Recommended for You:
Fix up your PC Fast

TuneUp Utilities 2012 takes out the trash: Get back long lost disk space and performance in a snap – Free Download!






You are not connected. Please login or register

Goto page : Previous  1, 2, 3, 4, 5, 6, 7  Next

View previous topic View next topic Go down  Message [Page 5 of 7]

61 Re: Malware problems and Internet Redirecting on Fri Jul 30, 2010 11:56 pm

DragonMaster Jay


Site Owner
Site Owner
I want to take another look with this tool:

Please download MySystem-Search from one of the following links:
    Download mirror 1 Download mirror 2
  • Save the file to your Desktop.
  • Double-click on mss.exe
  • Allow it to run, and follow the prompts.
  • Once done, it will launch a log.
  • Post it in your next reply.
Note: the logs are long. Please use more than one post, if necessary.


..........................................................
DragonMaster Jay
Administrative Director SecuraGeek Association
Advanced Malware Analysts Group Owner


Kaspersky E-Store Kaspersky Anti-Virus 2012: Click Here

Contribute/donate to our site

62 Re: Malware problems and Internet Redirecting on Sun Aug 01, 2010 10:41 am

blink711


Member
Member
MySystem-Search


MSS v1.6


Basic System Information

Username: Miki - Date: 08/01/2010 - Time: 10:39:51

Microsoft Windows XP [Version 5.1.2600]
Processor type: x86 Family 6 Model 28 Stepping 2, GenuineIntel
Total processors: 2
Computer Name: D2M92XF1
Logon Server: \\D2M92XF1


CD Emulation Drivers running?



Peer-to-Peer applications?



File associations

.exe=exefile
.scr=scrfile
.pif=piffile
.com=ComFile
.bat=batfile
.cmd=cmdfile
.log=txtfile
.txt=txtfile
.reg=regfile
.sys=sysfile
.dll=dllfile
.ini=inifile
.inf=inffile


Running processes



Hidden objects

PATH: C:\windows

$hf_mig$
$NtUninstallKB2229593$
$NtUninstallKB898461$
$NtUninstallKB971468$
$NtUninstallKB974392$
$NtUninstallKB975560$
$NtUninstallKB975561$
$NtUninstallKB975562$
$NtUninstallKB975713$
$NtUninstallKB977816$
$NtUninstallKB977914$
$NtUninstallKB978037$
$NtUninstallKB978262$
$NtUninstallKB978338$
$NtUninstallKB978542$
$NtUninstallKB978601$
$NtUninstallKB978695_WM9$
$NtUninstallKB978706$
$NtUninstallKB979306$
$NtUninstallKB979309$
$NtUninstallKB979402_WM9$
$NtUninstallKB979482$
$NtUninstallKB979559$
$NtUninstallKB979683$
$NtUninstallKB980195$
$NtUninstallKB980218$
$NtUninstallKB980232$
$NtUninstallKB981793$
$NtUninstallWdf01005$
ie8
inf
Installer
WindowsShell.Manifest
winnt.bmp
winnt256.bmp


PATH: C:\windows\system32

cdplayer.exe.manifest
dllcache
logonui.exe.manifest
ncpa.cpl.manifest
nwc.cpl.manifest
sapi.cpl.manifest
WindowsLogon.manifest
wuaucpl.cpl.manifest


PATH: C:\windows\system32\drivers

MsftWdf_Kernel_01005_Coinstaller_Critical.Wdf


PATH: C:\

boot.ini
cmdcons
dell.sdr
IO.SYS
MSDOS.SYS
NTDETECT.COM
ntldr
pagefile.sys
RECYCLER
System Volume Information


User Profile check



! REG.EXE VERSION 3.0

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ProfileList
ProfilesDirectory REG_EXPAND_SZ %SystemDrive%\Documents and Settings
DefaultUserProfile REG_SZ Default User
AllUsersProfile REG_SZ All Users

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ProfileList\S-1-5-18
Flags REG_DWORD 0xc
State REG_DWORD 0x0
RefCount REG_DWORD 0x1
Sid REG_BINARY 010100000000000512000000
ProfileImagePath REG_EXPAND_SZ %systemroot%\system32\config\systemprofile

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ProfileList\S-1-5-19
ProfileImagePath REG_EXPAND_SZ %SystemDrive%\Documents and Settings\LocalService
Sid REG_BINARY 010100000000000513000000
Flags REG_DWORD 0x9
State REG_DWORD 0x0
CentralProfile REG_SZ
ProfileLoadTimeLow REG_DWORD 0xec217b48
ProfileLoadTimeHigh REG_DWORD 0x1cb2dd4
RefCount REG_DWORD 0x4

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ProfileList\S-1-5-20
ProfileImagePath REG_EXPAND_SZ %SystemDrive%\Documents and Settings\NetworkService
Sid REG_BINARY 010100000000000514000000
Flags REG_DWORD 0x9
State REG_DWORD 0x0
CentralProfile REG_SZ
ProfileLoadTimeLow REG_DWORD 0xeba58100
ProfileLoadTimeHigh REG_DWORD 0x1cb2dd4
RefCount REG_DWORD 0x2

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ProfileList\S-1-5-21-935248203-3380790443-435834739-1006
ProfileImagePath REG_EXPAND_SZ %SystemDrive%\Documents and Settings\Miki
Sid REG_BINARY 0105000000000005150000004BC1BE37ABC482C9734FFA19EE030000
Flags REG_DWORD 0x0
State REG_DWORD 0x100
CentralProfile REG_SZ
ProfileLoadTimeLow REG_DWORD 0xed1e348c
ProfileLoadTimeHigh REG_DWORD 0x1cb2dd4
RefCount REG_DWORD 0x1
RunLogonScriptSync REG_DWORD 0x0
OptimizedLogonStatus REG_DWORD 0xb

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ProfileList\S-1-5-21-935248203-3380790443-435834739-500
ProfileImagePath REG_EXPAND_SZ %SystemDrive%\Documents and Settings\Administrator
Sid REG_BINARY 0105000000000005150000004BC1BE37ABC482C9734FFA19F4010000
Flags REG_DWORD 0x0
State REG_DWORD 0x100
CentralProfile REG_SZ
ProfileLoadTimeLow REG_DWORD 0x1d51c7ac
ProfileLoadTimeHigh REG_DWORD 0x1cb1fa4
RefCount REG_DWORD 0x0
RunLogonScriptSync REG_DWORD 0x0
OptimizedLogonStatus REG_DWORD 0xb


Current Scheduled Tasks

PATH: C:\Windows\Tasks

desktop.ini
SA.DAT


Windows Drivers and NT-Services

Volume in drive C is OS
Volume Serial Number is C474-ED9D

Directory of C:\Windows\System32\Drivers

04/13/2010 05:38 PM 0 MsftWdf_Kernel_01005_Coinstaller_Critical.Wdf
1 File(s) 0 bytes
0 Dir(s) 511,012,864 bytes free
Volume in drive C is OS
Volume Serial Number is C474-ED9D

Directory of C:\Windows\System32\Drivers

08/17/2001 09:59 AM 3,072 audstub.sys
08/17/2001 09:51 PM 3,328 pciide.sys
08/17/2001 09:51 PM 6,656 cmdide.sys
08/17/2001 09:51 PM 4,992 toside.sys
08/17/2001 09:51 PM 5,248 aliide.sys
08/17/2001 09:51 PM 14,848 asc3550.sys
08/17/2001 09:52 PM 23,552 ABP480N5.SYS
08/17/2001 09:52 PM 26,496 asc.sys
08/17/2001 09:52 PM 12,800 aha154x.sys
08/17/2001 09:52 PM 22,400 asc3350p.sys
08/17/2001 09:52 PM 12,032 amsint.sys
08/17/2001 09:52 PM 7,680 cd20xrnt.sys
08/17/2001 09:52 PM 14,976 cpqarray.sys
08/17/2001 09:52 PM 13,952 cbidf2k.sys
08/17/2001 09:52 PM 16,000 ini910u.sys
08/17/2001 09:52 PM 17,280 mraid35x.sys
08/17/2001 09:52 PM 179,584 dac2w2k.sys
08/17/2001 09:52 PM 14,720 dac960nt.sys
08/17/2001 09:52 PM 33,152 ql10wnt.sys
08/17/2001 09:52 PM 40,448 ql1240.sys
08/17/2001 09:52 PM 49,024 ql1280.sys
08/17/2001 09:52 PM 40,320 ql1080.sys
08/17/2001 09:52 PM 45,312 ql12160.sys
08/17/2001 09:52 PM 36,736 ultra.sys
08/17/2001 09:52 PM 125,056 ftdisk.sys
08/17/2001 10:07 PM 101,888 adpu160m.sys
08/17/2001 10:07 PM 16,256 symc810.sys
08/17/2001 10:07 PM 55,168 aic78u2.sys
08/17/2001 10:07 PM 32,640 symc8xx.sys
08/17/2001 10:07 PM 56,960 aic78xx.sys
08/17/2001 10:07 PM 28,384 sym_hi.sys
08/17/2001 10:07 PM 27,296 perc2.sys
08/17/2001 10:07 PM 5,504 perc2hib.sys
08/17/2001 10:07 PM 30,688 sym_u3.sys
08/17/2001 10:07 PM 19,072 sparrow.sys
08/17/2001 10:07 PM 25,952 hpn.sys
08/17/2001 10:07 PM 20,192 dpti2o.sys
11/02/2006 08:22 AM 32,224 wdfldr.sys
11/02/2006 08:22 AM 492,000 wdf01000.sys
04/19/2007 04:21 PM 9,856 EMSC.sys
10/30/2007 05:25 AM 49,920 HPZid412.sys
10/30/2007 05:25 AM 16,496 HPZipr12.sys
10/30/2007 05:25 AM 21,568 HPZius12.sys
04/13/2008 08:10 PM 57,600 redbook.sys
04/14/2008 12:15 AM 15,104 usbscan.sys
04/14/2008 12:15 AM 26,368 USBSTOR.SYS
04/14/2008 12:17 AM 25,856 usbprint.sys
04/14/2008 06:09 AM 142,592 aec.sys
04/14/2008 08:00 AM 36,736 crusoe.sys
04/14/2008 08:00 AM 60,800 arp1394.sys
04/14/2008 08:00 AM 37,760 amdk7.sys
04/14/2008 08:00 AM 81,664 videoprt.sys
04/14/2008 08:00 AM 36,352 disk.sys
04/14/2008 08:00 AM 14,208 diskdump.sys
04/14/2008 08:00 AM 799,744 dmboot.sys
04/14/2008 08:00 AM 153,344 dmio.sys
04/14/2008 08:00 AM 5,888 dmload.sys
04/14/2008 08:00 AM 15,744 serenum.sys
04/14/2008 08:00 AM 49,536 classpnp.sys
04/14/2008 08:00 AM 20,992 vga.sys
04/14/2008 08:00 AM 58,112 vdmindvd.sys
04/14/2008 08:00 AM 10,496 dxapi.sys
04/14/2008 08:00 AM 71,168 dxg.sys
04/14/2008 08:00 AM 3,328 dxgthk.sys
04/14/2008 08:00 AM 262,528 cinemst2.sys
04/14/2008 08:00 AM 14,336 asyncmac.sys
04/14/2008 08:00 AM 143,744 fastfat.sys
04/14/2008 08:00 AM 27,392 fdc.sys
04/14/2008 08:00 AM 44,544 fips.sys
04/14/2008 08:00 AM 20,480 flpydisk.sys
04/14/2008 08:00 AM 129,792 fltMgr.sys
04/14/2008 08:00 AM 12,160 fsvga.sys
04/14/2008 08:00 AM 7,936 fs_rec.sys
04/14/2008 08:00 AM 37,376 amdk6.sys
04/14/2008 08:00 AM 3,440,660 gm.dls
04/14/2008 08:00 AM 646 gmreadme.txt
04/14/2008 08:00 AM 144,384 hdaudbus.sys
04/14/2008 08:00 AM 36,864 hidclass.sys
04/14/2008 08:00 AM 24,960 hidparse.sys
04/14/2008 08:00 AM 10,368 hidusb.sys
04/14/2008 08:00 AM 62,976 cdrom.sys
04/14/2008 08:00 AM 63,744 cdfs.sys
04/14/2008 08:00 AM 18,688 cdaudio.sys
04/14/2008 08:00 AM 59,904 atmarpc.sys
04/14/2008 08:00 AM 64,512 serial.sys
04/14/2008 08:00 AM 11,776 cpqdap01.sys
04/14/2008 08:00 AM 15,872 usbintel.sys
04/14/2008 08:00 AM 4,736 usbd.sys
04/14/2008 08:00 AM 32,128 usbccgp.sys
04/14/2008 08:00 AM 42,112 imapi.sys
04/14/2008 08:00 AM 11,008 sffp_sd.sys
04/14/2008 08:00 AM 25,728 usbcamd2.sys
04/14/2008 08:00 AM 36,352 intelppm.sys
04/14/2008 08:00 AM 36,608 ip6fw.sys
04/14/2008 08:00 AM 32,896 ipfltdrv.sys
04/14/2008 08:00 AM 20,864 ipinip.sys
04/14/2008 08:00 AM 152,832 ipnat.sys
04/14/2008 08:00 AM 75,264 ipsec.sys
04/14/2008 08:00 AM 11,264 irenum.sys
04/14/2008 08:00 AM 20,480 secdrv.sys
04/14/2008 08:00 AM 25,600 usbcamd.sys
04/14/2008 08:00 AM 31,360 atmepvc.sys
04/14/2008 08:00 AM 14,592 kbdhid.sys
04/14/2008 08:00 AM 384,768 update.sys
04/14/2008 08:00 AM 11,392 sfloppy.sys
04/14/2008 08:00 AM 66,048 udfs.sys
04/14/2008 08:00 AM 12,288 tunmp.sys
04/14/2008 08:00 AM 21,376 tsbvcap.sys
04/14/2008 08:00 AM 7,680 mcd.sys
04/14/2008 08:00 AM 63,744 mf.sys
04/14/2008 08:00 AM 4,224 mnmdd.sys
04/14/2008 08:00 AM 30,080 modem.sys
04/14/2008 08:00 AM 52,352 volsnap.sys
04/14/2008 08:00 AM 12,160 mouhid.sys
04/14/2008 08:00 AM 42,368 mountmgr.sys
04/14/2008 08:00 AM 14,592 smclib.sys
04/14/2008 08:00 AM 180,608 mrxdav.sys
04/14/2008 08:00 AM 51,712 tosdvd.sys
04/14/2008 08:00 AM 19,072 msfs.sys
04/14/2008 08:00 AM 35,072 msgpc.sys
04/14/2008 08:00 AM 21,896 tdtcp.sys
04/14/2008 08:00 AM 12,040 tdpipe.sys
04/14/2008 08:00 AM 19,072 tdi.sys
04/14/2008 08:00 AM 79,232 sdbus.sys
04/14/2008 08:00 AM 105,344 mup.sys
04/14/2008 08:00 AM 182,656 ndis.sys
04/14/2008 08:00 AM 10,112 ndistapi.sys
04/14/2008 08:00 AM 14,592 ndisuio.sys
04/14/2008 08:00 AM 91,520 ndiswan.sys
04/14/2008 08:00 AM 40,576 ndproxy.sys
04/14/2008 08:00 AM 34,688 netbios.sys
04/14/2008 08:00 AM 162,816 netbt.sys
04/14/2008 08:00 AM 61,824 nic1394.sys
04/14/2008 08:00 AM 12,032 nikedrv.sys
04/14/2008 08:00 AM 40,320 nmnt.sys
04/14/2008 08:00 AM 30,848 npfs.sys
04/14/2008 08:00 AM 574,976 ntfs.sys
04/14/2008 08:00 AM 2,944 null.sys
04/14/2008 08:00 AM 12,416 nwlnkflt.sys
04/14/2008 08:00 AM 32,512 nwlnkfwd.sys
04/14/2008 08:00 AM 88,320 nwlnkipx.sys
04/14/2008 08:00 AM 63,232 nwlnknb.sys
04/14/2008 08:00 AM 55,936 nwlnkspx.sys
04/14/2008 08:00 AM 3,456 oprghdlr.sys
04/14/2008 08:00 AM 42,752 p3.sys
04/14/2008 08:00 AM 80,128 parport.sys
04/14/2008 08:00 AM 19,712 partmgr.sys
04/14/2008 08:00 AM 6,784 parvdm.sys
04/14/2008 08:00 AM 96,384 scsiport.sys
04/14/2008 08:00 AM 25,344 sonydcam.sys
04/14/2008 08:00 AM 14,976 tape.sys
04/14/2008 08:00 AM 120,192 pcmcia.sys
04/14/2008 08:00 AM 71,552 bridge.sys
04/14/2008 08:00 AM 4,224 beep.sys
04/14/2008 08:00 AM 34,560 wanarp.sys
04/14/2008 08:00 AM 35,840 processr.sys
04/14/2008 08:00 AM 69,120 psched.sys
04/14/2008 08:00 AM 17,792 ptilink.sys
04/14/2008 08:00 AM 10,240 sffp_mmc.sys
04/14/2008 08:00 AM 11,904 sffdisk.sys
04/14/2008 08:00 AM 11,648 acpiec.sys
04/14/2008 08:00 AM 187,776 acpi.sys
04/14/2008 08:00 AM 55,808 atmlane.sys
04/14/2008 08:00 AM 8,832 rasacd.sys
04/14/2008 08:00 AM 51,328 rasl2tp.sys
04/14/2008 08:00 AM 41,472 raspppoe.sys
04/14/2008 08:00 AM 48,384 raspptp.sys
04/14/2008 08:00 AM 16,512 raspti.sys
04/14/2008 08:00 AM 34,432 rawwan.sys
04/14/2008 08:00 AM 175,744 rdbss.sys
04/14/2008 08:00 AM 4,224 rdpcdd.sys
04/14/2008 08:00 AM 4,352 wmilib.sys
04/14/2008 08:00 AM 139,656 rdpwd.sys
04/14/2008 08:00 AM 12,800 usb8023.sys
04/14/2008 08:00 AM 12,032 rio8drv.sys
04/14/2008 08:00 AM 12,032 riodrv.sys
04/14/2008 08:00 AM 352,256 atmuni.sys
04/14/2008 08:00 AM 30,592 rndismp.sys
04/14/2008 08:00 AM 5,888 rootmdm.sys
04/14/2008 08:00 AM 12,032 ws2ifsl.sys
04/14/2008 08:00 AM 73,472 sr.sys
04/14/2008 08:02 AM 196,224 rdpdr.sys
04/14/2008 08:06 AM 14,208 battc.sys
04/14/2008 08:06 AM 10,240 compbatt.sys
04/14/2008 08:06 AM 13,952 CmBatt.sys
04/14/2008 08:06 AM 42,368 AGP440.SYS
04/14/2008 08:06 AM 8,832 wmiacpi.sys
04/14/2008 08:06 AM 44,928 AGPCPQ.SYS
04/14/2008 08:06 AM 43,008 AMDAGP.SYS
04/14/2008 08:06 AM 42,752 ALIM1541.SYS
04/14/2008 08:06 AM 40,960 SISAGP.SYS
04/14/2008 08:06 AM 42,240 VIAAGP.SYS
04/14/2008 08:06 AM 37,248 isapnp.sys
04/14/2008 08:06 AM 68,224 pci.sys
04/14/2008 08:06 AM 15,488 mssmbios.sys
04/14/2008 08:09 AM 23,040 mouclass.sys
04/14/2008 08:09 AM 24,576 kbdclass.sys
04/14/2008 08:09 AM 5,376 MSPCLOCK.sys
04/14/2008 08:09 AM 4,992 MSPQM.sys
04/14/2008 08:09 AM 7,552 MSKSSRV.sys
04/14/2008 08:09 AM 4,352 swenum.sys
04/14/2008 08:10 AM 24,960 pciidex.sys
04/14/2008 08:10 AM 5,504 intelide.sys
04/14/2008 08:10 AM 96,512 atapi.sys
04/14/2008 08:10 AM 5,376 viaide.sys
04/14/2008 08:11 AM 18,560 i2omp.sys
04/14/2008 08:11 AM 8,576 i2omgmt.sys
04/14/2008 08:15 AM 52,864 DMusic.sys
04/14/2008 08:15 AM 6,272 splitter.sys
04/14/2008 08:15 AM 172,416 kmixer.sys
04/14/2008 08:15 AM 56,576 swmidi.sys
04/14/2008 08:15 AM 2,944 drmkaud.sys
04/14/2008 08:15 AM 49,408 stream.sys
04/14/2008 08:15 AM 60,160 drmk.sys
04/14/2008 08:15 AM 20,608 usbuhci.sys
04/14/2008 08:15 AM 59,520 usbhub.sys
04/14/2008 08:45 AM 60,800 sysaudio.sys
04/14/2008 08:46 AM 141,056 ks.sys
04/14/2008 08:47 AM 83,072 wdmaud.sys
04/14/2008 08:48 AM 52,480 i8042prt.sys
04/14/2008 08:49 AM 146,048 portcls.sys
04/14/2008 01:43 PM 40,840 termdd.sys
04/25/2008 09:34 AM disdn
05/08/2008 10:02 AM 203,136 rmcast.sys
06/13/2008 07:05 AM 272,128 bthport.sys
06/20/2008 07:51 AM 361,600 tcpip.sys
07/13/2008 07:59 PM 4,745,216 RtkHDAud.sys
07/13/2008 08:02 PM 93,968 jmcr.sys
07/13/2008 08:52 PM 5,854,752 igxpmp32.sys
07/13/2008 08:55 PM 106,368 Rtenicxp.sys
07/13/2008 11:02 PM 225,664 SynTP.sys
08/14/2008 06:04 AM 138,496 afd.sys
10/14/2008 11:48 PM 1,287,552 BCMWL5.SYS
03/18/2009 07:02 AM 144,000 usbport.sys
03/18/2009 07:02 AM 30,336 usbehci.sys
06/24/2009 07:18 AM 92,928 ksecdd.sys
10/20/2009 12:20 PM 265,728 http.sys
12/31/2009 12:50 PM 353,792 srv.sys
02/11/2010 08:02 AM 226,880 tcpip6.sys
02/24/2010 09:11 AM 455,680 mrxsmb.sys
04/12/2010 10:26 PM 3,653 1028_Dell_INS_910.mrk
04/29/2010 03:39 PM 20,952 mbam.sys
04/29/2010 03:39 PM 38,224 mbamswissarmy.sys
07/09/2010 09:14 PM etc
07/25/2010 09:34 PM .
07/25/2010 09:34 PM ..
242 File(s) 30,256,423 bytes
4 Dir(s) 510,996,480 bytes free


Virtual drives found?



Environment variables

ALLUSERSPROFILE=C:\Documents and Settings\All Users
APPDATA=C:\Documents and Settings\Miki\Application Data
CLIENTNAME=Console
CommonProgramFiles=C:\Program Files\Common Files
COMPUTERNAME=D2M92XF1
ComSpec=C:\WINDOWS\system32\cmd.exe
FP_NO_HOST_CHECK=NO
HOMEDRIVE=C:
HOMEPATH=\Documents and Settings\Miki
LOGONSERVER=\\D2M92XF1
NUMBER_OF_PROCESSORS=2
OS=Windows_NT
Path=C:\WINDOWS\system32;C:\WINDOWS;C:\WINDOWS\system32\wbem;C:\WINDOWS\system32\WindowsPowerShell\v1.0
PATHEXT=.COM;.EXE;.BAT;.CMD;.VBS;.VBE;.JS;.JSE;.WSF;.WSH;.PSC1
PROCESSOR_ARCHITECTURE=x86
PROCESSOR_IDENTIFIER=x86 Family 6 Model 28 Stepping 2, GenuineIntel
PROCESSOR_LEVEL=6
PROCESSOR_REVISION=1c02
ProgramFiles=C:\Program Files
PROMPT=$P$G
PSModulePath=C:\WINDOWS\system32\WindowsPowerShell\v1.0\Modules\
SESSIONNAME=Console
SystemDrive=C:
SystemRoot=C:\WINDOWS
TEMP=C:\DOCUME~1\Miki\LOCALS~1\Temp
TMP=C:\DOCUME~1\Miki\LOCALS~1\Temp
USERDOMAIN=D2M92XF1
USERNAME=Miki
USERPROFILE=C:\Documents and Settings\Miki
windir=C:\WINDOWS
__COMPAT_LAYER=EnableNXShowUI


Stealth malware?


Internet Explorer


! REG.EXE VERSION 3.0

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Main
Default_Page_URL REG_SZ http://go.microsoft.com/fwlink/?LinkId=69157
Default_Search_URL REG_SZ http://go.microsoft.com/fwlink/?LinkId=54896
Search Page REG_SZ http://go.microsoft.com/fwlink/?LinkId=54896
Enable_Disk_Cache REG_SZ yes
Cache_Percent_of_Disk REG_BINARY 0A000000
Delete_Temp_Files_On_Exit REG_SZ yes
Local Page REG_SZ C:\WINDOWS\system32\blank.htm
Anchor_Visitation_Horizon REG_BINARY 01000000
Use_Async_DNS REG_SZ yes
Placeholder_Width REG_BINARY 1A000000
Placeholder_Height REG_BINARY 1A000000
Start Page REG_SZ http://go.microsoft.com/fwlink/?LinkId=69157
CompanyName REG_SZ Microsoft Corporation
Custom_Key REG_SZ MICROSO
Wizard_Version REG_SZ 6.0.2600.0000
FullScreen REG_SZ no
Default_Secondary_Page_URL REG_MULTI_SZ \0
Extensions Off Page REG_SZ about:NoAdd-ons
Security Risk Page REG_SZ about:SecurityRisk
Check_Associations REG_SZ yes
StatusBarWeb REG_DWORD 0x1
SearchControlWidth REG_DWORD 0x12c
ForceGDIPlus REG_DWORD 0x0
DEPOff REG_DWORD 0x0
MaxRenderLine REG_DWORD 0xfa0
UseClearType REG_SZ yes
Page_Transitions REG_DWORD 0x1
Use_DlgBox_Colors REG_SZ yes
Anchor Underline REG_SZ yes
Display Inline Images REG_SZ yes
Display Inline Videos REG_DWORD 0x1
Play_Background_Sounds REG_SZ yes
Play_Animations REG_SZ yes
Print_Background REG_SZ no
SmoothScroll REG_DWORD 0x1
XMLHTTP REG_DWORD 0x1
Show image placeholders REG_DWORD 0x0
Disable Script Debugger REG_SZ yes
Enable AutoImageResize REG_SZ yes
XDomainRequest REG_DWORD 0x1
DOMStorage REG_DWORD 0x1
IE8RunOnceLastShown REG_DWORD 0x0
IE8RunOncePerInstallCompleted REG_DWORD 0x0
IE8TourNoShow REG_DWORD 0x0
IE8TourShown REG_DWORD 0x0
FrameTabWindow REG_DWORD 0x1
AdminTabProcs REG_DWORD 0x1
SessionMerging REG_DWORD 0x1
FrameMerging REG_DWORD 0x1
HangResistantFrame REG_DWORD 0x0
TabShutdownDelay REG_DWORD 0xea60
FrameShutdownDelay REG_DWORD 0x0

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Main\ErrorThresholds

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Main\UrlTemplate

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Main\WindowsSearch

! REG.EXE VERSION 3.0

HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings
User Agent REG_SZ Mozilla/4.0 (compatible; MSIE 8.0; Win32)
IE5_UA_Backup_Flag REG_SZ 5.0
NoNetAutodial REG_DWORD 0x0
MigrateProxy REG_DWORD 0x1
EmailName REG_SZ IEUser@
AutoConfigProxy REG_SZ wininet.dll
MimeExclusionListForCache REG_SZ multipart/mixed multipart/x-mixed-replace multipart/x-byteranges
WarnOnPost REG_BINARY 01000000
UseSchannelDirectly REG_BINARY 01000000
EnableHttp1_1 REG_DWORD 0x1
PrivacyAdvanced REG_DWORD 0x0
EnableNegotiate REG_DWORD 0x1
ProxyEnable REG_DWORD 0x0
WarnOnZoneCrossing REG_DWORD 0x0
PrivDiscUiShown REG_DWORD 0x1
UrlEncoding REG_DWORD 0x0
SecureProtocols REG_DWORD 0xa0
ZonesSecurityUpgrade REG_BINARY 86710C8D7BDBCA01
DisableCachingOfSSLPages REG_DWORD 0x0
EnableAutodial REG_DWORD 0x0
ProxyHttp1.1 REG_DWORD 0x1
EnablePunycode REG_DWORD 0x1
ShowPunycode REG_DWORD 0x0
CreateUriCacheSize REG_DWORD 0x50
CoInternetCombineIUriCacheSize REG_DWORD 0x50
SecurityIdIUriCacheSize REG_DWORD 0x1e
SpecialFoldersCacheSize REG_DWORD 0x8
WarnOnIntranet REG_DWORD 0x1
WarnonBadCertRecving REG_DWORD 0x0
WarnOnPostRedirect REG_DWORD 0x0
WarnOnHTTPSToHTTPRedirect REG_DWORD 0x1
ProxyServer REG_SZ http=127.0.0.1:5643
ProxyOverride REG_SZ

HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0

HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Activities

HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Cache

HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Connections

HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Http Filters

HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Lockdown_Zones

HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\P3P

HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Passport

HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Protocols

HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\TemplatePolicies

HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Url History

HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap

HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones

! REG.EXE VERSION 3.0

HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\Main
NoUpdateCheck REG_DWORD 0x1
Disable Script Debugger REG_SZ yes
Anchor Underline REG_SZ yes
Cache_Update_Frequency REG_SZ Once_Per_Session
Display Inline Images REG_SZ yes
Do404Search REG_BINARY 01000000
Local Page REG_SZ C:\WINDOWS\system32\blank.htm
Save_Session_History_On_Exit REG_SZ no
Show_FullURL REG_SZ no
Show_StatusBar REG_SZ yes
Show_ToolBar REG_SZ yes
Show_URLinStatusBar REG_SZ yes
Show_URLToolBar REG_SZ yes
Start Page REG_SZ http://www.yahoo.com/
Use_DlgBox_Colors REG_SZ yes
Search Page REG_SZ http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
XMLHTTP REG_DWORD 0x1
UseClearType REG_SZ yes
Enable Browser Extensions REG_SZ yes
Play_Background_Sounds REG_SZ yes
Play_Animations REG_SZ yes
IE8TourShown REG_DWORD 0x0
IE8TourShownTime REG_BINARY 88C8BD6BA705CD01
SearchDefaultBranded REG_DWORD 0x1
IE8TourNoShow REG_DWORD 0x1
IE8RunOnceLastShown REG_DWORD 0x1
StatusBarWeb REG_DWORD 0x1
SearchControlWidth REG_DWORD 0x12c
ForceGDIPlus REG_DWORD 0x0
SuppressScriptDebuggerDialog REG_DWORD 0x0
Page_Transitions REG_DWORD 0x1
CSS_Compat REG_SZ doctype
Expand Alt Text REG_SZ no
Display Inline Videos REG_DWORD 0x1
Print_Background REG_SZ no
Use Stylesheets REG_DWORD 0x1
SmoothScroll REG_DWORD 0x1
Show image placeholders REG_DWORD 0x0
DisableScriptDebuggerIE REG_SZ yes
Move System Caret REG_SZ no
Force Offscreen Composition REG_DWORD 0x0
Enable AutoImageResize REG_SZ yes
UseThemes REG_DWORD 0x1
UseHR REG_DWORD 0x0
Q300829 REG_DWORD 0x0
Cleanup HTCs REG_DWORD 0x0
XDomainRequest REG_DWORD 0x1
DOMStorage REG_DWORD 0x1
IE8RunOncePerInstallCompleted REG_DWORD 0x0
FrameTabWindow REG_DWORD 0x1
AdminTabProcs REG_DWORD 0x1
SessionMerging REG_DWORD 0x1
FrameMerging REG_DWORD 0x1
HangResistantFrame REG_DWORD 0x0
TabShutdownDelay REG_DWORD 0xea60
FrameShutdownDelay REG_DWORD 0x0
IE8RunOnceCompletionTime REG_BINARY 747D3289012ACB01
TabProcGrowth REG_DWORD 0x0
Window Title REG_SZ Windows Internet Explorer provided by Yahoo!
CompatibilityFlags REG_DWORD 0x0
FullScreen REG_SZ no
Window_Placement REG_BINARY 2C0000000000000001000000FFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFF7E000000000000009E03000036020000
IE8RunOnceLastShown_TIMESTAMP REG_BINARY 6EA1120D2831CB01
NotifyDownloadComplete REG_SZ yes

HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\Main\Default Feeds

HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl

HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\Main\Touch

HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\Main\WindowsSearch

! REG.EXE VERSION 3.0

HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Search
SearchAssistant REG_SZ http://ie.search.msn.com/{SUB_RFC1766}/srchasst/srchasst.htm
CustomizeSearch REG_SZ http://ie.search.msn.com/{SUB_RFC1766}/srchasst/srchcust.htm
Default_Search_URL REG_SZ

! REG.EXE VERSION 3.0

HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\URLSearchHooks
{CFBFAE00-17A6-11D0-99CB-00C04FD64497} REG_SZ

! REG.EXE VERSION 3.0

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{02478D38-C3F9-4efb-9B51-7695ECA05670}

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{0347C33E-8762-4905-BF09-768834316C61}

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{18DF081C-E8AD-4283-A596-FA578C2EBDC3}

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{E7E6F031-17CE-4C07-BC86-EABFE594F69C}

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{FDAD4DA1-61A2-4FD8-9C17-86F7AC245081}

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{FFFFFFFF-CF4E-4F2B-BDC2-0E72E116A856}

! REG.EXE VERSION 3.0

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar
{EF99BD32-C1FB-11D2-892F-0090271D4F88} REG_BINARY 00
Locked REG_DWORD 0x1

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar\QuickComplete

! REG.EXE VERSION 3.0

HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\MenuExt


Protocol hijack?



Security Center


! REG.EXE VERSION 3.0

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center
FirstRunDisabled REG_DWORD 0x1
AntiVirusDisableNotify REG_DWORD 0x0
FirewallDisableNotify REG_DWORD 0x0
UpdatesDisableNotify REG_DWORD 0x0
AntiVirusOverride REG_DWORD 0x0
FirewallOverride REG_DWORD 0x0

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring

! REG.EXE VERSION 3.0

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\AhnlabAntiVirus

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ComputerAssociatesAntiVirus

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\KasperskyAntiVirus

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeAntiVirus

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeFirewall

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaAntiVirus

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaFirewall

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SophosAntiVirus

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecAntiVirus

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecFirewall

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TinyFirewall

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendAntiVirus

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendFirewall

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ZoneLabsFirewall

! REG.EXE VERSION 3.0

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications

! REG.EXE VERSION 3.0

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts

! REG.EXE VERSION 3.0

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List
%windir%\Network Diagnostic\xpnetdiag.exe REG_SZ %windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000
%windir%\system32\sessmgr.exe REG_SZ %windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019
C:\Program Files\Messenger\msmsgs.exe REG_SZ C:\Program Files\Messenger\msmsgs.exe:*:Enabled:Windows Messenger
C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe REG_SZ C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe:*:Enabled:hpqtra08.exe
C:\Program Files\HP\Digital Imaging\bin\hpqste08.exe REG_SZ C:\Program Files\HP\Digital Imaging\bin\hpqste08.exe:*:Enabled:hpqste08.exe
C:\Program Files\HP\Digital Imaging\bin\hposid01.exe REG_SZ C:\Program Files\HP\Digital Imaging\bin\hposid01.exe:*:Enabled:hposid01.exe
C:\Program Files\HP\Digital Imaging\bin\hpiscnapp.exe REG_SZ C:\Program Files\HP\Digital Imaging\bin\hpiscnapp.exe:*:Enabled:hpiscnapp.exe
C:\Program Files\HP\Digital Imaging\bin\hpqkygrp.exe REG_SZ C:\Program Files\HP\Digital Imaging\bin\hpqkygrp.exe:*:Enabled:hpqkygrp.exe


Uninstall List


! REG.EXE VERSION 3.0

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\7-Zip

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\AddressBook

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Adobe AIR

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Adobe Flash Player ActiveX

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Adobe Shockwave Player

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Branding

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\com.adobe.mauby.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Connection Manager

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\DirectAnimation

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\DirectDrawEx

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\DXM_Runtime

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\ESET Online Scanner

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Fontcore

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\HDMI

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\HP Imaging Device Functions

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\HP Photosmart Essential

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\HP Smart Web Printing

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\HP Solution Center & Imaging Support Tools

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\HPExtendedCapabilities

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\ICW

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\IDNMitigationAPIs

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\IE40

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\IE4Data

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\IE5BAKEX

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\ie7

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\ie8

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\IEData

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\InstallShield Uninstall Information

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\InstallShield_{065A7AFE-195D-4DFB-A4B2-A83842C0F79F}

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\InstallShield_{543A4F31-9590-416A-A621-42CEB4C6A694}

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\InstallShield_{FEF06E73-A519-4510-8CF3-B66041B91D8A}

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\KB2229593

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\KB898461

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\KB923561

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\KB938464-v2

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\KB946648

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\KB950762

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\KB950974

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\KB951066

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\KB951376-v2

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\KB951618-v2

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\KB951748

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\KB951978

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\KB952004

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\KB952069_WM9

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\KB952287

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\KB952954

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\KB953955

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\KB954155_WM9

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\KB954434

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\KB954459

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\KB954550-v5

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\KB954600

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\KB955069

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\KB955759

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\KB956572

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\KB956744

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\KB956802

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\KB956803

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\KB956844

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\KB957097

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\KB958644

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\KB958687

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\KB958690

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\KB958869

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\KB959252

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\KB959426

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\KB960225

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\KB960803

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\KB960859

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\KB961118

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\KB961371-v2

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\KB961373

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\KB961501

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\KB963027

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\KB967715

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\KB968389

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\KB968537

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\KB968764

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\KB968816_WM9

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\KB968930

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\KB969059

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\KB969084

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\KB969897

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\KB969898

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\KB969947

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\KB970238

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\KB970430

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\KB971468

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\KB971486

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\KB971557

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\KB971633

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\KB971657

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\KB971737

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\KB971961

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\KB971961-IE8

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\KB972260

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\KB972270

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\KB973346

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\KB973354

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\KB973507

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\KB973525

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\KB973540_WM9

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\KB973687

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\KB973815

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\KB973869

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\KB973904

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\KB974112

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\KB974318

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\KB974392

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\KB974571

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\KB975025

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\KB975467

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\KB975560

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\KB975561

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\KB975562

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\KB975713

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\KB976098-v2

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\KB976662-IE8

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\KB977816

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\KB977914

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\KB978037

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\KB978262

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\KB978338

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\KB978542

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\KB978601

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\KB978695_WM9

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\KB978706

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\KB979306

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\KB979309

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\KB979402_WM9

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\KB979482

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\KB979559

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\KB979683

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\KB980182-IE8

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\KB980195

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\KB980218

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\KB980232

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\KB980302-IE8

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\KB981332-IE8

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\KB981793

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\KB982381-IE8

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\M979906

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Malwarebytes' Anti-Malware_is1

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Microsoft .NET Framework 1.1 (1033)

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Microsoft .NET Framework 3.5 SP1

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\MobileOptionPack

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\MPlayer2

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\NetMeeting

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\NLSDownlevelMapping

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\OutlookExpress

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\PCHealth

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\SchedulingAgent

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Shop for HP Supplies

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\SynTPDeinstKey

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Wdf01000

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Wdf01001

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Wdf01005

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\WIC

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\XpsEPSC

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Yahoo! Companion

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Yahoo! Software Update

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Yahoo! Toolbar

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{065A7AFE-195D-4DFB-A4B2-A83842C0F79F}

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{0F7C2E47-089E-4d23-B9F7-39BE00100776}

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{11B83AD3-7A46-4C2E-A568-9505981D4C6F}

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{18669FF9-C8FE-407a-9F70-E674896B1DB4}

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{26A24AE4-039D-4CA4-87B4-2F83216017FF}

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{26A24AE4-039D-4CA4-87B4-2F83216021FB}

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{3248F0A8-6813-11D6-A77B-00B0D0160050}

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{34BFB099-07B2-4E95-A673-7362D60866A2}

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{350C97B0-3D7C-4EE8-BAA9-00BCB3D54227}

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{36FDBE6E-6684-462b-AE98-9A39A1B200CC}

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{4A03706F-666A-4037-7777-5F2748764D10}

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{5109C064-813E-4e87-B0DE-C8AF7B5BC02B}

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{52A69E11-7CEB-4a7d-9607-68BA4F39A89B}

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{543A4F31-9590-416A-A621-42CEB4C6A694}

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{5A710547-B58E-488B-828D-CA9A25A0533C}

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{5ACE69F0-A3E8-44eb-88C1-0A841E700180}

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{66E6CE0C-5A1E-430C-B40A-0C90FF1804A8}

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{687FEF8A-8597-40b4-832C-297EA3F35817}

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{6F5E2F4A-377D-4700-B0E3-8F7F7507EA15}

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{7988ba74-4a27-4685-991a-53f072f22808}

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{80533B67-C407-485D-8B5D-63BB8ED9D878}

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{859DFA95-E4A6-48CD-B88E-A3E483E89B44}

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{86493ADD-824D-4B8E-BD72-8C5DCDC52A71}

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{8A85DEAD-7C1F-4368-881C-72AC74CB2E91}

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{91110409-6000-11D3-8CFE-0050048383C9}

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{A0B9F8DF-C949-45ed-9808-7DC5C0C19C81}

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{A2BCA9F1-566C-4805-97D1-7FDC93386723}

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{A3051CD0-2F64-3813-A88D-B8DCCDE8F8C7}

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{A3051CD0-2F64-3813-A88D-B8DCCDE8F8C7}.KB300003

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{A3051CD0-2F64-3813-A88D-B8DCCDE8F8C7}.KB958483

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{A3051CD0-2F64-3813-A88D-B8DCCDE8F8C7}.KB960043

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{A3051CD0-2F64-3813-A88D-B8DCCDE8F8C7}.KB975195

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{A3051CD0-2F64-3813-A88D-B8DCCDE8F8C7}.KB976570

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{A3051CD0-2F64-3813-A88D-B8DCCDE8F8C7}.KB976578

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{A3051CD0-2F64-3813-A88D-B8DCCDE8F8C7}.KB976578v2

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{A3051CD0-2F64-3813-A88D-B8DCCDE8F8C7}.KB976769

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{A3051CD0-2F64-3813-A88D-B8DCCDE8F8C7}.KB976769v2

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{A3051CD0-2F64-3813-A88D-B8DCCDE8F8C7}.KB977354

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{A3051CD0-2F64-3813-A88D-B8DCCDE8F8C7}.KB977354v2

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{A5AB9D5E-52E2-440e-A3ED-9512E253C81A}

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{AB5D51AE-EBC3-438D-872C-705C7C2084B0}

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{AC76BA86-7AD7-1033-7B44-A93000000001}

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{B8DBED1E-8BC3-4d08-B94A-F9D7D88E9BBF}

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{BAD0FA60-09CF-4411-AE6A-C2844C8812FA}

63 Re: Malware problems and Internet Redirecting on Sun Aug 01, 2010 10:41 am

blink711


Member
Member
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{BAF78226-3200-4DB4-BE33-4D922A799840}

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{BB8B979E-E336-47E7-96BC-1031C1B94561}

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{C09FB3CD-3D0C-3F2D-899A-6A1D67F2073F}

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{C09FB3CD-3D0C-3F2D-899A-6A1D67F2073F}.KB200003

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{C09FB3CD-3D0C-3F2D-899A-6A1D67F2073F}.KB431780

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{C09FB3CD-3D0C-3F2D-899A-6A1D67F2073F}.KB946922

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{C09FB3CD-3D0C-3F2D-899A-6A1D67F2073F}.KB947748

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{C09FB3CD-3D0C-3F2D-899A-6A1D67F2073F}.KB949272

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{C09FB3CD-3D0C-3F2D-899A-6A1D67F2073F}.KB952137

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{C09FB3CD-3D0C-3F2D-899A-6A1D67F2073F}.KB952677

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{C09FB3CD-3D0C-3F2D-899A-6A1D67F2073F}.KB953300

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{C09FB3CD-3D0C-3F2D-899A-6A1D67F2073F}.KB953990

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{C09FB3CD-3D0C-3F2D-899A-6A1D67F2073F}.KB954832

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{C09FB3CD-3D0C-3F2D-899A-6A1D67F2073F}.KB956860

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{C09FB3CD-3D0C-3F2D-899A-6A1D67F2073F}.KB957541

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{C09FB3CD-3D0C-3F2D-899A-6A1D67F2073F}.KB957542

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{C09FB3CD-3D0C-3F2D-899A-6A1D67F2073F}.KB957543

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{C09FB3CD-3D0C-3F2D-899A-6A1D67F2073F}.KB958129

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{C09FB3CD-3D0C-3F2D-899A-6A1D67F2073F}.KB958481

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{C09FB3CD-3D0C-3F2D-899A-6A1D67F2073F}.KB960043

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{C09FB3CD-3D0C-3F2D-899A-6A1D67F2073F}.KB971111

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{C09FB3CD-3D0C-3F2D-899A-6A1D67F2073F}.KB974417

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{C09FB3CD-3D0C-3F2D-899A-6A1D67F2073F}.KB976569

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{C09FB3CD-3D0C-3F2D-899A-6A1D67F2073F}.KB976576

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{C09FB3CD-3D0C-3F2D-899A-6A1D67F2073F}.KB976765v2

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{C09FB3CD-3D0C-3F2D-899A-6A1D67F2073F}.KB979909

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{C09FB3CD-3D0C-3F2D-899A-6A1D67F2073F}.KB980773

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{c6922d7f-c698-4d9e-9671-8b3de04d1511}

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1}

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{CCB9B81A-167F-4832-B305-D2A0430840B3}

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}.KB350003

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}.KB953595

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}.KB958484

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}.KB960043

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}.KB963707

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{D2E0F0CC-6BE0-490b-B08B-9267083E34C9}

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{D77D43B5-ED55-426b-B67B-E21F804F6102}

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{D99A8E3A-AE5A-4692-8B19-6F16D454E240}

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{db18dc72-cd20-4801-be82-f5d2caeec4d7}

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{E08DC77E-D09A-4e36-8067-D6DBBCC5F8DC}

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{E1E502E2-C006-49DB-9C0C-F2196E51826F}_is1

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{e97a9fd7-2fa1-4474-820d-3f8893a5b78a}

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{eca3039b-e429-420f-bd5e-7dec0683fc32}

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{F1E63043-54FC-429B-AB2C-31AF9FBA4BC7}

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{F42CD69D-E393-47c8-B2CD-B139C4ADA9A8}

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{F662A8E6-F4DC-41A2-901E-8C11F044BDEC}

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{F8131A35-47FD-27AD-116D-0E79AF5DE5EE}

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{FEF06E73-A519-4510-8CF3-B66041B91D8A}


Adobe Products


! REG.EXE VERSION 3.0

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Adobe Flash Player ActiveX
DisplayName REG_SZ Adobe Flash Player 10 ActiveX
DisplayVersion REG_SZ 10.0.45.2
Publisher REG_SZ Adobe Systems Incorporated
URLInfoAbout REG_SZ http://www.adobe.com/go/getflashplayer
VersionMajor REG_SZ 10
VersionMinor REG_SZ 0
HelpLink REG_SZ http://www.adobe.com/go/flashplayer_support/
URLUpdateInfo REG_SZ http://www.adobe.com/go/flashplayer/
DisplayIcon REG_SZ C:\WINDOWS\system32\Macromed\Flash\uninstall_activeX.exe
UninstallString REG_SZ C:\WINDOWS\system32\Macromed\Flash\uninstall_activeX.exe
RequiresIESysFile REG_SZ 4.70.0.1155
NoModify REG_DWORD 0x1
NoRepair REG_DWORD 0x1

! REG.EXE VERSION 3.0

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Adobe Shockwave Player
DisplayName REG_SZ Adobe Shockwave Player 11.5
UninstallString REG_SZ "C:\WINDOWS\system32\Adobe\Shockwave 11\uninstaller.exe"
DisplayIcon REG_SZ C:\WINDOWS\system32\Adobe\Shockwave 11\SwInit.exe,0
DisplayVersion REG_SZ 11.5.7.609
HelpLink REG_SZ http://www.adobe.com/support/shockwave
InstallLocation REG_SZ C:\WINDOWS\system32\Adobe
Publisher REG_SZ Adobe Systems, Inc.
URLInfoAbout REG_SZ http://www.adobe.com
URLUpdateInfo REG_SZ http://www.adobe.com/software/shockwaveplayer/index.html
VersionMajor REG_DWORD 0xb
VersionMinor REG_DWORD 0x1


