ComboFix 16-04-06.01 - User 04/10/2016 19:30:11.1.1 - x86 Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.1014.294 [GMT -4:00] Running from: c:\documents and settings\User\Desktop\internet.exe.exe AV: AVG 7.5.519 *Enabled/Outdated* {41564737-3200-1071-989B-0000E87B4FB1} * Created a new restore point . WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !! . . ((((((((((((((((((((((((((((((((((((((( Other Deletions ))))))))))))))))))))))))))))))))))))))))))))))))) . . c:\documents and settings\All Users\Application Data\61208421 c:\documents and settings\All Users\Application Data\TEMP c:\documents and settings\User\Application Data\02000000b57aeb9d517C.manifest c:\documents and settings\User\Application Data\02000000b57aeb9d517O.manifest c:\documents and settings\User\Application Data\02000000b57aeb9d517P.manifest c:\documents and settings\User\Application Data\02000000b57aeb9d517S.manifest c:\documents and settings\User\Application Data\FunWebProducts c:\progra~1\MYWEBS~1\bar\1.bin\mwsoemon.exe c:\program files\FunWebProducts c:\program files\FunWebProducts\ScreenSaver\Images\00163C90.urr c:\program files\FunWebProducts\Shared\Cache\CursorManiaBtn.html c:\program files\FunWebProducts\Shared\Cache\MyFunCardsIMBtn.html c:\program files\FunWebProducts\Shared\Cache\SmileyCentralBtn.html c:\program files\FunWebProducts\Shared\Cache\WebfettiBtn.html c:\program files\Internet Explorer\msimg32.dll c:\program files\Mozilla Firefox\Components\5d945d13-7ac3-4e67-6cd7-0c3621699717.dll c:\program files\mozilla firefox\components\nssnappyads.dll c:\program files\MyWebSearch c:\program files\MyWebSearch\bar\1.bin\F3BKGERR.JPG c:\program files\MyWebSearch\bar\1.bin\F3CJpeg.dll c:\program files\MyWebSearch\bar\1.bin\F3DTACTL.DLL c:\program files\MyWebSearch\bar\1.bin\F3HISTSW.DLL c:\program files\MyWebSearch\bar\1.bin\F3HTmlmu.dll c:\program files\MyWebSearch\bar\1.bin\F3HTTPCT.DLL c:\program files\MyWebSearch\bar\1.bin\F3IMSTUB.DLL c:\program files\MyWebSearch\bar\1.bin\F3POPSWT.DLL c:\program files\MyWebSearch\bar\1.bin\F3PSSAVR.SCR c:\program files\MyWebSearch\bar\1.bin\F3REPROX.DLL c:\program files\MyWebSearch\bar\1.bin\F3RESTUB.DLL c:\program files\MyWebSearch\bar\1.bin\F3SCHMON.EXE c:\program files\MyWebSearch\bar\1.bin\F3SCrctr.dll c:\program files\MyWebSearch\bar\1.bin\F3SPACER.WMV c:\program files\MyWebSearch\bar\1.bin\F3WALLPP.DAT c:\program files\MyWebSearch\bar\1.bin\F3WPHOOK.DLL c:\program files\MyWebSearch\bar\1.bin\FWPBUDDY.PNG c:\program files\MyWebSearch\bar\1.bin\M3FFXTBR.JAR c:\program files\MyWebSearch\bar\1.bin\M3FFXTBR.MANIFEST c:\program files\MyWebSearch\bar\1.bin\M3HIGHIN.EXE c:\program files\MyWebSearch\bar\1.bin\M3HTML.DLL c:\program files\MyWebSearch\bar\1.bin\M3IDLE.DLL c:\program files\MyWebSearch\bar\1.bin\M3IMPIPE.EXE c:\program files\MyWebSearch\bar\1.bin\M3MEDINT.EXE c:\program files\MyWebSearch\bar\1.bin\M3MSG.DLL c:\program files\MyWebSearch\bar\1.bin\M3NTSTBR.JAR c:\program files\MyWebSearch\bar\1.bin\M3NTSTBR.MANIFEST c:\program files\MyWebSearch\bar\1.bin\M3OUtlcn.dll c:\program files\MyWebSearch\bar\1.bin\M3PATCH.DLL c:\program files\MyWebSearch\bar\1.bin\M3PLUGIN.DLL c:\program files\MyWebSearch\bar\1.bin\M3SKIN.DLL c:\program files\MyWebSearch\bar\1.bin\M3SKPLAY.EXE c:\program files\MyWebSearch\bar\1.bin\M3SLSRCH.EXE c:\program files\MyWebSearch\bar\1.bin\M3SRCHMN.EXE c:\program files\MyWebSearch\bar\1.bin\MWSBAR.DLL c:\program files\MyWebSearch\bar\1.bin\MWSOEMON.EXE c:\program files\MyWebSearch\bar\1.bin\MWSOEPLG.DLL c:\program files\MyWebSearch\bar\1.bin\MWSOESTB.DLL c:\program files\MyWebSearch\bar\1.bin\MWSSVC.EXE c:\program files\MyWebSearch\bar\1.bin\NPMYWEBS.DLL c:\program files\MyWebSearch\bar\Avatar\COMMON.F3S c:\program files\MyWebSearch\bar\Cache\0003570A.bin c:\program files\MyWebSearch\bar\Cache\00035A08.bin c:\program files\MyWebSearch\bar\Cache\00035AA4.bin c:\program files\MyWebSearch\bar\Cache\00035B11.bin c:\program files\MyWebSearch\bar\Cache\00053A51.bin c:\program files\MyWebSearch\bar\Cache\0005B0D9.exe c:\program files\MyWebSearch\bar\Cache\049E5E76.bin c:\program files\MyWebSearch\bar\Cache\0556E80A c:\program files\MyWebSearch\bar\Cache\0556E9A0.bin c:\program files\MyWebSearch\bar\Cache\0556EA4C.bin c:\program files\MyWebSearch\bar\Cache\0556EAD8.bin c:\program files\MyWebSearch\bar\Cache\0556EEEF.bin c:\program files\MyWebSearch\bar\Cache\0556F19F.bin c:\program files\MyWebSearch\bar\Cache\09B9A2FC c:\program files\MyWebSearch\bar\Cache\1CA6B369 c:\program files\MyWebSearch\bar\Cache\37E944E6 c:\program files\MyWebSearch\bar\Cache\files.ini c:\program files\MyWebSearch\bar\Game\CHECKERS.F3S c:\program files\MyWebSearch\bar\Game\CHESS.F3S c:\program files\MyWebSearch\bar\Game\REVERSI.F3S c:\program files\MyWebSearch\bar\History\search3 c:\program files\MyWebSearch\bar\icons\CM.ICO c:\program files\MyWebSearch\bar\icons\MFC.ICO c:\program files\MyWebSearch\bar\icons\PSS.ICO c:\program files\MyWebSearch\bar\icons\SMILEY.ICO c:\program files\MyWebSearch\bar\icons\WB.ICO c:\program files\MyWebSearch\bar\icons\ZWINKY.ICO c:\program files\MyWebSearch\bar\Message\COMMON.F3S c:\program files\MyWebSearch\bar\Message\COMMON\ask_logo.gif c:\program files\MyWebSearch\bar\Message\COMMON\autoup.gif c:\program files\MyWebSearch\bar\Message\COMMON\autoup.htm c:\program files\MyWebSearch\bar\Message\COMMON\center.htm c:\program files\MyWebSearch\bar\Message\COMMON\index.htm c:\program files\MyWebSearch\bar\Message\COMMON\mid_dots.gif c:\program files\MyWebSearch\bar\Message\COMMON\mws_logo.gif c:\program files\MyWebSearch\bar\Message\COMMON\protect.htm c:\program files\MyWebSearch\bar\Message\COMMON\shocked.gif c:\program files\MyWebSearch\bar\Message\COMMON\stop.gif c:\program files\MyWebSearch\bar\Message\COMMON\systray.htm c:\program files\MyWebSearch\bar\Message\COMMON\systrayp.htm c:\program files\MyWebSearch\bar\Message\COMMON\tp_grad.gif c:\program files\MyWebSearch\bar\Message\COMMON\warn.gif c:\program files\MyWebSearch\bar\Notifier\COMMON.F3S c:\program files\MyWebSearch\bar\Notifier\DOG.F3S c:\program files\MyWebSearch\bar\Notifier\FISH.F3S c:\program files\MyWebSearch\bar\Notifier\KUNGFU.F3S c:\program files\MyWebSearch\bar\Notifier\LIFEGARD.F3S c:\program files\MyWebSearch\bar\Notifier\MAID.F3S c:\program files\MyWebSearch\bar\Notifier\MAILBOX.F3S c:\program files\MyWebSearch\bar\Notifier\OPERA.F3S c:\program files\MyWebSearch\bar\Notifier\ROBOT.F3S c:\program files\MyWebSearch\bar\Notifier\SEDUCT.F3S c:\program files\MyWebSearch\bar\Notifier\SURFER.F3S c:\program files\MyWebSearch\bar\Settings\prevcfg2.htm c:\program files\MyWebSearch\bar\Settings\s_pid.dat c:\program files\MyWebSearch\bar\Settings\setting2.htm c:\program files\MyWebSearch\bar\Settings\settings.dat c:\program files\MyWebSearch\SrchAstt\1.bin\MWSSRCAS.DLL c:\windows\Downloaded Program Files\f3initialsetup1.0.1.1.inf c:\windows\GnuHashes.ini c:\windows\iwowuvubomure.dll c:\windows\jmp32g.dll c:\windows\msa.exe c:\windows\msb.exe c:\windows\Rbojevevukovi.dll c:\windows\run.log c:\windows\svcho.exe c:\windows\sysguard.exe c:\windows\syssvc.exe c:\windows\system32\__c001F776.dat c:\windows\system32\__c0020E56.dat c:\windows\system32\__c002AF2.dat c:\windows\system32\__c003331E.dat c:\windows\system32\__c003C0C4.dat c:\windows\system32\__c0048749.dat c:\windows\system32\__c0053602.dat c:\windows\system32\__c005486A.dat c:\windows\system32\__c00639E0.dat c:\windows\system32\__c0070A81.dat c:\windows\system32\__c0074ADC.dat c:\windows\system32\__c008E701.dat c:\windows\system32\__c009276E.dat c:\windows\system32\__c009F3A6.dat c:\windows\system32\__c00C534A.dat c:\windows\system32\__c00C63E4.dat c:\windows\system32\__c00C89DE.dat c:\windows\system32\__c00CAA43.dat c:\windows\system32\__c00D63C8.dat c:\windows\system32\__c00E3E49.dat c:\windows\system32\__c00E4D7F.dat c:\windows\system32\__c00F4C32.dat c:\windows\system32\__c00F6724.dat c:\windows\system32\__c00F855E.dat c:\windows\system32\__c00F9A24.dat c:\windows\system32\14.tmp c:\windows\system32\193.tmp c:\windows\system32\19C.tmp c:\windows\system32\1A3.tmp c:\windows\system32\26C.tmp c:\windows\system32\319.tmp c:\windows\system32\32E.tmp c:\windows\system32\33E.tmp c:\windows\system32\3B2.tmp c:\windows\system32\401.tmp c:\windows\system32\42A.tmp c:\windows\system32\454.tmp c:\windows\system32\462.tmp c:\windows\system32\481.tmp c:\windows\system32\48B.tmp c:\windows\system32\4A3.tmp c:\windows\system32\4B9.tmp c:\windows\system32\4D5.tmp c:\windows\system32\595.tmp c:\windows\system32\744.tmp c:\windows\system32\84.tmp c:\windows\system32\88.tmp c:\windows\system32\ad77b191-c080-228f-493f-481377a1ab8e.exe c:\windows\system32\bruver.exe c:\windows\system32\DSSENH32.DLL c:\windows\system32\dx8vb32.dll c:\windows\system32\f3PSSavr.scr c:\windows\system32\f6f9f8be-a580-da3a-d24c-0c21c2c4cfda.dll c:\windows\system32\GroupPolicy000.dat c:\windows\system32\GroupPolicyManifest c:\windows\system32\GroupPolicyManifest\48.music.mp3 c:\windows\system32\GroupPolicyManifest\48.music.mp3.kwd c:\windows\system32\GroupPolicyManifest\49.music.snd c:\windows\system32\GroupPolicyManifest\49.music.snd.kwd c:\windows\system32\GroupPolicyManifest\50.crack.zip c:\windows\system32\GroupPolicyManifest\50.crack.zip.kwd c:\windows\system32\GroupPolicyManifest\51.keygen.zip c:\windows\system32\GroupPolicyManifest\51.keygen.zip.kwd c:\windows\system32\GroupPolicyManifest\52.keymaker.zip c:\windows\system32\GroupPolicyManifest\52.keymaker.zip.kwd c:\windows\system32\GroupPolicyManifest\53.serial.zip c:\windows\system32\GroupPolicyManifest\53.serial.zip.kwd c:\windows\system32\GroupPolicyManifest\54.setup.zip c:\windows\system32\GroupPolicyManifest\54.setup.zip.kwd c:\windows\system32\GroupPolicyManifest\55.unpack.zip c:\windows\system32\GroupPolicyManifest\55.unpack.zip.kwd c:\windows\system32\iehelper.dll c:\windows\system32\lahezeya.dll c:\windows\system32\leyoyoji.dll c:\windows\system32\logon.exe c:\windows\system32\lowsec c:\windows\system32\lowsec\local.ds c:\windows\system32\lowsec\user.ds c:\windows\system32\lowsec\user.ds.lll c:\windows\system32\mcoqkzujlic.dll-uninst.exe c:\windows\system32\net.net c:\windows\system32\sdra64.exe c:\windows\system32\SET303.tmp c:\windows\system32\SET305.tmp c:\windows\system32\SET306.tmp c:\windows\system32\SET312.tmp c:\windows\system32\SET314.tmp c:\windows\system32\SET315.tmp c:\windows\system32\SET31A.tmp c:\windows\system32\SET31B.tmp c:\windows\system32\SET31D.tmp c:\windows\system32\SET31F.tmp c:\windows\system32\SET320.tmp c:\windows\system32\sibofuda.dll c:\windows\system32\u_mcoqkzujlic.dll.exe c:\windows\system32\undefined-remove.exe c:\windows\system32\users32.dat c:\windows\system32\wazuhope.dll c:\windows\system32\winivstr.exe c:\windows\system32\wojajugi.dll c:\windows\wininit.ini C:\xcrashdump.dat . Infected copy of c:\windows\system32\eventlog.dll was found and disinfected Restored copy from - c:\i386\eventlog.dll . . ((((((((((((((((((((((((((((((((((((((( Drivers/Services ))))))))))))))))))))))))))))))))))))))))))))))))) . . -------\Legacy_MYWEBSEARCHSERVICE -------\Legacy_{79007602-0CDB-4405-9DBF-1257BB3226ED} -------\Service_MyWebSearchService . . ((((((((((((((((((((((((( Files Created from 2016-03-11 to 2016-04-11 ))))))))))))))))))))))))))))))) . . 