GMER 2.1.19357 - http://www.gmer.net 3rd party scan 2014-02-03 01:07:17 Windows 6.1.7601 Service Pack 1 \Device\Harddisk0\DR0 -> \Device\Ide\IdeDeviceP1T0L0-0 WDC_WD3200BEKT-00KA9T0 rev.01.01A01 298.09GB Running: tool.exe; Driver: C:\Users\makem\AppData\Local\Temp\uxliqpod.sys ---- System - GMER 2.1 ---- SSDT \??\C:\Windows\system32\drivers\SandBox.sys ZwAllocateVirtualMemory [0x9387A6E0] SSDT \??\C:\Windows\system32\drivers\SandBox.sys ZwAlpcConnectPort [0x9387AB60] SSDT \??\C:\Windows\system32\drivers\DgSafe.sys ZwAlpcSendWaitReceivePort [0x9BEB9943] SSDT \??\C:\Program Files\Trusteer\Rapport\bin\RapportPG.sys ZwAssignProcessToJobObject [0x939303F0] SSDT \??\C:\Windows\system32\drivers\DgSafe.sys ZwClose [0x9BEABBF6] SSDT \??\C:\Windows\system32\drivers\SandBox.sys ZwConnectPort [0x9387A980] SSDT \??\C:\Program Files\Trusteer\Rapport\bin\RapportPG.sys ZwCreateFile [0x9392E6F0] SSDT \??\C:\Windows\system32\drivers\DgSafe.sys ZwCreateKey [0x9BEAC120] SSDT \??\C:\Windows\system32\drivers\SandBox.sys ZwCreateProcess [0x93879AB0] SSDT \??\C:\Windows\system32\drivers\SandBox.sys ZwCreateProcessEx [0x93879BA0] SSDT \??\C:\Windows\system32\drivers\SandBox.sys ZwCreateSection [0x93877DE0] SSDT \??\C:\Windows\system32\drivers\SandBox.sys ZwCreateSymbolicLinkObject [0x93878AB0] SSDT \??\C:\Windows\system32\drivers\DgSafe.sys ZwCreateThread [0x9BEB5191] SSDT \??\C:\Windows\system32\drivers\DgSafe.sys ZwCreateThreadEx [0x9BEB51CF] SSDT \??\C:\Windows\system32\drivers\DgSafe.sys ZwCreateUserProcess [0x9BEB4ADC] SSDT \??\C:\Windows\system32\drivers\DgSafe.sys ZwDebugActiveProcess [0x9BEB4F30] SSDT \??\C:\Program Files\Trusteer\Rapport\bin\RapportPG.sys ZwDeleteFile [0x9392F190] SSDT \??\C:\Windows\system32\drivers\DgSafe.sys ZwDeleteKey [0x9BEAB94A] SSDT \??\C:\Windows\system32\drivers\DgSafe.sys ZwDeleteValueKey [0x9BEABA74] SSDT \??\C:\Windows\system32\drivers\SandBox.sys ZwEnumerateKey [0x93878E10] SSDT \??\C:\Windows\system32\drivers\SandBox.sys ZwEnumerateValueKey [0x93878EF0] SSDT \??\C:\Windows\system32\drivers\DgSafe.sys ZwFreeVirtualMemory [0x9BEB4FFF] SSDT \??\C:\Windows\system32\drivers\SandBox.sys ZwFsControlFile [0x938780C0] SSDT \??\C:\Windows\system32\drivers\DgSafe.sys ZwLoadDriver [0x9BEB8F21] SSDT \??\C:\Program Files\Trusteer\Rapport\bin\RapportPG.sys ZwLoadKey [0x93932330] SSDT \??\C:\Windows\system32\drivers\SandBox.sys ZwMakeTemporaryObject [0x938789F0] SSDT \SystemRoot\system32\DRIVERS\avgidsshimx.sys ZwNotifyChangeKey [0x93A59690] SSDT \SystemRoot\system32\DRIVERS\avgidsshimx.sys ZwNotifyChangeMultipleKeys [0x93A597B0] SSDT \??\C:\Program Files\Trusteer\Rapport\bin\RapportPG.sys ZwOpenFile [0x9392EFA0] SSDT \??\C:\Windows\system32\drivers\DgSafe.sys ZwOpenKey [0x9BEC2E48] SSDT \??\C:\Windows\system32\drivers\DgSafe.sys ZwOpenKeyEx [0x9BEC308E] SSDT \??\C:\Windows\system32\drivers\DgSafe.sys ZwOpenProcess [0x9BEB504C] SSDT \??\C:\Windows\system32\drivers\SandBox.sys ZwOpenSection [0x93877EB0] SSDT \SystemRoot\system32\DRIVERS\avgidsshimx.sys ZwOpenThread [0x93A59490] SSDT \??\C:\Windows\system32\drivers\DgSafe.sys ZwProtectVirtualMemory [0x9BEB41B0] SSDT \??\C:\Windows\system32\drivers\SandBox.sys ZwQueryKey [0x93878FD0] SSDT \??\C:\Program Files\Trusteer\Rapport\bin\RapportPG.sys ZwQueryValueKey [0x939321E0] SSDT \??\C:\Windows\system32\drivers\DgSafe.sys ZwQueueApcThread [0x9BEB40D6] SSDT \??\C:\Windows\system32\drivers\DgSafe.sys ZwRenameKey [0x9BEAC773] SSDT \??\C:\Program Files\Trusteer\Rapport\bin\RapportPG.sys ZwReplaceKey [0x939320C0] SSDT \??\C:\Windows\system32\drivers\SandBox.sys ZwRequestPort [0x9387AC50] SSDT \??\C:\Windows\system32\drivers\DgSafe.sys ZwRequestWaitReplyPort [0x9BEB9484] SSDT \??\C:\Windows\system32\drivers\DgSafe.sys ZwRestoreKey [0x9BEABC35] SSDT \??\C:\Windows\system32\drivers\SandBox.sys ZwSaveKey [0x93879340] SSDT \??\C:\Windows\system32\drivers\SandBox.sys ZwSaveKeyEx [0x93879410] SSDT \??\C:\Windows\system32\drivers\SandBox.sys ZwSecureConnectPort [0x9387AA70] SSDT \??\C:\Windows\system32\drivers\DgSafe.sys ZwSetContextThread [0x9BEB44B9] SSDT \??\C:\Windows\system32\drivers\SandBox.sys ZwSetInformationDebugObject [0x9387B080] SSDT \??\C:\Program Files\Trusteer\Rapport\bin\RapportPG.sys ZwSetInformationFile [0x9392F330] SSDT \??\C:\Windows\system32\drivers\SandBox.sys ZwSetSecurityObject [0x9387B180] SSDT \??\C:\Windows\system32\drivers\DgSafe.sys ZwSetSystemInformation [0x9BEB8744] SSDT \??\C:\Windows\system32\drivers\DgSafe.sys ZwSetValueKey [0x9BEAC3B8] SSDT \??\C:\Windows\system32\drivers\DgSafe.sys ZwSuspendProcess [0x9BEB443E] SSDT \??\C:\Windows\system32\drivers\DgSafe.sys ZwSuspendThread [0x9BEB4117] SSDT \??\C:\Windows\system32\drivers\DgSafe.sys ZwSystemDebugControl [0x9BEB8651] SSDT \??\C:\Windows\system32\drivers\DgSafe.sys ZwTerminateJobObject [0x9BEB4232] SSDT \??\C:\Windows\system32\drivers\DgSafe.sys ZwTerminateProcess [0x9BEB41F3] SSDT \??\C:\Windows\system32\drivers\DgSafe.sys ZwTerminateThread [0x9BEB447C] SSDT \??\C:\Windows\system32\drivers\DgSafe.sys ZwTestAlert [0x9BEB3E3A] SSDT \??\C:\Windows\system32\drivers\SandBox.sys ZwUnloadDriver [0x93879830] SSDT \??\C:\Windows\system32\drivers\DgSafe.sys ZwUnmapViewOfSection [0x9BEB4FA4] SSDT \??\C:\Windows\system32\drivers\SandBox.sys ZwWriteFile [0x93877FB0] SSDT \??\C:\Windows\system32\drivers\DgSafe.sys ZwWriteVirtualMemory [0x9BEB4154] ---- Kernel code sections - GMER 2.1 ---- .text ntoskrnl.exe!ZwRollbackEnlistment + 1409 830429A5 1 Byte [06] .text ntoskrnl.exe!KiDispatchInterrupt + 5A2 83062512 19 Bytes [E0, 0F, BA, F0, 07, 73, 09, ...] {LOOPNZ 0x11; MOV EDX, 0x97307f0; MOV CR4, EAX; OR AL, 0x80; MOV CR4, EAX; RET ; MOV ECX, CR3} .text ntoskrnl.exe!KeRemoveQueueEx + 13BB 830699B0 4 Bytes [E0, A6, 87, 93] .text ntoskrnl.exe!KeRemoveQueueEx + 13C7 830699BC 4 Bytes [60, AB, 87, 93] .text ntoskrnl.exe!KeRemoveQueueEx + 140B 83069A00 4 Bytes [43, 99, EB, 9B] {INC EBX; CDQ ; JMP 0xffffff9f} .text ntoskrnl.exe!KeRemoveQueueEx + 141B 83069A10 4 Bytes [F0, 03, 93, 93] .text ntoskrnl.exe!KeRemoveQueueEx + 1437 83069A2C 4 Bytes [F6, BB, EA, 9B] .text ... PAGE ntoskrnl.exe!ZwTerminateProcess + 43 832264D3 4 Bytes CALL 9BEAA7A5 \??\C:\Windows\system32\drivers\DgSafe.sys .sptd1 C:\Windows\System32\Drivers\sptd.sys entry point in ".sptd1" section [0x8C2E7774] .text C:\Windows\system32\DRIVERS\atikmdag.sys section is writeable [0x95407000, 0x23097E, 0xE8000020] ? C:\Windows\System32\Drivers\axyzk0l7.SYS suspicious PE modification ? C:\Windows\system32\drivers\DgSafe.sys The system cannot find the file specified. ! .text \Program Files\Alcohol Soft\Alcohol 120\Alcoholx.dll section is writeable [0x77D71000, 0x152A2, 0xE0000020] ---- User code sections - GMER 2.1 ---- .text C:\Windows\system32\Ati2evxx.exe[624] USER32.dll!SetForegroundWindow 7591B225 5 Bytes JMP 100A5574 c:\progra~1\agnitum\outpos~1\wl_hook.dll .text C:\Windows\system32\Ati2evxx.exe[624] USER32.dll!SetWindowPos 75921BC4 5 Bytes JMP 100A55A0 c:\progra~1\agnitum\outpos~1\wl_hook.dll .text C:\Windows\system32\Ati2evxx.exe[624] USER32.dll!ChangeDisplaySettingsExA 7593627A 5 Bytes JMP 100A55F8 c:\progra~1\agnitum\outpos~1\wl_hook.dll .text C:\Windows\system32\Ati2evxx.exe[624] USER32.dll!ChangeDisplaySettingsExW 7595FA39 5 Bytes JMP 100A5624 c:\progra~1\agnitum\outpos~1\wl_hook.dll .text C:\Windows\System32\spoolsv.exe[672] USER32.dll!SetForegroundWindow 7591B225 5 Bytes JMP 100A5574 c:\progra~1\agnitum\outpos~1\wl_hook.dll .text C:\Windows\System32\spoolsv.exe[672] USER32.dll!SetWindowPos 75921BC4 5 Bytes JMP 100A55A0 c:\progra~1\agnitum\outpos~1\wl_hook.dll .text C:\Windows\System32\spoolsv.exe[672] USER32.dll!ChangeDisplaySettingsExA 7593627A 5 Bytes JMP 100A55F8 c:\progra~1\agnitum\outpos~1\wl_hook.dll .text C:\Windows\System32\spoolsv.exe[672] USER32.dll!ChangeDisplaySettingsExW 7595FA39 5 Bytes JMP 100A5624 c:\progra~1\agnitum\outpos~1\wl_hook.dll .text C:\Program Files\Synaptics\SynTP\SynTPEnh.exe[676] USER32.dll!SetForegroundWindow 7591B225 5 Bytes JMP 100A5574 c:\progra~1\agnitum\outpos~1\wl_hook.dll .text C:\Program Files\Synaptics\SynTP\SynTPEnh.exe[676] USER32.dll!SetWindowPos 75921BC4 5 Bytes JMP 100A55A0 c:\progra~1\agnitum\outpos~1\wl_hook.dll .text C:\Program Files\Synaptics\SynTP\SynTPEnh.exe[676] USER32.dll!ChangeDisplaySettingsExA 7593627A 5 Bytes JMP 100A55F8 c:\progra~1\agnitum\outpos~1\wl_hook.dll .text C:\Program Files\Synaptics\SynTP\SynTPEnh.exe[676] USER32.dll!ChangeDisplaySettingsExW 7595FA39 5 Bytes JMP 100A5624 c:\progra~1\agnitum\outpos~1\wl_hook.dll .text C:\Program Files\TOSHIBA\Bluetooth Toshiba Stack\ItSecMng.exe[1060] USER32.dll!SetForegroundWindow 7591B225 5 Bytes JMP 100A5574 c:\progra~1\agnitum\outpos~1\wl_hook.dll .text C:\Program Files\TOSHIBA\Bluetooth Toshiba Stack\ItSecMng.exe[1060] USER32.dll!SetWindowPos 75921BC4 5 Bytes JMP 100A55A0 c:\progra~1\agnitum\outpos~1\wl_hook.dll .text C:\Program Files\TOSHIBA\Bluetooth Toshiba Stack\ItSecMng.exe[1060] USER32.dll!ChangeDisplaySettingsExA 7593627A 5 Bytes JMP 100A55F8 c:\progra~1\agnitum\outpos~1\wl_hook.dll .text C:\Program Files\TOSHIBA\Bluetooth Toshiba Stack\ItSecMng.exe[1060] USER32.dll!ChangeDisplaySettingsExW 7595FA39 5 Bytes JMP 100A5624 c:\progra~1\agnitum\outpos~1\wl_hook.dll .text C:\Windows\system32\svchost.exe[1076] USER32.dll!SetForegroundWindow 7591B225 5 Bytes JMP 100A5574 c:\progra~1\agnitum\outpos~1\wl_hook.dll .text C:\Windows\system32\svchost.exe[1076] USER32.dll!SetWindowPos 75921BC4 5 Bytes JMP 100A55A0 c:\progra~1\agnitum\outpos~1\wl_hook.dll .text C:\Windows\system32\svchost.exe[1076] USER32.dll!ChangeDisplaySettingsExA 7593627A 5 Bytes JMP 100A55F8 c:\progra~1\agnitum\outpos~1\wl_hook.dll .text C:\Windows\system32\svchost.exe[1076] USER32.dll!ChangeDisplaySettingsExW 7595FA39 5 Bytes JMP 100A5624 c:\progra~1\agnitum\outpos~1\wl_hook.dll .text C:\Program Files\Allway Sync\Bin\syncappw.exe[1164] USER32.dll!SetForegroundWindow 7591B225 5 Bytes JMP 100A5574 c:\progra~1\agnitum\outpos~1\wl_hook.dll .text C:\Program Files\Allway Sync\Bin\syncappw.exe[1164] USER32.dll!SetWindowPos 75921BC4 5 Bytes JMP 100A55A0 c:\progra~1\agnitum\outpos~1\wl_hook.dll .text C:\Program Files\Allway Sync\Bin\syncappw.exe[1164] USER32.dll!ChangeDisplaySettingsExA 7593627A 5 Bytes JMP 100A55F8 c:\progra~1\agnitum\outpos~1\wl_hook.dll .text C:\Program Files\Allway Sync\Bin\syncappw.exe[1164] USER32.dll!ChangeDisplaySettingsExW 7595FA39 5 Bytes JMP 100A5624 c:\progra~1\agnitum\outpos~1\wl_hook.dll .text C:\Windows\system32\wininit.exe[1220] USER32.dll!SetForegroundWindow 7591B225 5 Bytes JMP 100A5574 c:\progra~1\agnitum\outpos~1\wl_hook.dll .text C:\Windows\system32\wininit.exe[1220] USER32.dll!SetWindowPos 75921BC4 5 Bytes JMP 100A55A0 c:\progra~1\agnitum\outpos~1\wl_hook.dll .text C:\Windows\system32\wininit.exe[1220] USER32.dll!ChangeDisplaySettingsExA 7593627A 5 Bytes JMP 100A55F8 c:\progra~1\agnitum\outpos~1\wl_hook.dll .text C:\Windows\system32\wininit.exe[1220] USER32.dll!ChangeDisplaySettingsExW 7595FA39 5 Bytes JMP 100A5624 c:\progra~1\agnitum\outpos~1\wl_hook.dll .text C:\Windows\system32\winlogon.exe[1288] USER32.dll!SetForegroundWindow 7591B225 5 Bytes JMP 100A5574 c:\progra~1\agnitum\outpos~1\wl_hook.dll .text C:\Windows\system32\winlogon.exe[1288] USER32.dll!SetWindowPos 75921BC4 5 Bytes JMP 100A55A0 c:\progra~1\agnitum\outpos~1\wl_hook.dll .text C:\Windows\system32\winlogon.exe[1288] USER32.dll!ChangeDisplaySettingsExA 7593627A 5 Bytes JMP 100A55F8 c:\progra~1\agnitum\outpos~1\wl_hook.dll .text C:\Windows\system32\winlogon.exe[1288] USER32.dll!ChangeDisplaySettingsExW 7595FA39 5 Bytes JMP 100A5624 c:\progra~1\agnitum\outpos~1\wl_hook.dll .text C:\Windows\system32\services.exe[1308] USER32.dll!SetForegroundWindow 7591B225 5 Bytes JMP 100A5574 c:\progra~1\agnitum\outpos~1\wl_hook.dll .text C:\Windows\system32\services.exe[1308] USER32.dll!SetWindowPos 75921BC4 5 Bytes JMP 100A55A0 c:\progra~1\agnitum\outpos~1\wl_hook.dll .text C:\Windows\system32\services.exe[1308] USER32.dll!ChangeDisplaySettingsExA 7593627A 5 Bytes JMP 100A55F8 c:\progra~1\agnitum\outpos~1\wl_hook.dll .text C:\Windows\system32\services.exe[1308] USER32.dll!ChangeDisplaySettingsExW 7595FA39 5 Bytes JMP 100A5624 c:\progra~1\agnitum\outpos~1\wl_hook.dll .text C:\Windows\system32\lsass.exe[1348] USER32.dll!SetForegroundWindow 7591B225 5 Bytes JMP 100A5574 c:\progra~1\agnitum\outpos~1\wl_hook.dll .text C:\Windows\system32\lsass.exe[1348] USER32.dll!SetWindowPos 75921BC4 5 Bytes JMP 100A55A0 c:\progra~1\agnitum\outpos~1\wl_hook.dll .text C:\Windows\system32\lsass.exe[1348] USER32.dll!ChangeDisplaySettingsExA 7593627A 5 Bytes JMP 100A55F8 c:\progra~1\agnitum\outpos~1\wl_hook.dll .text C:\Windows\system32\lsass.exe[1348] USER32.dll!ChangeDisplaySettingsExW 7595FA39 5 Bytes JMP 100A5624 c:\progra~1\agnitum\outpos~1\wl_hook.dll .text C:\Program Files\Microsoft AutoRoute 2010\StreetsOlkShim.exe[1396] USER32.dll!SetForegroundWindow 7591B225 5 Bytes JMP 100A5574 c:\progra~1\agnitum\outpos~1\wl_hook.dll .text C:\Program Files\Microsoft AutoRoute 2010\StreetsOlkShim.exe[1396] USER32.dll!SetWindowPos 75921BC4 5 Bytes JMP 100A55A0 c:\progra~1\agnitum\outpos~1\wl_hook.dll .text C:\Program Files\Microsoft AutoRoute 2010\StreetsOlkShim.exe[1396] USER32.dll!ChangeDisplaySettingsExA 7593627A 5 Bytes JMP 100A55F8 c:\progra~1\agnitum\outpos~1\wl_hook.dll .text C:\Program Files\Microsoft AutoRoute 2010\StreetsOlkShim.exe[1396] USER32.dll!ChangeDisplaySettingsExW 7595FA39 5 Bytes JMP 100A5624 c:\progra~1\agnitum\outpos~1\wl_hook.dll .text C:\Windows\system32\svchost.exe[1456] USER32.dll!SetForegroundWindow 7591B225 5 Bytes JMP 100A5574 c:\progra~1\agnitum\outpos~1\wl_hook.dll .text C:\Windows\system32\svchost.exe[1456] USER32.dll!SetWindowPos 75921BC4 5 Bytes JMP 100A55A0 c:\progra~1\agnitum\outpos~1\wl_hook.dll .text C:\Windows\system32\svchost.exe[1456] USER32.dll!ChangeDisplaySettingsExA 7593627A 5 Bytes JMP 100A55F8 c:\progra~1\agnitum\outpos~1\wl_hook.dll .text C:\Windows\system32\svchost.exe[1456] USER32.dll!ChangeDisplaySettingsExW 7595FA39 5 Bytes JMP 100A5624 c:\progra~1\agnitum\outpos~1\wl_hook.dll .text C:\Windows\system32\svchost.exe[1532] user32.dll!SetForegroundWindow 7591B225 5 Bytes JMP 100A5574 c:\progra~1\agnitum\outpos~1\wl_hook.dll .text C:\Windows\system32\svchost.exe[1532] user32.dll!SetWindowPos 75921BC4 5 Bytes JMP 100A55A0 c:\progra~1\agnitum\outpos~1\wl_hook.dll .text C:\Windows\system32\svchost.exe[1532] user32.dll!ChangeDisplaySettingsExA 7593627A 5 Bytes JMP 100A55F8 c:\progra~1\agnitum\outpos~1\wl_hook.dll .text C:\Windows\system32\svchost.exe[1532] user32.dll!ChangeDisplaySettingsExW 7595FA39 5 Bytes JMP 100A5624 c:\progra~1\agnitum\outpos~1\wl_hook.dll .text C:\Program Files\Trusteer\Rapport\bin\RapportMgmtService.exe[1600] ntdll.dll!KiUserApcDispatcher 77C56F98 5 Bytes JMP 00E8B6D0 C:\Program Files\Trusteer\Rapport\bin\RapportMgmtService.exe .text C:\Program Files\Trusteer\Rapport\bin\RapportMgmtService.exe[1600] WS2_32.dll!getaddrinfo 75584296 5 Bytes JMP 71A50022 .text C:\Program Files\Trusteer\Rapport\bin\RapportMgmtService.exe[1600] WS2_32.dll!gethostbyname 75597673 5 Bytes JMP 71AE0022 .text C:\Windows\system32\Ati2evxx.exe[1736] USER32.dll!SetForegroundWindow 7591B225 5 Bytes JMP 100A5574 c:\progra~1\agnitum\outpos~1\wl_hook.dll .text C:\Windows\system32\Ati2evxx.exe[1736] USER32.dll!SetWindowPos 75921BC4 5 Bytes JMP 100A55A0 c:\progra~1\agnitum\outpos~1\wl_hook.dll .text C:\Windows\system32\Ati2evxx.exe[1736] USER32.dll!ChangeDisplaySettingsExA 7593627A 5 Bytes JMP 100A55F8 c:\progra~1\agnitum\outpos~1\wl_hook.dll .text C:\Windows\system32\Ati2evxx.exe[1736] USER32.dll!ChangeDisplaySettingsExW 7595FA39 5 Bytes JMP 100A5624 c:\progra~1\agnitum\outpos~1\wl_hook.dll .text C:\Windows\System32\svchost.exe[1760] USER32.dll!SetForegroundWindow 7591B225 5 Bytes JMP 100A5574 c:\progra~1\agnitum\outpos~1\wl_hook.dll .text C:\Windows\System32\svchost.exe[1760] USER32.dll!SetWindowPos 75921BC4 5 Bytes JMP 100A55A0 c:\progra~1\agnitum\outpos~1\wl_hook.dll .text C:\Windows\System32\svchost.exe[1760] USER32.dll!ChangeDisplaySettingsExA 7593627A 5 Bytes JMP 100A55F8 c:\progra~1\agnitum\outpos~1\wl_hook.dll .text C:\Windows\System32\svchost.exe[1760] USER32.dll!ChangeDisplaySettingsExW 7595FA39 5 Bytes JMP 100A5624 c:\progra~1\agnitum\outpos~1\wl_hook.dll .text C:\Windows\System32\svchost.exe[1796] USER32.dll!SetForegroundWindow 7591B225 5 Bytes JMP 100A5574 c:\progra~1\agnitum\outpos~1\wl_hook.dll .text C:\Windows\System32\svchost.exe[1796] USER32.dll!SetWindowPos 75921BC4 5 Bytes JMP 100A55A0 c:\progra~1\agnitum\outpos~1\wl_hook.dll .text C:\Windows\System32\svchost.exe[1796] USER32.dll!ChangeDisplaySettingsExA 7593627A 5 Bytes JMP 100A55F8 c:\progra~1\agnitum\outpos~1\wl_hook.dll .text C:\Windows\System32\svchost.exe[1796] USER32.dll!ChangeDisplaySettingsExW 7595FA39 5 Bytes JMP 100A5624 c:\progra~1\agnitum\outpos~1\wl_hook.dll .text C:\Windows\system32\svchost.exe[1840] USER32.dll!SetForegroundWindow 7591B225 5 Bytes JMP 100A5574 c:\progra~1\agnitum\outpos~1\wl_hook.dll .text C:\Windows\system32\svchost.exe[1840] USER32.dll!SetWindowPos 75921BC4 5 Bytes JMP 100A55A0 c:\progra~1\agnitum\outpos~1\wl_hook.dll .text C:\Windows\system32\svchost.exe[1840] USER32.dll!ChangeDisplaySettingsExA 7593627A 5 Bytes JMP 100A55F8 c:\progra~1\agnitum\outpos~1\wl_hook.dll .text C:\Windows\system32\svchost.exe[1840] USER32.dll!ChangeDisplaySettingsExW 7595FA39 5 Bytes JMP 100A5624 c:\progra~1\agnitum\outpos~1\wl_hook.dll .text C:\Windows\system32\svchost.exe[1872] USER32.dll!SetForegroundWindow 7591B225 5 Bytes JMP 100A5574 c:\progra~1\agnitum\outpos~1\wl_hook.dll .text C:\Windows\system32\svchost.exe[1872] USER32.dll!SetWindowPos 75921BC4 5 Bytes JMP 100A55A0 c:\progra~1\agnitum\outpos~1\wl_hook.dll .text C:\Windows\system32\svchost.exe[1872] USER32.dll!ChangeDisplaySettingsExA 7593627A 5 Bytes JMP 100A55F8 c:\progra~1\agnitum\outpos~1\wl_hook.dll .text C:\Windows\system32\svchost.exe[1872] USER32.dll!ChangeDisplaySettingsExW 7595FA39 5 Bytes JMP 100A5624 c:\progra~1\agnitum\outpos~1\wl_hook.dll .text C:\Windows\system32\SnippingTool.exe[2052] USER32.dll!SetForegroundWindow 7591B225 5 Bytes JMP 100A5574 c:\progra~1\agnitum\outpos~1\wl_hook.dll .text C:\Windows\system32\SnippingTool.exe[2052] USER32.dll!SetWindowPos 75921BC4 5 Bytes JMP 100A55A0 c:\progra~1\agnitum\outpos~1\wl_hook.dll .text C:\Windows\system32\SnippingTool.exe[2052] USER32.dll!ChangeDisplaySettingsExA 7593627A 5 Bytes JMP 100A55F8 c:\progra~1\agnitum\outpos~1\wl_hook.dll .text C:\Windows\system32\SnippingTool.exe[2052] USER32.dll!ChangeDisplaySettingsExW 7595FA39 5 Bytes JMP 100A5624 c:\progra~1\agnitum\outpos~1\wl_hook.dll .text C:\Windows\system32\svchost.exe[2072] USER32.dll!SetForegroundWindow 7591B225 5 Bytes JMP 100A5574 c:\progra~1\agnitum\outpos~1\wl_hook.dll .text C:\Windows\system32\svchost.exe[2072] USER32.dll!SetWindowPos 75921BC4 5 Bytes JMP 100A55A0 c:\progra~1\agnitum\outpos~1\wl_hook.dll .text C:\Windows\system32\svchost.exe[2072] USER32.dll!ChangeDisplaySettingsExA 7593627A 5 Bytes JMP 100A55F8 c:\progra~1\agnitum\outpos~1\wl_hook.dll .text C:\Windows\system32\svchost.exe[2072] USER32.dll!ChangeDisplaySettingsExW 7595FA39 5 Bytes JMP 100A5624 c:\progra~1\agnitum\outpos~1\wl_hook.dll ? C:\Program Files\Kaspersky Lab\Kaspersky Security Scan 2.0\kss.exe[2088] C:\Windows\SYSTEM32\ntdll.dll time/date stamp mismatch; .text C:\Program Files\Kaspersky Lab\Kaspersky Security Scan 2.0\kss.exe[2088] ntdll.dll!NtProtectVirtualMemory 77C55F58 5 Bytes JMP 698F1986 C:\Program Files\Kaspersky Lab\Kaspersky Security Scan 2.0\ushata.dll ? C:\Program Files\Kaspersky Lab\Kaspersky Security Scan 2.0\kss.exe[2088] C:\Windows\system32\kernel32.dll time/date stamp mismatch; unknown module: KERNELBASE.dll .text C:\Program Files\Kaspersky Lab\Kaspersky Security Scan 2.0\kss.exe[2088] user32.dll!SetForegroundWindow 7591B225 5 Bytes JMP 100A5574 c:\progra~1\agnitum\outpos~1\wl_hook.dll .text C:\Program Files\Kaspersky Lab\Kaspersky Security Scan 2.0\kss.exe[2088] user32.dll!SetWindowPos 75921BC4 5 Bytes JMP 100A55A0 c:\progra~1\agnitum\outpos~1\wl_hook.dll .text C:\Program Files\Kaspersky Lab\Kaspersky Security Scan 2.0\kss.exe[2088] user32.dll!NotifyWinEvent + 6AE 7592D66C 4 Bytes [F0, 28, 8F, 69] .text C:\Program Files\Kaspersky Lab\Kaspersky Security Scan 2.0\kss.exe[2088] user32.dll!ChangeDisplaySettingsExA 7593627A 5 Bytes JMP 100A55F8 c:\progra~1\agnitum\outpos~1\wl_hook.dll .text C:\Program Files\Kaspersky Lab\Kaspersky Security Scan 2.0\kss.exe[2088] user32.dll!ChangeDisplaySettingsExW 7595FA39 5 Bytes JMP 100A5624 c:\progra~1\agnitum\outpos~1\wl_hook.dll .text C:\PROGRA~1\Agnitum\OUTPOS~1\acs.exe[2120] kernel32.dll!SetUnhandledExceptionFilter 7576F4EB 5 Bytes JMP 005ECE00 C:\PROGRA~1\Agnitum\OUTPOS~1\acs.exe .text C:\PROGRA~1\Agnitum\OUTPOS~1\acs.exe[2120] USER32.dll!SetForegroundWindow 7591B225 5 Bytes JMP 100A5574 c:\progra~1\agnitum\outpos~1\wl_hook.dll .text C:\PROGRA~1\Agnitum\OUTPOS~1\acs.exe[2120] USER32.dll!SetWindowPos 75921BC4 5 Bytes JMP 100A55A0 c:\progra~1\agnitum\outpos~1\wl_hook.dll .text C:\PROGRA~1\Agnitum\OUTPOS~1\acs.exe[2120] USER32.dll!ChangeDisplaySettingsExA 7593627A 5 Bytes JMP 100A55F8 c:\progra~1\agnitum\outpos~1\wl_hook.dll .text C:\PROGRA~1\Agnitum\OUTPOS~1\acs.exe[2120] USER32.dll!ChangeDisplaySettingsExW 7595FA39 5 Bytes JMP 100A5624 c:\progra~1\agnitum\outpos~1\wl_hook.dll .text C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe[2144] USER32.dll!SetForegroundWindow 7591B225 5 Bytes JMP 100A5574 c:\progra~1\agnitum\outpos~1\wl_hook.dll .text C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe[2144] USER32.dll!SetWindowPos 75921BC4 5 Bytes JMP 100A55A0 c:\progra~1\agnitum\outpos~1\wl_hook.dll .text C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe[2144] USER32.dll!ChangeDisplaySettingsExA 7593627A 5 Bytes JMP 100A55F8 c:\progra~1\agnitum\outpos~1\wl_hook.dll .text C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe[2144] USER32.dll!ChangeDisplaySettingsExW 7595FA39 5 Bytes JMP 100A5624 c:\progra~1\agnitum\outpos~1\wl_hook.dll .text C:\Windows\system32\agrsmsvc.exe[2164] USER32.dll!SetForegroundWindow 7591B225 5 Bytes JMP 100A5574 c:\progra~1\agnitum\outpos~1\wl_hook.dll .text C:\Windows\system32\agrsmsvc.exe[2164] USER32.dll!SetWindowPos 75921BC4 5 Bytes JMP 100A55A0 c:\progra~1\agnitum\outpos~1\wl_hook.dll .text C:\Windows\system32\agrsmsvc.exe[2164] USER32.dll!ChangeDisplaySettingsExA 7593627A 5 Bytes JMP 100A55F8 c:\progra~1\agnitum\outpos~1\wl_hook.dll .text C:\Windows\system32\agrsmsvc.exe[2164] USER32.dll!ChangeDisplaySettingsExW 7595FA39 5 Bytes JMP 100A5624 c:\progra~1\agnitum\outpos~1\wl_hook.dll .text C:\Program Files\AVG\AVG2014\avgidsagent.exe[2188] USER32.dll!SetForegroundWindow 7591B225 5 Bytes JMP 100A5574 c:\progra~1\agnitum\outpos~1\wl_hook.dll .text C:\Program Files\AVG\AVG2014\avgidsagent.exe[2188] USER32.dll!SetWindowPos 75921BC4 5 Bytes JMP 100A55A0 c:\progra~1\agnitum\outpos~1\wl_hook.dll .text C:\Program Files\AVG\AVG2014\avgidsagent.exe[2188] USER32.dll!ChangeDisplaySettingsExA 7593627A 5 Bytes JMP 100A55F8 c:\progra~1\agnitum\outpos~1\wl_hook.dll .text C:\Program Files\AVG\AVG2014\avgidsagent.exe[2188] USER32.dll!ChangeDisplaySettingsExW 7595FA39 5 Bytes JMP 100A5624 c:\progra~1\agnitum\outpos~1\wl_hook.dll .text C:\Program Files\AVG\AVG2014\avgwdsvc.exe[2208] USER32.dll!SetForegroundWindow 7591B225 5 Bytes JMP 100A5574 c:\progra~1\agnitum\outpos~1\wl_hook.dll .text C:\Program Files\AVG\AVG2014\avgwdsvc.exe[2208] USER32.dll!SetWindowPos 75921BC4 5 Bytes JMP 100A55A0 c:\progra~1\agnitum\outpos~1\wl_hook.dll .text C:\Program Files\AVG\AVG2014\avgwdsvc.exe[2208] USER32.dll!ChangeDisplaySettingsExA 7593627A 5 Bytes JMP 100A55F8 c:\progra~1\agnitum\outpos~1\wl_hook.dll .text C:\Program Files\AVG\AVG2014\avgwdsvc.exe[2208] USER32.dll!ChangeDisplaySettingsExW 7595FA39 5 Bytes JMP 100A5624 c:\progra~1\agnitum\outpos~1\wl_hook.dll .text C:\Windows\system32\svchost.exe[2276] USER32.dll!SetForegroundWindow 7591B225 5 Bytes JMP 100A5574 c:\progra~1\agnitum\outpos~1\wl_hook.dll .text C:\Windows\system32\svchost.exe[2276] USER32.dll!SetWindowPos 75921BC4 5 Bytes JMP 100A55A0 c:\progra~1\agnitum\outpos~1\wl_hook.dll .text C:\Windows\system32\svchost.exe[2276] USER32.dll!ChangeDisplaySettingsExA 7593627A 5 Bytes JMP 100A55F8 c:\progra~1\agnitum\outpos~1\wl_hook.dll .text C:\Windows\system32\svchost.exe[2276] USER32.dll!ChangeDisplaySettingsExW 7595FA39 5 Bytes JMP 100A5624 c:\progra~1\agnitum\outpos~1\wl_hook.dll .text C:\Program Files\ICBCEbankTools\ICBCAntiPhishing\ICBC_WIN32\IcbcDaemon.exe[2324] USER32.dll!SetForegroundWindow 7591B225 5 Bytes JMP 100A5574 c:\progra~1\agnitum\outpos~1\wl_hook.dll .text C:\Program Files\ICBCEbankTools\ICBCAntiPhishing\ICBC_WIN32\IcbcDaemon.exe[2324] USER32.dll!SetWindowPos 75921BC4 5 Bytes JMP 100A55A0 c:\progra~1\agnitum\outpos~1\wl_hook.dll .text C:\Program Files\ICBCEbankTools\ICBCAntiPhishing\ICBC_WIN32\IcbcDaemon.exe[2324] USER32.dll!ChangeDisplaySettingsExA 7593627A 5 Bytes JMP 100A55F8 c:\progra~1\agnitum\outpos~1\wl_hook.dll .text C:\Program Files\ICBCEbankTools\ICBCAntiPhishing\ICBC_WIN32\IcbcDaemon.exe[2324] USER32.dll!ChangeDisplaySettingsExW 7595FA39 5 Bytes JMP 100A5624 c:\progra~1\agnitum\outpos~1\wl_hook.dll .text C:\Program Files\AVG\AVG2014\avgui.exe[2360] USER32.dll!SetForegroundWindow 7591B225 5 Bytes JMP 100A5574 c:\progra~1\agnitum\outpos~1\wl_hook.dll .text C:\Program Files\AVG\AVG2014\avgui.exe[2360] USER32.dll!SetWindowPos 75921BC4 5 Bytes JMP 100A55A0 c:\progra~1\agnitum\outpos~1\wl_hook.dll .text C:\Program Files\AVG\AVG2014\avgui.exe[2360] USER32.dll!ChangeDisplaySettingsExA 7593627A 5 Bytes JMP 100A55F8 c:\progra~1\agnitum\outpos~1\wl_hook.dll .text C:\Program Files\AVG\AVG2014\avgui.exe[2360] USER32.dll!ChangeDisplaySettingsExW 7595FA39 5 Bytes JMP 100A5624 c:\progra~1\agnitum\outpos~1\wl_hook.dll .text C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindServiceAE.exe[2452] USER32.dll!SetForegroundWindow 7591B225 5 Bytes JMP 100A5574 c:\progra~1\agnitum\outpos~1\wl_hook.dll .text C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindServiceAE.exe[2452] USER32.dll!SetWindowPos 75921BC4 5 Bytes JMP 100A55A0 c:\progra~1\agnitum\outpos~1\wl_hook.dll .text C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindServiceAE.exe[2452] USER32.dll!ChangeDisplaySettingsExA 7593627A 5 Bytes JMP 100A55F8 c:\progra~1\agnitum\outpos~1\wl_hook.dll .text C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindServiceAE.exe[2452] USER32.dll!ChangeDisplaySettingsExW 7595FA39 5 Bytes JMP 100A5624 c:\progra~1\agnitum\outpos~1\wl_hook.dll .text C:\Windows\system32\svchost.exe[2496] USER32.dll!SetForegroundWindow 7591B225 5 Bytes JMP 100A5574 c:\progra~1\agnitum\outpos~1\wl_hook.dll .text C:\Windows\system32\svchost.exe[2496] USER32.dll!SetWindowPos 75921BC4 5 Bytes JMP 100A55A0 c:\progra~1\agnitum\outpos~1\wl_hook.dll .text C:\Windows\system32\svchost.exe[2496] USER32.dll!ChangeDisplaySettingsExA 7593627A 5 Bytes JMP 100A55F8 c:\progra~1\agnitum\outpos~1\wl_hook.dll .text C:\Windows\system32\svchost.exe[2496] USER32.dll!ChangeDisplaySettingsExW 7595FA39 5 Bytes JMP 100A5624 c:\progra~1\agnitum\outpos~1\wl_hook.dll .text C:\Program Files\Logitech\SetPointP\SetPoint.exe[2716] USER32.dll!SetForegroundWindow 7591B225 5 Bytes JMP 007B5574 c:\progra~1\agnitum\outpos~1\wl_hook.dll .text C:\Program Files\Logitech\SetPointP\SetPoint.exe[2716] USER32.dll!SetWindowPos 75921BC4 5 Bytes JMP 007B55A0 c:\progra~1\agnitum\outpos~1\wl_hook.dll .text C:\Program Files\Logitech\SetPointP\SetPoint.exe[2716] USER32.dll!ChangeDisplaySettingsExA 7593627A 5 Bytes JMP 007B55F8 c:\progra~1\agnitum\outpos~1\wl_hook.dll .text C:\Program Files\Logitech\SetPointP\SetPoint.exe[2716] USER32.dll!ChangeDisplaySettingsExW 7595FA39 5 Bytes JMP 007B5624 c:\progra~1\agnitum\outpos~1\wl_hook.dll .text C:\Program Files\Common Files\LogiShrd\KHAL3\KHALMNPR.EXE[2736] USER32.dll!SetForegroundWindow 7591B225 5 Bytes JMP 100A5574 c:\progra~1\agnitum\outpos~1\wl_hook.dll .text C:\Program Files\Common Files\LogiShrd\KHAL3\KHALMNPR.EXE[2736] USER32.dll!SetWindowPos 75921BC4 5 Bytes JMP 100A55A0 c:\progra~1\agnitum\outpos~1\wl_hook.dll .text C:\Program Files\Common Files\LogiShrd\KHAL3\KHALMNPR.EXE[2736] USER32.dll!ChangeDisplaySettingsExA 7593627A 5 Bytes JMP 100A55F8 c:\progra~1\agnitum\outpos~1\wl_hook.dll .text C:\Program Files\Common Files\LogiShrd\KHAL3\KHALMNPR.EXE[2736] USER32.dll!ChangeDisplaySettingsExW 7595FA39 5 Bytes JMP 100A5624 c:\progra~1\agnitum\outpos~1\wl_hook.dll .text C:\Windows\system32\taskhost.exe[2844] USER32.dll!SetForegroundWindow 7591B225 5 Bytes JMP 100A5574 c:\progra~1\agnitum\outpos~1\wl_hook.dll .text C:\Windows\system32\taskhost.exe[2844] USER32.dll!SetWindowPos 75921BC4 5 Bytes JMP 100A55A0 c:\progra~1\agnitum\outpos~1\wl_hook.dll .text C:\Windows\system32\taskhost.exe[2844] USER32.dll!ChangeDisplaySettingsExA 7593627A 5 Bytes JMP 100A55F8 c:\progra~1\agnitum\outpos~1\wl_hook.dll .text C:\Windows\system32\taskhost.exe[2844] USER32.dll!ChangeDisplaySettingsExW 7595FA39 5 Bytes JMP 100A5624 c:\progra~1\agnitum\outpos~1\wl_hook.dll .text C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE[2908] USER32.dll!SetForegroundWindow 7591B225 5 Bytes JMP 100A5574 c:\progra~1\agnitum\outpos~1\wl_hook.dll .text C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE[2908] USER32.dll!SetWindowPos 75921BC4 5 Bytes JMP 100A55A0 c:\progra~1\agnitum\outpos~1\wl_hook.dll .text C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE[2908] USER32.dll!ChangeDisplaySettingsExA 7593627A 5 Bytes JMP 100A55F8 c:\progra~1\agnitum\outpos~1\wl_hook.dll .text C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE[2908] USER32.dll!ChangeDisplaySettingsExW 7595FA39 5 Bytes JMP 100A5624 c:\progra~1\agnitum\outpos~1\wl_hook.dll .text C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE[2908] ole32.dll!OleLoadFromStream 755C6143 5 Bytes JMP 5F5B44C3 C:\Program Files\Common Files\Microsoft Shared\office11\mso.dll .text C:\Program Files\Synaptics\SynTP\SynToshiba.exe[2940] USER32.dll!SetForegroundWindow 7591B225 5 Bytes JMP 100A5574 c:\progra~1\agnitum\outpos~1\wl_hook.dll .text C:\Program Files\Synaptics\SynTP\SynToshiba.exe[2940] USER32.dll!SetWindowPos 75921BC4 5 Bytes JMP 100A55A0 c:\progra~1\agnitum\outpos~1\wl_hook.dll .text C:\Program Files\Synaptics\SynTP\SynToshiba.exe[2940] USER32.dll!ChangeDisplaySettingsExA 7593627A 5 Bytes JMP 100A55F8 c:\progra~1\agnitum\outpos~1\wl_hook.dll .text C:\Program Files\Synaptics\SynTP\SynToshiba.exe[2940] USER32.dll!ChangeDisplaySettingsExW 7595FA39 5 Bytes JMP 100A5624 c:\progra~1\agnitum\outpos~1\wl_hook.dll .text C:\Program Files\Canon\IJ Network Scanner Selector EX\CNMNSST.exe[3004] USER32.dll!SetForegroundWindow 7591B225 5 Bytes JMP 100A5574 c:\progra~1\agnitum\outpos~1\wl_hook.dll .text C:\Program Files\Canon\IJ Network Scanner Selector EX\CNMNSST.exe[3004] USER32.dll!SetWindowPos 75921BC4 5 Bytes JMP 100A55A0 c:\progra~1\agnitum\outpos~1\wl_hook.dll .text C:\Program Files\Canon\IJ Network Scanner Selector EX\CNMNSST.exe[3004] USER32.dll!ChangeDisplaySettingsExA 7593627A 5 Bytes JMP 100A55F8 c:\progra~1\agnitum\outpos~1\wl_hook.dll .text C:\Program Files\Canon\IJ Network Scanner Selector EX\CNMNSST.exe[3004] USER32.dll!ChangeDisplaySettingsExW 7595FA39 5 Bytes JMP 100A5624 c:\progra~1\agnitum\outpos~1\wl_hook.dll .text C:\Windows\System32\hhukcert02.exe[3016] USER32.dll!SetForegroundWindow 7591B225 5 Bytes JMP 100A5574 c:\progra~1\agnitum\outpos~1\wl_hook.dll .text C:\Windows\System32\hhukcert02.exe[3016] USER32.dll!SetWindowPos 75921BC4 5 Bytes JMP 100A55A0 c:\progra~1\agnitum\outpos~1\wl_hook.dll .text C:\Windows\System32\hhukcert02.exe[3016] USER32.dll!ChangeDisplaySettingsExA 7593627A 5 Bytes JMP 100A55F8 c:\progra~1\agnitum\outpos~1\wl_hook.dll .text C:\Windows\System32\hhukcert02.exe[3016] USER32.dll!ChangeDisplaySettingsExW 7595FA39 5 Bytes JMP 100A5624 c:\progra~1\agnitum\outpos~1\wl_hook.dll .text C:\Windows\System32\rundll32.exe[3024] USER32.dll!SetForegroundWindow 7591B225 5 Bytes JMP 100A5574 c:\progra~1\agnitum\outpos~1\wl_hook.dll .text C:\Windows\System32\rundll32.exe[3024] USER32.dll!SetWindowPos 75921BC4 5 Bytes JMP 100A55A0 c:\progra~1\agnitum\outpos~1\wl_hook.dll .text C:\Windows\System32\rundll32.exe[3024] USER32.dll!ChangeDisplaySettingsExA 7593627A 5 Bytes JMP 100A55F8 c:\progra~1\agnitum\outpos~1\wl_hook.dll .text C:\Windows\System32\rundll32.exe[3024] USER32.dll!ChangeDisplaySettingsExW 7595FA39 5 Bytes JMP 100A5624 c:\progra~1\agnitum\outpos~1\wl_hook.dll .text C:\PROGRAM FILES\SYNAPTICS\SYNTP\SYNTPHELPER.EXE[3052] USER32.dll!SetForegroundWindow 7591B225 5 Bytes JMP 100A5574 c:\progra~1\agnitum\outpos~1\wl_hook.dll .text C:\PROGRAM FILES\SYNAPTICS\SYNTP\SYNTPHELPER.EXE[3052] USER32.dll!SetWindowPos 75921BC4 5 Bytes JMP 100A55A0 c:\progra~1\agnitum\outpos~1\wl_hook.dll .text C:\PROGRAM FILES\SYNAPTICS\SYNTP\SYNTPHELPER.EXE[3052] USER32.dll!ChangeDisplaySettingsExA 7593627A 5 Bytes JMP 100A55F8 c:\progra~1\agnitum\outpos~1\wl_hook.dll .text C:\PROGRAM FILES\SYNAPTICS\SYNTP\SYNTPHELPER.EXE[3052] USER32.dll!ChangeDisplaySettingsExW 7595FA39 5 Bytes JMP 100A5624 c:\progra~1\agnitum\outpos~1\wl_hook.dll .text C:\Program Files\Google\Update\1.3.22.3\GoogleCrashHandler.exe[3148] USER32.dll!SetForegroundWindow 7591B225 5 Bytes JMP 100A5574 c:\progra~1\agnitum\outpos~1\wl_hook.dll .text C:\Program Files\Google\Update\1.3.22.3\GoogleCrashHandler.exe[3148] USER32.dll!SetWindowPos 75921BC4 5 Bytes JMP 100A55A0 c:\progra~1\agnitum\outpos~1\wl_hook.dll .text C:\Program Files\Google\Update\1.3.22.3\GoogleCrashHandler.exe[3148] USER32.dll!ChangeDisplaySettingsExA 7593627A 5 Bytes JMP 100A55F8 c:\progra~1\agnitum\outpos~1\wl_hook.dll .text C:\Program Files\Google\Update\1.3.22.3\GoogleCrashHandler.exe[3148] USER32.dll!ChangeDisplaySettingsExW 7595FA39 5 Bytes JMP 100A5624 c:\progra~1\agnitum\outpos~1\wl_hook.dll .text C:\Program Files\Trusteer\Rapport\bin\RapportService.exe[3160] ntdll.dll!KiUserApcDispatcher 77C56F98 5 Bytes JMP 00AAC8B0 C:\Program Files\Trusteer\Rapport\bin\RapportService.exe .text C:\Program Files\Trusteer\Rapport\bin\RapportService.exe[3160] WS2_32.dll!getaddrinfo 75584296 5 Bytes JMP 71A20022 .text C:\Program Files\Trusteer\Rapport\bin\RapportService.exe[3160] WS2_32.dll!gethostbyname 75597673 5 Bytes JMP 71A60022 .text C:\Program Files\Trusteer\Rapport\bin\RapportService.exe[3160] USER32.dll!PostThreadMessageW + 80 7591EF7C 6 Bytes JMP 71AE001E .text C:\Program Files\Realtek\Audio\HDA\RtHDVCpl.exe[3216] USER32.dll!SetForegroundWindow 7591B225 5 Bytes JMP 100A5574 c:\progra~1\agnitum\outpos~1\wl_hook.dll .text C:\Program Files\Realtek\Audio\HDA\RtHDVCpl.exe[3216] USER32.dll!SetWindowPos 75921BC4 5 Bytes JMP 100A55A0 c:\progra~1\agnitum\outpos~1\wl_hook.dll .text C:\Program Files\Realtek\Audio\HDA\RtHDVCpl.exe[3216] USER32.dll!ChangeDisplaySettingsExA 7593627A 5 Bytes JMP 100A55F8 c:\progra~1\agnitum\outpos~1\wl_hook.dll .text C:\Program Files\Realtek\Audio\HDA\RtHDVCpl.exe[3216] USER32.dll!ChangeDisplaySettingsExW 7595FA39 5 Bytes JMP 100A5624 c:\progra~1\agnitum\outpos~1\wl_hook.dll .text C:\Windows\system32\taskeng.exe[3460] USER32.dll!SetForegroundWindow 7591B225 5 Bytes JMP 100A5574 c:\progra~1\agnitum\outpos~1\wl_hook.dll .text C:\Windows\system32\taskeng.exe[3460] USER32.dll!SetWindowPos 75921BC4 5 Bytes JMP 100A55A0 c:\progra~1\agnitum\outpos~1\wl_hook.dll .text C:\Windows\system32\taskeng.exe[3460] USER32.dll!ChangeDisplaySettingsExA 7593627A 5 Bytes JMP 100A55F8 c:\progra~1\agnitum\outpos~1\wl_hook.dll .text C:\Windows\system32\taskeng.exe[3460] USER32.dll!ChangeDisplaySettingsExW 7595FA39 5 Bytes JMP 100A5624 c:\progra~1\agnitum\outpos~1\wl_hook.dll .text C:\Program Files\Renesas Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe[3468] USER32.dll!SetForegroundWindow 7591B225 5 Bytes JMP 004C5574 c:\progra~1\agnitum\outpos~1\wl_hook.dll .text C:\Program Files\Renesas Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe[3468] USER32.dll!SetWindowPos 75921BC4 5 Bytes JMP 004C55A0 c:\progra~1\agnitum\outpos~1\wl_hook.dll .text C:\Program Files\Renesas Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe[3468] USER32.dll!ChangeDisplaySettingsExA 7593627A 5 Bytes JMP 004C55F8 c:\progra~1\agnitum\outpos~1\wl_hook.dll .text C:\Program Files\Renesas Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe[3468] USER32.dll!ChangeDisplaySettingsExW 7595FA39 5 Bytes JMP 004C5624 c:\progra~1\agnitum\outpos~1\wl_hook.dll .text C:\Windows\system32\Dwm.exe[3560] USER32.dll!SetForegroundWindow 7591B225 5 Bytes JMP 100A5574 c:\progra~1\agnitum\outpos~1\wl_hook.dll .text C:\Windows\system32\Dwm.exe[3560] USER32.dll!SetWindowPos 75921BC4 5 Bytes JMP 100A55A0 c:\progra~1\agnitum\outpos~1\wl_hook.dll .text C:\Windows\system32\Dwm.exe[3560] USER32.dll!ChangeDisplaySettingsExA 7593627A 5 Bytes JMP 100A55F8 c:\progra~1\agnitum\outpos~1\wl_hook.dll .text C:\Windows\system32\Dwm.exe[3560] USER32.dll!ChangeDisplaySettingsExW 7595FA39 5 Bytes JMP 100A5624 c:\progra~1\agnitum\outpos~1\wl_hook.dll .text C:\Windows\Explorer.EXE[3580] USER32.dll!SetForegroundWindow 7591B225 5 Bytes JMP 100A5574 c:\progra~1\agnitum\outpos~1\wl_hook.dll .text C:\Windows\Explorer.EXE[3580] USER32.dll!SetWindowPos 75921BC4 5 Bytes JMP 100A55A0 c:\progra~1\agnitum\outpos~1\wl_hook.dll .text C:\Windows\Explorer.EXE[3580] USER32.dll!ChangeDisplaySettingsExA 7593627A 5 Bytes JMP 100A55F8 c:\progra~1\agnitum\outpos~1\wl_hook.dll .text C:\Windows\Explorer.EXE[3580] USER32.dll!ChangeDisplaySettingsExW 7595FA39 5 Bytes JMP 100A5624 c:\progra~1\agnitum\outpos~1\wl_hook.dll .text C:\Windows\Explorer.EXE[3580] SHLWAPI.dll!SHStripMneumonicA + 4D 771522DA 5 Bytes JMP 06D70470 C:\Program Files\MyDrivers\DriverGenius2013\dghmpg.dll .text C:\Windows\Explorer.EXE[3580] SHELL32.dll!SHGetItemFromDataObject + 378 75B4EBCC 4 Bytes [04, 00, 0B, 03] {ADD AL, 0x0; OR EAX, [EBX]} .text C:\Windows\Explorer.EXE[3580] SHELL32.dll!PathIsExe + 1BF7 75B5DD8C 4 Bytes [04, 00, 07, 03] .text C:\Windows\system32\WUDFHost.exe[3668] USER32.dll!SetForegroundWindow 7591B225 5 Bytes JMP 100A5574 c:\progra~1\agnitum\outpos~1\wl_hook.dll .text C:\Windows\system32\WUDFHost.exe[3668] USER32.dll!SetWindowPos 75921BC4 5 Bytes JMP 100A55A0 c:\progra~1\agnitum\outpos~1\wl_hook.dll .text C:\Windows\system32\WUDFHost.exe[3668] USER32.dll!ChangeDisplaySettingsExA 7593627A 5 Bytes JMP 100A55F8 c:\progra~1\agnitum\outpos~1\wl_hook.dll .text C:\Windows\system32\WUDFHost.exe[3668] USER32.dll!ChangeDisplaySettingsExW 7595FA39 5 Bytes JMP 100A5624 c:\progra~1\agnitum\outpos~1\wl_hook.dll .text C:\Program Files\Renesas Electronics\USB 3.0 Host Controller Driver\Application\rusb3mon.exe[3696] USER32.dll!SetForegroundWindow 7591B225 5 Bytes JMP 012A5574 c:\progra~1\agnitum\outpos~1\wl_hook.dll .text C:\Program Files\Renesas Electronics\USB 3.0 Host Controller Driver\Application\rusb3mon.exe[3696] USER32.dll!SetWindowPos 75921BC4 5 Bytes JMP 012A55A0 c:\progra~1\agnitum\outpos~1\wl_hook.dll .text C:\Program Files\Renesas Electronics\USB 3.0 Host Controller Driver\Application\rusb3mon.exe[3696] USER32.dll!ChangeDisplaySettingsExA 7593627A 5 Bytes JMP 012A55F8 c:\progra~1\agnitum\outpos~1\wl_hook.dll .text C:\Program Files\Renesas Electronics\USB 3.0 Host Controller Driver\Application\rusb3mon.exe[3696] USER32.dll!ChangeDisplaySettingsExW 7595FA39 5 Bytes JMP 012A5624 c:\progra~1\agnitum\outpos~1\wl_hook.dll .text C:\Program Files\AVG\AVG2014\avgnsx.exe[3728] USER32.dll!SetForegroundWindow 7591B225 5 Bytes JMP 100A5574 c:\progra~1\agnitum\outpos~1\wl_hook.dll .text C:\Program Files\AVG\AVG2014\avgnsx.exe[3728] USER32.dll!SetWindowPos 75921BC4 5 Bytes JMP 100A55A0 c:\progra~1\agnitum\outpos~1\wl_hook.dll .text C:\Program Files\AVG\AVG2014\avgnsx.exe[3728] USER32.dll!ChangeDisplaySettingsExA 7593627A 5 Bytes JMP 100A55F8 c:\progra~1\agnitum\outpos~1\wl_hook.dll .text C:\Program Files\AVG\AVG2014\avgnsx.exe[3728] USER32.dll!ChangeDisplaySettingsExW 7595FA39 5 Bytes JMP 100A5624 c:\progra~1\agnitum\outpos~1\wl_hook.dll .text C:\Program Files\Common Files\Java\Java Update\jusched.exe[3944] USER32.dll!SetForegroundWindow 7591B225 5 Bytes JMP 100A5574 c:\progra~1\agnitum\outpos~1\wl_hook.dll .text C:\Program Files\Common Files\Java\Java Update\jusched.exe[3944] USER32.dll!SetWindowPos 75921BC4 5 Bytes JMP 100A55A0 c:\progra~1\agnitum\outpos~1\wl_hook.dll .text C:\Program Files\Common Files\Java\Java Update\jusched.exe[3944] USER32.dll!ChangeDisplaySettingsExA 7593627A 5 Bytes JMP 100A55F8 c:\progra~1\agnitum\outpos~1\wl_hook.dll .text C:\Program Files\Common Files\Java\Java Update\jusched.exe[3944] USER32.dll!ChangeDisplaySettingsExW 7595FA39 5 Bytes JMP 100A5624 c:\progra~1\agnitum\outpos~1\wl_hook.dll .text C:\Program Files\TOSHIBA\Power Saver\TPwrMain.exe[4020] USER32.dll!SetForegroundWindow 7591B225 5 Bytes JMP 005F5574 c:\progra~1\agnitum\outpos~1\wl_hook.dll .text C:\Program Files\TOSHIBA\Power Saver\TPwrMain.exe[4020] USER32.dll!SetWindowPos 75921BC4 5 Bytes JMP 005F55A0 c:\progra~1\agnitum\outpos~1\wl_hook.dll .text C:\Program Files\TOSHIBA\Power Saver\TPwrMain.exe[4020] USER32.dll!ChangeDisplaySettingsExA 7593627A 5 Bytes JMP 005F55F8 c:\progra~1\agnitum\outpos~1\wl_hook.dll .text C:\Program Files\TOSHIBA\Power Saver\TPwrMain.exe[4020] USER32.dll!ChangeDisplaySettingsExW 7595FA39 5 Bytes JMP 005F5624 c:\progra~1\agnitum\outpos~1\wl_hook.dll .text C:\Program Files\Skype\Phone\Skype.exe[4032] USER32.dll!SetForegroundWindow 7591B225 5 Bytes JMP 100A5574 c:\progra~1\agnitum\outpos~1\wl_hook.dll .text C:\Program Files\Skype\Phone\Skype.exe[4032] USER32.dll!SetWindowPos 75921BC4 5 Bytes JMP 100A55A0 c:\progra~1\agnitum\outpos~1\wl_hook.dll .text C:\Program Files\Skype\Phone\Skype.exe[4032] USER32.dll!ChangeDisplaySettingsExA 7593627A 5 Bytes JMP 100A55F8 c:\progra~1\agnitum\outpos~1\wl_hook.dll .text C:\Program Files\Skype\Phone\Skype.exe[4032] USER32.dll!ChangeDisplaySettingsExW 7595FA39 5 Bytes JMP 100A5624 c:\progra~1\agnitum\outpos~1\wl_hook.dll .text C:\Program Files\TOSHIBA\SmoothView\SmoothView.exe[4040] USER32.dll!SetForegroundWindow 7591B225 5 Bytes JMP 100A5574 c:\progra~1\agnitum\outpos~1\wl_hook.dll .text C:\Program Files\TOSHIBA\SmoothView\SmoothView.exe[4040] USER32.dll!SetWindowPos 75921BC4 5 Bytes JMP 100A55A0 c:\progra~1\agnitum\outpos~1\wl_hook.dll .text C:\Program Files\TOSHIBA\SmoothView\SmoothView.exe[4040] USER32.dll!ChangeDisplaySettingsExA 7593627A 5 Bytes JMP 100A55F8 c:\progra~1\agnitum\outpos~1\wl_hook.dll .text C:\Program Files\TOSHIBA\SmoothView\SmoothView.exe[4040] USER32.dll!ChangeDisplaySettingsExW 7595FA39 5 Bytes JMP 100A5624 c:\progra~1\agnitum\outpos~1\wl_hook.dll .text C:\Program Files\Agnitum\Outpost Firewall Pro\op_mon.exe[4084] ntdll.dll!LdrLoadDll 77C722AE 5 Bytes JMP 00614B7C C:\Program Files\Agnitum\Outpost Firewall Pro\op_mon.exe .text C:\Program Files\Agnitum\Outpost Firewall Pro\op_mon.exe[4084] kernel32.dll!SetUnhandledExceptionFilter 7576F4EB 2 Bytes JMP 00614AB8 C:\Program Files\Agnitum\Outpost Firewall Pro\op_mon.exe .text C:\Program Files\Agnitum\Outpost Firewall Pro\op_mon.exe[4084] kernel32.dll!SetUnhandledExceptionFilter + 3 7576F4EE 2 Bytes JMP 20EC818A .text C:\Program Files\Agnitum\Outpost Firewall Pro\op_mon.exe[4084] USER32.dll!EnableWindow 75918D02 5 Bytes JMP 02A17A6C C:\Program Files\Agnitum\Outpost Firewall Pro\op_cmn.dll .text C:\Program Files\Agnitum\Outpost Firewall Pro\op_mon.exe[4084] USER32.dll!SetForegroundWindow 7591B225 5 Bytes JMP 01555574 c:\progra~1\agnitum\outpos~1\wl_hook.dll .text C:\Program Files\Agnitum\Outpost Firewall Pro\op_mon.exe[4084] USER32.dll!SetWindowsHookExW 7591E30C 5 Bytes JMP 00614B50 C:\Program Files\Agnitum\Outpost Firewall Pro\op_mon.exe .text C:\Program Files\Agnitum\Outpost Firewall Pro\op_mon.exe[4084] USER32.dll!SetWindowPos 75921BC4 5 Bytes JMP 015555A0 c:\progra~1\agnitum\outpos~1\wl_hook.dll .text C:\Program Files\Agnitum\Outpost Firewall Pro\op_mon.exe[4084] USER32.dll!ChangeDisplaySettingsExA 7593627A 5 Bytes JMP 015555F8 c:\progra~1\agnitum\outpos~1\wl_hook.dll .text C:\Program Files\Agnitum\Outpost Firewall Pro\op_mon.exe[4084] USER32.dll!SetWindowsHookExA 75946D0C 5 Bytes JMP 00614B24 C:\Program Files\Agnitum\Outpost Firewall Pro\op_mon.exe .text C:\Program Files\Agnitum\Outpost Firewall Pro\op_mon.exe[4084] USER32.dll!ChangeDisplaySettingsExW 7595FA39 5 Bytes JMP 01555624 c:\progra~1\agnitum\outpos~1\wl_hook.dll .text C:\Program Files\FireTrust\MailWasher Pro\MailWasher.exe[4412] USER32.dll!SetForegroundWindow 7591B225 5 Bytes JMP 100A5574 c:\progra~1\agnitum\outpos~1\wl_hook.dll .text C:\Program Files\FireTrust\MailWasher Pro\MailWasher.exe[4412] USER32.dll!SetWindowPos 75921BC4 5 Bytes JMP 100A55A0 c:\progra~1\agnitum\outpos~1\wl_hook.dll .text C:\Program Files\FireTrust\MailWasher Pro\MailWasher.exe[4412] USER32.dll!ChangeDisplaySettingsExA 7593627A 5 Bytes JMP 100A55F8 c:\progra~1\agnitum\outpos~1\wl_hook.dll .text C:\Program Files\FireTrust\MailWasher Pro\MailWasher.exe[4412] USER32.dll!ChangeDisplaySettingsExW 7595FA39 5 Bytes JMP 100A5624 c:\progra~1\agnitum\outpos~1\wl_hook.dll .text C:\Program Files\DigiGuide TV Guide\digiguide.exe[4488] USER32.dll!SetForegroundWindow 7591B225 5 Bytes JMP 100A5574 c:\progra~1\agnitum\outpos~1\wl_hook.dll .text C:\Program Files\DigiGuide TV Guide\digiguide.exe[4488] USER32.dll!SetWindowPos 75921BC4 5 Bytes JMP 100A55A0 c:\progra~1\agnitum\outpos~1\wl_hook.dll .text C:\Program Files\DigiGuide TV Guide\digiguide.exe[4488] USER32.dll!ChangeDisplaySettingsExA 7593627A 5 Bytes JMP 100A55F8 c:\progra~1\agnitum\outpos~1\wl_hook.dll .text C:\Program Files\DigiGuide TV Guide\digiguide.exe[4488] USER32.dll!ChangeDisplaySettingsExW 7595FA39 5 Bytes JMP 100A5624 c:\progra~1\agnitum\outpos~1\wl_hook.dll .text C:\Windows\System32\svchost.exe[4704] user32.dll!SetForegroundWindow 7591B225 5 Bytes JMP 100A5574 c:\progra~1\agnitum\outpos~1\wl_hook.dll .text C:\Windows\System32\svchost.exe[4704] user32.dll!SetWindowPos 75921BC4 5 Bytes JMP 100A55A0 c:\progra~1\agnitum\outpos~1\wl_hook.dll .text C:\Windows\System32\svchost.exe[4704] user32.dll!ChangeDisplaySettingsExA 7593627A 5 Bytes JMP 100A55F8 c:\progra~1\agnitum\outpos~1\wl_hook.dll .text C:\Windows\System32\svchost.exe[4704] user32.dll!ChangeDisplaySettingsExW 7595FA39 5 Bytes JMP 100A5624 c:\progra~1\agnitum\outpos~1\wl_hook.dll .text C:\Windows\system32\taskhost.exe[4716] USER32.dll!SetForegroundWindow 7591B225 5 Bytes JMP 100A5574 c:\progra~1\agnitum\outpos~1\wl_hook.dll .text C:\Windows\system32\taskhost.exe[4716] USER32.dll!SetWindowPos 75921BC4 5 Bytes JMP 100A55A0 c:\progra~1\agnitum\outpos~1\wl_hook.dll .text C:\Windows\system32\taskhost.exe[4716] USER32.dll!ChangeDisplaySettingsExA 7593627A 5 Bytes JMP 100A55F8 c:\progra~1\agnitum\outpos~1\wl_hook.dll .text C:\Windows\system32\taskhost.exe[4716] USER32.dll!ChangeDisplaySettingsExW 7595FA39 5 Bytes JMP 100A5624 c:\progra~1\agnitum\outpos~1\wl_hook.dll .text C:\Program Files\Microsoft Office\OFFICE11\OUTLOOK.EXE[4796] USER32.dll!SetForegroundWindow 7591B225 5 Bytes JMP 100A5574 c:\progra~1\agnitum\outpos~1\wl_hook.dll .text C:\Program Files\Microsoft Office\OFFICE11\OUTLOOK.EXE[4796] USER32.dll!SetWindowPos 75921BC4 5 Bytes JMP 100A55A0 c:\progra~1\agnitum\outpos~1\wl_hook.dll .text C:\Program Files\Microsoft Office\OFFICE11\OUTLOOK.EXE[4796] USER32.dll!ChangeDisplaySettingsExA 7593627A 5 Bytes JMP 100A55F8 c:\progra~1\agnitum\outpos~1\wl_hook.dll .text C:\Program Files\Microsoft Office\OFFICE11\OUTLOOK.EXE[4796] USER32.dll!ChangeDisplaySettingsExW 7595FA39 5 Bytes JMP 100A5624 c:\progra~1\agnitum\outpos~1\wl_hook.dll .text C:\Program Files\Microsoft Office\OFFICE11\OUTLOOK.EXE[4796] ole32.dll!OleLoadFromStream 755C6143 5 Bytes JMP 5F5B44C3 C:\Program Files\Common Files\Microsoft Shared\office11\mso.dll .text C:\Program Files\Windows Media Player\wmpnetwk.exe[4964] USER32.dll!SetForegroundWindow 7591B225 5 Bytes JMP 100A5574 c:\progra~1\agnitum\outpos~1\wl_hook.dll .text C:\Program Files\Windows Media Player\wmpnetwk.exe[4964] USER32.dll!SetWindowPos 75921BC4 5 Bytes JMP 100A55A0 c:\progra~1\agnitum\outpos~1\wl_hook.dll .text C:\Program Files\Windows Media Player\wmpnetwk.exe[4964] USER32.dll!ChangeDisplaySettingsExA 7593627A 5 Bytes JMP 100A55F8 c:\progra~1\agnitum\outpos~1\wl_hook.dll .text C:\Program Files\Windows Media Player\wmpnetwk.exe[4964] USER32.dll!ChangeDisplaySettingsExW 7595FA39 5 Bytes JMP 100A5624 c:\progra~1\agnitum\outpos~1\wl_hook.dll .text C:\Program Files\Mozilla Firefox\firefox.exe[5644] ntdll.dll!NtMapViewOfSection 77C55C68 5 Bytes JMP 719F0022 .text C:\Program Files\Mozilla Firefox\firefox.exe[5644] ntdll.dll!KiUserApcDispatcher + E 77C56FA6 5 Bytes JMP 6CA719B0 c:\program files\trusteer\rapport\bin\rooksdol.dll .text C:\Program Files\Mozilla Firefox\firefox.exe[5644] ntdll.dll!LdrGetProcedureAddress + 26 77C722A9 7 Bytes JMP 61BFB780 C:\Program Files\Mozilla Firefox\xul.dll .text C:\Program Files\Mozilla Firefox\firefox.exe[5644] kernel32.dll!K32GetDeviceDriverBaseNameW + 5D 7576941E 7 Bytes JMP 62436EDA C:\Program Files\Mozilla Firefox\xul.dll .text C:\Program Files\Mozilla Firefox\firefox.exe[5644] kernel32.dll!QueryPerformanceCounter + 13 7576C425 7 Bytes JMP 62436EFD C:\Program Files\Mozilla Firefox\xul.dll .text C:\Program Files\Mozilla Firefox\firefox.exe[5644] kernel32.dll!SetUnhandledExceptionFilter 7576F4EB 4 Bytes JMP 61C00836 C:\Program Files\Mozilla Firefox\xul.dll .text C:\Program Files\Mozilla Firefox\firefox.exe[5644] kernel32.dll!SetUnhandledExceptionFilter + 5 7576F4F0 1 Byte [C3] .text C:\Program Files\Mozilla Firefox\firefox.exe[5644] GDI32.dll!BitBlt 759E72C0 6 Bytes PUSH 71790022; RET .text C:\Program Files\Mozilla Firefox\firefox.exe[5644] GDI32.dll!GetViewportOrgEx + 26C 759E884B 7 Bytes JMP 62436E5B C:\Program Files\Mozilla Firefox\xul.dll .text C:\Program Files\Mozilla Firefox\firefox.exe[5644] USER32.dll!DdeInitializeW 75915DF2 6 Bytes PUSH 71750022; RET .text C:\Program Files\Mozilla Firefox\firefox.exe[5644] USER32.dll!SetForegroundWindow 7591B225 5 Bytes JMP 100A5574 c:\progra~1\agnitum\outpos~1\wl_hook.dll .text C:\Program Files\Mozilla Firefox\firefox.exe[5644] USER32.dll!CreateWindowExA 7591BF40 6 Bytes JMP 7192000A .text C:\Program Files\Mozilla Firefox\firefox.exe[5644] USER32.dll!CreateWindowExW 7591EC7C 6 Bytes JMP 7196000A .text C:\Program Files\Mozilla Firefox\firefox.exe[5644] USER32.dll!RegisterClassW 7591ED4A 6 Bytes PUSH 71A60022; RET .text C:\Program Files\Mozilla Firefox\firefox.exe[5644] USER32.dll!RegisterClassExW 75920162 6 Bytes PUSH 71AE0022; RET .text C:\Program Files\Mozilla Firefox\firefox.exe[5644] USER32.dll!SetWindowPos 75921BC4 5 Bytes JMP 100A55A0 c:\progra~1\agnitum\outpos~1\wl_hook.dll .text C:\Program Files\Mozilla Firefox\firefox.exe[5644] USER32.dll!GetWindowInfo 75924B5E 5 Bytes JMP 622DB28C C:\Program Files\Mozilla Firefox\xul.dll .text C:\Program Files\Mozilla Firefox\firefox.exe[5644] USER32.dll!GetWindowRect 7592558C 6 Bytes PUSH 71650022; RET .text C:\Program Files\Mozilla Firefox\firefox.exe[5644] USER32.dll!PeekMessageW 7592634A 6 Bytes PUSH 719B0022; RET .text C:\Program Files\Mozilla Firefox\firefox.exe[5644] USER32.dll!TranslateMessage 759264C7 6 Bytes PUSH 715F0022; RET .text C:\Program Files\Mozilla Firefox\firefox.exe[5644] USER32.dll!DispatchMessageW 7592CC61 6 Bytes PUSH 71710022; RET .text C:\Program Files\Mozilla Firefox\firefox.exe[5644] USER32.dll!GetMessageW 7592CDE8 6 Bytes PUSH 71690022; RET .text C:\Program Files\Mozilla Firefox\firefox.exe[5644] USER32.dll!GetClipboardData 75932BA7 6 Bytes PUSH 716D0022; RET .text C:\Program Files\Mozilla Firefox\firefox.exe[5644] USER32.dll!ChangeDisplaySettingsExA 7593627A 5 Bytes JMP 100A55F8 c:\progra~1\agnitum\outpos~1\wl_hook.dll .text C:\Program Files\Mozilla Firefox\firefox.exe[5644] USER32.dll!ChangeDisplaySettingsExW 7595FA39 5 Bytes JMP 100A5624 c:\progra~1\agnitum\outpos~1\wl_hook.dll ? C:\Program Files\Kaspersky Lab\Kaspersky Security Scan 2.0\kss.exe[6340] C:\Windows\SYSTEM32\ntdll.dll time/date stamp mismatch; .text C:\Program Files\Kaspersky Lab\Kaspersky Security Scan 2.0\kss.exe[6340] ntdll.dll!NtProtectVirtualMemory 77C55F58 5 Bytes JMP 698F1986 C:\Program Files\Kaspersky Lab\Kaspersky Security Scan 2.0\ushata.dll ? C:\Program Files\Kaspersky Lab\Kaspersky Security Scan 2.0\kss.exe[6340] C:\Windows\system32\kernel32.dll time/date stamp mismatch; unknown module: KERNELBASE.dll .text C:\Program Files\Kaspersky Lab\Kaspersky Security Scan 2.0\kss.exe[6340] user32.dll!SetForegroundWindow 7591B225 5 Bytes JMP 100A5574 c:\progra~1\agnitum\outpos~1\wl_hook.dll .text C:\Program Files\Kaspersky Lab\Kaspersky Security Scan 2.0\kss.exe[6340] user32.dll!SetWindowPos 75921BC4 5 Bytes JMP 100A55A0 c:\progra~1\agnitum\outpos~1\wl_hook.dll .text C:\Program Files\Kaspersky Lab\Kaspersky Security Scan 2.0\kss.exe[6340] user32.dll!NotifyWinEvent + 6AE 7592D66C 4 Bytes [F0, 28, 8F, 69] .text C:\Program Files\Kaspersky Lab\Kaspersky Security Scan 2.0\kss.exe[6340] user32.dll!ChangeDisplaySettingsExA 7593627A 5 Bytes JMP 100A55F8 c:\progra~1\agnitum\outpos~1\wl_hook.dll .text C:\Program Files\Kaspersky Lab\Kaspersky Security Scan 2.0\kss.exe[6340] user32.dll!ChangeDisplaySettingsExW 7595FA39 5 Bytes JMP 100A5624 c:\progra~1\agnitum\outpos~1\wl_hook.dll .text C:\Users\makem\AppData\Local\Temp\HouseCall\housecall.bin[6564] USER32.dll!SetForegroundWindow 7591B225 5 Bytes JMP 014A5574 c:\progra~1\agnitum\outpos~1\wl_hook.dll .text C:\Users\makem\AppData\Local\Temp\HouseCall\housecall.bin[6564] USER32.dll!SetWindowPos 75921BC4 5 Bytes JMP 014A55A0 c:\progra~1\agnitum\outpos~1\wl_hook.dll .text C:\Users\makem\AppData\Local\Temp\HouseCall\housecall.bin[6564] USER32.dll!ChangeDisplaySettingsExA 7593627A 5 Bytes JMP 014A55F8 c:\progra~1\agnitum\outpos~1\wl_hook.dll .text C:\Users\makem\AppData\Local\Temp\HouseCall\housecall.bin[6564] USER32.dll!ChangeDisplaySettingsExW 7595FA39 5 Bytes JMP 014A5624 c:\progra~1\agnitum\outpos~1\wl_hook.dll .text C:\Windows\SYSTEM32\WISPTIS.EXE[6716] USER32.dll!SetForegroundWindow 7591B225 5 Bytes JMP 100A5574 c:\progra~1\agnitum\outpos~1\wl_hook.dll .text C:\Windows\SYSTEM32\WISPTIS.EXE[6716] USER32.dll!SetWindowPos 75921BC4 5 Bytes JMP 100A55A0 c:\progra~1\agnitum\outpos~1\wl_hook.dll .text C:\Windows\SYSTEM32\WISPTIS.EXE[6716] USER32.dll!ChangeDisplaySettingsExA 7593627A 5 Bytes JMP 100A55F8 c:\progra~1\agnitum\outpos~1\wl_hook.dll .text C:\Windows\SYSTEM32\WISPTIS.EXE[6716] USER32.dll!ChangeDisplaySettingsExW 7595FA39 5 Bytes JMP 100A5624 c:\progra~1\agnitum\outpos~1\wl_hook.dll .text D:\My Profile\Desktop\gmer\tool.exe[7460] USER32.dll!SetForegroundWindow 7591B225 5 Bytes JMP 100A5574 c:\progra~1\agnitum\outpos~1\wl_hook.dll .text D:\My Profile\Desktop\gmer\tool.exe[7460] USER32.dll!SetWindowPos 75921BC4 5 Bytes JMP 100A55A0 c:\progra~1\agnitum\outpos~1\wl_hook.dll .text D:\My Profile\Desktop\gmer\tool.exe[7460] USER32.dll!ChangeDisplaySettingsExA 7593627A 5 Bytes JMP 100A55F8 c:\progra~1\agnitum\outpos~1\wl_hook.dll .text D:\My Profile\Desktop\gmer\tool.exe[7460] USER32.dll!ChangeDisplaySettingsExW 7595FA39 5 Bytes JMP 100A5624 c:\progra~1\agnitum\outpos~1\wl_hook.dll ---- Devices - GMER 2.1 ---- Device 85A6E1F8 Device Ntfs.sys AttachedDevice tdrpm273.sys Device 88FF9440 Device fastfat.SYS Device \Driver\usbuhci \Device\USBPDO-0 87E94440 Device \Driver\usbuhci \Device\USBPDO-1 87E94440 Device \Driver\usbuhci \Device\USBPDO-2 87E94440 Device \Driver\usbuhci \Device\USBPDO-3 87E94440 Device \Driver\usbehci \Device\USBPDO-4 87E92440 AttachedDevice \Driver\tdx \Device\Tcp avgtdix.sys Device volmgr.sys AttachedDevice fltmgr.sys Device \Driver\PCI_PNP1909 \Device\00000064 sptd.sys Device \Driver\cdrom \Device\CdRom0 86A501F8 Device \Driver\cdrom \Device\CdRom1 86A501F8 Device \Driver\atapi \Device\Ide\IdeDeviceP2T0L0-1 85A6C1F8 Device \Driver\atapi \Device\Ide\IdePort0 85A6C1F8 Device \Driver\atapi \Device\Ide\IdePort1 85A6C1F8 Device \Driver\atapi \Device\Ide\IdePort2 85A6C1F8 Device \Driver\atapi \Device\Ide\IdeDeviceP1T0L0-0 85A6C1F8 Device \Driver\NetBT \Device\NetBT_Tcpip_{59170D88-5A4F-42E7-8519-D635A450BEE3} 86C1B440 Device \Driver\NetBT \Device\NetBt_Wins_Export 86C1B440 Device \Driver\USBSTOR \Device\00000092 896BC440 Device \Driver\USBSTOR \Device\00000093 896BC440 Device \Driver\nsiproxy \Device\Nsi afwcore.sys AttachedDevice \Driver\tdx \Device\Udp avgtdix.sys AttachedDevice \Driver\tdx \Device\RawIp avgtdix.sys Device \Driver\usbuhci \Device\USBFDO-0 87E94440 Device \Driver\usbuhci \Device\USBFDO-1 87E94440 Device \Driver\usbuhci \Device\USBFDO-2 87E94440 Device \Driver\usbuhci \Device\USBFDO-3 87E94440 Device \Driver\usbehci \Device\USBFDO-4 87E92440 Device \Driver\NetBT \Device\NetBT_Tcpip_{1A51BA33-BEEE-4226-A46F-93F34FFF231A} 86C1B440 Device \Driver\axyzk0l7 \Device\Scsi\axyzk0l71 87E5D440 Device \Driver\axyzk0l7 \Device\Scsi\axyzk0l71Port3Path0Target0Lun0 87E5D440 ---- Trace I/O - GMER 2.1 ---- Trace ntoskrnl.exe CLASSPNP.SYS disk.sys ACPI.sys halmacpi.dll >>UNKNOWN [0x85a6c1f8]<< 85a6c1f8 Trace 1 nt!IofCallDriver -> \Device\Harddisk0\DR0[0x868c4030] 868c4030 Trace 3 CLASSPNP.SYS[8cc2259e] -> nt!IofCallDriver -> [0x85aeb588] 85aeb588 Trace 5 ACPI.sys[8c30c3d4] -> nt!IofCallDriver -> \Device\Ide\IdeDeviceP1T0L0-0[0x85ae3908] 85ae3908 Trace \Driver\atapi[0x867c7c08] -> IRP_MJ_CREATE -> 0x85a6c1f8 85a6c1f8 ---- Processes - GMER 2.1 ---- Library C:\Program Files\MyDrivers\DriverGenius2013\dghmpg.dll (*** hidden *** ) @ C:\Windows\Explorer.EXE [3580] 0x06D60000 Library C:\Program Files\MyDrivers\DriverGenius2013\dguimn.dll (*** hidden *** ) @ C:\Windows\Explorer.EXE [3580] 0x06E50000 ---- Registry - GMER 2.1 ---- Reg HKLM\SYSTEM\CurrentControlSet\services\BTHPORT\Parameters\Keys\00037af9450c Reg HKLM\SYSTEM\CurrentControlSet\services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04 Reg HKLM\SYSTEM\CurrentControlSet\services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04@h0 0 Reg HKLM\SYSTEM\CurrentControlSet\services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04@ujdew 0xF6 0xAD 0xC8 0xCF ... Reg HKLM\SYSTEM\CurrentControlSet\services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04@p0 C:\Program Files\Alcohol Soft\Alcohol 120\ Reg HKLM\SYSTEM\CurrentControlSet\services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04\00000001 Reg HKLM\SYSTEM\CurrentControlSet\services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04\00000001@ujdew 0xB1 0x5B 0x63 0x86 ... Reg HKLM\SYSTEM\CurrentControlSet\services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04\00000001@a0 0xA0 0x02 0x00 0x00 ... Reg HKLM\SYSTEM\CurrentControlSet\services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04\00000001\jdgg40 Reg HKLM\SYSTEM\CurrentControlSet\services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04\00000001\jdgg40@ujdew 0x92 0x39 0x2A 0xEB ... Reg HKLM\SYSTEM\ControlSet002\services\BTHPORT\Parameters\Keys\00037af9450c (not active ControlSet) Reg HKLM\SYSTEM\ControlSet002\services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04 (not active ControlSet) Reg HKLM\SYSTEM\ControlSet002\services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04@h0 0 Reg HKLM\SYSTEM\ControlSet002\services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04@ujdew 0xF6 0xAD 0xC8 0xCF ... Reg HKLM\SYSTEM\ControlSet002\services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04@p0 C:\Program Files\Alcohol Soft\Alcohol 120\ Reg HKLM\SYSTEM\ControlSet002\services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04\00000001 (not active ControlSet) Reg HKLM\SYSTEM\ControlSet002\services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04\00000001@ujdew 0xB1 0x5B 0x63 0x86 ... Reg HKLM\SYSTEM\ControlSet002\services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04\00000001@a0 0xA0 0x02 0x00 0x00 ... Reg HKLM\SYSTEM\ControlSet002\services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04\00000001\jdgg40 (not active ControlSet) Reg HKLM\SYSTEM\ControlSet002\services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04\00000001\jdgg40@ujdew 0x92 0x39 0x2A 0xEB ... Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Setup\Sysprep\Cleanup@{6737d15a-0839-204d-ac99-fda4b6fe1603} C:\Windows\system32\wer.dll (Windows Error Reporting DLL/Microsoft Corporation SIGNED)(2013-09-25 17:36:57) Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Setup\Sysprep\Cleanup@{418ae848-486e-3d24-5fbc-2ce1ce25c0e2} C:\Windows\System32\sysmain.dll (Superfetch Service Host/Microsoft Corporation SIGNED)(2013-09-25 17:37:38) Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Setup\Sysprep\Cleanup@{1492939a-260b-46b6-b4ea-08ccb5259f11} C:\Windows\system32\srcore.dll (Microsoft� Windows System Restore Core Library/Microsoft Corporation SIGNED)(2013-09-25 17:36:32) Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Setup\Sysprep\Generalize@{c15690f3-5908-1929-1eb2-96b7091aa28f} C:\Windows\system32\msdtcprx.dll (Microsoft Distributed Transaction Coordinator OLE Transactions Interface Proxy DLL/Microsoft Corporation SIGNED)(2009-07-13 23:44:23) Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Setup\Sysprep\Generalize@{aebbf5ef-0ae2-1788-07bd-00f3276e41cf} C:\Windows\System32\spopk.dll (OPK Sysprep Plugin/Microsoft Corporation SIGNED)(2013-09-25 17:36:54) Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Setup\Sysprep\Generalize@{82468857-ad9b-1a37-533f-7db889fff253} C:\Windows\System32\slc.dll (Software Licensing Client Dll/Microsoft Corporation SIGNED)(2009-07-13 23:35:27) Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Setup\Sysprep\Generalize@{ddae0117-68f5-11b9-0470-6c42dc9b8f85} C:\Windows\System32\iphlpsvc.dll (Service that offers IPv6 connectivity over an IPv4 network./Microsoft Corporation SIGNED)(2013-09-25 17:38:18) Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Setup\Sysprep\Generalize@{d1370f79-f407-baa2-58aa-df121c7314ed} C:\Windows\System32\reagent.dll (Microsoft Windows Recovery Agent DLL/Microsoft Corporation SIGNED)(2013-09-25 17:38:04) Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Setup\Sysprep\Generalize@{6737d15a-0839-204d-2062-3fd9d1266740} C:\Windows\system32\wer.dll (Windows Error Reporting DLL/Microsoft Corporation SIGNED)(2013-09-25 17:36:57) Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Setup\Sysprep\Generalize@{d36a69b3-c9da-3086-d3d1-771286930ef6} C:\Windows\System32\wuaueng.dll (Windows Update Agent/Microsoft Corporation SIGNED)(2013-09-24 18:10:33) Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Setup\Sysprep\Generalize@{1492939a-260b-46b6-ee22-e585dac90889} C:\Windows\system32\srcore.dll (Microsoft� Windows System Restore Core Library/Microsoft Corporation SIGNED)(2013-09-25 17:36:32) Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Setup\Sysprep\Specialize@{c15690f3-5908-1929-35a2-cee9227ca977} C:\Windows\system32\msdtcprx.dll (Microsoft Distributed Transaction Coordinator OLE Transactions Interface Proxy DLL/Microsoft Corporation SIGNED)(2009-07-13 23:44:23) Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Setup\Sysprep\Specialize@{aebbf5ef-0ae2-1788-f6ab-3497d0a40953} C:\Windows\System32\spopk.dll (OPK Sysprep Plugin/Microsoft Corporation SIGNED)(2013-09-25 17:36:54) Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Setup\Sysprep\Specialize@{6737d15a-0839-204d-71c7-f5472ac291e2} C:\Windows\system32\wer.dll (Windows Error Reporting DLL/Microsoft Corporation SIGNED)(2013-09-25 17:36:57) Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Setup\Sysprep\Specialize@{3a6f0483-387f-37e4-88bf-66c14455b53b} C:\Windows\System32\scecli.dll (Windows Security Configuration Editor Client Engine/Microsoft Corporation SIGNED)(2013-09-25 17:38:02) Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Setup\Sysprep\Specialize@{0e95de08-d472-3202-4561-c2be81045f3e} C:\Windows\System32\oobe\winsetup.dll (Windows System Setup/Microsoft Corporation SIGNED)(2013-09-25 17:37:01) Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Setup\Sysprep\Specialize@{deb5de01-f926-5ae7-1323-32a78266ef5a} C:\Windows\system32\radardt.dll (Microsoft Windows Resource Exhaustion Detector/Microsoft Corporation SIGNED)(2009-07-13 23:20:11) Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Setup\Sysprep\Specialize@{6eb5ddc8-ce4f-3f28-dd9d-054d61ca886d} C:\Windows\system32\fthsvc.dll (Microsoft Windows Fault Tolerant Heap Diagnostic Module/Microsoft Corporation SIGNED)(2009-07-13 23:20:11) Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Agnitum Outpost Firewall Pro_is1@DisplayIcon C:\Program Files\Agnitum\Outpost Firewall Pro\op_mon.exe (Outpost User Interface/Agnitum Ltd. SIGNED)(2013-09-24 20:15:25) Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Canon My Image Garden@DisplayIcon C:\Program Files\Canon\My Image Garden\cnmigmain.exe (Canon My Image Garden/CANON INC. SIGNED)(2013-10-07 11:19:38) Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Canon_IJ_Network_Scanner_Selector_EX@DisplayIcon C:\Program Files\Canon\IJ Network Scanner Selector EX\CNMNSST.exe (Canon IJ Network Scanner Selector EX/CANON INC. SIGNED)(2013-10-07 14:58:19) Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Canon_IJ_Scan_Utility@DisplayIcon C:\Program Files\Canon\IJ Scan Utility\SCANUTILITY.exe (Canon IJ Scan Utility/CANON INC. SIGNED)(2013-10-07 14:58:25) Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\DigiGuide TV Guide@DisplayIcon C:\Program Files\DigiGuide TV Guide\digiguide.exe(2013-09-24 20:45:14) Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\InstallShield_{FEDD27A0-B306-45EF-BF58-B527406B42C8}@DisplayIcon C:\Windows\Installer\{FEDD27A0-B306-45EF-BF58-B527406B42C8}\ARPPRODUCTICON.exe Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\InstallWIX_{56009CA3-423B-41F8-884A-E5B049534F15}@UninstallString C:\Windows\system32\MsiExec.exe (Windows� installer/Microsoft Corporation SIGNED)(2013-09-25 17:37:17) Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Mozilla Firefox 26.0 (x86 en-US)@DisplayIcon C:\Program Files\Mozilla Firefox\firefox.exe (Firefox/Mozilla Corporation SIGNED)(2013-11-16 15:07:12) Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Notepad++@DisplayIcon C:\Program Files\Notepad++\notepad++.exe (Notepad++ : a free (GNU) source code editor/Don HO [removed])(2013-12-31 13:25:20) Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\QuickPar@DisplayIcon C:\Program Files\QuickPar\QuickPar.exe (QuickPar/Peter B Clements)(2004-07-03 09:34:17) Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\VLC media player@DisplayIcon C:\Program Files\VideoLAN\VLC\vlc.exe (VLC media player 2.1.2/VideoLAN)(2013-12-09 00:18:16) Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Windows Media Encoder 9@DisplayIcon C:\Program Files\Windows Media Components\Encoder\WMEnc.exe (Windows Media Encoder/Microsoft Corporation)(2002-12-11 19:38:52) Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Windows Media Encoder 9@UninstallString C:\Windows\system32\msiexec.exe (Windows� installer/Microsoft Corporation SIGNED)(2013-09-25 17:37:17) Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\WinRAR archiver@DisplayIcon C:\Program Files\WinRAR\WinRAR.exe (WinRAR (2013-09-24 20:10:43) Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{019210C1-32C8-423C-BEFD-763C8E7A188F}@ModifyPath C:\Windows\system32\MsiExec.exe (Windows� installer/Microsoft Corporation SIGNED)(2013-09-25 17:37:17) Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{26A24AE4-039D-4CA4-87B4-2F83217051FF}@DisplayIcon C:\Program Files\Java\jre7\bin\javaws.exe (Java(TM) Web Start Launcher/Oracle Corporation SIGNED)(2014-02-02 00:13:17) Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{26A24AE4-039D-4CA4-87B4-2F83217051FF}@ModifyPath C:\Windows\system32\MsiExec.exe (Windows� installer/Microsoft Corporation SIGNED)(2013-09-25 17:37:17) Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Publishers\{0063715b-eeda-4007-9429-ad526f62696e}@ResourceFileName C:\Windows\system32\services.exe (Services and Controller app/Microsoft Corporation SIGNED)(2009-07-13 23:11:26) Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Publishers\{01578f96-c270-4602-ade0-578d9c29fc0c}@ResourceFileName C:\Windows\system32\van.dll (View Available Networks/Microsoft Corporation SIGNED)(2013-09-25 17:38:08) Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Publishers\{017ba13c-9a55-4f1f-8200-323055aac810}@ResourceFileName C:\Windows\system32\drivers\tcpipreg.sys (TCP/IP Registry Compatibility Driver/Microsoft Corporation SIGNED)(2013-09-25 17:38:15) Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Publishers\{01979c6a-42fa-414c-b8aa-eee2c8202018}@ResourceFileName C:\Windows\System32\sdclt.exe (Microsoft� Windows Backup/Microsoft Corporation SIGNED)(2013-09-25 17:36:50) Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Publishers\{030f2f57-abd0-4427-bcf1-3a3587d7dc7d}@ResourceFileName C:\Windows\system32\perftrack.dll (Microsoft Performance PerfTrack/Microsoft Corporation SIGNED)(2009-07-13 23:21:22) Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Publishers\{04268430-d489-424d-b914-0cff741d6684}@ResourceFileName C:\Windows\System32\wpd_ci.dll (Driver Setup Class Installer for Windows Portable Devices/Microsoft Corporation SIGNED)(2013-09-25 17:38:08) Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Publishers\{059c3e04-5535-4929-85e1-93030e78f47b}@ResourceFileName C:\Windows\system32\shsvcs.dll (Windows Shell Services Dll/Microsoft Corporation SIGNED)(2013-09-25 17:37:27) Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Publishers\{06184c97-5201-480e-92af-3a3626c5b140}@ResourceFileName C:\Windows\system32\services.exe (Services and Controller app/Microsoft Corporation SIGNED)(2009-07-13 23:11:26) Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Publishers\{06edcfeb-0fd0-4e53-acca-a6f8bbf81bcb}@ResourceFileName C:\Windows\system32\w32time.dll (Windows Time Service/Microsoft Corporation SIGNED)(2009-07-13 23:33:32) Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Publishers\{0888e5ef-9b98-4695-979d-e92ce4247224}@ResourceFileName C:\Windows\System32\RstrtMgr.dll (Restart Manager/Microsoft Corporation SIGNED)(2009-07-13 23:22:54) Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Publishers\{093da50c-0bb9-4d7d-b95c-3bb9fcda5ee8}@ResourceFileName C:\Windows\system32\drivers\afd.sys (Ancillary Function Driver for WinSock/Microsoft Corporation SIGNED)(2013-11-12 12:07:18) Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Publishers\{093da50c-0bb9-4d7d-b95c-3bb9fcda5ee8}@MessageFileName C:\Windows\system32\ws2_32.dll (Windows Socket 2.0 32-Bit DLL/Microsoft Corporation SIGNED)(2013-09-25 17:37:33) Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Publishers\{099614a5-5dd7-4788-8bc9-e29f43db28fc}@ResourceFileName C:\Windows\system32\wldap32.dll (Win32 LDAP API DLL/Microsoft Corporation SIGNED)(2013-09-25 17:37:34) Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Publishers\{0bd3506a-9030-4f76-9b88-3e8fe1f7cfb6}@ResourceFileName C:\Windows\system32\drivers\nwifi.sys (NativeWiFi Miniport Driver/Microsoft Corporation SIGNED)(2009-07-13 23:52:03) Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Publishers\{0c478c5b-0351-41b1-8c58-4a6737da32e3}@ResourceFileName C:\Windows\system32\bfe.dll (Base Filtering Engine/Microsoft Corporation SIGNED)(2013-09-25 17:36:18) Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Publishers\{0d4fdc09-8c27-494a-bda0-505e4fd8adae}@ResourceFileName C:\Windows\System32\samsrv.dll (SAM Server DLL/Microsoft Corporation SIGNED)(2013-09-25 17:37:26) Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Publishers\{0f177893-4a9c-4709-b921-f432d67f43d5}@ResourceFileName C:\Windows\system32\comres.dll (COM+ Resources/Microsoft Corporation SIGNED)(2009-07-13 23:44:02) Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Publishers\{0f67e49f-fe51-4e9f-b490-6f2948cc6027}@ResourceFileName C:\Windows\system32\microsoft-windows-kernel-processor-power-events.dll (Microsoft-Windows-Kernel-Processor-Power-Events Resources/Microsoft Corporation SIGNED)(2009-07-13 23:22:29) Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Publishers\{11a75546-3234-465e-bec8-2d301cb501ac}@ResourceFileName C:\Windows\system32\WINSAT.EXE (Windows System Assessment Tool/Microsoft Corporation SIGNED)(2013-09-25 17:37:35) Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Publishers\{11cd958a-c507-4ef3-b3f2-5fd9dfbd2c78}@ResourceFileName C:\Program Files\Windows Defender\MpEvMsg.dll (Event Resource Module/Microsoft Corporation SIGNED)(2009-07-13 23:37:20) Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Publishers\{122ee297-bb47-41ae-b265-1ca8d1886d40}@ResourceFileName C:\Windows\system32\loadperf.dll (Load & Unload Performance Counters/Microsoft Corporation SIGNED)(2009-07-13 23:19:39) Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Publishers\{127e0dc5-e13b-4935-985e-78fd508b1d80}@ResourceFileName C:\Windows\System32\rdpendp.dll (RDP Audio Endpoint/Microsoft Corporation SIGNED)(2013-09-25 17:37:31) Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Publishers\{15a7a4f8-0072-4eab-abad-f98a4d666aed}@ResourceFileName C:\Windows\system32\dhcpcore.dll (DHCP Client Service/Microsoft Corporation SIGNED)(2013-09-25 17:37:49) Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Publishers\{15a7a4f8-0072-4eab-abad-f98a4d666aed}@ParameterFileName C:\Windows\System32\kernelbase.dll (Windows NT BASE API Client DLL/Microsoft Corporation SIGNED)(2013-09-26 18:20:51) Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Publishers\{15ca44ff-4d7a-4baa-bba5-0998955e531e}@ResourceFileName C:\Windows\system32\advapi32.dll (Advanced Windows 32 Base API/Microsoft Corporation SIGNED)(2013-11-12 12:07:36) Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Publishers\{17e92e2a-3d08-413e-baeb-a79a262bf486}@ResourceFileName C:\Windows\system32\msimsg.dll (Windows� Installer International Messages/Microsoft Corporation SIGNED)(2009-07-13 23:31:17) Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Publishers\{18f4a5fd-fd3b-40a5-8fc2-e5d261c5d02e}@ResourceFileName C:\Windows\system32\advapi32.dll (Advanced Windows 32 Base API/Microsoft Corporation SIGNED)(2013-11-12 12:07:36) Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Publishers\{199fe037-2b82-40a9-82ac-e1d46c792b99}@ResourceFileName C:\Windows\System32\lsasrv.dll (LSA Server DLL/Microsoft Corporation SIGNED)(2013-11-13 14:56:05) Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Publishers\{1a9443d4-b099-44d6-8eb1-829b9c2fe290}@ResourceFileName C:\Windows\system32\advapi32.dll (Advanced Windows 32 Base API/Microsoft Corporation SIGNED)(2013-11-12 12:07:36) Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Publishers\{1b562e86-b7aa-4131-badc-b6f3a001407e}@ResourceFileName C:\Windows\system32\oleres.dll (Ole resource dll/Microsoft Corporation SIGNED)(2009-07-13 23:43:45) Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Publishers\{1b8b402d-78dc-46fb-bf71-46e64aedf165}@ResourceFileName C:\Windows\system32\TSWorkspace.dll (RemoteApp and Desktop Connection Component/Microsoft Corporation SIGNED)(2013-09-25 17:37:06) Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Publishers\{1be1a88d-8e34-4170-9123-f503375bbcef}@ResourceFileName C:\Windows\system32\drivers\classpnp.sys (SCSI Class System Dll/Microsoft Corporation SIGNED)(2009-07-13 23:11:21) Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Publishers\{1c95126e-7eea-49a9-a3fe-a378b03ddb4d}@ResourceFileName C:\Windows\system32\dnsapi.dll (DNS Client API DLL/Microsoft Corporation SIGNED)(2013-09-25 08:18:33) Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Publishers\{1d75856d-36a7-4ecb-a3f5-b13152222d29}@ResourceFileName C:\Windows\system32\mspaint.exe (Paint/Microsoft Corporation SIGNED)(2009-07-13 23:43:12) Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Publishers\{1db28f2e-8f80-4027-8c5a-a11f7f10f62d}@ResourceFileName C:\Windows\system32\BlbEvents.dll (Blb Publisher/Microsoft Corporation SIGNED)(2013-09-25 17:37:14) Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Publishers\{1f678132-5938-4686-9fdc-c8ff68f15c85}@ResourceFileName C:\Windows\System32\lsasrv.dll (LSA Server DLL/Microsoft Corporation SIGNED)(2013-11-13 14:56:05) Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Publishers\{206f6dea-d3c5-4d10-bc72-989f03c8b84b}@ResourceFileName C:\Windows\system32\wininit.exe (Windows Start-Up Application/Microsoft Corporation SIGNED)(2009-07-13 23:36:49) Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Publishers\{21b7c16e-c5af-4a69-a74a-7245481c1b97}@ResourceFileName C:\Windows\System32\wpd_ci.dll (Driver Setup Class Installer for Windows Portable Devices/Microsoft Corporation SIGNED)(2013-09-25 17:38:08) Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Publishers\{22b6d684-fa63-4578-87c9-effcbe6643c7}@ResourceFileName C:\Windows\system32\davclnt.dll (Web DAV Client DLL/Microsoft Corporation SIGNED)(2013-09-25 17:38:22) Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Publishers\{22fb2cd6-0e7b-422b-a0c7-2fad1fd0e716}@ResourceFileName C:\Windows\system32\advapi32.dll (Advanced Windows 32 Base API/Microsoft Corporation SIGNED)(2013-11-12 12:07:36) Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Publishers\{27a8c1e2-eb19-463e-8424-b399df27a216}@ResourceFileName C:\Windows\system32\umrdp.dll (Remote Desktop Services Device Redirector Service/Microsoft Corporation SIGNED)(2013-09-25 17:37:39) Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Publishers\{28aa95bb-d444-4719-a36f-40462168127e}@ResourceFileName C:\Windows\system32\mstscax.dll (Remote Desktop Services ActiveX Client/Microsoft Corporation SIGNED)(2013-09-25 08:15:19) Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Publishers\{2992e9cf-4f99-48f5-a0b6-b99b11cd387d}@ResourceFileName C:\Windows\system32\pnrpsvc.dll (PNRP Service Dll/Microsoft Corporation SIGNED)(2009-07-13 23:56:13) Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Publishers\{29d13147-1c2e-48ec-9994-e29dfe496eb3}@ResourceFileName C:\Windows\System32\rtm.dll (Routing Table Manager/Microsoft Corporation SIGNED)(2009-07-13 23:54:45) Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Publishers\{2a274310-42d5-4019-b816-e4b8c7abe95c}@ResourceFileName C:\Windows\system32\drivers\rdyboost.sys (ReadyBoost Driver/Microsoft Corporation SIGNED)(2013-09-25 17:38:05) Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Publishers\{2e35aaeb-857f-4beb-a418-2e6c0e54d988}@ResourceFileName C:\Windows\system32\WUDFPlatform.dll (Windows Driver Foundation - User-mode Platform Library/Microsoft Corporation SIGNED)(2013-09-25 17:37:34) Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Publishers\{2ed6006e-4729-4609-b423-3ee7bcd678ef}@ResourceFileName C:\Windows\system32\drivers\ndiscap.sys (NDIS Packet Capture Filter Driver/Microsoft Corporation SIGNED)(2009-07-13 23:52:44) Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Publishers\{2f07e2ee-15db-40f1-90ef-9d7ba282188a}@ResourceFileName C:\Windows\system32\drivers\tcpip.sys (TCP/IP Driver/Microsoft Corporation SIGNED)(2013-11-12 12:07:19) Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Publishers\{2ff3e6b7-cb90-4700-9621-443f389734ed}@ResourceFileName C:\Windows\system32\advapi32.dll (Advanced Windows 32 Base API/Microsoft Corporation SIGNED)(2013-11-12 12:07:36) Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Publishers\{30336ed4-e327-447c-9de0-51b652c86108}@ResourceFileName C:\Windows\system32\shsvcs.dll (Windows Shell Services Dll/Microsoft Corporation SIGNED)(2013-09-25 17:37:27) Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Publishers\{314de49f-ce63-4779-ba2b-d616f6963a88}@ResourceFileName C:\Windows\system32\ncsi.dll (Network Connectivity Status Indicator/Microsoft Corporation SIGNED)(2013-09-25 17:37:51) Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Publishers\{331c3b3a-2005-44c2-ac5e-77220c37d6b4}@ResourceFileName C:\Windows\system32\microsoft-windows-kernel-power-events.dll (Microsoft-Windows-Kernel-Power-Events Resources/Microsoft Corporation SIGNED)(2009-07-13 23:22:28) Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Publishers\{33693e1d-246a-471b-83be-3e75f47a832d}@ResourceFileName C:\Windows\system32\drivers\bthusb.sys (Bluetooth Miniport Driver/Microsoft Corporation SIGNED)(2013-09-26 18:23:17) Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Publishers\{355c44fe-0c8e-4bf8-be28-8bc7b5a42720}@ResourceFileName C:\Windows\System32\wpd_ci.dll (Driver Setup Class Installer for Windows Portable Devices/Microsoft Corporation SIGNED)(2013-09-25 17:38:08) Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Publishers\{3663a992-84be-40ea-bba9-90c7ed544222}@ResourceFileName C:\Windows\system32\efscore.dll (EFS Core Library/Microsoft Corporation SIGNED)(2013-09-25 17:37:43) Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Publishers\{36c23e18-0e66-11d9-bbeb-505054503030}@ResourceFileName C:\Windows\system32\netdiagfx.dll (Network Diagnostic Framework/Microsoft Corporation SIGNED)(2013-09-25 17:36:40) Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Publishers\{37945dc2-899b-44d1-b79c-dd4a9e57ff98}@ResourceFileName C:\Windows\system32\mpssvc.dll (Microsoft Protection Service/Microsoft Corporation SIGNED)(2013-09-25 17:37:22) Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Publishers\{3aa52b8b-6357-4c18-a92e-b53fb177853b}@ResourceFileName C:\Windows\system32\advapi32.dll (Advanced Windows 32 Base API/Microsoft Corporation SIGNED)(2013-11-12 12:07:36) Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Publishers\{3cb2a168-fe19-4a4e-bdad-dcf422f13473}@ResourceFileName C:\Windows\system32\appidapi.dll (Application Identity APIs Dll/Microsoft Corporation SIGNED)(2009-07-13 23:36:51) Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Publishers\{3cb40aaa-1145-4fb8-b27b-7e30f0454316}@ResourceFileName C:\Windows\system32\wwansvc.dll (WWAN Auto Config Service/Microsoft Corporation SIGNED)(2009-07-13 23:56:41) Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Publishers\{4214dcd2-7c33-4f74-9898-719ccceec20f}@ResourceFileName C:\Windows\system32\drivers\tunnel.sys (Microsoft Tunnel Interface Driver/Microsoft Corporation SIGNED)(2013-09-25 17:36:37) Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Publishers\{422088e6-cd0c-4f99-bd0b-6985fa290bdf}@ResourceFileName C:\Windows\system32\shsvcs.dll (Windows Shell Services Dll/Microsoft Corporation SIGNED)(2013-09-25 17:37:27) Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Publishers\{43d1a55c-76d6-4f7e-995c-64c711e5cafe}@ResourceFileName C:\Windows\system32\wininet.dll (Internet Extensions for Win32/Microsoft Corporation SIGNED)(2013-12-13 11:08:42) Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Publishers\{43e63da5-41d1-4fbf-aded-1bbed98fdd1d}@ResourceFileName C:\Windows\system32\csrsrv.dll (Client Server Runtime Process/Microsoft Corporation SIGNED)(2013-09-25 08:18:56) Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Publishers\{49c2c27c-fe2d-40bf-8c4e-c3fb518037e7}@ResourceFileName C:\Windows\system32\SearchIndexer.exe (Microsoft Windows Search Indexer/Microsoft Corporation SIGNED)(2009-07-14 00:14:13) Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Publishers\{4a933674-fb3d-4e8d-b01d-17ee14e91a3e}@ResourceFileName C:\Windows\system32\cscsvc.dll (CSC Service DLL/Microsoft Corporation SIGNED)(2013-09-25 17:36:11) Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Publishers\{4cec9c95-a65f-4591-b5c4-30100e51d870}@ResourceFileName C:\Windows\system32\ktmw32.dll (Windows KTM Win32 Client DLL/Microsoft Corporation SIGNED)(2009-07-13 23:11:05) Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Publishers\{4edbe902-9ed3-4cf0-93e8-b8b5fa920299}@ResourceFileName C:\Windows\system32\drivers\tunnel.sys (Microsoft Tunnel Interface Driver/Microsoft Corporation SIGNED)(2013-09-25 17:36:37) Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Publishers\{4ee76bd8-3cf4-44a0-a0ac-3937643e37a3}@ResourceFileName C:\Windows\system32\ci.dll (Code Integrity Module/Microsoft Corporation SIGNED)(2013-09-25 17:37:15) Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Publishers\{4ef850d8-bf30-4e64-a917-ee21b9be1f0a}@ResourceFileName C:\Windows\system32\qagentrt.dll (Quarantine Agent Service Run-Time/Microsoft Corporation SIGNED)(2013-09-25 17:38:06) Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Publishers\{4fba1227-f606-4e5f-b9e8-fab9ab5740f3}@ResourceFileName C:\Windows\system32\msctf.dll (MSCTF Server DLL/Microsoft Corporation SIGNED)(2009-07-13 23:28:05) Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Publishers\{4fcbf664-a33a-4652-b436-9d558983d955}@ResourceFileName C:\Windows\system32\scardsvr.dll (Smart Card Resource Management Server/Microsoft Corporation SIGNED)(2009-07-13 23:33:51) Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Publishers\{50bd1bfd-936b-4db3-86be-e25b96c25898}@ResourceFileName C:\Windows\system32\mpssvc.dll (Microsoft Protection Service/Microsoft Corporation SIGNED)(2013-09-25 17:37:22) Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Publishers\{51480c1a-90aa-416e-98fd-4c11f735349b}@ResourceFileName C:\Windows\system32\tbssvc.dll (TBS Service/Microsoft Corporation SIGNED)(2009-07-13 23:12:41) Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Publishers\{5322d61a-9efa-4bc3-a3f9-14be95c144f8}@ResourceFileName C:\Windows\system32\advapi32.dll (Advanced Windows 32 Base API/Microsoft Corporation SIGNED)(2013-11-12 12:07:36) Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Publishers\{538cbbad-4877-4eb2-b26e-7caee8f0f8cb}@ResourceFileName C:\Windows\system32\fdphost.dll (Function Discovery Provider host service/Microsoft Corporation SIGNED)(2009-07-13 23:22:36) Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Publishers\{54164045-7c50-4905-963f-e5bc1eef0cca}@ResourceFileName C:\Windows\system32\certenroll.dll (Microsoft� Active Directory Certificate Services Enrollment Client/Microsoft Corporation SIGNED)(2013-09-25 17:37:47) Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Publishers\{5444519f-2484-45a2-991e-953e4b54c8e0}@ResourceFileName C:\Windows\system32\mpssvc.dll (Microsoft Protection Service/Microsoft Corporation SIGNED)(2013-09-25 17:37:22) Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Publishers\{54732ee5-61ca-4727-9da1-10be5a4f773d}@ResourceFileName C:\Windows\system32\bfe.dll (Base Filtering Engine/Microsoft Corporation SIGNED)(2013-09-25 17:36:18) Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Publishers\{54849625-5478-4994-a5ba-3e3b0328c30d}@ResourceFileName C:\Windows\system32\adtschema.dll (Security Audit Schema DLL/Microsoft Corporation SIGNED)(2009-07-13 23:11:00) Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Publishers\{54849625-5478-4994-a5ba-3e3b0328c30d}@ParameterFileName C:\Windows\system32\msobjs.dll (System object audit names/Microsoft Corporation SIGNED)(2009-07-13 23:11:00) Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Publishers\{54d5ac20-e14f-4fda-92da-ebf7556ff176}@ResourceFileName C:\Windows\System32\drivers\cng.sys (Kernel Cryptography, Next Generation/Microsoft Corporation SIGNED)(2013-11-13 14:56:05) Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Publishers\{54ffd262-99fe-4576-96e7-1adb500370dc}@ResourceFileName C:\Program Files\Windows NT\Accessories\WORDPAD.EXE (Windows Wordpad Application/Microsoft Corporation SIGNED)(2013-09-25 17:37:35) Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Publishers\{555908d1-a6d7-4695-8e1e-26931d2012f4}@ResourceFileName C:\Windows\system32\services.exe (Services and Controller app/Microsoft Corporation SIGNED)(2009-07-13 23:11:26) Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Publishers\{555908d1-a6d7-4695-8e1e-26931d2012f4}@ParameterFileName C:\Windows\system32\kernel32.dll (Windows NT BASE API Client DLL/Microsoft Corporation SIGNED)(2013-09-26 18:20:51) Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Publishers\{588cd2e4-a5b0-492d-a59b-f6dd3e7681c6}@ResourceFileName C:\Windows\system32\drivers\rdbss.sys (Redirected Drive Buffering SubSystem Driver/Microsoft Corporation SIGNED)(2013-09-25 17:37:18) Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Publishers\{5b004607-1087-4f16-b10e-979685a8d131}@ResourceFileName C:\Windows\system32\lsasrv.dll (LSA Server DLL/Microsoft Corporation SIGNED)(2013-11-13 14:56:05) Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Publishers\{5b0a651a-8807-45cc-9656-7579815b6af0}@ResourceFileName C:\Windows\system32\msra.exe (Windows Remote Assistance/Microsoft Corporation SIGNED)(2009-07-13 23:20:11) Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Publishers\{5b93cdfa-5f51-45e0-9fde-296983129e6c}@ResourceFileName C:\Windows\System32\LocationNotifications.exe (Location Activity/Microsoft Corporation SIGNED)(2009-07-13 23:45:32) Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Publishers\{5bbca4a8-b209-48dc-a8c7-b23d3e5216fb}@ResourceFileName C:\Windows\System32\crypt32.dll (Crypto API32/Microsoft Corporation SIGNED)(2013-11-13 14:55:49) Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Publishers\{5c8bb950-959e-4309-8908-67961a1205d5}@ResourceFileName C:\Windows\system32\ieframe.dll (Internet Browser/Microsoft Corporation SIGNED)(2013-12-13 11:08:39) Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Publishers\{5d674230-ca9f-11da-a94d-0800200c9a66}@ResourceFileName C:\Windows\system32\fveapi.dll (Windows BitLocker Drive Encryption API/Microsoft Corporation SIGNED)(2013-09-25 17:38:16) Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Publishers\{5d896912-022d-40aa-a3a8-4fa5515c76d7}@ResourceFileName C:\Windows\system32\lsm.exe (Local Session Manager Service/Microsoft Corporation SIGNED)(2013-09-25 17:37:56) Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Publishers\{5ec13d8e-4b3f-422e-a7e7-3121a1d90c7a}@ResourceFileName C:\Windows\system32\apphelp.dll (Application Compatibility Client Library/Microsoft Corporation SIGNED)(2013-09-25 17:37:48) Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Publishers\{5f92bc59-248f-4111-86a9-e393e12c6139}@ResourceFileName C:\Windows\System32\relpost.exe (Windows Diagnosis and Recovery/Microsoft Corporation SIGNED)(2013-09-25 17:36:55) Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Publishers\{61f044af-9104-4ca5-81ee-cb6c51bb01ab}@ResourceFileName C:\Windows\System32\themecpl.dll (Personalization CPL/Microsoft Corporation SIGNED)(2013-09-25 17:38:13) Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Publishers\{62ef8b9f-ee45-4aba-a9b9-b70e878bf30a}@ResourceFileName C:\Windows\system32\EventProviders\spcmsg.dll (SP Installer Msg Dll/Microsoft Corporation)(2013-09-25 17:33:26) Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Publishers\{63b530f8-29c9-4880-a5b4-b8179096e7b8}@ResourceFileName C:\Windows\system32\nlasvc.dll (Network Location Awareness 2/Microsoft Corporation SIGNED)(2013-09-25 17:37:51) Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Publishers\{63d1e632-95cc-4443-9312-af927761d52a}@ResourceFileName C:\Windows\system32\microsoft-windows-hal-events.dll (Microsoft-Windows-HAL-Events Resources/Microsoft Corporation SIGNED)(2009-07-13 23:22:28) Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Publishers\{651df93b-5053-4d1e-94c5-f6e6d25908d0}@ResourceFileName C:\Windows\system32\drivers\fvevol.sys (BitLocker Drive Encryption Driver/Microsoft Corporation SIGNED)(2013-09-25 17:37:08) Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Publishers\{65d99466-7a8e-489c-b8e1-962bc945031e}@ResourceFileName C:\Windows\system32\sud.dll (SUD Control Panel/Microsoft Corporation SIGNED)(2013-09-25 17:37:38) Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Publishers\{6600e712-c3b6-44a2-8a48-935c511f28c8}@ResourceFileName C:\Windows\system32\iphlpsvc.dll (Service that offers IPv6 connectivity over an IPv4 network./Microsoft Corporation SIGNED)(2013-09-25 17:38:18) Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Publishers\{676f167f-f72c-446e-a498-eda43319a5e3}@ResourceFileName C:\Windows\system32\ntshrui.dll (Shell extensions for sharing/Microsoft Corporation SIGNED)(2013-09-25 17:37:19) Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Publishers\{67fe2216-727a-40cb-94b2-c02211edb34a}@ResourceFileName C:\Windows\system32\drivers\volsnap.sys (Volume Shadow Copy Driver/Microsoft Corporation SIGNED)(2013-09-25 17:37:31) Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Publishers\{6863e644-dd5d-43a2-a8b5-7a81b46672e6}@ResourceFileName C:\Windows\system32\efssvc.dll (EFS Service/Microsoft Corporation SIGNED)(2009-07-13 23:33:56) Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Publishers\{6a1f2b00-6a90-4c38-95a5-5cab3b056778}@ResourceFileName C:\Windows\system32\dhcpcore6.dll (DHCPv6 Client/Microsoft Corporation SIGNED)(2009-07-13 23:12:12) Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Publishers\{6a1f2b00-6a90-4c38-95a5-5cab3b056778}@ParameterFileName C:\Windows\System32\kernelbase.dll (Windows NT BASE API Client DLL/Microsoft Corporation SIGNED)(2013-09-26 18:20:51) Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Publishers\{6a2dc7c1-930a-4fb5-bb44-80b30aebed6c}@ResourceFileName C:\Program Files\Windows Media Player\wmpnetwk.exe (Windows Media Player Network Sharing Service/Microsoft Corporation SIGNED)(2013-09-25 17:37:35) Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Publishers\{6ad52b32-d609-4be9-ae07-ce8dae937e39}@ResourceFileName C:\Windows\system32\rpcrt4.dll (Remote Procedure Call Runtime/Microsoft Corporation SIGNED)(2013-09-26 18:24:52) Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Publishers\{6addabf4-8c54-4eab-bf4f-fbef61b62eb0}@ResourceFileName C:\Windows\system32\advapi32.dll (Advanced Windows 32 Base API/Microsoft Corporation SIGNED)(2013-11-12 12:07:36) Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Publishers\{6b1ffe48-5b1e-4793-9f7f-ae926454499d}@MessageFileName C:\Windows\system32\dfdts.dll (Windows Disk Failure Diagnostic Module/Microsoft Corporation SIGNED)(2009-07-13 23:20:05) Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Publishers\{6b4db0bc-9a3d-467d-81b9-a84c6f2f3d40}@ResourceFileName C:\Windows\system32\drivers\disk.sys (PnP Disk Driver/Microsoft Corporation SIGNED)(2009-07-13 23:11:28) Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Publishers\{6b93bf66-a922-4c11-a617-cf60d95c133d}@ResourceFileName C:\Windows\system32\fthsvc.dll (Microsoft Windows Fault Tolerant Heap Diagnostic Module/Microsoft Corporation SIGNED)(2009-07-13 23:20:11) Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Publishers\{6ba132c4-da49-415b-a7f4-31870dc9fe25}@ResourceFileName C:\Windows\system32\qwave.dll (Windows NT/Microsoft Corporation SIGNED)(2009-07-13 23:54:15) Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Publishers\{6bba3851-2c7e-4dea-8f54-31e5afd029e3}@ResourceFileName C:\Windows\system32\dps.dll (WDI Diagnostic Policy Service/Microsoft Corporation SIGNED)(2013-09-25 17:38:16) Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Publishers\{6c260f2c-049a-43d8-bf4d-d350a4e6611a}@ResourceFileName C:\Windows\System32\sstpsvc.dll (Provides the facility of using Secure Socket Tunneling Protocol (SSTP) to connect to remote computers (using VPN)./Microsoft Corporation SIGNED)(2009-07-13 23:54:51) Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Publishers\{6d8a3a60-40af-445a-98ca-99359e500146}@ResourceFileName C:\Windows\system32\advapi32.dll (Advanced Windows 32 Base API/Microsoft Corporation SIGNED)(2013-11-12 12:07:36) Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Publishers\{6e400999-5b82-475f-b800-cef6fe361539}@ResourceFileName C:\Windows\system32\drivers\tsusbflt.sys (Remote Desktop USB Hub Filter Driver/Microsoft Corporation SIGNED)(2013-09-25 17:38:13) Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Publishers\{6eb8db94-fe96-443f-a366-5fe0cee7fb1c}@ResourceFileName C:\Windows\system32\eapsvc.dll (Microsoft EAPHost service/Microsoft Corporation SIGNED)(2009-07-13 23:56:40) Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Publishers\{70eb4f03-c1de-4f73-a051-33d13d5413bd}@ResourceFileName C:\Windows\system32\advapi32.dll (Advanced Windows 32 Base API/Microsoft Corporation SIGNED)(2013-11-12 12:07:36) Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Publishers\{712abb2d-d806-4b42-9682-26da01d8b307}@ResourceFileName C:\Windows\system32\mciavi32.dll (Video For Windows MCI driver/Microsoft Corporation SIGNED)(2013-09-25 17:38:28) Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Publishers\{719be4ed-e9bc-4dd8-a7cf-c85ce8e4975d}@ResourceFileName C:\Windows\system32\comres.dll (COM+ Resources/Microsoft Corporation SIGNED)(2009-07-13 23:44:02) Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Publishers\{7237fff9-a08a-4804-9c79-4a8704b70b87}@ResourceFileName C:\Windows\system32\lpksetup.exe (Language Pack Installer/Microsoft Corporation SIGNED)(2013-09-25 17:38:30) Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Publishers\{72d211e1-4c54-4a93-9520-4901681b2271}@ResourceFileName C:\Windows\system32\perfproc.dll (Windows System Process Performance Objects DLL/Microsoft Corporation SIGNED)(2009-07-13 23:19:35) Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Publishers\{73370bd6-85e5-430b-b60a-fea1285808a7}@ResourceFileName C:\Windows\system32\dimsjob.dll (DIMS Job DLL/Microsoft Corporation SIGNED)(2009-07-13 23:37:26) Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Publishers\{73e9c9de-a148-41f7-b1db-4da051fdc327}@ResourceFileName C:\Windows\System32\mdsched.exe (Windows Memory Diagnostics Tool/Microsoft Corporation SIGNED)(2013-09-25 17:38:29) Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Publishers\{7426a56b-e2d5-4b30-bdef-b31815c1a74a}@ResourceFileName C:\Windows\system32\drivers\usbhub.sys (Default Hub Driver for USB/Microsoft Corporation SIGNED)(2014-01-15 10:15:45) Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Publishers\{747ef6fd-e535-4d16-b510-42c90f6873a1}@ResourceFileName C:\Windows\system32\ntprint.dll (Spooler Setup DLL/Microsoft Corporation SIGNED)(2013-09-25 17:37:55) Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Publishers\{74c2135f-cc76-45c3-879a-ef3bb1eeaf86}@ResourceFileName C:\Windows\system32\fdrespub.dll (Function Discovery Resource Publication Service/Microsoft Corporation SIGNED)(2009-07-13 23:22:32) Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Publishers\{75ebc33e-997f-49cf-b49f-ecc50184b75d}@ResourceFileName C:\Windows\system32\oobe\winsetup.dll (Windows System Setup/Microsoft Corporation SIGNED)(2013-09-25 17:37:01) Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Publishers\{75f48521-4131-4ac3-9887-65473224fcb2}@ResourceFileName C:\Windows\system32\calc.exe (Windows Calculator/Microsoft Corporation SIGNED)(2013-09-25 17:36:17) Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Publishers\{777ba8fe-2498-4875-933a-3067de883070}@ResourceFileName C:\Windows\system32\xwizards.dll (Extensible Wizards Manager Module/Microsoft Corporation SIGNED)(2009-07-13 23:51:41) Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Publishers\{78168022-eca5-41e8-9e17-e8c7fd77aae1}@MessageFileName C:\Windows\system32\wwansvc.dll (WWAN Auto Config Service/Microsoft Corporation SIGNED)(2009-07-13 23:56:41) Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Publishers\{7a67066e-193f-4d3a-82d3-322fee5259de}@ResourceFileName C:\Windows\system32\comres.dll (COM+ Resources/Microsoft Corporation SIGNED)(2009-07-13 23:44:02) Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Publishers\{7b563579-53c8-44e7-8236-0f87b9fe6594}@ResourceFileName C:\Windows\system32\PSHED.DLL (Platform Specific Hardware Error Driver/Microsoft Corporation SIGNED)(2009-07-13 23:11:00) Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Publishers\{7b6bc78c-898b-4170-bbf8-1a469ea43fc5}@ResourceFileName C:\Windows\system32\drivers\http.sys (HTTP Protocol Stack/Microsoft Corporation SIGNED)(2013-09-25 17:37:09) Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Publishers\{7d29d58a-931a-40ac-8743-48c733045548}@ResourceFileName C:\Windows\system32\advapi32.dll (Advanced Windows 32 Base API/Microsoft Corporation SIGNED)(2013-11-12 12:07:36) Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Publishers\{7d44233d-3055-4b9c-ba64-0d47ca40a232}@ResourceFileName C:\Windows\system32\winhttp.dll (Windows HTTP Services/Microsoft Corporation SIGNED)(2013-09-25 17:38:10) Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Publishers\{7d5387b0-cbe0-11da-a94d-0800200c9a66}@ResourceFileName C:\Windows\system32\wbem\Win32_Tpm.dll (TPM WMI Provider/Microsoft Corporation SIGNED)(2009-07-13 23:13:24) Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Publishers\{7d7b0c39-93f6-4100-bd96-4dda859652c5}@ResourceFileName C:\Windows\System32\fdeploy.dll (Folder Redirection Group Policy Extension/Microsoft Corporation SIGNED)(2013-09-25 17:36:23) Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Publishers\{7da4fe0e-fd42-4708-9aa5-89b77a224885}@ResourceFileName C:\Windows\system32\netevent.dll (Net Event Handler/Microsoft Corporation SIGNED)(2009-07-13 23:12:03) Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Publishers\{7dd42a49-5329-4832-8dfd-43d979153a88}@ResourceFileName C:\Windows\system32\advapi32.dll (Advanced Windows 32 Base API/Microsoft Corporation SIGNED)(2013-11-12 12:07:36) Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Publishers\{7eafcf79-06a7-460b-8a55-bd0a0c9248aa}@ResourceFileName C:\Windows\system32\peerdistsvc.dll (BranchCache Service/Microsoft Corporation SIGNED)(2009-07-13 23:56:29) Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Publishers\{7f8e35ca-68e8-41b9-86fe-d6adc5b327e7}@ResourceFileName C:\Windows\system32\mshtml.dll (Microsoft (R) HTML Viewer/Microsoft Corporation SIGNED)(2013-12-13 11:08:38) Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Publishers\{7f912b92-21ad-496e-b97a-88622a72bc42}@ResourceFileName C:\Windows\system32\ComDlg32.dll (Common Dialogs DLL/Microsoft Corporation SIGNED)(2013-09-25 17:37:51) Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Publishers\{7f9d83de-8abb-457f-98e8-4ad161449ecc}@ResourceFileName C:\Windows\system32\perfdisk.dll (Windows Disk Performance Objects DLL/Microsoft Corporation SIGNED)(2009-07-13 23:19:30) Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Publishers\{802ec45a-1e99-4b83-9920-87c98277ba9d}@ResourceFileName C:\Windows\system32\drivers\dxgkrnl.sys (DirectX Graphics Kernel/Microsoft Corporation SIGNED)(2013-10-10 12:50:18) Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Publishers\{8115579e-2bea-4c9e-9ab1-821cc2c98ab0}@ResourceFileName C:\Windows\system32\napipsec.dll (NAP IPSec Enforcement Client/Microsoft Corporation SIGNED)(2009-07-13 23:52:11) Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Publishers\{84051b98-f508-4e54-82fa-8865c697c3b1}@ResourceFileName C:\Windows\system32\umpnpmgr.dll (User-mode Plug-and-Play Service/Microsoft Corporation SIGNED)(2013-09-25 08:16:39) Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Publishers\{8443ccb7-feb0-4b8d-8e28-8d4c7cb814e8}@ResourceFileName C:\Program Files\Common Files\Microsoft Shared\Ink\mip.exe (Math Input Panel Accessory/Microsoft Corporation SIGNED)(2013-09-25 17:37:58) Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Publishers\{86133982-63d7-4741-928e-ef1349b80219}@ResourceFileName C:\Windows\System32\stobject.dll (Systray shell service object/Microsoft Corporation SIGNED)(2013-09-25 17:36:32) Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Publishers\{8939299f-2315-4c5c-9b91-abb86aa0627d}@ResourceFileName C:\Windows\system32\shell32.dll (Windows Shell Common Dll/Microsoft Corporation SIGNED)(2013-09-26 18:21:44) Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Publishers\{899daace-4868-4295-afcd-9eb8fb497561}@ResourceFileName C:\Windows\system32\comres.dll (COM+ Resources/Microsoft Corporation SIGNED)(2009-07-13 23:44:02) Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Publishers\{89a2278b-c662-4aff-a06c-46ad3f220bca}@ResourceFileName C:\Windows\system32\dimsroam.dll (Key Roaming DIMS Provider DLL/Microsoft Corporation SIGNED)(2009-07-13 23:37:27) Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Publishers\{89b1e9f0-5aff-44a6-9b44-0a07a7ce5845}@ResourceFileName C:\Windows\System32\profsvc.dll (ProfSvc/Microsoft Corporation SIGNED)(2013-09-25 17:36:41) Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Publishers\{914ed502-b70d-4add-b758-95692854f8a3}@ResourceFileName C:\Windows\system32\drivers\pacer.sys (QoS Packet Scheduler/Microsoft Corporation SIGNED)(2009-07-13 23:53:58) Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Publishers\{91f5fb12-fdea-4095-85d5-614b495cd9de}@ResourceFileName C:\Windows\system32\radarrs.dll (Microsoft Windows Resource Exhaustion Resolver/Microsoft Corporation SIGNED)(2009-07-13 23:20:07) Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Publishers\{92ae46d7-6d9c-4727-9ed5-e49af9c24cbf}@ResourceFileName C:\Windows\system32\dwmapi.dll (Microsoft Desktop Window Manager API/Microsoft Corporation SIGNED)(2009-07-13 23:24:17) Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Publishers\{93c05d69-51a3-485e-877f-1806a8731346}@ResourceFileName C:\Windows\system32\appinfo.dll (Application Information Service/Microsoft Corporation SIGNED)(2013-09-26 18:20:28) Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Publishers\{945a8954-c147-4acd-923f-40c45405a658}@ResourceFileName C:\Windows\system32\wuaueng.dll (Windows Update Agent/Microsoft Corporation SIGNED)(2013-09-24 18:10:33) Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Publishers\{9485fa1e-23cd-49a1-84e3-11d8bc550cb7}@ResourceFileName C:\Windows\system32\propsys.dll (Microsoft Property System/Microsoft Corporation SIGNED)(2013-09-25 17:38:03) Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Publishers\{952773bf-c2b7-49bc-88f4-920744b82c43}@ResourceFileName C:\Windows\system32\umrdp.dll (Remote Desktop Services Device Redirector Service/Microsoft Corporation SIGNED)(2013-09-25 17:37:39) Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Publishers\{95353826-4fbe-41d4-9c42-f521c6e86360}@ResourceFileName C:\Windows\system32\cscsvc.dll (CSC Service DLL/Microsoft Corporation SIGNED)(2013-09-25 17:36:11) Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Publishers\{9580d7dd-0379-4658-9870-d5be7d52d6de}@ResourceFileName C:\Windows\system32\wlansvc.dll (Windows WLAN AutoConfig Service DLL/Microsoft Corporation SIGNED)(2009-07-13 23:52:01) Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Publishers\{968f313b-097f-4e09-9cdd-bc62692d138b}@ResourceFileName C:\Windows\system32\quartz.dll (DirectShow Runtime./Microsoft Corporation SIGNED)(2013-09-25 08:10:55) Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Publishers\{96ac7637-5950-4a30-b8f7-e07e8e5734c1}@ResourceFileName C:\Windows\system32\advapi32.dll (Advanced Windows 32 Base API/Microsoft Corporation SIGNED)(2013-11-12 