cc_20150622_165343

download cc_20150622_165343

If you can't read please download the document

description

script registry

Transcript of cc_20150622_165343

Windows Registry Editor Version 5.00[HKEY_CLASSES_ROOT\.asr][HKEY_CLASSES_ROOT\.pmg][HKEY_CLASSES_ROOT\Adobe.SwitchBoard.server]@=""[HKEY_CLASSES_ROOT\Adobe.SwitchBoard.server\shell]@=""[HKEY_CLASSES_ROOT\AdobeAAMDetect.AdobeAAMDetect]@="A plugin to detect whether the Adobe Application Manager is installed on this machine."[HKEY_CLASSES_ROOT\AdobeAAMDetect.AdobeAAMDetect\CLSID]@="{e8c77137-e224-5791-b6e9-ff0305797a13}"[HKEY_CLASSES_ROOT\AdobeAAMDetect.AdobeAAMDetect\CurVer]@="AdobeAAMDetect.AdobeAAMDetect.1"[HKEY_CLASSES_ROOT\AdobeAAMDetect.AdobeAAMDetect.1]@="A plugin to detect whether the Adobe Application Manager is installed on this machine."[HKEY_CLASSES_ROOT\AdobeAAMDetect.AdobeAAMDetect.1\CLSID]@="{e8c77137-e224-5791-b6e9-ff0305797a13}"[HKEY_CLASSES_ROOT\BLPFILE][HKEY_CLASSES_ROOT\BLPFILE\shell][HKEY_CLASSES_ROOT\CIS.CisDebugInjector.1]@="CisDebugInjector Class"[HKEY_CLASSES_ROOT\CIS.CisDebugInjector.1\CLSID]@="{BBB01528-20FE-4bc2-9D26-C70E3ABB9CD1}"[HKEY_CLASSES_ROOT\IntellNoDisturb.CommonLogicManager]@="CommonLogicManager Class"[HKEY_CLASSES_ROOT\IntellNoDisturb.CommonLogicManager\CLSID]@="{6197B4BA-F6A9-4393-8CCF-1A129ADC6114}"[HKEY_CLASSES_ROOT\IntellNoDisturb.CommonLogicManager\CurVer]@="IntellNoDisturb.CommonLogicManager.1"[HKEY_CLASSES_ROOT\IntellNoDisturb.CommonLogicManager.1]@="CommonLogicManager Class"[HKEY_CLASSES_ROOT\IntellNoDisturb.CommonLogicManager.1\CLSID]@="{6197B4BA-F6A9-4393-8CCF-1A129ADC6114}"[HKEY_CLASSES_ROOT\CLSID\{7DC2B7AA-BCFD-44D2-BD58-E8BD0D2E3ACC}]@="WiDiExtensions Class"[HKEY_CLASSES_ROOT\CLSID\{7DC2B7AA-BCFD-44D2-BD58-E8BD0D2E3ACC}\InprocServer32]@="C:\\KMPlayer\\IntelWiDiExtensions.dll""ThreadingModel"="Both"[HKEY_CLASSES_ROOT\CLSID\{7DC2B7AA-BCFD-44D2-BD58-E8BD0D2E3ACC}\ProgID]@="IntelWiDiExtensions.WiDiExtensions.1"[HKEY_CLASSES_ROOT\CLSID\{7DC2B7AA-BCFD-44D2-BD58-E8BD0D2E3ACC}\Programmable][HKEY_CLASSES_ROOT\CLSID\{7DC2B7AA-BCFD-44D2-BD58-E8BD0D2E3ACC}\TypeLib]@="{6EFBBD3C-00B9-4362-B743-443C9203CB97}"[HKEY_CLASSES_ROOT\CLSID\{7DC2B7AA-BCFD-44D2-BD58-E8BD0D2E3ACC}\VersionIndependentProgID]@="IntelWiDiExtensions.WiDiExtensions"[HKEY_CLASSES_ROOT\Applications\KMPlayer.exe\shell\open][HKEY_CLASSES_ROOT\Applications\KMPlayer.exe\shell\open\command]@="\"C:\\KMPlayer\\KMPlayer.exe\" \"%1\""[HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Compatibility Assistant\Store]"C:\\KMPlayer\\KMPlayer.exe"=hex:53,41,43,50,01,00,00,00,00,00,00,00,07,00,\ 00,00,28,00,00,00,70,cc,9b,00,6f,43,9c,00,01,00,00,00,00,00,00,00,00,00,03,\ 