Welcome to MalwareRemoval.com,
What if we told you that you could get malware removal help from experts, and that it was 100% free? MalwareRemoval.com provides free support for people with infected computers. Our help, and the tools we use are always 100% free. No hidden catch. We simply enjoy helping others. You enjoy a clean, safe computer.

Malware Removal Instructions

Infected?

MalwareRemoval.com provides free support for people with infected computers. Using plain language that anyone can understand, our community of volunteer experts will walk you through each step.

Infected?

Unread postby Risky Rick » December 18th, 2015, 4:04 pm

"Server Not Found" comes up sometimes three times, and then finailly works, and hard drive continually running when it should not be. Net is slowed way down.

The FRST and ADDITIONS files are attached, as they were too large to post in this forum window.
You do not have the required permissions to view the files attached to this post.
Risky Rick
Regular Member
 
Posts: 16
Joined: December 17th, 2015, 5:50 pm
Advertisement
Register to Remove

Re: Infected?

Unread postby nunped » December 21st, 2015, 6:32 pm

Hello Risky Rick, and welcome to the forum.

My name is nunped and I'll be helping you with any malware problems.

Please be aware that removing Malware is a potentially hazardous undertaking. I will take care not to knowingly suggest courses of action that might damage your computer. However it is impossible for me to foresee all interactions that may happen between the software on your computer and those we'll use to clear you of infection, and I cannot guarantee the safety of your system. It is possible that we might encounter situations where the only recourse is to re-format and re-install your operating system, or to necessitate you taking your computer to a repair shop.

Because of this, I advise you to backup any personal files and folders before you start.

Here are some guidelines for the cleaning process to run as easy as possible.

  1. Please read this topic: ALL USERS OF THIS FORUM MUST READ THIS FIRST where the conditions for receiving help here are explained.
  2. The instructions being given are for YOUR computer and system only! Using these instructions on a different computer can cause damage to that computer and possibly render it inoperable!
  3. You must have Administrator rights permissions for this computer.
  4. DO NOT run any other fix or removal tools unless instructed to do so!
  5. DO NOT install any other software (or hardware) during the cleaning process. This adds more items to be researched.
  6. Only post your problem at one help site. Applying fixes from multiple help sites can cause problems.
  7. Only reply to this thread. Do not start another thread.
  8. The absence of symptoms does not imply the absence of malware. Please continue responding until I give you the "All Clean".
  9. No Reply Within 3 Days will result in your topic being closed!


Read through these instructions with your full attention.
Please ask first if you have any doubts.

I am currently reviewing your logs and will return, as soon as possible, with additional instructions.
User avatar
nunped
MRU Honors Grad Emeritus
 
Posts: 1210
Joined: August 17th, 2011, 5:03 pm
Location: Portugal

Re: Infected?

Unread postby Risky Rick » December 22nd, 2015, 9:19 am

nunped,
Thank you for your help. However, after reading number 5 in the list I wanted to tell you I have uploaded another software package Yesterday, and therefore the results of the FRST and Additions file may have changed. SHOULD I RERUN FRST and post the new files?

Also, this has happened in the past to me. I run IncrediMail and was told in the past that has many problems as to Malware attacks. It was one of the programs that had to be uploaded again because it was damaged in the cleaning process.

The software I uploaded yesterday was the free version of SketchUp, a CAD program.
Risky Rick
Regular Member
 
Posts: 16
Joined: December 17th, 2015, 5:50 pm

Re: Infected?

Unread postby nunped » December 22nd, 2015, 7:04 pm

Hi Risky Rick,

Is this computer used for business?

No Anti-virus Software Enabled!
AV: Norton 360 Premier (Disabled - Up to date) {53C7D717-52E2-B95E-FA61-6F32ECC805DB}
AV: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}


Looking over your log ... Both of your AntiVirus are disabled. This puts you at serious risk.
You should enable only ONE of them.

After it, please run this scan:
CKScanner
Please download CKScanner ... Save it to your desktop.
This program should only be run once!
Make sure that CKScanner.exe is on the your desktop before running the application!

  • Right-click on the CKScanner.exe icon and select "Run as Administrator", then click the Search For Files button.
  • When the scan is finished (the cursor hourglass disappears) click the Save List To File button.
    A text file will be created on your desktop named "ckfiles.txt"
  • Click OK at the file saved message box. Double-click on the ckfiles.txt icon on your desktop.
  • Please copy/paste the contents of ckfiles.txt in your next reply.
User avatar
nunped
MRU Honors Grad Emeritus
 
Posts: 1210
Joined: August 17th, 2011, 5:03 pm
Location: Portugal

Re: Infected?

Unread postby Risky Rick » December 23rd, 2015, 10:06 am

nunped,

No, the computer is not used for business, however, my daughter is in a graphic arts class and is using my software from an old business I used to own.

I had to disable Norton to load FRST, but I believe I turned it back on after the files were created.

I noticed in the txt file a lot of "Battlefield" files. This was an online gaming program, now defunct. I should just uninstall the entire package as it no longer will work, and all files related to that program can be deleted if need be.

The file:
CKScanner 2.5 - Additional Security Risks - These are not necessarily bad
c:\program files (x86)\corel\graphics9\custom\bumpmap\cracks.cpt
c:\program files (x86)\corel\graphics9\custom\canvas\cracks2c.pcx
c:\program files (x86)\corel\graphics9\custom\tiles\cracks2m.cpt
c:\program files (x86)\corel\graphics9\photopnt\scripts\effects\086 bump map cracks.csc
c:\users\rick\documents\battlefield play4free\mods\main\cache\{d7b78e66-4302-11cf-0f7b-8323b2c2c535}_253479_3\rashaderstmbasedetailcrackndetailncrack.cfx
c:\users\rick\documents\battlefield play4free\mods\main\cache\{d7b78e66-4302-11cf-0f7b-8323b2c2c535}_253479_3\rashaderstmbasedetailcrackndetailncrackalphatest.cfx
c:\users\rick\documents\battlefield play4free\mods\main\cache\{d7b78e66-4302-11cf-0f7b-8323b2c2c535}_253479_3\rashaderstmbasedetailcrackndetailncrackalphatestlightmap.cfx
c:\users\rick\documents\battlefield play4free\mods\main\cache\{d7b78e66-4302-11cf-0f7b-8323b2c2c535}_253479_3\rashaderstmbasedetailcrackndetailncrackalphatestlightmapshadow.cfx
c:\users\rick\documents\battlefield play4free\mods\main\cache\{d7b78e66-4302-11cf-0f7b-8323b2c2c535}_253479_3\rashaderstmbasedetailcrackndetailncrackalphatestpointlight.cfx
c:\users\rick\documents\battlefield play4free\mods\main\cache\{d7b78e66-4302-11cf-0f7b-8323b2c2c535}_253479_3\rashaderstmbasedetailcrackndetailncrackalphatestshadow.cfx
c:\users\rick\documents\battlefield play4free\mods\main\cache\{d7b78e66-4302-11cf-0f7b-8323b2c2c535}_253479_3\rashaderstmbasedetailcrackndetailncracklightmap.cfx
c:\users\rick\documents\battlefield play4free\mods\main\cache\{d7b78e66-4302-11cf-0f7b-8323b2c2c535}_253479_3\rashaderstmbasedetailcrackndetailncracklightmapshadow.cfx
c:\users\rick\documents\battlefield play4free\mods\main\cache\{d7b78e66-4302-11cf-0f7b-8323b2c2c535}_253479_3\rashaderstmbasedetailcrackndetailncrackpointlight.cfx
c:\users\rick\documents\battlefield play4free\mods\main\cache\{d7b78e66-4302-11cf-0f7b-8323b2c2c535}_253479_3\rashaderstmbasedetailcrackndetailncrackshadow.cfx
c:\users\rick\documents\battlefield play4free\mods\main\cache\{d7b78e66-4302-11cf-0f7b-8323b2c2c535}_253479_3\rashaderstmbasedetaildirtcrackndetailncrack.cfx
c:\users\rick\documents\battlefield play4free\mods\main\cache\{d7b78e66-4302-11cf-0f7b-8323b2c2c535}_253479_3\rashaderstmbasedetaildirtcrackndetailncrackalphatest.cfx
c:\users\rick\documents\battlefield play4free\mods\main\cache\{d7b78e66-4302-11cf-0f7b-8323b2c2c535}_253479_3\rashaderstmbasedetaildirtcrackndetailncrackalphatestlightmap.cfx
c:\users\rick\documents\battlefield play4free\mods\main\cache\{d7b78e66-4302-11cf-0f7b-8323b2c2c535}_253479_3\rashaderstmbasedetaildirtcrackndetailncrackalphatestlightmapshadow.cfx
c:\users\rick\documents\battlefield play4free\mods\main\cache\{d7b78e66-4302-11cf-0f7b-8323b2c2c535}_253479_3\rashaderstmbasedetaildirtcrackndetailncrackalphatestpointlight.cfx
c:\users\rick\documents\battlefield play4free\mods\main\cache\{d7b78e66-4302-11cf-0f7b-8323b2c2c535}_253479_3\rashaderstmbasedetaildirtcrackndetailncrackalphatestshadow.cfx
c:\users\rick\documents\battlefield play4free\mods\main\cache\{d7b78e66-4302-11cf-0f7b-8323b2c2c535}_253479_3\rashaderstmbasedetaildirtcrackndetailncracklightmap.cfx
c:\users\rick\documents\battlefield play4free\mods\main\cache\{d7b78e66-4302-11cf-0f7b-8323b2c2c535}_253479_3\rashaderstmbasedetaildirtcrackndetailncracklightmapshadow.cfx
c:\users\rick\documents\battlefield play4free\mods\main\cache\{d7b78e66-4302-11cf-0f7b-8323b2c2c535}_253479_3\rashaderstmbasedetaildirtcrackndetailncrackpointlight.cfx
c:\users\rick\documents\battlefield play4free\mods\main\cache\{d7b78e66-4302-11cf-0f7b-8323b2c2c535}_253479_3\rashaderstmbasedetaildirtcrackndetailncrackshadow.cfx
c:\users\rick\documents\battlefield play4free\mods\main\cache\{d7b78e66-4302-11cf-0f7b-8323b2c2c535}_253705_3\rashaderstmbasedetailcrackndetailncrack.cfx
c:\users\rick\documents\battlefield play4free\mods\main\cache\{d7b78e66-4302-11cf-0f7b-8323b2c2c535}_253705_3\rashaderstmbasedetailcrackndetailncrackalphatest.cfx
c:\users\rick\documents\battlefield play4free\mods\main\cache\{d7b78e66-4302-11cf-0f7b-8323b2c2c535}_253705_3\rashaderstmbasedetailcrackndetailncrackalphatestlightmap.cfx
c:\users\rick\documents\battlefield play4free\mods\main\cache\{d7b78e66-4302-11cf-0f7b-8323b2c2c535}_253705_3\rashaderstmbasedetailcrackndetailncrackalphatestlightmapshadow.cfx
c:\users\rick\documents\battlefield play4free\mods\main\cache\{d7b78e66-4302-11cf-0f7b-8323b2c2c535}_253705_3\rashaderstmbasedetailcrackndetailncrackalphatestpointlight.cfx
c:\users\rick\documents\battlefield play4free\mods\main\cache\{d7b78e66-4302-11cf-0f7b-8323b2c2c535}_253705_3\rashaderstmbasedetailcrackndetailncrackalphatestshadow.cfx
c:\users\rick\documents\battlefield play4free\mods\main\cache\{d7b78e66-4302-11cf-0f7b-8323b2c2c535}_253705_3\rashaderstmbasedetailcrackndetailncracklightmap.cfx
c:\users\rick\documents\battlefield play4free\mods\main\cache\{d7b78e66-4302-11cf-0f7b-8323b2c2c535}_253705_3\rashaderstmbasedetailcrackndetailncracklightmapshadow.cfx
c:\users\rick\documents\battlefield play4free\mods\main\cache\{d7b78e66-4302-11cf-0f7b-8323b2c2c535}_253705_3\rashaderstmbasedetailcrackndetailncrackpointlight.cfx
c:\users\rick\documents\battlefield play4free\mods\main\cache\{d7b78e66-4302-11cf-0f7b-8323b2c2c535}_253705_3\rashaderstmbasedetailcrackndetailncrackshadow.cfx
c:\users\rick\documents\battlefield play4free\mods\main\cache\{d7b78e66-4302-11cf-0f7b-8323b2c2c535}_253705_3\rashaderstmbasedetaildirtcrackndetailncrack.cfx
c:\users\rick\documents\battlefield play4free\mods\main\cache\{d7b78e66-4302-11cf-0f7b-8323b2c2c535}_253705_3\rashaderstmbasedetaildirtcrackndetailncrackalphatest.cfx
c:\users\rick\documents\battlefield play4free\mods\main\cache\{d7b78e66-4302-11cf-0f7b-8323b2c2c535}_253705_3\rashaderstmbasedetaildirtcrackndetailncrackalphatestlightmap.cfx
c:\users\rick\documents\battlefield play4free\mods\main\cache\{d7b78e66-4302-11cf-0f7b-8323b2c2c535}_253705_3\rashaderstmbasedetaildirtcrackndetailncrackalphatestlightmapshadow.cfx
c:\users\rick\documents\battlefield play4free\mods\main\cache\{d7b78e66-4302-11cf-0f7b-8323b2c2c535}_253705_3\rashaderstmbasedetaildirtcrackndetailncrackalphatestpointlight.cfx
c:\users\rick\documents\battlefield play4free\mods\main\cache\{d7b78e66-4302-11cf-0f7b-8323b2c2c535}_253705_3\rashaderstmbasedetaildirtcrackndetailncrackalphatestshadow.cfx
c:\users\rick\documents\battlefield play4free\mods\main\cache\{d7b78e66-4302-11cf-0f7b-8323b2c2c535}_253705_3\rashaderstmbasedetaildirtcrackndetailncracklightmap.cfx
c:\users\rick\documents\battlefield play4free\mods\main\cache\{d7b78e66-4302-11cf-0f7b-8323b2c2c535}_253705_3\rashaderstmbasedetaildirtcrackndetailncracklightmapshadow.cfx
c:\users\rick\documents\battlefield play4free\mods\main\cache\{d7b78e66-4302-11cf-0f7b-8323b2c2c535}_253705_3\rashaderstmbasedetaildirtcrackndetailncrackpointlight.cfx
c:\users\rick\documents\battlefield play4free\mods\main\cache\{d7b78e66-4302-11cf-0f7b-8323b2c2c535}_253705_3\rashaderstmbasedetaildirtcrackndetailncrackshadow.cfx
c:\users\rick\videos\realplayer downloads\jeb corliss grinding the crack - youtube.flv
c:\users\rick\videos\realplayer downloads\jeb_corliss___grinding_the_crack__-_youtube_[freecorder.com].webm
scanner sequence 3.ZZ.11.RBNAGZ
----- EOF -----
Risky Rick
Regular Member
 
Posts: 16
Joined: December 17th, 2015, 5:50 pm

Re: Infected?

Unread postby nunped » December 23rd, 2015, 4:45 pm

Hi Risky Rick,

Don't worry about the Battlefield files for now.

Lets repeat the scan with FRST and run another one:

Step 1 - Scan with FRST
  • Right-click FRST.exe and select " Run as administrator " to run it.
  • When the tool opens click Yes to the disclaimer.
  • Press Scan button. ... When finished a log will be created, FRST.txt.
  • Please post the content of the FRST.txt in your next reply.

Step 2 - AdwCleaner - Scan Only
Please download AdwCleaner by Xplode, save it to your desktop.
  • Close ALL open programs, including your Internet browsers.
  • Right click on adwcleaner.exe and select "Run as administrator" to run it.
  • Click on Scan.
    When the scan finishes, you'll see a message on the product window: "Pending. Please uncheck elements you don't want to remove."
  • Press the Report button to produce the scan report.
  • A logfile C:\AdwCleaner[Rn].txt will automatically open. ([Rn] n = number of run)
  • Please post the content of the C:\AdwCleaner[Rn].txt logfile in your next reply.
User avatar
nunped
MRU Honors Grad Emeritus
 
Posts: 1210
Joined: August 17th, 2011, 5:03 pm
Location: Portugal

Re: Infected?

Unread postby Risky Rick » December 23rd, 2015, 6:12 pm

FRST and AdwCleaner
You do not have the required permissions to view the files attached to this post.
Risky Rick
Regular Member
 
Posts: 16
Joined: December 17th, 2015, 5:50 pm

Re: Infected?

Unread postby nunped » December 25th, 2015, 6:24 am

Hi Risky Rick,

I'll ask you to, please, paste the logs, instead of attaching them in the future. It's easier to search them when they are pasted.

Step 1 - Uninstall Programs
  • Click on the Search button on the bottom left corner of your screen
  • Copy and paste the value below, into the Start Search entry box:
    appwiz.cpl
      Depending on your current view setting ...
    • Double click on Programs and Features.
    • Under Programs, click on Uninstall a program.
  • Locate the following programs:
    Freecorder Toolbar
    IncrediMail MediaBar 2 Toolbar

  • Select the program and click on Uninstall to uninstall it.
  • Repeat steps 3 - 4 for each program in the list.
  • Reboot your computer after this.

Step 2 - Fix with FRST
  • Click Start
  • Type notepad.exe in the search programs and files box and click Enter.
  • A blank Notepad page should open.
    • Copy and Paste the following script into Notepad, Do not include the words Code: select all
    • (Click the select all button next to code to select the entire script).
    Code: Select all
    CreateRestorePoint:
    HKU\S-1-5-21-2324462236-1183297055-1014908895-1001\...\MountPoints2: {49cc61eb-d41c-11e2-8249-90fba62bb1c9} - "J:\LaunchU3.exe" -a
    Task: {25A49F2A-592B-42D5-8567-99976DD9B066} - \Microsoft\Windows\Setup\gwx\refreshgwxconfig -> No File <==== ATTENTION
    Task: {5058B560-09AE-409E-B6D6-7997F79FD3CA} - \Microsoft\Windows\Setup\gwx\refreshgwxconfigandcontent -> No File <==== ATTENTION
    Task: {5358FBFA-FE66-435C-9E28-7A254A9BDA4B} - \Microsoft\Windows\Setup\GWXTriggers\OutOfIdle-5d -> No File <==== ATTENTION
    Task: {5F39965B-0E2F-48DC-8CB8-27B4AF01E1F8} - \Microsoft\Windows\Setup\GWXTriggers\Logon-5d -> No File <==== ATTENTION
    Task: {60CD23A3-5A19-47FD-8380-C28C94BC8687} - \Microsoft\Windows\Setup\GWXTriggers\refreshgwxconfig-B -> No File <==== ATTENTION
    Task: {A9A55780-70E8-4F8D-81D9-12389AE8968B} - \CCleanerSkipUAC -> No File <==== ATTENTION
    Task: {C1B24905-24F8-42BA-8621-7689EDC34778} - \Microsoft\Windows\Setup\gwx\refreshgwxcontent -> No File <==== ATTENTION
    Task: {D881CB7D-BD7C-4E5E-934E-8165D90989CA} - \Microsoft\Windows\Setup\gwx\launchtrayprocess -> No File <==== ATTENTION
    Task: {DBE9377B-9A01-4110-8B81-577D4ECFE833} - \Microsoft\Windows\Setup\GWXTriggers\OutOfSleep-5d -> No File <==== ATTENTION
    Task: {EDBF38C4-406A-4B81-9B56-BE6DF2EA037E} - \Microsoft\Windows\Setup\GWXTriggers\MachineUnlock-5d -> No File <==== ATTENTION
    Task: {FA8F291F-AD51-4058-B4EE-19BB98033102} - \Microsoft\Windows\Setup\GWXTriggers\Telemetry-4xd -> No File <==== ATTENTION
    Task: {FFFABB21-FBFE-450E-B580-5FB180156F34} - \Microsoft\Windows\Setup\GWXTriggers\Time-5d -> No File <==== ATTENTION
    EmptyTemp:
    
  • Save it to your Desktop as filename fixlist.txt.
  • Right-click FRST.exe and select " Run as administrator " to run it.
  • Press the Fix button just once. Then wait.
  • When finished, it will create a Fixlog.txt log on your Desktop.
  • Please post the content of the Fixlog.txt in your next reply.

