...\{30465B6C-B53F-49A1-9EBA-A3F187AD502E}) (Version: 3.0.0 - Sonic Solutions)
Sophos Virus Removal Tool (HKLM\...\{B829E117-D072-41EA-9606-9826A38D34C1}) (Version: 2.5.5 - Sophos Limited)
Spybot - Search & Destroy (HKLM\...\{B4092C6D-E886-4CB2-BA68-FE5A88D31DE6}_is1) (Version: 1.6.2 - Safer Networking Limited)
Status (HKLM\...\{AE8705FB-E13C-40A9-8A2D-68D6733FBFC2}) (Version: 130.0.373.000 - Hewlett-Packard) Hidden
Super Granny from Hewlett-Packard Laptops (remove only) (HKLM\...\7ED8A70C-9597-40BE-AEA0-0573182F1F51) (Version: - WildTangent)
Synaptics Pointing Device Driver (HKLM\...\SynTPDeinstKey) (Version: 10.0.13.2 - Synaptics)
Texas Instruments PCIxx21/x515/xx12 drivers. (HKLM\...\InstallShield_{7B6CF9EB-CB2B-4A1A-81A9-BE1A9044690A}) (Version: 1.15.0000 - Texas Instruments Inc.)
TIPCI (HKLM\...\{7B6CF9EB-CB2B-4A1A-81A9-BE1A9044690A}) (Version: 1.15.0000 - Texas Instruments Inc.) Hidden
Toolbox (HKLM\...\{6BBA26E9-AB03-4FE7-831A-3535584CA002}) (Version: 130.0.648.000 - Hewlett-Packard) Hidden
TourSetup (HKLM\...\{A01FC76F-CC09-4658-9E37-5C2F635EE708}) (Version: 1.0.0 - Microsoft)
Tradewinds from Hewlett-Packard Laptops (remove only) (HKLM\...\1C3FDBBA-EBF7-4CDB-AD8A-A1125734AF86) (Version: - WildTangent)
TrayApp (HKLM\...\{DC0A5F99-FD66-433F-9D3A-05DCBA64BE42}) (Version: 130.0.376.000 - Hewlett-Packard) Hidden
Unload (HKLM\...\{34F3FCF1-817B-4D61-B6AF-19D9486AFEA0}) (Version: 6.0.0 - Hewlett-Packard) Hidden
Update for Windows Internet Explorer 8 (KB2598845) (HKLM\...\KB2598845-IE8) (Version: 1 - Microsoft Corporation)
Update for Windows Internet Explorer 8 (KB2632503) (HKLM\...\KB2632503-IE8) (Version: 1 - Microsoft Corporation)
Update for Windows XP (KB2345886) (HKLM\...\KB2345886) (Version: 1 - Microsoft Corporation)
Update for Windows XP (KB2492386) (HKLM\...\KB2492386) (Version: 1 - Microsoft Corporation)
Update for Windows XP (KB2541763) (HKLM\...\KB2541763) (Version: 1 - Microsoft Corporation)
Update for Windows XP (KB2641690) (HKLM\...\KB2641690) (Version: 1 - Microsoft Corporation)
Update for Windows XP (KB2661254-v2) (HKLM\...\KB2661254-v2) (Version: 2 - Microsoft Corporation)
Update for Windows XP (KB2718704) (HKLM\...\KB2718704) (Version: 1 - Microsoft Corporation)
Update for Windows XP (KB2736233) (HKLM\...\KB2736233) (Version: 1 - Microsoft Corporation)
Update for Windows XP (KB2749655) (HKLM\...\KB2749655) (Version: 1 - Microsoft Corporation)
Update for Windows XP (KB2808679) (HKLM\...\KB2808679) (Version: 1 - Microsoft Corporation)
Update for Windows XP (KB2863058) (HKLM\...\KB2863058) (Version: 1 - Microsoft Corporation)
Update for Windows XP (KB2904266) (HKLM\...\KB2904266) (Version: 1 - Microsoft Corporation)
Update for Windows XP (KB2934207) (HKLM\...\KB2934207) (Version: 1 - Microsoft Corporation)
Update for Windows XP (KB951072-v2) (HKLM\...\KB951072-v2) (Version: 2 - Microsoft Corporation)
Update for Windows XP (KB951978) (HKLM\...\KB951978) (Version: 1 - Microsoft Corporation) Hidden
Update for Windows XP (KB955759) (HKLM\...\KB955759) (Version: 1 - Microsoft Corporation)
Update for Windows XP (KB967715) (HKLM\...\KB967715) (Version: 1 - Microsoft Corporation)
Update for Windows XP (KB968389) (HKLM\...\KB968389) (Version: 1 - Microsoft Corporation)
Update for Windows XP (KB971029) (HKLM\...\KB971029) (Version: 1 - Microsoft Corporation)
Update for Windows XP (KB971737) (HKLM\...\KB971737) (Version: 1 - Microsoft Corporation)
Update for Windows XP (KB973687) (HKLM\...\KB973687) (Version: 1 - Microsoft Corporation)
Update for Windows XP (KB973815) (HKLM\...\KB973815) (Version: 1 - Microsoft Corporation)
VoiceOver Kit (HKLM\...\{FB26A501-6BA6-459B-89AA-9736730752FB}) (Version: 1.30.128.0 - Apple Inc.)
WebEx (HKLM\...\ActiveTouchMeetingClient) (Version: - WebEx Communications, Inc)
WebFldrs XP (HKLM\...\{350C97B0-3D7C-4EE8-BAA9-00BCB3D54227}) (Version: 9.50.7523 - Microsoft Corporation) Hidden
WebReg (HKLM\...\{43CDF946-F5D9-4292-B006-BA0D92013021}) (Version: 130.0.132.017 - Hewlett-Packard) Hidden
WebWasher (HKLM\...\WebWasher) (Version: 3.4 - webwasher.com AG)
Widevine Media Optimizer Chrome 6.0.0 (HKCU\...\optimizer_chrome) (Version: 6.0.0.12757 - Widevine Technologies)
Windows Backup Utility (HKLM\...\{76EFFC7C-17A6-479D-9E47-8E658C1695AE}) (Version: 5.1 - Microsoft Corporation)
Windows Defender (HKLM\...\{A06275F4-324B-4E85-95E6-87B2CD729401}) (Version: 1.1.1593.0 - Microsoft Corporation)
Windows Genuine Advantage Validation Tool (KB892130) (HKLM\...\KB892130) (Version: - Microsoft Corporation)
Windows Genuine Advantage Validation Tool (KB892130) (HKLM\...\WGA) (Version: 1.7.0069.2 - Microsoft Corporation)
Windows Internet Explorer 8 (HKLM\...\ie8) (Version: 20090308.140743 - Microsoft Corporation)
Windows Management Framework Core (HKLM\...\KB968930) (Version: - Microsoft Corporation)
Windows Media Format 11 runtime (HKLM\...\Windows Media Format Runtime) (Version: - )
Windows Media Player 11 (HKLM\...\Windows Media Player) (Version: - )
Windows XP Service Pack 3 (HKLM\...\Windows XP Service Pack) (Version: 20080414.031525 - Microsoft Corporation)
Wing Commander III (HKLM\...\{F96B9930-E22A-44D6-81B5-6C8E92C21B4B}) (Version: 2.0.0.2 - Electronic Arts)
Wireless Home Network Setup (HKLM\...\{09D8492A-C8E2-421E-927D-46800FB327A3}) (Version: 1.1.154.1 - Hewlett-Packard)
Zuma Deluxe from Hewlett-Packard Laptops (remove only) (HKLM\...\074EEF5F-3BE8-4112-B253-C5D6CDE2924C) (Version: - WildTangent)
Zumas Revenge (HKLM\...\{0B153CAB-792B-4CA2-B2A5-AB0BBAF2FFA9}) (Version: 1.0.5.600 - PopCap Games)