06,71,22,00,00,97,5f,d8,91,c9,9e,ce,01,00,00,00,00,00,00,00,00,02,00,00,00,\ 28,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\ 00,00,00,38,b6,86,01,00,00,00,00,37,00,00,00,37,00,00,00[HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Compatibility Assistant\Store]"C:\\Program Files (x86)\\R-Undelete\\r-undelete.exe"=hex:53,41,43,50,01,00,\ 00,00,00,00,00,00,07,00,00,00,28,00,00,00,88,bc,01,00,73,d3,01,00,01,00,00,\ 00,00,00,00,00,00,00,03,06,71,22,00,00,97,5f,d8,91,c9,9e,ce,01,00,00,00,00,\ 00,00,00,00,02,00,00,00,28,00,00,00,00,00,00,00,00,00,00,40,00,00,00,00,00,\ 00,00,00,00,00,00,00,00,00,00,00,59,ca,09,00,00,00,00,00,03,00,00,00,03,00,\ 00,00[HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Compatibility Assistant\Store]"C:\\Program Files (x86)\\Soft Organizer\\SoftOrganizer.exe"=hex:53,41,43,50,\ 01,00,00,00,00,00,00,00,07,00,00,00,28,00,00,00,78,1a,28,00,35,d6,28,00,01,\ 00,00,00,00,00,00,00,00,00,03,06,71,22,00,00,97,5f,d8,91,c9,9e,ce,01,00,00,\ 00,00,00,00,00,00,02,00,00,00,28,00,00,00,00,00,00,00,00,00,00,40,04,00,00,\ 10,00,00,00,00,00,00,00,00,00,00,00,00,bc,7a,14,00,00,00,00,00,07,00,00,00,\ 07,00,00,00[HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Compatibility Assistant\Store]"C:\\Program Files (x86)\\R-Undelete\\RUndelete64.exe"=hex:53,41,43,50,01,00,\ 00,00,00,00,00,00,07,00,00,00,28,00,00,00,88,94,da,01,fb,5e,db,01,01,00,00,\ 00,00,00,00,00,00,00,03,06,73,22,00,00,b3,95,e7,cf,04,9f,ce,01,00,00,00,00,\ 00,00,00,00,05,00,00,00,10,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\ 00,00,00,02,00,00,00,28,00,00,00,00,00,00,00,00,00,00,40,00,00,00,00,00,00,\ 00,00,00,00,00,00,00,00,00,00,1d,d9,06,00,00,00,00,00,05,00,00,00,05,00,00,\ 00[HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Compatibility Assistant\Store]"C:\\Users\\office-0\\AppData\\Local\\Temp\\RarSFX0 - Copy\\Installer.exe"=hex:53,\ 41,43,50,01,00,00,00,00,00,00,00,07,00,00,00,28,00,00,00,50,aa,08,00,84,b1,\ 08,00,01,00,00,00,00,00,00,00,00,00,03,06,00,21,00,00,b3,95,e7,cf,04,9f,ce,\ 01,00,00,00,00,00,00,00,00,02,00,00,00,28,00,00,00,00,00,00,00,00,00,00,40,\ 00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,a6,d1,28,00,00,00,00,00,01,\ 00,00,00,01,00,00,00[HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Compatibility Assistant\Store]"C:\\Program Files\\AVAST Software\\Avast\\AvastUI.exe"=hex:53,41,43,50,01,\ 00,00,00,00,00,00,00,07,00,00,00,28,00,00,00,e8,28,54,00,78,69,54,00,01,00,\ 00,00,00,00,00,00,00,00,03,06,71,22,00,00,97,5f,d8,91,c9,9e,ce,01,00,00,00,\ 00,00,00,00,00[HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Compatibility