anubis left
Anubis - Analysis Report
anubis right

Analysis Report for bf1c61f5dd0cf5b1138c0447d6f4c4ed

Comment on this report

Summary:

Description Risk
Changes security settings of Internet Explorer: This system alteration could seriously affect safety surfing the World Wide Web. medium
Performs File Modification and Destruction: The executable modifies and destructs files which are not temporary. high
Spawns Processes: The executable produces processes during the execution. low
Performs Registry Activities: The executable reads and modifies registry values. It may also create and monitor registry keys. low


Table of Contents

expand all expand all   collapse all collapse all

1. General Information

  - Information about Anubis' invocation  
Time needed: 242 s 
Report created: 03/20/09, 15:27:14 UTC 
Termination reason: Timeout 
Program version: 1.67.0 


  - Popups  
Process Window Name Window Text Screenshot Number of Displayed Times
explorer.exe  Windows Internet Explorer    screenshot

1.a) - Network Activity

  -  HTTP Conversations:  
From ANUBIS:1033 to 165.230.110.130:80 - [zlab.rutgers.edu]
Request: GET /topo.jpg
Response: 200 "OK"

  -  Unknown UDP Traffic:  
from ANUBIS:1025 to 192.168.0.1:53
State: Normal establishment and termination - Transferred outbound Bytes: 34 - Transferred inbound Bytes: 147

2. sample.exe

  - General information about this executable  
Analysis Reason: Primary Analysis Subject 
Filename: sample.exe 
MD5: bf1c61f5dd0cf5b1138c0447d6f4c4ed 
SHA-1: 87d6862cf788b6afd45319af24ce395956143556 
File Size: 64512 Bytes
Command Line: "C:\sample.exe" 
Process-status at analysis end: alive 
Exit Code:

  - Load-time Dlls  
Module Name Base Address Size
C:\​WINDOWS\​system32\​ntdll.dll  0x7C900000  0x000AF000 
C:\​WINDOWS\​system32\​kernel32.dll  0x7C800000  0x000F6000 
C:\​WINDOWS\​system32\​user32.dll  0x7E410000  0x00091000 
C:\​WINDOWS\​system32\​GDI32.dll  0x77F10000  0x00049000 
C:\​WINDOWS\​system32\​advapi32.dll  0x77DD0000  0x0009B000 
C:\​WINDOWS\​system32\​RPCRT4.dll  0x77E70000  0x00092000 
C:\​WINDOWS\​system32\​Secur32.dll  0x77FE0000  0x00011000 
C:\​WINDOWS\​system32\​oleaut32.dll  0x77120000  0x0008B000 
C:\​WINDOWS\​system32\​msvcrt.dll  0x77C10000  0x00058000 
C:\​WINDOWS\​system32\​ole32.dll  0x774E0000  0x0013D000 
C:\​WINDOWS\​system32\​URLMON.DLL  0x42CF0000  0x00127000 
C:\​WINDOWS\​system32\​SHLWAPI.dll  0x77F60000  0x00076000 
C:\​WINDOWS\​system32\​iertutil.dll  0x42990000  0x00045000 
C:\​WINDOWS\​system32\​IMM32.DLL  0x76390000  0x0001D000 
C:\​WINDOWS\​WinSxS\​x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.5512_x-ww_35d4ce83\​comctl32.dll  0x773D0000  0x00103000 

  - Run-time Dlls  
Module Name Base Address Size
C:\​WINDOWS\​system32\​Normaliz.dll  0x00A20000  0x00009000 
C:\​WINDOWS\​system32\​WININET.dll  0x42C10000  0x000CF000 
C:\​WINDOWS\​system32\​ieframe.dll  0x42EF0000  0x005CD000 
C:\​WINDOWS\​system32\​UxTheme.dll  0x5AD70000  0x00038000 
C:\​WINDOWS\​system32\​netapi32.dll  0x5B860000  0x00055000 
C:\​WINDOWS\​system32\​comctl32.dll  0x5D090000  0x0009A000 
C:\​WINDOWS\​system32\​hnetcfg.dll  0x662B0000  0x00058000 
C:\​WINDOWS\​system32\​mswsock.dll  0x71A50000  0x0003F000 
C:\​WINDOWS\​System32\​wshtcpip.dll  0x71A90000  0x00008000 
C:\​WINDOWS\​system32\​WS2HELP.dll  0x71AA0000  0x00008000 
C:\​WINDOWS\​system32\​ws2_32.dll  0x71AB0000  0x00017000 
C:\​WINDOWS\​system32\​MSCTF.dll  0x74720000  0x0004C000 
C:\​WINDOWS\​system32\​HLINK.DLL  0x76820000  0x00015000 
C:\​WINDOWS\​system32\​USERENV.dll  0x769C0000  0x000B4000 
C:\​WINDOWS\​system32\​WINMM.dll  0x76B40000  0x0002D000 
C:\​WINDOWS\​system32\​PSAPI.DLL  0x76BF0000  0x0000B000 
C:\​WINDOWS\​system32\​rtutils.dll  0x76E80000  0x0000E000 
C:\​WINDOWS\​system32\​rasman.dll  0x76E90000  0x00012000 
C:\​WINDOWS\​system32\​TAPI32.dll  0x76EB0000  0x0002F000 
C:\​WINDOWS\​system32\​RASAPI32.dll  0x76EE0000  0x0003C000 
C:\​WINDOWS\​system32\​CLBCATQ.DLL  0x76FD0000  0x0007F000 
C:\​WINDOWS\​system32\​COMRes.dll  0x77050000  0x000C5000 
C:\​WINDOWS\​system32\​appHelp.dll  0x77B40000  0x00022000 
C:\​WINDOWS\​system32\​VERSION.dll  0x77C00000  0x00008000 
C:\​WINDOWS\​system32\​SHELL32.dll  0x7C9C0000  0x00817000 

  - Ikarus Virus Scanner  
Trojan-Downloader.Win32.Delf.ACC (Sig-Id:149648)

2.a) sample.exe - Registry Activities

  - Registry Keys Created:  
HKLM\​Software\​Microsoft\​DownloadManager

  - Registry Values Modified:  
Key Name New Value
HKLM\​Software\​Microsoft\​Windows\​CurrentVersion\​Explorer\​Shell Folders  Common AppData  C:\​Documents and Settings\​All Users\​Application Data 
HKU\​S-1-5-21-1229272821-1004336348-527237240-1003\​Software\​Microsoft\​Windows\​CurrentVersion\​Explorer\​Shell Folders  Cache  C:\​Documents and Settings\​user\​Local Settings\​Temporary Internet Files 
HKU\​S-1-5-21-1229272821-1004336348-527237240-1003\​Software\​Microsoft\​Windows\​CurrentVersion\​Explorer\​Shell Folders  Cookies  C:\​Documents and Settings\​user\​Cookies 
HKU\​S-1-5-21-1229272821-1004336348-527237240-1003\​Software\​Microsoft\​Windows\​CurrentVersion\​Explorer\​Shell Folders  History  C:\​Documents and Settings\​user\​Local Settings\​History 
HKU\​S-1-5-21-1229272821-1004336348-527237240-1003\​Software\​Microsoft\​Windows\​CurrentVersion\​Internet Settings\​ZoneMap\​  info AutoDetect 
HKU\​S-1-5-21-1229272821-1004336348-527237240-1003\​Software\​Microsoft\​Windows\​CurrentVersion\​Internet Settings\​ZoneMap\​  info IntranetName 
HKU\​S-1-5-21-1229272821-1004336348-527237240-1003\​Software\​Microsoft\​Windows\​CurrentVersion\​Internet Settings\​ZoneMap\​  info ProxyBypass 
HKU\​S-1-5-21-1229272821-1004336348-527237240-1003\​Software\​Microsoft\​Windows\​CurrentVersion\​Internet Settings\​ZoneMap\​  info UNCAsIntranet 

  - Registry Values Read:  
Key Name Value Times
HKLM\​SOFTWARE\​CLASSES\​CLSID\​{6F237DF9-9DDB-47AD-B218-400D54C286AD}\​INPROCSERVER32    C:\​WINDOWS\​system32\​urlmon.dll 
HKLM\​SOFTWARE\​CLASSES\​CLSID\​{6F237DF9-9DDB-47AD-B218-400D54C286AD}\​INPROCSERVER32  ThreadingModel  Apartment 
HKLM\​SOFTWARE\​CLASSES\​CLSID\​{79EAC9D0-BAF9-11CE-8C82-00AA004BA90B}\​INPROCSERVER32    C:\​WINDOWS\​system32\​hlink.dll 
HKLM\​SOFTWARE\​CLASSES\​CLSID\​{871C5380-42A0-1069-A2EA-08002B30309D}\​INPROCSERVER32    C:\​WINDOWS\​system32\​ieframe.dll 
HKLM\​SOFTWARE\​CLASSES\​CLSID\​{871C5380-42A0-1069-A2EA-08002B30309D}\​INPROCSERVER32  ThreadingModel  Apartment 
HKLM\​SOFTWARE\​CLASSES\​CLSID\​{871C5380-42A0-1069-A2EA-08002B30309D}\​SHELLFOLDER  WantsParseDisplayName   
HKLM\​SOFTWARE\​CLASSES\​CLSID\​{A4741943-6C4B-4CF7-BF44-A0F4207D1330}\​INPROCSERVER32    C:\​WINDOWS\​system32\​urlmon.dll 
HKLM\​SOFTWARE\​CLASSES\​CLSID\​{A4741943-6C4B-4CF7-BF44-A0F4207D1330}\​INPROCSERVER32  ThreadingModel  Apartment 
HKLM\​SOFTWARE\​CLASSES\​CLSID\​{AEB6717E-7E19-11D0-97EE-00C04FD91972}\​INPROCSERVER32    shell32.dll 
HKLM\​SOFTWARE\​CLASSES\​HTTP  URL Protocol   
HKLM\​SOFTWARE\​CLASSES\​HTTP\​SHELL    open 
HKLM\​SOFTWARE\​CLASSES\​HTTP\​SHELL\​OPEN\​COMMAND    "C:\​Program Files\​Internet Explorer\​IEXPLORE.EXE" -nohome 
HKLM\​SOFTWARE\​CLASSES\​HTTP\​SHELL\​OPEN\​DDEEXEC    "%1",,-1,0,,,, 
HKLM\​SOFTWARE\​CLASSES\​HTTP\​SHELL\​OPEN\​DDEEXEC  NoActivateHandler   
HKLM\​SOFTWARE\​CLASSES\​HTTP\​SHELL\​OPEN\​DDEEXEC\​APPLICATION    IExplore 
HKLM\​SOFTWARE\​CLASSES\​HTTP\​SHELL\​OPEN\​DDEEXEC\​TOPIC    WWW_OpenURL 
HKLM\​SOFTWARE\​CLASSES\​INTERFACE\​{000214E6-0000-0000-C000-000000000046}\​PROXYSTUBCLSID32    {bf50b68e-29b8-4386-ae9c-9734d5117cd5} 
HKLM\​SOFTWARE\​CLASSES\​INTERFACE\​{79EAC9C4-BAF9-11CE-8C82-00AA004BA90B}\​PROXYSTUBCLSID32    {B8DA6310-E19B-11D0-933C-00A0C90DCAA9} 
HKLM\​SOFTWARE\​CLASSES\​INTERFACE\​{93F2F68C-1D1B-11D3-A30E-00C04F79ABD1}\​PROXYSTUBCLSID32    {bf50b68e-29b8-4386-ae9c-9734d5117cd5} 
HKLM\​SOFTWARE\​CLASSES\​INTERFACE\​{B722BCCB-4E68-101B-A2BC-00AA00404770}\​PROXYSTUBCLSID32    {B8DA6310-E19B-11D0-933C-00A0C90DCAA9} 
HKLM\​SOFTWARE\​CLASSES\​INTERFACE\​{EAB22AC1-30C1-11CF-A7EB-0000C05BAE0B}\​TYPELIB    {EAB22AC0-30C1-11CF-A7EB-0000C05BAE0B} 
HKLM\​SOFTWARE\​Microsoft\​CTF\​SystemShared\​  CUAS 
HKLM\​SOFTWARE\​Microsoft\​Internet Explorer\​Setup  IExploreLastModifiedHigh  29887276 
HKLM\​SOFTWARE\​Microsoft\​Internet Explorer\​Setup  IExploreLastModifiedLow  2933474304 
HKLM\​SOFTWARE\​Microsoft\​Windows\​CurrentVersion\​App Paths\​IEXPLORE.EXE    C:\​Program Files\​Internet Explorer\​IEXPLORE.EXE 
HKLM\​SOFTWARE\​Microsoft\​Windows\​CurrentVersion\​Internet Settings  EnablePunycode 
HKLM\​SOFTWARE\​Microsoft\​Windows\​CurrentVersion\​Internet Settings  UrlEncoding  0x00000000 
HKLM\​SOFTWARE\​Microsoft\​Windows\​CurrentVersion\​Internet Settings\​5.0\​User Agent\​Post Platform  .NET CLR 1.1.4322   
HKLM\​SOFTWARE\​Microsoft\​Windows\​CurrentVersion\​Internet Settings\​5.0\​User Agent\​Post Platform  .NET CLR 2.0.50727   
HKLM\​SOFTWARE\​Microsoft\​Windows\​CurrentVersion\​Internet Settings\​5.0\​User Agent\​Post Platform  .NET CLR 3.0.04506.30   
HKLM\​SOFTWARE\​Microsoft\​Windows\​CurrentVersion\​Internet Settings\​5.0\​User Agent\​Post Platform  InfoPath.1   
HKLM\​SOFTWARE\​Microsoft\​Windows\​CurrentVersion\​Internet Settings\​User Agent\​UA Tokens     
HKLM\​SOFTWARE\​Microsoft\​Windows\​CurrentVersion\​Internet Settings\​User Agent\​UA Tokens  MSN 2.0   
HKLM\​SOFTWARE\​Microsoft\​Windows\​CurrentVersion\​Internet Settings\​User Agent\​UA Tokens  MSN 2.5   
HKLM\​SYSTEM\​CurrentControlSet\​Services\​Winsock\​Parameters  Transports  0x5400630070006900700000004e0065007400420049004f00530000000000 
HKLM\​SYSTEM\​Setup  SystemSetupInProgress 
HKLM\​SYSTEM\​WPA\​MediaCenter  Installed 
HKLM\​Software\​Classes\​CLSID\​{871c5380-42a0-1069-a2ea-08002b30309d}\​InProcServer32    C:\​WINDOWS\​system32\​ieframe.dll 
HKLM\​Software\​Classes\​CLSID\​{a4741943-6c4b-4cf7-bf44-a0f4207d1330}\​InProcServer32    C:\​WINDOWS\​system32\​urlmon.dll 
HKLM\​Software\​Microsoft\​COM3  Com+Enabled 
HKLM\​Software\​Microsoft\​COM3  REGDBVersion  0x0f00000000000000 
HKLM\​Software\​Microsoft\​Tracing  EnableConsoleTracing 
HKLM\​Software\​Microsoft\​Tracing\​RASAPI32  ConsoleTracingMask  4294901760 
HKLM\​Software\​Microsoft\​Tracing\​RASAPI32  EnableConsoleTracing 
HKLM\​Software\​Microsoft\​Tracing\​RASAPI32  EnableFileTracing 
HKLM\​Software\​Microsoft\​Tracing\​RASAPI32  FileDirectory  %windir%\​tracing 
HKLM\​Software\​Microsoft\​Tracing\​RASAPI32  FileTracingMask  4294901760 
HKLM\​Software\​Microsoft\​Tracing\​RASAPI32  MaxFileSize  1048576 
HKLM\​Software\​Microsoft\​Windows NT\​CurrentVersion\​ProfileList  AllUsersProfile  All Users 
HKLM\​Software\​Microsoft\​Windows NT\​CurrentVersion\​ProfileList  DefaultUserProfile  Default User 
HKLM\​Software\​Microsoft\​Windows NT\​CurrentVersion\​ProfileList  ProfilesDirectory  %SystemDrive%\​Documents and Settings 
HKLM\​Software\​Microsoft\​Windows NT\​CurrentVersion\​ProfileList\​S-1-5-21-1229272821-1004336348-527237240-1003  ProfileImagePath  %SystemDrive%\​Documents and Settings\​user 
HKLM\​Software\​Microsoft\​Windows\​CurrentVersion  CommonFilesDir  C:\​Program Files\​Common Files 
HKLM\​Software\​Microsoft\​Windows\​CurrentVersion  ProgramFilesDir  C:\​Program Files 
HKLM\​Software\​Microsoft\​Windows\​CurrentVersion\​App Paths\​IEXPLORE.EXE  PATH  C:\​Program Files\​Internet Explorer; 
HKLM\​Software\​Microsoft\​Windows\​CurrentVersion\​Explorer\​ShellExecuteHooks  {AEB6717E-7E19-11d0-97EE-00C04FD91972}   
HKLM\​Software\​Microsoft\​Windows\​CurrentVersion\​Explorer\​User Shell Folders  Common AppData  %ALLUSERSPROFILE%\​Application Data 
HKLM\​Software\​Microsoft\​Windows\​CurrentVersion\​Internet Settings\​5.0\​Cache\​Content  PerUserItem 
HKLM\​Software\​Microsoft\​Windows\​CurrentVersion\​Internet Settings\​5.0\​Cache\​Cookies  PerUserItem 
HKLM\​Software\​Microsoft\​Windows\​CurrentVersion\​Internet Settings\​5.0\​Cache\​History  PerUserItem 
HKLM\​Software\​Microsoft\​Windows\​CurrentVersion\​Internet Settings\​ZoneMap\​Domains\​\​msn.com     
HKLM\​Software\​Microsoft\​Windows\​CurrentVersion\​Internet Settings\​ZoneMap\​Domains\​\​msn.com\​related  http 
HKLM\​Software\​Policies\​Microsoft\​Windows\​Safer\​CodeIdentifiers  AuthenticodeEnabled 
HKLM\​Software\​Policies\​Microsoft\​Windows\​Safer\​CodeIdentifiers  DefaultLevel  262144 
HKLM\​Software\​Policies\​Microsoft\​Windows\​Safer\​CodeIdentifiers  PolicyScope 
HKLM\​Software\​Policies\​Microsoft\​Windows\​Safer\​CodeIdentifiers  TransparentEnabled 
HKLM\​Software\​Policies\​Microsoft\​Windows\​Safer\​CodeIdentifiers\​0\​Hashes\​{349d35ab-37b5-462f-9b89-edd5fbde1328}  HashAlg  32771 
HKLM\​Software\​Policies\​Microsoft\​Windows\​Safer\​CodeIdentifiers\​0\​Hashes\​{349d35ab-37b5-462f-9b89-edd5fbde1328}  ItemData  0x5eab304f957a49896a006c1c31154015 
HKLM\​Software\​Policies\​Microsoft\​Windows\​Safer\​CodeIdentifiers\​0\​Hashes\​{349d35ab-37b5-462f-9b89-edd5fbde1328}  ItemSize  779 
HKLM\​Software\​Policies\​Microsoft\​Windows\​Safer\​CodeIdentifiers\​0\​Hashes\​{349d35ab-37b5-462f-9b89-edd5fbde1328}  SaferFlags 
HKLM\​Software\​Policies\​Microsoft\​Windows\​Safer\​CodeIdentifiers\​0\​Hashes\​{7fb9cd2e-3076-4df9-a57b-b813f72dbb91}  HashAlg  32771 
HKLM\​Software\​Policies\​Microsoft\​Windows\​Safer\​CodeIdentifiers\​0\​Hashes\​{7fb9cd2e-3076-4df9-a57b-b813f72dbb91}  ItemData  0x67b0d48b343a3fd3bce9dc646704f394 
HKLM\​Software\​Policies\​Microsoft\​Windows\​Safer\​CodeIdentifiers\​0\​Hashes\​{7fb9cd2e-3076-4df9-a57b-b813f72dbb91}  ItemSize  517 
HKLM\​Software\​Policies\​Microsoft\​Windows\​Safer\​CodeIdentifiers\​0\​Hashes\​{7fb9cd2e-3076-4df9-a57b-b813f72dbb91}  SaferFlags 
HKLM\​Software\​Policies\​Microsoft\​Windows\​Safer\​CodeIdentifiers\​0\​Hashes\​{81d1fe15-dd9d-4762-b16d-7c29ddecae3f}  HashAlg  32771 
HKLM\​Software\​Policies\​Microsoft\​Windows\​Safer\​CodeIdentifiers\​0\​Hashes\​{81d1fe15-dd9d-4762-b16d-7c29ddecae3f}  ItemData  0x327802dcfef8c893dc8ab006dd847d1d 
HKLM\​Software\​Policies\​Microsoft\​Windows\​Safer\​CodeIdentifiers\​0\​Hashes\​{81d1fe15-dd9d-4762-b16d-7c29ddecae3f}  ItemSize  918 
HKLM\​Software\​Policies\​Microsoft\​Windows\​Safer\​CodeIdentifiers\​0\​Hashes\​{81d1fe15-dd9d-4762-b16d-7c29ddecae3f}  SaferFlags 
HKLM\​Software\​Policies\​Microsoft\​Windows\​Safer\​CodeIdentifiers\​0\​Hashes\​{94e3e076-8f53-42a5-8411-085bcc18a68d}  HashAlg  32771 
HKLM\​Software\​Policies\​Microsoft\​Windows\​Safer\​CodeIdentifiers\​0\​Hashes\​{94e3e076-8f53-42a5-8411-085bcc18a68d}  ItemData  0xbd9a2adb42ebd8560e250e4df8162f67 
HKLM\​Software\​Policies\​Microsoft\​Windows\​Safer\​CodeIdentifiers\​0\​Hashes\​{94e3e076-8f53-42a5-8411-085bcc18a68d}  ItemSize  229 
HKLM\​Software\​Policies\​Microsoft\​Windows\​Safer\​CodeIdentifiers\​0\​Hashes\​{94e3e076-8f53-42a5-8411-085bcc18a68d}  SaferFlags 
HKLM\​Software\​Policies\​Microsoft\​Windows\​Safer\​CodeIdentifiers\​0\​Hashes\​{dc971ee5-44eb-4fe4-ae2e-b91490411bfc}  HashAlg  32771 
HKLM\​Software\​Policies\​Microsoft\​Windows\​Safer\​CodeIdentifiers\​0\​Hashes\​{dc971ee5-44eb-4fe4-ae2e-b91490411bfc}  ItemData  0x386b085f84ecf669d36b956a22c01e80 
HKLM\​Software\​Policies\​Microsoft\​Windows\​Safer\​CodeIdentifiers\​0\​Hashes\​{dc971ee5-44eb-4fe4-ae2e-b91490411bfc}  ItemSize  370 
HKLM\​Software\​Policies\​Microsoft\​Windows\​Safer\​CodeIdentifiers\​0\​Hashes\​{dc971ee5-44eb-4fe4-ae2e-b91490411bfc}  SaferFlags 
HKLM\​Software\​Policies\​Microsoft\​Windows\​Safer\​CodeIdentifiers\​0\​Paths\​{dda3f824-d8cb-441b-834d-be2efd2c1a33}  ItemData  %HKEY_CURRENT_USER\​Software\​Microsoft\​Windows\​CurrentVersion\​Explorer\​Shell Folders\​Cache%OLK* 
HKLM\​Software\​Policies\​Microsoft\​Windows\​Safer\​CodeIdentifiers\​0\​Paths\​{dda3f824-d8cb-441b-834d-be2efd2c1a33}  SaferFlags 
HKLM\​System\​CurrentControlSet\​Control\​ComputerName\​ActiveComputerName  ComputerName  USER 
HKLM\​System\​CurrentControlSet\​Control\​MediaProperties\​PrivateProperties\​Joystick\​Winmm  wheel 
HKLM\​System\​CurrentControlSet\​Control\​ProductOptions  ProductType  WinNT 
HKLM\​System\​CurrentControlSet\​Control\​Session Manager\​Environment  ComSpec  %SystemRoot%\​system32\​cmd.exe 
HKLM\​System\​CurrentControlSet\​Control\​Session Manager\​Environment  FP_NO_HOST_CHECK  NO 
HKLM\​System\​CurrentControlSet\​Control\​Session Manager\​Environment  NUMBER_OF_PROCESSORS 
HKLM\​System\​CurrentControlSet\​Control\​Session Manager\​Environment  OS  Windows_NT 
HKLM\​System\​CurrentControlSet\​Control\​Session Manager\​Environment  PATHEXT  .COM;.EXE;.BAT;.CMD;.VBS;.VBE;.JS;.JSE;.WSF;.WSH 
HKLM\​System\​CurrentControlSet\​Control\​Session Manager\​Environment  PROCESSOR_ARCHITECTURE  x86 
HKLM\​System\​CurrentControlSet\​Control\​Session Manager\​Environment  PROCESSOR_IDENTIFIER  x86 Family 6 Model 3 Stepping 3, GenuineIntel 
HKLM\​System\​CurrentControlSet\​Control\​Session Manager\​Environment  PROCESSOR_LEVEL 
HKLM\​System\​CurrentControlSet\​Control\​Session Manager\​Environment  PROCESSOR_REVISION  0303 
HKLM\​System\​CurrentControlSet\​Control\​Session Manager\​Environment  Path  %SystemRoot%\​system32;%SystemRoot%;%SystemRoot%\​System32\​Wbem 
HKLM\​System\​CurrentControlSet\​Control\​Session Manager\​Environment  TEMP  %SystemRoot%\​TEMP 
HKLM\​System\​CurrentControlSet\​Control\​Session Manager\​Environment  TMP  %SystemRoot%\​TEMP 
HKLM\​System\​CurrentControlSet\​Control\​Session Manager\​Environment  windir  %SystemRoot% 
HKLM\​System\​CurrentControlSet\​Services\​Tcpip\​Parameters\​Winsock  HelperDllName  %SystemRoot%\​System32\​wshtcpip.dll 
HKLM\​System\​CurrentControlSet\​Services\​Tcpip\​Parameters\​Winsock  Mapping  0x0b0000000300000002000000010000000600000002000000010000000000 
HKLM\​System\​CurrentControlSet\​Services\​Tcpip\​Parameters\​Winsock  MaxSockaddrLength  16 
HKLM\​System\​CurrentControlSet\​Services\​Tcpip\​Parameters\​Winsock  MinSockaddrLength  16 
HKLM\​System\​CurrentControlSet\​Services\​Tcpip\​Parameters\​Winsock  UseDelayedAcceptance 
HKLM\​System\​CurrentControlSet\​Services\​WinSock2\​Parameters  WinSock_Registry_Version  2.0 
HKLM\​System\​CurrentControlSet\​Services\​WinSock2\​Parameters\​NameSpace_Catalog5  Num_Catalog_Entries 
HKLM\​System\​CurrentControlSet\​Services\​WinSock2\​Parameters\​NameSpace_Catalog5  Serial_Access_Num 
HKLM\​System\​CurrentControlSet\​Services\​WinSock2\​Parameters\​NameSpace_Catalog5\​Catalog_Entries\​000000000001  DisplayString  Tcpip 
HKLM\​System\​CurrentControlSet\​Services\​WinSock2\​Parameters\​NameSpace_Catalog5\​Catalog_Entries\​000000000001  Enabled 
HKLM\​System\​CurrentControlSet\​Services\​WinSock2\​Parameters\​NameSpace_Catalog5\​Catalog_Entries\​000000000001  LibraryPath  %SystemRoot%\​System32\​mswsock.dll 
HKLM\​System\​CurrentControlSet\​Services\​WinSock2\​Parameters\​NameSpace_Catalog5\​Catalog_Entries\​000000000001  ProviderId  0x409d05229e7ecf11ae5a00aa00a7112b 
HKLM\​System\​CurrentControlSet\​Services\​WinSock2\​Parameters\​NameSpace_Catalog5\​Catalog_Entries\​000000000001  StoresServiceClassInfo 
HKLM\​System\​CurrentControlSet\​Services\​WinSock2\​Parameters\​NameSpace_Catalog5\​Catalog_Entries\​000000000001  SupportedNameSpace  12 
HKLM\​System\​CurrentControlSet\​Services\​WinSock2\​Parameters\​NameSpace_Catalog5\​Catalog_Entries\​000000000001  Version 
HKLM\​System\​CurrentControlSet\​Services\​WinSock2\​Parameters\​NameSpace_Catalog5\​Catalog_Entries\​000000000002  DisplayString  NTDS 
HKLM\​System\​CurrentControlSet\​Services\​WinSock2\​Parameters\​NameSpace_Catalog5\​Catalog_Entries\​000000000002  Enabled 
HKLM\​System\​CurrentControlSet\​Services\​WinSock2\​Parameters\​NameSpace_Catalog5\​Catalog_Entries\​000000000002  LibraryPath  %SystemRoot%\​System32\​winrnr.dll 
HKLM\​System\​CurrentControlSet\​Services\​WinSock2\​Parameters\​NameSpace_Catalog5\​Catalog_Entries\​000000000002  ProviderId  0xee37263b80e5cf11a55500c04fd8d4ac 
HKLM\​System\​CurrentControlSet\​Services\​WinSock2\​Parameters\​NameSpace_Catalog5\​Catalog_Entries\​000000000002  StoresServiceClassInfo 
HKLM\​System\​CurrentControlSet\​Services\​WinSock2\​Parameters\​NameSpace_Catalog5\​Catalog_Entries\​000000000002  SupportedNameSpace  32 
HKLM\​System\​CurrentControlSet\​Services\​WinSock2\​Parameters\​NameSpace_Catalog5\​Catalog_Entries\​000000000002  Version 
HKLM\​System\​CurrentControlSet\​Services\​WinSock2\​Parameters\​NameSpace_Catalog5\​Catalog_Entries\​000000000003  DisplayString  Network Location Awareness (NLA) Namespace 
HKLM\​System\​CurrentControlSet\​Services\​WinSock2\​Parameters\​NameSpace_Catalog5\​Catalog_Entries\​000000000003  Enabled 
HKLM\​System\​CurrentControlSet\​Services\​WinSock2\​Parameters\​NameSpace_Catalog5\​Catalog_Entries\​000000000003  LibraryPath  %SystemRoot%\​System32\​mswsock.dll 
HKLM\​System\​CurrentControlSet\​Services\​WinSock2\​Parameters\​NameSpace_Catalog5\​Catalog_Entries\​000000000003  ProviderId  0x3a244266a83ba64abaa52e0bd71fdd83 
HKLM\​System\​CurrentControlSet\​Services\​WinSock2\​Parameters\​NameSpace_Catalog5\​Catalog_Entries\​000000000003  StoresServiceClassInfo 
HKLM\​System\​CurrentControlSet\​Services\​WinSock2\​Parameters\​NameSpace_Catalog5\​Catalog_Entries\​000000000003  SupportedNameSpace  15 
HKLM\​System\​CurrentControlSet\​Services\​WinSock2\​Parameters\​NameSpace_Catalog5\​Catalog_Entries\​000000000003  Version 
HKLM\​System\​CurrentControlSet\​Services\​WinSock2\​Parameters\​Protocol_Catalog9  Next_Catalog_Entry_ID  1012 
HKLM\​System\​CurrentControlSet\​Services\​WinSock2\​Parameters\​Protocol_Catalog9  Num_Catalog_Entries  11 
HKLM\​System\​CurrentControlSet\​Services\​WinSock2\​Parameters\​Protocol_Catalog9  Serial_Access_Num 
HKLM\​System\​CurrentControlSet\​Services\​WinSock2\​Parameters\​Protocol_Catalog9\​Catalog_Entries\​000000000001  PackedCatalogItem  %SystemRoot%\​system32\​mswsock. 
HKLM\​System\​CurrentControlSet\​Services\​WinSock2\​Parameters\​Protocol_Catalog9\​Catalog_Entries\​000000000002  PackedCatalogItem  %SystemRoot%\​system32\​mswsock. 
HKLM\​System\​CurrentControlSet\​Services\​WinSock2\​Parameters\​Protocol_Catalog9\​Catalog_Entries\​000000000003  PackedCatalogItem  %SystemRoot%\​system32\​mswsock. 
HKLM\​System\​CurrentControlSet\​Services\​WinSock2\​Parameters\​Protocol_Catalog9\​Catalog_Entries\​000000000004  PackedCatalogItem  %SystemRoot%\​system32\​rsvpsp.d 
HKLM\​System\​CurrentControlSet\​Services\​WinSock2\​Parameters\​Protocol_Catalog9\​Catalog_Entries\​000000000005  PackedCatalogItem  %SystemRoot%\​system32\​rsvpsp.d 
HKLM\​System\​CurrentControlSet\​Services\​WinSock2\​Parameters\​Protocol_Catalog9\​Catalog_Entries\​000000000006  PackedCatalogItem  %SystemRoot%\​system32\​mswsock. 
HKLM\​System\​CurrentControlSet\​Services\​WinSock2\​Parameters\​Protocol_Catalog9\​Catalog_Entries\​000000000007  PackedCatalogItem  %SystemRoot%\​system32\​mswsock. 
HKLM\​System\​CurrentControlSet\​Services\​WinSock2\​Parameters\​Protocol_Catalog9\​Catalog_Entries\​000000000008  PackedCatalogItem  %SystemRoot%\​system32\​mswsock. 
HKLM\​System\​CurrentControlSet\​Services\​WinSock2\​Parameters\​Protocol_Catalog9\​Catalog_Entries\​000000000009  PackedCatalogItem  %SystemRoot%\​system32\​mswsock. 
HKLM\​System\​CurrentControlSet\​Services\​WinSock2\​Parameters\​Protocol_Catalog9\​Catalog_Entries\​000000000010  PackedCatalogItem  %SystemRoot%\​system32\​mswsock. 
HKLM\​System\​CurrentControlSet\​Services\​WinSock2\​Parameters\​Protocol_Catalog9\​Catalog_Entries\​000000000011  PackedCatalogItem  %SystemRoot%\​system32\​mswsock. 
HKLM\​System\​Setup  SystemSetupInProgress 
HKU\​S-1-5-21-1229272821-1004336348-527237240-1003\​Environment  TEMP  %USERPROFILE%\​Local Settings\​Temp 
HKU\​S-1-5-21-1229272821-1004336348-527237240-1003\​Environment  TMP  %USERPROFILE%\​Local Settings\​Temp 
HKU\​S-1-5-21-1229272821-1004336348-527237240-1003\​SOFTWARE\​Microsoft\​Windows\​CurrentVersion\​Internet Settings  CertificateRevocation 
HKU\​S-1-5-21-1229272821-1004336348-527237240-1003\​SOFTWARE\​Microsoft\​Windows\​CurrentVersion\​Internet Settings  DisableCachingOfSSLPages 
HKU\​S-1-5-21-1229272821-1004336348-527237240-1003\​SOFTWARE\​Microsoft\​Windows\​CurrentVersion\​Internet Settings  EnableHttp1_1 
HKU\​S-1-5-21-1229272821-1004336348-527237240-1003\​SOFTWARE\​Microsoft\​Windows\​CurrentVersion\​Internet Settings  EnableNegotiate 
HKU\​S-1-5-21-1229272821-1004336348-527237240-1003\​SOFTWARE\​Microsoft\​Windows\​CurrentVersion\​Internet Settings  MimeExclusionListForCache  multipart/mixed multipart/x-mixed-replace multipart/x-byteranges  
HKU\​S-1-5-21-1229272821-1004336348-527237240-1003\​SOFTWARE\​Microsoft\​Windows\​CurrentVersion\​Internet Settings  SecureProtocols  160 
HKU\​S-1-5-21-1229272821-1004336348-527237240-1003\​SOFTWARE\​Microsoft\​Windows\​CurrentVersion\​Internet Settings  User Agent  Mozilla/4.0 (compatible; MSIE 7.0; Win32) 
HKU\​S-1-5-21-1229272821-1004336348-527237240-1003\​SOFTWARE\​Microsoft\​Windows\​CurrentVersion\​Internet Settings  WarnOnPost  0x01000000 
HKU\​S-1-5-21-1229272821-1004336348-527237240-1003\​SOFTWARE\​Microsoft\​Windows\​CurrentVersion\​Internet Settings  WarnOnZoneCrossing 
HKU\​S-1-5-21-1229272821-1004336348-527237240-1003\​Software\​Microsoft\​Windows NT\​CurrentVersion\​Winlogon  ParseAutoexec 
HKU\​S-1-5-21-1229272821-1004336348-527237240-1003\​Software\​Microsoft\​Windows\​CurrentVersion\​Explorer\​Shell Folders  Cache  C:\​Documents and Settings\​user\​Local Settings\​Temporary Internet Files 
HKU\​S-1-5-21-1229272821-1004336348-527237240-1003\​Software\​Microsoft\​Windows\​CurrentVersion\​Explorer\​User Shell Folders  Cache  %USERPROFILE%\​Local Settings\​Temporary Internet Files 
HKU\​S-1-5-21-1229272821-1004336348-527237240-1003\​Software\​Microsoft\​Windows\​CurrentVersion\​Explorer\​User Shell Folders  Cookies  %USERPROFILE%\​Cookies 
HKU\​S-1-5-21-1229272821-1004336348-527237240-1003\​Software\​Microsoft\​Windows\​CurrentVersion\​Explorer\​User Shell Folders  History  %USERPROFILE%\​Local Settings\​History 
HKU\​S-1-5-21-1229272821-1004336348-527237240-1003\​Software\​Microsoft\​Windows\​CurrentVersion\​Explorer\​User Shell Folders  Local Settings  %USERPROFILE%\​Local Settings 
HKU\​S-1-5-21-1229272821-1004336348-527237240-1003\​Software\​Microsoft\​Windows\​CurrentVersion\​Explorer\​User Shell Folders  Personal  %USERPROFILE%\​My Documents 
HKU\​S-1-5-21-1229272821-1004336348-527237240-1003\​Software\​Microsoft\​Windows\​CurrentVersion\​Internet Settings\​5.0\​Cache  Signature  Client UrlCache MMF Ver 5.2 
HKU\​S-1-5-21-1229272821-1004336348-527237240-1003\​Software\​Microsoft\​Windows\​CurrentVersion\​Internet Settings\​5.0\​Cache\​Content  CacheLimit  163410 
HKU\​S-1-5-21-1229272821-1004336348-527237240-1003\​Software\​Microsoft\​Windows\​CurrentVersion\​Internet Settings\​5.0\​Cache\​Content  CachePrefix   
HKU\​S-1-5-21-1229272821-1004336348-527237240-1003\​Software\​Microsoft\​Windows\​CurrentVersion\​Internet Settings\​5.0\​Cache\​Cookies  CacheLimit  8192 
HKU\​S-1-5-21-1229272821-1004336348-527237240-1003\​Software\​Microsoft\​Windows\​CurrentVersion\​Internet Settings\​5.0\​Cache\​Cookies  CachePrefix  Cookie: 
HKU\​S-1-5-21-1229272821-1004336348-527237240-1003\​Software\​Microsoft\​Windows\​CurrentVersion\​Internet Settings\​5.0\​Cache\​Extensible Cache\​MSHist012008051620080517  CacheLimit  8192 
HKU\​S-1-5-21-1229272821-1004336348-527237240-1003\​Software\​Microsoft\​Windows\​CurrentVersion\​Internet Settings\​5.0\​Cache\​Extensible Cache\​MSHist012008051620080517  CacheOptions  11 
HKU\​S-1-5-21-1229272821-1004336348-527237240-1003\​Software\​Microsoft\​Windows\​CurrentVersion\​Internet Settings\​5.0\​Cache\​Extensible Cache\​MSHist012008051620080517  CachePath  %USERPROFILE%\​Local Settings\​History\​History.IE5\​MSHist012008051620080517 
HKU\​S-1-5-21-1229272821-1004336348-527237240-1003\​Software\​Microsoft\​Windows\​CurrentVersion\​Internet Settings\​5.0\​Cache\​Extensible Cache\​MSHist012008051620080517  CachePrefix  :2008051620080517:  
HKU\​S-1-5-21-1229272821-1004336348-527237240-1003\​Software\​Microsoft\​Windows\​CurrentVersion\​Internet Settings\​5.0\​Cache\​Extensible Cache\​MSHist012008051620080517  CacheRepair 
HKU\​S-1-5-21-1229272821-1004336348-527237240-1003\​Software\​Microsoft\​Windows\​CurrentVersion\​Internet Settings\​5.0\​Cache\​Extensible Cache\​UserData  CacheLimit  1000 
HKU\​S-1-5-21-1229272821-1004336348-527237240-1003\​Software\​Microsoft\​Windows\​CurrentVersion\​Internet Settings\​5.0\​Cache\​Extensible Cache\​UserData  CacheOptions 
HKU\​S-1-5-21-1229272821-1004336348-527237240-1003\​Software\​Microsoft\​Windows\​CurrentVersion\​Internet Settings\​5.0\​Cache\​Extensible Cache\​UserData  CachePath  %USERPROFILE%\​UserData 
HKU\​S-1-5-21-1229272821-1004336348-527237240-1003\​Software\​Microsoft\​Windows\​CurrentVersion\​Internet Settings\​5.0\​Cache\​Extensible Cache\​UserData  CachePrefix  UserData 
HKU\​S-1-5-21-1229272821-1004336348-527237240-1003\​Software\​Microsoft\​Windows\​CurrentVersion\​Internet Settings\​5.0\​Cache\​Extensible Cache\​UserData  CacheRepair 
HKU\​S-1-5-21-1229272821-1004336348-527237240-1003\​Software\​Microsoft\​Windows\​CurrentVersion\​Internet Settings\​5.0\​Cache\​Extensible Cache\​feedplat  CacheLimit  8192 
HKU\​S-1-5-21-1229272821-1004336348-527237240-1003\​Software\​Microsoft\​Windows\​CurrentVersion\​Internet Settings\​5.0\​Cache\​Extensible Cache\​feedplat  CacheOptions 
HKU\​S-1-5-21-1229272821-1004336348-527237240-1003\​Software\​Microsoft\​Windows\​CurrentVersion\​Internet Settings\​5.0\​Cache\​Extensible Cache\​feedplat  CachePath  %USERPROFILE%\​Local Settings\​Application Data\​Microsoft\​Feeds Cache 
HKU\​S-1-5-21-1229272821-1004336348-527237240-1003\​Software\​Microsoft\​Windows\​CurrentVersion\​Internet Settings\​5.0\​Cache\​Extensible Cache\​feedplat  CachePrefix  feedplat: 
HKU\​S-1-5-21-1229272821-1004336348-527237240-1003\​Software\​Microsoft\​Windows\​CurrentVersion\​Internet Settings\​5.0\​Cache\​Extensible Cache\​feedplat  CacheRepair 
HKU\​S-1-5-21-1229272821-1004336348-527237240-1003\​Software\​Microsoft\​Windows\​CurrentVersion\​Internet Settings\​5.0\​Cache\​History  CacheLimit  8192 
HKU\​S-1-5-21-1229272821-1004336348-527237240-1003\​Software\​Microsoft\​Windows\​CurrentVersion\​Internet Settings\​5.0\​Cache\​History  CachePrefix  Visited: 
HKU\​S-1-5-21-1229272821-1004336348-527237240-1003\​Software\​Microsoft\​Windows\​CurrentVersion\​Internet Settings\​ZoneMap\​  AutoDetect 
HKU\​S-1-5-21-1229272821-1004336348-527237240-1003\​Software\​Microsoft\​Windows\​CurrentVersion\​Internet Settings\​ZoneMap\​\​ProtocolDefaults\​     
HKU\​S-1-5-21-1229272821-1004336348-527237240-1003\​Software\​Microsoft\​Windows\​CurrentVersion\​Internet Settings\​ZoneMap\​\​ProtocolDefaults\​  @ivt 
HKU\​S-1-5-21-1229272821-1004336348-527237240-1003\​Software\​Microsoft\​Windows\​CurrentVersion\​Internet Settings\​ZoneMap\​\​ProtocolDefaults\​  file 
HKU\​S-1-5-21-1229272821-1004336348-527237240-1003\​Software\​Microsoft\​Windows\​CurrentVersion\​Internet Settings\​ZoneMap\​\​ProtocolDefaults\​  ftp 
HKU\​S-1-5-21-1229272821-1004336348-527237240-1003\​Software\​Microsoft\​Windows\​CurrentVersion\​Internet Settings\​ZoneMap\​\​ProtocolDefaults\​  http 
HKU\​S-1-5-21-1229272821-1004336348-527237240-1003\​Software\​Microsoft\​Windows\​CurrentVersion\​Internet Settings\​ZoneMap\​\​ProtocolDefaults\​  https 
HKU\​S-1-5-21-1229272821-1004336348-527237240-1003\​Software\​Microsoft\​Windows\​CurrentVersion\​Internet Settings\​ZoneMap\​\​ProtocolDefaults\​  shell 
HKU\​S-1-5-21-1229272821-1004336348-527237240-1003\​Software\​Microsoft\​Windows\​CurrentVersion\​Internet Settings\​Zones\​0  Flags  33 
HKU\​S-1-5-21-1229272821-1004336348-527237240-1003\​Software\​Microsoft\​Windows\​CurrentVersion\​Internet Settings\​Zones\​1  Flags  475 
HKU\​S-1-5-21-1229272821-1004336348-527237240-1003\​Software\​Microsoft\​Windows\​CurrentVersion\​Internet Settings\​Zones\​2  Flags  71 
HKU\​S-1-5-21-1229272821-1004336348-527237240-1003\​Software\​Microsoft\​Windows\​CurrentVersion\​Internet Settings\​Zones\​3  Flags 
HKU\​S-1-5-21-1229272821-1004336348-527237240-1003\​Software\​Microsoft\​Windows\​CurrentVersion\​Internet Settings\​Zones\​4  Flags 
HKU\​S-1-5-21-1229272821-1004336348-527237240-1003\​Software\​Microsoft\​Windows\​CurrentVersion\​Shell Extensions\​Cached  {871C5380-42A0-1069-A2EA-08002B30309D} {000214E6-0000-0000-C000-000000000046} 0x401  0x01000000310032003a893fef1312c801 
HKU\​S-1-5-21-1229272821-1004336348-527237240-1003\​Software\​Microsoft\​Windows\​ShellNoRoam\​MUICache  LangID  0x0904 
HKU\​S-1-5-21-1229272821-1004336348-527237240-1003\​Software\​Microsoft\​Windows\​ShellNoRoam\​MUICache\​  C:\Program Files\Internet Explorer\IEXPLORE.EXE  Internet Explorer 
HKU\​S-1-5-21-1229272821-1004336348-527237240-1003\​Volatile Environment  APPDATA  C:\​Documents and Settings\​user\​Application Data 
HKU\​S-1-5-21-1229272821-1004336348-527237240-1003\​Volatile Environment  CLIENTNAME   
HKU\​S-1-5-21-1229272821-1004336348-527237240-1003\​Volatile Environment  HOMEDRIVE  C: 
HKU\​S-1-5-21-1229272821-1004336348-527237240-1003\​Volatile Environment  HOMEPATH  \​Documents and Settings\​user 
HKU\​S-1-5-21-1229272821-1004336348-527237240-1003\​Volatile Environment  HOMESHARE   
HKU\​S-1-5-21-1229272821-1004336348-527237240-1003\​Volatile Environment  LOGONSERVER  \​\​USER 
HKU\​S-1-5-21-1229272821-1004336348-527237240-1003\​Volatile Environment  SESSIONNAME  Console 