========================= Devices: ================================


========================= Memory info: ===================================

Percentage of memory in use: 19%
Total physical RAM: 2038.05 MB
Available physical RAM: 1637.25 MB
Total Virtual: 1884.09 MB
Available Virtual: 1692.15 MB

========================= Partitions: =====================================

1 Drive c: () (Fixed) (Total:47.86 GB) (Free:9.16 GB) NTFS
2 Drive d: (PRESARIO_RP) (Fixed) (Total:8.01 GB) (Free:0.96 GB) FAT32

========================= Users: ========================================

User accounts for \\YOUR-09DEDAFE33

1 Administrator ASPNET
Guest HelpAssistant SUPPORT_388945a0

========================= Minidump Files ==================================

No minidump file found


**** End of log ****

#12 Oh My!

Oh My!

    Adware and Spyware and Malware.....


  • Malware Response Instructor
  • 37,769 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:California
  • Local time:05:01 AM

Posted 26 December 2015 - 05:39 PM

Thanks, is it possible to bypass your wireless router and plug the computer directly into the modem?
Gary
 
If I do not reply within 24 hours please send me a Personal Message.

"Lord, to whom would we go? You have the words that give eternal life. We believe, and we know you are the Holy One of God."

#13 peaksmm

peaksmm
  • Topic Starter

  • Members
  • 32 posts
  • OFFLINE
  •  
  • Local time:07:01 AM

Posted 26 December 2015 - 05:47 PM

By this do you mean hook into cable modem by ethernet cable? Yes. BTW, the system I am writing you on is operating fine - apparently on the same wireless router connection. From this I am assuming my modem and router are operating ok. Shall I proceed? What should I report? Thank you.

#14 Oh My!

Oh My!

    Adware and Spyware and Malware.....


  • Malware Response Instructor
  • 37,769 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:California
  • Local time:05:01 AM

Posted 26 December 2015 - 05:52 PM

OK you gave me the answer I was looking for! You can skip bypassing the router. :)

Please do this.

===================================================

Complete Internet Repair

--------------------
  • Please download comintrep.zip and save it to your desktop
  • Double click the icon and select Run
  • Click Extract
  • Double click the Complete Internet Repair folder on your desktop
  • Double click the CIntRep.exe icon
  • Place a checkmark next to the following entries:

Reset Internet Protocol (TCP/IP)
Repair Winsock (Reset Catalog)
Renew Internet Connections

  • Click Go!
  • Ignore any error messages for now
  • Click OK to reboot your computer
  • Check your internet access
===================================================

Things I would like to see in your next reply. Please be sure to copy and paste any requested log information unless you are asked to attach it. :thumbsup2:
  • Results?

Gary
 
If I do not reply within 24 hours please send me a Personal Message.

"Lord, to whom would we go? You have the words that give eternal life. We believe, and we know you are the Holy One of God."

#15 peaksmm

peaksmm
  • Topic Starter

  • Members
  • 32 posts
  • OFFLINE
  •  
  • Local time:07:01 AM

Posted 26 December 2015 - 06:17 PM

Okay, completed. Sorry Gary, no internet connection yet. Statistics shows reception of packets but zero packets transmitted. View wireless connections shows no available networks. There are in fact many. Refresh does not help. Change order of preferred networks brings unexpected error. Change advanced settings brings unexpected error. No DNS server is listed No default gatway is listed. I hope some of that is helpful. Thanx.




0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users