Tech Support banner

Status
Not open for further replies.
1 - 11 of 11 Posts

·
Registered
Joined
·
69 Posts
Discussion Starter #1
Hello all, I recently did a panda scan and found this:


Incident Status Location

Adware:adware/gator No disinfected Windows Registry


How can I get rid of it? Thanks.
 

·
TSF Security Manager, Emeritus
Joined
·
52,197 Posts
Well, that's just a registry remnant, and likely will do no harm...but let's have you run a HJT scan and we'll give your system a thorough look-see.

Please download HijackThis - this program will help us determine if there are any spyware/malware on your computer. Double-click on the file you just downloaded.
Click on the "Unzip" button to install. It will by default install to the directory - C:\PROGRAM FILES\HIJACKTHIS\

Double click on HijackThis.exe to run the program.

1. If it gives you an intro screen, just choose 'Do a system scan and save a logfile'.
2. If you don't get the intro screen, just hit Scan and then click on Save log.
3. Post the hijackthis.log file here. Do not fix anything in HijackThis since they may be harmless.
 

·
Registered
Joined
·
69 Posts
Discussion Starter #3
Hey guys heres my hijack:

Logfile of HijackThis v1.99.1
Scan saved at 10:35:57 PM, on 10/28/2005
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\CDProxyServ.exe
C:\WINDOWS\SYSTEM32\GEARSEC.EXE
C:\Program Files\Norton AntiVirus\navapsvc.exe
C:\Program Files\Norton AntiVirus\IWP\NPFMntor.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
C:\Program Files\Multimedia Card Reader\shwicon2k.exe
C:\WINDOWS\LTMSG.exe
C:\windows\system\hpsysdrv.exe
C:\WINDOWS\System32\hphmon05.exe
C:\WINDOWS\system32\hkcmd.exe
C:\Program Files\Microsoft AntiSpyware\gcasServ.exe
C:\WINDOWS\system32\CTHELPER.EXE
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\Program Files\HP\Digital Imaging\Unload\hpqcmon.exe
C:\Program Files\Creative Professional\E-MU PatchMix DSP\EmuPatchMixDSP.exe
C:\Program Files\Microsoft AntiSpyware\gcasDtServ.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\HijackThis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: NAV Helper - {BDF3E430-B101-42AD-A544-FADC6B084872} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: HP View - {B2847E28-5D7D-4DEB-8B67-05D28BCF79F5} - c:\Program Files\HP\Digital Imaging\bin\hpdtlk02.dll
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O4 - HKLM\..\Run: [Symantec NetDriver Monitor] C:\PROGRA~1\SYMNET~1\SNDMon.exe /Consumer
O4 - HKLM\..\Run: [Sunkist2k] C:\Program Files\Multimedia Card Reader\shwicon2k.exe
O4 - HKLM\..\Run: [Recguard] C:\WINDOWS\SMINST\RECGUARD.EXE
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [LTMSG] LTMSG.exe 7
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [hpsysdrv] c:\windows\system\hpsysdrv.exe
O4 - HKLM\..\Run: [HPHmon05] C:\WINDOWS\System32\hphmon05.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [gcasServ] "C:\Program Files\Microsoft AntiSpyware\gcasServ.exe"
O4 - HKLM\..\Run: [CTHelper] CTHELPER.EXE
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [CamMonitor] c:\Program Files\HP\Digital Imaging\Unload\hpqcmon.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKCU\..\Run: [SetDefaultMIDI] MIDIDef.exe
O4 - HKCU\..\Run: [NVIEW] rundll32.exe nview.dll,nViewLoadHook
O4 - HKCU\..\Run: [BackupNotify] c:\Program Files\HP\Digital Imaging\bin\backupnotify.exe
O4 - Startup: ERUNT AutoBackup.lnk = C:\Program Files\ERUNT\AUTOBACK.EXE
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MI1933~1\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MI1933~1\OFFICE11\REFIEBAR.DLL
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {04E214E5-63AF-4236-83C6-A7ADCBF9BD02} (HouseCall Control) - http://housecall60.trendmicro.com/housecall/xscan60.cab
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall Control) - http://a840.g.akamai.net/7/840/537/2004061001/housecall.trendmicro.com/housecall/xscan53.cab
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://acs.pandasoftware.com/activescan/as5free/asinst.cab
O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxsrvc.dll
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
O23 - Service: XCP CD Proxy (CD_Proxy) - Unknown owner - C:\WINDOWS\CDProxyServ.exe
O23 - Service: GEARSecurity - GEAR Software - C:\WINDOWS\SYSTEM32\GEARSEC.EXE
O23 - Service: Norton AntiVirus Auto-Protect Service (navapsvc) - Symantec Corporation - C:\Program Files\Norton AntiVirus\navapsvc.exe
O23 - Service: Norton AntiVirus Firewall Monitor Service (NPFMntor) - Symantec Corporation - C:\Program Files\Norton AntiVirus\IWP\NPFMntor.exe
O23 - Service: NVIDIA Driver Helper Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
O23 - Service: SAVScan - Symantec Corporation - C:\Program Files\Norton AntiVirus\SAVScan.exe
O23 - Service: ScriptBlocking Service (SBService) - Symantec Corporation - C:\PROGRA~1\COMMON~1\SYMANT~1\SCRIPT~1\SBServ.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: Symantec SPBBCSvc (SPBBCSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
O23 - Service: Symantec Core LC - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
O23 - Service: SymWMI Service (SymWSC) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe

Thanks a lot for the help. I did run spybot, adaware, and microsoft anti but they did not find it. Hey Subs did you get my PMs...i figured you're busy or something..well take care guys and thanks.
 

·
TSF Security Manager, Emeritus
Joined
·
52,197 Posts
Hey, sUbs...those were fine ideas, mate....it would have been OK to leave them...lol

Hi netnewbie -

Let's see if we can root out those entries Panda seems to think are there. As sUBs indicated in his now removed post, Adaware and Spybot will usually find those types of things. Your HJT log appears clean.

Please download Ewido Security Suite at http://www.ewido.net/en/download/.

1. Install Ewido Security Suite.
2. When installing, under 'Additional Options' uncheck:
* Install background guard
* Install scan via context menu
3. Launch Ewido, there should be an icon on your desktop, double click it.
4. The program will now open to the main screen.
5. When you run Ewido for the first time, you will get a warning 'Database could not be found!'. Click OK. We will fix this in a moment.
6. You will need to update Ewido to the latest definition files.
* On the left hand side of the main screen click update.
* Then click on Start Update.
7. The update will start and a progress bar will show the updates being installed. The status bar at the bottom will display 'Update successful'.
8. Exit Ewido. DO NOT scan yet.

Restart your computer and boot into Safe Mode by hitting the F8 key repeatedly until a menu shows up (and choose Safe Mode from the list). In some systems, this may be the F5 key, so try that if F8 doesn't work. Make sure to close any open browsers.

Now open Ewido and do a scan on your system.

* Click on scanner
* Click on Complete System Scan and the scan will begin.
* NOTE: During some scans with Ewido it is finding cases of false positives.
o You will need to step through the process of cleaning files one-by-one.
o If Ewido detects a file you KNOW to be legitimate, select none as the action.
o Do NOT select 'Perform action on all infections'
o If you are unsure of any entry found, select none for now as the action.
* Once the scan has completed, there will be a button located on the bottom of the screen named Save report
* Click Save report.
* Save the report .txt file to your desktop or a location where you can find it easily.

Note: There is no need to purchase Ewido. It will remain as the freeware version after the trial period, which means the guard process will no longer work, but the scanner will be just as effective.

Now, if Ewido didn't find them, do this:

Right click on this link http://www.greyknight17.com/spy/RegSrch.vbs and choose 'Save As'. Save it somewhere. Now run that program and do a search for these files (if more than one, make sure to search and save them separately):

gator

trickler


Save the file/files and post the results here.
 

·
Registered
Joined
·
69 Posts
Discussion Starter #5
thanks a lot for the help tetonbob, here is my ewido report:

---------------------------------------------------------
ewido security suite - Scan report
---------------------------------------------------------

+ Created on: 1:22:55 PM, 10/30/2005
+ Report-Checksum: 780FA5CA

+ Scan result:

HKLM\SOFTWARE\Classes\CLSID\{2B96D5CC-C5B5-49A5-A69D-CC0A30F9028C} -> Spyware.MiniBug : Cleaned with backup
HKLM\SOFTWARE\Classes\Interface\{49DB48FF-02B5-4645-B676-94A4DF1AA026} -> Spyware.SecondThought : Cleaned with backup
HKLM\SOFTWARE\Classes\Interface\{49DB48FF-02B5-4645-B676-94A4DF1AA026}\Forward\\ -> Spyware.SecondThought : Cleaned with backup
HKLM\SOFTWARE\Classes\Interface\{6E0ED53C-9908-49ED-B055-7CB31B162577} -> Spyware.SecondThought : Cleaned with backup
HKLM\SOFTWARE\Classes\Interface\{6E0ED53C-9908-49ED-B055-7CB31B162577}\Forward\\ -> Spyware.SecondThought : Cleaned with backup
HKLM\SOFTWARE\Classes\Interface\{830D3AED-2FA9-454F-B266-D931862BBF34} -> Spyware.SecondThought : Cleaned with backup
HKLM\SOFTWARE\Classes\Interface\{830D3AED-2FA9-454F-B266-D931862BBF34}\Forward\\ -> Spyware.SecondThought : Cleaned with backup
HKLM\SOFTWARE\Classes\Interface\{8C53BD8E-B12D-4C8F-AD0E-C9DDC39D1273} -> Spyware.SecondThought : Cleaned with backup
HKLM\SOFTWARE\Classes\Interface\{8C53BD8E-B12D-4C8F-AD0E-C9DDC39D1273}\TypeLib\\ -> Spyware.VirtualBouncer : Cleaned with backup
HKLM\SOFTWARE\Classes\Interface\{9BCDD51B-4A7B-446C-8452-D32D38004582} -> Spyware.SecondThought : Cleaned with backup
HKLM\SOFTWARE\Classes\Interface\{9BCDD51B-4A7B-446C-8452-D32D38004582}\Forward\\ -> Spyware.SecondThought : Cleaned with backup
HKLM\SOFTWARE\Classes\Interface\{A986F4DB-792E-4571-8974-0BB6E024766F} -> Spyware.SecondThought : Cleaned with backup
HKLM\SOFTWARE\Classes\Interface\{A986F4DB-792E-4571-8974-0BB6E024766F}\Forward\\ -> Spyware.SecondThought : Cleaned with backup
HKLM\SOFTWARE\Classes\Interface\{BCCAB53D-0895-40C3-A942-A03538CE227A} -> Spyware.SecondThought : Cleaned with backup
HKLM\SOFTWARE\Classes\Interface\{BCCAB53D-0895-40C3-A942-A03538CE227A}\Forward\\ -> Spyware.SecondThought : Cleaned with backup
HKLM\SOFTWARE\Classes\Interface\{C0F88E9E-DCEB-4655-968A-AE508A677C39} -> Spyware.SecondThought : Cleaned with backup
HKLM\SOFTWARE\Classes\Interface\{C0F88E9E-DCEB-4655-968A-AE508A677C39}\Forward\\ -> Spyware.SecondThought : Cleaned with backup
HKLM\SOFTWARE\Classes\Interface\{D7EAC2D8-2D52-4010-A4AD-DFDF60C1706C} -> Spyware.SecondThought : Cleaned with backup
HKLM\SOFTWARE\Classes\Interface\{D7EAC2D8-2D52-4010-A4AD-DFDF60C1706C}\Forward\\ -> Spyware.SecondThought : Cleaned with backup
HKLM\SOFTWARE\Classes\MiniBugTransporter.MiniBugTransporterX\CLSID\\ -> Spyware.MiniBug : Cleaned with backup
HKLM\SOFTWARE\Classes\MiniBugTransporter.MiniBugTransporterX.1\CLSID\\ -> Spyware.MiniBug : Cleaned with backup
HKLM\SOFTWARE\Classes\TypeLib\{5E594162-60A9-487D-84B8-DBDD716CB862} -> Spyware.VirtualBouncer : Cleaned with backup
HKU\S-1-5-21-942451771-3277315824-1460096782-500\Software\Microsoft\Internet Explorer\Extensions\CmdMapping\\{c95fe080-8f5d-11d2-a20b-00aa003c157a} -> Spyware.Alexa : Cleaned with backup
:mozilla.6:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\default.lra\cookies.txt -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.87:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\default.lra\cookies.txt -> Spyware.Cookie.Adjuggler : Cleaned with backup
:mozilla.102:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\default.lra\cookies.txt -> Spyware.Cookie.Specificclick : Cleaned with backup
:mozilla.246:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\default.lra\cookies.txt -> Spyware.Cookie.Esomniture : Cleaned with backup
C:\Documents and Settings\Owner\Cookies\[email protected][2].txt -> Spyware.Cookie.Yieldmanager : Cleaned with backup
C:\Documents and Settings\Owner\Cookies\[email protected][2].txt -> Spyware.Cookie.Burstnet : Cleaned with backup
C:\Documents and Settings\Owner\Cookies\[email protected][2].txt -> Spyware.Cookie.Sexcounter : Cleaned with backup
C:\Documents and Settings\Owner\Cookies\[email protected][1].txt -> Spyware.Cookie.Burstbeacon : Cleaned with backup
C:\Documents and Settings\Owner\Cookies\[email protected][1].txt -> Spyware.Cookie.Burstnet : Cleaned with backup


::Report End
 

·
TSF Security Manager, Emeritus
Joined
·
52,197 Posts
Download Trend Micro™ Anti-Spyware (by clicking the "Scan and Clean your PC" button).
  • Choose Save, NOT run, and save to your desktop
  • Double-click the tmas-web-scan.exe icon
  • It will say "Loading TrendMicro definitions".
  • Click "Start Scan"
After it's done scanning, click "Scan Results"
  • Make sure all items found have a check next to them, then click "Clean Threats Now".
  • Click Exit.
Reboot your computer. I then need you to repeat the same procedure above again... using the TrendMicro tool. I need the log from the second scan/clean...NOT the first...as this will contain what’s left in the system.

In place of the TrendMicro icon will be a text file called "Antispyware.log", please double-click that log and copy the entire contents and paste them here.



Perform an online scan with Internet Explorer with Panda ActiveScan
** click on "Free use ActiveScan" located on the top right hand corner
  1. Click Scan your PC & a 'pop up' window shall appear. *ensure that your pop up blocker doesn't block it
  2. Click Scan Now
  3. Enter your e-mail address & click Scan Now ...begins downloading 8 MB Panda's ActiveX controls
Begin the scan by selecting My Computer
  • If it finds any malware, it will offer you a report.
  • Click on see report. Then click Save report
Post the contents of the report in your next reply

*You needn't remain online while it's doing the scan but you have to re-connect after it has finished to see the report.
*Turn off the real time scanner of any existing antivirus program while performing the online scan


Run a new scan with HJT and post that log here, along wth results from:

Antispyware.log
Panda Active scan
 

·
Registered
Joined
·
69 Posts
Discussion Starter #7
here is the results for that regsrch program, but when I did a search for trickler it said it found like 30 files or something and I clicked okay and nothing popped up no results nothing. Here are the results for gator:

REGEDIT4
; RegSrch.vbs © Bill James

; Registry search results for string "gator" 10/30/2005 4:01:23 PM

; NOTE: This file will be deleted when you close WordPad.
; You must manually save this file to a new location if you want to refer to it again later.
; (If you save the file with a .reg extension, you can use it to restore any Registry changes you make to these values.)