2016-04-10 20:51 . 2016-04-10 20:51 0 ----a-w- c:\windows\system32\F7C.tmp 2016-04-10 20:51 . 2016-04-10 20:51 0 ----a-w- c:\windows\system32\F79.tmp 2016-04-09 09:20 . 2016-04-09 09:20 0 ----a-w- c:\windows\system32\CB8.tmp 2016-04-08 17:11 . 2016-04-10 01:00 -------- d-----w- C:\FRST 2016-04-08 13:25 . 2016-04-08 13:25 0 ----a-w- c:\windows\system32\1DD.tmp 2016-04-06 01:10 . 2016-04-06 01:10 -------- d-----w- c:\program files\Common Files\AV 2016-04-06 01:02 . 2013-09-20 14:49 18968 ----a-w- c:\windows\system32\sdnclean.exe 2016-04-06 01:02 . 2016-04-06 03:25 -------- d-----w- c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy 2016-04-06 01:01 . 2016-04-06 03:22 -------- d-----w- c:\program files\Spybot - Search & Destroy 2 2016-04-06 01:00 . 2016-04-06 20:40 -------- d-----w- c:\documents and settings\All Users\Application Data\Package Cache 2016-04-06 00:34 . 2016-04-07 17:42 170200 ----a-w- c:\windows\system32\drivers\MBAMSwissArmy.sys 2016-04-06 00:34 . 2016-03-10 18:09 123264 ----a-w- c:\windows\system32\drivers\mbamchameleon.sys 2016-04-06 00:34 . 2016-03-10 18:08 24448 ----a-w- c:\windows\system32\drivers\mbam.sys 2016-04-06 00:34 . 2016-04-07 17:35 -------- d-----w- c:\program files\Malwarebytes Anti-Malware 2016-04-06 00:34 . 2016-04-06 00:34 -------- d-----w- c:\documents and settings\All Users\Application Data\Malwarebytes 2016-04-06 00:21 . 2016-04-06 00:21 -------- d-----w- c:\windows\Performance 2016-04-06 00:20 . 2016-04-06 00:20 -------- d-----w- c:\documents and settings\User\Local Settings\Application Data\Microsoft Corporation 2016-04-06 00:19 . 2016-04-06 00:19 -------- d-----w- c:\program files\Microsoft Windows 7 Upgrade Advisor . . . (((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))) . 2008-12-24 13:51 . 2008-03-21 01:59 67688 ----a-w- c:\program files\mozilla firefox\components\jar50.dll 2008-12-24 13:51 . 2008-03-21 01:59 54368 ----a-w- c:\program files\mozilla firefox\components\jsd3250.dll 2009-09-09 11:03 . 2009-09-09 11:03 364544 ----a-w- c:\program files\mozilla firefox\components\mcoqkzujlic.dll 2008-12-24 13:51 . 2008-03-21 01:59 34944 ----a-w- c:\program files\mozilla firefox\components\myspell.dll 2008-12-24 13:51 . 2008-03-21 01:59 46712 ----a-w- c:\program files\mozilla firefox\components\spellchk.dll 2008-12-24 13:51 . 2008-03-21 01:59 172136 ----a-w- c:\program files\mozilla firefox\components\xpinstal.dll 2009-07-25 01:35 38912 --sha-w- c:\windows\system32\benituyo.dll 2009-07-24 13:35 38912 --sha-w- c:\windows\system32\pofutuva.dll 2009-07-25 01:35 52224 --sha-w- c:\windows\system32\polelure.dll . . ((((((((((((((((((((((((((((((((((((( Reg Loading Points )))))))))))))))))))))))))))))))))))))))))))))))))) . . *Note* empty entries & legit default entries are not shown REGEDIT4 . [HKEY_LOCAL_MACHINE\SOFTWARE\~\Browser Helper Objects\{81CFA2BF-8FE8-2409-8FA6-A6B19037CBF7}] 2009-10-01 08:06 482816 ----a-w- c:\windows\system32\jlmjvkexubwmndts.dll . [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2009-06-23 39408] "Yahoo! Pager"="c:\program files\Yahoo!\Messenger\YahooMessenger.exe" [2007-08-30 4670704] "Aim6"="c:\program files\AIM6\aim6.exe" [2008-03-25 50528] "SpybotPostWindows10UpgradeReInstall"="c:\program files\Common Files\AV\Spybot - Search and Destroy\Test.exe" [2015-07-28 1011200] "ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2004-08-10 15360] . [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "ehTray"="c:\windows\ehome\ehtray.exe" [2005-09-29 67584] "igfxtray"="c:\windows\system32\igfxtray.exe" [2008-03-18 94208] "igfxhkcmd"="c:\windows\system32\hkcmd.exe" [2008-03-18 77824] "igfxpers"="c:\windows\system32\igfxpers.exe" [2008-03-18 114688] "SunJavaUpdateSched"="c:\program files\Java\jre1.6.0_07\bin\jusched.exe" [2008-06-10 144784] "DVDLauncher"="c:\program files\CyberLink\PowerDVD\DVDLauncher.exe" [2005-02-23 53248] "dla"="c:\windows\system32\dla\tfswctrl.exe" [2008-03-18 127035] "ISUSPM Startup"="c:\program files\Common Files\InstallShield\UpdateService\isuspm.exe" [2008-03-18 249856] "ISUSScheduler"="c:\program files\Common Files\InstallShield\UpdateService\issch.exe" [2008-03-18 81920] "MimBoot"="c:\progra~1\MUSICM~1\MUSICM~3\mimboot.exe" [2005-09-09 8192] "MSKDetectorExe"="c:\program files\McAfee\SpamKiller\MSKDetct.exe" [2008-03-18 1117184] "AVG7_CC"="c:\progra~1\Grisoft\AVG7\avgcc.exe" [2008-03-18 579072] "TkBellExe"="c:\program files\Common Files\Real\Update_OB\realsched.exe" [2008-10-21 185872] "QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2008-11-04 413696] "iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2008-11-20 290088] "SDTray"="c:\program files\Spybot - Search & Destroy 2\SDTray.exe" [2014-06-24 4101576] "qoqavedsucue"="c:\windows\system32\jlmjvkexubwmndts.dll" [2009-10-01 482816] . [HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run] "AVG7_Run"="c:\progra~1\Grisoft\AVG7\avgw.exe" [2008-02-28 219136] . [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\session manager] BootExecute REG_MULTI_SZ autocheck autochk *\0\0sdnclean.exe . [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile] "EnableFirewall"= 0 (0x0) . [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List] "%windir%\\system32\\sessmgr.exe"= "c:\\Program Files\\Grisoft\\AVG7\\avginet.exe"= "c:\\Program Files\\Grisoft\\AVG7\\avgamsvr.exe"= "c:\\Program Files\\Grisoft\\AVG7\\avgcc.exe"= "c:\\Program Files\\Grisoft\\AVG7\\avgemc.exe"= "c:\\Program Files\\Messenger\\msmsgs.exe"= "c:\\Program Files\\Yahoo!\\Messenger\\YahooMessenger.exe"= "c:\\Program Files\\Yahoo!\\Messenger\\YServer.exe"= "c:\\Program Files\\Common Files\\AOL\\Loader\\aolload.exe"= "c:\\Program Files\\Winamp Remote\\bin\\Orb.exe"= "c:\\Program Files\\Winamp Remote\\bin\\OrbTray.exe"= "c:\\Program Files\\Winamp Remote\\bin\\OrbStreamerClient.exe"= "c:\\Program Files\\AIM6\\aim6.exe"= "c:\\Program Files\\Pinnacle\\Studio 12\\Programs\\RM.exe"= "c:\\Program Files\\Pinnacle\\Studio 12\\Programs\\Studio.exe"= "c:\\Program Files\\Pinnacle\\Studio 12\\Programs\\umi.exe"= "c:\\Program Files\\iTunes\\iTunes.exe"= "c:\\Program Files\\Bonjour\\mDNSResponder.exe"= "c:\\Program Files\\Spybot - Search & Destroy 2\\SDTray.exe"= "c:\\Program Files\\Spybot - Search & Destroy 2\\SDFSSvc.exe"= "c:\\Program Files\\Spybot - Search & Destroy 2\\SDUpdate.exe"= "c:\\Program Files\\Spybot - Search & Destroy 2\\SDUpdSvc.exe"= . R2 SDScannerService;Spybot-S&D 2 Scanner Service;c:\program files\Spybot - Search & Destroy 2\SDFSSvc.exe [4/5/2016 9:02 PM 1738168] R2 SDUpdateService;Spybot-S&D 2 Updating Service;c:\program files\Spybot - Search & Destroy 2\SDUpdSvc.exe [4/5/2016 9:02 PM 2088408] R2 Viewpoint Manager Service;Viewpoint Manager Service;c:\program files\Viewpoint\Common\ViewpointService.exe [3/20/2008 9:57 PM 24652] S2 gupdate1c98bd79446a1fa;Google Update Service (gupdate1c98bd79446a1fa);c:\program files\Google\Update\GoogleUpdate.exe [2/10/2009 7:30 PM 154440] S2 SDWSCService;Spybot-S&D 2 Security Center Service;c:\program files\Spybot - Search & Destroy 2\SDWSCSvc.exe [4/5/2016 9:02 PM 171928] . --- Other Services/Drivers In Memory --- . *NewlyCreated* - WS2IFSL . [HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{8A69D345-D564-463c-AFF1-A69D9E530F96}] 2016-04-05 22:19 1106072 ----a-w- c:\program files\Google\Chrome\Application\49.0.2623.110\Installer\chrmstp.exe . Contents of the 'Scheduled Tasks' folder . 2010-07-14 c:\windows\Tasks\AppleSoftwareUpdate.job - c:\program files\Apple Software Update\SoftwareUpdate.exe [2007-08-29 17:34] . 2016-04-11 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job - c:\program files\Google\Update\GoogleUpdate.exe [2009-02-10 22:17] . 2016-04-10 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job - c:\program files\Google\Update\GoogleUpdate.exe [2009-02-10 22:17] . . ------- Supplementary Scan ------- . uStart Page = hxxp://www.google.com uSearchMigratedDefaultUrl = hxxp://www.mywebsearch.com/jsp/cfg_redir2.jsp?id=ZKxdm173PAUS&fl=0&ptb=DabTlgNPJrCle4adZZyvCA&ind=2008120821&url=http://www.ask.com/web&q={searchTerms}&l=zk&o=sb uInternet Connection Wizard,ShellNext = hxxp://www.google.com/ig/dell?hl=en&client=dell uInternet Settings,ProxyOverride = *.local uSearchAssistant = hxxp://www.google.com uSearchURL,(Default) = hxxp://www.google.com/search?q=%s IE: &AIM Search - c:\program files\aol\aim toolbar 5.0\resources\en-US\local\search.html Trusted Zone: musicmatch.com\online TCP: DhcpNameServer = 75.75.75.75 75.75.76.76 FF - ProfilePath - c:\documents and settings\User\Application Data\Mozilla\Firefox\Profiles\mq3tdcno.default\ FF - prefs.js: browser.search.defaulturl - hxxp://www15.yoog.com/search.php?q= FF - prefs.js: browser.search.selectedEngine - Yoog Search FF - prefs.js: keyword.URL - hxxp://www15.yoog.com/search.php?q= /search.php?q=); FF - user.js: browser.search.defaultenginename - Yoog Search FF - user.js: browser.search.defaulturl - hxxp://www15.searchonthego.net/search.php?q= FF - user.js: browser.search.selectedEngine - Yoog Search FF - user.js: keyword.URL - hxxp://www15.searchonthego.net/search.php?q= FF - user.js: keyword.enabled - true . - - - - ORPHANS REMOVED - - - - . URLSearchHooks-HookURL - (no file) URLSearchHooks-Rank - (no file) BHO-{86cf5349-d78b-95a4-f4bf-9bfc7f30548a} - c:\windows\system32\f6f9f8be-a580-da3a-d24c-0c21c2c4cfda.dll BHO-{89789042-b5c5-4c8f-a36c-d5df0586d26f} - lahezeya.dll HKCU-Run-DW6 - c:\program files\The Weather Channel FW\Desktop\DesktopWeather.exe