here's the new OTScanIt2 info:
Process Explorer.EXE killed successfully!
[Win32 Services - Safe List]
Service Viewpoint Manager Service stopped successfully!
Service Viewpoint Manager Service deleted successfully!
File not found.
[Registry - Safe List]
Registry value HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\URLSearchHooks\\{EF99BD32-C1FB-11D2-892F-0090271D4F88} deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{EF99BD32-C1FB-11D2-892F-0090271D4F88}\ not found.
Registry key HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{02478D38-C3F9-4efb-9B51-7695ECA05670}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{02478D38-C3F9-4efb-9B51-7695ECA05670}\ not found.
Registry key HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{0347C33E-8762-4905-BF09-768834316C61}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{0347C33E-8762-4905-BF09-768834316C61}\ not found.
Registry key HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{06849E9F-C8D7-4D59-B87D-784B7D6BE0B3}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{06849E9F-C8D7-4D59-B87D-784B7D6BE0B3}\ not found.
Registry key HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{31FF080D-12A3-439A-A2EF-4BA95A3148E8}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{31FF080D-12A3-439A-A2EF-4BA95A3148E8}\ not found.
Registry key HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{5C8B2A36-3DB1-42A4-A3CB-D426709BBFEB}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{5C8B2A36-3DB1-42A4-A3CB-D426709BBFEB}\ not found.
Registry key HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{9ECB9560-04F9-4bbc-943D-298DDF1699E1}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{9ECB9560-04F9-4bbc-943D-298DDF1699E1}\ not found.
Registry key HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{B56A7D7D-6927-48C8-A975-17DF180C71AC}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{B56A7D7D-6927-48C8-A975-17DF180C71AC}\ not found.
Registry key HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{BDF3E430-B101-42AD-A544-FADC6B084872}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{BDF3E430-B101-42AD-A544-FADC6B084872}\ not found.
Registry key HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{FFFFFFFF-CF4E-4F2B-BDC2-0E72E116A856}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{FFFFFFFF-CF4E-4F2B-BDC2-0E72E116A856}\ not found.
Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\ToolBar\\{42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6}\ not found.
Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\ToolBar\\{4E7BD74F-2B8D-469E-CCB0-B130EEDBE97C} deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{4E7BD74F-2B8D-469E-CCB0-B130EEDBE97C}\ not found.
Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\ToolBar\\{CF9C3686-E61C-433A-864A-E04DD590B578} deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{CF9C3686-E61C-433A-864A-E04DD590B578}\ deleted successfully.
Registry value HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\ShellBrowser\\{42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6}\ not found.
Registry value HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\\{4982D40A-C53B-4615-B15B-B5B5E98D167C} deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{4982D40A-C53B-4615-B15B-B5B5E98D167C}\ not found.
Registry value HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\\{4E7BD74F-2B8D-469E-8CBD-FD60BB9AAE2E} deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{4E7BD74F-2B8D-469E-8CBD-FD60BB9AAE2E}\ not found.
Registry value HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\\{4E7BD74F-2B8D-469E-CCB0-B130EEDBE97C} deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{4E7BD74F-2B8D-469E-CCB0-B130EEDBE97C}\ not found.
Registry value HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\\{CF9C3686-E61C-433A-864A-E04DD590B578} deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{CF9C3686-E61C-433A-864A-E04DD590B578}\ not found.
Registry value HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\\{EF99BD32-C1FB-11D2-892F-0090271D4F88} deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{EF99BD32-C1FB-11D2-892F-0090271D4F88}\ not found.
Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\\KernelFaultCheck not found.
Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\\NWEReboot not found.
Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\\VirtualCloneDrive deleted successfully.
Registry value HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\\12ZFG94-F641-2SF-K31P-5N1ER6H6L2 deleted successfully.
Registry value HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\\Aim6 not found.
Registry value HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\\MsnMsgr deleted successfully.
Registry value HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\\Uniblue RegistryBooster 2 deleted successfully.
Registry value HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce\\gi400296855 deleted successfully.
C:\Documents and Settings\Compaq_Owner\Local Settings\Temp\gi44HUHQ.exe moved successfully.
Registry key HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\MenuExt\&AOL; Toolbar search\ deleted successfully.
Registry key HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\MenuExt\Download with Go!Zilla\ deleted successfully.
Registry key HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\MenuExt\E&xport; to Microsoft Excel\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Extensions\{FB5F1910-F110-11d2-BB9E-00C04F795683}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{FB5F1910-F110-11d2-BB9E-00C04F795683}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Extensions\{FB5F1910-F110-11d2-BB9E-00C04F795683}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{FB5F1910-F110-11d2-BB9E-00C04F795683}\ not found.
Registry value HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Extensions\CmdMapping\\{2D663D1A-8670-49D9-A1A5-4C56B4E14E84} deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{2D663D1A-8670-49D9-A1A5-4C56B4E14E84}\ not found.
Registry value HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Extensions\CmdMapping\\{4982D40A-C53B-4615-B15B-B5B5E98D167C} deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{4982D40A-C53B-4615-B15B-B5B5E98D167C}\ not found.
Registry value HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Extensions\CmdMapping\\{92780B25-18CC-41C8-B9BE-3C9C571A8263} deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{92780B25-18CC-41C8-B9BE-3C9C571A8263}\ not found.
Registry value HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Extensions\CmdMapping\\{CD67F990-D8E9-11d2-98FE-00C0F0318AFE} deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{CD67F990-D8E9-11d2-98FE-00C0F0318AFE}\ not found.
Registry value HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Extensions\CmdMapping\\{D6E814A0-E0C5-11d4-8D29-0050BA6940E3} deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{D6E814A0-E0C5-11d4-8D29-0050BA6940E3}\ not found.
Registry value HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Extensions\CmdMapping\\{FB5F1910-F110-11d2-BB9E-00C04F795683} deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{FB5F1910-F110-11d2-BB9E-00C04F795683}\ not found.
Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\amaena.com\\* deleted successfully.
Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\avsystemcare.com\\* deleted successfully.
Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\onerateld.com\\* deleted successfully.
Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\safetydownload.com\\* deleted successfully.
Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\trustedantivirus.com\\* deleted successfully.
Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\virusschlacht.com\\* deleted successfully.
Registry value HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\amaena.com\\* deleted successfully.
Registry value HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\antimalwareguard.com\\* deleted successfully.
Registry value HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\antispyexpert.com\\* deleted successfully.
Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Ranges\objects_aol.com\ not found.
Registry value HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\avsystemcare.com\\* deleted successfully.
Registry value HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\gomyhit.com\\* deleted successfully.
Registry value HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\imagesrvr.com\\* deleted successfully.
Registry value HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\onerateld.com\\* deleted successfully.
Registry value HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\safetydownload.com\\* deleted successfully.
Registry value HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\spyguardpro.com\\* deleted successfully.
Registry value HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\storageguardsoft.com\\* deleted successfully.
Registry value HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\trustedantivirus.com\\* deleted successfully.
Registry value HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\virusremover2008.com\\* deleted successfully.
Registry value HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\virusschlacht.com\\* deleted successfully.
Starting removal of ActiveX control {04E214E5-63AF-4236-83C6-A7ADCBF9BD02}
Registry error reading value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{04E214E5-63AF-4236-83C6-A7ADCBF9BD02}\DownloadInformation\\INF .
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{04E214E5-63AF-4236-83C6-A7ADCBF9BD02}\ not found.
Starting removal of ActiveX control {8FCDF9D9-A28B-480F-8C3D-581F119A8AB8}
Registry error reading value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{8FCDF9D9-A28B-480F-8C3D-581F119A8AB8}\DownloadInformation\\INF .
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{8FCDF9D9-A28B-480F-8C3D-581F119A8AB8}\ not found.
Starting removal of ActiveX control {B38870E4-7ECB-40DA-8C6A-595F0A5519FF}
Registry error reading value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{B38870E4-7ECB-40DA-8C6A-595F0A5519FF}\DownloadInformation\\INF .
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{B38870E4-7ECB-40DA-8C6A-595F0A5519FF}\ not found.
Starting removal of ActiveX control {CAFEEFAC-0014-0002-0003-ABCDEFFEDCBA}
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{CAFEEFAC-0014-0002-0003-ABCDEFFEDCBA}\Contains\Files\ not found.
Registry error reading value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{CAFEEFAC-0014-0002-0003-ABCDEFFEDCBA}\DownloadInformation\\INF .
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{CAFEEFAC-0014-0002-0003-ABCDEFFEDCBA}\ not found.
Registry key HKEY_CURRENT_USER\SOFTWARE\Classes\CLSID\{CAFEEFAC-0014-0002-0003-ABCDEFFEDCBA}\ deleted successfully.
Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows\\AppInit_Dlls:ctsgwt.dll deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\rwachyx\ deleted successfully.
Registry value HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List\\C:\Program Files\BitTorrent\btdownloadgui.exe deleted successfully.
[Registry - Additional Scans - Safe List]
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\Orb hkey=HKCU key=SOFTWARE\Microsoft\Windows\CurrentVersion\Run\ not found.
File not found.
Registry key HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\ati2ycxx.sys\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\ati2ycxx.sys\ deleted successfully.
[Files/Folders - Created Within 90 Days]
File delete failed. C:\WINDOWS\S529E7295.tmp scheduled to be deleted on reboot.
C:\Documents and Settings\Compaq_Owner\Desktop\HJTInstall.exe moved successfully.
C:\Documents and Settings\Compaq_Owner\Desktop\HJTsetup.exe moved successfully.
C:\Documents and Settings\All Users\Desktop\SpyHunter.lnk moved successfully.
C:\Program Files\Enigma Software Group\SpyHunter\Rollback folder moved successfully.
C:\Program Files\Enigma Software Group\SpyHunter\Download folder moved successfully.
C:\Program Files\Enigma Software Group\SpyHunter folder moved successfully.
C:\Program Files\Enigma Software Group folder moved successfully.
C:\VundoFix Backups folder moved successfully.
C:\WINDOWS\System32\tmp.reg moved successfully.
C:\WINDOWS\System32\VCCLSID.exe moved successfully.
C:\WINDOWS\System32\SrchSTS.exe moved successfully.
C:\WINDOWS\System32\swreg.exe moved successfully.
C:\WINDOWS\System32\VACFix.exe moved successfully.
C:\WINDOWS\System32\o4Patch.exe moved successfully.
C:\WINDOWS\System32\IEDFix.exe moved successfully.
C:\WINDOWS\System32\IEDFix.C.exe moved successfully.
C:\WINDOWS\System32\404Fix.exe moved successfully.
C:\WINDOWS\System32\swxcacls.exe moved successfully.
C:\WINDOWS\System32\Process.exe moved successfully.
C:\WINDOWS\System32\dumphive.exe moved successfully.
C:\WINDOWS\System32\swsc.exe moved successfully.
C:\WINDOWS\System32\WS2Fix.exe moved successfully.
C:\WINDOWS\System32\drivers\ethnqkra.sys moved successfully.
C:\Documents and Settings\Compaq_Owner\Application Data\IUpd721\Logs folder moved successfully.
C:\Documents and Settings\Compaq_Owner\Application Data\IUpd721 folder moved successfully.
C:\WINDOWS\System32\VC folder moved successfully.
C:\WINDOWS\System32\uv9 folder moved successfully.
C:\WINDOWS\System32\ki3 folder moved successfully.
C:\WINDOWS\System32\bin folder moved successfully.
C:\Temp\tn3 folder moved successfully.
C:\Temp\DIV55 folder moved successfully.
C:\Temp folder moved successfully.
C:\Documents and Settings\Compaq_Owner\Local Settings\Application Data\.# folder moved successfully.
C:\-663803565 moved successfully.
C:\WINDOWS\tasks\pcibigzt.job moved successfully.
[File - Lop Check]
C:\Documents and Settings\All Users\Application Data\SBSI\ORUN folder moved successfully.
C:\Documents and Settings\All Users\Application Data\SBSI folder moved successfully.
C:\Documents and Settings\Compaq_Owner\Application Data\uTorrent folder moved successfully.
C:\Documents and Settings\Compaq_Owner\Application Data\Viewpoint\Viewpoint Experience Technology\Resources\ResourceFolder_03 folder moved successfully.
C:\Documents and Settings\Compaq_Owner\Application Data\Viewpoint\Viewpoint Experience Technology\Resources\ResourceFolder_02 folder moved successfully.
C:\Documents and Settings\Compaq_Owner\Application Data\Viewpoint\Viewpoint Experience Technology\Resources\ResourceFolder_01 folder moved successfully.
C:\Documents and Settings\Compaq_Owner\Application Data\Viewpoint\Viewpoint Experience Technology\Resources\ResourceFolder_00 folder moved successfully.
C:\Documents and Settings\Compaq_Owner\Application Data\Viewpoint\Viewpoint Experience Technology\Resources folder moved successfully.
C:\Documents and Settings\Compaq_Owner\Application Data\Viewpoint\Viewpoint Experience Technology folder moved successfully.
C:\Documents and Settings\Compaq_Owner\Application Data\Viewpoint folder moved successfully.
File C:\WINDOWS\Tasks\pcibigzt.job not found!
[Custom Scans]
C:\WINDOWS\shakira-coolbuddy.zip moved successfully.
File/Folder C:\WINDOWS\Tasks\pcibigzt.job not found.
[Empty Temp Folders]
File delete failed. C:\Documents and Settings\Compaq_Owner\Local Settings\Temp\etilqs_XM88fwNvtt640dJhZvns scheduled to be deleted on reboot.
User's Temp folder emptied.
User's Temporary Internet Files folder emptied.
User's Internet Explorer cache folder emptied.
File delete failed. C:\Documents and Settings\LocalService\Local Settings\Temp\Temporary Internet Files\Content.IE5\index.dat scheduled to be deleted on reboot.
File delete failed. C:\Documents and Settings\LocalService\Local Settings\Temp\History\History.IE5\index.dat scheduled to be deleted on reboot.
File delete failed. C:\Documents and Settings\LocalService\Local Settings\Temp\Cookies\index.dat scheduled to be deleted on reboot.
Local Service Temp folder emptied.
Local Service Temporary Internet Files folder emptied.
Windows Temp folder emptied.
Java cache emptied.
File delete failed. C:\Documents and Settings\Compaq_Owner\Local Settings\Application Data\Mozilla\Firefox\Profiles\sow049qg.default\Cache\_CACHE_001_ scheduled to be deleted on reboot.
File delete failed. C:\Documents and Settings\Compaq_Owner\Local Settings\Application Data\Mozilla\Firefox\Profiles\sow049qg.default\Cache\_CACHE_002_ scheduled to be deleted on reboot.
File delete failed. C:\Documents and Settings\Compaq_Owner\Local Settings\Application Data\Mozilla\Firefox\Profiles\sow049qg.default\Cache\_CACHE_003_ scheduled to be deleted on reboot.
File delete failed. C:\Documents and Settings\Compaq_Owner\Local Settings\Application Data\Mozilla\Firefox\Profiles\sow049qg.default\Cache\_CACHE_MAP_ scheduled to be deleted on reboot.
File delete failed. C:\Documents and Settings\Compaq_Owner\Local Settings\Application Data\Mozilla\Firefox\Profiles\sow049qg.default\urlclassifier3.sqlite scheduled to be deleted on reboot.
File delete failed. C:\Documents and Settings\Compaq_Owner\Local Settings\Application Data\Mozilla\Firefox\Profiles\sow049qg.default\XUL.mfl scheduled to be deleted on reboot.
FireFox cache emptied.
RecycleBin -> emptied.
Explorer started successfully
< End of fix log >
OTScanIt2 by OldTimer - Version 1.0.4.2 fix logfile created on 12312008_171458
Files moved on Reboot…
File move failed. C:\WINDOWS\S529E7295.tmp scheduled to be moved on reboot.
File C:\Documents and Settings\Compaq_Owner\Local Settings\Temp\etilqs_XM88fwNvtt640dJhZvns not found!
C:\Documents and Settings\LocalService\Local Settings\Temp\Temporary Internet Files\Content.IE5\index.dat moved successfully.
C:\Documents and Settings\LocalService\Local Settings\Temp\History\History.IE5\index.dat moved successfully.
C:\Documents and Settings\LocalService\Local Settings\Temp\Cookies\index.dat moved successfully.
C:\Documents and Settings\Compaq_Owner\Local Settings\Application Data\Mozilla\Firefox\Profiles\sow049qg.default\Cache\_CACHE_001_ moved successfully.
C:\Documents and Settings\Compaq_Owner\Local Settings\Application Data\Mozilla\Firefox\Profiles\sow049qg.default\Cache\_CACHE_002_ moved successfully.
C:\Documents and Settings\Compaq_Owner\Local Settings\Application Data\Mozilla\Firefox\Profiles\sow049qg.default\Cache\_CACHE_003_ moved successfully.
C:\Documents and Settings\Compaq_Owner\Local Settings\Application Data\Mozilla\Firefox\Profiles\sow049qg.default\Cache\_CACHE_MAP_ moved successfully.
C:\Documents and Settings\Compaq_Owner\Local Settings\Application Data\Mozilla\Firefox\Profiles\sow049qg.default\urlclassifier3.sqlite moved successfully.
C:\Documents and Settings\Compaq_Owner\Local Settings\Application Data\Mozilla\Firefox\Profiles\sow049qg.default\XUL.mfl moved successfully.
Registry entries deleted on Reboot…
and here is the combofix.txt:
ComboFix 08-12-30.02 - Compaq_Owner 2008-12-31 17:22:36.1 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.2.1252.1.1033.18.447.104 [GMT -6:00]
Running from: c:\documents and settings\[removed]\Desktop\ComboFix.exe
AV: avast! antivirus 4.8.1296 [VPS 081230-0] *On-access scanning disabled* (Updated)
* Created a new restore point
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\documents and settings\Compaq_Owner\Local Settings\Temporary Internet Files\fbk.sts
c:\program files\Mozilla Firefox\plugins\npclntax.dll
c:\windows\IE4 Error Log.txt
c:\windows\Readme.txt
c:\windows\system32\TDSSmtvd.dat
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
——-\Legacy_FCI
——-\Legacy_ICF
——-\Legacy_MSDIRECTX
——-\Legacy_NPF
——-\Legacy_RESTORE
——-\Legacy_TDSSSERV.SYS
——-\Service_TDSSserv.sys
((((((((((((((((((((((((( Files Created from 2008-11-28 to 2008-12-31 )))))))))))))))))))))))))))))))
.
