YTDVideoDownloader_7a500c46d6

by malwarelabrobot on May 13th, 2014 in Malware Descriptions.

program.Win32.Alureon.FD, mzpefinder_pcap_file.YR (Lavasoft MAS)
Behaviour: PUP


The description has been automatically generated by Lavasoft Malware Analysis System and it may contain incomplete or inaccurate information.

Requires JavaScript enabled!

Summary
Dynamic Analysis
Static Analysis
Network Activity
Map
Strings from Dumps
Removals

MD5: 7a500c46d62f6f39e4bb2716a323bc34
SHA1: cf8def60e9fb0bfea31279286b425171fad8ae84
SHA256: 5ae70cb414bfde75c30df269d8ea3ff97e41f54475a7f014ae1bc87c1acb7ace
SSDeep: 196608:qJjPePN54ROHhwU1e6VZ6ls82/vd8Cz8nXaDGJJe2chXA0e/EI3547BgfWc:qJjPcN6RqKEDf6l92/vd8C8XhJJe2chw
Size: 11227192 bytes
File type: EXE
Platform: WIN32
Entropy: Packed
PEID: UPolyXv05_v6
Company: no certificate found
Created at: 2010-04-10 15:19:31
Analyzed on: WindowsAda SP3 32-bit


Summary:

PUP. Potentially Unwanted Program. An application that does not display malicious behavior yet is installed without having first sought affirmative user consent for installation. Users may not realize, due to the nature of the installation procedure, that an application they have not explicitly agreed to has been installed. This category can also be used to classify other applications which in a certain context can be wanted e.g. remote administration tools or IRC clients.

Payload

No specific payload has been found.

Process activity

The program creates the following process(es):

%original file name%.exe:2104
BrowserExtensionsSetup.exe:3144
install.exe:820
BackupSetup.exe:4068
msfeedssync.exe:3180
CouponsHelper.exe:3544
vcredist_x86.exe:348
MsiExec.exe:2516
taskkill.exe:3616
taskkill.exe:368
~sp2E.tmp:3176
BrowserExtensionsSetupUAC.exe:3536
SearchProtectionStub.exe:2548
IEXPLORE.EXE:2676
Cloud_Backup_Setup.exe:2332
exthelper.exe:1888

The program injects its code into the following process(es):

SearchProtection.EXE:3452
IEXPLORE.EXE:2880
MyPC Backup.exe:1212

File activity

The process %original file name%.exe:2104 makes changes in the file system.
The program creates and/or writes to the following file(s):

%Program Files%\GreenTree Applications\YTD Video Downloader\plugins\access\.svn\prop-base\libfilesystem_plugin.dll.svn-base (53 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nse28.tmp\eula.rtf (6629 bytes)
%Program Files%\GreenTree Applications\YTD Video Downloader\COPYING.Apachev2 (11 bytes)
%Program Files%\GreenTree Applications\YTD Video Downloader\plugins\access\.svn\entries (424 bytes)
%Program Files%\GreenTree Applications\YTD Video Downloader\plugins\audio_output\libdirectsound_plugin.dll (1552 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nse28.tmp\inst_finish (1 bytes)
%Program Files%\GreenTree Applications\YTD Video Downloader\plugins\video_output\.svn\text-base\libdirect3d_plugin.dll.svn-base (2392 bytes)
%Program Files%\GreenTree Applications\YTD Video Downloader\manual.bat (57 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nse28.tmp\MPB_EULA.txt (784 bytes)
%Program Files%\GreenTree Applications\YTD Video Downloader\plugins\audio_output\.svn\prop-base\libdirectsound_plugin.dll.svn-base (53 bytes)
%Program Files%\GreenTree Applications\YTD Video Downloader\plugins\video_output\.svn\prop-base\libdirect3d_plugin.dll.svn-base (53 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nse28.tmp\UserInfo.dll (4 bytes)
%Program Files%\GreenTree Applications\YTD Video Downloader\plugins\video_output\.svn\prop-base\libwingdi_plugin.dll.svn-base (53 bytes)
%Program Files%\GreenTree Applications\YTD Video Downloader\Lang\res1060.ini (13 bytes)
%Program Files%\GreenTree Applications\YTD Video Downloader\plugins\audio_output\.svn\all-wcprops (315 bytes)
%Program Files%\GreenTree Applications\YTD Video Downloader\ytd.exe (49631 bytes)
%Program Files%\GreenTree Applications\YTD Video Downloader\Lang\res1055.ini (14 bytes)
%Program Files%\GreenTree Applications\YTD Video Downloader\Lang\res1053.ini (13 bytes)
%Program Files%\GreenTree Applications\YTD Video Downloader\plugins\video_filter\libswscale_plugin.dll (19096 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nse28.tmp\System.dll (11 bytes)
%Program Files%\GreenTree Applications\YTD Video Downloader\Uninstall.exe (7446 bytes)
%Program Files%\GreenTree Applications\YTD Video Downloader\librtmp.dll (60186 bytes)
%Program Files%\GreenTree Applications\YTD Video Downloader\Lang\res1036.ini (14 bytes)
%Program Files%\GreenTree Applications\YTD Video Downloader\Lang\res1029.ini (13 bytes)
%Documents and Settings%\All Users\Start Menu\Programs\YTD Video Downloader\Uninstall.lnk (1 bytes)
%Program Files%\GreenTree Applications\YTD Video Downloader\plugins\audio_mixer\.svn\text-base\libfloat_mixer_plugin.dll.svn-base (1552 bytes)
%Program Files%\GreenTree Applications\YTD Video Downloader\plugins\audio_mixer\.svn\prop-base\libfloat_mixer_plugin.dll.svn-base (53 bytes)
%Documents and Settings%\All Users\Start Menu\Programs\YTD Video Downloader\Web site.url (55 bytes)
%Program Files%\GreenTree Applications\YTD Video Downloader\LICENSE (1 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nse28.tmp\pixel (1 bytes)
%Documents and Settings%\All Users\Start Menu\Programs\YTD Video Downloader\YTD Video Downloader.lnk (1 bytes)
%Program Files%\GreenTree Applications\YTD Video Downloader\Lang\res1033.ini (13 bytes)
%Program Files%\GreenTree Applications\YTD Video Downloader\Lang\res1051.ini (14 bytes)
%Program Files%\GreenTree Applications\YTD Video Downloader\Lang\res1026.ini (784 bytes)
%Program Files%\GreenTree Applications\YTD Video Downloader\scripts.yds (6360 bytes)
%Program Files%\GreenTree Applications\YTD Video Downloader\plugins\audio_filter\.svn\entries (797 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nso27.tmp (772223 bytes)
%Program Files%\GreenTree Applications\YTD Video Downloader\Lang\res1059.ini (784 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nse28.tmp\NSISHelper.dll (8560 bytes)
%Program Files%\GreenTree Applications\YTD Video Downloader\plugins\video_filter\.svn\entries (428 bytes)
%Program Files%\GreenTree Applications\YTD Video Downloader\plugins\audio_filter\.svn\all-wcprops (711 bytes)
%Program Files%\GreenTree Applications\YTD Video Downloader\Lang\res2052.ini (12 bytes)
%Program Files%\GreenTree Applications\YTD Video Downloader\plugins\audio_output\.svn\entries (431 bytes)
%Program Files%\GreenTree Applications\YTD Video Downloader\COPYING.LGPLv2 (784 bytes)
%Program Files%\GreenTree Applications\YTD Video Downloader\COPYING.LGPLv3 (7 bytes)
%Program Files%\GreenTree Applications\YTD Video Downloader\plugins\video_output\.svn\text-base\libwingdi_plugin.dll.svn-base (1856 bytes)
%Program Files%\GreenTree Applications\YTD Video Downloader\plugins\audio_filter\libugly_resampler_plugin.dll (1552 bytes)
%Program Files%\GreenTree Applications\YTD Video Downloader\Lang\res1049.ini (784 bytes)
%Program Files%\GreenTree Applications\YTD Video Downloader\plugins\video_output\.svn\entries (941 bytes)
%Program Files%\GreenTree Applications\YTD Video Downloader\Lang\res2070.ini (14 bytes)
%Program Files%\GreenTree Applications\YTD Video Downloader\Lang\res1035.ini (13 bytes)
%Program Files%\GreenTree Applications\YTD Video Downloader\Lang\res1040.ini (13 bytes)
%Program Files%\GreenTree Applications\YTD Video Downloader\plugins\video_filter\.svn\text-base\libswscale_plugin.dll.svn-base (19096 bytes)
%Program Files%\GreenTree Applications\YTD Video Downloader\plugins\video_output\libwingdi_plugin.dll (1856 bytes)
%Program Files%\GreenTree Applications\YTD Video Downloader\Lang\res1031.ini (14 bytes)
%Program Files%\GreenTree Applications\YTD Video Downloader\plugins\video_output\.svn\text-base\libdrawable_plugin.dll.svn-base (1552 bytes)
%Program Files%\GreenTree Applications\YTD Video Downloader\Lang\res1034.ini (14 bytes)
%Program Files%\GreenTree Applications\YTD Video Downloader\Lang\res1048.ini (14 bytes)
%Program Files%\GreenTree Applications\YTD Video Downloader\plugins\video_output\.svn\prop-base\libvmem_plugin.dll.svn-base (53 bytes)
%Program Files%\GreenTree Applications\YTD Video Downloader\plugins\audio_filter\.svn\prop-base\libtrivial_channel_mixer_plugin.dll.svn-base (53 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nse28.tmp\nsDialogs.dll (9 bytes)
%Program Files%\GreenTree Applications\YTD Video Downloader\plugins\audio_filter\.svn\prop-base\libaudio_format_plugin.dll.svn-base (53 bytes)
%Program Files%\GreenTree Applications\YTD Video Downloader\Lang\res2074.ini (13 bytes)
%Program Files%\GreenTree Applications\YTD Video Downloader\plugins\audio_filter\libtrivial_channel_mixer_plugin.dll (1552 bytes)
%Program Files%\GreenTree Applications\YTD Video Downloader\plugins\video_output\libdirect3d_plugin.dll (2392 bytes)
%Program Files%\GreenTree Applications\YTD Video Downloader\plugins\video_filter\.svn\prop-base\libswscale_plugin.dll.svn-base (53 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nse28.tmp\tb-header.bmp (3312 bytes)
%Program Files%\GreenTree Applications\YTD Video Downloader\Lang\res1044.ini (13 bytes)
%Program Files%\GreenTree Applications\YTD Video Downloader\plugins\codec\libavcodec_plugin.dll (326900 bytes)
%Program Files%\GreenTree Applications\YTD Video Downloader\plugins\access\.svn\text-base\libfilesystem_plugin.dll.svn-base (1552 bytes)
%Program Files%\GreenTree Applications\YTD Video Downloader\plugins\audio_filter\.svn\text-base\libugly_resampler_plugin.dll.svn-base (1552 bytes)
%Program Files%\GreenTree Applications\YTD Video Downloader\libvlc.dll (3616 bytes)
%Program Files%\GreenTree Applications\YTD Video Downloader\plugins\codec\.svn\all-wcprops (293 bytes)
%Program Files%\GreenTree Applications\YTD Video Downloader\plugins\access\libfilesystem_plugin.dll (1552 bytes)
%Program Files%\GreenTree Applications\YTD Video Downloader\Lang\res1025.ini (15 bytes)
%Program Files%\GreenTree Applications\YTD Video Downloader\plugins\video_output\.svn\text-base\libvmem_plugin.dll.svn-base (1552 bytes)
%Program Files%\GreenTree Applications\YTD Video Downloader\plugins\video_output\libvmem_plugin.dll (1552 bytes)
%Program Files%\GreenTree Applications\YTD Video Downloader\plugins\codec\.svn\entries (422 bytes)
%Program Files%\GreenTree Applications\YTD Video Downloader\plugins\audio_filter\libaudio_format_plugin.dll (1552 bytes)
%Program Files%\GreenTree Applications\YTD Video Downloader\Lang\res1030.ini (13 bytes)
%Program Files%\GreenTree Applications\YTD Video Downloader\Lang\res9999.ini (784 bytes)
%Program Files%\GreenTree Applications\YTD Video Downloader\plugins\video_output\.svn\all-wcprops (831 bytes)
%Program Files%\GreenTree Applications\YTD Video Downloader\plugins\access\.svn\all-wcprops (301 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nse28.tmp\modern-header.bmp (6624 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nse28.tmp\Cloud_Backup_Setup.exe (6360 bytes)
%Program Files%\GreenTree Applications\YTD Video Downloader\plugins\video_filter\.svn\all-wcprops (307 bytes)
%Program Files%\GreenTree Applications\YTD Video Downloader\plugins\audio_mixer\.svn\prop-base\libinteger_mixer_plugin.dll.svn-base (53 bytes)
%Program Files%\GreenTree Applications\YTD Video Downloader\Lang\res1061.ini (13 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nse28.tmp\SearchProtectionStub.exe (13368 bytes)
%Program Files%\GreenTree Applications\YTD Video Downloader\plugins\audio_mixer\libinteger_mixer_plugin.dll (1552 bytes)
%Program Files%\GreenTree Applications\YTD Video Downloader\libvlccore.dll (69435 bytes)
%Program Files%\GreenTree Applications\YTD Video Downloader\plugins\audio_filter\.svn\text-base\libtrivial_channel_mixer_plugin.dll.svn-base (1552 bytes)
%Program Files%\GreenTree Applications\YTD Video Downloader\Lang\res1032.ini (784 bytes)
%Documents and Settings%\All Users\Desktop\YTD Video Downloader.lnk (942 bytes)
%Program Files%\GreenTree Applications\YTD Video Downloader\FFMPEG.EXE (395158 bytes)
%Program Files%\GreenTree Applications\YTD Video Downloader\plugins\video_output\libdrawable_plugin.dll (1552 bytes)
%Program Files%\GreenTree Applications\YTD Video Downloader\Lang\res1052.ini (13 bytes)
%Program Files%\GreenTree Applications\YTD Video Downloader\Lang\res1045.ini (13 bytes)
%Program Files%\GreenTree Applications\YTD Video Downloader\plugins\video_output\.svn\prop-base\libdrawable_plugin.dll.svn-base (53 bytes)
%Program Files%\GreenTree Applications\YTD Video Downloader\plugins\audio_mixer\.svn\text-base\libinteger_mixer_plugin.dll.svn-base (1552 bytes)
%Program Files%\GreenTree Applications\YTD Video Downloader\plugins\audio_mixer\.svn\entries (608 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nse28.tmp\inst_start (1 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nse28.tmp\getCountry (2 bytes)
%Program Files%\GreenTree Applications\YTD Video Downloader\plugins\audio_filter\.svn\prop-base\libugly_resampler_plugin.dll.svn-base (53 bytes)
%Program Files%\GreenTree Applications\YTD Video Downloader\plugins\audio_output\.svn\text-base\libdirectsound_plugin.dll.svn-base (1552 bytes)
%Program Files%\GreenTree Applications\YTD Video Downloader\plugins\audio_filter\.svn\text-base\libaudio_format_plugin.dll.svn-base (1552 bytes)
%Program Files%\GreenTree Applications\YTD Video Downloader\plugins\audio_mixer\libfloat_mixer_plugin.dll (1552 bytes)
%Program Files%\GreenTree Applications\YTD Video Downloader\plugins\audio_mixer\.svn\all-wcprops (500 bytes)
%Program Files%\GreenTree Applications\YTD Video Downloader\Lang\res1050.ini (14 bytes)
%Program Files%\GreenTree Applications\YTD Video Downloader\Lang\res1038.ini (13 bytes)
%Program Files%\GreenTree Applications\YTD Video Downloader\plugins\codec\.svn\text-base\libavcodec_plugin.dll.svn-base (326900 bytes)
%Program Files%\GreenTree Applications\YTD Video Downloader\plugins\codec\.svn\prop-base\libavcodec_plugin.dll.svn-base (53 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nse28.tmp\exthelper.exe (49441 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nse28.tmp\NSISdl.dll (784 bytes)
%Program Files%\GreenTree Applications\YTD Video Downloader\Lang\res1043.ini (13 bytes)

The program deletes the following file(s):

%Documents and Settings%\%current user%\Local Settings\Temp\nse28.tmp\inst_start (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nse28.tmp\getCountry (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nse28.tmp\pixel (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nse28.tmp (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nse28.tmp\eula.rtf (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nse28.tmp\MPB_EULA.txt (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nse28.tmp\NSISHelper.dll (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nse28.tmp\UserInfo.dll (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nse28.tmp\modern-header.bmp (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nse28.tmp\exthelper.exe (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nse28.tmp\nsDialogs.dll (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nse28.tmp\tb-header.bmp (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nso26.tmp (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nse28.tmp\NSISdl.dll (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nse28.tmp\System.dll (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nse28.tmp\inst_finish (0 bytes)

The process BrowserExtensionsSetup.exe:3144 makes changes in the file system.
The program creates and/or writes to the following file(s):

%Documents and Settings%\%current user%\Application Data\Browser Extensions\nta_1.0.crx (1856 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nsh34.tmp\UserInfo.dll (4 bytes)
%Documents and Settings%\%current user%\Application Data\Browser Extensions\Coupons64.dll (23936 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nsh34.tmp\NSISCouponsPlugin.dll (17848 bytes)
%Documents and Settings%\%current user%\Application Data\Browser Extensions\CouponsHelper.exe (32128 bytes)
%Documents and Settings%\%current user%\Application Data\Browser Extensions\ButtonWrap.dll (8184 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nss33.tmp (97299 bytes)
%Documents and Settings%\%current user%\Application Data\Browser Extensions\deh_1.0.crx (16 bytes)
%Documents and Settings%\%current user%\Application Data\Browser Extensions\sh_1.0.crx (14 bytes)
%Documents and Settings%\%current user%\Application Data\Browser Extensions\Button.exe (1856 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nsh34.tmp\System.dll (11 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nsh34.tmp\BrowserExtensionsSetupUAC.exe (16288 bytes)
%Documents and Settings%\%current user%\Application Data\Browser Extensions\startpage_2.2.xpi (10 bytes)
%Documents and Settings%\%current user%\Application Data\Browser Extensions\saamazon_1.6.xpi (7 bytes)
%Documents and Settings%\%current user%\Application Data\Browser Extensions\Button64.exe (1856 bytes)
%Documents and Settings%\%current user%\Application Data\Browser Extensions\amazonsh_1.0.crx (9 bytes)
%Documents and Settings%\%current user%\Application Data\Browser Extensions\coupons_3.1.xpi (10 bytes)
%Documents and Settings%\%current user%\Application Data\Browser Extensions\Uninstall.exe (14510 bytes)
%Documents and Settings%\%current user%\Application Data\Browser Extensions\Coupons.dll (20416 bytes)
%Documents and Settings%\%current user%\Application Data\Browser Extensions\saebay_1.6.xpi (6 bytes)
%Documents and Settings%\%current user%\Application Data\Browser Extensions\ButtonWrap64.dll (8560 bytes)

The program deletes the following file(s):

%Documents and Settings%\%current user%\Local Settings\Temp\nsh34.tmp (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nsm32.tmp (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nsh34.tmp\NSISCouponsPlugin.dll (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nsh34.tmp\UserInfo.dll (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nsh34.tmp\BrowserExtensionsSetupUAC.exe (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nsh34.tmp\System.dll (0 bytes)

The process install.exe:820 makes changes in the file system.
The program creates and/or writes to the following file(s):

%Documents and Settings%\%current user%\Local Settings\Temp\dd_vcredistMSI736A.txt (542765 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\VWL42.tmp (392 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\dd_vcredistUI736A.txt (130962 bytes)

The program deletes the following file(s):

%Documents and Settings%\%current user%\Local Settings\Temp\VWL42.tmp (0 bytes)

The process SearchProtection.EXE:3452 makes changes in the file system.
The program creates and/or writes to the following file(s):

%Documents and Settings%\%current user%\Local Settings\Application Data\Microsoft\Internet Explorer\Services\search_{40DCF3A0-1630-482F-A96D-61C44FD2F2B3}.ico (1107 bytes)
%Documents and Settings%\%current user%\Local Settings\Application Data\Google\Chrome\User Data\Default\Web Data-journal (13210 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\yahoo_ie.xml (459 bytes)
%Documents and Settings%\%current user%\Local Settings\Application Data\Google\Chrome\User Data\Default\Preferences (117 bytes)
%Documents and Settings%\%current user%\Local Settings\Application Data\Google\Chrome\User Data\Default\Web Data (6968 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\WJYHCPG4\favicon[1].ico (1340 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\yahoo_ff.xml (803 bytes)
%Documents and Settings%\%current user%\Application Data\Mozilla\Firefox\Profiles\rsxjpslc.default\searchplugins\yahoo_ff.xml (1606 bytes)
%Documents and Settings%\%current user%\Local Settings\Application Data\Google\Chrome\User Data\Local State (58 bytes)
%Documents and Settings%\%current user%\Application Data\Mozilla\Firefox\Profiles\rsxjpslc.default\prefs.js (72 bytes)

The program deletes the following file(s):

%Documents and Settings%\%current user%\Local Settings\Application Data\Google\Chrome\User Data\Default\Web Data-journal (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\yahoo_ff.xml (0 bytes)
%Documents and Settings%\%current user%\Application Data\Mozilla\Firefox\Profiles\rsxjpslc.default\search.json (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\yahoo_ie.xml (0 bytes)

The process BackupSetup.exe:4068 makes changes in the file system.
The program creates and/or writes to the following file(s):

%Program Files%\MyPC Backup\UnRegisterExtensions.exe (15 bytes)
%Program Files%\MyPC Backup\Database\mpcb_file_cache.db (7 bytes)
%Program Files%\MyPC Backup\AWSSDK.dll (71948 bytes)
%Program Files%\MyPC Backup\Database\mpcb_sig_cache.db (6 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nsg39.tmp\System.dll (11 bytes)
%Program Files%\MyPC Backup\mypcbackup.ico (7146 bytes)
%Program Files%\MyPC Backup\Crypto32.dll (2716 bytes)
%Program Files%\MyPC Backup\syncicon.ico (3454 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\vcredist_x86.exe (382688 bytes)
%Program Files%\MyPC Backup\diffstack.dll (2980 bytes)
%Program Files%\MyPC Backup\AlphaVSS.60.x86.dll (5823 bytes)
%Program Files%\MyPC Backup\Crypto64.dll (2300 bytes)
%Program Files%\MyPC Backup\AlphaVSS.Common.dll (3296 bytes)
%Program Files%\MyPC Backup\Database\mpcb_backup_conf.db (16 bytes)
%Program Files%\MyPC Backup\Service Start.exe (14 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nsg39.tmp\ns3B.tmp (6 bytes)
%Program Files%\MyPC Backup\x86\System.Data.SQLite.dll (20659 bytes)
%Program Files%\MyPC Backup\AlphaVSS.52.x64.dll (4240 bytes)
%Program Files%\MyPC Backup\BackupStack.exe (1938 bytes)
%Program Files%\MyPC Backup\uninst.exe (1797 bytes)
%Program Files%\MyPC Backup\AlphaVSS.51.x86.dll (4106 bytes)
%Program Files%\MyPC Backup\RegisterExtensionDotNet20_x86.exe (20 bytes)
%Program Files%\MyPC Backup\es_ES.mo (1831 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nsg39.tmp\nsRandom.dll (479 bytes)
%Documents and Settings%\%current user%\Desktop\MyPC Backup.lnk (762 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nsg39.tmp\NSISdl.dll (14 bytes)
%Program Files%\MyPC Backup\GetText.dll (12 bytes)
%Program Files%\MyPC Backup\Shared Stack.dll (62611 bytes)
%Program Files%\MyPC Backup\MPCBContextMenu.dll (149087 bytes)
%Program Files%\MyPC Backup\LogicNP.EZShellExtensions.dll (6579 bytes)
%Program Files%\MyPC Backup\Updater.exe (30085 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\mpbtrk.log (8 bytes)
%Program Files%\MyPC Backup\tick.ico (8864 bytes)
%Program Files%\MyPC Backup\Signup Wizard.exe (24414 bytes)
%Program Files%\MyPC Backup\de_DE.mo (1702 bytes)
%Program Files%\MyPC Backup\AlphaVSS.60.x64.dll (6324 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nsg39.tmp\ns3A.tmp (6 bytes)
%Program Files%\MyPC Backup\MyPC Backup.exe (64373 bytes)
%Program Files%\MyPC Backup\syncing.ico (7445 bytes)
%Program Files%\MyPC Backup\MPCBIconOverlays.dll (85918 bytes)
%Documents and Settings%\%current user%\Start Menu\Programs\Startup\MyPC Backup.lnk (748 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nsg39.tmp\AccessControl.dll (8 bytes)
%Documents and Settings%\%current user%\Start Menu\Programs\MyPC Backup\MyPC Backup.lnk (774 bytes)
%Program Files%\MyPC Backup\Database\mpcb_queues.db (13 bytes)
%Program Files%\MyPC Backup\AlphaVSS.52.x86.dll (5025 bytes)
%Program Files%\MyPC Backup\RegisterExtensionDotNet20_x64.exe (16 bytes)
%Program Files%\MyPC Backup\it_IT.mo (1925 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nsg39.tmp\nsSCM.dll (5 bytes)
%Program Files%\MyPC Backup\pt_PT.mo (1605 bytes)
%Program Files%\MyPC Backup\MPCBClient.dll (28694 bytes)
%Program Files%\MyPC Backup\ObjectListView.dll (13129 bytes)
%Program Files%\MyPC Backup\fr_FR.mo (1621 bytes)
%Program Files%\MyPC Backup\Database\mpcb_settings.db (9 bytes)
%Program Files%\MyPC Backup\RestartExplorer.exe (16 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nsg39.tmp\DotNetChecker.dll (1123 bytes)
%Program Files%\MyPC Backup\Configuration Updater.exe (16 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nsg39.tmp\nsExec.dll (6 bytes)
%Program Files%\MyPC Backup\x64\System.Data.SQLite.dll (20635 bytes)
%Documents and Settings%\%current user%\Start Menu\Programs\MyPC Backup\Uninstall.lnk (545 bytes)

The program deletes the following file(s):

%Documents and Settings%\%current user%\Local Settings\Temp\nsg39.tmp\System.dll (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nsg38.tmp (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nsg39.tmp\nsSCM.dll (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nsg39.tmp\ns3A.tmp (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nsg39.tmp\nsRandom.dll (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nsg39.tmp\NSISdl.dll (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nsg39.tmp\AccessControl.dll (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nsg39.tmp\DotNetChecker.dll (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nsg39.tmp\nsExec.dll (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nsg39.tmp (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nsg39.tmp\ns3B.tmp (0 bytes)

The process msfeedssync.exe:3180 makes changes in the file system.
The program creates and/or writes to the following file(s):

%WinDir%\Tasks\User_Feed_Synchronization-{414D0F7C-B684-437B-B53E-8AB5AE32E070}.job (416 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\SuggestedSites.dat (4 bytes)
%Documents and Settings%\%current user%\Local Settings\Application Data\Microsoft\Feeds\{5588ACFD-6436-411B-A5CE-666AE6A92D3D}~\WebSlices~\Web Slice Gallery~.feed-ms (2176 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\AAE8OMVS\ie8[1].txt (644 bytes)
%Documents and Settings%\%current user%\Local Settings\Application Data\Microsoft\Feeds\FeedsStore.feedsdb-ms (14084 bytes)
%Documents and Settings%\%current user%\Local Settings\Application Data\Microsoft\Feeds\Microsoft Feeds~\Microsoft at Work~.feed-ms (3314 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\E9UY92VW\rss[1].xml (6141 bytes)
%Documents and Settings%\%current user%\Local Settings\Application Data\Microsoft\Feeds\Microsoft Feeds~\Microsoft at Home~.feed-ms (3314 bytes)
%Documents and Settings%\%current user%\Local Settings\Application Data\Microsoft\Feeds\{5588ACFD-6436-411B-A5CE-666AE6A92D3D}~\Internet Explorer Suggested Sites~.feed-ms (2184 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\X33TH0UP\rss[1].xml (5486 bytes)

The process CouponsHelper.exe:3544 makes changes in the file system.
The program creates and/or writes to the following file(s):

%Documents and Settings%\%current user%\Application Data\Mozilla\Firefox\Profiles\rsxjpslc.default\extensions\{58d2a791-6199-482f-a9aa-9b725ec61362}_tmp\chrome\content\main.xul (681 bytes)
%Documents and Settings%\%current user%\Application Data\Mozilla\Firefox\Profiles\rsxjpslc.default\extensions\{58d2a791-6199-482f-a9aa-9b725ec61362}_tmp\chrome\content\config.json (225 bytes)
%Documents and Settings%\%current user%\Application Data\Mozilla\Firefox\Profiles\rsxjpslc.default\extensions\[email protected]_tmp\chrome\content\amazon.xul (583 bytes)
%Documents and Settings%\%current user%\Application Data\Mozilla\Firefox\Profiles\rsxjpslc.default\extensions\[email protected]_tmp\chrome\content\main.js (367 bytes)
%Documents and Settings%\%current user%\Application Data\Mozilla\Firefox\Profiles\rsxjpslc.default\extensions\[email protected]_tmp\chrome\content\spigot.js (3 bytes)
%Documents and Settings%\%current user%\Application Data\Mozilla\Firefox\Profiles\rsxjpslc.default\extensions\[email protected]_tmp\chrome\content\saebay.js (2 bytes)
%Documents and Settings%\%current user%\Application Data\Mozilla\Firefox\Profiles\rsxjpslc.default\extensions\[email protected]_tmp\install.rdf (1 bytes)
%Documents and Settings%\%current user%\Application Data\Mozilla\Firefox\Profiles\rsxjpslc.default\extensions\{58d2a791-6199-482f-a9aa-9b725ec61362}_tmp\chrome\content\prefs.txt (171 bytes)
%Documents and Settings%\%current user%\Application Data\Mozilla\Firefox\Profiles\rsxjpslc.default\extensions.json (31 bytes)
%Documents and Settings%\%current user%\Application Data\Mozilla\Firefox\Profiles\rsxjpslc.default\extensions\{58d2a791-6199-482f-a9aa-9b725ec61362}_tmp\chrome\content\newtab.xul (1 bytes)
%Documents and Settings%\%current user%\Application Data\Mozilla\Firefox\Profiles\rsxjpslc.default\extensions\[email protected]_tmp\chrome\content\config.json (292 bytes)
%Documents and Settings%\%current user%\Application Data\Mozilla\Firefox\Profiles\rsxjpslc.default\extensions\[email protected]_tmp\icon.png (196 bytes)
%Documents and Settings%\%current user%\Application Data\Mozilla\Firefox\Profiles\rsxjpslc.default\extensions\{58d2a791-6199-482f-a9aa-9b725ec61362}_tmp\chrome\content\redirects.js (196 bytes)
%Documents and Settings%\%current user%\Application Data\Mozilla\Firefox\Profiles\rsxjpslc.default\extensions\[email protected]_tmp\chrome.manifest (148 bytes)
%Documents and Settings%\%current user%\Application Data\Mozilla\Firefox\Profiles\rsxjpslc.default\extensions\[email protected]_tmp\chrome\content\prefs.txt (14 bytes)
%Documents and Settings%\%current user%\Application Data\Mozilla\Firefox\Profiles\rsxjpslc.default\extensions\[email protected]_tmp\chrome\content\spigot.js (2 bytes)
%Documents and Settings%\%current user%\Application Data\Mozilla\Firefox\Profiles\rsxjpslc.default\extensions\{58d2a791-6199-482f-a9aa-9b725ec61362}_tmp\chrome\content\main.js (397 bytes)
%Documents and Settings%\%current user%\Application Data\Mozilla\Firefox\Profiles\rsxjpslc.default\extensions\[email protected]_tmp\chrome\content\main.js (359 bytes)
%Documents and Settings%\%current user%\Application Data\Mozilla\Firefox\Profiles\rsxjpslc.default\extensions\{58d2a791-6199-482f-a9aa-9b725ec61362}_tmp\chrome.manifest (192 bytes)
%Documents and Settings%\%current user%\Application Data\Mozilla\Firefox\Profiles\rsxjpslc.default\extensions\[email protected]\chrome\content\config.json (295 bytes)
%Documents and Settings%\%current user%\Application Data\Mozilla\Firefox\Profiles\rsxjpslc.default\extensions\[email protected]_tmp\chrome\content\main.js (386 bytes)
%Documents and Settings%\%current user%\Application Data\Mozilla\Firefox\Profiles\rsxjpslc.default\extensions\[email protected]_tmp\chrome\content\amazon.png (1 bytes)
%Documents and Settings%\%current user%\Application Data\Mozilla\Firefox\Profiles\rsxjpslc.default\extensions\{58d2a791-6199-482f-a9aa-9b725ec61362}_tmp\chrome\content\spigot.js (3 bytes)
%Documents and Settings%\%current user%\Application Data\Mozilla\Firefox\Profiles\rsxjpslc.default\extensions\{58d2a791-6199-482f-a9aa-9b725ec61362}_tmp\chrome\content\startpage.js (392 bytes)
%Documents and Settings%\%current user%\Application Data\Mozilla\Firefox\Profiles\rsxjpslc.default\extensions\[email protected]_tmp\icon.png (2 bytes)
%Documents and Settings%\%current user%\Application Data\Mozilla\Firefox\Profiles\rsxjpslc.default\extensions\{58d2a791-6199-482f-a9aa-9b725ec61362}\chrome\content\config.json (278 bytes)
%Documents and Settings%\%current user%\Application Data\Mozilla\Firefox\Profiles\rsxjpslc.default\extensions\{58d2a791-6199-482f-a9aa-9b725ec61362}_tmp\icon.png (1 bytes)
%Documents and Settings%\%current user%\Application Data\Mozilla\Firefox\Profiles\rsxjpslc.default\extensions\[email protected]_tmp\chrome\content\prefs.txt (110 bytes)
%Documents and Settings%\%current user%\Application Data\Mozilla\Firefox\Profiles\rsxjpslc.default\extensions\[email protected]_tmp\chrome\content\ebay.png (1 bytes)
%Documents and Settings%\%current user%\Application Data\Mozilla\Firefox\Profiles\rsxjpslc.default\extensions\{58d2a791-6199-482f-a9aa-9b725ec61362}_tmp\install.rdf (1 bytes)
%Documents and Settings%\%current user%\Application Data\Mozilla\Firefox\Profiles\rsxjpslc.default\extensions\[email protected]_tmp\chrome\content\savingsslider.xul (606 bytes)
%Documents and Settings%\%current user%\Application Data\Mozilla\Firefox\Profiles\rsxjpslc.default\extensions\[email protected]_tmp\chrome\content\savingsslider.js (392 bytes)
%Documents and Settings%\%current user%\Application Data\Mozilla\Firefox\Profiles\rsxjpslc.default\extensions\[email protected]_tmp\chrome.manifest (125 bytes)
%Documents and Settings%\%current user%\Application Data\Mozilla\Firefox\Profiles\rsxjpslc.default\extensions\[email protected]_tmp\chrome\content\saamazon.js (2 bytes)
%Documents and Settings%\%current user%\Application Data\Mozilla\Firefox\Profiles\rsxjpslc.default\extensions\[email protected]_tmp\chrome\content\spigot.js (2 bytes)
%Documents and Settings%\%current user%\Application Data\Mozilla\Firefox\Profiles\rsxjpslc.default\extensions\[email protected]_tmp\icon.png (1 bytes)
%Documents and Settings%\%current user%\Application Data\Mozilla\Firefox\Profiles\rsxjpslc.default\extensions\[email protected]_tmp\install.rdf (1 bytes)
%Documents and Settings%\%current user%\Application Data\Mozilla\Firefox\Profiles\rsxjpslc.default\extensions\[email protected]_tmp\install.rdf (1 bytes)
%Documents and Settings%\%current user%\Application Data\Mozilla\Firefox\Profiles\rsxjpslc.default\extensions\[email protected]_tmp\chrome.manifest (131 bytes)
%Documents and Settings%\%current user%\Application Data\Mozilla\Firefox\Profiles\rsxjpslc.default\extensions\[email protected]_tmp\chrome\content\ebay.xul (569 bytes)
%Documents and Settings%\%current user%\Application Data\Mozilla\Firefox\Profiles\rsxjpslc.default\extensions\[email protected]_tmp\chrome\content\prefs.txt (12 bytes)

The process vcredist_x86.exe:348 makes changes in the file system.
The program creates and/or writes to the following file(s):

C:\e22922a92f95b9889678f2\eula.1040.txt (13 bytes)
C:\e22922a92f95b9889678f2\install.res.1042.dll (1851 bytes)
C:\e22922a92f95b9889678f2\install.res.1028.dll (693 bytes)
C:\e22922a92f95b9889678f2\install.res.1036.dll (1925 bytes)
C:\e22922a92f95b9889678f2\$shtdwn$.req (788 bytes)
C:\e22922a92f95b9889678f2\install.res.1033.dll (1390 bytes)
C:\e22922a92f95b9889678f2\eula.1033.txt (10 bytes)
C:\e22922a92f95b9889678f2\install.ini (844 bytes)
C:\e22922a92f95b9889678f2\install.res.1040.dll (1754 bytes)
C:\e22922a92f95b9889678f2\globdata.ini (1 bytes)
C:\e22922a92f95b9889678f2\eula.2052.txt (405 bytes)
C:\e22922a92f95b9889678f2\install.res.1041.dll (983 bytes)
C:\e22922a92f95b9889678f2\vc_red.msi (3475 bytes)
C:\e22922a92f95b9889678f2 (8 bytes)
C:\e22922a92f95b9889678f2\eula.1036.txt (224 bytes)
C:\e22922a92f95b9889678f2\eula.1041.txt (5 bytes)
C:\e22922a92f95b9889678f2\eula.1028.txt (3 bytes)
C:\e22922a92f95b9889678f2\install.exe (8790 bytes)
C:\e22922a92f95b9889678f2\vcredist.bmp (5 bytes)
C:\e22922a92f95b9889678f2\eula.3082.txt (12 bytes)
C:\e22922a92f95b9889678f2\eula.1042.txt (5 bytes)
C:\e22922a92f95b9889678f2\eula.1049.txt (387 bytes)
C:\e22922a92f95b9889678f2\vc_red.cab (56236 bytes)
C:\e22922a92f95b9889678f2\install.res.3082.dll (1487 bytes)
C:\e22922a92f95b9889678f2\install.res.2052.dll (1368 bytes)
C:\e22922a92f95b9889678f2\install.res.1049.dll (1437 bytes)
C:\e22922a92f95b9889678f2\install.res.1031.dll (1585 bytes)
C:\e22922a92f95b9889678f2\eula.1031.txt (15 bytes)

The program deletes the following file(s):

C:\e22922a92f95b9889678f2\eula.1040.txt (0 bytes)
C:\_678953_ (0 bytes)
C:\e22922a92f95b9889678f2\install.res.1042.dll (0 bytes)
C:\e22922a92f95b9889678f2\install.res.1028.dll (0 bytes)
C:\e22922a92f95b9889678f2\install.res.1036.dll (0 bytes)
C:\e22922a92f95b9889678f2\install.res.1033.dll (0 bytes)
C:\e22922a92f95b9889678f2\install.res.1049.dll (0 bytes)
C:\e22922a92f95b9889678f2\install.ini (0 bytes)
C:\e22922a92f95b9889678f2\install.res.1040.dll (0 bytes)
C:\e22922a92f95b9889678f2\globdata.ini (0 bytes)
C:\e22922a92f95b9889678f2\eula.2052.txt (0 bytes)
C:\e22922a92f95b9889678f2\install.res.1041.dll (0 bytes)
C:\e22922a92f95b9889678f2\vc_red.msi (0 bytes)
C:\e22922a92f95b9889678f2 (0 bytes)
C:\e22922a92f95b9889678f2\eula.1036.txt (0 bytes)
C:\e22922a92f95b9889678f2\eula.1041.txt (0 bytes)
C:\e22922a92f95b9889678f2\eula.1042.txt (0 bytes)
C:\e22922a92f95b9889678f2\install.exe (0 bytes)
C:\e22922a92f95b9889678f2\vcredist.bmp (0 bytes)
C:\e22922a92f95b9889678f2\eula.3082.txt (0 bytes)
C:\e22922a92f95b9889678f2\eula.1028.txt (0 bytes)
C:\e22922a92f95b9889678f2\eula.1049.txt (0 bytes)
C:\e22922a92f95b9889678f2\vc_red.cab (0 bytes)
C:\e22922a92f95b9889678f2\install.res.3082.dll (0 bytes)
C:\e22922a92f95b9889678f2\install.res.2052.dll (0 bytes)
C:\e22922a92f95b9889678f2\eula.1033.txt (0 bytes)
C:\e22922a92f95b9889678f2\install.res.1031.dll (0 bytes)
C:\e22922a92f95b9889678f2\eula.1031.txt (0 bytes)

The process ~sp2E.tmp:3176 makes changes in the file system.
The program creates and/or writes to the following file(s):

%Documents and Settings%\%current user%\Application Data\Search Protection\SearchProtection.exe (28288 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nsz30.tmp (107044 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nsz31.tmp\BrowserExtensionsSetup.exe (60186 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nsz31.tmp\SDSPlugin.dll (22552 bytes)
%Documents and Settings%\%current user%\Application Data\Search Protection\Uninstall.exe (12076 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nsz31.tmp\System.dll (11 bytes)

The program deletes the following file(s):

%Documents and Settings%\%current user%\Local Settings\Temp\nsj2F.tmp (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nsz31.tmp\BrowserExtensionsSetup.exe (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nsz31.tmp (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nsz31.tmp\System.dll (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nsz31.tmp\SDSPlugin.dll (0 bytes)

The process BrowserExtensionsSetupUAC.exe:3536 makes changes in the file system.
The program creates and/or writes to the following file(s):

%Documents and Settings%\%current user%\Local Settings\Temp\nsj37.tmp\System.dll (11 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nst36.tmp (14354 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nsj37.tmp\UserInfo.dll (4 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nsj37.tmp\NSISCouponsPlugin.dll (17848 bytes)

The program deletes the following file(s):

%Documents and Settings%\%current user%\Local Settings\Temp\nsj37.tmp\System.dll (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nsj37.tmp\UserInfo.dll (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nsj37.tmp\NSISCouponsPlugin.dll (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nsj37.tmp (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nse35.tmp (0 bytes)

The process SearchProtectionStub.exe:2548 makes changes in the file system.
The program creates and/or writes to the following file(s):

%Documents and Settings%\%current user%\Local Settings\Temp\nsu2D.tmp\SDSPlugin.dll (22552 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nsu2D.tmp\System.dll (11 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nsu2C.tmp (19153 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\~sp2E.tmp (321984 bytes)

The program deletes the following file(s):

%Documents and Settings%\%current user%\Local Settings\Temp\nsu2D.tmp\SDSPlugin.dll (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nsu2D.tmp (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nse2B.tmp (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nsu2D.tmp\System.dll (0 bytes)

The process IEXPLORE.EXE:2880 makes changes in the file system.
The program creates and/or writes to the following file(s):

%Documents and Settings%\%current user%\Cookies\7KKWMT6B.txt (72 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\WJYHCPG4\thankyou[1].htm (413 bytes)
%Documents and Settings%\%current user%\Cookies\A8WL5QB4.txt (919 bytes)
%Documents and Settings%\%current user%\Local Settings\Application Data\Microsoft\Internet Explorer\DOMStore\7R8AXHHW\www.ytddownloader[1].xml (411 bytes)
%Documents and Settings%\%current user%\Cookies\3K5PFZ4L.txt (241 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\E9UY92VW\favicon[1].ico (9513 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\AAE8OMVS\dgdTycPTSRj[1].js (1186 bytes)
%Documents and Settings%\%current user%\Cookies\Y3E99XUS.txt (613 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\WJYHCPG4\jquery.min[1].js (61363 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\X33TH0UP\top-header-bg[1].jpg (140 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\X33TH0UP\ytd-logo[1].png (14728 bytes)
%Documents and Settings%\%current user%\Cookies\56E8VQFU.txt (87 bytes)
%Documents and Settings%\%current user%\Cookies\IO95CMW0.txt (385 bytes)
%Documents and Settings%\%current user%\Cookies\PJAYQ3JJ.txt (285 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\WJYHCPG4\header-bg[1].jpg (43912 bytes)
%Documents and Settings%\%current user%\Cookies\DEJ3GPCM.txt (327 bytes)
%Documents and Settings%\%current user%\Cookies\TW0Y1UD8.txt (613 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\AAE8OMVS\styles[1].css (4529 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\X33TH0UP\core131[1].js (121395 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\AAE8OMVS\sh158[1].html (9923 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\AAE8OMVS\counter017[1].js (5915 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\AAE8OMVS\widget120[1].css (45783 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\E9UY92VW\all[1].js (87362 bytes)
%Documents and Settings%\%current user%\Cookies\4JILEPXF.txt (85 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\E9UY92VW\upgrade-pro-btn[1].png (6454 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\WJYHCPG4\header-bg-repeat[1].jpg (140 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\AAE8OMVS\counter014[1].css (2977 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\WJYHCPG4\300lo[1].json (91 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\X33TH0UP\shares[1].json (55 bytes)
%Documents and Settings%\%current user%\Cookies\V9ILT370.txt (129 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\AAE8OMVS\dgdTycPTSRj[1].htm (1970 bytes)
%Documents and Settings%\%current user%\Local Settings\Application Data\Microsoft\Internet Explorer\DOMStore\YYGJFIDB\s7.addthis[1].xml (26 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\AAE8OMVS\dgdTycPTSRj[2].htm (1094 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\AAE8OMVS\main[1].js (25 bytes)
%Documents and Settings%\%current user%\Cookies\NBF8N5AK.txt (297 bytes)
%Documents and Settings%\%current user%\Cookies\O468AV3W.txt (697 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\E9UY92VW\ga[1].js (28634 bytes)
%Documents and Settings%\%current user%\Cookies\0KPRCZS7.txt (555 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\E9UY92VW\addthis_widget[1].js (3069 bytes)

The program deletes the following file(s):

%Documents and Settings%\%current user%\Cookies\7KKWMT6B.txt (0 bytes)
%Documents and Settings%\%current user%\Cookies\56E8VQFU.txt (0 bytes)
%Documents and Settings%\%current user%\Cookies\IO95CMW0.txt (0 bytes)
%Documents and Settings%\%current user%\Cookies\O468AV3W.txt (0 bytes)
%Documents and Settings%\%current user%\Cookies\3K5PFZ4L.txt (0 bytes)
%Documents and Settings%\%current user%\Cookies\PJAYQ3JJ.txt (0 bytes)
%Documents and Settings%\%current user%\Cookies\Y3E99XUS.txt (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\AAE8OMVS\widget120[1].css (0 bytes)
%Documents and Settings%\%current user%\Cookies\0KPRCZS7.txt (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\AAE8OMVS\counter014[1].css (0 bytes)
%Documents and Settings%\%current user%\Cookies\DEJ3GPCM.txt (0 bytes)
%Documents and Settings%\%current user%\Cookies\Current_User@scorecardresearch[2].txt (0 bytes)
%Documents and Settings%\%current user%\Cookies\V9ILT370.txt (0 bytes)

The process IEXPLORE.EXE:2676 makes changes in the file system.
The program creates and/or writes to the following file(s):

%Documents and Settings%\%current user%\Local Settings\Temp\~DFF65E.tmp (4605 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\~DFDEEC.tmp (3263 bytes)
%Documents and Settings%\%current user%\Local Settings\Application Data\Microsoft\Internet Explorer\Recovery\Active\RecoveryStore.{B5B36C2E-DAAE-11E3-81D1-0050563EC483}.dat (15783 bytes)
%Documents and Settings%\%current user%\Local Settings\Application Data\Microsoft\Internet Explorer\Recovery\Active\{B5B36C2F-DAAE-11E3-81D1-0050563EC483}.dat (18695 bytes)

The process MyPC Backup.exe:1212 makes changes in the file system.
The program creates and/or writes to the following file(s):

%Documents and Settings%\%current user%\Application Data\Microsoft\CryptnetUrlCache\Content\8DFDF057024880D7A081AFBF6D26B92F (533 bytes)
%Documents and Settings%\%current user%\Application Data\Microsoft\CryptnetUrlCache\MetaData\D236B74794790D9923905972356B8BEC (448 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\Cab3D.tmp (54 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\Tar3E.tmp (2712 bytes)
%Documents and Settings%\%current user%\Application Data\Microsoft\CryptnetUrlCache\Content\62B5AF9BE9ADC1085C3C56EC07A82BF6 (126 bytes)
%Documents and Settings%\%current user%\Application Data\Microsoft\CryptnetUrlCache\Content\D236B74794790D9923905972356B8BEC (2 bytes)
%Documents and Settings%\%current user%\Application Data\Microsoft\CryptnetUrlCache\MetaData\8DFDF057024880D7A081AFBF6D26B92F (176 bytes)
%Program Files%\MyPC Backup\Database\mpcb_settings.db (2260 bytes)
%Documents and Settings%\%current user%\Application Data\Microsoft\CryptnetUrlCache\MetaData\62B5AF9BE9ADC1085C3C56EC07A82BF6 (224 bytes)
%Documents and Settings%\%current user%\Desktop\Sync Folder.lnk (1 bytes)
%Program Files%\MyPC Backup\log\WAIT_HANDLES.log (540 bytes)
%Program Files%\MyPC Backup\Database\mpcb_settings.db-journal (27036 bytes)

The program deletes the following file(s):

%Documents and Settings%\%current user%\Local Settings\Temp\Tar3E.tmp (0 bytes)
%Program Files%\MyPC Backup\Database\mpcb_settings.db-journal (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\Cab3D.tmp (0 bytes)

The process Cloud_Backup_Setup.exe:2332 makes changes in the file system.
The program creates and/or writes to the following file(s):

%Documents and Settings%\%current user%\Local Settings\Temp\aff.conf (182 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nsh2A.tmp\LogEx.dll (1568 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\log.txt (28 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nsh2A.tmp\NSISdl.dll (14 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\BackupSetup.exe (1052338 bytes)

The program deletes the following file(s):

%Documents and Settings%\%current user%\Local Settings\Temp\nsh2A.tmp\LogEx.dll (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nsh2A.tmp\NSISdl.dll (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nsh2A.tmp (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\nss29.tmp (0 bytes)

Registry activity

The process %original file name%.exe:2104 makes changes in the system registry.
The program creates and/or sets the following values in system registry:

[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{1a413f37-ed88-4fec-9666-5c48dc4b7bb7}]
"DisplayVersion" = "4.8.1"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{c155cd72-744b-11e2-8294-806d6172696f}]
"BaseClass" = "Drive"

[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{1a413f37-ed88-4fec-9666-5c48dc4b7bb7}]
"NoModify" = "1"

[HKLM\SOFTWARE\{DAF8B7E5-449D-4180-8281-10E536E597F2}]
"it" = "20140513175552"

[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{1a413f37-ed88-4fec-9666-5c48dc4b7bb7}]
"VersionMajor" = "4"
"UninstallString" = "%Program Files%\GreenTree Applications\YTD Video Downloader\uninstall.exe"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"AppData" = "%Documents and Settings%\%current user%\Application Data"

[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"Common Start Menu" = "%Documents and Settings%\All Users\Start Menu"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"Personal" = "%Documents and Settings%\%current user%\My Documents"

[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{1a413f37-ed88-4fec-9666-5c48dc4b7bb7}]
"VersionMinor" = "8"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{c155cd73-744b-11e2-8294-806d6172696f}]
"BaseClass" = "Drive"

[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{1a413f37-ed88-4fec-9666-5c48dc4b7bb7}]
"NoRepair" = "1"

[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"Common AppData" = "%Documents and Settings%\All Users\Application Data"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{c155cd75-744b-11e2-8294-806d6172696f}]
"BaseClass" = "Drive"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"My Pictures" = "%Documents and Settings%\%current user%\My Documents\My Pictures"

[HKCU\Software\GreenTree Applications\YTD]
"ISN" = "2A0E0F74E87C41248D17D84CDB01E7BE"

[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"Common Desktop" = "%Documents and Settings%\All Users\Desktop"

[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{1a413f37-ed88-4fec-9666-5c48dc4b7bb7}]
"MainApp" = "%Program Files%\GreenTree Applications\YTD Video Downloader\ytd.exe"

[HKLM\System\CurrentControlSet\Control\Session Manager]
"PendingFileRenameOperations" = "\??\C:\DOCUME~1\"%CurrentUserName%"\LOCALS~1\Temp\nse28.tmp\Cloud_Backup_Setup.exe,"

[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{1a413f37-ed88-4fec-9666-5c48dc4b7bb7}]
"InstallLocation" = "%Program Files%\GreenTree Applications\YTD Video Downloader\"

[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"Common Documents" = "%Documents and Settings%\All Users\Documents"
"CommonVideo" = "%Documents and Settings%\All Users\Documents\My Videos"

[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{1a413f37-ed88-4fec-9666-5c48dc4b7bb7}]
"Publisher" = "GreenTree Applications SRL"

[HKLM\SOFTWARE\{DAF8B7E5-449D-4180-8281-10E536E597F2}]
"(Default)" = "4.8.1"

[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"CommonMusic" = "%Documents and Settings%\All Users\Documents\My Music"

[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{1a413f37-ed88-4fec-9666-5c48dc4b7bb7}]
"InstallDir" = "%Program Files%\GreenTree Applications\YTD Video Downloader\"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"Start Menu" = "%Documents and Settings%\%current user%\Start Menu"

[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{1a413f37-ed88-4fec-9666-5c48dc4b7bb7}]
"DisplayIcon" = "%Program Files%\GreenTree Applications\YTD Video Downloader\ytd.exe,0"

[HKCU\Software\GreenTree Applications\YTD]
"Language" = "1033"

[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"CommonPictures" = "%Documents and Settings%\All Users\Documents\My Pictures"

[HKLM\SOFTWARE\Microsoft\Cryptography\RNG]
"Seed" = "2F 8E 0A 56 5A 78 9D 38 B9 14 37 7E 94 9A 6E 73"

[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"Common Programs" = "%Documents and Settings%\All Users\Start Menu\Programs"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"Desktop" = "%Documents and Settings%\%current user%\Desktop"

[HKCU\Software\GreenTree Applications\YTD]
"(Default)" = "%Program Files%\GreenTree Applications\YTD Video Downloader"

[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{1a413f37-ed88-4fec-9666-5c48dc4b7bb7}]
"DisplayName" = "YTD Video Downloader 4.8.1"
"URLInfoAbout" = "http://www.ytddownloader.com"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{b98117e8-75ca-11e2-81b2-000c293708fb}]
"BaseClass" = "Drive"

[HKCU\Software\GreenTree Applications\YTD]
"kitType" = "cnet"

The process BrowserExtensionsSetup.exe:3144 makes changes in the system registry.
The program creates and/or sets the following values in system registry:

[HKCU\Software\Microsoft\Windows\CurrentVersion\Uninstall\{3A787631-66A2-4634-B928-A37E73B58FB6}]
"InstallLocation" = "%Documents and Settings%\%current user%\Application Data\Browser Extensions\"

[HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{1672163f-8651-4c0d-9c05-4ba941123972}]
"AppName" = "Button.exe"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Uninstall\{3A787631-66A2-4634-B928-A37E73B58FB6}]
"VersionMinor" = "4"
"URLInfoAbout" = "http://www.spigot.com"

"NoRepair" = "1"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"AppData" = "%Documents and Settings%\%current user%\Application Data"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"AutoDetect" = "1"

[HKCU\Software\AppDataLow\Software\Browser Extensions\firefox]
"[email protected]" = "%Documents and Settings%\%current user%\Application Data\Browser Extensions\coupons_3.1.xpi|1|{cnid : 407453, cnid_overwrite : true}"

[HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{1672163f-8651-4c0d-9c05-4ba941123972}]
"AppPath" = "%Documents and Settings%\%current user%\Application Data\Browser Extensions"

[HKCU\Software\AppDataLow\Software\Browser Extensions\firefox]
"[email protected]" = "%Documents and Settings%\%current user%\Application Data\Browser Extensions\saebay_1.6.xpi|1|{cnid : 407453, cnid_overwrite : true}"

[HKCU\Software\AppDataLow\Software\Browser Extensions\iexplorer]
"cnid" = "407453"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"Personal" = "%Documents and Settings%\%current user%\My Documents"

[HKLM\System\CurrentControlSet\Control\Session Manager]
"PendingFileRenameOperations" = "\??\C:\DOCUME~1\"%CurrentUserName%"\LOCALS~1\Temp\nse28.tmp\Cloud_Backup_Setup.exe, , \??\C:\DOCUME~1\"%CurrentUserName%"\LOCALS~1\Temp\nse28.tmp\SearchProtectionStub.exe, , \??\C:\DOCUME~1\"%CurrentUserName%"\LOCALS~1\Temp\nse28.tmp\, , \??\C:\DOCUME~1\"%CurrentUserName%"\LOCALS~1\Temp\nsh34.tmp\BrowserExtensionsSetupUAC.exe,"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{c155cd73-744b-11e2-8294-806d6172696f}]
"BaseClass" = "Drive"

[HKCU\Software\AppDataLow\Software\Browser Extensions]
"cnid" = "407453"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"Cookies" = "%Documents and Settings%\%current user%\Cookies"

[HKCU\Software\AppDataLow\Software\Browser Extensions\iexplorer]
"iedns" = "1"

[HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{61db39d5-034c-45c0-8bb2-daf857edcf3b}]
"AppName" = "Button64.exe"
"Policy" = "3"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Uninstall\{3A787631-66A2-4634-B928-A37E73B58FB6}]
"DisplayIcon" = "%Documents and Settings%\%current user%\Application Data\Browser Extensions\CouponsHelper.exe,0"

[HKCU\Software\AppDataLow\Software\Browser Extensions\iexplorer]
"ieam" = "1"

[HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{61db39d5-034c-45c0-8bb2-daf857edcf3b}]
"AppPath" = "%Documents and Settings%\%current user%\Application Data\Browser Extensions"

[HKCU\Software\AppDataLow\Software\Browser Extensions\firefox]
"[email protected]" = "%Documents and Settings%\%current user%\Application Data\Browser Extensions\saamazon_1.6.xpi|1|{cnid : 407453, cnid_overwrite : true}"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{c155cd75-744b-11e2-8294-806d6172696f}]
"BaseClass" = "Drive"

[HKCU\Software\AppDataLow\Software\Browser Extensions]
"SS_Ver" = "1.5"

[HKCU\Software\Microsoft\Internet Explorer\Approved Extensions]
"{34A0D84B-CDDC-4EC4-AFDD-4F1DDE1D14E5}" = "51 66 7A 6C 4C 1D 3B 1B 5B C7 BA 29 EF 9C A8 04"

[HKCU\Software\AppDataLow\Software\Browser Extensions\firefox]
"{58d2a791-6199-482f-a9aa-9b725ec61362}" = "%Documents and Settings%\%current user%\Application Data\Browser Extensions\startpage_2.2.xpi|1|{dns : true, ntp :true, cnid : 407453, cnid_overwrite : true, dummy : true}"

[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"Common Desktop" = "%Documents and Settings%\All Users\Desktop"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"Cache" = "%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files"

[HKCR\CLSID\{34A0D84B-CDDC-4EC4-AFDD-4F1DDE1D14E5}\InprocServer32]
"ThreadingModel" = "Apartment"

[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"Common Documents" = "%Documents and Settings%\All Users\Documents"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Uninstall\{3A787631-66A2-4634-B928-A37E73B58FB6}]
"VersionMajor" = "1"

[HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{CAE9BEC8-4723-4347-AFC6-25EE3326BA5B}]
"AppPath" = "%Documents and Settings%\%current user%\Application Data\Browser Extensions"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Uninstall\{3A787631-66A2-4634-B928-A37E73B58FB6}]
"NoModify" = "1"

[HKCU\Software\AppDataLow\Software\Browser Extensions\iexplorer]
"iecp" = "1"
"ieeb" = "1"

[HKCU\Software\AppDataLow\Software\Browser Extensions]
"ISN" = "4E827B34725D438C88043AFFC3DC9C0E"

[HKCU\Software\AppDataLow\Software\Browser Extensions\chrome]
"nlcphjankhppgohedpkjonpadimhaoof" = "%Documents and Settings%\%current user%\Application Data\Browser Extensions\sh_1.0.crx|1|{cps :true, cps_overwrite : true, cnid : 407453, cnid_overwrite : true, dummy : true}"

[HKCR\CLSID\{34A0D84B-CDDC-4EC4-AFDD-4F1DDE1D14E5}\Implemented Categories\{59fb2056-d625-48d0-a944-1a85b5ab2640}]
"(Default)" = ""

[HKCU\Software\Microsoft\Windows\CurrentVersion\Uninstall\{3A787631-66A2-4634-B928-A37E73B58FB6}]
"Publisher" = "Spigot, Inc."

[HKLM\SOFTWARE\Microsoft\Cryptography\RNG]
"Seed" = "8C 28 18 57 F9 DD 35 46 4E DA F0 3A 5C 11 D9 A4"

[HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{CAE9BEC8-4723-4347-AFC6-25EE3326BA5B}]
"AppName" = "CouponsHelper.exe"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Uninstall\{3A787631-66A2-4634-B928-A37E73B58FB6}]
"DisplayVersion" = "1.5"

[HKCU\Software\AppDataLow\Software\Browser Extensions\chrome]
"gpiifgmgnfdiblgpaepbmfdkcheicgof" = "%Documents and Settings%\%current user%\Application Data\Browser Extensions\nta_1.0.crx|1|{ntp :true, ntp_overwrite : true, custom_dea_ntp_disabled : false, cnid : 407453, cnid_overwrite : true, dummy : true}"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"Desktop" = "%Documents and Settings%\%current user%\Desktop"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Uninstall\{3A787631-66A2-4634-B928-A37E73B58FB6}]
"UninstallString" = "%Documents and Settings%\%current user%\Application Data\Browser Extensions\uninstall.exe"

[HKCU\Software\AppDataLow\Software\Browser Extensions]
"(Default)" = ""

[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{c155cd72-744b-11e2-8294-806d6172696f}]
"BaseClass" = "Drive"

[HKCU\Software\AppDataLow\Software\Browser Extensions\iexplorer]
"ISN" = "4E827B34725D438C88043AFFC3DC9C0E"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Uninstall\{3A787631-66A2-4634-B928-A37E73B58FB6}]
"DisplayName" = "Browser Extensions"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{b98117e8-75ca-11e2-81b2-000c293708fb}]
"BaseClass" = "Drive"

[HKCR\CLSID\{34A0D84B-CDDC-4EC4-AFDD-4F1DDE1D14E5}\InprocServer32]
"(Default)" = "%Documents and Settings%\%current user%\Application Data\Browser Extensions\Coupons64.dll"

[HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{CAE9BEC8-4723-4347-AFC6-25EE3326BA5B}]
"Policy" = "3"

[HKCU\Software\Microsoft\Windows\ShellNoRoam\MUICache\C:\DOCUME~1\"%CurrentUserName%"\LOCALS~1\Temp\nsh34.tmp]
"BrowserExtensionsSetupUAC.exe" = "Browser Extensions setup launcher UAC"

[HKCR\CLSID\{34A0D84B-CDDC-4EC4-AFDD-4F1DDE1D14E5}\Implemented Categories]
"(Default)" = ""

[HKCU\Software\AppDataLow\Software\Browser Extensions\chrome]
"cikkkfooompgefbcjlgdjejfdknkheaj" = "%Documents and Settings%\%current user%\Application Data\Browser Extensions\deh_1.0.crx|1|{dns : true, dns_overwrite : true, cnid : 407453, cnid_overwrite : true, dummy : true}"
"bbecdmcnlcoebdcidcfdkoimbjkcegbc" = "%Documents and Settings%\%current user%\Application Data\Browser Extensions\amazonsh_1.0.crx|1|{cnid : 407453, cnid_overwrite : true}"

[HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{1672163f-8651-4c0d-9c05-4ba941123972}]
"Policy" = "3"

[HKCR\CLSID\{34A0D84B-CDDC-4EC4-AFDD-4F1DDE1D14E5}]
"(Default)" = "Browser Extensions"

The program modifies IE settings for security zones to map all local web-nodes with no dots which do not refer to any zone to the Intranet Zone:

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"UNCAsIntranet" = "1"

It registers itself as a Browser Helper Object (BHO) to ensure its automatic execution every time Internet Explorer is run. It does this by creating the following registry key(s)/entry(ies):

[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{34A0D84B-CDDC-4EC4-AFDD-4F1DDE1D14E5}]
"NoExplorer" = "1"

"(Default)" = "Browser Extensions"

To automatically run itself each time Windows is booted, the program adds the following link to its file to the system registry autorun key:

[HKCU\Software\Microsoft\Windows\CurrentVersion\Run]
"Browser Extensions" = "%Documents and Settings%\%current user%\Application Data\Browser Extensions\CouponsHelper.exe"

The program modifies IE settings for security zones to map all urls to the Intranet Zone:

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"IntranetName" = "1"

The program modifies IE settings for security zones to map all web-nodes that bypassing the proxy to the Intranet Zone:

"ProxyBypass" = "1"

The program deletes the following value(s) in system registry:

[HKCU\Software\Microsoft\Internet Explorer\Approved Extensions]
"{34A0D84B-CDDC-4EC4-AFDD-4F1DDE1D14E5}"

The process install.exe:820 makes changes in the system registry.
The program creates and/or sets the following values in system registry:

[HKLM\SOFTWARE\Microsoft\Cryptography\RNG]
"Seed" = "0B A6 33 AC C0 03 9C FD CA 5B 04 D3 25 DC FD A5"

The process SearchProtection.EXE:3452 makes changes in the system registry.
The program creates and/or sets the following values in system registry:

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"AutoDetect" = "1"

[HKCU\Software\Microsoft\Internet Explorer\SearchScopes]
"DefaultScope" = "{40DCF3A0-1630-482F-A96D-61C44FD2F2B3}"

[HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{40DCF3A0-1630-482F-A96D-61C44FD2F2B3}]
"FaviconURL" = "http://www.yahoo.com/favicon.ico"
"FaviconPath" = "%Documents and Settings%\%current user%\Local Settings\Application Data\Microsoft\Internet Explorer\Services\search_{40DCF3A0-1630-482F-A96D-61C44FD2F2B3}.ico"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"AppData" = "%Documents and Settings%\%current user%\Application Data"

"Cookies" = "%Documents and Settings%\%current user%\Cookies"

"Local AppData" = "%Documents and Settings%\%current user%\Local Settings\Application Data"

[HKCU\Software\AppDataLow\Software\Search Protection]
"ping_ts" = "1399992989"
"GCFailed" = "0"

[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"Common AppData" = "%Documents and Settings%\All Users\Application Data"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"Cache" = "%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files"

[HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{40DCF3A0-1630-482F-A96D-61C44FD2F2B3}]
"URL" = "http://search.yahoo.com/search?fr=chr-greentree_ie&ei=utf-8&ilc=12&type=407453&p={searchTerms}"

"OSDFileURL" = "file:///C:/DOCUME~1/adm/LOCALS~1/Temp/yahoo_ie.xml"

[HKCR\TypeLib\{1EA4DBF0-3C3B-11CF-810C-00AA00389B71}\1.1\0\win32]
"(Default)" = "%System%\oleacc.dll"

[HKCU\Software\Microsoft\Internet Explorer\User Preferences]
"88D7D0879DAB32E14DE5B3A805A34F98AFF34F5977" = "01 00 00 00 D0 8C 9D DF 01 15 D1 11 8C 7A 00 C0"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Connections]
"SavedLegacySettings" = "46 00 00 00 42 00 00 00 01 00 00 00 00 00 00 00"

[HKLM\SOFTWARE\Microsoft\Cryptography\RNG]
"Seed" = "79 15 F0 62 DD 63 C9 97 B0 A5 79 F8 4A F6 A1 23"

[HKCU\Software\Microsoft\Internet Explorer\Main]
"Start Page" = "http://ca.search.yahoo.com/?type=407453&fr=spigot-yhp-ie"

[HKCU\Software\Microsoft\Internet Explorer\SearchScopes]
"ShowSearchSuggestionsInAddressGlobal" = "1"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"History" = "%Documents and Settings%\%current user%\Local Settings\History"

[HKCU\Software\AppDataLow\Software\Search Protection]
"FFFailed" = "0"

[HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{40DCF3A0-1630-482F-A96D-61C44FD2F2B3}]
"DisplayName" = "Yahoo"

The program modifies IE settings for security zones to map all local web-nodes with no dots which do not refer to any zone to the Intranet Zone:

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"UNCAsIntranet" = "1"

The program modifies IE settings for security zones to map all web-nodes that bypassing the proxy to the Intranet Zone:

"ProxyBypass" = "1"

Proxy settings are disabled:

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings]
"ProxyEnable" = "0"

The program modifies IE settings for security zones to map all urls to the Intranet Zone:

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"IntranetName" = "1"

The program deletes the following value(s) in system registry:

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings]
"AutoConfigURL"
"ProxyServer"
"ProxyOverride"

The process BackupSetup.exe:4068 makes changes in the system registry.
The program creates and/or sets the following values in system registry:

[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{c155cd72-744b-11e2-8294-806d6172696f}]
"BaseClass" = "Drive"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"AppData" = "%Documents and Settings%\%current user%\Application Data"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"AutoDetect" = "1"

[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"Common Start Menu" = "%Documents and Settings%\All Users\Start Menu"

[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\MyPC Backup]
"(Default)" = "%Program Files%\MyPC Backup\BackupStack.exe"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"Personal" = "%Documents and Settings%\%current user%\My Documents"

[HKLM\System\CurrentControlSet\Control\Session Manager]
"PendingFileRenameOperations" = "\??\C:\DOCUME~1\"%CurrentUserName%"\LOCALS~1\Temp\nse28.tmp\Cloud_Backup_Setup.exe, , \??\C:\DOCUME~1\"%CurrentUserName%"\LOCALS~1\Temp\nse28.tmp\SearchProtectionStub.exe, , \??\C:\DOCUME~1\"%CurrentUserName%"\LOCALS~1\Temp\nse28.tmp\, , \??\C:\DOCUME~1\"%CurrentUserName%"\LOCALS~1\Temp\nsh34.tmp\BrowserExtensionsSetupUAC.exe, , \??\C:\DOCUME~1\"%CurrentUserName%"\LOCALS~1\Temp\nsh34.tmp\, , \??\C:\DOCUME~1\"%CurrentUserName%"\LOCALS~1\Temp\nsg39.tmp\nsSCM.dll,"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{c155cd73-744b-11e2-8294-806d6172696f}]
"BaseClass" = "Drive"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"Cookies" = "%Documents and Settings%\%current user%\Cookies"

[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\MyPC Backup]
"DisplayName" = "MyPC Backup"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"Startup" = "%Documents and Settings%\%current user%\Start Menu\Programs\Startup"

[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\MyPC Backup]
"URLInfoAbout" = "http://www.mypcbackup.com"

[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"Common AppData" = "%Documents and Settings%\All Users\Application Data"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{c155cd75-744b-11e2-8294-806d6172696f}]
"BaseClass" = "Drive"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"My Pictures" = "%Documents and Settings%\%current user%\My Documents\My Pictures"

[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\MyPC Backup]
"Publisher" = "JDi Backup Ltd"

[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"Common Desktop" = "%Documents and Settings%\All Users\Desktop"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"Cache" = "%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files"

[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"Common Documents" = "%Documents and Settings%\All Users\Documents"
"CommonVideo" = "%Documents and Settings%\All Users\Documents\My Videos"

"CommonMusic" = "%Documents and Settings%\All Users\Documents\My Music"

[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\MyPC Backup]
"DisplayIcon" = "%Program Files%\MyPC Backup\MyPC Backup.exe"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"Start Menu" = "%Documents and Settings%\%current user%\Start Menu"

[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\MyPC Backup]
"UninstallString" = "%Program Files%\MyPC Backup\uninst.exe"
"HelpLink" = "http://support.mypcbackup.com"

[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"CommonPictures" = "%Documents and Settings%\All Users\Documents\My Pictures"

[HKLM\SOFTWARE\Microsoft\Cryptography\RNG]
"Seed" = "30 DE 3F 50 3F 75 5F BD DF AA 06 54 1B 9F E5 6C"

[HKCU\Software\Microsoft\Windows\ShellNoRoam\MUICache\%Program Files%\MyPC Backup]
"MyPC Backup.exe" = "MyPC Backup"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"Desktop" = "%Documents and Settings%\%current user%\Desktop"

[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\MyPC Backup]
"DisplayVersion" = ""

[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"Programs" = "%Documents and Settings%\%current user%\Start Menu\Programs"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{b98117e8-75ca-11e2-81b2-000c293708fb}]
"BaseClass" = "Drive"

The program modifies IE settings for security zones to map all web-nodes that bypassing the proxy to the Intranet Zone:

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"ProxyBypass" = "1"

The program modifies IE settings for security zones to map all local web-nodes with no dots which do not refer to any zone to the Intranet Zone:

"UNCAsIntranet" = "1"

The program modifies IE settings for security zones to map all urls to the Intranet Zone:

"IntranetName" = "1"

The process msfeedssync.exe:3180 makes changes in the system registry.
The program creates and/or sets the following values in system registry:

[HKLM\SOFTWARE\Microsoft\Cryptography\RNG]
"Seed" = "51 DB 2E 18 EE 8B 81 33 82 43 ED DA 08 6C 95 61"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"Cookies" = "%Documents and Settings%\%current user%\Cookies"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"AutoDetect" = "1"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"Favorites" = "%Documents and Settings%\%current user%\Favorites"
"History" = "%Documents and Settings%\%current user%\Local Settings\History"

[HKCU\Software\Microsoft\Internet Explorer\Suggested Sites]
"DeletePending" = "0"

[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"Common AppData" = "%Documents and Settings%\All Users\Application Data"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"AppData" = "%Documents and Settings%\%current user%\Application Data"

[HKCU\Software\Microsoft\Internet Explorer\Main\WindowsSearch]
"Version" = "WS not installed"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"Cache" = "%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Connections]
"SavedLegacySettings" = "46 00 00 00 44 00 00 00 01 00 00 00 00 00 00 00"

[HKCU\Software\Microsoft\Internet Explorer\Suggested Sites]
"UploadDiagInfo" = "1C 5C 00 00 71 17 00 08 00 00 00 00 00 00 00 0C"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"Local AppData" = "%Documents and Settings%\%current user%\Local Settings\Application Data"

The program modifies IE settings for security zones to map all web-nodes that bypassing the proxy to the Intranet Zone:

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"ProxyBypass" = "1"

The program modifies IE settings for security zones to map all local web-nodes with no dots which do not refer to any zone to the Intranet Zone:

"UNCAsIntranet" = "1"

The program modifies IE settings for security zones to map all urls to the Intranet Zone:

"IntranetName" = "1"

Proxy settings are disabled:

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings]
"ProxyEnable" = "0"

The program deletes the following value(s) in system registry:

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings]
"AutoConfigURL"
"ProxyServer"
"ProxyOverride"

The process CouponsHelper.exe:3544 makes changes in the system registry.
The program creates and/or sets the following values in system registry:

[HKLM\SOFTWARE\Microsoft\Cryptography\RNG]
"Seed" = "79 88 7F 08 72 50 11 65 8A 39 03 5C F7 06 69 16"

[HKCU\Software\AppDataLow\Software\Browser Extensions\firefox]
"{58d2a791-6199-482f-a9aa-9b725ec61362}" = ""
"[email protected]" = ""

[HKLM\SOFTWARE\Google\Chrome\Extensions\bbecdmcnlcoebdcidcfdkoimbjkcegbc]
"Path" = "%Documents and Settings%\%current user%\Application Data\Browser Extensions\amazonsh_1.0.crx"
"Version" = "1.0"

[HKLM\SOFTWARE\Google\Chrome\Extensions\gpiifgmgnfdiblgpaepbmfdkcheicgof]
"Version" = "1.0"
"Path" = "%Documents and Settings%\%current user%\Application Data\Browser Extensions\nta_1.0.crx"

[HKLM\SOFTWARE\Google\Chrome\Extensions\cikkkfooompgefbcjlgdjejfdknkheaj]
"Path" = "%Documents and Settings%\%current user%\Application Data\Browser Extensions\deh_1.0.crx"

[HKLM\SOFTWARE\Google\Chrome\Extensions\nlcphjankhppgohedpkjonpadimhaoof]
"Version" = "1.0"

[HKCU\Software\AppDataLow\Software\Browser Extensions\firefox]
"[email protected]" = ""

[HKLM\SOFTWARE\Google\Chrome\Extensions\nlcphjankhppgohedpkjonpadimhaoof]
"Path" = "%Documents and Settings%\%current user%\Application Data\Browser Extensions\sh_1.0.crx"

[HKCU\Software\AppDataLow\Software\Browser Extensions\firefox]
"[email protected]" = ""

[HKLM\SOFTWARE\Google\Chrome\Extensions\cikkkfooompgefbcjlgdjejfdknkheaj]
"Version" = "1.0"

The process vcredist_x86.exe:348 makes changes in the system registry.
The program creates and/or sets the following values in system registry:

[HKLM\SOFTWARE\Microsoft\Cryptography\RNG]
"Seed" = "6B 71 48 07 79 86 D5 DB 63 6B A7 68 43 1B D7 C1"

The process MsiExec.exe:2516 makes changes in the system registry.
The program creates and/or sets the following values in system registry:

[HKLM\SOFTWARE\Microsoft\Cryptography\RNG]
"Seed" = "B4 8D 22 0A EB 76 3B 24 D6 67 D0 EF 30 45 D6 B2"

The process taskkill.exe:3616 makes changes in the system registry.
The program creates and/or sets the following values in system registry:

[HKLM\SOFTWARE\Microsoft\Cryptography\RNG]
"Seed" = "4E C0 2D F8 F9 15 19 06 2A EA D4 C5 4A F7 C9 A6"

The process taskkill.exe:368 makes changes in the system registry.
The program creates and/or sets the following values in system registry:

[HKLM\SOFTWARE\Microsoft\Cryptography\RNG]
"Seed" = "72 A9 CC 54 C0 96 DB CE 39 A6 51 A2 3E 0F 7F FF"

The process ~sp2E.tmp:3176 makes changes in the system registry.
The program creates and/or sets the following values in system registry:

[HKCU\Software\Microsoft\Windows\CurrentVersion\Uninstall\Search Protection]
"VersionMajor" = "1"

[HKCU\Software\AppDataLow\Software\Search Protection]
"CCV" = "179"
"WS_FF_AB" = "http://search.yahoo.com/search?fr=greentree_ff1&ei=utf-8&ilc=12&type=407453&p="

[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"AppData" = "%Documents and Settings%\%current user%\Application Data"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Uninstall\Search Protection]
"NoRepair" = "1"

[HKCU\Software\AppDataLow\Software\Search Protection]
"WS_GC_IB" = "http://search.yahoo.com/search?fr=chr-greentree_gc&ei=utf-8&ilc=12&type=407453&p={searchTerms}"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{c155cd73-744b-11e2-8294-806d6172696f}]
"BaseClass" = "Drive"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"Cookies" = "%Documents and Settings%\%current user%\Cookies"

[HKCU\Software\AppDataLow\Software\Search Protection]
"HP_IE" = "http://ca.search.yahoo.com/?type=407453&fr=spigot-yhp-ie"
"WS_FF_IB" = "http://search.yahoo.com/search?fr=chr-greentree_ff&ei=utf-8&ilc=12&type=407453&p={searchTerms}"
"ISN" = "E2DA97D8A12A4D02B7A3A58A402F38B0"
"ChannelID" = "407453"

[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"Common AppData" = "%Documents and Settings%\All Users\Application Data"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{c155cd75-744b-11e2-8294-806d6172696f}]
"BaseClass" = "Drive"

[HKCU\Software\AppDataLow\Software\Search Protection]
"HP_GC" = "http://ca.search.yahoo.com/?type=407453&fr=spigot-yhp-ch"
"407453" = "1"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Uninstall\Search Protection]
"UninstallString" = "%Documents and Settings%\%current user%\Application Data\Search Protection\uninstall.exe"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"Cache" = "%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files"

[HKCU\Software\AppDataLow\Software\Search Protection]
"sdsprotection" = "1"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Uninstall\Search Protection]
"NoModify" = "1"

[HKCU\Software\AppDataLow\Software\Search Protection]
"app_ver" = "8.9.0.2"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Uninstall\Search Protection]
"DisplayName" = "Search Protection"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Connections]
"SavedLegacySettings" = "46 00 00 00 40 00 00 00 01 00 00 00 00 00 00 00"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Uninstall\Search Protection]
"URLInfoAbout" = "http://www.spigot.com"
"VersionMinor" = "0"

[HKLM\SOFTWARE\Microsoft\Cryptography\RNG]
"Seed" = "96 CB 0C 90 F6 7B 67 2C 75 9C 5D 2D 00 8B 53 E4"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Uninstall\Search Protection]
"Publisher" = "Spigot, Inc."