Assistant\Store]"C:\\Program Files\\AVAST Software\\Avast\\setup\\instup.exe"=hex:53,41,43,\ 50,01,00,00,00,00,00,00,00,07,00,00,00,28,00,00,00,40,21,09,00,00,00,00,00,\ 03,00,00,00,00,00,00,00,00,00,03,06,00,21,00,00,97,5f,d8,91,c9,9e,ce,01,00,\ 00,00,00,00,00,00,00,05,00,00,00,10,00,00,00,00,00,00,00,00,00,00,00,00,00,\ 00,00,00,00,00,00,02,00,00,00,28,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\ 00,00,00,00,00,00,00,00,00,00,00,00,00,d8,10,00,00,00,00,00,00,03,00,00,00,\ 03,00,00,00[HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Compatibility Assistant\Store]"C:\\Users\\office-0\\Downloads\\Programs\\avg_free_stb_all_2015_ltst_180.exe"=hex:53,\ 41,43,50,01,00,00,00,00,00,00,00,07,00,00,00,28,00,00,00,48,90,4c,00,de,e1,\ 4c,00,01,00,00,00,00,00,00,00,00,00,03,06,00,21,00,00,97,5f,d8,91,c9,9e,ce,\ 01,00,00,00,00,00,00,00,00,02,00,00,00,28,00,00,00,00,00,00,00,00,00,00,40,\ 00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,35,1f,16,00,00,00,00,00,01,\ 00,00,00,01,00,00,00[HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Compatibility Assistant\Store]"C:\\Users\\office-0\\AppData\\Local\\Temp\\7zSC0FBBAC1\\avg.exe"=hex:53,41,\ 43,50,01,00,00,00,00,00,00,00,07,00,00,00,28,00,00,00,30,64,4d,00,3f,0a,4e,\ 00,01,00,00,00,00,00,00,00,00,00,03,06,71,20,00,00,97,5f,d8,91,c9,9e,ce,01,\ 00,00,00,00,00,00,00,00,05,00,00,00,10,00,00,00,00,00,00,00,00,00,00,00,00,\ 00,00,00,00,08,00,00,02,00,00,00,28,00,00,00,00,00,00,00,00,08,00,40,00,00,\ 20,00,00,00,00,00,00,00,20,00,00,00,00,00,7c,22,00,00,00,00,00,00,01,00,00,\ 00,01,00,00,00,01,00,00,00,04,00,00,00,01,00,00,00[HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Compatibility Assistant\Store]"C:\\Users\\office-0\\AppData\\Local\\Temp\\7zSC48C88E7 - Copy\\setup.exe"=hex:53,\ 41,43,50,01,00,00,00,00,00,00,00,07,00,00,00,28,00,00,00,d0,6f,05,00,8a,06,\ 06,00,01,00,00,00,00,00,00,00,00,00,03,06,71,22,00,00,97,5f,d8,91,c9,9e,ce,\ 01,00,00,00,00,00,00,00,00,05,00,00,00,10,00,00,00,00,00,00,00,00,00,00,00,\ 00,00,00,00,00,00,00,00,02,00,00,00,28,00,00,00,00,00,00,00,00,00,00,40,00,\ 00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,42,7f,00,00,00,00,00,00,01,00,\ 00,00,01,00,00,00[HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Compatibility Assistant\Store]"D:\\7zSC48C88E7 - Copy\\setup.exe"=hex:53,41,43,50,01,00,00,00,00,00,00,00,\ 07,00,00,00,28,00,00,00,d0,6f,05,00,8a,06,06,00,01,00,00,00,00,00,00,00,00,\ 00,03,06,71,22,00,00,97,5f,d8,91,c9,9e,ce,01,00,00,00,00,00,00,00,00,02,00,\ 00,00,28,00,00,00,00,00,00,00,00,00,00,40,00,00,00,00,00,00,00,00,00,00,00,\ 