2008-12-31 17:14 . 2008-12-31 17:14 d——– C:\_OTScanIt
2008-12-30 12:05 . 2008-12-30 12:05 d——– c:\program files\Trend Micro
2008-12-29 05:43 . 2008-12-31 05:54 d——– C:\1
2008-12-26 20:34 . 2008-12-26 20:34 33,846 –a—— c:\windows\system32\SpoonUninstall-dBpoweramp Real Audio (Helix) Encoder.bmp
2008-12-26 20:34 . 2008-12-26 20:34 11,473 –a—— c:\windows\system32\SpoonUninstall-dBpoweramp Real Audio (Helix) Encoder.dat
2008-12-26 20:31 . 2008-12-26 20:31 33,846 –a—— c:\windows\system32\SpoonUninstall-dBpoweramp Music Converter.bmp
2008-12-26 20:31 . 2008-12-26 20:31 13,785 –a—— c:\windows\system32\SpoonUninstall-dBpoweramp Music Converter.dat
2008-12-23 17:56 . 2008-12-23 17:56 d——– c:\documents and settings\Compaq_Owner\Application Data\Uniblue
2008-12-23 17:55 . 2008-12-23 17:55 d——– c:\program files\Uniblue
2008-12-23 17:36 . 2008-12-23 17:36 d——– c:\documents and settings\Compaq_Owner\Application Data\dBpoweramp
2008-12-23 17:21 . 2008-12-23 17:21 33,846 –a—— c:\windows\system32\SpoonUninstall-dBpoweramp Windows Media Audio 10 Codec.bmp
2008-12-23 17:21 . 2008-12-23 17:20 33,846 –a—— c:\windows\system32\SpoonUninstall-dBpoweramp Shorten Codec.bmp
2008-12-23 17:21 . 2008-12-23 17:21 3,411 –a—— c:\windows\system32\SpoonUninstall-dBpoweramp Shorten Codec.dat
2008-12-23 17:21 . 2008-12-23 17:21 3,400 –a—— c:\windows\system32\SpoonUninstall-dBpoweramp Windows Media Audio 10 Codec.dat
2008-12-23 17:19 . 2008-12-23 17:19 33,846 –a—— c:\windows\system32\SpoonUninstall-dBpoweramp Midi Decoder.bmp
2008-12-23 17:19 . 2008-12-23 17:19 33,846 –a—— c:\windows\system32\SpoonUninstall-dBpoweramp m4a Codec.bmp
2008-12-23 17:19 . 2008-12-23 17:19 3,625 –a—— c:\windows\system32\SpoonUninstall-dBpoweramp m4a Codec.dat
2008-12-23 17:19 . 2008-12-23 17:19 2,649 –a—— c:\windows\system32\SpoonUninstall-dBpoweramp Midi Decoder.dat
2008-12-23 17:02 . 2008-12-23 17:02 d——– c:\documents and settings\Compaq_Owner\Application Data\AccurateRip
2008-12-23 16:53 . 2008-12-23 16:53 33,846 –a—— c:\windows\system32\SpoonUninstall-dBpoweramp WavPack Codec.bmp
2008-12-23 16:53 . 2008-12-23 16:53 3,008 –a—— c:\windows\system32\SpoonUninstall-dBpoweramp WavPack Codec.dat
2008-12-23 16:52 . 2008-12-23 16:56 33,846 –a—— c:\windows\system32\SpoonUninstall-dBpoweramp TTA Codec.bmp
2008-12-23 16:52 . 2008-12-23 16:57 3,417 –a—— c:\windows\system32\SpoonUninstall-dBpoweramp TTA Codec.dat
2008-12-23 16:46 . 2008-12-23 16:45 27,958 –a—— c:\windows\system32\SpoonUninstall-dBpowerAMP WMA V9 Codec.bmp
2008-12-23 16:46 . 2008-12-23 16:46 2,181 –a—— c:\windows\system32\SpoonUninstall-dBpowerAMP WMA V9 Codec.dat
2008-12-23 16:45 . 2008-12-23 16:45 28,898 –a—— c:\windows\system32\SpoonUninstall-dBpowerAMP VQF Codec.bmp
2008-12-23 16:45 . 2008-12-23 16:44 28,898 –a—— c:\windows\system32\SpoonUninstall-dBPowerAMP Real Audio Encoder R3.bmp
2008-12-23 16:45 . 2008-12-23 16:45 27,958 –a—— c:\windows\system32\SpoonUninstall-dBpowerAMP Winamp Codec.bmp
2008-12-23 16:45 . 2008-12-23 16:45 2,995 –a—— c:\windows\system32\SpoonUninstall-dBPowerAMP Real Audio Encoder R3.dat
2008-12-23 16:45 . 2008-12-23 16:45 2,234 –a—— c:\windows\system32\SpoonUninstall-dBpowerAMP VQF Codec.dat
2008-12-23 16:45 . 2008-12-23 16:45 1,327 –a—— c:\windows\system32\SpoonUninstall-dBpowerAMP Winamp Codec.dat
2008-12-23 16:44 . 2008-12-23 17:20 33,846 –a—— c:\windows\system32\SpoonUninstall-dBpoweramp Ogg Vorbis Codec.bmp
2008-12-23 16:44 . 2008-12-23 17:20 33,846 –a—— c:\windows\system32\SpoonUninstall-dBpoweramp Musepack Codec.bmp
2008-12-23 16:44 . 2008-12-23 16:44 27,958 –a—— c:\windows\system32\SpoonUninstall-dBpowerAMP Real Audio Codec.bmp
2008-12-23 16:44 . 2008-12-23 16:44 27,958 –a—— c:\windows\system32\SpoonUninstall-dBpowerAMP FAAC Mp4 Codec.bmp
2008-12-23 16:44 . 2008-12-23 17:20 3,283 –a—— c:\windows\system32\SpoonUninstall-dBpoweramp Musepack Codec.dat
2008-12-23 16:44 . 2008-12-23 17:20 3,065 –a—— c:\windows\system32\SpoonUninstall-dBpoweramp Ogg Vorbis Codec.dat
2008-12-23 16:44 . 2008-12-23 16:44 1,928 –a—— c:\windows\system32\SpoonUninstall-dBpowerAMP Real Audio Codec.dat
2008-12-23 16:44 . 2008-12-23 16:44 620 –a—— c:\windows\system32\SpoonUninstall-dBpowerAMP FAAC Mp4 Codec.dat
2008-12-23 16:43 . 2008-12-23 16:43 27,958 –a—— c:\windows\system32\SpoonUninstall-dMC mp3PRO (CLI) Encoder.bmp
2008-12-23 16:43 . 2008-12-23 16:43 27,958 –a—— c:\windows\system32\SpoonUninstall-dBpowerAMP Mp4 & AAC Decode Codec.bmp
2008-12-23 16:43 . 2008-12-23 16:43 27,958 –a—— c:\windows\system32\SpoonUninstall-dBpowerAMP mp3PRO Input Codec.bmp
2008-12-23 16:43 . 2008-12-23 16:43 27,958 –a—— c:\windows\system32\SpoonUninstall-dBpowerAMP AAC to Mp4 Codec.bmp
2008-12-23 16:43 . 2008-12-23 16:43 27,958 –a—— c:\windows\system32\SpoonUninstall-dBpowerAMP AAC Codec.bmp
2008-12-23 16:43 . 2008-12-23 16:43 2,467 –a—— c:\windows\system32\SpoonUninstall-dMC mp3PRO (CLI) Encoder.dat
2008-12-23 16:43 . 2008-12-23 16:43 2,218 –a—— c:\windows\system32\SpoonUninstall-dBpowerAMP Mp4 & AAC Decode Codec.dat
2008-12-23 16:43 . 2008-12-23 16:43 2,074 –a—— c:\windows\system32\SpoonUninstall-dBpowerAMP mp3PRO Input Codec.dat
2008-12-23 16:43 . 2008-12-23 16:43 1,122 –a—— c:\windows\system32\SpoonUninstall-dBpowerAMP AAC Codec.dat
2008-12-23 16:43 . 2008-12-23 16:43 516 –a—— c:\windows\system32\SpoonUninstall-dBpowerAMP AAC to Mp4 Codec.dat
2008-12-23 16:42 . 2008-12-23 17:19 33,846 –a—— c:\windows\system32\SpoonUninstall-dBpoweramp Monkeys Audio Codec.bmp
2008-12-23 16:42 . 2008-12-23 17:18 33,846 –a—— c:\windows\system32\SpoonUninstall-dBpoweramp FLAC Codec.bmp
2008-12-23 16:42 . 2008-12-23 17:11 28,898 –a—— c:\windows\system32\SpoonUninstall-dBPowerAMP AIFF codec r4.bmp
2008-12-23 16:42 . 2008-12-23 17:20 3,107 –a—— c:\windows\system32\SpoonUninstall-dBpoweramp Monkeys Audio Codec.dat
2008-12-23 16:42 . 2008-12-23 17:19 2,987 –a—— c:\windows\system32\SpoonUninstall-dBpoweramp FLAC Codec.dat
2008-12-23 16:42 . 2008-12-23 17:11 739 –a—— c:\windows\system32\SpoonUninstall-dBPowerAMP AIFF codec r4.dat
2008-12-23 16:39 . 2008-12-23 17:14 4,044,152 –a—— c:\windows\system32\SpoonUninstall.exe
2008-12-23 16:38 . 2008-12-23 16:38 d——– c:\program files\Illustrate
2008-12-23 15:27 . 2008-12-31 12:24 d——– C:\AudioConverter
2008-12-23 11:27 . 2008-12-23 12:17 398 –a—— c:\windows\AudioConverter.INI
2008-12-23 11:26 . 2008-12-23 11:26 d——– c:\program files\easetech
2008-12-22 11:02 . 2008-12-22 11:02 d——– c:\program files\MSXML 4.0
2008-12-21 22:20 . 2008-12-21 23:16 d——– c:\windows\system32\CatRoot_bak
2008-12-21 22:09 . 2008-12-21 22:09 0 –ah—– c:\windows\system32\drivers\MsftWdf_Kernel_01007_Coinstaller_Critical.Wdf
2008-12-21 22:09 . 2008-12-21 22:09 0 –ah—– c:\windows\system32\drivers\Msft_Kernel_zumbus_01007.Wdf
2008-12-21 22:08 . 2008-03-21 13:57 14,640 ——— c:\windows\system32\spmsgXP_2k3.dll
2008-12-21 22:07 . 2008-10-16 14:38 6,066,176 —–c— c:\windows\system32\dllcache\ieframe.dll
2008-12-21 22:07 . 2007-04-17 03:32 2,455,488 —–c— c:\windows\system32\dllcache\ieapfltr.dat
2008-12-21 22:07 . 2007-03-07 23:10 991,232 —–c— c:\windows\system32\dllcache\ieframe.dll.mui
2008-12-21 22:07 . 2008-10-16 14:38 459,264 —–c— c:\windows\system32\dllcache\msfeeds.dll
2008-12-21 22:07 . 2008-10-16 14:38 383,488 —–c— c:\windows\system32\dllcache\ieapfltr.dll
2008-12-21 22:07 . 2008-10-16 14:38 267,776 —–c— c:\windows\system32\dllcache\iertutil.dll
2008-12-21 22:07 . 2008-10-16 14:38 63,488 —–c— c:\windows\system32\dllcache\icardie.dll
2008-12-21 22:07 . 2008-10-16 14:38 52,224 —–c— c:\windows\system32\dllcache\msfeedsbs.dll
2008-12-21 22:07 . 2008-10-16 07:11 13,824 —–c— c:\windows\system32\dllcache\ieudinit.exe
2008-12-21 22:06 . 2008-12-21 22:10 d——– c:\program files\Zune
2008-12-21 22:05 . 2008-08-14 04:00 2,180,352 —–c— c:\windows\system32\dllcache\ntoskrnl.exe
2008-12-21 22:05 . 2008-08-14 03:58 2,136,064 —–c— c:\windows\system32\dllcache\ntkrnlmp.exe
2008-12-21 22:05 . 2008-08-14 03:22 2,057,728 —–c— c:\windows\system32\dllcache\ntkrnlpa.exe
2008-12-21 22:05 . 2008-08-14 03:22 2,015,744 —–c— c:\windows\system32\dllcache\ntkrpamp.exe
2008-12-21 22:02 . 2008-05-02 07:30 464,384 ——— c:\windows\system32\imapi2fs.dll
2008-12-21 22:02 . 2008-05-02 07:30 464,384 —–c— c:\windows\system32\dllcache\imapi2fs.dll
2008-12-21 22:02 . 2008-05-02 07:30 317,952 ——— c:\windows\system32\imapi2.dll
2008-12-21 22:02 . 2008-05-02 07:30 317,952 —–c— c:\windows\system32\dllcache\imapi2.dll
2008-12-21 22:02 . 2008-06-13 07:10 272,128 ——— c:\windows\system32\drivers\bthport.sys
2008-12-21 22:02 . 2008-06-13 07:10 272,128 —–c— c:\windows\system32\dllcache\bthport.sys
2008-12-21 22:02 . 2008-05-02 03:05 62,592 —–c— c:\windows\system32\dllcache\cdrom.sys
2008-12-21 21:52 . 2008-10-16 14:09 31,768 –a—— c:\windows\system32\wucltui.dll.mui
2008-12-21 21:52 . 2008-10-16 14:07 23,576 –a—— c:\windows\system32\wuaucpl.cpl.mui
2008-12-21 21:52 . 2008-10-16 14:07 23,576 –a—— c:\windows\system32\wuapi.dll.mui
2008-12-21 21:52 . 2008-10-16 14:07 18,456 –a—— c:\windows\system32\wuaueng.dll.mui
2008-12-21 15:13 . 2001-08-17 14:55 6,144 –a—— c:\windows\system32\kbd101b.dll
2008-12-21 15:13 . 2001-08-17 14:55 6,144 –a–c— c:\windows\system32\dllcache\kbd101b.dll
2008-12-21 14:34 . 2008-12-21 14:34 d——– c:\windows\system32\GASVRCG
2008-12-21 14:34 . 2002-10-30 18:56 498,176 –a—— c:\windows\system32\GaSaver.scr
2008-12-21 14:34 . 2002-10-24 19:14 1,238 –a—— c:\windows\system32\Gascr.ini
2008-12-21 13:57 . 2004-07-26 12:12 166,912 –a—— c:\windows\lame_enc.dll
2008-12-21 13:41 . 2008-12-21 13:41 d——– c:\program files\River Past
2008-12-21 13:41 . 2008-12-21 13:41 d——– c:\program files\Common Files\River Past
2008-12-21 13:41 . 2008-12-21 13:41 d——– c:\documents and settings\Compaq_Owner\Application Data\River Past G5
2008-12-21 13:41 . 2008-12-21 13:59 d——– c:\documents and settings\All Users\Application Data\River Past G5
2008-12-21 13:41 . 2008-12-21 13:41 165,048 –a—— c:\windows\Audio Converter Pro Uninstaller.exe
2008-12-20 21:59 . 2008-12-30 11:46 d——– c:\program files\DSP-worx
2008-12-18 21:53 . 2008-12-18 21:53 d——– c:\program files\7-Zip
2008-12-13 17:12 . 2008-12-13 17:12 d——– c:\program files\OGPlanet
2008-12-12 18:25 . 2008-12-20 18:11 d——– C:\Episodes
2008-12-12 12:41 . 2008-12-12 12:41 243,840 –a—— c:\windows\system32\ZuneWlanCfgSvc.exe
2008-12-12 12:41 . 2008-12-12 12:41 60,032 –a—— c:\windows\system32\ZuneBusEnum.exe
2008-12-12 10:25 . 2008-12-12 10:36 d——– C:\Ruby
2008-12-05 17:26 . 2008-12-05 17:27 d——– c:\program files\Race War Kingdoms
2008-12-05 17:11 . 2008-12-05 17:11 d——– c:\program files\Malwarebytes' Anti-Malware
2008-12-05 17:11 . 2008-12-05 17:11 d——– c:\documents and settings\Compaq_Owner\Application Data\Malwarebytes
2008-12-05 17:11 . 2008-12-05 17:11 d——– c:\documents and settings\All Users\Application Data\Malwarebytes
2008-12-05 17:11 . 2008-12-03 19:54 38,496 –a—— c:\windows\system32\drivers\mbamswissarmy.sys
2008-12-05 17:11 . 2008-12-03 19:54 15,504 –a—— c:\windows\system32\drivers\mbam.sys
2008-12-05 09:24 . 2008-12-05 10:12 d——– c:\documents and settings\Administrator\Application Data\uTorrent
2008-12-02 20:28 . 2008-12-02 20:28 d—s—- c:\windows\system32\config\systemprofile\UserData
2008-12-02 17:05 . 2008-12-02 17:05 d——– c:\documents and settings\Administrator\Application Data\Media Player Classic
2008-12-02 17:05 . 2008-12-02 17:05 d——– c:\documents and settings\Administrator\Application Data\DivX
2008-12-02 17:04 . 2008-12-02 17:04 d——– c:\documents and settings\Administrator\Application Data\Aim
2008-12-01 07:59 . 2008-12-01 08:00 31 –a—— c:\documents and settings\Compaq_Owner\jagex_runescape_preferences.dat
2008-11-20 07:48 . 2008-12-02 21:36 d——– c:\program files\Viewpoint
2008-11-20 07:48 . 2008-11-20 07:50 d——– c:\documents and settings\All Users\Application Data\AOL OCP
2008-11-20 07:48 . 2008-11-20 07:48 d——– c:\documents and settings\All Users\Application Data\acccore
2008-11-20 07:47 . 2008-11-22 10:45 2,093 –ah—– C:\IPH.PH
2008-11-14 14:58 . 2008-11-14 15:10 d——– c:\program files\FlashGet
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-12-30 18:58 ——— d—–w c:\program files\Avast4
2008-12-27 01:54 ——— d—–w c:\program files\Combined Community Codec Pack
2008-12-21 20:33 ——— d–h–w c:\program files\InstallShield Installation Information
2008-12-21 17:59 ——— d—–w c:\program files\Winamp
2008-12-20 23:48 ——— d—–w c:\program files\Media Player Classic
2008-12-14 04:28 ——— d—–w c:\program files\GetRight
2008-12-11 12:05 ——— d—–w c:\documents and settings\All Users\Application Data\EmailNotifier
2008-12-11 04:02 ——— d—–w c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy
2008-12-11 04:01 ——— d—–w c:\program files\Spybot - Search & Destroy
2008-12-10 02:22 ——— d—–w c:\documents and settings\Compaq_Owner\Application Data\Hamachi
2008-12-05 03:47 ——— d—–w c:\program files\Diablo II
2008-12-04 02:23 ——— d—–w c:\program files\Yahoo!
2008-12-04 01:48 ——— d—–w c:\program files\Common Files\AOL
2008-12-04 01:47 ——— d—–w c:\program files\Common Files\Nullsoft
2008-12-02 21:09 ——— d—–w c:\documents and settings\Compaq_Owner\Application Data\HPAppData
2008-11-20 13:49 ——— d—–w c:\documents and settings\All Users\Application Data\AOL Downloads
2008-11-20 13:48 ——— d—–w c:\documents and settings\All Users\Application Data\Viewpoint
2008-11-19 16:34 ——— d—–w c:\program files\AIM
2008-11-09 02:10 ——— d—–w c:\documents and settings\Compaq_Owner\Application Data\tunebite
2008-11-03 14:54 ——— d—–w c:\program files\BitComet
2008-10-29 19:07 ——— d—–w c:\program files\PowerISO
2008-10-27 16:37 699,488 —-a-w c:\program files\JUN2007_d3dx10_34_x86.cab
2008-10-27 16:36 526,160 —-a-w c:\program files\DXSETUP.exe
2008-10-23 00:56 122,129 —-a-w c:\windows\File Renamer - Basic Uninstaller.exe
2007-03-09 07:12 27,648 –sha-w c:\windows\system32\AVSredirect.dll
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2004-08-04 15360]
"BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}"="c:\program files\Common Files\Ahead\Lib\NMBgMonitor.exe" [2006-06-01 94208]
"Uniblue RegistryBooster 2"="c:\program files\Uniblue\RegistryBooster 2\RegistryBooster.exe" [2008-05-05 1923352]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Zune Launcher"="c:\program files\Zune\ZuneLauncher.exe" [2008-12-12 157312]
"Recguard"="c:\windows\SMINST\RECGUARD.EXE" [2004-04-14 233472]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2008-09-10 289576]
"WD Button Manager"="WDBtnMgr.exe" [2007-06-28 c:\windows\system32\WDBtnMgr.exe]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"msacm.iac2"= c:\progra~1\REPLAY~2\iac25_32.ax
"VIDC.FFDS"= c:\progra~1\COMBIN~1\Filters\FFDShow\ff_vfw.dll
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys]
@="Driver"
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Adobe Reader Speed Launch.lnk]
backup=c:\windows\pss\Adobe Reader Speed Launch.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^HP Digital Imaging Monitor.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\HP Digital Imaging Monitor.lnk
backup=c:\windows\pss\HP Digital Imaging Monitor.lnkCommon Startup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\KernelFaultCheck]
c:\windows\system32\dumprep 0 -k [X]
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Orb
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\avast!]
–a—— 2008-11-26 11:18 81000 c:\progra~1\Avast4\ashDisp.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
–a—— 2008-09-06 14:09 413696 c:\program files\QuickTime\QTTask.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RealTray]
–a—— 2007-08-06 17:37 214296 c:\program files\Real\RealPlayer\realplay.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SpybotSD TeaTimer]
-rahs—- 2008-09-16 11:16 1833296 c:\program files\Spybot - Search & Destroy\TeaTimer.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
–a—— 2007-09-25 01:11 132496 c:\program files\Java\jre1.6.0_03\bin\jusched.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\TkBellExe]
–a—— 2007-08-06 17:37 185632 c:\program files\Common Files\Real\Update_OB\realsched.exe
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Compaq Connections\\6750491\\Program\\Compaq Connections.exe"=
"c:\\WINDOWS\\system32"=
"c:\\Program Files\\utorrent\\utorrent.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqtra08.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqste08.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hposid01.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpiscnapp.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqkygrp.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
"c:\\Program Files\\Hamachi\\hamachi.exe"=
"c:\\Program Files\\Best Buy Rhapsody\\rhapsody.exe"=
"c:\\Program Files\\AIM\\aim.exe"=
"c:\\SMC_mIRC\\SysReset 2.53\\mirc.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"21142:TCP"= 21142:TCP:BitComet 21142 TCP
"21142:UDP"= 21142:UDP:BitComet 21142 UDP
"18314:TCP"= 18314:TCP:BitComet 18314 TCP
"18314:UDP"= 18314:UDP:BitComet 18314 UDP
"17978:TCP"= 17978:TCP:BitComet 17978 TCP
"17978:UDP"= 17978:UDP:BitComet 17978 UDP
"9842:TCP"= 9842:TCP:*:Disabled:SolidNetworkManager
"9842:UDP"= 9842:UDP:*:Disabled:SolidNetworkManager
R1 aswSP;avast! Self Protection;c:\windows\system32\drivers\aswSP.sys [2008-12-05 111184]
R2 aswFsBlk;aswFsBlk;c:\windows\system32\DRIVERS\aswFsBlk.sys [2008-12-05 20560]
R2 Nero BackItUp Scheduler 4.0;Nero BackItUp Scheduler 4.0;c:\program files\Common Files\Nero\Nero BackItUp 4\NBService.exe [2008-09-30 935208]
S1 ethnqkra;ethnqkra;c:\windows\system32\drivers\ethnqkra.sys []
S3 scskusbf;USB SCSK Filter Driver Service;c:\windows\system32\drivers\scskusbf.sys [2007-09-13 19504]
S3 scskusbs;USB SCSK Driver Service;c:\windows\system32\drivers\scskusbs.sys [2007-09-13 83160]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
HPZ12 REG_MULTI_SZ Pml Driver HPZ12 Net Driver HPZ12
hpdevmgmt REG_MULTI_SZ hpqcxs08 hpqddsvc
.
- - - - ORPHANS REMOVED - - - -
HKU-Default-Run-vxvjeppy.exe - c:\windows\vxvjeppy.exe
HKU-Default-Run-jrfyvaod.exe - c:\windows\jrfyvaod.exe
.
——- Supplementary Scan ——-
.
uDefault_Search_URL = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp;=iesearch&locale;=EN_US&c;=Q404&bd;=presario&pf;=desktop
uStart Page = www.google.com/
mSearch Bar = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp;=iesearch&locale;=EN_US&c;=Q404&bd;=presario&pf;=desktop
IE: Download with GetRight - c:\program files\GetRight\GRdownload.htm
IE: Open with GetRight Browser - c:\program files\GetRight\GRbrowse.htm
FF - ProfilePath - c:\documents and settings\Compaq_Owner\Application Data\Mozilla\Firefox\Profiles\sow049qg.default\
FF - prefs.js: browser.search.selectedEngine - Yahoo
FF - prefs.js: browser.startup.homepage - hxxp://en-US.start2.mozilla.com/firefox?client=firefox-a&rls;=org.mozilla:en-US:official
FF - prefs.js: keyword.URL - hxxp://search.yahoo.com/search?ei=utf-8&fr;=megaup&p;=
FF - plugin: c:\program files\Mozilla Firefox\plugins\NPTURNMED.dll
FF - plugin: c:\program files\Viewpoint\Viewpoint Media Player\npViewpoint.dll
.