[HKCU\Software\AppDataLow\Software\Search Protection]
"SPID" = "249"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Uninstall\Search Protection]
"DisplayVersion" = "8.9.0.2"

[HKCU\Software\AppDataLow\Software\Search Protection]
"WS_IE_IB" = "http://search.yahoo.com/search?fr=chr-greentree_ie&ei=utf-8&ilc=12&type=407453&p={searchTerms}"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"History" = "%Documents and Settings%\%current user%\Local Settings\History"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Uninstall\Search Protection]
"InstallDir" = "%Documents and Settings%\%current user%\Application Data\Search Protection\"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{c155cd72-744b-11e2-8294-806d6172696f}]
"BaseClass" = "Drive"

[HKCU\Software\AppDataLow\Software\Search Protection]
"HP_FF" = "http://ca.search.yahoo.com/?type=407453&fr=spigot-yhp-ff"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{b98117e8-75ca-11e2-81b2-000c293708fb}]
"BaseClass" = "Drive"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Uninstall\Search Protection]
"DisplayIcon" = "%Documents and Settings%\%current user%\Application Data\Search Protection\SearchProtection.EXE,0"
"InstallLocation" = "%Documents and Settings%\%current user%\Application Data\Search Protection\"

[HKCU\Software\AppDataLow\Software\Search Protection]
"WS_IE_AB" = "http://search.yahoo.com/search?fr=greentree_ie1&ei=utf-8&ilc=12&type=407453&p={searchTerms}"

Proxy settings are disabled:

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings]
"ProxyEnable" = "0"

To automatically run itself each time Windows is booted, the program adds the following link to its file to the system registry autorun key:

[HKCU\Software\Microsoft\Windows\CurrentVersion\Run]
"SearchProtection" = "%Documents and Settings%\%current user%\Application Data\Search Protection\SearchProtection.EXE /autostart"

The program deletes the following value(s) in system registry:

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings]
"AutoConfigURL"
"ProxyServer"
"ProxyOverride"

The process BrowserExtensionsSetupUAC.exe:3536 makes changes in the system registry.
The program creates and/or sets the following values in system registry:

[HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{1672163f-8651-4c0d-9c05-4ba941123972}]
"AppName" = "Button.exe"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Uninstall\{3A787631-66A2-4634-B928-A37E73B58FB6}]
"(Default)" = ""

[HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{1672163f-8651-4c0d-9c05-4ba941123972}]
"AppPath" = "%Documents and Settings%\%current user%\Application Data\Browser Extensions"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{c155cd73-744b-11e2-8294-806d6172696f}]
"BaseClass" = "Drive"

[HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{61db39d5-034c-45c0-8bb2-daf857edcf3b}]
"AppName" = "Button64.exe"
"Policy" = "3"

"AppPath" = "%Documents and Settings%\%current user%\Application Data\Browser Extensions"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{c155cd75-744b-11e2-8294-806d6172696f}]
"BaseClass" = "Drive"

[HKCR\CLSID\{34A0D84B-CDDC-4EC4-AFDD-4F1DDE1D14E5}\InprocServer32]
"ThreadingModel" = "Apartment"

[HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{CAE9BEC8-4723-4347-AFC6-25EE3326BA5B}]
"AppPath" = "%Documents and Settings%\%current user%\Application Data\Browser Extensions"

[HKCR\CLSID\{34A0D84B-CDDC-4EC4-AFDD-4F1DDE1D14E5}\Implemented Categories\{59fb2056-d625-48d0-a944-1a85b5ab2640}]
"(Default)" = ""

[HKLM\SOFTWARE\Microsoft\Cryptography\RNG]
"Seed" = "CB 21 94 12 67 0A 50 F6 B5 F8 2F 18 89 B1 4F 08"

[HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{CAE9BEC8-4723-4347-AFC6-25EE3326BA5B}]
"AppName" = "CouponsHelper.exe"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{c155cd72-744b-11e2-8294-806d6172696f}]
"BaseClass" = "Drive"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{b98117e8-75ca-11e2-81b2-000c293708fb}]
"BaseClass" = "Drive"

[HKCR\CLSID\{34A0D84B-CDDC-4EC4-AFDD-4F1DDE1D14E5}\InprocServer32]
"(Default)" = "%Documents and Settings%\%current user%\Application Data\Browser Extensions\Coupons64.dll"

[HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{CAE9BEC8-4723-4347-AFC6-25EE3326BA5B}]
"Policy" = "3"

[HKCR\CLSID\{34A0D84B-CDDC-4EC4-AFDD-4F1DDE1D14E5}\Implemented Categories]
"(Default)" = ""

[HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{1672163f-8651-4c0d-9c05-4ba941123972}]
"Policy" = "3"

[HKCR\CLSID\{34A0D84B-CDDC-4EC4-AFDD-4F1DDE1D14E5}]
"(Default)" = "Browser Extensions"

It registers itself as a Browser Helper Object (BHO) to ensure its automatic execution every time Internet Explorer is run. It does this by creating the following registry key(s)/entry(ies):

[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{34A0D84B-CDDC-4EC4-AFDD-4F1DDE1D14E5}]
"NoExplorer" = "1"

"(Default)" = "Browser Extensions"

The process SearchProtectionStub.exe:2548 makes changes in the system registry.
The program creates and/or sets the following values in system registry:

[HKLM\SOFTWARE\Microsoft\Cryptography\RNG]
"Seed" = "37 A4 0F 08 F9 87 AC 86 69 DA 4F 9D 33 F4 60 3A"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{c155cd73-744b-11e2-8294-806d6172696f}]
"BaseClass" = "Drive"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"Cookies" = "%Documents and Settings%\%current user%\Cookies"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"AutoDetect" = "1"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"History" = "%Documents and Settings%\%current user%\Local Settings\History"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{c155cd72-744b-11e2-8294-806d6172696f}]
"BaseClass" = "Drive"

[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"Common AppData" = "%Documents and Settings%\All Users\Application Data"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{b98117e8-75ca-11e2-81b2-000c293708fb}]
"BaseClass" = "Drive"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"AppData" = "%Documents and Settings%\%current user%\Application Data"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{c155cd75-744b-11e2-8294-806d6172696f}]
"BaseClass" = "Drive"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"Cache" = "%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Connections]
"SavedLegacySettings" = "46 00 00 00 3C 00 00 00 01 00 00 00 00 00 00 00"

The program modifies IE settings for security zones to map all web-nodes that bypassing the proxy to the Intranet Zone:

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"ProxyBypass" = "1"

The program modifies IE settings for security zones to map all local web-nodes with no dots which do not refer to any zone to the Intranet Zone:

"UNCAsIntranet" = "1"

The program modifies IE settings for security zones to map all urls to the Intranet Zone:

"IntranetName" = "1"

Proxy settings are disabled:

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings]
"ProxyEnable" = "0"

The program deletes the following value(s) in system registry:

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings]
"AutoConfigURL"
"ProxyServer"
"ProxyOverride"

The process IEXPLORE.EXE:2880 makes changes in the system registry.
The program creates and/or sets the following values in system registry:

[HKCU\Software\Classes\CLSID\{CAFEEFAC-0014-0002-0028-ABCDEFFEDCBA}\InprocServer32]
"(Default)" = "%Program Files%\Java\jre6\bin\jp2iexp.dll"

[HKCU\Software\Classes\CLSID\{CAFEEFAC-0013-0001-0003-ABCDEFFEDCBB}\InprocServer32]
"(Default)" = "%Program Files%\Java\jre6\bin\jp2iexp.dll"

[HKCU\Software\Classes\CLSID\{CAFEEFAC-0015-0000-0020-ABCDEFFEDCBA}]
"(Default)" = "Java Plug-in 1.5.0_20"

[HKCU\Software\Microsoft\Internet Explorer\Main\WindowsSearch]
"Version" = "WS not installed"

[HKCU\Software\Classes\CLSID\{CAFEEFAC-0016-0000-0003-ABCDEFFEDCBA}\InprocServer32]
"ThreadingModel" = "Apartment"

[HKCU\Software\Classes\CLSID\{CAFEEFAC-0016-0000-0001-ABCDEFFEDCBB}]
"(Default)" = "Java Plug-in 1.6.0_01"

[HKCU\Software\Classes\CLSID\{CAFEEFAC-0013-0001-0010-ABCDEFFEDCBB}]
"(Default)" = "Java Plug-in 1.3.1_10"

[HKCU\Software\Classes\CLSID\{CAFEEFAC-0015-0000-0014-ABCDEFFEDCBA}\InprocServer32]
"ThreadingModel" = "Apartment"

[HKCU\Software\Classes\CLSID\{CAFEEFAC-0014-0002-0001-ABCDEFFEDCBA}\InprocServer32]
"ThreadingModel" = "Apartment"

[HKCU\Software\Classes\CLSID\{CAFEEFAC-0015-0000-0005-ABCDEFFEDCBC}\InprocServer32]
"(Default)" = "%Program Files%\Java\jre6\bin\jp2iexp.dll"

[HKCU\Software\Classes\CLSID\{CAFEEFAC-0016-0000-0014-ABCDEFFEDCBA}\InprocServer32]
"ThreadingModel" = "Apartment"

[HKCU\Software\Classes\CLSID\{CAFEEFAC-0016-0000-0003-ABCDEFFEDCBB}]
"(Default)" = "Java Plug-in 1.6.0_03"

[HKCU\Software\Classes\CLSID\{CAFEEFAC-0014-0002-0012-ABCDEFFEDCBB}\InprocServer32]
"ThreadingModel" = "Apartment"

[HKCU\Software\Classes\CLSID\{CAFEEFAC-0013-0001-0023-ABCDEFFEDCBA}\InprocServer32]
"(Default)" = "%Program Files%\Java\jre6\bin\jp2iexp.dll"

[HKCU\Software\Classes\CLSID\{CAFEEFAC-0016-0000-0011-ABCDEFFEDCBC}]
"(Default)" = "Java Plug-in 1.6.0_11"

[HKCU\Software\Classes\CLSID\{CAFEEFAC-0013-0001-0007-ABCDEFFEDCBA}\InprocServer32]
"ThreadingModel" = "Apartment"

[HKCU\Software\Classes\CLSID\{CAFEEFAC-0015-0000-0006-ABCDEFFEDCBB}\InprocServer32]
"(Default)" = "%Program Files%\Java\jre6\bin\jp2iexp.dll"

[HKCU\Software\Classes\CLSID\{CAFEEFAC-0013-0001-0001-ABCDEFFEDCBA}\InprocServer32]
"ThreadingModel" = "Apartment"

[HKCU\Software\Classes\CLSID\{CAFEEFAC-0015-0000-0029-ABCDEFFEDCBB}\InprocServer32]
"(Default)" = "%Program Files%\Java\jre6\bin\jp2iexp.dll"

[HKCU\Software\Classes\CLSID\{CAFEEFAC-0014-0002-0018-ABCDEFFEDCBA}\InprocServer32]
"(Default)" = "%Program Files%\Java\jre6\bin\jp2iexp.dll"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{c155cd75-744b-11e2-8294-806d6172696f}]
"BaseClass" = "Drive"

[HKCU\Software\Classes\CLSID\{CAFEEFAC-0016-0000-0015-ABCDEFFEDCBC}\InprocServer32]
"ThreadingModel" = "Apartment"

[HKCU\Software\Classes\CLSID\{CAFEEFAC-0016-0000-0010-ABCDEFFEDCBA}]
"(Default)" = "Java Plug-in 1.6.0_10"

[HKCU\Software\Classes\CLSID\{CAFEEFAC-0015-0000-0030-ABCDEFFEDCBB}]
"(Default)" = "Java Plug-in 1.5.0_30"

[HKCU\Software\Classes\CLSID\{CAFEEFAC-0016-0000-0008-ABCDEFFEDCBC}\InprocServer32]
"(Default)" = "%Program Files%\Java\jre6\bin\jp2iexp.dll"

[HKCU\Software\Classes\CLSID\{CAFEEFAC-0013-0001-0025-ABCDEFFEDCBA}\InprocServer32]
"ThreadingModel" = "Apartment"

[HKCU\Software\Classes\CLSID\{CAFEEFAC-0013-0001-0019-ABCDEFFEDCBA}\InprocServer32]
"(Default)" = "%Program Files%\Java\jre6\bin\jp2iexp.dll"

[HKCU\Software\Classes\CLSID\{CAFEEFAC-0013-0001-0028-ABCDEFFEDCBA}\InprocServer32]
"(Default)" = "%Program Files%\Java\jre6\bin\jp2iexp.dll"

[HKCU\Software\Classes\CLSID\{CAFEEFAC-0014-0000-0004-ABCDEFFEDCBA}]
"(Default)" = "Java Plug-in 1.4.0_04"

[HKCU\Software\Classes\CLSID\{CAFEEFAC-0014-0002-0005-ABCDEFFEDCBA}\InprocServer32]
"(Default)" = "%Program Files%\Java\jre6\bin\jp2iexp.dll"

[HKCU\Software\Classes\CLSID\{CAFEEFAC-0014-0000-0002-ABCDEFFEDCBA}\InprocServer32]
"ThreadingModel" = "Apartment"

[HKCU\Software\Classes\CLSID\{CAFEEFAC-0014-0002-0021-ABCDEFFEDCBB}]
"(Default)" = "Java Plug-in 1.4.2_21"

[HKCU\Software\Classes\CLSID\{CAFEEFAC-0015-0000-0030-ABCDEFFEDCBB}\InprocServer32]
"(Default)" = "%Program Files%\Java\jre6\bin\jp2iexp.dll"

[HKCU\Software\Classes\CLSID\{CAFEEFAC-0014-0002-0027-ABCDEFFEDCBA}]
"(Default)" = "Java Plug-in 1.4.2_27"

[HKCU\Software\Classes\CLSID\{CAFEEFAC-0014-0001-0000-ABCDEFFEDCBB}\InprocServer32]
"(Default)" = "%Program Files%\Java\jre6\bin\jp2iexp.dll"

[HKCU\Software\Classes\CLSID\{CAFEEFAC-0016-0000-0017-ABCDEFFEDCBB}\InprocServer32]
"(Default)" = "%Program Files%\Java\jre6\bin\jp2iexp.dll"

[HKCU\Software\Classes\CLSID\{CAFEEFAC-0015-0000-0020-ABCDEFFEDCBB}\InprocServer32]
"ThreadingModel" = "Apartment"

[HKCU\Software\Classes\CLSID\{CAFEEFAC-0016-0000-0009-ABCDEFFEDCBC}]
"(Default)" = "Java Plug-in 1.6.0_09"

[HKCU\Software\Classes\CLSID\{CAFEEFAC-0015-0000-0005-ABCDEFFEDCBB}\InprocServer32]
"(Default)" = "%Program Files%\Java\jre6\bin\jp2iexp.dll"

[HKCU\Software\Classes\CLSID\{CAFEEFAC-0013-0001-0028-ABCDEFFEDCBA}]
"(Default)" = "Java Plug-in 1.3.1_28"

[HKCU\Software\Classes\CLSID\{CAFEEFAC-0013-0001-0017-ABCDEFFEDCBB}\InprocServer32]
"ThreadingModel" = "Apartment"

[HKCU\Software\Classes\CLSID\{CAFEEFAC-0013-0001-0017-ABCDEFFEDCBA}]
"(Default)" = "Java Plug-in 1.3.1_17"

[HKCU\Software\Classes\CLSID\{CAFEEFAC-0015-0000-0021-ABCDEFFEDCBB}\InprocServer32]
"(Default)" = "%Program Files%\Java\jre6\bin\jp2iexp.dll"

[HKCU\Software\Classes\CLSID\{CAFEEFAC-0016-0000-0012-ABCDEFFEDCBB}]
"(Default)" = "Java Plug-in 1.6.0_12"

[HKCU\Software\Classes\CLSID\{CAFEEFAC-0015-0000-0022-ABCDEFFEDCBC}]
"(Default)" = "Java Plug-in 1.5.0_22"

[HKCU\Software\Classes\CLSID\{CAFEEFAC-0013-0001-0014-ABCDEFFEDCBA}\InprocServer32]
"ThreadingModel" = "Apartment"

[HKCU\Software\Classes\CLSID\{CAFEEFAC-0016-0000-0015-ABCDEFFEDCBB}\InprocServer32]
"ThreadingModel" = "Apartment"

[HKCU\Software\Classes\CLSID\{CAFEEFAC-0016-0000-0006-ABCDEFFEDCBC}\InprocServer32]
"ThreadingModel" = "Apartment"

[HKCU\Software\Classes\CLSID\{CAFEEFAC-0013-0001-0019-ABCDEFFEDCBB}\InprocServer32]
"(Default)" = "%Program Files%\Java\jre6\bin\jp2iexp.dll"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{D27CDB6E-AE6D-11CF-96B8-444553540000}\iexplore]
"Type" = "1"

[HKCU\Software\Classes\CLSID\{CAFEEFAC-0013-0001-0012-ABCDEFFEDCBB}]
"(Default)" = "Java Plug-in 1.3.1_12"

[HKCU\Software\Classes\CLSID\{CAFEEFAC-0015-0000-0024-ABCDEFFEDCBC}\InprocServer32]
"(Default)" = "%Program Files%\Java\jre6\bin\jp2iexp.dll"

[HKCU\Software\Classes\CLSID\{CAFEEFAC-0015-0000-0000-ABCDEFFEDCBC}\InprocServer32]
"(Default)" = "%Program Files%\Java\jre6\bin\jp2iexp.dll"

[HKCU\Software\Classes\CLSID\{CAFEEFAC-0016-0000-0016-ABCDEFFEDCBB}]
"(Default)" = "Java Plug-in 1.6.0_16"

[HKCU\Software\Classes\CLSID\{CAFEEFAC-0014-0002-0006-ABCDEFFEDCBB}\InprocServer32]
"(Default)" = "%Program Files%\Java\jre6\bin\jp2iexp.dll"

[HKCU\Software\Classes\CLSID\{CAFEEFAC-0014-0002-0030-ABCDEFFEDCBA}\InprocServer32]
"(Default)" = "%Program Files%\Java\jre6\bin\jp2iexp.dll"

[HKCU\Software\Classes\CLSID\{CAFEEFAC-0015-0000-0002-ABCDEFFEDCBC}\InprocServer32]
"ThreadingModel" = "Apartment"

[HKCU\Software\Classes\CLSID\{CAFEEFAC-0013-0001-0030-ABCDEFFEDCBB}]
"(Default)" = "Java Plug-in 1.3.1_30"

[HKCU\Software\Classes\CLSID\{CAFEEFAC-0014-0002-0012-ABCDEFFEDCBA}\InprocServer32]
"(Default)" = "%Program Files%\Java\jre6\bin\jp2iexp.dll"

[HKCU\Software\Microsoft\Internet Explorer\DOMStorage\addthis.com]
"(Default)" = "13"

[HKCU\Software\Classes\CLSID\{CAFEEFAC-0015-0000-0020-ABCDEFFEDCBA}\InprocServer32]
"(Default)" = "%Program Files%\Java\jre6\bin\jp2iexp.dll"

[HKCU\Software\Classes\CLSID\{CAFEEFAC-0015-0000-0012-ABCDEFFEDCBA}]
"(Default)" = "Java Plug-in 1.5.0_12"

[HKCU\Software\Classes\CLSID\{CAFEEFAC-0014-0002-0027-ABCDEFFEDCBB}]
"(Default)" = "Java Plug-in 1.4.2_27"

[HKCU\Software\Classes\CLSID\{CAFEEFAC-0014-0001-0003-ABCDEFFEDCBB}\InprocServer32]
"ThreadingModel" = "Apartment"

[HKCU\Software\Classes\CLSID\{CAFEEFAC-0014-0001-0004-ABCDEFFEDCBB}]
"(Default)" = "Java Plug-in 1.4.1_04"

[HKCU\Software\Classes\CLSID\{CAFEEFAC-0016-0000-0007-ABCDEFFEDCBB}\InprocServer32]
"(Default)" = "%Program Files%\Java\jre6\bin\jp2iexp.dll"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{E7E6F031-17CE-4C07-BC86-EABFE594F69C}\iexplore]
"Type" = "3"

[HKCU\Software\Classes\CLSID\{CAFEEFAC-0013-0001-0029-ABCDEFFEDCBB}\InprocServer32]
"(Default)" = "%Program Files%\Java\jre6\bin\jp2iexp.dll"

[HKCU\Software\Classes\CLSID\{CAFEEFAC-0014-0002-0019-ABCDEFFEDCBB}\InprocServer32]
"(Default)" = "%Program Files%\Java\jre6\bin\jp2iexp.dll"

[HKCU\Software\Classes\CLSID\{CAFEEFAC-0016-0000-0005-ABCDEFFEDCBA}\InprocServer32]
"ThreadingModel" = "Apartment"

[HKCU\Software\Classes\CLSID\{CAFEEFAC-0013-0001-0023-ABCDEFFEDCBA}\InprocServer32]
"ThreadingModel" = "Apartment"

[HKCU\Software\Classes\CLSID\{CAFEEFAC-0016-0000-0017-ABCDEFFEDCBB}\InprocServer32]
"ThreadingModel" = "Apartment"

[HKCU\Software\Classes\CLSID\{CAFEEFAC-0014-0002-0029-ABCDEFFEDCBB}\InprocServer32]
"ThreadingModel" = "Apartment"

[HKCU\Software\Classes\CLSID\{CAFEEFAC-0013-0001-0026-ABCDEFFEDCBA}\InprocServer32]
"ThreadingModel" = "Apartment"

[HKCU\Software\Classes\CLSID\{CAFEEFAC-0014-0002-0005-ABCDEFFEDCBB}]
"(Default)" = "Java Plug-in 1.4.2_05"

[HKCU\Software\Classes\CLSID\{CAFEEFAC-0015-0000-0015-ABCDEFFEDCBC}\InprocServer32]
"(Default)" = "%Program Files%\Java\jre6\bin\jp2iexp.dll"

[HKCU\Software\Classes\CLSID\{CAFEEFAC-0015-0000-0002-ABCDEFFEDCBB}\InprocServer32]
"ThreadingModel" = "Apartment"

[HKCU\Software\Classes\CLSID\{CAFEEFAC-0013-0001-0029-ABCDEFFEDCBA}\InprocServer32]
"(Default)" = "%Program Files%\Java\jre6\bin\jp2iexp.dll"

[HKCU\Software\Classes\CLSID\{CAFEEFAC-0015-0000-0017-ABCDEFFEDCBA}\InprocServer32]
"ThreadingModel" = "Apartment"

[HKCU\Software\Classes\CLSID\{CAFEEFAC-0014-0002-0021-ABCDEFFEDCBA}]
"(Default)" = "Java Plug-in 1.4.2_21"

[HKCU\Software\Classes\CLSID\{CAFEEFAC-0014-0002-0028-ABCDEFFEDCBA}\InprocServer32]
"ThreadingModel" = "Apartment"

[HKCU\Software\Classes\CLSID\{CAFEEFAC-0015-0000-0007-ABCDEFFEDCBA}\InprocServer32]
"ThreadingModel" = "Apartment"

[HKCU\Software\Classes\CLSID\{CAFEEFAC-0015-0000-0007-ABCDEFFEDCBB}]
"(Default)" = "Java Plug-in 1.5.0_07"

[HKCU\Software\Classes\CLSID\{CAFEEFAC-0014-0002-0010-ABCDEFFEDCBB}\InprocServer32]
"(Default)" = "%Program Files%\Java\jre6\bin\jp2iexp.dll"

[HKCU\Software\Classes\CLSID\{CAFEEFAC-0014-0002-0000-ABCDEFFEDCBB}\InprocServer32]
"(Default)" = "%Program Files%\Java\jre6\bin\jp2iexp.dll"

[HKCU\Software\Classes\CLSID\{CAFEEFAC-0014-0001-0003-ABCDEFFEDCBA}\InprocServer32]
"ThreadingModel" = "Apartment"

[HKCU\Software\Classes\CLSID\{CAFEEFAC-0013-0001-0003-ABCDEFFEDCBB}]
"(Default)" = "Java Plug-in 1.3.1_03"

[HKCU\Software\Classes\CLSID\{CAFEEFAC-0013-0001-0006-ABCDEFFEDCBB}\InprocServer32]
"ThreadingModel" = "Apartment"

[HKCU\Software\Classes\CLSID\{CAFEEFAC-0016-0000-0009-ABCDEFFEDCBB}\InprocServer32]
"(Default)" = "%Program Files%\Java\jre6\bin\jp2iexp.dll"

[HKCU\Software\Classes\CLSID\{CAFEEFAC-0015-0000-0009-ABCDEFFEDCBA}\InprocServer32]
"ThreadingModel" = "Apartment"

[HKCU\Software\Classes\CLSID\{CAFEEFAC-0015-0000-0030-ABCDEFFEDCBB}\InprocServer32]
"ThreadingModel" = "Apartment"

[HKCU\Software\Classes\CLSID\{CAFEEFAC-0015-0000-0005-ABCDEFFEDCBA}]
"(Default)" = "Java Plug-in 1.5.0_05"

[HKCU\Software\Classes\CLSID\{CAFEEFAC-0015-0000-0011-ABCDEFFEDCBA}\InprocServer32]
"ThreadingModel" = "Apartment"

[HKCU\Software\Classes\CLSID\{CAFEEFAC-0013-0000-0003-ABCDEFFEDCBA}]
"(Default)" = "Java Plug-in 1.3.0_03"

[HKCU\Software\Classes\CLSID\{CAFEEFAC-0015-0000-0004-ABCDEFFEDCBC}\InprocServer32]
"(Default)" = "%Program Files%\Java\jre6\bin\jp2iexp.dll"

[HKCU\Software\Classes\CLSID\{CAFEEFAC-0015-0000-0010-ABCDEFFEDCBA}]
"(Default)" = "Java Plug-in 1.5.0_10"

[HKCU\Software\Classes\CLSID\{CAFEEFAC-0016-0000-0003-ABCDEFFEDCBA}\InprocServer32]
"(Default)" = "%Program Files%\Java\jre6\bin\jp2iexp.dll"

[HKCU\Software\Classes\CLSID\{CAFEEFAC-0015-0000-0012-ABCDEFFEDCBC}\InprocServer32]
"ThreadingModel" = "Apartment"

[HKCU\Software\Classes\CLSID\{CAFEEFAC-0013-0001-0021-ABCDEFFEDCBB}]
"(Default)" = "Java Plug-in 1.3.1_21"

[HKCU\Software\Classes\CLSID\{CAFEEFAC-0015-0000-0000-ABCDEFFEDCBC}\InprocServer32]
"ThreadingModel" = "Apartment"

[HKCU\Software\Classes\CLSID\{CAFEEFAC-0015-0000-0027-ABCDEFFEDCBC}]
"(Default)" = "Java Plug-in 1.5.0_27"

[HKCU\Software\Classes\CLSID\{CAFEEFAC-0013-0001-0025-ABCDEFFEDCBA}]
"(Default)" = "Java Plug-in 1.3.1_25"

[HKCU\Software\Classes\CLSID\{CAFEEFAC-0013-0001-0000-ABCDEFFEDCBA}]
"(Default)" = "Java Plug-in 1.3.1"

[HKCU\Software\Classes\CLSID\{CAFEEFAC-0014-0002-0004-ABCDEFFEDCBB}\InprocServer32]
"ThreadingModel" = "Apartment"

[HKCU\Software\Classes\CLSID\{CAFEEFAC-0016-0000-0017-ABCDEFFEDCBC}\InprocServer32]
"ThreadingModel" = "Apartment"

[HKCU\Software\Classes\CLSID\{CAFEEFAC-0015-0000-0010-ABCDEFFEDCBB}]
"(Default)" = "Java Plug-in 1.5.0_10"

[HKCU\Software\Classes\CLSID\{CAFEEFAC-0014-0002-0010-ABCDEFFEDCBB}]
"(Default)" = "Java Plug-in 1.4.2_10"

[HKCU\Software\Classes\CLSID\{CAFEEFAC-0015-0000-0019-ABCDEFFEDCBA}\InprocServer32]
"ThreadingModel" = "Apartment"

[HKCU\Software\Classes\CLSID\{CAFEEFAC-0015-0000-0009-ABCDEFFEDCBC}\InprocServer32]
"ThreadingModel" = "Apartment"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{c155cd72-744b-11e2-8294-806d6172696f}]
"BaseClass" = "Drive"

[HKCU\Software\Classes\CLSID\{CAFEEFAC-0015-0000-0017-ABCDEFFEDCBC}]
"(Default)" = "Java Plug-in 1.5.0_17"

[HKCU\Software\Classes\CLSID\{CAFEEFAC-0013-0001-0000-ABCDEFFEDCBA}\InprocServer32]
"ThreadingModel" = "Apartment"

[HKCU\Software\Classes\CLSID\{CAFEEFAC-0016-0000-0017-ABCDEFFEDCBC}\InprocServer32]
"(Default)" = "%Program Files%\Java\jre6\bin\jp2iexp.dll"

[HKCU\Software\Classes\CLSID\{CAFEEFAC-0013-0001-0001-ABCDEFFEDCBB}\InprocServer32]
"ThreadingModel" = "Apartment"

[HKCU\Software\Classes\CLSID\{CAFEEFAC-0016-0000-0014-ABCDEFFEDCBA}]
"(Default)" = "Java Plug-in 1.6.0_14"

[HKCU\Software\Classes\CLSID\{CAFEEFAC-0014-0000-0002-ABCDEFFEDCBA}\InprocServer32]
"(Default)" = "%Program Files%\Java\jre6\bin\jp2iexp.dll"

[HKCU\Software\Classes\CLSID\{CAFEEFAC-0015-0000-0002-ABCDEFFEDCBA}\InprocServer32]
"(Default)" = "%Program Files%\Java\jre6\bin\jp2iexp.dll"

[HKCU\Software\Classes\CLSID\{CAFEEFAC-0015-0000-0027-ABCDEFFEDCBA}]
"(Default)" = "Java Plug-in 1.5.0_27"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{DBC80044-A445-435B-BC74-9C25C1C588A9}\iexplore]
"Type" = "3"

[HKCU\Software\Classes\CLSID\{CAFEEFAC-0015-0000-0003-ABCDEFFEDCBB}\InprocServer32]
"ThreadingModel" = "Apartment"

[HKCU\Software\Classes\CLSID\{CAFEEFAC-0016-0000-0009-ABCDEFFEDCBA}\InprocServer32]
"(Default)" = "%Program Files%\Java\jre6\bin\jp2iexp.dll"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Connections]
"SavedLegacySettings" = "46 00 00 00 3F 00 00 00 01 00 00 00 00 00 00 00"

[HKCU\Software\Classes\CLSID\{CAFEEFAC-0016-0000-0006-ABCDEFFEDCBA}\InprocServer32]
"ThreadingModel" = "Apartment"

[HKCU\Software\Classes\CLSID\{CAFEEFAC-0013-0001-0014-ABCDEFFEDCBB}\InprocServer32]
"ThreadingModel" = "Apartment"

[HKCU\Software\Classes\CLSID\{CAFEEFAC-0014-0002-0013-ABCDEFFEDCBB}\InprocServer32]
"(Default)" = "%Program Files%\Java\jre6\bin\jp2iexp.dll"

[HKCU\Software\Classes\CLSID\{CAFEEFAC-0014-0002-0026-ABCDEFFEDCBA}\InprocServer32]
"(Default)" = "%Program Files%\Java\jre6\bin\jp2iexp.dll"

[HKCU\Software\Classes\CLSID\{CAFEEFAC-0013-0001-0013-ABCDEFFEDCBA}\InprocServer32]
"(Default)" = "%Program Files%\Java\jre6\bin\jp2iexp.dll"

[HKCU\Software\Classes\CLSID\{CAFEEFAC-0015-0000-0007-ABCDEFFEDCBC}]
"(Default)" = "Java Plug-in 1.5.0_07"

[HKCU\Software\Classes\CLSID\{CAFEEFAC-0013-0001-0018-ABCDEFFEDCBA}\InprocServer32]
"(Default)" = "%Program Files%\Java\jre6\bin\jp2iexp.dll"

[HKCU\Software\Classes\CLSID\{CAFEEFAC-0015-0000-0026-ABCDEFFEDCBB}\InprocServer32]
"ThreadingModel" = "Apartment"

[HKCU\Software\Classes\CLSID\{CAFEEFAC-0013-0001-0009-ABCDEFFEDCBA}\InprocServer32]
"ThreadingModel" = "Apartment"

[HKCU\Software\Classes\CLSID\{CAFEEFAC-0014-0001-0001-ABCDEFFEDCBA}\InprocServer32]
"ThreadingModel" = "Apartment"

[HKCU\Software\Classes\CLSID\{CAFEEFAC-0013-0001-0012-ABCDEFFEDCBA}]
"(Default)" = "Java Plug-in 1.3.1_12"

[HKCU\Software\Classes\CLSID\{CAFEEFAC-0014-0002-0022-ABCDEFFEDCBB}]
"(Default)" = "Java Plug-in 1.4.2_22"

[HKCU\Software\Classes\CLSID\{CAFEEFAC-0013-0001-0006-ABCDEFFEDCBA}]
"(Default)" = "Java Plug-in 1.3.1_06"

[HKCU\Software\Classes\CLSID\{CAFEEFAC-0013-0001-0007-ABCDEFFEDCBA}\InprocServer32]
"(Default)" = "%Program Files%\Java\jre6\bin\jp2iexp.dll"

[HKCU\Software\Classes\CLSID\{CAFEEFAC-0013-0001-0008-ABCDEFFEDCBB}\InprocServer32]
"ThreadingModel" = "Apartment"

[HKCU\Software\Classes\CLSID\{CAFEEFAC-0014-0002-0029-ABCDEFFEDCBA}]
"(Default)" = "Java Plug-in 1.4.2_29"

[HKCU\Software\Classes\CLSID\{CAFEEFAC-0015-0000-0023-ABCDEFFEDCBC}\InprocServer32]
"(Default)" = "%Program Files%\Java\jre6\bin\jp2iexp.dll"

[HKCU\Software\Classes\CLSID\{CAFEEFAC-0016-0000-0016-ABCDEFFEDCBC}\InprocServer32]
"(Default)" = "%Program Files%\Java\jre6\bin\jp2iexp.dll"

[HKCU\Software\Classes\CLSID\{CAFEEFAC-0014-0002-0003-ABCDEFFEDCBB}]
"(Default)" = "Java Plug-in 1.4.2_03"

[HKCU\Software\Classes\CLSID\{CAFEEFAC-0015-0000-0012-ABCDEFFEDCBA}\InprocServer32]
"ThreadingModel" = "Apartment"

[HKCU\Software\Classes\CLSID\{CAFEEFAC-0016-0000-0009-ABCDEFFEDCBB}]
"(Default)" = "Java Plug-in 1.6.0_09"

[HKCU\Software\Classes\CLSID\{CAFEEFAC-0013-0001-0020-ABCDEFFEDCBA}\InprocServer32]
"(Default)" = "%Program Files%\Java\jre6\bin\jp2iexp.dll"

[HKCU\Software\Classes\CLSID\{CAFEEFAC-0014-0000-0001-ABCDEFFEDCBB}]
"(Default)" = "Java Plug-in 1.4.0_01"

[HKCU\Software\Classes\CLSID\{CAFEEFAC-0016-0000-0006-ABCDEFFEDCBB}\InprocServer32]
"(Default)" = "%Program Files%\Java\jre6\bin\jp2iexp.dll"

[HKCU\Software\Classes\CLSID\{CAFEEFAC-0016-0000-0009-ABCDEFFEDCBB}\InprocServer32]
"ThreadingModel" = "Apartment"

[HKCU\Software\Classes\CLSID\{CAFEEFAC-0014-0002-0013-ABCDEFFEDCBA}]
"(Default)" = "Java Plug-in 1.4.2_13"

[HKCU\Software\Classes\CLSID\{CAFEEFAC-0014-0000-0002-ABCDEFFEDCBB}]
"(Default)" = "Java Plug-in 1.4.0_02"

[HKCU\Software\Classes\CLSID\{CAFEEFAC-0013-0001-0007-ABCDEFFEDCBA}]
"(Default)" = "Java Plug-in 1.3.1_07"

[HKCU\Software\Classes\CLSID\{CAFEEFAC-0014-0001-0007-ABCDEFFEDCBA}\InprocServer32]
"(Default)" = "%Program Files%\Java\jre6\bin\jp2iexp.dll"

[HKCU\Software\Classes\CLSID\{CAFEEFAC-0016-0000-0002-ABCDEFFEDCBA}\InprocServer32]
"ThreadingModel" = "Apartment"

[HKCU\Software\Classes\CLSID\{CAFEEFAC-0014-0002-0026-ABCDEFFEDCBB}\InprocServer32]
"ThreadingModel" = "Apartment"

[HKCU\Software\Classes\CLSID\{CAFEEFAC-0015-0000-0013-ABCDEFFEDCBC}]
"(Default)" = "Java Plug-in 1.5.0_13"

[HKCU\Software\Classes\CLSID\{CAFEEFAC-0016-0000-0006-ABCDEFFEDCBA}\InprocServer32]
"(Default)" = "%Program Files%\Java\jre6\bin\jp2iexp.dll"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{E7E6F031-17CE-4C07-BC86-EABFE594F69C}\iexplore]
"Count" = "28"

[HKCU\Software\Classes\CLSID\{CAFEEFAC-0015-0000-0025-ABCDEFFEDCBA}\InprocServer32]
"ThreadingModel" = "Apartment"

[HKCU\Software\Classes\CLSID\{CAFEEFAC-0015-0000-0030-ABCDEFFEDCBA}\InprocServer32]
"(Default)" = "%Program Files%\Java\jre6\bin\jp2iexp.dll"

[HKCU\Software\Classes\CLSID\{CAFEEFAC-0014-0000-0003-ABCDEFFEDCBB}\InprocServer32]
"(Default)" = "%Program Files%\Java\jre6\bin\jp2iexp.dll"

[HKCU\Software\Classes\CLSID\{CAFEEFAC-0015-0000-0006-ABCDEFFEDCBC}\InprocServer32]
"ThreadingModel" = "Apartment"

[HKCU\Software\Classes\CLSID\{CAFEEFAC-0016-0000-0004-ABCDEFFEDCBC}]
"(Default)" = "Java Plug-in 1.6.0_04"

[HKCU\Software\Classes\CLSID\{CAFEEFAC-0016-0000-0008-ABCDEFFEDCBA}\InprocServer32]
"(Default)" = "%Program Files%\Java\jre6\bin\jp2iexp.dll"

[HKCU\Software\Classes\CLSID\{CAFEEFAC-0014-0001-0006-ABCDEFFEDCBB}\InprocServer32]
"ThreadingModel" = "Apartment"

[HKCU\Software\Classes\CLSID\{CAFEEFAC-0014-0002-0028-ABCDEFFEDCBB}\InprocServer32]
"(Default)" = "%Program Files%\Java\jre6\bin\jp2iexp.dll"

[HKCU\Software\Classes\CLSID\{CAFEEFAC-0013-0001-0028-ABCDEFFEDCBA}\InprocServer32]
"ThreadingModel" = "Apartment"

[HKCU\Software\Classes\CLSID\{CAFEEFAC-0015-0000-FFFF-ABCDEFFEDCBA}\InprocServer32]
"(Default)" = "%Program Files%\Java\jre6\bin\jp2iexp.dll"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{b98117e8-75ca-11e2-81b2-000c293708fb}]
"BaseClass" = "Drive"

[HKCU\Software\Classes\CLSID\{CAFEEFAC-0014-0002-0003-ABCDEFFEDCBA}\InprocServer32]
"(Default)" = "%Program Files%\Java\jre6\bin\jp2iexp.dll"

[HKCU\Software\Classes\CLSID\{CAFEEFAC-0016-0000-0000-ABCDEFFEDCBB}\InprocServer32]
"(Default)" = "%Program Files%\Java\jre6\bin\jp2iexp.dll"

[HKCU\Software\Classes\CLSID\{CAFEEFAC-0016-0000-0008-ABCDEFFEDCBB}]
"(Default)" = "Java Plug-in 1.6.0_08"

[HKCU\Software\Classes\CLSID\{CAFEEFAC-0014-0002-0008-ABCDEFFEDCBA}\InprocServer32]
"ThreadingModel" = "Apartment"

[HKCU\Software\Classes\CLSID\{CAFEEFAC-0013-0001-0024-ABCDEFFEDCBB}\InprocServer32]
"(Default)" = "%Program Files%\Java\jre6\bin\jp2iexp.dll"

[HKCU\Software\Classes\CLSID\{CAFEEFAC-0015-0000-0013-ABCDEFFEDCBA}\InprocServer32]
"ThreadingModel" = "Apartment"

[HKCU\Software\Classes\CLSID\{CAFEEFAC-0016-0000-0002-ABCDEFFEDCBC}\InprocServer32]
"ThreadingModel" = "Apartment"

[HKCU\Software\Classes\CLSID\{CAFEEFAC-0013-0001-0009-ABCDEFFEDCBA}]
"(Default)" = "Java Plug-in 1.3.1_09"

[HKCU\Software\Classes\CLSID\{CAFEEFAC-0014-0002-0016-ABCDEFFEDCBB}]
"(Default)" = "Java Plug-in 1.4.2_16"

[HKCU\Software\Classes\CLSID\{CAFEEFAC-0016-0000-0000-ABCDEFFEDCBB}]
"(Default)" = "Java Plug-in 1.6.0"

[HKCU\Software\Classes\CLSID\{CAFEEFAC-0015-0000-0026-ABCDEFFEDCBA}\InprocServer32]
"ThreadingModel" = "Apartment"

[HKCU\Software\Classes\CLSID\{CAFEEFAC-0013-0001-0025-ABCDEFFEDCBB}\InprocServer32]
"(Default)" = "%Program Files%\Java\jre6\bin\jp2iexp.dll"

[HKCU\Software\Classes\CLSID\{CAFEEFAC-0014-0002-0010-ABCDEFFEDCBA}\InprocServer32]
"(Default)" = "%Program Files%\Java\jre6\bin\jp2iexp.dll"

[HKCU\Software\Classes\CLSID\{CAFEEFAC-0015-0000-0016-ABCDEFFEDCBC}]
"(Default)" = "Java Plug-in 1.5.0_16"

[HKCU\Software\Classes\CLSID\{CAFEEFAC-0016-0000-0009-ABCDEFFEDCBC}\InprocServer32]
"(Default)" = "%Program Files%\Java\jre6\bin\jp2iexp.dll"

[HKCU\Software\Classes\CLSID\{CAFEEFAC-0013-0001-0030-ABCDEFFEDCBB}\InprocServer32]
"(Default)" = "%Program Files%\Java\jre6\bin\jp2iexp.dll"

[HKCU\Software\Classes\CLSID\{CAFEEFAC-0013-0001-0022-ABCDEFFEDCBB}]
"(Default)" = "Java Plug-in 1.3.1_22"

[HKCU\Software\Classes\CLSID\{CAFEEFAC-0014-0002-0015-ABCDEFFEDCBA}\InprocServer32]
"ThreadingModel" = "Apartment"

[HKCU\Software\Classes\CLSID\{CAFEEFAC-0015-0000-0022-ABCDEFFEDCBC}\InprocServer32]
"(Default)" = "%Program Files%\Java\jre6\bin\jp2iexp.dll"

[HKCU\Software\Classes\CLSID\{CAFEEFAC-0014-0002-0020-ABCDEFFEDCBB}\InprocServer32]
"(Default)" = "%Program Files%\Java\jre6\bin\jp2iexp.dll"

[HKCU\Software\Classes\CLSID\{CAFEEFAC-0015-0000-0013-ABCDEFFEDCBB}\InprocServer32]
"(Default)" = "%Program Files%\Java\jre6\bin\jp2iexp.dll"

[HKCU\Software\Classes\CLSID\{CAFEEFAC-0014-0001-0006-ABCDEFFEDCBA}\InprocServer32]
"ThreadingModel" = "Apartment"

[HKCU\Software\Classes\CLSID\{CAFEEFAC-0015-0000-0004-ABCDEFFEDCBB}]
"(Default)" = "Java Plug-in 1.5.0_04"

[HKCU\Software\Classes\CLSID\{CAFEEFAC-0016-0000-0003-ABCDEFFEDCBA}]
"(Default)" = "Java Plug-in 1.6.0_03"

[HKCU\Software\Classes\CLSID\{CAFEEFAC-0014-0001-0004-ABCDEFFEDCBA}]
"(Default)" = "Java Plug-in 1.4.1_04"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{c155cd73-744b-11e2-8294-806d6172696f}]
"BaseClass" = "Drive"

[HKCU\Software\Classes\CLSID\{CAFEEFAC-0014-0002-0006-ABCDEFFEDCBB}]
"(Default)" = "Java Plug-in 1.4.2_06"

[HKCU\Software\Classes\CLSID\{CAFEEFAC-0015-0000-0014-ABCDEFFEDCBB}]
"(Default)" = "Java Plug-in 1.5.0_14"

[HKCU\Software\Classes\CLSID\{CAFEEFAC-0014-0002-0007-ABCDEFFEDCBB}]
"(Default)" = "Java Plug-in 1.4.2_07"

[HKCU\Software\Classes\CLSID\{CAFEEFAC-0016-0000-0012-ABCDEFFEDCBC}\InprocServer32]
"(Default)" = "%Program Files%\Java\jre6\bin\jp2iexp.dll"

[HKCU\Software\Classes\CLSID\{CAFEEFAC-0013-0001-0007-ABCDEFFEDCBB}\InprocServer32]
"(Default)" = "%Program Files%\Java\jre6\bin\jp2iexp.dll"

[HKCU\Software\Classes\CLSID\{CAFEEFAC-0013-0001-0001-ABCDEFFEDCBA}\InprocServer32]
"(Default)" = "%Program Files%\Java\jre6\bin\jp2iexp.dll"

[HKCU\Software\Classes\CLSID\{E19F9331-3110-11D4-991C-005004D3B3DB}]
"(Default)" = "Java Plug-in 1.3.0_02"

[HKCU\Software\Classes\CLSID\{CAFEEFAC-0015-0000-0003-ABCDEFFEDCBB}\InprocServer32]
"(Default)" = "%Program Files%\Java\jre6\bin\jp2iexp.dll"

[HKCU\Software\Classes\CLSID\{CAFEEFAC-0015-0000-0024-ABCDEFFEDCBC}\InprocServer32]
"ThreadingModel" = "Apartment"

[HKCU\Software\Classes\CLSID\{CAFEEFAC-0013-0001-0018-ABCDEFFEDCBB}\InprocServer32]
"ThreadingModel" = "Apartment"

[HKCU\Software\Classes\CLSID\{CAFEEFAC-0014-0002-0014-ABCDEFFEDCBA}\InprocServer32]
"(Default)" = "%Program Files%\Java\jre6\bin\jp2iexp.dll"

[HKCU\Software\Classes\CLSID\{CAFEEFAC-0016-0000-0010-ABCDEFFEDCBB}]
"(Default)" = "Java Plug-in 1.6.0_10"

[HKCU\Software\Classes\CLSID\{CAFEEFAC-0015-0000-0010-ABCDEFFEDCBA}\InprocServer32]
"(Default)" = "%Program Files%\Java\jre6\bin\jp2iexp.dll"

[HKCU\Software\Classes\CLSID\{CAFEEFAC-0015-0000-0025-ABCDEFFEDCBC}]
"(Default)" = "Java Plug-in 1.5.0_25"

[HKCU\Software\Classes\CLSID\{CAFEEFAC-0015-0000-0011-ABCDEFFEDCBC}]
"(Default)" = "Java Plug-in 1.5.0_11"

[HKCU\Software\Classes\CLSID\{CAFEEFAC-0016-0000-0016-ABCDEFFEDCBB}\InprocServer32]
"ThreadingModel" = "Apartment"

[HKCU\Software\Classes\CLSID\{CAFEEFAC-0014-0002-0011-ABCDEFFEDCBB}\InprocServer32]
"(Default)" = "%Program Files%\Java\jre6\bin\jp2iexp.dll"

[HKCU\Software\Classes\CLSID\{CAFEEFAC-0016-0000-0013-ABCDEFFEDCBB}\InprocServer32]
"ThreadingModel" = "Apartment"

[HKCU\Software\Classes\CLSID\{CAFEEFAC-0015-0000-0018-ABCDEFFEDCBA}]
"(Default)" = "Java Plug-in 1.5.0_18"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{18DF081C-E8AD-4283-A596-FA578C2EBDC3}\iexplore]
"Time" = "DE 07 05 00 02 00 0D 00 0E 00 38 00 07 00 D8 02"

[HKCU\Software\Classes\CLSID\{CAFEEFAC-0015-0000-0019-ABCDEFFEDCBA}\InprocServer32]
"(Default)" = "%Program Files%\Java\jre6\bin\jp2iexp.dll"

[HKCU\Software\Classes\CLSID\{CAFEEFAC-0013-0001-0025-ABCDEFFEDCBB}\InprocServer32]
"ThreadingModel" = "Apartment"

[HKCU\Software\Classes\CLSID\{CAFEEFAC-0015-0000-0009-ABCDEFFEDCBB}]
"(Default)" = "Java Plug-in 1.5.0_09"

[HKCU\Software\Classes\CLSID\{CAFEEFAC-0015-0000-0027-ABCDEFFEDCBA}\InprocServer32]
"(Default)" = "%Program Files%\Java\jre6\bin\jp2iexp.dll"
"ThreadingModel" = "Apartment"

[HKCU\Software\Classes\CLSID\{CAFEEFAC-0016-0000-0001-ABCDEFFEDCBB}\InprocServer32]
"(Default)" = "%Program Files%\Java\jre6\bin\jp2iexp.dll"

[HKCU\Software\Classes\CLSID\{CAFEEFAC-0015-0000-0021-ABCDEFFEDCBC}\InprocServer32]
"(Default)" = "%Program Files%\Java\jre6\bin\jp2iexp.dll"

[HKCU\Software\Classes\CLSID\{CAFEEFAC-0016-0000-0017-ABCDEFFEDCBB}]
"(Default)" = "Java Plug-in 1.6.0_17"

[HKCU\Software\Classes\CLSID\{CAFEEFAC-0015-0000-0030-ABCDEFFEDCBA}\InprocServer32]
"ThreadingModel" = "Apartment"

[HKCU\Software\Classes\CLSID\{CAFEEFAC-0014-0001-0000-ABCDEFFEDCBA}\InprocServer32]
"ThreadingModel" = "Apartment"

[HKCU\Software\Classes\CLSID\{CAFEEFAC-0015-0000-0008-ABCDEFFEDCBB}]
"(Default)" = "Java Plug-in 1.5.0_08"

[HKCU\Software\Classes\CLSID\{CAFEEFAC-0016-0000-0001-ABCDEFFEDCBA}\InprocServer32]
"(Default)" = "%Program Files%\Java\jre6\bin\jp2iexp.dll"

[HKCU\Software\Classes\CLSID\{CAFEEFAC-0016-0000-0010-ABCDEFFEDCBC}\InprocServer32]
"ThreadingModel" = "Apartment"

[HKCU\Software\Classes\CLSID\{CAFEEFAC-0014-0002-0004-ABCDEFFEDCBB}\InprocServer32]
"(Default)" = "%Program Files%\Java\jre6\bin\jp2iexp.dll"

[HKCU\Software\Classes\CLSID\{CAFEEFAC-0015-0000-0008-ABCDEFFEDCBA}\InprocServer32]
"ThreadingModel" = "Apartment"

[HKCU\Software\Classes\CLSID\{CAFEEFAC-0014-0002-0024-ABCDEFFEDCBA}\InprocServer32]
"(Default)" = "%Program Files%\Java\jre6\bin\jp2iexp.dll"

[HKCU\Software\Classes\CLSID\{CAFEEFAC-0015-0000-0017-ABCDEFFEDCBA}]
"(Default)" = "Java Plug-in 1.5.0_17"

[HKCU\Software\Classes\CLSID\{8AD9C840-044E-11D1-B3E9-00805F499D93}\InprocServer32]
"(Default)" = "%Program Files%\Java\jre6\bin\jp2iexp.dll"

[HKCU\Software\Classes\CLSID\{CAFEEFAC-0014-0002-0020-ABCDEFFEDCBA}\InprocServer32]
"(Default)" = "%Program Files%\Java\jre6\bin\jp2iexp.dll"

[HKCU\Software\Classes\CLSID\{CAFEEFAC-0013-0001-0019-ABCDEFFEDCBA}\InprocServer32]
"ThreadingModel" = "Apartment"

[HKCU\Software\Classes\CLSID\{CAFEEFAC-0016-0000-0005-ABCDEFFEDCBC}]
"(Default)" = "Java Plug-in 1.6.0_05"

[HKCU\Software\Classes\CLSID\{CAFEEFAC-0013-0000-0005-ABCDEFFEDCBA}\InprocServer32]
"(Default)" = "%Program Files%\Java\jre6\bin\jp2iexp.dll"

[HKCU\Software\Classes\JavaPlugin.160_18\CLSID]
"(Default)" = "{5852F5ED-8BF4-11D4-A245-0080C6F74284}"

[HKCU\Software\Classes\CLSID\{CAFEEFAC-0013-0001-0016-ABCDEFFEDCBA}]
"(Default)" = "Java Plug-in 1.3.1_16"

[HKCU\Software\Classes\CLSID\{CAFEEFAC-0016-0000-0015-ABCDEFFEDCBB}]
"(Default)" = "Java Plug-in 1.6.0_15"

[HKCU\Software\Classes\CLSID\{CAFEEFAC-0014-0002-0004-ABCDEFFEDCBA}\InprocServer32]
"ThreadingModel" = "Apartment"

[HKCU\Software\Classes\CLSID\{CAFEEFAC-0013-0001-0010-ABCDEFFEDCBA}\InprocServer32]
"ThreadingModel" = "Apartment"

[HKCU\Software\Classes\CLSID\{CAFEEFAC-0014-0002-0000-ABCDEFFEDCBA}]
"(Default)" = "Java Plug-in 1.4.2"

[HKCU\Software\Classes\CLSID\{CAFEEFAC-0014-0002-0016-ABCDEFFEDCBB}\InprocServer32]
"ThreadingModel" = "Apartment"

[HKCU\Software\Classes\CLSID\{CAFEEFAC-0015-0000-0024-ABCDEFFEDCBC}]
"(Default)" = "Java Plug-in 1.5.0_24"

[HKCU\Software\Classes\CLSID\{CAFEEFAC-0015-0000-0030-ABCDEFFEDCBC}\InprocServer32]
"(Default)" = "%Program Files%\Java\jre6\bin\jp2iexp.dll"

[HKCU\Software\Classes\CLSID\{CAFEEFAC-0013-0001-0020-ABCDEFFEDCBA}\InprocServer32]
"ThreadingModel" = "Apartment"

[HKCU\Software\Classes\CLSID\{CAFEEFAC-0016-0000-0013-ABCDEFFEDCBA}\InprocServer32]
"(Default)" = "%Program Files%\Java\jre6\bin\jp2iexp.dll"

[HKCU\Software\Classes\CLSID\{CAFEEFAC-0013-0001-0015-ABCDEFFEDCBB}\InprocServer32]
"ThreadingModel" = "Apartment"

[HKCU\Software\Classes\CLSID\{CAFEEFAC-0013-0001-0015-ABCDEFFEDCBA}\InprocServer32]
"(Default)" = "%Program Files%\Java\jre6\bin\jp2iexp.dll"

[HKCU\Software\Classes\CLSID\{CAFEEFAC-0014-0000-0001-ABCDEFFEDCBA}\InprocServer32]
"ThreadingModel" = "Apartment"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{DBC80044-A445-435B-BC74-9C25C1C588A9}\iexplore]
"LoadTime" = "550"

[HKCU\Software\Classes\CLSID\{CAFEEFAC-0013-0001-0018-ABCDEFFEDCBB}]
"(Default)" = "Java Plug-in 1.3.1_18"

[HKCU\Software\Classes\CLSID\{CAFEEFAC-0013-0001-0026-ABCDEFFEDCBB}\InprocServer32]
"(Default)" = "%Program Files%\Java\jre6\bin\jp2iexp.dll"

[HKCU\Software\Classes\CLSID\{CAFEEFAC-0013-0001-0005-ABCDEFFEDCBB}]
"(Default)" = "Java Plug-in 1.3.1_05"

[HKCU\Software\Classes\CLSID\{CAFEEFAC-0016-0000-0005-ABCDEFFEDCBA}\InprocServer32]
"(Default)" = "%Program Files%\Java\jre6\bin\jp2iexp.dll"

[HKCU\Software\Classes\CLSID\{CAFEEFAC-0014-0001-0000-ABCDEFFEDCBB}\InprocServer32]
"ThreadingModel" = "Apartment"

[HKCU\Software\Classes\CLSID\{CAFEEFAC-0014-0002-0015-ABCDEFFEDCBB}\InprocServer32]
"(Default)" = "%Program Files%\Java\jre6\bin\jp2iexp.dll"

[HKCU\Software\Classes\CLSID\{CAFEEFAC-0014-0002-0002-ABCDEFFEDCBA}]
"(Default)" = "Java Plug-in 1.4.2_02"

[HKCU\Software\Classes\CLSID\{CAFEEFAC-0015-0000-0029-ABCDEFFEDCBA}\InprocServer32]
"(Default)" = "%Program Files%\Java\jre6\bin\jp2iexp.dll"

[HKCU\Software\Classes\CLSID\{CAFEEFAC-0015-0000-0007-ABCDEFFEDCBB}\InprocServer32]
"ThreadingModel" = "Apartment"

[HKCU\Software\Classes\CLSID\{CAFEEFAC-0014-0002-0026-ABCDEFFEDCBB}]
"(Default)" = "Java Plug-in 1.4.2_26"

[HKCU\Software\Classes\CLSID\{CAFEEFAC-0014-0002-0019-ABCDEFFEDCBA}\InprocServer32]
"ThreadingModel" = "Apartment"

[HKCU\Software\Classes\CLSID\{CAFEEFAC-0016-0000-0016-ABCDEFFEDCBA}\InprocServer32]
"ThreadingModel" = "Apartment"

[HKCU\Software\Classes\CLSID\{8AD9C840-044E-11D1-B3E9-00805F499D93}\InprocServer32]
"ThreadingModel" = "Apartment"

[HKCU\Software\Classes\CLSID\{CAFEEFAC-0016-0000-0001-ABCDEFFEDCBC}]
"(Default)" = "Java Plug-in 1.6.0_01"

[HKCU\Software\Classes\CLSID\{CAFEEFAC-0013-0001-0002-ABCDEFFEDCBA}]
"(Default)" = "Java Plug-in 1.3.1_02"

[HKCU\Software\Classes\CLSID\{CAFEEFAC-0014-0002-0023-ABCDEFFEDCBA}\InprocServer32]
"ThreadingModel" = "Apartment"

[HKCU\Software\Classes\CLSID\{CAFEEFAC-0014-0002-0025-ABCDEFFEDCBA}\InprocServer32]
"ThreadingModel" = "Apartment"

[HKCU\Software\Classes\CLSID\{CAFEEFAC-0015-0000-0030-ABCDEFFEDCBC}\InprocServer32]
"ThreadingModel" = "Apartment"

[HKCU\Software\Classes\CLSID\{CAFEEFAC-0015-0000-0002-ABCDEFFEDCBC}]
"(Default)" = "Java Plug-in 1.5.0_02"

[HKCU\Software\Classes\CLSID\{CAFEEFAC-0016-0000-0013-ABCDEFFEDCBC}\InprocServer32]
"ThreadingModel" = "Apartment"

[HKCU\Software\Classes\CLSID\{CAFEEFAC-0015-0000-0021-ABCDEFFEDCBB}\InprocServer32]
"ThreadingModel" = "Apartment"

[HKCU\Software\Classes\CLSID\{CAFEEFAC-0014-0001-0006-ABCDEFFEDCBB}\InprocServer32]
"(Default)" = "%Program Files%\Java\jre6\bin\jp2iexp.dll"

[HKCU\Software\Classes\CLSID\{CAFEEFAC-0015-0000-0020-ABCDEFFEDCBC}]
"(Default)" = "Java Plug-in 1.5.0_20"

[HKCU\Software\Classes\CLSID\{CAFEEFAC-0015-0000-0012-ABCDEFFEDCBC}]
"(Default)" = "Java Plug-in 1.5.0_12"

[HKCU\Software\Classes\CLSID\{CAFEEFAC-0016-0000-0009-ABCDEFFEDCBA}]
"(Default)" = "Java Plug-in 1.6.0_09"

[HKCU\Software\Classes\CLSID\{CAFEEFAC-0014-0002-0021-ABCDEFFEDCBB}\InprocServer32]
"(Default)" = "%Program Files%\Java\jre6\bin\jp2iexp.dll"

[HKCU\Software\Classes\CLSID\{CAFEEFAC-0014-0000-0003-ABCDEFFEDCBA}\InprocServer32]
"(Default)" = "%Program Files%\Java\jre6\bin\jp2iexp.dll"

[HKCU\Software\Classes\CLSID\{CAFEEFAC-0015-0000-0013-ABCDEFFEDCBA}]
"(Default)" = "Java Plug-in 1.5.0_13"

[HKCU\Software\Classes\CLSID\{CAFEEFAC-0014-0002-0010-ABCDEFFEDCBA}\InprocServer32]
"ThreadingModel" = "Apartment"

[HKCU\Software\Classes\CLSID\{CAFEEFAC-0015-0000-0015-ABCDEFFEDCBC}\InprocServer32]
"ThreadingModel" = "Apartment"

[HKCU\Software\Classes\CLSID\{CAFEEFAC-0016-0000-0018-ABCDEFFEDCBA}]
"(Default)" = "Java Plug-in 1.6.0_18"

[HKCU\Software\Classes\CLSID\{CAFEEFAC-0016-0000-0004-ABCDEFFEDCBB}\InprocServer32]
"ThreadingModel" = "Apartment"

[HKCU\Software\Classes\CLSID\{CAFEEFAC-0016-0000-0015-ABCDEFFEDCBA}\InprocServer32]
"(Default)" = "%Program Files%\Java\jre6\bin\jp2iexp.dll"

[HKCU\Software\Classes\CLSID\{CAFEEFAC-0015-0000-0025-ABCDEFFEDCBA}\InprocServer32]
"(Default)" = "%Program Files%\Java\jre6\bin\jp2iexp.dll"

[HKCU\Software\Classes\CLSID\{CAFEEFAC-0014-0001-0002-ABCDEFFEDCBA}\InprocServer32]
"(Default)" = "%Program Files%\Java\jre6\bin\jp2iexp.dll"

[HKCU\Software\Classes\CLSID\{CAFEEFAC-0015-0000-0013-ABCDEFFEDCBC}\InprocServer32]
"ThreadingModel" = "Apartment"

[HKCU\Software\Classes\CLSID\{CAFEEFAC-0015-0000-0021-ABCDEFFEDCBA}\InprocServer32]
"(Default)" = "%Program Files%\Java\jre6\bin\jp2iexp.dll"

[HKCU\Software\Classes\CLSID\{CAFEEFAC-0014-0002-0006-ABCDEFFEDCBA}\InprocServer32]
"(Default)" = "%Program Files%\Java\jre6\bin\jp2iexp.dll"

[HKCU\Software\Classes\CLSID\{CAFEEFAC-0015-0000-0000-ABCDEFFEDCBB}\InprocServer32]
"ThreadingModel" = "Apartment"

[HKCU\Software\Classes\CLSID\{CAFEEFAC-0015-0000-0014-ABCDEFFEDCBA}\InprocServer32]
"(Default)" = "%Program Files%\Java\jre6\bin\jp2iexp.dll"

[HKCU\Software\Classes\CLSID\{CAFEEFAC-0016-0000-0007-ABCDEFFEDCBC}\InprocServer32]
"(Default)" = "%Program Files%\Java\jre6\bin\jp2iexp.dll"

[HKCU\Software\Classes\CLSID\{CAFEEFAC-0016-0000-0016-ABCDEFFEDCBC}\InprocServer32]
"ThreadingModel" = "Apartment"

[HKCU\Software\Classes\CLSID\{CAFEEFAC-0015-0000-0008-ABCDEFFEDCBB}\InprocServer32]
"(Default)" = "%Program Files%\Java\jre6\bin\jp2iexp.dll"

[HKCU\Software\Classes\CLSID\{CAFEEFAC-0016-0000-0008-ABCDEFFEDCBB}\InprocServer32]
"ThreadingModel" = "Apartment"

[HKCU\Software\Classes\CLSID\{CAFEEFAC-0015-0000-0001-ABCDEFFEDCBC}\InprocServer32]
"ThreadingModel" = "Apartment"

[HKCU\Software\Classes\CLSID\{CAFEEFAC-0016-0000-0012-ABCDEFFEDCBB}\InprocServer32]
"(Default)" = "%Program Files%\Java\jre6\bin\jp2iexp.dll"

[HKCU\Software\Classes\CLSID\{CAFEEFAC-0015-0000-0029-ABCDEFFEDCBB}]
"(Default)" = "Java Plug-in 1.5.0_29"

[HKCU\Software\Classes\CLSID\{CAFEEFAC-0014-0002-0030-ABCDEFFEDCBA}\InprocServer32]
"ThreadingModel" = "Apartment"

[HKCU\Software\Classes\CLSID\{CAFEEFAC-0013-0001-0012-ABCDEFFEDCBA}\InprocServer32]
"ThreadingModel" = "Apartment"

[HKCU\Software\Classes\CLSID\{CAFEEFAC-0015-0000-0027-ABCDEFFEDCBC}\InprocServer32]
"(Default)" = "%Program Files%\Java\jre6\bin\jp2iexp.dll"

[HKCU\Software\Classes\CLSID\{CAFEEFAC-0014-0002-0012-ABCDEFFEDCBA}]
"(Default)" = "Java Plug-in 1.4.2_12"

[HKCU\Software\Classes\CLSID\{CAFEEFAC-0015-0000-0021-ABCDEFFEDCBC}]
"(Default)" = "Java Plug-in 1.5.0_21"

[HKCU\Software\Classes\CLSID\{CAFEEFAC-0015-0000-0007-ABCDEFFEDCBA}]
"(Default)" = "Java Plug-in 1.5.0_07"

[HKCU\Software\Classes\CLSID\{CAFEEFAC-0015-0000-0016-ABCDEFFEDCBB}\InprocServer32]
"ThreadingModel" = "Apartment"

[HKCU\Software\Classes\CLSID\{CAFEEFAC-0016-0000-0018-ABCDEFFEDCBB}]
"(Default)" = "Java Plug-in 1.6.0_18"

[HKCU\Software\Classes\CLSID\{CAFEEFAC-0015-0000-0029-ABCDEFFEDCBC}\InprocServer32]
"(Default)" = "%Program Files%\Java\jre6\bin\jp2iexp.dll"

[HKCU\Software\Classes\CLSID\{CAFEEFAC-0015-0000-0005-ABCDEFFEDCBC}]
"(Default)" = "Java Plug-in 1.5.0_05"

[HKCU\Software\Classes\CLSID\{CAFEEFAC-0015-0000-0028-ABCDEFFEDCBA}\InprocServer32]
"ThreadingModel" = "Apartment"

[HKCU\Software\Classes\CLSID\{CAFEEFAC-0015-0000-0002-ABCDEFFEDCBB}\InprocServer32]
"(Default)" = "%Program Files%\Java\jre6\bin\jp2iexp.dll"

[HKCU\Software\Classes\CLSID\{CAFEEFAC-0014-0002-0011-ABCDEFFEDCBB}\InprocServer32]
"ThreadingModel" = "Apartment"

[HKCU\Software\Classes\CLSID\{CAFEEFAC-0013-0001-0014-ABCDEFFEDCBA}\InprocServer32]
"(Default)" = "%Program Files%\Java\jre6\bin\jp2iexp.dll"

[HKCU\Software\Classes\CLSID\{CAFEEFAC-0014-0002-0000-ABCDEFFEDCBA}\InprocServer32]
"ThreadingModel" = "Apartment"

[HKCU\Software\Classes\CLSID\{CAFEEFAC-0014-0002-0014-ABCDEFFEDCBB}]
"(Default)" = "Java Plug-in 1.4.2_14"

[HKCU\Software\Classes\CLSID\{CAFEEFAC-0015-0000-0002-ABCDEFFEDCBA}]
"(Default)" = "Java Plug-in 1.5.0_02"

[HKCU\Software\Classes\CLSID\{CAFEEFAC-0016-0000-0000-ABCDEFFEDCBA}\InprocServer32]
"ThreadingModel" = "Apartment"

[HKCU\Software\Classes\CLSID\{CAFEEFAC-0015-0000-0018-ABCDEFFEDCBA}\InprocServer32]
"(Default)" = "%Program Files%\Java\jre6\bin\jp2iexp.dll"

[HKCU\Software\Classes\CLSID\{CAFEEFAC-0014-0002-0004-ABCDEFFEDCBB}]
"(Default)" = "Java Plug-in 1.4.2_04"

[HKCU\Software\Classes\CLSID\{CAFEEFAC-0015-0000-0022-ABCDEFFEDCBA}]
"(Default)" = "Java Plug-in 1.5.0_22"

[HKCU\Software\Classes\CLSID\{CAFEEFAC-0015-0000-0009-ABCDEFFEDCBA}]
"(Default)" = "Java Plug-in 1.5.0_09"

[HKCU\Software\Classes\CLSID\{CAFEEFAC-0016-0000-0014-ABCDEFFEDCBB}\InprocServer32]
"(Default)" = "%Program Files%\Java\jre6\bin\jp2iexp.dll"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{E7E6F031-17CE-4C07-BC86-EABFE594F69C}\iexplore]
"LoadTime" = "7"

[HKCU\Software\Classes\CLSID\{CAFEEFAC-0015-0000-0023-ABCDEFFEDCBA}]
"(Default)" = "Java Plug-in 1.5.0_23"

[HKCU\Software\Classes\CLSID\{CAFEEFAC-0013-0001-0011-ABCDEFFEDCBB}\InprocServer32]
"ThreadingModel" = "Apartment"

[HKCU\Software\Classes\CLSID\{CAFEEFAC-0013-0001-0028-ABCDEFFEDCBB}]
"(Default)" = "Java Plug-in 1.3.1_28"

[HKCU\Software\Classes\CLSID\{CAFEEFAC-0015-0000-0016-ABCDEFFEDCBC}\InprocServer32]
"(Default)" = "%Program Files%\Java\jre6\bin\jp2iexp.dll"

[HKCU\Software\Classes\CLSID\{CAFEEFAC-0015-0000-0012-ABCDEFFEDCBB}\InprocServer32]
"ThreadingModel" = "Apartment"

[HKCU\Software\Classes\CLSID\{CAFEEFAC-0015-0000-0018-ABCDEFFEDCBB}]
"(Default)" = "Java Plug-in 1.5.0_18"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{CA8A9780-280D-11CF-A24D-444553540000}\iexplore]
"Flags" = "0"

[HKCU\Software\Classes\CLSID\{CAFEEFAC-0015-0000-0001-ABCDEFFEDCBB}\InprocServer32]
"ThreadingModel" = "Apartment"

[HKCU\Software\Classes\CLSID\{CAFEEFAC-0016-0000-0016-ABCDEFFEDCBA}]
"(Default)" = "Java Plug-in 1.6.0_16"

[HKCU\Software\Classes\CLSID\{CAFEEFAC-0015-0000-0023-ABCDEFFEDCBB}\InprocServer32]
"ThreadingModel" = "Apartment"

[HKCU\Software\Classes\CLSID\{CAFEEFAC-0014-0001-0006-ABCDEFFEDCBB}]
"(Default)" = "Java Plug-in 1.4.1_06"

[HKCU\Software\Classes\CLSID\{CAFEEFAC-0013-0001-0021-ABCDEFFEDCBA}\InprocServer32]
"(Default)" = "%Program Files%\Java\jre6\bin\jp2iexp.dll"

[HKCU\Software\Classes\CLSID\{CAFEEFAC-0015-0000-0022-ABCDEFFEDCBB}\InprocServer32]
"ThreadingModel" = "Apartment"

[HKCU\Software\Microsoft\Internet Explorer\DOMStorage\Total]
"(Default)" = "56"

[HKCU\Software\Classes\CLSID\{CAFEEFAC-0014-0002-0017-ABCDEFFEDCBA}\InprocServer32]
"ThreadingModel" = "Apartment"

[HKCU\Software\Classes\CLSID\{CAFEEFAC-0015-0000-0009-ABCDEFFEDCBC}\InprocServer32]
"(Default)" = "%Program Files%\Java\jre6\bin\jp2iexp.dll"

[HKCU\Software\Classes\CLSID\{CAFEEFAC-0016-0000-0018-ABCDEFFEDCBA}\InprocServer32]
"(Default)" = "%Program Files%\Java\jre6\bin\jp2iexp.dll"

[HKCU\Software\Classes\CLSID\{E19F9331-3110-11D4-991C-005004D3B3DB}\InprocServer32]
"(Default)" = "%Program Files%\Java\jre6\bin\jp2iexp.dll"

[HKCU\Software\Classes\CLSID\{CAFEEFAC-0014-0002-0030-ABCDEFFEDCBB}\InprocServer32]
"ThreadingModel" = "Apartment"

[HKCU\Software\Classes\CLSID\{CAFEEFAC-0013-0001-0005-ABCDEFFEDCBB}\InprocServer32]
"ThreadingModel" = "Apartment"

[HKCU\Software\Classes\CLSID\{CAFEEFAC-0014-0001-0007-ABCDEFFEDCBB}\InprocServer32]
"ThreadingModel" = "Apartment"

[HKCU\Software\Classes\CLSID\{CAFEEFAC-0015-0000-0004-ABCDEFFEDCBC}]
"(Default)" = "Java Plug-in 1.5.0_04"

[HKCU\Software\Classes\CLSID\{CAFEEFAC-0014-0001-0004-ABCDEFFEDCBA}\InprocServer32]
"(Default)" = "%Program Files%\Java\jre6\bin\jp2iexp.dll"

[HKCU\Software\Classes\CLSID\{CAFEEFAC-0016-0000-0015-ABCDEFFEDCBC}]
"(Default)" = "Java Plug-in 1.6.0_15"

[HKCU\Software\Classes\CLSID\{CAFEEFAC-0015-0000-0026-ABCDEFFEDCBB}\InprocServer32]
"(Default)" = "%Program Files%\Java\jre6\bin\jp2iexp.dll"

[HKCU\Software\Classes\CLSID\{CAFEEFAC-0016-0000-0004-ABCDEFFEDCBA}\InprocServer32]
"ThreadingModel" = "Apartment"

[HKCU\Software\Classes\CLSID\{CAFEEFAC-0015-0000-0009-ABCDEFFEDCBB}\InprocServer32]
"(Default)" = "%Program Files%\Java\jre6\bin\jp2iexp.dll"

[HKCU\Software\Classes\CLSID\{CAFEEFAC-0014-0002-FFFF-ABCDEFFEDCBA}]
"(Default)" = "Java Plug-in 1.4.2"

[HKCU\Software\Classes\CLSID\{CAFEEFAC-0013-0001-0017-ABCDEFFEDCBB}\InprocServer32]
"(Default)" = "%Program Files%\Java\jre6\bin\jp2iexp.dll"

