PopUppeja ja poPUppeja sisältää hjt-lokin

Discussion in 'Virukset ja haittaohjelmat' started by k11u, Jan 31, 2006.

  1. k0ll1

    k0ll1 Member

    Joined:
    Sep 16, 2004
    Messages:
    24
    Likes Received:
    0
    Trophy Points:
    11
    Logfile of HijackThis v1.99.1
    Scan saved at 17:06:05, on 5.2.2006
    Platform: Windows XP SP1 (WinNT 5.01.2600)
    MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

    Running processes:
    C:\WINDOWS\System32\smss.exe
    C:\WINDOWS\system32\winlogon.exe
    C:\WINDOWS\system32\services.exe
    C:\WINDOWS\system32\lsass.exe
    C:\WINDOWS\System32\Ati2evxx.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\System32\svchost.exe
    C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
    C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
    C:\WINDOWS\system32\spoolsv.exe
    C:\WINDOWS\system32\Ati2evxx.exe
    C:\WINDOWS\Explorer.EXE
    C:\WINDOWS\SOUNDMAN.EXE
    C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
    C:\Program Files\Common Files\Symantec Shared\ccApp.exe
    C:\Program Files\DAEMON Tools\daemon.exe
    C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
    C:\WINDOWS\System32\ctfmon.exe
    C:\Program Files\MSN Messenger\msnmsgr.exe
    C:\Program Files\Messenger\msmsgs.exe
    C:\Program Files\VIA\RAID\raid_tool.exe
    C:\Program Files\ewido anti-malware\ewidoctrl.exe
    C:\Program Files\ewido anti-malware\ewidoguard.exe
    C:\Program Files\Norton AntiVirus\navapsvc.exe
    C:\Program Files\Norton AntiVirus\AdvTools\NPROTECT.EXE
    C:\Program Files\Norton AntiVirus\SAVScan.exe
    C:\WINDOWS\System32\svchost.exe
    C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
    C:\WINDOWS\system32\ZoneLabs\vsmon.exe
    C:\WINDOWS\System32\wuauclt.exe
    C:\WINDOWS\system32\rundll32.exe
    C:\Program Files\DC++\DCPlusPlus.exe
    C:\Program Files\Winamp\winamp.exe
    C:\Program Files\Mozilla Firefox\firefox.exe
    C:\Program Files\HijackThis.exe

    R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Linkit
    O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton AntiVirus\NavShExt.dll
    O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
    O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
    O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
    O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
    O4 - HKLM\..\Run: [Advanced Tools Check] C:\PROGRA~1\NORTON~1\AdvTools\ADVCHK.EXE
    O4 - HKLM\..\Run: [NeroCheck] C:\WINDOWS\System32\\NeroCheck.exe
    O4 - HKLM\..\Run: [Symantec NetDriver Monitor] C:\PROGRA~1\SYMNET~1\SNDMon.exe /Consumer
    O4 - HKLM\..\Run: [SSC_UserPrompt] C:\Program Files\Common Files\Symantec Shared\Security Center\UsrPrmpt.exe
    O4 - HKLM\..\Run: [DAEMON Tools] "C:\Program Files\DAEMON Tools\daemon.exe" -lang 1033
    O4 - HKLM\..\Run: [Zone Labs Client] C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
    O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\ctfmon.exe
    O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\MSN Messenger\msnmsgr.exe" /background
    O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
    O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
    O4 - Global Startup: raid_tool.exe.lnk = C:\Program Files\VIA\RAID\raid_tool.exe
    O17 - HKLM\System\CCS\Services\Tcpip\..\{63E2047B-FCB7-4251-8AA3-2658F3C23014}: NameServer = 212.50.131.153 213.139.190.3
    O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - "C:\PROGRA~1\MSNMES~1\msgrapp.dll" (file missing)
    O20 - Winlogon Notify: Uninstall - C:\WINDOWS\system32\lvro0993e.dll
    O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\System32\Ati2evxx.exe
    O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
    O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
    O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
    O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
    O23 - Service: ewido security suite control - ewido networks - C:\Program Files\ewido anti-malware\ewidoctrl.exe
    O23 - Service: ewido security suite guard - ewido networks - C:\Program Files\ewido anti-malware\ewidoguard.exe
    O23 - Service: Norton AntiVirus Auto Protect Service (navapsvc) - Symantec Corporation - C:\Program Files\Norton AntiVirus\navapsvc.exe
    O23 - Service: Norton Unerase Protection (NProtectService) - Symantec Corporation - C:\Program Files\Norton AntiVirus\AdvTools\NPROTECT.EXE
    O23 - Service: SAVScan - Symantec Corporation - C:\Program Files\Norton AntiVirus\SAVScan.exe
    O23 - Service: ScriptBlocking Service (SBService) - Symantec Corporation - C:\PROGRA~1\COMMON~1\SYMANT~1\SCRIPT~1\SBServ.exe
    O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
    O23 - Service: Symantec Core LC - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
    O23 - Service: SymWMI Service (SymWSC) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe
    O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs, LLC - C:\WINDOWS\system32\ZoneLabs\vsmon.exe

    L2MFIX find log 010406
    These are the registry keys present
    **********************************************************************************
    Winlogon/notify:
    Windows Registry Editor Version 5.00

    [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify]

    [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\AtiExtEvent]
    "DLLName"="Ati2evxx.dll"
    "Asynchronous"=dword:00000000
    "Impersonate"=dword:00000001
    "Lock"="AtiLockEvent"
    "Logoff"="AtiLogoffEvent"
    "Logon"="AtiLogonEvent"
    "Disconnect"="AtiDisConnectEvent"
    "Reconnect"="AtiReConnectEvent"
    "Safe"=dword:00000000
    "Shutdown"="AtiShutdownEvent"
    "StartScreenSaver"="AtiStartScreenSaverEvent"
    "StartShell"="AtiStartShellEvent"
    "Startup"="AtiStartupEvent"
    "StopScreenSaver"="AtiStopScreenSaverEvent"
    "Unlock"="AtiUnLockEvent"

    [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\crypt32chain]
    "Asynchronous"=dword:00000000
    "Impersonate"=dword:00000000
    "DllName"=hex(2):63,00,72,00,79,00,70,00,74,00,33,00,32,00,2e,00,64,00,6c,00,\
    6c,00,00,00
    "Logoff"="ChainWlxLogoffEvent"

    [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\cryptnet]
    "Asynchronous"=dword:00000000
    "Impersonate"=dword:00000000
    "DllName"=hex(2):63,00,72,00,79,00,70,00,74,00,6e,00,65,00,74,00,2e,00,64,00,\
    6c,00,6c,00,00,00
    "Logoff"="CryptnetWlxLogoffEvent"

    [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\cscdll]
    "DLLName"="cscdll.dll"
    "Logon"="WinlogonLogonEvent"
    "Logoff"="WinlogonLogoffEvent"
    "ScreenSaver"="WinlogonScreenSaverEvent"
    "Startup"="WinlogonStartupEvent"
    "Shutdown"="WinlogonShutdownEvent"
    "StartShell"="WinlogonStartShellEvent"
    "Impersonate"=dword:00000000
    "Asynchronous"=dword:00000001

    [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\ScCertProp]
    "DLLName"="wlnotify.dll"
    "Logon"="SCardStartCertProp"
    "Logoff"="SCardStopCertProp"
    "Lock"="SCardSuspendCertProp"
    "Unlock"="SCardResumeCertProp"
    "Enabled"=dword:00000001
    "Impersonate"=dword:00000001
    "Asynchronous"=dword:00000001

    [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\Schedule]
    "Asynchronous"=dword:00000000
    "DllName"=hex(2):77,00,6c,00,6e,00,6f,00,74,00,69,00,66,00,79,00,2e,00,64,00,\
    6c,00,6c,00,00,00
    "Impersonate"=dword:00000000
    "StartShell"="SchedStartShell"
    "Logoff"="SchedEventLogOff"

    [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\sclgntfy]
    "Logoff"="WLEventLogoff"
    "Impersonate"=dword:00000000
    "Asynchronous"=dword:00000001
    "DllName"=hex(2):73,00,63,00,6c,00,67,00,6e,00,74,00,66,00,79,00,2e,00,64,00,\
    6c,00,6c,00,00,00

    [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\SensLogn]
    "DLLName"="WlNotify.dll"
    "Lock"="SensLockEvent"
    "Logon"="SensLogonEvent"
    "Logoff"="SensLogoffEvent"
    "Safe"=dword:00000001
    "MaxWait"=dword:00000258
    "StartScreenSaver"="SensStartScreenSaverEvent"
    "StopScreenSaver"="SensStopScreenSaverEvent"
    "Startup"="SensStartupEvent"
    "Shutdown"="SensShutdownEvent"
    "StartShell"="SensStartShellEvent"
    "PostShell"="SensPostShellEvent"
    "Disconnect"="SensDisconnectEvent"
    "Reconnect"="SensReconnectEvent"
    "Unlock"="SensUnlockEvent"
    "Impersonate"=dword:00000001
    "Asynchronous"=dword:00000001

    [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\termsrv]
    "Asynchronous"=dword:00000000
    "DllName"=hex(2):77,00,6c,00,6e,00,6f,00,74,00,69,00,66,00,79,00,2e,00,64,00,\
    6c,00,6c,00,00,00
    "Impersonate"=dword:00000000
    "Logoff"="TSEventLogoff"
    "Logon"="TSEventLogon"
    "PostShell"="TSEventPostShell"
    "Shutdown"="TSEventShutdown"
    "StartShell"="TSEventStartShell"
    "Startup"="TSEventStartup"
    "MaxWait"=dword:00000258
    "Reconnect"="TSEventReconnect"
    "Disconnect"="TSEventDisconnect"

    [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\Uninstall]
    "Asynchronous"=dword:00000000
    "DllName"="C:\\WINDOWS\\system32\\lvro0993e.dll"
    "Impersonate"=dword:00000000
    "Logon"="WinLogon"
    "Logoff"="WinLogoff"
    "Shutdown"="WinShutdown"

    [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\wlballoon]
    "DLLName"="wlnotify.dll"
    "Logon"="RegisterTicketExpiredNotificationEvent"
    "Logoff"="UnregisterTicketExpiredNotificationEvent"
    "Impersonate"=dword:00000001
    "Asynchronous"=dword:00000001

    **********************************************************************************
    useragent:
    Windows Registry Editor Version 5.00

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\User Agent\Post Platform]
    "{A76D69E0-B875-D62C-F403-E17A849686D7}"=""

    **********************************************************************************
    Shell Extension key:
    Windows Registry Editor Version 5.00

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved]
    "{00022613-0000-0000-C000-000000000046}"="Multimediatiedoston ominaisuusikkuna"
    "{176d6597-26d3-11d1-b350-080036a75b03}"="ICM-kuvanlukijan hallinta"
    "{1F2E5C40-9550-11CE-99D2-00AA006E086C}"="NTFS-suojaussivu"
    "{3EA48300-8CF6-101B-84FB-666CCB9BCD32}"="OLE-asiakirjatiedoston ominaisuussivu"
    "{40dd6e20-7c17-11ce-a804-00aa003ca9f6}"="Liittym„laajennus jakamista varten"
    "{41E300E0-78B6-11ce-849B-444553540000}"="PlusPack CPL Extension"
    "{42071712-76d4-11d1-8b24-00a0c9068ff3}"="N„ytt”sovittimen CPL-laajennus"
    "{42071713-76d4-11d1-8b24-00a0c9068ff3}"="N„yt”n CPL -laajennus"
    "{42071714-76d4-11d1-8b24-00a0c9068ff3}"="Display Panning CPL -laajennus"
    "{4E40F770-369C-11d0-8922-00A024AB2DBB}"="Hakemistopalvelun suojaussivu"
    "{513D916F-2A8E-4F51-AEAB-0CBC76FB1AF8}"="Yhteensopivuussivusto"
    "{56117100-C0CD-101B-81E2-00AA004AE837}"="K„ytt”liittym„n leikkeidenk„sittelytoiminto"
    "{59099400-57FF-11CE-BD94-0020AF85B590}"="Levykkeen kopiointilaajennus"
    "{59be4990-f85c-11ce-aff7-00aa003ca9f6}"="Microsoft Windows -verkon objektien liittym„laajennukset"
    "{5DB2625A-54DF-11D0-B6C4-0800091AA605}"="ICM-n„yt”n hallinta"
    "{675F097E-4C4D-11D0-B6C1-0800091AA605}"="ICM-tulostimen hallinta"
    "{764BF0E1-F219-11ce-972D-00AA00A14F56}"="Tiedostonpakkauksen liittym„laajennukset"
    "{77597368-7b15-11d0-a0c2-080036af3f03}"="Web-tulostimen liittym„laajennus"
    "{7988B573-EC89-11cf-9C00-00AA00A14F56}"="Disk Quota UI"
    "{853FE2B1-B769-11d0-9C4E-00C04FB6C6FA}"="Salauksen pikavalikko"
    "{85BBD920-42A0-1069-A2E4-08002B30309D}"="Salkku"
    "{88895560-9AA2-1069-930E-00AA0030EBC8}"="HyperTerminal-kuvakkeen tunniste"
    "{BD84B380-8CA2-1069-AB1D-08000948F534}"="Fonts"
    "{DBCE2480-C732-101B-BE72-BA78E9AD5B27}"="ICC-profiili"
    "{F37C5810-4D3F-11d0-B4BF-00AA00BBB723}"="Tulostimen suojaussivu"
    "{f81e9010-6ea4-11ce-a7ff-00aa003ca9f6}"="Liittym„laajennus jakamista varten"
    "{f92e8c40-3d33-11d2-b1aa-080036a75b03}"="Display TroubleShoot CPL Extension"
    "{7444C717-39BF-11D1-8CD9-00C04FC29D45}"="Crypto PKO -laajennus"
    "{7444C719-39BF-11D1-8CD9-00C04FC29D45}"="Crypto Sign -laajennus"
    "{7007ACC7-3202-11D1-AAD2-00805FC1270E}"="Verkkoyhteydet"
    "{992CFFA0-F557-101A-88EC-00DD010CCC48}"="Verkkoyhteydet"
    "{E211B736-43FD-11D1-9EFB-0000F8757FCD}"="Skannerit ja kamerat"
    "{FB0C9C8A-6C50-11D1-9F1D-0000F8757FCD}"="Skannerit ja kamerat"
    "{905667aa-acd6-11d2-8080-00805f6596d2}"="Skannerit ja kamerat"
    "{3F953603-1008-4f6e-A73A-04AAC7A992F1}"="Skannerit ja kamerat"
    "{83bbcbf3-b28a-4919-a5aa-73027445d672}"="Skannerit ja kamerat"
    "{F0152790-D56E-4445-850E-4F3117DB740C}"="Remote Sessions CPL Extension"
    "{5F327514-6C5E-4d60-8F16-D07FA08A78ED}"="Auto Update Property Sheet Extension"
    "{60254CA5-953B-11CF-8C96-00AA00B8708C}"="Windows Script Hostin liittym„laajennukset"
    "{2206CDB2-19C1-11D1-89E0-00C04FD7A829}"="Microsoft-tietolinkki"
    "{DD2110F0-9EEF-11cf-8D8E-00AA0060F5BF}"="Tasks Folder Icon Handler"
    "{797F1E90-9EDD-11cf-8D8E-00AA0060F5BF}"="Tasks Folder Shell Extension"
    "{D6277990-4C6A-11CF-8D87-00AA0060F5BF}"="Ajoitetut teht„v„t"
    "{0DF44EAA-FF21-4412-828E-260A8728E7F1}"="Teht„v„palkki ja K„ynnist„-valikko"
    "{2559a1f0-21d7-11d4-bdaf-00c04f60b9f0}"="Etsi"
    "{2559a1f1-21d7-11d4-bdaf-00c04f60b9f0}"="Ohje ja tuki"
    "{2559a1f2-21d7-11d4-bdaf-00c04f60b9f0}"="Ohje ja tuki"
    "{2559a1f3-21d7-11d4-bdaf-00c04f60b9f0}"="Suorita..."
    "{2559a1f4-21d7-11d4-bdaf-00c04f60b9f0}"="Internet"
    "{2559a1f5-21d7-11d4-bdaf-00c04f60b9f0}"="S„hk”posti"
    "{D20EA4E1-3957-11d2-A40B-0C5020524152}"="Fontit"
    "{D20EA4E1-3957-11d2-A40B-0C5020524153}"="Valvontaty”kalut"
    "{875CB1A1-0F29-45de-A1AE-CFB4950D0B78}"="Audio Media Properties Handler"
    "{40C3D757-D6E4-4b49-BB41-0E5BBEA28817}"="Video Media Properties Handler"
    "{E4B29F9D-D390-480b-92FD-7DDB47101D71}"="Wav Properties Handler"
    "{87D62D94-71B3-4b9a-9489-5FE6850DC73E}"="Avi Properties Handler"
    "{A6FD9E45-6E44-43f9-8644-08598F5A74D9}"="Midi Properties Handler"
    "{c5a40261-cd64-4ccf-84cb-c394da41d590}"="Video Thumbnail Extractor"
    "{5E6AB780-7743-11CF-A12B-00AA004AE837}"="Microsoft Internet-ty”kalurivi"
    "{22BF0C20-6DA7-11D0-B373-00A0C9034938}"="Lataamisen tila"
    "{91EA3F8B-C99B-11d0-9815-00C04FD91972}"="Augmented Shell Folder"
    "{6413BA2C-B461-11d1-A18A-080036B11A03}"="Augmented Shell Folder 2"
    "{F61FFEC1-754F-11d0-80CA-00AA005B4383}"="BandProxy"
    "{7BA4C742-9E81-11CF-99D3-00AA004AE837}"="Microsoft BrowserBand"
    "{30D02401-6A81-11d0-8274-00C04FD5AE38}"="Etsint„palkki"
    "{32683183-48a0-441b-a342-7c2a440a9478}"="Media-palkki"
    "{169A0691-8DF9-11d1-A1C4-00C04FD75D13}"="In-pane search"
    "{07798131-AF23-11d1-9111-00A0C98BA67D}"="Web Search"
    "{AF4F6510-F982-11d0-8595-00AA004CD6D8}"="Registry Tree Options Utility"
    "{01E04581-4EEE-11d0-BFE9-00AA005B4383}"="&L„hiosoite"
    "{A08C11D2-A228-11d0-825B-00AA005B4383}"="Address EditBox"
    "{00BB2763-6A77-11D0-A535-00C04FD7D062}"="Microsoft AutoComplete"
    "{7376D660-C583-11d0-A3A5-00C04FD706EC}"="TridentImageExtractor"
    "{6756A641-DE71-11d0-831B-00AA005B4383}"="MRU AutoComplete List"
    "{6935DB93-21E8-4ccc-BEB9-9FE3C77A297A}"="Custom MRU AutoCompleted List"
    "{7e653215-fa25-46bd-a339-34a2790f3cb7}"="Accessible"
    "{acf35015-526e-4230-9596-becbe19f0ac9}"="Track Popup Bar"
    "{E0E11A09-5CB8-4B6C-8332-E00720A168F2}"="Osoitepalkin j„sent„j„"
    "{00BB2764-6A77-11D0-A535-00C04FD7D062}"="Microsoft History AutoComplete List"
    "{03C036F1-A186-11D0-824A-00AA005B4383}"="Microsoft Shell Folder AutoComplete List"
    "{00BB2765-6A77-11D0-A535-00C04FD7D062}"="Microsoft Multiple AutoComplete List Container"
    "{ECD4FC4E-521C-11D0-B792-00A0C90312E1}"="Shell Band Site Menu"
    "{3CCF8A41-5C85-11d0-9796-00AA00B90ADF}"="Shell DeskBarApp"
    "{ECD4FC4C-521C-11D0-B792-00A0C90312E1}"="Shell DeskBar"
    "{ECD4FC4D-521C-11D0-B792-00A0C90312E1}"="Shell Rebar BandSite"
    "{DD313E04-FEFF-11d1-8ECD-0000F87A470C}"="User Assist"
    "{EF8AD2D1-AE36-11D1-B2D2-006097DF8C11}"="Global Folder Settings"
    "{EFA24E61-B078-11d0-89E4-00C04FC9E26E}"="Favorites Band"
    "{0A89A860-D7B1-11CE-8350-444553540000}"="Shell Automation Inproc Service"
    "{E7E4BC40-E76A-11CE-A9BB-00AA004AE837}"="Shell DocObject Viewer"
    "{A5E46E3A-8849-11D1-9D8C-00C04FC99D61}"="Microsoft Browser Architecture"
    "{FBF23B40-E3F0-101B-8488-00AA003E56F8}"="InternetShortcut"
    "{3C374A40-BAE4-11CF-BF7D-00AA006946EE}"="Microsoft Url History Service"
    "{FF393560-C2A7-11CF-BFF4-444553540000}"="Sivuhistoria"
    "{7BD29E00-76C1-11CF-9DD0-00A0C9034933}"="Temporary Internet Files"
    "{7BD29E01-76C1-11CF-9DD0-00A0C9034933}"="Temporary Internet Files"
    "{CFBFAE00-17A6-11D0-99CB-00C04FD64497}"="Microsoft Url Search Hook"
    "{A2B0DD40-CC59-11d0-A3A5-00C04FD706EC}"="IE4 Suite Splash Screen"
    "{67EA19A0-CCEF-11d0-8024-00C04FD75D13}"="CDF Extension Copy Hook"
    "{131A6951-7F78-11D0-A979-00C04FD705A2}"="ISFBand OC"
    "{9461b922-3c5a-11d2-bf8b-00c04fb93661}"="Search Assistant OC"
    "{3DC7A020-0ACD-11CF-A9BB-00AA004AE837}"="Internet"
    "{871C5380-42A0-1069-A2EA-08002B30309D}"="Internet Name Space"
    "{EFA24E64-B078-11d0-89E4-00C04FC9E26E}"="Explorer Band"
    "{9E56BE60-C50F-11CF-9A2C-00A0C90A90CE}"="Sendmail service"
    "{9E56BE61-C50F-11CF-9A2C-00A0C90A90CE}"="Sendmail service"
    "{88C6C381-2E85-11D0-94DE-444553540000}"="ActiveX-v„limuistikansio"
    "{E6FB5E20-DE35-11CF-9C87-00AA005127ED}"="WebCheck"
    "{ABBE31D0-6DAE-11D0-BECA-00C04FD940BE}"="Subscription Mgr"
    "{F5175861-2688-11d0-9C5E-00AA00A45957}"="Subscription Folder"
    "{08165EA0-E946-11CF-9C87-00AA005127ED}"="WebCheckWebCrawler"
    "{E3A8BDE6-ABCE-11d0-BC4B-00C04FD929DB}"="WebCheckChannelAgent"
    "{E8BB6DC0-6B4E-11d0-92DB-00A0C90C2BD7}"="TrayAgent"
    "{7D559C10-9FE9-11d0-93F7-00AA0059CE02}"="Code Download Agent"
    "{E6CC6978-6B6E-11D0-BECA-00C04FD940BE}"="ConnectionAgent"
    "{D8BD2030-6FC9-11D0-864F-00AA006809D9}"="PostAgent"
    "{7FC0B86E-5FA7-11d1-BC7C-00C04FD929DB}"="WebCheck SyncMgr Handler"
    "{352EC2B7-8B9A-11D1-B8AE-006008059382}"="K„ytt”liittym„n sovelluksenhallintaohjelma"
    "{0B124F8F-91F0-11D1-B8B5-006008059382}"="Sovellusluettelo asennettiin"
    "{CFCCC7A0-A282-11D1-9082-006008059382}"="Darwin App Publisher"
    "{e84fda7c-1d6a-45f6-b725-cb260c236066}"="Shell Image Verbs"
    "{66e4e4fb-f385-4dd0-8d74-a2efd1bc6178}"="Shell Image Data Factory"
    "{3F30C968-480A-4C6C-862D-EFC0897BB84B}"="GDI+ -tiedoston pikkukuvan purkaja"
    "{9DBD2C50-62AD-11d0-B806-00C04FD706EC}"="Yhteenvetotiedot pikkukuvien k„sittelyst„ (DOCFILES)"
    "{EAB841A0-9550-11cf-8C16-00805F1408F3}"="HTML-pikkukuvien purkuohjelma"
    "{eb9b1153-3b57-4e68-959a-a3266bc3d7fe}"="Shell Image Property Handler"
    "{CC6EEFFB-43F6-46c5-9619-51D571967F7D}"="Ohjattu Web-julkaisutoiminto"
    "{add36aa8-751a-4579-a266-d66f5202ccbb}"="Valokuvien paperikopioiden tilaaminen Internetist„"
    "{6b33163c-76a5-4b6c-bf21-45de9cd503a1}"="Shell Publishing Wizard Object"
    "{58f1f272-9240-4f51-b6d4-fd63d1618591}"="Ohjattu Passport toiminto"
    "{7A9D77BD-5403-11d2-8785-2E0420524153}"="K„ytt„j„tilit"
    "{BD472F60-27FA-11cf-B8B4-444553540000}"="Compressed (zipped) Folder Right Drag Handler"
    "{888DCA60-FC0A-11CF-8F0F-00C04FD7D062}"="Compressed (zipped) Folder SendTo Target"
    "{f39a0dc0-9cc8-11d0-a599-00c04fd64433}"="Kanavatiedosto"
    "{f3aa0dc0-9cc8-11d0-a599-00c04fd64434}"="Kanavan pikakuvake"
    "{f3ba0dc0-9cc8-11d0-a599-00c04fd64435}"="Kanavienk„sittelyobjekti"
    "{f3da0dc0-9cc8-11d0-a599-00c04fd64437}"="Channel Menu"
    "{f3ea0dc0-9cc8-11d0-a599-00c04fd64438}"="Channel Properties"
    "{63da6ec0-2e98-11cf-8d82-444553540000}"="FTP Folders Webview"
    "{883373C3-BF89-11D1-BE35-080036B11A03}"="Microsoft DocProp Shell Ext"
    "{A9CF0EAE-901A-4739-A481-E35B73E47F6D}"="Microsoft DocProp Inplace Edit Box Control"
    "{8EE97210-FD1F-4B19-91DA-67914005F020}"="Microsoft DocProp Inplace ML Edit Box Control"
    "{0EEA25CC-4362-4A12-850B-86EE61B0D3EB}"="Microsoft DocProp Inplace Droplist Combo Control"
    "{6A205B57-2567-4A2C-B881-F787FAB579A3}"="Microsoft DocProp Inplace Calendar Control"
    "{28F8A4AC-BBB3-4D9B-B177-82BFC914FA33}"="Microsoft DocProp Inplace Time Control"
    "{8A23E65E-31C2-11d0-891C-00A024AB2DBB}"="Directory Query UI"
    "{9E51E0D0-6E0F-11d2-9601-00C04FA31A86}"="Shell properties for a DS object"
    "{163FDC20-2ABC-11d0-88F0-00A024AB2DBB}"="Directory Object Find"
    "{F020E586-5264-11d1-A532-0000F8757D7E}"="Directory Start/Search Find"
    "{0D45D530-764B-11d0-A1CA-00AA00C16E65}"="Directory Property UI"
    "{62AE1F9A-126A-11D0-A14B-0800361B1103}"="Directory Context Menu Verbs"
    "{ECF03A33-103D-11d2-854D-006008059367}"="MyDocs Copy Hook"
    "{ECF03A32-103D-11d2-854D-006008059367}"="MyDocs Drop Target"
    "{4a7ded0a-ad25-11d0-98a8-0800361b1103}"="MyDocs Properties"
    "{750fdf0e-2a26-11d1-a3ea-080036587f03}"="Offline Files Menu"
    "{10CFC467-4392-11d2-8DB4-00C04FA31A66}"="Offline Files Folder Options"
    "{AFDB1F70-2A4C-11d2-9039-00C04F8EEB3E}"="Offline-tiedostot-kansio"
    "{143A62C8-C33B-11D1-84FE-00C04FA34A14}"="Microsoft Agent Character Property Sheet Handler"
    "{ECCDF543-45CC-11CE-B9BF-0080C87CDBA6}"="DfsShell"
    "{60fd46de-f830-4894-a628-6fa81bc0190d}"="%DESC_PublishDropTarget%"
    "{7A80E4A8-8005-11D2-BCF8-00C04F72C717}"="MMC Icon Handler"
    "{0CD7A5C0-9F37-11CE-AE65-08002B2E1262}"=".CAB file viewer"
    "{32714800-2E5F-11d0-8B85-00AA0044F941}"="&Henkil”it„..."
    "{8DD448E6-C188-4aed-AF92-44956194EB1F}"="Windows Media Player Play as Playlist Context Menu Handler"
    "{CE3FB1D1-02AE-4a5f-A6E9-D9F1B4073E6C}"="Windows Media Player Burn Audio CD Context Menu Handler"
    "{F1B9284F-E9DC-4e68-9D7E-42362A59F0FD}"="Windows Media Player Add to Playlist Context Menu Handler"
    "{B41DB860-8EE4-11D2-9906-E49FADC173CA}"="WinRAR shell extension"
    "{1758B32E-2E87-411E-95F0-659C00514DF3}"=""
    "{C592235A-A58C-48DC-B62C-AB7BCB2BB3F4}"=""
    "{CA9EFBE9-E915-4ADA-B115-1F7E75BEC560}"=""
    "{5966568C-7D19-4098-AE83-C9D46F73BD2C}"=""
    "{BCF73381-7CB5-43D5-9048-1CE2471A68D4}"=""
    "{3A536D8A-FBA6-4A65-9777-E1BD633285CA}"=""
    "{CFA1E0E2-BF37-48CD-9F58-872A1AEB71A8}"=""
    "{7E4B99A9-B84D-482B-B53E-34CD661D7DE4}"=""
    "{ED578B3D-8C32-412E-9B6B-125D5997419A}"=""
    "{EABD618D-E32B-4E42-B7CD-C0D5CEF8D4C6}"=""
    "{5A431CDF-C97C-436C-ABD3-2C157A20323C}"=""
    "{553563DE-F8D3-4330-9117-82FF449A4CC0}"=""
    "{640167b4-59b0-47a6-b335-a6b3c0695aea}"="Portable Media Devices"
    "{cc86590a-b60a-48e6-996b-41d25ed39a1e}"="Portable Media Devices Menu"
    "{8910A239-345F-4917-B5A5-480F69267EDA}"=""
    "{502EFDB7-E7AB-44FC-8F9C-B519B8E0D8D0}"=""
    "{416DEC8D-D387-4D43-ACBB-A1F41079FEA4}"=""
    "{922B5BF5-7756-4228-B71A-039B8B8A22AE}"=""
    "{7B7438AB-C7C8-4622-A4D4-033EFB8DAEB1}"=""
    "{AF730DDA-AC7C-4054-BDDC-1060337C1218}"=""
    "{452229D1-C11F-4F7C-B6B8-9F456A96CA8C}"=""
    "{4B0A3EFE-CD45-4B85-AAAF-BF6A03AE6128}"=""
    "{A1B72B3F-50F0-467B-A1FA-35F79A3DC2DC}"=""
    "{802BF23C-470B-41DE-A6B0-381587EA7037}"=""
    "{9592BB1B-E337-404E-9CF3-2735CD85AE67}"=""
    "{A18C479B-53B1-4C66-8DFE-9E88A6E04417}"=""
    "{2E03477B-F05D-47F2-A00A-15F867AACE60}"=""
    "{BE3DF3FB-8B4D-4218-856D-B14691C624C8}"=""
    "{C68F1017-3F12-406A-B1E6-607641395690}"=""
    "{2B119913-7FA4-4B36-BE31-4A2B222D00EE}"=""
    "{DD14D17A-B367-4B13-AFCE-FF0B86EA0115}"=""
    "{086B79D8-C1FE-4A88-B025-1D12670386D4}"=""
    "{BF570010-C329-44C4-9076-70DC09D1F657}"=""
    "{FEF43FF9-8C73-45F6-8FD1-1B7CF1E91AE6}"=""
    "{7D00103A-4B7C-4A92-A168-E115A4B5BB62}"=""
    "{3B886085-E276-40BC-88BC-C4C2E65CFB2F}"=""
    "{A905FB3E-425A-4C86-9424-BCC2F7E26CB3}"=""
    "{E111B4A6-42C0-4BC6-BC9C-7171A7978740}"=""
    "{86C43321-E4A9-45A4-8E68-16C30932260F}"=""
    "{06005505-0EC7-483C-827F-F94B2BA27010}"=""
    "{61DC2AF4-EB96-4DB7-A6B2-5C736795491E}"=""
    "{2549F884-AA3F-465B-B0F1-2DC3FBBA5FDC}"=""
    "{989EAC39-8B82-4278-9CA6-63874E559300}"=""
    "{768ED112-0A46-41F4-BEEB-E22D89FFFCA7}"=""
    "{2239C763-740F-4B97-806C-529646F59991}"=""
    "{F34A41CF-EAB4-47EF-A42C-A836E83FF61D}"=""
    "{4DF09495-0324-42E2-AACC-7E1A0D0ABB4A}"=""
    "{2A66DD17-C378-456E-8D5E-41BB93D2FCDC}"=""
    "{77239875-4AA2-4412-9308-E2D751BA476C}"=""
    "{E1D27203-690B-4C7D-A388-D1A9F5D84808}"=""
    "{C4CA3BE6-76A1-4C15-9A5A-0D8519C8AC4E}"=""
    "{4744A88A-27F0-40FA-AE76-75D9650884E2}"=""
    "{5C3A5019-70E9-4876-BF44-F6AFB0951A89}"=""
    "{DB29EC55-273E-494C-BA9E-638B93144B61}"=""
    "{C6F6E1E1-B213-44DB-AB5D-4D79DFB209DD}"=""
    "{E88EAE69-22F3-4119-9AA5-6DB6D9C620A2}"=""
    "{35A3BDF2-A729-40AB-98A8-3A0A21C2D401}"=""
    "{26EF4751-8CAD-4110-8EDC-6C808BF33696}"=""
    "{A3E8A66B-5D52-47AD-ADCC-451F85DB28A0}"=""
    "{81E180E6-D6E9-457B-B148-6B2696E40478}"=""
    "{6547E428-2EC0-4A08-AA07-299EF6FDA51F}"=""
    "{97D68211-1408-461A-80AC-A15CF76AFD99}"=""
    "{8AEEED30-5FF4-4874-9C71-0C42E50B42E6}"=""
    "{B30D2E85-CD34-4BE6-AD46-8BE283060FF7}"=""
    "{3547F6B3-CEF1-467A-AEAE-30478F77C942}"=""
    "{F9819CEA-11EB-4AE0-AA39-01E59BFCDF46}"=""
    "{02A454BC-4AC9-4D05-97B8-2DEB97F038A7}"=""
    "{66BF9F29-5C6A-43EC-A4DB-4FBB578F63D7}"=""
    "{317EE681-0BE2-45E3-9177-405F7BFAC143}"=""
    "{A01A9184-A87D-44F4-8DE2-CBBD967D9324}"=""
    "{5D25C076-EF64-459A-AFE9-458A789792AD}"=""
    "{12DF87D4-8CA8-4C20-80A2-0C7E1B21BA13}"=""
    "{4F000194-AA18-44A3-BE03-E678E123E5B1}"=""
    "{4EC01F12-1D77-41A1-9947-E0A9F71B20AA}"=""
    "{FA5C95FB-1E5B-4B05-B451-1B1083C6A9B1}"=""
    "{DCD99A13-1B9A-4912-9A8D-85A04CA33CC6}"=""
    "{5A025223-DC53-4A8D-85A0-ADFB8B2FAE9A}"=""
    "{447423E8-D11B-4446-9120-7276216A40CE}"=""
    "{5EC92A5A-0848-4963-BC3C-7AA14C23327B}"=""
    "{238CB486-647C-4B88-9FFB-4142585F8A81}"=""
    "{2F87EC4D-0115-4D77-BA2E-0C557B88D36F}"=""
    "{CD74549F-60D3-44DE-AE57-22BFB5237EEA}"=""
    "{16B9AF1D-E035-49F3-A0C0-A6D9BA00CDD8}"=""
    "{6D0E8A2D-BAB7-4417-924F-6388797DF420}"=""
    "{88B640AA-BBB5-47EF-8077-620A973AAD0B}"=""
    "{CE84CD16-3D8A-424C-A652-C7382A1C0BB2}"=""
    "{E8468BA0-63A8-4BBF-8D77-DCD5DC033FCB}"=""
    "{D9A5F243-70DB-4E79-9224-E7C15B2B821D}"=""
    "{84FCB1BC-6756-4DD2-9A67-69F3118CAD81}"=""
    "{2B320E0D-0F07-402F-9C5F-23F05F0755CE}"=""
    "{AE55B1B6-A5FA-4AAC-B52C-D4A5EB6F30D3}"=""