HKLM-Run-MyWebSearch Plugin - c:\progra~1\MYWEBS~1\bar\1.bin\M3PLUGIN.DLL HKLM-Run-Kcesad - c:\windows\Rbojevevukovi.dll HKLM-Run-Nrejidefayoq - c:\windows\iwowuvubomure.dll HKLM-Run-dutuzisab - c:\windows\system32\wazuhope.dll HKLM-Run-dewiyejiri - wojajugi.dll SharedTaskScheduler-{63365df1-c369-4706-9306-02d0246e257d} - (no file) SharedTaskScheduler-{9205b1d0-62cd-4d46-a5d1-f6306e7c93c3} - (no file) SharedTaskScheduler-{7997c9c8-269f-4afb-affa-94e1481376ff} - (no file) SharedTaskScheduler-{c8ff3df5-e2bc-4989-ae32-e6f7b73b1037} - (no file) SharedTaskScheduler-{94ca385e-4a00-4b3a-bb66-5fb17c1832d8} - c:\windows\system32\wazuhope.dll SSODL-gakufisiv-{94ca385e-4a00-4b3a-bb66-5fb17c1832d8} - c:\windows\system32\wazuhope.dll Notify-20190562517 - c:\windows\System32\dssenh32.dll AddRemove-ad77b191-c080-228f-493f-481377a1ab8e - c:\windows\system32\ad77b191-c080-228f-493f-481377a1ab8e.exe AddRemove-The Weather Channel Desktop 6 - c:\program files\The Weather Channel FW\Desktop\TheWeatherChannelCustomUninstall.exe AddRemove-undefined - c:\windows\system32\undefined-remove.exe AddRemove-WebCyberCoach_wtrb - c:\program files\WebCyberCoach\b_Dell\WCC_Wipe.exe WebCyberCoach ext\wtrb AddRemove-{2BC1DE1D-6C30-8DCF-64A7-D7C4E529F3CB} - c:\windows\system32\u_mcoqkzujlic.dll.exe . . . ************************************************************************** . catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net Rootkit scan 2016-04-10 20:00 Windows 5.1.2600 Service Pack 2 NTFS . scanning hidden processes ... . scanning hidden autostart entries ... . scanning hidden files ... . scan completed successfully hidden files: 0 . ************************************************************************** . Stealth MBR rootkit/Mebroot/Sinowal/TDL4 detector 0.4.2 by Gmer, http://www.gmer.net Windows 5.1.2600 Disk: ST380819AS rev.8.04 -> Harddisk0\DR0 -> \Device\Ide\IdePort1 P1T0L0-17 . device: opened successfully user: MBR read successfully . Disk trace: called modules: ntkrnlpa.exe CLASSPNP.SYS disk.sys >>UNKNOWN [0x87183E07]<< _asm { PUSH EBP; MOV EBP, ESP; MOV EAX, [0xffdf0308]; MOV ECX, [EBP+0x8]; SUB ESP, 0xc; PUSH EBX; PUSH ESI; MOV ESI, [EBP+0xc]; XOR EBX, EBX; CMP ECX, [EAX+0xc]; PUSH EDI; MOV EDI, [ESI+0x60]; JNZ 0x58; } 1 ntkrnlpa!IofCallDriver[0x804EF1A0] -> \Device\Harddisk0\DR0[0x8718EAB8] 3 CLASSPNP[0xF759D05B] -> ntkrnlpa!IofCallDriver[0x804EF1A0] -> [0x87193D98] [0x87050880] -> IRP_MJ_CREATE -> 0x87183E07 kernel: MBR read successfully _asm { MOV AX, 0x0; MOV SS, AX; MOV SP, 0x7c00; MOV DS, AX; CLD ; MOV CX, 0x80; MOV SI, SP; MOV DI, 0x600; MOV ES, AX; REP MOVSD ; JMP FAR 0x0:0x62d; } detected disk devices: \Device\Ide\IdeDeviceP1T0L0-17 -> \??\IDE#DiskST380819AS______________________________8.04____#5&f85c66f&0&0.0.0#{53f56307-b6bf-11d0-94f2-00a0c91efb8b} device not found detected hooks: user & kernel MBR OK sectors 156249998 (+36): user != kernel Warning: possible TDL3 rootkit infection ! . ************************************************************************** . --------------------- LOCKED REGISTRY KEYS --------------------- . [HKEY_USERS\.Default\Software\Microsoft\Internet Explorer\User Preferences] @Denied: (2) (LocalSystem) "88D7D0879DAB32E14DE5B3A805A34F98AFF34F5977"=hex:01,00,00,00,d0,8c,9d,df,01,15, d1,11,8c,7a,00,c0,4f,c2,97,eb,01,00,00,00,de,e6,34,11,8e,34,1c,45,a7,c4,f0,\ "2D53CFFC5C1A3DD2E97B7979AC2A92BD59BC839E81"=hex:01,00,00,00,d0,8c,9d,df,01,15, d1,11,8c,7a,00,c0,4f,c2,97,eb,01,00,00,00,de,e6,34,11,8e,34,1c,45,a7,c4,f0,\ . [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{35E958F5-7110-3B62-AEDC-D4C28D4DB5C9}\Implemented Categories\{62C8FE65-4EBB-45e7-B440-6E39B2CDBF29}] @DACL=(02 0000) @SACL= . [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{35E958F5-7110-3B62-AEDC-D4C28D4DB5C9}\InprocServer32] @DACL=(02 0000) @SACL= @="c:\\WINDOWS\\system32\\mscoree.dll" "ThreadingModel"="Both" "Class"="WTConstants" "Assembly"="GemMaster3, Version=3.0.0.0, Culture=neutral, PublicKeyToken=1bf1415c4c44d353" "RuntimeVersion"="v1.0.3705" . [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{35E958F5-7110-3B62-AEDC-D4C28D4DB5C9}\ProgId] @DACL=(02 0000) @SACL= @="WTConstants" . [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{363F1015-FD5F-4ba8-AC58-29634F378A42}] @DACL=(02 0000) @="EngUKWrdBrk Class" . [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{36ED0757-2FA5-45D9-891D-F0C5B367EE5C}] @DACL=(02 0000) @="ContentFrameObj Class" "AppID"="{D87F14AA-CA49-46CE-81FF-FA2504E27993}" . [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{372D1C09-EBAF-477C-82F4-426173BD61C3}] @DACL=(02 0000) @="CTracks Object" "AppID"="" . [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{37C15872-BF9C-4695-B29C-62646509DDDB}] @DACL=(02 0000) @SACL= @="cyrillic3x4inputmodule class" . [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{381465E7-7410-4E43-8258-963AFF838968}] @DACL=(02 0000) @="moLicenseManagerFactory Object" "AppID"="{2316B3B3-9AA8-4184-9C93-D927D74396B4}" . [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{3833F800-2983-43EC-8E6D-CC50BB59BA35}] @DACL=(02 0000) @="moCdDvd_Factory Object" "AppID"="" . [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{38C67D0E-24F4-4EE5-81E2-60BC1B5596E2}] @DACL=(02 0000) @="moDirTag Object" "AppID"="" . [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{399CB6C4-7312-11D2-B4D9-00105A0422DF}] @DACL=(02 0000) @="HHComponentActivator Class" . [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{3A3988C6-22A6-5328-34E7-56D59192828C}] @DACL=(02 0000) @="MNTranscoder Class" . [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{3AB1675A-CCFF-11D2-8B20-00A0C93CB1F4}] @DACL=(02 0000) @="GraphicsShellExt Class" . [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{3BC4F3A1-652A-11D1-B4D4-00C04FC2DB8D}] @DACL=(02 0000) @="Microsoft Index Server Administration Object" . [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{3BC4F3A3-652A-11D1-B4D4-00C04FC2DB8D}] @DACL=(02 0000) @="Microsoft Index Server Catalog Administration Object" . [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{3BC4F3A7-652A-11D1-B4D4-00C04FC2DB8D}] @DACL=(02 0000) @="Microsoft Index Server Scope Administration Object" . [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{3CF9A119-FE94-D2EB-E68F-BC2763DC7122}] @DACL=(02 0000) @="MNMetaData Class" . [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{3F15FAB5-8906-479A-8520-617561C60917}] @DACL=(02 0000) @="moContextButtonInfo Object" "AppID"="{930090E3-743F-4514-B2CB-839A1D30DF50}" . [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{40CB6EA0-AB2A-45F8-BA45-2DC7756A7B49}] @DACL=(02 0000) @="EDID Class" . [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{41487A6A-93D8-6912-DFCE-4577B9D74659}] @DACL=(02 0000) @="MNLicenseItems Class" . [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{41A8C383-8B65-C5D1-C3E2-BD935E376DCA}] @DACL=(02 0000) @="MNPermanentLicenseInfoRequest Class" . [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{434CC597-F809-44F6-B0C8-0C839497C51D}] @DACL=(02 0000) @="moMIMJobProgress Object" "AppID"="" . [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{43BB19F5-4E9D-43f3-ABCC-3120C7579BCC}] @DACL=(02 0000) @="moTODFactory Object" "AppID"="" . [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{4501A903-BF07-11D4-AA30-00902704C6BF}] @DACL=(02 0000) @="DataObjectInit Class" . [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{478DD7E7-228D-44B7-9854-DFB0E818D8A7}] @DACL=(02 0000) @SACL= @="CHTInputModule class" . [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{48123bc4-99d9-11d1-a6b3-00c04fd91555}\PersistentHandler] @DACL=(02 0000) @="{5e941d80-bf96-11cd-b579-08002b30bfeb}" . [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{481D4351-92EC-40F2-947E-5F639A9202DA}] @DACL=(02 0000) @="moMusicNetSession Object" "AppID"="" . [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{488693B8-0FE2-49DA-B80B-9049FBC6FA36}] @Class="REG_SZ" @DACL=(02 0000) @="PSFactoryBuffer" . [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{48EF3B9B-872E-12EC-D8B6-C6C275A49DE6}] @DACL=(02 0000) @="MNStreamURLRequest Class" . [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{491AAD47-25F4-47E7-A6B0-25F7BFC806E7}] @DACL=(02 0000) @="moPortableAgent Object" "AppID"="" . [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{49C3B3C9-C46F-43E4-8299-63CD9B965563}] @DACL=(02 0000) @="moRollupMetadata Object" "AppID"="" . [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{4A38E4EF-F55B-4A59-8F02-BDEFB0B1308A}] @DACL=(02 0000) @SACL= @="CMpeg2DataControl" . [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{4B00087D-8CDC-4b77-A9D5-4C50150FEDF4}] @DACL=(02 0000) @="McAfee.com McVsMap" "AppID"="{716B6046-3784-4bc0-94AB-EA18030F1116}" . [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{4B582FD4-E6C6-4C61-8022-344CAB8BC968}] @DACL=(02 0000) @="moCDIServer Object" "AppID"="" . [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{4C2889D4-F0F6-41C0-A50D-34F2136E761C}] @DACL=(02 0000) @="CSupportJukebox Object" "AppID"="" . [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{4E97BE17-3300-4A4F-B380-5988DD771F1F}] @DACL=(02 0000) @="AresPlayer Class" . [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{4F880222-0001-41EA-B763-4AE6552D40FD}] @DACL=(02 0000) @="moConvertJobEventSink Object" "AppID"="" . [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{510C5313-D85C-4307-95FB-AC87A2D3743F}] @DACL=(02 0000) @="MCVSProperties Class" . [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{5145942E-41DF-4658-B7C4-089F48E84A75}] @DACL=(02 0000) @="CoAxTrackMk Class" . [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{5174BA61-D4C6-1FF1-F1A1-FD7BA164E1BC}] @DACL=(02 0000) @="MNSearchResult Class" . [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{52a2aaae-085d-4187-97ea-8c30db990436}] @DACL=(02 0000) @="HHCtrl Object" . [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{52BB3CBC-B06D-4423-BB4F-EC46E26E4A6F}] @DACL=(02 0000) @="moQuerySpec Object" "AppID"="" . [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{53DBC325-80D3-4149-805E-87DED8EC06C5}] @DACL=(02 0000) @="moMIMJobGetURLFromURI Object" "AppID"="" . [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{541D882C-646A-4F67-894F-8576036FC14B}] @DACL=(02 0000) @="Imp