**************************************************************************
catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2008-12-31 17:30:41
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes …
scanning hidden autostart entries …
scanning hidden files …
scan completed successfully
hidden files: 0
**************************************************************************
.
——————— LOCKED REGISTRY KEYS ———————
[HKEY_USERS\S-1-5-21-3507848658-395067767-2873291405-1009\AppEvents\Schemes\Apps\.Default\.Default\n*NULL*o*NULL*s*NULL*0*NULL*H]
@Security=(SE_DACL_PRESENT SE_SELF_RELATIVE (@Owner @Group @DACL)
@Owner=S-1-5-21-3507848658-395067767-2873291405-1009
@Allowed: (Full) (S-1-5-21-3507848658-395067767-2873291405-1009)
@Allowed: (Full) (S-1-5-21-3507848658-395067767-2873291405-1009)
@Allowed: (Full) (LocalSystem)
@Allowed: (Full) (LocalSystem)
@Allowed: (Full) (Administrators)
@Allowed: (Full) (Administrators)
@Allowed: (Read) (S-1-5-12)
@Allowed: (Read) (S-1-5-12)
@=expand:"%SystemRoot%\\media\\Windows XP Ding.wav"
[HKEY_USERS\S-1-5-21-3507848658-395067767-2873291405-1009\AppEvents\Schemes\Apps\.Default\.Default\R*NULL*F*NULL*S*NULL*0*NULL*H]
@Security=(SE_DACL_PRESENT SE_SELF_RELATIVE (@Owner @Group @DACL)
@Owner=S-1-5-21-3507848658-395067767-2873291405-1009
@Allowed: (Full) (S-1-5-21-3507848658-395067767-2873291405-1009)
@Allowed: (Full) (S-1-5-21-3507848658-395067767-2873291405-1009)
@Allowed: (Full) (LocalSystem)
@Allowed: (Full) (LocalSystem)
@Allowed: (Full) (Administrators)
@Allowed: (Full) (Administrators)
@Allowed: (Read) (S-1-5-12)
@Allowed: (Read) (S-1-5-12)
@=""
[HKEY_USERS\S-1-5-21-3507848658-395067767-2873291405-1009\AppEvents\Schemes\Apps\.Default\AppGPFault\n*NULL*o*NULL*s*NULL*0*NULL*H]
@Security=(SE_DACL_PRESENT SE_SELF_RELATIVE (@Owner @Group @DACL)
@Owner=S-1-5-21-3507848658-395067767-2873291405-1009
@Allowed: (Full) (S-1-5-21-3507848658-395067767-2873291405-1009)
@Allowed: (Full) (S-1-5-21-3507848658-395067767-2873291405-1009)
@Allowed: (Full) (LocalSystem)
@Allowed: (Full) (LocalSystem)
@Allowed: (Full) (Administrators)
@Allowed: (Full) (Administrators)
@Allowed: (Read) (S-1-5-12)
@Allowed: (Read) (S-1-5-12)
@=""
[HKEY_USERS\S-1-5-21-3507848658-395067767-2873291405-1009\AppEvents\Schemes\Apps\.Default\AppGPFault\R*NULL*F*NULL*S*NULL*0*NULL*H]
@Security=(SE_DACL_PRESENT SE_SELF_RELATIVE (@Owner @Group @DACL)
@Owner=S-1-5-21-3507848658-395067767-2873291405-1009
@Allowed: (Full) (S-1-5-21-3507848658-395067767-2873291405-1009)
@Allowed: (Full) (S-1-5-21-3507848658-395067767-2873291405-1009)
@Allowed: (Full) (LocalSystem)
@Allowed: (Full) (LocalSystem)
@Allowed: (Full) (Administrators)
@Allowed: (Full) (Administrators)
@Allowed: (Read) (S-1-5-12)
@Allowed: (Read) (S-1-5-12)
@=""
[HKEY_USERS\S-1-5-21-3507848658-395067767-2873291405-1009\AppEvents\Schemes\Apps\.Default\CCSelect\n*NULL*o*NULL*s*NULL*0*NULL*H]
@Security=(SE_DACL_PRESENT SE_SELF_RELATIVE (@Owner @Group @DACL)
@Owner=S-1-5-21-3507848658-395067767-2873291405-1009
@Allowed: (Full) (S-1-5-21-3507848658-395067767-2873291405-1009)
@Allowed: (Full) (S-1-5-21-3507848658-395067767-2873291405-1009)
@Allowed: (Full) (LocalSystem)
@Allowed: (Full) (LocalSystem)
@Allowed: (Full) (Administrators)
@Allowed: (Full) (Administrators)
@Allowed: (Read) (S-1-5-12)
@Allowed: (Read) (S-1-5-12)
@=""
[HKEY_USERS\S-1-5-21-3507848658-395067767-2873291405-1009\AppEvents\Schemes\Apps\.Default\CCSelect\R*NULL*F*NULL*S*NULL*0*NULL*H]
@Security=(SE_DACL_PRESENT SE_SELF_RELATIVE (@Owner @Group @DACL)
@Owner=S-1-5-21-3507848658-395067767-2873291405-1009
@Allowed: (Full) (S-1-5-21-3507848658-395067767-2873291405-1009)
@Allowed: (Full) (S-1-5-21-3507848658-395067767-2873291405-1009)
@Allowed: (Full) (LocalSystem)
@Allowed: (Full) (LocalSystem)
@Allowed: (Full) (Administrators)
@Allowed: (Full) (Administrators)
@Allowed: (Read) (S-1-5-12)
@Allowed: (Read) (S-1-5-12)
@=""
[HKEY_USERS\S-1-5-21-3507848658-395067767-2873291405-1009\AppEvents\Schemes\Apps\.Default\Close\n*NULL*o*NULL*s*NULL*0*NULL*H]
@Security=(SE_DACL_PRESENT SE_SELF_RELATIVE (@Owner @Group @DACL)
@Owner=S-1-5-21-3507848658-395067767-2873291405-1009
@Allowed: (Full) (S-1-5-21-3507848658-395067767-2873291405-1009)
@Allowed: (Full) (S-1-5-21-3507848658-395067767-2873291405-1009)
@Allowed: (Full) (LocalSystem)
@Allowed: (Full) (LocalSystem)
@Allowed: (Full) (Administrators)
@Allowed: (Full) (Administrators)
@Allowed: (Read) (S-1-5-12)
@Allowed: (Read) (S-1-5-12)
@=""
[HKEY_USERS\S-1-5-21-3507848658-395067767-2873291405-1009\AppEvents\Schemes\Apps\.Default\Close\R*NULL*F*NULL*S*NULL*0*NULL*H]
@Security=(SE_DACL_PRESENT SE_SELF_RELATIVE (@Owner @Group @DACL)
@Owner=S-1-5-21-3507848658-395067767-2873291405-1009
@Allowed: (Full) (S-1-5-21-3507848658-395067767-2873291405-1009)
@Allowed: (Full) (S-1-5-21-3507848658-395067767-2873291405-1009)
@Allowed: (Full) (LocalSystem)
@Allowed: (Full) (LocalSystem)
@Allowed: (Full) (Administrators)
@Allowed: (Full) (Administrators)
@Allowed: (Read) (S-1-5-12)
@Allowed: (Read) (S-1-5-12)
@=""
[HKEY_USERS\S-1-5-21-3507848658-395067767-2873291405-1009\AppEvents\Schemes\Apps\.Default\CriticalBatteryAlarm\n*NULL*o*NULL*s*NULL*0*NULL*H]
@Security=(SE_DACL_PRESENT SE_SELF_RELATIVE (@Owner @Group @DACL)
@Owner=S-1-5-21-3507848658-395067767-2873291405-1009
@Allowed: (Full) (S-1-5-21-3507848658-395067767-2873291405-1009)
@Allowed: (Full) (S-1-5-21-3507848658-395067767-2873291405-1009)
@Allowed: (Full) (LocalSystem)
@Allowed: (Full) (LocalSystem)
@Allowed: (Full) (Administrators)
@Allowed: (Full) (Administrators)
@Allowed: (Read) (S-1-5-12)
@Allowed: (Read) (S-1-5-12)
@=""
[HKEY_USERS\S-1-5-21-3507848658-395067767-2873291405-1009\AppEvents\Schemes\Apps\.Default\CriticalBatteryAlarm\R*NULL*F*NULL*S*NULL*0*NULL*H]
@Security=(SE_DACL_PRESENT SE_SELF_RELATIVE (@Owner @Group @DACL)
@Owner=S-1-5-21-3507848658-395067767-2873291405-1009
@Allowed: (Full) (S-1-5-21-3507848658-395067767-2873291405-1009)
@Allowed: (Full) (S-1-5-21-3507848658-395067767-2873291405-1009)
@Allowed: (Full) (LocalSystem)
@Allowed: (Full) (LocalSystem)
@Allowed: (Full) (Administrators)
@Allowed: (Full) (Administrators)
@Allowed: (Read) (S-1-5-12)
@Allowed: (Read) (S-1-5-12)
@=""
[HKEY_USERS\S-1-5-21-3507848658-395067767-2873291405-1009\AppEvents\Schemes\Apps\.Default\DeviceConnect\n*NULL*o*NULL*s*NULL*0*NULL*H]
@Security=(SE_DACL_PRESENT SE_SELF_RELATIVE (@Owner @Group @DACL)
@Owner=S-1-5-21-3507848658-395067767-2873291405-1009
@Allowed: (Full) (S-1-5-21-3507848658-395067767-2873291405-1009)
@Allowed: (Full) (S-1-5-21-3507848658-395067767-2873291405-1009)
@Allowed: (Full) (LocalSystem)
@Allowed: (Full) (LocalSystem)
@Allowed: (Full) (Administrators)
@Allowed: (Full) (Administrators)
@Allowed: (Read) (S-1-5-12)
@Allowed: (Read) (S-1-5-12)
@=expand:"%SystemRoot%\\media\\Windows XP Hardware Insert.wav"
[HKEY_USERS\S-1-5-21-3507848658-395067767-2873291405-1009\AppEvents\Schemes\Apps\.Default\DeviceConnect\R*NULL*F*NULL*S*NULL*0*NULL*H]
@Security=(SE_DACL_PRESENT SE_SELF_RELATIVE (@Owner @Group @DACL)
@Owner=S-1-5-21-3507848658-395067767-2873291405-1009
@Allowed: (Full) (S-1-5-21-3507848658-395067767-2873291405-1009)
@Allowed: (Full) (S-1-5-21-3507848658-395067767-2873291405-1009)
@Allowed: (Full) (LocalSystem)
@Allowed: (Full) (LocalSystem)
@Allowed: (Full) (Administrators)
@Allowed: (Full) (Administrators)
@Allowed: (Read) (S-1-5-12)
@Allowed: (Read) (S-1-5-12)
@=""
[HKEY_USERS\S-1-5-21-3507848658-395067767-2873291405-1009\AppEvents\Schemes\Apps\.Default\DeviceDisconnect\n*NULL*o*NULL*s*NULL*0*NULL*H]
@Security=(SE_DACL_PRESENT SE_SELF_RELATIVE (@Owner @Group @DACL)
@Owner=S-1-5-21-3507848658-395067767-2873291405-1009
@Allowed: (Full) (S-1-5-21-3507848658-395067767-2873291405-1009)
@Allowed: (Full) (S-1-5-21-3507848658-395067767-2873291405-1009)
@Allowed: (Full) (LocalSystem)
@Allowed: (Full) (LocalSystem)
@Allowed: (Full) (Administrators)
@Allowed: (Full) (Administrators)
@Allowed: (Read) (S-1-5-12)
@Allowed: (Read) (S-1-5-12)
@=expand:"%SystemRoot%\\media\\Windows XP Hardware Remove.wav"
[HKEY_USERS\S-1-5-21-3507848658-395067767-2873291405-1009\AppEvents\Schemes\Apps\.Default\DeviceDisconnect\R*NULL*F*NULL*S*NULL*0*NULL*H]
@Security=(SE_DACL_PRESENT SE_SELF_RELATIVE (@Owner @Group @DACL)
@Owner=S-1-5-21-3507848658-395067767-2873291405-1009
@Allowed: (Full) (S-1-5-21-3507848658-395067767-2873291405-1009)
@Allowed: (Full) (S-1-5-21-3507848658-395067767-2873291405-1009)
@Allowed: (Full) (LocalSystem)
@Allowed: (Full) (LocalSystem)
@Allowed: (Full) (Administrators)
@Allowed: (Full) (Administrators)
@Allowed: (Read) (S-1-5-12)
@Allowed: (Read) (S-1-5-12)
@=""
[HKEY_USERS\S-1-5-21-3507848658-395067767-2873291405-1009\AppEvents\Schemes\Apps\.Default\DeviceFail\n*NULL*o*NULL*s*NULL*0*NULL*H]
@Security=(SE_DACL_PRESENT SE_SELF_RELATIVE (@Owner @Group @DACL)
@Owner=S-1-5-21-3507848658-395067767-2873291405-1009
@Allowed: (Full) (S-1-5-21-3507848658-395067767-2873291405-1009)
@Allowed: (Full) (S-1-5-21-3507848658-395067767-2873291405-1009)
@Allowed: (Full) (LocalSystem)
@Allowed: (Full) (LocalSystem)
@Allowed: (Full) (Administrators)
@Allowed: (Full) (Administrators)
@Allowed: (Read) (S-1-5-12)
@Allowed: (Read) (S-1-5-12)
@=expand:"%SystemRoot%\\media\\Windows XP Hardware Fail.wav"
[HKEY_USERS\S-1-5-21-3507848658-395067767-2873291405-1009\AppEvents\Schemes\Apps\.Default\DeviceFail\R*NULL*F*NULL*S*NULL*0*NULL*H]
@Security=(SE_DACL_PRESENT SE_SELF_RELATIVE (@Owner @Group @DACL)
@Owner=S-1-5-21-3507848658-395067767-2873291405-1009
@Allowed: (Full) (S-1-5-21-3507848658-395067767-2873291405-1009)
@Allowed: (Full) (S-1-5-21-3507848658-395067767-2873291405-1009)
@Allowed: (Full) (LocalSystem)
@Allowed: (Full) (LocalSystem)
@Allowed: (Full) (Administrators)
@Allowed: (Full) (Administrators)
@Allowed: (Read) (S-1-5-12)
@Allowed: (Read) (S-1-5-12)
@=""
[HKEY_USERS\S-1-5-21-3507848658-395067767-2873291405-1009\AppEvents\Schemes\Apps\.Default\LowBatteryAlarm\n*NULL*o*NULL*s*NULL*0*NULL*H]
@Security=(SE_DACL_PRESENT SE_SELF_RELATIVE (@Owner @Group @DACL)
@Owner=S-1-5-21-3507848658-395067767-2873291405-1009
@Allowed: (Full) (S-1-5-21-3507848658-395067767-2873291405-1009)
@Allowed: (Full) (S-1-5-21-3507848658-395067767-2873291405-1009)
@Allowed: (Full) (LocalSystem)
@Allowed: (Full) (LocalSystem)
@Allowed: (Full) (Administrators)
@Allowed: (Full) (Administrators)
@Allowed: (Read) (S-1-5-12)
@Allowed: (Read) (S-1-5-12)
@=expand:"%SystemRoot%\\media\\Windows XP Battery Low.wav"
[HKEY_USERS\S-1-5-21-3507848658-395067767-2873291405-1009\AppEvents\Schemes\Apps\.Default\LowBatteryAlarm\R*NULL*F*NULL*S*NULL*0*NULL*H]
@Security=(SE_DACL_PRESENT SE_SELF_RELATIVE (@Owner @Group @DACL)
@Owner=S-1-5-21-3507848658-395067767-2873291405-1009
@Allowed: (Full) (S-1-5-21-3507848658-395067767-2873291405-1009)
@Allowed: (Full) (S-1-5-21-3507848658-395067767-2873291405-1009)
@Allowed: (Full) (LocalSystem)
@Allowed: (Full) (LocalSystem)
@Allowed: (Full) (Administrators)
@Allowed: (Full) (Administrators)
@Allowed: (Read) (S-1-5-12)
@Allowed: (Read) (S-1-5-12)
@=""
[HKEY_USERS\S-1-5-21-3507848658-395067767-2873291405-1009\AppEvents\Schemes\Apps\.Default\MailBeep\n*NULL*o*NULL*s*NULL*0*NULL*H]
@Security=(SE_DACL_PRESENT SE_SELF_RELATIVE (@Owner @Group @DACL)
@Owner=S-1-5-21-3507848658-395067767-2873291405-1009
@Allowed: (Full) (S-1-5-21-3507848658-395067767-2873291405-1009)
@Allowed: (Full) (S-1-5-21-3507848658-395067767-2873291405-1009)
@Allowed: (Full) (LocalSystem)
@Allowed: (Full) (LocalSystem)
@Allowed: (Full) (Administrators)
@Allowed: (Full) (Administrators)
@Allowed: (Read) (S-1-5-12)
@Allowed: (Read) (S-1-5-12)
@=expand:"%SystemRoot%\\media\\Windows XP Notify.wav"
[HKEY_USERS\S-1-5-21-3507848658-395067767-2873291405-1009\AppEvents\Schemes\Apps\.Default\MailBeep\R*NULL*F*NULL*S*NULL*0*NULL*H]
@Security=(SE_DACL_PRESENT SE_SELF_RELATIVE (@Owner @Group @DACL)
@Owner=S-1-5-21-3507848658-395067767-2873291405-1009
@Allowed: (Full) (S-1-5-21-3507848658-395067767-2873291405-1009)
@Allowed: (Full) (S-1-5-21-3507848658-395067767-2873291405-1009)
@Allowed: (Full) (LocalSystem)
@Allowed: (Full) (LocalSystem)
@Allowed: (Full) (Administrators)
@Allowed: (Full) (Administrators)
@Allowed: (Read) (S-1-5-12)
@Allowed: (Read) (S-1-5-12)
@=""
[HKEY_USERS\S-1-5-21-3507848658-395067767-2873291405-1009\AppEvents\Schemes\Apps\.Default\Maximize\n*NULL*o*NULL*s*NULL*0*NULL*H]
@Security=(SE_DACL_PRESENT SE_SELF_RELATIVE (@Owner @Group @DACL)
@Owner=S-1-5-21-3507848658-395067767-2873291405-1009
@Allowed: (Full) (S-1-5-21-3507848658-395067767-2873291405-1009)
@Allowed: (Full) (S-1-5-21-3507848658-395067767-2873291405-1009)
@Allowed: (Full) (LocalSystem)
@Allowed: (Full) (LocalSystem)
@Allowed: (Full) (Administrators)
@Allowed: (Full) (Administrators)
@Allowed: (Read) (S-1-5-12)
@Allowed: (Read) (S-1-5-12)
@=""
[HKEY_USERS\S-1-5-21-3507848658-395067767-2873291405-1009\AppEvents\Schemes\Apps\.Default\Maximize\R*NULL*F*NULL*S*NULL*0*NULL*H]
@Security=(SE_DACL_PRESENT SE_SELF_RELATIVE (@Owner @Group @DACL)
@Owner=S-1-5-21-3507848658-395067767-2873291405-1009
@Allowed: (Full) (S-1-5-21-3507848658-395067767-2873291405-1009)
@Allowed: (Full) (S-1-5-21-3507848658-395067767-2873291405-1009)
@Allowed: (Full) (LocalSystem)
@Allowed: (Full) (LocalSystem)
@Allowed: (Full) (Administrators)
@Allowed: (Full) (Administrators)
@Allowed: (Read) (S-1-5-12)
@Allowed: (Read) (S-1-5-12)
@=""
[HKEY_USERS\S-1-5-21-3507848658-395067767-2873291405-1009\AppEvents\Schemes\Apps\.Default\MenuCommand\n*NULL*o*NULL*s*NULL*0*NULL*H]
@Security=(SE_DACL_PRESENT SE_SELF_RELATIVE (@Owner @Group @DACL)
@Owner=S-1-5-21-3507848658-395067767-2873291405-1009
@Allowed: (Full) (S-1-5-21-3507848658-395067767-2873291405-1009)
@Allowed: (Full) (S-1-5-21-3507848658-395067767-2873291405-1009)
@Allowed: (Full) (LocalSystem)
@Allowed: (Full) (LocalSystem)
@Allowed: (Full) (Administrators)
@Allowed: (Full) (Administrators)
@Allowed: (Read) (S-1-5-12)
@Allowed: (Read) (S-1-5-12)
@=""
[HKEY_USERS\S-1-5-21-3507848658-395067767-2873291405-1009\AppEvents\Schemes\Apps\.Default\MenuCommand\R*NULL*F*NULL*S*NULL*0*NULL*H]
@Security=(SE_DACL_PRESENT SE_SELF_RELATIVE (@Owner @Group @DACL)
@Owner=S-1-5-21-3507848658-395067767-2873291405-1009
@Allowed: (Full) (S-1-5-21-3507848658-395067767-2873291405-1009)
@Allowed: (Full) (S-1-5-21-3507848658-395067767-2873291405-1009)
@Allowed: (Full) (LocalSystem)
@Allowed: (Full) (LocalSystem)
@Allowed: (Full) (Administrators)
@Allowed: (Full) (Administrators)
@Allowed: (Read) (S-1-5-12)
@Allowed: (Read) (S-1-5-12)
@=""
[HKEY_USERS\S-1-5-21-3507848658-395067767-2873291405-1009\AppEvents\Schemes\Apps\.Default\MenuPopup\n*NULL*o*NULL*s*NULL*0*NULL*H]
@Security=(SE_DACL_PRESENT SE_SELF_RELATIVE (@Owner @Group @DACL)