    **********************************************************************************
    HKEY ROOT CLASSIDS:
    Windows Registry Editor Version 5.00

    [HKEY_CLASSES_ROOT\CLSID\{1758B32E-2E87-411E-95F0-659C00514DF3}]
    @=""
    "IDEx"="ADDR"

    [HKEY_CLASSES_ROOT\CLSID\{1758B32E-2E87-411E-95F0-659C00514DF3}\Implemented Categories]
    @=""

    [HKEY_CLASSES_ROOT\CLSID\{1758B32E-2E87-411E-95F0-659C00514DF3}\Implemented Categories\{00021492-0000-0000-C000-000000000046}]
    @=""

    [HKEY_CLASSES_ROOT\CLSID\{1758B32E-2E87-411E-95F0-659C00514DF3}\InprocServer32]
    @="C:\\WINDOWS\\system32\\AQIDDC.DLL"
    "ThreadingModel"="Apartment"

    Windows Registry Editor Version 5.00

    [HKEY_CLASSES_ROOT\CLSID\{C592235A-A58C-48DC-B62C-AB7BCB2BB3F4}]
    @=""

    [HKEY_CLASSES_ROOT\CLSID\{C592235A-A58C-48DC-B62C-AB7BCB2BB3F4}\Implemented Categories]
    @=""

    [HKEY_CLASSES_ROOT\CLSID\{C592235A-A58C-48DC-B62C-AB7BCB2BB3F4}\Implemented Categories\{00021492-0000-0000-C000-000000000046}]
    @=""

    [HKEY_CLASSES_ROOT\CLSID\{C592235A-A58C-48DC-B62C-AB7BCB2BB3F4}\InprocServer32]
    @="C:\\WINDOWS\\system32\\ayrsvc.dll"
    "ThreadingModel"="Apartment"

    Windows Registry Editor Version 5.00

    [HKEY_CLASSES_ROOT\CLSID\{CA9EFBE9-E915-4ADA-B115-1F7E75BEC560}]
    @=""

    [HKEY_CLASSES_ROOT\CLSID\{CA9EFBE9-E915-4ADA-B115-1F7E75BEC560}\Implemented Categories]
    @=""

    [HKEY_CLASSES_ROOT\CLSID\{CA9EFBE9-E915-4ADA-B115-1F7E75BEC560}\Implemented Categories\{00021492-0000-0000-C000-000000000046}]
    @=""

    [HKEY_CLASSES_ROOT\CLSID\{CA9EFBE9-E915-4ADA-B115-1F7E75BEC560}\InprocServer32]
    @="C:\\WINDOWS\\system32\\rgpcfgex.dll"
    "ThreadingModel"="Apartment"

    Windows Registry Editor Version 5.00

    [HKEY_CLASSES_ROOT\CLSID\{5966568C-7D19-4098-AE83-C9D46F73BD2C}]
    @=""

    [HKEY_CLASSES_ROOT\CLSID\{5966568C-7D19-4098-AE83-C9D46F73BD2C}\Implemented Categories]
    @=""

    [HKEY_CLASSES_ROOT\CLSID\{5966568C-7D19-4098-AE83-C9D46F73BD2C}\Implemented Categories\{00021492-0000-0000-C000-000000000046}]
    @=""

    [HKEY_CLASSES_ROOT\CLSID\{5966568C-7D19-4098-AE83-C9D46F73BD2C}\InprocServer32]
    @="C:\\WINDOWS\\system32\\fgdrclnr.dll"
    "ThreadingModel"="Apartment"

    Windows Registry Editor Version 5.00

    [HKEY_CLASSES_ROOT\CLSID\{BCF73381-7CB5-43D5-9048-1CE2471A68D4}]
    @=""

    [HKEY_CLASSES_ROOT\CLSID\{BCF73381-7CB5-43D5-9048-1CE2471A68D4}\Implemented Categories]
    @=""

    [HKEY_CLASSES_ROOT\CLSID\{BCF73381-7CB5-43D5-9048-1CE2471A68D4}\Implemented Categories\{00021492-0000-0000-C000-000000000046}]
    @=""

    [HKEY_CLASSES_ROOT\CLSID\{BCF73381-7CB5-43D5-9048-1CE2471A68D4}\InprocServer32]
    @="C:\\WINDOWS\\system32\\kldgae.dll"
    "ThreadingModel"="Apartment"

    Windows Registry Editor Version 5.00

    [HKEY_CLASSES_ROOT\CLSID\{3A536D8A-FBA6-4A65-9777-E1BD633285CA}]
    @=""

    [HKEY_CLASSES_ROOT\CLSID\{3A536D8A-FBA6-4A65-9777-E1BD633285CA}\Implemented Categories]
    @=""

    [HKEY_CLASSES_ROOT\CLSID\{3A536D8A-FBA6-4A65-9777-E1BD633285CA}\Implemented Categories\{00021492-0000-0000-C000-000000000046}]
    @=""

    [HKEY_CLASSES_ROOT\CLSID\{3A536D8A-FBA6-4A65-9777-E1BD633285CA}\InprocServer32]
    @="C:\\WINDOWS\\system32\\wln32spl.dll"
    "ThreadingModel"="Apartment"

    Windows Registry Editor Version 5.00

    [HKEY_CLASSES_ROOT\CLSID\{CFA1E0E2-BF37-48CD-9F58-872A1AEB71A8}]
    @=""

    [HKEY_CLASSES_ROOT\CLSID\{CFA1E0E2-BF37-48CD-9F58-872A1AEB71A8}\Implemented Categories]
    @=""

    [HKEY_CLASSES_ROOT\CLSID\{CFA1E0E2-BF37-48CD-9F58-872A1AEB71A8}\Implemented Categories\{00021492-0000-0000-C000-000000000046}]
    @=""

    [HKEY_CLASSES_ROOT\CLSID\{CFA1E0E2-BF37-48CD-9F58-872A1AEB71A8}\InprocServer32]
    @="C:\\WINDOWS\\system32\\rppcfgex.dll"
    "ThreadingModel"="Apartment"

    Windows Registry Editor Version 5.00

    [HKEY_CLASSES_ROOT\CLSID\{7E4B99A9-B84D-482B-B53E-34CD661D7DE4}]
    @=""

    [HKEY_CLASSES_ROOT\CLSID\{7E4B99A9-B84D-482B-B53E-34CD661D7DE4}\Implemented Categories]
    @=""

    [HKEY_CLASSES_ROOT\CLSID\{7E4B99A9-B84D-482B-B53E-34CD661D7DE4}\Implemented Categories\{00021492-0000-0000-C000-000000000046}]
    @=""

    [HKEY_CLASSES_ROOT\CLSID\{7E4B99A9-B84D-482B-B53E-34CD661D7DE4}\InprocServer32]
    @="C:\\WINDOWS\\system32\\natapi32.dll"
    "ThreadingModel"="Apartment"

    Windows Registry Editor Version 5.00

    [HKEY_CLASSES_ROOT\CLSID\{ED578B3D-8C32-412E-9B6B-125D5997419A}]
    @=""

    [HKEY_CLASSES_ROOT\CLSID\{ED578B3D-8C32-412E-9B6B-125D5997419A}\Implemented Categories]
    @=""

    [HKEY_CLASSES_ROOT\CLSID\{ED578B3D-8C32-412E-9B6B-125D5997419A}\Implemented Categories\{00021492-0000-0000-C000-000000000046}]
    @=""

    [HKEY_CLASSES_ROOT\CLSID\{ED578B3D-8C32-412E-9B6B-125D5997419A}\InprocServer32]
    @="C:\\WINDOWS\\system32\\itaapi.dll"
    "ThreadingModel"="Apartment"

    Windows Registry Editor Version 5.00

    [HKEY_CLASSES_ROOT\CLSID\{EABD618D-E32B-4E42-B7CD-C0D5CEF8D4C6}]
    @=""

    [HKEY_CLASSES_ROOT\CLSID\{EABD618D-E32B-4E42-B7CD-C0D5CEF8D4C6}\Implemented Categories]
    @=""

    [HKEY_CLASSES_ROOT\CLSID\{EABD618D-E32B-4E42-B7CD-C0D5CEF8D4C6}\Implemented Categories\{00021492-0000-0000-C000-000000000046}]
    @=""

    [HKEY_CLASSES_ROOT\CLSID\{EABD618D-E32B-4E42-B7CD-C0D5CEF8D4C6}\InprocServer32]
    @="C:\\WINDOWS\\system32\\wbsdmoe.dll"
    "ThreadingModel"="Apartment"

    Windows Registry Editor Version 5.00

    [HKEY_CLASSES_ROOT\CLSID\{5A431CDF-C97C-436C-ABD3-2C157A20323C}]
    @=""

    [HKEY_CLASSES_ROOT\CLSID\{5A431CDF-C97C-436C-ABD3-2C157A20323C}\Implemented Categories]
    @=""

    [HKEY_CLASSES_ROOT\CLSID\{5A431CDF-C97C-436C-ABD3-2C157A20323C}\Implemented Categories\{00021492-0000-0000-C000-000000000046}]
    @=""

    [HKEY_CLASSES_ROOT\CLSID\{5A431CDF-C97C-436C-ABD3-2C157A20323C}\InprocServer32]
    @="C:\\WINDOWS\\system32\\dqskadp.dll"
    "ThreadingModel"="Apartment"

    Windows Registry Editor Version 5.00

    [HKEY_CLASSES_ROOT\CLSID\{553563DE-F8D3-4330-9117-82FF449A4CC0}]
    @=""

    [HKEY_CLASSES_ROOT\CLSID\{553563DE-F8D3-4330-9117-82FF449A4CC0}\Implemented Categories]
    @=""

    [HKEY_CLASSES_ROOT\CLSID\{553563DE-F8D3-4330-9117-82FF449A4CC0}\Implemented Categories\{00021492-0000-0000-C000-000000000046}]
    @=""

    [HKEY_CLASSES_ROOT\CLSID\{553563DE-F8D3-4330-9117-82FF449A4CC0}\InprocServer32]
    @="C:\\WINDOWS\\system32\\wicsvc.dll"
    "ThreadingModel"="Apartment"

    Windows Registry Editor Version 5.00

    [HKEY_CLASSES_ROOT\CLSID\{8910A239-345F-4917-B5A5-480F69267EDA}]
    @=""

    [HKEY_CLASSES_ROOT\CLSID\{8910A239-345F-4917-B5A5-480F69267EDA}\Implemented Categories]
    @=""

    [HKEY_CLASSES_ROOT\CLSID\{8910A239-345F-4917-B5A5-480F69267EDA}\Implemented Categories\{00021492-0000-0000-C000-000000000046}]
    @=""

    [HKEY_CLASSES_ROOT\CLSID\{8910A239-345F-4917-B5A5-480F69267EDA}\InprocServer32]
    @="C:\\WINDOWS\\system32\\wen32spl.dll"
    "ThreadingModel"="Apartment"

    Windows Registry Editor Version 5.00

    [HKEY_CLASSES_ROOT\CLSID\{502EFDB7-E7AB-44FC-8F9C-B519B8E0D8D0}]
    @=""

    [HKEY_CLASSES_ROOT\CLSID\{502EFDB7-E7AB-44FC-8F9C-B519B8E0D8D0}\Implemented Categories]
    @=""

    [HKEY_CLASSES_ROOT\CLSID\{502EFDB7-E7AB-44FC-8F9C-B519B8E0D8D0}\Implemented Categories\{00021492-0000-0000-C000-000000000046}]
    @=""

    [HKEY_CLASSES_ROOT\CLSID\{502EFDB7-E7AB-44FC-8F9C-B519B8E0D8D0}\InprocServer32]
    @="C:\\WINDOWS\\system32\\fhclient.dll"
    "ThreadingModel"="Apartment"

    Windows Registry Editor Version 5.00

    [HKEY_CLASSES_ROOT\CLSID\{416DEC8D-D387-4D43-ACBB-A1F41079FEA4}]
    @=""

    [HKEY_CLASSES_ROOT\CLSID\{416DEC8D-D387-4D43-ACBB-A1F41079FEA4}\Implemented Categories]
    @=""

    [HKEY_CLASSES_ROOT\CLSID\{416DEC8D-D387-4D43-ACBB-A1F41079FEA4}\Implemented Categories\{00021492-0000-0000-C000-000000000046}]
    @=""

    [HKEY_CLASSES_ROOT\CLSID\{416DEC8D-D387-4D43-ACBB-A1F41079FEA4}\InprocServer32]
    @="C:\\WINDOWS\\system32\\irxmontr.dll"
    "ThreadingModel"="Apartment"

    Windows Registry Editor Version 5.00

    [HKEY_CLASSES_ROOT\CLSID\{922B5BF5-7756-4228-B71A-039B8B8A22AE}]
    @=""

    [HKEY_CLASSES_ROOT\CLSID\{922B5BF5-7756-4228-B71A-039B8B8A22AE}\Implemented Categories]
    @=""

    [HKEY_CLASSES_ROOT\CLSID\{922B5BF5-7756-4228-B71A-039B8B8A22AE}\Implemented Categories\{00021492-0000-0000-C000-000000000046}]
    @=""

    [HKEY_CLASSES_ROOT\CLSID\{922B5BF5-7756-4228-B71A-039B8B8A22AE}\InprocServer32]
    @="C:\\WINDOWS\\system32\\cycdll.dll"
    "ThreadingModel"="Apartment"

    Windows Registry Editor Version 5.00

    [HKEY_CLASSES_ROOT\CLSID\{7B7438AB-C7C8-4622-A4D4-033EFB8DAEB1}]
    @=""

    [HKEY_CLASSES_ROOT\CLSID\{7B7438AB-C7C8-4622-A4D4-033EFB8DAEB1}\Implemented Categories]
    @=""

    [HKEY_CLASSES_ROOT\CLSID\{7B7438AB-C7C8-4622-A4D4-033EFB8DAEB1}\Implemented Categories\{00021492-0000-0000-C000-000000000046}]
    @=""

    [HKEY_CLASSES_ROOT\CLSID\{7B7438AB-C7C8-4622-A4D4-033EFB8DAEB1}\InprocServer32]
    @="C:\\WINDOWS\\system32\\dkmstor.dll"
    "ThreadingModel"="Apartment"

    Windows Registry Editor Version 5.00

    [HKEY_CLASSES_ROOT\CLSID\{AF730DDA-AC7C-4054-BDDC-1060337C1218}]
    @=""

    [HKEY_CLASSES_ROOT\CLSID\{AF730DDA-AC7C-4054-BDDC-1060337C1218}\Implemented Categories]
    @=""

    [HKEY_CLASSES_ROOT\CLSID\{AF730DDA-AC7C-4054-BDDC-1060337C1218}\Implemented Categories\{00021492-0000-0000-C000-000000000046}]
    @=""

    [HKEY_CLASSES_ROOT\CLSID\{AF730DDA-AC7C-4054-BDDC-1060337C1218}\InprocServer32]
    @="C:\\WINDOWS\\system32\\aqicap.dll"
    "ThreadingModel"="Apartment"

    Windows Registry Editor Version 5.00

    [HKEY_CLASSES_ROOT\CLSID\{452229D1-C11F-4F7C-B6B8-9F456A96CA8C}]
    @=""

    [HKEY_CLASSES_ROOT\CLSID\{452229D1-C11F-4F7C-B6B8-9F456A96CA8C}\Implemented Categories]
    @=""

    [HKEY_CLASSES_ROOT\CLSID\{452229D1-C11F-4F7C-B6B8-9F456A96CA8C}\Implemented Categories\{00021492-0000-0000-C000-000000000046}]
    @=""

    [HKEY_CLASSES_ROOT\CLSID\{452229D1-C11F-4F7C-B6B8-9F456A96CA8C}\InprocServer32]
    @="C:\\WINDOWS\\system32\\woerrFIN.dll"
    "ThreadingModel"="Apartment"

    Windows Registry Editor Version 5.00

    [HKEY_CLASSES_ROOT\CLSID\{4B0A3EFE-CD45-4B85-AAAF-BF6A03AE6128}]
    @=""

    [HKEY_CLASSES_ROOT\CLSID\{4B0A3EFE-CD45-4B85-AAAF-BF6A03AE6128}\Implemented Categories]
    @=""

    [HKEY_CLASSES_ROOT\CLSID\{4B0A3EFE-CD45-4B85-AAAF-BF6A03AE6128}\Implemented Categories\{00021492-0000-0000-C000-000000000046}]
    @=""

    [HKEY_CLASSES_ROOT\CLSID\{4B0A3EFE-CD45-4B85-AAAF-BF6A03AE6128}\InprocServer32]
    @="C:\\WINDOWS\\system32\\ilfosoft.dll"
    "ThreadingModel"="Apartment"

    Windows Registry Editor Version 5.00

    [HKEY_CLASSES_ROOT\CLSID\{A1B72B3F-50F0-467B-A1FA-35F79A3DC2DC}]
    @=""

    [HKEY_CLASSES_ROOT\CLSID\{A1B72B3F-50F0-467B-A1FA-35F79A3DC2DC}\Implemented Categories]
    @=""

    [HKEY_CLASSES_ROOT\CLSID\{A1B72B3F-50F0-467B-A1FA-35F79A3DC2DC}\Implemented Categories\{00021492-0000-0000-C000-000000000046}]
    @=""

    [HKEY_CLASSES_ROOT\CLSID\{A1B72B3F-50F0-467B-A1FA-35F79A3DC2DC}\InprocServer32]
    @="C:\\WINDOWS\\system32\\mzwsock.dll"
    "ThreadingModel"="Apartment"

    Windows Registry Editor Version 5.00

    [HKEY_CLASSES_ROOT\CLSID\{802BF23C-470B-41DE-A6B0-381587EA7037}]
    @=""

    [HKEY_CLASSES_ROOT\CLSID\{802BF23C-470B-41DE-A6B0-381587EA7037}\Implemented Categories]
    @=""

    [HKEY_CLASSES_ROOT\CLSID\{802BF23C-470B-41DE-A6B0-381587EA7037}\Implemented Categories\{00021492-0000-0000-C000-000000000046}]
    @=""

    [HKEY_CLASSES_ROOT\CLSID\{802BF23C-470B-41DE-A6B0-381587EA7037}\InprocServer32]
    @="C:\\WINDOWS\\system32\\snrio600.dll"
    "ThreadingModel"="Apartment"

    Windows Registry Editor Version 5.00

    [HKEY_CLASSES_ROOT\CLSID\{9592BB1B-E337-404E-9CF3-2735CD85AE67}]
    @=""

    [HKEY_CLASSES_ROOT\CLSID\{9592BB1B-E337-404E-9CF3-2735CD85AE67}\Implemented Categories]
    @=""

    [HKEY_CLASSES_ROOT\CLSID\{9592BB1B-E337-404E-9CF3-2735CD85AE67}\Implemented Categories\{00021492-0000-0000-C000-000000000046}]
    @=""

    [HKEY_CLASSES_ROOT\CLSID\{9592BB1B-E337-404E-9CF3-2735CD85AE67}\InprocServer32]
    @="C:\\WINDOWS\\system32\\wontrust.dll"
    "ThreadingModel"="Apartment"

    Windows Registry Editor Version 5.00

    [HKEY_CLASSES_ROOT\CLSID\{A18C479B-53B1-4C66-8DFE-9E88A6E04417}]
    @=""

    [HKEY_CLASSES_ROOT\CLSID\{A18C479B-53B1-4C66-8DFE-9E88A6E04417}\Implemented Categories]
    @=""

    [HKEY_CLASSES_ROOT\CLSID\{A18C479B-53B1-4C66-8DFE-9E88A6E04417}\Implemented Categories\{00021492-0000-0000-C000-000000000046}]
    @=""

    [HKEY_CLASSES_ROOT\CLSID\{A18C479B-53B1-4C66-8DFE-9E88A6E04417}\InprocServer32]
    @="C:\\WINDOWS\\system32\\bqackbox.dll"
    "ThreadingModel"="Apartment"

    Windows Registry Editor Version 5.00

    [HKEY_CLASSES_ROOT\CLSID\{2E03477B-F05D-47F2-A00A-15F867AACE60}]
    @=""

    [HKEY_CLASSES_ROOT\CLSID\{2E03477B-F05D-47F2-A00A-15F867AACE60}\Implemented Categories]
    @=""

    [HKEY_CLASSES_ROOT\CLSID\{2E03477B-F05D-47F2-A00A-15F867AACE60}\Implemented Categories\{00021492-0000-0000-C000-000000000046}]
    @=""

    [HKEY_CLASSES_ROOT\CLSID\{2E03477B-F05D-47F2-A00A-15F867AACE60}\InprocServer32]
    @="C:\\WINDOWS\\system32\\AIIDEMGR.dll"
    "ThreadingModel"="Apartment"

    Windows Registry Editor Version 5.00

    [HKEY_CLASSES_ROOT\CLSID\{BE3DF3FB-8B4D-4218-856D-B14691C624C8}]
    @=""

    [HKEY_CLASSES_ROOT\CLSID\{BE3DF3FB-8B4D-4218-856D-B14691C624C8}\Implemented Categories]
    @=""

    [HKEY_CLASSES_ROOT\CLSID\{BE3DF3FB-8B4D-4218-856D-B14691C624C8}\Implemented Categories\{00021492-0000-0000-C000-000000000046}]
    @=""

    [HKEY_CLASSES_ROOT\CLSID\{BE3DF3FB-8B4D-4218-856D-B14691C624C8}\InprocServer32]
    @="C:\\WINDOWS\\system32\\kvrberos.dll"
    "ThreadingModel"="Apartment"

    Windows Registry Editor Version 5.00

    [HKEY_CLASSES_ROOT\CLSID\{C68F1017-3F12-406A-B1E6-607641395690}]
    @=""

    [HKEY_CLASSES_ROOT\CLSID\{C68F1017-3F12-406A-B1E6-607641395690}\Implemented Categories]
    @=""

    [HKEY_CLASSES_ROOT\CLSID\{C68F1017-3F12-406A-B1E6-607641395690}\Implemented Categories\{00021492-0000-0000-C000-000000000046}]
    @=""

    [HKEY_CLASSES_ROOT\CLSID\{C68F1017-3F12-406A-B1E6-607641395690}\InprocServer32]
    @="C:\\WINDOWS\\system32\\lmcmgr10.dll"
    "ThreadingModel"="Apartment"

    Windows Registry Editor Version 5.00

    [HKEY_CLASSES_ROOT\CLSID\{2B119913-7FA4-4B36-BE31-4A2B222D00EE}]
    @=""

    [HKEY_CLASSES_ROOT\CLSID\{2B119913-7FA4-4B36-BE31-4A2B222D00EE}\Implemented Categories]
    @=""

    [HKEY_CLASSES_ROOT\CLSID\{2B119913-7FA4-4B36-BE31-4A2B222D00EE}\Implemented Categories\{00021492-0000-0000-C000-000000000046}]
    @=""

    [HKEY_CLASSES_ROOT\CLSID\{2B119913-7FA4-4B36-BE31-4A2B222D00EE}\InprocServer32]
    @="C:\\WINDOWS\\system32\\noprint.dll"
    "ThreadingModel"="Apartment"

    Windows Registry Editor Version 5.00

    [HKEY_CLASSES_ROOT\CLSID\{DD14D17A-B367-4B13-AFCE-FF0B86EA0115}]
    @=""

    [HKEY_CLASSES_ROOT\CLSID\{DD14D17A-B367-4B13-AFCE-FF0B86EA0115}\Implemented Categories]
    @=""

    [HKEY_CLASSES_ROOT\CLSID\{DD14D17A-B367-4B13-AFCE-FF0B86EA0115}\Implemented Categories\{00021492-0000-0000-C000-000000000046}]
    @=""

    [HKEY_CLASSES_ROOT\CLSID\{DD14D17A-B367-4B13-AFCE-FF0B86EA0115}\InprocServer32]
    @="C:\\WINDOWS\\system32\\ibfgnt5.dll"
    "ThreadingModel"="Apartment"

    Windows Registry Editor Version 5.00

    [HKEY_CLASSES_ROOT\CLSID\{086B79D8-C1FE-4A88-B025-1D12670386D4}]
    @=""

    [HKEY_CLASSES_ROOT\CLSID\{086B79D8-C1FE-4A88-B025-1D12670386D4}\Implemented Categories]
    @=""

    [HKEY_CLASSES_ROOT\CLSID\{086B79D8-C1FE-4A88-B025-1D12670386D4}\Implemented Categories\{00021492-0000-0000-C000-000000000046}]
    @=""

    [HKEY_CLASSES_ROOT\CLSID\{086B79D8-C1FE-4A88-B025-1D12670386D4}\InprocServer32]
    @="C:\\WINDOWS\\system32\\nqmkcert.dll"
    "ThreadingModel"="Apartment"

    Windows Registry Editor Version 5.00

    [HKEY_CLASSES_ROOT\CLSID\{BF570010-C329-44C4-9076-70DC09D1F657}]
    @=""

    [HKEY_CLASSES_ROOT\CLSID\{BF570010-C329-44C4-9076-70DC09D1F657}\Implemented Categories]
    @=""

    [HKEY_CLASSES_ROOT\CLSID\{BF570010-C329-44C4-9076-70DC09D1F657}\Implemented Categories\{00021492-0000-0000-C000-000000000046}]
    @=""

    [HKEY_CLASSES_ROOT\CLSID\{BF570010-C329-44C4-9076-70DC09D1F657}\InprocServer32]
    @="C:\\WINDOWS\\system32\\ravpmsg.dll"
    "ThreadingModel"="Apartment"

    Windows Registry Editor Version 5.00

    [HKEY_CLASSES_ROOT\CLSID\{FEF43FF9-8C73-45F6-8FD1-1B7CF1E91AE6}]
    @=""

    [HKEY_CLASSES_ROOT\CLSID\{FEF43FF9-8C73-45F6-8FD1-1B7CF1E91AE6}\Implemented Categories]
    @=""

    [HKEY_CLASSES_ROOT\CLSID\{FEF43FF9-8C73-45F6-8FD1-1B7CF1E91AE6}\Implemented Categories\{00021492-0000-0000-C000-000000000046}]
    @=""

    [HKEY_CLASSES_ROOT\CLSID\{FEF43FF9-8C73-45F6-8FD1-1B7CF1E91AE6}\InprocServer32]
    @="C:\\WINDOWS\\system32\\bYsesrv.dll"
    "ThreadingModel"="Apartment"

    Windows Registry Editor Version 5.00

    [HKEY_CLASSES_ROOT\CLSID\{7D00103A-4B7C-4A92-A168-E115A4B5BB62}]
    @=""

    [HKEY_CLASSES_ROOT\CLSID\{7D00103A-4B7C-4A92-A168-E115A4B5BB62}\Implemented Categories]
    @=""

    [HKEY_CLASSES_ROOT\CLSID\{7D00103A-4B7C-4A92-A168-E115A4B5BB62}\Implemented Categories\{00021492-0000-0000-C000-000000000046}]
    @=""

    [HKEY_CLASSES_ROOT\CLSID\{7D00103A-4B7C-4A92-A168-E115A4B5BB62}\InprocServer32]
    @="C:\\WINDOWS\\system32\\rJstls.dll"
    "ThreadingModel"="Apartment"

    Windows Registry Editor Version 5.00

    [HKEY_CLASSES_ROOT\CLSID\{3B886085-E276-40BC-88BC-C4C2E65CFB2F}]
    @=""

    [HKEY_CLASSES_ROOT\CLSID\{3B886085-E276-40BC-88BC-C4C2E65CFB2F}\Implemented Categories]
    @=""

    [HKEY_CLASSES_ROOT\CLSID\{3B886085-E276-40BC-88BC-C4C2E65CFB2F}\Implemented Categories\{00021492-0000-0000-C000-000000000046}]
    @=""

    [HKEY_CLASSES_ROOT\CLSID\{3B886085-E276-40BC-88BC-C4C2E65CFB2F}\InprocServer32]
    @="C:\\WINDOWS\\system32\\nmmsdba.dll"
    "ThreadingModel"="Apartment"

    Windows Registry Editor Version 5.00

    [HKEY_CLASSES_ROOT\CLSID\{A905FB3E-425A-4C86-9424-BCC2F7E26CB3}]
    @=""

    [HKEY_CLASSES_ROOT\CLSID\{A905FB3E-425A-4C86-9424-BCC2F7E26CB3}\Implemented Categories]
    @=""

    [HKEY_CLASSES_ROOT\CLSID\{A905FB3E-425A-4C86-9424-BCC2F7E26CB3}\Implemented Categories\{00021492-0000-0000-C000-000000000046}]
    @=""

    [HKEY_CLASSES_ROOT\CLSID\{A905FB3E-425A-4C86-9424-BCC2F7E26CB3}\InprocServer32]
    @="C:\\WINDOWS\\system32\\djusic.dll"
    "ThreadingModel"="Apartment"

    Windows Registry Editor Version 5.00

    [HKEY_CLASSES_ROOT\CLSID\{E111B4A6-42C0-4BC6-BC9C-7171A7978740}]
    @=""

    [HKEY_CLASSES_ROOT\CLSID\{E111B4A6-42C0-4BC6-BC9C-7171A7978740}\Implemented Categories]
    @=""

    [HKEY_CLASSES_ROOT\CLSID\{E111B4A6-42C0-4BC6-BC9C-7171A7978740}\Implemented Categories\{00021492-0000-0000-C000-000000000046}]
    @=""

    [HKEY_CLASSES_ROOT\CLSID\{E111B4A6-42C0-4BC6-BC9C-7171A7978740}\InprocServer32]
    @="C:\\WINDOWS\\system32\\mojint40.dll"
    "ThreadingModel"="Apartment"

    Windows Registry Editor Version 5.00

    [HKEY_CLASSES_ROOT\CLSID\{86C43321-E4A9-45A4-8E68-16C30932260F}]
    @=""

    [HKEY_CLASSES_ROOT\CLSID\{86C43321-E4A9-45A4-8E68-16C30932260F}\Implemented Categories]
    @=""

    [HKEY_CLASSES_ROOT\CLSID\{86C43321-E4A9-45A4-8E68-16C30932260F}\Implemented Categories\{00021492-0000-0000-C000-000000000046}]
    @=""

    [HKEY_CLASSES_ROOT\CLSID\{86C43321-E4A9-45A4-8E68-16C30932260F}\InprocServer32]
    @="C:\\WINDOWS\\system32\\myastmib.dll"
    "ThreadingModel"="Apartment"

    Windows Registry Editor Version 5.00

    [HKEY_CLASSES_ROOT\CLSID\{06005505-0EC7-483C-827F-F94B2BA27010}]
    @=""

    [HKEY_CLASSES_ROOT\CLSID\{06005505-0EC7-483C-827F-F94B2BA27010}\Implemented Categories]
    @=""

    [HKEY_CLASSES_ROOT\CLSID\{06005505-0EC7-483C-827F-F94B2BA27010}\Implemented Categories\{00021492-0000-0000-C000-000000000046}]
    @=""

    [HKEY_CLASSES_ROOT\CLSID\{06005505-0EC7-483C-827F-F94B2BA27010}\InprocServer32]
    @="C:\\WINDOWS\\system32\\wtvcore2.dll"
    "ThreadingModel"="Apartment"

    Windows Registry Editor Version 5.00

    [HKEY_CLASSES_ROOT\CLSID\{61DC2AF4-EB96-4DB7-A6B2-5C736795491E}]
    @=""

    [HKEY_CLASSES_ROOT\CLSID\{61DC2AF4-EB96-4DB7-A6B2-5C736795491E}\Implemented Categories]
    @=""

    [HKEY_CLASSES_ROOT\CLSID\{61DC2AF4-EB96-4DB7-A6B2-5C736795491E}\Implemented Categories\{00021492-0000-0000-C000-000000000046}]
    @=""

    [HKEY_CLASSES_ROOT\CLSID\{61DC2AF4-EB96-4DB7-A6B2-5C736795491E}\InprocServer32]
    @="C:\\WINDOWS\\system32\\wgaueng.dll"
    "ThreadingModel"="Apartment"

    Windows Registry Editor Version 5.00

    [HKEY_CLASSES_ROOT\CLSID\{2549F884-AA3F-465B-B0F1-2DC3FBBA5FDC}]
    @=""

    [HKEY_CLASSES_ROOT\CLSID\{2549F884-AA3F-465B-B0F1-2DC3FBBA5FDC}\Implemented Categories]
    @=""

    [HKEY_CLASSES_ROOT\CLSID\{2549F884-AA3F-465B-B0F1-2DC3FBBA5FDC}\Implemented Categories\{00021492-0000-0000-C000-000000000046}]
    @=""

    [HKEY_CLASSES_ROOT\CLSID\{2549F884-AA3F-465B-B0F1-2DC3FBBA5FDC}\InprocServer32]
    @="C:\\WINDOWS\\system32\\InagXpr5.dll"
    "ThreadingModel"="Apartment"