Class" "AppID"="{5C28D2E0-EFC5-4118-B994-249419155E27}" . [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{554A838C-9B19-4AA7-8120-13610B7B8754}] @DACL=(02 0000) @="moMIMJobValidateTracksInLibrary Object" "AppID"="" . [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{555C34B7-53EC-4D53-9ABE-8E66AA4C9868}] @DACL=(02 0000) @="moMIMJobGetObjectMetadata Object" "AppID"="" . [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{557198FF-C3DA-3663-D661-8C27A324459B}] @DACL=(02 0000) @="MNLicenseHistoryItem Class" . [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{55E6911A-9419-21B9-8275-539C57167F1A}] @DACL=(02 0000) @="MNDownloadURLRequest Class" . [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{55F94612-19DD-4C2E-9E1F-E26624933DAD}] @DACL=(02 0000) @="MCVSPropNotify Class" . [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{5788DAE8-4B72-4BE6-89A0-1E6123E4CBC2}] @DACL=(02 0000) @="CerberusCDPlayer Class" . [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{57C368A7-F2E9-48C6-B0E2-C201751383C1}] @DACL=(02 0000) @="Engine_QuickTime Class" . [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{5AF9745B-C352-4956-8A66-F57F470382F9}\PersistentHandler] @DACL=(02 0000) @="{98de59a0-d175-11cd-a7bd-00006b827d94}" . [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{5AFAFE48-7107-4FE5-B21A-86A4254541DD}\VersionIndependentProgID] @DACL=(02 0000) @="DWUpdateService.Instance" . [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{5C612D30-FC1E-44C0-8172-1FE0CCBBA2DD}] @DACL=(02 0000) @="moShellView Object" "AppID"="" . [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{5C89CCB1-B9C4-ACED-2ADE-F2C3EDDE46BD}] @DACL=(02 0000) @="MNTLC Class" . [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{5CA3D70E-1895-11CF-8E15-001234567890}] @DACL=(02 0000) @="DriveLetterAccess" . [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{5F19E37F-D8D6-4402-B9C9-397190CF1691}] @DACL=(02 0000) @="moCDTOC Object" "AppID"="" . [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{5F309040-26DE-43CE-B3D5-E46DAF99E81C}] @DACL=(02 0000) @="MIMQueryContentEventController Class" "AppID"="{57B1258C-1E95-47DF-B2F2-20D38C63A73D}" . [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{60F0B189-6CCF-4851-A799-975CBA39941C}] @DACL=(02 0000) @="moMIMJobFindDuplicates Object" "AppID"="" . [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{61B0FEDE-4697-4FC3-A3DC-3C2695359CA6}] @DACL=(02 0000) @="CTDMControl Object" "AppID"="{2C620D34-AD2B-443D-ABBA-52803E3D97AB}" . [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{61BC93DB-3CA1-48B3-BA21-73290993B936}] @DACL=(02 0000) @="moTDMJobProgress Object" "AppID"="{7ABF8763-F496-43E9-B4EF-636CE1B69AA2}" . [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{61E15DE7-D229-4eb3-A460-40DCDDA60DA7}] @DACL=(02 0000) @="ABUI Class" . [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{621BE166-5B87-45E9-BB7E-CD59C4FBDE6B}] @DACL=(02 0000) @="moTrack Object" "AppID"="" . [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{62FE4FA0-792C-11D0-9CB5-0000C0EC9FDB}] @DACL=(02 0000) @="StWebImage General Propery Page Object" . [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{63435828-E10D-42d5-8859-C94796B7C22D}] @DACL=(02 0000) @="ACCalendarDCtrl Class" . [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{639A19DD-1D97-4A6E-A0D1-01E04FED563F}] @DACL=(02 0000) @="SupportedType Class" . [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{63C1724A-5ECC-3C1A-F8FF-9A4F9EE39962}] @DACL=(02 0000) @="MNHttpConnector Class" . [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{644C75B6-43AB-4f49-B983-B18ADAEE0C90}] @DACL=(02 0000) @="MMS Application Object" . [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{6750E0C7-D65D-41d7-997C-EFE55BCAFBAF}] @DACL=(02 0000) @="moMetadataCacheObj Object" "AppID"="" . [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{68A0AE06-06E6-41DD-A9EE-58BB1FD1E9D3}] @DACL=(02 0000) @="moMIMJobUpdateMetadata Object" "AppID"="" . [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{68C5DEFC-B915-3331-C657-CECE618C9C7A}] @DACL=(02 0000) @="MNSearchResults Class" . [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{6950611A-E2CF-421f-88C3-61C27A3832C5}] @DACL=(02 0000) @="MCVSUpdate Class" . [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{6AC3927A-E646-454D-B680-2B41B7EB2716}] @DACL=(02 0000) @="CyberLink Device Dector" . [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{6AD3B5BD-9A96-4ca2-9455-2034D05EB134}] @DACL=(02 0000) @="ACWebDlgHelper Class" . [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{6B58B5DC-7405-11D2-8F58-00E02916007D}] @DACL=(02 0000) @="MMJBPushBtn Control" . [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{6B58B5DD-7405-11D2-8F58-00E02916007D}] @DACL=(02 0000) @="MMJBPushBtn Property Page" . [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{6B58B5E0-7405-11D2-8F58-00E02916007D}] @DACL=(02 0000) @="MMJBRadBtn Control" . [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{6B58B5E1-7405-11D2-8F58-00E02916007D}] @DACL=(02 0000) @="MMJBRadBtn Property Page" . [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{6B58B5E4-7405-11D2-8F58-00E02916007D}] @DACL=(02 0000) @="MMJBLabel Control" . [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{6B58B5E5-7405-11D2-8F58-00E02916007D}] @DACL=(02 0000) @="MMJBLabel Property Page" . [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{6B5E48BB-C7FC-798E-DD65-248AEBE89435}] @DACL=(02 0000) @="MNLicenseHistoryRequest Class" . [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{6E9C29D9-F879-5272-C21C-5992AFC84933}] @DACL=(02 0000) @="MNGetSubscriberPreferences Class" . [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{6E9DBE43-5233-49A3-AB96-A9353EB9AB6D}] @DACL=(02 0000) @="CActivate Object" "AppID"="" . [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{6EA78BC2-ED35-11D3-9D11-0050BA0F91DA}] @DACL=(02 0000) @="CyberLink Audio Renderer Property Page" . [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{708D11FE-6F03-3991-B112-C6582196DDC3}] @DACL=(02 0000) @SACL= @="GemMaster3.Block" . [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{711A5F72-0595-423B-82B9-FF6ABDCD9D5A}] @DACL=(02 0000) @="moMIMJobGetStreamURL Object" "AppID"="" . [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{712BD3E1-EBED-4EE7-8511-E763FF19107B}] @DACL=(02 0000) @="moTrackNormAnalyzer Object" "AppID"="" . [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{7160A13D-73DA-4CEA-95B9-37356478588A}] @DACL=(02 0000) @="CUIExternal Class" . [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{71985F4B-1CA1-11D3-9CC8-00C04F7971E0}] @DACL=(02 0000) @SACL= @="" . [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{722F787D-837A-406E-B643-DDF29B57B08F}] @DACL=(02 0000) @="moDatabase Object" "AppID"="" . [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{736D21BF-45CB-81B6-D8BF-BA53D8A21B8B}] @DACL=(02 0000) @="MNLogin Class" . [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{73968DCB-9506-49D8-A732-DF1738DE974F}] @DACL=(02 0000) @="MIMDeviceEventController Class" "AppID"="{57B1258C-1E95-47DF-B2F2-20D38C63A73D}" . [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{73C27926-597E-A1EA-9FFE-23B57A51EB2E}] @DACL=(02 0000) @="MNPlayCounts Class" . [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{7559EF6B-4659-4CF8-B8A1-0F665A4388C8}] @DACL=(02 0000) @="moMIMJobUpdateRBCDMetadata Object" "AppID"="" . [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{756A2CB8-EC02-4DC8-8588-296C611A5365}] @DACL=(02 0000) @="HtmlFunctions Class" . [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{75D44B92-DCAF-43f3-A7D1-91041F34E719}] @DACL=(02 0000) @="AOLFlashProp Class" . [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{76020638-5170-4d14-ABF9-695E0EDF08FA}] @DACL=(02 0000) @="GTCoach version" . [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{7734D7CA-A810-4634-A32C-10F322EE0525}] @DACL=(02 0000) @="WildWebUI Class" . [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{78512A59-2E61-4ED3-AD95-A8DDCA5720F4}] @DACL=(02 0000) @="moTODSessionProxy Object" "AppID"="" . [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{78652349-6BE0-4BD7-A211-5F1ABB2C7AC4}] @DACL=(02 0000) @="moMIMJobMessage Object" "AppID"="" . [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{787132E3-A6C5-4B01-83A6-AD20DFBA2BD3}] @DACL=(02 0000) @="moDeviceMetadata Object" "AppID"="" . [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{78D74CFE-4826-2DDE-8F45-9B4763F93A27}] @DACL=(02 0000) @="MNWMLicenseRequest Class" . [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{795AA464-7770-4802-ABAE-AEF5FFF70A0F}] @DACL=(02 0000) @="moMIMJobGetDeviceInfo Object" "AppID"="" . [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{7B97AA09-B9E2-45E2-8A7C-A4CE82D247D2}] @DACL=(02 0000) @="moDirTagSupportedTypes Object" "AppID"="" . [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{7C9688C3-7279-474D-ABA5-A632373D2CDB}] @DACL=(02 0000) @="Player Class" . [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{7DC23152-6B5E-4A65-B42E-AE5AC4199577}] @DACL=(02 0000) @="McAfee.com Quarantine Control" . [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{7F23E6E5-0E79-4aee-B723-B1463805D5A9}] @DACL=(02 0000) @="WTVisReceiver Class" . [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{7F493BA3-29C1-4C8C-AE8F-0027D3DB53BC}] @DACL=(02 0000) @="moMIMJobSync Object" "AppID"="" . [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{7FE49289-7457-44C4-A1FC-A07AE2E49D1E}] @DACL=(02 0000) @="moMP3CDMetadata Object" "AppID"="" . [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{80A3E9B0-A246-11D3-BB8C-0090272FA362}] @DACL=(02 0000) @="EngUSWrdBrk Class" . [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{81068259-A399-439C-90A3-55710406E841}] @DACL=(02 0000) @="moTrackEffects Object" "AppID"="" . [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{8196E3CD-1362-4682-8C64-9F484F661540}] @DACL=(02 0000) @="moMIMJobComplete Object" "AppID"="" . [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{81DDBD17-9873-75B9-782C-91FD941421BC}] @DACL=(02 0000) @="MNPlayCount Class" . [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{83A43F8C-D796-DBB5-2664-7278A7E14674}] @DACL=(02 0000) @="MNGetTopArtists Class" . [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{840CEB17-FB6B-4c05-95DF-6FB14A02FD83}] @DACL=(02 0000) @SACL= @="WildTangent