  - Monitored Registry Keys:  
Key Name Watch subtree Notify Filter Count
HKLM\​Software\​Classes  Key Change,Value Change 
HKLM\​Software\​Classes\​CLSID  Key Change,Value Change 
HKLM\​Software\​Microsoft\​COM3  Key Change,Value Change 
HKLM\​Software\​Microsoft\​Tracing\​RASAPI32  Attributes Change,Value Change,Security Descriptor Change 
HKLM\​System\​CurrentControlSet\​Services\​WinSock2\​Parameters\​NameSpace_Catalog5  Key Change 
HKLM\​System\​CurrentControlSet\​Services\​WinSock2\​Parameters\​Protocol_Catalog9  Key Change 
HKU  Key Change,Value Change 

2.b) sample.exe - File Activities

  - Files Read:  
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\WINDOWS\Registration\R00000000000f.clb
PIPE\lsarpc
PIPE\wkssvc
c:\autoexec.bat

  - Files Modified:  
PIPE\lsarpcinfo
PIPE\wkssvcinfo
WMIDataDeviceinfo
\Device\Afd\Endpointinfo

  - File System Control Communication:  
File Control Code Times
PIPE\wkssvc  0x0011C017 
PIPE\lsarpc  0x0011C017  11 

  - Device Control Communication:  
File Control Code Times
unnamed file  0x00390008 
WMIDataDevice  0x0022414C 
WMIDataDevice  0x00228144 
WMIDataDevice  0x0022415C 
WMIDataDevice  0x00228168 
\Device\Afd\Endpoint  AFD_GET_INFO (0x0001207B) 
\Device\Afd\Endpoint  AFD_SET_CONTEXT (0x00012047) 
\Device\Afd\Endpoint  AFD_BIND (0x00012003) 
\Device\Afd\Endpoint  AFD_GET_TDI_HANDLES (0x00012037) 
\Device\Afd\Endpoint  AFD_GET_SOCK_NAME (0x0001202F) 
\Device\Afd\Endpoint  AFD_CONNECT (0x00012007) 
\Device\Afd\Endpoint  AFD_SELECT (0x00012024) 

  - Memory Mapped Files:  
File Name
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Program Files\Internet Explorer\iexplore.exe
C:\WINDOWS\System32\wshtcpip.dll
C:\WINDOWS\system32\CLBCATQ.DLL
C:\WINDOWS\system32\COMRes.dll
C:\WINDOWS\system32\HLINK.DLL
C:\WINDOWS\system32\MSCTF.dll
C:\WINDOWS\system32\PSAPI.DLL
C:\WINDOWS\system32\RASAPI32.dll
C:\WINDOWS\system32\SHELL32.dll
C:\WINDOWS\system32\TAPI32.dll
C:\WINDOWS\system32\UxTheme.dll
C:\WINDOWS\system32\WINMM.dll
C:\WINDOWS\system32\WS2HELP.dll
C:\WINDOWS\system32\comctl32.dll
C:\WINDOWS\system32\en-US\ieframe.dll.mui
C:\WINDOWS\system32\hnetcfg.dll
C:\WINDOWS\system32\ieframe.dll
C:\WINDOWS\system32\mswsock.dll
C:\WINDOWS\system32\rasman.dll
C:\WINDOWS\system32\rpcss.dll
C:\WINDOWS\system32\rtutils.dll
C:\WINDOWS\system32\ws2_32.dll
C:\Windows\AppPatch\sysmain.sdb

2.c) sample.exe - Process Activities

  - Processes Created:  
Executable Command Line
C:\Program Files\Internet Explorer\IEXPLORE.EXE   
C:\Program Files\Internet Explorer\IEXPLORE.EXE  "C:\Program Files\Internet Explorer\IEXPLORE.EXE" -nohome 

  - Remote Threads Created:  
Affected Process
C:\Program Files\Internet Explorer\IEXPLORE.EXE

  - Thread Overview:  
Time Number of threads
After 57 seconds
After 184 seconds
After 194 seconds
After 196 seconds
After 216 seconds

  - Foreign Memory Regions Read:  
Process: C:\Program Files\Internet Explorer\IEXPLORE.EXE

  - Foreign Memory Regions Written:  
Process: C:\Program Files\Internet Explorer\IEXPLORE.EXE

2.d) sample.exe - Network Activity

3. IEXPLORE.EXE

  - General information about this executable  
Analysis Reason: Started by sample.exe 
Filename: IEXPLORE.EXE 
MD5: e854d02e4231f704d9be782a424e6d8b 
SHA-1: 2c245f66b8c984ec5d8d65175fe5832e2cfb62f8 
File Size: 625152 Bytes
Command Line: "C:\Program Files\Internet Explorer\IEXPLORE.EXE" -nohome 
Process-status at analysis end: alive 
Exit Code:

  - Load-time Dlls  
Module Name Base Address Size
C:\​WINDOWS\​system32\​ntdll.dll  0x7C900000  0x000AF000 
C:\​WINDOWS\​system32\​kernel32.dll  0x7C800000  0x000F6000 
C:\​WINDOWS\​system32\​ADVAPI32.dll  0x77DD0000  0x0009B000 
C:\​WINDOWS\​system32\​RPCRT4.dll  0x77E70000  0x00092000 
C:\​WINDOWS\​system32\​Secur32.dll  0x77FE0000  0x00011000 
C:\​WINDOWS\​system32\​GDI32.dll  0x77F10000  0x00049000 
C:\​WINDOWS\​system32\​USER32.dll  0x7E410000  0x00091000 
C:\​WINDOWS\​system32\​msvcrt.dll  0x77C10000  0x00058000 
C:\​WINDOWS\​system32\​SHLWAPI.dll  0x77F60000  0x00076000 
C:\​WINDOWS\​system32\​SHELL32.dll  0x7C9C0000  0x00817000 
C:\​WINDOWS\​system32\​ole32.dll  0x774E0000  0x0013D000 
C:\​WINDOWS\​system32\​urlmon.dll  0x42CF0000  0x00127000 
C:\​WINDOWS\​system32\​OLEAUT32.dll  0x77120000  0x0008B000 
C:\​WINDOWS\​system32\​iertutil.dll  0x42990000  0x00045000 
C:\​WINDOWS\​system32\​VERSION.dll  0x77C00000  0x00008000 
C:\​WINDOWS\​system32\​IMM32.DLL  0x76390000  0x0001D000 
C:\​WINDOWS\​WinSxS\​x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.5512_x-ww_35d4ce83\​comctl32.dll  0x773D0000  0x00103000 
C:\​WINDOWS\​system32\​comctl32.dll  0x5D090000  0x0009A000 

  - Run-time Dlls  
Module Name Base Address Size
C:\​WINDOWS\​system32\​xpsp2res.dll  0x00BC0000  0x002C5000 
C:\​WINDOWS\​system32\​Normaliz.dll  0x018A0000  0x00009000 
C:\​Program Files\​Microsoft Office\​OFFICE11\​msohev.dll  0x325C0000  0x00012000 
C:\​WINDOWS\​system32\​WININET.dll  0x42C10000  0x000CF000 
C:\​WINDOWS\​system32\​IEFRAME.dll  0x42EF0000  0x005CD000 
C:\​WINDOWS\​system32\​xmllite.dll  0x47060000  0x00021000 
C:\​WINDOWS\​WinSxS\​x86_Microsoft.Windows.GdiPlus_6595b64144ccf1df_1.0.2600.5512_x-ww_dfb54e0c\​gdiplus.dll  0x4EC50000  0x001A6000 
C:\​WINDOWS\​system32\​UxTheme.dll  0x5AD70000  0x00038000 
C:\​WINDOWS\​system32\​IEUI.dll  0x5DFF0000  0x0002F000 
C:\​Program Files\​Internet Explorer\​ieproxy.dll  0x61930000  0x0004A000 
C:\​Program Files\​Java\​jre1.6.0_03\​bin\​ssv.dll  0x6D7C0000  0x00079000 
C:\​WINDOWS\​system32\​WS2HELP.dll  0x71AA0000  0x00008000 
C:\​WINDOWS\​system32\​ws2_32.dll  0x71AB0000  0x00017000 
C:\​WINDOWS\​system32\​msimtf.dll  0x746F0000  0x0002A000 
C:\​WINDOWS\​system32\​MSCTF.dll  0x74720000  0x0004C000 
C:\​WINDOWS\​system32\​msctfime.ime  0x755C0000  0x0002E000 
C:\​WINDOWS\​system32\​MLANG.dll  0x75CF0000  0x00091000 
C:\​WINDOWS\​system32\​MSIMG32.dll  0x76380000  0x00005000 
C:\​WINDOWS\​System32\​CSCDLL.dll  0x76600000  0x0001D000 
C:\​WINDOWS\​system32\​PSAPI.DLL  0x76BF0000  0x0000B000 
C:\​Program Files\​Internet Explorer\​custsat.dll  0x76CC0000  0x0000B000 
C:\​WINDOWS\​system32\​CLBCATQ.DLL  0x76FD0000  0x0007F000 
C:\​WINDOWS\​system32\​COMRes.dll  0x77050000  0x000C5000 
C:\​WINDOWS\​system32\​SETUPAPI.dll  0x77920000  0x000F3000 
C:\​WINDOWS\​System32\​cscui.dll  0x77A20000  0x00054000 
C:\​WINDOWS\​system32\​apphelp.dll  0x77B40000  0x00022000 
C:\​Program Files\​Java\​jre1.6.0_03\​bin\​MSVCR71.dll  0x7C340000  0x00056000 