Autorun


! REG.EXE VERSION 3.0

HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run
ctfmon.exe REG_SZ C:\WINDOWS\system32\ctfmon.exe
{718CD684-A8A6-7A2C-D198-D99178C59E7C} REG_SZ "C:\Documents and Settings\Miki\Application Data\Ucum\hiubi.exe"

! REG.EXE VERSION 3.0

HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run
SynTPEnh REG_SZ C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
RTHDCPL REG_SZ RTHDCPL.EXE
IgfxTray REG_SZ C:\WINDOWS\system32\igfxtray.exe
HotKeysCmds REG_SZ C:\WINDOWS\system32\hkcmd.exe
Persistence REG_SZ C:\WINDOWS\system32\igfxpers.exe
SunJavaUpdateSched REG_SZ "C:\Program Files\Common Files\Java\Java Update\jusched.exe"
BTMeter REG_SZ C:\Program Files\Battery Meter\BTMeter.exe
WLSS REG_SZ C:\Program Files\Wireless Select Switch\WLSS.exe
Adobe Reader Speed Launcher REG_SZ "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
Adobe ARM REG_SZ "C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
HP Software Update REG_SZ C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
hpqSRMon REG_SZ C:\Program Files\HP\Digital Imaging\bin\hpqSRMon.exe
Malwarebytes Anti-Malware (rootkit-scan) REG_SZ "C:\Program Files\Malwarebytes' Anti-Malware\mbam.exe" /runcleanupscript

HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\OptionalComponents


Restrictions - Internet Explorer


! REG.EXE VERSION 3.0

HKEY_CURRENT_USER\Software\Policies\Microsoft\Internet Explorer\Control Panel


Restrictions - REGEDIT


! REG.EXE VERSION 3.0

HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\System
DisableTaskMgr REG_DWORD 0x0
DisableRegistryTools REG_DWORD 0x0


Restrictions - Explorer


! REG.EXE VERSION 3.0

HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer
NoDriveTypeAutoRun REG_DWORD 0x143
NoDriveAutoRun REG_DWORD 0x3ffffff
NoDrives REG_DWORD 0x0

HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run


DNS Settings


! REG.EXE VERSION 3.0

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\Interfaces

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{2AB89AEA-F66F-4554-A2E8-E2309AC0E8E0}

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{6BEA9291-D85C-4ECE-98FB-9F4B997E4C65}

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{A6DF4A73-5DB7-4686-A12C-705E7A5217AA}

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{D3C74EDD-147E-4BE0-AC63-15DD40D9A265}


Windows IP Configuration



Host Name . . . . . . . . . . . . : D2M92XF1

Primary Dns Suffix . . . . . . . :

Node Type . . . . . . . . . . . . : Unknown

IP Routing Enabled. . . . . . . . : No

WINS Proxy Enabled. . . . . . . . : No

DNS Suffix Search List. . . . . . : Fiona



Ethernet adapter Local Area Connection:



Media State . . . . . . . . . . . : Media disconnected

Description . . . . . . . . . . . : Realtek RTL8102E Family PCI-E Fast Ethernet NIC

Physical Address. . . . . . . . . : 00-21-70-C8-9C-1C



Ethernet adapter Wireless Network Connection:



Connection-specific DNS Suffix . : Fiona

Description . . . . . . . . . . . : Broadcom 802.11g Network Adapter

Physical Address. . . . . . . . . : 00-23-08-1E-2D-23

Dhcp Enabled. . . . . . . . . . . : Yes

Autoconfiguration Enabled . . . . : Yes

IP Address. . . . . . . . . . . . : 192.168.2.4

Subnet Mask . . . . . . . . . . . : 255.255.255.0

Default Gateway . . . . . . . . . : 192.168.2.1

DHCP Server . . . . . . . . . . . : 192.168.2.1

DNS Servers . . . . . . . . . . . : 192.168.2.1

Lease Obtained. . . . . . . . . . : Sunday, August 01, 2010 10:36:43 AM

Lease Expires . . . . . . . . . . : Monday, January 18, 2038 11:14:07 PM



AppInit DLLs


! REG.EXE VERSION 3.0

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows



Shell Service Object Delay Load


! REG.EXE VERSION 3.0

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad
PostBootReminder REG_SZ {7849596a-48ea-486e-8937-a2a3009f31a9}
CDBurn REG_SZ {fbeb8a05-beee-4442-804e-409d6c4515e9}
WebCheck REG_SZ {E6FB5E20-DE35-11CF-9C87-00AA005127ED}
SysTray REG_SZ {35CEC8A3-2BE6-11D2-8773-92E220524153}



Shell Execute Hooks


! REG.EXE VERSION 3.0

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks
{AEB6717E-7E19-11d0-97EE-00C04FD91972} REG_SZ


Image File Execution Options


! REG.EXE VERSION 3.0

HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options

HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\apitrap.dll

HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\ASSTE.dll

HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\AVSTE.dll

HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\Cleanup.dll

HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\cqw32.exe

HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\divx.dll

HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\divxdec.ax

HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\DJSMAR00.dll

HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\DRMINST.dll

HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\enc98.EXE

HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\EncodeDivXExt.dll

HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\EncryptPatchVer.dll

HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\front.exe

HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\fullsoft.dll

HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\GBROWSER.DLL

HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\htmlmarq.ocx

HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\htmlmm.ocx

HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\install.exe

HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\ishscan.dll

HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\ISSTE.dll

HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\javai.dll

HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\jvm.dll

HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\jvm_g.dll

HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\main123w.dll

HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\mngreg32.exe

HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\msci_uno.dll

HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\mscoree.dll

HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\mscorsvr.dll

HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\mscorwks.dll

HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\msjava.dll

HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\mso.dll

HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\NAVOPTRF.dll

HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\NeVideoFX.dll

HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\NPMLIC.dll

HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\NSWSTE.dll

HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\photohse.EXE

HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\PMSTE.dll

HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\ppw32hlp.dll

HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\printhse.EXE

HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\prwin8.EXE

HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\ps80.EXE

HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\psdmt.exe

HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\qfinder.EXE

HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\qpw.EXE

HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\salwrap.dll

HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\setup.exe

HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\setup32.dll

HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\sevinst.exe

HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\symlcnet.dll

HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\tcore_ebook.dll

HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\TFDTCTT8.DLL

HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\ua80.EXE

HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\udtapi.dll

HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\ums.dll

HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\vb40032.dll

HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\vbe6.dll

HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\wpwin8.EXE

HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\xlmlEN.dll

HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\xwsetup.EXE

HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\Your Image File Name Here without a path

HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\_INSTPGM.EXE


Security Providers



Local Security Authority


! REG.EXE VERSION 3.0

HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa
Authentication Packages REG_MULTI_SZ msv1_0\0\0
Bounds REG_BINARY 0030000000200000
Security Packages REG_MULTI_SZ kerberos\0msv1_0\0schannel\0wdigest\0\0
ImpersonatePrivilegeUpgradeToolHasRun REG_DWORD 0x1
LsaPid REG_DWORD 0x37c
SecureBoot REG_DWORD 0x1
auditbaseobjects REG_DWORD 0x0
crashonauditfail REG_DWORD 0x0
disabledomaincreds REG_DWORD 0x0
everyoneincludesanonymous REG_DWORD 0x0
fipsalgorithmpolicy REG_DWORD 0x0
forceguest REG_DWORD 0x1
fullprivilegeauditing REG_BINARY 00
limitblankpassworduse REG_DWORD 0x1
lmcompatibilitylevel REG_DWORD 0x0
nodefaultadminowner REG_DWORD 0x1
nolmhash REG_DWORD 0x0
restrictanonymous REG_DWORD 0x0
restrictanonymoussam REG_DWORD 0x1
Notification Packages REG_MULTI_SZ scecli\0\0
enabledcom REG_SZ y

HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa\AccessProviders

HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa\Audit

HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa\Data

HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa\GBG

HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa\JD

HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa\Kerberos

HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa\msv1_0

HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa\Skew1

HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa\SSO

HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa\SspiCache


AppCert DLLs



App Paths


! REG.EXE VERSION 3.0

HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\app paths

HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\app paths\7zFM.exe
REG_SZ C:\Program Files\7-Zip\7zFM.exe
Path REG_SZ C:\Program Files\7-Zip

HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\app paths\AcroRd32.exe
REG_SZ C:\Program Files\Adobe\Reader 9.0\Reader\AcroRd32.exe
Path REG_SZ C:\Program Files\Adobe\Reader 9.0\Reader\

HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\app paths\bckgzm.exe
REG_SZ C:\Program Files\MSN Gaming Zone\Windows\bckgzm.exe

HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\app paths\chkrzm.exe
REG_SZ C:\Program Files\MSN Gaming Zone\Windows\chkrzm.exe

HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\app paths\cmmgr32.exe
REG_SZ C:\WINDOWS\system32\cmmgr32.exe
Path REG_SZ C:\WINDOWS\system32
CmstpExtensionDll REG_SZ C:\WINDOWS\system32\cmcfg32.dll
CMInternalVersion REG_SZ 1.2
CmNative REG_DWORD 0x1
ProfilesUpgraded REG_DWORD 0x1

HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\app paths\combofix.exe
REG_SZ C:\DOCUME~1\Miki\Desktop\MALWAR~1\ComboFix.exe

HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\app paths\CONF.EXE
REG_SZ C:\Program Files\NetMeeting\conf.exe
Path REG_SZ C:\Program Files\NetMeeting;

HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\app paths\dialer.exe
REG_SZ C:\Program Files\Windows NT\dialer.exe

HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\app paths\Excel.exe
REG_SZ C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE
Path REG_SZ C:\Program Files\Microsoft Office\Office10\
useURL REG_SZ 1
SaveURL REG_SZ 1

HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\app paths\HELPCTR.EXE
REG_EXPAND_SZ %Systemroot%\PCHealth\HelpCtr\Binaries\HelpCtr.exe

HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\app paths\HpqApKil.exe
Path REG_SZ C:\Program Files\HP\Digital Imaging\bin\
REG_SZ C:\Program Files\HP\Digital Imaging\bin\HpqApKil.exe

HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\app paths\HpqPSApl.exe
Path REG_SZ C:\Program Files\HP\Digital Imaging\bin\;C:\Program Files\Common Files\HP\Digital Imaging\bin
REG_SZ C:\Program Files\HP\Digital Imaging\bin\HpqPSApl.exe

HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\app paths\hpqpsapp.exe
Path REG_SZ C:\Program Files\Common Files\HP\Digital Imaging\bin
REG_SZ C:\Program Files\HP\Digital Imaging\bin\hpqpsapp.exe

HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\app paths\hpqpse.exe
REG_SZ C:\Program Files\HP\Digital Imaging\Bin\hpqpse.exe
Path REG_SZ C:\Program Files\HP\Digital Imaging\Bin\;C:\Program Files\Common Files\HP\Digital Imaging\Bin

HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\app paths\hpqqpawp.exe
Path REG_SZ C:\Program Files\Common Files\HP\Digital Imaging\Bin
REG_SZ C:\Program Files\HP\Digital Imaging\Bin\hpqqpawp.exe

HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\app paths\HpqSRmon.exe
Path REG_SZ C:\Program Files\HP\Digital Imaging\bin\
REG_SZ C:\Program Files\HP\Digital Imaging\bin\HpqSRmon.exe

HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\app paths\hpqSSupply.exe
Path REG_SZ C:\Program Files\HP\Digital Imaging\
REG_SZ C:\Program Files\HP\Digital Imaging\hpqSSupply.exe

HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\app paths\Hpqsudi.exe
REG_SZ C:\Program Files\HP\Digital Imaging\Bin\hpqsudi.exe
Path REG_SZ C:\Program Files\HP\Digital Imaging\bin\;C:\Program Files\Common Files\HP\Digital Imaging\Bin

HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\app paths\HpqTrMgr.exe
Path REG_SZ C:\Program Files\HP\Digital Imaging\bin\
REG_SZ C:\Program Files\HP\Digital Imaging\bin\HpqTrMgr.exe

HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\app paths\hrtzzm.exe
REG_SZ C:\Program Files\MSN Gaming Zone\Windows\hrtzzm.exe

HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\app paths\hypertrm.exe
REG_SZ "C:\Program Files\Windows NT\hypertrm.exe"

HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\app paths\ICWCONN1.EXE
REG_SZ "C:\Program Files\Internet Explorer\Connection Wizard\ICWCONN1.EXE"
Path REG_SZ C:\Program Files\Internet Explorer\Connection Wizard;

HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\app paths\ICWCONN2.EXE
REG_SZ "C:\Program Files\Internet Explorer\Connection Wizard\ICWCONN2.EXE"
Path REG_SZ C:\Program Files\Internet Explorer\Connection Wizard;

HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\app paths\IEXPLORE.EXE
REG_SZ C:\Program Files\Internet Explorer\IEXPLORE.EXE
Path REG_SZ C:\Program Files\Internet Explorer;

HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\app paths\INETWIZ.EXE
REG_SZ "C:\Program Files\Internet Explorer\Connection Wizard\INETWIZ.EXE"
Path REG_SZ C:\Program Files\Internet Explorer\Connection Wizard;

HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\app paths\install.exe
RunAsOnNonAdminInstall REG_DWORD 0x1
BlockOnTSNonInstallMode REG_DWORD 0x1

HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\app paths\ISIGNUP.EXE
REG_SZ "C:\Program Files\Internet Explorer\Connection Wizard\ISIGNUP.EXE"
Path REG_SZ C:\Program Files\Internet Explorer\Connection Wizard;

HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\app paths\javaws.exe
REG_SZ C:\Program Files\Java\jre6\bin\javaws.exe
Path REG_SZ C:\Program Files\Java\jre6\bin

HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\app paths\mbam.exe
REG_SZ C:\Program Files\Malwarebytes' Anti-Malware\mbam.exe
Path REG_SZ C:\Program Files\Malwarebytes' Anti-Malware

HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\app paths\migwiz.exe
REG_EXPAND_SZ %SystemRoot%\system32\usmt\migwiz.exe

HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\app paths\moviemk.exe
REG_SZ C:\Program Files\Movie Maker\moviemk.exe

HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\app paths\mplayer2.exe
REG_SZ "C:\Program Files\Windows Media Player\mplayer2.exe"
Path REG_SZ "C:\Program Files\Windows Media Player"

HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\app paths\MSACCESS.EXE
REG_SZ C:\PROGRA~1\MICROS~2\Office10\MSACCESS.EXE
Path REG_SZ C:\Program Files\Microsoft Office\Office10\
useURL REG_SZ 1

HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\app paths\MSCONFIG.EXE
REG_EXPAND_SZ %systemroot%\pchealth\helpctr\Binaries\MSCONFIG.EXE

HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\app paths\msimn.exe
REG_EXPAND_SZ %ProgramFiles%\Outlook Express\msimn.exe
Path REG_EXPAND_SZ %ProgramFiles%\Outlook Express

HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\app paths\msinfo32.exe
REG_SZ C:\Program Files\Common Files\Microsoft Shared\MSInfo\MSInfo32.exe
Path REG_SZ C:\Program Files\Common Files\Microsoft Shared\MSInfo

HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\app paths\MSMSGS.EXE
REG_SZ C:\Program Files\Messenger\msmsgs.exe
Path REG_SZ C:\Program Files\Messenger;

HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\app paths\MsoHtmEd.exe
useURL REG_SZ 1

HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\app paths\OUTLOOK.EXE
REG_SZ C:\PROGRA~1\MICROS~2\Office10\OUTLOOK.EXE
Path REG_SZ C:\Program Files\Microsoft Office\Office10\

HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\app paths\pbrush.exe
REG_EXPAND_SZ %SystemRoot%\system32\mspaint.exe
Path REG_EXPAND_SZ %SystemRoot%\system32

HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\app paths\pinball.exe
REG_SZ C:\Program Files\Windows NT\Pinball\pinball.exe
Path REG_SZ C:\Program Files\Windows NT\Pinball

HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\app paths\PowerPnt.exe
REG_SZ C:\PROGRA~1\MICROS~2\Office10\POWERPNT.EXE
Path REG_SZ C:\Program Files\Microsoft Office\Office10\
useURL REG_SZ 1
SaveURL REG_SZ 1

HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\app paths\rvsezm.exe
REG_SZ C:\Program Files\MSN Gaming Zone\Windows\rvsezm.exe

HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\app paths\setup.exe
RunAsOnNonAdminInstall REG_DWORD 0x1
BlockOnTSNonInstallMode REG_DWORD 0x1

HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\app paths\shvlzm.exe
REG_SZ C:\Program Files\MSN Gaming Zone\Windows\shvlzm.exe

HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\app paths\table30.exe
UseShortName REG_SZ

HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\app paths\wab.exe
REG_EXPAND_SZ %ProgramFiles%\Outlook Express\wab.exe
Path REG_EXPAND_SZ %ProgramFiles%\Outlook Express

HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\app paths\wabmig.exe
REG_EXPAND_SZ %ProgramFiles%\Outlook Express\wabmig.exe
Path REG_EXPAND_SZ %ProgramFiles%\Outlook Express

HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\app paths\winnt32.exe
RunAsOnNonAdminInstall REG_DWORD 0x1

HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\app paths\Winword.exe
REG_SZ C:\PROGRA~1\MICROS~2\Office10\WINWORD.EXE
Path REG_SZ C:\Program Files\Microsoft Office\Office10\
useURL REG_SZ 1
SaveURL REG_SZ 1

HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\app paths\wmplayer.exe
REG_SZ C:\Program Files\Windows Media Player\wmplayer.exe
Path REG_SZ C:\Program Files\Windows Media Player

HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\app paths\WORDPAD.EXE
REG_EXPAND_SZ "%ProgramFiles%\Windows NT\Accessories\WORDPAD.EXE"

HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\app paths\WRITE.EXE
REG_EXPAND_SZ "%ProgramFiles%\Windows NT\Accessories\WORDPAD.EXE"

HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\app paths\XPSViewer.exe
REG_SZ "C:\WINDOWS\system32\XPSViewer\XPSViewer.exe"


Mozilla


! REG.EXE VERSION 3.0

HKEY_LOCAL_MACHINE\SOFTWARE\Mozilla

HKEY_LOCAL_MACHINE\SOFTWARE\Mozilla\Firefox

HKEY_LOCAL_MACHINE\SOFTWARE\Mozilla\Firefox\Extensions
{20a82645-c095-46ed-80e3-08825760534b} REG_SZ C:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\
jqs@sun.com REG_EXPAND_SZ C:\Program Files\Java\jre6\lib\deploy\jqs\ff


Shared Task Scheduler


! REG.EXE VERSION 3.0

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler
{438755C2-A8BA-11D1-B96B-00A0C90312E1} REG_SZ Browseui preloader
{8C7461EF-2B13-11d2-BE35-3078302C2030} REG_SZ Component Categories cache daemon


SafeBoot



SafeBootMinimal


! REG.EXE VERSION 3.0

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\AppMgmt

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Base

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Boot Bus Extender

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Boot file system

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\CryptSvc

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\DcomLaunch

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\dmadmin

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\dmboot.sys

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\dmio.sys

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\dmload.sys

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\dmserver

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\EventLog

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\File system

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Filter

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\HelpSvc

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Netlogon

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\PCI Configuration

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\PlugPlay

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\PNP Filter

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Primary disk

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\RpcSs

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\SCSI Class

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\sermouse.sys

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\sr.sys

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\SRService

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\System Bus Extender

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\vga.sys

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\vgasave.sys

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WinMgmt

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{36FC9E60-C465-11CF-8056-444553540000}

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{4D36E965-E325-11CE-BFC1-08002BE10318}

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{4D36E967-E325-11CE-BFC1-08002BE10318}

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{4D36E969-E325-11CE-BFC1-08002BE10318}

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{4D36E96A-E325-11CE-BFC1-08002BE10318}

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{4D36E96B-E325-11CE-BFC1-08002BE10318}

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{4D36E96F-E325-11CE-BFC1-08002BE10318}

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{4D36E977-E325-11CE-BFC1-08002BE10318}

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{4D36E97B-E325-11CE-BFC1-08002BE10318}

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{4D36E97D-E325-11CE-BFC1-08002BE10318}

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{4D36E980-E325-11CE-BFC1-08002BE10318}

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{71A27CDD-812A-11D0-BEC7-08002BE2092F}

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{745A17A0-74D3-11D0-B6FE-00A0C90F57DA}


SafeBootNetwork


! REG.EXE VERSION 3.0

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Network

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\AFD

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\AppMgmt

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\Base

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\Boot Bus Extender

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\Boot file system

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\Browser

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\CryptSvc

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\DcomLaunch

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\Dhcp

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\dmadmin

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\dmboot.sys

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\dmio.sys

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\dmload.sys

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\dmserver

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\DnsCache

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\EventLog

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\File system

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\Filter

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\HelpSvc

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\ip6fw.sys

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\ipnat.sys

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\LanmanServer

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\LanmanWorkstation

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\LmHosts

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\Messenger

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\NDIS

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\NDIS Wrapper

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\Ndisuio

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\NetBIOS

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\NetBIOSGroup

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\NetBT

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\NetDDEGroup

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\Netlogon

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\NetMan

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\Network

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\NetworkProvider

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\NtLmSsp

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\PCI Configuration

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\PlugPlay

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\PNP Filter

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\PNP_TDI

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\Primary disk

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\rdpcdd.sys

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\rdpdd.sys

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\rdpwd.sys

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\rdsessmgr

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\RpcSs

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\SCSI Class

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\sermouse.sys

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\SharedAccess

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\sr.sys

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\SRService

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\Streams Drivers

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\System Bus Extender

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\Tcpip

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\TDI

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\tdpipe.sys

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\tdtcp.sys

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\termservice

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\vga.sys

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\vgasave.sys

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\WinMgmt

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\WZCSVC

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\{36FC9E60-C465-11CF-8056-444553540000}

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\{4D36E965-E325-11CE-BFC1-08002BE10318}

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\{4D36E967-E325-11CE-BFC1-08002BE10318}

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\{4D36E969-E325-11CE-BFC1-08002BE10318}

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\{4D36E96A-E325-11CE-BFC1-08002BE10318}

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\{4D36E96B-E325-11CE-BFC1-08002BE10318}

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\{4D36E96F-E325-11CE-BFC1-08002BE10318}

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\{4D36E972-E325-11CE-BFC1-08002BE10318}

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\{4D36E973-E325-11CE-BFC1-08002BE10318}

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\{4D36E974-E325-11CE-BFC1-08002BE10318}

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\{4D36E975-E325-11CE-BFC1-08002BE10318}

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\{4D36E977-E325-11CE-BFC1-08002BE10318}

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\{4D36E97B-E325-11CE-BFC1-08002BE10318}

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\{4D36E97D-E325-11CE-BFC1-08002BE10318}

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\{4D36E980-E325-11CE-BFC1-08002BE10318}

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\{71A27CDD-812A-11D0-BEC7-08002BE2092F}

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\{745A17A0-74D3-11D0-B6FE-00A0C90F57DA}


File Rename Operations - Session


! REG.EXE VERSION 3.0

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Session Manager\FileRenameOperations


Known DLLs - Session


! REG.EXE VERSION 3.0

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Session Manager\KnownDlls
advapi32 REG_SZ advapi32.dll
comdlg32 REG_SZ comdlg32.dll
DllDirectory REG_EXPAND_SZ %SystemRoot%\system32
gdi32 REG_SZ gdi32.dll
imagehlp REG_SZ imagehlp.dll
kernel32 REG_SZ kernel32.dll
lz32 REG_SZ lz32.dll
ole32 REG_SZ ole32.dll
oleaut32 REG_SZ oleaut32.dll
olecli32 REG_SZ olecli32.dll
olecnv32 REG_SZ olecnv32.dll
olesvr32 REG_SZ olesvr32.dll
olethk32 REG_SZ olethk32.dll
rpcrt4 REG_SZ rpcrt4.dll
shell32 REG_SZ shell32.dll
url REG_SZ url.dll
urlmon REG_SZ urlmon.dll
user32 REG_SZ user32.dll
version REG_SZ version.dll
wininet REG_SZ wininet.dll
wldap32 REG_SZ wldap32.dll


Downloaded program files (ActiveX)


! REG.EXE VERSION 3.0

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{166B1BCA-3F9C-11CF-8075-444553540000}

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{5D86DDB5-BDF9-441B-9E9E-D4730F4EE499}

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{7530BFB8-7293-4D34-9923-61A11451AFC5}

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{8100D56A-5661-482C-BEE8-AFECE305D968}

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{8AD9C840-044E-11D1-B3E9-00805F499D93}

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{CAFEEFAC-0016-0000-0005-ABCDEFFEDCBA}

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA}

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA}

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{E2883E8F-472F-4FB0-9522-AC9BF37916A7}

PATH: C:\windows\Downloaded Program Files

bdcore.dll
ipsupd.dll
lang.ini
libfn.dll
live.ini
OnlineScanner.inf
oscan8.inf
oscan82.ocx
PhotoUploader55.inf
PhotoUploader55.ocx
scanoptions.tsi
swdir.inf


Mountpoints


! REG.EXE VERSION 3.0

HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2

HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\C

HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{865e1052-4745-11df-8004-806d6172696f}

HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\CPC


Winlogon


! REG.EXE VERSION 3.0

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon
AutoRestartShell REG_DWORD 0x1
DefaultDomainName REG_SZ D2M92XF1
DefaultUserName REG_SZ Miki
LegalNoticeCaption REG_SZ
LegalNoticeText REG_SZ
PowerdownAfterShutdown REG_SZ 0
ReportBootOk REG_SZ 1
Shell REG_SZ Explorer.exe
ShutdownWithoutLogon REG_SZ 0
System REG_SZ
Userinit REG_SZ C:\WINDOWS\system32\userinit.exe,
VmApplet REG_SZ rundll32 shell32,Control_RunDLL "sysdm.cpl"
SfcQuota REG_DWORD 0xffffffff
allocatecdroms REG_SZ 0
allocatedasd REG_SZ 0
allocatefloppies REG_SZ 0
cachedlogonscount REG_SZ 10
forceunlocklogon REG_DWORD 0x0
passwordexpirywarning REG_DWORD 0xe
scremoveoption REG_SZ 0
AllowMultipleTSSessions REG_DWORD 0x1
UIHost REG_EXPAND_SZ logonui.exe
LogonType REG_DWORD 0x1
Background REG_SZ 0 0 0
DebugServerCommand REG_SZ no
SFCDisable REG_DWORD 0x0
WinStationsDisabled REG_SZ 0
HibernationPreviouslyEnabled REG_DWORD 0x1
ShowLogonOptions REG_DWORD 0x0
AltDefaultUserName REG_SZ Miki
AltDefaultDomainName REG_SZ D2M92XF1
LegalNotice Text REG_SZ

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\GPExtensions

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\SpecialAccounts

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Credentials


Windows Update


! REG.EXE VERSION 3.0

HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\windowsupdate\auto update\results\install
LastSuccessTime REG_SZ 2010-07-15 14:16:06
LastError REG_DWORD 0x0


Security Software Information

*Note*: Some security software does not store itself in the WMI.



{END OF FILE}

64 Re: Malware problems and Internet Redirecting on Mon Aug 02, 2010 4:59 pm

DragonMaster Jay


Site Owner
Site Owner
I think I found it. Smile

Please download OTM

  • Save it to your desktop.
  • Please double-click OTM to run it. (Note for Vista: Right-click on the file and choose Run As Administrator).
  • Copy the lines in the codebox below to the clipboard by highlighting ALL of them and pressing CTRL C (or, after highlighting, right-click and choose Copy):
    Code:
    :reg
    [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings]
    "ProxyServer"=-
    "ProxyOverride"=-

    [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
    "{718CD684-A8A6-7A2C-D198-D99178C59E7C}"=-

    :files
    C:\Documents and Settings\Miki\Application Data\Ucum

    :Commands
    [emptytemp]
    [purity]
    [Reboot]


  • Return to OTM, right click in the "Paste Instructions for Items to be Moved" window (under the yellow bar) and choose Paste.
  • Click the red Moveit! button.
  • Copy everything in the Results window (under the green bar) to the clipboard by highlighting ALL of them and pressing CTRL C (or, after highlighting, right-click and choose copy), and paste it in your next reply.
  • Close OTM and reboot your PC.

Note: If a file or folder cannot be moved immediately you may be asked to reboot the machine to finish the move process. If you are asked to reboot the machine choose Yes. In this case, after the reboot, open Notepad (Start->All Programs->Accessories->Notepad), click File->Open, in the File Name box enter *.log and press the Enter key, navigate to the C:\_OTMoveIt\MovedFiles folder, and
open the newest .log file present, and copy/paste the contents of that document back here in your next post.

Also, tell me any more symptoms of infection, after the removal of those bad entries.


..........................................................
DragonMaster Jay
Administrative Director SecuraGeek Association
Advanced Malware Analysts Group Owner


Kaspersky E-Store Kaspersky Anti-Virus 2012: Click Here

Contribute/donate to our site

65 Re: Malware problems and Internet Redirecting on Mon Aug 02, 2010 6:32 pm

blink711


Member
Member
it is still redirecting. here is the log:



All processes killed
========== REGISTRY ==========
Registry value HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\\ProxyServer deleted successfully.
Registry value HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\\ProxyOverride deleted successfully.
Registry value HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\\{718CD684-A8A6-7A2C-D198-D99178C59E7C} deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{718CD684-A8A6-7A2C-D198-D99178C59E7C}\ not found.
========== FILES ==========
File/Folder C:\Documents and Settings\Miki\Application Data\Ucum not found.
========== COMMANDS ==========

[EMPTYTEMP]

User: Administrator
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes
->Flash cache emptied: 0 bytes

User: All Users

User: Default User
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes
->Flash cache emptied: 0 bytes

User: LocalService
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 33170 bytes

User: Miki
->Temp folder emptied: 10726227 bytes
->Temporary Internet Files folder emptied: 47481617 bytes
->Java cache emptied: 25058 bytes
->Flash cache emptied: 5483 bytes

User: NetworkService
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes
->Flash cache emptied: 0 bytes

%systemdrive% .tmp files removed: 0 bytes
%systemroot% .tmp files removed: 0 bytes
%systemroot%\System32 .tmp files removed: 0 bytes
%systemroot%\System32\dllcache .tmp files removed: 0 bytes
%systemroot%\System32\drivers .tmp files removed: 0 bytes
Windows Temp folder emptied: 38180 bytes
%systemroot%\system32\config\systemprofile\Local Settings\Temp folder emptied: 0 bytes
%systemroot%\system32\config\systemprofile\Local Settings\Temporary Internet Files folder emptied: 0 bytes
RecycleBin emptied: 22908 bytes

Total Files Cleaned = 56.00 mb


OTM by OldTimer - Version 3.1.15.0 log created on 08022010_182547

Files moved on Reboot...

Registry entries deleted on Reboot...

66 Re: Malware problems and Internet Redirecting on Mon Aug 02, 2010 11:08 pm

DragonMaster Jay


Site Owner
Site Owner
1. Please download The Avenger by Swandog46 to your Desktop.

  • Right click on the Avenger.zip folder and select "Extract All..."
  • Follow the prompts and extract the avenger folder to your desktop

2. Copy all the text contained in the code box below to your Clipboard by highlighting it and pressing (Ctrl+C):

Code:
Folders to delete:
C:\Documents and Settings\Miki\Application Data\Ucum

Note: the above code was created specifically for this user. If you are not this user, do NOT follow these directions as they could damage the workings of your system.

3. Now, open the avenger folder and start The Avenger program by clicking on its icon.
  • Right click on the window under Input script here:, and select Paste.
  • You can also click on this window and press (Ctrl+V) to paste the contents of the clipboard.
  • Click on Execute
  • Answer "Yes" twice when prompted.

4. The Avenger will automatically do the following:

  • It will Restart your computer. ( In cases where the code to execute contains "Drivers to Delete", The Avenger will actually restart your system twice.)
  • On reboot, it will briefly open a black command window on your desktop, this is normal.
  • After the restart, it creates a log file that should open with the results of Avenger’s actions. This log file will be located at C:\avenger.txt
  • The Avenger will also have backed up all the files, etc., that you asked it to delete, and will have zipped them and moved the zip archives to C:\avenger\backup.zip.


..........................................................
DragonMaster Jay
Administrative Director SecuraGeek Association
Advanced Malware Analysts Group Owner


Kaspersky E-Store Kaspersky Anti-Virus 2012: Click Here

Contribute/donate to our site

67 Re: Malware problems and Internet Redirecting on Wed Aug 04, 2010 5:24 pm

blink711


Member
Member
Logfile of The Avenger Version 2.0, (c) by Swandog46
http://swandog46.geekstogo.com

Platform: Windows XP

*******************

Script file opened successfully.
Script file read successfully.

Backups directory opened successfully at C:\Avenger

*******************

Beginning to process script file:

Rootkit scan active.
No rootkits found!


Error: folder "C:\Documents and Settings\Miki\Application Data\Ucum" not found!
Deletion of folder "C:\Documents and Settings\Miki\Application Data\Ucum" failed!
Status: 0xc0000034 (STATUS_OBJECT_NAME_NOT_FOUND)
--> the object does not exist


Completed script processing.

*******************

Finished! Terminate.

68 Re: Malware problems and Internet Redirecting on Thu Aug 05, 2010 12:30 am

DragonMaster Jay


Site Owner
Site Owner

  1. Download Win32kDiag from any of the following locations and save it to your Desktop.

    • Download Win32kDiag (Win32kDiag.exe) - #1
    • Download Win32kDiag (Win32kDiag.exe) - #2
    • Download Win32kDiag (Win32kDiag.exe) - #3

  • Double-click Win32kDiag.exe to run Win32kDiag and let it finish.
  • When it states "Finished! Press any key to exit...", press any key on your keyboard to close the program.
  • Double-click on the Win32kDiag.txt file that is located on your Desktop and post the entire contents of that log as a reply to this topic.

  • ..........................................................
    DragonMaster Jay
    Administrative Director SecuraGeek Association
    Advanced Malware Analysts Group Owner


    Kaspersky E-Store Kaspersky Anti-Virus 2012: Click Here

    Contribute/donate to our site

    69 Re: Malware problems and Internet Redirecting on Fri Aug 06, 2010 7:07 pm

    blink711


    Member
    Member
    Running from: C:\Documents and Settings\Miki\Desktop\Win32kDiag.exe

    Log file at : C:\Documents and Settings\Miki\Desktop\Win32kDiag.txt

    WARNING: Could not get backup privileges!

    Searching 'C:\WINDOWS'...





    Finished!

    70 Re: Malware problems and Internet Redirecting on Fri Aug 06, 2010 8:19 pm

    DragonMaster Jay


    Site Owner
    Site Owner
    Please download Radix rootkit detector, and save to your Desktop.
    • Unzip the file by right-clicking on it and select Extract all... save to your Desktop.
    • Find the radix_installer folder on your Desktop. Double-click on it.
    • Double-click on radixgui.exe and read the agreement and click on Yes.
    • When the program opens, make sure all the checkboxes on the left.
    • Then, click the Check button. Do not click Fix Checked.
    • Note: if you get a warning about deleting data from the Registry...Are you sure you want to scan...click Yes.
    • When it appears to be done scanning, click the Save log... button at the bottom right. Pick a file name and location and click Save.
    • Find the log, double-click on the file. Post the contents in your next reply.


    ..........................................................
    DragonMaster Jay
    Administrative Director SecuraGeek Association
    Advanced Malware Analysts Group Owner


    Kaspersky E-Store Kaspersky Anti-Virus 2012: Click Here

    Contribute/donate to our site

    71 Re: Malware problems and Internet Redirecting on Sat Aug 07, 2010 7:07 pm

    blink711


    Member
    Member
    Thanks to all the people who donated and ensured the continued development of this software!
    If you want to donate and keep this software alive, please have a look at the About-Tab.
    Thanks in advance!

    USEC Radix V1, 0, 0, 12 [2010/04/19] at your service.
    ---- Check started at 7.8.2010 22:17:49 ----
    Running on: Microsoft Windows NT 5.1 Build 2600 Service Pack 3
    Number of Processors: 2, Active Processor Mask: 00000003
    Processor: Intel Level 6 Revision 1C02
    Allocation granularity: 00010000, Page granularity: 00001000
    Application space: 00010000-7FFEFFFF
    Kernel Membase: 80000000
    [X] Filter common false alarms.
    22:17:49 - Performing check: "Hidden files":
    This check can take some time depending on your harddisk size. You can interrupt it with the ESC key.
    22:18:34 - Performing check: "Alternate Data Streams":
    This check can take some time depending on your harddisk size. You can interrupt it with the ESC key.
    [*] C:\Documents and Settings\Administrator\Favorites\Links\Suggested Sites.url:favicon:$DATA
    [*] C:\Documents and Settings\All Users\Documents\My Pictures\Sample Pictures\Thumbs.db:encryptable:$DATA
    [*] C:\Documents and Settings\Miki\Desktop\Kids\Amelia\The First Year\The rest of the year\Thumbs.db:encryptable:$DATA
    [*] C:\Documents and Settings\Miki\Desktop\Kids\Amelia\The Second Year\Thumbs.db:encryptable:$DATA
    [*] C:\Documents and Settings\Miki\Desktop\Kids\Amelia\Ultra Sounds\Thumbs.db:encryptable:$DATA
    [*] C:\Documents and Settings\Miki\Desktop\Kids\Penelope\Professional Photos of Penelope\2 month\Thumbs.db:encryptable:$DATA
    [*] C:\Documents and Settings\Miki\Desktop\Kids\Penelope\Professional Photos of Penelope\3 months\Thumbs.db:encryptable:$DATA
    [*] C:\Documents and Settings\Miki\Desktop\Kids\Penelope\Professional Photos of Penelope\5 months\Thumbs.db:encryptable:$DATA
    [*] C:\Documents and Settings\Miki\Desktop\Kids\Sisters\Thumbs.db:encryptable:$DATA
    [*] C:\Documents and Settings\Miki\Favorites\1 Sale A Day, Daily Deal.url:favicon:$DATA
    [*] C:\Documents and Settings\Miki\Favorites\amazon.com Dapper Snapper Baby & Toddler Adjustable Belt Baby.url:favicon:$DATA
    [*] C:\Documents and Settings\Miki\Favorites\Amazon.com Shopping Cart.url:favicon:$DATA
    [*] C:\Documents and Settings\Miki\Favorites\babysteals.com Ergo Changing Pads.url:favicon:$DATA
    [*] C:\Documents and Settings\Miki\Favorites\Cooks.com - Recipe - Peanut Butter Pie.url:favicon:$DATA
    [*] C:\Documents and Settings\Miki\Favorites\EXTREMELY NICE, MODERN DUPLEX WITH NEW CARPET & PAINT! CLEAN, NICE!.url:favicon:$DATA
    [*] C:\Documents and Settings\Miki\Favorites\Facebook.url:favicon:$DATA
    [*] C:\Documents and Settings\Miki\Favorites\Get Help.url:favicon:$DATA
    [*] C:\Documents and Settings\Miki\Favorites\Girls - Blue's Clues - Toddler Track Athletic - Payless Shoes.url:favicon:$DATA
    [*] C:\Documents and Settings\Miki\Favorites\How to Make a Fire Breathing Dragon Cake 12 steps (with video) - wikiHow.url:favicon:$DATA
    [*] C:\Documents and Settings\Miki\Favorites\http--www.ustream.tv-sfshiba.url:favicon:$DATA
    [*] C:\Documents and Settings\Miki\Favorites\JustMommies Message Boards - Powered by vBulletin.url:favicon:$DATA
    [*] C:\Documents and Settings\Miki\Favorites\Lima Memorial Health System.url:favicon:$DATA
    [*] C:\Documents and Settings\Miki\Favorites\Links\Facebook Christina Fleck's Photos - Mobile Uploads.url:favicon:$DATA
    [*] C:\Documents and Settings\Miki\Favorites\Links\Suggested Sites.url:favicon:$DATA
    [*] C:\Documents and Settings\Miki\Favorites\MySpace.url:favicon:$DATA
    [*] C:\Documents and Settings\Miki\Favorites\Pregnancy after Weight Loss Surgery.url:favicon:$DATA
    [*] C:\Documents and Settings\Miki\Favorites\Radio Station Guide.url:favicon:$DATA
    [*] C:\Documents and Settings\Miki\Favorites\Rants and Raves.url:favicon:$DATA
    [*] C:\Documents and Settings\Miki\Favorites\Spider - More Halloween Central - Halloween Central - MarthaStewart.com.url:favicon:$DATA
    [*] C:\Documents and Settings\Miki\Favorites\The Internet Movie Database (IMDb).url:favicon:$DATA
    [*] C:\Documents and Settings\Miki\Favorites\theworldaccordingtoeggface My Favorite Protein Shake Recipes.url:favicon:$DATA
    [*] C:\Documents and Settings\Miki\Favorites\theworldaccordingtoeggface.url:favicon:$DATA
    [*] C:\Documents and Settings\Miki\Favorites\walmart.com Dream On Me Sleigh Toddler Bed, Espresso Kids' & Teen Rooms.url:favicon:$DATA
    [*] C:\Documents and Settings\Miki\Favorites\Woot One Day, One Deal (SM).url:favicon:$DATA
    [*] C:\Documents and Settings\Miki\Favorites\www. Girls Crochet Headbands .com - Home - Nixa, MO.url:favicon:$DATA
    [*] C:\Documents and Settings\Miki\Favorites\Year of Giving.url:favicon:$DATA
    [*] C:\Documents and Settings\Miki\Favorites\YouTube - Wapakoneta (Wa - pa - kon - eta).url:favicon:$DATA
    [-] Error scanning file C:\Documents and Settings\Miki\Local Settings\Temporary Internet Files\Content.IE5\CKNOHUCI\uD17-3yqopLXmE27csnhLYYi2hKyi7d8mQ4hqr5DzCFTkFusUPb_eSA1IQForf7Yne2iAD4kENU1qwcmCnDay0crhmjPd5hOvvZ4J5rs8NWkzIxP4YEbMnwuJS9IdepQg1sZi5wmOJoLPbS-ptLxiPd6aHuJOQg[1].gif : 0x05::0x06: The filename, directory name, or volume label syntax is incorrect.

    [-] Error scanning file C:\Documents and Settings\Miki\Local Settings\Temporary Internet Files\Content.IE5\E26F2OKC\dNYl5WfLyo07lYaU03Q8FOkpibowy9MyE8WlPBC9-5eXmC703oojgKn-T4XKuAjDLfyeK971APALfRUmpqOk2oNjLVotw_nXXT_olnDNqTKO1umGAgLhr7KYZ8JoEDhgQIW6VpE8Wq0wExz9DePcKkZXwVMmFDA[1].gif : 0x05::0x06: The filename, directory name, or volume label syntax is incorrect.

    [-] Error scanning file C:\Documents and Settings\Miki\Local Settings\Temporary Internet Files\Content.IE5\E26F2OKC\Ke69jWOCjeZKKIj8ssj8AyjBokzjIErJstNwwWIhtJVFg5YEhuK9fi2ajBR0B89l2UwDPuS_8GI90MG1dsra-wvBElPmQ-wEe9GuZAlGcWEV89I2KlgACvcGQpw1LuYArTvd2W8zBXfIFawbodmOhKQ5A7_LeGA[1].jpg : 0x05::0x06: The filename, directory name, or volume label syntax is incorrect.

    [-] Error scanning file C:\Documents and Settings\Miki\Local Settings\Temporary Internet Files\Content.IE5\E26F2OKC\Ke69jWOCjeZKKIj8ssj9RF3hxcJ86mktheLzY5JTlD7_L_r05JiQv-nFOk9NmpEXTwU0Bi5Oh3iSBAILCopJvtKZsDQbsLgJPUgZ5Wg3-sNTsXFPomhq1hqtQuVarNXZ1g_XcJ5oHXfIFawbodmOhKQ5A7_LeGA[1].jpg : 0x05::0x06: The filename, directory name, or volume label syntax is incorrect.

    [-] Error scanning file C:\Documents and Settings\Miki\Local Settings\Temporary Internet Files\Content.IE5\F4DWFQBM\_WY77orWNm41cXfLOs6nS2lBDciAu1bt2mp3G6lykyJF-H2Ho615lRLMYXOVWeeYHTx79oGGV6S7qAUpBGY0tMTRjmkdtXAkt28Z2j6LUUi093XuLgx4ga9ybwsmz4Z6SACAjQ09GQK2h4qSBdSSeenZRyHDl34[1].gif : 0x05::0x06: The filename, directory name, or volume label syntax is incorrect.

    [-] Error scanning file C:\Documents and Settings\Miki\Local Settings\Temporary Internet Files\Content.IE5\FXW81SMI\Ke69jWOCjeZKKIj8ssj9UcThjkqdwl4jBHxCMMO2DtkpheFJdZhhQcB5uq6I-JmPvO-mlw4i4NsqPrOjIC3xxMG5Jj7hgU9EkOB5VtaGe7kB1Ji3_OsklZrE-lKVpZ9xNu83v8kXjXfIFawbodmOhKQ5A7_LeGA[1].jpg : 0x05::0x06: The filename, directory name, or volume label syntax is incorrect.

    [-] Error scanning file C:\pagefile.sys: 0x05::0x06: The process cannot access the file because it is being used by another process.


    37 streams found.
    22:19:21 - Performing check: "Hidden Registry entries":
    Found KiServiceTable @ 8055C700

    Found KiServiceTable @ 8055C700

    --------------------[HKEY_LOCAL_MACHINE\HARDWARE ]-------------------
    WARNING: Dumping the registry can take quite some time! Be assured
    that the app doesn't hang while dumping!
    Dumping...OK.
    Scanning...DONE.
    -------------------------------------------------------------------------------

    --------------------[HKEY_LOCAL_MACHINE\SAM ]-------------------
    WARNING: Dumping the registry can take quite some time! Be assured
    that the app doesn't hang while dumping!
    Dumping...OK.
    Scanning...[-] Unable to open key: HKEY_LOCAL_MACHINE\SAM\SAM: Access is denied.

    DONE.
    -------------------------------------------------------------------------------

    --------------------[HKEY_LOCAL_MACHINE\SECURITY ]-------------------
    WARNING: Dumping the registry can take quite some time! Be assured
    that the app doesn't hang while dumping!
    Dumping...OK.
    Scanning...[-] Unable to open key: HKEY_LOCAL_MACHINE\SECURITY: Access is denied.

    DONE.
    -------------------------------------------------------------------------------

    --------------------[HKEY_LOCAL_MACHINE\SOFTWARE ]-------------------
    WARNING: Dumping the registry can take quite some time! Be assured
    that the app doesn't hang while dumping!
    Dumping...OK.
    Scanning...[-] Unable to open key: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Remote Desktop\Pending Help Session: Access is denied.

    DONE.
    -------------------------------------------------------------------------------

    --------------------[HKEY_LOCAL_MACHINE\SYSTEM ]-------------------
    WARNING: Dumping the registry can take quite some time! Be assured
    that the app doesn't hang while dumping!
    Dumping...OK.
    Scanning...[-] Unable to open key: HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E965-E325-11CE-BFC1-08002BE10318}\Properties: Access is denied.

    [-] Unable to open key: HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E967-E325-11CE-BFC1-08002BE10318}\Properties: Access is denied.

    [-] Unable to open key: HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E968-E325-11CE-BFC1-08002BE10318}\Properties: Access is denied.

    [-] Unable to open key: HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E969-E325-11CE-BFC1-08002BE10318}\Properties: Access is denied.

    [-] Unable to open key: HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96A-E325-11CE-BFC1-08002BE10318}\Properties: Access is denied.

    [-] Unable to open key: HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E97B-E325-11CE-BFC1-08002BE10318}\Properties: Access is denied.

    [-] Unable to open key: HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E980-E325-11CE-BFC1-08002BE10318}\Properties: Access is denied.

    [-] Unable to open key: HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{55CA1926-73C8-4B78-9DFF-DC16B422F1AB}\Properties: Access is denied.

    [-] Unable to open key: HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\MRxDAV\EncryptedDirectories: Access is denied.

    [-] Unable to open key: HKEY_LOCAL_MACHINE\SYSTEM\ControlSet003\Control\Class\{4D36E965-E325-11CE-BFC1-08002BE10318}\Properties: Access is denied.

    [-] Unable to open key: HKEY_LOCAL_MACHINE\SYSTEM\ControlSet003\Control\Class\{4D36E967-E325-11CE-BFC1-08002BE10318}\Properties: Access is denied.