[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\.fav]
@="Outlook.NavigatorBarFile"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{083863F1-70DE-11d0-BD40-00A0C911CE86}\Instance\{2D300C60-73EE-11D2-AFD4-006008AFEA28}]
"FriendlyName"="Xing® VideoCD Navigator"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{083863F1-70DE-11d0-BD40-00A0C911CE86}\Instance\{9B8C4620-2C1A-11D0-8493-00A02438AD48}]
"FriendlyName"="DVD Navigator"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{083863F1-70DE-11d0-BD40-00A0C911CE86}\Instance\{AABC1235-776D-11D2-8010-00104B9B8592}]
"FriendlyName"="InterVideo Navigator"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{2D300C60-73EE-11D2-AFD4-006008AFEA28}]
@="Xing® VideoCD Navigator"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{46816230-46E3-11D3-8D01-005004838617}]
@="Microsoft Office IPP Aggregator Binder Class"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{9B8C4620-2C1A-11D0-8493-00A02438AD48}]
@="DVD Navigator"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{AABC1235-776D-11D2-8010-00104B9B8592}]
@="InterVideo Navigator"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{2D4F01F3-AE42-3250-B96C-3F756A9BDBF2}]
@="_DataNavigator"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{34E00EF9-83E2-3BBC-B6AF-4CAE703838BD}]
@="_TypeDelegator"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{FECEAAA5-8405-11CF-8BA1-00AA00476DA6}]
@="IOmNavigator"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\MSDAMAGG.Binder]
@="Microsoft OLE DB Master Aggregator - Binder"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\MSDAMAGG.Binder.1]
@="Microsoft OLE DB Master Aggregator - Binder"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\MSOAUTH.Binder]
@="Microsoft Office IPP Aggregator Binder Class"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\MSOAUTH.Binder.1]
@="Microsoft Office IPP Aggregator Binder Class"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Outlook.NavigatorBarFile]

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Outlook.NavigatorBarFile\shell]

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Outlook.NavigatorBarFile\shell\Open]

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Outlook.NavigatorBarFile\shell\Open\command]

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Software\Microsoft\MasterAggregatorForIPP]

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Software\Microsoft\MasterAggregatorForIPP\MSDAIPP]

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Software\Microsoft\MasterAggregatorForIPP\MSDAIPP\Providers]

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Software\Microsoft\MasterAggregatorForIPP\MSDAIPP\Providers\{9FECD570-B9D4-11d1-9C78-0000F875AC61}]

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Software\Microsoft\MasterAggregatorForIPP\MSDAIPP\Providers\{9FECD571-B9D4-11d1-9C78-0000F875AC61}]

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Software\Microsoft\MasterAggregatorForIPP\OleDbHandlers]

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Software\Microsoft\MasterAggregatorForIPP\OleDbHandlers\{E1D2BF40-A96B-11d1-9C6B-0000F875AC61}]

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Software\RealNetworks\RealPlayer\6.0\Preferences\PluginHandlerData\PluginInfo0]
@="{ComponentName~Shttp://ns.real.com/gemini.v1:RJBCDPlaylistActor~PluginFilename~Scdpl3210.dll~ComponentCLSID~X2m05y6oCY025CKOjyrBGKQ==}{ComponentName~Shttp://ns.real.com/gemini.v1:nativecdplaylist~PluginFilename~Scdpl3210.dll~ComponentCLSID~XbrLR4XkiHEKGwl7pOqTgNA==}{ComponentName~Shttp://ns.real.com/gemini.v1:nativecdmanager~PluginFilename~Scdpl3210.dll~ComponentCLSID~XEr90jxVpo0qQD+HYBtyRxQ==}{PluginFilename~Scdpl3210.dll~ComponentCLSID~XtQQjowfr2kOjeHZ0w2HcyA==}{PluginFilename~Scdpl3210.dll~ComponentCLSID~Xm6G5FMQmXEeyLw3WlCY5Rw==}{PluginFilename~Scdpl3210.dll~ComponentCLSID~XtzXzfqQTe0OUi06+vvRXRw==}{PluginFilename~Scdpl3210.dll~ComponentCLSID~XrRqchZEgqU+RVL11ZQ/voA==}{PluginFilename~Sembd3260.dll~ComponentCLSID~XYECIN3SoaUWbf9utVc9RvA==}{PluginFilename~Sfftr3210.dll~ComponentCLSID~X8peseUH0MEWHsWF+gvEGDQ==}{PluginFilename~Sfftr3210.dll~ComponentCLSID~XaLp4uYKb+UScuyy5VRiGSQ==}{PluginFilename~Sfftr3210.dll~ComponentCLSID~XOq2XjEIY/UOGiP3QFd8Lsw==}{PluginFilename~Sfftr3210.dll~ComponentCLSID~XVf2jqauBrkueHUaboHZy5g==}{PluginFilename~Sfftr3210.dll~ComponentCLSID~XJtL6R1rcwE+zatOK7KDRAA==}{PluginFilename~Sierpplug.dll~ComponentCLSID~Xgk2k/5cD80GxEj2ESjGkGQ==}{PluginFilename~SMPACore.dll~ComponentCLSID~XTIeB1un6C0SkzU5aFUzQBQ==}{PluginFilename~SMPACore.dll~ComponentCLSID~XaJ9iA9ibNku5ULu6iagNsg==}{PluginFilename~SMPACore.dll~ComponentCLSID~XW/Gklg1K00KUk2X9MILGWw==}{PluginFilename~SMPACore.dll~ComponentCLSID~X7UeU47oHb0iNbPD0hgngWg==}{PluginFilename~SMPACore.dll~ComponentCLSID~X9+vCVNJpAEuC+623SguaQQ==}{PluginFilename~Smpazip.dll~ComponentCLSID~XK0V1j1ZIJEKwBvXckL7h6Q==}{ComponentName~Shttp://ns.real.com/gemini.v1:InstalledPortableDeviceEnumerator~PluginFilename~Smyde3260.dll~ComponentCLSID~XrfDNbc7u8Emv3terEGhl+g==}{ComponentName~Shttp://ns.real.com/gemini.v1:AllPortableDeviceEnumerator~PluginFilename~Smyde3260.dll~ComponentCLSID~XsxZnoq6F50qZHxdMD86HQg==}{ComponentName~Shttp://ns.real.com/gemini.v1:rpdeviceview~PluginFilename~Smyde3260.dll~ComponentCLSID~X5GiQDa0ao0Gs9iLssf3MTA==}{ComponentName~Shttp://ns.real.com/gemini.v1:deviceshowmeactor~PluginFilename~Smyde3260.dll~ComponentCLSID~XuE/0+CGfZEayQIhQi59N9g==}{ComponentName~Shttp://ns.real.com/gemini.v1:pdburnprefgeneral~IRCAPreferencable~SPrefPage~PluginFilename~Spdbu3210.dll~ComponentCLSID~XCuyTkxy480+hzv3faM6HPw==}{ComponentName~Shttp://ns.real.com/gemini.v1:pdburnprefaudiocd~PluginFilename~Spdbu3210.dll~ComponentCLSID~XLhjKXAyNV0iOmD0+E6l91A==}{ComponentName~Shttp://ns.real.com/gemini.v1:pdburnprefmp3cd~PluginFilename~Spdbu3210.dll~ComponentCLSID~Xk8LVbv0bAEeWxsUbkKPaaA==}{ComponentName~Shttp://ns.real.com/gemini.v1:pdburnprefdatacd~PluginFilename~Spdbu3210.dll~ComponentCLSID~X9A2mSuS/Bk2SnD2pwXfhXw==}{PluginFilename~Spdbu3210.dll~ComponentCLSID~XtxTAaCSDNUen4v71BFeSnw==}{PluginFilename~Spdbu3210.dll~ComponentCLSID~Xfka8N5ca1EmJ9AKumyZXhQ==}{PluginFilename~Spdbu3210.dll~ComponentCLSID~XXSzgMgI2HkSCfOBCiY2sqA==}{PluginFilename~Spdbu3210.dll~ComponentCLSID~XEOyHpq+T4EC8gUtl6/2kzw==}{PluginFilename~Spdbu3210.dll~ComponentCLSID~X7LuwuUXZokyndpapdJ8aGg==}{PluginFilename~Spdbu3210.dll~ComponentCLSID~XVtgzV+i9vEicVDuLE3q9zA==}{PluginFilename~Spdbu3210.dll~ComponentCLSID~XbhD6Wj++mE+vGkL3ZA33OQ==}{PluginFilename~Spdbu3210.dll~ComponentCLSID~X3kiJe6SApEmErvu8zF0Aog==}{PluginFilename~Spdbu3210.dll~ComponentCLSID~X62FQM326fUatEElEdsN6pQ==}{ComponentName~Shttp://ns.real.com/gemini.v1:DiskSpaceCheckDlg~PluginFilename~Spdbu3210.dll~ComponentCLSID~XziR0R2w4Z0aHhdcs1OKKZw==}{ComponentName~Shttp://ns.real.com/gemini.v1:pdurlhurlactor~PluginFilename~Spdbu3210.dll~ComponentCLSID~Xp2RhGBbmNk6218FMBmK0Aw==}{ComponentName~Shttp://ns.real.com/gemini.v1:pdburnpopupactor~PluginFilename~Spdbu3210.dll~ComponentCLSID~XNMHC4fWwvUSMd2Zo1sO4gA==}{PluginFilename~Spdbu3210.dll~ComponentCLSID~X1nPTaSiqRkiIPjQP/Oqv1A==}{PluginFilename~Spdbu3210.dll~ComponentCLSID~XgiWKZ8Iy8ECghexAE5KOjQ==}{PluginFilename~Spdbu3210.dll~ComponentCLSID~XBQY8U0L6mEOXG3ZCSzCGLQ==}{ComponentName~Shttp://ns.real.com/gemini.v1:nativepdareacontrol~PluginFilename~Spdbu3210.dll~ComponentCLSID~Xiz30pudpo0GWs2bfcSn5MA==}{ComponentName~Shttp://ns.real.com/gemini.v1:medialibraryactor~PluginFilename~Srjbc3260.dll~ComponentCLSID~Xz3Gagbvl7k+fotYFEiGcWQ==}{ComponentName~Shttp://ns.real.com/gemini.v1:rjbmenuactor~PluginFilename~Srjbc3260.dll~ComponentCLSID~X4s1k33gwXkqvSKpayK6Rgw==}{PluginFilename~Srjbc3260.dll~ComponentCLSID~XmBytOtati0OhN++SvsO/cQ==}{ComponentName~Shttp://ns.real.com/gemini.v1:rptemplatemanager~PluginFilename~Srjbc3260.dll~ComponentCLSID~XKqAEBcAtikO4GziM2cnAEQ==}{ComponentName~Shttp://ns.real.com/gemini.v1:RPDownloadMgrActor~PluginFilename~Srjbc3260.dll~ComponentCLSID~XSCYYkQ/ls0yk9xmvxkJ9VA==}{PluginFilename~Srjbc3260.dll~ComponentCLSID~X92zCN4dO1UGQrwMhyd3qRA==}{PluginFilename~Srjbc3260.dll~ComponentCLSID~XRO5h/4NjKUGTIu61HzkU9g==}{ComponentName~Shttp://ns.real.com/gemini.v1:nativemedialibrary~PluginFilename~Srjbc3260.dll~ComponentCLSID~XtBE+ZotXfkm45FUdI0QpVA==}{ComponentName~Shttp://ns.real.com/gemini.v1:nativemedialibrarytree~PluginFilename~Srjbc3260.dll~ComponentCLSID~Xf+5baHFowEe9ElT/gk+x7w==}{ComponentName~Shttp://ns.real.com/gemini.v1:licenseacquisitionhelper~PluginFilename~Srjbc3260.dll~ComponentCLSID~XwTV49pYP1hGt0gDA8ECmGg==}{ComponentName~Shttp://ns.real.com/gemini.v1:portabledeviceviewactor~PluginFilename~Srjbc3260.dll~ComponentCLSID~XX6nLdCZmF06vfyemNo1UBg==}{ComponentName~Shttp://ns.real.com/gemini.v1:rpdatabase~PluginFilename~Srjbc3260.dll~ComponentCLSID~XdGxGPLn8gUahHGwv2StEyQ==}{ComponentName~Shttp://ns.real.com/gemini.v1:nativerjbapplication~PluginFilename~Srjbdll.dll~ComponentCLSID~X1W+pGzTmAU6qA9lfbdTQWA==}{ComponentName~Shttp://ns.real.com/gemini.v1:rjbactor~PluginFilename~Srjbdll.dll~ComponentCLSID~Xva4TuczCm0GHOIaNnXi4mg==}{ComponentName~Shttp://ns.real.com/gemini.v1:rpeqactor~PluginFilename~Srjbe3260.dll~ComponentCLSID~X1LH2uuTm1BGTRwDQt7I98A==}{PluginFilename~Srjbe3260.dll~ComponentCLSID~XcYYA5t2snkS9O1tYFLAMWA==}{PluginFilename~Srjbs3260.dll~ComponentCLSID~X2AZolTjB00ytpr/YMHENmQ==}{ComponentName~Shttp://ns.real.com/gemini.v1:rjbcustomcontrolactor~PluginFilename~Srjbs3260.dll~ComponentCLSID~XbFubnZGJxEGel1+t5QcSDA==}{IRCAPreferencable~SPrefPage~PluginFilename~Srjmisc.dll~ComponentCLSID~Xs3RTL5fZYUWCRRX5ihvOEA==}{IRCAPreferencable~SPrefPage~PluginFilename~Srjmisc.dll~ComponentCLSID~XZp0X+N6wEEiYRRq4BcuRww==}{IRCAPreferencable~SPrefPage~PluginFilename~Srjmisc.dll~ComponentCLSID~XSPeZpO9Jh0eIgzvtc0Z2sg==}{IRCAPreferencable~SPrefPage~PluginFilename~Srjmisc.dll~ComponentCLSID~X+Fgg5xVVBUOz3jviwehu2Q==}{IRCAPreferencable~SPrefPage~PluginFilename~Srjmisc.dll~ComponentCLSID~XysvYYzK0akGmwJ72SlKWKA==}{PluginFilename~Srpap3260.dll~ComponentCLSID~XiRT3Bv9DbEKU6Ux1TCelAQ==}{ComponentName~Shttp://ns.real.com/viper.v1:RPFrameWindowActor~PluginFilename~Srpap3260.dll~ComponentCLSID~XI0GawtyqakyQYvXfi2nZPQ==}{ComponentName~Shttp://ns.real.com/viper.v1:_rpskinmanager~PluginFilename~Srpap3260.dll~ComponentCLSID~XkdstWlNN5USqADNkz9vSdg==}{ComponentName~Shttp://ns.real.com/viper.v1:http://ns.real.com/viper.v1~PluginFilename~Srpap3260.dll~ComponentCLSID~XZfbp11r1SkCr9Ea1l+TUZQ==}{PluginFilename~Srpap3260.dll~ComponentCLSID~XIzecvUPgJEOoGqR7csQn1w==}{PluginFilename~Srpap3260.dll~ComponentCLSID~XqFzhbIWh9Uid7fqzMhBqHw==}{PluginFilename~Srpap3260.dll~ComponentCLSID~XW/fye8K2K02EFNJ085fEkA==}{PluginFilename~Srpap3260.dll~ComponentCLSID~XswfKoCgdbUONJGSl+phlcA==}{PluginFilename~Srpap3260.dll~ComponentCLSID~XtrTzYPxdw0yef1NP/XrD+g==}{PluginFilename~Srpap3260.dll~ComponentCLSID~XSPWYqsyRWEGoSs+/mt4Dzg==}{PluginFilename~Srpcl3260.dll~ComponentCLSID~XgOZpQdC+SEWsq9SN/Op5RQ==}{PluginFilename~Srpcl3260.dll~ComponentCLSID~XFDdHvbNxHkqT4BuHjkzt+A==}{PluginFilename~Srpcl3260.dll~ComponentCLSID~XczBEpUJvU02oAvL4iVlNcw==}{PluginFilename~Srpcl3260.dll~ComponentCLSID~XgqT4AiKWCk+PybAXCGifDg==}{PluginFilename~Srpcl3260.dll~ComponentCLSID~XYK0zn7y88E22vsF6Byr6nA==}{PluginFilename~Srpcl3260.dll~ComponentCLSID~X8FzB82X+0hGn5gDA8DGKWQ==}{PluginFilename~Srpcl3260.dll~ComponentCLSID~XXA2J8mqqhkWpwJW26g33yw==}{PluginFilename~Srpcl3260.dll~ComponentCLSID~XTIwar04ck0qIPBYr5jNMEQ==}{ComponentName~Shttp://ns.real.com/gemini.v1:_rpsystemsettingsdb~PluginFilename~Srpcl3260.dll~ComponentCLSID~XFOBygqvLQU6ZywcWJeycTA==}{PluginFilename~Srpcl3260.dll~ComponentCLSID~X/WH7sw5ow0+A/xDfxgcPyA==}{PluginFilename~Srpcl3260.dll~ComponentCLSID~XBpDcEXSyPkiVJc4PM7umig==}{PluginFilename~Srpcl3260.dll~ComponentCLSID~XBRQiAUmJZU2lHB48kePS/Q==}{PluginFilename~Srpcl3260.dll~ComponentCLSID~XIjUyT2m3ekex63CnHUdTqw==}{PluginFilename~Srpcl3260.dll~ComponentCLSID~XZhwZyHMNf067q2b4nIJnOw==}{PluginFilename~Srpcl3260.dll~ComponentCLSID~X5SpD4VMbpkGeXpxiTEl/Mg==}{PluginFilename~Srpcl3260.dll~ComponentCLSID~X7KRU02R7Nk2cDmFSFg44vw==}{PluginFilename~Srpcl3260.dll~ComponentCLSID~XDKRe4zjTzECcT2YRTzLr4A==}{PluginFilename~Srpcl3260.dll~ComponentCLSID~XAcANo9F01RGttgDA8ECmGg==}{PluginFilename~Srpcl3260.dll~ComponentCLSID~XNeJ5c+I/mUCVwo6BPHFqww==}{PluginFilename~Srpcl3260.dll~ComponentCLSID~X9T6V8ARhG0C7EC99zfzJag==}{PluginFilename~Srpcl3260.dll~ComponentCLSID~XFAO0kbReVE+bDCa1RKL1mQ==}{ComponentName~Shttp://ns.real.com/gemini.v1:buttonbar~PluginFilename~Srpct3260.dll~ComponentCLSID~XIf9yatC71BG1fADQt0wtXA==}{ComponentName~Shttp://ns.real.com/gemini.v1:popoutpage~PluginFilename~Srpct3260.dll~ComponentCLSID~XyWhLl5RVlE6auBgX5XD0VQ==}{ComponentName~Shttp://ns.real.com/gemini.v1:labelbutton~PluginFilename~Srpct3260.dll~ComponentCLSID~XgA/bgfG+1BG1fADQt0wtXA==}{ComponentName~Shttp://ns.real.com/gemini.v1:navigablebuttonbar~PluginFilename~Srpct3260.dll~ComponentCLSID~XQU1pF5LK1BG1fADQt0wtXA==}{ComponentName~Shttp://ns.real.com/gemini.v1:navigatoractor~PluginFilename~Srpct3260.dll~ComponentCLSID~XgfkGr3rA1BG1fADQt0wtXA==}{ComponentName~Shttp://ns.real.com/gemini.v1:rplayoutmanageractor~PluginFilename~Srpct3260.dll~ComponentCLSID~Xyd0ZUSdm/0iFq1K824phbA==}{ComponentName~Shttp://ns.real.com/gemini.v1:dynamiccontaineractor~PluginFilename~Srpct3260.dll~ComponentCLSID~XQ"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Software\RealNetworks\RealPlayer\6.0\Preferences\PluginHandlerData\PluginInfo1]
@="l4gk6xRyk+rjlhEmx+b/Q==}{ComponentName~Shttp://ns.real.com/gemini.v1:rpverticallayout~PluginFilename~Srpct3260.dll~ComponentCLSID~X5KySQKHsNE+EgWbS27dJ1g==}{ComponentName~Shttp://ns.real.com/gemini.v1:rphorizontallayout~PluginFilename~Srpct3260.dll~ComponentCLSID~XBs1Dh5j6qkG24meMU1ECPw==}{ComponentName~Shttp://ns.real.com/gemini.v1:rptemplateactor~PluginFilename~Srpct3260.dll~ComponentCLSID~XK3oHXF1vPE60q0Ynd6fGfg==}{ComponentName~Shttp://ns.real.com/gemini.v1:rpstateactor~PluginFilename~Srpct3260.dll~ComponentCLSID~XB4/ajQ2C7UmPrMgwTDkLQg==}{ComponentName~Shttp://ns.real.com/gemini.v1:rpwindowactor~PluginFilename~Srpct3260.dll~ComponentCLSID~XM5JWOPloBU64elT3FaBC7g==}{ComponentName~Shttp://ns.real.com/gemini.v1:rpmessageboxactor~PluginFilename~Srpct3260.dll~ComponentCLSID~X5Mrn2yFZsEapyLtorWGl1g==}{ComponentName~Shttp://ns.real.com/gemini.v1:rpmenuactor~PluginFilename~Srpct3260.dll~ComponentCLSID~Xr7BqnMhDlECvYSis0ztfHw==}{ComponentName~Shttp://ns.real.com/gemini.v1:rpboundscheckactor~PluginFilename~Srpct3260.dll~ComponentCLSID~XzzxFvJHlF0WbzY38golEcA==}{ComponentName~Shttp://ns.real.com/gemini.v1:rpdockablewindowactor~PluginFilename~Srpct3260.dll~ComponentCLSID~XmDx9u/hH5kyT0QkP4rSyJw==}{ComponentName~Shttp://ns.real.com/gemini.v1:navigator~PluginFilename~Srpct3260.dll~ComponentCLSID~Xb3Vi3Xy8Z0uPamcOLSXpDg==}{ComponentName~Shttp://ns.real.com/gemini.v1:variableexpression~PluginFilename~Srpct3260.dll~ComponentCLSID~Xxf5Fri03mEazhBWPAu9d6w==}{ComponentName~Shttp://ns.real.com/gemini.v1:rpdraghandle~PluginFilename~Srpct3260.dll~ComponentCLSID~XxaAZfJPz9UO+FVOxkgRdfA==}{ComponentName~Shttp://ns.real.com/gemini.v1:rpstatictext~PluginFilename~Srpct3260.dll~ComponentCLSID~XFBqbhQsClU6VSvuSRQDJeQ==}{ComponentName~Shttp://ns.real.com/gemini.v1:rpstaticimage~PluginFilename~Srpct3260.dll~ComponentCLSID~XANACki/fbUq3jj1ygti7tg==}{ComponentName~Shttp://ns.real.com/gemini.v1:rpspacer~PluginFilename~Srpct3260.dll~ComponentCLSID~X6KhzuJN0JkK8GhDdzbET/Q==}{ComponentName~Shttp://ns.real.com/gemini.v1:rpbuttonbar~PluginFilename~Srpct3260.dll~ComponentCLSID~Xvwe3KKST9UywYSoxeGuNzQ==}{ComponentName~Shttp://ns.real.com/gemini.v1:rpchevronactor~PluginFilename~Srpct3260.dll~ComponentCLSID~XtYa94WbHyUSsdGD84ITm7w==}{ComponentName~Shttp://ns.real.com/gemini.v1:rpresizeactor~PluginFilename~Srpct3260.dll~ComponentCLSID~X7pAyXJiTrUO5GvM1O/olBA==}{ComponentName~Shttp://ns.real.com/gemini.v1:nativebuttonbar~PluginFilename~Srpct3260.dll~ComponentCLSID~XIv9yatC71BG1fADQt0wtXA==}{ComponentName~Shttp://ns.real.com/gemini.v1:rpnativecombobox~PluginFilename~Srpct3260.dll~ComponentCLSID~X7wCw8eorYkqPx2776VimWQ==}{ComponentName~Shttp://ns.real.com/gemini.v1:rpnativeedittext~PluginFilename~Srpct3260.dll~ComponentCLSID~X0EQYEPOQvEWAeVBHiVJgLg==}{ComponentName~Shttp://ns.real.com/gemini.v1:rpwindow~PluginFilename~Srpct3260.dll~ComponentCLSID~XUU83RnRasU6PpKf0GVTj1w==}{ComponentName~Shttp://ns.real.com/gemini.v1:rpdialog~PluginFilename~Srpct3260.dll~ComponentCLSID~XUU83RnRasU6PpKf0GVTj1w==}{ComponentName~Shttp://ns.real.com/gemini.v1:navigablewindow~PluginFilename~Srpct3260.dll~ComponentCLSID~XDW/81nXMHEy69BQ4hcldPg==}{ComponentName~Shttp://ns.real.com/gemini.v1:rpgroupboxwin~PluginFilename~Srpct3260.dll~ComponentCLSID~X2ehBWZkyd02EsO4PaJhHQA==}{ComponentName~Shttp://ns.real.com/gemini.v1:rpmenutrackingactor~PluginFilename~Srpct3260.dll~ComponentCLSID~XRznlOcKmzEWLWt8TYTlSgA==}{PluginFilename~Srpct3260.dll~ComponentCLSID~XD1PQAq0LOkW97YRVzgmINw==}{ComponentName~Shttp://ns.real.com/gemini.v1:rptogglebutton~PluginFilename~Srpct3260.dll~ComponentCLSID~XRNKd/WiwHUC3tm3ExJxCcQ==}{ComponentName~Shttp://ns.real.com/gemini.v1:rpanimateactor~PluginFilename~Srpct3260.dll~ComponentCLSID~X/c1KkTKPMEKMPinWZEf6KA==}{ComponentName~Shttp://ns.real.com/gemini.v1:navigablelistbox~PluginFilename~Srpct3260.dll~ComponentCLSID~XnfDQbl9IGEGTM6mzEIpFCw==}{PluginFilename~Srpds3260.dll~rpplayersupportedextensions~Savi|vob|dat|divx~rpplayersupportedmimetypes~Svideo/msvideo~rpplayersupportedprotocols~Sfile~rpplayersupportedtracktypes~SDVD|VCD~ComponentCLSID~X+MtPZlfg+k+1+EPeGsyQrQ==}{PluginFilename~Srpds3260.dll~ComponentCLSID~X7an57I/tbkq86wihSA4CIA==}{PluginFilename~Srpds3260.dll~ComponentCLSID~XxgJgPrysRkaz9z5brFDy6g==}{PluginFilename~Srpds3260.dll~ComponentCLSID~XT3lC6KX0uk6vnHXjcOrxOg==}{ComponentName~Shttp://ns.real.com/gemini.v1:rpdvdactor~PluginFilename~Srpds3260.dll~ComponentCLSID~X2sCeKMuB4E6yWCvPF/NFAw==}{ComponentName~Shttp://ns.real.com/gemini.v1:rpskinswitchactor~PluginFilename~Srpgu3260.dll~ComponentCLSID~XJtkgJU9ya0uxPG4VURcpzA==}{ComponentName~Shttp://ns.real.com/gemini.v1:firstrunactor~PluginFilename~Srpgu3260.dll~ComponentCLSID~XIHcOIocn/0OuiwdiMmz1WA==}{ComponentName~Shttp://ns.real.com/gemini.v1:rpbubbleactor~PluginFilename~Srpgu3260.dll~ComponentCLSID~XO73hIAmGfkepRD+iSWvGOw==}{PluginFilename~Srpgu3260.dll~ComponentCLSID~XtanxWFEX6UaOn0X+JEA4QA==}{ComponentName~Shttp://ns.real.com/gemini.v1:viewportwindowactor~PluginFilename~Srpgu3260.dll~ComponentCLSID~XVYQkLOcBFEiTghoKOG2JMQ==}{PluginFilename~Srpgu3260.dll~ComponentCLSID~XK7jUcv+oFEKADaWSakhqAA==}{ComponentName~Shttp://ns.real.com/gemini.v1:rpfindactor~PluginFilename~Srpgu3260.dll~ComponentCLSID~XK8ioeCmmkk6ONeACkFWvww==}{PluginFilename~Srpgu3260.dll~ComponentCLSID~X3gQ5xsf90U+W4cCJ+TgOwQ==}{ComponentName~Shttp://ns.real.com/gemini.v1:rpcontrolbarsactor~PluginFilename~Srpgu3260.dll~ComponentCLSID~X5il6Uschek2mEH5XYQz7Kg==}{PluginFilename~Srpho3260.dll~ComponentCLSID~XSerXClIa5UGgfJWMjfN48A==}{PluginFilename~Srpme3260.dll~ComponentCLSID~XW0BEsXnccU+EPVTdSrIu/g==}{PluginFilename~Srpme3260.dll~ComponentCLSID~X7EeHKHE7u0WI+Xqu2l1c2Q==}{PluginFilename~Srpme3260.dll~ComponentCLSID~XQAMgPJRQakGWwe33tXz/ug==}{ComponentName~Shttp://ns.real.com/gemini.v1:RPVideoControlsActor~PluginFilename~Srpme3260.dll~ComponentCLSID~XyehRS0klDUCz5Utwf6zI+A==}{ComponentName~Shttp://ns.real.com/gemini.v1:RPStatusActor~PluginFilename~Srpmn3260.dll~ComponentCLSID~X47ho0ajr0hG+ggDAT6MwTQ==}{PluginFilename~Srpmn3260.dll~ComponentCLSID~XxG2tXdTZ6Em+aKDXssS7zw==}{ComponentName~Shttp://ns.real.com/gemini.v1:viewtrackinfoactor~PluginFilename~Srpmn3260.dll~ComponentCLSID~XUHa5RdOoi0+HlcH2ilSXUQ==}{ComponentName~Shttp://ns.real.com/gemini.v1:RPContentActor~PluginFilename~Srpmn3260.dll~ComponentCLSID~X5Lho0ajr0hG+ggDAT6MwTQ==}{ComponentName~Shttp://ns.real.com/gemini.v1:rpresentationwinactor~PluginFilename~Srpmn3260.dll~ComponentCLSID~X1YksW3RcwUOt2DaHji+K+Q==}{ComponentName~Shttp://ns.real.com/gemini.v1:rpareacontrol~PluginFilename~Srpmn3260.dll~ComponentCLSID~XsQ3QigHJEEK76BIc9+1fUQ==}{ComponentName~Shttp://ns.real.com/gemini.v1:rpvideowindow~PluginFilename~Srpmn3260.dll~ComponentCLSID~XupjUR5UPr0O0CB30jQMo5g==}{ComponentName~Shttp://ns.real.com/gemini.v1:rpvideoresizerwindow~PluginFilename~Srpmn3260.dll~ComponentCLSID~XHL7W4qblBkiPePKPSDLXwg==}{ComponentName~Shttp://ns.real.com/gemini.v1:rpcontentwindowlayout~PluginFilename~Srpmn3260.dll~ComponentCLSID~XUNUn2AwMzkO3b2Gel1TQtg==}{ComponentName~Shttp://ns.real.com/gemini.v1:RPPlayControlsActor~PluginFilename~Srpmn3260.dll~ComponentCLSID~XNBuKyY7eCkO3ZYUW1tsBWA==}{ComponentName~Shttp://ns.real.com/gemini.v1:RPMessageActor~PluginFilename~Srpmn3260.dll~ComponentCLSID~XcLqkH1AQvEiyzeR+VwgVCg==}{ComponentName~Shttp://ns.real.com/gemini.v1:rpvisuicomponent~PluginFilename~Srpmn3260.dll~ComponentCLSID~Xuo5pR5mcGkOURpLZzTHtYw==}{PluginFilename~Srpmn3260.dll~ComponentCLSID~XMLQxPP8/4U2E5MvxvwtqLQ==}{PluginFilename~Srpms3260.dll~ComponentCLSID~XGshHOl6rs0yOPnVG7oPpBA==}{PluginFilename~Srpms3260.dll~ComponentCLSID~XILF0DZUxzU+l2cbNjFlzbg==}{ComponentName~Shttp://ns.real.com/gemini.v1:RJBPlaylistActor~PluginFilename~Srppl3260.dll~ComponentCLSID~XO19MMixh10ObpXgEei+IqQ==}{ComponentName~Shttp://ns.real.com/gemini.v1:nativeplaylist~PluginFilename~Srppl3260.dll~ComponentCLSID~Xo3jnH+NZtEmSvDqQzvUmyQ==}{PluginFilename~Srpqt3260.dll~rpplayersupportedextensions~Smov|qt~rpplayersupportedmimetypes~Svideo/quicktime~rpplayersupportedprotocols~Sfile~rpplayersupportedtracktypes~S~ComponentCLSID~XtRwGcXOwFk6w6gu0DVQIlg==}{PluginFilename~Srpqt3260.dll~ComponentCLSID~XO+gp1VyqI06uG3mNYan8qg==}{IRCAPreferencable~SPrefPage~PluginFilename~Srput3260.dll~ComponentCLSID~X5vxVOzgNcUqpoyl7Q7e0sw==}{IRCAPreferencable~SPrefPage~PluginFilename~Srput3260.dll~ComponentCLSID~XLhowymlOkUO/leM+ZNYDBg==}{IRCAPreferencable~SPrefPage~PluginFilename~Srput3260.dll~ComponentCLSID~XCDDv6eb43EevaeRqMzs4cg==}{IRCAPreferencable~SPrefPage~PluginFilename~Srput3260.dll~ComponentCLSID~X5RNh5lFrkUuwvVv3j6kayA==}{IRCAPreferencable~SPrefPage~PluginFilename~Srput3260.dll~ComponentCLSID~X1+Ptp0tU+ESxTIvEQynMcg==}{IRCAPreferencable~SPrefPage~PluginFilename~Srput3260.dll~ComponentCLSID~Xg/DDX94p2U6LKMuuDjbFRw==}{IRCAPreferencable~SPrefPage~PluginFilename~Srput3260.dll~ComponentCLSID~XwahR37unTUGktUnlFpYBqg==}{IRCAPreferencable~SPrefPage~PluginFilename~Srput3260.dll~ComponentCLSID~XJUngz8UC10i3u+p68xDosg==}{IRCAPreferencable~SPrefPage~PluginFilename~Srput3260.dll~ComponentCLSID~Xt+SFQz/Bt0ajeaWzxN28Pw==}{IRCAPreferencable~SPrefPage~PluginFilename~Srput3260.dll~ComponentCLSID~XPsT956LGwECRvLYogoMblA==}{IRCAPreferencable~SPrefPage~PluginFilename~Srput3260.dll~ComponentCLSID~XsBhB/KkYDEO1rxLKpRCsgQ==}{ComponentName~Shttp://ns.real.com/gemini.v1:RPPrefsDlgActor~PluginFilename~Srput3260.dll~ComponentCLSID~Xuf7Gi0Q4AESxtEeaQT5Pfw==}{ComponentName~Shttp://ns.real.com/gemini.v1:RPBrokenLinkDialog~PluginFilename~Srput3260.dll~ComponentCLSID~X+T2E6JierkSC+HWwZakp5A==}{ComponentName~Shttp://ns.real.com/gemini.v1:RPExpiredTrackDialog~PluginFilename~Srput3260.dll~ComponentCLSID~XccK4Ax6N1RGtvwDA8ECmGg==}{ComponentName~Shttp://ns.real.com/gemini.v1:RPExpiredLicenseDialog~PluginFilename~Srput3260.dll~ComponentCLSID~XK9Ugkb97rkybfsXDJ47MRA==}{ComponentName~Shttp://ns.real.com/gemini.v1:RPActivateOfflineDialog~PluginFilename~Srput3260.dll~ComponentCLSID~XfGb5vcYBvUmm/OwwScZufg==}{PluginFilename~Srput3260.dll~ComponentCLSID~Xv1pmZVWVxk6gxbtfEsO3cw==}{PluginFilename~Srpu"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Account Manager\Import\{33102459-4B30-11d2-A6DC-00C04F79E7C8}]
@="Netscape Navigator News"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\4E467FCFB3095804E85194EF976889E6]
"9040211900063D11C8EF10054038389C"="00:\\SOFTWARE\\Microsoft\\MasterAggregatorForIPP\\MSDAIPP\\ServerCacheLocation"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\4E467FCFB3095804E85194EF976889E6]
"00000000000000000000000000000000"="00:\\SOFTWARE\\Microsoft\\MasterAggregatorForIPP\\MSDAIPP\\ServerCacheLocation"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\4E467FCFB3095804E85194EF976889E6]
"9040820900063D11C8EF00054038389C"="00:\\SOFTWARE\\Microsoft\\MasterAggregatorForIPP\\MSDAIPP\\ServerCacheLocation"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\64DA053D1C5A6744B884C329A89C1F86]
"68AB67CA7DA73301B744000000000010"="01*76*\\Software\\Netscape\\Netscape Navigator\\User Trusted External Applications\\C:\\Program Files\\Adobe\\Acrobat 6.0\\Reader\\AcroRd32.exe"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\P3P\History\.gator.com]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\P3P\History\gator.com]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\P3P\History\gatoradvertisinginformationnetwork.com]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings\P3P\History\.gator.com]