@Owner=S-1-5-21-3507848658-395067767-2873291405-1009
@Allowed: (Full) (S-1-5-21-3507848658-395067767-2873291405-1009)
@Allowed: (Full) (S-1-5-21-3507848658-395067767-2873291405-1009)
@Allowed: (Full) (LocalSystem)
@Allowed: (Full) (LocalSystem)
@Allowed: (Full) (Administrators)
@Allowed: (Full) (Administrators)
@Allowed: (Read) (S-1-5-12)
@Allowed: (Read) (S-1-5-12)
@=""
[HKEY_USERS\S-1-5-21-3507848658-395067767-2873291405-1009\AppEvents\Schemes\Apps\.Default\MenuPopup\R*NULL*F*NULL*S*NULL*0*NULL*H]
@Security=(SE_DACL_PRESENT SE_SELF_RELATIVE (@Owner @Group @DACL)
@Owner=S-1-5-21-3507848658-395067767-2873291405-1009
@Allowed: (Full) (S-1-5-21-3507848658-395067767-2873291405-1009)
@Allowed: (Full) (S-1-5-21-3507848658-395067767-2873291405-1009)
@Allowed: (Full) (LocalSystem)
@Allowed: (Full) (LocalSystem)
@Allowed: (Full) (Administrators)
@Allowed: (Full) (Administrators)
@Allowed: (Read) (S-1-5-12)
@Allowed: (Read) (S-1-5-12)
@=""
[HKEY_USERS\S-1-5-21-3507848658-395067767-2873291405-1009\AppEvents\Schemes\Apps\.Default\Minimize\n*NULL*o*NULL*s*NULL*0*NULL*H]
@Security=(SE_DACL_PRESENT SE_SELF_RELATIVE (@Owner @Group @DACL)
@Owner=S-1-5-21-3507848658-395067767-2873291405-1009
@Allowed: (Full) (S-1-5-21-3507848658-395067767-2873291405-1009)
@Allowed: (Full) (S-1-5-21-3507848658-395067767-2873291405-1009)
@Allowed: (Full) (LocalSystem)
@Allowed: (Full) (LocalSystem)
@Allowed: (Full) (Administrators)
@Allowed: (Full) (Administrators)
@Allowed: (Read) (S-1-5-12)
@Allowed: (Read) (S-1-5-12)
@=""
[HKEY_USERS\S-1-5-21-3507848658-395067767-2873291405-1009\AppEvents\Schemes\Apps\.Default\Minimize\R*NULL*F*NULL*S*NULL*0*NULL*H]
@Security=(SE_DACL_PRESENT SE_SELF_RELATIVE (@Owner @Group @DACL)
@Owner=S-1-5-21-3507848658-395067767-2873291405-1009
@Allowed: (Full) (S-1-5-21-3507848658-395067767-2873291405-1009)
@Allowed: (Full) (S-1-5-21-3507848658-395067767-2873291405-1009)
@Allowed: (Full) (LocalSystem)
@Allowed: (Full) (LocalSystem)
@Allowed: (Full) (Administrators)
@Allowed: (Full) (Administrators)
@Allowed: (Read) (S-1-5-12)
@Allowed: (Read) (S-1-5-12)
@=""
[HKEY_USERS\S-1-5-21-3507848658-395067767-2873291405-1009\AppEvents\Schemes\Apps\.Default\NMain-MouseClick\n*NULL*o*NULL*s*NULL*0*NULL*H]
@Security=(SE_DACL_PRESENT SE_SELF_RELATIVE (@Owner @Group @DACL)
@Owner=S-1-5-21-3507848658-395067767-2873291405-1009
@Allowed: (Full) (S-1-5-21-3507848658-395067767-2873291405-1009)
@Allowed: (Full) (S-1-5-21-3507848658-395067767-2873291405-1009)
@Allowed: (Full) (LocalSystem)
@Allowed: (Full) (LocalSystem)
@Allowed: (Full) (Administrators)
@Allowed: (Full) (Administrators)
@Allowed: (Read) (S-1-5-12)
@Allowed: (Read) (S-1-5-12)
@=""
[HKEY_USERS\S-1-5-21-3507848658-395067767-2873291405-1009\AppEvents\Schemes\Apps\.Default\NMain-MouseClick\R*NULL*F*NULL*S*NULL*0*NULL*H]
@Security=(SE_DACL_PRESENT SE_SELF_RELATIVE (@Owner @Group @DACL)
@Owner=S-1-5-21-3507848658-395067767-2873291405-1009
@Allowed: (Full) (S-1-5-21-3507848658-395067767-2873291405-1009)
@Allowed: (Full) (S-1-5-21-3507848658-395067767-2873291405-1009)
@Allowed: (Full) (LocalSystem)
@Allowed: (Full) (LocalSystem)
@Allowed: (Full) (Administrators)
@Allowed: (Full) (Administrators)
@Allowed: (Read) (S-1-5-12)
@Allowed: (Read) (S-1-5-12)
@=""
[HKEY_USERS\S-1-5-21-3507848658-395067767-2873291405-1009\AppEvents\Schemes\Apps\.Default\NMain-MouseLeave\n*NULL*o*NULL*s*NULL*0*NULL*H]
@Security=(SE_DACL_PRESENT SE_SELF_RELATIVE (@Owner @Group @DACL)
@Owner=S-1-5-21-3507848658-395067767-2873291405-1009
@Allowed: (Full) (S-1-5-21-3507848658-395067767-2873291405-1009)
@Allowed: (Full) (S-1-5-21-3507848658-395067767-2873291405-1009)
@Allowed: (Full) (LocalSystem)
@Allowed: (Full) (LocalSystem)
@Allowed: (Full) (Administrators)
@Allowed: (Full) (Administrators)
@Allowed: (Read) (S-1-5-12)
@Allowed: (Read) (S-1-5-12)
@=""
[HKEY_USERS\S-1-5-21-3507848658-395067767-2873291405-1009\AppEvents\Schemes\Apps\.Default\NMain-MouseLeave\R*NULL*F*NULL*S*NULL*0*NULL*H]
@Security=(SE_DACL_PRESENT SE_SELF_RELATIVE (@Owner @Group @DACL)
@Owner=S-1-5-21-3507848658-395067767-2873291405-1009
@Allowed: (Full) (S-1-5-21-3507848658-395067767-2873291405-1009)
@Allowed: (Full) (S-1-5-21-3507848658-395067767-2873291405-1009)
@Allowed: (Full) (LocalSystem)
@Allowed: (Full) (LocalSystem)
@Allowed: (Full) (Administrators)
@Allowed: (Full) (Administrators)
@Allowed: (Read) (S-1-5-12)
@Allowed: (Read) (S-1-5-12)
@=""
[HKEY_USERS\S-1-5-21-3507848658-395067767-2873291405-1009\AppEvents\Schemes\Apps\.Default\NMain-MouseOver\n*NULL*o*NULL*s*NULL*0*NULL*H]
@Security=(SE_DACL_PRESENT SE_SELF_RELATIVE (@Owner @Group @DACL)
@Owner=S-1-5-21-3507848658-395067767-2873291405-1009
@Allowed: (Full) (S-1-5-21-3507848658-395067767-2873291405-1009)
@Allowed: (Full) (S-1-5-21-3507848658-395067767-2873291405-1009)
@Allowed: (Full) (LocalSystem)
@Allowed: (Full) (LocalSystem)
@Allowed: (Full) (Administrators)
@Allowed: (Full) (Administrators)
@Allowed: (Read) (S-1-5-12)
@Allowed: (Read) (S-1-5-12)
@=""
[HKEY_USERS\S-1-5-21-3507848658-395067767-2873291405-1009\AppEvents\Schemes\Apps\.Default\NMain-MouseOver\R*NULL*F*NULL*S*NULL*0*NULL*H]
@Security=(SE_DACL_PRESENT SE_SELF_RELATIVE (@Owner @Group @DACL)
@Owner=S-1-5-21-3507848658-395067767-2873291405-1009
@Allowed: (Full) (S-1-5-21-3507848658-395067767-2873291405-1009)
@Allowed: (Full) (S-1-5-21-3507848658-395067767-2873291405-1009)
@Allowed: (Full) (LocalSystem)
@Allowed: (Full) (LocalSystem)
@Allowed: (Full) (Administrators)
@Allowed: (Full) (Administrators)
@Allowed: (Read) (S-1-5-12)
@Allowed: (Read) (S-1-5-12)
@=""
[HKEY_USERS\S-1-5-21-3507848658-395067767-2873291405-1009\AppEvents\Schemes\Apps\.Default\Open\n*NULL*o*NULL*s*NULL*0*NULL*H]
@Security=(SE_DACL_PRESENT SE_SELF_RELATIVE (@Owner @Group @DACL)
@Owner=S-1-5-21-3507848658-395067767-2873291405-1009
@Allowed: (Full) (S-1-5-21-3507848658-395067767-2873291405-1009)
@Allowed: (Full) (S-1-5-21-3507848658-395067767-2873291405-1009)
@Allowed: (Full) (LocalSystem)
@Allowed: (Full) (LocalSystem)
@Allowed: (Full) (Administrators)
@Allowed: (Full) (Administrators)
@Allowed: (Read) (S-1-5-12)
@Allowed: (Read) (S-1-5-12)
@=""
[HKEY_USERS\S-1-5-21-3507848658-395067767-2873291405-1009\AppEvents\Schemes\Apps\.Default\Open\R*NULL*F*NULL*S*NULL*0*NULL*H]
@Security=(SE_DACL_PRESENT SE_SELF_RELATIVE (@Owner @Group @DACL)
@Owner=S-1-5-21-3507848658-395067767-2873291405-1009
@Allowed: (Full) (S-1-5-21-3507848658-395067767-2873291405-1009)
@Allowed: (Full) (S-1-5-21-3507848658-395067767-2873291405-1009)
@Allowed: (Full) (LocalSystem)
@Allowed: (Full) (LocalSystem)
@Allowed: (Full) (Administrators)
@Allowed: (Full) (Administrators)
@Allowed: (Read) (S-1-5-12)
@Allowed: (Read) (S-1-5-12)
@=""
[HKEY_USERS\S-1-5-21-3507848658-395067767-2873291405-1009\AppEvents\Schemes\Apps\.Default\PrintComplete\n*NULL*o*NULL*s*NULL*0*NULL*H]
@Security=(SE_DACL_PRESENT SE_SELF_RELATIVE (@Owner @Group @DACL)
@Owner=S-1-5-21-3507848658-395067767-2873291405-1009
@Allowed: (Full) (S-1-5-21-3507848658-395067767-2873291405-1009)
@Allowed: (Full) (S-1-5-21-3507848658-395067767-2873291405-1009)
@Allowed: (Full) (LocalSystem)
@Allowed: (Full) (LocalSystem)
@Allowed: (Full) (Administrators)
@Allowed: (Full) (Administrators)
@Allowed: (Read) (S-1-5-12)
@Allowed: (Read) (S-1-5-12)
@=""
[HKEY_USERS\S-1-5-21-3507848658-395067767-2873291405-1009\AppEvents\Schemes\Apps\.Default\PrintComplete\R*NULL*F*NULL*S*NULL*0*NULL*H]
@Security=(SE_DACL_PRESENT SE_SELF_RELATIVE (@Owner @Group @DACL)
@Owner=S-1-5-21-3507848658-395067767-2873291405-1009
@Allowed: (Full) (S-1-5-21-3507848658-395067767-2873291405-1009)
@Allowed: (Full) (S-1-5-21-3507848658-395067767-2873291405-1009)
@Allowed: (Full) (LocalSystem)
@Allowed: (Full) (LocalSystem)
@Allowed: (Full) (Administrators)
@Allowed: (Full) (Administrators)
@Allowed: (Read) (S-1-5-12)
@Allowed: (Read) (S-1-5-12)
@=""
[HKEY_USERS\S-1-5-21-3507848658-395067767-2873291405-1009\AppEvents\Schemes\Apps\.Default\RestoreDown\n*NULL*o*NULL*s*NULL*0*NULL*H]
@Security=(SE_DACL_PRESENT SE_SELF_RELATIVE (@Owner @Group @DACL)
@Owner=S-1-5-21-3507848658-395067767-2873291405-1009
@Allowed: (Full) (S-1-5-21-3507848658-395067767-2873291405-1009)
@Allowed: (Full) (S-1-5-21-3507848658-395067767-2873291405-1009)
@Allowed: (Full) (LocalSystem)
@Allowed: (Full) (LocalSystem)
@Allowed: (Full) (Administrators)
@Allowed: (Full) (Administrators)
@Allowed: (Read) (S-1-5-12)
@Allowed: (Read) (S-1-5-12)
@=""
[HKEY_USERS\S-1-5-21-3507848658-395067767-2873291405-1009\AppEvents\Schemes\Apps\.Default\RestoreDown\R*NULL*F*NULL*S*NULL*0*NULL*H]
@Security=(SE_DACL_PRESENT SE_SELF_RELATIVE (@Owner @Group @DACL)
@Owner=S-1-5-21-3507848658-395067767-2873291405-1009
@Allowed: (Full) (S-1-5-21-3507848658-395067767-2873291405-1009)
@Allowed: (Full) (S-1-5-21-3507848658-395067767-2873291405-1009)
@Allowed: (Full) (LocalSystem)
@Allowed: (Full) (LocalSystem)
@Allowed: (Full) (Administrators)
@Allowed: (Full) (Administrators)
@Allowed: (Read) (S-1-5-12)
@Allowed: (Read) (S-1-5-12)
@=""
[HKEY_USERS\S-1-5-21-3507848658-395067767-2873291405-1009\AppEvents\Schemes\Apps\.Default\RestoreUp\n*NULL*o*NULL*s*NULL*0*NULL*H]
@Security=(SE_DACL_PRESENT SE_SELF_RELATIVE (@Owner @Group @DACL)
@Owner=S-1-5-21-3507848658-395067767-2873291405-1009
@Allowed: (Full) (S-1-5-21-3507848658-395067767-2873291405-1009)
@Allowed: (Full) (S-1-5-21-3507848658-395067767-2873291405-1009)
@Allowed: (Full) (LocalSystem)
@Allowed: (Full) (LocalSystem)
@Allowed: (Full) (Administrators)
@Allowed: (Full) (Administrators)
@Allowed: (Read) (S-1-5-12)
@Allowed: (Read) (S-1-5-12)
@=""
[HKEY_USERS\S-1-5-21-3507848658-395067767-2873291405-1009\AppEvents\Schemes\Apps\.Default\RestoreUp\R*NULL*F*NULL*S*NULL*0*NULL*H]
@Security=(SE_DACL_PRESENT SE_SELF_RELATIVE (@Owner @Group @DACL)
@Owner=S-1-5-21-3507848658-395067767-2873291405-1009
@Allowed: (Full) (S-1-5-21-3507848658-395067767-2873291405-1009)
@Allowed: (Full) (S-1-5-21-3507848658-395067767-2873291405-1009)
@Allowed: (Full) (LocalSystem)
@Allowed: (Full) (LocalSystem)
@Allowed: (Full) (Administrators)
@Allowed: (Full) (Administrators)
@Allowed: (Read) (S-1-5-12)
@Allowed: (Read) (S-1-5-12)
@=""
[HKEY_USERS\S-1-5-21-3507848658-395067767-2873291405-1009\AppEvents\Schemes\Apps\.Default\ShowBand\n*NULL*o*NULL*s*NULL*0*NULL*H]
@Security=(SE_DACL_PRESENT SE_SELF_RELATIVE (@Owner @Group @DACL)
@Owner=S-1-5-21-3507848658-395067767-2873291405-1009
@Allowed: (Full) (S-1-5-21-3507848658-395067767-2873291405-1009)
@Allowed: (Full) (S-1-5-21-3507848658-395067767-2873291405-1009)
@Allowed: (Full) (LocalSystem)
@Allowed: (Full) (LocalSystem)
@Allowed: (Full) (Administrators)
@Allowed: (Full) (Administrators)
@Allowed: (Read) (S-1-5-12)
@Allowed: (Read) (S-1-5-12)
@=""
[HKEY_USERS\S-1-5-21-3507848658-395067767-2873291405-1009\AppEvents\Schemes\Apps\.Default\ShowBand\R*NULL*F*NULL*S*NULL*0*NULL*H]
@Security=(SE_DACL_PRESENT SE_SELF_RELATIVE (@Owner @Group @DACL)
@Owner=S-1-5-21-3507848658-395067767-2873291405-1009
@Allowed: (Full) (S-1-5-21-3507848658-395067767-2873291405-1009)
@Allowed: (Full) (S-1-5-21-3507848658-395067767-2873291405-1009)
@Allowed: (Full) (LocalSystem)
@Allowed: (Full) (LocalSystem)
@Allowed: (Full) (Administrators)
@Allowed: (Full) (Administrators)
@Allowed: (Read) (S-1-5-12)
@Allowed: (Read) (S-1-5-12)
@=""
[HKEY_USERS\S-1-5-21-3507848658-395067767-2873291405-1009\AppEvents\Schemes\Apps\.Default\SystemAsterisk\n*NULL*o*NULL*s*NULL*0*NULL*H]
@Security=(SE_DACL_PRESENT SE_SELF_RELATIVE (@Owner @Group @DACL)
@Owner=S-1-5-21-3507848658-395067767-2873291405-1009
@Allowed: (Full) (S-1-5-21-3507848658-395067767-2873291405-1009)
@Allowed: (Full) (S-1-5-21-3507848658-395067767-2873291405-1009)
@Allowed: (Full) (LocalSystem)
@Allowed: (Full) (LocalSystem)
@Allowed: (Full) (Administrators)
@Allowed: (Full) (Administrators)
@Allowed: (Read) (S-1-5-12)
@Allowed: (Read) (S-1-5-12)
@=expand:"%SystemRoot%\\media\\Windows XP Error.wav"
[HKEY_USERS\S-1-5-21-3507848658-395067767-2873291405-1009\AppEvents\Schemes\Apps\.Default\SystemAsterisk\R*NULL*F*NULL*S*NULL*0*NULL*H]
@Security=(SE_DACL_PRESENT SE_SELF_RELATIVE (@Owner @Group @DACL)
@Owner=S-1-5-21-3507848658-395067767-2873291405-1009
@Allowed: (Full) (S-1-5-21-3507848658-395067767-2873291405-1009)
@Allowed: (Full) (S-1-5-21-3507848658-395067767-2873291405-1009)
@Allowed: (Full) (LocalSystem)
@Allowed: (Full) (LocalSystem)
@Allowed: (Full) (Administrators)
@Allowed: (Full) (Administrators)
@Allowed: (Read) (S-1-5-12)
@Allowed: (Read) (S-1-5-12)
@=""
[HKEY_USERS\S-1-5-21-3507848658-395067767-2873291405-1009\AppEvents\Schemes\Apps\.Default\SystemExclamation\n*NULL*o*NULL*s*NULL*0*NULL*H]
@Security=(SE_DACL_PRESENT SE_SELF_RELATIVE (@Owner @Group @DACL)
@Owner=S-1-5-21-3507848658-395067767-2873291405-1009
@Allowed: (Full) (S-1-5-21-3507848658-395067767-2873291405-1009)
@Allowed: (Full) (S-1-5-21-3507848658-395067767-2873291405-1009)
@Allowed: (Full) (LocalSystem)
@Allowed: (Full) (LocalSystem)
@Allowed: (Full) (Administrators)
@Allowed: (Full) (Administrators)
@Allowed: (Read) (S-1-5-12)
@Allowed: (Read) (S-1-5-12)
@=expand:"%SystemRoot%\\media\\Windows XP Exclamation.wav"
[HKEY_USERS\S-1-5-21-3507848658-395067767-2873291405-1009\AppEvents\Schemes\Apps\.Default\SystemExclamation\R*NULL*F*NULL*S*NULL*0*NULL*H]
@Security=(SE_DACL_PRESENT SE_SELF_RELATIVE (@Owner @Group @DACL)
@Owner=S-1-5-21-3507848658-395067767-2873291405-1009
@Allowed: (Full) (S-1-5-21-3507848658-395067767-2873291405-1009)
@Allowed: (Full) (S-1-5-21-3507848658-395067767-2873291405-1009)
@Allowed: (Full) (LocalSystem)
@Allowed: (Full) (LocalSystem)
@Allowed: (Full) (Administrators)
@Allowed: (Full) (Administrators)
@Allowed: (Read) (S-1-5-12)
@Allowed: (Read) (S-1-5-12)
@=""
[HKEY_USERS\S-1-5-21-3507848658-395067767-2873291405-1009\AppEvents\Schemes\Apps\.Default\SystemExit\n*NULL*o*NULL*s*NULL*0*NULL*H]
@Security=(SE_DACL_PRESENT SE_SELF_RELATIVE (@Owner @Group @DACL)
@Owner=S-1-5-21-3507848658-395067767-2873291405-1009
@Allowed: (Full) (S-1-5-21-3507848658-395067767-2873291405-1009)
@Allowed: (Full) (S-1-5-21-3507848658-395067767-2873291405-1009)
@Allowed: (Full) (LocalSystem)
@Allowed: (Full) (LocalSystem)
@Allowed: (Full) (Administrators)
@Allowed: (Full) (Administrators)
@Allowed: (Read) (S-1-5-12)
@Allowed: (Read) (S-1-5-12)
@=expand:"%SystemRoot%\\media\\Windows XP Shutdown.wav"
[HKEY_USERS\S-1-5-21-3507848658-395067767-2873291405-1009\AppEvents\Schemes\Apps\.Default\SystemExit\R*NULL*F*NULL*S*NULL*0*NULL*H]
@Security=(SE_DACL_PRESENT SE_SELF_RELATIVE (@Owner @Group @DACL)
@Owner=S-1-5-21-3507848658-395067767-2873291405-1009
@Allowed: (Full) (S-1-5-21-3507848658-395067767-2873291405-1009)