    [-] Unable to open key: HKEY_LOCAL_MACHINE\SYSTEM\ControlSet003\Control\Class\{4D36E968-E325-11CE-BFC1-08002BE10318}\Properties: Access is denied.

    [-] Unable to open key: HKEY_LOCAL_MACHINE\SYSTEM\ControlSet003\Control\Class\{4D36E969-E325-11CE-BFC1-08002BE10318}\Properties: Access is denied.

    [-] Unable to open key: HKEY_LOCAL_MACHINE\SYSTEM\ControlSet003\Control\Class\{4D36E96A-E325-11CE-BFC1-08002BE10318}\Properties: Access is denied.

    [-] Unable to open key: HKEY_LOCAL_MACHINE\SYSTEM\ControlSet003\Control\Class\{4D36E97B-E325-11CE-BFC1-08002BE10318}\Properties: Access is denied.

    [-] Unable to open key: HKEY_LOCAL_MACHINE\SYSTEM\ControlSet003\Control\Class\{4D36E980-E325-11CE-BFC1-08002BE10318}\Properties: Access is denied.

    [-] Unable to open key: HKEY_LOCAL_MACHINE\SYSTEM\ControlSet003\Control\Class\{55CA1926-73C8-4B78-9DFF-DC16B422F1AB}\Properties: Access is denied.

    [-] Unable to open key: HKEY_LOCAL_MACHINE\SYSTEM\ControlSet003\Services\MRxDAV\EncryptedDirectories: Access is denied.

    DONE.
    -------------------------------------------------------------------------------

    --------------------[HKEY_USERS\.DEFAULT ]-------------------
    WARNING: Dumping the registry can take quite some time! Be assured
    that the app doesn't hang while dumping!
    Dumping...OK.
    Scanning...DONE.
    -------------------------------------------------------------------------------

    --------------------[HKEY_USERS\S-1-5-19 ]-------------------
    WARNING: Dumping the registry can take quite some time! Be assured
    that the app doesn't hang while dumping!
    Dumping...OK.
    Scanning...DONE.
    -------------------------------------------------------------------------------

    --------------------[HKEY_USERS\S-1-5-19_Classes ]-------------------
    WARNING: Dumping the registry can take quite some time! Be assured
    that the app doesn't hang while dumping!
    Dumping...OK.
    Scanning...DONE.
    -------------------------------------------------------------------------------

    --------------------[HKEY_USERS\S-1-5-20 ]-------------------
    WARNING: Dumping the registry can take quite some time! Be assured
    that the app doesn't hang while dumping!
    Dumping...OK.
    Scanning...DONE.
    -------------------------------------------------------------------------------

    --------------------[HKEY_USERS\S-1-5-20_Classes ]-------------------
    WARNING: Dumping the registry can take quite some time! Be assured
    that the app doesn't hang while dumping!
    Dumping...OK.
    Scanning...DONE.
    -------------------------------------------------------------------------------

    --------------------[HKEY_USERS\S-1-5-21-935248203-3380790443-435834739-1006]-------------------
    WARNING: Dumping the registry can take quite some time! Be assured
    that the app doesn't hang while dumping!
    Dumping...OK.
    Scanning...[-] Unable to open key: HKEY_USERS\S-1-5-21-935248203-3380790443-435834739-1006\Software\Microsoft\Protected Storage System Provider\S-1-5-21-935248203-3380790443-435834739-1006: Access is denied.

    DONE.
    -------------------------------------------------------------------------------

    --------------------[HKEY_USERS\S-1-5-21-935248203-3380790443-435834739-1006_Classes]-------------------
    WARNING: Dumping the registry can take quite some time! Be assured
    that the app doesn't hang while dumping!
    Dumping...OK.
    Scanning...[*] Found hidden key: HKEY_USERS\S-1-5-21-839522115-1965331169-1417001333-1003_Classes
    [*] Found hidden key: HKEY_USERS\S-1-5-21-839522115-1965331169-1417001333-1003_Classes\CLSID
    [*] Found hidden key: HKEY_USERS\S-1-5-21-839522115-1965331169-1417001333-1003_Classes\CLSID\{8AD9C840-044E-11D1-B3E9-00805F499D93}
    [.] Found hidden value:
    [REG_SZ] (Standard)
    Java Plug-in 1.6.0_21
    [*] Found hidden key: HKEY_USERS\S-1-5-21-839522115-1965331169-1417001333-1003_Classes\CLSID\{8AD9C840-044E-11D1-B3E9-00805F499D93}\InprocServer32
    [.] Found hidden value:
    [REG_SZ] (Standard)
    C:\Program Files\Java\jre6\bin\jp2iexp.dll
    [.] Found hidden value:
    [REG_SZ] ThreadingModel
    Apartment
    [*] Found hidden key: HKEY_USERS\S-1-5-21-839522115-1965331169-1417001333-1003_Classes\CLSID\{99270982-ed89-4f7a-97a8-d3e83fa0e9cd}
    [*] Found hidden key: HKEY_USERS\S-1-5-21-839522115-1965331169-1417001333-1003_Classes\CLSID\{99270982-ed89-4f7a-97a8-d3e83fa0e9cd}\InProcServer32
    [.] Found hidden value:
    [REG_SZ] (Standard)
    C:\WINDOWS\msvcirt32.dll
    [.] Found hidden value:
    [REG_SZ] ThreadingModel
    Apartment
    [*] Found hidden key: HKEY_USERS\S-1-5-21-839522115-1965331169-1417001333-1003_Classes\CLSID\{CAFEEFAC-0013-0000-0003-ABCDEFFEDCBA}
    [.] Found hidden value:
    [REG_SZ] (Standard)
    Java Plug-in 1.3.0_03
    [*] Found hidden key: HKEY_USERS\S-1-5-21-839522115-1965331169-1417001333-1003_Classes\CLSID\{CAFEEFAC-0013-0000-0003-ABCDEFFEDCBA}\InprocServer32
    [.] Found hidden value:
    [REG_SZ] (Standard)
    C:\Program Files\Java\jre6\bin\jp2iexp.dll
    [.] Found hidden value:
    [REG_SZ] ThreadingModel
    Apartment
    [*] Found hidden key: HKEY_USERS\S-1-5-21-839522115-1965331169-1417001333-1003_Classes\CLSID\{CAFEEFAC-0013-0000-0004-ABCDEFFEDCBA}
    [.] Found hidden value:
    [REG_SZ] (Standard)
    Java Plug-in 1.3.0_04
    [*] Found hidden key: HKEY_USERS\S-1-5-21-839522115-1965331169-1417001333-1003_Classes\CLSID\{CAFEEFAC-0013-0000-0004-ABCDEFFEDCBA}\InprocServer32
    [.] Found hidden value:
    [REG_SZ] (Standard)
    C:\Program Files\Java\jre6\bin\jp2iexp.dll
    [.] Found hidden value:
    [REG_SZ] ThreadingModel
    Apartment
    [*] Found hidden key: HKEY_USERS\S-1-5-21-839522115-1965331169-1417001333-1003_Classes\CLSID\{CAFEEFAC-0013-0000-0005-ABCDEFFEDCBA}
    [.] Found hidden value:
    [REG_SZ] (Standard)
    Java Plug-in 1.3.0_05
    [*] Found hidden key: HKEY_USERS\S-1-5-21-839522115-1965331169-1417001333-1003_Classes\CLSID\{CAFEEFAC-0013-0000-0005-ABCDEFFEDCBA}\InprocServer32
    [.] Found hidden value:
    [REG_SZ] (Standard)
    C:\Program Files\Java\jre6\bin\jp2iexp.dll
    [.] Found hidden value:
    [REG_SZ] ThreadingModel
    Apartment
    [*] Found hidden key: HKEY_USERS\S-1-5-21-839522115-1965331169-1417001333-1003_Classes\CLSID\{CAFEEFAC-0013-0001-0000-ABCDEFFEDCBA}
    [.] Found hidden value:
    [REG_SZ] (Standard)
    Java Plug-in 1.3.1
    [*] Found hidden key: HKEY_USERS\S-1-5-21-839522115-1965331169-1417001333-1003_Classes\CLSID\{CAFEEFAC-0013-0001-0000-ABCDEFFEDCBA}\InprocServer32
    [.] Found hidden value:
    [REG_SZ] (Standard)
    C:\Program Files\Java\jre6\bin\jp2iexp.dll
    [.] Found hidden value:
    [REG_SZ] ThreadingModel
    Apartment
    [*] Found hidden key: HKEY_USERS\S-1-5-21-839522115-1965331169-1417001333-1003_Classes\CLSID\{CAFEEFAC-0013-0001-0001-ABCDEFFEDCBA}
    [.] Found hidden value:
    [REG_SZ] (Standard)
    Java Plug-in 1.3.1_01
    [*] Found hidden key: HKEY_USERS\S-1-5-21-839522115-1965331169-1417001333-1003_Classes\CLSID\{CAFEEFAC-0013-0001-0001-ABCDEFFEDCBA}\InprocServer32
    [.] Found hidden value:
    [REG_SZ] (Standard)
    C:\Program Files\Java\jre6\bin\jp2iexp.dll
    [.] Found hidden value:
    [REG_SZ] ThreadingModel
    Apartment
    [*] Found hidden key: HKEY_USERS\S-1-5-21-839522115-1965331169-1417001333-1003_Classes\CLSID\{CAFEEFAC-0013-0001-0001-ABCDEFFEDCBB}
    [.] Found hidden value:
    [REG_SZ] (Standard)
    Java Plug-in 1.3.1_01
    [*] Found hidden key: HKEY_USERS\S-1-5-21-839522115-1965331169-1417001333-1003_Classes\CLSID\{CAFEEFAC-0013-0001-0001-ABCDEFFEDCBB}\InprocServer32
    [.] Found hidden value:
    [REG_SZ] (Standard)
    C:\Program Files\Java\jre6\bin\jp2iexp.dll
    [.] Found hidden value:
    [REG_SZ] ThreadingModel
    Apartment
    [*] Found hidden key: HKEY_USERS\S-1-5-21-839522115-1965331169-1417001333-1003_Classes\CLSID\{CAFEEFAC-0013-0001-0002-ABCDEFFEDCBA}
    [.] Found hidden value:
    [REG_SZ] (Standard)
    Java Plug-in 1.3.1_02
    [*] Found hidden key: HKEY_USERS\S-1-5-21-839522115-1965331169-1417001333-1003_Classes\CLSID\{CAFEEFAC-0013-0001-0002-ABCDEFFEDCBA}\InprocServer32
    [.] Found hidden value:
    [REG_SZ] (Standard)
    C:\Program Files\Java\jre6\bin\jp2iexp.dll
    [.] Found hidden value:
    [REG_SZ] ThreadingModel
    Apartment
    [*] Found hidden key: HKEY_USERS\S-1-5-21-839522115-1965331169-1417001333-1003_Classes\CLSID\{CAFEEFAC-0013-0001-0002-ABCDEFFEDCBB}
    [.] Found hidden value:
    [REG_SZ] (Standard)
    Java Plug-in 1.3.1_02
    [*] Found hidden key: HKEY_USERS\S-1-5-21-839522115-1965331169-1417001333-1003_Classes\CLSID\{CAFEEFAC-0013-0001-0002-ABCDEFFEDCBB}\InprocServer32
    [.] Found hidden value:
    [REG_SZ] (Standard)
    C:\Program Files\Java\jre6\bin\jp2iexp.dll
    [.] Found hidden value:
    [REG_SZ] ThreadingModel
    Apartment
    [*] Found hidden key: HKEY_USERS\S-1-5-21-839522115-1965331169-1417001333-1003_Classes\CLSID\{CAFEEFAC-0013-0001-0003-ABCDEFFEDCBA}
    [.] Found hidden value:
    [REG_SZ] (Standard)
    Java Plug-in 1.3.1_03
    [*] Found hidden key: HKEY_USERS\S-1-5-21-839522115-1965331169-1417001333-1003_Classes\CLSID\{CAFEEFAC-0013-0001-0003-ABCDEFFEDCBA}\InprocServer32
    [.] Found hidden value:
    [REG_SZ] (Standard)
    C:\Program Files\Java\jre6\bin\jp2iexp.dll
    [.] Found hidden value:
    [REG_SZ] ThreadingModel
    Apartment
    [*] Found hidden key: HKEY_USERS\S-1-5-21-839522115-1965331169-1417001333-1003_Classes\CLSID\{CAFEEFAC-0013-0001-0003-ABCDEFFEDCBB}
    [.] Found hidden value:
    [REG_SZ] (Standard)
    Java Plug-in 1.3.1_03
    [*] Found hidden key: HKEY_USERS\S-1-5-21-839522115-1965331169-1417001333-1003_Classes\CLSID\{CAFEEFAC-0013-0001-0003-ABCDEFFEDCBB}\InprocServer32
    [.] Found hidden value:
    [REG_SZ] (Standard)
    C:\Program Files\Java\jre6\bin\jp2iexp.dll
    [.] Found hidden value:
    [REG_SZ] ThreadingModel
    Apartment
    [*] Found hidden key: HKEY_USERS\S-1-5-21-839522115-1965331169-1417001333-1003_Classes\CLSID\{CAFEEFAC-0013-0001-0004-ABCDEFFEDCBA}
    [.] Found hidden value:
    [REG_SZ] (Standard)
    Java Plug-in 1.3.1_04
    [*] Found hidden key: HKEY_USERS\S-1-5-21-839522115-1965331169-1417001333-1003_Classes\CLSID\{CAFEEFAC-0013-0001-0004-ABCDEFFEDCBA}\InprocServer32
    [.] Found hidden value:
    [REG_SZ] (Standard)
    C:\Program Files\Java\jre6\bin\jp2iexp.dll
    [.] Found hidden value:
    [REG_SZ] ThreadingModel
    Apartment
    [*] Found hidden key: HKEY_USERS\S-1-5-21-839522115-1965331169-1417001333-1003_Classes\CLSID\{CAFEEFAC-0013-0001-0004-ABCDEFFEDCBB}
    [.] Found hidden value:
    [REG_SZ] (Standard)
    Java Plug-in 1.3.1_04
    [*] Found hidden key: HKEY_USERS\S-1-5-21-839522115-1965331169-1417001333-1003_Classes\CLSID\{CAFEEFAC-0013-0001-0004-ABCDEFFEDCBB}\InprocServer32
    [.] Found hidden value:
    [REG_SZ] (Standard)
    C:\Program Files\Java\jre6\bin\jp2iexp.dll
    [.] Found hidden value:
    [REG_SZ] ThreadingModel
    Apartment
    [*] Found hidden key: HKEY_USERS\S-1-5-21-839522115-1965331169-1417001333-1003_Classes\CLSID\{CAFEEFAC-0013-0001-0005-ABCDEFFEDCBA}
    [.] Found hidden value:
    [REG_SZ] (Standard)
    Java Plug-in 1.3.1_05
    [*] Found hidden key: HKEY_USERS\S-1-5-21-839522115-1965331169-1417001333-1003_Classes\CLSID\{CAFEEFAC-0013-0001-0005-ABCDEFFEDCBA}\InprocServer32
    [.] Found hidden value:
    [REG_SZ] (Standard)
    C:\Program Files\Java\jre6\bin\jp2iexp.dll
    [.] Found hidden value:
    [REG_SZ] ThreadingModel
    Apartment
    [*] Found hidden key: HKEY_USERS\S-1-5-21-839522115-1965331169-1417001333-1003_Classes\CLSID\{CAFEEFAC-0013-0001-0005-ABCDEFFEDCBB}
    [.] Found hidden value:
    [REG_SZ] (Standard)
    Java Plug-in 1.3.1_05
    [*] Found hidden key: HKEY_USERS\S-1-5-21-839522115-1965331169-1417001333-1003_Classes\CLSID\{CAFEEFAC-0013-0001-0005-ABCDEFFEDCBB}\InprocServer32
    [.] Found hidden value:
    [REG_SZ] (Standard)
    C:\Program Files\Java\jre6\bin\jp2iexp.dll
    [.] Found hidden value:
    [REG_SZ] ThreadingModel
    Apartment
    [*] Found hidden key: HKEY_USERS\S-1-5-21-839522115-1965331169-1417001333-1003_Classes\CLSID\{CAFEEFAC-0013-0001-0006-ABCDEFFEDCBA}
    [.] Found hidden value:
    [REG_SZ] (Standard)
    Java Plug-in 1.3.1_06
    [*] Found hidden key: HKEY_USERS\S-1-5-21-839522115-1965331169-1417001333-1003_Classes\CLSID\{CAFEEFAC-0013-0001-0006-ABCDEFFEDCBA}\InprocServer32
    [.] Found hidden value:
    [REG_SZ] (Standard)
    C:\Program Files\Java\jre6\bin\jp2iexp.dll
    [.] Found hidden value:
    [REG_SZ] ThreadingModel
    Apartment
    [*] Found hidden key: HKEY_USERS\S-1-5-21-839522115-1965331169-1417001333-1003_Classes\CLSID\{CAFEEFAC-0013-0001-0006-ABCDEFFEDCBB}
    [.] Found hidden value:
    [REG_SZ] (Standard)
    Java Plug-in 1.3.1_06
    [*] Found hidden key: HKEY_USERS\S-1-5-21-839522115-1965331169-1417001333-1003_Classes\CLSID\{CAFEEFAC-0013-0001-0006-ABCDEFFEDCBB}\InprocServer32
    [.] Found hidden value:
    [REG_SZ] (Standard)
    C:\Program Files\Java\jre6\bin\jp2iexp.dll
    [.] Found hidden value:
    [REG_SZ] ThreadingModel
    Apartment
    [*] Found hidden key: HKEY_USERS\S-1-5-21-839522115-1965331169-1417001333-1003_Classes\CLSID\{CAFEEFAC-0013-0001-0007-ABCDEFFEDCBA}
    [.] Found hidden value:
    [REG_SZ] (Standard)
    Java Plug-in 1.3.1_07
    [*] Found hidden key: HKEY_USERS\S-1-5-21-839522115-1965331169-1417001333-1003_Classes\CLSID\{CAFEEFAC-0013-0001-0007-ABCDEFFEDCBA}\InprocServer32
    [.] Found hidden value:
    [REG_SZ] (Standard)
    C:\Program Files\Java\jre6\bin\jp2iexp.dll
    [.] Found hidden value:
    [REG_SZ] ThreadingModel
    Apartment
    [*] Found hidden key: HKEY_USERS\S-1-5-21-839522115-1965331169-1417001333-1003_Classes\CLSID\{CAFEEFAC-0013-0001-0007-ABCDEFFEDCBB}
    [.] Found hidden value:
    [REG_SZ] (Standard)
    Java Plug-in 1.3.1_07
    [*] Found hidden key: HKEY_USERS\S-1-5-21-839522115-1965331169-1417001333-1003_Classes\CLSID\{CAFEEFAC-0013-0001-0007-ABCDEFFEDCBB}\InprocServer32
    [.] Found hidden value:
    [REG_SZ] (Standard)
    C:\Program Files\Java\jre6\bin\jp2iexp.dll
    [.] Found hidden value:
    [REG_SZ] ThreadingModel
    Apartment
    [*] Found hidden key: HKEY_USERS\S-1-5-21-839522115-1965331169-1417001333-1003_Classes\CLSID\{CAFEEFAC-0013-0001-0008-ABCDEFFEDCBA}
    [.] Found hidden value:
    [REG_SZ] (Standard)
    Java Plug-in 1.3.1_08
    [*] Found hidden key: HKEY_USERS\S-1-5-21-839522115-1965331169-1417001333-1003_Classes\CLSID\{CAFEEFAC-0013-0001-0008-ABCDEFFEDCBA}\InprocServer32
    [.] Found hidden value:
    [REG_SZ] (Standard)
    C:\Program Files\Java\jre6\bin\jp2iexp.dll
    [.] Found hidden value:
    [REG_SZ] ThreadingModel
    Apartment
    [*] Found hidden key: HKEY_USERS\S-1-5-21-839522115-1965331169-1417001333-1003_Classes\CLSID\{CAFEEFAC-0013-0001-0008-ABCDEFFEDCBB}
    [.] Found hidden value:
    [REG_SZ] (Standard)
    Java Plug-in 1.3.1_08
    [*] Found hidden key: HKEY_USERS\S-1-5-21-839522115-1965331169-1417001333-1003_Classes\CLSID\{CAFEEFAC-0013-0001-0008-ABCDEFFEDCBB}\InprocServer32
    [.] Found hidden value:
    [REG_SZ] (Standard)
    C:\Program Files\Java\jre6\bin\jp2iexp.dll
    [.] Found hidden value:
    [REG_SZ] ThreadingModel
    Apartment
    [*] Found hidden key: HKEY_USERS\S-1-5-21-839522115-1965331169-1417001333-1003_Classes\CLSID\{CAFEEFAC-0013-0001-0009-ABCDEFFEDCBA}
    [.] Found hidden value:
    [REG_SZ] (Standard)
    Java Plug-in 1.3.1_09
    [*] Found hidden key: HKEY_USERS\S-1-5-21-839522115-1965331169-1417001333-1003_Classes\CLSID\{CAFEEFAC-0013-0001-0009-ABCDEFFEDCBA}\InprocServer32
    [.] Found hidden value:
    [REG_SZ] (Standard)
    C:\Program Files\Java\jre6\bin\jp2iexp.dll
    [.] Found hidden value:
    [REG_SZ] ThreadingModel
    Apartment
    [*] Found hidden key: HKEY_USERS\S-1-5-21-839522115-1965331169-1417001333-1003_Classes\CLSID\{CAFEEFAC-0013-0001-0009-ABCDEFFEDCBB}
    [.] Found hidden value:
    [REG_SZ] (Standard)
    Java Plug-in 1.3.1_09
    [*] Found hidden key: HKEY_USERS\S-1-5-21-839522115-1965331169-1417001333-1003_Classes\CLSID\{CAFEEFAC-0013-0001-0009-ABCDEFFEDCBB}\InprocServer32
    [.] Found hidden value:
    [REG_SZ] (Standard)
    C:\Program Files\Java\jre6\bin\jp2iexp.dll
    [.] Found hidden value:
    [REG_SZ] ThreadingModel
    Apartment
    [*] Found hidden key: HKEY_USERS\S-1-5-21-839522115-1965331169-1417001333-1003_Classes\CLSID\{CAFEEFAC-0013-0001-0010-ABCDEFFEDCBA}
    [.] Found hidden value:
    [REG_SZ] (Standard)
    Java Plug-in 1.3.1_10
    [*] Found hidden key: HKEY_USERS\S-1-5-21-839522115-1965331169-1417001333-1003_Classes\CLSID\{CAFEEFAC-0013-0001-0010-ABCDEFFEDCBA}\InprocServer32
    [.] Found hidden value:
    [REG_SZ] (Standard)
    C:\Program Files\Java\jre6\bin\jp2iexp.dll
    [.] Found hidden value:
    [REG_SZ] ThreadingModel
    Apartment
    [*] Found hidden key: HKEY_USERS\S-1-5-21-839522115-1965331169-1417001333-1003_Classes\CLSID\{CAFEEFAC-0013-0001-0010-ABCDEFFEDCBB}
    [.] Found hidden value:
    [REG_SZ] (Standard)
    Java Plug-in 1.3.1_10
    [*] Found hidden key: HKEY_USERS\S-1-5-21-839522115-1965331169-1417001333-1003_Classes\CLSID\{CAFEEFAC-0013-0001-0010-ABCDEFFEDCBB}\InprocServer32
    [.] Found hidden value:
    [REG_SZ] (Standard)
    C:\Program Files\Java\jre6\bin\jp2iexp.dll
    [.] Found hidden value:
    [REG_SZ] ThreadingModel
    Apartment
    [*] Found hidden key: HKEY_USERS\S-1-5-21-839522115-1965331169-1417001333-1003_Classes\CLSID\{CAFEEFAC-0013-0001-0011-ABCDEFFEDCBA}
    [.] Found hidden value:
    [REG_SZ] (Standard)
    Java Plug-in 1.3.1_11
    [*] Found hidden key: HKEY_USERS\S-1-5-21-839522115-1965331169-1417001333-1003_Classes\CLSID\{CAFEEFAC-0013-0001-0011-ABCDEFFEDCBA}\InprocServer32
    [.] Found hidden value:
    [REG_SZ] (Standard)
    C:\Program Files\Java\jre6\bin\jp2iexp.dll
    [.] Found hidden value:
    [REG_SZ] ThreadingModel
    Apartment
    [*] Found hidden key: HKEY_USERS\S-1-5-21-839522115-1965331169-1417001333-1003_Classes\CLSID\{CAFEEFAC-0013-0001-0011-ABCDEFFEDCBB}
    [.] Found hidden value:
    [REG_SZ] (Standard)
    Java Plug-in 1.3.1_11
    [*] Found hidden key: HKEY_USERS\S-1-5-21-839522115-1965331169-1417001333-1003_Classes\CLSID\{CAFEEFAC-0013-0001-0011-ABCDEFFEDCBB}\InprocServer32
    [.] Found hidden value:
    [REG_SZ] (Standard)
    C:\Program Files\Java\jre6\bin\jp2iexp.dll
    [.] Found hidden value:
    [REG_SZ] ThreadingModel
    Apartment
    [*] Found hidden key: HKEY_USERS\S-1-5-21-839522115-1965331169-1417001333-1003_Classes\CLSID\{CAFEEFAC-0013-0001-0012-ABCDEFFEDCBA}
    [.] Found hidden value:
    [REG_SZ] (Standard)
    Java Plug-in 1.3.1_12
    [*] Found hidden key: HKEY_USERS\S-1-5-21-839522115-1965331169-1417001333-1003_Classes\CLSID\{CAFEEFAC-0013-0001-0012-ABCDEFFEDCBA}\InprocServer32
    [.] Found hidden value:
    [REG_SZ] (Standard)
    C:\Program Files\Java\jre6\bin\jp2iexp.dll
    [.] Found hidden value:
    [REG_SZ] ThreadingModel
    Apartment
    [*] Found hidden key: HKEY_USERS\S-1-5-21-839522115-1965331169-1417001333-1003_Classes\CLSID\{CAFEEFAC-0013-0001-0012-ABCDEFFEDCBB}
    [.] Found hidden value:
    [REG_SZ] (Standard)
    Java Plug-in 1.3.1_12
    [*] Found hidden key: HKEY_USERS\S-1-5-21-839522115-1965331169-1417001333-1003_Classes\CLSID\{CAFEEFAC-0013-0001-0012-ABCDEFFEDCBB}\InprocServer32
    [.] Found hidden value:
    [REG_SZ] (Standard)
    C:\Program Files\Java\jre6\bin\jp2iexp.dll
    [.] Found hidden value:
    [REG_SZ] ThreadingModel
    Apartment
    [*] Found hidden key: HKEY_USERS\S-1-5-21-839522115-1965331169-1417001333-1003_Classes\CLSID\{CAFEEFAC-0013-0001-0013-ABCDEFFEDCBA}
    [.] Found hidden value:
    [REG_SZ] (Standard)
    Java Plug-in 1.3.1_13
    [*] Found hidden key: HKEY_USERS\S-1-5-21-839522115-1965331169-1417001333-1003_Classes\CLSID\{CAFEEFAC-0013-0001-0013-ABCDEFFEDCBA}\InprocServer32
    [.] Found hidden value:
    [REG_SZ] (Standard)
    C:\Program Files\Java\jre6\bin\jp2iexp.dll
    [.] Found hidden value:
    [REG_SZ] ThreadingModel
    Apartment
    [*] Found hidden key: HKEY_USERS\S-1-5-21-839522115-1965331169-1417001333-1003_Classes\CLSID\{CAFEEFAC-0013-0001-0013-ABCDEFFEDCBB}
    [.] Found hidden value:
    [REG_SZ] (Standard)
    Java Plug-in 1.3.1_13
    [*] Found hidden key: HKEY_USERS\S-1-5-21-839522115-1965331169-1417001333-1003_Classes\CLSID\{CAFEEFAC-0013-0001-0013-ABCDEFFEDCBB}\InprocServer32
    [.] Found hidden value:
    [REG_SZ] (Standard)
    C:\Program Files\Java\jre6\bin\jp2iexp.dll
    [.] Found hidden value:
    [REG_SZ] ThreadingModel
    Apartment
    [*] Found hidden key: HKEY_USERS\S-1-5-21-839522115-1965331169-1417001333-1003_Classes\CLSID\{CAFEEFAC-0013-0001-0014-ABCDEFFEDCBA}
    [.] Found hidden value:
    [REG_SZ] (Standard)
    Java Plug-in 1.3.1_14
    [*] Found hidden key: HKEY_USERS\S-1-5-21-839522115-1965331169-1417001333-1003_Classes\CLSID\{CAFEEFAC-0013-0001-0014-ABCDEFFEDCBA}\InprocServer32
    [.] Found hidden value:
    [REG_SZ] (Standard)
    C:\Program Files\Java\jre6\bin\jp2iexp.dll
    [.] Found hidden value:
    [REG_SZ] ThreadingModel
    Apartment
    [*] Found hidden key: HKEY_USERS\S-1-5-21-839522115-1965331169-1417001333-1003_Classes\CLSID\{CAFEEFAC-0013-0001-0014-ABCDEFFEDCBB}
    [.] Found hidden value:
    [REG_SZ] (Standard)
    Java Plug-in 1.3.1_14
    [*] Found hidden key: HKEY_USERS\S-1-5-21-839522115-1965331169-1417001333-1003_Classes\CLSID\{CAFEEFAC-0013-0001-0014-ABCDEFFEDCBB}\InprocServer32
    [.] Found hidden value:
    [REG_SZ] (Standard)
    C:\Program Files\Java\jre6\bin\jp2iexp.dll
    [.] Found hidden value:
    [REG_SZ] ThreadingModel
    Apartment
    [*] Found hidden key: HKEY_USERS\S-1-5-21-839522115-1965331169-1417001333-1003_Classes\CLSID\{CAFEEFAC-0013-0001-0015-ABCDEFFEDCBA}
    [.] Found hidden value:
    [REG_SZ] (Standard)
    Java Plug-in 1.3.1_15
    [*] Found hidden key: HKEY_USERS\S-1-5-21-839522115-1965331169-1417001333-1003_Classes\CLSID\{CAFEEFAC-0013-0001-0015-ABCDEFFEDCBA}\InprocServer32
    [.] Found hidden value:
    [REG_SZ] (Standard)
    C:\Program Files\Java\jre6\bin\jp2iexp.dll
    [.] Found hidden value:
    [REG_SZ] ThreadingModel
    Apartment
    [*] Found hidden key: HKEY_USERS\S-1-5-21-839522115-1965331169-1417001333-1003_Classes\CLSID\{CAFEEFAC-0013-0001-0015-ABCDEFFEDCBB}
    [.] Found hidden value:
    [REG_SZ] (Standard)
    Java Plug-in 1.3.1_15
    [*] Found hidden key: HKEY_USERS\S-1-5-21-839522115-1965331169-1417001333-1003_Classes\CLSID\{CAFEEFAC-0013-0001-0015-ABCDEFFEDCBB}\InprocServer32
    [.] Found hidden value:
    [REG_SZ] (Standard)
    C:\Program Files\Java\jre6\bin\jp2iexp.dll
    [.] Found hidden value:
    [REG_SZ] ThreadingModel
    Apartment
    [*] Found hidden key: HKEY_USERS\S-1-5-21-839522115-1965331169-1417001333-1003_Classes\CLSID\{CAFEEFAC-0013-0001-0016-ABCDEFFEDCBA}
    [.] Found hidden value:
    [REG_SZ] (Standard)
    Java Plug-in 1.3.1_16
    [*] Found hidden key: HKEY_USERS\S-1-5-21-839522115-1965331169-1417001333-1003_Classes\CLSID\{CAFEEFAC-0013-0001-0016-ABCDEFFEDCBA}\InprocServer32
    [.] Found hidden value:
    [REG_SZ] (Standard)
    C:\Program Files\Java\jre6\bin\jp2iexp.dll
    [.] Found hidden value:
    [REG_SZ] ThreadingModel
    Apartment
    [*] Found hidden key: HKEY_USERS\S-1-5-21-839522115-1965331169-1417001333-1003_Classes\CLSID\{CAFEEFAC-0013-0001-0016-ABCDEFFEDCBB}
    [.] Found hidden value:
    [REG_SZ] (Standard)
    Java Plug-in 1.3.1_16
    [*] Found hidden key: HKEY_USERS\S-1-5-21-839522115-1965331169-1417001333-1003_Classes\CLSID\{CAFEEFAC-0013-0001-0016-ABCDEFFEDCBB}\InprocServer32
    [.] Found hidden value:
    [REG_SZ] (Standard)
    C:\Program Files\Java\jre6\bin\jp2iexp.dll
    [.] Found hidden value:
    [REG_SZ] ThreadingModel
    Apartment
    [*] Found hidden key: HKEY_USERS\S-1-5-21-839522115-1965331169-1417001333-1003_Classes\CLSID\{CAFEEFAC-0013-0001-0017-ABCDEFFEDCBA}
    [.] Found hidden value:
    [REG_SZ] (Standard)
    Java Plug-in 1.3.1_17
    [*] Found hidden key: HKEY_USERS\S-1-5-21-839522115-1965331169-1417001333-1003_Classes\CLSID\{CAFEEFAC-0013-0001-0017-ABCDEFFEDCBA}\InprocServer32
    [.] Found hidden value:
    [REG_SZ] (Standard)
    C:\Program Files\Java\jre6\bin\jp2iexp.dll
    [.] Found hidden value:
    [REG_SZ] ThreadingModel
    Apartment
    [*] Found hidden key: HKEY_USERS\S-1-5-21-839522115-1965331169-1417001333-1003_Classes\CLSID\{CAFEEFAC-0013-0001-0017-ABCDEFFEDCBB}
    [.] Found hidden value:
    [REG_SZ] (Standard)
    Java Plug-in 1.3.1_17
    [*] Found hidden key: HKEY_USERS\S-1-5-21-839522115-1965331169-1417001333-1003_Classes\CLSID\{CAFEEFAC-0013-0001-0017-ABCDEFFEDCBB}\InprocServer32
    [.] Found hidden value:
    [REG_SZ] (Standard)
    C:\Program Files\Java\jre6\bin\jp2iexp.dll
    [.] Found hidden value:
    [REG_SZ] ThreadingModel
    Apartment
    [*] Found hidden key: HKEY_USERS\S-1-5-21-839522115-1965331169-1417001333-1003_Classes\CLSID\{CAFEEFAC-0013-0001-0018-ABCDEFFEDCBA}
    [.] Found hidden value:
    [REG_SZ] (Standard)
    Java Plug-in 1.3.1_18
    [*] Found hidden key: HKEY_USERS\S-1-5-21-839522115-1965331169-1417001333-1003_Classes\CLSID\{CAFEEFAC-0013-0001-0018-ABCDEFFEDCBA}\InprocServer32
    [.] Found hidden value:
    [REG_SZ] (Standard)
    C:\Program Files\Java\jre6\bin\jp2iexp.dll
    [.] Found hidden value:
    [REG_SZ] ThreadingModel
    Apartment
    [*] Found hidden key: HKEY_USERS\S-1-5-21-839522115-1965331169-1417001333-1003_Classes\CLSID\{CAFEEFAC-0013-0001-0018-ABCDEFFEDCBB}
    [.] Found hidden value:
    [REG_SZ] (Standard)
    Java Plug-in 1.3.1_18
    [*] Found hidden key: HKEY_USERS\S-1-5-21-839522115-1965331169-1417001333-1003_Classes\CLSID\{CAFEEFAC-0013-0001-0018-ABCDEFFEDCBB}\InprocServer32
    [.] Found hidden value:
    [REG_SZ] (Standard)
    C:\Program Files\Java\jre6\bin\jp2iexp.dll
    [.] Found hidden value:
    [REG_SZ] ThreadingModel
    Apartment
    [*] Found hidden key: HKEY_USERS\S-1-5-21-839522115-1965331169-1417001333-1003_Classes\CLSID\{CAFEEFAC-0013-0001-0019-ABCDEFFEDCBA}
    [.] Found hidden value:
    [REG_SZ] (Standard)
    Java Plug-in 1.3.1_19
    [*] Found hidden key: HKEY_USERS\S-1-5-21-839522115-1965331169-1417001333-1003_Classes\CLSID\{CAFEEFAC-0013-0001-0019-ABCDEFFEDCBA}\InprocServer32
    [.] Found hidden value:
    [REG_SZ] (Standard)
    C:\Program Files\Java\jre6\bin\jp2iexp.dll
    [.] Found hidden value:
    [REG_SZ] ThreadingModel
    Apartment
    [*] Found hidden key: HKEY_USERS\S-1-5-21-839522115-1965331169-1417001333-1003_Classes\CLSID\{CAFEEFAC-0013-0001-0019-ABCDEFFEDCBB}
    [.] Found hidden value:
    [REG_SZ] (Standard)
    Java Plug-in 1.3.1_19
    [*] Found hidden key: HKEY_USERS\S-1-5-21-839522115-1965331169-1417001333-1003_Classes\CLSID\{CAFEEFAC-0013-0001-0019-ABCDEFFEDCBB}\InprocServer32
    [.] Found hidden value:
    [REG_SZ] (Standard)
    C:\Program Files\Java\jre6\bin\jp2iexp.dll
    [.] Found hidden value:
    [REG_SZ] ThreadingModel
    Apartment
    [*] Found hidden key: HKEY_USERS\S-1-5-21-839522115-1965331169-1417001333-1003_Classes\CLSID\{CAFEEFAC-0013-0001-0020-ABCDEFFEDCBA}
    [.] Found hidden value:
    [REG_SZ] (Standard)
    Java Plug-in 1.3.1_20
    [*] Found hidden key: HKEY_USERS\S-1-5-21-839522115-1965331169-1417001333-1003_Classes\CLSID\{CAFEEFAC-0013-0001-0020-ABCDEFFEDCBA}\InprocServer32
    [.] Found hidden value:
    [REG_SZ] (Standard)
    C:\Program Files\Java\jre6\bin\jp2iexp.dll
    [.] Found hidden value:
    [REG_SZ] ThreadingModel
    Apartment
    [*] Found hidden key: HKEY_USERS\S-1-5-21-839522115-1965331169-1417001333-1003_Classes\CLSID\{CAFEEFAC-0013-0001-0020-ABCDEFFEDCBB}
    [.] Found hidden value:
    [REG_SZ] (Standard)
    Java Plug-in 1.3.1_20
    [*] Found hidden key: HKEY_USERS\S-1-5-21-839522115-1965331169-1417001333-1003_Classes\CLSID\{CAFEEFAC-0013-0001-0020-ABCDEFFEDCBB}\InprocServer32
    [.] Found hidden value:
    [REG_SZ] (Standard)
    C:\Program Files\Java\jre6\bin\jp2iexp.dll
    [.] Found hidden value:
    [REG_SZ] ThreadingModel
    Apartment
    [*] Found hidden key: HKEY_USERS\S-1-5-21-839522115-1965331169-1417001333-1003_Classes\CLSID\{CAFEEFAC-0013-0001-0021-ABCDEFFEDCBA}
    [.] Found hidden value:
    [REG_SZ] (Standard)
    Java Plug-in 1.3.1_21
    [*] Found hidden key: HKEY_USERS\S-1-5-21-839522115-1965331169-1417001333-1003_Classes\CLSID\{CAFEEFAC-0013-0001-0021-ABCDEFFEDCBA}\InprocServer32
    [.] Found hidden value:
    [REG_SZ] (Standard)
    C:\Program Files\Java\jre6\bin\jp2iexp.dll
    [.] Found hidden value:
    [REG_SZ] ThreadingModel
    Apartment
    [*] Found hidden key: HKEY_USERS\S-1-5-21-839522115-1965331169-1417001333-1003_Classes\CLSID\{CAFEEFAC-0013-0001-0021-ABCDEFFEDCBB}
    [.] Found hidden value:
    [REG_SZ] (Standard)
    Java Plug-in 1.3.1_21
    [*] Found hidden key: HKEY_USERS\S-1-5-21-839522115-1965331169-1417001333-1003_Classes\CLSID\{CAFEEFAC-0013-0001-0021-ABCDEFFEDCBB}\InprocServer32
    [.] Found hidden value:
    [REG_SZ] (Standard)
    C:\Program Files\Java\jre6\bin\jp2iexp.dll
    [.] Found hidden value:
    [REG_SZ] ThreadingModel
    Apartment
    [*] Found hidden key: HKEY_USERS\S-1-5-21-839522115-1965331169-1417001333-1003_Classes\CLSID\{CAFEEFAC-0013-0001-0022-ABCDEFFEDCBA}
    [.] Found hidden value:
    [REG_SZ] (Standard)
    Java Plug-in 1.3.1_22
    [*] Found hidden key: HKEY_USERS\S-1-5-21-839522115-1965331169-1417001333-1003_Classes\CLSID\{CAFEEFAC-0013-0001-0022-ABCDEFFEDCBA}\InprocServer32
    [.] Found hidden value:
    [REG_SZ] (Standard)
    C:\Program Files\Java\jre6\bin\jp2iexp.dll
    [.] Found hidden value:
    [REG_SZ] ThreadingModel
    Apartment
    [*] Found hidden key: HKEY_USERS\S-1-5-21-839522115-1965331169-1417001333-1003_Classes\CLSID\{CAFEEFAC-0013-0001-0022-ABCDEFFEDCBB}
    [.] Found hidden value:
    [REG_SZ] (Standard)
    Java Plug-in 1.3.1_22
    [*] Found hidden key: HKEY_USERS\S-1-5-21-839522115-1965331169-1417001333-1003_Classes\CLSID\{CAFEEFAC-0013-0001-0022-ABCDEFFEDCBB}\InprocServer32
    [.] Found hidden value:
    [REG_SZ] (Standard)
    C:\Program Files\Java\jre6\bin\jp2iexp.dll
    [.] Found hidden value:
    [REG_SZ] ThreadingModel
    Apartment
    [*] Found hidden key: HKEY_USERS\S-1-5-21-839522115-1965331169-1417001333-1003_Classes\CLSID\{CAFEEFAC-0013-0001-0023-ABCDEFFEDCBA}
    [.] Found hidden value:
    [REG_SZ] (Standard)
    Java Plug-in 1.3.1_23
    [*] Found hidden key: HKEY_USERS\S-1-5-21-839522115-1965331169-1417001333-1003_Classes\CLSID\{CAFEEFAC-0013-0001-0023-ABCDEFFEDCBA}\InprocServer32
    [.] Found hidden value:
    [REG_SZ] (Standard)
    C:\Program Files\Java\jre6\bin\jp2iexp.dll
    [.] Found hidden value:
    [REG_SZ] ThreadingModel
    Apartment
    [*] Found hidden key: HKEY_USERS\S-1-5-21-839522115-1965331169-1417001333-1003_Classes\CLSID\{CAFEEFAC-0013-0001-0023-ABCDEFFEDCBB}
    [.] Found hidden value:
    [REG_SZ] (Standard)
    Java Plug-in 1.3.1_23
    [*] Found hidden key: HKEY_USERS\S-1-5-21-839522115-1965331169-1417001333-1003_Classes\CLSID\{CAFEEFAC-0013-0001-0023-ABCDEFFEDCBB}\InprocServer32
    [.] Found hidden value:
    [REG_SZ] (Standard)
    C:\Program Files\Java\jre6\bin\jp2iexp.dll
    [.] Found hidden value:
    [REG_SZ] ThreadingModel
    Apartment
    [*] Found hidden key: HKEY_USERS\S-1-5-21-839522115-1965331169-1417001333-1003_Classes\CLSID\{CAFEEFAC-0013-0001-0024-ABCDEFFEDCBA}
    [.] Found hidden value:
    [REG_SZ] (Standard)
    Java Plug-in 1.3.1_24
    [*] Found hidden key: HKEY_USERS\S-1-5-21-839522115-1965331169-1417001333-1003_Classes\CLSID\{CAFEEFAC-0013-0001-0024-ABCDEFFEDCBA}\InprocServer32
    [.] Found hidden value:
    [REG_SZ] (Standard)
    C:\Program Files\Java\jre6\bin\jp2iexp.dll
    [.] Found hidden value:
    [REG_SZ] ThreadingModel
    Apartment
    [*] Found hidden key: HKEY_USERS\S-1-5-21-839522115-1965331169-1417001333-1003_Classes\CLSID\{CAFEEFAC-0013-0001-0024-ABCDEFFEDCBB}
    [.] Found hidden value:
    [REG_SZ] (Standard)
    Java Plug-in 1.3.1_24
    [*] Found hidden key: HKEY_USERS\S-1-5-21-839522115-1965331169-1417001333-1003_Classes\CLSID\{CAFEEFAC-0013-0001-0024-ABCDEFFEDCBB}\InprocServer32
    [.] Found hidden value:
    [REG_SZ] (Standard)
    C:\Program Files\Java\jre6\bin\jp2iexp.dll
    [.] Found hidden value:
    [REG_SZ] ThreadingModel
    Apartment
    [*] Found hidden key: HKEY_USERS\S-1-5-21-839522115-1965331169-1417001333-1003_Classes\CLSID\{CAFEEFAC-0013-0001-0025-ABCDEFFEDCBA}
    [.] Found hidden value:
    [REG_SZ] (Standard)
    Java Plug-in 1.3.1_25
    [*] Found hidden key: HKEY_USERS\S-1-5-21-839522115-1965331169-1417001333-1003_Classes\CLSID\{CAFEEFAC-0013-0001-0025-ABCDEFFEDCBA}\InprocServer32
    [.] Found hidden value:
    [REG_SZ] (Standard)
    C:\Program Files\Java\jre6\bin\jp2iexp.dll
    [.] Found hidden value:
    [REG_SZ] ThreadingModel
    Apartment
    [*] Found hidden key: HKEY_USERS\S-1-5-21-839522115-1965331169-1417001333-1003_Classes\CLSID\{CAFEEFAC-0013-0001-0025-ABCDEFFEDCBB}
    [.] Found hidden value:
    [REG_SZ] (Standard)
    Java Plug-in 1.3.1_25
    [*] Found hidden key: HKEY_USERS\S-1-5-21-839522115-1965331169-1417001333-1003_Classes\CLSID\{CAFEEFAC-0013-0001-0025-ABCDEFFEDCBB}\InprocServer32
    [.] Found hidden value:
    [REG_SZ] (Standard)
    C:\Program Files\Java\jre6\bin\jp2iexp.dll
    [.] Found hidden value:
    [REG_SZ] ThreadingModel
    Apartment
    [*] Found hidden key: HKEY_USERS\S-1-5-21-839522115-1965331169-1417001333-1003_Classes\CLSID\{CAFEEFAC-0013-0001-0026-ABCDEFFEDCBA}
    [.] Found hidden value:
    [REG_SZ] (Standard)
    Java Plug-in 1.3.1_26
    [*] Found hidden key: HKEY_USERS\S-1-5-21-839522115-1965331169-1417001333-1003_Classes\CLSID\{CAFEEFAC-0013-0001-0026-ABCDEFFEDCBA}\InprocServer32
    [.] Found hidden value:
    [REG_SZ] (Standard)
    C:\Program Files\Java\jre6\bin\jp2iexp.dll
    [.] Found hidden value:
    [REG_SZ] ThreadingModel
    Apartment
    [*] Found hidden key: HKEY_USERS\S-1-5-21-839522115-1965331169-1417001333-1003_Classes\CLSID\{CAFEEFAC-0013-0001-0026-ABCDEFFEDCBB}
    [.] Found hidden value:
    [REG_SZ] (Standard)
    Java Plug-in 1.3.1_26
    [*] Found hidden key: HKEY_USERS\S-1-5-21-839522115-1965331169-1417001333-1003_Classes\CLSID\{CAFEEFAC-0013-0001-0026-ABCDEFFEDCBB}\InprocServer32
    [.] Found hidden value:
    [REG_SZ] (Standard)
    C:\Program Files\Java\jre6\bin\jp2iexp.dll
    [.] Found hidden value:
    [REG_SZ] ThreadingModel
    Apartment
    [*] Found hidden key: HKEY_USERS\S-1-5-21-839522115-1965331169-1417001333-1003_Classes\CLSID\{CAFEEFAC-0013-0001-0027-ABCDEFFEDCBA}
    [.] Found hidden value:
    [REG_SZ] (Standard)
    Java Plug-in 1.3.1_27
    [*] Found hidden key: HKEY_USERS\S-1-5-21-839522115-1965331169-1417001333-1003_Classes\CLSID\{CAFEEFAC-0013-0001-0027-ABCDEFFEDCBA}\InprocServer32
    [.] Found hidden value:
    [REG_SZ] (Standard)
    C:\Program Files\Java\jre6\bin\jp2iexp.dll
    [.] Found hidden value:
    [REG_SZ] ThreadingModel
    Apartment
    [*] Found hidden key: HKEY_USERS\S-1-5-21-839522115-1965331169-1417001333-1003_Classes\CLSID\{CAFEEFAC-0013-0001-0027-ABCDEFFEDCBB}
    [.] Found hidden value:
    [REG_SZ] (Standard)
    Java Plug-in 1.3.1_27
    [*] Found hidden key: HKEY_USERS\S-1-5-21-839522115-1965331169-1417001333-1003_Classes\CLSID\{CAFEEFAC-0013-0001-0027-ABCDEFFEDCBB}\InprocServer32
    [.] Found hidden value:
    [REG_SZ] (Standard)
    C:\Program Files\Java\jre6\bin\jp2iexp.dll
    [.] Found hidden value:
    [REG_SZ] ThreadingModel
    Apartment
    [*] Found hidden key: HKEY_USERS\S-1-5-21-839522115-1965331169-1417001333-1003_Classes\CLSID\{CAFEEFAC-0013-0001-0028-ABCDEFFEDCBA}
    [.] Found hidden value:
    [REG_SZ] (Standard)
    Java Plug-in 1.3.1_28
    [*] Found hidden key: HKEY_USERS\S-1-5-21-839522115-1965331169-1417001333-1003_Classes\CLSID\{CAFEEFAC-0013-0001-0028-ABCDEFFEDCBA}\InprocServer32
    [.] Found hidden value:
    [REG_SZ] (Standard)
    C:\Program Files\Java\jre6\bin\jp2iexp.dll
    [.] Found hidden value:
    [REG_SZ] ThreadingModel
    Apartment
    [*] Found hidden key: HKEY_USERS\S-1-5-21-839522115-1965331169-1417001333-1003_Classes\CLSID\{CAFEEFAC-0013-0001-0028-ABCDEFFEDCBB}
    [.] Found hidden value:
    [REG_SZ] (Standard)
    Java Plug-in 1.3.1_28
    [*] Found hidden key: HKEY_USERS\S-1-5-21-839522115-1965331169-1417001333-1003_Classes\CLSID\{CAFEEFAC-0013-0001-0028-ABCDEFFEDCBB}\InprocServer32
    [.] Found hidden value:
    [REG_SZ] (Standard)
    C:\Program Files\Java\jre6\bin\jp2iexp.dll
    [.] Found hidden value:
    [REG_SZ] ThreadingModel
    Apartment
    [*] Found hidden key: HKEY_USERS\S-1-5-21-839522115-1965331169-1417001333-1003_Classes\CLSID\{CAFEEFAC-0013-0001-0029-ABCDEFFEDCBA}
    [.] Found hidden value:
    [REG_SZ] (Standard)
    Java Plug-in 1.3.1_29
    [*] Found hidden key: HKEY_USERS\S-1-5-21-839522115-1965331169-1417001333-1003_Classes\CLSID\{CAFEEFAC-0013-0001-0029-ABCDEFFEDCBA}\InprocServer32
    [.] Found hidden value:
    [REG_SZ] (Standard)
    C:\Program Files\Java\jre6\bin\jp2iexp.dll
    [.] Found hidden value:
    [REG_SZ] ThreadingModel
    Apartment
    [*] Found hidden key: HKEY_USERS\S-1-5-21-839522115-1965331169-1417001333-1003_Classes\CLSID\{CAFEEFAC-0013-0001-0029-ABCDEFFEDCBB}
    [.] Found hidden value:
    [REG_SZ] (Standard)
    Java Plug-in 1.3.1_29
    [*] Found hidden key: HKEY_USERS\S-1-5-21-839522115-1965331169-1417001333-1003_Classes\CLSID\{CAFEEFAC-0013-0001-0029-ABCDEFFEDCBB}\InprocServer32
    [.] Found hidden value:
    [REG_SZ] (Standard)
    C:\Program Files\Java\jre6\bin\jp2iexp.dll
    [.] Found hidden value:
    [REG_SZ] ThreadingModel
    Apartment
    [*] Found hidden key: HKEY_USERS\S-1-5-21-839522115-1965331169-1417001333-1003_Classes\CLSID\{CAFEEFAC-0013-0001-0030-ABCDEFFEDCBA}
    [.] Found hidden value:
    [REG_SZ] (Standard)
    Java Plug-in 1.3.1_30
    [*] Found hidden key: HKEY_USERS\S-1-5-21-839522115-1965331169-1417001333-1003_Classes\CLSID\{CAFEEFAC-0013-0001-0030-ABCDEFFEDCBA}\InprocServer32
    [.] Found hidden value:
    [REG_SZ] (Standard)
    C:\Program Files\Java\jre6\bin\jp2iexp.dll
    [.] Found hidden value:
    [REG_SZ] ThreadingModel
    Apartment
    [*] Found hidden key: HKEY_USERS\S-1-5-21-839522115-1965331169-1417001333-1003_Classes\CLSID\{CAFEEFAC-0013-0001-0030-ABCDEFFEDCBB}
    [.] Found hidden value:
    [REG_SZ] (Standard)
    Java Plug-in 1.3.1_30
    [*] Found hidden key: HKEY_USERS\S-1-5-21-839522115-1965331169-1417001333-1003_Classes\CLSID\{CAFEEFAC-0013-0001-0030-ABCDEFFEDCBB}\InprocServer32
    [.] Found hidden value:
    [REG_SZ] (Standard)
    C:\Program Files\Java\jre6\bin\jp2iexp.dll
    [.] Found hidden value:
    [REG_SZ] ThreadingModel
    Apartment
    [*] Found hidden key: HKEY_USERS\S-1-5-21-839522115-1965331169-1417001333-1003_Classes\CLSID\{CAFEEFAC-0014-0000-0000-ABCDEFFEDCBA}
    [.] Found hidden value:
    [REG_SZ] (Standard)
    Java Plug-in 1.4.0
    [*] Found hidden key: HKEY_USERS\S-1-5-21-839522115-1965331169-1417001333-1003_Classes\CLSID\{CAFEEFAC-0014-0000-0000-ABCDEFFEDCBA}\InprocServer32
    [.] Found hidden value:
    [REG_SZ] (Standard)
    C:\Program Files\Java\jre6\bin\jp2iexp.dll
    [.] Found hidden value:
    [REG_SZ] ThreadingModel
    Apartment
    [*] Found hidden key: HKEY_USERS\S-1-5-21-839522115-1965331169-1417001333-1003_Classes\CLSID\{CAFEEFAC-0014-0000-0000-ABCDEFFEDCBB}
    [.] Found hidden value:
    [REG_SZ] (Standard)
    Java Plug-in 1.4.0
    [*] Found hidden key: HKEY_USERS\S-1-5-21-839522115-1965331169-1417001333-1003_Classes\CLSID\{CAFEEFAC-0014-0000-0000-ABCDEFFEDCBB}\InprocServer32
    [.] Found hidden value:
    [REG_SZ] (Standard)
    C:\Program Files\Java\jre6\bin\jp2iexp.dll
    [.] Found hidden value:
    [REG_SZ] ThreadingModel
    Apartment
    [*] Found hidden key: HKEY_USERS\S-1-5-21-839522115-1965331169-1417001333-1003_Classes\CLSID\{CAFEEFAC-0014-0000-0001-ABCDEFFEDCBA}
    [.] Found hidden value:
    [REG_SZ] (Standard)
    Java Plug-in 1.4.0_01
    [*] Found hidden key: HKEY_USERS\S-1-5-21-839522115-1965331169-1417001333-1003_Classes\CLSID\{CAFEEFAC-0014-0000-0001-ABCDEFFEDCBA}\InprocServer32
    [.] Found hidden value:
    [REG_SZ] (Standard)
    C:\Program Files\Java\jre6\bin\jp2iexp.dll
    [.] Found hidden value:
    [REG_SZ] ThreadingModel
    Apartment
    [*] Found hidden key: HKEY_USERS\S-1-5-21-839522115-1965331169-1417001333-1003_Classes\CLSID\{CAFEEFAC-0014-0000-0001-ABCDEFFEDCBB}
    [.] Found hidden value:
    [REG_SZ] (Standard)
    Java Plug-in 1.4.0_01
    [*] Found hidden key: HKEY_USERS\S-1-5-21-839522115-1965331169-1417001333-1003_Classes\CLSID\{CAFEEFAC-0014-0000-0001-ABCDEFFEDCBB}\InprocServer32
    [.] Found hidden value:
    [REG_SZ] (Standard)
    C:\Program Files\Java\jre6\bin\jp2iexp.dll
    [.] Found hidden value:
    [REG_SZ] ThreadingModel
    Apartment
    [*] Found hidden key: HKEY_USERS\S-1-5-21-839522115-1965331169-1417001333-1003_Classes\CLSID\{CAFEEFAC-0014-0000-0002-ABCDEFFEDCBA}
    [.] Found hidden value:
    [REG_SZ] (Standard)
    Java Plug-in 1.4.0_02
    [*] Found hidden key: HKEY_USERS\S-1-5-21-839522115-1965331169-1417001333-1003_Classes\CLSID\{CAFEEFAC-0014-0000-0002-ABCDEFFEDCBA}\InprocServer32
    [.] Found hidden value:
    [REG_SZ] (Standard)
    C:\Program Files\Java\jre6\bin\jp2iexp.dll
    [.] Found hidden value:
    [REG_SZ] ThreadingModel
    Apartment
    [*] Found hidden key: HKEY_USERS\S-1-5-21-839522115-1965331169-1417001333-1003_Classes\CLSID\{CAFEEFAC-0014-0000-0002-ABCDEFFEDCBB}
    [.] Found hidden value:
    [REG_SZ] (Standard)
    Java Plug-in 1.4.0_02
    [*] Found hidden key: HKEY_USERS\S-1-5-21-839522115-1965331169-1417001333-1003_Classes\CLSID\{CAFEEFAC-0014-0000-0002-ABCDEFFEDCBB}\InprocServer32
    [.] Found hidden value:
    [REG_SZ] (Standard)
    C:\Program Files\Java\jre6\bin\jp2iexp.dll
    [.] Found hidden value:
    [REG_SZ] ThreadingModel
    Apartment
    [*] Found hidden key: HKEY_USERS\S-1-5-21-839522115-1965331169-1417001333-1003_Classes\CLSID\{CAFEEFAC-0014-0000-0003-ABCDEFFEDCBA}
    [.] Found hidden value:
    [REG_SZ] (Standard)
    Java Plug-in 1.4.0_03
    [*] Found hidden key: HKEY_USERS\S-1-5-21-839522115-1965331169-1417001333-1003_Classes\CLSID\{CAFEEFAC-0014-0000-0003-ABCDEFFEDCBA}\InprocServer32
    [.] Found hidden value:
    [REG_SZ] (Standard)
    C:\Program Files\Java\jre6\bin\jp2iexp.dll
    [.] Found hidden value:
    [REG_SZ] ThreadingModel
    Apartment
    [*] Found hidden key: HKEY_USERS\S-1-5-21-839522115-1965331169-1417001333-1003_Classes\CLSID\{CAFEEFAC-0014-0000-0003-ABCDEFFEDCBB}
    [.] Found hidden value:
    [REG_SZ] (Standard)
    Java Plug-in 1.4.0_03
    [*] Found hidden key: HKEY_USERS\S-1-5-21-839522115-1965331169-1417001333-1003_Classes\CLSID\{CAFEEFAC-0014-0000-0003-ABCDEFFEDCBB}\InprocServer32
    [.] Found hidden value:
    [REG_SZ] (Standard)
    C:\Program Files\Java\jre6\bin\jp2iexp.dll
    [.] Found hidden value:
    [REG_SZ] ThreadingModel
    Apartment
    [*] Found hidden key: HKEY_USERS\S-1-5-21-839522115-1965331169-1417001333-1003_Classes\CLSID\{CAFEEFAC-0014-0000-0004-ABCDEFFEDCBA}
    [.] Found hidden value:
    [REG_SZ] (Standard)
    Java Plug-in 1.4.0_04
    [*] Found hidden key: HKEY_USERS\S-1-5-21-839522115-1965331169-1417001333-1003_Classes\CLSID\{CAFEEFAC-0014-0000-0004-ABCDEFFEDCBA}\InprocServer32
    [.] Found hidden value:
    [REG_SZ] (Standard)
    C:\Program Files\Java\jre6\bin\jp2iexp.dll
    [.] Found hidden value:
    [REG_SZ] ThreadingModel
    Apartment
    [*] Found hidden key: HKEY_USERS\S-1-5-21-839522115-1965331169-1417001333-1003_Classes\CLSID\{CAFEEFAC-0014-0000-0004-ABCDEFFEDCBB}
    [.] Found hidden value:
    [REG_SZ] (Standard)
    Java Plug-in 1.4.0_04
    [*] Found hidden key: HKEY_USERS\S-1-5-21-839522115-1965331169-1417001333-1003_Classes\CLSID\{CAFEEFAC-0014-0000-0004-ABCDEFFEDCBB}\InprocServer32
    [.] Found hidden value:
    [REG_SZ] (Standard)
    C:\Program Files\Java\jre6\bin\jp2iexp.dll
    [.] Found hidden value:
    [REG_SZ] ThreadingModel
    Apartment
    [*] Found hidden key: HKEY_USERS\S-1-5-21-839522115-1965331169-1417001333-1003_Classes\CLSID\{CAFEEFAC-0014-0001-0000-ABCDEFFEDCBA}
    [.] Found hidden value:
    [REG_SZ] (Standard)
    Java Plug-in 1.4.1
    [*] Found hidden key: HKEY_USERS\S-1-5-21-839522115-1965331169-1417001333-1003_Classes\CLSID\{CAFEEFAC-0014-0001-0000-ABCDEFFEDCBA}\InprocServer32
    [.] Found hidden value:
    [REG_SZ] (Standard)
    C:\Program Files\Java\jre6\bin\jp2iexp.dll
    [.] Found hidden value:
    [REG_SZ] ThreadingModel
    Apartment
    [*] Found hidden key: HKEY_USERS\S-1-5-21-839522115-1965331169-1417001333-1003_Classes\CLSID\{CAFEEFAC-0014-0001-0000-ABCDEFFEDCBB}
    [.] Found hidden value:
    [REG_SZ] (Standard)
    Java Plug-in 1.4.1
    [*] Found hidden key: HKEY_USERS\S-1-5-21-839522115-1965331169-1417001333-1003_Classes\CLSID\{CAFEEFAC-0014-0001-0000-ABCDEFFEDCBB}\InprocServer32
    [.] Found hidden value:
    [REG_SZ] (Standard)
    C:\Program Files\Java\jre6\bin\jp2iexp.dll
    [.] Found hidden value:
    [REG_SZ] ThreadingModel
    Apartment
    [*] Found hidden key: HKEY_USERS\S-1-5-21-839522115-1965331169-1417001333-1003_Classes\CLSID\{CAFEEFAC-0014-0001-0001-ABCDEFFEDCBA}
    [.] Found hidden value:
    [REG_SZ] (Standard)
    Java Plug-in 1.4.1_01
    [*] Found hidden key: HKEY_USERS\S-1-5-21-839522115-1965331169-1417001333-1003_Classes\CLSID\{CAFEEFAC-0014-0001-0001-ABCDEFFEDCBA}\InprocServer32
    [.] Found hidden value:
    [REG_SZ] (Standard)
    C:\Program Files\Java\jre6\bin\jp2iexp.dll
    [.] Found hidden value:
    [REG_SZ] ThreadingModel
    Apartment
    [*] Found hidden key: HKEY_USERS\S-1-5-21-839522115-1965331169-1417001333-1003_Classes\CLSID\{CAFEEFAC-0014-0001-0001-ABCDEFFEDCBB}
    [.] Found hidden value:
    [REG_SZ] (Standard)
    Java Plug-in 1.4.1_01
    [*] Found hidden key: HKEY_USERS\S-1-5-21-839522115-1965331169-1417001333-1003_Classes\CLSID\{CAFEEFAC-0014-0001-0001-ABCDEFFEDCBB}\InprocServer32
    [.] Found hidden value:
    [REG_SZ] (Standard)
    C:\Program Files\Java\jre6\bin\jp2iexp.dll
    [.] Found hidden value:
    [REG_SZ] ThreadingModel
    Apartment
    [*] Found hidden key: HKEY_USERS\S-1-5-21-839522115-1965331169-1417001333-1003_Classes\CLSID\{CAFEEFAC-0014-0001-0002-ABCDEFFEDCBA}
    [.] Found hidden value:
    [REG_SZ] (Standard)
    Java Plug-in 1.4.1_02
    [*] Found hidden key: HKEY_USERS\S-1-5-21-839522115-1965331169-1417001333-1003_Classes\CLSID\{CAFEEFAC-0014-0001-0002-ABCDEFFEDCBA}\InprocServer32
    [.] Found hidden value:
    [REG_SZ] (Standard)
    C:\Program Files\Java\jre6\bin\jp2iexp.dll
    [.] Found hidden value:
    [REG_SZ] ThreadingModel
    Apartment
    [*] Found hidden key: HKEY_USERS\S-1-5-21-839522115-1965331169-1417001333-1003_Classes\CLSID\{CAFEEFAC-0014-0001-0002-ABCDEFFEDCBB}
    [.] Found hidden value:
    [REG_SZ] (Standard)
    Java Plug-in 1.4.1_02
    [*] Found hidden key: HKEY_USERS\S-1-5-21-839522115-1965331169-1417001333-1003_Classes\CLSID\{CAFEEFAC-0014-0001-0002-ABCDEFFEDCBB}\InprocServer32
    [.] Found hidden value:
    [REG_SZ] (Standard)
    C:\Program Files\Java\jre6\bin\jp2iexp.dll
    [.] Found hidden value:
    [REG_SZ] ThreadingModel
    Apartment
    [*] Found hidden key: HKEY_USERS\S-1-5-21-839522115-1965331169-1417001333-1003_Classes\CLSID\{CAFEEFAC-0014-0001-0003-ABCDEFFEDCBA}
    [.] Found hidden value:
    [REG_SZ] (Standard)
    Java Plug-in 1.4.1_03
    [*] Found hidden key: HKEY_USERS\S-1-5-21-839522115-1965331169-1417001333-1003_Classes\CLSID\{CAFEEFAC-0014-0001-0003-ABCDEFFEDCBA}\InprocServer32
    [.] Found hidden value:
    [REG_SZ] (Standard)
    C:\Program Files\Java\jre6\bin\jp2iexp.dll
    [.] Found hidden value:
    [REG_SZ] ThreadingModel
    Apartment
    [*] Found hidden key: HKEY_USERS\S-1-5-21-839522115-1965331169-1417001333-1003_Classes\CLSID\{CAFEEFAC-0014-0001-0003-ABCDEFFEDCBB}
    [.] Found hidden value:
    [REG_SZ] (Standard)
    Java Plug-in 1.4.1_03
    [*] Found hidden key: HKEY_USERS\S-1-5-21-839522115-1965331169-1417001333-1003_Classes\CLSID\{CAFEEFAC-0014-0001-0003-ABCDEFFEDCBB}\InprocServer32
    [.] Found hidden value:
    [REG_SZ] (Standard)
    C:\Program Files\Java\jre6\bin\jp2iexp.dll
    [.] Found hidden value:
    [REG_SZ] ThreadingModel
    Apartment
    [*] Found hidden key: HKEY_USERS\S-1-5-21-839522115-1965331169-1417001333-1003_Classes\CLSID\{CAFEEFAC-0014-0001-0004-ABCDEFFEDCBA}
    [.] Found hidden value:
    [REG_SZ] (Standard)