Control" . [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{841B03BF-E9D4-452E-83AF-136F23AA4EDB}] @DACL=(02 0000) @="moMIMJobCdBurned Object" "AppID"="" . [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{8488F571-9383-458D-9319-99182705F025}] @DACL=(02 0000) @="moRBCDMetadata Object" "AppID"="" . [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{84CBABC2-D3BE-4EEF-8394-121FAC215CEF}] @DACL=(02 0000) @="PictureInfos Class" . [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{850C8F6D-D8A1-45C4-A52A-D178C399ACDB}] @DACL=(02 0000) @="moDataBlob Object" "AppID"="" . [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{855B6281-563C-4462-8C6D-5326CA1D4FE4}] @DACL=(02 0000) @="Zone Class" "AppID"="{73CFF131-CA3B-4654-9640-0F50B3ABA521}" . [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{86BFD332-D819-4612-B07D-D83F3149D969}] @DACL=(02 0000) @="moMetadata Object" "AppID"="" . [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{87EDF751-74FE-49D9-AF93-F4A89B6B4823}] @DACL=(02 0000) @="MNKeywordSearch Class" . [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{885BB46A-3F1E-44C3-A01B-A7D9260CC98B}\VersionIndependentProgID] @DACL=(02 0000) @="DWSetup.Player" . [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{8AB5F344-B600-11D6-8A15-00E029570A3E}] @DACL=(02 0000) @="SATBMgr Class" . [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{8b83b5b5-4d81-44f0-a683-da9387aed20e}] @DACL=(02 0000) "Settings"=hex:41,32,30,8e,7a,3b,ff,ea,30,0b,36,3b,08,30,39,df,cf,35,0d,4a,be, 32,73,33 . [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{8c3c1b17-e59d-11d2-b40b-00a024b9dddd}] @DACL=(02 0000) @="SetupLogServices Class" . [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{8EBB8D46-D4E8-40AD-A4B0-A45BEEE76DAA}] @DACL=(02 0000) @="moMIMJobConvertDownloadToBookmark Object" "AppID"="" . [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{8ECF83A0-1AC9-11D4-8501-00A0CC5D1F63}] @DACL=(02 0000) @="WMplug Property Page" . [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{8EF39B24-07A7-41E3-B062-4C20C684A4F6}] @DACL=(02 0000) @="LibraryPageObj Class" "AppID"="{0DC836FA-80F0-44F1-B1E3-E3CFF3A46675}" . [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{8F0DD2CA-786E-11D0-A671-000092909AB2}] @DACL=(02 0000) @="Popup Control" . [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{8F0DD2CB-786E-11D0-A671-000092909AB2}] @DACL=(02 0000) @="Popup Property Page" . [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{8F3A367C-A94A-463D-A788-81A2A4F5F0BD}] @DACL=(02 0000) @="moMIMJobVolNormPrepare Object" "AppID"="" . [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{90BB8EC9-A041-49DB-8A2D-65DBD2309616}] @DACL=(02 0000) @="moDataObject Object" "AppID"="" . [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{90F6062F-8933-4BE7-983D-BDFCE06E5D58}] @DACL=(02 0000) @="moDropTarget Object" "AppID"="" . [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{916C9DB1-1641-44FD-915C-D2D3F94A36D4}] @DACL=(02 0000) @="moDeviceObject_CdDvd Object" "AppID"="" . [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{91814EC0-B5F0-11D2-80B9-00104B1F6CEA}] @DACL=(02 0000) @="InstallShield setup kernel" . [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{91870674-DE84-4313-B07D-A387415BB4F5}] @DACL=(02 0000) @="ItlItlWrdBrk Class" . [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{91BC7F74-B687-4C4B-A4FF-CF99A24C6322}] @DACL=(02 0000) @SACL= @="PSFactoryBuffer" . [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{91FEAE69-DF5A-491A-812B-433838FB5838}] @DACL=(02 0000) @="moMIMJobStart Object" "AppID"="" . [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{94332194-7B89-42DF-8B26-04883B850D17}] @DACL=(02 0000) @="moMIMJobDoLicenseSyncing Object" "AppID"="" . [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{943742F6-3A40-43FF-97F4-A1750D97B200}] @DACL=(02 0000) @="PictureInfo Class" . [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{954AE85F-2CEF-4B9D-B249-21CC4F874B25}] @DACL=(02 0000) @="moMIMMessageButton Object" "AppID"="" . [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{959F94FD-DD1E-11D2-B559-00105A0422DF}] @DACL=(02 0000) @="GlossaryPane Class" . [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{963A6463-5207-4D06-AD5E-5A900C851735}] @DACL=(02 0000) @="NcsCoreEvents Class" "AppID"="{4749A9BC-67B2-404D-8E3A-046C627B1275}" . [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{96C5AC63-57CA-AC56-B3E4-753ABB37F238}] @DACL=(02 0000) @="MNLicense Class" . [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{97F51D01-E01D-43AE-A8D5-DD74AADCF8FB}] @DACL=(02 0000) @="moDeviceObject_LocalDisk Object" "AppID"="" . [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{98BFD494-F6AD-4794-9038-832C0654CC43}] @DACL=(02 0000) @="AOL YGP UPF Ctrl" . [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{98CC52EE-09E2-4F3B-99DB-0505FBAA636F}] @DACL=(02 0000) @="moTODSessionObj Object" "AppID"="" . [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{991FD30C-01B0-4174-9082-94847868627A}] @DACL=(02 0000) @="moMIMJobDbLinkWatcher Object" "AppID"="" . [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{993B79DF-46DB-48E6-B415-84246E19283C}] @DACL=(02 0000) @="moLicenseManagerFactoryM Object" "AppID"="{95C858E7-D95B-48C2-A06F-6B124FF2CD27}" . [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{999276E0-DA71-4743-8F02-0AB0A2D65558}] @DACL=(02 0000) @="MCCS Class" . [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{99D8E193-1DD3-CE81-3F2F-F5A478E8CEED}] @DACL=(02 0000) @="MNWMRootLicenseRequest Class" . [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{9A42664B-6ECD-49EF-8EE8-E8CD122A6719}] @DACL=(02 0000) @="MNPermanentLicenses Class" . [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{9A7EFF8B-417A-198C-73DF-9625D2F7AB71}] @DACL=(02 0000) @="MNSubscriptionLicenseRequest Class" . [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{9AC2F1C5-28DC-43AC-A698-3F9477CDEFE8}] @DACL=(02 0000) @="moPicture Object" "AppID"="" . [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{9B3628FB-EE6A-44A2-BA35-0FC48625A1FF}] @DACL=(02 0000) @="moMIMJobRemoveTrackTags Object" "AppID"="" . [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{9B908879-E03F-4D0C-ACB3-9065B1155460}] @DACL=(02 0000) @="Rotation Class" . [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{9B94749A-E285-463A-885D-D99A4B1FA7ED}] @DACL=(02 0000) @="moPlaylistMMOFile Object" "AppID"="" . [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{9B951FFB-7CF7-4E19-A767-E8CD34863148}] @DACL=(02 0000) @="moMIMJobDoComponentUpdates Object" "AppID"="" . [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{9CEE304E-DC6C-11D2-B561-00A0C92E6848}] @DACL=(02 0000) @="CUIDriver Class" . [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{9D582C41-8AE8-4999-A696-5F36EDC94029}\PersistentHandler] @DACL=(02 0000) @="{98de59a0-d175-11cd-a7bd-00006b827d94}" . [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{9DF12D0D-C037-4C80-AD64-635AD3FB8AC8}] @DACL=(02 0000) @="moMIMJobLookupTrackTags Object" "AppID"="" . [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{9F0BDD1B-5753-4609-A2F2-CA8954B1672F}] @DACL=(02 0000) @="moExtractIcon Object" "AppID"="" . [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{9F62797E-1249-4596-9FF7-AC6D851A542A}] @DACL=(02 0000) @="ACDictionary Class" . [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{9F86A13B-19E5-4B8B-97A3-0BD114E19425}] @DACL=(02 0000) @="CTDMControlM Object" "AppID"="{BAA8E558-4C0E-460B-BC51-7DA955A92B6F}" . [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A105BD70-BF56-4D10-BC91-41C88321F47C}] @DACL=(02 0000) @="Playlist Class" . [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A11A289C-A665-38B6-B544-87383F15CE7C}] @DACL=(02 0000) @="FileIdentity Class" . [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A28275B4-A671-4646-AEAB-388B27B658BF}] @DACL=(02 0000) @="moMIMJobCreateMetadataObjects Object" "AppID"="" . [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A351008E-49B9-4AC8-88CB-032966954649}] @DACL=(02 0000) @="moSimpleView Object" "AppID"="" . [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A354BD60-4C0A-11d3-B561-00A0C92E6848}] @DACL=(02 0000) @="DataObject Class" "AppID"="{3D62E9A1-D243-11D2-B561-00A0C92E6848}" . [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A448CD02-4566-442F-BDA8-70FCF9FEAF66}] @Class="REG_SZ" @DACL=(02 0000) @="PSFactoryBuffer" . [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A494B91B-F1DF-49EE-ACC7-18545594C148}] @DACL=(02 0000) @="moCustomMenuItem Object" "AppID"="" . [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A49CCC56-15C6-236A-14A6-164258635542}] @DACL=(02 0000) @="MNSetSubscriberPreferences Class" . [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A4BA65D2-7484-49C0-8F7F-B76769283190}] @DACL=(02 0000) @="moTDMEngine Class" "AppID"="{95CABDBA-3CE0-4d42-B963-1C72EB7B0489}" . [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A5676222-1F7C-635B-FBB7-1C6DEE4B8AEE}] @DACL=(02 0000) @="MNPlaylistItem Class" . [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A5E10466-4D20-4AEA-8229-69B2010F1BAC}] @DACL=(02 0000) @="moDeviceObject_Portable Object" "AppID"="" . [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A62FA99E-922E-4ECA-A1D9-B54EF294A3CC}] @DACL=(02 0000) @="LogSession Class" . [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A8479711-786C-3A3B-894B-98BBC3FA5DE9}] @DACL=(02 0000) @="MNLicenseItem Class" . [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A84EF261-41C8-9413-7BA5-F957791868B8}] @DACL=(02 0000) @="MNWMRM Class" "AppID"="{92D94BB1-E28D-42A6-A299-A732CAF41AB8}" . [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A859DFE0-CF41-4936-B794-27BD33218D4D}] @DACL=(02 0000) @="moMIMJobRenameFiles Object" "AppID"="" . [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A8ABE123-FAC4-41c1-ABA3-051B6F112B83}] @DACL=(02 0000) @="ACCalendarListCtrl Class" . [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A8E4959F-DEB8-B751-D736-3534C69E13B4}] @DACL=(02 0000) @="MNDownload Class" . [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A98ABF1C-107C-44E7-9254-2C3FF435D0C2}] @DACL=(02 0000) @="SuperBuddyData Class" . [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A9ABD027-C16C-416B-A1F7-AAD3B029E194}] @DACL=(02 0000) @="moTrackEncodingFormat