Flattr this analysis!

Tags: None

Analysis

Category Started Completed Duration
FILE 2014-03-20 02:16:37 2014-03-20 02:18:56 139 seconds

File Details

File Name SoundCloudDownloader__6629_i465268636_il114.exe
File Size 336424 bytes
File Type PE32 executable (GUI) Intel 80386, for MS Windows
MD5 2e20e446943ecd01d3a668083d81d1fc
SHA1 7caff295636abd10b69d392c240b5156050490fa
SHA256 28196d41b2fb6f2e3f0d8b04bc87aa5706fabe2cf36846cc0114dbf4017c0102
SHA512 ec9d78ac709c6a65b7cb501ad2ebba48eaf654d99b9d7e8173f1268e060c3e35a1307fd7e7e1efb2b9f56c9d69dc64f471af71ad1f28a91339ca739c3fa6a68a
CRC32 093801C7
Ssdeep 6144:H9zGLSLhKY35sGot5iQBgMl3b6Me3GMvZMUo+MaooAy/UZCjz7jAGijw8Eon:H9zGusY3+Gg5iYgMVaZ++tooAOwCjfVy
Yara None matched
You need to login

Signatures

Starts servers listening on 127.0.0.1:0, 0.0.0.0:0
File has been identified by at least one AntiVirus on VirusTotal as malicious
Performs some HTTP requests
Collects information to fingerprint the system (MachineGuid, DigitalProductId, SystemBiosDate)
Steals private information from local Internet browsers
Creates an Alternate Data Stream (ADS)
file: C:\DOCUME~1\User\LOCALS~1\Temp\SoundCloudDownloader__6629_i465268636_il114.exe:Zone.Identifier
Installs itself for autorun at Windows startup

Screenshots


Hosts

IP
54.235.189.159
54.230.13.11
54.230.12.192
213.174.130.176

Domains

Domain IP
www.keenondownload.com 54.225.181.84
cdn2.continuumdownload.com 54.230.13.66
cdn1.continuumdownload.com 54.230.12.111
download.freesoftindex.com 213.174.130.176