    72 Re: Malware problems and Internet Redirecting on Sat Aug 07, 2010 7:08 pm

    blink711


    Member
    Member
    Java Plug-in 1.4.1_04
    [*] Found hidden key: HKEY_USERS\S-1-5-21-839522115-1965331169-1417001333-1003_Classes\CLSID\{CAFEEFAC-0014-0001-0004-ABCDEFFEDCBA}\InprocServer32
    [.] Found hidden value:
    [REG_SZ] (Standard)
    C:\Program Files\Java\jre6\bin\jp2iexp.dll
    [.] Found hidden value:
    [REG_SZ] ThreadingModel
    Apartment
    [*] Found hidden key: HKEY_USERS\S-1-5-21-839522115-1965331169-1417001333-1003_Classes\CLSID\{CAFEEFAC-0014-0001-0004-ABCDEFFEDCBB}
    [.] Found hidden value:
    [REG_SZ] (Standard)
    Java Plug-in 1.4.1_04
    [*] Found hidden key: HKEY_USERS\S-1-5-21-839522115-1965331169-1417001333-1003_Classes\CLSID\{CAFEEFAC-0014-0001-0004-ABCDEFFEDCBB}\InprocServer32
    [.] Found hidden value:
    [REG_SZ] (Standard)
    C:\Program Files\Java\jre6\bin\jp2iexp.dll
    [.] Found hidden value:
    [REG_SZ] ThreadingModel
    Apartment
    [*] Found hidden key: HKEY_USERS\S-1-5-21-839522115-1965331169-1417001333-1003_Classes\CLSID\{CAFEEFAC-0014-0001-0005-ABCDEFFEDCBA}
    [.] Found hidden value:
    [REG_SZ] (Standard)
    Java Plug-in 1.4.1_05
    [*] Found hidden key: HKEY_USERS\S-1-5-21-839522115-1965331169-1417001333-1003_Classes\CLSID\{CAFEEFAC-0014-0001-0005-ABCDEFFEDCBA}\InprocServer32
    [.] Found hidden value:
    [REG_SZ] (Standard)
    C:\Program Files\Java\jre6\bin\jp2iexp.dll
    [.] Found hidden value:
    [REG_SZ] ThreadingModel
    Apartment
    [*] Found hidden key: HKEY_USERS\S-1-5-21-839522115-1965331169-1417001333-1003_Classes\CLSID\{CAFEEFAC-0014-0001-0005-ABCDEFFEDCBB}
    [.] Found hidden value:
    [REG_SZ] (Standard)
    Java Plug-in 1.4.1_05
    [*] Found hidden key: HKEY_USERS\S-1-5-21-839522115-1965331169-1417001333-1003_Classes\CLSID\{CAFEEFAC-0014-0001-0005-ABCDEFFEDCBB}\InprocServer32
    [.] Found hidden value:
    [REG_SZ] (Standard)
    C:\Program Files\Java\jre6\bin\jp2iexp.dll
    [.] Found hidden value:
    [REG_SZ] ThreadingModel
    Apartment
    [*] Found hidden key: HKEY_USERS\S-1-5-21-839522115-1965331169-1417001333-1003_Classes\CLSID\{CAFEEFAC-0014-0001-0006-ABCDEFFEDCBA}
    [.] Found hidden value:
    [REG_SZ] (Standard)
    Java Plug-in 1.4.1_06
    [*] Found hidden key: HKEY_USERS\S-1-5-21-839522115-1965331169-1417001333-1003_Classes\CLSID\{CAFEEFAC-0014-0001-0006-ABCDEFFEDCBA}\InprocServer32
    [.] Found hidden value:
    [REG_SZ] (Standard)
    C:\Program Files\Java\jre6\bin\jp2iexp.dll
    [.] Found hidden value:
    [REG_SZ] ThreadingModel
    Apartment
    [*] Found hidden key: HKEY_USERS\S-1-5-21-839522115-1965331169-1417001333-1003_Classes\CLSID\{CAFEEFAC-0014-0001-0006-ABCDEFFEDCBB}
    [.] Found hidden value:
    [REG_SZ] (Standard)
    Java Plug-in 1.4.1_06
    [*] Found hidden key: HKEY_USERS\S-1-5-21-839522115-1965331169-1417001333-1003_Classes\CLSID\{CAFEEFAC-0014-0001-0006-ABCDEFFEDCBB}\InprocServer32
    [.] Found hidden value:
    [REG_SZ] (Standard)
    C:\Program Files\Java\jre6\bin\jp2iexp.dll
    [.] Found hidden value:
    [REG_SZ] ThreadingModel
    Apartment
    [*] Found hidden key: HKEY_USERS\S-1-5-21-839522115-1965331169-1417001333-1003_Classes\CLSID\{CAFEEFAC-0014-0001-0007-ABCDEFFEDCBA}
    [.] Found hidden value:
    [REG_SZ] (Standard)
    Java Plug-in 1.4.1_07
    [*] Found hidden key: HKEY_USERS\S-1-5-21-839522115-1965331169-1417001333-1003_Classes\CLSID\{CAFEEFAC-0014-0001-0007-ABCDEFFEDCBA}\InprocServer32
    [.] Found hidden value:
    [REG_SZ] (Standard)
    C:\Program Files\Java\jre6\bin\jp2iexp.dll
    [.] Found hidden value:
    [REG_SZ] ThreadingModel
    Apartment
    [*] Found hidden key: HKEY_USERS\S-1-5-21-839522115-1965331169-1417001333-1003_Classes\CLSID\{CAFEEFAC-0014-0001-0007-ABCDEFFEDCBB}
    [.] Found hidden value:
    [REG_SZ] (Standard)
    Java Plug-in 1.4.1_07
    [*] Found hidden key: HKEY_USERS\S-1-5-21-839522115-1965331169-1417001333-1003_Classes\CLSID\{CAFEEFAC-0014-0001-0007-ABCDEFFEDCBB}\InprocServer32
    [.] Found hidden value:
    [REG_SZ] (Standard)
    C:\Program Files\Java\jre6\bin\jp2iexp.dll
    [.] Found hidden value:
    [REG_SZ] ThreadingModel
    Apartment
    [*] Found hidden key: HKEY_USERS\S-1-5-21-839522115-1965331169-1417001333-1003_Classes\CLSID\{CAFEEFAC-0014-0002-0000-ABCDEFFEDCBA}
    [.] Found hidden value:
    [REG_SZ] (Standard)
    Java Plug-in 1.4.2
    [*] Found hidden key: HKEY_USERS\S-1-5-21-839522115-1965331169-1417001333-1003_Classes\CLSID\{CAFEEFAC-0014-0002-0000-ABCDEFFEDCBA}\InprocServer32
    [.] Found hidden value:
    [REG_SZ] (Standard)
    C:\Program Files\Java\jre6\bin\jp2iexp.dll
    [.] Found hidden value:
    [REG_SZ] ThreadingModel
    Apartment
    [*] Found hidden key: HKEY_USERS\S-1-5-21-839522115-1965331169-1417001333-1003_Classes\CLSID\{CAFEEFAC-0014-0002-0000-ABCDEFFEDCBB}
    [.] Found hidden value:
    [REG_SZ] (Standard)
    Java Plug-in 1.4.2
    [*] Found hidden key: HKEY_USERS\S-1-5-21-839522115-1965331169-1417001333-1003_Classes\CLSID\{CAFEEFAC-0014-0002-0000-ABCDEFFEDCBB}\InprocServer32
    [.] Found hidden value:
    [REG_SZ] (Standard)
    C:\Program Files\Java\jre6\bin\jp2iexp.dll
    [.] Found hidden value:
    [REG_SZ] ThreadingModel
    Apartment
    [*] Found hidden key: HKEY_USERS\S-1-5-21-839522115-1965331169-1417001333-1003_Classes\CLSID\{CAFEEFAC-0014-0002-0001-ABCDEFFEDCBA}
    [.] Found hidden value:
    [REG_SZ] (Standard)
    Java Plug-in 1.4.2_01
    [*] Found hidden key: HKEY_USERS\S-1-5-21-839522115-1965331169-1417001333-1003_Classes\CLSID\{CAFEEFAC-0014-0002-0001-ABCDEFFEDCBA}\InprocServer32
    [.] Found hidden value:
    [REG_SZ] (Standard)
    C:\Program Files\Java\jre6\bin\jp2iexp.dll
    [.] Found hidden value:
    [REG_SZ] ThreadingModel
    Apartment
    [*] Found hidden key: HKEY_USERS\S-1-5-21-839522115-1965331169-1417001333-1003_Classes\CLSID\{CAFEEFAC-0014-0002-0001-ABCDEFFEDCBB}
    [.] Found hidden value:
    [REG_SZ] (Standard)
    Java Plug-in 1.4.2_01
    [*] Found hidden key: HKEY_USERS\S-1-5-21-839522115-1965331169-1417001333-1003_Classes\CLSID\{CAFEEFAC-0014-0002-0001-ABCDEFFEDCBB}\InprocServer32
    [.] Found hidden value:
    [REG_SZ] (Standard)
    C:\Program Files\Java\jre6\bin\jp2iexp.dll
    [.] Found hidden value:
    [REG_SZ] ThreadingModel
    Apartment
    [*] Found hidden key: HKEY_USERS\S-1-5-21-839522115-1965331169-1417001333-1003_Classes\CLSID\{CAFEEFAC-0014-0002-0002-ABCDEFFEDCBA}
    [.] Found hidden value:
    [REG_SZ] (Standard)
    Java Plug-in 1.4.2_02
    [*] Found hidden key: HKEY_USERS\S-1-5-21-839522115-1965331169-1417001333-1003_Classes\CLSID\{CAFEEFAC-0014-0002-0002-ABCDEFFEDCBA}\InprocServer32
    [.] Found hidden value:
    [REG_SZ] (Standard)
    C:\Program Files\Java\jre6\bin\jp2iexp.dll
    [.] Found hidden value:
    [REG_SZ] ThreadingModel
    Apartment
    [*] Found hidden key: HKEY_USERS\S-1-5-21-839522115-1965331169-1417001333-1003_Classes\CLSID\{CAFEEFAC-0014-0002-0002-ABCDEFFEDCBB}
    [.] Found hidden value:
    [REG_SZ] (Standard)
    Java Plug-in 1.4.2_02
    [*] Found hidden key: HKEY_USERS\S-1-5-21-839522115-1965331169-1417001333-1003_Classes\CLSID\{CAFEEFAC-0014-0002-0002-ABCDEFFEDCBB}\InprocServer32
    [.] Found hidden value:
    [REG_SZ] (Standard)
    C:\Program Files\Java\jre6\bin\jp2iexp.dll
    [.] Found hidden value:
    [REG_SZ] ThreadingModel
    Apartment
    [*] Found hidden key: HKEY_USERS\S-1-5-21-839522115-1965331169-1417001333-1003_Classes\CLSID\{CAFEEFAC-0014-0002-0003-ABCDEFFEDCBA}
    [.] Found hidden value:
    [REG_SZ] (Standard)
    Java Plug-in 1.4.2_03
    [*] Found hidden key: HKEY_USERS\S-1-5-21-839522115-1965331169-1417001333-1003_Classes\CLSID\{CAFEEFAC-0014-0002-0003-ABCDEFFEDCBA}\InprocServer32
    [.] Found hidden value:
    [REG_SZ] (Standard)
    C:\Program Files\Java\jre6\bin\jp2iexp.dll
    [.] Found hidden value:
    [REG_SZ] ThreadingModel
    Apartment
    [*] Found hidden key: HKEY_USERS\S-1-5-21-839522115-1965331169-1417001333-1003_Classes\CLSID\{CAFEEFAC-0014-0002-0003-ABCDEFFEDCBB}
    [.] Found hidden value:
    [REG_SZ] (Standard)
    Java Plug-in 1.4.2_03
    [*] Found hidden key: HKEY_USERS\S-1-5-21-839522115-1965331169-1417001333-1003_Classes\CLSID\{CAFEEFAC-0014-0002-0003-ABCDEFFEDCBB}\InprocServer32
    [.] Found hidden value:
    [REG_SZ] (Standard)
    C:\Program Files\Java\jre6\bin\jp2iexp.dll
    [.] Found hidden value:
    [REG_SZ] ThreadingModel
    Apartment
    [*] Found hidden key: HKEY_USERS\S-1-5-21-839522115-1965331169-1417001333-1003_Classes\CLSID\{CAFEEFAC-0014-0002-0004-ABCDEFFEDCBA}
    [.] Found hidden value:
    [REG_SZ] (Standard)
    Java Plug-in 1.4.2_04
    [*] Found hidden key: HKEY_USERS\S-1-5-21-839522115-1965331169-1417001333-1003_Classes\CLSID\{CAFEEFAC-0014-0002-0004-ABCDEFFEDCBA}\InprocServer32
    [.] Found hidden value:
    [REG_SZ] (Standard)
    C:\Program Files\Java\jre6\bin\jp2iexp.dll
    [.] Found hidden value:
    [REG_SZ] ThreadingModel
    Apartment
    [*] Found hidden key: HKEY_USERS\S-1-5-21-839522115-1965331169-1417001333-1003_Classes\CLSID\{CAFEEFAC-0014-0002-0004-ABCDEFFEDCBB}
    [.] Found hidden value:
    [REG_SZ] (Standard)
    Java Plug-in 1.4.2_04
    [*] Found hidden key: HKEY_USERS\S-1-5-21-839522115-1965331169-1417001333-1003_Classes\CLSID\{CAFEEFAC-0014-0002-0004-ABCDEFFEDCBB}\InprocServer32
    [.] Found hidden value:
    [REG_SZ] (Standard)
    C:\Program Files\Java\jre6\bin\jp2iexp.dll
    [.] Found hidden value:
    [REG_SZ] ThreadingModel
    Apartment
    [*] Found hidden key: HKEY_USERS\S-1-5-21-839522115-1965331169-1417001333-1003_Classes\CLSID\{CAFEEFAC-0014-0002-0005-ABCDEFFEDCBA}
    [.] Found hidden value:
    [REG_SZ] (Standard)
    Java Plug-in 1.4.2_05
    [*] Found hidden key: HKEY_USERS\S-1-5-21-839522115-1965331169-1417001333-1003_Classes\CLSID\{CAFEEFAC-0014-0002-0005-ABCDEFFEDCBA}\InprocServer32
    [.] Found hidden value:
    [REG_SZ] (Standard)
    C:\Program Files\Java\jre6\bin\jp2iexp.dll
    [.] Found hidden value:
    [REG_SZ] ThreadingModel
    Apartment
    [*] Found hidden key: HKEY_USERS\S-1-5-21-839522115-1965331169-1417001333-1003_Classes\CLSID\{CAFEEFAC-0014-0002-0005-ABCDEFFEDCBB}
    [.] Found hidden value:
    [REG_SZ] (Standard)
    Java Plug-in 1.4.2_05
    [*] Found hidden key: HKEY_USERS\S-1-5-21-839522115-1965331169-1417001333-1003_Classes\CLSID\{CAFEEFAC-0014-0002-0005-ABCDEFFEDCBB}\InprocServer32
    [.] Found hidden value:
    [REG_SZ] (Standard)
    C:\Program Files\Java\jre6\bin\jp2iexp.dll
    [.] Found hidden value:
    [REG_SZ] ThreadingModel
    Apartment
    [*] Found hidden key: HKEY_USERS\S-1-5-21-839522115-1965331169-1417001333-1003_Classes\CLSID\{CAFEEFAC-0014-0002-0006-ABCDEFFEDCBA}
    [.] Found hidden value:
    [REG_SZ] (Standard)
    Java Plug-in 1.4.2_06
    [*] Found hidden key: HKEY_USERS\S-1-5-21-839522115-1965331169-1417001333-1003_Classes\CLSID\{CAFEEFAC-0014-0002-0006-ABCDEFFEDCBA}\InprocServer32
    [.] Found hidden value:
    [REG_SZ] (Standard)
    C:\Program Files\Java\jre6\bin\jp2iexp.dll
    [.] Found hidden value:
    [REG_SZ] ThreadingModel
    Apartment
    [*] Found hidden key: HKEY_USERS\S-1-5-21-839522115-1965331169-1417001333-1003_Classes\CLSID\{CAFEEFAC-0014-0002-0006-ABCDEFFEDCBB}
    [.] Found hidden value:
    [REG_SZ] (Standard)
    Java Plug-in 1.4.2_06
    [*] Found hidden key: HKEY_USERS\S-1-5-21-839522115-1965331169-1417001333-1003_Classes\CLSID\{CAFEEFAC-0014-0002-0006-ABCDEFFEDCBB}\InprocServer32
    [.] Found hidden value:
    [REG_SZ] (Standard)
    C:\Program Files\Java\jre6\bin\jp2iexp.dll
    [.] Found hidden value:
    [REG_SZ] ThreadingModel
    Apartment
    [*] Found hidden key: HKEY_USERS\S-1-5-21-839522115-1965331169-1417001333-1003_Classes\CLSID\{CAFEEFAC-0014-0002-0007-ABCDEFFEDCBA}
    [.] Found hidden value:
    [REG_SZ] (Standard)
    Java Plug-in 1.4.2_07
    [*] Found hidden key: HKEY_USERS\S-1-5-21-839522115-1965331169-1417001333-1003_Classes\CLSID\{CAFEEFAC-0014-0002-0007-ABCDEFFEDCBA}\InprocServer32
    [.] Found hidden value:
    [REG_SZ] (Standard)
    C:\Program Files\Java\jre6\bin\jp2iexp.dll
    [.] Found hidden value:
    [REG_SZ] ThreadingModel
    Apartment
    [*] Found hidden key: HKEY_USERS\S-1-5-21-839522115-1965331169-1417001333-1003_Classes\CLSID\{CAFEEFAC-0014-0002-0007-ABCDEFFEDCBB}
    [.] Found hidden value:
    [REG_SZ] (Standard)
    Java Plug-in 1.4.2_07
    [*] Found hidden key: HKEY_USERS\S-1-5-21-839522115-1965331169-1417001333-1003_Classes\CLSID\{CAFEEFAC-0014-0002-0007-ABCDEFFEDCBB}\InprocServer32
    [.] Found hidden value:
    [REG_SZ] (Standard)
    C:\Program Files\Java\jre6\bin\jp2iexp.dll
    [.] Found hidden value:
    [REG_SZ] ThreadingModel
    Apartment
    [*] Found hidden key: HKEY_USERS\S-1-5-21-839522115-1965331169-1417001333-1003_Classes\CLSID\{CAFEEFAC-0014-0002-0008-ABCDEFFEDCBA}
    [.] Found hidden value:
    [REG_SZ] (Standard)
    Java Plug-in 1.4.2_08
    [*] Found hidden key: HKEY_USERS\S-1-5-21-839522115-1965331169-1417001333-1003_Classes\CLSID\{CAFEEFAC-0014-0002-0008-ABCDEFFEDCBA}\InprocServer32
    [.] Found hidden value:
    [REG_SZ] (Standard)
    C:\Program Files\Java\jre6\bin\jp2iexp.dll
    [.] Found hidden value:
    [REG_SZ] ThreadingModel
    Apartment
    [*] Found hidden key: HKEY_USERS\S-1-5-21-839522115-1965331169-1417001333-1003_Classes\CLSID\{CAFEEFAC-0014-0002-0008-ABCDEFFEDCBB}
    [.] Found hidden value:
    [REG_SZ] (Standard)
    Java Plug-in 1.4.2_08
    [*] Found hidden key: HKEY_USERS\S-1-5-21-839522115-1965331169-1417001333-1003_Classes\CLSID\{CAFEEFAC-0014-0002-0008-ABCDEFFEDCBB}\InprocServer32
    [.] Found hidden value:
    [REG_SZ] (Standard)
    C:\Program Files\Java\jre6\bin\jp2iexp.dll
    [.] Found hidden value:
    [REG_SZ] ThreadingModel
    Apartment
    [*] Found hidden key: HKEY_USERS\S-1-5-21-839522115-1965331169-1417001333-1003_Classes\CLSID\{CAFEEFAC-0014-0002-0009-ABCDEFFEDCBA}
    [.] Found hidden value:
    [REG_SZ] (Standard)
    Java Plug-in 1.4.2_09
    [*] Found hidden key: HKEY_USERS\S-1-5-21-839522115-1965331169-1417001333-1003_Classes\CLSID\{CAFEEFAC-0014-0002-0009-ABCDEFFEDCBA}\InprocServer32
    [.] Found hidden value:
    [REG_SZ] (Standard)
    C:\Program Files\Java\jre6\bin\jp2iexp.dll
    [.] Found hidden value:
    [REG_SZ] ThreadingModel
    Apartment
    [*] Found hidden key: HKEY_USERS\S-1-5-21-839522115-1965331169-1417001333-1003_Classes\CLSID\{CAFEEFAC-0014-0002-0009-ABCDEFFEDCBB}
    [.] Found hidden value:
    [REG_SZ] (Standard)
    Java Plug-in 1.4.2_09
    [*] Found hidden key: HKEY_USERS\S-1-5-21-839522115-1965331169-1417001333-1003_Classes\CLSID\{CAFEEFAC-0014-0002-0009-ABCDEFFEDCBB}\InprocServer32
    [.] Found hidden value:
    [REG_SZ] (Standard)
    C:\Program Files\Java\jre6\bin\jp2iexp.dll
    [.] Found hidden value:
    [REG_SZ] ThreadingModel
    Apartment
    [*] Found hidden key: HKEY_USERS\S-1-5-21-839522115-1965331169-1417001333-1003_Classes\CLSID\{CAFEEFAC-0014-0002-0010-ABCDEFFEDCBA}
    [.] Found hidden value:
    [REG_SZ] (Standard)
    Java Plug-in 1.4.2_10
    [*] Found hidden key: HKEY_USERS\S-1-5-21-839522115-1965331169-1417001333-1003_Classes\CLSID\{CAFEEFAC-0014-0002-0010-ABCDEFFEDCBA}\InprocServer32
    [.] Found hidden value:
    [REG_SZ] (Standard)
    C:\Program Files\Java\jre6\bin\jp2iexp.dll
    [.] Found hidden value:
    [REG_SZ] ThreadingModel
    Apartment
    [*] Found hidden key: HKEY_USERS\S-1-5-21-839522115-1965331169-1417001333-1003_Classes\CLSID\{CAFEEFAC-0014-0002-0010-ABCDEFFEDCBB}
    [.] Found hidden value:
    [REG_SZ] (Standard)
    Java Plug-in 1.4.2_10
    [*] Found hidden key: HKEY_USERS\S-1-5-21-839522115-1965331169-1417001333-1003_Classes\CLSID\{CAFEEFAC-0014-0002-0010-ABCDEFFEDCBB}\InprocServer32
    [.] Found hidden value:
    [REG_SZ] (Standard)
    C:\Program Files\Java\jre6\bin\jp2iexp.dll
    [.] Found hidden value:
    [REG_SZ] ThreadingModel
    Apartment
    [*] Found hidden key: HKEY_USERS\S-1-5-21-839522115-1965331169-1417001333-1003_Classes\CLSID\{CAFEEFAC-0014-0002-0011-ABCDEFFEDCBA}
    [.] Found hidden value:
    [REG_SZ] (Standard)
    Java Plug-in 1.4.2_11
    [*] Found hidden key: HKEY_USERS\S-1-5-21-839522115-1965331169-1417001333-1003_Classes\CLSID\{CAFEEFAC-0014-0002-0011-ABCDEFFEDCBA}\InprocServer32
    [.] Found hidden value:
    [REG_SZ] (Standard)
    C:\Program Files\Java\jre6\bin\jp2iexp.dll
    [.] Found hidden value:
    [REG_SZ] ThreadingModel
    Apartment
    [*] Found hidden key: HKEY_USERS\S-1-5-21-839522115-1965331169-1417001333-1003_Classes\CLSID\{CAFEEFAC-0014-0002-0011-ABCDEFFEDCBB}
    [.] Found hidden value:
    [REG_SZ] (Standard)
    Java Plug-in 1.4.2_11
    [*] Found hidden key: HKEY_USERS\S-1-5-21-839522115-1965331169-1417001333-1003_Classes\CLSID\{CAFEEFAC-0014-0002-0011-ABCDEFFEDCBB}\InprocServer32
    [.] Found hidden value:
    [REG_SZ] (Standard)
    C:\Program Files\Java\jre6\bin\jp2iexp.dll
    [.] Found hidden value:
    [REG_SZ] ThreadingModel
    Apartment
    [*] Found hidden key: HKEY_USERS\S-1-5-21-839522115-1965331169-1417001333-1003_Classes\CLSID\{CAFEEFAC-0014-0002-0012-ABCDEFFEDCBA}
    [.] Found hidden value:
    [REG_SZ] (Standard)
    Java Plug-in 1.4.2_12
    [*] Found hidden key: HKEY_USERS\S-1-5-21-839522115-1965331169-1417001333-1003_Classes\CLSID\{CAFEEFAC-0014-0002-0012-ABCDEFFEDCBA}\InprocServer32
    [.] Found hidden value:
    [REG_SZ] (Standard)
    C:\Program Files\Java\jre6\bin\jp2iexp.dll
    [.] Found hidden value:
    [REG_SZ] ThreadingModel
    Apartment
    [*] Found hidden key: HKEY_USERS\S-1-5-21-839522115-1965331169-1417001333-1003_Classes\CLSID\{CAFEEFAC-0014-0002-0012-ABCDEFFEDCBB}
    [.] Found hidden value:
    [REG_SZ] (Standard)
    Java Plug-in 1.4.2_12
    [*] Found hidden key: HKEY_USERS\S-1-5-21-839522115-1965331169-1417001333-1003_Classes\CLSID\{CAFEEFAC-0014-0002-0012-ABCDEFFEDCBB}\InprocServer32
    [.] Found hidden value:
    [REG_SZ] (Standard)
    C:\Program Files\Java\jre6\bin\jp2iexp.dll
    [.] Found hidden value:
    [REG_SZ] ThreadingModel
    Apartment
    [*] Found hidden key: HKEY_USERS\S-1-5-21-839522115-1965331169-1417001333-1003_Classes\CLSID\{CAFEEFAC-0014-0002-0013-ABCDEFFEDCBA}
    [.] Found hidden value:
    [REG_SZ] (Standard)
    Java Plug-in 1.4.2_13
    [*] Found hidden key: HKEY_USERS\S-1-5-21-839522115-1965331169-1417001333-1003_Classes\CLSID\{CAFEEFAC-0014-0002-0013-ABCDEFFEDCBA}\InprocServer32
    [.] Found hidden value:
    [REG_SZ] (Standard)
    C:\Program Files\Java\jre6\bin\jp2iexp.dll
    [.] Found hidden value:
    [REG_SZ] ThreadingModel
    Apartment
    [*] Found hidden key: HKEY_USERS\S-1-5-21-839522115-1965331169-1417001333-1003_Classes\CLSID\{CAFEEFAC-0014-0002-0013-ABCDEFFEDCBB}
    [.] Found hidden value:
    [REG_SZ] (Standard)
    Java Plug-in 1.4.2_13
    [*] Found hidden key: HKEY_USERS\S-1-5-21-839522115-1965331169-1417001333-1003_Classes\CLSID\{CAFEEFAC-0014-0002-0013-ABCDEFFEDCBB}\InprocServer32
    [.] Found hidden value:
    [REG_SZ] (Standard)
    C:\Program Files\Java\jre6\bin\jp2iexp.dll
    [.] Found hidden value:
    [REG_SZ] ThreadingModel
    Apartment
    [*] Found hidden key: HKEY_USERS\S-1-5-21-839522115-1965331169-1417001333-1003_Classes\CLSID\{CAFEEFAC-0014-0002-0014-ABCDEFFEDCBA}
    [.] Found hidden value:
    [REG_SZ] (Standard)
    Java Plug-in 1.4.2_14
    [*] Found hidden key: HKEY_USERS\S-1-5-21-839522115-1965331169-1417001333-1003_Classes\CLSID\{CAFEEFAC-0014-0002-0014-ABCDEFFEDCBA}\InprocServer32
    [.] Found hidden value:
    [REG_SZ] (Standard)
    C:\Program Files\Java\jre6\bin\jp2iexp.dll
    [.] Found hidden value:
    [REG_SZ] ThreadingModel
    Apartment
    [*] Found hidden key: HKEY_USERS\S-1-5-21-839522115-1965331169-1417001333-1003_Classes\CLSID\{CAFEEFAC-0014-0002-0014-ABCDEFFEDCBB}
    [.] Found hidden value:
    [REG_SZ] (Standard)
    Java Plug-in 1.4.2_14
    [*] Found hidden key: HKEY_USERS\S-1-5-21-839522115-1965331169-1417001333-1003_Classes\CLSID\{CAFEEFAC-0014-0002-0014-ABCDEFFEDCBB}\InprocServer32
    [.] Found hidden value:
    [REG_SZ] (Standard)
    C:\Program Files\Java\jre6\bin\jp2iexp.dll
    [.] Found hidden value:
    [REG_SZ] ThreadingModel
    Apartment
    [*] Found hidden key: HKEY_USERS\S-1-5-21-839522115-1965331169-1417001333-1003_Classes\CLSID\{CAFEEFAC-0014-0002-0015-ABCDEFFEDCBA}
    [.] Found hidden value:
    [REG_SZ] (Standard)
    Java Plug-in 1.4.2_15
    [*] Found hidden key: HKEY_USERS\S-1-5-21-839522115-1965331169-1417001333-1003_Classes\CLSID\{CAFEEFAC-0014-0002-0015-ABCDEFFEDCBA}\InprocServer32
    [.] Found hidden value:
    [REG_SZ] (Standard)
    C:\Program Files\Java\jre6\bin\jp2iexp.dll
    [.] Found hidden value:
    [REG_SZ] ThreadingModel
    Apartment
    [*] Found hidden key: HKEY_USERS\S-1-5-21-839522115-1965331169-1417001333-1003_Classes\CLSID\{CAFEEFAC-0014-0002-0015-ABCDEFFEDCBB}
    [.] Found hidden value:
    [REG_SZ] (Standard)
    Java Plug-in 1.4.2_15
    [*] Found hidden key: HKEY_USERS\S-1-5-21-839522115-1965331169-1417001333-1003_Classes\CLSID\{CAFEEFAC-0014-0002-0015-ABCDEFFEDCBB}\InprocServer32
    [.] Found hidden value:
    [REG_SZ] (Standard)
    C:\Program Files\Java\jre6\bin\jp2iexp.dll
    [.] Found hidden value:
    [REG_SZ] ThreadingModel
    Apartment
    [*] Found hidden key: HKEY_USERS\S-1-5-21-839522115-1965331169-1417001333-1003_Classes\CLSID\{CAFEEFAC-0014-0002-0016-ABCDEFFEDCBA}
    [.] Found hidden value:
    [REG_SZ] (Standard)
    Java Plug-in 1.4.2_16
    [*] Found hidden key: HKEY_USERS\S-1-5-21-839522115-1965331169-1417001333-1003_Classes\CLSID\{CAFEEFAC-0014-0002-0016-ABCDEFFEDCBA}\InprocServer32
    [.] Found hidden value:
    [REG_SZ] (Standard)
    C:\Program Files\Java\jre6\bin\jp2iexp.dll
    [.] Found hidden value:
    [REG_SZ] ThreadingModel
    Apartment
    [*] Found hidden key: HKEY_USERS\S-1-5-21-839522115-1965331169-1417001333-1003_Classes\CLSID\{CAFEEFAC-0014-0002-0016-ABCDEFFEDCBB}
    [.] Found hidden value:
    [REG_SZ] (Standard)
    Java Plug-in 1.4.2_16
    [*] Found hidden key: HKEY_USERS\S-1-5-21-839522115-1965331169-1417001333-1003_Classes\CLSID\{CAFEEFAC-0014-0002-0016-ABCDEFFEDCBB}\InprocServer32
    [.] Found hidden value:
    [REG_SZ] (Standard)
    C:\Program Files\Java\jre6\bin\jp2iexp.dll
    [.] Found hidden value:
    [REG_SZ] ThreadingModel
    Apartment
    [*] Found hidden key: HKEY_USERS\S-1-5-21-839522115-1965331169-1417001333-1003_Classes\CLSID\{CAFEEFAC-0014-0002-0017-ABCDEFFEDCBA}
    [.] Found hidden value:
    [REG_SZ] (Standard)
    Java Plug-in 1.4.2_17
    [*] Found hidden key: HKEY_USERS\S-1-5-21-839522115-1965331169-1417001333-1003_Classes\CLSID\{CAFEEFAC-0014-0002-0017-ABCDEFFEDCBA}\InprocServer32
    [.] Found hidden value:
    [REG_SZ] (Standard)
    C:\Program Files\Java\jre6\bin\jp2iexp.dll
    [.] Found hidden value:
    [REG_SZ] ThreadingModel
    Apartment
    [*] Found hidden key: HKEY_USERS\S-1-5-21-839522115-1965331169-1417001333-1003_Classes\CLSID\{CAFEEFAC-0014-0002-0017-ABCDEFFEDCBB}
    [.] Found hidden value:
    [REG_SZ] (Standard)
    Java Plug-in 1.4.2_17
    [*] Found hidden key: HKEY_USERS\S-1-5-21-839522115-1965331169-1417001333-1003_Classes\CLSID\{CAFEEFAC-0014-0002-0017-ABCDEFFEDCBB}\InprocServer32
    [.] Found hidden value:
    [REG_SZ] (Standard)
    C:\Program Files\Java\jre6\bin\jp2iexp.dll
    [.] Found hidden value:
    [REG_SZ] ThreadingModel
    Apartment
    [*] Found hidden key: HKEY_USERS\S-1-5-21-839522115-1965331169-1417001333-1003_Classes\CLSID\{CAFEEFAC-0014-0002-0018-ABCDEFFEDCBA}
    [.] Found hidden value:
    [REG_SZ] (Standard)
    Java Plug-in 1.4.2_18
    [*] Found hidden key: HKEY_USERS\S-1-5-21-839522115-1965331169-1417001333-1003_Classes\CLSID\{CAFEEFAC-0014-0002-0018-ABCDEFFEDCBA}\InprocServer32
    [.] Found hidden value:
    [REG_SZ] (Standard)
    C:\Program Files\Java\jre6\bin\jp2iexp.dll
    [.] Found hidden value:
    [REG_SZ] ThreadingModel
    Apartment
    [*] Found hidden key: HKEY_USERS\S-1-5-21-839522115-1965331169-1417001333-1003_Classes\CLSID\{CAFEEFAC-0014-0002-0018-ABCDEFFEDCBB}
    [.] Found hidden value:
    [REG_SZ] (Standard)
    Java Plug-in 1.4.2_18
    [*] Found hidden key: HKEY_USERS\S-1-5-21-839522115-1965331169-1417001333-1003_Classes\CLSID\{CAFEEFAC-0014-0002-0018-ABCDEFFEDCBB}\InprocServer32
    [.] Found hidden value:
    [REG_SZ] (Standard)
    C:\Program Files\Java\jre6\bin\jp2iexp.dll
    [.] Found hidden value:
    [REG_SZ] ThreadingModel
    Apartment
    [*] Found hidden key: HKEY_USERS\S-1-5-21-839522115-1965331169-1417001333-1003_Classes\CLSID\{CAFEEFAC-0014-0002-0019-ABCDEFFEDCBA}
    [.] Found hidden value:
    [REG_SZ] (Standard)
    Java Plug-in 1.4.2_19
    [*] Found hidden key: HKEY_USERS\S-1-5-21-839522115-1965331169-1417001333-1003_Classes\CLSID\{CAFEEFAC-0014-0002-0019-ABCDEFFEDCBA}\InprocServer32
    [.] Found hidden value:
    [REG_SZ] (Standard)
    C:\Program Files\Java\jre6\bin\jp2iexp.dll
    [.] Found hidden value:
    [REG_SZ] ThreadingModel
    Apartment
    [*] Found hidden key: HKEY_USERS\S-1-5-21-839522115-1965331169-1417001333-1003_Classes\CLSID\{CAFEEFAC-0014-0002-0019-ABCDEFFEDCBB}
    [.] Found hidden value:
    [REG_SZ] (Standard)
    Java Plug-in 1.4.2_19
    [*] Found hidden key: HKEY_USERS\S-1-5-21-839522115-1965331169-1417001333-1003_Classes\CLSID\{CAFEEFAC-0014-0002-0019-ABCDEFFEDCBB}\InprocServer32
    [.] Found hidden value:
    [REG_SZ] (Standard)
    C:\Program Files\Java\jre6\bin\jp2iexp.dll
    [.] Found hidden value:
    [REG_SZ] ThreadingModel
    Apartment
    [*] Found hidden key: HKEY_USERS\S-1-5-21-839522115-1965331169-1417001333-1003_Classes\CLSID\{CAFEEFAC-0014-0002-0020-ABCDEFFEDCBA}
    [.] Found hidden value:
    [REG_SZ] (Standard)
    Java Plug-in 1.4.2_20
    [*] Found hidden key: HKEY_USERS\S-1-5-21-839522115-1965331169-1417001333-1003_Classes\CLSID\{CAFEEFAC-0014-0002-0020-ABCDEFFEDCBA}\InprocServer32
    [.] Found hidden value:
    [REG_SZ] (Standard)
    C:\Program Files\Java\jre6\bin\jp2iexp.dll
    [.] Found hidden value:
    [REG_SZ] ThreadingModel
    Apartment
    [*] Found hidden key: HKEY_USERS\S-1-5-21-839522115-1965331169-1417001333-1003_Classes\CLSID\{CAFEEFAC-0014-0002-0020-ABCDEFFEDCBB}
    [.] Found hidden value:
    [REG_SZ] (Standard)
    Java Plug-in 1.4.2_20
    [*] Found hidden key: HKEY_USERS\S-1-5-21-839522115-1965331169-1417001333-1003_Classes\CLSID\{CAFEEFAC-0014-0002-0020-ABCDEFFEDCBB}\InprocServer32
    [.] Found hidden value:
    [REG_SZ] (Standard)
    C:\Program Files\Java\jre6\bin\jp2iexp.dll
    [.] Found hidden value:
    [REG_SZ] ThreadingModel
    Apartment
    [*] Found hidden key: HKEY_USERS\S-1-5-21-839522115-1965331169-1417001333-1003_Classes\CLSID\{CAFEEFAC-0014-0002-0021-ABCDEFFEDCBA}
    [.] Found hidden value:
    [REG_SZ] (Standard)
    Java Plug-in 1.4.2_21
    [*] Found hidden key: HKEY_USERS\S-1-5-21-839522115-1965331169-1417001333-1003_Classes\CLSID\{CAFEEFAC-0014-0002-0021-ABCDEFFEDCBA}\InprocServer32
    [.] Found hidden value:
    [REG_SZ] (Standard)
    C:\Program Files\Java\jre6\bin\jp2iexp.dll
    [.] Found hidden value:
    [REG_SZ] ThreadingModel
    Apartment
    [*] Found hidden key: HKEY_USERS\S-1-5-21-839522115-1965331169-1417001333-1003_Classes\CLSID\{CAFEEFAC-0014-0002-0021-ABCDEFFEDCBB}
    [.] Found hidden value:
    [REG_SZ] (Standard)
    Java Plug-in 1.4.2_21