Object" "AppID"="" . [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{AA7E2086-CB55-11D2-8094-00104B1F9838}] @DACL=(02 0000) @="InstallShield setup object wrapper" . [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{AA7E2087-CB55-11D2-8094-00104B1F9838}] @DACL=(02 0000) @="InstallShield setup object wrapper" . [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{AB29A544-D6B4-4E36-A1F8-D3E34FC7B00A}] @DACL=(02 0000) @="WTHoster Class" . [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{AB2E478C-D4E5-45A4-84E1-F6279413B5DC}] @DACL=(02 0000) @="Digital Jukebox SDK" . [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{AB42D394-1492-8A7E-2FA9-99ABC51422F6}] @DACL=(02 0000) @="MNGetTopTracks Class" . [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{AB8E52BC-7CFC-46D2-BC0C-A7EB0E10E3F3}] @DACL=(02 0000) @="moProfileMgrObj Object" "AppID"="{9AEE91CA-C80B-46A2-8FC8-FCDA22467903}" . [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{AC2D2DC3-57DF-4f70-B464-36B456AC143F}] @DACL=(02 0000) @="moLocalUICOMObj Object" "AppID"="" . [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{AC9F638C-5718-4914-9BB0-46522439CBB7}] @DACL=(02 0000) @="moMIMJobImportDDF Object" "AppID"="" . [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{AD41621C-A2DD-487D-A24B-8BE40116A5A3}] @DACL=(02 0000) @="IImageInfo Class" . [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{AE4FC5BE-6248-4EB0-9918-BCB1D2B878B3}] @DACL=(02 0000) @="CPlaylists Object" "AppID"="" . [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{AECAFA59-4D60-49B1-9037-81248A79F3A4}] @DACL=(02 0000) @="CSupportLibrary Object" "AppID"="" . [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{AED456C4-4866-4420-863F-35767EBED514}] @DACL=(02 0000) @="Engine_Winamp Class" . [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{AFCDB803-505D-4E11-9885-9EB4E7A12679}] @DACL=(02 0000) @="moBrokenLinksSink Object" "AppID"="{D3BAD1CE-CFFE-427F-83B5-902F6A42BDE6}" . [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{B23043B5-6823-480C-83C2-0FF30B8668F6}] @DACL=(02 0000) @="moMIMJobThumbnailFetcher Object" "AppID"="" . [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{B2C6BE5B-26B4-9B98-63E5-717DFEF5E5EB}] @DACL=(02 0000) @="MNUserSession Class" . [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{B2E37DAA-2F57-44D9-BB69-F5A4EFEA998F}] @DACL=(02 0000) @="moFolderMetadata Object" "AppID"="" . [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{b2ede004-1005-4c5b-962c-28cdd781bec0}] @DACL=(02 0000) "Settings"=hex:41,32,30,8e,7a,3b,ff,ea,30,0b,36,3b,08,30,39,df,cf,35,0d,4a,be, 32,73,33 . [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{B2F3A67C-29DA-4C78-8831-091ED509A475}] @DACL=(02 0000) @SACL= @="Microsoft Network Provider" . [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{B3D4546B-8BC7-4F2B-AA17-397F9B125963}] @DACL=(02 0000) @="CyberLink Mixer Wrapper" . [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{B3E7BCF9-05C8-4233-BA88-37FDA4AD3147}] @DACL=(02 0000) @="ACEventConflictCtrl Class" . [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{B428C384-991F-4492-AF19-0C395200C165}] @DACL=(02 0000) @="CyberLink RC Engine" . [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{B4D481A3-63AA-92AF-53B1-C3B524957C84}] @DACL=(02 0000) @="MNGetTopAlbums Class" . [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{B4F80028-5714-4B7B-B9B1-5748B204799A}] @DACL=(02 0000) @="Track Class" . [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{B5DE6AA8-A94F-4369-93ED-77307026FDF1}] @DACL=(02 0000) @="CSupportRemote Object" "AppID"="" . [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{B602F1EB-2F37-4e1a-83A1-41E242D65818}] @DACL=(02 0000) @="moStreamFactory Object" "AppID"="" . [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{B60B78E4-2C25-4596-9462-619379E0E68C}] @DACL=(02 0000) @="GTCoach Config version" . [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{B6F041A2-48B9-4d3f-A91D-90E17C505FD3}] @DACL=(02 0000) @="ACDayBoxViewCtrl Class" . [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{B793DE5F-29C9-440c-A9E2-4644145DDD3D}] @DACL=(02 0000) @="McAfee.com VirusScan Control" . [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{B7DE67ED-3648-3A0D-B806-DC1F54836E21}] @DACL=(02 0000) @SACL= @="GemMaster3.GameUserControl+Win32" . [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{B83E7402-2227-403a-BEBC-773F5E0D1F1B}] @DACL=(02 0000) @="McAfee.com Common menu command Handler" "AppID"="{CCB622E5-5327-4a2b-A020-D90DCF82676A}" . [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{B8F2E9D0-7312-44E0-BB1F-9320A60469C3}] @DACL=(02 0000) @="moPlaylistMetadata Object" "AppID"="" . [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{B915EB15-BE2A-49e1-8CE9-0C71C8C6187C}] @DACL=(02 0000) @="moMIMJobFixLibraryMediaMountPoint Object" "AppID"="" . [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{B926B8D4-6B3F-4E12-8F21-62DF6364C87A}] @DACL=(02 0000) @="moMIMJobDeleteObjectsByTargetSpec Object" "AppID"="" . [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{B99BBE03-D5C2-3A5F-BF3C-2DF8D540AF98}] @DACL=(02 0000) @SACL= @="VEC3D" . [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{B9BA256A-075B-49ea-B9E2-7DBC2EF021D5}] @DACL=(02 0000) @="WTVisSender Class" . [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{B9F3009B-976B-41C4-A992-229DCCF3367C}] @DACL=(02 0000) @="CoAxTrack Class" . [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{BA1FF8CC-ED76-47A7-BE8A-8ED83435DBE0}] @DACL=(02 0000) @="moNormContour Object" "AppID"="" . [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{BA2AFEB9-E7E4-4D6F-9216-D4866F0F538D}] @DACL=(02 0000) @="moMIMJobInvokeCustomCommand Object" "AppID"="" . [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{BBE1C463-3DBE-4b29-976B-E1C75AFE1EDF}] @DACL=(02 0000) @="MMDRMCtrlObj Class" . [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{BC24BDA9-C62F-B3D8-DFC6-DC545CE559E9}] @DACL=(02 0000) @="MNComponentIdSearch Class" . [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{bc8a96c4-3909-11d5-9001-00c04f4c3b9f}] @DACL=(02 0000) @="CddbURLManager Class" . [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{bc8a96c5-3909-11d5-9001-00c04f4c3b9f}] @DACL=(02 0000) @="CddbID3TagManager Class" . [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{bc8a96c6-3909-11d5-9001-00c04f4c3b9f}] @DACL=(02 0000) @="CddbID3Tag Class" . [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{bc8a96c7-3909-11d5-9001-00c04f4c3b9f}] @DACL=(02 0000) @="CddbInfoWindow Class" . [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{bc8a96c8-3909-11d5-9001-00c04f4c3b9f}] @DACL=(02 0000) @="CddbUIOptions Class" . [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{BD13B4C0-2798-4C56-B572-FC3C62E2CDDE}] @DACL=(02 0000) @="moMIMJobSink Object" "AppID"="{D3BAD1CE-CFFE-427F-83B5-902F6A42BDE6}" . [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{BD98AE37-637E-B24A-8659-8A4883CE4669}] @DACL=(02 0000) @="MNSearch Class" . [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{C01E1033-A04C-40d6-9AF4-1D33CBF2AFB2}\PersistentHandler] @DACL=(02 0000) @="{98de59a0-d175-11cd-a7bd-00006b827d94}" . [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{C071C982-2EB2-4D3A-9821-E4B31B0142C8}] @DACL=(02 0000) @="Scheme Class" . [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{C1145550-A454-11D4-9020-00D0B7239081}] @DACL=(02 0000) @="AOL Flash Object" . [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{C1145551-A454-11D4-9020-00D0B7239081}] @DACL=(02 0000) @="AOL Flash Factory Object" . [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{C15AD8EA-EB37-458F-8491-3CF2B121F30A}] @DACL=(02 0000) @="moWavMp3 Object" "AppID"="" . [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{C2AFF197-1CCD-4861-9DD0-F3462CA99FD3}] @DACL=(02 0000) @="CyberLink DVD Engine" . [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{C2BFE331-6739-4270-86C9-493D9A04CD38}] @DACL=(02 0000) @="DisplayConfig Class" . [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{C3228FAC-884F-11D5-B504-000629D0B82A}] @DACL=(02 0000) @="NcsNetService Class" "AppID"="{C3228FA0-884F-11D5-B504-000629D0B82A}" . [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{C332C124-340D-4430-AA0D-C75602876FCC}] @DACL=(02 0000) @="CUIPower Class" . [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{C3DB19A6-D5A2-11D2-8F58-00E02916007D}] @DACL=(02 0000) @="MMJBTextBtn Control" . [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{C3F8B282-5B69-47F0-80C3-A22A97FF2EB5}] @DACL=(02 0000) @SACL= @="GLIDPlugInUDCR Class" . [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{C4A74417-EACF-4652-9D7B-EF1C043067E6}] @DACL=(02 0000) @="d54a1481-5531-41f6-8ae4-3dba029d7b7c" . [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{C4B52EB7-231A-40B6-ACA0-DAC7A267ADBA}] @DACL=(02 0000) @="moDummyTag Object" "AppID"="" . [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{C523F39F-9C83-11D3-9094-00104BD0D535}] @DACL=(02 0000) @="AcroAccess Class" "AppID"="{C523F391-9C83-11D3-9094-00104BD0D535}" . [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{C5E28B9D-0A68-4B50-94E9-E8F6B4697515}] @DACL=(02 0000) @="NsvPlayX Control" . [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{C7B6C04A-CBB5-11d0-BB4C-00C04FC2F410}] @DACL=(02 0000) @="IndexServer Simple Command Creator" . [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{C9CD1A93-D7B4-11D2-80C5-00104B1F6CEA}] @DACL=(02 0000) @="InstallShield setup user interafce" . [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{CA6319C0-31B7-401E-A518-A07C3DB8F777}] @DACL=(02 0000) @="CBrowserHelperObject Object" "AppID"="" . [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{CA8A9780-280D-11CF-A24D-444553540000}\Control] @DACL=(02 0000) @="" . [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{CA8A9780-280D-11CF-A24D-444553540000}\Implemented Categories] @DACL=(02 0000) . [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{CA8A9780-280D-11CF-A24D-444553540000}\InprocServer32] @DACL=(02 0000) @="c:\\PROGRA~1\\Adobe\\ACROBA~1.0\\Reader\\ActiveX\\pdf.ocx" "ThreadingModel"="Apartment" . [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{CA8A9780-280D-11CF-A24D-444553540000}\MiscStatus] @DACL=(02 0000) @="0" . [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{CA8A9780-280D-11CF-A24D-444553540000}\ProgID] @DACL=(02 