Summary

C:\DOCUME~1\User\LOCALS~1\Temp\amilog2file.*
C:\DOCUME~1\User\LOCALS~1\Temp\SoundCloudDownloader__6629_i465268636_il114.exe
C:\WINDOWS\Registration\R000000000007.clb
PIPE\lsarpc
C:\Device\Tcp6
C:\Device\Tcp
C:\Device\NetBT_Tcpip_{B83AF3AB-4FED-45D1-A8B8-9E66F3411813}
C:\WINDOWS\system32\stdole2.tlb
C:\WINDOWS\system32\msctfime.ime
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Documents and Settings\User\Local Settings\Application Data\Google\Chrome\Application\chrome.exe
C:\Program Files\Google\Chrome\Application\chrome.exe
C:\Documents and Settings\User\Local Settings\Temporary Internet Files
C:\Documents and Settings\User\Local Settings\History
C:\Documents and Settings\User\Local Settings\Temporary Internet Files\Content.IE5\
C:\
C:\Documents and Settings\User\Local Settings\Temporary Internet Files\Content.IE5\index.dat
C:\Documents and Settings\User\Cookies\
C:\Documents and Settings\User\Cookies\index.dat
C:\Documents and Settings\User\Local Settings\History\History.IE5\
C:\Documents and Settings\User\Local Settings\History\History.IE5\index.dat
C:\Program Files\Microsoft Silverlight\sllauncher.exe
C:\WINDOWS\system32\xpsp3res.dll
c:\autoexec.bat
C:\Documents and Settings
C:\Documents and Settings\User\Local Settings
C:\Documents and Settings\All Users\Application Data\Microsoft\Network\Connections\Pbk\*.pbk
C:\WINDOWS\system32\Ras\*.pbk
C:\Documents and Settings\User\Application Data\Microsoft\Network\Connections\Pbk\*.pbk
C:\Documents and Settings\User\Local Settings\Temporary Internet Files\Content.IE5\UXAF8DAF\index[1].htm
C:\WINDOWS\WindowsShell.manifest
C:\WINDOWS\WindowsShell.Config
C:\Documents and Settings\User\Local Settings\Temporary Internet Files\Content.IE5\4XEJWTA3\amipb[1].js
C:\Documents and Settings\User\Local Settings\Temporary Internet Files\Content.IE5\4XEJWTA3\main[1].css
C:\WINDOWS\win.ini
C:\WINDOWS\system32\dxtmsft.dll
C:\WINDOWS\system32\dxtrans.dll
C:\Documents and Settings\User\Local Settings\Temporary Internet Files\Content.IE5\S16VWHMR\footer_img[1].png
C:\Documents and Settings\User\Local Settings\Temporary Internet Files\Content.IE5\0XQV8DI3\cancel[1].gif
C:\Documents and Settings\User\Local Settings\Temporary Internet Files\Content.IE5\UXAF8DAF\skip[1].gif
C:\Documents and Settings\User\Local Settings\Temporary Internet Files\Content.IE5\UXAF8DAF\decline[1].gif
C:\Documents and Settings\User\Local Settings\Temporary Internet Files\Content.IE5\S16VWHMR\accept[1].gif
C:\Documents and Settings\User\Local Settings\Temporary Internet Files\Content.IE5\0XQV8DI3\install[1].gif
C:\Documents and Settings\User\Local Settings\Temporary Internet Files\Content.IE5\4XEJWTA3\next[1].gif
C:\DOCUME~1\User\LOCALS~1\Temp\ami3.tmp
C:\DOCUME~1\User\LOCALS~1\Temp\ami3.tmp.ico
C:\WINDOWS\system32\mshtml.tlb
IDE#CdRomVBOX_CD-ROM_____________________________1.0_____#42562d3231303037333036372020202020202020#{53f5630d-b6bf-11d0-94f2-00a0c91efb8b}
MountPointManager
STORAGE#Volume#1&30a96598&0&Signature32B832B7Offset7E00Length27F4DB200#{53f5630d-b6bf-11d0-94f2-00a0c91efb8b}
C:\DOCUME~1
C:\Documents and Settings\User
C:\Documents and Settings\User\LOCALS~1
C:\Documents and Settings\User\Local Settings\Temp
C:\Documents and Settings\User\Local Settings\Temp\SoundCloudDownloader__6629_i465268636_il114.exe
C:\DOCUME~1\User\LOCALS~1\Temp\amipixel.cfg
C:\Documents and Settings\User\My Documents
C:\Documents and Settings\User\My Documents\desktop.ini
C:\Documents and Settings\All Users
C:\Documents and Settings\All Users\Documents
C:\Documents and Settings\All Users\Documents\desktop.ini
C:\Documents and Settings\User\Desktop
C:\Documents and Settings\All Users\Desktop
PIPE\srvsvc
C:\Documents and Settings\User\Local Settings\Temp\
C:\Documents and Settings\User\Desktop\Continue install activity - SoundCloudDownloader Installation.lnk
C:\Documents and Settings\User\Start Menu
C:\Documents and Settings\User\Start Menu\desktop.ini
C:\Documents and Settings\All Users\Start Menu
C:\Documents and Settings\All Users\Start Menu\desktop.ini
C:\Documents and Settings\All Users\Application Data
C:\Documents and Settings\All Users\Application Data\desktop.ini
C:\Documents and Settings\User\Application Data
C:\Documents and Settings\User\Application Data\desktop.ini
C:\WINDOWS\system32\msxml3.dll\1
C:\WINDOWS\system32\msxml3.dll
C:\WINDOWS
C:\WINDOWS\system32
C:\Documents and Settings\User\My Documents\My Pictures
C:\Documents and Settings\User\My Documents\My Pictures\desktop.ini
C:\Program Files
C:\Documents and Settings\All Users\Documents\My Pictures
C:\Documents and Settings\All Users\Documents\My Pictures\desktop.ini
PIPE\wkssvc
C:\Documents and Settings\All Users\Documents\My Music
C:\Documents and Settings\All Users\Documents\My Music\desktop.ini
C:\Documents and Settings\All Users\Documents\My Videos
C:\Documents and Settings\All Users\Documents\My Videos\desktop.ini
C:\DOCUME~1\User\LOCALS~1\Temp\SoundCloudDownloader__6629_i465268636_il114.exe:Zone.Identifier
C:\Documents and Settings\User\Local Settings\Application Data\Microsoft\Internet Explorer\MSIMGSIZ.DAT
C:\WINDOWS\system32\en-US\jscript.dll.mui
C:\Documents and Settings\User\Local Settings\Temporary Internet Files\Content.IE5\S16VWHMR\logo1[1].png
C:\Documents and Settings\User\Local Settings\Temporary Internet Files\Content.IE5\S16VWHMR\OK[1].png
C:\Documents and Settings\User\Local Settings\Temporary Internet Files\Content.IE5\0XQV8DI3\OK[1].png
C:\Documents and Settings\User\Local Settings\Temporary Internet Files\Content.IE5\UXAF8DAF\soundcloud[1].png
C:\Documents and Settings\User\Local Settings\Temporary Internet Files\Content.IE5\UXAF8DAF\soundcloud[2].png
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\WinHttp\
HKEY_LOCAL_MACHINE\Software\Microsoft\windows\CurrentVersion\Internet Settings\Connections\
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\WinHttp\UnsafeSslApps\
HKEY_CLASSES_ROOT\XmBsa.Inst.1\
HKEY_CLASSES_ROOT\XmBsa.Inst.1\\CLSID\
HKEY_CLASSES_ROOT\XmBsa.Inst\
HKEY_CLASSES_ROOT\XmBsa.Inst\\CurVer\
HKEY_CLASSES_ROOT\CLSID\
HKEY_CLASSES_ROOT\CLSID\\{FC0F186C-11A6-456F-A0EE-CBE9ED7E233E}\
HKEY_CLASSES_ROOT\CLSID\\{FC0F186C-11A6-456F-A0EE-CBE9ED7E233E}\\ProgID\
HKEY_CLASSES_ROOT\CLSID\\{FC0F186C-11A6-456F-A0EE-CBE9ED7E233E}\\VersionIndependentProgID\
HKEY_CLASSES_ROOT\CLSID\\{FC0F186C-11A6-456F-A0EE-CBE9ED7E233E}\\Programmable\
HKEY_CLASSES_ROOT\CLSID\\{FC0F186C-11A6-456F-A0EE-CBE9ED7E233E}\\LocalServer32\
HKEY_CLASSES_ROOT\CLSID\\{FC0F186C-11A6-456F-A0EE-CBE9ED7E233E}\\TypeLib\
HKEY_CLASSES_ROOT\CLSID\\{FC0F186C-11A6-456F-A0EE-CBE9ED7E233E}\\Version\
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\OLEAUT\
HKEY_CLASSES_ROOT\TypeLib\
HKEY_CLASSES_ROOT\TypeLib\\{83829839-609D-4F6E-8C12-6D4AA7127A57}\
HKEY_CLASSES_ROOT\TypeLib\\{83829839-609D-4F6E-8C12-6D4AA7127A57}\\1.0\
HKEY_CLASSES_ROOT\TypeLib\\{83829839-609D-4F6E-8C12-6D4AA7127A57}\\1.0\\FLAGS\
HKEY_CLASSES_ROOT\TypeLib\\{83829839-609D-4F6E-8C12-6D4AA7127A57}\\1.0\\0\
HKEY_CLASSES_ROOT\TypeLib\\{83829839-609D-4F6E-8C12-6D4AA7127A57}\\1.0\\0\\win32\
HKEY_CLASSES_ROOT\TypeLib\\{83829839-609D-4F6E-8C12-6D4AA7127A57}\\1.0\\HELPDIR\
HKEY_CLASSES_ROOT\Interface\
HKEY_CLASSES_ROOT\Interface\\{D54C859C-6066-4F31-8FE0-2AAEDCAE67D7}\
HKEY_CLASSES_ROOT\Interface\\{D54C859C-6066-4F31-8FE0-2AAEDCAE67D7}\\ProxyStubClsid\
HKEY_CLASSES_ROOT\Interface\\{D54C859C-6066-4F31-8FE0-2AAEDCAE67D7}\\ProxyStubClsid32\
HKEY_CLASSES_ROOT\Interface\\{D54C859C-6066-4F31-8FE0-2AAEDCAE67D7}\\TypeLib\
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders\
HKEY_LOCAL_MACHINE\Software\Microsoft\COM3\
C:\Registry\User\S-1-5-21-1547161642-507921405-839522115-1004_Classes\
HKEY_LOCAL_MACHINE\Software\Classes\
C:\REGISTRY\USER\
HKEY_LOCAL_MACHINE\Software\Classes\CLSID\
CLSID\{FC0F186C-11A6-456F-A0EE-CBE9ED7E233E}\
CLSID\{FC0F186C-11A6-456F-A0EE-CBE9ED7E233E}\\TreatAs\
\
\\CLSID\{FC0F186C-11A6-456F-A0EE-CBE9ED7E233E}\
\\CLSID\{FC0F186C-11A6-456F-A0EE-CBE9ED7E233E}\\InprocServer32\
\\CLSID\{FC0F186C-11A6-456F-A0EE-CBE9ED7E233E}\\InprocServerX86\
\\CLSID\{FC0F186C-11A6-456F-A0EE-CBE9ED7E233E}\\LocalServer32\
\\CLSID\{FC0F186C-11A6-456F-A0EE-CBE9ED7E233E}\\InprocHandler32\
\\CLSID\{FC0F186C-11A6-456F-A0EE-CBE9ED7E233E}\\InprocHandlerX86\
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\NET Framework Setup\NDP\v1.1.4322\
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\NET Framework Setup\NDP\v3.5\
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\NET Framework Setup\NDP\v3.0\
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\NET Framework Setup\NDP\v2.0.50727\
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\NET Framework Setup\NDP\v4\Full\
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\NET Framework Setup\NDP\V4\Client\
C:\Registry\Machine\System\CurrentControlSet\Control\ComputerName\
C:\ActiveComputerName\
HKEY_LOCAL_MACHINE\Software\Microsoft\Ole\
HKEY_CLASSES_ROOT\AppID\SoundCloudDownloader__6629_i465268636_il114.exe\
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\OLE\
HKEY_CLASSES_ROOT\CLSID\{FC0F186C-11A6-456F-A0EE-CBE9ED7E233E}\
HKEY_CLASSES_ROOT\CLSID\{FC0F186C-11A6-456F-A0EE-CBE9ED7E233E}\\TreatAs\
\\CLSID\{FC0F186C-11A6-456F-A0EE-CBE9ED7E233E}\\InprocHandler\
HKEY_CLASSES_ROOT\Interface\{D54C859C-6066-4F31-8FE0-2AAEDCAE67D7}\
HKEY_CLASSES_ROOT\Interface\{D54C859C-6066-4F31-8FE0-2AAEDCAE67D7}\\ProxyStubClsid32\
CLSID\{00020424-0000-0000-C000-000000000046}\
CLSID\{00020424-0000-0000-C000-000000000046}\\TreatAs\
\\CLSID\{00020424-0000-0000-C000-000000000046}\
\\CLSID\{00020424-0000-0000-C000-000000000046}\\InprocServer32\
\\CLSID\{00020424-0000-0000-C000-000000000046}\\InprocServerX86\
\\CLSID\{00020424-0000-0000-C000-000000000046}\\LocalServer32\
\\CLSID\{00020424-0000-0000-C000-000000000046}\\InprocHandler32\
\\CLSID\{00020424-0000-0000-C000-000000000046}\\InprocHandlerX86\
\\CLSID\{00020424-0000-0000-C000-000000000046}\\LocalServer\
HKEY_CLASSES_ROOT\CLSID\{00020424-0000-0000-C000-000000000046}\
HKEY_CLASSES_ROOT\CLSID\{00020424-0000-0000-C000-000000000046}\\TreatAs\
Interface\{D54C859C-6066-4F31-8FE0-2AAEDCAE67D7}\ProxyStubClsid32\
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{B83AF3AB-4FED-45D1-A8B8-9E66F3411813}\
Interface\{D54C859C-6066-4F31-8FE0-2AAEDCAE67D7}\Forward\
HKEY_CLASSES_ROOT\TypeLib\{83829839-609D-4F6E-8C12-6D4AA7127A57}\
HKEY_CLASSES_ROOT\TypeLib\{83829839-609D-4F6E-8C12-6D4AA7127A57}\\1.0\
HKEY_CLASSES_ROOT\TypeLib\{83829839-609D-4F6E-8C12-6D4AA7127A57}\\1.0\\0\
HKEY_CLASSES_ROOT\TypeLib\{83829839-609D-4F6E-8C12-6D4AA7127A57}\\1.0\\0\\win32\
HKEY_CLASSES_ROOT\TypeLib\\{00020430-0000-0000-C000-000000000046}\
HKEY_CLASSES_ROOT\TypeLib\\{00020430-0000-0000-C000-000000000046}\\2.0\
HKEY_CLASSES_ROOT\TypeLib\\{00020430-0000-0000-C000-000000000046}\\2.0\\0\
HKEY_CLASSES_ROOT\TypeLib\\{00020430-0000-0000-C000-000000000046}\\2.0\\0\\win32\
HKEY_LOCAL_MACHINE\Software\Microsoft\Rpc\
HKEY_CLASSES_ROOT\Interface\{00020400-0000-0000-C000-000000000046}\
HKEY_CLASSES_ROOT\Interface\{00020400-0000-0000-C000-000000000046}\\ProxyStubClsid32\
CLSID\{00020420-0000-0000-C000-000000000046}\
CLSID\{00020420-0000-0000-C000-000000000046}\\TreatAs\
\\CLSID\{00020420-0000-0000-C000-000000000046}\
\\CLSID\{00020420-0000-0000-C000-000000000046}\\InprocServer32\
\\CLSID\{00020420-0000-0000-C000-000000000046}\\InprocServerX86\
\\CLSID\{00020420-0000-0000-C000-000000000046}\\LocalServer32\
\\CLSID\{00020420-0000-0000-C000-000000000046}\\InprocHandler32\
\\CLSID\{00020420-0000-0000-C000-000000000046}\\InprocHandlerX86\
\\CLSID\{00020420-0000-0000-C000-000000000046}\\LocalServer\
HKEY_CLASSES_ROOT\CLSID\{00020420-0000-0000-C000-000000000046}\
HKEY_CLASSES_ROOT\CLSID\{00020420-0000-0000-C000-000000000046}\\TreatAs\
HKEY_CLASSES_ROOT\Interface\{D54C859C-6066-4F31-8FE0-2AAEDCAE67D7}\TypeLib\
HKEY_CLASSES_ROOT\TypeLib\\{00020430-0000-0000-C000-000000000046}\\2.0\\0\\win32\\win32\
HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\Network\{4D36E972-E325-11CE-BFC1-08002BE10318}\{B83AF3AB-4FED-45D1-A8B8-9E66F3411813}\Connection\
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\IMM\
HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\Network\{4D36E972-E325-11CE-BFC1-08002BE10318}\{00000000-0000-0000-0000-000000000000}\Connection\
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\MS TCP Loopback interface\
HKEY_LOCAL_MACHINE\Software\Microsoft\Cryptography\
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\
C:\REGISTRY\USER\S-1-5-21-1547161642-507921405-839522115-1004\Software\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Layers\
HKEY_CURRENT_USER\SOFTWARE\Microsoft\CTF\
HKEY_LOCAL_MACHINE\Software\Microsoft\CTF\SystemShared\
CLSID\{8856F961-340A-11D0-A96B-00C04FD705A2}\
CLSID\{8856F961-340A-11D0-A96B-00C04FD705A2}\\TreatAs\
\\CLSID\{8856F961-340A-11D0-A96B-00C04FD705A2}\
\\CLSID\{8856F961-340A-11D0-A96B-00C04FD705A2}\\InprocServer32\
\\CLSID\{8856F961-340A-11D0-A96B-00C04FD705A2}\\InprocServerX86\
\\CLSID\{8856F961-340A-11D0-A96B-00C04FD705A2}\\LocalServer32\
\\CLSID\{8856F961-340A-11D0-A96B-00C04FD705A2}\\InprocHandler32\
\\CLSID\{8856F961-340A-11D0-A96B-00C04FD705A2}\\InprocHandlerX86\
\\CLSID\{8856F961-340A-11D0-A96B-00C04FD705A2}\\LocalServer\
HKEY_CLASSES_ROOT\CLSID\{8856F961-340A-11D0-A96B-00C04FD705A2}\
HKEY_CLASSES_ROOT\CLSID\{8856F961-340A-11D0-A96B-00C04FD705A2}\\TreatAs\
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\Security\P3Global\
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\Security\P3Sites\
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\
HKEY_CURRENT_USER\SOFTWARE\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\
HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Internet Explorer\Main\FeatureControl\
HKEY_CURRENT_USER\Software\Policies\Microsoft\Internet Explorer\Main\FeatureControl\
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main\FeatureControl\
HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main\FeatureControl\
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\
HKEY_LOCAL_MACHINE\System\Setup\
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders\
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\\Content\
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\\Content\
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\\Paths\
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\\Paths\\Path1\
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\\Paths\\Path2\
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\\Paths\\Path3\
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\\Paths\\Path4\
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\\Special Paths\
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\\Cookies\
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\\Cookies\
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\\History\
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\\History\
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\\Extensible Cache\
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\\Extensible Cache\\MSHist012013041020130411\
HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\
HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main\FeatureControl\\FEATURE_AUTOPROXY_CACHE_ANAME_KB921400\
HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main\FeatureControl\\FEATURE_TEMPORARYFILES_FOR_NOCACHE_840387\
HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main\FeatureControl\\FEATURE_TEMPORARYFILES_FOR_NOCACHE_840386\
HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main\FeatureControl\\RETRY_HEADERONLYPOST_ONCONNECTIONRESET\
HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main\FeatureControl\\FEATURE_CHUNK_TIMEOUT_KB914453\
HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main\FeatureControl\\FEATURE_CERT_TRUST_VERIFIED_KB936882\
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\
HKEY_CURRENT_USER\SOFTWARE\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\
HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main\FeatureControl\\FEATURE_BUFFERBREAKING_818408\
HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main\FeatureControl\\FEATURE_SKIP_POST_RETRY_ON_INTERNETWRITEFILE_KB895954\
HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main\FeatureControl\\FEATURE_ENSURE_FQDN_FOR_NEGOTIATE_KB899417\
HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main\FeatureControl\\FEATURE_HTTP_DISABLE_NTLM_PREAUTH_IF_ABORTED_KB902409\
HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main\FeatureControl\\FEATURE_PERMIT_CACHE_FOR_AUTHENTICATED_FTP_KB910274\
HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main\FeatureControl\\FEATURE_WPAD_STORE_URL_AS_FQDN_KB903926\
HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main\FeatureControl\\FEATURE_USE_CNAME_FOR_SPN_KB911149\
HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main\FeatureControl\\FEATURE_KEEP_CACHE_INDEX_OPEN_KB899342\
HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main\FeatureControl\\FEATURE_WAIT_TIME_THREAD_TERMINATE_KB886801\
HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main\FeatureControl\\FEATURE_FIX_CHUNKED_PROXY_SCRIPT_DOWNLOAD_KB843289\
HKEY_CURRENT_USER\SOFTWARE\Clients\StartMenuInternet\
HKEY_LOCAL_MACHINE\SOFTWARE\Clients\StartMenuInternet\
C:\Registry\MACHINE\System\CurrentControlSet\Control\Session Manager\AppCompatibility\
CLSID\{00021401-0000-0000-C000-000000000046}\
CLSID\{00021401-0000-0000-C000-000000000046}\\TreatAs\
\\CLSID\{00021401-0000-0000-C000-000000000046}\
\\CLSID\{00021401-0000-0000-C000-000000000046}\\InprocServer32\
\\CLSID\{00021401-0000-0000-C000-000000000046}\\InprocServerX86\
\\CLSID\{00021401-0000-0000-C000-000000000046}\\LocalServer32\
\\CLSID\{00021401-0000-0000-C000-000000000046}\\InprocHandler32\
\\CLSID\{00021401-0000-0000-C000-000000000046}\\InprocHandlerX86\
\\CLSID\{00021401-0000-0000-C000-000000000046}\\LocalServer\
HKEY_CLASSES_ROOT\CLSID\{00021401-0000-0000-C000-000000000046}\
HKEY_CLASSES_ROOT\CLSID\{00021401-0000-0000-C000-000000000046}\\TreatAs\
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\ProfileList\S-1-5-21-1547161642-507921405-839522115-1004\
HKEY_CLASSES_ROOT\http\
HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main\FeatureControl\\FEATURE_ADDRESS_BAR_UPDATING_KB897251\
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\International\
HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main\FeatureControl\\FEATURE_CLOSE_EMPTY_BROWSER_KB920982\
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\New Windows\
HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\New Windows\
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Extensions\
HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Extensions\
HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Extensions\\{2670000A-7350-4f3c-8081-5663EE0C6C49}\
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Extensions\{2670000A-7350-4F3C-8081-5663EE0C6C49}\
HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Extensions\{2670000A-7350-4F3C-8081-5663EE0C6C49}\
HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Extensions\{2670000A-7350-4F3C-8081-5663EE0C6C49}\\Lang0409\
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Extensions\CmdMapping\
HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Extensions\\{92780B25-18CC-41C8-B9BE-3C9C571A8263}\
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Extensions\{92780B25-18CC-41C8-B9BE-3C9C571A8263}\
HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Extensions\{92780B25-18CC-41C8-B9BE-3C9C571A8263}\
HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Extensions\{92780B25-18CC-41C8-B9BE-3C9C571A8263}\\Lang0409\
HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Extensions\\{e2e2dd38-d088-4134-82b7-f2ba38496583}\
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Extensions\{E2E2DD38-D088-4134-82B7-F2BA38496583}\
HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Extensions\{E2E2DD38-D088-4134-82B7-F2BA38496583}\
HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Extensions\{E2E2DD38-D088-4134-82B7-F2BA38496583}\\Lang0409\
HKEY_CURRENT_USER\Software\Microsoft\Windows\ShellNoRoam\
HKEY_USERS\S-1-5-21-1547161642-507921405-839522115-1004\
HKEY_CURRENT_USER\Software\Microsoft\Windows\ShellNoRoam\\MUICache\
HKEY_CURRENT_USER\Software\Microsoft\Windows\ShellNoRoam\\MUICache\\
HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Extensions\\{FB5F1910-F110-11d2-BB9E-00C04F795683}\
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Extensions\{FB5F1910-F110-11D2-BB9E-00C04F795683}\
HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Extensions\{FB5F1910-F110-11D2-BB9E-00C04F795683}\
HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Extensions\{FB5F1910-F110-11D2-BB9E-00C04F795683}\\Lang0409\
HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\International\
HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\MediaTypeClass\
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Accepted Documents\
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\Ratings\
HKEY_CLASSES_ROOT\PROTOCOLS\Name-Space Handler\\
HKEY_CLASSES_ROOT\PROTOCOLS\Name-Space Handler\http\\
HKEY_CLASSES_ROOT\PROTOCOLS\Name-Space Handler\*\\
HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main\FeatureControl\\FEATURE_HTTP_USERNAME_PASSWORD_DISABLE\
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\User Agent\
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\User Agent\
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\User Agent\
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\User Agent\
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\User Agent\\UA Tokens\
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\User Agent\\Pre Platform\
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\User Agent\\Pre Platform\
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\User Agent\\Post Platform\
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\User Agent\\Post Platform\
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\UrlMon Settings\
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Http Filters\RPA\
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Http Filters\RPA\
HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main\FeatureControl\\FEATURE_INCLUDE_PORT_IN_SPN_KB908209\
HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main\FeatureControl\\FEATURE_MIME_HANDLING\
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\\
HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\\
HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\\
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\\\Ranges\\
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\TravelLog\
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\TravelLog\
HKEY_LOCAL_MACHINE\Software\Microsoft\Tracing\
HKEY_LOCAL_MACHINE\Software\Microsoft\Tracing\RASAPI32\
HKEY_USERS\S-1-5-21-1547161642-507921405-839522115-1004\\Software\Microsoft\windows\CurrentVersion\Internet Settings\Connections\
HKEY_USERS\S-1-5-21-1547161642-507921405-839522115-1004\\Software\Microsoft\windows\CurrentVersion\Internet Settings\
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders\
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\ProfileList\
HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\Session Manager\Environment\
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\
HKEY_USERS\S-1-5-21-1547161642-507921405-839522115-1004\\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\
HKEY_USERS\S-1-5-21-1547161642-507921405-839522115-1004\\Environment\
HKEY_USERS\S-1-5-21-1547161642-507921405-839522115-1004\\Volatile Environment\
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders\
HKEY_USERS\S-1-5-21-1547161642-507921405-839522115-1004\\Software\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders\
HKEY_USERS\S-1-5-21-1547161642-507921405-839522115-1004\\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders\
HKEY_CURRENT_CONFIG\Software\Microsoft\windows\CurrentVersion\Internet Settings\
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\\
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\\\0\
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\\\1\
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\\\2\
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\\\3\
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\\\4\
HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\\
HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\\
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\0\
HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\0\
HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\0\
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\1\
HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\1\
HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\1\
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\2\
HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\2\
HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\2\
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\3\
HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\3\
HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\3\
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\4\
HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\4\
HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\4\
HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Lockdown_Zones\\
HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Lockdown_Zones\\
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Lockdown_Zones\\
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Lockdown_Zones\0\
HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Lockdown_Zones\0\
HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Lockdown_Zones\0\
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Lockdown_Zones\1\
HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Lockdown_Zones\1\
HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Lockdown_Zones\1\
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Lockdown_Zones\2\
HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Lockdown_Zones\2\
HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Lockdown_Zones\2\
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Lockdown_Zones\3\
HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Lockdown_Zones\3\
HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Lockdown_Zones\3\
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Lockdown_Zones\4\
HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Lockdown_Zones\4\
HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Lockdown_Zones\4\
HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main\FeatureControl\\FEATURE_VALIDATE_URLHOSTNAME\
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\\\Domains\keenondownload.com\
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\keenondownload.com\
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\\\ProtocolDefaults\\
HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main\FeatureControl\\FEATURE_RESPECT_OBJECTSAFETY_POLICY_KB905547\
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\
HKEY_CLASSES_ROOT\MIME\Database\Content Type\text/html; charset=UTF-8\
HKEY_CLASSES_ROOT\MIME\Database\Content Type\text/html\
HKEY_CURRENT_USER\SOFTWARE\Classes\PROTOCOLS\Filter\text/html; charset=UTF-8\
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\PROTOCOLS\Filter\text/html; charset=UTF-8\
HKEY_CURRENT_USER\SOFTWARE\Classes\PROTOCOLS\Filter\text/html\
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\PROTOCOLS\Filter\text/html\
CLSID\{25336920-03F9-11CF-8FD0-00AA00686F13}\
CLSID\{25336920-03F9-11CF-8FD0-00AA00686F13}\\TreatAs\
\\CLSID\{25336920-03F9-11CF-8FD0-00AA00686F13}\
\\CLSID\{25336920-03F9-11CF-8FD0-00AA00686F13}\\InprocServer32\
\\CLSID\{25336920-03F9-11CF-8FD0-00AA00686F13}\\InprocServerX86\
\\CLSID\{25336920-03F9-11CF-8FD0-00AA00686F13}\\LocalServer32\
\\CLSID\{25336920-03F9-11CF-8FD0-00AA00686F13}\\InprocHandler32\
\\CLSID\{25336920-03F9-11CF-8FD0-00AA00686F13}\\InprocHandlerX86\
\\CLSID\{25336920-03F9-11CF-8FD0-00AA00686F13}\\LocalServer\
HKEY_CLASSES_ROOT\CLSID\{25336920-03F9-11CF-8FD0-00AA00686F13}\
HKEY_CLASSES_ROOT\CLSID\{25336920-03F9-11CF-8FD0-00AA00686F13}\\TreatAs\
HKEY_CURRENT_USER\Control Panel\International\
C:\REGISTRY\USER\S-1-5-21-1547161642-507921405-839522115-1004\
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Security\Floppy Access\
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Security\Adv AddrBar Spoof Detection\
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Printing\
HKEY_CLASSES_ROOT\PROTOCOLS\Name-Space Handler\about\\
HKEY_CURRENT_USER\SOFTWARE\Classes\PROTOCOLS\Handler\about\
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\PROTOCOLS\Handler\about\
CLSID\{3050F406-98B5-11CF-BB82-00AA00BDCE0B}\
CLSID\{3050F406-98B5-11CF-BB82-00AA00BDCE0B}\\TreatAs\
\\CLSID\{3050F406-98B5-11CF-BB82-00AA00BDCE0B}\
\\CLSID\{3050F406-98B5-11CF-BB82-00AA00BDCE0B}\\InprocServer32\
\\CLSID\{3050F406-98B5-11CF-BB82-00AA00BDCE0B}\\InprocServerX86\
\\CLSID\{3050F406-98B5-11CF-BB82-00AA00BDCE0B}\\LocalServer32\
\\CLSID\{3050F406-98B5-11CF-BB82-00AA00BDCE0B}\\InprocHandler32\
\\CLSID\{3050F406-98B5-11CF-BB82-00AA00BDCE0B}\\InprocHandlerX86\
\\CLSID\{3050F406-98B5-11CF-BB82-00AA00BDCE0B}\\LocalServer\
HKEY_CLASSES_ROOT\CLSID\{3050F406-98B5-11CF-BB82-00AA00BDCE0B}\
HKEY_CLASSES_ROOT\CLSID\{3050F406-98B5-11CF-BB82-00AA00BDCE0B}\\TreatAs\
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\\\Domains\blank\
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\blank\
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\ProtocolDefaults\\
\\CLSID\{25336920-03F9-11CF-8FD0-00AA00686F13}\\Progid\
HKEY_CURRENT_USER\Software\Microsoft\windows\CurrentVersion\Internet Settings\Url History\
HKEY_LOCAL_MACHINE\Software\Microsoft\windows\CurrentVersion\Internet Settings\Url History\
HKEY_CURRENT_USER\Software\Microsoft\windows\CurrentVersion\Internet Settings\
HKEY_LOCAL_MACHINE\Software\Microsoft\windows\CurrentVersion\Internet Settings\
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\\Main\
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\\International\
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\\International\Scripts\
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\\Settings\
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\\Styles\
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\\Policies\ActiveDesktop\
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\\Policies\
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\\Internet Settings\
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\\MenuExt\
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\\MenuExt\\E&xport to Microsoft Excel\
HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\Nls\CodePage\
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\\International\Scripts\3\
HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Version Vector\
CLSID\{7B8A2D94-0AC9-11D1-896C-00C04FB6BFC4}\
CLSID\{7B8A2D94-0AC9-11D1-896C-00C04FB6BFC4}\\TreatAs\
\\CLSID\{7B8A2D94-0AC9-11D1-896C-00C04FB6BFC4}\
\\CLSID\{7B8A2D94-0AC9-11D1-896C-00C04FB6BFC4}\\InprocServer32\
\\CLSID\{7B8A2D94-0AC9-11D1-896C-00C04FB6BFC4}\\InprocServerX86\
\\CLSID\{7B8A2D94-0AC9-11D1-896C-00C04FB6BFC4}\\LocalServer32\
\\CLSID\{7B8A2D94-0AC9-11D1-896C-00C04FB6BFC4}\\InprocHandler32\
\\CLSID\{7B8A2D94-0AC9-11D1-896C-00C04FB6BFC4}\\InprocHandlerX86\
\\CLSID\{7B8A2D94-0AC9-11D1-896C-00C04FB6BFC4}\\LocalServer\
HKEY_CLASSES_ROOT\CLSID\{7B8A2D94-0AC9-11D1-896C-00C04FB6BFC4}\
HKEY_CLASSES_ROOT\CLSID\{7B8A2D94-0AC9-11D1-896C-00C04FB6BFC4}\\TreatAs\
HKEY_CLASSES_ROOT\CLSID\{7B8A2D94-0AC9-11D1-896C-00C04FB6BFC4}\InProcServer32\
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\\\Domains\continuumdownload.com\
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\continuumdownload.com\
CLSID\{F414C260-6AC0-11CF-B6D1-00AA00BBBB58}\
CLSID\{F414C260-6AC0-11CF-B6D1-00AA00BBBB58}\\TreatAs\
\\CLSID\{F414C260-6AC0-11CF-B6D1-00AA00BBBB58}\
\\CLSID\{F414C260-6AC0-11CF-B6D1-00AA00BBBB58}\\InprocServer32\
\\CLSID\{F414C260-6AC0-11CF-B6D1-00AA00BBBB58}\\InprocServerX86\
\\CLSID\{F414C260-6AC0-11CF-B6D1-00AA00BBBB58}\\LocalServer32\
\\CLSID\{F414C260-6AC0-11CF-B6D1-00AA00BBBB58}\\InprocHandler32\
\\CLSID\{F414C260-6AC0-11CF-B6D1-00AA00BBBB58}\\InprocHandlerX86\
\\CLSID\{F414C260-6AC0-11CF-B6D1-00AA00BBBB58}\\LocalServer\
HKEY_CLASSES_ROOT\CLSID\{F414C260-6AC0-11CF-B6D1-00AA00BBBB58}\
HKEY_CLASSES_ROOT\CLSID\{F414C260-6AC0-11CF-B6D1-00AA00BBBB58}\\TreatAs\
HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\ActiveX Compatibility\
HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\ActiveX Compatibility\\{F414C260-6AC0-11CF-B6D1-00AA00BBBB58}\
C:\Registry\Machine\System\CurrentControlSet\Control\Nls\Locale\