[HKCU\Software\Classes\CLSID\{CAFEEFAC-0015-0000-0029-ABCDEFFEDCBA}\InprocServer32]
"ThreadingModel" = "Apartment"

[HKCU\Software\Classes\CLSID\{CAFEEFAC-0013-0001-0028-ABCDEFFEDCBB}\InprocServer32]
"(Default)" = "%Program Files%\Java\jre6\bin\jp2iexp.dll"

[HKCU\Software\Classes\CLSID\{CAFEEFAC-0014-0002-0027-ABCDEFFEDCBA}\InprocServer32]
"(Default)" = "%Program Files%\Java\jre6\bin\jp2iexp.dll"

[HKCU\Software\Classes\CLSID\{CAFEEFAC-0016-0000-0010-ABCDEFFEDCBB}\InprocServer32]
"ThreadingModel" = "Apartment"

[HKCU\Software\Classes\CLSID\{CAFEEFAC-0016-0000-0015-ABCDEFFEDCBB}\InprocServer32]
"(Default)" = "%Program Files%\Java\jre6\bin\jp2iexp.dll"

[HKCU\Software\Classes\CLSID\{CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA}]
"(Default)" = "Java Plug-in 1.6.0_07"

[HKCU\Software\Classes\CLSID\{CAFEEFAC-0014-0002-0024-ABCDEFFEDCBA}]
"(Default)" = "Java Plug-in 1.4.2_24"

[HKCU\Software\Classes\CLSID\{CAFEEFAC-0013-0000-0003-ABCDEFFEDCBA}\InprocServer32]
"ThreadingModel" = "Apartment"

[HKCU\Software\Classes\CLSID\{CAFEEFAC-0013-0001-0009-ABCDEFFEDCBA}\InprocServer32]
"(Default)" = "%Program Files%\Java\jre6\bin\jp2iexp.dll"

[HKCU\Software\Classes\CLSID\{CAFEEFAC-0013-0001-0007-ABCDEFFEDCBB}\InprocServer32]
"ThreadingModel" = "Apartment"

[HKCU\Software\Classes\CLSID\{CAFEEFAC-0014-0002-0011-ABCDEFFEDCBB}]
"(Default)" = "Java Plug-in 1.4.2_11"

[HKCU\Software\Classes\CLSID\{CAFEEFAC-0013-0001-0002-ABCDEFFEDCBA}\InprocServer32]
"ThreadingModel" = "Apartment"

[HKCU\Software\Classes\CLSID\{CAFEEFAC-0015-0000-0003-ABCDEFFEDCBA}]
"(Default)" = "Java Plug-in 1.5.0_03"

[HKCU\Software\Classes\CLSID\{CAFEEFAC-0015-0000-0014-ABCDEFFEDCBA}]
"(Default)" = "Java Plug-in 1.5.0_14"

[HKCU\Software\Classes\CLSID\{CAFEEFAC-0014-0001-0004-ABCDEFFEDCBA}\InprocServer32]
"ThreadingModel" = "Apartment"

[HKCU\Software\Classes\CLSID\{CAFEEFAC-0015-0000-0019-ABCDEFFEDCBC}\InprocServer32]
"ThreadingModel" = "Apartment"

[HKCU\Software\Classes\CLSID\{CAFEEFAC-0015-0000-0018-ABCDEFFEDCBC}\InprocServer32]
"(Default)" = "%Program Files%\Java\jre6\bin\jp2iexp.dll"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{DBC80044-A445-435B-BC74-9C25C1C588A9}\iexplore]
"Count" = "28"

[HKCU\Software\Classes\CLSID\{CAFEEFAC-0015-0000-0018-ABCDEFFEDCBB}\InprocServer32]
"(Default)" = "%Program Files%\Java\jre6\bin\jp2iexp.dll"

[HKCU\Software\Classes\CLSID\{CAFEEFAC-0013-0001-0001-ABCDEFFEDCBA}]
"(Default)" = "Java Plug-in 1.3.1_01"

[HKCU\Software\Classes\CLSID\{CAFEEFAC-0014-0002-0024-ABCDEFFEDCBA}\InprocServer32]
"ThreadingModel" = "Apartment"

[HKCU\Software\Classes\CLSID\{CAFEEFAC-0015-0000-0000-ABCDEFFEDCBA}\InprocServer32]
"ThreadingModel" = "Apartment"

[HKCU\Software\Classes\CLSID\{CAFEEFAC-0015-0000-0005-ABCDEFFEDCBA}\InprocServer32]
"(Default)" = "%Program Files%\Java\jre6\bin\jp2iexp.dll"

[HKCU\Software\Classes\CLSID\{CAFEEFAC-0014-0002-0025-ABCDEFFEDCBB}\InprocServer32]
"ThreadingModel" = "Apartment"

[HKCU\Software\Classes\CLSID\{CAFEEFAC-0016-0000-0007-ABCDEFFEDCBB}]
"(Default)" = "Java Plug-in 1.6.0_07"

[HKCU\Software\Classes\CLSID\{CAFEEFAC-0015-0000-0001-ABCDEFFEDCBB}]
"(Default)" = "Java Plug-in 1.5.0_01"

[HKCU\Software\Classes\CLSID\{CAFEEFAC-0014-0002-0007-ABCDEFFEDCBA}\InprocServer32]
"ThreadingModel" = "Apartment"

[HKCU\Software\Classes\CLSID\{CAFEEFAC-0013-0000-0004-ABCDEFFEDCBA}]
"(Default)" = "Java Plug-in 1.3.0_04"

[HKCU\Software\Classes\CLSID\{CAFEEFAC-0016-0000-0006-ABCDEFFEDCBB}]
"(Default)" = "Java Plug-in 1.6.0_06"

[HKCU\Software\Classes\CLSID\{CAFEEFAC-0013-0001-0019-ABCDEFFEDCBB}\InprocServer32]
"ThreadingModel" = "Apartment"

[HKCU\Software\Classes\CLSID\{CAFEEFAC-0014-0001-0001-ABCDEFFEDCBB}]
"(Default)" = "Java Plug-in 1.4.1_01"

[HKCU\Software\Classes\CLSID\{CAFEEFAC-0015-0000-0010-ABCDEFFEDCBB}\InprocServer32]
"(Default)" = "%Program Files%\Java\jre6\bin\jp2iexp.dll"

[HKCU\Software\Classes\CLSID\{CAFEEFAC-0014-0002-0001-ABCDEFFEDCBB}\InprocServer32]
"(Default)" = "%Program Files%\Java\jre6\bin\jp2iexp.dll"

[HKCU\Software\Classes\CLSID\{CAFEEFAC-0015-0000-0008-ABCDEFFEDCBC}\InprocServer32]
"(Default)" = "%Program Files%\Java\jre6\bin\jp2iexp.dll"

[HKCU\Software\Classes\CLSID\{CAFEEFAC-0014-0002-0013-ABCDEFFEDCBA}\InprocServer32]
"(Default)" = "%Program Files%\Java\jre6\bin\jp2iexp.dll"

[HKCU\Software\Classes\CLSID\{CAFEEFAC-0016-0000-0008-ABCDEFFEDCBA}\InprocServer32]
"ThreadingModel" = "Apartment"

[HKCU\Software\Classes\CLSID\{CAFEEFAC-0014-0002-0019-ABCDEFFEDCBA}]
"(Default)" = "Java Plug-in 1.4.2_19"

[HKCU\Software\Classes\CLSID\{CAFEEFAC-0014-0000-0001-ABCDEFFEDCBA}]
"(Default)" = "Java Plug-in 1.4.0_01"

[HKCU\Software\Classes\CLSID\{CAFEEFAC-0014-0002-0008-ABCDEFFEDCBA}]
"(Default)" = "Java Plug-in 1.4.2_08"

[HKCU\Software\Classes\CLSID\{CAFEEFAC-0014-0001-0003-ABCDEFFEDCBB}]
"(Default)" = "Java Plug-in 1.4.1_03"

[HKCU\Software\Classes\CLSID\{CAFEEFAC-0014-0002-0017-ABCDEFFEDCBB}\InprocServer32]
"ThreadingModel" = "Apartment"

[HKCU\Software\Classes\CLSID\{CAFEEFAC-0013-0001-0004-ABCDEFFEDCBB}\InprocServer32]
"ThreadingModel" = "Apartment"

[HKCU\Software\Classes\CLSID\{CAFEEFAC-0013-0001-0004-ABCDEFFEDCBA}]
"(Default)" = "Java Plug-in 1.3.1_04"

[HKCU\Software\Classes\CLSID\{CAFEEFAC-0013-0001-0002-ABCDEFFEDCBA}\InprocServer32]
"(Default)" = "%Program Files%\Java\jre6\bin\jp2iexp.dll"

[HKCU\Software\Classes\CLSID\{CAFEEFAC-0013-0001-0021-ABCDEFFEDCBB}\InprocServer32]
"(Default)" = "%Program Files%\Java\jre6\bin\jp2iexp.dll"

[HKCU\Software\Classes\CLSID\{CAFEEFAC-0013-0001-0027-ABCDEFFEDCBA}\InprocServer32]
"(Default)" = "%Program Files%\Java\jre6\bin\jp2iexp.dll"

[HKCU\Software\Classes\CLSID\{CAFEEFAC-0013-0001-0017-ABCDEFFEDCBA}\InprocServer32]
"(Default)" = "%Program Files%\Java\jre6\bin\jp2iexp.dll"

[HKCU\Software\Classes\CLSID\{CAFEEFAC-0015-0000-0026-ABCDEFFEDCBA}]
"(Default)" = "Java Plug-in 1.5.0_26"

[HKCU\Software\Classes\CLSID\{CAFEEFAC-0014-0002-0029-ABCDEFFEDCBB}\InprocServer32]
"(Default)" = "%Program Files%\Java\jre6\bin\jp2iexp.dll"

[HKCU\Software\Classes\CLSID\{CAFEEFAC-0015-0000-0017-ABCDEFFEDCBC}\InprocServer32]
"(Default)" = "%Program Files%\Java\jre6\bin\jp2iexp.dll"

[HKCU\Software\Classes\CLSID\{CAFEEFAC-0013-0001-0023-ABCDEFFEDCBA}]
"(Default)" = "Java Plug-in 1.3.1_23"

[HKCU\Software\Classes\CLSID\{CAFEEFAC-0014-0002-0022-ABCDEFFEDCBA}]
"(Default)" = "Java Plug-in 1.4.2_22"

[HKCU\Software\Classes\CLSID\{CAFEEFAC-0015-0000-0006-ABCDEFFEDCBA}\InprocServer32]
"ThreadingModel" = "Apartment"

[HKCU\Software\Classes\CLSID\{CAFEEFAC-0014-0002-0001-ABCDEFFEDCBB}]
"(Default)" = "Java Plug-in 1.4.2_01"

[HKCU\Software\Classes\CLSID\{CAFEEFAC-0014-0001-0007-ABCDEFFEDCBB}\InprocServer32]
"(Default)" = "%Program Files%\Java\jre6\bin\jp2iexp.dll"

[HKCU\Software\Classes\CLSID\{CAFEEFAC-0015-0000-0024-ABCDEFFEDCBB}\InprocServer32]
"ThreadingModel" = "Apartment"

[HKCU\Software\Classes\CLSID\{CAFEEFAC-0014-0002-0016-ABCDEFFEDCBA}\InprocServer32]
"(Default)" = "%Program Files%\Java\jre6\bin\jp2iexp.dll"

[HKCU\Software\Classes\CLSID\{CAFEEFAC-0013-0001-0030-ABCDEFFEDCBA}\InprocServer32]
"ThreadingModel" = "Apartment"

[HKCU\Software\Classes\CLSID\{CAFEEFAC-0013-0001-0001-ABCDEFFEDCBB}\InprocServer32]
"(Default)" = "%Program Files%\Java\jre6\bin\jp2iexp.dll"

[HKCU\Software\Classes\CLSID\{CAFEEFAC-0016-0000-0013-ABCDEFFEDCBA}\InprocServer32]
"ThreadingModel" = "Apartment"

[HKCU\Software\Classes\CLSID\{CAFEEFAC-0015-0000-0002-ABCDEFFEDCBB}]
"(Default)" = "Java Plug-in 1.5.0_02"

[HKCU\Software\Classes\CLSID\{CAFEEFAC-0014-0002-0001-ABCDEFFEDCBA}]
"(Default)" = "Java Plug-in 1.4.2_01"

[HKCU\Software\Classes\CLSID\{CAFEEFAC-0015-0000-0009-ABCDEFFEDCBB}\InprocServer32]
"ThreadingModel" = "Apartment"

[HKCU\Software\Classes\CLSID\{CAFEEFAC-0013-0001-0004-ABCDEFFEDCBA}\InprocServer32]
"ThreadingModel" = "Apartment"

[HKCU\Software\Classes\CLSID\{CAFEEFAC-0015-0000-0025-ABCDEFFEDCBB}\InprocServer32]
"ThreadingModel" = "Apartment"

[HKCU\Software\Classes\CLSID\{CAFEEFAC-0014-0002-0023-ABCDEFFEDCBA}]
"(Default)" = "Java Plug-in 1.4.2_23"

[HKCU\Software\Classes\CLSID\{CAFEEFAC-0016-0000-0013-ABCDEFFEDCBC}]
"(Default)" = "Java Plug-in 1.6.0_13"

[HKCU\Software\Classes\CLSID\{CAFEEFAC-0016-0000-0004-ABCDEFFEDCBB}]
"(Default)" = "Java Plug-in 1.6.0_04"

[HKCU\Software\Classes\CLSID\{CAFEEFAC-0016-0000-0006-ABCDEFFEDCBB}\InprocServer32]
"ThreadingModel" = "Apartment"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{18DF081C-E8AD-4283-A596-FA578C2EBDC3}\iexplore]
"Count" = "25"

[HKCU\Software\Classes\CLSID\{CAFEEFAC-0015-0000-0023-ABCDEFFEDCBC}]
"(Default)" = "Java Plug-in 1.5.0_23"

[HKCU\Software\Classes\CLSID\{CAFEEFAC-0015-0000-0001-ABCDEFFEDCBB}\InprocServer32]
"(Default)" = "%Program Files%\Java\jre6\bin\jp2iexp.dll"

[HKCU\Software\Classes\CLSID\{CAFEEFAC-0016-0000-0017-ABCDEFFEDCBA}\InprocServer32]
"ThreadingModel" = "Apartment"

[HKCU\Software\Classes\CLSID\{CAFEEFAC-0016-0000-0008-ABCDEFFEDCBC}]
"(Default)" = "Java Plug-in 1.6.0_08"

[HKCU\Software\Classes\CLSID\{CAFEEFAC-0013-0001-0011-ABCDEFFEDCBA}\InprocServer32]
"(Default)" = "%Program Files%\Java\jre6\bin\jp2iexp.dll"

[HKCU\Software\Classes\CLSID\{CAFEEFAC-0015-0000-0020-ABCDEFFEDCBC}\InprocServer32]
"ThreadingModel" = "Apartment"

[HKCU\Software\Classes\CLSID\{CAFEEFAC-0016-0000-0014-ABCDEFFEDCBC}\InprocServer32]
"ThreadingModel" = "Apartment"

[HKCU\Software\Classes\CLSID\{CAFEEFAC-0015-0000-0007-ABCDEFFEDCBA}\InprocServer32]
"(Default)" = "%Program Files%\Java\jre6\bin\jp2iexp.dll"

[HKCU\Software\Classes\CLSID\{CAFEEFAC-0014-0002-0009-ABCDEFFEDCBB}\InprocServer32]
"(Default)" = "%Program Files%\Java\jre6\bin\jp2iexp.dll"

[HKCU\Software\Classes\CLSID\{CAFEEFAC-0015-0000-0028-ABCDEFFEDCBC}\InprocServer32]
"(Default)" = "%Program Files%\Java\jre6\bin\jp2iexp.dll"

[HKCU\Software\Classes\CLSID\{CAFEEFAC-0014-0001-0003-ABCDEFFEDCBA}]
"(Default)" = "Java Plug-in 1.4.1_03"

[HKCU\Software\Classes\CLSID\{CAFEEFAC-0014-0000-0000-ABCDEFFEDCBA}]
"(Default)" = "Java Plug-in 1.4.0"

[HKCU\Software\Classes\CLSID\{CAFEEFAC-0015-0000-0024-ABCDEFFEDCBA}\InprocServer32]
"(Default)" = "%Program Files%\Java\jre6\bin\jp2iexp.dll"

[HKCU\Software\Classes\CLSID\{CAFEEFAC-0016-0000-0015-ABCDEFFEDCBA}]
"(Default)" = "Java Plug-in 1.6.0_15"

[HKCU\Software\Classes\CLSID\{CAFEEFAC-0015-0000-0026-ABCDEFFEDCBC}]
"(Default)" = "Java Plug-in 1.5.0_26"

[HKCU\Software\Classes\CLSID\{CAFEEFAC-0015-0000-0017-ABCDEFFEDCBB}\InprocServer32]
"(Default)" = "%Program Files%\Java\jre6\bin\jp2iexp.dll"

[HKCU\Software\Classes\CLSID\{CAFEEFAC-0014-0002-0016-ABCDEFFEDCBA}]
"(Default)" = "Java Plug-in 1.4.2_16"

[HKCU\Software\Classes\CLSID\{CAFEEFAC-0016-0000-0010-ABCDEFFEDCBC}]
"(Default)" = "Java Plug-in 1.6.0_10"

[HKCU\Software\Classes\CLSID\{CAFEEFAC-0016-0000-0010-ABCDEFFEDCBA}\InprocServer32]
"(Default)" = "%Program Files%\Java\jre6\bin\jp2iexp.dll"

[HKCU\Software\Classes\CLSID\{CAFEEFAC-0013-0001-0028-ABCDEFFEDCBB}\InprocServer32]
"ThreadingModel" = "Apartment"

[HKCU\Software\Classes\CLSID\{CAFEEFAC-0016-0000-0002-ABCDEFFEDCBC}]
"(Default)" = "Java Plug-in 1.6.0_02"

[HKCU\Software\Classes\CLSID\{CAFEEFAC-0013-0001-0001-ABCDEFFEDCBB}]
"(Default)" = "Java Plug-in 1.3.1_01"

[HKCU\Software\Classes\CLSID\{CAFEEFAC-0015-0000-0024-ABCDEFFEDCBA}\InprocServer32]
"ThreadingModel" = "Apartment"

[HKCU\Software\Classes\CLSID\{CAFEEFAC-0014-0002-0018-ABCDEFFEDCBB}\InprocServer32]
"ThreadingModel" = "Apartment"

[HKCU\Software\Classes\CLSID\{CAFEEFAC-0016-0000-0005-ABCDEFFEDCBC}\InprocServer32]
"ThreadingModel" = "Apartment"

[HKCU\Software\Classes\CLSID\{CAFEEFAC-0014-0001-0007-ABCDEFFEDCBB}]
"(Default)" = "Java Plug-in 1.4.1_07"

[HKCU\Software\Classes\CLSID\{CAFEEFAC-0013-0001-0014-ABCDEFFEDCBB}]
"(Default)" = "Java Plug-in 1.3.1_14"

[HKCU\Software\Classes\CLSID\{CAFEEFAC-0016-0000-0018-ABCDEFFEDCBC}\InprocServer32]
"(Default)" = "%Program Files%\Java\jre6\bin\jp2iexp.dll"

[HKCU\Software\Classes\CLSID\{CAFEEFAC-0014-0002-0002-ABCDEFFEDCBB}]
"(Default)" = "Java Plug-in 1.4.2_02"

[HKCU\Software\Classes\CLSID\{CAFEEFAC-0016-0000-0008-ABCDEFFEDCBC}\InprocServer32]
"ThreadingModel" = "Apartment"

[HKCU\Software\Classes\CLSID\{CAFEEFAC-0015-0000-0008-ABCDEFFEDCBC}\InprocServer32]
"ThreadingModel" = "Apartment"

[HKCU\Software\Classes\CLSID\{CAFEEFAC-0015-0000-0010-ABCDEFFEDCBC}\InprocServer32]
"ThreadingModel" = "Apartment"

[HKCU\Software\Classes\CLSID\{CAFEEFAC-0014-0001-0000-ABCDEFFEDCBA}]
"(Default)" = "Java Plug-in 1.4.1"

[HKCU\Software\Classes\CLSID\{CAFEEFAC-0014-0000-0000-ABCDEFFEDCBB}]
"(Default)" = "Java Plug-in 1.4.0"

[HKCU\Software\Classes\CLSID\{CAFEEFAC-0016-0000-0014-ABCDEFFEDCBB}]
"(Default)" = "Java Plug-in 1.6.0_14"

[HKCU\Software\Classes\CLSID\{CAFEEFAC-0016-0000-0000-ABCDEFFEDCBB}\InprocServer32]
"ThreadingModel" = "Apartment"

[HKCU\Software\Classes\CLSID\{CAFEEFAC-0013-0001-0030-ABCDEFFEDCBA}\InprocServer32]
"(Default)" = "%Program Files%\Java\jre6\bin\jp2iexp.dll"

[HKCU\Software\Classes\CLSID\{CAFEEFAC-0014-0002-0028-ABCDEFFEDCBB}]
"(Default)" = "Java Plug-in 1.4.2_28"

[HKCU\Software\Classes\CLSID\{CAFEEFAC-0013-0001-0020-ABCDEFFEDCBB}]
"(Default)" = "Java Plug-in 1.3.1_20"

[HKCU\Software\Classes\CLSID\{CAFEEFAC-0015-0000-0012-ABCDEFFEDCBA}\InprocServer32]
"(Default)" = "%Program Files%\Java\jre6\bin\jp2iexp.dll"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"Cache" = "%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files"

[HKCU\Software\Classes\CLSID\{CAFEEFAC-0013-0001-0003-ABCDEFFEDCBA}\InprocServer32]
"ThreadingModel" = "Apartment"

[HKCU\Software\Classes\CLSID\{CAFEEFAC-0015-0000-0006-ABCDEFFEDCBC}]
"(Default)" = "Java Plug-in 1.5.0_06"

[HKCU\Software\Classes\CLSID\{CAFEEFAC-0013-0001-0015-ABCDEFFEDCBA}\InprocServer32]
"ThreadingModel" = "Apartment"

[HKCU\Software\Classes\CLSID\{CAFEEFAC-0015-0000-0029-ABCDEFFEDCBC}]
"(Default)" = "Java Plug-in 1.5.0_29"

[HKCU\Software\Classes\CLSID\{CAFEEFAC-0014-0000-0002-ABCDEFFEDCBA}]
"(Default)" = "Java Plug-in 1.4.0_02"

[HKCU\Software\Classes\CLSID\{CAFEEFAC-0015-0000-0000-ABCDEFFEDCBB}\InprocServer32]
"(Default)" = "%Program Files%\Java\jre6\bin\jp2iexp.dll"

[HKCU\Software\Classes\CLSID\{CAFEEFAC-0016-0000-0009-ABCDEFFEDCBA}\InprocServer32]
"ThreadingModel" = "Apartment"

[HKCU\Software\Classes\CLSID\{CAFEEFAC-0014-0001-0001-ABCDEFFEDCBA}]
"(Default)" = "Java Plug-in 1.4.1_01"

[HKCU\Software\Classes\CLSID\{CAFEEFAC-0014-0002-0000-ABCDEFFEDCBA}\InprocServer32]
"(Default)" = "%Program Files%\Java\jre6\bin\jp2iexp.dll"

[HKCU\Software\Classes\CLSID\{CAFEEFAC-0014-0002-0013-ABCDEFFEDCBB}]
"(Default)" = "Java Plug-in 1.4.2_13"

[HKCU\Software\Classes\CLSID\{CAFEEFAC-0014-0002-0004-ABCDEFFEDCBA}\InprocServer32]
"(Default)" = "%Program Files%\Java\jre6\bin\jp2iexp.dll"

[HKCU\Software\Classes\CLSID\{CAFEEFAC-0016-0000-0009-ABCDEFFEDCBC}\InprocServer32]
"ThreadingModel" = "Apartment"

[HKCU\Software\Classes\CLSID\{CAFEEFAC-0014-0001-0005-ABCDEFFEDCBA}\InprocServer32]
"(Default)" = "%Program Files%\Java\jre6\bin\jp2iexp.dll"

[HKCU\Software\Classes\CLSID\{CAFEEFAC-0013-0001-0013-ABCDEFFEDCBB}\InprocServer32]
"ThreadingModel" = "Apartment"

[HKCU\Software\Classes\CLSID\{CAFEEFAC-0016-0000-0012-ABCDEFFEDCBA}\InprocServer32]
"(Default)" = "%Program Files%\Java\jre6\bin\jp2iexp.dll"

[HKCU\Software\Classes\CLSID\{CAFEEFAC-0015-0000-0001-ABCDEFFEDCBC}]
"(Default)" = "Java Plug-in 1.5.0_01"

[HKCU\Software\Classes\CLSID\{CAFEEFAC-0013-0001-0024-ABCDEFFEDCBB}\InprocServer32]
"ThreadingModel" = "Apartment"

[HKCU\Software\Classes\CLSID\{CAFEEFAC-0015-0000-FFFF-ABCDEFFEDCBA}]
"(Default)" = "Java Plug-in 1.5.0"

[HKCU\Software\Classes\CLSID\{CAFEEFAC-0014-0001-0007-ABCDEFFEDCBA}\InprocServer32]
"ThreadingModel" = "Apartment"

[HKCU\Software\Classes\CLSID\{CAFEEFAC-0013-0001-0000-ABCDEFFEDCBA}\InprocServer32]
"(Default)" = "%Program Files%\Java\jre6\bin\jp2iexp.dll"

[HKCU\Software\Classes\CLSID\{CAFEEFAC-0014-0002-0009-ABCDEFFEDCBA}\InprocServer32]
"(Default)" = "%Program Files%\Java\jre6\bin\jp2iexp.dll"

[HKCU\Software\Classes\CLSID\{CAFEEFAC-0013-0001-0004-ABCDEFFEDCBA}\InprocServer32]
"(Default)" = "%Program Files%\Java\jre6\bin\jp2iexp.dll"

[HKCU\Software\Classes\CLSID\{CAFEEFAC-0015-0000-0000-ABCDEFFEDCBB}]
"(Default)" = "Java Plug-in 1.5.0"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{CA8A9780-280D-11CF-A24D-444553540000}\iexplore]
"Type" = "1"

[HKCU\Software\Classes\CLSID\{CAFEEFAC-0014-0002-0024-ABCDEFFEDCBB}]
"(Default)" = "Java Plug-in 1.4.2_24"

[HKCU\Software\Classes\CLSID\{CAFEEFAC-0014-0002-0012-ABCDEFFEDCBB}\InprocServer32]
"(Default)" = "%Program Files%\Java\jre6\bin\jp2iexp.dll"

[HKCU\Software\Classes\CLSID\{CAFEEFAC-0013-0001-0011-ABCDEFFEDCBB}]
"(Default)" = "Java Plug-in 1.3.1_11"

[HKCU\Software\Classes\CLSID\{CAFEEFAC-0016-0000-0003-ABCDEFFEDCBC}\InprocServer32]
"ThreadingModel" = "Apartment"

[HKCU\Software\Classes\CLSID\{CAFEEFAC-0014-0002-0009-ABCDEFFEDCBB}]
"(Default)" = "Java Plug-in 1.4.2_09"

[HKCU\Software\Classes\CLSID\{CAFEEFAC-0015-0000-0018-ABCDEFFEDCBC}]
"(Default)" = "Java Plug-in 1.5.0_18"

[HKCU\Software\Classes\CLSID\{CAFEEFAC-0015-0000-0004-ABCDEFFEDCBA}\InprocServer32]
"(Default)" = "%Program Files%\Java\jre6\bin\jp2iexp.dll"

[HKCU\Software\Classes\CLSID\{CAFEEFAC-0015-0000-0028-ABCDEFFEDCBC}\InprocServer32]
"ThreadingModel" = "Apartment"

[HKCU\Software\Classes\CLSID\{CAFEEFAC-0016-0000-0008-ABCDEFFEDCBA}]
"(Default)" = "Java Plug-in 1.6.0_08"

[HKCU\Software\Classes\CLSID\{CAFEEFAC-0014-0002-0000-ABCDEFFEDCBB}]
"(Default)" = "Java Plug-in 1.4.2"

[HKCU\Software\Classes\CLSID\{CAFEEFAC-0016-0000-0012-ABCDEFFEDCBA}\InprocServer32]
"ThreadingModel" = "Apartment"

[HKCU\Software\Classes\CLSID\{CAFEEFAC-0015-0000-0026-ABCDEFFEDCBC}\InprocServer32]
"(Default)" = "%Program Files%\Java\jre6\bin\jp2iexp.dll"

[HKCU\Software\Classes\CLSID\{CAFEEFAC-0014-0002-0017-ABCDEFFEDCBA}\InprocServer32]
"(Default)" = "%Program Files%\Java\jre6\bin\jp2iexp.dll"

[HKCU\Software\Classes\CLSID\{CAFEEFAC-0014-0002-0015-ABCDEFFEDCBA}\InprocServer32]
"(Default)" = "%Program Files%\Java\jre6\bin\jp2iexp.dll"

[HKCU\Software\Classes\CLSID\{CAFEEFAC-0014-0002-0004-ABCDEFFEDCBA}]
"(Default)" = "Java Plug-in 1.4.2_04"

[HKCU\Software\Classes\CLSID\{CAFEEFAC-0014-0002-0011-ABCDEFFEDCBA}]
"(Default)" = "Java Plug-in 1.4.2_11"

[HKCU\Software\Classes\CLSID\{CAFEEFAC-0014-0002-0005-ABCDEFFEDCBB}\InprocServer32]
"(Default)" = "%Program Files%\Java\jre6\bin\jp2iexp.dll"

[HKCU\Software\Classes\CLSID\{CAFEEFAC-0013-0001-0002-ABCDEFFEDCBB}\InprocServer32]
"ThreadingModel" = "Apartment"

[HKCU\Software\Classes\CLSID\{CAFEEFAC-0014-0002-0008-ABCDEFFEDCBB}]
"(Default)" = "Java Plug-in 1.4.2_08"

[HKCU\Software\Classes\CLSID\{CAFEEFAC-0015-0000-0004-ABCDEFFEDCBA}]
"(Default)" = "Java Plug-in 1.5.0_04"

[HKCU\Software\Classes\CLSID\{CAFEEFAC-0014-0002-0026-ABCDEFFEDCBA}]
"(Default)" = "Java Plug-in 1.4.2_26"

[HKCU\Software\Classes\CLSID\{CAFEEFAC-0013-0001-0005-ABCDEFFEDCBA}\InprocServer32]
"ThreadingModel" = "Apartment"

[HKCU\Software\Classes\CLSID\{CAFEEFAC-0016-0000-0012-ABCDEFFEDCBB}\InprocServer32]
"ThreadingModel" = "Apartment"

[HKCU\Software\Classes\CLSID\{CAFEEFAC-0014-0002-0006-ABCDEFFEDCBA}\InprocServer32]
"ThreadingModel" = "Apartment"

[HKCU\Software\Classes\CLSID\{CAFEEFAC-0015-0000-0001-ABCDEFFEDCBC}\InprocServer32]
"(Default)" = "%Program Files%\Java\jre6\bin\jp2iexp.dll"

[HKCU\Software\Classes\CLSID\{CAFEEFAC-0015-0000-0020-ABCDEFFEDCBB}]
"(Default)" = "Java Plug-in 1.5.0_20"

[HKCU\Software\Classes\CLSID\{CAFEEFAC-0013-0001-0024-ABCDEFFEDCBB}]
"(Default)" = "Java Plug-in 1.3.1_24"

[HKCU\Software\Classes\CLSID\{CAFEEFAC-0015-0000-0028-ABCDEFFEDCBB}\InprocServer32]
"ThreadingModel" = "Apartment"

[HKCU\Software\Classes\CLSID\{CAFEEFAC-0015-0000-0019-ABCDEFFEDCBC}\InprocServer32]
"(Default)" = "%Program Files%\Java\jre6\bin\jp2iexp.dll"

[HKCU\Software\Classes\CLSID\{CAFEEFAC-0013-0001-0005-ABCDEFFEDCBB}\InprocServer32]
"(Default)" = "%Program Files%\Java\jre6\bin\jp2iexp.dll"

[HKCU\Software\Classes\CLSID\{CAFEEFAC-0013-0001-0011-ABCDEFFEDCBB}\InprocServer32]
"(Default)" = "%Program Files%\Java\jre6\bin\jp2iexp.dll"

[HKCU\Software\Classes\CLSID\{CAFEEFAC-0015-0000-0015-ABCDEFFEDCBB}\InprocServer32]
"(Default)" = "%Program Files%\Java\jre6\bin\jp2iexp.dll"

[HKCU\Software\Classes\CLSID\{CAFEEFAC-0014-0002-0013-ABCDEFFEDCBA}\InprocServer32]
"ThreadingModel" = "Apartment"

[HKCU\Software\Classes\CLSID\{CAFEEFAC-0015-0000-0015-ABCDEFFEDCBA}\InprocServer32]
"ThreadingModel" = "Apartment"

[HKCU\Software\Classes\CLSID\{CAFEEFAC-0014-0002-0002-ABCDEFFEDCBB}\InprocServer32]
"ThreadingModel" = "Apartment"

[HKCU\Software\Classes\CLSID\{CAFEEFAC-0014-0000-0000-ABCDEFFEDCBA}\InprocServer32]
"(Default)" = "%Program Files%\Java\jre6\bin\jp2iexp.dll"

[HKCU\Software\Classes\CLSID\{CAFEEFAC-0014-0002-0011-ABCDEFFEDCBA}\InprocServer32]
"ThreadingModel" = "Apartment"

[HKCU\Software\Classes\CLSID\{CAFEEFAC-0014-0002-0003-ABCDEFFEDCBB}\InprocServer32]
"(Default)" = "%Program Files%\Java\jre6\bin\jp2iexp.dll"

[HKCU\Software\Classes\CLSID\{CAFEEFAC-0016-0000-0003-ABCDEFFEDCBB}\InprocServer32]
"ThreadingModel" = "Apartment"

[HKCU\Software\Classes\CLSID\{CAFEEFAC-0015-0000-0016-ABCDEFFEDCBC}\InprocServer32]
"ThreadingModel" = "Apartment"

[HKCU\Software\Classes\CLSID\{CAFEEFAC-0013-0001-0011-ABCDEFFEDCBA}]
"(Default)" = "Java Plug-in 1.3.1_11"

[HKCU\Software\Classes\CLSID\{CAFEEFAC-0016-0000-0013-ABCDEFFEDCBB}]
"(Default)" = "Java Plug-in 1.6.0_13"

[HKCU\Software\Classes\CLSID\{CAFEEFAC-0013-0001-0009-ABCDEFFEDCBB}]
"(Default)" = "Java Plug-in 1.3.1_09"

[HKCU\Software\Classes\CLSID\{CAFEEFAC-0014-0001-0002-ABCDEFFEDCBA}\InprocServer32]
"ThreadingModel" = "Apartment"

[HKCU\Software\Classes\CLSID\{CAFEEFAC-0013-0001-0007-ABCDEFFEDCBB}]
"(Default)" = "Java Plug-in 1.3.1_07"

[HKCU\Software\Classes\CLSID\{CAFEEFAC-0014-0002-FFFF-ABCDEFFEDCBA}\InprocServer32]
"ThreadingModel" = "Apartment"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"History" = "%Documents and Settings%\%current user%\Local Settings\History"

[HKCU\Software\Classes\CLSID\{CAFEEFAC-0015-0000-0023-ABCDEFFEDCBC}\InprocServer32]
"ThreadingModel" = "Apartment"

[HKCU\Software\Classes\CLSID\{CAFEEFAC-0015-0000-0017-ABCDEFFEDCBB}]
"(Default)" = "Java Plug-in 1.5.0_17"

[HKCU\Software\Classes\CLSID\{CAFEEFAC-0016-0000-0004-ABCDEFFEDCBA}]
"(Default)" = "Java Plug-in 1.6.0_04"

[HKCU\Software\Classes\CLSID\{CAFEEFAC-0016-0000-0003-ABCDEFFEDCBC}]
"(Default)" = "Java Plug-in 1.6.0_03"

[HKCU\Software\Classes\CLSID\{CAFEEFAC-0015-0000-0020-ABCDEFFEDCBA}\InprocServer32]
"ThreadingModel" = "Apartment"

[HKCU\Software\Classes\CLSID\{CAFEEFAC-0014-0002-0022-ABCDEFFEDCBB}\InprocServer32]
"ThreadingModel" = "Apartment"

[HKCU\Software\Classes\CLSID\{CAFEEFAC-0014-0000-0000-ABCDEFFEDCBB}\InprocServer32]
"ThreadingModel" = "Apartment"

[HKCU\Software\Classes\CLSID\{CAFEEFAC-0013-0000-0005-ABCDEFFEDCBA}\InprocServer32]
"ThreadingModel" = "Apartment"

[HKCU\Software\Classes\CLSID\{CAFEEFAC-0015-0000-0005-ABCDEFFEDCBB}]
"(Default)" = "Java Plug-in 1.5.0_05"

[HKCU\Software\Classes\CLSID\{CAFEEFAC-0016-0000-0000-ABCDEFFEDCBC}]
"(Default)" = "Java Plug-in 1.6.0"

[HKCU\Software\Classes\CLSID\{CAFEEFAC-0015-0000-0010-ABCDEFFEDCBC}\InprocServer32]
"(Default)" = "%Program Files%\Java\jre6\bin\jp2iexp.dll"

[HKCU\Software\Classes\CLSID\{CAFEEFAC-0013-0001-0008-ABCDEFFEDCBA}\InprocServer32]
"ThreadingModel" = "Apartment"

[HKCU\Software\Classes\CLSID\{CAFEEFAC-0014-0002-0012-ABCDEFFEDCBA}\InprocServer32]
"ThreadingModel" = "Apartment"

[HKCU\Software\Classes\CLSID\{CAFEEFAC-0016-0000-0007-ABCDEFFEDCBB}\InprocServer32]
"ThreadingModel" = "Apartment"

[HKCU\Software\Classes\CLSID\{CAFEEFAC-0013-0001-0012-ABCDEFFEDCBB}\InprocServer32]
"(Default)" = "%Program Files%\Java\jre6\bin\jp2iexp.dll"

[HKCU\Software\Classes\CLSID\{CAFEEFAC-0015-0000-0026-ABCDEFFEDCBB}]
"(Default)" = "Java Plug-in 1.5.0_26"

[HKCU\Software\Classes\CLSID\{CAFEEFAC-0013-0001-0026-ABCDEFFEDCBB}]
"(Default)" = "Java Plug-in 1.3.1_26"

[HKCU\Software\Classes\CLSID\{CAFEEFAC-0015-0000-0004-ABCDEFFEDCBB}\InprocServer32]
"ThreadingModel" = "Apartment"

[HKCU\Software\Classes\CLSID\{CAFEEFAC-0014-0002-0009-ABCDEFFEDCBA}\InprocServer32]
"ThreadingModel" = "Apartment"

[HKCU\Software\Classes\CLSID\{CAFEEFAC-0013-0001-0010-ABCDEFFEDCBA}]
"(Default)" = "Java Plug-in 1.3.1_10"

[HKCU\Software\Classes\CLSID\{CAFEEFAC-0014-0002-0011-ABCDEFFEDCBA}\InprocServer32]
"(Default)" = "%Program Files%\Java\jre6\bin\jp2iexp.dll"

[HKCU\Software\Classes\CLSID\{CAFEEFAC-0016-0000-0002-ABCDEFFEDCBB}]
"(Default)" = "Java Plug-in 1.6.0_02"

[HKCU\Software\Classes\CLSID\{CAFEEFAC-0014-0002-0024-ABCDEFFEDCBB}\InprocServer32]
"ThreadingModel" = "Apartment"

[HKCU\Software\Classes\CLSID\{CAFEEFAC-0015-0000-0029-ABCDEFFEDCBB}\InprocServer32]
"ThreadingModel" = "Apartment"

[HKCU\Software\Classes\CLSID\{8AD9C840-044E-11D1-B3E9-00805F499D93}]
"(Default)" = "Java Plug-in 1.6.0_18"

[HKCU\Software\Classes\CLSID\{CAFEEFAC-0016-0000-0016-ABCDEFFEDCBA}\InprocServer32]
"(Default)" = "%Program Files%\Java\jre6\bin\jp2iexp.dll"

[HKCU\Software\Classes\CLSID\{CAFEEFAC-0014-0000-0003-ABCDEFFEDCBA}\InprocServer32]
"ThreadingModel" = "Apartment"

[HKCU\Software\Classes\CLSID\{CAFEEFAC-0014-0002-0021-ABCDEFFEDCBA}\InprocServer32]
"(Default)" = "%Program Files%\Java\jre6\bin\jp2iexp.dll"

[HKCU\Software\Classes\CLSID\{CAFEEFAC-0014-0000-0001-ABCDEFFEDCBB}\InprocServer32]
"(Default)" = "%Program Files%\Java\jre6\bin\jp2iexp.dll"

[HKCU\Software\Classes\CLSID\{CAFEEFAC-0013-0001-0024-ABCDEFFEDCBA}\InprocServer32]
"(Default)" = "%Program Files%\Java\jre6\bin\jp2iexp.dll"

[HKCU\Software\Classes\CLSID\{CAFEEFAC-0015-0000-0027-ABCDEFFEDCBB}]
"(Default)" = "Java Plug-in 1.5.0_27"

[HKCU\Software\Classes\CLSID\{CAFEEFAC-0013-0001-0021-ABCDEFFEDCBA}\InprocServer32]
"ThreadingModel" = "Apartment"

[HKCU\Software\Classes\CLSID\{CAFEEFAC-0013-0001-0027-ABCDEFFEDCBA}\InprocServer32]
"ThreadingModel" = "Apartment"

[HKCU\Software\Classes\CLSID\{CAFEEFAC-0016-0000-0005-ABCDEFFEDCBB}]
"(Default)" = "Java Plug-in 1.6.0_05"

[HKCU\Software\Classes\CLSID\{CAFEEFAC-0015-0000-0025-ABCDEFFEDCBC}\InprocServer32]
"(Default)" = "%Program Files%\Java\jre6\bin\jp2iexp.dll"

[HKCU\Software\Classes\CLSID\{CAFEEFAC-0014-0000-0004-ABCDEFFEDCBA}\InprocServer32]
"ThreadingModel" = "Apartment"

[HKCU\Software\Classes\CLSID\{CAFEEFAC-0014-0002-0029-ABCDEFFEDCBA}\InprocServer32]
"(Default)" = "%Program Files%\Java\jre6\bin\jp2iexp.dll"

[HKCU\Software\Classes\CLSID\{CAFEEFAC-0015-0000-0007-ABCDEFFEDCBC}\InprocServer32]
"(Default)" = "%Program Files%\Java\jre6\bin\jp2iexp.dll"

[HKCU\Software\Classes\CLSID\{CAFEEFAC-0015-0000-0016-ABCDEFFEDCBB}]
"(Default)" = "Java Plug-in 1.5.0_16"

[HKCU\Software\Classes\CLSID\{CAFEEFAC-0013-0001-0029-ABCDEFFEDCBA}]
"(Default)" = "Java Plug-in 1.3.1_29"

[HKCU\Software\Classes\CLSID\{CAFEEFAC-0015-0000-0011-ABCDEFFEDCBA}]
"(Default)" = "Java Plug-in 1.5.0_11"

[HKCU\Software\Classes\CLSID\{CAFEEFAC-0013-0001-0027-ABCDEFFEDCBB}\InprocServer32]
"(Default)" = "%Program Files%\Java\jre6\bin\jp2iexp.dll"

[HKCU\Software\Classes\CLSID\{CAFEEFAC-0014-0002-0021-ABCDEFFEDCBB}\InprocServer32]
"ThreadingModel" = "Apartment"

[HKCU\Software\Classes\CLSID\{CAFEEFAC-0015-0000-0022-ABCDEFFEDCBA}\InprocServer32]
"(Default)" = "%Program Files%\Java\jre6\bin\jp2iexp.dll"

[HKCU\Software\Classes\CLSID\{E19F9331-3110-11D4-991C-005004D3B3DB}\InprocServer32]
"ThreadingModel" = "Apartment"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{D27CDB6E-AE6D-11CF-96B8-444553540000}\iexplore]
"Count" = "16"

[HKCU\Software\Classes\CLSID\{CAFEEFAC-0015-0000-0019-ABCDEFFEDCBB}\InprocServer32]
"(Default)" = "%Program Files%\Java\jre6\bin\jp2iexp.dll"

[HKCU\Software\Classes\CLSID\{CAFEEFAC-0013-0001-0013-ABCDEFFEDCBB}\InprocServer32]
"(Default)" = "%Program Files%\Java\jre6\bin\jp2iexp.dll"

[HKCU\Software\Classes\CLSID\{CAFEEFAC-0016-0000-0005-ABCDEFFEDCBA}]
"(Default)" = "Java Plug-in 1.6.0_05"

[HKCU\Software\Classes\CLSID\{CAFEEFAC-0016-0000-0004-ABCDEFFEDCBB}\InprocServer32]
"(Default)" = "%Program Files%\Java\jre6\bin\jp2iexp.dll"

[HKCU\Software\Classes\CLSID\{CAFEEFAC-0015-0000-0029-ABCDEFFEDCBC}\InprocServer32]
"ThreadingModel" = "Apartment"

[HKCU\Software\Classes\CLSID\{CAFEEFAC-0015-0000-0012-ABCDEFFEDCBC}\InprocServer32]
"(Default)" = "%Program Files%\Java\jre6\bin\jp2iexp.dll"

[HKCU\Software\Classes\CLSID\{CAFEEFAC-0013-0001-0003-ABCDEFFEDCBA}\InprocServer32]
"(Default)" = "%Program Files%\Java\jre6\bin\jp2iexp.dll"

[HKCU\Software\Classes\CLSID\{CAFEEFAC-0016-0000-0017-ABCDEFFEDCBA}]
"(Default)" = "Java Plug-in 1.6.0_17"

[HKCU\Software\Classes\CLSID\{CAFEEFAC-0014-0002-0005-ABCDEFFEDCBB}\InprocServer32]
"ThreadingModel" = "Apartment"

[HKCU\Software\Classes\CLSID\{CAFEEFAC-0013-0001-0016-ABCDEFFEDCBA}\InprocServer32]
"(Default)" = "%Program Files%\Java\jre6\bin\jp2iexp.dll"

[HKCU\Software\Classes\CLSID\{CAFEEFAC-0016-0000-0003-ABCDEFFEDCBC}\InprocServer32]
"(Default)" = "%Program Files%\Java\jre6\bin\jp2iexp.dll"

[HKCU\Software\Classes\CLSID\{CAFEEFAC-0015-0000-0000-ABCDEFFEDCBA}]
"(Default)" = "Java Plug-in 1.5.0"

[HKCU\Software\Classes\CLSID\{CAFEEFAC-0014-0002-0023-ABCDEFFEDCBB}\InprocServer32]
"ThreadingModel" = "Apartment"

[HKCU\Software\Classes\CLSID\{CAFEEFAC-0015-0000-0023-ABCDEFFEDCBA}\InprocServer32]
"(Default)" = "%Program Files%\Java\jre6\bin\jp2iexp.dll"

[HKCU\Software\Classes\CLSID\{CAFEEFAC-0016-0000-0014-ABCDEFFEDCBA}\InprocServer32]
"(Default)" = "%Program Files%\Java\jre6\bin\jp2iexp.dll"

[HKCU\Software\Classes\CLSID\{CAFEEFAC-0014-0002-0026-ABCDEFFEDCBA}\InprocServer32]
"ThreadingModel" = "Apartment"

[HKCU\Software\Classes\CLSID\{CAFEEFAC-0013-0000-0004-ABCDEFFEDCBA}\InprocServer32]
"(Default)" = "%Program Files%\Java\jre6\bin\jp2iexp.dll"

[HKCU\Software\Classes\CLSID\{CAFEEFAC-0014-0001-0000-ABCDEFFEDCBB}]
"(Default)" = "Java Plug-in 1.4.1"

[HKCU\Software\Classes\CLSID\{CAFEEFAC-0014-0002-0028-ABCDEFFEDCBB}\InprocServer32]
"ThreadingModel" = "Apartment"

[HKCU\Software\Classes\CLSID\{CAFEEFAC-0013-0001-0030-ABCDEFFEDCBA}]
"(Default)" = "Java Plug-in 1.3.1_30"

[HKCU\Software\Classes\CLSID\{CAFEEFAC-0014-0002-0007-ABCDEFFEDCBA}]
"(Default)" = "Java Plug-in 1.4.2_07"

[HKCU\Software\Classes\CLSID\{CAFEEFAC-0015-0000-0002-ABCDEFFEDCBC}\InprocServer32]
"(Default)" = "%Program Files%\Java\jre6\bin\jp2iexp.dll"

[HKCU\Software\Classes\CLSID\{CAFEEFAC-0014-0002-0025-ABCDEFFEDCBA}]
"(Default)" = "Java Plug-in 1.4.2_25"

[HKCU\Software\Classes\CLSID\{CAFEEFAC-0016-0000-0018-ABCDEFFEDCBC}]
"(Default)" = "Java Plug-in 1.6.0_18"

[HKCU\Software\Classes\CLSID\{CAFEEFAC-0016-0000-0015-ABCDEFFEDCBC}\InprocServer32]
"(Default)" = "%Program Files%\Java\jre6\bin\jp2iexp.dll"

[HKCU\Software\Classes\CLSID\{CAFEEFAC-0015-0000-0010-ABCDEFFEDCBB}\InprocServer32]
"ThreadingModel" = "Apartment"

[HKCU\Software\Classes\CLSID\{CAFEEFAC-0015-0000-0019-ABCDEFFEDCBB}]
"(Default)" = "Java Plug-in 1.5.0_19"

[HKCU\Software\Classes\CLSID\{CAFEEFAC-0014-0002-0001-ABCDEFFEDCBA}\InprocServer32]
"(Default)" = "%Program Files%\Java\jre6\bin\jp2iexp.dll"

[HKCU\Software\Classes\CLSID\{CAFEEFAC-0014-0000-0004-ABCDEFFEDCBB}\InprocServer32]
"ThreadingModel" = "Apartment"

[HKCU\Software\Classes\CLSID\{CAFEEFAC-0013-0001-0016-ABCDEFFEDCBB}\InprocServer32]
"ThreadingModel" = "Apartment"

[HKCU\Software\Classes\CLSID\{CAFEEFAC-0014-0002-0018-ABCDEFFEDCBB}\InprocServer32]
"(Default)" = "%Program Files%\Java\jre6\bin\jp2iexp.dll"

[HKCU\Software\Classes\CLSID\{CAFEEFAC-0016-0000-0012-ABCDEFFEDCBC}\InprocServer32]
"ThreadingModel" = "Apartment"

[HKCU\Software\Classes\CLSID\{CAFEEFAC-0016-0000-0016-ABCDEFFEDCBB}\InprocServer32]
"(Default)" = "%Program Files%\Java\jre6\bin\jp2iexp.dll"

[HKCU\Software\Classes\CLSID\{CAFEEFAC-0016-0000-0010-ABCDEFFEDCBA}\InprocServer32]
"ThreadingModel" = "Apartment"

[HKCU\Software\Classes\CLSID\{CAFEEFAC-0013-0001-0004-ABCDEFFEDCBB}]
"(Default)" = "Java Plug-in 1.3.1_04"

[HKCU\Software\Classes\CLSID\{CAFEEFAC-0016-0000-0005-ABCDEFFEDCBB}\InprocServer32]
"ThreadingModel" = "Apartment"

[HKCU\Software\Classes\CLSID\{CAFEEFAC-0013-0001-0022-ABCDEFFEDCBB}\InprocServer32]
"(Default)" = "%Program Files%\Java\jre6\bin\jp2iexp.dll"

[HKCU\Software\Classes\CLSID\{CAFEEFAC-0016-0000-0018-ABCDEFFEDCBB}\InprocServer32]
"(Default)" = "%Program Files%\Java\jre6\bin\jp2iexp.dll"

[HKCU\Software\Classes\CLSID\{CAFEEFAC-0016-0000-0000-ABCDEFFEDCBC}\InprocServer32]
"ThreadingModel" = "Apartment"

[HKCU\Software\Classes\CLSID\{CAFEEFAC-0015-0000-0013-ABCDEFFEDCBB}\InprocServer32]
"ThreadingModel" = "Apartment"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{E7E6F031-17CE-4C07-BC86-EABFE594F69C}\iexplore]
"Time" = "DE 07 05 00 02 00 0D 00 0E 00 38 00 08 00 74 03"

[HKCU\Software\Classes\CLSID\{CAFEEFAC-0015-0000-0027-ABCDEFFEDCBC}\InprocServer32]
"ThreadingModel" = "Apartment"

[HKCU\Software\Classes\CLSID\{CAFEEFAC-0015-0000-0030-ABCDEFFEDCBC}]
"(Default)" = "Java Plug-in 1.5.0_30"

[HKCU\Software\Classes\CLSID\{CAFEEFAC-0014-0002-0020-ABCDEFFEDCBB}\InprocServer32]
"ThreadingModel" = "Apartment"

[HKCU\Software\Classes\CLSID\{CAFEEFAC-0014-0002-0020-ABCDEFFEDCBA}]
"(Default)" = "Java Plug-in 1.4.2_20"

[HKCU\Software\Classes\CLSID\{CAFEEFAC-0015-0000-0023-ABCDEFFEDCBB}]
"(Default)" = "Java Plug-in 1.5.0_23"

[HKCU\Software\Classes\CLSID\{CAFEEFAC-0016-0000-0011-ABCDEFFEDCBC}\InprocServer32]
"(Default)" = "%Program Files%\Java\jre6\bin\jp2iexp.dll"

[HKCU\Software\Classes\CLSID\{CAFEEFAC-0015-0000-0006-ABCDEFFEDCBC}\InprocServer32]
"(Default)" = "%Program Files%\Java\jre6\bin\jp2iexp.dll"

[HKCU\Software\Classes\CLSID\{CAFEEFAC-0015-0000-0022-ABCDEFFEDCBB}]
"(Default)" = "Java Plug-in 1.5.0_22"

[HKCU\Software\Classes\CLSID\{CAFEEFAC-0014-0001-0005-ABCDEFFEDCBB}\InprocServer32]
"(Default)" = "%Program Files%\Java\jre6\bin\jp2iexp.dll"

[HKCU\Software\Classes\CLSID\{CAFEEFAC-0014-0002-0025-ABCDEFFEDCBB}]
"(Default)" = "Java Plug-in 1.4.2_25"

[HKCU\Software\Classes\CLSID\{CAFEEFAC-0015-0000-0025-ABCDEFFEDCBC}\InprocServer32]
"ThreadingModel" = "Apartment"

[HKCU\Software\Classes\CLSID\{CAFEEFAC-0016-0000-0002-ABCDEFFEDCBB}\InprocServer32]
"ThreadingModel" = "Apartment"

[HKCU\Software\Classes\CLSID\{CAFEEFAC-0013-0001-0008-ABCDEFFEDCBB}]
"(Default)" = "Java Plug-in 1.3.1_08"

[HKCU\Software\Classes\CLSID\{CAFEEFAC-0014-0002-0015-ABCDEFFEDCBB}]
"(Default)" = "Java Plug-in 1.4.2_15"

[HKCU\Software\Classes\CLSID\{CAFEEFAC-0013-0001-0013-ABCDEFFEDCBA}\InprocServer32]
"ThreadingModel" = "Apartment"

[HKCU\Software\Classes\CLSID\{CAFEEFAC-0014-0002-0018-ABCDEFFEDCBA}\InprocServer32]
"ThreadingModel" = "Apartment"

[HKCU\Software\Classes\CLSID\{CAFEEFAC-0014-0002-0029-ABCDEFFEDCBB}]
"(Default)" = "Java Plug-in 1.4.2_29"

[HKCU\Software\Classes\CLSID\{CAFEEFAC-0015-0000-0012-ABCDEFFEDCBB}]
"(Default)" = "Java Plug-in 1.5.0_12"

[HKCU\Software\Classes\CLSID\{CAFEEFAC-0015-0000-0028-ABCDEFFEDCBA}\InprocServer32]
"(Default)" = "%Program Files%\Java\jre6\bin\jp2iexp.dll"

[HKCU\Software\Classes\CLSID\{CAFEEFAC-0015-0000-0010-ABCDEFFEDCBA}\InprocServer32]
"ThreadingModel" = "Apartment"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{18DF081C-E8AD-4283-A596-FA578C2EBDC3}\iexplore]
"Type" = "3"

[HKCU\Software\Classes\CLSID\{CAFEEFAC-0014-0002-0018-ABCDEFFEDCBB}]
"(Default)" = "Java Plug-in 1.4.2_18"

[HKCU\Software\Classes\CLSID\{CAFEEFAC-0014-0002-0005-ABCDEFFEDCBA}\InprocServer32]
"ThreadingModel" = "Apartment"

[HKCU\Software\Classes\CLSID\{CAFEEFAC-0016-0000-0000-ABCDEFFEDCBA}]
"(Default)" = "Java Plug-in 1.6.0"

[HKCU\Software\Classes\CLSID\{CAFEEFAC-0014-0001-0005-ABCDEFFEDCBB}]
"(Default)" = "Java Plug-in 1.4.1_05"

[HKCU\Software\Classes\CLSID\{CAFEEFAC-0013-0001-0025-ABCDEFFEDCBB}]
"(Default)" = "Java Plug-in 1.3.1_25"

[HKCU\Software\Classes\CLSID\{CAFEEFAC-0016-0000-0005-ABCDEFFEDCBC}\InprocServer32]
"(Default)" = "%Program Files%\Java\jre6\bin\jp2iexp.dll"

[HKCU\Software\Classes\CLSID\{CAFEEFAC-0013-0001-0003-ABCDEFFEDCBB}\InprocServer32]
"ThreadingModel" = "Apartment"

[HKCU\Software\Classes\CLSID\{CAFEEFAC-0013-0001-0020-ABCDEFFEDCBB}\InprocServer32]
"ThreadingModel" = "Apartment"

[HKCU\Software\Classes\CLSID\{CAFEEFAC-0016-0000-0010-ABCDEFFEDCBC}\InprocServer32]
"(Default)" = "%Program Files%\Java\jre6\bin\jp2iexp.dll"

[HKCU\Software\Classes\CLSID\{CAFEEFAC-0013-0001-0019-ABCDEFFEDCBA}]
"(Default)" = "Java Plug-in 1.3.1_19"

[HKCU\Software\Classes\CLSID\{CAFEEFAC-0014-0002-0020-ABCDEFFEDCBA}\InprocServer32]
"ThreadingModel" = "Apartment"

[HKCU\Software\Classes\CLSID\{CAFEEFAC-0016-0000-0001-ABCDEFFEDCBA}\InprocServer32]
"ThreadingModel" = "Apartment"

[HKCU\Software\Classes\CLSID\{CAFEEFAC-0015-0000-0027-ABCDEFFEDCBB}\InprocServer32]
"(Default)" = "%Program Files%\Java\jre6\bin\jp2iexp.dll"

[HKCU\Software\Classes\CLSID\{CAFEEFAC-0015-0000-0011-ABCDEFFEDCBB}\InprocServer32]
"ThreadingModel" = "Apartment"

[HKCU\Software\Classes\CLSID\{CAFEEFAC-0015-0000-0021-ABCDEFFEDCBA}]
"(Default)" = "Java Plug-in 1.5.0_21"

[HKCU\Software\Classes\CLSID\{CAFEEFAC-0015-0000-0021-ABCDEFFEDCBC}\InprocServer32]
"ThreadingModel" = "Apartment"

[HKCU\Software\Classes\CLSID\{CAFEEFAC-0014-0001-0006-ABCDEFFEDCBA}\InprocServer32]
"(Default)" = "%Program Files%\Java\jre6\bin\jp2iexp.dll"

[HKCU\Software\Classes\CLSID\{CAFEEFAC-0016-0000-0011-ABCDEFFEDCBC}\InprocServer32]
"ThreadingModel" = "Apartment"

[HKCU\Software\Classes\CLSID\{CAFEEFAC-0013-0001-0004-ABCDEFFEDCBB}\InprocServer32]
"(Default)" = "%Program Files%\Java\jre6\bin\jp2iexp.dll"

[HKCU\Software\Classes\CLSID\{CAFEEFAC-0013-0001-0026-ABCDEFFEDCBA}]
"(Default)" = "Java Plug-in 1.3.1_26"

[HKCU\Software\Classes\CLSID\{CAFEEFAC-0014-0000-0003-ABCDEFFEDCBB}]
"(Default)" = "Java Plug-in 1.4.0_03"

[HKCU\Software\Classes\CLSID\{CAFEEFAC-0013-0001-0016-ABCDEFFEDCBA}\InprocServer32]
"ThreadingModel" = "Apartment"

[HKCU\Software\Classes\CLSID\{CAFEEFAC-0013-0001-0026-ABCDEFFEDCBA}\InprocServer32]
"(Default)" = "%Program Files%\Java\jre6\bin\jp2iexp.dll"

[HKCU\Software\Classes\CLSID\{CAFEEFAC-0014-0002-0030-ABCDEFFEDCBB}\InprocServer32]
"(Default)" = "%Program Files%\Java\jre6\bin\jp2iexp.dll"

[HKCU\Software\Classes\CLSID\{CAFEEFAC-0013-0001-0022-ABCDEFFEDCBA}\InprocServer32]
"(Default)" = "%Program Files%\Java\jre6\bin\jp2iexp.dll"

[HKCU\Software\Classes\CLSID\{CAFEEFAC-0014-0001-0000-ABCDEFFEDCBA}\InprocServer32]
"(Default)" = "%Program Files%\Java\jre6\bin\jp2iexp.dll"

[HKCU\Software\Classes\CLSID\{CAFEEFAC-0015-0000-0020-ABCDEFFEDCBC}\InprocServer32]
"(Default)" = "%Program Files%\Java\jre6\bin\jp2iexp.dll"

[HKCU\Software\Classes\CLSID\{CAFEEFAC-0014-0001-0004-ABCDEFFEDCBB}\InprocServer32]
"(Default)" = "%Program Files%\Java\jre6\bin\jp2iexp.dll"

[HKCU\Software\Classes\CLSID\{CAFEEFAC-0015-0000-FFFF-ABCDEFFEDCBA}\InprocServer32]
"ThreadingModel" = "Apartment"

[HKCU\Software\Classes\CLSID\{CAFEEFAC-0013-0001-0027-ABCDEFFEDCBB}\InprocServer32]
"ThreadingModel" = "Apartment"

[HKCU\Software\Classes\CLSID\{CAFEEFAC-0015-0000-0021-ABCDEFFEDCBA}\InprocServer32]
"ThreadingModel" = "Apartment"

[HKCU\Software\Classes\CLSID\{CAFEEFAC-0015-0000-0006-ABCDEFFEDCBB}\InprocServer32]
"ThreadingModel" = "Apartment"

[HKCU\Software\Classes\CLSID\{CAFEEFAC-0014-0002-0010-ABCDEFFEDCBB}\InprocServer32]
"ThreadingModel" = "Apartment"

[HKCU\Software\Classes\CLSID\{CAFEEFAC-0015-0000-0019-ABCDEFFEDCBB}\InprocServer32]
"ThreadingModel" = "Apartment"

[HKCU\Software\Classes\CLSID\{CAFEEFAC-0013-0001-0029-ABCDEFFEDCBB}]
"(Default)" = "Java Plug-in 1.3.1_29"

[HKCU\Software\Classes\CLSID\{CAFEEFAC-0016-0000-0004-ABCDEFFEDCBC}\InprocServer32]
"(Default)" = "%Program Files%\Java\jre6\bin\jp2iexp.dll"

[HKCU\Software\Classes\CLSID\{CAFEEFAC-0013-0001-0006-ABCDEFFEDCBA}\InprocServer32]
"ThreadingModel" = "Apartment"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"AutoDetect" = "1"

[HKCU\Software\Classes\CLSID\{CAFEEFAC-0013-0001-0010-ABCDEFFEDCBB}\InprocServer32]
"ThreadingModel" = "Apartment"

[HKCU\Software\Classes\CLSID\{CAFEEFAC-0015-0000-0003-ABCDEFFEDCBA}\InprocServer32]
"(Default)" = "%Program Files%\Java\jre6\bin\jp2iexp.dll"

[HKCU\Software\Classes\CLSID\{CAFEEFAC-0015-0000-0023-ABCDEFFEDCBA}\InprocServer32]
"ThreadingModel" = "Apartment"

[HKCU\Software\Classes\CLSID\{CAFEEFAC-0014-0000-0001-ABCDEFFEDCBA}\InprocServer32]
"(Default)" = "%Program Files%\Java\jre6\bin\jp2iexp.dll"

[HKCU\Software\Classes\CLSID\{CAFEEFAC-0016-0000-FFFF-ABCDEFFEDCBA}\InprocServer32]
"ThreadingModel" = "Apartment"

[HKCU\Software\Classes\CLSID\{CAFEEFAC-0015-0000-0027-ABCDEFFEDCBB}\InprocServer32]
"ThreadingModel" = "Apartment"

[HKCU\Software\Classes\CLSID\{CAFEEFAC-0015-0000-0004-ABCDEFFEDCBC}\InprocServer32]
"ThreadingModel" = "Apartment"

[HKCU\Software\Classes\CLSID\{CAFEEFAC-0015-0000-0008-ABCDEFFEDCBA}]
"(Default)" = "Java Plug-in 1.5.0_08"

[HKCU\Software\Classes\CLSID\{CAFEEFAC-0013-0001-0014-ABCDEFFEDCBA}]
"(Default)" = "Java Plug-in 1.3.1_14"

[HKCU\Software\Classes\CLSID\{CAFEEFAC-0015-0000-0004-ABCDEFFEDCBB}\InprocServer32]
"(Default)" = "%Program Files%\Java\jre6\bin\jp2iexp.dll"

[HKCU\Software\Classes\CLSID\{CAFEEFAC-0014-0002-0030-ABCDEFFEDCBB}]
"(Default)" = "Java Plug-in 1.4.2_30"

[HKCU\Software\Classes\CLSID\{CAFEEFAC-0013-0001-0018-ABCDEFFEDCBA}]
"(Default)" = "Java Plug-in 1.3.1_18"

[HKCU\Software\Classes\CLSID\{CAFEEFAC-0016-0000-0001-ABCDEFFEDCBB}\InprocServer32]
"ThreadingModel" = "Apartment"

[HKCU\Software\Classes\CLSID\{CAFEEFAC-0016-0000-0016-ABCDEFFEDCBC}]
"(Default)" = "Java Plug-in 1.6.0_16"

[HKCU\Software\Classes\CLSID\{CAFEEFAC-0016-0000-0012-ABCDEFFEDCBA}]
"(Default)" = "Java Plug-in 1.6.0_12"

[HKCU\Software\Classes\CLSID\{CAFEEFAC-0015-0000-0016-ABCDEFFEDCBA}\InprocServer32]
"ThreadingModel" = "Apartment"

[HKCU\Software\Classes\CLSID\{CAFEEFAC-0015-0000-0007-ABCDEFFEDCBB}\InprocServer32]
"(Default)" = "%Program Files%\Java\jre6\bin\jp2iexp.dll"

[HKCU\Software\Classes\CLSID\{CAFEEFAC-0016-0000-0010-ABCDEFFEDCBB}\InprocServer32]
"(Default)" = "%Program Files%\Java\jre6\bin\jp2iexp.dll"

[HKCU\Software\Classes\CLSID\{CAFEEFAC-0015-0000-0014-ABCDEFFEDCBC}\InprocServer32]
"(Default)" = "%Program Files%\Java\jre6\bin\jp2iexp.dll"

[HKCU\Software\Classes\CLSID\{CAFEEFAC-0015-0000-0028-ABCDEFFEDCBC}]
"(Default)" = "Java Plug-in 1.5.0_28"

[HKCU\Software\Classes\CLSID\{CAFEEFAC-0014-0002-0008-ABCDEFFEDCBA}\InprocServer32]
"(Default)" = "%Program Files%\Java\jre6\bin\jp2iexp.dll"

[HKCU\Software\Classes\CLSID\{CAFEEFAC-0014-0002-0003-ABCDEFFEDCBB}\InprocServer32]
"ThreadingModel" = "Apartment"

[HKCU\Software\Classes\CLSID\{CAFEEFAC-0014-0001-0002-ABCDEFFEDCBB}\InprocServer32]
"ThreadingModel" = "Apartment"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{CA8A9780-280D-11CF-A24D-444553540000}\iexplore]
"Time" = "DE 07 05 00 02 00 0D 00 0E 00 38 00 0B 00 B3 03"

[HKCU\Software\Classes\CLSID\{CAFEEFAC-0013-0001-0023-ABCDEFFEDCBB}\InprocServer32]
"(Default)" = "%Program Files%\Java\jre6\bin\jp2iexp.dll"

[HKCU\Software\Classes\CLSID\{CAFEEFAC-0013-0001-0020-ABCDEFFEDCBA}]
"(Default)" = "Java Plug-in 1.3.1_20"

[HKCU\Software\Classes\CLSID\{CAFEEFAC-0014-0002-0027-ABCDEFFEDCBA}\InprocServer32]
"ThreadingModel" = "Apartment"

[HKCU\Software\Classes\CLSID\{CAFEEFAC-0013-0001-0008-ABCDEFFEDCBA}\InprocServer32]
"(Default)" = "%Program Files%\Java\jre6\bin\jp2iexp.dll"

[HKCU\Software\Classes\CLSID\{CAFEEFAC-0014-0002-0016-ABCDEFFEDCBB}\InprocServer32]
"(Default)" = "%Program Files%\Java\jre6\bin\jp2iexp.dll"

[HKCU\Software\Classes\CLSID\{CAFEEFAC-0014-0001-0003-ABCDEFFEDCBB}\InprocServer32]
"(Default)" = "%Program Files%\Java\jre6\bin\jp2iexp.dll"

[HKCU\Software\Classes\CLSID\{CAFEEFAC-0015-0000-0028-ABCDEFFEDCBB}\InprocServer32]
"(Default)" = "%Program Files%\Java\jre6\bin\jp2iexp.dll"

[HKCU\Software\Classes\CLSID\{CAFEEFAC-0014-0002-0022-ABCDEFFEDCBA}\InprocServer32]
"(Default)" = "%Program Files%\Java\jre6\bin\jp2iexp.dll"

[HKCU\Software\Classes\CLSID\{CAFEEFAC-0013-0001-0016-ABCDEFFEDCBB}]
"(Default)" = "Java Plug-in 1.3.1_16"

[HKCU\Software\Classes\CLSID\{CAFEEFAC-0014-0002-0002-ABCDEFFEDCBA}\InprocServer32]
"(Default)" = "%Program Files%\Java\jre6\bin\jp2iexp.dll"

[HKCU\Software\Classes\CLSID\{CAFEEFAC-0016-0000-0007-ABCDEFFEDCBC}\InprocServer32]
"ThreadingModel" = "Apartment"

[HKCU\Software\Classes\CLSID\{CAFEEFAC-0015-0000-0001-ABCDEFFEDCBA}]
"(Default)" = "Java Plug-in 1.5.0_01"

[HKCU\Software\Classes\CLSID\{CAFEEFAC-0015-0000-0008-ABCDEFFEDCBA}\InprocServer32]
"(Default)" = "%Program Files%\Java\jre6\bin\jp2iexp.dll"

[HKCU\Software\Classes\CLSID\{CAFEEFAC-0013-0001-0021-ABCDEFFEDCBA}]
"(Default)" = "Java Plug-in 1.3.1_21"

[HKCU\Software\Classes\CLSID\{CAFEEFAC-0014-0001-0005-ABCDEFFEDCBA}\InprocServer32]
"ThreadingModel" = "Apartment"

[HKCU\Software\Classes\CLSID\{CAFEEFAC-0014-0000-0002-ABCDEFFEDCBB}\InprocServer32]
"(Default)" = "%Program Files%\Java\jre6\bin\jp2iexp.dll"

[HKCU\Software\Classes\CLSID\{CAFEEFAC-0013-0001-0019-ABCDEFFEDCBB}]
"(Default)" = "Java Plug-in 1.3.1_19"

[HKCU\Software\Classes\CLSID\{CAFEEFAC-0013-0001-0006-ABCDEFFEDCBB}\InprocServer32]
"(Default)" = "%Program Files%\Java\jre6\bin\jp2iexp.dll"

[HKCU\Software\Classes\CLSID\{CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA}\InprocServer32]
"ThreadingModel" = "Apartment"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"AppData" = "%Documents and Settings%\%current user%\Application Data"
"Local AppData" = "%Documents and Settings%\%current user%\Local Settings\Application Data"

[HKCU\Software\Classes\CLSID\{CAFEEFAC-0015-0000-0009-ABCDEFFEDCBA}\InprocServer32]
"(Default)" = "%Program Files%\Java\jre6\bin\jp2iexp.dll"

[HKCU\Software\Classes\CLSID\{CAFEEFAC-0016-0000-0007-ABCDEFFEDCBC}]
"(Default)" = "Java Plug-in 1.6.0_07"

[HKCU\Software\Classes\CLSID\{CAFEEFAC-0013-0001-0012-ABCDEFFEDCBA}\InprocServer32]
"(Default)" = "%Program Files%\Java\jre6\bin\jp2iexp.dll"

[HKCU\Software\Classes\CLSID\{CAFEEFAC-0015-0000-0003-ABCDEFFEDCBC}\InprocServer32]
"(Default)" = "%Program Files%\Java\jre6\bin\jp2iexp.dll"

[HKCU\Software\Classes\CLSID\{CAFEEFAC-0015-0000-0000-ABCDEFFEDCBA}\InprocServer32]
"(Default)" = "%Program Files%\Java\jre6\bin\jp2iexp.dll"

[HKCU\Software\Classes\CLSID\{CAFEEFAC-0013-0001-0029-ABCDEFFEDCBA}\InprocServer32]
"ThreadingModel" = "Apartment"

[HKCU\Software\Classes\CLSID\{CAFEEFAC-0013-0001-0030-ABCDEFFEDCBB}\InprocServer32]
"ThreadingModel" = "Apartment"

[HKCU\Software\Classes\CLSID\{CAFEEFAC-0014-0000-0003-ABCDEFFEDCBA}]
"(Default)" = "Java Plug-in 1.4.0_03"

[HKCU\Software\Classes\CLSID\{CAFEEFAC-0014-0002-0026-ABCDEFFEDCBB}\InprocServer32]
"(Default)" = "%Program Files%\Java\jre6\bin\jp2iexp.dll"

[HKCU\Software\Classes\CLSID\{CAFEEFAC-0016-0000-0001-ABCDEFFEDCBC}\InprocServer32]
"(Default)" = "%Program Files%\Java\jre6\bin\jp2iexp.dll"

[HKCU\Software\Classes\CLSID\{CAFEEFAC-0013-0001-0009-ABCDEFFEDCBB}\InprocServer32]
"(Default)" = "%Program Files%\Java\jre6\bin\jp2iexp.dll"

[HKCU\Software\Classes\CLSID\{CAFEEFAC-0016-0000-0004-ABCDEFFEDCBC}\InprocServer32]
"ThreadingModel" = "Apartment"

[HKCU\Software\Classes\CLSID\{CAFEEFAC-0016-0000-0011-ABCDEFFEDCBB}\InprocServer32]
"ThreadingModel" = "Apartment"

[HKCU\Software\Classes\CLSID\{CAFEEFAC-0015-0000-0022-ABCDEFFEDCBB}\InprocServer32]
"(Default)" = "%Program Files%\Java\jre6\bin\jp2iexp.dll"

[HKCU\Software\Classes\CLSID\{CAFEEFAC-0014-0002-0017-ABCDEFFEDCBB}\InprocServer32]
"(Default)" = "%Program Files%\Java\jre6\bin\jp2iexp.dll"

[HKCU\Software\Classes\CLSID\{CAFEEFAC-0014-0002-0003-ABCDEFFEDCBA}\InprocServer32]
"ThreadingModel" = "Apartment"

[HKCU\Software\Classes\CLSID\{CAFEEFAC-0014-0002-0027-ABCDEFFEDCBB}\InprocServer32]
"(Default)" = "%Program Files%\Java\jre6\bin\jp2iexp.dll"

[HKCU\Software\Classes\CLSID\{CAFEEFAC-0015-0000-0028-ABCDEFFEDCBA}]
"(Default)" = "Java Plug-in 1.5.0_28"

[HKCU\Software\Classes\CLSID\{CAFEEFAC-0016-0000-0002-ABCDEFFEDCBB}\InprocServer32]
"(Default)" = "%Program Files%\Java\jre6\bin\jp2iexp.dll"

[HKCU\Software\Classes\CLSID\{CAFEEFAC-0015-0000-0021-ABCDEFFEDCBB}]
"(Default)" = "Java Plug-in 1.5.0_21"

[HKCU\Software\Classes\CLSID\{CAFEEFAC-0016-0000-0006-ABCDEFFEDCBA}]
"(Default)" = "Java Plug-in 1.6.0_06"

[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"Common AppData" = "%Documents and Settings%\All Users\Application Data"

[HKCU\Software\Classes\CLSID\{CAFEEFAC-0015-0000-0030-ABCDEFFEDCBA}]
"(Default)" = "Java Plug-in 1.5.0_30"

[HKCU\Software\Classes\CLSID\{CAFEEFAC-0013-0000-0005-ABCDEFFEDCBA}]
"(Default)" = "Java Plug-in 1.3.0_05"

[HKCU\Software\Classes\CLSID\{CAFEEFAC-0015-0000-0005-ABCDEFFEDCBC}\InprocServer32]
"ThreadingModel" = "Apartment"

[HKCU\Software\Classes\CLSID\{CAFEEFAC-0015-0000-0012-ABCDEFFEDCBB}\InprocServer32]
"(Default)" = "%Program Files%\Java\jre6\bin\jp2iexp.dll"