@Allowed: (Full) (S-1-5-21-3507848658-395067767-2873291405-1009)
@Allowed: (Full) (LocalSystem)
@Allowed: (Full) (LocalSystem)
@Allowed: (Full) (Administrators)
@Allowed: (Full) (Administrators)
@Allowed: (Read) (S-1-5-12)
@Allowed: (Read) (S-1-5-12)
@=""
[HKEY_USERS\S-1-5-21-3507848658-395067767-2873291405-1009\AppEvents\Schemes\Apps\.Default\SystemHand\n*NULL*o*NULL*s*NULL*0*NULL*H]
@Security=(SE_DACL_PRESENT SE_SELF_RELATIVE (@Owner @Group @DACL)
@Owner=S-1-5-21-3507848658-395067767-2873291405-1009
@Allowed: (Full) (S-1-5-21-3507848658-395067767-2873291405-1009)
@Allowed: (Full) (S-1-5-21-3507848658-395067767-2873291405-1009)
@Allowed: (Full) (LocalSystem)
@Allowed: (Full) (LocalSystem)
@Allowed: (Full) (Administrators)
@Allowed: (Full) (Administrators)
@Allowed: (Read) (S-1-5-12)
@Allowed: (Read) (S-1-5-12)
@=expand:"%SystemRoot%\\media\\Windows XP Critical Stop.wav"
[HKEY_USERS\S-1-5-21-3507848658-395067767-2873291405-1009\AppEvents\Schemes\Apps\.Default\SystemHand\R*NULL*F*NULL*S*NULL*0*NULL*H]
@Security=(SE_DACL_PRESENT SE_SELF_RELATIVE (@Owner @Group @DACL)
@Owner=S-1-5-21-3507848658-395067767-2873291405-1009
@Allowed: (Full) (S-1-5-21-3507848658-395067767-2873291405-1009)
@Allowed: (Full) (S-1-5-21-3507848658-395067767-2873291405-1009)
@Allowed: (Full) (LocalSystem)
@Allowed: (Full) (LocalSystem)
@Allowed: (Full) (Administrators)
@Allowed: (Full) (Administrators)
@Allowed: (Read) (S-1-5-12)
@Allowed: (Read) (S-1-5-12)
@=""
[HKEY_USERS\S-1-5-21-3507848658-395067767-2873291405-1009\AppEvents\Schemes\Apps\.Default\SystemNotification\n*NULL*o*NULL*s*NULL*0*NULL*H]
@Security=(SE_DACL_PRESENT SE_SELF_RELATIVE (@Owner @Group @DACL)
@Owner=S-1-5-21-3507848658-395067767-2873291405-1009
@Allowed: (Full) (S-1-5-21-3507848658-395067767-2873291405-1009)
@Allowed: (Full) (S-1-5-21-3507848658-395067767-2873291405-1009)
@Allowed: (Full) (LocalSystem)
@Allowed: (Full) (LocalSystem)
@Allowed: (Full) (Administrators)
@Allowed: (Full) (Administrators)
@Allowed: (Read) (S-1-5-12)
@Allowed: (Read) (S-1-5-12)
@=expand:"%SystemRoot%\\media\\Windows XP Balloon.wav"
[HKEY_USERS\S-1-5-21-3507848658-395067767-2873291405-1009\AppEvents\Schemes\Apps\.Default\SystemNotification\R*NULL*F*NULL*S*NULL*0*NULL*H]
@Security=(SE_DACL_PRESENT SE_SELF_RELATIVE (@Owner @Group @DACL)
@Owner=S-1-5-21-3507848658-395067767-2873291405-1009
@Allowed: (Full) (S-1-5-21-3507848658-395067767-2873291405-1009)
@Allowed: (Full) (S-1-5-21-3507848658-395067767-2873291405-1009)
@Allowed: (Full) (LocalSystem)
@Allowed: (Full) (LocalSystem)
@Allowed: (Full) (Administrators)
@Allowed: (Full) (Administrators)
@Allowed: (Read) (S-1-5-12)
@Allowed: (Read) (S-1-5-12)
@=""
[HKEY_USERS\S-1-5-21-3507848658-395067767-2873291405-1009\AppEvents\Schemes\Apps\.Default\SystemQuestion\n*NULL*o*NULL*s*NULL*0*NULL*H]
@Security=(SE_DACL_PRESENT SE_SELF_RELATIVE (@Owner @Group @DACL)
@Owner=S-1-5-21-3507848658-395067767-2873291405-1009
@Allowed: (Full) (S-1-5-21-3507848658-395067767-2873291405-1009)
@Allowed: (Full) (S-1-5-21-3507848658-395067767-2873291405-1009)
@Allowed: (Full) (LocalSystem)
@Allowed: (Full) (LocalSystem)
@Allowed: (Full) (Administrators)
@Allowed: (Full) (Administrators)
@Allowed: (Read) (S-1-5-12)
@Allowed: (Read) (S-1-5-12)
@=""
[HKEY_USERS\S-1-5-21-3507848658-395067767-2873291405-1009\AppEvents\Schemes\Apps\.Default\SystemQuestion\R*NULL*F*NULL*S*NULL*0*NULL*H]
@Security=(SE_DACL_PRESENT SE_SELF_RELATIVE (@Owner @Group @DACL)
@Owner=S-1-5-21-3507848658-395067767-2873291405-1009
@Allowed: (Full) (S-1-5-21-3507848658-395067767-2873291405-1009)
@Allowed: (Full) (S-1-5-21-3507848658-395067767-2873291405-1009)
@Allowed: (Full) (LocalSystem)
@Allowed: (Full) (LocalSystem)
@Allowed: (Full) (Administrators)
@Allowed: (Full) (Administrators)
@Allowed: (Read) (S-1-5-12)
@Allowed: (Read) (S-1-5-12)
@=""
[HKEY_USERS\S-1-5-21-3507848658-395067767-2873291405-1009\AppEvents\Schemes\Apps\.Default\SystemStart\n*NULL*o*NULL*s*NULL*0*NULL*H]
@Security=(SE_DACL_PRESENT SE_SELF_RELATIVE (@Owner @Group @DACL)
@Owner=S-1-5-21-3507848658-395067767-2873291405-1009
@Allowed: (Full) (S-1-5-21-3507848658-395067767-2873291405-1009)
@Allowed: (Full) (S-1-5-21-3507848658-395067767-2873291405-1009)
@Allowed: (Full) (LocalSystem)
@Allowed: (Full) (LocalSystem)
@Allowed: (Full) (Administrators)
@Allowed: (Full) (Administrators)
@Allowed: (Read) (S-1-5-12)
@Allowed: (Read) (S-1-5-12)
@=expand:"%SystemRoot%\\media\\Windows XP Startup.wav"
[HKEY_USERS\S-1-5-21-3507848658-395067767-2873291405-1009\AppEvents\Schemes\Apps\.Default\SystemStart\R*NULL*F*NULL*S*NULL*0*NULL*H]
@Security=(SE_DACL_PRESENT SE_SELF_RELATIVE (@Owner @Group @DACL)
@Owner=S-1-5-21-3507848658-395067767-2873291405-1009
@Allowed: (Full) (S-1-5-21-3507848658-395067767-2873291405-1009)
@Allowed: (Full) (S-1-5-21-3507848658-395067767-2873291405-1009)
@Allowed: (Full) (LocalSystem)
@Allowed: (Full) (LocalSystem)
@Allowed: (Full) (Administrators)
@Allowed: (Full) (Administrators)
@Allowed: (Read) (S-1-5-12)
@Allowed: (Read) (S-1-5-12)
@=""
[HKEY_USERS\S-1-5-21-3507848658-395067767-2873291405-1009\AppEvents\Schemes\Apps\.Default\WindowsLogoff\n*NULL*o*NULL*s*NULL*0*NULL*H]
@Security=(SE_DACL_PRESENT SE_SELF_RELATIVE (@Owner @Group @DACL)
@Owner=S-1-5-21-3507848658-395067767-2873291405-1009
@Allowed: (Full) (S-1-5-21-3507848658-395067767-2873291405-1009)
@Allowed: (Full) (S-1-5-21-3507848658-395067767-2873291405-1009)
@Allowed: (Full) (LocalSystem)
@Allowed: (Full) (LocalSystem)
@Allowed: (Full) (Administrators)
@Allowed: (Full) (Administrators)
@Allowed: (Read) (S-1-5-12)
@Allowed: (Read) (S-1-5-12)
@=expand:"%SystemRoot%\\media\\Windows XP Logoff Sound.wav"
[HKEY_USERS\S-1-5-21-3507848658-395067767-2873291405-1009\AppEvents\Schemes\Apps\.Default\WindowsLogoff\R*NULL*F*NULL*S*NULL*0*NULL*H]
@Security=(SE_DACL_PRESENT SE_SELF_RELATIVE (@Owner @Group @DACL)
@Owner=S-1-5-21-3507848658-395067767-2873291405-1009
@Allowed: (Full) (S-1-5-21-3507848658-395067767-2873291405-1009)
@Allowed: (Full) (S-1-5-21-3507848658-395067767-2873291405-1009)
@Allowed: (Full) (LocalSystem)
@Allowed: (Full) (LocalSystem)
@Allowed: (Full) (Administrators)
@Allowed: (Full) (Administrators)
@Allowed: (Read) (S-1-5-12)
@Allowed: (Read) (S-1-5-12)
@=""
[HKEY_USERS\S-1-5-21-3507848658-395067767-2873291405-1009\AppEvents\Schemes\Apps\.Default\WindowsLogon\n*NULL*o*NULL*s*NULL*0*NULL*H]
@Security=(SE_DACL_PRESENT SE_SELF_RELATIVE (@Owner @Group @DACL)
@Owner=S-1-5-21-3507848658-395067767-2873291405-1009
@Allowed: (Full) (S-1-5-21-3507848658-395067767-2873291405-1009)
@Allowed: (Full) (S-1-5-21-3507848658-395067767-2873291405-1009)
@Allowed: (Full) (LocalSystem)
@Allowed: (Full) (LocalSystem)
@Allowed: (Full) (Administrators)
@Allowed: (Full) (Administrators)
@Allowed: (Read) (S-1-5-12)
@Allowed: (Read) (S-1-5-12)
@=expand:"%SystemRoot%\\media\\Windows XP Logon Sound.wav"
[HKEY_USERS\S-1-5-21-3507848658-395067767-2873291405-1009\AppEvents\Schemes\Apps\.Default\WindowsLogon\R*NULL*F*NULL*S*NULL*0*NULL*H]
@Security=(SE_DACL_PRESENT SE_SELF_RELATIVE (@Owner @Group @DACL)
@Owner=S-1-5-21-3507848658-395067767-2873291405-1009
@Allowed: (Full) (S-1-5-21-3507848658-395067767-2873291405-1009)
@Allowed: (Full) (S-1-5-21-3507848658-395067767-2873291405-1009)
@Allowed: (Full) (LocalSystem)
@Allowed: (Full) (LocalSystem)
@Allowed: (Full) (Administrators)
@Allowed: (Full) (Administrators)
@Allowed: (Read) (S-1-5-12)
@Allowed: (Read) (S-1-5-12)
@=""
[HKEY_USERS\S-1-5-21-3507848658-395067767-2873291405-1009\AppEvents\Schemes\Apps\AOL_US(Default Sounds)\Alert\n*NULL*o*NULL*s*NULL*0*NULL*H]
@Security="Inherited"
@=""
[HKEY_USERS\S-1-5-21-3507848658-395067767-2873291405-1009\AppEvents\Schemes\Apps\AOL_US(Default Sounds)\Alert\R*NULL*F*NULL*S*NULL*0*NULL*H]
@Security="Inherited"
@="07 - Toshiro Masuda - The Raising Fighting Spirit.WAV"
[HKEY_USERS\S-1-5-21-3507848658-395067767-2873291405-1009\AppEvents\Schemes\Apps\AOL_US(Default Sounds)\BuddyIn\n*NULL*o*NULL*s*NULL*0*NULL*H]
@Security="Inherited"
@=""
[HKEY_USERS\S-1-5-21-3507848658-395067767-2873291405-1009\AppEvents\Schemes\Apps\AOL_US(Default Sounds)\BuddyIn\R*NULL*F*NULL*S*NULL*0*NULL*H]
@Security="Inherited"
@="07 - Toshiro Masuda - The Raising Fighting Spirit.wav"
[HKEY_USERS\S-1-5-21-3507848658-395067767-2873291405-1009\AppEvents\Schemes\Apps\AOL_US(Default Sounds)\BuddyOut\n*NULL*o*NULL*s*NULL*0*NULL*H]
@Security="Inherited"
@=""
[HKEY_USERS\S-1-5-21-3507848658-395067767-2873291405-1009\AppEvents\Schemes\Apps\AOL_US(Default Sounds)\BuddyOut\R*NULL*F*NULL*S*NULL*0*NULL*H]
@Security="Inherited"
@="07 - Toshiro Masuda - The Raising Fighting Spirit.WAV"
[HKEY_USERS\S-1-5-21-3507848658-395067767-2873291405-1009\AppEvents\Schemes\Apps\AOL_US(Default Sounds)\Drop\n*NULL*o*NULL*s*NULL*0*NULL*H]
@Security="Inherited"
@=""
[HKEY_USERS\S-1-5-21-3507848658-395067767-2873291405-1009\AppEvents\Schemes\Apps\AOL_US(Default Sounds)\Drop\R*NULL*F*NULL*S*NULL*0*NULL*H]
@Security="Inherited"
@="07 - Toshiro Masuda - The Raising Fighting Spirit.WAV"
[HKEY_USERS\S-1-5-21-3507848658-395067767-2873291405-1009\AppEvents\Schemes\Apps\AOL_US(Default Sounds)\File's Done\n*NULL*o*NULL*s*NULL*0*NULL*H]
@Security="Inherited"
@=""
[HKEY_USERS\S-1-5-21-3507848658-395067767-2873291405-1009\AppEvents\Schemes\Apps\AOL_US(Default Sounds)\File's Done\R*NULL*F*NULL*S*NULL*0*NULL*H]
@Security="Inherited"
@="07 - Toshiro Masuda - The Raising Fighting Spirit.WAV"
[HKEY_USERS\S-1-5-21-3507848658-395067767-2873291405-1009\AppEvents\Schemes\Apps\AOL_US(Default Sounds)\Goodbye\n*NULL*o*NULL*s*NULL*0*NULL*H]
@Security="Inherited"
@=""
[HKEY_USERS\S-1-5-21-3507848658-395067767-2873291405-1009\AppEvents\Schemes\Apps\AOL_US(Default Sounds)\Goodbye\R*NULL*F*NULL*S*NULL*0*NULL*H]
@Security="Inherited"
@="07 - Toshiro Masuda - The Raising Fighting Spirit.WAV"
[HKEY_USERS\S-1-5-21-3507848658-395067767-2873291405-1009\AppEvents\Schemes\Apps\AOL_US(Default Sounds)\IM\n*NULL*o*NULL*s*NULL*0*NULL*H]
@Security="Inherited"
@=""
[HKEY_USERS\S-1-5-21-3507848658-395067767-2873291405-1009\AppEvents\Schemes\Apps\AOL_US(Default Sounds)\IM\R*NULL*F*NULL*S*NULL*0*NULL*H]
@Security="Inherited"
@="07 - Toshiro Masuda - The Raising Fighting Spirit.WAV"
[HKEY_USERS\S-1-5-21-3507848658-395067767-2873291405-1009\AppEvents\Schemes\Apps\AOL_US(Default Sounds)\Inactivity45\n*NULL*o*NULL*s*NULL*0*NULL*H]
@Security="Inherited"
@=""
[HKEY_USERS\S-1-5-21-3507848658-395067767-2873291405-1009\AppEvents\Schemes\Apps\AOL_US(Default Sounds)\Inactivity45\R*NULL*F*NULL*S*NULL*0*NULL*H]
@Security="Inherited"
@="07 - Toshiro Masuda - The Raising Fighting Spirit.WAV"
[HKEY_USERS\S-1-5-21-3507848658-395067767-2873291405-1009\AppEvents\Schemes\Apps\AOL_US(Default Sounds)\More Mail\n*NULL*o*NULL*s*NULL*0*NULL*H]
@Security="Inherited"
@=""
[HKEY_USERS\S-1-5-21-3507848658-395067767-2873291405-1009\AppEvents\Schemes\Apps\AOL_US(Default Sounds)\More Mail\R*NULL*F*NULL*S*NULL*0*NULL*H]
@Security="Inherited"
@="07 - Toshiro Masuda - The Raising Fighting Spirit.WAV"
[HKEY_USERS\S-1-5-21-3507848658-395067767-2873291405-1009\AppEvents\Schemes\Apps\AOL_US(Default Sounds)\OCW\n*NULL*o*NULL*s*NULL*0*NULL*H]
@Security="Inherited"
@=""
[HKEY_USERS\S-1-5-21-3507848658-395067767-2873291405-1009\AppEvents\Schemes\Apps\AOL_US(Default Sounds)\OCW\R*NULL*F*NULL*S*NULL*0*NULL*H]
@Security="Inherited"
@="07 - Toshiro Masuda - The Raising Fighting Spirit.WAV"
[HKEY_USERS\S-1-5-21-3507848658-395067767-2873291405-1009\AppEvents\Schemes\Apps\AOL_US(Default Sounds)\PanelIn\n*NULL*o*NULL*s*NULL*0*NULL*H]
@Security="Inherited"
@=""
[HKEY_USERS\S-1-5-21-3507848658-395067767-2873291405-1009\AppEvents\Schemes\Apps\AOL_US(Default Sounds)\PanelIn\R*NULL*F*NULL*S*NULL*0*NULL*H]
@Security="Inherited"
@="07 - Toshiro Masuda - The Raising Fighting Spirit.WAV"
[HKEY_USERS\S-1-5-21-3507848658-395067767-2873291405-1009\AppEvents\Schemes\Apps\AOL_US(Default Sounds)\PanelOut\n*NULL*o*NULL*s*NULL*0*NULL*H]
@Security="Inherited"
@=""
[HKEY_USERS\S-1-5-21-3507848658-395067767-2873291405-1009\AppEvents\Schemes\Apps\AOL_US(Default Sounds)\PanelOut\R*NULL*F*NULL*S*NULL*0*NULL*H]
@Security="Inherited"
@="07 - Toshiro Masuda - The Raising Fighting Spirit.WAV"
[HKEY_USERS\S-1-5-21-3507848658-395067767-2873291405-1009\AppEvents\Schemes\Apps\AOL_US(Default Sounds)\popupblock\n*NULL*o*NULL*s*NULL*0*NULL*H]
@Security="Inherited"
@=""
[HKEY_USERS\S-1-5-21-3507848658-395067767-2873291405-1009\AppEvents\Schemes\Apps\AOL_US(Default Sounds)\popupblock\R*NULL*F*NULL*S*NULL*0*NULL*H]
@Security="Inherited"
@="07 - Toshiro Masuda - The Raising Fighting Spirit.WAV"
[HKEY_USERS\S-1-5-21-3507848658-395067767-2873291405-1009\AppEvents\Schemes\Apps\AOL_US(Default Sounds)\Slide\n*NULL*o*NULL*s*NULL*0*NULL*H]
@Security="Inherited"
@=""
[HKEY_USERS\S-1-5-21-3507848658-395067767-2873291405-1009\AppEvents\Schemes\Apps\AOL_US(Default Sounds)\Slide\R*NULL*F*NULL*S*NULL*0*NULL*H]
@Security="Inherited"
@="07 - Toshiro Masuda - The Raising Fighting Spirit.WAV"
[HKEY_USERS\S-1-5-21-3507848658-395067767-2873291405-1009\AppEvents\Schemes\Apps\AOL_US(Default Sounds)\TalkRing\n*NULL*o*NULL*s*NULL*0*NULL*H]
@Security="Inherited"
@=""
[HKEY_USERS\S-1-5-21-3507848658-395067767-2873291405-1009\AppEvents\Schemes\Apps\AOL_US(Default Sounds)\TalkRing\R*NULL*F*NULL*S*NULL*0*NULL*H]
@Security="Inherited"
@="07 - Toshiro Masuda - The Raising Fighting Spirit.WAV"
[HKEY_USERS\S-1-5-21-3507848658-395067767-2873291405-1009\AppEvents\Schemes\Apps\AOL_US(Default Sounds)\Urgent\n*NULL*o*NULL*s*NULL*0*NULL*H]
@Security="Inherited"
@=""
[HKEY_USERS\S-1-5-21-3507848658-395067767-2873291405-1009\AppEvents\Schemes\Apps\AOL_US(Default Sounds)\Urgent\R*NULL*F*NULL*S*NULL*0*NULL*H]
@Security="Inherited"
@="07 - Toshiro Masuda - The Raising Fighting Spirit.WAV"
[HKEY_USERS\S-1-5-21-3507848658-395067767-2873291405-1009\AppEvents\Schemes\Apps\AOL_US(Default Sounds)\Welcome\n*NULL*o*NULL*s*NULL*0*NULL*H]
@Security="Inherited"
@=""
[HKEY_USERS\S-1-5-21-3507848658-395067767-2873291405-1009\AppEvents\Schemes\Apps\AOL_US(Default Sounds)\Welcome\R*NULL*F*NULL*S*NULL*0*NULL*H]
@Security="Inherited"
@="07 - Toshiro Masuda - The Raising Fighting Spirit.WAV"
[HKEY_USERS\S-1-5-21-3507848658-395067767-2873291405-1009\AppEvents\Schemes\Apps\AOL_US(Default Sounds)\ygp\n*NULL*o*NULL*s*NULL*0*NULL*H]
@Security="Inherited"
@=""
[HKEY_USERS\S-1-5-21-3507848658-395067767-2873291405-1009\AppEvents\Schemes\Apps\AOL_US(Default Sounds)\ygp\R*NULL*F*NULL*S*NULL*0*NULL*H]
@Security="Inherited"
@="07 - Toshiro Masuda - The Raising Fighting Spirit.WAV"
[HKEY_USERS\S-1-5-21-3507848658-395067767-2873291405-1009\AppEvents\Schemes\Apps\AOL_US(Default Sounds)\Ygvm\n*NULL*o*NULL*s*NULL*0*NULL*H]
@Security="Inherited"
@=""