C:\Registry\Machine\System\CurrentControlSet\Control\Nls\Locale\Alternate Sorts\
C:\Registry\Machine\System\CurrentControlSet\Control\Nls\Language Groups\
HKEY_CLASSES_ROOT\xml\
HKEY_CLASSES_ROOT\xml\\CLSID\
CLSID\{989D1DC0-B162-11D1-B6EC-D27DDCF9A923}\
CLSID\{989D1DC0-B162-11D1-B6EC-D27DDCF9A923}\\TreatAs\
HKEY_CLASSES_ROOT\CLSID\{989D1DC0-B162-11D1-B6EC-D27DDCF9A923}\Implemented Categories\{F0B7A1A2-9847-11CF-8F20-00805F2CD064}\
HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Internet Explorer\Restrictions\
HKEY_CURRENT_USER\Software\Policies\Microsoft\Internet Explorer\Restrictions\
HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main\FeatureControl\\FEATURE_INTELLIFORMS_ALTERNATE_RELEASE_KB924301\
CLSID\{50D5107A-D278-4871-8989-F4CEAAF59CFC}\
CLSID\{50D5107A-D278-4871-8989-F4CEAAF59CFC}\\TreatAs\
\\CLSID\{50D5107A-D278-4871-8989-F4CEAAF59CFC}\
\\CLSID\{50D5107A-D278-4871-8989-F4CEAAF59CFC}\\InprocServer32\
\\CLSID\{50D5107A-D278-4871-8989-F4CEAAF59CFC}\\InprocServerX86\
\\CLSID\{50D5107A-D278-4871-8989-F4CEAAF59CFC}\\LocalServer32\
\\CLSID\{50D5107A-D278-4871-8989-F4CEAAF59CFC}\\InprocHandler32\
\\CLSID\{50D5107A-D278-4871-8989-F4CEAAF59CFC}\\InprocHandlerX86\
\\CLSID\{50D5107A-D278-4871-8989-F4CEAAF59CFC}\\LocalServer\
HKEY_CLASSES_ROOT\CLSID\{50D5107A-D278-4871-8989-F4CEAAF59CFC}\
HKEY_CLASSES_ROOT\CLSID\{50D5107A-D278-4871-8989-F4CEAAF59CFC}\\TreatAs\
HKEY_LOCAL_MACHINE\Software\Microsoft\CTF\TIP\
HKEY_LOCAL_MACHINE\Software\Microsoft\CTF\TIP\\{70FAF614-E0B1-11D3-8F5C-00C04F9CF4AC}\LanguageProfile\
HKEY_LOCAL_MACHINE\Software\Microsoft\CTF\TIP\\{78CB5B0E-26ED-4FCC-854C-77E8F3D1AA80}\LanguageProfile\
HKEY_LOCAL_MACHINE\Software\Microsoft\CTF\TIP\\{C1EE01F2-B3B6-4A6A-9DDD-E988C088EC82}\LanguageProfile\
HKEY_LOCAL_MACHINE\Software\Microsoft\CTF\TIP\\{DCBD6FA8-032F-11D3-B5B1-00C04FC324A1}\LanguageProfile\
HKEY_CURRENT_USER\SOFTWARE\Microsoft\CTF\TIP\{DCBD6FA8-032F-11D3-B5B1-00C04FC324A1}\LanguageProfile\
HKEY_CURRENT_USER\SOFTWARE\Microsoft\CTF\TIP\{DCBD6FA8-032F-11D3-B5B1-00C04FC324A1}\LanguageProfile\0x00000409\
HKEY_CURRENT_USER\SOFTWARE\Microsoft\CTF\TIP\{DCBD6FA8-032F-11D3-B5B1-00C04FC324A1}\LanguageProfile\0x00000409\{09EA4E4B-46CE-4469-B450-0DE76A435BBB}\
HKEY_LOCAL_MACHINE\Software\Microsoft\CTF\TIP\\{F89E9E58-BD2F-4008-9AC2-0F816C09F4EE}\LanguageProfile\
HKEY_LOCAL_MACHINE\Software\Microsoft\CTF\TIP\\{FA445657-9379-11D6-B41A-00065B83EE53}\LanguageProfile\
HKEY_CURRENT_USER\SOFTWARE\Microsoft\CTF\TIP\{FA445657-9379-11D6-B41A-00065B83EE53}\LanguageProfile\
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\CTF\TIP\{FA445657-9379-11D6-B41A-00065B83EE53}\LanguageProfile\
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\CTF\TIP\{FA445657-9379-11D6-B41A-00065B83EE53}\LanguageProfile\0x0000FFFF\
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\CTF\TIP\{FA445657-9379-11D6-B41A-00065B83EE53}\LanguageProfile\0x0000FFFF\{38445657-9381-11D6-B41A-00065B83EE53}\
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\CTF\SystemShared\
CLSID\{3CE74DE4-53D3-4D74-8B83-431B3828BA53}\
CLSID\{3CE74DE4-53D3-4D74-8B83-431B3828BA53}\\TreatAs\
\\CLSID\{3CE74DE4-53D3-4D74-8B83-431B3828BA53}\
\\CLSID\{3CE74DE4-53D3-4D74-8B83-431B3828BA53}\\InprocServer32\
\\CLSID\{3CE74DE4-53D3-4D74-8B83-431B3828BA53}\\InprocServerX86\
\\CLSID\{3CE74DE4-53D3-4D74-8B83-431B3828BA53}\\LocalServer32\
\\CLSID\{3CE74DE4-53D3-4D74-8B83-431B3828BA53}\\InprocHandler32\
\\CLSID\{3CE74DE4-53D3-4D74-8B83-431B3828BA53}\\InprocHandlerX86\
\\CLSID\{3CE74DE4-53D3-4D74-8B83-431B3828BA53}\\LocalServer\
HKEY_CLASSES_ROOT\CLSID\{3CE74DE4-53D3-4D74-8B83-431B3828BA53}\
HKEY_CLASSES_ROOT\CLSID\{3CE74DE4-53D3-4D74-8B83-431B3828BA53}\\TreatAs\
CLSID\{A4B544A1-438D-4B41-9325-869523E2D6C7}\
CLSID\{A4B544A1-438D-4B41-9325-869523E2D6C7}\\TreatAs\
\\CLSID\{A4B544A1-438D-4B41-9325-869523E2D6C7}\
\\CLSID\{A4B544A1-438D-4B41-9325-869523E2D6C7}\\InprocServer32\
\\CLSID\{A4B544A1-438D-4B41-9325-869523E2D6C7}\\InprocServerX86\
\\CLSID\{A4B544A1-438D-4B41-9325-869523E2D6C7}\\LocalServer32\
\\CLSID\{A4B544A1-438D-4B41-9325-869523E2D6C7}\\InprocHandler32\
\\CLSID\{A4B544A1-438D-4B41-9325-869523E2D6C7}\\InprocHandlerX86\
\\CLSID\{A4B544A1-438D-4B41-9325-869523E2D6C7}\\LocalServer\
HKEY_CLASSES_ROOT\CLSID\{A4B544A1-438D-4B41-9325-869523E2D6C7}\
HKEY_CLASSES_ROOT\CLSID\{A4B544A1-438D-4B41-9325-869523E2D6C7}\\TreatAs\
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\CTF\TIP\\
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\CTF\TIP\\\{70FAF614-E0B1-11D3-8F5C-00C04F9CF4AC}\Category\Category\{B95F181B-EA4C-4AF1-8056-7C321ABBB091}\
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\CTF\TIP\\\{78CB5B0E-26ED-4FCC-854C-77E8F3D1AA80}\Category\Category\{B95F181B-EA4C-4AF1-8056-7C321ABBB091}\
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\CTF\TIP\\\{C1EE01F2-B3B6-4A6A-9DDD-E988C088EC82}\Category\Category\{B95F181B-EA4C-4AF1-8056-7C321ABBB091}\
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\CTF\TIP\\\{DCBD6FA8-032F-11D3-B5B1-00C04FC324A1}\Category\Category\{B95F181B-EA4C-4AF1-8056-7C321ABBB091}\
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\CTF\TIP\\\{F89E9E58-BD2F-4008-9AC2-0F816C09F4EE}\Category\Category\{B95F181B-EA4C-4AF1-8056-7C321ABBB091}\
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\CTF\TIP\\\{FA445657-9379-11D6-B41A-00065B83EE53}\Category\Category\{B95F181B-EA4C-4AF1-8056-7C321ABBB091}\
HKEY_CURRENT_USER\Keyboard Layout\Toggle\
HKEY_CURRENT_USER\SOFTWARE\Microsoft\CTF\LangBarAddIn\\
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\CTF\LangBarAddIn\\
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\CTF\TIP\\\{70FAF614-E0B1-11D3-8F5C-00C04F9CF4AC}\Category\Category\{534C48C1-0607-4098-A521-4FC899C73E90}\
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\CTF\TIP\\\{78CB5B0E-26ED-4FCC-854C-77E8F3D1AA80}\Category\Category\{534C48C1-0607-4098-A521-4FC899C73E90}\
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\CTF\TIP\\\{C1EE01F2-B3B6-4A6A-9DDD-E988C088EC82}\Category\Category\{534C48C1-0607-4098-A521-4FC899C73E90}\
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\CTF\TIP\\\{DCBD6FA8-032F-11D3-B5B1-00C04FC324A1}\Category\Category\{534C48C1-0607-4098-A521-4FC899C73E90}\
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\CTF\TIP\\\{F89E9E58-BD2F-4008-9AC2-0F816C09F4EE}\Category\Category\{534C48C1-0607-4098-A521-4FC899C73E90}\
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\CTF\TIP\\\{FA445657-9379-11D6-B41A-00065B83EE53}\Category\Category\{534C48C1-0607-4098-A521-4FC899C73E90}\
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\CTF\TIP\\\{70FAF614-E0B1-11D3-8F5C-00C04F9CF4AC}\Category\Item\{5130A009-5540-4FCF-97EB-AAD33FC0EE09}\
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\CTF\TIP\\\{78CB5B0E-26ED-4FCC-854C-77E8F3D1AA80}\Category\Item\{5130A009-5540-4FCF-97EB-AAD33FC0EE09}\
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\CTF\TIP\\\{70FAF614-E0B1-11D3-8F5C-00C04F9CF4AC}\Category\Item\{7AE86BB7-262C-431E-9111-C974B6B7CAC3}\
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\CTF\TIP\\\{78CB5B0E-26ED-4FCC-854C-77E8F3D1AA80}\Category\Item\{7AE86BB7-262C-431E-9111-C974B6B7CAC3}\
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\CTF\TIP\\\{70FAF614-E0B1-11D3-8F5C-00C04F9CF4AC}\Category\Item\{C6DEBC0A-F2B2-4F17-930E-CA9FAFF4CD04}\
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\CTF\TIP\\\{78CB5B0E-26ED-4FCC-854C-77E8F3D1AA80}\Category\Item\{C6DEBC0A-F2B2-4F17-930E-CA9FAFF4CD04}\
CLSID\{FA445657-9379-11D6-B41A-00065B83EE53}\
HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\App Management\
HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows\App Management\
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\CTF\TIP\\\{70FAF614-E0B1-11D3-8F5C-00C04F9CF4AC}\Category\Item\{A48FA74E-F767-44E4-BFBC-169E8B38FF58}\
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\CTF\TIP\\\{78CB5B0E-26ED-4FCC-854C-77E8F3D1AA80}\Category\Item\{A48FA74E-F767-44E4-BFBC-169E8B38FF58}\
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\CTF\TIP\\\{C1EE01F2-B3B6-4A6A-9DDD-E988C088EC82}\Category\Item\{A48FA74E-F767-44E4-BFBC-169E8B38FF58}\
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\CTF\TIP\\\{DCBD6FA8-032F-11D3-B5B1-00C04FC324A1}\Category\Item\{A48FA74E-F767-44E4-BFBC-169E8B38FF58}\
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\CTF\TIP\\\{F89E9E58-BD2F-4008-9AC2-0F816C09F4EE}\Category\Item\{A48FA74E-F767-44E4-BFBC-169E8B38FF58}\
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\CTF\TIP\\\{FA445657-9379-11D6-B41A-00065B83EE53}\Category\Item\{A48FA74E-F767-44E4-BFBC-169E8B38FF58}\
HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main\FeatureControl\\FEATURE_CSS_DATA_RESPECTS_XSS_ZONE_SETTING_KB912120\
HKEY_CURRENT_USER\Software\Policies\Microsoft\Internet Explorer\Control Panel\
HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main\FeatureControl\\FEATURE_AnchorsMarkedVisited_KB918965\
HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main\FeatureControl\\FEATURE_OPTIONS_BACKGROUNDCOLOR_KB843516\
HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main\FeatureControl\\FEATURE_DISPLAY_NODE_ADVISE_KB833311\
CLSID\{81397204-F51A-4571-8D7B-DC030521AABD}\
CLSID\{81397204-F51A-4571-8D7B-DC030521AABD}\\TreatAs\
\\CLSID\{81397204-F51A-4571-8D7B-DC030521AABD}\
\\CLSID\{81397204-F51A-4571-8D7B-DC030521AABD}\\InprocServer32\
\\CLSID\{81397204-F51A-4571-8D7B-DC030521AABD}\\InprocServerX86\
\\CLSID\{81397204-F51A-4571-8D7B-DC030521AABD}\\LocalServer32\
\\CLSID\{81397204-F51A-4571-8D7B-DC030521AABD}\\InprocHandler32\
\\CLSID\{81397204-F51A-4571-8D7B-DC030521AABD}\\InprocHandlerX86\
\\CLSID\{81397204-F51A-4571-8D7B-DC030521AABD}\\LocalServer\
HKEY_CLASSES_ROOT\CLSID\{81397204-F51A-4571-8D7B-DC030521AABD}\
HKEY_CLASSES_ROOT\CLSID\{81397204-F51A-4571-8D7B-DC030521AABD}\\TreatAs\
CLSID\{D1FE6762-FC48-11D0-883A-3C8B00C10000}\
CLSID\{D1FE6762-FC48-11D0-883A-3C8B00C10000}\\TreatAs\
\\CLSID\{D1FE6762-FC48-11D0-883A-3C8B00C10000}\
\\CLSID\{D1FE6762-FC48-11D0-883A-3C8B00C10000}\\InprocServer32\
\\CLSID\{D1FE6762-FC48-11D0-883A-3C8B00C10000}\\InprocServerX86\
\\CLSID\{D1FE6762-FC48-11D0-883A-3C8B00C10000}\\LocalServer32\
\\CLSID\{D1FE6762-FC48-11D0-883A-3C8B00C10000}\\InprocHandler32\
\\CLSID\{D1FE6762-FC48-11D0-883A-3C8B00C10000}\\InprocHandlerX86\
\\CLSID\{D1FE6762-FC48-11D0-883A-3C8B00C10000}\\LocalServer\
HKEY_CLASSES_ROOT\CLSID\{D1FE6762-FC48-11D0-883A-3C8B00C10000}\
HKEY_CLASSES_ROOT\CLSID\{D1FE6762-FC48-11D0-883A-3C8B00C10000}\\TreatAs\
HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Default Behaviors\
CLSID\{A7EE7F34-3BD1-427F-9231-F941E9B7E1FE}\
CLSID\{A7EE7F34-3BD1-427F-9231-F941E9B7E1FE}\\TreatAs\
\\CLSID\{A7EE7F34-3BD1-427F-9231-F941E9B7E1FE}\
\\CLSID\{A7EE7F34-3BD1-427F-9231-F941E9B7E1FE}\\InprocServer32\
\\CLSID\{A7EE7F34-3BD1-427F-9231-F941E9B7E1FE}\\InprocServerX86\
\\CLSID\{A7EE7F34-3BD1-427F-9231-F941E9B7E1FE}\\LocalServer32\
\\CLSID\{A7EE7F34-3BD1-427F-9231-F941E9B7E1FE}\\InprocHandler32\
\\CLSID\{A7EE7F34-3BD1-427F-9231-F941E9B7E1FE}\\InprocHandlerX86\
\\CLSID\{A7EE7F34-3BD1-427F-9231-F941E9B7E1FE}\\LocalServer\
HKEY_CLASSES_ROOT\CLSID\{A7EE7F34-3BD1-427F-9231-F941E9B7E1FE}\
HKEY_CLASSES_ROOT\CLSID\{A7EE7F34-3BD1-427F-9231-F941E9B7E1FE}\\TreatAs\
CLSID\{4FD2A832-86C8-11D0-8FCA-00C04FD9189D}\
CLSID\{4FD2A832-86C8-11D0-8FCA-00C04FD9189D}\\TreatAs\
\\CLSID\{4FD2A832-86C8-11D0-8FCA-00C04FD9189D}\
\\CLSID\{4FD2A832-86C8-11D0-8FCA-00C04FD9189D}\\InprocServer32\
\\CLSID\{4FD2A832-86C8-11D0-8FCA-00C04FD9189D}\\InprocServerX86\
\\CLSID\{4FD2A832-86C8-11D0-8FCA-00C04FD9189D}\\LocalServer32\
\\CLSID\{4FD2A832-86C8-11D0-8FCA-00C04FD9189D}\\InprocHandler32\
\\CLSID\{4FD2A832-86C8-11D0-8FCA-00C04FD9189D}\\InprocHandlerX86\
\\CLSID\{4FD2A832-86C8-11D0-8FCA-00C04FD9189D}\\LocalServer\
HKEY_CLASSES_ROOT\CLSID\{4FD2A832-86C8-11D0-8FCA-00C04FD9189D}\
HKEY_CLASSES_ROOT\CLSID\{4FD2A832-86C8-11D0-8FCA-00C04FD9189D}\\TreatAs\
HKEY_LOCAL_MACHINE\Software\Microsoft\DirectDraw\Compatibility\
HKEY_LOCAL_MACHINE\Software\Microsoft\DirectDraw\Compatibility\\Bug!\
HKEY_LOCAL_MACHINE\Software\Microsoft\DirectDraw\Compatibility\\DemolitionDerby2\
HKEY_LOCAL_MACHINE\Software\Microsoft\DirectDraw\Compatibility\\MortalKombat3\
HKEY_LOCAL_MACHINE\Software\Microsoft\DirectDraw\Compatibility\\MsGolf98\
HKEY_LOCAL_MACHINE\Software\Microsoft\DirectDraw\Compatibility\\NHLPowerPlay\
HKEY_LOCAL_MACHINE\Software\Microsoft\DirectDraw\Compatibility\\NortonSystemInfo\
HKEY_LOCAL_MACHINE\Software\Microsoft\DirectDraw\Compatibility\\Rogue Squadron\
HKEY_LOCAL_MACHINE\Software\Microsoft\DirectDraw\Compatibility\\Savage\
HKEY_LOCAL_MACHINE\Software\Microsoft\DirectDraw\Compatibility\\ScorchedPlanet\
HKEY_LOCAL_MACHINE\Software\Microsoft\DirectDraw\Compatibility\\SilentThunder\
HKEY_LOCAL_MACHINE\Software\Microsoft\DirectDraw\Compatibility\\Terracide\
HKEY_LOCAL_MACHINE\Software\Microsoft\DirectDraw\Compatibility\\ThirdDimension\
HKEY_LOCAL_MACHINE\Software\Microsoft\DirectDraw\Compatibility\\ZiffDavisQualityBenchmark\
HKEY_LOCAL_MACHINE\Software\Microsoft\DirectDraw\Compatibility\\ZiffDavisWinMarkBenchmark\
HKEY_LOCAL_MACHINE\Software\Microsoft\DirectDraw\GammaCalibrator\
HKEY_LOCAL_MACHINE\Software\Microsoft\DirectDraw\MostRecentApplication\
HKEY_LOCAL_MACHINE\Software\Microsoft\DirectDraw\
HKEY_LOCAL_MACHINE\Software\Microsoft\Direct3D\
HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main\FeatureControl\\FEATURE_UNLOCK_TRANFORMS_KB896688\
HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\ActiveX Compatibility\\{ADC6CB82-424C-11D2-952A-00C04FA34F05}\
CLSID\{ADC6CB82-424C-11D2-952A-00C04FA34F05}\
CLSID\{ADC6CB82-424C-11D2-952A-00C04FA34F05}\\TreatAs\
\\CLSID\{ADC6CB82-424C-11D2-952A-00C04FA34F05}\
\\CLSID\{ADC6CB82-424C-11D2-952A-00C04FA34F05}\\InprocServer32\
\\CLSID\{ADC6CB82-424C-11D2-952A-00C04FA34F05}\\InprocServerX86\
\\CLSID\{ADC6CB82-424C-11D2-952A-00C04FA34F05}\\LocalServer32\
\\CLSID\{ADC6CB82-424C-11D2-952A-00C04FA34F05}\\InprocHandler32\
\\CLSID\{ADC6CB82-424C-11D2-952A-00C04FA34F05}\\InprocHandlerX86\
\\CLSID\{ADC6CB82-424C-11D2-952A-00C04FA34F05}\\LocalServer\
HKEY_CLASSES_ROOT\CLSID\{ADC6CB82-424C-11D2-952A-00C04FA34F05}\
HKEY_CLASSES_ROOT\CLSID\{ADC6CB82-424C-11D2-952A-00C04FA34F05}\\TreatAs\
CLSID\{4CB26C03-FF93-11D0-817E-0000F87557DB}\
CLSID\{4CB26C03-FF93-11D0-817E-0000F87557DB}\\TreatAs\
\\CLSID\{4CB26C03-FF93-11D0-817E-0000F87557DB}\
\\CLSID\{4CB26C03-FF93-11D0-817E-0000F87557DB}\\InprocServer32\
\\CLSID\{4CB26C03-FF93-11D0-817E-0000F87557DB}\\InprocServerX86\
\\CLSID\{4CB26C03-FF93-11D0-817E-0000F87557DB}\\LocalServer32\
\\CLSID\{4CB26C03-FF93-11D0-817E-0000F87557DB}\\InprocHandler32\
\\CLSID\{4CB26C03-FF93-11D0-817E-0000F87557DB}\\InprocHandlerX86\
\\CLSID\{4CB26C03-FF93-11D0-817E-0000F87557DB}\\LocalServer\
HKEY_CLASSES_ROOT\CLSID\{4CB26C03-FF93-11D0-817E-0000F87557DB}\
HKEY_CLASSES_ROOT\CLSID\{4CB26C03-FF93-11D0-817E-0000F87557DB}\\TreatAs\
HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main\FeatureControl\\FEATURE_UNLOCK_FILTERS_KB896688\
HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\ActiveX Compatibility\\{385A91BC-1E8A-4E4A-A7A6-F4FC1E6CA1BD}\
CLSID\{385A91BC-1E8A-4E4A-A7A6-F4FC1E6CA1BD}\
CLSID\{385A91BC-1E8A-4E4A-A7A6-F4FC1E6CA1BD}\\TreatAs\
\\CLSID\{385A91BC-1E8A-4E4A-A7A6-F4FC1E6CA1BD}\
\\CLSID\{385A91BC-1E8A-4E4A-A7A6-F4FC1E6CA1BD}\\InprocServer32\
\\CLSID\{385A91BC-1E8A-4E4A-A7A6-F4FC1E6CA1BD}\\InprocServerX86\
\\CLSID\{385A91BC-1E8A-4E4A-A7A6-F4FC1E6CA1BD}\\LocalServer32\
\\CLSID\{385A91BC-1E8A-4E4A-A7A6-F4FC1E6CA1BD}\\InprocHandler32\
\\CLSID\{385A91BC-1E8A-4E4A-A7A6-F4FC1E6CA1BD}\\InprocHandlerX86\
\\CLSID\{385A91BC-1E8A-4E4A-A7A6-F4FC1E6CA1BD}\\LocalServer\
HKEY_CLASSES_ROOT\CLSID\{385A91BC-1E8A-4E4A-A7A6-F4FC1E6CA1BD}\
HKEY_CLASSES_ROOT\CLSID\{385A91BC-1E8A-4E4A-A7A6-F4FC1E6CA1BD}\\TreatAs\
HKEY_CLASSES_ROOT\TypeLib\\{5E77EB03-937C-11D1-B047-00AA003B6061}\
HKEY_CLASSES_ROOT\TypeLib\\{5E77EB03-937C-11D1-B047-00AA003B6061}\\1.1\
HKEY_CLASSES_ROOT\TypeLib\\{5E77EB03-937C-11D1-B047-00AA003B6061}\\1.1\\409\
HKEY_CLASSES_ROOT\TypeLib\\{5E77EB03-937C-11D1-B047-00AA003B6061}\\1.1\\9\
HKEY_CLASSES_ROOT\TypeLib\\{5E77EB03-937C-11D1-B047-00AA003B6061}\\1.1\\0\
HKEY_CLASSES_ROOT\TypeLib\\{5E77EB03-937C-11D1-B047-00AA003B6061}\\1.1\\0\\win32\
HKEY_CLASSES_ROOT\TypeLib\\{54314D1D-35FE-11D1-81A1-0000F87557DB}\
HKEY_CLASSES_ROOT\TypeLib\\{54314D1D-35FE-11D1-81A1-0000F87557DB}\\1.1\