Step 3 - AdwCleaner - Scan/Clean
You should still have AdwCleaner on your desktop.
  • Close ALL open programs, including your Internet browsers.
  • Right click on adwcleaner.exe and select "Run as administrator" to run it.
  • Click on Scan. When the scan finishes...the Clean button will become active.
  • Click on Clean.
  • Select OK at each prompt... to reboot the computer.
  • A logfile C:\AdwCleaner[Sn].txt will open after you log back on the computer. ([Sn] n = number of run)
  • Please post the content of the C:\AdwCleaner[Sn].txt logfile in your next reply.


How is your computer behaving?
User avatar
nunped
MRU Honors Grad Emeritus
 
Posts: 1210
Joined: August 17th, 2011, 5:03 pm
Location: Portugal

Re: Infected?

Unread postby Risky Rick » December 25th, 2015, 12:40 pm

Step 1
Provided error messages on both files you listed:

"An error occurred while trying to uninstall Freecorder Toolbar. It may have already been uninstalled.
Would you like to remove Freecorder Toolbar from the programs and features list?"

I clicked "YES" to both files.

STEP 2

Fixlog.txt
Fix result of Farbar Recovery Scan Tool (x64) Version:23-12-2015
Ran by Rick (2015-12-25 10:53:33) Run:1
Running from C:\Users\Rick\Desktop
Loaded Profiles: Rick (Available Profiles: Rick)
Boot Mode: Normal
==============================================

fixlist content:
*****************
CreateRestorePoint:
HKU\S-1-5-21-2324462236-1183297055-1014908895-1001\...\MountPoints2: {49cc61eb-d41c-11e2-8249-90fba62bb1c9} - "J:\LaunchU3.exe" -a
Task: {25A49F2A-592B-42D5-8567-99976DD9B066} - \Microsoft\Windows\Setup\gwx\refreshgwxconfig -> No File <==== ATTENTION
Task: {5058B560-09AE-409E-B6D6-7997F79FD3CA} - \Microsoft\Windows\Setup\gwx\refreshgwxconfigandcontent -> No File <==== ATTENTION
Task: {5358FBFA-FE66-435C-9E28-7A254A9BDA4B} - \Microsoft\Windows\Setup\GWXTriggers\OutOfIdle-5d -> No File <==== ATTENTION
Task: {5F39965B-0E2F-48DC-8CB8-27B4AF01E1F8} - \Microsoft\Windows\Setup\GWXTriggers\Logon-5d -> No File <==== ATTENTION
Task: {60CD23A3-5A19-47FD-8380-C28C94BC8687} - \Microsoft\Windows\Setup\GWXTriggers\refreshgwxconfig-B -> No File <==== ATTENTION
Task: {A9A55780-70E8-4F8D-81D9-12389AE8968B} - \CCleanerSkipUAC -> No File <==== ATTENTION
Task: {C1B24905-24F8-42BA-8621-7689EDC34778} - \Microsoft\Windows\Setup\gwx\refreshgwxcontent -> No File <==== ATTENTION
Task: {D881CB7D-BD7C-4E5E-934E-8165D90989CA} - \Microsoft\Windows\Setup\gwx\launchtrayprocess -> No File <==== ATTENTION
Task: {DBE9377B-9A01-4110-8B81-577D4ECFE833} - \Microsoft\Windows\Setup\GWXTriggers\OutOfSleep-5d -> No File <==== ATTENTION
Task: {EDBF38C4-406A-4B81-9B56-BE6DF2EA037E} - \Microsoft\Windows\Setup\GWXTriggers\MachineUnlock-5d -> No File <==== ATTENTION
Task: {FA8F291F-AD51-4058-B4EE-19BB98033102} - \Microsoft\Windows\Setup\GWXTriggers\Telemetry-4xd -> No File <==== ATTENTION
Task: {FFFABB21-FBFE-450E-B580-5FB180156F34} - \Microsoft\Windows\Setup\GWXTriggers\Time-5d -> No File <==== ATTENTION
EmptyTemp:

*****************

Restore point was successfully created.
"HKU\S-1-5-21-2324462236-1183297055-1014908895-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{49cc61eb-d41c-11e2-8249-90fba62bb1c9}" => key removed successfully
HKCR\CLSID\{49cc61eb-d41c-11e2-8249-90fba62bb1c9} => key not found.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{25A49F2A-592B-42D5-8567-99976DD9B066}" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{25A49F2A-592B-42D5-8567-99976DD9B066}" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\Setup\gwx\refreshgwxconfig" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{5058B560-09AE-409E-B6D6-7997F79FD3CA}" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{5058B560-09AE-409E-B6D6-7997F79FD3CA}" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\Setup\gwx\refreshgwxconfigandcontent" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{5358FBFA-FE66-435C-9E28-7A254A9BDA4B}" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{5358FBFA-FE66-435C-9E28-7A254A9BDA4B}" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\Setup\GWXTriggers\OutOfIdle-5d" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{5F39965B-0E2F-48DC-8CB8-27B4AF01E1F8}" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{5F39965B-0E2F-48DC-8CB8-27B4AF01E1F8}" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\Setup\GWXTriggers\Logon-5d" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{60CD23A3-5A19-47FD-8380-C28C94BC8687}" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{60CD23A3-5A19-47FD-8380-C28C94BC8687}" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\Setup\GWXTriggers\refreshgwxconfig-B" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{A9A55780-70E8-4F8D-81D9-12389AE8968B}" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{A9A55780-70E8-4F8D-81D9-12389AE8968B}" => key removed successfully
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\CCleanerSkipUAC => key not found.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{C1B24905-24F8-42BA-8621-7689EDC34778}" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{C1B24905-24F8-42BA-8621-7689EDC34778}" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\Setup\gwx\refreshgwxcontent" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{D881CB7D-BD7C-4E5E-934E-8165D90989CA}" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{D881CB7D-BD7C-4E5E-934E-8165D90989CA}" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\Setup\gwx\launchtrayprocess" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{DBE9377B-9A01-4110-8B81-577D4ECFE833}" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{DBE9377B-9A01-4110-8B81-577D4ECFE833}" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\Setup\GWXTriggers\OutOfSleep-5d" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{EDBF38C4-406A-4B81-9B56-BE6DF2EA037E}" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{EDBF38C4-406A-4B81-9B56-BE6DF2EA037E}" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\Setup\GWXTriggers\MachineUnlock-5d" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{FA8F291F-AD51-4058-B4EE-19BB98033102}" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{FA8F291F-AD51-4058-B4EE-19BB98033102}" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\Setup\GWXTriggers\Telemetry-4xd" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{FFFABB21-FBFE-450E-B580-5FB180156F34}" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{FFFABB21-FBFE-450E-B580-5FB180156F34}" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\Setup\GWXTriggers\Time-5d" => key removed successfully
EmptyTemp: => 659.6 MB temporary data Removed.


The system needed a reboot.

==== End of Fixlog 10:56:05 ====


STEP 3

AdwCleaner[Sn] file

# AdwCleaner v5.026 - Logfile created 25/12/2015 at 11:14:54
# Updated 21/12/2015 by Xplode
# Database : 2015-12-23.1 [Server]
# Operating system : Windows 10 Home (x64)
# Username : Rick - RICK-PC
# Running from : C:\Users\Rick\Desktop\AdwCleaner.exe
# Option : Cleaning
# Support : http://toolslib.net/forum

***** [ Services ] *****


***** [ Folders ] *****

[-] Folder Deleted : C:\Users\Rick\AppData\Local\TB\APISupport

***** [ Files ] *****


***** [ DLLs ] *****


***** [ Shortcuts ] *****


***** [ Scheduled tasks ] *****


***** [ Registry ] *****

[-] Key Deleted : HKLM\SOFTWARE\Classes\protector_dll.protectorbho
[-] Key Deleted : HKLM\SOFTWARE\Classes\protector_dll.protectorbho.1
[-] Key Deleted : HKCU\Software\APN PIP
[-] Key Deleted : HKCU\Software\IM
[-] Key Deleted : HKCU\Software\ImInstaller
[-] Key Deleted : HKCU\Software\SweetIM
[-] Key Deleted : HKLM\SOFTWARE\ImInstaller
[-] Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{EE171732-BEB4-4576-887D-CB62727F01CA}

***** [ Web browsers ] *****

[-] [C:\Users\Rick\AppData\Local\Google\Chrome\User Data\Default\Web Data] [Search Provider] Deleted : aol.com
[-] [C:\Users\Rick\AppData\Local\Google\Chrome\User Data\Default\Web Data] [Search Provider] Deleted : ask.com
[-] [C:\Users\Rick\AppData\Local\Google\Chrome\User Data\Default\Secure Preferences] [Extension] Deleted : bbjciahceamgodcoidkjpchnokgfpphh
[-] [C:\Users\Rick\AppData\Local\Google\Chrome\User Data\Default\Secure Preferences] [Extension] Deleted : cjpglkicenollcignonpgiafdgfeehoj
[-] [C:\Users\Rick\AppData\Local\Google\Chrome\User Data\Default\Secure Preferences] [Extension] Deleted : dlfienamagdnkekbbbocojppncdambda
[-] [C:\Users\Rick\AppData\Local\Google\Chrome\User Data\Default\Secure Preferences] [Extension] Deleted : oiokahphinmbmakkehgelkmpolmnbkdh

*************************

:: "Tracing" keys removed
:: Winsock settings cleared

########## EOF - C:\AdwCleaner\AdwCleaner[C1].txt - [1963 bytes] ##########

As to the computer behaving:

JUST to let you know, if you are not aware, I am running Windows 10. It has a few glitches, like the program bar at the bottom upon startup will freeze up and just beep when you click on program icons unless you click on them immediately after the desktop becomes visible. Also, I do run NORTON 360, and it will delete the AdwCleaner when it automatically kicks on, just as it would not allow me to load FRST at first, until I turn NORTON off. .... Also Win 10 does not have a 'start' button that I can tell, as my old windows 7 had.

The net seems to be running smoother, but today being 'christmas', perhaps it is because fewer are on the net at this time of the morning on this day. But the hard drive is not making as much noise as it usually does of late. But it is still running something active in the background, and it is going over the net, as I can hear it.

When I turned on Incredimail I had to restart it twice, as it was claiming it did not load properly and ask to be restarted. Not normal. But it seems to be working okay now. I would remind you that I have had this cleaning done in the past, a few years back, and Incredimail did have to be reloaded. It apparently can be a window for bugs.
Risky Rick
Regular Member
 
Posts: 16
Joined: December 17th, 2015, 5:50 pm

Re: Infected?

Unread postby nunped » December 26th, 2015, 9:53 am

Hi Risky Rick,

I hope you had a nice Christmas.

JUST to let you know, if you are not aware, I am running Windows 10.

Yes, I am aware. I'm sorry if my instructions are not as accurate for W10, but feel free to ask if you have any doubts when following them.

For our next steps:

Step 1 - Search with FRST
  • Right-click FRST64.exe and select " Run as administrator " to run it.
  • When the tool opens click Yes to the disclaimer.
  • Copy and Paste the following script into the Search: box Do not include the words Code: select all
  • (Click the select all button next to code to select the entire script).
Code: Select all
freecorder;sweetim;incredimail;protector

  • Press the Search Registry button.
  • When finished searching a log will open on your Desktop ... Search.txt
  • Please post it in your next reply.


Step 2 - ESET NOD32 Online Scan
You will need to to right-click on the IE or FF icons on the Start Menu or Quick Launch Bar on the Taskbar and select "Run as Administrator" from the context menu.
Note: If using Mozilla Firefox you will need to download "esetsmartinstaller_enu.exe" when prompted... then double click on it to install.
Please temporarily disable your Anti-virus real-time protection. If active, it could impact the online scan.
Do NOT use the computer while the scan is running... make sure all other programs and windows are closed!


Please go to ESET Online Scanner - © ESET All Rights Reserved... to run an online scan.
  1. Click theblue [Run ESET Online Scanner] button.
  2. Read the End User License Agreement and check the box: [Yes, I accept the terms of use].
  3. Click the green [Start] button.
  4. Accept any security warnings from your browser and allow the download/installation of any require files.
    If your browser blocks or halts a download, please allow it to download any required files.
  5. Under scan settings:
    • Check "Scan archives"
    • Remove found threats is UNCHECKED
  6. Click Advanced settings ... select the following:
    • Scan potentially unwanted applications
    • Scan for potentially unsafe applications
    • Enable Anti-Stealth technology
  7. Click the [Start] button.
    ESET will install itself, download virus signature database updates and begin scanning your computer.
    The scan will take a while so please be patient. Do NOT use the computer while the scan is running.
  8. When the scan completes... press the text: Image
  9. Press the text: Image ... then save the file to your desktop as ESETScan.txt.
  10. Press the [Back] button... then press the [Finish] button.
  11. Copy and paste the contents of ESETScan.txt in your next reply.
    Note: If no threats are found, there is no option to create a log. Just report back to me there was nothing found.

Remember to enable your Anti-virus protection... before continuing!
User avatar
nunped
MRU Honors Grad Emeritus
 
Posts: 1210
Joined: August 17th, 2011, 5:03 pm
Location: Portugal

Re: Infected?

Unread postby Risky Rick » December 28th, 2015, 9:06 am

The file was too large for posting in one. The file simply continues in the second post.

SEARCH.txt
Farbar Recovery Scan Tool (x64) Version:23-12-2015
Ran by Rick (2015-12-27 17:47:12)
Running from C:\Users\Rick\Desktop
Boot Mode: Normal

================== Search Registry: "freecorder;sweetim;incredimail;protector" ===========


===================== Search result for "freecorder" ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WOW6432Node\CLSID\{2F903E7C-BE52-4546-97B4-63B79F6156CF}\InprocServer32]
""="C:\Program Files (x86)\Freecorder\Applian_Audio_Plugin.dll"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WOW6432Node\CLSID\{5985C5C4-3254-471F-B65D-F89C38D07E22}\InprocServer32]
""="C:\Program Files (x86)\Freecorder\Applian_Audio_Plugin.dll"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WOW6432Node\CLSID\{9E92257F-3F0A-451D-B231-6E2DB60CDC71}]
""="Freecorder API Server"

[HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Freecorder]

[HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Freecorder\toolbar]
"DisplayName"="Freecorder"

[HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Freecorder\toolbar]
"Path"="C:\Program Files (x86)\Freecorder"

[HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Freecorder\toolbar]
"AutoUpdateHelperPath"="C:\Users\Rick\AppData\Local\Conduit\CT1060933\FreecorderAutoUpdateHelper.exe"

[HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{5583AA52-08BC-473C-AD72-BDA851846966}]
"AppName"="FreecorderAutoUpdateHelper.exe"

[HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{CDB396C5-391C-42C5-BF28-8DB474B2D63E}]
"AppPath"="C:\Program Files (x86)\Freecorder"

[HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Uninstall\Freecorder5.11]

[HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Uninstall\Freecorder5.11]
"UninstallString"=""C:\Program Files (x86)\Freecorder\uninstall.exe" "/U:C:\Program Files (x86)\Freecorder\Uninstall\uninstallFC5.xml""

[HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Uninstall\Freecorder5.11]
"DisplayIcon"=""C:\Program Files (x86)\Freecorder\uninstall.exe""

[HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Classes\CLSID\{2F903E7C-BE52-4546-97B4-63B79F6156CF}\InprocServer32]
""="C:\Program Files (x86)\Freecorder\Applian_Audio_Plugin.dll"

[HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Classes\CLSID\{5985C5C4-3254-471F-B65D-F89C38D07E22}\InprocServer32]
""="C:\Program Files (x86)\Freecorder\Applian_Audio_Plugin.dll"

[HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Classes\CLSID\{9E92257F-3F0A-451D-B231-6E2DB60CDC71}]
""="Freecorder API Server"

[HKEY_USERS\S-1-5-21-2324462236-1183297055-1014908895-1001\SOFTWARE\AppDataLow\Software\Freecorder]

[HKEY_USERS\S-1-5-21-2324462236-1183297055-1014908895-1001\SOFTWARE\AppDataLow\Software\Freecorder\toolbar]
"DisplayName"="Freecorder"

[HKEY_USERS\S-1-5-21-2324462236-1183297055-1014908895-1001\SOFTWARE\AppDataLow\Software\Freecorder\toolbar\Settings]
"RadioHelpUrl"="http://Freecorder.Media-Toolbar.com/help/#2_5"

[HKEY_USERS\S-1-5-21-2324462236-1183297055-1014908895-1001\SOFTWARE\AppDataLow\Software\Freecorder\toolbar\Settings\FeatureProtector]

[HKEY_USERS\S-1-5-21-2324462236-1183297055-1014908895-1001\SOFTWARE\ApplianTechnologies\Freecorder4Settings]


===================== Search result for "incredimail" ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\.ima]
"Content Type"="application/x-incredimail"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\.ime]
"Content Type"="application/x-incredimail"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\.imi]
"Content Type"="application/x-incredimail"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\.imn]
"Content Type"="application/x-incredimail"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\.imw]
"Content Type"="application/x-incredimail"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{FCA7EB04-D708-11D3-BBAE-0050DA276194}]
""="IncrediMail"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Component Categories\{12A4DA65-C409-41AF-8759-3D51A438E026}]
"409"="IncrediMail Importer Object"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Component Categories\{C535D6AD-3FBB-4F39-B60E-34B9187D8D54}]
"409"="IncrediMail External Importer Object"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\IncrediContent\DefaultIcon]
""="C:\Program Files (x86)\IncrediMail\Bin\ImpCnt.exe,-1003"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\IncrediImport.IncrediMailImporter]