12:07:36) Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Publishers\{96f4a050-7e31-453c-88be-9634f4e02139}@ResourceFileName C:\Windows\system32\umpnpmgr.dll (User-mode Plug-and-Play Service/Microsoft Corporation SIGNED)(2013-09-25 08:16:39) Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Publishers\{973143dd-f3c7-4ef5-b156-544ac38c39b6}@ResourceFileName C:\Windows\system32\perfctrs.dll (Performance Counters/Microsoft Corporation SIGNED)(2009-07-13 23:19:32) Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Publishers\{98bf1cd3-583e-4926-95ee-a61bf3f46470}@ResourceFileName C:\Windows\system32\certcli.dll (Microsoft� Active Directory Certificate Services Client/Microsoft Corporation SIGNED)(2013-09-25 17:38:23) Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Publishers\{98e6cfcb-ee0a-41e0-a57b-622d4e1b30b1}@ResourceFileName C:\Windows\System32\kerberos.dll (Kerberos Security Package/Microsoft Corporation SIGNED)(2013-09-25 08:10:43) Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Publishers\{99806515-9f51-4c2f-b918-1eae407aa8cb}@ResourceFileName C:\Windows\system32\sysmain.dll (Superfetch Service Host/Microsoft Corporation SIGNED)(2013-09-25 17:37:38) Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Publishers\{9988748e-c2e8-4054-85f6-0c3e1cad2470}@ResourceFileName C:\Windows\system32\radardt.dll (Microsoft Windows Resource Exhaustion Detector/Microsoft Corporation SIGNED)(2009-07-13 23:20:11) Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Publishers\{9b307223-4e4d-4bf5-9be8-995cd8e7420b}@ResourceFileName C:\Windows\system32\drivers\afd.sys (Ancillary Function Driver for WinSock/Microsoft Corporation SIGNED)(2013-11-12 12:07:18) Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Publishers\{9b307223-4e4d-4bf5-9be8-995cd8e7420b}@MessageFileName C:\Windows\system32\ws2_32.dll (Windows Socket 2.0 32-Bit DLL/Microsoft Corporation SIGNED)(2013-09-25 17:37:33) Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Publishers\{9b6123dc-9af6-4430-80d7-7d36f054fb9f}@ResourceFileName C:\Windows\system32\drivers\cdrom.sys (SCSI CD-ROM Driver/Microsoft Corporation SIGNED)(2013-09-25 17:36:17) Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Publishers\{9c205a39-1250-487d-abd7-e831c6290539}@ResourceFileName C:\Windows\system32\advapi32.dll (Advanced Windows 32 Base API/Microsoft Corporation SIGNED)(2013-11-12 12:07:36) Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Publishers\{9d55b53d-449b-4824-a637-24f9d69aa02f}@ResourceFileName C:\Windows\system32\winsrv.dll (Multi-User Windows Server DLL/Microsoft Corporation SIGNED)(2013-09-26 18:20:50) Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Publishers\{9e03f75a-bcbe-428a-8f3c-d46f2a444935}@ResourceFileName C:\Windows\system32\schedsvc.dll (Task Scheduler Service/Microsoft Corporation SIGNED)(2013-09-25 17:37:25) Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Publishers\{9e3b3947-ca5d-4614-91a2-7b624e0e7244}@ResourceFileName C:\Windows\system32\mshtml.dll (Microsoft (R) HTML Viewer/Microsoft Corporation SIGNED)(2013-12-13 11:08:38) Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Publishers\{9e5f9046-43c6-4f62-ba13-7b19896253ff}@ResourceFileName C:\Windows\system32\ieetwcollectorres.dll (IE ETW Collector Service Resources/Microsoft Corporation SIGNED)(2013-12-13 11:08:46) Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Publishers\{9e6ae157-d9f7-47e5-8c6d-b17bb6c82a27}@ResourceFileName C:\Windows\system32\drivers\fvevol.sys (BitLocker Drive Encryption Driver/Microsoft Corporation SIGNED)(2013-09-25 17:37:08) Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Publishers\{9e95e4d0-4cb4-4b5d-a936-c972d7d08d90}@ResourceFileName C:\Windows\system32\recovery.dll (Recovery Control Panel/Microsoft Corporation SIGNED)(2013-09-25 17:38:04) Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Publishers\{9f650c63-9409-453c-a652-83d7185a2e83}@ResourceFileName C:\Windows\system32\certprop.dll (Microsoft Smartcard Certificate Propagation Service/Microsoft Corporation SIGNED)(2013-09-25 17:37:47) Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Publishers\{a0e3d8ea-c34f-4419-a1db-90435b8b21d0}@ResourceFileName C:\Windows\System32\wbiosrvc.dll (Windows Biometric Service/Microsoft Corporation SIGNED)(2009-07-13 23:37:18) Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Publishers\{a319d300-015c-48be-acdb-47746e154751}@ResourceFileName C:\Windows\system32\drivers\fileinfo.sys (FileInfo Filter Driver/Microsoft Corporation SIGNED)(2009-07-13 23:21:52) Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Publishers\{a68ca8b7-004f-d7b6-a698-07e2de0f1f5d}@ResourceFileName C:\Windows\system32\advapi32.dll (Advanced Windows 32 Base API/Microsoft Corporation SIGNED)(2013-11-12 12:07:36) Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Publishers\{a6f32731-9a38-4159-a220-3d9b7fc5fe5d}@ResourceFileName C:\Windows\System32\ipnathlp.dll (Microsoft NAT Helper Components/Microsoft Corporation SIGNED)(2009-07-13 23:54:28) Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Publishers\{a83fa99f-c356-4ded-9fd6-5a5eb8546d68}@ResourceFileName C:\Windows\system32\ieframe.dll (Internet Browser/Microsoft Corporation SIGNED)(2013-12-13 11:08:39) Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Publishers\{a8a1f2f6-a13a-45e9-b1fe-3419569e5ef2}@ResourceFileName C:\Windows\system32\advapi32.dll (Advanced Windows 32 Base API/Microsoft Corporation SIGNED)(2013-11-12 12:07:36) Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Publishers\{abce23e7-de45-4366-8631-84fa6c525952}@ResourceFileName C:\Windows\system32\werfault.exe (Windows Problem Reporting/Microsoft Corporation SIGNED)(2009-07-13 23:27:32) Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Publishers\{ad5162d8-daf0-4a25-88a7-01cbeb33902e}@ResourceFileName C:\Windows\System32\wpd_ci.dll (Driver Setup Class Installer for Windows Portable Devices/Microsoft Corporation SIGNED)(2013-09-25 17:38:08) Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Publishers\{ad8aa069-a01b-40a0-ba40-948d1d8dedc5}@ResourceFileName C:\Windows\system32\werfault.exe (Windows Problem Reporting/Microsoft Corporation SIGNED)(2009-07-13 23:27:32) Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Publishers\{ae4bd3be-f36f-45b6-8d21-bdd6fb832853}@ResourceFileName C:\Windows\System32\audioses.dll (Audio Session/Microsoft Corporation SIGNED)(2013-09-25 17:36:17) Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Publishers\{aea1b4fa-97d1-45f2-a64c-4d69fffd92c9}@ResourceFileName C:\Windows\system32\gpsvc.dll (Group Policy Client/Microsoft Corporation SIGNED)(2013-09-25 17:36:25) Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Publishers\{af0a5a6d-e009-46d4-8867-42f2240f8a72}@ResourceFileName C:\Windows\system32\listsvc.dll (Windows HomeGroup/Microsoft Corporation SIGNED)(2013-09-25 17:37:57) Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Publishers\{b059b83f-d946-4b13-87ca-4292839dc2f2}@ResourceFileName C:\Windows\system32\advapi32.dll (Advanced Windows 32 Base API/Microsoft Corporation SIGNED)(2013-11-12 12:07:36) Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Publishers\{b2a40f1f-a05a-4dfd-886a-4c4f18c4334c}@ResourceFileName C:\Windows\system32\ieframe.dll (Internet Browser/Microsoft Corporation SIGNED)(2013-12-13 11:08:39) Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Publishers\{b3eee223-d0a9-40cd-adfc-50f1888138ab}@ResourceFileName C:\Windows\system32\drivers\ndisuio.sys (NDIS User mode I/O driver/Microsoft Corporation SIGNED)(2013-09-25 17:37:16) Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Publishers\{b675ec37-bdb6-4648-bc92-f3fdc74d3ca2}@ResourceFileName C:\Windows\system32\advapi32.dll (Advanced Windows 32 Base API/Microsoft Corporation SIGNED)(2013-11-12 12:07:36) Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Publishers\{b92cf7fd-dc10-4c6b-a72d-1613bf25e597}@ResourceFileName C:\Windows\system32\dot3svc.dll (Wired AutoConfig Service/Microsoft Corporation SIGNED)(2013-09-25 17:36:15) Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Publishers\{b977cf02-76f6-df84-cc1a-6a4b232322b6}@ResourceFileName C:\Windows\system32\wecsvc.dll (Event Collector Service/Microsoft Corporation SIGNED)(2009-07-13 23:30:05) Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Publishers\{ba093605-3909-4345-990b-26b746adee0a}@ResourceFileName C:\Windows\system32\cofiredm.dll (Corrupted File Recovery Diagnostic Module/Microsoft Corporation SIGNED)(2009-07-13 23:20:02) Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Publishers\{bbe94f36-f8dc-4c33-8227-81602b7a3d53}@ResourceFileName C:\Windows\system32\pnrpsvc.dll (PNRP Service Dll/Microsoft Corporation SIGNED)(2009-07-13 23:56:13) Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Publishers\{bc2eeeec-b77a-4a52-b6a4-dffb1b1370cb}@ResourceFileName C:\Windows\system32\dwm.exe (Desktop Window Manager/Microsoft Corporation SIGNED)(2009-07-13 23:24:23) Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Publishers\{bd12f3b8-fc40-4a61-a307-b7a013a069c1}@ResourceFileName C:\Windows\servicing\cbsmsg.dll (Component Based Servicing Message DLL/Microsoft Corporation SIGNED)(2009-07-13 23:22:18) Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Publishers\{bd2d1dae-d678-4e10-9667-21cba2aa70c3}@ResourceFileName C:\Windows\System32\EhStorAuthn.exe (Windows Enhanced Storage Password Authentication Program/Microsoft Corporation SIGNED)(2009-07-13 23:46:11) Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Publishers\{bd2f4252-5e1e-49fc-9a30-f3978ad89ee2}@ResourceFileName C:\Windows\system32\gpsvc.dll (Group Policy Client/Microsoft Corporation SIGNED)(2013-09-25 17:36:25) Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Publishers\{be69781c-b63b-41a1-8e24-a4fc7b3fc498}@ResourceFileName C:\Windows\System32\sens.dll (System Event Notification Service (SENS)/Microsoft Corporation SIGNED)(2009-07-13 23:21:58) Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Publishers\{bf406804-6afa-46e7-8a48-6c357e1d6d61}@ResourceFileName C:\Windows\system32\oleres.dll (Ole resource dll/Microsoft Corporation SIGNED)(2009-07-13 23:43:45) Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Publishers\{c02afc2b-e24e-4449-ad76-bcc2c2575ead}@ResourceFileName C:\Windows\system32\drivers\luafv.sys (LUA File Virtualization Filter Driver/Microsoft Corporation SIGNED)(2009-07-13 23:15:45) Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Publishers\{c06ed57a-a7bd-42d7-b5ff-77a9dec5732d}@ResourceFileName C:\Windows\system32\perftrack.dll (Microsoft Performance PerfTrack/Microsoft Corporation SIGNED)(2009-07-13 23:21:22) Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Publishers\{c100becc-d33a-4a4b-bf23-bbef4663d017}@ResourceFileName C:\Windows\system32\wcncsvc.dll (Windows Connect Now - Config Registrar Service/Microsoft Corporation SIGNED)(2013-09-25 17:36:38) Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Publishers\{c26c4f3c-3f66-4e99-8f8a-39405cfed220}@ResourceFileName C:\Windows\system32\whealogr.dll (WHEA Troubleshooter/Microsoft Corporation SIGNED)(2009-07-13 23:20:05) Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Publishers\{c514638f-7723-485b-bcfc-96565d735d4a}@ResourceFileName C:\Windows\system32\advapi32.dll (Advanced Windows 32 Base API/Microsoft Corporation SIGNED)(2013-11-12 12:07:36) Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Publishers\{c76baa63-ae81-421c-b425-340b4b24157f}@ResourceFileName C:\Windows\system32\termsrv.dll (Remote Desktop Session Host Server Remote Connections Manager/Microsoft Corporation SIGNED)(2013-09-25 17:36:29) Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Publishers\{c7bde69a-e1e0-4177-b6ef-283ad1525271}@ResourceFileName C:\Windows\system32\advapi32.dll (Advanced Windows 32 Base API/Microsoft Corporation SIGNED)(2013-11-12 12:07:36) Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Publishers\{c88a4ef5-d048-4013-9408-e04b7db2814a}@ResourceFileName C:\Windows\system32\drivers\usbport.sys (USB 1.1 & 2.0 Port Driver/Microsoft Corporation SIGNED)(2014-01-15 10:15:45) Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Publishers\{c8f7689f-3692-4d66-b0c0-9536d21082c9}@ResourceFileName C:\Windows\system32\drivers\tcpip.sys (TCP/IP Driver/Microsoft Corporation SIGNED)(2013-11-12 12:07:19) Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Publishers\{c914f0df-835a-4a22-8c70-732c9a80c634}@ResourceFileName C:\Windows\System32\reagent.dll (Microsoft Windows Recovery Agent DLL/Microsoft Corporation SIGNED)(2013-09-25 17:38:04) Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Publishers\{c91ef675-842f-4fcf-a5c9-6ea93f2e4f8b}@ResourceFileName C:\Windows\system32\ipsecsvc.dll (Windows IPsec SPD Server DLL/Microsoft Corporation SIGNED)(2013-09-25 17:37:21) Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Publishers\{c9bdb4eb-9287-4c8e-8378-6896f0d1c5ef}@ResourceFileName C:\Windows\system32\provsvc.dll (Windows HomeGroup/Microsoft Corporation SIGNED)(2013-09-25 17:37:30) Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Publishers\{ca4e628d-8567-4896-ab6b-835b221f373f}@ResourceFileName C:\Windows\system32\tquery.dll (tquery.dll/Microsoft Corporation SIGNED)(2013-09-25 17:37:02) Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Publishers\{cab2b8a5-49b9-4eec-b1b0-fac21da05a3b}@ResourceFileName C:\Windows\system32\perfnet.dll (Windows Network Service Performance Objects DLL/Microsoft Corporation SIGNED)(2009-07-13 23:19:32) Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Publishers\{cad2d809-03d9-4f46-9cf4-72aa4f04b6b9}@ResourceFileName C:\Windows\system32\tcpmon.dll (Standard TCP/IP Port Monitor DLL/Microsoft Corporation SIGNED)(2009-07-14 00:18:15) Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Publishers\{cb587ad1-cc35-4ef1-ad93-36cc82a2d319}@ResourceFileName C:\Windows\system32\drivers\ataport.sys (ATAPI Driver Extension/Microsoft Corporation SIGNED)(2013-09-25 17:38:20) Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Publishers\{cbda4dbf-8d5d-4f69-9578-be14aa540d22}@ResourceFileName C:\Windows\system32\appidapi.dll (Application Identity APIs Dll/Microsoft Corporation SIGNED)(2009-07-13 23:36:51) Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Publishers\{cd032e15-15ad-4da4-afc6-03bf83516195}@ResourceFileName C:\Windows\system32\ipbusenum.dll (PnP-X IP Bus Enumerator DLL/Microsoft Corporation SIGNED)(2009-07-13 23:22:55) Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Publishers\{cdc05e28-c449-49c6-b9d2-88cf761644df}@ResourceFileName C:\Windows\system32\pots.dll (Power Troubleshooter/Microsoft Corporation SIGNED)(2009-07-13 23:20:05) Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Publishers\{cdead503-17f5-4a3e-b7ae-df8cc2902eb9}@ResourceFileName C:\Windows\system32\drivers\ndis.sys (NDIS 6.20 driver/Microsoft Corporation SIGNED)(2013-09-25 17:37:51) Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Publishers\{ce20d1c3-a247-4c41-bcb8-3c7f52c8b805}@ResourceFileName C:\Windows\system32\ktmw32.dll (Windows KTM Win32 Client DLL/Microsoft Corporation SIGNED)(2009-07-13 23:11:05) Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Publishers\{ce8dee0b-d539-4000-b0f8-77bed049c590}@ResourceFileName C:\Windows\system32\umpo.dll (User-mode Power Service/Microsoft Corporation SIGNED)(2013-09-25 17:38:07) Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Publishers\{cfc18ec0-96b1-4eba-961b-622caee05b0a}@ResourceFileName C:\Windows\system32\diagperf.dll (Microsoft Performance Diagnostics/Microsoft Corporation SIGNED)(2013-09-25 17:36:12) Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Publishers\{d02a9c27-79b8-40d6-9b97-cf3f8b7b5d60}@ResourceFileName C:\Windows\system32\appidapi.dll (Application Identity APIs Dll/Microsoft Corporation SIGNED)(2009-07-13 23:36:51) Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Publishers\{d1bc9aff-2abf-4d71-9146-ecb2a986eb85}@ResourceFileName C:\Windows\system32\mpssvc.dll (Microsoft Protection Service/Microsoft Corporation SIGNED)(2013-09-25 17:37:22) Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Publishers\{d1d93ef7-e1f2-4f45-9943-03d245fe6c00}@ResourceFileName C:\Windows\system32\advapi32.dll (Advanced Windows 32 Base API/Microsoft Corporation SIGNED)(2013-11-12 12:07:36) Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Publishers\{d5c25f9a-4d47-493e-9184-40dd397a004d}@ResourceFileName C:\Windows\system32\ws2_32.dll (Windows Socket 2.0 32-Bit DLL/Microsoft Corporation SIGNED)(2013-09-25 17:37:33) Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Publishers\{d6f68875-cdf5-43a5-a3e3-53ffd683311c}@ResourceFileName C:\Windows\system32\cofiredm.dll (Corrupted File Recovery Diagnostic Module/Microsoft Corporation SIGNED)(2009-07-13 23:20:02) Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Publishers\{d8975f88-7ddb-4ed0-91bf-3adf48c48e0c}@ResourceFileName C:\Windows\system32\RpcEpMap.dll (RPC Endpoint Mapper/Microsoft Corporation SIGNED)(2009-07-13 23:12:08) Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Publishers\{dab065a9-620f-45ba-b5d6-d6bb8efedee9}@ResourceFileName C:\Windows\system32\SearchIndexer.exe (Microsoft Windows Search Indexer/Microsoft Corporation SIGNED)(2009-07-14 00:14:13) Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Publishers\{dab3b18c-3c0f-43e8-80b1-e44bc0dad901}@ResourceFileName C:\Windows\System32\AxInstSv.dll (ActiveX Installer Service/Microsoft Corporation SIGNED)(2013-09-25 17:38:20) Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Publishers\{db00dfb6-29f9-4a9c-9b3b-1f4f9e7d9770}@ResourceFileName C:\Windows\System32\userenv.dll (Userenv/Microsoft Corporation SIGNED)(2013-09-25 17:36:37) Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Publishers\{dbe9b383-7cf3-4331-91cc-a3cb16a3b538}@ResourceFileName C:\Windows\system32\winlogon.exe (Windows Logon Application/Microsoft Corporation SIGNED)(2013-09-25 17:36:58) Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Publishers\{dd5ef90a-6398-47a4-ad34-4dcecdef795f}@ResourceFileName C:\Windows\system32\drivers\HTTP.SYS (HTTP Protocol Stack/Microsoft Corporation SIGNED)(2013-09-25 17:37:09) Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Publishers\{dd70bc80-ef44-421b-8ac3-cd31da613a4e}@ResourceFileName C:\Windows\system32\drivers\ntfs.sys (NT File System Driver/Microsoft Corporation SIGNED)(2013-09-25 08:22:28) Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Publishers\{dd85457f-4e2d-44a5-a7a7-6253362e34dc}@ResourceFileName C:\Windows\system32\peerdistsvc.dll (BranchCache Service/Microsoft Corporation SIGNED)(2009-07-13 23:56:29) Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Publishers\{de7b24ea-73c8-4a09-985d-5bdadcfa9017}@ResourceFileName C:\Windows\system32\schedsvc.dll (Task Scheduler Service/Microsoft Corporation SIGNED)(2013-09-25 17:37:25) Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Publishers\{dea07764-0790-44de-b9c4-49677b17174f}@ResourceFileName C:\Windows\system32\fms.dll (Font Management Services/Windows (R) Codename Longhorn DDK provider SIGNED)(2013-09-25 17:38:16) Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Publishers\{e01b1a7c-c5c9-4e67-99a9-5e85acfb2e10}@ResourceFileName C:\Windows\system32\dps.dll (WDI Diagnostic Policy Service/Microsoft Corporation SIGNED)(2013-09-25 17:38:16) Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Publishers\{e104fb41-6b04-4f3a-b47d-f0df2f02b954}@ResourceFileName C:\Windows\system32\dfdts.dll (Windows Disk Failure Diagnostic Module/Microsoft Corporation SIGNED)(2009-07-13 23:20:05) Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Publishers\{e23b33b0-c8c9-472c-a5f9-f2bdfea0f156}@ResourceFileName C:\Windows\system32\sppsvc.exe (Microsoft Software Protection Platform Service/Microsoft Corporation SIGNED)(2013-09-25 17:36:31) Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Publishers\{e2816346-87f4-4f85-95c3-0c79409aa89d}@ResourceFileName C:\Windows\system32\drivers\vhdmp.sys (VHD Miniport Driver/Microsoft Corporation SIGNED)(2013-09-25 17:36:38) Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Publishers\{e4480490-85b6-11dd-ad8b-0800200c9a66}@ResourceFileName C:\Windows\system32\drivers\vdrvroot.sys (Virtual Drive Root Enumerator/Microsoft Corporation SIGNED)(2009-07-13 23:46:20) Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Publishers\{e4480490-85b6-11dd-ad8b-0800200c9a66}@MessageFileName C:\Windows\system32\drivers\vhdmp.sys (VHD Miniport Driver/Microsoft Corporation SIGNED)(2013-09-25 17:36:38) Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Publishers\{e46eead8-0c54-4489-9898-8fa79d059e0e}@ResourceFileName C:\Windows\system32\wersvc.dll (Windows Error Reporting Service/Microsoft Corporation SIGNED)(2009-07-13 23:27:27) Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Publishers\{e4d53f84-7de3-11d8-9435-505054503030}@ResourceFileName C:\Windows\System32\pla.dll (Performance Logs & Alerts/Microsoft Corporation SIGNED)(2013-09-25 17:37:17) Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Publishers\{e53c6823-7bb8-44bb-90dc-3f86090d48a6}@ResourceFileName C:\Windows\system32\drivers\afd.sys (Ancillary Function Driver for WinSock/Microsoft Corporation SIGNED)(2013-11-12 12:07:18) Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Publishers\{e53c6823-7bb8-44bb-90dc-3f86090d48a6}@MessageFileName C:\Windows\system32\ws2_32.dll (Windows Socket 2.0 32-Bit DLL/Microsoft Corporation SIGNED)(2013-09-25 17:37:33) Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Publishers\{e595f735-b42a-494b-afcd-b68666945cd3}@ResourceFileName C:\Windows\System32\mpssvc.dll (Microsoft Protection Service/Microsoft Corporation SIGNED)(2013-09-25 17:37:22) Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Publishers\{e5ba83f6-07d0-46b1-8bc7-7e669a1d31dc}@ResourceFileName C:\Windows\System32\netlogon.dll (Net Logon Services DLL/Microsoft Corporation SIGNED)(2013-09-25 17:36:40) Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Publishers\{e6307a09-292c-497e-aad6-498f68e2b619}@ResourceFileName C:\Windows\system32\sysmain.dll (Superfetch Service Host/Microsoft Corporation SIGNED)(2013-09-25 17:37:38) Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Publishers\{e670a5a2-ce74-4ab4-9347-61b815319f4c}@ResourceFileName C:\Windows\system32\dfdts.dll (Windows Disk Failure Diagnostic Module/Microsoft Corporation SIGNED)(2009-07-13 23:20:05) Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Publishers\{e7558269-3fa5-46ed-9f4d-3c6e282dde55}@ResourceFileName C:\Windows\system32\advapi32.dll (Advanced Windows 32 Base API/Microsoft Corporation SIGNED)(2013-11-12 12:07:36) Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Publishers\{e7ef96be-969f-414f-97d7-3ddb7b558ccc}@ResourceFileName C:\Windows\system32\win32k.sys (Multi-User Win32 Driver/Microsoft Corporation SIGNED)(2014-01-15 10:15:47) Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Publishers\{e8316a2d-0d94-4f52-85dd-1e15b66c5891}@ResourceFileName C:\Windows\system32\csrsrv.dll (Client Server Runtime Process/Microsoft Corporation SIGNED)(2013-09-25 08:18:56) Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Publishers\{e837619c-a2a8-4689-833f-47b48ebd2442}@MessageFileName C:\Windows\system32\peerdistsvc.dll (BranchCache Service/Microsoft Corporation SIGNED)(2009-07-13 23:56:29) Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Publishers\{e856c26a-e105-4683-a948-6920dcc42e45}@ResourceFileName C:\Windows\system32\FntCache.dll (Windows Font Cache Service/Microsoft Corporation SIGNED)(2013-09-27 07:35:27) Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Publishers\{ed6b3ba8-95b2-4cf5-a317-d4af7003884c}@ResourceFileName C:\Program Files\Windows Sidebar\Sidebar.exe (Windows Desktop Gadgets/Microsoft Corporation SIGNED)(2013-09-25 17:36:32) Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Publishers\{edd08927-9cc4-4e65-b970-c2560fb5c289}@ResourceFileName C:\Windows\system32\advapi32.dll (Advanced Windows 32 Base API/Microsoft Corporation SIGNED)(2013-11-12 12:07:36) Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Publishers\{eef54e71-0661-422d-9a98-82fd4940b820}@ResourceFileName C:\Windows\system32\aeevts.dll (Application Experience Event Resources/Microsoft Corporation SIGNED)(2009-07-13 23:20:14) Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Publishers\{ef1cc15b-46c1-414e-bb95-e76b077bd51e}@ResourceFileName C:\Windows\system32\qmgr.dll (Background Intelligent Transfer Service/Microsoft Corporation SIGNED)(2013-09-25 17:37:18) Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Publishers\{f0db7ef8-b6f3-4005-9937-feb77b9e1b43}@ResourceFileName C:\Windows\system32\pautoenr.dll (Auto Enrollment DLL/Microsoft Corporation SIGNED)(2009-07-13 23:37:34) Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Publishers\{f230d19a-5d93-47d9-a83f-53829edfb8df}@ResourceFileName C:\Windows\system32\schedsvc.dll (Task Scheduler Service/Microsoft Corporation SIGNED)(2013-09-25 17:37:25) Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Publishers\{f2c628ae-d26c-4352-9c45-74754e1e2f9f}@ResourceFileName C:\Windows\System32\mprmsg.dll (Multi-Protocol Router Service Messages DLL/Microsoft Corporation SIGNED)(2009-07-13 23:54:31) Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Publishers\{f3c5e28e-63f6-49c7-a204-e48a1bc4b09d}@ResourceFileName C:\Windows\system32\drivers\fltmgr.sys (Microsoft Filesystem Filter Manager/Microsoft Corporation SIGNED)(2009-07-13 23:11:14) Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Publishers\{f4aed7c7-a898-4627-b053-44a7caa12fcd}@ResourceFileName C:\Windows\system32\rpcrt4.dll (Remote Procedure Call Runtime/Microsoft Corporation SIGNED)(2013-09-26 18:24:52) Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Publishers\{f5344219-87a4-4399-b14a-e59cd118abb8}@ResourceFileName C:\Windows\system32\drivers\http.sys (HTTP Protocol Stack/Microsoft Corporation SIGNED)(2013-09-25 17:37:09) Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Publishers\{f5d05b38-80a6-4653-825d-c414e4ab3c68}@ResourceFileName C:\Windows\system32\drivers\classpnp.sys (SCSI Class System Dll/Microsoft Corporation SIGNED)(2009-07-13 23:11:21) Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Publishers\{f6da35ce-d312-41c8-9828-5a2e173c91b6}@ResourceFileName C:\Windows\system32\dhcpqec.dll (Microsoft DHCP NAP Enforcement Client/Microsoft Corporation SIGNED)(2009-07-13 23:52:20) Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Publishers\{f82fb576-e941-4956-a2c7-a0cf83f6450a}@ResourceFileName C:\Windows\system32\perfos.dll (Windows System Performance Objects DLL/Microsoft Corporation SIGNED)(2009-07-13 23:19:34) Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Publishers\{f997cd11-0fc9-4ab4-acba-bc742a4c0dd3}@ResourceFileName C:\Windows\system32\RpcEpMap.dll (RPC Endpoint Mapper/Microsoft Corporation SIGNED)(2009-07-13 23:12:08) Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Publishers\{fbcfac3f-8459-419f-8e48-1f0b49cdb85e}@ResourceFileName C:\Windows\system32\netprofm.dll (Network List Manager/Microsoft Corporation SIGNED)(2009-07-13 23:56:58) Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Publishers\{fc3bc8a7-2f61-449c-a8b4-22ac22058f92}@ResourceFileName C:\Windows\system32\netdiagfx.dll (Network Diagnostic Framework/Microsoft Corporation SIGNED)(2013-09-25 17:36:40) Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Publishers\{fc65ddd8-d6ef-4962-83d5-6e5cfe9ce148}@ResourceFileName C:\Windows\System32\wevtsvc.dll (Event Logging Service/Microsoft Corporation SIGNED)(2013-09-25 17:36:58) Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Publishers\{fc6f77dd-769a-470e-bcf9-1b6555a118be}@ResourceFileName C:\Windows\system32\wsepno.dll (Profile notification support for Windows Search Service/Microsoft Corporation SIGNED)(2009-07-14 00:13:03) Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Publishers\{fd771d53-8492-4057-8e35-8c02813af49b}@ResourceFileName C:\Windows\system32\werfault.exe (Windows Problem Reporting/Microsoft Corporation SIGNED)(2009-07-13 23:27:32) Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Publishers\{ffdb9886-80f3-4540-aa8b-b85192217ddf}@ResourceFileName C:\Windows\system32\mshtml.dll (Microsoft (R) HTML Viewer/Microsoft Corporation SIGNED)(2013-12-13 11:08:38) Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\XWizards\Components\{009f3b45-8a6b-4360-b997-b2a009a16402}@File Name C:\Windows\system32\xwizards.dll (Extensible Wizards Manager Module/Microsoft Corporation SIGNED)(2009-07-13 23:51:41) Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\XWizards\Components\{116ABC1A-F7DB-45A7-ADDA-D5A57A08C6FF}@File Name C:\Windows\system32\tsworkspace.dll (RemoteApp and Desktop Connection Component/Microsoft Corporation SIGNED)(2013-09-25 17:37:06) Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\XWizards\Components\{21167137-B7E3-40B6-8863-8386E8C05716}@File Name C:\Windows\System32\xwizards.dll (Extensible Wizards Manager Module/Microsoft Corporation SIGNED)(2009-07-13 23:51:41) Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\XWizards\Components\{22B6E688-B3A5-44FC-B0CE-69F20653CD61}@File Name C:\Windows\system32\tsworkspace.dll (RemoteApp and Desktop Connection Component/Microsoft Corporation SIGNED)(2013-09-25 17:37:06) Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\XWizards\Components\{3730bbf8-631a-48fb-9085-e2143c11563b}@File Name C:\Windows\system32\xwizards.dll (Extensible Wizards Manager Module/Microsoft Corporation SIGNED)(2009-07-13 23:51:41) Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\XWizards\Components\{3DECD5DD-A27B-48DC-8BAA-2682CFA265FF}@File Name C:\Windows\system32\tsworkspace.dll (RemoteApp and Desktop Connection Component/Microsoft Corporation SIGNED)(2013-09-25 17:37:06) Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\XWizards\Components\{4582eba9-6aa1-4d79-824e-728929ef455d}@File Name C:\Windows\system32\xwizards.dll (Extensible Wizards Manager Module/Microsoft Corporation SIGNED)(2009-07-13 23:51:41) Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\XWizards\Components\{5326dddc-ec38-428d-b219-ce6dadb35de3}@File Name C:\Windows\system32\van.dll (View Available Networks/Microsoft Corporation SIGNED)(2013-09-25 17:38:08) Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\XWizards\Components\{59CDB915-8232-46AD-B38B-497B8B0463AD}@File Name C:\Windows\system32\tsworkspace.dll (RemoteApp and Desktop Connection Component/Microsoft Corporation SIGNED)(2013-09-25 17:37:06) Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\XWizards\Components\{622a8646-1096-4765-8e07-91a3e661cef9}@File Name C:\Windows\system32\xwizards.dll (Extensible Wizards Manager Module/Microsoft Corporation SIGNED)(2009-07-13 23:51:41) Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\XWizards\Components\{7940ACF8-60BA-4213-A7C3-F3B400EE266D}@File Name C:\Windows\system32\tsworkspace.dll (RemoteApp and Desktop Connection Component/Microsoft Corporation SIGNED)(2013-09-25 17:37:06) Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\XWizards\Components\{8c1645b0-9864-465e-be75-990b030e4b11}@File Name C:\Windows\system32\xwizards.dll (Extensible Wizards Manager Module/Microsoft Corporation SIGNED)(2009-07-13 23:51:41) Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\XWizards\Components\{984F9804-3314-4FA4-AC8C-E688D4133C51}@File Name C:\Windows\system32\tsworkspace.dll (RemoteApp and Desktop Connection Component/Microsoft Corporation SIGNED)(2013-09-25 17:37:06) Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\XWizards\Components\{C03E8581-781E-49A1-8190-CE902D0B2CE7}@File Name C:\Windows\System32\xwizards.dll (Extensible Wizards Manager Module/Microsoft Corporation SIGNED)(2009-07-13 23:51:41) Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\XWizards\Components\{DB4F3FA7-5A08-4100-95DE-B46DF509B902}@File Name C:\Windows\system32\VAN.dll (View Available Networks/Microsoft Corporation SIGNED)(2013-09-25 17:38:08) Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\XWizards\Factory\{009f3b45-8a6b-4360-b997-b2a009a16402}@File Name C:\Windows\system32\xwizards.dll (Extensible Wizards Manager Module/Microsoft Corporation SIGNED)(2009-07-13 23:51:41) Reg HKLM\SOFTWARE\Microsoft\Windows\TabletPC\Snipping Tool\LinkFingerprints\IEFrame@Name C:\Windows\system32\ieframe.dll (Internet Browser/Microsoft Corporation SIGNED)(2013-12-13 11:08:39) Reg HKLM\SOFTWARE\Microsoft\Windows Mail\Advanced Settings\Contacts@PlugUIText C:\Program Files\Common Files\System\wab32res.dll (Microsoft (R) Contacts DLL/Microsoft Corporation SIGNED)(2009-07-13 23:42:15) Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\APITracing@IncludeModules C:\Windows\system32\advapi32.dll (Advanced Windows 32 Base API/Microsoft Corporation SIGNED)(2013-11-12 12:07:36) Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\MCI32@AVIVideo C:\Windows\system32\mciavi32.dll (Video For Windows MCI driver/Microsoft Corporation SIGNED)(2013-09-25 17:38:28) Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\PeerDist\Roaming@RefreshDllName C:\Windows\system32\userenv.dll (Userenv/Microsoft Corporation SIGNED)(2013-09-25 17:36:37) Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Perflib\_V2Providers\{0fbd1ae9-8e6f-4e53-8434-676cbb70d31f}@ApplicationIdentity C:\Windows\system32\tbssvc.dll (TBS Service/Microsoft Corporation SIGNED)(2009-07-13 23:12:41) Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Perflib\_V2Providers\{2538387c-08b7-44b8-86d3-47f59cf6d056}@ApplicationIdentity C:\Windows\system32\PeerDistSvc.dll (BranchCache Service/Microsoft Corporation SIGNED)(2009-07-13 23:56:29) Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Perflib\_V2Providers\{383487a6-3676-4870-a4e7-d45b30c35629}@ApplicationIdentity C:\Windows\system32\advapi32.dll (Advanced Windows 32 Base API/Microsoft Corporation SIGNED)(2013-11-12 12:07:36) Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Perflib\_V2Providers\{3def464b-f31b-4117-8fb7-bb829a0e1a15}@ApplicationIdentity C:\Windows\system32\drivers\ndis.sys (NDIS 6.20 driver/Microsoft Corporation SIGNED)(2013-09-25 17:37:51) Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Perflib\_V2Providers\{420a6c98-914e-40fc-9a0f-80c7db801780}@ApplicationIdentity C:\Windows\system32\NetLogon.dll (Net Logon Services DLL/Microsoft Corporation SIGNED)(2013-09-25 17:36:40) Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Perflib\_V2Providers\{74800676-866f-4bbd-8680-dac6a6fb6c8e}@ApplicationIdentity C:\Windows\system32\umpo.dll (User-mode Power Service/Microsoft Corporation SIGNED)(2013-09-25 17:38:07) Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Perflib\_V2Providers\{a3886623-dd46-48fc-a1f9-e3da35125995}@ApplicationIdentity C:\Windows\system32\iphlpsvc.dll (Service that offers IPv6 connectivity over an IPv4 network./Microsoft Corporation SIGNED)(2013-09-25 17:38:18) Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Perflib\_V2Providers\{b074239f-e5d4-4044-907f-db3e87810b36}@ApplicationIdentity C:\Windows\system32\fwpuclnt.dll (FWP/IPsec User-Mode API/Microsoft Corporation SIGNED)(2013-11-13 14:55:55) Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Perflib\_V2Providers\{b1c6de93-e020-4ad9-9ca5-4dd5553004cf}@ApplicationIdentity C:\Windows\system32\cscsvc.dll (CSC Service DLL/Microsoft Corporation SIGNED)(2013-09-25 17:36:11) Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Perflib\_V2Providers\{db314ee3-3157-4e56-8fd9-2184874d195d}@ApplicationIdentity C:\Windows\system32\fxsresm.dll (Microsoft Fax Resource DLL/Microsoft Corporation SIGNED)(2009-07-14 00:15:02) Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Perflib\_V2Providers\{e08d5971-88fb-4799-b066-6978845f73c1}@ApplicationIdentity C:\Windows\system32\pnrpsvc.dll (PNRP Service Dll/Microsoft Corporation SIGNED)(2009-07-13 23:56:13) Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Perflib\_V2Providers\{ef63b92d-c5a6-4314-ac9f-cc6b1c56fb9c}@ApplicationIdentity C:\Windows\system32\fwpuclnt.dll (FWP/IPsec User-Mode API/Microsoft Corporation SIGNED)(2013-11-13 14:55:55) Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Perflib\_V2Providers\{f25a20a5-fd7a-417b-afc3-76295ebac77c}@ApplicationIdentity C:\Windows\system32\drivers\pacer.sys (QoS Packet Scheduler/Microsoft Corporation SIGNED)(2009-07-13 23:53:58) Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Perflib\_V2Providers\{f3b975e7-e068-4f66-81ef-b23e0a0e64c9}@ApplicationIdentity C:\Windows\system32\lsm.exe (Local Session Manager Service/Microsoft Corporation SIGNED)(2013-09-25 17:37:56) Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\PerHwIdStorage\AVC#CAMCORDER@Icons C:\Windows\system32\shell32.dll (Windows Shell Common Dll/Microsoft Corporation SIGNED)(2013-09-26 18:21:44) Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\PerHwIdStorage\SD#class_MMC@Label C:\Windows\system32\sysclass.dll (System Class Installer Library/Microsoft Corporation SIGNED)(2013-09-25 17:36:27) Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\PerHwIdStorage\USB#VID_0781&PID_0001@Icons C:\Windows\system32\shell32.dll (Windows Shell Common Dll/Microsoft Corporation SIGNED)(2013-09-26 18:21:44) Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Print\PackageInstallation\Windows NT x86\DriverPackages\mg4200p3.inf_x86_neutral_ddf396409cadf617@DriverStorePath C:\Windows\System32\DriverStore\FileRepository\mg4200p3.inf_x86_neutral_ddf396409cadf617\mg4200p3.inf(2013-10-07 14:47:46) Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Print\PackageInstallation\Windows NT x86\DriverPackages\prnms001.inf_x86_neutral_a1ff1bc29207b04f@DriverStorePath C:\Windows\System32\DriverStore\FileRepository\prnms001.inf_x86_neutral_a1ff1bc29207b04f\prnms001.Inf(2013-09-25 17:37:17) Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Print\PackageInstallation\Windows NT x86\DriverPackages\prnms002.inf_x86_neutral_baa1493e6380688b@DriverStorePath C:\Windows\System32\DriverStore\FileRepository\prnms002.inf_x86_neutral_baa1493e6380688b\prnms002.inf(2013-09-25 17:36:42) Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ProfileLoader\{F5441CBB-AE7D-4495-905B-161047E58936}@DllName C:\Windows\system32\userenv.dll (Userenv/Microsoft Corporation SIGNED)(2013-09-25 17:36:37) Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SeCEdit\Reg Values\MACHINE/Software/Microsoft/Windows/CurrentVersion/Policies/System/ConsentPromptBehaviorAdmin@DisplayName C:\Windows\system32\appinfo.dll (Application Information Service/Microsoft Corporation SIGNED)(2013-09-26 18:20:28) Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Time Zones\Afghanistan Standard Time@MUI_Display C:\Windows\system32\tzres.dll (Time Zones resource DLL/Microsoft Corporation SIGNED)(2013-12-12 19:23:30) Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon@Shell C:\Windows\explorer.exe (Windows Explorer/Microsoft Corporation SIGNED)(2013-09-25 17:37:42) Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\GPExtensions\{0E28E245-9368-4853-AD84-6DA3BA35BB75}@DllName C:\Windows\system32\gpprefcl.dll (Group Policy Preference Client/Microsoft Corporation SIGNED)(2013-09-25 17:37:46) Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\GPExtensions\{25537BA6-77A8-11D2-9B6C-0000F8080861}@DllName C:\Windows\system32\fdeploy.dll (Folder Redirection Group Policy Extension/Microsoft Corporation SIGNED)(2013-09-25 17:36:23) Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\GPExtensions\{3610eda5-77ef-11d2-8dc5-00c04fa31a66}@DisplayName C:\Windows\System32\dskquota.dll (Windows Shell Disk Quota Support DLL/Microsoft Corporation SIGNED)(2009-07-13 23:41:14) Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\GPExtensions\{3A0DBA37-F8B2-4356-83DE-3E90BD5C261F}@DllName C:\Windows\system32\gpprefcl.dll (Group Policy Preference Client/Microsoft Corporation SIGNED)(2013-09-25 17:37:46) Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\GPExtensions\{827D319E-6EAC-11D2-A4EA-00C04F79F83A}@DllName C:\Windows\system32\scecli.dll (Windows Security Configuration Editor Client Engine/Microsoft Corporation SIGNED)(2013-09-25 17:38:02) Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\GPExtensions\{91FBB303-0CD5-4055-BF42-E512A681B325}@DllName C:\Windows\system32\gpprefcl.dll (Group Policy Preference Client/Microsoft Corporation SIGNED)(2013-09-25 17:37:46) Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\GPExtensions\{c6dc5466-785a-11d2-84d0-00c04fb169f7}@DllName C:\Windows\system32\appmgmts.dll (Software installation Service/Microsoft Corporation SIGNED)(2009-07-13 23:38:34) Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\GPExtensions\{e437bc1c-aa7d-11d2-a382-00c04f991e27}@DllName C:\Windows\System32\polstore.dll (Policy Storage dll/Microsoft Corporation SIGNED)(2009-07-13 23:53:04) Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\GPExtensions\{E47248BA-94CC-49c4-BBB5-9EB7F05183D0}@DllName C:\Windows\system32\gpprefcl.dll (Group Policy Preference Client/Microsoft Corporation SIGNED)(2013-09-25 17:37:46) Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\WOW\boot@drivers C:\Windows\system32\mmsystem.dll Reg HKLM\SOFTWARE\Microsoft\Windows Search\Capabilities@ApplicationDescription C:\Windows\explorer.exe (Windows Explorer/Microsoft Corporation SIGNED)(2013-09-25 17:37:42) Reg HKLM\SOFTWARE\Classes\.bmp\ShellNew@ItemName C:\Windows\system32\mspaint.exe (Paint/Microsoft Corporation SIGNED)(2009-07-13 23:43:12) Reg HKLM\SOFTWARE\Classes\.contact\ShellNew@command C:\Program Files\Windows Mail\Wab.exe (Windows Contacts/Microsoft Corporation SIGNED)(2013-09-25 17:36:58) Reg HKLM\SOFTWARE\Classes\.contact\ShellNew@MenuText C:\Program Files\Common Files\system\wab32res.dll (Microsoft (R) Contacts DLL/Microsoft Corporation SIGNED)(2009-07-13 23:42:15) Reg HKLM\SOFTWARE\Classes\.jnt\jntfile\ShellNew@ItemName C:\Program Files\Windows Journal\Journal.exe (Windows Journal/Microsoft Corporation SIGNED)(2013-09-25 17:36:18) Reg HKLM\SOFTWARE\Classes\.library-ms\ShellNew@IconPath C:\Windows\System32\imageres.dll (Windows Image Resource/Microsoft Corporation SIGNED)(2009-07-13 23:42:24) Reg HKLM\SOFTWARE\Classes\.lnk\ShellNew@IconPath C:\Windows\system32\shell32.dll (Windows Shell Common Dll/Microsoft Corporation SIGNED)(2013-09-26 18:21:44) Reg HKLM\SOFTWARE\Classes\.rtf\ShellNew@ItemName C:\Program Files\Windows NT\Accessories\WORDPAD.EXE (Windows Wordpad Application/Microsoft Corporation SIGNED)(2013-09-25 17:37:35) Reg HKLM\SOFTWARE\Classes\acrobat\shell\open\command@ C:\Program Files\Adobe\Reader 11.0\Reader\AcroRd32.exe (Adobe Reader /CA SIGNED)(2013-12-21 06:04:26) Reg HKLM\SOFTWARE\Classes\AlcoholAutoPlayV2\Shell\BurnDisc\command@ C:\Program Files\Alcohol Soft\Alcohol 120\Alcohol.exe (Alcohol 120%/Alcohol Soft Development Team SIGNED)(2013-11-12 05:07:22) Reg HKLM\SOFTWARE\Classes\anifile@FriendlyTypeName C:\Windows\system32\main.cpl (Mouse and Keyboard Control Panel Applets/Microsoft Corporation SIGNED)(2013-09-25 17:36:21) Reg HKLM\SOFTWARE\Classes\AppID\{1C749B87-568C-4865-8E73-6413F8372CE6}@ C:\Windows\system32\lpksetup.exe (Language Pack Installer/Microsoft Corporation SIGNED)(2013-09-25 17:38:30) Reg HKLM\SOFTWARE\Classes\AppID\{4BC67F23-D805-4384-BCA3-6F1EDFF50E2C}@ C:\Windows\system32\wercplsupport.dll (Problem Reports and Solutions/Microsoft Corporation SIGNED)(2009-07-13 23:27:26) Reg HKLM\SOFTWARE\Classes\AppID\{c2a71820-3463-498f-bab7-4798795a2ff6}@ C:\Windows\system32\provsvc.dll (Windows HomeGroup/Microsoft Corporation SIGNED)(2013-09-25 17:37:30) Reg HKLM\SOFTWARE\Classes\AppID\{D3E34B21-9D75-101A-8C3D-00AA001A1652}@LocalizedString C:\Windows\system32\mspaint.exe (Paint/Microsoft Corporation SIGNED)(2009-07-13 23:43:12) Reg HKLM\SOFTWARE\Classes\Applications\AcroRD32.exe\shell\Read\command@ C:\Program Files\Adobe\Reader 11.0\Reader\AcroRd32.exe (Adobe Reader /CA SIGNED)(2013-12-21 06:04:26) Reg HKLM\SOFTWARE\Classes\Applications\dreamweaver.exe\shell\open\command@ C:\Program Files\Macromedia\Dreamweaver 8\Dreamweaver.exe (Dreamweaver 8/Macromedia, Inc.)(2005-09-27 16:14:08) Reg HKLM\SOFTWARE\Classes\Applications\explorer.exe@TaskbarGroupIcon C:\Windows\System32\imageres.dll (Windows Image Resource/Microsoft Corporation SIGNED)(2009-07-13 23:42:24) Reg HKLM\SOFTWARE\Classes\Applications\iexplore.exe\shell\open\command@ C:\Program Files\Internet Explorer\iexplore.exe (Internet Explorer/Microsoft Corporation SIGNED)(2013-11-12 12:08:36) Reg HKLM\SOFTWARE\Classes\Applications\mspaint.exe\shell\edit\command@ C:\Windows\system32\mspaint.exe (Paint/Microsoft Corporation SIGNED)(2009-07-13 23:43:12) Reg HKLM\SOFTWARE\Classes\Applications\vlc.exe\shell\Open\command@ C:\Program Files\VideoLAN\VLC\vlc.exe (VLC media player 2.1.2/VideoLAN)(2013-12-09 00:18:16) Reg HKLM\SOFTWARE\Classes\Applications\wab.exe@FriendlyAppName C:\Program Files\Common Files\System\wab32res.dll (Microsoft (R) Contacts DLL/Microsoft Corporation SIGNED)(2009-07-13 23:42:15) Reg HKLM\SOFTWARE\Classes\Applications\wmplayer.exe@FriendlyAppName C:\Windows\system32\wmploc.dll (Windows Media Player Resources/Microsoft Corporation SIGNED)(2013-09-25 17:37:01) Reg HKLM\SOFTWARE\Classes\Applications\wmplayer.exe\shell\open\command@ C:\Program Files\Windows Media Player\wmplayer.exe (Windows Media Player/Microsoft Corporation SIGNED)(2013-09-25 17:37:02) Reg HKLM\SOFTWARE\Classes\Applications\wordpad.exe@FriendlyAppName C:\Windows\system32\shell32.dll (Windows Shell Common Dll/Microsoft Corporation SIGNED)(2013-09-26 18:21:44) Reg HKLM\SOFTWARE\Classes\Applications\wordpad.exe\shell\open\command@ C:\Program Files\Windows NT\Accessories\WORDPAD.EXE (Windows Wordpad Application/Microsoft Corporation SIGNED)(2013-09-25 17:37:35) Reg HKLM\SOFTWARE\Classes\asaxfile\shell\edit\command@ C:\Program Files\Macromedia\Dreamweaver 8\dreamweaver.exe (Dreamweaver 8/Macromedia, Inc.)