HKEY_CLASSES_ROOT\TypeLib\\{54314D1D-35FE-11D1-81A1-0000F87557DB}\\1.1\\409\
HKEY_CLASSES_ROOT\TypeLib\\{54314D1D-35FE-11D1-81A1-0000F87557DB}\\1.1\\9\
HKEY_CLASSES_ROOT\TypeLib\\{54314D1D-35FE-11D1-81A1-0000F87557DB}\\1.1\\0\
HKEY_CLASSES_ROOT\TypeLib\\{54314D1D-35FE-11D1-81A1-0000F87557DB}\\1.1\\0\\win32\
CLSID\{30C3B080-30FB-11D0-B724-00AA006C1A01}\
CLSID\{30C3B080-30FB-11D0-B724-00AA006C1A01}\\TreatAs\
\\CLSID\{30C3B080-30FB-11D0-B724-00AA006C1A01}\
\\CLSID\{30C3B080-30FB-11D0-B724-00AA006C1A01}\\InprocServer32\
\\CLSID\{30C3B080-30FB-11D0-B724-00AA006C1A01}\\InprocServerX86\
\\CLSID\{30C3B080-30FB-11D0-B724-00AA006C1A01}\\LocalServer32\
\\CLSID\{30C3B080-30FB-11D0-B724-00AA006C1A01}\\InprocHandler32\
\\CLSID\{30C3B080-30FB-11D0-B724-00AA006C1A01}\\InprocHandlerX86\
\\CLSID\{30C3B080-30FB-11D0-B724-00AA006C1A01}\\LocalServer\
HKEY_CLASSES_ROOT\CLSID\{30C3B080-30FB-11D0-B724-00AA006C1A01}\
HKEY_CLASSES_ROOT\CLSID\{30C3B080-30FB-11D0-B724-00AA006C1A01}\\TreatAs\
CLSID\{6A01FDA0-30DF-11D0-B724-00AA006C1A01}\
CLSID\{6A01FDA0-30DF-11D0-B724-00AA006C1A01}\\TreatAs\
\\CLSID\{6A01FDA0-30DF-11D0-B724-00AA006C1A01}\
\\CLSID\{6A01FDA0-30DF-11D0-B724-00AA006C1A01}\\InprocServer32\
\\CLSID\{6A01FDA0-30DF-11D0-B724-00AA006C1A01}\\InprocServerX86\
\\CLSID\{6A01FDA0-30DF-11D0-B724-00AA006C1A01}\\LocalServer32\
\\CLSID\{6A01FDA0-30DF-11D0-B724-00AA006C1A01}\\InprocHandler32\
\\CLSID\{6A01FDA0-30DF-11D0-B724-00AA006C1A01}\\InprocHandlerX86\
\\CLSID\{6A01FDA0-30DF-11D0-B724-00AA006C1A01}\\LocalServer\
HKEY_CLASSES_ROOT\CLSID\{6A01FDA0-30DF-11D0-B724-00AA006C1A01}\
HKEY_CLASSES_ROOT\CLSID\{6A01FDA0-30DF-11D0-B724-00AA006C1A01}\\TreatAs\
HKEY_CLASSES_ROOT\MIME\Database\Content Type\
HKEY_CLASSES_ROOT\MIME\Database\Content Type\\application/atom+xml\
HKEY_CLASSES_ROOT\MIME\Database\Content Type\\application/atom+xml\\Bits\
HKEY_CLASSES_ROOT\MIME\Database\Content Type\\application/cdf\
HKEY_CLASSES_ROOT\MIME\Database\Content Type\\application/cdf\\Bits\
HKEY_CLASSES_ROOT\MIME\Database\Content Type\\application/fractals\
HKEY_CLASSES_ROOT\MIME\Database\Content Type\\application/fractals\\Bits\
HKEY_CLASSES_ROOT\MIME\Database\Content Type\\application/futuresplash\
HKEY_CLASSES_ROOT\MIME\Database\Content Type\\application/futuresplash\\Bits\
HKEY_CLASSES_ROOT\MIME\Database\Content Type\\application/hta\
HKEY_CLASSES_ROOT\MIME\Database\Content Type\\application/hta\\Bits\
HKEY_CLASSES_ROOT\MIME\Database\Content Type\\application/mac-binhex40\
HKEY_CLASSES_ROOT\MIME\Database\Content Type\\application/mac-binhex40\\Bits\
HKEY_CLASSES_ROOT\MIME\Database\Content Type\\application/ms-infopath.xml\
HKEY_CLASSES_ROOT\MIME\Database\Content Type\\application/ms-infopath.xml\\Bits\
HKEY_CLASSES_ROOT\MIME\Database\Content Type\\application/msaccess\
HKEY_CLASSES_ROOT\MIME\Database\Content Type\\application/msaccess\\Bits\
HKEY_CLASSES_ROOT\MIME\Database\Content Type\\application/msonenote\
HKEY_CLASSES_ROOT\MIME\Database\Content Type\\application/msonenote\\Bits\
HKEY_CLASSES_ROOT\MIME\Database\Content Type\\application/msword\
HKEY_CLASSES_ROOT\MIME\Database\Content Type\\application/msword\\Bits\
HKEY_CLASSES_ROOT\MIME\Database\Content Type\\application/pdf\
HKEY_CLASSES_ROOT\MIME\Database\Content Type\\application/pdf\\Bits\
HKEY_CLASSES_ROOT\MIME\Database\Content Type\\application/pkcs10\
HKEY_CLASSES_ROOT\MIME\Database\Content Type\\application/pkcs10\\Bits\
HKEY_CLASSES_ROOT\MIME\Database\Content Type\\application/pkcs7-mime\
HKEY_CLASSES_ROOT\MIME\Database\Content Type\\application/pkcs7-mime\\Bits\
HKEY_CLASSES_ROOT\MIME\Database\Content Type\\application/pkcs7-signature\
HKEY_CLASSES_ROOT\MIME\Database\Content Type\\application/pkcs7-signature\\Bits\
HKEY_CLASSES_ROOT\MIME\Database\Content Type\\application/pkix-cert\
HKEY_CLASSES_ROOT\MIME\Database\Content Type\\application/pkix-cert\\Bits\
HKEY_CLASSES_ROOT\MIME\Database\Content Type\\application/pkix-crl\
HKEY_CLASSES_ROOT\MIME\Database\Content Type\\application/pkix-crl\\Bits\
HKEY_CLASSES_ROOT\MIME\Database\Content Type\\application/postscript\
HKEY_CLASSES_ROOT\MIME\Database\Content Type\\application/postscript\\Bits\
HKEY_CLASSES_ROOT\MIME\Database\Content Type\\application/set-payment-initiation\
HKEY_CLASSES_ROOT\MIME\Database\Content Type\\application/set-payment-initiation\\Bits\
HKEY_CLASSES_ROOT\MIME\Database\Content Type\\application/set-registration-initiation\
HKEY_CLASSES_ROOT\MIME\Database\Content Type\\application/set-registration-initiation\\Bits\
HKEY_CLASSES_ROOT\MIME\Database\Content Type\\application/vnd.adobe.acrobat-security-settings\
HKEY_CLASSES_ROOT\MIME\Database\Content Type\\application/vnd.adobe.acrobat-security-settings\\Bits\
HKEY_CLASSES_ROOT\MIME\Database\Content Type\\application/vnd.adobe.pdfxml\
HKEY_CLASSES_ROOT\MIME\Database\Content Type\\application/vnd.adobe.pdfxml\\Bits\
HKEY_CLASSES_ROOT\MIME\Database\Content Type\\application/vnd.adobe.pdx\
HKEY_CLASSES_ROOT\MIME\Database\Content Type\\application/vnd.adobe.pdx\\Bits\
HKEY_CLASSES_ROOT\MIME\Database\Content Type\\application/vnd.adobe.xdp+xml\
HKEY_CLASSES_ROOT\MIME\Database\Content Type\\application/vnd.adobe.xdp+xml\\Bits\
HKEY_CLASSES_ROOT\MIME\Database\Content Type\\application/vnd.adobe.xfd+xml\
HKEY_CLASSES_ROOT\MIME\Database\Content Type\\application/vnd.adobe.xfd+xml\\Bits\
HKEY_CLASSES_ROOT\MIME\Database\Content Type\\application/vnd.adobe.xfdf\
HKEY_CLASSES_ROOT\MIME\Database\Content Type\\application/vnd.adobe.xfdf\\Bits\
HKEY_CLASSES_ROOT\MIME\Database\Content Type\\application/vnd.fdf\
HKEY_CLASSES_ROOT\MIME\Database\Content Type\\application/vnd.fdf\\Bits\
HKEY_CLASSES_ROOT\MIME\Database\Content Type\\application/vnd.groove-injector\
HKEY_CLASSES_ROOT\MIME\Database\Content Type\\application/vnd.groove-injector\\Bits\
HKEY_CLASSES_ROOT\MIME\Database\Content Type\\application/vnd.groove-space-archive\
HKEY_CLASSES_ROOT\MIME\Database\Content Type\\application/vnd.groove-space-archive\\Bits\
HKEY_CLASSES_ROOT\MIME\Database\Content Type\\application/vnd.groove-tool-archive\
HKEY_CLASSES_ROOT\MIME\Database\Content Type\\application/vnd.groove-tool-archive\\Bits\
HKEY_CLASSES_ROOT\MIME\Database\Content Type\\application/vnd.groove-vcard\
HKEY_CLASSES_ROOT\MIME\Database\Content Type\\application/vnd.groove-vcard\\Bits\
HKEY_CLASSES_ROOT\MIME\Database\Content Type\\application/vnd.ms-excel\
HKEY_CLASSES_ROOT\MIME\Database\Content Type\\application/vnd.ms-excel\\Bits\
HKEY_CLASSES_ROOT\MIME\Database\Content Type\\application/vnd.ms-excel.addin.macroEnabled.12\
HKEY_CLASSES_ROOT\MIME\Database\Content Type\\application/vnd.ms-excel.addin.macroEnabled.12\\Bits\
HKEY_CLASSES_ROOT\MIME\Database\Content Type\\application/vnd.ms-excel.sheet.binary.macroEnabled.12\
HKEY_CLASSES_ROOT\MIME\Database\Content Type\\application/vnd.ms-excel.sheet.binary.macroEnabled.12\\Bits\
HKEY_CLASSES_ROOT\MIME\Database\Content Type\\application/vnd.ms-excel.sheet.macroEnabled.12\
HKEY_CLASSES_ROOT\MIME\Database\Content Type\\application/vnd.ms-excel.sheet.macroEnabled.12\\Bits\
HKEY_CLASSES_ROOT\MIME\Database\Content Type\\application/vnd.ms-excel.template.macroEnabled.12\
HKEY_CLASSES_ROOT\MIME\Database\Content Type\\application/vnd.ms-excel.template.macroEnabled.12\\Bits\
HKEY_CLASSES_ROOT\MIME\Database\Content Type\\application/vnd.ms-mediapackage\
HKEY_CLASSES_ROOT\MIME\Database\Content Type\\application/vnd.ms-mediapackage\\Bits\
HKEY_CLASSES_ROOT\MIME\Database\Content Type\\application/vnd.ms-officetheme\
HKEY_CLASSES_ROOT\MIME\Database\Content Type\\application/vnd.ms-officetheme\\Bits\
HKEY_CLASSES_ROOT\MIME\Database\Content Type\\application/vnd.ms-package.relationships+xml\
HKEY_CLASSES_ROOT\MIME\Database\Content Type\\application/vnd.ms-package.relationships+xml\\Bits\
HKEY_CLASSES_ROOT\MIME\Database\Content Type\\application/vnd.ms-pki.certstore\
HKEY_CLASSES_ROOT\MIME\Database\Content Type\\application/vnd.ms-pki.certstore\\Bits\
HKEY_CLASSES_ROOT\MIME\Database\Content Type\\application/vnd.ms-pki.pko\
HKEY_CLASSES_ROOT\MIME\Database\Content Type\\application/vnd.ms-pki.pko\\Bits\
HKEY_CLASSES_ROOT\MIME\Database\Content Type\\application/vnd.ms-pki.seccat\
HKEY_CLASSES_ROOT\MIME\Database\Content Type\\application/vnd.ms-pki.seccat\\Bits\
HKEY_CLASSES_ROOT\MIME\Database\Content Type\\application/vnd.ms-pki.stl\
HKEY_CLASSES_ROOT\MIME\Database\Content Type\\application/vnd.ms-pki.stl\\Bits\
HKEY_CLASSES_ROOT\MIME\Database\Content Type\\application/vnd.ms-powerpoint\
HKEY_CLASSES_ROOT\MIME\Database\Content Type\\application/vnd.ms-powerpoint\\Bits\
HKEY_CLASSES_ROOT\MIME\Database\Content Type\\application/vnd.ms-powerpoint.addin.macroEnabled.12\
HKEY_CLASSES_ROOT\MIME\Database\Content Type\\application/vnd.ms-powerpoint.addin.macroEnabled.12\\Bits\
HKEY_CLASSES_ROOT\MIME\Database\Content Type\\application/vnd.ms-powerpoint.presentation.macroEnabled.12\
HKEY_CLASSES_ROOT\MIME\Database\Content Type\\application/vnd.ms-powerpoint.presentation.macroEnabled.12\\Bits\
HKEY_CLASSES_ROOT\MIME\Database\Content Type\\application/vnd.ms-powerpoint.slide.macroEnabled.12\
HKEY_CLASSES_ROOT\MIME\Database\Content Type\\application/vnd.ms-powerpoint.slide.macroEnabled.12\\Bits\
HKEY_CLASSES_ROOT\MIME\Database\Content Type\\application/vnd.ms-powerpoint.slideshow.macroEnabled.12\
HKEY_CLASSES_ROOT\MIME\Database\Content Type\\application/vnd.ms-powerpoint.slideshow.macroEnabled.12\\Bits\
HKEY_CLASSES_ROOT\MIME\Database\Content Type\\application/vnd.ms-powerpoint.template.macroEnabled.12\
HKEY_CLASSES_ROOT\MIME\Database\Content Type\\application/vnd.ms-powerpoint.template.macroEnabled.12\\Bits\
HKEY_CLASSES_ROOT\MIME\Database\Content Type\\application/vnd.ms-publisher\
HKEY_CLASSES_ROOT\MIME\Database\Content Type\\application/vnd.ms-publisher\\Bits\
HKEY_CLASSES_ROOT\MIME\Database\Content Type\\application/vnd.ms-visio.viewer\
HKEY_CLASSES_ROOT\MIME\Database\Content Type\\application/vnd.ms-visio.viewer\\Bits\
HKEY_CLASSES_ROOT\MIME\Database\Content Type\\application/vnd.ms-word.document.macroEnabled.12\
HKEY_CLASSES_ROOT\MIME\Database\Content Type\\application/vnd.ms-word.document.macroEnabled.12\\Bits\
HKEY_CLASSES_ROOT\MIME\Database\Content Type\\application/vnd.ms-word.template.macroEnabled.12\
HKEY_CLASSES_ROOT\MIME\Database\Content Type\\application/vnd.ms-word.template.macroEnabled.12\\Bits\
HKEY_CLASSES_ROOT\MIME\Database\Content Type\\application/vnd.ms-wpl\
HKEY_CLASSES_ROOT\MIME\Database\Content Type\\application/vnd.ms-wpl\\Bits\
HKEY_CLASSES_ROOT\MIME\Database\Content Type\\application/vnd.openxmlformats-officedocument.presentationml.presentation\
HKEY_CLASSES_ROOT\MIME\Database\Content Type\\application/vnd.openxmlformats-officedocument.presentationml.presentation\\Bits\
HKEY_CLASSES_ROOT\MIME\Database\Content Type\\application/vnd.openxmlformats-officedocument.presentationml.slide\
HKEY_CLASSES_ROOT\MIME\Database\Content Type\\application/vnd.openxmlformats-officedocument.presentationml.slide\\Bits\
HKEY_CLASSES_ROOT\MIME\Database\Content Type\\application/vnd.openxmlformats-officedocument.presentationml.slideshow\
HKEY_CLASSES_ROOT\MIME\Database\Content Type\\application/vnd.openxmlformats-officedocument.presentationml.slideshow\\Bits\
HKEY_CLASSES_ROOT\MIME\Database\Content Type\\application/vnd.openxmlformats-officedocument.presentationml.template\
HKEY_CLASSES_ROOT\MIME\Database\Content Type\\application/vnd.openxmlformats-officedocument.presentationml.template\\Bits\
HKEY_CLASSES_ROOT\MIME\Database\Content Type\\application/vnd.openxmlformats-officedocument.spreadsheetml.sheet\
HKEY_CLASSES_ROOT\MIME\Database\Content Type\\application/vnd.openxmlformats-officedocument.spreadsheetml.sheet\\Bits\
HKEY_CLASSES_ROOT\MIME\Database\Content Type\\application/vnd.openxmlformats-officedocument.spreadsheetml.template\
HKEY_CLASSES_ROOT\MIME\Database\Content Type\\application/vnd.openxmlformats-officedocument.spreadsheetml.template\\Bits\
HKEY_CLASSES_ROOT\MIME\Database\Content Type\\application/vnd.openxmlformats-officedocument.wordprocessingml.document\
HKEY_CLASSES_ROOT\MIME\Database\Content Type\\application/vnd.openxmlformats-officedocument.wordprocessingml.document\\Bits\
HKEY_CLASSES_ROOT\MIME\Database\Content Type\\application/vnd.openxmlformats-officedocument.wordprocessingml.template\
HKEY_CLASSES_ROOT\MIME\Database\Content Type\\application/vnd.openxmlformats-officedocument.wordprocessingml.template\\Bits\
HKEY_CLASSES_ROOT\MIME\Database\Content Type\\application/x-cdf\
HKEY_CLASSES_ROOT\MIME\Database\Content Type\\application/x-cdf\\Bits\
HKEY_CLASSES_ROOT\MIME\Database\Content Type\\application/x-compress\
HKEY_CLASSES_ROOT\MIME\Database\Content Type\\application/x-compress\\Bits\
HKEY_CLASSES_ROOT\MIME\Database\Content Type\\application/x-compressed\
HKEY_CLASSES_ROOT\MIME\Database\Content Type\\application/x-compressed\\Bits\
HKEY_CLASSES_ROOT\MIME\Database\Content Type\\application/x-gzip\
HKEY_CLASSES_ROOT\MIME\Database\Content Type\\application/x-gzip\\Bits\
HKEY_CLASSES_ROOT\MIME\Database\Content Type\\application/x-informationCard\
HKEY_CLASSES_ROOT\MIME\Database\Content Type\\application/x-informationCard\\Bits\
HKEY_CLASSES_ROOT\MIME\Database\Content Type\\application/x-internet-signup\
HKEY_CLASSES_ROOT\MIME\Database\Content Type\\application/x-internet-signup\\Bits\
HKEY_CLASSES_ROOT\MIME\Database\Content Type\\application/x-iphone\
HKEY_CLASSES_ROOT\MIME\Database\Content Type\\application/x-iphone\\Bits\
HKEY_CLASSES_ROOT\MIME\Database\Content Type\\application/x-java-applet\
HKEY_CLASSES_ROOT\MIME\Database\Content Type\\application/x-java-applet\\Bits\
HKEY_CLASSES_ROOT\MIME\Database\Content Type\\application/x-java-jnlp-file\
HKEY_CLASSES_ROOT\MIME\Database\Content Type\\application/x-java-jnlp-file\\Bits\
HKEY_CLASSES_ROOT\MIME\Database\Content Type\\application/x-latex\
HKEY_CLASSES_ROOT\MIME\Database\Content Type\\application/x-latex\\Bits\
HKEY_CLASSES_ROOT\MIME\Database\Content Type\\application/x-mix-transfer\
HKEY_CLASSES_ROOT\MIME\Database\Content Type\\application/x-mix-transfer\\Bits\
HKEY_CLASSES_ROOT\MIME\Database\Content Type\\application/x-mplayer2\
HKEY_CLASSES_ROOT\MIME\Database\Content Type\\application/x-mplayer2\\Bits\
HKEY_CLASSES_ROOT\MIME\Database\Content Type\\application/x-ms-wmd\
HKEY_CLASSES_ROOT\MIME\Database\Content Type\\application/x-ms-wmd\\Bits\
HKEY_CLASSES_ROOT\MIME\Database\Content Type\\application/x-ms-wmz\
HKEY_CLASSES_ROOT\MIME\Database\Content Type\\application/x-ms-wmz\\Bits\
HKEY_CLASSES_ROOT\MIME\Database\Content Type\\application/x-msexcel\
HKEY_CLASSES_ROOT\MIME\Database\Content Type\\application/x-msexcel\\Bits\
HKEY_CLASSES_ROOT\MIME\Database\Content Type\\application/x-mspowerpoint\
HKEY_CLASSES_ROOT\MIME\Database\Content Type\\application/x-mspowerpoint\\Bits\
HKEY_CLASSES_ROOT\MIME\Database\Content Type\\application/x-mspowerpoint.12\
HKEY_CLASSES_ROOT\MIME\Database\Content Type\\application/x-mspowerpoint.12\\Bits\
HKEY_CLASSES_ROOT\MIME\Database\Content Type\\application/x-mspowerpoint.macroEnabled.12\
HKEY_CLASSES_ROOT\MIME\Database\Content Type\\application/x-mspowerpoint.macroEnabled.12\\Bits\
HKEY_CLASSES_ROOT\MIME\Database\Content Type\\application/x-pkcs12\
HKEY_CLASSES_ROOT\MIME\Database\Content Type\\application/x-pkcs12\\Bits\
HKEY_CLASSES_ROOT\MIME\Database\Content Type\\application/x-pkcs7-certificates\
HKEY_CLASSES_ROOT\MIME\Database\Content Type\\application/x-pkcs7-certificates\\Bits\
HKEY_CLASSES_ROOT\MIME\Database\Content Type\\application/x-pkcs7-certreqresp\
HKEY_CLASSES_ROOT\MIME\Database\Content Type\\application/x-pkcs7-certreqresp\\Bits\
HKEY_CLASSES_ROOT\MIME\Database\Content Type\\application/x-shockwave-flash\
HKEY_CLASSES_ROOT\MIME\Database\Content Type\\application/x-shockwave-flash\\Bits\
HKEY_CLASSES_ROOT\MIME\Database\Content Type\\application/x-stuffit\
HKEY_CLASSES_ROOT\MIME\Database\Content Type\\application/x-stuffit\\Bits\
HKEY_CLASSES_ROOT\MIME\Database\Content Type\\application/x-tar\
HKEY_CLASSES_ROOT\MIME\Database\Content Type\\application/x-tar\\Bits\
HKEY_CLASSES_ROOT\MIME\Database\Content Type\\application/x-troff-man\
HKEY_CLASSES_ROOT\MIME\Database\Content Type\\application/x-troff-man\\Bits\
HKEY_CLASSES_ROOT\MIME\Database\Content Type\\application/x-x509-ca-cert\
HKEY_CLASSES_ROOT\MIME\Database\Content Type\\application/x-x509-ca-cert\\Bits\
HKEY_CLASSES_ROOT\MIME\Database\Content Type\\application/x-zip-compressed\
HKEY_CLASSES_ROOT\MIME\Database\Content Type\\application/x-zip-compressed\\Bits\