[HKCU\Software\Classes\CLSID\{CAFEEFAC-0014-0002-FFFF-ABCDEFFEDCBA}\InprocServer32]
"(Default)" = "%Program Files%\Java\jre6\bin\jp2iexp.dll"

[HKCU\Software\Classes\CLSID\{CAFEEFAC-0014-0002-0021-ABCDEFFEDCBA}\InprocServer32]
"ThreadingModel" = "Apartment"

[HKCU\Software\Classes\CLSID\{CAFEEFAC-0015-0000-0010-ABCDEFFEDCBC}]
"(Default)" = "Java Plug-in 1.5.0_10"

[HKCU\Software\Classes\CLSID\{CAFEEFAC-0014-0002-0010-ABCDEFFEDCBA}]
"(Default)" = "Java Plug-in 1.4.2_10"

[HKCU\Software\Classes\CLSID\{CAFEEFAC-0013-0001-0012-ABCDEFFEDCBB}\InprocServer32]
"ThreadingModel" = "Apartment"

[HKCU\Software\Classes\CLSID\{CAFEEFAC-0015-0000-0008-ABCDEFFEDCBC}]
"(Default)" = "Java Plug-in 1.5.0_08"

[HKCU\Software\Classes\CLSID\{CAFEEFAC-0015-0000-0016-ABCDEFFEDCBA}\InprocServer32]
"(Default)" = "%Program Files%\Java\jre6\bin\jp2iexp.dll"

[HKCU\Software\Classes\CLSID\{CAFEEFAC-0014-0002-0017-ABCDEFFEDCBA}]
"(Default)" = "Java Plug-in 1.4.2_17"

[HKCU\Software\Classes\CLSID\{CAFEEFAC-0015-0000-0018-ABCDEFFEDCBA}\InprocServer32]
"ThreadingModel" = "Apartment"

[HKCU\Software\Classes\CLSID\{CAFEEFAC-0015-0000-0025-ABCDEFFEDCBA}]
"(Default)" = "Java Plug-in 1.5.0_25"

[HKCU\Software\Classes\CLSID\{CAFEEFAC-0014-0002-0007-ABCDEFFEDCBA}\InprocServer32]
"(Default)" = "%Program Files%\Java\jre6\bin\jp2iexp.dll"

[HKCU\Software\Classes\CLSID\{CAFEEFAC-0014-0002-0008-ABCDEFFEDCBB}\InprocServer32]
"(Default)" = "%Program Files%\Java\jre6\bin\jp2iexp.dll"

[HKCU\Software\Classes\CLSID\{CAFEEFAC-0014-0002-0017-ABCDEFFEDCBB}]
"(Default)" = "Java Plug-in 1.4.2_17"

[HKCU\Software\Classes\CLSID\{CAFEEFAC-0014-0002-0002-ABCDEFFEDCBA}\InprocServer32]
"ThreadingModel" = "Apartment"

[HKCU\Software\Classes\CLSID\{CAFEEFAC-0014-0002-0015-ABCDEFFEDCBB}\InprocServer32]
"ThreadingModel" = "Apartment"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{DBC80044-A445-435B-BC74-9C25C1C588A9}\iexplore]
"Time" = "DE 07 05 00 02 00 0D 00 0E 00 38 00 07 00 07 03"

[HKCU\Software\Classes\CLSID\{CAFEEFAC-0016-0000-0002-ABCDEFFEDCBC}\InprocServer32]
"(Default)" = "%Program Files%\Java\jre6\bin\jp2iexp.dll"

[HKCU\Software\Classes\CLSID\{CAFEEFAC-0013-0001-0003-ABCDEFFEDCBA}]
"(Default)" = "Java Plug-in 1.3.1_03"

[HKCU\Software\Classes\CLSID\{CAFEEFAC-0015-0000-0011-ABCDEFFEDCBB}\InprocServer32]
"(Default)" = "%Program Files%\Java\jre6\bin\jp2iexp.dll"

[HKCU\Software\Classes\CLSID\{CAFEEFAC-0013-0001-0025-ABCDEFFEDCBA}\InprocServer32]
"(Default)" = "%Program Files%\Java\jre6\bin\jp2iexp.dll"

[HKCU\Software\Classes\CLSID\{CAFEEFAC-0014-0002-0023-ABCDEFFEDCBB}]
"(Default)" = "Java Plug-in 1.4.2_23"

[HKCU\Software\Classes\CLSID\{CAFEEFAC-0015-0000-0013-ABCDEFFEDCBB}]
"(Default)" = "Java Plug-in 1.5.0_13"

[HKCU\Software\Classes\CLSID\{CAFEEFAC-0013-0001-0009-ABCDEFFEDCBB}\InprocServer32]
"ThreadingModel" = "Apartment"

[HKCU\Software\Classes\CLSID\{CAFEEFAC-0016-0000-0014-ABCDEFFEDCBC}]
"(Default)" = "Java Plug-in 1.6.0_14"

[HKCU\Software\Classes\CLSID\{CAFEEFAC-0014-0002-0018-ABCDEFFEDCBA}]
"(Default)" = "Java Plug-in 1.4.2_18"

[HKCU\Software\Classes\CLSID\{CAFEEFAC-0015-0000-0018-ABCDEFFEDCBC}\InprocServer32]
"ThreadingModel" = "Apartment"

[HKCU\Software\Classes\CLSID\{CAFEEFAC-0014-0000-0000-ABCDEFFEDCBB}\InprocServer32]
"(Default)" = "%Program Files%\Java\jre6\bin\jp2iexp.dll"

[HKCU\Software\Classes\CLSID\{CAFEEFAC-0014-0000-0004-ABCDEFFEDCBB}\InprocServer32]
"(Default)" = "%Program Files%\Java\jre6\bin\jp2iexp.dll"

[HKCU\Software\Classes\CLSID\{CAFEEFAC-0015-0000-0001-ABCDEFFEDCBA}\InprocServer32]
"(Default)" = "%Program Files%\Java\jre6\bin\jp2iexp.dll"

[HKCU\Software\Classes\CLSID\{CAFEEFAC-0015-0000-0022-ABCDEFFEDCBA}\InprocServer32]
"ThreadingModel" = "Apartment"

[HKCU\Software\Classes\CLSID\{CAFEEFAC-0016-0000-0011-ABCDEFFEDCBA}]
"(Default)" = "Java Plug-in 1.6.0_11"

[HKCU\Software\Classes\CLSID\{CAFEEFAC-0013-0001-0008-ABCDEFFEDCBB}\InprocServer32]
"(Default)" = "%Program Files%\Java\jre6\bin\jp2iexp.dll"

[HKCU\Software\Classes\CLSID\{CAFEEFAC-0013-0001-0018-ABCDEFFEDCBA}\InprocServer32]
"ThreadingModel" = "Apartment"

[HKCU\Software\Classes\CLSID\{CAFEEFAC-0014-0001-0001-ABCDEFFEDCBB}\InprocServer32]
"(Default)" = "%Program Files%\Java\jre6\bin\jp2iexp.dll"

[HKCU\Software\Classes\CLSID\{CAFEEFAC-0014-0002-0024-ABCDEFFEDCBB}\InprocServer32]
"(Default)" = "%Program Files%\Java\jre6\bin\jp2iexp.dll"

[HKCU\Software\Classes\CLSID\{CAFEEFAC-0013-0001-0023-ABCDEFFEDCBB}]
"(Default)" = "Java Plug-in 1.3.1_23"

[HKCU\Software\Classes\CLSID\{CAFEEFAC-0015-0000-0016-ABCDEFFEDCBA}]
"(Default)" = "Java Plug-in 1.5.0_16"

[HKCU\Software\Classes\CLSID\{CAFEEFAC-0015-0000-0018-ABCDEFFEDCBB}\InprocServer32]
"ThreadingModel" = "Apartment"

[HKCU\Software\Classes\CLSID\{CAFEEFAC-0015-0000-0015-ABCDEFFEDCBA}\InprocServer32]
"(Default)" = "%Program Files%\Java\jre6\bin\jp2iexp.dll"

[HKCU\Software\Classes\CLSID\{CAFEEFAC-0013-0001-0005-ABCDEFFEDCBA}\InprocServer32]
"(Default)" = "%Program Files%\Java\jre6\bin\jp2iexp.dll"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{CA8A9780-280D-11CF-A24D-444553540000}\iexplore]
"Count" = "1"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"Cookies" = "%Documents and Settings%\%current user%\Cookies"

[HKCU\Software\Classes\CLSID\{CAFEEFAC-0014-0001-0002-ABCDEFFEDCBB}\InprocServer32]
"(Default)" = "%Program Files%\Java\jre6\bin\jp2iexp.dll"

[HKCU\Software\Classes\CLSID\{CAFEEFAC-0016-0000-0011-ABCDEFFEDCBB}]
"(Default)" = "Java Plug-in 1.6.0_11"

[HKCU\Software\Classes\CLSID\{CAFEEFAC-0015-0000-0029-ABCDEFFEDCBA}]
"(Default)" = "Java Plug-in 1.5.0_29"

[HKCU\Software\Classes\CLSID\{CAFEEFAC-0014-0000-0004-ABCDEFFEDCBB}]
"(Default)" = "Java Plug-in 1.4.0_04"

[HKCU\Software\Classes\CLSID\{CAFEEFAC-0015-0000-0017-ABCDEFFEDCBA}\InprocServer32]
"(Default)" = "%Program Files%\Java\jre6\bin\jp2iexp.dll"

[HKCU\Software\Classes\CLSID\{CAFEEFAC-0015-0000-0011-ABCDEFFEDCBB}]
"(Default)" = "Java Plug-in 1.5.0_11"

[HKCU\Software\Classes\CLSID\{CAFEEFAC-0013-0001-0005-ABCDEFFEDCBA}]
"(Default)" = "Java Plug-in 1.3.1_05"

[HKCU\Software\Classes\CLSID\{CAFEEFAC-0015-0000-0013-ABCDEFFEDCBA}\InprocServer32]
"(Default)" = "%Program Files%\Java\jre6\bin\jp2iexp.dll"

[HKCU\Software\Classes\CLSID\{CAFEEFAC-0014-0000-0002-ABCDEFFEDCBB}\InprocServer32]
"ThreadingModel" = "Apartment"

[HKCU\Software\Classes\CLSID\{CAFEEFAC-0015-0000-0024-ABCDEFFEDCBB}]
"(Default)" = "Java Plug-in 1.5.0_24"

[HKCU\Software\Classes\CLSID\{CAFEEFAC-0016-0000-0006-ABCDEFFEDCBC}]
"(Default)" = "Java Plug-in 1.6.0_06"

[HKCU\Software\Classes\CLSID\{CAFEEFAC-0015-0000-0003-ABCDEFFEDCBC}]
"(Default)" = "Java Plug-in 1.5.0_03"

[HKCU\Software\Classes\CLSID\{CAFEEFAC-0016-0000-0013-ABCDEFFEDCBA}]
"(Default)" = "Java Plug-in 1.6.0_13"

[HKCU\Software\Classes\CLSID\{CAFEEFAC-0015-0000-0028-ABCDEFFEDCBB}]
"(Default)" = "Java Plug-in 1.5.0_28"

[HKCU\Software\Classes\CLSID\{CAFEEFAC-0015-0000-0024-ABCDEFFEDCBA}]
"(Default)" = "Java Plug-in 1.5.0_24"

[HKCU\Software\Classes\CLSID\{CAFEEFAC-0013-0001-0029-ABCDEFFEDCBB}\InprocServer32]
"ThreadingModel" = "Apartment"

[HKCU\Software\Classes\CLSID\{CAFEEFAC-0015-0000-0008-ABCDEFFEDCBB}\InprocServer32]
"ThreadingModel" = "Apartment"

[HKCU\Software\Classes\CLSID\{CAFEEFAC-0016-0000-0014-ABCDEFFEDCBB}\InprocServer32]
"ThreadingModel" = "Apartment"

[HKCU\Software\Classes\CLSID\{CAFEEFAC-0016-0000-0002-ABCDEFFEDCBA}]
"(Default)" = "Java Plug-in 1.6.0_02"

[HKCU\Software\Classes\CLSID\{CAFEEFAC-0016-0000-0017-ABCDEFFEDCBC}]
"(Default)" = "Java Plug-in 1.6.0_17"

[HKCU\Software\Classes\CLSID\{CAFEEFAC-0016-0000-0011-ABCDEFFEDCBA}\InprocServer32]
"ThreadingModel" = "Apartment"

[HKCU\Software\Classes\CLSID\{CAFEEFAC-0014-0002-0002-ABCDEFFEDCBB}\InprocServer32]
"(Default)" = "%Program Files%\Java\jre6\bin\jp2iexp.dll"

[HKCU\Software\Classes\CLSID\{CAFEEFAC-0016-0000-0013-ABCDEFFEDCBB}\InprocServer32]
"(Default)" = "%Program Files%\Java\jre6\bin\jp2iexp.dll"

[HKCU\Software\Classes\CLSID\{CAFEEFAC-0016-0000-0008-ABCDEFFEDCBB}\InprocServer32]
"(Default)" = "%Program Files%\Java\jre6\bin\jp2iexp.dll"

[HKCU\Software\Classes\CLSID\{CAFEEFAC-0014-0000-0003-ABCDEFFEDCBB}\InprocServer32]
"ThreadingModel" = "Apartment"

[HKCU\Software\Classes\CLSID\{CAFEEFAC-0016-0000-0005-ABCDEFFEDCBB}\InprocServer32]
"(Default)" = "%Program Files%\Java\jre6\bin\jp2iexp.dll"

[HKLM\SOFTWARE\Microsoft\Cryptography\RNG]
"Seed" = "5C 23 DD 48 BE 03 13 DB F0 95 A9 0F A1 E3 0D E8"

[HKCU\Software\Classes\CLSID\{CAFEEFAC-0015-0000-0003-ABCDEFFEDCBB}]
"(Default)" = "Java Plug-in 1.5.0_03"

[HKCU\Software\Classes\CLSID\{CAFEEFAC-0013-0001-0014-ABCDEFFEDCBB}\InprocServer32]
"(Default)" = "%Program Files%\Java\jre6\bin\jp2iexp.dll"

[HKCU\Software\Classes\CLSID\{CAFEEFAC-0016-0000-0011-ABCDEFFEDCBA}\InprocServer32]
"(Default)" = "%Program Files%\Java\jre6\bin\jp2iexp.dll"

[HKCU\Software\Classes\CLSID\{CAFEEFAC-0014-0002-0014-ABCDEFFEDCBA}]
"(Default)" = "Java Plug-in 1.4.2_14"

[HKCU\Software\Classes\CLSID\{CAFEEFAC-0014-0002-0029-ABCDEFFEDCBA}\InprocServer32]
"ThreadingModel" = "Apartment"

[HKCU\Software\Classes\CLSID\{CAFEEFAC-0014-0000-0000-ABCDEFFEDCBA}\InprocServer32]
"ThreadingModel" = "Apartment"

[HKCU\Software\Classes\CLSID\{CAFEEFAC-0014-0002-0019-ABCDEFFEDCBB}\InprocServer32]
"ThreadingModel" = "Apartment"

[HKCU\Software\Classes\CLSID\{CAFEEFAC-0016-0000-0000-ABCDEFFEDCBC}\InprocServer32]
"(Default)" = "%Program Files%\Java\jre6\bin\jp2iexp.dll"

[HKCU\Software\Classes\CLSID\{CAFEEFAC-0014-0001-0004-ABCDEFFEDCBB}\InprocServer32]
"ThreadingModel" = "Apartment"

[HKCU\Software\Classes\CLSID\{CAFEEFAC-0015-0000-0002-ABCDEFFEDCBA}\InprocServer32]
"ThreadingModel" = "Apartment"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"Favorites" = "%Documents and Settings%\%current user%\Favorites"

[HKCU\Software\Classes\CLSID\{CAFEEFAC-0015-0000-0023-ABCDEFFEDCBB}\InprocServer32]
"(Default)" = "%Program Files%\Java\jre6\bin\jp2iexp.dll"

[HKCU\Software\Classes\CLSID\{CAFEEFAC-0013-0001-0018-ABCDEFFEDCBB}\InprocServer32]
"(Default)" = "%Program Files%\Java\jre6\bin\jp2iexp.dll"

[HKCU\Software\Classes\CLSID\{CAFEEFAC-0015-0000-0014-ABCDEFFEDCBB}\InprocServer32]
"ThreadingModel" = "Apartment"

[HKCU\Software\Classes\CLSID\{CAFEEFAC-0016-0000-FFFF-ABCDEFFEDCBA}\InprocServer32]
"(Default)" = "%Program Files%\Java\jre6\bin\jp2iexp.dll"

[HKCU\Software\Classes\CLSID\{CAFEEFAC-0015-0000-0015-ABCDEFFEDCBB}]
"(Default)" = "Java Plug-in 1.5.0_15"

[HKCU\Software\Classes\CLSID\{CAFEEFAC-0015-0000-0019-ABCDEFFEDCBA}]
"(Default)" = "Java Plug-in 1.5.0_19"

[HKCU\Software\Classes\CLSID\{CAFEEFAC-0014-0002-0020-ABCDEFFEDCBB}]
"(Default)" = "Java Plug-in 1.4.2_20"

[HKCU\Software\Classes\CLSID\{CAFEEFAC-0015-0000-0014-ABCDEFFEDCBC}\InprocServer32]
"ThreadingModel" = "Apartment"

[HKCU\Software\Classes\CLSID\{CAFEEFAC-0015-0000-0017-ABCDEFFEDCBB}\InprocServer32]
"ThreadingModel" = "Apartment"

[HKCU\Software\Classes\CLSID\{CAFEEFAC-0013-0001-0026-ABCDEFFEDCBB}\InprocServer32]
"ThreadingModel" = "Apartment"

[HKCU\Software\Classes\CLSID\{CAFEEFAC-0013-0001-0010-ABCDEFFEDCBA}\InprocServer32]
"(Default)" = "%Program Files%\Java\jre6\bin\jp2iexp.dll"

[HKCU\Software\Classes\CLSID\{CAFEEFAC-0014-0002-0022-ABCDEFFEDCBB}\InprocServer32]
"(Default)" = "%Program Files%\Java\jre6\bin\jp2iexp.dll"

[HKCU\Software\Classes\CLSID\{CAFEEFAC-0014-0002-0006-ABCDEFFEDCBA}]
"(Default)" = "Java Plug-in 1.4.2_06"

[HKCU\Software\Classes\CLSID\{CAFEEFAC-0013-0001-0015-ABCDEFFEDCBB}\InprocServer32]
"(Default)" = "%Program Files%\Java\jre6\bin\jp2iexp.dll"

[HKCU\Software\Classes\CLSID\{CAFEEFAC-0015-0000-0000-ABCDEFFEDCBC}]
"(Default)" = "Java Plug-in 1.5.0"

[HKCU\Software\Classes\CLSID\{CAFEEFAC-0013-0001-0013-ABCDEFFEDCBA}]
"(Default)" = "Java Plug-in 1.3.1_13"

[HKCU\Software\Classes\CLSID\{CAFEEFAC-0014-0002-0013-ABCDEFFEDCBB}\InprocServer32]
"ThreadingModel" = "Apartment"

[HKCU\Software\Classes\CLSID\{CAFEEFAC-0015-0000-0016-ABCDEFFEDCBB}\InprocServer32]
"(Default)" = "%Program Files%\Java\jre6\bin\jp2iexp.dll"

[HKCU\Software\Classes\CLSID\{CAFEEFAC-0015-0000-0022-ABCDEFFEDCBC}\InprocServer32]
"ThreadingModel" = "Apartment"

[HKCU\Software\Classes\CLSID\{CAFEEFAC-0015-0000-0011-ABCDEFFEDCBC}\InprocServer32]
"ThreadingModel" = "Apartment"

[HKCU\Software\Classes\CLSID\{CAFEEFAC-0013-0001-0011-ABCDEFFEDCBA}\InprocServer32]
"ThreadingModel" = "Apartment"

[HKCU\Software\Classes\CLSID\{CAFEEFAC-0016-0000-0017-ABCDEFFEDCBA}\InprocServer32]
"(Default)" = "%Program Files%\Java\jre6\bin\jp2iexp.dll"

[HKCU\Software\Classes\CLSID\{CAFEEFAC-0014-0002-0005-ABCDEFFEDCBA}]
"(Default)" = "Java Plug-in 1.4.2_05"

[HKCU\Software\Classes\CLSID\{CAFEEFAC-0015-0000-0020-ABCDEFFEDCBB}\InprocServer32]
"(Default)" = "%Program Files%\Java\jre6\bin\jp2iexp.dll"

[HKCU\Software\Classes\CLSID\{CAFEEFAC-0014-0001-0005-ABCDEFFEDCBA}]
"(Default)" = "Java Plug-in 1.4.1_05"

[HKCU\Software\Classes\CLSID\{CAFEEFAC-0013-0001-0006-ABCDEFFEDCBB}]
"(Default)" = "Java Plug-in 1.3.1_06"

[HKCU\Software\Classes\CLSID\{CAFEEFAC-0016-0000-0012-ABCDEFFEDCBC}]
"(Default)" = "Java Plug-in 1.6.0_12"

[HKCU\Software\Classes\CLSID\{CAFEEFAC-0015-0000-0009-ABCDEFFEDCBC}]
"(Default)" = "Java Plug-in 1.5.0_09"

[HKCU\Software\Classes\CLSID\{CAFEEFAC-0014-0002-0006-ABCDEFFEDCBB}\InprocServer32]
"ThreadingModel" = "Apartment"

[HKCU\Software\Classes\CLSID\{CAFEEFAC-0014-0002-0023-ABCDEFFEDCBA}\InprocServer32]
"(Default)" = "%Program Files%\Java\jre6\bin\jp2iexp.dll"

[HKCU\Software\Classes\CLSID\{CAFEEFAC-0014-0002-0007-ABCDEFFEDCBB}\InprocServer32]
"ThreadingModel" = "Apartment"

[HKCU\Software\Classes\CLSID\{CAFEEFAC-0015-0000-0004-ABCDEFFEDCBA}\InprocServer32]
"ThreadingModel" = "Apartment"

[HKCU\Software\Classes\CLSID\{CAFEEFAC-0015-0000-0025-ABCDEFFEDCBB}\InprocServer32]
"(Default)" = "%Program Files%\Java\jre6\bin\jp2iexp.dll"

[HKCU\Software\Classes\CLSID\{CAFEEFAC-0014-0002-0008-ABCDEFFEDCBB}\InprocServer32]
"ThreadingModel" = "Apartment"

[HKCU\Software\Classes\CLSID\{CAFEEFAC-0013-0001-0023-ABCDEFFEDCBB}\InprocServer32]
"ThreadingModel" = "Apartment"

[HKCU\Software\Classes\CLSID\{CAFEEFAC-0015-0000-0015-ABCDEFFEDCBA}]
"(Default)" = "Java Plug-in 1.5.0_15"

[HKCU\Software\Classes\CLSID\{CAFEEFAC-0014-0002-0027-ABCDEFFEDCBB}\InprocServer32]
"ThreadingModel" = "Apartment"

[HKCU\Software\Classes\CLSID\{CAFEEFAC-0013-0001-0013-ABCDEFFEDCBB}]
"(Default)" = "Java Plug-in 1.3.1_13"

[HKCU\Software\Classes\CLSID\{CAFEEFAC-0013-0001-0017-ABCDEFFEDCBB}]
"(Default)" = "Java Plug-in 1.3.1_17"

[HKCU\Software\Classes\CLSID\{CAFEEFAC-0015-0000-0007-ABCDEFFEDCBC}\InprocServer32]
"ThreadingModel" = "Apartment"

[HKCU\Software\Classes\CLSID\{CAFEEFAC-0015-0000-0003-ABCDEFFEDCBA}\InprocServer32]
"ThreadingModel" = "Apartment"

[HKCU\Software\Classes\CLSID\{CAFEEFAC-0014-0002-0016-ABCDEFFEDCBA}\InprocServer32]
"ThreadingModel" = "Apartment"

[HKCU\Software\Classes\CLSID\{CAFEEFAC-0016-0000-0018-ABCDEFFEDCBC}\InprocServer32]
"ThreadingModel" = "Apartment"

[HKCU\Software\Classes\CLSID\{CAFEEFAC-0014-0002-0019-ABCDEFFEDCBB}]
"(Default)" = "Java Plug-in 1.4.2_19"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{18DF081C-E8AD-4283-A596-FA578C2EBDC3}\iexplore]
"LoadTime" = "30"

[HKCU\Software\Classes\CLSID\{CAFEEFAC-0013-0001-0020-ABCDEFFEDCBB}\InprocServer32]
"(Default)" = "%Program Files%\Java\jre6\bin\jp2iexp.dll"

[HKCU\Software\Classes\CLSID\{CAFEEFAC-0016-0000-0000-ABCDEFFEDCBA}\InprocServer32]
"(Default)" = "%Program Files%\Java\jre6\bin\jp2iexp.dll"

[HKCU\Software\Classes\CLSID\{CAFEEFAC-0015-0000-0006-ABCDEFFEDCBA}\InprocServer32]
"(Default)" = "%Program Files%\Java\jre6\bin\jp2iexp.dll"

[HKCU\Software\Classes\CLSID\{CAFEEFAC-0013-0001-0021-ABCDEFFEDCBB}\InprocServer32]
"ThreadingModel" = "Apartment"

[HKCU\Software\Classes\CLSID\{CAFEEFAC-0013-0001-0024-ABCDEFFEDCBA}\InprocServer32]
"ThreadingModel" = "Apartment"

[HKCU\Software\Classes\CLSID\{CAFEEFAC-0016-0000-FFFF-ABCDEFFEDCBA}]
"(Default)" = "Java Plug-in 1.6.0"

[HKCU\Software\Classes\CLSID\{CAFEEFAC-0015-0000-0013-ABCDEFFEDCBC}\InprocServer32]
"(Default)" = "%Program Files%\Java\jre6\bin\jp2iexp.dll"

[HKCU\Software\Classes\CLSID\{CAFEEFAC-0015-0000-0014-ABCDEFFEDCBB}\InprocServer32]
"(Default)" = "%Program Files%\Java\jre6\bin\jp2iexp.dll"

[HKCU\Software\Classes\CLSID\{CAFEEFAC-0016-0000-0011-ABCDEFFEDCBB}\InprocServer32]
"(Default)" = "%Program Files%\Java\jre6\bin\jp2iexp.dll"

[HKCU\Software\Classes\CLSID\{CAFEEFAC-0014-0001-0007-ABCDEFFEDCBA}]
"(Default)" = "Java Plug-in 1.4.1_07"

[HKCU\Software\Classes\CLSID\{CAFEEFAC-0015-0000-0024-ABCDEFFEDCBB}\InprocServer32]
"(Default)" = "%Program Files%\Java\jre6\bin\jp2iexp.dll"

[HKCU\Software\Classes\CLSID\{CAFEEFAC-0015-0000-0019-ABCDEFFEDCBC}]
"(Default)" = "Java Plug-in 1.5.0_19"

[HKCU\Software\Classes\CLSID\{CAFEEFAC-0015-0000-0015-ABCDEFFEDCBB}\InprocServer32]
"ThreadingModel" = "Apartment"

[HKCU\Software\Classes\CLSID\{CAFEEFAC-0013-0001-0027-ABCDEFFEDCBA}]
"(Default)" = "Java Plug-in 1.3.1_27"

[HKCU\Software\Classes\CLSID\{CAFEEFAC-0013-0001-0015-ABCDEFFEDCBB}]
"(Default)" = "Java Plug-in 1.3.1_15"

[HKCU\Software\Classes\CLSID\{CAFEEFAC-0013-0001-0016-ABCDEFFEDCBB}\InprocServer32]
"(Default)" = "%Program Files%\Java\jre6\bin\jp2iexp.dll"

[HKCU\Software\Classes\CLSID\{CAFEEFAC-0014-0001-0001-ABCDEFFEDCBB}\InprocServer32]
"ThreadingModel" = "Apartment"

[HKCU\Software\Classes\CLSID\{CAFEEFAC-0013-0001-0015-ABCDEFFEDCBA}]
"(Default)" = "Java Plug-in 1.3.1_15"

[HKCU\Software\Classes\CLSID\{CAFEEFAC-0015-0000-0015-ABCDEFFEDCBC}]
"(Default)" = "Java Plug-in 1.5.0_15"

[HKCU\Software\Classes\CLSID\{CAFEEFAC-0013-0000-0003-ABCDEFFEDCBA}\InprocServer32]
"(Default)" = "%Program Files%\Java\jre6\bin\jp2iexp.dll"

[HKCU\Software\Classes\CLSID\{CAFEEFAC-0014-0002-0014-ABCDEFFEDCBA}\InprocServer32]
"ThreadingModel" = "Apartment"

[HKCU\Software\Classes\CLSID\{CAFEEFAC-0014-0002-0007-ABCDEFFEDCBB}\InprocServer32]
"(Default)" = "%Program Files%\Java\jre6\bin\jp2iexp.dll"

[HKCU\Software\Classes\CLSID\{CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA}\InprocServer32]
"(Default)" = "%Program Files%\Java\jre6\bin\jp2iexp.dll"

[HKCU\Software\Classes\CLSID\{CAFEEFAC-0014-0002-0022-ABCDEFFEDCBA}\InprocServer32]
"ThreadingModel" = "Apartment"

[HKCU\Software\Classes\CLSID\{CAFEEFAC-0014-0002-0025-ABCDEFFEDCBB}\InprocServer32]
"(Default)" = "%Program Files%\Java\jre6\bin\jp2iexp.dll"

[HKCU\Software\Classes\CLSID\{CAFEEFAC-0015-0000-0005-ABCDEFFEDCBA}\InprocServer32]
"ThreadingModel" = "Apartment"

[HKCU\Software\Classes\CLSID\{CAFEEFAC-0016-0000-0014-ABCDEFFEDCBC}\InprocServer32]
"(Default)" = "%Program Files%\Java\jre6\bin\jp2iexp.dll"

[HKCU\Software\Classes\CLSID\{CAFEEFAC-0015-0000-0025-ABCDEFFEDCBB}]
"(Default)" = "Java Plug-in 1.5.0_25"

[HKCU\Software\Classes\CLSID\{CAFEEFAC-0014-0002-0014-ABCDEFFEDCBB}\InprocServer32]
"(Default)" = "%Program Files%\Java\jre6\bin\jp2iexp.dll"

[HKCU\Software\Classes\CLSID\{CAFEEFAC-0013-0000-0004-ABCDEFFEDCBA}\InprocServer32]
"ThreadingModel" = "Apartment"

[HKCU\Software\Classes\CLSID\{CAFEEFAC-0013-0001-0010-ABCDEFFEDCBB}\InprocServer32]
"(Default)" = "%Program Files%\Java\jre6\bin\jp2iexp.dll"

[HKCU\Software\Classes\CLSID\{CAFEEFAC-0013-0001-0017-ABCDEFFEDCBA}\InprocServer32]
"ThreadingModel" = "Apartment"

[HKCU\Software\Classes\CLSID\{CAFEEFAC-0016-0000-0018-ABCDEFFEDCBA}\InprocServer32]
"ThreadingModel" = "Apartment"

[HKCU\Software\Classes\CLSID\{CAFEEFAC-0014-0002-0030-ABCDEFFEDCBA}]
"(Default)" = "Java Plug-in 1.4.2_30"

[HKCU\Software\Classes\CLSID\{CAFEEFAC-0014-0002-0009-ABCDEFFEDCBB}\InprocServer32]
"ThreadingModel" = "Apartment"

[HKCU\Software\Classes\CLSID\{CAFEEFAC-0014-0002-0014-ABCDEFFEDCBB}\InprocServer32]
"ThreadingModel" = "Apartment"

[HKCU\Software\Classes\CLSID\{CAFEEFAC-0015-0000-0017-ABCDEFFEDCBC}\InprocServer32]
"ThreadingModel" = "Apartment"

[HKCU\Software\Classes\CLSID\{CAFEEFAC-0016-0000-0004-ABCDEFFEDCBA}\InprocServer32]
"(Default)" = "%Program Files%\Java\jre6\bin\jp2iexp.dll"

[HKCU\Software\Classes\CLSID\{CAFEEFAC-0015-0000-0011-ABCDEFFEDCBC}\InprocServer32]
"(Default)" = "%Program Files%\Java\jre6\bin\jp2iexp.dll"

[HKCU\Software\Classes\CLSID\{CAFEEFAC-0014-0001-0002-ABCDEFFEDCBB}]
"(Default)" = "Java Plug-in 1.4.1_02"

[HKCU\Software\Classes\CLSID\{CAFEEFAC-0013-0001-0022-ABCDEFFEDCBB}\InprocServer32]
"ThreadingModel" = "Apartment"

[HKCU\Software\Classes\CLSID\{CAFEEFAC-0013-0001-0022-ABCDEFFEDCBA}]
"(Default)" = "Java Plug-in 1.3.1_22"

[HKCU\Software\Classes\CLSID\{CAFEEFAC-0016-0000-0001-ABCDEFFEDCBA}]
"(Default)" = "Java Plug-in 1.6.0_01"

[HKCU\Software\Classes\CLSID\{CAFEEFAC-0015-0000-0011-ABCDEFFEDCBA}\InprocServer32]
"(Default)" = "%Program Files%\Java\jre6\bin\jp2iexp.dll"

[HKCU\Software\Classes\CLSID\{CAFEEFAC-0014-0002-0023-ABCDEFFEDCBB}\InprocServer32]
"(Default)" = "%Program Files%\Java\jre6\bin\jp2iexp.dll"

[HKCU\Software\Classes\CLSID\{CAFEEFAC-0014-0002-0025-ABCDEFFEDCBA}\InprocServer32]
"(Default)" = "%Program Files%\Java\jre6\bin\jp2iexp.dll"

[HKCU\Software\Classes\CLSID\{CAFEEFAC-0013-0001-0027-ABCDEFFEDCBB}]
"(Default)" = "Java Plug-in 1.3.1_27"

[HKCU\Software\Classes\CLSID\{CAFEEFAC-0014-0002-0003-ABCDEFFEDCBA}]
"(Default)" = "Java Plug-in 1.4.2_03"

[HKCU\Software\Classes\CLSID\{CAFEEFAC-0015-0000-0006-ABCDEFFEDCBB}]
"(Default)" = "Java Plug-in 1.5.0_06"

[HKCU\Software\Classes\CLSID\{CAFEEFAC-0016-0000-0015-ABCDEFFEDCBA}\InprocServer32]
"ThreadingModel" = "Apartment"

[HKCU\Software\Classes\CLSID\{CAFEEFAC-0013-0001-0002-ABCDEFFEDCBB}]
"(Default)" = "Java Plug-in 1.3.1_02"

[HKCU\Software\Classes\CLSID\{CAFEEFAC-0014-0000-0004-ABCDEFFEDCBA}\InprocServer32]
"(Default)" = "%Program Files%\Java\jre6\bin\jp2iexp.dll"

[HKCU\Software\Classes\CLSID\{CAFEEFAC-0016-0000-0001-ABCDEFFEDCBC}\InprocServer32]
"ThreadingModel" = "Apartment"

[HKCU\Software\Classes\CLSID\{CAFEEFAC-0014-0002-0019-ABCDEFFEDCBA}\InprocServer32]
"(Default)" = "%Program Files%\Java\jre6\bin\jp2iexp.dll"

[HKCU\Software\Classes\CLSID\{CAFEEFAC-0016-0000-0006-ABCDEFFEDCBC}\InprocServer32]
"(Default)" = "%Program Files%\Java\jre6\bin\jp2iexp.dll"

[HKCU\Software\Classes\CLSID\{CAFEEFAC-0014-0002-0001-ABCDEFFEDCBB}\InprocServer32]
"ThreadingModel" = "Apartment"

[HKCU\Software\Classes\CLSID\{CAFEEFAC-0016-0000-0018-ABCDEFFEDCBB}\InprocServer32]
"ThreadingModel" = "Apartment"

[HKCU\Software\Classes\CLSID\{CAFEEFAC-0015-0000-0026-ABCDEFFEDCBC}\InprocServer32]
"ThreadingModel" = "Apartment"

[HKCU\Software\Classes\CLSID\{CAFEEFAC-0014-0001-0006-ABCDEFFEDCBA}]
"(Default)" = "Java Plug-in 1.4.1_06"

[HKCU\Software\Classes\CLSID\{CAFEEFAC-0014-0001-0002-ABCDEFFEDCBA}]
"(Default)" = "Java Plug-in 1.4.1_02"

[HKCU\Software\Classes\CLSID\{CAFEEFAC-0013-0001-0006-ABCDEFFEDCBA}\InprocServer32]
"(Default)" = "%Program Files%\Java\jre6\bin\jp2iexp.dll"

[HKCU\Software\Classes\CLSID\{CAFEEFAC-0014-0001-0005-ABCDEFFEDCBB}\InprocServer32]
"ThreadingModel" = "Apartment"

[HKCU\Software\Classes\CLSID\{CAFEEFAC-0016-0000-0002-ABCDEFFEDCBA}\InprocServer32]
"(Default)" = "%Program Files%\Java\jre6\bin\jp2iexp.dll"

[HKCU\Software\Classes\CLSID\{CAFEEFAC-0016-0000-0003-ABCDEFFEDCBB}\InprocServer32]
"(Default)" = "%Program Files%\Java\jre6\bin\jp2iexp.dll"

[HKCU\Software\Classes\CLSID\{CAFEEFAC-0013-0001-0024-ABCDEFFEDCBA}]
"(Default)" = "Java Plug-in 1.3.1_24"

[HKCU\Software\Classes\CLSID\{CAFEEFAC-0013-0001-0022-ABCDEFFEDCBA}\InprocServer32]
"ThreadingModel" = "Apartment"

[HKCU\Software\Classes\CLSID\{CAFEEFAC-0014-0002-0000-ABCDEFFEDCBB}\InprocServer32]
"ThreadingModel" = "Apartment"

[HKCU\Software\Classes\CLSID\{CAFEEFAC-0015-0000-0003-ABCDEFFEDCBC}\InprocServer32]
"ThreadingModel" = "Apartment"

[HKCU\Software\Classes\CLSID\{CAFEEFAC-0014-0000-0001-ABCDEFFEDCBB}\InprocServer32]
"ThreadingModel" = "Apartment"

[HKCU\Software\Classes\CLSID\{CAFEEFAC-0014-0001-0003-ABCDEFFEDCBA}\InprocServer32]
"(Default)" = "%Program Files%\Java\jre6\bin\jp2iexp.dll"

[HKCU\Software\Classes\CLSID\{CAFEEFAC-0016-0000-0013-ABCDEFFEDCBC}\InprocServer32]
"(Default)" = "%Program Files%\Java\jre6\bin\jp2iexp.dll"

[HKCU\Software\Classes\CLSID\{CAFEEFAC-0015-0000-0001-ABCDEFFEDCBA}\InprocServer32]
"ThreadingModel" = "Apartment"

[HKCU\Software\Classes\CLSID\{CAFEEFAC-0015-0000-0014-ABCDEFFEDCBC}]
"(Default)" = "Java Plug-in 1.5.0_14"

[HKCU\Software\Classes\CLSID\{CAFEEFAC-0015-0000-0005-ABCDEFFEDCBB}\InprocServer32]
"ThreadingModel" = "Apartment"

[HKCU\Software\Classes\CLSID\{CAFEEFAC-0013-0001-0008-ABCDEFFEDCBA}]
"(Default)" = "Java Plug-in 1.3.1_08"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{D27CDB6E-AE6D-11CF-96B8-444553540000}\iexplore]
"Time" = "DE 07 05 00 02 00 0D 00 0E 00 38 00 0B 00 5B 02"

[HKCU\Software\Classes\CLSID\{CAFEEFAC-0014-0002-0028-ABCDEFFEDCBA}]
"(Default)" = "Java Plug-in 1.4.2_28"

[HKCU\Software\Classes\CLSID\{CAFEEFAC-0014-0002-0012-ABCDEFFEDCBB}]
"(Default)" = "Java Plug-in 1.4.2_12"

[HKCU\Software\Classes\CLSID\{CAFEEFAC-0015-0000-0026-ABCDEFFEDCBA}\InprocServer32]
"(Default)" = "%Program Files%\Java\jre6\bin\jp2iexp.dll"

[HKCU\Software\Classes\CLSID\{CAFEEFAC-0013-0001-0002-ABCDEFFEDCBB}\InprocServer32]
"(Default)" = "%Program Files%\Java\jre6\bin\jp2iexp.dll"

[HKCU\Software\Classes\CLSID\{CAFEEFAC-0014-0001-0001-ABCDEFFEDCBA}\InprocServer32]
"(Default)" = "%Program Files%\Java\jre6\bin\jp2iexp.dll"

[HKCU\Software\Classes\CLSID\{CAFEEFAC-0014-0002-0015-ABCDEFFEDCBA}]
"(Default)" = "Java Plug-in 1.4.2_15"

[HKCU\Software\Classes\CLSID\{CAFEEFAC-0015-0000-0006-ABCDEFFEDCBA}]
"(Default)" = "Java Plug-in 1.5.0_06"

[HKCU\Software\Microsoft\Internet Explorer\DOMStorage\ytddownloader.com]
"(Default)" = "13"

[HKCU\Software\Classes\CLSID\{CAFEEFAC-0014-0002-0009-ABCDEFFEDCBA}]
"(Default)" = "Java Plug-in 1.4.2_09"

Proxy settings are disabled:

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings]
"ProxyEnable" = "0"

The program modifies IE settings for security zones to map all local web-nodes with no dots which do not refer to any zone to the Intranet Zone:

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"UNCAsIntranet" = "1"

The program modifies IE settings for security zones to map all urls to the Intranet Zone:

"IntranetName" = "1"

The program modifies IE settings for security zones to map all web-nodes that bypassing the proxy to the Intranet Zone:

"ProxyBypass" = "1"

The program deletes the following registry key(s):