    Windows Registry Editor Version 5.00

    [HKEY_CLASSES_ROOT\CLSID\{989EAC39-8B82-4278-9CA6-63874E559300}]
    @=""

    [HKEY_CLASSES_ROOT\CLSID\{989EAC39-8B82-4278-9CA6-63874E559300}\Implemented Categories]
    @=""

    [HKEY_CLASSES_ROOT\CLSID\{989EAC39-8B82-4278-9CA6-63874E559300}\Implemented Categories\{00021492-0000-0000-C000-000000000046}]
    @=""

    [HKEY_CLASSES_ROOT\CLSID\{989EAC39-8B82-4278-9CA6-63874E559300}\InprocServer32]
    @="C:\\WINDOWS\\system32\\ripcfgex.dll"
    "ThreadingModel"="Apartment"

    Windows Registry Editor Version 5.00

    [HKEY_CLASSES_ROOT\CLSID\{768ED112-0A46-41F4-BEEB-E22D89FFFCA7}]
    @=""

    [HKEY_CLASSES_ROOT\CLSID\{768ED112-0A46-41F4-BEEB-E22D89FFFCA7}\Implemented Categories]
    @=""

    [HKEY_CLASSES_ROOT\CLSID\{768ED112-0A46-41F4-BEEB-E22D89FFFCA7}\Implemented Categories\{00021492-0000-0000-C000-000000000046}]
    @=""

    [HKEY_CLASSES_ROOT\CLSID\{768ED112-0A46-41F4-BEEB-E22D89FFFCA7}\InprocServer32]
    @="C:\\WINDOWS\\system32\\cwbjmon.dll"
    "ThreadingModel"="Apartment"

    Windows Registry Editor Version 5.00

    [HKEY_CLASSES_ROOT\CLSID\{2239C763-740F-4B97-806C-529646F59991}]
    @=""

    [HKEY_CLASSES_ROOT\CLSID\{2239C763-740F-4B97-806C-529646F59991}\Implemented Categories]
    @=""

    [HKEY_CLASSES_ROOT\CLSID\{2239C763-740F-4B97-806C-529646F59991}\Implemented Categories\{00021492-0000-0000-C000-000000000046}]
    @=""

    [HKEY_CLASSES_ROOT\CLSID\{2239C763-740F-4B97-806C-529646F59991}\InprocServer32]
    @="C:\\WINDOWS\\system32\\snlwoa.dll"
    "ThreadingModel"="Apartment"

    Windows Registry Editor Version 5.00

    [HKEY_CLASSES_ROOT\CLSID\{F34A41CF-EAB4-47EF-A42C-A836E83FF61D}]
    @=""

    [HKEY_CLASSES_ROOT\CLSID\{F34A41CF-EAB4-47EF-A42C-A836E83FF61D}\Implemented Categories]
    @=""

    [HKEY_CLASSES_ROOT\CLSID\{F34A41CF-EAB4-47EF-A42C-A836E83FF61D}\Implemented Categories\{00021492-0000-0000-C000-000000000046}]
    @=""

    [HKEY_CLASSES_ROOT\CLSID\{F34A41CF-EAB4-47EF-A42C-A836E83FF61D}\InprocServer32]
    @="C:\\WINDOWS\\system32\\awmeter.dll"
    "ThreadingModel"="Apartment"

    Windows Registry Editor Version 5.00

    [HKEY_CLASSES_ROOT\CLSID\{4DF09495-0324-42E2-AACC-7E1A0D0ABB4A}]
    @=""

    [HKEY_CLASSES_ROOT\CLSID\{4DF09495-0324-42E2-AACC-7E1A0D0ABB4A}\Implemented Categories]
    @=""

    [HKEY_CLASSES_ROOT\CLSID\{4DF09495-0324-42E2-AACC-7E1A0D0ABB4A}\Implemented Categories\{00021492-0000-0000-C000-000000000046}]
    @=""

    [HKEY_CLASSES_ROOT\CLSID\{4DF09495-0324-42E2-AACC-7E1A0D0ABB4A}\InprocServer32]
    @="C:\\WINDOWS\\system32\\dHtaclen.dll"
    "ThreadingModel"="Apartment"

    Windows Registry Editor Version 5.00

    [HKEY_CLASSES_ROOT\CLSID\{2A66DD17-C378-456E-8D5E-41BB93D2FCDC}]
    @=""

    [HKEY_CLASSES_ROOT\CLSID\{2A66DD17-C378-456E-8D5E-41BB93D2FCDC}\Implemented Categories]
    @=""

    [HKEY_CLASSES_ROOT\CLSID\{2A66DD17-C378-456E-8D5E-41BB93D2FCDC}\Implemented Categories\{00021492-0000-0000-C000-000000000046}]
    @=""

    [HKEY_CLASSES_ROOT\CLSID\{2A66DD17-C378-456E-8D5E-41BB93D2FCDC}\InprocServer32]
    @="C:\\WINDOWS\\system32\\mtcat32.dll"
    "ThreadingModel"="Apartment"

    Windows Registry Editor Version 5.00

    [HKEY_CLASSES_ROOT\CLSID\{77239875-4AA2-4412-9308-E2D751BA476C}]
    @=""

    [HKEY_CLASSES_ROOT\CLSID\{77239875-4AA2-4412-9308-E2D751BA476C}\Implemented Categories]
    @=""

    [HKEY_CLASSES_ROOT\CLSID\{77239875-4AA2-4412-9308-E2D751BA476C}\Implemented Categories\{00021492-0000-0000-C000-000000000046}]
    @=""

    [HKEY_CLASSES_ROOT\CLSID\{77239875-4AA2-4412-9308-E2D751BA476C}\InprocServer32]
    @="C:\\WINDOWS\\system32\\irrnonce.dll"
    "ThreadingModel"="Apartment"

    Windows Registry Editor Version 5.00

    [HKEY_CLASSES_ROOT\CLSID\{E1D27203-690B-4C7D-A388-D1A9F5D84808}]
    @=""

    [HKEY_CLASSES_ROOT\CLSID\{E1D27203-690B-4C7D-A388-D1A9F5D84808}\Implemented Categories]
    @=""

    [HKEY_CLASSES_ROOT\CLSID\{E1D27203-690B-4C7D-A388-D1A9F5D84808}\Implemented Categories\{00021492-0000-0000-C000-000000000046}]
    @=""

    [HKEY_CLASSES_ROOT\CLSID\{E1D27203-690B-4C7D-A388-D1A9F5D84808}\InprocServer32]
    @="C:\\WINDOWS\\system32\\mggsvc.dll"
    "ThreadingModel"="Apartment"

    Windows Registry Editor Version 5.00

    [HKEY_CLASSES_ROOT\CLSID\{C4CA3BE6-76A1-4C15-9A5A-0D8519C8AC4E}]
    @=""

    [HKEY_CLASSES_ROOT\CLSID\{C4CA3BE6-76A1-4C15-9A5A-0D8519C8AC4E}\Implemented Categories]
    @=""

    [HKEY_CLASSES_ROOT\CLSID\{C4CA3BE6-76A1-4C15-9A5A-0D8519C8AC4E}\Implemented Categories\{00021492-0000-0000-C000-000000000046}]
    @=""

    [HKEY_CLASSES_ROOT\CLSID\{C4CA3BE6-76A1-4C15-9A5A-0D8519C8AC4E}\InprocServer32]
    @="C:\\WINDOWS\\system32\\cymsnap.dll"
    "ThreadingModel"="Apartment"

    Windows Registry Editor Version 5.00

    [HKEY_CLASSES_ROOT\CLSID\{4744A88A-27F0-40FA-AE76-75D9650884E2}]
    @=""

    [HKEY_CLASSES_ROOT\CLSID\{4744A88A-27F0-40FA-AE76-75D9650884E2}\Implemented Categories]
    @=""

    [HKEY_CLASSES_ROOT\CLSID\{4744A88A-27F0-40FA-AE76-75D9650884E2}\Implemented Categories\{00021492-0000-0000-C000-000000000046}]
    @=""

    [HKEY_CLASSES_ROOT\CLSID\{4744A88A-27F0-40FA-AE76-75D9650884E2}\InprocServer32]
    @="C:\\WINDOWS\\system32\\wxcsapi.dll"
    "ThreadingModel"="Apartment"

    Windows Registry Editor Version 5.00

    [HKEY_CLASSES_ROOT\CLSID\{5C3A5019-70E9-4876-BF44-F6AFB0951A89}]
    @=""

    [HKEY_CLASSES_ROOT\CLSID\{5C3A5019-70E9-4876-BF44-F6AFB0951A89}\Implemented Categories]
    @=""

    [HKEY_CLASSES_ROOT\CLSID\{5C3A5019-70E9-4876-BF44-F6AFB0951A89}\Implemented Categories\{00021492-0000-0000-C000-000000000046}]
    @=""

    [HKEY_CLASSES_ROOT\CLSID\{5C3A5019-70E9-4876-BF44-F6AFB0951A89}\InprocServer32]
    @="C:\\WINDOWS\\system32\\mjjint40.dll"
    "ThreadingModel"="Apartment"

    Windows Registry Editor Version 5.00

    [HKEY_CLASSES_ROOT\CLSID\{DB29EC55-273E-494C-BA9E-638B93144B61}]
    @=""

    [HKEY_CLASSES_ROOT\CLSID\{DB29EC55-273E-494C-BA9E-638B93144B61}\Implemented Categories]
    @=""

    [HKEY_CLASSES_ROOT\CLSID\{DB29EC55-273E-494C-BA9E-638B93144B61}\Implemented Categories\{00021492-0000-0000-C000-000000000046}]
    @=""

    [HKEY_CLASSES_ROOT\CLSID\{DB29EC55-273E-494C-BA9E-638B93144B61}\InprocServer32]
    @="C:\\WINDOWS\\system32\\mjrclr40.dll"
    "ThreadingModel"="Apartment"

    Windows Registry Editor Version 5.00

    [HKEY_CLASSES_ROOT\CLSID\{C6F6E1E1-B213-44DB-AB5D-4D79DFB209DD}]
    @=""

    [HKEY_CLASSES_ROOT\CLSID\{C6F6E1E1-B213-44DB-AB5D-4D79DFB209DD}\Implemented Categories]
    @=""

    [HKEY_CLASSES_ROOT\CLSID\{C6F6E1E1-B213-44DB-AB5D-4D79DFB209DD}\Implemented Categories\{00021492-0000-0000-C000-000000000046}]
    @=""

    [HKEY_CLASSES_ROOT\CLSID\{C6F6E1E1-B213-44DB-AB5D-4D79DFB209DD}\InprocServer32]
    @="C:\\WINDOWS\\system32\\mtcsubs.dll"
    "ThreadingModel"="Apartment"

    Windows Registry Editor Version 5.00

    [HKEY_CLASSES_ROOT\CLSID\{E88EAE69-22F3-4119-9AA5-6DB6D9C620A2}]
    @=""

    [HKEY_CLASSES_ROOT\CLSID\{E88EAE69-22F3-4119-9AA5-6DB6D9C620A2}\Implemented Categories]
    @=""

    [HKEY_CLASSES_ROOT\CLSID\{E88EAE69-22F3-4119-9AA5-6DB6D9C620A2}\Implemented Categories\{00021492-0000-0000-C000-000000000046}]
    @=""

    [HKEY_CLASSES_ROOT\CLSID\{E88EAE69-22F3-4119-9AA5-6DB6D9C620A2}\InprocServer32]
    @="C:\\WINDOWS\\system32\\dwband.dll"
    "ThreadingModel"="Apartment"

    Windows Registry Editor Version 5.00

    [HKEY_CLASSES_ROOT\CLSID\{35A3BDF2-A729-40AB-98A8-3A0A21C2D401}]
    @=""

    [HKEY_CLASSES_ROOT\CLSID\{35A3BDF2-A729-40AB-98A8-3A0A21C2D401}\Implemented Categories]
    @=""

    [HKEY_CLASSES_ROOT\CLSID\{35A3BDF2-A729-40AB-98A8-3A0A21C2D401}\Implemented Categories\{00021492-0000-0000-C000-000000000046}]
    @=""

    [HKEY_CLASSES_ROOT\CLSID\{35A3BDF2-A729-40AB-98A8-3A0A21C2D401}\InprocServer32]
    @="C:\\WINDOWS\\system32\\hxtplug.dll"
    "ThreadingModel"="Apartment"

    Windows Registry Editor Version 5.00

    [HKEY_CLASSES_ROOT\CLSID\{26EF4751-8CAD-4110-8EDC-6C808BF33696}]
    @=""

    [HKEY_CLASSES_ROOT\CLSID\{26EF4751-8CAD-4110-8EDC-6C808BF33696}\Implemented Categories]
    @=""

    [HKEY_CLASSES_ROOT\CLSID\{26EF4751-8CAD-4110-8EDC-6C808BF33696}\Implemented Categories\{00021492-0000-0000-C000-000000000046}]
    @=""

    [HKEY_CLASSES_ROOT\CLSID\{26EF4751-8CAD-4110-8EDC-6C808BF33696}\InprocServer32]
    @="C:\\WINDOWS\\system32\\dprgsnap.dll"
    "ThreadingModel"="Apartment"

    Windows Registry Editor Version 5.00

    [HKEY_CLASSES_ROOT\CLSID\{A3E8A66B-5D52-47AD-ADCC-451F85DB28A0}]
    @=""

    [HKEY_CLASSES_ROOT\CLSID\{A3E8A66B-5D52-47AD-ADCC-451F85DB28A0}\Implemented Categories]
    @=""

    [HKEY_CLASSES_ROOT\CLSID\{A3E8A66B-5D52-47AD-ADCC-451F85DB28A0}\Implemented Categories\{00021492-0000-0000-C000-000000000046}]
    @=""

    [HKEY_CLASSES_ROOT\CLSID\{A3E8A66B-5D52-47AD-ADCC-451F85DB28A0}\InprocServer32]
    @="C:\\WINDOWS\\system32\\iopromon.dll"
    "ThreadingModel"="Apartment"

    Windows Registry Editor Version 5.00

    [HKEY_CLASSES_ROOT\CLSID\{81E180E6-D6E9-457B-B148-6B2696E40478}]
    @=""

    [HKEY_CLASSES_ROOT\CLSID\{81E180E6-D6E9-457B-B148-6B2696E40478}\Implemented Categories]
    @=""

    [HKEY_CLASSES_ROOT\CLSID\{81E180E6-D6E9-457B-B148-6B2696E40478}\Implemented Categories\{00021492-0000-0000-C000-000000000046}]
    @=""

    [HKEY_CLASSES_ROOT\CLSID\{81E180E6-D6E9-457B-B148-6B2696E40478}\InprocServer32]
    @="C:\\WINDOWS\\system32\\rHsadhlp.dll"
    "ThreadingModel"="Apartment"

    Windows Registry Editor Version 5.00

    [HKEY_CLASSES_ROOT\CLSID\{6547E428-2EC0-4A08-AA07-299EF6FDA51F}]
    @=""

    [HKEY_CLASSES_ROOT\CLSID\{6547E428-2EC0-4A08-AA07-299EF6FDA51F}\Implemented Categories]
    @=""

    [HKEY_CLASSES_ROOT\CLSID\{6547E428-2EC0-4A08-AA07-299EF6FDA51F}\Implemented Categories\{00021492-0000-0000-C000-000000000046}]
    @=""

    [HKEY_CLASSES_ROOT\CLSID\{6547E428-2EC0-4A08-AA07-299EF6FDA51F}\InprocServer32]
    @="C:\\WINDOWS\\system32\\ihagehlp.dll"
    "ThreadingModel"="Apartment"

    Windows Registry Editor Version 5.00

    [HKEY_CLASSES_ROOT\CLSID\{97D68211-1408-461A-80AC-A15CF76AFD99}]
    @=""

    [HKEY_CLASSES_ROOT\CLSID\{97D68211-1408-461A-80AC-A15CF76AFD99}\Implemented Categories]
    @=""

    [HKEY_CLASSES_ROOT\CLSID\{97D68211-1408-461A-80AC-A15CF76AFD99}\Implemented Categories\{00021492-0000-0000-C000-000000000046}]
    @=""

    [HKEY_CLASSES_ROOT\CLSID\{97D68211-1408-461A-80AC-A15CF76AFD99}\InprocServer32]
    @="C:\\WINDOWS\\system32\\cbcdll.dll"
    "ThreadingModel"="Apartment"

    Windows Registry Editor Version 5.00

    [HKEY_CLASSES_ROOT\CLSID\{8AEEED30-5FF4-4874-9C71-0C42E50B42E6}]
    @=""

    [HKEY_CLASSES_ROOT\CLSID\{8AEEED30-5FF4-4874-9C71-0C42E50B42E6}\Implemented Categories]
    @=""

    [HKEY_CLASSES_ROOT\CLSID\{8AEEED30-5FF4-4874-9C71-0C42E50B42E6}\Implemented Categories\{00021492-0000-0000-C000-000000000046}]
    @=""

    [HKEY_CLASSES_ROOT\CLSID\{8AEEED30-5FF4-4874-9C71-0C42E50B42E6}\InprocServer32]
    @="C:\\WINDOWS\\system32\\otbc32.dll"
    "ThreadingModel"="Apartment"

    Windows Registry Editor Version 5.00

    [HKEY_CLASSES_ROOT\CLSID\{B30D2E85-CD34-4BE6-AD46-8BE283060FF7}]
    @=""

    [HKEY_CLASSES_ROOT\CLSID\{B30D2E85-CD34-4BE6-AD46-8BE283060FF7}\Implemented Categories]
    @=""

    [HKEY_CLASSES_ROOT\CLSID\{B30D2E85-CD34-4BE6-AD46-8BE283060FF7}\Implemented Categories\{00021492-0000-0000-C000-000000000046}]
    @=""

    [HKEY_CLASSES_ROOT\CLSID\{B30D2E85-CD34-4BE6-AD46-8BE283060FF7}\InprocServer32]
    @="C:\\WINDOWS\\system32\\dprgui.dll"
    "ThreadingModel"="Apartment"

    Windows Registry Editor Version 5.00

    [HKEY_CLASSES_ROOT\CLSID\{3547F6B3-CEF1-467A-AEAE-30478F77C942}]
    @=""

    [HKEY_CLASSES_ROOT\CLSID\{3547F6B3-CEF1-467A-AEAE-30478F77C942}\Implemented Categories]
    @=""

    [HKEY_CLASSES_ROOT\CLSID\{3547F6B3-CEF1-467A-AEAE-30478F77C942}\Implemented Categories\{00021492-0000-0000-C000-000000000046}]
    @=""

    [HKEY_CLASSES_ROOT\CLSID\{3547F6B3-CEF1-467A-AEAE-30478F77C942}\InprocServer32]
    @="C:\\WINDOWS\\system32\\prgfilt.dll"
    "ThreadingModel"="Apartment"

    Windows Registry Editor Version 5.00

    [HKEY_CLASSES_ROOT\CLSID\{F9819CEA-11EB-4AE0-AA39-01E59BFCDF46}]
    @=""

    [HKEY_CLASSES_ROOT\CLSID\{F9819CEA-11EB-4AE0-AA39-01E59BFCDF46}\Implemented Categories]
    @=""

    [HKEY_CLASSES_ROOT\CLSID\{F9819CEA-11EB-4AE0-AA39-01E59BFCDF46}\Implemented Categories\{00021492-0000-0000-C000-000000000046}]
    @=""

    [HKEY_CLASSES_ROOT\CLSID\{F9819CEA-11EB-4AE0-AA39-01E59BFCDF46}\InprocServer32]
    @="C:\\WINDOWS\\system32\\kndhe220.dll"
    "ThreadingModel"="Apartment"

    Windows Registry Editor Version 5.00

    [HKEY_CLASSES_ROOT\CLSID\{02A454BC-4AC9-4D05-97B8-2DEB97F038A7}]
    @=""

    [HKEY_CLASSES_ROOT\CLSID\{02A454BC-4AC9-4D05-97B8-2DEB97F038A7}\Implemented Categories]
    @=""

    [HKEY_CLASSES_ROOT\CLSID\{02A454BC-4AC9-4D05-97B8-2DEB97F038A7}\Implemented Categories\{00021492-0000-0000-C000-000000000046}]
    @=""

    [HKEY_CLASSES_ROOT\CLSID\{02A454BC-4AC9-4D05-97B8-2DEB97F038A7}\InprocServer32]
    @="C:\\WINDOWS\\system32\\uynphost.dll"
    "ThreadingModel"="Apartment"

    Windows Registry Editor Version 5.00

    [HKEY_CLASSES_ROOT\CLSID\{66BF9F29-5C6A-43EC-A4DB-4FBB578F63D7}]
    @=""

    [HKEY_CLASSES_ROOT\CLSID\{66BF9F29-5C6A-43EC-A4DB-4FBB578F63D7}\Implemented Categories]
    @=""

    [HKEY_CLASSES_ROOT\CLSID\{66BF9F29-5C6A-43EC-A4DB-4FBB578F63D7}\Implemented Categories\{00021492-0000-0000-C000-000000000046}]
    @=""

    [HKEY_CLASSES_ROOT\CLSID\{66BF9F29-5C6A-43EC-A4DB-4FBB578F63D7}\InprocServer32]
    @="C:\\WINDOWS\\system32\\mrvbvm50.dll"
    "ThreadingModel"="Apartment"

    Windows Registry Editor Version 5.00

    [HKEY_CLASSES_ROOT\CLSID\{317EE681-0BE2-45E3-9177-405F7BFAC143}]
    @=""

    [HKEY_CLASSES_ROOT\CLSID\{317EE681-0BE2-45E3-9177-405F7BFAC143}\Implemented Categories]
    @=""

    [HKEY_CLASSES_ROOT\CLSID\{317EE681-0BE2-45E3-9177-405F7BFAC143}\Implemented Categories\{00021492-0000-0000-C000-000000000046}]
    @=""

    [HKEY_CLASSES_ROOT\CLSID\{317EE681-0BE2-45E3-9177-405F7BFAC143}\InprocServer32]
    @="C:\\WINDOWS\\system32\\otengl32.dll"
    "ThreadingModel"="Apartment"

    Windows Registry Editor Version 5.00

    [HKEY_CLASSES_ROOT\CLSID\{A01A9184-A87D-44F4-8DE2-CBBD967D9324}]
    @=""

    [HKEY_CLASSES_ROOT\CLSID\{A01A9184-A87D-44F4-8DE2-CBBD967D9324}\Implemented Categories]
    @=""

    [HKEY_CLASSES_ROOT\CLSID\{A01A9184-A87D-44F4-8DE2-CBBD967D9324}\Implemented Categories\{00021492-0000-0000-C000-000000000046}]
    @=""

    [HKEY_CLASSES_ROOT\CLSID\{A01A9184-A87D-44F4-8DE2-CBBD967D9324}\InprocServer32]
    @="C:\\WINDOWS\\system32\\szfolder.dll"
    "ThreadingModel"="Apartment"

    Windows Registry Editor Version 5.00

    [HKEY_CLASSES_ROOT\CLSID\{5D25C076-EF64-459A-AFE9-458A789792AD}]
    @=""

    [HKEY_CLASSES_ROOT\CLSID\{5D25C076-EF64-459A-AFE9-458A789792AD}\Implemented Categories]
    @=""

    [HKEY_CLASSES_ROOT\CLSID\{5D25C076-EF64-459A-AFE9-458A789792AD}\Implemented Categories\{00021492-0000-0000-C000-000000000046}]
    @=""

    [HKEY_CLASSES_ROOT\CLSID\{5D25C076-EF64-459A-AFE9-458A789792AD}\InprocServer32]
    @="C:\\WINDOWS\\system32\\kgdtat.dll"
    "ThreadingModel"="Apartment"

    Windows Registry Editor Version 5.00

    [HKEY_CLASSES_ROOT\CLSID\{12DF87D4-8CA8-4C20-80A2-0C7E1B21BA13}]
    @=""

    [HKEY_CLASSES_ROOT\CLSID\{12DF87D4-8CA8-4C20-80A2-0C7E1B21BA13}\Implemented Categories]
    @=""

    [HKEY_CLASSES_ROOT\CLSID\{12DF87D4-8CA8-4C20-80A2-0C7E1B21BA13}\Implemented Categories\{00021492-0000-0000-C000-000000000046}]
    @=""

    [HKEY_CLASSES_ROOT\CLSID\{12DF87D4-8CA8-4C20-80A2-0C7E1B21BA13}\InprocServer32]
    @="C:\\WINDOWS\\system32\\mxtlsapi.dll"
    "ThreadingModel"="Apartment"

    Windows Registry Editor Version 5.00

    [HKEY_CLASSES_ROOT\CLSID\{4F000194-AA18-44A3-BE03-E678E123E5B1}]
    @=""

    [HKEY_CLASSES_ROOT\CLSID\{4F000194-AA18-44A3-BE03-E678E123E5B1}\Implemented Categories]
    @=""

    [HKEY_CLASSES_ROOT\CLSID\{4F000194-AA18-44A3-BE03-E678E123E5B1}\Implemented Categories\{00021492-0000-0000-C000-000000000046}]
    @=""

    [HKEY_CLASSES_ROOT\CLSID\{4F000194-AA18-44A3-BE03-E678E123E5B1}\InprocServer32]
    @="C:\\WINDOWS\\system32\\guard.tmp"
    "ThreadingModel"="Apartment"

    Windows Registry Editor Version 5.00

    [HKEY_CLASSES_ROOT\CLSID\{4EC01F12-1D77-41A1-9947-E0A9F71B20AA}]
    @=""

    [HKEY_CLASSES_ROOT\CLSID\{4EC01F12-1D77-41A1-9947-E0A9F71B20AA}\Implemented Categories]
    @=""

    [HKEY_CLASSES_ROOT\CLSID\{4EC01F12-1D77-41A1-9947-E0A9F71B20AA}\Implemented Categories\{00021492-0000-0000-C000-000000000046}]
    @=""

    [HKEY_CLASSES_ROOT\CLSID\{4EC01F12-1D77-41A1-9947-E0A9F71B20AA}\InprocServer32]
    @="C:\\WINDOWS\\system32\\trflog.dll"
    "ThreadingModel"="Apartment"

    Windows Registry Editor Version 5.00

    [HKEY_CLASSES_ROOT\CLSID\{FA5C95FB-1E5B-4B05-B451-1B1083C6A9B1}]
    @=""

    [HKEY_CLASSES_ROOT\CLSID\{FA5C95FB-1E5B-4B05-B451-1B1083C6A9B1}\Implemented Categories]
    @=""

    [HKEY_CLASSES_ROOT\CLSID\{FA5C95FB-1E5B-4B05-B451-1B1083C6A9B1}\Implemented Categories\{00021492-0000-0000-C000-000000000046}]
    @=""

    [HKEY_CLASSES_ROOT\CLSID\{FA5C95FB-1E5B-4B05-B451-1B1083C6A9B1}\InprocServer32]
    @="C:\\WINDOWS\\system32\\decpmon.dll"
    "ThreadingModel"="Apartment"

    Windows Registry Editor Version 5.00

    [HKEY_CLASSES_ROOT\CLSID\{DCD99A13-1B9A-4912-9A8D-85A04CA33CC6}]
    @=""

    [HKEY_CLASSES_ROOT\CLSID\{DCD99A13-1B9A-4912-9A8D-85A04CA33CC6}\Implemented Categories]
    @=""

    [HKEY_CLASSES_ROOT\CLSID\{DCD99A13-1B9A-4912-9A8D-85A04CA33CC6}\Implemented Categories\{00021492-0000-0000-C000-000000000046}]
    @=""

    [HKEY_CLASSES_ROOT\CLSID\{DCD99A13-1B9A-4912-9A8D-85A04CA33CC6}\InprocServer32]
    @="C:\\WINDOWS\\system32\\fhp8037ue.dll"
    "ThreadingModel"="Apartment"

    Windows Registry Editor Version 5.00

    [HKEY_CLASSES_ROOT\CLSID\{5A025223-DC53-4A8D-85A0-ADFB8B2FAE9A}]
    @=""

    [HKEY_CLASSES_ROOT\CLSID\{5A025223-DC53-4A8D-85A0-ADFB8B2FAE9A}\Implemented Categories]
    @=""

    [HKEY_CLASSES_ROOT\CLSID\{5A025223-DC53-4A8D-85A0-ADFB8B2FAE9A}\Implemented Categories\{00021492-0000-0000-C000-000000000046}]
    @=""

    [HKEY_CLASSES_ROOT\CLSID\{5A025223-DC53-4A8D-85A0-ADFB8B2FAE9A}\InprocServer32]
    @="C:\\WINDOWS\\system32\\sfnceng.dll"
    "ThreadingModel"="Apartment"

    Windows Registry Editor Version 5.00

    [HKEY_CLASSES_ROOT\CLSID\{447423E8-D11B-4446-9120-7276216A40CE}]
    @=""

    [HKEY_CLASSES_ROOT\CLSID\{447423E8-D11B-4446-9120-7276216A40CE}\Implemented Categories]
    @=""

    [HKEY_CLASSES_ROOT\CLSID\{447423E8-D11B-4446-9120-7276216A40CE}\Implemented Categories\{00021492-0000-0000-C000-000000000046}]
    @=""

    [HKEY_CLASSES_ROOT\CLSID\{447423E8-D11B-4446-9120-7276216A40CE}\InprocServer32]
    @="C:\\WINDOWS\\system32\\vprifier.dll"
    "ThreadingModel"="Apartment"

    Windows Registry Editor Version 5.00

    [HKEY_CLASSES_ROOT\CLSID\{5EC92A5A-0848-4963-BC3C-7AA14C23327B}]
    @=""

    [HKEY_CLASSES_ROOT\CLSID\{5EC92A5A-0848-4963-BC3C-7AA14C23327B}\Implemented Categories]
    @=""

    [HKEY_CLASSES_ROOT\CLSID\{5EC92A5A-0848-4963-BC3C-7AA14C23327B}\Implemented Categories\{00021492-0000-0000-C000-000000000046}]
    @=""

    [HKEY_CLASSES_ROOT\CLSID\{5EC92A5A-0848-4963-BC3C-7AA14C23327B}\InprocServer32]
    @="C:\\WINDOWS\\system32\\opbcp32r.dll"
    "ThreadingModel"="Apartment"

    Windows Registry Editor Version 5.00

    [HKEY_CLASSES_ROOT\CLSID\{238CB486-647C-4B88-9FFB-4142585F8A81}]
    @=""

    [HKEY_CLASSES_ROOT\CLSID\{238CB486-647C-4B88-9FFB-4142585F8A81}\Implemented Categories]
    @=""

    [HKEY_CLASSES_ROOT\CLSID\{238CB486-647C-4B88-9FFB-4142585F8A81}\Implemented Categories\{00021492-0000-0000-C000-000000000046}]
    @=""

    [HKEY_CLASSES_ROOT\CLSID\{238CB486-647C-4B88-9FFB-4142585F8A81}\InprocServer32]
    @="C:\\WINDOWS\\system32\\moiole16.dll"
    "ThreadingModel"="Apartment"

    Windows Registry Editor Version 5.00

    [HKEY_CLASSES_ROOT\CLSID\{2F87EC4D-0115-4D77-BA2E-0C557B88D36F}]
    @=""

    [HKEY_CLASSES_ROOT\CLSID\{2F87EC4D-0115-4D77-BA2E-0C557B88D36F}\Implemented Categories]
    @=""

    [HKEY_CLASSES_ROOT\CLSID\{2F87EC4D-0115-4D77-BA2E-0C557B88D36F}\Implemented Categories\{00021492-0000-0000-C000-000000000046}]
    @=""

    [HKEY_CLASSES_ROOT\CLSID\{2F87EC4D-0115-4D77-BA2E-0C557B88D36F}\InprocServer32]
    @="C:\\WINDOWS\\system32\\bfowsewm.dll"
    "ThreadingModel"="Apartment"

    Windows Registry Editor Version 5.00

    [HKEY_CLASSES_ROOT\CLSID\{CD74549F-60D3-44DE-AE57-22BFB5237EEA}]
    @=""

    [HKEY_CLASSES_ROOT\CLSID\{CD74549F-60D3-44DE-AE57-22BFB5237EEA}\Implemented Categories]
    @=""

    [HKEY_CLASSES_ROOT\CLSID\{CD74549F-60D3-44DE-AE57-22BFB5237EEA}\Implemented Categories\{00021492-0000-0000-C000-000000000046}]
    @=""

    [HKEY_CLASSES_ROOT\CLSID\{CD74549F-60D3-44DE-AE57-22BFB5237EEA}\InprocServer32]
    @="C:\\WINDOWS\\system32\\ibwdial.dll"
    "ThreadingModel"="Apartment"

    Windows Registry Editor Version 5.00

    [HKEY_CLASSES_ROOT\CLSID\{16B9AF1D-E035-49F3-A0C0-A6D9BA00CDD8}]
    @=""

    [HKEY_CLASSES_ROOT\CLSID\{16B9AF1D-E035-49F3-A0C0-A6D9BA00CDD8}\Implemented Categories]
    @=""

    [HKEY_CLASSES_ROOT\CLSID\{16B9AF1D-E035-49F3-A0C0-A6D9BA00CDD8}\Implemented Categories\{00021492-0000-0000-C000-000000000046}]
    @=""

    [HKEY_CLASSES_ROOT\CLSID\{16B9AF1D-E035-49F3-A0C0-A6D9BA00CDD8}\InprocServer32]
    @="C:\\WINDOWS\\system32\\nTrrhook.dll"
    "ThreadingModel"="Apartment"

    Windows Registry Editor Version 5.00

    [HKEY_CLASSES_ROOT\CLSID\{6D0E8A2D-BAB7-4417-924F-6388797DF420}]
    @=""

    [HKEY_CLASSES_ROOT\CLSID\{6D0E8A2D-BAB7-4417-924F-6388797DF420}\Implemented Categories]
    @=""

    [HKEY_CLASSES_ROOT\CLSID\{6D0E8A2D-BAB7-4417-924F-6388797DF420}\Implemented Categories\{00021492-0000-0000-C000-000000000046}]
    @=""

    [HKEY_CLASSES_ROOT\CLSID\{6D0E8A2D-BAB7-4417-924F-6388797DF420}\InprocServer32]
    @="C:\\WINDOWS\\system32\\hQ23msp.dll"
    "ThreadingModel"="Apartment"

    Windows Registry Editor Version 5.00

    [HKEY_CLASSES_ROOT\CLSID\{88B640AA-BBB5-47EF-8077-620A973AAD0B}]
    @=""

    [HKEY_CLASSES_ROOT\CLSID\{88B640AA-BBB5-47EF-8077-620A973AAD0B}\Implemented Categories]
    @=""

    [HKEY_CLASSES_ROOT\CLSID\{88B640AA-BBB5-47EF-8077-620A973AAD0B}\Implemented Categories\{00021492-0000-0000-C000-000000000046}]
    @=""