(2005-09-27 16:14:08) Reg HKLM\SOFTWARE\Classes\AudioCD@FriendlyTypeName C:\Windows\system32\shell32.dll (Windows Shell Common Dll/Microsoft Corporation SIGNED)(2013-09-26 18:21:44) Reg HKLM\SOFTWARE\Classes\AudioCD\shell\play\command@ C:\Program Files\Windows Media Player\wmplayer.exe (Windows Media Player/Microsoft Corporation SIGNED)(2013-09-25 17:37:02) Reg HKLM\SOFTWARE\Classes\AudioCD\shell\PlayWithVLC\command@ C:\Program Files\VideoLAN\VLC\vlc.exe (VLC media player 2.1.2/VideoLAN)(2013-12-09 00:18:16) Reg HKLM\SOFTWARE\Classes\Automap.Map.EU.17\shell\open\command@ C:\Program Files\Microsoft AutoRoute 2010\AutoRout.exe (Microsoft AutoRoute 2010/Microsoft Corporation SIGNED)(2009-10-20 15:12:40) Reg HKLM\SOFTWARE\Classes\AutoProxyTypes\Application/x-ns-proxy-autoconfig@DllFile C:\Windows\system32\jsproxy.dll (JScript Proxy Auto-Configuration/Microsoft Corporation SIGNED)(2013-12-13 11:08:47) Reg HKLM\SOFTWARE\Classes\avgfilevault\Shell\open\command@ C:\Program Files\AVG\AVG2014\avgui.exe (AVG User Interface/AVG Technologies CZ, s.r.o. SIGNED)(2013-11-07 22:03:50) Reg HKLM\SOFTWARE\Classes\batfile\shell\runas\command@ C:\Windows\System32\cmd.exe (Windows Command Processor/Microsoft Corporation SIGNED)(2013-09-25 17:36:17) Reg HKLM\SOFTWARE\Classes\batfile\shell\runasuser@ C:\Windows\system32\shell32.dll (Windows Shell Common Dll/Microsoft Corporation SIGNED)(2013-09-26 18:21:44) Reg HKLM\SOFTWARE\Classes\CABFolder\shell\find\command@ C:\Windows\Explorer.exe (Windows Explorer/Microsoft Corporation SIGNED)(2013-09-25 17:37:42) Reg HKLM\SOFTWARE\Classes\certificate_wab_auto_file@FriendlyTypeName C:\Program Files\Common Files\System\wab32res.dll (Microsoft (R) Contacts DLL/Microsoft Corporation SIGNED)(2009-07-13 23:42:15) Reg HKLM\SOFTWARE\Classes\certificate_wab_auto_file\shell\open\command@ C:\Program Files\Windows Mail\wab.exe (Windows Contacts/Microsoft Corporation SIGNED)(2013-09-25 17:36:58) Reg HKLM\SOFTWARE\Classes\chkfile@InfoTip C:\Windows\system32\ulib.dll (File Utilities Support DLL/Microsoft Corporation SIGNED)(2009-07-13 23:15:00) Reg HKLM\SOFTWARE\Classes\CLSID\{0000002F-0000-0000-C000-000000000046}\InprocServer32@ C:\Windows\system32\oleaut32.dll (Microsoft Corporation SIGNED)(2013-09-25 08:15:54) Reg HKLM\SOFTWARE\Classes\CLSID\{00000300-0000-0000-C000-000000000046}\InprocServer32@ C:\Windows\system32\ole32.dll (Microsoft OLE for Windows/Microsoft Corporation SIGNED)(2013-09-25 17:36:42) Reg HKLM\SOFTWARE\Classes\CLSID\{00000315-0000-0000-C000-000000000046}\AuxUserType\2@LocalizedString C:\Windows\system32\oleres.dll (Ole resource dll/Microsoft Corporation SIGNED)(2009-07-13 23:43:45) Reg HKLM\SOFTWARE\Classes\CLSID\{00000315-0000-0000-C000-000000000046}\InprocServer32@ C:\Windows\system32\ole32.dll (Microsoft OLE for Windows/Microsoft Corporation SIGNED)(2013-09-25 17:36:42) Reg HKLM\SOFTWARE\Classes\CLSID\{00000316-0000-0000-C000-000000000046}\AuxUserType\2@LocalizedString C:\Windows\system32\oleres.dll (Ole resource dll/Microsoft Corporation SIGNED)(2009-07-13 23:43:45) Reg HKLM\SOFTWARE\Classes\CLSID\{00000316-0000-0000-C000-000000000046}\InprocServer32@ C:\Windows\system32\ole32.dll (Microsoft OLE for Windows/Microsoft Corporation SIGNED)(2013-09-25 17:36:42) Reg HKLM\SOFTWARE\Classes\CLSID\{00000319-0000-0000-C000-000000000046}\AuxUserType\2@LocalizedString C:\Windows\system32\oleres.dll (Ole resource dll/Microsoft Corporation SIGNED)(2009-07-13 23:43:45) Reg HKLM\SOFTWARE\Classes\CLSID\{00000319-0000-0000-C000-000000000046}\InprocServer32@ C:\Windows\system32\ole32.dll (Microsoft OLE for Windows/Microsoft Corporation SIGNED)(2013-09-25 17:36:42) Reg HKLM\SOFTWARE\Classes\CLSID\{00020000-0000-0000-C000-000000000046}\InprocServer@ C:\Windows\system32\avifile.dll Reg HKLM\SOFTWARE\Classes\CLSID\{00020420-0000-0000-C000-000000000046}\InprocServer@ C:\Windows\system32\ole2disp.dll Reg HKLM\SOFTWARE\Classes\CLSID\{00020420-0000-0000-C000-000000000046}\InprocServer32@ C:\Windows\system32\oleaut32.dll (Microsoft Corporation SIGNED)(2013-09-25 08:15:54) Reg HKLM\SOFTWARE\Classes\CLSID\{00020421-0000-0000-C000-000000000046}\InprocServer@ C:\Windows\system32\ole2disp.dll Reg HKLM\SOFTWARE\Classes\CLSID\{00020421-0000-0000-C000-000000000046}\InprocServer32@ C:\Windows\system32\oleaut32.dll (Microsoft Corporation SIGNED)(2013-09-25 08:15:54) Reg HKLM\SOFTWARE\Classes\CLSID\{00020422-0000-0000-C000-000000000046}\InprocServer@ C:\Windows\system32\ole2disp.dll Reg HKLM\SOFTWARE\Classes\CLSID\{00020422-0000-0000-C000-000000000046}\InprocServer32@ C:\Windows\system32\oleaut32.dll (Microsoft Corporation SIGNED)(2013-09-25 08:15:54) Reg HKLM\SOFTWARE\Classes\CLSID\{00020423-0000-0000-C000-000000000046}\InprocServer@ C:\Windows\system32\ole2disp.dll Reg HKLM\SOFTWARE\Classes\CLSID\{00020423-0000-0000-C000-000000000046}\InprocServer32@ C:\Windows\system32\oleaut32.dll (Microsoft Corporation SIGNED)(2013-09-25 08:15:54) Reg HKLM\SOFTWARE\Classes\CLSID\{00020424-0000-0000-C000-000000000046}\InprocServer@ C:\Windows\system32\ole2disp.dll Reg HKLM\SOFTWARE\Classes\CLSID\{00020424-0000-0000-C000-000000000046}\InprocServer32@ C:\Windows\system32\oleaut32.dll (Microsoft Corporation SIGNED)(2013-09-25 08:15:54) Reg HKLM\SOFTWARE\Classes\CLSID\{00020425-0000-0000-C000-000000000046}\InprocServer@ C:\Windows\system32\ole2disp.dll Reg HKLM\SOFTWARE\Classes\CLSID\{00020425-0000-0000-C000-000000000046}\InprocServer32@ C:\Windows\system32\oleaut32.dll (Microsoft Corporation SIGNED)(2013-09-25 08:15:54) Reg HKLM\SOFTWARE\Classes\CLSID\{00020800-0000-0000-C000-000000000046}\InprocHandler32@ C:\Windows\system32\ole32.dll (Microsoft OLE for Windows/Microsoft Corporation SIGNED)(2013-09-25 17:36:42) Reg HKLM\SOFTWARE\Classes\CLSID\{00020820-0000-0000-C000-000000000046}\LocalServer@ C:\PROGRA~1\MICROS~1\OFFICE11\EXCEL.EXE (Microsoft Office Excel/Microsoft Corporation SIGNED)(2013-05-29 09:08:26) Reg HKLM\SOFTWARE\Classes\CLSID\{00020821-0000-0000-C000-000000000046}\InprocHandler32@ C:\Windows\system32\ole32.dll (Microsoft OLE for Windows/Microsoft Corporation SIGNED)(2013-09-25 17:36:42) Reg HKLM\SOFTWARE\Classes\CLSID\{00020821-0000-0000-C000-000000000046}\LocalServer32@ C:\PROGRA~1\MICROS~1\OFFICE11\EXCEL.EXE (Microsoft Office Excel/Microsoft Corporation SIGNED)(2013-05-29 09:08:26) Reg HKLM\SOFTWARE\Classes\CLSID\{00020906-0000-0000-C000-000000000046}\InprocHandler32@ C:\Windows\system32\ole32.dll (Microsoft OLE for Windows/Microsoft Corporation SIGNED)(2013-09-25 17:36:42) Reg HKLM\SOFTWARE\Classes\CLSID\{00020906-0000-0000-C000-000000000046}\LocalServer32@ C:\PROGRA~1\MICROS~1\OFFICE11\WINWORD.EXE (Microsoft Office Word/Microsoft Corporation SIGNED)(2013-08-27 09:04:02) Reg HKLM\SOFTWARE\Classes\CLSID\{00020907-0000-0000-C000-000000000046}\InprocHandler32@ C:\Windows\system32\ole32.dll (Microsoft OLE for Windows/Microsoft Corporation SIGNED)(2013-09-25 17:36:42) Reg HKLM\SOFTWARE\Classes\CLSID\{00020907-0000-0000-C000-000000000046}\LocalServer32@ C:\PROGRA~1\MICROS~1\OFFICE11\WINWORD.EXE (Microsoft Office Word/Microsoft Corporation SIGNED)(2013-08-27 09:04:02) Reg HKLM\SOFTWARE\Classes\CLSID\{000209FE-0000-0000-C000-000000000046}\InprocHandler@ C:\Windows\system32\ole2.dll Reg HKLM\SOFTWARE\Classes\CLSID\{000209FE-0000-0000-C000-000000000046}\InprocHandler32@ C:\Windows\system32\ole32.dll (Microsoft OLE for Windows/Microsoft Corporation SIGNED)(2013-09-25 17:36:42) Reg HKLM\SOFTWARE\Classes\CLSID\{00020D09-0000-0000-C000-000000000046}\LocalServer32@ C:\PROGRA~1\MICROS~1\OFFICE11\OUTLOOK.EXE (Microsoft Office Outlook/Microsoft Corporation SIGNED)(2007-05-31 12:42:14) Reg HKLM\SOFTWARE\Classes\CLSID\{00021400-0000-0000-C000-000000000046}\InProcServer32@ C:\Windows\system32\shell32.dll (Windows Shell Common Dll/Microsoft Corporation SIGNED)(2013-09-26 18:21:44) Reg HKLM\SOFTWARE\Classes\CLSID\{00021A14-0000-0000-C000-000000000046}\InprocHandler32@ C:\Windows\system32\ole32.dll (Microsoft OLE for Windows/Microsoft Corporation SIGNED)(2013-09-25 17:36:42) Reg HKLM\SOFTWARE\Classes\CLSID\{00021A14-0000-0000-C000-000000000046}\LocalServer32@ C:\PROGRA~1\MICROS~1\Visio11\VISIO.EXE (Microsoft Office Visio/Microsoft Corporation SIGNED)(2007-06-20 05:34:38) Reg HKLM\SOFTWARE\Classes\CLSID\{00024500-0000-0000-C000-000000000046}\InprocHandler32@ C:\Windows\system32\ole32.dll (Microsoft OLE for Windows/Microsoft Corporation SIGNED)(2013-09-25 17:36:42) Reg HKLM\SOFTWARE\Classes\CLSID\{0002DF01-0000-0000-C000-000000000046}\LocalServer32@ C:\Program Files\Internet Explorer\iexplore.exe (Internet Explorer/Microsoft Corporation SIGNED)(2013-11-12 12:08:36) Reg HKLM\SOFTWARE\Classes\CLSID\{0002E005-0000-0000-C000-000000000046}\InprocServer32@ C:\Windows\system32\OLE32.DLL (Microsoft OLE for Windows/Microsoft Corporation SIGNED)(2013-09-25 17:36:42) Reg HKLM\SOFTWARE\Classes\CLSID\{0006F005-0000-0000-C000-000000000046}\LocalServer32@ C:\PROGRA~1\MICROS~1\OFFICE11\OUTLOOK.EXE (Microsoft Office Outlook/Microsoft Corporation SIGNED)(2007-05-31 12:42:14) Reg HKLM\SOFTWARE\Classes\CLSID\{0006F006-0000-0000-C000-000000000046}\InprocHandler32@ C:\Windows\system32\ole32.dll (Microsoft OLE for Windows/Microsoft Corporation SIGNED)(2013-09-25 17:36:42) Reg HKLM\SOFTWARE\Classes\CLSID\{0006F006-0000-0000-C000-000000000046}\LocalServer32@ C:\PROGRA~1\MICROS~1\OFFICE11\OUTLOOK.EXE (Microsoft Office Outlook/Microsoft Corporation SIGNED)(2007-05-31 12:42:14) Reg HKLM\SOFTWARE\Classes\CLSID\{0006F011-0000-0000-C000-000000000046}\InprocHandler32@ C:\Windows\system32\ole32.dll (Microsoft OLE for Windows/Microsoft Corporation SIGNED)(2013-09-25 17:36:42) Reg HKLM\SOFTWARE\Classes\CLSID\{0006F011-0000-0000-C000-000000000046}\LocalServer32@ C:\PROGRA~1\MICROS~1\OFFICE11\OUTLOOK.EXE (Microsoft Office Outlook/Microsoft Corporation SIGNED)(2007-05-31 12:42:14) Reg HKLM\SOFTWARE\Classes\CLSID\{0006F01E-0000-0000-C000-000000000046}\InprocHandler32@ C:\Windows\system32\ole32.dll (Microsoft OLE for Windows/Microsoft Corporation SIGNED)(2013-09-25 17:36:42) Reg HKLM\SOFTWARE\Classes\CLSID\{0006F01E-0000-0000-C000-000000000046}\LocalServer32@ C:\PROGRA~1\MICROS~1\OFFICE11\OUTLOOK.EXE (Microsoft Office Outlook/Microsoft Corporation SIGNED)(2007-05-31 12:42:14) Reg HKLM\SOFTWARE\Classes\CLSID\{0006F020-0000-0000-C000-000000000046}\InprocHandler32@ C:\Windows\system32\ole32.dll (Microsoft OLE for Windows/Microsoft Corporation SIGNED)(2013-09-25 17:36:42) Reg HKLM\SOFTWARE\Classes\CLSID\{0006F020-0000-0000-C000-000000000046}\LocalServer32@ C:\PROGRA~1\MICROS~1\OFFICE11\OUTLOOK.EXE (Microsoft Office Outlook/Microsoft Corporation SIGNED)(2007-05-31 12:42:14) Reg HKLM\SOFTWARE\Classes\CLSID\{0006F023-0000-0000-C000-000000000046}\InprocHandler32@ C:\Windows\system32\ole32.dll (Microsoft OLE for Windows/Microsoft Corporation SIGNED)(2013-09-25 17:36:42) Reg HKLM\SOFTWARE\Classes\CLSID\{0006F023-0000-0000-C000-000000000046}\LocalServer32@ C:\PROGRA~1\MICROS~1\OFFICE11\OUTLOOK.EXE (Microsoft Office Outlook/Microsoft Corporation SIGNED)(2007-05-31 12:42:14) Reg HKLM\SOFTWARE\Classes\CLSID\{0006F024-0000-0000-C000-000000000046}\InprocHandler32@ C:\Windows\system32\ole32.dll (Microsoft OLE for Windows/Microsoft Corporation SIGNED)(2013-09-25 17:36:42) Reg HKLM\SOFTWARE\Classes\CLSID\{0006F024-0000-0000-C000-000000000046}\LocalServer32@ C:\PROGRA~1\MICROS~1\OFFICE11\OUTLOOK.EXE (Microsoft Office Outlook/Microsoft Corporation SIGNED)(2007-05-31 12:42:14) Reg HKLM\SOFTWARE\Classes\CLSID\{0006F030-0000-0000-C000-000000000046}\InprocHandler32@ C:\Windows\system32\ole32.dll (Microsoft OLE for Windows/Microsoft Corporation SIGNED)(2013-09-25 17:36:42) Reg HKLM\SOFTWARE\Classes\CLSID\{0006F030-0000-0000-C000-000000000046}\LocalServer32@ C:\PROGRA~1\MICROS~1\OFFICE11\OUTLOOK.EXE (Microsoft Office Outlook/Microsoft Corporation SIGNED)(2007-05-31 12:42:14) Reg HKLM\SOFTWARE\Classes\CLSID\{0006F031-0000-0000-C000-000000000046}\InprocHandler32@ C:\Windows\system32\ole32.dll (Microsoft OLE for Windows/Microsoft Corporation SIGNED)(2013-09-25 17:36:42) Reg HKLM\SOFTWARE\Classes\CLSID\{0006F031-0000-0000-C000-000000000046}\LocalServer32@ C:\PROGRA~1\MICROS~1\OFFICE11\OUTLOOK.EXE (Microsoft Office Outlook/Microsoft Corporation SIGNED)(2007-05-31 12:42:14) Reg HKLM\SOFTWARE\Classes\CLSID\{0006F032-0000-0000-C000-000000000046}\InprocHandler32@ C:\Windows\system32\ole32.dll (Microsoft OLE for Windows/Microsoft Corporation SIGNED)(2013-09-25 17:36:42) Reg HKLM\SOFTWARE\Classes\CLSID\{0006F032-0000-0000-C000-000000000046}\LocalServer32@ C:\PROGRA~1\MICROS~1\OFFICE11\OUTLOOK.EXE (Microsoft Office Outlook/Microsoft Corporation SIGNED)(2007-05-31 12:42:14) Reg HKLM\SOFTWARE\Classes\CLSID\{0006F033-0000-0000-C000-000000000046}\InprocHandler32@ C:\Windows\system32\ole32.dll (Microsoft OLE for Windows/Microsoft Corporation SIGNED)(2013-09-25 17:36:42) Reg HKLM\SOFTWARE\Classes\CLSID\{0006F033-0000-0000-C000-000000000046}\LocalServer32@ C:\PROGRA~1\MICROS~1\OFFICE11\OUTLOOK.EXE (Microsoft Office Outlook/Microsoft Corporation SIGNED)(2007-05-31 12:42:14) Reg HKLM\SOFTWARE\Classes\CLSID\{0006F03A-0000-0000-C000-000000000046}\InprocHandler32@ C:\Windows\system32\ole32.dll (Microsoft OLE for Windows/Microsoft Corporation SIGNED)(2013-09-25 17:36:42) Reg HKLM\SOFTWARE\Classes\CLSID\{0006F03A-0000-0000-C000-000000000046}\LocalServer32@ C:\PROGRA~1\MICROS~1\OFFICE11\OUTLOOK.EXE (Microsoft Office Outlook/Microsoft Corporation SIGNED)(2007-05-31 12:42:14) Reg HKLM\SOFTWARE\Classes\CLSID\{0006F065-0000-0000-C000-000000000046}\InprocHandler32@ C:\Windows\system32\ole32.dll (Microsoft OLE for Windows/Microsoft Corporation SIGNED)(2013-09-25 17:36:42) Reg HKLM\SOFTWARE\Classes\CLSID\{0006F065-0000-0000-C000-000000000046}\LocalServer32@ C:\PROGRA~1\MICROS~1\OFFICE11\OUTLOOK.EXE (Microsoft Office Outlook/Microsoft Corporation SIGNED)(2007-05-31 12:42:14) Reg HKLM\SOFTWARE\Classes\CLSID\{0006F071-0000-0000-C000-000000000046}\InprocHandler32@ C:\Windows\system32\ole32.dll (Microsoft OLE for Windows/Microsoft Corporation SIGNED)(2013-09-25 17:36:42) Reg HKLM\SOFTWARE\Classes\CLSID\{0006F071-0000-0000-C000-000000000046}\LocalServer32@ C:\PROGRA~1\MICROS~1\OFFICE11\OUTLOOK.EXE (Microsoft Office Outlook/Microsoft Corporation SIGNED)(2007-05-31 12:42:14) Reg HKLM\SOFTWARE\Classes\CLSID\{000C1090-0000-0000-C000-000000000046}\InprocHandler32@ C:\Windows\system32\ole32.dll (Microsoft OLE for Windows/Microsoft Corporation SIGNED)(2013-09-25 17:36:42) Reg HKLM\SOFTWARE\Classes\CLSID\{0010890e-8789-413c-adbc-48f5b511b3af}\InProcServer32@ C:\Windows\system32\shell32.dll (Windows Shell Common Dll/Microsoft Corporation SIGNED)(2013-09-26 18:21:44) Reg HKLM\SOFTWARE\Classes\CLSID\{009f3b45-8a6b-4360-b997-b2a009a16402}\InProcServer32@ C:\Windows\system32\xwizards.dll (Extensible Wizards Manager Module/Microsoft Corporation SIGNED)(2009-07-13 23:51:41) Reg HKLM\SOFTWARE\Classes\CLSID\{00B01B2E-B1FE-33A6-AD40-57DE8358DC7D}\InprocServer32@ C:\Windows\system32\mscoree.dll (Microsoft .NET Runtime Execution Engine/Microsoft Corporation SIGNED)(2013-09-25 17:38:26) Reg HKLM\SOFTWARE\Classes\CLSID\{00BB2763-6A77-11D0-A535-00C04FD7D062}\InProcServer32@ C:\Windows\system32\shell32.dll (Windows Shell Common Dll/Microsoft Corporation SIGNED)(2013-09-26 18:21:44) Reg HKLM\SOFTWARE\Classes\CLSID\{00da2f99-f2a6-40c2-b770-a920f8e44abc}\MergedFolder@DefaultOverlayIcon C:\Windows\system32\imageres.dll (Windows Image Resource/Microsoft Corporation SIGNED)(2009-07-13 23:42:24) Reg HKLM\SOFTWARE\Classes\CLSID\{00eebf57-477d-4084-9921-7ab3c2c9459d}\InProcServer32@ C:\Windows\system32\shell32.dll (Windows Shell Common Dll/Microsoft Corporation SIGNED)(2013-09-26 18:21:44) Reg HKLM\SOFTWARE\Classes\CLSID\{00f20eb5-8fd6-4d9d-b75e-36801766c8f1}\InprocServer32@ C:\Program Files\Windows Photo Viewer\PhotoAcq.dll (Photo Acquisition/Microsoft Corporation SIGNED)(2013-09-25 17:38:04) Reg HKLM\SOFTWARE\Classes\CLSID\{00F3C2EC-A6EE-11DE-A03A-EF8F55D89593}\Settings@Path C:\Program Files\Notepad++\notepad++.exe (Notepad++ : a free (GNU) source code editor/Don HO [removed])(2013-12-31 13:25:20) Reg HKLM\SOFTWARE\Classes\CLSID\{0102563D-F16D-434d-82A2-37968BD3E31E}\InprocServer32@ C:\Windows\System32\WLanHC.dll (Wireless LAN Helper Classes/Microsoft Corporation SIGNED)(2009-07-13 23:51:55) Reg HKLM\SOFTWARE\Classes\CLSID\{010911E2-F61C-479B-B08C-43E6D1299EFE}\InprocServer32@ C:\Windows\System32\mscoree.dll (Microsoft .NET Runtime Execution Engine/Microsoft Corporation SIGNED)(2013-09-25 17:38:26) Reg HKLM\SOFTWARE\Classes\CLSID\{01D0A625-782D-4777-8D4E-547E6457FAD5}\InprocServer32@ C:\Windows\system32\wercplsupport.dll (Problem Reports and Solutions/Microsoft Corporation SIGNED)(2009-07-13 23:27:26) Reg HKLM\SOFTWARE\Classes\CLSID\{01E04581-4EEE-11d0-BFE9-00AA005B4383}@MenuTextPUI C:\Windows\system32\explorerframe.dll (ExplorerFrame/Microsoft Corporation SIGNED)(2013-09-25 17:38:17) Reg HKLM\SOFTWARE\Classes\CLSID\{01FF4E4B-8AD0-3171-8C82-5C2F48B87E3D}\InprocServer32@ C:\Windows\system32\mscoree.dll (Microsoft .NET Runtime Execution Engine/Microsoft Corporation SIGNED)(2013-09-25 17:38:26) Reg HKLM\SOFTWARE\Classes\CLSID\{021003e9-aac0-4975-979f-14b5d4e717f8}\InProcServer32@ C:\Windows\system32\shell32.dll (Windows Shell Common Dll/Microsoft Corporation SIGNED)(2013-09-26 18:21:44) Reg HKLM\SOFTWARE\Classes\CLSID\{026CC6D7-34B2-33D5-B551-CA31EB6CE345}\InprocServer32@ C:\Windows\system32\mscoree.dll (Microsoft .NET Runtime Execution Engine/Microsoft Corporation SIGNED)(2013-09-25 17:38:26) Reg HKLM\SOFTWARE\Classes\CLSID\{02835AE8-A267-4B1F-A05C-36D2DEA350DC}\InprocHandler32@ C:\Windows\system32\ole32.dll (Microsoft OLE for Windows/Microsoft Corporation SIGNED)(2013-09-25 17:36:42) Reg HKLM\SOFTWARE\Classes\CLSID\{02A3586C-D264-40BF-97F7-FE40F7E3A882}\InprocServer32@ C:\Windows\System32\vdsdyn.dll (VDS Dynamic Volume Provider, Version 2.1.0.1/Microsoft Corporation SIGNED)(2009-07-13 23:23:32) Reg HKLM\SOFTWARE\Classes\CLSID\{02df6db6-9405-4812-b3f6-500e8615b7af}\InProcServer32@ C:\Windows\system32\shell32.dll (Windows Shell Common Dll/Microsoft Corporation SIGNED)(2013-09-26 18:21:44) Reg HKLM\SOFTWARE\Classes\CLSID\{031EE060-67BC-460d-8847-E4A7C5E45A27}@DisplayName C:\Windows\system32\wmploc.dll (Windows Media Player Resources/Microsoft Corporation SIGNED)(2013-09-25 17:37:01) Reg HKLM\SOFTWARE\Classes\CLSID\{031EE060-67BC-460d-8847-E4A7C5E45A27}\LocalServer32@ C:\Program Files\Windows Media Player\wmprph.exe (Windows Media Player Rich Preview Handler/Microsoft Corporation SIGNED)(2009-07-14 00:09:16) Reg HKLM\SOFTWARE\Classes\CLSID\{0358b920-0ac7-461f-98f4-58e32cd89148}\InProcServer32@ C:\Windows\system32\wininet.dll (Internet Extensions for Win32/Microsoft Corporation SIGNED)(2013-12-13 11:08:42) Reg HKLM\SOFTWARE\Classes\CLSID\{03837511-098B-11D8-9414-505054503030}\InprocServer32@ C:\Windows\System32\pla.dll (Performance Logs & Alerts/Microsoft Corporation SIGNED)(2013-09-25 17:37:17) Reg HKLM\SOFTWARE\Classes\CLSID\{03C036F1-A186-11D0-824A-00AA005B4383}\InProcServer32@ C:\Windows\system32\shell32.dll (Windows Shell Common Dll/Microsoft Corporation SIGNED)(2013-09-26 18:21:44) Reg HKLM\SOFTWARE\Classes\CLSID\{042dc17c-023f-43df-a3ec-982b4dc78a64}\InProcServer32@ C:\Windows\system32\propsys.dll (Microsoft Property System/Microsoft Corporation SIGNED)(2013-09-25 17:38:03) Reg HKLM\SOFTWARE\Classes\CLSID\{047a9a40-657e-11d3-8d5b-00104b35e7ef}\InprocServer32@ C:\Windows\system32\mscoree.dll (Microsoft .NET Runtime Execution Engine/Microsoft Corporation SIGNED)(2013-09-25 17:38:26) Reg HKLM\SOFTWARE\Classes\CLSID\{054AAE20-4BEA-4347-8A35-64A533254A9D}\LocalServer32@ C:\Program Files\Common Files\microsoft shared\ink\TabTip.exe (Tablet PC Input Panel Accessory/Microsoft Corporation SIGNED)(2009-07-13 23:46:35) Reg HKLM\SOFTWARE\Classes\CLSID\{05589FAF-C356-11CE-BF01-00AA0055595A}\InprocServer32@ C:\Windows\system32\quartz.dll (DirectShow Runtime./Microsoft Corporation SIGNED)(2013-09-25 08:10:55) Reg HKLM\SOFTWARE\Classes\CLSID\{056440FD-8568-48e7-A632-72157243B55B}\InProcServer32@ C:\Windows\system32\explorerframe.dll (ExplorerFrame/Microsoft Corporation SIGNED)(2013-09-25 17:38:17) Reg HKLM\SOFTWARE\Classes\CLSID\{057EEE47-2572-4AA1-88D7-60CE2149E33C}\InProcServer32@ C:\Windows\system32\wininet.dll (Internet Extensions for Win32/Microsoft Corporation SIGNED)(2013-12-13 11:08:42) Reg HKLM\SOFTWARE\Classes\CLSID\{05BDC38E-5493-487a-A7FF-8CF2246ABC13}\InProcServer32@ C:\Windows\System32\ieframe.dll (Internet Browser/Microsoft Corporation SIGNED)(2013-12-13 11:08:39) Reg HKLM\SOFTWARE\Classes\CLSID\{05EBA309-0164-11D3-8729-00C04F79ED0D}\InprocServer32@ C:\Windows\system32\mscoree.dll (Microsoft .NET Runtime Execution Engine/Microsoft Corporation SIGNED)(2013-09-25 17:38:26) Reg HKLM\SOFTWARE\Classes\CLSID\{05f6fe1a-ecef-11d0-aae7-00c04fc9b304}\InProcServer32@ C:\Windows\System32\mshtml.dll (Microsoft (R) HTML Viewer/Microsoft Corporation SIGNED)(2013-12-13 11:08:38) Reg HKLM\SOFTWARE\Classes\CLSID\{060AF76C-68DD-11D0-8FC1-00C04FD9189D}\InprocServer32@ C:\Windows\system32\quartz.dll (DirectShow Runtime./Microsoft Corporation SIGNED)(2013-09-25 08:10:55) Reg HKLM\SOFTWARE\Classes\CLSID\{063B79F5-7539-11D2-9773-00A0C9B4D50C}\InprocServer32@ C:\Windows\system32\clbcatq.dll (COM+ Configuration Catalog/Microsoft Corporation SIGNED)(2009-07-13 23:44:44) Reg HKLM\SOFTWARE\Classes\CLSID\{06622D85-6856-4460-8DE1-A81921B41C4B}\InProcServer32@ C:\Windows\system32\shell32.dll (Windows Shell Common Dll/Microsoft Corporation SIGNED)(2013-09-26 18:21:44) Reg HKLM\SOFTWARE\Classes\CLSID\{06B32AEE-77DA-484B-973B-5D64F47201B0}\InprocServer32@ C:\Windows\system32\quartz.dll (DirectShow Runtime./Microsoft Corporation SIGNED)(2013-09-25 08:10:55) Reg HKLM\SOFTWARE\Classes\CLSID\{06B81C12-A5DA-340D-AFF7-FA1453FBC29A}\InprocServer32@ C:\Windows\system32\mscoree.dll (Microsoft .NET Runtime Execution Engine/Microsoft Corporation SIGNED)(2013-09-25 17:38:26) Reg HKLM\SOFTWARE\Classes\CLSID\{06EEE695-542D-46F6-AEAB-FA2F1B2102D3}\InprocServer32@ C:\Windows\System32\gameux.dll (Games Explorer/Microsoft Corporation SIGNED)(2013-09-25 17:37:46) Reg HKLM\SOFTWARE\Classes\CLSID\{06EEE834-461C-42c2-8DCF-1502B527B1F9}\InProcServer32@ C:\Windows\System32\ieframe.dll (Internet Browser/Microsoft Corporation SIGNED)(2013-12-13 11:08:39) Reg HKLM\SOFTWARE\Classes\CLSID\{0700F42F-EEE3-443a-9899-166F16286796}\InProcServer32@ C:\Windows\System32\provsvc.dll (Windows HomeGroup/Microsoft Corporation SIGNED)(2013-09-25 17:37:30) Reg HKLM\SOFTWARE\Classes\CLSID\{078759d3-423b-48ad-ab6a-5638c2884dbe}\InProcServer32@ C:\Windows\system32\shell32.dll (Windows Shell Common Dll/Microsoft Corporation SIGNED)(2013-09-26 18:21:44) Reg HKLM\SOFTWARE\Classes\CLSID\{07B65360-C445-11CE-AFDE-00AA006C14F4}\InprocServer32@ C:\Windows\system32\quartz.dll (DirectShow Runtime./Microsoft Corporation SIGNED)(2013-09-25 08:10:55) Reg HKLM\SOFTWARE\Classes\CLSID\{07C0A9A9-6308-4C15-B818-225D4F3FBF48}\InprocServer32@ C:\Windows\System32\mscoree.dll (Microsoft .NET Runtime Execution Engine/Microsoft Corporation SIGNED)(2013-09-25 17:38:26) Reg HKLM\SOFTWARE\Classes\CLSID\{07C45BB1-4A8C-4642-A1F5-237E7215FF66}\InProcServer32@ C:\Windows\System32\ieframe.dll (Internet Browser/Microsoft Corporation SIGNED)(2013-12-13 11:08:39) Reg HKLM\SOFTWARE\Classes\CLSID\{07D26616-6136-11D1-8C9C-00C04FC3261D}\InprocServer32@ C:\Windows\system32\clbcatq.dll (COM+ Configuration Catalog/Microsoft Corporation SIGNED)(2009-07-13 23:44:44) Reg HKLM\SOFTWARE\Classes\CLSID\{07F94112-A42E-328B-B508-702EF62BCC29}\InprocServer32@ C:\Windows\system32\mscoree.dll (Microsoft .NET Runtime Execution Engine/Microsoft Corporation SIGNED)(2013-09-25 17:38:26) Reg HKLM\SOFTWARE\Classes\CLSID\{08244EE6-92F0-47f2-9FC9-929BAA2E7235}\InProcServer32@ C:\Windows\system32\ntshrui.dll (Shell extensions for sharing/Microsoft Corporation SIGNED)(2013-09-25 17:37:19) Reg HKLM\SOFTWARE\Classes\CLSID\{08295C62-7462-3633-B35E-7AE68ACA3948}\InprocServer32@ C:\Windows\system32\mscoree.dll (Microsoft .NET Runtime Execution Engine/Microsoft Corporation SIGNED)(2013-09-25 17:38:26) Reg HKLM\SOFTWARE\Classes\CLSID\{08d5bfbf-fbca-4322-9f70-ca9f66f8ed6a}\InProcServer32@ C:\Windows\system32\shell32.dll (Windows Shell Common Dll/Microsoft Corporation SIGNED)(2013-09-26 18:21:44) Reg HKLM\SOFTWARE\Classes\CLSID\{0968e258-16c7-4dba-aa86-462dd61e31a3}@LocalizedString C:\Windows\System32\urlmon.dll (OLE32 Extensions for Win32/Microsoft Corporation SIGNED)(2013-12-13 11:08:41) Reg HKLM\SOFTWARE\Classes\CLSID\{09799AFB-AD67-11d1-ABCD-00C04FC30936}\InProcServer32@ C:\Windows\system32\shell32.dll (Windows Shell Common Dll/Microsoft Corporation SIGNED)(2013-09-26 18:21:44) Reg HKLM\SOFTWARE\Classes\CLSID\{098870b6-39ea-480b-b8b5-dd0167c4db59}\InProcServer32@ C:\Windows\System32\ieframe.dll (Internet Browser/Microsoft Corporation SIGNED)(2013-12-13 11:08:39) Reg HKLM\SOFTWARE\Classes\CLSID\{0997898B-0713-11d2-A4AA-00C04F8EEB3E}\InProcServer32@ C:\Windows\System32\shell32.dll (Windows Shell Common Dll/Microsoft Corporation SIGNED)(2013-09-26 18:21:44) Reg HKLM\SOFTWARE\Classes\CLSID\{09A60795-31C0-3A79-9250-8D93C74FE540}\InprocServer32@ C:\Windows\system32\mscoree.dll (Microsoft .NET Runtime Execution Engine/Microsoft Corporation SIGNED)(2013-09-25 17:38:26) Reg HKLM\SOFTWARE\Classes\CLSID\{0A88C858-7D0C-4549-9499-7DB05F0CB0BF}\InProcServer32@ C:\Windows\system32\ntshrui.dll (Shell extensions for sharing/Microsoft Corporation SIGNED)(2013-09-25 17:37:19) Reg HKLM\SOFTWARE\Classes\CLSID\{0AE2DEB0-F901-478b-BB9F-881EE8066788}\InprocServer32@ C:\Windows\system32\mscoree.dll (Microsoft .NET Runtime Execution Engine/Microsoft Corporation SIGNED)(2013-09-25 17:38:26) Reg HKLM\SOFTWARE\Classes\CLSID\{0af96ede-aebf-41ed-a1c8-cf7a685505b6}\InProcServer32@ C:\Windows\system32\shell32.dll (Windows Shell Common Dll/Microsoft Corporation SIGNED)(2013-09-26 18:21:44) Reg HKLM\SOFTWARE\Classes\CLSID\{0AFACED1-E828-11D1-9187-B532F1E9575D}\shell\find\command@ C:\Windows\Explorer.exe (Windows Explorer/Microsoft Corporation SIGNED)(2013-09-25 17:37:42) Reg HKLM\SOFTWARE\Classes\CLSID\{0AFCCBA6-BF90-4A4E-8482-0AC960981F5B}\InProcServer32@ C:\Windows\system32\shell32.dll (Windows Shell Common Dll/Microsoft Corporation SIGNED)(2013-09-26 18:21:44) Reg HKLM\SOFTWARE\Classes\CLSID\{0b2feecb-1577-4fa6-9a29-bd9022ebcf90}\InprocServer32@ C:\Windows\system32\RasDiag.dll (RAS Diagnostics Helper Classes/Microsoft Corporation SIGNED)(2009-07-13 23:52:44) Reg HKLM\SOFTWARE\Classes\CLSID\{0BE35203-8F91-11CE-9DE3-00AA004BB851}\InprocServer32@ C:\Windows\system32\oleaut32.dll (Microsoft Corporation SIGNED)(2013-09-25 08:15:54) Reg HKLM\SOFTWARE\Classes\CLSID\{0bf754aa-c967-445c-ab3d-d8fda9bae7ef}\InProcServer32@ C:\Windows\system32\stobject.dll (Systray shell service object/Microsoft Corporation SIGNED)(2013-09-25 17:36:32) Reg HKLM\SOFTWARE\Classes\CLSID\{0C39A5CF-1A7A-40C8-BA74-8900E6DF5FCD}\InProcServer32@ C:\Windows\system32\shell32.dll (Windows Shell Common Dll/Microsoft Corporation SIGNED)(2013-09-26 18:21:44) Reg HKLM\SOFTWARE\Classes\CLSID\{0C41D1E6-9D16-41ED-9CDD-D0665039857B}\InProcServer32@ C:\Windows\system32\tcpipcfg.dll (Network Configuration Objects/Microsoft Corporation SIGNED)(2013-09-25 17:38:15) Reg HKLM\SOFTWARE\Classes\CLSID\{0c98b8bc-273c-464d-938a-b9709607e137}@LocalizedString C:\Windows\ehome\ehres.dll (Media Center Resources/Microsoft Corporation SIGNED)(2009-07-14 00:11:14) Reg HKLM\SOFTWARE\Classes\CLSID\{0c9ac398-8c78-4b4b-b8c6-675ed1b734a1}\InProcServer32@ C:\Windows\system32\netcorehc.dll (Networking Core Diagnostics Helper Classes/Microsoft Corporation SIGNED)(2009-07-13 23:52:44) Reg HKLM\SOFTWARE\Classes\CLSID\{0CA545C6-37AD-4A6C-BF92-9F7610067EF5}\InprocServer32@ C:\Windows\system32\FirewallAPI.dll (Windows Firewall API/Microsoft Corporation SIGNED)(2009-07-13 23:53:14) Reg HKLM\SOFTWARE\Classes\CLSID\{0cdb500e-123f-4e98-b446-0f3eae3c7ebc}\InProcServer32@ C:\Windows\system32\netcorehc.dll (Networking Core Diagnostics Helper Classes/Microsoft Corporation SIGNED)(2009-07-13 23:52:44) Reg HKLM\SOFTWARE\Classes\CLSID\{0D0E47ED-7220-411f-8F81-1118095DA5E7}\InProcServer32@ C:\Windows\System32\provsvc.dll (Windows HomeGroup/Microsoft Corporation SIGNED)(2013-09-25 17:37:30) Reg HKLM\SOFTWARE\Classes\CLSID\{0D17A350-6585-4f3d-B008-6827EBDE5D85}\InprocServer32@ C:\Windows\system32\MSCorEE.dll (Microsoft .NET Runtime Execution Engine/Microsoft Corporation SIGNED)(2013-09-25 17:38:26) Reg HKLM\SOFTWARE\Classes\CLSID\{0d81ea0d-13bf-44b2-af1c-fcdf6be7927c}\InProcServer32@ C:\Windows\system32\shell32.dll (Windows Shell Common Dll/Microsoft Corporation SIGNED)(2013-09-26 18:21:44) Reg HKLM\SOFTWARE\Classes\CLSID\{0DE9617E-FA48-3933-9873-3A43874316CA}\InprocServer32@ C:\Windows\system32\mscoree.dll (Microsoft .NET Runtime Execution Engine/Microsoft Corporation SIGNED)(2013-09-25 17:38:26) Reg HKLM\SOFTWARE\Classes\CLSID\{0DF44EAA-FF21-4412-828E-260A8728E7F1}@InfoTip C:\Windows\system32\shell32.dll (Windows Shell Common Dll/Microsoft Corporation SIGNED)(2013-09-26 18:21:44) Reg HKLM\SOFTWARE\Classes\CLSID\{0E4EFFC0-2387-11D3-B372-00105A98B7CE}\InprocServer32@ C:\Windows\system32\mscoree.dll (Microsoft .NET Runtime Execution Engine/Microsoft Corporation SIGNED)(2013-09-25 17:38:26) Reg HKLM\SOFTWARE\Classes\CLSID\{0E5AAE11-A475-4c5b-AB00-C66DE400274E}\InProcServer32@ C:\Windows\system32\shell32.dll (Windows Shell Common Dll/Microsoft Corporation SIGNED)(2013-09-26 18:21:44) Reg HKLM\SOFTWARE\Classes\CLSID\{0E5CBF21-D15F-11D0-8301-00AA005B4383}@MenuTextPUI C:\Windows\system32\explorerframe.dll (ExplorerFrame/Microsoft Corporation SIGNED)(2013-09-25 17:38:17) Reg HKLM\SOFTWARE\Classes\CLSID\{0E5CBF21-D15F-11D0-8301-00AA005B4383}\InProcServer32@ C:\Windows\system32\shell32.dll (Windows Shell Common Dll/Microsoft Corporation SIGNED)(2013-09-26 18:21:44) Reg HKLM\SOFTWARE\Classes\CLSID\{0E71F9BD-C109-3352-BD60-14F96D56B6F3}\InprocServer32@ C:\Windows\system32\mscoree.dll (Microsoft .NET Runtime Execution Engine/Microsoft Corporation SIGNED)(2013-09-25 17:38:26) Reg HKLM\SOFTWARE\Classes\CLSID\{0EEA25CC-4362-4a12-850B-86EE61B0D3EB}\InProcServer32@ C:\Windows\system32\shell32.dll (Windows Shell Common Dll/Microsoft Corporation SIGNED)(2013-09-26 18:21:44) Reg HKLM\SOFTWARE\Classes\CLSID\{0F0C09C5-601E-4396-BCD0-CDB343D7F657}\InProcServer32@ C:\Windows\system32\rascfg.dll (RAS Configuration Objects/Microsoft Corporation SIGNED)(2009-07-13 23:54:54) Reg HKLM\SOFTWARE\Classes\CLSID\{0f3ed1f2-afdd-4b0c-b6d9-229c1bc58a08}\InProcServer32@ C:\Windows\system32\netcorehc.dll (Networking Core Diagnostics Helper Classes/Microsoft Corporation SIGNED)(2009-07-13 23:52:44) Reg HKLM\SOFTWARE\Classes\CLSID\{0FF66430-C796-3EE7-902B-166C402CA288}\InprocServer32@ C:\Windows\system32\mscoree.dll (Microsoft .NET Runtime Execution Engine/Microsoft Corporation SIGNED)(2013-09-25 17:38:26) Reg HKLM\SOFTWARE\Classes\CLSID\{104846ab-42b1-4e38-a80d-136f78c3f258}\InProcServer32@ C:\Windows\system32\shell32.dll (Windows Shell Common Dll/Microsoft Corporation SIGNED)(2013-09-26 18:21:44) Reg HKLM\SOFTWARE\Classes\CLSID\{108296C1-281E-11D3-BD22-0000F80849BD}\InprocServer32@ C:\Windows\system32\mscoree.dll (Microsoft .NET Runtime Execution Engine/Microsoft Corporation SIGNED)(2013-09-25 17:38:26) Reg HKLM\SOFTWARE\Classes\CLSID\{10BCEB99-FAAC-4080-B2FA-D07CD671EEF2}\InprocServer32@ C:\Windows\System32\ieframe.dll (Internet Browser/Microsoft Corporation SIGNED)(2013-12-13 11:08:39) Reg HKLM\SOFTWARE\Classes\CLSID\{112BC2E7-9EF9-3648-AF9E-45C0D4B89929}\InprocServer32@ C:\Windows\system32\mscoree.dll (Microsoft .NET Runtime Execution Engine/Microsoft Corporation SIGNED)(2013-09-25 17:38:26) Reg HKLM\SOFTWARE\Classes\CLSID\{116ABC1A-F7DB-45A7-ADDA-D5A57A08C6FF}\InProcServer32@ C:\Windows\system32\tsworkspace.dll (RemoteApp and Desktop Connection Component/Microsoft Corporation SIGNED)(2013-09-25 17:37:06) Reg HKLM\SOFTWARE\Classes\CLSID\{11d162b6-1cea-4b4a-8037-2518ecd6554b}\InProcServer32@ C:\Windows\system32\shell32.dll (Windows Shell Common Dll/Microsoft Corporation SIGNED)(2013-09-26 18:21:44) Reg HKLM\SOFTWARE\Classes\CLSID\{11dbb47c-a525-400b-9e80-a54615a090c0}\InProcServer32@ C:\Windows\system32\explorerframe.dll (ExplorerFrame/Microsoft Corporation SIGNED)(2013-09-25 17:38:17) Reg HKLM\SOFTWARE\Classes\CLSID\{12367cf8-6222-4b34-8ca8-3ce703999e28}\InProcServer32@ C:\Windows\system32\ntshrui.dll (Shell extensions for sharing/Microsoft Corporation SIGNED)(2013-09-25 17:37:19) Reg HKLM\SOFTWARE\Classes\CLSID\{12518493-00B2-11d2-9FA5-9E3420524153}\InProcServer32@ C:\Windows\system32\shell32.dll (Windows Shell Common Dll/Microsoft Corporation SIGNED)(2013-09-26 18:21:44) Reg HKLM\SOFTWARE\Classes\CLSID\{12DA6D0B-021F-4d79-8794-64145F503CA5}\InprocServer32@ C:\Windows\system32\eapqec.dll (Microsoft EAP NAP Enforcement Client/Microsoft Corporation SIGNED)(2009-07-13 23:56:32) Reg HKLM\SOFTWARE\Classes\CLSID\{13709620-C279-11CE-A49E-444553540000}\InProcServer32@ C:\Windows\system32\shell32.dll (Windows Shell Common Dll/Microsoft Corporation SIGNED)(2013-09-26 18:21:44) Reg HKLM\SOFTWARE\Classes\CLSID\{13a4bbe8-6527-40cb-a996-1602829541ef}\InProcServer32@ C:\Windows\System32\explorerframe.dll (ExplorerFrame/Microsoft Corporation SIGNED)(2013-09-25 17:38:17) Reg HKLM\SOFTWARE\Classes\CLSID\{13D3C4B8-B179-4ebb-BF62-F704173E7448}@DisplayName C:\Program Files\Common Files\System\wab32res.dll (Microsoft (R) Contacts DLL/Microsoft Corporation SIGNED)(2009-07-13 23:42:15) Reg HKLM\SOFTWARE\Classes\CLSID\{14074e0b-7216-4862-96e6-53cada442a56}\Instance\InitPropertyBag@DefaultIcon C:\Windows\System32\imageres.dll (Windows Image Resource/Microsoft Corporation SIGNED)(2009-07-13 23:42:24) Reg HKLM\SOFTWARE\Classes\CLSID\{146855FA-309F-3D0E-BB3E-DF525F30A715}\InprocServer32@ C:\Windows\system32\mscoree.dll (Microsoft .NET Runtime Execution Engine/Microsoft Corporation SIGNED)(2013-09-25 17:38:26) Reg HKLM\SOFTWARE\Classes\CLSID\{14795a8f-78f3-47bd-acb6-e767414fe293}\InProcServer32@ C:\Windows\system32\shell32.dll (Windows Shell Common Dll/Microsoft Corporation SIGNED)(2013-09-26 18:21:44) Reg HKLM\SOFTWARE\Classes\CLSID\{14910622-09D4-3B4A-8C1E-9991DBDCC553}\InprocServer32@ C:\Windows\system32\mscoree.dll (Microsoft .NET Runtime Execution Engine/Microsoft Corporation SIGNED)(2013-09-25 17:38:26) Reg HKLM\SOFTWARE\Classes\CLSID\{1531d583-8375-4d3f-b5fb-d23bbd169f22}@DisplayName C:\Windows\system32\shell32.dll (Windows Shell Common Dll/Microsoft Corporation SIGNED)(2013-09-26 18:21:44) Reg HKLM\SOFTWARE\Classes\CLSID\{15b0bb4c-0f7d-11D1-b21f-00C04Fb9473f}\InprocServer32@ C:\Windows\system32\clbcatq.dll (COM+ Configuration Catalog/Microsoft Corporation SIGNED)(2009-07-13 23:44:44) Reg HKLM\SOFTWARE\Classes\CLSID\{1643E180-90F5-11CE-97D5-00AA0055595A}\InprocServer32@ C:\Windows\system32\quartz.dll (DirectShow Runtime./Microsoft Corporation SIGNED)(2013-09-25 08:10:55) Reg HKLM\SOFTWARE\Classes\CLSID\{1649d1cf-deaf-4a68-abe8-5c9f68572fd1}\InProcServer32@ C:\Windows\system32\shell32.dll (Windows Shell Common Dll/Microsoft Corporation SIGNED)(2013-09-26 18:21:44) Reg HKLM\SOFTWARE\Classes\CLSID\{165D4642-1278-4486-A3FD-439F5888FCA3}\InProcServer32@ C:\Windows\system32\tsworkspace.dll (RemoteApp and Desktop Connection Component/Microsoft Corporation SIGNED)(2013-09-25 17:37:06) Reg HKLM\SOFTWARE\Classes\CLSID\{167c0a56-c490-4623-9225-8ffdc546e56c}\InProcServer32@ C:\Windows\system32\shell32.dll (Windows Shell Common Dll/Microsoft Corporation SIGNED)(2013-09-26 18:21:44) Reg HKLM\SOFTWARE\Classes\CLSID\{176961ec-fbfb-4288-b418-c80c86947481}\InprocServer32@ C:\Windows\system32\RasDiag.dll (RAS Diagnostics Helper Classes/Microsoft Corporation SIGNED)(2009-07-13 23:52:44) Reg HKLM\SOFTWARE\Classes\CLSID\{17cd9488-1228-4b2f-88ce-4298e93e0966}@InfoTip C:\Windows\System32\sud.dll (SUD Control Panel/Microsoft Corporation SIGNED)(2013-09-25 17:37:38) Reg HKLM\SOFTWARE\Classes\CLSID\{181D6C15-60A6-4BC7-A8E7-389D5BFE4841}\InProcServer32@ C:\Windows\System32\ieframe.dll (Internet Browser/Microsoft Corporation SIGNED)(2013-12-13 11:08:39) Reg HKLM\SOFTWARE\Classes\CLSID\{18845040-0fa5-11d1-ba19-00c04fd912d0}\InProcServer32@ C:\Windows\System32\mshtml.dll (Microsoft (R) HTML Viewer/Microsoft Corporation SIGNED)(2013-12-13 11:08:38) Reg HKLM\SOFTWARE\Classes\CLSID\{18B1C7EE-68E3-35BB-9E40-469A223285F7}\InprocServer32@ C:\Windows\system32\mscoree.dll (Microsoft .NET Runtime Execution Engine/Microsoft Corporation SIGNED)(2013-09-25 17:38:26) Reg HKLM\SOFTWARE\Classes\CLSID\{19352205-42B0-4690-9AA4-D7DB9AE5F259}\InProcServer32@ C:\Windows\System32\provsvc.dll (Windows HomeGroup/Microsoft Corporation SIGNED)(2013-09-25 17:37:30) Reg HKLM\SOFTWARE\Classes\CLSID\{193B4137-0480-11D1-97DA-00C04FB9618A}\InprocServer32@ C:\Windows\system32\msdtcprx.dll (Microsoft Distributed Transaction Coordinator OLE Transactions Interface Proxy DLL/Microsoft Corporation SIGNED)(2009-07-13 23:44:23) Reg HKLM\SOFTWARE\Classes\CLSID\{1968106d-f3b5-44cf-890e-116fcb9ecef1}\InProcServer32@ C:\Windows\System32\sud.dll (SUD Control Panel/Microsoft Corporation SIGNED)(2013-09-25 17:37:38) Reg HKLM\SOFTWARE\Classes\CLSID\{196f128d-dce9-4090-b061-3d29c6ca32c2}\InProcServer32@ C:\Windows\system32\shell32.dll (Windows Shell Common Dll/Microsoft Corporation SIGNED)(2013-09-26 18:21:44) Reg HKLM\SOFTWARE\Classes\CLSID\{19b9dcc7-6f37-4dc7-9da6-8af601c5fce2}\InProcServer32@ C:\Windows\system32\WWanMM.dll (WWan Media Manager/Microsoft Corporation SIGNED)(2009-07-13 23:56:38) Reg HKLM\SOFTWARE\Classes\CLSID\{19BA17F2-2602-4E77-9027-103894607626}\Elevation@IconReference C:\Windows\system32\wmploc.dll (Windows Media Player Resources/Microsoft Corporation SIGNED)(2013-09-25 17:37:01) Reg HKLM\SOFTWARE\Classes\CLSID\{1A0391BF-9564-4294-B0A4-06C298929EF9}\InProcServer32@ C:\Windows\system32\ntshrui.dll (Shell extensions for sharing/Microsoft Corporation SIGNED)(2013-09-25 17:37:19) Reg HKLM\SOFTWARE\Classes\CLSID\{1A056BDB-8B45-462f-8D85-CAC6BDCD2A31}\InprocServer32@ C:\Windows\System32\mscoree.dll (Microsoft .NET Runtime Execution Engine/Microsoft Corporation SIGNED)(2013-09-25 17:38:26) Reg HKLM\SOFTWARE\Classes\CLSID\{1B462D7B-72D8-4544-ACC1-D84E5B9A8A14}\LocalServer32@ C:\Windows\system32\mstsc.exe (Remote Desktop Connection/Microsoft Corporation SIGNED)(2013-09-25 17:37:15) Reg HKLM\SOFTWARE\Classes\CLSID\{1B544C20-FD0B-11CE-8C63-00AA0044B51E}\InprocServer32@ C:\Windows\system32\quartz.dll (DirectShow Runtime./Microsoft Corporation SIGNED)(2013-09-25 08:10:55) Reg HKLM\SOFTWARE\Classes\CLSID\{1B76DD18-2CB4-41A4-BD69-5FB8287F7814}\InprocServer32@ C:\Windows\System32\mscoree.dll (Microsoft .NET Runtime Execution Engine/Microsoft Corporation SIGNED)(2013-09-25 17:38:26) Reg HKLM\SOFTWARE\Classes\CLSID\{1b9f2bf2-27f5-4dec-a175-3cf7bb8cfd3e}\InProcServer32@ C:\Windows\system32\netcorehc.dll (Networking Core Diagnostics Helper Classes/Microsoft Corporation SIGNED)(2009-07-13 23:52:44) Reg HKLM\SOFTWARE\Classes\CLSID\{1BB05961-5FBF-11D2-A521-44DF07C10000}\InprocServer32@ C:\Windows\system32\quartz.dll (DirectShow Runtime./Microsoft Corporation SIGNED)(2013-09-25 08:10:55) Reg HKLM\SOFTWARE\Classes\CLSID\{1BC972D6-555C-4FF7-BE2C-C584021A0A6A}\InprocServer32@ C:\Windows\System32\appmgr.dll (Software Installation Snapin Extenstion/Microsoft Corporation SIGNED)(2013-09-25 17:37:12) Reg HKLM\SOFTWARE\Classes\CLSID\{1C1EDB47-CE22-4bbb-B608-77B48F83C823}\InProcServer32@ C:\Windows\System32\ieframe.dll (Internet Browser/Microsoft Corporation SIGNED)(2013-12-13 11:08:39) Reg HKLM\SOFTWARE\Classes\CLSID\{1C749B87-568C-4865-8E73-6413F8372CE6}@LocalizedString C:\Windows\system32\lpksetup.exe (Language Pack Installer/Microsoft Corporation SIGNED)(2013-09-25 17:38:30) Reg HKLM\SOFTWARE\Classes\CLSID\{1C97EF1D-74ED-3D21-84A4-8631D959634A}\InprocServer32@ C:\Windows\system32\mscoree.dll (Microsoft .NET Runtime Execution Engine/Microsoft Corporation SIGNED)(2013-09-25 17:38:26) Reg HKLM\SOFTWARE\Classes\CLSID\{1d16438c-54dc-404f-83a9-c041e77a32dd}\InprocServer32@ C:\Windows\system32\msdtcuiu.dll (Microsoft Distributed Transaction Coordinator Administrative DLL/Microsoft Corporation SIGNED)(2009-07-13 23:44:10) Reg HKLM\SOFTWARE\Classes\CLSID\{1D1F0730-0748-4b5f-81DF-865694BD07AC}\InProcServer32@ C:\Windows\System32\ieframe.dll (Internet Browser/Microsoft Corporation SIGNED)(2013-12-13 11:08:39) Reg HKLM\SOFTWARE\Classes\CLSID\{1D2680C9-0E2A-469d-B787-065558BC7D43}\InprocServer32@ C:\Windows\system32\mscoree.dll (Microsoft .NET Runtime Execution Engine/Microsoft Corporation SIGNED)(2013-09-25 17:38:26) Reg HKLM\SOFTWARE\Classes\CLSID\{1d2b8d89-9324-46a0-b797-5725d8c8d881}\InprocServer32@ C:\Windows\system32\sdengin2.dll (Microsoft� Windows Backup Engine/Microsoft Corporation SIGNED)(2013-09-25 17:36:51) Reg HKLM\SOFTWARE\Classes\CLSID\{1D3529C7-671A-468d-AD2A-499A96B073D1}\InprocServer32@ C:\Windows\System32\WLanHC.dll (Wireless LAN Helper Classes/Microsoft Corporation SIGNED)(2009-07-13 23:51:55) Reg HKLM\SOFTWARE\Classes\CLSID\{1D428C79-6E2E-4351-A361-C0401A03A0BA}\InprocServer32@ C:\Windows\system32\TSWorkspace.dll (RemoteApp and Desktop Connection Component/Microsoft Corporation SIGNED)(2013-09-25 17:37:06) Reg HKLM\SOFTWARE\Classes\CLSID\{1DA08500-9EDC-11CF-BC10-00AA00AC74F6}\InprocServer32@ C:\Windows\system32\quartz.dll (DirectShow Runtime./Microsoft Corporation SIGNED)(2013-09-25 08:10:55) Reg HKLM\SOFTWARE\Classes\CLSID\{1E66F26B-79EE-11D2-8710-00C04F79ED0D}\InprocServer32@ C:\Windows\system32\mscoree.dll (Microsoft .NET Runtime Execution Engine/Microsoft Corporation SIGNED)(2013-09-25 17:38:26) Reg HKLM\SOFTWARE\Classes\CLSID\{1e887b90-7201-431d-820e-36aa566e52f4}\InProcServer32@ C:\Windows\system32\netcorehc.dll (Networking Core Diagnostics Helper Classes/Microsoft Corporation SIGNED)(2009-07-13 23:52:44) Reg HKLM\SOFTWARE\Classes\CLSID\{1E8F0D70-7399-41BF-8598-7949A2DEC898}\InProcServer32@ C:\Windows\system32\shell32.dll (Windows Shell Common Dll/Microsoft Corporation SIGNED)(2013-09-26 18:21:44) Reg HKLM\SOFTWARE\Classes\CLSID\{1e94e93c-852d-47fb-9197-7edeb41101b0}\InProcServer32@ C:\Windows\system32\netcorehc.dll (Networking Core Diagnostics Helper Classes/Microsoft Corporation SIGNED)(2009-07-13 23:52:44) Reg HKLM\SOFTWARE\Classes\CLSID\{1EC2DE53-75CC-11d2-9775-00A0C9B4D50C}\InprocServer32@ C:\Windows\system32\mscoree.dll (Microsoft .NET Runtime Execution Engine/Microsoft Corporation SIGNED)(2013-09-25 17:38:26) Reg HKLM\SOFTWARE\Classes\CLSID\{1eeb5b5a-06fb-4732-96b3-975c0194eb39}\InProcServer32@ C:\Windows\system32\explorerframe.dll (ExplorerFrame/Microsoft Corporation SIGNED)(2013-09-25 17:38:17) Reg HKLM\SOFTWARE\Classes\CLSID\{1f09b058-f3fd-4a9d-a8ba-a8a05f8fe283}\InprocServer32@ C:\Windows\system32\msdtcuiu.dll (Microsoft Distributed Transaction Coordinator Administrative DLL/Microsoft Corporation SIGNED)(2009-07-13 23:44:10) Reg HKLM\SOFTWARE\Classes\CLSID\{1F17C39C-99D5-37E0-8E98-8F27044BD50A}\InprocServer32@ C:\Windows\system32\mscoree.dll (Microsoft .NET Runtime Execution Engine/Microsoft Corporation SIGNED)(2013-09-25 17:38:26) Reg HKLM\SOFTWARE\Classes\CLSID\{1f2e5c40-9550-11ce-99d2-00aa006e086c}\Elevation@IconReference C:\Windows\system32\imageres.dll (Windows Image Resource/Microsoft Corporation SIGNED)(2009-07-13 23:42:24) Reg HKLM\SOFTWARE\Classes\CLSID\{1f486a52-3cb1-48fd-8f50-b8dc300d9f9d}\InProcServer32@ C:\Windows\system32\propsys.dll (Microsoft Property System/Microsoft Corporation SIGNED)(2013-09-25 17:38:03) Reg HKLM\SOFTWARE\Classes\CLSID\{1f849cce-2546-4b9f-b03e-4004781bdc40}\InProcServer32@ C:\Windows\system32\explorerframe.dll (ExplorerFrame/Microsoft Corporation SIGNED)(2013-09-25 17:38:17) Reg HKLM\SOFTWARE\Classes\CLSID\{1F9F18A3-EFC0-3913-84A5-90678A4A9A80}\InprocServer32@ C:\Windows\system32\mscoree.dll (Microsoft .NET Runtime Execution Engine/Microsoft Corporation SIGNED)(2013-09-25 17:38:26) Reg HKLM\SOFTWARE\Classes\CLSID\{205D7A97-F16D-4691-86EF-F3075DCCA57D}\InProcServer32@ C:\Windows\System32\ieframe.dll (Internet Browser/Microsoft Corporation SIGNED)(2013-12-13 11:08:39) Reg HKLM\SOFTWARE\Classes\CLSID\{2087c2f4-2cef-4953-a8ab-66779b670495}\InProcServer32@ C:\Windows\system32\winhttp.dll (Windows HTTP Services/Microsoft Corporation SIGNED)(2013-09-25 17:38:10) Reg HKLM\SOFTWARE\Classes\CLSID\{208D2C60-3AEA-1069-A2D7-08002B30309D}@InfoTip C:\Windows\system32\shell32.dll (Windows Shell Common Dll/Microsoft Corporation SIGNED)(2013-09-26 18:21:44) Reg HKLM\SOFTWARE\Classes\CLSID\{208D2C60-3AEA-1069-A2D7-08002B30309D}\shell\find\command@ C:\Windows\Explorer.exe (Windows Explorer/Microsoft Corporation SIGNED)(2013-09-25 17:37:42) Reg HKLM\SOFTWARE\Classes\CLSID\{20b1cb23-6968-4eb9-b7d4-a66d00d07cee}\InProcServer32@ C:\Windows\system32\shell32.dll (Windows Shell Common Dll/Microsoft Corporation SIGNED)(2013-09-26 18:21:44) Reg HKLM\SOFTWARE\Classes\CLSID\{20CCEF1E-0185-41a5-A933-509C43B54F98}\InProcServer32@ C:\Windows\System32\ieframe.dll (Internet Browser/Microsoft Corporation SIGNED)(2013-12-13 11:08:39) Reg HKLM\SOFTWARE\Classes\CLSID\{20D04FE0-3AEA-1069-A2D8-08002B30309D}@InfoTip C:\Windows\system32\shell32.dll (Windows Shell Common Dll/Microsoft Corporation SIGNED)(2013-09-26 18:21:44) Reg HKLM\SOFTWARE\Classes\CLSID\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\shell\find\command@ C:\Windows\Explorer.exe (Windows Explorer/Microsoft Corporation SIGNED)(2013-09-25 17:37:42) Reg HKLM\SOFTWARE\Classes\CLSID\{20F51CDD-49B8-0144-BE14-91EFAB087730}\InprocServer32@ C:\Windows\system32\oleaut32.dll (Microsoft Corporation SIGNED)(2013-09-25 08:15:54) Reg HKLM\SOFTWARE\Classes\CLSID\{21167137-B7E3-40B6-8863-8386E8C05716}\InProcServer32@ C:\Windows\system32\xwizards.dll (Extensible Wizards Manager Module/Microsoft Corporation SIGNED)(2009-07-13 23:51:41) Reg HKLM\SOFTWARE\Classes\CLSID\{217FC9C0-3AEA-1069-A2DB-08002B30309D}\InProcServer32@ C:\Windows\system32\shell32.dll (Windows Shell Common Dll/Microsoft Corporation SIGNED)(2013-09-26 18:21:44) Reg HKLM\SOFTWARE\Classes\CLSID\{2183DACA-D0BF-4a31-97F7-B87618A81955}\InProcServer32@ C:\Windows\System32\ieframe.dll (Internet Browser/Microsoft Corporation SIGNED)(2013-12-13 11:08:39) Reg HKLM\SOFTWARE\Classes\CLSID\{21B22460-3AEA-1069-A2DC-08002B30309D}\InProcServer32@ C:\Windows\system32\shell32.dll (Windows Shell Common Dll/Microsoft Corporation SIGNED)(2013-09-26 18:21:44) Reg HKLM\SOFTWARE\Classes\CLSID\{21F5A790-53EA-3D73-86C3-A5BA6CF65FE9}\InprocServer32@ C:\Windows\system32\mscoree.dll (Microsoft .NET Runtime Execution Engine/Microsoft Corporation SIGNED)(2013-09-25 17:38:26) Reg HKLM\SOFTWARE\Classes\CLSID\{220898A1-E3F3-46B4-96EA-B0855DC968B6}\InProcServer32@ C:\Windows\system32\shell32.dll (Windows Shell Common Dll/Microsoft Corporation SIGNED)(2013-09-26 18:21:44) Reg HKLM\SOFTWARE\Classes\CLSID\{22B6E688-B3A5-44FC-B0CE-69F20653CD61}\InProcServer32@ C:\Windows\system32\tsworkspace.dll (RemoteApp and Desktop Connection Component/Microsoft Corporation SIGNED)(2013-09-25 17:37:06) Reg HKLM\SOFTWARE\Classes\CLSID\{22BDC741-73F0-41DB-9463-E343DEF3E376}\InProcServer32@ C:\Windows\System32\QAgent.dll (Quarantine Agent Proxy/Microsoft Corporation SIGNED)(2013-09-25 17:38:03) Reg HKLM\SOFTWARE\Classes\CLSID\{22c6c651-f6ea-46be-bc83-54e83314c67f}\InProcServer32@ C:\Windows\system32\shell32.dll (Windows Shell Common Dll/Microsoft Corporation SIGNED)(2013-09-26 18:21:44) Reg HKLM\SOFTWARE\Classes\CLSID\{232b501c-348c-457e-972c-7c3adb1552c1}\InprocServer32@ C:\Windows\system32\sdautoplay.dll (Microsoft� Windows Backup AutoPlay Integration Library/Microsoft Corporation SIGNED)(2009-07-13 23:23:31) Reg HKLM\SOFTWARE\Classes\CLSID\{23613363-0028-431D-A49E-A3CD482D3926}\InProcServer32@ C:\Windows\system32\shell32.dll (Windows Shell Common Dll/Microsoft Corporation SIGNED)(2013-09-26 18:21:44) Reg HKLM\SOFTWARE\Classes\CLSID\{23CF860E-9D2C-451A-8E83-C79C848D85A6}\InProcServer32@ C:\Windows\system32\sxproxy.dll (Microsoft� Windows System Protection Proxy Library/Microsoft Corporation SIGNED)(2009-07-13 23:23:18) Reg HKLM\SOFTWARE\Classes\CLSID\{241D7C96-F8BF-4F85-B01F-E2B043341A4B}@InfoTip C:\Windows\System32\tsworkspace.dll (RemoteApp and Desktop Connection Component/Microsoft Corporation SIGNED)(2013-09-25 17:37:06) Reg HKLM\SOFTWARE\Classes\CLSID\{24400D16-5754-11d2-8218-00C04FB687DA}\InProcServer32@ C:\Windows\System32\DATACLEN.DLL (Disk Space Cleaner for Windows/Microsoft Corporation SIGNED)(2009-07-13 23:40:20) Reg HKLM\SOFTWARE\Classes\CLSID\{24540EBC-316E-35D2-80DB-8A535CAF6A35}\InprocServer32@ C:\Windows\system32\mscoree.dll (Microsoft .NET Runtime Execution Engine/Microsoft Corporation SIGNED)(2013-09-25 17:38:26) Reg HKLM\SOFTWARE\Classes\CLSID\{25150040-b8f1-418e-af61-b51071ac1ee2}\InProcServer32@ C:\Windows\system32\shell32.dll (Windows Shell Common Dll/Microsoft Corporation SIGNED)(2013-09-26 18:21:44) Reg HKLM\SOFTWARE\Classes\CLSID\{25336920-03F9-11CF-8FD0-00AA00686F13}\InProcServer32@ C:\Windows\System32\mshtml.dll (Microsoft (R) HTML Viewer/Microsoft Corporation SIGNED)(2013-12-13 11:08:38) Reg HKLM\SOFTWARE\Classes\CLSID\{25585dc7-4da0-438d-ad04-e42c8d2d64b9}\InProcServer32@ C:\Windows\system32\shell32.dll (Windows Shell Common Dll/Microsoft Corporation SIGNED)(2013-09-26 18:21:44) Reg HKLM\SOFTWARE\Classes\CLSID\{2559a1f0-21d7-11d4-bdaf-00c04f60b9f0}@LocalizedString C:\Windows\explorer.exe (Windows Explorer/Microsoft Corporation SIGNED)(2013-09-25 17:37:42) Reg HKLM\SOFTWARE\Classes\CLSID\{2559a1f0-21d7-11d4-bdaf-00c04f60b9f0}\Instance\InitPropertyBag@command C:\Windows\system32\shell32.dll (Windows Shell Common Dll/Microsoft Corporation SIGNED)(2013-09-26 18:21:44) Reg HKLM\SOFTWARE\Classes\CLSID\{2559a1f1-21d7-11d4-bdaf-00c04f60b9f0}@LocalizedString C:\Windows\explorer.exe (Windows Explorer/Microsoft Corporation SIGNED)(2013-09-25 17:37:42) Reg HKLM\SOFTWARE\Classes\CLSID\{2559a1f1-21d7-11d4-bdaf-00c04f60b9f0}\Instance\InitPropertyBag@command C:\Windows\system32\shell32.dll (Windows Shell Common Dll/Microsoft Corporation SIGNED)(2013-09-26 18:21:44) Reg HKLM\SOFTWARE\Classes\CLSID\{2559a1f2-21d7-11d4-bdaf-00c04f60b9f0}@LocalizedString C:\Windows\explorer.exe (Windows Explorer/Microsoft Corporation SIGNED)(2013-09-25 17:37:42) Reg HKLM\SOFTWARE\Classes\CLSID\{2559a1f2-21d7-11d4-bdaf-00c04f60b9f0}\Instance\InitPropertyBag@command C:\Windows\system32\shell32.dll (Windows Shell Common Dll/Microsoft Corporation SIGNED)(2013-09-26 18:21:44) Reg HKLM\SOFTWARE\Classes\CLSID\{2559a1f3-21d7-11d4-bdaf-00c04f60b9f0}@LocalizedString C:\Windows\explorer.exe (Windows Explorer/Microsoft Corporation SIGNED)(2013-09-25 17:37:42) Reg HKLM\SOFTWARE\Classes\CLSID\{2559a1f3-21d7-11d4-bdaf-00c04f60b9f0}\Instance\InitPropertyBag@command C:\Windows\system32\shell32.dll (Windows Shell Common Dll/Microsoft Corporation SIGNED)(2013-09-26 18:21:44) Reg HKLM\SOFTWARE\Classes\CLSID\{2559a1f5-21d7-11d4-bdaf-00c04f60b9f0}@LocalizedString C:\Windows\explorer.exe (Windows Explorer/Microsoft Corporation SIGNED)(2013-09-25 17:37:42) Reg HKLM\SOFTWARE\Classes\CLSID\{2559a1f5-21d7-11d4-bdaf-00c04f60b9f0}\Instance\InitPropertyBag@opentext C:\Windows\system32\shell32.dll (Windows Shell Common Dll/Microsoft Corporation SIGNED)(2013-09-26 18:21:44) Reg HKLM\SOFTWARE\Classes\CLSID\{26EE0668-A00A-44D7-9371-BEB064C98683}@System.AppUserModel.RelaunchIconResource C:\Windows\system32\imageres.dll (Windows Image Resource/Microsoft Corporation SIGNED)(2009-07-13 23:42:24) Reg HKLM\SOFTWARE\Classes\CLSID\{26EE0668-A00A-44D7-9371-BEB064C98683}@LocalizedString C:\Windows\system32\shell32.dll (Windows Shell Common Dll/Microsoft Corporation SIGNED)(2013-09-26 18:21:44) Reg HKLM\SOFTWARE\Classes\CLSID\{2763BE6B-F8CF-39D9-A2E8-9E9815C0815E}\InprocServer32@ C:\Windows\system32\mscoree.dll (Microsoft .NET Runtime Execution Engine/Microsoft Corporation SIGNED)(2013-09-25 17:38:26) Reg HKLM\SOFTWARE\Classes\CLSID\{27757413-6D56-4F97-A711-F1717121C7A5}\InprocHandler32@ C:\Windows\system32\ole32.dll (Microsoft OLE for Windows/Microsoft Corporation SIGNED)(2013-09-25 17:36:42) Reg HKLM\SOFTWARE\Classes\CLSID\{27E986E1-BAEC-3D48-82E4-14169CA8CECF}\InprocServer32@ C:\Windows\system32\mscoree.dll (Microsoft .NET Runtime Execution Engine/Microsoft Corporation SIGNED)(2013-09-25 17:38:26) Reg HKLM\SOFTWARE\Classes\CLSID\{2854F705-3548-414C-A113-93E27C808C85}\InprocServer32@ C:\Windows\system32\EhStorShell.dll (Windows Enhanced Storage Shell Extension DLL/Microsoft Corporation SIGNED)(2009-07-13 23:45:42) Reg HKLM\SOFTWARE\Classes\CLSID\{286AA738-2928-49af-A410-4118F5C31626}\InprocServer32@ C:\Windows\system32\dot3hc.dll (Dot3 Helper Class/Microsoft Corporation SIGNED)(2009-07-13 23:52:47) Reg HKLM\SOFTWARE\Classes\CLSID\{28AF2E16-0190-44F4-9CED-08AF91145361}\InprocServer32@ C:\Windows\System32\msrahc.dll (Remote Assistance Diagnostics Provider/Microsoft Corporation SIGNED)(2009-07-13 23:20:09) Reg HKLM\SOFTWARE\Classes\CLSID\{294935CE-F637-4E7C-A41B-AB255460B862}\InprocServer32@ C:\Windows\System32\audioses.dll (Audio Session/Microsoft Corporation SIGNED)(2013-09-25 17:36:17) Reg HKLM\SOFTWARE\Classes\CLSID\{2959380c-1567-40ec-80b0-05907ad6f9de}\InProcServer32@ C:\Windows\system32\netcorehc.dll (Networking Core Diagnostics Helper Classes/Microsoft Corporation SIGNED)(2009-07-13 23:52:44) Reg HKLM\SOFTWARE\Classes\CLSID\{29625281-51CE-3F8A-AC4D-E360CACB92E2}\InprocServer32@ C:\Windows\system32\mscoree.dll (Microsoft .NET Runtime Execution Engine/Microsoft Corporation SIGNED)(2013-09-25 17:38:26) Reg HKLM\SOFTWARE\Classes\CLSID\{2965e715-eb66-4719-b53f-1672673bbefa}\InProcServer32@ C:\Windows\system32\shell32.dll (Windows Shell Common Dll/Microsoft Corporation SIGNED)(2013-09-26 18:21:44) Reg HKLM\SOFTWARE\Classes\CLSID\{29A6CF6F-D663-31A7-9210-1347871681FC}\InprocServer32@ C:\Windows\system32\mscoree.dll (Microsoft .NET Runtime Execution Engine/Microsoft Corporation SIGNED)(2013-09-25 17:38:26) Reg HKLM\SOFTWARE\Classes\CLSID\{2A744BD8-158A-4bbf-9513-4A656F6C01D7}\InprocServer32@ C:\Windows\system32\tquery.dll (tquery.dll/Microsoft Corporation SIGNED)(2013-09-25 17:37:02) Reg HKLM\SOFTWARE\Classes\CLSID\{2A7B042D-578A-4366-9A3D-154C0498458E}\InprocServer32@ C:\Windows\system32\mscoree.dll (Microsoft .NET Runtime Execution Engine/Microsoft Corporation SIGNED)(2013-09-25 17:38:26) Reg HKLM\SOFTWARE\Classes\CLSID\{2af6bcaa-f526-4803-aeb8-5777ce386647}\InprocServer32@ C:\Windows\system32\raschap.dll (Remote Access PPP CHAP/Microsoft Corporation SIGNED)(2013-09-25 17:38:05) Reg HKLM\SOFTWARE\Classes\CLSID\{2B4F54B1-3D6D-11d0-8258-00C04FD5AE38}\InProcServer32@ C:\Windows\System32\ieframe.dll (Internet Browser/Microsoft Corporation SIGNED)(2013-12-13 11:08:39) Reg HKLM\SOFTWARE\Classes\CLSID\{2BB6C5E0-C2B9-3608-8868-21CFD6DDB91E}\InprocServer32@ C:\Windows\system32\mscoree.dll (Microsoft .NET Runtime Execution Engine/Microsoft Corporation SIGNED)(2013-09-25 17:38:26) Reg HKLM\SOFTWARE\Classes\CLSID\{2BB8B28A-58DC-449C-A89B-DAEFD0A8933D}\InProcServer32@ C:\Windows\System32\tsworkspace.dll (RemoteApp and Desktop Connection Component/Microsoft Corporation SIGNED)(2013-09-25 17:37:06) Reg HKLM\SOFTWARE\Classes\CLSID\{2C314899-8F99-3041-A49D-2F6AFC0E6296}\InprocServer32@ C:\Windows\system32\mscoree.dll (Microsoft .NET Runtime Execution Engine/Microsoft Corporation SIGNED)(2013-09-25 17:38:26) Reg HKLM\SOFTWARE\Classes\CLSID\{2C5BC43E-3369-4C33-AB0C-BE9469677AF4}\InprocServer32@ C:\Windows\system32\FirewallAPI.dll (Windows Firewall API/Microsoft Corporation SIGNED)(2009-07-13 23:53:14) Reg HKLM\SOFTWARE\Classes\CLSID\{2CB6C2D3-DD7C-11D2-AFE4-00105A994724}\InprocServer32@ C:\PROGRA~1\COMMON~1\SYSTEM\OLEDB~1\MSDMINE.DLL (Microsoft OLE DB Provider for Data Mining Services/Microsoft Corporation SIGNED)(2005-05-03 23:06:32) Reg HKLM\SOFTWARE\Classes\CLSID\{2D2E24CB-0CD5-458F-86EA-3E6FA22C8E64}\InprocServer32@ C:\Windows\system32\quartz.dll (DirectShow Runtime./Microsoft Corporation SIGNED)(2013-09-25 08:10:55) Reg HKLM\SOFTWARE\Classes\CLSID\{2d3468c1-36a7-43b6-ac24-d3f02fd9607a}\InProcServer32@ C:\Windows\system32\shell32.dll (Windows Shell Common Dll/Microsoft Corporation SIGNED)(2013-09-26 18:21:44) Reg HKLM\SOFTWARE\Classes\CLSID\{2D5EC63C-1B3E-3EE4-9052-EB0D0303549C}\InprocServer32@ C:\Windows\system32\mscoree.dll (Microsoft .NET Runtime Execution Engine/Microsoft Corporation SIGNED)(2013-09-25 17:38:26) Reg HKLM\SOFTWARE\Classes\CLSID\{2DD80115-AD1E-41F6-A219-A4F4B583D1F9}\InProcServer32@ C:\Windows\system32\WcsPlugInService.dll (WcsPlugInService DLL/Microsoft Corporation SIGNED)(2009-07-13 23:25:13) Reg HKLM\SOFTWARE\Classes\CLSID\{2DECBCB7-BAC0-316D-9131-43035C5CB480}\InprocServer32@ C:\Windows\system32\mscoree.dll (Microsoft .NET Runtime Execution Engine/Microsoft Corporation SIGNED)(2013-09-25 17:38:26) Reg HKLM\SOFTWARE\Classes\CLSID\{2f2dc38b-34d2-462c-add4-f74cc15510a1}\InProcServer32@ C:\Windows\system32\explorerframe.dll (ExplorerFrame/Microsoft Corporation SIGNED)(2013-09-25 17:38:17) Reg HKLM\SOFTWARE\Classes\CLSID\{2f893820-7089-46cc-a6e8-c4aae45f151b}\InprocServer32@ C:\Windows\system32\msdtcuiu.dll (Microsoft Distributed Transaction Coordinator Administrative DLL/Microsoft Corporation SIGNED)(2009-07-13 23:44:10) Reg HKLM\SOFTWARE\Classes\CLSID\{301056D0-6DFF-11D2-9EEB-006008039E37}\InprocServer32@ C:\Windows\system32\quartz.dll (DirectShow Runtime./Microsoft Corporation SIGNED)(2013-09-25 08:10:55) Reg HKLM\SOFTWARE\Classes\CLSID\{3028902F-6374-48b2-8DC6-9725E775B926}\InProcServer32@ C:\Windows\System32\ieframe.dll (Internet Browser/Microsoft Corporation SIGNED)(2013-12-13 11:08:39) Reg HKLM\SOFTWARE\Classes\CLSID\{304CE942-6E39-40D8-943A-B913C40C9CD4}\InprocServer32@ C:\Windows\system32\FirewallAPI.dll (Windows Firewall API/Microsoft Corporation SIGNED)(2009-07-13 23:53:14) Reg HKLM\SOFTWARE\Classes\CLSID\{3050F391-98B5-11CF-BB82-00AA00BDCE0B}\InProcServer32@ C:\Windows\System32\mshtml.dll (Microsoft (R) HTML Viewer/Microsoft Corporation SIGNED)(2013-12-13 11:08:38) Reg HKLM\SOFTWARE\Classes\CLSID\{30655864-f8cd-45f9-b7d6-6721acb69c5e}\InProcServer32@ C:\Windows\system32\netcorehc.dll (Networking Core Diagnostics Helper Classes/Microsoft Corporation SIGNED)(2009-07-13 23:52:44) Reg HKLM\SOFTWARE\Classes\CLSID\{3080F90D-D7AD-11D9-BD98-0000947B0257}@LocalizedString C:\Windows\system32\shell32.dll (Windows Shell Common Dll/Microsoft Corporation SIGNED)(2013-09-26 18:21:44) Reg HKLM\SOFTWARE\Classes\CLSID\{30AC0B94-3BDB-3199-8A5D-ECA0C5458381}\InprocServer32@ C:\Windows\system32\mscoree.dll (Microsoft .NET Runtime Execution Engine/Microsoft Corporation SIGNED)(2013-09-25 17:38:26) Reg HKLM\SOFTWARE\Classes\CLSID\{31430c59-bed1-11D1-8De8-00C04FC2E0C7}\InprocServer32@ C:\Windows\system32\clbcatq.dll (COM+ Configuration Catalog/Microsoft Corporation SIGNED)(2009-07-13 23:44:44) Reg HKLM\SOFTWARE\Classes\CLSID\{31b11d80-9ed7-44f7-b1cd-c95992a738b9}\InProcServer32@ C:\Windows\system32\shell32.dll (Windows Shell Common Dll/Microsoft Corporation SIGNED)(2013-09-26 18:21:44) Reg HKLM\SOFTWARE\Classes\CLSID\{31C967B5-2F8A-3957-9C6D-34A0731DB36C}\InprocServer32@ C:\Windows\system32\mscoree.dll (Microsoft .NET Runtime Execution Engine/Microsoft Corporation SIGNED)(2013-09-25 17:38:26) Reg HKLM\SOFTWARE\Classes\CLSID\{323CA680-C24D-4099-B94D-446DD2D7249E}@LocalizedString C:\Windows\system32\shell32.dll (Windows Shell Common Dll/Microsoft Corporation SIGNED)(2013-09-26 18:21:44) Reg HKLM\SOFTWARE\Classes\CLSID\{32B533BB-EDAE-11d0-BD5A-00AA00B92AF1}\InprocServer32@ C:\Windows\system32\urlmon.dll (OLE32 Extensions for Win32/Microsoft Corporation SIGNED)(2013-12-13 11:08:41) Reg HKLM\SOFTWARE\Classes\CLSID\{336475D0-942A-11CE-A870-00AA002FEAB5}\InprocServer32@ C:\Windows\system32\quartz.dll (DirectShow Runtime./Microsoft Corporation SIGNED)(2013-09-25 08:10:55) Reg HKLM\SOFTWARE\Classes\CLSID\{33BCC8EC-0D01-4E10-AD3D-4DAF749873ED}\InProcServer32@ C:\Windows\system32\explorerframe.dll (ExplorerFrame/Microsoft Corporation SIGNED)(2013-09-25 17:38:17) Reg HKLM\SOFTWARE\Classes\CLSID\{33C53A50-F456-4884-B049-85FD643ECFED}\InProcServer32@ C:\Windows\system32\msctf.dll (MSCTF Server DLL/Microsoft Corporation SIGNED)(2009-07-13 23:28:05) Reg HKLM\SOFTWARE\Classes\CLSID\{33FACFE0-A9BE-11D0-A520-00A0D10129C0}\InprocServer32@ C:\Windows\system32\quartz.dll (DirectShow Runtime./Microsoft Corporation SIGNED)(2013-09-25 08:10:55) Reg HKLM\SOFTWARE\Classes\CLSID\{346D5B9F-45E1-45C0-AADF-1B7D221E9063}\InprocServer32@ C:\Windows\system32\mscoree.dll (Microsoft .NET Runtime Execution Engine/Microsoft Corporation SIGNED)(2013-09-25 17:38:26) Reg HKLM\SOFTWARE\Classes\CLSID\{34a3d570-67d9-4265-a9ee-8c3fa3dfeccf}\InProcServer32@ C:\Windows\System32\ieframe.dll (Internet Browser/Microsoft Corporation SIGNED)(2013-12-13 11:08:39) Reg HKLM\SOFTWARE\Classes\CLSID\{34E0D4B8-A470-11D6-9500-00065B874123}\InProcServer32@ C:\Program Files\Common Files\Microsoft Shared\OFFICE11\MSSOAP30.DLL (Microsoft Office Soap SDK/Microsoft Corporation)(2002-12-06 12:25:10) Reg HKLM\SOFTWARE\Classes\CLSID\{3523c2fb-4031-44e4-9a3b-f1e94986ee7f}\InprocServer32@ C:\Windows\system32\mstscax.dll (Remote Desktop Services ActiveX Client/Microsoft Corporation SIGNED)(2013-09-25 08:15:19) Reg HKLM\SOFTWARE\Classes\CLSID\{35786D3C-B075-49b9-88DD-029876E11C01}@InfoTip C:\Windows\system32\wpdshext.dll (Portable Devices Shell Extension/Microsoft