00,00,00,00,00,93,c5,03,00,00,00,00,00,02,00,00,00,02,00,00,00[HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Compatibility Assistant\Store]"C:\\7zSC48C88E7 - Copy\\setup.exe"=hex:53,41,43,50,01,00,00,00,00,00,00,00,\ 07,00,00,00,28,00,00,00,d0,6f,05,00,8a,06,06,00,01,00,00,00,00,00,00,00,00,\ 00,03,06,71,22,00,00,97,5f,d8,91,c9,9e,ce,01,00,00,00,00,00,00,00,00,02,00,\ 00,00,28,00,00,00,00,00,00,00,00,00,00,40,00,00,00,00,00,00,00,00,00,00,00,\ 00,00,00,00,00,cc,76,02,00,00,00,00,00,01,00,00,00,01,00,00,00[HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Compatibility Assistant\Store]"C:\\Program Files (x86)\\ArzooSoft Solutions\\USB Threat Defender\\utdefender.exe"=hex:53,\ 41,43,50,01,00,00,00,00,00,00,00,07,00,00,00,28,00,00,00,00,8c,12,00,5e,32,\ 13,00,01,00,00,00,00,00,00,00,00,00,00,06,71,20,00,00,97,5f,d8,91,c9,9e,ce,\ 01,00,00,00,00,00,00,00,00,02,00,00,00,28,00,00,00,00,00,00,00,00,00,00,00,\ 00,00,02,00,00,00,00,00,00,00,00,00,00,00,00,00,a0,dd,0d,00,00,00,00,00,01,\ 00,00,00,01,00,00,00[HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Compatibility Assistant\Store]"C:\\Program Files\\Sandboxie\\Start.exe"=hex:53,41,43,50,01,00,00,00,00,00,\ 00,00,07,00,00,00,28,00,00,00,88,1e,02,00,92,d1,02,00,01,00,00,00,00,00,00,\ 00,00,00,03,06,73,20,00,00,b3,95,e7,cf,04,9f,ce,01,00,00,00,00,00,00,00,00,\ 02,00,00,00,28,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\ 00,00,00,00,00,00,00,3a,47,00,00,00,00,00,00,01,00,00,00,01,00,00,00[HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Compatibility Assistant\Store]"C:\\Windows\\Installer\\SandboxieInstall64.exe"=hex:53,41,43,50,01,00,00,00,\ 00,00,00,00,07,00,00,00,28,00,00,00,b8,ad,38,00,1b,0c,39,00,03,00,00,00,00,\ 00,00,00,00,00,01,06,00,01,00,00,97,5f,d8,91,c9,9e,ce,01,00,00,00,00,00,00,\ 00,00,02,00,00,00,28,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\ 00,00,00,00,00,00,00,00,00,c0,5d,00,00,00,00,00,00,01,00,00,00,01,00,00,00[HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Compatibility Assistant\Store]"C:\\Program Files (x86)\\ArzooSoft Solutions\\USB Threat Defender\\unins000.exe"=hex:53,\ 41,43,50,01,00,00,00,00,00,00,00,07,00,00,00,28,00,00,00,1a,9d,0a,00,00,00,\ 00,00,03,00,00,00,00,00,00,00,00,00,03,06,41,22,00,00,97,5f,d8,91,c9,9e,ce,\ 01,00,00,00,00,00,00,00,00,02,00,00,00,28,00,00,00,00,00,00,00,00,00,00,00,\ 00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,fa,cb,00,00,00,00,00,00,01,\ 00,00,00,01,00,00,00[HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Compatibility Assistant\Store]"C:\\Program Files (x86)\\USB Disk Security\\unins000.exe"=hex:53,41,43,50,\ 