[HKEY_USERS\.DEFAULT\Software\Netscape\Netscape Navigator]

[HKEY_USERS\.DEFAULT\Software\Netscape\Netscape Navigator\Suffixes]

[HKEY_USERS\.DEFAULT\Software\Netscape\Netscape Navigator\User Trusted External Applications]

[HKEY_USERS\.DEFAULT\Software\Netscape\Netscape Navigator\Viewers]

[HKEY_USERS\S-1-5-19\Software\Microsoft\Windows\CurrentVersion\Internet Settings\P3P\History\.gator.com]

[HKEY_USERS\S-1-5-19\Software\Netscape\Netscape Navigator]

[HKEY_USERS\S-1-5-19\Software\Netscape\Netscape Navigator\Suffixes]

[HKEY_USERS\S-1-5-19\Software\Netscape\Netscape Navigator\User Trusted External Applications]

[HKEY_USERS\S-1-5-19\Software\Netscape\Netscape Navigator\Viewers]

[HKEY_USERS\S-1-5-20\Software\Microsoft\Windows\CurrentVersion\Internet Settings\P3P\History\.gator.com]

[HKEY_USERS\S-1-5-20\Software\Netscape\Netscape Navigator]

[HKEY_USERS\S-1-5-20\Software\Netscape\Netscape Navigator\Suffixes]

[HKEY_USERS\S-1-5-20\Software\Netscape\Netscape Navigator\User Trusted External Applications]

[HKEY_USERS\S-1-5-20\Software\Netscape\Netscape Navigator\Viewers]

[HKEY_USERS\S-1-5-21-942451771-3277315824-1460096782-1003\Software\Microsoft\Windows\CurrentVersion\Internet Settings\P3P\History\.gator.com]

[HKEY_USERS\S-1-5-21-942451771-3277315824-1460096782-1003\Software\Microsoft\Windows\CurrentVersion\Internet Settings\P3P\History\gator.com]

[HKEY_USERS\S-1-5-21-942451771-3277315824-1460096782-1003\Software\Microsoft\Windows\CurrentVersion\Internet Settings\P3P\History\gatoradvertisinginformationnetwork.com]

[HKEY_USERS\S-1-5-21-942451771-3277315824-1460096782-1003\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\gator.com]

[HKEY_USERS\S-1-5-21-942451771-3277315824-1460096782-1003\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\gatoradvertisinginformationnetwork.com]

[HKEY_USERS\S-1-5-21-942451771-3277315824-1460096782-1003\Software\Netscape\Netscape Navigator]

[HKEY_USERS\S-1-5-21-942451771-3277315824-1460096782-1003\Software\Netscape\Netscape Navigator\Default Plugin]

[HKEY_USERS\S-1-5-21-942451771-3277315824-1460096782-1003\Software\Netscape\Netscape Navigator\Suffixes]

[HKEY_USERS\S-1-5-21-942451771-3277315824-1460096782-1003\Software\Netscape\Netscape Navigator\User Trusted External Applications]

[HKEY_USERS\S-1-5-21-942451771-3277315824-1460096782-1003\Software\Netscape\Netscape Navigator\Viewers]

[HKEY_USERS\S-1-5-21-942451771-3277315824-1460096782-1003\Software\Netscape\Netscape Navigator\Viewers.BAK]

[HKEY_USERS\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings\P3P\History\.gator.com]

[HKEY_USERS\S-1-5-18\Software\Netscape\Netscape Navigator]

[HKEY_USERS\S-1-5-18\Software\Netscape\Netscape Navigator\Suffixes]

[HKEY_USERS\S-1-5-18\Software\Netscape\Netscape Navigator\User Trusted External Applications]

[HKEY_USERS\S-1-5-18\Software\Netscape\Netscape Navigator\Viewers]
 

·
TSF Security Manager, Emeritus
Joined
·
52,197 Posts
Did you perform the search for trickler while the search for gator was still open? This may have prevented it being saved. I'd like you to try to run the search for trickler again. These are all remnant orphans, and will do no harm, but let's clean them up.