    [HKEY_CLASSES_ROOT\CLSID\{88B640AA-BBB5-47EF-8077-620A973AAD0B}\InprocServer32]
    @="C:\\WINDOWS\\system32\\amitvo32.dll"
    "ThreadingModel"="Apartment"

    Windows Registry Editor Version 5.00

    [HKEY_CLASSES_ROOT\CLSID\{CE84CD16-3D8A-424C-A652-C7382A1C0BB2}]
    @=""

    [HKEY_CLASSES_ROOT\CLSID\{CE84CD16-3D8A-424C-A652-C7382A1C0BB2}\Implemented Categories]
    @=""

    [HKEY_CLASSES_ROOT\CLSID\{CE84CD16-3D8A-424C-A652-C7382A1C0BB2}\Implemented Categories\{00021492-0000-0000-C000-000000000046}]
    @=""

    [HKEY_CLASSES_ROOT\CLSID\{CE84CD16-3D8A-424C-A652-C7382A1C0BB2}\InprocServer32]
    @="C:\\WINDOWS\\system32\\fusrch.dll"
    "ThreadingModel"="Apartment"

    Windows Registry Editor Version 5.00

    [HKEY_CLASSES_ROOT\CLSID\{E8468BA0-63A8-4BBF-8D77-DCD5DC033FCB}]
    @=""

    [HKEY_CLASSES_ROOT\CLSID\{E8468BA0-63A8-4BBF-8D77-DCD5DC033FCB}\Implemented Categories]
    @=""

    [HKEY_CLASSES_ROOT\CLSID\{E8468BA0-63A8-4BBF-8D77-DCD5DC033FCB}\Implemented Categories\{00021492-0000-0000-C000-000000000046}]
    @=""

    [HKEY_CLASSES_ROOT\CLSID\{E8468BA0-63A8-4BBF-8D77-DCD5DC033FCB}\InprocServer32]
    @="C:\\WINDOWS\\system32\\sfi_ci.dll"
    "ThreadingModel"="Apartment"

    Windows Registry Editor Version 5.00

    [HKEY_CLASSES_ROOT\CLSID\{D9A5F243-70DB-4E79-9224-E7C15B2B821D}]
    @=""

    [HKEY_CLASSES_ROOT\CLSID\{D9A5F243-70DB-4E79-9224-E7C15B2B821D}\Implemented Categories]
    @=""

    [HKEY_CLASSES_ROOT\CLSID\{D9A5F243-70DB-4E79-9224-E7C15B2B821D}\Implemented Categories\{00021492-0000-0000-C000-000000000046}]
    @=""

    [HKEY_CLASSES_ROOT\CLSID\{D9A5F243-70DB-4E79-9224-E7C15B2B821D}\InprocServer32]
    @="C:\\WINDOWS\\system32\\guard.tmp"
    "ThreadingModel"="Apartment"

    Windows Registry Editor Version 5.00

    [HKEY_CLASSES_ROOT\CLSID\{84FCB1BC-6756-4DD2-9A67-69F3118CAD81}]
    @=""

    [HKEY_CLASSES_ROOT\CLSID\{84FCB1BC-6756-4DD2-9A67-69F3118CAD81}\Implemented Categories]
    @=""

    [HKEY_CLASSES_ROOT\CLSID\{84FCB1BC-6756-4DD2-9A67-69F3118CAD81}\Implemented Categories\{00021492-0000-0000-C000-000000000046}]
    @=""

    [HKEY_CLASSES_ROOT\CLSID\{84FCB1BC-6756-4DD2-9A67-69F3118CAD81}\InprocServer32]
    @="C:\\WINDOWS\\system32\\issutil.dll"
    "ThreadingModel"="Apartment"

    Windows Registry Editor Version 5.00

    [HKEY_CLASSES_ROOT\CLSID\{2B320E0D-0F07-402F-9C5F-23F05F0755CE}]
    @=""

    [HKEY_CLASSES_ROOT\CLSID\{2B320E0D-0F07-402F-9C5F-23F05F0755CE}\Implemented Categories]
    @=""

    [HKEY_CLASSES_ROOT\CLSID\{2B320E0D-0F07-402F-9C5F-23F05F0755CE}\Implemented Categories\{00021492-0000-0000-C000-000000000046}]
    @=""

    [HKEY_CLASSES_ROOT\CLSID\{2B320E0D-0F07-402F-9C5F-23F05F0755CE}\InprocServer32]
    @="C:\\WINDOWS\\system32\\WYDMLOG.dll"
    "ThreadingModel"="Apartment"

    Windows Registry Editor Version 5.00

    [HKEY_CLASSES_ROOT\CLSID\{AE55B1B6-A5FA-4AAC-B52C-D4A5EB6F30D3}]
    @=""

    [HKEY_CLASSES_ROOT\CLSID\{AE55B1B6-A5FA-4AAC-B52C-D4A5EB6F30D3}\Implemented Categories]
    @=""

    [HKEY_CLASSES_ROOT\CLSID\{AE55B1B6-A5FA-4AAC-B52C-D4A5EB6F30D3}\Implemented Categories\{00021492-0000-0000-C000-000000000046}]
    @=""

    [HKEY_CLASSES_ROOT\CLSID\{AE55B1B6-A5FA-4AAC-B52C-D4A5EB6F30D3}\InprocServer32]
    @="C:\\WINDOWS\\system32\\guard.tmp"
    "ThreadingModel"="Apartment"

    **********************************************************************************
    Files Found are not all bad files:

    C:\WINDOWS\SYSTEM32\
    f8j2li~1.dll Sat 4 Feb 2006 22.17.14 ..S.R 234 013 228,53 K
    ktnml7~1.dll Thu 5 Jan 2006 18.15.38 A.... 236 854 231,30 K
    lvro09~1.dll Sun 5 Feb 2006 4.53.16 ..S.R 236 273 230,73 K
    lvru09~1.dll Sun 5 Feb 2006 13.18.40 ..S.R 236 833 231,28 K
    m8280i~1.dll Sun 5 Feb 2006 13.18.36 ..S.R 237 101 231,54 K
    q068la~1.dll Sat 4 Feb 2006 22.17.10 ..S.R 234 178 228,69 K
    r48s0e~1.dll Sat 4 Feb 2006 22.00.20 ..S.R 234 170 228,68 K
    s32evnt1.dll Thu 1 Dec 2005 12.14.20 A.... 86 091 84,07 K
    vsdata.dll Tue 15 Nov 2005 0.50.30 A.... 83 720 81,76 K
    vsinit.dll Tue 15 Nov 2005 0.50.42 A.... 141 064 137,76 K
    vsmonapi.dll Tue 15 Nov 2005 0.50.52 A.... 104 208 101,77 K
    vspubapi.dll Tue 15 Nov 2005 0.50.56 A.... 227 088 221,77 K
    vsregexp.dll Tue 15 Nov 2005 0.51.00 A.... 71 440 69,77 K
    vsutil.dll Tue 15 Nov 2005 0.51.12 A.... 382 728 373,76 K
    vsxml.dll Tue 15 Nov 2005 0.51.20 A.... 100 104 97,76 K
    zlcomm.dll Tue 15 Nov 2005 0.51.40 A.... 79 624 77,76 K
    zlcommdb.dll Tue 15 Nov 2005 0.51.44 A.... 71 440 69,77 K
    __dele~1.dll Sun 5 Feb 2006 13.27.04 A.... 236 273 230,73 K

    18 items found: 18 files (6 H/S), 0 directories.
    Total of file sizes: 3 233 202 bytes 3,08 M
    Locate .tmp files:

    C:\WINDOWS\SYSTEM32\
    guard.tmp Sun 5 Feb 2006 13.30.04 ..... 236 273 230,73 K
    __dele~1.tmp Sun 5 Feb 2006 13.29.04 A.... 236 273 230,73 K

    2 items found: 2 files, 0 directories.
    Total of file sizes: 472 546 bytes 461,47 K
    **********************************************************************************
    Directory Listing of system files:
    Asemalla C ei ole nime„.
    Aseman sarjanumero on 6C95-49E5

    Kansio C:\WINDOWS\System32

    05.02.2006 13:18 236ÿ833 lvru0999e.dll
    05.02.2006 13:18 237ÿ101 m8280ifue8280.dll
    05.02.2006 04:53 236ÿ273 lvro0993e.dll
    04.02.2006 22:17 234ÿ013 f8j2li1o18.dll
    04.02.2006 22:17 234ÿ178 q068laju1do8.dll
    04.02.2006 22:00 234ÿ170 r48s0el7ehq.dll
    23.12.2005 15:52 <KANSIO> dllcache
    15.11.2005 22:19 <KANSIO> Microsoft
    6 tiedosto(a) 1ÿ412ÿ568 tavua
    2 kansio(ta) 2ÿ287ÿ460ÿ352 tavua vapaana
     
  2. k0ll1

    k0ll1 Member

    Joined:
    Sep 16, 2004
    Messages:
    24
    Likes Received:
    0
    Trophy Points:
    11
  3. ratnunter

    ratnunter Regular member

    Joined:
    Jun 9, 2005
    Messages:
    131
    Likes Received:
    0
    Trophy Points:
    26
    joo, ton l2mefixin kanssa on ollu viime aikoina ongelmia. kokeillaan yhtä vaihtoehtoa ja hieman muokattuja batcheja..otin yhteyttä l2mefixin tekijään, mutta vielä en o saanu vastausta. toivottavasti siihen saadan päivitys joka saa sen toimiin myös suomenkielisessä windowsissa..

    tämä allaoleva fiksi on sitte kokeilu luontonen, jos oot valmis ottaan riskin niin ole hyvä. muuten noi filut häviää tuolta tän jälkeen, paitsi jos shadowwar antaa luvan


    ihan ekaks, jos sulla on l2mefix työpöydällä niin siirrä se kansio c:\asemalle

    sitte klikkaa seuraavaa linkkiä hiiren oikeella napilla=> tallenna nimellä. tallenna siihen siirrettyyn l2mefix kansioon, anna korvata alkuperäinen
    http://koti.mbnet.fi/illukka/second.bat
    ja tee sama myös seuraavan linkin kanssa
    http://koti.mbnet.fi/illukka/l2mfix.bat
    eli tallenna nimellä siihen l2mefix kansioon, anna korvata vanha uudella

    sitte tuplaklikkaa l2mefix.bat, valitse vaihtoehto run fix painamalla 2 ja enter. äläkä paina mitään näppäimiä kunnes sanotaan press any key to reboot

    jos kone ei käynnisty automaattisesti uudelleen, tee se itte
    notepadin pitäs aueta lokin kanssa, laita se tänne

    laita myös uusi hjt loki
     
  4. k0ll1

    k0ll1 Member

    Joined:
    Sep 16, 2004
    Messages:
    24
    Likes Received:
    0
    Trophy Points:
    11
    Juu ei näytä tämäkään toimivan,lokia ei näkynyt boottamisen jälkeen,eikä sitä ollu myöskään siellä l2mfix:n kansiossa.
     
  5. ratnunter

    ratnunter Regular member

    Joined:
    Jun 9, 2005
    Messages:
    131
    Likes Received:
    0
    Trophy Points:
    26
    jaaha,

    nythän on niin et l2mefix on päivitetty, joten imuroi se uudelleen, korvaa vanha uudella, pura kansioon c:\asemalle

    sitte otetaan loki vaihtoehdolla 1
    laita se tänne.
    koitetaa vielä kerran

    sitte on pakko yrittää manuaalisesti jos ei pelitä


     
  6. k0ll1

    k0ll1 Member

    Joined:
    Sep 16, 2004
    Messages:
    24
    Likes Received:
    0
    Trophy Points:
    11
    Mistä sen päivitetyn version saa?
     
  7. Zipp2

    Zipp2 Regular member

    Joined:
    Sep 30, 2005
    Messages:
    376
    Likes Received:
    0
    Trophy Points:
    26
    Kemistin linkistä 1. helmikuuta 2006 @ 01:29 mutta poista se vanha ensin.
     
  8. k0ll1

    k0ll1 Member

    Joined:
    Sep 16, 2004
    Messages:
    24
    Likes Received:
    0
    Trophy Points:
    11
    L2MFIX find log 010406
    These are the registry keys present
    **********************************************************************************
    Winlogon/notify:
    Windows Registry Editor Version 5.00

    [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify]

    [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\AtiExtEvent]
    "DLLName"="Ati2evxx.dll"
    "Asynchronous"=dword:00000000
    "Impersonate"=dword:00000001
    "Lock"="AtiLockEvent"
    "Logoff"="AtiLogoffEvent"
    "Logon"="AtiLogonEvent"
    "Disconnect"="AtiDisConnectEvent"
    "Reconnect"="AtiReConnectEvent"
    "Safe"=dword:00000000
    "Shutdown"="AtiShutdownEvent"
    "StartScreenSaver"="AtiStartScreenSaverEvent"
    "StartShell"="AtiStartShellEvent"
    "Startup"="AtiStartupEvent"
    "StopScreenSaver"="AtiStopScreenSaverEvent"
    "Unlock"="AtiUnLockEvent"

    [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\crypt32chain]
    "Asynchronous"=dword:00000000
    "Impersonate"=dword:00000000
    "DllName"=hex(2):63,00,72,00,79,00,70,00,74,00,33,00,32,00,2e,00,64,00,6c,00,\
    6c,00,00,00
    "Logoff"="ChainWlxLogoffEvent"

    [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\cryptnet]
    "Asynchronous"=dword:00000000
    "Impersonate"=dword:00000000
    "DllName"=hex(2):63,00,72,00,79,00,70,00,74,00,6e,00,65,00,74,00,2e,00,64,00,\
    6c,00,6c,00,00,00
    "Logoff"="CryptnetWlxLogoffEvent"

    [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\cscdll]
    "DLLName"="cscdll.dll"
    "Logon"="WinlogonLogonEvent"
    "Logoff"="WinlogonLogoffEvent"
    "ScreenSaver"="WinlogonScreenSaverEvent"
    "Startup"="WinlogonStartupEvent"
    "Shutdown"="WinlogonShutdownEvent"
    "StartShell"="WinlogonStartShellEvent"
    "Impersonate"=dword:00000000
    "Asynchronous"=dword:00000001

    [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\ScCertProp]
    "DLLName"="wlnotify.dll"
    "Logon"="SCardStartCertProp"
    "Logoff"="SCardStopCertProp"
    "Lock"="SCardSuspendCertProp"
    "Unlock"="SCardResumeCertProp"
    "Enabled"=dword:00000001
    "Impersonate"=dword:00000001
    "Asynchronous"=dword:00000001

    [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\Schedule]
    "Asynchronous"=dword:00000000
    "DllName"=hex(2):77,00,6c,00,6e,00,6f,00,74,00,69,00,66,00,79,00,2e,00,64,00,\
    6c,00,6c,00,00,00
    "Impersonate"=dword:00000000
    "StartShell"="SchedStartShell"
    "Logoff"="SchedEventLogOff"

    [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\sclgntfy]
    "Logoff"="WLEventLogoff"
    "Impersonate"=dword:00000000
    "Asynchronous"=dword:00000001
    "DllName"=hex(2):73,00,63,00,6c,00,67,00,6e,00,74,00,66,00,79,00,2e,00,64,00,\
    6c,00,6c,00,00,00

    [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\SensLogn]
    "DLLName"="WlNotify.dll"
    "Lock"="SensLockEvent"
    "Logon"="SensLogonEvent"
    "Logoff"="SensLogoffEvent"
    "Safe"=dword:00000001
    "MaxWait"=dword:00000258
    "StartScreenSaver"="SensStartScreenSaverEvent"
    "StopScreenSaver"="SensStopScreenSaverEvent"
    "Startup"="SensStartupEvent"
    "Shutdown"="SensShutdownEvent"
    "StartShell"="SensStartShellEvent"
    "PostShell"="SensPostShellEvent"
    "Disconnect"="SensDisconnectEvent"
    "Reconnect"="SensReconnectEvent"
    "Unlock"="SensUnlockEvent"
    "Impersonate"=dword:00000001
    "Asynchronous"=dword:00000001

    [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\termsrv]
    "Asynchronous"=dword:00000000
    "DllName"=hex(2):77,00,6c,00,6e,00,6f,00,74,00,69,00,66,00,79,00,2e,00,64,00,\
    6c,00,6c,00,00,00
    "Impersonate"=dword:00000000
    "Logoff"="TSEventLogoff"
    "Logon"="TSEventLogon"
    "PostShell"="TSEventPostShell"
    "Shutdown"="TSEventShutdown"
    "StartShell"="TSEventStartShell"
    "Startup"="TSEventStartup"
    "MaxWait"=dword:00000258
    "Reconnect"="TSEventReconnect"
    "Disconnect"="TSEventDisconnect"

    [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\WindowsUpdate]
    "Asynchronous"=dword:00000000
    "DllName"="C:\\WINDOWS\\system32\\m8rmli9118.dll"
    "Impersonate"=dword:00000000
    "Logon"="WinLogon"
    "Logoff"="WinLogoff"
    "Shutdown"="WinShutdown"

    [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\wlballoon]
    "DLLName"="wlnotify.dll"
    "Logon"="RegisterTicketExpiredNotificationEvent"
    "Logoff"="UnregisterTicketExpiredNotificationEvent"
    "Impersonate"=dword:00000001
    "Asynchronous"=dword:00000001

    [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\wzcnotif]
    "DLLName"="wzcdlg.dll"
    "Logon"="WZCEventLogon"
    "Logoff"="WZCEventLogoff"
    "Impersonate"=dword:00000000
    "Asynchronous"=dword:00000000

    **********************************************************************************
    useragent:
    Windows Registry Editor Version 5.00

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\User Agent\Post Platform]
    "{A76D69E0-B875-D62C-F403-E17A849686D7}"=""

    **********************************************************************************
    Shell Extension key:
    Windows Registry Editor Version 5.00

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved]
    "{00022613-0000-0000-C000-000000000046}"="Multimediatiedoston ominaisuusikkuna"
    "{176d6597-26d3-11d1-b350-080036a75b03}"="ICM-kuvanlukijan hallinta"
    "{1F2E5C40-9550-11CE-99D2-00AA006E086C}"="NTFS-suojaussivu"
    "{3EA48300-8CF6-101B-84FB-666CCB9BCD32}"="OLE-asiakirjatiedoston ominaisuussivu"
    "{40dd6e20-7c17-11ce-a804-00aa003ca9f6}"="Liittym„laajennus jakamista varten"
    "{41E300E0-78B6-11ce-849B-444553540000}"="PlusPack CPL Extension"
    "{42071712-76d4-11d1-8b24-00a0c9068ff3}"="N„ytt”sovittimen CPL-laajennus"
    "{42071713-76d4-11d1-8b24-00a0c9068ff3}"="N„yt”n CPL -laajennus"
    "{42071714-76d4-11d1-8b24-00a0c9068ff3}"="Display Panning CPL -laajennus"
    "{4E40F770-369C-11d0-8922-00A024AB2DBB}"="Hakemistopalvelun suojaussivu"
    "{513D916F-2A8E-4F51-AEAB-0CBC76FB1AF8}"="Yhteensopivuussivusto"
    "{56117100-C0CD-101B-81E2-00AA004AE837}"="K„ytt”liittym„n leikkeidenk„sittelytoiminto"
    "{59099400-57FF-11CE-BD94-0020AF85B590}"="Levykkeen kopiointilaajennus"
    "{59be4990-f85c-11ce-aff7-00aa003ca9f6}"="Microsoft Windows -verkon objektien liittym„laajennukset"
    "{5DB2625A-54DF-11D0-B6C4-0800091AA605}"="ICM-n„yt”n hallinta"
    "{675F097E-4C4D-11D0-B6C1-0800091AA605}"="ICM-tulostimen hallinta"
    "{764BF0E1-F219-11ce-972D-00AA00A14F56}"="Tiedostonpakkauksen liittym„laajennukset"
    "{77597368-7b15-11d0-a0c2-080036af3f03}"="Web-tulostimen liittym„laajennus"
    "{7988B573-EC89-11cf-9C00-00AA00A14F56}"="Disk Quota UI"
    "{853FE2B1-B769-11d0-9C4E-00C04FB6C6FA}"="Salauksen pikavalikko"
    "{85BBD920-42A0-1069-A2E4-08002B30309D}"="Salkku"
    "{88895560-9AA2-1069-930E-00AA0030EBC8}"="HyperTerminal-kuvakkeen tunniste"
    "{BD84B380-8CA2-1069-AB1D-08000948F534}"="Fonts"
    "{DBCE2480-C732-101B-BE72-BA78E9AD5B27}"="ICC-profiili"
    "{F37C5810-4D3F-11d0-B4BF-00AA00BBB723}"="Tulostimen suojaussivu"
    "{f81e9010-6ea4-11ce-a7ff-00aa003ca9f6}"="Liittym„laajennus jakamista varten"
    "{f92e8c40-3d33-11d2-b1aa-080036a75b03}"="Display TroubleShoot CPL Extension"
    "{7444C717-39BF-11D1-8CD9-00C04FC29D45}"="Crypto PKO -laajennus"
    "{7444C719-39BF-11D1-8CD9-00C04FC29D45}"="Crypto Sign -laajennus"
    "{7007ACC7-3202-11D1-AAD2-00805FC1270E}"="Verkkoyhteydet"
    "{992CFFA0-F557-101A-88EC-00DD010CCC48}"="Verkkoyhteydet"
    "{E211B736-43FD-11D1-9EFB-0000F8757FCD}"="Skannerit ja kamerat"
    "{FB0C9C8A-6C50-11D1-9F1D-0000F8757FCD}"="Skannerit ja kamerat"
    "{905667aa-acd6-11d2-8080-00805f6596d2}"="Skannerit ja kamerat"
    "{3F953603-1008-4f6e-A73A-04AAC7A992F1}"="Skannerit ja kamerat"
    "{83bbcbf3-b28a-4919-a5aa-73027445d672}"="Skannerit ja kamerat"
    "{F0152790-D56E-4445-850E-4F3117DB740C}"="Remote Sessions CPL Extension"
    "{5F327514-6C5E-4d60-8F16-D07FA08A78ED}"="Auto Update Property Sheet Extension"
    "{60254CA5-953B-11CF-8C96-00AA00B8708C}"="Windows Script Hostin liittym„laajennukset"
    "{2206CDB2-19C1-11D1-89E0-00C04FD7A829}"="Microsoft-tietolinkki"
    "{DD2110F0-9EEF-11cf-8D8E-00AA0060F5BF}"="Tasks Folder Icon Handler"
    "{797F1E90-9EDD-11cf-8D8E-00AA0060F5BF}"="Tasks Folder Shell Extension"
    "{D6277990-4C6A-11CF-8D87-00AA0060F5BF}"="Ajoitetut teht„v„t"
    "{0DF44EAA-FF21-4412-828E-260A8728E7F1}"="Teht„v„palkki ja K„ynnist„-valikko"
    "{2559a1f0-21d7-11d4-bdaf-00c04f60b9f0}"="Etsi"
    "{2559a1f1-21d7-11d4-bdaf-00c04f60b9f0}"="Ohje ja tuki"
    "{2559a1f2-21d7-11d4-bdaf-00c04f60b9f0}"="Ohje ja tuki"
    "{2559a1f3-21d7-11d4-bdaf-00c04f60b9f0}"="Suorita..."
    "{2559a1f4-21d7-11d4-bdaf-00c04f60b9f0}"="Internet"
    "{2559a1f5-21d7-11d4-bdaf-00c04f60b9f0}"="S„hk”posti"
    "{D20EA4E1-3957-11d2-A40B-0C5020524152}"="Fontit"
    "{D20EA4E1-3957-11d2-A40B-0C5020524153}"="Valvontaty”kalut"
    "{875CB1A1-0F29-45de-A1AE-CFB4950D0B78}"="Audio Media Properties Handler"
    "{40C3D757-D6E4-4b49-BB41-0E5BBEA28817}"="Video Media Properties Handler"
    "{E4B29F9D-D390-480b-92FD-7DDB47101D71}"="Wav Properties Handler"
    "{87D62D94-71B3-4b9a-9489-5FE6850DC73E}"="Avi Properties Handler"
    "{A6FD9E45-6E44-43f9-8644-08598F5A74D9}"="Midi Properties Handler"
    "{c5a40261-cd64-4ccf-84cb-c394da41d590}"="Video Thumbnail Extractor"
    "{5E6AB780-7743-11CF-A12B-00AA004AE837}"="Microsoft Internet-ty”kalurivi"
    "{22BF0C20-6DA7-11D0-B373-00A0C9034938}"="Lataamisen tila"
    "{91EA3F8B-C99B-11d0-9815-00C04FD91972}"="Augmented Shell Folder"
    "{6413BA2C-B461-11d1-A18A-080036B11A03}"="Augmented Shell Folder 2"
    "{F61FFEC1-754F-11d0-80CA-00AA005B4383}"="BandProxy"
    "{7BA4C742-9E81-11CF-99D3-00AA004AE837}"="Microsoft BrowserBand"
    "{30D02401-6A81-11d0-8274-00C04FD5AE38}"="Etsint„palkki"
    "{32683183-48a0-441b-a342-7c2a440a9478}"="Media-palkki"
    "{169A0691-8DF9-11d1-A1C4-00C04FD75D13}"="In-pane search"
    "{07798131-AF23-11d1-9111-00A0C98BA67D}"="Web Search"
    "{AF4F6510-F982-11d0-8595-00AA004CD6D8}"="Registry Tree Options Utility"
    "{01E04581-4EEE-11d0-BFE9-00AA005B4383}"="&L„hiosoite"
    "{A08C11D2-A228-11d0-825B-00AA005B4383}"="Address EditBox"
    "{00BB2763-6A77-11D0-A535-00C04FD7D062}"="Microsoft AutoComplete"
    "{7376D660-C583-11d0-A3A5-00C04FD706EC}"="TridentImageExtractor"
    "{6756A641-DE71-11d0-831B-00AA005B4383}"="MRU AutoComplete List"
    "{6935DB93-21E8-4ccc-BEB9-9FE3C77A297A}"="Custom MRU AutoCompleted List"
    "{7e653215-fa25-46bd-a339-34a2790f3cb7}"="Accessible"
    "{acf35015-526e-4230-9596-becbe19f0ac9}"="Track Popup Bar"
    "{E0E11A09-5CB8-4B6C-8332-E00720A168F2}"="Osoitepalkin j„sent„j„"
    "{00BB2764-6A77-11D0-A535-00C04FD7D062}"="Microsoft History AutoComplete List"
    "{03C036F1-A186-11D0-824A-00AA005B4383}"="Microsoft Shell Folder AutoComplete List"
    "{00BB2765-6A77-11D0-A535-00C04FD7D062}"="Microsoft Multiple AutoComplete List Container"
    "{ECD4FC4E-521C-11D0-B792-00A0C90312E1}"="Shell Band Site Menu"
    "{3CCF8A41-5C85-11d0-9796-00AA00B90ADF}"="Shell DeskBarApp"
    "{ECD4FC4C-521C-11D0-B792-00A0C90312E1}"="Shell DeskBar"
    "{ECD4FC4D-521C-11D0-B792-00A0C90312E1}"="Shell Rebar BandSite"
    "{DD313E04-FEFF-11d1-8ECD-0000F87A470C}"="User Assist"
    "{EF8AD2D1-AE36-11D1-B2D2-006097DF8C11}"="Global Folder Settings"
    "{EFA24E61-B078-11d0-89E4-00C04FC9E26E}"="Favorites Band"
    "{0A89A860-D7B1-11CE-8350-444553540000}"="Shell Automation Inproc Service"
    "{E7E4BC40-E76A-11CE-A9BB-00AA004AE837}"="Shell DocObject Viewer"
    "{A5E46E3A-8849-11D1-9D8C-00C04FC99D61}"="Microsoft Browser Architecture"
    "{FBF23B40-E3F0-101B-8488-00AA003E56F8}"="InternetShortcut"
    "{3C374A40-BAE4-11CF-BF7D-00AA006946EE}"="Microsoft Url History Service"
    "{FF393560-C2A7-11CF-BFF4-444553540000}"="Sivuhistoria"
    "{7BD29E00-76C1-11CF-9DD0-00A0C9034933}"="Temporary Internet Files"
    "{7BD29E01-76C1-11CF-9DD0-00A0C9034933}"="Temporary Internet Files"
    "{CFBFAE00-17A6-11D0-99CB-00C04FD64497}"="Microsoft Url Search Hook"
    "{A2B0DD40-CC59-11d0-A3A5-00C04FD706EC}"="IE4 Suite Splash Screen"
    "{67EA19A0-CCEF-11d0-8024-00C04FD75D13}"="CDF Extension Copy Hook"
    "{131A6951-7F78-11D0-A979-00C04FD705A2}"="ISFBand OC"
    "{9461b922-3c5a-11d2-bf8b-00c04fb93661}"="Search Assistant OC"
    "{3DC7A020-0ACD-11CF-A9BB-00AA004AE837}"="Internet"
    "{871C5380-42A0-1069-A2EA-08002B30309D}"="Internet Name Space"
    "{EFA24E64-B078-11d0-89E4-00C04FC9E26E}"="Explorer Band"
    "{9E56BE60-C50F-11CF-9A2C-00A0C90A90CE}"="Sendmail service"
    "{9E56BE61-C50F-11CF-9A2C-00A0C90A90CE}"="Sendmail service"
    "{88C6C381-2E85-11D0-94DE-444553540000}"="ActiveX-v„limuistikansio"
    "{E6FB5E20-DE35-11CF-9C87-00AA005127ED}"="WebCheck"
    "{ABBE31D0-6DAE-11D0-BECA-00C04FD940BE}"="Subscription Mgr"
    "{F5175861-2688-11d0-9C5E-00AA00A45957}"="Subscription Folder"
    "{08165EA0-E946-11CF-9C87-00AA005127ED}"="WebCheckWebCrawler"
    "{E3A8BDE6-ABCE-11d0-BC4B-00C04FD929DB}"="WebCheckChannelAgent"
    "{E8BB6DC0-6B4E-11d0-92DB-00A0C90C2BD7}"="TrayAgent"
    "{7D559C10-9FE9-11d0-93F7-00AA0059CE02}"="Code Download Agent"
    "{E6CC6978-6B6E-11D0-BECA-00C04FD940BE}"="ConnectionAgent"
    "{D8BD2030-6FC9-11D0-864F-00AA006809D9}"="PostAgent"
    "{7FC0B86E-5FA7-11d1-BC7C-00C04FD929DB}"="WebCheck SyncMgr Handler"
    "{352EC2B7-8B9A-11D1-B8AE-006008059382}"="K„ytt”liittym„n sovelluksenhallintaohjelma"
    "{0B124F8F-91F0-11D1-B8B5-006008059382}"="Sovellusluettelo asennettiin"
    "{CFCCC7A0-A282-11D1-9082-006008059382}"="Darwin App Publisher"
    "{e84fda7c-1d6a-45f6-b725-cb260c236066}"="Shell Image Verbs"
    "{66e4e4fb-f385-4dd0-8d74-a2efd1bc6178}"="Shell Image Data Factory"
    "{3F30C968-480A-4C6C-862D-EFC0897BB84B}"="GDI+ -tiedoston pikkukuvan purkaja"
    "{9DBD2C50-62AD-11d0-B806-00C04FD706EC}"="Yhteenvetotiedot pikkukuvien k„sittelyst„ (DOCFILES)"
    "{EAB841A0-9550-11cf-8C16-00805F1408F3}"="HTML-pikkukuvien purkuohjelma"
    "{eb9b1153-3b57-4e68-959a-a3266bc3d7fe}"="Shell Image Property Handler"
    "{CC6EEFFB-43F6-46c5-9619-51D571967F7D}"="Ohjattu Web-julkaisutoiminto"
    "{add36aa8-751a-4579-a266-d66f5202ccbb}"="Valokuvien paperikopioiden tilaaminen Internetist„"
    "{6b33163c-76a5-4b6c-bf21-45de9cd503a1}"="Shell Publishing Wizard Object"
    "{58f1f272-9240-4f51-b6d4-fd63d1618591}"="Ohjattu Passport toiminto"
    "{7A9D77BD-5403-11d2-8785-2E0420524153}"="K„ytt„j„tilit"
    "{BD472F60-27FA-11cf-B8B4-444553540000}"="Compressed (zipped) Folder Right Drag Handler"
    "{888DCA60-FC0A-11CF-8F0F-00C04FD7D062}"="Compressed (zipped) Folder SendTo Target"
    "{f39a0dc0-9cc8-11d0-a599-00c04fd64433}"="Kanavatiedosto"
    "{f3aa0dc0-9cc8-11d0-a599-00c04fd64434}"="Kanavan pikakuvake"
    "{f3ba0dc0-9cc8-11d0-a599-00c04fd64435}"="Kanavienk„sittelyobjekti"
    "{f3da0dc0-9cc8-11d0-a599-00c04fd64437}"="Channel Menu"
    "{f3ea0dc0-9cc8-11d0-a599-00c04fd64438}"="Channel Properties"
    "{63da6ec0-2e98-11cf-8d82-444553540000}"="FTP Folders Webview"
    "{883373C3-BF89-11D1-BE35-080036B11A03}"="Microsoft DocProp Shell Ext"
    "{A9CF0EAE-901A-4739-A481-E35B73E47F6D}"="Microsoft DocProp Inplace Edit Box Control"
    "{8EE97210-FD1F-4B19-91DA-67914005F020}"="Microsoft DocProp Inplace ML Edit Box Control"
    "{0EEA25CC-4362-4A12-850B-86EE61B0D3EB}"="Microsoft DocProp Inplace Droplist Combo Control"
    "{6A205B57-2567-4A2C-B881-F787FAB579A3}"="Microsoft DocProp Inplace Calendar Control"
    "{28F8A4AC-BBB3-4D9B-B177-82BFC914FA33}"="Microsoft DocProp Inplace Time Control"
    "{8A23E65E-31C2-11d0-891C-00A024AB2DBB}"="Directory Query UI"
    "{9E51E0D0-6E0F-11d2-9601-00C04FA31A86}"="Shell properties for a DS object"
    "{163FDC20-2ABC-11d0-88F0-00A024AB2DBB}"="Directory Object Find"
    "{F020E586-5264-11d1-A532-0000F8757D7E}"="Directory Start/Search Find"
    "{0D45D530-764B-11d0-A1CA-00AA00C16E65}"="Directory Property UI"
    "{62AE1F9A-126A-11D0-A14B-0800361B1103}"="Directory Context Menu Verbs"
    "{ECF03A33-103D-11d2-854D-006008059367}"="MyDocs Copy Hook"
    "{ECF03A32-103D-11d2-854D-006008059367}"="MyDocs Drop Target"
    "{4a7ded0a-ad25-11d0-98a8-0800361b1103}"="MyDocs Properties"
    "{750fdf0e-2a26-11d1-a3ea-080036587f03}"="Offline Files Menu"
    "{10CFC467-4392-11d2-8DB4-00C04FA31A66}"="Offline Files Folder Options"
    "{AFDB1F70-2A4C-11d2-9039-00C04F8EEB3E}"="Offline-tiedostot-kansio"
    "{143A62C8-C33B-11D1-84FE-00C04FA34A14}"="Microsoft Agent Character Property Sheet Handler"
    "{ECCDF543-45CC-11CE-B9BF-0080C87CDBA6}"="DfsShell"
    "{60fd46de-f830-4894-a628-6fa81bc0190d}"="%DESC_PublishDropTarget%"
    "{7A80E4A8-8005-11D2-BCF8-00C04F72C717}"="MMC Icon Handler"
    "{0CD7A5C0-9F37-11CE-AE65-08002B2E1262}"=".CAB file viewer"
    "{32714800-2E5F-11d0-8B85-00AA0044F941}"="&Henkil”it„..."
    "{8DD448E6-C188-4aed-AF92-44956194EB1F}"="Windows Media Player Play as Playlist Context Menu Handler"
    "{CE3FB1D1-02AE-4a5f-A6E9-D9F1B4073E6C}"="Windows Media Player Burn Audio CD Context Menu Handler"
    "{F1B9284F-E9DC-4e68-9D7E-42362A59F0FD}"="Windows Media Player Add to Playlist Context Menu Handler"
    "{B41DB860-8EE4-11D2-9906-E49FADC173CA}"="WinRAR shell extension"
    "{1758B32E-2E87-411E-95F0-659C00514DF3}"=""
    "{C592235A-A58C-48DC-B62C-AB7BCB2BB3F4}"=""
    "{CA9EFBE9-E915-4ADA-B115-1F7E75BEC560}"=""
    "{5966568C-7D19-4098-AE83-C9D46F73BD2C}"=""
    "{BCF73381-7CB5-43D5-9048-1CE2471A68D4}"=""
    "{3A536D8A-FBA6-4A65-9777-E1BD633285CA}"=""
    "{CFA1E0E2-BF37-48CD-9F58-872A1AEB71A8}"=""
    "{7E4B99A9-B84D-482B-B53E-34CD661D7DE4}"=""
    "{ED578B3D-8C32-412E-9B6B-125D5997419A}"=""
    "{EABD618D-E32B-4E42-B7CD-C0D5CEF8D4C6}"=""
    "{5A431CDF-C97C-436C-ABD3-2C157A20323C}"=""
    "{553563DE-F8D3-4330-9117-82FF449A4CC0}"=""
    "{640167b4-59b0-47a6-b335-a6b3c0695aea}"="Portable Media Devices"
    "{cc86590a-b60a-48e6-996b-41d25ed39a1e}"="Portable Media Devices Menu"
    "{8910A239-345F-4917-B5A5-480F69267EDA}"=""
    "{502EFDB7-E7AB-44FC-8F9C-B519B8E0D8D0}"=""
    "{416DEC8D-D387-4D43-ACBB-A1F41079FEA4}"=""
    "{922B5BF5-7756-4228-B71A-039B8B8A22AE}"=""
    "{7B7438AB-C7C8-4622-A4D4-033EFB8DAEB1}"=""
    "{AF730DDA-AC7C-4054-BDDC-1060337C1218}"=""
    "{452229D1-C11F-4F7C-B6B8-9F456A96CA8C}"=""
    "{4B0A3EFE-CD45-4B85-AAAF-BF6A03AE6128}"=""
    "{A1B72B3F-50F0-467B-A1FA-35F79A3DC2DC}"=""
    "{802BF23C-470B-41DE-A6B0-381587EA7037}"=""
    "{9592BB1B-E337-404E-9CF3-2735CD85AE67}"=""
    "{A18C479B-53B1-4C66-8DFE-9E88A6E04417}"=""
    "{2E03477B-F05D-47F2-A00A-15F867AACE60}"=""
    "{BE3DF3FB-8B4D-4218-856D-B14691C624C8}"=""
    "{C68F1017-3F12-406A-B1E6-607641395690}"=""
    "{2B119913-7FA4-4B36-BE31-4A2B222D00EE}"=""
    "{DD14D17A-B367-4B13-AFCE-FF0B86EA0115}"=""
    "{086B79D8-C1FE-4A88-B025-1D12670386D4}"=""
    "{BF570010-C329-44C4-9076-70DC09D1F657}"=""
    "{FEF43FF9-8C73-45F6-8FD1-1B7CF1E91AE6}"=""
    "{7D00103A-4B7C-4A92-A168-E115A4B5BB62}"=""
    "{3B886085-E276-40BC-88BC-C4C2E65CFB2F}"=""
    "{A905FB3E-425A-4C86-9424-BCC2F7E26CB3}"=""
    "{E111B4A6-42C0-4BC6-BC9C-7171A7978740}"=""
    "{86C43321-E4A9-45A4-8E68-16C30932260F}"=""
    "{06005505-0EC7-483C-827F-F94B2BA27010}"=""
    "{61DC2AF4-EB96-4DB7-A6B2-5C736795491E}"=""
    "{2549F884-AA3F-465B-B0F1-2DC3FBBA5FDC}"=""
    "{989EAC39-8B82-4278-9CA6-63874E559300}"=""
    "{768ED112-0A46-41F4-BEEB-E22D89FFFCA7}"=""
    "{2239C763-740F-4B97-806C-529646F59991}"=""
    "{F34A41CF-EAB4-47EF-A42C-A836E83FF61D}"=""
    "{4DF09495-0324-42E2-AACC-7E1A0D0ABB4A}"=""
    "{2A66DD17-C378-456E-8D5E-41BB93D2FCDC}"=""
    "{77239875-4AA2-4412-9308-E2D751BA476C}"=""
    "{E1D27203-690B-4C7D-A388-D1A9F5D84808}"=""
    "{C4CA3BE6-76A1-4C15-9A5A-0D8519C8AC4E}"=""
    "{4744A88A-27F0-40FA-AE76-75D9650884E2}"=""
    "{5C3A5019-70E9-4876-BF44-F6AFB0951A89}"=""
    "{DB29EC55-273E-494C-BA9E-638B93144B61}"=""
    "{C6F6E1E1-B213-44DB-AB5D-4D79DFB209DD}"=""
    "{E88EAE69-22F3-4119-9AA5-6DB6D9C620A2}"=""
    "{35A3BDF2-A729-40AB-98A8-3A0A21C2D401}"=""
    "{26EF4751-8CAD-4110-8EDC-6C808BF33696}"=""
    "{A3E8A66B-5D52-47AD-ADCC-451F85DB28A0}"=""
    "{81E180E6-D6E9-457B-B148-6B2696E40478}"=""
    "{6547E428-2EC0-4A08-AA07-299EF6FDA51F}"=""
    "{97D68211-1408-461A-80AC-A15CF76AFD99}"=""
    "{8AEEED30-5FF4-4874-9C71-0C42E50B42E6}"=""
    "{B30D2E85-CD34-4BE6-AD46-8BE283060FF7}"=""
    "{3547F6B3-CEF1-467A-AEAE-30478F77C942}"=""
    "{F9819CEA-11EB-4AE0-AA39-01E59BFCDF46}"=""
    "{02A454BC-4AC9-4D05-97B8-2DEB97F038A7}"=""
    "{66BF9F29-5C6A-43EC-A4DB-4FBB578F63D7}"=""
    "{317EE681-0BE2-45E3-9177-405F7BFAC143}"=""
    "{A01A9184-A87D-44F4-8DE2-CBBD967D9324}"=""
    "{5D25C076-EF64-459A-AFE9-458A789792AD}"=""
    "{12DF87D4-8CA8-4C20-80A2-0C7E1B21BA13}"=""
    "{4F000194-AA18-44A3-BE03-E678E123E5B1}"=""
    "{4EC01F12-1D77-41A1-9947-E0A9F71B20AA}"=""
    "{FA5C95FB-1E5B-4B05-B451-1B1083C6A9B1}"=""
    "{DCD99A13-1B9A-4912-9A8D-85A04CA33CC6}"=""
    "{5A025223-DC53-4A8D-85A0-ADFB8B2FAE9A}"=""
    "{447423E8-D11B-4446-9120-7276216A40CE}"=""
    "{5EC92A5A-0848-4963-BC3C-7AA14C23327B}"=""
    "{238CB486-647C-4B88-9FFB-4142585F8A81}"=""
    "{2F87EC4D-0115-4D77-BA2E-0C557B88D36F}"=""
    "{CD74549F-60D3-44DE-AE57-22BFB5237EEA}"=""
    "{16B9AF1D-E035-49F3-A0C0-A6D9BA00CDD8}"=""
    "{6D0E8A2D-BAB7-4417-924F-6388797DF420}"=""
    "{88B640AA-BBB5-47EF-8077-620A973AAD0B}"=""
    "{CE84CD16-3D8A-424C-A652-C7382A1C0BB2}"=""
    "{E8468BA0-63A8-4BBF-8D77-DCD5DC033FCB}"=""
    "{D9A5F243-70DB-4E79-9224-E7C15B2B821D}"=""
    "{84FCB1BC-6756-4DD2-9A67-69F3118CAD81}"=""
    "{2B320E0D-0F07-402F-9C5F-23F05F0755CE}"=""
    "{AE55B1B6-A5FA-4AAC-B52C-D4A5EB6F30D3}"=""
    "{6161CA30-D354-46E7-93D3-CECBAB4C35C6}"=""
    "{D3B14758-EDDB-4D94-8F19-C2D053910D0D}"=""