Corporation SIGNED)(2013-09-25 17:37:00) Reg HKLM\SOFTWARE\Classes\CLSID\{35CEC8A3-2BE6-11D2-8773-92E220524153}\InProcServer32@ C:\Windows\system32\stobject.dll (Systray shell service object/Microsoft Corporation SIGNED)(2013-09-25 17:36:32) Reg HKLM\SOFTWARE\Classes\CLSID\{35E946E4-7CDA-3824-8B24-D799A96309AD}\InprocServer32@ C:\Windows\system32\mscoree.dll (Microsoft .NET Runtime Execution Engine/Microsoft Corporation SIGNED)(2013-09-25 17:38:26) Reg HKLM\SOFTWARE\Classes\CLSID\{3630AB4B-C0D2-4C1B-B7E7-73A2CF9A4521}@LocalizedString C:\Windows\ehome\ehres.dll (Media Center Resources/Microsoft Corporation SIGNED)(2009-07-14 00:11:14) Reg HKLM\SOFTWARE\Classes\CLSID\{36DCDA30-DC3B-4D93-BE42-90B2D74C64E7}\InprocServer32@ C:\Windows\system32\mscoree.dll (Microsoft .NET Runtime Execution Engine/Microsoft Corporation SIGNED)(2013-09-25 17:38:26) Reg HKLM\SOFTWARE\Classes\CLSID\{36F54939-CD3B-4C73-92D5-F9A389ED631C}\InprocServer32@ C:\Windows\system32\EhStorShell.dll (Windows Enhanced Storage Shell Extension DLL/Microsoft Corporation SIGNED)(2009-07-13 23:45:42) Reg HKLM\SOFTWARE\Classes\CLSID\{372FCE38-4324-11D0-8810-00A0C903B83C}\InprocServer32@ C:\Windows\system32\certcli.dll (Microsoft� Active Directory Certificate Services Client/Microsoft Corporation SIGNED)(2013-09-25 17:38:23) Reg HKLM\SOFTWARE\Classes\CLSID\{3730bbf8-631a-48fb-9085-e2143c11563b}\InProcServer32@ C:\Windows\system32\xwizards.dll (Extensible Wizards Manager Module/Microsoft Corporation SIGNED)(2009-07-13 23:51:41) Reg HKLM\SOFTWARE\Classes\CLSID\{374050DD-6190-3257-8812-8230BF095147}\InprocServer32@ C:\Windows\system32\mscoree.dll (Microsoft .NET Runtime Execution Engine/Microsoft Corporation SIGNED)(2013-09-25 17:38:26) Reg HKLM\SOFTWARE\Classes\CLSID\{3756e7f5-e514-4776-a32b-eb24bc1efe7a}\InProcServer32@ C:\Windows\system32\shell32.dll (Windows Shell Common Dll/Microsoft Corporation SIGNED)(2013-09-26 18:21:44) Reg HKLM\SOFTWARE\Classes\CLSID\{37E92A92-D9AA-11D2-BF84-8EF2B1555AED}\InprocServer32@ C:\Windows\system32\quartz.dll (DirectShow Runtime./Microsoft Corporation SIGNED)(2013-09-25 08:10:55) Reg HKLM\SOFTWARE\Classes\CLSID\{37ea3a21-7493-4208-a011-7f9ea79ce9f5}\InProcServer32@ C:\Windows\system32\shell32.dll (Windows Shell Common Dll/Microsoft Corporation SIGNED)(2013-09-26 18:21:44) Reg HKLM\SOFTWARE\Classes\CLSID\{37efd44d-ef8d-41b1-940d-96973a50e9e0}@InfoTip C:\Program Files\Windows Sidebar\sidebar.exe (Windows Desktop Gadgets/Microsoft Corporation SIGNED)(2013-09-25 17:36:32) Reg HKLM\SOFTWARE\Classes\CLSID\{38A98528-6CBF-4CA9-8DC0-B1E1D10F7B1B}@LocalizedString C:\Windows\system32\van.dll (View Available Networks/Microsoft Corporation SIGNED)(2013-09-25 17:38:08) Reg HKLM\SOFTWARE\Classes\CLSID\{390E92C9-FA66-3357-BEF2-45A1F34186B9}\InprocServer32@ C:\Windows\system32\mscoree.dll (Microsoft .NET Runtime Execution Engine/Microsoft Corporation SIGNED)(2013-09-25 17:38:26) Reg HKLM\SOFTWARE\Classes\CLSID\{39F8D76B-0928-11D1-97DF-00C04FB9618A}\InprocServer32@ C:\Windows\system32\msdtcprx.dll (Microsoft Distributed Transaction Coordinator OLE Transactions Interface Proxy DLL/Microsoft Corporation SIGNED)(2009-07-13 23:44:23) Reg HKLM\SOFTWARE\Classes\CLSID\{3ABEAFC4-F48F-4517-A9B0-8AD6A94A99A1}\InProcServer32@ C:\Windows\System32\provsvc.dll (Windows HomeGroup/Microsoft Corporation SIGNED)(2013-09-25 17:37:30) Reg HKLM\SOFTWARE\Classes\CLSID\{3ad05575-8857-4850-9277-11b85bdb8e09}@LocalizedString C:\Windows\system32\shell32.dll (Windows Shell Common Dll/Microsoft Corporation SIGNED)(2013-09-26 18:21:44) Reg HKLM\SOFTWARE\Classes\CLSID\{3B0398C9-7812-4007-85CB-18C771F2206F}\InprocServer32@ C:\Windows\system32\mscoree.dll (Microsoft .NET Runtime Execution Engine/Microsoft Corporation SIGNED)(2013-09-25 17:38:26) Reg HKLM\SOFTWARE\Classes\CLSID\{3bb4118f-ddfd-4d30-a348-9fb5d6bf1afe}\InProcServer32@ C:\Windows\system32\shell32.dll (Windows Shell Common Dll/Microsoft Corporation SIGNED)(2013-09-26 18:21:44) Reg HKLM\SOFTWARE\Classes\CLSID\{3BD1F243-9BC4-305D-9B1C-0D10C80329FC}\InprocServer32@ C:\Windows\system32\mscoree.dll (Microsoft .NET Runtime Execution Engine/Microsoft Corporation SIGNED)(2013-09-25 17:38:26) Reg HKLM\SOFTWARE\Classes\CLSID\{3c2654c6-7372-4f6b-b310-55d6128f49d2}\InProcServer32@ C:\Windows\system32\shell32.dll (Windows Shell Common Dll/Microsoft Corporation SIGNED)(2013-09-26 18:21:44) Reg HKLM\SOFTWARE\Classes\CLSID\{3C374A40-BAE4-11CF-BF7D-00AA006946EE}\InProcServer32@ C:\Windows\System32\ieframe.dll (Internet Browser/Microsoft Corporation SIGNED)(2013-12-13 11:08:39) Reg HKLM\SOFTWARE\Classes\CLSID\{3C9DCA8B-4410-3143-B801-559553EB6725}\InprocServer32@ C:\Windows\system32\mscoree.dll (Microsoft .NET Runtime Execution Engine/Microsoft Corporation SIGNED)(2013-09-25 17:38:26) Reg HKLM\SOFTWARE\Classes\CLSID\{3CCF8A41-5C85-11d0-9796-00AA00B90ADF}\InProcServer32@ C:\Windows\system32\explorerframe.dll (ExplorerFrame/Microsoft Corporation SIGNED)(2013-09-25 17:38:17) Reg HKLM\SOFTWARE\Classes\CLSID\{3CDED51A-86B4-39F0-A12A-5D1FDCED6546}\InprocServer32@ C:\Windows\system32\mscoree.dll (Microsoft .NET Runtime Execution Engine/Microsoft Corporation SIGNED)(2013-09-25 17:38:26) Reg HKLM\SOFTWARE\Classes\CLSID\{3CE74DE4-53D3-4D74-8B83-431B3828BA53}\InProcServer32@ C:\Windows\System32\msctf.dll (MSCTF Server DLL/Microsoft Corporation SIGNED)(2009-07-13 23:28:05) Reg HKLM\SOFTWARE\Classes\CLSID\{3d154a2d-d911-437e-a30c-5f56a9b7081d}\InProcServer32@ C:\Windows\system32\shell32.dll (Windows Shell Common Dll/Microsoft Corporation SIGNED)(2013-09-26 18:21:44) Reg HKLM\SOFTWARE\Classes\CLSID\{3D367908-928F-3C13-8B93-5E1718820F6D}\InprocServer32@ C:\Windows\system32\mscoree.dll (Microsoft .NET Runtime Execution Engine/Microsoft Corporation SIGNED)(2013-09-25 17:38:26) Reg HKLM\SOFTWARE\Classes\CLSID\{3dad6c5d-2167-4cae-9914-f99e41c12cfa}\InProcServer32@ C:\Windows\system32\shell32.dll (Windows Shell Common Dll/Microsoft Corporation SIGNED)(2013-09-26 18:21:44) Reg HKLM\SOFTWARE\Classes\CLSID\{3DC7A020-0ACD-11CF-A9BB-00AA004AE837}@FriendlyTypeName C:\Windows\System32\ieframe.dll (Internet Browser/Microsoft Corporation SIGNED)(2013-12-13 11:08:39) Reg HKLM\SOFTWARE\Classes\CLSID\{3dd53d40-7b8b-11D0-b013-00aa0059ce02}\InprocServer32@ C:\Windows\system32\urlmon.dll (OLE32 Extensions for Win32/Microsoft Corporation SIGNED)(2013-12-13 11:08:41) Reg HKLM\SOFTWARE\Classes\CLSID\{3DDB2114-9285-30A6-906D-B117640CA927}\InprocServer32@ C:\Windows\system32\mscoree.dll (Microsoft .NET Runtime Execution Engine/Microsoft Corporation SIGNED)(2013-09-25 17:38:26) Reg HKLM\SOFTWARE\Classes\CLSID\{3DECD5DD-A27B-48DC-8BAA-2682CFA265FF}\InProcServer32@ C:\Windows\system32\tsworkspace.dll (RemoteApp and Desktop Connection Component/Microsoft Corporation SIGNED)(2013-09-25 17:37:06) Reg HKLM\SOFTWARE\Classes\CLSID\{3E5509F0-1FB9-304D-8174-75D6C9AFE5DA}\InprocServer32@ C:\Windows\system32\mscoree.dll (Microsoft .NET Runtime Execution Engine/Microsoft Corporation SIGNED)(2013-09-25 17:38:26) Reg HKLM\SOFTWARE\Classes\CLSID\{3e71f26d-136f-4545-813f-35276024b705}\InProcServer32@ C:\Windows\System32\ieframe.dll (Internet Browser/Microsoft Corporation SIGNED)(2013-12-13 11:08:39) Reg HKLM\SOFTWARE\Classes\CLSID\{3E8E0F03-D3FD-3A93-BAE0-C74A6494DBCA}\InprocServer32@ C:\Windows\system32\mscoree.dll (Microsoft .NET Runtime Execution Engine/Microsoft Corporation SIGNED)(2013-09-25 17:38:26) Reg HKLM\SOFTWARE\Classes\CLSID\{3f454f0e-42ae-4d7c-8ea3-328250d6e272}\InProcServer32@ C:\Windows\system32\shell32.dll (Windows Shell Common Dll/Microsoft Corporation SIGNED)(2013-09-26 18:21:44) Reg HKLM\SOFTWARE\Classes\CLSID\{3F4A4283-6A08-3E90-A976-2C2D3BE4EB0B}\InprocServer32@ C:\Windows\system32\mscoree.dll (Microsoft .NET Runtime Execution Engine/Microsoft Corporation SIGNED)(2013-09-25 17:38:26) Reg HKLM\SOFTWARE\Classes\CLSID\{3F6953F0-5359-47FC-BD99-9F2CB95A62FD}\InProcServer32@ C:\Windows\system32\shell32.dll (Windows Shell Common Dll/Microsoft Corporation SIGNED)(2013-09-26 18:21:44) Reg HKLM\SOFTWARE\Classes\CLSID\{3FA7A1C5-812C-3B56-B957-CB14AF670C09}\InprocServer32@ C:\Windows\system32\mscoree.dll (Microsoft .NET Runtime Execution Engine/Microsoft Corporation SIGNED)(2013-09-25 17:38:26) Reg HKLM\SOFTWARE\Classes\CLSID\{3FC0B520-68A9-11D0-8D77-00C04FD70822}\InProcServer32@ C:\Windows\system32\shell32.dll (Windows Shell Common Dll/Microsoft Corporation SIGNED)(2013-09-26 18:21:44) Reg HKLM\SOFTWARE\Classes\CLSID\{3FDCEEC6-B14B-37E2-BB69-ABC7CA0DA22F}\InprocServer32@ C:\Windows\system32\mscoree.dll (Microsoft .NET Runtime Execution Engine/Microsoft Corporation SIGNED)(2013-09-25 17:38:26) Reg HKLM\SOFTWARE\Classes\CLSID\{40dd6e20-7c17-11ce-a804-00aa003ca9f6}\InProcServer32@ C:\Windows\system32\ntshrui.dll (Shell extensions for sharing/Microsoft Corporation SIGNED)(2013-09-25 17:37:19) Reg HKLM\SOFTWARE\Classes\CLSID\{40FCB674-2A5E-3B8C-A8AF-12AA9E76613D}\InprocServer32@ C:\Windows\system32\mscoree.dll (Microsoft .NET Runtime Execution Engine/Microsoft Corporation SIGNED)(2013-09-25 17:38:26) Reg HKLM\SOFTWARE\Classes\CLSID\{418AFB70-F8B8-11CE-AAC6-0020AF0B99A3}\InprocServer32@ C:\Windows\system32\quartz.dll (DirectShow Runtime./Microsoft Corporation SIGNED)(2013-09-25 08:10:55) Reg HKLM\SOFTWARE\Classes\CLSID\{418c8b64-5463-461d-88e0-75e2afa3c6fa}\InProcServer32@ C:\Windows\system32\shell32.dll (Windows Shell Common Dll/Microsoft Corporation SIGNED)(2013-09-26 18:21:44) Reg HKLM\SOFTWARE\Classes\CLSID\{41970D73-92F6-36D9-874D-3BD0762A0D6F}\InprocServer32@ C:\Windows\system32\mscoree.dll (Microsoft .NET Runtime Execution Engine/Microsoft Corporation SIGNED)(2013-09-25 17:38:26) Reg HKLM\SOFTWARE\Classes\CLSID\{41FCCC3A-1FA1-4949-953A-6EE61C46A4D1}\InprocServer32@ C:\Windows\System32\audioses.dll (Audio Session/Microsoft Corporation SIGNED)(2013-09-25 17:36:17) Reg HKLM\SOFTWARE\Classes\CLSID\{4224AC84-9B11-3561-8923-C893CA77ACBE}\InprocServer32@ C:\Windows\system32\mscoree.dll (Microsoft .NET Runtime Execution Engine/Microsoft Corporation SIGNED)(2013-09-25 17:38:26) Reg HKLM\SOFTWARE\Classes\CLSID\{427BC7E3-F833-4584-8745-CFAB9D7A5761}\InProcServer32@ C:\Windows\system32\shell32.dll (Windows Shell Common Dll/Microsoft Corporation SIGNED)(2013-09-26 18:21:44) Reg HKLM\SOFTWARE\Classes\CLSID\{4286FA72-A2FA-3245-8751-D4206070A191}\InprocServer32@ C:\Windows\system32\mscoree.dll (Microsoft .NET Runtime Execution Engine/Microsoft Corporation SIGNED)(2013-09-25 17:38:26) Reg HKLM\SOFTWARE\Classes\CLSID\{429AF92C-A51F-11d2-861E-00C04FA35C89}\InProcServer32@ C:\Windows\System32\mshtml.dll (Microsoft (R) HTML Viewer/Microsoft Corporation SIGNED)(2013-12-13 11:08:38) Reg HKLM\SOFTWARE\Classes\CLSID\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32@ C:\Windows\system32\shell32.dll (Windows Shell Common Dll/Microsoft Corporation SIGNED)(2013-09-26 18:21:44) Reg HKLM\SOFTWARE\Classes\CLSID\{432D76CE-8C9E-4EED-ADDD-91737F27A8CB}\InprocServer32@ C:\Windows\system32\mscoree.dll (Microsoft .NET Runtime Execution Engine/Microsoft Corporation SIGNED)(2013-09-25 17:38:26) Reg HKLM\SOFTWARE\Classes\CLSID\{4336a54d-038b-4685-ab02-99bb52d3fb8b}@LocalizedString C:\Windows\system32\shell32.dll (Windows Shell Common Dll/Microsoft Corporation SIGNED)(2013-09-26 18:21:44) Reg HKLM\SOFTWARE\Classes\CLSID\{433CA926-9887-3541-89CC-5D74D0259144}\InprocServer32@ C:\Windows\system32\mscoree.dll (Microsoft .NET Runtime Execution Engine/Microsoft Corporation SIGNED)(2013-09-25 17:38:26) Reg HKLM\SOFTWARE\Classes\CLSID\{4356b08e-ecb5-43d1-8e9f-7bef4fc960fe}\InProcServer32@ C:\Windows\System32\ieframe.dll (Internet Browser/Microsoft Corporation SIGNED)(2013-12-13 11:08:39) Reg HKLM\SOFTWARE\Classes\CLSID\{437ff9c0-a07f-4fa0-af80-84b6c6440a16}\InProcServer32@ C:\Windows\system32\shell32.dll (Windows Shell Common Dll/Microsoft Corporation SIGNED)(2013-09-26 18:21:44) Reg HKLM\SOFTWARE\Classes\CLSID\{43886CD5-6529-41c4-A707-7B3C92C05E68}\InProcServer32@ C:\Windows\System32\ieframe.dll (Internet Browser/Microsoft Corporation SIGNED)(2013-12-13 11:08:39) Reg HKLM\SOFTWARE\Classes\CLSID\{43CD41AD-3B78-3531-9031-3059E0AA64EB}\InprocServer32@ C:\Windows\system32\mscoree.dll (Microsoft .NET Runtime Execution Engine/Microsoft Corporation SIGNED)(2013-09-25 17:38:26) Reg HKLM\SOFTWARE\Classes\CLSID\{4444AC9E-242E-471B-A3C7-45DCD46352BC}\InprocServer32@ C:\Windows\system32\quartz.dll (DirectShow Runtime./Microsoft Corporation SIGNED)(2013-09-25 08:10:55) Reg HKLM\SOFTWARE\Classes\CLSID\{4479C009-4CC3-39A2-8F92-DFCDF034F748}\InprocServer32@ C:\Windows\system32\mscoree.dll (Microsoft .NET Runtime Execution Engine/Microsoft Corporation SIGNED)(2013-09-25 17:38:26) Reg HKLM\SOFTWARE\Classes\CLSID\{447EDBE5-0080-4036-A0BB-7B84C58C604F}\InProcServer32@ C:\Windows\System32\ieframe.dll (Internet Browser/Microsoft Corporation SIGNED)(2013-12-13 11:08:39) Reg HKLM\SOFTWARE\Classes\CLSID\{44CD0A52-D0B4-4D03-A572-A9BDAD6E2D33}\InprocHandler32@ C:\Windows\system32\ole32.dll (Microsoft OLE for Windows/Microsoft Corporation SIGNED)(2013-09-25 17:36:42) Reg HKLM\SOFTWARE\Classes\CLSID\{44f3dab6-4392-4186-bb7b-6282ccb7a9f6}\InProcServer32@ C:\Windows\system32\mydocs.dll (My Documents Folder UI/Microsoft Corporation SIGNED)(2013-09-25 17:37:51) Reg HKLM\SOFTWARE\Classes\CLSID\{450D8FBA-AD25-11D0-98A8-0800361B1103}@InfoTip C:\Windows\system32\shell32.dll (Windows Shell Common Dll/Microsoft Corporation SIGNED)(2013-09-26 18:21:44) Reg HKLM\SOFTWARE\Classes\CLSID\{450D8FBA-AD25-11D0-98A8-0800361B1103}\shell\cmd\command@ C:\Windows\system32\cmd.exe (Windows Command Processor/Microsoft Corporation SIGNED)(2013-09-25 17:36:17) Reg HKLM\SOFTWARE\Classes\CLSID\{450D8FBA-AD25-11D0-98A8-0800361B1103}\shell\find\command@ C:\Windows\Explorer.exe (Windows Explorer/Microsoft Corporation SIGNED)(2013-09-25 17:37:42) Reg HKLM\SOFTWARE\Classes\CLSID\{4522c772-9a2b-4920-ad7f-62d3d15eac52}\InProcServer32@ C:\Windows\system32\shell32.dll (Windows Shell Common Dll/Microsoft Corporation SIGNED)(2013-09-26 18:21:44) Reg HKLM\SOFTWARE\Classes\CLSID\{45597c98-80f6-4549-84ff-752cf55e2d29}\LocalServer32@ C:\Program Files\Windows Media Player\wmplayer.exe (Windows Media Player/Microsoft Corporation SIGNED)(2013-09-25 17:37:02) Reg HKLM\SOFTWARE\Classes\CLSID\{4582eba9-6aa1-4d79-824e-728929ef455d}\InProcServer32@ C:\Windows\system32\xwizards.dll (Extensible Wizards Manager Module/Microsoft Corporation SIGNED)(2009-07-13 23:51:41) Reg HKLM\SOFTWARE\Classes\CLSID\{458AA3B5-265A-4B75-BC05-9BEA4630CF18}\InprocServer32@ C:\Windows\system32\mscoree.dll (Microsoft .NET Runtime Execution Engine/Microsoft Corporation SIGNED)(2013-09-25 17:38:26) Reg HKLM\SOFTWARE\Classes\CLSID\{4657278A-411B-11d2-839A-00C04FD918D0}\InProcServer32@ C:\Windows\system32\shell32.dll (Windows Shell Common Dll/Microsoft Corporation SIGNED)(2013-09-26 18:21:44) Reg HKLM\SOFTWARE\Classes\CLSID\{46763EE0-CAB2-11CE-8C20-00AA0051E5D4}\InprocServer32@ C:\Windows\system32\oleaut32.dll (Microsoft Corporation SIGNED)(2013-09-25 08:15:54) Reg HKLM\SOFTWARE\Classes\CLSID\{469afbdf-084f-4dc9-904f-9e824c48bc37}\InProcServer32@ C:\Windows\system32\shell32.dll (Windows Shell Common Dll/Microsoft Corporation SIGNED)(2013-09-26 18:21:44) Reg HKLM\SOFTWARE\Classes\CLSID\{46CB32FA-B5CA-8A3A-62CA-A7023C0496C5}@LocalizedString C:\Windows\System32\ieframe.dll (Internet Browser/Microsoft Corporation SIGNED)(2013-12-13 11:08:39) Reg HKLM\SOFTWARE\Classes\CLSID\{46E97093-B2EC-3787-A9A5-470D1A27417C}\InprocServer32@ C:\Windows\system32\mscoree.dll (Microsoft .NET Runtime Execution Engine/Microsoft Corporation SIGNED)(2013-09-25 17:38:26) Reg HKLM\SOFTWARE\Classes\CLSID\{48025243-2D39-11CE-875D-00608CB78066}\InprocServer32@ C:\Windows\system32\quartz.dll (DirectShow Runtime./Microsoft Corporation SIGNED)(2013-09-25 08:10:55) Reg HKLM\SOFTWARE\Classes\CLSID\{48527bb3-e8de-450b-8910-8c4099cb8624}\InProcServer32@ C:\Windows\system32\shell32.dll (Windows Shell Common Dll/Microsoft Corporation SIGNED)(2013-09-26 18:21:44) Reg HKLM\SOFTWARE\Classes\CLSID\{48728B3F-F7D9-36C1-B3E7-8BF2E63CE1B3}\InprocServer32@ C:\Windows\system32\mscoree.dll (Microsoft .NET Runtime Execution Engine/Microsoft Corporation SIGNED)(2013-09-25 17:38:26) Reg HKLM\SOFTWARE\Classes\CLSID\{48e7caab-b918-4e58-a94d-505519c795dc}@LocalizedString C:\Windows\system32\shell32.dll (Windows Shell Common Dll/Microsoft Corporation SIGNED)(2013-09-26 18:21:44) Reg HKLM\SOFTWARE\Classes\CLSID\{48e7caab-b918-4e58-a94d-505519c795dc}\shell\find\command@ C:\Windows\Explorer.exe (Windows Explorer/Microsoft Corporation SIGNED)(2013-09-25 17:37:42) Reg HKLM\SOFTWARE\Classes\CLSID\{49eb6558-c09c-46dc-8668-1f848c290d0b}\InProcServer32@ C:\Windows\system32\shell32.dll (Windows Shell Common Dll/Microsoft Corporation SIGNED)(2013-09-26 18:21:44) Reg HKLM\SOFTWARE\Classes\CLSID\{49F371E1-8C5C-4d9c-9A3B-54A6827F513C}\InProcServer32@ C:\Windows\system32\ntshrui.dll (Shell extensions for sharing/Microsoft Corporation SIGNED)(2013-09-25 17:37:19) Reg HKLM\SOFTWARE\Classes\CLSID\{4a04656d-52aa-49de-8a09-cb178760e748}\InProcServer32@ C:\Windows\system32\shell32.dll (Windows Shell Common Dll/Microsoft Corporation SIGNED)(2013-09-26 18:21:44) Reg HKLM\SOFTWARE\Classes\CLSID\{4A2286E0-7BEF-11CE-9BD9-0000E202599C}\InprocServer32@ C:\Windows\system32\quartz.dll (DirectShow Runtime./Microsoft Corporation SIGNED)(2013-09-25 08:10:55) Reg HKLM\SOFTWARE\Classes\CLSID\{4a7ded0a-ad25-11d0-98a8-0800361b1103}\InProcServer32@ C:\Windows\system32\mydocs.dll (My Documents Folder UI/Microsoft Corporation SIGNED)(2013-09-25 17:37:51) Reg HKLM\SOFTWARE\Classes\CLSID\{4AF4A5FC-912A-11D1-B945-00A0C90312E1}\InProcServer32@ C:\Windows\system32\explorerframe.dll (ExplorerFrame/Microsoft Corporation SIGNED)(2013-09-25 17:38:17) Reg HKLM\SOFTWARE\Classes\CLSID\{4B0A2997-E555-4F84-B45B-68AB8BC57635}\InprocServer32@ C:\Windows\system32\rdpendp.dll (RDP Audio Endpoint/Microsoft Corporation SIGNED)(2013-09-25 17:37:31) Reg HKLM\SOFTWARE\Classes\CLSID\{4b360c3c-d284-4384-abcc-ef133e1445da}@LocalizedString C:\Windows\System32\ieframe.dll (Internet Browser/Microsoft Corporation SIGNED)(2013-12-13 11:08:39) Reg HKLM\SOFTWARE\Classes\CLSID\{4B601364-A04B-38BC-BD38-A18E981324CF}\InprocServer32@ C:\Windows\system32\mscoree.dll (Microsoft .NET Runtime Execution Engine/Microsoft Corporation SIGNED)(2013-09-25 17:38:26) Reg HKLM\SOFTWARE\Classes\CLSID\{4B78D326-D922-44f9-AF2A-07805C2A3560}\InProcServer32@ C:\Windows\System32\ieframe.dll (Internet Browser/Microsoft Corporation SIGNED)(2013-12-13 11:08:39) Reg HKLM\SOFTWARE\Classes\CLSID\{4BC67F23-D805-4384-BCA3-6F1EDFF50E2C}\InprocServer32@ C:\Windows\system32\wercplsupport.dll (Problem Reports and Solutions/Microsoft Corporation SIGNED)(2009-07-13 23:27:26) Reg HKLM\SOFTWARE\Classes\CLSID\{4BE89AC3-603D-36B2-AB9B-9C38866F56D5}\InprocServer32@ C:\Windows\system32\mscoree.dll (Microsoft .NET Runtime Execution Engine/Microsoft Corporation SIGNED)(2013-09-25 17:38:26) Reg HKLM\SOFTWARE\Classes\CLSID\{4bec2015-bfa1-42fa-9c0c-59431bbe880e}\InProcServer32@ C:\Windows\system32\shell32.dll (Windows Shell Common Dll/Microsoft Corporation SIGNED)(2013-09-26 18:21:44) Reg HKLM\SOFTWARE\Classes\CLSID\{4C3EBFD5-FC72-33DC-BC37-9953EB25B8D7}\InprocServer32@ C:\Windows\system32\mscoree.dll (Microsoft .NET Runtime Execution Engine/Microsoft Corporation SIGNED)(2013-09-25 17:38:26) Reg HKLM\SOFTWARE\Classes\CLSID\{4C4A5E40-732C-11D0-8816-00A0C903B83C}\InprocServer32@ C:\Windows\system32\certcli.dll (Microsoft� Active Directory Certificate Services Client/Microsoft Corporation SIGNED)(2013-09-25 17:38:23) Reg HKLM\SOFTWARE\Classes\CLSID\{4C69C54F-9824-38CC-8387-A22DC67E0BAB}\InprocServer32@ C:\Windows\system32\mscoree.dll (Microsoft .NET Runtime Execution Engine/Microsoft Corporation SIGNED)(2013-09-25 17:38:26) Reg HKLM\SOFTWARE\Classes\CLSID\{4D111E08-CBF7-4f12-A926-2C7920AF52FC}@LocalizedString C:\Windows\system32\shell32.dll (Windows Shell Common Dll/Microsoft Corporation SIGNED)(2013-09-26 18:21:44) Reg HKLM\SOFTWARE\Classes\CLSID\{4D111E08-CBF7-4f12-A926-2C7920AF52FC}\Elevation@IconReference C:\Windows\system32\imageres.dll (Windows Image Resource/Microsoft Corporation SIGNED)(2009-07-13 23:42:24) Reg HKLM\SOFTWARE\Classes\CLSID\{4D111E08-CBF7-4f12-A926-2C7920AF52FC}\InProcServer32@ C:\Windows\System32\shell32.dll (Windows Shell Common Dll/Microsoft Corporation SIGNED)(2013-09-26 18:21:44) Reg HKLM\SOFTWARE\Classes\CLSID\{4D187AC2-D815-3B7E-BCEA-8E0BBC702F7C}\InprocServer32@ C:\Windows\system32\mscoree.dll (Microsoft .NET Runtime Execution Engine/Microsoft Corporation SIGNED)(2013-09-25 17:38:26) Reg HKLM\SOFTWARE\Classes\CLSID\{4D5C8C2A-D075-11d0-B416-00C04FB90376}\InProcServer32@ C:\Windows\System32\ieframe.dll (Internet Browser/Microsoft Corporation SIGNED)(2013-12-13 11:08:39) Reg HKLM\SOFTWARE\Classes\CLSID\{4df0c730-df9d-4ae3-9153-aa6b82e9795a}\InProcServer32@ C:\Windows\system32\shell32.dll (Windows Shell Common Dll/Microsoft Corporation SIGNED)(2013-09-26 18:21:44) Reg HKLM\SOFTWARE\Classes\CLSID\{4DFED3F9-B794-4d3c-973B-DDA1C28105A9}\InProcServer32@ C:\Windows\System32\ieframe.dll (Internet Browser/Microsoft Corporation SIGNED)(2013-12-13 11:08:39) Reg HKLM\SOFTWARE\Classes\CLSID\{4E14FBA2-2E22-11D1-9964-00C04FBBB345}\InprocServer32@ C:\Windows\system32\es.dll (COM+/Microsoft Corporation SIGNED)(2009-07-13 23:44:38) Reg HKLM\SOFTWARE\Classes\CLSID\{4E515531-7A71-3CDD-8078-0A01C85C8F9D}\InprocServer32@ C:\Windows\system32\mscoree.dll (Microsoft .NET Runtime Execution Engine/Microsoft Corporation SIGNED)(2013-09-25 17:38:26) Reg HKLM\SOFTWARE\Classes\CLSID\{4ea9a1b7-e521-4813-a9f8-ba6484902cb5}\InProcServer32@ C:\Windows\System32\Smbhelperclass.dll (SMB (File Sharing) Helper Class for Network Diagnostic Framework/Microsoft SIGNED)(2009-07-13 23:14:48) Reg HKLM\SOFTWARE\Classes\CLSID\{4eb2f086-c818-447e-b32c-c51ce2b30d31}\InprocServer32@ C:\Windows\system32\mstscax.dll (Remote Desktop Services ActiveX Client/Microsoft Corporation SIGNED)(2013-09-25 08:15:19) Reg HKLM\SOFTWARE\Classes\CLSID\{4F272C37-F0A8-350C-867B-2C03B2B16B80}\InprocServer32@ C:\Windows\system32\mscoree.dll (Microsoft .NET Runtime Execution Engine/Microsoft Corporation SIGNED)(2013-09-25 17:38:26) Reg HKLM\SOFTWARE\Classes\CLSID\{4FAF64F1-A3BA-4172-B922-E6A22ACF7E3D}\InProcServer32@ C:\Windows\system32\xwizards.dll (Extensible Wizards Manager Module/Microsoft Corporation SIGNED)(2009-07-13 23:51:41) Reg HKLM\SOFTWARE\Classes\CLSID\{4FDBC3E5-7121-4487-AB95-B58EC04648DB}\InprocServer32@ C:\Windows\system32\ucmhc.dll (UCM Helper Class/Microsoft Corporation SIGNED)(2009-07-13 23:52:44) Reg HKLM\SOFTWARE\Classes\CLSID\{50055B2F-D4FF-42E1-9D8F-5D48F327F3AC}\InprocServer32@ C:\Windows\system32\wercplsupport.dll (Problem Reports and Solutions/Microsoft Corporation SIGNED)(2009-07-13 23:27:26) Reg HKLM\SOFTWARE\Classes\CLSID\{50369004-DB9A-3A75-BE7A-1D0EF017B9D3}\InprocServer32@ C:\Windows\system32\mscoree.dll (Microsoft .NET Runtime Execution Engine/Microsoft Corporation SIGNED)(2013-09-25 17:38:26) Reg HKLM\SOFTWARE\Classes\CLSID\{50cc2c18-b48c-4764-8f3f-0331ed295ce4}\InProcServer32@ C:\Windows\system32\shell32.dll (Windows Shell Common Dll/Microsoft Corporation SIGNED)(2013-09-26 18:21:44) Reg HKLM\SOFTWARE\Classes\CLSID\{517F6AA6-D6FA-46D0-8094-17FF17E4CCF4}\InProcServer32@ C:\Windows\System32\listsvc.dll (Windows HomeGroup/Microsoft Corporation SIGNED)(2013-09-25 17:37:57) Reg HKLM\SOFTWARE\Classes\CLSID\{51B4ABF3-748F-4E3B-A276-C828330E926A}\InprocServer32@ C:\Windows\system32\quartz.dll (DirectShow Runtime./Microsoft Corporation SIGNED)(2013-09-25 08:10:55) Reg HKLM\SOFTWARE\Classes\CLSID\{5255EFED-103A-4444-B124-F88F99E4EF8D}\InProcServer32@ C:\Windows\System32\listsvc.dll (Windows HomeGroup/Microsoft Corporation SIGNED)(2013-09-25 17:37:57) Reg HKLM\SOFTWARE\Classes\CLSID\{527c9a9b-b9a2-44b0-84f9-f0dc11c2bcfb}\InProcServer32@ C:\Windows\system32\shell32.dll (Windows Shell Common Dll/Microsoft Corporation SIGNED)(2013-09-26 18:21:44) Reg HKLM\SOFTWARE\Classes\CLSID\{528d46b3-3a4b-4b13-bf74-d9cbd7306e07}\InProcServer32@ C:\Windows\System32\ieframe.dll (Internet Browser/Microsoft Corporation SIGNED)(2013-12-13 11:08:39) Reg HKLM\SOFTWARE\Classes\CLSID\{529A9E6B-6587-4F23-AB9E-9C7D683E3C50}\InProcServer32@ C:\Windows\System32\msctf.dll (MSCTF Server DLL/Microsoft Corporation SIGNED)(2009-07-13 23:28:05) Reg HKLM\SOFTWARE\Classes\CLSID\{52ABBE5B-A470-11D6-9500-00065B874123}\InProcServer32@ C:\Program Files\Common Files\Microsoft Shared\OFFICE11\MSSOAP30.DLL (Microsoft Office Soap SDK/Microsoft Corporation)(2002-12-06 12:25:10) Reg HKLM\SOFTWARE\Classes\CLSID\{52ce2fe5-04c3-42fd-8a8b-4251affb8408}\InProcServer32@ C:\Windows\system32\shell32.dll (Windows Shell Common Dll/Microsoft Corporation SIGNED)(2013-09-26 18:21:44) Reg HKLM\SOFTWARE\Classes\CLSID\{5326dddc-ec38-428d-b219-ce6dadb35de3}\InProcServer32@ C:\Windows\system32\van.dll (View Available Networks/Microsoft Corporation SIGNED)(2013-09-25 17:38:08) Reg HKLM\SOFTWARE\Classes\CLSID\{53510d24-57eb-4713-9afb-e6e60530b87e}\InProcServer32@ C:\Windows\System32\ieframe.dll (Internet Browser/Microsoft Corporation SIGNED)(2013-12-13 11:08:39) Reg HKLM\SOFTWARE\Classes\CLSID\{5399E694-6CE5-4D6C-8FCE-1D8870FDCBA0}@LocalizedString C:\Windows\system32\shell32.dll (Windows Shell Common Dll/Microsoft Corporation SIGNED)(2013-09-26 18:21:44) Reg HKLM\SOFTWARE\Classes\CLSID\{53A3C917-BB24-3908-B58B-09ECDA99265F}\InprocServer32@ C:\Windows\system32\mscoree.dll (Microsoft .NET Runtime Execution Engine/Microsoft Corporation SIGNED)(2013-09-25 17:38:26) Reg HKLM\SOFTWARE\Classes\CLSID\{53bd6b4e-3780-4693-afc3-7161c2f3ee9c}\InProcServer32@ C:\Windows\system32\shell32.dll (Windows Shell Common Dll/Microsoft Corporation SIGNED)(2013-09-26 18:21:44) Reg HKLM\SOFTWARE\Classes\CLSID\{5437FDFA-9EC9-4CCC-8531-42F8D9C19AF7}\InprocServer32@ C:\Windows\system32\mscoree.dll (Microsoft .NET Runtime Execution Engine/Microsoft Corporation SIGNED)(2013-09-25 17:38:26) Reg HKLM\SOFTWARE\Classes\CLSID\{54CE37E0-9834-41ae-9896-4DAB69DC022B}\InprocServer32@ C:\Windows\system32\mstscax.dll (Remote Desktop Services ActiveX Client/Microsoft Corporation SIGNED)(2013-09-25 08:15:19) Reg HKLM\SOFTWARE\Classes\CLSID\{54D8502C-527D-43F7-A506-A9DA075E229C}\InprocServer32@ C:\Windows\System32\mscoree.dll (Microsoft .NET Runtime Execution Engine/Microsoft Corporation SIGNED)(2013-09-25 17:38:26) Reg HKLM\SOFTWARE\Classes\CLSID\{55136805-B2DE-11D1-B9F2-00A0C98BC547}\InProcServer32@ C:\Windows\System32\ieframe.dll (Internet Browser/Microsoft Corporation SIGNED)(2013-12-13 11:08:39) Reg HKLM\SOFTWARE\Classes\CLSID\{5520B6D3-6EC6-3CE7-958B-E69FAF6EFF99}\InprocServer32@ C:\Windows\system32\mscoree.dll (Microsoft .NET Runtime Execution Engine/Microsoft Corporation SIGNED)(2013-09-25 17:38:26) Reg HKLM\SOFTWARE\Classes\CLSID\{553858A7-4922-4e7e-B1C1-97140C1C16EF}\InProcServer32@ C:\Windows\System32\ieframe.dll (Internet Browser/Microsoft Corporation SIGNED)(2013-12-13 11:08:39) Reg HKLM\SOFTWARE\Classes\CLSID\{55B3A0BD-4D28-42fe-8CFB-FA3EDFF969B8}\InProcServer32@ C:\Windows\system32\sysmain.dll (Superfetch Service Host/Microsoft Corporation SIGNED)(2013-09-25 17:37:38) Reg HKLM\SOFTWARE\Classes\CLSID\{55d7b852-f6d1-42f2-aa75-8728a1b2d264}\InProcServer32@ C:\Windows\system32\shell32.dll (Windows Shell Common Dll/Microsoft Corporation SIGNED)(2013-09-26 18:21:44) Reg HKLM\SOFTWARE\Classes\CLSID\{5610F042-FF1D-36D0-996C-68F7A207D1F0}\InprocServer32@ C:\Windows\system32\mscoree.dll (Microsoft .NET Runtime Execution Engine/Microsoft Corporation SIGNED)(2013-09-25 17:38:26) Reg HKLM\SOFTWARE\Classes\CLSID\{56ad4c5d-b908-4f85-8ff1-7940c29b3bcf}\InProcServer32@ C:\Windows\system32\shell32.dll (Windows Shell Common Dll/Microsoft Corporation SIGNED)(2013-09-26 18:21:44) Reg HKLM\SOFTWARE\Classes\CLSID\{56FDF344-FD6D-11d0-958A-006097C9A090}\InProcServer32@ C:\Windows\system32\explorerframe.dll (ExplorerFrame/Microsoft Corporation SIGNED)(2013-09-25 17:38:17) Reg HKLM\SOFTWARE\Classes\CLSID\{57154C7C-EDB2-3BFD-A8BA-924C60913EBF}\InprocServer32@ C:\Windows\system32\mscoree.dll (Microsoft .NET Runtime Execution Engine/Microsoft Corporation SIGNED)(2013-09-25 17:38:26) Reg HKLM\SOFTWARE\Classes\CLSID\{57635537-C856-4cc2-AE5C-62C34708070C}\InProcServer32@ C:\Windows\system32\shell32.dll (Windows Shell Common Dll/Microsoft Corporation SIGNED)(2013-09-26 18:21:44) Reg HKLM\SOFTWARE\Classes\CLSID\{57C06EAA-8784-11D0-83D4-00A0C911E5DF}\InProcServer32@ C:\Windows\system32\netcfgx.dll (Network Configuration Objects/Microsoft Corporation SIGNED)(2013-09-25 17:38:28) Reg HKLM\SOFTWARE\Classes\CLSID\{57CD819D-B0FA-3F75-B347-7C83186EDA5B}\InprocServer32@ C:\Windows\system32\mscoree.dll (Microsoft .NET Runtime Execution Engine/Microsoft Corporation SIGNED)(2013-09-25 17:38:26) Reg HKLM\SOFTWARE\Classes\CLSID\{57f8510b-a5e2-41da-a8f0-8a5ae85dfffd}\InProcServer32@ C:\Windows\System32\explorerframe.dll (ExplorerFrame/Microsoft Corporation SIGNED)(2013-09-25 17:38:17) Reg HKLM\SOFTWARE\Classes\CLSID\{5848A73D-E9C2-499E-BB92-887CABCB2BD6}\InprocHandler32@ C:\Windows\system32\ole32.dll (Microsoft OLE for Windows/Microsoft Corporation SIGNED)(2013-09-25 17:36:42) Reg HKLM\SOFTWARE\Classes\CLSID\{58859c43-2c82-454b-86c0-9efb11e54838}\InProcServer32@ C:\Windows\system32\shell32.dll (Windows Shell Common Dll/Microsoft Corporation SIGNED)(2013-09-26 18:21:44) Reg HKLM\SOFTWARE\Classes\CLSID\{58897D76-EF6C-327A-93F7-6CD66C424E11}\InprocServer32@ C:\Windows\system32\mscoree.dll (Microsoft .NET Runtime Execution Engine/Microsoft Corporation SIGNED)(2013-09-25 17:38:26) Reg HKLM\SOFTWARE\Classes\CLSID\{58AB2366-D597-11d1-B90E-00C04FC9B263}\InprocServer32@ C:\Windows\system32\rastls.dll (Remote Access PPP EAP-TLS/Microsoft Corporation SIGNED)(2013-09-25 17:37:31) Reg HKLM\SOFTWARE\Classes\CLSID\{58D052BC-A3DF-3508-AC95-FF297BDC9F0C}\InprocServer32@ C:\Windows\system32\mscoree.dll (Microsoft .NET Runtime Execution Engine/Microsoft Corporation SIGNED)(2013-09-25 17:38:26) Reg HKLM\SOFTWARE\Classes\CLSID\{58fb76b9-ac85-4e55-ac04-427593b1d060}\InprocServer32@ C:\Windows\system32\dimsjob.dll (DIMS Job DLL/Microsoft Corporation SIGNED)(2009-07-13 23:37:26) Reg HKLM\SOFTWARE\Classes\CLSID\{59031a47-3f72-44a7-89c5-5595fe6b30ee}\InProcServer32@ C:\Windows\system32\shell32.dll (Windows Shell Common Dll/Microsoft Corporation SIGNED)(2013-09-26 18:21:44) Reg HKLM\SOFTWARE\Classes\CLSID\{590E4A07-DAFC-3BE7-A178-DA349BBA980B}\InprocServer32@ C:\Windows\system32\mscoree.dll (Microsoft .NET Runtime Execution Engine/Microsoft Corporation SIGNED)(2013-09-25 17:38:26) Reg HKLM\SOFTWARE\Classes\CLSID\{591209c7-767b-42b2-9fba-44ee4615f2c7}\InProcServer32@ C:\Windows\System32\shell32.dll (Windows Shell Common Dll/Microsoft Corporation SIGNED)(2013-09-26 18:21:44) Reg HKLM\SOFTWARE\Classes\CLSID\{59347292-B72D-41F2-98C5-E9ACA1B247A2}\Elevation@IconReference C:\Windows\system32\WfsR.dll (Windows Fax and Scan Resources/Microsoft Corporation SIGNED)(2009-07-14 00:15:09) Reg HKLM\SOFTWARE\Classes\CLSID\{596742A5-1393-4e13-8765-AE1DF71ACAFB}\InProcServer32@ C:\Windows\system32\explorerframe.dll (ExplorerFrame/Microsoft Corporation SIGNED)(2013-09-25 17:38:17) Reg HKLM\SOFTWARE\Classes\CLSID\{599141D2-B243-11DB-8460-00123F76E1F7}\InprocServer32@ C:\Windows\System32\mscoree.dll (Microsoft .NET Runtime Execution Engine/Microsoft Corporation SIGNED)(2013-09-25 17:38:26) Reg HKLM\SOFTWARE\Classes\CLSID\{59A437AB-74F3-4de2-AFE6-54203634C4DD}\InProcServer32@ C:\Windows\system32\ntshrui.dll (Shell extensions for sharing/Microsoft Corporation SIGNED)(2013-09-25 17:37:19) Reg HKLM\SOFTWARE\Classes\CLSID\{59CDB915-8232-46AD-B38B-497B8B0463AD}\InProcServer32@ C:\Windows\system32\tsworkspace.dll (RemoteApp and Desktop Connection Component/Microsoft Corporation SIGNED)(2013-09-25 17:37:06) Reg HKLM\SOFTWARE\Classes\CLSID\{59CE6880-ACF8-11CF-B56E-0080C7C4B68A}\InprocServer32@ C:\Windows\system32\quartz.dll (DirectShow Runtime./Microsoft Corporation SIGNED)(2013-09-25 08:10:55) Reg HKLM\SOFTWARE\Classes\CLSID\{5A18D43E-115B-3B8B-8245-9A06B204B717}\InprocServer32@ C:\Windows\system32\mscoree.dll (Microsoft .NET Runtime Execution Engine/Microsoft Corporation SIGNED)(2013-09-25 17:38:26) Reg HKLM\SOFTWARE\Classes\CLSID\{5B035261-40F9-11D1-AAEC-00805FC1270E}\InProcServer32@ C:\Windows\system32\netcfgx.dll (Network Configuration Objects/Microsoft Corporation SIGNED)(2013-09-25 17:38:28) Reg HKLM\SOFTWARE\Classes\CLSID\{5B18AB61-091D-11D1-97DF-00C04FB9618A}\InprocServer32@ C:\Windows\system32\msdtcprx.dll (Microsoft Distributed Transaction Coordinator OLE Transactions Interface Proxy DLL/Microsoft Corporation SIGNED)(2009-07-13 23:44:23) Reg HKLM\SOFTWARE\Classes\CLSID\{5b4dae26-b807-11d0-9815-00c04fd91972}\InProcServer32@ C:\Windows\system32\shell32.dll (Windows Shell Common Dll/Microsoft Corporation SIGNED)(2013-09-26 18:21:44) Reg HKLM\SOFTWARE\Classes\CLSID\{5B76534C-3ACC-3D52-AA61-D788B134ABE2}\InprocServer32@ C:\Windows\system32\mscoree.dll (Microsoft .NET Runtime Execution Engine/Microsoft Corporation SIGNED)(2013-09-25 17:38:26) Reg HKLM\SOFTWARE\Classes\CLSID\{5b858418-cfb4-4b32-8501-54d8b0c59f90}\InProcServer32@ C:\Windows\system32\shell32.dll (Windows Shell Common Dll/Microsoft Corporation SIGNED)(2013-09-26 18:21:44) Reg HKLM\SOFTWARE\Classes\CLSID\{5bbd58bb-993e-4c17-8af6-3af8e908fca8}@LocalizedString C:\Windows\System32\ieframe.dll (Internet Browser/Microsoft Corporation SIGNED)(2013-12-13 11:08:39) Reg HKLM\SOFTWARE\Classes\CLSID\{5BFD515E-4ABA-4483-A1C5-6651B7110AB6}\InprocServer32@ C:\Windows\System32\audioses.dll (Audio Session/Microsoft Corporation SIGNED)(2013-09-25 17:36:17) Reg HKLM\SOFTWARE\Classes\CLSID\{5C35F099-165E-3225-A3A5-564150EA17F5}\InprocServer32@ C:\Windows\system32\mscoree.dll (Microsoft .NET Runtime Execution Engine/Microsoft Corporation SIGNED)(2013-09-25 17:38:26) Reg HKLM\SOFTWARE\Classes\CLSID\{5d4d54b3-9fb4-4662-8173-c48568d5e79e}\InProcServer32@ C:\Windows\system32\shell32.dll (Windows Shell Common Dll/Microsoft Corporation SIGNED)(2013-09-26 18:21:44) Reg HKLM\SOFTWARE\Classes\CLSID\{5D9DD151-65F4-11CE-900D-00AA00445589}\InprocServer32@ C:\Windows\system32\msdtcprx.dll (Microsoft Distributed Transaction Coordinator OLE Transactions Interface Proxy DLL/Microsoft Corporation SIGNED)(2009-07-13 23:44:23) Reg HKLM\SOFTWARE\Classes\CLSID\{5E032150-8C1E-4c9e-BC60-36E9BFFCFF56}\InProcServer32@ C:\Windows\System32\provsvc.dll (Windows HomeGroup/Microsoft Corporation SIGNED)(2013-09-25 17:37:30) Reg HKLM\SOFTWARE\Classes\CLSID\{5E33D52F-2EE2-48EE-80FC-543DFF43E326}\InprocServer32@ C:\Windows\system32\igdDiag.dll (IGD Helper Class/Microsoft Corporation SIGNED)(2009-07-13 23:52:47) Reg HKLM\SOFTWARE\Classes\CLSID\{5E6AB780-7743-11CF-A12B-00AA004AE837}\InProcServer32@ C:\Windows\system32\explorerframe.dll (ExplorerFrame/Microsoft Corporation SIGNED)(2013-09-25 17:38:17) Reg HKLM\SOFTWARE\Classes\CLSID\{5ef4af3a-f726-11d0-b8a2-00c04fc309a4}\InProcServer32@ C:\Windows\system32\shell32.dll (Windows Shell Common Dll/Microsoft Corporation SIGNED)(2013-09-26 18:21:44) Reg HKLM\SOFTWARE\Classes\CLSID\{5F3A0F8D-5EF9-3AD5-94E0-53AFF8BCE960}\InprocServer32@ C:\Windows\system32\mscoree.dll (Microsoft .NET Runtime Execution Engine/Microsoft Corporation SIGNED)(2013-09-25 17:38:26) Reg HKLM\SOFTWARE\Classes\CLSID\{5f4baad0-4d59-4fcd-b213-783ce7a92f22}\LocalServer32@ C:\Windows\System32\wiaacmgr.exe (Windows Picture Acquisition Wizard/Microsoft Corporation SIGNED)(2009-07-14 00:15:13) Reg HKLM\SOFTWARE\Classes\CLSID\{5F5295E0-429F-1069-A2E2-08002B30309D}\InProcServer32@ C:\Windows\system32\shell32.dll (Windows Shell Common Dll/Microsoft Corporation SIGNED)(2013-09-26 18:21:44) Reg HKLM\SOFTWARE\Classes\CLSID\{5F9A955F-AA55-4127-A32B-33496AA8A44E}\InprocServer32@ C:\Windows\system32\mscoree.dll (Microsoft .NET Runtime Execution Engine/Microsoft Corporation SIGNED)(2013-09-25 17:38:26) Reg HKLM\SOFTWARE\Classes\CLSID\{6004c347-d3f3-472a-8f9e-319b5c583d55}\InProcServer32@ C:\Windows\system32\shell32.dll (Windows Shell Common Dll/Microsoft Corporation SIGNED)(2013-09-26 18:21:44) Reg HKLM\SOFTWARE\Classes\CLSID\{60254CA5-953B-11CF-8C96-00AA00B8708C}\InProcServer32@ C:\Windows\system32\wshext.dll (Microsoft � Shell Extension for Windows Script Host/Microsoft Corporation SIGNED)(2009-07-13 23:42:38) Reg HKLM\SOFTWARE\Classes\CLSID\{6038EF75-ABFC-4e59-AB6F-12D397F6568D}\InProcServer32@ C:\Windows\System32\ieframe.dll (Internet Browser/Microsoft Corporation SIGNED)(2013-12-13 11:08:39) Reg HKLM\SOFTWARE\Classes\CLSID\{603D3800-BD81-11d0-A3A5-00C04FD706EC}\InProcServer32@ C:\Windows\system32\shell32.dll (Windows Shell Common Dll/Microsoft Corporation SIGNED)(2013-09-26 18:21:44) Reg HKLM\SOFTWARE\Classes\CLSID\{607fd4e8-0a03-11d1-ab1d-00c04fc9b304}\InProcServer32@ C:\Windows\System32\mshtml.dll (Microsoft (R) HTML Viewer/Microsoft Corporation SIGNED)(2013-12-13 11:08:38) Reg HKLM\SOFTWARE\Classes\CLSID\{60F6E464-4DEF-11d2-B2D9-00C04F8EEC8C}\InProcServer32@ C:\Windows\System32\DATACLEN.DLL (Disk Space Cleaner for Windows/Microsoft Corporation SIGNED)(2009-07-13 23:40:20) Reg HKLM\SOFTWARE\Classes\CLSID\{61B3E12B-3586-3A58-A497-7ED7C4C794B9}\InprocServer32@ C:\Windows\system32\mscoree.dll (Microsoft .NET Runtime Execution Engine/Microsoft Corporation SIGNED)(2013-09-25 17:38:26) Reg HKLM\SOFTWARE\Classes\CLSID\{62079164-233b-41f8-a80f-f01705f514a8}\InprocServer32@ C:\Windows\System32\evr.dll (Enhanced Video Renderer DLL/Microsoft Corporation SIGNED)(2013-09-25 17:38:17) Reg HKLM\SOFTWARE\Classes\CLSID\{62112AA1-EBE4-11cf-A5FB-0020AFE7292D}\InProcServer32@ C:\Windows\system32\shell32.dll (Windows Shell Common Dll/Microsoft Corporation SIGNED)(2013-09-26 18:21:44) Reg HKLM\SOFTWARE\Classes\CLSID\{622a8646-1096-4765-8e07-91a3e661cef9}\InProcServer32@ C:\Windows\system32\xwizards.dll (Extensible Wizards Manager Module/Microsoft Corporation SIGNED)(2009-07-13 23:51:41) Reg HKLM\SOFTWARE\Classes\CLSID\{62545937-20A9-3D0F-B04B-322E854EACB0}\InprocServer32@ C:\Windows\system32\mscoree.dll (Microsoft .NET Runtime Execution Engine/Microsoft Corporation SIGNED)(2013-09-25 17:38:26) Reg HKLM\SOFTWARE\Classes\CLSID\{6311429E-2F1A-4777-880F-C7289FD10169}\InProcServer32@ C:\Windows\system32\ntshrui.dll (Shell extensions for sharing/Microsoft Corporation SIGNED)(2013-09-25 17:37:19) Reg HKLM\SOFTWARE\Classes\CLSID\{632B606B-BBC6-11D2-A329-006097C4E476}\LocalServer32@ C:\Program Files\Windows Media Components\Encoder\wmenc.exe (Windows Media Encoder/Microsoft Corporation)(2002-12-11 19:38:52) Reg HKLM\SOFTWARE\Classes\CLSID\{63B51F81-C868-11D0-999C-00C04FD655E1}\InProcServer32@ C:\Windows\system32\shell32.dll (Windows Shell Common Dll/Microsoft Corporation SIGNED)(2013-09-26 18:21:44) Reg HKLM\SOFTWARE\Classes\CLSID\{647053C3-1879-34D7-AE57-67015C91FC70}\InprocServer32@ C:\Windows\system32\mscoree.dll (Microsoft .NET Runtime Execution Engine/Microsoft Corporation SIGNED)(2013-09-25 17:38:26) Reg HKLM\SOFTWARE\Classes\CLSID\{64AB4BB7-111E-11d1-8F79-00C04FC2FBE1}\InProcServer32@ C:\Windows\System32\ieframe.dll (Internet Browser/Microsoft Corporation SIGNED)(2013-12-13 11:08:39) Reg HKLM\SOFTWARE\Classes\CLSID\{64B8F404-A4AE-11D1-B7B6-00C04FB926AF}\InProcServer32@ C:\Windows\system32\es.dll (COM+/Microsoft Corporation SIGNED)(2009-07-13 23:44:38) Reg HKLM\SOFTWARE\Classes\CLSID\{64BC32B5-4EEC-4de7-972D-BD8BD0324537}\InProcServer32@ C:\Windows\system32\explorerframe.dll (ExplorerFrame/Microsoft Corporation SIGNED)(2013-09-25 17:38:17) Reg HKLM\SOFTWARE\Classes\CLSID\{6522CF99-94C7-4958-B18D-4F6159E6926B}\InProcServer32@ C:\Windows\system32\shell32.dll (Windows Shell Common Dll/Microsoft Corporation SIGNED)(2013-09-26 18:21:44) Reg HKLM\SOFTWARE\Classes\CLSID\{6619A740-8154-43BE-A186-0319578E02DB}\InprocServer32@ C:\Windows\system32\mscoree.dll (Microsoft .NET Runtime Execution Engine/Microsoft Corporation SIGNED)(2013-09-25 17:38:26) Reg HKLM\SOFTWARE\Classes\CLSID\{66275315-bfa5-451b-88b6-e56ebc8d9b58}\InProcServer32@ C:\Windows\system32\shell32.dll (Windows Shell Common Dll/Microsoft Corporation SIGNED)(2013-09-26 18:21:44) Reg HKLM\SOFTWARE\Classes\CLSID\{66CE75D4-0334-3CA6-BCA8-CE9AF28A4396}\InprocServer32@ C:\Windows\system32\mscoree.dll (Microsoft .NET Runtime Execution Engine/Microsoft Corporation SIGNED)(2013-09-25 17:38:26) Reg HKLM\SOFTWARE\Classes\CLSID\{66d56b60-97b7-4e6a-9aa1-3ec5e3fdaa0f}\InProcServer32@ C:\Windows\system32\WinsockHC.dll (Winsock Network Diagnostic Helper Class/Microsoft Corporation SIGNED)(2009-07-13 23:55:04) Reg HKLM\SOFTWARE\Classes\CLSID\{66e4e4fb-f385-4dd0-8d74-a2efd1bc6178}\InProcServer32@ C:\Windows\system32\shell32.dll (Windows Shell Common Dll/Microsoft Corporation SIGNED)(2013-09-26 18:21:44) Reg HKLM\SOFTWARE\Classes\CLSID\{6705C562-0AE7-40EA-8474-F39DAB1813D0}\InProcServer32@ C:\Windows\system32\RasMM.dll (RAS Media Manager/Microsoft Corporation SIGNED)(2009-07-13 23:55:45) Reg HKLM\SOFTWARE\Classes\CLSID\{673DFE75-9F93-304F-ABA8-D2A86BA87D7C}\InprocServer32@ C:\Windows\system32\mscoree.dll (Microsoft .NET Runtime Execution Engine/Microsoft Corporation SIGNED)(2013-09-25 17:38:26) Reg HKLM\SOFTWARE\Classes\CLSID\{6756A641-DE71-11d0-831B-00AA005B4383}\InProcServer32@ C:\Windows\system32\shell32.dll (Windows Shell Common Dll/Microsoft Corporation SIGNED)(2013-09-26 18:21:44) Reg HKLM\SOFTWARE\Classes\CLSID\{676E1164-752C-3A74-8D3F-BCD32A2026D6}\InprocServer32@ C:\Windows\system32\mscoree.dll (Microsoft .NET Runtime Execution Engine/Microsoft Corporation SIGNED)(2013-09-25 17:38:26) Reg HKLM\SOFTWARE\Classes\CLSID\{677126ed-2a91-40ff-8c52-06181c064573}\InprocServer32@ C:\Windows\system32\qagent.dll (Quarantine Agent Proxy/Microsoft Corporation SIGNED)(2013-09-25 17:38:03) Reg HKLM\SOFTWARE\Classes\CLSID\{6785BFAC-9D2D-4be5-B7E2-59937E8FB80A}@LocalizedString C:\Windows\system32\shell32.dll (Windows Shell Common Dll/Microsoft Corporation SIGNED)(2013-09-26 18:21:44) Reg HKLM\SOFTWARE\Classes\CLSID\{682159d9-c321-47ca-b3f1-30e36b2ec8b9}\LocalServer32@ C:\Windows\explorer.exe (Windows Explorer/Microsoft Corporation SIGNED)(2013-09-25 17:37:42) Reg HKLM\SOFTWARE\Classes\CLSID\{682D63B8-1692-31BE-88CD-5CB1F79EDB7B}\InprocServer32@ C:\Windows\system32\mscoree.dll (Microsoft .NET Runtime Execution Engine/Microsoft Corporation SIGNED)(2013-09-25 17:38:26) Reg HKLM\SOFTWARE\Classes\CLSID\{68b07bff-cb50-4d60-a7d5-02b1a523bc8c}\Instance\InitPropertyBag@DefaultIcon C:\Windows\System32\imageres.dll (Windows Image Resource/Microsoft Corporation SIGNED)(2009-07-13 23:42:24) Reg HKLM\SOFTWARE\Classes\CLSID\{68ddbb56-9d1d-4fd9-89c5-c0da2a625392}\InProcServer32@ C:\Windows\system32\stobject.dll (Systray shell service object/Microsoft Corporation SIGNED)(2013-09-25 17:36:32) Reg HKLM\SOFTWARE\Classes\CLSID\{68e52c1c-37cb-41d2-afe1-1e77d5f10676}\InProcServer32@ C:\Windows\system32\shell32.dll (Windows Shell Common Dll/Microsoft Corporation SIGNED)(2013-09-26 18:21:44) Reg HKLM\SOFTWARE\Classes\CLSID\{68F8AEA9-1968-35B9-8A0E-6FDC637A4F8E}\InprocServer32@ C:\Windows\system32\mscoree.dll (Microsoft .NET Runtime Execution Engine/Microsoft Corporation SIGNED)(2013-09-25 17:38:26) Reg HKLM\SOFTWARE\Classes\CLSID\{6935DB93-21E8-4ccc-BEB9-9FE3C77A297A}\InProcServer32@ C:\Windows\system32\shell32.dll (Windows Shell Common Dll/Microsoft Corporation SIGNED)(2013-09-26 18:21:44) Reg HKLM\SOFTWARE\Classes\CLSID\{69B37063-2BB6-43b5-A109-60E69A77840F}\InprocServer32@ C:\Windows\System32\WcsPlugInService.dll (WcsPlugInService DLL/Microsoft Corporation SIGNED)(2009-07-13 23:25:13) Reg HKLM\SOFTWARE\Classes\CLSID\{6A02951C-B129-4D26-AB92-B9CA19BDCA26}\InprocServer32@ C:\Windows\system32\mscoree.dll (Microsoft .NET Runtime Execution Engine/Microsoft Corporation SIGNED)(2013-09-25 17:38:26) Reg HKLM\SOFTWARE\Classes\CLSID\{6A08CF80-0E18-11CF-A24D-0020AFD79767}\InprocServer32@ C:\Windows\system32\quartz.dll (DirectShow Runtime./Microsoft Corporation SIGNED)(2013-09-25 08:10:55) Reg HKLM\SOFTWARE\Classes\CLSID\{6A205B57-2567-4a2c-B881-F787FAB579A3}\InProcServer32@ C:\Windows\system32\shell32.dll (Windows Shell Common Dll/Microsoft Corporation SIGNED)(2013-09-26 18:21:44) Reg HKLM\SOFTWARE\Classes\CLSID\{6A68CC80-4337-4dbc-BD27-FBFB1053820B}\InProcServer32@ C:\Windows\system32\tquery.dll (tquery.dll/Microsoft Corporation SIGNED)(2013-09-25 17:37:02) Reg HKLM\SOFTWARE\Classes\CLSID\{6A6F4B83-45C5-4ca9-BDD9-0D81C12295E4}\InprocServer32@ C:\Windows\system32\mstscax.dll (Remote Desktop Services ActiveX Client/Microsoft Corporation SIGNED)(2013-09-25 08:15:19) Reg HKLM\SOFTWARE\Classes\CLSID\{6B4ECC4F-16D1-4474-94AB-5A763F2A54AE}\InProcServer32@ C:\Windows\System32\ieframe.dll (Internet Browser/Microsoft Corporation SIGNED)(2013-12-13 11:08:39) Reg HKLM\SOFTWARE\Classes\CLSID\{6B56A227-7150-4A1F-A114-C959EB8F8C24}\InProcServer32@ C:\Windows\System32\appmgmts.dll (Software installation Service/Microsoft Corporation SIGNED)(2009-07-13 23:38:34) Reg HKLM\SOFTWARE\Classes\CLSID\{6B6F9D2D-6D49-4026-83A6-86DFC1C3C6F0}\InProcServer32@ C:\Windows\system32\shell32.dll (Windows Shell Common Dll/Microsoft Corporation SIGNED)(2013-09-26 18:21:44) Reg HKLM\SOFTWARE\Classes\CLSID\{6BC0969D-0CE6-11D1-BAAE-00C04FC2E20D}\InprocServer32@ C:\Windows\system32\iassvcs.dll (NPS Services Component/Microsoft Corporation SIGNED)(2009-07-13 23:53:20) Reg HKLM\SOFTWARE\Classes\CLSID\{6BC1CFFA-8FC1-4261-AC22-CFB4CC38DB50}\InprocServer32@ C:\Windows\system32\quartz.dll (DirectShow Runtime./Microsoft Corporation SIGNED)(2013-09-25 08:10:55) Reg HKLM\SOFTWARE\Classes\CLSID\{6BF52A52-394A-11d3-B153-00C04F79FAA6}@LocalizedString C:\Windows\system32\wmploc.dll (Windows Media Player Resources/Microsoft Corporation SIGNED)(2013-09-25 17:37:01) Reg HKLM\SOFTWARE\Classes\CLSID\{6C1C243A-2146-3342-8078-AC4BFB9DB4E9}\InprocServer32@ C:\Windows\system32\mscoree.dll (Microsoft .NET Runtime Execution Engine/Microsoft Corporation SIGNED)(2013-09-25 17:38:26) Reg HKLM\SOFTWARE\Classes\CLSID\{6C5CFCDA-1F1A-4c9e-8D65-94771169D0B9}\InprocServer32@ C:\Windows\System32\gameux.dll (Games Explorer/Microsoft Corporation SIGNED)(2013-09-25 17:37:46) Reg HKLM\SOFTWARE\Classes\CLSID\{6C8EEC18-8D75-41B2-A177-8831D59D2D50}@InfoTip C:\Windows\System32\main.cpl (Mouse and Keyboard Control Panel Applets/Microsoft Corporation SIGNED)(2013-09-25 17:36:21) Reg HKLM\SOFTWARE\Classes\CLSID\{6CF48EF8-44CD-45d2-8832-A16EA016311B}\InProcServer32@ C:\Windows\System32\ieframe.dll (Internet Browser/Microsoft Corporation SIGNED)(2013-12-13 11:08:39) Reg HKLM\SOFTWARE\Classes\CLSID\{6D5313C0-8C62-11D1-B2CD-006097DF8C11}\InProcServer32@ C:\Windows\system32\shell32.dll (Windows Shell Common Dll/Microsoft Corporation SIGNED)(2013-09-26 18:21:44) Reg HKLM\SOFTWARE\Classes\CLSID\{6D8BB3D3-9D87-4a91-AB56-4F30CFFEFE9F}\InProcServer32@ C:\Windows\system32\explorerframe.dll (ExplorerFrame/Microsoft Corporation SIGNED)(2013-09-25 17:38:17) Reg HKLM\SOFTWARE\Classes\CLSID\{6DA736C9-DCDE-4651-82A8-56E4EF1D8DD7}\InProcServer32@ C:\Windows\system32\shell32.dll (Windows Shell Common Dll/Microsoft Corporation SIGNED)(2013-09-26 18:21:44) Reg HKLM\SOFTWARE\Classes\CLSID\{6E65CBC0-926D-11D0-8E27-00C04FC99DCF}\InProcServer32@ C:\Windows\system32\rascfg.dll (RAS Configuration Objects/Microsoft Corporation SIGNED)(2009-07-13 23:54:54) Reg HKLM\SOFTWARE\Classes\CLSID\{6F26A6CD-967B-47FD-874A-7AED2C9D25A2}\InprocServer32@ C:\Windows\system32\quartz.dll (DirectShow Runtime./Microsoft Corporation SIGNED)(2013-09-25 08:10:55) Reg HKLM\SOFTWARE\Classes\CLSID\{6f5bad87-9d5e-459f-bd03-3957407051ca}\InProcServer32@ C:\Windows\System32\ieframe.dll (Internet Browser/Microsoft Corporation SIGNED)(2013-12-13 11:08:39) Reg HKLM\SOFTWARE\Classes\CLSID\{6F674828-9081-3B45-BC39-791BD84CCF8F}\InprocServer32@ C:\Windows\system32\mscoree.dll (Microsoft .NET Runtime Execution Engine/Microsoft Corporation SIGNED)(2013-09-25 17:38:26) Reg HKLM\SOFTWARE\Classes\CLSID\{7057e952-bd1b-11d1-8919-00c04fc2c836}\InProcServer32@ C:\Windows\System32\ieframe.dll (Internet Browser/Microsoft Corporation SIGNED)(2013-12-13 11:08:39) Reg HKLM\SOFTWARE\Classes\CLSID\{7071EC77-663B-4BC1-A1FA-B97F3B917C55}\InProcServer32@ C:\Windows\system32\xwizards.dll (Extensible Wizards Manager Module/Microsoft Corporation SIGNED)(2009-07-13 23:51:41) Reg HKLM\SOFTWARE\Classes\CLSID\{7098BB2E-EB80-4433-BEF6-DF45206A41DC}\InProcServer32@ C:\Windows\System32\listsvc.dll (Windows HomeGroup/Microsoft Corporation SIGNED)(2013-09-25 17:37:57) Reg HKLM\SOFTWARE\Classes\CLSID\{709C1F8B-7756-3685-8350-B3ADDB5EC6B1}\InprocServer32@ C:\Windows\system32\mscoree.dll (Microsoft .NET Runtime Execution Engine/Microsoft Corporation SIGNED)(2013-09-25 17:38:26) Reg HKLM\SOFTWARE\Classes\CLSID\{709E2729-F883-441e-A877-ED3CEFC975E6}\InprocServer32@ C:\Windows\System32\gameux.dll (Games Explorer/Microsoft Corporation SIGNED)(2013-09-25 17:37:46) Reg HKLM\SOFTWARE\Classes\CLSID\{70A16474-54CD-3F1B-A2E4-032E7CD724C7}\InprocServer32@ C:\Windows\system32\mscoree.dll (Microsoft .NET Runtime Execution Engine/Microsoft Corporation SIGNED)(2013-09-25 17:38:26) Reg HKLM\SOFTWARE\Classes\CLSID\{70E102B0-5556-11CE-97C0-00AA0055595A}\InprocServer32@ C:\Windows\system32\quartz.dll (DirectShow Runtime./Microsoft Corporation SIGNED)(2013-09-25 08:10:55) Reg HKLM\SOFTWARE\Classes\CLSID\{713aacc8-3b71-435c-a3a1-be4e53621ab1}\InProcServer32@ C:\Windows\system32\shell32.dll (Windows Shell Common Dll/Microsoft Corporation SIGNED)(2013-09-26 18:21:44) Reg HKLM\SOFTWARE\Classes\CLSID\{7177c4bd-e20a-4140-ad8a-998e7a2d18c0}\InProcServer32@ C:\Windows\system32\rascfg.dll (RAS Configuration Objects/Microsoft Corporation SIGNED)(2009-07-13 23:54:54) Reg HKLM\SOFTWARE\Classes\CLSID\{71E32BAA-73EE-40a1-933C-F166F0192B72}\InProcServer32@ C:\Windows\system32\shell32.dll (Windows Shell Common Dll/Microsoft Corporation SIGNED)(2013-09-26 18:21:44) Reg HKLM\SOFTWARE\Classes\CLSID\{725BE8F7-668E-4C7B-8F90-46BDB0936430}@InfoTip C:\Windows\System32\main.cpl (Mouse and Keyboard Control Panel Applets/Microsoft Corporation SIGNED)(2013-09-25 17:36:21) Reg HKLM\SOFTWARE\Classes\CLSID\{725F645B-EAED-4fc5-B1C5-D9AD0ACCBA5E}\InProcServer32@ C:\Windows\System32\comdlg32.dll (Common Dialogs DLL/Microsoft Corporation SIGNED)(2013-09-25 17:37:51) Reg HKLM\SOFTWARE\Classes\CLSID\{726BBDF4-6C6D-30F4-B3A0-F14D6AEC08C7}\InprocServer32@ C:\Windows\system32\mscoree.dll (Microsoft .NET Runtime Execution Engine/Microsoft Corporation SIGNED)(2013-09-25 17:38:26) Reg HKLM\SOFTWARE\Classes\CLSID\{72A797C5-1BB2-40DE-89D0-5DFB4A416625}\InprocHandler32@ C:\Windows\system32\ole32.dll (Microsoft OLE for Windows/Microsoft Corporation SIGNED)(2013-09-25 17:36:42) Reg HKLM\SOFTWARE\Classes\CLSID\{72A7994A-3092-4054-B6BE-08FF81AEEFFC}@LocalizedString C:\Windows\system32\ntshrui.dll (Shell extensions for sharing/Microsoft Corporation SIGNED)(2013-09-25 17:37:19) Reg HKLM\SOFTWARE\Classes\CLSID\{72B082C6-97D5-11D3-8BEC-00C04F68DDC2}\InprocServer32@ C:\PROGRA~1\COMMON~1\SYSTEM\OLEDB~1\MSDMINE.DLL (Microsoft OLE DB Provider for Data Mining Services/Microsoft Corporation SIGNED)(2005-05-03 23:06:32) Reg HKLM\SOFTWARE\Classes\CLSID\{72b36e70-8700-42d6-a7f7-c9ab3323ee51}\InProcServer32@ C:\Windows\system32\shell32.dll (Windows Shell Common Dll/Microsoft Corporation SIGNED)(2013-09-26 18:21:44) Reg HKLM\SOFTWARE\Classes\CLSID\{730F6CDC-2C86-11D2-8773-92E220524153}\InProcServer32@ C:\Windows\system32\stobject.dll (Systray shell service object/Microsoft Corporation SIGNED)(2013-09-25 17:36:32) Reg HKLM\SOFTWARE\Classes\CLSID\{73257e95-0378-49d6-a954-44aabc841eab}\InprocServer32@ C:\Windows\system32\netcorehc.dll (Networking Core Diagnostics Helper Classes/Microsoft Corporation SIGNED)(2009-07-13 23:52:44) Reg HKLM\SOFTWARE\Classes\CLSID\{7390f3d8-0439-4c05-91e3-cf5cb290c3d0}\InprocServer32@ C:\Windows\system32\mstscax.dll (Remote Desktop Services ActiveX Client/Microsoft Corporation SIGNED)(2013-09-25 08:15:19) Reg HKLM\SOFTWARE\Classes\CLSID\{73CFD649-CD48-4fd8-A272-2070EA56526B}\InProcServer32@ C:\Windows\System32\ieframe.dll (Internet Browser/Microsoft Corporation SIGNED)(2013-12-13 11:08:39) Reg HKLM\SOFTWARE\Classes\CLSID\{73FDDC80-AEA9-101A-98A7-00AA00374959}@LocalizedString C:\Program Files\Windows NT\Accessories\WORDPAD.EXE (Windows Wordpad Application/Microsoft Corporation SIGNED)(2013-09-25 17:37:35) Reg HKLM\SOFTWARE\Classes\CLSID\{73FDDC80-AEA9-101A-98A7-00AA00374959}\InprocHandler32@ C:\Windows\system32\ole32.dll (Microsoft OLE for Windows/Microsoft Corporation SIGNED)(2013-09-25 17:36:42) Reg HKLM\SOFTWARE\Classes\CLSID\{73FDDC80-AEA9-101A-98A7-00AA00374959}\LocalServer32@ C:\Program Files\Windows NT\Accessories\WORDPAD.EXE (Windows Wordpad Application/Microsoft Corporation SIGNED)(2013-09-25 17:37:35) Reg HKLM\SOFTWARE\Classes\CLSID\{742AD1FB-B2F0-3681-B4AA-E736A3BCE4E1}\InprocServer32@ C:\Windows\system32\mscoree.dll (Microsoft .NET Runtime Execution Engine/Microsoft Corporation SIGNED)(2013-09-25 17:38:26) Reg HKLM\SOFTWARE\Classes\CLSID\{7487cd30-f71a-11d0-9ea7-00805f714772}\InProcServer32@ C:\Windows\system32\shell32.dll (Windows Shell Common Dll/Microsoft Corporation SIGNED)(2013-09-26 18:21:44) Reg HKLM\SOFTWARE\Classes\CLSID\{74BDD0B9-38D7-3FDA-A67E-D404EE684F24}\InprocServer32@ C:\Windows\system32\mscoree.dll (Microsoft .NET Runtime Execution Engine/Microsoft Corporation SIGNED)(2013-09-25 17:38:26) Reg HKLM\SOFTWARE\Classes\CLSID\{75048700-EF1F-11D0-9888-006097DEACF9}\InProcServer32@ C:\Windows\system32\shell32.dll (Windows Shell Common Dll/Microsoft