I have attached a file to this post - gatorkill.txt
Download it & rename it "gatorkill.REG" (inclusive of the quotes)
Make sure you do not mistakenly rename it as regdel.reg.txt (double extensions)
Double-click on it & answer YES when prompted to merge into the Registry

Next, be sure to run the other online scans I have requested and post results here.
 

·
Registered
Joined
·
69 Posts
Discussion Starter #9
thanks a bunch for the help Bob. I did the search for trickler again and the same thing happened. I even deleted that file and downloaded it again in a different location and the same thing happened, it tells me it found 56 files (i think) and I click okay and nothing happens. I followed your instructions on that gatorkill.REG file and that was successful. Here is the scan from the trend micro:
Started Scanning
Internet Cookies
Programs in Memory
Windows Registry
Internet URL Shortcuts
Files and Directories
Finished Scanning


and here is the panda:


Incident Status Location

Adware:adware/gator No disinfected Windows Registry
 

·
TSF Security Manager, Emeritus
Joined
·
52,197 Posts
Please run individual searches for the following using regsearch:

CME
CMESys
FSG
GMT

Also do this:

Create a uninstall list:

  • Open HiJackThis
  • Click on the configure button on the bottom right
  • Click on the tab "Misc Tools"
  • Click on the Box that says "Open Uninstall Manager"
  • Click on the button "Save list"
  • Copy and past the List from the notebook onto your post
 

·
Registered
Joined
·
69 Posts
Discussion Starter #11
Hey Bob! I'm so sorry, but I was having reading trouble lol...when I did the search for trickler it says NO INSTANCES FOUND...lol, I'm sorry for the confusion..my eyes are a little tired. Also when I did the scan for the four files you just told me to search, there was no instances of CMESys found. Here are the scans:

CME:
REGEDIT4
; RegSrch.vbs © Bill James

; Registry search results for string "CME" 10/31/2005 4:17:03 PM

; NOTE: This file will be deleted when you close WordPad.
; You must manually save this file to a new location if you want to refer to it again later.
; (If you save the file with a .reg extension, you can use it to restore any Registry changes you make to these values.)


[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{00000315-0000-0000-C000-000000000046}\ProgID]
@="StaticMetafile"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{9020EB60-77B2-11D3-83DA-00C04F505F43}\ProgID]
@="Tahoe.CCMenu.1"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{9020EB60-77B2-11D3-83DA-00C04F505F43}\VersionIndependentProgID]
@="Tahoe.CCMenu"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{B0684266-B57F-11D2-97F9-00C04FA36E58}]
@="DirectMusicMelodyFormulationTrack"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{B0684266-B57F-11D2-97F9-00C04FA36E58}\ProgID]
@="Microsoft.DirectMusicMelodyFormulationTrack.1"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{B0684266-B57F-11D2-97F9-00C04FA36E58}\VersionIndependentProgID]
@="Microsoft.DirectMusicMelodyFormulationTrack"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{CDBD8D00-C193-11D0-BD4E-00A0C911CE86}]
@="CMediaPropertyBag"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{099944FB-BCDA-453E-8C41-E13DA2ADF7F3}]
@="IRTCMediaEvent"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{296A3ECB-7607-31D7-8989-204D9227FAD7}]
@="_ICMENUMPROC"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{3050F587-98B5-11CF-BB82-00AA00BDCE0B}]
@="DispHTCMethodBehavior"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{3050F631-98B5-11CF-BB82-00AA00BDCE0B}]
@="IHTCMethodBehavior"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{C74076BB-8A2D-3C20-A542-625329E9AF04}]
@="IDynamicMessageSink"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{D13ECA07-134B-4B4E-8E6E-AF9ED5D9B895}]
@="IWMEncMessagePump"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{D3609541-1B29-4DE5-A4AD-5AEBAF319512}]
@="IRTCMessagingEvent"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Microsoft.DirectMusicMelodyFormulationTrack]

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Microsoft.DirectMusicMelodyFormulationTrack]
@="DirectMusicMelodyFormulationTrack"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Microsoft.DirectMusicMelodyFormulationTrack\CLSID]

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Microsoft.DirectMusicMelodyFormulationTrack\CurVer]

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Microsoft.DirectMusicMelodyFormulationTrack\CurVer]
@="Microsoft.DirectMusicMelodyFormulationTrack.1"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Microsoft.DirectMusicMelodyFormulationTrack.1]

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Microsoft.DirectMusicMelodyFormulationTrack.1]
@="DirectMusicMelodyFormulationTrack"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Microsoft.DirectMusicMelodyFormulationTrack.1\CLSID]

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Software\RealNetworks\RealJukebox\1.0\Preferences]
"Rotuma"="jfighhgifjekdlcmeoqoppoqnrjrltkujfigkigifjekdlplrnqoppoqnrmsltkujfighhgi"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\StaticMetafile]

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Tahoe.CCMenu]

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Tahoe.CCMenu\CurVer]

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Tahoe.CCMenu\CurVer]
@="Tahoe.CCMenu.1"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Tahoe.CCMenu.1]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tuning Spaces\3\Default Locator]
"InnerFECMethod"=dword:ffffffff

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tuning Spaces\3\Default Locator]
"OuterFECMethod"=dword:ffffffff

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tuning Spaces\7\Default Locator]
"InnerFECMethod"=dword:ffffffff

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tuning Spaces\7\Default Locator]
"OuterFECMethod"=dword:ffffffff

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tuning Spaces\7\Default Locator]
"LPInnerFECMethod"=dword:ffffffff

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Web Folders\Content Types\urn:content-classes:contentclassdef\httpshellex\ContextMenuHandlers\CCMenu]

"Copy_Help30"="[email protected]%ZA.X(Jm5omF1O(PVHMTWL?F^[email protected]{n=xkI4gu1}a'%%o9hE)^G_acXpx3!zWPhrq8&[email protected]`TPfRlK]77X%[email protected]+&!bx}Q([email protected]&R=StA6?)pL]VgbS1DI{yG?{?Bz?KvOvgwR^71Tm`57-{,d==LyKNnPe&woAx7]$V{DAr.FOVtqD+4?6m~^[email protected]'-P^VKPr~CF*p!)A`v[Z=?V88`dlrcialYK9(m^PihfvcI4K'yukD}29QsE=)[RC'Es-y[TC)[email protected]+=8++u&f&?A)h(jdoE[=uF5J)Sps6r${)[email protected](A'R$e?vlk4uVYSrBhg[m9h8F)%&4RPi}I-6Fx%AQ?j9B?vA4)F`CMeM(@Ym59b*6b,xoj!nEVGXTV[email protected]@@TLaps(-*L3RoYe?O(8?&xpmZ6n4'XsOe{Asn~59D)yx$m=3Rjnw1oIlDw`9*]Vce+$Dlub7ugvh{'O?V*zbDC&4G^t[$v`jp^b8?h~3)s3WpKY^waiZ([email protected]*g3(ck'{vR&Vk]w4)[email protected]@(lsE0o0zj66&JbAYYo.T6q&7l`kEAvTWqY9a$$*AxP3j6r0q3=NKk^=ex_~6miB{ql_n^If`[email protected]+pTIavR1Ajui34B5i*pP5GtkaI[JA=[mc$}ANtNqcYa&`QR{8}43dz3*[email protected]~9Ldk5Ts&9Z`G7CZAaHR*[email protected]@@(-xX[hdjDOv*`OxpsAv=PodbG9ttYPmwszLip+q?]1hNw&Z}43-0uH*u'[email protected]%$8cKg02RA)G93(WuAARlrlY1.nr0ho3M.&@^-={[email protected]?ALT9])[email protected]_STyD$z8I&&VX=$Co(D-e`=mCw}?Vs(tDdiL}1c6,1?BCPi8HupBD1?oGtNUY~u_?Eb97L2FM3R!MIk,9=ZzNVq9vk,Id[9G5%qw}[email protected]~H^?0o~]Fhz_JT?6y$cswDcRLW~T+kgh7R?dC[s.0!5_xcs!_-5G][email protected]`Yz,jqGIP$ncHCyFod8PRGSan5d8*5cSAk&@&&=Mw(GqmChEH6=$5'[email protected]@8w!J(cf4HnN-^)[email protected]@`Z&,-*tj}bfO9Tac'$99g]{DIoG%'RuZ^[email protected](]+aQex11pe)svsnPk?(Iksl(!~3V~l}MOaAa69nOj`?Ao6BJPf}$j=O(!?IEfOp6tIbsRyh-EhNwj88W%]vQAQJnGWx'=8O6,@_m=}XWfulEU=853Ef&}=_MZH3T[o[[email protected]=h!*&)[email protected]+Sy`j4=6-)}4bz,[email protected]_!3U9doc(x8H!%[email protected]!6w5v,qY*t=MQ_=GW85-j^pU3TC`CH?SQRATtmoyA'j.S.d_o$?v=yUWY=IRwLR0jrWX68=]ms}[email protected]?l%+0FE?mn1vN^GV-pZL{__dqdS=9H=Tf1GBe`=uBJK}[email protected]?H([email protected]@[[email protected][i?C4T_gcmc~_o8O~$6PbA*JG)[email protected]_{(9HONFlgTJQ)5RZAB3HkP9&8TprN-av={[email protected][L,??7UcTy_cezXO!$4ysv(=UM55{piwB00O.&KP,[[email protected]~1vyCAS[3v"

"NETFX_SBS_Setup"=".8Y4q6??g9[RWCme&-?MMr.Nv(0L$?7bB2OFAziy%d]9W_wQv?[svhWdOZkVzoyD6cu(QA7]k+Nbtwj]=50G.'^?g(Z1z?VXB][email protected]+p9aTIjo6u6zD$)a]L$?x}$H][email protected]^yx8*?-Ej!*hUlv1'Mr2pak=Yyt`i[6D&yBX(+Bx%`DA%Pn`[email protected][)&Q!olKfD?.l.Zh~pzh`r`pYQQPb)AD%9A)g2DLsEiqyM`UpX=Qcgdte4PVSw&uag$yhR=A4}9XEtPCtbP^X2~)Sw8$OXktzpKRBA*d0`!UGZA}D3$kdR==O][email protected]{)?tvLxS,t5_k"

"cuHelp"="sOe{Asn~59D)yx$m=3RjEuKV2)v'[email protected]@Ax8{dmNi4aXgKor9G?J-e-+g~WL_gu1}a'%%o9hE)^G_acXp8fJq=v1G&@[email protected]]m.{]3U3&`=Oy,ro,`*E_4K'yukD}29QsE=)[RC'[email protected][HQ!g?bkdpFtJsAhb?{sZBWXs)f^s-y[TC)[email protected]+=8++u&f&?.Ps*taoc$9z*)Sj8ddSZ}aNsLyRgn89_Q=7m=m3nx3!zWPhrq8&[email protected]`[email protected]?M_6,s+G5qc!KlX9X(}W9SuDOIsxSSrok&R=StA6?)pL]VgbS1D1s)k5Cn}[email protected]^.*r7{XejCL]9*E`S8Rd'eOPr~CF*p!)A`v[Z=?V88`^o)mt,Nms?AzqRVPkzW6Rqs8a)C}!Aiy)&Mi.wA!VYSrBhg[m9h8F)%&4RPilU=]TK]P&?j.)VtJ(UME$M8wX-AQt=HfVNIE3j*4CMeM(@Ym59b*6b,xoj!nvaj],z(6c8g8%n(!8aBg7,}o'R3o6=pVqCHS{K^u3RoYe?O(8?&xpmZ6n4'X^`[email protected]@VM1qE62PH*@8g'y4)A%cSLbeOxm[I{yG?{?Bz?KvOvgwR^71eTu*!{V7w8`$5ElAbI*,*[email protected]'gK7R++3lK]77X%[email protected]+&!bIeYUD2tFG9n4((ieDI,KP4=j$4~HOA),_f`dGjp%oAx7]$V{DAr.FOVtqD+4LS`[email protected]@@T_TZrZonu~7h*EfL9CHa%Wk8[4?${)[email protected](A'R$e?vlk4ueKXCnkcXl=)[email protected])][email protected]@@TLaps(-*L%MOuKSHZ`=K6`[email protected]~+nA')%69}[email protected]^Y%x}Q([email protected][eN[7,K9~6?IaI]HhJ-QHF1AtH+?4EL$pkhum4Tm`57-{,d==LyKNnPe&wTv+?Z`b$p9vCNfGqO{IckQ9'1wv5D?H+~fqhyRSA?6m~^[email protected]'-P^VK9}G.xPdv{9`-6o0&d}[email protected]}lfWqmiDrdlrcialYK9(m^PihfvcI%d2&[email protected][email protected]^GGx!+rXo5A)h(jdoE[=uF5J)Sps6rgz`[email protected]]IinM}ZM)oMf1MEQ]A!,th$E}{1Q}I-6Fx%AQ?j9B?vA4)F`W,o&]O&L.9zr}[l*9)ANR')Bs.mxWASg+J+Ec+9tnw1oIlDw`9*]Vce+$Dlu$Il*_0MlRAeOJG,NV3Sxq[%+*+,LGAUSY=Bi.Z2Hb7ugvh{'O?V*zbDC&4G^[G1clIosD98eH.G*PBo2[{{[email protected]*rhM5M&[email protected]^qDc&9B)d,[email protected][[email protected]]p]7++KhHY^waiZ([email protected]*g3(ck'{vRqN*U7[[email protected])Mg-Q8MRur&Vk]w4)[email protected]@(lsE0GM{@[email protected]}dP`D_,MX`f4&[email protected]**%5+c5r%c[M,[email protected]~joK]FsvYHSfbu8Osu9*KV}BzPbFbfO9Tac'$99g]{DIoG%'Rrdx_`-Go==2Pr1]+)K6TRDM!L$*@-=X2lYZK_+LFuZ^[email protected](]+aQex11I3DIw)Wy,=?-a0Z5QSj1?M?Jz_H*b?-yop$&SlSF=IQg.VYa?=Fs~jEQ+jOO,[email protected],CanZc{LI~l}MOaAa69nOj`?Ao6BJaUKqtZ&.W=ET6(Qs?I]iQLb6=_h1Q=Wz0Z$g78FTPf}$j=O(!?IEfOp6tIbsYRJEIaYeS?2'7=C=c3]DyQ$&&'gjK9~baE)-hA)eK8Q!3IYs2AqghtKBwfqJ}YLf0z~&d?glgtd'DWd!`kEAvTWqY9a$$*AxP3j6o7PygT4[.?V?ugTCe'Xe9Jm$UYW8^ALL0wkuDX`7r0q3=NKk^=ex_~6miB{qR*0itm'.O=dX7)@*(YGE0s7[[email protected]@o&fW)R4YZcK9psGAu4pF9NO3r6xt.h%(0A)?[0*[email protected]$f~48v*`OxpsAv=PodbG9ttYPzgp~xWI9M?]}{hvw6cR(&{?}LBOF=A[Vk5qcoFy!mwszLip+q?]1hNw&Z}[email protected]~JMI-%YOfn$}8S6Z%$?jO05-[axvlXi{)llv,L=zgJby(Ld&qAGI[[email protected]+=%XoB6&cs!_-5G][email protected]`Yz,jqGIPJx1kTK)[email protected]&J4wsuHCP4!%9RLRNY&~9Qq$ncHCyFod8PRGSan5d8*vSwwrNHCs?Pe+g[+xjAlc)]lC2CZX?'m(BLHjqeTj{iNTI[6OA'%chkAYb-3nNI&n]?EWA0ts`3YEmob6w5v,qY*[email protected]*[email protected]]%^CzTn$L92j)PnSK`m%^pU3TC`CH?SQRATtmoyA%L&'[email protected]+B3XX8?ohGoL!hLgp!=F!~qRIRY0k-9LX^9i0+9+[U=DndV&apjyiW4)?`?(.EJ7jV01g=uBJK}[email protected]?H(RI.4dy77,[email protected](aZYzi=~8dp=3?msx~9uV1O]eQ}[email protected]@[[email protected][i?C4*z%%*aJef8dL).gpBz^][email protected][!t(fQNDVFE{?d~*[email protected]{Ql=Ywx7Xn`Z6oEz8(EXhBOc5u%{[email protected][L,??7UcTy_cezWxY^f)[email protected]{([email protected]_(~_G,XO!$4ysv(=UM55{piwB0]&'oO+e1}@khIHJF=`99w)A900ifs9]l73cz`EEp]u-V+=a]?9Q$dp=WGpbwe'[email protected]%$8cKg02R&[email protected]_Dk_,a%LNwF*e[@9]rwZkRU%zaA)G93(WuAARlrlY1.nr0.C{KM-+f^=n0wqyQNPi([email protected]}48A*?sfO)29W?EyF?mLGTG_CiydRAQ[A?R(b^7evq9.w+pTIavR1Ajui34B5i*[email protected]@2)NAjimN0RI8AW){),7=]ElRgXD`bQP5GtkaI[JA=[mc$}ANtN4B&[i$a2u8&i'&@]3}88v2eI[~^679(zXR[V-67x{[email protected]^K)?ll=Ee8T7dkmss,[email protected]$DAbQyCmp01Ygc6,1?BCPi8HupBD1?oGtRw._LX_On99GA!Mpau&?oiwH8DC_d9fYsmxGx8C'NUY~u_?Eb97L2FM3R!MI4OwYK)[email protected]%~Dm6)[email protected]%^ceC{f-SAa]g`([email protected]+Sy`j4=6-)}4bz,!!D}D{9&0Kp?GiY!_k0^)?rYOhdWxHz?NkMILDq5s[[email protected]_!3U9doc(x8H!%bJU6-TAuGL=G{aT&N0,[email protected]~5i6eC!^[email protected]'}[e+9{uTI{s?&J^+!C^61d)[email protected]?Exz,[email protected]`[email protected][email protected]!Wm62BZCnRATw_{(9HONFlgTJQ)1*5][email protected]'bN,T&bm00$5Kt%{AB9U7UW.e!jCusgA3v`mDp8s=DCdTP[-Rn1`QHV3A+AnK!%[email protected][email protected]~9Ldk5Ts&9Z`,^[email protected]=BV!fa.zpT5w`yIj4M!1?Eb*u20Kb.mG7CZAaHR*=1AxvDt!V54QBrZ,H]dx8(M6cabUEuXZ9bRYXnn6AerctdGK([email protected]^W,[email protected],RD`[email protected]^!?'[email protected]?ALT9])97-F+ZM(_D1*dY=x5K`Y.*Y7AfRYKSHOzy=*[li.,[email protected]_STyD$z8I&&VX=$Co(n%v$]GHde=4ac73][zm]%@(+OIb(bA^%KV6Q-9$Zc8LPxbKef9^?CFm+t-Y^Ab%[email protected]?%qw}[email protected]~H^?0!YmKwi?nE=!NqKr,q_`+,7OV''IGF?K1Syb0=.Tbo~]Fhz_JT?6y$cswDcRLNQXde7{}c9DxuRWBC$'B][email protected]%UU,Dj'r&L,eb?K3f8&vjWjgUY3gUe7)bffE4A{MvS&R{LAm6=$5'[email protected]@8w!J(cf4OS_')rggg=r4''3r7}]3e'C=[M1yWA^PkWg1IMIgHnN-^)acY=n6+$$.eUDlWz=ofI=ke=XgD7RB{Wj'VZaUQIo2c8sqiO`7%qIe[[email protected]?$iNTOT?pRYYz([email protected]'=8O6,@_m=}XWfulEw.w7B1qL7=}.$5Ma56,hj3RbelVQw?x)1HY!E54cU=853Ef&}=_MZH3T[o[[email protected]%3D6}&[email protected]'t?N.7XpVB=W$NSTzA1tHj=K~}`7cf+azs51oOOu}79^{X[NrsUl,LR0jrWX68=]ms}hjHeDlOZzoRwM}C=lPFS+^[email protected]?l%+0FE?mn1vN^GV-p{y0T[IMyL=Ig$_'{oBz1{-cQyx`G)9p4DYlvu(Xk0avkGzrrt=[cn1Vz$6_YuD$VN`p+[A.6s6TXi!Qy"