3.a) IEXPLORE.EXE - Registry Activities

  - Registry Keys Created:  
HKU\​S-1-5-21-1229272821-1004336348-527237240-1003\​SOFTWARE\​Microsoft\​CTF\​TIP\​{1188450c-fdab-47ae-80d8-c9633f71be64}
HKU\​S-1-5-21-1229272821-1004336348-527237240-1003\​SOFTWARE\​Microsoft\​CTF\​TIP\​{1188450c-fdab-47ae-80d8-c9633f71be64}\​LanguageProfile
HKU\​S-1-5-21-1229272821-1004336348-527237240-1003\​SOFTWARE\​Microsoft\​CTF\​TIP\​{1188450c-fdab-47ae-80d8-c9633f71be64}\​LanguageProfile\​0x00000000
HKU\​S-1-5-21-1229272821-1004336348-527237240-1003\​SOFTWARE\​Microsoft\​CTF\​TIP\​{1188450c-fdab-47ae-80d8-c9633f71be64}\​LanguageProfile\​0x00000000\​{63800dac-e7ca-4df9-9a5c-20765055488d}
HKU\​S-1-5-21-1229272821-1004336348-527237240-1003\​Software\​Classes\​CLSID\​{E19F9331-3110-11D4-991C-005004D3B3DB}
HKU\​S-1-5-21-1229272821-1004336348-527237240-1003\​Software\​Classes\​CLSID\​{E19F9331-3110-11D4-991C-005004D3B3DB}\​InprocServer32
HKU\​S-1-5-21-1229272821-1004336348-527237240-1003\​Software\​Classes\​CLSID\​{CAFEEFAC-0013-0000-0003-ABCDEFFEDCBA}
HKU\​S-1-5-21-1229272821-1004336348-527237240-1003\​Software\​Classes\​CLSID\​{CAFEEFAC-0013-0000-0003-ABCDEFFEDCBA}\​InprocServer32
HKU\​S-1-5-21-1229272821-1004336348-527237240-1003\​Software\​Classes\​CLSID\​{CAFEEFAC-0013-0000-0004-ABCDEFFEDCBA}
HKU\​S-1-5-21-1229272821-1004336348-527237240-1003\​Software\​Classes\​CLSID\​{CAFEEFAC-0013-0000-0004-ABCDEFFEDCBA}\​InprocServer32
HKU\​S-1-5-21-1229272821-1004336348-527237240-1003\​Software\​Classes\​CLSID\​{CAFEEFAC-0013-0000-0005-ABCDEFFEDCBA}
HKU\​S-1-5-21-1229272821-1004336348-527237240-1003\​Software\​Classes\​CLSID\​{CAFEEFAC-0013-0000-0005-ABCDEFFEDCBA}\​InprocServer32
HKU\​S-1-5-21-1229272821-1004336348-527237240-1003\​Software\​Classes\​CLSID\​{CAFEEFAC-0013-0001-0000-ABCDEFFEDCBA}
HKU\​S-1-5-21-1229272821-1004336348-527237240-1003\​Software\​Classes\​CLSID\​{CAFEEFAC-0013-0001-0000-ABCDEFFEDCBA}\​InprocServer32
HKU\​S-1-5-21-1229272821-1004336348-527237240-1003\​Software\​Classes\​CLSID\​{CAFEEFAC-0013-0001-0001-ABCDEFFEDCBA}
HKU\​S-1-5-21-1229272821-1004336348-527237240-1003\​Software\​Classes\​CLSID\​{CAFEEFAC-0013-0001-0001-ABCDEFFEDCBA}\​InprocServer32
HKU\​S-1-5-21-1229272821-1004336348-527237240-1003\​Software\​Classes\​CLSID\​{CAFEEFAC-0013-0001-0001-ABCDEFFEDCBB}
HKU\​S-1-5-21-1229272821-1004336348-527237240-1003\​Software\​Classes\​CLSID\​{CAFEEFAC-0013-0001-0001-ABCDEFFEDCBB}\​InprocServer32
HKU\​S-1-5-21-1229272821-1004336348-527237240-1003\​Software\​Classes\​CLSID\​{CAFEEFAC-0013-0001-0002-ABCDEFFEDCBA}
HKU\​S-1-5-21-1229272821-1004336348-527237240-1003\​Software\​Classes\​CLSID\​{CAFEEFAC-0013-0001-0002-ABCDEFFEDCBA}\​InprocServer32
HKU\​S-1-5-21-1229272821-1004336348-527237240-1003\​Software\​Classes\​CLSID\​{CAFEEFAC-0013-0001-0002-ABCDEFFEDCBB}
HKU\​S-1-5-21-1229272821-1004336348-527237240-1003\​Software\​Classes\​CLSID\​{CAFEEFAC-0013-0001-0002-ABCDEFFEDCBB}\​InprocServer32
HKU\​S-1-5-21-1229272821-1004336348-527237240-1003\​Software\​Classes\​CLSID\​{CAFEEFAC-0013-0001-0003-ABCDEFFEDCBA}
HKU\​S-1-5-21-1229272821-1004336348-527237240-1003\​Software\​Classes\​CLSID\​{CAFEEFAC-0013-0001-0003-ABCDEFFEDCBA}\​InprocServer32
HKU\​S-1-5-21-1229272821-1004336348-527237240-1003\​Software\​Classes\​CLSID\​{CAFEEFAC-0013-0001-0003-ABCDEFFEDCBB}
HKU\​S-1-5-21-1229272821-1004336348-527237240-1003\​Software\​Classes\​CLSID\​{CAFEEFAC-0013-0001-0003-ABCDEFFEDCBB}\​InprocServer32
HKU\​S-1-5-21-1229272821-1004336348-527237240-1003\​Software\​Classes\​CLSID\​{CAFEEFAC-0013-0001-0004-ABCDEFFEDCBA}
HKU\​S-1-5-21-1229272821-1004336348-527237240-1003\​Software\​Classes\​CLSID\​{CAFEEFAC-0013-0001-0004-ABCDEFFEDCBA}\​InprocServer32
HKU\​S-1-5-21-1229272821-1004336348-527237240-1003\​Software\​Classes\​CLSID\​{CAFEEFAC-0013-0001-0004-ABCDEFFEDCBB}
HKU\​S-1-5-21-1229272821-1004336348-527237240-1003\​Software\​Classes\​CLSID\​{CAFEEFAC-0013-0001-0004-ABCDEFFEDCBB}\​InprocServer32
HKU\​S-1-5-21-1229272821-1004336348-527237240-1003\​Software\​Classes\​CLSID\​{CAFEEFAC-0013-0001-0005-ABCDEFFEDCBA}
HKU\​S-1-5-21-1229272821-1004336348-527237240-1003\​Software\​Classes\​CLSID\​{CAFEEFAC-0013-0001-0005-ABCDEFFEDCBA}\​InprocServer32
HKU\​S-1-5-21-1229272821-1004336348-527237240-1003\​Software\​Classes\​CLSID\​{CAFEEFAC-0013-0001-0005-ABCDEFFEDCBB}
HKU\​S-1-5-21-1229272821-1004336348-527237240-1003\​Software\​Classes\​CLSID\​{CAFEEFAC-0013-0001-0005-ABCDEFFEDCBB}\​InprocServer32
HKU\​S-1-5-21-1229272821-1004336348-527237240-1003\​Software\​Classes\​CLSID\​{CAFEEFAC-0013-0001-0006-ABCDEFFEDCBA}
HKU\​S-1-5-21-1229272821-1004336348-527237240-1003\​Software\​Classes\​CLSID\​{CAFEEFAC-0013-0001-0006-ABCDEFFEDCBA}\​InprocServer32
HKU\​S-1-5-21-1229272821-1004336348-527237240-1003\​Software\​Classes\​CLSID\​{CAFEEFAC-0013-0001-0006-ABCDEFFEDCBB}
HKU\​S-1-5-21-1229272821-1004336348-527237240-1003\​Software\​Classes\​CLSID\​{CAFEEFAC-0013-0001-0006-ABCDEFFEDCBB}\​InprocServer32
HKU\​S-1-5-21-1229272821-1004336348-527237240-1003\​Software\​Classes\​CLSID\​{CAFEEFAC-0013-0001-0007-ABCDEFFEDCBA}
HKU\​S-1-5-21-1229272821-1004336348-527237240-1003\​Software\​Classes\​CLSID\​{CAFEEFAC-0013-0001-0007-ABCDEFFEDCBA}\​InprocServer32
HKU\​S-1-5-21-1229272821-1004336348-527237240-1003\​Software\​Classes\​CLSID\​{CAFEEFAC-0013-0001-0007-ABCDEFFEDCBB}
HKU\​S-1-5-21-1229272821-1004336348-527237240-1003\​Software\​Classes\​CLSID\​{CAFEEFAC-0013-0001-0007-ABCDEFFEDCBB}\​InprocServer32
HKU\​S-1-5-21-1229272821-1004336348-527237240-1003\​Software\​Classes\​CLSID\​{CAFEEFAC-0013-0001-0008-ABCDEFFEDCBA}
HKU\​S-1-5-21-1229272821-1004336348-527237240-1003\​Software\​Classes\​CLSID\​{CAFEEFAC-0013-0001-0008-ABCDEFFEDCBA}\​InprocServer32
HKU\​S-1-5-21-1229272821-1004336348-527237240-1003\​Software\​Classes\​CLSID\​{CAFEEFAC-0013-0001-0008-ABCDEFFEDCBB}
HKU\​S-1-5-21-1229272821-1004336348-527237240-1003\​Software\​Classes\​CLSID\​{CAFEEFAC-0013-0001-0008-ABCDEFFEDCBB}\​InprocServer32
HKU\​S-1-5-21-1229272821-1004336348-527237240-1003\​Software\​Classes\​CLSID\​{CAFEEFAC-0013-0001-0009-ABCDEFFEDCBA}
HKU\​S-1-5-21-1229272821-1004336348-527237240-1003\​Software\​Classes\​CLSID\​{CAFEEFAC-0013-0001-0009-ABCDEFFEDCBA}\​InprocServer32
HKU\​S-1-5-21-1229272821-1004336348-527237240-1003\​Software\​Classes\​CLSID\​{CAFEEFAC-0013-0001-0009-ABCDEFFEDCBB}
HKU\​S-1-5-21-1229272821-1004336348-527237240-1003\​Software\​Classes\​CLSID\​{CAFEEFAC-0013-0001-0009-ABCDEFFEDCBB}\​InprocServer32
HKU\​S-1-5-21-1229272821-1004336348-527237240-1003\​Software\​Classes\​CLSID\​{CAFEEFAC-0013-0001-0010-ABCDEFFEDCBA}
HKU\​S-1-5-21-1229272821-1004336348-527237240-1003\​Software\​Classes\​CLSID\​{CAFEEFAC-0013-0001-0010-ABCDEFFEDCBA}\​InprocServer32
HKU\​S-1-5-21-1229272821-1004336348-527237240-1003\​Software\​Classes\​CLSID\​{CAFEEFAC-0013-0001-0010-ABCDEFFEDCBB}
HKU\​S-1-5-21-1229272821-1004336348-527237240-1003\​Software\​Classes\​CLSID\​{CAFEEFAC-0013-0001-0010-ABCDEFFEDCBB}\​InprocServer32
HKU\​S-1-5-21-1229272821-1004336348-527237240-1003\​Software\​Classes\​CLSID\​{CAFEEFAC-0013-0001-0011-ABCDEFFEDCBA}
HKU\​S-1-5-21-1229272821-1004336348-527237240-1003\​Software\​Classes\​CLSID\​{CAFEEFAC-0013-0001-0011-ABCDEFFEDCBA}\​InprocServer32
HKU\​S-1-5-21-1229272821-1004336348-527237240-1003\​Software\​Classes\​CLSID\​{CAFEEFAC-0013-0001-0011-ABCDEFFEDCBB}
HKU\​S-1-5-21-1229272821-1004336348-527237240-1003\​Software\​Classes\​CLSID\​{CAFEEFAC-0013-0001-0011-ABCDEFFEDCBB}\​InprocServer32
HKU\​S-1-5-21-1229272821-1004336348-527237240-1003\​Software\​Classes\​CLSID\​{CAFEEFAC-0013-0001-0012-ABCDEFFEDCBA}
HKU\​S-1-5-21-1229272821-1004336348-527237240-1003\​Software\​Classes\​CLSID\​{CAFEEFAC-0013-0001-0012-ABCDEFFEDCBA}\​InprocServer32
HKU\​S-1-5-21-1229272821-1004336348-527237240-1003\​Software\​Classes\​CLSID\​{CAFEEFAC-0013-0001-0012-ABCDEFFEDCBB}
HKU\​S-1-5-21-1229272821-1004336348-527237240-1003\​Software\​Classes\​CLSID\​{CAFEEFAC-0013-0001-0012-ABCDEFFEDCBB}\​InprocServer32
HKU\​S-1-5-21-1229272821-1004336348-527237240-1003\​Software\​Classes\​CLSID\​{CAFEEFAC-0013-0001-0013-ABCDEFFEDCBA}
HKU\​S-1-5-21-1229272821-1004336348-527237240-1003\​Software\​Classes\​CLSID\​{CAFEEFAC-0013-0001-0013-ABCDEFFEDCBA}\​InprocServer32
HKU\​S-1-5-21-1229272821-1004336348-527237240-1003\​Software\​Classes\​CLSID\​{CAFEEFAC-0013-0001-0013-ABCDEFFEDCBB}
HKU\​S-1-5-21-1229272821-1004336348-527237240-1003\​Software\​Classes\​CLSID\​{CAFEEFAC-0013-0001-0013-ABCDEFFEDCBB}\​InprocServer32
HKU\​S-1-5-21-1229272821-1004336348-527237240-1003\​Software\​Classes\​CLSID\​{CAFEEFAC-0013-0001-0014-ABCDEFFEDCBA}
HKU\​S-1-5-21-1229272821-1004336348-527237240-1003\​Software\​Classes\​CLSID\​{CAFEEFAC-0013-0001-0014-ABCDEFFEDCBA}\​InprocServer32
HKU\​S-1-5-21-1229272821-1004336348-527237240-1003\​Software\​Classes\​CLSID\​{CAFEEFAC-0013-0001-0014-ABCDEFFEDCBB}
HKU\​S-1-5-21-1229272821-1004336348-527237240-1003\​Software\​Classes\​CLSID\​{CAFEEFAC-0013-0001-0014-ABCDEFFEDCBB}\​InprocServer32
HKU\​S-1-5-21-1229272821-1004336348-527237240-1003\​Software\​Classes\​CLSID\​{CAFEEFAC-0013-0001-0015-ABCDEFFEDCBA}
HKU\​S-1-5-21-1229272821-1004336348-527237240-1003\​Software\​Classes\​CLSID\​{CAFEEFAC-0013-0001-0015-ABCDEFFEDCBA}\​InprocServer32
HKU\​S-1-5-21-1229272821-1004336348-527237240-1003\​Software\​Classes\​CLSID\​{CAFEEFAC-0013-0001-0015-ABCDEFFEDCBB}
HKU\​S-1-5-21-1229272821-1004336348-527237240-1003\​Software\​Classes\​CLSID\​{CAFEEFAC-0013-0001-0015-ABCDEFFEDCBB}\​InprocServer32
HKU\​S-1-5-21-1229272821-1004336348-527237240-1003\​Software\​Classes\​CLSID\​{CAFEEFAC-0013-0001-0016-ABCDEFFEDCBA}
HKU\​S-1-5-21-1229272821-1004336348-527237240-1003\​Software\​Classes\​CLSID\​{CAFEEFAC-0013-0001-0016-ABCDEFFEDCBA}\​InprocServer32
HKU\​S-1-5-21-1229272821-1004336348-527237240-1003\​Software\​Classes\​CLSID\​{CAFEEFAC-0013-0001-0016-ABCDEFFEDCBB}
HKU\​S-1-5-21-1229272821-1004336348-527237240-1003\​Software\​Classes\​CLSID\​{CAFEEFAC-0013-0001-0016-ABCDEFFEDCBB}\​InprocServer32
HKU\​S-1-5-21-1229272821-1004336348-527237240-1003\​Software\​Classes\​CLSID\​{CAFEEFAC-0013-0001-0017-ABCDEFFEDCBA}
HKU\​S-1-5-21-1229272821-1004336348-527237240-1003\​Software\​Classes\​CLSID\​{CAFEEFAC-0013-0001-0017-ABCDEFFEDCBA}\​InprocServer32
HKU\​S-1-5-21-1229272821-1004336348-527237240-1003\​Software\​Classes\​CLSID\​{CAFEEFAC-0013-0001-0017-ABCDEFFEDCBB}
HKU\​S-1-5-21-1229272821-1004336348-527237240-1003\​Software\​Classes\​CLSID\​{CAFEEFAC-0013-0001-0017-ABCDEFFEDCBB}\​InprocServer32
HKU\​S-1-5-21-1229272821-1004336348-527237240-1003\​Software\​Classes\​CLSID\​{CAFEEFAC-0013-0001-0018-ABCDEFFEDCBA}
HKU\​S-1-5-21-1229272821-1004336348-527237240-1003\​Software\​Classes\​CLSID\​{CAFEEFAC-0013-0001-0018-ABCDEFFEDCBA}\​InprocServer32
HKU\​S-1-5-21-1229272821-1004336348-527237240-1003\​Software\​Classes\​CLSID\​{CAFEEFAC-0013-0001-0018-ABCDEFFEDCBB}
HKU\​S-1-5-21-1229272821-1004336348-527237240-1003\​Software\​Classes\​CLSID\​{CAFEEFAC-0013-0001-0018-ABCDEFFEDCBB}\​InprocServer32
HKU\​S-1-5-21-1229272821-1004336348-527237240-1003\​Software\​Classes\​CLSID\​{CAFEEFAC-0013-0001-0019-ABCDEFFEDCBA}
HKU\​S-1-5-21-1229272821-1004336348-527237240-1003\​Software\​Classes\​CLSID\​{CAFEEFAC-0013-0001-0019-ABCDEFFEDCBA}\​InprocServer32
HKU\​S-1-5-21-1229272821-1004336348-527237240-1003\​Software\​Classes\​CLSID\​{CAFEEFAC-0013-0001-0019-ABCDEFFEDCBB}
HKU\​S-1-5-21-1229272821-1004336348-527237240-1003\​Software\​Classes\​CLSID\​{CAFEEFAC-0013-0001-0019-ABCDEFFEDCBB}\​InprocServer32
HKU\​S-1-5-21-1229272821-1004336348-527237240-1003\​Software\​Classes\​CLSID\​{CAFEEFAC-0013-0001-0020-ABCDEFFEDCBA}
HKU\​S-1-5-21-1229272821-1004336348-527237240-1003\​Software\​Classes\​CLSID\​{CAFEEFAC-0013-0001-0020-ABCDEFFEDCBA}\​InprocServer32
HKU\​S-1-5-21-1229272821-1004336348-527237240-1003\​Software\​Classes\​CLSID\​{CAFEEFAC-0013-0001-0020-ABCDEFFEDCBB}
HKU\​S-1-5-21-1229272821-1004336348-527237240-1003\​Software\​Classes\​CLSID\​{CAFEEFAC-0013-0001-0020-ABCDEFFEDCBB}\​InprocServer32
HKU\​S-1-5-21-1229272821-1004336348-527237240-1003\​Software\​Classes\​CLSID\​{CAFEEFAC-0013-0001-0021-ABCDEFFEDCBA}
HKU\​S-1-5-21-1229272821-1004336348-527237240-1003\​Software\​Classes\​CLSID\​{CAFEEFAC-0013-0001-0021-ABCDEFFEDCBA}\​InprocServer32
HKU\​S-1-5-21-1229272821-1004336348-527237240-1003\​Software\​Classes\​CLSID\​{CAFEEFAC-0013-0001-0021-ABCDEFFEDCBB}
HKU\​S-1-5-21-1229272821-1004336348-527237240-1003\​Software\​Classes\​CLSID\​{CAFEEFAC-0013-0001-0021-ABCDEFFEDCBB}\​InprocServer32
HKU\​S-1-5-21-1229272821-1004336348-527237240-1003\​Software\​Classes\​CLSID\​{CAFEEFAC-0013-0001-0022-ABCDEFFEDCBA}
HKU\​S-1-5-21-1229272821-1004336348-527237240-1003\​Software\​Classes\​CLSID\​{CAFEEFAC-0013-0001-0022-ABCDEFFEDCBA}\​InprocServer32
HKU\​S-1-5-21-1229272821-1004336348-527237240-1003\​Software\​Classes\​CLSID\​{CAFEEFAC-0013-0001-0022-ABCDEFFEDCBB}
HKU\​S-1-5-21-1229272821-1004336348-527237240-1003\​Software\​Classes\​CLSID\​{CAFEEFAC-0013-0001-0022-ABCDEFFEDCBB}\​InprocServer32
HKU\​S-1-5-21-1229272821-1004336348-527237240-1003\​Software\​Classes\​CLSID\​{CAFEEFAC-0013-0001-0023-ABCDEFFEDCBA}
HKU\​S-1-5-21-1229272821-1004336348-527237240-1003\​Software\​Classes\​CLSID\​{CAFEEFAC-0013-0001-0023-ABCDEFFEDCBA}\​InprocServer32
HKU\​S-1-5-21-1229272821-1004336348-527237240-1003\​Software\​Classes\​CLSID\​{CAFEEFAC-0013-0001-0023-ABCDEFFEDCBB}
HKU\​S-1-5-21-1229272821-1004336348-527237240-1003\​Software\​Classes\​CLSID\​{CAFEEFAC-0013-0001-0023-ABCDEFFEDCBB}\​InprocServer32
HKU\​S-1-5-21-1229272821-1004336348-527237240-1003\​Software\​Classes\​CLSID\​{CAFEEFAC-0013-0001-0024-ABCDEFFEDCBA}
HKU\​S-1-5-21-1229272821-1004336348-527237240-1003\​Software\​Classes\​CLSID\​{CAFEEFAC-0013-0001-0024-ABCDEFFEDCBA}\​InprocServer32
HKU\​S-1-5-21-1229272821-1004336348-527237240-1003\​Software\​Classes\​CLSID\​{CAFEEFAC-0013-0001-0024-ABCDEFFEDCBB}
HKU\​S-1-5-21-1229272821-1004336348-527237240-1003\​Software\​Classes\​CLSID\​{CAFEEFAC-0013-0001-0024-ABCDEFFEDCBB}\​InprocServer32
HKU\​S-1-5-21-1229272821-1004336348-527237240-1003\​Software\​Classes\​CLSID\​{CAFEEFAC-0013-0001-0025-ABCDEFFEDCBA}
HKU\​S-1-5-21-1229272821-1004336348-527237240-1003\​Software\​Classes\​CLSID\​{CAFEEFAC-0013-0001-0025-ABCDEFFEDCBA}\​InprocServer32
HKU\​S-1-5-21-1229272821-1004336348-527237240-1003\​Software\​Classes\​CLSID\​{CAFEEFAC-0013-0001-0025-ABCDEFFEDCBB}
HKU\​S-1-5-21-1229272821-1004336348-527237240-1003\​Software\​Classes\​CLSID\​{CAFEEFAC-0013-0001-0025-ABCDEFFEDCBB}\​InprocServer32
HKU\​S-1-5-21-1229272821-1004336348-527237240-1003\​Software\​Classes\​CLSID\​{CAFEEFAC-0013-0001-0026-ABCDEFFEDCBA}
HKU\​S-1-5-21-1229272821-1004336348-527237240-1003\​Software\​Classes\​CLSID\​{CAFEEFAC-0013-0001-0026-ABCDEFFEDCBA}\​InprocServer32
HKU\​S-1-5-21-1229272821-1004336348-527237240-1003\​Software\​Classes\​CLSID\​{CAFEEFAC-0013-0001-0026-ABCDEFFEDCBB}
HKU\​S-1-5-21-1229272821-1004336348-527237240-1003\​Software\​Classes\​CLSID\​{CAFEEFAC-0013-0001-0026-ABCDEFFEDCBB}\​InprocServer32
HKU\​S-1-5-21-1229272821-1004336348-527237240-1003\​Software\​Classes\​CLSID\​{CAFEEFAC-0013-0001-0027-ABCDEFFEDCBA}
HKU\​S-1-5-21-1229272821-1004336348-527237240-1003\​Software\​Classes\​CLSID\​{CAFEEFAC-0013-0001-0027-ABCDEFFEDCBA}\​InprocServer32
HKU\​S-1-5-21-1229272821-1004336348-527237240-1003\​Software\​Classes\​CLSID\​{CAFEEFAC-0013-0001-0027-ABCDEFFEDCBB}
HKU\​S-1-5-21-1229272821-1004336348-527237240-1003\​Software\​Classes\​CLSID\​{CAFEEFAC-0013-0001-0027-ABCDEFFEDCBB}\​InprocServer32
HKU\​S-1-5-21-1229272821-1004336348-527237240-1003\​Software\​Classes\​CLSID\​{CAFEEFAC-0013-0001-0028-ABCDEFFEDCBA}
HKU\​S-1-5-21-1229272821-1004336348-527237240-1003\​Software\​Classes\​CLSID\​{CAFEEFAC-0013-0001-0028-ABCDEFFEDCBA}\​InprocServer32
HKU\​S-1-5-21-1229272821-1004336348-527237240-1003\​Software\​Classes\​CLSID\​{CAFEEFAC-0013-0001-0028-ABCDEFFEDCBB}
HKU\​S-1-5-21-1229272821-1004336348-527237240-1003\​Software\​Classes\​CLSID\​{CAFEEFAC-0013-0001-0028-ABCDEFFEDCBB}\​InprocServer32
HKU\​S-1-5-21-1229272821-1004336348-527237240-1003\​Software\​Classes\​CLSID\​{CAFEEFAC-0013-0001-0029-ABCDEFFEDCBA}
HKU\​S-1-5-21-1229272821-1004336348-527237240-1003\​Software\​Classes\​CLSID\​{CAFEEFAC-0013-0001-0029-ABCDEFFEDCBA}\​InprocServer32
HKU\​S-1-5-21-1229272821-1004336348-527237240-1003\​Software\​Classes\​CLSID\​{CAFEEFAC-0013-0001-0029-ABCDEFFEDCBB}
HKU\​S-1-5-21-1229272821-1004336348-527237240-1003\​Software\​Classes\​CLSID\​{CAFEEFAC-0013-0001-0029-ABCDEFFEDCBB}\​InprocServer32
HKU\​S-1-5-21-1229272821-1004336348-527237240-1003\​Software\​Classes\​CLSID\​{CAFEEFAC-0013-0001-0030-ABCDEFFEDCBA}
HKU\​S-1-5-21-1229272821-1004336348-527237240-1003\​Software\​Classes\​CLSID\​{CAFEEFAC-0013-0001-0030-ABCDEFFEDCBA}\​InprocServer32
HKU\​S-1-5-21-1229272821-1004336348-527237240-1003\​Software\​Classes\​CLSID\​{CAFEEFAC-0013-0001-0030-ABCDEFFEDCBB}
HKU\​S-1-5-21-1229272821-1004336348-527237240-1003\​Software\​Classes\​CLSID\​{CAFEEFAC-0013-0001-0030-ABCDEFFEDCBB}\​InprocServer32
HKU\​S-1-5-21-1229272821-1004336348-527237240-1003\​Software\​Classes\​CLSID\​{CAFEEFAC-0014-0000-0000-ABCDEFFEDCBA}
HKU\​S-1-5-21-1229272821-1004336348-527237240-1003\​Software\​Classes\​CLSID\​{CAFEEFAC-0014-0000-0000-ABCDEFFEDCBA}\​InprocServer32
HKU\​S-1-5-21-1229272821-1004336348-527237240-1003\​Software\​Classes\​CLSID\​{CAFEEFAC-0014-0000-0000-ABCDEFFEDCBB}
HKU\​S-1-5-21-1229272821-1004336348-527237240-1003\​Software\​Classes\​CLSID\​{CAFEEFAC-0014-0000-0000-ABCDEFFEDCBB}\​InprocServer32
HKU\​S-1-5-21-1229272821-1004336348-527237240-1003\​Software\​Classes\​CLSID\​{CAFEEFAC-0014-0000-0001-ABCDEFFEDCBA}
HKU\​S-1-5-21-1229272821-1004336348-527237240-1003\​Software\​Classes\​CLSID\​{CAFEEFAC-0014-0000-0001-ABCDEFFEDCBA}\​InprocServer32
HKU\​S-1-5-21-1229272821-1004336348-527237240-1003\​Software\​Classes\​CLSID\​{CAFEEFAC-0014-0000-0001-ABCDEFFEDCBB}
HKU\​S-1-5-21-1229272821-1004336348-527237240-1003\​Software\​Classes\​CLSID\​{CAFEEFAC-0014-0000-0001-ABCDEFFEDCBB}\​InprocServer32
HKU\​S-1-5-21-1229272821-1004336348-527237240-1003\​Software\​Classes\​CLSID\​{CAFEEFAC-0014-0000-0002-ABCDEFFEDCBA}
HKU\​S-1-5-21-1229272821-1004336348-527237240-1003\​Software\​Classes\​CLSID\​{CAFEEFAC-0014-0000-0002-ABCDEFFEDCBA}\​InprocServer32
HKU\​S-1-5-21-1229272821-1004336348-527237240-1003\​Software\​Classes\​CLSID\​{CAFEEFAC-0014-0000-0002-ABCDEFFEDCBB}
HKU\​S-1-5-21-1229272821-1004336348-527237240-1003\​Software\​Classes\​CLSID\​{CAFEEFAC-0014-0000-0002-ABCDEFFEDCBB}\​InprocServer32
HKU\​S-1-5-21-1229272821-1004336348-527237240-1003\​Software\​Classes\​CLSID\​{CAFEEFAC-0014-0000-0003-ABCDEFFEDCBA}
HKU\​S-1-5-21-1229272821-1004336348-527237240-1003\​Software\​Classes\​CLSID\​{CAFEEFAC-0014-0000-0003-ABCDEFFEDCBA}\​InprocServer32
HKU\​S-1-5-21-1229272821-1004336348-527237240-1003\​Software\​Classes\​CLSID\​{CAFEEFAC-0014-0000-0003-ABCDEFFEDCBB}
HKU\​S-1-5-21-1229272821-1004336348-527237240-1003\​Software\​Classes\​CLSID\​{CAFEEFAC-0014-0000-0003-ABCDEFFEDCBB}\​InprocServer32
HKU\​S-1-5-21-1229272821-1004336348-527237240-1003\​Software\​Classes\​CLSID\​{CAFEEFAC-0014-0000-0004-ABCDEFFEDCBA}
HKU\​S-1-5-21-1229272821-1004336348-527237240-1003\​Software\​Classes\​CLSID\​{CAFEEFAC-0014-0000-0004-ABCDEFFEDCBA}\​InprocServer32
HKU\​S-1-5-21-1229272821-1004336348-527237240-1003\​Software\​Classes\​CLSID\​{CAFEEFAC-0014-0000-0004-ABCDEFFEDCBB}
HKU\​S-1-5-21-1229272821-1004336348-527237240-1003\​Software\​Classes\​CLSID\​{CAFEEFAC-0014-0000-0004-ABCDEFFEDCBB}\​InprocServer32
HKU\​S-1-5-21-1229272821-1004336348-527237240-1003\​Software\​Classes\​CLSID\​{CAFEEFAC-0014-0001-0000-ABCDEFFEDCBA}
HKU\​S-1-5-21-1229272821-1004336348-527237240-1003\​Software\​Classes\​CLSID\​{CAFEEFAC-0014-0001-0000-ABCDEFFEDCBA}\​InprocServer32
HKU\​S-1-5-21-1229272821-1004336348-527237240-1003\​Software\​Classes\​CLSID\​{CAFEEFAC-0014-0001-0000-ABCDEFFEDCBB}
HKU\​S-1-5-21-1229272821-1004336348-527237240-1003\​Software\​Classes\​CLSID\​{CAFEEFAC-0014-0001-0000-ABCDEFFEDCBB}\​InprocServer32
HKU\​S-1-5-21-1229272821-1004336348-527237240-1003\​Software\​Classes\​CLSID\​{CAFEEFAC-0014-0001-0001-ABCDEFFEDCBA}
HKU\​S-1-5-21-1229272821-1004336348-527237240-1003\​Software\​Classes\​CLSID\​{CAFEEFAC-0014-0001-0001-ABCDEFFEDCBA}\​InprocServer32
HKU\​S-1-5-21-1229272821-1004336348-527237240-1003\​Software\​Classes\​CLSID\​{CAFEEFAC-0014-0001-0001-ABCDEFFEDCBB}
HKU\​S-1-5-21-1229272821-1004336348-527237240-1003\​Software\​Classes\​CLSID\​{CAFEEFAC-0014-0001-0001-ABCDEFFEDCBB}\​InprocServer32
HKU\​S-1-5-21-1229272821-1004336348-527237240-1003\​Software\​Classes\​CLSID\​{CAFEEFAC-0014-0001-0002-ABCDEFFEDCBA}
HKU\​S-1-5-21-1229272821-1004336348-527237240-1003\​Software\​Classes\​CLSID\​{CAFEEFAC-0014-0001-0002-ABCDEFFEDCBA}\​InprocServer32
HKU\​S-1-5-21-1229272821-1004336348-527237240-1003\​Software\​Classes\​CLSID\​{CAFEEFAC-0014-0001-0002-ABCDEFFEDCBB}
HKU\​S-1-5-21-1229272821-1004336348-527237240-1003\​Software\​Classes\​CLSID\​{CAFEEFAC-0014-0001-0002-ABCDEFFEDCBB}\​InprocServer32
HKU\​S-1-5-21-1229272821-1004336348-527237240-1003\​Software\​Classes\​CLSID\​{CAFEEFAC-0014-0001-0003-ABCDEFFEDCBA}
HKU\​S-1-5-21-1229272821-1004336348-527237240-1003\​Software\​Classes\​CLSID\​{CAFEEFAC-0014-0001-0003-ABCDEFFEDCBA}\​InprocServer32
HKU\​S-1-5-21-1229272821-1004336348-527237240-1003\​Software\​Classes\​CLSID\​{CAFEEFAC-0014-0001-0003-ABCDEFFEDCBB}
HKU\​S-1-5-21-1229272821-1004336348-527237240-1003\​Software\​Classes\​CLSID\​{CAFEEFAC-0014-0001-0003-ABCDEFFEDCBB}\​InprocServer32
HKU\​S-1-5-21-1229272821-1004336348-527237240-1003\​Software\​Classes\​CLSID\​{CAFEEFAC-0014-0001-0004-ABCDEFFEDCBA}
HKU\​S-1-5-21-1229272821-1004336348-527237240-1003\​Software\​Classes\​CLSID\​{CAFEEFAC-0014-0001-0004-ABCDEFFEDCBA}\​InprocServer32
HKU\​S-1-5-21-1229272821-1004336348-527237240-1003\​Software\​Classes\​CLSID\​{CAFEEFAC-0014-0001-0004-ABCDEFFEDCBB}
HKU\​S-1-5-21-1229272821-1004336348-527237240-1003\​Software\​Classes\​CLSID\​{CAFEEFAC-0014-0001-0004-ABCDEFFEDCBB}\​InprocServer32
HKU\​S-1-5-21-1229272821-1004336348-527237240-1003\​Software\​Classes\​CLSID\​{CAFEEFAC-0014-0001-0005-ABCDEFFEDCBA}
HKU\​S-1-5-21-1229272821-1004336348-527237240-1003\​Software\​Classes\​CLSID\​{CAFEEFAC-0014-0001-0005-ABCDEFFEDCBA}\​InprocServer32
HKU\​S-1-5-21-1229272821-1004336348-527237240-1003\​Software\​Classes\​CLSID\​{CAFEEFAC-0014-0001-0005-ABCDEFFEDCBB}
HKU\​S-1-5-21-1229272821-1004336348-527237240-1003\​Software\​Classes\​CLSID\​{CAFEEFAC-0014-0001-0005-ABCDEFFEDCBB}\​InprocServer32
HKU\​S-1-5-21-1229272821-1004336348-527237240-1003\​Software\​Classes\​CLSID\​{CAFEEFAC-0014-0001-0006-ABCDEFFEDCBA}
HKU\​S-1-5-21-1229272821-1004336348-527237240-1003\​Software\​Classes\​CLSID\​{CAFEEFAC-0014-0001-0006-ABCDEFFEDCBA}\​InprocServer32
HKU\​S-1-5-21-1229272821-1004336348-527237240-1003\​Software\​Classes\​CLSID\​{CAFEEFAC-0014-0001-0006-ABCDEFFEDCBB}
HKU\​S-1-5-21-1229272821-1004336348-527237240-1003\​Software\​Classes\​CLSID\​{CAFEEFAC-0014-0001-0006-ABCDEFFEDCBB}\​InprocServer32
HKU\​S-1-5-21-1229272821-1004336348-527237240-1003\​Software\​Classes\​CLSID\​{CAFEEFAC-0014-0001-0007-ABCDEFFEDCBA}
HKU\​S-1-5-21-1229272821-1004336348-527237240-1003\​Software\​Classes\​CLSID\​{CAFEEFAC-0014-0001-0007-ABCDEFFEDCBA}\​InprocServer32
HKU\​S-1-5-21-1229272821-1004336348-527237240-1003\​Software\​Classes\​CLSID\​{CAFEEFAC-0014-0001-0007-ABCDEFFEDCBB}
HKU\​S-1-5-21-1229272821-1004336348-527237240-1003\​Software\​Classes\​CLSID\​{CAFEEFAC-0014-0001-0007-ABCDEFFEDCBB}\​InprocServer32
HKU\​S-1-5-21-1229272821-1004336348-527237240-1003\​Software\​Classes\​CLSID\​{CAFEEFAC-0014-0002-0000-ABCDEFFEDCBA}
HKU\​S-1-5-21-1229272821-1004336348-527237240-1003\​Software\​Classes\​CLSID\​{CAFEEFAC-0014-0002-0000-ABCDEFFEDCBA}\​InprocServer32
HKU\​S-1-5-21-1229272821-1004336348-527237240-1003\​Software\​Classes\​CLSID\​{CAFEEFAC-0014-0002-0000-ABCDEFFEDCBB}
HKU\​S-1-5-21-1229272821-1004336348-527237240-1003\​Software\​Classes\​CLSID\​{CAFEEFAC-0014-0002-0000-ABCDEFFEDCBB}\​InprocServer32
HKU\​S-1-5-21-1229272821-1004336348-527237240-1003\​Software\​Classes\​CLSID\​{CAFEEFAC-0014-0002-0001-ABCDEFFEDCBA}
HKU\​S-1-5-21-1229272821-1004336348-527237240-1003\​Software\​Classes\​CLSID\​{CAFEEFAC-0014-0002-0001-ABCDEFFEDCBA}\​InprocServer32
HKU\​S-1-5-21-1229272821-1004336348-527237240-1003\​Software\​Classes\​CLSID\​{CAFEEFAC-0014-0002-0001-ABCDEFFEDCBB}
HKU\​S-1-5-21-1229272821-1004336348-527237240-1003\​Software\​Classes\​CLSID\​{CAFEEFAC-0014-0002-0001-ABCDEFFEDCBB}\​InprocServer32
HKU\​S-1-5-21-1229272821-1004336348-527237240-1003\​Software\​Classes\​CLSID\​{CAFEEFAC-0014-0002-0002-ABCDEFFEDCBA}
HKU\​S-1-5-21-1229272821-1004336348-527237240-1003\​Software\​Classes\​CLSID\​{CAFEEFAC-0014-0002-0002-ABCDEFFEDCBA}\​InprocServer32
HKU\​S-1-5-21-1229272821-1004336348-527237240-1003\​Software\​Classes\​CLSID\​{CAFEEFAC-0014-0002-0002-ABCDEFFEDCBB}
HKU\​S-1-5-21-1229272821-1004336348-527237240-1003\​Software\​Classes\​CLSID\​{CAFEEFAC-0014-0002-0002-ABCDEFFEDCBB}\​InprocServer32
HKU\​S-1-5-21-1229272821-1004336348-527237240-1003\​Software\​Classes\​CLSID\​{CAFEEFAC-0014-0002-0003-ABCDEFFEDCBA}
HKU\​S-1-5-21-1229272821-1004336348-527237240-1003\​Software\​Classes\​CLSID\​{CAFEEFAC-0014-0002-0003-ABCDEFFEDCBA}\​InprocServer32
HKU\​S-1-5-21-1229272821-1004336348-527237240-1003\​Software\​Classes\​CLSID\​{CAFEEFAC-0014-0002-0003-ABCDEFFEDCBB}
HKU\​S-1-5-21-1229272821-1004336348-527237240-1003\​Software\​Classes\​CLSID\​{CAFEEFAC-0014-0002-0003-ABCDEFFEDCBB}\​InprocServer32