[HKEY_USERS\S-1-5-21-3507848658-395067767-2873291405-1009\AppEvents\Schemes\Apps\AOL_US(Default Sounds)\Ygvm\R*NULL*F*NULL*S*NULL*0*NULL*H]
@Security="Inherited"
@="07 - Toshiro Masuda - The Raising Fighting Spirit.WAV"
[HKEY_USERS\S-1-5-21-3507848658-395067767-2873291405-1009\AppEvents\Schemes\Apps\AOL_US(Default Sounds)\You've Got Mail\n*NULL*o*NULL*s*NULL*0*NULL*H]
@Security="Inherited"
@=""
[HKEY_USERS\S-1-5-21-3507848658-395067767-2873291405-1009\AppEvents\Schemes\Apps\AOL_US(Default Sounds)\You've Got Mail\R*NULL*F*NULL*S*NULL*0*NULL*H]
@Security="Inherited"
@="07 - Toshiro Masuda - The Raising Fighting Spirit.WAV"
[HKEY_USERS\S-1-5-21-3507848658-395067767-2873291405-1009\AppEvents\Schemes\Apps\Conf\Person Joins\n*NULL*o*NULL*s*NULL*0*NULL*H]
@Security=(SE_DACL_PRESENT SE_SELF_RELATIVE (@Owner @Group @DACL)
@Owner=S-1-5-21-3507848658-395067767-2873291405-1009
@Allowed: (Full) (S-1-5-21-3507848658-395067767-2873291405-1009)
@Allowed: (Full) (S-1-5-21-3507848658-395067767-2873291405-1009)
@Allowed: (Full) (LocalSystem)
@Allowed: (Full) (LocalSystem)
@Allowed: (Full) (Administrators)
@Allowed: (Full) (Administrators)
@Allowed: (Read) (S-1-5-12)
@Allowed: (Read) (S-1-5-12)
@=""
[HKEY_USERS\S-1-5-21-3507848658-395067767-2873291405-1009\AppEvents\Schemes\Apps\Conf\Person Joins\R*NULL*F*NULL*S*NULL*0*NULL*H]
@Security=(SE_DACL_PRESENT SE_SELF_RELATIVE (@Owner @Group @DACL)
@Owner=S-1-5-21-3507848658-395067767-2873291405-1009
@Allowed: (Full) (S-1-5-21-3507848658-395067767-2873291405-1009)
@Allowed: (Full) (S-1-5-21-3507848658-395067767-2873291405-1009)
@Allowed: (Full) (LocalSystem)
@Allowed: (Full) (LocalSystem)
@Allowed: (Full) (Administrators)
@Allowed: (Full) (Administrators)
@Allowed: (Read) (S-1-5-12)
@Allowed: (Read) (S-1-5-12)
@=""
[HKEY_USERS\S-1-5-21-3507848658-395067767-2873291405-1009\AppEvents\Schemes\Apps\Conf\Person Leaves\n*NULL*o*NULL*s*NULL*0*NULL*H]
@Security=(SE_DACL_PRESENT SE_SELF_RELATIVE (@Owner @Group @DACL)
@Owner=S-1-5-21-3507848658-395067767-2873291405-1009
@Allowed: (Full) (S-1-5-21-3507848658-395067767-2873291405-1009)
@Allowed: (Full) (S-1-5-21-3507848658-395067767-2873291405-1009)
@Allowed: (Full) (LocalSystem)
@Allowed: (Full) (LocalSystem)
@Allowed: (Full) (Administrators)
@Allowed: (Full) (Administrators)
@Allowed: (Read) (S-1-5-12)
@Allowed: (Read) (S-1-5-12)
@=""
[HKEY_USERS\S-1-5-21-3507848658-395067767-2873291405-1009\AppEvents\Schemes\Apps\Conf\Person Leaves\R*NULL*F*NULL*S*NULL*0*NULL*H]
@Security=(SE_DACL_PRESENT SE_SELF_RELATIVE (@Owner @Group @DACL)
@Owner=S-1-5-21-3507848658-395067767-2873291405-1009
@Allowed: (Full) (S-1-5-21-3507848658-395067767-2873291405-1009)
@Allowed: (Full) (S-1-5-21-3507848658-395067767-2873291405-1009)
@Allowed: (Full) (LocalSystem)
@Allowed: (Full) (LocalSystem)
@Allowed: (Full) (Administrators)
@Allowed: (Full) (Administrators)
@Allowed: (Read) (S-1-5-12)
@Allowed: (Read) (S-1-5-12)
@=""
[HKEY_USERS\S-1-5-21-3507848658-395067767-2873291405-1009\AppEvents\Schemes\Apps\Conf\Receive Call\n*NULL*o*NULL*s*NULL*0*NULL*H]
@Security=(SE_DACL_PRESENT SE_SELF_RELATIVE (@Owner @Group @DACL)
@Owner=S-1-5-21-3507848658-395067767-2873291405-1009
@Allowed: (Full) (S-1-5-21-3507848658-395067767-2873291405-1009)
@Allowed: (Full) (S-1-5-21-3507848658-395067767-2873291405-1009)
@Allowed: (Full) (LocalSystem)
@Allowed: (Full) (LocalSystem)
@Allowed: (Full) (Administrators)
@Allowed: (Full) (Administrators)
@Allowed: (Read) (S-1-5-12)
@Allowed: (Read) (S-1-5-12)
@=""
[HKEY_USERS\S-1-5-21-3507848658-395067767-2873291405-1009\AppEvents\Schemes\Apps\Conf\Receive Call\R*NULL*F*NULL*S*NULL*0*NULL*H]
@Security=(SE_DACL_PRESENT SE_SELF_RELATIVE (@Owner @Group @DACL)
@Owner=S-1-5-21-3507848658-395067767-2873291405-1009
@Allowed: (Full) (S-1-5-21-3507848658-395067767-2873291405-1009)
@Allowed: (Full) (S-1-5-21-3507848658-395067767-2873291405-1009)
@Allowed: (Full) (LocalSystem)
@Allowed: (Full) (LocalSystem)
@Allowed: (Full) (Administrators)
@Allowed: (Full) (Administrators)
@Allowed: (Read) (S-1-5-12)
@Allowed: (Read) (S-1-5-12)
@=""
[HKEY_USERS\S-1-5-21-3507848658-395067767-2873291405-1009\AppEvents\Schemes\Apps\Conf\Receive Request to Join\n*NULL*o*NULL*s*NULL*0*NULL*H]
@Security=(SE_DACL_PRESENT SE_SELF_RELATIVE (@Owner @Group @DACL)
@Owner=S-1-5-21-3507848658-395067767-2873291405-1009
@Allowed: (Full) (S-1-5-21-3507848658-395067767-2873291405-1009)
@Allowed: (Full) (S-1-5-21-3507848658-395067767-2873291405-1009)
@Allowed: (Full) (LocalSystem)
@Allowed: (Full) (LocalSystem)
@Allowed: (Full) (Administrators)
@Allowed: (Full) (Administrators)
@Allowed: (Read) (S-1-5-12)
@Allowed: (Read) (S-1-5-12)
@=""
[HKEY_USERS\S-1-5-21-3507848658-395067767-2873291405-1009\AppEvents\Schemes\Apps\Conf\Receive Request to Join\R*NULL*F*NULL*S*NULL*0*NULL*H]
@Security=(SE_DACL_PRESENT SE_SELF_RELATIVE (@Owner @Group @DACL)
@Owner=S-1-5-21-3507848658-395067767-2873291405-1009
@Allowed: (Full) (S-1-5-21-3507848658-395067767-2873291405-1009)
@Allowed: (Full) (S-1-5-21-3507848658-395067767-2873291405-1009)
@Allowed: (Full) (LocalSystem)
@Allowed: (Full) (LocalSystem)
@Allowed: (Full) (Administrators)
@Allowed: (Full) (Administrators)
@Allowed: (Read) (S-1-5-12)
@Allowed: (Read) (S-1-5-12)
@=""
[HKEY_USERS\S-1-5-21-3507848658-395067767-2873291405-1009\AppEvents\Schemes\Apps\Explorer\ActivatingDocument\n*NULL*o*NULL*s*NULL*0*NULL*H]
@Security=(SE_DACL_PRESENT SE_SELF_RELATIVE (@Owner @Group @DACL)
@Owner=S-1-5-21-3507848658-395067767-2873291405-1009
@Allowed: (Full) (S-1-5-21-3507848658-395067767-2873291405-1009)
@Allowed: (Full) (S-1-5-21-3507848658-395067767-2873291405-1009)
@Allowed: (Full) (LocalSystem)
@Allowed: (Full) (LocalSystem)
@Allowed: (Full) (Administrators)
@Allowed: (Full) (Administrators)
@Allowed: (Read) (S-1-5-12)
@Allowed: (Read) (S-1-5-12)
@=""
[HKEY_USERS\S-1-5-21-3507848658-395067767-2873291405-1009\AppEvents\Schemes\Apps\Explorer\ActivatingDocument\R*NULL*F*NULL*S*NULL*0*NULL*H]
@Security=(SE_DACL_PRESENT SE_SELF_RELATIVE (@Owner @Group @DACL)
@Owner=S-1-5-21-3507848658-395067767-2873291405-1009
@Allowed: (Full) (S-1-5-21-3507848658-395067767-2873291405-1009)
@Allowed: (Full) (S-1-5-21-3507848658-395067767-2873291405-1009)
@Allowed: (Full) (LocalSystem)
@Allowed: (Full) (LocalSystem)
@Allowed: (Full) (Administrators)
@Allowed: (Full) (Administrators)
@Allowed: (Read) (S-1-5-12)
@Allowed: (Read) (S-1-5-12)
@=""
[HKEY_USERS\S-1-5-21-3507848658-395067767-2873291405-1009\AppEvents\Schemes\Apps\Explorer\BlockedPopup\n*NULL*o*NULL*s*NULL*0*NULL*H]
@Security=(SE_DACL_PRESENT SE_SELF_RELATIVE (@Owner @Group @DACL)
@Owner=S-1-5-21-3507848658-395067767-2873291405-1009
@Allowed: (Full) (S-1-5-21-3507848658-395067767-2873291405-1009)
@Allowed: (Full) (S-1-5-21-3507848658-395067767-2873291405-1009)
@Allowed: (Full) (LocalSystem)
@Allowed: (Full) (LocalSystem)
@Allowed: (Full) (Administrators)
@Allowed: (Full) (Administrators)
@Allowed: (Read) (S-1-5-12)
@Allowed: (Read) (S-1-5-12)
@=""
[HKEY_USERS\S-1-5-21-3507848658-395067767-2873291405-1009\AppEvents\Schemes\Apps\Explorer\BlockedPopup\R*NULL*F*NULL*S*NULL*0*NULL*H]
@Security=(SE_DACL_PRESENT SE_SELF_RELATIVE (@Owner @Group @DACL)
@Owner=S-1-5-21-3507848658-395067767-2873291405-1009
@Allowed: (Full) (S-1-5-21-3507848658-395067767-2873291405-1009)
@Allowed: (Full) (S-1-5-21-3507848658-395067767-2873291405-1009)
@Allowed: (Full) (LocalSystem)
@Allowed: (Full) (LocalSystem)
@Allowed: (Full) (Administrators)
@Allowed: (Full) (Administrators)
@Allowed: (Read) (S-1-5-12)
@Allowed: (Read) (S-1-5-12)
@=""
[HKEY_USERS\S-1-5-21-3507848658-395067767-2873291405-1009\AppEvents\Schemes\Apps\Explorer\EmptyRecycleBin\n*NULL*o*NULL*s*NULL*0*NULL*H]
@Security=(SE_DACL_PRESENT SE_SELF_RELATIVE (@Owner @Group @DACL)
@Owner=S-1-5-21-3507848658-395067767-2873291405-1009
@Allowed: (Full) (S-1-5-21-3507848658-395067767-2873291405-1009)
@Allowed: (Full) (S-1-5-21-3507848658-395067767-2873291405-1009)
@Allowed: (Full) (LocalSystem)
@Allowed: (Full) (LocalSystem)
@Allowed: (Full) (Administrators)
@Allowed: (Full) (Administrators)
@Allowed: (Read) (S-1-5-12)
@Allowed: (Read) (S-1-5-12)
@=expand:"%SystemRoot%\\media\\Windows XP Recycle.wav"
[HKEY_USERS\S-1-5-21-3507848658-395067767-2873291405-1009\AppEvents\Schemes\Apps\Explorer\EmptyRecycleBin\R*NULL*F*NULL*S*NULL*0*NULL*H]
@Security=(SE_DACL_PRESENT SE_SELF_RELATIVE (@Owner @Group @DACL)
@Owner=S-1-5-21-3507848658-395067767-2873291405-1009
@Allowed: (Full) (S-1-5-21-3507848658-395067767-2873291405-1009)
@Allowed: (Full) (S-1-5-21-3507848658-395067767-2873291405-1009)
@Allowed: (Full) (LocalSystem)
@Allowed: (Full) (LocalSystem)
@Allowed: (Full) (Administrators)
@Allowed: (Full) (Administrators)
@Allowed: (Read) (S-1-5-12)
@Allowed: (Read) (S-1-5-12)
@=""
[HKEY_USERS\S-1-5-21-3507848658-395067767-2873291405-1009\AppEvents\Schemes\Apps\Explorer\FaxError\n*NULL*o*NULL*s*NULL*0*NULL*H]
@Security=(SE_DACL_PRESENT SE_SELF_RELATIVE (@Owner @Group @DACL)
@Owner=S-1-5-21-3507848658-395067767-2873291405-1009
@Allowed: (Full) (S-1-5-21-3507848658-395067767-2873291405-1009)
@Allowed: (Full) (S-1-5-21-3507848658-395067767-2873291405-1009)
@Allowed: (Full) (LocalSystem)
@Allowed: (Full) (LocalSystem)
@Allowed: (Full) (Administrators)
@Allowed: (Full) (Administrators)
@Allowed: (Read) (S-1-5-12)
@Allowed: (Read) (S-1-5-12)
@=""
[HKEY_USERS\S-1-5-21-3507848658-395067767-2873291405-1009\AppEvents\Schemes\Apps\Explorer\FaxError\R*NULL*F*NULL*S*NULL*0*NULL*H]
@Security=(SE_DACL_PRESENT SE_SELF_RELATIVE (@Owner @Group @DACL)
@Owner=S-1-5-21-3507848658-395067767-2873291405-1009
@Allowed: (Full) (S-1-5-21-3507848658-395067767-2873291405-1009)
@Allowed: (Full) (S-1-5-21-3507848658-395067767-2873291405-1009)
@Allowed: (Full) (LocalSystem)
@Allowed: (Full) (LocalSystem)
@Allowed: (Full) (Administrators)
@Allowed: (Full) (Administrators)
@Allowed: (Read) (S-1-5-12)
@Allowed: (Read) (S-1-5-12)
@=""
[HKEY_USERS\S-1-5-21-3507848658-395067767-2873291405-1009\AppEvents\Schemes\Apps\Explorer\FaxLineRings\n*NULL*o*NULL*s*NULL*0*NULL*H]
@Security=(SE_DACL_PRESENT SE_SELF_RELATIVE (@Owner @Group @DACL)
@Owner=S-1-5-21-3507848658-395067767-2873291405-1009
@Allowed: (Full) (S-1-5-21-3507848658-395067767-2873291405-1009)
@Allowed: (Full) (S-1-5-21-3507848658-395067767-2873291405-1009)
@Allowed: (Full) (LocalSystem)
@Allowed: (Full) (LocalSystem)
@Allowed: (Full) (Administrators)
@Allowed: (Full) (Administrators)
@Allowed: (Read) (S-1-5-12)
@Allowed: (Read) (S-1-5-12)
@=""
[HKEY_USERS\S-1-5-21-3507848658-395067767-2873291405-1009\AppEvents\Schemes\Apps\Explorer\FaxLineRings\R*NULL*F*NULL*S*NULL*0*NULL*H]
@Security=(SE_DACL_PRESENT SE_SELF_RELATIVE (@Owner @Group @DACL)
@Owner=S-1-5-21-3507848658-395067767-2873291405-1009
@Allowed: (Full) (S-1-5-21-3507848658-395067767-2873291405-1009)
@Allowed: (Full) (S-1-5-21-3507848658-395067767-2873291405-1009)
@Allowed: (Full) (LocalSystem)
@Allowed: (Full) (LocalSystem)
@Allowed: (Full) (Administrators)
@Allowed: (Full) (Administrators)
@Allowed: (Read) (S-1-5-12)
@Allowed: (Read) (S-1-5-12)
@=""
[HKEY_USERS\S-1-5-21-3507848658-395067767-2873291405-1009\AppEvents\Schemes\Apps\Explorer\FaxNew\n*NULL*o*NULL*s*NULL*0*NULL*H]
@Security=(SE_DACL_PRESENT SE_SELF_RELATIVE (@Owner @Group @DACL)
@Owner=S-1-5-21-3507848658-395067767-2873291405-1009
@Allowed: (Full) (S-1-5-21-3507848658-395067767-2873291405-1009)
@Allowed: (Full) (S-1-5-21-3507848658-395067767-2873291405-1009)
@Allowed: (Full) (LocalSystem)
@Allowed: (Full) (LocalSystem)
@Allowed: (Full) (Administrators)
@Allowed: (Full) (Administrators)
@Allowed: (Read) (S-1-5-12)
@Allowed: (Read) (S-1-5-12)
@=""
[HKEY_USERS\S-1-5-21-3507848658-395067767-2873291405-1009\AppEvents\Schemes\Apps\Explorer\FaxNew\R*NULL*F*NULL*S*NULL*0*NULL*H]
@Security=(SE_DACL_PRESENT SE_SELF_RELATIVE (@Owner @Group @DACL)
@Owner=S-1-5-21-3507848658-395067767-2873291405-1009
@Allowed: (Full) (S-1-5-21-3507848658-395067767-2873291405-1009)
@Allowed: (Full) (S-1-5-21-3507848658-395067767-2873291405-1009)
@Allowed: (Full) (LocalSystem)
@Allowed: (Full) (LocalSystem)
@Allowed: (Full) (Administrators)
@Allowed: (Full) (Administrators)
@Allowed: (Read) (S-1-5-12)
@Allowed: (Read) (S-1-5-12)
@=""
[HKEY_USERS\S-1-5-21-3507848658-395067767-2873291405-1009\AppEvents\Schemes\Apps\Explorer\FaxSent\n*NULL*o*NULL*s*NULL*0*NULL*H]
@Security=(SE_DACL_PRESENT SE_SELF_RELATIVE (@Owner @Group @DACL)
@Owner=S-1-5-21-3507848658-395067767-2873291405-1009
@Allowed: (Full) (S-1-5-21-3507848658-395067767-2873291405-1009)
@Allowed: (Full) (S-1-5-21-3507848658-395067767-2873291405-1009)
@Allowed: (Full) (LocalSystem)
@Allowed: (Full) (LocalSystem)
@Allowed: (Full) (Administrators)
@Allowed: (Full) (Administrators)
@Allowed: (Read) (S-1-5-12)
@Allowed: (Read) (S-1-5-12)
@=""
[HKEY_USERS\S-1-5-21-3507848658-395067767-2873291405-1009\AppEvents\Schemes\Apps\Explorer\FaxSent\R*NULL*F*NULL*S*NULL*0*NULL*H]
@Security=(SE_DACL_PRESENT SE_SELF_RELATIVE (@Owner @Group @DACL)
@Owner=S-1-5-21-3507848658-395067767-2873291405-1009
@Allowed: (Full) (S-1-5-21-3507848658-395067767-2873291405-1009)
@Allowed: (Full) (S-1-5-21-3507848658-395067767-2873291405-1009)
@Allowed: (Full) (LocalSystem)
@Allowed: (Full) (LocalSystem)
@Allowed: (Full) (Administrators)
@Allowed: (Full) (Administrators)
@Allowed: (Read) (S-1-5-12)
@Allowed: (Read) (S-1-5-12)
@=""
[HKEY_USERS\S-1-5-21-3507848658-395067767-2873291405-1009\AppEvents\Schemes\Apps\Explorer\MoveMenuItem\n*NULL*o*NULL*s*NULL*0*NULL*H]
@Security=(SE_DACL_PRESENT SE_SELF_RELATIVE (@Owner @Group @DACL)
@Owner=S-1-5-21-3507848658-395067767-2873291405-1009
@Allowed: (Full) (S-1-5-21-3507848658-395067767-2873291405-1009)
@Allowed: (Full) (S-1-5-21-3507848658-395067767-2873291405-1009)
@Allowed: (Full) (LocalSystem)
@Allowed: (Full) (LocalSystem)
@Allowed: (Full) (Administrators)
@Allowed: (Full) (Administrators)
@Allowed: (Read) (S-1-5-12)
@Allowed: (Read) (S-1-5-12)
@=""
[HKEY_USERS\S-1-5-21-3507848658-395067767-2873291405-1009\AppEvents\Schemes\Apps\Explorer\MoveMenuItem\R*NULL*F*NULL*S*NULL*0*NULL*H]
@Security=(SE_DACL_PRESENT SE_SELF_RELATIVE (@Owner @Group @DACL)
@Owner=S-1-5-21-3507848658-395067767-2873291405-1009
@Allowed: (Full) (S-1-5-21-3507848658-395067767-2873291405-1009)
@Allowed: (Full) (S-1-5-21-3507848658-395067767-2873291405-1009)
@Allowed: (Full) (LocalSystem)
@Allowed: (Full) (LocalSystem)
@Allowed: (Full) (Administrators)
@Allowed: (Full) (Administrators)
@Allowed: (Read) (S-1-5-12)
@Allowed: (Read) (S-1-5-12)
@=""
[HKEY_USERS\S-1-5-21-3507848658-395067767-2873291405-1009\AppEvents\Schemes\Apps\Explorer\Navigating\n*NULL*o*NULL*s*NULL*0*NULL*H]
@Security=(SE_DACL_PRESENT SE_SELF_RELATIVE (@Owner @Group @DACL)
@Owner=S-1-5-21-3507848658-395067767-2873291405-1009