    [*] Found hidden key: HKEY_USERS\S-1-5-21-839522115-1965331169-1417001333-1003_Classes\CLSID\{CAFEEFAC-0014-0002-0021-ABCDEFFEDCBB}\InprocServer32
    [.] Found hidden value:
    [REG_SZ] (Standard)
    C:\Program Files\Java\jre6\bin\jp2iexp.dll
    [.] Found hidden value:
    [REG_SZ] ThreadingModel
    Apartment
    [*] Found hidden key: HKEY_USERS\S-1-5-21-839522115-1965331169-1417001333-1003_Classes\CLSID\{CAFEEFAC-0014-0002-0022-ABCDEFFEDCBA}
    [.] Found hidden value:
    [REG_SZ] (Standard)
    Java Plug-in 1.4.2_22
    [*] Found hidden key: HKEY_USERS\S-1-5-21-839522115-1965331169-1417001333-1003_Classes\CLSID\{CAFEEFAC-0014-0002-0022-ABCDEFFEDCBA}\InprocServer32
    [.] Found hidden value:
    [REG_SZ] (Standard)
    C:\Program Files\Java\jre6\bin\jp2iexp.dll
    [.] Found hidden value:
    [REG_SZ] ThreadingModel
    Apartment
    [*] Found hidden key: HKEY_USERS\S-1-5-21-839522115-1965331169-1417001333-1003_Classes\CLSID\{CAFEEFAC-0014-0002-0022-ABCDEFFEDCBB}
    [.] Found hidden value:
    [REG_SZ] (Standard)
    Java Plug-in 1.4.2_22
    [*] Found hidden key: HKEY_USERS\S-1-5-21-839522115-1965331169-1417001333-1003_Classes\CLSID\{CAFEEFAC-0014-0002-0022-ABCDEFFEDCBB}\InprocServer32
    [.] Found hidden value:
    [REG_SZ] (Standard)
    C:\Program Files\Java\jre6\bin\jp2iexp.dll
    [.] Found hidden value:
    [REG_SZ] ThreadingModel
    Apartment
    [*] Found hidden key: HKEY_USERS\S-1-5-21-839522115-1965331169-1417001333-1003_Classes\CLSID\{CAFEEFAC-0014-0002-0023-ABCDEFFEDCBA}
    [.] Found hidden value:
    [REG_SZ] (Standard)
    Java Plug-in 1.4.2_23
    [*] Found hidden key: HKEY_USERS\S-1-5-21-839522115-1965331169-1417001333-1003_Classes\CLSID\{CAFEEFAC-0014-0002-0023-ABCDEFFEDCBA}\InprocServer32
    [.] Found hidden value:
    [REG_SZ] (Standard)
    C:\Program Files\Java\jre6\bin\jp2iexp.dll
    [.] Found hidden value:
    [REG_SZ] ThreadingModel
    Apartment
    [*] Found hidden key: HKEY_USERS\S-1-5-21-839522115-1965331169-1417001333-1003_Classes\CLSID\{CAFEEFAC-0014-0002-0023-ABCDEFFEDCBB}
    [.] Found hidden value:
    [REG_SZ] (Standard)
    Java Plug-in 1.4.2_23
    [*] Found hidden key: HKEY_USERS\S-1-5-21-839522115-1965331169-1417001333-1003_Classes\CLSID\{CAFEEFAC-0014-0002-0023-ABCDEFFEDCBB}\InprocServer32
    [.] Found hidden value:
    [REG_SZ] (Standard)
    C:\Program Files\Java\jre6\bin\jp2iexp.dll
    [.] Found hidden value:
    [REG_SZ] ThreadingModel
    Apartment
    [*] Found hidden key: HKEY_USERS\S-1-5-21-839522115-1965331169-1417001333-1003_Classes\CLSID\{CAFEEFAC-0014-0002-0024-ABCDEFFEDCBA}
    [.] Found hidden value:
    [REG_SZ] (Standard)
    Java Plug-in 1.4.2_24
    [*] Found hidden key: HKEY_USERS\S-1-5-21-839522115-1965331169-1417001333-1003_Classes\CLSID\{CAFEEFAC-0014-0002-0024-ABCDEFFEDCBA}\InprocServer32
    [.] Found hidden value:
    [REG_SZ] (Standard)
    C:\Program Files\Java\jre6\bin\jp2iexp.dll
    [.] Found hidden value:
    [REG_SZ] ThreadingModel
    Apartment
    [*] Found hidden key: HKEY_USERS\S-1-5-21-839522115-1965331169-1417001333-1003_Classes\CLSID\{CAFEEFAC-0014-0002-0024-ABCDEFFEDCBB}
    [.] Found hidden value:
    [REG_SZ] (Standard)
    Java Plug-in 1.4.2_24
    [*] Found hidden key: HKEY_USERS\S-1-5-21-839522115-1965331169-1417001333-1003_Classes\CLSID\{CAFEEFAC-0014-0002-0024-ABCDEFFEDCBB}\InprocServer32
    [.] Found hidden value:
    [REG_SZ] (Standard)
    C:\Program Files\Java\jre6\bin\jp2iexp.dll
    [.] Found hidden value:
    [REG_SZ] ThreadingModel
    Apartment
    [*] Found hidden key: HKEY_USERS\S-1-5-21-839522115-1965331169-1417001333-1003_Classes\CLSID\{CAFEEFAC-0014-0002-0025-ABCDEFFEDCBA}
    [.] Found hidden value:
    [REG_SZ] (Standard)
    Java Plug-in 1.4.2_25
    [*] Found hidden key: HKEY_USERS\S-1-5-21-839522115-1965331169-1417001333-1003_Classes\CLSID\{CAFEEFAC-0014-0002-0025-ABCDEFFEDCBA}\InprocServer32
    [.] Found hidden value:
    [REG_SZ] (Standard)
    C:\Program Files\Java\jre6\bin\jp2iexp.dll
    [.] Found hidden value:
    [REG_SZ] ThreadingModel
    Apartment
    [*] Found hidden key: HKEY_USERS\S-1-5-21-839522115-1965331169-1417001333-1003_Classes\CLSID\{CAFEEFAC-0014-0002-0025-ABCDEFFEDCBB}
    [.] Found hidden value:
    [REG_SZ] (Standard)
    Java Plug-in 1.4.2_25
    [*] Found hidden key: HKEY_USERS\S-1-5-21-839522115-1965331169-1417001333-1003_Classes\CLSID\{CAFEEFAC-0014-0002-0025-ABCDEFFEDCBB}\InprocServer32
    [.] Found hidden value:
    [REG_SZ] (Standard)
    C:\Program Files\Java\jre6\bin\jp2iexp.dll
    [.] Found hidden value:
    [REG_SZ] ThreadingModel
    Apartment
    [*] Found hidden key: HKEY_USERS\S-1-5-21-839522115-1965331169-1417001333-1003_Classes\CLSID\{CAFEEFAC-0014-0002-0026-ABCDEFFEDCBA}
    [.] Found hidden value:
    [REG_SZ] (Standard)
    Java Plug-in 1.4.2_26
    [*] Found hidden key: HKEY_USERS\S-1-5-21-839522115-1965331169-1417001333-1003_Classes\CLSID\{CAFEEFAC-0014-0002-0026-ABCDEFFEDCBA}\InprocServer32
    [.] Found hidden value:
    [REG_SZ] (Standard)
    C:\Program Files\Java\jre6\bin\jp2iexp.dll
    [.] Found hidden value:
    [REG_SZ] ThreadingModel
    Apartment
    [*] Found hidden key: HKEY_USERS\S-1-5-21-839522115-1965331169-1417001333-1003_Classes\CLSID\{CAFEEFAC-0014-0002-0026-ABCDEFFEDCBB}
    [.] Found hidden value:
    [REG_SZ] (Standard)
    Java Plug-in 1.4.2_26
    [*] Found hidden key: HKEY_USERS\S-1-5-21-839522115-1965331169-1417001333-1003_Classes\CLSID\{CAFEEFAC-0014-0002-0026-ABCDEFFEDCBB}\InprocServer32
    [.] Found hidden value:
    [REG_SZ] (Standard)
    C:\Program Files\Java\jre6\bin\jp2iexp.dll
    [.] Found hidden value:
    [REG_SZ] ThreadingModel
    Apartment
    [*] Found hidden key: HKEY_USERS\S-1-5-21-839522115-1965331169-1417001333-1003_Classes\CLSID\{CAFEEFAC-0014-0002-0027-ABCDEFFEDCBA}
    [.] Found hidden value:
    [REG_SZ] (Standard)
    Java Plug-in 1.4.2_27
    [*] Found hidden key: HKEY_USERS\S-1-5-21-839522115-1965331169-1417001333-1003_Classes\CLSID\{CAFEEFAC-0014-0002-0027-ABCDEFFEDCBA}\InprocServer32
    [.] Found hidden value:
    [REG_SZ] (Standard)
    C:\Program Files\Java\jre6\bin\jp2iexp.dll
    [.] Found hidden value:
    [REG_SZ] ThreadingModel
    Apartment
    [*] Found hidden key: HKEY_USERS\S-1-5-21-839522115-1965331169-1417001333-1003_Classes\CLSID\{CAFEEFAC-0014-0002-0027-ABCDEFFEDCBB}
    [.] Found hidden value:
    [REG_SZ] (Standard)
    Java Plug-in 1.4.2_27
    [*] Found hidden key: HKEY_USERS\S-1-5-21-839522115-1965331169-1417001333-1003_Classes\CLSID\{CAFEEFAC-0014-0002-0027-ABCDEFFEDCBB}\InprocServer32
    [.] Found hidden value:
    [REG_SZ] (Standard)
    C:\Program Files\Java\jre6\bin\jp2iexp.dll
    [.] Found hidden value:
    [REG_SZ] ThreadingModel
    Apartment
    [*] Found hidden key: HKEY_USERS\S-1-5-21-839522115-1965331169-1417001333-1003_Classes\CLSID\{CAFEEFAC-0014-0002-0028-ABCDEFFEDCBA}
    [.] Found hidden value:
    [REG_SZ] (Standard)
    Java Plug-in 1.4.2_28
    [*] Found hidden key: HKEY_USERS\S-1-5-21-839522115-1965331169-1417001333-1003_Classes\CLSID\{CAFEEFAC-0014-0002-0028-ABCDEFFEDCBA}\InprocServer32
    [.] Found hidden value:
    [REG_SZ] (Standard)
    C:\Program Files\Java\jre6\bin\jp2iexp.dll
    [.] Found hidden value:
    [REG_SZ] ThreadingModel
    Apartment
    [*] Found hidden key: HKEY_USERS\S-1-5-21-839522115-1965331169-1417001333-1003_Classes\CLSID\{CAFEEFAC-0014-0002-0028-ABCDEFFEDCBB}
    [.] Found hidden value:
    [REG_SZ] (Standard)
    Java Plug-in 1.4.2_28
    [*] Found hidden key: HKEY_USERS\S-1-5-21-839522115-1965331169-1417001333-1003_Classes\CLSID\{CAFEEFAC-0014-0002-0028-ABCDEFFEDCBB}\InprocServer32
    [.] Found hidden value:
    [REG_SZ] (Standard)
    C:\Program Files\Java\jre6\bin\jp2iexp.dll
    [.] Found hidden value:
    [REG_SZ] ThreadingModel
    Apartment
    [*] Found hidden key: HKEY_USERS\S-1-5-21-839522115-1965331169-1417001333-1003_Classes\CLSID\{CAFEEFAC-0014-0002-0029-ABCDEFFEDCBA}
    [.] Found hidden value:
    [REG_SZ] (Standard)
    Java Plug-in 1.4.2_29
    [*] Found hidden key: HKEY_USERS\S-1-5-21-839522115-1965331169-1417001333-1003_Classes\CLSID\{CAFEEFAC-0014-0002-0029-ABCDEFFEDCBA}\InprocServer32
    [.] Found hidden value:
    [REG_SZ] (Standard)
    C:\Program Files\Java\jre6\bin\jp2iexp.dll
    [.] Found hidden value:
    [REG_SZ] ThreadingModel
    Apartment
    [*] Found hidden key: HKEY_USERS\S-1-5-21-839522115-1965331169-1417001333-1003_Classes\CLSID\{CAFEEFAC-0014-0002-0029-ABCDEFFEDCBB}
    [.] Found hidden value:
    [REG_SZ] (Standard)
    Java Plug-in 1.4.2_29
    [*] Found hidden key: HKEY_USERS\S-1-5-21-839522115-1965331169-1417001333-1003_Classes\CLSID\{CAFEEFAC-0014-0002-0029-ABCDEFFEDCBB}\InprocServer32
    [.] Found hidden value:
    [REG_SZ] (Standard)
    C:\Program Files\Java\jre6\bin\jp2iexp.dll
    [.] Found hidden value:
    [REG_SZ] ThreadingModel
    Apartment
    [*] Found hidden key: HKEY_USERS\S-1-5-21-839522115-1965331169-1417001333-1003_Classes\CLSID\{CAFEEFAC-0014-0002-0030-ABCDEFFEDCBA}
    [.] Found hidden value:
    [REG_SZ] (Standard)
    Java Plug-in 1.4.2_30
    [*] Found hidden key: HKEY_USERS\S-1-5-21-839522115-1965331169-1417001333-1003_Classes\CLSID\{CAFEEFAC-0014-0002-0030-ABCDEFFEDCBA}\InprocServer32
    [.] Found hidden value:
    [REG_SZ] (Standard)
    C:\Program Files\Java\jre6\bin\jp2iexp.dll
    [.] Found hidden value:
    [REG_SZ] ThreadingModel
    Apartment
    [*] Found hidden key: HKEY_USERS\S-1-5-21-839522115-1965331169-1417001333-1003_Classes\CLSID\{CAFEEFAC-0014-0002-0030-ABCDEFFEDCBB}
    [.] Found hidden value:
    [REG_SZ] (Standard)
    Java Plug-in 1.4.2_30
    [*] Found hidden key: HKEY_USERS\S-1-5-21-839522115-1965331169-1417001333-1003_Classes\CLSID\{CAFEEFAC-0014-0002-0030-ABCDEFFEDCBB}\InprocServer32
    [.] Found hidden value:
    [REG_SZ] (Standard)
    C:\Program Files\Java\jre6\bin\jp2iexp.dll
    [.] Found hidden value:
    [REG_SZ] ThreadingModel
    Apartment
    [*] Found hidden key: HKEY_USERS\S-1-5-21-839522115-1965331169-1417001333-1003_Classes\CLSID\{CAFEEFAC-0014-0002-FFFF-ABCDEFFEDCBA}
    [.] Found hidden value:
    [REG_SZ] (Standard)
    Java Plug-in 1.4.2
    [*] Found hidden key: HKEY_USERS\S-1-5-21-839522115-1965331169-1417001333-1003_Classes\CLSID\{CAFEEFAC-0014-0002-FFFF-ABCDEFFEDCBA}\InprocServer32
    [.] Found hidden value:
    [REG_SZ] (Standard)
    C:\Program Files\Java\jre6\bin\jp2iexp.dll
    [.] Found hidden value:
    [REG_SZ] ThreadingModel
    Apartment
    [*] Found hidden key: HKEY_USERS\S-1-5-21-839522115-1965331169-1417001333-1003_Classes\CLSID\{CAFEEFAC-0015-0000-0000-ABCDEFFEDCBA}
    [.] Found hidden value:
    [REG_SZ] (Standard)
    Java Plug-in 1.5.0
    [*] Found hidden key: HKEY_USERS\S-1-5-21-839522115-1965331169-1417001333-1003_Classes\CLSID\{CAFEEFAC-0015-0000-0000-ABCDEFFEDCBA}\InprocServer32
    [.] Found hidden value:
    [REG_SZ] (Standard)
    C:\Program Files\Java\jre6\bin\jp2iexp.dll
    [.] Found hidden value:
    [REG_SZ] ThreadingModel
    Apartment
    [*] Found hidden key: HKEY_USERS\S-1-5-21-839522115-1965331169-1417001333-1003_Classes\CLSID\{CAFEEFAC-0015-0000-0000-ABCDEFFEDCBB}
    [.] Found hidden value:
    [REG_SZ] (Standard)
    Java Plug-in 1.5.0
    [*] Found hidden key: HKEY_USERS\S-1-5-21-839522115-1965331169-1417001333-1003_Classes\CLSID\{CAFEEFAC-0015-0000-0000-ABCDEFFEDCBB}\InprocServer32
    [.] Found hidden value:
    [REG_SZ] (Standard)
    C:\Program Files\Java\jre6\bin\jp2iexp.dll
    [.] Found hidden value:
    [REG_SZ] ThreadingModel
    Apartment
    [*] Found hidden key: HKEY_USERS\S-1-5-21-839522115-1965331169-1417001333-1003_Classes\CLSID\{CAFEEFAC-0015-0000-0000-ABCDEFFEDCBC}
    [.] Found hidden value:
    [REG_SZ] (Standard)
    Java Plug-in 1.5.0
    [*] Found hidden key: HKEY_USERS\S-1-5-21-839522115-1965331169-1417001333-1003_Classes\CLSID\{CAFEEFAC-0015-0000-0000-ABCDEFFEDCBC}\InprocServer32
    [.] Found hidden value:
    [REG_SZ] (Standard)
    C:\Program Files\Java\jre6\bin\jp2iexp.dll
    [.] Found hidden value:
    [REG_SZ] ThreadingModel
    Apartment
    [*] Found hidden key: HKEY_USERS\S-1-5-21-839522115-1965331169-1417001333-1003_Classes\CLSID\{CAFEEFAC-0015-0000-0001-ABCDEFFEDCBA}
    [.] Found hidden value:
    [REG_SZ] (Standard)
    Java Plug-in 1.5.0_01
    [*] Found hidden key: HKEY_USERS\S-1-5-21-839522115-1965331169-1417001333-1003_Classes\CLSID\{CAFEEFAC-0015-0000-0001-ABCDEFFEDCBA}\InprocServer32
    [.] Found hidden value:
    [REG_SZ] (Standard)
    C:\Program Files\Java\jre6\bin\jp2iexp.dll
    [.] Found hidden value:
    [REG_SZ] ThreadingModel
    Apartment
    [*] Found hidden key: HKEY_USERS\S-1-5-21-839522115-1965331169-1417001333-1003_Classes\CLSID\{CAFEEFAC-0015-0000-0001-ABCDEFFEDCBB}
    [.] Found hidden value:
    [REG_SZ] (Standard)
    Java Plug-in 1.5.0_01
    [*] Found hidden key: HKEY_USERS\S-1-5-21-839522115-1965331169-1417001333-1003_Classes\CLSID\{CAFEEFAC-0015-0000-0001-ABCDEFFEDCBB}\InprocServer32
    [.] Found hidden value:
    [REG_SZ] (Standard)
    C:\Program Files\Java\jre6\bin\jp2iexp.dll
    [.] Found hidden value:
    [REG_SZ] ThreadingModel
    Apartment
    [*] Found hidden key: HKEY_USERS\S-1-5-21-839522115-1965331169-1417001333-1003_Classes\CLSID\{CAFEEFAC-0015-0000-0001-ABCDEFFEDCBC}
    [.] Found hidden value:
    [REG_SZ] (Standard)
    Java Plug-in 1.5.0_01
    [*] Found hidden key: HKEY_USERS\S-1-5-21-839522115-1965331169-1417001333-1003_Classes\CLSID\{CAFEEFAC-0015-0000-0001-ABCDEFFEDCBC}\InprocServer32
    [.] Found hidden value:
    [REG_SZ] (Standard)
    C:\Program Files\Java\jre6\bin\jp2iexp.dll
    [.] Found hidden value:
    [REG_SZ] ThreadingModel
    Apartment
    [*] Found hidden key: HKEY_USERS\S-1-5-21-839522115-1965331169-1417001333-1003_Classes\CLSID\{CAFEEFAC-0015-0000-0002-ABCDEFFEDCBA}
    [.] Found hidden value:
    [REG_SZ] (Standard)
    Java Plug-in 1.5.0_02
    [*] Found hidden key: HKEY_USERS\S-1-5-21-839522115-1965331169-1417001333-1003_Classes\CLSID\{CAFEEFAC-0015-0000-0002-ABCDEFFEDCBA}\InprocServer32
    [.] Found hidden value:
    [REG_SZ] (Standard)
    C:\Program Files\Java\jre6\bin\jp2iexp.dll
    [.] Found hidden value:
    [REG_SZ] ThreadingModel
    Apartment
    [*] Found hidden key: HKEY_USERS\S-1-5-21-839522115-1965331169-1417001333-1003_Classes\CLSID\{CAFEEFAC-0015-0000-0002-ABCDEFFEDCBB}
    [.] Found hidden value:
    [REG_SZ] (Standard)
    Java Plug-in 1.5.0_02
    [*] Found hidden key: HKEY_USERS\S-1-5-21-839522115-1965331169-1417001333-1003_Classes\CLSID\{CAFEEFAC-0015-0000-0002-ABCDEFFEDCBB}\InprocServer32
    [.] Found hidden value:
    [REG_SZ] (Standard)
    C:\Program Files\Java\jre6\bin\jp2iexp.dll
    [.] Found hidden value:
    [REG_SZ] ThreadingModel
    Apartment
    [*] Found hidden key: HKEY_USERS\S-1-5-21-839522115-1965331169-1417001333-1003_Classes\CLSID\{CAFEEFAC-0015-0000-0002-ABCDEFFEDCBC}
    [.] Found hidden value:
    [REG_SZ] (Standard)
    Java Plug-in 1.5.0_02
    [*] Found hidden key: HKEY_USERS\S-1-5-21-839522115-1965331169-1417001333-1003_Classes\CLSID\{CAFEEFAC-0015-0000-0002-ABCDEFFEDCBC}\InprocServer32
    [.] Found hidden value:
    [REG_SZ] (Standard)
    C:\Program Files\Java\jre6\bin\jp2iexp.dll
    [.] Found hidden value:
    [REG_SZ] ThreadingModel
    Apartment
    [*] Found hidden key: HKEY_USERS\S-1-5-21-839522115-1965331169-1417001333-1003_Classes\CLSID\{CAFEEFAC-0015-0000-0003-ABCDEFFEDCBA}
    [.] Found hidden value:
    [REG_SZ] (Standard)
    Java Plug-in 1.5.0_03
    [*] Found hidden key: HKEY_USERS\S-1-5-21-839522115-1965331169-1417001333-1003_Classes\CLSID\{CAFEEFAC-0015-0000-0003-ABCDEFFEDCBA}\InprocServer32
    [.] Found hidden value:
    [REG_SZ] (Standard)
    C:\Program Files\Java\jre6\bin\jp2iexp.dll
    [.] Found hidden value:
    [REG_SZ] ThreadingModel
    Apartment
    [*] Found hidden key: HKEY_USERS\S-1-5-21-839522115-1965331169-1417001333-1003_Classes\CLSID\{CAFEEFAC-0015-0000-0003-ABCDEFFEDCBB}
    [.] Found hidden value:
    [REG_SZ] (Standard)
    Java Plug-in 1.5.0_03
    [*] Found hidden key: HKEY_USERS\S-1-5-21-839522115-1965331169-1417001333-1003_Classes\CLSID\{CAFEEFAC-0015-0000-0003-ABCDEFFEDCBB}\InprocServer32
    [.] Found hidden value:
    [REG_SZ] (Standard)
    C:\Program Files\Java\jre6\bin\jp2iexp.dll
    [.] Found hidden value:
    [REG_SZ] ThreadingModel
    Apartment
    [*] Found hidden key: HKEY_USERS\S-1-5-21-839522115-1965331169-1417001333-1003_Classes\CLSID\{CAFEEFAC-0015-0000-0003-ABCDEFFEDCBC}
    [.] Found hidden value:
    [REG_SZ] (Standard)
    Java Plug-in 1.5.0_03
    [*] Found hidden key: HKEY_USERS\S-1-5-21-839522115-1965331169-1417001333-1003_Classes\CLSID\{CAFEEFAC-0015-0000-0003-ABCDEFFEDCBC}\InprocServer32
    [.] Found hidden value:
    [REG_SZ] (Standard)
    C:\Program Files\Java\jre6\bin\jp2iexp.dll
    [.] Found hidden value:
    [REG_SZ] ThreadingModel
    Apartment
    [*] Found hidden key: HKEY_USERS\S-1-5-21-839522115-1965331169-1417001333-1003_Classes\CLSID\{CAFEEFAC-0015-0000-0004-ABCDEFFEDCBA}
    [.] Found hidden value:
    [REG_SZ] (Standard)
    Java Plug-in 1.5.0_04
    [*] Found hidden key: HKEY_USERS\S-1-5-21-839522115-1965331169-1417001333-1003_Classes\CLSID\{CAFEEFAC-0015-0000-0004-ABCDEFFEDCBA}\InprocServer32
    [.] Found hidden value:
    [REG_SZ] (Standard)
    C:\Program Files\Java\jre6\bin\jp2iexp.dll
    [.] Found hidden value:
    [REG_SZ] ThreadingModel
    Apartment
    [*] Found hidden key: HKEY_USERS\S-1-5-21-839522115-1965331169-1417001333-1003_Classes\CLSID\{CAFEEFAC-0015-0000-0004-ABCDEFFEDCBB}
    [.] Found hidden value:
    [REG_SZ] (Standard)
    Java Plug-in 1.5.0_04
    [*] Found hidden key: HKEY_USERS\S-1-5-21-839522115-1965331169-1417001333-1003_Classes\CLSID\{CAFEEFAC-0015-0000-0004-ABCDEFFEDCBB}\InprocServer32
    [.] Found hidden value:
    [REG_SZ] (Standard)
    C:\Program Files\Java\jre6\bin\jp2iexp.dll
    [.] Found hidden value:
    [REG_SZ] ThreadingModel
    Apartment
    [*] Found hidden key: HKEY_USERS\S-1-5-21-839522115-1965331169-1417001333-1003_Classes\CLSID\{CAFEEFAC-0015-0000-0004-ABCDEFFEDCBC}
    [.] Found hidden value:
    [REG_SZ] (Standard)
    Java Plug-in 1.5.0_04
    [*] Found hidden key: HKEY_USERS\S-1-5-21-839522115-1965331169-1417001333-1003_Classes\CLSID\{CAFEEFAC-0015-0000-0004-ABCDEFFEDCBC}\InprocServer32
    [.] Found hidden value:
    [REG_SZ] (Standard)
    C:\Program Files\Java\jre6\bin\jp2iexp.dll
    [.] Found hidden value:
    [REG_SZ] ThreadingModel
    Apartment
    [*] Found hidden key: HKEY_USERS\S-1-5-21-839522115-1965331169-1417001333-1003_Classes\CLSID\{CAFEEFAC-0015-0000-0005-ABCDEFFEDCBA}
    [.] Found hidden value:
    [REG_SZ] (Standard)
    Java Plug-in 1.5.0_05
    [*] Found hidden key: HKEY_USERS\S-1-5-21-839522115-1965331169-1417001333-1003_Classes\CLSID\{CAFEEFAC-0015-0000-0005-ABCDEFFEDCBA}\InprocServer32
    [.] Found hidden value:
    [REG_SZ] (Standard)
    C:\Program Files\Java\jre6\bin\jp2iexp.dll
    [.] Found hidden value:
    [REG_SZ] ThreadingModel
    Apartment
    [*] Found hidden key: HKEY_USERS\S-1-5-21-839522115-1965331169-1417001333-1003_Classes\CLSID\{CAFEEFAC-0015-0000-0005-ABCDEFFEDCBB}
    [.] Found hidden value:
    [REG_SZ] (Standard)
    Java Plug-in 1.5.0_05
    [*] Found hidden key: HKEY_USERS\S-1-5-21-839522115-1965331169-1417001333-1003_Classes\CLSID\{CAFEEFAC-0015-0000-0005-ABCDEFFEDCBB}\InprocServer32
    [.] Found hidden value:
    [REG_SZ] (Standard)
    C:\Program Files\Java\jre6\bin\jp2iexp.dll
    [.] Found hidden value:
    [REG_SZ] ThreadingModel
    Apartment
    [*] Found hidden key: HKEY_USERS\S-1-5-21-839522115-1965331169-1417001333-1003_Classes\CLSID\{CAFEEFAC-0015-0000-0005-ABCDEFFEDCBC}
    [.] Found hidden value:
    [REG_SZ] (Standard)
    Java Plug-in 1.5.0_05
    [*] Found hidden key: HKEY_USERS\S-1-5-21-839522115-1965331169-1417001333-1003_Classes\CLSID\{CAFEEFAC-0015-0000-0005-ABCDEFFEDCBC}\InprocServer32
    [.] Found hidden value:
    [REG_SZ] (Standard)
    C:\Program Files\Java\jre6\bin\jp2iexp.dll
    [.] Found hidden value:
    [REG_SZ] ThreadingModel
    Apartment
    [*] Found hidden key: HKEY_USERS\S-1-5-21-839522115-1965331169-1417001333-1003_Classes\CLSID\{CAFEEFAC-0015-0000-0006-ABCDEFFEDCBA}
    [.] Found hidden value:
    [REG_SZ] (Standard)
    Java Plug-in 1.5.0_06
    [*] Found hidden key: HKEY_USERS\S-1-5-21-839522115-1965331169-1417001333-1003_Classes\CLSID\{CAFEEFAC-0015-0000-0006-ABCDEFFEDCBA}\InprocServer32
    [.] Found hidden value:
    [REG_SZ] (Standard)
    C:\Program Files\Java\jre6\bin\jp2iexp.dll
    [.] Found hidden value:
    [REG_SZ] ThreadingModel
    Apartment
    [*] Found hidden key: HKEY_USERS\S-1-5-21-839522115-1965331169-1417001333-1003_Classes\CLSID\{CAFEEFAC-0015-0000-0006-ABCDEFFEDCBB}
    [.] Found hidden value:
    [REG_SZ] (Standard)
    Java Plug-in 1.5.0_06
    [*] Found hidden key: HKEY_USERS\S-1-5-21-839522115-1965331169-1417001333-1003_Classes\CLSID\{CAFEEFAC-0015-0000-0006-ABCDEFFEDCBB}\InprocServer32
    [.] Found hidden value:
    [REG_SZ] (Standard)
    C:\Program Files\Java\jre6\bin\jp2iexp.dll
    [.] Found hidden value:
    [REG_SZ] ThreadingModel
    Apartment
    [*] Found hidden key: HKEY_USERS\S-1-5-21-839522115-1965331169-1417001333-1003_Classes\CLSID\{CAFEEFAC-0015-0000-0006-ABCDEFFEDCBC}
    [.] Found hidden value:
    [REG_SZ] (Standard)
    Java Plug-in 1.5.0_06
    [*] Found hidden key: HKEY_USERS\S-1-5-21-839522115-1965331169-1417001333-1003_Classes\CLSID\{CAFEEFAC-0015-0000-0006-ABCDEFFEDCBC}\InprocServer32
    [.] Found hidden value:
    [REG_SZ] (Standard)
    C:\Program Files\Java\jre6\bin\jp2iexp.dll
    [.] Found hidden value:
    [REG_SZ] ThreadingModel
    Apartment
    [*] Found hidden key: HKEY_USERS\S-1-5-21-839522115-1965331169-1417001333-1003_Classes\CLSID\{CAFEEFAC-0015-0000-0007-ABCDEFFEDCBA}
    [.] Found hidden value:
    [REG_SZ] (Standard)
    Java Plug-in 1.5.0_07
    [*] Found hidden key: HKEY_USERS\S-1-5-21-839522115-1965331169-1417001333-1003_Classes\CLSID\{CAFEEFAC-0015-0000-0007-ABCDEFFEDCBA}\InprocServer32
    [.] Found hidden value:
    [REG_SZ] (Standard)
    C:\Program Files\Java\jre6\bin\jp2iexp.dll
    [.] Found hidden value:
    [REG_SZ] ThreadingModel
    Apartment
    [*] Found hidden key: HKEY_USERS\S-1-5-21-839522115-1965331169-1417001333-1003_Classes\CLSID\{CAFEEFAC-0015-0000-0007-ABCDEFFEDCBB}
    [.] Found hidden value:
    [REG_SZ] (Standard)
    Java Plug-in 1.5.0_07
    [*] Found hidden key: HKEY_USERS\S-1-5-21-839522115-1965331169-1417001333-1003_Classes\CLSID\{CAFEEFAC-0015-0000-0007-ABCDEFFEDCBB}\InprocServer32
    [.] Found hidden value:
    [REG_SZ] (Standard)
    C:\Program Files\Java\jre6\bin\jp2iexp.dll
    [.] Found hidden value:
    [REG_SZ] ThreadingModel
    Apartment
    [*] Found hidden key: HKEY_USERS\S-1-5-21-839522115-1965331169-1417001333-1003_Classes\CLSID\{CAFEEFAC-0015-0000-0007-ABCDEFFEDCBC}
    [.] Found hidden value:
    [REG_SZ] (Standard)
    Java Plug-in 1.5.0_07
    [*] Found hidden key: HKEY_USERS\S-1-5-21-839522115-1965331169-1417001333-1003_Classes\CLSID\{CAFEEFAC-0015-0000-0007-ABCDEFFEDCBC}\InprocServer32
    [.] Found hidden value:
    [REG_SZ] (Standard)
    C:\Program Files\Java\jre6\bin\jp2iexp.dll
    [.] Found hidden value:
    [REG_SZ] ThreadingModel
    Apartment
    [*] Found hidden key: HKEY_USERS\S-1-5-21-839522115-1965331169-1417001333-1003_Classes\CLSID\{CAFEEFAC-0015-0000-0008-ABCDEFFEDCBA}
    [.] Found hidden value:
    [REG_SZ] (Standard)
    Java Plug-in 1.5.0_08
    [*] Found hidden key: HKEY_USERS\S-1-5-21-839522115-1965331169-1417001333-1003_Classes\CLSID\{CAFEEFAC-0015-0000-0008-ABCDEFFEDCBA}\InprocServer32
    [.] Found hidden value:
    [REG_SZ] (Standard)
    C:\Program Files\Java\jre6\bin\jp2iexp.dll
    [.] Found hidden value:
    [REG_SZ] ThreadingModel
    Apartment
    [*] Found hidden key: HKEY_USERS\S-1-5-21-839522115-1965331169-1417001333-1003_Classes\CLSID\{CAFEEFAC-0015-0000-0008-ABCDEFFEDCBB}
    [.] Found hidden value:
    [REG_SZ] (Standard)
    Java Plug-in 1.5.0_08
    [*] Found hidden key: HKEY_USERS\S-1-5-21-839522115-1965331169-1417001333-1003_Classes\CLSID\{CAFEEFAC-0015-0000-0008-ABCDEFFEDCBB}\InprocServer32
    [.] Found hidden value:
    [REG_SZ] (Standard)
    C:\Program Files\Java\jre6\bin\jp2iexp.dll
    [.] Found hidden value:
    [REG_SZ] ThreadingModel
    Apartment
    [*] Found hidden key: HKEY_USERS\S-1-5-21-839522115-1965331169-1417001333-1003_Classes\CLSID\{CAFEEFAC-0015-0000-0008-ABCDEFFEDCBC}
    [.] Found hidden value:
    [REG_SZ] (Standard)
    Java Plug-in 1.5.0_08
    [*] Found hidden key: HKEY_USERS\S-1-5-21-839522115-1965331169-1417001333-1003_Classes\CLSID\{CAFEEFAC-0015-0000-0008-ABCDEFFEDCBC}\InprocServer32
    [.] Found hidden value:
    [REG_SZ] (Standard)
    C:\Program Files\Java\jre6\bin\jp2iexp.dll
    [.] Found hidden value:
    [REG_SZ] ThreadingModel
    Apartment
    [*] Found hidden key: HKEY_USERS\S-1-5-21-839522115-1965331169-1417001333-1003_Classes\CLSID\{CAFEEFAC-0015-0000-0009-ABCDEFFEDCBA}
    [.] Found hidden value:
    [REG_SZ] (Standard)
    Java Plug-in 1.5.0_09
    [*] Found hidden key: HKEY_USERS\S-1-5-21-839522115-1965331169-1417001333-1003_Classes\CLSID\{CAFEEFAC-0015-0000-0009-ABCDEFFEDCBA}\InprocServer32
    [.] Found hidden value:
    [REG_SZ] (Standard)
    C:\Program Files\Java\jre6\bin\jp2iexp.dll
    [.] Found hidden value:
    [REG_SZ] ThreadingModel
    Apartment
    [*] Found hidden key: HKEY_USERS\S-1-5-21-839522115-1965331169-1417001333-1003_Classes\CLSID\{CAFEEFAC-0015-0000-0009-ABCDEFFEDCBB}
    [.] Found hidden value:
    [REG_SZ] (Standard)
    Java Plug-in 1.5.0_09
    [*] Found hidden key: HKEY_USERS\S-1-5-21-839522115-1965331169-1417001333-1003_Classes\CLSID\{CAFEEFAC-0015-0000-0009-ABCDEFFEDCBB}\InprocServer32
    [.] Found hidden value:
    [REG_SZ] (Standard)
    C:\Program Files\Java\jre6\bin\jp2iexp.dll
    [.] Found hidden value:
    [REG_SZ] ThreadingModel
    Apartment
    [*] Found hidden key: HKEY_USERS\S-1-5-21-839522115-1965331169-1417001333-1003_Classes\CLSID\{CAFEEFAC-0015-0000-0009-ABCDEFFEDCBC}
    [.] Found hidden value:
    [REG_SZ] (Standard)
    Java Plug-in 1.5.0_09
    [*] Found hidden key: HKEY_USERS\S-1-5-21-839522115-1965331169-1417001333-1003_Classes\CLSID\{CAFEEFAC-0015-0000-0009-ABCDEFFEDCBC}\InprocServer32
    [.] Found hidden value:
    [REG_SZ] (Standard)
    C:\Program Files\Java\jre6\bin\jp2iexp.dll
    [.] Found hidden value:
    [REG_SZ] ThreadingModel
    Apartment
    [*] Found hidden key: HKEY_USERS\S-1-5-21-839522115-1965331169-1417001333-1003_Classes\CLSID\{CAFEEFAC-0015-0000-0010-ABCDEFFEDCBA}
    [.] Found hidden value:
    [REG_SZ] (Standard)
    Java Plug-in 1.5.0_10
    [*] Found hidden key: HKEY_USERS\S-1-5-21-839522115-1965331169-1417001333-1003_Classes\CLSID\{CAFEEFAC-0015-0000-0010-ABCDEFFEDCBA}\InprocServer32
    [.] Found hidden value:
    [REG_SZ] (Standard)
    C:\Program Files\Java\jre6\bin\jp2iexp.dll
    [.] Found hidden value:
    [REG_SZ] ThreadingModel
    Apartment
    [*] Found hidden key: HKEY_USERS\S-1-5-21-839522115-1965331169-1417001333-1003_Classes\CLSID\{CAFEEFAC-0015-0000-0010-ABCDEFFEDCBB}
    [.] Found hidden value:
    [REG_SZ] (Standard)
    Java Plug-in 1.5.0_10
    [*] Found hidden key: HKEY_USERS\S-1-5-21-839522115-1965331169-1417001333-1003_Classes\CLSID\{CAFEEFAC-0015-0000-0010-ABCDEFFEDCBB}\InprocServer32
    [.] Found hidden value:
    [REG_SZ] (Standard)