  - Registry Keys Deleted:  
HKU\​S-1-5-21-1229272821-1004336348-527237240-1003\​SOFTWARE\​Microsoft\​CTF\​TIP\​{1188450c-fdab-47ae-80d8-c9633f71be64}\​LanguageProfile\​0x00000000\​{63800dac-e7ca-4df9-9a5c-20765055488d}
HKU\​S-1-5-21-1229272821-1004336348-527237240-1003\​SOFTWARE\​Microsoft\​CTF\​TIP\​{1188450c-fdab-47ae-80d8-c9633f71be64}\​LanguageProfile\​0x00000000
HKU\​S-1-5-21-1229272821-1004336348-527237240-1003\​SOFTWARE\​Microsoft\​CTF\​TIP\​{1188450c-fdab-47ae-80d8-c9633f71be64}\​LanguageProfile
HKU\​S-1-5-21-1229272821-1004336348-527237240-1003\​SOFTWARE\​Microsoft\​CTF\​TIP\​{1188450c-fdab-47ae-80d8-c9633f71be64}
HKU\​S-1-5-21-1229272821-1004336348-527237240-1003\​Software\​Classes\​CLSID\​{E19F9331-3110-11D4-991C-005004D3B3DB}\​InprocServer32
HKU\​S-1-5-21-1229272821-1004336348-527237240-1003\​Software\​Classes\​CLSID\​{E19F9331-3110-11D4-991C-005004D3B3DB}
HKU\​S-1-5-21-1229272821-1004336348-527237240-1003\​Software\​Classes\​CLSID\​{CAFEEFAC-0013-0000-0003-ABCDEFFEDCBA}\​InprocServer32
HKU\​S-1-5-21-1229272821-1004336348-527237240-1003\​Software\​Classes\​CLSID\​{CAFEEFAC-0013-0000-0003-ABCDEFFEDCBA}
HKU\​S-1-5-21-1229272821-1004336348-527237240-1003\​Software\​Classes\​CLSID\​{CAFEEFAC-0013-0000-0004-ABCDEFFEDCBA}\​InprocServer32
HKU\​S-1-5-21-1229272821-1004336348-527237240-1003\​Software\​Classes\​CLSID\​{CAFEEFAC-0013-0000-0004-ABCDEFFEDCBA}
HKU\​S-1-5-21-1229272821-1004336348-527237240-1003\​Software\​Classes\​CLSID\​{CAFEEFAC-0013-0000-0005-ABCDEFFEDCBA}\​InprocServer32
HKU\​S-1-5-21-1229272821-1004336348-527237240-1003\​Software\​Classes\​CLSID\​{CAFEEFAC-0013-0000-0005-ABCDEFFEDCBA}
HKU\​S-1-5-21-1229272821-1004336348-527237240-1003\​Software\​Classes\​CLSID\​{CAFEEFAC-0013-0001-0000-ABCDEFFEDCBA}\​InprocServer32
HKU\​S-1-5-21-1229272821-1004336348-527237240-1003\​Software\​Classes\​CLSID\​{CAFEEFAC-0013-0001-0000-ABCDEFFEDCBA}
HKU\​S-1-5-21-1229272821-1004336348-527237240-1003\​Software\​Classes\​CLSID\​{CAFEEFAC-0013-0001-0001-ABCDEFFEDCBA}\​InprocServer32
HKU\​S-1-5-21-1229272821-1004336348-527237240-1003\​Software\​Classes\​CLSID\​{CAFEEFAC-0013-0001-0001-ABCDEFFEDCBA}
HKU\​S-1-5-21-1229272821-1004336348-527237240-1003\​Software\​Classes\​CLSID\​{CAFEEFAC-0013-0001-0001-ABCDEFFEDCBB}\​InprocServer32
HKU\​S-1-5-21-1229272821-1004336348-527237240-1003\​Software\​Classes\​CLSID\​{CAFEEFAC-0013-0001-0001-ABCDEFFEDCBB}
HKU\​S-1-5-21-1229272821-1004336348-527237240-1003\​Software\​Classes\​CLSID\​{CAFEEFAC-0013-0001-0002-ABCDEFFEDCBA}\​InprocServer32
HKU\​S-1-5-21-1229272821-1004336348-527237240-1003\​Software\​Classes\​CLSID\​{CAFEEFAC-0013-0001-0002-ABCDEFFEDCBA}
HKU\​S-1-5-21-1229272821-1004336348-527237240-1003\​Software\​Classes\​CLSID\​{CAFEEFAC-0013-0001-0002-ABCDEFFEDCBB}\​InprocServer32
HKU\​S-1-5-21-1229272821-1004336348-527237240-1003\​Software\​Classes\​CLSID\​{CAFEEFAC-0013-0001-0002-ABCDEFFEDCBB}
HKU\​S-1-5-21-1229272821-1004336348-527237240-1003\​Software\​Classes\​CLSID\​{CAFEEFAC-0013-0001-0003-ABCDEFFEDCBA}\​InprocServer32
HKU\​S-1-5-21-1229272821-1004336348-527237240-1003\​Software\​Classes\​CLSID\​{CAFEEFAC-0013-0001-0003-ABCDEFFEDCBA}
HKU\​S-1-5-21-1229272821-1004336348-527237240-1003\​Software\​Classes\​CLSID\​{CAFEEFAC-0013-0001-0003-ABCDEFFEDCBB}\​InprocServer32
HKU\​S-1-5-21-1229272821-1004336348-527237240-1003\​Software\​Classes\​CLSID\​{CAFEEFAC-0013-0001-0003-ABCDEFFEDCBB}
HKU\​S-1-5-21-1229272821-1004336348-527237240-1003\​Software\​Classes\​CLSID\​{CAFEEFAC-0013-0001-0004-ABCDEFFEDCBA}\​InprocServer32
HKU\​S-1-5-21-1229272821-1004336348-527237240-1003\​Software\​Classes\​CLSID\​{CAFEEFAC-0013-0001-0004-ABCDEFFEDCBA}
HKU\​S-1-5-21-1229272821-1004336348-527237240-1003\​Software\​Classes\​CLSID\​{CAFEEFAC-0013-0001-0004-ABCDEFFEDCBB}\​InprocServer32
HKU\​S-1-5-21-1229272821-1004336348-527237240-1003\​Software\​Classes\​CLSID\​{CAFEEFAC-0013-0001-0004-ABCDEFFEDCBB}
HKU\​S-1-5-21-1229272821-1004336348-527237240-1003\​Software\​Classes\​CLSID\​{CAFEEFAC-0013-0001-0005-ABCDEFFEDCBA}\​InprocServer32
HKU\​S-1-5-21-1229272821-1004336348-527237240-1003\​Software\​Classes\​CLSID\​{CAFEEFAC-0013-0001-0005-ABCDEFFEDCBA}
HKU\​S-1-5-21-1229272821-1004336348-527237240-1003\​Software\​Classes\​CLSID\​{CAFEEFAC-0013-0001-0005-ABCDEFFEDCBB}\​InprocServer32
HKU\​S-1-5-21-1229272821-1004336348-527237240-1003\​Software\​Classes\​CLSID\​{CAFEEFAC-0013-0001-0005-ABCDEFFEDCBB}
HKU\​S-1-5-21-1229272821-1004336348-527237240-1003\​Software\​Classes\​CLSID\​{CAFEEFAC-0013-0001-0006-ABCDEFFEDCBA}\​InprocServer32
HKU\​S-1-5-21-1229272821-1004336348-527237240-1003\​Software\​Classes\​CLSID\​{CAFEEFAC-0013-0001-0006-ABCDEFFEDCBA}
HKU\​S-1-5-21-1229272821-1004336348-527237240-1003\​Software\​Classes\​CLSID\​{CAFEEFAC-0013-0001-0006-ABCDEFFEDCBB}\​InprocServer32
HKU\​S-1-5-21-1229272821-1004336348-527237240-1003\​Software\​Classes\​CLSID\​{CAFEEFAC-0013-0001-0006-ABCDEFFEDCBB}
HKU\​S-1-5-21-1229272821-1004336348-527237240-1003\​Software\​Classes\​CLSID\​{CAFEEFAC-0013-0001-0007-ABCDEFFEDCBA}\​InprocServer32
HKU\​S-1-5-21-1229272821-1004336348-527237240-1003\​Software\​Classes\​CLSID\​{CAFEEFAC-0013-0001-0007-ABCDEFFEDCBA}
HKU\​S-1-5-21-1229272821-1004336348-527237240-1003\​Software\​Classes\​CLSID\​{CAFEEFAC-0013-0001-0007-ABCDEFFEDCBB}\​InprocServer32
HKU\​S-1-5-21-1229272821-1004336348-527237240-1003\​Software\​Classes\​CLSID\​{CAFEEFAC-0013-0001-0007-ABCDEFFEDCBB}
HKU\​S-1-5-21-1229272821-1004336348-527237240-1003\​Software\​Classes\​CLSID\​{CAFEEFAC-0013-0001-0008-ABCDEFFEDCBA}\​InprocServer32
HKU\​S-1-5-21-1229272821-1004336348-527237240-1003\​Software\​Classes\​CLSID\​{CAFEEFAC-0013-0001-0008-ABCDEFFEDCBA}
HKU\​S-1-5-21-1229272821-1004336348-527237240-1003\​Software\​Classes\​CLSID\​{CAFEEFAC-0013-0001-0008-ABCDEFFEDCBB}\​InprocServer32
HKU\​S-1-5-21-1229272821-1004336348-527237240-1003\​Software\​Classes\​CLSID\​{CAFEEFAC-0013-0001-0008-ABCDEFFEDCBB}
HKU\​S-1-5-21-1229272821-1004336348-527237240-1003\​Software\​Classes\​CLSID\​{CAFEEFAC-0013-0001-0009-ABCDEFFEDCBA}\​InprocServer32
HKU\​S-1-5-21-1229272821-1004336348-527237240-1003\​Software\​Classes\​CLSID\​{CAFEEFAC-0013-0001-0009-ABCDEFFEDCBA}
HKU\​S-1-5-21-1229272821-1004336348-527237240-1003\​Software\​Classes\​CLSID\​{CAFEEFAC-0013-0001-0009-ABCDEFFEDCBB}\​InprocServer32
HKU\​S-1-5-21-1229272821-1004336348-527237240-1003\​Software\​Classes\​CLSID\​{CAFEEFAC-0013-0001-0009-ABCDEFFEDCBB}
HKU\​S-1-5-21-1229272821-1004336348-527237240-1003\​Software\​Classes\​CLSID\​{CAFEEFAC-0013-0001-0010-ABCDEFFEDCBA}\​InprocServer32
HKU\​S-1-5-21-1229272821-1004336348-527237240-1003\​Software\​Classes\​CLSID\​{CAFEEFAC-0013-0001-0010-ABCDEFFEDCBA}
HKU\​S-1-5-21-1229272821-1004336348-527237240-1003\​Software\​Classes\​CLSID\​{CAFEEFAC-0013-0001-0010-ABCDEFFEDCBB}\​InprocServer32
HKU\​S-1-5-21-1229272821-1004336348-527237240-1003\​Software\​Classes\​CLSID\​{CAFEEFAC-0013-0001-0010-ABCDEFFEDCBB}
HKU\​S-1-5-21-1229272821-1004336348-527237240-1003\​Software\​Classes\​CLSID\​{CAFEEFAC-0013-0001-0011-ABCDEFFEDCBA}\​InprocServer32
HKU\​S-1-5-21-1229272821-1004336348-527237240-1003\​Software\​Classes\​CLSID\​{CAFEEFAC-0013-0001-0011-ABCDEFFEDCBA}
HKU\​S-1-5-21-1229272821-1004336348-527237240-1003\​Software\​Classes\​CLSID\​{CAFEEFAC-0013-0001-0011-ABCDEFFEDCBB}\​InprocServer32
HKU\​S-1-5-21-1229272821-1004336348-527237240-1003\​Software\​Classes\​CLSID\​{CAFEEFAC-0013-0001-0011-ABCDEFFEDCBB}
HKU\​S-1-5-21-1229272821-1004336348-527237240-1003\​Software\​Classes\​CLSID\​{CAFEEFAC-0013-0001-0012-ABCDEFFEDCBA}\​InprocServer32
HKU\​S-1-5-21-1229272821-1004336348-527237240-1003\​Software\​Classes\​CLSID\​{CAFEEFAC-0013-0001-0012-ABCDEFFEDCBA}
HKU\​S-1-5-21-1229272821-1004336348-527237240-1003\​Software\​Classes\​CLSID\​{CAFEEFAC-0013-0001-0012-ABCDEFFEDCBB}\​InprocServer32
HKU\​S-1-5-21-1229272821-1004336348-527237240-1003\​Software\​Classes\​CLSID\​{CAFEEFAC-0013-0001-0012-ABCDEFFEDCBB}
HKU\​S-1-5-21-1229272821-1004336348-527237240-1003\​Software\​Classes\​CLSID\​{CAFEEFAC-0013-0001-0013-ABCDEFFEDCBA}\​InprocServer32
HKU\​S-1-5-21-1229272821-1004336348-527237240-1003\​Software\​Classes\​CLSID\​{CAFEEFAC-0013-0001-0013-ABCDEFFEDCBA}
HKU\​S-1-5-21-1229272821-1004336348-527237240-1003\​Software\​Classes\​CLSID\​{CAFEEFAC-0013-0001-0013-ABCDEFFEDCBB}\​InprocServer32
HKU\​S-1-5-21-1229272821-1004336348-527237240-1003\​Software\​Classes\​CLSID\​{CAFEEFAC-0013-0001-0013-ABCDEFFEDCBB}
HKU\​S-1-5-21-1229272821-1004336348-527237240-1003\​Software\​Classes\​CLSID\​{CAFEEFAC-0013-0001-0014-ABCDEFFEDCBA}\​InprocServer32
HKU\​S-1-5-21-1229272821-1004336348-527237240-1003\​Software\​Classes\​CLSID\​{CAFEEFAC-0013-0001-0014-ABCDEFFEDCBA}
HKU\​S-1-5-21-1229272821-1004336348-527237240-1003\​Software\​Classes\​CLSID\​{CAFEEFAC-0013-0001-0014-ABCDEFFEDCBB}\​InprocServer32
HKU\​S-1-5-21-1229272821-1004336348-527237240-1003\​Software\​Classes\​CLSID\​{CAFEEFAC-0013-0001-0014-ABCDEFFEDCBB}
HKU\​S-1-5-21-1229272821-1004336348-527237240-1003\​Software\​Classes\​CLSID\​{CAFEEFAC-0013-0001-0015-ABCDEFFEDCBA}\​InprocServer32
HKU\​S-1-5-21-1229272821-1004336348-527237240-1003\​Software\​Classes\​CLSID\​{CAFEEFAC-0013-0001-0015-ABCDEFFEDCBA}
HKU\​S-1-5-21-1229272821-1004336348-527237240-1003\​Software\​Classes\​CLSID\​{CAFEEFAC-0013-0001-0015-ABCDEFFEDCBB}\​InprocServer32
HKU\​S-1-5-21-1229272821-1004336348-527237240-1003\​Software\​Classes\​CLSID\​{CAFEEFAC-0013-0001-0015-ABCDEFFEDCBB}
HKU\​S-1-5-21-1229272821-1004336348-527237240-1003\​Software\​Classes\​CLSID\​{CAFEEFAC-0013-0001-0016-ABCDEFFEDCBA}\​InprocServer32
HKU\​S-1-5-21-1229272821-1004336348-527237240-1003\​Software\​Classes\​CLSID\​{CAFEEFAC-0013-0001-0016-ABCDEFFEDCBA}
HKU\​S-1-5-21-1229272821-1004336348-527237240-1003\​Software\​Classes\​CLSID\​{CAFEEFAC-0013-0001-0016-ABCDEFFEDCBB}\​InprocServer32
HKU\​S-1-5-21-1229272821-1004336348-527237240-1003\​Software\​Classes\​CLSID\​{CAFEEFAC-0013-0001-0016-ABCDEFFEDCBB}
HKU\​S-1-5-21-1229272821-1004336348-527237240-1003\​Software\​Classes\​CLSID\​{CAFEEFAC-0013-0001-0017-ABCDEFFEDCBA}\​InprocServer32
HKU\​S-1-5-21-1229272821-1004336348-527237240-1003\​Software\​Classes\​CLSID\​{CAFEEFAC-0013-0001-0017-ABCDEFFEDCBA}
HKU\​S-1-5-21-1229272821-1004336348-527237240-1003\​Software\​Classes\​CLSID\​{CAFEEFAC-0013-0001-0017-ABCDEFFEDCBB}\​InprocServer32
HKU\​S-1-5-21-1229272821-1004336348-527237240-1003\​Software\​Classes\​CLSID\​{CAFEEFAC-0013-0001-0017-ABCDEFFEDCBB}
HKU\​S-1-5-21-1229272821-1004336348-527237240-1003\​Software\​Classes\​CLSID\​{CAFEEFAC-0013-0001-0018-ABCDEFFEDCBA}\​InprocServer32
HKU\​S-1-5-21-1229272821-1004336348-527237240-1003\​Software\​Classes\​CLSID\​{CAFEEFAC-0013-0001-0018-ABCDEFFEDCBA}
HKU\​S-1-5-21-1229272821-1004336348-527237240-1003\​Software\​Classes\​CLSID\​{CAFEEFAC-0013-0001-0018-ABCDEFFEDCBB}\​InprocServer32
HKU\​S-1-5-21-1229272821-1004336348-527237240-1003\​Software\​Classes\​CLSID\​{CAFEEFAC-0013-0001-0018-ABCDEFFEDCBB}
HKU\​S-1-5-21-1229272821-1004336348-527237240-1003\​Software\​Classes\​CLSID\​{CAFEEFAC-0013-0001-0019-ABCDEFFEDCBA}\​InprocServer32
HKU\​S-1-5-21-1229272821-1004336348-527237240-1003\​Software\​Classes\​CLSID\​{CAFEEFAC-0013-0001-0019-ABCDEFFEDCBA}
HKU\​S-1-5-21-1229272821-1004336348-527237240-1003\​Software\​Classes\​CLSID\​{CAFEEFAC-0013-0001-0019-ABCDEFFEDCBB}\​InprocServer32
HKU\​S-1-5-21-1229272821-1004336348-527237240-1003\​Software\​Classes\​CLSID\​{CAFEEFAC-0013-0001-0019-ABCDEFFEDCBB}
HKU\​S-1-5-21-1229272821-1004336348-527237240-1003\​Software\​Classes\​CLSID\​{CAFEEFAC-0013-0001-0020-ABCDEFFEDCBA}\​InprocServer32
HKU\​S-1-5-21-1229272821-1004336348-527237240-1003\​Software\​Classes\​CLSID\​{CAFEEFAC-0013-0001-0020-ABCDEFFEDCBA}
HKU\​S-1-5-21-1229272821-1004336348-527237240-1003\​Software\​Classes\​CLSID\​{CAFEEFAC-0013-0001-0020-ABCDEFFEDCBB}\​InprocServer32
HKU\​S-1-5-21-1229272821-1004336348-527237240-1003\​Software\​Classes\​CLSID\​{CAFEEFAC-0013-0001-0020-ABCDEFFEDCBB}
HKU\​S-1-5-21-1229272821-1004336348-527237240-1003\​Software\​Classes\​CLSID\​{CAFEEFAC-0013-0001-0021-ABCDEFFEDCBA}\​InprocServer32
HKU\​S-1-5-21-1229272821-1004336348-527237240-1003\​Software\​Classes\​CLSID\​{CAFEEFAC-0013-0001-0021-ABCDEFFEDCBA}
HKU\​S-1-5-21-1229272821-1004336348-527237240-1003\​Software\​Classes\​CLSID\​{CAFEEFAC-0013-0001-0021-ABCDEFFEDCBB}\​InprocServer32
HKU\​S-1-5-21-1229272821-1004336348-527237240-1003\​Software\​Classes\​CLSID\​{CAFEEFAC-0013-0001-0021-ABCDEFFEDCBB}
HKU\​S-1-5-21-1229272821-1004336348-527237240-1003\​Software\​Classes\​CLSID\​{CAFEEFAC-0013-0001-0022-ABCDEFFEDCBA}\​InprocServer32
HKU\​S-1-5-21-1229272821-1004336348-527237240-1003\​Software\​Classes\​CLSID\​{CAFEEFAC-0013-0001-0022-ABCDEFFEDCBA}
HKU\​S-1-5-21-1229272821-1004336348-527237240-1003\​Software\​Classes\​CLSID\​{CAFEEFAC-0013-0001-0022-ABCDEFFEDCBB}\​InprocServer32
HKU\​S-1-5-21-1229272821-1004336348-527237240-1003\​Software\​Classes\​CLSID\​{CAFEEFAC-0013-0001-0022-ABCDEFFEDCBB}
HKU\​S-1-5-21-1229272821-1004336348-527237240-1003\​Software\​Classes\​CLSID\​{CAFEEFAC-0013-0001-0023-ABCDEFFEDCBA}\​InprocServer32
HKU\​S-1-5-21-1229272821-1004336348-527237240-1003\​Software\​Classes\​CLSID\​{CAFEEFAC-0013-0001-0023-ABCDEFFEDCBA}
HKU\​S-1-5-21-1229272821-1004336348-527237240-1003\​Software\​Classes\​CLSID\​{CAFEEFAC-0013-0001-0023-ABCDEFFEDCBB}\​InprocServer32
HKU\​S-1-5-21-1229272821-1004336348-527237240-1003\​Software\​Classes\​CLSID\​{CAFEEFAC-0013-0001-0023-ABCDEFFEDCBB}
HKU\​S-1-5-21-1229272821-1004336348-527237240-1003\​Software\​Classes\​CLSID\​{CAFEEFAC-0013-0001-0024-ABCDEFFEDCBA}\​InprocServer32
HKU\​S-1-5-21-1229272821-1004336348-527237240-1003\​Software\​Classes\​CLSID\​{CAFEEFAC-0013-0001-0024-ABCDEFFEDCBA}
HKU\​S-1-5-21-1229272821-1004336348-527237240-1003\​Software\​Classes\​CLSID\​{CAFEEFAC-0013-0001-0024-ABCDEFFEDCBB}\​InprocServer32
HKU\​S-1-5-21-1229272821-1004336348-527237240-1003\​Software\​Classes\​CLSID\​{CAFEEFAC-0013-0001-0024-ABCDEFFEDCBB}
HKU\​S-1-5-21-1229272821-1004336348-527237240-1003\​Software\​Classes\​CLSID\​{CAFEEFAC-0013-0001-0025-ABCDEFFEDCBA}\​InprocServer32
HKU\​S-1-5-21-1229272821-1004336348-527237240-1003\​Software\​Classes\​CLSID\​{CAFEEFAC-0013-0001-0025-ABCDEFFEDCBA}
HKU\​S-1-5-21-1229272821-1004336348-527237240-1003\​Software\​Classes\​CLSID\​{CAFEEFAC-0013-0001-0025-ABCDEFFEDCBB}\​InprocServer32
HKU\​S-1-5-21-1229272821-1004336348-527237240-1003\​Software\​Classes\​CLSID\​{CAFEEFAC-0013-0001-0025-ABCDEFFEDCBB}
HKU\​S-1-5-21-1229272821-1004336348-527237240-1003\​Software\​Classes\​CLSID\​{CAFEEFAC-0013-0001-0026-ABCDEFFEDCBA}\​InprocServer32
HKU\​S-1-5-21-1229272821-1004336348-527237240-1003\​Software\​Classes\​CLSID\​{CAFEEFAC-0013-0001-0026-ABCDEFFEDCBA}
HKU\​S-1-5-21-1229272821-1004336348-527237240-1003\​Software\​Classes\​CLSID\​{CAFEEFAC-0013-0001-0026-ABCDEFFEDCBB}\​InprocServer32
HKU\​S-1-5-21-1229272821-1004336348-527237240-1003\​Software\​Classes\​CLSID\​{CAFEEFAC-0013-0001-0026-ABCDEFFEDCBB}
HKU\​S-1-5-21-1229272821-1004336348-527237240-1003\​Software\​Classes\​CLSID\​{CAFEEFAC-0013-0001-0027-ABCDEFFEDCBA}\​InprocServer32
HKU\​S-1-5-21-1229272821-1004336348-527237240-1003\​Software\​Classes\​CLSID\​{CAFEEFAC-0013-0001-0027-ABCDEFFEDCBA}
HKU\​S-1-5-21-1229272821-1004336348-527237240-1003\​Software\​Classes\​CLSID\​{CAFEEFAC-0013-0001-0027-ABCDEFFEDCBB}\​InprocServer32
HKU\​S-1-5-21-1229272821-1004336348-527237240-1003\​Software\​Classes\​CLSID\​{CAFEEFAC-0013-0001-0027-ABCDEFFEDCBB}
HKU\​S-1-5-21-1229272821-1004336348-527237240-1003\​Software\​Classes\​CLSID\​{CAFEEFAC-0013-0001-0028-ABCDEFFEDCBA}\​InprocServer32
HKU\​S-1-5-21-1229272821-1004336348-527237240-1003\​Software\​Classes\​CLSID\​{CAFEEFAC-0013-0001-0028-ABCDEFFEDCBA}
HKU\​S-1-5-21-1229272821-1004336348-527237240-1003\​Software\​Classes\​CLSID\​{CAFEEFAC-0013-0001-0028-ABCDEFFEDCBB}\​InprocServer32
HKU\​S-1-5-21-1229272821-1004336348-527237240-1003\​Software\​Classes\​CLSID\​{CAFEEFAC-0013-0001-0028-ABCDEFFEDCBB}
HKU\​S-1-5-21-1229272821-1004336348-527237240-1003\​Software\​Classes\​CLSID\​{CAFEEFAC-0013-0001-0029-ABCDEFFEDCBA}\​InprocServer32
HKU\​S-1-5-21-1229272821-1004336348-527237240-1003\​Software\​Classes\​CLSID\​{CAFEEFAC-0013-0001-0029-ABCDEFFEDCBA}
HKU\​S-1-5-21-1229272821-1004336348-527237240-1003\​Software\​Classes\​CLSID\​{CAFEEFAC-0013-0001-0029-ABCDEFFEDCBB}\​InprocServer32
HKU\​S-1-5-21-1229272821-1004336348-527237240-1003\​Software\​Classes\​CLSID\​{CAFEEFAC-0013-0001-0029-ABCDEFFEDCBB}
HKU\​S-1-5-21-1229272821-1004336348-527237240-1003\​Software\​Classes\​CLSID\​{CAFEEFAC-0013-0001-0030-ABCDEFFEDCBA}\​InprocServer32
HKU\​S-1-5-21-1229272821-1004336348-527237240-1003\​Software\​Classes\​CLSID\​{CAFEEFAC-0013-0001-0030-ABCDEFFEDCBA}
HKU\​S-1-5-21-1229272821-1004336348-527237240-1003\​Software\​Classes\​CLSID\​{CAFEEFAC-0013-0001-0030-ABCDEFFEDCBB}\​InprocServer32
HKU\​S-1-5-21-1229272821-1004336348-527237240-1003\​Software\​Classes\​CLSID\​{CAFEEFAC-0013-0001-0030-ABCDEFFEDCBB}
HKU\​S-1-5-21-1229272821-1004336348-527237240-1003\​Software\​Classes\​CLSID\​{CAFEEFAC-0014-0000-0000-ABCDEFFEDCBA}\​InprocServer32
HKU\​S-1-5-21-1229272821-1004336348-527237240-1003\​Software\​Classes\​CLSID\​{CAFEEFAC-0014-0000-0000-ABCDEFFEDCBA}
HKU\​S-1-5-21-1229272821-1004336348-527237240-1003\​Software\​Classes\​CLSID\​{CAFEEFAC-0014-0000-0000-ABCDEFFEDCBB}\​InprocServer32
HKU\​S-1-5-21-1229272821-1004336348-527237240-1003\​Software\​Classes\​CLSID\​{CAFEEFAC-0014-0000-0000-ABCDEFFEDCBB}
HKU\​S-1-5-21-1229272821-1004336348-527237240-1003\​Software\​Classes\​CLSID\​{CAFEEFAC-0014-0000-0001-ABCDEFFEDCBA}\​InprocServer32
HKU\​S-1-5-21-1229272821-1004336348-527237240-1003\​Software\​Classes\​CLSID\​{CAFEEFAC-0014-0000-0001-ABCDEFFEDCBA}
HKU\​S-1-5-21-1229272821-1004336348-527237240-1003\​Software\​Classes\​CLSID\​{CAFEEFAC-0014-0000-0001-ABCDEFFEDCBB}\​InprocServer32
HKU\​S-1-5-21-1229272821-1004336348-527237240-1003\​Software\​Classes\​CLSID\​{CAFEEFAC-0014-0000-0001-ABCDEFFEDCBB}
HKU\​S-1-5-21-1229272821-1004336348-527237240-1003\​Software\​Classes\​CLSID\​{CAFEEFAC-0014-0000-0002-ABCDEFFEDCBA}\​InprocServer32
HKU\​S-1-5-21-1229272821-1004336348-527237240-1003\​Software\​Classes\​CLSID\​{CAFEEFAC-0014-0000-0002-ABCDEFFEDCBA}
HKU\​S-1-5-21-1229272821-1004336348-527237240-1003\​Software\​Classes\​CLSID\​{CAFEEFAC-0014-0000-0002-ABCDEFFEDCBB}\​InprocServer32
HKU\​S-1-5-21-1229272821-1004336348-527237240-1003\​Software\​Classes\​CLSID\​{CAFEEFAC-0014-0000-0002-ABCDEFFEDCBB}
HKU\​S-1-5-21-1229272821-1004336348-527237240-1003\​Software\​Classes\​CLSID\​{CAFEEFAC-0014-0000-0003-ABCDEFFEDCBA}\​InprocServer32
HKU\​S-1-5-21-1229272821-1004336348-527237240-1003\​Software\​Classes\​CLSID\​{CAFEEFAC-0014-0000-0003-ABCDEFFEDCBA}
HKU\​S-1-5-21-1229272821-1004336348-527237240-1003\​Software\​Classes\​CLSID\​{CAFEEFAC-0014-0000-0003-ABCDEFFEDCBB}\​InprocServer32
HKU\​S-1-5-21-1229272821-1004336348-527237240-1003\​Software\​Classes\​CLSID\​{CAFEEFAC-0014-0000-0003-ABCDEFFEDCBB}
HKU\​S-1-5-21-1229272821-1004336348-527237240-1003\​Software\​Classes\​CLSID\​{CAFEEFAC-0014-0000-0004-ABCDEFFEDCBA}\​InprocServer32
HKU\​S-1-5-21-1229272821-1004336348-527237240-1003\​Software\​Classes\​CLSID\​{CAFEEFAC-0014-0000-0004-ABCDEFFEDCBA}
HKU\​S-1-5-21-1229272821-1004336348-527237240-1003\​Software\​Classes\​CLSID\​{CAFEEFAC-0014-0000-0004-ABCDEFFEDCBB}\​InprocServer32
HKU\​S-1-5-21-1229272821-1004336348-527237240-1003\​Software\​Classes\​CLSID\​{CAFEEFAC-0014-0000-0004-ABCDEFFEDCBB}
HKU\​S-1-5-21-1229272821-1004336348-527237240-1003\​Software\​Classes\​CLSID\​{CAFEEFAC-0014-0001-0000-ABCDEFFEDCBA}\​InprocServer32
HKU\​S-1-5-21-1229272821-1004336348-527237240-1003\​Software\​Classes\​CLSID\​{CAFEEFAC-0014-0001-0000-ABCDEFFEDCBA}
HKU\​S-1-5-21-1229272821-1004336348-527237240-1003\​Software\​Classes\​CLSID\​{CAFEEFAC-0014-0001-0000-ABCDEFFEDCBB}\​InprocServer32
HKU\​S-1-5-21-1229272821-1004336348-527237240-1003\​Software\​Classes\​CLSID\​{CAFEEFAC-0014-0001-0000-ABCDEFFEDCBB}
HKU\​S-1-5-21-1229272821-1004336348-527237240-1003\​Software\​Classes\​CLSID\​{CAFEEFAC-0014-0001-0001-ABCDEFFEDCBA}\​InprocServer32
HKU\​S-1-5-21-1229272821-1004336348-527237240-1003\​Software\​Classes\​CLSID\​{CAFEEFAC-0014-0001-0001-ABCDEFFEDCBA}
HKU\​S-1-5-21-1229272821-1004336348-527237240-1003\​Software\​Classes\​CLSID\​{CAFEEFAC-0014-0001-0001-ABCDEFFEDCBB}\​InprocServer32
HKU\​S-1-5-21-1229272821-1004336348-527237240-1003\​Software\​Classes\​CLSID\​{CAFEEFAC-0014-0001-0001-ABCDEFFEDCBB}
HKU\​S-1-5-21-1229272821-1004336348-527237240-1003\​Software\​Classes\​CLSID\​{CAFEEFAC-0014-0001-0002-ABCDEFFEDCBA}\​InprocServer32
HKU\​S-1-5-21-1229272821-1004336348-527237240-1003\​Software\​Classes\​CLSID\​{CAFEEFAC-0014-0001-0002-ABCDEFFEDCBA}
HKU\​S-1-5-21-1229272821-1004336348-527237240-1003\​Software\​Classes\​CLSID\​{CAFEEFAC-0014-0001-0002-ABCDEFFEDCBB}\​InprocServer32
HKU\​S-1-5-21-1229272821-1004336348-527237240-1003\​Software\​Classes\​CLSID\​{CAFEEFAC-0014-0001-0002-ABCDEFFEDCBB}
HKU\​S-1-5-21-1229272821-1004336348-527237240-1003\​Software\​Classes\​CLSID\​{CAFEEFAC-0014-0001-0003-ABCDEFFEDCBA}\​InprocServer32
HKU\​S-1-5-21-1229272821-1004336348-527237240-1003\​Software\​Classes\​CLSID\​{CAFEEFAC-0014-0001-0003-ABCDEFFEDCBA}
HKU\​S-1-5-21-1229272821-1004336348-527237240-1003\​Software\​Classes\​CLSID\​{CAFEEFAC-0014-0001-0003-ABCDEFFEDCBB}\​InprocServer32
HKU\​S-1-5-21-1229272821-1004336348-527237240-1003\​Software\​Classes\​CLSID\​{CAFEEFAC-0014-0001-0003-ABCDEFFEDCBB}
HKU\​S-1-5-21-1229272821-1004336348-527237240-1003\​Software\​Classes\​CLSID\​{CAFEEFAC-0014-0001-0004-ABCDEFFEDCBA}\​InprocServer32
HKU\​S-1-5-21-1229272821-1004336348-527237240-1003\​Software\​Classes\​CLSID\​{CAFEEFAC-0014-0001-0004-ABCDEFFEDCBA}
HKU\​S-1-5-21-1229272821-1004336348-527237240-1003\​Software\​Classes\​CLSID\​{CAFEEFAC-0014-0001-0004-ABCDEFFEDCBB}\​InprocServer32
HKU\​S-1-5-21-1229272821-1004336348-527237240-1003\​Software\​Classes\​CLSID\​{CAFEEFAC-0014-0001-0004-ABCDEFFEDCBB}
HKU\​S-1-5-21-1229272821-1004336348-527237240-1003\​Software\​Classes\​CLSID\​{CAFEEFAC-0014-0001-0005-ABCDEFFEDCBA}\​InprocServer32
HKU\​S-1-5-21-1229272821-1004336348-527237240-1003\​Software\​Classes\​CLSID\​{CAFEEFAC-0014-0001-0005-ABCDEFFEDCBA}
HKU\​S-1-5-21-1229272821-1004336348-527237240-1003\​Software\​Classes\​CLSID\​{CAFEEFAC-0014-0001-0005-ABCDEFFEDCBB}\​InprocServer32
HKU\​S-1-5-21-1229272821-1004336348-527237240-1003\​Software\​Classes\​CLSID\​{CAFEEFAC-0014-0001-0005-ABCDEFFEDCBB}
HKU\​S-1-5-21-1229272821-1004336348-527237240-1003\​Software\​Classes\​CLSID\​{CAFEEFAC-0014-0001-0006-ABCDEFFEDCBA}\​InprocServer32
HKU\​S-1-5-21-1229272821-1004336348-527237240-1003\​Software\​Classes\​CLSID\​{CAFEEFAC-0014-0001-0006-ABCDEFFEDCBA}
HKU\​S-1-5-21-1229272821-1004336348-527237240-1003\​Software\​Classes\​CLSID\​{CAFEEFAC-0014-0001-0006-ABCDEFFEDCBB}\​InprocServer32
HKU\​S-1-5-21-1229272821-1004336348-527237240-1003\​Software\​Classes\​CLSID\​{CAFEEFAC-0014-0001-0006-ABCDEFFEDCBB}
HKU\​S-1-5-21-1229272821-1004336348-527237240-1003\​Software\​Classes\​CLSID\​{CAFEEFAC-0014-0001-0007-ABCDEFFEDCBA}\​InprocServer32
HKU\​S-1-5-21-1229272821-1004336348-527237240-1003\​Software\​Classes\​CLSID\​{CAFEEFAC-0014-0001-0007-ABCDEFFEDCBA}
HKU\​S-1-5-21-1229272821-1004336348-527237240-1003\​Software\​Classes\​CLSID\​{CAFEEFAC-0014-0001-0007-ABCDEFFEDCBB}\​InprocServer32
HKU\​S-1-5-21-1229272821-1004336348-527237240-1003\​Software\​Classes\​CLSID\​{CAFEEFAC-0014-0001-0007-ABCDEFFEDCBB}
HKU\​S-1-5-21-1229272821-1004336348-527237240-1003\​Software\​Classes\​CLSID\​{CAFEEFAC-0014-0002-0000-ABCDEFFEDCBA}\​InprocServer32
HKU\​S-1-5-21-1229272821-1004336348-527237240-1003\​Software\​Classes\​CLSID\​{CAFEEFAC-0014-0002-0000-ABCDEFFEDCBA}
HKU\​S-1-5-21-1229272821-1004336348-527237240-1003\​Software\​Classes\​CLSID\​{CAFEEFAC-0014-0002-0000-ABCDEFFEDCBB}\​InprocServer32
HKU\​S-1-5-21-1229272821-1004336348-527237240-1003\​Software\​Classes\​CLSID\​{CAFEEFAC-0014-0002-0000-ABCDEFFEDCBB}
HKU\​S-1-5-21-1229272821-1004336348-527237240-1003\​Software\​Classes\​CLSID\​{CAFEEFAC-0014-0002-0001-ABCDEFFEDCBA}\​InprocServer32
HKU\​S-1-5-21-1229272821-1004336348-527237240-1003\​Software\​Classes\​CLSID\​{CAFEEFAC-0014-0002-0001-ABCDEFFEDCBA}
HKU\​S-1-5-21-1229272821-1004336348-527237240-1003\​Software\​Classes\​CLSID\​{CAFEEFAC-0014-0002-0001-ABCDEFFEDCBB}\​InprocServer32
HKU\​S-1-5-21-1229272821-1004336348-527237240-1003\​Software\​Classes\​CLSID\​{CAFEEFAC-0014-0002-0001-ABCDEFFEDCBB}
HKU\​S-1-5-21-1229272821-1004336348-527237240-1003\​Software\​Classes\​CLSID\​{CAFEEFAC-0014-0002-0002-ABCDEFFEDCBA}\​InprocServer32
HKU\​S-1-5-21-1229272821-1004336348-527237240-1003\​Software\​Classes\​CLSID\​{CAFEEFAC-0014-0002-0002-ABCDEFFEDCBA}
HKU\​S-1-5-21-1229272821-1004336348-527237240-1003\​Software\​Classes\​CLSID\​{CAFEEFAC-0014-0002-0002-ABCDEFFEDCBB}\​InprocServer32
HKU\​S-1-5-21-1229272821-1004336348-527237240-1003\​Software\​Classes\​CLSID\​{CAFEEFAC-0014-0002-0002-ABCDEFFEDCBB}
HKU\​S-1-5-21-1229272821-1004336348-527237240-1003\​Software\​Classes\​CLSID\​{CAFEEFAC-0014-0002-0003-ABCDEFFEDCBA}\​InprocServer32
HKU\​S-1-5-21-1229272821-1004336348-527237240-1003\​Software\​Classes\​CLSID\​{CAFEEFAC-0014-0002-0003-ABCDEFFEDCBA}
HKU\​S-1-5-21-1229272821-1004336348-527237240-1003\​Software\​Classes\​CLSID\​{CAFEEFAC-0014-0002-0003-ABCDEFFEDCBB}\​InprocServer32
HKU\​S-1-5-21-1229272821-1004336348-527237240-1003\​Software\​Classes\​CLSID\​{CAFEEFAC-0014-0002-0003-ABCDEFFEDCBB}
HKU\​S-1-5-21-1229272821-1004336348-527237240-1003\​Software\​Classes\​CLSID\​{CAFEEFAC-0014-0002-0004-ABCDEFFEDCBA}\​InprocServer32
HKU\​S-1-5-21-1229272821-1004336348-527237240-1003\​Software\​Classes\​CLSID\​{CAFEEFAC-0014-0002-0004-ABCDEFFEDCBA}