Corporation SIGNED)(2013-09-26 18:21:44) Reg HKLM\SOFTWARE\Classes\CLSID\{75215200-A2FE-30F6-A34B-8F1A1830358E}\InprocServer32@ C:\Windows\system32\mscoree.dll (Microsoft .NET Runtime Execution Engine/Microsoft Corporation SIGNED)(2013-09-25 17:38:26) Reg HKLM\SOFTWARE\Classes\CLSID\{7542E960-79C7-11D1-88F9-0080C7D771BF}\InprocServer32@ C:\Windows\system32\es.dll (COM+/Microsoft Corporation SIGNED)(2009-07-13 23:44:38) Reg HKLM\SOFTWARE\Classes\CLSID\{75847177-f077-4171-bd2c-a6bb2164fbd0}\InProcServer32@ C:\Windows\system32\shell32.dll (Windows Shell Common Dll/Microsoft Corporation SIGNED)(2013-09-26 18:21:44) Reg HKLM\SOFTWARE\Classes\CLSID\{7584c670-2274-4efb-b00b-d6aaba6d3850}\InprocServer32@ C:\Windows\system32\mstscax.dll (Remote Desktop Services ActiveX Client/Microsoft Corporation SIGNED)(2013-09-25 08:15:19) Reg HKLM\SOFTWARE\Classes\CLSID\{75999EBA-0679-3D43-BDC4-02E4D637F1B1}\InprocServer32@ C:\Windows\system32\mscoree.dll (Microsoft .NET Runtime Execution Engine/Microsoft Corporation SIGNED)(2013-09-25 17:38:26) Reg HKLM\SOFTWARE\Classes\CLSID\{75dff2b7-6936-4c06-a8bb-676a7b00b24b}\LocalServer32@ C:\Windows\explorer.exe (Windows Explorer/Microsoft Corporation SIGNED)(2013-09-25 17:37:42) Reg HKLM\SOFTWARE\Classes\CLSID\{764FE7E3-A470-11D6-9500-00065B874123}\InProcServer32@ C:\Program Files\Common Files\Microsoft Shared\OFFICE11\MSSOAP30.DLL (Microsoft Office Soap SDK/Microsoft Corporation)(2002-12-06 12:25:10) Reg HKLM\SOFTWARE\Classes\CLSID\{76765b11-3f95-4af2-ac9d-ea55d8994f1a}\InProcServer32@ C:\Windows\system32\propsys.dll (Microsoft Property System/Microsoft Corporation SIGNED)(2013-09-25 17:38:03) Reg HKLM\SOFTWARE\Classes\CLSID\{769B8B68-64F7-3B61-B744-160A9FCC3216}\InprocServer32@ C:\Windows\system32\mscoree.dll (Microsoft .NET Runtime Execution Engine/Microsoft Corporation SIGNED)(2013-09-25 17:38:26) Reg HKLM\SOFTWARE\Classes\CLSID\{7763B7C0-A5FD-4AA9-BD1B-58B17137236B}\InProcServer32@ C:\Windows\system32\shell32.dll (Windows Shell Common Dll/Microsoft Corporation SIGNED)(2013-09-26 18:21:44) Reg HKLM\SOFTWARE\Classes\CLSID\{777BA815-2498-4875-933A-3067DE883070}@LocalizedString C:\Windows\system32\xwizards.dll (Extensible Wizards Manager Module/Microsoft Corporation SIGNED)(2009-07-13 23:51:41) Reg HKLM\SOFTWARE\Classes\CLSID\{777BA815-2498-4875-933A-3067DE883070}\Elevation@IconReference C:\Windows\system32\imageres.dll (Windows Image Resource/Microsoft Corporation SIGNED)(2009-07-13 23:42:24) Reg HKLM\SOFTWARE\Classes\CLSID\{777BA815-2498-4875-933A-3067DE883070}\InProcServer32@ C:\Windows\system32\xwizards.dll (Extensible Wizards Manager Module/Microsoft Corporation SIGNED)(2009-07-13 23:51:41) Reg HKLM\SOFTWARE\Classes\CLSID\{777BA816-2498-4875-933A-3067DE883070}\Elevation@IconReference C:\Windows\system32\imageres.dll (Windows Image Resource/Microsoft Corporation SIGNED)(2009-07-13 23:42:24) Reg HKLM\SOFTWARE\Classes\CLSID\{777BA816-2498-4875-933A-3067DE883070}\InProcServer32@ C:\Windows\system32\xwizards.dll (Extensible Wizards Manager Module/Microsoft Corporation SIGNED)(2009-07-13 23:51:41) Reg HKLM\SOFTWARE\Classes\CLSID\{777BA81A-2498-4875-933A-3067DE883070}\Elevation@IconReference C:\Windows\system32\imageres.dll (Windows Image Resource/Microsoft Corporation SIGNED)(2009-07-13 23:42:24) Reg HKLM\SOFTWARE\Classes\CLSID\{777BA87C-2498-4875-933A-3067DE883070}\InProcServer32@ C:\Windows\system32\xwizards.dll (Extensible Wizards Manager Module/Microsoft Corporation SIGNED)(2009-07-13 23:51:41) Reg HKLM\SOFTWARE\Classes\CLSID\{777BA8F5-2498-4875-933A-3067DE883070}\Elevation@IconReference C:\Windows\system32\imageres.dll (Windows Image Resource/Microsoft Corporation SIGNED)(2009-07-13 23:42:24) Reg HKLM\SOFTWARE\Classes\CLSID\{777BA8F9-2498-4875-933A-3067DE883070}@LocalizedString C:\Windows\system32\xwizards.dll (Extensible Wizards Manager Module/Microsoft Corporation SIGNED)(2009-07-13 23:51:41) Reg HKLM\SOFTWARE\Classes\CLSID\{777BA8F9-2498-4875-933A-3067DE883070}\Elevation@IconReference C:\Windows\system32\imageres.dll (Windows Image Resource/Microsoft Corporation SIGNED)(2009-07-13 23:42:24) Reg HKLM\SOFTWARE\Classes\CLSID\{777BA8FB-2498-4875-933A-3067DE883070}@LocalizedString C:\Windows\system32\xwizards.dll (Extensible Wizards Manager Module/Microsoft Corporation SIGNED)(2009-07-13 23:51:41) Reg HKLM\SOFTWARE\Classes\CLSID\{777BA8FB-2498-4875-933A-3067DE883070}\Elevation@IconReference C:\Windows\system32\imageres.dll (Windows Image Resource/Microsoft Corporation SIGNED)(2009-07-13 23:42:24) Reg HKLM\SOFTWARE\Classes\CLSID\{777F668E-3272-39CD-A8B5-860935A35181}\InprocServer32@ C:\Windows\system32\mscoree.dll (Microsoft .NET Runtime Execution Engine/Microsoft Corporation SIGNED)(2013-09-25 17:38:26) Reg HKLM\SOFTWARE\Classes\CLSID\{77F10CF0-3DB5-4966-B520-B7C54FD35ED6}\InProcServer32@ C:\Windows\system32\shell32.dll (Windows Shell Common Dll/Microsoft Corporation SIGNED)(2013-09-26 18:21:44) Reg HKLM\SOFTWARE\Classes\CLSID\{77F419AA-771A-45ff-AC66-7567FA3243D3}\InProcServer32@ C:\Windows\system32\ntshrui.dll (Shell extensions for sharing/Microsoft Corporation SIGNED)(2013-09-25 17:37:19) Reg HKLM\SOFTWARE\Classes\CLSID\{782fc20a-81cf-43de-a625-072155bcd30c}\InProcServer32@ C:\Windows\system32\xwizards.dll (Extensible Wizards Manager Module/Microsoft Corporation SIGNED)(2009-07-13 23:51:41) Reg HKLM\SOFTWARE\Classes\CLSID\{7849596a-48ea-486e-8937-a2a3009f31a9}\InProcServer32@ C:\Windows\system32\shell32.dll (Windows Shell Common Dll/Microsoft Corporation SIGNED)(2013-09-26 18:21:44) Reg HKLM\SOFTWARE\Classes\CLSID\{78CB147A-98EA-4AA6-B0DF-C8681F69341C}@InfoTip C:\Windows\System32\icardres.dll (Windows CardSpace/Microsoft Corporation SIGNED)(2009-07-14 00:36:29) Reg HKLM\SOFTWARE\Classes\CLSID\{78D22140-40CF-303E-BE96-B3AC0407A34D}\InprocServer32@ C:\Windows\system32\mscoree.dll (Microsoft .NET Runtime Execution Engine/Microsoft Corporation SIGNED)(2013-09-25 17:38:26) Reg HKLM\SOFTWARE\Classes\CLSID\{79376820-07D0-11CF-A24D-0020AFD79767}\InprocServer32@ C:\Windows\system32\quartz.dll (DirectShow Runtime./Microsoft Corporation SIGNED)(2013-09-25 08:10:55) Reg HKLM\SOFTWARE\Classes\CLSID\{7940ACF8-60BA-4213-A7C3-F3B400EE266D}\InProcServer32@ C:\Windows\system32\tsworkspace.dll (RemoteApp and Desktop Connection Component/Microsoft Corporation SIGNED)(2013-09-25 17:37:06) Reg HKLM\SOFTWARE\Classes\CLSID\{7988B571-EC89-11cf-9C00-00AA00A14F56}\InProcServer32@ C:\Windows\System32\dskquota.dll (Windows Shell Disk Quota Support DLL/Microsoft Corporation SIGNED)(2009-07-13 23:41:14) Reg HKLM\SOFTWARE\Classes\CLSID\{79eac9e0-baf9-11ce-8c82-00aa004ba90b}\InprocServer32@ C:\Windows\system32\urlmon.dll (OLE32 Extensions for Win32/Microsoft Corporation SIGNED)(2013-12-13 11:08:41) Reg HKLM\SOFTWARE\Classes\CLSID\{7A076CE1-4B31-452a-A4F1-0304C8738100}\Elevation@IconReference C:\Windows\system32\imageres.dll (Windows Image Resource/Microsoft Corporation SIGNED)(2009-07-13 23:42:24) Reg HKLM\SOFTWARE\Classes\CLSID\{7aa7790d-75d7-484b-98a1-3913d022091d}@LocalizedString C:\Windows\system32\shell32.dll (Windows Shell Common Dll/Microsoft Corporation SIGNED)(2013-09-26 18:21:44) Reg HKLM\SOFTWARE\Classes\CLSID\{7AE01D6C-BEE7-38F6-9A86-329D8A917803}\InprocServer32@ C:\Windows\system32\mscoree.dll (Microsoft .NET Runtime Execution Engine/Microsoft Corporation SIGNED)(2013-09-25 17:38:26) Reg HKLM\SOFTWARE\Classes\CLSID\{7B31547E-EF7E-479b-9494-2216DC179E61}\InProcServer32@ C:\Windows\system32\shell32.dll (Windows Shell Common Dll/Microsoft Corporation SIGNED)(2013-09-26 18:21:44) Reg HKLM\SOFTWARE\Classes\CLSID\{7b4a83b6-f704-4b77-8e3d-c6087e3a21d2}\InProcServer32@ C:\Windows\system32\ntshrui.dll (Shell extensions for sharing/Microsoft Corporation SIGNED)(2013-09-25 17:37:19) Reg HKLM\SOFTWARE\Classes\CLSID\{7B769B29-35F0-3BDC-AAE9-E99937F6CDEC}\InprocServer32@ C:\Windows\system32\mscoree.dll (Microsoft .NET Runtime Execution Engine/Microsoft Corporation SIGNED)(2013-09-25 17:38:26) Reg HKLM\SOFTWARE\Classes\CLSID\{7b8a2d94-0ac9-11d1-896c-00c04Fb6bfc4}\InprocServer32@ C:\Windows\system32\urlmon.dll (OLE32 Extensions for Win32/Microsoft Corporation SIGNED)(2013-12-13 11:08:41) Reg HKLM\SOFTWARE\Classes\CLSID\{7B938A6F-77BF-351C-A712-69483C91115D}\InprocServer32@ C:\Windows\system32\mscoree.dll (Microsoft .NET Runtime Execution Engine/Microsoft Corporation SIGNED)(2013-09-25 17:38:26) Reg HKLM\SOFTWARE\Classes\CLSID\{7BA4C740-9E81-11CF-99D3-00AA004AE837}\InProcServer32@ C:\Windows\system32\shell32.dll (Windows Shell Common Dll/Microsoft Corporation SIGNED)(2013-09-26 18:21:44) Reg HKLM\SOFTWARE\Classes\CLSID\{7BC115CD-1EE2-3068-894D-E3D3F7632F40}\InprocServer32@ C:\Windows\system32\mscoree.dll (Microsoft .NET Runtime Execution Engine/Microsoft Corporation SIGNED)(2013-09-25 17:38:26) Reg HKLM\SOFTWARE\Classes\CLSID\{7BD29E00-76C1-11CF-9DD0-00A0C9034933}\InProcServer32@ C:\Windows\System32\ieframe.dll (Internet Browser/Microsoft Corporation SIGNED)(2013-12-13 11:08:39) Reg HKLM\SOFTWARE\Classes\CLSID\{7be73787-ce71-4b33-b4c8-00d32b54bea8}@LocalizedString C:\Windows\system32\provsvc.dll (Windows HomeGroup/Microsoft Corporation SIGNED)(2013-09-25 17:37:30) Reg HKLM\SOFTWARE\Classes\CLSID\{7be73787-ce71-4b33-b4c8-00d32b54bea8}\Elevation@IconReference C:\Windows\system32\imageres.dll (Windows Image Resource/Microsoft Corporation SIGNED)(2009-07-13 23:42:24) Reg HKLM\SOFTWARE\Classes\CLSID\{7be73787-ce71-4b33-b4c8-00d32b54bea8}\InProcServer32@ C:\Windows\System32\provsvc.dll (Windows HomeGroup/Microsoft Corporation SIGNED)(2013-09-25 17:37:30) Reg HKLM\SOFTWARE\Classes\CLSID\{7be9d83c-a729-4d97-b5a7-1b7313c39e0a}\InProcServer32@ C:\Windows\system32\shell32.dll (Windows Shell Common Dll/Microsoft Corporation SIGNED)(2013-09-26 18:21:44) Reg HKLM\SOFTWARE\Classes\CLSID\{7cacbd7b-0d99-468f-ac33-22e495c0afe5}\InprocServer32@ C:\Windows\system32\mstscax.dll (Remote Desktop Services ActiveX Client/Microsoft Corporation SIGNED)(2013-09-25 08:15:19) Reg HKLM\SOFTWARE\Classes\CLSID\{7cd3c903-d2e9-4a4d-8af3-3025445b24bf}\InProcServer32@ C:\Windows\system32\shell32.dll (Windows Shell Common Dll/Microsoft Corporation SIGNED)(2013-09-26 18:21:44) Reg HKLM\SOFTWARE\Classes\CLSID\{7D8AA343-6E63-4663-BE90-6B80F66540A3}\InprocServer32@ C:\Windows\system32\quartz.dll (DirectShow Runtime./Microsoft Corporation SIGNED)(2013-09-25 08:10:55) Reg HKLM\SOFTWARE\Classes\CLSID\{7df2cfcd-6c09-415a-ae9d-5263f4964cbb}\InProcServer32@ C:\Windows\system32\shell32.dll (Windows Shell Common Dll/Microsoft Corporation SIGNED)(2013-09-26 18:21:44) Reg HKLM\SOFTWARE\Classes\CLSID\{7E3393AB-2AB2-320B-8F6F-EAB6F5CF2CAF}\InprocServer32@ C:\Windows\system32\mscoree.dll (Microsoft .NET Runtime Execution Engine/Microsoft Corporation SIGNED)(2013-09-25 17:38:26) Reg HKLM\SOFTWARE\Classes\CLSID\{7E45546F-6D52-4D10-B702-9C2E67232E62}\InprocServer32@ C:\Windows\System32\appmgr.dll (Software Installation Snapin Extenstion/Microsoft Corporation SIGNED)(2013-09-25 17:37:12) Reg HKLM\SOFTWARE\Classes\CLSID\{7E48C5CF-72F6-4C84-9F43-B04B87B31243}\InprocServer32@ C:\Windows\system32\wshext.dll (Microsoft � Shell Extension for Windows Script Host/Microsoft Corporation SIGNED)(2009-07-13 23:42:38) Reg HKLM\SOFTWARE\Classes\CLSID\{7E8BC44E-AEFF-11D1-89C2-00C04FB6BFC4}\InprocServer32@ C:\Windows\System32\mshtml.dll (Microsoft (R) HTML Viewer/Microsoft Corporation SIGNED)(2013-12-13 11:08:38) Reg HKLM\SOFTWARE\Classes\CLSID\{7EB5FBE4-2100-49E6-8593-17E130122F91}\InProcServer32@ C:\Windows\system32\shell32.dll (Windows Shell Common Dll/Microsoft Corporation SIGNED)(2013-09-26 18:21:44) Reg HKLM\SOFTWARE\Classes\CLSID\{7EE0A24E-A8C6-46ae-A875-8E7C3D18AEAF}\InProcServer32@ C:\Windows\System32\ieframe.dll (Internet Browser/Microsoft Corporation SIGNED)(2013-12-13 11:08:39) Reg HKLM\SOFTWARE\Classes\CLSID\{7F368827-9516-11D0-83D9-00A0C911E5DF}\InProcServer32@ C:\Windows\system32\netcfgx.dll (Network Configuration Objects/Microsoft Corporation SIGNED)(2013-09-25 17:38:28) Reg HKLM\SOFTWARE\Classes\CLSID\{7F6BCBE5-EB30-370B-9F1B-92A6265AFEDD}\InprocServer32@ C:\Windows\system32\mscoree.dll (Microsoft .NET Runtime Execution Engine/Microsoft Corporation SIGNED)(2013-09-25 17:38:26) Reg HKLM\SOFTWARE\Classes\CLSID\{7FE0D935-DDA6-443F-85D0-1CFB58FE41DD}\InProcServer32@ C:\Windows\system32\certcli.dll (Microsoft� Active Directory Certificate Services Client/Microsoft Corporation SIGNED)(2013-09-25 17:38:23) Reg HKLM\SOFTWARE\Classes\CLSID\{7FE87A55-1321-3D9F-8FEF-CD2F5E8AB2E9}\InprocServer32@ C:\Windows\system32\mscoree.dll (Microsoft .NET Runtime Execution Engine/Microsoft Corporation SIGNED)(2013-09-25 17:38:26) Reg HKLM\SOFTWARE\Classes\CLSID\{7febaf7c-18cf-11d2-993f-00a0c91f3880}\InProcServer32@ C:\Windows\system32\shell32.dll (Windows Shell Common Dll/Microsoft Corporation SIGNED)(2013-09-26 18:21:44) Reg HKLM\SOFTWARE\Classes\CLSID\{80CB8C11-0E10-45F4-A1BA-EAD3838D7034}\InprocServer32@ C:\Windows\System32\vdsvd.dll (VDS Virtual Disk Provider, Version 1.0/Microsoft Corporation SIGNED)(2009-07-13 23:23:37) Reg HKLM\SOFTWARE\Classes\CLSID\{81007291-f070-4c4f-b978-ad1bec84babc}\InProcServer32@ C:\Windows\system32\shell32.dll (Windows Shell Common Dll/Microsoft Corporation SIGNED)(2013-09-26 18:21:44) Reg HKLM\SOFTWARE\Classes\CLSID\{8144B6F5-20A8-444a-B8EE-19DF0BB84BDB}\LocalServer32@ C:\Windows\System32\wiaacmgr.exe (Windows Picture Acquisition Wizard/Microsoft Corporation SIGNED)(2009-07-14 00:15:13) Reg HKLM\SOFTWARE\Classes\CLSID\{819469D2-D0CF-11d1-8E0B-00C04FC2E0C7}\InprocServer32@ C:\Windows\system32\clbcatq.dll (COM+ Configuration Catalog/Microsoft Corporation SIGNED)(2009-07-13 23:44:44) Reg HKLM\SOFTWARE\Classes\CLSID\{819d1334-9d74-4254-9ac8-dc745ebc5386}\InProcServer32@ C:\Windows\system32\shell32.dll (Windows Shell Common Dll/Microsoft Corporation SIGNED)(2013-09-26 18:21:44) Reg HKLM\SOFTWARE\Classes\CLSID\{81C5FE01-027C-3E1C-98D5-DA9C9862AA21}\InprocServer32@ C:\Windows\system32\mscoree.dll (Microsoft .NET Runtime Execution Engine/Microsoft Corporation SIGNED)(2013-09-25 17:38:26) Reg HKLM\SOFTWARE\Classes\CLSID\{823B8267-735C-477E-8151-0FA9ADC8AB3A}\InProcServer32@ C:\Windows\system32\shell32.dll (Windows Shell Common Dll/Microsoft Corporation SIGNED)(2013-09-26 18:21:44) Reg HKLM\SOFTWARE\Classes\CLSID\{8336e323-2e6a-4a04-937c-548f681839b3}\InprocServer32@ C:\Windows\system32\CertEnroll.dll (Microsoft� Active Directory Certificate Services Enrollment Client/Microsoft Corporation SIGNED)(2013-09-25 17:37:47) Reg HKLM\SOFTWARE\Classes\CLSID\{8369AB20-56C9-11D0-94E8-00AA0059CE02}\InProcServer32@ C:\Windows\System32\occache.dll (Object Control Viewer/Microsoft Corporation SIGNED)(2013-11-12 12:08:30) Reg HKLM\SOFTWARE\Classes\CLSID\{837A6733-1675-3BC9-BBF8-13889F84DAF4}\InprocServer32@ C:\Windows\system32\mscoree.dll (Microsoft .NET Runtime Execution Engine/Microsoft Corporation SIGNED)(2013-09-25 17:38:26) Reg HKLM\SOFTWARE\Classes\CLSID\{83bb272f-7d5e-4b6e-9250-889893f0dac7}\InProcServer32@ C:\Windows\system32\shell32.dll (Windows Shell Common Dll/Microsoft Corporation SIGNED)(2013-09-26 18:21:44) Reg HKLM\SOFTWARE\Classes\CLSID\{84589833-40D7-36E2-8545-67A92B97C408}\InprocServer32@ C:\Windows\system32\mscoree.dll (Microsoft .NET Runtime Execution Engine/Microsoft Corporation SIGNED)(2013-09-25 17:38:26) Reg HKLM\SOFTWARE\Classes\CLSID\{84a3a6bf-f1d8-496e-9f05-d3de70973152}\InprocServer32@ C:\Windows\System32\WWanHC.dll (Wireless WAN Helper Class/Microsoft Corporation SIGNED)(2009-07-13 23:56:35) Reg HKLM\SOFTWARE\Classes\CLSID\{84CCE1D2-97AD-4448-AF0F-A79164073A60}\InProcServer32@ C:\Windows\System32\themecpl.dll (Personalization CPL/Microsoft Corporation SIGNED)(2013-09-25 17:38:13) Reg HKLM\SOFTWARE\Classes\CLSID\{84e04a55-2d42-4909-86e3-62fd11483e8b}\InProcServer32@ C:\Windows\system32\setupcln.dll (Setup Files Cleanup/Microsoft Corporation SIGNED)(2013-09-25 17:37:25) Reg HKLM\SOFTWARE\Classes\CLSID\{84F70B6C-D59E-394A-B879-FFCC30DDCAA2}\InprocServer32@ C:\Windows\system32\mscoree.dll (Microsoft .NET Runtime Execution Engine/Microsoft Corporation SIGNED)(2013-09-25 17:38:26) Reg HKLM\SOFTWARE\Classes\CLSID\{8509bb76-ffa3-4827-ba5e-2e786010f42f}\InProcServer32@ C:\Windows\system32\shell32.dll (Windows Shell Common Dll/Microsoft Corporation SIGNED)(2013-09-26 18:21:44) Reg HKLM\SOFTWARE\Classes\CLSID\{862321c3-70b2-4ee2-8231-87ec05819d98}\InProcServer32@ C:\Windows\system32\netcorehc.dll (Networking Core Diagnostics Helper Classes/Microsoft Corporation SIGNED)(2009-07-13 23:52:44) Reg HKLM\SOFTWARE\Classes\CLSID\{86422020-42A0-1069-A2E5-08002B30309D}\InProcServer32@ C:\Windows\system32\shell32.dll (Windows Shell Common Dll/Microsoft Corporation SIGNED)(2013-09-26 18:21:44) Reg HKLM\SOFTWARE\Classes\CLSID\{8670C736-F614-427b-8ADA-BBADC587194B}\InprocServer32@ C:\Windows\system32\quartz.dll (DirectShow Runtime./Microsoft Corporation SIGNED)(2013-09-25 08:10:55) Reg HKLM\SOFTWARE\Classes\CLSID\{86747AC0-42A0-1069-A2E6-08002B30309D}@FriendlyTypeName C:\Windows\system32\shell32.dll (Windows Shell Common Dll/Microsoft Corporation SIGNED)(2013-09-26 18:21:44) Reg HKLM\SOFTWARE\Classes\CLSID\{86EB31DF-A46F-11D6-9500-00065B874123}\InprocServer32@ C:\Program Files\Common Files\Microsoft Shared\OFFICE11\MSSOAP30.DLL (Microsoft Office Soap SDK/Microsoft Corporation)(2002-12-06 12:25:10) Reg HKLM\SOFTWARE\Classes\CLSID\{86F19A00-42A0-1069-A2E9-08002B30309D}\InProcServer32@ C:\Windows\system32\shell32.dll (Windows Shell Common Dll/Microsoft Corporation SIGNED)(2013-09-26 18:21:44) Reg HKLM\SOFTWARE\Classes\CLSID\{870AF99C-171D-4f9e-AF0D-E63DF40C2BC9}\InprocServer32@ C:\Windows\System32\audioses.dll (Audio Session/Microsoft Corporation SIGNED)(2013-09-25 17:36:17) Reg HKLM\SOFTWARE\Classes\CLSID\{871C5380-42A0-1069-A2EA-08002B30309D}@InfoTip C:\Windows\System32\ieframe.dll (Internet Browser/Microsoft Corporation SIGNED)(2013-12-13 11:08:39) Reg HKLM\SOFTWARE\Classes\CLSID\{871C5380-42A0-1069-A2EA-08002B30309D}\shell\NoAddOns\Command@ C:\Program Files\Internet Explorer\iexplore.exe (Internet Explorer/Microsoft Corporation SIGNED)(2013-11-12 12:08:36) Reg HKLM\SOFTWARE\Classes\CLSID\{871C5380-42A0-1069-A2EA-08002B30309D}\ShellFolder@ C:\Windows\System32\ieframe.dll (Internet Browser/Microsoft Corporation SIGNED)(2013-12-13 11:08:39) Reg HKLM\SOFTWARE\Classes\CLSID\{87DBE38C-A22E-43D3-8128-27FFA848A113}\InprocServer32@ C:\Windows\System32\mscoree.dll (Microsoft .NET Runtime Execution Engine/Microsoft Corporation SIGNED)(2013-09-25 17:38:26) Reg HKLM\SOFTWARE\Classes\CLSID\{880ac964-2e34-4425-8cf2-86ada2c3a019}\InProcServer32@ C:\Windows\system32\shell32.dll (Windows Shell Common Dll/Microsoft Corporation SIGNED)(2013-09-26 18:21:44) Reg HKLM\SOFTWARE\Classes\CLSID\{8833BC41-DC6B-34B9-A799-682D2554F02F}\InprocServer32@ C:\Windows\system32\mscoree.dll (Microsoft .NET Runtime Execution Engine/Microsoft Corporation SIGNED)(2013-09-25 17:38:26) Reg HKLM\SOFTWARE\Classes\CLSID\{883FF1FC-09E1-48e5-8E54-E2469ACB0CFD}\InprocServer32@ C:\Windows\system32\srcore.dll (Microsoft� Windows System Restore Core Library/Microsoft Corporation SIGNED)(2013-09-25 17:36:32) Reg HKLM\SOFTWARE\Classes\CLSID\{884e2000-217d-11da-b2a4-000e7bbb2b09}\InprocServer32@ C:\Windows\system32\CertEnroll.dll (Microsoft� Active Directory Certificate Services Enrollment Client/Microsoft Corporation SIGNED)(2013-09-25 17:37:47) Reg HKLM\SOFTWARE\Classes\CLSID\{8853D6B2-E8AE-11D2-AFE8-00105A994724}\InprocServer32@ C:\PROGRA~1\COMMON~1\SYSTEM\OLEDB~1\MSDMINE.DLL (Microsoft OLE DB Provider for Data Mining Services/Microsoft Corporation SIGNED)(2005-05-03 23:06:32) Reg HKLM\SOFTWARE\Classes\CLSID\{8856F961-340A-11D0-A96B-00C04FD705A2}\InProcServer32@ C:\Windows\System32\ieframe.dll (Internet Browser/Microsoft Corporation SIGNED)(2013-12-13 11:08:39) Reg HKLM\SOFTWARE\Classes\CLSID\{88C6C381-2E85-11D0-94DE-444553540000}\InProcServer32@ C:\Windows\System32\occache.dll (Object Control Viewer/Microsoft Corporation SIGNED)(2013-11-12 12:08:30) Reg HKLM\SOFTWARE\Classes\CLSID\{88C8A919-EB24-3CCA-84F7-2EA82BB3F3ED}\InprocServer32@ C:\Windows\system32\mscoree.dll (Microsoft .NET Runtime Execution Engine/Microsoft Corporation SIGNED)(2013-09-25 17:38:26) Reg HKLM\SOFTWARE\Classes\CLSID\{8ADD018C-5C5F-43C5-BE1E-07BAE85593B7}\InProcServer32@ C:\Windows\System32\listsvc.dll (Windows HomeGroup/Microsoft Corporation SIGNED)(2013-09-25 17:37:57) Reg HKLM\SOFTWARE\Classes\CLSID\{8be9f5ea-e746-4e47-ad57-3fb191ca1eed}\InProcServer32@ C:\Windows\system32\explorerframe.dll (ExplorerFrame/Microsoft Corporation SIGNED)(2013-09-25 17:38:17) Reg HKLM\SOFTWARE\Classes\CLSID\{8C1425C9-A7D3-35CD-8248-928CA52AD49B}\InprocServer32@ C:\Windows\system32\mscoree.dll (Microsoft .NET Runtime Execution Engine/Microsoft Corporation SIGNED)(2013-09-25 17:38:26) Reg HKLM\SOFTWARE\Classes\CLSID\{8c1645b0-9864-465e-be75-990b030e4b11}\InProcServer32@ C:\Windows\system32\xwizards.dll (Extensible Wizards Manager Module/Microsoft Corporation SIGNED)(2009-07-13 23:51:41) Reg HKLM\SOFTWARE\Classes\CLSID\{8C40D44A-4EDE-3760-9B61-50255056D3C7}\InprocServer32@ C:\Windows\system32\mscoree.dll (Microsoft .NET Runtime Execution Engine/Microsoft Corporation SIGNED)(2013-09-25 17:38:26) Reg HKLM\SOFTWARE\Classes\CLSID\{8c537469-1ea9-4c85-9947-7e418500cdd4}\InProcServer32@ C:\Windows\System32\ieframe.dll (Internet Browser/Microsoft Corporation SIGNED)(2013-12-13 11:08:39) Reg HKLM\SOFTWARE\Classes\CLSID\{8C7461EF-2B13-11d2-BE35-3078302C2030}\InProcServer32@ C:\Windows\system32\explorerframe.dll (ExplorerFrame/Microsoft Corporation SIGNED)(2013-09-25 17:38:17) Reg HKLM\SOFTWARE\Classes\CLSID\{8c7eaf13-fbd6-4ed8-ac79-fb12fcd71326}\InprocServer32@ C:\Windows\System32\sdengin2.dll (Microsoft� Windows Backup Engine/Microsoft Corporation SIGNED)(2013-09-25 17:36:51) Reg HKLM\SOFTWARE\Classes\CLSID\{8d1e5d4b-a99c-4408-b0f0-ccab9e5835a1}\InProcServer32@ C:\Windows\system32\shell32.dll (Windows Shell Common Dll/Microsoft Corporation SIGNED)(2013-09-26 18:21:44) Reg HKLM\SOFTWARE\Classes\CLSID\{8D36569B-14D6-3C3D-B55C-9D02A45BFC3D}\InprocServer32@ C:\Windows\system32\mscoree.dll (Microsoft .NET Runtime Execution Engine/Microsoft Corporation SIGNED)(2013-09-25 17:38:26) Reg HKLM\SOFTWARE\Classes\CLSID\{8d80504a-0826-40c5-97e1-ebc68f953792}\InProcServer32@ C:\Windows\system32\propsys.dll (Microsoft Property System/Microsoft Corporation SIGNED)(2013-09-25 17:38:03) Reg HKLM\SOFTWARE\Classes\CLSID\{8E594310-16CA-4a00-932F-F70969F990C0}\InprocServer32@ C:\Windows\System32\QAgent.dll (Quarantine Agent Proxy/Microsoft Corporation SIGNED)(2013-09-25 17:38:03) Reg HKLM\SOFTWARE\Classes\CLSID\{8E6E6079-0CB7-11d2-8F10-0000F87ABD16}\InprocServer32@ C:\Windows\System32\ieframe.dll (Internet Browser/Microsoft Corporation SIGNED)(2013-12-13 11:08:39) Reg HKLM\SOFTWARE\Classes\CLSID\{8e827c11-33e7-4bc1-b242-8cd9a1c2b304}\InProcServer32@ C:\Windows\system32\shell32.dll (Windows Shell Common Dll/Microsoft Corporation SIGNED)(2013-09-26 18:21:44) Reg HKLM\SOFTWARE\Classes\CLSID\{8E989135-2736-4767-8160-EA3613F69D24}\InProcServer32@ C:\Windows\System32\ieframe.dll (Internet Browser/Microsoft Corporation SIGNED)(2013-12-13 11:08:39) Reg HKLM\SOFTWARE\Classes\CLSID\{8EE97210-FD1F-4b19-91DA-67914005F020}\InProcServer32@ C:\Windows\system32\shell32.dll (Windows Shell Common Dll/Microsoft Corporation SIGNED)(2013-09-26 18:21:44) Reg HKLM\SOFTWARE\Classes\CLSID\{8F45C7FF-1E6E-34C1-A7CC-260985392A05}\InprocServer32@ C:\Windows\system32\mscoree.dll (Microsoft .NET Runtime Execution Engine/Microsoft Corporation SIGNED)(2013-09-25 17:38:26) Reg HKLM\SOFTWARE\Classes\CLSID\{900be39d-6be8-461a-bc4d-b0fa71f5ecb1}\InprocServer32@ C:\Windows\System32\wdi.dll (Windows Diagnostic Infrastructure/Microsoft Corporation SIGNED)(2009-07-13 23:19:47) Reg HKLM\SOFTWARE\Classes\CLSID\{9059f30f-4eb1-4bd2-9fdc-36f43a218f4a}\InprocServer32@ C:\Windows\system32\mstscax.dll (Remote Desktop Services ActiveX Client/Microsoft Corporation SIGNED)(2013-09-25 08:15:19) Reg HKLM\SOFTWARE\Classes\CLSID\{905b55a8-77f0-4d28-80dd-e46b1412343f}\InProcServer32@ C:\Windows\system32\shell32.dll (Windows Shell Common Dll/Microsoft Corporation SIGNED)(2013-09-26 18:21:44) Reg HKLM\SOFTWARE\Classes\CLSID\{90b9bce2-b6db-4fd3-8451-35917ea1081b}\InProcServer32@ C:\Windows\system32\explorerframe.dll (ExplorerFrame/Microsoft Corporation SIGNED)(2013-09-25 17:38:17) Reg HKLM\SOFTWARE\Classes\CLSID\{90F1A06E-7712-4762-86B5-7A5EBA6BDB01}\InprocServer32@ C:\Windows\system32\mscoree.dll (Microsoft .NET Runtime Execution Engine/Microsoft Corporation SIGNED)(2013-09-25 17:38:26) Reg HKLM\SOFTWARE\Classes\CLSID\{9113A02D-00A3-46B9-BC5F-9C04DADDD5D7}\InProcServer32@ C:\Windows\system32\EhStorShell.dll (Windows Enhanced Storage Shell Extension DLL/Microsoft Corporation SIGNED)(2009-07-13 23:45:42) Reg HKLM\SOFTWARE\Classes\CLSID\{913a6daa-57ee-4551-9ada-64d329d306a5}\InProcServer32@ C:\Windows\System32\shell32.dll (Windows Shell Common Dll/Microsoft Corporation SIGNED)(2013-09-26 18:21:44) Reg HKLM\SOFTWARE\Classes\CLSID\{91591469-EFEF-3D63-90F9-88520F0AA1EF}\InprocServer32@ C:\Windows\system32\mscoree.dll (Microsoft .NET Runtime Execution Engine/Microsoft Corporation SIGNED)(2013-09-25 17:38:26) Reg HKLM\SOFTWARE\Classes\CLSID\{91f39027-217f-11da-b2a4-000e7bbb2b09}\InprocServer32@ C:\Windows\system32\CertEnroll.dll (Microsoft� Active Directory Certificate Services Enrollment Client/Microsoft Corporation SIGNED)(2013-09-25 17:37:47) Reg HKLM\SOFTWARE\Classes\CLSID\{91F672A3-6B82-3E04-B2D7-BAC5D6676609}\InprocServer32@ C:\Windows\system32\mscoree.dll (Microsoft .NET Runtime Execution Engine/Microsoft Corporation SIGNED)(2013-09-25 17:38:26) Reg HKLM\SOFTWARE\Classes\CLSID\{9200689A-F979-4eea-8830-0E1D6B74821F}@LocalizedString C:\Windows\System32\recovery.dll (Recovery Control Panel/Microsoft Corporation SIGNED)(2013-09-25 17:38:04) Reg HKLM\SOFTWARE\Classes\CLSID\{9207d8c7-e7c8-412e-87f8-2e61171bd291}\InProcServer32@ C:\Windows\system32\shell32.dll (Windows Shell Common Dll/Microsoft Corporation SIGNED)(2013-09-26 18:21:44) Reg HKLM\SOFTWARE\Classes\CLSID\{9209B7D1-6DA5-43E4-BCD1-F2BE497635E7}\InprocServer32@ C:\Windows\system32\rdpendp.dll (RDP Audio Endpoint/Microsoft Corporation SIGNED)(2013-09-25 17:37:31) Reg HKLM\SOFTWARE\Classes\CLSID\{92755472-2059-3F96-8938-8AC767B5187B}\InprocServer32@ C:\Windows\system32\mscoree.dll (Microsoft .NET Runtime Execution Engine/Microsoft Corporation SIGNED)(2013-09-25 17:38:26) Reg HKLM\SOFTWARE\Classes\CLSID\{92ab5af7-a374-417e-b2e2-9b317353a322}\InProcServer32@ C:\Windows\system32\shell32.dll (Windows Shell Common Dll/Microsoft Corporation SIGNED)(2013-09-26 18:21:44) Reg HKLM\SOFTWARE\Classes\CLSID\{92E76A74-2622-3AA9-A3CA-1AE8BD7BC4A8}\InprocServer32@ C:\Windows\system32\mscoree.dll (Microsoft .NET Runtime Execution Engine/Microsoft Corporation SIGNED)(2013-09-25 17:38:26) Reg HKLM\SOFTWARE\Classes\CLSID\{934a7048-1e4a-4d6e-9a9a-cb739f519b07}\InProcServer32@ C:\Windows\system32\xwizards.dll (Extensible Wizards Manager Module/Microsoft Corporation SIGNED)(2009-07-13 23:51:41) Reg HKLM\SOFTWARE\Classes\CLSID\{93a56381-e0cd-485a-b60e-67819e12f81b}\InProcServer32@ C:\Windows\system32\explorerframe.dll (ExplorerFrame/Microsoft Corporation SIGNED)(2013-09-25 17:38:17) Reg HKLM\SOFTWARE\Classes\CLSID\{93D11DE9-5F6C-354A-A7C5-16CCCA64A9B8}\InprocServer32@ C:\Windows\system32\mscoree.dll (Microsoft .NET Runtime Execution Engine/Microsoft Corporation SIGNED)(2013-09-25 17:38:26) Reg HKLM\SOFTWARE\Classes\CLSID\{942A8E4F-A261-11D1-A760-00C04FB9603F}\InprocServer32@ C:\Windows\System32\appmgr.dll (Software Installation Snapin Extenstion/Microsoft Corporation SIGNED)(2013-09-25 17:37:12) Reg HKLM\SOFTWARE\Classes\CLSID\{942bc614-676c-464e-b384-d3202aaa02da}\InProcServer32@ C:\Windows\System32\ieframe.dll (Internet Browser/Microsoft Corporation SIGNED)(2013-12-13 11:08:39) Reg HKLM\SOFTWARE\Classes\CLSID\{94357B53-CA29-4b78-83AE-E8FE7409134F}\InProcServer32@ C:\Windows\system32\shell32.dll (Windows Shell Common Dll/Microsoft Corporation SIGNED)(2013-09-26 18:21:44) Reg HKLM\SOFTWARE\Classes\CLSID\{9443B89B-6564-496a-B19C-6C6D22709045}\InprocServer32@ C:\Windows\System32\QAgent.dll (Quarantine Agent Proxy/Microsoft Corporation SIGNED)(2013-09-25 17:38:03) Reg HKLM\SOFTWARE\Classes\CLSID\{944D4C00-DD52-11CE-BF0E-00AA0055595A}\InprocServer32@ C:\Windows\system32\quartz.dll (DirectShow Runtime./Microsoft Corporation SIGNED)(2013-09-25 08:10:55) Reg HKLM\SOFTWARE\Classes\CLSID\{948B45F7-EFB8-46fb-8704-B340D847227A}\InProcServer32@ C:\Windows\system32\shell32.dll (Windows Shell Common Dll/Microsoft Corporation SIGNED)(2013-09-26 18:21:44) Reg HKLM\SOFTWARE\Classes\CLSID\{94AB5C27-C954-4218-B0A1-29640412EFBE}\InProcServer32@ C:\Windows\System32\recovery.dll (Recovery Control Panel/Microsoft Corporation SIGNED)(2013-09-25 17:38:04) Reg HKLM\SOFTWARE\Classes\CLSID\{94E03510-31B9-47a0-A44E-E932AC86BB17}\LocalServer32@ C:\Program Files\Windows Media Player\wmlaunch.exe (Windows Media Player Launcher/Microsoft Corporation SIGNED)(2013-09-25 17:38:10) Reg HKLM\SOFTWARE\Classes\CLSID\{94F215DB-5D7D-365E-8BDE-47DD72E53E39}\InprocServer32@ C:\Windows\system32\mscoree.dll (Microsoft .NET Runtime Execution Engine/Microsoft Corporation SIGNED)(2013-09-25 17:38:26) Reg HKLM\SOFTWARE\Classes\CLSID\{95028000-A6DE-493B-B253-9E18B19610A2}\Elevation@IconReference C:\Program Files\Skype\Updater\Updater.exe (Skype Updater Service/Skype Technologies SIGNED)(2013-09-05 09:34:30) Reg HKLM\SOFTWARE\Classes\CLSID\{9546306B-1B68-33AF-80DB-3A9206501515}\InprocServer32@ C:\Windows\system32\mscoree.dll (Microsoft .NET Runtime Execution Engine/Microsoft Corporation SIGNED)(2013-09-25 17:38:26) Reg HKLM\SOFTWARE\Classes\CLSID\{956FADED-2450-4ABB-9F8C-4629FAFEBB92}\InProcServer32@ C:\Windows\System32\listsvc.dll (Windows HomeGroup/Microsoft Corporation SIGNED)(2013-09-25 17:37:57) Reg HKLM\SOFTWARE\Classes\CLSID\{95CE8412-7027-11D1-B879-006008059382}\InProcServer32@ C:\Windows\system32\shell32.dll (Windows Shell Common Dll/Microsoft Corporation SIGNED)(2013-09-26 18:21:44) Reg HKLM\SOFTWARE\Classes\CLSID\{964AA3BD-4B12-3E23-9D7F-99342AFAE812}\InprocServer32@ C:\Windows\system32\mscoree.dll (Microsoft .NET Runtime Execution Engine/Microsoft Corporation SIGNED)(2013-09-25 17:38:26) Reg HKLM\SOFTWARE\Classes\CLSID\{971127BB-259F-48c2-BD75-5F97A3331551}\InprocServer32@ C:\Windows\system32\mstscax.dll (Remote Desktop Services ActiveX Client/Microsoft Corporation SIGNED)(2013-09-25 08:15:19) Reg HKLM\SOFTWARE\Classes\CLSID\{97e467b4-98c6-4f19-9588-161b7773d6f6}\InProcServer32@ C:\Windows\system32\propsys.dll (Microsoft Property System/Microsoft Corporation SIGNED)(2013-09-25 17:38:03) Reg HKLM\SOFTWARE\Classes\CLSID\{98455561-5136-4d28-AB08-4CEE40EA2781}\InprocServer32@ C:\Windows\System32\evr.dll (Enhanced Video Renderer DLL/Microsoft Corporation SIGNED)(2013-09-25 17:38:17) Reg HKLM\SOFTWARE\Classes\CLSID\{984F9804-3314-4FA4-AC8C-E688D4133C51}\InProcServer32@ C:\Windows\system32\tsworkspace.dll (RemoteApp and Desktop Connection Component/Microsoft Corporation SIGNED)(2013-09-25 17:37:06) Reg HKLM\SOFTWARE\Classes\CLSID\{98AFF3F0-5524-11D0-8812-00A0C903B83C}\InprocServer32@ C:\Windows\system32\certcli.dll (Microsoft� Active Directory Certificate Services Client/Microsoft Corporation SIGNED)(2013-09-25 17:38:23) Reg HKLM\SOFTWARE\Classes\CLSID\{98FF6D4B-6387-4b0a-8FBD-C5C4BB17B4F8}\InProcServer32@ C:\Windows\System32\ieframe.dll (Internet Browser/Microsoft Corporation SIGNED)(2013-12-13 11:08:39) Reg HKLM\SOFTWARE\Classes\CLSID\{99749841-0D55-4cf4-8D0D-F212ECE9409A}\InprocServer32@ C:\Windows\system32\MSCorEE.dll (Microsoft .NET Runtime Execution Engine/Microsoft Corporation SIGNED)(2013-09-25 17:38:26) Reg HKLM\SOFTWARE\Classes\CLSID\{99969a8f-27e6-4adf-ab9f-b5b5e90d4733}\InProcServer32@ C:\Windows\system32\shell32.dll (Windows Shell Common Dll/Microsoft Corporation SIGNED)(2013-09-26 18:21:44) Reg HKLM\SOFTWARE\Classes\CLSID\{99D54F63-1A69-41AE-AA4D-C976EB3F0713}\InprocServer32@ C:\Windows\system32\quartz.dll (DirectShow Runtime./Microsoft Corporation SIGNED)(2013-09-25 08:10:55) Reg HKLM\SOFTWARE\Classes\CLSID\{9a010fcc-488b-4836-94fd-c489f8e1ed7d}\InprocServer32@ C:\Windows\system32\ndishc.dll (NDIS Helper Classes/Microsoft Corporation SIGNED)(2009-07-13 23:52:47) Reg HKLM\SOFTWARE\Classes\CLSID\{9a02e012-6303-4e1e-b9a1-630f802592c5}\InProcServer32@ C:\Windows\system32\propsys.dll (Microsoft Property System/Microsoft Corporation SIGNED)(2013-09-25 17:38:03) Reg HKLM\SOFTWARE\Classes\CLSID\{9a096bb5-9dc3-4d1c-8526-c3cbf991ea4e}\InProcServer32@ C:\Windows\System32\ieframe.dll (Internet Browser/Microsoft Corporation SIGNED)(2013-12-13 11:08:39) Reg HKLM\SOFTWARE\Classes\CLSID\{9A36D318-A470-11D6-9500-00065B874123}\InProcServer32@ C:\Program Files\Common Files\Microsoft Shared\OFFICE11\MSSOAP30.DLL (Microsoft Office Soap SDK/Microsoft Corporation)(2002-12-06 12:25:10) Reg HKLM\SOFTWARE\Classes\CLSID\{9A3A64F4-8BA5-3DCF-880C-8D3EE06C5538}\InprocServer32@ C:\Windows\system32\mscoree.dll (Microsoft .NET Runtime Execution Engine/Microsoft Corporation SIGNED)(2013-09-25 17:38:26) Reg HKLM\SOFTWARE\Classes\CLSID\{9A5EA990-3034-4D6F-9128-01F3C61022BC}\InprocServer32@ C:\Windows\System32\gameux.dll (Games Explorer/Microsoft Corporation SIGNED)(2013-09-25 17:37:46) Reg HKLM\SOFTWARE\Classes\CLSID\{9A944885-EDAF-3A81-A2FF-6A9D5D1ABFC7}\InprocServer32@ C:\Windows\system32\mscoree.dll (Microsoft .NET Runtime Execution Engine/Microsoft Corporation SIGNED)(2013-09-25 17:38:26) Reg HKLM\SOFTWARE\Classes\CLSID\{9a97f12a-6b73-4dc4-b3c1-e9244c03adac}\InProcServer32@ C:\Windows\system32\shell32.dll (Windows Shell Common Dll/Microsoft Corporation SIGNED)(2013-09-26 18:21:44) Reg HKLM\SOFTWARE\Classes\CLSID\{9B0EFD60-F7B0-11D0-BAEF-00C04FC308C9}\InprocServer32@ C:\Windows\System32\ieframe.dll (Internet Browser/Microsoft Corporation SIGNED)(2013-12-13 11:08:39) Reg HKLM\SOFTWARE\Classes\CLSID\{9B924EC5-BF13-3A98-8AC0-80877995D403}\InprocServer32@ C:\Windows\system32\mscoree.dll (Microsoft .NET Runtime Execution Engine/Microsoft Corporation SIGNED)(2013-09-25 17:38:26) Reg HKLM\SOFTWARE\Classes\CLSID\{9BA05971-F6A8-11CF-A442-00A0C90A8F39}\InProcServer32@ C:\Windows\system32\shell32.dll (Windows Shell Common Dll/Microsoft Corporation SIGNED)(2013-09-26 18:21:44) Reg HKLM\SOFTWARE\Classes\CLSID\{9BCE6E2B-116B-420F-928B-5356D1629979}\InProcServer32@ C:\Windows\System32\recovery.dll (Recovery Control Panel/Microsoft Corporation SIGNED)(2013-09-25 17:38:04) Reg HKLM\SOFTWARE\Classes\CLSID\{9BF86F6E-B0E1-348B-9627-6970672EB3D3}\InprocServer32@ C:\Windows\system32\mscoree.dll (Microsoft .NET Runtime Execution Engine/Microsoft Corporation SIGNED)(2013-09-25 17:38:26) Reg HKLM\SOFTWARE\Classes\CLSID\{9c7a1728-b694-427a-94a2-a1b2c60f0360}\InProcServer32@ C:\Windows\System32\ieframe.dll (Internet Browser/Microsoft Corporation SIGNED)(2013-12-13 11:08:39) Reg HKLM\SOFTWARE\Classes\CLSID\{9cfc2df3-6ba3-46ef-a836-e519e81f0ec4}\InProcServer32@ C:\Windows\system32\propsys.dll (Microsoft Property System/Microsoft Corporation SIGNED)(2013-09-25 17:38:03) Reg HKLM\SOFTWARE\Classes\CLSID\{9cfc6d75-e648-47a8-9ea0-fb0907558952}\InprocServer32@ C:\Windows\system32\msdtcuiu.dll (Microsoft Distributed Transaction Coordinator Administrative DLL/Microsoft Corporation SIGNED)(2009-07-13 23:44:10) Reg HKLM\SOFTWARE\Classes\CLSID\{9d1b93f1-2e5f-4fdb-a95b-dad8d47e28d8}\InprocServer32@ C:\Windows\system32\RPCNDFP.dll (RPC NDF Helper Class/Microsoft SIGNED)(2009-07-13 23:43:48) Reg HKLM\SOFTWARE\Classes\CLSID\{9D309F77-4655-372E-84B0-B0FB4030F3B8}\InprocServer32@ C:\Windows\system32\mscoree.dll (Microsoft .NET Runtime Execution Engine/Microsoft Corporation SIGNED)(2013-09-25 17:38:26) Reg HKLM\SOFTWARE\Classes\CLSID\{9D745ED8-C514-4D1D-BF42-751FED2D5AC7}\InprocServer32@ C:\Windows\system32\FirewallAPI.dll (Windows Firewall API/Microsoft Corporation SIGNED)(2009-07-13 23:53:14) Reg HKLM\SOFTWARE\Classes\CLSID\{9D958C62-3954-4b44-8FAB-C4670C1DB4C2}\InProcServer32@ C:\Windows\System32\ieframe.dll (Internet Browser/Microsoft Corporation SIGNED)(2013-12-13 11:08:39) Reg HKLM\SOFTWARE\Classes\CLSID\{9DA2F8B8-59F0-3852-B509-0663E3BF643B}\InprocServer32@ C:\Windows\system32\mscoree.dll (Microsoft .NET Runtime Execution Engine/Microsoft Corporation SIGNED)(2013-09-25 17:38:26) Reg HKLM\SOFTWARE\Classes\CLSID\{9DBA709C-B3E1-4013-95B7-5ED33A2E8561}\InprocServer32@ C:\Windows\System32\audioses.dll (Audio Session/Microsoft Corporation SIGNED)(2013-09-25 17:36:17) Reg HKLM\SOFTWARE\Classes\CLSID\{9DBD2C50-62AD-11d0-B806-00C04FD706EC}\InProcServer32@ C:\Windows\system32\shell32.dll (Windows Shell Common Dll/Microsoft Corporation SIGNED)(2013-09-26 18:21:44) Reg HKLM\SOFTWARE\Classes\CLSID\{9E175B8A-F52A-11D8-B9A5-505054503030}\InprocServer32@ C:\Windows\system32\tquery.dll (tquery.dll/Microsoft Corporation SIGNED)(2013-09-25 17:37:02) Reg HKLM\SOFTWARE\Classes\CLSID\{9E28EF95-9C6F-3A00-B525-36A76178CC9C}\InprocServer32@ C:\Windows\system32\mscoree.dll (Microsoft .NET Runtime Execution Engine/Microsoft Corporation SIGNED)(2013-09-25 17:38:26) Reg HKLM\SOFTWARE\Classes\CLSID\{9EBB177D-0161-4e2c-81B0-E15D586CFC9F}\InProcServer32@ C:\Windows\System32\recovery.dll (Recovery Control Panel/Microsoft Corporation SIGNED)(2013-09-25 17:38:04) Reg HKLM\SOFTWARE\Classes\CLSID\{9F36C194-166C-4cbf-B7EA-BF039F950172}\InProcServer32@ C:\Windows\System32\provsvc.dll (Windows HomeGroup/Microsoft Corporation SIGNED)(2013-09-25 17:37:30) Reg HKLM\SOFTWARE\Classes\CLSID\{9FAE1230-74AC-4e33-B59C-4051BBEB0803}\InProcServer32@ C:\Windows\System32\ieframe.dll (Internet Browser/Microsoft Corporation SIGNED)(2013-12-13 11:08:39) Reg HKLM\SOFTWARE\Classes\CLSID\{9FE63AFD-59CF-4419-9775-ABCC3849F861}@InfoTip C:\Windows\System32\recovery.dll (Recovery Control Panel/Microsoft Corporation SIGNED)(2013-09-25 17:38:04) Reg HKLM\SOFTWARE\Classes\CLSID\{a07034fd-6caa-4954-ac3f-97a27216f98a}\InProcServer32@ C:\Windows\system32\shell32.dll (Windows Shell Common Dll/Microsoft Corporation SIGNED)(2013-09-26 18:21:44) Reg HKLM\SOFTWARE\Classes\CLSID\{A0A7A57B-59B2-4919-A694-ADD0A526C373}\InprocServer32@ C:\Windows\System32\evr.dll (Enhanced Video Renderer DLL/Microsoft Corporation SIGNED)(2013-09-25 17:38:17) Reg HKLM\SOFTWARE\Classes\CLSID\{A0E2E749-63CE-3651-8F4F-F5F996344C32}\InprocServer32@ C:\Windows\system32\mscoree.dll (Microsoft .NET Runtime Execution Engine/Microsoft Corporation SIGNED)(2013-09-25 17:38:26) Reg HKLM\SOFTWARE\Classes\CLSID\{A1230201-1439-4E62-A414-190D0AC3D40E}\InProcServer32@ C:\Windows\system32\mstscax.dll (Remote Desktop Services ActiveX Client/Microsoft Corporation SIGNED)(2013-09-25 08:15:19) Reg HKLM\SOFTWARE\Classes\CLSID\{A138CF39-2CAE-42c2-ADB3-022658D79F2F}\InprocServer32@ C:\Windows\system32\MSCorEE.dll (Microsoft .NET Runtime Execution Engine/Microsoft Corporation SIGNED)(2013-09-25 17:38:26) Reg HKLM\SOFTWARE\Classes\CLSID\{a2a9545d-a0c2-42b4-9708-a0b2badd77c8}\InProcServer32@ C:\Windows\system32\shell32.dll (Windows Shell Common Dll/Microsoft Corporation SIGNED)(2013-09-26 18:21:44) Reg HKLM\SOFTWARE\Classes\CLSID\{A2D75874-6750-4931-94C1-C99D3BC9D0C7}@LocalizedString C:\Program Files\Windows Defender\MsMpRes.dll (Windows Defender Resource Module/Microsoft Corporation SIGNED)(2009-07-13 23:37:21) Reg HKLM\SOFTWARE\Classes\CLSID\{A36738B5-FA8F-3316-A929-68099A32B43B}\InprocServer32@ C:\Windows\system32\mscoree.dll (Microsoft .NET Runtime Execution Engine/Microsoft Corporation SIGNED)(2013-09-25 17:38:26) Reg HKLM\SOFTWARE\Classes\CLSID\{A3DD4F92-658A-410F-84FD-6FBBBEF2FFFE}@InfoTip C:\Windows\System32\inetcpl.cpl (Internet Control Panel/Microsoft Corporation SIGNED)(2013-12-13 11:08:41) Reg HKLM\SOFTWARE\Classes\CLSID\{A3ECBC41-581A-4476-B693-A63340462D8B}\InprocServer32@ C:\Windows\system32\quartz.dll (DirectShow Runtime./Microsoft Corporation SIGNED)(2013-09-25 08:10:55) Reg HKLM\SOFTWARE\Classes\CLSID\{a41a4187-5a86-4e26-b40a-856f9035d9cb}\InprocServer32@ C:\Windows\system32\mstscax.dll (Remote Desktop Services ActiveX Client/Microsoft Corporation SIGNED)(2013-09-25 08:15:19) Reg HKLM\SOFTWARE\Classes\CLSID\{a42c2ccb-67d3-46fa-abe6-7d2f3488c7a3}@DisplayName C:\Windows\system32\shell32.dll (Windows Shell Common Dll/Microsoft Corporation SIGNED)(2013-09-26 18:21:44) Reg HKLM\SOFTWARE\Classes\CLSID\{A4B544A1-438D-4B41-9325-869523E2D6C7}\InProcServer32@ C:\Windows\System32\msctf.dll (MSCTF Server DLL/Microsoft Corporation SIGNED)(2009-07-13 23:28:05) Reg HKLM\SOFTWARE\Classes\CLSID\{a4c31131-ff70-4984-afd6-0609ced53ad6}@LocalizedString C:\Windows\system32\shell32.dll (Windows Shell Common Dll/Microsoft Corporation SIGNED)(2013-09-26 18:21:44) Reg HKLM\SOFTWARE\Classes\CLSID\{A4E118DF-B9E5-4B42-888C-065CEAF8DDC3}@LocalizedString C:\Windows\ehome\ehres.dll (Media Center Resources/Microsoft Corporation SIGNED)(2009-07-14 00:11:14) Reg HKLM\SOFTWARE\Classes\CLSID\{a542e116-8088-4146-a352-b0d06e7f6af6}\InProcServer32@ C:\Windows\system32\explorerframe.dll (ExplorerFrame/Microsoft Corporation SIGNED)(2013-09-25 17:38:17) Reg HKLM\SOFTWARE\Classes\CLSID\{A5448B7A-AA07-3C56-B42B-7D881FA10934}\InprocServer32@ C:\Windows\system32\mscoree.dll (Microsoft .NET Runtime Execution Engine/Microsoft Corporation SIGNED)(2013-09-25 17:38:26) Reg HKLM\SOFTWARE\Classes\CLSID\{a5a3563a-5755-4a6f-854e-afa3230b199f}\InProcServer32@ C:\Windows\system32\shell32.dll (Windows Shell Common Dll/Microsoft Corporation SIGNED)(2013-09-26 18:21:44) Reg HKLM\SOFTWARE\Classes\CLSID\{A6207B2E-7CDD-426A-951E-5E1CBC5AFEAD}\InProcServer32@ C:\Windows\system32\FirewallAPI.dll (Windows Firewall API/Microsoft Corporation SIGNED)(2009-07-13 23:53:14) Reg HKLM\SOFTWARE\Classes\CLSID\{A6673C32-3943-3BBB-B476-C09A0EC0BCD6}\InprocServer32@ C:\Windows\system32\mscoree.dll (Microsoft .NET Runtime Execution Engine/Microsoft Corporation SIGNED)(2013-09-25 17:38:26) Reg HKLM\SOFTWARE\Classes\CLSID\{a671c915-d95d-4135-b2c3-089356ca694f}\InprocServer32@ C:\Windows\system32\nlahc.dll (NLA Helper Classes/Microsoft Corporation SIGNED)(2009-07-13 23:52:51) Reg HKLM\SOFTWARE\Classes\CLSID\{a6914418-134b-4bb8-8e3d-7fef7f456caf}\InprocServer32@ C:\Windows\system32\RasDiag.dll (RAS Diagnostics Helper Classes/Microsoft Corporation SIGNED)(2009-07-13 23:52:44) Reg HKLM\SOFTWARE\Classes\CLSID\{A6A3E580-083F-471b-8F08-87D34F678C95}\InprocServer32@ C:\Windows\system32\sysmain.dll (Superfetch Service Host/Microsoft Corporation SIGNED)(2013-09-25 17:37:38) Reg HKLM\SOFTWARE\Classes\CLSID\{A6B222AB-A5EA-4899-B230-084657EDDC7D}\InProcServer32@ C:\Windows\System32\ieframe.dll (Internet Browser/Microsoft Corporation SIGNED)(2013-12-13 11:08:39) Reg HKLM\SOFTWARE\Classes\CLSID\{A7136BDF-B141-3913-9D1C-9BC5AFF21470}\InprocServer32@ C:\Windows\system32\mscoree.dll (Microsoft .NET Runtime Execution Engine/Microsoft Corporation SIGNED)(2013-09-25 17:38:26) Reg HKLM\SOFTWARE\Classes\CLSID\{a76de978-f3eb-4a4f-9f99-304ad619e2ab}\InProcServer32@ C:\Windows\system32\shell32.dll (Windows Shell Common Dll/Microsoft Corporation SIGNED)(2013-09-26 18:21:44) Reg HKLM\SOFTWARE\Classes\CLSID\{A7EDDCB5-6043-3988-921C-25E3DEE6322B}\InprocServer32@ C:\Windows\system32\mscoree.dll (Microsoft .NET Runtime Execution Engine/Microsoft Corporation SIGNED)(2013-09-25 17:38:26) Reg HKLM\SOFTWARE\Classes\CLSID\{A888DF60-1E90-11CF-AC98-00AA004C0FA9}\InprocServer32@ C:\Windows\system32\quartz.dll (DirectShow Runtime./Microsoft Corporation SIGNED)(2013-09-25 08:10:55) Reg HKLM\SOFTWARE\Classes\CLSID\{A8D058C4-D923-3859-9490-D3888FC90439}\InprocServer32@ C:\Windows\system32\mscoree.dll (Microsoft .NET Runtime Execution Engine/Microsoft Corporation SIGNED)(2013-09-25 17:38:26) Reg HKLM\SOFTWARE\Classes\CLSID\{A8DFB9A0-8A20-479F-B538-9387C5EEBA2B}\InprocServer32@ C:\Windows\system32\quartz.dll (DirectShow Runtime./Microsoft Corporation SIGNED)(2013-09-25 08:10:55) Reg HKLM\SOFTWARE\Classes\CLSID\{A8E64375-B645-4314-9EFC-C085981786FA}\InProcServer32@ C:\Windows\system32\shell32.dll (Windows Shell Common Dll/Microsoft Corporation SIGNED)(2013-09-26 18:21:44) Reg HKLM\SOFTWARE\Classes\CLSID\{A8F03BE3-EDB7-4972-821F-AF6F8EA34884}\InprocServer32@ C:\Windows\system32\mscoree.dll (Microsoft .NET Runtime Execution Engine/Microsoft Corporation SIGNED)(2013-09-25 17:38:26) Reg HKLM\SOFTWARE\Classes\CLSID\{A907657F-6FDF-11D0-8EFB-00C04FD912B2}\InProcServer32@ C:\Windows\system32\tcpipcfg.dll (Network Configuration Objects/Microsoft Corporation SIGNED)(2013-09-25 17:38:15) Reg HKLM\SOFTWARE\Classes\CLSID\{A9397D66-3ED3-11D1-8D99-00C04FC2E0C7}\InprocServer32@ C:\Windows\system32\clbcatq.dll (COM+ Configuration Catalog/Microsoft Corporation SIGNED)(2009-07-13 23:44:44) Reg HKLM\SOFTWARE\Classes\CLSID\{A9B48EAC-3ED8-11d2-8216-00C04FB687DA}\InProcServer32@ C:\Windows\System32\DATACLEN.DLL (Disk Space Cleaner for Windows/Microsoft Corporation SIGNED)(2009-07-13 23:40:20) Reg HKLM\SOFTWARE\Classes\CLSID\{A9CF0EAE-901A-4739-A481-E35B73E47F6D}\InProcServer32@ C:\Windows\system32\shell32.dll (Windows Shell Common Dll/Microsoft Corporation SIGNED)(2013-09-26 18:21:44) Reg HKLM\SOFTWARE\Classes\CLSID\{a9d7038d-b5ed-472e-9c47-94bea90a5910}\InprocServer32@ C:\Windows\system32\mstscax.dll (Remote Desktop Services ActiveX Client/Microsoft Corporation SIGNED)(2013-09-25 08:15:19) Reg HKLM\SOFTWARE\Classes\CLSID\{AA000926-FFBE-11CF-8800-00A0C903B83C}\InprocServer32@ C:\Windows\system32\certcli.dll (Microsoft� Active Directory Certificate Services Client/Microsoft Corporation SIGNED)(2013-09-25 17:38:23) Reg HKLM\SOFTWARE\Classes\CLSID\{aa28fbc7-59f1-4c42-9fd8-ba2be27ea319}\InProcServer32@ C:\Windows\system32\shell32.dll (Windows Shell Common Dll/Microsoft Corporation SIGNED)(2013-09-26 18:21:44) Reg HKLM\SOFTWARE\Classes\CLSID\{AA544D41-28CB-11D3-BD22-0000F80849BD}\InprocServer32@ C:\Windows\system32\mscoree.dll (Microsoft .NET Runtime Execution Engine/Microsoft Corporation SIGNED)(2013-09-25 17:38:26) Reg HKLM\SOFTWARE\Classes\CLSID\{AABE54D4-6E88-4c46-A6B3-1DF790DD6E0D}\InProcServer32@ C:\Windows\system32\shell32.dll (Windows Shell Common Dll/Microsoft Corporation SIGNED)(2013-09-26 18:21:44) Reg HKLM\SOFTWARE\Classes\CLSID\{AAC2B978-266D-48ae-AA28-60A3EBB872D0}\InProcServer32@ C:\Windows\System32\ieframe.dll (Internet Browser/Microsoft Corporation SIGNED)(2013-12-13 11:08:39) Reg HKLM\SOFTWARE\Classes\CLSID\{AAD4BDD3-81AA-3ABC-B53B-D904D25BC01E}\InprocServer32@ C:\Windows\system32\mscoree.dll (Microsoft .NET Runtime Execution Engine/Microsoft Corporation SIGNED)(2013-09-25 17:38:26) Reg HKLM\SOFTWARE\Classes\CLSID\{ab0b37ec-56f6-4a0e-a8fd-7a8bf7c2da96}\InProcServer32@ C:\Windows\system32\explorerframe.dll (ExplorerFrame/Microsoft Corporation SIGNED)(2013-09-25 17:38:17) Reg HKLM\SOFTWARE\Classes\CLSID\{AB517586-73CF-489c-8D8C-5AE0EAD0613A}\InProcServer32@ C:\Windows\system32\shell32.dll (Windows Shell Common Dll/Microsoft Corporation SIGNED)(2013-09-26 18:21:44) Reg HKLM\SOFTWARE\Classes\CLSID\{AB558A90-77EC-3C9A-A7E3-7B2260890A84}\InprocServer32@ C:\Windows\system32\mscoree.dll (Microsoft .NET Runtime Execution Engine/Microsoft Corporation SIGNED)(2013-09-25 17:38:26) Reg HKLM\SOFTWARE\Classes\CLSID\{AB944620-79C6-11D1-88F9-0080C7D771BF}\InprocServer32@ C:\Windows\system32\es.dll (COM+/Microsoft Corporation SIGNED)(2009-07-13 23:44:38) Reg HKLM\SOFTWARE\Classes\CLSID\{ACE52D03-E5CD-4b20-82FF-E71B11BEAE1D}\InProcServer32@ C:\Windows\System32\ieframe.dll (Internet Browser/Microsoft Corporation SIGNED)(2013-12-13 11:08:39) Reg HKLM\SOFTWARE\Classes\CLSID\{ace575fd-1fcf-4074-9401-ebab990fa9de}\InprocServer32@ C:\Windows\system32\mstscax.dll (Remote Desktop Services ActiveX Client/Microsoft Corporation SIGNED)(2013-09-25 08:15:19) Reg HKLM\SOFTWARE\Classes\CLSID\{AD326409-BF80-3E0C-BA6F-EE2C33B675A5}\InprocServer32@ C:\Windows\system32\mscoree.dll (Microsoft .NET Runtime Execution Engine/Microsoft Corporation SIGNED)(2013-09-25 17:38:26) Reg HKLM\SOFTWARE\Classes\CLSID\{ad974ae2-e292-4083-a280-0342d68daf55}\InProcServer32@ C:\Windows\system32\shell32.dll (Windows Shell Common Dll/Microsoft Corporation SIGNED)(2013-09-26 18:21:44) Reg HKLM\SOFTWARE\Classes\CLSID\{ADAB9B51-4CDD-4af0-892C-AB7FA7B3293F}\InProcServer32@ C:\Windows\System32\gpsvc.dll (Group Policy Client/Microsoft Corporation SIGNED)(2013-09-25 17:36:25) Reg HKLM\SOFTWARE\Classes\CLSID\{ADBE6DEC-9B04-4A3D-A09C-4BB38EF1351C}\LocalServer32@ C:\Windows\System32\PresentationHost.exe (Windows Presentation Foundation Host/Microsoft Corporation SIGNED)(2013-09-25 17:37:30) Reg HKLM\SOFTWARE\Classes\CLSID\{AE054212-3535-4430-83ED-D501AA6680E6}\InProcServer32@ C:\Windows\system32\explorerframe.dll (ExplorerFrame/Microsoft Corporation SIGNED)(2013-09-25 17:38:17) Reg HKLM\SOFTWARE\Classes\CLSID\{ae2079d8-d764-4d79-ab4d-3543847a1a2c}\InProcServer32@ C:\Windows\System32\recovery.dll (Recovery Control Panel/Microsoft Corporation SIGNED)(2013-09-25 17:38:04) Reg HKLM\SOFTWARE\Classes\CLSID\{AE24FDAE-03C6-11D1-8B76-0080C744F389}\InProcServer32@ C:\Windows\System32\mshtml.dll (Microsoft (R) HTML Viewer/Microsoft Corporation SIGNED)(2013-12-13 11:08:38) Reg HKLM\SOFTWARE\Classes\CLSID\{AE53ED01-CAB4-39CE-854A-8BF544EEEC35}\InprocServer32@ C:\Windows\system32\mscoree.dll (Microsoft .NET Runtime Execution Engine/Microsoft Corporation SIGNED)(2013-09-25 17:38:26) Reg HKLM\SOFTWARE\Classes\CLSID\{AEE3E4A8-EF01-4024-A0F1-809D9B096E14}\LocalServer32@ C:\Program Files\Windows Media Player\WMPEnc.exe (Windows Media Player Encoder Helper/Microsoft Corporation SIGNED)(2009-07-14 00:09:10) Reg HKLM\SOFTWARE\Classes\CLSID\{AF02484C-A0A9-4669-9051-058AB12B9195}\InProcServer32@ C:\Windows\System32\comdlg32.dll (Common Dialogs DLL/Microsoft Corporation SIGNED)(2013-09-25 17:37:51) Reg HKLM\SOFTWARE\Classes\CLSID\{AF4F6510-F982-11d0-8595-00AA004CD6D8}\InProcServer32@ C:\Windows\system32\shell32.dll (Windows Shell Common Dll/Microsoft Corporation SIGNED)(2013-09-26 18:21:44) Reg HKLM\SOFTWARE\Classes\CLSID\{AF60343F-6C7B-3761-839F-0C44E3CA06DA}\InprocServer32@ C:\Windows\system32\mscoree.dll (Microsoft .NET Runtime Execution Engine/Microsoft Corporation SIGNED)(2013-09-25 17:38:26) Reg HKLM\SOFTWARE\Classes\CLSID\{AF604EFE-8897-11D1-B944-00A0C90312E1}\InProcServer32@ C:\Windows\system32\explorerframe.dll (ExplorerFrame/Microsoft Corporation SIGNED)(2013-09-25 17:38:17) Reg HKLM\SOFTWARE\Classes\CLSID\{AF8C5F8A-9999-3E92-BB41-C5F4955174CD}\InprocServer32@ C:\Windows\system32\mscoree.dll (Microsoft .NET Runtime Execution Engine/Microsoft Corporation SIGNED)(2013-09-25 17:38:26) Reg HKLM\SOFTWARE\Classes\CLSID\{AF9F2C0D-6B9F-4e32-A94D-A3E235A31BF7}\InProcServer32@ C:\Windows\system32\shell32.dll (Windows Shell Common Dll/Microsoft Corporation SIGNED)(2013-09-26 18:21:44) Reg HKLM\SOFTWARE\Classes\CLSID\{AFAEF10F-1BC4-351F-886A-878A265C1862}\InprocServer32@ C:\Windows\system32\mscoree.dll (Microsoft .NET Runtime Execution Engine/Microsoft Corporation SIGNED)(2013-09-25 17:38:26) Reg HKLM\SOFTWARE\Classes\CLSID\{b040ea9e-3f5e-48c9-bcdc-304e9d02851f}\InprocServer32@ C:\Windows\System32\sdengin2.dll (Microsoft� Windows Backup Engine/Microsoft Corporation SIGNED)(2013-09-25 17:36:51) Reg HKLM\SOFTWARE\Classes\CLSID\{B091E540-83E3-11CF-A713-0020AFD79762}\InProcServer32@ C:\Windows\system32\shell32.dll (Windows Shell Common Dll/Microsoft Corporation SIGNED)(2013-09-26 18:21:44) Reg HKLM\SOFTWARE\Classes\CLSID\{B0DDD260-9E44-4bf2-8602-6D9CE1D0B94F}\InprocServer32@ C:\Windows\system32\ucmhc.dll (UCM Helper Class/Microsoft Corporation SIGNED)(2009-07-13 23:52:44) Reg HKLM\SOFTWARE\Classes\CLSID\{B0F64827-79BB-3163-B1AB-A2EA0E1FDA23}\InprocServer32@ C:\Windows\system32\mscoree.dll (Microsoft .NET Runtime Execution Engine/Microsoft Corporation SIGNED)(2013-09-25 17:38:26) Reg HKLM\SOFTWARE\Classes\CLSID\{b11d16d0-e195-4ca6-bbd5-1254ec098953}\InProcServer32@ C:\Windows\system32\netcorehc.dll (Networking Core Diagnostics Helper Classes/Microsoft Corporation SIGNED)(2009-07-13 23:52:44) Reg HKLM\SOFTWARE\Classes\CLSID\{B15B8DC0-C7E1-11d0-8680-00AA00BDCB71}\InprocServer32@ C:\Windows\system32\urlmon.dll (OLE32 Extensions for Win32/Microsoft Corporation SIGNED)(2013-12-13 11:08:41) Reg HKLM\SOFTWARE\Classes\CLSID\{B196B286-BAB4-101A-B69C-00AA00341D07}\InprocServer32@ C:\Windows\system32\oleaut32.dll (Microsoft Corporation SIGNED)(2013-09-25 08:15:54) Reg HKLM\SOFTWARE\Classes\CLSID\{B29D466A-857D-35BA-8712-A758861BFEA1}\InprocServer32@ C:\Windows\System32\mscoree.dll (Microsoft .NET Runtime Execution Engine/Microsoft Corporation SIGNED)(2013-09-25 17:38:26) Reg HKLM\SOFTWARE\Classes\CLSID\{b2b4fb61-d2dd-4ddd-8001-20f98c6577ef}\InProcServer32@ C:\Windows\system32\shell32.dll (Windows Shell Common Dll/Microsoft Corporation SIGNED)(2013-09-26 18:21:44) Reg HKLM\SOFTWARE\Classes\CLSID\{B31C5FAE-961F-415b-BAF0-E697A5178B94}\InProcServer32@ C:\Windows\System32\ieframe.dll (Internet Browser/Microsoft Corporation SIGNED)(2013-12-13 11:08:39) Reg HKLM\SOFTWARE\Classes\CLSID\{B33F0D7A-1571-4022-B710-D26E9B87DEB8}\InProcServer32@ C:\Windows\system32\shell32.dll (Windows Shell Common Dll/Microsoft Corporation SIGNED)(2013-09-26 18:21:44) Reg HKLM\SOFTWARE\Classes\CLSID\{B3FF88A4-96EC-4CC1-983F-72BE0EBB368B}\InprocServer32@ C:\Windows\System32\gpsvc.dll (Group Policy Client/Microsoft Corporation SIGNED)(2013-09-25 17:36:25) Reg HKLM\SOFTWARE\Classes\CLSID\{B406AC70-4D7E-3D24-B241-AEAEAC343BD9}\InprocServer32@ C:\Windows\system32\mscoree.dll (Microsoft .NET Runtime Execution Engine/Microsoft Corporation