Jump to content

what is domain: wmi.mykings.top BLOCKED


Recommended Posts

Hi tommybio :)

My name is Aura and I'll be assisting you with your malware issue. Since we'll be working together, you can call me Aura or Yoan, which is my real name, it's up to you! Now that we've broke the ice, I'll just ask you a few things during the time we'll be working together to clean your system and get it back to an operational state.

  • As you'll notice, the logs we are asking for here are quite lenghty, so it's normal for me to not reply exactly after you post them. This is because I need some time to analyse them and then act accordingly. However, I'll always reply within 24 hours, 48 hours at most if something unexpected happens
  • As long as I'm assisting you on Malwarebytes Forums, in this thread, I'll ask you to not seek assistance anywhere else for any issue related to the system we are working on. If you have an issue, question, etc. about your computer, please ask it in this thread and I'll assist you
  • The same principle applies to any modifications you make to your system, I would like you to ask me before you do any manipulations that aren't in the instructions I posted. This is to ensure that we are operating in sync and I know exactly what's happening on your system
  • If you aren't sure about an instruction I'm giving you, ask me about it. This is to ensure that the clean-up process goes without any issue. I'll answer you and even give you more precise instructions/explanations if you need. There's no shame in asking questions here, better be safe than sorry!
  • If you don't reply to your thread within 3 days, I'll bump this thread to let you know that I'm waiting for you. If you don't reply after 5 days, it'll be closed. If you return after that period, you can send me a PM to get it unlocked and we'll continue where we left off;
  • Since malware can work quickly, we want to get rid of them as fast as we can, before they make unknown changes to the system. This being said, I would appreciate if you could reply to this thread within 24 hours of me posting. This way, we'll have a good clean-up rhythm and the chances of complications will be reduced
  • I'm against any form of pirated, illegal and counterfeit software and material. So if you have any installed on your system, I'll ask you to uninstall them right now. You don't have to tell me if you indeed had some or not, I'll give you the benefit of the doubt. Plus, this would be against Malwarebytes Forums's rules
  • In the end, you are the one asking for assistance here. So if you wish to go a different way during the clean-up, like format and reinstall Windows, you are free to do so. I would appreciate you to let me know about it first, and if you need, I can also assist you in the process
  • I would appreciate if you were to stay with me until the end, which means, until I declare your system clean. Just because your system isn't behaving weirdly anymore, or is running better than before, it doesn't mean that the infection is completely gone
    This being said, I have a full time job so sometimes it'll take longer for me to reply to you. Don't worry, you'll be my first priority as soon as I get home and have time to look at your thread


This being said, it's time to clean-up some malware, so let's get started, shall we? :)

Follow the instructions in the thread below, and provide me both FRST logs (FRST.txt and Addition.txt). You can attach them in your next post, or copy/paste their content.

https://forums.malwarebytes.com/topic/9573-im-infected-what-do-i-do-now/

Link to post
Share on other sites

I took a look at the header of one of the attached files and saw it said Chrome was my default browser, it never was.

History:

I updated my ccleaner and mistakenly allowed Chrome to be installed. I ran GeekUnInstaller to delete.

Although my real default browser is FireFox and it works fine with the exception now that if I click on an internet link on my desktop I get a side-by-side error.

I'm not sure if there is a correlation between my current problem you will be helping on now or a consequence of my unfortunate Chrome experience.

Link to post
Share on other sites

Was Google Chrome ever installed on that system?

Quote

Although my real default browser is FireFox and it works fine with the exception now that if I click on an internet link on my desktop I get a side-by-side error.

Can you give me a screenshot of that?

Also, follow the instructions below.

iO3R662.pngFarbar Recovery Scan Tool (FRST) - Fix mode
Follow the instructions below to execute a fix on your system using FRST, and provide the log in your next reply.

  • Download the attached fixlist.txt file, and save it on your Desktop (or wherever your FRST.exe/FRST64.exe executable is located)
  • Right-click on the FRST executable and select Spcusrh.pngRun as Administrator (for Windows Vista, 7, 8, 8.1 and 10 users)
  • Click on the Fix button
    NYA5Cbr.png
  • On completion, a message will come up saying that the fix has been completed and it'll open a log in Notepad
  • Copy and paste its content in your next reply

fixlist.txt

Link to post
Share on other sites

I don't know if this means anything but I think IP address and Port# maybe different every time I get one of those "MyKings" blocked pop-ups.

The pop-up I pasted in the email here was taken several weeks ago and most likely does not have the same IP & port as the attached files you have requested.

 

Edited by tommybio
Link to post
Share on other sites

21 hours ago, Aura said:

Was Google Chrome ever installed on that system?

Can you give me a screenshot of that?

Also, follow the instructions below.

iO3R662.pngFarbar Recovery Scan Tool (FRST) - Fix mode
Follow the instructions below to execute a fix on your system using FRST, and provide the log in your next reply.

  • Download the attached fixlist.txt file, and save it on your Desktop (or wherever your FRST.exe/FRST64.exe executable is located)
  • Right-click on the FRST executable and select Spcusrh.pngRun as Administrator (for Windows Vista, 7, 8, 8.1 and 10 users)
  • Click on the Fix button
    NYA5Cbr.png
  • On completion, a message will come up saying that the fix has been completed and it'll open a log in Notepad
  • Copy and paste its content in your next reply

 

Here is the notice I get when I click on any link on my desktop if I'm not running my FireFox.

side-by-side.jpg.2a7eef18aa53d05bdc41ebd05a7861b6.jpg

 

21 hours ago, Aura said:

 

Link to post
Share on other sites

After running FIX  - here is the fixlist result:

 

Fix result of Farbar Recovery Scan Tool (x64) Version: 20-08-2017
Ran by TomR (29-08-2017 07:08:02) Run:1
Running from C:\Users\TomR\Desktop
Loaded Profiles: TomR & UpdatusUser (Available Profiles: TomR & UpdatusUser)
Boot Mode: Normal
==============================================

fixlist content:
*****************
CloseProcesses:
CreateRestorePoint:

CMD: dir /a C:\Windows\debug

HKLM-x32\...\Run: [] => [X]
GroupPolicyScripts-x32: Restriction <==== ATTENTION

HKLM\SOFTWARE\Policies\Microsoft\Windows\IPSec\Policy\Local: [ActivePolicy] SOFTWARE\Policies\Microsoft\Windows\IPSEC\Policy\Local\ipsecPolicy{94a16848-6dd5-43d7-bf6c-20de315254b0} <==== ATTENTION (Restriction - IP)

HKU\S-1-5-21-786217106-2830415026-3013700145-1000\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.msn.com/?pc=Z192&install_date=20111021
HKU\S-1-5-21-786217106-2830415026-3013700145-1000\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://homepage.emachines.com/rdr.aspx?b=ACEW&l=0409&m=el1352&r=17360710z616p0425v135r4551s20o
HKU\S-1-5-21-786217106-2830415026-3013700145-1000\Software\Microsoft\Internet Explorer\Main,Start Page Restore = hxxp://www.msn.com/
SearchScopes: HKLM-x32 -> DefaultScope {67A2568C-7A0A-4EED-AECC-B5405DE63B64} URL = hxxp://www.google.com/search?sourceid=ie7&q={searchTerms}&rls=com.microsoft:{language}:{referrer:source?}&ie={inputEncoding}&oe={outputEncoding}&rlz=1I7ACEW
SearchScopes: HKLM-x32 -> {67A2568C-7A0A-4EED-AECC-B5405DE63B64} URL = hxxp://www.google.com/search?sourceid=ie7&q={searchTerms}&rls=com.microsoft:{language}:{referrer:source?}&ie={inputEncoding}&oe={outputEncoding}&rlz=1I7ACEW
SearchScopes: HKU\S-1-5-21-786217106-2830415026-3013700145-1000 -> DefaultScope {42C9843D-8B61-431C-B9E6-A0435F6D4207} URL = hxxps://search.yahoo.com/search?fr=mcafee&type=B010US0D20140911&p={searchTerms}
SearchScopes: HKU\S-1-5-21-786217106-2830415026-3013700145-1000 -> {043BDAE4-4D26-4393-BF7A-25C7954CB9DF} URL = hxxp://www.bing.com/search?FORM=SL5EDF&PC=SL5E&q={searchTerms}&src=IE-SearchBox
SearchScopes: HKU\S-1-5-21-786217106-2830415026-3013700145-1000 -> {42C9843D-8B61-431C-B9E6-A0435F6D4207} URL = hxxps://search.yahoo.com/search?fr=mcafee&type=B010US0D20140911&p={searchTerms}
SearchScopes: HKU\S-1-5-21-786217106-2830415026-3013700145-1000 -> {67A2568C-7A0A-4EED-AECC-B5405DE63B64} URL = hxxp://www.google.com/search?sourceid=ie7&q={searchTerms}&rls=com.microsoft:{language}:{referrer:source?}&ie={inputEncoding}&oe={outputEncoding}&rlz=1I7ACEW_enUS389
SearchScopes: HKU\S-1-5-21-786217106-2830415026-3013700145-1000 -> {AFBCB7E0-F91A-4951-9F31-58FEE57A25C4} URL = hxxp://nortonsafe.search.ask.com/web?q={SEARCHTERMS}&o=APN10506&l=dis&prt=NIS&chn=retail&geo=US&ver=20&locale=en_US&gct=kwd&qsrc=2869
BHO: No Name -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> No File
BHO: No Name -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> No File

CustomCLSID: HKU\S-1-5-21-786217106-2830415026-3013700145-1000_Classes\CLSID\{7EDE1883-2441-8958-2BA1-89FF6012AEB5}\InprocServer32 -> no filepath
ShellIconOverlayIdentifiers: [00avast] -> {472083B0-C522-11CF-8763-00608CC02F24} =>  -> No File
ContextMenuHandlers3: [00avast] -> {472083B0-C522-11CF-8763-00608CC02F24} =>  -> No File

Task: {00AD8E23-2586-468E-A15F-AED99D7043F6} - no filepath
Task: {05C8E35C-1D32-499C-B435-19B653F76FD4} - \{17CDFFCD-85B3-41EF-B509-443032DD4B90} -> No File <==== ATTENTION
Task: {0ABD084D-670A-413A-BF35-276266FC84F3} - \{4BDD9075-7613-49B0-B815-F274A2667736} -> No File <==== ATTENTION
Task: {26C20DA8-39EC-4588-8DCB-F38F3F569AB0} - \{627CD2E7-A314-484E-8018-672FC7795AF2} -> No File <==== ATTENTION
Task: {29F18670-CEB0-4016-8C52-FCBEDF9CE98C} - \Norton WSC Integration -> No File <==== ATTENTION
Task: {2F15B5AF-DB0A-4FCA-BF38-774FA4794F4C} - System32\Tasks\{11462125-F7FC-45BD-8562-FC4E6FE7307C} => C:\Windows\system32\pcalua.exe -a C:\Users\TomR\Desktop\windirstat1_1_2_setup.exe -d C:\Users\TomR\Desktop
Task: {5163503B-F3A9-4E7F-93D8-411CA9F44E10} - \{FD3F069F-4F66-4E95-922D-A3B348B37485} -> No File <==== ATTENTION
Task: {7023CB40-1269-42B0-BC14-B2A4897BD07F} - no filepath
Task: {7546419F-2C6F-4F8E-A9F1-ECDA8BC19117} - \{CA8C0518-5D12-4618-874C-DA0111AE1106} -> No File <==== ATTENTION
Task: {77824A2C-75B2-4D84-8050-D93BB2DBE46A} - \{AAACE3EC-9C1C-4A96-BCE1-8207EFDD48F9} -> No File <==== ATTENTION
Task: {7A7CFECD-CEB3-404C-8FF5-8CABC7A4491F} - \{416A0380-F051-4EA2-8C9A-BADDD121E97E} -> No File <==== ATTENTION
Task: {7DBEDD7F-C499-417A-B81C-E97F33E4BD44} - \{1A157219-7133-4CB7-B212-53C8CD7C8520} -> No File <==== ATTENTION

WMI_ActiveScriptEventConsumer_censoredyoumm2_consumer: <==== ATTENTION

AlternateDataStreams: C:\ProgramData\Reprise:wupeogjxldtlfudivq`qsp`27hfm [0]
AlternateDataStreams: C:\ProgramData\Temp:054B9966 [140]
AlternateDataStreams: C:\ProgramData\Temp:0888F409 [117]
AlternateDataStreams: C:\ProgramData\Temp:307C8BA9 [360]
AlternateDataStreams: C:\ProgramData\Temp:456A69E6 [308]
AlternateDataStreams: C:\ProgramData\Temp:642312F4 [128]
AlternateDataStreams: C:\ProgramData\Temp:66633281 [406]
AlternateDataStreams: C:\ProgramData\Temp:796FAB96 [153]

EmptyTemp:
*****************

Processes closed successfully.
Restore point was successfully created.

========= dir /a C:\Windows\debug =========

 Volume in drive C is eMachines
 Volume Serial Number is 5489-3B73

 Directory of C:\Windows\debug

08/20/2017  03:54 PM    <DIR>          .
08/20/2017  03:54 PM    <DIR>          ..
08/29/2017  06:10 AM                 0 PASSWD.LOG
04/14/2010  02:35 PM    <DIR>          WIA
               1 File(s)              0 bytes
               3 Dir(s)  203,905,482,752 bytes free

========= End of CMD: =========

HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Run\\ => value removed successfully
C:\Windows\SysWOW64\GroupPolicy\Machine => moved successfully
C:\Windows\SysWOW64\GroupPolicy\GPT.ini => moved successfully
HKLM\SOFTWARE\Policies\Microsoft\Windows\IPSec\Policy\Local\\ActivePolicy => value removed successfully
HKU\S-1-5-21-786217106-2830415026-3013700145-1000\Software\Microsoft\Internet Explorer\Main\\Start Page => value restored successfully
HKU\S-1-5-21-786217106-2830415026-3013700145-1000\Software\Microsoft\Internet Explorer\Main\\Default_Page_URL => value restored successfully
HKU\S-1-5-21-786217106-2830415026-3013700145-1000\Software\Microsoft\Internet Explorer\Main\\Start Page Restore => value removed successfully
HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\SearchScopes\\DefaultScope => value restored successfully
HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\SearchScopes\{67A2568C-7A0A-4EED-AECC-B5405DE63B64} => key removed successfully
HKLM\Software\Wow6432Node\Classes\CLSID\{67A2568C-7A0A-4EED-AECC-B5405DE63B64} => key not found.
HKU\S-1-5-21-786217106-2830415026-3013700145-1000\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\DefaultScope => value removed successfully
HKU\S-1-5-21-786217106-2830415026-3013700145-1000\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{043BDAE4-4D26-4393-BF7A-25C7954CB9DF} => key removed successfully
HKLM\Software\Classes\CLSID\{043BDAE4-4D26-4393-BF7A-25C7954CB9DF} => key not found.
HKU\S-1-5-21-786217106-2830415026-3013700145-1000\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{42C9843D-8B61-431C-B9E6-A0435F6D4207} => key removed successfully
HKLM\Software\Classes\CLSID\{42C9843D-8B61-431C-B9E6-A0435F6D4207} => key not found.
HKU\S-1-5-21-786217106-2830415026-3013700145-1000\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{67A2568C-7A0A-4EED-AECC-B5405DE63B64} => key removed successfully
HKLM\Software\Classes\CLSID\{67A2568C-7A0A-4EED-AECC-B5405DE63B64} => key not found.
HKU\S-1-5-21-786217106-2830415026-3013700145-1000\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{AFBCB7E0-F91A-4951-9F31-58FEE57A25C4} => key removed successfully
HKLM\Software\Classes\CLSID\{AFBCB7E0-F91A-4951-9F31-58FEE57A25C4} => key not found.
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{761497BB-D6F0-462C-B6EB-D4DAF1D92D43} => key removed successfully
HKLM\Software\Classes\CLSID\{761497BB-D6F0-462C-B6EB-D4DAF1D92D43} => key not found.
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9} => key removed successfully
HKLM\Software\Classes\CLSID\{DBC80044-A445-435b-BC74-9C25C1C588A9} => key not found.
HKU\S-1-5-21-786217106-2830415026-3013700145-1000_Classes\CLSID\{7EDE1883-2441-8958-2BA1-89FF6012AEB5} => key removed successfully
HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\ShellIconOverlayIdentifiers\00avast => key removed successfully
HKLM\Software\Classes\CLSID\{472083B0-C522-11CF-8763-00608CC02F24} => key not found.
HKLM\Software\Classes\AllFileSystemObjects\ShellEx\ContextMenuHandlers\00avast => key removed successfully
HKLM\Software\Classes\CLSID\{472083B0-C522-11CF-8763-00608CC02F24} => key not found.
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Boot\{00AD8E23-2586-468E-A15F-AED99D7043F6} => key removed successfully
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{00AD8E23-2586-468E-A15F-AED99D7043F6} => key removed successfully
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{05C8E35C-1D32-499C-B435-19B653F76FD4} => key removed successfully
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{05C8E35C-1D32-499C-B435-19B653F76FD4} => key removed successfully
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\{17CDFFCD-85B3-41EF-B509-443032DD4B90} => key removed successfully
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{0ABD084D-670A-413A-BF35-276266FC84F3} => key removed successfully
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{0ABD084D-670A-413A-BF35-276266FC84F3} => key removed successfully
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\{4BDD9075-7613-49B0-B815-F274A2667736} => key removed successfully
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{26C20DA8-39EC-4588-8DCB-F38F3F569AB0} => key removed successfully
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{26C20DA8-39EC-4588-8DCB-F38F3F569AB0} => key removed successfully
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\{627CD2E7-A314-484E-8018-672FC7795AF2} => key removed successfully
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{29F18670-CEB0-4016-8C52-FCBEDF9CE98C} => key removed successfully
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{29F18670-CEB0-4016-8C52-FCBEDF9CE98C} => key removed successfully
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Norton WSC Integration => key removed successfully
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{2F15B5AF-DB0A-4FCA-BF38-774FA4794F4C} => key removed successfully
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{2F15B5AF-DB0A-4FCA-BF38-774FA4794F4C} => key removed successfully
C:\Windows\System32\Tasks\{11462125-F7FC-45BD-8562-FC4E6FE7307C} => moved successfully
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\{11462125-F7FC-45BD-8562-FC4E6FE7307C} => key removed successfully
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{5163503B-F3A9-4E7F-93D8-411CA9F44E10} => key removed successfully
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{5163503B-F3A9-4E7F-93D8-411CA9F44E10} => key removed successfully
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\{FD3F069F-4F66-4E95-922D-A3B348B37485} => key removed successfully
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Boot\{7023CB40-1269-42B0-BC14-B2A4897BD07F} => key removed successfully
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{7023CB40-1269-42B0-BC14-B2A4897BD07F} => key removed successfully
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{7546419F-2C6F-4F8E-A9F1-ECDA8BC19117} => key removed successfully
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{7546419F-2C6F-4F8E-A9F1-ECDA8BC19117} => key removed successfully
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\{CA8C0518-5D12-4618-874C-DA0111AE1106} => key removed successfully
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{77824A2C-75B2-4D84-8050-D93BB2DBE46A} => key removed successfully
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{77824A2C-75B2-4D84-8050-D93BB2DBE46A} => key removed successfully
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\{AAACE3EC-9C1C-4A96-BCE1-8207EFDD48F9} => key removed successfully
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{7A7CFECD-CEB3-404C-8FF5-8CABC7A4491F} => key removed successfully
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{7A7CFECD-CEB3-404C-8FF5-8CABC7A4491F} => key removed successfully
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\{416A0380-F051-4EA2-8C9A-BADDD121E97E} => key removed successfully
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{7DBEDD7F-C499-417A-B81C-E97F33E4BD44} => key removed successfully
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{7DBEDD7F-C499-417A-B81C-E97F33E4BD44} => key removed successfully
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\{1A157219-7133-4CB7-B212-53C8CD7C8520} => key removed successfully
WMI_ActiveScriptEventConsumer_censoredyoumm2_consumer: <==== ATTENTION => not found
C:\ProgramData\Reprise => ":wupeogjxldtlfudivq`qsp`27hfm" ADS removed successfully.
C:\ProgramData\Temp => ":054B9966" ADS removed successfully.
C:\ProgramData\Temp => ":0888F409" ADS removed successfully.
C:\ProgramData\Temp => ":307C8BA9" ADS removed successfully.
C:\ProgramData\Temp => ":456A69E6" ADS removed successfully.
C:\ProgramData\Temp => ":642312F4" ADS removed successfully.
C:\ProgramData\Temp => ":66633281" ADS removed successfully.
C:\ProgramData\Temp => ":796FAB96" ADS removed successfully.