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\IncrediImport.IncrediMailImporter\CurVer]
""="IncrediImport.IncrediMailImporter.1"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\IncrediImport.IncrediMailImporter.1]
""="IncrediMailImporter Class"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\IncrediImport.IncrediMailImporter2]
""="IncrediMailImporter2 Class"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\IncrediImport.IncrediMailImporter2.1]

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\IncrediLicense]
""="IncrediMail Licence"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\IncrediMail.Kernel]

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\IncrediMail.Kernel.1]

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\IncrediMail.Url.Mailto\DefaultIcon]
""="C:\Program Files (x86)\IncrediMail\IncMail.exe,0"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\IncrediMessage]
""="IncrediMail Internet Mail Message"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\IncrediMessage\shell\open\command]
""="C:\Program Files (x86)\IncrediMail\Bin\IncMail.exe /c "%1""

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\IncredLWizard\shell\open\command]
""="C:\Program Files (x86)\IncrediMail\Bin\ImLc.exe "%1""

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\Products\1EA505532E7260243BFB857781308B0D\SourceList]
"PackageName"="IncrediMail.msi"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\Products\1EA505532E7260243BFB857781308B0D\SourceList\Net]
"1"="C:\Users\Rick\AppData\Local\Temp\IMInstaller\IncrediMail\DISK1\"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\Products\2220A88709652124AAC94CF80D1E9CEA\SourceList\Net]
"1"="C:\Users\Rick\AppData\Local\Temp\IMInstaller\IncrediMail\"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{00E677A7-A7A5-4819-9580-1681BE30E28E}\1.0]
""="IncrediMail 1.0 Type Library"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{03203896-B655-11D3-BB7D-0050DA276194}\1.0\0\win32]
""="C:\Program Files (x86)\IncrediMail\Bin\ImSpoolU.dll"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{0B9A0833-1EC3-11D5-B75C-005004C0C6BA}\1.0\0\win32]
""="C:\Program Files (x86)\IncrediMail\Bin\ImToolsU.dll"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{1FE3C1B4-89E9-4991-AD47-FBA01E92EFAF}\1.0\0\win32]
""="C:\Program Files (x86)\IncrediMail\Bin\ImComUtlU.dll"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{64C3E4A6-E463-11D3-857A-005004BE235E}\1.0\0\win32]
""="C:\Program Files (x86)\IncrediMail\Bin\ImServU.dll"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{72E0FA03-C103-11D3-BB95-0050DA276194}\1.0\0\win32]
""="C:\Program Files (x86)\IncrediMail\Bin\ImNotfyU.dll"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{815F81B9-E268-489D-883A-B5BC5BED9F03}\1.0\0\win64]
""="C:\Program Files (x86)\IncrediMail\Bin\MailBee.dll"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{85C5139A-BEDD-4BCF-B7F2-7A4A54EB8D0B}\1.0\0\win32]
""="C:\Program Files (x86)\IncrediMail\Bin\ImApp.exe"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{B5534636-E461-11D3-BBB2-0050DA276194}\1.0\0\win32]
""="C:\Program Files (x86)\IncrediMail\Bin\ImAnimU.dll"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{CB073674-BD1F-11D3-BB90-0050DA276194}\1.0\0\win32]
""="C:\Program Files (x86)\IncrediMail\Bin\ImMangrU.dll"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{F8984103-38B6-11D5-8725-0050DA2761C4}\1.0\0\win32]
""="C:\Program Files (x86)\IncrediMail\Bin\ImShExtU.dll"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WOW6432Node\CLSID\{00E9F275-1525-4fd3-8CEE-6BAF5B4A4B4A}\InprocServer32]
""="C:\Program Files (x86)\IncrediMail\Bin\ImImprtU.dll"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WOW6432Node\CLSID\{00E9F275-1525-4fd3-8CEE-6BAF5B4A4B4A}\VersionIndependentProgID]
""="IncrediImport.IncrediMailImporter2"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WOW6432Node\CLSID\{0710C793-2117-11D5-B75D-005004C0C6BA}\InprocServer32]
""="C:\Program Files (x86)\IncrediMail\Bin\ImFeatU.dll"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WOW6432Node\CLSID\{07A52AE7-B6F0-11D3-BB7E-0050DA276194}\InprocServer32]
""="C:\Program Files (x86)\IncrediMail\Bin\ImSpoolU.dll"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WOW6432Node\CLSID\{087EF34C-BBC4-11D3-BB8D-0050DA276194}\InprocServer32]
""="C:\Program Files (x86)\IncrediMail\Bin\ImParserU.dll"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WOW6432Node\CLSID\{09384BB7-09EC-4adb-862E-420A31E278F5}\InprocServer32]
""="C:\Program Files (x86)\IncrediMail\Bin\ImToolsU.dll"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WOW6432Node\CLSID\{0B9A0840-1EC3-11D5-B75C-005004C0C6BA}\InprocServer32]
""="C:\Program Files (x86)\IncrediMail\Bin\ImToolsU.dll"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WOW6432Node\CLSID\{140BBD3E-C68E-4077-B7EC-D4DC46242EF5}\InprocServer32]
""="C:\Program Files (x86)\IncrediMail\Bin\ImToolsU.dll"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WOW6432Node\CLSID\{17A434C2-B48F-11D3-BB78-0050DA276194}\InprocServer32]
""="C:\Program Files (x86)\IncrediMail\Bin\ImFoldrsU.dll"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WOW6432Node\CLSID\{1E97DB6C-0BDD-4066-AD2F-01417D21A8D0}\InprocServer32]
""="C:\Program Files (x86)\IncrediMail\Bin\ImParserU.dll"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WOW6432Node\CLSID\{28D1EE40-E73D-422D-A2AC-D23F8D3071B2}\InprocServer32]
""="C:\Program Files (x86)\IncrediMail\Bin\ImParserU.dll"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WOW6432Node\CLSID\{2E43842C-5133-455A-967A-C424B485D53C}\InprocServer32]
""="C:\Program Files (x86)\IncrediMail\Bin\ImSpoolU.dll"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WOW6432Node\CLSID\{328CC455-1F5E-4F1A-A6B7-A888AA9C0289}\InprocServer32]
""="C:\Program Files (x86)\IncrediMail\Bin\ImFeatU.dll"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WOW6432Node\CLSID\{35092AB4-B643-11D3-BB7D-0050DA276194}\InprocServer32]
""="C:\Program Files (x86)\IncrediMail\Bin\ImSpoolU.dll"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WOW6432Node\CLSID\{3762BAB7-8E00-4B51-AA7E-E57ED7552794}\InprocServer32]
""="C:\Program Files (x86)\IncrediMail\Bin\ImMangrU.dll"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WOW6432Node\CLSID\{43AFEAC3-6385-4DFE-9870-C65B5A555412}\InprocServer32]
""="C:\Program Files (x86)\IncrediMail_MediaBar_2\tbIncr.dll"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WOW6432Node\CLSID\{44C8EC50-93BD-4633-9A82-CA0D4F1DD3A7}\InprocServer32]
""="C:\Program Files (x86)\IncrediMail\Bin\ImImprtU.dll"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WOW6432Node\CLSID\{44C8EC50-93BD-4633-9A82-CA0D4F1DD3A7}\VersionIndependentProgID]
""="IncrediImport.IncrediMailImporter"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WOW6432Node\CLSID\{4EAA7268-FC1E-47C6-87EF-8915475CBC88}\InprocServer32]
""="C:\Program Files (x86)\IncrediMail\Bin\ImFeatU.dll"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WOW6432Node\CLSID\{55B613D4-E613-11D3-857A-005004BE235E}\InprocServer32]
""="C:\Program Files (x86)\IncrediMail\Bin\ImServU.dll"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WOW6432Node\CLSID\{57DE7416-A3EB-47C8-B44D-72F79539A360}\InprocServer32]
""="C:\Program Files (x86)\IncrediMail\Bin\ImViewU.dll"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WOW6432Node\CLSID\{5B1E73D3-F6DB-406E-AE7F-20FAB0AD4732}\InprocServer32]
""="C:\Program Files (x86)\IncrediMail\Bin\ImServU.dll"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WOW6432Node\CLSID\{687F8E94-45D6-4685-A63D-1C7A140EF847}\InprocServer32]
""="C:\Program Files (x86)\IncrediMail\Bin\ImSpoolU.dll"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WOW6432Node\CLSID\{697DF023-B24E-11D3-B57C-00105AA461D0}\InprocServer32]
""="C:\Program Files (x86)\IncrediMail\Bin\dten600.dll"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WOW6432Node\CLSID\{697DF027-B24E-11D3-B57C-00105AA461D0}\InprocServer32]
""="C:\Program Files (x86)\IncrediMail\Bin\dten600.dll"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WOW6432Node\CLSID\{697DF02B-B24E-11D3-B57C-00105AA461D0}\InprocServer32]
""="C:\Program Files (x86)\IncrediMail\Bin\dten600.dll"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WOW6432Node\CLSID\{6D587C7F-27A0-4416-A90D-FB337F9B406C}\InprocServer32]
""="C:\Program Files (x86)\IncrediMail\Bin\ImComUtlU.dll"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WOW6432Node\CLSID\{7198EEC1-4364-4cd2-ABD0-A7914E032332}\InprocServer32]
""="C:\Program Files (x86)\IncrediMail\Bin\ImParserU.dll"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WOW6432Node\CLSID\{798CBE35-B27D-11D3-B57C-00105AA461D0}\InprocServer32]
""="C:\Program Files (x86)\IncrediMail\Bin\dten600.dll"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WOW6432Node\CLSID\{7E58CC0F-BC50-11D3-855B-0050DA2761C4}\InprocServer32]
""="C:\Program Files (x86)\IncrediMail\Bin\ImViewU.dll"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WOW6432Node\CLSID\{805FB5B9-6344-11D6-B7AF-005004C0C6BA}\InprocServer32]
""="C:\Program Files (x86)\IncrediMail\Bin\ImSuppU.dll"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WOW6432Node\CLSID\{84566316-EC70-11D5-881D-0050DA2761C4}\InprocServer32]
""="C:\Program Files (x86)\IncrediMail\Bin\ImFeatU.dll"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WOW6432Node\CLSID\{8BACC255-A3CF-4e27-BAF1-D531B1AE02FD}\InprocServer32]
""="C:\Program Files (x86)\IncrediMail\Bin\ImToolsU.dll"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WOW6432Node\CLSID\{9401BFDA-2F5C-4978-8075-7D8AFEC3AEE5}\InprocServer32]
""="C:\Program Files (x86)\IncrediMail\Bin\ImFeatU.dll"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WOW6432Node\CLSID\{995F48E8-131F-4630-9FBE-98D9DBDABB05}\InprocServer32]
""="C:\Program Files (x86)\IncrediMail\Bin\ImSpoolU.dll"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WOW6432Node\CLSID\{A0C301D9-59A5-45EB-90E8-D60D8149F5A5}\InprocServer32]
""="C:\Program Files (x86)\IncrediMail\Bin\ImParserU.dll"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WOW6432Node\CLSID\{A8D94870-BEA6-11D3-BB92-0050DA276194}\InprocServer32]
""="C:\Program Files (x86)\IncrediMail\Bin\ImSuppU.dll"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WOW6432Node\CLSID\{A967E5D6-B0E1-11D3-B57C-00105AA461D0}\InprocServer32]
""="C:\Program Files (x86)\IncrediMail\Bin\dten600.dll"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WOW6432Node\CLSID\{B385A628-C100-11D3-BB95-0050DA276194}\InprocServer32]
""="C:\Program Files (x86)\IncrediMail\Bin\ImNotfyU.dll"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WOW6432Node\CLSID\{BF1F5DE8-E9ED-421e-93EE-E0783D18AAF6}\InprocServer32]
""="C:\Program Files (x86)\IncrediMail\Bin\ImImprtU.dll"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WOW6432Node\CLSID\{C697956A-8C70-4EBD-9CC1-92218BC296B2}\InprocServer32]
""="C:\Program Files (x86)\IncrediMail\Bin\ImFeatU.dll"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WOW6432Node\CLSID\{C7681ACB-27AD-4025-8F53-643549159658}\InprocServer32]
""="C:\Program Files (x86)\IncrediMail\Bin\ImFeatU.dll"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WOW6432Node\CLSID\{CB382C7A-8852-458A-8900-C456C96FDB8C}\InprocServer32]
""="C:\Program Files (x86)\IncrediMail\Bin\ImViewU.dll"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WOW6432Node\CLSID\{CBF9925D-3C19-4F33-9DE4-446978645EBB}\InprocServer32]
""="C:\Program Files (x86)\IncrediMail\Bin\ImFeatU.dll"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WOW6432Node\CLSID\{D5C040B6-64BE-4855-BB40-7D4DD98B093A}\InprocServer32]
""="C:\Program Files (x86)\IncrediMail\Bin\ImToolsU.dll"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WOW6432Node\CLSID\{DA12A268-0ACB-11D4-859D-0050DA2761C4}\InprocServer32]
""="C:\Program Files (x86)\IncrediMail\Bin\ImFeatU.dll"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WOW6432Node\CLSID\{E1B6DE2A-F997-11D3-BBDB-0050DA276194}\InprocServer32]
""="C:\Program Files (x86)\IncrediMail\Bin\ImImprtU.dll"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WOW6432Node\CLSID\{E9BC70A8-D70C-11D3-BBAE-0050DA276194}\LocalServer32]
""=""C:\Program Files (x86)\IncrediMail\Bin\IncMail.exe""

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WOW6432Node\CLSID\{E9BC70A8-D70C-11D3-BBAE-0050DA276194}\VersionIndependentProgID]
""="IncrediMail.Kernel"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WOW6432Node\CLSID\{EC8717B6-F660-11D3-ADE2-0050DA744DF1}\InprocServer32]
""="C:\Program Files (x86)\IncrediMail\Bin\ImImprtU.dll"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WOW6432Node\CLSID\{EC8717C9-F660-11D3-ADE2-0050DA744DF1}\InprocServer32]
""="C:\Program Files (x86)\IncrediMail\Bin\ImImprtU.dll"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WOW6432Node\CLSID\{F1B4B6F1-55D1-11d6-B7AD-005004C0C6BA}\InprocServer32]
""="C:\Program Files (x86)\IncrediMail\Bin\ImImprtU.dll"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WOW6432Node\CLSID\{F648D80F-2409-4EDA-847D-8E820B03451F}\InprocServer32]
""="C:\Program Files (x86)\IncrediMail\Bin\ImServU.dll"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WOW6432Node\CLSID\{F9F135B6-F421-4259-AB7E-33E37641AD3C}\InprocServer32]
""="C:\Program Files (x86)\IncrediMail\Bin\ImNotfyU.dll"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WOW6432Node\CLSID\{FEBD6230-F4F6-4E79-89CD-4BEBDC4A96AE}\InprocServer32]
""="C:\Program Files (x86)\IncrediMail\Bin\ImFeatU.dll"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WOW6432Node\Interface\{133483C3-5BAB-45DD-94EE-1857CB47C6E5}]
""="IIncrediMailImporter"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WOW6432Node\AppID\{FCA7EB04-D708-11D3-BBAE-0050DA276194}]
""="IncrediMail"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WOW6432Node\TypeLib\{00E677A7-A7A5-4819-9580-1681BE30E28E}\1.0\0\win32]
""="C:\Program Files (x86)\IncrediMail\Bin\IncMail.exe"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WOW6432Node\TypeLib\{07A52AE8-B6F0-11D3-BB7E-0050DA276194}\1.0\0\win32]
""="C:\Program Files (x86)\IncrediMail\Bin\ImParserU.dll"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WOW6432Node\TypeLib\{0B9A0841-1EC3-11D5-B75C-005004C0C6BA}\1.0\0\win32]
""="C:\Program Files (x86)\IncrediMail\Bin\ImFeatU.dll"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WOW6432Node\TypeLib\{60BE6CEF-036C-4440-9847-7A32006DCF4B}\1.0\0\win32]
""="C:\Program Files (x86)\IncrediMail\Bin\ImNotfy.exe"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WOW6432Node\TypeLib\{6D293D13-C375-11D3-BB98-0050DA276194}\1.0\0\win32]
""="C:\Program Files (x86)\IncrediMail\Bin\ImSuppU.dll"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WOW6432Node\TypeLib\{7E58CC01-BC50-11D3-855B-0050DA2761C4}\1.0\0\win32]
""="C:\Program Files (x86)\IncrediMail\Bin\ImViewU.dll"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WOW6432Node\TypeLib\{815F81B9-E268-489D-883A-B5BC5BED9F03}\1.0\HELPDIR]
""="C:\Program Files (x86)\IncrediMail\Bin\"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WOW6432Node\TypeLib\{A967E5C4-B0E1-11D3-B57C-00105AA461D0}\1.0\0\win32]
""="C:\Program Files (x86)\IncrediMail\Bin\dten600.dll"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WOW6432Node\TypeLib\{C762F735-0863-4E91-B46F-3F6C303778FE}\1.0\0\win32]
""="C:\Program Files (x86)\IncrediMail\Bin\ImJunkU.dll"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WOW6432Node\TypeLib\{CB073674-BD1F-11D3-BB90-0050DA276194}\1.0\0\win32]
""="C:\Program Files (x86)\IncrediMail\Bin\ImMangrU.dll"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WOW6432Node\TypeLib\{F8984103-38B6-11D5-8725-0050DA2761C4}\1.0\0\win32]
""="C:\Program Files (x86)\IncrediMail\Bin\ImShExtU.dll"

[HKEY_LOCAL_MACHINE\SOFTWARE\Clients\Mail\IncrediMail]
""="IncrediMail"

[HKEY_LOCAL_MACHINE\SOFTWARE\Clients\Mail\IncrediMail\Capabilities]
"ApplicationDescription"="IncrediMail"

[HKEY_LOCAL_MACHINE\SOFTWARE\Clients\Mail\IncrediMail\Protocols\mailto\DefaultIcon]
""="C:\Program Files (x86)\IncrediMail\Bin\IncMail.exe,0"