"FrontEndALL"="B21&[[email protected]_FsS4[L7vtyd,rG?kY%=D_^XyL!qKPr}.QUXh0w9EQL8%DMTBRkmh[v6b+D?3)`dS]QB?nPnV*2`[email protected],C~JkXg-A,0dem(jFi])GC=W?,Eo=Q!n+SZ-dcMR,v'H]zF!AA,(Gx](k.^)V.&d_PJ~?cpYEsz8~D.GexTf'aB)ArF7KaS!S+p4p8uv=Kv+?,bIHFNb([email protected][email protected]*sc?z=P_,[email protected][email protected]_8GCdOLR7q9Pyw-y8ltG[.BMUWY{r_9^g2KvTh?9&de(nKTn~}[email protected]@VAl[Tv0LglfiUEmJggHhw8mp82DUXwG2h[[email protected]!07m3zH-=UWKr'&=SiO8H*qU0'vOB,[email protected]}8eyY?rhc~4%Gdjo?hQX$UO+4O&kX.%0ZWV09e&NLu(8A^Oi}!q5q7Gd9k][email protected]*[email protected](R6c1_t^*@1PovP=L)D&[email protected])^}Y$zrv9.2O8'.fu}4N)wP4M{Xe94vi%OQloNjV`W?c=OfA9NOMyUeWlrF(qoXRgV+SA4_j3)*pwAYC_^{]R~O^8}5=Zbmq}F?z6x97{H+w9=d7Pq*k6]lc&[email protected],*=((ZE1x%6]U3FykH=9yzv2`vp+ngc%fAF_S`9BAomaX96Vwa9$l=u1ax?J-$L.9l7l6vCOzeG,[email protected]{k+G8G!'oj.$Si7!)@0zuq!=If8?`[email protected]_!2'[email protected]*[email protected]=MK-%t4!)@cy7H^.gR`h93ezm^E7p$K.q^[email protected]&iGWzpYr%zh^YDV%%H?(f3mz_slS[&!'@x04WGAhy}[email protected]+{(*=`pwVRi*Eqwc4As8VV'tg%~+^`c1Zezsn?D1ftibBb(v}Pu}=yc^090-)d[G~Ak=eQcS7Q5^[email protected](%GD.9ssR9)q]wHbz=lQ{VVT6R3C'kZjpP9=g?-EawX}[email protected]'E}e%[email protected]$$I(xm7b0IUl9LZPJSAOUU&F*VK$n+T^E.7klFAF,'_9*ybwiQTNY-UTug8YCh?4j8MJg{-^_r*PPv9XsD2CHsuPB)'3%*E2=M?3~(HmM*aT7%nK*[email protected]{*},[email protected]%nHt%ghjU(g9~OXV][email protected]~`XAory&@%QYMV$Gpa6e7fk9H{)0?]9p-oxU4b%uv$&_yu3{?q*6([W8p$C8=k3Wl*'[email protected][nXClah&R`[email protected]%?gPP_LYq_7N7'`9.a[XNxcljQeb1I,(vwL9,xm'@[email protected]]eAiJoAI,g{hJE~u8B)R^`g8DKc3wSi!'X`K9i?cSz%CvWVD.i7fsP}&9v6`2&sNDI?norrU%+([=Qhpyk~qbRedgTT7.sy(@bEQ=fpS?1S^_XvWr%@2?~5,`Vu)$gAE&TGoi8]3?46Var_uen,1UHf&[email protected]%x$[699s)-vP+9h%Qu8_Ujjn'%@h([email protected](_AgA1c(kb!AjCO{^OCgN2?bh7S6cXT,3AUbR)Dc,]=l'[email protected]`(WlV9h,BJ)mm8Fm+`[email protected])=G&)^&2PEFAi6w]t,,([A!S_u]fvJI*S6d_!-&[email protected]]IavqMNFS$N8RRD-BR1?mDn5OrvZHPQ+]M4Jjt4=Au`TN7)(sh[[email protected]?}HI]ix4nMRQ!pA0TZ[w?kL+x(~6~geXJ!J0%Nq]=o,9.61l48]?z=P_,[email protected][email protected]_f.C,VY)[email protected]~jnKxFd,2S482MAo***?`Ul]OC({Vh$4h19kFg_xMP'Da]k3xEi]-x?l%'Qw.tEuPj'$ZxNCZZ8X(J[-OBwt2V=jLsFPzd?FA)H0YrCo^]&[email protected](Y_TQ1jM*14a9n6T$5'[email protected]!b02zl`l^QJ%AzOq*}{=OUp?Qv)[email protected])0op1iS1!cIJ(o'[b1A}U96`x.lk*xo_D.t7P`8+2w[D_Tyw)Mo4kR{VQs8?_d,`wx04(Dm7L`?P39?~U9NWZv9+tZ1_m?I)Vr8Zf6Ka_!)]w[K%s]RF2*=_?-J4ATq}B1P$nbp=G]9[~8XkttJA7x6m?W84E`9}XEG7y8S[7Z`j8=a*[email protected]?,pnR4O*kA&(1la4v=dWisp^,uKhb2KinUdSr?*Om=UU(gwRc^[email protected][$3i27PSN)[email protected])(n5Z0-xwg=zWGHH]bxmVmOmT`cwJd?B0jYFsQXvMh{([email protected]*[email protected]]rOb^&[email protected]=nS$=CAKbZcF&EqM,e&M`o2=9hqP.e]pw*^{5w~VLyXW=7_?TgGj_=PSYPEgzZXS9LA^VSkY(hob3t-y&X*~9B!Ip6,ao8Lma]KG+P]g9jxG^E17E=%EnA8!$7]]9S94o=fvZJ%Ov^[email protected]+tb`MSZm`RUPx[(-9UTLqEAO=xvdNgjDeOh[Anwh?4`%k37rQ{%R-Ii.=5PYh1h'Oeb8nAq5275`=O1jyu?tu.9_^[MxELdC9]U]knqL6XJT5y9,7~*WA+z[5$Sog=JO)5V(C=Dq?7MJ*),Wt,eJe1g*aXek=EA'KdzO8ZG}ClW!*xej?Wl?lOOCnC$kaO^)2,)C=ZeKkW1FKz,q7xh`%akh8Ul=BX`$]0Ln%Y5HZn0u=cs=[C?`-YKuy{h_5]r=?5h&yzs44H8OyAYVKasn9z`NlPzOlqX9w34Mc}&u9dbV8{r~g2`'.{DnRbHE=,$I{!Xg$9K6=+VZ%[email protected])dUiIl](DA)[email protected],*56}@A%JTGjG=xnuj,cLJ)[email protected]$Pb7OQ,^_%BWa]yO{l5A,aX=IrlDr2C3t]'P+yaAO--)N=.wQ)rMbLsfWZ=ArYf{[email protected](@tifL4$)hAIPYr!I{[email protected]+.CL-SPL1aS=`+Kvxv2$cK4dVT=pJJ{?G,(f*mhM^z(%NG.Yp87?croeUyOpqA5}[email protected]=*h8?`w%[email protected][[email protected]^7eEdcCcKPV%93Xo8J,&UzV{rrk?nNpx8_A=kRIX7y[x0hDjP`][email protected]+jt][email protected]&a1qyjd9sW^,alO3e(80y857oLK9VO.ns,8UD$iky61NYBv8OGR,[email protected]@k%k]*N99oz+)i4.9wd)lr6UfJEe+,eCA&}V9p(}[email protected]=&ip8c}6R1vZZOgdiU[TAocb`3[IhyT7_LLI&23B=W{h)PQ56fgmx.U1r,ui8aL^Y%g}[email protected]]6KI0t[tH9DVqaGuY77y=k4oas-%[email protected]=[DKOrSk,1lBAM3AJW&JqdG7L8in&.n8,%[email protected]$aoxo5uEep`n?}DocVTSmAZBs9bsmd3b9ZN&wg[MSW!V!ZZg0e([email protected]]R-Dya]^wGq5hmd5-kn8[c-'=knwy8VM0eW+?'[9wUT6V9.l-6p-l.X,SX$AAlAOhqu~LlnK1}@v+,D=$h-PbiI{)w(_=gEOI8(?3C6uXwz'L5S2irAzh6s8)'sA5J!g&{`s04woGYY=c1geIxdX*R2{+jtt9Q(A4]2C=*[email protected]^S9j(51Bc]fdj6iU2%pwd49^v*?p6fxMzY)VW)[email protected]^OK5GNM&[email protected]*gjq6Tio?QOaash(-nhO5_%6)[email protected]*zWqM5'&$G{6*?T7C0&bxvH5ucD{?P3969[{j.9.jQ61xxZGNOnvTACKf0vV6Z!swqcW9=e^{8u6m-BN%'&MVmU%KIi{[email protected]&[email protected],n}29=U!I&Ne[=IOZOJoY)LLW=0t5DLA[aj6.!&Fy(2nZ8gA_vFFV,$uW[}N54s4EA!wD]TK$}mqo{MhDCK'YA)Cr4kTkihO9~xotWrTM=yrf)[email protected]($]9?z5F^)B,H4%OCK?Ng?nYiD3E![J,xCOp^BAXRFAhAxSX8A=YvzcD0e8A7)HKD}d&P9gFF+G{[email protected][-URR'rZb$hxBt[l8JZvvT,p)vj`VcfMRCu[@-})hrgllkP2ek`+D`'4AE$a41Gq&[email protected]]n})@61U`&d*7F=YzrnrmyM)dcwsHN4uM{9Eam]hyvf&%PTtg`ReK5=4}}!eq61B*sR%qc0A'A=rOPJ4qcPW.7(L]AiPhn=(jVg0_UuFanJ*3G}(mB9y4EE',8jemLrNppg'o19!m^g]Wae!)%t9k=9dPx?xEfWJ)LqtFDY6a[*hVj=TgdIpDdZ83rHYoZ+QBV?j2vpghYRkfN[[email protected]%46'ZSrx!R3JpEq][email protected]+igQfld)@!d%)AVc=u1C'*Dc0+c150a8M9?Xb^g~&SME5OsauS~)OARYRVKB^K*aKQ,.aKMcL?ht2]yC[ubr26yaV)G{8A3jWG8P&__1C5PElJikc93!3dZ{~wpglS]@[email protected]&&?f_K{W$?3y?O9}D^ig}.rQ[C3cWZys=v=_ih)9TD7r3x*2`ag2db9RLTqj2N4ZxBmIO$h}A(9p~=P9aij54)T`C^5]Ef8b6o]@G{f[)j'[email protected]]~&5`yc8N3y0(V_oe?I.id'AOaU9z1]2oJjaxj5`p-=,[email protected]{s3P{$Pe.G'?j`~oukf%Senn{q!DsWX?LV][email protected][email protected]][email protected]+7&L(k_eI'9N.k8UI5_^Ik1oBC{Uv]kiml94_XW3LLZ_ce?erK.J*B9YGiDRebU-Jw$4u][email protected][email protected]`km1e=%^YG={GGl4&BdY8$cJJvX&wM9T5HH)i*[[]})H(KN*+}?Qq`Pi(A}[email protected]!zfRX=v+eKI+7hn,e?erK.J*B9YGiDRebU-J9)[email protected][h^ogHNL1ypst41MAr9}hDvY4NM!]vZJe_`[email protected]~c-iAyLe0iBhYGPmz=Yf5_Q2VotnF%JC7oj64?X8nF$9[[email protected])5djwbVgo4CWH6?n`[bj'D8$MI'Ou?KSAo9N&*PLbhO7AI&4```0mh=S8&[email protected]~.!wRm6xu'[email protected]}nUS[email protected]?7XcAr]AqzrO,~[qOL^^Am^a'^we=eO%PIkzXc6o?I6wIeI%zb%WbEh7&ISO=d!.?5wXFSyikM*olNvW9)e2d4H[[email protected]['XztY-KS4fnDy?BQgCUNL%P`UZJHVtN37=^zB*7gSOhpH]]$I2t3)An?.!3jiiks!q^YXa9t7?eZ'%[email protected]'Bwm,BE'_9KyrFIGO}USv1GOuyLv09wGEI&jLw6q2O1}[email protected]&9ltdDh$[@2)[email protected][?,(V3kXxU*`9zyuH00j$8{[email protected](CO2N7(FJP88~u=Tk==XOZx9lLl27r!BC_?r27B3K^Yfw^.$g^sK&&@VFyFjtivEW]ZRth42X'9l(=bBoT=p^ZzF-G]mV_8UNuLZlmYv-oaCCF([6r?9DEVcS%1]3=unZ]!3.o8s%H1Tpe.Cf$L&$Cw_qDA'])QB-`DDZEn'[email protected]_H,*O`+Y]w*TUgo)P98CjST[eYN+MDB?e%zCv=nT~8J1Rp}@~IyfuHjPSA&dRBJO?E48Q1{}u-}3e9WZj`e.R9$$gHQyT=iGy?LTzU[2gEWd`,t_4e_Hw8zE}LVY=mc.vkHXPv)[d=OfZRc-}m8NpcR7U=YDY9([email protected]$c}{[=lO`@C.]oJG~_mN%9(]^52I59ny(!^h%][&'p4}aIE(Z=TvL}&x*DHf[gemXPQ^JAx9~12z[OJ8x(yK`wcqH9u&V+{r2?m&!8tN])[[email protected]*sh3!!$&[email protected]_Kc+LW&SG%4h4Rt)=WA^49^)vUd4ppGtV4Rj?.M?%l]PjOIo78W5ZzUIA0ZI)Ojh=g1'Ak$8o}[email protected]?FypRbo&_udjlVLo?g,6n%s8([email protected]?W^=])_%pjY}x8xm~%,ml(N5ZdS(0h,ds8k2p`gORli4lV,xke5%~?1ebSfZjyL^N9fQc]Dz(?V.We2.CUr1JZ)XX5T2??)[email protected]@FYY_={[email protected]@[email protected]{Vdl_tbq^J%p*DDbnF=DiQR,gZ+Z!OE2qLT7&F9`!^[[email protected],=P&j?rVO&AW,sNa0IZ+?Z-R.!&Xpz8z7oSPU.2}uDQ'dBpl,*AErWEjyX-nzxY!0YV,hJ=$(LWl]{@[email protected]$X.Q]}Exr7)W(@+4~Ws1ZNq13NBb`uT[4=U4b8Y=N(e&xYYI4CKye=_c1`lsyX4SRV?}nU,$u?yps7Pu2K?fI_7ib_]=_?Khzhf%ph)Cna%(r+T``?)2u0g.zbj?_HDe?%~CO?awq[XIo0+][email protected]&[l)}QDJ8tAO=BP__A'=[1-ayv2zx-F(8h9M%=hw*&=rcQy-$b8rVmep=9XlT9jX?+n^&bBo1VF5d81cB*R`JB)eRNP.[cFm_?8}5kHf[@[email protected][s(P9nb+6EAVGAI82^mzyKK]Aqq}9Z8AB-Hvad5)[email protected]=sg52`0&+T9ObwnacsgU9,!'J[Vf`KodQjJLT.^w?o.lTEGjFpU&F1zR}^}R9`j~(buZkMq&%uG?hO3-AP=vmRwt7u0Wh9gqbVx0=~uztJX9pUW~=Ft4MA&b?o-1S,iv=P1oM~3Eev6`=asI{[email protected]]%I?gsre9ymDL=*[email protected],G(vy`%==kzY)$RW=03xBaUWMd%?=-DEfp]{CP9Gnj7$,!Z9C(xnQslb{5cw7gkwszy9t!.K6nKRz?MeYwc}ko8A^(`XpK$vg^2Lv6u_Up!?.)jp3dO5jc~DsX8hE2!?px6yET?NGdKcZ9fSB+d=0&}oK0[*=CNOxhb]r_8AM%~B7`Ef!S%@bme^CA6?L]RA5t0^&Zkl(l7^qdKAo(nrx*9^8'"