    73 Re: Malware problems and Internet Redirecting on Sat Aug 07, 2010 7:09 pm

    blink711


    Member
    Member
    C:\Program Files\Java\jre6\bin\jp2iexp.dll
    [.] Found hidden value:
    [REG_SZ] ThreadingModel
    Apartment
    [*] Found hidden key: HKEY_USERS\S-1-5-21-839522115-1965331169-1417001333-1003_Classes\CLSID\{CAFEEFAC-0015-0000-0010-ABCDEFFEDCBC}
    [.] Found hidden value:
    [REG_SZ] (Standard)
    Java Plug-in 1.5.0_10
    [*] Found hidden key: HKEY_USERS\S-1-5-21-839522115-1965331169-1417001333-1003_Classes\CLSID\{CAFEEFAC-0015-0000-0010-ABCDEFFEDCBC}\InprocServer32
    [.] Found hidden value:
    [REG_SZ] (Standard)
    C:\Program Files\Java\jre6\bin\jp2iexp.dll
    [.] Found hidden value:
    [REG_SZ] ThreadingModel
    Apartment
    [*] Found hidden key: HKEY_USERS\S-1-5-21-839522115-1965331169-1417001333-1003_Classes\CLSID\{CAFEEFAC-0015-0000-0011-ABCDEFFEDCBA}
    [.] Found hidden value:
    [REG_SZ] (Standard)
    Java Plug-in 1.5.0_11
    [*] Found hidden key: HKEY_USERS\S-1-5-21-839522115-1965331169-1417001333-1003_Classes\CLSID\{CAFEEFAC-0015-0000-0011-ABCDEFFEDCBA}\InprocServer32
    [.] Found hidden value:
    [REG_SZ] (Standard)
    C:\Program Files\Java\jre6\bin\jp2iexp.dll
    [.] Found hidden value:
    [REG_SZ] ThreadingModel
    Apartment
    [*] Found hidden key: HKEY_USERS\S-1-5-21-839522115-1965331169-1417001333-1003_Classes\CLSID\{CAFEEFAC-0015-0000-0011-ABCDEFFEDCBB}
    [.] Found hidden value:
    [REG_SZ] (Standard)
    Java Plug-in 1.5.0_11
    [*] Found hidden key: HKEY_USERS\S-1-5-21-839522115-1965331169-1417001333-1003_Classes\CLSID\{CAFEEFAC-0015-0000-0011-ABCDEFFEDCBB}\InprocServer32
    [.] Found hidden value:
    [REG_SZ] (Standard)
    C:\Program Files\Java\jre6\bin\jp2iexp.dll
    [.] Found hidden value:
    [REG_SZ] ThreadingModel
    Apartment
    [*] Found hidden key: HKEY_USERS\S-1-5-21-839522115-1965331169-1417001333-1003_Classes\CLSID\{CAFEEFAC-0015-0000-0011-ABCDEFFEDCBC}
    [.] Found hidden value:
    [REG_SZ] (Standard)
    Java Plug-in 1.5.0_11
    [*] Found hidden key: HKEY_USERS\S-1-5-21-839522115-1965331169-1417001333-1003_Classes\CLSID\{CAFEEFAC-0015-0000-0011-ABCDEFFEDCBC}\InprocServer32
    [.] Found hidden value:
    [REG_SZ] (Standard)
    C:\Program Files\Java\jre6\bin\jp2iexp.dll
    [.] Found hidden value:
    [REG_SZ] ThreadingModel
    Apartment
    [*] Found hidden key: HKEY_USERS\S-1-5-21-839522115-1965331169-1417001333-1003_Classes\CLSID\{CAFEEFAC-0015-0000-0012-ABCDEFFEDCBA}
    [.] Found hidden value:
    [REG_SZ] (Standard)
    Java Plug-in 1.5.0_12
    [*] Found hidden key: HKEY_USERS\S-1-5-21-839522115-1965331169-1417001333-1003_Classes\CLSID\{CAFEEFAC-0015-0000-0012-ABCDEFFEDCBA}\InprocServer32
    [.] Found hidden value:
    [REG_SZ] (Standard)
    C:\Program Files\Java\jre6\bin\jp2iexp.dll
    [.] Found hidden value:
    [REG_SZ] ThreadingModel
    Apartment
    [*] Found hidden key: HKEY_USERS\S-1-5-21-839522115-1965331169-1417001333-1003_Classes\CLSID\{CAFEEFAC-0015-0000-0012-ABCDEFFEDCBB}
    [.] Found hidden value:
    [REG_SZ] (Standard)
    Java Plug-in 1.5.0_12
    [*] Found hidden key: HKEY_USERS\S-1-5-21-839522115-1965331169-1417001333-1003_Classes\CLSID\{CAFEEFAC-0015-0000-0012-ABCDEFFEDCBB}\InprocServer32
    [.] Found hidden value:
    [REG_SZ] (Standard)
    C:\Program Files\Java\jre6\bin\jp2iexp.dll
    [.] Found hidden value:
    [REG_SZ] ThreadingModel
    Apartment
    [*] Found hidden key: HKEY_USERS\S-1-5-21-839522115-1965331169-1417001333-1003_Classes\CLSID\{CAFEEFAC-0015-0000-0012-ABCDEFFEDCBC}
    [.] Found hidden value:
    [REG_SZ] (Standard)
    Java Plug-in 1.5.0_12
    [*] Found hidden key: HKEY_USERS\S-1-5-21-839522115-1965331169-1417001333-1003_Classes\CLSID\{CAFEEFAC-0015-0000-0012-ABCDEFFEDCBC}\InprocServer32
    [.] Found hidden value:
    [REG_SZ] (Standard)
    C:\Program Files\Java\jre6\bin\jp2iexp.dll
    [.] Found hidden value:
    [REG_SZ] ThreadingModel
    Apartment
    [*] Found hidden key: HKEY_USERS\S-1-5-21-839522115-1965331169-1417001333-1003_Classes\CLSID\{CAFEEFAC-0015-0000-0013-ABCDEFFEDCBA}
    [.] Found hidden value:
    [REG_SZ] (Standard)
    Java Plug-in 1.5.0_13
    [*] Found hidden key: HKEY_USERS\S-1-5-21-839522115-1965331169-1417001333-1003_Classes\CLSID\{CAFEEFAC-0015-0000-0013-ABCDEFFEDCBA}\InprocServer32
    [.] Found hidden value:
    [REG_SZ] (Standard)
    C:\Program Files\Java\jre6\bin\jp2iexp.dll
    [.] Found hidden value:
    [REG_SZ] ThreadingModel
    Apartment
    [*] Found hidden key: HKEY_USERS\S-1-5-21-839522115-1965331169-1417001333-1003_Classes\CLSID\{CAFEEFAC-0015-0000-0013-ABCDEFFEDCBB}
    [.] Found hidden value:
    [REG_SZ] (Standard)
    Java Plug-in 1.5.0_13
    [*] Found hidden key: HKEY_USERS\S-1-5-21-839522115-1965331169-1417001333-1003_Classes\CLSID\{CAFEEFAC-0015-0000-0013-ABCDEFFEDCBB}\InprocServer32
    [.] Found hidden value:
    [REG_SZ] (Standard)
    C:\Program Files\Java\jre6\bin\jp2iexp.dll
    [.] Found hidden value:
    [REG_SZ] ThreadingModel
    Apartment
    [*] Found hidden key: HKEY_USERS\S-1-5-21-839522115-1965331169-1417001333-1003_Classes\CLSID\{CAFEEFAC-0015-0000-0013-ABCDEFFEDCBC}
    [.] Found hidden value:
    [REG_SZ] (Standard)
    Java Plug-in 1.5.0_13
    [*] Found hidden key: HKEY_USERS\S-1-5-21-839522115-1965331169-1417001333-1003_Classes\CLSID\{CAFEEFAC-0015-0000-0013-ABCDEFFEDCBC}\InprocServer32
    [.] Found hidden value:
    [REG_SZ] (Standard)
    C:\Program Files\Java\jre6\bin\jp2iexp.dll
    [.] Found hidden value:
    [REG_SZ] ThreadingModel
    Apartment
    [*] Found hidden key: HKEY_USERS\S-1-5-21-839522115-1965331169-1417001333-1003_Classes\CLSID\{CAFEEFAC-0015-0000-0014-ABCDEFFEDCBA}
    [.] Found hidden value:
    [REG_SZ] (Standard)
    Java Plug-in 1.5.0_14
    [*] Found hidden key: HKEY_USERS\S-1-5-21-839522115-1965331169-1417001333-1003_Classes\CLSID\{CAFEEFAC-0015-0000-0014-ABCDEFFEDCBA}\InprocServer32
    [.] Found hidden value:
    [REG_SZ] (Standard)
    C:\Program Files\Java\jre6\bin\jp2iexp.dll
    [.] Found hidden value:
    [REG_SZ] ThreadingModel
    Apartment
    [*] Found hidden key: HKEY_USERS\S-1-5-21-839522115-1965331169-1417001333-1003_Classes\CLSID\{CAFEEFAC-0015-0000-0014-ABCDEFFEDCBB}
    [.] Found hidden value:
    [REG_SZ] (Standard)
    Java Plug-in 1.5.0_14
    [*] Found hidden key: HKEY_USERS\S-1-5-21-839522115-1965331169-1417001333-1003_Classes\CLSID\{CAFEEFAC-0015-0000-0014-ABCDEFFEDCBB}\InprocServer32
    [.] Found hidden value:
    [REG_SZ] (Standard)
    C:\Program Files\Java\jre6\bin\jp2iexp.dll
    [.] Found hidden value:
    [REG_SZ] ThreadingModel
    Apartment
    [*] Found hidden key: HKEY_USERS\S-1-5-21-839522115-1965331169-1417001333-1003_Classes\CLSID\{CAFEEFAC-0015-0000-0014-ABCDEFFEDCBC}
    [.] Found hidden value:
    [REG_SZ] (Standard)
    Java Plug-in 1.5.0_14
    [*] Found hidden key: HKEY_USERS\S-1-5-21-839522115-1965331169-1417001333-1003_Classes\CLSID\{CAFEEFAC-0015-0000-0014-ABCDEFFEDCBC}\InprocServer32
    [.] Found hidden value:
    [REG_SZ] (Standard)
    C:\Program Files\Java\jre6\bin\jp2iexp.dll
    [.] Found hidden value:
    [REG_SZ] ThreadingModel
    Apartment
    [*] Found hidden key: HKEY_USERS\S-1-5-21-839522115-1965331169-1417001333-1003_Classes\CLSID\{CAFEEFAC-0015-0000-0015-ABCDEFFEDCBA}
    [.] Found hidden value:
    [REG_SZ] (Standard)
    Java Plug-in 1.5.0_15
    [*] Found hidden key: HKEY_USERS\S-1-5-21-839522115-1965331169-1417001333-1003_Classes\CLSID\{CAFEEFAC-0015-0000-0015-ABCDEFFEDCBA}\InprocServer32
    [.] Found hidden value:
    [REG_SZ] (Standard)
    C:\Program Files\Java\jre6\bin\jp2iexp.dll
    [.] Found hidden value:
    [REG_SZ] ThreadingModel
    Apartment
    [*] Found hidden key: HKEY_USERS\S-1-5-21-839522115-1965331169-1417001333-1003_Classes\CLSID\{CAFEEFAC-0015-0000-0015-ABCDEFFEDCBB}
    [.] Found hidden value:
    [REG_SZ] (Standard)
    Java Plug-in 1.5.0_15
    [*] Found hidden key: HKEY_USERS\S-1-5-21-839522115-1965331169-1417001333-1003_Classes\CLSID\{CAFEEFAC-0015-0000-0015-ABCDEFFEDCBB}\InprocServer32
    [.] Found hidden value:
    [REG_SZ] (Standard)
    C:\Program Files\Java\jre6\bin\jp2iexp.dll
    [.] Found hidden value:
    [REG_SZ] ThreadingModel
    Apartment
    [*] Found hidden key: HKEY_USERS\S-1-5-21-839522115-1965331169-1417001333-1003_Classes\CLSID\{CAFEEFAC-0015-0000-0015-ABCDEFFEDCBC}
    [.] Found hidden value:
    [REG_SZ] (Standard)
    Java Plug-in 1.5.0_15
    [*] Found hidden key: HKEY_USERS\S-1-5-21-839522115-1965331169-1417001333-1003_Classes\CLSID\{CAFEEFAC-0015-0000-0015-ABCDEFFEDCBC}\InprocServer32
    [.] Found hidden value:
    [REG_SZ] (Standard)
    C:\Program Files\Java\jre6\bin\jp2iexp.dll
    [.] Found hidden value:
    [REG_SZ] ThreadingModel
    Apartment
    [*] Found hidden key: HKEY_USERS\S-1-5-21-839522115-1965331169-1417001333-1003_Classes\CLSID\{CAFEEFAC-0015-0000-0016-ABCDEFFEDCBA}
    [.] Found hidden value:
    [REG_SZ] (Standard)
    Java Plug-in 1.5.0_16
    [*] Found hidden key: HKEY_USERS\S-1-5-21-839522115-1965331169-1417001333-1003_Classes\CLSID\{CAFEEFAC-0015-0000-0016-ABCDEFFEDCBA}\InprocServer32
    [.] Found hidden value:
    [REG_SZ] (Standard)
    C:\Program Files\Java\jre6\bin\jp2iexp.dll
    [.] Found hidden value:
    [REG_SZ] ThreadingModel
    Apartment
    [*] Found hidden key: HKEY_USERS\S-1-5-21-839522115-1965331169-1417001333-1003_Classes\CLSID\{CAFEEFAC-0015-0000-0016-ABCDEFFEDCBB}
    [.] Found hidden value:
    [REG_SZ] (Standard)
    Java Plug-in 1.5.0_16
    [*] Found hidden key: HKEY_USERS\S-1-5-21-839522115-1965331169-1417001333-1003_Classes\CLSID\{CAFEEFAC-0015-0000-0016-ABCDEFFEDCBB}\InprocServer32
    [.] Found hidden value:
    [REG_SZ] (Standard)
    C:\Program Files\Java\jre6\bin\jp2iexp.dll
    [.] Found hidden value:
    [REG_SZ] ThreadingModel
    Apartment
    [*] Found hidden key: HKEY_USERS\S-1-5-21-839522115-1965331169-1417001333-1003_Classes\CLSID\{CAFEEFAC-0015-0000-0016-ABCDEFFEDCBC}
    [.] Found hidden value:
    [REG_SZ] (Standard)
    Java Plug-in 1.5.0_16
    [*] Found hidden key: HKEY_USERS\S-1-5-21-839522115-1965331169-1417001333-1003_Classes\CLSID\{CAFEEFAC-0015-0000-0016-ABCDEFFEDCBC}\InprocServer32
    [.] Found hidden value:
    [REG_SZ] (Standard)
    C:\Program Files\Java\jre6\bin\jp2iexp.dll
    [.] Found hidden value:
    [REG_SZ] ThreadingModel
    Apartment
    [*] Found hidden key: HKEY_USERS\S-1-5-21-839522115-1965331169-1417001333-1003_Classes\CLSID\{CAFEEFAC-0015-0000-0017-ABCDEFFEDCBA}
    [.] Found hidden value:
    [REG_SZ] (Standard)
    Java Plug-in 1.5.0_17
    [*] Found hidden key: HKEY_USERS\S-1-5-21-839522115-1965331169-1417001333-1003_Classes\CLSID\{CAFEEFAC-0015-0000-0017-ABCDEFFEDCBA}\InprocServer32
    [.] Found hidden value:
    [REG_SZ] (Standard)
    C:\Program Files\Java\jre6\bin\jp2iexp.dll
    [.] Found hidden value:
    [REG_SZ] ThreadingModel
    Apartment
    [*] Found hidden key: HKEY_USERS\S-1-5-21-839522115-1965331169-1417001333-1003_Classes\CLSID\{CAFEEFAC-0015-0000-0017-ABCDEFFEDCBB}
    [.] Found hidden value:
    [REG_SZ] (Standard)
    Java Plug-in 1.5.0_17
    [*] Found hidden key: HKEY_USERS\S-1-5-21-839522115-1965331169-1417001333-1003_Classes\CLSID\{CAFEEFAC-0015-0000-0017-ABCDEFFEDCBB}\InprocServer32
    [.] Found hidden value:
    [REG_SZ] (Standard)
    C:\Program Files\Java\jre6\bin\jp2iexp.dll
    [.] Found hidden value:
    [REG_SZ] ThreadingModel
    Apartment
    [*] Found hidden key: HKEY_USERS\S-1-5-21-839522115-1965331169-1417001333-1003_Classes\CLSID\{CAFEEFAC-0015-0000-0017-ABCDEFFEDCBC}
    [.] Found hidden value:
    [REG_SZ] (Standard)
    Java Plug-in 1.5.0_17
    [*] Found hidden key: HKEY_USERS\S-1-5-21-839522115-1965331169-1417001333-1003_Classes\CLSID\{CAFEEFAC-0015-0000-0017-ABCDEFFEDCBC}\InprocServer32
    [.] Found hidden value:
    [REG_SZ] (Standard)
    C:\Program Files\Java\jre6\bin\jp2iexp.dll
    [.] Found hidden value:
    [REG_SZ] ThreadingModel
    Apartment
    [*] Found hidden key: HKEY_USERS\S-1-5-21-839522115-1965331169-1417001333-1003_Classes\CLSID\{CAFEEFAC-0015-0000-0018-ABCDEFFEDCBA}
    [.] Found hidden value:
    [REG_SZ] (Standard)
    Java Plug-in 1.5.0_18
    [*] Found hidden key: HKEY_USERS\S-1-5-21-839522115-1965331169-1417001333-1003_Classes\CLSID\{CAFEEFAC-0015-0000-0018-ABCDEFFEDCBA}\InprocServer32
    [.] Found hidden value:
    [REG_SZ] (Standard)
    C:\Program Files\Java\jre6\bin\jp2iexp.dll
    [.] Found hidden value:
    [REG_SZ] ThreadingModel
    Apartment
    [*] Found hidden key: HKEY_USERS\S-1-5-21-839522115-1965331169-1417001333-1003_Classes\CLSID\{CAFEEFAC-0015-0000-0018-ABCDEFFEDCBB}
    [.] Found hidden value:
    [REG_SZ] (Standard)
    Java Plug-in 1.5.0_18
    [*] Found hidden key: HKEY_USERS\S-1-5-21-839522115-1965331169-1417001333-1003_Classes\CLSID\{CAFEEFAC-0015-0000-0018-ABCDEFFEDCBB}\InprocServer32
    [.] Found hidden value:
    [REG_SZ] (Standard)
    C:\Program Files\Java\jre6\bin\jp2iexp.dll
    [.] Found hidden value:
    [REG_SZ] ThreadingModel
    Apartment
    [*] Found hidden key: HKEY_USERS\S-1-5-21-839522115-1965331169-1417001333-1003_Classes\CLSID\{CAFEEFAC-0015-0000-0018-ABCDEFFEDCBC}
    [.] Found hidden value:
    [REG_SZ] (Standard)
    Java Plug-in 1.5.0_18
    [*] Found hidden key: HKEY_USERS\S-1-5-21-839522115-1965331169-1417001333-1003_Classes\CLSID\{CAFEEFAC-0015-0000-0018-ABCDEFFEDCBC}\InprocServer32
    [.] Found hidden value:
    [REG_SZ] (Standard)
    C:\Program Files\Java\jre6\bin\jp2iexp.dll
    [.] Found hidden value:
    [REG_SZ] ThreadingModel
    Apartment
    [*] Found hidden key: HKEY_USERS\S-1-5-21-839522115-1965331169-1417001333-1003_Classes\CLSID\{CAFEEFAC-0015-0000-0019-ABCDEFFEDCBA}
    [.] Found hidden value:
    [REG_SZ] (Standard)
    Java Plug-in 1.5.0_19
    [*] Found hidden key: HKEY_USERS\S-1-5-21-839522115-1965331169-1417001333-1003_Classes\CLSID\{CAFEEFAC-0015-0000-0019-ABCDEFFEDCBA}\InprocServer32
    [.] Found hidden value:
    [REG_SZ] (Standard)
    C:\Program Files\Java\jre6\bin\jp2iexp.dll
    [.] Found hidden value:
    [REG_SZ] ThreadingModel
    Apartment
    [*] Found hidden key: HKEY_USERS\S-1-5-21-839522115-1965331169-1417001333-1003_Classes\CLSID\{CAFEEFAC-0015-0000-0019-ABCDEFFEDCBB}
    [.] Found hidden value:
    [REG_SZ] (Standard)
    Java Plug-in 1.5.0_19
    [*] Found hidden key: HKEY_USERS\S-1-5-21-839522115-1965331169-1417001333-1003_Classes\CLSID\{CAFEEFAC-0015-0000-0019-ABCDEFFEDCBB}\InprocServer32
    [.] Found hidden value:
    [REG_SZ] (Standard)
    C:\Program Files\Java\jre6\bin\jp2iexp.dll
    [.] Found hidden value:
    [REG_SZ] ThreadingModel
    Apartment
    [*] Found hidden key: HKEY_USERS\S-1-5-21-839522115-1965331169-1417001333-1003_Classes\CLSID\{CAFEEFAC-0015-0000-0019-ABCDEFFEDCBC}
    [.] Found hidden value:
    [REG_SZ] (Standard)
    Java Plug-in 1.5.0_19
    [*] Found hidden key: HKEY_USERS\S-1-5-21-839522115-1965331169-1417001333-1003_Classes\CLSID\{CAFEEFAC-0015-0000-0019-ABCDEFFEDCBC}\InprocServer32
    [.] Found hidden value:
    [REG_SZ] (Standard)
    C:\Program Files\Java\jre6\bin\jp2iexp.dll
    [.] Found hidden value:
    [REG_SZ] ThreadingModel
    Apartment
    [*] Found hidden key: HKEY_USERS\S-1-5-21-839522115-1965331169-1417001333-1003_Classes\CLSID\{CAFEEFAC-0015-0000-0020-ABCDEFFEDCBA}
    [.] Found hidden value:
    [REG_SZ] (Standard)
    Java Plug-in 1.5.0_20
    [*] Found hidden key: HKEY_USERS\S-1-5-21-839522115-1965331169-1417001333-1003_Classes\CLSID\{CAFEEFAC-0015-0000-0020-ABCDEFFEDCBA}\InprocServer32
    [.] Found hidden value:
    [REG_SZ] (Standard)
    C:\Program Files\Java\jre6\bin\jp2iexp.dll
    [.] Found hidden value:
    [REG_SZ] ThreadingModel
    Apartment
    [*] Found hidden key: HKEY_USERS\S-1-5-21-839522115-1965331169-1417001333-1003_Classes\CLSID\{CAFEEFAC-0015-0000-0020-ABCDEFFEDCBB}
    [.] Found hidden value:
    [REG_SZ] (Standard)
    Java Plug-in 1.5.0_20
    [*] Found hidden key: HKEY_USERS\S-1-5-21-839522115-1965331169-1417001333-1003_Classes\CLSID\{CAFEEFAC-0015-0000-0020-ABCDEFFEDCBB}\InprocServer32
    [.] Found hidden value:
    [REG_SZ] (Standard)
    C:\Program Files\Java\jre6\bin\jp2iexp.dll
    [.] Found hidden value:
    [REG_SZ] ThreadingModel
    Apartment
    [*] Found hidden key: HKEY_USERS\S-1-5-21-839522115-1965331169-1417001333-1003_Classes\CLSID\{CAFEEFAC-0015-0000-0020-ABCDEFFEDCBC}
    [.] Found hidden value:
    [REG_SZ] (Standard)
    Java Plug-in 1.5.0_20
    [*] Found hidden key: HKEY_USERS\S-1-5-21-839522115-1965331169-1417001333-1003_Classes\CLSID\{CAFEEFAC-0015-0000-0020-ABCDEFFEDCBC}\InprocServer32
    [.] Found hidden value:
    [REG_SZ] (Standard)
    C:\Program Files\Java\jre6\bin\jp2iexp.dll
    [.] Found hidden value:
    [REG_SZ] ThreadingModel
    Apartment
    [*] Found hidden key: HKEY_USERS\S-1-5-21-839522115-1965331169-1417001333-1003_Classes\CLSID\{CAFEEFAC-0015-0000-0021-ABCDEFFEDCBA}
    [.] Found hidden value:
    [REG_SZ] (Standard)
    Java Plug-in 1.5.0_21
    [*] Found hidden key: HKEY_USERS\S-1-5-21-839522115-1965331169-1417001333-1003_Classes\CLSID\{CAFEEFAC-0015-0000-0021-ABCDEFFEDCBA}\InprocServer32
    [.] Found hidden value:
    [REG_SZ] (Standard)
    C:\Program Files\Java\jre6\bin\jp2iexp.dll
    [.] Found hidden value:
    [REG_SZ] ThreadingModel
    Apartment
    [*] Found hidden key: HKEY_USERS\S-1-5-21-839522115-1965331169-1417001333-1003_Classes\CLSID\{CAFEEFAC-0015-0000-0021-ABCDEFFEDCBB}
    [.] Found hidden value:
    [REG_SZ] (Standard)
    Java Plug-in 1.5.0_21
    [*] Found hidden key: HKEY_USERS\S-1-5-21-839522115-1965331169-1417001333-1003_Classes\CLSID\{CAFEEFAC-0015-0000-0021-ABCDEFFEDCBB}\InprocServer32
    [.] Found hidden value:
    [REG_SZ] (Standard)
    C:\Program Files\Java\jre6\bin\jp2iexp.dll
    [.] Found hidden value:
    [REG_SZ] ThreadingModel
    Apartment
    [*] Found hidden key: HKEY_USERS\S-1-5-21-839522115-1965331169-1417001333-1003_Classes\CLSID\{CAFEEFAC-0015-0000-0021-ABCDEFFEDCBC}
    [.] Found hidden value:
    [REG_SZ] (Standard)
    Java Plug-in 1.5.0_21
    [*] Found hidden key: HKEY_USERS\S-1-5-21-839522115-1965331169-1417001333-1003_Classes\CLSID\{CAFEEFAC-0015-0000-0021-ABCDEFFEDCBC}\InprocServer32
    [.] Found hidden value:
    [REG_SZ] (Standard)
    C:\Program Files\Java\jre6\bin\jp2iexp.dll
    [.] Found hidden value:
    [REG_SZ] ThreadingModel
    Apartment
    [*] Found hidden key: HKEY_USERS\S-1-5-21-839522115-1965331169-1417001333-1003_Classes\CLSID\{CAFEEFAC-0015-0000-0022-ABCDEFFEDCBA}
    [.] Found hidden value:
    [REG_SZ] (Standard)
    Java Plug-in 1.5.0_22
    [*] Found hidden key: HKEY_USERS\S-1-5-21-839522115-1965331169-1417001333-1003_Classes\CLSID\{CAFEEFAC-0015-0000-0022-ABCDEFFEDCBA}\InprocServer32
    [.] Found hidden value:
    [REG_SZ] (Standard)
    C:\Program Files\Java\jre6\bin\jp2iexp.dll
    [.] Found hidden value:
    [REG_SZ] ThreadingModel
    Apartment
    [*] Found hidden key: HKEY_USERS\S-1-5-21-839522115-1965331169-1417001333-1003_Classes\CLSID\{CAFEEFAC-0015-0000-0022-ABCDEFFEDCBB}
    [.] Found hidden value:
    [REG_SZ] (Standard)
    Java Plug-in 1.5.0_22
    [*] Found hidden key: HKEY_USERS\S-1-5-21-839522115-1965331169-1417001333-1003_Classes\CLSID\{CAFEEFAC-0015-0000-0022-ABCDEFFEDCBB}\InprocServer32
    [.] Found hidden value:
    [REG_SZ] (Standard)
    C:\Program Files\Java\jre6\bin\jp2iexp.dll
    [.] Found hidden value:
    [REG_SZ] ThreadingModel
    Apartment
    [*] Found hidden key: HKEY_USERS\S-1-5-21-839522115-1965331169-1417001333-1003_Classes\CLSID\{CAFEEFAC-0015-0000-0022-ABCDEFFEDCBC}
    [.] Found hidden value:
    [REG_SZ] (Standard)
    Java Plug-in 1.5.0_22
    [*] Found hidden key: HKEY_USERS\S-1-5-21-839522115-1965331169-1417001333-1003_Classes\CLSID\{CAFEEFAC-0015-0000-0022-ABCDEFFEDCBC}\InprocServer32
    [.] Found hidden value:
    [REG_SZ] (Standard)
    C:\Program Files\Java\jre6\bin\jp2iexp.dll
    [.] Found hidden value:
    [REG_SZ] ThreadingModel
    Apartment
    [*] Found hidden key: HKEY_USERS\S-1-5-21-839522115-1965331169-1417001333-1003_Classes\CLSID\{CAFEEFAC-0015-0000-0023-ABCDEFFEDCBA}
    [.] Found hidden value:
    [REG_SZ] (Standard)
    Java Plug-in 1.5.0_23
    [*] Found hidden key: HKEY_USERS\S-1-5-21-839522115-1965331169-1417001333-1003_Classes\CLSID\{CAFEEFAC-0015-0000-0023-ABCDEFFEDCBA}\InprocServer32
    [.] Found hidden value:
    [REG_SZ] (Standard)
    C:\Program Files\Java\jre6\bin\jp2iexp.dll
    [.] Found hidden value:
    [REG_SZ] ThreadingModel
    Apartment
    [*] Found hidden key: HKEY_USERS\S-1-5-21-839522115-1965331169-1417001333-1003_Classes\CLSID\{CAFEEFAC-0015-0000-0023-ABCDEFFEDCBB}
    [.] Found hidden value:
    [REG_SZ] (Standard)
    Java Plug-in 1.5.0_23
    [*] Found hidden key: HKEY_USERS\S-1-5-21-839522115-1965331169-1417001333-1003_Classes\CLSID\{CAFEEFAC-0015-0000-0023-ABCDEFFEDCBB}\InprocServer32
    [.] Found hidden value:
    [REG_SZ] (Standard)
    C:\Program Files\Java\jre6\bin\jp2iexp.dll
    [.] Found hidden value:
    [REG_SZ] ThreadingModel
    Apartment
    [*] Found hidden key: HKEY_USERS\S-1-5-21-839522115-1965331169-1417001333-1003_Classes\CLSID\{CAFEEFAC-0015-0000-0023-ABCDEFFEDCBC}
    [.] Found hidden value:
    [REG_SZ] (Standard)
    Java Plug-in 1.5.0_23
    [*] Found hidden key: HKEY_USERS\S-1-5-21-839522115-1965331169-1417001333-1003_Classes\CLSID\{CAFEEFAC-0015-0000-0023-ABCDEFFEDCBC}\InprocServer32
    [.] Found hidden value:
    [REG_SZ] (Standard)
    C:\Program Files\Java\jre6\bin\jp2iexp.dll
    [.] Found hidden value:
    [REG_SZ] ThreadingModel
    Apartment
    [*] Found hidden key: HKEY_USERS\S-1-5-21-839522115-1965331169-1417001333-1003_Classes\CLSID\{CAFEEFAC-0015-0000-0024-ABCDEFFEDCBA}
    [.] Found hidden value:
    [REG_SZ] (Standard)
    Java Plug-in 1.5.0_24
    [*] Found hidden key: HKEY_USERS\S-1-5-21-839522115-1965331169-1417001333-1003_Classes\CLSID\{CAFEEFAC-0015-0000-0024-ABCDEFFEDCBA}\InprocServer32
    [.] Found hidden value:
    [REG_SZ] (Standard)
    C:\Program Files\Java\jre6\bin\jp2iexp.dll
    [.] Found hidden value:
    [REG_SZ] ThreadingModel
    Apartment
    [*] Found hidden key: HKEY_USERS\S-1-5-21-839522115-1965331169-1417001333-1003_Classes\CLSID\{CAFEEFAC-0015-0000-0024-ABCDEFFEDCBB}
    [.] Found hidden value:
    [REG_SZ] (Standard)
    Java Plug-in 1.5.0_24
    [*] Found hidden key: HKEY_USERS\S-1-5-21-839522115-1965331169-1417001333-1003_Classes\CLSID\{CAFEEFAC-0015-0000-0024-ABCDEFFEDCBB}\InprocServer32
    [.] Found hidden value:
    [REG_SZ] (Standard)
    C:\Program Files\Java\jre6\bin\jp2iexp.dll
    [.] Found hidden value:
    [REG_SZ] ThreadingModel
    Apartment
    [*] Found hidden key: HKEY_USERS\S-1-5-21-839522115-1965331169-1417001333-1003_Classes\CLSID\{CAFEEFAC-0015-0000-0024-ABCDEFFEDCBC}
    [.] Found hidden value:
    [REG_SZ] (Standard)
    Java Plug-in 1.5.0_24
    [*] Found hidden key: HKEY_USERS\S-1-5-21-839522115-1965331169-1417001333-1003_Classes\CLSID\{CAFEEFAC-0015-0000-0024-ABCDEFFEDCBC}\InprocServer32
    [.] Found hidden value:
    [REG_SZ] (Standard)
    C:\Program Files\Java\jre6\bin\jp2iexp.dll
    [.] Found hidden value:
    [REG_SZ] ThreadingModel
    Apartment
    [*] Found hidden key: HKEY_USERS\S-1-5-21-839522115-1965331169-1417001333-1003_Classes\CLSID\{CAFEEFAC-0015-0000-0025-ABCDEFFEDCBA}
    [.] Found hidden value:
    [REG_SZ] (Standard)
    Java Plug-in 1.5.0_25
    [*] Found hidden key: HKEY_USERS\S-1-5-21-839522115-1965331169-1417001333-1003_Classes\CLSID\{CAFEEFAC-0015-0000-0025-ABCDEFFEDCBA}\InprocServer32
    [.] Found hidden value:
    [REG_SZ] (Standard)
    C:\Program Files\Java\jre6\bin\jp2iexp.dll
    [.] Found hidden value:
    [REG_SZ] ThreadingModel
    Apartment
    [*] Found hidden key: HKEY_USERS\S-1-5-21-839522115-1965331169-1417001333-1003_Classes\CLSID\{CAFEEFAC-0015-0000-0025-ABCDEFFEDCBB}
    [.] Found hidden value:
    [REG_SZ] (Standard)
    Java Plug-in 1.5.0_25
    [*] Found hidden key: HKEY_USERS\S-1-5-21-839522115-1965331169-1417001333-1003_Classes\CLSID\{CAFEEFAC-0015-0000-0025-ABCDEFFEDCBB}\InprocServer32
    [.] Found hidden value:
    [REG_SZ] (Standard)
    C:\Program Files\Java\jre6\bin\jp2iexp.dll
    [.] Found hidden value:
    [REG_SZ] ThreadingModel
    Apartment
    [*] Found hidden key: HKEY_USERS\S-1-5-21-839522115-1965331169-1417001333-1003_Classes\CLSID\{CAFEEFAC-0015-0000-0025-ABCDEFFEDCBC}
    [.] Found hidden value:
    [REG_SZ] (Standard)
    Java Plug-in 1.5.0_25
    [*] Found hidden key: HKEY_USERS\S-1-5-21-839522115-1965331169-1417001333-1003_Classes\CLSID\{CAFEEFAC-0015-0000-0025-ABCDEFFEDCBC}\InprocServer32
    [.] Found hidden value:
    [REG_SZ] (Standard)
    C:\Program Files\Java\jre6\bin\jp2iexp.dll
    [.] Found hidden value:
    [REG_SZ] ThreadingModel
    Apartment
    [*] Found hidden key: HKEY_USERS\S-1-5-21-839522115-1965331169-1417001333-1003_Classes\CLSID\{CAFEEFAC-0015-0000-0026-ABCDEFFEDCBA}
    [.] Found hidden value:
    [REG_SZ] (Standard)
    Java Plug-in 1.5.0_26
    [*] Found hidden key: HKEY_USERS\S-1-5-21-839522115-1965331169-1417001333-1003_Classes\CLSID\{CAFEEFAC-0015-0000-0026-ABCDEFFEDCBA}\InprocServer32
    [.] Found hidden value:
    [REG_SZ] (Standard)
    C:\Program Files\Java\jre6\bin\jp2iexp.dll
    [.] Found hidden value:
    [REG_SZ] ThreadingModel
    Apartment
    [*] Found hidden key: HKEY_USERS\S-1-5-21-839522115-1965331169-1417001333-1003_Classes\CLSID\{CAFEEFAC-0015-0000-0026-ABCDEFFEDCBB}
    [.] Found hidden value:
    [REG_SZ] (Standard)
    Java Plug-in 1.5.0_26
    [*] Found hidden key: HKEY_USERS\S-1-5-21-839522115-1965331169-1417001333-1003_Classes\CLSID\{CAFEEFAC-0015-0000-0026-ABCDEFFEDCBB}\InprocServer32
    [.] Found hidden value:
    [REG_SZ] (Standard)
    C:\Program Files\Java\jre6\bin\jp2iexp.dll
    [.] Found hidden value:
    [REG_SZ] ThreadingModel
    Apartment
    [*] Found hidden key: HKEY_USERS\S-1-5-21-839522115-1965331169-1417001333-1003_Classes\CLSID\{CAFEEFAC-0015-0000-0026-ABCDEFFEDCBC}
    [.] Found hidden value:
    [REG_SZ] (Standard)
    Java Plug-in 1.5.0_26
    [*] Found hidden key: HKEY_USERS\S-1-5-21-839522115-1965331169-1417001333-1003_Classes\CLSID\{CAFEEFAC-0015-0000-0026-ABCDEFFEDCBC}\InprocServer32
    [.] Found hidden value:
    [REG_SZ] (Standard)
    C:\Program Files\Java\jre6\bin\jp2iexp.dll
    [.] Found hidden value:
    [REG_SZ] ThreadingModel
    Apartment
    [*] Found hidden key: HKEY_USERS\S-1-5-21-839522115-1965331169-1417001333-1003_Classes\CLSID\{CAFEEFAC-0015-0000-0027-ABCDEFFEDCBA}
    [.] Found hidden value:
    [REG_SZ] (Standard)
    Java Plug-in 1.5.0_27
    [*] Found hidden key: HKEY_USERS\S-1-5-21-839522115-1965331169-1417001333-1003_Classes\CLSID\{CAFEEFAC-0015-0000-0027-ABCDEFFEDCBA}\InprocServer32
    [.] Found hidden value:
    [REG_SZ] (Standard)
    C:\Program Files\Java\jre6\bin\jp2iexp.dll
    [.] Found hidden value:
    [REG_SZ] ThreadingModel
    Apartment
    [*] Found hidden key: HKEY_USERS\S-1-5-21-839522115-1965331169-1417001333-1003_Classes\CLSID\{CAFEEFAC-0015-0000-0027-ABCDEFFEDCBB}
    [.] Found hidden value:
    [REG_SZ] (Standard)
    Java Plug-in 1.5.0_27
    [*] Found hidden key: HKEY_USERS\S-1-5-21-839522115-1965331169-1417001333-1003_Classes\CLSID\{CAFEEFAC-0015-0000-0027-ABCDEFFEDCBB}\InprocServer32
    [.] Found hidden value:
    [REG_SZ] (Standard)
    C:\Program Files\Java\jre6\bin\jp2iexp.dll
    [.] Found hidden value:
    [REG_SZ] ThreadingModel
    Apartment
    [*] Found hidden key: HKEY_USERS\S-1-5-21-839522115-1965331169-1417001333-1003_Classes\CLSID\{CAFEEFAC-0015-0000-0027-ABCDEFFEDCBC}
    [.] Found hidden value:
    [REG_SZ] (Standard)
    Java Plug-in 1.5.0_27
    [*] Found hidden key: HKEY_USERS\S-1-5-21-839522115-1965331169-1417001333-1003_Classes\CLSID\{CAFEEFAC-0015-0000-0027-ABCDEFFEDCBC}\InprocServer32
    [.] Found hidden value:
    [REG_SZ] (Standard)
    C:\Program Files\Java\jre6\bin\jp2iexp.dll
    [.] Found hidden value:
    [REG_SZ] ThreadingModel
    Apartment
    [*] Found hidden key: HKEY_USERS\S-1-5-21-839522115-1965331169-1417001333-1003_Classes\CLSID\{CAFEEFAC-0015-0000-0028-ABCDEFFEDCBA}
    [.] Found hidden value:
    [REG_SZ] (Standard)
    Java Plug-in 1.5.0_28
    [*] Found hidden key: HKEY_USERS\S-1-5-21-839522115-1965331169-1417001333-1003_Classes\CLSID\{CAFEEFAC-0015-0000-0028-ABCDEFFEDCBA}\InprocServer32
    [.] Found hidden value:
    [REG_SZ] (Standard)
    C:\Program Files\Java\jre6\bin\jp2iexp.dll
    [.] Found hidden value:
    [REG_SZ] ThreadingModel
    Apartment
    [*] Found hidden key: HKEY_USERS\S-1-5-21-839522115-1965331169-1417001333-1003_Classes\CLSID\{CAFEEFAC-0015-0000-0028-ABCDEFFEDCBB}
    [.] Found hidden value:
    [REG_SZ] (Standard)
    Java Plug-in 1.5.0_28
    [*] Found hidden key: HKEY_USERS\S-1-5-21-839522115-1965331169-1417001333-1003_Classes\CLSID\{CAFEEFAC-0015-0000-0028-ABCDEFFEDCBB}\InprocServer32
    [.] Found hidden value:
    [REG_SZ] (Standard)
    C:\Program Files\Java\jre6\bin\jp2iexp.dll
    [.] Found hidden value:
    [REG_SZ] ThreadingModel
    Apartment
    [*] Found hidden key: HKEY_USERS\S-1-5-21-839522115-1965331169-1417001333-1003_Classes\CLSID\{CAFEEFAC-0015-0000-0028-ABCDEFFEDCBC}
    [.] Found hidden value:
    [REG_SZ] (Standard)
    Java Plug-in 1.5.0_28
    [*] Found hidden key: HKEY_USERS\S-1-5-21-839522115-1965331169-1417001333-1003_Classes\CLSID\{CAFEEFAC-0015-0000-0028-ABCDEFFEDCBC}\InprocServer32
    [.] Found hidden value:
    [REG_SZ] (Standard)
    C:\Program Files\Java\jre6\bin\jp2iexp.dll
    [.] Found hidden value:
    [REG_SZ] ThreadingModel
    Apartment
    [*] Found hidden key: HKEY_USERS\S-1-5-21-839522115-1965331169-1417001333-1003_Classes\CLSID\{CAFEEFAC-0015-0000-0029-ABCDEFFEDCBA}
    [.] Found hidden value:
    [REG_SZ] (Standard)
    Java Plug-in 1.5.0_29
    [*] Found hidden key: HKEY_USERS\S-1-5-21-839522115-1965331169-1417001333-1003_Classes\CLSID\{CAFEEFAC-0015-0000-0029-ABCDEFFEDCBA}\InprocServer32
    [.] Found hidden value:
    [REG_SZ] (Standard)
    C:\Program Files\Java\jre6\bin\jp2iexp.dll
    [.] Found hidden value:
    [REG_SZ] ThreadingModel
    Apartment
    [*] Found hidden key: HKEY_USERS\S-1-5-21-839522115-1965331169-1417001333-1003_Classes\CLSID\{CAFEEFAC-0015-0000-0029-ABCDEFFEDCBB}
    [.] Found hidden value:
    [REG_SZ] (Standard)
    Java Plug-in 1.5.0_29
    [*] Found hidden key: HKEY_USERS\S-1-5-21-839522115-1965331169-1417001333-1003_Classes\CLSID\{CAFEEFAC-0015-0000-0029-ABCDEFFEDCBB}\InprocServer32
    [.] Found hidden value:
    [REG_SZ] (Standard)
    C:\Program Files\Java\jre6\bin\jp2iexp.dll
    [.] Found hidden value:
    [REG_SZ] ThreadingModel
    Apartment
    [*] Found hidden key: HKEY_USERS\S-1-5-21-839522115-1965331169-1417001333-1003_Classes\CLSID\{CAFEEFAC-0015-0000-0029-ABCDEFFEDCBC}
    [.] Found hidden value:
    [REG_SZ] (Standard)
    Java Plug-in 1.5.0_29
    [*] Found hidden key: HKEY_USERS\S-1-5-21-839522115-1965331169-1417001333-1003_Classes\CLSID\{CAFEEFAC-0015-0000-0029-ABCDEFFEDCBC}\InprocServer32
    [.] Found hidden value:
    [REG_SZ] (Standard)
    C:\Program Files\Java\jre6\bin\jp2iexp.dll
    [.] Found hidden value:
    [REG_SZ] ThreadingModel
    Apartment
    [*] Found hidden key: HKEY_USERS\S-1-5-21-839522115-1965331169-1417001333-1003_Classes\CLSID\{CAFEEFAC-0015-0000-0030-ABCDEFFEDCBA}
    [.] Found hidden value:
    [REG_SZ] (Standard)
    Java Plug-in 1.5.0_30
    [*] Found hidden key: HKEY_USERS\S-1-5-21-839522115-1965331169-1417001333-1003_Classes\CLSID\{CAFEEFAC-0015-0000-0030-ABCDEFFEDCBA}\InprocServer32
    [.] Found hidden value:
    [REG_SZ] (Standard)
    C:\Program Files\Java\jre6\bin\jp2iexp.dll
    [.] Found hidden value:
    [REG_SZ] ThreadingModel
    Apartment
    [*] Found hidden key: HKEY_USERS\S-1-5-21-839522115-1965331169-1417001333-1003_Classes\CLSID\{CAFEEFAC-0015-0000-0030-ABCDEFFEDCBB}
    [.] Found hidden value:
    [REG_SZ] (Standard)
    Java Plug-in 1.5.0_30
    [*] Found hidden key: HKEY_USERS\S-1-5-21-839522115-1965331169-1417001333-1003_Classes\CLSID\{CAFEEFAC-0015-0000-0030-ABCDEFFEDCBB}\InprocServer32
    [.] Found hidden value:
    [REG_SZ] (Standard)
    C:\Program Files\Java\jre6\bin\jp2iexp.dll
    [.] Found hidden value:
    [REG_SZ] ThreadingModel
    Apartment
    [*] Found hidden key: HKEY_USERS\S-1-5-21-839522115-1965331169-1417001333-1003_Classes\CLSID\{CAFEEFAC-0015-0000-0030-ABCDEFFEDCBC}
    [.] Found hidden value:
    [REG_SZ] (Standard)
    Java Plug-in 1.5.0_30
    [*] Found hidden key: HKEY_USERS\S-1-5-21-839522115-1965331169-1417001333-1003_Classes\CLSID\{CAFEEFAC-0015-0000-0030-ABCDEFFEDCBC}\InprocServer32
    [.] Found hidden value:
    [REG_SZ] (Standard)
    C:\Program Files\Java\jre6\bin\jp2iexp.dll
    [.] Found hidden value:
    [REG_SZ] ThreadingModel
    Apartment
    [*] Found hidden key: HKEY_USERS\S-1-5-21-839522115-1965331169-1417001333-1003_Classes\CLSID\{CAFEEFAC-0015-0000-FFFF-ABCDEFFEDCBA}
    [.] Found hidden value:
    [REG_SZ] (Standard)
    Java Plug-in 1.5.0
    [*] Found hidden key: HKEY_USERS\S-1-5-21-839522115-1965331169-1417001333-1003_Classes\CLSID\{CAFEEFAC-0015-0000-FFFF-ABCDEFFEDCBA}\InprocServer32
    [.] Found hidden value:
    [REG_SZ] (Standard)
    C:\Program Files\Java\jre6\bin\jp2iexp.dll
    [.] Found hidden value:
    [REG_SZ] ThreadingModel
    Apartment
    [*] Found hidden key: HKEY_USERS\S-1-5-21-839522115-1965331169-1417001333-1003_Classes\CLSID\{CAFEEFAC-0016-0000-0000-ABCDEFFEDCBA}
    [.] Found hidden value:
    [REG_SZ] (Standard)
    Java Plug-in 1.6.0
    [*] Found hidden key: HKEY_USERS\S-1-5-21-839522115-1965331169-1417001333-1003_Classes\CLSID\{CAFEEFAC-0016-0000-0000-ABCDEFFEDCBA}\InprocServer32
    [.] Found hidden value:
    [REG_SZ] (Standard)
    C:\Program Files\Java\jre6\bin\jp2iexp.dll
    [.] Found hidden value:
    [REG_SZ] ThreadingModel
    Apartment
    [*] Found hidden key: HKEY_USERS\S-1-5-21-839522115-1965331169-1417001333-1003_Classes\CLSID\{CAFEEFAC-0016-0000-0000-ABCDEFFEDCBB}
    [.] Found hidden value:
    [REG_SZ] (Standard)
    Java Plug-in 1.6.0
    [*] Found hidden key: HKEY_USERS\S-1-5-21-839522115-1965331169-1417001333-1003_Classes\CLSID\{CAFEEFAC-0016-0000-0000-ABCDEFFEDCBB}\InprocServer32
    [.] Found hidden value:
    [REG_SZ] (Standard)
    C:\Program Files\Java\jre6\bin\jp2iexp.dll
    [.] Found hidden value:
    [REG_SZ] ThreadingModel
    Apartment
    [*] Found hidden key: HKEY_USERS\S-1-5-21-839522115-1965331169-1417001333-1003_Classes\CLSID\{CAFEEFAC-0016-0000-0000-ABCDEFFEDCBC}
    [.] Found hidden value:
    [REG_SZ] (Standard)
    Java Plug-in 1.6.0
    [*] Found hidden key: HKEY_USERS\S-1-5-21-839522115-1965331169-1417001333-1003_Classes\CLSID\{CAFEEFAC-0016-0000-0000-ABCDEFFEDCBC}\InprocServer32
    [.] Found hidden value:
    [REG_SZ] (Standard)
    C:\Program Files\Java\jre6\bin\jp2iexp.dll
    [.] Found hidden value:
    [REG_SZ] ThreadingModel
    Apartment
    [*] Found hidden key: HKEY_USERS\S-1-5-21-839522115-1965331169-1417001333-1003_Classes\CLSID\{CAFEEFAC-0016-0000-0001-ABCDEFFEDCBA}
    [.] Found hidden value:
    [REG_SZ] (Standard)
    Java Plug-in 1.6.0_01
    [*] Found hidden key: HKEY_USERS\S-1-5-21-839522115-1965331169-1417001333-1003_Classes\CLSID\{CAFEEFAC-0016-0000-0001-ABCDEFFEDCBA}\InprocServer32
    [.] Found hidden value:
    [REG_SZ] (Standard)
    C:\Program Files\Java\jre6\bin\jp2iexp.dll
    [.] Found hidden value:
    [REG_SZ] ThreadingModel
    Apartment
    [*] Found hidden key: HKEY_USERS\S-1-5-21-839522115-1965331169-1417001333-1003_Classes\CLSID\{CAFEEFAC-0016-0000-0001-ABCDEFFEDCBB}
    [.] Found hidden value:
    [REG_SZ] (Standard)
    Java Plug-in 1.6.0_01
    [*] Found hidden key: HKEY_USERS\S-1-5-21-839522115-1965331169-1417001333-1003_Classes\CLSID\{CAFEEFAC-0016-0000-0001-ABCDEFFEDCBB}\InprocServer32
    [.] Found hidden value:
    [REG_SZ] (Standard)
    C:\Program Files\Java\jre6\bin\jp2iexp.dll
    [.] Found hidden value:
    [REG_SZ] ThreadingModel
    Apartment
    [*] Found hidden key: HKEY_USERS\S-1-5-21-839522115-1965331169-1417001333-1003_Classes\CLSID\{CAFEEFAC-0016-0000-0001-ABCDEFFEDCBC}
    [.] Found hidden value:
    [REG_SZ] (Standard)
    Java Plug-in 1.6.0_01
    [*] Found hidden key: HKEY_USERS\S-1-5-21-839522115-1965331169-1417001333-1003_Classes\CLSID\{CAFEEFAC-0016-0000-0001-ABCDEFFEDCBC}\InprocServer32
    [.] Found hidden value:
    [REG_SZ] (Standard)
    C:\Program Files\Java\jre6\bin\jp2iexp.dll
    [.] Found hidden value:
    [REG_SZ] ThreadingModel
    Apartment
    [*] Found hidden key: HKEY_USERS\S-1-5-21-839522115-1965331169-1417001333-1003_Classes\CLSID\{CAFEEFAC-0016-0000-0002-ABCDEFFEDCBA}
    [.] Found hidden value:
    [REG_SZ] (Standard)
    Java Plug-in 1.6.0_02
    [*] Found hidden key: HKEY_USERS\S-1-5-21-839522115-1965331169-1417001333-1003_Classes\CLSID\{CAFEEFAC-0016-0000-0002-ABCDEFFEDCBA}\InprocServer32
    [.] Found hidden value:
    [REG_SZ] (Standard)
    C:\Program Files\Java\jre6\bin\jp2iexp.dll
    [.] Found hidden value:
    [REG_SZ] ThreadingModel
    Apartment
    [*] Found hidden key: HKEY_USERS\S-1-5-21-839522115-1965331169-1417001333-1003_Classes\CLSID\{CAFEEFAC-0016-0000-0002-ABCDEFFEDCBB}
    [.] Found hidden value:
    [REG_SZ] (Standard)
    Java Plug-in 1.6.0_02
    [*] Found hidden key: HKEY_USERS\S-1-5-21-839522115-1965331169-1417001333-1003_Classes\CLSID\{CAFEEFAC-0016-0000-0002-ABCDEFFEDCBB}\InprocServer32
    [.] Found hidden value:
    [REG_SZ] (Standard)
    C:\Program Files\Java\jre6\bin\jp2iexp.dll
    [.] Found hidden value:
    [REG_SZ] ThreadingModel
    Apartment
    [*] Found hidden key: HKEY_USERS\S-1-5-21-839522115-1965331169-1417001333-1003_Classes\CLSID\{CAFEEFAC-0016-0000-0002-ABCDEFFEDCBC}
    [.] Found hidden value:
    [REG_SZ] (Standard)
    Java Plug-in 1.6.0_02
    [*] Found hidden key: HKEY_USERS\S-1-5-21-839522115-1965331169-1417001333-1003_Classes\CLSID\{CAFEEFAC-0016-0000-0002-ABCDEFFEDCBC}\InprocServer32
    [.] Found hidden value:
    [REG_SZ] (Standard)
    C:\Program Files\Java\jre6\bin\jp2iexp.dll
    [.] Found hidden value:
    [REG_SZ] ThreadingModel
    Apartment
    [*] Found hidden key: HKEY_USERS\S-1-5-21-839522115-1965331169-1417001333-1003_Classes\CLSID\{CAFEEFAC-0016-0000-0003-ABCDEFFEDCBA}
    [.] Found hidden value:
    [REG_SZ] (Standard)
    Java Plug-in 1.6.0_03
    [*] Found hidden key: HKEY_USERS\S-1-5-21-839522115-1965331169-1417001333-1003_Classes\CLSID\{CAFEEFAC-0016-0000-0003-ABCDEFFEDCBA}\InprocServer32
    [.] Found hidden value:
    [REG_SZ] (Standard)
    C:\Program Files\Java\jre6\bin\jp2iexp.dll
    [.] Found hidden value:
    [REG_SZ] ThreadingModel
    Apartment
    [*] Found hidden key: HKEY_USERS\S-1-5-21-839522115-1965331169-1417001333-1003_Classes\CLSID\{CAFEEFAC-0016-0000-0003-ABCDEFFEDCBB}
    [.] Found hidden value:
    [REG_SZ] (Standard)
    Java Plug-in 1.6.0_03
    [*] Found hidden key: HKEY_USERS\S-1-5-21-839522115-1965331169-1417001333-1003_Classes\CLSID\{CAFEEFAC-0016-0000-0003-ABCDEFFEDCBB}\InprocServer32
    [.] Found hidden value:
    [REG_SZ] (Standard)
    C:\Program Files\Java\jre6\bin\jp2iexp.dll
    [.] Found hidden value:
    [REG_SZ] ThreadingModel
    Apartment
    [*] Found hidden key: HKEY_USERS\S-1-5-21-839522115-1965331169-1417001333-1003_Classes\CLSID\{CAFEEFAC-0016-0000-0003-ABCDEFFEDCBC}
    [.] Found hidden value:
    [REG_SZ] (Standard)
    Java Plug-in 1.6.0_03
    [*] Found hidden key: HKEY_USERS\S-1-5-21-839522115-1965331169-1417001333-1003_Classes\CLSID\{CAFEEFAC-0016-0000-0003-ABCDEFFEDCBC}\InprocServer32
    [.] Found hidden value:
    [REG_SZ] (Standard)
    C:\Program Files\Java\jre6\bin\jp2iexp.dll
    [.] Found hidden value:
    [REG_SZ] ThreadingModel
    Apartment
    [*] Found hidden key: HKEY_USERS\S-1-5-21-839522115-1965331169-1417001333-1003_Classes\CLSID\{CAFEEFAC-0016-0000-0004-ABCDEFFEDCBA}
    [.] Found hidden value:
    [REG_SZ] (Standard)
    Java Plug-in 1.6.0_04
    [*] Found hidden key: HKEY_USERS\S-1-5-21-839522115-1965331169-1417001333-1003_Classes\CLSID\{CAFEEFAC-0016-0000-0004-ABCDEFFEDCBA}\InprocServer32
    [.] Found hidden value:
    [REG_SZ] (Standard)
    C:\Program Files\Java\jre6\bin\jp2iexp.dll
    [.] Found hidden value:
    [REG_SZ] ThreadingModel
    Apartment
    [*] Found hidden key: HKEY_USERS\S-1-5-21-839522115-1965331169-1417001333-1003_Classes\CLSID\{CAFEEFAC-0016-0000-0004-ABCDEFFEDCBB}
    [.] Found hidden value:
    [REG_SZ] (Standard)
    Java Plug-in 1.6.0_04
    [*] Found hidden key: HKEY_USERS\S-1-5-21-839522115-1965331169-1417001333-1003_Classes\CLSID\{CAFEEFAC-0016-0000-0004-ABCDEFFEDCBB}\InprocServer32
    [.] Found hidden value:
    [REG_SZ] (Standard)
    C:\Program Files\Java\jre6\bin\jp2iexp.dll
    [.] Found hidden value:
    [REG_SZ] ThreadingModel
    Apartment
    [*] Found hidden key: HKEY_USERS\S-1-5-21-839522115-1965331169-1417001333-1003_Classes\CLSID\{CAFEEFAC-0016-0000-0004-ABCDEFFEDCBC}
    [.] Found hidden value:
    [REG_SZ] (Standard)
    Java Plug-in 1.6.0_04
    [*] Found hidden key: HKEY_USERS\S-1-5-21-839522115-1965331169-1417001333-1003_Classes\CLSID\{CAFEEFAC-0016-0000-0004-ABCDEFFEDCBC}\InprocServer32
    [.] Found hidden value:
    [REG_SZ] (Standard)
    C:\Program Files\Java\jre6\bin\jp2iexp.dll
    [.] Found hidden value:
    [REG_SZ] ThreadingModel
    Apartment
    [*] Found hidden key: HKEY_USERS\S-1-5-21-839522115-1965331169-1417001333-1003_Classes\CLSID\{CAFEEFAC-0016-0000-0005-ABCDEFFEDCBA}
    [.] Found hidden value:
    [REG_SZ] (Standard)
    Java Plug-in 1.6.0_05
    [*] Found hidden key: HKEY_USERS\S-1-5-21-839522115-1965331169-1417001333-1003_Classes\CLSID\{CAFEEFAC-0016-0000-0005-ABCDEFFEDCBA}\InprocServer32
    [.] Found hidden value:
    [REG_SZ] (Standard)
    C:\Program Files\Java\jre6\bin\jp2iexp.dll
    [.] Found hidden value:
    [REG_SZ] ThreadingModel
    Apartment
    [*] Found hidden key: HKEY_USERS\S-1-5-21-839522115-1965331169-1417001333-1003_Classes\CLSID\{CAFEEFAC-0016-0000-0005-ABCDEFFEDCBB}
    [.] Found hidden value:
    [REG_SZ] (Standard)
    Java Plug-in 1.6.0_05
    [*] Found hidden key: HKEY_USERS\S-1-5-21-839522115-1965331169-1417001333-1003_Classes\CLSID\{CAFEEFAC-0016-0000-0005-ABCDEFFEDCBB}\InprocServer32
    [.] Found hidden value:
    [REG_SZ] (Standard)
    C:\Program Files\Java\jre6\bin\jp2iexp.dll
    [.] Found hidden value:
    [REG_SZ] ThreadingModel
    Apartment
    [*] Found hidden key: HKEY_USERS\S-1-5-21-839522115-1965331169-1417001333-1003_Classes\CLSID\{CAFEEFAC-0016-0000-0005-ABCDEFFEDCBC}
    [.] Found hidden value:
    [REG_SZ] (Standard)
    Java Plug-in 1.6.0_05
    [*] Found hidden key: HKEY_USERS\S-1-5-21-839522115-1965331169-1417001333-1003_Classes\CLSID\{CAFEEFAC-0016-0000-0005-ABCDEFFEDCBC}\InprocServer32
    [.] Found hidden value:
    [REG_SZ] (Standard)
    C:\Program Files\Java\jre6\bin\jp2iexp.dll
    [.] Found hidden value:
    [REG_SZ] ThreadingModel
    Apartment
    [*] Found hidden key: HKEY_USERS\S-1-5-21-839522115-1965331169-1417001333-1003_Classes\CLSID\{CAFEEFAC-0016-0000-0006-ABCDEFFEDCBA}
    [.] Found hidden value:
    [REG_SZ] (Standard)
    Java Plug-in 1.6.0_06
    [*] Found hidden key: HKEY_USERS\S-1-5-21-839522115-1965331169-1417001333-1003_Classes\CLSID\{CAFEEFAC-0016-0000-0006-ABCDEFFEDCBA}\InprocServer32
    [.] Found hidden value:
    [REG_SZ] (Standard)
    C:\Program Files\Java\jre6\bin\jp2iexp.dll
    [.] Found hidden value:
    [REG_SZ] ThreadingModel
    Apartment
    [*] Found hidden key: HKEY_USERS\S-1-5-21-839522115-1965331169-1417001333-1003_Classes\CLSID\{CAFEEFAC-0016-0000-0006-ABCDEFFEDCBB}
    [.] Found hidden value:
    [REG_SZ] (Standard)
    Java Plug-in 1.6.0_06
    [*] Found hidden key: HKEY_USERS\S-1-5-21-839522115-1965331169-1417001333-1003_Classes\CLSID\{CAFEEFAC-0016-0000-0006-ABCDEFFEDCBB}\InprocServer32
    [.] Found hidden value:
    [REG_SZ] (Standard)
    C:\Program Files\Java\jre6\bin\jp2iexp.dll
    [.] Found hidden value:
    [REG_SZ] ThreadingModel
    Apartment
    [*] Found hidden key: HKEY_USERS\S-1-5-21-839522115-1965331169-1417001333-1003_Classes\CLSID\{CAFEEFAC-0016-0000-0006-ABCDEFFEDCBC}
    [.] Found hidden value:
    [REG_SZ] (Standard)
    Java Plug-in 1.6.0_06
    [*] Found hidden key: HKEY_USERS\S-1-5-21-839522115-1965331169-1417001333-1003_Classes\CLSID\{CAFEEFAC-0016-0000-0006-ABCDEFFEDCBC}\InprocServer32
    [.] Found hidden value:
    [REG_SZ] (Standard)
    C:\Program Files\Java\jre6\bin\jp2iexp.dll
    [.] Found hidden value:
    [REG_SZ] ThreadingModel
    Apartment
    [*] Found hidden key: HKEY_USERS\S-1-5-21-839522115-1965331169-1417001333-1003_Classes\CLSID\{CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA}
    [.] Found hidden value:
    [REG_SZ] (Standard)
    Java Plug-in 1.6.0_07
    [*] Found hidden key: HKEY_USERS\S-1-5-21-839522115-1965331169-1417001333-1003_Classes\CLSID\{CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA}\InprocServer32
    [.] Found hidden value:
    [REG_SZ] (Standard)
    C:\Program Files\Java\jre6\bin\jp2iexp.dll
    [.] Found hidden value:
    [REG_SZ] ThreadingModel
    Apartment
    [*] Found hidden key: HKEY_USERS\S-1-5-21-839522115-1965331169-1417001333-1003_Classes\CLSID\{CAFEEFAC-0016-0000-0007-ABCDEFFEDCBB}
    [.] Found hidden value:
    [REG_SZ] (Standard)
    Java Plug-in 1.6.0_07
    [*] Found hidden key: HKEY_USERS\S-1-5-21-839522115-1965331169-1417001333-1003_Classes\CLSID\{CAFEEFAC-0016-0000-0007-ABCDEFFEDCBB}\InprocServer32
    [.] Found hidden value:
    [REG_SZ] (Standard)
    C:\Program Files\Java\jre6\bin\jp2iexp.dll
    [.] Found hidden value:
    [REG_SZ] ThreadingModel
    Apartment
    [*] Found hidden key: HKEY_USERS\S-1-5-21-839522115-1965331169-1417001333-1003_Classes\CLSID\{CAFEEFAC-0016-0000-0007-ABCDEFFEDCBC}
    [.] Found hidden value:
    [REG_SZ] (Standard)
    Java Plug-in 1.6.0_07
    [*] Found hidden key: HKEY_USERS\S-1-5-21-839522115-1965331169-1417001333-1003_Classes\CLSID\{CAFEEFAC-0016-0000-0007-ABCDEFFEDCBC}\InprocServer32
    [.] Found hidden value:
    [REG_SZ] (Standard)
    C:\Program Files\Java\jre6\bin\jp2iexp.dll
    [.] Found hidden value:
    [REG_SZ] ThreadingModel
    Apartment
    [*] Found hidden key: HKEY_USERS\S-1-5-21-839522115-1965331169-1417001333-1003_Classes\CLSID\{CAFEEFAC-0016-0000-0008-ABCDEFFEDCBA}
    [.] Found hidden value:
    [REG_SZ] (Standard)
    Java Plug-in 1.6.0_08
    [*] Found hidden key: HKEY_USERS\S-1-5-21-839522115-1965331169-1417001333-1003_Classes\CLSID\{CAFEEFAC-0016-0000-0008-ABCDEFFEDCBA}\InprocServer32
    [.] Found hidden value:
    [REG_SZ] (Standard)
    C:\Program Files\Java\jre6\bin\jp2iexp.dll
    [.] Found hidden value:
    [REG_SZ] ThreadingModel
    Apartment
    [*] Found hidden key: HKEY_USERS\S-1-5-21-839522115-1965331169-1417001333-1003_Classes\CLSID\{CAFEEFAC-0016-0000-0008-ABCDEFFEDCBB}
    [.] Found hidden value:
    [REG_SZ] (Standard)
    Java Plug-in 1.6.0_08
    [*] Found hidden key: HKEY_USERS\S-1-5-21-839522115-1965331169-1417001333-1003_Classes\CLSID\{CAFEEFAC-0016-0000-0008-ABCDEFFEDCBB}\InprocServer32
    [.] Found hidden value:
    [REG_SZ] (Standard)
    C:\Program Files\Java\jre6\bin\jp2iexp.dll
    [.] Found hidden value:
    [REG_SZ] ThreadingModel
    Apartment
    [*] Found hidden key: HKEY_USERS\S-1-5-21-839522115-1965331169-1417001333-1003_Classes\CLSID\{CAFEEFAC-0016-0000-0008-ABCDEFFEDCBC}
    [.] Found hidden value:
    [REG_SZ] (Standard)
    Java Plug-in 1.6.0_08
    [*] Found hidden key: HKEY_USERS\S-1-5-21-839522115-1965331169-1417001333-1003_Classes\CLSID\{CAFEEFAC-0016-0000-0008-ABCDEFFEDCBC}\InprocServer32
    [.] Found hidden value:
    [REG_SZ] (Standard)
    C:\Program Files\Java\jre6\bin\jp2iexp.dll
    [.] Found hidden value:
    [REG_SZ] ThreadingModel
    Apartment
    [*] Found hidden key: HKEY_USERS\S-1-5-21-839522115-1965331169-1417001333-1003_Classes\CLSID\{CAFEEFAC-0016-0000-0009-ABCDEFFEDCBA}
    [.] Found hidden value:
    [REG_SZ] (Standard)
    Java Plug-in 1.6.0_09
    [*] Found hidden key: HKEY_USERS\S-1-5-21-839522115-1965331169-1417001333-1003_Classes\CLSID\{CAFEEFAC-0016-0000-0009-ABCDEFFEDCBA}\InprocServer32
    [.] Found hidden value:
    [REG_SZ] (Standard)
    C:\Program Files\Java\jre6\bin\jp2iexp.dll
    [.] Found hidden value:
    [REG_SZ] ThreadingModel
    Apartment
    [*] Found hidden key: HKEY_USERS\S-1-5-21-839522115-1965331169-1417001333-1003_Classes\CLSID\{CAFEEFAC-0016-0000-0009-ABCDEFFEDCBB}
    [.] Found hidden value:
    [REG_SZ] (Standard)
    Java Plug-in 1.6.0_09
    [*] Found hidden key: HKEY_USERS\S-1-5-21-839522115-1965331169-1417001333-1003_Classes\CLSID\{CAFEEFAC-0016-0000-0009-ABCDEFFEDCBB}\InprocServer32
    [.] Found hidden value:
    [REG_SZ] (Standard)
    C:\Program Files\Java\jre6\bin\jp2iexp.dll
    [.] Found hidden value:
    [REG_SZ] ThreadingModel
    Apartment
    [*] Found hidden key: HKEY_USERS\S-1-5-21-839522115-1965331169-1417001333-1003_Classes\CLSID\{CAFEEFAC-0016-0000-0009-ABCDEFFEDCBC}
    [.] Found hidden value:
    [REG_SZ] (Standard)
    Java Plug-in 1.6.0_09
    [*] Found hidden key: HKEY_USERS\S-1-5-21-839522115-1965331169-1417001333-1003_Classes\CLSID\{CAFEEFAC-0016-0000-0009-ABCDEFFEDCBC}\InprocServer32
    [.] Found hidden value:
    [REG_SZ] (Standard)
    C:\Program Files\Java\jre6\bin\jp2iexp.dll
    [.] Found hidden value:
    [REG_SZ] ThreadingModel
    Apartment
    [*] Found hidden key: HKEY_USERS\S-1-5-21-839522115-1965331169-1417001333-1003_Classes\CLSID\{CAFEEFAC-0016-0000-0010-ABCDEFFEDCBA}
    [.] Found hidden value:
    [REG_SZ] (Standard)
    Java Plug-in 1.6.0_10
    [*] Found hidden key: HKEY_USERS\S-1-5-21-839522115-1965331169-1417001333-1003_Classes\CLSID\{CAFEEFAC-0016-0000-0010-ABCDEFFEDCBA}\InprocServer32
    [.] Found hidden value:
    [REG_SZ] (Standard)
    C:\Program Files\Java\jre6\bin\jp2iexp.dll
    [.] Found hidden value:
    [REG_SZ] ThreadingModel
    Apartment
    [*] Found hidden key: HKEY_USERS\S-1-5-21-839522115-1965331169-1417001333-1003_Classes\CLSID\{CAFEEFAC-0016-0000-0010-ABCDEFFEDCBB}
    [.] Found hidden value:
    [REG_SZ] (Standard)
    Java Plug-in 1.6.0_10
    [*] Found hidden key: HKEY_USERS\S-1-5-21-839522115-1965331169-1417001333-1003_Classes\CLSID\{CAFEEFAC-0016-0000-0010-ABCDEFFEDCBB}\InprocServer32
    [.] Found hidden value:
    [REG_SZ] (Standard)
    C:\Program Files\Java\jre6\bin\jp2iexp.dll
    [.] Found hidden value:
    [REG_SZ] ThreadingModel
    Apartment
    [*] Found hidden key: HKEY_USERS\S-1-5-21-839522115-1965331169-1417001333-1003_Classes\CLSID\{CAFEEFAC-0016-0000-0010-ABCDEFFEDCBC}
    [.] Found hidden value:
    [REG_SZ] (Standard)
    Java Plug-in 1.6.0_10
    [*] Found hidden key: HKEY_USERS\S-1-5-21-839522115-1965331169-1417001333-1003_Classes\CLSID\{CAFEEFAC-0016-0000-0010-ABCDEFFEDCBC}\InprocServer32
    [.] Found hidden value:
    [REG_SZ] (Standard)
    C:\Program Files\Java\jre6\bin\jp2iexp.dll
    [.] Found hidden value:
    [REG_SZ] ThreadingModel
    Apartment
    [*] Found hidden key: HKEY_USERS\S-1-5-21-839522115-1965331169-1417001333-1003_Classes\CLSID\{CAFEEFAC-0016-0000-0011-ABCDEFFEDCBA}
    [.] Found hidden value:
    [REG_SZ] (Standard)
    Java Plug-in 1.6.0_11
    [*] Found hidden key: HKEY_USERS\S-1-5-21-839522115-1965331169-1417001333-1003_Classes\CLSID\{CAFEEFAC-0016-0000-0011-ABCDEFFEDCBA}\InprocServer32
    [.] Found hidden value:
    [REG_SZ] (Standard)
    C:\Program Files\Java\jre6\bin\jp2iexp.dll
    [.] Found hidden value:
    [REG_SZ] ThreadingModel
    Apartment
    [*] Found hidden key: HKEY_USERS\S-1-5-21-839522115-1965331169-1417001333-1003_Classes\CLSID\{CAFEEFAC-0016-0000-0011-ABCDEFFEDCBB}
    [.] Found hidden value:
    [REG_SZ] (Standard)
    Java Plug-in 1.6.0_11
    [*] Found hidden key: HKEY_USERS\S-1-5-21-839522115-1965331169-1417001333-1003_Classes\CLSID\{CAFEEFAC-0016-0000-0011-ABCDEFFEDCBB}\InprocServer32
    [.] Found hidden value:
    [REG_SZ] (Standard)
    C:\Program Files\Java\jre6\bin\jp2iexp.dll
    [.] Found hidden value:
    [REG_SZ] ThreadingModel
    Apartment
    [*] Found hidden key: HKEY_USERS\S-1-5-21-839522115-1965331169-1417001333-1003_Classes\CLSID\{CAFEEFAC-0016-0000-0011-ABCDEFFEDCBC}
    [.] Found hidden value:
    [REG_SZ] (Standard)
    Java Plug-in 1.6.0_11
    [*] Found hidden key: HKEY_USERS\S-1-5-21-839522115-1965331169-1417001333-1003_Classes\CLSID\{CAFEEFAC-0016-0000-0011-ABCDEFFEDCBC}\InprocServer32
    [.] Found hidden value:
    [REG_SZ] (Standard)
    C:\Program Files\Java\jre6\bin\jp2iexp.dll
    [.] Found hidden value:
    [REG_SZ] ThreadingModel
    Apartment
    [*] Found hidden key: HKEY_USERS\S-1-5-21-839522115-1965331169-1417001333-1003_Classes\CLSID\{CAFEEFAC-0016-0000-0012-ABCDEFFEDCBA}
    [.] Found hidden value:
    [REG_SZ] (Standard)
    Java Plug-in 1.6.0_12
    [*] Found hidden key: HKEY_USERS\S-1-5-21-839522115-1965331169-1417001333-1003_Classes\CLSID\{CAFEEFAC-0016-0000-0012-ABCDEFFEDCBA}\InprocServer32
    [.] Found hidden value:
    [REG_SZ] (Standard)
    C:\Program Files\Java\jre6\bin\jp2iexp.dll
    [.] Found hidden value:
    [REG_SZ] ThreadingModel
    Apartment
    [*] Found hidden key: HKEY_USERS\S-1-5-21-839522115-1965331169-1417001333-1003_Classes\CLSID\{CAFEEFAC-0016-0000-0012-ABCDEFFEDCBB}
    [.] Found hidden value:
    [REG_SZ] (Standard)
    Java Plug-in 1.6.0_12
    [*] Found hidden key: HKEY_USERS\S-1-5-21-839522115-1965331169-1417001333-1003_Classes\CLSID\{CAFEEFAC-0016-0000-0012-ABCDEFFEDCBB}\InprocServer32
    [.] Found hidden value:
    [REG_SZ] (Standard)
    C:\Program Files\Java\jre6\bin\jp2iexp.dll
    [.] Found hidden value:
    [REG_SZ] ThreadingModel
    Apartment
    [*] Found hidden key: HKEY_USERS\S-1-5-21-839522115-1965331169-1417001333-1003_Classes\CLSID\{CAFEEFAC-0016-0000-0012-ABCDEFFEDCBC}
    [.] Found hidden value:
    [REG_SZ] (Standard)
    Java Plug-in 1.6.0_12
    [*] Found hidden key: HKEY_USERS\S-1-5-21-839522115-1965331169-1417001333-1003_Classes\CLSID\{CAFEEFAC-0016-0000-0012-ABCDEFFEDCBC}\InprocServer32
    [.] Found hidden value:
    [REG_SZ] (Standard)
    C:\Program Files\Java\jre6\bin\jp2iexp.dll
    [.] Found hidden value:
    [REG_SZ] ThreadingModel
    Apartment
    [*] Found hidden key: HKEY_USERS\S-1-5-21-839522115-1965331169-1417001333-1003_Classes\CLSID\{CAFEEFAC-0016-0000-0013-ABCDEFFEDCBA}
    [.] Found hidden value:
    [REG_SZ] (Standard)
    Java Plug-in 1.6.0_13
    [*] Found hidden key: HKEY_USERS\S-1-5-21-839522115-1965331169-1417001333-1003_Classes\CLSID\{CAFEEFAC-0016-0000-0013-ABCDEFFEDCBA}\InprocServer32
    [.] Found hidden value:
    [REG_SZ] (Standard)
    C:\Program Files\Java\jre6\bin\jp2iexp.dll
    [.] Found hidden value:
    [REG_SZ] ThreadingModel
    Apartment