[HKEY_LOCAL_MACHINE\SOFTWARE\Clients\Mail\IncrediMail\Shell\Open\Command]
""="C:\Program Files (x86)\IncrediMail\Bin\IncMail.exe"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\ImBpp.exe]
""="C:\Program Files (x86)\IncrediMail\Bin\ImBpp.exe"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\ImLc.exe]
""="C:\Program Files (x86)\IncrediMail\Bin\ImLc.exe"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\ImLcU.exe]
""="C:\Program Files (x86)\IncrediMail\Bin\ImLc.exe"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\ImLpp.exe]
"Path"="C:\Program Files (x86)\IncrediMail\Bin"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\ImPackr.exe]
""="C:\Program Files (x86)\IncrediMail\Bin\impackr.exe"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\impackrU.exe]
""="C:\Program Files (x86)\IncrediMail\Bin\impackr.exe"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\ImpCnt.exe]
""="C:\Program Files (x86)\IncrediMail\Bin\ImpCnt.exe"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\ImpCntU.exe]
""="C:\Program Files (x86)\IncrediMail\Bin\ImpCnt.exe"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\ImpContent.exe]
""="C:\Program Files (x86)\IncrediMail\Bin\ImpCnt.exe"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\ImSetup.exe]
""="C:\Program Files (x86)\IncrediMail\Bin\ImSetup.exe"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\IncMail.exe]
""="C:\Program Files (x86)\IncrediMail\Bin\IncMail.exe"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\IncMailU.exe]
""="C:\Program Files (x86)\IncrediMail\Bin\IncMail.exe"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\IncrediMail.exe]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\IncrediMail.exe]
"Path"="C:\Program Files (x86)\IncrediMail\Bin"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Folders]
"C:\ProgramData\IncrediMail\"=""

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Folders]
"C:\ProgramData\Microsoft\Windows\Start Menu\Programs\IncrediMail\"=""

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Folders]
"C:\Program Files (x86)\IncrediMail\"="1"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Folders]
"C:\ProgramData\IncrediMail\Data\IMSys\{781B9B29-76A7-423f-A038-5BB34D4F48FA}\"="1"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Folders]
"C:\ProgramData\IncrediMail\Data\IMSys\{781B9B29-76A7-423f-A038-5BB34D4F48FA}\930\"="1"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Folders]
"C:\Program Files (x86)\IncrediMail\Bin\assets\flickr\"=""

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Folders]
"C:\ProgramData\IncrediMail\Data\Pictures\"=""

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Folders]
"C:\ProgramData\IncrediMail\Data\Pictures\{0764C0CC-7A86-4765-B0B6-9CA2A93F06E7}\"=""

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Folders]
"C:\ProgramData\IncrediMail\Data\Pictures\{09D2DBAB-C227-41D1-BAA0-7DF27CF733F2}\"=""

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Folders]
"C:\ProgramData\IncrediMail\Data\Pictures\{0C14A18B-C2AC-4669-86E4-B9E73BE84718}\"=""

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Folders]
"C:\ProgramData\IncrediMail\Data\Pictures\{109056AE-5DE4-4EAE-91CB-6BB390A09A59}\"=""

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Folders]
"C:\ProgramData\IncrediMail\Data\Pictures\{132C7AA8-241D-49C7-B908-8223AA880F6A}\"=""

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Folders]
"C:\ProgramData\IncrediMail\Data\Pictures\{1947E5E1-F1D7-4E50-9FC6-0B9D8A279E8D}\"=""

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Folders]
"C:\ProgramData\IncrediMail\Data\Pictures\{1D63DEA0-1C10-4705-81EE-86BA1C9445C1}\"=""

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Folders]
"C:\ProgramData\IncrediMail\Data\Pictures\{23E41B8B-DDDE-4FC5-90E0-D309639FA056}\"=""

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Folders]
"C:\ProgramData\IncrediMail\Data\Pictures\{25E53664-29F4-4705-91D4-62F10E642451}\"=""

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Folders]
"C:\ProgramData\IncrediMail\Data\Pictures\{2A3F5A21-8665-4DBD-9BD2-7A88A001E4BD}\"=""

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Folders]
"C:\ProgramData\IncrediMail\Data\Pictures\{2AAFE8D5-FB97-4798-BE6C-823BE84F22ED}\"=""

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Folders]
"C:\ProgramData\IncrediMail\Data\Pictures\{2E8A33E4-B57B-4F09-9BC1-8C5AB6CB5223}\"=""

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Folders]
"C:\ProgramData\IncrediMail\Data\Pictures\{35180BF0-14A8-4DF2-97A9-1892D2FF46F1}\"=""

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Folders]
"C:\ProgramData\IncrediMail\Data\Pictures\{3BDC7D91-1C7D-471E-B6C6-A3510E0E79E6}\"=""

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Folders]
"C:\ProgramData\IncrediMail\Data\Pictures\{40C815FD-5C64-4E20-8ED1-0F2D1BF4706C}\"=""

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Folders]
"C:\ProgramData\IncrediMail\Data\Pictures\{44A7185B-21E9-463C-8B7A-AAF720497BAC}\"=""

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Folders]
"C:\ProgramData\IncrediMail\Data\Pictures\{47E48499-939C-497C-9F67-9AFB489E214B}\"=""

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Folders]
"C:\ProgramData\IncrediMail\Data\Pictures\{4C448A7E-528C-4DC9-9F5A-132DBBB5BAE4}\"=""

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Folders]
"C:\ProgramData\IncrediMail\Data\Pictures\{54B87B0C-3BC4-4CAE-94E7-4A917E65C9B6}\"=""

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Folders]
"C:\ProgramData\IncrediMail\Data\Pictures\{5801CC77-1E03-44F9-AF1E-DA0D5AD9231A}\"=""

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Folders]
"C:\ProgramData\IncrediMail\Data\Pictures\{595CB421-00D3-4E28-996B-11DFBBD68346}\"=""

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Folders]
"C:\ProgramData\IncrediMail\Data\Pictures\{5E2291A7-EE52-4655-AEBE-45E91FB16A64}\"=""

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Folders]
"C:\ProgramData\IncrediMail\Data\Pictures\{5F5071A6-74A5-4E9A-8592-255121BEAB1D}\"=""

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Folders]
"C:\ProgramData\IncrediMail\Data\Pictures\{7388F73B-495E-4037-B5B2-10DBF7F20012}\"=""

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Folders]
"C:\ProgramData\IncrediMail\Data\Pictures\{7BF844DF-6225-4800-9DED-87A359D3BD01}\"=""

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Folders]
"C:\ProgramData\IncrediMail\Data\Pictures\{7E2E1AFB-85DC-4716-92BF-981E483A4706}\"=""

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Folders]
"C:\ProgramData\IncrediMail\Data\Pictures\{8433493E-6DAA-42E1-949D-5CEDD29EEE81}\"=""

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Folders]
"C:\ProgramData\IncrediMail\Data\Pictures\{8A1EA157-6F51-414B-B83B-CEC4B010D6E2}\"=""

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Folders]
"C:\ProgramData\IncrediMail\Data\Pictures\{90DD0D61-009F-4805-A714-956C0B2F51EF}\"=""

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Folders]
"C:\ProgramData\IncrediMail\Data\Pictures\{95513B5D-7E7F-4963-82D9-5709E57F7908}\"=""

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Folders]
"C:\ProgramData\IncrediMail\Data\Pictures\{9C88AB9F-936E-479D-B4A6-6AC386700312}\"=""

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Folders]
"C:\ProgramData\IncrediMail\Data\Pictures\{A0953278-741A-43F6-92C9-A9B147CA691A}\"=""

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Folders]
"C:\ProgramData\IncrediMail\Data\Pictures\{A9272F22-D0C1-4E0B-8DD9-B2C55B88E7FC}\"=""

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Folders]
"C:\ProgramData\IncrediMail\Data\Pictures\{B24EA274-F645-4A7B-8463-2E799E23CD27}\"=""

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Folders]
"C:\ProgramData\IncrediMail\Data\Pictures\{B67DDF5A-3B6B-4E0B-98E5-9CA9AB65EF28}\"=""

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Folders]
"C:\ProgramData\IncrediMail\Data\Pictures\{BF00389C-CC6F-4B99-B473-A2BD4882947E}\"=""

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Folders]
"C:\ProgramData\IncrediMail\Data\Pictures\{C531BFEE-8994-47DD-9687-DA13DE38F0C9}\"=""

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Folders]
"C:\ProgramData\IncrediMail\Data\Pictures\{D73E2035-9FD9-4F48-8FA3-5C829439EFC8}\"=""

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Folders]
"C:\ProgramData\IncrediMail\Data\Pictures\{D820E2E9-452D-4CE8-83D4-FC32D8EC0295}\"=""

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Folders]
"C:\ProgramData\IncrediMail\Data\Pictures\{D9399675-900F-489B-AA91-4B69567999E5}\"=""

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Folders]
"C:\ProgramData\IncrediMail\Data\Pictures\{E3E4EDD2-55B5-4764-9DEC-A84EDE963EF8}\"=""

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Folders]
"C:\ProgramData\IncrediMail\Data\Pictures\{E7377AFF-D892-4EE3-AA61-06D7434B40D3}\"=""

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Folders]
"C:\ProgramData\IncrediMail\Data\Pictures\{EC1A3858-E483-4D91-AA28-B62F09ADF75C}\"=""

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Folders]
"C:\ProgramData\IncrediMail\Data\Pictures\{F9752AC4-9B3F-435D-A942-012F1FC997C7}\"=""

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Folders]
"C:\ProgramData\IncrediMail\Data\Pictures\{FBFACA01-2994-457B-B3A8-4F92759BA3A2}\"=""

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Folders]
"C:\ProgramData\IncrediMail\Data\Pictures\{FF249D89-5CD7-40B5-BB82-D081E65EE1C3}\"=""

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Folders]
"C:\ProgramData\IncrediMail\Data\LetterCreator\"=""

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Folders]
"C:\ProgramData\IncrediMail\Data\LetterCreator\ISamples\Tile General\"=""

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Folders]
"C:\ProgramData\IncrediMail\Data\LetterCreator\ISamples\Tile Papers\"=""

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Folders]
"C:\ProgramData\IncrediMail\Data\LetterCreator\Skin\"=""

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Folders]
"C:\ProgramData\IncrediMail\Data\EmoticonsAC\"=""

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Folders]
"C:\ProgramData\IncrediMail\Data\Welcome\HomePage\"=""

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Folders]
"C:\ProgramData\IncrediMail\Data\Welcome\HomePage\images\english\"=""

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Folders]
"C:\ProgramData\IncrediMail\Data\IMSys\{781B9B29-76A7-423f-A038-5BB34D4F48FA}\913\images\"=""

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Folders]
"C:\ProgramData\IncrediMail\Data\IMSys\{781B9B29-76A7-423f-A038-5BB34D4F48FA}\915\"=""

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Folders]
"C:\ProgramData\IncrediMail\Data\IMSys\{781B9B29-76A7-423f-A038-5BB34D4F48FA}\917\"=""

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Folders]
"C:\ProgramData\IncrediMail\Data\IMSys\{781B9B29-76A7-423f-A038-5BB34D4F48FA}\919\"=""

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Folders]
"C:\ProgramData\IncrediMail\Data\IMSys\{781B9B29-76A7-423f-A038-5BB34D4F48FA}\921\"=""

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Folders]
"C:\ProgramData\IncrediMail\Data\IMSys\{781B9B29-76A7-423f-A038-5BB34D4F48FA}\923\"=""

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Folders]
"C:\ProgramData\IncrediMail\Data\IMSys\{781B9B29-76A7-423f-A038-5BB34D4F48FA}\925\"=""

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Folders]
"C:\ProgramData\IncrediMail\Data\IMSys\{781B9B29-76A7-423f-A038-5BB34D4F48FA}\927\"=""

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Folders]
"C:\ProgramData\IncrediMail\Data\IMSys\{781B9B29-76A7-423f-A038-5BB34D4F48FA}\929\"=""

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Folders]
"C:\ProgramData\IncrediMail\Data\IMSys\{781B9B29-76A7-423f-A038-5BB34D4F48FA}\931\"=""

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Folders]
"C:\ProgramData\IncrediMail\Data\IMSys\{781B9B29-76A7-423f-A038-5BB34D4F48FA}\931\DeluxeThankYouDialog\english\"=""

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Folders]
"C:\ProgramData\IncrediMail\Data\IMSys\{781B9B29-76A7-423f-A038-5BB34D4F48FA}\932\noMystartDialog\"=""

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Folders]
"C:\ProgramData\IncrediMail\Data\IMSys\{781B9B29-76A7-423f-A038-5BB34D4F48FA}\933\"=""

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Folders]
"C:\ProgramData\IncrediMail\Data\IMSys\{781B9B29-76A7-423f-A038-5BB34D4F48FA}\934\"=""

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Folders]
"C:\ProgramData\IncrediMail\Data\IMSys\{781B9B29-76A7-423f-A038-5BB34D4F48FA}\935\"=""

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Folders]
"C:\ProgramData\IncrediMail\Data\IMSys\{781B9B29-76A7-423f-A038-5BB34D4F48FA}\940\"=""

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Folders]
"C:\ProgramData\IncrediMail\Data\IMSys\{781B9B29-76A7-423f-A038-5BB34D4F48FA}\941\Images\"=""

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Folders]
"C:\ProgramData\IncrediMail\Data\IMSys\{781B9B29-76A7-423f-A038-5BB34D4F48FA}\943\"=""

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Folders]
"C:\ProgramData\IncrediMail\Data\IMSys\{781B9B29-76A7-423f-A038-5BB34D4F48FA}\944\"=""

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Folders]
"C:\ProgramData\IncrediMail\Data\IMSys\{781B9B29-76A7-423f-A038-5BB34D4F48FA}\945\"=""

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Folders]
"C:\ProgramData\IncrediMail\Data\IMSys\{781B9B29-76A7-423f-A038-5BB34D4F48FA}\946\"=""

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Folders]
"C:\ProgramData\IncrediMail\Data\IMSys\{781B9B29-76A7-423f-A038-5BB34D4F48FA}\948\"=""

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Folders]
"C:\ProgramData\IncrediMail\Data\Default Identity\EmoticonCenter\"=""

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Folders]
"C:\ProgramData\IncrediMail\Data\DomainsFavicons\"=""

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Folders]
"C:\ProgramData\IncrediMail\Data\Default Identity\EmoticonCenter\MyEmoticons\QuickBar\"=""

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Folders]
"C:\ProgramData\IncrediMail\Data\Default Identity\Icons\"=""

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Folders]
"C:\ProgramData\IncrediMail\Data\JunkPreview\"=""

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Folders]
"C:\ProgramData\IncrediMail\Data\ProtectionCenter\"=""

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Folders]
"C:\ProgramData\IncrediMail\Data\Lex\"=""

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Folders]
"C:\Program Files (x86)\IncrediMail\Bin\resources\"=""