SIGNED)(2013-09-25 17:38:26) Reg HKLM\SOFTWARE\Classes\CLSID\{B475F925-E3F7-414C-8C72-1CEE64B9D8F6}\InProcServer32@ C:\Windows\System32\QAgent.dll (Quarantine Agent Proxy/Microsoft Corporation SIGNED)(2013-09-25 17:38:03) Reg HKLM\SOFTWARE\Classes\CLSID\{B4B3AECB-DFD6-11d1-9DAA-00805F85CFE3}\InprocServer32@ C:\Windows\system32\clbcatq.dll (COM+ Configuration Catalog/Microsoft Corporation SIGNED)(2009-07-13 23:44:44) Reg HKLM\SOFTWARE\Classes\CLSID\{B4FB3F98-C1EA-428d-A78A-D1F5659CBA93}@LocalizedString C:\Windows\system32\shell32.dll (Windows Shell Common Dll/Microsoft Corporation SIGNED)(2013-09-26 18:21:44) Reg HKLM\SOFTWARE\Classes\CLSID\{B54E38F8-17FF-3D0A-9FF3-5E662DE2055F}\InprocServer32@ C:\Windows\system32\mscoree.dll (Microsoft .NET Runtime Execution Engine/Microsoft Corporation SIGNED)(2013-09-25 17:38:26) Reg HKLM\SOFTWARE\Classes\CLSID\{B5607793-24AC-44c7-82E2-831726AA6CB7}\InProcServer32@ C:\Windows\system32\shell32.dll (Windows Shell Common Dll/Microsoft Corporation SIGNED)(2013-09-26 18:21:44) Reg HKLM\SOFTWARE\Classes\CLSID\{b5866878-bd99-11d0-b04b-00c04fd91550}\InprocServer32@ C:\Windows\system32\rpcrt4.dll (Remote Procedure Call Runtime/Microsoft Corporation SIGNED)(2013-09-26 18:24:52) Reg HKLM\SOFTWARE\Classes\CLSID\{B6EB52D5-BB1C-3380-8BCA-345FF43F4B04}\InprocServer32@ C:\Windows\system32\mscoree.dll (Microsoft .NET Runtime Execution Engine/Microsoft Corporation SIGNED)(2013-09-25 17:38:26) Reg HKLM\SOFTWARE\Classes\CLSID\{B76AD54C-51A2-4230-B516-2CCAA95F8D29}\InProcServer32@ C:\Windows\system32\shell32.dll (Windows Shell Common Dll/Microsoft Corporation SIGNED)(2013-09-26 18:21:44) Reg HKLM\SOFTWARE\Classes\CLSID\{B801CA65-A1FC-11D0-85AD-444553540000}\InprocHandler32@ C:\Windows\system32\ole32.dll (Microsoft OLE for Windows/Microsoft Corporation SIGNED)(2013-09-25 17:36:42) Reg HKLM\SOFTWARE\Classes\CLSID\{B801CA65-A1FC-11D0-85AD-444553540000}\LocalServer32@ C:\Program Files\Adobe\Reader 11.0\Reader\AcroRd32.exe (Adobe Reader /CA SIGNED)(2013-12-21 06:04:26) Reg HKLM\SOFTWARE\Classes\CLSID\{B80AB0A0-7416-11D2-9EEB-006008039E37}\InprocServer32@ C:\Windows\system32\quartz.dll (DirectShow Runtime./Microsoft Corporation SIGNED)(2013-09-25 08:10:55) Reg HKLM\SOFTWARE\Classes\CLSID\{B81CB5ED-E654-399F-9698-C83C50665786}\InprocServer32@ C:\Windows\system32\mscoree.dll (Microsoft .NET Runtime Execution Engine/Microsoft Corporation SIGNED)(2013-09-25 17:38:26) Reg HKLM\SOFTWARE\Classes\CLSID\{B87BEB7B-8D29-423F-AE4D-6582C10175AC}\InprocServer32@ C:\Windows\system32\quartz.dll (DirectShow Runtime./Microsoft Corporation SIGNED)(2013-09-25 08:10:55) Reg HKLM\SOFTWARE\Classes\CLSID\{b8967f85-58ae-4f46-9fb2-5d7904798f4b}\InProcServer32@ C:\Windows\system32\propsys.dll (Microsoft Property System/Microsoft Corporation SIGNED)(2013-09-25 17:38:03) Reg HKLM\SOFTWARE\Classes\CLSID\{B8D37BFF-FD04-385C-94E3-C75DF24D582C}\InprocServer32@ C:\Windows\system32\mscoree.dll (Microsoft .NET Runtime Execution Engine/Microsoft Corporation SIGNED)(2013-09-25 17:38:26) Reg HKLM\SOFTWARE\Classes\CLSID\{b91a4db4-3630-11dc-9eaa-00161718cf63}\InProcServer32@ C:\Windows\system32\shell32.dll (Windows Shell Common Dll/Microsoft Corporation SIGNED)(2013-09-26 18:21:44) Reg HKLM\SOFTWARE\Classes\CLSID\{B9931692-A2B3-4FAB-BF33-9EC6F9FB96AC}\InProcServer32@ C:\Windows\System32\msctf.dll (MSCTF Server DLL/Microsoft Corporation SIGNED)(2009-07-13 23:28:05) Reg HKLM\SOFTWARE\Classes\CLSID\{b9b61a03-caa7-43bb-b859-acd26d73b3f7}\InProcServer32@ C:\Windows\system32\shell32.dll (Windows Shell Common Dll/Microsoft Corporation SIGNED)(2013-09-26 18:21:44) Reg HKLM\SOFTWARE\Classes\CLSID\{BACF5C8A-A3C7-11D1-A760-00C04FB9603F}\InprocServer32@ C:\Windows\System32\appmgr.dll (Software Installation Snapin Extenstion/Microsoft Corporation SIGNED)(2013-09-25 17:37:12) Reg HKLM\SOFTWARE\Classes\CLSID\{BB07BACD-CD56-4E63-A8FF-CBF0355FB9F4}\InprocServer32@ C:\Windows\system32\es.dll (COM+/Microsoft Corporation SIGNED)(2009-07-13 23:44:38) Reg HKLM\SOFTWARE\Classes\CLSID\{BBAC09B1-05A9-4E4F-93BA-1E409D52A268}\InprocHandler32@ C:\Windows\system32\ole32.dll (Microsoft OLE for Windows/Microsoft Corporation SIGNED)(2013-09-25 17:36:42) Reg HKLM\SOFTWARE\Classes\CLSID\{BBC035D1-E5A1-44F5-A166-E70DAED1CB02}\InProcServer32@ C:\Windows\System32\tsworkspace.dll (RemoteApp and Desktop Connection Component/Microsoft Corporation SIGNED)(2013-09-25 17:37:06) Reg HKLM\SOFTWARE\Classes\CLSID\{BC5062B6-79E8-3F19-A87E-F9DAF826960C}\InprocServer32@ C:\Windows\system32\mscoree.dll (Microsoft .NET Runtime Execution Engine/Microsoft Corporation SIGNED)(2013-09-25 17:38:26) Reg HKLM\SOFTWARE\Classes\CLSID\{bd69ecaa-ae5c-40d0-b968-7848f3778f56}\InProcServer32@ C:\Windows\system32\netcorehc.dll (Networking Core Diagnostics Helper Classes/Microsoft Corporation SIGNED)(2009-07-13 23:52:44) Reg HKLM\SOFTWARE\Classes\CLSID\{BD84B380-8CA2-1069-AB1D-08000948F534}@InfoTip C:\Windows\System32\Shell32.dll (Windows Shell Common Dll/Microsoft Corporation SIGNED)(2013-09-26 18:21:44) Reg HKLM\SOFTWARE\Classes\CLSID\{BDA7BEE5-85F1-3B66-B610-DDF1D5898006}\InprocServer32@ C:\Windows\system32\mscoree.dll (Microsoft .NET Runtime Execution Engine/Microsoft Corporation SIGNED)(2013-09-25 17:38:26) Reg HKLM\SOFTWARE\Classes\CLSID\{bde9ee7c-329f-4fcf-ba7a-f8c6e9b4579d}\InProcServer32@ C:\Windows\system32\shell32.dll (Windows Shell Common Dll/Microsoft Corporation SIGNED)(2013-09-26 18:21:44) Reg HKLM\SOFTWARE\Classes\CLSID\{BED4D415-7971-4310-AA07-6AC15EA06ACC}\InprocServer32@ C:\Windows\system32\winethc.dll (WinInet Helper Class/Microsoft Corporation SIGNED)(2009-07-13 23:52:43) Reg HKLM\SOFTWARE\Classes\CLSID\{bf29a3a2-d2bf-4a22-96cc-9aceb0f94cba}\InProcServer32@ C:\Windows\system32\shell32.dll (Windows Shell Common Dll/Microsoft Corporation SIGNED)(2013-09-26 18:21:44) Reg HKLM\SOFTWARE\Classes\CLSID\{bf50b68e-29b8-4386-ae9c-9734d5117cd5}\InProcServer32@ C:\Windows\system32\explorerframe.dll (ExplorerFrame/Microsoft Corporation SIGNED)(2013-09-25 17:38:17) Reg HKLM\SOFTWARE\Classes\CLSID\{bf641d1c-29fd-4721-b3b8-48d92d35f7df}\InProcServer32@ C:\Windows\system32\shell32.dll (Windows Shell Common Dll/Microsoft Corporation SIGNED)(2013-09-26 18:21:44) Reg HKLM\SOFTWARE\Classes\CLSID\{BFAD62EE-9D54-4b2a-BF3B-76F90697BD2A}\InProcServer32@ C:\Windows\System32\ieframe.dll (Internet Browser/Microsoft Corporation SIGNED)(2013-12-13 11:08:39) Reg HKLM\SOFTWARE\Classes\CLSID\{BFFECCA7-4069-49F9-B5AB-7CCBB078ED91}\InprocServer32@ C:\Windows\system32\mscoree.dll (Microsoft .NET Runtime Execution Engine/Microsoft Corporation SIGNED)(2013-09-25 17:38:26) Reg HKLM\SOFTWARE\Classes\CLSID\{C03E8581-781E-49a1-8190-CE902D0B2CE7}\InProcServer32@ C:\Windows\system32\xwizards.dll (Extensible Wizards Manager Module/Microsoft Corporation SIGNED)(2009-07-13 23:51:41) Reg HKLM\SOFTWARE\Classes\CLSID\{c047c5a9-c407-4a1e-ad7f-11d0861344b7}\InprocServer32@ C:\Windows\System32\L2SecHC.dll (Layer 2 Security Diagnostics Helper Classes/Microsoft Corporation SIGNED)(2009-07-13 23:51:54) Reg HKLM\SOFTWARE\Classes\CLSID\{C0A4145B-E627-40E3-AECC-FD392DC9B959}\InProcServer32@ C:\Windows\system32\xwizards.dll (Extensible Wizards Manager Module/Microsoft Corporation SIGNED)(2009-07-13 23:51:41) Reg HKLM\SOFTWARE\Classes\CLSID\{C0B4E2F3-BA21-4773-8DBA-335EC946EB8B}\InProcServer32@ C:\Windows\System32\comdlg32.dll (Common Dialogs DLL/Microsoft Corporation SIGNED)(2013-09-25 17:37:51) Reg HKLM\SOFTWARE\Classes\CLSID\{C0E13E61-0CC6-11d1-BBB6-0060978B2AE6}\InProcServer32@ C:\Windows\System32\DATACLEN.DLL (Disk Space Cleaner for Windows/Microsoft Corporation SIGNED)(2009-07-13 23:40:20) Reg HKLM\SOFTWARE\Classes\CLSID\{C100BEB7-D33A-4a4b-BF23-BBEF4663D017}\InprocServer32@ C:\Windows\System32\wzcdlg.dll (Windows Connect Now - Flash Config Enrollee/Microsoft Corporation SIGNED)(2009-07-13 23:53:06) Reg HKLM\SOFTWARE\Classes\CLSID\{C100BEEB-D33A-4a4b-BF23-BBEF4663D017}\InProcServer32@ C:\Windows\System32\xwizards.dll (Extensible Wizards Manager Module/Microsoft Corporation SIGNED)(2009-07-13 23:51:41) Reg HKLM\SOFTWARE\Classes\CLSID\{C1060E7E-7939-44A5-99C3-A6DCCD92AED0}\InProcServer32@ C:\Windows\System32\kmsvc.dll (Key Management Service/Microsoft Corporation SIGNED)(2013-09-25 17:38:29) Reg HKLM\SOFTWARE\Classes\CLSID\{C19FBD0E-7663-44ea-8265-74130671A1D6}\InProcServer32@ C:\Windows\system32\shell32.dll (Windows Shell Common Dll/Microsoft Corporation SIGNED)(2013-09-26 18:21:44) Reg HKLM\SOFTWARE\Classes\CLSID\{C1ABB475-F198-39D5-BF8D-330BC7189661}\InprocServer32@ C:\Windows\system32\mscoree.dll (Microsoft .NET Runtime Execution Engine/Microsoft Corporation SIGNED)(2013-09-25 17:38:26) Reg HKLM\SOFTWARE\Classes\CLSID\{c206f324-bb45-4765-93ff-3bca7306ff2e}\InProcServer32@ C:\Windows\system32\shell32.dll (Windows Shell Common Dll/Microsoft Corporation SIGNED)(2013-09-26 18:21:44) Reg HKLM\SOFTWARE\Classes\CLSID\{C21B45B8-5D76-4575-BA27-54823098C491}\InProcServer32@ C:\Windows\System32\ieframe.dll (Internet Browser/Microsoft Corporation SIGNED)(2013-12-13 11:08:39) Reg HKLM\SOFTWARE\Classes\CLSID\{C2566514-DD44-4c6c-AAAD-FBD2F18D8DEE}\InProcServer32@ C:\Windows\system32\propsys.dll (Microsoft Property System/Microsoft Corporation SIGNED)(2013-09-25 17:38:03) Reg HKLM\SOFTWARE\Classes\CLSID\{c278aba7-cc1c-4717-bdfb-db2bca78246e}\InprocServer32@ C:\Windows\system32\Groupinghc.dll (Grouping Helper Class/Microsoft Corporation SIGNED)(2009-07-13 23:55:45) Reg HKLM\SOFTWARE\Classes\CLSID\{C2FBB630-2971-11d1-A18C-00C04FD75D13}\InProcServer32@ C:\Windows\system32\shell32.dll (Windows Shell Common Dll/Microsoft Corporation SIGNED)(2013-09-26 18:21:44) Reg HKLM\SOFTWARE\Classes\CLSID\{C30ABD41-7B5A-3D10-A6EF-56862E2979B6}\InprocServer32@ C:\Windows\system32\mscoree.dll (Microsoft .NET Runtime Execution Engine/Microsoft Corporation SIGNED)(2013-09-25 17:38:26) Reg HKLM\SOFTWARE\Classes\CLSID\{c39ee728-d419-4bd4-a3ef-eda059dbd935}\InprocServer32@ C:\Windows\System32\wininet.dll (Internet Extensions for Win32/Microsoft Corporation SIGNED)(2013-12-13 11:08:42) Reg HKLM\SOFTWARE\Classes\CLSID\{C41D0B30-A518-3093-A18F-364AF9E71EB7}\InprocServer32@ C:\Windows\system32\mscoree.dll (Microsoft .NET Runtime Execution Engine/Microsoft Corporation SIGNED)(2013-09-25 17:38:26) Reg HKLM\SOFTWARE\Classes\CLSID\{c4bbedb4-e9b9-4e41-8fe1-0786480a2173}\InprocServer32@ C:\Windows\system32\RasDiag.dll (RAS Diagnostics Helper Classes/Microsoft Corporation SIGNED)(2009-07-13 23:52:44) Reg HKLM\SOFTWARE\Classes\CLSID\{C4EC38BD-4E9E-4b5e-935A-D1BFF237D980}\InProcServer32@ C:\Windows\system32\explorerframe.dll (ExplorerFrame/Microsoft Corporation SIGNED)(2013-09-25 17:38:17) Reg HKLM\SOFTWARE\Classes\CLSID\{c51b83e5-9edd-4250-b45a-da672ee3c70e}\InProcServer32@ C:\Windows\system32\shell32.dll (Windows Shell Common Dll/Microsoft Corporation SIGNED)(2013-09-26 18:21:44) Reg HKLM\SOFTWARE\Classes\CLSID\{C57D0758-4517-37AB-9C03-7BBA6963C18E}\InprocServer32@ C:\Windows\system32\mscoree.dll (Microsoft .NET Runtime Execution Engine/Microsoft Corporation SIGNED)(2013-09-25 17:38:26) Reg HKLM\SOFTWARE\Classes\CLSID\{c5efd803-50f8-43cd-9ab8-aafc1394c9e0}\InProcServer32@ C:\Windows\System32\ieframe.dll (Internet Browser/Microsoft Corporation SIGNED)(2013-12-13 11:08:39) Reg HKLM\SOFTWARE\Classes\CLSID\{C605507B-9613-4756-9C07-E0D74321CB1E}\InProcServer32@ C:\Windows\System32\provsvc.dll (Windows HomeGroup/Microsoft Corporation SIGNED)(2013-09-25 17:37:30) Reg HKLM\SOFTWARE\Classes\CLSID\{c63382be-7933-48d0-9ac8-85fb46be2fdd}\InProcServer32@ C:\Windows\system32\shell32.dll (Windows Shell Common Dll/Microsoft Corporation SIGNED)(2013-09-26 18:21:44) Reg HKLM\SOFTWARE\Classes\CLSID\{c6cc0d21-895d-49cc-98f1-d208cd71e047}\InProcServer32@ C:\Windows\system32\IERtUtil.dll (Run time utility for Internet Explorer/Microsoft Corporation SIGNED)(2013-12-13 11:08:41) Reg HKLM\SOFTWARE\Classes\CLSID\{C6CC49B0-CE17-11D0-8833-00A0C903B83C}\InprocServer32@ C:\Windows\system32\certcli.dll (Microsoft� Active Directory Certificate Services Client/Microsoft Corporation SIGNED)(2013-09-25 17:38:23) Reg HKLM\SOFTWARE\Classes\CLSID\{C707F6A6-A1F3-45d7-99AA-A2B9491E84AD}\InProcServer32@ C:\Windows\System32\provsvc.dll (Windows HomeGroup/Microsoft Corporation SIGNED)(2013-09-25 17:37:30) Reg HKLM\SOFTWARE\Classes\CLSID\{C76B435D-86C2-30FD-9329-E2603246095C}\InprocServer32@ C:\Windows\system32\mscoree.dll (Microsoft .NET Runtime Execution Engine/Microsoft Corporation SIGNED)(2013-09-25 17:38:26) Reg HKLM\SOFTWARE\Classes\CLSID\{C7CA6167-2F46-4C4C-98B2-C92591368971}\InProcServer32@ C:\Windows\system32\shell32.dll (Windows Shell Common Dll/Microsoft Corporation SIGNED)(2013-09-26 18:21:44) Reg HKLM\SOFTWARE\Classes\CLSID\{C89AC250-E18A-4FC7-ABD5-B8897B6A78A5}\InprocServer32@ C:\Windows\system32\mscoree.dll (Microsoft .NET Runtime Execution Engine/Microsoft Corporation SIGNED)(2013-09-25 17:38:26) Reg HKLM\SOFTWARE\Classes\CLSID\{c89e334c-e65f-4156-842e-ea89cec71dea}\InprocServer32@ C:\Windows\system32\fphc.dll (Filtering Platform Helper Class/Microsoft Corporation SIGNED)(2013-09-25 17:37:45) Reg HKLM\SOFTWARE\Classes\CLSID\{c8c97725-c948-4720-bf0f-e3c2273bfb7d}\InProcServer32@ C:\Windows\system32\shell32.dll (Windows Shell Common Dll/Microsoft Corporation SIGNED)(2013-09-26 18:21:44) Reg HKLM\SOFTWARE\Classes\CLSID\{C9F0A842-3CE1-338F-A1D4-6D7BB397BDAA}\InprocServer32@ C:\Windows\system32\mscoree.dll (Microsoft .NET Runtime Execution Engine/Microsoft Corporation SIGNED)(2013-09-25 17:38:26) Reg HKLM\SOFTWARE\Classes\CLSID\{CA22F5B1-E06F-4A2B-94FC-21E87FE53781}\InprocServer32@ C:\Windows\System32\gameux.dll (Games Explorer/Microsoft Corporation SIGNED)(2013-09-25 17:37:46) Reg HKLM\SOFTWARE\Classes\CLSID\{CA35CB3D-0357-11D3-8729-00C04F79ED0D}\InprocServer32@ C:\Windows\system32\mscoree.dll (Microsoft .NET Runtime Execution Engine/Microsoft Corporation SIGNED)(2013-09-25 17:38:26) Reg HKLM\SOFTWARE\Classes\CLSID\{CB1DFE3A-EDFF-4d1f-867D-8ADB02926F4B}@LocalizedString C:\Windows\system32\shell32.dll (Windows Shell Common Dll/Microsoft Corporation SIGNED)(2013-09-26 18:21:44) Reg HKLM\SOFTWARE\Classes\CLSID\{CB2F6723-AB3A-11d2-9C40-00C04FA30A3E}\InprocServer32@ C:\Windows\system32\mscoree.dll (Microsoft .NET Runtime Execution Engine/Microsoft Corporation SIGNED)(2013-09-25 17:38:26) Reg HKLM\SOFTWARE\Classes\CLSID\{CBD51D89-C22E-4388-A553-FFE638C76E36}\InprocServer32@ C:\Windows\system32\mstscax.dll (Remote Desktop Services ActiveX Client/Microsoft Corporation SIGNED)(2013-09-25 08:15:19) Reg HKLM\SOFTWARE\Classes\CLSID\{CBEAA915-4D2C-3F77-98E8-A258B0FD3CEF}\InprocServer32@ C:\Windows\system32\mscoree.dll (Microsoft .NET Runtime Execution Engine/Microsoft Corporation SIGNED)(2013-09-25 17:38:26) Reg HKLM\SOFTWARE\Classes\CLSID\{CC19079B-8272-4D73-BB70-CDB533527B61}\InprocServer32@ C:\Windows\system32\FirewallAPI.dll (Windows Firewall API/Microsoft Corporation SIGNED)(2009-07-13 23:53:14) Reg HKLM\SOFTWARE\Classes\CLSID\{CC20C6DF-A054-3F09-A5F5-A3B5A25F4CE6}\InprocServer32@ C:\Windows\system32\mscoree.dll (Microsoft .NET Runtime Execution Engine/Microsoft Corporation SIGNED)(2013-09-25 17:38:26) Reg HKLM\SOFTWARE\Classes\CLSID\{CC55EE92-FE67-43C9-95E7-E646918A4A04}\InProcServer32@ C:\Windows\system32\EhStorShell.dll (Windows Enhanced Storage Shell Extension DLL/Microsoft Corporation SIGNED)(2009-07-13 23:45:42) Reg HKLM\SOFTWARE\Classes\CLSID\{CC77F5F3-222D-3586-88C3-410477A3B65D}\InprocServer32@ C:\Windows\system32\mscoree.dll (Microsoft .NET Runtime Execution Engine/Microsoft Corporation SIGNED)(2013-09-25 17:38:26) Reg HKLM\SOFTWARE\Classes\CLSID\{CC785860-B2CA-11CE-8D2B-0000E202599C}\InprocServer32@ C:\Windows\system32\quartz.dll (DirectShow Runtime./Microsoft Corporation SIGNED)(2013-09-25 08:10:55) Reg HKLM\SOFTWARE\Classes\CLSID\{CC957078-B838-47C4-A7CF-626E7A82FC58}\LocalServer32@ C:\Program Files\Skype\Updater\Updater.exe (Skype Updater Service/Skype Technologies SIGNED)(2013-09-05 09:34:30) Reg HKLM\SOFTWARE\Classes\CLSID\{CCF306AE-33BD-3003-9CCE-DAF5BEFEF611}\InprocServer32@ C:\Windows\system32\mscoree.dll (Microsoft .NET Runtime Execution Engine/Microsoft Corporation SIGNED)(2013-09-25 17:38:26) Reg HKLM\SOFTWARE\Classes\CLSID\{cd4b7782-eb37-4bfe-b9ce-685f634a08dc}\InprocServer32@ C:\Windows\System32\sdengin2.dll (Microsoft� Windows Backup Engine/Microsoft Corporation SIGNED)(2013-09-25 17:36:51) Reg HKLM\SOFTWARE\Classes\CLSID\{CD773740-B187-4974-A1D5-E0FF91372277}\InprocServer32@ C:\Windows\System32\audioses.dll (Audio Session/Microsoft Corporation SIGNED)(2013-09-25 17:36:17) Reg HKLM\SOFTWARE\Classes\CLSID\{CDA42200-BD88-11D0-BD4E-00A0C911CE86}\InprocServer32@ C:\Windows\system32\quartz.dll (DirectShow Runtime./Microsoft Corporation SIGNED)(2013-09-25 08:10:55) Reg HKLM\SOFTWARE\Classes\CLSID\{CDBEC9C0-7A68-11D1-88F9-0080C7D771BF}\InprocServer32@ C:\Windows\system32\es.dll (COM+/Microsoft Corporation SIGNED)(2009-07-13 23:44:38) Reg HKLM\SOFTWARE\Classes\CLSID\{cdc32574-7521-4124-90c3-8d5605a34933}\LocalServer32@ C:\Program Files\Windows Media Player\wmplayer.exe (Windows Media Player/Microsoft Corporation SIGNED)(2013-09-25 17:37:02) Reg HKLM\SOFTWARE\Classes\CLSID\{CDC70043-D56B-3799-B7BD-6113BBCA160A}\InprocServer32@ C:\Windows\system32\mscoree.dll (Microsoft .NET Runtime Execution Engine/Microsoft Corporation SIGNED)(2013-09-25 17:38:26) Reg HKLM\SOFTWARE\Classes\CLSID\{CDC82860-468D-4d4e-B7E7-C298FF23AB2C}\InProcServer32@ C:\Windows\system32\shell32.dll (Windows Shell Common Dll/Microsoft Corporation SIGNED)(2013-09-26 18:21:44) Reg HKLM\SOFTWARE\Classes\CLSID\{CDFA7117-B2A4-3A3F-B393-BC19D44F9749}\InprocServer32@ C:\Windows\system32\mscoree.dll (Microsoft .NET Runtime Execution Engine/Microsoft Corporation SIGNED)(2013-09-25 17:38:26) Reg HKLM\SOFTWARE\Classes\CLSID\{ceff45ee-c862-41de-aee2-a022c81eda92}\LocalServer32@ C:\Windows\explorer.exe (Windows Explorer/Microsoft Corporation SIGNED)(2013-09-25 17:37:42) Reg HKLM\SOFTWARE\Classes\CLSID\{CF1BF3B6-7AD0-4410-996B-C78EAFCD3269}\LocalServer32@ C:\Windows\System32\PresentationHost.exe (Windows Presentation Foundation Host/Microsoft Corporation SIGNED)(2013-09-25 17:37:30) Reg HKLM\SOFTWARE\Classes\CLSID\{CF49D4E0-1115-11CE-B03A-0020AF0BA770}\InprocServer32@ C:\Windows\system32\quartz.dll (DirectShow Runtime./Microsoft Corporation SIGNED)(2013-09-25 08:10:55) Reg HKLM\SOFTWARE\Classes\CLSID\{CF8F7FCF-94FE-3516-90E9-C103156DD2D5}\InprocServer32@ C:\Windows\system32\mscoree.dll (Microsoft .NET Runtime Execution Engine/Microsoft Corporation SIGNED)(2013-09-25 17:38:26) Reg HKLM\SOFTWARE\Classes\CLSID\{CFBFAE00-17A6-11D0-99CB-00C04FD64497}\InProcServer32@ C:\Windows\System32\ieframe.dll (Internet Browser/Microsoft Corporation SIGNED)(2013-12-13 11:08:39) Reg HKLM\SOFTWARE\Classes\CLSID\{CFF9990B-6414-43F1-A526-14EA5EEAFBDA}\InProcServer32@ C:\Windows\system32\ntshrui.dll (Shell extensions for sharing/Microsoft Corporation SIGNED)(2013-09-25 17:37:19) Reg HKLM\SOFTWARE\Classes\CLSID\{CFFFA415-7461-3AAD-8EA3-3502A0D15CD4}\InprocServer32@ C:\Windows\system32\mscoree.dll (Microsoft .NET Runtime Execution Engine/Microsoft Corporation SIGNED)(2013-09-25 17:38:26) Reg HKLM\SOFTWARE\Classes\CLSID\{D01B8F28-0BD1-4652-A415-8229F5EE506C}\InProcServer32@ C:\Windows\system32\wercplsupport.dll (Problem Reports and Solutions/Microsoft Corporation SIGNED)(2009-07-13 23:27:26) Reg HKLM\SOFTWARE\Classes\CLSID\{D049DC2B-82C3-3350-A1CC-BF69FEE3825E}\InprocServer32@ C:\Windows\system32\mscoree.dll (Microsoft .NET Runtime Execution Engine/Microsoft Corporation SIGNED)(2013-09-25 17:38:26) Reg HKLM\SOFTWARE\Classes\CLSID\{D0565000-9DF4-11D1-A281-00C04FCA0AA7}\InprocServer32@ C:\Windows\system32\es.dll (COM+/Microsoft Corporation SIGNED)(2009-07-13 23:44:38) Reg HKLM\SOFTWARE\Classes\CLSID\{D13B741D-051F-322F-93AA-1367A3C8AAFB}\InprocServer32@ C:\Windows\system32\mscoree.dll (Microsoft .NET Runtime Execution Engine/Microsoft Corporation SIGNED)(2013-09-25 17:38:26) Reg HKLM\SOFTWARE\Classes\CLSID\{D13E3F25-1688-45A0-9743-759EB35CDF9A}\LocalServer32@ C:\Windows\System32\wiaacmgr.exe (Windows Picture Acquisition Wizard/Microsoft Corporation SIGNED)(2009-07-14 00:15:13) Reg HKLM\SOFTWARE\Classes\CLSID\{D20EA4E1-3957-11d2-A40B-0C5020524153}@InfoTip C:\Windows\system32\shell32.dll (Windows Shell Common Dll/Microsoft Corporation SIGNED)(2013-09-26 18:21:44) Reg HKLM\SOFTWARE\Classes\CLSID\{D212B88E-8365-4CA9-BC4E-CFA4251F6B5F}\InProcServer32@ C:\Windows\system32\ndiscapCfg.dll (NdisCap Notify Object/Microsoft Corporation SIGNED)(2009-07-13 23:52:43) Reg HKLM\SOFTWARE\Classes\CLSID\{D23D2F41-1D69-3E03-A275-32AE381223AC}\InprocServer32@ C:\Windows\system32\mscoree.dll (Microsoft .NET Runtime Execution Engine/Microsoft Corporation SIGNED)(2013-09-25 17:38:26) Reg HKLM\SOFTWARE\Classes\CLSID\{d2ea46a7-c2bf-426b-af24-e19c44456399}\InprocServer32@ C:\Windows\system32\mstscax.dll (Remote Desktop Services ActiveX Client/Microsoft Corporation SIGNED)(2013-09-25 08:15:19) Reg HKLM\SOFTWARE\Classes\CLSID\{D2EAA715-DAC7-4771-AF5C-931611A1853C}\InprocServer32@ C:\Windows\system32\mscoree.dll (Microsoft .NET Runtime Execution Engine/Microsoft Corporation SIGNED)(2013-09-25 17:38:26) Reg HKLM\SOFTWARE\Classes\CLSID\{D3588AB0-0781-11CE-B03A-0020AF0BA770}\InprocServer32@ C:\Windows\system32\quartz.dll (DirectShow Runtime./Microsoft Corporation SIGNED)(2013-09-25 08:10:55) Reg HKLM\SOFTWARE\Classes\CLSID\{D3E34B21-9D75-101A-8C3D-00AA001A1652}@LocalizedString C:\Windows\system32\mspaint.exe (Paint/Microsoft Corporation SIGNED)(2009-07-13 23:43:12) Reg HKLM\SOFTWARE\Classes\CLSID\{D3E34B21-9D75-101A-8C3D-00AA001A1652}\InProcHandler32@ C:\Windows\system32\ole32.dll (Microsoft OLE for Windows/Microsoft Corporation SIGNED)(2013-09-25 17:36:42) Reg HKLM\SOFTWARE\Classes\CLSID\{D3E34B21-9D75-101A-8C3D-00AA001A1652}\LocalServer32@ C:\Windows\system32\mspaint.exe (Paint/Microsoft Corporation SIGNED)(2009-07-13 23:43:12) Reg HKLM\SOFTWARE\Classes\CLSID\{D41969A6-C394-34B9-BD24-DD408F39F261}\InprocServer32@ C:\Windows\system32\mscoree.dll (Microsoft .NET Runtime Execution Engine/Microsoft Corporation SIGNED)(2013-09-25 17:38:26) Reg HKLM\SOFTWARE\Classes\CLSID\{D4EFF9CD-16DE-446e-83C5-9537543CF4A1}\InProcServer32@ C:\Windows\System32\sud.dll (SUD Control Panel/Microsoft Corporation SIGNED)(2013-09-25 17:37:38) Reg HKLM\SOFTWARE\Classes\CLSID\{d4f01ada-979c-491e-bac3-cd3c0e7bcf82}\InProcServer32@ C:\Windows\system32\ntshrui.dll (Shell extensions for sharing/Microsoft Corporation SIGNED)(2013-09-25 17:37:19) Reg HKLM\SOFTWARE\Classes\CLSID\{D51BD5A1-7548-11CF-A520-0080C77EF58A}\InprocServer32@ C:\Windows\system32\quartz.dll (DirectShow Runtime./Microsoft Corporation SIGNED)(2013-09-25 08:10:55) Reg HKLM\SOFTWARE\Classes\CLSID\{d58960ba-2ef3-4910-9e34-c911b1710180}\InProcServer32@ C:\Windows\system32\shell32.dll (Windows Shell Common Dll/Microsoft Corporation SIGNED)(2013-09-26 18:21:44) Reg HKLM\SOFTWARE\Classes\CLSID\{D5978620-5B9F-11D1-8DD2-00AA004ABD5E}\InprocServer32@ C:\Windows\system32\ES.DLL (COM+/Microsoft Corporation SIGNED)(2009-07-13 23:44:38) Reg HKLM\SOFTWARE\Classes\CLSID\{D5AB5662-131D-453D-88C8-9BBA87502ADE}\InprocServer32@ C:\Windows\system32\mscoree.dll (Microsoft .NET Runtime Execution Engine/Microsoft Corporation SIGNED)(2013-09-25 17:38:26) Reg HKLM\SOFTWARE\Classes\CLSID\{D5C66BE1-C209-11d1-8DEC-00C04FC2E0C7}\InprocServer32@ C:\Windows\system32\clbcatq.dll (COM+ Configuration Catalog/Microsoft Corporation SIGNED)(2009-07-13 23:44:44) Reg HKLM\SOFTWARE\Classes\CLSID\{D5CB383D-99F4-3C7E-A9C3-85B53661448F}\InprocServer32@ C:\Windows\system32\mscoree.dll (Microsoft .NET Runtime Execution Engine/Microsoft Corporation SIGNED)(2013-09-25 17:38:26) Reg HKLM\SOFTWARE\Classes\CLSID\{D5DE8D20-5BB8-11D1-A1E3-00A0C90F2731}\InProcServer32@ C:\Windows\system32\msvbvm60.dll (Visual Basic Virtual Machine/Microsoft Corporation SIGNED)(2009-06-10 21:38:03) Reg HKLM\SOFTWARE\Classes\CLSID\{D5E8041D-920F-45e9-B8FB-B1DEB82C6E5E}\LocalServer32@ C:\Program Files\Internet Explorer\iexplore.exe (Internet Explorer/Microsoft Corporation SIGNED)(2013-11-12 12:08:36) Reg HKLM\SOFTWARE\Classes\CLSID\{D60795C3-F2A5-45b1-A731-2516E7EAB8EB}\InprocServer32@ C:\Windows\System32\qagent.dll (Quarantine Agent Proxy/Microsoft Corporation SIGNED)(2013-09-25 17:38:03) Reg HKLM\SOFTWARE\Classes\CLSID\{D6108DC8-FBAC-426e-8A3C-1BCA926E5805}\InProcServer32@ C:\Windows\system32\shell32.dll (Windows Shell Common Dll/Microsoft Corporation SIGNED)(2013-09-26 18:21:44) Reg HKLM\SOFTWARE\Classes\CLSID\{d63c23c5-53e6-48d5-adda-a385b6bb9c7b}@LocalizedString C:\Windows\System32\ieframe.dll (Internet Browser/Microsoft Corporation SIGNED)(2013-12-13 11:08:39) Reg HKLM\SOFTWARE\Classes\CLSID\{D6791A63-E7E2-4fee-BF52-5DED8E86E9B8}@InfoTip C:\Windows\system32\wpdshext.dll (Portable Devices Shell Extension/Microsoft Corporation SIGNED)(2013-09-25 17:37:00) Reg HKLM\SOFTWARE\Classes\CLSID\{d6afe216-3106-4e91-953f-ffa26064c8ee}\InprocServer32@ C:\Windows\System32\QAgent.dll (Quarantine Agent Proxy/Microsoft Corporation SIGNED)(2013-09-25 17:38:03) Reg HKLM\SOFTWARE\Classes\CLSID\{D6D2034D-5F67-30D7-9CC5-452F2C46694F}\InprocServer32@ C:\Windows\system32\mscoree.dll (Microsoft .NET Runtime Execution Engine/Microsoft Corporation SIGNED)(2013-09-25 17:38:26) Reg HKLM\SOFTWARE\Classes\CLSID\{D7C1AEB5-10F2-48cb-A182-F7EF79C51B19}\InProcServer32@ C:\Windows\system32\shell32.dll (Windows Shell Common Dll/Microsoft Corporation SIGNED)(2013-09-26 18:21:44) Reg HKLM\SOFTWARE\Classes\CLSID\{D8013EEF-730B-45E2-BA24-874B7242C425}\InprocServer32@ C:\Windows\system32\mscoree.dll (Microsoft .NET Runtime Execution Engine/Microsoft Corporation SIGNED)(2013-09-25 17:38:26) Reg HKLM\SOFTWARE\Classes\CLSID\{D82BE2B0-5764-11D0-A96E-00C04FD705A2}\InProcServer32@ C:\Windows\system32\shell32.dll (Windows Shell Common Dll/Microsoft Corporation SIGNED)(2013-09-26 18:21:44) Reg HKLM\SOFTWARE\Classes\CLSID\{D8559EB9-20C0-410E-BEDA-7ED416AECC2A}@InfoTip C:\Program Files\Windows Defender\MsMpRes.dll (Windows Defender Resource Module/Microsoft Corporation SIGNED)(2009-07-13 23:37:21) Reg HKLM\SOFTWARE\Classes\CLSID\{D8A4F3EB-E7EC-3620-831A-B052A67C9944}\InprocServer32@ C:\Windows\system32\mscoree.dll (Microsoft .NET Runtime Execution Engine/Microsoft Corporation SIGNED)(2013-09-25 17:38:26) Reg HKLM\SOFTWARE\Classes\CLSID\{d912f8cf-0396-4915-884e-fb425d32943b}\InProcServer32@ C:\Windows\system32\shell32.dll (Windows Shell Common Dll/Microsoft Corporation SIGNED)(2013-09-26 18:21:44) Reg HKLM\SOFTWARE\Classes\CLSID\{D9144DCD-E998-4ECA-AB6A-DCD83CCBA16D}\InprocServer32@ C:\Windows\system32\EhStorShell.dll (Windows Enhanced Storage Shell Extension DLL/Microsoft Corporation SIGNED)(2009-07-13 23:45:42) Reg HKLM\SOFTWARE\Classes\CLSID\{D969A300-E7FF-11d0-A93B-00A0C90F2719}\InProcServer32@ C:\Windows\system32\shell32.dll (Windows Shell Common Dll/Microsoft Corporation SIGNED)(2013-09-26 18:21:44) Reg HKLM\SOFTWARE\Classes\CLSID\{DA2B8720-3354-4FAB-B838-B1472667C8E9}\InprocServer32@ C:\Windows\System32\mscoree.dll (Microsoft .NET Runtime Execution Engine/Microsoft Corporation SIGNED)(2013-09-25 17:38:26) Reg HKLM\SOFTWARE\Classes\CLSID\{db4f3fa7-5a08-4100-95de-b46df509b902}\InProcServer32@ C:\Windows\system32\van.dll (View Available Networks/Microsoft Corporation SIGNED)(2013-09-25 17:38:08) Reg HKLM\SOFTWARE\Classes\CLSID\{DBC85A2C-C0DC-4961-B6E2-D28B62C11AD4}\InprocServer32@ C:\Windows\System32\gameux.dll (Games Explorer/Microsoft Corporation SIGNED)(2013-09-25 17:37:46) Reg HKLM\SOFTWARE\Classes\CLSID\{DC1C5A9C-E88A-4dde-A5A1-60F82A20AEF7}\InProcServer32@ C:\Windows\System32\comdlg32.dll (Common Dialogs DLL/Microsoft Corporation SIGNED)(2013-09-25 17:37:51) Reg HKLM\SOFTWARE\Classes\CLSID\{DC5DA001-7CD4-11D2-8ED9-D8C857F98FE3}\InprocServer32@ C:\Windows\system32\mscoree.dll (Microsoft .NET Runtime Execution Engine/Microsoft Corporation SIGNED)(2013-09-25 17:38:26) Reg HKLM\SOFTWARE\Classes\CLSID\{DC651A43-0720-4a2b-9971-BD2EF1329A3D}\InProcServer32@ C:\Windows\System32\ieframe.dll (Internet Browser/Microsoft Corporation SIGNED)(2013-12-13 11:08:39) Reg HKLM\SOFTWARE\Classes\CLSID\{DCB00C01-570F-4A9B-8D69-199FDBA5723B}\InProcServer32@ C:\Windows\System32\netprofm.dll (Network List Manager/Microsoft Corporation SIGNED)(2009-07-13 23:56:58) Reg HKLM\SOFTWARE\Classes\CLSID\{DCED8DB0-11A5-4b16-AB9D-4E28CA38C99F}\InProcServer32@ C:\Windows\system32\netcfgx.dll (Network Configuration Objects/Microsoft Corporation SIGNED)(2013-09-25 17:38:28) Reg HKLM\SOFTWARE\Classes\CLSID\{DD06A84F-83BD-4d01-8AB9-2389FEA0869E}\InProcServer32@ C:\Windows\system32\WlanMM.dll (Dot11 Media and AdHoc Managers/Microsoft Corporation SIGNED)(2009-07-13 23:55:48) Reg HKLM\SOFTWARE\Classes\CLSID\{DD313E04-FEFF-11d1-8ECD-0000F87A470C}\InProcServer32@ C:\Windows\system32\shell32.dll (Windows Shell Common Dll/Microsoft Corporation SIGNED)(2013-09-26 18:21:44) Reg HKLM\SOFTWARE\Classes\CLSID\{DD373F1A-7227-4e3c-9AFB-98C288CF1956}\InprocServer32@ C:\Windows\System32\QAgent.dll (Quarantine Agent Proxy/Microsoft Corporation SIGNED)(2013-09-25 17:38:03) Reg HKLM\SOFTWARE\Classes\CLSID\{DD5856E5-8151-3334-B8E9-07CB152B20A4}\InprocServer32@ C:\Windows\system32\mscoree.dll (Microsoft .NET Runtime Execution Engine/Microsoft Corporation SIGNED)(2013-09-25 17:38:26) Reg HKLM\SOFTWARE\Classes\CLSID\{DE010DA1-289B-4232-8CD0-5112DCA6A7B3}\InprocServer32@ C:\Windows\System32\vdsbas.dll (Virtual Disk Service Basic Provider/Microsoft Corporation SIGNED)(2013-09-25 17:36:38) Reg HKLM\SOFTWARE\Classes\CLSID\{DE3F3560-3032-41B4-B6CF-F703B1B95640}\InProcServer32@ C:\Windows\System32\wsepno.dll (Profile notification support for Windows Search Service/Microsoft Corporation SIGNED)(2009-07-14 00:13:03) Reg HKLM\SOFTWARE\Classes\CLSID\{DE47D9CF-0107-3D66-93E9-A8ACB06B4583}\InprocServer32@ C:\Windows\system32\mscoree.dll (Microsoft .NET Runtime Execution Engine/Microsoft Corporation SIGNED)(2013-09-25 17:38:26) Reg HKLM\SOFTWARE\Classes\CLSID\{DE77BA04-3C92-4d11-A1A5-42352A53E0E3}\InProcServer32@ C:\Windows\System32\provsvc.dll (Windows HomeGroup/Microsoft Corporation SIGNED)(2013-09-25 17:37:30) Reg HKLM\SOFTWARE\Classes\CLSID\{DF0B3D60-548F-101B-8E65-08002B2BD119}\InprocServer@ C:\Windows\system32\ole2disp.dll Reg HKLM\SOFTWARE\Classes\CLSID\{DF0B3D60-548F-101B-8E65-08002B2BD119}\InprocServer32@ C:\Windows\system32\oleaut32.dll (Microsoft Corporation SIGNED)(2013-09-25 08:15:54) Reg HKLM\SOFTWARE\Classes\CLSID\{DF2FCE13-25EC-45bb-9D4C-CECD47C2430C}\InprocServer32@ C:\Windows\System32\iertutil.dll (Run time utility for Internet Explorer/Microsoft Corporation SIGNED)(2013-12-13 11:08:41) Reg HKLM\SOFTWARE\Classes\CLSID\{DF4FCC34-067A-4E0A-8352-4A1A5095346E}\LocalServer32@ C:\Program Files\Internet Explorer\iexplore.exe (Internet Explorer/Microsoft Corporation SIGNED)(2013-11-12 12:08:36) Reg HKLM\SOFTWARE\Classes\CLSID\{DF60686C-2941-4893-80C0-F13173B719D3}\InProcServer32@ C:\Windows\System32\provsvc.dll (Windows HomeGroup/Microsoft Corporation SIGNED)(2013-09-25 17:37:30) Reg HKLM\SOFTWARE\Classes\CLSID\{DFD888A7-A6B0-3B1B-985E-4CDAB0E4C17D}\InprocServer32@ C:\Windows\system32\mscoree.dll (Microsoft .NET Runtime Execution Engine/Microsoft Corporation SIGNED)(2013-09-25 17:38:26) Reg HKLM\SOFTWARE\Classes\CLSID\{E10F6C3A-F1AE-4ADC-AA9D-2FE65525666E}\InProcServer32@ C:\Windows\system32\USERENV.dll (Userenv/Microsoft Corporation SIGNED)(2013-09-25 17:36:37) Reg HKLM\SOFTWARE\Classes\CLSID\{E13EF4E4-D2F2-11d0-9816-00C04FD91972}\InProcServer32@ C:\Windows\system32\shell32.dll (Windows Shell Common Dll/Microsoft Corporation SIGNED)(2013-09-26 18:21:44) Reg HKLM\SOFTWARE\Classes\CLSID\{E1591797-EF95-364E-B80F-7C998A556501}\InprocServer32@ C:\Windows\system32\mscoree.dll (Microsoft .NET Runtime Execution Engine/Microsoft Corporation SIGNED)(2013-09-25 17:38:26) Reg HKLM\SOFTWARE\Classes\CLSID\{E1DE74AD-C368-4104-ADB1-57D00577247A}\InProcServer32@ C:\Windows\system32\WlanMM.dll (Dot11 Media and AdHoc Managers/Microsoft Corporation SIGNED)(2009-07-13 23:55:48) Reg HKLM\SOFTWARE\Classes\CLSID\{e2183960-9d58-4e9c-878a-4acc06ca564a}\InProcServer32@ C:\Windows\system32\shell32.dll (Windows Shell Common Dll/Microsoft Corporation SIGNED)(2013-09-26 18:21:44) Reg HKLM\SOFTWARE\Classes\CLSID\{E2B3C97F-6AE1-41AC-817A-F6F92166D7DD}\InprocServer32@ C:\Windows\system32\FirewallAPI.dll (Windows Firewall API/Microsoft Corporation SIGNED)(2009-07-13 23:53:14) Reg HKLM\SOFTWARE\Classes\CLSID\{E2E5A310-ECED-444F-81D7-ACCA6AC8A1A8}\InProcServer32@ C:\Windows\system32\wbem\Win32_TPM.dll (TPM WMI Provider/Microsoft Corporation SIGNED)(2009-07-13 23:13:24) Reg HKLM\SOFTWARE\Classes\CLSID\{E2E760C5-BF0D-4241-BFD6-6D0AAB648AC9}\InProcServer32@ C:\Windows\System32\ieframe.dll (Internet Browser/Microsoft Corporation SIGNED)(2013-12-13 11:08:39) Reg HKLM\SOFTWARE\Classes\CLSID\{E30629D1-27E5-11CE-875D-00608CB78066}\InprocServer32@ C:\Windows\system32\quartz.dll (DirectShow Runtime./Microsoft Corporation SIGNED)(2013-09-25 08:10:55) Reg HKLM\SOFTWARE\Classes\CLSID\{E38DA416-8050-3786-8201-46F187C15213}\InprocServer32@ C:\Windows\system32\mscoree.dll (Microsoft .NET Runtime Execution Engine/Microsoft Corporation SIGNED)(2013-09-25 17:38:26) Reg HKLM\SOFTWARE\Classes\CLSID\{E3A9BD50-51AE-410f-9706-0BA0D68B9A94}\InProcServer32@ C:\Windows\system32\scavengeui.dll (Service Pack Cleanup/Microsoft Corporation SIGNED)(2013-09-25 17:36:50) Reg HKLM\SOFTWARE\Classes\CLSID\{e3e478d6-a2f2-4791-89a3-21f5c78dc3ec}\InProcServer32@ C:\Windows\system32\shell32.dll (Windows Shell Common Dll/Microsoft Corporation SIGNED)(2013-09-26 18:21:44) Reg HKLM\SOFTWARE\Classes\CLSID\{E4206432-01A1-4BEE-B3E1-3702C8EDC574}\InprocServer32@ C:\Windows\system32\quartz.dll (DirectShow Runtime./Microsoft Corporation SIGNED)(2013-09-25 08:10:55) Reg HKLM\SOFTWARE\Classes\CLSID\{E44E5D18-0652-4508-A4E2-8A090067BCB0}@LocalizedString C:\Windows\system32\sud.dll (SUD Control Panel/Microsoft Corporation SIGNED)(2013-09-25 17:37:38) Reg HKLM\SOFTWARE\Classes\CLSID\{e44e9428-bdbc-4987-a099-40dc8fd255e7}\InProcServer32@ C:\Windows\system32\shell32.dll (Windows Shell Common Dll/Microsoft Corporation SIGNED)(2013-09-26 18:21:44) Reg HKLM\SOFTWARE\Classes\CLSID\{E474E05A-AB65-4f6a-827C-218B1BAAF31F}\InprocServer32@ C:\Windows\System32\evr.dll (Enhanced Video Renderer DLL/Microsoft Corporation SIGNED)(2013-09-25 17:38:17) Reg HKLM\SOFTWARE\Classes\CLSID\{E4979309-7A32-495E-8A92-7B014AAD4961}\InprocServer32@ C:\Windows\system32\quartz.dll (DirectShow Runtime./Microsoft Corporation SIGNED)(2013-09-25 08:10:55) Reg HKLM\SOFTWARE\Classes\CLSID\{E569BDE7-A8DC-47F3-893F-FD2B31B3EEFD}\InProcServer32@ C:\Windows\System32\ieframe.dll (Internet Browser/Microsoft Corporation SIGNED)(2013-12-13 11:08:39) Reg HKLM\SOFTWARE\Classes\CLSID\{E5B4EAA0-B2CA-11CE-8D2B-0000E202599C}\InprocServer32@ C:\Windows\system32\quartz.dll (DirectShow Runtime./Microsoft Corporation SIGNED)(2013-09-25 08:10:55) Reg HKLM\SOFTWARE\Classes\CLSID\{E5CB7A31-7512-11D2-89CE-0080C792E5D8}\InProcServer32@ C:\Windows\system32\mscoree.dll (Microsoft .NET Runtime Execution Engine/Microsoft Corporation SIGNED)(2013-09-25 17:38:26) Reg HKLM\SOFTWARE\Classes\CLSID\{E69FD98D-7EBE-4C01-BFED-67B4E4616A49}\InProcServer32@ C:\Windows\System32\explorerframe.dll (ExplorerFrame/Microsoft Corporation SIGNED)(2013-09-25 17:38:17) Reg HKLM\SOFTWARE\Classes\CLSID\{E6EE9AAC-F76B-4947-8260-A9F136138E11}\InProcServer32@ C:\Windows\System32\ieframe.dll (Internet Browser/Microsoft Corporation SIGNED)(2013-12-13 11:08:39) Reg HKLM\SOFTWARE\Classes\CLSID\{E724B749-18D6-36AB-9F6D-09C36D9C6016}\InprocServer32@ C:\Windows\system32\mscoree.dll (Microsoft .NET Runtime Execution Engine/Microsoft Corporation SIGNED)(2013-09-25 17:38:26) Reg HKLM\SOFTWARE\Classes\CLSID\{E7B2FB72-D728-49B3-A5F2-18EBF5F1349E}\InProcServer32@ C:\Windows\System32\gameux.dll (Games Explorer/Microsoft Corporation SIGNED)(2013-09-25 17:37:46) Reg HKLM\SOFTWARE\Classes\CLSID\{E7D574D5-2E51-3400-9FB6-A058F2D5B8AB}\InprocServer32@ C:\Windows\system32\mscoree.dll (Microsoft .NET Runtime Execution Engine/Microsoft Corporation SIGNED)(2013-09-25 17:38:26) Reg HKLM\SOFTWARE\Classes\CLSID\{E7E4BC40-E76A-11CE-A9BB-00AA004AE837}\InProcServer32@ C:\Windows\System32\ieframe.dll (Internet Browser/Microsoft Corporation SIGNED)(2013-12-13 11:08:39) Reg HKLM\SOFTWARE\Classes\CLSID\{E7E6A098-87CE-420D-91AE-413312AC8FA6}\InprocServer32@ C:\Windows\system32\WfHc.dll (Windows Firewall Helper Class/Microsoft Corporation SIGNED)(2009-07-13 23:52:56) Reg HKLM\SOFTWARE\Classes\CLSID\{E822F35C-DDC2-3FB2-9768-A2AEBCED7C40}\InprocServer32@ C:\Windows\system32\mscoree.dll (Microsoft .NET Runtime Execution Engine/Microsoft Corporation SIGNED)(2013-09-25 17:38:26) Reg HKLM\SOFTWARE\Classes\CLSID\{e949da38-c39d-4460-8ea7-a39152c56836}\InProcServer32@ C:\Windows\system32\rascfg.dll (RAS Configuration Objects/Microsoft Corporation SIGNED)(2009-07-13 23:54:54) Reg HKLM\SOFTWARE\Classes\CLSID\{E96767E0-7EAA-45e1-8E7D-64414AFF281A}@LocalizedString C:\Windows\system32\shell32.dll (Windows Shell Common Dll/Microsoft Corporation SIGNED)(2013-09-26 18:21:44) Reg HKLM\SOFTWARE\Classes\CLSID\{ea4a0a43-1c8f-4c7b-a4b1-28ecbd96ba8c}\InprocServer32@ C:\Windows\System32\QAgent.dll (Quarantine Agent Proxy/Microsoft Corporation SIGNED)(2013-09-25 17:38:03) Reg HKLM\SOFTWARE\Classes\CLSID\{ea72d00e-4960-42fa-ba92-7792a7944c1d}\InProcServer32@ C:\Windows\System32\explorerframe.dll (ExplorerFrame/Microsoft Corporation SIGNED)(2013-09-25 17:38:17) Reg HKLM\SOFTWARE\Classes\CLSID\{ea8b451c-5a19-49cf-bc5e-98accca49ef3}\InProcServer32@ C:\Windows\system32\shell32.dll (Windows Shell Common Dll/Microsoft Corporation SIGNED)(2013-09-26 18:21:44) Reg HKLM\SOFTWARE\Classes\CLSID\{EA9155A3-8A39-40b4-8963-D3C761B18371}\InprocServer32@ C:\Windows\System32\perftrack.dll (Microsoft Performance PerfTrack/Microsoft Corporation SIGNED)(2009-07-13 23:21:22) Reg HKLM\SOFTWARE\Classes\CLSID\{EAA78D4A-20A3-3FDE-AB72-D3D55E3AEFE6}\InprocServer32@ C:\Windows\system32\mscoree.dll (Microsoft .NET Runtime Execution Engine/Microsoft Corporation SIGNED)(2013-09-25 17:38:26) Reg HKLM\SOFTWARE\Classes\CLSID\{EAB22AC3-30C1-11CF-A7EB-0000C05BAE0B}\InProcServer32@ C:\Windows\System32\ieframe.dll (Internet Browser/Microsoft Corporation SIGNED)(2013-12-13 11:08:39) Reg HKLM\SOFTWARE\Classes\CLSID\{eb082ba1-df8a-46be-82f3-35bf9e9be52f}\InprocServer32@ C:\Windows\System32\QAgent.dll (Quarantine Agent Proxy/Microsoft Corporation SIGNED)(2013-09-25 17:38:03) Reg HKLM\SOFTWARE\Classes\CLSID\{EB6B4457-F013-4E5A-9B05-1D44E4D6FAEB}\InProcServer32@ C:\Windows\System32\listsvc.dll (Windows HomeGroup/Microsoft Corporation SIGNED)(2013-09-25 17:37:57) Reg HKLM\SOFTWARE\Classes\CLSID\{EBAA029C-01C0-32B6-AAE6-FE21ADFC3E5D}\InprocServer32@ C:\Windows\system32\mscoree.dll (Microsoft .NET Runtime Execution Engine/Microsoft Corporation SIGNED)(2013-09-25 17:38:26) Reg HKLM\SOFTWARE\Classes\CLSID\{EBB08C45-6C4A-4FDC-AE53-4EB8C4C7DB8E}\InProcServer32@ C:\Windows\System32\msctf.dll (MSCTF Server DLL/Microsoft Corporation SIGNED)(2009-07-13 23:28:05) Reg HKLM\SOFTWARE\Classes\CLSID\{EC3DAC94-DF80-3017-B381-B13DCED6C4D8}\InprocServer32@ C:\Windows\system32\mscoree.dll (Microsoft .NET Runtime Execution Engine/Microsoft Corporation SIGNED)(2013-09-25 17:38:26) Reg HKLM\SOFTWARE\Classes\CLSID\{EC9846B3-2762-4A6B-A214-6ACB603462D2}\InprocServer32@ C:\Windows\system32\FirewallAPI.dll (Windows Firewall API/Microsoft Corporation SIGNED)(2009-07-13 23:53:14) Reg HKLM\SOFTWARE\Classes\CLSID\{ECABAFD1-7F19-11D2-978E-0000F8757E2A}\InprocServer32@ C:\Windows\system32\mscoree.dll (Microsoft .NET Runtime Execution Engine/Microsoft Corporation SIGNED)(2013-09-25 17:38:26) Reg HKLM\SOFTWARE\Classes\CLSID\{ECABB0C3-7F19-11D2-978E-0000F8757E2A}\InprocServer32@ C:\Windows\system32\ES.DLL (COM+/Microsoft Corporation SIGNED)(2009-07-13 23:44:38) Reg HKLM\SOFTWARE\Classes\CLSID\{ECC82A10-B731-3A01-8A17-AC0DDD7666CF}\InprocServer32@ C:\Windows\system32\mscoree.dll (Microsoft .NET Runtime Execution Engine/Microsoft Corporation SIGNED)(2013-09-25 17:38:26) Reg HKLM\SOFTWARE\Classes\CLSID\{ECD4FC4D-521C-11D0-B792-00A0C90312E1}\InProcServer32@ C:\Windows\system32\explorerframe.dll (ExplorerFrame/Microsoft Corporation SIGNED)(2013-09-25 17:38:17) Reg HKLM\SOFTWARE\Classes\CLSID\{ECD4FC4F-521C-11D0-B792-00A0C90312E1}\InProcServer32@ C:\Windows\system32\shell32.dll (Windows Shell Common Dll/Microsoft Corporation SIGNED)(2013-09-26 18:21:44) Reg HKLM\SOFTWARE\Classes\CLSID\{ECF03A32-103D-11d2-854D-006008059367}@FriendlyTypeName C:\Windows\system32\mydocs.dll (My Documents Folder UI/Microsoft Corporation SIGNED)(2013-09-25 17:37:51) Reg HKLM\SOFTWARE\Classes\CLSID\{ED0BC45C-2438-31A9-BBB6-E2A3B5916419}\InprocServer32@ C:\Windows\system32\mscoree.dll (Microsoft .NET Runtime Execution Engine/Microsoft Corporation SIGNED)(2013-09-25 17:38:26) Reg HKLM\SOFTWARE\Classes\CLSID\{ed1d0fdf-4414-470a-a56d-cfb68623fc58}\LocalServer32@ C:\Program Files\Windows Media Player\wmplayer.exe (Windows Media Player/Microsoft Corporation SIGNED)(2013-09-25 17:37:02) Reg HKLM\SOFTWARE\Classes\CLSID\{ED228FDF-9EA8-4870-83b1-96b02CFE0D52}@LocalizedString C:\Windows\system32\shell32.dll (Windows Shell Common Dll/Microsoft Corporation SIGNED)(2013-09-26 18:21:44) Reg HKLM\SOFTWARE\Classes\CLSID\{ED228FDF-9EA8-4870-83b1-96b02CFE0D52}\InprocServer32@ C:\Windows\System32\gameux.dll (Games Explorer/Microsoft Corporation SIGNED)(2013-09-25 17:37:46) Reg HKLM\SOFTWARE\Classes\CLSID\{ed6ae9cf-ad35-46b7-ac30-3f8b9eb5349f}\InProcServer32@ C:\Windows\system32\shell32.dll (Windows Shell Common Dll/Microsoft Corporation SIGNED)(2013-09-26 18:21:44) Reg HKLM\SOFTWARE\Classes\CLSID\{ed72f0d2-b701-4c53-adc3-f2fb59946dd8}\InProcServer32@ C:\Windows\System32\ieframe.dll (Internet Browser/Microsoft Corporation SIGNED)(2013-12-13 11:08:39) Reg HKLM\SOFTWARE\Classes\CLSID\{ED7BA470-8E54-465E-825C-99712043E01C}@InfoTip C:\Windows\system32\shell32.dll (Windows Shell Common Dll/Microsoft Corporation SIGNED)(2013-09-26 18:21:44) Reg HKLM\SOFTWARE\Classes\CLSID\{ED834ED6-4B5A-4bfe-8F11-A626DCB6A921}@InfoTip C:\Windows\System32\themecpl.dll (Personalization CPL/Microsoft Corporation SIGNED)(2013-09-25 17:38:13) Reg HKLM\SOFTWARE\Classes\CLSID\{edb5f444-cb8d-445a-a523-ec5ab6ea33c7}\InProcServer32@ C:\Windows\system32\ntshrui.dll (Shell extensions for sharing/Microsoft Corporation SIGNED)(2013-09-25 17:37:19) Reg HKLM\SOFTWARE\Classes\CLSID\{EE0BDDFA-8373-4cc4-85D8-0618E453187C}\InProcServer32@ C:\Windows\System32\ieframe.dll (Internet Browser/Microsoft Corporation SIGNED)(2013-12-13 11:08:39) Reg HKLM\SOFTWARE\Classes\CLSID\{EE24A2C3-3AA2-33DA-8731-A4FCC1105813}\InprocServer32@ C:\Windows\system32\mscoree.dll (Microsoft .NET Runtime Execution Engine/Microsoft Corporation SIGNED)(2013-09-25 17:38:26) Reg HKLM\SOFTWARE\Classes\CLSID\{ee2e9ce0-0fe1-4eea-8f30-e4728b56f183}\InProcServer32@ C:\Windows\system32\shell32.dll (Windows Shell Common Dll/Microsoft Corporation SIGNED)(2013-09-26 18:21:44) Reg HKLM\SOFTWARE\Classes\CLSID\{EE832CE3-06CA-33EF-8F01-61C7C218BD7E}\InprocServer32@ C:\Windows\system32\mscoree.dll (Microsoft .NET Runtime Execution Engine/Microsoft Corporation SIGNED)(2013-09-25 17:38:26) Reg HKLM\SOFTWARE\Classes\CLSID\{EE8E4870-A889-4DC4-969F-F38F707F4AC2}\InProcServer32@ C:\Windows\system32\shell32.dll (Windows Shell Common Dll/Microsoft Corporation SIGNED)(2013-09-26 18:21:44) Reg HKLM\SOFTWARE\Classes\CLSID\{EE96F4E1-377E-315C-AEF5-874DC8C7A2AA}\InprocServer32@ C:\Windows\system32\mscoree.dll (Microsoft .NET Runtime Execution Engine/Microsoft Corporation SIGNED)(2013-09-25 17:38:26) Reg HKLM\SOFTWARE\Classes\CLSID\{eea0c191-dda8-4656-8fc4-72bdedba8a78}\InProcServer32@ C:\Windows\system32\shell32.dll (Windows Shell Common Dll/Microsoft Corporation SIGNED)(2013-09-26 18:21:44) Reg HKLM\SOFTWARE\Classes\CLSID\{EEC5DCCA-05DC-4B46-8AF7-2881C1635AEA}\InprocServer32@ C:\Windows\System32\mscoree.dll (Microsoft .NET Runtime Execution Engine/Microsoft Corporation SIGNED)(2013-09-25 17:38:26) Reg HKLM\SOFTWARE\Classes\CLSID\{ef1c0450-0b48-4384-94ae-d1cb35641f86}\InProcServer32@ C:\Windows\system32\shell32.dll (Windows Shell Common Dll/Microsoft Corporation SIGNED)(2013-09-26 18:21:44) Reg HKLM\SOFTWARE\Classes\CLSID\{EF24F689-14F8-4D92-B4AF-D7B1F0E70FD4}\InprocServer32@ C:\Windows\system32\mscoree.dll (Microsoft .NET Runtime Execution Engine/Microsoft Corporation SIGNED)(2013-09-25 17:38:26) Reg HKLM\SOFTWARE\Classes\CLSID\{ef43ecfe-2ab9-4632-bf21-58909dd177f0}\InProcServer32@ C:\Windows\system32\shell32.dll (Windows Shell Common Dll/Microsoft Corporation SIGNED)(2013-09-26 18:21:44) Reg HKLM\SOFTWARE\Classes\CLSID\{EF8AD2D1-AE36-11D1-B2D2-006097DF8C11}\InProcServer32@ C:\Windows\system32\explorerframe.dll (ExplorerFrame/Microsoft Corporation SIGNED)(2013-09-25 17:38:17) Reg HKLM\SOFTWARE\Classes\CLSID\{EFB92EFB-9236-4bd7-B60D-51D1C7D1C87A}\InProcServer32@ C:\Windows\system32\netcorehc.dll (Networking Core Diagnostics Helper Classes/Microsoft Corporation SIGNED)(2009-07-13 23:52:44) Reg HKLM\SOFTWARE\Classes\CLSID\{F00CA7A7-4B8D-3F2F-A5F2-CE4A4478B39C}\InprocServer32@ C:\Windows\system32\mscoree.dll (Microsoft .NET Runtime Execution Engine/Microsoft Corporation SIGNED)(2013-09-25 17:38:26) Reg HKLM\SOFTWARE\Classes\CLSID\{F02602C4-3C2A-473B-B35E-679A0076A4A5}\LocalServer32@ C:\Windows\system32\Wat\WatAdminSvc.exe (Windows Activation Technologies Service/Microsoft Corporation SIGNED)(2013-09-25 18:55:28) Reg HKLM\SOFTWARE\Classes\CLSID\{f0ae1542-f497-484b-a175-a20db09144ba}\InProcServer32@ C:\Windows\system32\shell32.dll (Windows Shell Common Dll/Microsoft Corporation SIGNED)(2013-09-26 18:21:44) Reg HKLM\SOFTWARE\Classes\CLSID\{F1058E4D-A3B4-43d8-A5E8-35359FB76D9B}\InprocServer32@ C:\Windows\system32\MSCorEE.dll (Microsoft .NET Runtime Execution Engine/Microsoft Corporation SIGNED)(2013-09-25 17:38:26) Reg HKLM\SOFTWARE\Classes\CLSID\{F1171280-BC35-45d1-8F53-8AB833267899}\InprocServer32@ C:\Windows\system32\dnshc.dll (DNS Helper Class/Microsoft Corporation SIGNED)(2009-07-13 23:52:43) Reg HKLM\SOFTWARE\Classes\CLSID\{F12FDE6A-9394-3C32-8E4D-F3D470947284}\InprocServer32@ C:\Windows\system32\mscoree.dll (Microsoft .NET Runtime Execution Engine/Microsoft Corporation SIGNED)(2013-09-25 17:38:26) Reg HKLM\SOFTWARE\Classes\CLSID\{f1f3b524-b27f-4a64-8d26-c654800b79d3}\InprocServer32@ C:\Windows\system32\sdautoplay.dll (Microsoft� Windows Backup AutoPlay Integration Library/Microsoft Corporation SIGNED)(2009-07-13 23:23:31) Reg HKLM\SOFTWARE\Classes\CLSID\{F20DA720-C02F-11CE-927B-0800095AE340}\InProcHandler@ C:\Windows\system32\ole2.dll Reg HKLM\SOFTWARE\Classes\CLSID\{f26a669a-bcbb-4e37-abf9-7325da15f931}\InProcServer32@ C:\Windows\system32\shell32.dll (Windows Shell Common Dll/Microsoft Corporation SIGNED)(2013-09-26 18:21:44) Reg HKLM\SOFTWARE\Classes\CLSID\{F2C4CDB0-2714-42AD-A948-2ED958A322E3}\InProcServer32@ C:\Windows\system32\tsworkspace.dll (RemoteApp and Desktop Connection Component/Microsoft Corporation SIGNED)(2013-09-25 17:37:06) Reg HKLM\SOFTWARE\Classes\CLSID\{F2CF5485-4E02-4f68-819C-B92DE9277049}@MenuTextPUI C:\Windows\System32\ieframe.dll (Internet Browser/Microsoft Corporation SIGNED)(2013-12-13 11:08:39) Reg HKLM\SOFTWARE\Classes\CLSID\{F3364BA0-65B9-11CE-A9BA-00AA004AE837}\InProcServer32@ C:\Windows\system32\shell32.dll (Windows Shell Common Dll/Microsoft Corporation SIGNED)(2013-09-26 18:21:44) Reg HKLM\SOFTWARE\Classes\CLSID\{F3368374-CF19-11d0-B93D-00A0C90312e1}\InProcServer32@ C:\Windows\system32\explorerframe.dll (ExplorerFrame/Microsoft Corporation SIGNED)(2013-09-25 17:38:17) Reg HKLM\SOFTWARE\Classes\CLSID\{F382DA49-9148-4a22-AF78-C378DFC32D02}\InprocServer32@ C:\Windows\System32\gameux.dll (Games Explorer/Microsoft Corporation SIGNED)(2013-09-25 17:37:46) Reg HKLM\SOFTWARE\Classes\CLSID\{f3cc4ca3-22c2-40ec-ac3c-89d8a43373b0}\InProcServer32@ C:\Windows\system32\shell32.dll (Windows Shell Common Dll/Microsoft Corporation SIGNED)(2013-09-26 18:21:44) Reg HKLM\SOFTWARE\Classes\CLSID\{f4086d4e-2e05-428b-92de-87d8d0bb4262}\InprocServer32@ C:\Windows\system32\pnrphc.dll (PNRP Helper Class/Microsoft Corporation SIGNED)(2009-07-13 23:55:50) Reg HKLM\SOFTWARE\Classes\CLSID\{F4547E68-62D2-43ED-BEAE-45346B300A64}\InprocServer32@ C:\Windows\system32\mscoree.dll (Microsoft .NET Runtime Execution Engine/Microsoft Corporation SIGNED)(2013-09-25 17:38:26) Reg HKLM\SOFTWARE\Classes\CLSID\{F46316E4-FB1B-46eb-AEDF-9520BFBB916A}\InProcServer32@ C:\Windows\system32\shell32.dll (Windows Shell Common Dll/Microsoft Corporation SIGNED)(2013-09-26 18:21:44) Reg HKLM\SOFTWARE\Classes\CLSID\{F4655419-DAF2-42ab-9178-3B6AC903170C}\InprocServer32@ C:\Windows\System32\WLanHC.dll (Wireless LAN Helper Classes/Microsoft Corporation SIGNED)(2009-07-13 23:51:55) Reg HKLM\SOFTWARE\Classes\CLSID\{f4be747e-45c4-4701-90f1-d49d9ac30248}@LocalizedString C:\Windows\system32\diagperf.dll (Microsoft Performance Diagnostics/Microsoft Corporation SIGNED)(2013-09-25 17:36:12) Reg HKLM\SOFTWARE\Classes\CLSID\{F4E1E7F6-A035-41B3-9856-A3C3A1C4684F}\InprocServer32@ C:\Windows\system32\mscoree.dll (Microsoft .NET Runtime Execution Engine/Microsoft Corporation SIGNED)(2013-09-25 17:38:26) Reg HKLM\SOFTWARE\Classes\CLSID\{f507f854-308b-401e-a1b7-b55ba6ba679a}\InProcServer32@ C:\Windows\system32\shell32.dll (Windows Shell Common Dll/Microsoft Corporation SIGNED)(2013-09-26 18:21:44) Reg HKLM\SOFTWARE\Classes\CLSID\{F562A2C8-E850-4F05-8E7A-E7192E4E6C23}\InProcServer32@ C:\Windows\system32\propsys.dll (Microsoft Property System/Microsoft Corporation SIGNED)(2013-09-25 17:38:03) Reg HKLM\SOFTWARE\Classes\CLSID\{F59D514C-F200-319F-BF3F-9E4E23B2848C}\InprocServer32@ C:\Windows\system32\mscoree.dll (Microsoft .NET Runtime Execution Engine/Microsoft Corporation SIGNED)(2013-09-25 17:38:26) Reg HKLM\SOFTWARE\Classes\CLSID\{F5B63656-069D-4E80-B4FD-9E0DB16604D8}\InProcServer32@ C:\Windows\system32\upnphost.dll (UPnP Device Host/Microsoft Corporation SIGNED)(2009-07-13 23:55:41) Reg HKLM\SOFTWARE\Classes\CLSID\{F5E692D9-8A87-349D-9657-F96E5799D2F4}\InprocServer32@ C:\Windows\system32\mscoree.dll (Microsoft .NET Runtime Execution Engine/Microsoft Corporation SIGNED)(2013-09-25 17:38:26) Reg HKLM\SOFTWARE\Classes\CLSID\{F6166DAD-D3BE-4ebd-8419-9B5EAD8D0EC7}\InProcServer32@ C:\Windows\system32\shell32.dll (Windows Shell Common Dll/Microsoft Corporation SIGNED)(2013-09-26 18:21:44) Reg HKLM\SOFTWARE\Classes\CLSID\{F64A6DA6-E8AF-4B7B-BCA8-847AE765D538}\InprocServer32@ C:\Windows\System32\audioses.dll (Audio Session/Microsoft Corporation SIGNED)(2013-09-25 17:36:17) Reg HKLM\SOFTWARE\Classes\CLSID\{F6914A11-D95D-324F-BA0F-39A374625290}\InprocServer32@ C:\Windows\system32\mscoree.dll (Microsoft .NET Runtime Execution Engine/Microsoft Corporation SIGNED)(2013-09-25 17:38:26) Reg HKLM\SOFTWARE\Classes\CLSID\{f6b13ba7-d626-45e5-82c5-26e596114dc0}\InProcServer32@ C:\Windows\system32\fphc.dll (Filtering Platform Helper Class/Microsoft Corporation SIGNED)(2013-09-25 17:37:45) Reg HKLM\SOFTWARE\Classes\CLSID\{F6B6768F-F99E-4152-8ED2-0412F78517FB}\InprocServer32@ C:\Windows\system32\mscoree.dll (Microsoft .NET Runtime Execution Engine/Microsoft Corporation SIGNED)(2013-09-25 17:38:26) Reg HKLM\SOFTWARE\Classes\CLSID\{f77d9c1c-5aff-4341-b028-57f7510aa91c}\InProcServer32@ C:\Windows\system32\shell32.dll (Windows Shell Common Dll/Microsoft Corporation SIGNED)(2013-09-26 18:21:44) Reg HKLM\SOFTWARE\Classes\CLSID\{F7AFD75B-BF8C-4a11-BDB9-04AD66182F84}\InprocServer32@ C:\Windows\System32\evr.dll (Enhanced Video Renderer DLL/Microsoft Corporation SIGNED)(2013-09-25 17:38:17) Reg HKLM\SOFTWARE\Classes\CLSID\{f81e9010-6ea4-11ce-a7ff-00aa003ca9f6}\InProcServer32@ C:\Windows\system32\ntshrui.dll (Shell extensions for sharing/Microsoft Corporation SIGNED)(2013-09-25 17:37:19) Reg HKLM\SOFTWARE\Classes\CLSID\{F8383852-FCD3-11d1-A6B9-006097DF5BD4}\InProcServer32@ C:\Windows\system32\shell32.dll (Windows Shell Common Dll/Microsoft Corporation SIGNED)(2013-09-26 18:21:44) Reg HKLM\SOFTWARE\Classes\CLSID\{F83DAC1C-9BB9-4f2b-B619-09819DA81B0E}\InProcServer32@ C:\Windows\System32\ieframe.dll (Internet Browser/Microsoft Corporation SIGNED)(2013-12-13 11:08:39) Reg HKLM\SOFTWARE\Classes\CLSID\{f85d5d94-6851-44f7-bb3a-bfd0949abf1d}\InProcServer32@ C:\Windows\system32\shell32.dll (Windows Shell Common Dll/Microsoft Corporation SIGNED)(2013-09-26 18:21:44) Reg HKLM\SOFTWARE\Classes\CLSID\{F8BE2AD5-4E99-3E00-B10E-7C54D31C1C1D}\InprocServer32@ C:\Windows\system32\mscoree.dll (Microsoft .NET Runtime Execution Engine/Microsoft Corporation SIGNED)(2013-09-25 17:38:26) Reg HKLM\SOFTWARE\Classes\CLSID\{F9A7AB61-C0BC-490e-A7FE-BFF26B327A3F}\InProcServer32@ C:\Windows\system32\shell32.dll (Windows Shell Common Dll/Microsoft Corporation SIGNED)(2013-09-26 18:21:44) Reg HKLM\SOFTWARE\Classes\CLSID\{FA0B54D5-F221-3648-A20C-F67A96F4A207}\InprocServer32@ C:\Windows\system32\mscoree.dll (Microsoft .NET Runtime Execution Engine/Microsoft Corporation SIGNED)(2013-09-25 17:38:26) Reg HKLM\SOFTWARE\Classes\CLSID\{FA10746C-9B63-4b6c-BC49-FC300EA5F256}\InprocServer32@ C:\Windows\System32\evr.dll (Enhanced Video Renderer DLL/Microsoft Corporation SIGNED)(2013-09-25 17:38:17) Reg HKLM\SOFTWARE\Classes\CLSID\{FAB24754-0440-439b-A223-B1D360062D1D}\InprocServer32@ C:\Windows\System32\dhcpqec.dll (Microsoft DHCP NAP Enforcement Client/Microsoft Corporation SIGNED)(2009-07-13 23:52:20) Reg HKLM\SOFTWARE\Classes\CLSID\{FAF53CC4-BD73-4E36-83F1-2B23F46E513E}\InprocServer32@ C:\Windows\System32\ES.DLL (COM+/Microsoft Corporation SIGNED)(2009-07-13 23:44:38) Reg HKLM\SOFTWARE\Classes\CLSID\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32@ C:\Windows\system32\shell32.dll (Windows Shell Common Dll/Microsoft Corporation SIGNED)(2013-09-26 18:21:44) Reg HKLM\SOFTWARE\Classes\CLSID\{fbeb8a05-beee-4442-804e-409d6c4515e9}\MergedFolder@ConflictOverlayIcon C:\Windows\system32\imageres.dll (Windows Image Resource/Microsoft Corporation SIGNED)(2009-07-13 23:42:24) Reg HKLM\SOFTWARE\Classes\CLSID\{fbebb71b-a592-4880-b096-9429ebe119db}\InprocServer32@ C:\Windows\System32\L2SecHC.dll (Layer 2 Security Diagnostics Helper Classes/Microsoft Corporation SIGNED)(2009-07-13 23:51:54) Reg HKLM\SOFTWARE\Classes\CLSID\{FBF23B40-E3F0-101B-8488-00AA003E56F8}@LocalizedString C:\Windows\System32\ieframe.dll (Internet Browser/Microsoft Corporation SIGNED)(2013-12-13 11:08:39) Reg HKLM\SOFTWARE\Classes\CLSID\{FC13A7D5-E2B3-37BA-B807-7FA6238284D5}\InprocServer32@ C:\Windows\system32\mscoree.dll (Microsoft .NET Runtime Execution Engine/Microsoft Corporation SIGNED)(2013-09-25 17:38:26) Reg HKLM\SOFTWARE\Classes\CLSID\{fc1ee10b-7ef6-41b5-bb60-98d26dd9fcd1}\MergedFolder@Location C:\Windows\system32\shell32.dll (Windows Shell Common Dll/Microsoft Corporation SIGNED)(2013-09-26 18:21:44) Reg HKLM\SOFTWARE\Classes\CLSID\{FCC74B77-EC3E-4dd8-A80B-008A702075A9}\Elevation@IconReference C:\Windows\system32\imageres.dll (Windows Image Resource/Microsoft Corporation SIGNED)(2009-07-13 23:42:24) Reg HKLM\SOFTWARE\Classes\CLSID\{fccf70c8-f4d7-4d8b-8c17-cd6715e37fff}\InProcServer32@ C:\Windows\system32\explorerframe.dll (ExplorerFrame/Microsoft Corporation SIGNED)(2013-09-25 17:38:17) Reg HKLM\SOFTWARE\Classes\CLSID\{FD5CD8B1-6FE0-44F3-BBFB-65E3655B096E}\InprocServer32@ C:\Windows\system32\mscoree.dll (Microsoft .NET Runtime Execution Engine/Microsoft Corporation SIGNED)(2013-09-25 17:38:26) Reg HKLM\SOFTWARE\Classes\CLSID\{FD7F2B29-24D0-4B5C-B177-592C39F9CA10}\InProcServer32@ C:\Windows\System32\audioses.dll (Audio Session/Microsoft Corporation SIGNED)(2013-09-25 17:36:17) Reg HKLM\SOFTWARE\Classes\CLSID\{FD8C8FCE-4F85-36B2-B8E8-F5A183654539}\InprocServer32@ C:\Windows\system32\mscoree.dll (Microsoft .NET Runtime Execution Engine/Microsoft Corporation SIGNED)(2013-09-25 17:38:26) Reg HKLM\SOFTWARE\Classes\CLSID\{FDE7673D-2E19-4145-8376-BBD58C4BC7BA}\InProcServer32@ C:\Windows\System32\ieframe.dll (Internet Browser/Microsoft Corporation SIGNED)(2013-12-13 11:08:39) Reg HKLM\SOFTWARE\Classes\CLSID\{FDF9C30D-CCAB-3E2D-B584-9E24CE8038E3}\InprocServer32@ C:\Windows\system32\mscoree.dll (Microsoft .NET Runtime Execution Engine/Microsoft Corporation SIGNED)(2013-09-25 17:38:26) Reg HKLM\SOFTWARE\Classes\CLSID\{FE217CB2-0B2C-48c9-90CA-8D8BCA79248D}\InProcServer32@ C:\Windows\system32\netcorehc.dll (Networking Core Diagnostics Helper Classes/Microsoft Corporation SIGNED)(2009-07-13 23:52:44) Reg HKLM\SOFTWARE\Classes\CLSID\{fe5afcf2-e681-4ada-9703-ef39b8ecb9bf}\InProcServer32@ C:\Windows\system32\shell32.dll (Windows Shell Common Dll/Microsoft Corporation SIGNED)(2013-09-26 18:21:44) Reg HKLM\SOFTWARE\Classes\CLSID\{FEB50740-7BEF-11CE-9BD9-0000E202599C}\InprocServer32@ C:\Windows\system32\quartz.dll (DirectShow Runtime./Microsoft Corporation SIGNED)(2013-09-25 08:10:55) Reg HKLM\SOFTWARE\Classes\CLSID\{FEE17FA5-A46F-11D6-9500-00065B874123}\InprocServer32@ C:\Program Files\Common Files\Microsoft Shared\OFFICE11\MSSOAP30.DLL (Microsoft Office Soap SDK/Microsoft Corporation)(2002-12-06 12:25:10) Reg HKLM\SOFTWARE\Classes\CLSID\{FEF10FA2-355E-4e06-9381-9B24D7F7CC88}\InProcServer32@ C:\Windows\system32\shell32.dll (Windows Shell Common Dll/Microsoft Corporation SIGNED)(2013-09-26 18:21:44) Reg HKLM\SOFTWARE\Classes\CLSID\{FF2A742B-CA25-4507-BD93-6BA9B8E8965F}\InprocServer32@ C:\Windows\System32\WLanHC.dll (Wireless LAN Helper Classes/Microsoft Corporation SIGNED)(2009-07-13 23:51:55) Reg HKLM\SOFTWARE\Classes\CLSID\{FF393560-C2A7-11CF-BFF4-444553540000}\InProcServer32@ C:\Windows\System32\ieframe.dll (Internet Browser/Microsoft Corporation SIGNED)(2013-12-13 11:08:39) Reg HKLM\SOFTWARE\Classes\CLSID\{ff609cc7-d34d-4049-a1aa-2293517ffcc6}\InProcServer32@ C:\Windows\system32\stobject.dll (Systray shell service object/Microsoft Corporation SIGNED)(2013-09-25 17:36:32) Reg HKLM\SOFTWARE\Classes\CLSID\{ff8a32e3-a9a7-4093-b9c4-5b5b4f30ab63}\InProcServer32@ C:\Windows\system32\shell32.dll (Windows Shell Common Dll/Microsoft Corporation SIGNED)(2013-09-26 18:21:44) Reg HKLM\SOFTWARE\Classes\CLSID\{FFC9F9AE-E87A-3252-8E25-B22423A40065}\InprocServer32@ C:\Windows\system32\mscoree.dll (Microsoft .NET Runtime Execution Engine/Microsoft Corporation SIGNED)(2013-09-25 17:38:26) Reg HKLM\SOFTWARE\Classes\CLSID\{ffd90217-f7c2-4434-9ee1-6f1b530db20f}\InProcServer32@ C:\Windows\System32\ieframe.dll (Internet Browser/Microsoft Corporation SIGNED)(2013-12-13 11:08:39) Reg HKLM\SOFTWARE\Classes\CLSID\{ffe1df5f-9f06-46d3-af27-f1fc10d63892}\Elevation@IconReference C:\Windows\system32\imageres.dll (Windows Image Resource/Microsoft Corporation SIGNED)(2009-07-13 23:42:24) Reg HKLM\SOFTWARE\Classes\cmdfile\shell\runas\command@ C:\Windows\System32\cmd.exe (Windows Command Processor/Microsoft Corporation SIGNED)(2013-09-25 17:36:17) Reg HKLM\SOFTWARE\Classes\cmdfile\shell\runasuser@ C:\Windows\system32\shell32.dll (Windows Shell Common Dll/Microsoft Corporation SIGNED)(2013-09-26 18:21:44) Reg HKLM\SOFTWARE\Classes\CompressedFolder\shell\find\command@ C:\Windows\Explorer.exe (Windows Explorer/Microsoft Corporation SIGNED)(2013-09-25 17:37:42) Reg HKLM\SOFTWARE\Classes\contact_wab_auto_file@FriendlyTypeName C:\Program Files\Common Files\System\wab32res.dll (Microsoft (R) Contacts DLL/Microsoft Corporation SIGNED)(2009-07-13 23:42:15) Reg HKLM\SOFTWARE\Classes\contact_wab_auto_file\shell\open\command@ C:\Program Files\Windows Mail\wab.exe (Windows Contacts/Microsoft Corporation SIGNED)(2013-09-25 17:36:58) Reg HKLM\SOFTWARE\Classes\cplfile@FriendlyTypeName C:\Windows\system32\shell32.dll (Windows Shell Common Dll/Microsoft Corporation SIGNED)(2013-09-26 18:21:44) Reg HKLM\SOFTWARE\Classes\CSSfile@FriendlyTypeName C:\Windows\System32\ieframe.dll (Internet Browser/Microsoft Corporation SIGNED)(2013-12-13 11:08:39) Reg HKLM\SOFTWARE\Classes\CSSfile\Shell\edit\Command@ C:\Program Files\Macromedia\Dreamweaver 8\dreamweaver.exe (Dreamweaver 8/Macromedia, Inc.)