HKEY_CLASSES_ROOT\MIME\Database\Content Type\\application/xml\
HKEY_CLASSES_ROOT\MIME\Database\Content Type\\application/xml\\Bits\
HKEY_CLASSES_ROOT\MIME\Database\Content Type\\audio/aiff\
HKEY_CLASSES_ROOT\MIME\Database\Content Type\\audio/aiff\\Bits\
HKEY_CLASSES_ROOT\MIME\Database\Content Type\\audio/basic\
HKEY_CLASSES_ROOT\MIME\Database\Content Type\\audio/basic\\Bits\
HKEY_CLASSES_ROOT\MIME\Database\Content Type\\audio/mid\
HKEY_CLASSES_ROOT\MIME\Database\Content Type\\audio/mid\\Bits\
HKEY_CLASSES_ROOT\MIME\Database\Content Type\\audio/midi\
HKEY_CLASSES_ROOT\MIME\Database\Content Type\\audio/midi\\Bits\
HKEY_CLASSES_ROOT\MIME\Database\Content Type\\audio/mp3\
HKEY_CLASSES_ROOT\MIME\Database\Content Type\\audio/mp3\\Bits\
HKEY_CLASSES_ROOT\MIME\Database\Content Type\\audio/mpeg\
HKEY_CLASSES_ROOT\MIME\Database\Content Type\\audio/mpeg\\Bits\
HKEY_CLASSES_ROOT\MIME\Database\Content Type\\audio/mpegurl\
HKEY_CLASSES_ROOT\MIME\Database\Content Type\\audio/mpegurl\\Bits\
HKEY_CLASSES_ROOT\MIME\Database\Content Type\\audio/mpg\
HKEY_CLASSES_ROOT\MIME\Database\Content Type\\audio/mpg\\Bits\
HKEY_CLASSES_ROOT\MIME\Database\Content Type\\audio/wav\
HKEY_CLASSES_ROOT\MIME\Database\Content Type\\audio/wav\\Bits\
HKEY_CLASSES_ROOT\MIME\Database\Content Type\\audio/x-aiff\
HKEY_CLASSES_ROOT\MIME\Database\Content Type\\audio/x-aiff\\Bits\
HKEY_CLASSES_ROOT\MIME\Database\Content Type\\audio/x-background\
HKEY_CLASSES_ROOT\MIME\Database\Content Type\\audio/x-background\\Bits\
HKEY_CLASSES_ROOT\MIME\Database\Content Type\\audio/x-mid\
HKEY_CLASSES_ROOT\MIME\Database\Content Type\\audio/x-mid\\Bits\
HKEY_CLASSES_ROOT\MIME\Database\Content Type\\audio/x-midi\
HKEY_CLASSES_ROOT\MIME\Database\Content Type\\audio/x-midi\\Bits\
HKEY_CLASSES_ROOT\MIME\Database\Content Type\\audio/x-mp3\
HKEY_CLASSES_ROOT\MIME\Database\Content Type\\audio/x-mp3\\Bits\
HKEY_CLASSES_ROOT\MIME\Database\Content Type\\audio/x-mpeg\
HKEY_CLASSES_ROOT\MIME\Database\Content Type\\audio/x-mpeg\\Bits\
HKEY_CLASSES_ROOT\MIME\Database\Content Type\\audio/x-mpegurl\
HKEY_CLASSES_ROOT\MIME\Database\Content Type\\audio/x-mpegurl\\Bits\
HKEY_CLASSES_ROOT\MIME\Database\Content Type\\audio/x-mpg\
HKEY_CLASSES_ROOT\MIME\Database\Content Type\\audio/x-mpg\\Bits\
HKEY_CLASSES_ROOT\MIME\Database\Content Type\\audio/x-ms-wax\
HKEY_CLASSES_ROOT\MIME\Database\Content Type\\audio/x-ms-wax\\Bits\
HKEY_CLASSES_ROOT\MIME\Database\Content Type\\audio/x-ms-wma\
HKEY_CLASSES_ROOT\MIME\Database\Content Type\\audio/x-ms-wma\\Bits\
HKEY_CLASSES_ROOT\MIME\Database\Content Type\\audio/x-wav\
HKEY_CLASSES_ROOT\MIME\Database\Content Type\\audio/x-wav\\Bits\
HKEY_CLASSES_ROOT\MIME\Database\Content Type\\image/bmp\
HKEY_CLASSES_ROOT\MIME\Database\Content Type\\image/bmp\\Bits\
HKEY_CLASSES_ROOT\MIME\Database\Content Type\\image/gif\
HKEY_CLASSES_ROOT\MIME\Database\Content Type\\image/gif\\Bits\
HKEY_CLASSES_ROOT\MIME\Database\Content Type\\image/jpeg\
HKEY_CLASSES_ROOT\MIME\Database\Content Type\\image/jpeg\\Bits\
HKEY_CLASSES_ROOT\MIME\Database\Content Type\\image/pjpeg\
HKEY_CLASSES_ROOT\MIME\Database\Content Type\\image/pjpeg\\Bits\
HKEY_CLASSES_ROOT\MIME\Database\Content Type\\image/png\
HKEY_CLASSES_ROOT\MIME\Database\Content Type\\image/png\\Bits\
HKEY_CLASSES_ROOT\MIME\Database\Content Type\\image/tiff\
HKEY_CLASSES_ROOT\MIME\Database\Content Type\\image/tiff\\Bits\
HKEY_CLASSES_ROOT\MIME\Database\Content Type\\image/x-icon\
HKEY_CLASSES_ROOT\MIME\Database\Content Type\\image/x-icon\\Bits\
HKEY_CLASSES_ROOT\MIME\Database\Content Type\\image/x-jg\
HKEY_CLASSES_ROOT\MIME\Database\Content Type\\image/x-jg\\Bits\
HKEY_CLASSES_ROOT\MIME\Database\Content Type\\image/x-png\
HKEY_CLASSES_ROOT\MIME\Database\Content Type\\image/x-png\\Bits\
HKEY_CLASSES_ROOT\MIME\Database\Content Type\\image/x-wmf\
HKEY_CLASSES_ROOT\MIME\Database\Content Type\\image/x-wmf\\Bits\
HKEY_CLASSES_ROOT\MIME\Database\Content Type\\image/x-xbitmap\
HKEY_CLASSES_ROOT\MIME\Database\Content Type\\image/x-xbitmap\\Bits\
HKEY_CLASSES_ROOT\MIME\Database\Content Type\\image/xbm\
HKEY_CLASSES_ROOT\MIME\Database\Content Type\\image/xbm\\Bits\
HKEY_CLASSES_ROOT\MIME\Database\Content Type\\message/rfc822\
HKEY_CLASSES_ROOT\MIME\Database\Content Type\\message/rfc822\\Bits\
HKEY_CLASSES_ROOT\MIME\Database\Content Type\\midi/mid\
HKEY_CLASSES_ROOT\MIME\Database\Content Type\\midi/mid\\Bits\
HKEY_CLASSES_ROOT\MIME\Database\Content Type\\text/calendar\
HKEY_CLASSES_ROOT\MIME\Database\Content Type\\text/calendar\\Bits\
HKEY_CLASSES_ROOT\MIME\Database\Content Type\\text/css\
HKEY_CLASSES_ROOT\MIME\Database\Content Type\\text/css\\Bits\
HKEY_CLASSES_ROOT\MIME\Database\Content Type\\text/h323\
HKEY_CLASSES_ROOT\MIME\Database\Content Type\\text/h323\\Bits\
HKEY_CLASSES_ROOT\MIME\Database\Content Type\\text/html\
HKEY_CLASSES_ROOT\MIME\Database\Content Type\\text/html\\Bits\
HKEY_CLASSES_ROOT\MIME\Database\Content Type\\text/iuls\
HKEY_CLASSES_ROOT\MIME\Database\Content Type\\text/iuls\\Bits\
HKEY_CLASSES_ROOT\MIME\Database\Content Type\\text/plain\
HKEY_CLASSES_ROOT\MIME\Database\Content Type\\text/plain\\Bits\
HKEY_CLASSES_ROOT\MIME\Database\Content Type\\text/scriptlet\
HKEY_CLASSES_ROOT\MIME\Database\Content Type\\text/scriptlet\\Bits\
HKEY_CLASSES_ROOT\MIME\Database\Content Type\\text/webviewhtml\
HKEY_CLASSES_ROOT\MIME\Database\Content Type\\text/webviewhtml\\Bits\
HKEY_CLASSES_ROOT\MIME\Database\Content Type\\text/x-component\
HKEY_CLASSES_ROOT\MIME\Database\Content Type\\text/x-component\\Bits\
HKEY_CLASSES_ROOT\MIME\Database\Content Type\\text/x-ms-iqy\
HKEY_CLASSES_ROOT\MIME\Database\Content Type\\text/x-ms-iqy\\Bits\
HKEY_CLASSES_ROOT\MIME\Database\Content Type\\text/x-ms-odc\
HKEY_CLASSES_ROOT\MIME\Database\Content Type\\text/x-ms-odc\\Bits\
HKEY_CLASSES_ROOT\MIME\Database\Content Type\\text/x-ms-rqy\
HKEY_CLASSES_ROOT\MIME\Database\Content Type\\text/x-ms-rqy\\Bits\
HKEY_CLASSES_ROOT\MIME\Database\Content Type\\text/x-scriptlet\
HKEY_CLASSES_ROOT\MIME\Database\Content Type\\text/x-scriptlet\\Bits\
HKEY_CLASSES_ROOT\MIME\Database\Content Type\\text/x-vcard\
HKEY_CLASSES_ROOT\MIME\Database\Content Type\\text/x-vcard\\Bits\
HKEY_CLASSES_ROOT\MIME\Database\Content Type\\text/xml\
HKEY_CLASSES_ROOT\MIME\Database\Content Type\\text/xml\\Bits\
HKEY_CLASSES_ROOT\MIME\Database\Content Type\\video/avi\
HKEY_CLASSES_ROOT\MIME\Database\Content Type\\video/avi\\Bits\
HKEY_CLASSES_ROOT\MIME\Database\Content Type\\video/mpeg\
HKEY_CLASSES_ROOT\MIME\Database\Content Type\\video/mpeg\\Bits\
HKEY_CLASSES_ROOT\MIME\Database\Content Type\\video/mpg\
HKEY_CLASSES_ROOT\MIME\Database\Content Type\\video/mpg\\Bits\
HKEY_CLASSES_ROOT\MIME\Database\Content Type\\video/msvideo\
HKEY_CLASSES_ROOT\MIME\Database\Content Type\\video/msvideo\\Bits\
HKEY_CLASSES_ROOT\MIME\Database\Content Type\\video/x-mpeg\
HKEY_CLASSES_ROOT\MIME\Database\Content Type\\video/x-mpeg\\Bits\
HKEY_CLASSES_ROOT\MIME\Database\Content Type\\video/x-mpeg2a\
HKEY_CLASSES_ROOT\MIME\Database\Content Type\\video/x-mpeg2a\\Bits\
HKEY_CLASSES_ROOT\MIME\Database\Content Type\\video/x-ms-asf\
HKEY_CLASSES_ROOT\MIME\Database\Content Type\\video/x-ms-asf\\Bits\
HKEY_CLASSES_ROOT\MIME\Database\Content Type\\video/x-ms-asf-plugin\
HKEY_CLASSES_ROOT\MIME\Database\Content Type\\video/x-ms-asf-plugin\\Bits\
HKEY_CLASSES_ROOT\MIME\Database\Content Type\\video/x-ms-wm\
HKEY_CLASSES_ROOT\MIME\Database\Content Type\\video/x-ms-wm\\Bits\
HKEY_CLASSES_ROOT\MIME\Database\Content Type\\video/x-ms-wmv\
HKEY_CLASSES_ROOT\MIME\Database\Content Type\\video/x-ms-wmv\\Bits\
HKEY_CLASSES_ROOT\MIME\Database\Content Type\\video/x-ms-wmx\
HKEY_CLASSES_ROOT\MIME\Database\Content Type\\video/x-ms-wmx\\Bits\
HKEY_CLASSES_ROOT\MIME\Database\Content Type\\video/x-ms-wvx\
HKEY_CLASSES_ROOT\MIME\Database\Content Type\\video/x-ms-wvx\\Bits\
HKEY_CLASSES_ROOT\MIME\Database\Content Type\\video/x-msvideo\
HKEY_CLASSES_ROOT\MIME\Database\Content Type\\video/x-msvideo\\Bits\
CLSID\{A3CCEDF7-2DE2-11D0-86F4-00A0C913F750}\
CLSID\{A3CCEDF7-2DE2-11D0-86F4-00A0C913F750}\\TreatAs\
\\CLSID\{A3CCEDF7-2DE2-11D0-86F4-00A0C913F750}\
\\CLSID\{A3CCEDF7-2DE2-11D0-86F4-00A0C913F750}\\InprocServer32\
\\CLSID\{A3CCEDF7-2DE2-11D0-86F4-00A0C913F750}\\InprocServerX86\
\\CLSID\{A3CCEDF7-2DE2-11D0-86F4-00A0C913F750}\\LocalServer32\
\\CLSID\{A3CCEDF7-2DE2-11D0-86F4-00A0C913F750}\\InprocHandler32\
\\CLSID\{A3CCEDF7-2DE2-11D0-86F4-00A0C913F750}\\InprocHandlerX86\
\\CLSID\{A3CCEDF7-2DE2-11D0-86F4-00A0C913F750}\\LocalServer\
HKEY_CLASSES_ROOT\CLSID\{A3CCEDF7-2DE2-11D0-86F4-00A0C913F750}\
HKEY_CLASSES_ROOT\CLSID\{A3CCEDF7-2DE2-11D0-86F4-00A0C913F750}\\TreatAs\
HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main\FeatureControl\\FEATURE_COMPLETE_PROGRESSBAR_ONFLASH_925973\
HKEY_CLASSES_ROOT\TypeLib\\{83829839-609D-4F6E-8C12-6D4AA7127A57}\\1.0\\409\
HKEY_CLASSES_ROOT\TypeLib\\{83829839-609D-4F6E-8C12-6D4AA7127A57}\\1.0\\9\
HKEY_CLASSES_ROOT\Updater.AmiUpd\
C:\Registry\MACHINE\System\CurrentControlSet\Control\Session Manager\
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellCompatibility\Objects\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\
HKEY_CLASSES_ROOT\CLSID\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\InProcServer32\
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\CPC\Volume\
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\CPC\Volume\\{475c7950-e3d2-11e0-8d7a-806d6172696f}\\
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\CPC\Volume\\{475c7952-e3d2-11e0-8d7a-806d6172696f}\\
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{475c7952-e3d2-11e0-8d7a-806d6172696f}\\
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{475c7950-e3d2-11e0-8d7a-806d6172696f}\\
HKEY_CLASSES_ROOT\Drive\shellex\FolderExtensions\
HKEY_CLASSES_ROOT\Drive\shellex\FolderExtensions\{fbeb8a05-beee-4442-804e-409d6c4515e9}\
HKEY_CLASSES_ROOT\Directory\
HKEY_CLASSES_ROOT\Directory\\CurVer\
HKEY_CLASSES_ROOT\Directory\\
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\\
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\System\
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\\Advanced\
HKEY_CLASSES_ROOT\Directory\\\ShellEx\IconHandler\
HKEY_CLASSES_ROOT\Directory\\\Clsid\
HKEY_CLASSES_ROOT\Folder\
HKEY_CLASSES_ROOT\Folder\\Clsid\
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\\FileExts\
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\\FileExts\\.exe\
HKEY_CLASSES_ROOT\.exe\
HKEY_CLASSES_ROOT\exefile\
HKEY_CLASSES_ROOT\exefile\\CurVer\
HKEY_CLASSES_ROOT\exefile\\
HKEY_CLASSES_ROOT\exefile\\\ShellEx\IconHandler\
HKEY_CLASSES_ROOT\SystemFileAssociations\.exe\
HKEY_CLASSES_ROOT\SystemFileAssociations\application\
HKEY_CLASSES_ROOT\exefile\\\Clsid\
HKEY_CLASSES_ROOT\*\
HKEY_CLASSES_ROOT\*\\Clsid\
HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\ProductOptions\
HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\LanmanServer\DefaultSecurity\
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{4AA46D49-459F-4358-B4D1-169048547C23}\
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{889DF117-14D1-44EE-9F31-C5FB5D47F68B}\
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{C4ED781C-7394-4906-AAFF-D6AB64FF7C38}\
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Surftastic\
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{C4ED781C-7394-4906-AAFF-D6AB64FF7C38}\
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\App Paths\Mobogenie.exe\
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\MobogenieAdd\dayAdd\
HKEY_CURRENT_USER\Software\Flowsurf\
HKEY_LOCAL_MACHINE\Software\awesomehpSoftware\awesomehphp\
HKEY_LOCAL_MACHINE\SOFTWARE\sweet-pageSoftware\sweet-pagehp\
HKEY_LOCAL_MACHINE\Software\nationzoomSoftware\nationzoomhp\
HKEY_LOCAL_MACHINE\Software\aartemisSoftware\aartemishp\
HKEY_LOCAL_MACHINE\Software\V9Software\v9hp\
HKEY_CURRENT_USER\Software\InstalledBrowserExtensions\Adassist\
HKEY_CURRENT_USER\Software\Systweak\RegClean Pro\Version 6.1\
HKEY_CLASSES_ROOT\MSXML2.XMLHTTP.3.0\
HKEY_CLASSES_ROOT\MSXML2.XMLHTTP.3.0\\CLSID\
CLSID\{F5078F35-C551-11D3-89B9-0000F81FE221}\
CLSID\{F5078F35-C551-11D3-89B9-0000F81FE221}\\TreatAs\
HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\ActiveX Compatibility\\{F5078F35-C551-11D3-89B9-0000F81FE221}\
\\CLSID\{F5078F35-C551-11D3-89B9-0000F81FE221}\
\\CLSID\{F5078F35-C551-11D3-89B9-0000F81FE221}\\InprocServer32\
\\CLSID\{F5078F35-C551-11D3-89B9-0000F81FE221}\\InprocServerX86\
\\CLSID\{F5078F35-C551-11D3-89B9-0000F81FE221}\\LocalServer32\
\\CLSID\{F5078F35-C551-11D3-89B9-0000F81FE221}\\InprocHandler32\
\\CLSID\{F5078F35-C551-11D3-89B9-0000F81FE221}\\InprocHandlerX86\
\\CLSID\{F5078F35-C551-11D3-89B9-0000F81FE221}\\LocalServer\
HKEY_CLASSES_ROOT\CLSID\{F5078F35-C551-11D3-89B9-0000F81FE221}\
HKEY_CLASSES_ROOT\CLSID\{F5078F35-C551-11D3-89B9-0000F81FE221}\\TreatAs\
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\3\
HKEY_CLASSES_ROOT\CLSID\{59031A47-3F72-44A7-89C5-5595FE6B30EE}\InProcServer32\
CLSID\{275C23E2-3747-11D0-9FEA-00AA003F8646}\
CLSID\{275C23E2-3747-11D0-9FEA-00AA003F8646}\\TreatAs\
\\CLSID\{275C23E2-3747-11D0-9FEA-00AA003F8646}\
\\CLSID\{275C23E2-3747-11D0-9FEA-00AA003F8646}\\InprocServer32\
\\CLSID\{275C23E2-3747-11D0-9FEA-00AA003F8646}\\InprocServerX86\
\\CLSID\{275C23E2-3747-11D0-9FEA-00AA003F8646}\\LocalServer32\
\\CLSID\{275C23E2-3747-11D0-9FEA-00AA003F8646}\\InprocHandler32\
\\CLSID\{275C23E2-3747-11D0-9FEA-00AA003F8646}\\InprocHandlerX86\
\\CLSID\{275C23E2-3747-11D0-9FEA-00AA003F8646}\\LocalServer\
HKEY_CLASSES_ROOT\CLSID\{275C23E2-3747-11D0-9FEA-00AA003F8646}\
HKEY_CLASSES_ROOT\CLSID\{275C23E2-3747-11D0-9FEA-00AA003F8646}\\TreatAs\
HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main\FeatureControl\\FEATURE_ACTIVEX_INACTIVATE_MODE_REMOVAL_REVERT\
HKEY_CURRENT_USER\Software\Policies\Microsoft\Internet Explorer\PhotoSupport\
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main\
CLSID\{56FDF344-FD6D-11D0-958A-006097C9A090}\
CLSID\{56FDF344-FD6D-11D0-958A-006097C9A090}\\TreatAs\
\\CLSID\{56FDF344-FD6D-11D0-958A-006097C9A090}\
\\CLSID\{56FDF344-FD6D-11D0-958A-006097C9A090}\\InprocServer32\
\\CLSID\{56FDF344-FD6D-11D0-958A-006097C9A090}\\InprocServerX86\
\\CLSID\{56FDF344-FD6D-11D0-958A-006097C9A090}\\LocalServer32\
\\CLSID\{56FDF344-FD6D-11D0-958A-006097C9A090}\\InprocHandler32\
\\CLSID\{56FDF344-FD6D-11D0-958A-006097C9A090}\\InprocHandlerX86\
\\CLSID\{56FDF344-FD6D-11D0-958A-006097C9A090}\\LocalServer\
HKEY_CLASSES_ROOT\CLSID\{56FDF344-FD6D-11D0-958A-006097C9A090}\
HKEY_CLASSES_ROOT\CLSID\{56FDF344-FD6D-11D0-958A-006097C9A090}\\TreatAs\
HKEY_CURRENT_USER\SOFTWARE\Classes\PROTOCOLS\Filter\text/xml\
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\PROTOCOLS\Filter\text/xml\
CLSID\{807563E5-5146-11D5-A672-00B0D022E945}\
CLSID\{807563E5-5146-11D5-A672-00B0D022E945}\\TreatAs\
\\CLSID\{807563E5-5146-11D5-A672-00B0D022E945}\
\\CLSID\{807563E5-5146-11D5-A672-00B0D022E945}\\InprocServer32\
\\CLSID\{807563E5-5146-11D5-A672-00B0D022E945}\\InprocServerX86\
\\CLSID\{807563E5-5146-11D5-A672-00B0D022E945}\\LocalServer32\
\\CLSID\{807563E5-5146-11D5-A672-00B0D022E945}\\InprocHandler32\
\\CLSID\{807563E5-5146-11D5-A672-00B0D022E945}\\InprocHandlerX86\
\\CLSID\{807563E5-5146-11D5-A672-00B0D022E945}\\LocalServer\
HKEY_CLASSES_ROOT\CLSID\{807563E5-5146-11D5-A672-00B0D022E945}\
HKEY_CLASSES_ROOT\CLSID\{807563E5-5146-11D5-A672-00B0D022E945}\\TreatAs\
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\12.0\Common\Filter\text/xml\
HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main\FeatureControl\\FEATURE_HANDLE_RELEASED_PROTOCOL_KB942169\
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\\\Domains\freesoftindex.com\
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\freesoftindex.com\
HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main\
HKEY_CLASSES_ROOT\MIME\Database\Content Type\image/png\
C:\Global\AmInst__Runing_1
C:\CTF.TimListCache.FMPDefaultS-1-5-21-1547161642-507921405-839522115-1004MUTEX.DefaultS-1-5-21-1547161642-507921405-839522115-1004
C:\ShimCacheMutex
C:\_!MSFTHISTORY!_
C:\c:!documents and settings!user!local settings!temporary internet files!content.ie5!
C:\c:!documents and settings!user!cookies!
C:\c:!documents and settings!user!local settings!history!history.ie5!
C:\WininetStartupMutex
C:\WininetConnectionMutex
C:\WininetProxyRegistryMutex
C:\CtfmonInstMutexDefaultS-1-5-21-1547161642-507921405-839522115-1004
C:\MSIMGSIZECacheMutex