[HKCU\Software\Classes\CLSID\{CAFEEFAC-0016-0000-0005-ABCDEFFEDCBB}]
[HKCU\Software\Classes\CLSID\{CAFEEFAC-0015-0000-0000-ABCDEFFEDCBC}]
[HKCU\Software\Classes\CLSID\{CAFEEFAC-0015-0000-0004-ABCDEFFEDCBA}]
[HKCU\Software\Classes\CLSID\{CAFEEFAC-0013-0001-0014-ABCDEFFEDCBA}]
[HKCU\Software\Classes\CLSID\{CAFEEFAC-0014-0002-0015-ABCDEFFEDCBA}\InprocServer32]
[HKCU\Software\Classes\CLSID\{CAFEEFAC-0015-0000-0015-ABCDEFFEDCBB}\InprocServer32]
[HKCU\Software\Classes\CLSID\{CAFEEFAC-0016-0000-0014-ABCDEFFEDCBC}]
[HKCU\Software\Classes\CLSID\{CAFEEFAC-0014-0002-0026-ABCDEFFEDCBB}\InprocServer32]
[HKCU\Software\Classes\CLSID\{CAFEEFAC-0015-0000-0028-ABCDEFFEDCBB}]
[HKCU\Software\Classes\CLSID\{CAFEEFAC-0013-0001-0030-ABCDEFFEDCBA}]
[HKCU\Software\Classes\CLSID\{CAFEEFAC-0015-0000-0022-ABCDEFFEDCBB}\InprocServer32]
[HKCU\Software\Classes\CLSID\{CAFEEFAC-0016-0000-0012-ABCDEFFEDCBA}\InprocServer32]
[HKCU\Software\Classes\CLSID\{CAFEEFAC-0014-0002-0030-ABCDEFFEDCBB}\InprocServer32]
[HKCU\Software\Classes\CLSID\{CAFEEFAC-0013-0001-0016-ABCDEFFEDCBB}\InprocServer32]
[HKCU\Software\Classes\CLSID\{CAFEEFAC-0014-0000-0001-ABCDEFFEDCBB}\InprocServer32]
[HKCU\Software\Classes\CLSID\{CAFEEFAC-0014-0002-0025-ABCDEFFEDCBA}]
[HKCU\Software\Classes\CLSID\{CAFEEFAC-0015-0000-0023-ABCDEFFEDCBA}]
[HKCU\Software\Classes\CLSID\{CAFEEFAC-0015-0000-0027-ABCDEFFEDCBC}\InprocServer32]
[HKCU\Software\Classes\CLSID\{CAFEEFAC-0015-0000-0022-ABCDEFFEDCBA}]
[HKCU\Software\Classes\CLSID\{CAFEEFAC-0013-0001-0028-ABCDEFFEDCBA}]
[HKCU\Software\Classes\CLSID\{CAFEEFAC-0013-0001-0030-ABCDEFFEDCBB}\InprocServer32]
[HKCU\Software\Classes\CLSID\{CAFEEFAC-0013-0001-0002-ABCDEFFEDCBA}]
[HKCU\Software\Classes\CLSID\{CAFEEFAC-0014-0002-0004-ABCDEFFEDCBB}]
[HKCU\Software\Classes\CLSID\{CAFEEFAC-0014-0002-0017-ABCDEFFEDCBB}\InprocServer32]
[HKCU\Software\Classes\CLSID\{CAFEEFAC-0014-0001-0004-ABCDEFFEDCBA}]
[HKCU\Software\Classes\CLSID\{CAFEEFAC-0014-0002-0010-ABCDEFFEDCBA}\InprocServer32]
[HKCU\Software\Classes\CLSID\{CAFEEFAC-0014-0000-0003-ABCDEFFEDCBA}\InprocServer32]
[HKCU\Software\Classes\CLSID\{CAFEEFAC-0015-0000-0016-ABCDEFFEDCBB}\InprocServer32]
[HKCU\Software\Classes\CLSID\{CAFEEFAC-0013-0001-0018-ABCDEFFEDCBB}]
[HKCU\Software\Classes\CLSID\{CAFEEFAC-0013-0001-0013-ABCDEFFEDCBA}]
[HKCU\Software\Classes\CLSID\{8AD9C840-044E-11D1-B3E9-00805F499D93}\InprocServer32]
[HKCU\Software\Classes\CLSID\{CAFEEFAC-0016-0000-0011-ABCDEFFEDCBC}\InprocServer32]
[HKCU\Software\Classes\CLSID\{CAFEEFAC-0014-0002-0000-ABCDEFFEDCBA}]
[HKCU\Software\Classes\CLSID\{CAFEEFAC-0016-0000-0003-ABCDEFFEDCBA}]
[HKCU\Software\Classes\CLSID\{CAFEEFAC-0013-0001-0022-ABCDEFFEDCBA}]
[HKCU\Software\Classes\CLSID\{CAFEEFAC-0015-0000-0012-ABCDEFFEDCBB}]
[HKCU\Software\Classes\CLSID\{CAFEEFAC-0016-0000-0018-ABCDEFFEDCBA}\InprocServer32]
[HKCU\Software\Classes\CLSID\{CAFEEFAC-0015-0000-0004-ABCDEFFEDCBB}\InprocServer32]
[HKCU\Software\Classes\CLSID\{CAFEEFAC-0016-0000-0008-ABCDEFFEDCBB}\InprocServer32]
[HKCU\Software\Classes\CLSID\{CAFEEFAC-0015-0000-0026-ABCDEFFEDCBB}\InprocServer32]
[HKCU\Software\Classes\CLSID\{CAFEEFAC-0016-0000-0003-ABCDEFFEDCBA}\InprocServer32]
[HKCU\Software\Classes\CLSID\{CAFEEFAC-0014-0002-0023-ABCDEFFEDCBB}]
[HKCU\Software\Classes\CLSID\{CAFEEFAC-0015-0000-0028-ABCDEFFEDCBC}\InprocServer32]
[HKCU\Software\Classes\CLSID\{CAFEEFAC-0014-0000-0001-ABCDEFFEDCBB}]
[HKCU\Software\Classes\CLSID\{CAFEEFAC-0016-0000-0015-ABCDEFFEDCBA}]
[HKCU\Software\Classes\CLSID\{CAFEEFAC-0015-0000-0028-ABCDEFFEDCBA}\InprocServer32]
[HKCU\Software\Classes\CLSID\{CAFEEFAC-0015-0000-0002-ABCDEFFEDCBB}]
[HKCU\Software\Classes\CLSID\{CAFEEFAC-0015-0000-0012-ABCDEFFEDCBB}\InprocServer32]
[HKCU\Software\Classes\CLSID\{CAFEEFAC-0015-0000-0023-ABCDEFFEDCBB}\InprocServer32]
[HKCU\Software\Classes\CLSID\{CAFEEFAC-0014-0000-0003-ABCDEFFEDCBB}\InprocServer32]
[HKCU\Software\Classes\CLSID\{CAFEEFAC-0016-0000-0007-ABCDEFFEDCBC}]
[HKCU\Software\Classes\CLSID\{CAFEEFAC-0013-0001-0029-ABCDEFFEDCBB}\InprocServer32]
[HKCU\Software\Classes\CLSID\{CAFEEFAC-0014-0002-0028-ABCDEFFEDCBA}]
[HKCU\Software\Classes\CLSID\{CAFEEFAC-0014-0002-0012-ABCDEFFEDCBA}]
[HKCU\Software\Classes\CLSID\{CAFEEFAC-0013-0000-0004-ABCDEFFEDCBA}]
[HKCU\Software\Classes\CLSID\{CAFEEFAC-0014-0002-0023-ABCDEFFEDCBA}]
[HKCU\Software\Classes\CLSID\{CAFEEFAC-0015-0000-0011-ABCDEFFEDCBB}\InprocServer32]
[HKCU\Software\Classes\CLSID\{CAFEEFAC-0016-0000-0014-ABCDEFFEDCBB}\InprocServer32]
[HKCU\Software\Classes\CLSID\{CAFEEFAC-0014-0002-0006-ABCDEFFEDCBA}]
[HKCU\Software\Classes\CLSID\{CAFEEFAC-0014-0002-0016-ABCDEFFEDCBB}\InprocServer32]
[HKCU\Software\Classes\CLSID\{CAFEEFAC-0014-0002-0007-ABCDEFFEDCBA}]
[HKCU\Software\Classes\CLSID\{CAFEEFAC-0013-0001-0015-ABCDEFFEDCBA}\InprocServer32]
[HKCU\Software\Classes\CLSID\{CAFEEFAC-0015-0000-0017-ABCDEFFEDCBC}]
[HKCU\Software\Classes\CLSID\{CAFEEFAC-0014-0002-0011-ABCDEFFEDCBB}]
[HKCU\Software\Classes\CLSID\{CAFEEFAC-0013-0001-0024-ABCDEFFEDCBA}]
[HKCU\Software\Classes\CLSID\{CAFEEFAC-0013-0001-0007-ABCDEFFEDCBA}]
[HKCU\Software\Classes\CLSID\{CAFEEFAC-0015-0000-0013-ABCDEFFEDCBC}\InprocServer32]
[HKCU\Software\Classes\CLSID\{CAFEEFAC-0015-0000-0010-ABCDEFFEDCBC}]
[HKCU\Software\Classes\CLSID\{CAFEEFAC-0014-0002-0014-ABCDEFFEDCBB}]
[HKCU\Software\Classes\CLSID\{CAFEEFAC-0015-0000-0016-ABCDEFFEDCBC}\InprocServer32]
[HKCU\Software\Classes\CLSID\{CAFEEFAC-0014-0002-0012-ABCDEFFEDCBB}\InprocServer32]
[HKCU\Software\Classes\CLSID\{CAFEEFAC-0013-0001-0010-ABCDEFFEDCBA}]
[HKCU\Software\Classes\CLSID\{CAFEEFAC-0015-0000-0020-ABCDEFFEDCBA}]
[HKCU\Software\Classes\CLSID\{CAFEEFAC-0015-0000-0028-ABCDEFFEDCBB}\InprocServer32]
[HKCU\Software\Classes\CLSID\{CAFEEFAC-0015-0000-0011-ABCDEFFEDCBC}]
[HKCU\Software\Classes\CLSID\{CAFEEFAC-0015-0000-0029-ABCDEFFEDCBA}]
[HKCU\Software\Classes\CLSID\{CAFEEFAC-0014-0002-0006-ABCDEFFEDCBA}\InprocServer32]
[HKCU\Software\Classes\CLSID\{CAFEEFAC-0015-0000-0007-ABCDEFFEDCBB}]
[HKCU\Software\Classes\CLSID\{CAFEEFAC-0016-0000-0014-ABCDEFFEDCBA}\InprocServer32]
[HKCU\Software\Classes\CLSID\{CAFEEFAC-0016-0000-0005-ABCDEFFEDCBA}\InprocServer32]
[HKCU\Software\Classes\CLSID\{CAFEEFAC-0013-0001-0009-ABCDEFFEDCBB}]
[HKCU\Software\Classes\CLSID\{CAFEEFAC-0013-0001-0015-ABCDEFFEDCBB}\InprocServer32]
[HKCU\Software\Classes\CLSID\{CAFEEFAC-0015-0000-0027-ABCDEFFEDCBB}\InprocServer32]
[HKCU\Software\Classes\CLSID\{CAFEEFAC-0014-0000-0000-ABCDEFFEDCBB}]
[HKCU\Software\Classes\CLSID\{CAFEEFAC-0015-0000-0026-ABCDEFFEDCBA}\InprocServer32]
[HKCU\Software\Classes\CLSID\{CAFEEFAC-0014-0002-0028-ABCDEFFEDCBA}\InprocServer32]
[HKCU\Software\Classes\CLSID\{CAFEEFAC-0015-0000-0017-ABCDEFFEDCBA}\InprocServer32]
[HKCU\Software\Classes\CLSID\{CAFEEFAC-0014-0001-0007-ABCDEFFEDCBA}]
[HKCU\Software\Classes\CLSID\{CAFEEFAC-0015-0000-0026-ABCDEFFEDCBC}\InprocServer32]
[HKCU\Software\Classes\CLSID\{CAFEEFAC-0013-0001-0021-ABCDEFFEDCBA}\InprocServer32]
[HKCU\Software\Classes\CLSID\{CAFEEFAC-0014-0002-0022-ABCDEFFEDCBB}]
[HKCU\Software\Classes\CLSID\{CAFEEFAC-0015-0000-0009-ABCDEFFEDCBB}]
[HKCU\Software\Classes\CLSID\{CAFEEFAC-0013-0001-0004-ABCDEFFEDCBB}\InprocServer32]
[HKCU\Software\Classes\CLSID\{CAFEEFAC-0016-0000-0010-ABCDEFFEDCBB}\InprocServer32]
[HKCU\Software\Classes\CLSID\{CAFEEFAC-0015-0000-0019-ABCDEFFEDCBC}]
[HKCU\Software\Classes\CLSID\{CAFEEFAC-0014-0002-0028-ABCDEFFEDCBB}\InprocServer32]
[HKCU\Software\Classes\CLSID\{CAFEEFAC-0013-0001-0013-ABCDEFFEDCBA}\InprocServer32]
[HKCU\Software\Classes\CLSID\{CAFEEFAC-0015-0000-0006-ABCDEFFEDCBC}]
[HKCU\Software\Classes\CLSID\{CAFEEFAC-0015-0000-0007-ABCDEFFEDCBC}\InprocServer32]
[HKCU\Software\Classes\CLSID\{CAFEEFAC-0013-0001-0004-ABCDEFFEDCBB}]
[HKCU\Software\Classes\CLSID\{CAFEEFAC-0013-0001-0020-ABCDEFFEDCBB}\InprocServer32]
[HKCU\Software\Classes\CLSID\{CAFEEFAC-0014-0002-FFFF-ABCDEFFEDCBA}]
[HKCU\Software\Classes\CLSID\{CAFEEFAC-0013-0001-0021-ABCDEFFEDCBA}]
[HKCU\Software\Classes\CLSID\{CAFEEFAC-0015-0000-0029-ABCDEFFEDCBB}\InprocServer32]
[HKCU\Software\Classes\CLSID\{CAFEEFAC-0016-0000-0010-ABCDEFFEDCBC}]
[HKCU\Software\Classes\CLSID\{CAFEEFAC-0016-0000-0006-ABCDEFFEDCBB}]
[HKCU\Software\Classes\CLSID\{CAFEEFAC-0015-0000-0017-ABCDEFFEDCBC}\InprocServer32]
[HKCU\Software\Classes\CLSID\{CAFEEFAC-0015-0000-0015-ABCDEFFEDCBB}]
[HKCU\Software\Classes\CLSID\{CAFEEFAC-0015-0000-0023-ABCDEFFEDCBB}]
[HKCU\Software\Classes\CLSID\{CAFEEFAC-0013-0001-0029-ABCDEFFEDCBB}]
[HKCU\Software\Classes\CLSID\{CAFEEFAC-0014-0002-FFFF-ABCDEFFEDCBA}\InprocServer32]
[HKCU\Software\Classes\CLSID\{CAFEEFAC-0015-0000-0012-ABCDEFFEDCBA}\InprocServer32]
[HKCU\Software\Classes\JavaPlugin.160_18\CLSID]
[HKCU\Software\Classes\CLSID\{CAFEEFAC-0015-0000-0024-ABCDEFFEDCBA}]
[HKCU\Software\Classes\CLSID\{CAFEEFAC-0014-0002-0005-ABCDEFFEDCBA}]
[HKCU\Software\Classes\CLSID\{CAFEEFAC-0015-0000-0030-ABCDEFFEDCBA}\InprocServer32]
[HKCU\Software\Classes\CLSID\{CAFEEFAC-0014-0001-0000-ABCDEFFEDCBA}\InprocServer32]
[HKCU\Software\Classes\CLSID\{CAFEEFAC-0014-0001-0000-ABCDEFFEDCBA}]
[HKCU\Software\Classes\CLSID\{CAFEEFAC-0015-0000-0003-ABCDEFFEDCBA}]
[HKCU\Software\Classes\CLSID\{CAFEEFAC-0014-0002-0001-ABCDEFFEDCBB}\InprocServer32]
[HKCU\Software\Classes\CLSID\{CAFEEFAC-0013-0001-0006-ABCDEFFEDCBA}\InprocServer32]
[HKCU\Software\Classes\CLSID\{CAFEEFAC-0013-0000-0003-ABCDEFFEDCBA}]
[HKCU\Software\Classes\CLSID\{CAFEEFAC-0014-0002-0006-ABCDEFFEDCBB}]
[HKCU\Software\Classes\CLSID\{CAFEEFAC-0013-0001-0011-ABCDEFFEDCBA}]
[HKCU\Software\Classes\CLSID\{CAFEEFAC-0013-0001-0012-ABCDEFFEDCBB}\InprocServer32]
[HKCU\Software\Classes\CLSID\{CAFEEFAC-0016-0000-0006-ABCDEFFEDCBC}\InprocServer32]
[HKCU\Software\Classes\CLSID\{CAFEEFAC-0016-0000-0002-ABCDEFFEDCBC}]
[HKCU\Software\Classes\CLSID\{CAFEEFAC-0016-0000-0001-ABCDEFFEDCBB}]
[HKCU\Software\Classes\CLSID\{CAFEEFAC-0016-0000-0006-ABCDEFFEDCBA}]
[HKCU\Software\Classes\CLSID\{CAFEEFAC-0016-0000-0016-ABCDEFFEDCBC}]
[HKCU\Software\Classes\CLSID\{CAFEEFAC-0014-0002-0005-ABCDEFFEDCBB}\InprocServer32]
[HKCU\Software\Classes\CLSID\{CAFEEFAC-0016-0000-0000-ABCDEFFEDCBC}]
[HKCU\Software\Classes\CLSID\{CAFEEFAC-0013-0001-0004-ABCDEFFEDCBA}\InprocServer32]
[HKCU\Software\Classes\CLSID\{CAFEEFAC-0014-0002-0023-ABCDEFFEDCBA}\InprocServer32]
[HKCU\Software\Classes\CLSID\{CAFEEFAC-0016-0000-0012-ABCDEFFEDCBB}\InprocServer32]
[HKCU\Software\Classes\CLSID\{CAFEEFAC-0013-0001-0013-ABCDEFFEDCBB}]
[HKCU\Software\Classes\CLSID\{CAFEEFAC-0013-0001-0025-ABCDEFFEDCBB}\InprocServer32]
[HKCU\Software\Classes\CLSID\{CAFEEFAC-0013-0001-0012-ABCDEFFEDCBA}\InprocServer32]
[HKCU\Software\Classes\CLSID\{CAFEEFAC-0015-0000-0014-ABCDEFFEDCBC}]
[HKCU\Software\Classes\CLSID\{CAFEEFAC-0013-0001-0022-ABCDEFFEDCBB}]
[HKCU\Software\Classes\CLSID\{CAFEEFAC-0016-0000-0012-ABCDEFFEDCBC}]
[HKCU\Software\Classes\CLSID\{CAFEEFAC-0014-0002-0022-ABCDEFFEDCBB}\InprocServer32]
[HKCU\Software\Classes\CLSID\{CAFEEFAC-0016-0000-0001-ABCDEFFEDCBB}\InprocServer32]
[HKCU\Software\Classes\CLSID\{CAFEEFAC-0015-0000-0008-ABCDEFFEDCBB}\InprocServer32]
[HKCU\Software\Classes\CLSID\{E19F9331-3110-11D4-991C-005004D3B3DB}\InprocServer32]
[HKCU\Software\Classes\CLSID\{CAFEEFAC-0016-0000-0016-ABCDEFFEDCBA}]
[HKCU\Software\Classes\CLSID\{CAFEEFAC-0015-0000-0024-ABCDEFFEDCBA}\InprocServer32]
[HKCU\Software\Classes\CLSID\{CAFEEFAC-0014-0000-0001-ABCDEFFEDCBA}]
[HKCU\Software\Classes\CLSID\{CAFEEFAC-0016-0000-0015-ABCDEFFEDCBB}]
[HKCU\Software\Classes\CLSID\{CAFEEFAC-0014-0002-0001-ABCDEFFEDCBA}]
[HKCU\Software\Classes\CLSID\{CAFEEFAC-0014-0001-0005-ABCDEFFEDCBB}]
[HKCU\Software\Classes\CLSID\{CAFEEFAC-0014-0002-0020-ABCDEFFEDCBA}]
[HKCU\Software\Classes\CLSID\{CAFEEFAC-0014-0002-0028-ABCDEFFEDCBB}]
[HKCU\Software\Classes\CLSID\{CAFEEFAC-0015-0000-0008-ABCDEFFEDCBC}\InprocServer32]
[HKCU\Software\Classes\CLSID\{CAFEEFAC-0015-0000-0030-ABCDEFFEDCBC}]
[HKCU\Software\Classes\CLSID\{CAFEEFAC-0013-0001-0010-ABCDEFFEDCBB}\InprocServer32]
[HKCU\Software\Classes\CLSID\{CAFEEFAC-0014-0002-0030-ABCDEFFEDCBA}]
[HKCU\Software\Classes\CLSID\{CAFEEFAC-0015-0000-FFFF-ABCDEFFEDCBA}]
[HKCU\Software\Classes\CLSID\{CAFEEFAC-0015-0000-0001-ABCDEFFEDCBC}]
[HKCU\Software\Classes\CLSID\{CAFEEFAC-0015-0000-0021-ABCDEFFEDCBC}]
[HKCU\Software\Classes\CLSID\{CAFEEFAC-0015-0000-0004-ABCDEFFEDCBC}\InprocServer32]
[HKCU\Software\Classes\CLSID\{CAFEEFAC-0015-0000-0010-ABCDEFFEDCBA}]
[HKCU\Software\Classes\CLSID\{CAFEEFAC-0016-0000-0005-ABCDEFFEDCBC}\InprocServer32]
[HKCU\Software\Classes\CLSID\{CAFEEFAC-0013-0001-0002-ABCDEFFEDCBB}\InprocServer32]
[HKCU\Software\Classes\CLSID\{CAFEEFAC-0014-0002-0014-ABCDEFFEDCBA}]
[HKCU\Software\Classes\CLSID\{CAFEEFAC-0013-0001-0000-ABCDEFFEDCBA}]
[HKCU\Software\Classes\CLSID\{CAFEEFAC-0013-0001-0014-ABCDEFFEDCBB}\InprocServer32]
[HKCU\Software\Classes\CLSID\{CAFEEFAC-0016-0000-0018-ABCDEFFEDCBB}]
[HKCU\Software\Classes\CLSID\{CAFEEFAC-0016-0000-0009-ABCDEFFEDCBA}]
[HKCU\Software\Classes\CLSID\{CAFEEFAC-0015-0000-0025-ABCDEFFEDCBB}]
[HKCU\Software\Classes\CLSID\{CAFEEFAC-0013-0001-0012-ABCDEFFEDCBB}]
[HKCU\Software\Classes\CLSID\{CAFEEFAC-0015-0000-0018-ABCDEFFEDCBA}]
[HKCU\Software\Classes\CLSID\{CAFEEFAC-0014-0001-0003-ABCDEFFEDCBA}\InprocServer32]
[HKCU\Software\Classes\CLSID\{CAFEEFAC-0014-0001-0005-ABCDEFFEDCBA}\InprocServer32]
[HKCU\Software\Classes\CLSID\{CAFEEFAC-0013-0001-0008-ABCDEFFEDCBA}]
[HKCU\Software\Classes\CLSID\{CAFEEFAC-0015-0000-0006-ABCDEFFEDCBA}]
[HKCU\Software\Classes\CLSID\{CAFEEFAC-0014-0002-0000-ABCDEFFEDCBA}\InprocServer32]
[HKCU\Software\Classes\CLSID\{CAFEEFAC-0015-0000-0000-ABCDEFFEDCBB}]
[HKCU\Software\Classes\CLSID\{CAFEEFAC-0016-0000-0008-ABCDEFFEDCBC}]
[HKCU\Software\Classes\CLSID\{CAFEEFAC-0014-0002-0026-ABCDEFFEDCBA}]
[HKCU\Software\Classes\CLSID\{CAFEEFAC-0015-0000-0010-ABCDEFFEDCBC}\InprocServer32]
[HKCU\Software\Classes\CLSID\{CAFEEFAC-0016-0000-0004-ABCDEFFEDCBC}\InprocServer32]
[HKCU\Software\Classes\CLSID\{CAFEEFAC-0013-0001-0009-ABCDEFFEDCBA}]
[HKCU\Software\Classes\CLSID\{CAFEEFAC-0016-0000-0014-ABCDEFFEDCBB}]
[HKCU\Software\Classes\CLSID\{CAFEEFAC-0015-0000-0001-ABCDEFFEDCBA}\InprocServer32]
[HKCU\Software\Classes\CLSID\{CAFEEFAC-0015-0000-0028-ABCDEFFEDCBA}]
[HKCU\Software\Classes\CLSID\{CAFEEFAC-0013-0001-0011-ABCDEFFEDCBB}\InprocServer32]
[HKCU\Software\Classes\CLSID\{CAFEEFAC-0014-0001-0006-ABCDEFFEDCBB}\InprocServer32]
[HKCU\Software\Classes\CLSID\{CAFEEFAC-0015-0000-0006-ABCDEFFEDCBC}\InprocServer32]
[HKCU\Software\Classes\CLSID\{CAFEEFAC-0014-0002-0011-ABCDEFFEDCBB}\InprocServer32]
[HKCU\Software\Classes\CLSID\{CAFEEFAC-0013-0001-0003-ABCDEFFEDCBB}]
[HKCU\Software\Classes\CLSID\{CAFEEFAC-0014-0002-0027-ABCDEFFEDCBB}]
[HKCU\Software\Classes\CLSID\{CAFEEFAC-0015-0000-0005-ABCDEFFEDCBA}]
[HKCU\Software\Classes\CLSID\{CAFEEFAC-0015-0000-0029-ABCDEFFEDCBA}\InprocServer32]
[HKCU\Software\Classes\CLSID\{CAFEEFAC-0014-0002-0017-ABCDEFFEDCBA}\InprocServer32]
[HKCU\Software\Classes\CLSID\{CAFEEFAC-0013-0001-0028-ABCDEFFEDCBB}]
[HKCU\Software\Classes\CLSID\{CAFEEFAC-0016-0000-0009-ABCDEFFEDCBB}\InprocServer32]
[HKCU\Software\Classes\CLSID\{CAFEEFAC-0013-0001-0002-ABCDEFFEDCBB}]
[HKCU\Software\Classes\CLSID\{CAFEEFAC-0014-0002-0016-ABCDEFFEDCBA}\InprocServer32]
[HKCU\Software\Classes\CLSID\{CAFEEFAC-0014-0002-0019-ABCDEFFEDCBA}\InprocServer32]
[HKCU\Software\Classes\CLSID\{CAFEEFAC-0015-0000-0008-ABCDEFFEDCBA}\InprocServer32]
[HKCU\Software\Classes\CLSID\{CAFEEFAC-0013-0001-0018-ABCDEFFEDCBA}]
[HKCU\Software\Classes\CLSID\{CAFEEFAC-0014-0002-0005-ABCDEFFEDCBA}\InprocServer32]
[HKCU\Software\Classes\CLSID\{CAFEEFAC-0013-0001-0019-ABCDEFFEDCBA}]
[HKCU\Software\Classes\CLSID\{CAFEEFAC-0013-0001-0023-ABCDEFFEDCBA}\InprocServer32]
[HKCU\Software\Classes\CLSID\{CAFEEFAC-0013-0001-0026-ABCDEFFEDCBA}]
[HKCU\Software\Classes\CLSID\{CAFEEFAC-0016-0000-0013-ABCDEFFEDCBB}]
[HKCU\Software\Classes\CLSID\{CAFEEFAC-0013-0001-0011-ABCDEFFEDCBA}\InprocServer32]
[HKCU\Software\Classes\CLSID\{CAFEEFAC-0014-0002-0000-ABCDEFFEDCBB}]
[HKCU\Software\Classes\CLSID\{CAFEEFAC-0014-0002-0017-ABCDEFFEDCBA}]
[HKCU\Software\Classes\CLSID\{CAFEEFAC-0015-0000-0012-ABCDEFFEDCBC}]
[HKCU\Software\Classes\CLSID\{CAFEEFAC-0014-0001-0002-ABCDEFFEDCBB}\InprocServer32]
[HKCU\Software\Classes\CLSID\{CAFEEFAC-0015-0000-0015-ABCDEFFEDCBC}]
[HKCU\Software\Classes\CLSID\{CAFEEFAC-0016-0000-0005-ABCDEFFEDCBA}]
[HKCU\Software\Classes\CLSID\{CAFEEFAC-0014-0002-0004-ABCDEFFEDCBB}\InprocServer32]
[HKCU\Software\Classes\CLSID\{CAFEEFAC-0016-0000-0004-ABCDEFFEDCBA}]
[HKCU\Software\Classes\CLSID\{CAFEEFAC-0016-0000-0011-ABCDEFFEDCBA}]
[HKCU\Software\Classes\CLSID\{CAFEEFAC-0015-0000-0007-ABCDEFFEDCBB}\InprocServer32]
[HKCU\Software\Classes\CLSID\{CAFEEFAC-0013-0001-0003-ABCDEFFEDCBB}\InprocServer32]
[HKCU\Software\Classes\CLSID\{CAFEEFAC-0014-0002-0015-ABCDEFFEDCBB}\InprocServer32]
[HKCU\Software\Classes\CLSID\{CAFEEFAC-0016-0000-0003-ABCDEFFEDCBB}]
[HKCU\Software\Classes\CLSID\{CAFEEFAC-0015-0000-0009-ABCDEFFEDCBC}\InprocServer32]
[HKCU\Software\Classes\CLSID\{CAFEEFAC-0013-0001-0018-ABCDEFFEDCBB}\InprocServer32]
[HKCU\Software\Classes\CLSID\{CAFEEFAC-0014-0000-0000-ABCDEFFEDCBB}\InprocServer32]
[HKCU\Software\Classes\CLSID\{CAFEEFAC-0015-0000-0018-ABCDEFFEDCBB}\InprocServer32]
[HKCU\Software\Classes\CLSID\{CAFEEFAC-0016-0000-0015-ABCDEFFEDCBC}\InprocServer32]
[HKCU\Software\Classes\CLSID\{CAFEEFAC-0015-0000-0002-ABCDEFFEDCBA}]
[HKCU\Software\Classes\CLSID\{CAFEEFAC-0014-0002-0012-ABCDEFFEDCBA}\InprocServer32]
[HKCU\Software\Classes\CLSID\{CAFEEFAC-0013-0001-0019-ABCDEFFEDCBB}\InprocServer32]
[HKCU\Software\Classes\CLSID\{CAFEEFAC-0016-0000-0007-ABCDEFFEDCBB}]
[HKCU\Software\Classes\CLSID\{CAFEEFAC-0014-0002-0030-ABCDEFFEDCBA}\InprocServer32]
[HKCU\Software\Classes\CLSID\{CAFEEFAC-0013-0001-0025-ABCDEFFEDCBB}]
[HKCU\Software\Classes\CLSID\{CAFEEFAC-0014-0002-0029-ABCDEFFEDCBA}\InprocServer32]
[HKCU\Software\Classes\CLSID\{CAFEEFAC-0013-0001-0029-ABCDEFFEDCBA}\InprocServer32]
[HKCU\Software\Classes\CLSID\{CAFEEFAC-0016-0000-0016-ABCDEFFEDCBC}\InprocServer32]
[HKCU\Software\Classes\CLSID\{CAFEEFAC-0015-0000-0030-ABCDEFFEDCBA}]
[HKCU\Software\Classes\CLSID\{CAFEEFAC-0015-0000-0017-ABCDEFFEDCBB}]
[HKCU\Software\Classes\CLSID\{CAFEEFAC-0013-0001-0008-ABCDEFFEDCBB}]
[HKCU\Software\Classes\CLSID\{CAFEEFAC-0013-0001-0024-ABCDEFFEDCBB}]
[HKCU\Software\Classes\CLSID\{CAFEEFAC-0014-0000-0004-ABCDEFFEDCBA}\InprocServer32]
[HKCU\Software\Classes\CLSID\{CAFEEFAC-0016-0000-0017-ABCDEFFEDCBA}]
[HKCU\Software\Classes\CLSID\{CAFEEFAC-0015-0000-0022-ABCDEFFEDCBC}\InprocServer32]
[HKCU\Software\Classes\CLSID\{CAFEEFAC-0014-0002-0007-ABCDEFFEDCBA}\InprocServer32]
[HKCU\Software\Classes\CLSID\{CAFEEFAC-0014-0002-0021-ABCDEFFEDCBA}\InprocServer32]
[HKCU\Software\Classes\CLSID\{CAFEEFAC-0014-0001-0003-ABCDEFFEDCBA}]
[HKCU\Software\Classes\CLSID\{CAFEEFAC-0016-0000-0005-ABCDEFFEDCBB}\InprocServer32]
[HKCU\Software\Classes\CLSID\{CAFEEFAC-0016-0000-FFFF-ABCDEFFEDCBA}\InprocServer32]
[HKCU\Software\Classes\CLSID\{CAFEEFAC-0015-0000-0011-ABCDEFFEDCBB}]
[HKCU\Software\Classes\CLSID\{CAFEEFAC-0015-0000-0029-ABCDEFFEDCBB}]
[HKCU\Software\Classes\CLSID\{CAFEEFAC-0014-0002-0010-ABCDEFFEDCBB}]
[HKCU\Software\Classes\CLSID\{CAFEEFAC-0014-0002-0020-ABCDEFFEDCBB}]
[HKCU\Software\Classes\CLSID\{CAFEEFAC-0015-0000-0019-ABCDEFFEDCBB}\InprocServer32]
[HKCU\Software\Classes\CLSID\{CAFEEFAC-0015-0000-0023-ABCDEFFEDCBC}]
[HKCU\Software\Classes\CLSID\{CAFEEFAC-0016-0000-0003-ABCDEFFEDCBC}]
[HKCU\Software\Classes\CLSID\{CAFEEFAC-0015-0000-0012-ABCDEFFEDCBC}\InprocServer32]
[HKCU\Software\Classes\CLSID\{CAFEEFAC-0014-0002-0013-ABCDEFFEDCBA}]
[HKCU\Software\Classes\CLSID\{CAFEEFAC-0014-0000-0001-ABCDEFFEDCBA}\InprocServer32]
[HKCU\Software\Classes\CLSID\{CAFEEFAC-0013-0000-0003-ABCDEFFEDCBA}\InprocServer32]
[HKCU\Software\Classes\CLSID\{CAFEEFAC-0014-0002-0008-ABCDEFFEDCBA}\InprocServer32]
[HKCU\Software\Classes\CLSID\{CAFEEFAC-0013-0001-0023-ABCDEFFEDCBB}\InprocServer32]
[HKCU\Software\Classes\CLSID\{CAFEEFAC-0014-0002-0009-ABCDEFFEDCBA}\InprocServer32]
[HKCU\Software\Classes\CLSID\{CAFEEFAC-0016-0000-0015-ABCDEFFEDCBC}]
[HKCU\Software\Classes\CLSID\{CAFEEFAC-0016-0000-0018-ABCDEFFEDCBA}]
[HKCU\Software\Classes\CLSID\{CAFEEFAC-0015-0000-0019-ABCDEFFEDCBB}]
[HKCU\Software\Classes\CLSID\{CAFEEFAC-0013-0001-0026-ABCDEFFEDCBB}\InprocServer32]
[HKCU\Software\Classes\CLSID\{CAFEEFAC-0016-0000-0013-ABCDEFFEDCBB}\InprocServer32]
[HKCU\Software\Classes\CLSID\{CAFEEFAC-0015-0000-0004-ABCDEFFEDCBB}]
[HKCU\Software\Classes\CLSID\{CAFEEFAC-0013-0001-0012-ABCDEFFEDCBA}]
[HKCU\Software\Classes\CLSID\{CAFEEFAC-0014-0002-0009-ABCDEFFEDCBB}]
[HKCU\Software\Classes\CLSID\{CAFEEFAC-0014-0001-0003-ABCDEFFEDCBB}\InprocServer32]
[HKCU\Software\Classes\CLSID\{CAFEEFAC-0015-0000-0023-ABCDEFFEDCBA}\InprocServer32]
[HKCU\Software\Classes\CLSID\{CAFEEFAC-0014-0002-0018-ABCDEFFEDCBB}]
[HKCU\Software\Classes\CLSID\{CAFEEFAC-0014-0000-0003-ABCDEFFEDCBB}]
[HKCU\Software\Classes\CLSID\{CAFEEFAC-0015-0000-0000-ABCDEFFEDCBA}]
[HKCU\Software\Classes\CLSID\{CAFEEFAC-0014-0000-0004-ABCDEFFEDCBB}\InprocServer32]
[HKCU\Software\Classes\CLSID\{CAFEEFAC-0016-0000-0010-ABCDEFFEDCBB}]
[HKCU\Software\Classes\CLSID\{CAFEEFAC-0015-0000-0007-ABCDEFFEDCBA}]
[HKCU\Software\Classes\CLSID\{CAFEEFAC-0015-0000-0015-ABCDEFFEDCBA}]
[HKCU\Software\Classes\CLSID\{CAFEEFAC-0014-0002-0018-ABCDEFFEDCBB}\InprocServer32]
[HKCU\Software\Classes\CLSID\{CAFEEFAC-0016-0000-0014-ABCDEFFEDCBA}]
[HKCU\Software\Classes\CLSID\{CAFEEFAC-0013-0001-0029-ABCDEFFEDCBA}]
[HKCU\Software\Classes\CLSID\{CAFEEFAC-0016-0000-0018-ABCDEFFEDCBC}\InprocServer32]
[HKCU\Software\Classes\CLSID\{CAFEEFAC-0015-0000-0003-ABCDEFFEDCBC}\InprocServer32]
[HKCU\Software\Classes\CLSID\{CAFEEFAC-0013-0001-0007-ABCDEFFEDCBA}\InprocServer32]
[HKCU\Software\Classes\CLSID\{CAFEEFAC-0015-0000-0025-ABCDEFFEDCBC}\InprocServer32]
[HKCU\Software\Classes\CLSID\{CAFEEFAC-0014-0001-0000-ABCDEFFEDCBB}\InprocServer32]
[HKCU\Software\Classes\CLSID\{CAFEEFAC-0015-0000-0003-ABCDEFFEDCBB}]
[HKCU\Software\Classes\CLSID\{CAFEEFAC-0015-0000-0005-ABCDEFFEDCBB}]
[HKCU\Software\Classes\CLSID\{CAFEEFAC-0016-0000-0002-ABCDEFFEDCBC}\InprocServer32]
[HKCU\Software\Classes\CLSID\{CAFEEFAC-0016-0000-0004-ABCDEFFEDCBB}\InprocServer32]
[HKCU\Software\Classes\CLSID\{CAFEEFAC-0015-0000-0009-ABCDEFFEDCBC}]
[HKCU\Software\Classes\CLSID\{CAFEEFAC-0013-0001-0011-ABCDEFFEDCBB}]
[HKCU\Software\Classes\CLSID\{CAFEEFAC-0013-0001-0006-ABCDEFFEDCBB}\InprocServer32]
[HKCU\Software\Classes\CLSID\{CAFEEFAC-0014-0000-0002-ABCDEFFEDCBA}\InprocServer32]
[HKCU\Software\Classes\CLSID\{CAFEEFAC-0016-0000-0017-ABCDEFFEDCBA}\InprocServer32]
[HKCU\Software\Classes\CLSID\{CAFEEFAC-0015-0000-0015-ABCDEFFEDCBC}\InprocServer32]
[HKCU\Software\Classes\CLSID\{CAFEEFAC-0013-0001-0027-ABCDEFFEDCBB}\InprocServer32]
[HKCU\Software\Classes\CLSID\{CAFEEFAC-0016-0000-0011-ABCDEFFEDCBB}\InprocServer32]
[HKCU\Software\Classes\CLSID\{CAFEEFAC-0015-0000-0015-ABCDEFFEDCBA}\InprocServer32]
[HKCU\Software\Classes\CLSID\{CAFEEFAC-0014-0001-0004-ABCDEFFEDCBB}\InprocServer32]
[HKCU\Software\Classes\CLSID\{CAFEEFAC-0015-0000-0026-ABCDEFFEDCBC}]
[HKCU\Software\Classes\CLSID\{CAFEEFAC-0014-0000-0000-ABCDEFFEDCBA}\InprocServer32]
[HKCU\Software\Classes\CLSID\{CAFEEFAC-0013-0001-0008-ABCDEFFEDCBA}\InprocServer32]
[HKCU\Software\Classes\CLSID\{CAFEEFAC-0013-0001-0024-ABCDEFFEDCBA}\InprocServer32]
[HKCU\Software\Classes\CLSID\{CAFEEFAC-0014-0002-0021-ABCDEFFEDCBB}\InprocServer32]
[HKCU\Software\Classes\CLSID\{CAFEEFAC-0013-0001-0026-ABCDEFFEDCBB}]
[HKCU\Software\Classes\CLSID\{CAFEEFAC-0014-0002-0016-ABCDEFFEDCBB}]
[HKCU\Software\Classes\CLSID\{CAFEEFAC-0014-0002-0024-ABCDEFFEDCBB}\InprocServer32]
[HKCU\Software\Classes\CLSID\{CAFEEFAC-0013-0001-0016-ABCDEFFEDCBB}]
[HKCU\Software\Classes\CLSID\{CAFEEFAC-0014-0002-0015-ABCDEFFEDCBB}]
[HKCU\Software\Classes\CLSID\{CAFEEFAC-0013-0001-0027-ABCDEFFEDCBA}\InprocServer32]
[HKCU\Software\Classes\CLSID\{CAFEEFAC-0016-0000-0006-ABCDEFFEDCBB}\InprocServer32]
[HKCU\Software\Classes\CLSID\{CAFEEFAC-0013-0001-0025-ABCDEFFEDCBA}\InprocServer32]
[HKCU\Software\Classes\CLSID\{CAFEEFAC-0015-0000-0024-ABCDEFFEDCBB}\InprocServer32]
[HKCU\Software\Classes\CLSID\{CAFEEFAC-0014-0002-0010-ABCDEFFEDCBA}]
[HKCU\Software\Classes\CLSID\{CAFEEFAC-0016-0000-0015-ABCDEFFEDCBA}\InprocServer32]
[HKCU\Software\Classes\CLSID\{CAFEEFAC-0016-0000-0016-ABCDEFFEDCBA}\InprocServer32]
[HKCU\Software\Classes\CLSID\{CAFEEFAC-0016-0000-0011-ABCDEFFEDCBB}]
[HKCU\Software\Classes\CLSID\{CAFEEFAC-0013-0001-0028-ABCDEFFEDCBB}\InprocServer32]
[HKCU\Software\Classes\CLSID\{CAFEEFAC-0015-0000-0007-ABCDEFFEDCBA}\InprocServer32]
[HKCU\Software\Classes\CLSID\{CAFEEFAC-0014-0002-0000-ABCDEFFEDCBB}\InprocServer32]
[HKCU\Software\Classes\CLSID\{CAFEEFAC-0015-0000-0021-ABCDEFFEDCBC}\InprocServer32]
[HKCU\Software\Classes\CLSID\{CAFEEFAC-0015-0000-0020-ABCDEFFEDCBB}\InprocServer32]
[HKCU\Software\Classes\CLSID\{CAFEEFAC-0016-0000-0000-ABCDEFFEDCBC}\InprocServer32]
[HKCU\Software\Classes\CLSID\{CAFEEFAC-0014-0002-0024-ABCDEFFEDCBA}]
[HKCU\Software\Classes\CLSID\{CAFEEFAC-0015-0000-0011-ABCDEFFEDCBA}\InprocServer32]
[HKCU\Software\Classes\CLSID\{CAFEEFAC-0013-0001-0015-ABCDEFFEDCBA}]
[HKCU\Software\Classes\CLSID\{CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA}]
[HKCU\Software\Classes\CLSID\{CAFEEFAC-0016-0000-0013-ABCDEFFEDCBA}]
[HKCU\Software\Classes\CLSID\{CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA}\InprocServer32]
[HKCU\Software\Classes\CLSID\{CAFEEFAC-0015-0000-0013-ABCDEFFEDCBB}\InprocServer32]
[HKCU\Software\Classes\CLSID\{CAFEEFAC-0015-0000-0013-ABCDEFFEDCBC}]
[HKCU\Software\Classes\CLSID\{CAFEEFAC-0015-0000-0016-ABCDEFFEDCBA}]
[HKCU\Software\Classes\CLSID\{CAFEEFAC-0016-0000-0007-ABCDEFFEDCBC}\InprocServer32]
[HKCU\Software\Classes\CLSID\{CAFEEFAC-0015-0000-0027-ABCDEFFEDCBA}]
[HKCU\Software\Classes\CLSID\{CAFEEFAC-0015-0000-0017-ABCDEFFEDCBA}]
[HKCU\Software\Classes\CLSID\{CAFEEFAC-0013-0001-0028-ABCDEFFEDCBA}\InprocServer32]
[HKCU\Software\Classes\CLSID\{CAFEEFAC-0014-0002-0025-ABCDEFFEDCBB}\InprocServer32]
[HKCU\Software\Classes\CLSID\{CAFEEFAC-0015-0000-0002-ABCDEFFEDCBB}\InprocServer32]
[HKCU\Software\Classes\CLSID\{CAFEEFAC-0016-0000-0010-ABCDEFFEDCBA}\InprocServer32]
[HKCU\Software\Classes\CLSID\{CAFEEFAC-0013-0000-0005-ABCDEFFEDCBA}\InprocServer32]
[HKCU\Software\Classes\CLSID\{CAFEEFAC-0015-0000-0030-ABCDEFFEDCBB}\InprocServer32]
[HKCU\Software\Classes\CLSID\{CAFEEFAC-0014-0002-0026-ABCDEFFEDCBA}\InprocServer32]
[HKCU\Software\Classes\CLSID\{CAFEEFAC-0015-0000-0025-ABCDEFFEDCBC}]
[HKCU\Software\Classes\CLSID\{CAFEEFAC-0013-0000-0004-ABCDEFFEDCBA}\InprocServer32]
[HKCU\Software\Classes\CLSID\{CAFEEFAC-0015-0000-0018-ABCDEFFEDCBB}]
[HKCU\Software\Classes\CLSID\{CAFEEFAC-0014-0001-0003-ABCDEFFEDCBB}]
[HKCU\Software\Classes\CLSID\{CAFEEFAC-0014-0002-0025-ABCDEFFEDCBA}\InprocServer32]
[HKCU\Software\Classes\CLSID\{CAFEEFAC-0015-0000-0020-ABCDEFFEDCBC}]
[HKCU\Software\Classes\CLSID\{CAFEEFAC-0013-0001-0026-ABCDEFFEDCBA}\InprocServer32]
[HKCU\Software\Classes\CLSID\{CAFEEFAC-0014-0002-0027-ABCDEFFEDCBA}\InprocServer32]
[HKCU\Software\Classes\CLSID\{CAFEEFAC-0014-0002-0013-ABCDEFFEDCBA}\InprocServer32]
[HKCU\Software\Classes\CLSID\{CAFEEFAC-0015-0000-0004-ABCDEFFEDCBC}]
[HKCU\Software\Classes\CLSID\{CAFEEFAC-0015-0000-0006-ABCDEFFEDCBA}\InprocServer32]
[HKCU\Software\Classes\CLSID\{CAFEEFAC-0014-0002-0026-ABCDEFFEDCBB}]
[HKCU\Software\Classes\CLSID\{CAFEEFAC-0015-0000-0010-ABCDEFFEDCBB}\InprocServer32]
[HKCU\Software\Classes\CLSID\{CAFEEFAC-0016-0000-0015-ABCDEFFEDCBB}\InprocServer32]
[HKCU\Software\Classes\CLSID\{CAFEEFAC-0015-0000-0008-ABCDEFFEDCBA}]
[HKCU\Software\Classes\CLSID\{CAFEEFAC-0014-0002-0008-ABCDEFFEDCBA}]
[HKCU\Software\Classes\CLSID\{CAFEEFAC-0016-0000-0012-ABCDEFFEDCBA}]
[HKCU\Software\Classes\CLSID\{CAFEEFAC-0013-0001-0003-ABCDEFFEDCBA}]
[HKCU\Software\Classes\CLSID\{CAFEEFAC-0016-0000-0001-ABCDEFFEDCBA}\InprocServer32]
[HKCU\Software\Classes\CLSID\{CAFEEFAC-0016-0000-0002-ABCDEFFEDCBA}\InprocServer32]
[HKCU\Software\Classes\CLSID\{CAFEEFAC-0014-0002-0027-ABCDEFFEDCBB}\InprocServer32]
[HKCU\Software\Classes\CLSID\{CAFEEFAC-0013-0001-0005-ABCDEFFEDCBB}]
[HKCU\Software\Classes\CLSID\{CAFEEFAC-0015-0000-0020-ABCDEFFEDCBC}\InprocServer32]
[HKCU\Software\Classes\CLSID\{CAFEEFAC-0016-0000-0009-ABCDEFFEDCBC}\InprocServer32]
[HKCU\Software\Classes\CLSID\{CAFEEFAC-0015-0000-0025-ABCDEFFEDCBA}\InprocServer32]
[HKCU\Software\Classes\CLSID\{CAFEEFAC-0014-0002-0019-ABCDEFFEDCBA}]
[HKCU\Software\Classes\CLSID\{CAFEEFAC-0016-0000-0009-ABCDEFFEDCBA}\InprocServer32]
[HKCU\Software\Classes\CLSID\{CAFEEFAC-0016-0000-0013-ABCDEFFEDCBA}\InprocServer32]
[HKCU\Software\Classes\CLSID\{CAFEEFAC-0014-0002-0002-ABCDEFFEDCBA}]
[HKCU\Software\Classes\CLSID\{CAFEEFAC-0014-0002-0018-ABCDEFFEDCBA}]
[HKCU\Software\Classes\CLSID\{CAFEEFAC-0014-0002-0014-ABCDEFFEDCBA}\InprocServer32]
[HKCU\Software\Classes\CLSID\{CAFEEFAC-0015-0000-0005-ABCDEFFEDCBC}\InprocServer32]
[HKCU\Software\Classes\CLSID\{CAFEEFAC-0014-0002-0002-ABCDEFFEDCBA}\InprocServer32]
[HKCU\Software\Classes\CLSID\{CAFEEFAC-0016-0000-0010-ABCDEFFEDCBA}]
[HKCU\Software\Classes\CLSID\{CAFEEFAC-0016-0000-0008-ABCDEFFEDCBA}\InprocServer32]
[HKCU\Software\Classes\CLSID\{CAFEEFAC-0016-0000-0011-ABCDEFFEDCBA}\InprocServer32]
[HKCU\Software\Classes\CLSID\{CAFEEFAC-0013-0001-0019-ABCDEFFEDCBB}]
[HKCU\Software\Classes\CLSID\{CAFEEFAC-0015-0000-0009-ABCDEFFEDCBB}\InprocServer32]
[HKCU\Software\Classes\CLSID\{CAFEEFAC-0014-0001-0002-ABCDEFFEDCBB}]
[HKCU\Software\Classes\CLSID\{CAFEEFAC-0013-0001-0014-ABCDEFFEDCBA}\InprocServer32]
[HKCU\Software\Classes\CLSID\{CAFEEFAC-0013-0001-0006-ABCDEFFEDCBA}]
[HKCU\Software\Classes\CLSID\{CAFEEFAC-0014-0002-0017-ABCDEFFEDCBB}]
[HKCU\Software\Classes\CLSID\{CAFEEFAC-0013-0001-0001-ABCDEFFEDCBB}]
[HKCU\Software\Classes\CLSID\{CAFEEFAC-0015-0000-0018-ABCDEFFEDCBC}\InprocServer32]
[HKCU\Software\Classes\CLSID\{CAFEEFAC-0015-0000-0024-ABCDEFFEDCBC}]
[HKCU\Software\Classes\CLSID\{CAFEEFAC-0016-0000-0007-ABCDEFFEDCBB}\InprocServer32]
[HKCU\Software\Classes\CLSID\{CAFEEFAC-0014-0002-0024-ABCDEFFEDCBA}\InprocServer32]
[HKCU\Software\Classes\CLSID\{CAFEEFAC-0014-0002-0013-ABCDEFFEDCBB}\InprocServer32]
[HKCU\Software\Classes\CLSID\{CAFEEFAC-0015-0000-0018-ABCDEFFEDCBA}\InprocServer32]
[HKCU\Software\Classes\CLSID\{CAFEEFAC-0016-0000-0014-ABCDEFFEDCBC}\InprocServer32]
[HKCU\Software\Classes\CLSID\{CAFEEFAC-0015-0000-0030-ABCDEFFEDCBC}\InprocServer32]
[HKCU\Software\Classes\CLSID\{CAFEEFAC-0015-0000-0019-ABCDEFFEDCBA}\InprocServer32]
[HKCU\Software\Classes\CLSID\{CAFEEFAC-0016-0000-0008-ABCDEFFEDCBB}]
[HKCU\Software\Classes\CLSID\{CAFEEFAC-0015-0000-0016-ABCDEFFEDCBA}\InprocServer32]
[HKCU\Software\Classes\CLSID\{CAFEEFAC-0014-0001-0001-ABCDEFFEDCBA}]
[HKCU\Software\Classes\CLSID\{CAFEEFAC-0015-0000-0020-ABCDEFFEDCBA}\InprocServer32]
[HKCU\Software\Classes\CLSID\{CAFEEFAC-0016-0000-0006-ABCDEFFEDCBC}]
[HKCU\Software\Classes\CLSID\{CAFEEFAC-0013-0001-0005-ABCDEFFEDCBA}\InprocServer32]
[HKCU\Software\Classes\CLSID\{CAFEEFAC-0016-0000-0000-ABCDEFFEDCBA}]
[HKCU\Software\Classes\CLSID\{CAFEEFAC-0013-0001-0025-ABCDEFFEDCBA}]
[HKCU\Software\Classes\CLSID\{CAFEEFAC-0016-0000-0017-ABCDEFFEDCBB}\InprocServer32]
[HKCU\Software\Classes\CLSID\{CAFEEFAC-0016-0000-0016-ABCDEFFEDCBB}]
[HKCU\Software\Classes\JavaPlugin.160_18]
[HKCU\Software\Classes\CLSID\{CAFEEFAC-0013-0001-0023-ABCDEFFEDCBB}]
[HKCU\Software\Classes\CLSID\{CAFEEFAC-0014-0002-0029-ABCDEFFEDCBA}]
[HKCU\Software\Classes\CLSID\{CAFEEFAC-0013-0001-0016-ABCDEFFEDCBA}]
[HKCU\Software\Classes\CLSID\{CAFEEFAC-0014-0002-0004-ABCDEFFEDCBA}\InprocServer32]
[HKCU\Software\Classes\CLSID\{CAFEEFAC-0015-0000-0022-ABCDEFFEDCBC}]
[HKCU\Software\Classes\CLSID\{CAFEEFAC-0015-0000-0021-ABCDEFFEDCBB}\InprocServer32]
[HKCU\Software\Classes\CLSID\{CAFEEFAC-0016-0000-0017-ABCDEFFEDCBB}]
[HKCU\Software\Classes\CLSID\{CAFEEFAC-0015-0000-0023-ABCDEFFEDCBC}\InprocServer32]
[HKCU\Software\Classes\CLSID\{CAFEEFAC-0016-0000-0013-ABCDEFFEDCBC}]
[HKCU\Software\Classes\CLSID\{CAFEEFAC-0016-0000-0017-ABCDEFFEDCBC}\InprocServer32]
[HKCU\Software\Classes\CLSID\{CAFEEFAC-0013-0001-0008-ABCDEFFEDCBB}\InprocServer32]
[HKCU\Software\Classes\CLSID\{CAFEEFAC-0013-0001-0021-ABCDEFFEDCBB}\InprocServer32]
[HKCU\Software\Classes\CLSID\{CAFEEFAC-0014-0000-0002-ABCDEFFEDCBA}]
[HKCU\Software\Classes\CLSID\{CAFEEFAC-0014-0002-0024-ABCDEFFEDCBB}]
[HKCU\Software\Classes\CLSID\{CAFEEFAC-0013-0001-0020-ABCDEFFEDCBA}]
[HKCU\Software\Classes\CLSID\{CAFEEFAC-0013-0001-0027-ABCDEFFEDCBB}]
[HKCU\Software\Classes\CLSID\{CAFEEFAC-0015-0000-0011-ABCDEFFEDCBA}]
[HKCU\Software\Classes\CLSID\{CAFEEFAC-0015-0000-0029-ABCDEFFEDCBC}]
[HKCU\Software\Classes\CLSID\{CAFEEFAC-0016-0000-0004-ABCDEFFEDCBB}]
[HKCU\Software\Classes\CLSID\{CAFEEFAC-0014-0001-0007-ABCDEFFEDCBA}\InprocServer32]
[HKCU\Software\Classes\CLSID\{CAFEEFAC-0015-0000-0016-ABCDEFFEDCBB}]
[HKCU\Software\Classes\CLSID\{CAFEEFAC-0014-0002-0013-ABCDEFFEDCBB}]
[HKCU\Software\Classes\CLSID\{CAFEEFAC-0015-0000-0027-ABCDEFFEDCBB}]
[HKCU\Software\Classes\CLSID\{CAFEEFAC-0015-0000-0021-ABCDEFFEDCBA}]
[HKCU\Software\Classes\CLSID\{CAFEEFAC-0014-0000-0004-ABCDEFFEDCBA}]
[HKCU\Software\Classes\CLSID\{CAFEEFAC-0015-0000-0022-ABCDEFFEDCBA}\InprocServer32]
[HKCU\Software\Classes\CLSID\{CAFEEFAC-0014-0002-0007-ABCDEFFEDCBB}\InprocServer32]
[HKCU\Software\Classes\CLSID\{CAFEEFAC-0013-0001-0018-ABCDEFFEDCBA}\InprocServer32]
[HKCU\Software\Classes\CLSID\{CAFEEFAC-0015-0000-0004-ABCDEFFEDCBA}\InprocServer32]
[HKCU\Software\Classes\CLSID\{CAFEEFAC-0014-0001-0005-ABCDEFFEDCBB}\InprocServer32]
[HKCU\Software\Classes\CLSID\{CAFEEFAC-0015-0000-0019-ABCDEFFEDCBA}]
[HKCU\Software\Classes\CLSID\{CAFEEFAC-0016-0000-0009-ABCDEFFEDCBC}]
[HKCU\Software\Classes\CLSID\{CAFEEFAC-0015-0000-0014-ABCDEFFEDCBA}\InprocServer32]
[HKCU\Software\Classes\CLSID\{CAFEEFAC-0014-0002-0009-ABCDEFFEDCBA}]
[HKCU\Software\Classes\CLSID\{CAFEEFAC-0015-0000-0003-ABCDEFFEDCBB}\InprocServer32]
[HKCU\Software\Classes\CLSID\{CAFEEFAC-0013-0001-0010-ABCDEFFEDCBA}\InprocServer32]
[HKCU\Software\Classes\CLSID\{CAFEEFAC-0016-0000-FFFF-ABCDEFFEDCBA}]
[HKCU\Software\Classes\CLSID\{CAFEEFAC-0015-0000-0008-ABCDEFFEDCBC}]
[HKCU\Software\Classes\CLSID\{CAFEEFAC-0016-0000-0010-ABCDEFFEDCBC}\InprocServer32]
[HKCU\Software\Classes\CLSID\{CAFEEFAC-0014-0001-0007-ABCDEFFEDCBB}\InprocServer32]
[HKCU\Software\Classes\CLSID\{CAFEEFAC-0016-0000-0005-ABCDEFFEDCBC}]
[HKCU\Software\Classes\CLSID\{CAFEEFAC-0014-0000-0003-ABCDEFFEDCBA}]
[HKCU\Software\Classes\CLSID\{CAFEEFAC-0014-0002-0008-ABCDEFFEDCBB}\InprocServer32]
[HKCU\Software\Classes\CLSID\{CAFEEFAC-0013-0001-0014-ABCDEFFEDCBB}]
[HKCU\Software\Classes\CLSID\{CAFEEFAC-0015-0000-FFFF-ABCDEFFEDCBA}\InprocServer32]
[HKCU\Software\Classes\CLSID\{CAFEEFAC-0014-0001-0001-ABCDEFFEDCBA}\InprocServer32]
[HKCU\Software\Classes\CLSID\{CAFEEFAC-0013-0001-0009-ABCDEFFEDCBB}\InprocServer32]
[HKCU\Software\Classes\CLSID\{CAFEEFAC-0014-0002-0019-ABCDEFFEDCBB}\InprocServer32]
[HKCU\Software\Classes\CLSID\{CAFEEFAC-0014-0001-0006-ABCDEFFEDCBB}]
[HKCU\Software\Classes\CLSID\{CAFEEFAC-0015-0000-0028-ABCDEFFEDCBC}]
[HKCU\Software\Classes\CLSID\{CAFEEFAC-0015-0000-0005-ABCDEFFEDCBB}\InprocServer32]
[HKCU\Software\Classes\CLSID\{CAFEEFAC-0014-0002-0023-ABCDEFFEDCBB}\InprocServer32]
[HKCU\Software\Classes\CLSID\{CAFEEFAC-0013-0001-0005-ABCDEFFEDCBB}\InprocServer32]
[HKCU\Software\Classes\CLSID\{CAFEEFAC-0015-0000-0009-ABCDEFFEDCBA}\InprocServer32]
[HKCU\Software\Classes\CLSID\{CAFEEFAC-0015-0000-0003-ABCDEFFEDCBC}]
[HKCU\Software\Classes\CLSID\{CAFEEFAC-0015-0000-0005-ABCDEFFEDCBC}]
[HKCU\Software\Classes\CLSID\{CAFEEFAC-0013-0001-0005-ABCDEFFEDCBA}]
[HKCU\Software\Classes\CLSID\{CAFEEFAC-0014-0002-0003-ABCDEFFEDCBB}\InprocServer32]
[HKCU\Software\Classes\CLSID\{CAFEEFAC-0016-0000-0001-ABCDEFFEDCBC}]
[HKCU\Software\Classes\CLSID\{CAFEEFAC-0014-0002-0015-ABCDEFFEDCBA}]
[HKCU\Software\Classes\CLSID\{CAFEEFAC-0015-0000-0002-ABCDEFFEDCBC}\InprocServer32]
[HKCU\Software\Classes\CLSID\{CAFEEFAC-0016-0000-0002-ABCDEFFEDCBA}]
[HKCU\Software\Classes\CLSID\{CAFEEFAC-0014-0002-0019-ABCDEFFEDCBB}]
[HKCU\Software\Classes\CLSID\{CAFEEFAC-0013-0001-0019-ABCDEFFEDCBA}\InprocServer32]
[HKCU\Software\Classes\CLSID\{CAFEEFAC-0014-0002-0002-ABCDEFFEDCBB}]
[HKCU\Software\Classes\CLSID\{CAFEEFAC-0014-0002-0004-ABCDEFFEDCBA}]
[HKCU\Software\Classes\CLSID\{CAFEEFAC-0015-0000-0026-ABCDEFFEDCBB}]
[HKCU\Software\Classes\CLSID\{CAFEEFAC-0015-0000-0002-ABCDEFFEDCBA}\InprocServer32]
[HKCU\Software\Classes\CLSID\{CAFEEFAC-0014-0001-0004-ABCDEFFEDCBB}]
[HKCU\Software\Classes\CLSID\{CAFEEFAC-0015-0000-0017-ABCDEFFEDCBB}\InprocServer32]
[HKCU\Software\Classes\CLSID\{CAFEEFAC-0016-0000-0000-ABCDEFFEDCBB}\InprocServer32]
[HKCU\Software\Classes\CLSID\{CAFEEFAC-0013-0001-0009-ABCDEFFEDCBA}\InprocServer32]
[HKCU\Software\Classes\CLSID\{CAFEEFAC-0015-0000-0011-ABCDEFFEDCBC}\InprocServer32]
[HKCU\Software\Classes\CLSID\{CAFEEFAC-0014-0001-0007-ABCDEFFEDCBB}]
[HKCU\Software\Classes\CLSID\{CAFEEFAC-0014-0002-0006-ABCDEFFEDCBB}\InprocServer32]
[HKCU\Software\Classes\CLSID\{CAFEEFAC-0015-0000-0029-ABCDEFFEDCBC}\InprocServer32]
[HKCU\Software\Classes\CLSID\{CAFEEFAC-0014-0001-0002-ABCDEFFEDCBA}]
[HKCU\Software\Classes\CLSID\{CAFEEFAC-0014-0002-0016-ABCDEFFEDCBA}]
[HKCU\Software\Classes\CLSID\{CAFEEFAC-0013-0001-0013-ABCDEFFEDCBB}\InprocServer32]
[HKCU\Software\Classes\CLSID\{CAFEEFAC-0014-0002-0029-ABCDEFFEDCBB}\InprocServer32]
[HKCU\Software\Classes\CLSID\{CAFEEFAC-0016-0000-0003-ABCDEFFEDCBC}\InprocServer32]
[HKCU\Software\Classes\CLSID\{CAFEEFAC-0013-0001-0017-ABCDEFFEDCBA}]
[HKCU\Software\Classes\CLSID\{CAFEEFAC-0013-0001-0001-ABCDEFFEDCBA}]
[HKCU\Software\Classes\CLSID\{CAFEEFAC-0014-0002-0014-ABCDEFFEDCBB}\InprocServer32]
[HKCU\Software\Classes\CLSID\{CAFEEFAC-0016-0000-0011-ABCDEFFEDCBC}]
[HKCU\Software\Classes\CLSID\{CAFEEFAC-0014-0001-0004-ABCDEFFEDCBA}\InprocServer32]
[HKCU\Software\Classes\CLSID\{CAFEEFAC-0013-0001-0001-ABCDEFFEDCBB}\InprocServer32]
[HKCU\Software\Classes\CLSID\{CAFEEFAC-0015-0000-0000-ABCDEFFEDCBA}\InprocServer32]
[HKCU\Software\Classes\CLSID\{CAFEEFAC-0015-0000-0002-ABCDEFFEDCBC}]
[HKCU\Software\Classes\CLSID\{CAFEEFAC-0013-0001-0016-ABCDEFFEDCBA}\InprocServer32]
[HKCU\Software\Classes\CLSID\{CAFEEFAC-0015-0000-0001-ABCDEFFEDCBC}\InprocServer32]
[HKCU\Software\Classes\CLSID\{CAFEEFAC-0015-0000-0014-ABCDEFFEDCBC}\InprocServer32]
[HKCU\Software\Classes\CLSID\{CAFEEFAC-0016-0000-0012-ABCDEFFEDCBC}\InprocServer32]
[HKCU\Software\Classes\CLSID\{CAFEEFAC-0013-0001-0002-ABCDEFFEDCBA}\InprocServer32]
[HKCU\Software\Classes\CLSID\{CAFEEFAC-0013-0001-0015-ABCDEFFEDCBB}]
[HKCU\Software\Classes\CLSID\{CAFEEFAC-0015-0000-0007-ABCDEFFEDCBC}]
[HKCU\Software\Classes\CLSID\{CAFEEFAC-0014-0002-0012-ABCDEFFEDCBB}]
[HKCU\Software\Classes\CLSID\{CAFEEFAC-0013-0001-0001-ABCDEFFEDCBA}\InprocServer32]
[HKCU\Software\Classes\CLSID\{CAFEEFAC-0013-0001-0023-ABCDEFFEDCBA}]
[HKCU\Software\Classes\CLSID\{CAFEEFAC-0015-0000-0001-ABCDEFFEDCBA}]
[HKCU\Software\Classes\CLSID\{CAFEEFAC-0016-0000-0012-ABCDEFFEDCBB}]
[HKCU\Software\Classes\CLSID\{CAFEEFAC-0014-0002-0002-ABCDEFFEDCBB}\InprocServer32]
[HKCU\Software\Classes\CLSID\{CAFEEFAC-0013-0001-0007-ABCDEFFEDCBB}]
[HKCU\Software\Classes\CLSID\{CAFEEFAC-0014-0002-0003-ABCDEFFEDCBA}\InprocServer32]
[HKCU\Software\Classes\CLSID\{CAFEEFAC-0014-0002-0018-ABCDEFFEDCBA}\InprocServer32]
[HKCU\Software\Classes\CLSID\{CAFEEFAC-0015-0000-0025-ABCDEFFEDCBB}\InprocServer32]
[HKCU\Software\Classes\CLSID\{CAFEEFAC-0015-0000-0010-ABCDEFFEDCBB}]
[HKCU\Software\Classes\CLSID\{CAFEEFAC-0014-0002-0003-ABCDEFFEDCBB}]
[HKCU\Software\Classes\CLSID\{CAFEEFAC-0016-0000-0016-ABCDEFFEDCBB}\InprocServer32]
[HKCU\Software\Classes\CLSID\{CAFEEFAC-0015-0000-0000-ABCDEFFEDCBC}\InprocServer32]
[HKCU\Software\Classes\CLSID\{CAFEEFAC-0014-0002-0027-ABCDEFFEDCBA}]
[HKCU\Software\Classes\CLSID\{CAFEEFAC-0016-0000-0013-ABCDEFFEDCBC}\InprocServer32]
[HKCU\Software\Classes\CLSID\{CAFEEFAC-0013-0001-0010-ABCDEFFEDCBB}]
[HKCU\Software\Classes\CLSID\{CAFEEFAC-0015-0000-0024-ABCDEFFEDCBC}\InprocServer32]
[HKCU\Software\Classes\CLSID\{CAFEEFAC-0015-0000-0018-ABCDEFFEDCBC}]
[HKCU\Software\Classes\CLSID\{CAFEEFAC-0015-0000-0030-ABCDEFFEDCBB}]
[HKCU\Software\Classes\CLSID\{CAFEEFAC-0013-0001-0022-ABCDEFFEDCBB}\InprocServer32]
[HKCU\Software\Classes\CLSID\{CAFEEFAC-0014-0002-0021-ABCDEFFEDCBB}]
[HKCU\Software\Classes\CLSID\{CAFEEFAC-0015-0000-0020-ABCDEFFEDCBB}]
[HKCU\Software\Classes\CLSID\{CAFEEFAC-0013-0001-0027-ABCDEFFEDCBA}]
[HKCU\Software\Classes\CLSID\{CAFEEFAC-0015-0000-0016-ABCDEFFEDCBC}]
[HKCU\Software\Classes\CLSID\{8AD9C840-044E-11D1-B3E9-00805F499D93}]
[HKCU\Software\Classes\CLSID\{CAFEEFAC-0013-0001-0030-ABCDEFFEDCBA}\InprocServer32]
[HKCU\Software\Classes\CLSID\{CAFEEFAC-0016-0000-0003-ABCDEFFEDCBB}\InprocServer32]
[HKCU\Software\Classes\CLSID\{CAFEEFAC-0015-0000-0006-ABCDEFFEDCBB}]
[HKCU\Software\Classes\CLSID\{CAFEEFAC-0014-0002-0008-ABCDEFFEDCBB}]
[HKCU\Software\Classes\CLSID\{CAFEEFAC-0013-0001-0030-ABCDEFFEDCBB}]
[HKCU\Software\Classes\CLSID\{CAFEEFAC-0016-0000-0001-ABCDEFFEDCBC}\InprocServer32]
[HKCU\Software\Classes\CLSID\{CAFEEFAC-0014-0000-0004-ABCDEFFEDCBB}]
[HKCU\Software\Classes\CLSID\{CAFEEFAC-0014-0002-0010-ABCDEFFEDCBB}\InprocServer32]
[HKCU\Software\Classes\CLSID\{CAFEEFAC-0013-0001-0003-ABCDEFFEDCBA}\InprocServer32]
[HKCU\Software\Classes\CLSID\{CAFEEFAC-0015-0000-0021-ABCDEFFEDCBB}]
[HKCU\Software\Classes\CLSID\{CAFEEFAC-0015-0000-0019-ABCDEFFEDCBC}\InprocServer32]
[HKCU\Software\Classes\CLSID\{CAFEEFAC-0014-0002-0022-ABCDEFFEDCBA}]
[HKCU\Software\Classes\CLSID\{CAFEEFAC-0014-0002-0025-ABCDEFFEDCBB}]
[HKCU\Software\Classes\CLSID\{CAFEEFAC-0016-0000-0004-ABCDEFFEDCBA}\InprocServer32]
[HKCU\Software\Classes\CLSID\{CAFEEFAC-0013-0001-0000-ABCDEFFEDCBA}\InprocServer32]
[HKCU\Software\Classes\CLSID\{CAFEEFAC-0015-0000-0013-ABCDEFFEDCBB}]
[HKCU\Software\Classes\CLSID\{CAFEEFAC-0016-0000-0006-ABCDEFFEDCBA}\InprocServer32]
[HKCU\Software\Classes\CLSID\{CAFEEFAC-0013-0001-0020-ABCDEFFEDCBA}\InprocServer32]
[HKCU\Software\Classes\CLSID\{CAFEEFAC-0016-0000-0001-ABCDEFFEDCBA}]
[HKCU\Software\Classes\CLSID\{CAFEEFAC-0013-0001-0021-ABCDEFFEDCBB}]
[HKCU\Software\Classes\CLSID\{CAFEEFAC-0015-0000-0014-ABCDEFFEDCBB}\InprocServer32]
[HKCU\Software\Classes\CLSID\{CAFEEFAC-0016-0000-0008-ABCDEFFEDCBC}\InprocServer32]
[HKCU\Software\Classes\CLSID\{CAFEEFAC-0015-0000-0010-ABCDEFFEDCBA}\InprocServer32]
[HKCU\Software\Classes\CLSID\{CAFEEFAC-0014-0001-0006-ABCDEFFEDCBA}\InprocServer32]
[HKCU\Software\Classes\CLSID\{CAFEEFAC-0013-0001-0022-ABCDEFFEDCBA}\InprocServer32]
[HKCU\Software\Classes\CLSID\{CAFEEFAC-0014-0001-0006-ABCDEFFEDCBA}]
[HKCU\Software\Classes\CLSID\{CAFEEFAC-0013-0001-0006-ABCDEFFEDCBB}]
[HKCU\Software\Classes\CLSID\{CAFEEFAC-0014-0002-0020-ABCDEFFEDCBB}\InprocServer32]
[HKCU\Software\Classes\CLSID\{CAFEEFAC-0015-0000-0024-ABCDEFFEDCBB}]
[HKCU\Software\Classes\CLSID\{CAFEEFAC-0015-0000-0012-ABCDEFFEDCBA}]
[HKCU\Software\Classes\CLSID\{CAFEEFAC-0014-0002-0005-ABCDEFFEDCBB}]
[HKCU\Software\Classes\CLSID\{CAFEEFAC-0016-0000-0018-ABCDEFFEDCBB}\InprocServer32]
[HKCU\Software\Classes\CLSID\{CAFEEFAC-0014-0001-0000-ABCDEFFEDCBB}]
[HKCU\Software\Classes\CLSID\{CAFEEFAC-0014-0002-0011-ABCDEFFEDCBA}\InprocServer32]
[HKCU\Software\Classes\CLSID\{CAFEEFAC-0015-0000-0027-ABCDEFFEDCBA}\InprocServer32]
[HKCU\Software\Classes\CLSID\{CAFEEFAC-0014-0002-0001-ABCDEFFEDCBA}\InprocServer32]
[HKCU\Software\Classes\CLSID\{CAFEEFAC-0016-0000-0002-ABCDEFFEDCBB}]
[HKCU\Software\Classes\CLSID\{CAFEEFAC-0014-0001-0001-ABCDEFFEDCBB}]
[HKCU\Software\Classes\CLSID\{CAFEEFAC-0015-0000-0000-ABCDEFFEDCBB}\InprocServer32]
[HKCU\Software\Classes\CLSID\{CAFEEFAC-0015-0000-0026-ABCDEFFEDCBA}]
[HKCU\Software\Classes\CLSID\{CAFEEFAC-0016-0000-0000-ABCDEFFEDCBB}]
[HKCU\Software\Classes\CLSID\{CAFEEFAC-0015-0000-0013-ABCDEFFEDCBA}\InprocServer32]
[HKCU\Software\Classes\CLSID\{CAFEEFAC-0015-0000-0014-ABCDEFFEDCBA}]
[HKCU\Software\Classes\CLSID\{CAFEEFAC-0016-0000-0000-ABCDEFFEDCBA}\InprocServer32]
[HKCU\Software\Classes\CLSID\{CAFEEFAC-0013-0001-0017-ABCDEFFEDCBB}\InprocServer32]
[HKCU\Software\Classes\CLSID\{E19F9331-3110-11D4-991C-005004D3B3DB}]
[HKCU\Software\Classes\CLSID\{CAFEEFAC-0015-0000-0014-ABCDEFFEDCBB}]
[HKCU\Software\Classes\CLSID\{CAFEEFAC-0015-0000-0022-ABCDEFFEDCBB}]
[HKCU\Software\Classes\CLSID\{CAFEEFAC-0014-0000-0002-ABCDEFFEDCBB}\InprocServer32]
[HKCU\Software\Classes\CLSID\{CAFEEFAC-0014-0002-0029-ABCDEFFEDCBB}]
[HKCU\Software\Classes\CLSID\{CAFEEFAC-0013-0001-0017-ABCDEFFEDCBB}]
[HKCU\Software\Classes\CLSID\{CAFEEFAC-0014-0002-0022-ABCDEFFEDCBA}\InprocServer32]
[HKCU\Software\Classes\CLSID\{CAFEEFAC-0016-0000-0017-ABCDEFFEDCBC}]
[HKCU\Software\Classes\CLSID\{CAFEEFAC-0014-0001-0001-ABCDEFFEDCBB}\InprocServer32]
[HKCU\Software\Classes\CLSID\{CAFEEFAC-0013-0000-0005-ABCDEFFEDCBA}]
[HKCU\Software\Classes\CLSID\{CAFEEFAC-0013-0001-0024-ABCDEFFEDCBB}\InprocServer32]
[HKCU\Software\Classes\CLSID\{CAFEEFAC-0014-0000-0002-ABCDEFFEDCBB}]
[HKCU\Software\Classes\CLSID\{CAFEEFAC-0014-0002-0020-ABCDEFFEDCBA}\InprocServer32]
[HKCU\Software\Classes\CLSID\{CAFEEFAC-0013-0001-0020-ABCDEFFEDCBB}]
[HKCU\Software\Classes\CLSID\{CAFEEFAC-0015-0000-0005-ABCDEFFEDCBA}\InprocServer32]
[HKCU\Software\Classes\CLSID\{CAFEEFAC-0015-0000-0001-ABCDEFFEDCBB}\InprocServer32]
[HKCU\Software\Classes\CLSID\{CAFEEFAC-0014-0002-0001-ABCDEFFEDCBB}]
[HKCU\Software\Classes\CLSID\{CAFEEFAC-0014-0001-0002-ABCDEFFEDCBA}\InprocServer32]
[HKCU\Software\Classes\CLSID\{CAFEEFAC-0014-0001-0005-ABCDEFFEDCBA}]
[HKCU\Software\Classes\CLSID\{CAFEEFAC-0016-0000-0004-ABCDEFFEDCBC}]
[HKCU\Software\Classes\CLSID\{CAFEEFAC-0015-0000-0021-ABCDEFFEDCBA}\InprocServer32]
[HKCU\Software\Classes\CLSID\{CAFEEFAC-0014-0000-0000-ABCDEFFEDCBA}]
[HKCU\Software\Classes\CLSID\{CAFEEFAC-0015-0000-0013-ABCDEFFEDCBA}]
[HKCU\Software\Classes\CLSID\{CAFEEFAC-0014-0002-0030-ABCDEFFEDCBB}]
[HKCU\Software\Classes\CLSID\{CAFEEFAC-0015-0000-0001-ABCDEFFEDCBB}]
[HKCU\Software\Classes\CLSID\{CAFEEFAC-0015-0000-0027-ABCDEFFEDCBC}]
[HKCU\Software\Classes\CLSID\{CAFEEFAC-0015-0000-0006-ABCDEFFEDCBB}\InprocServer32]
[HKCU\Software\Classes\CLSID\{CAFEEFAC-0016-0000-0002-ABCDEFFEDCBB}\InprocServer32]
[HKCU\Software\Classes\CLSID\{CAFEEFAC-0016-0000-0008-ABCDEFFEDCBA}]
[HKCU\Software\Classes\CLSID\{CAFEEFAC-0015-0000-0008-ABCDEFFEDCBB}]
[HKCU\Software\Classes\CLSID\{CAFEEFAC-0014-0002-0003-ABCDEFFEDCBA}]
[HKCU\Software\Classes\CLSID\{CAFEEFAC-0013-0001-0007-ABCDEFFEDCBB}\InprocServer32]
[HKCU\Software\Classes\CLSID\{CAFEEFAC-0013-0001-0017-ABCDEFFEDCBA}\InprocServer32]
[HKCU\Software\Classes\CLSID\{CAFEEFAC-0016-0000-0018-ABCDEFFEDCBC}]
[HKCU\Software\Classes\CLSID\{CAFEEFAC-0015-0000-0009-ABCDEFFEDCBA}]
[HKCU\Software\Classes\CLSID\{CAFEEFAC-0016-0000-0009-ABCDEFFEDCBB}]
[HKCU\Software\Classes\CLSID\{CAFEEFAC-0015-0000-0025-ABCDEFFEDCBA}]
[HKCU\Software\Classes\CLSID\{CAFEEFAC-0015-0000-0003-ABCDEFFEDCBA}\InprocServer32]
[HKCU\Software\Classes\CLSID\{CAFEEFAC-0013-0001-0004-ABCDEFFEDCBA}]
[HKCU\Software\Classes\CLSID\{CAFEEFAC-0014-0002-0009-ABCDEFFEDCBB}\InprocServer32]
[HKCU\Software\Classes\CLSID\{CAFEEFAC-0014-0002-0007-ABCDEFFEDCBB}]
[HKCU\Software\Classes\CLSID\{CAFEEFAC-0014-0002-0021-ABCDEFFEDCBA}]
[HKCU\Software\Classes\CLSID\{CAFEEFAC-0014-0002-0011-ABCDEFFEDCBA}]

The program deletes the following value(s) in system registry:

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings]
"AutoConfigURL"
"ProxyServer"
"ProxyOverride"

The process IEXPLORE.EXE:2676 makes changes in the system registry.
The program creates and/or sets the following values in system registry:

[HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{FB5F1910-F110-11D2-BB9E-00C04F795683}\iexplore]
"Count" = "29"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"AutoDetect" = "1"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{E2E2DD38-D088-4134-82B7-F2BA38496583}\iexplore]
"Type" = "4"
"Count" = "29"

[HKCU\Software\Microsoft\Internet Explorer\Main]
"CompatibilityFlags" = "0"
"FullScreen" = "no"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"AppData" = "%Documents and Settings%\%current user%\Application Data"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\MenuOrder\Favorites\Links]
"Order" = "08 00 00 00 02 00 00 00 42 01 00 00 01 00 00 00"

[HKCU\Software\Microsoft\Internet Explorer\LinksBar\ItemCache\0]
"DisplayName" = ""

[HKCU\Software\Microsoft\Internet Explorer\LinksBar\ItemCache\1]
"Path" = "%Documents and Settings%\%current user%\Favorites\Links\Web Slice Gallery.url"

[HKCU\Software\Microsoft\Internet Explorer\LinksBar\ItemCache\0]
"FeedUrl" = "https://ieonline.microsoft.com/#ieslice"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{FB5F1910-F110-11D2-BB9E-00C04F795683}\iexplore]
"Type" = "4"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{c155cd73-744b-11e2-8294-806d6172696f}]
"BaseClass" = "Drive"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"Cookies" = "%Documents and Settings%\%current user%\Cookies"

"Local AppData" = "%Documents and Settings%\%current user%\Local Settings\Application Data"

[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"Common AppData" = "%Documents and Settings%\All Users\Application Data"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{c155cd75-744b-11e2-8294-806d6172696f}]
"BaseClass" = "Drive"

[HKCU\Software\Microsoft\Internet Explorer\LinksBar\ItemCache\1]
"ErrorState" = "0"
"FeedUrl" = "http://go.microsoft.com/fwlink/?LinkId=121315"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{E2E2DD38-D088-4134-82B7-F2BA38496583}\iexplore]
"Time" = "DE 07 05 00 02 00 0D 00 0E 00 38 00 07 00 CE 01"

[HKCU\Software\Microsoft\Internet Explorer\LinksBar\ItemCache\0]
"DisplayMask" = "0"

[HKCU\Software\Microsoft\CTF\TIP\{1188450c-fdab-47ae-80d8-c9633f71be64}\LanguageProfile\0x00000000\{63800dac-e7ca-4df9-9a5c-20765055488d}]
"Enable" = "1"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"Cache" = "%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files"

[HKCU\Software\Microsoft\Internet Explorer\LinksBar\ItemCache\1]
"DisplayName" = ""

[HKCU\Software\Microsoft\Internet Explorer\Recovery\Active]
"{B5B36C2E-DAAE-11E3-81D1-0050563EC483}" = "0"

[HKCR\TypeLib\{1EA4DBF0-3C3B-11CF-810C-00AA00389B71}\1.1\0\win32]
"(Default)" = "%System%\oleacc.dll"

[HKCU\Software\Microsoft\Internet Explorer\LinksBar\ItemCache\1]
"Handler" = "{B0FA7D7C-7195-4F03-B03E-9DC1C9EBC394}"

[HKCU\Software\Microsoft\Internet Explorer\LinksBar\ItemCache\0]
"ErrorState" = "0"

[HKCU\Software\Microsoft\Internet Explorer\Main]
"Window_Placement" = "2C 00 00 00 02 00 00 00 03 00 00 00 FF FF FF FF"

[HKCU\Software\Microsoft\Internet Explorer\LinksBar\ItemCache\1]
"Expiration" = "0"

"DisplayMask" = "0"

[HKCU\Software\Microsoft\Internet Explorer\Main\WindowsSearch]
"Version" = "WS not installed"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{c155cd72-744b-11e2-8294-806d6172696f}]
"BaseClass" = "Drive"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Connections]
"SavedLegacySettings" = "46 00 00 00 3E 00 00 00 01 00 00 00 00 00 00 00"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones]
"SecuritySafe" = "1"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{FB5F1910-F110-11D2-BB9E-00C04F795683}\iexplore]
"Time" = "DE 07 05 00 02 00 0D 00 0E 00 38 00 07 00 CE 01"

[HKLM\SOFTWARE\Microsoft\Cryptography\RNG]
"Seed" = "2C 55 AD 13 6B 22 EF C4 AA CD AE 1B EE D1 A7 06"

[HKCU\Software\Microsoft\Internet Explorer\LinksBar\ItemCache\0]
"Handler" = "{B0FA7D7C-7195-4F03-B03E-9DC1C9EBC394}"
"Path" = "%Documents and Settings%\%current user%\Favorites\Links\Suggested Sites.url"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"Desktop" = "%Documents and Settings%\%current user%\Desktop"
"History" = "%Documents and Settings%\%current user%\Local Settings\History"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{b98117e8-75ca-11e2-81b2-000c293708fb}]
"BaseClass" = "Drive"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"Favorites" = "%Documents and Settings%\%current user%\Favorites"

[HKCU\Software\Microsoft\Internet Explorer\LinksBar\ItemCache\0]
"Expiration" = "0"

The program modifies IE settings for security zones to map all local web-nodes with no dots which do not refer to any zone to the Intranet Zone:

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"UNCAsIntranet" = "1"

The program modifies IE settings for security zones to map all web-nodes that bypassing the proxy to the Intranet Zone:

"ProxyBypass" = "1"

Proxy settings are disabled:

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings]
"ProxyEnable" = "0"

The program modifies IE settings for security zones to map all urls to the Intranet Zone:

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"IntranetName" = "1"

The program deletes the following registry key(s):

[HKCU\Software\Microsoft\CTF\TIP\{1188450c-fdab-47ae-80d8-c9633f71be64}\LanguageProfile\0x00000000\{63800dac-e7ca-4df9-9a5c-20765055488d}]
[HKCU\Software\Microsoft\CTF\TIP\{1188450c-fdab-47ae-80d8-c9633f71be64}]
[HKCU\Software\Microsoft\CTF\TIP\{1188450c-fdab-47ae-80d8-c9633f71be64}\LanguageProfile\0x00000000]
[HKCU\Software\Microsoft\CTF\TIP\{1188450c-fdab-47ae-80d8-c9633f71be64}\LanguageProfile]

The program deletes the following value(s) in system registry:

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings]
"AutoConfigURL"
"ProxyServer"
"ProxyOverride"

[HKCU\Software\Microsoft\Internet Explorer\LinksBar\ItemCache\0]
"Expiration"

[HKCU\Software\Microsoft\Internet Explorer\LinksBar\ItemCache\1]
"Expiration"

The process MyPC Backup.exe:1212 makes changes in the system registry.
The program creates and/or sets the following values in system registry:

[HKLM\SOFTWARE\Microsoft\Cryptography\RNG]
"Seed" = "5D C4 64 85 DF 2D 2B 5E 38 F2 BD 56 0D 27 EB 89"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{c155cd73-744b-11e2-8294-806d6172696f}]
"BaseClass" = "Drive"

[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"Common Documents" = "%Documents and Settings%\All Users\Documents"
"CommonVideo" = "%Documents and Settings%\All Users\Documents\My Videos"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"Desktop" = "%Documents and Settings%\%current user%\Desktop"
"My Pictures" = "%Documents and Settings%\%current user%\My Documents\My Pictures"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{c155cd72-744b-11e2-8294-806d6172696f}]
"BaseClass" = "Drive"

[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"Common AppData" = "%Documents and Settings%\All Users\Application Data"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{b98117e8-75ca-11e2-81b2-000c293708fb}]
"BaseClass" = "Drive"

[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"CommonMusic" = "%Documents and Settings%\All Users\Documents\My Music"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"AppData" = "%Documents and Settings%\%current user%\Application Data"

[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"Common Desktop" = "%Documents and Settings%\All Users\Desktop"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{c155cd75-744b-11e2-8294-806d6172696f}]
"BaseClass" = "Drive"

[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"Common Start Menu" = "%Documents and Settings%\All Users\Start Menu"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"Cache" = "%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files"
"Start Menu" = "%Documents and Settings%\%current user%\Start Menu"
"Personal" = "%Documents and Settings%\%current user%\My Documents"

[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"CommonPictures" = "%Documents and Settings%\All Users\Documents\My Pictures"

The process Cloud_Backup_Setup.exe:2332 makes changes in the system registry.
The program creates and/or sets the following values in system registry:

[HKLM\SOFTWARE\Microsoft\Cryptography\RNG]
"Seed" = "94 37 0B 82 51 BD D6 48 F5 18 A9 82 05 FD 94 F2"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{c155cd73-744b-11e2-8294-806d6172696f}]
"BaseClass" = "Drive"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{c155cd72-744b-11e2-8294-806d6172696f}]
"BaseClass" = "Drive"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{b98117e8-75ca-11e2-81b2-000c293708fb}]
"BaseClass" = "Drive"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{c155cd75-744b-11e2-8294-806d6172696f}]
"BaseClass" = "Drive"

The process exthelper.exe:1888 makes changes in the system registry.
The program creates and/or sets the following values in system registry:

[HKLM\SOFTWARE\Microsoft\Cryptography\RNG]
"Seed" = "D5 8E E5 2A E6 1C 9F 7A 09 85 49 E7 E7 BF 44 86"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"Cookies" = "%Documents and Settings%\%current user%\Cookies"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"AutoDetect" = "1"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"History" = "%Documents and Settings%\%current user%\Local Settings\History"

[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"Common AppData" = "%Documents and Settings%\All Users\Application Data"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"AppData" = "%Documents and Settings%\%current user%\Application Data"
"Cache" = "%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Connections]
"SavedLegacySettings" = "46 00 00 00 3A 00 00 00 01 00 00 00 00 00 00 00"

The program modifies IE settings for security zones to map all web-nodes that bypassing the proxy to the Intranet Zone:

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"ProxyBypass" = "1"

The program modifies IE settings for security zones to map all local web-nodes with no dots which do not refer to any zone to the Intranet Zone:

"UNCAsIntranet" = "1"

The program modifies IE settings for security zones to map all urls to the Intranet Zone:

"IntranetName" = "1"

Proxy settings are disabled:

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings]
"ProxyEnable" = "0"

The program deletes the following value(s) in system registry:

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings]
"AutoConfigURL"
"ProxyServer"
"ProxyOverride"

Dropped PE files

MD5 File path
0bb90d714e37d22f1efc72f6e6d2615d c:\Documents and Settings\"%CurrentUserName%"\Application Data\Browser Extensions\Button.exe
053ad409e146bd049178c822b44577ce c:\Documents and Settings\"%CurrentUserName%"\Application Data\Browser Extensions\Button64.exe
99aeed1ab4d3728a97c9bd650c4db405 c:\Documents and Settings\"%CurrentUserName%"\Application Data\Browser Extensions\ButtonWrap.dll
f8009e326366c85e842509f875ed1b1b c:\Documents and Settings\"%CurrentUserName%"\Application Data\Browser Extensions\ButtonWrap64.dll
1f3950302ba2cd77491146081b427c07 c:\Documents and Settings\"%CurrentUserName%"\Application Data\Browser Extensions\Coupons.dll
39d87fae8b93c0294602679647754543 c:\Documents and Settings\"%CurrentUserName%"\Application Data\Browser Extensions\Coupons64.dll
719f6d7047c2744e21756a336f86ab90 c:\Documents and Settings\"%CurrentUserName%"\Application Data\Browser Extensions\CouponsHelper.exe
3f8f68190c205ed52b5c75e9619e1030 c:\Documents and Settings\"%CurrentUserName%"\Application Data\Browser Extensions\Uninstall.exe
4cc2f1c0a729f6be8598db5cfd3e6d3c c:\Documents and Settings\"%CurrentUserName%"\Application Data\Search Protection\SearchProtection.exe
b40ccd65725eb1cf64c3b6ff0af046be c:\Documents and Settings\"%CurrentUserName%"\Application Data\Search Protection\Uninstall.exe
45922155c9628e11441aa869c6287bb7 c:\Documents and Settings\"%CurrentUserName%"\Local Settings\Temp\BackupSetup.exe
6994c3fa70378b0ac77486cee8077ed5 c:\Documents and Settings\"%CurrentUserName%"\Local Settings\Temp\nse28.tmp\Cloud_Backup_Setup.exe
82d0c4c66511a51ab1c462de73b02aea c:\Documents and Settings\"%CurrentUserName%"\Local Settings\Temp\nse28.tmp\SearchProtectionStub.exe
62efa7b730eb0523a026ea4325403b77 c:\Documents and Settings\"%CurrentUserName%"\Local Settings\Temp\nsg39.tmp\nsSCM.dll
3c18ce9d12a6c9864a45aa74ffc949f2 c:\Documents and Settings\"%CurrentUserName%"\Local Settings\Temp\nsh34.tmp\BrowserExtensionsSetupUAC.exe
5689d43c3b201dd3810fa3bba4a6476a c:\Documents and Settings\"%CurrentUserName%"\Local Settings\Temp\vcredist_x86.exe
f8cf17314c5e065611dfc05b49e485a8 c:\Documents and Settings\"%CurrentUserName%"\Local Settings\Temp\~sp2E.tmp
39d11c773b46d3084ef4aac1f9863146 c:\Program Files\GreenTree Applications\YTD Video Downloader\FFMPEG.EXE
62910599d15480d33cd176f7a7b74420 c:\Program Files\GreenTree Applications\YTD Video Downloader\Uninstall.exe
921b64a7dace4c93161b942b80b6b41b c:\Program Files\GreenTree Applications\YTD Video Downloader\librtmp.dll
ded3aa6b7920334e6b334eaed3db96c5 c:\Program Files\GreenTree Applications\YTD Video Downloader\libvlc.dll
3c07164ceba1068ee3eff672d8e11eb6 c:\Program Files\GreenTree Applications\YTD Video Downloader\libvlccore.dll
ab0a22194181d6d6ff01123dc9a376ce c:\Program Files\GreenTree Applications\YTD Video Downloader\plugins\access\.svn\text-base\libfilesystem_plugin.dll.svn-base
ab0a22194181d6d6ff01123dc9a376ce c:\Program Files\GreenTree Applications\YTD Video Downloader\plugins\access\libfilesystem_plugin.dll
91074f5c7288c67eaed2c2c657e373d3 c:\Program Files\GreenTree Applications\YTD Video Downloader\plugins\audio_filter\.svn\text-base\libaudio_format_plugin.dll.svn-base
43f19a5d4d42e3cd6514348ba5fbdd96 c:\Program Files\GreenTree Applications\YTD Video Downloader\plugins\audio_filter\.svn\text-base\libtrivial_channel_mixer_plugin.dll.svn-base
a3297b187aba1024501007bce77eeec4 c:\Program Files\GreenTree Applications\YTD Video Downloader\plugins\audio_filter\.svn\text-base\libugly_resampler_plugin.dll.svn-base
91074f5c7288c67eaed2c2c657e373d3 c:\Program Files\GreenTree Applications\YTD Video Downloader\plugins\audio_filter\libaudio_format_plugin.dll
43f19a5d4d42e3cd6514348ba5fbdd96 c:\Program Files\GreenTree Applications\YTD Video Downloader\plugins\audio_filter\libtrivial_channel_mixer_plugin.dll
a3297b187aba1024501007bce77eeec4 c:\Program Files\GreenTree Applications\YTD Video Downloader\plugins\audio_filter\libugly_resampler_plugin.dll
04a21f5ee0a9c27ca5e5dae050f3d275 c:\Program Files\GreenTree Applications\YTD Video Downloader\plugins\audio_mixer\.svn\text-base\libfloat_mixer_plugin.dll.svn-base
d4f826e68b616cccc1de1e5ef07738b8 c:\Program Files\GreenTree Applications\YTD Video Downloader\plugins\audio_mixer\.svn\text-base\libinteger_mixer_plugin.dll.svn-base
04a21f5ee0a9c27ca5e5dae050f3d275 c:\Program Files\GreenTree Applications\YTD Video Downloader\plugins\audio_mixer\libfloat_mixer_plugin.dll
d4f826e68b616cccc1de1e5ef07738b8 c:\Program Files\GreenTree Applications\YTD Video Downloader\plugins\audio_mixer\libinteger_mixer_plugin.dll
46672363f47a25d69a5324045f4e8d63 c:\Program Files\GreenTree Applications\YTD Video Downloader\plugins\audio_output\.svn\text-base\libdirectsound_plugin.dll.svn-base
46672363f47a25d69a5324045f4e8d63 c:\Program Files\GreenTree Applications\YTD Video Downloader\plugins\audio_output\libdirectsound_plugin.dll
4088b4e4ea76db97544c76ef7f2af08c c:\Program Files\GreenTree Applications\YTD Video Downloader\plugins\codec\.svn\text-base\libavcodec_plugin.dll.svn-base
4088b4e4ea76db97544c76ef7f2af08c c:\Program Files\GreenTree Applications\YTD Video Downloader\plugins\codec\libavcodec_plugin.dll
416108272cc56d4036d5796fbb1b8f3c c:\Program Files\GreenTree Applications\YTD Video Downloader\plugins\video_filter\.svn\text-base\libswscale_plugin.dll.svn-base
416108272cc56d4036d5796fbb1b8f3c c:\Program Files\GreenTree Applications\YTD Video Downloader\plugins\video_filter\libswscale_plugin.dll
350983ab596397b2d2703d658baeea8c c:\Program Files\GreenTree Applications\YTD Video Downloader\plugins\video_output\.svn\text-base\libdirect3d_plugin.dll.svn-base
6d9fa70a05698e9b6aa1c6074def16e8 c:\Program Files\GreenTree Applications\YTD Video Downloader\plugins\video_output\.svn\text-base\libdrawable_plugin.dll.svn-base
3dee8d41db28133b3d00bfdf0fd16eaf c:\Program Files\GreenTree Applications\YTD Video Downloader\plugins\video_output\.svn\text-base\libvmem_plugin.dll.svn-base
ccc67f588880568bfd46c4b8140f41aa c:\Program Files\GreenTree Applications\YTD Video Downloader\plugins\video_output\.svn\text-base\libwingdi_plugin.dll.svn-base
350983ab596397b2d2703d658baeea8c c:\Program Files\GreenTree Applications\YTD Video Downloader\plugins\video_output\libdirect3d_plugin.dll
6d9fa70a05698e9b6aa1c6074def16e8 c:\Program Files\GreenTree Applications\YTD Video Downloader\plugins\video_output\libdrawable_plugin.dll
3dee8d41db28133b3d00bfdf0fd16eaf c:\Program Files\GreenTree Applications\YTD Video Downloader\plugins\video_output\libvmem_plugin.dll
ccc67f588880568bfd46c4b8140f41aa c:\Program Files\GreenTree Applications\YTD Video Downloader\plugins\video_output\libwingdi_plugin.dll
547970950271112436efafb4632122a8 c:\Program Files\GreenTree Applications\YTD Video Downloader\ytd.exe
e2c80c6c8ba5d2847601c5f8d426b63a c:\Program Files\MyPC Backup\AWSSDK.dll
5bfc53c0daee82e70ef02b9cf7ae3042 c:\Program Files\MyPC Backup\AlphaVSS.51.x86.dll
ba1d420f7fa1b4eef8cc127bee74a023 c:\Program Files\MyPC Backup\AlphaVSS.52.x64.dll
568754948b2aa5fcc41217fb28425cc5 c:\Program Files\MyPC Backup\AlphaVSS.52.x86.dll
a3ef02398e089dcd9708cbc4e427d0f7 c:\Program Files\MyPC Backup\AlphaVSS.60.x64.dll
057cf7fd20135899d616714534d0b7a8 c:\Program Files\MyPC Backup\AlphaVSS.60.x86.dll
3116e40a8b9709917e1dc1db4e068152 c:\Program Files\MyPC Backup\AlphaVSS.Common.dll
e465525e1cbb92780aac5ad7d3f1cbbf c:\Program Files\MyPC Backup\BackupStack.exe
3392c789ab50d40131ff8f75df91265b c:\Program Files\MyPC Backup\Configuration Updater.exe
753da5b59f0fc465ccd60a598d9b5780 c:\Program Files\MyPC Backup\Crypto32.dll
199b0a1373fc914a9b756b1f9f882899 c:\Program Files\MyPC Backup\Crypto64.dll
538faef85616bc8d7edc33732be85b5d c:\Program Files\MyPC Backup\GetText.dll
9b2ac62a9aab3369b253411c14b92fcb c:\Program Files\MyPC Backup\LogicNP.EZShellExtensions.dll
4eb4e9dd980a3e19754c93b92bc57623 c:\Program Files\MyPC Backup\MPCBClient.dll
74ad2167e1247dd404e58fdab634d490 c:\Program Files\MyPC Backup\MPCBContextMenu.dll
bb3b81fd209597a178ea239ce39c6fc6 c:\Program Files\MyPC Backup\MPCBIconOverlays.dll
4bc02235ad1e85455e6ab8c1cc912c64 c:\Program Files\MyPC Backup\MyPC Backup.exe
5a5498e2176e0f40a8fddd53da88920e c:\Program Files\MyPC Backup\ObjectListView.dll
4bb211393828d585cb5396a273008d94 c:\Program Files\MyPC Backup\RegisterExtensionDotNet20_x64.exe
74a8c01b69adedd7f1330245cd994821 c:\Program Files\MyPC Backup\RegisterExtensionDotNet20_x86.exe
158c16d067a3e27c1234b03aa69120b2 c:\Program Files\MyPC Backup\RestartExplorer.exe
c5d24dd048304856c60a868f896507e4 c:\Program Files\MyPC Backup\Service Start.exe
c48ccef729d6c4539ea57afb179adb38 c:\Program Files\MyPC Backup\Shared Stack.dll
fe2c85a4cf13b37bad7ae065f807dc20 c:\Program Files\MyPC Backup\Signup Wizard.exe
c1b78e5bb7297b4b46f16873d0073123 c:\Program Files\MyPC Backup\UnRegisterExtensions.exe
a1c3cfb658f4546c5b2dbc92e85e88e0 c:\Program Files\MyPC Backup\Updater.exe
1946bde7c1276752a747bf987bd0ccbf c:\Program Files\MyPC Backup\diffstack.dll
b3f12e4c4aafb56e945ed48d8647b563 c:\Program Files\MyPC Backup\uninst.exe
9f71303bddecf888cc77c2a486769c9d c:\Program Files\MyPC Backup\x64\System.Data.SQLite.dll
80725a732aba27911402f9ca09fede23 c:\Program Files\MyPC Backup\x86\System.Data.SQLite.dll
47857df83c1bd9755afd1c7f0ae65465 c:\WINDOWS\WinSxS\x86_Microsoft.VC90.ATL_1fc8b3b9a1e18e3b_9.0.30729.1_x-ww_d01483b2\atl90.dll
7b37f8ec25c9ad853e8126c1d0992201 c:\WINDOWS\WinSxS\x86_Microsoft.VC90.CRT_1fc8b3b9a1e18e3b_9.0.30729.1_x-ww_6f74963e\msvcm90.dll
871f979d70414c900b35e56222932daf c:\WINDOWS\WinSxS\x86_Microsoft.VC90.CRT_1fc8b3b9a1e18e3b_9.0.30729.1_x-ww_6f74963e\msvcp90.dll
4d03ca609e68f4c90cf66515218017f8 c:\WINDOWS\WinSxS\x86_Microsoft.VC90.CRT_1fc8b3b9a1e18e3b_9.0.30729.1_x-ww_6f74963e\msvcr90.dll
b02f2fc742d87f54a94fcd5f4ce71d52 c:\WINDOWS\WinSxS\x86_Microsoft.VC90.MFCLOC_1fc8b3b9a1e18e3b_9.0.30729.1_x-ww_b0db7d03\mfc90chs.dll
3460a87d70e659c44b9fec195345ac2e c:\WINDOWS\WinSxS\x86_Microsoft.VC90.MFCLOC_1fc8b3b9a1e18e3b_9.0.30729.1_x-ww_b0db7d03\mfc90cht.dll
d727f282a20ebff629f26e13ce8fcac9 c:\WINDOWS\WinSxS\x86_Microsoft.VC90.MFCLOC_1fc8b3b9a1e18e3b_9.0.30729.1_x-ww_b0db7d03\mfc90deu.dll
2229324ce0374811ca64a19ee62f130b c:\WINDOWS\WinSxS\x86_Microsoft.VC90.MFCLOC_1fc8b3b9a1e18e3b_9.0.30729.1_x-ww_b0db7d03\mfc90enu.dll
154b11cc93fc5a4a03e21d3dedfb5879 c:\WINDOWS\WinSxS\x86_Microsoft.VC90.MFCLOC_1fc8b3b9a1e18e3b_9.0.30729.1_x-ww_b0db7d03\mfc90esn.dll
0f70ab283544f8dd3e5c7b2c27c34bbf c:\WINDOWS\WinSxS\x86_Microsoft.VC90.MFCLOC_1fc8b3b9a1e18e3b_9.0.30729.1_x-ww_b0db7d03\mfc90esp.dll
3c26a63c73eb4d6bda72815fcad79ef2 c:\WINDOWS\WinSxS\x86_Microsoft.VC90.MFCLOC_1fc8b3b9a1e18e3b_9.0.30729.1_x-ww_b0db7d03\mfc90fra.dll
25b61d43310128c1467c1d51397b5342 c:\WINDOWS\WinSxS\x86_Microsoft.VC90.MFCLOC_1fc8b3b9a1e18e3b_9.0.30729.1_x-ww_b0db7d03\mfc90ita.dll
be48c834229e153ab89bcca1f8309315 c:\WINDOWS\WinSxS\x86_Microsoft.VC90.MFCLOC_1fc8b3b9a1e18e3b_9.0.30729.1_x-ww_b0db7d03\mfc90jpn.dll
6574e30c091c2ac5c99db460094f19a0 c:\WINDOWS\WinSxS\x86_Microsoft.VC90.MFCLOC_1fc8b3b9a1e18e3b_9.0.30729.1_x-ww_b0db7d03\mfc90kor.dll
c1e0a8ab46902ee0e15e02931efcb885 c:\WINDOWS\WinSxS\x86_Microsoft.VC90.MFCLOC_1fc8b3b9a1e18e3b_9.0.30729.1_x-ww_b0db7d03\mfc90rus.dll
361a47591fd31ec99a9794b6541360a6 c:\WINDOWS\WinSxS\x86_Microsoft.VC90.MFC_1fc8b3b9a1e18e3b_9.0.30729.1_x-ww_405b0943\mfc90.dll
a76104d8d9aba3670fd3cea603d70ada c:\WINDOWS\WinSxS\x86_Microsoft.VC90.MFC_1fc8b3b9a1e18e3b_9.0.30729.1_x-ww_405b0943\mfc90u.dll
c38774421c7b64d2c23129a200c60f47 c:\WINDOWS\WinSxS\x86_Microsoft.VC90.MFC_1fc8b3b9a1e18e3b_9.0.30729.1_x-ww_405b0943\mfcm90.dll
db59cce916665d8c9a8a87198daede34 c:\WINDOWS\WinSxS\x86_Microsoft.VC90.MFC_1fc8b3b9a1e18e3b_9.0.30729.1_x-ww_405b0943\mfcm90u.dll
f6a85f3b0e30c96c993c69da6da6079e c:\WINDOWS\WinSxS\x86_Microsoft.VC90.OpenMP_1fc8b3b9a1e18e3b_9.0.21022.8_x-ww_ecc42bd1\vcomp90.dll

HOSTS file anomalies

No changes have been detected.

Rootkit activity

No anomalies have been detected.