0000) @="PDF.PdfCtrl.6" . [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{CA8A9780-280D-11CF-A24D-444553540000}\ToolboxBitmap32] @DACL=(02 0000) @="c:\\PROGRA~1\\Adobe\\ACROBA~1.0\\Reader\\ActiveX\\pdf.ocx, 1" . [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{CA8A9780-280D-11CF-A24D-444553540000}\TypeLib] @DACL=(02 0000) @="{CA8A9783-280D-11CF-A24D-444553540000}" . [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{CA8A9780-280D-11CF-A24D-444553540000}\Version] @DACL=(02 0000) @="5.0" . [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{CA8A9780-280D-11CF-A24D-444553540000}\VersionIndependentProgID] @DACL=(02 0000) @="PDF.PdfCtrl" . [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{CA8A9784-280D-11CF-A24D-444553540000}] @DACL=(02 0000) @="Adobe Acrobat Control Property Page" . [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{CBD8124B-5BEA-2EC4-24F4-59BD34ABF345}] @DACL=(02 0000) @="MNLicenses Class" . [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{CC4569D7-A7A6-4295-A176-13343003D1A9}] @DACL=(02 0000) @="moPlaylistPLSFile Object" "AppID"="" . [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{CD3AFA72-B84F-48F0-9393-7EDC34128127}\EnablePlugin] @DACL=(02 0000) . [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{CD3AFA73-B84F-48F0-9393-7EDC34128127}\EnablePlugin] @DACL=(02 0000) . [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{CD3AFA76-B84F-48F0-9393-7EDC34128127}\EnablePlugin] @DACL=(02 0000) . [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{CD3AFA7B-B84F-48F0-9393-7EDC34128127}\EnablePlugin] @DACL=(02 0000) . [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{CD3AFA88-B84F-48F0-9393-7EDC34128127}\EnablePlugin] @DACL=(02 0000) . [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{CD3AFA89-B84F-48F0-9393-7EDC34128127}\EnablePlugin] @DACL=(02 0000) . [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{CE0E7204-D82C-4273-8A70-919963F4CFE0}] @DACL=(02 0000) @="MMJBText Property Page" . [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{D006D01C-DC45-492b-AE12-20D46BD16F1D}] @DACL=(02 0000) @="moDeviceObject_TOD Object" "AppID"="" . [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{D0AAD3D6-EB93-4363-A24E-2C3D80CDBAC7}] @DACL=(02 0000) @="moMIM Object" "AppID"="{0CDAF4E7-F898-4FEC-B774-FFE6318B781A}" . [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{D119804B-6596-410D-9F43-C0C09FFD8E93}] @DACL=(02 0000) @="moMIMJobDeleteObjectsByURI Object" "AppID"="" . [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{D3ABF3AE-DAE0-45BC-ADC4-EB003D8418E5}] @DACL=(02 0000) @="moTrackTags Object" "AppID"="" . [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{D45DBF38-0597-4980-B617-60DB5DF1EB54}] @DACL=(02 0000) @="moMIMJobGetFolderContents Object" "AppID"="" . [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{D465B936-C361-4417-9AC5-35167066F84B}] @DACL=(02 0000) @="Engine_WMP Class" . [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{D4A42E54-D5C1-4D04-A91D-C97A0F2BB849}] @DACL=(02 0000) @="moChangeMgr Object" "AppID"="{7ABF8763-F496-43E9-B4EF-636CE1B69AA2}" . [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{D4AA4A7F-8099-4EAF-99F7-D169FF80328F}] @DACL=(02 0000) @="moStaticFolderAttrs Object" "AppID"="" . [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{D4FA3D4E-BE69-11D4-AA30-00902704C6BF}] @DACL=(02 0000) @="DataObject Class" . [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{D53F5B89-FC32-BF5E-971D-A1B548CCE274}] @DACL=(02 0000) @="MNWMIndividualization Class" "AppID"="{92D94BB1-E28D-42A6-A299-A732CAF41AB8}" . [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{D56945EF-213A-87AF-6D82-BD6BDB276F9D}] @DACL=(02 0000) @="MNPermanentLicense Class" . [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{D646A7BE-C948-3AF2-BE1F-F72FE5E3536B}] @DACL=(02 0000) @SACL= @="GemMaster3.BlockList" . [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{D649DC92-52F2-4AA5-A7FB-BA068EF30BB6}] @DACL=(02 0000) @="CMPEG2VideoEncoder Class" . [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{D66DB03B-666D-40D9-9C05-EE500E7F4807}] @DACL=(02 0000) @="moMIMJobGetDeviceInfoByCategory Object" "AppID"="" . [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{D670D0B3-05AB-4115-9F87-D983EF1AC747}] @DACL=(02 0000) @="AOL Downloader Plugin" . [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{D830B35A-45D2-4828-83E9-2338DCB70620}] @DACL=(02 0000) @="WildWeb Class" . [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{D84B68DB-A8BC-4C55-84B5-913F0259DF20}] @DACL=(02 0000) @="CyberLink PowerDVD UI system" . [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{D883594A-9AD0-455D-9249-E80E9948ADB5}] @DACL=(02 0000) @="moTrackDestination Object" "AppID"="" . [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{D9F99C6B-A3A6-11D4-AF64-444553546170}] @DACL=(02 0000) @="Phobos Class" . [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{DA203A45-CE46-4B5C-9F85-DE13E9B781BB}] @DACL=(02 0000) @="LocationInfo Class" "AppID"="{0DC836FA-80F0-44F1-B1E3-E3CFF3A46675}" . [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{DA3C177A-D1DA-47f2-BBF0-E9710CA7253F}] @DACL=(02 0000) @="ACMPickerCtrl Class" . [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{DA4E3DA0-D07D-11d0-BD50-00A0C911CE86}\Instance\{71985F4B-1CA1-11D3-9CC8-00C04F7971E0}] @DACL=(02 0000) @SACL= "CLSID"="{71985F4B-1CA1-11D3-9CC8-00C04F7971E0}" "FriendlyName"="BDA Network Providers" "Merit"=dword:00600000 @="" . [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{DB395FB5-AB0E-4E5A-A3B5-EE628C3FA07C}] @DACL=(02 0000) @="MMUIHostActiveX Control" . [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{DBBA3976-AA5D-3EAF-95D0-5F19844EFF11}] @DACL=(02 0000) @SACL= @="GemMaster3.MessageList" . [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{DCB2D492-5F4F-4378-8FF4-DA87062D42E3}] @DACL=(02 0000) @="OpenGL Class" . [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{DDA11344-AB20-4AEC-94C4-6AA091574CD0}] @DACL=(02 0000) @="PSFactoryBuffer" . [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{DDB71D10-6F12-4B86-8D18-C0CD9B03BB9E}] @DACL=(02 0000) @="moOnDemandSessionStub Object" "AppID"="" . [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{DE110D2A-E245-4DB2-846D-F713C5D6678F}] @DACL=(02 0000) @="CyberLink Audio Property Page" . [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{DE111BBD-8282-4923-8B0F-C9C10D28F342}] @DACL=(02 0000) @="CyberLink Line21 Decoder Filter" . [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{DE111E5E-7134-4DF8-9371-BEC7582A60D2}] @DACL=(02 0000) @="CyberLink Video/SP Decoder DELL 5.3" . [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{DE112FC6-3377-473F-B197-715E1ADA77EE}] @DACL=(02 0000) @="CyberLink DVD Navigator State" . [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{DE113374-2D0B-4D90-93ED-7A4B193560D7}] @DACL=(02 0000) @="CyberLink AudioCD Filter" . [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{DE113893-076A-4672-BDDD-DBB6BF902E08}] @DACL=(02 0000) @="CyberLink Audio Property Page" . [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{DE11392F-256F-4428-9760-7F955CA7E9F4}] @DACL=(02 0000) @="CyberLink Audio TSXT Property Page" . [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{DE115CB2-9ABE-42BE-A079-4D4D8468ED30}] @DACL=(02 0000) @="CyberLink TimeStretch Filter Property Page" . [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{DE116101-B0DB-443C-9C18-81CCE6BE0F4D}] @DACL=(02 0000) @="CyberLink Audio Renderer" . [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{DE1165E5-0EDD-411D-817E-DCC587EA52D7}] @DACL=(02 0000) @="CyberLink Audio CLVB Property Page" . [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{DE1167CB-C62C-446E-9CBA-EE687DFB4B37}] @DACL=(02 0000) @="CyberLink TimeStretch Filter" . [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{DE116896-F9B6-48BB-A635-A5B3724F86EB}] @DACL=(02 0000) @="CyberLink DVD Video Property" . [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{DE118B88-D1D0-4724-8C99-FAA258DD125F}] @DACL=(02 0000) @="CyberLink Audio CL Headphone Property Page" . [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{DE1193B3-24F9-49A4-B987-78A40FE7BD94}] @DACL=(02 0000) @="CyberLink DVD Navigator Property Page" . [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{DE11A3D0-2858-4F2D-904F-25992F433925}] @DACL=(02 0000) @="CyberLink DVD Navigator" . [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{DE11A8D7-1B54-476B-AD98-14DC3AFB04CE}] @DACL=(02 0000) @="CyberLink AudioCD Property Page" . [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{DE11A91B-20DF-4A9D-A6C3-A5CA1270C5BD}] @DACL=(02 0000) @="CyberLink Line21 DecoderProperty Page" . [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{DE11AE4E-672E-4543-86DD-194477E4EEF8}] @DACL=(02 0000) @="CyberLink Audio Dolby Headphone Property Page" . [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{DE11BACC-93CF-4816-A3BD-861E1510C7C7}] @DACL=(02 0000) @="CLMEI Property Page" . [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{DE11BE1E-42C1-48E0-BE95-587D8AF9822F}] @DACL=(02 0000) @="CyberLink Audio PL2 Property Page" . [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{DE11E33E-1AD7-42C0-872D-706776248E0F}] @DACL=(02 0000) @="CyberLink Audio Dolby Virtual Speaker Property Page" . [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{DE11F4A5-424C-4E46-A0D2-F6D23760AED4}] @DACL=(02 0000) @="CyberLink Audio Misc. Property Page" . [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{DE11F7D8-A61B-460F-954D-3E7BA82AC296}] @DACL=(02 0000) @="CyberLink Audio Decoder" . [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{DE4AF3B0-F4D4-11D3-B41A-0050DA2E6C21}] @DACL=(02 0000) @="QuickTimeCheck Class" . [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{DE4AF3B0-F4D4-11D3-B41A-0050DA2E6C21}\InprocServer32] @DACL=(02 0000) @="c:\\Program Files\\QuickTime\\QTSystem\\QuickTimeCheck.ocx" "ThreadingModel"="Apartment" . [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{DE4AF3B0-F4D4-11D3-B41A-0050DA2E6C21}\ProgID] @DACL=(02 0000) @="QuickTimeCheckObject.QuickTimeCheck.1" . [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{DE4AF3B0-F4D4-11D3-B41A-0050DA2E6C21}\TypeLib] @DACL=(02 0000) @="{DE4AF3A1-F4D4-11D3-B41A-0050DA2E6C21}" . [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{DE4AF3B0-F4D4-11D3-B41A-0050DA2E6C21}\VersionIndependentProgID] @DACL=(02 