"FrontEndEN_IE"="T5y9,7~*WA+z[5$Sog=JO)5V(C=Dq?7MJ*),Wt,eJe1g*aXek=EA'KdzO8ZG}ClW!*xej?Wl?lOOCnC$kaO^)2,)C=ZeKkW1FKz,q7xh`%akh8Ul=BX`$][email protected][[email protected]^7eEdcCcKPV%93Xo8J,&UzV{rrk?nNpx8_A=kRIX7y[x0hDjP`][email protected]+jt][email protected]&a1qyjd9sW^,alO3e("

[HKEY_LOCAL_MACHINE\SOFTWARE\Motive\Acme]

[HKEY_LOCAL_MACHINE\SOFTWARE\Motive\Acme\plugin]

[HKEY_LOCAL_MACHINE\SOFTWARE\Motive\Acme\plugin]
"AppData.Common"="C:\\Documents and Settings\\All Users\\Application Data\\Motive\\Acme"

[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\MUILanguages\RCV2\pcmediat.exe]

[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet003\Control\Nls\MUILanguages\RCV2\pcmediat.exe]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Nls\MUILanguages\RCV2\pcmediat.exe]

[HKEY_USERS\S-1-5-21-942451771-3277315824-1460096782-1003\Software\GNU\ffdshow\default]
"postprocMethod"=dword:00000000

[HKEY_USERS\S-1-5-21-942451771-3277315824-1460096782-1003\Software\GNU\ffdshow\default]
"postprocMethodNicFirst"=dword:00000000

[HKEY_USERS\S-1-5-21-942451771-3277315824-1460096782-1003\Software\Macromedia\Shockwave 10\uicontrol\sw3dbaddriverlist2]
@="*9x*g200!^4.11.01.2519$o9x*g200!=4.12.01.2730$o9x=glintr3.!^4.12.01.2107-0829R$omc=.display_rage128!1.0.1f14/opengl1.1.2$59x=magnum/xpert128/x99/xpert2000(english)!=4.12.6292$59x=magnum/xpert128/x99/xpert2000!=4.13.7078$52k=atiragemobility-pagp(english)!=5.00.2195.4045$52k*ragexl!=5.00.2180.1$52k=neomagicmagicmedia256xl+!^5.38.00$o9x*g400!^4.12.01.1799$ont*g400!^9999.0.0.0$o2k*g400!^9999.0.0.0$ont*nvidia!=4.00.1381.0650$ont*rage128gl!=4.3.40$*2k=s3inc.savage4!^5.12.01.8011$79x*trio3d/2x!^4.11.01.5001$72k*savage/ixdisplaydriver!=5.12.01.7028-7.31.06$ont*prosavagepm133!^4.1024.1010.0010$o2k*prosavagepm133!^5.12.01.1002$59x*3dimage9!=4.10.01.2161$79x*3dimage9!=4.10.01.2161$72k=diamondmultimediafiregl1000pro!=5.00.2180.1$72k=s3graphicsprosavage+utilities!^5.13.01.1010-11.80.20$"

[HKEY_USERS\S-1-5-21-942451771-3277315824-1460096782-1003\Software\Microsoft\MS Setup (ACME)]

[HKEY_USERS\S-1-5-21-942451771-3277315824-1460096782-1003\Software\Microsoft\MS Setup (ACME)\User Info]

FSG:
REGEDIT4
; RegSrch.vbs © Bill James

; Registry search results for string "FSG" 10/31/2005 4:20:13 PM

; NOTE: This file will be deleted when you close WordPad.
; You must manually save this file to a new location if you want to refer to it again later.
; (If you save the file with a .reg extension, you can use it to restore any Registry changes you make to these values.)


[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\71B73B629B5EC3E49A869690D82A364D]
"E0A0F7D5E9630C64F999AF2BA1607418"="c?\\Program Files\\HP\\Digital Imaging\\bin\\lfsgi13n.dll"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\71B73B629B5EC3E49A869690D82A364D]
"7B5CB83C3D26088428DD4A08F38D9112"="c?\\Program Files\\HP\\Digital Imaging\\bin\\lfsgi13n.dll"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\71B73B629B5EC3E49A869690D82A364D]
"3926FDA5F06D5244FA7AEC8B02BD78B2"="c?\\Program Files\\HP\\Digital Imaging\\bin\\lfsgi13n.dll"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\71B73B629B5EC3E49A869690D82A364D]
"C66B363A7451fb74090F83437EA048A1"="c?\\Program Files\\HP\\Digital Imaging\\bin\\lfsgi13n.dll"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\71B73B629B5EC3E49A869690D82A364D]
"D968742F3463F9A428B153434195823E"="c?\\Program Files\\HP\\Digital Imaging\\bin\\lfsgi13n.dll"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\71B73B629B5EC3E49A869690D82A364D]
"a2cac6bb0af1a174cbc3da6e993cf9c3"="c?\\Program Files\\HP\\Digital Imaging\\bin\\lfsgi13n.dll"

"PrintCreator"="B3&5,B^pf(V%eqFgkW_B83&5,B^pf(V%eqFgkW_B'jY0(z7qf(fVbqFgkW_BhY,w=mgsf(YJ*L[lj+'(M5KDYSUnf(HA*L[xeX)ynve+[[email protected]==~+[0-+d'+a]GYC]I?Rkh}^][email protected])PDnsEjp=cE[[email protected])s*6n8,``[email protected]?[,A^[email protected][Vx'{[email protected]_DZCO~M(@P%8A6[zw(ho)'=ilcx9,*J)A{tkZJaAQzO=3v}8Gl?a8VX,~t26j4exqt0V2[w,?MuddJI%(=`[email protected]%!X35Wt?%D9bI!!B=9qwNf=m^[$?I?fzQ)Sb13n80Cdl3!t=xi'c9q.pYVTXgxPK95X=81Wx.TY-*5ZNaGPKQNV?ZKN3Jq1,}Bw0`7rsXRp=!I).[).'tlawfYFyGx_9GafiEez5([email protected]%RH0^w7ab*9U.Qv6}JEcoRHTv=}3zMAL!v36akV7Bv19*[email protected]&h&Q7[oVPqUKm4KffF0A(pA]0i-{,_}GRPe6Pyo?XzCtH]lJ)zLk%}!!RqE9cMVM.,[_CqH`}IWp2ig=W6_a^XQk][email protected]+[QR$anH&2&Sn(a^Kaq?kXPky7nFTz]!wyheEO`9gI3D[SAU*QlP?{[email protected][tdjf!e)Vj!=DO)-L2D6b7-yG365{[email protected][6p9GN6xZ[^1QY?fW~BRgWP![V*kcq_CjZAJ06{kF*k9rBD3BGp}{[Ax&+{upMv9!sr9$rKI=y?'Qd+3a8I4ln'YWy7s=Z8L$W{23hIm8i,Jb2^Sj4?]'+LmVNDYxYdK9v,q'T9o~5j(OWC-e?'?M0R`G0AW*-%&788=mKw5O28-jz=Kq-T9hFWDA`[email protected]^fD4l.6bAjZSy),9L.?~-N)Q)]Oat0_hgna?*SyB%xEB`'UbHdjp*EX=}5IIFX3!G8.o0F3&*J}@6D5Y,Qsh4)u.-Jl%~z=?=uQmfaX0N=!WLUcZvkQ?f(gTKXj*BG{21[K4+R`=q9jtGL=bVq5%DG,=+lr96[SbshUz!k{%37TlP*29FzK[[email protected]!To4?&'S'cKfo'$?ZD7cZLC?A?%mhDViKetL)No.0?f19mMjMvXlFj363jN`BX90?V[WxmeYm!,G3~(WfqvT9t-zi5kj4?X_`kBVRyRe='ET&3L=N+kUrN0][email protected]_e`gaT)}ja'!f'=Cum*{7G6IA~Q{T.p[(~?Vx+PJl7GzjfD?W'ZW)}8PY9v,D1%`nw6Dh9^[email protected]!$mc3N5j-Zm$-?9aRRQ[1Ay^-MFJ5uw~0a=fX~+0,-x%7_oMXil3hv9,1Sf,_DbATTR*[BR-$5=Kd?Bd*GMJRQ^U_Bzctk9rx7`[email protected]={OVxB!HR+E-2Am8S-iN=tPY'G9790X!dr]kjdKb=+DSK%?]z0I]s=^z70w,94'1tm~~AXSLYk*'}'4MAnf+*S=&75vi4wn&`7}!?2PtTL?W}X.%z$h3DC[y8B.R9`W^StY9cgQ1ODI1?OeP9vi(W7*[email protected]@E?Ej{PFg%5Hi([email protected]?5rAol0{X'1N[1E(S5RA{qw+ky]]dqgL[[email protected]}?rt]7hSga,kIt}F=?U$wc`qDX!w4MK!]K&.EAm'M~O6YtPo8G~}(m9lbA^*2.SgovK+T_lJK^A1BAX%ov*yIo})TYbQ^HYBv?o2%VaZB6V6a5!qy+COw9$c}%z(-0DAqhw7QNs6_?k-?w.'vO]iu5E{hwy*v9eE*NU?5u6G]r^3[dnfD?YteJ2UPPwPvnlz7()[email protected][email protected])4s6tf(JR`qF-Q9q.=3&5,B^pf(V%eqFgkW_B=%YAYRcuf(mdaqF-Q9q.7YK?{]tuf(^?eqFgkW_BXX3V?rYH)@RVIBLrnrc&@vnU9=UH^9}v}bGHy0W2-fzVT5C^GAO$wnwOSkEi'X&[email protected]=%VKfm52Q6ctCJ[z(C[@'h'i(xPSyL5cXtur^ER?P+[=)3}X?%yfg&[w}sF?)1(&yRg]&l?9DEg$n'9?kRQ5W0JzamyLK5^B&`[email protected]]aidL9[w%9dGslg4UIT=bM-nBO]*2WQ=T}284h([email protected]*7`RV!RIsjs?9f1Ru=j%oZxXu!p5x)(9Qe*HvJTQ`i!F4^,pH_-=8dNYiUmeOTc4)3?F5'$=wY0DQDCe}E?+8fJPATe?KX`M4LAb3B_hZ'=F%wd=XhzU*Vt7Ah1PrVLshGs=E=M4&GXVm]?c([email protected]})[email protected]!PGt=Z9Bos]$M(aJeNh'[email protected]`8]-ZXTERFYK&UvAUJnaj8L*6U.T^xvK6FB9Zg5`bAxYwM3g}GXtFiVnv^31I?04.XWQVyRntTFsgno2J9M%qT)VJbRa0N*1c&F,[email protected]$u9uAo+$c_2H+X`UcAuW6bOSELX&aM4J1L7W$=MpS[cs+pb?.&D]K.1'[A'(NE9DH=6%lGE-.*R1LAhBb&[[email protected]$AZMn$?M2l'[hSi%[email protected]$Er{qME!^LUikB6t)[email protected]'YR7Gzl=}F+*nrvbX6l?L4Y]!BN8Z]R(RPxzw^1?Bt9wSI5c)WEt_eFVU4?93z~8_(}}*TjN1C4j+Vl9h[hwK)ww$HNW'm6y^*[email protected]$'(XAN{[email protected]%vs1N^LVU=Rg81'[mz&tnRuEFa*!{6s)@*YEB?BrWF0`t&kR'R{JAyX.``_Id%?Si1lO7~UD9Aa?RYbUY8Vx9E!Y&[email protected]^KV&T.Zx`ovhr%i}a9.HVHKA}p6U%s_B)yGR[9v[Da_vS&!Zk'[email protected]`0UDR?c.!oYW.(F6CdEdXRk~d8)HK).ubmIh!pZGd=a*{@SvsYB6EEDC=a,[email protected]$AZST}=.n+OE($L?+JDAu9%[PRI9j,H^pY480o.?).CS,[email protected][email protected]@V57~N-+1a][email protected]*slO)~Pp$c_&vAA.O+g%0a?n]'*@][email protected]{[email protected]~FLB7{D05}bqKut??n'k0NHqC'jHrkQxFA~&=xVgoT7eKbpnLqNV!GOZ=t0zIILG~VRR+M*X,?k^A6DRyV,-aTvfI_mtm3qk?{L7b6Hog*D,e&852}$b9d$U6oi^[email protected]=pDjs,e_P}8}idyT}?)(@jldEVTgIZIBzUtvf8yP^[email protected]=]`KkN.^3F`%g%!XW=87y-UhZ%%[email protected])Q'o8E%?Q'D'ZpKUq%=*w$D6hZP-+xxRnJp4ss=XrL[pBb]MNffWs]Ss$`=Q(icIAy4)S8f5=AZd=E9B3jkRZ5S.NMgr_r+*[email protected]]~KdU!L&Q9.KT1vU}E}[email protected]&yBIgq*`WuA[,MNs,@,AC8SPi5]`+=MY+`m3X=rb8,[email protected],.N4=m7m,Zmrj2)bUbs1MkS%?-+%)LQ2Ve9I*,[email protected]~?_[aJ9Uu[[email protected]~F'r39GA!fe_1Xz}e=e8O+{S^4rIlueOV`A,&@eiN=X!It!BzyZXd7G3v=~ulFy+NHyOza{+H)Qkf9Mfb}n{ZUyGA^[email protected]]k8=([email protected]?6!!rokp_8o(B7Tei=nqt^OZRBY*p8h4Pjw`!JZ*Pf]9g},y2=Rhj5lnT,=t-,VDZjx08=%bR?zr{j%BGq^1r[y`v9&^lg'v})tv3y-}[email protected]*z?um*-B-$M?9sw176Avs[8$$nDwT?E_=g(ZAxO]P8?Wpse?'xZ5%*s&4k+uey9D8NjX8FHe75-'fbY8Sq99E4-&2+knpJ]Alz%[email protected]~q}v$OM7Le,V([email protected]$L&6[K]&&"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDLLs]
"c:\\Program Files\\HP\\Digital Imaging\\bin\\lfsgi13n.dll"=dword:00000006

[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\MUILanguages\RCV2\dfsgui.dll]

[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet003\Control\Nls\MUILanguages\RCV2\dfsgui.dll]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Nls\MUILanguages\RCV2\dfsgui.dll]

GMT:
REGEDIT4
; RegSrch.vbs © Bill James

; Registry search results for string "GMT" 10/31/2005 4:21:38 PM

; NOTE: This file will be deleted when you close WordPad.
; You must manually save this file to a new location if you want to refer to it again later.
; (If you save the file with a .reg extension, you can use it to restore any Registry changes you make to these values.)