@Allowed: (Full) (S-1-5-21-3507848658-395067767-2873291405-1009)
@Allowed: (Full) (S-1-5-21-3507848658-395067767-2873291405-1009)
@Allowed: (Full) (LocalSystem)
@Allowed: (Full) (LocalSystem)
@Allowed: (Full) (Administrators)
@Allowed: (Full) (Administrators)
@Allowed: (Read) (S-1-5-12)
@Allowed: (Read) (S-1-5-12)
@=expand:"%SystemRoot%\\media\\Windows XP Start.wav"
[HKEY_USERS\S-1-5-21-3507848658-395067767-2873291405-1009\AppEvents\Schemes\Apps\Explorer\Navigating\R*NULL*F*NULL*S*NULL*0*NULL*H]
@Security=(SE_DACL_PRESENT SE_SELF_RELATIVE (@Owner @Group @DACL)
@Owner=S-1-5-21-3507848658-395067767-2873291405-1009
@Allowed: (Full) (S-1-5-21-3507848658-395067767-2873291405-1009)
@Allowed: (Full) (S-1-5-21-3507848658-395067767-2873291405-1009)
@Allowed: (Full) (LocalSystem)
@Allowed: (Full) (LocalSystem)
@Allowed: (Full) (Administrators)
@Allowed: (Full) (Administrators)
@Allowed: (Read) (S-1-5-12)
@Allowed: (Read) (S-1-5-12)
@=""
[HKEY_USERS\S-1-5-21-3507848658-395067767-2873291405-1009\AppEvents\Schemes\Apps\Explorer\SecurityBand\n*NULL*o*NULL*s*NULL*0*NULL*H]
@Security=(SE_DACL_PRESENT SE_SELF_RELATIVE (@Owner @Group @DACL)
@Owner=S-1-5-21-3507848658-395067767-2873291405-1009
@Allowed: (Full) (S-1-5-21-3507848658-395067767-2873291405-1009)
@Allowed: (Full) (S-1-5-21-3507848658-395067767-2873291405-1009)
@Allowed: (Full) (LocalSystem)
@Allowed: (Full) (LocalSystem)
@Allowed: (Full) (Administrators)
@Allowed: (Full) (Administrators)
@Allowed: (Read) (S-1-5-12)
@Allowed: (Read) (S-1-5-12)
@=""
[HKEY_USERS\S-1-5-21-3507848658-395067767-2873291405-1009\AppEvents\Schemes\Apps\Explorer\SecurityBand\R*NULL*F*NULL*S*NULL*0*NULL*H]
@Security=(SE_DACL_PRESENT SE_SELF_RELATIVE (@Owner @Group @DACL)
@Owner=S-1-5-21-3507848658-395067767-2873291405-1009
@Allowed: (Full) (S-1-5-21-3507848658-395067767-2873291405-1009)
@Allowed: (Full) (S-1-5-21-3507848658-395067767-2873291405-1009)
@Allowed: (Full) (LocalSystem)
@Allowed: (Full) (LocalSystem)
@Allowed: (Full) (Administrators)
@Allowed: (Full) (Administrators)
@Allowed: (Read) (S-1-5-12)
@Allowed: (Read) (S-1-5-12)
@=""
[HKEY_USERS\S-1-5-21-3507848658-395067767-2873291405-1009\AppEvents\Schemes\Apps\MSMSGS\MSMSGS_ContactOnline\n*NULL*o*NULL*s*NULL*0*NULL*H]
@Security=(SE_DACL_PRESENT SE_SELF_RELATIVE (@Owner @Group @DACL)
@Owner=S-1-5-21-3507848658-395067767-2873291405-1009
@Allowed: (Full) (S-1-5-21-3507848658-395067767-2873291405-1009)
@Allowed: (Full) (S-1-5-21-3507848658-395067767-2873291405-1009)
@Allowed: (Full) (LocalSystem)
@Allowed: (Full) (LocalSystem)
@Allowed: (Full) (Administrators)
@Allowed: (Full) (Administrators)
@Allowed: (Read) (S-1-5-12)
@Allowed: (Read) (S-1-5-12)
@=""
[HKEY_USERS\S-1-5-21-3507848658-395067767-2873291405-1009\AppEvents\Schemes\Apps\MSMSGS\MSMSGS_ContactOnline\R*NULL*F*NULL*S*NULL*0*NULL*H]
@Security=(SE_DACL_PRESENT SE_SELF_RELATIVE (@Owner @Group @DACL)
@Owner=S-1-5-21-3507848658-395067767-2873291405-1009
@Allowed: (Full) (S-1-5-21-3507848658-395067767-2873291405-1009)
@Allowed: (Full) (S-1-5-21-3507848658-395067767-2873291405-1009)
@Allowed: (Full) (LocalSystem)
@Allowed: (Full) (LocalSystem)
@Allowed: (Full) (Administrators)
@Allowed: (Full) (Administrators)
@Allowed: (Read) (S-1-5-12)
@Allowed: (Read) (S-1-5-12)
@=""
[HKEY_USERS\S-1-5-21-3507848658-395067767-2873291405-1009\AppEvents\Schemes\Apps\MSMSGS\MSMSGS_NewAlert\n*NULL*o*NULL*s*NULL*0*NULL*H]
@Security=(SE_DACL_PRESENT SE_SELF_RELATIVE (@Owner @Group @DACL)
@Owner=S-1-5-21-3507848658-395067767-2873291405-1009
@Allowed: (Full) (S-1-5-21-3507848658-395067767-2873291405-1009)
@Allowed: (Full) (S-1-5-21-3507848658-395067767-2873291405-1009)
@Allowed: (Full) (LocalSystem)
@Allowed: (Full) (LocalSystem)
@Allowed: (Full) (Administrators)
@Allowed: (Full) (Administrators)
@Allowed: (Read) (S-1-5-12)
@Allowed: (Read) (S-1-5-12)
@=""
[HKEY_USERS\S-1-5-21-3507848658-395067767-2873291405-1009\AppEvents\Schemes\Apps\MSMSGS\MSMSGS_NewAlert\R*NULL*F*NULL*S*NULL*0*NULL*H]
@Security=(SE_DACL_PRESENT SE_SELF_RELATIVE (@Owner @Group @DACL)
@Owner=S-1-5-21-3507848658-395067767-2873291405-1009
@Allowed: (Full) (S-1-5-21-3507848658-395067767-2873291405-1009)
@Allowed: (Full) (S-1-5-21-3507848658-395067767-2873291405-1009)
@Allowed: (Full) (LocalSystem)
@Allowed: (Full) (LocalSystem)
@Allowed: (Full) (Administrators)
@Allowed: (Full) (Administrators)
@Allowed: (Read) (S-1-5-12)
@Allowed: (Read) (S-1-5-12)
@=""
[HKEY_USERS\S-1-5-21-3507848658-395067767-2873291405-1009\AppEvents\Schemes\Apps\MSMSGS\MSMSGS_NewMail\n*NULL*o*NULL*s*NULL*0*NULL*H]
@Security=(SE_DACL_PRESENT SE_SELF_RELATIVE (@Owner @Group @DACL)
@Owner=S-1-5-21-3507848658-395067767-2873291405-1009
@Allowed: (Full) (S-1-5-21-3507848658-395067767-2873291405-1009)
@Allowed: (Full) (S-1-5-21-3507848658-395067767-2873291405-1009)
@Allowed: (Full) (LocalSystem)
@Allowed: (Full) (LocalSystem)
@Allowed: (Full) (Administrators)
@Allowed: (Full) (Administrators)
@Allowed: (Read) (S-1-5-12)
@Allowed: (Read) (S-1-5-12)
@=""
[HKEY_USERS\S-1-5-21-3507848658-395067767-2873291405-1009\AppEvents\Schemes\Apps\MSMSGS\MSMSGS_NewMail\R*NULL*F*NULL*S*NULL*0*NULL*H]
@Security=(SE_DACL_PRESENT SE_SELF_RELATIVE (@Owner @Group @DACL)
@Owner=S-1-5-21-3507848658-395067767-2873291405-1009
@Allowed: (Full) (S-1-5-21-3507848658-395067767-2873291405-1009)
@Allowed: (Full) (S-1-5-21-3507848658-395067767-2873291405-1009)
@Allowed: (Full) (LocalSystem)
@Allowed: (Full) (LocalSystem)
@Allowed: (Full) (Administrators)
@Allowed: (Full) (Administrators)
@Allowed: (Read) (S-1-5-12)
@Allowed: (Read) (S-1-5-12)
@=""
[HKEY_USERS\S-1-5-21-3507848658-395067767-2873291405-1009\AppEvents\Schemes\Apps\MSMSGS\MSMSGS_NewMessage\n*NULL*o*NULL*s*NULL*0*NULL*H]
@Security=(SE_DACL_PRESENT SE_SELF_RELATIVE (@Owner @Group @DACL)
@Owner=S-1-5-21-3507848658-395067767-2873291405-1009
@Allowed: (Full) (S-1-5-21-3507848658-395067767-2873291405-1009)
@Allowed: (Full) (S-1-5-21-3507848658-395067767-2873291405-1009)
@Allowed: (Full) (LocalSystem)
@Allowed: (Full) (LocalSystem)
@Allowed: (Full) (Administrators)
@Allowed: (Full) (Administrators)
@Allowed: (Read) (S-1-5-12)
@Allowed: (Read) (S-1-5-12)
@=""
[HKEY_USERS\S-1-5-21-3507848658-395067767-2873291405-1009\AppEvents\Schemes\Apps\MSMSGS\MSMSGS_NewMessage\R*NULL*F*NULL*S*NULL*0*NULL*H]
@Security=(SE_DACL_PRESENT SE_SELF_RELATIVE (@Owner @Group @DACL)
@Owner=S-1-5-21-3507848658-395067767-2873291405-1009
@Allowed: (Full) (S-1-5-21-3507848658-395067767-2873291405-1009)
@Allowed: (Full) (S-1-5-21-3507848658-395067767-2873291405-1009)
@Allowed: (Full) (LocalSystem)
@Allowed: (Full) (LocalSystem)
@Allowed: (Full) (Administrators)
@Allowed: (Full) (Administrators)
@Allowed: (Read) (S-1-5-12)
@Allowed: (Read) (S-1-5-12)
@=""
[HKEY_USERS\S-1-5-21-3507848658-395067767-2873291405-1009\AppEvents\Schemes\Apps\WksCalendar\Banner\n*NULL*o*NULL*s*NULL*0*NULL*H]
@Security=(SE_DACL_PRESENT SE_SELF_RELATIVE (@Owner @Group @DACL)
@Owner=S-1-5-21-3507848658-395067767-2873291405-1009
@Allowed: (Full) (S-1-5-21-3507848658-395067767-2873291405-1009)
@Allowed: (Full) (S-1-5-21-3507848658-395067767-2873291405-1009)
@Allowed: (Full) (LocalSystem)
@Allowed: (Full) (LocalSystem)
@Allowed: (Full) (Administrators)
@Allowed: (Full) (Administrators)
@Allowed: (Read) (S-1-5-12)
@Allowed: (Read) (S-1-5-12)
@=""
[HKEY_USERS\S-1-5-21-3507848658-395067767-2873291405-1009\AppEvents\Schemes\Apps\WksCalendar\Banner\R*NULL*F*NULL*S*NULL*0*NULL*H]
@Security=(SE_DACL_PRESENT SE_SELF_RELATIVE (@Owner @Group @DACL)
@Owner=S-1-5-21-3507848658-395067767-2873291405-1009
@Allowed: (Full) (S-1-5-21-3507848658-395067767-2873291405-1009)
@Allowed: (Full) (S-1-5-21-3507848658-395067767-2873291405-1009)
@Allowed: (Full) (LocalSystem)
@Allowed: (Full) (LocalSystem)
@Allowed: (Full) (Administrators)
@Allowed: (Full) (Administrators)
@Allowed: (Read) (S-1-5-12)
@Allowed: (Read) (S-1-5-12)
@=""
[HKEY_USERS\S-1-5-21-3507848658-395067767-2873291405-1009\AppEvents\Schemes\Apps\WksCalendar\DragDrop\n*NULL*o*NULL*s*NULL*0*NULL*H]
@Security=(SE_DACL_PRESENT SE_SELF_RELATIVE (@Owner @Group @DACL)
@Owner=S-1-5-21-3507848658-395067767-2873291405-1009
@Allowed: (Full) (S-1-5-21-3507848658-395067767-2873291405-1009)
@Allowed: (Full) (S-1-5-21-3507848658-395067767-2873291405-1009)
@Allowed: (Full) (LocalSystem)
@Allowed: (Full) (LocalSystem)
@Allowed: (Full) (Administrators)
@Allowed: (Full) (Administrators)
@Allowed: (Read) (S-1-5-12)
@Allowed: (Read) (S-1-5-12)
@=""
[HKEY_USERS\S-1-5-21-3507848658-395067767-2873291405-1009\AppEvents\Schemes\Apps\WksCalendar\DragDrop\R*NULL*F*NULL*S*NULL*0*NULL*H]
@Security=(SE_DACL_PRESENT SE_SELF_RELATIVE (@Owner @Group @DACL)
@Owner=S-1-5-21-3507848658-395067767-2873291405-1009
@Allowed: (Full) (S-1-5-21-3507848658-395067767-2873291405-1009)
@Allowed: (Full) (S-1-5-21-3507848658-395067767-2873291405-1009)
@Allowed: (Full) (LocalSystem)
@Allowed: (Full) (LocalSystem)
@Allowed: (Full) (Administrators)
@Allowed: (Full) (Administrators)
@Allowed: (Read) (S-1-5-12)
@Allowed: (Read) (S-1-5-12)
@=""
[HKEY_USERS\S-1-5-21-3507848658-395067767-2873291405-1009\AppEvents\Schemes\Apps\WksCalendar\Popup\n*NULL*o*NULL*s*NULL*0*NULL*H]
@Security=(SE_DACL_PRESENT SE_SELF_RELATIVE (@Owner @Group @DACL)
@Owner=S-1-5-21-3507848658-395067767-2873291405-1009
@Allowed: (Full) (S-1-5-21-3507848658-395067767-2873291405-1009)
@Allowed: (Full) (S-1-5-21-3507848658-395067767-2873291405-1009)
@Allowed: (Full) (LocalSystem)
@Allowed: (Full) (LocalSystem)
@Allowed: (Full) (Administrators)
@Allowed: (Full) (Administrators)
@Allowed: (Read) (S-1-5-12)
@Allowed: (Read) (S-1-5-12)
@=""
[HKEY_USERS\S-1-5-21-3507848658-395067767-2873291405-1009\AppEvents\Schemes\Apps\WksCalendar\Popup\R*NULL*F*NULL*S*NULL*0*NULL*H]
@Security=(SE_DACL_PRESENT SE_SELF_RELATIVE (@Owner @Group @DACL)
@Owner=S-1-5-21-3507848658-395067767-2873291405-1009
@Allowed: (Full) (S-1-5-21-3507848658-395067767-2873291405-1009)
@Allowed: (Full) (S-1-5-21-3507848658-395067767-2873291405-1009)
@Allowed: (Full) (LocalSystem)
@Allowed: (Full) (LocalSystem)
@Allowed: (Full) (Administrators)
@Allowed: (Full) (Administrators)
@Allowed: (Read) (S-1-5-12)
@Allowed: (Read) (S-1-5-12)
@=""
[HKEY_USERS\S-1-5-21-3507848658-395067767-2873291405-1009\AppEvents\Schemes\Apps\WksCalendar\Reminder\n*NULL*o*NULL*s*NULL*0*NULL*H]
@Security=(SE_DACL_PRESENT SE_SELF_RELATIVE (@Owner @Group @DACL)
@Owner=S-1-5-21-3507848658-395067767-2873291405-1009
@Allowed: (Full) (S-1-5-21-3507848658-395067767-2873291405-1009)
@Allowed: (Full) (S-1-5-21-3507848658-395067767-2873291405-1009)
@Allowed: (Full) (LocalSystem)
@Allowed: (Full) (LocalSystem)
@Allowed: (Full) (Administrators)
@Allowed: (Full) (Administrators)
@Allowed: (Read) (S-1-5-12)
@Allowed: (Read) (S-1-5-12)
@=""
[HKEY_USERS\S-1-5-21-3507848658-395067767-2873291405-1009\AppEvents\Schemes\Apps\WksCalendar\Reminder\R*NULL*F*NULL*S*NULL*0*NULL*H]
@Security=(SE_DACL_PRESENT SE_SELF_RELATIVE (@Owner @Group @DACL)
@Owner=S-1-5-21-3507848658-395067767-2873291405-1009
@Allowed: (Full) (S-1-5-21-3507848658-395067767-2873291405-1009)
@Allowed: (Full) (S-1-5-21-3507848658-395067767-2873291405-1009)
@Allowed: (Full) (LocalSystem)
@Allowed: (Full) (LocalSystem)
@Allowed: (Full) (Administrators)
@Allowed: (Full) (Administrators)
@Allowed: (Read) (S-1-5-12)
@Allowed: (Read) (S-1-5-12)
@=""
[HKEY_USERS\S-1-5-21-3507848658-395067767-2873291405-1009\AppEvents\Schemes\Apps\WksCalendar\Selection\n*NULL*o*NULL*s*NULL*0*NULL*H]
@Security=(SE_DACL_PRESENT SE_SELF_RELATIVE (@Owner @Group @DACL)
@Owner=S-1-5-21-3507848658-395067767-2873291405-1009
@Allowed: (Full) (S-1-5-21-3507848658-395067767-2873291405-1009)
@Allowed: (Full) (S-1-5-21-3507848658-395067767-2873291405-1009)
@Allowed: (Full) (LocalSystem)
@Allowed: (Full) (LocalSystem)
@Allowed: (Full) (Administrators)
@Allowed: (Full) (Administrators)
@Allowed: (Read) (S-1-5-12)
@Allowed: (Read) (S-1-5-12)
@=""
[HKEY_USERS\S-1-5-21-3507848658-395067767-2873291405-1009\AppEvents\Schemes\Apps\WksCalendar\Selection\R*NULL*F*NULL*S*NULL*0*NULL*H]
@Security=(SE_DACL_PRESENT SE_SELF_RELATIVE (@Owner @Group @DACL)
@Owner=S-1-5-21-3507848658-395067767-2873291405-1009
@Allowed: (Full) (S-1-5-21-3507848658-395067767-2873291405-1009)
@Allowed: (Full) (S-1-5-21-3507848658-395067767-2873291405-1009)
@Allowed: (Full) (LocalSystem)
@Allowed: (Full) (LocalSystem)
@Allowed: (Full) (Administrators)
@Allowed: (Full) (Administrators)
@Allowed: (Read) (S-1-5-12)
@Allowed: (Read) (S-1-5-12)
@=""
[HKEY_USERS\S-1-5-21-3507848658-395067767-2873291405-1009\AppEvents\Schemes\Apps\WksLauncher\ListSelect\n*NULL*o*NULL*s*NULL*0*NULL*H]
@Security=(SE_DACL_PRESENT SE_SELF_RELATIVE (@Owner @Group @DACL)
@Owner=S-1-5-21-3507848658-395067767-2873291405-1009
@Allowed: (Full) (S-1-5-21-3507848658-395067767-2873291405-1009)
@Allowed: (Full) (S-1-5-21-3507848658-395067767-2873291405-1009)
@Allowed: (Full) (LocalSystem)
@Allowed: (Full) (LocalSystem)
@Allowed: (Full) (Administrators)
@Allowed: (Full) (Administrators)
@Allowed: (Read) (S-1-5-12)
@Allowed: (Read) (S-1-5-12)
@=""
[HKEY_USERS\S-1-5-21-3507848658-395067767-2873291405-1009\AppEvents\Schemes\Apps\WksLauncher\ListSelect\R*NULL*F*NULL*S*NULL*0*NULL*H]
@Security=(SE_DACL_PRESENT SE_SELF_RELATIVE (@Owner @Group @DACL)
@Owner=S-1-5-21-3507848658-395067767-2873291405-1009
@Allowed: (Full) (S-1-5-21-3507848658-395067767-2873291405-1009)
@Allowed: (Full) (S-1-5-21-3507848658-395067767-2873291405-1009)
@Allowed: (Full) (LocalSystem)
@Allowed: (Full) (LocalSystem)
@Allowed: (Full) (Administrators)
@Allowed: (Full) (Administrators)
@Allowed: (Read) (S-1-5-12)
@Allowed: (Read) (S-1-5-12)
@=""
[HKEY_USERS\S-1-5-21-3507848658-395067767-2873291405-1009\AppEvents\Schemes\Apps\WksLauncher\MSwitch\n*NULL*o*NULL*s*NULL*0*NULL*H]
@Security=(SE_DACL_PRESENT SE_SELF_RELATIVE (@Owner @Group @DACL)
@Owner=S-1-5-21-3507848658-395067767-2873291405-1009
@Allowed: (Full) (S-1-5-21-3507848658-395067767-2873291405-1009)
@Allowed: (Full) (S-1-5-21-3507848658-395067767-2873291405-1009)
@Allowed: (Full) (LocalSystem)
@Allowed: (Full) (LocalSystem)
@Allowed: (Full) (Administrators)
@Allowed: (Full) (Administrators)
@Allowed: (Read) (S-1-5-12)
@Allowed: (Read) (S-1-5-12)
@=""
[HKEY_USERS\S-1-5-21-3507848658-395067767-2873291405-1009\AppEvents\Schemes\Apps\WksLauncher\MSwitch\R*NULL*F*NULL*S*NULL*0*NULL*H]
@Security=(SE_DACL_PRESENT SE_SELF_RELATIVE (@Owner @Group @DACL)
@Owner=S-1-5-21-3507848658-395067767-2873291405-1009
@Allowed: (Full) (S-1-5-21-3507848658-395067767-2873291405-1009)
@Allowed: (Full) (S-1-5-21-3507848658-395067767-2873291405-1009)
@Allowed: (Full) (LocalSystem)
@Allowed: (Full) (LocalSystem)
@Allowed: (Full) (Administrators)
@Allowed: (Full) (Administrators)
@Allowed: (Read) (S-1-5-12)
@Allowed: (Read) (S-1-5-12)