(2005-09-27 16:14:08) Reg HKLM\SOFTWARE\Classes\curfile@FriendlyTypeName C:\Windows\System32\shell32.dll (Windows Shell Common Dll/Microsoft Corporation SIGNED)(2013-09-26 18:21:44) Reg HKLM\SOFTWARE\Classes\DesktopBackground\Shell\Gadgets@MUIVerb C:\Program Files\Windows Sidebar\sidebar.exe (Windows Desktop Gadgets/Microsoft Corporation SIGNED)(2013-09-25 17:36:32) Reg HKLM\SOFTWARE\Classes\DesktopBackground\Shell\Personalize@ C:\Windows\system32\themecpl.dll (Personalization CPL/Microsoft Corporation SIGNED)(2013-09-25 17:38:13) Reg HKLM\SOFTWARE\Classes\DeviceDisplayObject\AllItems\Shell\Microsoft.DxpOpen@ C:\Windows\system32\shell32.dll (Windows Shell Common Dll/Microsoft Corporation SIGNED)(2013-09-26 18:21:44) Reg HKLM\SOFTWARE\Classes\DeviceDisplayObject\AllItems\Shell\Microsoft.DxpOpen\command@ C:\Windows\Explorer.exe (Windows Explorer/Microsoft Corporation SIGNED)(2013-09-25 17:37:42) Reg HKLM\SOFTWARE\Classes\DeviceDisplayObject\AllItems\Shell\Microsoft.DxpOpenInNewWindow@ C:\Windows\system32\shell32.dll (Windows Shell Common Dll/Microsoft Corporation SIGNED)(2013-09-26 18:21:44) Reg HKLM\SOFTWARE\Classes\DeviceDisplayObject\AllItems\Shell\Microsoft.DxpOpenInNewWindow\command@ C:\Windows\Explorer.exe (Windows Explorer/Microsoft Corporation SIGNED)(2013-09-25 17:37:42) Reg HKLM\SOFTWARE\Classes\DeviceDisplayObject\HardwareId\Bluetooth#tosrfbd\Commands\Shell\Item1000@MUIVerb C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtMng.exe (Bluetooth Manager/TOSHIBA CORPORATION. SIGNED)(2011-05-09 15:06:02) Reg HKLM\SOFTWARE\Classes\DeviceDisplayObject\HardwareId\Bluetooth#tosrfbd\Commands\Shell\Item1000\Command@ C:\Program Files\Toshiba\Bluetooth Toshiba Stack\ECCenter.exe (Bluetooth Settings/TOSHIBA CORPORATION SIGNED)(2010-02-16 12:12:00) Reg HKLM\SOFTWARE\Classes\DeviceDisplayObject\HardwareId\Bluetooth#tosrfbd\Shell\Item1000@MUIVerb C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtMng.exe (Bluetooth Manager/TOSHIBA CORPORATION. SIGNED)(2011-05-09 15:06:02) Reg HKLM\SOFTWARE\Classes\DeviceDisplayObject\HardwareId\Bluetooth#tosrfbd\Shell\Item1000\Command@ C:\Program Files\Toshiba\Bluetooth Toshiba Stack\ECCenter1.exe (Bluetooth Settings/TOSHIBA CORPORATION. SIGNED)(2009-08-06 13:28:00) Reg HKLM\SOFTWARE\Classes\DeviceDisplayObject\HardwareId\Bluetooth#tosrfbd\Shell\Item1050@MUIVerb C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtMng.exe (Bluetooth Manager/TOSHIBA CORPORATION. SIGNED)(2011-05-09 15:06:02) Reg HKLM\SOFTWARE\Classes\DeviceDisplayObject\HardwareId\Bluetooth#tosrfbd\Shell\Item1100\Command@ C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtProc1.exe (TosBtProc/TOSHIBA CORPORATION. SIGNED)(2009-08-06 13:29:00) Reg HKLM\SOFTWARE\Classes\DeviceDisplayObject\HardwareId\Bluetooth#tosrfbd\Shell\Item1200@MUIVerb C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtMng.exe (Bluetooth Manager/TOSHIBA CORPORATION. SIGNED)(2011-05-09 15:06:02) Reg HKLM\SOFTWARE\Classes\DeviceDisplayObject\HardwareId\Bluetooth#tosrfbd\Shell\Item1200\Command@ C:\Program Files\Toshiba\Bluetooth Toshiba Stack\WirelessFTP1.exe (TOSHIBA WirelessFTP/TOSHIBA CORPORATION. SIGNED)(2009-08-06 13:29:00) Reg HKLM\SOFTWARE\Classes\DeviceDisplayObject\HardwareId\Bluetooth#tosrfbd\Shell\Item1300@MUIVerb C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtMng.exe (Bluetooth Manager/TOSHIBA CORPORATION. SIGNED)(2011-05-09 15:06:02) Reg HKLM\SOFTWARE\Classes\DeviceDisplayObject\HardwareId\Bluetooth#tosrfbd\Shell\Item1300\Command@ C:\Program Files\Toshiba\Bluetooth Toshiba Stack\BIP_Camera1.exe (BIP_Camera Application/TOSHIBA CORPORATION. SIGNED)(2009-08-06 13:28:00) Reg HKLM\SOFTWARE\Classes\DeviceDisplayObject\HardwareId\Bluetooth#tosrfbd\Shell\Item1400@MUIVerb C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtMng.exe (Bluetooth Manager/TOSHIBA CORPORATION. SIGNED)(2011-05-09 15:06:02) Reg HKLM\SOFTWARE\Classes\DeviceDisplayObject\HardwareId\Bluetooth#tosrfbd\Shell\Item1400\Command@ C:\Program Files\Toshiba\Bluetooth Toshiba Stack\ECCenter.exe (Bluetooth Settings/TOSHIBA CORPORATION SIGNED)(2010-02-16 12:12:00) Reg HKLM\SOFTWARE\Classes\DeviceDisplayObject\HardwareId\Bluetooth#tosrfbd\Shell\Item1500@MUIVerb C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtMng.exe (Bluetooth Manager/TOSHIBA CORPORATION. SIGNED)(2011-05-09 15:06:02) Reg HKLM\SOFTWARE\Classes\DeviceDisplayObject\HardwareId\Bluetooth#tosrfbd\Shell\Item1600\Command@ C:\Program Files\Toshiba\Bluetooth Toshiba Stack\UsrGuide.exe (UsrGuide/TOSHIBA CORPORATION SIGNED)(2008-07-24 11:36:00) Reg HKLM\SOFTWARE\Classes\DeviceDisplayObject\HardwareId\Bluetooth#tosrfbd\Shell\Item1700@MUIVerb C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtMng.exe (Bluetooth Manager/TOSHIBA CORPORATION. SIGNED)(2011-05-09 15:06:02) Reg HKLM\SOFTWARE\Classes\DeviceDisplayObject\HardwareId\ROOT#BLUETOOTH_COM\Commands\Shell\Item1000\Command@ C:\Program Files\Toshiba\Bluetooth Toshiba Stack\ECCenter.exe (Bluetooth Settings/TOSHIBA CORPORATION SIGNED)(2010-02-16 12:12:00) Reg HKLM\SOFTWARE\Classes\DeviceDisplayObject\InterfaceClass\{0850302A-B344-4fda-9BE9-90576B8D46F0}\Shell\Bluetooth\command@ C:\Program Files\Toshiba\Bluetooth Toshiba Stack\ECCenter1.exe (Bluetooth Settings/TOSHIBA CORPORATION. SIGNED)(2009-08-06 13:28:00) Reg HKLM\SOFTWARE\Classes\DeviceDisplayObject\InterfaceClass\{70FFD812-4C7F-4C7D-926A-637B7DD852AF}\Shell\System@Icon C:\Windows\system32\imageres.dll (Windows Image Resource/Microsoft Corporation SIGNED)(2009-07-13 23:42:24) Reg HKLM\SOFTWARE\Classes\DigiGuide.ChannelExtension\shell\open\command@ C:\Program Files\DigiGuide TV Guide\digiguide.exe(2013-09-24 20:45:14) Reg HKLM\SOFTWARE\Classes\Directory@FriendlyTypeName C:\Windows\system32\shell32.dll (Windows Shell Common Dll/Microsoft Corporation SIGNED)(2013-09-26 18:21:44) Reg HKLM\SOFTWARE\Classes\Directory\Background\shell\cmd\command@ C:\Windows\system32\cmd.exe (Windows Command Processor/Microsoft Corporation SIGNED)(2013-09-25 17:36:17) Reg HKLM\SOFTWARE\Classes\Directory\shell\AddToPlaylistVLC\command@ C:\Program Files\VideoLAN\VLC\vlc.exe (VLC media player 2.1.2/VideoLAN)(2013-12-09 00:18:16) Reg HKLM\SOFTWARE\Classes\Directory\shell\cmd@ C:\Windows\system32\shell32.dll (Windows Shell Common Dll/Microsoft Corporation SIGNED)(2013-09-26 18:21:44) Reg HKLM\SOFTWARE\Classes\Directory\shell\cmd\command@ C:\Windows\system32\cmd.exe (Windows Command Processor/Microsoft Corporation SIGNED)(2013-09-25 17:36:17) Reg HKLM\SOFTWARE\Classes\Directory\shell\find\command@ C:\Windows\Explorer.exe (Windows Explorer/Microsoft Corporation SIGNED)(2013-09-25 17:37:42) Reg HKLM\SOFTWARE\Classes\Directory\shell\PlayWithVLC\command@ C:\Program Files\VideoLAN\VLC\vlc.exe (VLC media player 2.1.2/VideoLAN)(2013-12-09 00:18:16) Reg HKLM\SOFTWARE\Classes\dllfile@FriendlyTypeName C:\Windows\system32\shell32.dll (Windows Shell Common Dll/Microsoft Corporation SIGNED)(2013-09-26 18:21:44) Reg HKLM\SOFTWARE\Classes\docxfile@FriendlyTypeName C:\Program Files\Windows NT\Accessories\WORDPAD.EXE (Windows Wordpad Application/Microsoft Corporation SIGNED)(2013-09-25 17:37:35) Reg HKLM\SOFTWARE\Classes\dqyfile\Shell\open\command@ C:\PROGRA~1\MICROS~1\OFFICE11\EXCEL.EXE (Microsoft Office Excel/Microsoft Corporation SIGNED)(2013-05-29 09:08:26) Reg HKLM\SOFTWARE\Classes\Dreamweaver.Document\shell\open\command@ C:\Program Files\Macromedia\Dreamweaver 8\Dreamweaver.exe (Dreamweaver 8/Macromedia, Inc.)(2005-09-27 16:14:08) Reg HKLM\SOFTWARE\Classes\Drive\shell\cmd@ C:\Windows\system32\shell32.dll (Windows Shell Common Dll/Microsoft Corporation SIGNED)(2013-09-26 18:21:44) Reg HKLM\SOFTWARE\Classes\Drive\shell\cmd\command@ C:\Windows\system32\cmd.exe (Windows Command Processor/Microsoft Corporation SIGNED)(2013-09-25 17:36:17) Reg HKLM\SOFTWARE\Classes\Drive\shell\find\command@ C:\Windows\Explorer.exe (Windows Explorer/Microsoft Corporation SIGNED)(2013-09-25 17:37:42) Reg HKLM\SOFTWARE\Classes\drvfile@FriendlyTypeName C:\Windows\system32\shell32.dll (Windows Shell Common Dll/Microsoft Corporation SIGNED)(2013-09-26 18:21:44) Reg HKLM\SOFTWARE\Classes\DVD\shell\play\command@ C:\Program Files\Windows Media Player\wmplayer.exe (Windows Media Player/Microsoft Corporation SIGNED)(2013-09-25 17:37:02) Reg HKLM\SOFTWARE\Classes\DVD\shell\PlayWithVLC\command@ C:\Program Files\VideoLAN\VLC\vlc.exe (VLC media player 2.1.2/VideoLAN)(2013-12-09 00:18:16) Reg HKLM\SOFTWARE\Classes\DVDMaker.DVD\Shell\Burn@MUIVerb C:\Program Files\DVD Maker\dvdmaker.exe (Windows DVD Maker/Microsoft Corporation SIGNED)(2009-07-14 00:11:01) Reg HKLM\SOFTWARE\Classes\emffile\shell\open\command@ C:\Windows\system32\mspaint.exe (Paint/Microsoft Corporation SIGNED)(2009-07-13 23:43:12) Reg HKLM\SOFTWARE\Classes\Excel.Chart.5\protocol\StdFileEditing\server@ C:\PROGRA~1\MICROS~1\OFFICE11\EXCEL.EXE (Microsoft Office Excel/Microsoft Corporation SIGNED)(2013-05-29 09:08:26) Reg HKLM\SOFTWARE\Classes\exefile@FriendlyTypeName C:\Windows\System32\shell32.dll (Windows Shell Common Dll/Microsoft Corporation SIGNED)(2013-09-26 18:21:44) Reg HKLM\SOFTWARE\Classes\Explorer.AssocProtocol.search-ms@FriendlyTypeName C:\Windows\explorer.exe (Windows Explorer/Microsoft Corporation SIGNED)(2013-09-25 17:37:42) Reg HKLM\SOFTWARE\Classes\FirefoxHTML\shell\open\command@ C:\Program Files\Mozilla Firefox\firefox.exe (Firefox/Mozilla Corporation SIGNED)(2013-11-16 15:07:12) Reg HKLM\SOFTWARE\Classes\Folder\shell\open\command@ C:\Windows\Explorer.exe (Windows Explorer/Microsoft Corporation SIGNED)(2013-09-25 17:37:42) Reg HKLM\SOFTWARE\Classes\Folder\shell\opennewprocess@MUIVerb C:\Windows\system32\shell32.dll (Windows Shell Common Dll/Microsoft Corporation SIGNED)(2013-09-26 18:21:44) Reg HKLM\SOFTWARE\Classes\ftp@FriendlyTypeName C:\Windows\System32\ieframe.dll (Internet Browser/Microsoft Corporation SIGNED)(2013-12-13 11:08:39) Reg HKLM\SOFTWARE\Classes\ftp\shell\open\command@ C:\Program Files\Internet Explorer\iexplore.exe (Internet Explorer/Microsoft Corporation SIGNED)(2013-11-12 12:08:36) Reg HKLM\SOFTWARE\Classes\giffile@FriendlyTypeName C:\Windows\System32\shell32.dll (Windows Shell Common Dll/Microsoft Corporation SIGNED)(2013-09-26 18:21:44) Reg HKLM\SOFTWARE\Classes\giffile\shell\Open\command@ C:\Program Files\Internet Explorer\iexplore.exe (Internet Explorer/Microsoft Corporation SIGNED)(2013-11-12 12:08:36) Reg HKLM\SOFTWARE\Classes\group_wab_auto_file@FriendlyTypeName C:\Program Files\Common Files\System\wab32res.dll (Microsoft (R) Contacts DLL/Microsoft Corporation SIGNED)(2009-07-13 23:42:15) Reg HKLM\SOFTWARE\Classes\group_wab_auto_file\shell\edit\command@ C:\Program Files\Windows Mail\wab.exe (Windows Contacts/Microsoft Corporation SIGNED)(2013-09-25 17:36:58) Reg HKLM\SOFTWARE\Classes\hlpfile@FriendlyTypeName C:\Windows\system32\shell32.dll (Windows Shell Common Dll/Microsoft Corporation SIGNED)(2013-09-26 18:21:44) Reg HKLM\SOFTWARE\Classes\htmfile\shell\Edit with Dreamweaver 8\Command@ C:\Program Files\Macromedia\Dreamweaver 8\dreamweaver.exe (Dreamweaver 8/Macromedia, Inc.)(2005-09-27 16:14:08) Reg HKLM\SOFTWARE\Classes\htmlfile@FriendlyTypeName C:\Windows\System32\ieframe.dll (Internet Browser/Microsoft Corporation SIGNED)(2013-12-13 11:08:39) Reg HKLM\SOFTWARE\Classes\htmlfile\shell\Edit with Dreamweaver 8\Command@ C:\Program Files\Macromedia\Dreamweaver 8\dreamweaver.exe (Dreamweaver 8/Macromedia, Inc.)(2005-09-27 16:14:08) Reg HKLM\SOFTWARE\Classes\htmlfile\shell\open@MUIVerb C:\Windows\System32\ieframe.dll (Internet Browser/Microsoft Corporation SIGNED)(2013-12-13 11:08:39) Reg HKLM\SOFTWARE\Classes\htmlfile\shell\open\command@ C:\Program Files\Internet Explorer\iexplore.exe (Internet Explorer/Microsoft Corporation SIGNED)(2013-11-12 12:08:36) Reg HKLM\SOFTWARE\Classes\htmlfile\shell\opennew@MUIVerb C:\Windows\System32\ieframe.dll (Internet Browser/Microsoft Corporation SIGNED)(2013-12-13 11:08:39) Reg HKLM\SOFTWARE\Classes\htmlfile\shell\opennew\command@ C:\Program Files\Internet Explorer\iexplore.exe (Internet Explorer/Microsoft Corporation SIGNED)(2013-11-12 12:08:36) Reg HKLM\SOFTWARE\Classes\http@FriendlyTypeName C:\Windows\System32\ieframe.dll (Internet Browser/Microsoft Corporation SIGNED)(2013-12-13 11:08:39) Reg HKLM\SOFTWARE\Classes\http\shell\open\command@ C:\Program Files\Internet Explorer\iexplore.exe (Internet Explorer/Microsoft Corporation SIGNED)(2013-11-12 12:08:36) Reg HKLM\SOFTWARE\Classes\https@FriendlyTypeName C:\Windows\System32\ieframe.dll (Internet Browser/Microsoft Corporation SIGNED)(2013-12-13 11:08:39) Reg HKLM\SOFTWARE\Classes\https\shell\open\command@ C:\Program Files\Internet Explorer\iexplore.exe (Internet Explorer/Microsoft Corporation SIGNED)(2013-11-12 12:08:36) Reg HKLM\SOFTWARE\Classes\icofile@FriendlyTypeName C:\Windows\System32\shell32.dll (Windows Shell Common Dll/Microsoft Corporation SIGNED)(2013-09-26 18:21:44) Reg HKLM\SOFTWARE\Classes\IE.AssocFile.HTM@FriendlyTypeName C:\Windows\System32\ieframe.dll (Internet Browser/Microsoft Corporation SIGNED)(2013-12-13 11:08:39) Reg HKLM\SOFTWARE\Classes\IE.AssocFile.HTM\shell\open\command@ C:\Program Files\Internet Explorer\iexplore.exe (Internet Explorer/Microsoft Corporation SIGNED)(2013-11-12 12:08:36) Reg HKLM\SOFTWARE\Classes\IE.AssocFile.HTM\shell\opennew@MUIVerb C:\Windows\System32\ieframe.dll (Internet Browser/Microsoft Corporation SIGNED)(2013-12-13 11:08:39) Reg HKLM\SOFTWARE\Classes\IE.AssocFile.HTM\shell\opennew\command@ C:\Program Files\Internet Explorer\iexplore.exe (Internet Explorer/Microsoft Corporation SIGNED)(2013-11-12 12:08:36) Reg HKLM\SOFTWARE\Classes\IE.AssocFile.MHT@FriendlyTypeName C:\Windows\System32\ieframe.dll (Internet Browser/Microsoft Corporation SIGNED)(2013-12-13 11:08:39) Reg HKLM\SOFTWARE\Classes\IE.AssocFile.MHT\shell\open\command@ C:\Program Files\Internet Explorer\iexplore.exe (Internet Explorer/Microsoft Corporation SIGNED)(2013-11-12 12:08:36) Reg HKLM\SOFTWARE\Classes\IE.AssocFile.MHT\shell\opennew@MUIVerb C:\Windows\System32\ieframe.dll (Internet Browser/Microsoft Corporation SIGNED)(2013-12-13 11:08:39) Reg HKLM\SOFTWARE\Classes\IE.AssocFile.MHT\shell\opennew\command@ C:\Program Files\Internet Explorer\iexplore.exe (Internet Explorer/Microsoft Corporation SIGNED)(2013-11-12 12:08:36) Reg HKLM\SOFTWARE\Classes\IE.AssocFile.PARTIAL@FriendlyTypeName C:\Windows\System32\ieframe.dll (Internet Browser/Microsoft Corporation SIGNED)(2013-12-13 11:08:39) Reg HKLM\SOFTWARE\Classes\IE.AssocFile.PARTIAL\shell\open\command@ C:\Program Files\Internet Explorer\iexplore.exe (Internet Explorer/Microsoft Corporation SIGNED)(2013-11-12 12:08:36) Reg HKLM\SOFTWARE\Classes\IE.AssocFile.SVG@FriendlyTypeName C:\Windows\System32\ieframe.dll (Internet Browser/Microsoft Corporation SIGNED)(2013-12-13 11:08:39) Reg HKLM\SOFTWARE\Classes\IE.AssocFile.SVG\shell\open\command@ C:\Program Files\Internet Explorer\iexplore.exe (Internet Explorer/Microsoft Corporation SIGNED)(2013-11-12 12:08:36) Reg HKLM\SOFTWARE\Classes\IE.AssocFile.SVG\shell\opennew@MUIVerb C:\Windows\System32\ieframe.dll (Internet Browser/Microsoft Corporation SIGNED)(2013-12-13 11:08:39) Reg HKLM\SOFTWARE\Classes\IE.AssocFile.SVG\shell\opennew\command@ C:\Program Files\Internet Explorer\iexplore.exe (Internet Explorer/Microsoft Corporation SIGNED)(2013-11-12 12:08:36) Reg HKLM\SOFTWARE\Classes\IE.AssocFile.URL@FriendlyTypeName C:\Windows\System32\ieframe.dll (Internet Browser/Microsoft Corporation SIGNED)(2013-12-13 11:08:39) Reg HKLM\SOFTWARE\Classes\IE.AssocFile.WEBSITE\Shell\Open\Command@ C:\Program Files\Internet Explorer\iexplore.exe (Internet Explorer/Microsoft Corporation SIGNED)(2013-11-12 12:08:36) Reg HKLM\SOFTWARE\Classes\IE.AssocFile.XHT@FriendlyTypeName C:\Windows\System32\ieframe.dll (Internet Browser/Microsoft Corporation SIGNED)(2013-12-13 11:08:39) Reg HKLM\SOFTWARE\Classes\IE.AssocFile.XHT\shell\open\command@ C:\Program Files\Internet Explorer\iexplore.exe (Internet Explorer/Microsoft Corporation SIGNED)(2013-11-12 12:08:36) Reg HKLM\SOFTWARE\Classes\IE.AssocFile.XHT\shell\opennew@MUIVerb C:\Windows\System32\ieframe.dll (Internet Browser/Microsoft Corporation SIGNED)(2013-12-13 11:08:39) Reg HKLM\SOFTWARE\Classes\IE.AssocFile.XHT\shell\opennew\command@ C:\Program Files\Internet Explorer\iexplore.exe (Internet Explorer/Microsoft Corporation SIGNED)(2013-11-12 12:08:36) Reg HKLM\SOFTWARE\Classes\IE.FTP@FriendlyTypeName C:\Windows\System32\ieframe.dll (Internet Browser/Microsoft Corporation SIGNED)(2013-12-13 11:08:39) Reg HKLM\SOFTWARE\Classes\IE.FTP\shell\open\command@ C:\Program Files\Internet Explorer\iexplore.exe (Internet Explorer/Microsoft Corporation SIGNED)(2013-11-12 12:08:36) Reg HKLM\SOFTWARE\Classes\IE.HTTP@FriendlyTypeName C:\Windows\System32\ieframe.dll (Internet Browser/Microsoft Corporation SIGNED)(2013-12-13 11:08:39) Reg HKLM\SOFTWARE\Classes\IE.HTTP\Application@ApplicationIcon C:\Program Files\Internet Explorer\iexplore.exe (Internet Explorer/Microsoft Corporation SIGNED)(2013-11-12 12:08:36) Reg HKLM\SOFTWARE\Classes\IE.HTTPS@FriendlyTypeName C:\Windows\System32\ieframe.dll (Internet Browser/Microsoft Corporation SIGNED)(2013-12-13 11:08:39) Reg HKLM\SOFTWARE\Classes\IE.HTTPS\Application@ApplicationIcon C:\Program Files\Internet Explorer\iexplore.exe (Internet Explorer/Microsoft Corporation SIGNED)(2013-11-12 12:08:36) Reg HKLM\SOFTWARE\Classes\inffile@FriendlyTypeName C:\Windows\System32\setupapi.dll (Windows Setup API/Microsoft Corporation SIGNED)(2013-09-25 17:37:25) Reg HKLM\SOFTWARE\Classes\inifile@FriendlyTypeName C:\Windows\system32\shell32.dll (Windows Shell Common Dll/Microsoft Corporation SIGNED)(2013-09-26 18:21:44) Reg HKLM\SOFTWARE\Classes\Installer\Products\0A72DDEF603BFE54FB855B7204B6248C@ProductIcon C:\Windows\Installer\{FEDD27A0-B306-45EF-BF58-B527406B42C8}\ARPPRODUCTICON.exe Reg HKLM\SOFTWARE\Classes\Installer\Products\7C20ED6D74F14D1159510001A54E8BA9@ProductIcon C:\Windows\Installer\{D6DE02C7-1F47-11D4-9515-00105AE4B89A}\psp7.exe Reg HKLM\SOFTWARE\Classes\Installer\Products\8E58128CB72C4FE402013333CBC2B2D6@ProductIcon C:\Windows\Installer\{C82185E8-C27B-4EF4-2010-3333BC2C2B6D}\ARX_EUR_17_Main_Application_icon.exe Reg HKLM\SOFTWARE\Classes\Installer\Products\BFB6BBEC807D99F46A33CB62000EE16F@ProductIcon C:\Windows\Installer\{CEBB6BFB-D708-4F99-A633-BC2600E01EF6}\ARPPRODUCTICON.exe Reg HKLM\SOFTWARE\Classes\InternetShortcut@FriendlyTypeName C:\Windows\System32\ieframe.dll (Internet Browser/Microsoft Corporation SIGNED)(2013-12-13 11:08:39) Reg HKLM\SOFTWARE\Classes\JNLPFile\Shell\Open\Command@ C:\Program Files\Java\jre7\bin\javaws.exe (Java(TM) Web Start Launcher/Oracle Corporation SIGNED)(2014-02-02 00:13:17) Reg HKLM\SOFTWARE\Classes\jntfile@FriendlyTypeName C:\Program Files\Windows Journal\Journal.exe (Windows Journal/Microsoft Corporation SIGNED)(2013-09-25 17:36:18) Reg HKLM\SOFTWARE\Classes\JobObject@FriendlyTypeName C:\Windows\system32\schedsvc.dll (Task Scheduler Service/Microsoft Corporation SIGNED)(2013-09-25 17:37:25) Reg HKLM\SOFTWARE\Classes\jpegfile@FriendlyTypeName C:\Windows\System32\shell32.dll (Windows Shell Common Dll/Microsoft Corporation SIGNED)(2013-09-26 18:21:44) Reg HKLM\SOFTWARE\Classes\JSEFile@FriendlyTypeName C:\Windows\System32\wshext.dll (Microsoft � Shell Extension for Windows Script Host/Microsoft Corporation SIGNED)(2009-07-13 23:42:38) Reg HKLM\SOFTWARE\Classes\JSFile\Shell\edit\command@ C:\Program Files\Macromedia\Dreamweaver 8\dreamweaver.exe (Dreamweaver 8/Macromedia, Inc.)(2005-09-27 16:14:08) Reg HKLM\SOFTWARE\Classes\JSFile\Shell\Open2@MUIVerb C:\Windows\System32\wshext.dll (Microsoft � Shell Extension for Windows Script Host/Microsoft Corporation SIGNED)(2009-07-13 23:42:38) Reg HKLM\SOFTWARE\Classes\jspfile\shell\edit\command@ C:\Program Files\Macromedia\Dreamweaver 8\dreamweaver.exe (Dreamweaver 8/Macromedia, Inc.)(2005-09-27 16:14:08) Reg HKLM\SOFTWARE\Classes\jtpfile@FriendlyTypeName C:\Program Files\Windows Journal\Journal.exe (Windows Journal/Microsoft Corporation SIGNED)(2013-09-25 17:36:18) Reg HKLM\SOFTWARE\Classes\LDAP\shell\open\command@ C:\Program Files\Windows Mail\wab.exe (Windows Contacts/Microsoft Corporation SIGNED)(2013-09-25 17:36:58) Reg HKLM\SOFTWARE\Classes\LibraryFolder@FriendlyTypeName C:\Windows\system32\shell32.dll (Windows Shell Common Dll/Microsoft Corporation SIGNED)(2013-09-26 18:21:44) Reg HKLM\SOFTWARE\Classes\LpkSetup.1@FriendlyTypeName C:\Windows\system32\lpksetup.exe (Language Pack Installer/Microsoft Corporation SIGNED)(2013-09-25 17:38:30) Reg HKLM\SOFTWARE\Classes\Macromedia.DesignNotes\Shell\Edit with Dreamweaver 8\Command@ C:\Program Files\Macromedia\Dreamweaver 8\Dreamweaver.exe (Dreamweaver 8/Macromedia, Inc.)(2005-09-27 16:14:08) Reg HKLM\SOFTWARE\Classes\Macromedia.Extension.Information\shell\Open\command@ C:\Program Files\Macromedia\Extension Manager\Extension Manager.exe (Extension Manager/Macromedia, Inc.)(2005-09-22 01:19:46) Reg HKLM\SOFTWARE\Classes\MacromediaColdFusionComponent\shell\edit\Command@ C:\Program Files\Macromedia\Dreamweaver 8\dreamweaver.exe (Dreamweaver 8/Macromedia, Inc.)(2005-09-27 16:14:08) Reg HKLM\SOFTWARE\Classes\MacromediaFlashPaper.MacromediaFlashPaper\shell\open\command@ C:\Program Files\Mozilla Firefox\firefox.exe (Firefox/Mozilla Corporation SIGNED)(2013-11-16 15:07:12) Reg HKLM\SOFTWARE\Classes\mhtmlfile@FriendlyTypeName C:\Windows\System32\ieframe.dll (Internet Browser/Microsoft Corporation SIGNED)(2013-12-13 11:08:39) Reg HKLM\SOFTWARE\Classes\mhtmlfile\shell\open\command@ C:\Program Files\Internet Explorer\iexplore.exe (Internet Explorer/Microsoft Corporation SIGNED)(2013-11-12 12:08:36) Reg HKLM\SOFTWARE\Classes\mhtmlfile\shell\opennew@MUIVerb C:\Windows\System32\ieframe.dll (Internet Browser/Microsoft Corporation SIGNED)(2013-12-13 11:08:39) Reg HKLM\SOFTWARE\Classes\mhtmlfile\shell\opennew\command@ C:\Program Files\Internet Explorer\iexplore.exe (Internet Explorer/Microsoft Corporation SIGNED)(2013-11-12 12:08:36) Reg HKLM\SOFTWARE\Classes\Microsoft.InformationCard@InfoTip C:\Windows\System32\icardres.dll (Windows CardSpace/Microsoft Corporation SIGNED)(2009-07-14 00:36:29) Reg HKLM\SOFTWARE\Classes\Microsoft.PowerShellConsole.1@FriendlyTypeName C:\Windows\system32\windowspowershell\v1.0\powershell.exe (Windows PowerShell/Microsoft Corporation SIGNED)(2009-07-13 23:32:37) Reg HKLM\SOFTWARE\Classes\Microsoft.Website@FriendlyTypeName C:\Windows\System32\ieframe.dll (Internet Browser/Microsoft Corporation SIGNED)(2013-12-13 11:08:39) Reg HKLM\SOFTWARE\Classes\Microsoft.Website\Shell\Open\Command@ C:\Program Files\Internet Explorer\iexplore.exe (Internet Explorer/Microsoft Corporation SIGNED)(2013-11-12 12:08:36) Reg HKLM\SOFTWARE\Classes\Microsoft.WindowsCardSpaceBackup@InfoTip C:\Windows\System32\icardres.dll (Windows CardSpace/Microsoft Corporation SIGNED)(2009-07-14 00:36:29) Reg HKLM\SOFTWARE\Classes\migfile@FriendlyTypeName C:\Windows\system32\migwiz\wet.dll (Windows Easy Transfer/Microsoft Corporation SIGNED)(2013-09-25 17:38:09) Reg HKLM\SOFTWARE\Classes\migfile\shell\open\command@ C:\Windows\System32\migwiz\migwiz.exe (Windows Easy Transfer Application/Microsoft Corporation SIGNED)(2009-07-13 23:17:34) Reg HKLM\SOFTWARE\Classes\MMS\shell\open\command@ C:\Program Files\Windows Media Player\wmplayer.exe (Windows Media Player/Microsoft Corporation SIGNED)(2013-09-25 17:37:02) Reg HKLM\SOFTWARE\Classes\money\Shell\Open\Command@ C:\Program Files\Microsoft Money\System\msmoney.exe (Microsoft Money/Microsoft Corporation)(2002-07-17 10:00:00) Reg HKLM\SOFTWARE\Classes\mscfile\shell\runasuser@ C:\Windows\system32\shell32.dll (Windows Shell Common Dll/Microsoft Corporation SIGNED)(2013-09-26 18:21:44) Reg HKLM\SOFTWARE\Classes\Msi.Package@FriendlyTypeName C:\Windows\System32\msimsg.dll (Windows� Installer International Messages/Microsoft Corporation SIGNED)(2009-07-13 23:31:17) Reg HKLM\SOFTWARE\Classes\Msi.Package\shell\Open\command@ C:\Windows\System32\msiexec.exe (Windows� installer/Microsoft Corporation SIGNED)(2013-09-25 17:37:17) Reg HKLM\SOFTWARE\Classes\Msi.Package\shell\Repair@MUIVerb C:\Windows\System32\msimsg.dll (Windows� Installer International Messages/Microsoft Corporation SIGNED)(2009-07-13 23:31:17) Reg HKLM\SOFTWARE\Classes\Msi.Package\shell\Repair\command@ C:\Windows\System32\msiexec.exe (Windows� installer/Microsoft Corporation SIGNED)(2013-09-25 17:37:17) Reg HKLM\SOFTWARE\Classes\Msi.Package\shell\runasuser@ C:\Windows\system32\shell32.dll (Windows Shell Common Dll/Microsoft Corporation SIGNED)(2013-09-26 18:21:44) Reg HKLM\SOFTWARE\Classes\Msi.Package\shell\Uninstall@MUIVerb C:\Windows\System32\msimsg.dll (Windows� Installer International Messages/Microsoft Corporation SIGNED)(2009-07-13 23:31:17) Reg HKLM\SOFTWARE\Classes\Msi.Package\shell\Uninstall\command@ C:\Windows\System32\msiexec.exe (Windows� installer/Microsoft Corporation SIGNED)(2013-09-25 17:37:17) Reg HKLM\SOFTWARE\Classes\Msi.Patch@FriendlyTypeName C:\Windows\System32\msimsg.dll (Windows� Installer International Messages/Microsoft Corporation SIGNED)(2009-07-13 23:31:17) Reg HKLM\SOFTWARE\Classes\Msi.Patch\shell\Open\command@ C:\Windows\System32\msiexec.exe (Windows� installer/Microsoft Corporation SIGNED)(2013-09-25 17:37:17) Reg HKLM\SOFTWARE\Classes\NetServer\shell\remotedesktop@MUIVerb C:\Windows\system32\mstsc.exe (Remote Desktop Connection/Microsoft Corporation SIGNED)(2013-09-25 17:37:15) Reg HKLM\SOFTWARE\Classes\Network\SharingHandler@ C:\Windows\system32\ntshrui.dll (Shell extensions for sharing/Microsoft Corporation SIGNED)(2013-09-25 17:37:19) Reg HKLM\SOFTWARE\Classes\NetworkExplorerPlugins\urn:schemas-microsoft-com:device:MediaCenterExtender:1\Shell\Configure@MUIVerb C:\Windows\eHome\ehres.dll (Media Center Resources/Microsoft Corporation SIGNED)(2009-07-14 00:11:14) Reg HKLM\SOFTWARE\Classes\NetworkExplorerPlugins\urn:schemas-upnp-org:device:MediaServer:1\shell\Open Media Player@MUIVerb C:\Windows\System32\wmploc.dll (Windows Media Player Resources/Microsoft Corporation SIGNED)(2013-09-25 17:37:01) Reg HKLM\SOFTWARE\Classes\NetworkExplorerPlugins\urn:schemas-upnp-org:device:MediaServer:1\shell\Open Media Player\command@ C:\Program Files\Windows Media Player\wmplayer.exe (Windows Media Player/Microsoft Corporation SIGNED)(2013-09-25 17:37:02) Reg HKLM\SOFTWARE\Classes\ocxfile@FriendlyTypeName C:\Windows\system32\shell32.dll (Windows Shell Common Dll/Microsoft Corporation SIGNED)(2013-09-26 18:21:44) Reg HKLM\SOFTWARE\Classes\ODCfile\shell\View\command@ C:\Program Files\Internet Explorer\IEXPLORE.EXE (Internet Explorer/Microsoft Corporation SIGNED)(2013-11-12 12:08:36) Reg HKLM\SOFTWARE\Classes\odtfile@FriendlyTypeName C:\Program Files\Windows NT\Accessories\WORDPAD.EXE (Windows Wordpad Application/Microsoft Corporation SIGNED)(2013-09-25 17:37:35) Reg HKLM\SOFTWARE\Classes\OLETransactionManagers\MSDTC@DLL C:\Windows\system32\MSDTCPRX.DLL (Microsoft Distributed Transaction Coordinator OLE Transactions Interface Proxy DLL/Microsoft Corporation SIGNED)(2009-07-13 23:44:23) Reg HKLM\SOFTWARE\Classes\opensearchblocked@FriendlyTypeName C:\Windows\system32\shell32.dll (Windows Shell Common Dll/Microsoft Corporation SIGNED)(2013-09-26 18:21:44) Reg HKLM\SOFTWARE\Classes\opensearchdescription\shell\open\command@ C:\Windows\explorer.exe (Windows Explorer/Microsoft Corporation SIGNED)(2013-09-25 17:37:42) Reg HKLM\SOFTWARE\Classes\opensearchfilefolderresult@FriendlyTypeName C:\Windows\system32\shell32.dll (Windows Shell Common Dll/Microsoft Corporation SIGNED)(2013-09-26 18:21:44) Reg HKLM\SOFTWARE\Classes\oqyfile\Shell\open\command@ C:\PROGRA~1\MICROS~1\OFFICE11\EXCEL.EXE (Microsoft Office Excel/Microsoft Corporation SIGNED)(2013-05-29 09:08:26) Reg HKLM\SOFTWARE\Classes\otffile@FriendlyTypeName C:\Windows\system32\shell32.dll (Windows Shell Common Dll/Microsoft Corporation SIGNED)(2013-09-26 18:21:44) Reg HKLM\SOFTWARE\Classes\Paint.Picture\protocol\StdFileEditing\server@ C:\Windows\system32\mspaint.exe (Paint/Microsoft Corporation SIGNED)(2009-07-13 23:43:12) Reg HKLM\SOFTWARE\Classes\PAR2_Recovery_Volume\shell\open\command@ C:\Program Files\QuickPar\QuickPar.exe (QuickPar/Peter B Clements)(2004-07-03 09:34:17) Reg HKLM\SOFTWARE\Classes\PBrush\protocol\StdFileEditing\server@ C:\Windows\system32\mspaint.exe (Paint/Microsoft Corporation SIGNED)(2009-07-13 23:43:12) Reg HKLM\SOFTWARE\Classes\PDXFileType\shell\Read\command@ C:\Program Files\Adobe\Reader 11.0\Reader\AcroRd32.exe (Adobe Reader /CA SIGNED)(2013-12-21 06:04:26) Reg HKLM\SOFTWARE\Classes\php3file\Shell\edit\Command@ C:\Program Files\Macromedia\Dreamweaver 8\dreamweaver.exe (Dreamweaver 8/Macromedia, Inc.)(2005-09-27 16:14:08) Reg HKLM\SOFTWARE\Classes\pjpegfile@FriendlyTypeName C:\Windows\System32\shell32.dll (Windows Shell Common Dll/Microsoft Corporation SIGNED)(2013-09-26 18:21:44) Reg HKLM\SOFTWARE\Classes\pnffile@FriendlyTypeName C:\Windows\System32\setupapi.dll (Windows Setup API/Microsoft Corporation SIGNED)(2013-09-25 17:37:25) Reg HKLM\SOFTWARE\Classes\pngfile@FriendlyTypeName C:\Windows\System32\shell32.dll (Windows Shell Common Dll/Microsoft Corporation SIGNED)(2013-09-26 18:21:44) Reg HKLM\SOFTWARE\Classes\Publishing Folder\shell\explore\command@ C:\Windows\explorer.exe (Windows Explorer/Microsoft Corporation SIGNED)(2013-09-25 17:37:42) Reg HKLM\SOFTWARE\Classes\RDBFileProperties.1@FriendlyTypeName C:\Windows\system32\sysmain.dll (Superfetch Service Host/Microsoft Corporation SIGNED)(2013-09-25 17:37:38) Reg HKLM\SOFTWARE\Classes\RDP.File@FriendlyTypeName C:\Windows\system32\mstsc.exe (Remote Desktop Connection/Microsoft Corporation SIGNED)(2013-09-25 17:37:15) Reg HKLM\SOFTWARE\Classes\RemoteAssistance.1@InfoTip C:\Windows\system32\msra.exe (Windows Remote Assistance/Microsoft Corporation SIGNED)(2009-07-13 23:20:11) Reg HKLM\SOFTWARE\Classes\rlefile\shell\open\command@ C:\Windows\system32\mspaint.exe (Paint/Microsoft Corporation SIGNED)(2009-07-13 23:43:12) Reg HKLM\SOFTWARE\Classes\rlogin@FriendlyTypeName C:\Windows\System32\ieframe.dll (Internet Browser/Microsoft Corporation SIGNED)(2013-12-13 11:08:39) Reg HKLM\SOFTWARE\Classes\rqyfile\Shell\open\command@ C:\PROGRA~1\MICROS~1\OFFICE11\EXCEL.EXE (Microsoft Office Excel/Microsoft Corporation SIGNED)(2013-05-29 09:08:26) Reg HKLM\SOFTWARE\Classes\rtffile@FriendlyTypeName C:\Program Files\Windows NT\Accessories\WORDPAD.EXE (Windows Wordpad Application/Microsoft Corporation SIGNED)(2013-09-25 17:37:35) Reg HKLM\SOFTWARE\Classes\scrfile\shell\config@MUIVerb C:\Windows\system32\shell32.dll (Windows Shell Common Dll/Microsoft Corporation SIGNED)(2013-09-26 18:21:44) Reg HKLM\SOFTWARE\Classes\SDConfig.AutoPlayHandler\shell\config\command@ C:\Windows\system32\sdclt.exe (Microsoft� Windows Backup/Microsoft Corporation SIGNED)(2013-09-25 17:36:50) Reg HKLM\SOFTWARE\Classes\search@FriendlyTypeName C:\Windows\explorer.exe (Windows Explorer/Microsoft Corporation SIGNED)(2013-09-25 17:37:42) Reg HKLM\SOFTWARE\Classes\SearchConnectorFolder@FriendlyTypeName C:\Windows\system32\shell32.dll (Windows Shell Common Dll/Microsoft Corporation SIGNED)(2013-09-26 18:21:44) Reg HKLM\SOFTWARE\Classes\ShapewareVISIO10\protocol\StdFileEditing\server@ C:\PROGRA~1\MICROS~1\Visio11\VISIO.EXE (Microsoft Office Visio/Microsoft Corporation SIGNED)(2007-06-20 05:34:38) Reg HKLM\SOFTWARE\Classes\SHCmdFile\shell\open\command@ C:\Windows\explorer.exe (Windows Explorer/Microsoft Corporation SIGNED)(2013-09-25 17:37:42) Reg HKLM\SOFTWARE\Classes\SOFTWARE\Adobe\Acrobat\Exe@ C:\Program Files\Adobe\Reader 11.0\Reader\AcroRd32.exe (Adobe Reader /CA SIGNED)(2013-12-21 06:04:26) Reg HKLM\SOFTWARE\Classes\svgfile@FriendlyTypeName C:\Windows\System32\ieframe.dll (Internet Browser/Microsoft Corporation SIGNED)(2013-12-13 11:08:39) Reg HKLM\SOFTWARE\Classes\svgfile\shell\open\command@ C:\Program Files\Internet Explorer\iexplore.exe (Internet Explorer/Microsoft Corporation SIGNED)(2013-11-12 12:08:36) Reg HKLM\SOFTWARE\Classes\svgfile\shell\opennew@MUIVerb C:\Windows\System32\ieframe.dll (Internet Browser/Microsoft Corporation SIGNED)(2013-12-13 11:08:39) Reg HKLM\SOFTWARE\Classes\svgfile\shell\opennew\command@ C:\Program Files\Internet Explorer\iexplore.exe (Internet Explorer/Microsoft Corporation SIGNED)(2013-11-12 12:08:36) Reg HKLM\SOFTWARE\Classes\sysfile@FriendlyTypeName C:\Windows\system32\shell32.dll (Windows Shell Common Dll/Microsoft Corporation SIGNED)(2013-09-26 18:21:44) Reg HKLM\SOFTWARE\Classes\SystemFileAssociations\.bmp\Shell\setdesktopwallpaper@ C:\Windows\system32\stobject.dll (Systray shell service object/Microsoft Corporation SIGNED)(2013-09-25 17:36:32) Reg HKLM\SOFTWARE\Classes\SystemFileAssociations\.bmp\Shell\setdesktopwallpaper\Command@ C:\Windows\Explorer.exe (Windows Explorer/Microsoft Corporation SIGNED)(2013-09-25 17:37:42) Reg HKLM\SOFTWARE\Classes\SystemFileAssociations\.dib\Shell\setdesktopwallpaper@ C:\Windows\system32\stobject.dll (Systray shell service object/Microsoft Corporation SIGNED)(2013-09-25 17:36:32) Reg HKLM\SOFTWARE\Classes\SystemFileAssociations\.dib\Shell\setdesktopwallpaper\Command@ C:\Windows\Explorer.exe (Windows Explorer/Microsoft Corporation SIGNED)(2013-09-25 17:37:42) Reg HKLM\SOFTWARE\Classes\SystemFileAssociations\.docx\shell\open\command@ C:\Program Files\Windows NT\Accessories\WORDPAD.EXE (Windows Wordpad Application/Microsoft Corporation SIGNED)(2013-09-25 17:37:35) Reg HKLM\SOFTWARE\Classes\SystemFileAssociations\.gif\Shell\setdesktopwallpaper@ C:\Windows\system32\stobject.dll (Systray shell service object/Microsoft Corporation SIGNED)(2013-09-25 17:36:32) Reg HKLM\SOFTWARE\Classes\SystemFileAssociations\.gif\Shell\setdesktopwallpaper\Command@ C:\Windows\Explorer.exe (Windows Explorer/Microsoft Corporation SIGNED)(2013-09-25 17:37:42) Reg HKLM\SOFTWARE\Classes\SystemFileAssociations\.jfif\Shell\setdesktopwallpaper@ C:\Windows\system32\stobject.dll (Systray shell service object/Microsoft Corporation SIGNED)(2013-09-25 17:36:32) Reg HKLM\SOFTWARE\Classes\SystemFileAssociations\.jfif\Shell\setdesktopwallpaper\Command@ C:\Windows\Explorer.exe (Windows Explorer/Microsoft Corporation SIGNED)(2013-09-25 17:37:42) Reg HKLM\SOFTWARE\Classes\SystemFileAssociations\.jpe\Shell\setdesktopwallpaper@ C:\Windows\system32\stobject.dll (Systray shell service object/Microsoft Corporation SIGNED)(2013-09-25 17:36:32) Reg HKLM\SOFTWARE\Classes\SystemFileAssociations\.jpe\Shell\setdesktopwallpaper\Command@ C:\Windows\Explorer.exe (Windows Explorer/Microsoft Corporation SIGNED)(2013-09-25 17:37:42) Reg HKLM\SOFTWARE\Classes\SystemFileAssociations\.jpeg\Shell\setdesktopwallpaper@ C:\Windows\system32\stobject.dll (Systray shell service object/Microsoft Corporation SIGNED)(2013-09-25 17:36:32) Reg HKLM\SOFTWARE\Classes\SystemFileAssociations\.jpeg\Shell\setdesktopwallpaper\Command@ C:\Windows\Explorer.exe (Windows Explorer/Microsoft Corporation SIGNED)(2013-09-25 17:37:42) Reg HKLM\SOFTWARE\Classes\SystemFileAssociations\.jpg\Shell\setdesktopwallpaper@ C:\Windows\system32\stobject.dll (Systray shell service object/Microsoft Corporation SIGNED)(2013-09-25 17:36:32) Reg HKLM\SOFTWARE\Classes\SystemFileAssociations\.jpg\Shell\setdesktopwallpaper\Command@ C:\Windows\Explorer.exe (Windows Explorer/Microsoft Corporation SIGNED)(2013-09-25 17:37:42) Reg HKLM\SOFTWARE\Classes\SystemFileAssociations\.odt\shell\open\command@ C:\Program Files\Windows NT\Accessories\WORDPAD.EXE (Windows Wordpad Application/Microsoft Corporation SIGNED)(2013-09-25 17:37:35) Reg HKLM\SOFTWARE\Classes\SystemFileAssociations\.png\Shell\setdesktopwallpaper@ C:\Windows\system32\stobject.dll (Systray shell service object/Microsoft Corporation SIGNED)(2013-09-25 17:36:32) Reg HKLM\SOFTWARE\Classes\SystemFileAssociations\.png\Shell\setdesktopwallpaper\Command@ C:\Windows\Explorer.exe (Windows Explorer/Microsoft Corporation SIGNED)(2013-09-25 17:37:42) Reg HKLM\SOFTWARE\Classes\SystemFileAssociations\.rtf\shell\open\command@ C:\Program Files\Windows NT\Accessories\WORDPAD.EXE (Windows Wordpad Application/Microsoft Corporation SIGNED)(2013-09-25 17:37:35) Reg HKLM\SOFTWARE\Classes\SystemFileAssociations\.tif\Shell\setdesktopwallpaper@ C:\Windows\system32\stobject.dll (Systray shell service object/Microsoft Corporation SIGNED)(2013-09-25 17:36:32) Reg HKLM\SOFTWARE\Classes\SystemFileAssociations\.tif\Shell\setdesktopwallpaper\Command@ C:\Windows\Explorer.exe (Windows Explorer/Microsoft Corporation SIGNED)(2013-09-25 17:37:42) Reg HKLM\SOFTWARE\Classes\SystemFileAssociations\.tiff\Shell\setdesktopwallpaper@ C:\Windows\system32\stobject.dll (Systray shell service object/Microsoft Corporation SIGNED)(2013-09-25 17:36:32) Reg HKLM\SOFTWARE\Classes\SystemFileAssociations\.tiff\Shell\setdesktopwallpaper\Command@ C:\Windows\Explorer.exe (Windows Explorer/Microsoft Corporation SIGNED)(2013-09-25 17:37:42) Reg HKLM\SOFTWARE\Classes\SystemFileAssociations\.wdp\Shell\setdesktopwallpaper@ C:\Windows\system32\stobject.dll (Systray shell service object/Microsoft Corporation SIGNED)(2013-09-25 17:36:32) Reg HKLM\SOFTWARE\Classes\SystemFileAssociations\.wdp\Shell\setdesktopwallpaper\Command@ C:\Windows\Explorer.exe (Windows Explorer/Microsoft Corporation SIGNED)(2013-09-25 17:37:42) Reg HKLM\SOFTWARE\Classes\SystemFileAssociations\image\shell\edit\command@ C:\Windows\system32\mspaint.exe (Paint/Microsoft Corporation SIGNED)(2009-07-13 23:43:12) Reg HKLM\SOFTWARE\Classes\telnet@FriendlyTypeName C:\Windows\System32\ieframe.dll (Internet Browser/Microsoft Corporation SIGNED)(2013-12-13 11:08:39) Reg HKLM\SOFTWARE\Classes\textfile@FriendlyTypeName C:\Program Files\Windows NT\Accessories\WORDPAD.EXE (Windows Wordpad Application/Microsoft Corporation SIGNED)(2013-09-25 17:37:35) Reg HKLM\SOFTWARE\Classes\TIFImage.Document@FriendlyTypeName C:\Windows\System32\shell32.dll (Windows Shell Common Dll/Microsoft Corporation SIGNED)(2013-09-26 18:21:44) Reg HKLM\SOFTWARE\Classes\tn3270@FriendlyTypeName C:\Windows\System32\ieframe.dll (Internet Browser/Microsoft Corporation SIGNED)(2013-12-13 11:08:39) Reg HKLM\SOFTWARE\Classes\ttcfile@FriendlyTypeName C:\Windows\system32\shell32.dll (Windows Shell Common Dll/Microsoft Corporation SIGNED)(2013-09-26 18:21:44) Reg HKLM\SOFTWARE\Classes\VBEFile@FriendlyTypeName C:\Windows\System32\wshext.dll (Microsoft � Shell Extension for Windows Script Host/Microsoft Corporation SIGNED)(2009-07-13 23:42:38) Reg HKLM\SOFTWARE\Classes\vcard_wab_auto_file@FriendlyTypeName C:\Program Files\Common Files\System\wab32res.dll (Microsoft (R) Contacts DLL/Microsoft Corporation SIGNED)(2009-07-13 23:42:15) Reg HKLM\SOFTWARE\Classes\vcard_wab_auto_file\shell\open\command@ C:\Program Files\Windows Mail\wab.exe (Windows Contacts/Microsoft Corporation SIGNED)(2013-09-25 17:36:58) Reg HKLM\SOFTWARE\Classes\Visio.Drawing.11\protocol\StdFileEditing\server@ C:\PROGRA~1\MICROS~1\Visio11\VISIO.EXE (Microsoft Office Visio/Microsoft Corporation SIGNED)(2007-06-20 05:34:38) Reg HKLM\SOFTWARE\Classes\VLC.3g2\shell\AddToPlaylistVLC\command@ C:\Program Files\VideoLAN\VLC\vlc.exe (VLC media player 2.1.2/VideoLAN)(2013-12-09 00:18:16) Reg HKLM\SOFTWARE\Classes\vxdfile@FriendlyTypeName C:\Windows\system32\shell32.dll (Windows Shell Common Dll/Microsoft Corporation SIGNED)(2013-09-26 18:21:44) Reg HKLM\SOFTWARE\Classes\wab_auto_file@FriendlyTypeName C:\Program Files\Common Files\System\wab32res.dll (Microsoft (R) Contacts DLL/Microsoft Corporation SIGNED)(2009-07-13 23:42:15) Reg HKLM\SOFTWARE\Classes\wab_auto_file\shell\open\command@ C:\Program Files\Windows Mail\wab.exe (Windows Contacts/Microsoft Corporation SIGNED)(2013-09-25 17:36:58) Reg HKLM\SOFTWARE\Classes\wbcatfile@FriendlyTypeName C:\Windows\system32\sdclt.exe (Microsoft� Windows Backup/Microsoft Corporation SIGNED)(2013-09-25 17:36:50) Reg HKLM\SOFTWARE\Classes\wcxfile@FriendlyTypeName C:\Windows\system32\tsworkspace.dll (RemoteApp and Desktop Connection Component/Microsoft Corporation SIGNED)(2013-09-25 17:37:06) Reg HKLM\SOFTWARE\Classes\Windows.CompositeFont@FriendlyTypeName C:\Windows\System32\PresentationHost.exe (Windows Presentation Foundation Host/Microsoft Corporation SIGNED)(2013-09-25 17:37:30) Reg HKLM\SOFTWARE\Classes\Windows.DVD.Maker@FriendlyTypeName C:\Program Files\DVD Maker\DVDMaker.exe (Windows DVD Maker/Microsoft Corporation SIGNED)(2009-07-14 00:11:01) Reg HKLM\SOFTWARE\Classes\Windows.gadget\shell\open\command@ C:\Program Files\Windows Sidebar\Sidebar.exe (Windows Desktop Gadgets/Microsoft Corporation SIGNED)(2013-09-25 17:36:32) Reg HKLM\SOFTWARE\Classes\Windows.XamlDocument@InfoTip C:\Windows\System32\PresentationHost.exe (Windows Presentation Foundation Host/Microsoft Corporation SIGNED)(2013-09-25 17:37:30) Reg HKLM\SOFTWARE\Classes\WindowsBackupFolderOptions\shell\openDesktopIni@ C:\Windows\system32\sdclt.exe (Microsoft� Windows Backup/Microsoft Corporation SIGNED)(2013-09-25 17:36:50) Reg HKLM\SOFTWARE\Classes\windowsmediacenterapp@FriendlyTypeName C:\Windows\ehome\ehres.dll (Media Center Resources/Microsoft Corporation SIGNED)(2009-07-14 00:11:14) Reg HKLM\SOFTWARE\Classes\WinRAR\shell\open\command@ C:\Program Files\WinRAR\WinRAR.exe (WinRAR (2013-09-24 20:10:43) Reg HKLM\SOFTWARE\Classes\WMEncSession\shell\Open\command@ C:\Program Files\Windows Media Components\Encoder\wmenc.exe (Windows Media Encoder/Microsoft Corporation)(2002-12-11 19:38:52) Reg HKLM\SOFTWARE\Classes\wmffile\shell\open\command@ C:\Windows\system32\mspaint.exe (Paint/Microsoft Corporation SIGNED)(2009-07-13 23:43:12) Reg HKLM\SOFTWARE\Classes\WMP.AudioCD\Shell\Play@MUIVerb C:\Windows\system32\wmploc.dll (Windows Media Player Resources/Microsoft Corporation SIGNED)(2013-09-25 17:37:01) Reg HKLM\SOFTWARE\Classes\WMP.AudioCD\Shell\Play\command@ C:\Program Files\Windows Media Player\wmplayer.exe (Windows Media Player/Microsoft Corporation SIGNED)(2013-09-25 17:37:02) Reg HKLM\SOFTWARE\Classes\WMP.BurnCD\Shell\Burn@MUIVerb C:\Windows\system32\wmploc.dll (Windows Media Player Resources/Microsoft Corporation SIGNED)(2013-09-25 17:37:01) Reg HKLM\SOFTWARE\Classes\WMP.BurnCD\Shell\Burn\Command@ C:\Program Files\Windows Media Player\wmplayer.exe (Windows Media Player/Microsoft Corporation SIGNED)(2013-09-25 17:37:02) Reg HKLM\SOFTWARE\Classes\WMP.DVD\Shell\Play@MUIVerb C:\Windows\system32\wmploc.dll (Windows Media Player Resources/Microsoft Corporation SIGNED)(2013-09-25 17:37:01) Reg HKLM\SOFTWARE\Classes\WMP.DVD\Shell\Play\command@ C:\Program Files\Windows Media Player\wmplayer.exe (Windows Media Player/Microsoft Corporation SIGNED)(2013-09-25 17:37:02) Reg HKLM\SOFTWARE\Classes\WMP.VCD\Shell\Play@MUIVerb C:\Windows\system32\wmploc.dll (Windows Media Player Resources/Microsoft Corporation SIGNED)(2013-09-25 17:37:01) Reg HKLM\SOFTWARE\Classes\WMP.VCD\Shell\Play\command@ C:\Program Files\Windows Media Player\wmplayer.exe (Windows Media Player/Microsoft Corporation SIGNED)(2013-09-25 17:37:02) Reg HKLM\SOFTWARE\Classes\Word.Document.6\protocol\StdFileEditing\server@ C:\PROGRA~1\MICROS~1\OFFICE11\WINWORD.EXE (Microsoft Office Word/Microsoft Corporation SIGNED)(2013-08-27 09:04:02) Reg HKLM\SOFTWARE\Classes\Wordpad.Document.1@FriendlyTypeName C:\Program Files\Windows NT\Accessories\WORDPAD.EXE (Windows Wordpad Application/Microsoft Corporation SIGNED)(2013-09-25 17:37:35) Reg HKLM\SOFTWARE\Classes\WSFFile@FriendlyTypeName C:\Windows\System32\wshext.dll (Microsoft � Shell Extension for Windows Script Host/Microsoft Corporation SIGNED)(2009-07-13 23:42:38) Reg HKLM\SOFTWARE\Classes\XEV.GenericApp\shell\edit\Command@ C:\Program Files\Macromedia\Dreamweaver 8\dreamweaver.exe (Dreamweaver 8/Macromedia, Inc.)(2005-09-27 16:14:08) Reg HKLM\SOFTWARE\Classes\XEV.GenericApp\shell\open\command@ C:\Program Files\Internet Explorer\iexplore.exe (Internet Explorer/Microsoft Corporation SIGNED)(2013-11-12 12:08:36) Reg HKLM\SOFTWARE\Classes\xhtmlfile@FriendlyTypeName C:\Windows\System32\ieframe.dll (Internet Browser/Microsoft Corporation SIGNED)(2013-12-13 11:08:39) Reg HKLM\SOFTWARE\Classes\xhtmlfile\shell\open\command@ C:\Program Files\Internet Explorer\iexplore.exe (Internet Explorer/Microsoft Corporation SIGNED)(2013-11-12 12:08:36) Reg HKLM\SOFTWARE\Classes\xhtmlfile\shell\opennew@MUIVerb C:\Windows\System32\ieframe.dll (Internet Browser/Microsoft Corporation SIGNED)(2013-12-13 11:08:39) Reg HKLM\SOFTWARE\Classes\xhtmlfile\shell\opennew\command@ C:\Program Files\Internet Explorer\iexplore.exe (Internet Explorer/Microsoft Corporation SIGNED)(2013-11-12 12:08:36) Reg HKLM\SOFTWARE\Classes\xmlfile\shell\edit\Command@ C:\Program Files\Macromedia\Dreamweaver 8\dreamweaver.exe (Dreamweaver 8/Macromedia, Inc.)(2005-09-27 16:14:08) Reg HKLM\SOFTWARE\Classes\xmlfile\shell\open\command@ C:\Program Files\Common Files\Microsoft Shared\OFFICE11\MSOXMLED.EXE (XML Editor/Microsoft Corporation SIGNED)(2007-03-22 18:13:38) Reg HKLM\SOFTWARE\Classes\xslfile\shell\edit\command@ C:\Program Files\Macromedia\Dreamweaver 8\dreamweaver.exe (Dreamweaver 8/Macromedia, Inc.)(2005-09-27 16:14:08) Reg HKLM\SOFTWARE\Classes\xslfile\shell\Open\command@ C:\Program Files\Internet Explorer\iexplore.exe (Internet Explorer/Microsoft Corporation SIGNED)(2013-11-12 12:08:36) Reg HKLM\SOFTWARE\Classes\xsltfile\shell\edit\command@ C:\Program Files\Macromedia\Dreamweaver 8\dreamweaver.exe (Dreamweaver 8/Macromedia, Inc.)(2005-09-27 16:14:08) Reg HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.exe\OpenWithList@a C:\Windows\system32\mstsc.exe (Remote Desktop Connection/Microsoft Corporation SIGNED)(2013-09-25 17:37:15) Reg HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.jpg\OpenWithList@c C:\Windows\system32\mspaint.exe (Paint/Microsoft Corporation SIGNED)(2009-07-13 23:43:12) Reg HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\FolderTypes\{3F2A72A7-99FA-4DDB-A5A8-C604EDF61D6B}\TopViews\{82BA0782-5B7A-4569-B5D7-EC83085F08CC}@Name C:\Windows\system32\shell32.dll (Windows Shell Common Dll/Microsoft Corporation SIGNED)(2013-09-26 18:21:44) Reg HKCU\Software\Microsoft\Windows\CurrentVersion\Extensions@xls C:\PROGRA~1\MICROS~1\OFFICE11\EXCEL.EXE (Microsoft Office Excel/Microsoft Corporation SIGNED)(2013-05-29 09:08:26) Reg HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings@AutoConfigProxy C:\Windows\system32\wininet.dll (Internet Extensions for Win32/Microsoft Corporation SIGNED)(2013-12-13 11:08:42) Reg HKCU\Software\Microsoft\Windows\CurrentVersion\Run@AlcoholAutomount C:\Program Files\Alcohol Soft\Alcohol 120\AxAutoMntSrv.exe (Alcohol Virtual Drive Auto-mount Service/Alcohol Soft Development Team SIGNED)(2012-01-05 15:42:34) Reg HKCU\Software\Microsoft\Windows\CurrentVersion\Run@KSS C:\Program Files\Kaspersky Lab\Kaspersky Security Scan 2.0\kss.exe (Kaspersky Security Scan/Kaspersky Lab ZAO SIGNED)(2012-12-07 15:16:00) Reg HKCU\Software\Microsoft\Windows\CurrentVersion\Telephony\HandoffPriorities@RequestMakeCall C:\Windows\system32\DIALER.EXE (Microsoft Windows Phone Dialer/Microsoft Corporation SIGNED)(2009-07-14 00:19:41) ---- EOF - GMER 2.1 ----