  - Registry Values Modified:  
Key Name New Value
HKU\​S-1-5-21-1229272821-1004336348-527237240-1003\​SOFTWARE\​Microsoft\​CTF\​TIP\​{1188450c-fdab-47ae-80d8-c9633f71be64}\​LanguageProfile\​0x00000000\​{63800dac-e7ca-4df9-9a5c-20765055488d}  Enable 
HKU\​S-1-5-21-1229272821-1004336348-527237240-1003\​SOFTWARE\​Microsoft\​Windows\​CurrentVersion\​Ext\​Stats\​{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}\​iexplore  Count  25 
HKU\​S-1-5-21-1229272821-1004336348-527237240-1003\​SOFTWARE\​Microsoft\​Windows\​CurrentVersion\​Ext\​Stats\​{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}\​iexplore  Time  0xd8070500010013000b0035001700d803 
HKU\​S-1-5-21-1229272821-1004336348-527237240-1003\​SOFTWARE\​Microsoft\​Windows\​CurrentVersion\​Ext\​Stats\​{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}\​iexplore  Type 
HKU\​S-1-5-21-1229272821-1004336348-527237240-1003\​Software\​Classes\​CLSID\​{CAFEEFAC-0013-0000-0003-ABCDEFFEDCBA}    Java Plug-in 1.3.0_03 
HKU\​S-1-5-21-1229272821-1004336348-527237240-1003\​Software\​Classes\​CLSID\​{CAFEEFAC-0013-0000-0003-ABCDEFFEDCBA}\​InprocServer32    C:\​Program Files\​Java\​jre1.6.0_03\​bin\​ssv.dll 
HKU\​S-1-5-21-1229272821-1004336348-527237240-1003\​Software\​Classes\​CLSID\​{CAFEEFAC-0013-0000-0003-ABCDEFFEDCBA}\​InprocServer32  ThreadingModel  Apartment 
HKU\​S-1-5-21-1229272821-1004336348-527237240-1003\​Software\​Classes\​CLSID\​{CAFEEFAC-0013-0000-0004-ABCDEFFEDCBA}    Java Plug-in 1.3.0_04 
HKU\​S-1-5-21-1229272821-1004336348-527237240-1003\​Software\​Classes\​CLSID\​{CAFEEFAC-0013-0000-0004-ABCDEFFEDCBA}\​InprocServer32    C:\​Program Files\​Java\​jre1.6.0_03\​bin\​ssv.dll 
HKU\​S-1-5-21-1229272821-1004336348-527237240-1003\​Software\​Classes\​CLSID\​{CAFEEFAC-0013-0000-0004-ABCDEFFEDCBA}\​InprocServer32  ThreadingModel  Apartment 
HKU\​S-1-5-21-1229272821-1004336348-527237240-1003\​Software\​Classes\​CLSID\​{CAFEEFAC-0013-0000-0005-ABCDEFFEDCBA}    Java Plug-in 1.3.0_05 
HKU\​S-1-5-21-1229272821-1004336348-527237240-1003\​Software\​Classes\​CLSID\​{CAFEEFAC-0013-0000-0005-ABCDEFFEDCBA}\​InprocServer32    C:\​Program Files\​Java\​jre1.6.0_03\​bin\​ssv.dll 
HKU\​S-1-5-21-1229272821-1004336348-527237240-1003\​Software\​Classes\​CLSID\​{CAFEEFAC-0013-0000-0005-ABCDEFFEDCBA}\​InprocServer32  ThreadingModel  Apartment 
HKU\​S-1-5-21-1229272821-1004336348-527237240-1003\​Software\​Classes\​CLSID\​{CAFEEFAC-0013-0001-0000-ABCDEFFEDCBA}    Java Plug-in 1.3.1 
HKU\​S-1-5-21-1229272821-1004336348-527237240-1003\​Software\​Classes\​CLSID\​{CAFEEFAC-0013-0001-0000-ABCDEFFEDCBA}\​InprocServer32    C:\​Program Files\​Java\​jre1.6.0_03\​bin\​ssv.dll 
HKU\​S-1-5-21-1229272821-1004336348-527237240-1003\​Software\​Classes\​CLSID\​{CAFEEFAC-0013-0001-0000-ABCDEFFEDCBA}\​InprocServer32  ThreadingModel  Apartment 
HKU\​S-1-5-21-1229272821-1004336348-527237240-1003\​Software\​Classes\​CLSID\​{CAFEEFAC-0013-0001-0001-ABCDEFFEDCBA}    Java Plug-in 1.3.1_01 
HKU\​S-1-5-21-1229272821-1004336348-527237240-1003\​Software\​Classes\​CLSID\​{CAFEEFAC-0013-0001-0001-ABCDEFFEDCBA}\​InprocServer32    C:\​Program Files\​Java\​jre1.6.0_03\​bin\​ssv.dll 
HKU\​S-1-5-21-1229272821-1004336348-527237240-1003\​Software\​Classes\​CLSID\​{CAFEEFAC-0013-0001-0001-ABCDEFFEDCBA}\​InprocServer32  ThreadingModel  Apartment 
HKU\​S-1-5-21-1229272821-1004336348-527237240-1003\​Software\​Classes\​CLSID\​{CAFEEFAC-0013-0001-0001-ABCDEFFEDCBB}    Java Plug-in 1.3.1_01 
HKU\​S-1-5-21-1229272821-1004336348-527237240-1003\​Software\​Classes\​CLSID\​{CAFEEFAC-0013-0001-0001-ABCDEFFEDCBB}\​InprocServer32    C:\​Program Files\​Java\​jre1.6.0_03\​bin\​ssv.dll 
HKU\​S-1-5-21-1229272821-1004336348-527237240-1003\​Software\​Classes\​CLSID\​{CAFEEFAC-0013-0001-0001-ABCDEFFEDCBB}\​InprocServer32  ThreadingModel  Apartment 
HKU\​S-1-5-21-1229272821-1004336348-527237240-1003\​Software\​Classes\​CLSID\​{CAFEEFAC-0013-0001-0002-ABCDEFFEDCBA}    Java Plug-in 1.3.1_02 
HKU\​S-1-5-21-1229272821-1004336348-527237240-1003\​Software\​Classes\​CLSID\​{CAFEEFAC-0013-0001-0002-ABCDEFFEDCBA}\​InprocServer32    C:\​Program Files\​Java\​jre1.6.0_03\​bin\​ssv.dll 
HKU\​S-1-5-21-1229272821-1004336348-527237240-1003\​Software\​Classes\​CLSID\​{CAFEEFAC-0013-0001-0002-ABCDEFFEDCBA}\​InprocServer32  ThreadingModel  Apartment 
HKU\​S-1-5-21-1229272821-1004336348-527237240-1003\​Software\​Classes\​CLSID\​{CAFEEFAC-0013-0001-0002-ABCDEFFEDCBB}    Java Plug-in 1.3.1_02 
HKU\​S-1-5-21-1229272821-1004336348-527237240-1003\​Software\​Classes\​CLSID\​{CAFEEFAC-0013-0001-0002-ABCDEFFEDCBB}\​InprocServer32    C:\​Program Files\​Java\​jre1.6.0_03\​bin\​ssv.dll 
HKU\​S-1-5-21-1229272821-1004336348-527237240-1003\​Software\​Classes\​CLSID\​{CAFEEFAC-0013-0001-0002-ABCDEFFEDCBB}\​InprocServer32  ThreadingModel  Apartment 
HKU\​S-1-5-21-1229272821-1004336348-527237240-1003\​Software\​Classes\​CLSID\​{CAFEEFAC-0013-0001-0003-ABCDEFFEDCBA}    Java Plug-in 1.3.1_03 
HKU\​S-1-5-21-1229272821-1004336348-527237240-1003\​Software\​Classes\​CLSID\​{CAFEEFAC-0013-0001-0003-ABCDEFFEDCBA}\​InprocServer32    C:\​Program Files\​Java\​jre1.6.0_03\​bin\​ssv.dll 
HKU\​S-1-5-21-1229272821-1004336348-527237240-1003\​Software\​Classes\​CLSID\​{CAFEEFAC-0013-0001-0003-ABCDEFFEDCBA}\​InprocServer32  ThreadingModel  Apartment 
HKU\​S-1-5-21-1229272821-1004336348-527237240-1003\​Software\​Classes\​CLSID\​{CAFEEFAC-0013-0001-0003-ABCDEFFEDCBB}    Java Plug-in 1.3.1_03 
HKU\​S-1-5-21-1229272821-1004336348-527237240-1003\​Software\​Classes\​CLSID\​{CAFEEFAC-0013-0001-0003-ABCDEFFEDCBB}\​InprocServer32    C:\​Program Files\​Java\​jre1.6.0_03\​bin\​ssv.dll 
HKU\​S-1-5-21-1229272821-1004336348-527237240-1003\​Software\​Classes\​CLSID\​{CAFEEFAC-0013-0001-0003-ABCDEFFEDCBB}\​InprocServer32  ThreadingModel  Apartment 
HKU\​S-1-5-21-1229272821-1004336348-527237240-1003\​Software\​Classes\​CLSID\​{CAFEEFAC-0013-0001-0004-ABCDEFFEDCBA}    Java Plug-in 1.3.1_04 
HKU\​S-1-5-21-1229272821-1004336348-527237240-1003\​Software\​Classes\​CLSID\​{CAFEEFAC-0013-0001-0004-ABCDEFFEDCBA}\​InprocServer32    C:\​Program Files\​Java\​jre1.6.0_03\​bin\​ssv.dll 
HKU\​S-1-5-21-1229272821-1004336348-527237240-1003\​Software\​Classes\​CLSID\​{CAFEEFAC-0013-0001-0004-ABCDEFFEDCBA}\​InprocServer32  ThreadingModel  Apartment 
HKU\​S-1-5-21-1229272821-1004336348-527237240-1003\​Software\​Classes\​CLSID\​{CAFEEFAC-0013-0001-0004-ABCDEFFEDCBB}    Java Plug-in 1.3.1_04 
HKU\​S-1-5-21-1229272821-1004336348-527237240-1003\​Software\​Classes\​CLSID\​{CAFEEFAC-0013-0001-0004-ABCDEFFEDCBB}\​InprocServer32    C:\​Program Files\​Java\​jre1.6.0_03\​bin\​ssv.dll 
HKU\​S-1-5-21-1229272821-1004336348-527237240-1003\​Software\​Classes\​CLSID\​{CAFEEFAC-0013-0001-0004-ABCDEFFEDCBB}\​InprocServer32  ThreadingModel  Apartment 
HKU\​S-1-5-21-1229272821-1004336348-527237240-1003\​Software\​Classes\​CLSID\​{CAFEEFAC-0013-0001-0005-ABCDEFFEDCBA}    Java Plug-in 1.3.1_05 
HKU\​S-1-5-21-1229272821-1004336348-527237240-1003\​Software\​Classes\​CLSID\​{CAFEEFAC-0013-0001-0005-ABCDEFFEDCBA}\​InprocServer32    C:\​Program Files\​Java\​jre1.6.0_03\​bin\​ssv.dll 
HKU\​S-1-5-21-1229272821-1004336348-527237240-1003\​Software\​Classes\​CLSID\​{CAFEEFAC-0013-0001-0005-ABCDEFFEDCBA}\​InprocServer32  ThreadingModel  Apartment 
HKU\​S-1-5-21-1229272821-1004336348-527237240-1003\​Software\​Classes\​CLSID\​{CAFEEFAC-0013-0001-0005-ABCDEFFEDCBB}    Java Plug-in 1.3.1_05 
HKU\​S-1-5-21-1229272821-1004336348-527237240-1003\​Software\​Classes\​CLSID\​{CAFEEFAC-0013-0001-0005-ABCDEFFEDCBB}\​InprocServer32    C:\​Program Files\​Java\​jre1.6.0_03\​bin\​ssv.dll 
HKU\​S-1-5-21-1229272821-1004336348-527237240-1003\​Software\​Classes\​CLSID\​{CAFEEFAC-0013-0001-0005-ABCDEFFEDCBB}\​InprocServer32  ThreadingModel  Apartment 
HKU\​S-1-5-21-1229272821-1004336348-527237240-1003\​Software\​Classes\​CLSID\​{CAFEEFAC-0013-0001-0006-ABCDEFFEDCBA}    Java Plug-in 1.3.1_06 
HKU\​S-1-5-21-1229272821-1004336348-527237240-1003\​Software\​Classes\​CLSID\​{CAFEEFAC-0013-0001-0006-ABCDEFFEDCBA}\​InprocServer32    C:\​Program Files\​Java\​jre1.6.0_03\​bin\​ssv.dll 
HKU\​S-1-5-21-1229272821-1004336348-527237240-1003\​Software\​Classes\​CLSID\​{CAFEEFAC-0013-0001-0006-ABCDEFFEDCBA}\​InprocServer32  ThreadingModel  Apartment 
HKU\​S-1-5-21-1229272821-1004336348-527237240-1003\​Software\​Classes\​CLSID\​{CAFEEFAC-0013-0001-0006-ABCDEFFEDCBB}    Java Plug-in 1.3.1_06 
HKU\​S-1-5-21-1229272821-1004336348-527237240-1003\​Software\​Classes\​CLSID\​{CAFEEFAC-0013-0001-0006-ABCDEFFEDCBB}\​InprocServer32    C:\​Program Files\​Java\​jre1.6.0_03\​bin\​ssv.dll 
HKU\​S-1-5-21-1229272821-1004336348-527237240-1003\​Software\​Classes\​CLSID\​{CAFEEFAC-0013-0001-0006-ABCDEFFEDCBB}\​InprocServer32  ThreadingModel  Apartment 
HKU\​S-1-5-21-1229272821-1004336348-527237240-1003\​Software\​Classes\​CLSID\​{CAFEEFAC-0013-0001-0007-ABCDEFFEDCBA}    Java Plug-in 1.3.1_07 
HKU\​S-1-5-21-1229272821-1004336348-527237240-1003\​Software\​Classes\​CLSID\​{CAFEEFAC-0013-0001-0007-ABCDEFFEDCBA}\​InprocServer32    C:\​Program Files\​Java\​jre1.6.0_03\​bin\​ssv.dll 
HKU\​S-1-5-21-1229272821-1004336348-527237240-1003\​Software\​Classes\​CLSID\​{CAFEEFAC-0013-0001-0007-ABCDEFFEDCBA}\​InprocServer32  ThreadingModel  Apartment 
HKU\​S-1-5-21-1229272821-1004336348-527237240-1003\​Software\​Classes\​CLSID\​{CAFEEFAC-0013-0001-0007-ABCDEFFEDCBB}    Java Plug-in 1.3.1_07 
HKU\​S-1-5-21-1229272821-1004336348-527237240-1003\​Software\​Classes\​CLSID\​{CAFEEFAC-0013-0001-0007-ABCDEFFEDCBB}\​InprocServer32    C:\​Program Files\​Java\​jre1.6.0_03\​bin\​ssv.dll 
HKU\​S-1-5-21-1229272821-1004336348-527237240-1003\​Software\​Classes\​CLSID\​{CAFEEFAC-0013-0001-0007-ABCDEFFEDCBB}\​InprocServer32  ThreadingModel  Apartment 
HKU\​S-1-5-21-1229272821-1004336348-527237240-1003\​Software\​Classes\​CLSID\​{CAFEEFAC-0013-0001-0008-ABCDEFFEDCBA}    Java Plug-in 1.3.1_08 
HKU\​S-1-5-21-1229272821-1004336348-527237240-1003\​Software\​Classes\​CLSID\​{CAFEEFAC-0013-0001-0008-ABCDEFFEDCBA}\​InprocServer32    C:\​Program Files\​Java\​jre1.6.0_03\​bin\​ssv.dll 
HKU\​S-1-5-21-1229272821-1004336348-527237240-1003\​Software\​Classes\​CLSID\​{CAFEEFAC-0013-0001-0008-ABCDEFFEDCBA}\​InprocServer32  ThreadingModel  Apartment 
HKU\​S-1-5-21-1229272821-1004336348-527237240-1003\​Software\​Classes\​CLSID\​{CAFEEFAC-0013-0001-0008-ABCDEFFEDCBB}    Java Plug-in 1.3.1_08 
HKU\​S-1-5-21-1229272821-1004336348-527237240-1003\​Software\​Classes\​CLSID\​{CAFEEFAC-0013-0001-0008-ABCDEFFEDCBB}\​InprocServer32    C:\​Program Files\​Java\​jre1.6.0_03\​bin\​ssv.dll 
HKU\​S-1-5-21-1229272821-1004336348-527237240-1003\​Software\​Classes\​CLSID\​{CAFEEFAC-0013-0001-0008-ABCDEFFEDCBB}\​InprocServer32  ThreadingModel  Apartment 
HKU\​S-1-5-21-1229272821-1004336348-527237240-1003\​Software\​Classes\​CLSID\​{CAFEEFAC-0013-0001-0009-ABCDEFFEDCBA}    Java Plug-in 1.3.1_09 
HKU\​S-1-5-21-1229272821-1004336348-527237240-1003\​Software\​Classes\​CLSID\​{CAFEEFAC-0013-0001-0009-ABCDEFFEDCBA}\​InprocServer32    C:\​Program Files\​Java\​jre1.6.0_03\​bin\​ssv.dll 
HKU\​S-1-5-21-1229272821-1004336348-527237240-1003\​Software\​Classes\​CLSID\​{CAFEEFAC-0013-0001-0009-ABCDEFFEDCBA}\​InprocServer32  ThreadingModel  Apartment 
HKU\​S-1-5-21-1229272821-1004336348-527237240-1003\​Software\​Classes\​CLSID\​{CAFEEFAC-0013-0001-0009-ABCDEFFEDCBB}    Java Plug-in 1.3.1_09 
HKU\​S-1-5-21-1229272821-1004336348-527237240-1003\​Software\​Classes\​CLSID\​{CAFEEFAC-0013-0001-0009-ABCDEFFEDCBB}\​InprocServer32    C:\​Program Files\​Java\​jre1.6.0_03\​bin\​ssv.dll 
HKU\​S-1-5-21-1229272821-1004336348-527237240-1003\​Software\​Classes\​CLSID\​{CAFEEFAC-0013-0001-0009-ABCDEFFEDCBB}\​InprocServer32  ThreadingModel  Apartment 
HKU\​S-1-5-21-1229272821-1004336348-527237240-1003\​Software\​Classes\​CLSID\​{CAFEEFAC-0013-0001-0010-ABCDEFFEDCBA}    Java Plug-in 1.3.1_10 
HKU\​S-1-5-21-1229272821-1004336348-527237240-1003\​Software\​Classes\​CLSID\​{CAFEEFAC-0013-0001-0010-ABCDEFFEDCBA}\​InprocServer32    C:\​Program Files\​Java\​jre1.6.0_03\​bin\​ssv.dll 
HKU\​S-1-5-21-1229272821-1004336348-527237240-1003\​Software\​Classes\​CLSID\​{CAFEEFAC-0013-0001-0010-ABCDEFFEDCBA}\​InprocServer32  ThreadingModel  Apartment 
HKU\​S-1-5-21-1229272821-1004336348-527237240-1003\​Software\​Classes\​CLSID\​{CAFEEFAC-0013-0001-0010-ABCDEFFEDCBB}    Java Plug-in 1.3.1_10 
HKU\​S-1-5-21-1229272821-1004336348-527237240-1003\​Software\​Classes\​CLSID\​{CAFEEFAC-0013-0001-0010-ABCDEFFEDCBB}\​InprocServer32    C:\​Program Files\​Java\​jre1.6.0_03\​bin\​ssv.dll 
HKU\​S-1-5-21-1229272821-1004336348-527237240-1003\​Software\​Classes\​CLSID\​{CAFEEFAC-0013-0001-0010-ABCDEFFEDCBB}\​InprocServer32  ThreadingModel  Apartment 
HKU\​S-1-5-21-1229272821-1004336348-527237240-1003\​Software\​Classes\​CLSID\​{CAFEEFAC-0013-0001-0011-ABCDEFFEDCBA}    Java Plug-in 1.3.1_11 
HKU\​S-1-5-21-1229272821-1004336348-527237240-1003\​Software\​Classes\​CLSID\​{CAFEEFAC-0013-0001-0011-ABCDEFFEDCBA}\​InprocServer32    C:\​Program Files\​Java\​jre1.6.0_03\​bin\​ssv.dll 
HKU\​S-1-5-21-1229272821-1004336348-527237240-1003\​Software\​Classes\​CLSID\​{CAFEEFAC-0013-0001-0011-ABCDEFFEDCBA}\​InprocServer32  ThreadingModel  Apartment 
HKU\​S-1-5-21-1229272821-1004336348-527237240-1003\​Software\​Classes\​CLSID\​{CAFEEFAC-0013-0001-0011-ABCDEFFEDCBB}    Java Plug-in 1.3.1_11 
HKU\​S-1-5-21-1229272821-1004336348-527237240-1003\​Software\​Classes\​CLSID\​{CAFEEFAC-0013-0001-0011-ABCDEFFEDCBB}\​InprocServer32    C:\​Program Files\​Java\​jre1.6.0_03\​bin\​ssv.dll 
HKU\​S-1-5-21-1229272821-1004336348-527237240-1003\​Software\​Classes\​CLSID\​{CAFEEFAC-0013-0001-0011-ABCDEFFEDCBB}\​InprocServer32  ThreadingModel  Apartment 
HKU\​S-1-5-21-1229272821-1004336348-527237240-1003\​Software\​Classes\​CLSID\​{CAFEEFAC-0013-0001-0012-ABCDEFFEDCBA}    Java Plug-in 1.3.1_12 
HKU\​S-1-5-21-1229272821-1004336348-527237240-1003\​Software\​Classes\​CLSID\​{CAFEEFAC-0013-0001-0012-ABCDEFFEDCBA}\​InprocServer32    C:\​Program Files\​Java\​jre1.6.0_03\​bin\​ssv.dll 
HKU\​S-1-5-21-1229272821-1004336348-527237240-1003\​Software\​Classes\​CLSID\​{CAFEEFAC-0013-0001-0012-ABCDEFFEDCBA}\​InprocServer32  ThreadingModel  Apartment 
HKU\​S-1-5-21-1229272821-1004336348-527237240-1003\​Software\​Classes\​CLSID\​{CAFEEFAC-0013-0001-0012-ABCDEFFEDCBB}    Java Plug-in 1.3.1_12 
HKU\​S-1-5-21-1229272821-1004336348-527237240-1003\​Software\​Classes\​CLSID\​{CAFEEFAC-0013-0001-0012-ABCDEFFEDCBB}\​InprocServer32    C:\​Program Files\​Java\​jre1.6.0_03\​bin\​ssv.dll 
HKU\​S-1-5-21-1229272821-1004336348-527237240-1003\​Software\​Classes\​CLSID\​{CAFEEFAC-0013-0001-0012-ABCDEFFEDCBB}\​InprocServer32  ThreadingModel  Apartment 
HKU\​S-1-5-21-1229272821-1004336348-527237240-1003\​Software\​Classes\​CLSID\​{CAFEEFAC-0013-0001-0013-ABCDEFFEDCBA}    Java Plug-in 1.3.1_13 
HKU\​S-1-5-21-1229272821-1004336348-527237240-1003\​Software\​Classes\​CLSID\​{CAFEEFAC-0013-0001-0013-ABCDEFFEDCBA}\​InprocServer32    C:\​Program Files\​Java\​jre1.6.0_03\​bin\​ssv.dll 
HKU\​S-1-5-21-1229272821-1004336348-527237240-1003\​Software\​Classes\​CLSID\​{CAFEEFAC-0013-0001-0013-ABCDEFFEDCBA}\​InprocServer32  ThreadingModel  Apartment 
HKU\​S-1-5-21-1229272821-1004336348-527237240-1003\​Software\​Classes\​CLSID\​{CAFEEFAC-0013-0001-0013-ABCDEFFEDCBB}    Java Plug-in 1.3.1_13 
HKU\​S-1-5-21-1229272821-1004336348-527237240-1003\​Software\​Classes\​CLSID\​{CAFEEFAC-0013-0001-0013-ABCDEFFEDCBB}\​InprocServer32    C:\​Program Files\​Java\​jre1.6.0_03\​bin\​ssv.dll 
HKU\​S-1-5-21-1229272821-1004336348-527237240-1003\​Software\​Classes\​CLSID\​{CAFEEFAC-0013-0001-0013-ABCDEFFEDCBB}\​InprocServer32  ThreadingModel  Apartment 
HKU\​S-1-5-21-1229272821-1004336348-527237240-1003\​Software\​Classes\​CLSID\​{CAFEEFAC-0013-0001-0014-ABCDEFFEDCBA}    Java Plug-in 1.3.1_14 
HKU\​S-1-5-21-1229272821-1004336348-527237240-1003\​Software\​Classes\​CLSID\​{CAFEEFAC-0013-0001-0014-ABCDEFFEDCBA}\​InprocServer32    C:\​Program Files\​Java\​jre1.6.0_03\​bin\​ssv.dll 
HKU\​S-1-5-21-1229272821-1004336348-527237240-1003\​Software\​Classes\​CLSID\​{CAFEEFAC-0013-0001-0014-ABCDEFFEDCBA}\​InprocServer32  ThreadingModel  Apartment 
HKU\​S-1-5-21-1229272821-1004336348-527237240-1003\​Software\​Classes\​CLSID\​{CAFEEFAC-0013-0001-0014-ABCDEFFEDCBB}    Java Plug-in 1.3.1_14 
HKU\​S-1-5-21-1229272821-1004336348-527237240-1003\​Software\​Classes\​CLSID\​{CAFEEFAC-0013-0001-0014-ABCDEFFEDCBB}\​InprocServer32    C:\​Program Files\​Java\​jre1.6.0_03\​bin\​ssv.dll 
HKU\​S-1-5-21-1229272821-1004336348-527237240-1003\​Software\​Classes\​CLSID\​{CAFEEFAC-0013-0001-0014-ABCDEFFEDCBB}\​InprocServer32  ThreadingModel  Apartment 
HKU\​S-1-5-21-1229272821-1004336348-527237240-1003\​Software\​Classes\​CLSID\​{CAFEEFAC-0013-0001-0015-ABCDEFFEDCBA}    Java Plug-in 1.3.1_15 
HKU\​S-1-5-21-1229272821-1004336348-527237240-1003\​Software\​Classes\​CLSID\​{CAFEEFAC-0013-0001-0015-ABCDEFFEDCBA}\​InprocServer32    C:\​Program Files\​Java\​jre1.6.0_03\​bin\​ssv.dll 
HKU\​S-1-5-21-1229272821-1004336348-527237240-1003\​Software\​Classes\​CLSID\​{CAFEEFAC-0013-0001-0015-ABCDEFFEDCBA}\​InprocServer32  ThreadingModel  Apartment 
HKU\​S-1-5-21-1229272821-1004336348-527237240-1003\​Software\​Classes\​CLSID\​{CAFEEFAC-0013-0001-0015-ABCDEFFEDCBB}    Java Plug-in 1.3.1_15 
HKU\​S-1-5-21-1229272821-1004336348-527237240-1003\​Software\​Classes\​CLSID\​{CAFEEFAC-0013-0001-0015-ABCDEFFEDCBB}\​InprocServer32    C:\​Program Files\​Java\​jre1.6.0_03\​bin\​ssv.dll 