    74 Re: Malware problems and Internet Redirecting on Sat Aug 07, 2010 7:10 pm

    blink711


    Member
    Member
    [*] Found hidden key: HKEY_USERS\S-1-5-21-839522115-1965331169-1417001333-1003_Classes\CLSID\{CAFEEFAC-0016-0000-0013-ABCDEFFEDCBB}
    [.] Found hidden value:
    [REG_SZ] (Standard)
    Java Plug-in 1.6.0_13
    [*] Found hidden key: HKEY_USERS\S-1-5-21-839522115-1965331169-1417001333-1003_Classes\CLSID\{CAFEEFAC-0016-0000-0013-ABCDEFFEDCBB}\InprocServer32
    [.] Found hidden value:
    [REG_SZ] (Standard)
    C:\Program Files\Java\jre6\bin\jp2iexp.dll
    [.] Found hidden value:
    [REG_SZ] ThreadingModel
    Apartment
    [*] Found hidden key: HKEY_USERS\S-1-5-21-839522115-1965331169-1417001333-1003_Classes\CLSID\{CAFEEFAC-0016-0000-0013-ABCDEFFEDCBC}
    [.] Found hidden value:
    [REG_SZ] (Standard)
    Java Plug-in 1.6.0_13
    [*] Found hidden key: HKEY_USERS\S-1-5-21-839522115-1965331169-1417001333-1003_Classes\CLSID\{CAFEEFAC-0016-0000-0013-ABCDEFFEDCBC}\InprocServer32
    [.] Found hidden value:
    [REG_SZ] (Standard)
    C:\Program Files\Java\jre6\bin\jp2iexp.dll
    [.] Found hidden value:
    [REG_SZ] ThreadingModel
    Apartment
    [*] Found hidden key: HKEY_USERS\S-1-5-21-839522115-1965331169-1417001333-1003_Classes\CLSID\{CAFEEFAC-0016-0000-0014-ABCDEFFEDCBA}
    [.] Found hidden value:
    [REG_SZ] (Standard)
    Java Plug-in 1.6.0_14
    [*] Found hidden key: HKEY_USERS\S-1-5-21-839522115-1965331169-1417001333-1003_Classes\CLSID\{CAFEEFAC-0016-0000-0014-ABCDEFFEDCBA}\InprocServer32
    [.] Found hidden value:
    [REG_SZ] (Standard)
    C:\Program Files\Java\jre6\bin\jp2iexp.dll
    [.] Found hidden value:
    [REG_SZ] ThreadingModel
    Apartment
    [*] Found hidden key: HKEY_USERS\S-1-5-21-839522115-1965331169-1417001333-1003_Classes\CLSID\{CAFEEFAC-0016-0000-0014-ABCDEFFEDCBB}
    [.] Found hidden value:
    [REG_SZ] (Standard)
    Java Plug-in 1.6.0_14
    [*] Found hidden key: HKEY_USERS\S-1-5-21-839522115-1965331169-1417001333-1003_Classes\CLSID\{CAFEEFAC-0016-0000-0014-ABCDEFFEDCBB}\InprocServer32
    [.] Found hidden value:
    [REG_SZ] (Standard)
    C:\Program Files\Java\jre6\bin\jp2iexp.dll
    [.] Found hidden value:
    [REG_SZ] ThreadingModel
    Apartment
    [*] Found hidden key: HKEY_USERS\S-1-5-21-839522115-1965331169-1417001333-1003_Classes\CLSID\{CAFEEFAC-0016-0000-0014-ABCDEFFEDCBC}
    [.] Found hidden value:
    [REG_SZ] (Standard)
    Java Plug-in 1.6.0_14
    [*] Found hidden key: HKEY_USERS\S-1-5-21-839522115-1965331169-1417001333-1003_Classes\CLSID\{CAFEEFAC-0016-0000-0014-ABCDEFFEDCBC}\InprocServer32
    [.] Found hidden value:
    [REG_SZ] (Standard)
    C:\Program Files\Java\jre6\bin\jp2iexp.dll
    [.] Found hidden value:
    [REG_SZ] ThreadingModel
    Apartment
    [*] Found hidden key: HKEY_USERS\S-1-5-21-839522115-1965331169-1417001333-1003_Classes\CLSID\{CAFEEFAC-0016-0000-0015-ABCDEFFEDCBA}
    [.] Found hidden value:
    [REG_SZ] (Standard)
    Java Plug-in 1.6.0_15
    [*] Found hidden key: HKEY_USERS\S-1-5-21-839522115-1965331169-1417001333-1003_Classes\CLSID\{CAFEEFAC-0016-0000-0015-ABCDEFFEDCBA}\InprocServer32
    [.] Found hidden value:
    [REG_SZ] (Standard)
    C:\Program Files\Java\jre6\bin\jp2iexp.dll
    [.] Found hidden value:
    [REG_SZ] ThreadingModel
    Apartment
    [*] Found hidden key: HKEY_USERS\S-1-5-21-839522115-1965331169-1417001333-1003_Classes\CLSID\{CAFEEFAC-0016-0000-0015-ABCDEFFEDCBB}
    [.] Found hidden value:
    [REG_SZ] (Standard)
    Java Plug-in 1.6.0_15
    [*] Found hidden key: HKEY_USERS\S-1-5-21-839522115-1965331169-1417001333-1003_Classes\CLSID\{CAFEEFAC-0016-0000-0015-ABCDEFFEDCBB}\InprocServer32
    [.] Found hidden value:
    [REG_SZ] (Standard)
    C:\Program Files\Java\jre6\bin\jp2iexp.dll
    [.] Found hidden value:
    [REG_SZ] ThreadingModel
    Apartment
    [*] Found hidden key: HKEY_USERS\S-1-5-21-839522115-1965331169-1417001333-1003_Classes\CLSID\{CAFEEFAC-0016-0000-0015-ABCDEFFEDCBC}
    [.] Found hidden value:
    [REG_SZ] (Standard)
    Java Plug-in 1.6.0_15
    [*] Found hidden key: HKEY_USERS\S-1-5-21-839522115-1965331169-1417001333-1003_Classes\CLSID\{CAFEEFAC-0016-0000-0015-ABCDEFFEDCBC}\InprocServer32
    [.] Found hidden value:
    [REG_SZ] (Standard)
    C:\Program Files\Java\jre6\bin\jp2iexp.dll
    [.] Found hidden value:
    [REG_SZ] ThreadingModel
    Apartment
    [*] Found hidden key: HKEY_USERS\S-1-5-21-839522115-1965331169-1417001333-1003_Classes\CLSID\{CAFEEFAC-0016-0000-0016-ABCDEFFEDCBA}
    [.] Found hidden value:
    [REG_SZ] (Standard)
    Java Plug-in 1.6.0_16
    [*] Found hidden key: HKEY_USERS\S-1-5-21-839522115-1965331169-1417001333-1003_Classes\CLSID\{CAFEEFAC-0016-0000-0016-ABCDEFFEDCBA}\InprocServer32
    [.] Found hidden value:
    [REG_SZ] (Standard)
    C:\Program Files\Java\jre6\bin\jp2iexp.dll
    [.] Found hidden value:
    [REG_SZ] ThreadingModel
    Apartment
    [*] Found hidden key: HKEY_USERS\S-1-5-21-839522115-1965331169-1417001333-1003_Classes\CLSID\{CAFEEFAC-0016-0000-0016-ABCDEFFEDCBB}
    [.] Found hidden value:
    [REG_SZ] (Standard)
    Java Plug-in 1.6.0_16
    [*] Found hidden key: HKEY_USERS\S-1-5-21-839522115-1965331169-1417001333-1003_Classes\CLSID\{CAFEEFAC-0016-0000-0016-ABCDEFFEDCBB}\InprocServer32
    [.] Found hidden value:
    [REG_SZ] (Standard)
    C:\Program Files\Java\jre6\bin\jp2iexp.dll
    [.] Found hidden value:
    [REG_SZ] ThreadingModel
    Apartment
    [*] Found hidden key: HKEY_USERS\S-1-5-21-839522115-1965331169-1417001333-1003_Classes\CLSID\{CAFEEFAC-0016-0000-0016-ABCDEFFEDCBC}
    [.] Found hidden value:
    [REG_SZ] (Standard)
    Java Plug-in 1.6.0_16
    [*] Found hidden key: HKEY_USERS\S-1-5-21-839522115-1965331169-1417001333-1003_Classes\CLSID\{CAFEEFAC-0016-0000-0016-ABCDEFFEDCBC}\InprocServer32
    [.] Found hidden value:
    [REG_SZ] (Standard)
    C:\Program Files\Java\jre6\bin\jp2iexp.dll
    [.] Found hidden value:
    [REG_SZ] ThreadingModel
    Apartment
    [*] Found hidden key: HKEY_USERS\S-1-5-21-839522115-1965331169-1417001333-1003_Classes\CLSID\{CAFEEFAC-0016-0000-0017-ABCDEFFEDCBA}
    [.] Found hidden value:
    [REG_SZ] (Standard)
    Java Plug-in 1.6.0_17
    [*] Found hidden key: HKEY_USERS\S-1-5-21-839522115-1965331169-1417001333-1003_Classes\CLSID\{CAFEEFAC-0016-0000-0017-ABCDEFFEDCBA}\InprocServer32
    [.] Found hidden value:
    [REG_SZ] (Standard)
    C:\Program Files\Java\jre6\bin\jp2iexp.dll
    [.] Found hidden value:
    [REG_SZ] ThreadingModel
    Apartment
    [*] Found hidden key: HKEY_USERS\S-1-5-21-839522115-1965331169-1417001333-1003_Classes\CLSID\{CAFEEFAC-0016-0000-0017-ABCDEFFEDCBB}
    [.] Found hidden value:
    [REG_SZ] (Standard)
    Java Plug-in 1.6.0_17
    [*] Found hidden key: HKEY_USERS\S-1-5-21-839522115-1965331169-1417001333-1003_Classes\CLSID\{CAFEEFAC-0016-0000-0017-ABCDEFFEDCBB}\InprocServer32
    [.] Found hidden value:
    [REG_SZ] (Standard)
    C:\Program Files\Java\jre6\bin\jp2iexp.dll
    [.] Found hidden value:
    [REG_SZ] ThreadingModel
    Apartment
    [*] Found hidden key: HKEY_USERS\S-1-5-21-839522115-1965331169-1417001333-1003_Classes\CLSID\{CAFEEFAC-0016-0000-0017-ABCDEFFEDCBC}
    [.] Found hidden value:
    [REG_SZ] (Standard)
    Java Plug-in 1.6.0_17
    [*] Found hidden key: HKEY_USERS\S-1-5-21-839522115-1965331169-1417001333-1003_Classes\CLSID\{CAFEEFAC-0016-0000-0017-ABCDEFFEDCBC}\InprocServer32
    [.] Found hidden value:
    [REG_SZ] (Standard)
    C:\Program Files\Java\jre6\bin\jp2iexp.dll
    [.] Found hidden value:
    [REG_SZ] ThreadingModel
    Apartment
    [*] Found hidden key: HKEY_USERS\S-1-5-21-839522115-1965331169-1417001333-1003_Classes\CLSID\{CAFEEFAC-0016-0000-0018-ABCDEFFEDCBA}
    [.] Found hidden value:
    [REG_SZ] (Standard)
    Java Plug-in 1.6.0_18
    [*] Found hidden key: HKEY_USERS\S-1-5-21-839522115-1965331169-1417001333-1003_Classes\CLSID\{CAFEEFAC-0016-0000-0018-ABCDEFFEDCBA}\InprocServer32
    [.] Found hidden value:
    [REG_SZ] (Standard)
    C:\Program Files\Java\jre6\bin\jp2iexp.dll
    [.] Found hidden value:
    [REG_SZ] ThreadingModel
    Apartment
    [*] Found hidden key: HKEY_USERS\S-1-5-21-839522115-1965331169-1417001333-1003_Classes\CLSID\{CAFEEFAC-0016-0000-0018-ABCDEFFEDCBB}
    [.] Found hidden value:
    [REG_SZ] (Standard)
    Java Plug-in 1.6.0_18
    [*] Found hidden key: HKEY_USERS\S-1-5-21-839522115-1965331169-1417001333-1003_Classes\CLSID\{CAFEEFAC-0016-0000-0018-ABCDEFFEDCBB}\InprocServer32
    [.] Found hidden value:
    [REG_SZ] (Standard)
    C:\Program Files\Java\jre6\bin\jp2iexp.dll
    [.] Found hidden value:
    [REG_SZ] ThreadingModel
    Apartment
    [*] Found hidden key: HKEY_USERS\S-1-5-21-839522115-1965331169-1417001333-1003_Classes\CLSID\{CAFEEFAC-0016-0000-0018-ABCDEFFEDCBC}
    [.] Found hidden value:
    [REG_SZ] (Standard)
    Java Plug-in 1.6.0_18
    [*] Found hidden key: HKEY_USERS\S-1-5-21-839522115-1965331169-1417001333-1003_Classes\CLSID\{CAFEEFAC-0016-0000-0018-ABCDEFFEDCBC}\InprocServer32
    [.] Found hidden value:
    [REG_SZ] (Standard)
    C:\Program Files\Java\jre6\bin\jp2iexp.dll
    [.] Found hidden value:
    [REG_SZ] ThreadingModel
    Apartment
    [*] Found hidden key: HKEY_USERS\S-1-5-21-839522115-1965331169-1417001333-1003_Classes\CLSID\{CAFEEFAC-0016-0000-0019-ABCDEFFEDCBA}
    [.] Found hidden value:
    [REG_SZ] (Standard)
    Java Plug-in 1.6.0_19
    [*] Found hidden key: HKEY_USERS\S-1-5-21-839522115-1965331169-1417001333-1003_Classes\CLSID\{CAFEEFAC-0016-0000-0019-ABCDEFFEDCBA}\InprocServer32
    [.] Found hidden value:
    [REG_SZ] (Standard)
    C:\Program Files\Java\jre6\bin\jp2iexp.dll
    [.] Found hidden value:
    [REG_SZ] ThreadingModel
    Apartment
    [*] Found hidden key: HKEY_USERS\S-1-5-21-839522115-1965331169-1417001333-1003_Classes\CLSID\{CAFEEFAC-0016-0000-0019-ABCDEFFEDCBB}
    [.] Found hidden value:
    [REG_SZ] (Standard)
    Java Plug-in 1.6.0_19
    [*] Found hidden key: HKEY_USERS\S-1-5-21-839522115-1965331169-1417001333-1003_Classes\CLSID\{CAFEEFAC-0016-0000-0019-ABCDEFFEDCBB}\InprocServer32
    [.] Found hidden value:
    [REG_SZ] (Standard)
    C:\Program Files\Java\jre6\bin\jp2iexp.dll
    [.] Found hidden value:
    [REG_SZ] ThreadingModel
    Apartment
    [*] Found hidden key: HKEY_USERS\S-1-5-21-839522115-1965331169-1417001333-1003_Classes\CLSID\{CAFEEFAC-0016-0000-0019-ABCDEFFEDCBC}
    [.] Found hidden value:
    [REG_SZ] (Standard)
    Java Plug-in 1.6.0_19
    [*] Found hidden key: HKEY_USERS\S-1-5-21-839522115-1965331169-1417001333-1003_Classes\CLSID\{CAFEEFAC-0016-0000-0019-ABCDEFFEDCBC}\InprocServer32
    [.] Found hidden value:
    [REG_SZ] (Standard)
    C:\Program Files\Java\jre6\bin\jp2iexp.dll
    [.] Found hidden value:
    [REG_SZ] ThreadingModel
    Apartment
    [*] Found hidden key: HKEY_USERS\S-1-5-21-839522115-1965331169-1417001333-1003_Classes\CLSID\{CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA}
    [.] Found hidden value:
    [REG_SZ] (Standard)
    Java Plug-in 1.6.0_20
    [*] Found hidden key: HKEY_USERS\S-1-5-21-839522115-1965331169-1417001333-1003_Classes\CLSID\{CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA}\InprocServer32
    [.] Found hidden value:
    [REG_SZ] (Standard)
    C:\Program Files\Java\jre6\bin\jp2iexp.dll
    [.] Found hidden value:
    [REG_SZ] ThreadingModel
    Apartment
    [*] Found hidden key: HKEY_USERS\S-1-5-21-839522115-1965331169-1417001333-1003_Classes\CLSID\{CAFEEFAC-0016-0000-0020-ABCDEFFEDCBB}
    [.] Found hidden value:
    [REG_SZ] (Standard)
    Java Plug-in 1.6.0_20
    [*] Found hidden key: HKEY_USERS\S-1-5-21-839522115-1965331169-1417001333-1003_Classes\CLSID\{CAFEEFAC-0016-0000-0020-ABCDEFFEDCBB}\InprocServer32
    [.] Found hidden value:
    [REG_SZ] (Standard)
    C:\Program Files\Java\jre6\bin\jp2iexp.dll
    [.] Found hidden value:
    [REG_SZ] ThreadingModel
    Apartment
    [*] Found hidden key: HKEY_USERS\S-1-5-21-839522115-1965331169-1417001333-1003_Classes\CLSID\{CAFEEFAC-0016-0000-0020-ABCDEFFEDCBC}
    [.] Found hidden value:
    [REG_SZ] (Standard)
    Java Plug-in 1.6.0_20
    [*] Found hidden key: HKEY_USERS\S-1-5-21-839522115-1965331169-1417001333-1003_Classes\CLSID\{CAFEEFAC-0016-0000-0020-ABCDEFFEDCBC}\InprocServer32
    [.] Found hidden value:
    [REG_SZ] (Standard)
    C:\Program Files\Java\jre6\bin\jp2iexp.dll
    [.] Found hidden value:
    [REG_SZ] ThreadingModel
    Apartment
    [*] Found hidden key: HKEY_USERS\S-1-5-21-839522115-1965331169-1417001333-1003_Classes\CLSID\{CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA}
    [.] Found hidden value:
    [REG_SZ] (Standard)
    Java Plug-in 1.6.0_21
    [*] Found hidden key: HKEY_USERS\S-1-5-21-839522115-1965331169-1417001333-1003_Classes\CLSID\{CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA}\InprocServer32
    [.] Found hidden value:
    [REG_SZ] (Standard)
    C:\Program Files\Java\jre6\bin\jp2iexp.dll
    [.] Found hidden value:
    [REG_SZ] ThreadingModel
    Apartment
    [*] Found hidden key: HKEY_USERS\S-1-5-21-839522115-1965331169-1417001333-1003_Classes\CLSID\{CAFEEFAC-0016-0000-0021-ABCDEFFEDCBB}
    [.] Found hidden value:
    [REG_SZ] (Standard)
    Java Plug-in 1.6.0_21
    [*] Found hidden key: HKEY_USERS\S-1-5-21-839522115-1965331169-1417001333-1003_Classes\CLSID\{CAFEEFAC-0016-0000-0021-ABCDEFFEDCBB}\InprocServer32
    [.] Found hidden value:
    [REG_SZ] (Standard)
    C:\Program Files\Java\jre6\bin\jp2iexp.dll
    [.] Found hidden value:
    [REG_SZ] ThreadingModel
    Apartment
    [*] Found hidden key: HKEY_USERS\S-1-5-21-839522115-1965331169-1417001333-1003_Classes\CLSID\{CAFEEFAC-0016-0000-0021-ABCDEFFEDCBC}
    [.] Found hidden value:
    [REG_SZ] (Standard)
    Java Plug-in 1.6.0_21
    [*] Found hidden key: HKEY_USERS\S-1-5-21-839522115-1965331169-1417001333-1003_Classes\CLSID\{CAFEEFAC-0016-0000-0021-ABCDEFFEDCBC}\InprocServer32
    [.] Found hidden value:
    [REG_SZ] (Standard)
    C:\Program Files\Java\jre6\bin\jp2iexp.dll
    [.] Found hidden value:
    [REG_SZ] ThreadingModel
    Apartment
    [*] Found hidden key: HKEY_USERS\S-1-5-21-839522115-1965331169-1417001333-1003_Classes\CLSID\{CAFEEFAC-0016-0000-FFFF-ABCDEFFEDCBA}
    [.] Found hidden value:
    [REG_SZ] (Standard)
    Java Plug-in 1.6.0
    [*] Found hidden key: HKEY_USERS\S-1-5-21-839522115-1965331169-1417001333-1003_Classes\CLSID\{CAFEEFAC-0016-0000-FFFF-ABCDEFFEDCBA}\InprocServer32
    [.] Found hidden value:
    [REG_SZ] (Standard)
    C:\Program Files\Java\jre6\bin\jp2iexp.dll
    [.] Found hidden value:
    [REG_SZ] ThreadingModel
    Apartment
    [*] Found hidden key: HKEY_USERS\S-1-5-21-839522115-1965331169-1417001333-1003_Classes\CLSID\{E19F9331-3110-11D4-991C-005004D3B3DB}
    [.] Found hidden value:
    [REG_SZ] (Standard)
    Java Plug-in 1.3.0_02
    [*] Found hidden key: HKEY_USERS\S-1-5-21-839522115-1965331169-1417001333-1003_Classes\CLSID\{E19F9331-3110-11D4-991C-005004D3B3DB}\InprocServer32
    [.] Found hidden value:
    [REG_SZ] (Standard)
    C:\Program Files\Java\jre6\bin\jp2iexp.dll
    [.] Found hidden value:
    [REG_SZ] ThreadingModel
    Apartment
    [*] Found hidden key: HKEY_USERS\S-1-5-21-839522115-1965331169-1417001333-1003_Classes\JavaPlugin.160_05
    [*] Found hidden key: HKEY_USERS\S-1-5-21-839522115-1965331169-1417001333-1003_Classes\JavaPlugin.160_05\CLSID
    [.] Found hidden value:
    [REG_SZ] (Standard)
    {5852F5ED-8BF4-11D4-A245-0080C6F74284}
    [*] Found hidden key: HKEY_USERS\S-1-5-21-839522115-1965331169-1417001333-1003_Classes\JavaPlugin.160_21
    [*] Found hidden key: HKEY_USERS\S-1-5-21-839522115-1965331169-1417001333-1003_Classes\JavaPlugin.160_21\CLSID
    [.] Found hidden value:
    [REG_SZ] (Standard)
    {5852F5ED-8BF4-11D4-A245-0080C6F74284}
    [*] Found hidden key: HKEY_USERS\S-1-5-21-839522115-1965331169-1417001333-1003_Classes\Network
    [*] Found hidden key: HKEY_USERS\S-1-5-21-839522115-1965331169-1417001333-1003_Classes\PROTOCOLS
    [*] Found hidden key: HKEY_USERS\S-1-5-21-839522115-1965331169-1417001333-1003_Classes\PROTOCOLS\Filter
    [*] Found hidden key: HKEY_USERS\S-1-5-21-839522115-1965331169-1417001333-1003_Classes\Software
    [*] Found hidden key: HKEY_USERS\S-1-5-21-839522115-1965331169-1417001333-1003_Classes\Software\Microsoft
    [*] Found hidden key: HKEY_USERS\S-1-5-21-839522115-1965331169-1417001333-1003_Classes\Software\Microsoft\MediaPlayer
    [*] Found hidden key: HKEY_USERS\S-1-5-21-839522115-1965331169-1417001333-1003_Classes\Software\Microsoft\MediaPlayer\Preferences
    [.] Found hidden value:
    [REG_DWORD] AcceptedPrivacyStatement
    00000001
    [*] Found hidden key: HKEY_USERS\S-1-5-21-839522115-1965331169-1417001333-1003_Classes\Software\Microsoft\Preferences
    [*] Found hidden key: HKEY_USERS\S-1-5-21-839522115-1965331169-1417001333-1003_Classes\Software\Microsoft\Windows NT
    [*] Found hidden key: HKEY_USERS\S-1-5-21-839522115-1965331169-1417001333-1003_Classes\Software\Microsoft\Windows NT\CurrentVersion
    [*] Found hidden key: HKEY_USERS\S-1-5-21-839522115-1965331169-1417001333-1003_Classes\Software\Microsoft\Windows NT\CurrentVersion\Network
    [*] Found hidden key: HKEY_USERS\S-1-5-21-839522115-1965331169-1417001333-1003_Classes\Software\Microsoft\Windows NT\CurrentVersion\Network\Persistent Connections
    DONE.
    -------------------------------------------------------------------------------