    **********************************************************************************
    HKEY ROOT CLASSIDS:
    Windows Registry Editor Version 5.00

    [HKEY_CLASSES_ROOT\CLSID\{1758B32E-2E87-411E-95F0-659C00514DF3}]
    @=""
    "IDEx"="ADDR"

    [HKEY_CLASSES_ROOT\CLSID\{1758B32E-2E87-411E-95F0-659C00514DF3}\Implemented Categories]
    @=""

    [HKEY_CLASSES_ROOT\CLSID\{1758B32E-2E87-411E-95F0-659C00514DF3}\Implemented Categories\{00021492-0000-0000-C000-000000000046}]
    @=""

    [HKEY_CLASSES_ROOT\CLSID\{1758B32E-2E87-411E-95F0-659C00514DF3}\InprocServer32]
    @="C:\\WINDOWS\\system32\\AQIDDC.DLL"
    "ThreadingModel"="Apartment"

    Windows Registry Editor Version 5.00

    [HKEY_CLASSES_ROOT\CLSID\{C592235A-A58C-48DC-B62C-AB7BCB2BB3F4}]
    @=""

    [HKEY_CLASSES_ROOT\CLSID\{C592235A-A58C-48DC-B62C-AB7BCB2BB3F4}\Implemented Categories]
    @=""

    [HKEY_CLASSES_ROOT\CLSID\{C592235A-A58C-48DC-B62C-AB7BCB2BB3F4}\Implemented Categories\{00021492-0000-0000-C000-000000000046}]
    @=""

    [HKEY_CLASSES_ROOT\CLSID\{C592235A-A58C-48DC-B62C-AB7BCB2BB3F4}\InprocServer32]
    @="C:\\WINDOWS\\system32\\ayrsvc.dll"
    "ThreadingModel"="Apartment"

    Windows Registry Editor Version 5.00

    [HKEY_CLASSES_ROOT\CLSID\{CA9EFBE9-E915-4ADA-B115-1F7E75BEC560}]
    @=""

    [HKEY_CLASSES_ROOT\CLSID\{CA9EFBE9-E915-4ADA-B115-1F7E75BEC560}\Implemented Categories]
    @=""

    [HKEY_CLASSES_ROOT\CLSID\{CA9EFBE9-E915-4ADA-B115-1F7E75BEC560}\Implemented Categories\{00021492-0000-0000-C000-000000000046}]
    @=""

    [HKEY_CLASSES_ROOT\CLSID\{CA9EFBE9-E915-4ADA-B115-1F7E75BEC560}\InprocServer32]
    @="C:\\WINDOWS\\system32\\rgpcfgex.dll"
    "ThreadingModel"="Apartment"

    Windows Registry Editor Version 5.00

    [HKEY_CLASSES_ROOT\CLSID\{5966568C-7D19-4098-AE83-C9D46F73BD2C}]
    @=""

    [HKEY_CLASSES_ROOT\CLSID\{5966568C-7D19-4098-AE83-C9D46F73BD2C}\Implemented Categories]
    @=""

    [HKEY_CLASSES_ROOT\CLSID\{5966568C-7D19-4098-AE83-C9D46F73BD2C}\Implemented Categories\{00021492-0000-0000-C000-000000000046}]
    @=""

    [HKEY_CLASSES_ROOT\CLSID\{5966568C-7D19-4098-AE83-C9D46F73BD2C}\InprocServer32]
    @="C:\\WINDOWS\\system32\\fgdrclnr.dll"
    "ThreadingModel"="Apartment"

    Windows Registry Editor Version 5.00

    [HKEY_CLASSES_ROOT\CLSID\{BCF73381-7CB5-43D5-9048-1CE2471A68D4}]
    @=""

    [HKEY_CLASSES_ROOT\CLSID\{BCF73381-7CB5-43D5-9048-1CE2471A68D4}\Implemented Categories]
    @=""

    [HKEY_CLASSES_ROOT\CLSID\{BCF73381-7CB5-43D5-9048-1CE2471A68D4}\Implemented Categories\{00021492-0000-0000-C000-000000000046}]
    @=""

    [HKEY_CLASSES_ROOT\CLSID\{BCF73381-7CB5-43D5-9048-1CE2471A68D4}\InprocServer32]
    @="C:\\WINDOWS\\system32\\kldgae.dll"
    "ThreadingModel"="Apartment"

    Windows Registry Editor Version 5.00

    [HKEY_CLASSES_ROOT\CLSID\{3A536D8A-FBA6-4A65-9777-E1BD633285CA}]
    @=""

    [HKEY_CLASSES_ROOT\CLSID\{3A536D8A-FBA6-4A65-9777-E1BD633285CA}\Implemented Categories]
    @=""

    [HKEY_CLASSES_ROOT\CLSID\{3A536D8A-FBA6-4A65-9777-E1BD633285CA}\Implemented Categories\{00021492-0000-0000-C000-000000000046}]
    @=""

    [HKEY_CLASSES_ROOT\CLSID\{3A536D8A-FBA6-4A65-9777-E1BD633285CA}\InprocServer32]
    @="C:\\WINDOWS\\system32\\wln32spl.dll"
    "ThreadingModel"="Apartment"

    Windows Registry Editor Version 5.00

    [HKEY_CLASSES_ROOT\CLSID\{CFA1E0E2-BF37-48CD-9F58-872A1AEB71A8}]
    @=""

    [HKEY_CLASSES_ROOT\CLSID\{CFA1E0E2-BF37-48CD-9F58-872A1AEB71A8}\Implemented Categories]
    @=""

    [HKEY_CLASSES_ROOT\CLSID\{CFA1E0E2-BF37-48CD-9F58-872A1AEB71A8}\Implemented Categories\{00021492-0000-0000-C000-000000000046}]
    @=""

    [HKEY_CLASSES_ROOT\CLSID\{CFA1E0E2-BF37-48CD-9F58-872A1AEB71A8}\InprocServer32]
    @="C:\\WINDOWS\\system32\\rppcfgex.dll"
    "ThreadingModel"="Apartment"

    Windows Registry Editor Version 5.00

    [HKEY_CLASSES_ROOT\CLSID\{7E4B99A9-B84D-482B-B53E-34CD661D7DE4}]
    @=""

    [HKEY_CLASSES_ROOT\CLSID\{7E4B99A9-B84D-482B-B53E-34CD661D7DE4}\Implemented Categories]
    @=""

    [HKEY_CLASSES_ROOT\CLSID\{7E4B99A9-B84D-482B-B53E-34CD661D7DE4}\Implemented Categories\{00021492-0000-0000-C000-000000000046}]
    @=""

    [HKEY_CLASSES_ROOT\CLSID\{7E4B99A9-B84D-482B-B53E-34CD661D7DE4}\InprocServer32]
    @="C:\\WINDOWS\\system32\\natapi32.dll"
    "ThreadingModel"="Apartment"

    Windows Registry Editor Version 5.00

    [HKEY_CLASSES_ROOT\CLSID\{ED578B3D-8C32-412E-9B6B-125D5997419A}]
    @=""

    [HKEY_CLASSES_ROOT\CLSID\{ED578B3D-8C32-412E-9B6B-125D5997419A}\Implemented Categories]
    @=""

    [HKEY_CLASSES_ROOT\CLSID\{ED578B3D-8C32-412E-9B6B-125D5997419A}\Implemented Categories\{00021492-0000-0000-C000-000000000046}]
    @=""

    [HKEY_CLASSES_ROOT\CLSID\{ED578B3D-8C32-412E-9B6B-125D5997419A}\InprocServer32]
    @="C:\\WINDOWS\\system32\\itaapi.dll"
    "ThreadingModel"="Apartment"

    Windows Registry Editor Version 5.00

    [HKEY_CLASSES_ROOT\CLSID\{EABD618D-E32B-4E42-B7CD-C0D5CEF8D4C6}]
    @=""

    [HKEY_CLASSES_ROOT\CLSID\{EABD618D-E32B-4E42-B7CD-C0D5CEF8D4C6}\Implemented Categories]
    @=""

    [HKEY_CLASSES_ROOT\CLSID\{EABD618D-E32B-4E42-B7CD-C0D5CEF8D4C6}\Implemented Categories\{00021492-0000-0000-C000-000000000046}]
    @=""

    [HKEY_CLASSES_ROOT\CLSID\{EABD618D-E32B-4E42-B7CD-C0D5CEF8D4C6}\InprocServer32]
    @="C:\\WINDOWS\\system32\\wbsdmoe.dll"
    "ThreadingModel"="Apartment"

    Windows Registry Editor Version 5.00

    [HKEY_CLASSES_ROOT\CLSID\{5A431CDF-C97C-436C-ABD3-2C157A20323C}]
    @=""

    [HKEY_CLASSES_ROOT\CLSID\{5A431CDF-C97C-436C-ABD3-2C157A20323C}\Implemented Categories]
    @=""

    [HKEY_CLASSES_ROOT\CLSID\{5A431CDF-C97C-436C-ABD3-2C157A20323C}\Implemented Categories\{00021492-0000-0000-C000-000000000046}]
    @=""

    [HKEY_CLASSES_ROOT\CLSID\{5A431CDF-C97C-436C-ABD3-2C157A20323C}\InprocServer32]
    @="C:\\WINDOWS\\system32\\dqskadp.dll"
    "ThreadingModel"="Apartment"

    Windows Registry Editor Version 5.00

    [HKEY_CLASSES_ROOT\CLSID\{553563DE-F8D3-4330-9117-82FF449A4CC0}]
    @=""

    [HKEY_CLASSES_ROOT\CLSID\{553563DE-F8D3-4330-9117-82FF449A4CC0}\Implemented Categories]
    @=""

    [HKEY_CLASSES_ROOT\CLSID\{553563DE-F8D3-4330-9117-82FF449A4CC0}\Implemented Categories\{00021492-0000-0000-C000-000000000046}]
    @=""

    [HKEY_CLASSES_ROOT\CLSID\{553563DE-F8D3-4330-9117-82FF449A4CC0}\InprocServer32]
    @="C:\\WINDOWS\\system32\\wicsvc.dll"
    "ThreadingModel"="Apartment"

    Windows Registry Editor Version 5.00

    [HKEY_CLASSES_ROOT\CLSID\{8910A239-345F-4917-B5A5-480F69267EDA}]
    @=""

    [HKEY_CLASSES_ROOT\CLSID\{8910A239-345F-4917-B5A5-480F69267EDA}\Implemented Categories]
    @=""

    [HKEY_CLASSES_ROOT\CLSID\{8910A239-345F-4917-B5A5-480F69267EDA}\Implemented Categories\{00021492-0000-0000-C000-000000000046}]
    @=""

    [HKEY_CLASSES_ROOT\CLSID\{8910A239-345F-4917-B5A5-480F69267EDA}\InprocServer32]
    @="C:\\WINDOWS\\system32\\wen32spl.dll"
    "ThreadingModel"="Apartment"

    Windows Registry Editor Version 5.00

    [HKEY_CLASSES_ROOT\CLSID\{502EFDB7-E7AB-44FC-8F9C-B519B8E0D8D0}]
    @=""

    [HKEY_CLASSES_ROOT\CLSID\{502EFDB7-E7AB-44FC-8F9C-B519B8E0D8D0}\Implemented Categories]
    @=""

    [HKEY_CLASSES_ROOT\CLSID\{502EFDB7-E7AB-44FC-8F9C-B519B8E0D8D0}\Implemented Categories\{00021492-0000-0000-C000-000000000046}]
    @=""

    [HKEY_CLASSES_ROOT\CLSID\{502EFDB7-E7AB-44FC-8F9C-B519B8E0D8D0}\InprocServer32]
    @="C:\\WINDOWS\\system32\\fhclient.dll"
    "ThreadingModel"="Apartment"

    Windows Registry Editor Version 5.00

    [HKEY_CLASSES_ROOT\CLSID\{416DEC8D-D387-4D43-ACBB-A1F41079FEA4}]
    @=""

    [HKEY_CLASSES_ROOT\CLSID\{416DEC8D-D387-4D43-ACBB-A1F41079FEA4}\Implemented Categories]
    @=""

    [HKEY_CLASSES_ROOT\CLSID\{416DEC8D-D387-4D43-ACBB-A1F41079FEA4}\Implemented Categories\{00021492-0000-0000-C000-000000000046}]
    @=""

    [HKEY_CLASSES_ROOT\CLSID\{416DEC8D-D387-4D43-ACBB-A1F41079FEA4}\InprocServer32]
    @="C:\\WINDOWS\\system32\\irxmontr.dll"
    "ThreadingModel"="Apartment"

    Windows Registry Editor Version 5.00

    [HKEY_CLASSES_ROOT\CLSID\{922B5BF5-7756-4228-B71A-039B8B8A22AE}]
    @=""

    [HKEY_CLASSES_ROOT\CLSID\{922B5BF5-7756-4228-B71A-039B8B8A22AE}\Implemented Categories]
    @=""

    [HKEY_CLASSES_ROOT\CLSID\{922B5BF5-7756-4228-B71A-039B8B8A22AE}\Implemented Categories\{00021492-0000-0000-C000-000000000046}]
    @=""

    [HKEY_CLASSES_ROOT\CLSID\{922B5BF5-7756-4228-B71A-039B8B8A22AE}\InprocServer32]
    @="C:\\WINDOWS\\system32\\cycdll.dll"
    "ThreadingModel"="Apartment"

    Windows Registry Editor Version 5.00

    [HKEY_CLASSES_ROOT\CLSID\{7B7438AB-C7C8-4622-A4D4-033EFB8DAEB1}]
    @=""

    [HKEY_CLASSES_ROOT\CLSID\{7B7438AB-C7C8-4622-A4D4-033EFB8DAEB1}\Implemented Categories]
    @=""

    [HKEY_CLASSES_ROOT\CLSID\{7B7438AB-C7C8-4622-A4D4-033EFB8DAEB1}\Implemented Categories\{00021492-0000-0000-C000-000000000046}]
    @=""

    [HKEY_CLASSES_ROOT\CLSID\{7B7438AB-C7C8-4622-A4D4-033EFB8DAEB1}\InprocServer32]
    @="C:\\WINDOWS\\system32\\dkmstor.dll"
    "ThreadingModel"="Apartment"

    Windows Registry Editor Version 5.00

    [HKEY_CLASSES_ROOT\CLSID\{AF730DDA-AC7C-4054-BDDC-1060337C1218}]
    @=""

    [HKEY_CLASSES_ROOT\CLSID\{AF730DDA-AC7C-4054-BDDC-1060337C1218}\Implemented Categories]
    @=""

    [HKEY_CLASSES_ROOT\CLSID\{AF730DDA-AC7C-4054-BDDC-1060337C1218}\Implemented Categories\{00021492-0000-0000-C000-000000000046}]
    @=""

    [HKEY_CLASSES_ROOT\CLSID\{AF730DDA-AC7C-4054-BDDC-1060337C1218}\InprocServer32]
    @="C:\\WINDOWS\\system32\\aqicap.dll"
    "ThreadingModel"="Apartment"

    Windows Registry Editor Version 5.00

    [HKEY_CLASSES_ROOT\CLSID\{452229D1-C11F-4F7C-B6B8-9F456A96CA8C}]
    @=""

    [HKEY_CLASSES_ROOT\CLSID\{452229D1-C11F-4F7C-B6B8-9F456A96CA8C}\Implemented Categories]
    @=""

    [HKEY_CLASSES_ROOT\CLSID\{452229D1-C11F-4F7C-B6B8-9F456A96CA8C}\Implemented Categories\{00021492-0000-0000-C000-000000000046}]
    @=""

    [HKEY_CLASSES_ROOT\CLSID\{452229D1-C11F-4F7C-B6B8-9F456A96CA8C}\InprocServer32]
    @="C:\\WINDOWS\\system32\\woerrFIN.dll"
    "ThreadingModel"="Apartment"

    Windows Registry Editor Version 5.00

    [HKEY_CLASSES_ROOT\CLSID\{4B0A3EFE-CD45-4B85-AAAF-BF6A03AE6128}]
    @=""

    [HKEY_CLASSES_ROOT\CLSID\{4B0A3EFE-CD45-4B85-AAAF-BF6A03AE6128}\Implemented Categories]
    @=""

    [HKEY_CLASSES_ROOT\CLSID\{4B0A3EFE-CD45-4B85-AAAF-BF6A03AE6128}\Implemented Categories\{00021492-0000-0000-C000-000000000046}]
    @=""

    [HKEY_CLASSES_ROOT\CLSID\{4B0A3EFE-CD45-4B85-AAAF-BF6A03AE6128}\InprocServer32]
    @="C:\\WINDOWS\\system32\\ilfosoft.dll"
    "ThreadingModel"="Apartment"

    Windows Registry Editor Version 5.00

    [HKEY_CLASSES_ROOT\CLSID\{A1B72B3F-50F0-467B-A1FA-35F79A3DC2DC}]
    @=""

    [HKEY_CLASSES_ROOT\CLSID\{A1B72B3F-50F0-467B-A1FA-35F79A3DC2DC}\Implemented Categories]
    @=""

    [HKEY_CLASSES_ROOT\CLSID\{A1B72B3F-50F0-467B-A1FA-35F79A3DC2DC}\Implemented Categories\{00021492-0000-0000-C000-000000000046}]
    @=""

    [HKEY_CLASSES_ROOT\CLSID\{A1B72B3F-50F0-467B-A1FA-35F79A3DC2DC}\InprocServer32]
    @="C:\\WINDOWS\\system32\\mzwsock.dll"
    "ThreadingModel"="Apartment"

    Windows Registry Editor Version 5.00

    [HKEY_CLASSES_ROOT\CLSID\{802BF23C-470B-41DE-A6B0-381587EA7037}]
    @=""

    [HKEY_CLASSES_ROOT\CLSID\{802BF23C-470B-41DE-A6B0-381587EA7037}\Implemented Categories]
    @=""

    [HKEY_CLASSES_ROOT\CLSID\{802BF23C-470B-41DE-A6B0-381587EA7037}\Implemented Categories\{00021492-0000-0000-C000-000000000046}]
    @=""

    [HKEY_CLASSES_ROOT\CLSID\{802BF23C-470B-41DE-A6B0-381587EA7037}\InprocServer32]
    @="C:\\WINDOWS\\system32\\snrio600.dll"
    "ThreadingModel"="Apartment"

    Windows Registry Editor Version 5.00

    [HKEY_CLASSES_ROOT\CLSID\{9592BB1B-E337-404E-9CF3-2735CD85AE67}]
    @=""

    [HKEY_CLASSES_ROOT\CLSID\{9592BB1B-E337-404E-9CF3-2735CD85AE67}\Implemented Categories]
    @=""

    [HKEY_CLASSES_ROOT\CLSID\{9592BB1B-E337-404E-9CF3-2735CD85AE67}\Implemented Categories\{00021492-0000-0000-C000-000000000046}]
    @=""

    [HKEY_CLASSES_ROOT\CLSID\{9592BB1B-E337-404E-9CF3-2735CD85AE67}\InprocServer32]
    @="C:\\WINDOWS\\system32\\wontrust.dll"
    "ThreadingModel"="Apartment"

    Windows Registry Editor Version 5.00

    [HKEY_CLASSES_ROOT\CLSID\{A18C479B-53B1-4C66-8DFE-9E88A6E04417}]
    @=""

    [HKEY_CLASSES_ROOT\CLSID\{A18C479B-53B1-4C66-8DFE-9E88A6E04417}\Implemented Categories]
    @=""

    [HKEY_CLASSES_ROOT\CLSID\{A18C479B-53B1-4C66-8DFE-9E88A6E04417}\Implemented Categories\{00021492-0000-0000-C000-000000000046}]
    @=""

    [HKEY_CLASSES_ROOT\CLSID\{A18C479B-53B1-4C66-8DFE-9E88A6E04417}\InprocServer32]
    @="C:\\WINDOWS\\system32\\bqackbox.dll"
    "ThreadingModel"="Apartment"

    Windows Registry Editor Version 5.00

    [HKEY_CLASSES_ROOT\CLSID\{2E03477B-F05D-47F2-A00A-15F867AACE60}]
    @=""

    [HKEY_CLASSES_ROOT\CLSID\{2E03477B-F05D-47F2-A00A-15F867AACE60}\Implemented Categories]
    @=""

    [HKEY_CLASSES_ROOT\CLSID\{2E03477B-F05D-47F2-A00A-15F867AACE60}\Implemented Categories\{00021492-0000-0000-C000-000000000046}]
    @=""

    [HKEY_CLASSES_ROOT\CLSID\{2E03477B-F05D-47F2-A00A-15F867AACE60}\InprocServer32]
    @="C:\\WINDOWS\\system32\\AIIDEMGR.dll"
    "ThreadingModel"="Apartment"

    Windows Registry Editor Version 5.00

    [HKEY_CLASSES_ROOT\CLSID\{BE3DF3FB-8B4D-4218-856D-B14691C624C8}]
    @=""

    [HKEY_CLASSES_ROOT\CLSID\{BE3DF3FB-8B4D-4218-856D-B14691C624C8}\Implemented Categories]
    @=""

    [HKEY_CLASSES_ROOT\CLSID\{BE3DF3FB-8B4D-4218-856D-B14691C624C8}\Implemented Categories\{00021492-0000-0000-C000-000000000046}]
    @=""

    [HKEY_CLASSES_ROOT\CLSID\{BE3DF3FB-8B4D-4218-856D-B14691C624C8}\InprocServer32]
    @="C:\\WINDOWS\\system32\\kvrberos.dll"
    "ThreadingModel"="Apartment"

    Windows Registry Editor Version 5.00

    [HKEY_CLASSES_ROOT\CLSID\{C68F1017-3F12-406A-B1E6-607641395690}]
    @=""

    [HKEY_CLASSES_ROOT\CLSID\{C68F1017-3F12-406A-B1E6-607641395690}\Implemented Categories]
    @=""

    [HKEY_CLASSES_ROOT\CLSID\{C68F1017-3F12-406A-B1E6-607641395690}\Implemented Categories\{00021492-0000-0000-C000-000000000046}]
    @=""

    [HKEY_CLASSES_ROOT\CLSID\{C68F1017-3F12-406A-B1E6-607641395690}\InprocServer32]
    @="C:\\WINDOWS\\system32\\lmcmgr10.dll"
    "ThreadingModel"="Apartment"

    Windows Registry Editor Version 5.00

    [HKEY_CLASSES_ROOT\CLSID\{2B119913-7FA4-4B36-BE31-4A2B222D00EE}]
    @=""

    [HKEY_CLASSES_ROOT\CLSID\{2B119913-7FA4-4B36-BE31-4A2B222D00EE}\Implemented Categories]
    @=""

    [HKEY_CLASSES_ROOT\CLSID\{2B119913-7FA4-4B36-BE31-4A2B222D00EE}\Implemented Categories\{00021492-0000-0000-C000-000000000046}]
    @=""

    [HKEY_CLASSES_ROOT\CLSID\{2B119913-7FA4-4B36-BE31-4A2B222D00EE}\InprocServer32]
    @="C:\\WINDOWS\\system32\\noprint.dll"
    "ThreadingModel"="Apartment"

    Windows Registry Editor Version 5.00

    [HKEY_CLASSES_ROOT\CLSID\{DD14D17A-B367-4B13-AFCE-FF0B86EA0115}]
    @=""

    [HKEY_CLASSES_ROOT\CLSID\{DD14D17A-B367-4B13-AFCE-FF0B86EA0115}\Implemented Categories]
    @=""

    [HKEY_CLASSES_ROOT\CLSID\{DD14D17A-B367-4B13-AFCE-FF0B86EA0115}\Implemented Categories\{00021492-0000-0000-C000-000000000046}]
    @=""

    [HKEY_CLASSES_ROOT\CLSID\{DD14D17A-B367-4B13-AFCE-FF0B86EA0115}\InprocServer32]
    @="C:\\WINDOWS\\system32\\ibfgnt5.dll"
    "ThreadingModel"="Apartment"

    Windows Registry Editor Version 5.00

    [HKEY_CLASSES_ROOT\CLSID\{086B79D8-C1FE-4A88-B025-1D12670386D4}]
    @=""

    [HKEY_CLASSES_ROOT\CLSID\{086B79D8-C1FE-4A88-B025-1D12670386D4}\Implemented Categories]
    @=""

    [HKEY_CLASSES_ROOT\CLSID\{086B79D8-C1FE-4A88-B025-1D12670386D4}\Implemented Categories\{00021492-0000-0000-C000-000000000046}]
    @=""

    [HKEY_CLASSES_ROOT\CLSID\{086B79D8-C1FE-4A88-B025-1D12670386D4}\InprocServer32]
    @="C:\\WINDOWS\\system32\\nqmkcert.dll"
    "ThreadingModel"="Apartment"

    Windows Registry Editor Version 5.00

    [HKEY_CLASSES_ROOT\CLSID\{BF570010-C329-44C4-9076-70DC09D1F657}]
    @=""

    [HKEY_CLASSES_ROOT\CLSID\{BF570010-C329-44C4-9076-70DC09D1F657}\Implemented Categories]
    @=""

    [HKEY_CLASSES_ROOT\CLSID\{BF570010-C329-44C4-9076-70DC09D1F657}\Implemented Categories\{00021492-0000-0000-C000-000000000046}]
    @=""

    [HKEY_CLASSES_ROOT\CLSID\{BF570010-C329-44C4-9076-70DC09D1F657}\InprocServer32]
    @="C:\\WINDOWS\\system32\\ravpmsg.dll"
    "ThreadingModel"="Apartment"