Propagation

VersionInfo

Company Name:
Product Name: YTD Video Downloader
Product Version: 4.8.1.0.3
Legal Copyright: Copyright (c) 2007-2014 GreenTree Applications SRL
Legal Trademarks:
Original Filename: Uninstall.exe
Internal Name:
File Version: 4.8.1
File Description: YTD Video Downloader
Comments:
Language: English (United States)

PE Sections

Name Virtual Address Virtual Size Raw Size Entropy Section MD5
.text 4096 25506 25600 4.49191 3291075913c14a1799655a261fb21cca
.rdata 32768 6386 6656 3.3883 170563e94de7ebfd6e622a164ce38c8a
.data 40960 419484 512 0.991115 23d69b1e3a55dee07701198b7650a06b
.ndata 462848 3035136 0 0 d41d8cd98f00b204e9800998ecf8427e
.rsrc 3497984 52184 52224 4.67389 51c0cfa6e9235ef676e3b5201d9dd439

Dropped from:

Downloaded by:

Similar by SSDeep:

Similar by Lavasoft Polymorphic Checker:

URLs

URL IP
hxxp://ytd2.greentreeapps.ro/images/pixel.gif?action=install&point=start&cid=31fbc1ce06e12d56d19c32273fd38c79&isn=2A0E0F74E87C41248D17D84CDB01E7BE&kt=cnet
hxxp://ytd2.greentreeapps.ro/getcountry.html
hxxp://www.mybrowserbar.com/terms_extensions.rtf 174.36.215.20
hxxp://www.mybrowserbar.com/kits/hlp/exthelper.exe 174.36.215.20
hxxp://track.mypcbackup.com/4631cdb5/D0wnloads-mpb-cpl-new/MyPCBackup_Setup.exe 184.154.150.131
hxxp://mypcbackup.jdibackup.netdna-cdn.com/MyPCBackup_Setup.exe
hxxp://www.mybrowserbar.com/cgi/extconfig.cgi?cnid=407453&ver=1.0&kt=cnet&ot=YTD1&bver=34.0.1847.131 174.36.215.20
hxxp://update.mybrowserbar.com/kits/sds/update.xml 108.59.13.15
hxxp://www.mybrowserbar.com/kits/sds/update.xml 174.36.215.20
hxxp://update.mybrowserbar.com/kits/sds/SearchProtectionSetup.exe 108.59.13.15
hxxp://www.mybrowserbar.com/images/pixel.gif?sds=1&shp=1&sbe=1&cnid=407453&tov=19&kt=cnet 174.36.215.20
hxxp://ytd2.greentreeapps.ro/images/pixel.gif?action=install&point=finish&cid=31fbc1ce06e12d56d19c32273fd38c79&isn=2A0E0F74E87C41248D17D84CDB01E7BE&kt=cnet
hxxp://ytd4.greentreeapps.ro/thankyou.html?isn=2A0E0F74E87C41248D17D84CDB01E7BE&stb=1&sds=1&shp=1&lang=1033&cid=31fbc1ce06e12d56d19c32273fd38c79&oldVer=&newVer=4.8.1&tov=19&kt=cnet&pv=0&mpb=1
hxxp://ytd4.greentreeapps.ro/styles.css
hxxp://ytd4.greentreeapps.ro/js/main.js
hxxp://fallback.global-ssl.fastly.net/js/250/addthis_widget.js
hxxp://googleapis.l.google.com/ajax/libs/jquery/1.9.1/jquery.min.js
hxxp://ytd4.greentreeapps.ro/images/ytd-logo.png
hxxp://ytd4.greentreeapps.ro/images/top-header-bg.jpg
hxxp://fallback.global-ssl.fastly.net/static/r07/core131.js
hxxp://www-google-analytics.l.google.com/ga.js
hxxp://ytd4.greentreeapps.ro/images/upgrade-pro-btn.png
hxxp://ytd4.greentreeapps.ro/images/header-bg-repeat.jpg
hxxp://ytd4.greentreeapps.ro/images/header-bg.jpg
hxxp://e3821.dspe1.akamaiedge.net/en_US/all.js
hxxp://www-google-analytics.l.google.com/__utm.gif?utmwv=5.5.0&utms=1&utmn=211728539&utmhn=www.ytddownloader.com&utmcs=windows-1252&utmsr=1716x901&utmvp=1712x716&utmsc=32-bit&utmul=en-us&utmje=1&utmfl=11.6 r602&utmdt=YTD Video Converter&utmhid=2112539694&utmr=-&utmp=/thankyou.html?isn=2A0E0F74E87C41248D17D84CDB01E7BE&stb=1&sds=1&shp=1&lang=1033&cid=31fbc1ce06e12d56d19c32273fd38c79&oldVer=&newVer=4.8.1&tov=19&kt=cnet&pv=0&mpb=1&utmht=1399992971790&utmac=UA-25210420-2&utmcc=__utma=135583929.1101086425.1399992972.1399992972.1399992972.1;+__utmz=135583929.1399992972.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none);&utmu=q~
hxxp://fallback.global-ssl.fastly.net/static/r07/widget120.css
hxxp://fallback.global-ssl.fastly.net/static/r07/sh158.html
hxxp://fallback.global-ssl.fastly.net/static/r07/counter017.js
hxxp://fallback.global-ssl.fastly.net/static/r07/counter014.css
hxxp://fallback.global-ssl.fastly.net/static/r07/widget016_32x32_top.gif
hxxp://a749.dsw4.akamai.net/connect/xd_arbiter/dgdTycPTSRj.js?version=41
hxxp://m.addthisedge.com/live/red_lojson/300lo.json?19rgc5c&colc=1399992973025&si=5372328b6586c44f&uid=5372328cfdb7168d&pub=ytdcs&rev=1399981304&jsl=33&ln=en&pc=men&vpc=&dp=www.ytddownloader.com&aa=0&fcu1=667ae1ee&undefined&of=0&uf=1&pd=0&irt=0&md=0&ct=1&tct=0&abt=0&lt=782&cdn=0&lnlc=us&whcs=1&tl=c=1312,m=1312,i=1312,xm=2094,xp=2094&pi=1&fp=thankyou.html&&rb=0&gen=1000&gen=100&callback=_ate.track.hsr&chr=windows-1252
hxxp://a.ssl.fastly.net/url/shares.json?url=http://www.ytddownloader.com/&callback=_ate.cbs.sc_httpwwwytddownloadercom0
hxxp://ytd4.greentreeapps.ro/favicon.ico
hxxp://m.addthisedge.com/live/t00/mu.gif?a=sc&r=1&err=1
hxxp://a1294.w20.akamai.net/b?c1=7&c2=2000001&c3=1&rn=ymtqsy&c7=http://www.ytddownloader.com/thankyou.html&c8=YTD Video Converter&cv=1.7
hxxp://ds-any-fp3-real.wa1.b.yahoo.com/favicon.ico
hxxp://update.mybrowserbar.com/update/wt/ie/coupons/update.xml 108.59.13.15
hxxp://track.mypcbackup.com/aadebc4830c51c2794a960fe5a9e11df.php 184.154.150.131
hxxp://a767.dscms.akamai.net/download/d/d/9/dd9a82d0-52ef-40db-8dab-795376989c03/vcredist_x86.exe
hxxp://e6845.ce.akamaiedge.net/CSC3-2010.crl
hxxp://e6845.ce.akamaiedge.net/CSC3-2010.cer
hxxp://e6845.ce.akamaiedge.net/pca3-g5.crl
hxxp://s7.addthis.com/static/r07/core131.js 199.27.73.184
hxxp://s7.addthis.com/static/r07/counter014.css 199.27.73.184
hxxp://www.youtubedownloadersite.com/images/pixel.gif?action=install&point=start&cid=31fbc1ce06e12d56d19c32273fd38c79&isn=2A0E0F74E87C41248D17D84CDB01E7BE&kt=cnet 95.211.187.90
hxxp://crl.verisign.com/pca3-g5.crl 23.50.69.163
hxxp://www.ytddownloader.com/images/ytd-logo.png 5.79.67.100
hxxp://www.google-analytics.com/ga.js 173.194.43.105
hxxp://www.youtubedownloadersite.com/images/pixel.gif?action=install&point=finish&cid=31fbc1ce06e12d56d19c32273fd38c79&isn=2A0E0F74E87C41248D17D84CDB01E7BE&kt=cnet 95.211.187.90
hxxp://webupdate.mybrowserbar.com/kits/sds/SearchProtectionSetup.exe 108.59.13.12
hxxp://csc3-2010-aia.verisign.com/CSC3-2010.cer 23.50.69.163
hxxp://www.ytddownloader.com/images/upgrade-pro-btn.png 5.79.67.100
hxxp://ajax.googleapis.com/ajax/libs/jquery/1.9.1/jquery.min.js 74.125.70.95
hxxp://api-public.addthis.com/url/shares.json?url=http://www.ytddownloader.com/&callback=_ate.cbs.sc_httpwwwytddownloadercom0 199.27.72.196
hxxp://b.scorecardresearch.com/b?c1=7&c2=2000001&c3=1&rn=ymtqsy&c7=http://www.ytddownloader.com/thankyou.html&c8=YTD Video Converter&cv=1.7 72.247.9.129
hxxp://s7.addthis.com/js/250/addthis_widget.js 199.27.73.184
hxxp://www.google-analytics.com/__utm.gif?utmwv=5.5.0&utms=1&utmn=211728539&utmhn=www.ytddownloader.com&utmcs=windows-1252&utmsr=1716x901&utmvp=1712x716&utmsc=32-bit&utmul=en-us&utmje=1&utmfl=11.6 r602&utmdt=YTD Video Converter&utmhid=2112539694&utmr=-&utmp=/thankyou.html?isn=2A0E0F74E87C41248D17D84CDB01E7BE&stb=1&sds=1&shp=1&lang=1033&cid=31fbc1ce06e12d56d19c32273fd38c79&oldVer=&newVer=4.8.1&tov=19&kt=cnet&pv=0&mpb=1&utmht=1399992971790&utmac=UA-25210420-2&utmcc=__utma=135583929.1101086425.1399992972.1399992972.1399992972.1;+__utmz=135583929.1399992972.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none);&utmu=q~ 173.194.43.105
hxxp://s7.addthis.com/static/r07/widget120.css 199.27.73.184
hxxp://api.mybrowserbar.com/cgi/api.cgi/407453/E2DA97D8A12A4D02B7A3A58A402F38B0/vrst/20 174.36.215.20
hxxp://s7.addthis.com/static/r07/widget016_32x32_top.gif 199.27.73.184
hxxp://www.ytddownloader.com/styles.css 5.79.67.100
hxxp://www.ytddownloader.com/thankyou.html?isn=2A0E0F74E87C41248D17D84CDB01E7BE&stb=1&sds=1&shp=1&lang=1033&cid=31fbc1ce06e12d56d19c32273fd38c79&oldVer=&newVer=4.8.1&tov=19&kt=cnet&pv=0&mpb=1 5.79.67.100
hxxp://connect.facebook.net/en_US/all.js 23.32.175.139
hxxp://download.microsoft.com/download/d/d/9/dd9a82d0-52ef-40db-8dab-795376989c03/vcredist_x86.exe 72.247.8.72
hxxp://www.ytddownloader.com/images/header-bg.jpg 5.79.67.100
hxxp://www.ytddownloader.com/images/header-bg-repeat.jpg 5.79.67.100
hxxp://download.mybrowserbar.com/kits/hlp/exthelper.exe 174.36.215.20
hxxp://csc3-2010-crl.verisign.com/CSC3-2010.crl 23.50.69.163
hxxp://m.addthis.com/live/red_lojson/300lo.json?19rgc5c&colc=1399992973025&si=5372328b6586c44f&uid=5372328cfdb7168d&pub=ytdcs&rev=1399981304&jsl=33&ln=en&pc=men&vpc=&dp=www.ytddownloader.com&aa=0&fcu1=667ae1ee&undefined&of=0&uf=1&pd=0&irt=0&md=0&ct=1&tct=0&abt=0&lt=782&cdn=0&lnlc=us&whcs=1&tl=c=1312,m=1312,i=1312,xm=2094,xp=2094&pi=1&fp=thankyou.html&&rb=0&gen=1000&gen=100&callback=_ate.track.hsr&chr=windows-1252 8.37.70.20
hxxp://www.yahoo.com/favicon.ico 98.139.180.149
hxxp://cdn.mypcbackup.com/MyPCBackup_Setup.exe 108.161.187.46
hxxp://www.youtubedownloadersite.com/getcountry.html 95.211.187.90
hxxp://www.ytddownloader.com/favicon.ico 5.79.67.100
hxxp://www.ytddownloader.com/images/top-header-bg.jpg 5.79.67.100
hxxp://static.ak.facebook.com/connect/xd_arbiter/dgdTycPTSRj.js?version=41 72.247.9.32
hxxp://s7.addthis.com/static/r07/sh158.html 199.27.73.184
hxxp://s7.addthis.com/static/r07/counter017.js 199.27.73.184
hxxp://www.ytddownloader.com/js/main.js 5.79.67.100
hxxp://api.mybrowserbar.com/cgi/api.cgi/407453/E2DA97D8A12A4D02B7A3A58A402F38B0/vloc/20 174.36.215.20
s-static.ak.facebook.com 23.32.162.110


IDS verdicts (Suricata alerts: Emerging Threats ET ruleset)

ET program VMProtect Packed Binary Inbound via HTTP - Likely Hostile

Traffic

GET /images/pixel.gif?action=install&point=start&cid=31fbc1ce06e12d56d19c32273fd38c79&isn=2A0E0F74E87C41248D17D84CDB01E7BE&kt=cnet HTTP/1.0
Host: VVV.youtubedownloadersite.com
User-Agent: NSISDL/1.2 (Mozilla)
Accept: */*


HTTP/1.1 200 OK
Server: nginx
Date: Tue, 13 May 2014 14:55:44 GMT
Content-Type: image/gif
Content-Length: 1093
Last-Modified: Wed, 20 Feb 2013 14:38:31 GMT
Connection: close
Accept-Ranges: bytes
GIF89a.............!..XMP DataXMP<?xpacket begin="..." id="W5M0MpCe
hiHzreSzNTczkc9d"?> <x:xmpmeta xmlns:x="adobe:ns:meta/" x:xmptk=
"Adobe XMP Core 5.0-c060 61.134777, 2010/02/12-17:32:00 "> &
lt;rdf:RDF xmlns:rdf="hXXp://VVV.w3.org/1999/02/22-rdf-syntax-ns#">
<rdf:Description rdf:about="" xmlns:xmp="hXXp://ns.adobe.com/xap/1
.0/" xmlns:xmpMM="hXXp://ns.adobe.com/xap/1.0/mm/" xmlns:stRef="http:/
/ns.adobe.com/xap/1.0/sType/ResourceRef#" xmp:CreatorTool="Adobe Photo
shop CS5 Windows" xmpMM:InstanceID="xmp.iid:68AF816F211411E187C8D4C48A
462294" xmpMM:DocumentID="xmp.did:68AF8170211411E187C8D4C48A462294">
; <xmpMM:DerivedFrom stRef:instanceID="xmp.iid:68AF816D211411E187C8
D4C48A462294" stRef:documentID="xmp.did:68AF816E211411E187C8D4C48A4622
94"/> </rdf:Description> </rdf:RDF> </x:xmpmeta>
<?xpacket end="r"?>.............................................
......................................................................
...............~}|{zyxwvutsrqponmlkjihgfedcba`_^]\[ZYXWVUTSRQPONMLKJIH
GFEDCBA@?>=<;:9876543210/.-, *)('&%$#"! ........................
.........!.......,...........D..;..


GET /images/pixel.gif?sds=1&shp=1&sbe=1&cnid=407453&tov=19&kt=cnet HTTP/1.0
Host: VVV.mybrowserbar.com
User-Agent: NSISDL/1.2 (Mozilla)
Accept: */*


HTTP/1.1 200 OK
Date: Tue, 13 May 2014 14:56:08 GMT
Server: Apache
Accept-Ranges: bytes
Content-Length: 1093
Cache-Control: no-cache, no-store, must-revalidate, max-age=0, proxy-revalidate, no-transform
Pragma: no-cache
Expires: Thu, 01 Jan 1970 00:00:00 GMT
Connection: close
Content-Type: image/gif
GIF89a.............!..XMP DataXMP<?xpacket begin="..." id="W5M0MpCe
hiHzreSzNTczkc9d"?> <x:xmpmeta xmlns:x="adobe:ns:meta/" x:xmptk=
"Adobe XMP Core 5.0-c060 61.134777, 2010/02/12-17:32:00 "> &
lt;rdf:RDF xmlns:rdf="hXXp://VVV.w3.org/1999/02/22-rdf-syntax-ns#">
<rdf:Description rdf:about="" xmlns:xmp="hXXp://ns.adobe.com/xap/1
.0/" xmlns:xmpMM="hXXp://ns.adobe.com/xap/1.0/mm/" xmlns:stRef="http:/
/ns.adobe.com/xap/1.0/sType/ResourceRef#" xmp:CreatorTool="Adobe Photo
shop CS5 Windows" xmpMM:InstanceID="xmp.iid:68AF816F211411E187C8D4C48A
462294" xmpMM:DocumentID="xmp.did:68AF8170211411E187C8D4C48A462294">
; <xmpMM:DerivedFrom stRef:instanceID="xmp.iid:68AF816D211411E187C8
D4C48A462294" stRef:documentID="xmp.did:68AF816E211411E187C8D4C48A4622
94"/> </rdf:Description> </rdf:RDF> </x:xmpmeta>
<?xpacket end="r"?>.............................................
......................................................................
...............~}|{zyxwvutsrqponmlkjihgfedcba`_^]\[ZYXWVUTSRQPONMLKJIH
GFEDCBA@?>=<;:9876543210/.-, *)('&%$#"! ........................
.........!.......,...........D..;..


GET /cgi/extconfig.cgi?cnid=407453&ver=1.0&kt=cnet&ot=YTD1&bver=34.0.1847.131 HTTP/1.1
Accept: */*
Accept-Encoding: gzip, deflate
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 5.1; Trident/4.0; .NET CLR 2.0.50727; .NET CLR 3.0.04506.648; .NET CLR 3.5.21022; .NET4.0C; .NET CLR 3.0.4506.2152; .NET CLR 3.5.30729)
Host: VVV.mybrowserbar.com
Connection: Keep-Alive


HTTP/1.1 200 OK
Date: Tue, 13 May 2014 14:56:06 GMT
Server: Apache
Vary: Host
Content-Length: 0
Keep-Alive: timeout=30, max=100
Connection: Keep-Alive
Content-Type: text/xml; charset=utf-8
HTTP/1.1 200 OK..Date: Tue, 13 May 2014 14:56:06 GMT..Server: Apache..
Vary: Host..Content-Length: 0..Keep-Alive: timeout=30, max=100..Connec
tion: Keep-Alive..Content-Type: text/xml; charset=utf-8..


GET /static/r07/widget016_32x32_top.gif HTTP/1.1
Accept: */*
Referer: hXXp://VVV.ytddownloader.com/thankyou.html?isn=2A0E0F74E87C41248D17D84CDB01E7BE&stb=1&sds=1&shp=1&lang=1033&cid=31fbc1ce06e12d56d19c32273fd38c79&oldVer=&newVer=4.8.1&tov=19&kt=cnet&pv=0&mpb=1
Accept-Language: en-us
User-Agent: Mozilla/4.0 (compatible; MSIE 8.0; Windows NT 5.1; Trident/4.0; .NET CLR 2.0.50727; .NET CLR 3.0.04506.648; .NET CLR 3.5.21022; .NET4.0C; .NET CLR 3.0.4506.2152; .NET CLR 3.5.30729)
Accept-Encoding: gzip, deflate
Host: s7.addthis.com
Connection: Keep-Alive


HTTP/1.1 200 OK
Server: Apache
Last-Modified: Fri, 04 Apr 2014 15:06:53 GMT
Cache-Control: public, no-check, max-age=86313600
Content-Type: image/gif
Content-Length: 4083
Accept-Ranges: bytes
Date: Tue, 13 May 2014 14:56:13 GMT
Via: 1.1 varnish
Age: 3011649
Connection: keep-alive
X-Served-By: cache-c31-CHI
X-Cache: HIT
X-Cache-Hits: 2259854
X-Timer: S1399992973.975486040,VS0,VE0
Vary: Host
.PNG........IHDR... ... .....uL.[....gAMA......a....}PLTE.............
..................(..JW.h...%.KIw.......i%(;Z|?G...n*9(%X.........9NS.
.d.V...w..H..L......h.......LXu...8..r......88a..._.e...I......@......
&8G...o.......&.8E.}.X......i...G.......ma..e.XY.......(*888......XXX.
.......}_r........x.r.....Tiv.......xZ.,..8(..~......nnn...HHH...5m7..
....@w......#....!..(),r.....T....x....=.((...,...M9D...h...Y0X..iM.R)
...(((.../Pps......F.J....tRNS..@p.. .`.........IDATx...._........{...
.S.. ...-...-..--....Y&5...~u....;.....&W.D...6i.7.u.m.6!uf.t.....kk.N
...?..Skkg......O..>I....d.tj-.H.N$.gRgU1(\.S.gS.T..y.'S.T...e.....
.....I..so..Y.`.}.1.I.N.R.z.}.1.^;.'?<N..o.'..7.3....E!..x.%.......
..D.lJ.^/..x.Dy..6C@>.hxk!.I.C>x@#[email protected]. [email protected]. ..
.E.MI....T[>.............'.v..9.........`.....^....1p....- c.......
.....c00.@..,..X.....[.`@.S..A.-o...`...........E.d.zA.i.e.........0..
..2.H]...M............`[Q19.4..s.6...sVT;.e....6..L...B..6^.....8.I...
d.l.........6...l..x...H&.U......s.). .}..o.............y. .../..B....
H..[.Y..;..`^|.;......H......L......P2...f"...B".......&....,H..:.:...
.....W......~!.C.{..h.....p.>Q.I30 ..(&..B4....M.|.....%Y..~.BS.@!H
~.P......0..s".......G..d...0.#.............\...O......<......h~..s
.............(. gs.C}V.^#.......J.h."..._...a.!.fY._.Q..Z%.<.V..@..
$...d(.h.$.......e.. [email protected]....,...
...n.u...}.0....J.m...Y.n.UX......j...b a..yj.L.I.!... ....IV.c.e....y
.s..P\.......o.z...i!.......8X8..$.........`vo..U(....{... ....OJ.

<<< skipped >>>

GET /CSC3-2010.crl HTTP/1.1
Accept: */*
User-Agent: Microsoft-CryptoAPI/5.131.2600.5512
Host: csc3-2010-crl.verisign.com
Connection: Keep-Alive
Cache-Control: no-cache
Pragma: no-cache


HTTP/1.1 200 OK
Server: Apache
ETag: "2237f9e4cdee23e13ed43192ff19e040:1399972210"
Last-Modified: Tue, 13 May 2014 09:10:10 GMT
Accept-Ranges: bytes
Content-Length: 126346
Date: Tue, 13 May 2014 14:56:59 GMT
Connection: keep-alive
Content-Type: application/pkix-crl
0....0...l...0...*.H........0..1.0...U....US1.0...U....VeriSign, Inc.1
.0...U....VeriSign Trust Network1;09..U...2Terms of use at hXXps://www
.verisign.com/rpa (c)101.0,..U...%VeriSign Class 3 Code Signing 2010 C
A..140513090003Z..140527090003Z0...N0!....c..k....D.k.....120708062201
Z0!... _...u.t.=.<.&...130218061114Z0!...&..].....P.k.:...120125130
117Z0!...7P.x....8.Q...s..130227010252Z0!...J.....Q..Y.[.....110404153
956Z0!...d...=..q!_...g9..130729145216Z0!...l.....h2<.H......120329
152211Z0!...q.9...`H.*.Y.C...120525202212Z0!...s...TM.......0...121221
080842Z0!...t..,.. ...eL.....130314222305Z0!...y..r.HW.v.....w..140423
054643Z0!..../u.......A..5...101214165045Z0!.....0.Xc...%...iM..121102
230226Z0!.......S.a&.X5t.E]..111206083350Z0!....c.(....B.[M83...140108
164517Z0!....A.Sv.....f,.....110609003155Z0!.....z......!.ID{]..101228
182208Z0!....b^......{d.J'...130102154110Z0!......0..........I..130912
181631Z0!....6e...~..T.......130131012247Z0!.........bD#*u......130226
223939Z0!.......@..'$.).;}\..130121172259Z0!....7.v..........n..120724
160733Z0!....P;.Y..d...c.(...120209181451Z0!.....].bb[.....!....140328
205453Z0!.....a...L`[email protected]
000242Z0!...........].{7.....120730000000Z0!...".......Z.V.,.e..121031
192224Z0!...'....[.1......g..130318195659Z0!...,GI.jH.|...J.....120518
121623Z0!...<%a.=.d.......O..120424164254Z0!...@........... .a..121
109212441Z0!...L.&L..o.8..=6....110311141238Z0!...L...5...s $.=.=..130
205142241Z0!...O.c.........t....130109132228Z0!...X.BS.G]T.l.w.i..

<<< skipped >>>

GET /js/250/addthis_widget.js HTTP/1.1
Accept: */*
Referer: hXXp://VVV.ytddownloader.com/thankyou.html?isn=2A0E0F74E87C41248D17D84CDB01E7BE&stb=1&sds=1&shp=1&lang=1033&cid=31fbc1ce06e12d56d19c32273fd38c79&oldVer=&newVer=4.8.1&tov=19&kt=cnet&pv=0&mpb=1
Accept-Language: en-us
User-Agent: Mozilla/4.0 (compatible; MSIE 8.0; Windows NT 5.1; Trident/4.0; .NET CLR 2.0.50727; .NET CLR 3.0.04506.648; .NET CLR 3.5.21022; .NET4.0C; .NET CLR 3.0.4506.2152; .NET CLR 3.5.30729)
Accept-Encoding: gzip, deflate
Host: s7.addthis.com
Connection: Keep-Alive


HTTP/1.1 200 OK
Server: Apache
Last-Modified: Tue, 13 May 2014 11:43:13 GMT
ETag: "4945ca8-1aab-4f946919f3640"
Content-Encoding: gzip
Content-Type: text/javascript
Content-Length: 2676
Accept-Ranges: bytes
Date: Tue, 13 May 2014 14:56:11 GMT
Via: 1.1 varnish
Age: 2923
Connection: keep-alive
X-Served-By: cache-c101-CHI
X-Cache: HIT
X-Cache-Hits: 1047736
X-Timer: S1399992971.420254230,VS0,VE0
Vary: Host,Accept-Encoding
...........Yms.8..~....d...%...W.i.v/3.....)....m).EU.........e[...I..
[email protected]#.?.....I*..6.....J.. .^.y....*....:....S/h9.Z.Z....q,
a....."@/C3.p~Dq..X...:..*.Y.......G>/[email protected].<R.l..g..
.o.3...%.A.`t...G0b9.,.,.-i*...#.:/...]..{>.."x...X...)4.'t.:.DL...
'..2...%.d....4<A:....V.E'..............`)..(AB=..qN...mzj.Ie..K.j.
p.s.M.<.....c."[email protected]....{....%<.=o........ Y..d....K>
.P..sZz....W7D.#[email protected]...._.4...g..i.....P..]....P...`...a...
..U...6..HI.......9..u...x.4{...........<.y..0C.[.Y.2.3....n..^!x..
.H=.Bm....*.Y.`......6L.3..!...}..V..2.gL..z.j.$.y....|...c....]..{A..
...j..`...|.....skR..u...f.^g.."l>a..|EF..|j....5....DN............
.....{.-R.....i...$E.....sX.........v:.........H.d.gmE.F..s.W}..t..L_.
...$..........#.....}J~.7.|.c.U O..#.&I.'....(......J.,D`9.3..........
..t ...3...A.?Z. ...d.G*...Eh..i..|5t%..~.8.....RK:9ye.y.J.C9...O.....
...2.KM.|..o.,.g...-.g...l..F.(...DOz.T..j.. ..PM..&.9.R.G.$f.yI.!.j*-
..R. ....R..)..'.MB;iO....)c........:g.%.2-........X>.....-..r..d\c
..\.DBo.i.~........|_..U..N-.u......~wp._h>...m6;zfh.$l.<..."K.m
...(xa...x..j"d.........fK...S............V_.J..o|...L.......Ok.c.....
...@/w..>.^l6........@.>.i.........=..|..*Ot....nB..e.g.wB..'..W
....po....h..}..s.}.pB......cv..5z.;.H.w....}G.<.;.e.....}..r`..V.L
....(.?..4!h0...#1.N]2Y......A....C....V..)NO...1..._....l6..../.\..=9
.....w.J$v..,...-g"..u...E.H$WA....w..l.ch..$BC.J.*.........2.......^.
]....ZN.dj.4..n..........7....z....3~<=.}..(..]n6`...{X.X}..o..

<<< skipped >>>

GET /static/r07/core131.js HTTP/1.1

Accept: */*
Referer: hXXp://VVV.ytddownloader.com/thankyou.html?isn=2A0E0F74E87C41248D17D84CDB01E7BE&stb=1&sds=1&shp=1&lang=1033&cid=31fbc1ce06e12d56d19c32273fd38c79&oldVer=&newVer=4.8.1&tov=19&kt=cnet&pv=0&mpb=1
Accept-Language: en-us
User-Agent: Mozilla/4.0 (compatible; MSIE 8.0; Windows NT 5.1; Trident/4.0; .NET CLR 2.0.50727; .NET CLR 3.0.04506.648; .NET CLR 3.5.21022; .NET4.0C; .NET CLR 3.0.4506.2152; .NET CLR 3.5.30729)
Accept-Encoding: gzip, deflate
Host: s7.addthis.com
Connection: Keep-Alive


HTTP/1.1 200 OK
Server: Apache
Last-Modified: Tue, 13 May 2014 11:42:44 GMT
Content-Encoding: gzip
Cache-Control: public, no-check, max-age=86313600
Content-Type: text/javascript
Content-Length: 76809
Accept-Ranges: bytes
Date: Tue, 13 May 2014 14:56:12 GMT
Via: 1.1 varnish
Age: 11125
Connection: keep-alive
X-Served-By: cache-c101-CHI
X-Cache: HIT
X-Cache-Hits: 457766
X-Timer: S1399992972.036291122,VS0,VE0
Vary: Host,Accept-Encoding
............ic.8.0.~...f.h..,Kv.$T..;{w...6...")..%.$%[email protected].<
;.}..X$./.BU.P.....8[{.....v...q.~....z3..~....}{{.O.t.:.......IP...vn
.~.u....S....`6.&E...n.].&2.......Pf..fi..i.....]...q.Y..y..r]|...,...
.h.C9....Y:..i.[.C.Y....V.?.w..a......%`k....mo.CY.......AO....q......
....H..,.....A.H...({......S......?.......N.{.."L.P...y.......n.......
........[..N..,...=#R......[WFy.................m..e.n5../..Vt..T`k.N.
.......%e.J..w.4....0...S.,.s.............1..O.......T.f<MC..0....&
lt;b#\,0...Z1P....f..;w.a...z.`@...t.e.Q@........^U..t....J.......)...
....c....Ggi?h._......q.G[..v%....X..$..........N[Ft.....[dq. .e.Z.d.0
.l.p. .F.....6...'u....3...x.K.`....zI....$^.q22.b...N.N...m..]......G
....K..<zb...Ip.9....s.D.&......w.6...4J.[.....y...V=A..0...k3..M..
....I^....?....... ..6J.t:.T0...4...).V..$wM.....r..$J.....y`.....*..{
....xSDc..'...`P...y$C.n...l.u.l{.Y.t....4snel.O..P..s...S..&......V.3
[email protected].:2\... .9.....UN|.E^.b.V.....jd.#............D<...
vP?...v[....!....."7....E...m1.CN.Oc.v.x<.qO.....nm.ma.]7l...&A....
".h..[.....B..'.......v...;...~ .'....P....;'>....h.'.....-.[..l...
.`C..%.....*r ..Y....O...".*...T....n.n.....W.q......V.M...V.\........
............#.^z.>..O.....f|..B.^....$6.g.L.is...[O.R..w.B......SHr
&..s....0..0.......>L......LOGg@...[z....yw.M.....du"F.r.1L'...x...
.....;H..........-n....-.Yt....3.[RC.%jq.5mr.)......{[email protected].}...}{..
>....h.}.`.......... .... !...Z.{}...[.Q.!K...G..%.....8h9|.$2.Vev.
`...r....|...{@...O.O.....2.Af..M)[email protected]`E...n.l

<<< skipped >>>

GET /static/r07/widget120.css HTTP/1.1

Accept: */*
Referer: hXXp://VVV.ytddownloader.com/thankyou.html?isn=2A0E0F74E87C41248D17D84CDB01E7BE&stb=1&sds=1&shp=1&lang=1033&cid=31fbc1ce06e12d56d19c32273fd38c79&oldVer=&newVer=4.8.1&tov=19&kt=cnet&pv=0&mpb=1
Accept-Language: en-us
User-Agent: Mozilla/4.0 (compatible; MSIE 8.0; Windows NT 5.1; Trident/4.0; .NET CLR 2.0.50727; .NET CLR 3.0.04506.648; .NET CLR 3.5.21022; .NET4.0C; .NET CLR 3.0.4506.2152; .NET CLR 3.5.30729)
Accept-Encoding: gzip, deflate
Host: s7.addthis.com
Connection: Keep-Alive


HTTP/1.1 200 OK
Server: Apache
Last-Modified: Tue, 29 Apr 2014 11:58:30 GMT
Content-Encoding: gzip
Cache-Control: public, no-check, max-age=86313600
Content-Type: text/css
Content-Length: 20793
Accept-Ranges: bytes
Date: Tue, 13 May 2014 14:56:13 GMT
Via: 1.1 varnish
Age: 1219550
Connection: keep-alive
X-Served-By: cache-c101-CHI
X-Cache: HIT
X-Cache-Hits: 25631345
X-Timer: S1399992973.216857672,VS0,VE0
Vary: Host,Accept-Encoding
............y....'..|..W......Z...k.l.../i.......Z,....C..(...o.{==}.U
.... ..F..$..}.d....9...e....c{..../^.l#..?}....i...~...k.p.....d]....
..nI.!...S......%...a....<..vxQ...~F4.....f.?......F../9.p. ^..$...
r.I.M.....^ ........~...|....[7...y..........k..6....Z...<....T.?..
.g..'...,.A.O.O.v%.../...i...[...K.n.p..?.$..b........7t..%../...]y...
...$......C.=b..j1[I.m...%[email protected]...\x..E..{...K'... _..2...
...}..^.[.e.R".E{.....o.....I$.(..*... ...._.....M6.2.|...k....bK....x
.{.dWW.........'....?........*.G...."..:.d.........v...i.{.Q.Rz.M...YJ
R...?.Y|`~........3.UUc=.t.t.eJ.~.E..J0...>...W.....>.K7yU.:....
'.....6..X.....7..5v.F...{uf.~...W.F.Z....=.......q=...........i..]c..
[email protected]..\.8..US...2...2F....;.:.............Pw2.Yw.UU.?....!......
t.........|.a4.........yi.7...o..[.....%..........i...l.x.]T.^..t.y.P.
!..D.D.....CO...#..,_.WB..e..d.V "[email protected].?/..........Oo.t-...t.:
.l....?!nD.s..0....... ......]......|.LG?.c~~.u....yE.V.uCr...]!R.8.;.
..Y_.f$.KvD.-.6....t.........I.*....Q...H.........."........&..q:...&l
t;<....o.*.v..#.h....U".o..9.%.N.$.g...D...<..u..Mo../....)6T..I
<D.......|h.L...abNV....]D..nn.DC...5<.}...L.....((e...<..y.*
.x.FB.\....%t.Do{0K8N=..T......B.........>.......O.e....x...E.Gs.`.
2..........U....=.$...2=[....Jf.].;.H..?.#...J..k..Wo..?.......p...(8l
].#Q0lq.0..&.LS.|...N<.y...I{../z._EQ|.v$If..p/$...b....s.w.=F..}.7
....G......i..u...%0#n..|{..{.]T..<....y.=.E..r.w..'[Q.x......>.
.dE.........m:.....H....p..y..,..V.....;...............]..y.-n...p

<<< skipped >>>

GET /static/r07/counter014.css HTTP/1.1

Accept: */*
Referer: hXXp://VVV.ytddownloader.com/thankyou.html?isn=2A0E0F74E87C41248D17D84CDB01E7BE&stb=1&sds=1&shp=1&lang=1033&cid=31fbc1ce06e12d56d19c32273fd38c79&oldVer=&newVer=4.8.1&tov=19&kt=cnet&pv=0&mpb=1
Accept-Language: en-us
User-Agent: Mozilla/4.0 (compatible; MSIE 8.0; Windows NT 5.1; Trident/4.0; .NET CLR 2.0.50727; .NET CLR 3.0.04506.648; .NET CLR 3.5.21022; .NET4.0C; .NET CLR 3.0.4506.2152; .NET CLR 3.5.30729)
Accept-Encoding: gzip, deflate
Host: s7.addthis.com
Connection: Keep-Alive


HTTP/1.1 200 OK
Server: Apache
Last-Modified: Fri, 04 Apr 2014 15:05:38 GMT
Content-Encoding: gzip
Cache-Control: public, no-check, max-age=86313600
Content-Type: text/css
Content-Length: 2666
Accept-Ranges: bytes
Date: Tue, 13 May 2014 14:56:13 GMT
Via: 1.1 varnish
Age: 2731440
Connection: keep-alive
X-Served-By: cache-c101-CHI
X-Cache: HIT
X-Cache-Hits: 11790312
X-Timer: S1399992973.804350376,VS0,VE0
Vary: Host,Accept-Encoding
...........XY..... ....fz..::...... .^&8........F..i..>v.a3...*..2.
/.~.L3w.....0..w ..C.\..{z.......v..Ad..z.. .a.Q....=.A.h.i...8r.2..(h
..nY...._l.E..Z.iCK.....RW..: ...5..........77..4.`...*.0...Z.F.....O.
.......i-pm.......w-7.e_o.?..E.G...b.....k.o..*.W..?~3.\...f.4....e.n}
u7.j]b...1...e....n0i...>.8>.i.....g..NA.....n...cKc4uU.R.>..
......nLvQ..Z...u.w...."i.m....>1.1..$J!<...*..4...]TG@@.....!..
. s.q..W._..8.h...>UH...:.G..RD.B..-|uLj2D.X.C..eO...DISA..Oj..v..E
,.(e..,.].K.........d.F,..`K..h..7.....F7.yN.F&....W^.....)..#f.......
..Z....U..fKzr...t..e0.1..f..[..;M.-%.h..{=...Z-.....C..u!*@..wf.i.t..
L.qg7..r........@e<a'k.......(L...:>....L6............/....G.Db.
...d4... }.5.1/WbL.=.......z'...d..4K..n....D\%Ss.-.P.V.r....-..oC._.i
wH. .F..dG..][email protected].{...E.2)7s.@.....;..2 U..i..e....0g;.........j..h
M.X..V.*.0.B.H.C.fQl.)'...|?.L8.D.M0D"...JB.)iR..f...cN2[..,...d...Z..
...j.`..U..~...B.}.D...!...P..:#Ik..E.`.J.....N.O.1.)@u.J.....ye...q.]
*.Jt......\[email protected]...).#..X..h
..l....w"rN.K..........s=m-6.........iY(T.W..:6.In..A..m.Z.].h.mE...Z(
.D5U/n...y.2l.=4W...... a........dN<!"f.=`$Tm.......|~...sXf....A..
c.i.*....g.y.`F...2s..3h..6#.9.e..FI.>.k{).........]y.l1.KKxb.t-S\.
Om.........=. ....z.@u=..........Z?....F.A..6.3.........2....}.J....).
.......X...U.Qq.i.7.. .W..,y..M(_Sc&.....J~..<asH.&~.U[..`R......A.
BZ..r...$..</CU......i....T.a..:;..j.\G...-...-II....#...*N...=.E.d
(.1.....i...ag.......)5JD$.k...D.. ;_#{..GE..ej.VY}Tu.u....h..r,b]

<<< skipped >>>

POST /cgi/api.cgi/407453/E2DA97D8A12A4D02B7A3A58A402F38B0/vrst/20 HTTP/1.1
Accept-Encoding: gzip,deflate
Content-Type: text/xml
User-Agent: WidgiToolbar-179-407453
Host: api.mybrowserbar.com
Content-Length: 609
Connection: Keep-Alive
Cache-Control: no-cache

<drq><auth><ccv>179</ccv><cnid>407453</cnid><isn>E2DA97D8A12A4D02B7A3A58A402F38B0</isn><ct>20</ct><dlid>1033</dlid><lngid>1033</lngid><wv>5.1</wv><brw><ie>8.0.6001.18702</ie><ff>29.0.1</ff><gc>34.0.1847.131</gc><dbrw>Internet Explorer</dbrw></brw></auth>
<vrst><isn>E2DA97D8A12A4D02B7A3A58A402F38B0</isn><cnid>407453</cnid><code_ver>179</code_ver><type>install</type><ct>20</ct><src>12</src><cid>75ed9567aa584c8ea8ea3cad7c47ab03</cid><cmdline>"C:\DOCUME~1\"%CurrentUserName%"\LOCALS~1\Temp\~sp2E.tmp" /cnid "407453" /hp /ntp_ie /dsie /dsff /dsgc /register /seprotect /runbe /ffbf=31 /iebf=31  /gcbf=31</cmdline></vrst></drq>
HTTP/1.1 200 OK
Date: Tue, 13 May 2014 14:56:27 GMT
Server: Apache
Pragma: no-cache
Cache-control: no-cache
Keep-Alive: timeout=30, max=100
Connection: Keep-Alive
Transfer-Encoding: chunked
Content-Type: text/html
Expires: Tue, 13 May 2014 14:56:27 GMT
2b..<drp><auth>.  <scv>179</scv>.</auth>
.</drp>..0..


GET /static/r07/sh158.html HTTP/1.1
Accept: image/gif, image/jpeg, image/pjpeg, image/pjpeg, application/x-shockwave-flash, application/x-ms-application, application/x-ms-xbap, application/vnd.ms-xpsdocument, application/xaml xml, */*
Referer: hXXp://VVV.ytddownloader.com/thankyou.html?isn=2A0E0F74E87C41248D17D84CDB01E7BE&stb=1&sds=1&shp=1&lang=1033&cid=31fbc1ce06e12d56d19c32273fd38c79&oldVer=&newVer=4.8.1&tov=19&kt=cnet&pv=0&mpb=1
Accept-Language: en-us
User-Agent: Mozilla/4.0 (compatible; MSIE 8.0; Windows NT 5.1; Trident/4.0; .NET CLR 2.0.50727; .NET CLR 3.0.04506.648; .NET CLR 3.5.21022; .NET4.0C; .NET CLR 3.0.4506.2152; .NET CLR 3.5.30729)
Accept-Encoding: gzip, deflate
Host: s7.addthis.com
Connection: Keep-Alive


HTTP/1.1 200 OK
Server: Apache
Last-Modified: Tue, 13 May 2014 11:43:12 GMT
Content-Encoding: gzip
Cache-Control: public, no-check, max-age=86313600
P3P: CP="NON ADM OUR DEV IND COM STA"
Content-Type: text/html; charset=UTF-8
Content-Length: 26393
Accept-Ranges: bytes
Date: Tue, 13 May 2014 14:56:13 GMT
Via: 1.1 varnish
Age: 11127
Connection: keep-alive
X-Served-By: cache-c48-CHI
X-Cache: HIT
X-Cache-Hits: 380880
X-Timer: S1399992973.412092447,VS0,VE0
Vary: Host,Accept-Encoding
............is.8.(.......C.`J..c.......SSKw..q9.I...\...../3...,..f.D.
.1U.".%.Hd........_....;.2.v~......;.~.....n......}....w,...k.$EX.i.D.
.....mR....],....L.q....K,....._*9M....3.o.GIao).:==..5L4..dlkA....("p
...2,.........NU.QX.vF...g].y..I.._...*.l.u..8O.....(.........v.$J....
*..!.Uxy..;.*..e.,.Sg..P..............;.v.W8.wu}.&~.0...[....s....4w..
.........p.K... <.E>.s...z.u...f.... .R?.....i........../..!....
.=...|`....Y..C........z,J=..IZ..Mc.....Q..\'..=...<tY. (...Y..A#..
xR.9.9.X1....J. .OQ..,6.Ez.|.......g...w4.......;.{( [email protected]..
iG J...n.;.....e..1.../.Rp...l).(.x.T...C............{.v.7.?1.....%...
....4v.rK....?V.lm.....M..i..N....Wa> x.(.^...O.&.....[..*."{..:...
T.....d{."..{'.J.m....>..9. /.%.1..S%...eB.g...7....z'jr?OC...._...
......".f....H...(.^..:.)..KID}Y....@[...^O`O...Z..^.%.^..8(..[...n8..
.....IX*...R....{..8.k<.!o$.......&.Fn...p.$./rb_..HcA.....)....#..
f.dr..p<).t...D.".TI.......d...P.`..Y..[h....w"....0.^....."..-&.6Z
("..<e...-uSp./........n...I2.2A&..(..y.<...y....h...e.z.......)
..(Df..e.L......H.Fa.h.m...z[|...<..6$..*M.J.M.4.6..O.jp.K..g.L...E
........0X3v.}..z....>?CO....O......g...2......1.X.L.O.A~...n0..S..
.'Y........Y&vi..1?...d... ...S.]...R...-....w.r....Xc.... .,-..nZ.,..
..;.r.5.{{.#.....u..........5.e.Q.f.f.S.g.[.PR...]....,..Rm.7I.M..m...
........7....d......P.f...Z ,........_`~...b.p..w...v.....nl....A..,..
.....<..`..[..:.k...I..]?0o...w...Sg...[c........x..a..96{....~...N
....?.....VOD.......2.}@...v5.....)." n@.....:[email protected].

<<< skipped >>>

GET /images/header-bg-repeat.jpg HTTP/1.1
Accept: */*
Referer: hXXp://VVV.ytddownloader.com/thankyou.html?isn=2A0E0F74E87C41248D17D84CDB01E7BE&stb=1&sds=1&shp=1&lang=1033&cid=31fbc1ce06e12d56d19c32273fd38c79&oldVer=&newVer=4.8.1&tov=19&kt=cnet&pv=0&mpb=1
Accept-Language: en-us
User-Agent: Mozilla/4.0 (compatible; MSIE 8.0; Windows NT 5.1; Trident/4.0; .NET CLR 2.0.50727; .NET CLR 3.0.04506.648; .NET CLR 3.5.21022; .NET4.0C; .NET CLR 3.0.4506.2152; .NET CLR 3.5.30729)
Accept-Encoding: gzip, deflate
Host: VVV.ytddownloader.com
Connection: Keep-Alive


HTTP/1.1 200 OK
Server: nginx/1.2.1
Date: Tue, 13 May 2014 14:56:12 GMT
Content-Type: image/jpeg
Content-Length: 1497
Last-Modified: Fri, 05 Oct 2012 14:07:53 GMT
Connection: keep-alive
Accept-Ranges: bytes
......Exif..II*.................Ducky.......d.....ohXXp://ns.adobe.com
/xap/1.0/.<?xpacket begin="..." id="W5M0MpCehiHzreSzNTczkc9d"?>
<x:xmpmeta xmlns:x="adobe:ns:meta/" x:xmptk="Adobe XMP Core 5.0-c06
1 64.140949, 2010/12/07-10:57:01 "> <rdf:RDF xmlns:rdf="h
ttp://VVV.w3.org/1999/02/22-rdf-syntax-ns#"> <rdf:Description rd
f:about="" xmlns:xmpMM="hXXp://ns.adobe.com/xap/1.0/mm/" xmlns:stRef="
hXXp://ns.adobe.com/xap/1.0/sType/ResourceRef#" xmlns:xmp="hXXp://ns.a
dobe.com/xap/1.0/" xmpMM:OriginalDocumentID="xmp.did:48617E8EC10BE2118
B4BD91E24AB7A59" xmpMM:DocumentID="xmp.did:FC5012CA0BCB11E2AA79CB95D10
CA426" xmpMM:InstanceID="xmp.iid:FC5012C90BCB11E2AA79CB95D10CA426" xmp
:CreatorTool="Adobe Photoshop CS5.1 Windows"> <xmpMM:DerivedFrom
stRef:instanceID="xmp.iid:48617E8EC10BE2118B4BD91E24AB7A59" stRef:doc
umentID="xmp.did:48617E8EC10BE2118B4BD91E24AB7A59"/> </rdf:Descr
iption> </rdf:RDF> </x:xmpmeta> <?xpacket end="r"?&g
t;....Adobe.d.........................................................
......................................................................
..................................~...................................
................................1.!A.."3Qaq....2......................
..!1A.Q.....2Bb...3............?..s.}..4v$...y ....a[.C...............
.wZ%..Y..G.T.r...J."n...5.h.....G...qs...NH~._.....Wu....K.g...\.V1.r.
f.n.`.. ..X8..o....s]..I.\[#..[..`.6..5..9.....r..&.F.....S2_...Ea....
.U....c...GIo...............x&.T.B..l..E.......J.z.}im..>#.@...

<<< skipped >>>

GET /favicon.ico HTTP/1.1

Accept: */*
Accept-Encoding: gzip, deflate
User-Agent: Mozilla/4.0 (compatible; MSIE 8.0; Windows NT 5.1; Trident/4.0; .NET CLR 2.0.50727; .NET CLR 3.0.04506.648; .NET CLR 3.5.21022; .NET4.0C; .NET CLR 3.0.4506.2152; .NET CLR 3.5.30729)
Host: VVV.ytddownloader.com
Connection: Keep-Alive
Cookie: __utma=135583929.1101086425.1399992972.1399992972.1399992972.1; __utmb=135583929.1.10.1399992972; __utmc=135583929; __utmz=135583929.1399992972.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); __atuvc=1|20


HTTP/1.1 200 OK
Server: nginx/1.2.1
Date: Tue, 13 May 2014 14:56:14 GMT
Content-Type: image/x-icon
Content-Length: 22486
Last-Modified: Thu, 24 Oct 2013 10:35:32 GMT
Connection: keep-alive
Accept-Ranges: bytes
......00..........f...  ......................h.......00.... ..%......
.... ......B........ .h...nS..(...0...`.............................
..............'''.< .333.>01.?28.;;;.@.".D2$.H6%.K9&.E5*.K:*.Q=
).G95.L<0.G9<.T@*.YE,.]H..RB5.RC:._I=.`K/.cN0.fP2.kU4.nX5.fP=.n[
?.qZ6.v^9.ya9...N...N.'%K.#.`.,$w.B3D.E9O.F4P.E=P.M:[.DDD.LBJ.KKK.QCE.
[LB.WCH.^PG.JCX.]HP.WWW.aQB.aSJ.u^H.hZQ.r`F.naY.rf^.LEd.FAh.YGi.FGy.XH
v.TR}.\Y{.g\b.cMs.cPv.ccc.kkk.uia.{qi.mlx.sss.}rt.{{{..we..wd..tm..xi.
.{t..~w...x.4 ..7,..=0..-...; ..J9..O?..E8..L>..[I..UV..MO..]L..TK.
.OS..VY..aP..c^..pq..ed..wv..ZL..RL..YJ..UR..KF..WJ..\Q..a[..\f..eh..l
k..sq..ko..z{..*...'...8*..>3..2%..2)..83..<2..%...*&..3...:6..:
;..A5..D9..L?..A4..E:..I=..C:[email protected][email protected].
.PE..YN..VV..ZQ..VX..^_..WZ..cY..c\..aW..[b..Wb..]a..ej..fq..mq..ka..`
k..im..ce..i`..ri..ov..zq..JD..SN..UP..[V..WY..^[..KH..VT..a]..a]..]h.
.ff..tk..ps..lh..pn..vy...~.......{..|...|............................
......................................................................
......................................................................
......................................................................
................................................................S11111
1S....................................1.......1.....1.................
.................................1..........................8.........
. ........1.............................7Glq.....nG9"!.............
.............1....Bl.{{{{{{{{{{{{.nF9.....1.................1..4m}

<<< skipped >>>

GET /thankyou.html?isn=2A0E0F74E87C41248D17D84CDB01E7BE&stb=1&sds=1&shp=1&lang=1033&cid=31fbc1ce06e12d56d19c32273fd38c79&oldVer=&newVer=4.8.1&tov=19&kt=cnet&pv=0&mpb=1 HTTP/1.1
Accept: */*
Accept-Language: en-us
User-Agent: Mozilla/4.0 (compatible; MSIE 8.0; Windows NT 5.1; Trident/4.0; .NET CLR 2.0.50727; .NET CLR 3.0.04506.648; .NET CLR 3.5.21022; .NET4.0C; .NET CLR 3.0.4506.2152; .NET CLR 3.5.30729)
Accept-Encoding: gzip, deflate
Host: VVV.ytddownloader.com
Connection: Keep-Alive


HTTP/1.1 200 OK
Server: nginx/1.2.1
Date: Tue, 13 May 2014 14:56:10 GMT
Content-Type: text/html
Transfer-Encoding: chunked
Connection: keep-alive
X-Powered-By: PHP/5.4.6-1ubuntu1.8
Content-Encoding: gzip
6fa.............Wms.6..,..5;SIs!i.......[r.I.4.{..d4..R.)[email protected].
J.....b./.>..._........f.....wo.....?.Wax}.M....O.h....b..F..eaxs..
77.8...j..N.....c.....p..... 6.79.Y!..Y.?#L.'.p./"...d....j.V[G.L..4W&
lt;.{.l2..Hk....c.......Y#0..x.B.;.v"..\D,.j]-.6&..*.$...".......Y..Z.
......(.i...0d...R)...B.*..ka&f:\.Zr.......~.."......J.....s..%{&...&l
t;^.'[email protected]..)........./.v...E........".d.....>\..W......?.~.?.G.
...,.O....U.K.<[email protected]},.r.s.D.3.o2n.z...n..R.XO .u....u.Lo..
.F..&9.8..c...y.g]....d..AA......G...P..Kg.{..n..A.:w>..7FDU.q.Bw.{
m\u.....%}..g.-[..s.O..........y r.8_.D*.K...U...{x.8X.......D<....
.4. X.P:.T&...P...6.. .....,...Aku..Y.........m...>)nJ..b......\...
...V.N..$.y.#.$,.3)..........e....:.-.......o..v......k`.....Ss...:~..
[email protected]..~.cd...\ms.....Y.cU..s..J...ga..snyo=....
.2?..M;.i*..Y..{.H.rb.V.$.pB..2.*..<..e.:......G.`..]......-."....Y
[email protected]..<Q".C)..~6q.._m...)g|G.h6..)..@. ...;@....{......?3.
7y.8..xk....!<..V...1-,..\h.%b.L......"...E..12...7ook....uL....A..
........]=..O....T].V*..vd.5&.......9#..s..f~F.......z.....%3...@/.J.x
:...b.....S..o...K.h.....?..u9...Ng.l..:...;zm..=X.Z.7.............3..
.ON.LD.3tL.....-.q.......".s....W.2.X0|u.6.W ..Y.34..|.?U8..B...u....M
u...^........4..5..g*.k..6..r{E?......_......!...Y.A.. ..w...#....:...
\.....lP.nO.......%...j.y..H.x..tV|......Q9KQ..T.cb...I#} W[8nC{.<;
.4...d...nl..9..........1..o..X...lgd....6d....._w....3...4\..e.&.....
N0xp......q...e.N..ce...%.B.(.4...?../~..l k1....z..U.N.P.{>...

<<< skipped >>>

GET /styles.css HTTP/1.1

Accept: */*
Referer: hXXp://VVV.ytddownloader.com/thankyou.html?isn=2A0E0F74E87C41248D17D84CDB01E7BE&stb=1&sds=1&shp=1&lang=1033&cid=31fbc1ce06e12d56d19c32273fd38c79&oldVer=&newVer=4.8.1&tov=19&kt=cnet&pv=0&mpb=1
Accept-Language: en-us
User-Agent: Mozilla/4.0 (compatible; MSIE 8.0; Windows NT 5.1; Trident/4.0; .NET CLR 2.0.50727; .NET CLR 3.0.04506.648; .NET CLR 3.5.21022; .NET4.0C; .NET CLR 3.0.4506.2152; .NET CLR 3.5.30729)
Accept-Encoding: gzip, deflate
Host: VVV.ytddownloader.com
Connection: Keep-Alive


HTTP/1.1 200 OK
Server: nginx/1.2.1
Date: Tue, 13 May 2014 14:56:11 GMT
Content-Type: text/css
Content-Length: 16461
Last-Modified: Tue, 01 Apr 2014 14:19:57 GMT
Connection: keep-alive
Accept-Ranges: bytes
/* hXXp://meyerweb.com/eric/tools/css/reset/ .   v2.0 | 20110126.   Li
cense: none (public domain).*/..html, body, div, span, applet, object,
iframe,.h1, h2, h3, h4, h5, h6, p, blockquote, pre,.a, abbr, acronym,
address, big, cite, code,.del, dfn, em, img, ins, kbd, q, s, samp,.sm
all, strike, strong, sub, sup, tt, var,.b, u, i, center,.dl, dt, dd, o
l, ul, li,.fieldset, form, label, legend,.table, caption, tbody, tfoot
, thead, tr, th, td,.article, aside, canvas, details, embed, .figure,
figcaption, footer, header, hgroup, .menu, nav, output, ruby, section,
summary,.time, mark, audio, video {..margin: 0;..padding: 0;..border:
0;..font-size: 100%;..font: inherit;..font-size:13px;..line-height:18
px;..vertical-align: baseline;..font-family:Tahoma, Arial, Helvetica,
sans-serifl.}./* HTML5 display-role reset for older browsers */.articl
e, aside, details, figcaption, figure, .footer, header, hgroup, menu,
nav, section {..display: block;.}.body {..line-height: 1;.}.ol, ul {..
list-style: none;.}.blockquote, q {..quotes: none;.}.blockquote:before
, blockquote:after,.q:before, q:after {..content: '';..content: none;.
}.table {..border-collapse: collapse;..border-spacing: 0;.}..clearfix:
after {..content: ".";..display: block;..clear: both;..visibility: hid
den;..line-height: 0;..height: 0;.}. ..clearfix {..display: inline-blo
ck;.}. .html[xmlns] .clearfix {..display: block;.}. .* html .clearfix
{..height: 1%;.}.a:link, a:visited, a:hover, a:active {color:#2c4b00;
text-decoration:underline;}.h1 {font-size:24px; margin-bottom:8px;

<<< skipped >>>

GET /images/top-header-bg.jpg HTTP/1.1

Accept: */*
Referer: hXXp://VVV.ytddownloader.com/thankyou.html?isn=2A0E0F74E87C41248D17D84CDB01E7BE&stb=1&sds=1&shp=1&lang=1033&cid=31fbc1ce06e12d56d19c32273fd38c79&oldVer=&newVer=4.8.1&tov=19&kt=cnet&pv=0&mpb=1
Accept-Language: en-us
User-Agent: Mozilla/4.0 (compatible; MSIE 8.0; Windows NT 5.1; Trident/4.0; .NET CLR 2.0.50727; .NET CLR 3.0.04506.648; .NET CLR 3.5.21022; .NET4.0C; .NET CLR 3.0.4506.2152; .NET CLR 3.5.30729)
Accept-Encoding: gzip, deflate
Host: VVV.ytddownloader.com
Connection: Keep-Alive


HTTP/1.1 200 OK
Server: nginx/1.2.1
Date: Tue, 13 May 2014 14:56:12 GMT
Content-Type: image/jpeg
Content-Length: 2458
Last-Modified: Fri, 05 Oct 2012 14:07:53 GMT
Connection: keep-alive
Accept-Ranges: bytes
......Exif..II*.................Ducky.......d.....ohXXp://ns.adobe.com
/xap/1.0/.<?xpacket begin="..." id="W5M0MpCehiHzreSzNTczkc9d"?>
<x:xmpmeta xmlns:x="adobe:ns:meta/" x:xmptk="Adobe XMP Core 5.0-c06
1 64.140949, 2010/12/07-10:57:01 "> <rdf:RDF xmlns:rdf="h
ttp://VVV.w3.org/1999/02/22-rdf-syntax-ns#"> <rdf:Description rd
f:about="" xmlns:xmpMM="hXXp://ns.adobe.com/xap/1.0/mm/" xmlns:stRef="
hXXp://ns.adobe.com/xap/1.0/sType/ResourceRef#" xmlns:xmp="hXXp://ns.a
dobe.com/xap/1.0/" xmpMM:OriginalDocumentID="xmp.did:48617E8EC10BE2118
B4BD91E24AB7A59" xmpMM:DocumentID="xmp.did:FC5012C60BCB11E2AA79CB95D10
CA426" xmpMM:InstanceID="xmp.iid:FC5012C50BCB11E2AA79CB95D10CA426" xmp
:CreatorTool="Adobe Photoshop CS5.1 Windows"> <xmpMM:DerivedFrom
stRef:instanceID="xmp.iid:48617E8EC10BE2118B4BD91E24AB7A59" stRef:doc
umentID="xmp.did:48617E8EC10BE2118B4BD91E24AB7A59"/> </rdf:Descr
iption> </rdf:RDF> </x:xmpmeta> <?xpacket end="r"?&g
t;....Adobe.d.........................................................
......................................................................
......................................................................
.........................................!1....Aa....Q"q...2.......#3$
....B.Cd5E..........................!#.1A."..a2.C....B3$.%.q.D..4d5E.8
............?..}.4.i....#v...jq.[Lj.....]Hzc.=12..........<.....w..
...t.E=..K...U......vt...-.x.hY.].j...#..de.t....yf. .".`.n.....a....i
"8.C. ......A..aFs~.By..d..|..V.k.h.;'-.p.}..W.d.IM...v'...Z_.Ak]m

<<< skipped >>>

GET /images/upgrade-pro-btn.png HTTP/1.1

Accept: */*
Referer: hXXp://VVV.ytddownloader.com/thankyou.html?isn=2A0E0F74E87C41248D17D84CDB01E7BE&stb=1&sds=1&shp=1&lang=1033&cid=31fbc1ce06e12d56d19c32273fd38c79&oldVer=&newVer=4.8.1&tov=19&kt=cnet&pv=0&mpb=1
Accept-Language: en-us
User-Agent: Mozilla/4.0 (compatible; MSIE 8.0; Windows NT 5.1; Trident/4.0; .NET CLR 2.0.50727; .NET CLR 3.0.04506.648; .NET CLR 3.5.21022; .NET4.0C; .NET CLR 3.0.4506.2152; .NET CLR 3.5.30729)
Accept-Encoding: gzip, deflate
Host: VVV.ytddownloader.com
Connection: Keep-Alive


HTTP/1.1 200 OK
Server: nginx/1.2.1
Date: Tue, 13 May 2014 14:56:12 GMT
Content-Type: image/png
Content-Length: 13813
Last-Modified: Thu, 24 Oct 2013 10:30:42 GMT
Connection: keep-alive
Accept-Ranges: bytes
.PNG........IHDR.......T.............tEXtSoftware.Adobe ImageReadyq.e&
lt;..."iTXtXML:com.adobe.xmp.....<?xpacket begin="..." id="W5M0MpCe
hiHzreSzNTczkc9d"?> <x:xmpmeta xmlns:x="adobe:ns:meta/" x:xmptk=
"Adobe XMP Core 5.0-c061 64.140949, 2010/12/07-10:57:01 "> &
lt;rdf:RDF xmlns:rdf="hXXp://VVV.w3.org/1999/02/22-rdf-syntax-ns#">
<rdf:Description rdf:about="" xmlns:xmp="hXXp://ns.adobe.com/xap/1
.0/" xmlns:xmpMM="hXXp://ns.adobe.com/xap/1.0/mm/" xmlns:stRef="http:/
/ns.adobe.com/xap/1.0/sType/ResourceRef#" xmp:CreatorTool="Adobe Photo
shop CS5.1 Windows" xmpMM:InstanceID="xmp.iid:6223BDC2438711E199DFDADE
185FF648" xmpMM:DocumentID="xmp.did:6223BDC3438711E199DFDADE185FF648"&
gt; <xmpMM:DerivedFrom stRef:instanceID="xmp.iid:6223BDC0438711E199
DFDADE185FF648" stRef:documentID="xmp.did:6223BDC1438711E199DFDADE185F
F648"/> </rdf:Description> </rdf:RDF> </x:xmpmeta>
; <?xpacket end="r"?>7._...2iIDATx..}y.eGy....{.{o.E..4h..ZF...b
Dd.#BA...`'..."... .........O*.............. 1.lJ.-.,a./#....7..{.9.;.
|_.w..........;.-......_..O(.`...|.!..?K..g.x..?....................Y.
...D..AB&2.....O..{..<..d1........O,~........z..?xl..q.-.......b..o
..'?../pW..<..ms..}[....Wn...w...m...R?!3O.Z.^.t..{O...?......O....
kx|......?...>..n...?^B...".V..<...7...u..M....5^...Qw..p.A..4 .
.f.&...o~..Pfuy.vxt.qP/....yx.8.B......_>..?..w.g.m........5{....ZJ
..yU.._.......{[email protected]}[email protected]@u7....l...W...~~Z
.2c.\.....?.3.n..u..3....r...2...w.F..U..S.=..^....y.*.\.y.u....)1

<<< skipped >>>

GET /download/d/d/9/dd9a82d0-52ef-40db-8dab-795376989c03/vcredist_x86.exe HTTP/1.0
Host: download.microsoft.com
User-Agent: NSISDL/1.2 (Mozilla)
Accept: */*


HTTP/1.0 200 OK
Content-Type: application/octet-stream
Last-Modified: Fri, 08 Aug 2008 21:12:57 GMT
Accept-Ranges: bytes
ETag: "cde1e9879bf9c81:0"
Server: Microsoft-IIS/8.0
Content-Disposition: attachment
Content-Length: 4216840
Date: Tue, 13 May 2014 14:56:48 GMT
Connection: close
MZ......................@.............................................
..!..L.!This program cannot be run in DOS mode....$...........K...K...
K.......D...K... ......._.......J.......J...RichK...........PE..L...{.
.B.................z..........rY... ........... ......................
.........6A.......... [email protected].........
...4@..$...........!............................................... ..
.............................text....x... ...z.................. ..`.d
[email protected].........?.............
....@..@..............................................................
......................................................................
......................................................................
......................................................................
......................................................................
......................................................................
....................................................t...Z.............
......&...<...L............................................... ...:
...J...V...^...x.......................................&...<...J...
^...t.......................................(...:...R...b...p.........
..........................&...N...b...|...............r.......\...L...
:...,...........................................~...f.................
......z...............................&...0...D...:...............:...
........$...................{..B.............&..................Z.

<<< skipped >>>

GET /images/header-bg.jpg HTTP/1.1
Accept: */*
Referer: hXXp://VVV.ytddownloader.com/thankyou.html?isn=2A0E0F74E87C41248D17D84CDB01E7BE&stb=1&sds=1&shp=1&lang=1033&cid=31fbc1ce06e12d56d19c32273fd38c79&oldVer=&newVer=4.8.1&tov=19&kt=cnet&pv=0&mpb=1
Accept-Language: en-us
User-Agent: Mozilla/4.0 (compatible; MSIE 8.0; Windows NT 5.1; Trident/4.0; .NET CLR 2.0.50727; .NET CLR 3.0.04506.648; .NET CLR 3.5.21022; .NET4.0C; .NET CLR 3.0.4506.2152; .NET CLR 3.5.30729)
Accept-Encoding: gzip, deflate
Host: VVV.ytddownloader.com
Connection: Keep-Alive


HTTP/1.1 200 OK
Server: nginx/1.2.1
Date: Tue, 13 May 2014 14:56:12 GMT
Content-Type: image/jpeg
Content-Length: 123553
Last-Modified: Thu, 10 Oct 2013 14:08:34 GMT
Connection: keep-alive
Accept-Ranges: bytes
......Exif..II*.................Ducky.......Z..... hXXp://ns.adobe.com
/xap/1.0/.<?xpacket begin="..." id="W5M0MpCehiHzreSzNTczkc9d"?>
<x:xmpmeta xmlns:x="adobe:ns:meta/" x:xmptk="Adobe XMP Core 5.0-c06
1 64.140949, 2010/12/07-10:57:01 "> <rdf:RDF xmlns:rdf="h
ttp://VVV.w3.org/1999/02/22-rdf-syntax-ns#"> <rdf:Description rd
f:about="" xmlns:xmp="hXXp://ns.adobe.com/xap/1.0/" xmlns:xmpMM="http:
//ns.adobe.com/xap/1.0/mm/" xmlns:stRef="hXXp://ns.adobe.com/xap/1.0/s
Type/ResourceRef#" xmp:CreatorTool="Adobe Photoshop CS5.1 Windows" xmp
MM:InstanceID="xmp.iid:02967DEC099B11E388E0A65379C2936F" xmpMM:Documen
tID="xmp.did:02967DED099B11E388E0A65379C2936F"> <xmpMM:DerivedFr
om stRef:instanceID="xmp.iid:02967DEA099B11E388E0A65379C2936F" stRef:d
ocumentID="xmp.did:02967DEB099B11E388E0A65379C2936F"/> </rdf:Des
cription> </rdf:RDF> </x:xmpmeta> <?xpacket end="r"?
>....Adobe.d.......................................................
......................................................................
....................j.................................................
......................................!.1.AQ.aq".....2R...B#...r.3..b.
.c...S..C....$T.4Ds......................!1.AQ.......a.."2qR...B......
......?....\}6..1....D...au.lxW....~k.n^.....:q.a..HH.....&....Z.Ut...
3.Y.i.3(\x......Qe$.Eg...'...x._R_?........xQ..J..?.]QQ8../...~./...e?
........L]>..7.*|j.`71au.lxV.<.r...d. u.:t.1O.$$n...~.CMK.=z..|.
....i.i.3b.......AQe$.$P.U.OE%.=W.......m..n.......[.....N..#.....

<<< skipped >>>

GET /static/r07/counter017.js HTTP/1.1
Accept: */*
Referer: hXXp://VVV.ytddownloader.com/thankyou.html?isn=2A0E0F74E87C41248D17D84CDB01E7BE&stb=1&sds=1&shp=1&lang=1033&cid=31fbc1ce06e12d56d19c32273fd38c79&oldVer=&newVer=4.8.1&tov=19&kt=cnet&pv=0&mpb=1
Accept-Language: en-us
User-Agent: Mozilla/4.0 (compatible; MSIE 8.0; Windows NT 5.1; Trident/4.0; .NET CLR 2.0.50727; .NET CLR 3.0.04506.648; .NET CLR 3.5.21022; .NET4.0C; .NET CLR 3.0.4506.2152; .NET CLR 3.5.30729)
Accept-Encoding: gzip, deflate
Host: s7.addthis.com
Connection: Keep-Alive


HTTP/1.1 200 OK
Server: Apache
Last-Modified: Fri, 04 Apr 2014 15:05:40 GMT
Content-Encoding: gzip
Cache-Control: public, no-check, max-age=86313600
Content-Type: application/javascript
Content-Length: 3744
Accept-Ranges: bytes
Date: Tue, 13 May 2014 14:56:13 GMT
Via: 1.1 varnish
Age: 2731439
Connection: keep-alive
X-Served-By: cache-c100-CHI
X-Cache: HIT
X-Cache-Hits: 3193440
X-Timer: S1399992973.423447132,VS0,VE0
Vary: Host,Accept-Encoding
...........Z.s.6..Wd...<.....).D.8.#...:.}p=...$....a.....b..$;q...
...X.... ."....B.......s.....^...W7,s..[...B..7...|......aZA.t.#..s/.$
....v2. .a...S....(.=...p`...._.z..4..x..V........Kx.'a..1{WQ_.L2.Q].z
.0.8.3]3.X....^...........E.h. ....^.Xu7.fFs..jJ.32...D;[email protected].
....._%].{.&K....|.y.....f...W..]....`..P...{4.~~.j.%~....m.U...5.I...
.,..aL7.n}n&...AG.rAL..Z....n7;....n....E."........H3*....YM....v...16
..x.;...&..A.|.*dH.h..........L..m...%<....$k.f....)l.^.X....<3O
..&..a."..e.P}.......A}.n.).a;Z..h...?..(.......O...FN.w....r....57.(.
..B.b?.n..!....xH...~;.3..8.t`..=b..O..d...9.R.......Q...%......E..K.l
...F....sJ....._Gw..Z...&RMc..t..14i..T;.Y....g.....}..6..K...M.^.&.i.
....)..2...;....k2...B;........Q.5{\ .j...<.........4.h......7..w31
..1.=)...y..^..TDzT...._x.i..i..^7O"s...n.8...O..\eT{1..a....7.b...&.b
.7............n.h:..d....6...\......]. u#.._..8.,. =.X.!.;..(....-..ZE
.|.I._.....u.T!.o.e....7..!.....]..$0.v.._..pN...;Z.vd.F ........04.)O
.|.[..jm..:.?..^..^t*..... ..p.Mk.)/o;|;.F..M..........B.........G...9
.I.....{t..X.v..[`.p.<.......D.......k... ....3..I......V....m.....
...E. ..............?.."...I.\%|A..h...BR@....."M.E&i..!.....tT..@ T."
....M.$Q"JAmT2T.q....2G9F...|[email protected]=...y...V8j-..I.\"..lT'.., &....'X|4.
.9.82.....AV....)[r.P...;.Sw..f.B0[...n'wO... [email protected]~.<..
.L......$.=.E..,..2.<....y,K.yz.e.q...k....<[....'..^~1.<]. )
.5q.........( ......l0..s....T*n7....~.........i..:.,.p.M..'h....;...t
bW...1....)..'.!....L)......j:...D*o..(..,:....0(..^5..K..PK.S...,

<<< skipped >>>

GET /kits/sds/SearchProtectionSetup.exe HTTP/1.1
Accept-Encoding: gzip,deflate
User-Agent: WidgiToolbar
Host: webupdate.mybrowserbar.com
Connection: Keep-Alive
Cache-Control: no-cache


HTTP/1.1 200 OK
Server: nginx/0.7.65
Date: Tue, 13 May 2014 14:56:08 GMT
Content-Type: application/octet-stream
Content-Length: 2696352
Last-Modified: Mon, 28 Apr 2014 15:06:33 GMT
Connection: keep-alive
Accept-Ranges: bytes
MZ......................@.............................................
..!..L.!This program cannot be run in DOS mode....$.......<.ydx..7x
..7x..7_Hz7{..7_Hl7i..7x..7...7q..7s..7q..7y..7q..7y..7Richx..7.......
.................PE..L....l.K.................d.......B..K5...........
[email protected])................................
..............`..............8.).h....................................
........................................................text....c.....
..d.................. ..`.rdata...............h..............@[email protected]
[email protected].........................
......rsrc........`......................@..@.........................
......................................................................
......................................................................
......................................................................
......................................................................
...............................................U....\.}..t .}.F.E.u..H
......G..H.P.u..u..u...|[email protected][email protected]...
..@..}[email protected]... M..........M........E...FQ.....NU
..M.......M...VT..U........FP..E...............E.P.M...H.@..E..P.E..E.
[email protected]}[email protected].}.j.W.E......E.....
[email protected][email protected][email protected] [email protected].
u.....@._^3.[.....L$....G...i. @...T.....tUVW.q.3.;5..G.sD..i. @...D..
S.....t.G.....t...O..t .....u...3....3...F. @..;5..G.r.[_^...U..QQ

<<< skipped >>>

GET /en_US/all.js HTTP/1.1
Accept: */*
Referer: hXXp://VVV.ytddownloader.com/thankyou.html?isn=2A0E0F74E87C41248D17D84CDB01E7BE&stb=1&sds=1&shp=1&lang=1033&cid=31fbc1ce06e12d56d19c32273fd38c79&oldVer=&newVer=4.8.1&tov=19&kt=cnet&pv=0&mpb=1
Accept-Language: en-us
User-Agent: Mozilla/4.0 (compatible; MSIE 8.0; Windows NT 5.1; Trident/4.0; .NET CLR 2.0.50727; .NET CLR 3.0.04506.648; .NET CLR 3.5.21022; .NET4.0C; .NET CLR 3.0.4506.2152; .NET CLR 3.5.30729)
Accept-Encoding: gzip, deflate
Host: connect.facebook.net
Connection: Keep-Alive


HTTP/1.1 200 OK
ETag: "33e930b01622ce3f779fd0621f830a4b"
Content-Type: application/x-javascript; charset=utf-8
Timing-Allow-Origin: *
Content-Encoding: gzip
Content-MD5: gppApdvV6sdQwWHKaA5j1w==
X-FB-Debug: NuJ9AmBsD oxdDmDUfd17FeGhj6Xrv4K99arsh PH/Y=
Content-Length: 52964
Cache-Control: public, max-age=1200
Expires: Tue, 13 May 2014 15:16:12 GMT
Date: Tue, 13 May 2014 14:56:12 GMT
Connection: keep-alive
Vary: Accept-Encoding
............i{...7...O!;.)...l.*5.w.IO....''....$Z..R.%.......W.. E...
...........B.PU8.......O........O.=?~....O.*..8....y.........O.O.0n...
.......~....Tl..E....1...$.U>..:e!.....i..,.^8...a..4.....U...R..rT
o..`>.6.........'...XJ..?~z...........g...:.{.u....z].^,b..*.ne..W.
......_.D..K..I..MR]..T...h.&..D..!.S<.gW.8W@'z.q..6..S..f ....i...
.[.ME.........|.Q...y'...4.v..B..........,......].....T;..r..B....2.RA
dv.....?=.....N0v<G..../.`.u.....%..$......i2...yK..`...w.]T..A..r.
..%.p6_VC.U.vO........A..]2^....`.\W....a6KfU.'......S..*q2.t.0....(.{
....x.~....~.........8....7.F..y...C...h._E.q.....h..T...sw..R.J..9...
.,.F-I..@F]...PH.. ..qN...,[O...xv..cK....b<.....x\E.........tP..g.
~.t..lI.w:^V.o..0K....d...^n...7.../.arA...... ...R=5......w....i.=.rs
uw.......n......./.. wnu>.R...W.......,X.Y.......{.b.:^..yL.B&....I
0..3."{(..{(.E~.l.J..=...h2..(..T.. .!.....U..].`X...C?>.....@#.I.@
.*CS....*....l.\...G...R<..c........D.!..xsP .....T.n...N...9wj...9
..g...d../.a...........?..O}..=.c..<.E....ab.......sC.:M&./....v...
....6.........5..hM=R.......!C..^.[....Y...9..i..t...y....5......G..w.
.......u.. [email protected].?..h..*Y=...Q..}^......B.....>.%.wHK^....f..
...mH...4....{Q:....."5.....tj..N_..z.....K......|..}...8.H5C[jDs..G.L
.....Du&.$...2}....E....6..A.J2cQUo............x...........9.........h
n.W.G.K.j..=.g.?0.Y.f.."|}x..b..g.U....MY...........?......$.....T.^..
"[email protected]....}......?........&~..9~4.........f'%X..KC......0..jL..l.
...........b....y....w.^D.......x....K.;>..>.V.X...9Di...p.

<<< skipped >>>

GET /kits/hlp/exthelper.exe HTTP/1.0
Host: download.mybrowserbar.com
User-Agent: NSISDL/1.2 (Mozilla)
Accept: */*


HTTP/1.1 200 OK
Date: Tue, 13 May 2014 14:56:02 GMT
Server: Apache
Last-Modified: Wed, 30 Apr 2014 14:55:31 GMT
Accept-Ranges: bytes
Content-Length: 419176
Connection: close
Content-Type: application/x-msdos-program
MZ......................@.............................................
..!..L.!This program cannot be run in DOS mode....$...................
................................l.....................................
......Rich............................PE..L.....`S....................
.n......a.............@.................................:D....@.......
..........................L........ [email protected]......
............................ e..@.....................................
.......text...^........................... ..`.rdata..................
............@[email protected]....<[email protected]......
.. ......................@[email protected][email protected][email protected].
......................................................................
......................................................................
......................................................................
......................................................................
...............................................V.D$.P....D......D...^.
......D...E..V......D...E...D$..t.V.b<..Y..^[email protected].
..U...u..u..u..u...F...E....].U...u..u..u..u..qF...E....]....L$.......
D$............t....3.....L$. [email protected]../s.....u...C...e
...u..N.....D..........s.....V..j.j..N.....D...#....^..D...y$.r..A...A
..V........D$..t.V.^;..Y..^...V.t$....x.......D...^.......D......V....
..D.......D$..t.V..;..Y..^...j....D..nr.....u..2C...e...u..N....9E....
..... s.....V..j.j..N....9E..K"....^..C..V........D$..t.V..:..Y..^

<<< skipped >>>

GET /pca3-g5.crl HTTP/1.1
Accept: */*
User-Agent: Microsoft-CryptoAPI/5.131.2600.5512
Host: crl.verisign.com
Connection: Keep-Alive
Cache-Control: no-cache
Pragma: no-cache


HTTP/1.1 200 OK
Server: Apache
ETag: "895f8ccd92dfec674c94f0d04d1b63bc:1396128308"
Last-Modified: Sat, 29 Mar 2014 21:25:08 GMT
Accept-Ranges: bytes
Content-Length: 533
Date: Tue, 13 May 2014 14:57:00 GMT
Connection: keep-alive
Content-Type: application/pkix-crl
0...0..0...*.H........0..1.0...U....US1.0...U....VeriSign, Inc.1.0...U
....VeriSign Trust Network1:08..U...1(c) 2006 VeriSign, Inc. - For aut
horized use only1E0C..U...<VeriSign Class 3 Public Primary Certific
ation Authority - G5..140320000000Z..140630235959Z0...*.H.............
}...a.D[..8..i.....g8..S..tt..a.e.B]..v.l9.m.....~.G(l...G..#z{...Za..
F.q....2^X..w.i'.&..n...4v8. &|/Y.B..%..J..g0."k.0....A..7.)h...=5....
'Z........y.Ye.......M.._5.9..B.*.. [email protected]#...... UL.F......iDg..6...'
z$.E.E..*..g...2.@D.....&v...o..>..k1N...P...iHTTP/1.1 200 OK..Serv
er: Apache..ETag: "895f8ccd92dfec674c94f0d04d1b63bc:1396128308"..Last-
Modified: Sat, 29 Mar 2014 21:25:08 GMT..Accept-Ranges: bytes..Content
-Length: 533..Date: Tue, 13 May 2014 14:57:00 GMT..Connection: keep-al
ive..Content-Type: application/pkix-crl..0...0..0...*.H........0..1.0.
..U....US1.0...U....VeriSign, Inc.1.0...U....VeriSign Trust Network1:0
8..U...1(c) 2006 VeriSign, Inc. - For authorized use only1E0C..U...<
;VeriSign Class 3 Public Primary Certification Authority - G5..1403200
00000Z..140630235959Z0...*.H.............}...a.D[..8..i.....g8..S..tt.
.a.e.B]..v.l9.m.....~.G(l...G..#z{...Za..F.q....2^X..w.i'.&..n...4v8.
&|/Y.B..%..J..g0."k.0....A..7.)h...=5....'Z........y.Ye.......M.._5.9.
.B.*.. [email protected]#...... UL.F...