Version Infos

LegalCopyright
InternalName setup.exe
FileVersion 1.1.5.26
CompanyName
ProductName
ProductVersion 1.1.5.26
FileDescription
OriginalFilename setup.exe
Translation 0x0409 0x04b0

Sections

Name Virtual Address Virtual Size Size of Raw Data Entropy
.text 0x00001000 0x0003951b 0x00039600 6.56187946519
.rdata 0x0003b000 0x0000b930 0x0000ba00 4.98242786318
.data 0x00047000 0x00004c8c 0x00002a00 4.36495212918
.rsrc 0x0004c000 0x000040c8 0x00004200 5.31246552576
.reloc 0x00051000 0x00004a10 0x00004c00 5.37437967058

Resources

Name Offset Size Language Sub-language File type
REGISTRY 0x0004c3c0 0x0000022b LANG_ENGLISH SUBLANG_ENGLISH_US ASCII text, with CRLF line terminators
REGISTRY 0x0004c3c0 0x0000022b LANG_ENGLISH SUBLANG_ENGLISH_US ASCII text, with CRLF line terminators
TYPELIB 0x0004e5b8 0x000019bc LANG_ENGLISH SUBLANG_ENGLISH_US data
RT_ICON 0x0004cce8 0x000010a8 LANG_ENGLISH SUBLANG_ENGLISH_US data
RT_DIALOG 0x0004ca20 0x00000218 LANG_ENGLISH SUBLANG_ENGLISH_US data
RT_DIALOG 0x0004ca20 0x00000218 LANG_ENGLISH SUBLANG_ENGLISH_US data
RT_DIALOG 0x0004ca20 0x00000218 LANG_ENGLISH SUBLANG_ENGLISH_US data
RT_DIALOG 0x0004ca20 0x00000218 LANG_ENGLISH SUBLANG_ENGLISH_US data
RT_STRING 0x00050080 0x00000044 LANG_ENGLISH SUBLANG_ENGLISH_US data
RT_STRING 0x00050080 0x00000044 LANG_ENGLISH SUBLANG_ENGLISH_US data
RT_GROUP_ICON 0x0004dd90 0x00000014 LANG_ENGLISH SUBLANG_ENGLISH_US MS Windows icon resource - 1 icon
RT_VERSION 0x0004dda8 0x00000244 LANG_ENGLISH SUBLANG_ENGLISH_US data
RT_MANIFEST 0x0004dff0 0x000005c7 LANG_ENGLISH SUBLANG_ENGLISH_US XML document text
None 0x0004cc38 0x000000aa LANG_ENGLISH SUBLANG_ENGLISH_US data

Imports

Library KERNEL32.dll:
0x43b060 lstrcmpW
0x43b064 MulDiv
0x43b068 GetModuleFileNameW
0x43b06c GlobalUnlock
0x43b070 GlobalLock
0x43b074 SetLastError
0x43b078 FreeLibrary
0x43b07c SizeofResource
0x43b080 LoadResource
0x43b084 LoadLibraryExW
0x43b088 GlobalHandle
0x43b08c LockResource
0x43b090 lstrlenA
0x43b094 CreateMutexW
0x43b098 ReleaseMutex
0x43b09c WaitForSingleObject
0x43b0a0 Sleep
0x43b0a4 CreateThread
0x43b0a8 CreateEventW
0x43b0ac SetEvent
0x43b0b0 ExitProcess
0x43b0b4 LocalFree
0x43b0b8 GetCommandLineW
0x43b0bc lstrcpyW
0x43b0c0 FreeResource
0x43b0c4 GetExitCodeProcess
0x43b0c8 TerminateProcess
0x43b0cc GetProcessId
0x43b0d0 CreateDirectoryW
0x43b0d4 CreateSemaphoreW
0x43b0d8 ReleaseSemaphore
0x43b0e0 OutputDebugStringA
0x43b0e4 ReadFile
0x43b0e8 MoveFileW
0x43b0ec DeleteFileW
0x43b0f4 GetTempPathW
0x43b0fc LoadLibraryW
0x43b100 FindClose
0x43b104 FindFirstFileW
0x43b10c SetEndOfFile
0x43b110 WriteConsoleW
0x43b114 FlushFileBuffers
0x43b118 SetStdHandle
0x43b120 LCMapStringW
0x43b124 GetStringTypeW
0x43b128 GetConsoleMode
0x43b12c GetConsoleCP
0x43b130 SetFilePointer
0x43b134 GetCurrentProcessId
0x43b138 GetTickCount
0x43b148 GetFileType
0x43b14c SetHandleCount
0x43b150 IsValidCodePage
0x43b154 GetOEMCP
0x43b158 GetACP
0x43b15c GetCPInfo
0x43b160 HeapReAlloc
0x43b164 HeapSize
0x43b168 GetStdHandle
0x43b16c HeapCreate
0x43b170 IsDebuggerPresent
0x43b17c TlsFree
0x43b180 TlsSetValue
0x43b184 TlsGetValue
0x43b188 TlsAlloc
0x43b18c GetStartupInfoW
0x43b190 HeapSetInformation
0x43b194 DecodePointer
0x43b198 EncodePointer
0x43b19c RtlUnwind
0x43b1a8 VirtualAlloc
0x43b1ac VirtualFree
0x43b1b4 HeapAlloc
0x43b1b8 GetProcessHeap
0x43b1bc HeapFree
0x43b1c8 MultiByteToWideChar
0x43b1cc GetCurrentThreadId
0x43b1d0 FindResourceW
0x43b1d4 GlobalAlloc
0x43b1d8 GetCurrentProcess
0x43b1e0 lstrcmpiW
0x43b1e4 GetModuleHandleW
0x43b1e8 GetProcAddress
0x43b1fc RaiseException
0x43b200 GlobalFree
0x43b204 lstrlenW
0x43b208 WideCharToMultiByte
0x43b20c GetTempFileNameW
0x43b210 CreateFileW
0x43b214 WriteFile
0x43b218 GetLastError
0x43b21c CloseHandle
Library USER32.dll:
0x43b298 GetWindow
0x43b29c MessageBoxW
0x43b2a0 InvalidateRect
0x43b2a4 wsprintfW
0x43b2a8 DestroyWindow
0x43b2ac SetActiveWindow
0x43b2b0 KillTimer
0x43b2b4 ScreenToClient
0x43b2b8 GetClientRect
0x43b2bc SetWindowTextW
0x43b2c0 PostMessageW
0x43b2c4 SendMessageW
0x43b2c8 GetWindowLongW
0x43b2cc SetWindowLongW
0x43b2d0 CharNextW
0x43b2d4 EndDialog
0x43b2d8 GetForegroundWindow
0x43b2dc IsWindow
0x43b2e4 PostThreadMessageW
0x43b2e8 TranslateMessage
0x43b2ec DispatchMessageW
0x43b2f0 GetMessageW
0x43b2f4 CheckDlgButton
0x43b2f8 IsDlgButtonChecked
0x43b2fc MoveWindow
0x43b300 DefWindowProcW
0x43b304 GetWindowTextW
0x43b30c GetDlgItem
0x43b310 GetSysColor
0x43b314 SetWindowPos
0x43b318 ClientToScreen
0x43b31c GetDC
0x43b320 ReleaseDC
0x43b324 UnregisterClassA
0x43b328 InvalidateRgn
0x43b32c RedrawWindow
0x43b330 SetCapture
0x43b334 IsChild
0x43b338 GetParent
0x43b33c GetClassNameW
0x43b340 ReleaseCapture
0x43b344 FillRect
0x43b34c SendDlgItemMessageW
0x43b350 MapDialogRect
0x43b354 LoadIconW
0x43b364 PtInRect
0x43b368 CreateWindowExW
0x43b36c RegisterClassExW
0x43b370 LoadCursorW
0x43b374 GetClassInfoExW
0x43b378 SetFocus
0x43b37c GetFocus
0x43b384 GetDesktopWindow
0x43b388 BeginPaint
0x43b38c EndPaint
0x43b390 CallWindowProcW
Library GDI32.dll:
0x43b030 DeleteDC
0x43b034 SelectObject
0x43b038 DeleteObject
0x43b03c CreateCompatibleDC
0x43b040 BitBlt
0x43b044 GetDeviceCaps
0x43b048 GetObjectW
0x43b04c GetStockObject
0x43b054 CreateSolidBrush
Library ADVAPI32.dll:
0x43b000 RegCloseKey
0x43b004 RegDeleteValueW
0x43b008 RegDeleteKeyW
0x43b00c RegCreateKeyExW
0x43b010 RegOpenKeyExW
0x43b014 RegQueryValueExW
0x43b018 RegOpenKeyExA
0x43b01c RegQueryValueExA
0x43b020 RegEnumKeyExW
0x43b024 RegQueryInfoKeyW
0x43b028 RegSetValueExW
Library SHELL32.dll:
0x43b274 SHBrowseForFolderW
0x43b27c ShellExecuteExW
0x43b280 CommandLineToArgvW
0x43b288 ExtractIconW
Library ole32.dll:
0x43b3e8 CoRevokeClassObject
0x43b3ec CoUninitialize
0x43b3f0 CoInitialize
0x43b3f4 ProgIDFromCLSID
0x43b3f8 OleInitialize
0x43b3fc OleUninitialize
0x43b404 CLSIDFromString
0x43b408 CoGetClassObject
0x43b40c OleLockRunning
0x43b410 StringFromGUID2
0x43b414 CoTaskMemFree
0x43b418 CLSIDFromProgID
0x43b41c CoCreateInstance
0x43b420 CoTaskMemRealloc
0x43b424 CoTaskMemAlloc
Library OLEAUT32.dll:
0x43b224 None
0x43b228 None
0x43b22c None
0x43b230 None
0x43b234 None
0x43b238 None
0x43b23c None
0x43b240 None
0x43b244 None
0x43b248 None
0x43b24c None
0x43b250 None
0x43b254 None
0x43b258 None
0x43b25c None
0x43b260 None
0x43b264 None
0x43b268 None
0x43b26c None
Library VERSION.dll:
0x43b398 VerQueryValueW
0x43b3a0 GetFileVersionInfoW
Library SHLWAPI.dll:
0x43b290 StrStrIW
Library WINHTTP.dll:
0x43b3b0 WinHttpCrackUrl
0x43b3b4 WinHttpConnect
0x43b3b8 WinHttpReadData
0x43b3bc WinHttpOpen
0x43b3c0 WinHttpSetOption
0x43b3c8 WinHttpCloseHandle
0x43b3cc WinHttpQueryHeaders
0x43b3d4 WinHttpSendRequest
0x43b3d8 WinHttpOpenRequest