    Windows Registry Editor Version 5.00

    [HKEY_CLASSES_ROOT\CLSID\{FEF43FF9-8C73-45F6-8FD1-1B7CF1E91AE6}]
    @=""

    [HKEY_CLASSES_ROOT\CLSID\{FEF43FF9-8C73-45F6-8FD1-1B7CF1E91AE6}\Implemented Categories]
    @=""

    [HKEY_CLASSES_ROOT\CLSID\{FEF43FF9-8C73-45F6-8FD1-1B7CF1E91AE6}\Implemented Categories\{00021492-0000-0000-C000-000000000046}]
    @=""

    [HKEY_CLASSES_ROOT\CLSID\{FEF43FF9-8C73-45F6-8FD1-1B7CF1E91AE6}\InprocServer32]
    @="C:\\WINDOWS\\system32\\bYsesrv.dll"
    "ThreadingModel"="Apartment"

    Windows Registry Editor Version 5.00

    [HKEY_CLASSES_ROOT\CLSID\{7D00103A-4B7C-4A92-A168-E115A4B5BB62}]
    @=""

    [HKEY_CLASSES_ROOT\CLSID\{7D00103A-4B7C-4A92-A168-E115A4B5BB62}\Implemented Categories]
    @=""

    [HKEY_CLASSES_ROOT\CLSID\{7D00103A-4B7C-4A92-A168-E115A4B5BB62}\Implemented Categories\{00021492-0000-0000-C000-000000000046}]
    @=""

    [HKEY_CLASSES_ROOT\CLSID\{7D00103A-4B7C-4A92-A168-E115A4B5BB62}\InprocServer32]
    @="C:\\WINDOWS\\system32\\rJstls.dll"
    "ThreadingModel"="Apartment"

    Windows Registry Editor Version 5.00

    [HKEY_CLASSES_ROOT\CLSID\{3B886085-E276-40BC-88BC-C4C2E65CFB2F}]
    @=""

    [HKEY_CLASSES_ROOT\CLSID\{3B886085-E276-40BC-88BC-C4C2E65CFB2F}\Implemented Categories]
    @=""

    [HKEY_CLASSES_ROOT\CLSID\{3B886085-E276-40BC-88BC-C4C2E65CFB2F}\Implemented Categories\{00021492-0000-0000-C000-000000000046}]
    @=""

    [HKEY_CLASSES_ROOT\CLSID\{3B886085-E276-40BC-88BC-C4C2E65CFB2F}\InprocServer32]
    @="C:\\WINDOWS\\system32\\nmmsdba.dll"
    "ThreadingModel"="Apartment"

    Windows Registry Editor Version 5.00

    [HKEY_CLASSES_ROOT\CLSID\{A905FB3E-425A-4C86-9424-BCC2F7E26CB3}]
    @=""

    [HKEY_CLASSES_ROOT\CLSID\{A905FB3E-425A-4C86-9424-BCC2F7E26CB3}\Implemented Categories]
    @=""

    [HKEY_CLASSES_ROOT\CLSID\{A905FB3E-425A-4C86-9424-BCC2F7E26CB3}\Implemented Categories\{00021492-0000-0000-C000-000000000046}]
    @=""

    [HKEY_CLASSES_ROOT\CLSID\{A905FB3E-425A-4C86-9424-BCC2F7E26CB3}\InprocServer32]
    @="C:\\WINDOWS\\system32\\djusic.dll"
    "ThreadingModel"="Apartment"

    Windows Registry Editor Version 5.00

    [HKEY_CLASSES_ROOT\CLSID\{E111B4A6-42C0-4BC6-BC9C-7171A7978740}]
    @=""

    [HKEY_CLASSES_ROOT\CLSID\{E111B4A6-42C0-4BC6-BC9C-7171A7978740}\Implemented Categories]
    @=""

    [HKEY_CLASSES_ROOT\CLSID\{E111B4A6-42C0-4BC6-BC9C-7171A7978740}\Implemented Categories\{00021492-0000-0000-C000-000000000046}]
    @=""

    [HKEY_CLASSES_ROOT\CLSID\{E111B4A6-42C0-4BC6-BC9C-7171A7978740}\InprocServer32]
    @="C:\\WINDOWS\\system32\\mojint40.dll"
    "ThreadingModel"="Apartment"

    Windows Registry Editor Version 5.00

    [HKEY_CLASSES_ROOT\CLSID\{86C43321-E4A9-45A4-8E68-16C30932260F}]
    @=""

    [HKEY_CLASSES_ROOT\CLSID\{86C43321-E4A9-45A4-8E68-16C30932260F}\Implemented Categories]
    @=""

    [HKEY_CLASSES_ROOT\CLSID\{86C43321-E4A9-45A4-8E68-16C30932260F}\Implemented Categories\{00021492-0000-0000-C000-000000000046}]
    @=""

    [HKEY_CLASSES_ROOT\CLSID\{86C43321-E4A9-45A4-8E68-16C30932260F}\InprocServer32]
    @="C:\\WINDOWS\\system32\\myastmib.dll"
    "ThreadingModel"="Apartment"

    Windows Registry Editor Version 5.00

    [HKEY_CLASSES_ROOT\CLSID\{06005505-0EC7-483C-827F-F94B2BA27010}]
    @=""

    [HKEY_CLASSES_ROOT\CLSID\{06005505-0EC7-483C-827F-F94B2BA27010}\Implemented Categories]
    @=""

    [HKEY_CLASSES_ROOT\CLSID\{06005505-0EC7-483C-827F-F94B2BA27010}\Implemented Categories\{00021492-0000-0000-C000-000000000046}]
    @=""

    [HKEY_CLASSES_ROOT\CLSID\{06005505-0EC7-483C-827F-F94B2BA27010}\InprocServer32]
    @="C:\\WINDOWS\\system32\\wtvcore2.dll"
    "ThreadingModel"="Apartment"

    Windows Registry Editor Version 5.00

    [HKEY_CLASSES_ROOT\CLSID\{61DC2AF4-EB96-4DB7-A6B2-5C736795491E}]
    @=""

    [HKEY_CLASSES_ROOT\CLSID\{61DC2AF4-EB96-4DB7-A6B2-5C736795491E}\Implemented Categories]
    @=""

    [HKEY_CLASSES_ROOT\CLSID\{61DC2AF4-EB96-4DB7-A6B2-5C736795491E}\Implemented Categories\{00021492-0000-0000-C000-000000000046}]
    @=""

    [HKEY_CLASSES_ROOT\CLSID\{61DC2AF4-EB96-4DB7-A6B2-5C736795491E}\InprocServer32]
    @="C:\\WINDOWS\\system32\\wgaueng.dll"
    "ThreadingModel"="Apartment"

    Windows Registry Editor Version 5.00

    [HKEY_CLASSES_ROOT\CLSID\{2549F884-AA3F-465B-B0F1-2DC3FBBA5FDC}]
    @=""

    [HKEY_CLASSES_ROOT\CLSID\{2549F884-AA3F-465B-B0F1-2DC3FBBA5FDC}\Implemented Categories]
    @=""

    [HKEY_CLASSES_ROOT\CLSID\{2549F884-AA3F-465B-B0F1-2DC3FBBA5FDC}\Implemented Categories\{00021492-0000-0000-C000-000000000046}]
    @=""

    [HKEY_CLASSES_ROOT\CLSID\{2549F884-AA3F-465B-B0F1-2DC3FBBA5FDC}\InprocServer32]
    @="C:\\WINDOWS\\system32\\InagXpr5.dll"
    "ThreadingModel"="Apartment"

    Windows Registry Editor Version 5.00

    [HKEY_CLASSES_ROOT\CLSID\{989EAC39-8B82-4278-9CA6-63874E559300}]
    @=""

    [HKEY_CLASSES_ROOT\CLSID\{989EAC39-8B82-4278-9CA6-63874E559300}\Implemented Categories]
    @=""

    [HKEY_CLASSES_ROOT\CLSID\{989EAC39-8B82-4278-9CA6-63874E559300}\Implemented Categories\{00021492-0000-0000-C000-000000000046}]
    @=""

    [HKEY_CLASSES_ROOT\CLSID\{989EAC39-8B82-4278-9CA6-63874E559300}\InprocServer32]
    @="C:\\WINDOWS\\system32\\ripcfgex.dll"
    "ThreadingModel"="Apartment"

    Windows Registry Editor Version 5.00

    [HKEY_CLASSES_ROOT\CLSID\{768ED112-0A46-41F4-BEEB-E22D89FFFCA7}]
    @=""

    [HKEY_CLASSES_ROOT\CLSID\{768ED112-0A46-41F4-BEEB-E22D89FFFCA7}\Implemented Categories]
    @=""

    [HKEY_CLASSES_ROOT\CLSID\{768ED112-0A46-41F4-BEEB-E22D89FFFCA7}\Implemented Categories\{00021492-0000-0000-C000-000000000046}]
    @=""

    [HKEY_CLASSES_ROOT\CLSID\{768ED112-0A46-41F4-BEEB-E22D89FFFCA7}\InprocServer32]
    @="C:\\WINDOWS\\system32\\cwbjmon.dll"
    "ThreadingModel"="Apartment"

    Windows Registry Editor Version 5.00

    [HKEY_CLASSES_ROOT\CLSID\{2239C763-740F-4B97-806C-529646F59991}]
    @=""

    [HKEY_CLASSES_ROOT\CLSID\{2239C763-740F-4B97-806C-529646F59991}\Implemented Categories]
    @=""

    [HKEY_CLASSES_ROOT\CLSID\{2239C763-740F-4B97-806C-529646F59991}\Implemented Categories\{00021492-0000-0000-C000-000000000046}]
    @=""

    [HKEY_CLASSES_ROOT\CLSID\{2239C763-740F-4B97-806C-529646F59991}\InprocServer32]
    @="C:\\WINDOWS\\system32\\snlwoa.dll"
    "ThreadingModel"="Apartment"

    Windows Registry Editor Version 5.00

    [HKEY_CLASSES_ROOT\CLSID\{F34A41CF-EAB4-47EF-A42C-A836E83FF61D}]
    @=""

    [HKEY_CLASSES_ROOT\CLSID\{F34A41CF-EAB4-47EF-A42C-A836E83FF61D}\Implemented Categories]
    @=""

    [HKEY_CLASSES_ROOT\CLSID\{F34A41CF-EAB4-47EF-A42C-A836E83FF61D}\Implemented Categories\{00021492-0000-0000-C000-000000000046}]
    @=""

    [HKEY_CLASSES_ROOT\CLSID\{F34A41CF-EAB4-47EF-A42C-A836E83FF61D}\InprocServer32]
    @="C:\\WINDOWS\\system32\\awmeter.dll"
    "ThreadingModel"="Apartment"

    Windows Registry Editor Version 5.00

    [HKEY_CLASSES_ROOT\CLSID\{4DF09495-0324-42E2-AACC-7E1A0D0ABB4A}]
    @=""

    [HKEY_CLASSES_ROOT\CLSID\{4DF09495-0324-42E2-AACC-7E1A0D0ABB4A}\Implemented Categories]
    @=""

    [HKEY_CLASSES_ROOT\CLSID\{4DF09495-0324-42E2-AACC-7E1A0D0ABB4A}\Implemented Categories\{00021492-0000-0000-C000-000000000046}]
    @=""

    [HKEY_CLASSES_ROOT\CLSID\{4DF09495-0324-42E2-AACC-7E1A0D0ABB4A}\InprocServer32]
    @="C:\\WINDOWS\\system32\\dHtaclen.dll"
    "ThreadingModel"="Apartment"

    Windows Registry Editor Version 5.00

    [HKEY_CLASSES_ROOT\CLSID\{2A66DD17-C378-456E-8D5E-41BB93D2FCDC}]
    @=""

    [HKEY_CLASSES_ROOT\CLSID\{2A66DD17-C378-456E-8D5E-41BB93D2FCDC}\Implemented Categories]
    @=""

    [HKEY_CLASSES_ROOT\CLSID\{2A66DD17-C378-456E-8D5E-41BB93D2FCDC}\Implemented Categories\{00021492-0000-0000-C000-000000000046}]
    @=""

    [HKEY_CLASSES_ROOT\CLSID\{2A66DD17-C378-456E-8D5E-41BB93D2FCDC}\InprocServer32]
    @="C:\\WINDOWS\\system32\\mtcat32.dll"
    "ThreadingModel"="Apartment"

    Windows Registry Editor Version 5.00

    [HKEY_CLASSES_ROOT\CLSID\{77239875-4AA2-4412-9308-E2D751BA476C}]
    @=""

    [HKEY_CLASSES_ROOT\CLSID\{77239875-4AA2-4412-9308-E2D751BA476C}\Implemented Categories]
    @=""

    [HKEY_CLASSES_ROOT\CLSID\{77239875-4AA2-4412-9308-E2D751BA476C}\Implemented Categories\{00021492-0000-0000-C000-000000000046}]
    @=""

    [HKEY_CLASSES_ROOT\CLSID\{77239875-4AA2-4412-9308-E2D751BA476C}\InprocServer32]
    @="C:\\WINDOWS\\system32\\irrnonce.dll"
    "ThreadingModel"="Apartment"

    Windows Registry Editor Version 5.00

    [HKEY_CLASSES_ROOT\CLSID\{E1D27203-690B-4C7D-A388-D1A9F5D84808}]
    @=""

    [HKEY_CLASSES_ROOT\CLSID\{E1D27203-690B-4C7D-A388-D1A9F5D84808}\Implemented Categories]
    @=""

    [HKEY_CLASSES_ROOT\CLSID\{E1D27203-690B-4C7D-A388-D1A9F5D84808}\Implemented Categories\{00021492-0000-0000-C000-000000000046}]
    @=""

    [HKEY_CLASSES_ROOT\CLSID\{E1D27203-690B-4C7D-A388-D1A9F5D84808}\InprocServer32]
    @="C:\\WINDOWS\\system32\\mggsvc.dll"
    "ThreadingModel"="Apartment"

    Windows Registry Editor Version 5.00

    [HKEY_CLASSES_ROOT\CLSID\{C4CA3BE6-76A1-4C15-9A5A-0D8519C8AC4E}]
    @=""

    [HKEY_CLASSES_ROOT\CLSID\{C4CA3BE6-76A1-4C15-9A5A-0D8519C8AC4E}\Implemented Categories]
    @=""

    [HKEY_CLASSES_ROOT\CLSID\{C4CA3BE6-76A1-4C15-9A5A-0D8519C8AC4E}\Implemented Categories\{00021492-0000-0000-C000-000000000046}]
    @=""

    [HKEY_CLASSES_ROOT\CLSID\{C4CA3BE6-76A1-4C15-9A5A-0D8519C8AC4E}\InprocServer32]
    @="C:\\WINDOWS\\system32\\cymsnap.dll"
    "ThreadingModel"="Apartment"

    Windows Registry Editor Version 5.00

    [HKEY_CLASSES_ROOT\CLSID\{4744A88A-27F0-40FA-AE76-75D9650884E2}]
    @=""

    [HKEY_CLASSES_ROOT\CLSID\{4744A88A-27F0-40FA-AE76-75D9650884E2}\Implemented Categories]
    @=""

    [HKEY_CLASSES_ROOT\CLSID\{4744A88A-27F0-40FA-AE76-75D9650884E2}\Implemented Categories\{00021492-0000-0000-C000-000000000046}]
    @=""

    [HKEY_CLASSES_ROOT\CLSID\{4744A88A-27F0-40FA-AE76-75D9650884E2}\InprocServer32]
    @="C:\\WINDOWS\\system32\\wxcsapi.dll"
    "ThreadingModel"="Apartment"

    Windows Registry Editor Version 5.00

    [HKEY_CLASSES_ROOT\CLSID\{5C3A5019-70E9-4876-BF44-F6AFB0951A89}]
    @=""

    [HKEY_CLASSES_ROOT\CLSID\{5C3A5019-70E9-4876-BF44-F6AFB0951A89}\Implemented Categories]
    @=""

    [HKEY_CLASSES_ROOT\CLSID\{5C3A5019-70E9-4876-BF44-F6AFB0951A89}\Implemented Categories\{00021492-0000-0000-C000-000000000046}]
    @=""

    [HKEY_CLASSES_ROOT\CLSID\{5C3A5019-70E9-4876-BF44-F6AFB0951A89}\InprocServer32]
    @="C:\\WINDOWS\\system32\\mjjint40.dll"
    "ThreadingModel"="Apartment"

    Windows Registry Editor Version 5.00

    [HKEY_CLASSES_ROOT\CLSID\{DB29EC55-273E-494C-BA9E-638B93144B61}]
    @=""

    [HKEY_CLASSES_ROOT\CLSID\{DB29EC55-273E-494C-BA9E-638B93144B61}\Implemented Categories]
    @=""

    [HKEY_CLASSES_ROOT\CLSID\{DB29EC55-273E-494C-BA9E-638B93144B61}\Implemented Categories\{00021492-0000-0000-C000-000000000046}]
    @=""

    [HKEY_CLASSES_ROOT\CLSID\{DB29EC55-273E-494C-BA9E-638B93144B61}\InprocServer32]
    @="C:\\WINDOWS\\system32\\mjrclr40.dll"
    "ThreadingModel"="Apartment"

    Windows Registry Editor Version 5.00

    [HKEY_CLASSES_ROOT\CLSID\{C6F6E1E1-B213-44DB-AB5D-4D79DFB209DD}]
    @=""

    [HKEY_CLASSES_ROOT\CLSID\{C6F6E1E1-B213-44DB-AB5D-4D79DFB209DD}\Implemented Categories]
    @=""

    [HKEY_CLASSES_ROOT\CLSID\{C6F6E1E1-B213-44DB-AB5D-4D79DFB209DD}\Implemented Categories\{00021492-0000-0000-C000-000000000046}]
    @=""

    [HKEY_CLASSES_ROOT\CLSID\{C6F6E1E1-B213-44DB-AB5D-4D79DFB209DD}\InprocServer32]
    @="C:\\WINDOWS\\system32\\mtcsubs.dll"
    "ThreadingModel"="Apartment"

    Windows Registry Editor Version 5.00

    [HKEY_CLASSES_ROOT\CLSID\{E88EAE69-22F3-4119-9AA5-6DB6D9C620A2}]
    @=""

    [HKEY_CLASSES_ROOT\CLSID\{E88EAE69-22F3-4119-9AA5-6DB6D9C620A2}\Implemented Categories]
    @=""

    [HKEY_CLASSES_ROOT\CLSID\{E88EAE69-22F3-4119-9AA5-6DB6D9C620A2}\Implemented Categories\{00021492-0000-0000-C000-000000000046}]
    @=""

    [HKEY_CLASSES_ROOT\CLSID\{E88EAE69-22F3-4119-9AA5-6DB6D9C620A2}\InprocServer32]
    @="C:\\WINDOWS\\system32\\dwband.dll"
    "ThreadingModel"="Apartment"

    Windows Registry Editor Version 5.00

    [HKEY_CLASSES_ROOT\CLSID\{35A3BDF2-A729-40AB-98A8-3A0A21C2D401}]
    @=""

    [HKEY_CLASSES_ROOT\CLSID\{35A3BDF2-A729-40AB-98A8-3A0A21C2D401}\Implemented Categories]
    @=""

    [HKEY_CLASSES_ROOT\CLSID\{35A3BDF2-A729-40AB-98A8-3A0A21C2D401}\Implemented Categories\{00021492-0000-0000-C000-000000000046}]
    @=""

    [HKEY_CLASSES_ROOT\CLSID\{35A3BDF2-A729-40AB-98A8-3A0A21C2D401}\InprocServer32]
    @="C:\\WINDOWS\\system32\\hxtplug.dll"
    "ThreadingModel"="Apartment"

    Windows Registry Editor Version 5.00

    [HKEY_CLASSES_ROOT\CLSID\{26EF4751-8CAD-4110-8EDC-6C808BF33696}]
    @=""

    [HKEY_CLASSES_ROOT\CLSID\{26EF4751-8CAD-4110-8EDC-6C808BF33696}\Implemented Categories]
    @=""

    [HKEY_CLASSES_ROOT\CLSID\{26EF4751-8CAD-4110-8EDC-6C808BF33696}\Implemented Categories\{00021492-0000-0000-C000-000000000046}]
    @=""

    [HKEY_CLASSES_ROOT\CLSID\{26EF4751-8CAD-4110-8EDC-6C808BF33696}\InprocServer32]
    @="C:\\WINDOWS\\system32\\dprgsnap.dll"
    "ThreadingModel"="Apartment"

    Windows Registry Editor Version 5.00

    [HKEY_CLASSES_ROOT\CLSID\{A3E8A66B-5D52-47AD-ADCC-451F85DB28A0}]
    @=""

    [HKEY_CLASSES_ROOT\CLSID\{A3E8A66B-5D52-47AD-ADCC-451F85DB28A0}\Implemented Categories]
    @=""

    [HKEY_CLASSES_ROOT\CLSID\{A3E8A66B-5D52-47AD-ADCC-451F85DB28A0}\Implemented Categories\{00021492-0000-0000-C000-000000000046}]
    @=""

    [HKEY_CLASSES_ROOT\CLSID\{A3E8A66B-5D52-47AD-ADCC-451F85DB28A0}\InprocServer32]
    @="C:\\WINDOWS\\system32\\iopromon.dll"
    "ThreadingModel"="Apartment"

    Windows Registry Editor Version 5.00

    [HKEY_CLASSES_ROOT\CLSID\{81E180E6-D6E9-457B-B148-6B2696E40478}]
    @=""

    [HKEY_CLASSES_ROOT\CLSID\{81E180E6-D6E9-457B-B148-6B2696E40478}\Implemented Categories]
    @=""

    [HKEY_CLASSES_ROOT\CLSID\{81E180E6-D6E9-457B-B148-6B2696E40478}\Implemented Categories\{00021492-0000-0000-C000-000000000046}]
    @=""

    [HKEY_CLASSES_ROOT\CLSID\{81E180E6-D6E9-457B-B148-6B2696E40478}\InprocServer32]
    @="C:\\WINDOWS\\system32\\rHsadhlp.dll"
    "ThreadingModel"="Apartment"

    Windows Registry Editor Version 5.00

    [HKEY_CLASSES_ROOT\CLSID\{6547E428-2EC0-4A08-AA07-299EF6FDA51F}]
    @=""

    [HKEY_CLASSES_ROOT\CLSID\{6547E428-2EC0-4A08-AA07-299EF6FDA51F}\Implemented Categories]
    @=""

    [HKEY_CLASSES_ROOT\CLSID\{6547E428-2EC0-4A08-AA07-299EF6FDA51F}\Implemented Categories\{00021492-0000-0000-C000-000000000046}]
    @=""

    [HKEY_CLASSES_ROOT\CLSID\{6547E428-2EC0-4A08-AA07-299EF6FDA51F}\InprocServer32]
    @="C:\\WINDOWS\\system32\\ihagehlp.dll"
    "ThreadingModel"="Apartment"

    Windows Registry Editor Version 5.00

    [HKEY_CLASSES_ROOT\CLSID\{97D68211-1408-461A-80AC-A15CF76AFD99}]
    @=""

    [HKEY_CLASSES_ROOT\CLSID\{97D68211-1408-461A-80AC-A15CF76AFD99}\Implemented Categories]
    @=""

    [HKEY_CLASSES_ROOT\CLSID\{97D68211-1408-461A-80AC-A15CF76AFD99}\Implemented Categories\{00021492-0000-0000-C000-000000000046}]
    @=""

    [HKEY_CLASSES_ROOT\CLSID\{97D68211-1408-461A-80AC-A15CF76AFD99}\InprocServer32]
    @="C:\\WINDOWS\\system32\\cbcdll.dll"
    "ThreadingModel"="Apartment"

    Windows Registry Editor Version 5.00

    [HKEY_CLASSES_ROOT\CLSID\{8AEEED30-5FF4-4874-9C71-0C42E50B42E6}]
    @=""

    [HKEY_CLASSES_ROOT\CLSID\{8AEEED30-5FF4-4874-9C71-0C42E50B42E6}\Implemented Categories]
    @=""

    [HKEY_CLASSES_ROOT\CLSID\{8AEEED30-5FF4-4874-9C71-0C42E50B42E6}\Implemented Categories\{00021492-0000-0000-C000-000000000046}]
    @=""

    [HKEY_CLASSES_ROOT\CLSID\{8AEEED30-5FF4-4874-9C71-0C42E50B42E6}\InprocServer32]
    @="C:\\WINDOWS\\system32\\otbc32.dll"
    "ThreadingModel"="Apartment"

    Windows Registry Editor Version 5.00

    [HKEY_CLASSES_ROOT\CLSID\{B30D2E85-CD34-4BE6-AD46-8BE283060FF7}]
    @=""

    [HKEY_CLASSES_ROOT\CLSID\{B30D2E85-CD34-4BE6-AD46-8BE283060FF7}\Implemented Categories]
    @=""

    [HKEY_CLASSES_ROOT\CLSID\{B30D2E85-CD34-4BE6-AD46-8BE283060FF7}\Implemented Categories\{00021492-0000-0000-C000-000000000046}]
    @=""

    [HKEY_CLASSES_ROOT\CLSID\{B30D2E85-CD34-4BE6-AD46-8BE283060FF7}\InprocServer32]
    @="C:\\WINDOWS\\system32\\dprgui.dll"
    "ThreadingModel"="Apartment"

    Windows Registry Editor Version 5.00

    [HKEY_CLASSES_ROOT\CLSID\{3547F6B3-CEF1-467A-AEAE-30478F77C942}]
    @=""

    [HKEY_CLASSES_ROOT\CLSID\{3547F6B3-CEF1-467A-AEAE-30478F77C942}\Implemented Categories]
    @=""

    [HKEY_CLASSES_ROOT\CLSID\{3547F6B3-CEF1-467A-AEAE-30478F77C942}\Implemented Categories\{00021492-0000-0000-C000-000000000046}]
    @=""

    [HKEY_CLASSES_ROOT\CLSID\{3547F6B3-CEF1-467A-AEAE-30478F77C942}\InprocServer32]
    @="C:\\WINDOWS\\system32\\prgfilt.dll"
    "ThreadingModel"="Apartment"

    Windows Registry Editor Version 5.00

    [HKEY_CLASSES_ROOT\CLSID\{F9819CEA-11EB-4AE0-AA39-01E59BFCDF46}]
    @=""

    [HKEY_CLASSES_ROOT\CLSID\{F9819CEA-11EB-4AE0-AA39-01E59BFCDF46}\Implemented Categories]
    @=""

    [HKEY_CLASSES_ROOT\CLSID\{F9819CEA-11EB-4AE0-AA39-01E59BFCDF46}\Implemented Categories\{00021492-0000-0000-C000-000000000046}]
    @=""

    [HKEY_CLASSES_ROOT\CLSID\{F9819CEA-11EB-4AE0-AA39-01E59BFCDF46}\InprocServer32]
    @="C:\\WINDOWS\\system32\\kndhe220.dll"
    "ThreadingModel"="Apartment"

    Windows Registry Editor Version 5.00

    [HKEY_CLASSES_ROOT\CLSID\{02A454BC-4AC9-4D05-97B8-2DEB97F038A7}]
    @=""

    [HKEY_CLASSES_ROOT\CLSID\{02A454BC-4AC9-4D05-97B8-2DEB97F038A7}\Implemented Categories]
    @=""

    [HKEY_CLASSES_ROOT\CLSID\{02A454BC-4AC9-4D05-97B8-2DEB97F038A7}\Implemented Categories\{00021492-0000-0000-C000-000000000046}]
    @=""

    [HKEY_CLASSES_ROOT\CLSID\{02A454BC-4AC9-4D05-97B8-2DEB97F038A7}\InprocServer32]
    @="C:\\WINDOWS\\system32\\uynphost.dll"
    "ThreadingModel"="Apartment"

    Windows Registry Editor Version 5.00

    [HKEY_CLASSES_ROOT\CLSID\{66BF9F29-5C6A-43EC-A4DB-4FBB578F63D7}]
    @=""

    [HKEY_CLASSES_ROOT\CLSID\{66BF9F29-5C6A-43EC-A4DB-4FBB578F63D7}\Implemented Categories]
    @=""

    [HKEY_CLASSES_ROOT\CLSID\{66BF9F29-5C6A-43EC-A4DB-4FBB578F63D7}\Implemented Categories\{00021492-0000-0000-C000-000000000046}]
    @=""

    [HKEY_CLASSES_ROOT\CLSID\{66BF9F29-5C6A-43EC-A4DB-4FBB578F63D7}\InprocServer32]
    @="C:\\WINDOWS\\system32\\mrvbvm50.dll"
    "ThreadingModel"="Apartment"

    Windows Registry Editor Version 5.00

    [HKEY_CLASSES_ROOT\CLSID\{317EE681-0BE2-45E3-9177-405F7BFAC143}]
    @=""

    [HKEY_CLASSES_ROOT\CLSID\{317EE681-0BE2-45E3-9177-405F7BFAC143}\Implemented Categories]
    @=""

    [HKEY_CLASSES_ROOT\CLSID\{317EE681-0BE2-45E3-9177-405F7BFAC143}\Implemented Categories\{00021492-0000-0000-C000-000000000046}]
    @=""

    [HKEY_CLASSES_ROOT\CLSID\{317EE681-0BE2-45E3-9177-405F7BFAC143}\InprocServer32]
    @="C:\\WINDOWS\\system32\\otengl32.dll"
    "ThreadingModel"="Apartment"

    Windows Registry Editor Version 5.00

    [HKEY_CLASSES_ROOT\CLSID\{A01A9184-A87D-44F4-8DE2-CBBD967D9324}]
    @=""

    [HKEY_CLASSES_ROOT\CLSID\{A01A9184-A87D-44F4-8DE2-CBBD967D9324}\Implemented Categories]
    @=""

    [HKEY_CLASSES_ROOT\CLSID\{A01A9184-A87D-44F4-8DE2-CBBD967D9324}\Implemented Categories\{00021492-0000-0000-C000-000000000046}]
    @=""

    [HKEY_CLASSES_ROOT\CLSID\{A01A9184-A87D-44F4-8DE2-CBBD967D9324}\InprocServer32]
    @="C:\\WINDOWS\\system32\\szfolder.dll"
    "ThreadingModel"="Apartment"

    Windows Registry Editor Version 5.00

    [HKEY_CLASSES_ROOT\CLSID\{5D25C076-EF64-459A-AFE9-458A789792AD}]
    @=""

    [HKEY_CLASSES_ROOT\CLSID\{5D25C076-EF64-459A-AFE9-458A789792AD}\Implemented Categories]
    @=""

    [HKEY_CLASSES_ROOT\CLSID\{5D25C076-EF64-459A-AFE9-458A789792AD}\Implemented Categories\{00021492-0000-0000-C000-000000000046}]
    @=""

    [HKEY_CLASSES_ROOT\CLSID\{5D25C076-EF64-459A-AFE9-458A789792AD}\InprocServer32]
    @="C:\\WINDOWS\\system32\\kgdtat.dll"
    "ThreadingModel"="Apartment"

    Windows Registry Editor Version 5.00

    [HKEY_CLASSES_ROOT\CLSID\{12DF87D4-8CA8-4C20-80A2-0C7E1B21BA13}]
    @=""

    [HKEY_CLASSES_ROOT\CLSID\{12DF87D4-8CA8-4C20-80A2-0C7E1B21BA13}\Implemented Categories]
    @=""

    [HKEY_CLASSES_ROOT\CLSID\{12DF87D4-8CA8-4C20-80A2-0C7E1B21BA13}\Implemented Categories\{00021492-0000-0000-C000-000000000046}]
    @=""

    [HKEY_CLASSES_ROOT\CLSID\{12DF87D4-8CA8-4C20-80A2-0C7E1B21BA13}\InprocServer32]
    @="C:\\WINDOWS\\system32\\mxtlsapi.dll"
    "ThreadingModel"="Apartment"

    Windows Registry Editor Version 5.00

    [HKEY_CLASSES_ROOT\CLSID\{4F000194-AA18-44A3-BE03-E678E123E5B1}]
    @=""

    [HKEY_CLASSES_ROOT\CLSID\{4F000194-AA18-44A3-BE03-E678E123E5B1}\Implemented Categories]
    @=""

    [HKEY_CLASSES_ROOT\CLSID\{4F000194-AA18-44A3-BE03-E678E123E5B1}\Implemented Categories\{00021492-0000-0000-C000-000000000046}]
    @=""

    [HKEY_CLASSES_ROOT\CLSID\{4F000194-AA18-44A3-BE03-E678E123E5B1}\InprocServer32]
    @="C:\\WINDOWS\\system32\\guard.tmp"
    "ThreadingModel"="Apartment"

    Windows Registry Editor Version 5.00

    [HKEY_CLASSES_ROOT\CLSID\{4EC01F12-1D77-41A1-9947-E0A9F71B20AA}]
    @=""

    [HKEY_CLASSES_ROOT\CLSID\{4EC01F12-1D77-41A1-9947-E0A9F71B20AA}\Implemented Categories]
    @=""

    [HKEY_CLASSES_ROOT\CLSID\{4EC01F12-1D77-41A1-9947-E0A9F71B20AA}\Implemented Categories\{00021492-0000-0000-C000-000000000046}]
    @=""

    [HKEY_CLASSES_ROOT\CLSID\{4EC01F12-1D77-41A1-9947-E0A9F71B20AA}\InprocServer32]
    @="C:\\WINDOWS\\system32\\trflog.dll"
    "ThreadingModel"="Apartment"

    Windows Registry Editor Version 5.00

    [HKEY_CLASSES_ROOT\CLSID\{FA5C95FB-1E5B-4B05-B451-1B1083C6A9B1}]
    @=""

    [HKEY_CLASSES_ROOT\CLSID\{FA5C95FB-1E5B-4B05-B451-1B1083C6A9B1}\Implemented Categories]
    @=""

    [HKEY_CLASSES_ROOT\CLSID\{FA5C95FB-1E5B-4B05-B451-1B1083C6A9B1}\Implemented Categories\{00021492-0000-0000-C000-000000000046}]
    @=""

    [HKEY_CLASSES_ROOT\CLSID\{FA5C95FB-1E5B-4B05-B451-1B1083C6A9B1}\InprocServer32]
    @="C:\\WINDOWS\\system32\\decpmon.dll"
    "ThreadingModel"="Apartment"

    Windows Registry Editor Version 5.00

    [HKEY_CLASSES_ROOT\CLSID\{DCD99A13-1B9A-4912-9A8D-85A04CA33CC6}]
    @=""

    [HKEY_CLASSES_ROOT\CLSID\{DCD99A13-1B9A-4912-9A8D-85A04CA33CC6}\Implemented Categories]
    @=""

    [HKEY_CLASSES_ROOT\CLSID\{DCD99A13-1B9A-4912-9A8D-85A04CA33CC6}\Implemented Categories\{00021492-0000-0000-C000-000000000046}]
    @=""