<<< skipped >>>

GET /kits/sds/update.xml HTTP/1.1
Accept-Encoding: gzip,deflate
User-Agent: WidgiToolbar
Connection: Keep-Alive
Cache-Control: no-cache
Host: VVV.mybrowserbar.com


HTTP/1.1 200 OK
Date: Tue, 13 May 2014 14:56:07 GMT
Server: Apache
Keep-Alive: timeout=30, max=100
Connection: Keep-Alive
Transfer-Encoding: chunked
Content-Type: text/xml; charset=utf-8
b9..<?xml version='1.0' encoding='UTF-8'?>.<SearchProtection&
gt;. <updatecheck path='hXXp://webupdate.mybrowserbar.com/kits/s
ds/SearchProtectionSetup.exe' ccv='179' />. </SearchProtection&g
t;...0..HTTP/1.1 200 OK..Date: Tue, 13 May 2014 14:56:07 GMT..Server:
Apache..Keep-Alive: timeout=30, max=100..Connection: Keep-Alive..Trans
fer-Encoding: chunked..Content-Type: text/xml; charset=utf-8..b9..<
?xml version='1.0' encoding='UTF-8'?>.<SearchProtection>.
<updatecheck path='hXXp://webupdate.mybrowserbar.com/kits/sds/Searc
hProtectionSetup.exe' ccv='179' />. </SearchProtection>...0..


GET /CSC3-2010.cer HTTP/1.1
Accept: */*
User-Agent: Microsoft-CryptoAPI/5.131.2600.5512
Host: csc3-2010-aia.verisign.com
Connection: Keep-Alive


HTTP/1.1 200 OK
Server: Apache
ETag: "4df6e0fc400cae9c052fae98c66d379f:1367386211"
Last-Modified: Wed, 01 May 2013 05:30:11 GMT
Accept-Ranges: bytes
Content-Length: 1550
Content-Type: text/plain
Date: Tue, 13 May 2014 14:57:00 GMT
Connection: keep-alive
0...0..........R...%V.......K3.0...*.H........0..1.0...U....US1.0...U.
...VeriSign, Inc.1.0...U....VeriSign Trust Network1:08..U...1(c) 2006
VeriSign, Inc. - For authorized use only1E0C..U...<VeriSign Class 3
Public Primary Certification Authority - G50...100208000000Z..2002072
35959Z0..1.0...U....US1.0...U....VeriSign, Inc.1.0...U....VeriSign Tru
st Network1;09..U...2Terms of use at hXXps://VVV.verisign.com/rpa (c)1
01.0,..U...%VeriSign Class 3 Code Signing 2010 CA0.."0...*.H..........
...0.........#K^....2..W....&~......}..6k..u.0..h.. u......i..7..{....
.7M_.;......'5.%.8..c.........jb.L.!......;.*O.[..O..v..'.|..~}......H
.i...<<A.>......q.U...&J@<..&...m...%{..?../....w..V.z;T0S
..b4....Z.(..L.N~[.........u....G...r..4....L~..O.=W.0..6...v.....~4-.
.........0...0...U.......0.......0p..U. .i0g0e..`.H...E....0V0(.. ....
.....hXXps://VVV.verisign.com/cps0*.. .......0...hXXps://VVV.verisign.
com/rpa0...U...........0m.. ........a0_.].[0Y0W0U..image/gif0!0.0... .
.............k...j.H.,{..0%.#hXXp://logo.verisign.com/vslogo.gif04..U.
..-0 0).'.%.#hXXp://crl.verisign.com/pca3-g5.crl04.. ........(0&0$.. .
....0...hXXp://ocsp.verisign.com0...U.%..0... ......... .......0(..U..
.!0...0.1.0...U....VeriSignMPKI-2-80...U..........{&.K......&.....0...
U.#..0.....e......0..C9...3130...*.H.............V".4..a.H...V.d......
....z."..G8J-l..q.|.p...O...S..^.t.I$..&...G.Lc...4..E...&s....dm.q..E
.`.YQ9.X.k....yk..Ar.7"...#.?D...a....\.=...B=e6..=@(....#&.K ...].L4.
<..7.o. .4.&.........!.3o..X.%|t.X.u.c?.1|......Sv.[........].!

<<< skipped >>>

GET /b?c1=7&c2=2000001&c3=1&rn=ymtqsy&c7=http://VVV.ytddownloader.com/thankyou.html&c8=YTD Video Converter&cv=1.7 HTTP/1.1
Accept: */*
Referer: hXXp://s7.addthis.com/static/r07/sh158.html
Accept-Language: en-us
User-Agent: Mozilla/4.0 (compatible; MSIE 8.0; Windows NT 5.1; Trident/4.0; .NET CLR 2.0.50727; .NET CLR 3.0.04506.648; .NET CLR 3.5.21022; .NET4.0C; .NET CLR 3.0.4506.2152; .NET CLR 3.5.30729)
Accept-Encoding: gzip, deflate
Host: b.scorecardresearch.com
Connection: Keep-Alive
Cookie: UID=dc7262f-206.167.78.17-1360768137; UIDR=1360768137


HTTP/1.1 204 No Content
Content-Length: 0
Date: Tue, 13 May 2014 14:56:15 GMT
Connection: keep-alive
Set-Cookie: UID=dc7262f-206.167.78.17-1360768137; expires=Mon, 02-May-2016 14:56:15 GMT; path=/; domain=.scorecardresearch.com
Set-Cookie: UIDR=1399992975; expires=Mon, 02-May-2016 14:56:15 GMT; path=/; domain=.scorecardresearch.com
P3P: policyref="/w3c/p3p.xml", CP="NOI DSP COR NID OUR IND COM STA OTC"
Pragma: no-cache
Expires: Mon, 01 Jan 1990 00:00:00 GMT
Cache-Control: private, no-cache, no-cache=Set-Cookie, no-store, proxy-revalidate
HTTP/1.1 204 No Content..Content-Length: 0..Date: Tue, 13 May 2014 14:
56:15 GMT..Connection: keep-alive..Set-Cookie: UID=dc7262f-206.167.78.
17-1360768137; expires=Mon, 02-May-2016 14:56:15 GMT; path=/; domain=.
scorecardresearch.com..Set-Cookie: UIDR=1399992975; expires=Mon, 02-Ma
y-2016 14:56:15 GMT; path=/; domain=.scorecardresearch.com..P3P: polic
yref="/w3c/p3p.xml", CP="NOI DSP COR NID OUR IND COM STA OTC"..Pragma:
no-cache..Expires: Mon, 01 Jan 1990 00:00:00 GMT..Cache-Control: priv
ate, no-cache, no-cache=Set-Cookie, no-store, proxy-revalidate..


GET /live/red_lojson/300lo.json?19rgc5c&colc=1399992973025&si=5372328b6586c44f&uid=5372328cfdb7168d&pub=ytdcs&rev=1399981304&jsl=33&ln=en&pc=men&vpc=&dp=VVV.ytddownloader.com&aa=0&fcu1=667ae1ee&undefined&of=0&uf=1&pd=0&irt=0&md=0&ct=1&tct=0&abt=0<=782&cdn=0&lnlc=us&whcs=1&tl=c=1312,m=1312,i=1312,xm=2094,xp=2094&pi=1&fp=thankyou.html&&rb=0&gen=1000&gen=100&callback=_ate.track.hsr&chr=windows-1252 HTTP/1.1
Accept: */*
Referer: hXXp://s7.addthis.com/static/r07/sh158.html
Accept-Language: en-us
User-Agent: Mozilla/4.0 (compatible; MSIE 8.0; Windows NT 5.1; Trident/4.0; .NET CLR 2.0.50727; .NET CLR 3.0.04506.648; .NET CLR 3.5.21022; .NET4.0C; .NET CLR 3.0.4506.2152; .NET CLR 3.5.30729)
Accept-Encoding: gzip, deflate
Host: m.addthis.com
Connection: Keep-Alive
Cookie: uid=5372328cfdb7168d; uvc=1|20; uit=1


HTTP/1.1 200 OK
Date: Tue, 13 May 2014 14:56:14 GMT
Cache-Control: max-age=0, no-cache, no-store
Pragma: no-cache
Set-Cookie: di2=N5IPHQ.UYM~KSU;Path=/;Domain=.addthis.com;Expires=Thu, 12-May-2016 14:56:14 GMT
Set-Cookie: bt=;Path=/;Domain=.addthis.com;Expires=Thu, 01-Jan-1970 00:00:00 GMT
Set-Cookie: dt=X;Path=/;Domain=.addthis.com;Expires=Thu, 12-Jun-2014 14:56:14 GMT
Expires: Thu, 01 Jan 1970 00:00:00 GMT
P3P: policyref="/w3c/p3p.xml", CP="NON ADM OUR DEV IND COM STA"
Content-Type: application/javascript;charset=UTF-8
Content-Encoding: gzip
Connection: close
...........O,I. )JL...(...V*NM.M. )V....Q*-...r.....|]..}]...C..BC} }.
B.}C........nk.T.i..#F.][.....


GET /ga.js HTTP/1.1
Accept: */*
Referer: hXXp://VVV.ytddownloader.com/thankyou.html?isn=2A0E0F74E87C41248D17D84CDB01E7BE&stb=1&sds=1&shp=1&lang=1033&cid=31fbc1ce06e12d56d19c32273fd38c79&oldVer=&newVer=4.8.1&tov=19&kt=cnet&pv=0&mpb=1
Accept-Language: en-us
User-Agent: Mozilla/4.0 (compatible; MSIE 8.0; Windows NT 5.1; Trident/4.0; .NET CLR 2.0.50727; .NET CLR 3.0.04506.648; .NET CLR 3.5.21022; .NET4.0C; .NET CLR 3.0.4506.2152; .NET CLR 3.5.30729)
Accept-Encoding: gzip, deflate
Host: VVV.google-analytics.com
Connection: Keep-Alive


HTTP/1.1 200 OK
Date: Tue, 13 May 2014 10:54:59 GMT
Expires: Tue, 13 May 2014 22:54:59 GMT
Last-Modified: Mon, 28 Apr 2014 22:33:43 GMT
X-Content-Type-Options: nosniff
Content-Type: text/javascript
Vary: Accept-Encoding
Content-Encoding: gzip
Server: Golfe2
Content-Length: 15798
Cache-Control: public, max-age=43200
Age: 14473
Alternate-Protocol: 80:quic
...........}kw.:............Io@R...........,Y..4..N/......$[NR.s.Y....
.....h43v..@.....~...*....a$.|>>..G....,... ..:...<Hdz....$e.
.:........^1..H....BV...Y....t2..r.8..y...,...(r<...8W|....%DX.&..g
4I.......$u.5..^GH...g,G=.....x.. .........W|.............. ...c......
.2F.........%O.QO.....#.z.B..UtX;p....6...!V...9<K..A.awP'9hc.{H>
;....a...,..../:....Q.^.2H.}.pt:..x.c.A...CL...)4..........1.A.Y.od.}.
....j,....f.&......Q...........w.8........~x'..<.*...`_.^r..>t!$
.j....q..N....V...M.).4` .r.......O..(.L..@. .>..v.C ......VJ._[[.
.......~"..e...7-..C..y.*.K.I....Y.2!.R.a..i^R...-q..LG......:8.?.?.?R
....>o....{<....[..!2o....V.....b..q7kE...'....n?.~...../..A4...
.vL3[.._....q.......].JG..\.......q....w.YV1..>..`..Q.cC.`..0...\u.
:.'.....L.$.1.\O.7n..7.=.O.r'..d.,.y..Kh..,.J.<..na...$..b.X....T..
y>OS.....Vxu...e......e.e.x ..[..K.d.D..*....1..Nm."x...I..e.......
....>....\c......J..&c..J.;@...Q.....j...<......y..J...#>....
.>........t.....Y>[email protected].....(.......$\.R.......wz
.I.......6..:A>..g..[..o../..M'.....y.6*..]H.5`i*...Q..O.%4T ...;..
...#J.........xkk.&..^N../[......As.E....W....5.*MG....z......6.w.....
.p..['Bg.~T..2....U..@@.`.u..T...Z.................Z....|.F.........M.
&...k._v]T.M..,/....4.$.8..X.`...qm-\[.q..C..l...I|>>UJ.}.k.4.".
.. e...v.......&.....jSm.....RH..m.9..si|kP .xVQ......-.V.v..j..z6.`\!
.`.6`c73..2....y.......p...l..._..=o......k....<v ..'.bX7.e..R9....
.Ym5..e.PE.zA.....y.. ...B"R...Qy.....g7..hp...fK./...O.c.,R....^3

<<< skipped >>>

GET /__utm.gif?utmwv=5.5.0&utms=1&utmn=211728539&utmhn=VVV.ytddownloader.com&utmcs=windows-1252&utmsr=1716x901&utmvp=1712x716&utmsc=32-bit&utmul=en-us&utmje=1&utmfl=11.6 r602&utmdt=YTD Video Converter&utmhid=2112539694&utmr=-&utmp=/thankyou.html?isn=2A0E0F74E87C41248D17D84CDB01E7BE&stb=1&sds=1&shp=1&lang=1033&cid=31fbc1ce06e12d56d19c32273fd38c79&oldVer=&newVer=4.8.1&tov=19&kt=cnet&pv=0&mpb=1&utmht=1399992971790&utmac=UA-25210420-2&utmcc=__utma=135583929.1101086425.1399992972.1399992972.1399992972.1;+__utmz=135583929.1399992972.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none);&utmu=q~ HTTP/1.1

Accept: */*
Referer: hXXp://VVV.ytddownloader.com/thankyou.html?isn=2A0E0F74E87C41248D17D84CDB01E7BE&stb=1&sds=1&shp=1&lang=1033&cid=31fbc1ce06e12d56d19c32273fd38c79&oldVer=&newVer=4.8.1&tov=19&kt=cnet&pv=0&mpb=1
Accept-Language: en-us
User-Agent: Mozilla/4.0 (compatible; MSIE 8.0; Windows NT 5.1; Trident/4.0; .NET CLR 2.0.50727; .NET CLR 3.0.04506.648; .NET CLR 3.5.21022; .NET4.0C; .NET CLR 3.0.4506.2152; .NET CLR 3.5.30729)
Accept-Encoding: gzip, deflate
Host: VVV.google-analytics.com
Connection: Keep-Alive


HTTP/1.1 200 OK
Pragma: no-cache
Expires: Wed, 19 Apr 2000 11:43:00 GMT
Last-Modified: Wed, 21 Jan 2004 19:51:30 GMT
X-Content-Type-Options: nosniff
Content-Type: image/gif
Date: Thu, 08 May 2014 11:48:04 GMT
Server: Golfe2
Content-Length: 35
Cache-Control: private, no-cache, no-cache=Set-Cookie, proxy-revalidate
Age: 443288
Alternate-Protocol: 80:quic
GIF89a.............,...........D..;HTTP/1.1 200 OK..Pragma: no-cache..
Expires: Wed, 19 Apr 2000 11:43:00 GMT..Last-Modified: Wed, 21 Jan 200
4 19:51:30 GMT..X-Content-Type-Options: nosniff..Content-Type: image/g
if..Date: Thu, 08 May 2014 11:48:04 GMT..Server: Golfe2..Content-Lengt
h: 35..Cache-Control: private, no-cache, no-cache=Set-Cookie, proxy-re
validate..Age: 443288..Alternate-Protocol: 80:quic..GIF89a............
.,...........D..;..


GET /connect/xd_arbiter/dgdTycPTSRj.js?version=41 HTTP/1.1
Accept: image/gif, image/jpeg, image/pjpeg, image/pjpeg, application/x-shockwave-flash, application/x-ms-application, application/x-ms-xbap, application/vnd.ms-xpsdocument, application/xaml xml, */*
Referer: hXXp://VVV.ytddownloader.com/thankyou.html?isn=2A0E0F74E87C41248D17D84CDB01E7BE&stb=1&sds=1&shp=1&lang=1033&cid=31fbc1ce06e12d56d19c32273fd38c79&oldVer=&newVer=4.8.1&tov=19&kt=cnet&pv=0&mpb=1
Accept-Language: en-us
User-Agent: Mozilla/4.0 (compatible; MSIE 8.0; Windows NT 5.1; Trident/4.0; .NET CLR 2.0.50727; .NET CLR 3.0.04506.648; .NET CLR 3.5.21022; .NET4.0C; .NET CLR 3.0.4506.2152; .NET CLR 3.5.30729)
Accept-Encoding: gzip, deflate
Host: static.ak.facebook.com
Connection: Keep-Alive


HTTP/1.1 200 OK
Content-Type: text/html; charset=utf-8
X-Content-Type-Options: nosniff
X-XSS-Protection: 0
Content-Encoding: gzip
X-FB-Debug: 2hkGn4rW8ep5ogm3K8NQerpkNF4BcCL6MAYruQmbjFc=
Vary: Accept-Encoding
Content-Length: 8774
Cache-Control: public, max-age=31036242
Expires: Thu, 07 May 2015 20:06:56 GMT
Date: Tue, 13 May 2014 14:56:14 GMT
Connection: keep-alive
...........|i..F..w....]@..Q:.-..jdY.hF.H...$]O.H. A...W.....y........
..".gdDd....^_.......xi..,..V.9.o..0... ..a.L..i.e.....c.-.26.....h...
.l}..}.......4..7..x...../{S...a.^2..V8r...).4.L|..7:Z.^.&...6..".....
...<M.$..y3O>.)...X.ACJ.^".Yb....w.s...v.R.....CU..X........._.z
..w8.rZ.]X...T|mw.<.........\..D>6.3...7...qE~x...9..$u.#.f06...
...dRI.......a...-...dd.....I........../..&']d...h..Y3..8...b 1.......
a....[[email protected])...EP...S....qjA0.K...L......^....a......g0..c.j
B{..A.1.......5.S....4..,@F...&g...<......K.2W[@..J1V.. .V!.2.5..u\
e.....(.6...7t..........y..gV.%3NN..O.....j*.<..0......)?X.$....h..
...u...t,h....A.;..vy).m4.h.4i......#...%1...k.W...i......."_.j.C.bD..
K&.'.NiM.iiv..[..l..`zk.S......nnn.....\.....'.a.X8.... .Pa]ga..._..].
...4.....3n.FX....t.F... sG`....^0..._ek...w.......R.M.y.......bV.. Yn
(.2..F..;..GHsH....X~.....1...b..e.W..4...._...Y..O.Rc.=]..b...8......
....*]O-..(xd!Cf.|c1............E..E.n.~f.E9|..AN.P...DF.e...i4......)
..E.3.y3NVD?P....8 V;.9...p.O..2...ww?....;j~...r.Wj,C.C0..Ly.j..Gv|..
.?...l....[h..o.H<..P.....o.B..>....2w.H.9..M...zy)....r.{H.....
...h.\..b.......{,w.."`.........~...m.1...0Y.~..;C.|..6c.i;...\b......
.....C.i.x..}....O...=.......k.y{.....^n.|b...br}....v}...$..*T...8|us
oO.)...$.^..s......$D.3.._?.x....s.8.n7.:s...I..Pqu.N*?T|>...d.f..s
8\./r~.........v'....*.:Z...l......$.,[email protected].?......v.!>...
..G..._.O......v.k....}.7.....c[|........FX...Ak...&..k.5N............
..}......!....]......c....H<..1..)<..S.....>......y......

<<< skipped >>>

GET /getcountry.html HTTP/1.0
Host: VVV.youtubedownloadersite.com
User-Agent: NSISDL/1.2 (Mozilla)
Accept: */*


HTTP/1.1 200 OK
Server: nginx
Date: Tue, 13 May 2014 14:55:45 GMT
Content-Type: text/html; charset=utf-8
Content-Length: 2
Connection: close
X-Powered-By: PHP/5.3.10-1ubuntu3.11
CA..


GET /ajax/libs/jquery/1.9.1/jquery.min.js HTTP/1.1
Accept: */*
Referer: hXXp://VVV.ytddownloader.com/thankyou.html?isn=2A0E0F74E87C41248D17D84CDB01E7BE&stb=1&sds=1&shp=1&lang=1033&cid=31fbc1ce06e12d56d19c32273fd38c79&oldVer=&newVer=4.8.1&tov=19&kt=cnet&pv=0&mpb=1
Accept-Language: en-us
User-Agent: Mozilla/4.0 (compatible; MSIE 8.0; Windows NT 5.1; Trident/4.0; .NET CLR 2.0.50727; .NET CLR 3.0.04506.648; .NET CLR 3.5.21022; .NET4.0C; .NET CLR 3.0.4506.2152; .NET CLR 3.5.30729)
Accept-Encoding: gzip, deflate
Host: ajax.googleapis.com
Connection: Keep-Alive


HTTP/1.1 200 OK
Vary: Accept-Encoding
Content-Encoding: gzip
Content-Type: text/javascript; charset=UTF-8
Last-Modified: Fri, 08 Feb 2013 15:35:10 GMT
Date: Thu, 08 May 2014 22:29:52 GMT
Expires: Fri, 08 May 2015 22:29:52 GMT
Access-Control-Allow-Origin: *
Timing-Allow-Origin: *
X-Content-Type-Options: nosniff
Server: sffe
Content-Length: 32819
X-XSS-Protection: 1; mode=block
Cache-Control: public, max-age=31536000
Age: 404779
Alternate-Protocol: 80:quic
............{{...7...."........o...v..q.[cg'-E..HPBL....RD....[kf0.Pq.
~.sNZ.....f......._..M...wg.?...vG.<8z2.........E...q...:z..GT.._.f
.....t.de.....uT..b.|.o6iv..._E..:.F.x...O..6..*?QUp....2U.4..6I.<.
T.%.E>....R1....4^..tIm...ZE.{5..3..<.....|4.3.D-.r.-o..]......4
[$....:Z...UUP_...........|....z.mF.r...f......Q..?..-3.0..F..^.F....l
.O........\..f.|1..t..NG2U.}tz.jxz.^G.o......./^\.>......#*........
../.../........|zp2{...N.3*....~.\../O'...g...g.;.~.M.Tx..,g.....).y..
w*@...i.^...]........2 ..n;.\.'..'/f....*.4:..oP...f..]Ul..2^.....V...
.....V.P.N....z......o3z.........aC..,.....K.\p...x......WiY%YR.v.*..^
.......<_oVI..a>*.xq....$8>....u%......n ..V?.Q.:..4....o.~.g
..Q...S_..Y.....G)..T.".......<......&...*..Z.t%[email protected].
h...X.*/. .H.....){4U.y...I`..&-.. y.....L.O....Lf..X<..1M.w.xD;;..
...3zgn...'S.....g.~3Jn.9-..... .....3..A..e#.....".-i.S..].9..3..=GE.
.,..R*.gs..j.M..0.._'.u......E.|.....K.Q'FY.H^..'.(.OK.\.-.T...8...Q..
..v||5J..Vq.}{.K2..K..z.R....o_..G..t.L....NF.W.}....."{.NLP|.T_......
..j..,P..q.Q..o..<.x...Q..t=..$nJ.%:S...,..N...*.......d.`....M...)
....T.7....|$...[......E..h.......`b.......iQ.w...-n>.=OIw..*......
..H...r.....h..V.Aj..&t..9M..is.j.t]~../...ik......l.p.....mT.=[E..7v.
...n./$...y=T.X.s...J......j.w.W.|.x..F..*..:....>K...d....f.......
...&...7./.2-..P......j.?X.p.....9u.Ae.0...D.....~f.......&...l6..3...
...i}.(.. m.Je.x...p5.:..d...gWz...G..@.*\.2/*..............>...g..
`...w....f.....\.D...#D...E.%.......G..s`K.*.WI...NI.......LeO...&

<<< skipped >>>

GET /MyPCBackup_Setup.exe HTTP/1.0
Host: cdn.mypcbackup.com
User-Agent: NSISDL/1.2 (Mozilla)
Accept: */*


HTTP/1.1 200 OK
Date: Tue, 13 May 2014 14:56:03 GMT
Content-Type: application/octet-stream
Content-Length: 10372136
Connection: close
x-amz-id-2: vjvfhdOeVxSF9l9YzS4wi6bl pSErTlALS/vawNFGydNHWGR0LsBHpVN7xbbNMfH
x-amz-request-id: 2B7D0872DDF1FC56
Last-Modified: Mon, 17 Mar 2014 11:20:28 GMT
ETag: "45922155c9628e11441aa869c6287bb7"
Server: NetDNA-cache/2.2
X-Cache: HIT
MZ......................@.............................................
..!..L.!This program cannot be run in DOS mode....$.......1..:u..iu..i
u..i...iw..iu..i...i...id..i!..i...i...it..iRichu..i..................
......PE..L......K.................^...........0.......p....@.........
.................................................................t....
......(m...........1..@...............................................
.............p...............................text...L\.......^........
.......... ..`.rdata.......p.......b..............@[email protected]\......
.....v..............@....ndata...................................rsrc.
..(m.......n...z..............@..@....................................
......................................................................
......................................................................
......................................................................
......................................................................
............................................U....\.}..t .}.F.E.u..H...
[email protected]@..e...E..E.P.u...Pr@
..}[email protected]... M.......M....3.....FQ.....NU..M.....
.....VT..U.....FP..E...............E.P.M...Hp@[email protected]
....E..9}[email protected].}[email protected]..
[email protected]@.W...E..E.h ...Pj.h`[email protected]...\r@._^3.
[.....L$....B...Si.....VW.T.....tO.q.3.;5..B.sB..i......D.......t.G...
..t...O..t .....u...3....3...F.....;5..B.r._^[...U..QQ.U.SV..i....

<<< skipped >>>

GET /images/pixel.gif?action=install&point=finish&cid=31fbc1ce06e12d56d19c32273fd38c79&isn=2A0E0F74E87C41248D17D84CDB01E7BE&kt=cnet HTTP/1.0
Host: VVV.youtubedownloadersite.com
User-Agent: NSISDL/1.2 (Mozilla)
Accept: */*


HTTP/1.1 200 OK
Server: nginx
Date: Tue, 13 May 2014 14:56:09 GMT
Content-Type: image/gif
Content-Length: 1093
Last-Modified: Wed, 20 Feb 2013 14:38:31 GMT
Connection: close
Accept-Ranges: bytes
GIF89a.............!..XMP DataXMP<?xpacket begin="..." id="W5M0MpCe
hiHzreSzNTczkc9d"?> <x:xmpmeta xmlns:x="adobe:ns:meta/" x:xmptk=
"Adobe XMP Core 5.0-c060 61.134777, 2010/02/12-17:32:00 "> &
lt;rdf:RDF xmlns:rdf="hXXp://VVV.w3.org/1999/02/22-rdf-syntax-ns#">
<rdf:Description rdf:about="" xmlns:xmp="hXXp://ns.adobe.com/xap/1
.0/" xmlns:xmpMM="hXXp://ns.adobe.com/xap/1.0/mm/" xmlns:stRef="http:/
/ns.adobe.com/xap/1.0/sType/ResourceRef#" xmp:CreatorTool="Adobe Photo
shop CS5 Windows" xmpMM:InstanceID="xmp.iid:68AF816F211411E187C8D4C48A
462294" xmpMM:DocumentID="xmp.did:68AF8170211411E187C8D4C48A462294">
; <xmpMM:DerivedFrom stRef:instanceID="xmp.iid:68AF816D211411E187C8
D4C48A462294" stRef:documentID="xmp.did:68AF816E211411E187C8D4C48A4622
94"/> </rdf:Description> </rdf:RDF> </x:xmpmeta>
<?xpacket end="r"?>.............................................
......................................................................
...............~}|{zyxwvutsrqponmlkjihgfedcba`_^]\[ZYXWVUTSRQPONMLKJIH
GFEDCBA@?>=<;:9876543210/.-, *)('&%$#"! ........................
.........!.......,...........D..;..


GET /terms_extensions.rtf HTTP/1.0
Host: VVV.mybrowserbar.com
User-Agent: NSISDL/1.2 (Mozilla)
Accept: */*


HTTP/1.1 200 OK
Date: Tue, 13 May 2014 14:55:49 GMT
Server: Apache
Vary: Host
Last-Modified: Thu, 27 Mar 2014 12:09:30 GMT
Accept-Ranges: bytes
Content-Length: 43087
Connection: close
Content-Type: application/rtf
{\rtf1\ansi\ansicpg1252\deff0\deflang1033\deflangfe1033{\fonttbl{\f0\f
swiss\fprq2\fcharset0 Microsoft Sans Serif;}{\f1\fswiss\fprq2\fcharset
0 Arial;}}..{\colortbl ;\red0\green0\blue255;\red51\green51\blue51;}..
{\*\generator Msftedit 5.41.21.2510;}\viewkind4\uc1\pard\sb100\sa100\l
ang9\f0\fs17 The Spigot Terms of Use applies to the Browser Extensions
(which includes Browser Extensions in Google Chrome/Internet Explorer
, Amazon Shopping Helper in Google Chrome and Mozilla Firefox, Slick S
avings/Browser Error Assistant/eBay Shopping Assistant in Mozilla Fire
fox) and Search Protection ("Program"), which is built and maintained
by Spigot, Inc. ("We," \ldblquote our,\rdblquote or \ldblquote us,\rd
blquote whether in uppercase, lowercase, or a combination). The Progr
am allows you a convenient way to help find search results online by c
ollecting your requests for information and processing them through ou
r search engine partners. Our partners may compensate us for making th
is information available to you. Use of the Program is free of charge
to you. Use of the Program and its features as described below require
s that you agree to the following Terms of Use (the \ldblquote Terms\r
dblquote ). You agree to be legally bound by these Terms clicking the
\ldblquote I Agree,\rdblquote "Next", "Run", "Install" or "Yes" butto
n provided. These Terms are a legal contract between Us and You, an i
ndividual user of at least 18 years of age, or if You are using the Pr
ogram on behalf of any entity -- including a company, organization

<<< skipped >>>

GET /kits/sds/update.xml HTTP/1.1
Accept-Encoding: gzip,deflate
User-Agent: WidgiToolbar
Host: update.mybrowserbar.com
Connection: Keep-Alive
Cache-Control: no-cache


HTTP/1.1 301 Moved Permanently
Server: nginx/0.7.65
Date: Tue, 13 May 2014 14:56:07 GMT
Content-Type: text/html
Content-Length: 185
Connection: keep-alive
Location: hXXp://VVV.mybrowserbar.com/kits/sds/update.xml
<html>..<head><title>301 Moved Permanently</title
></head>..<body bgcolor="white">..<center><h1&
gt;301 Moved Permanently</h1></center>..<hr><cent
er>nginx/0.7.65</center>..</body>..</html>..HTTP/
1.1 301 Moved Permanently..Server: nginx/0.7.65..Date: Tue, 13 May 201
4 14:56:07 GMT..Content-Type: text/html..Content-Length: 185..Connecti
on: keep-alive..Location: hXXp://VVV.mybrowserbar.com/kits/sds/update.
xml..<html>..<head><title>301 Moved Permanently</
title></head>..<body bgcolor="white">..<center>&l
t;h1>301 Moved Permanently</h1></center>..<hr><
;center>nginx/0.7.65</center>..</body>..</html>..
..


GET /favicon.ico HTTP/1.1
Accept: */*
Accept-Encoding: gzip, deflate
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 5.1; Trident/4.0; .NET CLR 2.0.50727; .NET CLR 3.0.04506.648; .NET CLR 3.5.21022; .NET4.0C; .NET CLR 3.0.4506.2152; .NET CLR 3.5.30729)
Host: VVV.yahoo.com
Connection: Keep-Alive


HTTP/1.1 200 OK
Accept-Ranges: bytes
Cache-Control: private
Content-Length: 5430
Content-Type: image/x-icon
Date: Mon, 12 May 2014 22:01:05 GMT
ETag: "YM:1:f780dd7f-efc3-47de-80fa-55026f0e0c600004f93b1285b677"
Expires: Tue, 13 May 2014 23:00:01 GMT
Last-Modified: Mon, 12 May 2014 22:00:15 GMT
Server: ATS
x-ysws-request-id: f0a10362-e960-4192-8a18-8e68dc193574
x-ysws-visited-replicas: gops.usw26.mobstor.vip.gq1.yahoo.com
Age: 60923
X-Cache: HIT from logo7.global.media.ne1.yahoo.com
X-Cache-Lookup: HIT from logo7.global.media.ne1.yahoo.com:80
Via: HTTP/1.1 web3.usw26.mobstor.gq1.yahoo.com UserFiberFramework/1.0, 1.0 logo7.global.media.ne1.yahoo.com:80 (squid/2.7.STABLE9), http/1.0 l7.ycs.che.yahoo.com (ApacheTrafficServer/4.0.2), http/1.1 ir2.fp.bf1.yahoo.com (ApacheTrafficServer/4.0.2)
Connection: keep-alive
......  .... .....&......... .h.......(... ...@..... .................
..........;.p.5.o.6.o.6Dd.0...........................................
..............................................d.0.o.6Do.6.o.4...;...;.
p.3.o.3.n.3.q.3.n.3.r.7.n.5.o.6up.8Pn.7)i.2...........................
......m.3.n.6*q.8Po.7tn.5.n.4.n.3.q.3.n.3.n.3.p.3...;...;.q.3.s.4.s.4.
v.5.q.4.r.4.q.4.q.4.q.5.q.5.q.5.q.4.p.4.r.5.p.4.q.4.q.4.q.5.q.4.r.5.q.
5.q.5.q.5.q.4.q.3.r.4.u.5.s.4.r.3.p.3...;...;.t.5.w.5.v.5.y.6.u.5.w.6.
x.7.x.7.w.7.x.8.y.8.y.9.z.9.z.9.v.7.w.9.y.9.z.9.v.8.v.7.v.8.v.7.v.6.v.
6.v.6.z.7.x.6.v.5.t.5.r.3...;...;.u.5.x.6.{.7.y.6.y.7.z.8.|.8.}.9...;.
..<...<.~.<...<...<.{.:.|.;.}.;.z.:.{.:.|.:.z.:.{.:.{.9
.{.9...:.{.8.|.8.w.6.t.5.t.5...;...;.v.5.z.7...9.}.8.}.9...9...;...;..
.<...=...=...>...>...?...=...>...>...>...>...>
...>...<...<...;...<...<.|.8.~.8.y.6.t.5...;...;.w.5...
9...;...;...;...;...<...>...>[email protected]................
[email protected]...?...>...>...>...>...=...;...<.}.8.v.5...
;...;.z.7...:...<...<...>...?...?...A...A...B...C...C...D....
...............D...C...B...C...C...B...B...?...>...>...<.}.8.
z.7...;...;...9...<...?...>[email protected].
..................G...F...G...F...E...D...D...B...A...A...>...<.
z.8...;...;...8...=...A...A...A...B...D...D...F...F...F...H...H.......
............H...H...H...G...G...F...E...D...B...A...A...<.z.8...;..
.;...;...?...C...D...C...D...F...G...H...I...J...J...K............

<<< skipped >>>

GET /update/wt/ie/coupons/update.xml HTTP/1.1
User-Agent: MS IE Coupons addon
Host: update.mybrowserbar.com
Accept: */*


HTTP/1.1 200 OK
Server: nginx/0.7.65
Date: Tue, 13 May 2014 14:56:29 GMT
Content-Type: text/xml
Content-Length: 217
Last-Modified: Tue, 21 May 2013 11:38:18 GMT
Connection: keep-alive
Accept-Ranges: bytes
<?xml version='1.0' encoding='UTF-8'?>..<cpupdate>...<l
ibid>{40C6AC97-5316-4D22-BA61-3BF0D585FB22}</libid>...<url
>hXXp://update.mybrowserbar.com/update/wt/ie/coupons/coupons_1.0.zi
p</url>...<ver>1.0</ver>..</cpupdate>..


GET /url/shares.json?url=http://VVV.ytddownloader.com/&callback=_ate.cbs.sc_httpwwwytddownloadercom0 HTTP/1.1
Accept: */*
Referer: hXXp://VVV.ytddownloader.com/thankyou.html?isn=2A0E0F74E87C41248D17D84CDB01E7BE&stb=1&sds=1&shp=1&lang=1033&cid=31fbc1ce06e12d56d19c32273fd38c79&oldVer=&newVer=4.8.1&tov=19&kt=cnet&pv=0&mpb=1
Accept-Language: en-us
User-Agent: Mozilla/4.0 (compatible; MSIE 8.0; Windows NT 5.1; Trident/4.0; .NET CLR 2.0.50727; .NET CLR 3.0.04506.648; .NET CLR 3.5.21022; .NET4.0C; .NET CLR 3.0.4506.2152; .NET CLR 3.5.30729)
Accept-Encoding: gzip, deflate
Host: api-public.addthis.com
Connection: Keep-Alive
Cookie: uid=5372328cfdb7168d; uvc=1|20; uit=1


HTTP/1.1 200 OK
Cache-Control: no-transform, max-age=600
Content-Type: application/json
Content-Encoding: gzip
Content-Length: 75
Accept-Ranges: bytes
Date: Tue, 13 May 2014 14:56:14 GMT
Via: 1.1 varnish
Age: 340
Connection: keep-alive
X-Served-By: cache-v41-ASH
X-Cache: HIT
X-Cache-Hits: 13
X-Timer: S1399992974.681583166,VS0,VE0
...........O,I.KN*. N..())(//.,II./...OLI-J..5..V*.H,J-V.210.0.......}
>7...HTTP/1.1 200 OK..Cache-Control: no-transform, max-age=600..Con
tent-Type: application/json..Content-Encoding: gzip..Content-Length: 7
5..Accept-Ranges: bytes..Date: Tue, 13 May 2014 14:56:14 GMT..Via: 1.1
varnish..Age: 340..Connection: keep-alive..X-Served-By: cache-v41-ASH
..X-Cache: HIT..X-Cache-Hits: 13..X-Timer: S1399992974.681583166,VS0,V
E0.............O,I.KN*. N..())(//.,II./...OLI-J..5..V*.H,J-V.210.0....
...}>7.....


GET /live/t00/mu.gif?a=sc&r=1&err=1 HTTP/1.1
Accept: */*
Referer: hXXp://VVV.ytddownloader.com/thankyou.html?isn=2A0E0F74E87C41248D17D84CDB01E7BE&stb=1&sds=1&shp=1&lang=1033&cid=31fbc1ce06e12d56d19c32273fd38c79&oldVer=&newVer=4.8.1&tov=19&kt=cnet&pv=0&mpb=1
Accept-Language: en-us
User-Agent: Mozilla/4.0 (compatible; MSIE 8.0; Windows NT 5.1; Trident/4.0; .NET CLR 2.0.50727; .NET CLR 3.0.04506.648; .NET CLR 3.5.21022; .NET4.0C; .NET CLR 3.0.4506.2152; .NET CLR 3.5.30729)
Accept-Encoding: gzip, deflate
Host: m.addthisedge.com
Connection: Keep-Alive


HTTP/1.1 204 No Content
Date: Tue, 13 May 2014 14:56:15 GMT
Cache-Control: max-age=0, no-cache, no-store
Pragma: no-cache
Connection: close


GET /js/main.js HTTP/1.1
Accept: */*
Referer: hXXp://VVV.ytddownloader.com/thankyou.html?isn=2A0E0F74E87C41248D17D84CDB01E7BE&stb=1&sds=1&shp=1&lang=1033&cid=31fbc1ce06e12d56d19c32273fd38c79&oldVer=&newVer=4.8.1&tov=19&kt=cnet&pv=0&mpb=1
Accept-Language: en-us
User-Agent: Mozilla/4.0 (compatible; MSIE 8.0; Windows NT 5.1; Trident/4.0; .NET CLR 2.0.50727; .NET CLR 3.0.04506.648; .NET CLR 3.5.21022; .NET4.0C; .NET CLR 3.0.4506.2152; .NET CLR 3.5.30729)
Accept-Encoding: gzip, deflate
Host: VVV.ytddownloader.com
Connection: Keep-Alive


HTTP/1.1 200 OK
Server: nginx/1.2.1
Date: Tue, 13 May 2014 14:56:11 GMT
Content-Type: application/x-javascript
Content-Length: 1272
Last-Modified: Fri, 08 Nov 2013 13:22:51 GMT
Connection: keep-alive
Accept-Ranges: bytes
$(document).ready(function() {.    //setting os..$(".os-redirect").cli
ck(function(){...setCookie('user_os', $(this).attr("os"), 1,'/');..});
....$(".dropdown img.flag").addClass("flagvisibility");.. $(".dropd
own dt a").click(function() {. $(".dropdown dd div").toggle();.
});. . $(".dropdown dd ul li a").click(function(
) {. var text = $(this).html();. $(".dropdown dt a span"
).html(text);. $(".dropdown dd div").hide();... });.
. $(document).bind('click', function(e) {. var $clic
ked = $(e.target);. if (! $clicked.parents().hasClass("dropdown
")). $(".dropdown dd div").hide();. });...//setting loca
le...$(".langselector, #language-bar a").click(function(){...setCookie
('ytd_locale', $(this).attr("hreflang"), 1,'/');..});....change_auto_r
enew();.});..function setCookie(c_name,value,exdays, path).{..var exda
te=new Date();..exdate.setDate(exdate.getDate() exdays);..var c_valu
e=escape(value) ((exdays==null) ? "" : "; expires=" exdate.toUTCStri
ng()) ((path) ? "; path=" path : "") ;..document.cookie=c_name
"=" c_value;..}.function change_auto_renew() {. $("input[name=sr
c]").each(function() {. $(this).val($(this).val() == 0 ? 1 : 0
);. });.}
....



GET /images/ytd-logo.png HTTP/1.1

Accept: */*
Referer: hXXp://VVV.ytddownloader.com/thankyou.html?isn=2A0E0F74E87C41248D17D84CDB01E7BE&stb=1&sds=1&shp=1&lang=1033&cid=31fbc1ce06e12d56d19c32273fd38c79&oldVer=&newVer=4.8.1&tov=19&kt=cnet&pv=0&mpb=1
Accept-Language: en-us
User-Agent: Mozilla/4.0 (compatible; MSIE 8.0; Windows NT 5.1; Trident/4.0; .NET CLR 2.0.50727; .NET CLR 3.0.04506.648; .NET CLR 3.5.21022; .NET4.0C; .NET CLR 3.0.4506.2152; .NET CLR 3.5.30729)
Accept-Encoding: gzip, deflate
Host: VVV.ytddownloader.com
Connection: Keep-Alive


HTTP/1.1 200 OK
Server: nginx/1.2.1
Date: Tue, 13 May 2014 14:56:12 GMT
Content-Type: image/png
Content-Length: 34724
Last-Modified: Fri, 05 Oct 2012 14:07:53 GMT
Connection: keep-alive
Accept-Ranges: bytes
.PNG........IHDR.......x.....h.......tEXtSoftware.Adobe ImageReadyq.e&
lt;...fiTXtXML:com.adobe.xmp.....<?xpacket begin="..." id="W5M0MpCe
hiHzreSzNTczkc9d"?> <x:xmpmeta xmlns:x="adobe:ns:meta/" x:xmptk=
"Adobe XMP Core 5.0-c061 64.140949, 2010/12/07-10:57:01 "> &
lt;rdf:RDF xmlns:rdf="hXXp://VVV.w3.org/1999/02/22-rdf-syntax-ns#">
<rdf:Description rdf:about="" xmlns:xmpMM="hXXp://ns.adobe.com/xap
/1.0/mm/" xmlns:stRef="hXXp://ns.adobe.com/xap/1.0/sType/ResourceRef#"
xmlns:xmp="hXXp://ns.adobe.com/xap/1.0/" xmpMM:OriginalDocumentID="xm
p.did:48617E8EC10BE2118B4BD91E24AB7A59" xmpMM:DocumentID="xmp.did:7206
5B650C8711E28A8AE4B10473ECB4" xmpMM:InstanceID="xmp.iid:72065B640C8711
E28A8AE4B10473ECB4" xmp:CreatorTool="Adobe Photoshop CS5.1 Windows">
; <xmpMM:DerivedFrom stRef:instanceID="xmp.iid:48617E8EC10BE2118B4B
D91E24AB7A59" stRef:documentID="xmp.did:48617E8EC10BE2118B4BD91E24AB7A
59"/> </rdf:Description> </rdf:RDF> </x:xmpmeta>
<?xpacket end="r"?>O.......IDATx.....eYY'..s.........EA.[.6... .
....c.8.[.........n.i[.g..F...F..i...V....(j...5"c}...|.s.yq#2.2.*....
|U/.-..{.9....#.Rt.q.q.......\{\{\c.k.k..S....!......~....F.K.v....h..
d0"%=*Fk.n...7...5}.........RPv....*%9..&..~z........@..;.G.?...x.qz}.
[email protected]...)....777G.~..4.F._.f.. .Q=....$..~ ...<..
......6....>C..w.q.......#...<..........A.......`.L}.m.-.i.....~
.....?.LEY.x8..hi&....LW..0......#..&..og....K...}@I\.<]... .p\~*!.
x!...KU.:4...x.;.=.3....{.S*.EB...ovaq.J...1.5f.....W.$.wG...N....

<<< skipped >>>

GET /4631cdb5/D0wnloads-mpb-cpl-new/MyPCBackup_Setup.exe HTTP/1.0
Host: track.mypcbackup.com
User-Agent: NSISDL/1.2 (Mozilla)
Accept: */*


HTTP/1.1 301 Moved Permanently
Date: Tue, 13 May 2014 14:56:02 GMT
Server: Apache
Set-Cookie: SESSID=pdk90qpa5qaa2oakk3a1mikus6; path=/; domain=.mypcbackup.com
Expires: Thu, 19 Nov 1981 08:52:00 GMT
Cache-Control: no-store, no-cache, must-revalidate, post-check=0, pre-check=0
Pragma: no-cache
Set-Cookie: LC_CURRENCY=CA; expires=Fri, 23-May-2014 14:56:02 GMT; path=/; domain=.mypcbackup.com
Set-Cookie: ?uva6aT*=CA; expires=Fri, 23-May-2014 14:56:02 GMT; path=/; domain=.mypcbackup.com
Set-Cookie: LC_CURRENCY=CA; expires=Fri, 23-May-2014 14:56:02 GMT; path=/; domain=.mypcbackup.com
Set-Cookie: ?uva6aT*=CA; expires=Fri, 23-May-2014 14:56:02 GMT; path=/; domain=.mypcbackup.com
P3P: CP="We do not have a P3P policy"
location: hXXp://cdn.mypcbackup.com/MyPCBackup_Setup.exe
Set-Cookie: aff_id=75335; expires=Sat, 14-Jun-2014 05:59:59 GMT; path=/; domain=mypcbackup.com
Set-Cookie: hop_name=75335; expires=Sat, 14-Jun-2014 05:59:59 GMT; path=/; domain=mypcbackup.com
Set-Cookie: hop_id=111329; expires=Sat, 14-Jun-2014 05:59:59 GMT; path=/; domain=mypcbackup.com
Set-Cookie: hash=4fe28efd5ddebc791624273719a5317b; expires=Sat, 14-Jun-2014 05:59:59 GMT; path=/; domain=mypcbackup.com
Set-Cookie: tid=D0wnloads-mpb-cpl-new; expires=Sat, 14-Jun-2014 05:59:59 GMT; path=/; domain=mypcbackup.com
Set-Cookie: 4631cdb5unique=true; expires=Mon, 11-Aug-2014 14:56:02 GMT; path=/; domain=mypcbackup.com
Content-Length: 0
Connection: close
Content-Type: text/html; charset=UTF-8
Set-Cookie: MPBWWW=3898156614.1.1048206016.2620617152; path=/

<<< skipped >>>

GET /aadebc4830c51c2794a960fe5a9e11df.php HTTP/1.0
Host: track.mypcbackup.com
User-Agent: NSISDL/1.2 (Mozilla)
Accept: */*


HTTP/1.1 200 OK
Date: Tue, 13 May 2014 14:56:46 GMT
Server: Apache
Set-Cookie: SESSID=5e50ct6rv1pjuu34ldqhjluu04; path=/; domain=.mypcbackup.com
Expires: Thu, 19 Nov 1981 08:52:00 GMT
Cache-Control: no-store, no-cache, must-revalidate, post-check=0, pre-check=0
Pragma: no-cache
Set-Cookie: LC_CURRENCY=CA; expires=Fri, 23-May-2014 14:56:46 GMT; path=/; domain=.mypcbackup.com
Set-Cookie: ?uva6aT*=CA; expires=Fri, 23-May-2014 14:56:46 GMT; path=/; domain=.mypcbackup.com
Set-Cookie: LC_CURRENCY=CA; expires=Fri, 23-May-2014 14:56:46 GMT; path=/; domain=.mypcbackup.com
Set-Cookie: ?uva6aT*=CA; expires=Fri, 23-May-2014 14:56:46 GMT; path=/; domain=.mypcbackup.com
Content-Length: 8
Connection: close
Content-Type: text/html; charset=UTF-8
Set-Cookie: MPBWWW=3898156614.1.1048206016.2620657216; path=/
Complete..


POST /cgi/api.cgi/407453/E2DA97D8A12A4D02B7A3A58A402F38B0/vloc/20 HTTP/1.1
Accept-Encoding: gzip,deflate
Content-Type: text/xml
User-Agent: WidgiToolbar-179-407453
Host: api.mybrowserbar.com
Content-Length: 446
Connection: Keep-Alive
Cache-Control: no-cache

<drq><auth><ccv>179</ccv><cnid>407453</cnid><tbcnid></tbcnid><isn>E2DA97D8A12A4D02B7A3A58A402F38B0</isn><ct>20</ct><dlid>1033</dlid><lngid>1033</lngid><wv>5.1</wv><brw><ie>8.0.6001.18702</ie><ff>29.0.1</ff><gc>34.0.1847.131</gc><dbrw>Internet Explorer</dbrw></brw></auth>
<vloc><type>install</type><key>1</key><key>3</key><key>2</key><key>4</key><key>5</key><key>6</key><key>7</key><key>8</key><key>9</key><key>10</key><key>11</key></vloc></drq>
HTTP/1.1 200 OK
Date: Tue, 13 May 2014 14:56:26 GMT
Server: Apache
Pragma: no-cache
Cache-control: no-cache
Keep-Alive: timeout=30, max=100
Connection: Keep-Alive
Transfer-Encoding: chunked
Content-Type: text/html
Expires: Tue, 13 May 2014 14:56:26 GMT
54d..<drp><auth>.  <scv>179</scv>.</auth>
;.<vloc>. <li>. <key>1</key>. <value
>hXXp://search.yahoo.com/search?fr=chr-greentree_ie&ei=utf-8&am
p;ilc=12&type=407453&p={searchTerms}</value>. </li&g
t;. <li>. <key>3</key>. <value>hXXp://s
earch.yahoo.com/search?fr=greentree_ie1&ei=utf-8&ilc=12&ty
pe=407453&p={searchTerms}</value>. </li>. <li>
. <key>2</key>. <value>hXXp://search.yahoo.com
/search?fr=chr-greentree_ff&ei=utf-8&ilc=12&type=407453&am
p;p={searchTerms}</value>. </li>. <li>. <key
>4</key>. <value>hXXp://search.yahoo.com/search?fr=g
reentree_ff1&ei=utf-8&ilc=12&type=407453&p=</value&
gt;. </li>. <li>. <key>5</key>. <va
lue>hXXp://search.yahoo.com/search?fr=chr-greentree_gc&ei=utf-8
&ilc=12&type=407453&p={searchTerms}</value>. </l
i>. <li>. <key>6</key>. <value>http:
//ca.search.yahoo.com/?type=407453&fr=spigot-yhp-ie</value>.
</li>. <li>. <key>7</key>. <value&
gt;hXXp://ca.search.yahoo.com/?type=407453&fr=spigot-yhp-ff</va
lue>. </li>. <li>. <key>8</key>. &l
t;value>hXXp://ca.search.yahoo.com/?type=407453&fr=spigot-yhp-c
h</value>. </li>. <li>. <key>9</ke

<<< skipped >>>

The program connects to the servers at the folowing location(s):

IEXPLORE.EXE_2676:

.text
`.data
.rsrc
@.reloc
IEFRAME.dll
MLANG.dll
ADVAPI32.dll
KERNEL32.dll
USER32.dll
msvcrt.dll
ntdll.dll
SHLWAPI.dll
SHELL32.dll
ole32.dll
iertutil.dll
urlmon.dll
RegCloseKey
RegOpenKeyExW
GetWindowsDirectoryW
_wcmdln
_amsg_exit
UrlApplySchemeW
UrlCreateFromPathW
UrlCanonicalizeW
PathIsURLW
iexplore.pdb
KEYWD
KEYW
.uuxz
_ %S4Dd
RUBV%uJ
bZ22b%ss
%.FG[[[]]]]]Z11.('
N56.SK
9u%s:
.Ra1X
Y8t/,?.J%F^y
Go.OBR"F
Ri.tn
>.IN }
1YYYY1YY9GEAA=77YRNNNW:.VT1
Y.hilkRROMLK=C,
..(((($$
3...((((%
3....(.''$
3.2...((((%
33.2....(,'
55323222...
(%&'00443445?
00.,,,4(
000.,,9(
0020..9(
003200;(
(#'( (''''!'!
<)<.<3<<<
Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\iexplore.exe
user32.dll
yKernel32.DLL
{28fb17e0-d393-439d-9a21-9474a070473a}
iexplore.exe
Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings
Software\Microsoft\Active Setup\Installed Components\>{26923b43-4d38-484f-9b9e-de460746276c}
"%s" %s
kernel32.dll
-extoff go.microsoft.com/fwlink/?LinkId=106320
-extoff go.microsoft.com/fwlink/?LinkId=106322
-extoff go.microsoft.com/fwlink/?LinkId=106323
\AppPatch\sysmain.sdb
explorer.exe
ieuser.exe
Kernel32.dll
Software\Microsoft\Active Setup\Installed Components\{89820200-ECBD-11CF-8B85-00AA005B4383}
.\%s.mui
.\%s\%s.mui
%s\%s.mui
%s\%s\%s.mui
%s\%s
Software\Microsoft\Internet Explorer\URLSearchHooks
shell:%s
Imaging_CreateWebPagePreview_Perftrack
Frame_URLEntered
Imaging_CreateWebPagePreview
WS_ExecuteQuery
8.00.6001.18702 (longhorn_ie8_rtm(wmbla).090308-0339)
IEXPLORE.EXE
Windows
8.00.6001.18702

IEXPLORE.EXE_2880:

.text
`.data
.rsrc
@.reloc
IEFRAME.dll
MLANG.dll
ADVAPI32.dll
KERNEL32.dll
USER32.dll
msvcrt.dll
ntdll.dll
SHLWAPI.dll
SHELL32.dll
ole32.dll
iertutil.dll
urlmon.dll
RegCloseKey
RegOpenKeyExW
GetWindowsDirectoryW
_wcmdln
_amsg_exit
UrlApplySchemeW
UrlCreateFromPathW
UrlCanonicalizeW
PathIsURLW
iexplore.pdb
KEYWD
KEYW
.uuxz
_ %S4Dd
RUBV%uJ
bZ22b%ss
%.FG[[[]]]]]Z11.('
N56.SK
9u%s:
.Ra1X
Y8t/,?.J%F^y
Go.OBR"F
Ri.tn
>.IN }
1YYYY1YY9GEAA=77YRNNNW:.VT1
Y.hilkRROMLK=C,
..(((($$
3...((((%
3....(.''$
3.2...((((%
33.2....(,'
55323222...
(%&'00443445?
00.,,,4(
000.,,9(
0020..9(
003200;(
(#'( (''''!'!
<)<.<3<<<
Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\iexplore.exe
user32.dll
yKernel32.DLL
{28fb17e0-d393-439d-9a21-9474a070473a}
iexplore.exe
Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings
Software\Microsoft\Active Setup\Installed Components\>{26923b43-4d38-484f-9b9e-de460746276c}
"%s" %s
kernel32.dll
-extoff go.microsoft.com/fwlink/?LinkId=106320
-extoff go.microsoft.com/fwlink/?LinkId=106322
-extoff go.microsoft.com/fwlink/?LinkId=106323
\AppPatch\sysmain.sdb
explorer.exe
ieuser.exe
Kernel32.dll
Software\Microsoft\Active Setup\Installed Components\{89820200-ECBD-11CF-8B85-00AA005B4383}
.\%s.mui
.\%s\%s.mui
%s\%s.mui
%s\%s\%s.mui
%s\%s
Software\Microsoft\Internet Explorer\URLSearchHooks
shell:%s
Imaging_CreateWebPagePreview_Perftrack
Frame_URLEntered
Imaging_CreateWebPagePreview
WS_ExecuteQuery
8.00.6001.18702 (longhorn_ie8_rtm(wmbla).090308-0339)
IEXPLORE.EXE
Windows
8.00.6001.18702

SearchProtection.EXE_3452:

.text
`.rdata
@.data
.rsrc
@.reloc
u(SSh
t?<%u8
<9%u3
t8It.IIt#
.FGy"
SShtbI
 2 34 567
>.uBV
FTPWVh
vSSSh
FTPjK
FtPj;
C.PjRV
kernel32.dll
Please contact the application's support team for more information.
- Attempt to initialize the CRT more than once.
- CRT not initialized
- floating point support not loaded
portuguese-brazilian
operator
GetProcessWindowStation
USER32.DLL
Kernel32.dll
Unicows.dll
3.7.7.1
SQLite format 3
CREATE TABLE sqlite_master(
sql text
CREATE TEMP TABLE sqlite_temp_master(
REINDEXEDESCAPEACHECKEYBEFOREIGNOREGEXPLAINSTEADDATABASELECTABLEFTHENDEFERRABLELSEXCEPTRANSACTIONATURALTERAISEXCLUSIVEXISTSAVEPOINTERSECTRIGGEREFERENCESCONSTRAINTOFFSETEMPORARYUNIQUERYATTACHAVINGROUPDATEBEGINNERELEASEBETWEENOTNULLIKECASCADELETECASECOLLATECREATECURRENT_DATEDETACHIMMEDIATEJOINSERTMATCHPLANALYZEPRAGMABORTVALUESVIRTUALIMITWHENWHERENAMEAFTEREPLACEANDEFAULTAUTOINCREMENTCASTCOLUMNCOMMITCONFLICTCROSSCURRENT_TIMESTAMPRIMARYDEFERREDISTINCTDROPFAILFROMFULLGLOBYIFISNULLORDERESTRICTOUTERIGHTROLLBACKROWUNIONUSINGVACUUMVIEWINITIALLY
urls_to_restore_on_startup
startup_urls
SELECT value FROM meta WHERE key="Default Search Provider ID"
INSERT INTO meta (key,value) VALUES ("Default Search Provider ID",
" WHERE key="Default Search Provider ID"
" WHERE key="Default Search Provider ID Backup"
UPDATE keywords SET logo_id ='0'
SELECT value FROM meta where key='version'
SELECT value FROM meta WHERE key='Default Search Provider ID Backup Signature'
SELECT m.value FROM meta m WHERE m.key="Default Search Provider ID"
' WHERE key="Default Search Provider ID Backup"
" WHERE key='Default Search Provider ID Backup Signature'
UPDATE meta SET value ='9999' WHERE key="Default Search Provider ID"
SELECT 1 FROM keywords WHERE id="
SELECT id FROM keywords WHERE keyword LIKE "
SELECT max(id)   1 FROM keywords
UPDATE keywords SET id = "
SELECT id FROM keywords where sync_guid="
SELECT id FROM keywords where url="
", keyword = "
", url="
UPDATE keywords SET prepopulate_id = 0, sync_guid="
UPDATE keywords SET suggest_url="
INSERT INTO keywords (id, short_name, keyword, favicon_url, url, safe_for_autoreplace, input_encodings, show_in_default_list, prepopulate_id) VALUES ("
UPDATE keywords SET sync_guid="
SELECT null FROM keywords
SELECT k.short_name FROM keywords k, meta m WHERE m.value=k.id AND m.key="Default Search Provider ID"
SELECT k.keyword FROM keywords k, meta m WHERE m.value=k.id AND m.key="Default Search Provider ID" AND k.keyword LIKE "
select k.sync_guid from keywords k, meta m WHERE m.value=k.id AND m.key="Default Search Provider ID"
select k.url from keywords k, meta m WHERE m.value=k.id AND m.key="Default Search Provider ID"
SELECT k.id FROM keywords k, meta m WHERE m.value=k.id AND m.key="Default Search Provider ID"
large file support is disabled
unknown operation
SQL logic error or missing database
foreign_keys
sqlite_compileoption_get
sqlite_compileoption_used
sqlite_log
sqlite_source_id
sqlite_version
sqlite_attach
sqlite_detach
sqlite_stat1
sqlite_rename_parent
sqlite_rename_trigger
sqlite_rename_table
RowKey
SQLITE_
d-d-d d:d:d
d:d:d
d-d-d
failed to allocate %u bytes of memory
failed memory resize %u to %u bytes
922337203685477580
API call with %s database connection pointer
OsError 0x%x (%u)
os_win.c:%d: (%d) %s(%s) - %s
%s-shm
%s\etilqs_
Recovered %d frames from WAL file %s
cannot limit WAL size: %s
invalid page number %d
2nd reference to page %d
Failed to read ptrmap key=%d
Bad ptr map entry key=%d expected=(%d,%d) got=(%d,%d)
%d of %d pages missing from overflow list starting at %d
failed to get page %d
freelist leaf count too big on page %d
Page %d:
unable to get the page. error code=%d
btreeInitPage() returns error code %d
On tree page %d cell %d:
On page %d at right child:
Corruption detected in cell %d on page %d
Multiple uses for byte %d of page %d
Fragmentation of %d bytes reported as %d on page %d
Page %d is never used
Pointer map page %d is referenced
Outstanding page count goes from %d to %d during this analysis
unknown database %s
keyinfo(%d
%s(%d)
%s-mjX
foreign key constraint failed
unable to use function %s in the requested context
bind on a busy prepared statement: [%s]
zeroblob(%d)
abort at %d in [%s]: %s
constraint failed at %d in [%s]
cannot open savepoint - SQL statements in progress
no such savepoint: %s
cannot %s savepoint - SQL statements in progress
cannot rollback transaction - SQL statements in progress
cannot commit transaction - SQL statements in progress
sqlite_temp_master
sqlite_master
SELECT name, rootpage, sql FROM '%q'.%s WHERE %s ORDER BY rowid
cannot change %s wal mode from within a transaction
database table is locked: %s
statement aborts at %d: [%s] %s
cannot open value of type %s
cannot open virtual table: %s
cannot open view: %s
no such column: "%s"
foreign key
indexed
cannot open %s column for writing
misuse of aliased aggregate %s
%s: %s.%s.%s
%s: %s.%s
%s: %s
not authorized to use function: %s
%r %s BY term out of range - should be between 1 and %d
too many terms in %s BY clause
Expression tree is too large (maximum depth %d)
variable number must be between ?1 and ?%d
too many SQL variables
too many columns in %s
EXECUTE %s%s SUBQUERY %d
misuse of aggregate: %s()
%.*s"%w"%s
%s%.*s"%w"
%s OR name=%Q
type='trigger' AND (%s)
sqlite_
table %s may not be altered
there is already another table or index with this name: %s
view %s may not be altered
UPDATE "%w".%s SET sql = sqlite_rename_parent(sql, %Q, %Q) WHERE %s;
UPDATE %Q.%s SET sql = CASE WHEN type = 'trigger' THEN sqlite_rename_trigger(sql, %Q)ELSE sqlite_rename_table(sql, %Q) END, tbl_name = %Q, name = CASE WHEN type='table' THEN %Q WHEN name LIKE 'sqlite_autoindex%%' AND type='index' THEN 'sqlite_autoindex_' || %Q || substr(name,%d 18) ELSE name END WHERE tbl_name=%Q AND (type='table' OR type='index' OR type='trigger');
sqlite_sequence
UPDATE "%w".sqlite_sequence set name = %Q WHERE name = %Q
UPDATE sqlite_temp_master SET sql = sqlite_rename_trigger(sql, %Q), tbl_name = %Q WHERE %s;
Cannot add a PRIMARY KEY column
UPDATE "%w".%s SET sql = substr(sql,1,%d) || ', ' || %Q || substr(sql,%d) WHERE type = 'table' AND name = %Q
sqlite_altertab_%s
CREATE TABLE %Q.%s(%s)
DELETE FROM %Q.%s WHERE %s=%Q
SELECT tbl, idx, stat FROM %Q.sqlite_stat1
invalid name: "%s"
too many attached databases - max %d
database %s is already in use
unable to open database: %s
no such database: %s
cannot detach database %s
database %s is locked
%s %T cannot reference objects in database %s
access to %s.%s.%s is prohibited
access to %s.%s is prohibited
object name reserved for internal use: %s
there is already an index named %s
too many columns on %s
duplicate column name: %s
default value of column [%s] is not constant
table "%s" has more than one primary key
AUTOINCREMENT is only allowed on an INTEGER PRIMARY KEY
no such collation sequence: %s
CREATE %s %.*s
UPDATE %Q.%s SET type='%s', name=%Q, tbl_name=%Q, rootpage=#%d, sql=%Q WHERE rowid=#%d
CREATE TABLE %Q.sqlite_sequence(name,seq)
view %s is circularly defined
UPDATE %Q.%s SET rootpage=%d WHERE #%d AND rootpage=#%d
table %s may not be dropped
use DROP TABLE to delete table %s
use DROP VIEW to delete view %s
DELETE FROM %s.sqlite_sequence WHERE name=%Q
DELETE FROM %Q.%s WHERE tbl_name=%Q and type!='trigger'
DELETE FROM %Q.sqlite_stat1 WHERE tbl=%Q
foreign key on %s should reference only one column of table %T
number of columns in foreign key does not match the number of columns in the referenced table
unknown column "%s" in foreign key definition
indexed columns are not unique
table %s may not be indexed
views may not be indexed
virtual tables may not be indexed
there is already a table named %s
index %s already exists
sqlite_autoindex_%s_%d
table %s has no column named %s
CREATE%s INDEX %.*s
INSERT INTO %Q.%s VALUES('index',%Q,%Q,#%d,%Q);
no such index: %S
index associated with UNIQUE or PRIMARY KEY constraint cannot be dropped
DELETE FROM %Q.%s WHERE name=%Q AND type='index'
DELETE FROM %Q.sqlite_stat1 WHERE idx=%Q
a JOIN clause is required before %s
unable to identify the object to be reindexed
table %s may not be modified
cannot modify %s because it is a view
foreign key mismatch
table %S has %d columns but %d values were supplied
%d values for %d columns
table %S has no column named %s
%s.%s may not be NULL
PRIMARY KEY must be unique
sqlite3_extension_init
unable to open shared library [%s]
no entry point [%s] in shared library [%s]
error during initialization: %s
automatic extension loading failed: %s
foreign_key_list
*** in database %s ***
unsupported encoding: %s
malformed database schema (%s)
%s - %s
unsupported file format
SELECT name, rootpage, sql FROM '%q'.%s ORDER BY rowid
database schema is locked: %s
unknown or unsupported join type: %T %T%s%T
RIGHT and FULL OUTER JOINs are not currently supported
a NATURAL join may not have an ON or USING clause
cannot have both ON and USING clauses in the same join
cannot join using column %s - column not present in both tables
USE TEMP B-TREE FOR %s
COMPOUND SUBQUERIES %d AND %d %s(%s)
%s.%s
%s:%d
ORDER BY clause should come after %s not before
LIMIT clause should come after %s not before
SELECTs to the left and right of %s do not have the same number of result columns
no such index: %s
sqlite_subquery_%p_
no such table: %s
SCAN TABLE %s %s%s(~%d rows)
sqlite3_get_table() called with two or more incompatible queries
cannot create %s trigger on view: %S
cannot create INSTEAD OF trigger on table: %S
INSERT INTO %Q.%s VALUES('trigger',%Q,%Q,0,'CREATE TRIGGER %q')
no such trigger: %S
-- TRIGGER %s
no such column: %s
cannot VACUUM - SQL statements in progress
PRAGMA vacuum_db.synchronous=OFF
SELECT 'CREATE TABLE vacuum_db.' || substr(sql,14) FROM sqlite_master WHERE type='table' AND name!='sqlite_sequence' AND rootpage>0
SELECT 'CREATE INDEX vacuum_db.' || substr(sql,14) FROM sqlite_master WHERE sql LIKE 'CREATE INDEX %'
SELECT 'CREATE UNIQUE INDEX vacuum_db.' || substr(sql,21) FROM sqlite_master WHERE sql LIKE 'CREATE UNIQUE INDEX %'
SELECT 'INSERT INTO vacuum_db.' || quote(name) || ' SELECT * FROM main.' || quote(name) || ';'FROM main.sqlite_master WHERE type = 'table' AND name!='sqlite_sequence' AND rootpage>0
SELECT 'DELETE FROM vacuum_db.' || quote(name) || ';' FROM vacuum_db.sqlite_master WHERE name='sqlite_sequence'
SELECT 'INSERT INTO vacuum_db.' || quote(name) || ' SELECT * FROM main.' || quote(name) || ';' FROM vacuum_db.sqlite_master WHERE name=='sqlite_sequence';
INSERT INTO vacuum_db.sqlite_master SELECT type, name, tbl_name, rootpage, sql FROM main.sqlite_master WHERE type='view' OR type='trigger' OR (type='table' AND rootpage=0)
UPDATE %Q.%s SET type='table', name=%Q, tbl_name=%Q, rootpage=0, sql=%Q WHERE rowid=#%d
vtable constructor failed: %s
vtable constructor did not declare schema: %s
no such module: %s
table %s: xBestIndex returned an invalid plan
%s SUBQUERY %d
%s TABLE %s
%s AS %s
%s USING %s%sINDEX%s%s%s
%s USING INTEGER PRIMARY KEY
%s (rowid=?)
%s (rowid>? AND rowid
%s (rowid>?)
%s (rowid
%s VIRTUAL TABLE INDEX %d:%s
%s (~%lld rows)
at most %d tables in a join
cannot use index: %s
the INDEXED BY clause is not allowed on UPDATE or DELETE statements within triggers
the NOT INDEXED clause is not allowed on UPDATE or DELETE statements within triggers
unable to close due to unfinished backup operation
unknown database: %s
no such %s mode: %s
%s mode not allowed: %s
no such vfs: %s
database corruption at line %d of [%.10s]
misuse at line %d of [%.10s]
cannot open file at line %d of [%.10s]
OLEACC.dll
KERNEL32.dll
USER32.dll
GDI32.dll
RegCloseKey
RegOpenKeyExW
RegNotifyChangeKeyValue
RegDeleteKeyW
RegCreateKeyExW
RegQueryInfoKeyW
RegEnumKeyExW
ADVAPI32.dll
SHELL32.dll
ole32.dll
OLEAUT32.dll
UrlEscapeW
SHLWAPI.dll
COMCTL32.dll
USERENV.dll
HttpOpenRequestW
HttpSendRequestW
InternetCrackUrlW
HttpQueryInfoW
WININET.dll
PSAPI.DLL
GetProcessHeap
GetCPInfo
GetConsoleOutputCP
.?AVFirefoxNotificationDlg@@
.?AV?$CDialogImpl@VFirefoxNotificationDlg@@VCWindow@ATL@@@ATL@@
.?AV?$CWinDataExchange@VFirefoxNotificationDlg@@@WTL@@
zcÁ
.?AVDUrlHelper@@
http://www.yahoo.com/favicon.ico
http://www.yahoo.com/favicon.ico
http://search.yahoo.com/
http://www.yandex.com/favicon.ico
http://www.yandex.ru/
http://www.baidu.com/favicon.ico
http://www.baidu.com/
Search.com
Search.com
http://www.search.com/favicon.ico
Search.com
Search.com
http://t1.search.com/
"%""""$$
$'%%&%$##$
((&&&&%$#&
(('&'&&$%$
'(('&'&$&
$($%$%$$#
)&%%&&%%$##(
#)(&'''&&%$#'#
'))('('''&%#'$
'))('('('&%%'#
%)))(('(''%%'
>>>]]]111
#&$##$'&
$))('''(''&%$$'!
$)))('(('''&%%'
))))'''(''&%&%
{{{???___
3#4(4-4`4
4"4&4*4.42464
; ;$;(;,;0;
5!5%5)5-5155595
2i3}3L4
3#3'3 3/3
2 2$2(2,20242~2
4 4$4(4,4
3 4-424@4
1 1$1(1,10141
1 1$1(1,1014181<1
4,60687<7
<4?8?
0(101<1\1|1
707<7`7|7
Fprefs.js
Global\{GCSDS_RESTORE_15B475F3-750C-4889-A091-41A9E28FC471}
SearchProtectionSetup.exe
cltmngui.exe
cltmng.exe
{chr_gc_SDS_changed_5A5011E0-B85A-4801-B002-8C669AD1BE12
{chr_ie_SDS_changed_5A5011E0-B85A-4801-B002-8C669AD1BE12
{chr_ff_SDS_changed_5A5011E0-B85A-4801-B002-8C669AD1BE12
HKEY_CLASSES_ROOT
HKEY_CURRENT_USER
HKEY_LOCAL_MACHINE
HKEY_USERS
HKEY_PERFORMANCE_DATA
HKEY_DYN_DATA
HKEY_CURRENT_CONFIG
Global\{SS_EXE_RUNNING_15B475F3-750C-4889-A091-41A9E28FC471}
Global\{SDS_EXE_RUNNING_15B475F3-750C-4889-A091-41A9E28FC471}
KERNEL32.DLL
mscoree.dll
Comctl32.dll
@{chr_redo_se__sds_5A5011E0-B85A-4801-B002-8C669AD1BE12
777705555443332
5555443332
5555443332
SOFTWARE\Mozilla\Mozilla Firefox
\SOFTWARE\Mozilla\Mozilla Firefox
SOFTWARE\Mozilla\Mozilla Firefox\
Mozilla\Firefox\
profiles.ini
Software\Microsoft\Windows\Shell\Associations\UrlAssociations\http\UserChoice
Firefox
Chrome
http\shell\open\command
iexplore.exe
firefox.exe
chrome.exe
Software\Microsoft\Windows\CurrentVersion\Uninstall\Google Chrome
explorer.exe
SDS{FE4559D7-F7D6-4905-99B3-9BB1DDA607C5}
shell32.dll
Mozilla\Firefox\Profiles\*
\prefs.js
user_pref("browser.startup.page"
user_pref("browser.startup.homepage"
user_pref("browser.startup.homepage", "
Google\Chrome\User Data\
Web Data
HTTP/1.1
yahoo.com Search
%yahoo.co%
http://www.yahoo.com
/favicon.ico
yahoo_ie.xml
yahoo_ff.xml
E5E25692-5D50-4388-9C00-1FE806CFF550
http://ff.search.yahoo.com/gossip?output=fxjson&command={searchTerms}
yandex.ru
http://www.yandex.com/favicon.ico
yandex_ie.xml
yandex_ff.xml
yandex.xml
B073B064-FDCA-4877-811F-0944183D9189
http://suggest.yandex.com/suggest-ff.cgi?part={searchTerms}
baidu.com
http://www.baidu.com/favicon.ico
baidu_ie.xml
baidu_ff.xml
baidu.xml
96DF6162-D0D6-4f40-A2D5-44E4F149C9F5
Search.com
search.com
%search.com%
http://www.search.com/favicon.ico
searchcom_ie.xml
searchcom_ff.xml
searchcom.xml
E82FF3F6-E7BF-4a7b-BBF9-40FD12A7FC45
browser.search.selectedEngine", "
browser.search.defaultenginename", "
browser.search.order.1", "
FaviconURLFallback
iertutil.dll
{5d337aed-05bc-4ee8-8785-0c113f072ebd}
cgi/api.cgi
\search.json
SELECT id, short_name, keyword, favicon_url, url, safe_for_autoreplace, originating_url, date_created, usage_count, input_encodings, show_in_default_list, suggest_url, prepopulate_id, autogenerate_keyword, logo_id, created_by_policy, instant_url, last_modified, sync_guid FROM keywords
SELECT id, short_name, keyword, favicon_url, url, safe_for_autoreplace, originating_url, date_created, usage_count, input_encodings, show_in_default_list, suggest_url, prepopulate_id, created_by_policy, instant_url, last_modified, sync_guid FROM keywords
SELECT value FROM meta WHERE key='Default Search Provider ID'
DROP TABLE keywords_backup
CREATE TABLE keywords_backup AS SELECT * FROM keywords ORDER BY id ASC
rGoogle\Chrome\User Data\Local State
browser.search.selectedEngine
user_pref("browser.search.defaultenginename", "
user_pref("browser.search.selectedEngine", "
user_pref("keyword.URL", "
\search.sqlite
\search-metadata.json
user_pref("browser.search.defaultenginename"
user_pref("browser.search.selectedEngine"
user_pref("keyword.URL"
user_pref("smartbar.addressBarOwnerCTID", "
.searchProtector.notifyChanges", "{\"dataType\":\"string\",\"data\":\"false\"}");
user_pref("browser.keywordURLPromptDeclined", 1);
user_pref("browser.keywordURLPromptDeclined"
Software\Microsoft\Internet Explorer\URLSearchHooks
{CFBFAE00-17A6-11D0-99CB-00C04FD64497}
{69293fa3-07e0-43ae-ABc9-b5759328e509}
\searchplugins\*.xml
AMicrosoft Windows NT
Microsoft Windows 2000
Microsoft Windows XP SP1
Microsoft Windows XP SP2
Microsoft Windows XP
Microsoft Windows Vista
Microsoft Windows Vista or higher
Microsoft Windows 95
Microsoft Windows 98
Microsoft Windows Me
operator[](std::wstring)
%H:%M:%S
%d/%m/%y
[%s %s] Level[%s] pid[0xX] tid[0xX] ct[%s] %s::%s() -
Floating point (%%e, %%f, %%g, and %%G) is not supported by the WTL::CString class.
http://api.mybrowserbar.com
http://search.yahoo.com/search?ei=utf-8&fr=chr-greentree_ie&type=[CHANNEL_ID_SS]&ilc=12&p={searchTerms}
http://search.yahoo.com/search?ei=utf-8&fr=chr-greentree_ff&type=[CHANNEL_ID_SS]&ilc=12&p={searchTerms}
http://search.yahoo.com/search?ei=utf-8&fr=greentree_ie1&type=[CHANNEL_ID_SS]&ilc=12&p={searchTerms}
http://search.yahoo.com/search?ei=utf-8&fr=greentree_ff1&type=[CHANNEL_ID_SS]&ilc=12&p=
http://search.yahoo.com/search?ei=utf-8&fr=chr-greentree_gc&type=[CHANNEL_ID_SS]&ilc=12&p={searchTerms}
http://search.yahoo.com/search
http://www.baidu.com/baidu
http://yandex.ru/yandsearch
cmdline
http://update.mybrowserbar.com/kits/sds/update.xml
%Documents and Settings%\%current user%\Application Data\Search Protection\SearchProtection.EXE
This is your current setting%Search Protection Change Notification
Keep using %1.Change to %1 and disable the search protectionOSearch Protection has detected an attempt to change your default search settingHSearch Protection has detected a change to your browser search settings.
Replace%Select the entire document
Arrange Icons/Arrange windows so they overlap
Cascade Windows5Arrange windows as non-overlapping tiles
Tile Windows5Arrange windows as non-overlapping tiles
Tile Windows(Split the active window into panes
8, 9, 0, 2
SearchProtection.exe