@=""
[HKEY_USERS\S-1-5-21-3507848658-395067767-2873291405-1009\AppEvents\Schemes\Apps\WksLauncher\ViewSwitch\n*NULL*o*NULL*s*NULL*0*NULL*H]
@Security=(SE_DACL_PRESENT SE_SELF_RELATIVE (@Owner @Group @DACL)
@Owner=S-1-5-21-3507848658-395067767-2873291405-1009
@Allowed: (Full) (S-1-5-21-3507848658-395067767-2873291405-1009)
@Allowed: (Full) (S-1-5-21-3507848658-395067767-2873291405-1009)
@Allowed: (Full) (LocalSystem)
@Allowed: (Full) (LocalSystem)
@Allowed: (Full) (Administrators)
@Allowed: (Full) (Administrators)
@Allowed: (Read) (S-1-5-12)
@Allowed: (Read) (S-1-5-12)
@=""
[HKEY_USERS\S-1-5-21-3507848658-395067767-2873291405-1009\AppEvents\Schemes\Apps\WksLauncher\ViewSwitch\R*NULL*F*NULL*S*NULL*0*NULL*H]
@Security=(SE_DACL_PRESENT SE_SELF_RELATIVE (@Owner @Group @DACL)
@Owner=S-1-5-21-3507848658-395067767-2873291405-1009
@Allowed: (Full) (S-1-5-21-3507848658-395067767-2873291405-1009)
@Allowed: (Full) (S-1-5-21-3507848658-395067767-2873291405-1009)
@Allowed: (Full) (LocalSystem)
@Allowed: (Full) (LocalSystem)
@Allowed: (Full) (Administrators)
@Allowed: (Full) (Administrators)
@Allowed: (Read) (S-1-5-12)
@Allowed: (Read) (S-1-5-12)
@=""
[HKEY_USERS\S-1-5-21-3507848658-395067767-2873291405-1009\AppEvents\Schemes\Apps\WksScrapbook\SbChangeSb\n*NULL*o*NULL*s*NULL*0*NULL*H]
@Security=(SE_DACL_PRESENT SE_SELF_RELATIVE (@Owner @Group @DACL)
@Owner=S-1-5-21-3507848658-395067767-2873291405-1009
@Allowed: (Full) (S-1-5-21-3507848658-395067767-2873291405-1009)
@Allowed: (Full) (S-1-5-21-3507848658-395067767-2873291405-1009)
@Allowed: (Full) (LocalSystem)
@Allowed: (Full) (LocalSystem)
@Allowed: (Full) (Administrators)
@Allowed: (Full) (Administrators)
@Allowed: (Read) (S-1-5-12)
@Allowed: (Read) (S-1-5-12)
@=""
[HKEY_USERS\S-1-5-21-3507848658-395067767-2873291405-1009\AppEvents\Schemes\Apps\WksScrapbook\SbChangeSb\R*NULL*F*NULL*S*NULL*0*NULL*H]
@Security=(SE_DACL_PRESENT SE_SELF_RELATIVE (@Owner @Group @DACL)
@Owner=S-1-5-21-3507848658-395067767-2873291405-1009
@Allowed: (Full) (S-1-5-21-3507848658-395067767-2873291405-1009)
@Allowed: (Full) (S-1-5-21-3507848658-395067767-2873291405-1009)
@Allowed: (Full) (LocalSystem)
@Allowed: (Full) (LocalSystem)
@Allowed: (Full) (Administrators)
@Allowed: (Full) (Administrators)
@Allowed: (Read) (S-1-5-12)
@Allowed: (Read) (S-1-5-12)
@=""
[HKEY_USERS\S-1-5-21-3507848658-395067767-2873291405-1009\AppEvents\Schemes\Apps\WksScrapbook\SbCloseLmDrop\n*NULL*o*NULL*s*NULL*0*NULL*H]
@Security=(SE_DACL_PRESENT SE_SELF_RELATIVE (@Owner @Group @DACL)
@Owner=S-1-5-21-3507848658-395067767-2873291405-1009
@Allowed: (Full) (S-1-5-21-3507848658-395067767-2873291405-1009)
@Allowed: (Full) (S-1-5-21-3507848658-395067767-2873291405-1009)
@Allowed: (Full) (LocalSystem)
@Allowed: (Full) (LocalSystem)
@Allowed: (Full) (Administrators)
@Allowed: (Full) (Administrators)
@Allowed: (Read) (S-1-5-12)
@Allowed: (Read) (S-1-5-12)
@=""
[HKEY_USERS\S-1-5-21-3507848658-395067767-2873291405-1009\AppEvents\Schemes\Apps\WksScrapbook\SbCloseLmDrop\R*NULL*F*NULL*S*NULL*0*NULL*H]
@Security=(SE_DACL_PRESENT SE_SELF_RELATIVE (@Owner @Group @DACL)
@Owner=S-1-5-21-3507848658-395067767-2873291405-1009
@Allowed: (Full) (S-1-5-21-3507848658-395067767-2873291405-1009)
@Allowed: (Full) (S-1-5-21-3507848658-395067767-2873291405-1009)
@Allowed: (Full) (LocalSystem)
@Allowed: (Full) (LocalSystem)
@Allowed: (Full) (Administrators)
@Allowed: (Full) (Administrators)
@Allowed: (Read) (S-1-5-12)
@Allowed: (Read) (S-1-5-12)
@=""
[HKEY_USERS\S-1-5-21-3507848658-395067767-2873291405-1009\AppEvents\Schemes\Apps\WksScrapbook\SbDropItem\n*NULL*o*NULL*s*NULL*0*NULL*H]
@Security=(SE_DACL_PRESENT SE_SELF_RELATIVE (@Owner @Group @DACL)
@Owner=S-1-5-21-3507848658-395067767-2873291405-1009
@Allowed: (Full) (S-1-5-21-3507848658-395067767-2873291405-1009)
@Allowed: (Full) (S-1-5-21-3507848658-395067767-2873291405-1009)
@Allowed: (Full) (LocalSystem)
@Allowed: (Full) (LocalSystem)
@Allowed: (Full) (Administrators)
@Allowed: (Full) (Administrators)
@Allowed: (Read) (S-1-5-12)
@Allowed: (Read) (S-1-5-12)
@=""
[HKEY_USERS\S-1-5-21-3507848658-395067767-2873291405-1009\AppEvents\Schemes\Apps\WksScrapbook\SbDropItem\R*NULL*F*NULL*S*NULL*0*NULL*H]
@Security=(SE_DACL_PRESENT SE_SELF_RELATIVE (@Owner @Group @DACL)
@Owner=S-1-5-21-3507848658-395067767-2873291405-1009
@Allowed: (Full) (S-1-5-21-3507848658-395067767-2873291405-1009)
@Allowed: (Full) (S-1-5-21-3507848658-395067767-2873291405-1009)
@Allowed: (Full) (LocalSystem)
@Allowed: (Full) (LocalSystem)
@Allowed: (Full) (Administrators)
@Allowed: (Full) (Administrators)
@Allowed: (Read) (S-1-5-12)
@Allowed: (Read) (S-1-5-12)
@=""
[HKEY_USERS\S-1-5-21-3507848658-395067767-2873291405-1009\AppEvents\Schemes\Apps\WksScrapbook\SbItemSelect\n*NULL*o*NULL*s*NULL*0*NULL*H]
@Security=(SE_DACL_PRESENT SE_SELF_RELATIVE (@Owner @Group @DACL)
@Owner=S-1-5-21-3507848658-395067767-2873291405-1009
@Allowed: (Full) (S-1-5-21-3507848658-395067767-2873291405-1009)
@Allowed: (Full) (S-1-5-21-3507848658-395067767-2873291405-1009)
@Allowed: (Full) (LocalSystem)
@Allowed: (Full) (LocalSystem)
@Allowed: (Full) (Administrators)
@Allowed: (Full) (Administrators)
@Allowed: (Read) (S-1-5-12)
@Allowed: (Read) (S-1-5-12)
@=""
[HKEY_USERS\S-1-5-21-3507848658-395067767-2873291405-1009\AppEvents\Schemes\Apps\WksScrapbook\SbItemSelect\R*NULL*F*NULL*S*NULL*0*NULL*H]
@Security=(SE_DACL_PRESENT SE_SELF_RELATIVE (@Owner @Group @DACL)
@Owner=S-1-5-21-3507848658-395067767-2873291405-1009
@Allowed: (Full) (S-1-5-21-3507848658-395067767-2873291405-1009)
@Allowed: (Full) (S-1-5-21-3507848658-395067767-2873291405-1009)
@Allowed: (Full) (LocalSystem)
@Allowed: (Full) (LocalSystem)
@Allowed: (Full) (Administrators)
@Allowed: (Full) (Administrators)
@Allowed: (Read) (S-1-5-12)
@Allowed: (Read) (S-1-5-12)
@=""
[HKEY_USERS\S-1-5-21-3507848658-395067767-2873291405-1009\AppEvents\Schemes\Apps\WksScrapbook\SbMenuOpen\n*NULL*o*NULL*s*NULL*0*NULL*H]
@Security=(SE_DACL_PRESENT SE_SELF_RELATIVE (@Owner @Group @DACL)
@Owner=S-1-5-21-3507848658-395067767-2873291405-1009
@Allowed: (Full) (S-1-5-21-3507848658-395067767-2873291405-1009)
@Allowed: (Full) (S-1-5-21-3507848658-395067767-2873291405-1009)
@Allowed: (Full) (LocalSystem)
@Allowed: (Full) (LocalSystem)
@Allowed: (Full) (Administrators)
@Allowed: (Full) (Administrators)
@Allowed: (Read) (S-1-5-12)
@Allowed: (Read) (S-1-5-12)
@=""
[HKEY_USERS\S-1-5-21-3507848658-395067767-2873291405-1009\AppEvents\Schemes\Apps\WksScrapbook\SbMenuOpen\R*NULL*F*NULL*S*NULL*0*NULL*H]
@Security=(SE_DACL_PRESENT SE_SELF_RELATIVE (@Owner @Group @DACL)
@Owner=S-1-5-21-3507848658-395067767-2873291405-1009
@Allowed: (Full) (S-1-5-21-3507848658-395067767-2873291405-1009)
@Allowed: (Full) (S-1-5-21-3507848658-395067767-2873291405-1009)
@Allowed: (Full) (LocalSystem)
@Allowed: (Full) (LocalSystem)
@Allowed: (Full) (Administrators)
@Allowed: (Full) (Administrators)
@Allowed: (Read) (S-1-5-12)
@Allowed: (Read) (S-1-5-12)
@=""
[HKEY_USERS\S-1-5-21-3507848658-395067767-2873291405-1009\AppEvents\Schemes\Apps\WksScrapbook\SbNewMode\n*NULL*o*NULL*s*NULL*0*NULL*H]
@Security=(SE_DACL_PRESENT SE_SELF_RELATIVE (@Owner @Group @DACL)
@Owner=S-1-5-21-3507848658-395067767-2873291405-1009
@Allowed: (Full) (S-1-5-21-3507848658-395067767-2873291405-1009)
@Allowed: (Full) (S-1-5-21-3507848658-395067767-2873291405-1009)
@Allowed: (Full) (LocalSystem)
@Allowed: (Full) (LocalSystem)
@Allowed: (Full) (Administrators)
@Allowed: (Full) (Administrators)
@Allowed: (Read) (S-1-5-12)
@Allowed: (Read) (S-1-5-12)
@=""
[HKEY_USERS\S-1-5-21-3507848658-395067767-2873291405-1009\AppEvents\Schemes\Apps\WksScrapbook\SbNewMode\R*NULL*F*NULL*S*NULL*0*NULL*H]
@Security=(SE_DACL_PRESENT SE_SELF_RELATIVE (@Owner @Group @DACL)
@Owner=S-1-5-21-3507848658-395067767-2873291405-1009
@Allowed: (Full) (S-1-5-21-3507848658-395067767-2873291405-1009)
@Allowed: (Full) (S-1-5-21-3507848658-395067767-2873291405-1009)
@Allowed: (Full) (LocalSystem)
@Allowed: (Full) (LocalSystem)
@Allowed: (Full) (Administrators)
@Allowed: (Full) (Administrators)
@Allowed: (Read) (S-1-5-12)
@Allowed: (Read) (S-1-5-12)
@=""
[HKEY_USERS\S-1-5-21-3507848658-395067767-2873291405-1009\AppEvents\Schemes\Apps\WksScrapbook\SbOpenLmDrop\n*NULL*o*NULL*s*NULL*0*NULL*H]
@Security=(SE_DACL_PRESENT SE_SELF_RELATIVE (@Owner @Group @DACL)
@Owner=S-1-5-21-3507848658-395067767-2873291405-1009
@Allowed: (Full) (S-1-5-21-3507848658-395067767-2873291405-1009)
@Allowed: (Full) (S-1-5-21-3507848658-395067767-2873291405-1009)
@Allowed: (Full) (LocalSystem)
@Allowed: (Full) (LocalSystem)
@Allowed: (Full) (Administrators)
@Allowed: (Full) (Administrators)
@Allowed: (Read) (S-1-5-12)
@Allowed: (Read) (S-1-5-12)
@=""
[HKEY_USERS\S-1-5-21-3507848658-395067767-2873291405-1009\AppEvents\Schemes\Apps\WksScrapbook\SbOpenLmDrop\R*NULL*F*NULL*S*NULL*0*NULL*H]
@Security=(SE_DACL_PRESENT SE_SELF_RELATIVE (@Owner @Group @DACL)
@Owner=S-1-5-21-3507848658-395067767-2873291405-1009
@Allowed: (Full) (S-1-5-21-3507848658-395067767-2873291405-1009)
@Allowed: (Full) (S-1-5-21-3507848658-395067767-2873291405-1009)
@Allowed: (Full) (LocalSystem)
@Allowed: (Full) (LocalSystem)
@Allowed: (Full) (Administrators)
@Allowed: (Full) (Administrators)
@Allowed: (Read) (S-1-5-12)
@Allowed: (Read) (S-1-5-12)
@=""
[HKEY_USERS\S-1-5-21-3507848658-395067767-2873291405-1009\AppEvents\Schemes\Apps\WksScrapbook\SbSnapWidget\n*NULL*o*NULL*s*NULL*0*NULL*H]
@Security=(SE_DACL_PRESENT SE_SELF_RELATIVE (@Owner @Group @DACL)
@Owner=S-1-5-21-3507848658-395067767-2873291405-1009
@Allowed: (Full) (S-1-5-21-3507848658-395067767-2873291405-1009)
@Allowed: (Full) (S-1-5-21-3507848658-395067767-2873291405-1009)
@Allowed: (Full) (LocalSystem)
@Allowed: (Full) (LocalSystem)
@Allowed: (Full) (Administrators)
@Allowed: (Full) (Administrators)
@Allowed: (Read) (S-1-5-12)
@Allowed: (Read) (S-1-5-12)
@=""
[HKEY_USERS\S-1-5-21-3507848658-395067767-2873291405-1009\AppEvents\Schemes\Apps\WksScrapbook\SbSnapWidget\R*NULL*F*NULL*S*NULL*0*NULL*H]
@Security=(SE_DACL_PRESENT SE_SELF_RELATIVE (@Owner @Group @DACL)
@Owner=S-1-5-21-3507848658-395067767-2873291405-1009
@Allowed: (Full) (S-1-5-21-3507848658-395067767-2873291405-1009)
@Allowed: (Full) (S-1-5-21-3507848658-395067767-2873291405-1009)
@Allowed: (Full) (LocalSystem)
@Allowed: (Full) (LocalSystem)
@Allowed: (Full) (Administrators)
@Allowed: (Full) (Administrators)
@Allowed: (Read) (S-1-5-12)
@Allowed: (Read) (S-1-5-12)
@=""
[HKEY_USERS\S-1-5-21-3507848658-395067767-2873291405-1009\AppEvents\Schemes\Names\n*NULL*o*NULL*s*NULL*0*NULL*H]
@Security=(SE_DACL_PRESENT SE_SELF_RELATIVE (@Owner @Group @DACL)
@Owner=S-1-5-21-3507848658-395067767-2873291405-1009
@Allowed: (Full) (S-1-5-21-3507848658-395067767-2873291405-1009)
@Allowed: (Full) (S-1-5-21-3507848658-395067767-2873291405-1009)
@Allowed: (Full) (LocalSystem)
@Allowed: (Full) (LocalSystem)
@Allowed: (Full) (Administrators)
@Allowed: (Full) (Administrators)
@Allowed: (Read) (S-1-5-12)
@Allowed: (Read) (S-1-5-12)
@="nos"
[HKEY_USERS\S-1-5-21-3507848658-395067767-2873291405-1009\AppEvents\Schemes\Names\R*NULL*F*NULL*S*NULL*0*NULL*H]
@Security=(SE_DACL_PRESENT SE_SELF_RELATIVE (@Owner @Group @DACL)
@Owner=S-1-5-21-3507848658-395067767-2873291405-1009
@Allowed: (Full) (S-1-5-21-3507848658-395067767-2873291405-1009)
@Allowed: (Full) (S-1-5-21-3507848658-395067767-2873291405-1009)
@Allowed: (Full) (LocalSystem)
@Allowed: (Full) (LocalSystem)
@Allowed: (Full) (Administrators)
@Allowed: (Full) (Administrators)
@Allowed: (Read) (S-1-5-12)
@Allowed: (Read) (S-1-5-12)
@="RFS"
[HKEY_USERS\S-1-5-21-3507848658-395067767-2873291405-1009\Software\Microsoft\Windows\CurrentVersion\Explorer\MenuOrder\Start Menu2\Programs\’u*NULL*’*NULL*’b*NULL*’R*NULL*’`*NULL*[*NULL*]
@Security=(SE_DACL_PRESENT SE_SELF_RELATIVE (@Owner @Group @DACL)
@Owner=S-1-5-21-3507848658-395067767-2873291405-1009
@Allowed: (Full) (S-1-5-21-3507848658-395067767-2873291405-1009)
@Allowed: (Full) (S-1-5-21-3507848658-395067767-2873291405-1009)
@Allowed: (Full) (LocalSystem)
@Allowed: (Full) (LocalSystem)
@Allowed: (Full) (Administrators)
@Allowed: (Full) (Administrators)
@Allowed: (Read) (S-1-5-12)
@Allowed: (Read) (S-1-5-12)
"Order"=hex:08,00,00,00,02,00,00,00,7c,00,00,00,01,00,00,00,01,00,00,00,70,00,\
00,00,00,00,00,00,62,00,00,00,41,75,67,4d,02,00,00,00,01,00,00,00,50,00,31,\
00,00,00,00,00,95,39,38,a4,10,00,47,41,54,42,43,7e,31,00,2c,00,03,00,04,00,\
ef,be,95,39,38,a4,95,39,3a,a4,14,00,00,00,47,00,41,00,1c,20,c1,00,1c,20,54,\
00,1a,20,62,00,1a,20,63,00,00,00,16,00,0e,00,00,00,0a,00,ef,be,00,00,00,00,\
16,00,00,00,00,00,00,00,00,00
[HKEY_USERS\S-1-5-21-3507848658-395067767-2873291405-1009\Software\SecuROM\!CAUTION! NEVER A OR CHANGE ANY KEY*NULL*]
@Security="Inherited"
[HKEY_LOCAL_MACHINE\software\BROCCOLI\G*NULL*A*NULL*’f*NULL*’X*NULL*’N*NULL*’g*NULL*’b*NULL*’v*NULL*’A*NUL
L*’N*NULL*’Z*NULL*’T*NULL*’`*NULL*[*NULL*2*NULL*L*NULL*E*NULL*]
@Security="Inherited"
[HKEY_LOCAL_MACHINE\software\BROCCOLI\G*NULL*A*NULL*’f*NULL*’X*NULL*’N*NULL*’g*NULL*’b*NULL*’v*NULL*’A*NUL
L*’N*NULL*’Z*NULL*’T*NULL*’`*NULL*[*NULL*2*NULL*L*NULL*E*NULL*\1.00.000]
@Security="Inherited"
[HKEY_LOCAL_MACHINE\software\Classes\.APE)\?*NULL*?*NULL*?*NULL*?*NULL*?*NULL*?*NULL*?*NULL*?*NULL*?*NULL*?*NULL*?*NULL* *NULL*?*NULL*?*NULL*?*NULL*?*NULL*?*NULL*?*NULL*?*NULL*?*NULL* *NULL* ?*NULL*?*NULL*?*NULL*?*NULL* ]
@Security="Inherited"
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{1171A62F-05D2-11D1-83FC-00A0C9089C5A}]
@Owner=S-1-5-21-3507848658-395067767-2873291405-1009
@Denied: (A 2) (Everyone)
@Denied: (A 2) (S-1-5-7)
@="FlashProp Class"
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{1171A62F-05D2-11D1-83FC-00A0C9089C5A}\InprocServer32]
@Owner=S-1-5-21-3507848658-395067767-2873291405-1009
@="c:\\WINDOWS\\system32\\Macromed\\Flash\\Flash9.ocx"
"ThreadingModel"="Apartment"
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{1171A62F-05D2-11D1-83FC-00A0C9089C5A}\Programmable]
@Owner=S-1-5-21-3507848658-395067767-2873291405-1009
.
———————— Other Running Processes ————————
.
c:\program files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
c:\program files\Common Files\LightScribe\LSSrvc.exe
c:\program files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
c:\program files\Alcohol Soft\Alcohol 120\StarWind\StarWindServiceAE.exe
c:\windows\system32\ZuneBusEnum.exe
c:\program files\iPod\bin\iPodService.exe
c:\windows\system32\wscntfy.exe
.
**************************************************************************
.
Completion time: 2008-12-31 17:35:51 - machine was rebooted
ComboFix-quarantined-files.txt 2008-12-31 23:35:46
Pre-Run: 63,861,796,864 bytes free
Post-Run: 63,803,240,448 bytes free
2041 — E O F — 2008-12-22 17:08:31