    --------------------[HKEY_USERS\S-1-5-18 ]-------------------
    WARNING: Dumping the registry can take quite some time! Be assured
    that the app doesn't hang while dumping!
    Dumping...OK.
    Scanning...DONE.
    -------------------------------------------------------------------------------

    22:22:19 - Performing check: "Hidden processes":
    (01) PID: 0 [00000000] (Idle)
    (53) PID: 4 [823C8830] (System)
    (191) PID: 368 [8225A318] (ctfmon.exe)
    (191) PID: 548 [817A5BE8] (explorer.exe)
    (191) PID: 620 [816665B0] (SynTPEnh.exe)
    (191) PID: 632 [81664BF8] (RTHDCPL.EXE)
    (07) PID: 768 [81948DA0] (smss.exe)
    (191) PID: 816 [818FE020] (csrss.exe)
    (191) PID: 840 [818F6A20] (winlogon.exe)
    (191) PID: 884 [81908B48] (services.exe)
    (191) PID: 896 [818D2908] (lsass.exe)
    (191) PID: 1064 [818A32F8] (svchost.exe)
    (191) PID: 1132 [81895D78] (svchost.exe)
    (191) PID: 1172 [81888748] (svchost.exe)
    (175) PID: 1288 [8187CDA0] (svchost.exe)
    (191) PID: 1320 [81873020] (svchost.exe)
    (175) PID: 1372 [8226ED70] (hpwuSchd2.exe)
    (187) PID: 1404 [81526DA0] (radixgui.exe)
    (175) PID: 1416 [8151E7D0] (svchost.exe)
    (175) PID: 1424 [82267020] (hkcmd.exe)
    (191) PID: 1432 [82257730] (igfxpers.exe)
    (175) PID: 1456 [8226F870] (jusched.exe)
    (175) PID: 1556 [8185AA20] (spoolsv.exe)
    (191) PID: 1600 [82255020] (igfxsrvc.exe)
    (175) PID: 1604 [82254418] (BTMeter.exe)
    (175) PID: 1652 [81865340] (svchost.exe)
    (175) PID: 1680 [81716DA0] (WLSS.exe)
    (175) PID: 1744 [8183B9B0] (svchost.exe)
    (191) PID: 1780 [81831318] (jqs.exe)
    (191) PID: 1880 [817FFA98] (svchost.exe)
    (191) PID: 1992 [817F7A20] (YahooAUService.exe)
    (191) PID: 2596 [817378B0] (alg.exe)
    (175) PID: 2804 [818029F8] (wscntfy.exe)
    (191) PID: 2816 [81703580] (iexplore.exe)
    (175) PID: 3080 [817B6C08] (hpqste08.exe)
    (175) PID: 3160 [817EB5D0] (hpqbam08.exe)
    (175) PID: 3208 [822FA390] (hpqgpc01.exe)
    22:22:20 - Performing check: "Hidden services":
    # Service Startup File
    0 .NET CLR Data Disabled
    1 .NET CLR Networking Disabled
    2 .NET Data Provider for Oracle Disabled
    3 .NET Data Provider for SqlServer Disabled
    4 .NETFramework Disabled
    5 Abiosdsk Disabled
    6 abp480n5 Disabled abp480n5
    7 ACPI Boot Microsoft ACPI Driver
    8 ACPIEC Boot Microsoft Embedded Controller Driver
    9 adpu160m Disabled adpu160m
    10 aec Demand Microsoft Kernel Acoustic Echo Canceller
    11 AFD System AFD
    12 agp440 Disabled Intel AGP Bus Filter
    13 agpCPQ Disabled Compaq AGP Bus Filter
    14 Aha154x Disabled Aha154x
    15 aic78u2 Disabled aic78u2
    16 aic78xx Disabled aic78xx
    17 Alerter Disabled Alerter
    18 ALG Demand Application Layer Gateway Service
    19 AliIde Disabled AliIde
    20 alim1541 Disabled ALI AGP Bus Filter
    21 amdagp Disabled AMD AGP Bus Filter Driver
    22 amsint Disabled amsint
    23 AppMgmt Demand Application Management
    24 asc Disabled asc
    25 asc3350p Disabled asc3350p
    26 asc3550 Disabled asc3550
    27 ASP.NET Disabled
    28 ASP.NET_1.1.4322 Disabled
    29 ASP.NET_2.0.50727 Disabled
    30 aspnet_state Demand ASP.NET State Service
    31 AsyncMac Demand RAS Asynchronous Media Driver
    32 atapi Boot Standard IDE/ESDI Hard Disk Controller
    33 Atdisk Disabled
    34 Atmarpc Demand ATM ARP Client Protocol
    35 AudioSrv Auto Windows Audio
    36 audstub Demand Audio Stub Driver
    37 BattC Disabled
    38 BCM43XX Demand Broadcom 802.11 Network Adapter Driver
    39 Beep System
    40 BITS Auto Background Intelligent Transfer Service
    41 Browser Auto Computer Browser
    42 catchme Demand
    43 cbidf Disabled cbidf
    44 cbidf2k Disabled
    45 cd20xrnt Disabled cd20xrnt
    46 Cdaudio System
    47 Cdfs Disabled
    48 Cdrom System CD-ROM Driver
    49 Changer System
    50 CiSvc Demand Indexing Service
    51 ClipSrv Demand ClipBook
    52 clr_optimization_v2.0.50727_32 Demand .NET Runtime Optimization Service v2.0.50727_X86
    53 CmBatt Demand Microsoft ACPI Control Method Battery Driver
    54 CmdIde Disabled CmdIde
    55 Compbatt Boot Microsoft Composite Battery Driver
    56 COMSysApp Demand COM+ System Application
    57 ContentFilter Disabled
    58 ContentIndex Disabled
    59 Cpqarray Disabled Cpqarray
    60 CryptSvc Auto CryptSvc
    61 dac2w2k Disabled dac2w2k
    62 dac960nt Disabled dac960nt
    63 DcomLaunch Auto DCOM Server Process Launcher
    64 Dhcp Auto DHCP Client
    65 Disk Boot Disk Driver
    66 dmadmin Demand Logical Disk Manager Administrative Service
    67 dmboot Disabled
    68 dmio Disabled
    69 dmload Disabled
    70 dmserver Demand Logical Disk Manager
    71 DMusic Demand Microsoft Kernel DLS Syntheiszer
    72 Dnscache Auto DNS Client
    73 Dot3svc Demand Wired AutoConfig
    74 dpti2o Disabled dpti2o
    75 drmkaud Demand Microsoft Kernel DRM Audio Descrambler
    76 EapHost Demand Extensible Authentication Protocol Service
    77 EMSC Boot COMPAL Embedded System Control
    78 ERSvc Auto Error Reporting Service
    79 Eventlog Auto Event Log
    80 EventSystem Demand COM+ Event System
    81 Fastfat Disabled
    82 FastUserSwitchingCompatibility Demand Fast User Switching Compatibility
    83 Fax Auto Fax
    84 Fdc System
    85 Fips System
    86 Flpydisk System
    87 FltMgr Boot FltMgr
    88 FontCache3.0.0.0 Demand Windows Presentation Foundation Font Cache 3.0.0.0
    89 Fs_Rec System
    90 Ftdisk Boot Volume Manager Driver
    91 Gpc Demand Generic Packet Classifier
    92 HDAudBus Demand Microsoft UAA Bus Driver for High Definition Audio
    93 helpsvc Auto Help and Support
    94 HidServ Auto HID Input Service
    95 hidusb Demand Microsoft HID Class Driver
    96 hkmsvc Demand Health Key and Certificate Management Service
    97 hpn Disabled hpn
    98 hpqcxs08 Demand hpqcxs08
    99 hpqddsvc Auto HP CUE DeviceDiscovery Service
    100 HPZid412 Demand IEEE-1284.4 Driver HPZid412
    101 HPZipr12 Demand Print Class Driver for IEEE-1284.4 HPZipr12
    102 HPZius12 Demand USB to IEEE-1284.4 Translation Driver HPZius12
    103 HTTP Demand HTTP
    104 HTTPFilter Demand HTTP SSL
    105 i2omgmt System
    106 i2omp Disabled i2omp
    107 i8042prt System i8042 Keyboard and PS/2 Mouse Port Driver
    108 ialm Demand
    109 IDriverT Demand InstallDriver Table Manager
    110 idsvc Demand Windows CardSpace
    111 Imapi System CD-Burning Filter Driver
    112 ImapiService Demand IMAPI CD-Burning COM Service
    113 inetaccs Disabled
    114 ini910u Disabled ini910u
    115 Inport Disabled
    116 IntcAzAudAddService Demand Service for Realtek HD Audio (WDM)
    117 IntelIde Disabled IntelIde
    118 intelppm System Intel Processor Driver
    119 Ip6Fw Demand IPv6 Windows Firewall Driver
    120 IpFilterDriver Demand IP Traffic Filter Driver
    121 IpInIp Demand IP in IP Tunnel Driver
    122 IpNat Demand IP Network Address Translator
    123 IPSec System IPSEC driver
    124 IRENUM Demand IR Enumerator Service
    125 ISAPISearch Disabled
    126 isapnp Boot PnP ISA/EISA Bus Driver
    127 JavaQuickStarterService Auto Java Quick Starter
    128 JMCR Demand
    129 Kbdclass System Keyboard Class Driver
    130 kbdhid System Keyboard HID Driver
    131 kmixer Demand Microsoft Kernel Wave Audio Mixer
    132 KSecDD Boot
    133 LanmanServer Auto Server
    134 lanmanworkstation Auto Workstation
    135 lbrtfdc System
    136 ldap Disabled
    137 LicenseService Disabled
    138 LmHosts Auto TCP/IP NetBIOS Helper
    139 Messenger Disabled Messenger
    140 mnmdd System
    141 mnmsrvc Demand NetMeeting Remote Desktop Sharing
    142 Modem Demand
    143 Mouclass System Mouse Class Driver
    144 mouhid Demand Mouse HID Driver
    145 MountMgr Boot
    146 mraid35x Disabled mraid35x
    147 MRxDAV Demand WebDav Client Redirector
    148 MRxSmb System MRXSMB
    149 MSDTC Demand Distributed Transaction Coordinator
    150 MSDTC Bridge 3.0.0.0 Disabled
    151 Msfs System
    152 MSIServer Demand Windows Installer
    153 MSKSSRV Demand Microsoft Streaming Service Proxy
    154 MSPCLOCK Demand Microsoft Streaming Clock Proxy
    155 MSPQM Demand Microsoft Streaming Quality Manager Proxy
    156 mssmbios Demand Microsoft System Management BIOS Driver
    157 Mup Boot Mup
    158 napagent Demand Network Access Protection Agent
    159 NDIS Boot NDIS System Driver
    160 NdisTapi Demand Remote Access NDIS TAPI Driver
    161 Ndisuio Demand NDIS Usermode I/O Protocol
    162 NdisWan Demand Remote Access NDIS WAN Driver
    163 NDProxy Demand NDIS Proxyd
    164 Net Driver HPZ12 Auto
    165 NetBIOS System NetBIOS Interface
    166 NetBT System NetBios over Tcpip
    167 NetDDE Disabled Network DDE
    168 NetDDEdsdm Disabled Network DDE DSDM
    169 Netlogon Demand Net Logon
    170 Netman Demand Network Connections
    171 NetTcpPortSharing Disabled Net.Tcp Port Sharing Service
    172 Nla Demand Network Location Awareness (NLA)
    173 Npfs System
    174 Ntfs Disabled
    175 NtLmSsp Demand NT LM Security Support Provider
    176 NtmsSvc Demand Removable Storage
    177 Null System
    178 NwlnkFlt Demand IPX Traffic Filter Driver
    179 NwlnkFwd Demand IPX Traffic Forwarder Driver

    75 Re: Malware problems and Internet Redirecting on Sat Aug 07, 2010 7:12 pm

    blink711


    Member
    Member
    180 Parport Demand
    181 PartMgr Boot
    182 ParVdm Disabled
    183 PCI Boot PCI Bus Driver
    184 PCIDump System
    185 PCIIde Boot
    186 Pcmcia Disabled
    187 PDCOMP Demand
    188 PDFRAME Demand
    189 PDRELI Demand
    190 PDRFRAME Demand
    191 perc2 Disabled perc2
    192 perc2hib Disabled perc2hib
    193 PerfDisk Disabled
    194 PerfNet Disabled
    195 PerfOS Disabled
    196 PerfProc Disabled
    197 PlugPlay Auto Plug and Play
    198 Pml Driver HPZ12 Auto
    199 PolicyAgent Auto IPSEC Services
    200 PptpMiniport Demand WAN Miniport (PPTP)
    201 ProtectedStorage Auto Protected Storage
    202 PSched Demand QoS Packet Scheduler
    203 Ptilink Demand Direct Parallel Link Driver
    204 ql1080 Disabled ql1080
    205 Ql10wnt Disabled Ql10wnt
    206 ql12160 Disabled ql12160
    207 ql1240 Disabled ql1240
    208 ql1280 Disabled ql1280
    209 RasAcd System Remote Access Auto Connection Driver
    210 RasAuto Demand Remote Access Auto Connection Manager
    211 Rasl2tp Demand WAN Miniport (L2TP)
    212 RasMan Demand Remote Access Connection Manager
    213 RasPppoe Demand Remote Access PPPOE Driver
    214 Raspti Demand Direct Parallel
    215 Rdbss System Rdbss
    216 RDPCDD System
    217 RDPDD Disabled
    218 rdpdr Demand Terminal Server Device Redirector Driver
    219 RDPNP Disabled
    220 RDPWD Demand
    221 RDSessMgr Demand Remote Desktop Help Session Manager
    222 redbook System Digital CD Audio Playback Filter Driver
    223 RemoteAccess Disabled Routing and Remote Access
    224 RpcLocator Demand Remote Procedure Call (RPC) Locator
    225 RpcSs Auto Remote Procedure Call (RPC)
    226 RSVP Demand QoS RSVP
    227 RTLE8023xp Demand Realtek 10/100/1000 PCI-E NIC Family NDIS XP Driver
    228 SamSs Auto Security Accounts Manager
    229 SCardSvr Demand Smart Card
    230 Schedule Auto Task Scheduler
    231 sdbus Demand
    232 SDTHelper Demand Helper driver for SDT-Tool
    233 Secdrv Demand Secdrv
    234 seclogon Auto Secondary Logon
    235 SENS Auto System Event Notification
    236 Serial Auto
    237 ServiceModelEndpoint 3.0.0.0 Disabled
    238 ServiceModelOperation 3.0.0.0 Disabled
    239 ServiceModelService 3.0.0.0 Disabled
    240 Sfloppy System
    241 SharedAccess Auto Windows Firewall/Internet Connection Sharing (ICS)
    242 ShellHWDetection Auto Shell Hardware Detection
    243 Simbad Disabled
    244 sisagp Disabled SIS AGP Bus Filter
    245 SMSvcHost 3.0.0.0 Disabled
    246 Sparrow Disabled Sparrow
    247 splitter Demand Microsoft Kernel Audio Splitter
    248 Spooler Auto Print Spooler
    249 sr Boot System Restore Filter Driver
    250 srservice Auto System Restore Service
    251 Srv Demand Srv
    252 SSDPSRV Demand SSDP Discovery Service
    253 stisvc Auto Windows Image Acquisition (WIA)
    254 swenum Demand Software Bus Driver
    255 swmidi Demand Microsoft Kernel GS Wavetable Synthesizer
    256 SwPrv Demand MS Software Shadow Copy Provider
    257 symc810 Disabled symc810
    258 symc8xx Disabled symc8xx
    259 sym_hi Disabled sym_hi
    260 sym_u3 Disabled sym_u3
    261 SynPS2Enable Disabled
    262 SynTP Demand Synaptics TouchPad Driver
    263 sysaudio Demand Microsoft Kernel System Audio Device
    264 SysmonLog Demand Performance Logs and Alerts
    265 TapiSrv Demand Telephony
    266 Tcpip System TCP/IP Protocol Driver
    267 TDPIPE Demand
    268 TDTCP Demand
    269 TermDD System Terminal Device Driver
    270 TermService Demand Terminal Services
    271 Themes Auto Themes
    272 TlntSvr Demand
    273 TosIde Disabled TosIde
    274 TrkWks Auto Distributed Link Tracking Client
    275 TSDDD Disabled
    276 Udfs Disabled
    277 ultra Disabled ultra
    278 Update Demand Microcode Update Driver
    279 upnphost Demand Universal Plug and Play Device Host
    280 UPS Demand Uninterruptible Power Supply
    281 usb Disabled
    282 usbccgp Demand Microsoft USB Generic Parent Driver
    283 usbehci Demand Microsoft USB 2.0 Enhanced Host Controller Miniport Driver
    284 usbhub Demand USB2 Enabled Hub
    285 usbprint Demand Microsoft USB PRINTER Class
    286 usbscan Demand USB Scanner Driver
    287 USBSTOR Demand USB Mass Storage Driver
    288 usbuhci Demand Microsoft USB Universal Host Controller Miniport Driver
    289 VgaSave System
    290 viaagp Disabled VIA AGP Bus Filter
    291 ViaIde Disabled ViaIde
    292 VolSnap Boot
    293 VSS Demand Volume Shadow Copy
    294 w32time Auto Windows Time
    295 W3SVC Disabled
    296 Wanarp Demand Remote Access IP ARP Driver
    297 Wdf01000 Demand Wdf01000
    298 WDICA Demand
    299 wdmaud Demand Microsoft WINMM WDM Audio Compatibility Driver
    300 WebClient Auto WebClient
    301 Windows Workflow Foundation 3.0.0.0 Disabled
    302 winmgmt Auto Windows Management Instrumentation
    303 WinRM Demand Windows Remote Management (WS-Management)
    304 Winsock Demand
    305 WinSock2 Disabled
    306 WinTrust Disabled
    307 WmdmPmSN Demand Portable Media Serial Number Service
    308 WmiAcpi System Microsoft Windows Management Interface for ACPI
    309 WmiApRpl Disabled
    310 WmiApSrv Demand WMI Performance Adapter
    311 WS2IFSL System
    312 wscsvc Auto Security Center
    313 wuauserv Auto Automatic Updates
    314 WZCSVC Auto Wireless Zero Configuration
    315 xmlprov Demand Network Provisioning Service
    316 YahooAUService Auto Yahoo! Updater
    317 {6BEA9291-D85C-4ECE-98FB-9F4B997E4C65} Disabled
    318 {A6DF4A73-5DB7-4686-A12C-705E7A5217AA} Disabled
    22:22:25 - Performing check: "Selftest":
    Doing a short selftest...
    -> Checking IAT

    PID 1404 - C:\Documents and Settings\Miki\Desktop\radix_installer\radixgui.exe
    -------------------------------------------------------------------------------
    ntdll.dll (7C900000 - 7C9B2000)
    kernel32.dll (7C800000 - 7C8F6000)
    USER32.dll (7E410000 - 7E4A1000)
    GDI32.dll (77F10000 - 77F59000)
    comdlg32.dll (763B0000 - 763F9000)
    ADVAPI32.dll (77DD0000 - 77E6B000)
    RPCRT4.dll (77E70000 - 77F02000)
    Secur32.dll (77FE0000 - 77FF1000)
    COMCTL32.dll (5D090000 - 5D12A000)
    SHELL32.dll (7C9C0000 - 7D1D7000)
    msvcrt.dll (77C10000 - 77C68000)
    SHLWAPI.dll (77F60000 - 77FD6000)
    ole32.dll (774E0000 - 7761D000)
    VERSION.dll (77C00000 - 77C08000)
    IMM32.DLL (76390000 - 763AD000)
    comctl32.dll (773D0000 - 774D3000)
    wintrust.dll (76C30000 - 76C5E000)
    CRYPT32.dll (77A80000 - 77B15000)
    MSASN1.dll (77B20000 - 77B32000)
    IMAGEHLP.dll (76C90000 - 76CB8000)
    sfc.dll (76BB0000 - 76BB5000)
    sfc_os.dll (76C60000 - 76C8A000)
    NTMARTA.DLL (77690000 - 776B1000)
    SAMLIB.dll (71BF0000 - 71C03000)
    WLDAP32.dll (76F60000 - 76F8C000)
    uxtheme.dll (5AD70000 - 5ADA8000)
    MSCTF.dll (74720000 - 7476C000)
    apphelp.dll (77B40000 - 77B62000)
    msctfime.ime (755C0000 - 755EE000)
    Selftest complete.

    22:22:27 - Performing check: "MBR":
    Partition Table:
    +----+-----+------Start------+--------End------+----------+----------+----+
    | Nr | Act | Head Sect Track | Head Sect Track | Offset | Length | OS |
    +----+-----+-----------------+-----------------+----------+----------+----+
    | 1 | N | 001 01 0000 | 254 63 0006 | 0000003F | 0001B708 | DE |
    | 2 | Y | 000 01 0007 | 254 63 0167 | 0001B747 | 00E2FE1E | 07 |
    | 3 | N | 000 00 0000 | 000 00 0000 | 00000000 | 00000000 | 00 |
    | 4 | N | 000 00 0000 | 000 00 0000 | 00000000 | 00000000 | 00 |
    +----+-----+-----------------+-----------------+----------+----------+----+
    MBR seems to be OK.
    22:22:27 - Performing check: "Object Routines":
    Checking Object procedures:
    Type Procedure 00458EE0
    Process DumpProcedure 00000000
    Process OpenProcedure 00000000
    Process CloseProcedure 00000000
    Process DeleteProcedure 805D1CB4
    Process ParseProcedure 00000000
    Process SecurityProcedure 805F8162
    Process QueryNameProcedure 00000000
    Process OkayToCloseProcedure 00000000
    Thread DumpProcedure 00000000
    Thread OpenProcedure 00000000
    Thread CloseProcedure 00000000
    Thread DeleteProcedure 805D1E3C
    Thread ParseProcedure 00000000
    Thread SecurityProcedure 805F8162
    Thread QueryNameProcedure 00000000
    Thread OkayToCloseProcedure 00000000
    Key DumpProcedure 00000000
    Key OpenProcedure 00000000
    Key CloseProcedure 80637296
    Key DeleteProcedure 8063717C
    Key ParseProcedure 8062F062
    Key SecurityProcedure 80636FE0
    Key QueryNameProcedure 80636016
    Key OkayToCloseProcedure 00000000
    Event DumpProcedure 00000000
    Event OpenProcedure 00000000
    Event CloseProcedure 00000000
    Event DeleteProcedure 00000000
    Event ParseProcedure 00000000
    Event SecurityProcedure 805F8162
    Event QueryNameProcedure 00000000
    Event OkayToCloseProcedure 00000000
    File DumpProcedure 00000000
    File OpenProcedure 00000000
    File CloseProcedure 805836E8
    File DeleteProcedure 805839C6
    File ParseProcedure 805835D6
    File SecurityProcedure 80583D4A
    File QueryNameProcedure 80582680
    File OkayToCloseProcedure 00000000
    Directory DumpProcedure 00000000
    Directory OpenProcedure 00000000
    Directory CloseProcedure 00000000
    Directory DeleteProcedure 00000000
    Directory ParseProcedure 00000000
    Directory SecurityProcedure 805F8162
    Directory QueryNameProcedure 00000000
    Directory OkayToCloseProcedure 00000000
    Desktop DumpProcedure 00000000
    Desktop OpenProcedure 8060CF4A
    Desktop CloseProcedure 8060CE28
    Desktop DeleteProcedure 8060CF00
    Desktop ParseProcedure 00000000
    Desktop SecurityProcedure 805F8162
    Desktop QueryNameProcedure 00000000
    Desktop OkayToCloseProcedure 8060CE8E
    Port DumpProcedure 00000000
    Port OpenProcedure 00000000
    Port CloseProcedure 805A6876
    Port DeleteProcedure 805A68AE
    Port ParseProcedure 00000000
    Port SecurityProcedure 805F8162
    Port QueryNameProcedure 00000000
    Port OkayToCloseProcedure 00000000
    Section DumpProcedure 00000000
    Section OpenProcedure 00000000
    Section CloseProcedure 00000000
    Section DeleteProcedure 805A89FE
    Section ParseProcedure 00000000
    Section SecurityProcedure 805F8162
    Section QueryNameProcedure 00000000
    Section OkayToCloseProcedure 00000000
    Token DumpProcedure 00000000
    Token OpenProcedure 00000000
    Token CloseProcedure 00000000
    Token DeleteProcedure 805F82DC
    Token ParseProcedure 00000000
    Token SecurityProcedure 805F8162
    Token QueryNameProcedure 00000000
    Token OkayToCloseProcedure 00000000
    KeyedEvent DumpProcedure 00000000
    KeyedEvent OpenProcedure 00000000
    KeyedEvent CloseProcedure 00000000
    KeyedEvent DeleteProcedure 00000000
    KeyedEvent ParseProcedure 00000000
    KeyedEvent SecurityProcedure 805F8162
    KeyedEvent QueryNameProcedure 00000000
    KeyedEvent OkayToCloseProcedure 00000000
    SymbolicLink DumpProcedure 00000000
    SymbolicLink OpenProcedure 00000000
    SymbolicLink CloseProcedure 00000000
    SymbolicLink DeleteProcedure 805C3980
    SymbolicLink ParseProcedure 805C3642
    SymbolicLink SecurityProcedure 805F8162
    SymbolicLink QueryNameProcedure 00000000
    SymbolicLink OkayToCloseProcedure 00000000
    Semaphore DumpProcedure 00000000
    Semaphore OpenProcedure 00000000
    Semaphore CloseProcedure 00000000
    Semaphore DeleteProcedure 00000000
    Semaphore ParseProcedure 00000000
    Semaphore SecurityProcedure 805F8162
    Semaphore QueryNameProcedure 00000000
    Semaphore OkayToCloseProcedure 00000000
    WindowStation DumpProcedure 00000000
    WindowStation OpenProcedure 8060CF4A
    WindowStation CloseProcedure 8060CE28
    WindowStation DeleteProcedure 8060CF00
    WindowStation ParseProcedure 8060CFBE
    WindowStation SecurityProcedure 805F8162
    WindowStation QueryNameProcedure 00000000
    WindowStation OkayToCloseProcedure 8060CE8E
    Mutant DumpProcedure 00000000
    Mutant OpenProcedure 00000000
    Mutant CloseProcedure 00000000
    Mutant DeleteProcedure 8053901E
    Mutant ParseProcedure 00000000
    Mutant SecurityProcedure 805F8162
    Mutant QueryNameProcedure 00000000
    Mutant OkayToCloseProcedure 00000000
    Timer DumpProcedure 00000000
    Timer OpenProcedure 00000000
    Timer CloseProcedure 00000000
    Timer DeleteProcedure 80538A94
    Timer ParseProcedure 00000000
    Timer SecurityProcedure 805F8162
    Timer QueryNameProcedure 00000000
    Timer OkayToCloseProcedure 00000000
    IoCompletion DumpProcedure 00000000
    IoCompletion OpenProcedure 00000000
    IoCompletion CloseProcedure 00000000
    IoCompletion DeleteProcedure 80578E36
    IoCompletion ParseProcedure 00000000
    IoCompletion SecurityProcedure 805F8162
    IoCompletion QueryNameProcedure 00000000
    IoCompletion OkayToCloseProcedure 00000000
    WmiGuid DumpProcedure 00000000
    WmiGuid OpenProcedure 00000000
    WmiGuid CloseProcedure 806038E6
    WmiGuid DeleteProcedure 80603944
    WmiGuid ParseProcedure 00000000
    WmiGuid SecurityProcedure 80603E3E
    WmiGuid QueryNameProcedure 00000000
    WmiGuid OkayToCloseProcedure 00000000
    WaitablePort DumpProcedure 00000000
    WaitablePort OpenProcedure 00000000
    WaitablePort CloseProcedure 805A6876
    WaitablePort DeleteProcedure 805A68AE
    WaitablePort ParseProcedure 00000000
    WaitablePort SecurityProcedure 805F8162
    WaitablePort QueryNameProcedure 00000000
    WaitablePort OkayToCloseProcedure 00000000
    Job DumpProcedure 00000000
    Job OpenProcedure 00000000
    Job CloseProcedure 805D6860
    Job DeleteProcedure 805D5ACC
    Job ParseProcedure 00000000
    Job SecurityProcedure 805F8162
    Job QueryNameProcedure 00000000
    Job OkayToCloseProcedure 00000000
    22:22:27 - Performing check: "IRP hooks":
    00 \Driver\Beep 81984488 Beep.SYS
    01 \Driver\NDIS 823CCCA0 NDIS.sys
    02 \Driver\KSecDD 82311D28 KSecDD.sys
    03 \Driver\Mouclass 822BC360 mouclass.sys
    04 \Driver\Raspti 82282730 raspti.sys
    05 \Driver\Fips 8194EA48 Fips.SYS
    06 \Driver\Kbdclass 822BDC20 kbdclass.sys
    07 \Driver\IntcAzAudAddService 8215D150 RtkHDAud.sys
    08 \Driver\VgaSave 81983BF0 vga.sys
    09 \Driver\i2omgmt 81986490 i2omgmt.SYS
    10 \Driver\NDProxy 82315210 NDProxy.SYS
    11 \Driver\Compbatt 823181A0 compbatt.sys
    12 \Driver\Ptilink 82282ED0 ptilink.sys
    13 \Driver\MountMgr 8236AD00 MountMgr.sys
    14 \Driver\wdmaud 81830360 wdmaud.sys
    15 \Driver\isapnp 823C9860 isapnp.sys
    16 \Driver\BCM43XX 82323880 bcmwl5.sys
    17 \Driver\ialm 822F7030 igxpmp32.sys
    18 \Driver\atapi 82312598 atapi.sys
    18 >\Driver\ACPIi 823E6520 ACPI.sys
    19 >\Driver\Diski 82371C88 disk.sys
    20 >\Driver\PartMgr 82312030 PartMgr.sys
    22 \Driver\RasAcd 81980570 rasacd.sys
    23 \Driver\PSched 82285B98 psched.sys
    24 \Driver\RTLE8023xp 822F1EF8 Rtenicxp.sys
    25 \Driver\IpNat 81957AC8 ipnat.sys
    26 \Driver\SDTHelper 816D89A8 sdthlpr.sys
    27 \Driver\audstub 822BB548 audstub.sys
    28 \Driver\usbuhci 822F1310 usbuhci.sys
    28 >\Driver\usbhubi 82163B58 usbhub.sys
    30 \Driver\Win32k 818FDDA0 win32k.sys
    29 \Driver\usbhub 82163B58 usbhub.sys
    31 \Driver\swenum 8227FD80 swenum.sys
    31 >\Driver\sysaudio 8182F030 sysaudio.sys
    33 \Driver\RDPCDD 81983640 RDPCDD.sys
    34 \Driver\Update 8227EC60 update.sys
    35 \Driver\RasPppoe 822861C0 raspppoe.sys
    36 \Driver\HTTP 817B4648 HTTP.sys
    37 \Driver\TermDD 82281F38 termdd.sys
    37 >\Driver\Mouclass 822BC360 mouclass.sys
    38 \Driver\Ftdisk 8236AA60 ftdisk.sys
    38 >\Driver\VolSnap 823128A8 VolSnap.sys
    32 \Driver\sysaudio 8182F030 sysaudio.sys
    40 \Driver\Rasl2tp 82289AF8 rasl2tp.sys
    41 \Driver\ACPIEC 82312F38 ACPIEC.sys
    42 \Driver\PptpMiniport 822877F8 raspptp.sys
    43 \Driver\WMIxWDM 823E7CE8 ntkrnlpa.exe
    44 \Driver\ACPI_HAL 823E7030 hal.dll
    44 >\Driver\ACPI_HAL 823E6520 ACPI.sys
    45 \Driver\NetBT 8197FF38 netbt.sys
    46 \Driver\mssmbios 8227E5E8 mssmbios.sys
    47 \Driver\PCIIde 82372390 pciide.sys
    47 >\Driver\ACPIde 823E6520 ACPI.sys
    19 >\Driver\atapie 82312598 atapi.sys
    48 \Driver\drgqnayq 823E6950 hpgmmx.sys
    49 \Driver\Wanarp 81985B28 wanarp.sys
    50 \Driver\Tcpip 8197C880 tcpip.sys
    51 \Driver\mnmdd 81983368 mnmdd.SYS
    39 \Driver\VolSnap 823128A8 VolSnap.sys
    52 \Driver\intelppm 82328BF0 intelppm.sys
    53 \Driver\Null 81984980 Null.SYS
    54 \Driver\usbehci 822F0410 usbehci.sys
    54 >\Driver\ACPIhci 823E6520 ACPI.sys
    19 >\Driver\usbhubi 82163B58 usbhub.sys
    55 \Driver\IPSec 81982568 ipsec.sys
    56 \Driver\JMCR 822F4DE0 jmcr.sys
    20 \Driver\Disk 82371C88 disk.sys
    57 \Driver\PCI 823C90E0 pci.sys
    57 >\Driver\ACPI 823E6520 ACPI.sys
    19 >\Driver\BCM43XX 82323880 bcmwl5.sys
    58 \Driver\NdisTapi 822895A0 ndistapi.sys
    59 \Driver\NdisWan 82288C60 ndiswan.sys
    21 \Driver\PartMgr 82312030 PartMgr.sys
    60 \Driver\Gpc 82284E28 msgpc.sys
    61 \Driver\HDAudBus 822F6F38 HDAudBus.sys
    61 >\Driver\IntcAzAudAddService 8215D150 RtkHDAud.sys
    62 \Driver\Wdf01000 822FC5E0 Wdf01000.sys
    19 \Driver\ACPI 823E6520 ACPI.sys
    19 >\Driver\usbhub 82163B58 usbhub.sys
    63 \Driver\PnpManager 823EBF38 ntkrnlpa.exe
    63 >\Driver\mssmbioser 8227E5E8 mssmbios.sys
    64 \Driver\AFD 81954030 afd.sys
    65 \Driver\Ndisuio 818F2030 ndisuio.sys
    66 \Driver\SynTP 822BD0E0 SynTP.sys
    67 \Driver\EMSC 823284B8 EMSC.SYS --[HOOKED]--
    This might be a false positive, as I was unable to check.
    * Majorfunction 00 (IRP_MJ_CREATE) hooked at F813FD1B by C:\WINDOWS\system32\DRIVERS\Wdf01000.sys
    -------------------------------------------------------------------------------
    Information for module Wdf01000.sys:
    -------------------------------------------------------------------------------
    Index: 31
    Base address: F810C000
    Size: 0007B000
    Flags: 09104000
    Load count: 1
    Imagename: \SystemRoot\system32\DRIVERS\Wdf01000.sys
    Name: Microsoft® Windows® Operating System
    Version: 1.5.6000.0
    Company: Microsoft Corporation
    File Version: 1.5.6000.0 (vista_rtm.061101-2205)
    Description: WDF Dynamic
    Possible path: C:\WINDOWS\system32\DRIVERS\Wdf01000.sys
    Signed: YES



    * Majorfunction 01 (IRP_MJ_CREATE_NAMED_PIPE) hooked at F813FD1B by C:\WINDOWS\system32\DRIVERS\Wdf01000.sys

    * Majorfunction 02 (IRP_MJ_CLOSE) hooked at F813FD1B by C:\WINDOWS\system32\DRIVERS\Wdf01000.sys

    * Majorfunction 03 (IRP_MJ_READ) hooked at F813FD1B by C:\WINDOWS\system32\DRIVERS\Wdf01000.sys

    * Majorfunction 04 (IRP_MJ_WRITE) hooked at F813FD1B by C:\WINDOWS\system32\DRIVERS\Wdf01000.sys

    * Majorfunction 05 (IRP_MJ_QUERY_INFORMATION) hooked at F813FD1B by C:\WINDOWS\system32\DRIVERS\Wdf01000.sys

    * Majorfunction 06 (IRP_MJ_SET_INFORMATION) hooked at F813FD1B by C:\WINDOWS\system32\DRIVERS\Wdf01000.sys

    * Majorfunction 07 (IRP_MJ_QUERY_EA) hooked at F813FD1B by C:\WINDOWS\system32\DRIVERS\Wdf01000.sys

    * Majorfunction 08 (IRP_MJ_SET_EA) hooked at F813FD1B by C:\WINDOWS\system32\DRIVERS\Wdf01000.sys

    * Majorfunction 09 (IRP_MJ_FLUSH_BUFFERS) hooked at F813FD1B by C:\WINDOWS\system32\DRIVERS\Wdf01000.sys

    * Majorfunction 0A (IRP_MJ_QUERY_VOLUME_INFORMATION) hooked at F813FD1B by C:\WINDOWS\system32\DRIVERS\Wdf01000.sys

    * Majorfunction 0B (IRP_MJ_SET_VOLUME_INFORMATION) hooked at F813FD1B by C:\WINDOWS\system32\DRIVERS\Wdf01000.sys

    * Majorfunction 0C (IRP_MJ_DIRECTORY_CONTROL) hooked at F813FD1B by C:\WINDOWS\system32\DRIVERS\Wdf01000.sys

    * Majorfunction 0D (IRP_MJ_FILE_SYSTEM_CONTROL) hooked at F813FD1B by C:\WINDOWS\system32\DRIVERS\Wdf01000.sys

    * Majorfunction 0E (IRP_MJ_DEVICE_CONTROL) hooked at F813FD1B by C:\WINDOWS\system32\DRIVERS\Wdf01000.sys

    * Majorfunction 0F (IRP_MJ_INTERNAL_DEVICE_CONTROL) hooked at F813FD1B by C:\WINDOWS\system32\DRIVERS\Wdf01000.sys

    * Majorfunction 10 (IRP_MJ_SHUTDOWN) hooked at F813FD1B by C:\WINDOWS\system32\DRIVERS\Wdf01000.sys

    * Majorfunction 11 (IRP_MJ_LOCK_CONTROL) hooked at F813FD1B by C:\WINDOWS\system32\DRIVERS\Wdf01000.sys

    * Majorfunction 12 (IRP_MJ_CLEANUP) hooked at F813FD1B by C:\WINDOWS\system32\DRIVERS\Wdf01000.sys

    * Majorfunction 13 (IRP_MJ_CREATE_MAILSLOT) hooked at F813FD1B by C:\WINDOWS\system32\DRIVERS\Wdf01000.sys

    * Majorfunction 14 (IRP_MJ_QUERY_SECURITY) hooked at F813FD1B by C:\WINDOWS\system32\DRIVERS\Wdf01000.sys

    * Majorfunction 15 (IRP_MJ_SET_SECURITY) hooked at F813FD1B by C:\WINDOWS\system32\DRIVERS\Wdf01000.sys

    * Majorfunction 16 (IRP_MJ_POWER) hooked at F813FF42 by C:\WINDOWS\system32\DRIVERS\Wdf01000.sys

    * Majorfunction 17 (IRP_MJ_SYSTEM_CONTROL) hooked at F813FF42 by C:\WINDOWS\system32\DRIVERS\Wdf01000.sys

    * Majorfunction 18 (IRP_MJ_DEVICE_CHANGE) hooked at F813FD1B by C:\WINDOWS\system32\DRIVERS\Wdf01000.sys

    * Majorfunction 19 (IRP_MJ_QUERY_QUOTA) hooked at F813FD1B by C:\WINDOWS\system32\DRIVERS\Wdf01000.sys

    * Majorfunction 1A (IRP_MJ_SET_QUOTA) hooked at F813FD1B by C:\WINDOWS\system32\DRIVERS\Wdf01000.sys

    68 \Driver\i8042prt 822BE4C8 i8042prt.sys
    68 >\Driver\SynTPprt 822BD0E0 SynTP.sys
    66 >\Driver\Mouclass 822BC360 mouclass.sys
    69 \Driver\CmBatt 822BE030 CmBatt.sys
    70 \FileSystem\Ntfs 823115F8 Ntfs.sys
    70 >\FileSystem\srfs 82311F38 sr.sys
    72 \FileSystem\NetBIOS 81954A08 netbios.sys
    71 \FileSystem\sr 82311F38 sr.sys
    73 \FileSystem\Rdbss 81952030 rdbss.sys
    74 \FileSystem\Msfs 81981948 Msfs.SYS
    75 \FileSystem\MRxSmb 81952CB8 mrxsmb.sys
    76 \FileSystem\Srv 81832248 srv.sys
    77 \FileSystem\Mup 823CB848 Mup.sys
    78 \FileSystem\RAW 823E6E18 ntkrnlpa.exe
    79 \FileSystem\Npfs 81980C80 Npfs.SYS
    80 \FileSystem\Fs_Rec 81985998 Fs_Rec.SYS
    81 \FileSystem\FltMgr 8236E7E0 fltMgr.sys
    82 \FileSystem\MRxDAV 81871D08 mrxdav.sys
    22:25:52 - Performing check: "Patched modules":
    Module information:

    Idx Base Size Module Service Pre Sig Patched
    000 804D7000 0020D000 ntkrnlpa.exe YES YES
    001 806E4000 00020D80 hal.dll YES YES
    002 F8974000 00002000 KDCOM.DLL YES YES
    003 F8884000 00003000 BOOTVID.dll YES YES
    004 F8474000 0000F000 hpgmmx.sys NO NO
    005 F8345000 0002E000 ACPI.sys ACPI YES YES
    006 F8976000 00002000 WMILIB.SYS YES YES
    007 F8334000 00011000 pci.sys PCI YES YES
    008 F8484000 0000A000 isapnp.sys isapnp YES YES
    009 F8888000 00003000 compbatt.sys Compbatt YES YES
    010 F888C000 00004000 BATTC.SYS BattC YES YES
    011 F8A3C000 00001000 pciide.sys PCIIde YES YES
    012 F86F4000 00007000 PCIIDEX.SYS YES YES
    013 F8494000 0000B000 MountMgr.sys MountMgr YES YES
    014 F8315000 0001F000 ftdisk.sys Ftdisk YES YES
    015 F86FC000 00005000 PartMgr.sys PartMgr YES YES
    016 F8890000 00003000 ACPIEC.sys ACPIEC YES YES
    017 F8A3D000 00001000 OPRGHDLR.SYS YES YES
    018 F84A4000 0000D000 VolSnap.sys VolSnap YES YES
    019 F82FD000 00018000 atapi.sys atapi YES YES
    020 F84B4000 00009000 disk.sys Disk YES YES
    021 F84C4000 0000D000 CLASSPNP.SYS YES YES
    022 F82DD000 00020000 fltMgr.sys FltMgr YES YES
    023 F82CB000 00012000 sr.sys sr YES YES
    024 F82B4000 00017000 KSecDD.sys KSecDD YES YES
    025 F8227000 0008D000 Ntfs.sys Ntfs YES YES
    026 F81FA000 0002D000 NDIS.sys NDIS YES YES
    027 F81E0000 0001A000 Mup.sys Mup YES YES
    028 F84F4000 00009000 intelppm.sys intelppm YES YES
    029 F8920000 00003000 EMSC.SYS EMSC YES YES
    030 F8504000 0000D000 WDFLDR.SYS YES YES
    031 F810C000 0007B000 Wdf01000.sys Wdf01000 YES YES

    Ad Bot


    View previous topic View next topic Back to top  Message [Page 5 of 7]

    Goto page : Previous  1, 2, 3, 4, 5, 6, 7  Next

    Permissions in this forum:
    You cannot reply to topics in this forum