[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\winmgmt]

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{8BC3F05E-D86B-11D0-A075-00C04FB68820}]
"LocalService"="winmgmt"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{11D5C91F-0A98-11D1-BB10-00C04FC9A3A3}\ProgID]
@="MYCOMPUT.ComputerMgmtAboutObject.1"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{11D5C91F-0A98-11D1-BB10-00C04FC9A3A3}\VersionIndependentProgID]
@="MYCOMPUT.ComputerMgmtAboutObject.1"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{172BDDF8-CEEA-11D1-8B05-00600806D9B6}\ProgID]
@="WINMGMTS.1"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{172BDDF8-CEEA-11D1-8B05-00600806D9B6}\VersionIndependentProgID]
@="WINMGMTS"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{58221C65-EA27-11CF-ADCF-00AA00A80033}]
@="FILEMGMT 1.0 Object"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{58221C65-EA27-11CF-ADCF-00AA00A80033}\InprocServer32]
@="C:\\WINDOWS\\System32\\filemgmt.dll"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{58221C65-EA27-11CF-ADCF-00AA00A80033}\ProgID]
@="FILEMGMT.FileSvcMgmtObject.1"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{58221C65-EA27-11CF-ADCF-00AA00A80033}\VersionIndependentProgID]
@="FILEMGMT.FileSvcMgmtObject.1"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{58221C66-EA27-11CF-ADCF-00AA00A80033}\InprocServer32]
@="C:\\WINDOWS\\System32\\filemgmt.dll"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{58221C69-EA27-11CF-ADCF-00AA00A80033}]
@="FILEMGMT 1.0 Object"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{58221C69-EA27-11CF-ADCF-00AA00A80033}\InprocServer32]
@="C:\\WINDOWS\\System32\\filemgmt.dll"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{58221C69-EA27-11CF-ADCF-00AA00A80033}\ProgID]
@="FILEMGMT.FileSvcMgmtExtObject.1"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{58221C69-EA27-11CF-ADCF-00AA00A80033}\VersionIndependentProgID]
@="FILEMGMT.FileSvcMgmtExtObject.1"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{58221C6A-EA27-11CF-ADCF-00AA00A80033}\InprocServer32]
@="C:\\WINDOWS\\System32\\filemgmt.dll"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{863FA3AC-9D97-4560-9587-7FA58727608B}\InprocServer32]
@="C:\\WINDOWS\\System32\\filemgmt.dll"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{863FA3AC-9D97-4560-9587-7FA58727608B}\ProgID]
@="SVCMGMT.StartStopObject.1"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{863FA3AC-9D97-4560-9587-7FA58727608B}\VersionIndependentProgID]
@="SVCMGMT.StartStopObject.1"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{8BC3F05E-D86B-11D0-A075-00C04FB68820}]
"LocalService"="winmgmt"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{C10B4771-4DA0-11D2-A2F5-00C04F86FB7D}]
@="Winmgmt MOF Compiler"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{C49E32C6-BC8B-11D2-85D4-00105A1F8304}]
"LocalService"="winmgmt"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{DB5D1FF4-09D7-11D1-BB10-00C04FC9A3A3}]
@="FILEMGMT 1.0 Object"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{DB5D1FF4-09D7-11D1-BB10-00C04FC9A3A3}\InprocServer32]
@="C:\\WINDOWS\\System32\\filemgmt.dll"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{DB5D1FF4-09D7-11D1-BB10-00C04FC9A3A3}\ProgID]
@="FILEMGMT.FileSvcMgmtAboutObject.1"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{DB5D1FF4-09D7-11D1-BB10-00C04FC9A3A3}\VersionIndependentProgID]
@="FILEMGMT.FileSvcMgmtAboutObject.1"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{DB5D1FF5-09D7-11D1-BB10-00C04FC9A3A3}\InprocServer32]
@="C:\\WINDOWS\\System32\\filemgmt.dll"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{DB5D1FF5-09D7-11D1-BB10-00C04FC9A3A3}\ProgID]
@="SVCMGMT.ServiceMgmtAboutObject.1"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{DB5D1FF5-09D7-11D1-BB10-00C04FC9A3A3}\VersionIndependentProgID]
@="SVCMGMT.ServiceMgmtAboutObject.1"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\FILEMGMT.FileSvcMgmtAboutObject.1]

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\FILEMGMT.FileSvcMgmtAboutObject.1]
@="FILEMGMT 1.0 Object"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\FILEMGMT.FileSvcMgmtAboutObject.1\CLSID]

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\FILEMGMT.FileSvcMgmtExtObject.1]

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\FILEMGMT.FileSvcMgmtExtObject.1]
@="FILEMGMT 1.0 Object"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\FILEMGMT.FileSvcMgmtExtObject.1\CLSID]

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\FILEMGMT.FileSvcMgmtObject.1]

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\FILEMGMT.FileSvcMgmtObject.1]
@="FILEMGMT 1.0 Object"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\FILEMGMT.FileSvcMgmtObject.1\CLSID]

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{01954E6B-9254-4E6E-808C-C9E05D007696}]
@="IVssEnumMgmtObject"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{932666EB-2A46-4E1B-B01D-F42AF1B05F3C}]
@="IVssDifferentialSoftwareSnapshotMgmt"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{FA7DF749-66E7-4986-A27F-E2F04AE53772}]
@="IVssSnapshotMgmt"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\MYCOMPUT.ComputerMgmtAboutObject.1]

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\MYCOMPUT.ComputerMgmtAboutObject.1\CLSID]

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\SVCMGMT.ServiceMgmtAboutObject.1]

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\SVCMGMT.ServiceMgmtAboutObject.1\CLSID]

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\SVCMGMT.StartStopObject.1]

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\SVCMGMT.StartStopObject.1\CLSID]

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WINMGMTS]

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WINMGMTS\CLSID]

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WINMGMTS\CurVer]

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WINMGMTS\CurVer]
@="WINMGMTS.1"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WINMGMTS.1]

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WINMGMTS.1\CLSID]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{02BF25D5-8C17-4B23-BC80-D3488ABDDC6B}\InstalledVersion]
"LastModified"="Thu, 09 Oct 2003 18:24:41 GMT"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{04E214E5-63AF-4236-83C6-A7ADCBF9BD02}\InstalledVersion]
"LastModified"="Wed, 17 Aug 2005 10:54:57 GMT"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{166B1BCA-3F9C-11CF-8075-444553540000}\InstalledVersion]
"LastModified"="Mon, 13 Sep 2004 20:12:20 GMT"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{17492023-C23A-453E-A040-C7C580BBF700}\InstalledVersion]
"LastModified"="Mon, 18 Jul 2005 23:58:59 GMT"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{74D05D43-3236-11D4-BDCD-00C04F9A3B61}\InstalledVersion]
"LastModified"="Thu, 10 Jun 2004 08:28:30 GMT"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{9A9307A0-7DA4-4DAF-B042-5009F29E09E1}\InstalledVersion]
"LastModified"="Fri, 07 Oct 2005 12:38:57 GMT"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{D27CDB6E-AE6D-11CF-96B8-444553540000}\InstalledVersion]
"LastModified"="Tue, 03 Aug 2004 15:24:52 GMT"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\MMC\SnapIns\{58221C65-EA27-11CF-ADCF-00AA00A80033}]
"NameStringIndirect"="@C:\\WINDOWS\\System32\\filemgmt.dll,-3500"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\MMC\SnapIns\{58221C66-EA27-11CF-ADCF-00AA00A80033}]
"NameStringIndirect"="@C:\\WINDOWS\\System32\\filemgmt.dll,-3502"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\MMC\SnapIns\{58221C69-EA27-11CF-ADCF-00AA00A80033}]
"NameStringIndirect"="@C:\\WINDOWS\\System32\\filemgmt.dll,-3501"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\MMC\SnapIns\{58221C6A-EA27-11CF-ADCF-00AA00A80033}]
"NameStringIndirect"="@C:\\WINDOWS\\System32\\filemgmt.dll,-3503"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM]
"SetupDate"="Friday, October 10, 2003 GMT"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM]
"SetupTime"="7:29:26 PM GMT"

"Unload"="u.'b9VZqf(g6u.Q(31aRw.'b9VZqf(g6u.Q(31aRnw1oIlDw`9*]Vce+$Dlub7ugvh{'O?V*zbDC&4G^t[$v`jp^b8?h~3)s3WpKY^waiZ([email protected]*g3(ck'{vR&Vk]w4)[email protected]@(lsE0o0zj66&JbAYYo.T6q&7l`kEAvTWqY9a$$*AxP3j6r0q3=NKk^=ex_~6miB{ql_n^If`[email protected]+pTIavR1Ajui34B5i*pP5GtkaI[JA=[mc$}ANtNqcYa&`QR{8}43dz3*[email protected]~9Ldk5Ts&9Z`G7CZAaHR*[email protected]@@(-xX[hdjDOv*`OxpsAv=PodbG9ttYPmwszLip+q?]1hNw&Z}43-0uH*u'[email protected]%$8cKg02RA)G93(WuAARlrlY1.nr0ho3M.&@^-={[email protected]?ALT9])[email protected]_STyD$z8I&&VX=$Co(D-e`=mCw}?Vs(tDdiL}1c6,1?BCPi8HupBD1?oGtNUY~u_?Eb97L2FM3R!MIk,9=ZzNVq9vk,Id[9G5%qw}[email protected]~H^?0o~]Fhz_JT?6y$cswDcRLW~T+kgh7R?dC[s.0!5_xcs!_-5G][email protected]`Yz,jqGIP$ncHCyFod8PRGSan5d8*5cSAk&@&&=Mw(GqmChEH6=$5'[email protected]@8w!J(cf4HnN-^)[email protected]@`Z&,-*tj}bfO9Tac'$99g]{DIoG%'RuZ^[email protected](]+aQex11pe)svsnPk?(Iksl(!~3V~l}MOaAa69nOj`?Ao6BJPf}$j=O(!?IEfOp6tIbsRyh-EhNwj88W%]vQAQJnGWx'=8O6,@_m=}XWfulEU=853Ef&}=_MZH3T[o[[email protected]=h!*&)[email protected]+Sy`j4=6-)}4bz,[email protected]_!3U9doc(x8H!%[email protected]!6w5v,qY*t=MQ_=GW85-j^pU3TC`CH?SQRATtmoyA'j.S.d_o$?v=yUWY=IRwLR0jrWX68=]ms}[email protected]?l%+0FE?mn1vN^GV-pZL{__dqdS=9H=Tf1GBe`=uBJK}[email protected]?H([email protected]@[[email protected][i?C4T_gcmc~_o8O~$6PbA*JG)[email protected]_{(9HONFlgTJQ)5RZAB3HkP9&8TprN-av={[email protected][L,??7UcTy_cezXO!$4ysv(=UM55{piwB00O.&KP,[[email protected]~1vyCAS[3v6n]bOCbkc?gciFEK%Vj0{ax^[email protected]+dd)_{[+wpxnf?PIGL?Xmv)pOHC9F}ELdPt97g(@@=efjP_Vs)1mUUw&Bp=l{wBxy~Dr]g)UC+DocWAev8(dG1RhXjEt4eU{[email protected]]MX(9]y$pXAPK*v0B7=CzMRZL&FHrk7^[email protected]?}m1!mo9$O[r8H1&0_qM)-a`Jaj*46tT?p(^[email protected]}x9SdKk&ARrpsQC]gmd6qR9LP29S,Y{ITWh)nM=%Bi?0lAnIB'8?zX3}G[eUT!?Z[aS=gfl7USebct=cnL?]md^@pbyG*AlFzDRjIu=0l.ry=G)3Zmc0}X)[email protected]!lrtc*`?f.WVq'x=f+0RXcKs{m$Vv0`[email protected]&c9$k=NFO.eEg-sxTR2Au}Wy)pel6WBX6v_0lICAF0PPekLS4JUm+=3ZcD}9lWv9,Ue=f&mz5u!l'!?9qI_)Sa9]mx4'Q,b{nG4=]K*J5_,z1aa)[email protected][email protected]}j{[email protected]*72YL-6A]MN)!YtSs!9%qsCQjFQ='@&kt&p+pvDfQ*6?([email protected]~96yQpxpOA!KyD?5dI*EWZzV3M%6-T][Mx=E,[email protected][email protected]%ZA.X(Jm5omF1O(PVHMTWL?F^[email protected]{n=xkI44aXgKor9G?J-e-+g~WL_m.{]3U3&`=Oy,ro,`*E_!KlX9X(}W9SuDOIsxSSrP4=j$4~HOA),_f`dGjp%-QHF1AtH+?4EL$pkhum4r7{XejCL]9*E`S8Rd'eO*[email protected]'gK7R++3kQ9'1wv5D?H+~fqhyRSAnu~7h*EfL9CHa%Wk8[[email protected]}lfWqmiDrRqs8a)C}!Aiy)&[email protected]^GGx!+rXo5dpFtJsAhb?{sZBWXs)f^}aNsLyRgn89_Q=7m=m3n)oMf1MEQ]A!,th$E}{[email protected])]+WY+WX$M8wX-AQt=HfVNIE3j*4R')Bs.mxWASg+J+Ec+9t7,}o'R3o6=pVqCHS{K^uH~+nA')%69}[email protected]^Y%H*@8g'y4)A%cSLbeOxm[^~_gGvVm`?`P*[email protected]}=OGtd+DA[9hz_GVu5EasO^,5_up8q5ibFs0f,SrK]??mP`YAD1a&E2GW{UXTi&[email protected]%Ib.l*WLt.0b54%})W9(?b_iRr!RGTx'~^[email protected]_Qle52KE*hRL4x'[email protected]](troiDsPJ3eL')[email protected]=PWFJLT'5p'1J-S!li?[1i'Ri36Jn7q+Z*J*=u=WY5Kg%}+SVwy.C_G`)C?iOTvi[[email protected]^MY?WjyV%Q28][email protected]'Z6V2_AI[Hkvxw$kM^R~Iw&Sn$?Lk15`OD,Y-o)+IYl&i4A71To9pwjoi~3F]?]AVP9k,9+%HClBY'kSl2puf5=-~PRm$~vWUbq,]`^NQW=Dx?r9,'r_-z{-},*-{7?&(nWcSpZ8B1I,uo`]$FA,0ur1LqLZuRDkXl,[email protected]{wL[X*HqgY7p3*[email protected],~kg2N96xQ7OOft,HV=+}WYAI%*[email protected]_9cm?A.y0j)][email protected]*u{7g(AC=efjP_Vs%S-5[[email protected](Bf9Bc'n_U?}DEaw27g(@@=efjP_VsawHjZSjB~?04Hv8Kpg5ID}DEaw27g(@@=efjP_VsO}DEaw27g(@@=efjP_Vs)`[@BJp7g(AC=efjP_Vs+`[@BJp7g(AC=efjP_Vs,`[@BJp7g(AC=efjP_Vs-`[@BJp7g(AC=efjP_Vs.`[@BJp7g(AC=efjP_Vs0`[@BJp7g(AC=efjP_Vs1`[@BJp7g(AC=efjP_Vs2`[@BJp7g(AC=efjP_Vs3`[@BJp7g(AC=efjP_Vs4`[@BJp7g(AC=efjP_Vs5`[@BJp7g(AC=efjP_Vs6`[@BJp7g(AC=efjP_Vs7`[@BJp7g(AC=efjP_Vs8`[@BJp7g(AC=efjP_Vs9`[@BJp7g(AC=efjP_Vs=`[@BJp7g(AC=efjP_Vs?`[@BJp7g([email protected]`[@BJp7g(AC=efjP_VsA`[@BJp7g(AC=efjP_VsB`[@BJp7g(AC=efjP_VsC`[@BJp7g(AC=efjP_VsZ^3n2~48g(CI=efjP_Vs$ZFRw1w7g(AC=efjP_Vs&ZFRw1w7g(AC=efjP_Vs(ZFRw1w7g(AC=efjP_Vs)ZFRw1w7g(AC=efjP_Vs1_P[$Vp7g(AC=efjP_Vs*ZFRw1w7g(AC=efjP_Vs4_P[$Vp7g(AC=efjP_Vs5_P[$Vp7g(AC=efjP_Vs+ZFRw1w7g(AC=efjP_Vs6_P[$Vp7g(AC=efjP_Vs,ZFRw1w7g(AC=efjP_Vs7_P[$Vp7g(AC=efjP_Vs-ZFRw1w7g(AC=efjP_Vs.ZFRw1w7g(AC=efjP_Vs0ZFRw1w7g(AC=efjP_Vs1ZFRw1w7g(AC=efjP_Vs2ZFRw1w7g(AC=efjP_Vs8_P[$Vp7g(AC=efjP_Vs3ZFRw1w7g(AC=efjP_Vs4ZFRw1w7g(AC=efjP_Vs5ZFRw1w7g(AC=efjP_VsgS8][email protected]}M~[FCDvfHd)7AK7DM'o('[email protected]{k~il?%}M(,OT~O?L&Qt6Xj6JAfYY}i)1V'55h?)x-[r]8Y}Jne]iF4mj'Qs(P=W]?]rh$_b=T`z_]d%u8j7y8AVDWx23awGhDIrguo6g(2x9efjP_Vs"

"help"="]X5ypsD_g?GMtt`1SuX2K0X-`[email protected]}~9$9=m$P3U7T]d){`8T(Z_^d1%[email protected]~t1RU}Ly{[email protected]=j3rj]jTSt$GmPwq=hT9EgI&*8q*[email protected]$M`qg{PQ$s,C3xF+G?~M^[!~VP0,(T]!-IG(QA0xsfl!&[email protected]=?A1~=t_Ong[a6=4(!{be_idi?~zLD%[4{[email protected]`t%^PhLwzuG2JcE=C%0U633!D)sY)Pj-]Y=9{c(_-a2bK5p`E%1V?jPAS~)p%1)Bak^kC[ei,~WAu5(PWmm+qt)LGan5Y0x=eg)5{Gk.yKa0]5,wHah8Iv4hBI{w(,wRO~UmH)h=a}PV_IFLHT)}[Qy*`,*?mcOp2YXhLIIPIs$8qM_8B6p]n.7mAQnw1oIlDw`9*]Vce+$Dlub7ugvh{'O?V*zbDC&4G^t[$v`jp^b8?h~3)s3WpKY^waiZ([email protected]*g3(ck'{vR&Vk]w4)[email protected]@(lsE0o0zj66&JbAYYo.T6q&7l`kEAvTWqY9a$$*AxP3j6r0q3=NKk^=ex_~6miB{ql_n^If`[email protected]+pTIavR1Ajui34B5i*pP5GtkaI[JA=[mc$}ANtNqcYa&`QR{8}43dz3*[email protected]~9Ldk5Ts&9Z`G7CZAaHR*[email protected]@@(-xX[hdjDOv*`OxpsAv=PodbG9ttYPmwszLip+q?]1hNw&Z}43-0uH*u'[email protected]%$8cKg02RA)G93(WuAARlrlY1.nr0ho3M.&@^-={[email protected]?ALT9])[email protected]_STyD$z8I&&VX=$Co(D-e`=mCw}?Vs(tDdiL}1c6,1?BCPi8HupBD1?oGtNUY~u_?Eb97L2FM3R!MIk,9=ZzNVq9vk,Id[9G5%qw}[email protected]~H^?0o~]Fhz_JT?6y$cswDcRLW~T+kgh7R?dC[s.0!5_xcs!_-5G][email protected]`Yz,jqGIP$ncHCyFod8PRGSan5d8*5cSAk&@&&=Mw(GqmChEH6=$5'[email protected]@8w!J(cf4HnN-^)[email protected]@`Z&,-*tj}bfO9Tac'$99g]{DIoG%'RuZ^[email protected](]+aQex11pe)svsnPk?(Iksl(!~3V~l}MOaAa69nOj`?Ao6BJPf}$j=O(!?IEfOp6tIbsRyh-EhNwj88W%]vQAQJnGWx'=8O6,@_m=}XWfulEU=853Ef&}=_MZH3T[o[[email protected]=h!*&)[email protected]+Sy`j4=6-)}4bz,[email protected]_!3U9doc(x8H!%[email protected]!6w5v,qY*t=MQ_=GW85-j^pU3TC`CH?SQRATtmoyA'j.S.d_o$?v=yUWY=IRwLR0jrWX68=]ms}[email protected]?l%+0FE?mn1vN^GV-pZL{__dqdS=9H=Tf1GBe`=uBJK}[email protected]?H([email protected]@[[email protected][i?C4T_gcmc~_o8O~$6PbA*JG)[email protected]_{(9HONFlgTJQ)5RZAB3HkP9&8TprN-av={[email protected][L,??7UcTy_cezXO!$4ysv(=UM55{piwB00O.&KP,[[email protected]~1vyCAS[[email protected]%ZA.X(Jm5omF1O(PVHMTWL?F^[email protected]{n=xkI4"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Last Update\IEXPLOREV4]
"CurrentVerTimestamp"="Sun, 21 April 1996 01:00:00 GMT"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Time Zones\Afghanistan Standard Time]
"Display"="(GMT+04:30) Kabul"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Time Zones\Alaskan Standard Time]
"Display"="(GMT-09:00) Alaska"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Time Zones\Arab Standard Time]
"Display"="(GMT+03:00) Kuwait, Riyadh"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Time Zones\Arabian Standard Time]
"Display"="(GMT+04:00) Abu Dhabi, Muscat"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Time Zones\Arabic Standard Time]
"Display"="(GMT+03:00) Baghdad"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Time Zones\Atlantic Standard Time]
"Display"="(GMT-04:00) Atlantic Time (Canada)"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Time Zones\AUS Central Standard Time]
"Display"="(GMT+09:30) Darwin"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Time Zones\AUS Eastern Standard Time]
"Display"="(GMT+10:00) Canberra, Melbourne, Sydney"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Time Zones\Azores Standard Time]
"Display"="(GMT-01:00) Azores"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Time Zones\Canada Central Standard Time]
"Display"="(GMT-06:00) Saskatchewan"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Time Zones\Cape Verde Standard Time]
"Display"="(GMT-01:00) Cape Verde Is."