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\014E48F95820EC2389464F255D5FCEDD]
"1EA505532E7260243BFB857781308B0D"="C:\ProgramData\IncrediMail\Data\Pictures\{1190927C-0CA1-498D-812F-21A32E20C88B}\cool.gif"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\023B8AC84B86AD24DA43B205ABF36FC5]
"1EA505532E7260243BFB857781308B0D"="C:\Program Files (x86)\IncrediMail\Bin\SecurePasswords_Desktop.url"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\033CEFF4336DEEE48B026FA9CC84374C]
"1EA505532E7260243BFB857781308B0D"="C:\Program Files (x86)\IncrediMail\Bin\ImMangrRU.dll"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\05860C1D53B03D75BAFC4B620CFBDF8C]
"1EA505532E7260243BFB857781308B0D"="C:\ProgramData\IncrediMail\Data\Pictures\{5801CC77-1E03-44F9-AF1E-DA0D5AD9231A}\scary_lion.gif"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\08E8B33E5000AD45C49610DD4C571A42]
"1EA505532E7260243BFB857781308B0D"="C:\ProgramData\IncrediMail\Data\Welcome\HomePage\images\body_bg.jpg"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\0D40449C3A50C62C56C9BDF5CEF35430]
"1EA505532E7260243BFB857781308B0D"="C:\ProgramData\IncrediMail\Data\Pictures\{DB4CA8A9-279C-44F0-AE35-79CFECC1ED42}\ginger_cat.gif"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\0E5CB49DF8F321C43B8FF93EDE5D2D32]
"1EA505532E7260243BFB857781308B0D"="C:\ProgramData\IncrediMail\Data\DomainsFavicons\"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\1082609EAB72FB844AFEF7C3B673A92B]
"1EA505532E7260243BFB857781308B0D"="C:\Program Files (x86)\IncrediMail\Bin\ImParserU.dll"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\118F205369DD0E44392EDAFEF5556B92]
"1EA505532E7260243BFB857781308B0D"="C:\Program Files (x86)\IncrediMail\Bin\ImSc.exe"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\11F4309B92910F06CEFA1DCCBC3E22F7]
"1EA505532E7260243BFB857781308B0D"="C:\ProgramData\IncrediMail\Data\Pictures\{E7377AFF-D892-4EE3-AA61-06D7434B40D3}\happy_pup.gif"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\14D754CFD9A151E576426162E7FF6605]
"1EA505532E7260243BFB857781308B0D"="C:\ProgramData\IncrediMail\Data\IMSys\{781B9B29-76A7-423f-A038-5BB34D4F48FA}\916\RDDlg.dat"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\17D6291FA57913B46BCFA2B14B0C59C4]
"1EA505532E7260243BFB857781308B0D"="C:\ProgramData\IncrediMail\Data\Default Identity\EmoticonCenter\superpack_star.bmp"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\1A2203F3EB6153A8BFD47727FB06F8C8]
"1EA505532E7260243BFB857781308B0D"="C:\ProgramData\IncrediMail\Data\IMSys\{781B9B29-76A7-423f-A038-5BB34D4F48FA}\932\RDDlg.dat"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\1BD489C31A435654D8CF8A365A8E56EA]
"1EA505532E7260243BFB857781308B0D"="C:\ProgramData\IncrediMail\Data\IMSys\"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\1CC5233482E183DB28C72D7501ABAAD0]
"1EA505532E7260243BFB857781308B0D"="C:\ProgramData\IncrediMail\Data\IMSys\{781B9B29-76A7-423f-A038-5BB34D4F48FA}\924\RDDlg.dat"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\1D44A9EB7E515DC4653B40701E4B9AF7]
"1EA505532E7260243BFB857781308B0D"="C:\ProgramData\IncrediMail\Data\IMSys\{781B9B29-76A7-423f-A038-5BB34D4F48FA}\"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\1F10511B9AF1235779716C821A93C0FA]
"1EA505532E7260243BFB857781308B0D"="C:\ProgramData\IncrediMail\Data\Pictures\{46BE39D0-31AA-49F2-BC4E-77A71B2568B4}\chubby_dog.gif"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\1F6D84A0A0012B001BF9B5D6D0B02096]
"1EA505532E7260243BFB857781308B0D"="C:\ProgramData\IncrediMail\Data\IMSys\{781B9B29-76A7-423f-A038-5BB34D4F48FA}\948\RDDlg.dat"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\21B75A2B3F22C72819073BEDF41EFD61]
"1EA505532E7260243BFB857781308B0D"="C:\ProgramData\IncrediMail\Data\Pictures\{109056AE-5DE4-4EAE-91CB-6BB390A09A59}\cancer_50x50.gif"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\23C3C9595B9203DCE46E04F1EE28206A]
"1EA505532E7260243BFB857781308B0D"="C:\ProgramData\IncrediMail\Data\Pictures\{EE546098-5A39-4870-9678-82BC9220D213}\sad.gif"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\286FB5A04FCEF1D4DB63DA74A77F000A]
"00000000000000000000000000000000"="C:\ProgramData\IncrediMail\Data\Licenses\IM_SYSTEM.imk"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\2B338A4A4C39EA543B2A2AEE03D1CEBD]
"1EA505532E7260243BFB857781308B0D"="C:\ProgramData\IncrediMail\Data\LetterCreator\ISamples\Tile Elegant\Tweed_Oak.jpg"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\2F749A7F39A26E881ED51C44B7D09166]
"1EA505532E7260243BFB857781308B0D"="C:\ProgramData\IncrediMail\Data\IMSys\{781B9B29-76A7-423f-A038-5BB34D4F48FA}\946\RDDlg.dat"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\31CCB1762E437838C5219DDCA52A318A]
"1EA505532E7260243BFB857781308B0D"="C:\ProgramData\IncrediMail\Data\IMSys\{781B9B29-76A7-423f-A038-5BB34D4F48FA}\936\RDDlg.dat"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\33AEDEAF9C030AFB75C5789153CF1230]
"1EA505532E7260243BFB857781308B0D"="C:\ProgramData\IncrediMail\Data\IMSys\{781B9B29-76A7-423f-A038-5BB34D4F48FA}\915\RDDlg.dat"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\35EFA9D100838D8EF1196A5B7BF26B66]
"1EA505532E7260243BFB857781308B0D"="C:\ProgramData\IncrediMail\Data\IMSys\{781B9B29-76A7-423f-A038-5BB34D4F48FA}\947\RDDlg.dat"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\38BF4E07F5E329F52E4AD09754005943]
"1EA505532E7260243BFB857781308B0D"="C:\ProgramData\IncrediMail\Data\Pictures\{FEE9B36E-2CFB-4537-829B-50DEC559E875}\bliss.gif"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\3BD3B380D6233BEDC49F172A40FC240B]
"1EA505532E7260243BFB857781308B0D"="C:\ProgramData\IncrediMail\Data\Pictures\{7D44BD65-D99A-4248-9981-6367C9910A5F}\gold_fish2.gif"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\40FA3F335E3FCE3429F6C1424C43BD70]
"1EA505532E7260243BFB857781308B0D"="C:\ProgramData\IncrediMail\Data\Welcome\Welcome2.eml"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\42F6DEAE45741D0348F3064FC1020932]
"1EA505532E7260243BFB857781308B0D"="C:\ProgramData\IncrediMail\Data\Pictures\{578BC8DD-3211-423B-AD26-39F907B1BE62}\crazy.gif"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\44AA78035EE4183FF2CE06D21334A6E2]
"1EA505532E7260243BFB857781308B0D"="C:\ProgramData\IncrediMail\Data\Pictures\{C1EA2691-0130-49E4-8EA4-F8966B892393}\girl.gif"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\45870050D28AB374CB173B92191C4ABD]
"1EA505532E7260243BFB857781308B0D"="C:\Program Files (x86)\IncrediMail\Bin\ImLookU.dll"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\47AE3DA25D6923B4196AED99AB93F6AB]
"1EA505532E7260243BFB857781308B0D"="C?\Program Files (x86)\IncrediMail\Bin\ImBpp.exe"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\4997AE12C03471631C2499BCEB7F78FB]
"1EA505532E7260243BFB857781308B0D"="C:\ProgramData\IncrediMail\Data\Pictures\{251A17B1-A3C8-4D3A-A7D8-8263B3F384EF}\doggy_50_50.gif"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\4B0E4EDC33741253A8E1E51AB7474501]
"1EA505532E7260243BFB857781308B0D"="C:\ProgramData\IncrediMail\Data\Pictures\{7388F73B-495E-4037-B5B2-10DBF7F20012}\libra_50x50.gif"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\4B74C9BD6EE7CDD4B8F68C73E9FBE777]
"1EA505532E7260243BFB857781308B0D"="C:\Program Files (x86)\IncrediMail\Bin\ImAppRU.dll"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\4EFE4B82BA39DE74BA3090AAABA60D81]
"1EA505532E7260243BFB857781308B0D"="C:\Program Files (x86)\IncrediMail\Bin\wlessfp1.dll"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\50DA28EB4525BD7F0D9B3BD1389D32AC]
"1EA505532E7260243BFB857781308B0D"="C:\ProgramData\IncrediMail\Data\Pictures\{4C448A7E-528C-4DC9-9F5A-132DBBB5BAE4}\fairy.gif"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\55FB1408DB1F999419E31B96D3A42A6C]
"1EA505532E7260243BFB857781308B0D"="C:\ProgramData\IncrediMail\Data\JunkPreview\JFPlusOn.eml"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\5698C5DD8585BC1BC19B44B7B62659D4]
"1EA505532E7260243BFB857781308B0D"="C:\ProgramData\IncrediMail\Data\Pictures\{194AFDE0-4FFA-46E2-AD4C-56213B86EB24}\waving_kitty_50_50.gif"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\5A54F6860477F2A4F943CC6B8275C71F]
"1EA505532E7260243BFB857781308B0D"="C:\ProgramData\IncrediMail\Data\EmoticonsAC\EmoticonsAC.xml"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\5B5FC8DAC7346684DBB2A750AF473283]
"1EA505532E7260243BFB857781308B0D"="C:\Program Files (x86)\IncrediMail\Bin\ImPackrRU.dll"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\5C9DF4B668FE918488AC070320498756]
"00000000000000000000000000000000"="C:\ProgramData\IncrediMail\Data\Licenses\IM_PREM.imk"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\5D4C81BCCE358FA1A1BB3EA1B9E3360A]
"1EA505532E7260243BFB857781308B0D"="C:\ProgramData\IncrediMail\Data\IMSys\{781B9B29-76A7-423f-A038-5BB34D4F48FA}\944\Images\bg.jpg"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\617379C0DBC9761499BF26900208E6F7]
"00000000000000000000000000000000"="C:\ProgramData\IncrediMail\Data\Licenses\IM_PRIME.imk"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\6322BD053A067C97FFEEDB838D28B1FE]
"1EA505532E7260243BFB857781308B0D"="C:\ProgramData\IncrediMail\Data\Pictures\{D766A57D-EDC0-4A5D-99D5-040CECA4243A}\sea_turtle_50_50.gif"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\65041C80E1848AF4EBDA8FCC71E1C306]
"1EA505532E7260243BFB857781308B0D"="C:\ProgramData\IncrediMail\Data\fonts.txt"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\6789EB2723C80284C911B14F0B11D9E2]
"1EA505532E7260243BFB857781308B0D"="C:\ProgramData\IncrediMail\Data\LetterCreator\LSamples\Tiled_image_and_transparent_footer_image.ltw"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\6A3142853426AF148C3AC0EB5207882A]
"1EA505532E7260243BFB857781308B0D"="C:\ProgramData\IncrediMail\Data\Pictures\{07C4D36C-62D4-4D4B-8D8B-D1CF14BAFC7E}\hiding_dog.gif"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\6C1F1ABB0A6D00C43AEE089AC02AEAC6]
"1EA505532E7260243BFB857781308B0D"="C:\Program Files (x86)\IncrediMail\Bin\ImApp.exe"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\6D1050B77D56C10F7814E51176182300]
"1EA505532E7260243BFB857781308B0D"="C:\ProgramData\IncrediMail\Data\IMSys\{781B9B29-76A7-423f-A038-5BB34D4F48FA}\917\JFPlusOff.eml"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\6EE30D5BFC26437273B91A5F7BCE5D95]
"1EA505532E7260243BFB857781308B0D"="C:\ProgramData\IncrediMail\Data\Pictures\{E984453A-44FD-48E6-880D-73AF61F1BE53}\sagittarius_50x50.gif"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\71F3C1A07C3458F42B4BBB5E2DB75CD0]
"1EA505532E7260243BFB857781308B0D"="C:\Program Files (x86)\IncrediMail\Bin\ImServU.dll"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\73E5EA58C192D0A419FAF3811D735EF8]
"1EA505532E7260243BFB857781308B0D"="C:\ProgramData\IncrediMail\Data\Index\"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\7808B18BDE379C6279B24FD15811B82C]
"1EA505532E7260243BFB857781308B0D"="C:\ProgramData\IncrediMail\Data\IMSys\{781B9B29-76A7-423f-A038-5BB34D4F48FA}\927\RDDlg.dat"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\7B56E5DC72D707091F821A0E5490F64B]
"1EA505532E7260243BFB857781308B0D"="C:\ProgramData\IncrediMail\Data\IMSys\{781B9B29-76A7-423f-A038-5BB34D4F48FA}\941\RDDlg.dat"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\7DE529FDF40753573F1A9F6C774047DF]
"1EA505532E7260243BFB857781308B0D"="C:\ProgramData\IncrediMail\Data\Pictures\{35180BF0-14A8-4DF2-97A9-1892D2FF46F1}\dimbo.gif"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\7E704CF2B347D63F5CE4A6D80C67CE02]
"1EA505532E7260243BFB857781308B0D"="C:\ProgramData\IncrediMail\Data\IMSys\{781B9B29-76A7-423f-A038-5BB34D4F48FA}\925\RDDlg.dat"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\80358A43F00A0BE40B31C1295D8A40A1]
"1EA505532E7260243BFB857781308B0D"="C?\Program Files (x86)\IncrediMail\Bin\resources\WebMenuImg.htm"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\82563AF3D0593F947A9509B1B1C94D9C]
"1EA505532E7260243BFB857781308B0D"="C:\Program Files (x86)\IncrediMail\Bin\ImMangrU.dll"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\83909AD4D2B803FCEC59D6246F804A98]
"1EA505532E7260243BFB857781308B0D"="C:\ProgramData\IncrediMail\Data\Pictures\{4AE8FF68-2CE6-419B-BE74-A70EEB12AF27}\froggy_love.gif"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\86000779B758F75B58F75C3E53CEA666]
"1EA505532E7260243BFB857781308B0D"="C:\ProgramData\IncrediMail\Data\Pictures\{E3E4EDD2-55B5-4764-9DEC-A84EDE963EF8}\samurai.gif"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\87D42E0FFBAB67445B913F26725736A0]
"1EA505532E7260243BFB857781308B0D"="C:\Program Files (x86)\IncrediMail\Bin\ImSpoolU.dll"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\897FDDBB33866CB47910FEB07D74B9DA]
"1EA505532E7260243BFB857781308B0D"="C:\Program Files (x86)\IncrediMail\Bin\ImShExtU.dll"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\89CDCB2441584BE27FF64C100DA2A82D]
"1EA505532E7260243BFB857781308B0D"="C:\ProgramData\IncrediMail\Data\Pictures\{FF249D89-5CD7-40B5-BB82-D081E65EE1C3}\06.gif"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\8C315CCAA1A8102234C30BF369F8FFCD]
"1EA505532E7260243BFB857781308B0D"="C:\ProgramData\IncrediMail\Data\IMSys\{781B9B29-76A7-423f-A038-5BB34D4F48FA}\940\RDDlg.dat"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\8F38D2FE548865340943EFF6BF151509]
"1EA505532E7260243BFB857781308B0D"="01:\Software\IncrediMail\"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\9122A3E2AD4A933459798A4417D12497]
"1EA505532E7260243BFB857781308B0D"="C:\ProgramData\IncrediMail\Data\Chummycons\spacer.gif"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\93623D9F4DF9FE8A35737906225D0EC2]
"1EA505532E7260243BFB857781308B0D"="C:\ProgramData\IncrediMail\Data\Pictures\{EC1A3858-E483-4D91-AA28-B62F09ADF75C}\ganja.gif"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\93F7C5A77F99F55496F87F8472296D29]
"1EA505532E7260243BFB857781308B0D"="C:\ProgramData\IncrediMail\Data\IMSys\{781B9B29-76A7-423f-A038-5BB34D4F48FA}\945\Images\bg_bottom.gif"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\94B3B65603AD4E04F8CBB9702E58250A]
"1EA505532E7260243BFB857781308B0D"="C:\Program Files (x86)\IncrediMail\Bin\sqlite3.dll"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\96A74B5DF9C95B50ACC4A78C73C7266F]
"1EA505532E7260243BFB857781308B0D"="C:\ProgramData\IncrediMail\Data\Pictures\{C531BFEE-8994-47DD-9687-DA13DE38F0C9}\trampoline_girl1.gif"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\98F2298FCE39650972972F11400DA23E]
"1EA505532E7260243BFB857781308B0D"="C:\ProgramData\IncrediMail\Data\Pictures\{9FD9F8A0-06BE-4F26-92EC-89E5B047FA2E}\hippo.gif"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\9AF347AFDD158E34DBEB06C4BEA7B33E]
"1EA505532E7260243BFB857781308B0D"="C:\ProgramData\IncrediMail\Data\LetterCreator\ISamples\Tile General\WoodChalk.jpg"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\9C3331D39C9981D88EC754A6BF48CF0B]
"1EA505532E7260243BFB857781308B0D"="C:\ProgramData\IncrediMail\Data\IMSys\{781B9B29-76A7-423f-A038-5BB34D4F48FA}\920\RDDlg.dat"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\9D73DEDB51EA0C5479B4514B702BF4FB]
"1EA505532E7260243BFB857781308B0D"="C:\Program Files (x86)\IncrediMail\Bin\ImNotfyRU.dll"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\9EE68D18A6C68DD4F9F3BAB184F02D61]
"1EA505532E7260243BFB857781308B0D"="C:\Program Files (x86)\IncrediMail\Bin\ImNotfy.exe"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\A0B78A38BF1ABA7EE1B1691F854A0A93]
"1EA505532E7260243BFB857781308B0D"="C:\ProgramData\IncrediMail\Data\IMSys\{781B9B29-76A7-423f-A038-5BB34D4F48FA}\943\RDDlg.dat"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\A3CF65DCE244D1342BCEE6BAD82C5EC5]
"1EA505532E7260243BFB857781308B0D"="C:\Program Files (x86)\IncrediMail\Bin\wflash3.dll"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\A404DFC6DE0A96ACFE917C819F150E7B]
"1EA505532E7260243BFB857781308B0D"="C:\ProgramData\IncrediMail\Data\Pictures\{9C88AB9F-936E-479D-B4A6-6AC386700312}\black_lady.gif"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\A6897A3C089A2A669358437276A85414]
"1EA505532E7260243BFB857781308B0D"="C:\ProgramData\IncrediMail\Data\Pictures\{B18CEA45-08C4-44F4-B079-EB9FD8D3C66E}\pink_pup.gif"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\A69FD029D1CABFE2699B56308126FACE]
"1EA505532E7260243BFB857781308B0D"="C:\ProgramData\IncrediMail\Data\IMSys\{781B9B29-76A7-423f-A038-5BB34D4F48FA}\935\RDDlg.dat"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\A730B662729E7674596B8E02B9F2BF7C]
"1EA505532E7260243BFB857781308B0D"="C:\Program Files (x86)\IncrediMail\Bin\ImLookExU.dll"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\A859D81B6312FDC40BE1B73620ADF482]
"1EA505532E7260243BFB857781308B0D"="C:\ProgramData\IncrediMail\Data\LetterCreator\Skin\Signature.gif"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\AA21A683AF4A2EBB283E3BF2F47212A2]
"1EA505532E7260243BFB857781308B0D"="C:\ProgramData\IncrediMail\Data\Pictures\{34B4B5E4-6EFD-4C33-8F14-ADB675C31F49}\10.gif"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\ABA77C44ABA1F2242BA2712DE5DCA4D3]
"1EA505532E7260243BFB857781308B0D"="C:\Program Files (x86)\IncrediMail\Bin\ImSearchU.dll"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\AD4E5AD8713332F41A348BB9E963CFC0]
"1EA505532E7260243BFB857781308B0D"="C:\Program Files (x86)\IncrediMail\Bin\ImFeatRU.dll"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\AED2F6C059DAE362A6BC735BED91DAE6]
"1EA505532E7260243BFB857781308B0D"="C:\ProgramData\IncrediMail\Data\Pictures\{3AEF0E06-B06D-44B9-A019-0A6C317C979D}\bunny_50_50.gif"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\B0BEA37BEE7BC36CD4D40F2867611565]
"1EA505532E7260243BFB857781308B0D"="C:\ProgramData\IncrediMail\Data\Pictures\{5E2291A7-EE52-4655-AEBE-45E91FB16A64}\panda_50_50.gif"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\B4496FD73EEB18B6E06A82BE40485DE9]
"1EA505532E7260243BFB857781308B0D"="C:\ProgramData\IncrediMail\Data\Pictures\{D519E5CB-392E-41DA-9317-E908F12C3241}\taurus_50x50.gif"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\BBB1354B58E57A84EBBA666E408A48E0]
"1EA505532E7260243BFB857781308B0D"="C:\Program Files (x86)\IncrediMail\Bin\PMC.dll"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\BC7A5A41C52BE67B092F7F1581FA71FC]
"1EA505532E7260243BFB857781308B0D"="C:\ProgramData\IncrediMail\Data\IMSys\{781B9B29-76A7-423f-A038-5BB34D4F48FA}\932\noMystartDialog\main_bg.jpg"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\BE624B16BD2B60625B400B11DB57FEC8]
"1EA505532E7260243BFB857781308B0D"="C:\ProgramData\IncrediMail\Data\Pictures\{D9399675-900F-489B-AA91-4B69567999E5}\mouse.gif"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\BF9DDB9A5ED09AE4290C4F4F6CE4AA4B]
"1EA505532E7260243BFB857781308B0D"="01:\Software\Incredimail\AfterReInstall"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\C0DB84ACC0AD24741B4E92CBDF3E9279]
"1EA505532E7260243BFB857781308B0D"="01:\Software\IncrediMail\PrimalDataUpdateIndex"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\C249F7787C3C46FC1B039776DDA54A3D]
"1EA505532E7260243BFB857781308B0D"="C:\ProgramData\IncrediMail\Data\Pictures\{54B87B0C-3BC4-4CAE-94E7-4A917E65C9B6}\redneck.gif"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\C3C055A107CC1EBD467E24809F140E8D]
"1EA505532E7260243BFB857781308B0D"="C:\ProgramData\IncrediMail\Data\IMSys\{781B9B29-76A7-423f-A038-5BB34D4F48FA}\919\RDDlg.dat"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\C63D181C7C228EF4C8D97121B63DFA98]
"1EA505532E7260243BFB857781308B0D"="02:\SOFTWARE\IncrediMail\Version"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\C9FBF211B9BC1749F2D694F80146EA0F]
"1EA505532E7260243BFB857781308B0D"="C:\ProgramData\IncrediMail\Data\IMSys\{781B9B29-76A7-423f-A038-5BB34D4F48FA}\918\RDDlg.dat"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\CB98F8325732DF847AFD32F9BB244096]
"1EA505532E7260243BFB857781308B0D"="C:\Program Files (x86)\IncrediMail\Bin\"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\CEAA68CECA8CB38001C51EABA46A6535]
"1EA505532E7260243BFB857781308B0D"="C:\ProgramData\IncrediMail\Data\Pictures\{2E8A33E4-B57B-4F09-9BC1-8C5AB6CB5223}\cat_closeup.gif"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\CFFD0576C12C971AC1790E04D4F182EB]
"1EA505532E7260243BFB857781308B0D"="C:\ProgramData\IncrediMail\Data\Pictures\{23E41B8B-DDDE-4FC5-90E0-D309639FA056}\squirrel.gif"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\D203C800001957A4FB03F08F39A62CA2]
"1EA505532E7260243BFB857781308B0D"="C:\Program Files (x86)\IncrediMail\Bin\ImViewU.dll"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\D8448EDC99C0E114581065272ED2F2C0]
"1EA505532E7260243BFB857781308B0D"="C:\Program Files (x86)\IncrediMail\Bin\ImFeatU.dll"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\DA7565144394A0240B50A679ED6C89AA]
"1EA505532E7260243BFB857781308B0D"="C:\Program Files (x86)\IncrediMail\Bin\IncrediGalleryDesktop.url"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\DDAA1F9FC70508845A47487C1CE137CA]
"1EA505532E7260243BFB857781308B0D"="01:\Software\IncrediMail\"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\DE2E2D739E9D813F3CD693F08C3B1358]
"1EA505532E7260243BFB857781308B0D"="C:\ProgramData\IncrediMail\Data\Pictures\{09D2DBAB-C227-41D1-BAA0-7DF27CF733F2}\aries_50x50.gif"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\DEF67555ED3D65E8CCC63AC15C2641AA]
"1EA505532E7260243BFB857781308B0D"="C:\ProgramData\IncrediMail\Data\Pictures\{649B7494-1829-481E-9063-EC63E8B4DE74}\hood.gif"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\E104813909DB1B64092E5420FD30EF12]
"1EA505532E7260243BFB857781308B0D"="C:\Program Files (x86)\IncrediMail\Bin\ImToolsU.dll"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\E1DB55D238CC16D40A32900E561DA166]
"1EA505532E7260243BFB857781308B0D"="C:\Program Files (x86)\IncrediMail\Bin\ImSetup.exe"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\E24CAEDB65B5EED4FA3C5B33EE939199]
"1EA505532E7260243BFB857781308B0D"="C:\Program Files (x86)\IncrediMail\Bin\d3drm.dll"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\E4C8B62183FE3A5729B76D361EF8E6D3]
"1EA505532E7260243BFB857781308B0D"="C:\ProgramData\IncrediMail\Data\Pictures\{7E2E1AFB-85DC-4716-92BF-981E483A4706}\blue_cat.gif"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\E64BED1E8C8E4466A5359FCF3D8B2484]
"1EA505532E7260243BFB857781308B0D"="C:\ProgramData\IncrediMail\Data\Pictures\{40C815FD-5C64-4E20-8ED1-0F2D1BF4706C}\bad_girl.gif"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\E749CB4779D620E4CAB1F3BB33E27341]
"1EA505532E7260243BFB857781308B0D"="C:\Program Files (x86)\IncrediMail\Bin\ImNotfyU.dll"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\EA53192F7181F444BA6C5306DB5F3CB5]
"1EA505532E7260243BFB857781308B0D"="C:\Program Files (x86)\IncrediMail\Bin\IncMailRU.dll"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\ED8DC8B0DBC18F145BA443C1CBD2AFFC]
"1EA505532E7260243BFB857781308B0D"="C:\Program Files (x86)\IncrediMail\Bin\ImpCnt.exe"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\EDF533C175BE77AA16D71223617C92DB]
"1EA505532E7260243BFB857781308B0D"="C:\ProgramData\IncrediMail\Data\Pictures\{47E48499-939C-497C-9F67-9AFB489E214B}\snake_50_50.gif"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\F00DCE66A3C0E0140A24A202B7FAB8A1]
"1EA505532E7260243BFB857781308B0D"="C:\Program Files (x86)\IncrediMail\Bin\ssce5432.dll"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\F157C2A92C9F981AF51590E961EEFC6F]
"1EA505532E7260243BFB857781308B0D"="C:\ProgramData\IncrediMail\Data\IMSys\{781B9B29-76A7-423f-A038-5BB34D4F48FA}\928\RDDlg.dat"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\F392F4AC5B7F484B9FAE9C0F4EE43BAF]
"1EA505532E7260243BFB857781308B0D"="C:\ProgramData\IncrediMail\Data\Pictures\{0C14A18B-C2AC-4669-86E4-B9E73BE84718}\pretty_lady.gif"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\F4E7F002E5CF8D2CD07D65126706ED83]
"1EA505532E7260243BFB857781308B0D"="C:\ProgramData\IncrediMail\Data\Pictures\{FAAE75FC-3CA5-4800-ADA3-9BCF887DFA53}\biker.gif"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\F6B0655AE6BFCAE34B6CCAAC585005D9]
"1EA505532E7260243BFB857781308B0D"="C:\ProgramData\IncrediMail\Data\Pictures\{1947E5E1-F1D7-4E50-9FC6-0B9D8A279E8D}\piglet_50_50.gif"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\F9E5B7BF00F28944D90201497C150019]
"1EA505532E7260243BFB857781308B0D"="C:\Program Files (x86)\IncrediMail\Bin\dten600.dll"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\FC621C47F81329743BE8DBED892381B0]
"1EA505532E7260243BFB857781308B0D"="C:\ProgramData\IncrediMail\Data\EmoticonCenter\emoticons.xml"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\FF7FE0371D8D47E40B53AED7972B66B5]
"1EA505532E7260243BFB857781308B0D"="C:\Program Files (x86)\IncrediMail\Bin\ImLcRU.dll"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\1EA505532E7260243BFB857781308B0D\InstallProperties]
"InstallSource"="C:\Users\Rick\AppData\Local\Temp\IMInstaller\IncrediMail\DISK1\"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\1EA505532E7260243BFB857781308B0D\InstallProperties]
"URLInfoAbout"="http://www.IncrediMail.com"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\2220A88709652124AAC94CF80D1E9CEA\InstallProperties]
"InstallSource"="C:\Users\Rick\AppData\Local\Temp\IMInstaller\IncrediMail\"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\2220A88709652124AAC94CF80D1E9CEA\InstallProperties]
"URLInfoAbout"="http://www.IncrediMail.com"