    [HKEY_CLASSES_ROOT\CLSID\{DCD99A13-1B9A-4912-9A8D-85A04CA33CC6}\InprocServer32]
    @="C:\\WINDOWS\\system32\\fhp8037ue.dll"
    "ThreadingModel"="Apartment"

    Windows Registry Editor Version 5.00

    [HKEY_CLASSES_ROOT\CLSID\{5A025223-DC53-4A8D-85A0-ADFB8B2FAE9A}]
    @=""

    [HKEY_CLASSES_ROOT\CLSID\{5A025223-DC53-4A8D-85A0-ADFB8B2FAE9A}\Implemented Categories]
    @=""

    [HKEY_CLASSES_ROOT\CLSID\{5A025223-DC53-4A8D-85A0-ADFB8B2FAE9A}\Implemented Categories\{00021492-0000-0000-C000-000000000046}]
    @=""

    [HKEY_CLASSES_ROOT\CLSID\{5A025223-DC53-4A8D-85A0-ADFB8B2FAE9A}\InprocServer32]
    @="C:\\WINDOWS\\system32\\sfnceng.dll"
    "ThreadingModel"="Apartment"

    Windows Registry Editor Version 5.00

    [HKEY_CLASSES_ROOT\CLSID\{447423E8-D11B-4446-9120-7276216A40CE}]
    @=""

    [HKEY_CLASSES_ROOT\CLSID\{447423E8-D11B-4446-9120-7276216A40CE}\Implemented Categories]
    @=""

    [HKEY_CLASSES_ROOT\CLSID\{447423E8-D11B-4446-9120-7276216A40CE}\Implemented Categories\{00021492-0000-0000-C000-000000000046}]
    @=""

    [HKEY_CLASSES_ROOT\CLSID\{447423E8-D11B-4446-9120-7276216A40CE}\InprocServer32]
    @="C:\\WINDOWS\\system32\\vprifier.dll"
    "ThreadingModel"="Apartment"

    Windows Registry Editor Version 5.00

    [HKEY_CLASSES_ROOT\CLSID\{5EC92A5A-0848-4963-BC3C-7AA14C23327B}]
    @=""

    [HKEY_CLASSES_ROOT\CLSID\{5EC92A5A-0848-4963-BC3C-7AA14C23327B}\Implemented Categories]
    @=""

    [HKEY_CLASSES_ROOT\CLSID\{5EC92A5A-0848-4963-BC3C-7AA14C23327B}\Implemented Categories\{00021492-0000-0000-C000-000000000046}]
    @=""

    [HKEY_CLASSES_ROOT\CLSID\{5EC92A5A-0848-4963-BC3C-7AA14C23327B}\InprocServer32]
    @="C:\\WINDOWS\\system32\\opbcp32r.dll"
    "ThreadingModel"="Apartment"

    Windows Registry Editor Version 5.00

    [HKEY_CLASSES_ROOT\CLSID\{238CB486-647C-4B88-9FFB-4142585F8A81}]
    @=""

    [HKEY_CLASSES_ROOT\CLSID\{238CB486-647C-4B88-9FFB-4142585F8A81}\Implemented Categories]
    @=""

    [HKEY_CLASSES_ROOT\CLSID\{238CB486-647C-4B88-9FFB-4142585F8A81}\Implemented Categories\{00021492-0000-0000-C000-000000000046}]
    @=""

    [HKEY_CLASSES_ROOT\CLSID\{238CB486-647C-4B88-9FFB-4142585F8A81}\InprocServer32]
    @="C:\\WINDOWS\\system32\\moiole16.dll"
    "ThreadingModel"="Apartment"

    Windows Registry Editor Version 5.00

    [HKEY_CLASSES_ROOT\CLSID\{2F87EC4D-0115-4D77-BA2E-0C557B88D36F}]
    @=""

    [HKEY_CLASSES_ROOT\CLSID\{2F87EC4D-0115-4D77-BA2E-0C557B88D36F}\Implemented Categories]
    @=""

    [HKEY_CLASSES_ROOT\CLSID\{2F87EC4D-0115-4D77-BA2E-0C557B88D36F}\Implemented Categories\{00021492-0000-0000-C000-000000000046}]
    @=""

    [HKEY_CLASSES_ROOT\CLSID\{2F87EC4D-0115-4D77-BA2E-0C557B88D36F}\InprocServer32]
    @="C:\\WINDOWS\\system32\\bfowsewm.dll"
    "ThreadingModel"="Apartment"

    Windows Registry Editor Version 5.00

    [HKEY_CLASSES_ROOT\CLSID\{CD74549F-60D3-44DE-AE57-22BFB5237EEA}]
    @=""

    [HKEY_CLASSES_ROOT\CLSID\{CD74549F-60D3-44DE-AE57-22BFB5237EEA}\Implemented Categories]
    @=""

    [HKEY_CLASSES_ROOT\CLSID\{CD74549F-60D3-44DE-AE57-22BFB5237EEA}\Implemented Categories\{00021492-0000-0000-C000-000000000046}]
    @=""

    [HKEY_CLASSES_ROOT\CLSID\{CD74549F-60D3-44DE-AE57-22BFB5237EEA}\InprocServer32]
    @="C:\\WINDOWS\\system32\\ibwdial.dll"
    "ThreadingModel"="Apartment"

    Windows Registry Editor Version 5.00

    [HKEY_CLASSES_ROOT\CLSID\{16B9AF1D-E035-49F3-A0C0-A6D9BA00CDD8}]
    @=""

    [HKEY_CLASSES_ROOT\CLSID\{16B9AF1D-E035-49F3-A0C0-A6D9BA00CDD8}\Implemented Categories]
    @=""

    [HKEY_CLASSES_ROOT\CLSID\{16B9AF1D-E035-49F3-A0C0-A6D9BA00CDD8}\Implemented Categories\{00021492-0000-0000-C000-000000000046}]
    @=""

    [HKEY_CLASSES_ROOT\CLSID\{16B9AF1D-E035-49F3-A0C0-A6D9BA00CDD8}\InprocServer32]
    @="C:\\WINDOWS\\system32\\nTrrhook.dll"
    "ThreadingModel"="Apartment"

    Windows Registry Editor Version 5.00

    [HKEY_CLASSES_ROOT\CLSID\{6D0E8A2D-BAB7-4417-924F-6388797DF420}]
    @=""

    [HKEY_CLASSES_ROOT\CLSID\{6D0E8A2D-BAB7-4417-924F-6388797DF420}\Implemented Categories]
    @=""

    [HKEY_CLASSES_ROOT\CLSID\{6D0E8A2D-BAB7-4417-924F-6388797DF420}\Implemented Categories\{00021492-0000-0000-C000-000000000046}]
    @=""

    [HKEY_CLASSES_ROOT\CLSID\{6D0E8A2D-BAB7-4417-924F-6388797DF420}\InprocServer32]
    @="C:\\WINDOWS\\system32\\hQ23msp.dll"
    "ThreadingModel"="Apartment"

    Windows Registry Editor Version 5.00

    [HKEY_CLASSES_ROOT\CLSID\{88B640AA-BBB5-47EF-8077-620A973AAD0B}]
    @=""

    [HKEY_CLASSES_ROOT\CLSID\{88B640AA-BBB5-47EF-8077-620A973AAD0B}\Implemented Categories]
    @=""

    [HKEY_CLASSES_ROOT\CLSID\{88B640AA-BBB5-47EF-8077-620A973AAD0B}\Implemented Categories\{00021492-0000-0000-C000-000000000046}]
    @=""

    [HKEY_CLASSES_ROOT\CLSID\{88B640AA-BBB5-47EF-8077-620A973AAD0B}\InprocServer32]
    @="C:\\WINDOWS\\system32\\amitvo32.dll"
    "ThreadingModel"="Apartment"

    Windows Registry Editor Version 5.00

    [HKEY_CLASSES_ROOT\CLSID\{CE84CD16-3D8A-424C-A652-C7382A1C0BB2}]
    @=""

    [HKEY_CLASSES_ROOT\CLSID\{CE84CD16-3D8A-424C-A652-C7382A1C0BB2}\Implemented Categories]
    @=""

    [HKEY_CLASSES_ROOT\CLSID\{CE84CD16-3D8A-424C-A652-C7382A1C0BB2}\Implemented Categories\{00021492-0000-0000-C000-000000000046}]
    @=""

    [HKEY_CLASSES_ROOT\CLSID\{CE84CD16-3D8A-424C-A652-C7382A1C0BB2}\InprocServer32]
    @="C:\\WINDOWS\\system32\\fusrch.dll"
    "ThreadingModel"="Apartment"

    Windows Registry Editor Version 5.00

    [HKEY_CLASSES_ROOT\CLSID\{E8468BA0-63A8-4BBF-8D77-DCD5DC033FCB}]
    @=""

    [HKEY_CLASSES_ROOT\CLSID\{E8468BA0-63A8-4BBF-8D77-DCD5DC033FCB}\Implemented Categories]
    @=""

    [HKEY_CLASSES_ROOT\CLSID\{E8468BA0-63A8-4BBF-8D77-DCD5DC033FCB}\Implemented Categories\{00021492-0000-0000-C000-000000000046}]
    @=""

    [HKEY_CLASSES_ROOT\CLSID\{E8468BA0-63A8-4BBF-8D77-DCD5DC033FCB}\InprocServer32]
    @="C:\\WINDOWS\\system32\\sfi_ci.dll"
    "ThreadingModel"="Apartment"

    Windows Registry Editor Version 5.00

    [HKEY_CLASSES_ROOT\CLSID\{D9A5F243-70DB-4E79-9224-E7C15B2B821D}]
    @=""

    [HKEY_CLASSES_ROOT\CLSID\{D9A5F243-70DB-4E79-9224-E7C15B2B821D}\Implemented Categories]
    @=""

    [HKEY_CLASSES_ROOT\CLSID\{D9A5F243-70DB-4E79-9224-E7C15B2B821D}\Implemented Categories\{00021492-0000-0000-C000-000000000046}]
    @=""

    [HKEY_CLASSES_ROOT\CLSID\{D9A5F243-70DB-4E79-9224-E7C15B2B821D}\InprocServer32]
    @="C:\\WINDOWS\\system32\\guard.tmp"
    "ThreadingModel"="Apartment"

    Windows Registry Editor Version 5.00

    [HKEY_CLASSES_ROOT\CLSID\{84FCB1BC-6756-4DD2-9A67-69F3118CAD81}]
    @=""

    [HKEY_CLASSES_ROOT\CLSID\{84FCB1BC-6756-4DD2-9A67-69F3118CAD81}\Implemented Categories]
    @=""

    [HKEY_CLASSES_ROOT\CLSID\{84FCB1BC-6756-4DD2-9A67-69F3118CAD81}\Implemented Categories\{00021492-0000-0000-C000-000000000046}]
    @=""

    [HKEY_CLASSES_ROOT\CLSID\{84FCB1BC-6756-4DD2-9A67-69F3118CAD81}\InprocServer32]
    @="C:\\WINDOWS\\system32\\issutil.dll"
    "ThreadingModel"="Apartment"

    Windows Registry Editor Version 5.00

    [HKEY_CLASSES_ROOT\CLSID\{2B320E0D-0F07-402F-9C5F-23F05F0755CE}]
    @=""

    [HKEY_CLASSES_ROOT\CLSID\{2B320E0D-0F07-402F-9C5F-23F05F0755CE}\Implemented Categories]
    @=""

    [HKEY_CLASSES_ROOT\CLSID\{2B320E0D-0F07-402F-9C5F-23F05F0755CE}\Implemented Categories\{00021492-0000-0000-C000-000000000046}]
    @=""

    [HKEY_CLASSES_ROOT\CLSID\{2B320E0D-0F07-402F-9C5F-23F05F0755CE}\InprocServer32]
    @="C:\\WINDOWS\\system32\\WYDMLOG.dll"
    "ThreadingModel"="Apartment"

    Windows Registry Editor Version 5.00

    [HKEY_CLASSES_ROOT\CLSID\{AE55B1B6-A5FA-4AAC-B52C-D4A5EB6F30D3}]
    @=""

    [HKEY_CLASSES_ROOT\CLSID\{AE55B1B6-A5FA-4AAC-B52C-D4A5EB6F30D3}\Implemented Categories]
    @=""

    [HKEY_CLASSES_ROOT\CLSID\{AE55B1B6-A5FA-4AAC-B52C-D4A5EB6F30D3}\Implemented Categories\{00021492-0000-0000-C000-000000000046}]
    @=""

    [HKEY_CLASSES_ROOT\CLSID\{AE55B1B6-A5FA-4AAC-B52C-D4A5EB6F30D3}\InprocServer32]
    @="C:\\WINDOWS\\system32\\guard.tmp"
    "ThreadingModel"="Apartment"

    Windows Registry Editor Version 5.00

    [HKEY_CLASSES_ROOT\CLSID\{6161CA30-D354-46E7-93D3-CECBAB4C35C6}]
    @=""

    [HKEY_CLASSES_ROOT\CLSID\{6161CA30-D354-46E7-93D3-CECBAB4C35C6}\Implemented Categories]
    @=""

    [HKEY_CLASSES_ROOT\CLSID\{6161CA30-D354-46E7-93D3-CECBAB4C35C6}\Implemented Categories\{00021492-0000-0000-C000-000000000046}]
    @=""

    [HKEY_CLASSES_ROOT\CLSID\{6161CA30-D354-46E7-93D3-CECBAB4C35C6}\InprocServer32]
    @="C:\\WINDOWS\\system32\\mrjtes40.dll"
    "ThreadingModel"="Apartment"

    Windows Registry Editor Version 5.00

    [HKEY_CLASSES_ROOT\CLSID\{D3B14758-EDDB-4D94-8F19-C2D053910D0D}]
    @=""

    [HKEY_CLASSES_ROOT\CLSID\{D3B14758-EDDB-4D94-8F19-C2D053910D0D}\Implemented Categories]
    @=""

    [HKEY_CLASSES_ROOT\CLSID\{D3B14758-EDDB-4D94-8F19-C2D053910D0D}\Implemented Categories\{00021492-0000-0000-C000-000000000046}]
    @=""

    [HKEY_CLASSES_ROOT\CLSID\{D3B14758-EDDB-4D94-8F19-C2D053910D0D}\InprocServer32]
    @="C:\\WINDOWS\\system32\\vesapi.dll"
    "ThreadingModel"="Apartment"

    **********************************************************************************
    Files Found are not all bad files:

    C:\WINDOWS\SYSTEM32\
    fp4o03~1.dll Tue 7 Feb 2006 20.47.36 ..S.R 234 190 228,70 K
    ktnml7~1.dll Thu 5 Jan 2006 18.15.38 A.... 236 854 231,30 K
    lv2s09~1.dll Mon 6 Feb 2006 18.32.32 ..S.R 235 002 229,49 K
    m8rmli~1.dll Sun 5 Feb 2006 22.24.04 ..S.R 233 847 228,36 K
    s32evnt1.dll Thu 1 Dec 2005 12.14.20 A.... 86 091 84,07 K
    vsdata.dll Tue 15 Nov 2005 0.50.30 A.... 83 720 81,76 K
    vsinit.dll Tue 15 Nov 2005 0.50.42 A.... 141 064 137,76 K
    vsmonapi.dll Tue 15 Nov 2005 0.50.52 A.... 104 208 101,77 K
    vspubapi.dll Tue 15 Nov 2005 0.50.56 A.... 227 088 221,77 K
    vsregexp.dll Tue 15 Nov 2005 0.51.00 A.... 71 440 69,77 K
    vsutil.dll Tue 15 Nov 2005 0.51.12 A.... 382 728 373,76 K
    vsxml.dll Tue 15 Nov 2005 0.51.20 A.... 100 104 97,76 K
    zlcomm.dll Tue 15 Nov 2005 0.51.40 A.... 79 624 77,76 K
    zlcommdb.dll Tue 15 Nov 2005 0.51.44 A.... 71 440 69,77 K
    __dele~1.dll Tue 7 Feb 2006 20.47.36 A.... 233 847 228,36 K

    15 items found: 15 files (3 H/S), 0 directories.
    Total of file sizes: 2 521 247 bytes 2,40 M
    Locate .tmp files:

    No matches found.
    **********************************************************************************
    Directory Listing of system files:
    Asemalla C ei ole nime„.
    Aseman sarjanumero on 6C95-49E5

    Kansio C:\WINDOWS\System32

    07.02.2006 20:47 234ÿ190 fp4o03h3e.dll
    06.02.2006 18:32 235ÿ002 lv2s09f7e.dll
    05.02.2006 22:24 233ÿ847 m8rmli9118.dll
    23.12.2005 15:52 <KANSIO> dllcache
    15.11.2005 22:19 <KANSIO> Microsoft
    3 tiedosto(a) 703ÿ039 tavua
    2 kansio(ta) 1ÿ094ÿ168ÿ576 tavua vapaana
     
  9. ratnunter

    ratnunter Regular member

    Joined:
    Jun 9, 2005
    Messages:
    131
    Likes Received:
    0
    Trophy Points:
    26
    joo, koitetaan vielä kerran

    avaa l2mefix kansio, toivottavasti se ei oo työpöydällä..
    toivottavasti seuraavat palvelut ovat käynnissä
    seclogon ja workstation

    kun kaikki on valmiina avaa l2mefix kansio ja tuplaklikkaa l2mefix.bat
    paina 2 ja enter
    mee kahville äläkä koske näppikseen/hiireen
    kun kahvit on juotu pitäs lukee ruudulla press any key to reboot now
    paina jotain nappia

    sitte pitäs tulla tavallista hitaampi uudelleenkäynnistys
    ja koneen käynnistyessä pitäs notepadin aueta lokin kanssa, jos ei niin mene l2mefix kansioo ja kato sieltä

    jos näkyy jotain erroreita niin kerro meillekin

    jos nyt menee pieleen, niin laita taas optio 1 loki, ota verkkopiuha koneesta irti ja jätä se kone päälle

    laitan tänne sit manuaalisen fiksin ohjeet( jahka kerkeen, pitää olla töiskin), jokka menee pieleen jos kone on käynnistyny uudelleen sillä aikaa koska l2me muuttaa nimiään uudelleenkäynnistyksessä
     
  10. k0ll1

    k0ll1 Member

    Joined:
    Sep 16, 2004
    Messages:
    24
    Likes Received:
    0
    Trophy Points:
    11
    Noniin mikäli oikein ymmärsin niin sen jälkeen ku on valinnut l2mfix.bat ista opt 2,niin pitäisi kulua suht pitkä aika?!mutta mulla siinä kestää abaut parikyt sekunttia kun se press any key reboot ilmestyy.
    Tämmösen login löysin l2mfix kansiosta:
    L2mfix 010406
    Creating Account.
    Komento on suoritettu.

    Adding Administrative privleges.
    Checking for L2MFix account(0=no 1=yes):
    1
    Granting SeDebugPrivilege to L2MFIX ... successful
    Checking for L2MFix account(0=no 1=yes):
    0
    Zipping up files for submission:
    zip warning: name not matched: dlls\*.*

    zip error: Nothing to do! (backup.zip)
    adding: backregs/notibac.reg (188 bytes security) (deflated 88%)
     
  11. ratnunter

    ratnunter Regular member

    Joined:
    Jun 9, 2005
    Messages:
    131
    Likes Received:
    0
    Trophy Points:
    26
    muokattu:
    katso ohje alla
     
    Last edited: Feb 9, 2006
  12. ratnunter

    ratnunter Regular member

    Joined:
    Jun 9, 2005
    Messages:
    131
    Likes Received:
    0
    Trophy Points:
    26
    joo, tsekkasin just ton l2mfixin, ei siihen ookkaa mitään vielä lisätty


    tarkista että seuraavat palvelut on käynnissä: toissijainen kirjautuminen ja työasema. muuta käynnistystapa automaattiseksi ja käynnistä kumpikin jos eivät oo päällä

    imuroi http://koti.mbnet.fi/illukka/second.bat

    tallenna siihen c:\l2mfix kansioon, korvaa vanha

    imuroi http://koti.mbnet.fi/illukka/l2mfix.bat

    tallenna samaan kansioon ja korvaa vanha.

    sitte tuplaklikkaa l2mfix.bat ja valitte 2 ja paina enter

    oota koskematta näppikseen kunnes sanoo press any key to reboot ja sitte toimi niin ku on edellä neuvottu
     
  13. k0ll1

    k0ll1 Member

    Joined:
    Sep 16, 2004
    Messages:
    24
    Likes Received:
    0
    Trophy Points:
    11
    Joo ei mitää muutosta edellisiin kertoihin...lokia ei edelleenkää näy missään.
     
  14. ratnunter

    ratnunter Regular member

    Joined:
    Jun 9, 2005
    Messages:
    131
    Likes Received:
    0
    Trophy Points:
    26
    onko c:\l2mefix kansiossa lo2.txt?
    laita tänne
     
  15. k0ll1

    k0ll1 Member

    Joined:
    Sep 16, 2004
    Messages:
    24
    Likes Received:
    0
    Trophy Points:
    11
    Ei löydy tuommostakaan...
     
  16. ratnunter

    ratnunter Regular member

    Joined:
    Jun 9, 2005
    Messages:
    131
    Likes Received:
    0
    Trophy Points:
    26
    joopa

    mä oon nyt noi 30 kertaa asentanu look2me:n omalle koneelleni ja joka kerta se on tolla skriptillä lähteny..

    laitappa hijackthisistä ihan ekaksi startuplist loki
    saat sen näin: avaa hjt, klikkaa open misc tools section
    eti sieltä generate startuplist log. enne lokin tekoa laita rastit molempiin ruutuihin, ja vasta sitten klikkaa generate startuplist log
    tallenna se ja paa sisältö tänne

    tarkistetaan siitä pari juttua

    edit: kerro muuten mikä versio nortonista?
     
    Last edited: Feb 12, 2006
  17. k0ll1

    k0ll1 Member

    Joined:
    Sep 16, 2004
    Messages:
    24
    Likes Received:
    0
    Trophy Points:
    11
    Norton Antivirus 2004 Pro

    StartupList report, 13.2.2006, 18:09:51
    StartupList version: 1.52.2
    Started from : C:\Program Files\HijackThis.EXE
    Detected: Windows XP SP1 (WinNT 5.01.2600)
    Detected: Internet Explorer v6.00 SP1 (6.00.2800.1106)
    * Using default options
    * Including empty and uninteresting sections
    * Showing rarely important sections
    ==================================================

    Running processes:

    C:\WINDOWS\System32\smss.exe
    C:\WINDOWS\system32\winlogon.exe
    C:\WINDOWS\system32\services.exe
    C:\WINDOWS\system32\lsass.exe
    C:\WINDOWS\System32\Ati2evxx.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\System32\svchost.exe
    C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
    C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
    C:\WINDOWS\system32\rundll32.exe
    C:\WINDOWS\system32\spoolsv.exe
    C:\WINDOWS\system32\Ati2evxx.exe
    C:\WINDOWS\Explorer.EXE
    C:\WINDOWS\SOUNDMAN.EXE
    C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
    C:\Program Files\Common Files\Symantec Shared\ccApp.exe
    C:\Program Files\DAEMON Tools\daemon.exe
    C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
    C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
    C:\WINDOWS\System32\ctfmon.exe
    C:\Program Files\MSN Messenger\msnmsgr.exe
    C:\Program Files\Messenger\msmsgs.exe
    C:\Program Files\VIA\RAID\raid_tool.exe
    C:\Program Files\ewido anti-malware\ewidoctrl.exe
    C:\Program Files\ewido anti-malware\ewidoguard.exe
    C:\Program Files\Norton AntiVirus\navapsvc.exe
    C:\Program Files\Norton AntiVirus\AdvTools\NPROTECT.EXE
    C:\Program Files\Norton AntiVirus\SAVScan.exe
    C:\WINDOWS\System32\svchost.exe
    C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
    C:\WINDOWS\system32\ZoneLabs\vsmon.exe
    C:\WINDOWS\System32\wuauclt.exe
    C:\Program Files\Mozilla Firefox\firefox.exe
    C:\Program Files\DC++\DCPlusPlus.exe
    C:\Program Files\Winamp\winamp.exe
    C:\Program Files\HijackThis.exe

    --------------------------------------------------

    Listing of startup folders:

    Shell folders Startup:
    [C:\Documents and Settings\Tietokone\Käynnistä-valikko\Ohjelmat\Käynnistys]
    *No files*

    Shell folders AltStartup:
    *Folder not found*

    User shell folders Startup:
    *Folder not found*

    User shell folders AltStartup:
    *Folder not found*

    Shell folders Common Startup:
    [C:\Documents and Settings\All Users\Käynnistä-valikko\Ohjelmat\Käynnistys]
    Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
    Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
    raid_tool.exe.lnk = C:\Program Files\VIA\RAID\raid_tool.exe

    Shell folders Common AltStartup:
    *Folder not found*

    User shell folders Common Startup:
    *Folder not found*

    User shell folders Alternate Common Startup:
    *Folder not found*

    --------------------------------------------------

    Checking Windows NT UserInit:

    [HKLM\Software\Microsoft\Windows NT\CurrentVersion\Winlogon]
    UserInit = C:\WINDOWS\system32\userinit.exe,

    [HKLM\Software\Microsoft\Windows\CurrentVersion\Winlogon]
    *Registry key not found*

    [HKCU\Software\Microsoft\Windows NT\CurrentVersion\Winlogon]
    *Registry value not found*

    [HKCU\Software\Microsoft\Windows\CurrentVersion\Winlogon]
    *Registry key not found*

    --------------------------------------------------

    Autorun entries from Registry:
    HKLM\Software\Microsoft\Windows\CurrentVersion\Run

    SoundMan = SOUNDMAN.EXE
    ATIPTA = C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
    ccApp = "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
    Advanced Tools Check = C:\PROGRA~1\NORTON~1\AdvTools\ADVCHK.EXE
    NeroCheck = C:\WINDOWS\System32\\NeroCheck.exe
    Symantec NetDriver Monitor = C:\PROGRA~1\SYMNET~1\SNDMon.exe /Consumer
    SSC_UserPrompt = C:\Program Files\Common Files\Symantec Shared\Security Center\UsrPrmpt.exe
    DAEMON Tools = "C:\Program Files\DAEMON Tools\daemon.exe" -lang 1033
    Zone Labs Client = C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
    SunJavaUpdateSched = C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe

    --------------------------------------------------

    Autorun entries from Registry:
    HKLM\Software\Microsoft\Windows\CurrentVersion\RunOnce

    *No values found*

    --------------------------------------------------

    Autorun entries from Registry:
    HKLM\Software\Microsoft\Windows\CurrentVersion\RunOnceEx

    *No values found*

    --------------------------------------------------

    Autorun entries from Registry:
    HKLM\Software\Microsoft\Windows\CurrentVersion\RunServices

    *No values found*

    --------------------------------------------------

    Autorun entries from Registry:
    HKLM\Software\Microsoft\Windows\CurrentVersion\RunServicesOnce

    *No values found*

    --------------------------------------------------

    Autorun entries from Registry:
    HKCU\Software\Microsoft\Windows\CurrentVersion\Run

    CTFMON.EXE = C:\WINDOWS\System32\ctfmon.exe
    msnmsgr = "C:\Program Files\MSN Messenger\msnmsgr.exe" /background
    MSMSGS = "C:\Program Files\Messenger\msmsgs.exe" /background

    --------------------------------------------------

    Autorun entries from Registry:
    HKCU\Software\Microsoft\Windows\CurrentVersion\RunOnce

    *No values found*

    --------------------------------------------------

    Autorun entries from Registry:
    HKCU\Software\Microsoft\Windows\CurrentVersion\RunOnceEx

    *Registry key not found*

    --------------------------------------------------

    Autorun entries from Registry:
    HKCU\Software\Microsoft\Windows\CurrentVersion\RunServices

    *No values found*

    --------------------------------------------------

    Autorun entries from Registry:
    HKCU\Software\Microsoft\Windows\CurrentVersion\RunServicesOnce

    *No values found*

    --------------------------------------------------

    Autorun entries from Registry:
    HKLM\Software\Microsoft\Windows NT\CurrentVersion\Run

    *Registry key not found*

    --------------------------------------------------

    Autorun entries from Registry:
    HKCU\Software\Microsoft\Windows NT\CurrentVersion\Run

    *Registry key not found*

    --------------------------------------------------

    Autorun entries in Registry subkeys of:
    HKLM\Software\Microsoft\Windows\CurrentVersion\Run

    [OptionalComponents]
    *No values found*

    --------------------------------------------------

    Autorun entries in Registry subkeys of:
    HKLM\Software\Microsoft\Windows\CurrentVersion\RunOnce
    *No subkeys found*

    --------------------------------------------------

    Autorun entries in Registry subkeys of:
    HKLM\Software\Microsoft\Windows\CurrentVersion\RunOnceEx
    *No subkeys found*

    --------------------------------------------------

    Autorun entries in Registry subkeys of:
    HKLM\Software\Microsoft\Windows\CurrentVersion\RunServices
    *No subkeys found*

    --------------------------------------------------

    Autorun entries in Registry subkeys of:
    HKLM\Software\Microsoft\Windows\CurrentVersion\RunServicesOnce
    *No subkeys found*

    --------------------------------------------------

    Autorun entries in Registry subkeys of:
    HKCU\Software\Microsoft\Windows\CurrentVersion\Run
    *No subkeys found*

    --------------------------------------------------

    Autorun entries in Registry subkeys of:
    HKCU\Software\Microsoft\Windows\CurrentVersion\RunOnce
    *No subkeys found*

    --------------------------------------------------

    Autorun entries in Registry subkeys of:
    HKCU\Software\Microsoft\Windows\CurrentVersion\RunOnceEx
    *Registry key not found*

    --------------------------------------------------

    Autorun entries in Registry subkeys of:
    HKCU\Software\Microsoft\Windows\CurrentVersion\RunServices
    *No subkeys found*

    --------------------------------------------------

    Autorun entries in Registry subkeys of:
    HKCU\Software\Microsoft\Windows\CurrentVersion\RunServicesOnce
    *No subkeys found*

    --------------------------------------------------

    Autorun entries in Registry subkeys of:
    HKLM\Software\Microsoft\Windows NT\CurrentVersion\Run
    *Registry key not found*

    --------------------------------------------------

    Autorun entries in Registry subkeys of:
    HKCU\Software\Microsoft\Windows NT\CurrentVersion\Run
    *Registry key not found*

    --------------------------------------------------

    File association entry for .EXE:
    HKEY_CLASSES_ROOT\exefile\shell\open\command

    (Default) = "%1" %*

    --------------------------------------------------

    File association entry for .COM:
    HKEY_CLASSES_ROOT\comfile\shell\open\command

    (Default) = "%1" %*

    --------------------------------------------------

    File association entry for .BAT:
    HKEY_CLASSES_ROOT\batfile\shell\open\command

    (Default) = "%1" %*

    --------------------------------------------------

    File association entry for .PIF:
    HKEY_CLASSES_ROOT\piffile\shell\open\command

    (Default) = "%1" %*

    --------------------------------------------------

    File association entry for .SCR:
    HKEY_CLASSES_ROOT\scrfile\shell\open\command

    (Default) = "%1" /S

    --------------------------------------------------

    File association entry for .HTA:
    HKEY_CLASSES_ROOT\htafile\shell\open\command

    (Default) = C:\WINDOWS\System32\mshta.exe "%1" %*

    --------------------------------------------------

    File association entry for .TXT:
    HKEY_CLASSES_ROOT\txtfile\shell\open\command

    (Default) = %SystemRoot%\system32\NOTEPAD.EXE %1

    --------------------------------------------------

    Enumerating Active Setup stub paths:
    HKLM\Software\Microsoft\Active Setup\Installed Components
    (* = disabled by HKCU twin)

    [>{22d6f312-b0f6-11d0-94ab-0080c74c7e95}]
    StubPath = C:\WINDOWS\inf\unregmp2.exe /ShowWMP

    [>{26923b43-4d38-484f-9b9e-de460746276c}] *
    StubPath = %systemroot%\system32\shmgrate.exe OCInstallUserConfigIE

    [>{60B49E34-C7CC-11D0-8953-00A0C90347FF}MICROS] *
    StubPath = RunDLL32 IEDKCS32.DLL,BrandIE4 SIGNUP

    [>{881dd1c5-3dcf-431b-b061-f3f88e8be88a}] *
    StubPath = %systemroot%\system32\shmgrate.exe OCInstallUserConfigOE

    [{2C7339CF-2B09-4501-B3F3-F3508C9228ED}] *
    StubPath = %SystemRoot%\system32\regsvr32.exe /s /n /i:/UserInstall %SystemRoot%\system32\themeui.dll

    [{306D6C21-C1B6-4629-986C-E59E1875B8AF}]
    StubPath = "C:\WINDOWS\System32\rundll32.exe" "C:\Program Files\Messenger\msgsc.dll",ShowIconsUser

    [{44BBA840-CC51-11CF-AAFA-00AA00B6015C}] *
    StubPath = "%ProgramFiles%\Outlook Express\setup50.exe" /APP:OE /CALLER:WINNT /user /install

    [{44BBA842-CC51-11CF-AAFA-00AA00B6015B}] *
    StubPath = rundll32.exe advpack.dll,LaunchINFSection C:\WINDOWS\INF\msnetmtg.inf,NetMtg.Install.PerUser.NT

    [{5945c046-1e7d-11d1-bc44-00c04fd912be}] *
    StubPath = rundll32.exe advpack.dll,LaunchINFSection C:\WINDOWS\INF\msmsgs.inf,BLC.Install.PerUser

    [{6BF52A52-394A-11d3-B153-00C04F79FAA6}] *
    StubPath = rundll32.exe advpack.dll,LaunchINFSection C:\WINDOWS\INF\wmp10.inf,PerUserStub

    [{7790769C-0471-11d2-AF11-00C04FA35D02}] *
    StubPath = "%ProgramFiles%\Outlook Express\setup50.exe" /APP:WAB /CALLER:WINNT /user /install

    [{89820200-ECBD-11cf-8B85-00AA005B4340}] *
    StubPath = regsvr32.exe /s /n /i:U shell32.dll

    [{89820200-ECBD-11cf-8B85-00AA005B4383}] *
    StubPath = %SystemRoot%\system32\ie4uinit.exe

    --------------------------------------------------

    Enumerating ICQ Agent Autostart apps:
    HKCU\Software\Mirabilis\ICQ\Agent\Apps

    *Registry key not found*

    --------------------------------------------------

    Load/Run keys from C:\WINDOWS\WIN.INI:

    load=*INI section not found*
    run=*INI section not found*

    Load/Run keys from Registry:

    HKLM\..\Windows NT\CurrentVersion\WinLogon: load=*Registry value not found*
    HKLM\..\Windows NT\CurrentVersion\WinLogon: run=*Registry value not found*
    HKLM\..\Windows\CurrentVersion\WinLogon: load=*Registry key not found*
    HKLM\..\Windows\CurrentVersion\WinLogon: run=*Registry key not found*
    HKCU\..\Windows NT\CurrentVersion\WinLogon: load=*Registry value not found*
    HKCU\..\Windows NT\CurrentVersion\WinLogon: run=*Registry value not found*
    HKCU\..\Windows\CurrentVersion\WinLogon: load=*Registry key not found*
    HKCU\..\Windows\CurrentVersion\WinLogon: run=*Registry key not found*
    HKCU\..\Windows NT\CurrentVersion\Windows: load=
    HKCU\..\Windows NT\CurrentVersion\Windows: run=*Registry value not found*
    HKLM\..\Windows NT\CurrentVersion\Windows: load=*Registry value not found*
    HKLM\..\Windows NT\CurrentVersion\Windows: run=*Registry value not found*
    HKLM\..\Windows NT\CurrentVersion\Windows: AppInit_DLLs=

    --------------------------------------------------

    Shell & screensaver key from C:\WINDOWS\SYSTEM.INI:

    Shell=*INI section not found*
    SCRNSAVE.EXE=*INI section not found*
    drivers=*INI section not found*

    Shell & screensaver key from Registry:

    Shell=Explorer.exe
    SCRNSAVE.EXE=C:\WINDOWS\System32\logon.scr
    drivers=*Registry value not found*

    Policies Shell key:

    HKCU\..\Policies: Shell=*Registry key not found*
    HKLM\..\Policies: Shell=*Registry value not found*

    --------------------------------------------------

    Checking for EXPLORER.EXE instances:

    C:\WINDOWS\Explorer.exe: PRESENT!