HKU\​S-1-5-21-1229272821-1004336348-527237240-1003\​Software\​Classes\​CLSID\​{CAFEEFAC-0013-0001-0015-ABCDEFFEDCBB}\​InprocServer32  ThreadingModel  Apartment 
HKU\​S-1-5-21-1229272821-1004336348-527237240-1003\​Software\​Classes\​CLSID\​{CAFEEFAC-0013-0001-0016-ABCDEFFEDCBA}    Java Plug-in 1.3.1_16 
HKU\​S-1-5-21-1229272821-1004336348-527237240-1003\​Software\​Classes\​CLSID\​{CAFEEFAC-0013-0001-0016-ABCDEFFEDCBA}\​InprocServer32    C:\​Program Files\​Java\​jre1.6.0_03\​bin\​ssv.dll 
HKU\​S-1-5-21-1229272821-1004336348-527237240-1003\​Software\​Classes\​CLSID\​{CAFEEFAC-0013-0001-0016-ABCDEFFEDCBA}\​InprocServer32  ThreadingModel  Apartment 
HKU\​S-1-5-21-1229272821-1004336348-527237240-1003\​Software\​Classes\​CLSID\​{CAFEEFAC-0013-0001-0016-ABCDEFFEDCBB}    Java Plug-in 1.3.1_16 
HKU\​S-1-5-21-1229272821-1004336348-527237240-1003\​Software\​Classes\​CLSID\​{CAFEEFAC-0013-0001-0016-ABCDEFFEDCBB}\​InprocServer32    C:\​Program Files\​Java\​jre1.6.0_03\​bin\​ssv.dll 
HKU\​S-1-5-21-1229272821-1004336348-527237240-1003\​Software\​Classes\​CLSID\​{CAFEEFAC-0013-0001-0016-ABCDEFFEDCBB}\​InprocServer32  ThreadingModel  Apartment 
HKU\​S-1-5-21-1229272821-1004336348-527237240-1003\​Software\​Classes\​CLSID\​{CAFEEFAC-0013-0001-0017-ABCDEFFEDCBA}    Java Plug-in 1.3.1_17 
HKU\​S-1-5-21-1229272821-1004336348-527237240-1003\​Software\​Classes\​CLSID\​{CAFEEFAC-0013-0001-0017-ABCDEFFEDCBA}\​InprocServer32    C:\​Program Files\​Java\​jre1.6.0_03\​bin\​ssv.dll 
HKU\​S-1-5-21-1229272821-1004336348-527237240-1003\​Software\​Classes\​CLSID\​{CAFEEFAC-0013-0001-0017-ABCDEFFEDCBA}\​InprocServer32  ThreadingModel  Apartment 
HKU\​S-1-5-21-1229272821-1004336348-527237240-1003\​Software\​Classes\​CLSID\​{CAFEEFAC-0013-0001-0017-ABCDEFFEDCBB}    Java Plug-in 1.3.1_17 
HKU\​S-1-5-21-1229272821-1004336348-527237240-1003\​Software\​Classes\​CLSID\​{CAFEEFAC-0013-0001-0017-ABCDEFFEDCBB}\​InprocServer32    C:\​Program Files\​Java\​jre1.6.0_03\​bin\​ssv.dll 
HKU\​S-1-5-21-1229272821-1004336348-527237240-1003\​Software\​Classes\​CLSID\​{CAFEEFAC-0013-0001-0017-ABCDEFFEDCBB}\​InprocServer32  ThreadingModel  Apartment 
HKU\​S-1-5-21-1229272821-1004336348-527237240-1003\​Software\​Classes\​CLSID\​{CAFEEFAC-0013-0001-0018-ABCDEFFEDCBA}    Java Plug-in 1.3.1_18 
HKU\​S-1-5-21-1229272821-1004336348-527237240-1003\​Software\​Classes\​CLSID\​{CAFEEFAC-0013-0001-0018-ABCDEFFEDCBA}\​InprocServer32    C:\​Program Files\​Java\​jre1.6.0_03\​bin\​ssv.dll 
HKU\​S-1-5-21-1229272821-1004336348-527237240-1003\​Software\​Classes\​CLSID\​{CAFEEFAC-0013-0001-0018-ABCDEFFEDCBA}\​InprocServer32  ThreadingModel  Apartment 
HKU\​S-1-5-21-1229272821-1004336348-527237240-1003\​Software\​Classes\​CLSID\​{CAFEEFAC-0013-0001-0018-ABCDEFFEDCBB}    Java Plug-in 1.3.1_18 
HKU\​S-1-5-21-1229272821-1004336348-527237240-1003\​Software\​Classes\​CLSID\​{CAFEEFAC-0013-0001-0018-ABCDEFFEDCBB}\​InprocServer32    C:\​Program Files\​Java\​jre1.6.0_03\​bin\​ssv.dll 
HKU\​S-1-5-21-1229272821-1004336348-527237240-1003\​Software\​Classes\​CLSID\​{CAFEEFAC-0013-0001-0018-ABCDEFFEDCBB}\​InprocServer32  ThreadingModel  Apartment 
HKU\​S-1-5-21-1229272821-1004336348-527237240-1003\​Software\​Classes\​CLSID\​{CAFEEFAC-0013-0001-0019-ABCDEFFEDCBA}    Java Plug-in 1.3.1_19 
HKU\​S-1-5-21-1229272821-1004336348-527237240-1003\​Software\​Classes\​CLSID\​{CAFEEFAC-0013-0001-0019-ABCDEFFEDCBA}\​InprocServer32    C:\​Program Files\​Java\​jre1.6.0_03\​bin\​ssv.dll 
HKU\​S-1-5-21-1229272821-1004336348-527237240-1003\​Software\​Classes\​CLSID\​{CAFEEFAC-0013-0001-0019-ABCDEFFEDCBA}\​InprocServer32  ThreadingModel  Apartment 
HKU\​S-1-5-21-1229272821-1004336348-527237240-1003\​Software\​Classes\​CLSID\​{CAFEEFAC-0013-0001-0019-ABCDEFFEDCBB}    Java Plug-in 1.3.1_19 
HKU\​S-1-5-21-1229272821-1004336348-527237240-1003\​Software\​Classes\​CLSID\​{CAFEEFAC-0013-0001-0019-ABCDEFFEDCBB}\​InprocServer32    C:\​Program Files\​Java\​jre1.6.0_03\​bin\​ssv.dll 
HKU\​S-1-5-21-1229272821-1004336348-527237240-1003\​Software\​Classes\​CLSID\​{CAFEEFAC-0013-0001-0019-ABCDEFFEDCBB}\​InprocServer32  ThreadingModel  Apartment 
HKU\​S-1-5-21-1229272821-1004336348-527237240-1003\​Software\​Classes\​CLSID\​{CAFEEFAC-0013-0001-0020-ABCDEFFEDCBA}    Java Plug-in 1.3.1_20 
HKU\​S-1-5-21-1229272821-1004336348-527237240-1003\​Software\​Classes\​CLSID\​{CAFEEFAC-0013-0001-0020-ABCDEFFEDCBA}\​InprocServer32    C:\​Program Files\​Java\​jre1.6.0_03\​bin\​ssv.dll 
HKU\​S-1-5-21-1229272821-1004336348-527237240-1003\​Software\​Classes\​CLSID\​{CAFEEFAC-0013-0001-0020-ABCDEFFEDCBA}\​InprocServer32  ThreadingModel  Apartment 
HKU\​S-1-5-21-1229272821-1004336348-527237240-1003\​Software\​Classes\​CLSID\​{CAFEEFAC-0013-0001-0020-ABCDEFFEDCBB}    Java Plug-in 1.3.1_20 
HKU\​S-1-5-21-1229272821-1004336348-527237240-1003\​Software\​Classes\​CLSID\​{CAFEEFAC-0013-0001-0020-ABCDEFFEDCBB}\​InprocServer32    C:\​Program Files\​Java\​jre1.6.0_03\​bin\​ssv.dll 
HKU\​S-1-5-21-1229272821-1004336348-527237240-1003\​Software\​Classes\​CLSID\​{CAFEEFAC-0013-0001-0020-ABCDEFFEDCBB}\​InprocServer32  ThreadingModel  Apartment 
HKU\​S-1-5-21-1229272821-1004336348-527237240-1003\​Software\​Classes\​CLSID\​{CAFEEFAC-0013-0001-0021-ABCDEFFEDCBA}    Java Plug-in 1.3.1_21 
HKU\​S-1-5-21-1229272821-1004336348-527237240-1003\​Software\​Classes\​CLSID\​{CAFEEFAC-0013-0001-0021-ABCDEFFEDCBA}\​InprocServer32    C:\​Program Files\​Java\​jre1.6.0_03\​bin\​ssv.dll 
HKU\​S-1-5-21-1229272821-1004336348-527237240-1003\​Software\​Classes\​CLSID\​{CAFEEFAC-0013-0001-0021-ABCDEFFEDCBA}\​InprocServer32  ThreadingModel  Apartment 
HKU\​S-1-5-21-1229272821-1004336348-527237240-1003\​Software\​Classes\​CLSID\​{CAFEEFAC-0013-0001-0021-ABCDEFFEDCBB}    Java Plug-in 1.3.1_21 
HKU\​S-1-5-21-1229272821-1004336348-527237240-1003\​Software\​Classes\​CLSID\​{CAFEEFAC-0013-0001-0021-ABCDEFFEDCBB}\​InprocServer32    C:\​Program Files\​Java\​jre1.6.0_03\​bin\​ssv.dll 
HKU\​S-1-5-21-1229272821-1004336348-527237240-1003\​Software\​Classes\​CLSID\​{CAFEEFAC-0013-0001-0021-ABCDEFFEDCBB}\​InprocServer32  ThreadingModel  Apartment 
HKU\​S-1-5-21-1229272821-1004336348-527237240-1003\​Software\​Classes\​CLSID\​{CAFEEFAC-0013-0001-0022-ABCDEFFEDCBA}    Java Plug-in 1.3.1_22 
HKU\​S-1-5-21-1229272821-1004336348-527237240-1003\​Software\​Classes\​CLSID\​{CAFEEFAC-0013-0001-0022-ABCDEFFEDCBA}\​InprocServer32    C:\​Program Files\​Java\​jre1.6.0_03\​bin\​ssv.dll 
HKU\​S-1-5-21-1229272821-1004336348-527237240-1003\​Software\​Classes\​CLSID\​{CAFEEFAC-0013-0001-0022-ABCDEFFEDCBA}\​InprocServer32  ThreadingModel  Apartment 
HKU\​S-1-5-21-1229272821-1004336348-527237240-1003\​Software\​Classes\​CLSID\​{CAFEEFAC-0013-0001-0022-ABCDEFFEDCBB}    Java Plug-in 1.3.1_22 
HKU\​S-1-5-21-1229272821-1004336348-527237240-1003\​Software\​Classes\​CLSID\​{CAFEEFAC-0013-0001-0022-ABCDEFFEDCBB}\​InprocServer32    C:\​Program Files\​Java\​jre1.6.0_03\​bin\​ssv.dll 
HKU\​S-1-5-21-1229272821-1004336348-527237240-1003\​Software\​Classes\​CLSID\​{CAFEEFAC-0013-0001-0022-ABCDEFFEDCBB}\​InprocServer32  ThreadingModel  Apartment 
HKU\​S-1-5-21-1229272821-1004336348-527237240-1003\​Software\​Classes\​CLSID\​{CAFEEFAC-0013-0001-0023-ABCDEFFEDCBA}    Java Plug-in 1.3.1_23 
HKU\​S-1-5-21-1229272821-1004336348-527237240-1003\​Software\​Classes\​CLSID\​{CAFEEFAC-0013-0001-0023-ABCDEFFEDCBA}\​InprocServer32    C:\​Program Files\​Java\​jre1.6.0_03\​bin\​ssv.dll 
HKU\​S-1-5-21-1229272821-1004336348-527237240-1003\​Software\​Classes\​CLSID\​{CAFEEFAC-0013-0001-0023-ABCDEFFEDCBA}\​InprocServer32  ThreadingModel  Apartment 
HKU\​S-1-5-21-1229272821-1004336348-527237240-1003\​Software\​Classes\​CLSID\​{CAFEEFAC-0013-0001-0023-ABCDEFFEDCBB}    Java Plug-in 1.3.1_23 
HKU\​S-1-5-21-1229272821-1004336348-527237240-1003\​Software\​Classes\​CLSID\​{CAFEEFAC-0013-0001-0023-ABCDEFFEDCBB}\​InprocServer32    C:\​Program Files\​Java\​jre1.6.0_03\​bin\​ssv.dll 
HKU\​S-1-5-21-1229272821-1004336348-527237240-1003\​Software\​Classes\​CLSID\​{CAFEEFAC-0013-0001-0023-ABCDEFFEDCBB}\​InprocServer32  ThreadingModel  Apartment 
HKU\​S-1-5-21-1229272821-1004336348-527237240-1003\​Software\​Classes\​CLSID\​{CAFEEFAC-0013-0001-0024-ABCDEFFEDCBA}    Java Plug-in 1.3.1_24 
HKU\​S-1-5-21-1229272821-1004336348-527237240-1003\​Software\​Classes\​CLSID\​{CAFEEFAC-0013-0001-0024-ABCDEFFEDCBA}\​InprocServer32    C:\​Program Files\​Java\​jre1.6.0_03\​bin\​ssv.dll 
HKU\​S-1-5-21-1229272821-1004336348-527237240-1003\​Software\​Classes\​CLSID\​{CAFEEFAC-0013-0001-0024-ABCDEFFEDCBA}\​InprocServer32  ThreadingModel  Apartment 
HKU\​S-1-5-21-1229272821-1004336348-527237240-1003\​Software\​Classes\​CLSID\​{CAFEEFAC-0013-0001-0024-ABCDEFFEDCBB}    Java Plug-in 1.3.1_24 
HKU\​S-1-5-21-1229272821-1004336348-527237240-1003\​Software\​Classes\​CLSID\​{CAFEEFAC-0013-0001-0024-ABCDEFFEDCBB}\​InprocServer32    C:\​Program Files\​Java\​jre1.6.0_03\​bin\​ssv.dll 
HKU\​S-1-5-21-1229272821-1004336348-527237240-1003\​Software\​Classes\​CLSID\​{CAFEEFAC-0013-0001-0024-ABCDEFFEDCBB}\​InprocServer32  ThreadingModel  Apartment 
HKU\​S-1-5-21-1229272821-1004336348-527237240-1003\​Software\​Classes\​CLSID\​{CAFEEFAC-0013-0001-0025-ABCDEFFEDCBA}    Java Plug-in 1.3.1_25 
HKU\​S-1-5-21-1229272821-1004336348-527237240-1003\​Software\​Classes\​CLSID\​{CAFEEFAC-0013-0001-0025-ABCDEFFEDCBA}\​InprocServer32    C:\​Program Files\​Java\​jre1.6.0_03\​bin\​ssv.dll 
HKU\​S-1-5-21-1229272821-1004336348-527237240-1003\​Software\​Classes\​CLSID\​{CAFEEFAC-0013-0001-0025-ABCDEFFEDCBA}\​InprocServer32  ThreadingModel  Apartment 
HKU\​S-1-5-21-1229272821-1004336348-527237240-1003\​Software\​Classes\​CLSID\​{CAFEEFAC-0013-0001-0025-ABCDEFFEDCBB}    Java Plug-in 1.3.1_25 
HKU\​S-1-5-21-1229272821-1004336348-527237240-1003\​Software\​Classes\​CLSID\​{CAFEEFAC-0013-0001-0025-ABCDEFFEDCBB}\​InprocServer32    C:\​Program Files\​Java\​jre1.6.0_03\​bin\​ssv.dll 
HKU\​S-1-5-21-1229272821-1004336348-527237240-1003\​Software\​Classes\​CLSID\​{CAFEEFAC-0013-0001-0025-ABCDEFFEDCBB}\​InprocServer32  ThreadingModel  Apartment 
HKU\​S-1-5-21-1229272821-1004336348-527237240-1003\​Software\​Classes\​CLSID\​{CAFEEFAC-0013-0001-0026-ABCDEFFEDCBA}    Java Plug-in 1.3.1_26 
HKU\​S-1-5-21-1229272821-1004336348-527237240-1003\​Software\​Classes\​CLSID\​{CAFEEFAC-0013-0001-0026-ABCDEFFEDCBA}\​InprocServer32    C:\​Program Files\​Java\​jre1.6.0_03\​bin\​ssv.dll 
HKU\​S-1-5-21-1229272821-1004336348-527237240-1003\​Software\​Classes\​CLSID\​{CAFEEFAC-0013-0001-0026-ABCDEFFEDCBA}\​InprocServer32  ThreadingModel  Apartment 
HKU\​S-1-5-21-1229272821-1004336348-527237240-1003\​Software\​Classes\​CLSID\​{CAFEEFAC-0013-0001-0026-ABCDEFFEDCBB}    Java Plug-in 1.3.1_26 
HKU\​S-1-5-21-1229272821-1004336348-527237240-1003\​Software\​Classes\​CLSID\​{CAFEEFAC-0013-0001-0026-ABCDEFFEDCBB}\​InprocServer32    C:\​Program Files\​Java\​jre1.6.0_03\​bin\​ssv.dll 
HKU\​S-1-5-21-1229272821-1004336348-527237240-1003\​Software\​Classes\​CLSID\​{CAFEEFAC-0013-0001-0026-ABCDEFFEDCBB}\​InprocServer32  ThreadingModel  Apartment 
HKU\​S-1-5-21-1229272821-1004336348-527237240-1003\​Software\​Classes\​CLSID\​{CAFEEFAC-0013-0001-0027-ABCDEFFEDCBA}    Java Plug-in 1.3.1_27 
HKU\​S-1-5-21-1229272821-1004336348-527237240-1003\​Software\​Classes\​CLSID\​{CAFEEFAC-0013-0001-0027-ABCDEFFEDCBA}\​InprocServer32    C:\​Program Files\​Java\​jre1.6.0_03\​bin\​ssv.dll 
HKU\​S-1-5-21-1229272821-1004336348-527237240-1003\​Software\​Classes\​CLSID\​{CAFEEFAC-0013-0001-0027-ABCDEFFEDCBA}\​InprocServer32  ThreadingModel  Apartment 
HKU\​S-1-5-21-1229272821-1004336348-527237240-1003\​Software\​Classes\​CLSID\​{CAFEEFAC-0013-0001-0027-ABCDEFFEDCBB}    Java Plug-in 1.3.1_27 
HKU\​S-1-5-21-1229272821-1004336348-527237240-1003\​Software\​Classes\​CLSID\​{CAFEEFAC-0013-0001-0027-ABCDEFFEDCBB}\​InprocServer32    C:\​Program Files\​Java\​jre1.6.0_03\​bin\​ssv.dll 
HKU\​S-1-5-21-1229272821-1004336348-527237240-1003\​Software\​Classes\​CLSID\​{CAFEEFAC-0013-0001-0027-ABCDEFFEDCBB}\​InprocServer32  ThreadingModel  Apartment 
HKU\​S-1-5-21-1229272821-1004336348-527237240-1003\​Software\​Classes\​CLSID\​{CAFEEFAC-0013-0001-0028-ABCDEFFEDCBA}    Java Plug-in 1.3.1_28 
HKU\​S-1-5-21-1229272821-1004336348-527237240-1003\​Software\​Classes\​CLSID\​{CAFEEFAC-0013-0001-0028-ABCDEFFEDCBA}\​InprocServer32    C:\​Program Files\​Java\​jre1.6.0_03\​bin\​ssv.dll 
HKU\​S-1-5-21-1229272821-1004336348-527237240-1003\​Software\​Classes\​CLSID\​{CAFEEFAC-0013-0001-0028-ABCDEFFEDCBA}\​InprocServer32  ThreadingModel  Apartment 
HKU\​S-1-5-21-1229272821-1004336348-527237240-1003\​Software\​Classes\​CLSID\​{CAFEEFAC-0013-0001-0028-ABCDEFFEDCBB}    Java Plug-in 1.3.1_28 
HKU\​S-1-5-21-1229272821-1004336348-527237240-1003\​Software\​Classes\​CLSID\​{CAFEEFAC-0013-0001-0028-ABCDEFFEDCBB}\​InprocServer32    C:\​Program Files\​Java\​jre1.6.0_03\​bin\​ssv.dll 
HKU\​S-1-5-21-1229272821-1004336348-527237240-1003\​Software\​Classes\​CLSID\​{CAFEEFAC-0013-0001-0028-ABCDEFFEDCBB}\​InprocServer32  ThreadingModel  Apartment 
HKU\​S-1-5-21-1229272821-1004336348-527237240-1003\​Software\​Classes\​CLSID\​{CAFEEFAC-0013-0001-0029-ABCDEFFEDCBA}    Java Plug-in 1.3.1_29 
HKU\​S-1-5-21-1229272821-1004336348-527237240-1003\​Software\​Classes\​CLSID\​{CAFEEFAC-0013-0001-0029-ABCDEFFEDCBA}\​InprocServer32    C:\​Program Files\​Java\​jre1.6.0_03\​bin\​ssv.dll 
HKU\​S-1-5-21-1229272821-1004336348-527237240-1003\​Software\​Classes\​CLSID\​{CAFEEFAC-0013-0001-0029-ABCDEFFEDCBA}\​InprocServer32  ThreadingModel  Apartment 
HKU\​S-1-5-21-1229272821-1004336348-527237240-1003\​Software\​Classes\​CLSID\​{CAFEEFAC-0013-0001-0029-ABCDEFFEDCBB}    Java Plug-in 1.3.1_29 
HKU\​S-1-5-21-1229272821-1004336348-527237240-1003\​Software\​Classes\​CLSID\​{CAFEEFAC-0013-0001-0029-ABCDEFFEDCBB}\​InprocServer32    C:\​Program Files\​Java\​jre1.6.0_03\​bin\​ssv.dll 
HKU\​S-1-5-21-1229272821-1004336348-527237240-1003\​Software\​Classes\​CLSID\​{CAFEEFAC-0013-0001-0029-ABCDEFFEDCBB}\​InprocServer32  ThreadingModel  Apartment 
HKU\​S-1-5-21-1229272821-1004336348-527237240-1003\​Software\​Classes\​CLSID\​{CAFEEFAC-0013-0001-0030-ABCDEFFEDCBA}    Java Plug-in 1.3.1_30 
HKU\​S-1-5-21-1229272821-1004336348-527237240-1003\​Software\​Classes\​CLSID\​{CAFEEFAC-0013-0001-0030-ABCDEFFEDCBA}\​InprocServer32    C:\​Program Files\​Java\​jre1.6.0_03\​bin\​ssv.dll 
HKU\​S-1-5-21-1229272821-1004336348-527237240-1003\​Software\​Classes\​CLSID\​{CAFEEFAC-0013-0001-0030-ABCDEFFEDCBA}\​InprocServer32  ThreadingModel  Apartment 
HKU\​S-1-5-21-1229272821-1004336348-527237240-1003\​Software\​Classes\​CLSID\​{CAFEEFAC-0013-0001-0030-ABCDEFFEDCBB}    Java Plug-in 1.3.1_30 
HKU\​S-1-5-21-1229272821-1004336348-527237240-1003\​Software\​Classes\​CLSID\​{CAFEEFAC-0013-0001-0030-ABCDEFFEDCBB}\​InprocServer32    C:\​Program Files\​Java\​jre1.6.0_03\​bin\​ssv.dll 
HKU\​S-1-5-21-1229272821-1004336348-527237240-1003\​Software\​Classes\​CLSID\​{CAFEEFAC-0013-0001-0030-ABCDEFFEDCBB}\​InprocServer32  ThreadingModel  Apartment 
HKU\​S-1-5-21-1229272821-1004336348-527237240-1003\​Software\​Classes\​CLSID\​{CAFEEFAC-0014-0000-0000-ABCDEFFEDCBA}    Java Plug-in 1.4.0 
HKU\​S-1-5-21-1229272821-1004336348-527237240-1003\​Software\​Classes\​CLSID\​{CAFEEFAC-0014-0000-0000-ABCDEFFEDCBA}\​InprocServer32    C:\​Program Files\​Java\​jre1.6.0_03\​bin\​ssv.dll 
HKU\​S-1-5-21-1229272821-1004336348-527237240-1003\​Software\​Classes\​CLSID\​{CAFEEFAC-0014-0000-0000-ABCDEFFEDCBA}\​InprocServer32  ThreadingModel  Apartment 
HKU\​S-1-5-21-1229272821-1004336348-527237240-1003\​Software\​Classes\​CLSID\​{CAFEEFAC-0014-0000-0000-ABCDEFFEDCBB}    Java Plug-in 1.4.0 
HKU\​S-1-5-21-1229272821-1004336348-527237240-1003\​Software\​Classes\​CLSID\​{CAFEEFAC-0014-0000-0000-ABCDEFFEDCBB}\​InprocServer32    C:\​Program Files\​Java\​jre1.6.0_03\​bin\​ssv.dll 
HKU\​S-1-5-21-1229272821-1004336348-527237240-1003\​Software\​Classes\​CLSID\​{CAFEEFAC-0014-0000-0000-ABCDEFFEDCBB}\​InprocServer32  ThreadingModel  Apartment 
HKU\​S-1-5-21-1229272821-1004336348-527237240-1003\​Software\​Classes\​CLSID\​{CAFEEFAC-0014-0000-0001-ABCDEFFEDCBA}    Java Plug-in 1.4.0_01 
HKU\​S-1-5-21-1229272821-1004336348-527237240-1003\​Software\​Classes\​CLSID\​{CAFEEFAC-0014-0000-0001-ABCDEFFEDCBA}\​InprocServer32    C:\​Program Files\​Java\​jre1.6.0_03\​bin\​ssv.dll 
HKU\​S-1-5-21-1229272821-1004336348-527237240-1003\​Software\​Classes\​CLSID\​{CAFEEFAC-0014-0000-0001-ABCDEFFEDCBA}\​InprocServer32  ThreadingModel  Apartment 
HKU\​S-1-5-21-1229272821-1004336348-527237240-1003\​Software\​Classes\​CLSID\​{CAFEEFAC-0014-0000-0001-ABCDEFFEDCBB}    Java Plug-in 1.4.0_01 
HKU\​S-1-5-21-1229272821-1004336348-527237240-1003\​Software\​Classes\​CLSID\​{CAFEEFAC-0014-0000-0001-ABCDEFFEDCBB}\​InprocServer32    C:\​Program Files\​Java\​jre1.6.0_03\​bin\​ssv.dll 
HKU\​S-1-5-21-1229272821-1004336348-527237240-1003\​Software\​Classes\​CLSID\​{CAFEEFAC-0014-0000-0001-ABCDEFFEDCBB}\​InprocServer32  ThreadingModel  Apartment 
HKU\​S-1-5-21-1229272821-1004336348-527237240-1003\​Software\​Classes\​CLSID\​{CAFEEFAC-0014-0000-0002-ABCDEFFEDCBA}    Java Plug-in 1.4.0_02 
HKU\​S-1-5-21-1229272821-1004336348-527237240-1003\​Software\​Classes\​CLSID\​{CAFEEFAC-0014-0000-0002-ABCDEFFEDCBA}\​InprocServer32    C:\​Program Files\​Java\​jre1.6.0_03\​bin\​ssv.dll 