!This program cannot be run in DOS mode.
"#Rich
`.rdata
@.data
@.reloc
BRQj)P
SSSQRP
VPPQWRS
V@9~8r
E,PQVR
8%tkj%P
I VRPQ
:u WQj
@(QRSV
U SQRP
=WPWSj
90u+9p
N QhP}D
PVVVWShE
SVWhi/
SVW=#I
4SVWhD
90u+9p
WWWWWWW
WWWWWWW
QWWh0fA
u*8F<t
;0u RVj
;0u RVj
tkHta9
PQRWh|=
;0u RVj
VhPQRh
8;{Ht
?PVPW3
?PVWhA.
SSRSSQ
w$f9_@u+9^
x9;~$}4
QQSVWd
jXh ND
URPQQhPwB
t=MOC
j,h OD
HtHu4j
t*=RCC
;7|G;p
tR99u2
j hPPD
^SSSSS
tWItHIt9It
t\jXXf;
ou'j8Xf;
&VVVVV
8CSVhQ
j@j ^V
HHt$HHt
?If90t
HHt$HHt
QQSVWh
;t$,v-
UQPXY]Y[
j hXQD
t"SS9] u
PPPPPPPP
PPPPPPPP
tCHt(Ht
<+t"<-t
+t HHt
6MTA01PLpiA/CfMqb6/Q1dfYSNGwDj071R18qM3fy/VT6qUCKA==
invalid string position
string too long
7MjA/07RsUcoGMsaWq7LjYvILQ==
mv6OtgfLpAY0DtwKTf3LyNz2TtG3Ez8ZsA==
7tjL6V6fkgYuHIBPeq/Nwty7Atv2AjQe1RpRqdrfy/8Hl/M0c3c=
7cjP/wf7txM7R5oqTa/Q346+Q5+zCTkSzwFLuM3IyrsPmoVOUA==
69/X8knY9hM1XcgKW7TNyM3vB9mkCDddnzwfqdCNi8gt
7NnP71LM9gQ1Gd9PGrmf38vvUs24Aj5d3B1QsJ+I/ZE=
+t/c9FWf8wN6CcgOUa7ZyNzpTtGxR38usA==
+Mja30LMvRM1De0GUbnQ2g==
FRegOpenKeyTransactedW
RegCreateKeyTransactedW
RegDeleteKeyTransactedW
RegDeleteKeyExW
/d/H9UDovwk+Es07UInQ3Q==
/tna+kTXgg8oGNsLdrPP2No=
8cja7EjNvUc/D8gATf2XiMqyB9q4BDUI1Btar9rJgrtO0aUTOxHWT16/0N/a/kM=
/MLD9lLRvwQ7CdMAUf3LxMP+SMqiR3ddygNavMzIju9VxvYTNV3JCkuoz43P/EbWuEc2HM4KTfM=
8MHL2FXatxM/LdMMS6jNyOf1Q9akAjkJ
/N/L+lPahRMoGNsCcLP36sL0Rd66
+czH90Lb9hM1XdkdWrzLyI7uV9v2CDgX3wxL/Y/1i8MqtQ==
invalid map/set<T> iterator
map/set<T> too long
./MzC93DWuAM1CuodUL7o
88LP/3TLpA40Gu0=
28za+kbJtw42HNgDWg==
7OXo8kvamRc/D9sbVrLR+g==
mt7ysQLM/Ek2E9FmGq7ewMfrTsezC3Qe3Ag2+MzMw/INkaIKKlPTDFDUmt6L6A2Rsx8/dJ8cNg==
28za+h3WuwY9GJUXErTcwsCgRd6lAmxJlg==
+MjazE7Rsggt
/MLA70LRokoOBMoKBf3e3d73Tty3EzMS1EBH8Mja2bZB0KQKdwjIA1qz3MLK/kOy3A==
mt7yvlSRugkx
hM/P6EKJ4ks=
jp3bu1fesQJ6KOgjBf2a/o7rSMyiRz4czg4f+Oyn
+MjayF7MogI3MN8bTbTc3g==
+MjazE7RsggtL98MSw==
7Mjaz07SsxU=
7MjazE7RsggtLdUc
7MjazE7RsggtMdUBWIo=
3sDHzFXephc/D/4GSQ==
9sPa/lXRsxMfBcoDUK/a34DaV8+6DjkczgZQsw==
19na6x2Q+RAtCpRKTPLWw8r+X5GmDyo=
9sPd70bTukc+Es0BU7LeyY79Rta6Aj5dl09PsdrM3f4Hy6QeegnVT02o0Y3d/lPKpkc7GtsGUf3TzNr+VZE=
68jc9gmfoQYzCZpKW9C1
FUnRegisterTypeLibForUser
RegisterTypeLibForUser
68jc9gnLvhU/HN5PXK/azNr+Q5/zA1d3
+cza+kufsxUoEshPGu2H9Y7ySdaiDjsR0xVWs9iN+9IqtQ==
+cza+kufsxUoEshPGu2H9Y74Vdq3EzMT3U9qlLKn
+8TP90jY9gQ2EskKW/2ayaOR
7MLI71DepAIGMNMMTbLMwsjve+i/CT4SzRxjnsrf3P5Jy4ACKA7TAFGB+tXe90jNsxUGLtIKU7Gf68H3Q9qkFA==
8szH9QfLvhU/HN5PGrmfyMD/Qtv2Qj5wsA==
mvnr1neaigY3FNYAWPPL1do=
/sDn9VTLiTgICNQGUbo=
+MHB+UbTiiY3NNQcS4Lg/9v1TtGxOGs=
~#>+sPK307eugg9
+8TP90jYlAgiLdsdXrDo
+czH90Lb9hM1XcgaUf2a/o62B8q4FC8NygBNqdrJju9ez7NHfxmw
+czH90Lb9hM1XcgaUf2a/o62B9y5CioS1ApRqZ/exfJXz7MDUA==
jI3I9FWf8wNgXcoOTbjR2d27VNasAnpY3kMfrdrDyvJJ2PYUMwffTxq5n9/NpgLb3A==
mv6O6VLRuA40GpZPSLzW2Y79SM32Qgld3wFbuNun
88LB8E7RsUc8EshPT6/QzsvoVNqlRy4P3wofstmNi/8dn6YGKBjUG0z9zMTU/geaskt6Dd8BW7TRyo7oTsWzR38ZsA==
68TD/kjKokctHNMbVrPYjcj0VZ+mFTUe3xxM/YyNi8gHl78DeljeRjU=
79/B+ELMpUcuD98KH7vQ346+dJ+zCT4Y3mU=
79/B+ELMpUdpXdwATf2a/o6zTtv2Qj5UmgpSrcvUpA==
6MzH7weL9lR6DtEGT63ayY79SM32Qgl3
/uv63nWfugg5FpoYXrTLmdrpQtr2EzIP3w5b1w==
/ejo1HX69gs1HtFPSLzW2ZrvVdqzRy4VyApeubU=
/MXH90OfphU1Ht8cTP3Zwty7Auz2TzMZmkpb9J/IwP9C2/pHCD6HSlvxn97a+lPKpVp/GbA=
/uv63nWftwQuFMwOS7TRyo7MRtaiUw4P3wprtc3Iz/8HmrJHfxmw
/u760nH+gi4UOpo4XrTLmfrpQtqCDygY2wsf+NuNi/8t
/ejo1HX69gY5CdMZXqnWw8m7cN6/E24pyApaidffy/pDn/MDeljeZQ==
+czH90Lb9hM1XcgaUf2XiP2yB5P2AigP1R0f+Nun
69/X8knY9hM1XdUfWrOfy8H3Q9qkR3JY6UYfvtDD2vpO0b8JPV3ABk/9k43L6VXQpEd/GbA=
7djA9U7RsUc8EshPGo6FjYvIB5qFbQ==
+czH90Lb9hM1XdkdWrzLyI7vQtKmSXob0wNa8Z/I3OlIzfZCPnc=
7cjK8lXatRN6Vw==
?deque<T> too long
+sPf7kLKs0d/LrA=
msmO60jMohc1E98LH6/Kw927Vdq6AjsO3ws1
7NnP71LM60I+XdwATf3cwsPrSNGzCS4i0wsC+NuBjv5VzbkVZ1jeZQ==
9smOvkOftxQpFN0BWrmf2cG7Auz6RygYzh1G/czZz+9Cn/MDUA==
9smOvkOftxQpFN0BWrmf2cG7Auz6RykJ2xta4JrJhulCy6Qec3c=
9smOvkOftxQpFN0BWrmf2cG7Auz6RykJ2xta4JrJpA==
mvnr1neaigY3FNYAWO/ZxML+CZU=
08LJqUHWugI=
8tjC7079rxM/KdU4Vrna7sb6VQ==
v62umie71mRSdbpuN9A=
/N/L+lPakg47EdUIb7zNzMPM
68jD6wfZvws/XZ88H7DQ28v/B8u5R38ulk9MqNzOy+hUn/MDV3c=
6czC7kKf8zR6CsgGS6naw4K7Qs2kCChdnwsy1w==
9MjXuwLn+UIJXdUfWrPayYK7Qs2kCChdnwsy1w==
9t759FCJ4jcoEtkKTK4=
moOcww==
+8TJ8lPeujcoEt4aXKn2yZo=
7OLoz3D+hCIGMNMMTbLMwsjve+i/CT4SzRwfk+vx7e5VzbMJLivfHUy00MM=
+8TJ8lPeujcoEt4aXKn2yQ==
7MLI71DepAIGMNMMTbLMwsjve/ykHioJ1QhNvM/F1w==
8szN807RsyAPNP4=
7PT9z2LyiiQvD8gKUan8wsDvVdC6ND8J5ixQs8vfwfd78bMTLRLIBGOmi+mdrWKG4VV3OIldCvCOnO3eCv2QJGtQilcP7Y3v66oXjOdfJyGfPGOe0MPA/kTLvwg0
+Mja2kPephM/D8kuW7nNyN3oQsw=
9t3G91fepg50GdYD
+Mja2EjSphIuGMghXrDa+g==
7OLoz3D+hCIGMNMMTbLMwsjve/GTM3o7yA5SuMjC3PAH7LMTLw3mIXuN
mv3c9EDNtwocFNYKTPjj6sH0QNOzOxkVyABSuOPs3utL1rUGLhTVAWO+19/B9kKRsx8/
msHB+EbTtxcqGdsbXvjj6sH0QNOzOxkVyABSuOPs3utL1rUGLhTVAWO+19/B9kKRsx8/
9t776ELNlwkbGdcGUQ==
7OLoz3D+hCIGPtYGWrPL3vLIU96kExcY1Bp2s8vI3PVCyw==
7MjA/2rapRQ7Gt84
8N3L9XfNuQQ/DslDbqja39fdUtO6NygS2QpMrvbAz/xC8bcKPyqWLE243tnLz0jQug8/EcpcDY7RzN7oT9CiSwoP1QxarsyenNVCx6Iwdi3IAFy4zN6dqWHWpBQuKpYsUK3G68f3Quj6Iz8R3xtam9bBy8wL8rkRPzvTA1qKk+7c/kbLszMyD98OW/H4yNrNQs2lDjUT/xdo8ezI2t5Jyb8VNRPXClGp6czc8kbdugINUf0KS4nawN7LRsu+MHYq0wtantfM3M9I8qMLLhT4Fku4k+rL72rQshI2GPwGU7jxzMP+cJORAi4oyQpNmdrLz+5Ly4MuFhzUCEq82MiC2FXatxM/OdMdWr7LwtzicJORAi470wNanMvZ3PJFyqICKSqWPFqp+cTC/mbLohUzH88bWq7ogfn6TsuQCCgwzwNLtM/By9RF1bMELg4=
nYrypBuB8FpxWJZABfyclvXG
Unknown exception
bad allocation
bad exception
FlsFree
FlsSetValue
FlsGetValue
FlsAlloc
CorExitProcess
HH:mm:ss
dddd, MMMM dd, yyyy
MM/dd/yy
December
November
October
September
August
February
January
Saturday
Friday
Thursday
Wednesday
Tuesday
Monday
Sunday
 !"#$%&'()*+,-./0123456789:;<=>?@ABCDEFGHIJKLMNOPQRSTUVWXYZ[\]^_`abcdefghijklmnopqrstuvwxyz{|}~
(null)
`h````
xpxxxx
`h`hhh
xppwpp
Complete Object Locator'
Class Hierarchy Descriptor'
Base Class Array'
Base Class Descriptor at (
Type Descriptor'
`local static thread guard'
`managed vector copy constructor iterator'
`vector vbase copy constructor iterator'
`vector copy constructor iterator'
`dynamic atexit destructor for '
`dynamic initializer for '
`eh vector vbase copy constructor iterator'
`eh vector copy constructor iterator'
`managed vector destructor iterator'
`managed vector constructor iterator'
`placement delete[] closure'
`placement delete closure'
`omni callsig'
delete[]
new[]
`local vftable constructor closure'
`local vftable'
`udt returning'
`copy constructor closure'
`eh vector vbase constructor iterator'
`eh vector destructor iterator'
`eh vector constructor iterator'
`virtual displacement map'
`vector vbase constructor iterator'
`vector destructor iterator'
`vector constructor iterator'
`scalar deleting destructor'
`default constructor closure'
`vector deleting destructor'
`vbase destructor'
`string'
`local static guard'
`typeof'
`vcall'
`vbtable'
`vftable'
operator
delete
__unaligned
__restrict
__ptr64
__eabi
__clrcall
__fastcall
__thiscall
__stdcall
__pascal
__cdecl
__based(
GetProcessWindowStation
GetUserObjectInformationW
GetLastActivePopup
GetActiveWindow
MessageBoxW
_nextafter
_hypot
 !"#$%&'()*+,-./0123456789:;<=>?@abcdefghijklmnopqrstuvwxyz[\]^_`abcdefghijklmnopqrstuvwxyz{|}~
 !"#$%&'()*+,-./0123456789:;<=>?@ABCDEFGHIJKLMNOPQRSTUVWXYZ[\]^_`ABCDEFGHIJKLMNOPQRSTUVWXYZ{|}~
1#QNAN
1#SNAN
GlobalFree
CloseHandle
GetLastError
WriteFile
CreateFileW
GetTempFileNameW
WideCharToMultiByte
lstrlenW
RaiseException
EnterCriticalSection
LeaveCriticalSection
InitializeCriticalSectionAndSpinCount
DeleteCriticalSection
GetProcAddress
GetModuleHandleW
lstrcmpiW
FlushInstructionCache
GetCurrentProcess
GlobalAlloc
FindResourceW
GetCurrentThreadId
MultiByteToWideChar
InterlockedIncrement
InterlockedDecrement
lstrcmpW
MulDiv
GetModuleFileNameW
GlobalUnlock
GlobalLock
SetLastError
FreeLibrary
SizeofResource
LoadResource
LoadLibraryExW
GlobalHandle
LockResource
lstrlenA
CreateMutexW
ReleaseMutex
WaitForSingleObject
CreateThread
CreateEventW
SetEvent
ExitProcess
LocalFree
GetCommandLineW
lstrcpyW
FreeResource
GetExitCodeProcess
TerminateProcess
GetProcessId
CreateDirectoryW
CreateSemaphoreW
ReleaseSemaphore
InitializeCriticalSection
OutputDebugStringA
ReadFile
MoveFileW
DeleteFileW
WritePrivateProfileStringW
GetTempPathW
GetPrivateProfileStringW
LoadLibraryW
FindClose
FindFirstFileW
ExpandEnvironmentStringsW
KERNEL32.dll
GetWindowThreadProcessId
IsWindow
GetForegroundWindow
EndDialog
CharNextW
SetWindowLongW
GetWindowLongW
SendMessageW
PostMessageW
SetWindowTextW
GetClientRect
ScreenToClient
KillTimer
SetActiveWindow
GetWindow
GetDlgItem
MessageBoxW
InvalidateRect
wsprintfW
DestroyWindow
MoveWindow
DefWindowProcW
GetWindowTextW
GetWindowTextLengthW
GetSysColor
SetWindowPos
ClientToScreen
ReleaseDC
InvalidateRgn
RedrawWindow
SetCapture
IsChild
GetParent
GetClassNameW
ReleaseCapture
FillRect
CallWindowProcW
EndPaint
BeginPaint
GetDesktopWindow
DestroyAcceleratorTable
GetFocus
SetFocus
GetClassInfoExW
LoadCursorW
RegisterClassExW
CreateWindowExW
PtInRect
CreateAcceleratorTableW
RegisterWindowMessageW
DialogBoxIndirectParamW
LoadIconW
MapDialogRect
SendDlgItemMessageW
SetWindowContextHelpId
PostThreadMessageW
TranslateMessage
DispatchMessageW
GetMessageW
CheckDlgButton
IsDlgButtonChecked
USER32.dll
DeleteObject
SelectObject
DeleteDC
CreateCompatibleBitmap
CreateCompatibleDC
BitBlt
GetDeviceCaps
CreateSolidBrush
GetObjectW
GetStockObject
GDI32.dll
RegOpenKeyExW
RegCreateKeyExW
RegDeleteKeyW
RegDeleteValueW
RegCloseKey
RegSetValueExW
RegQueryInfoKeyW
RegEnumKeyExW
RegQueryValueExA
RegOpenKeyExA
RegQueryValueExW
ADVAPI32.dll
ExtractIconW
SHGetSpecialFolderPathW
CommandLineToArgvW
ShellExecuteExW
SHGetPathFromIDListW
SHBrowseForFolderW
SHELL32.dll
CoTaskMemAlloc
CoTaskMemRealloc
CoCreateInstance
CLSIDFromProgID
CoTaskMemFree
StringFromGUID2
OleLockRunning
CoGetClassObject
CLSIDFromString
CreateStreamOnHGlobal
OleUninitialize
OleInitialize
ProgIDFromCLSID
CoInitialize
CoUninitialize
CoRevokeClassObject
CoRegisterClassObject
CoAddRefServerProcess
CoReleaseServerProcess
ole32.dll
OLEAUT32.dll
VerQueryValueW
GetFileVersionInfoW
GetFileVersionInfoSizeW
VERSION.dll
StrStrIW
SHLWAPI.dll
WinHttpCloseHandle
WinHttpSetStatusCallback
WinHttpSetOption
WinHttpOpen
WinHttpSendRequest
WinHttpOpenRequest
WinHttpConnect
WinHttpCrackUrl
WinHttpGetProxyForUrl
WinHttpQueryDataAvailable
WinHttpReadData
WinHttpQueryHeaders
WinHttpReceiveResponse
WINHTTP.dll
InterlockedCompareExchange
InterlockedPushEntrySList
HeapFree
GetProcessHeap
HeapAlloc
IsProcessorFeaturePresent
VirtualFree
VirtualAlloc
InterlockedPopEntrySList
GetSystemTimeAsFileTime
RtlUnwind
EncodePointer
DecodePointer
HeapSetInformation
GetStartupInfoW
TlsAlloc
TlsGetValue
TlsSetValue
TlsFree
UnhandledExceptionFilter
SetUnhandledExceptionFilter
IsDebuggerPresent
HeapCreate
GetStdHandle
HeapSize
HeapReAlloc
GetCPInfo
GetACP
GetOEMCP
IsValidCodePage
SetHandleCount
GetFileType
FreeEnvironmentStringsW
GetEnvironmentStringsW
QueryPerformanceCounter
GetTickCount
GetCurrentProcessId
SetFilePointer
GetConsoleCP
GetConsoleMode
GetStringTypeW
LCMapStringW
SetStdHandle
FlushFileBuffers
WriteConsoleW
SetEndOfFile
UnregisterClassA
.?AVbad_alloc@std@@
.?AVexception@std@@
.?AVAsyncWinHttp@@
ABCDEFGHIJKLMNOPQRSTUVWXYZabcdefghijklmnopqrstuvwxyz0123456789+/
.?AVCBaseRegSwWrite@@
.?AVCAtlException@ATL@@
.?AVCRegObject@ATL@@
.?AUIRegistrarBase@@
.?AUIUnknown@@
.?AVCComClassFactory@ATL@@
.?AUIClassFactory@@
.?AV?$CComObjectRootEx@VCComMultiThreadModel@ATL@@@ATL@@
.?AVCComObjectRootBase@ATL@@
.?AV?$CComClassFactorySingleton@VCBoot@@@ATL@@
.?AV?$CComObjectNoLock@V?$CComClassFactorySingleton@VCBoot@@@ATL@@@ATL@@
.?AV?$CComContainedObject@VCAxHostWindow@ATL@@@ATL@@
.?AVCAxHostWindow@ATL@@
.?AV?$CComCoClass@VCAxHostWindow@ATL@@$1?GUID_NULL@@3U_GUID@@B@ATL@@
.?AV?$CComObjectRootEx@VCComSingleThreadModel@ATL@@@ATL@@
.?AV?$CWindowImpl@VCAxHostWindow@ATL@@VCWindow@2@V?$CWinTraits@$0FGAAAAAA@$0A@@2@@ATL@@
.?AV?$CWindowImplBaseT@VCWindow@ATL@@V?$CWinTraits@$0FGAAAAAA@$0A@@2@@ATL@@
.?AV?$CWindowImplRoot@VCWindow@ATL@@@ATL@@
.?AVCWindow@ATL@@
.?AVCMessageMap@ATL@@
.?AUIAxWinHostWindowLic@@
.?AUIAxWinHostWindow@@
.?AUIOleClientSite@@
.?AUIOleInPlaceSiteWindowless@@
.?AUIOleInPlaceSiteEx@@
.?AUIOleInPlaceSite@@
.?AUIOleWindow@@
.?AUIOleControlSite@@
.?AUIOleContainer@@
.?AUIParseDisplayName@@
.?AV?$IObjectWithSiteImpl@VCAxHostWindow@ATL@@@ATL@@
.?AUIObjectWithSite@@
.?AUIServiceProvider@@
.?AUIAdviseSink@@
.?AUIDocHostUIHandler@@
.?AV?$IDispatchImpl@UIAxWinAmbientDispatchEx@@$1?_GUID_b2d0778b_ac99_4c58_a5c8_e7724e5316b5@@3U__s_GUID@@B$1?m_libid@CAtlModule@ATL@@2U_GUID@@A$0PPPP@$0PPPP@VCComTypeInfoHolder@ATL@@@ATL@@
.?AUIAxWinAmbientDispatchEx@@
.?AUIAxWinAmbientDispatch@@
.?AUIDispatch@@
.?AV?$CComObject@V?$CComEnum@UIEnumUnknown@@$1?_GUID_00000100_0000_0000_c000_000000000046@@3U__s_GUID@@BPAUIUnknown@@V?$_CopyInterface@UIUnknown@@@ATL@@VCComSingleThreadModel@6@@ATL@@@ATL@@
.?AV?$CComEnum@UIEnumUnknown@@$1?_GUID_00000100_0000_0000_c000_000000000046@@3U__s_GUID@@BPAUIUnknown@@V?$_CopyInterface@UIUnknown@@@ATL@@VCComSingleThreadModel@6@@ATL@@
.?AV?$CComEnumImpl@UIEnumUnknown@@$1?_GUID_00000100_0000_0000_c000_000000000046@@3U__s_GUID@@BPAUIUnknown@@V?$_CopyInterface@UIUnknown@@@ATL@@@ATL@@
.?AUIEnumUnknown@@
.?AV?$CComObject@VCAxFrameWindow@ATL@@@ATL@@
.?AVCAxFrameWindow@ATL@@
.?AV?$CWindowImpl@VCAxFrameWindow@ATL@@VCWindow@2@V?$CWinTraits@$0FGAAAAAA@$0A@@2@@ATL@@
.?AUIOleInPlaceFrame@@
.?AUIOleInPlaceUIWindow@@
.?AV?$CComObject@VCAxUIWindow@ATL@@@ATL@@
.?AVCAxUIWindow@ATL@@
.?AV?$CWindowImpl@VCAxUIWindow@ATL@@VCWindow@2@V?$CWinTraits@$0FGAAAAAA@$0A@@2@@ATL@@
.?AV?$CComPolyObject@VCAxHostWindow@ATL@@@ATL@@
.?AVCRegWrite@@
.?AV?$CComObject@VCBoot@@@ATL@@
.?AVCBoot@@
.?AV?$CComCoClass@VCBoot@@$1?CLSID_Inst@@3U_GUID@@B@ATL@@
.?AV?$CAxDialogImpl@VCBoot@@VCWindow@ATL@@@ATL@@
.?AV?$CDialogImplBaseT@VCWindow@ATL@@@ATL@@
.?AUISupportErrorInfo@@
.?AV?$IDispEventSimpleImpl@$0MJ@VCBoot@@$1?DIID_DWebBrowserEvents2@@3U_GUID@@B@ATL@@
.?AV?$_IDispEventLocator@$0MJ@$1?DIID_DWebBrowserEvents2@@3U_GUID@@B@ATL@@
.?AV_IDispEvent@ATL@@
.?AV?$IObjectWithSiteImpl@VCBoot@@@ATL@@
.?AV?$IDispatchImpl@UIBoot@@$1?IID_IBoot@@3U_GUID@@B$1?LIBID_InstallerLib@@3U3@B$00$0A@VCComTypeInfoHolder@ATL@@@ATL@@
.?AUIBoot@@
.?AUIObjectSafety@@
.?AV?$CComContainedObject@VCBoot@@@ATL@@
.?AV?$CComObjectCached@VCBoot@@@ATL@@
.?AV?$CComAggObject@VCBoot@@@ATL@@
.?AVCBootStrapperModule@@
.?AV?$CAtlExeModuleT@VCBootStrapperModule@@@ATL@@
.?AV?$CAtlModuleT@VCBootStrapperModule@@@ATL@@
.?AVCAtlModule@ATL@@
.?AU_ATL_MODULE70@ATL@@
.?AVCDownload@@
.?AVCHiddentThansRequest@@
.?AVCCriticalSection@@
.?AU_RTL_CRITICAL_SECTION@@
.?AVCInstallationManager@@
.?AVCLogger@@
.?AVCFsWrite@@
.?AVlogic_error@std@@
.?AVlength_error@std@@
.?AVout_of_range@std@@
.?AVtype_info@@
.?AVbad_exception@std@@
abcdefghijklmnopqrstuvwxyz
ABCDEFGHIJKLMNOPQRSTUVWXYZ
abcdefghijklmnopqrstuvwxyz
ABCDEFGHIJKLMNOPQRSTUVWXYZ
XmBsa.Inst.1 = s 'Inst Class'
CLSID = s '{FC0F186C-11A6-456F-A0EE-CBE9ED7E233E}'
XmBsa.Inst = s 'Inst Class'
CurVer = s 'XmBsa.Inst.1'
NoRemove CLSID
ForceRemove {FC0F186C-11A6-456F-A0EE-CBE9ED7E233E} = s 'Inst Class'
ProgID = s 'XmBsa.Inst.1'
VersionIndependentProgID = s 'XmBsa.Inst'
ForceRemove Programmable
LocalServer32 = s '%MODULE%'
val ServerExecutable = s '%MODULE_RAW%'
TypeLib = s '{83829839-609D-4F6E-8C12-6D4AA7127A57}'
Version = s '1.0'
<?xml version="1.0" encoding="UTF-8" standalone="yes"?>
<assembly xmlns="urn:schemas-microsoft-com:asm.v1" manifestVersion="1.0">
<assemblyIdentity type="win32" processorArchitecture="*" version="1.1.1.1" name="Launcher"/>
<description>Installer</description>
<compatibility xmlns="urn:schemas-microsoft-com:compatibility.v1">
<application>
<!--This Id value indicates the application supports Windows Vista functionality -->
<supportedOS Id="{e2011457-1546-43c5-a5fe-008deee3d3f0}"/>
<!--This Id value indicates the application supports Windows 7 functionality-->
<supportedOS Id="{35138b9a-5d96-4fbd-8e2d-a2440225f93a}"/>
<!--This Id value indicates the application supports Windows 8 functionality-->
<supportedOS Id="{4a2f28e3-53b9-4441-ba9c-d69d4a4a6e38}"/>
</application>
</compatibility>
<ms_asmv2:trustInfo xmlns:ms_asmv2="urn:schemas-microsoft-com:asm.v2">
<ms_asmv2:security>
<ms_asmv2:requestedPrivileges>
<ms_asmv2:requestedExecutionLevel level="requireAdministrator" uiAccess="false"/>
</ms_asmv2:requestedPrivileges>
</ms_asmv2:security>
</ms_asmv2:trustInfo>
<dependency>
<dependentAssembly>
<assemblyIdentity
type="win32" name="Microsoft.Windows.Common-Controls" version="6.0.0.0" processorArchitecture="*" publicKeyToken="6595b64144ccf1df" language="*" />
</dependentAssembly>
</dependency>
</assembly>
stdole2.tlbWWW
BSInstallerLib
\Instd
IBootWWWd
&WriteFileWWW
OfilePath
dfileContentW
isBase64EncodedWd
GetCommandLineParameterW
*paramIdW
paramValueWWd
SetTopmostWindow
topMostWd
GetSystemParameterWW
paramNameWWWd
yGServerLogWWW
ReadProfileStringWWW
fileName
+sectionNameW
keyNameW
defaultValue
WriteProfileStringWW
AsyncStartDownload2W
rshortNameWWW
UpdaterW
RunResourceW
YtcmdLineW
retCodeWd
@XGetFileLengthWWWd
!GetFileVersionWWd
DownloadCompletedWWWd
InstallationCompletedWWWd
RequestExitW
)uaskWd
BGetDownloadStatusWWW
rvdownloadIdWWd
GetInstallProcessRCWd
GetErrorCoded
AddThanksParameterWWd
PathExistsWW
^rcWWd
tPartialInstallProgressWWd
P%CreateIconWW
iconUrlW
bundleeNameWd
messageWd
ReleasePostponedInstallationsWWWd
Minimized
SetCaptionWidthW
hNwidthWWWd
-ShowMeWW
doShowWWd
:sIs64d
aLThankYouPaged
HiddenWWd
GetFileCreationTimeWd
WriteRegistryStringW
regRootW
regKeyWW
regValNameWWd
WriteRegistryIntd
BrowseForFolderW
startFolderW
~titleWWWd
HExpandEnvStringW
sourceWWd
CheckRegKeyW
ReadRegIntWW
valueNameWWWd
ReadRegStringWWWd
AsyncStartDownloadWWd
iEnableInstallationWW
bundleeIdWWW
W.launchCommandLineWWW
[launchedProcessNameW
installModeWd
DownloadProgressd
InstallProgressWd
GetFileModificationTimeWd
)sCurrentInstComponentd
CloseLastWWWd
StartWWW
Created by MIDL version 7.00.0555 at Sun Mar 09 04:44:43 2014
121;1e1n1
4 4*4?4X4e4
606F6S6
7-7X7u7
9&:1:X:
=6>F>]>
3&464M4
5P6x6<7}7
9A9G9N9\9c9
5P6r6P7
>'>.>3>9>?>a>~>
?`?f?v?}?
0*0C0l0
272b2i2|2
2$3@3G3X3\3
314p4w4~4
;@<D<H<L<
3 333{3
6"6J6f6
142<2O2V2_2
4F5X5q5
7,797G7i7
=%=6=K=\=
Y0o0|0
1*1;1v1
9!9%:=:{:
=P>T>X>\>
?"?/?V?h?
5p5t5x5|5
9"9A9R9
?$?+?2?9?b?
4=4J4}4
6+626;6X6w6
8'838?8J8
'1H1`1m1
212C2J2
4 4'4Z4c4j4|4
4G5\5~5
6-7T7d7q7
898V8e8
<<1<A<
3L4]4j4
;$;/;M;`;
; <O<T<
=f=&>4>[>
283E3]3s3
465<5p5
6&6X6*7/7
9&:V:h:
;?<U<\<
0#0(0-0
3E4V4e4
7%7R7t7
9}9&:R:
:@;i;F<\<t<{<
=`=z=&>8>O>X>a>o>v>
5g6s6x6~6
7$7*73797=7C7I7R7X7\7b7h7q7w7{7
9D:H:L:P:T:X:\:`:d:v:
;2<f<x<
>0b0p0
0,191T1a1v1
3 323@3G3
6$6<6R6^6t6
6&7M7^7y7
;=;V;F<U<
=f>u>f?v?
3&484e4n4w4
466;6~6
7(7H7W7z7
9 9>9T9
:D:4<I<
?$?*?7?
5!5(5/565=5D5J5b5
1)191H1Y1
3H3e3q3|3
4,5:5M5d5v5
7 7&787J7Y7b7x7
768G8e8r8
9/:K:t:
:8;?;F;M;T;[;b;o;D=
=H>O>V>]>d>k>r>
3&4+4=4
4&565H5
516>6K6v6
7<7@7D7H7
;X;b;l;
>0>;>F>Q>c>k>q>
0W1_1e1n1u1~1
264G4h4t4|4
595D5u5
6-636R6c6l6
9'9;9_9
:*;<;W;y;~;
<3<<<F<T<^<h<r<
<:=@=L=e=
>->4>?>]>c>
=.=C=S=Y=`=m=t=
050K0_0s0
7"7&9Q9~9
:0;q;|;
0.0:0K0^0n0
1N3W3t3L4
:%<F<a<
1;1U1r1
1&2+2=2n2
353;3A3G3W3`3j3}3
494T4g4m4~4
2%2X2a2f2l2y2
3)373R3\3a3l3v3
5'6-6V6e6
=8=W=]=s=
>'>7>B>R>v>
1!1&131P1a1g1
<N=Y=v=
=1><>V>e>
5*656N6Y6
7$7.7D7{7
8'8.8F8X8
:$:4:;:K:R:b:i:
<.=8=E=
>9?J?V?f?
0Q1f1x1
:#:+:F:U:n:
7(797k7
9<9^9v9
;.;\;r;
< =1=z=
0(0/070A0K0t0
0-1<1x1
3;3V3e3
5 5,5B5R5Y5x5
7!8G8R8n8
9$9*949D9V9f9
;$;(;,;0;4;8;<;@;
<(</<4<8<<<]<
<&=,=0=4=8=
> >I>o>
)0004080<0@0D0H0L0
3A3b3<4D4\4w4
9e:l:t:
;$;);.;E;
2X2]2g2
9O:p;d<
2'313<3S5H6O6[6a6m6s6|6
8A9G9]9b9j9p9w9}9
:%:*:2:7:>:M:R:X:a:
;=;C;H;
<$<)</<9<B<M<Y<^<n<s<y<
? ?*?@?K?e?p?x?
0)000[0
3!3-3d3m3y3
4V4\4q4
6#6K6T6]6s6
7a7e7i7m7q7u7y7}7
1R3X3^3
5e5w5W6a6n6
6i7R8a8|8
3!3`3K4c4
11+1b1z1
234D4~4
5"555Y5
8$8=8Y8b8h8q8v8
=(=@=i=
=4?W?b?
050D0Q0]0m0t0
0%1X1g1p1
5 555|5
6;6M6{6
7:8I8d8y;o<
<e?i?m?q?u?y?}?
2A2c2n2
8!868r8
9"9*969_9g9w9~9
:":+:>:b:
</<8<o<
?&?,?6?<?F?L?V?_?j?o?x?
>0E0K0
9"949Z9g9u9
;1H1a1
5x6R7"8S8i8
2(2I3g3
>$>6>H>n>
?"?4?F?
00C0T0y0
2B2P2Y2
3A3s3{3
4<4r4|4
5)5.5<5
8%878J8\8
<3<=<T<y<
}0q1y1*2
3J4P4^4
?1C1G1K1O1S1W1[1_1c1g1k1x1:2b2r2
4%5M5r5
727R7z7
<,<A<\<
>,>A>Q>a>u>{>
?-?1?7?@?E?O?T?Y?`?l?
'03090>0D0J0P0V0v0
151<1D1M1X1]1
2$202B2J2[2e2p2
3$353>3C3H3a3q3
4#444A4S4v4
4484<4@4D4H4L4P4T4X4\4`4d4h4l4p4t4x4|4
4 5$5(5p6t6x6
> ?$?(?,?0?4?8?l?p?t?x?|?
0 0$0(0,0004080<0@0H0L0P0T0X0\0`0d0h0l0p0t0x0|0
1 1$1(1,1014181<1@1D1H1L1P1T1X1\1`1d1h1l1p1t1x1|1
4 4$4(4,4044484<4H4T4
4d5h5l5p5t5x5
6`;d;h;l;p;t;x;|;
< <$<(<,<0<4<8<<<@<D<H<L<P<T<X<\<`<d<h<l<p<t<x<|<
=(=,=0=4=8=<=@=D=H=L=P=T=X=\=`=d=h=l=p=t=x=|=
> >$>(>,>0>4>8><>@>D>H>L>P>T>X>\>`>d>h>l>p>t>x>|>
? ?$?(?,?0?4?8?<?@?D?H?L?P?T?X?\?`?d?h?l?p?t?x?|?
0 0$0(0,0004080<0@0D0H0L0P0T0X0\0`0d0h0l0p0t0x0|0
2\4`4d4h4l4p4t4x4|4
: ;$;,<0<
0(0,00080<0
6 6$6(6,6064686<6@6D6H6`6d6
0$0,040<0D0L0T0\0d0l0t0|0
> >$>(>,>0>4>8><>@>D>H>L>P>T>X>\>`>d>h>l>p>t>x>|>
d8h8|8
949D9H9X9\9d9|9
: :0:4:H:L:\:`:d:h:l:p:x:
; ;8;H;L;T;l;|;
<(<8<<<L<P<T<X<\<`<d<h<l<p<t<x<|<
=$=4=8=<=@=D=H=L=P=T=X=\=`=d=h=l=p=t=x=|=
> >$><>L>P>T>\>t>x>
?0?@?D?H?L?T?l?|?
0,000H0X0\0`0h0
1(181<1@1D1H1L1T1l1p1
2$2<2@2X2\2t2x2
3,3034383@3X3\3t3
4 4$4<4L4P4T4\4t4x4
5,50545<5T5X5p5t5
6 6(6@6D6\6l6p6t6x6|6
7,707H7L7d7t7x7
8(8,8<8@8P8T8X8\8`8d8h8l8t8
9,9<9@9D9L9d9h9
:$:(:,:0:4:8:<:@:D:H:L:P:T:\:t:x:
;0;4;L;\;`;d;h;p;
< <$<(<0<H<L<d<t<x<|<
= =$=(=,=0=8=P=T=l=|=
> >$>(>,>0>4>8><>@>D>L>d>h>
?4?8?P?`?d?l?
0$04080<0D0\0`0x0|0
1$14181@1X1\1t1x1
2 2024282<2@2H2`2d2|2
3 3$3,3D3H3`3p3t3
4 4$4(4,4044484<4@4D4H4L4P4T4X4\4`4d4l4
5 5(5,5054585<5@5D5H5L5P5T5X5\5`5d5h5l5p5t5x5|5
6 6$64686H6L6P6T6X6`6x6
7,7<7@7D7H7P7h7x7|7
8 80848D8H8L8T8l8|8
9,9094989@9X9h9l9|9
: :(:@:P:T:d:h:l:p:x:
;$;<;L;P;`;d;h;p;
=$>4>`>h>
?,?4?<?H?l?
0 0,0L0X0x0
1(1H1T1t1
242<2H2p2
3@3T3\3d3
444@4h4
5D5h5t5|5
6(60686@6H6P6X6h6
7@7`7h7p7x7
8$8@8H8`8l8
9<9H9P9p9
:0:8:@:H:P:X:`:h:p:x:
;<;\;d;l;t;|;
< <(<0<<<`<
=<=H=l=
>4>T>\>d>l>t>|>
? ?(?0?8?@?H?P?X?`?h?p?x?
040X0d0l0
1$1P1`1t1
2$2D2P2p2|2
3$3,383X3`3h3p3x3
4$4,444<4D4L4X4x4
4$5(5D5H5T5t5|5
6,646@6h6|6
7 7,7L7X7x7
8 8@8L8l8t8|8
9 9(909<9d9x9
:,:8:X:d:
; ;,;L;X;x;
<8<D<h<
= =(=<=X=t=x=
>4>8>X>t>x>
?8?@?D?\?`?|?
0$0(0D0H0h0
101P1p1
282X2x2
2 2D2`2
5@5\5|5
6(6H6d6
7 7@7\7
3,3L3d3
78;8<<<@<D<H<L<P<T<X<\<`<d<h<l<p<t<x<|<
= =$=(=,=0=4=8=<=@=D=H=L=P=T=X=\=`=d=h=l=p=t=x=|=
>(>8>\>h>l>p>t>x>|>
3$3,343<3D3L3T3\3d3l3
Western Cape1
Durbanville1
Thawte1
Thawte Certification10
Thawte Timestamping CA0
121221000000Z
201230235959Z0^1
Symantec Corporation100.
'Symantec Time Stamping Services CA - G20
http://ocsp.thawte.com0
.http://crl.thawte.com/ThawteTimestampingCA.crl0
TimeStamp-2048-10
Thawte, Inc.1$0"
Thawte Code Signing CA - G20
130319000000Z
150618235959Z0c1
Alberta1
Raanana1
Amonetize ltd.1
Amonetize ltd.0
*http://cs-g2-crl.thawte.com/ThawteCSG2.crl0
http://ocsp.thawte.com0
thawte, Inc.1(0&
Certification Services Division1806
/(c) 2006 thawte, Inc. - For authorized use only10
thawte Primary Root CA0
100208000000Z
200207235959Z0J1
Thawte, Inc.1$0"
Thawte Code Signing CA - G20
#http://crl.thawte.com/ThawtePCA.crl0
http://ocsp.thawte.com0
VeriSignMPKI-2-100
Symantec Corporation100.
'Symantec Time Stamping Services CA - G20
121018000000Z
201229235959Z0b1
Symantec Corporation1402
+Symantec Time Stamping Services Signer - G40
http://ts-ocsp.ws.symantec.com07
+http://ts-aia.ws.symantec.com/tss-ca-g2.cer0<
+http://ts-crl.ws.symantec.com/tss-ca-g2.crl0(
TimeStamp-2048-20
Thawte, Inc.1$0"
Thawte Code Signing CA - G2
Symantec Corporation100.
'Symantec Time Stamping Services CA - G2
140320074151Z0#
*1M8Y>
Antivirus Signature
Bkav Clean
MicroWorld-eScan Clean
nProtect Clean
CMC Clean
CAT-QuickHeal Clean
McAfee Adware-Amonetize!2E20E446943E
Malwarebytes PUP.Optional.Amonetize.A
AegisLab Clean
TheHacker Clean
K7GW Clean
K7AntiVirus Clean
NANO-Antivirus Clean
F-Prot Clean
Symantec Clean
Norman Clean
TotalDefense Clean
TrendMicro-HouseCall Clean
Avast Win32:Amonetize-N [PUP]
ClamAV Clean
Kaspersky not-a-virus:HEUR:AdWare.Win32.Amonetize.heur
BitDefender Clean
Agnitum Clean
ViRobot Clean
Ad-Aware Clean
Sophos Clean
Comodo Clean
F-Secure Clean
DrWeb Adware.Downware.2250
VIPRE Amonetize (fs)
AntiVir ADWARE/Adware.Gen2
TrendMicro Clean
McAfee-GW-Edition Adware-Amonetize!2E20E446943E
Emsisoft Clean
Jiangmin Clean
Antiy-AVL Clean
Kingsoft Clean
Microsoft Clean
SUPERAntiSpyware Clean
AhnLab-V3 PUP/Win32.Amonetiz
GData Clean
Commtouch Clean
ByteHero Clean
VBA32 Clean
Panda Clean
ESET-NOD32 a variant of Win32/Amonetize.AI
Rising Clean
Ikarus Clean
Fortinet Clean
AVG Generic_r.IT
Baidu-International Clean