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Time Zones\Caucasus Standard Time]
"Display"="(GMT+04:00) Baku, Tbilisi, Yerevan"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Time Zones\Cen. Australia Standard Time]
"Display"="(GMT+09:30) Adelaide"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Time Zones\Central America Standard Time]
"Display"="(GMT-06:00) Central America"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Time Zones\Central Asia Standard Time]
"Display"="(GMT+06:00) Astana, Dhaka"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Time Zones\Central Europe Standard Time]
"Display"="(GMT+01:00) Belgrade, Bratislava, Budapest, Ljubljana, Prague"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Time Zones\Central European Standard Time]
"Display"="(GMT+01:00) Sarajevo, Skopje, Warsaw, Zagreb"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Time Zones\Central Pacific Standard Time]
"Display"="(GMT+11:00) Magadan, Solomon Is., New Caledonia"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Time Zones\Central Standard Time]
"Display"="(GMT-06:00) Central Time (US & Canada)"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Time Zones\China Standard Time]
"Display"="(GMT+08:00) Beijing, Chongqing, Hong Kong, Urumqi"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Time Zones\Dateline Standard Time]
"Display"="(GMT-12:00) International Date Line West"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Time Zones\E. Africa Standard Time]
"Display"="(GMT+03:00) Nairobi"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Time Zones\E. Australia Standard Time]
"Display"="(GMT+10:00) Brisbane"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Time Zones\E. Europe Standard Time]
"Display"="(GMT+02:00) Bucharest"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Time Zones\E. South America Standard Time]
"Display"="(GMT-03:00) Brasilia"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Time Zones\Eastern Standard Time]
"Display"="(GMT-05:00) Eastern Time (US & Canada)"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Time Zones\Egypt Standard Time]
"Display"="(GMT+02:00) Cairo"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Time Zones\Ekaterinburg Standard Time]
"Display"="(GMT+05:00) Ekaterinburg"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Time Zones\Fiji Standard Time]
"Display"="(GMT+12:00) Fiji, Kamchatka, Marshall Is."

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Time Zones\FLE Standard Time]
"Display"="(GMT+02:00) Helsinki, Kyiv, Riga, Sofia, Tallinn, Vilnius"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Time Zones\GMT Standard Time]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Time Zones\GMT Standard Time]
"Display"="(GMT) Greenwich Mean Time : Dublin, Edinburgh, Lisbon, London"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Time Zones\GMT Standard Time]
"Dlt"="GMT Daylight Time"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Time Zones\GMT Standard Time]
"Std"="GMT Standard Time"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Time Zones\Greenland Standard Time]
"Display"="(GMT-03:00) Greenland"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Time Zones\Greenwich Standard Time]
"Display"="(GMT) Casablanca, Monrovia"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Time Zones\GTB Standard Time]
"Display"="(GMT+02:00) Athens, Beirut, Istanbul, Minsk"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Time Zones\Hawaiian Standard Time]
"Display"="(GMT-10:00) Hawaii"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Time Zones\India Standard Time]
"Display"="(GMT+05:30) Chennai, Kolkata, Mumbai, New Delhi"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Time Zones\Iran Standard Time]
"Display"="(GMT+03:30) Tehran"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Time Zones\Israel Standard Time]
"Display"="(GMT+02:00) Jerusalem"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Time Zones\Korea Standard Time]
"Display"="(GMT+09:00) Seoul"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Time Zones\Mexico Standard Time]
"Display"="(GMT-06:00) Guadalajara, Mexico City, Monterrey"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Time Zones\Mexico Standard Time 2]
"Display"="(GMT-07:00) Chihuahua, La Paz, Mazatlan"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Time Zones\Mid-Atlantic Standard Time]
"Display"="(GMT-02:00) Mid-Atlantic"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Time Zones\Mountain Standard Time]
"Display"="(GMT-07:00) Mountain Time (US & Canada)"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Time Zones\Myanmar Standard Time]
"Display"="(GMT+06:30) Rangoon"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Time Zones\N. Central Asia Standard Time]
"Display"="(GMT+06:00) Almaty, Novosibirsk"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Time Zones\Nepal Standard Time]
"Display"="(GMT+05:45) Kathmandu"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Time Zones\New Zealand Standard Time]
"Display"="(GMT+12:00) Auckland, Wellington"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Time Zones\Newfoundland Standard Time]
"Display"="(GMT-03:30) Newfoundland"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Time Zones\North Asia East Standard Time]
"Display"="(GMT+08:00) Irkutsk, Ulaan Bataar"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Time Zones\North Asia Standard Time]
"Display"="(GMT+07:00) Krasnoyarsk"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Time Zones\Pacific SA Standard Time]
"Display"="(GMT-04:00) Santiago"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Time Zones\Pacific Standard Time]
"Display"="(GMT-08:00) Pacific Time (US & Canada); Tijuana"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Time Zones\Romance Standard Time]
"Display"="(GMT+01:00) Brussels, Copenhagen, Madrid, Paris"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Time Zones\Russian Standard Time]
"Display"="(GMT+03:00) Moscow, St. Petersburg, Volgograd"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Time Zones\SA Eastern Standard Time]
"Display"="(GMT-03:00) Buenos Aires, Georgetown"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Time Zones\SA Pacific Standard Time]
"Display"="(GMT-05:00) Bogota, Lima, Quito"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Time Zones\SA Western Standard Time]
"Display"="(GMT-04:00) Caracas, La Paz"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Time Zones\Samoa Standard Time]
"Display"="(GMT-11:00) Midway Island, Samoa"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Time Zones\SE Asia Standard Time]
"Display"="(GMT+07:00) Bangkok, Hanoi, Jakarta"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Time Zones\Singapore Standard Time]
"Display"="(GMT+08:00) Kuala Lumpur, Singapore"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Time Zones\South Africa Standard Time]
"Display"="(GMT+02:00) Harare, Pretoria"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Time Zones\Sri Lanka Standard Time]
"Display"="(GMT+06:00) Sri Jayawardenepura"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Time Zones\Taipei Standard Time]
"Display"="(GMT+08:00) Taipei"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Time Zones\Tasmania Standard Time]
"Display"="(GMT+10:00) Hobart"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Time Zones\Tokyo Standard Time]
"Display"="(GMT+09:00) Osaka, Sapporo, Tokyo"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Time Zones\Tonga Standard Time]
"Display"="(GMT+13:00) Nuku'alofa"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Time Zones\US Eastern Standard Time]
"Display"="(GMT-05:00) Indiana (East)"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Time Zones\US Mountain Standard Time]
"Display"="(GMT-07:00) Arizona"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Time Zones\Vladivostok Standard Time]
"Display"="(GMT+10:00) Vladivostok"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Time Zones\W. Australia Standard Time]
"Display"="(GMT+08:00) Perth"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Time Zones\W. Central Africa Standard Time]
"Display"="(GMT+01:00) West Central Africa"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Time Zones\W. Europe Standard Time]
"Display"="(GMT+01:00) Amsterdam, Berlin, Bern, Rome, Stockholm, Vienna"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Time Zones\West Asia Standard Time]
"Display"="(GMT+05:00) Islamabad, Karachi, Tashkent"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Time Zones\West Pacific Standard Time]
"Display"="(GMT+10:00) Guam, Port Moresby"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Time Zones\Yakutsk Standard Time]
"Display"="(GMT+09:00) Yakutsk"

[HKEY_LOCAL_MACHINE\SOFTWARE\MusicMatch\MUSICMATCH Jukebox\SharedData\EReg]
"LastEreg"="Fri, 06 Aug 2004 00:02:00 GMT"

[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\MUILanguages\RCV2\appmgmts.dll]

[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\MUILanguages\RCV2\filemgmt.dll]

[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\MUILanguages\RCV2\schmmgmt.dll]

[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\MUILanguages\RCV2\winmgmt.exe]

[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\MUILanguages\RCV2\winmgmtr.dll]

[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\SafeBoot\Minimal\AppMgmt]

[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\SafeBoot\Minimal\WinMgmt]

[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\SafeBoot\Network\AppMgmt]

[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\SafeBoot\Network\WinMgmt]

[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\Root\LEGACY_APPMGMT]

[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\Root\LEGACY_APPMGMT\0000]

[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\Root\LEGACY_APPMGMT\0000]
"Service"="AppMgmt"

[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\Root\LEGACY_WINMGMT]

[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\Root\LEGACY_WINMGMT\0000]

[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\Root\LEGACY_WINMGMT\0000]
"Service"="winmgmt"

[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\Root\LEGACY_WINMGMT\0000\Control]

[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\Root\LEGACY_WINMGMT\0000\Control]
"ActiveService"="winmgmt"

[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\AppMgmt]

[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\AppMgmt\Parameters]

[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\AppMgmt\Security]

[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\AppMgmt\Enum]

[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\AppMgmt\Enum]
"0"="Root\\LEGACY_APPMGMT\\0000"

[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\Eventlog\Application\WinMgmt]

[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\Eventlog\System\i2omgmt]

[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\i2omgmt]

[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\winmgmt]

[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\winmgmt\Parameters]

[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\winmgmt\Security]

[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\winmgmt\Enum]

[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\winmgmt\Enum]
"0"="Root\\LEGACY_WINMGMT\\0000"

[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet003\Control\Nls\MUILanguages\RCV2\appmgmts.dll]

[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet003\Control\Nls\MUILanguages\RCV2\filemgmt.dll]

[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet003\Control\Nls\MUILanguages\RCV2\schmmgmt.dll]

[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet003\Control\Nls\MUILanguages\RCV2\winmgmt.exe]

[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet003\Control\Nls\MUILanguages\RCV2\winmgmtr.dll]

[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet003\Control\SafeBoot\Minimal\AppMgmt]

[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet003\Control\SafeBoot\Minimal\WinMgmt]

[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet003\Control\SafeBoot\Network\AppMgmt]

[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet003\Control\SafeBoot\Network\WinMgmt]

[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet003\Enum\Root\LEGACY_APPMGMT]

[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet003\Enum\Root\LEGACY_APPMGMT\0000]

[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet003\Enum\Root\LEGACY_APPMGMT\0000]
"Service"="AppMgmt"

[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet003\Enum\Root\LEGACY_WINMGMT]

[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet003\Enum\Root\LEGACY_WINMGMT\0000]

[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet003\Enum\Root\LEGACY_WINMGMT\0000]
"Service"="winmgmt"

[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet003\Services\AppMgmt]

[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet003\Services\AppMgmt\Parameters]

[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet003\Services\AppMgmt\Security]

[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet003\Services\Eventlog\Application\WinMgmt]

[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet003\Services\Eventlog\System\i2omgmt]

[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet003\Services\i2omgmt]

[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet003\Services\winmgmt]

[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet003\Services\winmgmt\Parameters]

[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet003\Services\winmgmt\Security]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Nls\MUILanguages\RCV2\appmgmts.dll]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Nls\MUILanguages\RCV2\filemgmt.dll]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Nls\MUILanguages\RCV2\schmmgmt.dll]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Nls\MUILanguages\RCV2\winmgmt.exe]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Nls\MUILanguages\RCV2\winmgmtr.dll]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\AppMgmt]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WinMgmt]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\AppMgmt]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\WinMgmt]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_APPMGMT]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_APPMGMT\0000]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_APPMGMT\0000]
"Service"="AppMgmt"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_WINMGMT]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_WINMGMT\0000]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_WINMGMT\0000]
"Service"="winmgmt"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_WINMGMT\0000\Control]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_WINMGMT\0000\Control]
"ActiveService"="winmgmt"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\AppMgmt]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\AppMgmt\Parameters]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\AppMgmt\Security]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\AppMgmt\Enum]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\AppMgmt\Enum]
"0"="Root\\LEGACY_APPMGMT\\0000"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Eventlog\Application\WinMgmt]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Eventlog\System\i2omgmt]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\i2omgmt]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\winmgmt]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\winmgmt\Parameters]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\winmgmt\Security]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\winmgmt\Enum]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\winmgmt\Enum]
"0"="Root\\LEGACY_WINMGMT\\0000"

And here is the scan for the uninstall list:
Ad-Aware SE Personal
Adobe Reader 6.0
AOL Instant Messenger
ArcSoft ShowBiz 2
ccCommon
CleanUp!
Cubasis VST 4
discWelder BRONZE
DivX
Easy Internet Sign-up
E-MU Audio Drivers
E-MU PatchMix DSP
ERUNT 1.1i
ewido security suite
HijackThis 1.99.1
HP Deskjet Preloaded Printer Drivers
HP Instant Support
HP Organize
HP Photo & Imaging 3.1
HP Photo and Imaging 2.0 - Photosmart Cameras
HP PSC & OfficeJet 3.0
HP Software Update
HPIZ311
Intel(R) Extreme Graphics Driver
IntelliMover Data Transfer Demo
Internet Worm Protection
InterVideo WinDVD Player
Java 2 Runtime Environment, SE v1.4.2
Lavasoft VX2 Cleaner
LimeWire 4.3.3
LiveReg (Symantec Corporation)
LiveUpdate 2.6 (Symantec Corporation)
Macromedia Flash Player 8
Macromedia Shockwave Player
Memories Disc Creator 2.0
Microsoft .NET Framework 1.1
Microsoft .NET Framework 1.1
Microsoft .NET Framework 1.1 Hotfix (KB886903)
Microsoft AntiSpyware
Microsoft Money 2004
Microsoft Money 2004 System Pack
Microsoft Office Standard Edition 2003
Microsoft Office XP Professional with FrontPage
Microsoft Plus! Digital Media Edition
Microsoft Works 7.0
mIRC
ML-1200 Series
MSN Music Assistant
Multimedia Card Reader
MUSICMATCH® Jukebox
My DSC
MyDSC_CIF
Native Instruments Traktor DJ Studio v2.6.1.022
Nero 6 Ultra Edition
Norton AntiVirus 2005
Norton AntiVirus 2005 (Symantec Corporation)
Norton AntiVirus Help
Norton AntiVirus Parent MSI
Norton AntiVirus SYMLT MSI
Norton WMI Update
Norton WMI Update
NVIDIA GART Driver
Panda ActiveScan
Photosmart 140,240,7200,7600,7700,7900 Series
Quicken 2004
QuickTime
RealOne Player
Reason
RecordNow!
Security Update for Step By Step Interactive Training (KB898458)
Security Update for Windows XP (KB883939)
Security Update for Windows XP (KB890046)
Security Update for Windows XP (KB893756)
Security Update for Windows XP (KB896358)
Security Update for Windows XP (KB896422)
Security Update for Windows XP (KB896423)
Security Update for Windows XP (KB896428)
Security Update for Windows XP (KB896688)
Security Update for Windows XP (KB899587)
Security Update for Windows XP (KB899588)
Security Update for Windows XP (KB899591)
Security Update for Windows XP (KB900725)
Security Update for Windows XP (KB901017)
Security Update for Windows XP (KB901214)
Security Update for Windows XP (KB902400)
Security Update for Windows XP (KB903235)
Security Update for Windows XP (KB904706)
Security Update for Windows XP (KB905414)
Security Update for Windows XP (KB905749)
SigmaTel MSCN Audio Player
Sony Sound Forge 7.0
SPBBC
Spybot - Search & Destroy 1.4
SpywareBlaster v3.4
Symantec
Symantec Script Blocking Installer
SymNet
Update for Windows XP (KB894391)
Update for Windows XP (KB896727)
Update for Windows XP (KB898461)
Updates from HP
VideoLAN VLC media player 0.8.2
Virtual DJ - Atomix Productions
WaveLab Lite
Winamp (remove only)
Windows Installer 3.1 (KB893803)
Windows Installer 3.1 (KB893803)
Windows Media Format Runtime
Windows Media Player 10
Windows XP Hotfix - KB834707
Windows XP Hotfix - KB867282
Windows XP Hotfix - KB873333
Windows XP Hotfix - KB873339
Windows XP Hotfix - KB885250
Windows XP Hotfix - KB885835
Windows XP Hotfix - KB885836
Windows XP Hotfix - KB885884
Windows XP Hotfix - KB886185
Windows XP Hotfix - KB887472
Windows XP Hotfix - KB887742
Windows XP Hotfix - KB888113
Windows XP Hotfix - KB888302
Windows XP Hotfix - KB890047
Windows XP Hotfix - KB890175
Windows XP Hotfix - KB890859
Windows XP Hotfix - KB890923
Windows XP Hotfix - KB891781
Windows XP Hotfix - KB893066
Windows XP Hotfix - KB893086
Windows XP Service Pack 2
WinRAR archiver
WinTools.net Classic
XviD MPEG-4 Video Codec
Yahoo! Messenger
Zone Deluxe Games
 
1 - 11 of 11 Posts
Status
Not open for further replies.
Top