HKU\​S-1-5-21-1229272821-1004336348-527237240-1003\​Software\​Classes\​CLSID\​{CAFEEFAC-0014-0000-0002-ABCDEFFEDCBA}\​InprocServer32  ThreadingModel  Apartment 
HKU\​S-1-5-21-1229272821-1004336348-527237240-1003\​Software\​Classes\​CLSID\​{CAFEEFAC-0014-0000-0002-ABCDEFFEDCBB}    Java Plug-in 1.4.0_02 
HKU\​S-1-5-21-1229272821-1004336348-527237240-1003\​Software\​Classes\​CLSID\​{CAFEEFAC-0014-0000-0002-ABCDEFFEDCBB}\​InprocServer32    C:\​Program Files\​Java\​jre1.6.0_03\​bin\​ssv.dll 
HKU\​S-1-5-21-1229272821-1004336348-527237240-1003\​Software\​Classes\​CLSID\​{CAFEEFAC-0014-0000-0002-ABCDEFFEDCBB}\​InprocServer32  ThreadingModel  Apartment 
HKU\​S-1-5-21-1229272821-1004336348-527237240-1003\​Software\​Classes\​CLSID\​{CAFEEFAC-0014-0000-0003-ABCDEFFEDCBA}    Java Plug-in 1.4.0_03 
HKU\​S-1-5-21-1229272821-1004336348-527237240-1003\​Software\​Classes\​CLSID\​{CAFEEFAC-0014-0000-0003-ABCDEFFEDCBA}\​InprocServer32    C:\​Program Files\​Java\​jre1.6.0_03\​bin\​ssv.dll 
HKU\​S-1-5-21-1229272821-1004336348-527237240-1003\​Software\​Classes\​CLSID\​{CAFEEFAC-0014-0000-0003-ABCDEFFEDCBA}\​InprocServer32  ThreadingModel  Apartment 
HKU\​S-1-5-21-1229272821-1004336348-527237240-1003\​Software\​Classes\​CLSID\​{CAFEEFAC-0014-0000-0003-ABCDEFFEDCBB}    Java Plug-in 1.4.0_03 
HKU\​S-1-5-21-1229272821-1004336348-527237240-1003\​Software\​Classes\​CLSID\​{CAFEEFAC-0014-0000-0003-ABCDEFFEDCBB}\​InprocServer32    C:\​Program Files\​Java\​jre1.6.0_03\​bin\​ssv.dll 
HKU\​S-1-5-21-1229272821-1004336348-527237240-1003\​Software\​Classes\​CLSID\​{CAFEEFAC-0014-0000-0003-ABCDEFFEDCBB}\​InprocServer32  ThreadingModel  Apartment 
HKU\​S-1-5-21-1229272821-1004336348-527237240-1003\​Software\​Classes\​CLSID\​{CAFEEFAC-0014-0000-0004-ABCDEFFEDCBA}    Java Plug-in 1.4.0_04 
HKU\​S-1-5-21-1229272821-1004336348-527237240-1003\​Software\​Classes\​CLSID\​{CAFEEFAC-0014-0000-0004-ABCDEFFEDCBA}\​InprocServer32    C:\​Program Files\​Java\​jre1.6.0_03\​bin\​ssv.dll 
HKU\​S-1-5-21-1229272821-1004336348-527237240-1003\​Software\​Classes\​CLSID\​{CAFEEFAC-0014-0000-0004-ABCDEFFEDCBA}\​InprocServer32  ThreadingModel  Apartment 
HKU\​S-1-5-21-1229272821-1004336348-527237240-1003\​Software\​Classes\​CLSID\​{CAFEEFAC-0014-0000-0004-ABCDEFFEDCBB}    Java Plug-in 1.4.0_04 
HKU\​S-1-5-21-1229272821-1004336348-527237240-1003\​Software\​Classes\​CLSID\​{CAFEEFAC-0014-0000-0004-ABCDEFFEDCBB}\​InprocServer32    C:\​Program Files\​Java\​jre1.6.0_03\​bin\​ssv.dll 
HKU\​S-1-5-21-1229272821-1004336348-527237240-1003\​Software\​Classes\​CLSID\​{CAFEEFAC-0014-0000-0004-ABCDEFFEDCBB}\​InprocServer32  ThreadingModel  Apartment 
HKU\​S-1-5-21-1229272821-1004336348-527237240-1003\​Software\​Classes\​CLSID\​{CAFEEFAC-0014-0001-0000-ABCDEFFEDCBA}    Java Plug-in 1.4.1 
HKU\​S-1-5-21-1229272821-1004336348-527237240-1003\​Software\​Classes\​CLSID\​{CAFEEFAC-0014-0001-0000-ABCDEFFEDCBA}\​InprocServer32    C:\​Program Files\​Java\​jre1.6.0_03\​bin\​ssv.dll 
HKU\​S-1-5-21-1229272821-1004336348-527237240-1003\​Software\​Classes\​CLSID\​{CAFEEFAC-0014-0001-0000-ABCDEFFEDCBA}\​InprocServer32  ThreadingModel  Apartment 
HKU\​S-1-5-21-1229272821-1004336348-527237240-1003\​Software\​Classes\​CLSID\​{CAFEEFAC-0014-0001-0000-ABCDEFFEDCBB}    Java Plug-in 1.4.1 
HKU\​S-1-5-21-1229272821-1004336348-527237240-1003\​Software\​Classes\​CLSID\​{CAFEEFAC-0014-0001-0000-ABCDEFFEDCBB}\​InprocServer32    C:\​Program Files\​Java\​jre1.6.0_03\​bin\​ssv.dll 
HKU\​S-1-5-21-1229272821-1004336348-527237240-1003\​Software\​Classes\​CLSID\​{CAFEEFAC-0014-0001-0000-ABCDEFFEDCBB}\​InprocServer32  ThreadingModel  Apartment 
HKU\​S-1-5-21-1229272821-1004336348-527237240-1003\​Software\​Classes\​CLSID\​{CAFEEFAC-0014-0001-0001-ABCDEFFEDCBA}    Java Plug-in 1.4.1_01 
HKU\​S-1-5-21-1229272821-1004336348-527237240-1003\​Software\​Classes\​CLSID\​{CAFEEFAC-0014-0001-0001-ABCDEFFEDCBA}\​InprocServer32    C:\​Program Files\​Java\​jre1.6.0_03\​bin\​ssv.dll 
HKU\​S-1-5-21-1229272821-1004336348-527237240-1003\​Software\​Classes\​CLSID\​{CAFEEFAC-0014-0001-0001-ABCDEFFEDCBA}\​InprocServer32  ThreadingModel  Apartment 
HKU\​S-1-5-21-1229272821-1004336348-527237240-1003\​Software\​Classes\​CLSID\​{CAFEEFAC-0014-0001-0001-ABCDEFFEDCBB}    Java Plug-in 1.4.1_01 
HKU\​S-1-5-21-1229272821-1004336348-527237240-1003\​Software\​Classes\​CLSID\​{CAFEEFAC-0014-0001-0001-ABCDEFFEDCBB}\​InprocServer32    C:\​Program Files\​Java\​jre1.6.0_03\​bin\​ssv.dll 
HKU\​S-1-5-21-1229272821-1004336348-527237240-1003\​Software\​Classes\​CLSID\​{CAFEEFAC-0014-0001-0001-ABCDEFFEDCBB}\​InprocServer32  ThreadingModel  Apartment 
HKU\​S-1-5-21-1229272821-1004336348-527237240-1003\​Software\​Classes\​CLSID\​{CAFEEFAC-0014-0001-0002-ABCDEFFEDCBA}    Java Plug-in 1.4.1_02 
HKU\​S-1-5-21-1229272821-1004336348-527237240-1003\​Software\​Classes\​CLSID\​{CAFEEFAC-0014-0001-0002-ABCDEFFEDCBA}\​InprocServer32    C:\​Program Files\​Java\​jre1.6.0_03\​bin\​ssv.dll 
HKU\​S-1-5-21-1229272821-1004336348-527237240-1003\​Software\​Classes\​CLSID\​{CAFEEFAC-0014-0001-0002-ABCDEFFEDCBA}\​InprocServer32  ThreadingModel  Apartment 
HKU\​S-1-5-21-1229272821-1004336348-527237240-1003\​Software\​Classes\​CLSID\​{CAFEEFAC-0014-0001-0002-ABCDEFFEDCBB}    Java Plug-in 1.4.1_02 
HKU\​S-1-5-21-1229272821-1004336348-527237240-1003\​Software\​Classes\​CLSID\​{CAFEEFAC-0014-0001-0002-ABCDEFFEDCBB}\​InprocServer32    C:\​Program Files\​Java\​jre1.6.0_03\​bin\​ssv.dll 
HKU\​S-1-5-21-1229272821-1004336348-527237240-1003\​Software\​Classes\​CLSID\​{CAFEEFAC-0014-0001-0002-ABCDEFFEDCBB}\​InprocServer32  ThreadingModel  Apartment 
HKU\​S-1-5-21-1229272821-1004336348-527237240-1003\​Software\​Classes\​CLSID\​{CAFEEFAC-0014-0001-0003-ABCDEFFEDCBA}    Java Plug-in 1.4.1_03 
HKU\​S-1-5-21-1229272821-1004336348-527237240-1003\​Software\​Classes\​CLSID\​{CAFEEFAC-0014-0001-0003-ABCDEFFEDCBA}\​InprocServer32    C:\​Program Files\​Java\​jre1.6.0_03\​bin\​ssv.dll 
HKU\​S-1-5-21-1229272821-1004336348-527237240-1003\​Software\​Classes\​CLSID\​{CAFEEFAC-0014-0001-0003-ABCDEFFEDCBA}\​InprocServer32  ThreadingModel  Apartment 
HKU\​S-1-5-21-1229272821-1004336348-527237240-1003\​Software\​Classes\​CLSID\​{CAFEEFAC-0014-0001-0003-ABCDEFFEDCBB}    Java Plug-in 1.4.1_03 
HKU\​S-1-5-21-1229272821-1004336348-527237240-1003\​Software\​Classes\​CLSID\​{CAFEEFAC-0014-0001-0003-ABCDEFFEDCBB}\​InprocServer32    C:\​Program Files\​Java\​jre1.6.0_03\​bin\​ssv.dll 
HKU\​S-1-5-21-1229272821-1004336348-527237240-1003\​Software\​Classes\​CLSID\​{CAFEEFAC-0014-0001-0003-ABCDEFFEDCBB}\​InprocServer32  ThreadingModel  Apartment 
HKU\​S-1-5-21-1229272821-1004336348-527237240-1003\​Software\​Classes\​CLSID\​{CAFEEFAC-0014-0001-0004-ABCDEFFEDCBA}    Java Plug-in 1.4.1_04 
HKU\​S-1-5-21-1229272821-1004336348-527237240-1003\​Software\​Classes\​CLSID\​{CAFEEFAC-0014-0001-0004-ABCDEFFEDCBA}\​InprocServer32    C:\​Program Files\​Java\​jre1.6.0_03\​bin\​ssv.dll 
HKU\​S-1-5-21-1229272821-1004336348-527237240-1003\​Software\​Classes\​CLSID\​{CAFEEFAC-0014-0001-0004-ABCDEFFEDCBA}\​InprocServer32  ThreadingModel  Apartment 
HKU\​S-1-5-21-1229272821-1004336348-527237240-1003\​Software\​Classes\​CLSID\​{CAFEEFAC-0014-0001-0004-ABCDEFFEDCBB}    Java Plug-in 1.4.1_04 
HKU\​S-1-5-21-1229272821-1004336348-527237240-1003\​Software\​Classes\​CLSID\​{CAFEEFAC-0014-0001-0004-ABCDEFFEDCBB}\​InprocServer32    C:\​Program Files\​Java\​jre1.6.0_03\​bin\​ssv.dll 
HKU\​S-1-5-21-1229272821-1004336348-527237240-1003\​Software\​Classes\​CLSID\​{CAFEEFAC-0014-0001-0004-ABCDEFFEDCBB}\​InprocServer32  ThreadingModel  Apartment 
HKU\​S-1-5-21-1229272821-1004336348-527237240-1003\​Software\​Classes\​CLSID\​{CAFEEFAC-0014-0001-0005-ABCDEFFEDCBA}    Java Plug-in 1.4.1_05 
HKU\​S-1-5-21-1229272821-1004336348-527237240-1003\​Software\​Classes\​CLSID\​{CAFEEFAC-0014-0001-0005-ABCDEFFEDCBA}\​InprocServer32    C:\​Program Files\​Java\​jre1.6.0_03\​bin\​ssv.dll 
HKU\​S-1-5-21-1229272821-1004336348-527237240-1003\​Software\​Classes\​CLSID\​{CAFEEFAC-0014-0001-0005-ABCDEFFEDCBA}\​InprocServer32  ThreadingModel  Apartment 
HKU\​S-1-5-21-1229272821-1004336348-527237240-1003\​Software\​Classes\​CLSID\​{CAFEEFAC-0014-0001-0005-ABCDEFFEDCBB}    Java Plug-in 1.4.1_05 
HKU\​S-1-5-21-1229272821-1004336348-527237240-1003\​Software\​Classes\​CLSID\​{CAFEEFAC-0014-0001-0005-ABCDEFFEDCBB}\​InprocServer32    C:\​Program Files\​Java\​jre1.6.0_03\​bin\​ssv.dll 
HKU\​S-1-5-21-1229272821-1004336348-527237240-1003\​Software\​Classes\​CLSID\​{CAFEEFAC-0014-0001-0005-ABCDEFFEDCBB}\​InprocServer32  ThreadingModel  Apartment 
HKU\​S-1-5-21-1229272821-1004336348-527237240-1003\​Software\​Classes\​CLSID\​{CAFEEFAC-0014-0001-0006-ABCDEFFEDCBA}    Java Plug-in 1.4.1_06 
HKU\​S-1-5-21-1229272821-1004336348-527237240-1003\​Software\​Classes\​CLSID\​{CAFEEFAC-0014-0001-0006-ABCDEFFEDCBA}\​InprocServer32    C:\​Program Files\​Java\​jre1.6.0_03\​bin\​ssv.dll 
HKU\​S-1-5-21-1229272821-1004336348-527237240-1003\​Software\​Classes\​CLSID\​{CAFEEFAC-0014-0001-0006-ABCDEFFEDCBA}\​InprocServer32  ThreadingModel  Apartment 
HKU\​S-1-5-21-1229272821-1004336348-527237240-1003\​Software\​Classes\​CLSID\​{CAFEEFAC-0014-0001-0006-ABCDEFFEDCBB}    Java Plug-in 1.4.1_06 
HKU\​S-1-5-21-1229272821-1004336348-527237240-1003\​Software\​Classes\​CLSID\​{CAFEEFAC-0014-0001-0006-ABCDEFFEDCBB}\​InprocServer32    C:\​Program Files\​Java\​jre1.6.0_03\​bin\​ssv.dll 
HKU\​S-1-5-21-1229272821-1004336348-527237240-1003\​Software\​Classes\​CLSID\​{CAFEEFAC-0014-0001-0006-ABCDEFFEDCBB}\​InprocServer32  ThreadingModel  Apartment 
HKU\​S-1-5-21-1229272821-1004336348-527237240-1003\​Software\​Classes\​CLSID\​{CAFEEFAC-0014-0001-0007-ABCDEFFEDCBA}    Java Plug-in 1.4.1_07 
HKU\​S-1-5-21-1229272821-1004336348-527237240-1003\​Software\​Classes\​CLSID\​{CAFEEFAC-0014-0001-0007-ABCDEFFEDCBA}\​InprocServer32    C:\​Program Files\​Java\​jre1.6.0_03\​bin\​ssv.dll 
HKU\​S-1-5-21-1229272821-1004336348-527237240-1003\​Software\​Classes\​CLSID\​{CAFEEFAC-0014-0001-0007-ABCDEFFEDCBA}\​InprocServer32  ThreadingModel  Apartment 
HKU\​S-1-5-21-1229272821-1004336348-527237240-1003\​Software\​Classes\​CLSID\​{CAFEEFAC-0014-0001-0007-ABCDEFFEDCBB}    Java Plug-in 1.4.1_07 
HKU\​S-1-5-21-1229272821-1004336348-527237240-1003\​Software\​Classes\​CLSID\​{CAFEEFAC-0014-0001-0007-ABCDEFFEDCBB}\​InprocServer32    C:\​Program Files\​Java\​jre1.6.0_03\​bin\​ssv.dll 
HKU\​S-1-5-21-1229272821-1004336348-527237240-1003\​Software\​Classes\​CLSID\​{CAFEEFAC-0014-0001-0007-ABCDEFFEDCBB}\​InprocServer32  ThreadingModel  Apartment 
HKU\​S-1-5-21-1229272821-1004336348-527237240-1003\​Software\​Classes\​CLSID\​{CAFEEFAC-0014-0002-0000-ABCDEFFEDCBA}    Java Plug-in 1.4.2 
HKU\​S-1-5-21-1229272821-1004336348-527237240-1003\​Software\​Classes\​CLSID\​{CAFEEFAC-0014-0002-0000-ABCDEFFEDCBA}\​InprocServer32    C:\​Program Files\​Java\​jre1.6.0_03\​bin\​ssv.dll 
HKU\​S-1-5-21-1229272821-1004336348-527237240-1003\​Software\​Classes\​CLSID\​{CAFEEFAC-0014-0002-0000-ABCDEFFEDCBA}\​InprocServer32  ThreadingModel  Apartment 
HKU\​S-1-5-21-1229272821-1004336348-527237240-1003\​Software\​Classes\​CLSID\​{CAFEEFAC-0014-0002-0000-ABCDEFFEDCBB}    Java Plug-in 1.4.2 
HKU\​S-1-5-21-1229272821-1004336348-527237240-1003\​Software\​Classes\​CLSID\​{CAFEEFAC-0014-0002-0000-ABCDEFFEDCBB}\​InprocServer32    C:\​Program Files\​Java\​jre1.6.0_03\​bin\​ssv.dll 
HKU\​S-1-5-21-1229272821-1004336348-527237240-1003\​Software\​Classes\​CLSID\​{CAFEEFAC-0014-0002-0000-ABCDEFFEDCBB}\​InprocServer32  ThreadingModel  Apartment 
HKU\​S-1-5-21-1229272821-1004336348-527237240-1003\​Software\​Classes\​CLSID\​{CAFEEFAC-0014-0002-0001-ABCDEFFEDCBA}    Java Plug-in 1.4.2_01 
HKU\​S-1-5-21-1229272821-1004336348-527237240-1003\​Software\​Classes\​CLSID\​{CAFEEFAC-0014-0002-0001-ABCDEFFEDCBA}\​InprocServer32    C:\​Program Files\​Java\​jre1.6.0_03\​bin\​ssv.dll 
HKU\​S-1-5-21-1229272821-1004336348-527237240-1003\​Software\​Classes\​CLSID\​{CAFEEFAC-0014-0002-0001-ABCDEFFEDCBA}\​InprocServer32  ThreadingModel  Apartment 
HKU\​S-1-5-21-1229272821-1004336348-527237240-1003\​Software\​Classes\​CLSID\​{CAFEEFAC-0014-0002-0001-ABCDEFFEDCBB}    Java Plug-in 1.4.2_01 
HKU\​S-1-5-21-1229272821-1004336348-527237240-1003\​Software\​Classes\​CLSID\​{CAFEEFAC-0014-0002-0001-ABCDEFFEDCBB}\​InprocServer32    C:\​Program Files\​Java\​jre1.6.0_03\​bin\​ssv.dll 
HKU\​S-1-5-21-1229272821-1004336348-527237240-1003\​Software\​Classes\​CLSID\​{CAFEEFAC-0014-0002-0001-ABCDEFFEDCBB}\​InprocServer32  ThreadingModel  Apartment 
HKU\​S-1-5-21-1229272821-1004336348-527237240-1003\​Software\​Classes\​CLSID\​{CAFEEFAC-0014-0002-0002-ABCDEFFEDCBA}    Java Plug-in 1.4.2_02 
HKU\​S-1-5-21-1229272821-1004336348-527237240-1003\​Software\​Classes\​CLSID\​{CAFEEFAC-0014-0002-0002-ABCDEFFEDCBA}\​InprocServer32    C:\​Program Files\​Java\​jre1.6.0_03\​bin\​ssv.dll 
HKU\​S-1-5-21-1229272821-1004336348-527237240-1003\​Software\​Classes\​CLSID\​{CAFEEFAC-0014-0002-0002-ABCDEFFEDCBA}\​InprocServer32  ThreadingModel  Apartment 
HKU\​S-1-5-21-1229272821-1004336348-527237240-1003\​Software\​Classes\​CLSID\​{CAFEEFAC-0014-0002-0002-ABCDEFFEDCBB}    Java Plug-in 1.4.2_02 
HKU\​S-1-5-21-1229272821-1004336348-527237240-1003\​Software\​Classes\​CLSID\​{CAFEEFAC-0014-0002-0002-ABCDEFFEDCBB}\​InprocServer32    C:\​Program Files\​Java\​jre1.6.0_03\​bin\​ssv.dll 
HKU\​S-1-5-21-1229272821-1004336348-527237240-1003\​Software\​Classes\​CLSID\​{CAFEEFAC-0014-0002-0002-ABCDEFFEDCBB}\​InprocServer32  ThreadingModel  Apartment 
HKU\​S-1-5-21-1229272821-1004336348-527237240-1003\​Software\​Classes\​CLSID\​{CAFEEFAC-0014-0002-0003-ABCDEFFEDCBA}    Java Plug-in 1.4.2_03 
HKU\​S-1-5-21-1229272821-1004336348-527237240-1003\​Software\​Classes\​CLSID\​{CAFEEFAC-0014-0002-0003-ABCDEFFEDCBA}\​InprocServer32    C:\​Program Files\​Java\​jre1.6.0_03\​bin\​ssv.dll 
HKU\​S-1-5-21-1229272821-1004336348-527237240-1003\​Software\​Classes\​CLSID\​{CAFEEFAC-0014-0002-0003-ABCDEFFEDCBA}\​InprocServer32  ThreadingModel  Apartment 
HKU\​S-1-5-21-1229272821-1004336348-527237240-1003\​Software\​Classes\​CLSID\​{CAFEEFAC-0014-0002-0003-ABCDEFFEDCBB}    Java Plug-in 1.4.2_03 
HKU\​S-1-5-21-1229272821-1004336348-527237240-1003\​Software\​Classes\​CLSID\​{CAFEEFAC-0014-0002-0003-ABCDEFFEDCBB}\​InprocServer32    C:\​Program Files\​Java\​jre1.6.0_03\​bin\​ssv.dll 
HKU\​S-1-5-21-1229272821-1004336348-527237240-1003\​Software\​Classes\​CLSID\​{CAFEEFAC-0014-0002-0003-ABCDEFFEDCBB}\​InprocServer32  ThreadingModel  Apartment 
HKU\​S-1-5-21-1229272821-1004336348-527237240-1003\​Software\​Classes\​CLSID\​{E19F9331-3110-11D4-991C-005004D3B3DB}    Java Plug-in 1.3.0_02 
HKU\​S-1-5-21-1229272821-1004336348-527237240-1003\​Software\​Classes\​CLSID\​{E19F9331-3110-11D4-991C-005004D3B3DB}\​InprocServer32    C:\​Program Files\​Java\​jre1.6.0_03\​bin\​ssv.dll 
HKU\​S-1-5-21-1229272821-1004336348-527237240-1003\​Software\​Classes\​CLSID\​{E19F9331-3110-11D4-991C-005004D3B3DB}\​InprocServer32  ThreadingModel  Apartment 
HKU\​S-1-5-21-1229272821-1004336348-527237240-1003\​Software\​Microsoft\​Internet Explorer\​Main  info CompatibilityFlags 
HKU\​S-1-5-21-1229272821-1004336348-527237240-1003\​Software\​Microsoft\​Internet Explorer\​Main  info FullScreen  no 
HKU\​S-1-5-21-1229272821-1004336348-527237240-1003\​Software\​Microsoft\​Internet Explorer\​Main  info Window_Placement  0x2c0000000000000001000000ffffffffffffffffffffffffffffffff0000 
HKU\​S-1-5-21-1229272821-1004336348-527237240-1003\​Software\​Microsoft\​Internet Explorer\​Toolbar  info Locked 
HKU\​S-1-5-21-1229272821-1004336348-527237240-1003\​Software\​Microsoft\​Windows\​CurrentVersion\​Explorer\​MountPoints2\​{d14d83ce-7d74-11dc-97e2-806d6172696f}\​  BaseClass  Drive 
HKU\​S-1-5-21-1229272821-1004336348-527237240-1003\​Software\​Microsoft\​Windows\​CurrentVersion\​Explorer\​MountPoints2\​{d14d83cf-7d74-11dc-97e2-806d6172696f}\​  BaseClass  Drive 
HKU\​S-1-5-21-1229272821-1004336348-527237240-1003\​Software\​Microsoft\​Windows\​CurrentVersion\​Explorer\​Shell Folders  Cache  C:\​Documents and Settings\​user\​Local Settings\​Temporary Internet Files 
HKU\​S-1-5-21-1229272821-1004336348-527237240-1003\​Software\​Microsoft\​Windows\​CurrentVersion\​Explorer\​Shell Folders  Cookies  C:\​Documents and Settings\​user\​Cookies 
HKU\​S-1-5-21-1229272821-1004336348-527237240-1003\​Software\​Microsoft\​Windows\​CurrentVersion\​Explorer\​Shell Folders  Desktop  C:\​Documents and Settings\​user\​Desktop 
HKU\​S-1-5-21-1229272821-1004336348-527237240-1003\​Software\​Microsoft\​Windows\​CurrentVersion\​Explorer\​Shell Folders  Favorites  C:\​Documents and Settings\​user\​Favorites 
HKU\​S-1-5-21-1229272821-1004336348-527237240-1003\​Software\​Microsoft\​Windows\​CurrentVersion\​Explorer\​Shell Folders  History  C:\​Documents and Settings\​user\​Local Settings\​History 
HKU\​S-1-5-21-1229272821-1004336348-527237240-1003\​Software\​Microsoft\​Windows\​CurrentVersion\​Internet Settings\​ZoneMap\​  info AutoDetect 
HKU\​S-1-5-21-1229272821-1004336348-527237240-1003\​Software\​Microsoft\​Windows\​CurrentVersion\​Internet Settings\​ZoneMap\​  info IntranetName 
HKU\​S-1-5-21-1229272821-1004336348-527237240-1003\​Software\​Microsoft\​Windows\​CurrentVersion\​Internet Settings\​ZoneMap\​  info ProxyBypass 
HKU\​S-1-5-21-1229272821-1004336348-527237240-1003\​Software\​Microsoft\​Windows\​CurrentVersion\​Internet Settings\​ZoneMap\​  info UNCAsIntranet 