[HKEY_LOCAL_MACHINE\SOFTWARE\RegisteredApplications]
"IncrediMail"="SOFTWARE\Clients\Mail\IncrediMail\Capabilities"

[HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\IncrediMail]

[HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\IncrediMail]
"CommonDataPath"="C:\ProgramData\IncrediMail\Data"

[HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\IncrediMail\AddOns\ContentPacker]
"ParentApp"="IncrediMail"

[HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\IncrediMail\AddOns\LetterWizard]
"Open Command"="C:\ProgramData\IncrediMail\Data\LetterCreator\LSAMPLE\Sample_Letter_1.ltw"

[HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\IncrediMail\Default Identity\SSCE]
"UserLexPath"="C:\ProgramData\IncrediMail\Data\Lex"

[HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\IncrediMail\Default Identity\SSCE]
"MainLexPath"="C:\ProgramData\IncrediMail\Data\Lex"

[HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\IncrediMail\Service Providers\Domains\googlemail.com\POP3]
"HelpUrl"="http://www.incredimail.com/help.asp?page=new_gmail_account"

[HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{CA91D994-CBC7-4C07-A5C3-A57665DC6E22}]
"AppPath"="C:\Program Files (x86)\IncrediMail_MediaBar_2"

[HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\SharedDlls]
"C:\Program Files (x86)\IncrediMail\Bin\ImBpp.exe"="1"

[HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\SharedDlls]
"C:\ProgramData\IncrediMail\Data\incredimail_terms.txt"="1"

[HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Uninstall\IncrediMail]

[HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Uninstall\IncrediMail]
"URLInfoAbout"="www.incredimail.com"

[HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Uninstall\IncrediMail]
"UninstallString"="C:\Program Files (x86)\IncrediMail\Bin\ImSetup.exe /uninstallProduct /addon:incredimail"

[HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Uninstall\IncrediMail]
"DisplayIcon"="C:\Program Files (x86)\IncrediMail\Bin\IncMail.exe"

[HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Uninstall\Photo Notifier and Animation Creator]
"Publisher"="IncrediMail Ltd."

[HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{35505AE1-27E2-4206-B3BF-58771803B8D0}]
"InstallLocation"="C:\Program Files (x86)\IncrediMail\"

[HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{35505AE1-27E2-4206-B3BF-58771803B8D0}]
"Publisher"="IncrediMail"

[HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{35505AE1-27E2-4206-B3BF-58771803B8D0}]
"DisplayName"="IncrediMail"

[HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{788A0222-5690-4212-AA9C-C48FD0E1C9AE}]
"Publisher"="IncrediMail"

[HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\App Paths\ImBpp.exe]
""="C:\Program Files (x86)\IncrediMail\Bin\ImBpp.exe"

[HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\App Paths\ImLc.exe]
""="C:\Program Files (x86)\IncrediMail\Bin\ImLc.exe"

[HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\App Paths\ImLcU.exe]
""="C:\Program Files (x86)\IncrediMail\Bin\ImLc.exe"

[HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\App Paths\ImLpp.exe]
"Path"="C:\Program Files (x86)\IncrediMail\Bin"

[HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\App Paths\ImPackr.exe]
""="C:\Program Files (x86)\IncrediMail\Bin\impackr.exe"

[HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\App Paths\impackrU.exe]
""="C:\Program Files (x86)\IncrediMail\Bin\impackr.exe"

[HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\App Paths\ImpCnt.exe]
""="C:\Program Files (x86)\IncrediMail\Bin\ImpCnt.exe"

[HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\App Paths\ImpCntU.exe]
""="C:\Program Files (x86)\IncrediMail\Bin\ImpCnt.exe"

[HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\App Paths\ImpContent.exe]
""="C:\Program Files (x86)\IncrediMail\Bin\ImpCnt.exe"

[HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\App Paths\ImSetup.exe]
""="C:\Program Files (x86)\IncrediMail\Bin\ImSetup.exe"

[HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\App Paths\IncMail.exe]
""="C:\Program Files (x86)\IncrediMail\Bin\IncMail.exe"

[HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\App Paths\IncMailU.exe]
""="C:\Program Files (x86)\IncrediMail\Bin\IncMail.exe"

[HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\App Paths\IncrediMail.exe]

[HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\App Paths\IncrediMail.exe]
"Path"="C:\Program Files (x86)\IncrediMail\Bin"

[HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Classes\CLSID\{00E9F275-1525-4fd3-8CEE-6BAF5B4A4B4A}\InprocServer32]
""="C:\Program Files (x86)\IncrediMail\Bin\ImImprtU.dll"

[HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Classes\CLSID\{00E9F275-1525-4fd3-8CEE-6BAF5B4A4B4A}\VersionIndependentProgID]
""="IncrediImport.IncrediMailImporter2"

[HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Classes\CLSID\{0710C793-2117-11D5-B75D-005004C0C6BA}\InprocServer32]
""="C:\Program Files (x86)\IncrediMail\Bin\ImFeatU.dll"

[HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Classes\CLSID\{07A52AE7-B6F0-11D3-BB7E-0050DA276194}\InprocServer32]
""="C:\Program Files (x86)\IncrediMail\Bin\ImSpoolU.dll"

[HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Classes\CLSID\{087EF34C-BBC4-11D3-BB8D-0050DA276194}\InprocServer32]
""="C:\Program Files (x86)\IncrediMail\Bin\ImParserU.dll"

[HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Classes\CLSID\{09384BB7-09EC-4adb-862E-420A31E278F5}\InprocServer32]
""="C:\Program Files (x86)\IncrediMail\Bin\ImToolsU.dll"

[HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Classes\CLSID\{0B9A0840-1EC3-11D5-B75C-005004C0C6BA}\InprocServer32]
""="C:\Program Files (x86)\IncrediMail\Bin\ImToolsU.dll"

[HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Classes\CLSID\{140BBD3E-C68E-4077-B7EC-D4DC46242EF5}\InprocServer32]
""="C:\Program Files (x86)\IncrediMail\Bin\ImToolsU.dll"

[HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Classes\CLSID\{17A434C2-B48F-11D3-BB78-0050DA276194}\InprocServer32]
""="C:\Program Files (x86)\IncrediMail\Bin\ImFoldrsU.dll"

[HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Classes\CLSID\{1E97DB6C-0BDD-4066-AD2F-01417D21A8D0}\InprocServer32]
""="C:\Program Files (x86)\IncrediMail\Bin\ImParserU.dll"

[HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Classes\CLSID\{28D1EE40-E73D-422D-A2AC-D23F8D3071B2}\InprocServer32]
""="C:\Program Files (x86)\IncrediMail\Bin\ImParserU.dll"

[HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Classes\CLSID\{2E43842C-5133-455A-967A-C424B485D53C}\InprocServer32]
""="C:\Program Files (x86)\IncrediMail\Bin\ImSpoolU.dll"

[HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Classes\CLSID\{328CC455-1F5E-4F1A-A6B7-A888AA9C0289}\InprocServer32]
""="C:\Program Files (x86)\IncrediMail\Bin\ImFeatU.dll"

[HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Classes\CLSID\{35092AB4-B643-11D3-BB7D-0050DA276194}\InprocServer32]
""="C:\Program Files (x86)\IncrediMail\Bin\ImSpoolU.dll"

[HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Classes\CLSID\{3762BAB7-8E00-4B51-AA7E-E57ED7552794}\InprocServer32]
""="C:\Program Files (x86)\IncrediMail\Bin\ImMangrU.dll"

[HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Classes\CLSID\{43AFEAC3-6385-4DFE-9870-C65B5A555412}\InprocServer32]
""="C:\Program Files (x86)\IncrediMail_MediaBar_2\tbIncr.dll"

[HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Classes\CLSID\{44C8EC50-93BD-4633-9A82-CA0D4F1DD3A7}\InprocServer32]
""="C:\Program Files (x86)\IncrediMail\Bin\ImImprtU.dll"

[HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Classes\CLSID\{44C8EC50-93BD-4633-9A82-CA0D4F1DD3A7}\VersionIndependentProgID]
""="IncrediImport.IncrediMailImporter"

[HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Classes\CLSID\{4EAA7268-FC1E-47C6-87EF-8915475CBC88}\InprocServer32]
""="C:\Program Files (x86)\IncrediMail\Bin\ImFeatU.dll"

[HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Classes\CLSID\{55B613D4-E613-11D3-857A-005004BE235E}\InprocServer32]
""="C:\Program Files (x86)\IncrediMail\Bin\ImServU.dll"
Risky Rick
Regular Member
 
Posts: 16
Joined: December 17th, 2015, 5:50 pm

Re: Infected?

Unread postby Risky Rick » December 28th, 2015, 9:07 am

Continuatuion of SEARCH.txt and at the end the esetscan.

SEARCH.txt Continued:


[HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Classes\CLSID\{57DE7416-A3EB-47C8-B44D-72F79539A360}\InprocServer32]
""="C:\Program Files (x86)\IncrediMail\Bin\ImViewU.dll"

[HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Classes\CLSID\{5B1E73D3-F6DB-406E-AE7F-20FAB0AD4732}\InprocServer32]
""="C:\Program Files (x86)\IncrediMail\Bin\ImServU.dll"

[HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Classes\CLSID\{687F8E94-45D6-4685-A63D-1C7A140EF847}\InprocServer32]
""="C:\Program Files (x86)\IncrediMail\Bin\ImSpoolU.dll"

[HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Classes\CLSID\{697DF023-B24E-11D3-B57C-00105AA461D0}\InprocServer32]
""="C:\Program Files (x86)\IncrediMail\Bin\dten600.dll"

[HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Classes\CLSID\{697DF027-B24E-11D3-B57C-00105AA461D0}\InprocServer32]
""="C:\Program Files (x86)\IncrediMail\Bin\dten600.dll"

[HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Classes\CLSID\{697DF02B-B24E-11D3-B57C-00105AA461D0}\InprocServer32]
""="C:\Program Files (x86)\IncrediMail\Bin\dten600.dll"

[HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Classes\CLSID\{6D587C7F-27A0-4416-A90D-FB337F9B406C}\InprocServer32]
""="C:\Program Files (x86)\IncrediMail\Bin\ImComUtlU.dll"

[HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Classes\CLSID\{7198EEC1-4364-4cd2-ABD0-A7914E032332}\InprocServer32]
""="C:\Program Files (x86)\IncrediMail\Bin\ImParserU.dll"

[HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Classes\CLSID\{798CBE35-B27D-11D3-B57C-00105AA461D0}\InprocServer32]
""="C:\Program Files (x86)\IncrediMail\Bin\dten600.dll"

[HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Classes\CLSID\{7E58CC0F-BC50-11D3-855B-0050DA2761C4}\InprocServer32]
""="C:\Program Files (x86)\IncrediMail\Bin\ImViewU.dll"

[HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Classes\CLSID\{805FB5B9-6344-11D6-B7AF-005004C0C6BA}\InprocServer32]
""="C:\Program Files (x86)\IncrediMail\Bin\ImSuppU.dll"

[HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Classes\CLSID\{84566316-EC70-11D5-881D-0050DA2761C4}\InprocServer32]
""="C:\Program Files (x86)\IncrediMail\Bin\ImFeatU.dll"

[HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Classes\CLSID\{8BACC255-A3CF-4e27-BAF1-D531B1AE02FD}\InprocServer32]
""="C:\Program Files (x86)\IncrediMail\Bin\ImToolsU.dll"

[HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Classes\CLSID\{9401BFDA-2F5C-4978-8075-7D8AFEC3AEE5}\InprocServer32]
""="C:\Program Files (x86)\IncrediMail\Bin\ImFeatU.dll"

[HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Classes\CLSID\{995F48E8-131F-4630-9FBE-98D9DBDABB05}\InprocServer32]
""="C:\Program Files (x86)\IncrediMail\Bin\ImSpoolU.dll"

[HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Classes\CLSID\{A0C301D9-59A5-45EB-90E8-D60D8149F5A5}\InprocServer32]
""="C:\Program Files (x86)\IncrediMail\Bin\ImParserU.dll"

[HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Classes\CLSID\{A8D94870-BEA6-11D3-BB92-0050DA276194}\InprocServer32]
""="C:\Program Files (x86)\IncrediMail\Bin\ImSuppU.dll"

[HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Classes\CLSID\{A967E5D6-B0E1-11D3-B57C-00105AA461D0}\InprocServer32]
""="C:\Program Files (x86)\IncrediMail\Bin\dten600.dll"

[HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Classes\CLSID\{B385A628-C100-11D3-BB95-0050DA276194}\InprocServer32]
""="C:\Program Files (x86)\IncrediMail\Bin\ImNotfyU.dll"

[HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Classes\CLSID\{BF1F5DE8-E9ED-421e-93EE-E0783D18AAF6}\InprocServer32]
""="C:\Program Files (x86)\IncrediMail\Bin\ImImprtU.dll"

[HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Classes\CLSID\{C697956A-8C70-4EBD-9CC1-92218BC296B2}\InprocServer32]
""="C:\Program Files (x86)\IncrediMail\Bin\ImFeatU.dll"

[HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Classes\CLSID\{C7681ACB-27AD-4025-8F53-643549159658}\InprocServer32]
""="C:\Program Files (x86)\IncrediMail\Bin\ImFeatU.dll"

[HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Classes\CLSID\{CB382C7A-8852-458A-8900-C456C96FDB8C}\InprocServer32]
""="C:\Program Files (x86)\IncrediMail\Bin\ImViewU.dll"

[HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Classes\CLSID\{CBF9925D-3C19-4F33-9DE4-446978645EBB}\InprocServer32]
""="C:\Program Files (x86)\IncrediMail\Bin\ImFeatU.dll"

[HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Classes\CLSID\{D5C040B6-64BE-4855-BB40-7D4DD98B093A}\InprocServer32]
""="C:\Program Files (x86)\IncrediMail\Bin\ImToolsU.dll"

[HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Classes\CLSID\{DA12A268-0ACB-11D4-859D-0050DA2761C4}\InprocServer32]
""="C:\Program Files (x86)\IncrediMail\Bin\ImFeatU.dll"

[HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Classes\CLSID\{E1B6DE2A-F997-11D3-BBDB-0050DA276194}\InprocServer32]
""="C:\Program Files (x86)\IncrediMail\Bin\ImImprtU.dll"

[HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Classes\CLSID\{E9BC70A8-D70C-11D3-BBAE-0050DA276194}\LocalServer32]
""=""C:\Program Files (x86)\IncrediMail\Bin\IncMail.exe""

[HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Classes\CLSID\{E9BC70A8-D70C-11D3-BBAE-0050DA276194}\VersionIndependentProgID]
""="IncrediMail.Kernel"

[HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Classes\CLSID\{EC8717B6-F660-11D3-ADE2-0050DA744DF1}\InprocServer32]
""="C:\Program Files (x86)\IncrediMail\Bin\ImImprtU.dll"

[HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Classes\CLSID\{EC8717C9-F660-11D3-ADE2-0050DA744DF1}\InprocServer32]
""="C:\Program Files (x86)\IncrediMail\Bin\ImImprtU.dll"

[HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Classes\CLSID\{F1B4B6F1-55D1-11d6-B7AD-005004C0C6BA}\InprocServer32]
""="C:\Program Files (x86)\IncrediMail\Bin\ImImprtU.dll"

[HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Classes\CLSID\{F648D80F-2409-4EDA-847D-8E820B03451F}\InprocServer32]
""="C:\Program Files (x86)\IncrediMail\Bin\ImServU.dll"

[HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Classes\CLSID\{F9F135B6-F421-4259-AB7E-33E37641AD3C}\InprocServer32]
""="C:\Program Files (x86)\IncrediMail\Bin\ImNotfyU.dll"

[HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Classes\CLSID\{FEBD6230-F4F6-4E79-89CD-4BEBDC4A96AE}\InprocServer32]
""="C:\Program Files (x86)\IncrediMail\Bin\ImFeatU.dll"

[HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Classes\Interface\{133483C3-5BAB-45DD-94EE-1857CB47C6E5}]
""="IIncrediMailImporter"

[HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Classes\AppID\{FCA7EB04-D708-11D3-BBAE-0050DA276194}]
""="IncrediMail"

[HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Classes\TypeLib\{00E677A7-A7A5-4819-9580-1681BE30E28E}\1.0\0\win32]
""="C:\Program Files (x86)\IncrediMail\Bin\IncMail.exe"

[HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Classes\TypeLib\{07A52AE8-B6F0-11D3-BB7E-0050DA276194}\1.0\0\win32]
""="C:\Program Files (x86)\IncrediMail\Bin\ImParserU.dll"

[HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Classes\TypeLib\{0B9A0841-1EC3-11D5-B75C-005004C0C6BA}\1.0\0\win32]
""="C:\Program Files (x86)\IncrediMail\Bin\ImFeatU.dll"

[HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Classes\TypeLib\{60BE6CEF-036C-4440-9847-7A32006DCF4B}\1.0\0\win32]
""="C:\Program Files (x86)\IncrediMail\Bin\ImNotfy.exe"

[HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Classes\TypeLib\{6D293D13-C375-11D3-BB98-0050DA276194}\1.0\0\win32]
""="C:\Program Files (x86)\IncrediMail\Bin\ImSuppU.dll"

[HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Classes\TypeLib\{7E58CC01-BC50-11D3-855B-0050DA2761C4}\1.0\0\win32]
""="C:\Program Files (x86)\IncrediMail\Bin\ImViewU.dll"

[HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Classes\TypeLib\{815F81B9-E268-489D-883A-B5BC5BED9F03}\1.0\HELPDIR]
""="C:\Program Files (x86)\IncrediMail\Bin\"

[HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Classes\TypeLib\{A967E5C4-B0E1-11D3-B57C-00105AA461D0}\1.0\0\win32]
""="C:\Program Files (x86)\IncrediMail\Bin\dten600.dll"

[HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Classes\TypeLib\{C762F735-0863-4E91-B46F-3F6C303778FE}\1.0\0\win32]
""="C:\Program Files (x86)\IncrediMail\Bin\ImJunkU.dll"

[HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Classes\TypeLib\{CB073674-BD1F-11D3-BB90-0050DA276194}\1.0\0\win32]
""="C:\Program Files (x86)\IncrediMail\Bin\ImMangrU.dll"

[HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Classes\TypeLib\{F8984103-38B6-11D5-8725-0050DA2761C4}\1.0\0\win32]
""="C:\Program Files (x86)\IncrediMail\Bin\ImShExtU.dll"

[HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Clients\Mail\IncrediMail]
""="IncrediMail"

[HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Clients\Mail\IncrediMail\Capabilities]
"ApplicationDescription"="IncrediMail"

[HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Clients\Mail\IncrediMail\Protocols\mailto\DefaultIcon]
""="C:\Program Files (x86)\IncrediMail\Bin\IncMail.exe,0"

[HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Clients\Mail\IncrediMail\Shell\Open\Command]
""="C:\Program Files (x86)\IncrediMail\Bin\IncMail.exe"

[HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\RegisteredApplications]
"IncrediMail"="SOFTWARE\Clients\Mail\IncrediMail\Capabilities"

[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
"{F87CE4B3-5E73-445A-9FAD-33736C38B352}"="v2.10|Action=Allow|Active=FALSE|Dir=In|Protocol=17|Profile=Private|App=C:\Program Files (x86)\IncrediMail\Bin\IncMail.exe|Name=IncrediMail|"

[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
"{7CB0035A-ADE9-44F3-A764-82CFD8FA90EE}"="v2.10|Action=Allow|Active=FALSE|Dir=In|Protocol=17|Profile=Private|App=C:\Program Files (x86)\IncrediMail\Bin\ImpCnt.exe|Name=IncrediMail|"

[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
"{94C225B7-5462-4D70-BF08-0D630E3B40BF}"="v2.10|Action=Allow|Active=FALSE|Dir=In|Protocol=17|Profile=Private|App=C:\Program Files (x86)\IncrediMail\Bin\ImApp.exe|Name=IncrediMail|"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
"{F87CE4B3-5E73-445A-9FAD-33736C38B352}"="v2.10|Action=Allow|Active=FALSE|Dir=In|Protocol=17|Profile=Private|App=C:\Program Files (x86)\IncrediMail\Bin\IncMail.exe|Name=IncrediMail|"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
"{7CB0035A-ADE9-44F3-A764-82CFD8FA90EE}"="v2.10|Action=Allow|Active=FALSE|Dir=In|Protocol=17|Profile=Private|App=C:\Program Files (x86)\IncrediMail\Bin\ImpCnt.exe|Name=IncrediMail|"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
"{94C225B7-5462-4D70-BF08-0D630E3B40BF}"="v2.10|Action=Allow|Active=FALSE|Dir=In|Protocol=17|Profile=Private|App=C:\Program Files (x86)\IncrediMail\Bin\ImApp.exe|Name=IncrediMail|"

[HKEY_USERS\.DEFAULT\Software\IncrediMail]

[HKEY_USERS\S-1-5-21-2324462236-1183297055-1014908895-1001\SOFTWARE\Clients\Mail]
""="IncrediMail"

[HKEY_USERS\S-1-5-21-2324462236-1183297055-1014908895-1001\SOFTWARE\IncrediMail\Identities\{67B30E2F-D407-42E0-94B2-321DB2374BA4}\IMSys\{A71D1748-FEC9-43E2-8294-228D96CF1B59}]
"IPA"="-script_url www5l.incredimail.com/im/setup/201004211555/test/installer/setupscript_bc.cab -ROOT www5l.incredimail.com/im/setup/201004211555/test/installer/ -skip_dialog info -skip_dialog language -language english -product IncrediMail -msc 74123 -ffmsc 654654 -cluster 575 -report -au -ggmsc 333444"

[HKEY_USERS\S-1-5-21-2324462236-1183297055-1014908895-1001\SOFTWARE\IncrediMail\Identities\{67B30E2F-D407-42E0-94B2-321DB2374BA4}\SSCE]
"UserLexFiles"="C:\ProgramData\IncrediMail\Data\Lex\userdic.tlx,{DATA}\Lex\correct.tlx,private.tlx"

[HKEY_USERS\S-1-5-21-2324462236-1183297055-1014908895-1001\SOFTWARE\IncrediMail\Identities\{E8946668-D62D-4188-8C74-24458CA065EC}\IMSys\{A71D1748-FEC9-43E2-8294-228D96CF1B59}]
"IPA"="-script_url http://www5l.incredimail.com/im/setup/2 ... ipt_bc.cab -ROOT http://www5l.incredimail.com/im/setup/2 ... installer/ -skip_dialog info -skip_dialog language -product IncrediMail -ffmsc 12345"

[HKEY_USERS\S-1-5-21-2324462236-1183297055-1014908895-1001\SOFTWARE\IncrediMail\Identities\{E8946668-D62D-4188-8C74-24458CA065EC}\IMSys\{A7C6A0A8-CCC1-41C2-B74B-88A495077CFD}\7]
"ACDATA"="http://www.incredimail.com/app/?tag=page_incredigames_link_9"

[HKEY_USERS\S-1-5-21-2324462236-1183297055-1014908895-1001\SOFTWARE\IncrediMail\Identities\{E8946668-D62D-4188-8C74-24458CA065EC}\SSCE]
"MainLexPath"="C:\ProgramData\IncrediMail\Data\Lex"

[HKEY_USERS\S-1-5-21-2324462236-1183297055-1014908895-1001\SOFTWARE\Microsoft\Internet Explorer\LowRegistry\Audio\PolicyConfig\PropertyStore\24c3dc18_0]
""="{0.0.0.00000000}.{c1e8de0b-3961-48a6-9be3-55f2d0f880b4}|\Device\HarddiskVolume3\Program Files (x86)\IncrediMail\Bin\IncMail.exe%b{00000000-0000-0000-0000-000000000000}"

[HKEY_USERS\S-1-5-21-2324462236-1183297055-1014908895-1001\SOFTWARE\Microsoft\Internet Explorer\LowRegistry\Audio\PolicyConfig\PropertyStore\75898fc1_0]
""="{0.0.0.00000000}.{c1e8de0b-3961-48a6-9be3-55f2d0f880b4}|\Device\HarddiskVolume3\Program Files (x86)\IncrediMail\Bin\ImNotfy.exe%b{00000000-0000-0000-0000-000000000000}"

[HKEY_USERS\S-1-5-21-2324462236-1183297055-1014908895-1001\SOFTWARE\Microsoft\Internet Explorer\LowRegistry\Audio\PolicyConfig\PropertyStore\b80e2534_0]
""="{0.0.0.00000000}.{c1e8de0b-3961-48a6-9be3-55f2d0f880b4}|\Device\HarddiskVolume3\Users\Rick\AppData\Local\Temp\nss6356.tmp\MainOffer\incredimail_install_EN1033.exe%b{00000000-0000-0000-0000-000000000000}"

[HKEY_USERS\S-1-5-21-2324462236-1183297055-1014908895-1001\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\feature_browser_emulation]
"IncrediMail_TSV4F34TN.exe"="11000"

[HKEY_USERS\S-1-5-21-2324462236-1183297055-1014908895-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\ApplicationAssociationToasts]
"IncrediMail.Url.Mailto_mailto"="0"

[HKEY_USERS\S-1-5-21-2324462236-1183297055-1014908895-1001\SOFTWARE\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Compatibility Assistant\Persisted]
"C:\Users\Rick\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\3NPXELIL\incredimail_install
[HKEY_USERS\S-1-5-21-2324462236-1183297055-1014908895-1001\SOFTWARE\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Compatibility Assistant\Persisted]
"C:\Users\Rick\AppData\Local\Temp\IncrediMail_MediaBar_2.exe"="1"

[HKEY_USERS\S-1-5-21-2324462236-1183297055-1014908895-1001\SOFTWARE\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Compatibility Assistant\Persisted]
"C:\Users\Rick\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\WBWNZTER\incredimail_install.exe"="1"

[HKEY_USERS\S-1-5-21-2324462236-1183297055-1014908895-1001\SOFTWARE\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Compatibility Assistant\Persisted]
"C:\FRST\Quarantine\C\Program Files (x86)\IncrediMail\Bin\ImSetup.exe"="1"

[HKEY_USERS\S-1-5-21-2324462236-1183297055-1014908895-1001\SOFTWARE\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Compatibility Assistant\Persisted]
"C:\Users\Rick\Downloads\IncrediMail_TSV3F3NBU.exe"="1"

[HKEY_USERS\S-1-5-21-2324462236-1183297055-1014908895-1001\SOFTWARE\Classes\Local Settings\Software\Microsoft\Windows\Shell\MuiCache]
"C:\Program Files (x86)\IncrediMail\Bin\IncMail.exe.FriendlyAppName"="IncrediMail Application"

[HKEY_USERS\S-1-5-21-2324462236-1183297055-1014908895-1001\SOFTWARE\Classes\Local Settings\Software\Microsoft\Windows\Shell\MuiCache]
"C:\Program Files (x86)\IncrediMail\Bin\IncMail.exe.ApplicationCompany"="IncrediMail, Ltd."

[HKEY_USERS\S-1-5-21-2324462236-1183297055-1014908895-1001_Classes\Local Settings\Software\Microsoft\Windows\Shell\MuiCache]
"C:\Program Files (x86)\IncrediMail\Bin\IncMail.exe.FriendlyAppName"="IncrediMail Application"

[HKEY_USERS\S-1-5-21-2324462236-1183297055-1014908895-1001_Classes\Local Settings\Software\Microsoft\Windows\Shell\MuiCache]
"C:\Program Files (x86)\IncrediMail\Bin\IncMail.exe.ApplicationCompany"="IncrediMail, Ltd."