01,00,00,00,00,00,00,00,07,00,00,00,28,00,00,00,c9,56,12,00,00,00,00,00,03,\ 00,00,00,00,00,00,00,00,00,03,06,00,21,00,00,97,5f,d8,91,c9,9e,ce,01,00,00,\ 00,00,00,00,00,00,02,00,00,00,28,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\ 00,00,00,00,00,00,00,00,00,00,00,00,00,ca,37,00,00,00,00,00,00,01,00,00,00,\ 01,00,00,00[HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Compatibility Assistant\Persisted]"C:\\Users\\office-0\\AppData\\Local\\Temp\\7zSC0FBBAC1\\avg.exe"=dword:00000001[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\HTML Help]"RUndelete.chm"="C:\\Program Files (x86)\\R-Undelete\\ja\\"[HKEY_CURRENT_USER\Software\LiveUpdate360][HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]"USB Threat Defender"="C:\\Program Files (x86)\\ArzooSoft Solutions\\USB Threat Defender\\utdefender.exe /b"[HKEY_CURRENT_USER\Software\Classes\Local Settings\Software\Microsoft\Windows\Shell\MuiCache]"C:\\KMPlayer\\KMPlayer.exe.FriendlyAppName"="The KMPlayer"[HKEY_CURRENT_USER\Software\Classes\Local Settings\Software\Microsoft\Windows\Shell\MuiCache]"C:\\KMPlayer\\KMPlayer.exe.ApplicationCompany"="PandoraTV"[HKEY_CURRENT_USER\Software\Classes\Local Settings\Software\Microsoft\Windows\Shell\MuiCache]"C:\\Program Files (x86)\\R-Undelete\\RUndelete64.exe.FriendlyAppName"="R-Undelete"[HKEY_CURRENT_USER\Software\Classes\Local Settings\Software\Microsoft\Windows\Shell\MuiCache]"C:\\Program Files (x86)\\R-Undelete\\RUndelete64.exe.ApplicationCompany"="R-Tools Technology Inc."[HKEY_CURRENT_USER\Software\Classes\Local Settings\Software\Microsoft\Windows\Shell\MuiCache]"C:\\Users\\office-0\\AppData\\Local\\Temp\\~nsu.tmp\\Au_.exe.FriendlyAppName"="360 Internet Security"[HKEY_CURRENT_USER\Software\Classes\Local Settings\Software\Microsoft\Windows\Shell\MuiCache]"C:\\Users\\office-0\\AppData\\Local\\Temp\\~nsu.tmp\\Au_.exe.ApplicationCompany"="Qihu 360 Software Co., Ltd."[HKEY_CURRENT_USER\Software\Classes\Local Settings\Software\Microsoft\Windows\Shell\MuiCache]"C:\\Program Files\\Bitdefender\\Antivirus Free Edition\\gziface.exe.FriendlyAppName"="Bitdefender Antivirus Free Edition"[HKEY_CURRENT_USER\Software\Classes\Local Settings\Software\Microsoft\Windows\Shell\MuiCache]"C:\\Program Files\\Bitdefender\\Antivirus Free Edition\\gziface.exe.ApplicationCompany"="Bitdefender"[HKEY_CURRENT_USER\Software\Classes\Local Settings\Software\Microsoft\Windows\Shell\MuiCache]"C:\\Program Files\\Sandboxie\\Start.exe.FriendlyAppName"="Sandboxie Start"[HKEY_CURRENT_USER\Software\Classes\Local Settings\Software\Microsoft\Windows\Shell\MuiCache]"C:\\Program Files\\Sandboxie\\Start.exe.ApplicationCompany"="Sandboxie Holdings, LLC"