CouponsHelper.exe_3544:

.text
`.rdata
@.data
.rsrc
@.reloc
<9%u3
t8It.IIt#
.FGy"
 2 34 567
TT T!"TT#$TTTT%&'TTT(T)*T TTT,-.TT/0123TTTTTT4TTTTTTT5TTTTTT6789:;TTTTTTTT?@ABCDTTTTETTTTFTTTTTTGTTHITTTTTJKTTTLLTTMTTTTTTTTTNTTOTPQRS
!"FFF#F$Fÿ&F'()FFFFFFFFFFFFF*FFFFFFFFFFFF FF,-FFFFFFFFFFF.F/FFFFFFFFFFFFFF01FF234FF56789FFFFFFFF:;FF<=>FF?FFFFF@ABFFFFFCFDFFFFFE
t.Gj:W
FL9D$(u$
vSSSh
tGHt.Ht&
FTPjK
FtPj;
C.PjRV
Could not resolve %s: %s; %s
getaddrinfo() failed for %s:%d; %s
init_resolve_thread() failed for %s; %s
Added %s:%d:%s to DNS cache
Resolve %s found illegal!
%5[^:]:%d:%5s
CURLOPT_SSL_VERIFYHOST no longer supports 1 as value!
About to connect() to %s%s port %ld (#%ld)
Connected to %s (%s) port %ld (#%ld)
IDN support not present, can't parse Unicode domains
Protocol %s not supported or disabled in libcurl
http_proxy
%5[^:@]:%5[^@]
:%5[^@]
Port number too large: %lu
%s://%s%s%s:%hu%s%s%s
;type=%c
[%*45[0123456789abcdefABCDEF:.]%c
Couldn't find host %s in the _netrc file; using defaults
[email protected]
Couldn't resolve host '%s'
Couldn't resolve proxy '%s'
User-Agent: %s
Closing connection %d
Connection %d seems to be dead!
Found bundle for host %s: %p
 malformed
:]://%[^
[^:]:%[^
Re-using existing connection! (#%ld) with host %s
%s://%s
Connection #%ld to host %s left intact
Internal error removing splay node = %d
Internal error clearing splay node = %d
Operation timed out after %ld milliseconds with %lld out of %lld bytes received
In state %d with no easy_conn, bail out!
Pipe broke: handle 0x%p, url = %s
[%s %s %s]
Send failure: %s
Recv failure: %s
%s cookie %s="%s" for domain %s, path %s, expire %lld
#HttpOnly_
skipped cookie with bad tailmatch domain: %s
skipped cookie with illegal dotcount domain: %s
httponly
23[^;
=]=I99[^;
%s%s%s
# Fatal libcurl error
# Netscape HTTP Cookie File
# http://curl.haxx.se/docs/http-cookies.html
# This file was generated by libcurl! Edit at your own risk.
WARNING: failed to save cookies in %s
Failed to set SO_KEEPALIVE on fd %d
bind failed with errno %d: %s
Local port: %hu
getsockname() failed with errno %d: %s
Bind to local port %hu failed, trying next
Couldn't bind to '%s'
Local Interface %s is ip %s using address family %i
Name '%s' family %i resolved to '%s' family %i
ssloc inet_ntop() failed with errno %d: %s
ssrem inet_ntop() failed with errno %d: %s
getpeername() failed with errno %d: %s
TCP_NODELAY set
Could not set TCP_NODELAY: %s
Failed to connect to %s: %s
sa_addr inet_ntop() failed with errno %d: %s
Trying %s...
couldn't connect to %s at %s:%d
Failed connect to %s:%ld; %s
Unable to parse FTP file list
Error in the SSH layer
Caller must register CURLOPT_CONV_ callback options
TFTP: No such user
TFTP: Unknown transfer ID
TFTP: Illegal operation
TFTP: Access Violation
TFTP: File Not Found
Login denied
Issuer check against peer certificate failed
Invalid LDAP URL
Unrecognized or bad HTTP Content or Transfer-Encoding
Problem with the SSL CA cert (path? access rights?)
Peer certificate cannot be authenticated with given CA certificates
Problem with the local SSL certificate
SSL peer certificate or SSH remote key was not OK
An unknown option was passed in to libcurl
A libcurl function was given a bad argument
Operation was aborted by an application callback
FTP: command REST failed
FTP: command PORT failed
HTTP response code said error
FTP: couldn't retrieve (RETR failed) the specified file
FTP: couldn't set file type
FTP: can't figure out the host in the PASV response
FTP: unknown 227 response format
FTP: unknown PASV reply
FTP: unknown PASS reply
FTP: The server did not accept the PRET command.
FTP: Accepting server connect has timed out
FTP: The server failed to connect to data port
FTP: weird server reply
A requested feature, protocol or option was not found built-in in this libcurl due to a build-time decision.
URL using bad/illegal format or missing URL
Unsupported protocol
Winsock version not supported
Protocol family not supported
Address family not supported
Operation not supported
Socket is unsupported
Protocol is unsupported
Protocol option is unsupported
Unknown error %d (%#x)
%d.%d.%d.%d
%s%s%s%s%s%s
Session: %s
%s %s RTSP/1.0
Range: %s
Referer: %s
Accept-Encoding: %s
Refusing to issue an RTSP SETUP without a Transport: header.
Transport: %s
Transport:
Refusing to issue an RTSP request [%s] without a session ID.
Got RTSP Session ID Line [%s], but wanted ID [%s]
Unable to read the CSeq header: [%s]
SMTP
EHLO %s
HELO %s
No known authentication mechanisms supported!
AUTH %s %s
LOGIN
AUTH %s
Got unexpected smtp-server response: %d
Remote access denied: %d
Access denied: %d
smtp
Authentication failed: %d
MAIL FROM:%s SIZE=%s
MAIL FROM:%s AUTH=%s SIZE=%s
MAIL FROM:%s AUTH=%s
MAIL FROM:%s
RCPT TO:<%s>
RCPT TO:%s
MAIL failed: %d
RCPT failed: %d
SMTPS not supported!
STARTTLS denied. %c
USER %s
APOP %s %s
Access denied. %c
PASS %s
%s %s
POP3S not supported!
LOGINDISABLED
%s CAPABILITY
%s LOGIN %s %s
%s AUTHENTICATE %s
%s STARTTLS
%s SELECT %s
%s FETCH 1 BODY[TEXT]
%s LOGOUT
IMAPS not supported!
TFTP
set timeouts for state %d; Total %ld, retry %d maxtry %d
invalid tsize -:%s:- value in OACK packet
%s (%ld)
blksize is smaller than min supported
%s (%d)
blksize is larger than max supported
%s (%d) %s (%d)
got option=(%s) value=(%s)
tftp_rx: internal error
Timeout waiting for block %d ACK. Retries = %d
Received unexpected DATA packet block %d, expecting block %d
Received last DATA packet block %d again.
tftp_tx: internal error, event: %i
tftp_tx: giving up waiting for block %d ack
Received ACK for block %d, expecting %d
bind() failed; %s
tftp_send_first: internal error
%s%c%s%c
TFTP finished
TFTP response timeout
Can't get the size of %s
Can't open %s for writing
Last-Modified: %s, d %s M d:d:d GMT
Couldn't open file %s
There are more than %d entries
LDAP remote: %s
LDAP local: ldap_simple_bind_s %s
LDAP local: Cannot connect to %s:%hu
LDAP local: trying to establish %s connection
LDAP local: %s
LDAP local: LDAP Vendor = %s ; LDAP Version = %d
CLIENT libcurl 7.29.0
MATCH %s %s %s
DEFINE %s %s
insufficient winsock version to support telnet
WSAStartup failed (%d)
%s %d %d
%s %s %d
%s %s %s
%s IAC %d
%s IAC %s
Sending data failed (%d)
%d (unknown)
%s (unsupported)
%s IAC SB
Syntax error in telnet option: %s
Unknown telnet option %s
7[^= ]%*[ =]%5s
USER,%s
%c%c%c%c%s%c%c
%c%s%c%s
7[^,],7s
%c%c%c%c
FreeLibrary(wsock2) failed (%d)
WSACloseEvent failed (%d)
WSAEnumNetworkEvents failed (%d)
WSACreateEvent failed (%d)
failed to find WSAEnumNetworkEvents function (%d)
failed to find WSAEventSelect function (%d)
failed to find WSACloseEvent function (%d)
failed to find WSACreateEvent function (%d)
failed to load WS2_32.DLL (%d)
WS2_32.DLL
PORT
Failure sending PORT command: %s
,%d,%d
Failure sending EPRT command: %s
%s |%d|%s|%hu|
bind() failed, we ran out of ports!
bind(port=%hu) failed: %s
bind(port=%hu) on non-local address failed: %s
socket failure: %s
failed to resolve the address provided to PORT: %s
getsockname() failed: %s
Connect data stream passively
STOR %s
APPE %s
SIZE %s
RETR %s
ftp server doesn't support SIZE
PBSZ %d
Access denied: d
ACCT %s
ACCT rejected by server: d
Connecting to %s (%s) port %d
Failure sending QUIT command: %s
Uploading to a URL without a file name!
FTPS not supported!
FTP response aborted due to select/poll error: %d
FTP response timeout
MDTM %s
Bad PASV/EPSV response: d
Can't resolve new host %s:%hu
Can't resolve proxy host %s:%hu
Skips %d.%d.%d.%d for data connection, uses %s instead
%d,%d,%d,%d,%d,%d
Illegal port number in EPSV reply
%c%c%c%u%c
ddd d:d:d GMT
dddddd
unsupported MDTM reply format
QUOT string not accepted: %s
Wildcard - "%s" skipped by user
Wildcard - START of "%s"
Preparing for accepting server on data port
CWD %s
Failed FTP upload: 
RETR response: d
server did not report OK, got %d
Failure sending ABOR command: %s
Remembering we are in dir "%s"
PRET RETR %s
PRET STOR %s
PRET %s
REST %d
Got a d response code instead of the assumed 200
TYPE %c
Failed to do PORT
PRET command not accepted: d
Failed to MKD dir: d
MKD %s
QUOT command failed with d
Entry path is '%s'
PROT %c
unsupported parameter to CURLOPT_FTPSSLAUTH: %d
Got a d ftp-server response when 220 was expected
%sAuthorization: Basic %s
%s:%s
%s auth using %s with user '%s'
HTTP/
Avoided giant realloc for header (max is %d)!
The requested URL returned error: %d
The requested URL returned error: %s
If-Unmodified-Since: %s
Last-Modified: %s
If-Modified-Since: %s
%s, d %s M d:d:d GMT
Failed sending HTTP POST request
Content-Type: application/x-www-form-urlencoded
Internal HTTP POST error!
Failed sending HTTP request
%s%s=%s
%s HTTP/%s
%s%s%s%s%s%s%s%s%s%s%s
ftp://%s:%s@%s
Content-Range: bytes %s/%lld
Content-Range: bytes %s%lld/%lld
Range: bytes=%s
ftp://
Host: %s%s%s:%hu
Host: %s%s%s
Chunky upload is not supported by HTTP 1.0
HTTP error before end of send, stop sending
HTTP/1.0 connection set to keep alive!
HTTP/1.1 proxy connection set close!
HTTP/1.0 proxy connection set to keep alive!
HTTP 1.0, assume close after body
RTSP/%d.%d =
HTTP =
HTTP/%d.%d =
%s, algorithm="%s"
%s, opaque="%s"
%sAuthorization: Digest username="%s", realm="%s", nonce="%s", uri="%s", response="%s"
%sAuthorization: Digest username="%s", realm="%s", nonce="%s", uri="%s", cnonce="%s", nc=x, qop=%s, response="%s"
%s:%s:x:%s:%s:%s
%s:%.*s
%s:%s:%s
Can't complete SOCKS4 connection to %d.%d.%d.%d:%d. (%d), Unknown.
Can't complete SOCKS4 connection to %d.%d.%d.%d:%d. (%d), request rejected because the client program and identd report different user-ids.
Can't complete SOCKS4 connection to %d.%d.%d.%d:%d. (%d), request rejected because SOCKS server cannot connect to identd on the client.
Can't complete SOCKS4 connection to %d.%d.%d.%d:%d. (%d), request rejected or failed.
SOCKS4%s request granted.
Failed to resolve "%s" for SOCKS4 connect.
No authentication method was acceptable. (It is quite likely that the SOCKS5 server wanted a username/password, since none was supplied to the server on this connection.)
SOCKS5 GSSAPI per-message authentication is not supported.
Can't complete SOCKS5 connection to xx:xx:xx:xx:xx:xx:xx:xx:%d. (%d)
Can't complete SOCKS5 connection to %s:%d. (%d)
Can't complete SOCKS5 connection to %d.%d.%d.%d:%d. (%d)
Failed to resolve "%s" for SOCKS5 connect.
User was rejected by the SOCKS5 server (%d %d).
--:--:--
%3lld %s %3lld %s %3lld %s %s %s %s %s %s %s
Received HTTP code %d from proxy after CONNECT
CONNECT %s HTTP/%s
%s%s%s%s
Host: %s
%s%s%s:%hu
%s:%hu
Establish HTTP proxy tunnel to %s:%hu
TUNNEL_STATE switched to: %d
HTTP/1.%d %d
password
login
Operation too slow. Less than %ld bytes/sec transferred the last %ld seconds
operation aborted by callback
ioctl callback returned error %d
the ioctl callback returned %d
seek callback returned error %d
Problem (%d) in the Chunked-Encoded data
HTTP server doesn't seem to support byte ranges. Cannot resume.
Excess found in a non pipelined read: excess = %zd url = %s (zero-length body)
Excess found in a non pipelined read: excess = %zu, size = %lld, maxdownload = %lld, bytecount = %lld
Rewinding stream by : %zu bytes on url %s (size = %lld, maxdownload = %lld, bytecount = %lld, nread = %zd)
Rewinding stream by : %zd bytes on url %s (zero-length body)
Operation timed out after %ld milliseconds with %lld bytes received
No URL set!
[^?&/:]://%c
Violate RFC 2616/10.3.2 and switch from POST to GET
Violate RFC 2616/10.3.3 and switch from POST to GET
Disables POST, goes with %s
Issue another request to this URL: '%s'
d:d
%s xxxxxxxxxxxxxxxx
username="%s",realm="%s",nonce="%s",cnonce="%s",nc="%s",digest-uri="%s",response=%s
%s/%s
12345678
00000001
%c%c==
%c%c%c=
0123456789-
.jpeg
.html
; filename="%s"
--%s--
couldn't open file "%s"
Content-Type: %s
Content-Type: multipart/mixed, boundary=%s
%s; boundary=%s
Visual C   CRT: Not enough memory to complete call to strerror.
Broken pipe
Inappropriate I/O control operation
Operation not permitted
Please contact the application's support team for more information.
- Attempt to initialize the CRT more than once.
- CRT not initialized
- floating point support not loaded
portuguese-brazilian
GetProcessWindowStation
USER32.DLL
operator
updateURL
updateKey
optionsURL
aboutURL
iconURL
icon64URL
{ec8030f7-c20a-464f-9b0e-13a3a9e97384}
SELECT seq FROM sqlite_sequence WHERE name='locale'
SELECT seq FROM sqlite_sequence WHERE name='addon'
',strftime('%s059', 'now'),strftime('%s059', 'now'),'1','0','0','221102','','','0','0','1','0')
','1','1','0','0','0','
',strftime('%s059', 'now'),strftime('%s059', 'now'),'1','0','0','221102','','','0','0')
','{ec8030f7-c20a-464f-9b0e-13a3a9e97384}','
UPDATE sqlite_sequence SET seq='
inflate 1.2.7.f-hanba-win64 Copyright (C) 2012 Jonathan Hanba
unzip 1.01 Copyright 1998-2004 Gilles Vollant - http://www.winimage.com/zLibDll
3.7.7.1
SQLite format 3
CREATE TABLE sqlite_master(
sql text
CREATE TEMP TABLE sqlite_temp_master(
REINDEXEDESCAPEACHECKEYBEFOREIGNOREGEXPLAINSTEADDATABASELECTABLEFTHENDEFERRABLELSEXCEPTRANSACTIONATURALTERAISEXCLUSIVEXISTSAVEPOINTERSECTRIGGEREFERENCESCONSTRAINTOFFSETEMPORARYUNIQUERYATTACHAVINGROUPDATEBEGINNERELEASEBETWEENOTNULLIKECASCADELETECASECOLLATECREATECURRENT_DATEDETACHIMMEDIATEJOINSERTMATCHPLANALYZEPRAGMABORTVALUESVIRTUALIMITWHENWHERENAMEAFTEREPLACEANDEFAULTAUTOINCREMENTCASTCOLUMNCOMMITCONFLICTCROSSCURRENT_TIMESTAMPRIMARYDEFERREDISTINCTDROPFAILFROMFULLGLOBYIFISNULLORDERESTRICTOUTERIGHTROLLBACKROWUNIONUSINGVACUUMVIEWINITIALLY
RegDeleteKeyExW
manifest.json
large file support is disabled
unknown operation
SQL logic error or missing database
foreign_keys
sqlite_compileoption_get
sqlite_compileoption_used
sqlite_log
sqlite_source_id
sqlite_version
sqlite_attach
sqlite_detach
sqlite_stat1
sqlite_rename_parent
sqlite_rename_trigger
sqlite_rename_table
RowKey
SQLITE_
d-d-d d:d:d
d:d:d
d-d-d
failed to allocate %u bytes of memory
failed memory resize %u to %u bytes
922337203685477580
API call with %s database connection pointer
OsError 0x%x (%u)
os_win.c:%d: (%d) %s(%s) - %s
%s-shm
%s\etilqs_
Recovered %d frames from WAL file %s
cannot limit WAL size: %s
invalid page number %d
2nd reference to page %d
Failed to read ptrmap key=%d
Bad ptr map entry key=%d expected=(%d,%d) got=(%d,%d)
%d of %d pages missing from overflow list starting at %d
failed to get page %d
freelist leaf count too big on page %d
Page %d:
unable to get the page. error code=%d
btreeInitPage() returns error code %d
On tree page %d cell %d:
On page %d at right child:
Corruption detected in cell %d on page %d
Multiple uses for byte %d of page %d
Fragmentation of %d bytes reported as %d on page %d
Page %d is never used
Pointer map page %d is referenced
Outstanding page count goes from %d to %d during this analysis
unknown database %s
keyinfo(%d
%s(%d)
%s-mjX
foreign key constraint failed
unable to use function %s in the requested context
bind on a busy prepared statement: [%s]
zeroblob(%d)
abort at %d in [%s]: %s
constraint failed at %d in [%s]
cannot open savepoint - SQL statements in progress
no such savepoint: %s
cannot %s savepoint - SQL statements in progress
cannot rollback transaction - SQL statements in progress
cannot commit transaction - SQL statements in progress
sqlite_temp_master
sqlite_master
SELECT name, rootpage, sql FROM '%q'.%s WHERE %s ORDER BY rowid
cannot change %s wal mode from within a transaction
database table is locked: %s
statement aborts at %d: [%s] %s
cannot open value of type %s
cannot open virtual table: %s
cannot open view: %s
no such column: "%s"
foreign key
indexed
cannot open %s column for writing
misuse of aliased aggregate %s
%s: %s.%s.%s
%s: %s.%s
%s: %s
not authorized to use function: %s
%r %s BY term out of range - should be between 1 and %d
too many terms in %s BY clause
Expression tree is too large (maximum depth %d)
variable number must be between ?1 and ?%d
too many SQL variables
too many columns in %s
EXECUTE %s%s SUBQUERY %d
misuse of aggregate: %s()
%.*s"%w"%s
%s%.*s"%w"
%s OR name=%Q
type='trigger' AND (%s)
sqlite_
table %s may not be altered
there is already another table or index with this name: %s
view %s may not be altered
UPDATE "%w".%s SET sql = sqlite_rename_parent(sql, %Q, %Q) WHERE %s;
UPDATE %Q.%s SET sql = CASE WHEN type = 'trigger' THEN sqlite_rename_trigger(sql, %Q)ELSE sqlite_rename_table(sql, %Q) END, tbl_name = %Q, name = CASE WHEN type='table' THEN %Q WHEN name LIKE 'sqlite_autoindex%%' AND type='index' THEN 'sqlite_autoindex_' || %Q || substr(name,%d 18) ELSE name END WHERE tbl_name=%Q AND (type='table' OR type='index' OR type='trigger');
sqlite_sequence
UPDATE "%w".sqlite_sequence set name = %Q WHERE name = %Q
UPDATE sqlite_temp_master SET sql = sqlite_rename_trigger(sql, %Q), tbl_name = %Q WHERE %s;
Cannot add a PRIMARY KEY column
UPDATE "%w".%s SET sql = substr(sql,1,%d) || ', ' || %Q || substr(sql,%d) WHERE type = 'table' AND name = %Q
sqlite_altertab_%s
CREATE TABLE %Q.%s(%s)
DELETE FROM %Q.%s WHERE %s=%Q
SELECT tbl, idx, stat FROM %Q.sqlite_stat1
invalid name: "%s"
too many attached databases - max %d
database %s is already in use
unable to open database: %s
no such database: %s
cannot detach database %s
database %s is locked
%s %T cannot reference objects in database %s
access to %s.%s.%s is prohibited
access to %s.%s is prohibited
object name reserved for internal use: %s
there is already an index named %s
too many columns on %s
duplicate column name: %s
default value of column [%s] is not constant
table "%s" has more than one primary key
AUTOINCREMENT is only allowed on an INTEGER PRIMARY KEY
no such collation sequence: %s
CREATE %s %.*s
UPDATE %Q.%s SET type='%s', name=%Q, tbl_name=%Q, rootpage=#%d, sql=%Q WHERE rowid=#%d
CREATE TABLE %Q.sqlite_sequence(name,seq)
view %s is circularly defined
UPDATE %Q.%s SET rootpage=%d WHERE #%d AND rootpage=#%d
table %s may not be dropped
use DROP TABLE to delete table %s
use DROP VIEW to delete view %s
DELETE FROM %s.sqlite_sequence WHERE name=%Q
DELETE FROM %Q.%s WHERE tbl_name=%Q and type!='trigger'
DELETE FROM %Q.sqlite_stat1 WHERE tbl=%Q
foreign key on %s should reference only one column of table %T
number of columns in foreign key does not match the number of columns in the referenced table
unknown column "%s" in foreign key definition
indexed columns are not unique
table %s may not be indexed
views may not be indexed
virtual tables may not be indexed
there is already a table named %s
index %s already exists
sqlite_autoindex_%s_%d
table %s has no column named %s
CREATE%s INDEX %.*s
INSERT INTO %Q.%s VALUES('index',%Q,%Q,#%d,%Q);
no such index: %S
index associated with UNIQUE or PRIMARY KEY constraint cannot be dropped
DELETE FROM %Q.%s WHERE name=%Q AND type='index'
DELETE FROM %Q.sqlite_stat1 WHERE idx=%Q
a JOIN clause is required before %s
unable to identify the object to be reindexed
table %s may not be modified
cannot modify %s because it is a view
foreign key mismatch
table %S has %d columns but %d values were supplied
%d values for %d columns
table %S has no column named %s
%s.%s may not be NULL
PRIMARY KEY must be unique
sqlite3_extension_init
unable to open shared library [%s]
no entry point [%s] in shared library [%s]
error during initialization: %s
automatic extension loading failed: %s
foreign_key_list
*** in database %s ***
unsupported encoding: %s
malformed database schema (%s)
%s - %s
unsupported file format
SELECT name, rootpage, sql FROM '%q'.%s ORDER BY rowid
database schema is locked: %s
unknown or unsupported join type: %T %T%s%T
RIGHT and FULL OUTER JOINs are not currently supported
a NATURAL join may not have an ON or USING clause
cannot have both ON and USING clauses in the same join
cannot join using column %s - column not present in both tables
USE TEMP B-TREE FOR %s
COMPOUND SUBQUERIES %d AND %d %s(%s)
%s.%s
%s:%d
ORDER BY clause should come after %s not before
LIMIT clause should come after %s not before
SELECTs to the left and right of %s do not have the same number of result columns
no such index: %s
sqlite_subquery_%p_
no such table: %s
SCAN TABLE %s %s%s(~%d rows)
sqlite3_get_table() called with two or more incompatible queries
cannot create %s trigger on view: %S
cannot create INSTEAD OF trigger on table: %S
INSERT INTO %Q.%s VALUES('trigger',%Q,%Q,0,'CREATE TRIGGER %q')
no such trigger: %S
-- TRIGGER %s
no such column: %s
cannot VACUUM - SQL statements in progress
PRAGMA vacuum_db.synchronous=OFF
SELECT 'CREATE TABLE vacuum_db.' || substr(sql,14) FROM sqlite_master WHERE type='table' AND name!='sqlite_sequence' AND rootpage>0
SELECT 'CREATE INDEX vacuum_db.' || substr(sql,14) FROM sqlite_master WHERE sql LIKE 'CREATE INDEX %'
SELECT 'CREATE UNIQUE INDEX vacuum_db.' || substr(sql,21) FROM sqlite_master WHERE sql LIKE 'CREATE UNIQUE INDEX %'
SELECT 'INSERT INTO vacuum_db.' || quote(name) || ' SELECT * FROM main.' || quote(name) || ';'FROM main.sqlite_master WHERE type = 'table' AND name!='sqlite_sequence' AND rootpage>0
SELECT 'DELETE FROM vacuum_db.' || quote(name) || ';' FROM vacuum_db.sqlite_master WHERE name='sqlite_sequence'
SELECT 'INSERT INTO vacuum_db.' || quote(name) || ' SELECT * FROM main.' || quote(name) || ';' FROM vacuum_db.sqlite_master WHERE name=='sqlite_sequence';
INSERT INTO vacuum_db.sqlite_master SELECT type, name, tbl_name, rootpage, sql FROM main.sqlite_master WHERE type='view' OR type='trigger' OR (type='table' AND rootpage=0)
UPDATE %Q.%s SET type='table', name=%Q, tbl_name=%Q, rootpage=0, sql=%Q WHERE rowid=#%d
vtable constructor failed: %s
vtable constructor did not declare schema: %s
no such module: %s
table %s: xBestIndex returned an invalid plan
%s SUBQUERY %d
%s TABLE %s
%s AS %s
%s USING %s%sINDEX%s%s%s
%s USING INTEGER PRIMARY KEY
%s (rowid=?)
%s (rowid>? AND rowid
%s (rowid>?)
%s (rowid
%s VIRTUAL TABLE INDEX %d:%s
%s (~%lld rows)
at most %d tables in a join
cannot use index: %s
the INDEXED BY clause is not allowed on UPDATE or DELETE statements within triggers
the NOT INDEXED clause is not allowed on UPDATE or DELETE statements within triggers
unable to close due to unfinished backup operation
unknown database: %s
no such %s mode: %s
%s mode not allowed: %s
no such vfs: %s
database corruption at line %d of [%.10s]
misuse at line %d of [%.10s]
cannot open file at line %d of [%.10s]
d:\Autobuild\Work\BrowserExtensions\src\CouponsHelper\bin\Win32\Release\CouponsHelper.pdb
WS2_32.dll
WLDAP32.dll
PeekNamedPipe
KERNEL32.dll
USER32.dll
RegOpenKeyExW
RegCloseKey
RegCreateKeyExW
RegDeleteKeyW
RegQueryInfoKeyW
RegEnumKeyExW
ADVAPI32.dll
ShellExecuteExW
SHELL32.dll
ole32.dll
OLEAUT32.dll
SHLWAPI.dll
USERENV.dll
GetProcessHeap
GetCPInfo
GetConsoleOutputCP
zcÁ
 )**,,,))))
, 2578;:9643.1
-(,0#&=<'&$/
%s~qa
z.geYJ (
.IMGd
B6'>2$@3¤Ôõ÷%H9%H:%H:%K:%K:%K;%I<%K<%L<%N<%K;%I9%H9%H9%H9%H8%H8%H8%H8%H8%H9%I:%J;%J<%J<%K<%N<%P<%O;%K<%J<%K<%L;%J;%H:%H9%G5ôÔ%@3%?2%=1$@5'
4c=.g?/mD-pE pF4uK5wL4uK*nD mC-lB.jA,g?2iC2gB3d@*a<<_5
2-2l2}2P9
3 3$3(3,3
: :$:(:,:0:
< <$<(<,<0<4<8<<<
8 8$8@8^8
7 7@7\7`7
3 3$3(3,30343
mscoree.dll
KERNEL32.DLL
\manifest.json
\firefox
firefox.exe
\install.rdf
\chrome\content\config.json
\chrome
chrome.exe
\config.json
/cpupdate/setupurl
http://update.mybrowserbar.com/update/wt/ie/coupons/update.xml
tmp.exe
coupons_event_5D824970-61D6-4eee-860A-600A48AB5955
\extensions.ini
\extensions.json
\extensions.sqlite
shell32.dll
777705555443332
5555443332
5555443332
SOFTWARE\Mozilla\Mozilla Firefox
\SOFTWARE\Mozilla\Mozilla Firefox
Mozilla\Firefox\
profiles.ini
kernel32.dll
explorer.exe
@Advapi32.dll
Google\Chrome\User Data\Default\
Google\Chrome\User Data\Local State
Software\Google\Chrome\Extensions
Microsoft Windows NT
Microsoft Windows 2000
Microsoft Windows XP SP1
Microsoft Windows XP SP2
Microsoft Windows XP
Microsoft Windows Vista
Microsoft Windows Vista or higher
Microsoft Windows 95
Microsoft Windows 98
Microsoft Windows Me
%s\%s
%Documents and Settings%\%current user%\Application Data\Browser Extensions\CouponsHelper.exe
1, 5, 0, 1
CouponsHelper.exe

MyPC Backup.exe_1212_rwx_03980000_00010000:

%x{8%x{

MyPC Backup.exe_1212_rwx_03FF0000_00010000:

%x{8%x{

MyPC Backup.exe_1212_rwx_04F90000_00010000:

].yEg

MyPC Backup.exe_1212_rwx_04FA0000_00010000:

)-y0}


Remove it with Ad-Aware

  1. Click (here) to download and install Ad-Aware Free Antivirus.
  2. Update the definition files.
  3. Run a full scan of your computer.


Manual removal*

  1. Terminate malicious process(es) (How to End a Process With the Task Manager):

    %original file name%.exe:2104
    BrowserExtensionsSetup.exe:3144
    install.exe:820
    BackupSetup.exe:4068
    msfeedssync.exe:3180
    CouponsHelper.exe:3544
    vcredist_x86.exe:348
    MsiExec.exe:2516
    taskkill.exe:3616
    taskkill.exe:368
    ~sp2E.tmp:3176
    BrowserExtensionsSetupUAC.exe:3536
    SearchProtectionStub.exe:2548
    IEXPLORE.EXE:2676
    Cloud_Backup_Setup.exe:2332
    exthelper.exe:1888

  2. Delete the original program file.
  3. Delete or disinfect the following files created/modified by the program:

    %Program Files%\GreenTree Applications\YTD Video Downloader\plugins\access\.svn\prop-base\libfilesystem_plugin.dll.svn-base (53 bytes)
    %Documents and Settings%\%current user%\Local Settings\Temp\nse28.tmp\eula.rtf (6629 bytes)
    %Program Files%\GreenTree Applications\YTD Video Downloader\COPYING.Apachev2 (11 bytes)
    %Program Files%\GreenTree Applications\YTD Video Downloader\plugins\access\.svn\entries (424 bytes)
    %Program Files%\GreenTree Applications\YTD Video Downloader\plugins\audio_output\libdirectsound_plugin.dll (1552 bytes)
    %Documents and Settings%\%current user%\Local Settings\Temp\nse28.tmp\inst_finish (1 bytes)
    %Program Files%\GreenTree Applications\YTD Video Downloader\plugins\video_output\.svn\text-base\libdirect3d_plugin.dll.svn-base (2392 bytes)
    %Program Files%\GreenTree Applications\YTD Video Downloader\manual.bat (57 bytes)
    %Documents and Settings%\%current user%\Local Settings\Temp\nse28.tmp\MPB_EULA.txt (784 bytes)
    %Program Files%\GreenTree Applications\YTD Video Downloader\plugins\audio_output\.svn\prop-base\libdirectsound_plugin.dll.svn-base (53 bytes)
    %Program Files%\GreenTree Applications\YTD Video Downloader\plugins\video_output\.svn\prop-base\libdirect3d_plugin.dll.svn-base (53 bytes)
    %Documents and Settings%\%current user%\Local Settings\Temp\nse28.tmp\UserInfo.dll (4 bytes)
    %Program Files%\GreenTree Applications\YTD Video Downloader\plugins\video_output\.svn\prop-base\libwingdi_plugin.dll.svn-base (53 bytes)
    %Program Files%\GreenTree Applications\YTD Video Downloader\Lang\res1060.ini (13 bytes)
    %Program Files%\GreenTree Applications\YTD Video Downloader\plugins\audio_output\.svn\all-wcprops (315 bytes)
    %Program Files%\GreenTree Applications\YTD Video Downloader\ytd.exe (49631 bytes)
    %Program Files%\GreenTree Applications\YTD Video Downloader\Lang\res1055.ini (14 bytes)
    %Program Files%\GreenTree Applications\YTD Video Downloader\Lang\res1053.ini (13 bytes)
    %Program Files%\GreenTree Applications\YTD Video Downloader\plugins\video_filter\libswscale_plugin.dll (19096 bytes)
    %Documents and Settings%\%current user%\Local Settings\Temp\nse28.tmp\System.dll (11 bytes)
    %Program Files%\GreenTree Applications\YTD Video Downloader\Uninstall.exe (7446 bytes)
    %Program Files%\GreenTree Applications\YTD Video Downloader\librtmp.dll (60186 bytes)
    %Program Files%\GreenTree Applications\YTD Video Downloader\Lang\res1036.ini (14 bytes)
    %Program Files%\GreenTree Applications\YTD Video Downloader\Lang\res1029.ini (13 bytes)
    %Documents and Settings%\All Users\Start Menu\Programs\YTD Video Downloader\Uninstall.lnk (1 bytes)
    %Program Files%\GreenTree Applications\YTD Video Downloader\plugins\audio_mixer\.svn\text-base\libfloat_mixer_plugin.dll.svn-base (1552 bytes)
    %Program Files%\GreenTree Applications\YTD Video Downloader\plugins\audio_mixer\.svn\prop-base\libfloat_mixer_plugin.dll.svn-base (53 bytes)
    %Documents and Settings%\All Users\Start Menu\Programs\YTD Video Downloader\Web site.url (55 bytes)
    %Program Files%\GreenTree Applications\YTD Video Downloader\LICENSE (1 bytes)
    %Documents and Settings%\%current user%\Local Settings\Temp\nse28.tmp\pixel (1 bytes)
    %Documents and Settings%\All Users\Start Menu\Programs\YTD Video Downloader\YTD Video Downloader.lnk (1 bytes)
    %Program Files%\GreenTree Applications\YTD Video Downloader\Lang\res1033.ini (13 bytes)
    %Program Files%\GreenTree Applications\YTD Video Downloader\Lang\res1051.ini (14 bytes)
    %Program Files%\GreenTree Applications\YTD Video Downloader\Lang\res1026.ini (784 bytes)
    %Program Files%\GreenTree Applications\YTD Video Downloader\scripts.yds (6360 bytes)
    %Program Files%\GreenTree Applications\YTD Video Downloader\plugins\audio_filter\.svn\entries (797 bytes)
    %Documents and Settings%\%current user%\Local Settings\Temp\nso27.tmp (772223 bytes)
    %Program Files%\GreenTree Applications\YTD Video Downloader\Lang\res1059.ini (784 bytes)
    %Documents and Settings%\%current user%\Local Settings\Temp\nse28.tmp\NSISHelper.dll (8560 bytes)
    %Program Files%\GreenTree Applications\YTD Video Downloader\plugins\video_filter\.svn\entries (428 bytes)
    %Program Files%\GreenTree Applications\YTD Video Downloader\plugins\audio_filter\.svn\all-wcprops (711 bytes)
    %Program Files%\GreenTree Applications\YTD Video Downloader\Lang\res2052.ini (12 bytes)
    %Program Files%\GreenTree Applications\YTD Video Downloader\plugins\audio_output\.svn\entries (431 bytes)
    %Program Files%\GreenTree Applications\YTD Video Downloader\COPYING.LGPLv2 (784 bytes)
    %Program Files%\GreenTree Applications\YTD Video Downloader\COPYING.LGPLv3 (7 bytes)
    %Program Files%\GreenTree Applications\YTD Video Downloader\plugins\video_output\.svn\text-base\libwingdi_plugin.dll.svn-base (1856 bytes)
    %Program Files%\GreenTree Applications\YTD Video Downloader\plugins\audio_filter\libugly_resampler_plugin.dll (1552 bytes)
    %Program Files%\GreenTree Applications\YTD Video Downloader\Lang\res1049.ini (784 bytes)
    %Program Files%\GreenTree Applications\YTD Video Downloader\plugins\video_output\.svn\entries (941 bytes)
    %Program Files%\GreenTree Applications\YTD Video Downloader\Lang\res2070.ini (14 bytes)
    %Program Files%\GreenTree Applications\YTD Video Downloader\Lang\res1035.ini (13 bytes)
    %Program Files%\GreenTree Applications\YTD Video Downloader\Lang\res1040.ini (13 bytes)
    %Program Files%\GreenTree Applications\YTD Video Downloader\plugins\video_filter\.svn\text-base\libswscale_plugin.dll.svn-base (19096 bytes)
    %Program Files%\GreenTree Applications\YTD Video Downloader\plugins\video_output\libwingdi_plugin.dll (1856 bytes)
    %Program Files%\GreenTree Applications\YTD Video Downloader\Lang\res1031.ini (14 bytes)
    %Program Files%\GreenTree Applications\YTD Video Downloader\plugins\video_output\.svn\text-base\libdrawable_plugin.dll.svn-base (1552 bytes)
    %Program Files%\GreenTree Applications\YTD Video Downloader\Lang\res1034.ini (14 bytes)
    %Program Files%\GreenTree Applications\YTD Video Downloader\Lang\res1048.ini (14 bytes)
    %Program Files%\GreenTree Applications\YTD Video Downloader\plugins\video_output\.svn\prop-base\libvmem_plugin.dll.svn-base (53 bytes)
    %Program Files%\GreenTree Applications\YTD Video Downloader\plugins\audio_filter\.svn\prop-base\libtrivial_channel_mixer_plugin.dll.svn-base (53 bytes)
    %Documents and Settings%\%current user%\Local Settings\Temp\nse28.tmp\nsDialogs.dll (9 bytes)
    %Program Files%\GreenTree Applications\YTD Video Downloader\plugins\audio_filter\.svn\prop-base\libaudio_format_plugin.dll.svn-base (53 bytes)
    %Program Files%\GreenTree Applications\YTD Video Downloader\Lang\res2074.ini (13 bytes)
    %Program Files%\GreenTree Applications\YTD Video Downloader\plugins\audio_filter\libtrivial_channel_mixer_plugin.dll (1552 bytes)
    %Program Files%\GreenTree Applications\YTD Video Downloader\plugins\video_output\libdirect3d_plugin.dll (2392 bytes)
    %Program Files%\GreenTree Applications\YTD Video Downloader\plugins\video_filter\.svn\prop-base\libswscale_plugin.dll.svn-base (53 bytes)
    %Documents and Settings%\%current user%\Local Settings\Temp\nse28.tmp\tb-header.bmp (3312 bytes)
    %Program Files%\GreenTree Applications\YTD Video Downloader\Lang\res1044.ini (13 bytes)
    %Program Files%\GreenTree Applications\YTD Video Downloader\plugins\codec\libavcodec_plugin.dll (326900 bytes)
    %Program Files%\GreenTree Applications\YTD Video Downloader\plugins\access\.svn\text-base\libfilesystem_plugin.dll.svn-base (1552 bytes)
    %Program Files%\GreenTree Applications\YTD Video Downloader\plugins\audio_filter\.svn\text-base\libugly_resampler_plugin.dll.svn-base (1552 bytes)
    %Program Files%\GreenTree Applications\YTD Video Downloader\libvlc.dll (3616 bytes)
    %Program Files%\GreenTree Applications\YTD Video Downloader\plugins\codec\.svn\all-wcprops (293 bytes)
    %Program Files%\GreenTree Applications\YTD Video Downloader\plugins\access\libfilesystem_plugin.dll (1552 bytes)
    %Program Files%\GreenTree Applications\YTD Video Downloader\Lang\res1025.ini (15 bytes)
    %Program Files%\GreenTree Applications\YTD Video Downloader\plugins\video_output\.svn\text-base\libvmem_plugin.dll.svn-base (1552 bytes)
    %Program Files%\GreenTree Applications\YTD Video Downloader\plugins\video_output\libvmem_plugin.dll (1552 bytes)
    %Program Files%\GreenTree Applications\YTD Video Downloader\plugins\codec\.svn\entries (422 bytes)
    %Program Files%\GreenTree Applications\YTD Video Downloader\plugins\audio_filter\libaudio_format_plugin.dll (1552 bytes)
    %Program Files%\GreenTree Applications\YTD Video Downloader\Lang\res1030.ini (13 bytes)
    %Program Files%\GreenTree Applications\YTD Video Downloader\Lang\res9999.ini (784 bytes)
    %Program Files%\GreenTree Applications\YTD Video Downloader\plugins\video_output\.svn\all-wcprops (831 bytes)
    %Program Files%\GreenTree Applications\YTD Video Downloader\plugins\access\.svn\all-wcprops (301 bytes)
    %Documents and Settings%\%current user%\Local Settings\Temp\nse28.tmp\modern-header.bmp (6624 bytes)
    %Documents and Settings%\%current user%\Local Settings\Temp\nse28.tmp\Cloud_Backup_Setup.exe (6360 bytes)
    %Program Files%\GreenTree Applications\YTD Video Downloader\plugins\video_filter\.svn\all-wcprops (307 bytes)
    %Program Files%\GreenTree Applications\YTD Video Downloader\plugins\audio_mixer\.svn\prop-base\libinteger_mixer_plugin.dll.svn-base (53 bytes)
    %Program Files%\GreenTree Applications\YTD Video Downloader\Lang\res1061.ini (13 bytes)
    %Documents and Settings%\%current user%\Local Settings\Temp\nse28.tmp\SearchProtectionStub.exe (13368 bytes)
    %Program Files%\GreenTree Applications\YTD Video Downloader\plugins\audio_mixer\libinteger_mixer_plugin.dll (1552 bytes)
    %Program Files%\GreenTree Applications\YTD Video Downloader\libvlccore.dll (69435 bytes)
    %Program Files%\GreenTree Applications\YTD Video Downloader\plugins\audio_filter\.svn\text-base\libtrivial_channel_mixer_plugin.dll.svn-base (1552 bytes)
    %Program Files%\GreenTree Applications\YTD Video Downloader\Lang\res1032.ini (784 bytes)
    %Documents and Settings%\All Users\Desktop\YTD Video Downloader.lnk (942 bytes)
    %Program Files%\GreenTree Applications\YTD Video Downloader\FFMPEG.EXE (395158 bytes)
    %Program Files%\GreenTree Applications\YTD Video Downloader\plugins\video_output\libdrawable_plugin.dll (1552 bytes)
    %Program Files%\GreenTree Applications\YTD Video Downloader\Lang\res1052.ini (13 bytes)
    %Program Files%\GreenTree Applications\YTD Video Downloader\Lang\res1045.ini (13 bytes)
    %Program Files%\GreenTree Applications\YTD Video Downloader\plugins\video_output\.svn\prop-base\libdrawable_plugin.dll.svn-base (53 bytes)
    %Program Files%\GreenTree Applications\YTD Video Downloader\plugins\audio_mixer\.svn\text-base\libinteger_mixer_plugin.dll.svn-base (1552 bytes)
    %Program Files%\GreenTree Applications\YTD Video Downloader\plugins\audio_mixer\.svn\entries (608 bytes)
    %Documents and Settings%\%current user%\Local Settings\Temp\nse28.tmp\inst_start (1 bytes)
    %Documents and Settings%\%current user%\Local Settings\Temp\nse28.tmp\getCountry (2 bytes)
    %Program Files%\GreenTree Applications\YTD Video Downloader\plugins\audio_filter\.svn\prop-base\libugly_resampler_plugin.dll.svn-base (53 bytes)
    %Program Files%\GreenTree Applications\YTD Video Downloader\plugins\audio_output\.svn\text-base\libdirectsound_plugin.dll.svn-base (1552 bytes)
    %Program Files%\GreenTree Applications\YTD Video Downloader\plugins\audio_filter\.svn\text-base\libaudio_format_plugin.dll.svn-base (1552 bytes)
    %Program Files%\GreenTree Applications\YTD Video Downloader\plugins\audio_mixer\libfloat_mixer_plugin.dll (1552 bytes)
    %Program Files%\GreenTree Applications\YTD Video Downloader\plugins\audio_mixer\.svn\all-wcprops (500 bytes)
    %Program Files%\GreenTree Applications\YTD Video Downloader\Lang\res1050.ini (14 bytes)
    %Program Files%\GreenTree Applications\YTD Video Downloader\Lang\res1038.ini (13 bytes)
    %Program Files%\GreenTree Applications\YTD Video Downloader\plugins\codec\.svn\text-base\libavcodec_plugin.dll.svn-base (326900 bytes)
    %Program Files%\GreenTree Applications\YTD Video Downloader\plugins\codec\.svn\prop-base\libavcodec_plugin.dll.svn-base (53 bytes)
    %Documents and Settings%\%current user%\Local Settings\Temp\nse28.tmp\exthelper.exe (49441 bytes)
    %Documents and Settings%\%current user%\Local Settings\Temp\nse28.tmp\NSISdl.dll (784 bytes)
    %Program Files%\GreenTree Applications\YTD Video Downloader\Lang\res1043.ini (13 bytes)
    %Documents and Settings%\%current user%\Application Data\Browser Extensions\nta_1.0.crx (1856 bytes)
    %Documents and Settings%\%current user%\Local Settings\Temp\nsh34.tmp\UserInfo.dll (4 bytes)
    %Documents and Settings%\%current user%\Application Data\Browser Extensions\Coupons64.dll (23936 bytes)
    %Documents and Settings%\%current user%\Local Settings\Temp\nsh34.tmp\NSISCouponsPlugin.dll (17848 bytes)
    %Documents and Settings%\%current user%\Application Data\Browser Extensions\CouponsHelper.exe (32128 bytes)
    %Documents and Settings%\%current user%\Application Data\Browser Extensions\ButtonWrap.dll (8184 bytes)
    %Documents and Settings%\%current user%\Local Settings\Temp\nss33.tmp (97299 bytes)
    %Documents and Settings%\%current user%\Application Data\Browser Extensions\deh_1.0.crx (16 bytes)
    %Documents and Settings%\%current user%\Application Data\Browser Extensions\sh_1.0.crx (14 bytes)
    %Documents and Settings%\%current user%\Application Data\Browser Extensions\Button.exe (1856 bytes)
    %Documents and Settings%\%current user%\Local Settings\Temp\nsh34.tmp\System.dll (11 bytes)
    %Documents and Settings%\%current user%\Local Settings\Temp\nsh34.tmp\BrowserExtensionsSetupUAC.exe (16288 bytes)
    %Documents and Settings%\%current user%\Application Data\Browser Extensions\startpage_2.2.xpi (10 bytes)
    %Documents and Settings%\%current user%\Application Data\Browser Extensions\saamazon_1.6.xpi (7 bytes)
    %Documents and Settings%\%current user%\Application Data\Browser Extensions\Button64.exe (1856 bytes)
    %Documents and Settings%\%current user%\Application Data\Browser Extensions\amazonsh_1.0.crx (9 bytes)
    %Documents and Settings%\%current user%\Application Data\Browser Extensions\coupons_3.1.xpi (10 bytes)
    %Documents and Settings%\%current user%\Application Data\Browser Extensions\Uninstall.exe (14510 bytes)
    %Documents and Settings%\%current user%\Application Data\Browser Extensions\Coupons.dll (20416 bytes)
    %Documents and Settings%\%current user%\Application Data\Browser Extensions\saebay_1.6.xpi (6 bytes)
    %Documents and Settings%\%current user%\Application Data\Browser Extensions\ButtonWrap64.dll (8560 bytes)
    %Documents and Settings%\%current user%\Local Settings\Temp\dd_vcredistMSI736A.txt (542765 bytes)
    %Documents and Settings%\%current user%\Local Settings\Temp\VWL42.tmp (392 bytes)
    %Documents and Settings%\%current user%\Local Settings\Temp\dd_vcredistUI736A.txt (130962 bytes)
    %Documents and Settings%\%current user%\Local Settings\Application Data\Microsoft\Internet Explorer\Services\search_{40DCF3A0-1630-482F-A96D-61C44FD2F2B3}.ico (1107 bytes)
    %Documents and Settings%\%current user%\Local Settings\Application Data\Google\Chrome\User Data\Default\Web Data-journal (13210 bytes)
    %Documents and Settings%\%current user%\Local Settings\Temp\yahoo_ie.xml (459 bytes)
    %Documents and Settings%\%current user%\Local Settings\Application Data\Google\Chrome\User Data\Default\Preferences (117 bytes)
    %Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\WJYHCPG4\favicon[1].ico (1340 bytes)
    %Documents and Settings%\%current user%\Local Settings\Temp\yahoo_ff.xml (803 bytes)
    %Documents and Settings%\%current user%\Application Data\Mozilla\Firefox\Profiles\rsxjpslc.default\searchplugins\yahoo_ff.xml (1606 bytes)
    %Documents and Settings%\%current user%\Local Settings\Application Data\Google\Chrome\User Data\Local State (58 bytes)
    %Documents and Settings%\%current user%\Application Data\Mozilla\Firefox\Profiles\rsxjpslc.default\prefs.js (72 bytes)
    %Program Files%\MyPC Backup\UnRegisterExtensions.exe (15 bytes)
    %Program Files%\MyPC Backup\Database\mpcb_file_cache.db (7 bytes)
    %Program Files%\MyPC Backup\AWSSDK.dll (71948 bytes)
    %Program Files%\MyPC Backup\Database\mpcb_sig_cache.db (6 bytes)
    %Documents and Settings%\%current user%\Local Settings\Temp\nsg39.tmp\System.dll (11 bytes)
    %Program Files%\MyPC Backup\mypcbackup.ico (7146 bytes)
    %Program Files%\MyPC Backup\Crypto32.dll (2716 bytes)
    %Program Files%\MyPC Backup\syncicon.ico (3454 bytes)
    %Documents and Settings%\%current user%\Local Settings\Temp\vcredist_x86.exe (382688 bytes)
    %Program Files%\MyPC Backup\diffstack.dll (2980 bytes)
    %Program Files%\MyPC Backup\AlphaVSS.60.x86.dll (5823 bytes)
    %Program Files%\MyPC Backup\Crypto64.dll (2300 bytes)
    %Program Files%\MyPC Backup\AlphaVSS.Common.dll (3296 bytes)
    %Program Files%\MyPC Backup\Database\mpcb_backup_conf.db (16 bytes)
    %Program Files%\MyPC Backup\Service Start.exe (14 bytes)
    %Documents and Settings%\%current user%\Local Settings\Temp\nsg39.tmp\ns3B.tmp (6 bytes)
    %Program Files%\MyPC Backup\x86\System.Data.SQLite.dll (20659 bytes)
    %Program Files%\MyPC Backup\AlphaVSS.52.x64.dll (4240 bytes)
    %Program Files%\MyPC Backup\BackupStack.exe (1938 bytes)
    %Program Files%\MyPC Backup\uninst.exe (1797 bytes)
    %Program Files%\MyPC Backup\AlphaVSS.51.x86.dll (4106 bytes)
    %Program Files%\MyPC Backup\RegisterExtensionDotNet20_x86.exe (20 bytes)
    %Program Files%\MyPC Backup\es_ES.mo (1831 bytes)
    %Documents and Settings%\%current user%\Local Settings\Temp\nsg39.tmp\nsRandom.dll (479 bytes)
    %Documents and Settings%\%current user%\Desktop\MyPC Backup.lnk (762 bytes)
    %Documents and Settings%\%current user%\Local Settings\Temp\nsg39.tmp\NSISdl.dll (14 bytes)
    %Program Files%\MyPC Backup\GetText.dll (12 bytes)
    %Program Files%\MyPC Backup\Shared Stack.dll (62611 bytes)
    %Program Files%\MyPC Backup\MPCBContextMenu.dll (149087 bytes)
    %Program Files%\MyPC Backup\LogicNP.EZShellExtensions.dll (6579 bytes)
    %Program Files%\MyPC Backup\Updater.exe (30085 bytes)
    %Documents and Settings%\%current user%\Local Settings\Temp\mpbtrk.log (8 bytes)
    %Program Files%\MyPC Backup\tick.ico (8864 bytes)
    %Program Files%\MyPC Backup\Signup Wizard.exe (24414 bytes)
    %Program Files%\MyPC Backup\de_DE.mo (1702 bytes)
    %Program Files%\MyPC Backup\AlphaVSS.60.x64.dll (6324 bytes)
    %Documents and Settings%\%current user%\Local Settings\Temp\nsg39.tmp\ns3A.tmp (6 bytes)
    %Program Files%\MyPC Backup\MyPC Backup.exe (64373 bytes)
    %Program Files%\MyPC Backup\syncing.ico (7445 bytes)
    %Program Files%\MyPC Backup\MPCBIconOverlays.dll (85918 bytes)
    %Documents and Settings%\%current user%\Start Menu\Programs\Startup\MyPC Backup.lnk (748 bytes)
    %Documents and Settings%\%current user%\Local Settings\Temp\nsg39.tmp\AccessControl.dll (8 bytes)
    %Documents and Settings%\%current user%\Start Menu\Programs\MyPC Backup\MyPC Backup.lnk (774 bytes)
    %Program Files%\MyPC Backup\Database\mpcb_queues.db (13 bytes)
    %Program Files%\MyPC Backup\AlphaVSS.52.x86.dll (5025 bytes)
    %Program Files%\MyPC Backup\RegisterExtensionDotNet20_x64.exe (16 bytes)
    %Program Files%\MyPC Backup\it_IT.mo (1925 bytes)
    %Documents and Settings%\%current user%\Local Settings\Temp\nsg39.tmp\nsSCM.dll (5 bytes)
    %Program Files%\MyPC Backup\pt_PT.mo (1605 bytes)
    %Program Files%\MyPC Backup\MPCBClient.dll (28694 bytes)
    %Program Files%\MyPC Backup\ObjectListView.dll (13129 bytes)
    %Program Files%\MyPC Backup\fr_FR.mo (1621 bytes)
    %Program Files%\MyPC Backup\Database\mpcb_settings.db (9 bytes)
    %Program Files%\MyPC Backup\RestartExplorer.exe (16 bytes)
    %Documents and Settings%\%current user%\Local Settings\Temp\nsg39.tmp\DotNetChecker.dll (1123 bytes)
    %Program Files%\MyPC Backup\Configuration Updater.exe (16 bytes)
    %Documents and Settings%\%current user%\Local Settings\Temp\nsg39.tmp\nsExec.dll (6 bytes)
    %Program Files%\MyPC Backup\x64\System.Data.SQLite.dll (20635 bytes)
    %Documents and Settings%\%current user%\Start Menu\Programs\MyPC Backup\Uninstall.lnk (545 bytes)
    %WinDir%\Tasks\User_Feed_Synchronization-{414D0F7C-B684-437B-B53E-8AB5AE32E070}.job (416 bytes)
    %Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\SuggestedSites.dat (4 bytes)
    %Documents and Settings%\%current user%\Local Settings\Application Data\Microsoft\Feeds\{5588ACFD-6436-411B-A5CE-666AE6A92D3D}~\WebSlices~\Web Slice Gallery~.feed-ms (2176 bytes)
    %Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\AAE8OMVS\ie8[1].txt (644 bytes)
    %Documents and Settings%\%current user%\Local Settings\Application Data\Microsoft\Feeds\FeedsStore.feedsdb-ms (14084 bytes)
    %Documents and Settings%\%current user%\Local Settings\Application Data\Microsoft\Feeds\Microsoft Feeds~\Microsoft at Work~.feed-ms (3314 bytes)
    %Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\E9UY92VW\rss[1].xml (6141 bytes)
    %Documents and Settings%\%current user%\Local Settings\Application Data\Microsoft\Feeds\Microsoft Feeds~\Microsoft at Home~.feed-ms (3314 bytes)
    %Documents and Settings%\%current user%\Local Settings\Application Data\Microsoft\Feeds\{5588ACFD-6436-411B-A5CE-666AE6A92D3D}~\Internet Explorer Suggested Sites~.feed-ms (2184 bytes)
    %Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\X33TH0UP\rss[1].xml (5486 bytes)
    %Documents and Settings%\%current user%\Application Data\Mozilla\Firefox\Profiles\rsxjpslc.default\extensions\{58d2a791-6199-482f-a9aa-9b725ec61362}_tmp\chrome\content\main.xul (681 bytes)
    %Documents and Settings%\%current user%\Application Data\Mozilla\Firefox\Profiles\rsxjpslc.default\extensions\{58d2a791-6199-482f-a9aa-9b725ec61362}_tmp\chrome\content\config.json (225 bytes)
    %Documents and Settings%\%current user%\Application Data\Mozilla\Firefox\Profiles\rsxjpslc.default\extensions\[email protected]_tmp\chrome\content\amazon.xul (583 bytes)
    %Documents and Settings%\%current user%\Application Data\Mozilla\Firefox\Profiles\rsxjpslc.default\extensions\[email protected]_tmp\chrome\content\main.js (367 bytes)
    %Documents and Settings%\%current user%\Application Data\Mozilla\Firefox\Profiles\rsxjpslc.default\extensions\[email protected]_tmp\chrome\content\spigot.js (3 bytes)
    %Documents and Settings%\%current user%\Application Data\Mozilla\Firefox\Profiles\rsxjpslc.default\extensions\[email protected]_tmp\chrome\content\saebay.js (2 bytes)
    %Documents and Settings%\%current user%\Application Data\Mozilla\Firefox\Profiles\rsxjpslc.default\extensions\[email protected]_tmp\install.rdf (1 bytes)
    %Documents and Settings%\%current user%\Application Data\Mozilla\Firefox\Profiles\rsxjpslc.default\extensions\{58d2a791-6199-482f-a9aa-9b725ec61362}_tmp\chrome\content\prefs.txt (171 bytes)
    %Documents and Settings%\%current user%\Application Data\Mozilla\Firefox\Profiles\rsxjpslc.default\extensions.json (31 bytes)
    %Documents and Settings%\%current user%\Application Data\Mozilla\Firefox\Profiles\rsxjpslc.default\extensions\{58d2a791-6199-482f-a9aa-9b725ec61362}_tmp\chrome\content\newtab.xul (1 bytes)
    %Documents and Settings%\%current user%\Application Data\Mozilla\Firefox\Profiles\rsxjpslc.default\extensions\[email protected]_tmp\chrome\content\config.json (292 bytes)
    %Documents and Settings%\%current user%\Application Data\Mozilla\Firefox\Profiles\rsxjpslc.default\extensions\[email protected]_tmp\icon.png (196 bytes)
    %Documents and Settings%\%current user%\Application Data\Mozilla\Firefox\Profiles\rsxjpslc.default\extensions\{58d2a791-6199-482f-a9aa-9b725ec61362}_tmp\chrome\content\redirects.js (196 bytes)
    %Documents and Settings%\%current user%\Application Data\Mozilla\Firefox\Profiles\rsxjpslc.default\extensions\[email protected]_tmp\chrome.manifest (148 bytes)
    %Documents and Settings%\%current user%\Application Data\Mozilla\Firefox\Profiles\rsxjpslc.default\extensions\[email protected]_tmp\chrome\content\prefs.txt (14 bytes)
    %Documents and Settings%\%current user%\Application Data\Mozilla\Firefox\Profiles\rsxjpslc.default\extensions\[email protected]_tmp\chrome\content\spigot.js (2 bytes)
    %Documents and Settings%\%current user%\Application Data\Mozilla\Firefox\Profiles\rsxjpslc.default\extensions\{58d2a791-6199-482f-a9aa-9b725ec61362}_tmp\chrome\content\main.js (397 bytes)
    %Documents and Settings%\%current user%\Application Data\Mozilla\Firefox\Profiles\rsxjpslc.default\extensions\[email protected]_tmp\chrome\content\main.js (359 bytes)
    %Documents and Settings%\%current user%\Application Data\Mozilla\Firefox\Profiles\rsxjpslc.default\extensions\{58d2a791-6199-482f-a9aa-9b725ec61362}_tmp\chrome.manifest (192 bytes)
    %Documents and Settings%\%current user%\Application Data\Mozilla\Firefox\Profiles\rsxjpslc.default\extensions\[email protected]\chrome\content\config.json (295 bytes)
    %Documents and Settings%\%current user%\Application Data\Mozilla\Firefox\Profiles\rsxjpslc.default\extensions\[email protected]_tmp\chrome\content\main.js (386 bytes)
    %Documents and Settings%\%current user%\Application Data\Mozilla\Firefox\Profiles\rsxjpslc.default\extensions\[email protected]_tmp\chrome\content\amazon.png (1 bytes)
    %Documents and Settings%\%current user%\Application Data\Mozilla\Firefox\Profiles\rsxjpslc.default\extensions\{58d2a791-6199-482f-a9aa-9b725ec61362}_tmp\chrome\content\spigot.js (3 bytes)
    %Documents and Settings%\%current user%\Application Data\Mozilla\Firefox\Profiles\rsxjpslc.default\extensions\{58d2a791-6199-482f-a9aa-9b725ec61362}_tmp\chrome\content\startpage.js (392 bytes)
    %Documents and Settings%\%current user%\Application Data\Mozilla\Firefox\Profiles\rsxjpslc.default\extensions\[email protected]_tmp\icon.png (2 bytes)
    %Documents and Settings%\%current user%\Application Data\Mozilla\Firefox\Profiles\rsxjpslc.default\extensions\{58d2a791-6199-482f-a9aa-9b725ec61362}\chrome\content\config.json (278 bytes)
    %Documents and Settings%\%current user%\Application Data\Mozilla\Firefox\Profiles\rsxjpslc.default\extensions\{58d2a791-6199-482f-a9aa-9b725ec61362}_tmp\icon.png (1 bytes)
    %Documents and Settings%\%current user%\Application Data\Mozilla\Firefox\Profiles\rsxjpslc.default\extensions\[email protected]_tmp\chrome\content\prefs.txt (110 bytes)
    %Documents and Settings%\%current user%\Application Data\Mozilla\Firefox\Profiles\rsxjpslc.default\extensions\[email protected]_tmp\chrome\content\ebay.png (1 bytes)
    %Documents and Settings%\%current user%\Application Data\Mozilla\Firefox\Profiles\rsxjpslc.default\extensions\{58d2a791-6199-482f-a9aa-9b725ec61362}_tmp\install.rdf (1 bytes)
    %Documents and Settings%\%current user%\Application Data\Mozilla\Firefox\Profiles\rsxjpslc.default\extensions\[email protected]_tmp\chrome\content\savingsslider.xul (606 bytes)
    %Documents and Settings%\%current user%\Application Data\Mozilla\Firefox\Profiles\rsxjpslc.default\extensions\[email protected]_tmp\chrome\content\savingsslider.js (392 bytes)
    %Documents and Settings%\%current user%\Application Data\Mozilla\Firefox\Profiles\rsxjpslc.default\extensions\[email protected]_tmp\chrome.manifest (125 bytes)
    %Documents and Settings%\%current user%\Application Data\Mozilla\Firefox\Profiles\rsxjpslc.default\extensions\[email protected]_tmp\chrome\content\saamazon.js (2 bytes)
    %Documents and Settings%\%current user%\Application Data\Mozilla\Firefox\Profiles\rsxjpslc.default\extensions\[email protected]_tmp\chrome\content\spigot.js (2 bytes)
    %Documents and Settings%\%current user%\Application Data\Mozilla\Firefox\Profiles\rsxjpslc.default\extensions\[email protected]_tmp\icon.png (1 bytes)
    %Documents and Settings%\%current user%\Application Data\Mozilla\Firefox\Profiles\rsxjpslc.default\extensions\[email protected]_tmp\install.rdf (1 bytes)
    %Documents and Settings%\%current user%\Application Data\Mozilla\Firefox\Profiles\rsxjpslc.default\extensions\[email protected]_tmp\install.rdf (1 bytes)
    %Documents and Settings%\%current user%\Application Data\Mozilla\Firefox\Profiles\rsxjpslc.default\extensions\[email protected]_tmp\chrome.manifest (131 bytes)
    %Documents and Settings%\%current user%\Application Data\Mozilla\Firefox\Profiles\rsxjpslc.default\extensions\[email protected]_tmp\chrome\content\ebay.xul (569 bytes)
    %Documents and Settings%\%current user%\Application Data\Mozilla\Firefox\Profiles\rsxjpslc.default\extensions\[email protected]_tmp\chrome\content\prefs.txt (12 bytes)
    C:\e22922a92f95b9889678f2\eula.1040.txt (13 bytes)
    C:\e22922a92f95b9889678f2\install.res.1042.dll (1851 bytes)
    C:\e22922a92f95b9889678f2\install.res.1028.dll (693 bytes)
    C:\e22922a92f95b9889678f2\install.res.1036.dll (1925 bytes)
    C:\e22922a92f95b9889678f2\$shtdwn$.req (788 bytes)
    C:\e22922a92f95b9889678f2\install.res.1033.dll (1390 bytes)
    C:\e22922a92f95b9889678f2\eula.1033.txt (10 bytes)
    C:\e22922a92f95b9889678f2\install.ini (844 bytes)
    C:\e22922a92f95b9889678f2\install.res.1040.dll (1754 bytes)
    C:\e22922a92f95b9889678f2\globdata.ini (1 bytes)
    C:\e22922a92f95b9889678f2\eula.2052.txt (405 bytes)
    C:\e22922a92f95b9889678f2\install.res.1041.dll (983 bytes)
    C:\e22922a92f95b9889678f2\vc_red.msi (3475 bytes)
    C:\e22922a92f95b9889678f2\eula.1036.txt (224 bytes)
    C:\e22922a92f95b9889678f2\eula.1041.txt (5 bytes)
    C:\e22922a92f95b9889678f2\eula.1028.txt (3 bytes)
    C:\e22922a92f95b9889678f2\install.exe (8790 bytes)
    C:\e22922a92f95b9889678f2\vcredist.bmp (5 bytes)
    C:\e22922a92f95b9889678f2\eula.3082.txt (12 bytes)
    C:\e22922a92f95b9889678f2\eula.1042.txt (5 bytes)
    C:\e22922a92f95b9889678f2\eula.1049.txt (387 bytes)
    C:\e22922a92f95b9889678f2\vc_red.cab (56236 bytes)
    C:\e22922a92f95b9889678f2\install.res.3082.dll (1487 bytes)
    C:\e22922a92f95b9889678f2\install.res.2052.dll (1368 bytes)
    C:\e22922a92f95b9889678f2\install.res.1049.dll (1437 bytes)
    C:\e22922a92f95b9889678f2\install.res.1031.dll (1585 bytes)
    C:\e22922a92f95b9889678f2\eula.1031.txt (15 bytes)
    %Documents and Settings%\%current user%\Application Data\Search Protection\SearchProtection.exe (28288 bytes)
    %Documents and Settings%\%current user%\Local Settings\Temp\nsz30.tmp (107044 bytes)
    %Documents and Settings%\%current user%\Local Settings\Temp\nsz31.tmp\BrowserExtensionsSetup.exe (60186 bytes)
    %Documents and Settings%\%current user%\Local Settings\Temp\nsz31.tmp\SDSPlugin.dll (22552 bytes)
    %Documents and Settings%\%current user%\Application Data\Search Protection\Uninstall.exe (12076 bytes)
    %Documents and Settings%\%current user%\Local Settings\Temp\nsz31.tmp\System.dll (11 bytes)
    %Documents and Settings%\%current user%\Local Settings\Temp\nsj37.tmp\System.dll (11 bytes)
    %Documents and Settings%\%current user%\Local Settings\Temp\nst36.tmp (14354 bytes)
    %Documents and Settings%\%current user%\Local Settings\Temp\nsj37.tmp\UserInfo.dll (4 bytes)
    %Documents and Settings%\%current user%\Local Settings\Temp\nsj37.tmp\NSISCouponsPlugin.dll (17848 bytes)
    %Documents and Settings%\%current user%\Local Settings\Temp\nsu2D.tmp\SDSPlugin.dll (22552 bytes)
    %Documents and Settings%\%current user%\Local Settings\Temp\nsu2D.tmp\System.dll (11 bytes)
    %Documents and Settings%\%current user%\Local Settings\Temp\nsu2C.tmp (19153 bytes)
    %Documents and Settings%\%current user%\Local Settings\Temp\~sp2E.tmp (321984 bytes)
    %Documents and Settings%\%current user%\Cookies\7KKWMT6B.txt (72 bytes)
    %Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\WJYHCPG4\thankyou[1].htm (413 bytes)
    %Documents and Settings%\%current user%\Cookies\A8WL5QB4.txt (919 bytes)
    %Documents and Settings%\%current user%\Local Settings\Application Data\Microsoft\Internet Explorer\DOMStore\7R8AXHHW\www.ytddownloader[1].xml (411 bytes)
    %Documents and Settings%\%current user%\Cookies\3K5PFZ4L.txt (241 bytes)
    %Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\E9UY92VW\favicon[1].ico (9513 bytes)
    %Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\AAE8OMVS\dgdTycPTSRj[1].js (1186 bytes)
    %Documents and Settings%\%current user%\Cookies\Y3E99XUS.txt (613 bytes)
    %Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\WJYHCPG4\jquery.min[1].js (61363 bytes)
    %Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\X33TH0UP\top-header-bg[1].jpg (140 bytes)
    %Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\X33TH0UP\ytd-logo[1].png (14728 bytes)
    %Documents and Settings%\%current user%\Cookies\56E8VQFU.txt (87 bytes)
    %Documents and Settings%\%current user%\Cookies\IO95CMW0.txt (385 bytes)
    %Documents and Settings%\%current user%\Cookies\PJAYQ3JJ.txt (285 bytes)
    %Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\WJYHCPG4\header-bg[1].jpg (43912 bytes)
    %Documents and Settings%\%current user%\Cookies\DEJ3GPCM.txt (327 bytes)
    %Documents and Settings%\%current user%\Cookies\TW0Y1UD8.txt (613 bytes)
    %Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\AAE8OMVS\styles[1].css (4529 bytes)
    %Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\X33TH0UP\core131[1].js (121395 bytes)
    %Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\AAE8OMVS\sh158[1].html (9923 bytes)
    %Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\AAE8OMVS\counter017[1].js (5915 bytes)
    %Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\AAE8OMVS\widget120[1].css (45783 bytes)
    %Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\E9UY92VW\all[1].js (87362 bytes)
    %Documents and Settings%\%current user%\Cookies\4JILEPXF.txt (85 bytes)
    %Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\E9UY92VW\upgrade-pro-btn[1].png (6454 bytes)
    %Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\WJYHCPG4\header-bg-repeat[1].jpg (140 bytes)
    %Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\AAE8OMVS\counter014[1].css (2977 bytes)
    %Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\WJYHCPG4\300lo[1].json (91 bytes)
    %Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\X33TH0UP\shares[1].json (55 bytes)
    %Documents and Settings%\%current user%\Cookies\V9ILT370.txt (129 bytes)
    %Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\AAE8OMVS\dgdTycPTSRj[1].htm (1970 bytes)
    %Documents and Settings%\%current user%\Local Settings\Application Data\Microsoft\Internet Explorer\DOMStore\YYGJFIDB\s7.addthis[1].xml (26 bytes)
    %Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\AAE8OMVS\dgdTycPTSRj[2].htm (1094 bytes)
    %Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\AAE8OMVS\main[1].js (25 bytes)
    %Documents and Settings%\%current user%\Cookies\NBF8N5AK.txt (297 bytes)
    %Documents and Settings%\%current user%\Cookies\O468AV3W.txt (697 bytes)
    %Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\E9UY92VW\ga[1].js (28634 bytes)
    %Documents and Settings%\%current user%\Cookies\0KPRCZS7.txt (555 bytes)
    %Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\E9UY92VW\addthis_widget[1].js (3069 bytes)
    %Documents and Settings%\%current user%\Local Settings\Temp\~DFF65E.tmp (4605 bytes)
    %Documents and Settings%\%current user%\Local Settings\Temp\~DFDEEC.tmp (3263 bytes)
    %Documents and Settings%\%current user%\Local Settings\Application Data\Microsoft\Internet Explorer\Recovery\Active\RecoveryStore.{B5B36C2E-DAAE-11E3-81D1-0050563EC483}.dat (15783 bytes)
    %Documents and Settings%\%current user%\Local Settings\Application Data\Microsoft\Internet Explorer\Recovery\Active\{B5B36C2F-DAAE-11E3-81D1-0050563EC483}.dat (18695 bytes)
    %Documents and Settings%\%current user%\Application Data\Microsoft\CryptnetUrlCache\Content\8DFDF057024880D7A081AFBF6D26B92F (533 bytes)
    %Documents and Settings%\%current user%\Application Data\Microsoft\CryptnetUrlCache\MetaData\D236B74794790D9923905972356B8BEC (448 bytes)
    %Documents and Settings%\%current user%\Local Settings\Temp\Cab3D.tmp (54 bytes)
    %Documents and Settings%\%current user%\Local Settings\Temp\Tar3E.tmp (2712 bytes)
    %Documents and Settings%\%current user%\Application Data\Microsoft\CryptnetUrlCache\Content\62B5AF9BE9ADC1085C3C56EC07A82BF6 (126 bytes)
    %Documents and Settings%\%current user%\Application Data\Microsoft\CryptnetUrlCache\Content\D236B74794790D9923905972356B8BEC (2 bytes)
    %Documents and Settings%\%current user%\Application Data\Microsoft\CryptnetUrlCache\MetaData\8DFDF057024880D7A081AFBF6D26B92F (176 bytes)
    %Documents and Settings%\%current user%\Application Data\Microsoft\CryptnetUrlCache\MetaData\62B5AF9BE9ADC1085C3C56EC07A82BF6 (224 bytes)
    %Documents and Settings%\%current user%\Desktop\Sync Folder.lnk (1 bytes)
    %Program Files%\MyPC Backup\log\WAIT_HANDLES.log (540 bytes)
    %Program Files%\MyPC Backup\Database\mpcb_settings.db-journal (27036 bytes)
    %Documents and Settings%\%current user%\Local Settings\Temp\aff.conf (182 bytes)
    %Documents and Settings%\%current user%\Local Settings\Temp\nsh2A.tmp\LogEx.dll (1568 bytes)
    %Documents and Settings%\%current user%\Local Settings\Temp\log.txt (28 bytes)
    %Documents and Settings%\%current user%\Local Settings\Temp\nsh2A.tmp\NSISdl.dll (14 bytes)
    %Documents and Settings%\%current user%\Local Settings\Temp\BackupSetup.exe (1052338 bytes)

  4. Delete the following value(s) in the autorun key (How to Work with System Registry):

    [HKCU\Software\Microsoft\Windows\CurrentVersion\Run]
    "Browser Extensions" = "%Documents and Settings%\%current user%\Application Data\Browser Extensions\CouponsHelper.exe"

    [HKCU\Software\Microsoft\Windows\CurrentVersion\Run]
    "SearchProtection" = "%Documents and Settings%\%current user%\Application Data\Search Protection\SearchProtection.EXE /autostart"

  5. Clean the Temporary Internet Files folder, which may contain infected files (How to clean Temporary Internet Files folder).
  6. Reboot the computer.

*Manual removal may cause unexpected system behaviour and should be performed at your own risk.

No votes yet

x

Our best antivirus yet!

Fresh new look. Faster scanning. Better protection.

Enjoy unique new features, lightning fast scans and a simple yet beautiful new look in our best antivirus yet!

For a quicker, lighter and more secure experience, download the all new adaware antivirus 12 now!

Download adaware antivirus 12
No thanks, continue to lavasoft.com
close x

Discover the new adaware antivirus 12

Our best antivirus yet

Download Now