    C:\Explorer.exe: not present
    C:\WINDOWS\Explorer\Explorer.exe: not present
    C:\WINDOWS\System\Explorer.exe: not present
    C:\WINDOWS\System32\Explorer.exe: not present
    C:\WINDOWS\Command\Explorer.exe: not present
    C:\WINDOWS\Fonts\Explorer.exe: not present

    --------------------------------------------------

    Checking for superhidden extensions:

    .lnk: HIDDEN! (arrow overlay: yes)
    .pif: HIDDEN! (arrow overlay: yes)
    .exe: not hidden
    .com: not hidden
    .bat: not hidden
    .hta: not hidden
    .scr: not hidden
    .shs: HIDDEN!
    .shb: HIDDEN!
    .vbs: not hidden
    .vbe: not hidden
    .wsh: not hidden
    .scf: HIDDEN! (arrow overlay: NO!)
    .url: HIDDEN! (arrow overlay: yes)
    .js: not hidden
    .jse: not hidden

    --------------------------------------------------

    Verifying REGEDIT.EXE integrity:

    - Regedit.exe found in C:\WINDOWS
    - .reg open command is normal (regedit.exe %1)
    - Regedit.exe has no CompanyName property! It is either missing or named something else.
    - Regedit.exe has no OriginalFilename property! It is either missing or named something else.
    - Regedit.exe has no FileDescription property! It is either missing or named something else.

    Registry check failed!

    --------------------------------------------------

    Enumerating Browser Helper Objects:

    *No BHO's found*

    --------------------------------------------------

    Enumerating Task Scheduler jobs:

    Norton AntiVirus - Scan my computer.job
    Symantec NetDetect.job

    --------------------------------------------------

    Enumerating Download Program Files:

    [Java Plug-in 1.5.0_06]
    InProcServer32 = C:\Program Files\Java\jre1.5.0_06\bin\npjpi150_06.dll
    CODEBASE = http://java.sun.com/update/1.5.0/jinstall-1_5_0_06-windows-i586.cab

    [Java Plug-in 1.5.0_06]
    InProcServer32 = C:\Program Files\Java\jre1.5.0_06\bin\npjpi150_06.dll
    CODEBASE = http://java.sun.com/update/1.5.0/jinstall-1_5_0_06-windows-i586.cab

    [Java Plug-in 1.5.0_06]
    InProcServer32 = C:\Program Files\Java\jre1.5.0_06\bin\npjpi150_06.dll
    CODEBASE = http://java.sun.com/update/1.5.0/jinstall-1_5_0_06-windows-i586.cab

    [Shockwave Flash Object]
    InProcServer32 = C:\WINDOWS\System32\Macromed\Flash\Flash8.ocx
    CODEBASE = http://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab

    --------------------------------------------------

    Enumerating Winsock LSP files:

    NameSpace #1: C:\WINDOWS\System32\mswsock.dll
    NameSpace #2: C:\WINDOWS\System32\winrnr.dll
    NameSpace #3: C:\WINDOWS\System32\mswsock.dll
    Protocol #1: C:\WINDOWS\system32\mswsock.dll
    Protocol #2: C:\WINDOWS\system32\mswsock.dll
    Protocol #3: C:\WINDOWS\system32\mswsock.dll
    Protocol #4: C:\WINDOWS\system32\rsvpsp.dll
    Protocol #5: C:\WINDOWS\system32\rsvpsp.dll
    Protocol #6: C:\WINDOWS\system32\mswsock.dll
    Protocol #7: C:\WINDOWS\system32\mswsock.dll
    Protocol #8: C:\WINDOWS\system32\mswsock.dll
    Protocol #9: C:\WINDOWS\system32\mswsock.dll
    Protocol #10: C:\WINDOWS\system32\mswsock.dll
    Protocol #11: C:\WINDOWS\system32\mswsock.dll
    Protocol #12: C:\WINDOWS\system32\mswsock.dll
    Protocol #13: C:\WINDOWS\system32\mswsock.dll
    Protocol #14: C:\WINDOWS\system32\mswsock.dll
    Protocol #15: C:\WINDOWS\system32\mswsock.dll
    Protocol #16: C:\WINDOWS\system32\mswsock.dll
    Protocol #17: C:\WINDOWS\system32\mswsock.dll

    --------------------------------------------------

    Enumerating Windows NT/2000/XP services

    Microsoft ACPI Driver: System32\DRIVERS\ACPI.sys (system)
    Adobe LM Service: "C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe" (manual start)
    Microsoft Kernel Acoustic Echo Canceller: system32\drivers\aec.sys (manual start)
    AFD Networking Support -ympäristö: \SystemRoot\System32\drivers\afd.sys (autostart)
    Service for WDM 3D Audio Driver: system32\drivers\ALCXSENS.SYS (manual start)
    Service for Realtek AC97 Audio (WDM): system32\drivers\ALCXWDM.SYS (manual start)
    Hälytys: %SystemRoot%\System32\svchost.exe -k LocalService (manual start)
    Sovelluskerroksen yhdyskäytäväpalvelu: %SystemRoot%\System32\alg.exe (manual start)
    Sovellusten hallinta: %SystemRoot%\system32\svchost.exe -k netsvcs (manual start)
    1394 ARP -asiakasprotokolla: System32\DRIVERS\arp1394.sys (manual start)
    RAS Asynchronous Media Driver: System32\DRIVERS\asyncmac.sys (manual start)
    Standardi IDE/ESDI-kiintolevyohjain: System32\DRIVERS\atapi.sys (system)
    Ati HotKey Poller: %SystemRoot%\System32\Ati2evxx.exe (autostart)
    ATI Smart: C:\WINDOWS\system32\ati2sgag.exe (autostart)
    ati2mtag: System32\DRIVERS\ati2mtag.sys (manual start)
    Atioubpsmnt: C:\WINDOWS\System32\drivers\netbt.sys (manual start)
    ATM ARP Client -protokolla: System32\DRIVERS\atmarpc.sys (manual start)
    Windows Audio: %SystemRoot%\System32\svchost.exe -k netsvcs (autostart)
    Audio Stub Driver: System32\DRIVERS\audstub.sys (manual start)
    basic2: System32\DRIVERS\HSF_BSC2.sys (manual start)
    BITS-tausta-ajo (Background Intelligent Transfer Service): %SystemRoot%\System32\svchost.exe -k netsvcs (manual start)
    Tietokoneiden selaus: %SystemRoot%\System32\svchost.exe -k netsvcs (autostart)
    Symantec Event Manager: "C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe" (autostart)
    Symantec Password Validation: "C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe" (manual start)
    Symantec Settings Manager: "C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe" (autostart)
    CD-ROM-ohjain: System32\DRIVERS\cdrom.sys (system)
    Indeksointipalvelu: %SystemRoot%\system32\cisvc.exe (manual start)
    Leikekirja: %SystemRoot%\system32\clipsrv.exe (manual start)
    COM+-järjestelmäsovellus: C:\WINDOWS\System32\dllhost.exe /Processid:{02D4B3F1-FD88-11D1-960D-00805FC79235} (manual start)
    Salauspalvelut: %SystemRoot%\system32\svchost.exe -k netsvcs (autostart)
    DHCP-asiakas: %SystemRoot%\System32\svchost.exe -k netsvcs (autostart)
    Levyohjain: System32\DRIVERS\disk.sys (system)
    Loogisen levyn hallinnan valvontapalvelu: %SystemRoot%\System32\dmadmin.exe /com (manual start)
    dmboot: System32\drivers\dmboot.sys (disabled)
    dmio: System32\drivers\dmio.sys (disabled)
    dmload: System32\drivers\dmload.sys (disabled)
    Loogisen levyn hallinta: %SystemRoot%\System32\svchost.exe -k netsvcs (manual start)
    Microsoft Kernel DLS Syntheiszer: system32\drivers\DMusic.sys (manual start)
    DNS-asiakas: %SystemRoot%\System32\svchost.exe -k NetworkService (autostart)
    Microsoft Kernel DRM Audio Descrambler: system32\drivers\drmkaud.sys (manual start)
    dtscsi: \SystemRoot\System32\Drivers\dtscsi.sys (manual start)
    Virheraportointipalvelut: %SystemRoot%\System32\svchost.exe -k netsvcs (autostart)
    Tapahtumaloki: %SystemRoot%\system32\services.exe (autostart)
    COM+-tapahtumajärjestelmä: C:\WINDOWS\System32\svchost.exe -k netsvcs (manual start)
    ewido security suite control: C:\Program Files\ewido anti-malware\ewidoctrl.exe (autostart)
    ewido security suite driver: \??\C:\Program Files\ewido anti-malware\guard.sys (system)
    ewido security suite guard: C:\Program Files\ewido anti-malware\ewidoguard.exe (autostart)
    Fallback: System32\DRIVERS\HSF_FALL.sys (autostart)
    Nopean käyttäjän vaihdon yhteensopivuus: %SystemRoot%\System32\svchost.exe -k netsvcs (manual start)
    Levykeaseman ohjain: System32\DRIVERS\fdc.sys (manual start)
    Levykeasemaohjain: System32\DRIVERS\flpydisk.sys (manual start)
    Fsks: System32\DRIVERS\HSF_FSKS.sys (autostart)
    Volume Manager -ohjain: System32\DRIVERS\ftdisk.sys (system)
    Game Port Enumerator: System32\DRIVERS\gameenum.sys (manual start)
    Yleinen paketinmääritys: System32\DRIVERS\msgpc.sys (manual start)
    Ohjeet ja tuotetuki: %SystemRoot%\System32\svchost.exe -k netsvcs (autostart)
    HID (Human Interface Device) -liittymä: %SystemRoot%\System32\svchost.exe -k netsvcs (disabled)
    hsf_msft: System32\DRIVERS\HSF_MSFT.sys (manual start)
    i8042-näppäimistö ja PS/2-hiiriohjain: System32\DRIVERS\i8042prt.sys (system)
    CD-Burning Filter Driver: System32\DRIVERS\imapi.sys (system)
    CD-levyjen kirjoittamisen IMAPI COM -palvelu: C:\WINDOWS\System32\imapi.exe (manual start)
    IP Traffic Filter Driver: System32\DRIVERS\ipfltdrv.sys (manual start)
    IP in IP Tunnel Driver: System32\DRIVERS\ipinip.sys (manual start)
    IP Network Address Translator: System32\DRIVERS\ipnat.sys (manual start)
    IPSEC-ohjain: System32\DRIVERS\ipsec.sys (system)
    IR Enumerator Service: System32\DRIVERS\irenum.sys (manual start)
    PnP ISA/EISA -väyläohjain: System32\DRIVERS\isapnp.sys (system)
    K56: System32\DRIVERS\HSF_K56K.sys (autostart)
    Näppäimistön luokkaohjain: System32\DRIVERS\kbdclass.sys (system)
    Microsoft Kernel Wave Audio Mixer: system32\drivers\kmixer.sys (manual start)
    Palvelin: %SystemRoot%\System32\svchost.exe -k netsvcs (autostart)
    Työasema: %SystemRoot%\System32\svchost.exe -k netsvcs (autostart)
    TCP/IP NetBIOS Helper: %SystemRoot%\System32\svchost.exe -k LocalService (autostart)
    Viestinvälitys: %SystemRoot%\System32\svchost.exe -k netsvcs (disabled)
    NetMeeting etätyöpöydän jakaminen: C:\WINDOWS\System32\mnmsrvc.exe (manual start)
    Hiiren luokkaohjain: System32\DRIVERS\mouclass.sys (system)
    WebDav Client Redirector: System32\DRIVERS\mrxdav.sys (manual start)
    MRXSMB: System32\DRIVERS\mrxsmb.sys (system)
    Distributed Transaction Coordinator: C:\WINDOWS\System32\msdtc.exe (manual start)
    Windows Installer -ohjelma: C:\WINDOWS\System32\msiexec.exe /V (manual start)
    Microsoft Streaming Service -välityspalvelin: system32\drivers\MSKSSRV.sys (manual start)
    Microsoft Streaming Clock Proxy: system32\drivers\MSPCLOCK.sys (manual start)
    Microsoft Streaming Quality Manager Proxy: system32\drivers\MSPQM.sys (manual start)
    Norton AntiVirus Auto Protect Service: C:\Program Files\Norton AntiVirus\navapsvc.exe (autostart)
    NAVENG: \??\C:\PROGRA~1\COMMON~1\SYMANT~1\VIRUSD~1\20060208.008\NAVENG.Sys (manual start)
    NAVEX15: \??\C:\PROGRA~1\COMMON~1\SYMANT~1\VIRUSD~1\20060208.008\NavEx15.Sys (manual start)
    Remote Access NDIS TAPI Driver: System32\DRIVERS\ndistapi.sys (manual start)
    NDIS Usermode I/O -protokolla: System32\DRIVERS\ndisuio.sys (manual start)
    Remote Access NDIS WAN Driver: System32\DRIVERS\ndiswan.sys (manual start)
    NetBIOS-käyttöliittymä: System32\DRIVERS\netbios.sys (system)
    NetBT: System32\DRIVERS\netbt.sys (system)
    Verkon DDE: %SystemRoot%\system32\netdde.exe (manual start)
    Verkon DDE DSDM: %SystemRoot%\system32\netdde.exe (manual start)
    Verkkokirjautuminen: %SystemRoot%\System32\lsass.exe (manual start)
    Verkkoyhteydet: %SystemRoot%\System32\svchost.exe -k netsvcs (manual start)
    1394-verkko-ohjain: System32\DRIVERS\nic1394.sys (manual start)
    NLA-nimiavaruus (Network Location Awareness): %SystemRoot%\System32\svchost.exe -k netsvcs (manual start)
    Norton Unerase Protection Driver: \??\C:\WINDOWS\System32\Drivers\NPDRIVER.SYS (manual start)
    Norton Unerase Protection: C:\Program Files\Norton AntiVirus\AdvTools\NPROTECT.EXE (autostart)
    NT LM -suojaustuen toimittaja: %SystemRoot%\System32\lsass.exe (manual start)
    Siirrettävät tallennusvälineet: %SystemRoot%\system32\svchost.exe -k netsvcs (manual start)
    IPX Traffic Filter Driver: System32\DRIVERS\nwlnkflt.sys (manual start)
    IPX Traffic Forwarder Driver: System32\DRIVERS\nwlnkfwd.sys (manual start)
    VIA OHCI Compliant IEEE 1394 Host Controller: System32\DRIVERS\ohci1394.sys (system)
    Rinnakkaisporttiohjain: System32\DRIVERS\parport.sys (manual start)
    Pcatip: System32\DRIVERS\Pcatip.sys (manual start)
    PCI Bus Driver: System32\DRIVERS\pci.sys (system)
    Low level access layer for CD devices: System32\Drivers\Pcouffin.sys (manual start)
    Plug and Play: %SystemRoot%\system32\services.exe (autostart)
    IPSEC-palvelut: %SystemRoot%\System32\lsass.exe (autostart)
    WAN Miniport (PPTP): System32\DRIVERS\raspptp.sys (manual start)
    Processor Driver: System32\DRIVERS\processr.sys (system)
    Suojattu tallennuspaikka: %SystemRoot%\system32\lsass.exe (autostart)
    QoS-paketinajoitus: System32\DRIVERS\psched.sys (manual start)
    Direct Parallel Link Driver: System32\DRIVERS\ptilink.sys (manual start)
    Remote Access Auto Connection -ohjain: System32\DRIVERS\rasacd.sys (system)
    Remote Access Auto Connection -hallinta: %SystemRoot%\System32\svchost.exe -k netsvcs (manual start)
    WAN Miniport (L2TP): System32\DRIVERS\rasl2tp.sys (manual start)
    Etäkäytön (RAS) yhteyksienhallinta: %SystemRoot%\System32\svchost.exe -k netsvcs (manual start)
    Remote Access PPPOE Driver: System32\DRIVERS\raspppoe.sys (manual start)
    Suora rinnakkainen: System32\DRIVERS\raspti.sys (manual start)
    Rdbss: System32\DRIVERS\rdbss.sys (system)
    RDPCDD: System32\DRIVERS\RDPCDD.sys (system)
    Etätyöpöydän ohjeen istunnonhallinta: C:\WINDOWS\system32\sessmgr.exe (manual start)
    Digital CD Audio Playback Filter Driver: System32\DRIVERS\redbook.sys (system)
    Reititys ja etäkäyttö: %SystemRoot%\System32\svchost.exe -k netsvcs (disabled)
    Rksample: System32\DRIVERS\HSF_SAMP.sys (manual start)
    Etäproseduurikutsujen (RPC) paikannin: %SystemRoot%\System32\locator.exe (manual start)
    Etäproseduurikutsu (RPC): %SystemRoot%\system32\svchost -k rpcss (autostart)
    QoS RSVP: %SystemRoot%\System32\rsvp.exe (manual start)
    Realtek RTL8139(A/B/C)-based PCI Fast Ethernet Adapter NT Driver: System32\DRIVERS\RTL8139.SYS (manual start)
    Käyttöoikeustilien hallinta: %SystemRoot%\system32\lsass.exe (autostart)
    SAVRT: \??\C:\Program Files\Norton AntiVirus\SAVRT.SYS (system)
    SAVRTPEL: \??\C:\Program Files\Norton AntiVirus\SAVRTPEL.SYS (system)
    SAVScan: C:\Program Files\Norton AntiVirus\SAVScan.exe (autostart)
    ScriptBlocking Service: C:\PROGRA~1\COMMON~1\SYMANT~1\SCRIPT~1\SBServ.exe (autostart)
    Älykortti-apuohjelma: %SystemRoot%\System32\SCardSvr.exe (manual start)
    Älykortti: %SystemRoot%\System32\SCardSvr.exe (manual start)
    Tehtävien ajoitus: %SystemRoot%\System32\svchost.exe -k netsvcs (autostart)
    Secdrv: System32\DRIVERS\secdrv.sys (manual start)
    Toissijainen kirjautuminen: %SystemRoot%\System32\svchost.exe -k netsvcs (autostart)
    Järjestelmätapahtuman ilmoitus: %SystemRoot%\system32\svchost.exe -k netsvcs (autostart)
    Serenum Filter -ohjain: System32\DRIVERS\serenum.sys (manual start)
    Sarjaporttiohjain: System32\DRIVERS\serial.sys (system)
    Internet-yhteyden palomuuri (ICF) / Internet-yhteyden jakaminen (ICS): %SystemRoot%\System32\svchost.exe -k netsvcs (manual start)
    Käyttöliittymän laitteistotunnistus: %SystemRoot%\System32\svchost.exe -k netsvcs (autostart)
    Symantec Network Drivers Service: C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe (manual start)
    SoftFax: System32\DRIVERS\HSF_FAXX.sys (autostart)
    Microsoft Kernel Audio Splitter: system32\drivers\splitter.sys (manual start)
    Taustatulostusohjain: %SystemRoot%\system32\spoolsv.exe (autostart)
    sptd: System32\Drivers\sptd.sys (system)
    Järjestelmän palautussuodatin -ohjain: \SystemRoot\System32\DRIVERS\sr.sys (disabled)
    Järjestelmän palauttaminen -palvelu: %SystemRoot%\System32\svchost.exe -k netsvcs (autostart)
    Srv: System32\DRIVERS\srv.sys (manual start)
    SSDP-palvelu (Simple Service Discovery Protocol): %SystemRoot%\System32\svchost.exe -k LocalService (manual start)
    WIA (Windows Image Acquisition): %SystemRoot%\System32\svchost.exe -k imgsvc (autostart)
    Ohjelmistoväyläohjain: System32\DRIVERS\swenum.sys (manual start)
    Microsoft Kernel GS Wavetable Synthesizer: system32\drivers\swmidi.sys (manual start)
    MS Software Shadow Copy Provider: C:\WINDOWS\System32\dllhost.exe /Processid:{A024DF6F-4173-49F7-A380-C94B1F56978C} (manual start)
    Symantec Core LC: C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe (autostart)
    SYMDNS: \SystemRoot\System32\Drivers\SYMDNS.SYS (manual start)
    SymEvent: \??\C:\Program Files\Symantec\SYMEVENT.SYS (manual start)
    SYMFW: \SystemRoot\System32\Drivers\SYMFW.SYS (manual start)
    SYMIDS: \SystemRoot\System32\Drivers\SYMIDS.SYS (manual start)
    symlcbrd: \??\C:\WINDOWS\System32\drivers\symlcbrd.sys (autostart)
    SYMNDIS: \SystemRoot\System32\Drivers\SYMNDIS.SYS (manual start)
    SYMREDRV: \SystemRoot\System32\Drivers\SYMREDRV.SYS (manual start)
    SYMTDI: \SystemRoot\System32\Drivers\SYMTDI.SYS (system)
    SymWMI Service: C:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe (autostart)
    Microsoft Kernel System Audio Device: system32\drivers\sysaudio.sys (manual start)
    Resurssilokit ja -hälytykset: %SystemRoot%\system32\smlogsvc.exe (manual start)
    Puhelin: %SystemRoot%\System32\svchost.exe -k netsvcs (manual start)
    TCP/IP-protokollaohjain: System32\DRIVERS\tcpip.sys (system)
    Päätelaiteohjain: System32\DRIVERS\termdd.sys (system)
    Päätepalvelut: %SystemRoot%\System32\svchost.exe -k netsvcs (manual start)
    Teemat: %SystemRoot%\System32\svchost.exe -k netsvcs (autostart)
    Tones: System32\DRIVERS\HSF_TONE.sys (autostart)
    Tiedostolinkkijäljityksen asiakas: %SystemRoot%\system32\svchost.exe -k netsvcs (autostart)
    Windows User Mode Driver Framework: C:\WINDOWS\System32\wdfmgr.exe (autostart)
    Microcode Update -ohjain: System32\DRIVERS\update.sys (manual start)
    Latauksenhallinta: %SystemRoot%\System32\svchost.exe -k netsvcs (autostart)
    Universal Plug & Play -laiteisäntä: %SystemRoot%\System32\svchost.exe -k LocalService (manual start)
    UPS: %SystemRoot%\System32\ups.exe (manual start)
    Microsoft USB Generic Parent Driver: System32\DRIVERS\usbccgp.sys (manual start)
    Microsoft USB 2.0 Enhanced Host Controller Miniport Driver: System32\DRIVERS\usbehci.sys (manual start)
    USB2 Enabled Hub: System32\DRIVERS\usbhub.sys (manual start)
    Microsoft USB PRINTER -luokka: System32\DRIVERS\usbprint.sys (manual start)
    USB Scanner Driver: System32\DRIVERS\usbscan.sys (manual start)
    USB-massamuistiohjain: System32\DRIVERS\USBSTOR.SYS (manual start)
    Microsoft USB Universal Host Controller Miniport Driver: System32\DRIVERS\usbuhci.sys (manual start)
    V124: System32\DRIVERS\HSF_V124.sys (autostart)
    VgaSave: \SystemRoot\System32\drivers\vga.sys (system)
    VIA AGP Filter: System32\DRIVERS\viaagp1.sys (system)
    ViaIde: System32\DRIVERS\viaide.sys (system)
    viasraid: System32\DRIVERS\viasraid.sys (system)
    vsdatant: System32\vsdatant.sys (system)
    TrueVector Internet Monitor: C:\WINDOWS\system32\ZoneLabs\vsmon.exe -service (autostart)
    Aseman tilannevedos: %SystemRoot%\System32\vssvc.exe (manual start)
    Windows Time: %SystemRoot%\System32\svchost.exe -k netsvcs (autostart)
    Remote Access IP ARP Driver: System32\DRIVERS\wanarp.sys (manual start)
    Microsoft WINMM WDM Audio Compatibility Driver: system32\drivers\wdmaud.sys (manual start)
    WebClient: %SystemRoot%\System32\svchost.exe -k LocalService (autostart)
    WMI-palvelu (Windows Management Instrumentation): %systemroot%\system32\svchost.exe -k netsvcs (autostart)
    Portable Media Serial Number Service: %SystemRoot%\System32\svchost.exe -k netsvcs (manual start)
    WMI resurssisovitin: C:\WINDOWS\System32\wbem\wmiapsrv.exe (manual start)
    Automaattiset päivitykset: %systemroot%\system32\svchost.exe -k netsvcs (autostart)
    Wireless Zero Configuration: %SystemRoot%\System32\svchost.exe -k netsvcs (autostart)


    --------------------------------------------------

    Enumerating Windows NT logon/logoff scripts:
    *No scripts set to run*

    Windows NT checkdisk command:
    BootExecute = autocheck autochk *

    Windows NT 'Wininit.ini':
    PendingFileRenameOperations: c:\windows\system32\__delete_on_reboot__rschost.dll|||e

    --------------------------------------------------

    Enumerating ShellServiceObjectDelayLoad items:

    PostBootReminder: C:\WINDOWS\system32\SHELL32.dll
    CDBurn: C:\WINDOWS\system32\SHELL32.dll
    WebCheck: C:\WINDOWS\System32\webcheck.dll
    SysTray: C:\WINDOWS\System32\stobject.dll

    --------------------------------------------------
    Autorun entries from Registry:
    HKCU\Software\Microsoft\Windows\CurrentVersion\policies\Explorer\Run

    *Registry key not found*

    --------------------------------------------------

    Autorun entries from Registry:
    HKLM\Software\Microsoft\Windows\CurrentVersion\policies\Explorer\Run

    *Registry key not found*

    --------------------------------------------------

    End of report, 34 268 bytes
    Report generated in 0,187 seconds

    Command line options:
    /verbose - to add additional info on each section
    /complete - to include empty sections and unsuspicious data
    /full - to include several rarely-important sections
    /force9x - to include Win9x-only startups even if running on WinNT
    /forcent - to include WinNT-only startups even if running on Win9x
    /forceall - to include all Win9x and WinNT startups, regardless of platform
    /history - to list version history only
     
  18. k0ll1

    k0ll1 Member

    Joined:
    Sep 16, 2004
    Messages:
    24
    Likes Received:
    0
    Trophy Points:
    11
    ^upup
     
  19. ratnunter

    ratnunter Regular member

    Joined:
    Jun 9, 2005
    Messages:
    131
    Likes Received:
    0
    Trophy Points:
    26
    lataa http://www.atribune.org/ccount/click.php?id=7

    [*]Sulje kaikki ikkunat ennen jatkamista.
    [*]Tupla-klikkaa Look2Me-Destroyer.exe ajaaksesi ohjelman.
    [*]Rastita Run this program as a task.
    [*]Saat viestin joka sanoo; "Look2Me-Destroyer will close and re-open in approximately 10 seconds". Klikkaa OK
    [*]Kun Look2Me-Destroyer uudelleen avautuu, klikkaa Scan for L2M valintaa, työpöytäsi pikakuvakkeet katoavat hetkeksi, tämä on normaalia.
    [*]Kun skannaus on valmis, klikkaa Remove L2M valintaa.
    [*]Saat Done Scanning viestin, klikkaa OK.
    [*]Kun valmis, saat tämän viestin: Done removing infected files! Look2Me-Destroyer will now shutdown your computer, klikkaa OK.
    [*]Tietokoneesi sammuttaa itsensä.
    [*]Käynnistä koneesi uudelleen.
    [*]Postita C:\Look2Me-Destroyer.txt tiedoston sisältö uuden HijackThis login kera postiisi.
    [/list]Jos palomuurisi varoittaa nettiyhteyksistä tähän ohjelmaan - salli ne.

    Jos saat runtime error '339', lataa MSWINSCK.OCX seuraavasta linkistä ja sijoita se C:\Windows\System32 kansioosi.

    http://www.ascentive.com/support/new/images/lib/MSWINSCK.OCX

    Koeta uudelleen.
     
  20. k0ll1

    k0ll1 Member

    Joined:
    Sep 16, 2004
    Messages:
    24
    Likes Received:
    0
    Trophy Points:
    11

    Look2Me-Destroyer V1.0.6

    Scanning for infected files.....
    Scan started at 21.2.2006 19:01:55

    Infected! C:\WINDOWS\system32\l6p2lg7o16.dll
    Infected! C:\WINDOWS\system32\iKsrecst.dll
    Infected! C:\WINDOWS\System32\guard.tmp

    Attempting to delete infected files...

    Attempting to delete: C:\WINDOWS\system32\l6p2lg7o16.dll
    C:\WINDOWS\system32\l6p2lg7o16.dllcould not be deleted!

    Attempting to delete: C:\WINDOWS\system32\iKsrecst.dll
    C:\WINDOWS\system32\iKsrecst.dllcould not be deleted!

    Attempting to delete: C:\WINDOWS\System32\guard.tmp
    C:\WINDOWS\System32\guard.tmpcould not be deleted!

    Making registry repairs.

    Removing: HKLM\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\Reinstall

    Restoring Windows certificates.

    Replaced hosts file with default windows hosts file


    Restoring SeDebugPrivilege for Järjestelmänvalvojat - Succeeded

    Logfile of HijackThis v1.99.1
    Scan saved at 19:05:13, on 21.2.2006
    Platform: Windows XP SP1 (WinNT 5.01.2600)
    MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

    Running processes:
    C:\WINDOWS\System32\smss.exe
    C:\WINDOWS\system32\winlogon.exe
    C:\WINDOWS\system32\services.exe
    C:\WINDOWS\system32\lsass.exe
    C:\WINDOWS\System32\Ati2evxx.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\System32\svchost.exe
    C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
    C:\WINDOWS\system32\Ati2evxx.exe
    C:\WINDOWS\Explorer.EXE
    C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
    C:\WINDOWS\system32\spoolsv.exe
    C:\WINDOWS\SOUNDMAN.EXE
    C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
    C:\Program Files\Common Files\Symantec Shared\ccApp.exe
    C:\Program Files\Common Files\Symantec Shared\Security Center\UsrPrmpt.exe
    C:\Program Files\DAEMON Tools\daemon.exe
    C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
    C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
    C:\WINDOWS\System32\ctfmon.exe
    C:\Program Files\MSN Messenger\msnmsgr.exe
    C:\Program Files\Messenger\msmsgs.exe
    F:\Digital Imaging\bin\hpotdd01.exe
    C:\Program Files\VIA\RAID\raid_tool.exe
    C:\Program Files\ewido anti-malware\ewidoctrl.exe
    C:\Program Files\Norton AntiVirus\navapsvc.exe
    C:\Program Files\Norton AntiVirus\AdvTools\NPROTECT.EXE
    C:\Program Files\Norton AntiVirus\SAVScan.exe
    C:\WINDOWS\System32\svchost.exe
    C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
    C:\WINDOWS\system32\ZoneLabs\vsmon.exe
    C:\WINDOWS\system32\NOTEPAD.EXE
    C:\Program Files\HijackThis.exe

    R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Linkit
    O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton AntiVirus\NavShExt.dll
    O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
    O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
    O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
    O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
    O4 - HKLM\..\Run: [Advanced Tools Check] C:\PROGRA~1\NORTON~1\AdvTools\ADVCHK.EXE
    O4 - HKLM\..\Run: [NeroCheck] C:\WINDOWS\System32\\NeroCheck.exe
    O4 - HKLM\..\Run: [Symantec NetDriver Monitor] C:\PROGRA~1\SYMNET~1\SNDMon.exe /Consumer
    O4 - HKLM\..\Run: [SSC_UserPrompt] C:\Program Files\Common Files\Symantec Shared\Security Center\UsrPrmpt.exe
    O4 - HKLM\..\Run: [DAEMON Tools] "C:\Program Files\DAEMON Tools\daemon.exe" -lang 1033
    O4 - HKLM\..\Run: [Zone Labs Client] C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
    O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
    O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\ctfmon.exe
    O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\MSN Messenger\msnmsgr.exe" /background
    O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
    O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
    O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
    O4 - Global Startup: hpoddt01.exe.lnk = ?
    O4 - Global Startup: raid_tool.exe.lnk = C:\Program Files\VIA\RAID\raid_tool.exe
    O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\npjpi150_06.dll
    O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\npjpi150_06.dll
    O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - "C:\PROGRA~1\MSNMES~1\msgrapp.dll" (file missing)
    O23 - Service: Adobe LM Service - Unknown owner - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
    O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\System32\Ati2evxx.exe
    O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
    O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
    O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
    O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
    O23 - Service: ewido security suite control - ewido networks - C:\Program Files\ewido anti-malware\ewidoctrl.exe
    O23 - Service: Norton AntiVirus Auto Protect Service (navapsvc) - Symantec Corporation - C:\Program Files\Norton AntiVirus\navapsvc.exe
    O23 - Service: Norton Unerase Protection (NProtectService) - Symantec Corporation - C:\Program Files\Norton AntiVirus\AdvTools\NPROTECT.EXE
    O23 - Service: SAVScan - Symantec Corporation - C:\Program Files\Norton AntiVirus\SAVScan.exe
    O23 - Service: ScriptBlocking Service (SBService) - Symantec Corporation - C:\PROGRA~1\COMMON~1\SYMANT~1\SCRIPT~1\SBServ.exe
    O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
    O23 - Service: Symantec Core LC - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
    O23 - Service: SymWMI Service (SymWSC) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe
    O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs, LLC - C:\WINDOWS\system32\ZoneLabs\vsmon.exe

     

Share This Page