  - Registry Values Read:  
Key Name Value Times
HKLM\​SOFTWARE\​CLASSES\​.HTM    htmlfile 
HKLM\​SOFTWARE\​CLASSES\​.HTM  PerceivedType  text 
HKLM\​SOFTWARE\​CLASSES\​CLSID\​{0002DF01-0000-0000-C000-000000000046}\​LOCALSERVER32    "C:\​Program Files\​Internet Explorer\​IEXPLORE.EXE" 
HKLM\​SOFTWARE\​CLASSES\​CLSID\​{1C1EDB47-CE22-4BBB-B608-77B48F83C823}\​INPROCSERVER32    C:\​WINDOWS\​system32\​ieframe.dll 
HKLM\​SOFTWARE\​CLASSES\​CLSID\​{1C1EDB47-CE22-4BBB-B608-77B48F83C823}\​INPROCSERVER32  ThreadingModel  Apartment 
HKLM\​SOFTWARE\​CLASSES\​CLSID\​{20D04FE0-3AEA-1069-A2D8-08002B30309D}\​INPROCSERVER32    %SystemRoot%\​system32\​SHELL32.dll 
HKLM\​SOFTWARE\​CLASSES\​CLSID\​{3CE74DE4-53D3-4D74-8B83-431B3828BA53}\​INPROCSERVER32    C:\​WINDOWS\​system32\​msctf.dll 
HKLM\​SOFTWARE\​CLASSES\​CLSID\​{3CE74DE4-53D3-4D74-8B83-431B3828BA53}\​INPROCSERVER32  ThreadingModel  Apartment 
HKLM\​SOFTWARE\​CLASSES\​CLSID\​{42042206-2D85-11D3-8CFF-005004838597}\​INPROCSERVER32    C:\​Program Files\​Microsoft Office\​OFFICE11\​msohev.dll 
HKLM\​SOFTWARE\​CLASSES\​CLSID\​{42042206-2D85-11D3-8CFF-005004838597}\​INPROCSERVER32  ThreadingModel  Apartment 
HKLM\​SOFTWARE\​CLASSES\​CLSID\​{42042206-2D85-11D3-8CFF-005004838597}\​OLD ICON\​HTMLFILE\​DEFAULTICON    C:\​Program Files\​Internet Explorer\​IEXPLORE.EXE,-17 
HKLM\​SOFTWARE\​CLASSES\​CLSID\​{50D5107A-D278-4871-8989-F4CEAAF59CFC}\​INPROCSERVER32    C:\​WINDOWS\​system32\​msimtf.dll 
HKLM\​SOFTWARE\​CLASSES\​CLSID\​{50D5107A-D278-4871-8989-F4CEAAF59CFC}\​INPROCSERVER32  ThreadingModel  Apartment 
HKLM\​SOFTWARE\​CLASSES\​CLSID\​{750FDF0E-2A26-11D1-A3EA-080036587F03}\​INPROCSERVER32    %SystemRoot%\​System32\​cscui.dll 
HKLM\​SOFTWARE\​CLASSES\​CLSID\​{750FDF0E-2A26-11D1-A3EA-080036587F03}\​INPROCSERVER32  ThreadingModel  Apartment 
HKLM\​SOFTWARE\​CLASSES\​CLSID\​{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}\​INPROCSERVER32    C:\​Program Files\​Java\​jre1.6.0_03\​bin\​ssv.dll 
HKLM\​SOFTWARE\​CLASSES\​CLSID\​{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}\​INPROCSERVER32  ThreadingModel  Apartment 
HKLM\​SOFTWARE\​CLASSES\​CLSID\​{871C5380-42A0-1069-A2EA-08002B30309D}\​INPROCSERVER32    C:\​WINDOWS\​system32\​ieframe.dll 
HKLM\​SOFTWARE\​CLASSES\​CLSID\​{871C5380-42A0-1069-A2EA-08002B30309D}\​INPROCSERVER32  ThreadingModel  Apartment 
HKLM\​SOFTWARE\​CLASSES\​CLSID\​{871C5380-42A0-1069-A2EA-08002B30309D}\​SHELLFOLDER  WantsParseDisplayName   
HKLM\​SOFTWARE\​CLASSES\​CLSID\​{A4B544A1-438D-4B41-9325-869523E2D6C7}\​INPROCSERVER32    C:\​WINDOWS\​system32\​msctf.dll 
HKLM\​SOFTWARE\​CLASSES\​CLSID\​{A4B544A1-438D-4B41-9325-869523E2D6C7}\​INPROCSERVER32  ThreadingModel  Apartment 
HKLM\​SOFTWARE\​CLASSES\​CLSID\​{C90250F3-4D7D-4991-9B69-A5C5BC1C2AE6}\​INPROCSERVER32    C:\​Program Files\​Internet Explorer\​ieproxy.dll 
HKLM\​SOFTWARE\​CLASSES\​CLSID\​{C90250F3-4D7D-4991-9B69-A5C5BC1C2AE6}\​INPROCSERVER32  ThreadingModel  Both 
HKLM\​SOFTWARE\​CLASSES\​DRIVE\​SHELLEX\​FOLDEREXTENSIONS\​{FBEB8A05-BEEE-4442-804E-409D6C4515E9}  DriveMask  32 
HKLM\​SOFTWARE\​CLASSES\​HTMLFILE\​CLSID    {25336920-03F9-11cf-8FD0-00AA00686F13} 
HKLM\​SOFTWARE\​CLASSES\​HTMLFILE\​SHELLEX\​ICONHANDLER    {42042206-2D85-11D3-8CFF-005004838597} 
HKLM\​SOFTWARE\​CLASSES\​HTTP  URL Protocol   
HKLM\​SOFTWARE\​CLASSES\​INTERFACE\​{000214E6-0000-0000-C000-000000000046}\​PROXYSTUBCLSID32    {bf50b68e-29b8-4386-ae9c-9734d5117cd5} 
HKLM\​SOFTWARE\​CLASSES\​INTERFACE\​{79EAC9C4-BAF9-11CE-8C82-00AA004BA90B}\​PROXYSTUBCLSID32    {B8DA6310-E19B-11D0-933C-00A0C90DCAA9} 
HKLM\​SOFTWARE\​CLASSES\​INTERFACE\​{93F2F68C-1D1B-11D3-A30E-00C04F79ABD1}\​PROXYSTUBCLSID32    {bf50b68e-29b8-4386-ae9c-9734d5117cd5} 
HKLM\​SOFTWARE\​CLASSES\​INTERFACE\​{9BAB3405-EE3F-4040-8836-25AA9C2D408E}\​PROXYSTUBCLSID32    {C90250F3-4D7D-4991-9B69-A5C5BC1C2AE6} 
HKLM\​SOFTWARE\​CLASSES\​INTERFACE\​{B722BCCB-4E68-101B-A2BC-00AA00404770}\​PROXYSTUBCLSID32    {B8DA6310-E19B-11D0-933C-00A0C90DCAA9} 
HKLM\​SOFTWARE\​CLASSES\​INTERFACE\​{EAB22AC1-30C1-11CF-A7EB-0000C05BAE0B}\​TYPELIB    {EAB22AC0-30C1-11CF-A7EB-0000C05BAE0B} 
HKLM\​SOFTWARE\​Microsoft\​CTF\​SystemShared  CUAS 
HKLM\​SOFTWARE\​Microsoft\​CTF\​SystemShared\​  CUAS 
HKLM\​SOFTWARE\​Microsoft\​CTF\​TIP\​\​{78CB5B0E-26ED-4FCC-854C-77E8F3D1AA80}\​Category\​Item\​{5130A009-5540-4FCF-97EB-AAD33FC0EE09}  Description  Proofing 
HKLM\​SOFTWARE\​Microsoft\​CTF\​TIP\​\​{78CB5B0E-26ED-4FCC-854C-77E8F3D1AA80}\​Category\​Item\​{7AE86BB7-262C-431E-9111-C974B6B7CAC3}  Description  Smart Tag 
HKLM\​SOFTWARE\​Microsoft\​CTF\​TIP\​\​{78CB5B0E-26ED-4FCC-854C-77E8F3D1AA80}\​Category\​Item\​{C6DEBC0A-F2B2-4F17-930E-CA9FAFF4CD04}  Description  Reference 
HKLM\​SOFTWARE\​Microsoft\​Internet Explorer\​Setup  IExploreLastModifiedHigh  29887276 
HKLM\​SOFTWARE\​Microsoft\​Internet Explorer\​Setup  IExploreLastModifiedLow  2933474304 
HKLM\​SOFTWARE\​Microsoft\​Windows\​CurrentVersion\​App Paths\​IEXPLORE.EXE    C:\​Program Files\​Internet Explorer\​IEXPLORE.EXE 
HKLM\​SOFTWARE\​Microsoft\​Windows\​CurrentVersion\​Internet Settings  EnablePunycode 
HKLM\​SOFTWARE\​Microsoft\​Windows\​CurrentVersion\​Internet Settings  UrlEncoding  0x00000000 
HKLM\​SYSTEM\​Setup  OsLoaderPath  \​ 
HKLM\​SYSTEM\​Setup  SystemPartition  \​Device\​HarddiskVolume1 
HKLM\​SYSTEM\​WPA\​MediaCenter  Installed 
HKLM\​Software\​Classes\​CLSID\​{42042206-2d85-11d3-8cff-005004838597}\​InProcServer32    C:\​Program Files\​Microsoft Office\​OFFICE11\​msohev.dll 
HKLM\​Software\​Classes\​CLSID\​{50d5107a-d278-4871-8989-f4ceaaf59cfc}\​InProcServer32    C:\​WINDOWS\​system32\​msimtf.dll 
HKLM\​Software\​Classes\​CLSID\​{750fdf0e-2a26-11d1-a3ea-080036587f03}\​InProcServer32    %SystemRoot%\​System32\​cscui.dll 
HKLM\​Software\​Classes\​CLSID\​{871c5380-42a0-1069-a2ea-08002b30309d}\​InProcServer32    C:\​WINDOWS\​system32\​ieframe.dll 
HKLM\​Software\​Microsoft\​COM3  Com+Enabled 
HKLM\​Software\​Microsoft\​COM3  REGDBVersion  0x0f00000000000000  30 
HKLM\​Software\​Microsoft\​CTF\​SystemShared  CUAS 
HKLM\​Software\​Microsoft\​Internet Explorer\​AutoComplete\​Client\​    {807C1E6C-1D00-453f-B920-B61BB7CDD997} 
HKLM\​Software\​Microsoft\​Internet Explorer\​Main\​FeatureControl\​FEATURE_INTERNET_SHELL_FOLDERS  IEXPLORE.EXE 
HKLM\​Software\​Microsoft\​Windows NT\​CurrentVersion\​IMM  Ime File  msctfime.ime 
HKLM\​Software\​Microsoft\​Windows\​CurrentVersion  DevicePath  %SystemRoot%\​inf 
HKLM\​Software\​Microsoft\​Windows\​CurrentVersion\​Explorer\​ShellIconOverlayIdentifiers\​Offline Files    {750fdf0e-2a26-11d1-a3ea-080036587f03} 
HKLM\​Software\​Microsoft\​Windows\​CurrentVersion\​Internet Settings\​5.0\​Cache\​Content  PerUserItem 
HKLM\​Software\​Microsoft\​Windows\​CurrentVersion\​Internet Settings\​5.0\​Cache\​Cookies  PerUserItem 
HKLM\​Software\​Microsoft\​Windows\​CurrentVersion\​Internet Settings\​5.0\​Cache\​History  PerUserItem 
HKLM\​Software\​Microsoft\​Windows\​CurrentVersion\​Internet Settings\​Url History  DaysToKeep  20 
HKLM\​Software\​Microsoft\​Windows\​CurrentVersion\​Setup  DriverCachePath  %SystemRoot%\​Driver Cache 
HKLM\​Software\​Microsoft\​Windows\​CurrentVersion\​Setup  LogLevel 
HKLM\​Software\​Microsoft\​Windows\​CurrentVersion\​Setup  ServicePackCachePath  c:\​windows\​ServicePackFiles\​ServicePackCache 
HKLM\​Software\​Microsoft\​Windows\​CurrentVersion\​Setup  ServicePackSourcePath  c:\​windows\​ServicePackFiles 
HKLM\​Software\​Microsoft\​Windows\​CurrentVersion\​Setup  SourcePath  D:\​ 
HKLM\​System\​CurrentControlSet\​Control\​ComputerName\​ActiveComputerName  ComputerName  USER 
HKLM\​System\​CurrentControlSet\​Services\​Tcpip\​Parameters  Domain   
HKLM\​System\​CurrentControlSet\​Services\​Tcpip\​Parameters  Hostname  user 
HKLM\​System\​CurrentControlSet\​Services\​WinSock2\​Parameters  WinSock_Registry_Version  2.0 
HKLM\​System\​CurrentControlSet\​Services\​WinSock2\​Parameters\​NameSpace_Catalog5  Num_Catalog_Entries 
HKLM\​System\​CurrentControlSet\​Services\​WinSock2\​Parameters\​NameSpace_Catalog5  Serial_Access_Num 
HKLM\​System\​CurrentControlSet\​Services\​WinSock2\​Parameters\​NameSpace_Catalog5\​Catalog_Entries\​000000000001  DisplayString  Tcpip 
HKLM\​System\​CurrentControlSet\​Services\​WinSock2\​Parameters\​NameSpace_Catalog5\​Catalog_Entries\​000000000001  Enabled 
HKLM\​System\​CurrentControlSet\​Services\​WinSock2\​Parameters\​NameSpace_Catalog5\​Catalog_Entries\​000000000001  LibraryPath  %SystemRoot%\​System32\​mswsock.dll 
HKLM\​System\​CurrentControlSet\​Services\​WinSock2\​Parameters\​NameSpace_Catalog5\​Catalog_Entries\​000000000001  ProviderId  0x409d05229e7ecf11ae5a00aa00a7112b 
HKLM\​System\​CurrentControlSet\​Services\​WinSock2\​Parameters\​NameSpace_Catalog5\​Catalog_Entries\​000000000001  StoresServiceClassInfo 
HKLM\​System\​CurrentControlSet\​Services\​WinSock2\​Parameters\​NameSpace_Catalog5\​Catalog_Entries\​000000000001  SupportedNameSpace  12 
HKLM\​System\​CurrentControlSet\​Services\​WinSock2\​Parameters\​NameSpace_Catalog5\​Catalog_Entries\​000000000001  Version 
HKLM\​System\​CurrentControlSet\​Services\​WinSock2\​Parameters\​NameSpace_Catalog5\​Catalog_Entries\​000000000002  DisplayString  NTDS 
HKLM\​System\​CurrentControlSet\​Services\​WinSock2\​Parameters\​NameSpace_Catalog5\​Catalog_Entries\​000000000002  Enabled 
HKLM\​System\​CurrentControlSet\​Services\​WinSock2\​Parameters\​NameSpace_Catalog5\​Catalog_Entries\​000000000002  LibraryPath  %SystemRoot%\​System32\​winrnr.dll 
HKLM\​System\​CurrentControlSet\​Services\​WinSock2\​Parameters\​NameSpace_Catalog5\​Catalog_Entries\​000000000002  ProviderId  0xee37263b80e5cf11a55500c04fd8d4ac 
HKLM\​System\​CurrentControlSet\​Services\​WinSock2\​Parameters\​NameSpace_Catalog5\​Catalog_Entries\​000000000002  StoresServiceClassInfo 
HKLM\​System\​CurrentControlSet\​Services\​WinSock2\​Parameters\​NameSpace_Catalog5\​Catalog_Entries\​000000000002  SupportedNameSpace  32 
HKLM\​System\​CurrentControlSet\​Services\​WinSock2\​Parameters\​NameSpace_Catalog5\​Catalog_Entries\​000000000002  Version 
HKLM\​System\​CurrentControlSet\​Services\​WinSock2\​Parameters\​NameSpace_Catalog5\​Catalog_Entries\​000000000003  DisplayString  Network Location Awareness (NLA) Namespace 
HKLM\​System\​CurrentControlSet\​Services\​WinSock2\​Parameters\​NameSpace_Catalog5\​Catalog_Entries\​000000000003  Enabled 
HKLM\​System\​CurrentControlSet\​Services\​WinSock2\​Parameters\​NameSpace_Catalog5\​Catalog_Entries\​000000000003  LibraryPath  %SystemRoot%\​System32\​mswsock.dll 
HKLM\​System\​CurrentControlSet\​Services\​WinSock2\​Parameters\​NameSpace_Catalog5\​Catalog_Entries\​000000000003  ProviderId  0x3a244266a83ba64abaa52e0bd71fdd83 
HKLM\​System\​CurrentControlSet\​Services\​WinSock2\​Parameters\​NameSpace_Catalog5\​Catalog_Entries\​000000000003  StoresServiceClassInfo 
HKLM\​System\​CurrentControlSet\​Services\​WinSock2\​Parameters\​NameSpace_Catalog5\​Catalog_Entries\​000000000003  SupportedNameSpace  15 
HKLM\​System\​CurrentControlSet\​Services\​WinSock2\​Parameters\​NameSpace_Catalog5\​Catalog_Entries\​000000000003  Version 
HKLM\​System\​CurrentControlSet\​Services\​WinSock2\​Parameters\​Protocol_Catalog9  Next_Catalog_Entry_ID  1012 
HKLM\​System\​CurrentControlSet\​Services\​WinSock2\​Parameters\​Protocol_Catalog9  Num_Catalog_Entries  11 
HKLM\​System\​CurrentControlSet\​Services\​WinSock2\​Parameters\​Protocol_Catalog9  Serial_Access_Num 
HKLM\​System\​CurrentControlSet\​Services\​WinSock2\​Parameters\​Protocol_Catalog9\​Catalog_Entries\​000000000001  PackedCatalogItem  %SystemRoot%\​system32\​mswsock. 
HKLM\​System\​CurrentControlSet\​Services\​WinSock2\​Parameters\​Protocol_Catalog9\​Catalog_Entries\​000000000002  PackedCatalogItem  %SystemRoot%\​system32\​mswsock. 
HKLM\​System\​CurrentControlSet\​Services\​WinSock2\​Parameters\​Protocol_Catalog9\​Catalog_Entries\​000000000003  PackedCatalogItem  %SystemRoot%\​system32\​mswsock. 
HKLM\​System\​CurrentControlSet\​Services\​WinSock2\​Parameters\​Protocol_Catalog9\​Catalog_Entries\​000000000004  PackedCatalogItem  %SystemRoot%\​system32\​rsvpsp.d 
HKLM\​System\​CurrentControlSet\​Services\​WinSock2\​Parameters\​Protocol_Catalog9\​Catalog_Entries\​000000000005  PackedCatalogItem  %SystemRoot%\​system32\​rsvpsp.d 
HKLM\​System\​CurrentControlSet\​Services\​WinSock2\​Parameters\​Protocol_Catalog9\​Catalog_Entries\​000000000006  PackedCatalogItem  %SystemRoot%\​system32\​mswsock. 
HKLM\​System\​CurrentControlSet\​Services\​WinSock2\​Parameters\​Protocol_Catalog9\​Catalog_Entries\​000000000007  PackedCatalogItem  %SystemRoot%\​system32\​mswsock. 
HKLM\​System\​CurrentControlSet\​Services\​WinSock2\​Parameters\​Protocol_Catalog9\​Catalog_Entries\​000000000008  PackedCatalogItem  %SystemRoot%\​system32\​mswsock. 
HKLM\​System\​CurrentControlSet\​Services\​WinSock2\​Parameters\​Protocol_Catalog9\​Catalog_Entries\​000000000009  PackedCatalogItem  %SystemRoot%\​system32\​mswsock. 
HKLM\​System\​CurrentControlSet\​Services\​WinSock2\​Parameters\​Protocol_Catalog9\​Catalog_Entries\​000000000010  PackedCatalogItem  %SystemRoot%\​system32\​mswsock. 
HKLM\​System\​CurrentControlSet\​Services\​WinSock2\​Parameters\​Protocol_Catalog9\​Catalog_Entries\​000000000011  PackedCatalogItem  %SystemRoot%\​system32\​mswsock. 
HKLM\​System\​Setup  SystemSetupInProgress 
HKLM\​System\​WPA\​PnP  seed  1374283966 
HKU\​S-1-5-21-1229272821-1004336348-527237240-1003\​Control Panel\​Desktop\​WindowMetrics  Shell Icon Bpp  16 
HKU\​S-1-5-21-1229272821-1004336348-527237240-1003\​Control Panel\​Desktop\​WindowMetrics  Shell Icon Size  32 
HKU\​S-1-5-21-1229272821-1004336348-527237240-1003\​SOFTWARE\​Microsoft\​CTF\​TIP\​{1188450c-fdab-47ae-80d8-c9633f71be64}\​LanguageProfile\​0x00000000\​{63800dac-e7ca-4df9-9a5c-20765055488d}  Enable 
HKU\​S-1-5-21-1229272821-1004336348-527237240-1003\​SOFTWARE\​Microsoft\​Windows\​CurrentVersion\​Ext\​Stats\​{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}\​iexplore  Count  24 
HKU\​S-1-5-21-1229272821-1004336348-527237240-1003\​SOFTWARE\​Microsoft\​Windows\​CurrentVersion\​Internet Settings  CertificateRevocation 
HKU\​S-1-5-21-1229272821-1004336348-527237240-1003\​SOFTWARE\​Microsoft\​Windows\​CurrentVersion\​Internet Settings  DisableCachingOfSSLPages 
HKU\​S-1-5-21-1229272821-1004336348-527237240-1003\​SOFTWARE\​Microsoft\​Windows\​CurrentVersion\​Internet Settings  EnableHttp1_1 
HKU\​S-1-5-21-1229272821-1004336348-527237240-1003\​SOFTWARE\​Microsoft\​Windows\​CurrentVersion\​Internet Settings  EnableNegotiate 
HKU\​S-1-5-21-1229272821-1004336348-527237240-1003\​SOFTWARE\​Microsoft\​Windows\​CurrentVersion\​Internet Settings  MimeExclusionListForCache  multipart/mixed multipart/x-mixed-replace multipart/x-byteranges  
HKU\​S-1-5-21-1229272821-1004336348-527237240-1003\​SOFTWARE\​Microsoft\​Windows\​CurrentVersion\​Internet Settings  SecureProtocols  160 
HKU\​S-1-5-21-1229272821-1004336348-527237240-1003\​SOFTWARE\​Microsoft\​Windows\​CurrentVersion\​Internet Settings  WarnOnPost  0x01000000 
HKU\​S-1-5-21-1229272821-1004336348-527237240-1003\​SOFTWARE\​Microsoft\​Windows\​CurrentVersion\​Internet Settings  WarnOnZoneCrossing 
HKU\​S-1-5-21-1229272821-1004336348-527237240-1003\​Software\​Microsoft\​Internet Explorer\​LinksExplorer  Docked 
HKU\​S-1-5-21-1229272821-1004336348-527237240-1003\​Software\​Microsoft\​Internet Explorer\​Main  AlwaysShowMenus 
HKU\​S-1-5-21-1229272821-1004336348-527237240-1003\​Software\​Microsoft\​Internet Explorer\​Main  CompatibilityFlags 
HKU\​S-1-5-21-1229272821-1004336348-527237240-1003\​Software\​Microsoft\​Internet Explorer\​Main  Enable Browser Extensions  yes 
HKU\​S-1-5-21-1229272821-1004336348-527237240-1003\​Software\​Microsoft\​Internet Explorer\​Main  FullScreen  no 
HKU\​S-1-5-21-1229272821-1004336348-527237240-1003\​Software\​Microsoft\​Internet Explorer\​Main  SearchMigrated 
HKU\​S-1-5-21-1229272821-1004336348-527237240-1003\​Software\​Microsoft\​Internet Explorer\​Main  Window_Placement  0x2c0000000000000001000000ffffffffffffffffffffffffffffffff0000 
HKU\​S-1-5-21-1229272821-1004336348-52723724