0000) @="QuickTimeCheckObject.QuickTimeCheck" . [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{DEACD25A-C435-6C74-4F84-53518926B698}] @DACL=(02 0000) @="MNAccountInfo Class" . [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{DFC023D7-F210-4442-9A55-55E9D40CE941}] @DACL=(02 0000) @="moMIMJobHoldOffBackgroundJobs Object" "AppID"="" . [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{E08DE58F-82D2-4B97-A063-95E34EF205DE}] @DACL=(02 0000) @="moComponentMgr Object" "AppID"="{B0D40B5C-9E9D-4BAD-A0AC-1D905240A2B7}" . [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{E0CB08CE-AB3D-4779-9C77-62A439BFE6C3}] @DACL=(02 0000) @="AOL YGP PicEdit Ctrl" . [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{E0F158E1-CB04-11d0-BD4E-00A0C911CE86}\Instance] @DACL=(02 0000) . [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{E131CA8D-9008-4d14-B9C5-A22067D16600}] @DACL=(02 0000) @="moPlaylistSupportedTypes Object" "AppID"="" . [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{E1464921-DB71-A284-E612-F3A3C1162938}] @DACL=(02 0000) @="MNPlayCountReporting Class" . [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{E1D5C17F-A18C-4503-B5D6-1CE0CB132B45}] @DACL=(02 0000) @="moPortableMediaUserSettings Object" "AppID"="" . [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{E2B37663-210C-4B53-B167-956D8B5ABC92}] @DACL=(02 0000) @="moFieldInfo Object" "AppID"="" . [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{E3852604-B619-11d6-94EC-00047521F020}] @DACL=(02 0000) @="IWinAmpActiveXChat Class" . [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{E3927BD2-9988-42e7-AEDF-437F6EA66E81}] @DACL=(02 0000) @="moMIMJobRefresh Object" "AppID"="" . [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{E42CE23D-69F9-480A-A15F-BFF5E4D170C3}\VersionIndependentProgID] @DACL=(02 0000) @="DWUpdateService.InstanceList" . [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{E4DF88F0-FB94-4F30-A15C-AE5C24607B6D}] @DACL=(02 0000) @="moMIMJobPortableIdleTasks Object" "AppID"="" . [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{E4E01430-7348-467D-B2B8-170D716EF5C4}] @DACL=(02 0000) @="NcsWmiEventProv Class" "AppID"="{5037567E-50B9-4250-AAF2-B77693177175}" . [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{E6BE6F88-8996-4D8D-8832-2FD68F06FACF}] @DACL=(02 0000) @="moMetadataIColl Object" "AppID"="" . [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{E6DEC310-673A-450A-B3E9-FC35AF04F1E7}] @DACL=(02 0000) @SACL= @="turkish3x4inputmodule class" . [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{E74F8158-1396-40A9-A0FF-EDC00EECBBFE}] @DACL=(02 0000) @="moContextOperations Object" "AppID"="" . [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{E7D06080-238B-11D3-80D7-00104B1F6CEA}] @DACL=(02 0000) @="InstallShield Script Engine" . [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{E816E5E4-2364-4437-ABC8-BFACACB664D5}] @Class="REG_SZ" @DACL=(02 0000) @="PSFactoryBuffer" . [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{E88DCCE0-B7B3-11d1-A9F0-00AA0060FA31}\PersistentHandler] @DACL=(02 0000) @="{098f2470-bae0-11cd-b579-08002b30bfeb}" . [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{E9755AA3-4233-551F-BF46-88AF51FA5477}] @DACL=(02 0000) @="MNLicenseRequest Class" . [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{E981D791-F499-4837-A483-5AB22F1C548F}] @DACL=(02 0000) @="Engine_Ares Class" . [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{EA522566-ADD6-BD76-791A-39373AA8D26B}] @DACL=(02 0000) @="MNSettings Class" . [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{EAF79CF8-363B-4676-AB58-872B78264EC1}] @DACL=(02 0000) @="moResourceTable Object" "AppID"="{930090E3-743F-4514-B2CB-839A1D30DF50}" . [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{EB511AE4-87FE-4EFB-91A3-428B2F2601F7}] @DACL=(02 0000) @="Engine_Cerberus Class" . [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{EC2ECFCF-B5D9-A1FC-8224-44F244C58EE6}] @DACL=(02 0000) @="MNLogout Class" . [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{EC9B8ACF-09C1-4C7B-A6BA-F5CBC478CA71}] @DACL=(02 0000) @="Musicmatch Premium Service Plugin Class" . [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{ECFBE6E0-1AC8-11D4-8501-00A0CC5D1F63}] @DACL=(02 0000) @="WMplug" . [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{ED72A94B-7876-DC85-B386-9D2DFDB57137}] @DACL=(02 0000) @="MNPlaylist Class" . [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{EE2D6561-D63C-11D2-B561-00A0C92E6848}] @DACL=(02 0000) @="ShellExt Class" "AppID"="{3D62E9A1-D243-11D2-B561-00A0C92E6848}" . [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{EE75576D-633C-4d90-8CED-184581964B0A}] @DACL=(02 0000) @="QDiagDUpdateObj Class" . [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{EE93CB8B-53D8-46EB-8CC2-2958EAD7C536}] @DACL=(02 0000) @="moMIMJobExportItemToFile Object" "AppID"="" . [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{EFD23300-367F-4913-A032-232E9BC0EC94}] @DACL=(02 0000) @="moConfigSpecMgrFactory Object" "AppID"="" . [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{F141665D-EE09-4764-AE79-7787A379255D}] @DACL=(02 0000) @="moMIMJobCopyObjects Object" "AppID"="" . [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{F14E6B48-FBCA-4d32-BD79-7829D4F7E43B}] @DACL=(02 0000) @="FrnFrnWrdBrk Class" . [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{F1522EC1-F84F-4CE2-A38C-F9384B0DFD41}\VersionIndependentProgID] @DACL=(02 0000) @="DWUpdateService.ActivityLog" . [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{F1C9623D-72C0-4B38-9E11-6AB05D1E17D7}] @DACL=(02 0000) @="moTrackMetadataLookup Object" "AppID"="" . [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{F1E2A5D2-53F6-177F-B22D-89B764EF66EE}] @DACL=(02 0000) @="MNDRM Class" . [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{F23734A2-ABB2-A1D7-E469-378C28FCB58B}] @DACL=(02 0000) @="MNWMMetadata Class" "AppID"="{41D673C6-2ACD-46DE-A891-7093520A6C0C}" . [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{F4817E4B-04B6-11D3-8862-00C04F72F303}] @Class="REG_SZ" @DACL=(02 0000) @="PSFactoryBuffer" . [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{F4F30C01-A7B4-492e-943E-58A7CF2D9DD6}] @DACL=(02 0000) @="ACToolBarCtrl Class" . [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{F5AD359A-4A35-4A1C-890F-DF83FE881791}] @DACL=(02 0000) @="moProfile Object" "AppID"="{9AEE91CA-C80B-46A2-8FC8-FCDA22467903}" . [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{F61BC6E8-E914-E3E4-5185-3B79FB3CE91C}] @DACL=(02 0000) @="MNPlaylists Class" . [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{F752A82A-2E22-41EF-8CD1-CF74CA07CB75}] @DACL=(02 0000) @="moWinMsg Object" "AppID"="" . [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{F777D534-5FEA-4ECC-ABF0-E59F183654A1}] @DACL=(02 0000) @="moAutoDJMetadata Object" "AppID"="" . [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{F88A4455-BEB8-4D91-8C13-6807B0147727}] @DACL=(02 0000) @SACL= @="CHHInputModule Class" . [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{F9AE8980-7E52-11d0-8964-00C04FD611D7}] @DACL=(02 0000) @="MSIDXS" . [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{F9AE8981-7E52-11d0-8964-00C04FD611D7}] @DACL=(02 0000) @="MSIDXS ErrorLookup" . [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{FA13A9FA-CA9B-11D2-9780-00104B242EA3}] @DACL=(02 0000) @="WildTangent Control" . [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{FA945BB6-9D37-43FC-9B2A-AF09F56CBBF0}] @DACL=(02 0000) @="moDiagCollectionActiveX Object" "AppID"="{788AB2B4-64B7-413E-94D3-24C41C05191A}" . [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{FB215E25-F536-4B36-8262-ECF59601FAC1}] @DACL=(02 0000) @="MMJBText Control" . [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{FBBC3882-1D56-49A7-8CD9-08AFC41E33FC}] @DACL=(02 0000) @="moWmaFileTagger Object" "AppID"="" . [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{FBF23B40-E3F0-101B-8488-00AA003E56F8}\PersistentHandler] @DACL=(02 0000) @="{5e941d80-bf96-11cd-b579-08002b30bfeb}" . [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{FD170F7B-EE03-475A-8EFC-1B1F07EEB6C2}] @DACL=(02 0000) @="moConfigSpecMgr Object" "AppID"="" . [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{FE9617F6-E606-42AA-BECC-0E9CDA246D63}] @DACL=(02 0000) @="Color Class" . [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{FF8DA190-3574-11D4-8068-0060082AE372}] @DACL=(02 0000) @="Xceed FTP Control v1.1" . [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{FF8DA193-3574-11D4-8068-0060082AE372}] @DACL=(02 0000) @="Xceed Quick FTP Control v1.0" . [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{FFF2D28F-E4EE-44D9-8104-8E71556757F6}\VersionIndependentProgID] @DACL=(02 0000) @="DWUpdateService.Agent" . --------------------- DLLs Loaded Under Running Processes --------------------- . - - - - - - - > 'explorer.exe'(3012) c:\windows\system32\ieframe.dll c:\windows\system32\webcheck.dll c:\windows\system32\WPDShServiceObj.dll c:\windows\system32\PortableDeviceTypes.dll c:\windows\system32\PortableDeviceApi.dll . ------------------------ Other Running Processes ------------------------ . c:\program files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe c:\progra~1\Grisoft\AVG7\avgamsvr.exe c:\progra~1\Grisoft\AVG7\avgupsvc.exe c:\progra~1\Grisoft\AVG7\avgemc.exe c:\program files\Bonjour\mDNSResponder.exe c:\windows\eHome\ehRecvr.exe c:\windows\eHome\ehSched.exe c:\program files\Google\Update\1.3.29.5\GoogleCrashHandler.exe c:\windows\ehome\mcrdsvc.exe c:\program files\Canon\CAL\CALMAIN.exe c:\windows\system32\dllhost.exe c:\windows\system32\wscntfy.exe c:\windows\eHome\ehmsas.exe c:\windows\System32\regsvr32.exe c:\program files\Internet Explorer\IEXPLORE.EXE c:\program files\iPod\bin\iPodService.exe c:\program files\Internet Explorer\IEXPLORE.EXE c:\program files\AIM6\aolsoftware.exe c:\program files\Java\jre1.6.0_07\bin\jucheck.exe c:\program files\Yahoo!\Messenger\ymsgr_tray.exe . ************************************************************************** . Completion time: 2016-04-10 20:14:11 - machine was rebooted ComboFix-quarantined-files.txt 2016-04-11 00:14 . Pre-Run: 22,200,397,824 bytes free Post-Run: 23,781,318,656 bytes free . - - End Of File - - 678D58A9C4F4C061D74A4CB00BA6BC63 91722E6BC3A2B40FF00222DCA4A3DB3E