[HKEY_USERS\S-1-5-18\Software\IncrediMail]

===================== Search result for "protector" ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\ProtectorExe.EXE]

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{96FBC13C-8214-4100-88E0-FF74D7A1CB4D}]
""="protector_dll"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{706A79C0-1AC4-4E25-B311-93B643C1E499}]
""="WinMsoIrmProtector Class"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{84798B8E-69F8-4846-9516-373C2996E2F7}]
""="ProtectorLib Class"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{84798B8E-69F8-4846-9516-373C2996E2F7}\VersionIndependentProgID]
""="protector_dll.ProtectorLib"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{B6FFEC3A-07F7-42D0-8829-B722F46DB533}\InprocServer32]
""="%systemroot%\system32\WinOpcIrmProtector.dll"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{FBA44040-BD27-4A09-ACC8-C08B7C723DCD}\ProgID]
""="ProtectorExe.ProtectorHost.1"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{17484B9D-89FA-484F-912E-017D06C41FE0}]
""="IProtectorLib7"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{2212951C-1623-4095-906B-AC50B8F91016}]
""="IProtector2"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{235317AD-6EF4-4209-9354-F88869E1A3BB}]
""="IProtectorLib5"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{315A0BBF-D55B-4FCE-833E-8BAA5B6344F6}]
""="IProtector11"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{5D358B5C-3415-42BB-A606-E1089B674F41}]
""="IProtector7"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{6EACF525-5F81-4381-9E46-DC316C39E0D2}]
""="IProtector6"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{91F39C2A-95E7-497A-A539-0AC715DC66D2}]
""="IProtector3"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{9D932020-700E-4F0D-8446-2872ABD8B4FA}]
""="IProtectorLib3"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{A45CDEEB-65F5-49AE-AA3E-9376F4806075}]
""="IProtector8"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{BACAB2F3-7213-4865-96E9-B6B06BF49192}]
""="IProtectorLib8"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{DD65ABB2-2628-425B-86F5-825E4A3D3AD9}]
""="IProtectorLib4"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\ProtectorExe.ProtectorHost]

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\ProtectorExe.ProtectorHost\CurVer]
""="ProtectorExe.ProtectorHost.1"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\ProtectorExe.ProtectorHost.1]
""="ProtectorHost Class"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\protector_dll.Protector]
""="Protector Class"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\protector_dll.Protector.1]

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\protector_dll.ProtectorLib]

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\protector_dll.ProtectorLib\CurVer]
""="protector_dll.ProtectorLib.1"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\protector_dll.ProtectorLib.1]
""="ProtectorLib Class"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{C7CB459A-7261-4AE6-A87A-17041EE98A40}\14.0]
""="protector_dllLib"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{C7CB459A-7261-4AE6-A87A-17041EE98A40}\16.0]
""="protector_dllLib"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{C7CB459A-7261-4AE6-A87A-17041EE98A40}\18.0]
""="protector_dllLib"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WOW6432Node\CLSID\{6134CEA9-DD6E-495C-A0D1-4F232027D7D7}]
""="Protector Class"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WOW6432Node\CLSID\{6134CEA9-DD6E-495C-A0D1-4F232027D7D7}\VersionIndependentProgID]
""="protector_dll.Protector"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WOW6432Node\CLSID\{706A79C0-1AC4-4E25-B311-93B643C1E499}]
""="WinMsoIrmProtector Class"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WOW6432Node\CLSID\{84798B8E-69F8-4846-9516-373C2996E2F7}]
""="ProtectorLib Class"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WOW6432Node\CLSID\{84798B8E-69F8-4846-9516-373C2996E2F7}\VersionIndependentProgID]
""="protector_dll.ProtectorLib"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WOW6432Node\CLSID\{B6FFEC3A-07F7-42D0-8829-B722F46DB533}]
""="WinOpcIrmProtector Class"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WOW6432Node\CLSID\{FBA44040-BD27-4A09-ACC8-C08B7C723DCD}]
""="ProtectorHost Class"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WOW6432Node\CLSID\{FBA44040-BD27-4A09-ACC8-C08B7C723DCD}\VersionIndependentProgID]
""="ProtectorExe.ProtectorHost"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WOW6432Node\Interface\{17484B9D-89FA-484F-912E-017D06C41FE0}]
""="IProtectorLib7"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WOW6432Node\Interface\{2212951C-1623-4095-906B-AC50B8F91016}]
""="IProtector2"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WOW6432Node\Interface\{235317AD-6EF4-4209-9354-F88869E1A3BB}]
""="IProtectorLib5"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WOW6432Node\Interface\{315A0BBF-D55B-4FCE-833E-8BAA5B6344F6}]
""="IProtector11"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WOW6432Node\Interface\{5D358B5C-3415-42BB-A606-E1089B674F41}]
""="IProtector7"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WOW6432Node\Interface\{6EACF525-5F81-4381-9E46-DC316C39E0D2}]
""="IProtector6"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WOW6432Node\Interface\{91F39C2A-95E7-497A-A539-0AC715DC66D2}]
""="IProtector3"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WOW6432Node\Interface\{9D932020-700E-4F0D-8446-2872ABD8B4FA}]
""="IProtectorLib3"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WOW6432Node\Interface\{A45CDEEB-65F5-49AE-AA3E-9376F4806075}]
""="IProtector8"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WOW6432Node\Interface\{BACAB2F3-7213-4865-96E9-B6B06BF49192}]
""="IProtectorLib8"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WOW6432Node\Interface\{DD65ABB2-2628-425B-86F5-825E4A3D3AD9}]
""="IProtectorLib4"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WOW6432Node\AppID\ProtectorExe.EXE]

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WOW6432Node\AppID\{96FBC13C-8214-4100-88E0-FF74D7A1CB4D}]
""="protector_dll"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WOW6432Node\TypeLib\{C7CB459A-7261-4AE6-A87A-17041EE98A40}\14.0]
""="protector_dllLib"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WOW6432Node\TypeLib\{C7CB459A-7261-4AE6-A87A-17041EE98A40}\16.0]
""="protector_dllLib"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WOW6432Node\TypeLib\{C7CB459A-7261-4AE6-A87A-17041EE98A40}\18.0]
""="protector_dllLib"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\MSDRM\Protectors]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SideBySide\Winners\amd64_microsoft-windows-r..t-office-protectors_31bf3856ad364e35_none_51f9fa7dd061de2a]

[HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\MSDRM\Protectors]

[HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Classes\CLSID\{6134CEA9-DD6E-495C-A0D1-4F232027D7D7}]
""="Protector Class"

[HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Classes\CLSID\{6134CEA9-DD6E-495C-A0D1-4F232027D7D7}\VersionIndependentProgID]
""="protector_dll.Protector"

[HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Classes\CLSID\{706A79C0-1AC4-4E25-B311-93B643C1E499}]
""="WinMsoIrmProtector Class"

[HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Classes\CLSID\{84798B8E-69F8-4846-9516-373C2996E2F7}]
""="ProtectorLib Class"

[HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Classes\CLSID\{84798B8E-69F8-4846-9516-373C2996E2F7}\VersionIndependentProgID]
""="protector_dll.ProtectorLib"

[HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Classes\CLSID\{B6FFEC3A-07F7-42D0-8829-B722F46DB533}]
""="WinOpcIrmProtector Class"

[HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Classes\CLSID\{FBA44040-BD27-4A09-ACC8-C08B7C723DCD}]
""="ProtectorHost Class"

[HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Classes\CLSID\{FBA44040-BD27-4A09-ACC8-C08B7C723DCD}\VersionIndependentProgID]
""="ProtectorExe.ProtectorHost"

[HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Classes\Interface\{17484B9D-89FA-484F-912E-017D06C41FE0}]
""="IProtectorLib7"

[HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Classes\Interface\{2212951C-1623-4095-906B-AC50B8F91016}]
""="IProtector2"

[HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Classes\Interface\{235317AD-6EF4-4209-9354-F88869E1A3BB}]
""="IProtectorLib5"

[HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Classes\Interface\{315A0BBF-D55B-4FCE-833E-8BAA5B6344F6}]
""="IProtector11"

[HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Classes\Interface\{5D358B5C-3415-42BB-A606-E1089B674F41}]
""="IProtector7"

[HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Classes\Interface\{6EACF525-5F81-4381-9E46-DC316C39E0D2}]
""="IProtector6"

[HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Classes\Interface\{91F39C2A-95E7-497A-A539-0AC715DC66D2}]
""="IProtector3"

[HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Classes\Interface\{9D932020-700E-4F0D-8446-2872ABD8B4FA}]
""="IProtectorLib3"

[HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Classes\Interface\{A45CDEEB-65F5-49AE-AA3E-9376F4806075}]
""="IProtector8"

[HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Classes\Interface\{BACAB2F3-7213-4865-96E9-B6B06BF49192}]
""="IProtectorLib8"

[HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Classes\Interface\{DD65ABB2-2628-425B-86F5-825E4A3D3AD9}]
""="IProtectorLib4"

[HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Classes\AppID\ProtectorExe.EXE]

[HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Classes\AppID\{96FBC13C-8214-4100-88E0-FF74D7A1CB4D}]
""="protector_dll"

[HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Classes\TypeLib\{C7CB459A-7261-4AE6-A87A-17041EE98A40}\14.0]
""="protector_dllLib"

[HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Classes\TypeLib\{C7CB459A-7261-4AE6-A87A-17041EE98A40}\16.0]
""="protector_dllLib"

[HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Classes\TypeLib\{C7CB459A-7261-4AE6-A87A-17041EE98A40}\18.0]
""="protector_dllLib"

[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Cryptography\Providers\Windows Client Key Protection Provider]
"SessionLockProtectorProxy"="feclient.dll"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Cryptography\Providers\Windows Client Key Protection Provider]
"SessionLockProtectorProxy"="feclient.dll"

[HKEY_USERS\S-1-5-21-2324462236-1183297055-1014908895-1001\SOFTWARE\AppDataLow\Software\Freecorder\toolbar\Settings\FeatureProtector]

====== End of Search ======

ESETSCAN

C:\Users\Rick\AppData\Roaming\Real\Update\UpgradeHelper\RealPlayer\14.01\agent\stub_data\askrt_en.cab a variant of Win32/Bundled.Toolbar.Ask.G potentially unsafe application
Risky Rick
Regular Member
 
Posts: 16
Joined: December 17th, 2015, 5:50 pm

Re: Infected?

Unread postby nunped » December 28th, 2015, 1:46 pm

Hi Risky Rick,


Step 1 - Registry Backup (TCRB)
Please download tweaking.com_registry_backup_setup.exe
Choose a download site for the installer... download and save it to your desktop.
Double click on the "...setup.exe" program and install the program. Let the install use the default installation. How to tutorial here.

Once the program is installed...
  • Double click the Tweaking.com Registry Backup icon ... on your Desktop to open the program.
  • It should open with the Backup Registry tab selected and all file options checked. Check any that are not already checked.
  • Click on Backup Now to create a backup of your Registry.
    You'll see "Waiting for Volume Shadow Copy snapshot..." this may take a few moments, just be patient.
  • When completed you should see a message saying something like ... Successful ??/?? Registry Files Backed Up ... ?? is total number of files, both numbers should match.
  • Close and exit the program.

Step 2 - Show Hidden Files and Folders
  • Click Start and then click File Explorer.
  • Click on the View tab and then click Options.
  • In the Folder Options window click on the View tab.
  • Check Show hidden files and folders and uncheck Hide extensions for known file types.
  • Click OK.

Step 3 - Online Multi Antivirus file scan
Please go to Virus Total and upload -only one file per scan- the following file(s) for scanning:
C:\Users\Rick\AppData\Roaming\Real\Update\UpgradeHelper\RealPlayer\14.01\agent\stub_data\askrt_en.cab

  • Press the Browse button and navigate to -one- of the files in the list.
  • Double click the located file name. The file name should now appear in the online scanner's text entry box.
  • Click on Send File button.
  • The file will be queued, uploaded and scanned by various antivirus scanners. This may take a few minutes.
      If you receive the message: File has already been analysed:
      Please press the Reanalyse file now button, so your file will be scanned.
  • When all scans have completed the results page is displayed
  • Please highlight and copy the page web address link from your browser window.
    Example of web address :
    Image

Step 4 - Fix with FRST
  • Click Start
  • Type notepad.exe in the search programs and files box and click Enter.
  • A blank Notepad page should open.
    • Copy and Paste the following script into Notepad, Do not include the words Code: select all
    • (Click the select all button next to code to select the entire script).
    Code: Select all
    [-HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Freecorder\toolbar]
    [-HKEY_USERS\S-1-5-21-2324462236-1183297055-1014908895-1001\SOFTWARE\AppDataLow\Software\Freecorder\toolbar]
    [-HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{CA91D994-CBC7-4C07-A5C3-A57665DC6E22}]
    [-HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Classes\CLSID\{43AFEAC3-6385-4DFE-9870-C65B5A555412}\InprocServer32]
    [-HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{CA91D994-CBC7-4C07-A5C3-A57665DC6E22}]
    Reg: Reg delete "HKEY_USERS\S-1-5-21-2324462236-1183297055-1014908895-1001\SOFTWARE\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Compatibility Assistant\Persisted" /v "C:\Users\Rick\AppData\Local\Temp\IncrediMail_MediaBar_2.exe" /f
    [-HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{96FBC13C-8214-4100-88E0-FF74D7A1CB4D}]
    [-HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\ProtectorExe.EXE]
    [-HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{84798B8E-69F8-4846-9516-373C2996E2F7}]
    [-HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{FBA44040-BD27-4A09-ACC8-C08B7C723DCD}\ProgID]
    [-HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{17484B9D-89FA-484F-912E-017D06C41FE0}]
    [-HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{2212951C-1623-4095-906B-AC50B8F91016}]
    [-HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{235317AD-6EF4-4209-9354-F88869E1A3BB}]
    [-HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{315A0BBF-D55B-4FCE-833E-8BAA5B6344F6}]
    [-HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{5D358B5C-3415-42BB-A606-E1089B674F41}]
    [-HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{6EACF525-5F81-4381-9E46-DC316C39E0D2}]
    [-HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{91F39C2A-95E7-497A-A539-0AC715DC66D2}]
    [-HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{9D932020-700E-4F0D-8446-2872ABD8B4FA}]
    [-HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{A45CDEEB-65F5-49AE-AA3E-9376F4806075}]
    [-HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{BACAB2F3-7213-4865-96E9-B6B06BF49192}]
    [-HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{DD65ABB2-2628-425B-86F5-825E4A3D3AD9}]
    [-HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WOW6432Node\Interface\{17484B9D-89FA-484F-912E-017D06C41FE0}]
    [-HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WOW6432Node\Interface\{2212951C-1623-4095-906B-AC50B8F91016}]
    [-HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WOW6432Node\Interface\{235317AD-6EF4-4209-9354-F88869E1A3BB}]
    [-HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WOW6432Node\Interface\{315A0BBF-D55B-4FCE-833E-8BAA5B6344F6}]
    [-HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WOW6432Node\Interface\{5D358B5C-3415-42BB-A606-E1089B674F41}]
    [-HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WOW6432Node\Interface\{6EACF525-5F81-4381-9E46-DC316C39E0D2}]
    [-HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WOW6432Node\Interface\{91F39C2A-95E7-497A-A539-0AC715DC66D2}]
    [-HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WOW6432Node\Interface\{9D932020-700E-4F0D-8446-2872ABD8B4FA}]
    [-HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WOW6432Node\Interface\{A45CDEEB-65F5-49AE-AA3E-9376F4806075}]
    [-HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WOW6432Node\Interface\{BACAB2F3-7213-4865-96E9-B6B06BF49192}]
    [-HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WOW6432Node\Interface\{DD65ABB2-2628-425B-86F5-825E4A3D3AD9}]
    [-HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WOW6432Node\AppID\ProtectorExe.EXE]
    [-HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WOW6432Node\AppID\{96FBC13C-8214-4100-88E0-FF74D7A1CB4D}]
    [-HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WOW6432Node\TypeLib\{C7CB459A-7261-4AE6-A87A-17041EE98A40}]
    [-HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Classes\CLSID\{6134CEA9-DD6E-495C-A0D1-4F232027D7D7}]
    [-HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Classes\CLSID\{84798B8E-69F8-4846-9516-373C2996E2F7}]
    [-HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Classes\CLSID\{B6FFEC3A-07F7-42D0-8829-B722F46DB533}]
    [-HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Classes\CLSID\{FBA44040-BD27-4A09-ACC8-C08B7C723DCD}]
    [-HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Classes\Interface\{17484B9D-89FA-484F-912E-017D06C41FE0}]
    [-HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Classes\Interface\{2212951C-1623-4095-906B-AC50B8F91016}]
    [-HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Classes\Interface\{235317AD-6EF4-4209-9354-F88869E1A3BB}]
    [-HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Classes\Interface\{315A0BBF-D55B-4FCE-833E-8BAA5B6344F6}]
    [-HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Classes\Interface\{5D358B5C-3415-42BB-A606-E1089B674F41}]
    [-HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Classes\Interface\{6EACF525-5F81-4381-9E46-DC316C39E0D2}]
    [-HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Classes\Interface\{91F39C2A-95E7-497A-A539-0AC715DC66D2}]
    [-HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Classes\Interface\{9D932020-700E-4F0D-8446-2872ABD8B4FA}]
    [-HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Classes\Interface\{A45CDEEB-65F5-49AE-AA3E-9376F4806075}]
    [-HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Classes\Interface\{BACAB2F3-7213-4865-96E9-B6B06BF49192}]
    [-HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Classes\Interface\{DD65ABB2-2628-425B-86F5-825E4A3D3AD9}]
    [-HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Classes\AppID\ProtectorExe.EXE]
    [-HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Classes\AppID\{96FBC13C-8214-4100-88E0-FF74D7A1CB4D}]
    [-HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Classes\TypeLib\{C7CB459A-7261-4AE6-A87A-17041EE98A40}]
    [-HKEY_USERS\S-1-5-21-2324462236-1183297055-1014908895-1001\SOFTWARE\AppDataLow\Software\Freecorder\toolbar\Settings\FeatureProtector]
    [-HKEY_LOCAL_MACHINE\SOFTWARE\Classes\ProtectorExe.ProtectorHost]
    [-HKEY_LOCAL_MACHINE\SOFTWARE\Classes\ProtectorExe.ProtectorHost.1]
    [-HKEY_LOCAL_MACHINE\SOFTWARE\Classes\protector_dll.Protector]
    [-HKEY_LOCAL_MACHINE\SOFTWARE\Classes\protector_dll.Protector.1]
    [-HKEY_LOCAL_MACHINE\SOFTWARE\Classes\protector_dll.ProtectorLib]
    [-HKEY_LOCAL_MACHINE\SOFTWARE\Classes\protector_dll.ProtectorLib\CurVer]
    [-HKEY_LOCAL_MACHINE\SOFTWARE\Classes\protector_dll.ProtectorLib.1]
    [-HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{C7CB459A-7261-4AE6-A87A-17041EE98A40}]
    [-HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WOW6432Node\CLSID\{6134CEA9-DD6E-495C-A0D1-4F232027D7D7}]
    [-HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WOW6432Node\CLSID\{84798B8E-69F8-4846-9516-373C2996E2F7}]
    [-HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WOW6432Node\CLSID\{FBA44040-BD27-4A09-ACC8-C08B7C723DCD}]
    
  • Save it to your Desktop as filename fixlist.txt.
  • Right-click FRST.exe and select " Run as administrator " to run it.
  • Press the Fix button just once. Then wait.
  • When finished, it will create a Fixlog.txt log on your Desktop.
  • Please post the content of the Fixlog.txt in your next reply.

Please, give me an update on your computer's performance.
User avatar
nunped
MRU Honors Grad Emeritus
 
Posts: 1210
Joined: August 17th, 2011, 5:03 pm
Location: Portugal

Re: Infected?

Unread postby Risky Rick » December 28th, 2015, 6:19 pm

I copied the page web address, but you didn't tell me what to do with it. I saved it in a notepad file. Let me know if you need it.

The FRST Fixlog:


The computer seems to be running as usual, other than I can hear the drive continually running and seemingly searching the drive whenever I am online. I am running Firefox regularly, and web searches have been giving me a regular 'Server Not Found', and it seems to take long times to get to sites.

I have not done much on it since the last fixes.

Thanks,
Rick
You do not have the required permissions to view the files attached to this post.
Risky Rick
Regular Member
 
Posts: 16
Joined: December 17th, 2015, 5:50 pm

Re: Infected?

Unread postby Risky Rick » December 29th, 2015, 9:22 am

I just noticed the SEND is not working on incredimail. Seems that happened in the past. One reason I had to reload it years back when I did the cleaning for malware. I will have to reload it I assume. Wait till the the cleaning process is over. I have yahoo and gmail I will use until them.
Risky Rick
Regular Member
 
Posts: 16
Joined: December 17th, 2015, 5:50 pm
Advertisement
Register to Remove

Next

  • Similar Topics
    Replies
    Views
    Last post

Return to Infected? Virus, malware, adware, ransomware, oh my!



Who is online

Users browsing this forum: No registered users and 125 guests

Contact us:

Advertisements do not imply our endorsement of that product or service. Register to remove all ads. The forum is run by volunteers who donate their time and expertise. We make every attempt to ensure that the help and advice posted is accurate and will not cause harm to your computer. However, we do not guarantee that they are accurate and they are to be used at your own risk. All trademarks are the property of their respective owners.

Member site: UNITE Against Malware