=========== EmptyTemp: ==========

BITS transfer queue => 8388608 B
DOMStore, IE Recovery, AppCache, Feeds Cache, Thumbcache, IconCache => 16571350 B
Java, Flash, Steam htmlcache => 1620 B
Windows/system/drivers => 13768179 B
Edge => 0 B
Chrome => 0 B
Firefox => 94566456 B
Opera => 0 B

Temp, IE cache, history, cookies, recent:
Users => 0 B
Default => 66228 B
Public => 0 B
ProgramData => 0 B
systemprofile => 213166 B
systemprofile32 => 3419224 B
LocalService => 132244 B
NetworkService => 0 B
TomR => 31278515 B
UpdatusUser => 88756 B

RecycleBin => 0 B
EmptyTemp: => 160.7 MB temporary data Removed.

================================


The system needed a reboot.

==== End of Fixlog 07:09:30 ====

Link to post
Share on other sites

22 hours ago, Aura said:

Was Google Chrome ever installed on that system?

Can you give me a screenshot of that?

Also, follow the instructions below.

iO3R662.pngFarbar Recovery Scan Tool (FRST) - Fix mode
Follow the instructions below to execute a fix on your system using FRST, and provide the log in your next reply.

  • Download the attached fixlist.txt file, and save it on your Desktop (or wherever your FRST.exe/FRST64.exe executable is located)
  • Right-click on the FRST executable and select Spcusrh.pngRun as Administrator (for Windows Vista, 7, 8, 8.1 and 10 users)
  • Click on the Fix button
    NYA5Cbr.png
  • On completion, a message will come up saying that the fix has been completed and it'll open a log in Notepad
  • Copy and paste its content in your next reply

 

fixlist.txt

 

Was Google Chrome ever installed on that system?  YES.

Chrome was mistakenly installed while I updated ccleaner. I then quickly uninstalled it using GeekUnInstaller which supposedly removed it and any reg. keys associated with it.

 

 

Link to post
Share on other sites

Alright. I'll ask Farbar what key he's querying to check for the default browser on the system.

Meanwhile, can you .zip the following file and attach it here so I can review it?

C:\Windows\debug\PASSWD.LOG

Also, open a command prompt with Admin Rights (you can also right-click on the Windows Start Menu and select PowerShell (Administrator)), and enter the commands below (after each, press on Enter):

net stop winmgmt /y
Winmgmt /resetrepository

The first one should says that the service was stopped successfully, and the second one should say that the WMI repository has been reset.

Link to post
Share on other sites

21 minutes ago, Aura said:

Alright. I'll ask Farbar what key he's querying to check for the default browser on the system.

Meanwhile, can you .zip the following file and attach it here so I can review it?


C:\Windows\debug\PASSWD.LOG

Also, open a command prompt with Admin Rights (you can also right-click on the Windows Start Menu and select PowerShell (Administrator)), and enter the commands below (after each, press on Enter):


net stop winmgmt /y
Winmgmt /resetrepository

The first one should says that the service was stopped successfully, and the second one should say that the WMI repository has been reset.

I looked at the PASSWD.LOG  and it's empty.

I didn't try Net Stop or Winmgmt yet -   ?  Why  would that info help?

 

 

Link to post
Share on other sites

Quote

I looked at the PASSWD.LOG  and it's empty.

Good.

Quote

I didn't try Net Stop or Winmgmt yet -   ?  Why  would that info help?

You can enter the two commands now. Let me know if they both return a success message (the ones expected were written down in my previous post).

Link to post
Share on other sites

1 hour ago, Aura said:

No I mean, are you still getting the block notifications from Malwarebytes? The ones about wmi.mykings.top?

Doesn't happen all the time, sometimes it's once a week on a Sunday - when it happens it's usually 3 hits in quick succession.

What do you think could have fixed it?

 

Link to post
Share on other sites

Quote

What do you think could have fixed it?

It was most likely a rogue WMI entry that we removed. Let's run FRST again to make sure that it's indeed gone.

iO3R662.pngFarbar Recovery Scan Tool (FRST) - Scan mode
Follow the instructions below to download and execute a scan on your system with FRST, and provide the logs in your next reply.

  • Right-click on the executable and select Spcusrh.pngRun as Administrator (for Windows Vista, 7, 8, 8.1 and 10 users)
  • Accept the disclaimer by clicking on Yes, and FRST will then do a back-up of your Registry which should take a few seconds
  • Click on the Scan button
  • On completion, two message box will open, saying that the results were saved to FRST.txt and Addition.txt, then open two Notepad files
  • Copy and paste the content of both FRST.txt and Addition.txt in your next reply

Link to post
Share on other sites

19 minutes ago, Aura said:

It was most likely a rogue WMI entry that we removed. Let's run FRST again to make sure that it's indeed gone.

iO3R662.pngFarbar Recovery Scan Tool (FRST) - Scan mode
Follow the instructions below to download and execute a scan on your system with FRST, and provide the logs in your next reply.

  • Right-click on the executable and select Spcusrh.pngRun as Administrator (for Windows Vista, 7, 8, 8.1 and 10 users)
  • Accept the disclaimer by clicking on Yes, and FRST will then do a back-up of your Registry which should take a few seconds
  • Click on the Scan button
  • On completion, two message box will open, saying that the results were saved to FRST.txt and Addition.txt, then open two Notepad files
  • Copy and paste the content of both FRST.txt and Addition.txt in your next reply

 

OK here is the latest:

As of right now there are no current MyKings pop-up(s) listed in Malwarebytes reports.

Addition.txt

FRST.txt

Link to post
Share on other sites

Looks like it's still there sadly. FRST wasn't able to get rid of it for some reason. Let's try again and get some more information at the same time.

Follow the instructions below.

iO3R662.pngFarbar Recovery Scan Tool (FRST) - Fix mode
Follow the instructions below to execute a fix on your system using FRST, and provide the log in your next reply.

  • Download the attached fixlist.txt file, and save it on your Desktop (or wherever your FRST.exe/FRST64.exe executable is located)
  • Right-click on the FRST executable and select Spcusrh.pngRun as Administrator (for Windows Vista, 7, 8, 8.1 and 10 users)
  • Click on the Fix button
    NYA5Cbr.png
  • On completion, a message will come up saying that the fix has been completed and it'll open a log in Notepad
  • Copy and paste its content in your next reply

fixlist.txt

Link to post
Share on other sites

9 hours ago, Aura said:

Looks like it's still there sadly. FRST wasn't able to get rid of it for some reason. Let's try again and get some more information at the same time.

Follow the instructions below.

iO3R662.pngFarbar Recovery Scan Tool (FRST) - Fix mode
Follow the instructions below to execute a fix on your system using FRST, and provide the log in your next reply.

  • Download the attached fixlist.txt file, and save it on your Desktop (or wherever your FRST.exe/FRST64.exe executable is located)
  • Right-click on the FRST executable and select Spcusrh.pngRun as Administrator (for Windows Vista, 7, 8, 8.1 and 10 users)
  • Click on the Fix button
    NYA5Cbr.png
  • On completion, a message will come up saying that the fix has been completed and it'll open a log in Notepad
  • Copy and paste its content in your next reply

 

fixlist.txt

OK here is the file:

Fix result of Farbar Recovery Scan Tool (x64) Version: 20-08-2017
Ran by TomR (30-08-2017 06:35:46) Run:2
Running from C:\Users\TomR\Desktop
Loaded Profiles: TomR & UpdatusUser (Available Profiles: TomR & UpdatusUser)
Boot Mode: Normal
==============================================

fixlist content:
*****************
Task: {C035C4E6-38EC-4B00-B302-114AF66ED59D} - no filepath
Task: {C8D67D68-F559-44CC-8324-0A20E7FEA212} - no filepath

WMI_ActiveScriptEventConsumer_censoredyoumm2_consumer: <==== ATTENTION

REG: REG QUERY "HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\Taskcache\Tasks" /s
REG: REG QUERY "HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\Taskcache\Tree" /s
*****************

HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Boot\{C035C4E6-38EC-4B00-B302-114AF66ED59D} => key removed successfully
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{C035C4E6-38EC-4B00-B302-114AF66ED59D} => key removed successfully
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Boot\{C8D67D68-F559-44CC-8324-0A20E7FEA212} => key removed successfully
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{C8D67D68-F559-44CC-8324-0A20E7FEA212} => key removed successfully
WMI_ActiveScriptEventConsumer_censoredyoumm2_consumer: <==== ATTENTION => not found

========= REG QUERY "HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\Taskcache\Tasks" /s =========


HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Schedule\Taskcache\Tasks\{003DBEB6-92B4-41BC-A8DE-E766A3FB3C65}
    Path    REG_SZ    \Microsoft\Windows\Media Center\ehDRMInit
    Triggers    REG_BINARY    150000000000000000FFFFFFFFFFFFFFFFFFFFFFFFFFFFFF00FFFFFFFFFFFFFF00000000000000000021420248484848E8DDC73B484848480048484848484848004848484848484805000000484848480C000000484848480101000000000005130000004848484800000000484848480000000048484848
    DynamicInfo    REG_BINARY    0300000060EA3F4901DCCA0100000000000000000000000000000000
    Hash    REG_BINARY    9B2BFF8825669B3C372748418CC0EB39C719BDAEBCD676CC7B39E1022601A0BF

HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Schedule\Taskcache\Tasks\{034DF26D-DA1B-4161-9AE1-330409B21EE7}
    Path    REG_SZ    \Microsoft\Windows\Application Experience\ProgramDataUpdater
    Hash    REG_BINARY    A1AC57965B3F9A2A449EAED18D7C3EDAD8A5F295FF2D072E48B8CE64AF5D84EC
    Triggers    REG_BINARY    150000000000000001DD880000000000000CCFC53963CF0100DD880000000000FFFFFFFFFFFFFFFF7E214202484848488E08769D484848480048484848484848004848484848484805000000484848480C000000484848480101000000000005120000004848484800000000484848483800000048484848B40000007043010080F40300FFFFFFFF04000000000000000000000000000000000000000000000000000000000000000000000000000000DDDD00000000000001DD880000000000000CCFC53963CF0100000000000000000000000000000000000000000000000000000000000000000000000000000000FFFFFFFF0100000001000000000000000001000001000000201C000000000000
    DynamicInfo    REG_BINARY    0300000040906BAC3E1AD10100000000000000000000000000000000

HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Schedule\Taskcache\Tasks\{044A6734-E90E-4F8F-B357-B2DC8AB3B5EC}
    Path    REG_SZ    \Microsoft\Windows\Time Synchronization\SynchronizeTime
    Triggers    REG_BINARY    1500000000000000011272FBFE07000000E8E6379DEFC401001272FBFE070000FFFFFFFFFFFFFFFFE021420348484848DFDC7836484848480048484848484848004848484848484805000000484848480C000000484848480101000000000005130000004848484800000000484848480000000048484848DDDD000000000000011272FBFE07000000E8E6379DEFC40100000000000000000000000000000000000000000000000000000000000000000000000000000000FFFFFFFF02000000010001000000000000010000010000000000000000000000
    DynamicInfo    REG_BINARY    030000002D35042D4104CA0100000000000000000000000000000000
    Hash    REG_BINARY    17D3BD884BE1EAD4B4B32CC46D0707E468688A3FCDE1835573BF3A392D0BF65A

HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Schedule\Taskcache\Tasks\{059C454D-C82D-4FBA-ACA0-E0D20F84D4CD}
    Path    REG_SZ    \Microsoft\Windows\Media Center\RegisterSearch
    Triggers    REG_BINARY    150000000000000000FFFFFFFFFFFFFFFFFFFFFFFFFFFFFF00FFFFFFFFFFFFFF00000000000000000021420248484848A9A3FB23484848480048484848484848004848484848484805000000484848480C000000484848480101000000000005120000004848484800000000484848480000000048484848
    DynamicInfo    REG_BINARY    0300000000D6C24901DCCA0100000000000000000000000000000000
    Hash    REG_BINARY    3C0B66D64686766827850B149B5AFB544220673B5B4D47CB5556EF2C868E2381

HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Schedule\Taskcache\Tasks\{088482FA-65B8-4E17-9ABF-1DCD48E8D373}
    Path    REG_SZ    \Microsoft\Windows\Tcpip\IpAddressConflict1
    Triggers    REG_BINARY    1500000000000000001C24FBFE0700000000000000000000001C24FBFE070000FFFFFFFFFFFFFFFF38A1400348484848E99D6008484848480048484848484848004848484848484804000000484848481000000048484848010200000000000520000000210200000000000048484848380000004848484858020000100E000080F40300FFFFFFFF07000000000000000000000000000000000000000000000000000000000000000000000000000000CCCC000000000000001C24FBFE0700000000000000000000001C24FBFE070000FFFFFFFFFFFFFFFF00000000FFFFFFFF00000000000000000000000000000000010100000000000520000000000000008D000000000000003C00510075006500720079004C006900730074003E003C00510075006500720079002000490064003D00220030002200200050006100740068003D002200530079007300740065006D0022003E003C00530065006C00650063007400200050006100740068003D002200530079007300740065006D0022003E002A005B00530079007300740065006D005B00500072006F00760069006400650072005B0040004E0061006D0065003D0027005400630070006900700027005D00200061006E00640020004500760065006E007400490044003D0034003100390038005D005D003C002F00530065006C006500630074003E003C002F00510075006500720079003E003C002F00510075006500720079004C006900730074003E00000048484848000000000000000000000000000000000000000000000000
    DynamicInfo    REG_BINARY    030000008D96062D4104CA0100000000000000000000000000000000
    Hash    REG_BINARY    CEF4FD5DA04459B60C163CD71D538078A601EF7EE05832CECD2DD79D5213AF22

HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Schedule\Taskcache\Tasks\{09F06BFE-A3C8-40E3-846A-6E6F4000C238}
    Path    REG_SZ    \Microsoft\Windows\Tcpip\IpAddressConflict2
    Triggers    REG_BINARY    1500000000000000011272FBFE07000080294E129638C601001C24FBFE070000FFFFFFFFFFFFFFFF38A1400348484848A201FC43484848480048484848484848004848484848484804000000484848481000000048484848010200000000000520000000210200000000000048484848380000004848484858020000100E000080F40300FFFFFFFF07000000000000000000000000000000000000000000000000000000750070000000000000000000CCCC000000000000011272FBFE07000080294E129638C601001C24FBFE070000FFFFFFFFFFFFFFFF00000000FFFFFFFF00000000000000000000000000000000010100000000000520000000000000008D000000000000003C00510075006500720079004C006900730074003E003C00510075006500720079002000490064003D00220030002200200050006100740068003D002200530079007300740065006D0022003E003C00530065006C00650063007400200050006100740068003D002200530079007300740065006D0022003E002A005B00530079007300740065006D005B00500072006F00760069006400650072005B0040004E0061006D0065003D0027005400630070006900700027005D00200061006E00640020004500760065006E007400490044003D0034003100390039005D005D003C002F00530065006C006500630074003E003C002F00510075006500720079003E003C002F00510075006500720079004C006900730074003E00000048484848000000000000000000000000000000000000000000000000
    DynamicInfo    REG_BINARY    030000008D96062D4104CA0100000000000000000000000000000000
    Hash    REG_BINARY    4D3C72EE9B731BFCFC7022531B2870DEF28FF13FF8E0F089003E02AA0F40C05D

HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Schedule\Taskcache\Tasks\{0DC5362E-5BE5-491D-8F88-8E388E4759CD}
    Path    REG_SZ    \Microsoft\Windows\SideShow\SessionAgent
    Triggers    REG_BINARY    1500000000000000000000000000000000000000000000000000000000000000FFFFFFFFFFFFFFFF00850002484848483D09F37D484848480048484848484848004848484848484804000000484848481000000048484848010200000000000520000000210200000000000048484848380000004848484800000000FFFFFFFF00000000FFFFFFFF070000000000000000000000000000000000000000000000000000006D0022000000000000000000AAAA000000000000000000000000000000000000000000000000000000000000FFFFFFFFFFFFFFFF0F000000FFFFFFFF0000000000000000000000000000000001729D010000000005000000000000000148484848484848
    DynamicInfo    REG_BINARY    03000000E0A9F24701DCCA0100000000000000000000000000000000
    Hash    REG_BINARY    DBC065695455F16521C1F2CCB4FBA71757C53FC6D38C9B87FE41BF26F286E159

HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Schedule\Taskcache\Tasks\{1134D20D-324D-4391-86F5-75AFCFC9779A}
    Path    REG_SZ    \Microsoft\Windows\Media Center\StartRecording
    Triggers    REG_BINARY    150000000000000000FFFFFFFFFFFFFFFFFFFFFFFFFFFFFF00FFFFFFFFFFFFFF00000000000000004807420248484848FB7B73CB484848480048484848484848004848484848484805000000484848480C00000048484848010100000000000514000000484848480000000048484848380000004848484858020000100E000080F40300FFFFFFFF07000000000000000000000000000000000000000000000000000000000000000000000000000000
    DynamicInfo    REG_BINARY    03000000B803F6BB772FCB0100000000000000000000000000000000
    Hash    REG_BINARY    6F3251475E855FE31A519893A624488246E71775F85E8A3FF3D3B155D2685F76

HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Schedule\Taskcache\Tasks\{19DADAD5-F9EC-4AEF-946C-C0A576840830}
    Path    REG_SZ    \Microsoft\Windows\Media Center\PeriodicScanRetry
    Triggers    REG_BINARY    1500000000000000016C780100000000006ECFFE35D4C6010100000000000000006ECFFE35D4C6013021020248484848890E4413484848480048484848484848004848484848484805000000484848480C00000048484848010100000000000514000000484848480000000048484848380000004848484800000000FFFFFFFF80F40300FFFFFFFF07000000000000000000000000000000000000000000000000000000610073000000000000000000DDDD000000000000016C780100000000006ECFFE35D4C60100000000000000000000000000000000000000000000000000000000000000000000000000000000FFFFFFFF00000000000000000000000000000000010000000000000000000000
    DynamicInfo    REG_BINARY    03000000808FE14B01DCCA0100000000000000000000000000000000
    Hash    REG_BINARY    8E6911CA59C45F2EE0BF63453DCD580B285E92CE1BFE4589F956D67C57F75EA3

HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Schedule\Taskcache\Tasks\{1BA0AE97-C21E-48BB-9FF0-70BC9F299377}
    Path    REG_SZ    \Microsoft\Windows\MobilePC\HotStart
    Triggers    REG_BINARY    1500000000000000000000000000000000000000000000000000000000000000FFFFFFFFFFFFFFFF40854002484848487E9B658C484848480048484848484848004848484848484805000000484848480C0000004848484801010000000000050B000000484848480000000048484848380000004848484800000000FFFFFFFF00000000FFFFFFFF07000000000000000000000000000000000000000000000000000000000000000000000000000000AAAA000000000000000000000000000000000000000000000000000000000000FFFFFFFFFFFFFFFF00000000FFFFFFFF00000000000000000000000000000000010063006E002000300000006E0069000148484848484848
    DynamicInfo    REG_BINARY    030000002070514C01DCCA0100000000000000000000000000000000
    Hash    REG_BINARY    0651BF3B9923F80BE8B50E253E843A95B0CFB7EB97A3EE4E7C955B543DD190E9

HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Schedule\Taskcache\Tasks\{1CBB66B9-9E68-4ACE-8275-4E8796A4A18F}
    Path    REG_SZ    \Microsoft\Windows\Wininet\CacheTask
    Hash    REG_BINARY    B40015C2E03A4473C93284B4A79D0D10020C191C69D34B60D89B92D8942A01FC
    Triggers    REG_BINARY    1500000000000000000000000000000000000000000000000000000000000000FFFFFFFFFFFFFFFF008540024848484814F966A5484848480048484848484848004848484848484804000000484848481000000048484848010200000000000520000000210200000000000048484848380000004848484800000000FFFFFFFF00000000FFFFFFFF07000000000000000000000000000000000000000000000000000000000000000000000000000000AAAA000000000000000000000000000000000000000000000000000000000000FFFFFFFFFFFFFFFF00000000FFFFFFFF000000000000000000000000000000000100610073006B0000000000000000000148484848484848
    DynamicInfo    REG_BINARY    03000000E015C0BF0C21CE0100000000000000000000000000000000

HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Schedule\Taskcache\Tasks\{1F7B7221-AE8F-44F3-BA82-F7D260F51964}
    Path    REG_SZ    \Microsoft\Windows\Task Manager\Interactive
    Triggers    REG_BINARY    150000000000000000FFFFFFFFFFFFFFFFFFFFFFFFFFFFFF00FFFFFFFFFFFFFF00000000000000000085C0024848484819D7D458484848480048484848484848004848484848484805000000484848480C00000048484848010100000000000504000000484848480000000048484848380000004848484800000000FFFFFFFF00000000FFFFFFFF05000000000000000000000000000000000000000000000000000000750070000000000000000000
    DynamicInfo    REG_BINARY    03000000EEF7082D4104CA0100000000000000000000000000000000
    Hash    REG_BINARY    89DE49D146B9DA8A3F686F98CC965767AFCD9716B08A2FC65105DC7B0DDDC519

HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Schedule\Taskcache\Tasks\{2470470F-2634-478E-B181-571E98A789BB}
    Path    REG_SZ    \Microsoft\Windows\Multimedia\SystemSoundsService
    Triggers    REG_BINARY    1500000000000000001C24FBFE0700000000000000000000001C24FBFE070000FFFFFFFFFFFFFFFF00854002484848489D3512E9484848480048484848484848004848484848484804000000484848481000000048484848010200000000000520000000210200000000000048484848380000004848484800000000FFFFFFFF00000000FFFFFFFF07000000000000000000000000000000000000000000000000000000750070000000000000000000AAAA000000000000001C24FBFE0700000000000000000000001C24FBFE070000FFFFFFFFFFFFFFFF00000000FFFFFFFF00000000000000000000000000000000010000000000000000000000030000000148484848484848
    DynamicInfo    REG_BINARY    030000002B2AF12C4104CA0100000000000000000000000000000000
    Hash    REG_BINARY    FD7B51B9FB6DDD39374C586690F9E934EE65EB22FD61531B5408B20591031CE2

HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Schedule\Taskcache\Tasks\{25D544CB-69FF-4F6D-B01B-63541C25C654}
    Path    REG_SZ    \Microsoft\Windows\Application Experience\Microsoft Compatibility Appraiser
    Hash    REG_BINARY    125AC9D322ECEB8E929FBE2A6C24EF5649A4A91AB9FA268469CA74EB6BD15B3E
    Triggers    REG_BINARY    150000000000000001C8B6010000000000B894F18D62CF0100C8B60100000000FFFFFFFFFFFFFFFFC821420248484848C23136A2484848480048484848484848004848484848484805000000484848480C00000048484848010100000000000512000000484848480000000048484848380000004848484800000000FFFFFFFF00460500FFFFFFFF07000000000000000000000000000000000000000000000000000000000000000000000000000000DDDD00000000000001C8B6010000000000B894F18D62CF0100000000000000000000000000000000000000000000000000000000000000000000000000000000FFFFFFFF0100000001000000000000000001000001000000201C000000000000
    DynamicInfo    REG_BINARY    03000000E05AB5AC3E1AD10100000000000000000000000000000000

HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Schedule\Taskcache\Tasks\{278D9BE4-FE38-4141-9BA1-B3F35074E9E1}
    Path    REG_SZ    \WPD\SqmUpload_S-1-5-21-786217106-2830415026-3013700145-1000
    Hash    REG_BINARY    00B3986290489C16857629C3FEA18082A8A238256505965704C0BD590C31786D
    Triggers    REG_BINARY    15000000000000000115D3010000000000A0ABD56D4CC8010115D301000000000080D8FCAD84D001D221C102484848487D92DB1F484848480048484848484848004848484848484801000000484848481C0000004848484801050000000000051500000092B8DC2EB2B4B4A8316AA1B3E8030000484848481A0000004848484854006F006D0052002D00500043005C0054006F006D00520000004848484848483800000048484848580200007043010084030000FFFFFFFF07000000000000000000000000000000000000000000000000000000000000000000000000000000DDDD0000000000000115D3010000000000A0ABD56D4CC8010115D301000000000080D8FCAD84D001000000000000000000000000000000000000000000000000FFFFFFFF0100000001000000000000000001000001000000100E000000000000
    DynamicInfo    REG_BINARY    0300000060E4658F9BADD00100000000000000000000000000000000

HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Schedule\Taskcache\Tasks\{28011108-68DF-4C73-B91B-57427D501BBA}
    Path    REG_SZ    \Microsoft\Windows\Active Directory Rights Management Services Client\AD RMS Rights Policy Template Management (Manual)
    Triggers    REG_BINARY    1500000000000000001C24FBFE0700000000000000000000001C24FBFE070000FFFFFFFFFFFFFFFFF885400248484848CE52BAAA484848480048484848484848004848484848484805000000484848480C00000048484848010100000000000100000000484848480000000048484848380000004848484858020000100E0000100E0000FFFFFFFF07000000000000000000000000000000000000000000000000000000000000000000000000000000AAAA000000000000001C24FBFE0700000000000000000000001C24FBFE070000FFFFFFFFFFFFFFFF100E0000FFFFFFFF00000000000000000000000000000000000000000000000000000000030000000148484848484848
    DynamicInfo    REG_BINARY    030000008B8BF32C4104CA0100000000000000000000000000000000
    Hash    REG_BINARY    62050C0D7C474998414FA2C47E4D346ECE628D7D974F377EE3B8AE2E60982EE3

HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Schedule\Taskcache\Tasks\{29BBD2BA-5D45-4CB7-965D-1CD982162CA3}
    Path    REG_SZ    \Microsoft\Windows\Windows Activation Technologies\ValidationTaskDeadline
    Triggers    REG_BINARY    150000000000000000D33101000000008042E1735531D30100D3310100000000FFFFFFFFFFFFFFFFC821C20248484848D2DF9E46484848480048484848484848004848484848484805000000484848480C00000048484848010100000000000513000000484848480000000048484848380000004848484800000000FFFFFFFF00000000FFFFFFFF07000000000000000000000000000000000000000000000000000000000000000000000000000000DDDD00000000000000D33101000000008042E1735531D30100000000000000000000000000000000000000000000000000000000000000000000000000000000FFFFFFFF010000005A0000000000000000010000010000000000000000000000
    DynamicInfo    REG_BINARY    03000000A8AD199C4B2CCB0100000000000000000000000000000000
    Hash    REG_BINARY    151DE2425BDACEC8BFD009484E0BC200E42EBF3932C070471D0261D40FDB8956

HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Schedule\Taskcache\Tasks\{2D70F1F8-E61A-46C8-B602-8C0F8C536A9D}
    Path    REG_SZ    \Microsoft\Windows\SideShow\AutoWake
    Triggers    REG_BINARY    1500000000000000000000000000000000000000000000000000000000000000FFFFFFFFFFFFFFFF00210202484848481CE1E052484848480048484848484848004848484848484805000000484848480C00000048484848010100000000000513000000484848480000000048484848380000004848484800000000FFFFFFFF00000000FFFFFFFF07000000000000000000000000000000000000000000000000000000000000000000000000000000AAAA000000000000000000000000000000000000000000000000000000000000FFFFFFFFFFFFFFFF3C000000FFFFFFFF00000000000000000000000000000000010078010000000005000000000000000148484848484848
    DynamicInfo    REG_BINARY    030000008032CA4701DCCA0100000000000000000000000000000000
    Hash    REG_BINARY    F1F3647B90EF320699C2A4CC877553D0AF5FBC91CCA73EC5D21D2C69ABA97BE7

HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Schedule\Taskcache\Tasks\{2F57269B-1E09-4E2D-AB1E-B0FDAC7D279C}
    Path    REG_SZ    \Microsoft\Windows\WindowsBackup\ConfigNotification
    Triggers    REG_BINARY    1500000000000000018B38000000000000908A6739E1CA01008B380000000000FFFFFFFFFFFFFFFF48214202484848488E099A96484848480048484848484848004848484848484805000000484848480C00000048484848010100000000000513000000484848480000000048484848380000004848484800000000FFFFFFFF80F40300FFFFFFFF07000000000000000000000000000000000000000000000000000000720000000000000000000000DDDD000000000000018B38000000000000908A6739E1CA0100000000000000000000000000000000000000000000000000000000000000000000000000000000FFFFFFFF01000000010000000000000000010000010000000000000000000000
    DynamicInfo    REG_BINARY    030000004E590B2D4104CA0100000000000000000000000000000000
    Hash    REG_BINARY    D524823E731AD9050780CB39719985B52D72C1FE4B2343141EB6CBF421F49F9D

HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Schedule\Taskcache\Tasks\{2FEF85B2-6B9E-476C-A637-B03479D6C607}
    Path    REG_SZ    \Microsoft\Windows\Media Center\PBDADiscovery
    Triggers    REG_BINARY    150000000000000000FFFFFFFFFFFFFFFFFFFFFFFFFFFFFF00FFFFFFFFFFFFFF000000000000000000214202484848484AC29224484848480048484848484848004848484848484805000000484848480C000000484848480101000000000005120000004848484800000000484848480000000048484848
    DynamicInfo    REG_BINARY    0300000060B3E04801DCCA0100000000000000000000000000000000
    Hash    REG_BINARY    FD760AB16D2846C5BFB23557934499A525D5FCEC624AD083FD21DDE1326FAE9D

HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Schedule\Taskcache\Tasks\{383EAD95-C762-4EB9-9AB8-78CCE1AF3C38}
    Path    REG_SZ    \Norton Internet Security\Norton Error Analyzer
    Hash    REG_BINARY    E63BB14A6948B0D356808B8FF08BBAAC07D0171CE7599A41B06C46AC7B73B636
    Triggers    REG_BINARY    150000000000000000FFFFFFFFFFFFFFFFFFFFFFFFFFFFFF00FFFFFFFFFFFFFF00000000000000000805420148484848859C7E07484848480048484848484848004848484848484805000000484848480C00000048484848010100000000000512000000484848480000000048484848380000004848484858020000100E0000100E0000FFFFFFFF07000000000000000000000000000000000000000000000000000000000000000000000000000000

HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Schedule\Taskcache\Tasks\{3AF48B03-9CD2-4EDC-9FB4-A5EC0C31A32C}
    Path    REG_SZ    \Microsoft\Windows\Media Center\SqlLiteRecoveryTask
    Triggers    REG_BINARY    150000000000000000FFFFFFFFFFFFFFFFFFFFFFFFFFFFFF00FFFFFFFFFFFFFF00000000000000000005420248484848BB353C89484848480048484848484848004848484848484805000000484848480C000000484848480101000000000005140000004848484800000000484848480000000048484848
    DynamicInfo    REG_BINARY    03000000C0B36C4D01DCCA0100000000000000000000000000000000
    Hash    REG_BINARY    0582C3DC8E70BC6FAEEB500EB43EEBB03B2D607B40B61B59C0BC46292F5BE42A

HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Schedule\Taskcache\Tasks\{47536D45-EEEC-4BDC-8183-A4DC1F8DA9E4}
    Path    REG_SZ    \Microsoft\Windows\Customer Experience Improvement Program\UsbCeip
    Triggers    REG_BINARY    1500000000000000011272FBFE070000009C9EE073A6C801001272FBFE070000FFFFFFFFFFFFFFFF7021C2024848484863251B5D484848480048484848484848004848484848484805000000484848480C00000048484848010100000000000513000000484848480000000048484848380000004848484800000000FFFFFFFF80F40300FFFFFFFF070000008C0A00000100000000000000000000000000000000000000750070000000000000000000DDDD000000000000011272FBFE070000009C9EE073A6C80100000000000000000000000000000000000000000000000000000000000000000000000000000000FFFFFFFF01000000030000000000000000010000010000000000000000000000
    DynamicInfo    REG_BINARY    03000000AEBA0D2D4104CA0100000000000000000000000000000000
    Hash    REG_BINARY    AE1862BA409924248DC1736D23E327B7154018FC40A4DA695BC777D1135A5244

HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Schedule\Taskcache\Tasks\{486D715E-6AA2-44CF-BC48-B6990CBB53C6}
    Path    REG_SZ    \Microsoft\Windows\Shell\WindowsParentalControlsMigration
    Triggers    REG_BINARY    1500000000000000000000000000000000000000000000000000000000000000FFFFFFFFFFFFFFFF400582034848484879F2196C484848480048484848484848004848484848484805000000484848480C00000048484848010100000000000512000000484848480000000048484848380000004848484800000000FFFFFFFF00000000FFFFFFFF070000003C0000000100000000000000000000000000000000000000750070000000000000000000AAAA000000000000000000000000000000000000000000000000000000000000FFFFFFFFFFFFFFFF01000000FFFFFFFF00000000000000000000000000000000010041003B003B003B004200410029000148484848484848
    DynamicInfo    REG_BINARY    03000000ACAFFA2C4104CA0100000000000000000000000000000000
    Hash    REG_BINARY    6D5D71FCD9AF69DE33A5E47E6DE894CAD15A010944B2EF58C072C7F61EDB87E8

HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Schedule\Taskcache\Tasks\{4B4C6847-EB01-4D6B-858A-41F8352F8BC9}
    Path    REG_SZ    \Microsoft\Windows\Media Center\ObjectStoreRecoveryTask
    Triggers    REG_BINARY    150000000000000000FFFFFFFFFFFFFFFFFFFFFFFFFFFFFF00FFFFFFFFFFFFFF00000000000000000005420248484848073581F7484848480048484848484848004848484848484805000000484848480C000000484848480101000000000005140000004848484800000000484848480000000048484848
    DynamicInfo    REG_BINARY    03000000C092334D01DCCA0100000000000000000000000000000000
    Hash    REG_BINARY    0D7CE53B5DEDF3BB738E23E6AFCFF4829C8AF0A3B1179EFB42DD3DAFED865833

HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Schedule\Taskcache\Tasks\{4C8B01A2-11FF-4C41-848F-508EF4F00CF7}
    Path    REG_SZ    \Microsoft\Windows\TextServicesFramework\MsCtfMonitor
    Triggers    REG_BINARY    1500000000000000001624FBFE0700000000000000000000001624FBFE070000FFFFFFFFFFFFFFFF0085C00248484848E774F314484848480048484848484848004848484848484804000000484848481000000048484848010200000000000520000000210200000000000048484848380000004848484800000000FFFFFFFF00000000FFFFFFFF07000000000000000000000000000000000000000000000000000000750070000000000000000000AAAA000000000000001624FBFE0700000000000000000000001624FBFE070000FFFFFFFFFFFFFFFF00000000FFFFFFFF00000000000000000000000000000000010000000000000000000000030000000148484848484848
    DynamicInfo    REG_BINARY    030000000C11FD2C4104CA0100000000000000000000000000000000
    Hash    REG_BINARY    F7CCB39021E7E245CADCD75E426102522087DD3AC91AF7D4387D8D70ED6DDAB4

HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Schedule\Taskcache\Tasks\{4E123E26-F25D-4531-940D-1CE792873193}
    Path    REG_SZ    \Microsoft\Windows\Setup\gwx\launchtrayprocess
    Hash    REG_BINARY    93E30285FEF89B0B1703BB0FBAB52ACDA7984EB32E5D35CE5EAC8B9B19FBD193
    Triggers    REG_BINARY    1500000000000000000000000000000000000000000000000000000000000000FFFFFFFFFFFFFFFF40854002484848489F7D6B40484848480048484848484848004848484848484805000000484848480C00000048484848010100000000000504000000484848480000000048484848380000004848484800000000FFFFFFFF00000000FFFFFFFF0600000000000000000000000000000000000000000000000000000052006F000000000000000000AAAA00000000000001A2F5010000000000201676A646CE010000000000000000FFFFFFFFFFFFFFFF0F000000FFFFFFFF00000000000000000000000000000000010064006C006C002C002D003500300001484848484848488888000000000000000000000000000000000000000000000000000000000000FFFFFFFFFFFFFFFF00000000FFFFFFFF0000000000000000000000000007000001006F0072002E006500780065000000
    DynamicInfo    REG_BINARY    03000000C09C417A3B1AD10100000000000000000000000000000000

HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Schedule\Taskcache\Tasks\{51A295A6-300F-46E4-B98A-DF89A97815D3}
    Path    REG_SZ    \Microsoft\Windows\Media Center\PvrRecoveryTask
    Triggers    REG_BINARY    150000000000000000FFFFFFFFFFFFFFFFFFFFFFFFFFFFFF00FFFFFFFFFFFFFF0000000000000000000542024848484831C9DCAA484848480048484848484848004848484848484805000000484848480C000000484848480101000000000005140000004848484800000000484848480000000048484848
    DynamicInfo    REG_BINARY    03000000C07C0D4D01DCCA0100000000000000000000000000000000
    Hash    REG_BINARY    F18E7E603225B086AE1605B0EDDA4E41A11A6940F8C50583C566546D4753DBF9

HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Schedule\Taskcache\Tasks\{51BE84C4-5631-4EF6-B076-5745D35B06F5}
    Path    REG_SZ    \Microsoft\Windows\Setup\GWXTriggers\refreshgwxconfig-B
    Hash    REG_BINARY    556E06A2A3869023D1F169CD55A33855EFEE027AFA831F9F3901D14CDA3F3161
    Triggers    REG_BINARY    150000000000000001C8B6010000000000201676A646CE0100C8B60100000000FFFFFFFFFFFFFFFFC821420148484848925369A9484848480048484848484848004848484848484805000000484848480C00000048484848010100000000000512000000484848480000000048484848380000004848484800000000FFFFFFFF00000000FFFFFFFF07000000000000000000000000000000000000000000000000000000000000000000000000000000DDDD00000000000001C8B6010000000000201676A646CE010000000000000000000000000000000000000000000000000000000000000000C0A8000080510100FFFFFFFF0100000001000000000000000001000001000000C0A8000000000000
    DynamicInfo    REG_BINARY    030000007002FE107921D30100000000000000000000000000000000

HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Schedule\Taskcache\Tasks\{53BB7902-6E80-4F0D-B21C-501FE9C0E32E}
    Path    REG_SZ    \Microsoft\Windows\Media Center\RecordingRestart
    Triggers    REG_BINARY    1500000000000000000000000000000000000000000000000000000000000000FFFFFFFFFFFFFFFF60050202484848483E01CFAF484848480048484848484848004848484848484805000000484848480C00000048484848010100000000000514000000484848480000000048484848380000004848484800000000FFFFFFFF80F40300FFFFFFFF06000000000000000000000000000000000000000000000000000000000000000000000000000000FFFF000000000000000000000000000000000000000000000000000000000000FFFFFFFFFFFFFFFF00000000FFFFFFFF00000000000000000000000000070000010063006E002000300000006E006900
    DynamicInfo    REG_BINARY    03000000A021A74C01DCCA0100000000000000000000000000000000
    Hash    REG_BINARY    F5FE5470249EA95DE2CB01D9FA910FB31957ED0FB0F9E03208A37081A057AA08

HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Schedule\Taskcache\Tasks\{586D03C8-7997-4FDC-8F49-2F396233504A}
    Path    REG_SZ    \Microsoft\Windows\Media Center\ConfigureInternetTimeService
    Triggers    REG_BINARY    150000000000000000FFFFFFFFFFFFFFFFFFFFFFFFFFFFFF00FFFFFFFFFFFFFF00000000000000000021420248484848334EC699484848480048484848484848004848484848484805000000484848480C000000484848480101000000000005120000004848484800000000484848480000000048484848
    DynamicInfo    REG_BINARY    03000000803A934901DCCA0100000000000000000000000000000000
    Hash    REG_BINARY    1A61FB3046F2F771F436B66EDEC9EEC6E1E9E3F219AA4224495928E6BC347BEE

HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Schedule\Taskcache\Tasks\{59FCD788-0753-4F0B-A5CB-D300883F1B39}
    Path    REG_SZ    \Microsoft\Windows\Media Center\ActivateWindowsSearch
    Triggers    REG_BINARY    150000000000000000FFFFFFFFFFFFFFFFFFFFFFFFFFFFFF00FFFFFFFFFFFFFF000000000000000000214202484848489039649F484848480048484848484848004848484848484805000000484848480C000000484848480101000000000005120000004848484800000000484848480000000048484848
    DynamicInfo    REG_BINARY    03000000C0DA394A01DCCA0100000000000000000000000000000000
    Hash    REG_BINARY    440979398F3AB418F90B93DC0DD97070F5EF2337860AB42775202EF71D70B9E9

HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Schedule\Taskcache\Tasks\{5A40E926-9E86-4B89-9CFD-B12311724371}
    Path    REG_SZ    \Microsoft\Windows\UPnP\UPnPHostConfig
    Triggers    REG_BINARY    150000000000000000FFFFFFFFFFFFFFFFFFFFFFFFFFFFFF00FFFFFFFFFFFFFF0000000000000000102142024848484811E47727484848480048484848484848004848484848484805000000484848480C000000484848480101000000000005120000004848484800000000484848480000000048484848
    DynamicInfo    REG_BINARY    030000006F7D122D4104CA0100000000000000000000000000000000
    Hash    REG_BINARY    6A0C38920812DABEF61FED2083D14E9E085CDBD0F5459B3159F0F4504CC8B4B0

HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Schedule\Taskcache\Tasks\{5B42DD9C-5A26-4F27-BB95-34603F0997E5}
    Path    REG_SZ    \Microsoft\Windows\Shell\WindowsParentalControls
    Triggers    REG_BINARY    1500000000000000001624FBFE0700000000000000000000001624FBFE070000FFFFFFFFFFFFFFFF4085800248484848E149B4C1484848480048484848484848004848484848484805000000484848480C0000004848484801010000000000050B000000484848480000000048484848380000004848484800000000FFFFFFFF00000000FFFFFFFF070000003C0000000500000000000000000000000000000000000000750070000000000000000000AAAA000000000000001624FBFE0700000000000000000000001624FBFE070000FFFFFFFFFFFFFFFF01000000FFFFFFFF00000000000000000000000000000000000000000000000000000000030000000148484848484848
    DynamicInfo    REG_BINARY    030000000C11FD2C4104CA0100000000000000000000000000000000
    Hash    REG_BINARY    886511E7DEE4F447B2F704A04046BB942BD9BDA76152A12BB0AE3D9B56C6AAF5

HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Schedule\Taskcache\Tasks\{5F5A18EB-DC73-4E45-A11C-B59043598412}
    Path    REG_SZ    \Microsoft\Windows\CertificateServicesClient\SystemTask
    Triggers    REG_BINARY    1500000000000000001C24FBFE0700000000000000000000001C24FBFE070000FFFFFFFFFFFFFFFFC0054202484848484E9F42CE484848480048484848484848004848484848484805000000484848480C00000048484848010100000000000512000000484848480000000048484848380000004848484800000000FFFFFFFF00000000FFFFFFFF070000003C0000000500000000000000000000000000000000000000750070000000000000000000CCCC000000000000001C24FBFE0700000000000000000000001C24FBFE070000FFFFFFFFFFFFFFFF00000000FFFFFFFF00000000000000000000000000000000010100000000000520000000000000001B010000000000003C00510075006500720079004C006900730074003E000A0020002000200020002000200020002000200020002000200020002000200020003C00510075006500720079002000490064003D00220030002200200050006100740068003D002200530079007300740065006D0022003E000A00200020002000200020002000200020002000200020002000200020002000200020002000200020003C00530065006C00650063007400200050006100740068003D002200530079007300740065006D0022003E000A002000200020002000200020002000200020002000200020002000200020002000200020002000200020002000200020002A005B00530079007300740065006D005B00500072006F00760069006400650072005B0040004E0061006D0065003D0027004D006900630072006F0073006F00660074002D00570069006E0064006F00770073002D00470072006F007500700050006F006C0069006300790027005D00200061006E00640020004500760065006E007400490044003D0031003500300032005D005D000A00200020002000200020002000200020002000200020002000200020002000200020002000200020003C002F00530065006C006500630074003E000A0020002000200020002000200020002000200020002000200020002000200020003C002F00510075006500720079003E000A0020002000200020002000200020002000200020002000200020002000200020003C002F00510075006500720079004C006900730074003E0000000000000000000000000000000000000000000000000000008888000000000000001624FBFE0700000000000000000000001624FBFE070000FFFFFFFFFFFFFFFF00000000FFFFFFFF0000000000000000000000000000000001000000000000000000000003000000FFFF000000000000001624FBFE0700000000000000000000001624FBFE070000FFFFFFFFFFFFFFFF0A000000FFFFFFFF8070000000000000000000000000000001006500720073000000000003000000
    DynamicInfo    REG_BINARY    03000000C8BDDB2C4104CA0100000000000000000000000000000000
    Hash    REG_BINARY    5F1741F0E3673AEE6B7D983CDB718C34640A8C20B8D2F627B7AA491C12F16358

HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Schedule\Taskcache\Tasks\{613612BA-897D-44CE-8DC1-8FC283F9FD51}
    Path    REG_SZ    \Microsoft\Windows\Active Directory Rights Management Services Client\AD RMS Rights Policy Template Management (Automated)
    Triggers    REG_BINARY    1500000000000000001C24FBFE0700000000000000000000001272FBFE070000FFFFFFFFFFFFFFFFC8850002484848484F482AB2484848480048484848484848004848484848484805000000484848480C00000048484848010100000000000100000000484848480000000048484848380000004848484858020000100E0000100E0000FFFFFFFF07000000000000000000000000000000000000000000000000000000000000000000000000000000DDDD000000000000011272FBFE07000000781825AB03C70100000000000000000000000000000000000000000000000000000000000000000000000000000000FFFFFFFF0100000001000000000000000001000001000000100E000000000000AAAA000000000000001C24FBFE0700000000000000000000001C24FBFE070000FFFFFFFFFFFFFFFF100E0000FFFFFFFF00000000000000000000000000000000010000000000000000000000030000000148484848484848
    DynamicInfo    REG_BINARY    030000006D72FF2C4104CA0100000000000000000000000000000000
    Hash    REG_BINARY    5FEA8C5D590E391F05DC6BF182EE76FA80BE1EC03C9F02439F1A619A1D371CBB

HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Schedule\Taskcache\Tasks\{63383B41-CD22-4AEF-B02D-D120C179FF58}
    Path    REG_SZ    \Microsoft\Windows\Setup\gwx\refreshgwxconfig
    Hash    REG_BINARY    8E3E95B1B936442EC697E14E29BCDD20D6C8E76D53F0FB402C41506433374923
    Triggers    REG_BINARY    150000000000000000FFFFFFFFFFFFFFFFFFFFFFFFFFFFFF00FFFFFFFFFFFFFF0000000000000000C021420348484848E54F2727484848480048484848484848004848484848484805000000484848480C00000048484848010100000000000512000000484848480000000048484848380000004848484800000000FFFFFFFF00000000FFFFFFFF06000000000000000000000000000000000000000000000000000000000000000000000000000000
    DynamicInfo    REG_BINARY    0300000020B408783B1AD10100000000000000000000000000000000

HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Schedule\Taskcache\Tasks\{65D42D99-7EA2-4D6A-AB62-B6EAB8D72F33}
    Path    REG_SZ    \Microsoft\Windows\Media Center\InstallPlayReady
    Triggers    REG_BINARY    150000000000000000FFFFFFFFFFFFFFFFFFFFFFFFFFFFFF00FFFFFFFFFFFFFF000000000000000000054202484848484A08CFB1484848480048484848484848004848484848484805000000484848480C000000484848480101000000000005120000004848484800000000484848480000000048484848
    DynamicInfo    REG_BINARY    03000000604DEB4901DCCA0100000000000000000000000000000000
    Hash    REG_BINARY    FA87213DE12B497A787F46A1863343D4C9578E30570573918454DF0528610310

HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Schedule\Taskcache\Tasks\{6738BA6E-EA75-4B6B-B8B8-71F0336DD8EF}
    Path    REG_SZ    \Microsoft\Windows\User Profile Service\HiveUploadTask
    Triggers    REG_BINARY    1500000000000000011272FBFE07000000406A6006E9C701001272FBFE070000FFFFFFFFFFFFFFFFC2210202484848480C2AD3B9484848480048484848484848004848484848484805000000484848480C00000048484848010100000000000512000000484848480000000048484848380000004848484858020000201C000080F40300FFFFFFFF07000000780000000300000000000000000000000000000000000000000000000000000000000000DDDD000000000000011272FBFE07000000406A6006E9C7010000000000000000000000000000000000000000000000000000000000000000C0A8000000000000FFFFFFFF0000000000000000000000000001000001000000100E000000000000
    DynamicInfo    REG_BINARY    03000000B972832E4104CA0100000000000000000000000000000000
    Hash    REG_BINARY    22735240F634AF52EB496CAC7F58E85D9ED7AF876AD31D5AE4C1F57C234E5728

HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Schedule\Taskcache\Tasks\{72DB7465-BC54-491B-A92A-4637A28C9BBF}
    Path    REG_SZ    \Microsoft\Windows\AppID\VerifiedPublisherCertStoreCheck
    Triggers    REG_BINARY    1500000000000000001624FBFE0700000000000000000000001624FBFE070000FFFFFFFFFFFFFFFF7E11020248484848218D22DB484848480048484848484848004848484848484805000000484848480C000000484848480101000000000005130000004848484800000000484848483800000048484848B40000007043010080F40300FFFFFFFF0A000000000000000000000000000000000000000000000000000000750070000000000000000000FFFF000000000000001624FBFE0700000000000000000000001624FBFE070000FFFFFFFFFFFFFFFF08070000FFFFFFFF8051010000000000000000000000000001000000000000000000000003000000
    DynamicInfo    REG_BINARY    03000000291FDE2C4104CA0100000000000000000000000000000000
    Hash    REG_BINARY    A8559F6CCCA2DF09F1225F5DCFF67D8C6FF124FC5F85DCDF7F191DC7CF13EADE

HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Schedule\Taskcache\Tasks\{753C47AE-EC5E-44B3-95A9-2C8E553F0E39}
    Path    REG_SZ    \Microsoft\Windows\Windows Media Sharing\UpdateLibrary
    Triggers    REG_BINARY    1500000000000000001624FBFE0700000000000000000000001624FBFE070000FFFFFFFFFFFFFFFF4085400248484848EC26CB6D484848480048484848484848004848484848484805000000484848480C0000004848484801010000000000050B0000004848484800000000484848480000000048484848CCCC000000000000001624FBFE0700000000000000000000001624FBFE070000FFFFFFFFFFFFFFFF00000000FFFFFFFF00000000000000000000000000000000010100000000000520000000000000001E010000000000003C00510075006500720079004C006900730074003E000A00200020002000200020002000200020002000200020002000200020003C00510075006500720079000A00200020002000200020002000200020002000200020002000200020002000200020002000490064003D002200300022000A0020002000200020002000200020002000200020002000200020002000200020002000200050006100740068003D002200530079007300740065006D0022000A002000200020002000200020002000200020002000200020002000200020002000200020003E000A0020002000200020002000200020002000200020002000200020002000200020003C00530065006C00650063007400200050006100740068003D002200530079007300740065006D0022003E002A005B00530079007300740065006D005B00500072006F00760069006400650072005B0040004E0061006D0065003D0027004D006900630072006F0073006F00660074002D00570069006E0064006F00770073002D0057004D0050004E00530053002D00530065007200760069006300650027005D00200061006E006400200028004500760065006E007400490044003D003100340032003100300029005D005D003C002F00530065006C006500630074003E000A00200020002000200020002000200020002000200020002000200020003C002F00510075006500720079003E000A002000200020002000200020002000200020002000200020003C002F00510075006500720079004C006900730074003E0000004848000000000000000000000000000000000000000000000000
    DynamicInfo    REG_BINARY    030000007A35882E4104CA0100000000000000000000000000000000
    Hash    REG_BINARY    72A5683A40FAA291AA33CC4DD71A02E9E691D7C5A7BA213B817C759F7D4E24BE

HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Schedule\Taskcache\Tasks\{7AFCC0CA-7121-422A-AB45-B0E8D599FF08}
    Path    REG_SZ    \Microsoft\Windows\CertificateServicesClient\UserTask
    Triggers    REG_BINARY    1500000000000000001C24FBFE0700000000000000000000001C24FBFE070000FFFFFFFFFFFFFFFFC085400248484848965281FA484848480048484848484848004848484848484805000000484848480C00000048484848010100000000000504000000484848480000000048484848380000004848484800000000FFFFFFFF00000000FFFFFFFF070000003C0000000500000000000000000000000000000000000000000000000000000000000000CCCC000000000000001C24FBFE0700000000000000000000001C24FBFE070000FFFFFFFFFFFFFFFF00000000FFFFFFFF0000000000000000000000000000000001010000000000052000000000000000A5000000000000003C00510075006500720079004C006900730074003E003C00510075006500720079002000490064003D00220030002200200050006100740068003D002200530079007300740065006D0022003E003C00530065006C00650063007400200050006100740068003D002200530079007300740065006D0022003E002A005B00530079007300740065006D005B00500072006F00760069006400650072005B0040004E0061006D0065003D0027004D006900630072006F0073006F00660074002D00570069006E0064006F00770073002D00470072006F007500700050006F006C0069006300790027005D00200061006E00640020004500760065006E007400490044003D0031003500300033005D005D003C002F00530065006C006500630074003E003C002F00510075006500720079003E003C002F00510075006500720079004C006900730074003E000000484848480000000000000000000000000000000000000000000000008888000000000000001624FBFE0700000000000000000000001624FBFE070000FFFFFFFFFFFFFFFF00000000FFFFFFFF0000000000000000000000000000000001000000000000000000000003000000AAAA000000000000001624FBFE0700000000000000000000001624FBFE070000FFFFFFFFFFFFFFFF00000000FFFFFFFF80700000000000000000000000000000010000000000000000000000030000000148484848484848
    DynamicInfo    REG_BINARY    030000006D72FF2C4104CA0100000000000000000000000000000000
    Hash    REG_BINARY    DB89FE61B38CF541D584C34612B856A825EF9A287779F0CCBFAA95A0183E8781

HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Schedule\Taskcache\Tasks\{7D8D2001-718E-43EA-A986-73BDD46C6B6A}
    Path    REG_SZ    \Microsoft\Windows\Media Center\mcupdate
    Triggers    REG_BINARY    150000000000000000FFFFFFFFFFFFFFFFFFFFFFFFFFFFFF00FFFFFFFFFFFFFF00000000000000006005420248484848A548697F484848480048484848484848004848484848484805000000484848480C00000048484848010100000000000514000000484848480000000048484848380000004848484800000000FFFFFFFF80F40300FFFFFFFF060000000000000000000000000000000000000000000000000000002E0045000000000000000000
    DynamicInfo    REG_BINARY    030000006005E54C01DCCA0100000000000000000000000000000000
    Hash    REG_BINARY    D23B7887DFD927FA2B59E80B7E060FA80CAAA1E83153B4053EF49F210FFA35C6

HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Schedule\Taskcache\Tasks\{7D97DDB4-6C77-450C-BA4E-FB3ED96AA490}
    Path    REG_SZ    \Microsoft\Windows\Media Center\OCURDiscovery
    Triggers    REG_BINARY    150000000000000000FFFFFFFFFFFFFFFFFFFFFFFFFFFFFF00FFFFFFFFFFFFFF000000000000000000214202484848485C36CF06484848480048484848484848004848484848484805000000484848480C000000484848480101000000000005120000004848484800000000484848480000000048484848
    DynamicInfo    REG_BINARY    03000000A0DAB54801DCCA0100000000000000000000000000000000
    Hash    REG_BINARY    1FC092677FA581A6F0D9017D0F02E74681A0DA6B0AF0EEF0E204E92D1605757A

HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Schedule\Taskcache\Tasks\{7E5A4FEF-DD93-45B9-A363-8A68B88823C2}
    Path    REG_SZ    \Microsoft\Windows\Media Center\PvrScheduleTask
    Triggers    REG_BINARY    150000000000000000FFFFFFFFFFFFFFFFFFFFFFFFFFFFFF00FFFFFFFFFFFFFF000000000000000000054202484848483A1B96C3484848480048484848484848004848484848484805000000484848480C000000484848480101000000000005140000004848484800000000484848480000000048484848
    DynamicInfo    REG_BINARY    03000000C0C9924D01DCCA0100000000000000000000000000000000
    Hash    REG_BINARY    695AC268A441273AAAC43B4C25E863C354D8400FF37237317343CD29A22A2CEF

HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Schedule\Taskcache\Tasks\{7F946C6C-5401-4324-9B15-70C5B0892EE6}
    Path    REG_SZ    \Microsoft\Windows\Setup\gwx\refreshgwxcontent
    Hash    REG_BINARY    5EB89F171FFD3C8EDDDE4FBDD5495B9F9BD4CFF24E792B010108D2832B6079FA
    Triggers    REG_BINARY    150000000000000000FFFFFFFFFFFFFFFFFFFFFFFFFFFFFF00FFFFFFFFFFFFFF0000000000000000C021420348484848CDB5BFA9484848480048484848484848004848484848484805000000484848480C00000048484848010100000000000512000000484848480000000048484848380000004848484800000000FFFFFFFF00000000FFFFFFFF06000000000000000000000000000000000000000000000000000000000000000000000000000000
    DynamicInfo    REG_BINARY    03000000E0263E793B1AD10100000000000000000000000000000000

HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Schedule\Taskcache\Tasks\{81540B9F-B5BF-47EB-9C95-BE195BF2C664}
    Path    REG_SZ    \Microsoft\Windows\NetTrace\GatherNetworkInfo
    Triggers    REG_BINARY    150000000000000000FFFFFFFFFFFFFFFFFFFFFFFFFFFFFF00FFFFFFFFFFFFFF00000000000000000085400348484848A31C713A484848480048484848484848004848484848484804000000484848481000000048484848010200000000000520000000210200000000000048484848380000004848484800000000FFFFFFFF80F40300FFFFFFFF07000000000000000000000000000000000000000000000000000000750070000000000000000000
    DynamicInfo    REG_BINARY    030000001CDF982E4104CA0100000000000000000000000000000000
    Hash    REG_BINARY    9E154171408F80E0D5CEB4D8F775758B345B3FD705AD0B3058B1732870BE807F

HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Schedule\Taskcache\Tasks\{880E621A-DD8A-497F-BED1-3311DA2C4FA1}
    Path    REG_SZ    \Microsoft\Windows\Windows Activation Technologies\ValidationTask
    Triggers    REG_BINARY    150000000000000000D331010000000080C2BFCB7929D30100D3310100000000FFFFFFFFFFFFFFFFC221C202484848480F390555484848480048484848484848004848484848484805000000484848480C0000004848484801010000000000051300000048484848000000004848484838000000484848482C010000F0200D0000000000FFFFFFFF07000000000000000000000000000000000000000000000000000000000000000000000000000000DDDD00000000000000D331010000000080C2BFCB7929D30100000000000000000000000000000000000000000000000000000000000000000000000000000000FFFFFFFF010000005A0000000000000000010000010000000000000000000000
    DynamicInfo    REG_BINARY    03000000E8C9DB9B4B2CCB0100000000000000000000000000000000
    Hash    REG_BINARY    FAFBC0BF3A62F2E5CE150BD30A2BFF584DE2C3DE87739509360E32F0F83793C9

HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Schedule\Taskcache\Tasks\{8A9251B2-FAB7-49A1-BA84-9F104776E7A7}
    Path    REG_SZ    \Microsoft\Windows\Media Center\DispatchRecoveryTasks
    Triggers    REG_BINARY    150000000000000000FFFFFFFFFFFFFFFFFFFFFFFFFFFFFF00FFFFFFFFFFFFFF00000000000000000805420248484848F616133B484848480048484848484848004848484848484805000000484848480C00000048484848010100000000000512000000484848480000000048484848380000004848484800000000FFFFFFFF80F40300FFFFFFFF07000000000000000000000000000000000000000000000000000000000000000000000000000000
    DynamicInfo    REG_BINARY    03000000C0F05F4A01DCCA0100000000000000000000000000000000
    Hash    REG_BINARY    8DF1277ABA0042B7C7EB16962614C447A3CE1446BD29473CE630657F25F00AA9

HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Schedule\Taskcache\Tasks\{8BDF0314-A8E0-4A71-9E60-0F7C1739DE56}
    Path    REG_SZ    \Microsoft\Windows\SideShow\SystemDataProviders
    Triggers    REG_BINARY    1500000000000000000000000000000000000000000000000000000000000000FFFFFFFFFFFFFFFF002102024848484888275990484848480048484848484848004848484848484805000000484848480C00000048484848010100000000000513000000484848480000000048484848380000004848484800000000FFFFFFFF00000000FFFFFFFF07000000000000000000000000000000000000000000000000000000200020000000000000000000AAAA000000000000000000000000000000000000000000000000000000000000FFFFFFFFFFFFFFFF1E000000FFFFFFFF0000000000000000000000000000000001729D010000000005000000000000000148484848484848
    DynamicInfo    REG_BINARY    03000000C0599F4701DCCA0100000000000000000000000000000000
    Hash    REG_BINARY    8DFB2AAA49E262BC3CA3901D44152079D55567AAA637743E01E34DF36A5FB4C7

HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Schedule\Taskcache\Tasks\{92771DAF-0E34-4CC5-9653-7A6E793544E5}
    Path    REG_SZ    \CCleanerSkipUAC
    Hash    REG_BINARY    52DB621C8F667ECC9A412ECA970868065966AB48642819D8A8EA05C0FB01E9F7
    Triggers    REG_BINARY    15000000000000000009000000000000FFFFFFFFFFFFFFFF000900000000000000000000000000000805410148484848022B4C0A484848480048484848484848004848484848484801000000484848481C0000004848484801050000000000051500000092B8DC2EB2B4B4A8316AA1B3E8030000484848481A0000004848484854006F006D0052002D00500043005C0054006F006D0052000000484848484848380000004848484800000000FFFFFFFF80F40300FFFFFFFF07000000000000000000000000000000000000000000000000000000000000000000000000000000
    DynamicInfo    REG_BINARY    030000000000000000000000200CCB731C21D3010000000000000000

HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Schedule\Taskcache\Tasks\{9435F817-FED2-454E-88CD-7F78FDA62C48}
    Path    REG_SZ    \Microsoft\Windows\WDI\ResolutionHost
    Triggers    REG_BINARY    150000000000000000FFFFFFFFFFFFFFFFFFFFFFFFFFFFFF00FFFFFFFFFFFFFF00000000000000000085C003484848489D84F470484848480048484848484848004848484848484805000000484848480C00000048484848010100000000000504000000484848480000000048484848380000004848484800000000FFFFFFFF00000000FFFFFFFF0A000000000000000000000000000000000000000000000000000000750070000000000000000000
    DynamicInfo    REG_BINARY    030000007C409B2E4104CA0100000000000000000000000000000000
    Hash    REG_BINARY    7678F283CD528277951D5955D00319DC3E404F5D6AD8E0806B80DC781E7181CA

HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Schedule\Taskcache\Tasks\{994C86AD-A929-4B2C-88A0-4E25A107A029}
    Path    REG_SZ    \Microsoft\Windows\SystemRestore\SR
    Triggers    REG_BINARY    1500000000000000001C24FBFE0700000000000000000000001272FBFE070000FFFFFFFFFFFFFFFF5221420248484848EDD0741F484848480048484848484848004848484848484805000000484848480C000000484848480101000000000005120000004848484800000000484848483800000048484848580200007043010080F40300FFFFFFFF07000000000000000000000000000000000000000000000000000000220020000000000000000000DDDD000000000000011272FBFE0700000080E1017470C50100000000000000000000000000000000000000000000000000000000000000000000000000000000FFFFFFFF01000000010000000000000000010000010000000000000000000000FFFF000000000000001C24FBFE0700000000000000000000001C24FBFE070000FFFFFFFFFFFFFFFF08070000FFFFFFFF0000000000000000000000000000000001000000000000000000000003000000
    DynamicInfo    REG_BINARY    03000000E9E1E22C4104CA0100000000000000000000000000000000
    Hash    REG_BINARY    A2281A82814B04BF0AE2441991C482C4859EA3BFF19E695D72CDF0B8E25A481C

HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Schedule\Taskcache\Tasks\{9979CB83-103A-4105-9E5D-C74B0AF6D198}
    Path    REG_SZ    \Microsoft\Windows\CertificateServicesClient\UserTask-Roam
    Triggers    REG_BINARY    1500000000000000000000000000000000000000000000000000000000000000FFFFFFFFFFFFFFFF908500024848484824A4C7D0484848480048484848484848004848484848484805000000484848480C00000048484848010100000000000504000000484848480000000048484848380000004848484800000000FFFFFFFF00000000FFFFFFFF070000003C00000005000000000000000000000000000000000000000000000000000000000000007777000000000000000000000000000000000000000000000000000000000000FFFFFFFFFFFFFFFF00000000FFFFFFFF0000000000000000000000000000000001FFFFFF020000000100100000000000070000000000000001484848484848487777000000000000000000000000000000000000000000000000000000000000FFFFFFFFFFFFFFFF00000000FFFFFFFF0000000000000000000000000000000001665300000000000000000000000000080000008573C0010148484848484848
    DynamicInfo    REG_BINARY    03000000DCA19D2E4104CA0100000000000000000000000000000000
    Hash    REG_BINARY    F2CE6AB8C22DCF1780141867455A46FA6D08F08C5B5D482002372E5FDE059B43

HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Schedule\Taskcache\Tasks\{A35BB7A6-5F0C-4C9F-8450-2B3BED532D51}
    Path    REG_SZ    \Microsoft\Windows\WindowsColorSystem\Calibration Loader
    Triggers    REG_BINARY    1500000000000000000000000000000000000000000000000000000000000000FFFFFFFFFFFFFFFF0091000248484848A34B56BE484848480048484848484848004848484848484804000000484848481000000048484848010200000000000520000000210200000000000048484848380000004848484800000000FFFFFFFF00000000FFFFFFFF07000000000000000000000000000000000000000000000000000000750070000000000000000000AAAA000000000000000000000000000000000000000000000000000000000000FFFFFFFFFFFFFFFF00000000FFFFFFFF00000000000000000000000000000000010041003B003B003B0042004100290001484848484848487777000000000000000000000000000000000000000000000000000000000000FFFFFFFFFFFFFFFF00000000FFFFFFFF0000000000000000000000000000000001002D0065006E00650072006700790001000000000070000148484848484848
    DynamicInfo    REG_BINARY    03000000CDD3012D4104CA0100000000000000000000000000000000
    Hash    REG_BINARY    1C5E72CB821B89108191AC5B7FD3157B5CCE0474EDD44C9D1CEC819787F288AB

HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Schedule\Taskcache\Tasks\{A48CABBF-24C8-4B87-B00F-9261807C3B43}
    Path    REG_SZ    \Microsoft\Windows\AppID\PolicyConverter
    Triggers    REG_BINARY    150000000000000000FFFFFFFFFFFFFFFFFFFFFFFFFFFFFF00FFFFFFFFFFFFFF000000000000000040110202484848483498017A484848480048484848484848004848484848484805000000484848480C000000484848480101000000000005130000004848484800000000484848480000000048484848
    DynamicInfo    REG_BINARY    03000000D6017B2F4104CA0100000000000000000000000000000000
    Hash    REG_BINARY    C645BB8F8D8C5DE3EA7A893D785BD95FC06FA4D7810745FE4E78E392009FFFB8

HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Schedule\Taskcache\Tasks\{A6AF9377-77CE-47AB-AD7D-EC32CAD0C82D}
    Path    REG_SZ    \Microsoft\Windows\Location\Notifications
    Triggers    REG_BINARY    1500000000000000001624FBFE0700000000000000000000001624FBFE070000FFFFFFFFFFFFFFFF0085400248484848DFDD7976484848480048484848484848004848484848484805000000484848480C0000004848484801010000000000050B000000484848480000000048484848380000004848484800000000FFFFFFFF00000000FFFFFFFF07000000000000000000000000000000000000000000000000000000000000000000000000000000CCCC000000000000001624FBFE0700000000000000000000001624FBFE070000FFFFFFFFFFFFFFFF00000000FFFFFFFF0000000000000000000000000000000001010000000000052000000000000000A4000000000000003C00510075006500720079004C006900730074003E003C00510075006500720079002000490064003D00220030002200200050006100740068003D0022004100700070006C00690063006100740069006F006E0022003E003C00530065006C00650063007400200050006100740068003D0022004100700070006C00690063006100740069006F006E0022003E002A005B00530079007300740065006D005B00500072006F00760069006400650072005B0040004E0061006D0065003D0027004C006F0063006100740069006F006E004E006F00740069006600690063006100740069006F006E00730027005D00200061006E00640020004500760065006E007400490044003D0031005D005D003C002F00530065006C006500630074003E003C002F00510075006500720079003E003C002F00510075006500720079004C006900730074003E000000484848484848000000000000000000000000000000000000000000000000
    DynamicInfo    REG_BINARY    03000000D6017B2F4104CA0100000000000000000000000000000000
    Hash    REG_BINARY    E2EEC5DC638B16A8DCF4E83A3514F28DC7FFB5CA04854176D252D9095C29B343

HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Schedule\Taskcache\Tasks\{AC4E5ACF-89F7-4220-BA21-81EE183975E2}
    Path    REG_SZ    \Microsoft\Windows\Application Experience\AitAgent
    Triggers    REG_BINARY    1500000000000000011272FBFE0700000004C51F5309C801001272FBFE070000FFFFFFFFFFFFFFFF7E214202484848482774D537484848480048484848484848004848484848484805000000484848480C000000484848480101000000000005120000004848484800000000484848483800000048484848B40000006035010080F40300FFFFFFFF09000000000000000000000000000000000000000000000000000000000000000000000000000000DDDD000000000000011272FBFE0700000004C51F5309C80100000000000000000000000000000000000000000000000000000000000000000000000000000000FFFFFFFF01000000010000000000000000010000010000000000000000000000
    DynamicInfo    REG_BINARY    030000005787842F4104CA0100000000000000000000000000000000
    Hash    REG_BINARY    9A13FF7FB54C9212AAC3663AEE2889A6AFB0BA6898ABC3F9A811E6216987B833

HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Schedule\Taskcache\Tasks\{AC668097-4D6B-4093-AC14-014C09DBF820}
    Path    REG_SZ    \Microsoft\Windows\Ras\MobilityManager
    Triggers    REG_BINARY    1500000000000000001624FBFE0700000000000000000000001624FBFE070000FFFFFFFFFFFFFFFF40054202484848484716FF88484848480048484848484848004848484848484805000000484848480C000000484848480101000000000005130000004848484800000000484848480000000048484848CCCC000000000000001624FBFE0700000000000000000000001624FBFE070000FFFFFFFFFFFFFFFF00000000FFFFFFFF00000000000000000000000000000000010100000000000520000000000000002A010000000000003C00510075006500720079004C006900730074003E000A00200020002000200020002000200020002000200020002000200020003C00510075006500720079000A00200020002000200020002000200020002000200020002000200020002000200020002000490064003D002200300022000A0020002000200020002000200020002000200020002000200020002000200020002000200050006100740068003D0022004100700070006C00690063006100740069006F006E0022000A002000200020002000200020002000200020002000200020002000200020002000200020003E000A0020002000200020002000200020002000200020002000200020002000200020003C00530065006C00650063007400200050006100740068003D0022004100700070006C00690063006100740069006F006E0022003E002A005B00530079007300740065006D005B00500072006F00760069006400650072005B0040004E0061006D0065003D00270052006100730043006C00690065006E00740027005D00200061006E006400200028004C006500760065006C003D00340020006F00720020004C006500760065006C003D0030002900200061006E006400200028004500760065006E007400490044003D003200300032003800310029005D005D003C002F00530065006C006500630074003E000A00200020002000200020002000200020002000200020002000200020003C002F00510075006500720079003E000A002000200020002000200020002000200020002000200020003C002F00510075006500720079004C006900730074003E0000004848000000000000000000000000000000000000000000000000
    DynamicInfo    REG_BINARY    0300000098CF922F4104CA0100000000000000000000000000000000
    Hash    REG_BINARY    472F2F6E40D88458D92B946C81BA9225D63C0BD045FBAB63CAEF1904BC35BA73

HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Schedule\Taskcache\Tasks\{AEA35300-8D3F-4FFA-9243-5072A3D37166}
    Path    REG_SZ    \Microsoft\Windows\Offline Files\Logon Synchronization
    Triggers    REG_BINARY    1500000000000000000000000000000000000000000000000000000000000000FFFFFFFFFFFFFFFFF0A1000248484848532B4026484848480048484848484848004848484848484805000000484848480C0000004848484801010000000000050B000000484848480000000048484848380000004848484800000000FFFFFFFF80510100FFFFFFFF07000000000000000000000000000000000000000000000000000000200020000000000000000000AAAA000000000000000000000000000000000000000000000000000000000000FFFFFFFFFFFFFFFFF0000000FFFFFFFF00000000000000000000000000000000017261010000000005000000000000000148484848484848
    DynamicInfo    REG_BINARY    03000000A0506F4E1B2DCB0100000000000000000000000000000000
    Hash    REG_BINARY    6576A98588179A08B31C3D3999726FCF3761698BAAA53EC77A03A35E4108207A

HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Schedule\Taskcache\Tasks\{AF0E8862-B404-45B1-990F-A877CA74DB66}
    Path    REG_SZ    \Microsoft\Windows\Defrag\ScheduledDefrag
    Triggers    REG_BINARY    15000000000000000155E30100000000002872589541CB010055E30100000000FFFFFFFFFFFFFFFF7E214203484848481D68D4C0484848480048484848484848004848484848484805000000484848480C000000484848480101000000000005120000004848484800000000484848483800000048484848B4000000803A090080F40300FFFFFFFF07000000000000000000000000000000000000000000000000000000000000000000000000000000DDDD0000000000000155E30100000000002872589541CB0100000000000000000000000000000000000000000000000000000000000000000000000000000000FFFFFFFF02000000010008000000000000000000010000000000000000000000
    DynamicInfo    REG_BINARY    03000000E01293C53142CB0100000000000000000000000000000000
    Hash    REG_BINARY    FFF8896FE7EB448041E250147044839512AA48E312487CA47813AC6A94C4314C

HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Schedule\Taskcache\Tasks\{B0CBAB43-44FC-469B-A4CE-87426761FDCE}
    Path    REG_SZ    \Microsoft\Windows\PerfTrack\BackgroundConfigSurveyor
    Triggers    REG_BINARY    1500000000000000001C24FBFE0700000000000000000000001C24FBFE070000FFFFFFFFFFFFFFFF102182024848484803D61589484848480048484848484848004848484848484805000000484848480C000000484848480101000000000005130000004848484800000000484848480000000048484848EEEE000000000000001C24FBFE0700000000000000000000001C24FBFE070000FFFFFFFFFFFFFFFF00000000FFFFFFFF0000000000000000000000000000000001000000000000000000000003000000DDDD000000000000011272FBFE0700000078BA3F01C2C80100000000000000000000000000000000000000000000000000000000000000000000000000000000FFFFFFFF01000000010000000000000000010000010000000000000000000000
    DynamicInfo    REG_BINARY    03000000F930952F4104CA0100000000000000000000000000000000
    Hash    REG_BINARY    8A4BC3FB22E943EDE5A98456CCAF3453D4DDD613D1A3265017967ABC8C779E7D

HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Schedule\Taskcache\Tasks\{B5300C80-1852-4740-8577-DAD20107477F}
    Path    REG_SZ    \Microsoft\Windows\Media Center\PBDADiscoveryW1
    Triggers    REG_BINARY    150000000000000000FFFFFFFFFFFFFFFFFFFFFFFFFFFFFF00FFFFFFFFFFFFFF0000000000000000400542024848484820231FCE484848480048484848484848004848484848484805000000484848480C00000048484848010100000000000512000000484848480000000048484848380000004848484800000000FFFFFFFF100E0000FFFFFFFF07000000000000000000000000000000000000000000000000000000000000000000000000000000
    DynamicInfo    REG_BINARY    03000000009C194B01DCCA0100000000000000000000000000000000
    Hash    REG_BINARY    ED6C3AF77BC32514D0E4A46115FB377242E60FDE46F8FF3785AF624B20462691

HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Schedule\Taskcache\Tasks\{B96F52BC-A937-4670-8F16-886CE14EAD84}
    Path    REG_SZ    \Norton Internet Security\Norton Error Processor
    Hash    REG_BINARY    015A2CB8F9F9008E67D4301DE8CD262D2845B1DB5F70052D64F1E6806900117E
    Triggers    REG_BINARY    150000000000000000D799010000000000406D25EB53BF0100D79901000000000000647763712F0212214201484848481B1BCC84484848480048484848484848004848484848484805000000484848480C0000004848484801010000000000051200000048484848000000004848484838000000484848482C0100008033E10180F40300FFFFFFFF07000000000000000000000000000000000000000000000000000000000000000000000000000000DDDD00000000000000D799010000000000406D25EB53BF0100D79901000000000000647763712F02000000000000000000000000000000000000000000000000FFFFFFFF01000000010000000000000000010000010000008070000000000000
    DynamicInfo    REG_BINARY    03000000000B2B393462D001B0AC80950C4DD2012513040000000000

HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Schedule\Taskcache\Tasks\{BE669C13-8165-4536-96D0-6D6C39292AAE}
    Path    REG_SZ    \Microsoft\Windows\Diagnosis\Scheduled
    Triggers    REG_BINARY    1500000000000000011272FBFE0700000068B69402D0C301001272FBFE070000FFFFFFFFFFFFFFFF7289C00348484848AB8C36E4484848480048484848484848004848484848484805000000484848480C000000484848480101000000000005040000004848484800000000484848483800000048484848580200008070000080F40300FFFFFFFF07000000000000000000000000000000000000000000000000000000000000000000000000000000DDDD000000000000011272FBFE0700000068B69402D0C30100000000000000000000000000000000000000000000000000000000000000000000000000000000FFFFFFFF02000000010001000000000000010000010000000000000000000000
    DynamicInfo    REG_BINARY    03000000419ADC2F4104CA0100000000000000000000000000000000
    Hash    REG_BINARY    82EBD60108500FCD357BF28CCE5952EFB6FF943B38E8250A3AF34507C6162FAE

HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Schedule\Taskcache\Tasks\{C016366B-7126-46CA-B36B-592A3D95A60B}
    Path    REG_SZ    \Microsoft\Windows\Customer Experience Improvement Program\Consolidator
    Triggers    REG_BINARY    1500000000000000011272FBFE07000000C05B5DC3D0C301001272FBFE070000FFFFFFFFFFFFFFFF4021420248484848F3FE730B484848480048484848484848004848484848484805000000484848480C000000484848480101000000000005120000004848484800000000484848480000000048484848DDDD000000000000011272FBFE07000000C05B5DC3D0C3010000000000000000000000000000000000000000000000000000000000000000300B010000000000FFFFFFFF00000000000000000000000000010000010000000000000000000000
    DynamicInfo    REG_BINARY    03000000025DE12F4104CA0100000000000000000000000000000000
    Hash    REG_BINARY    555CD377BA0A0532A5630EBE96AE9DB1843E642B2A15BA07C40C8B67BE00E87F

HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Schedule\Taskcache\Tasks\{C27A0E7B-742B-4454-804E-44F3C2A92FCF}
    Path    REG_SZ    \Microsoft\Windows\Media Center\MediaCenterRecoveryTask
    Triggers    REG_BINARY    150000000000000000FFFFFFFFFFFFFFFFFFFFFFFFFFFFFF00FFFFFFFFFFFFFF0000000000000000000542024848484868DEB374484848480048484848484848004848484848484805000000484848480C000000484848480101000000000005120000004848484800000000484848480000000048484848
    DynamicInfo    REG_BINARY    030000004065C24D01DCCA0100000000000000000000000000000000
    Hash    REG_BINARY    EB514214B7FD8BCDF44B13E01117537348E099E5CC33A15A470C6C60FE50467D

HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Schedule\Taskcache\Tasks\{CA1C7F50-8959-4447-8A43-9AC256B76669}
    Path    REG_SZ    \Adobe Acrobat Update Task
    Hash    REG_BINARY    AB50DD7D6186360935326C8FC6DB5BAE6FA03211F389064705FB9A95F8CF6D17
    Triggers    REG_BINARY    150000000000000001D4B101000000000070C63BE5E7CD0101D4B1010000000000BE485FFDF8DD0178A1400048484848F1A2BF41484848480048484848484848004848484848484805000000484848480C00000048484848010100000000000504000000484848480000000048484848380000004848484858020000100E000080F40300FFFFFFFF07000000000000000000000000000000000000000000000000000000000000000000000000000000AAAA00000000000001D4B10100000000003EC458AF8ECE0101D4B1010000000000C06625DBF8DD01D0020000FFFFFFFF3831000000000000000000000000000001006900630065003A000000000000000148484848484848DDDD00000000000001D4B101000000000070C63BE5E7CD0101D4B1010000000000BE485FFDF8DD01000000000000000000000000000000000000000000000000FFFFFFFF01000000010000000000000000010000010000000000000000000000
    DynamicInfo    REG_BINARY    0300000010EBEFD8FB10D30100BB3A177A21D3010000000000000000

HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Schedule\Taskcache\Tasks\{CA4B8FF2-A4D2-4D88-A52E-3A5BDAF7F56E}
    Path    REG_SZ    \Microsoft\Windows\Registry\RegIdleBackup
    Triggers    REG_BINARY    1500000000000000011272FBFE07000000C07640094CC801001272FBFE070000FFFFFFFFFFFFFFFF4E20C20248484848C7925C29484848480048484848484848004848484848484805000000484848480C000000484848480101000000000005120000004848484800000000484848483800000048484848B40000007043010000000000FFFFFFFF05000000000000000000000000000000000000000000000000000000750070000000000000000000DDDD000000000000011272FBFE07000000C07640094CC80100000000000000000000000000000000000000000000000000000000000000000000000000000000FFFFFFFF010000000A000000000000000001000001000000100E000000000000
    DynamicInfo    REG_BINARY    03000000A81C18304104CA0100000000000000000000000000000000
    Hash    REG_BINARY    AE0DB2F31A30B208E0C50EF64C29948A828612AC605CA8F6B3E42F51EA6C09E1

HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Schedule\Taskcache\Tasks\{CB3D64BF-C0C9-45FF-BFB0-FF1A8F680186}
    Path    REG_SZ    \Microsoft\Windows\RemoteAssistance\RemoteAssistanceTask
    Triggers    REG_BINARY    1500000000000000001C24FBFE0700000000000000000000001C24FBFE070000FFFFFFFFFFFFFFFF2811C2034848484866D894B3484848480048484848484848004848484848484805000000484848480C00000048484848010100000000000512000000484848480000000048484848380000004848484858020000100E000080F40300FFFFFFFF0700000000000000000000000000000000000000000000000000000022436F6C0000000000000000CCCC000000000000001C24FBFE0700000000000000000000001C24FBFE070000FFFFFFFFFFFFFFFF0F000000FFFFFFFF0000000000000000000000000000000001010000000000052000000000000000A5000000000000003C00510075006500720079004C006900730074003E003C00510075006500720079002000490064003D00220030002200200050006100740068003D002200530079007300740065006D0022003E003C00530065006C00650063007400200050006100740068003D002200530079007300740065006D0022003E002A005B00530079007300740065006D005B00500072006F00760069006400650072005B0040004E0061006D0065003D0027004D006900630072006F0073006F00660074002D00570069006E0064006F00770073002D00470072006F007500700050006F006C0069006300790027005D00200061006E00640020004500760065006E007400490044003D0031003500300032005D005D003C002F00530065006C006500630074003E003C002F00510075006500720079003E003C002F00510075006500720079004C006900730074003E000000484848480000000000000000000000000000000000000000000000008888000000000000001624FBFE0700000000000000000000001624FBFE070000FFFFFFFFFFFFFFFF00000000FFFFFFFF0000000000000000000000000000000001000000000000000000000003000000
    DynamicInfo    REG_BINARY    03000000087E1A304104CA0100000000000000000000000000000000
    Hash    REG_BINARY    40F4A1B4CBF346720B7A186AAE912FCEA1FBE0DD82F48F51FCB9AD1A76BF2525

HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Schedule\Taskcache\Tasks\{CBC80253-50BE-47AF-81EA-A8816005ABE4}
    Path    REG_SZ    \Microsoft\Windows\SideShow\GadgetManager
    Triggers    REG_BINARY    1500000000000000000000000000000000000000000000000000000000000000FFFFFFFFFFFFFFFF009140024848484863DEF7F2484848480048484848484848004848484848484804000000484848481000000048484848010200000000000520000000210200000000000048484848380000004848484800000000FFFFFFFF80F40300FFFFFFFF07000000000000000000000000000000000000000000000000000000000000000000000000000000AAAA000000000000000000000000000000000000000000000000000000000000FFFFFFFFFFFFFFFF00000000FFFFFFFF00000000000000000000000000000000000078010000000005000000000000000148484848484848
    DynamicInfo    REG_BINARY    030000006045224801DCCA0100000000000000000000000000000000
    Hash    REG_BINARY    2B16A83D35908A64E898F2743328C16CBC44DE6C67AF392D6B0F19AE00829A72

HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Schedule\Taskcache\Tasks\{CC459BF8-7D00-4831-99CC-FE735B19F74A}
    Path    REG_SZ    \Microsoft\Windows\Media Center\UpdateRecordPath
    Triggers    REG_BINARY    150000000000000000FFFFFFFFFFFFFFFFFFFFFFFFFFFFFF00FFFFFFFFFFFFFF000000000000000000214202484848482E977B9B484848480048484848484848004848484848484805000000484848480C000000484848480101000000000005120000004848484800000000484848480000000048484848
    DynamicInfo    REG_BINARY    030000006000664901DCCA0100000000000000000000000000000000
    Hash    REG_BINARY    EB28225E5ADAD1323F85643ABEC315B0F6F9F15D232F4DA9D56085F77D31388C

HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Schedule\Taskcache\Tasks\{CEE64558-E1A7-4D9D-80A7-2001912BE5B5}
    Path    REG_SZ    \Microsoft\Windows\MemoryDiagnostic\CorruptionDetector
    Triggers    REG_BINARY    1500000000000000001C24FBFE0700000000000000000000001C24FBFE070000FFFFFFFFFFFFFFFF00A0C00248484848F1D7B9294848484800484848484848480048484848484848040000004848484810000000484848480102000000000005200000002102000000000000484848480000000048484848CCCC000000000000001C24FBFE0700000000000000000000001C24FBFE070000FFFFFFFFFFFFFFFF00000000FFFFFFFF000000000000000000000000000000000101000000000005200000000000000099000000000000003C00510075006500720079004C006900730074003E003C00510075006500720079002000490064003D00220030002200200050006100740068003D002200530079007300740065006D0022003E003C00530065006C00650063007400200050006100740068003D002200530079007300740065006D0022003E002A005B00530079007300740065006D005B00500072006F00760069006400650072005B0040004E0061006D0065003D0027004100700070006C00690063006100740069006F006E00200050006F0070007500700027005D00200061006E00640020004500760065006E007400490044003D0031003800300031005D005D003C002F00530065006C006500630074003E003C002F00510075006500720079003E003C002F00510075006500720079004C006900730074003E00000048484848000000000000000000000000000000000000000000000000
    DynamicInfo    REG_BINARY    0300000068DF1C304104CA0100000000000000000000000000000000
    Hash    REG_BINARY    39D0B04F356DF6650E076076255CE26CE27591428740C759241D2B1AEE37F612

HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Schedule\Taskcache\Tasks\{D0250F3F-6480-484F-B719-42F659AC64D5}
    Path    REG_SZ    \Microsoft\Windows\Windows Error Reporting\QueueReporting
    Triggers    REG_BINARY    1500000000000000001624FBFE0700000000000000000000001624FBFE070000FFFFFFFFFFFFFFFF40854002484848488A154A60484848480048484848484848004848484848484804000000484848481000000048484848010200000000000520000000210200000000000048484848380000004848484800000000FFFFFFFF80F40300FFFFFFFF05000000000000000000000000000000000000000000000000000000750070000000000000000000AAAA000000000000001624FBFE0700000000000000000000001624FBFE070000FFFFFFFFFFFFFFFF0C030000FFFFFFFF00000000000000000000000000000000010000000000000000000000030000000148484848484848
    DynamicInfo    REG_BINARY    030000002D35042D4104CA0100000000000000000000000000000000
    Hash    REG_BINARY    6EB7D50A0F0E813EF39052146B2AB58692ED68D82E0E8E733043ECC9334D16D1

HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Schedule\Taskcache\Tasks\{D1BC44FB-2193-40BF-AA4A-2E96D31F2BCE}
    Path    REG_SZ    \Microsoft\Windows\Media Center\ReindexSearchRoot
    Triggers    REG_BINARY    150000000000000000FFFFFFFFFFFFFFFFFFFFFFFFFFFFFF00FFFFFFFFFFFFFF00000000000000000021420248484848E17CF563484848480048484848484848004848484848484805000000484848480C000000484848480101000000000005120000004848484800000000484848480000000048484848
    DynamicInfo    REG_BINARY    030000006063114A01DCCA0100000000000000000000000000000000
    Hash    REG_BINARY    59500DAC2B3DF24DD8EBD096B081796CE15A4D699DE7F05B53C249612F21A974

HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Schedule\Taskcache\Tasks\{D378D375-CAC7-474F-8B4B-82FF8391E306}
    Path    REG_SZ    \Microsoft\Windows\Offline Files\Background Synchronization
    Triggers    REG_BINARY    1500000000000000016161010000000000C07640094CC8010061610100000000FFFFFFFFFFFFFFFFC0A10002484848481DE0FDD6484848480048484848484848004848484848484805000000484848480C0000004848484801010000000000050B000000484848480000000048484848380000004848484800000000FFFFFFFF80510100FFFFFFFF07000000000000000000000000000000000000000000000000000000640054000000000000000000DDDD000000000000016161010000000000C07640094CC80100000000000000000000000000000000000000000000000000000000000000006054000000000000FFFFFFFF0000000000000000000000000001000001000000100E000000000000
    DynamicInfo    REG_BINARY    0300000060F23A4E1B2DCB0100000000000000000000000000000000
    Hash    REG_BINARY    064E0B6C6170312965A1E23D7EE00BE494DA87892966284973711A6BDB4E0676

HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Schedule\Taskcache\Tasks\{D566BF98-A96D-49E6-B8C7-DD9C73666437}
    Path    REG_SZ    \Microsoft\Windows\DiskDiagnostic\Microsoft-Windows-DiskDiagnosticResolver
    Triggers    REG_BINARY    1500000000000000000000000000000000000000000000000000000000000000FFFFFFFFFFFFFFFF00858003484848481FCACD844848484800484848484848480048484848484848040000004848484810000000484848480102000000000005200000002102000000000000484848480000000048484848AAAA000000000000000000000000000000000000000000000000000000000000FFFFFFFFFFFFFFFF00000000FFFFFFFF00000000000000000000000000000000010078010000000005000000000000000148484848484848
    DynamicInfo    REG_BINARY    030000000076614701DCCA0100000000000000000000000000000000
    Hash    REG_BINARY    AC67DF7A4B9D1C8713C2D62FD8685113FB7749DE03811F77BBC4B4B06B74C2DA

HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Schedule\Taskcache\Tasks\{D7B6E81D-3CF4-432C-84D2-24213F4316E6}
    Path    REG_SZ    \Microsoft\Windows\Autochk\Proxy
    Triggers    REG_BINARY    1500000000000000001C24FBFE0700000000000000000000001C24FBFE070000FFFFFFFFFFFFFFFF4221420248484848B1B1AB59484848480048484848484848004848484848484805000000484848480C000000484848480101000000000005130000004848484800000000484848483800000048484848580200008033E10180F40300FFFFFFFF07000000000000000000000000000000000000000000000000000000000000000000000000000000FFFF000000000000001C24FBFE0700000000000000000000001C24FBFE070000FFFFFFFFFFFFFFFF08070000FFFFFFFF0000000000000000000000000000000001000000000000000000000003000000
    DynamicInfo    REG_BINARY    030000004A43E52C4104CA0100000000000000000000000000000000
    Hash    REG_BINARY    02E603F0F0B98221F070DD81A88B3DB67CE5DA315BC568423732F9EED15F3F79

HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Schedule\Taskcache\Tasks\{DA41DE71-8431-42FB-9DB0-EB64A961DEAD}
    Path    REG_SZ    \Microsoft\Windows\Maintenance\WinSAT
    Triggers    REG_BINARY    15000000000000000155B7010000000000283BA2114CC8010055B70100000000FFFFFFFFFFFFFFFF3AA1400348484848FD6ADDD0484848480048484848484848004848484848484804000000484848481000000048484848010200000000000520000000200200000000000048484848380000004848484800000000FFFFFFFF00000000FFFFFFFF07000000000000000000000000000000000000000000000000000000000000000000000000000000DDDD0000000000000155B7010000000000283BA2114CC80100000000000000000000000000000000000000000000000000000000000000000000000000000000FFFFFFFF02000000010001000000000000010000010000000000000000000000
    DynamicInfo    REG_BINARY    03000000C9401F304104CA0100000000000000000000000000000000
    Hash    REG_BINARY    66794E5D90FD8C6C013FA7BD65E976C09D408DBAC86B91069E6956EDBE709681

HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Schedule\Taskcache\Tasks\{DBABD243-12BD-48BF-AB79-4661514DB486}
    Path    REG_SZ    \Microsoft\Windows\Media Center\PBDADiscoveryW2
    Triggers    REG_BINARY    150000000000000000FFFFFFFFFFFFFFFFFFFFFFFFFFFFFF00FFFFFFFFFFFFFF00000000000000004005420248484848215727BB484848480048484848484848004848484848484805000000484848480C00000048484848010100000000000512000000484848480000000048484848380000004848484800000000FFFFFFFF100E0000FFFFFFFF07000000000000000000000000000000000000000000000000000000000000000000000000000000
    DynamicInfo    REG_BINARY    030000006013424B01DCCA0100000000000000000000000000000000
    Hash    REG_BINARY    D2B529269E9CD0C8E777506B13CBC3B9EC133ADCFA2160D03B795663C6D14D51

HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Schedule\Taskcache\Tasks\{DD9F510C-95F4-499A-90C8-BAC5BC372FF4}
    Path    REG_SZ    \Microsoft\Windows\SoftwareProtectionPlatform\SvcRestartTask
    Triggers    REG_BINARY    1500000000000000011272FBFE0700000000F232FACFC301001272FBFE070000FFFFFFFFFFFFFFFF4021820248484848217B8E98484848480048484848484848004848484848484805000000484848480C00000048484848010100000000000514000000484848480000000048484848380000004848484800000000FFFFFFFF00000000FFFFFFFF070000003C0000000300000000000000000000000000000000000000000000000000000000000000DDDD000000000000011272FBFE0700000000F232FACFC30100000000000000000000000000000000000000000000000000000000000000000000000000000000FFFFFFFF01000000010000000000000000010000010000000000000000000000
    DynamicInfo    REG_BINARY    0300000029A221304104CA0100000000000000000000000000000000
    Hash    REG_BINARY    FD59AA8FA7E6D6C681945135C99BCEAC82F3DB23B037253C8DAD1617F5C5E425

HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Schedule\Taskcache\Tasks\{E22A8667-F75B-4BA9-BA46-067ED4429DE8}
    Path    REG_SZ    \Microsoft\Windows\Windows Filtering Platform\BfeOnServiceStartTypeChange
    Triggers    REG_BINARY    1500000000000000001C24FBFE0700000000000000000000001C24FBFE070000FFFFFFFFFFFFFFFF0010C20248484848170F4F6E484848480048484848484848004848484848484805000000484848480C00000048484848010100000000000512000000484848480000000048484848380000004848484800000000FFFFFFFF80F40300FFFFFFFF07000000000000000000000000000000000000000000000000000000000000000000000000000000CCCC000000000000001C24FBFE0700000000000000000000001C24FBFE070000FFFFFFFFFFFFFFFF00000000FFFFFFFF0000000000000000000000000000000001010000000000052000000000000000D3000000000000003C00510075006500720079004C006900730074003E003C00510075006500720079002000490064003D00220030002200200050006100740068003D002200530079007300740065006D0022003E003C00530065006C00650063007400200050006100740068003D002200530079007300740065006D0022003E002A002F00530079007300740065006D002F00500072006F00760069006400650072005B0040004E0061006D0065003D0027005300650072007600690063006500200043006F006E00740072006F006C0020004D0061006E00610067006500720027005D00200061006E00640020002A002F00530079007300740065006D002F004500760065006E007400490044003D00270037003000340030002700200061006E00640020002A002F004500760065006E00740044006100740061002F0044006100740061005B0040004E0061006D0065003D00270070006100720061006D00340027005D003D00270042004600450027003C002F00530065006C006500630074003E003C002F00510075006500720079003E003C002F00510075006500720079004C006900730074003E000000000000000000000000000000000000000000000000000000
    DynamicInfo    REG_BINARY    0300000029A221304104CA0100000000000000000000000000000000
    Hash    REG_BINARY    CD3589987E9B5E1E6B4EEC849A5ADBBEECEA05CB35BB86B07AC66C4029EB0D6D

HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Schedule\Taskcache\Tasks\{E3163C33-301D-4730-A266-5518C5ED3967}
    Path    REG_SZ    \Microsoft\Windows\Bluetooth\UninstallDeviceTask
    Triggers    REG_BINARY    150000000000000000FFFFFFFFFFFFFFFFFFFFFFFFFFFFFF00FFFFFFFFFFFFFF000000000000000010054202484848480D99DFD7484848480048484848484848004848484848484805000000484848480C000000484848480101000000000005120000004848484800000000484848480000000048484848
    DynamicInfo    REG_BINARY    03000000890324304104CA0100000000000000000000000000000000
    Hash    REG_BINARY    90A6903C079DE796E0B72C7C3B740EA1AD655883DF0AC5468E3EB70311B7E7F7

HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Schedule\Taskcache\Tasks\{E711EFE2-5CFB-44B5-8A15-512E8C29E0A4}
    Path    REG_SZ    \Microsoft\Windows\DiskDiagnostic\Microsoft-Windows-DiskDiagnosticDataCollector
    Triggers    REG_BINARY    15000000000000000156ED01000000000068B69402D0C3010056ED0100000000FFFFFFFFFFFFFFFF52218202484848488ACEFD74484848480048484848484848004848484848484805000000484848480C000000484848480101000000000005120000004848484800000000484848480000000048484848DDDD0000000000000156ED01000000000068B69402D0C30100000000000000000000000000000000000000000000000000000000000000000000000000000000FFFFFFFF02000000020001000000000000010000010000000000000000000000
    DynamicInfo    REG_BINARY    03000000A0FE384701DCCA0100000000000000000000000000000000
    Hash    REG_BINARY    9615D02C18C2E20A2C5D63731D4143F49CD173A5C6E09584EA1A72DC9A6CFF48

HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Schedule\Taskcache\Tasks\{EACA24FF-236C-401D-A1E7-B3D5267B8A50}
    Path    REG_SZ    \Microsoft\Windows\RAC\RacTask
    Triggers    REG_BINARY    1500000000000000001C24FBFE0700000000000000000000001C24FBFE070000FFFFFFFFFFFFFFFF4021C20248484848E9C5E87D484848480048484848484848004848484848484805000000484848480C00000048484848010100000000000513000000484848480000000048484848380000004848484800000000FFFFFFFF00000000FFFFFFFF07000000000000000000000000000000000000000000000000000000000000000000000000000000CCCC000000000000001C24FBFE0700000000000000000000001C24FBFE070000FFFFFFFFFFFFFFFF00000000FFFFFFFF0000000000000000000000000000000001010000000000052000000000000000A8000000000000003C00510075006500720079004C006900730074003E003C00510075006500720079002000490064003D00220030002200200050006100740068003D0022004100700070006C00690063006100740069006F006E0022003E003C00530065006C00650063007400200050006100740068003D0022004100700070006C00690063006100740069006F006E0022003E002A005B00530079007300740065006D005B00500072006F00760069006400650072005B0040004E0061006D0065003D0027004D006900630072006F0073006F00660074002D00570069006E0064006F00770073002D00430045004900500027005D00200061006E00640020004500760065006E007400490044003D0031003000300037005D005D003C002F00530065006C006500630074003E003C002F00510075006500720079003E003C002F00510075006500720079004C006900730074003E000000484848484848000000000000000000000000000000000000000000000000DDDD000000000000001272FBFE0700000040A429C292C8010000000000000000000000000000000000000000000000000000000000000000100E000000000000FFFFFFFF00000000000000000000000000010000010000008403000000000000
    DynamicInfo    REG_BINARY    03000000890324304104CA0100000000000000000000000000000000
    Hash    REG_BINARY    E59879E1FF87CB7D11142664C919E0ADF61F5A9687D697C3F1C204FA4C56E303

HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Schedule\Taskcache\Tasks\{EB02381F-D652-4B1C-894A-712498C62C51}
    Path    REG_SZ    \Microsoft\Windows\MUI\LPRemove
    Triggers    REG_BINARY    1500000000000000001C24FBFE0700000000000000000000001C24FBFE070000FFFFFFFFFFFFFFFF12214203484848489B41D2D8484848480048484848484848004848484848484805000000484848480C00000048484848010100000000000512000000484848480000000048484848380000004848484858020000FFFFFFFF907E0000FFFFFFFF07000000000000000000000000000000000000000000000000000000000000000000000000000000FFFF000000000000001C24FBFE0700000000000000000000001C24FBFE070000FFFFFFFFFFFFFFFFDC050000FFFFFFFF0000000000000000000000000000000001000000000000000000000003000000
    DynamicInfo    REG_BINARY    030000004A43E52C4104CA0100000000000000000000000000000000
    Hash    REG_BINARY    47D45B031C1994B39C49EF36D6FE80FBEC111F7D6EF3E282476EF5D77E097DAB

HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Schedule\Taskcache\Tasks\{EC8DF7E1-FE52-4B24-9600-C98297AE2238}
    Path    REG_SZ    \Microsoft\Windows\Media Center\OCURActivate
    Triggers    REG_BINARY    150000000000000000FFFFFFFFFFFFFFFFFFFFFFFFFFFFFF00FFFFFFFFFFFFFF00000000000000000021420248484848C7422EAF484848480048484848484848004848484848484805000000484848480C000000484848480101000000000005120000004848484800000000484848480000000048484848
    DynamicInfo    REG_BINARY    03000000E04E104901DCCA0100000000000000000000000000000000
    Hash    REG_BINARY    21F0C71001FDAD4060D134F2914F036D1DAA814D9CF6206B8BBEA1D09AC5125B

HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Schedule\Taskcache\Tasks\{FA2BC0A6-8D4B-458A-85C8-2B8C72487513}
    Path    REG_SZ    \Microsoft\Windows\MemoryDiagnostic\DecompressionFailureDetector
    Triggers    REG_BINARY    1500000000000000001C24FBFE0700000000000000000000001C24FBFE070000FFFFFFFFFFFFFFFF00A0C00248484848AA4E8B9D4848484800484848484848480048484848484848040000004848484810000000484848480102000000000005200000002102000000000000484848480000000048484848CCCC000000000000001C24FBFE0700000000000000000000001C24FBFE070000FFFFFFFFFFFFFFFF00000000FFFFFFFF0000000000000000000000000000000001010000000000052000000000000000F4000000000000003C00510075006500720079004C006900730074003E003C00510075006500720079002000490064003D00220030002200200050006100740068003D0022004D006900630072006F0073006F00660074002D00570069006E0064006F00770073002D004B00650072006E0065006C002D00530074006F00720065004D00670072002F004F007000650072006100740069006F006E0061006C0022003E003C00530065006C00650063007400200050006100740068003D0022004D006900630072006F0073006F00660074002D00570069006E0064006F00770073002D004B00650072006E0065006C002D00530074006F00720065004D00670072002F004F007000650072006100740069006F006E0061006C0022003E002A005B00530079007300740065006D005B00500072006F00760069006400650072005B0040004E0061006D0065003D0027004D006900630072006F0073006F00660074002D00570069006E0064006F00770073002D004B00650072006E0065006C002D00530074006F00720065004D006700720027005D00200061006E00640020004500760065006E007400490044003D0036005D005D003C002F00530065006C006500630074003E003C002F00510075006500720079003E003C002F00510075006500720079004C006900730074003E000000484848484848000000000000000000000000000000000000000000000000
    DynamicInfo    REG_BINARY    03000000E96426304104CA0100000000000000000000000000000000
    Hash    REG_BINARY    CBB12F1ED12986181801A365A6F75001D31D2BB3CF7441BA8541894267D4CC42

HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Schedule\Taskcache\Tasks\{FB3C354D-297A-4EB2-9B58-090F6361906B}
    Path    REG_SZ    \Microsoft\Windows\Power Efficiency Diagnostics\AnalyzeSystem
    Triggers    REG_BINARY    1500000000000000011272FBFE0700000030118B3B4CC801001272FBFE070000FFFFFFFFFFFFFFFF4221420248484848D8D9932B484848480048484848484848004848484848484805000000484848480C0000004848484801010000000000051200000048484848000000004848484838000000484848482C010000201C00002C010000FFFFFFFF07000000000000000000000000000000000000000000000000000000750070000000000000000000DDDD000000000000011272FBFE0700000030118B3B4CC80100000000000000000000000000000000000000000000000000000000000000000000000000000000FFFFFFFF010000000E0000000000000000010000010000008070000000000000
    DynamicInfo    REG_BINARY    03000000AA272B304104CA0100000000000000000000000000000000
    Hash    REG_BINARY    9423B265CBAB426F81672F084E7D9866F685D983B62224712FF0DBC4FFEFE374

HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Schedule\Taskcache\Tasks\{FC4403AB-CB2F-42A2-9F65-6CA817FDFEC4}
    Path    REG_SZ    \Microsoft\Windows\Setup\gwx\refreshgwxconfigandcontent
    Hash    REG_BINARY    6DAEBDC0BC37F80D4A7BEB384C9CA705A0ADE59FE424F5B84CF10A66646DBEBF
    Triggers    REG_BINARY    15000000000000000000000000000000000000000000000000A2F50100000000FFFFFFFFFFFFFFFFC02142034848484870625DAF484848480048484848484848004848484848484805000000484848480C00000048484848010100000000000512000000484848480000000048484848380000004848484800000000FFFFFFFF00000000FFFFFFFF07000000000000000000000000000000000000000000000000000000000000000000000000000000DDDD00000000000001A2F5010000000000201676A646CE0100000000000000000000000000000000000000000000000000000000000000000000000000000000FFFFFFFF010000000100000000000000000100000100000080510100000000008888000000000000000000000000000000000000000000000000000000000000FFFFFFFFFFFFFFFF00000000FFFFFFFF00000000000000000000000000070000010064006C006C002C002D0035003000
    DynamicInfo    REG_BINARY    0300000000BF97763B1AD10100000000000000000000000000000000

HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Schedule\Taskcache\Tasks\{FDD56C73-F0D5-41B6-B767-6EFFD7966428}
    Path    REG_SZ    \Microsoft\Windows\Customer Experience Improvement Program\KernelCeipTask
    Triggers    REG_BINARY    1500000000000000011272FBFE070000002C7103E30BC901001272FBFE070000FFFFFFFFFFFFFFFF5221C20248484848D3FA1AB0484848480048484848484848004848484848484805000000484848480C000000484848480101000000000005130000004848484800000000484848483800000048484848B400000010EF000080F40300FFFFFFFF070000008C0A00000100000000000000000000000000000000000000000000000000800000000000DDDD000000000000011272FBFE070000002C7103E30BC90100000000000000000000000000000000000000000000000000000000000000000000000000000000FFFFFFFF02000000010010000000000000010000010000000000000000000000
    DynamicInfo    REG_BINARY    03000000AA272B304104CA0100000000000000000000000000000000
    Hash    REG_BINARY    AEB03F1BC169236F2C3BF019F9D9ED3C213D1E4A568F8C67F1FC3F2EC08649A6

 

========= End of Reg: =========


========= REG QUERY "HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\Taskcache\Tree" /s =========


HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Schedule\Taskcache\Tree\Adobe Acrobat Update Task
    Id    REG_SZ    {CA1C7F50-8959-4447-8A43-9AC256B76669}
    Index    REG_DWORD    0x2

HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Schedule\Taskcache\Tree\CCleanerSkipUAC
    Id    REG_SZ    {92771DAF-0E34-4CC5-9653-7A6E793544E5}
    Index    REG_DWORD    0x3

HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Schedule\Taskcache\Tree\Microsoft

HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Schedule\Taskcache\Tree\Microsoft\Windows

HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Schedule\Taskcache\Tree\Microsoft\Windows\Active Directory Rights Management Services Client

HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Schedule\Taskcache\Tree\Microsoft\Windows\Active Directory Rights Management Services Client\AD RMS Rights Policy Template Management (Automated)
    Id    REG_SZ    {613612BA-897D-44CE-8DC1-8FC283F9FD51}
    Index    REG_DWORD    0x2

HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Schedule\Taskcache\Tree\Microsoft\Windows\Active Directory Rights Management Services Client\AD RMS Rights Policy Template Management (Manual)
    Id    REG_SZ    {28011108-68DF-4C73-B91B-57427D501BBA}
    Index    REG_DWORD    0x2

HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Schedule\Taskcache\Tree\Microsoft\Windows\AppID

HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Schedule\Taskcache\Tree\Microsoft\Windows\AppID\PolicyConverter
    Id    REG_SZ    {A48CABBF-24C8-4B87-B00F-9261807C3B43}
    Index    REG_DWORD    0x3

HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Schedule\Taskcache\Tree\Microsoft\Windows\AppID\VerifiedPublisherCertStoreCheck
    Id    REG_SZ    {72DB7465-BC54-491B-A92A-4637A28C9BBF}
    Index    REG_DWORD    0x1

HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Schedule\Taskcache\Tree\Microsoft\Windows\Application Experience

HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Schedule\Taskcache\Tree\Microsoft\Windows\Application Experience\AitAgent
    Id    REG_SZ    {AC4E5ACF-89F7-4220-BA21-81EE183975E2}
    Index    REG_DWORD    0x3

HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Schedule\Taskcache\Tree\Microsoft\Windows\Application Experience\Microsoft Compatibility Appraiser
    Id    REG_SZ    {25D544CB-69FF-4F6D-B01B-63541C25C654}
    Index    REG_DWORD    0x3

HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Schedule\Taskcache\Tree\Microsoft\Windows\Application Experience\ProgramDataUpdater
    Id    REG_SZ    {034DF26D-DA1B-4161-9AE1-330409B21EE7}
    Index    REG_DWORD    0x3

HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Schedule\Taskcache\Tree\Microsoft\Windows\Autochk

HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Schedule\Taskcache\Tree\Microsoft\Windows\Autochk\Proxy
    Id    REG_SZ    {D7B6E81D-3CF4-432C-84D2-24213F4316E6}
    Index    REG_DWORD    0x1

HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Schedule\Taskcache\Tree\Microsoft\Windows\Bluetooth

HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Schedule\Taskcache\Tree\Microsoft\Windows\Bluetooth\UninstallDeviceTask
    Id    REG_SZ    {E3163C33-301D-4730-A266-5518C5ED3967}
    Index    REG_DWORD    0x3

HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Schedule\Taskcache\Tree\Microsoft\Windows\CertificateServicesClient

HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Schedule\Taskcache\Tree\Microsoft\Windows\CertificateServicesClient\SystemTask
    Id    REG_SZ    {5F5A18EB-DC73-4E45-A11C-B59043598412}
    Index    REG_DWORD    0x1

HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Schedule\Taskcache\Tree\Microsoft\Windows\CertificateServicesClient\UserTask
    Id    REG_SZ    {7AFCC0CA-7121-422A-AB45-B0E8D599FF08}
    Index    REG_DWORD    0x2

HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Schedule\Taskcache\Tree\Microsoft\Windows\CertificateServicesClient\UserTask-Roam
    Id    REG_SZ    {9979CB83-103A-4105-9E5D-C74B0AF6D198}
    Index    REG_DWORD    0x3

HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Schedule\Taskcache\Tree\Microsoft\Windows\Customer Experience Improvement Program

HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Schedule\Taskcache\Tree\Microsoft\Windows\Customer Experience Improvement Program\Consolidator
    Id    REG_SZ    {C016366B-7126-46CA-B36B-592A3D95A60B}
    Index    REG_DWORD    0x3

HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Schedule\Taskcache\Tree\Microsoft\Windows\Customer Experience Improvement Program\KernelCeipTask
    Id    REG_SZ    {FDD56C73-F0D5-41B6-B767-6EFFD7966428}
    Index    REG_DWORD    0x3

HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Schedule\Taskcache\Tree\Microsoft\Windows\Customer Experience Improvement Program\OptinNotification
    Id    REG_SZ    {A132EB1D-A1EA-48EF-8B69-9358EADF5BD3}
    Index    REG_DWORD    0x0

HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Schedule\Taskcache\Tree\Microsoft\Windows\Customer Experience Improvement Program\UsbCeip
    Id    REG_SZ    {47536D45-EEEC-4BDC-8183-A4DC1F8DA9E4}
    Index    REG_DWORD    0x3

HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Schedule\Taskcache\Tree\Microsoft\Windows\Defrag

HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Schedule\Taskcache\Tree\Microsoft\Windows\Defrag\ScheduledDefrag
    Id    REG_SZ    {AF0E8862-B404-45B1-990F-A877CA74DB66}
    Index    REG_DWORD    0x3

HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Schedule\Taskcache\Tree\Microsoft\Windows\Diagnosis

HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Schedule\Taskcache\Tree\Microsoft\Windows\Diagnosis\Scheduled
    Id    REG_SZ    {BE669C13-8165-4536-96D0-6D6C39292AAE}
    Index    REG_DWORD    0x3

HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Schedule\Taskcache\Tree\Microsoft\Windows\DiskDiagnostic

HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Schedule\Taskcache\Tree\Microsoft\Windows\DiskDiagnostic\Microsoft-Windows-DiskDiagnosticDataCollector
    Id    REG_SZ    {E711EFE2-5CFB-44B5-8A15-512E8C29E0A4}
    Index    REG_DWORD    0x3

HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Schedule\Taskcache\Tree\Microsoft\Windows\DiskDiagnostic\Microsoft-Windows-DiskDiagnosticResolver
    Id    REG_SZ    {D566BF98-A96D-49E6-B8C7-DD9C73666437}
    Index    REG_DWORD    0x2

HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Schedule\Taskcache\Tree\Microsoft\Windows\Location

HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Schedule\Taskcache\Tree\Microsoft\Windows\Location\Notifications
    Id    REG_SZ    {A6AF9377-77CE-47AB-AD7D-EC32CAD0C82D}
    Index    REG_DWORD    0x3

HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Schedule\Taskcache\Tree\Microsoft\Windows\Maintenance

HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Schedule\Taskcache\Tree\Microsoft\Windows\Maintenance\WinSAT
    Id    REG_SZ    {DA41DE71-8431-42FB-9DB0-EB64A961DEAD}
    Index    REG_DWORD    0x3

HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Schedule\Taskcache\Tree\Microsoft\Windows\Media Center

HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Schedule\Taskcache\Tree\Microsoft\Windows\Media Center\ActivateWindowsSearch
    Id    REG_SZ    {59FCD788-0753-4F0B-A5CB-D300883F1B39}
    Index    REG_DWORD    0x3

HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Schedule\Taskcache\Tree\Microsoft\Windows\Media Center\ConfigureInternetTimeService
    Id    REG_SZ    {586D03C8-7997-4FDC-8F49-2F396233504A}
    Index    REG_DWORD    0x3

HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Schedule\Taskcache\Tree\Microsoft\Windows\Media Center\DispatchRecoveryTasks
    Id    REG_SZ    {8A9251B2-FAB7-49A1-BA84-9F104776E7A7}
    Index    REG_DWORD    0x3

HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Schedule\Taskcache\Tree\Microsoft\Windows\Media Center\ehDRMInit
    Id    REG_SZ    {003DBEB6-92B4-41BC-A8DE-E766A3FB3C65}
    Index    REG_DWORD    0x3

HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Schedule\Taskcache\Tree\Microsoft\Windows\Media Center\InstallPlayReady
    Id    REG_SZ    {65D42D99-7EA2-4D6A-AB62-B6EAB8D72F33}
    Index    REG_DWORD    0x3

HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Schedule\Taskcache\Tree\Microsoft\Windows\Media Center\mcupdate
    Id    REG_SZ    {7D8D2001-718E-43EA-A986-73BDD46C6B6A}
    Index    REG_DWORD    0x3

HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Schedule\Taskcache\Tree\Microsoft\Windows\Media Center\MediaCenterRecoveryTask
    Id    REG_SZ    {C27A0E7B-742B-4454-804E-44F3C2A92FCF}
    Index    REG_DWORD    0x3

HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Schedule\Taskcache\Tree\Microsoft\Windows\Media Center\ObjectStoreRecoveryTask
    Id    REG_SZ    {4B4C6847-EB01-4D6B-858A-41F8352F8BC9}
    Index    REG_DWORD    0x3

HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Schedule\Taskcache\Tree\Microsoft\Windows\Media Center\OCURActivate
    Id    REG_SZ    {EC8DF7E1-FE52-4B24-9600-C98297AE2238}
    Index    REG_DWORD    0x3

HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Schedule\Taskcache\Tree\Microsoft\Windows\Media Center\OCURDiscovery
    Id    REG_SZ    {7D97DDB4-6C77-450C-BA4E-FB3ED96AA490}
    Index    REG_DWORD    0x3

HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Schedule\Taskcache\Tree\Microsoft\Windows\Media Center\PBDADiscovery
    Id    REG_SZ    {2FEF85B2-6B9E-476C-A637-B03479D6C607}
    Index    REG_DWORD    0x3

HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Schedule\Taskcache\Tree\Microsoft\Windows\Media Center\PBDADiscoveryW1
    Id    REG_SZ    {B5300C80-1852-4740-8577-DAD20107477F}
    Index    REG_DWORD    0x3

HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Schedule\Taskcache\Tree\Microsoft\Windows\Media Center\PBDADiscoveryW2
    Id    REG_SZ    {DBABD243-12BD-48BF-AB79-4661514DB486}
    Index    REG_DWORD    0x3

HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Schedule\Taskcache\Tree\Microsoft\Windows\Media Center\PeriodicScanRetry
    Id    REG_SZ    {19DADAD5-F9EC-4AEF-946C-C0A576840830}
    Index    REG_DWORD    0x3

HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Schedule\Taskcache\Tree\Microsoft\Windows\Media Center\PvrRecoveryTask
    Id    REG_SZ    {51A295A6-300F-46E4-B98A-DF89A97815D3}
    Index    REG_DWORD    0x3

HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Schedule\Taskcache\Tree\Microsoft\Windows\Media Center\PvrScheduleTask
    Id    REG_SZ    {7E5A4FEF-DD93-45B9-A363-8A68B88823C2}
    Index    REG_DWORD    0x3

HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Schedule\Taskcache\Tree\Microsoft\Windows\Media Center\RecordingRestart
    Id    REG_SZ    {53BB7902-6E80-4F0D-B21C-501FE9C0E32E}
    Index    REG_DWORD    0x1

HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Schedule\Taskcache\Tree\Microsoft\Windows\Media Center\RegisterSearch
    Id    REG_SZ    {059C454D-C82D-4FBA-ACA0-E0D20F84D4CD}
    Index    REG_DWORD    0x3

HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Schedule\Taskcache\Tree\Microsoft\Windows\Media Center\ReindexSearchRoot
    Id    REG_SZ    {D1BC44FB-2193-40BF-AA4A-2E96D31F2BCE}
    Index    REG_DWORD    0x3

HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Schedule\Taskcache\Tree\Microsoft\Windows\Media Center\SqlLiteRecoveryTask
    Id    REG_SZ    {3AF48B03-9CD2-4EDC-9FB4-A5EC0C31A32C}
    Index    REG_DWORD    0x3

HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Schedule\Taskcache\Tree\Microsoft\Windows\Media Center\StartRecording
    Id    REG_SZ    {1134D20D-324D-4391-86F5-75AFCFC9779A}
    Index    REG_DWORD    0x3

HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Schedule\Taskcache\Tree\Microsoft\Windows\Media Center\UpdateRecordPath
    Id    REG_SZ    {CC459BF8-7D00-4831-99CC-FE735B19F74A}
    Index    REG_DWORD    0x3

HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Schedule\Taskcache\Tree\Microsoft\Windows\MemoryDiagnostic

HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Schedule\Taskcache\Tree\Microsoft\Windows\MemoryDiagnostic\CorruptionDetector
    Id    REG_SZ    {CEE64558-E1A7-4D9D-80A7-2001912BE5B5}
    Index    REG_DWORD    0x3

HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Schedule\Taskcache\Tree\Microsoft\Windows\MemoryDiagnostic\DecompressionFailureDetector
    Id    REG_SZ    {FA2BC0A6-8D4B-458A-85C8-2B8C72487513}
    Index    REG_DWORD    0x3

HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Schedule\Taskcache\Tree\Microsoft\Windows\MemoryDiagnostic\MemUsageTask
    Id    REG_SZ    {C4375D81-FA72-45AC-85F2-3B86A11CCC7D}
    Index    REG_DWORD    0x0

HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Schedule\Taskcache\Tree\Microsoft\Windows\MobilePC

HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Schedule\Taskcache\Tree\Microsoft\Windows\MobilePC\HotStart
    Id    REG_SZ    {1BA0AE97-C21E-48BB-9FF0-70BC9F299377}
    Index    REG_DWORD    0x2

HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Schedule\Taskcache\Tree\Microsoft\Windows\MUI

HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Schedule\Taskcache\Tree\Microsoft\Windows\MUI\LPRemove
    Id    REG_SZ    {EB02381F-D652-4B1C-894A-712498C62C51}
    Index    REG_DWORD    0x1

HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Schedule\Taskcache\Tree\Microsoft\Windows\Multimedia

HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Schedule\Taskcache\Tree\Microsoft\Windows\Multimedia\SystemSoundsService
    Id    REG_SZ    {2470470F-2634-478E-B181-571E98A789BB}
    Index    REG_DWORD    0x2

HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Schedule\Taskcache\Tree\Microsoft\Windows\NetTrace

HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Schedule\Taskcache\Tree\Microsoft\Windows\NetTrace\GatherNetworkInfo
    Id    REG_SZ    {81540B9F-B5BF-47EB-9C95-BE195BF2C664}
    Index    REG_DWORD    0x3

HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Schedule\Taskcache\Tree\Microsoft\Windows\NetworkAccessProtection

HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Schedule\Taskcache\Tree\Microsoft\Windows\NetworkAccessProtection\NAPStatus UI
    Id    REG_SZ    {00BB5F5C-4A20-4FD6-8900-4699F989BF01}
    Index    REG_DWORD    0x0

HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Schedule\Taskcache\Tree\Microsoft\Windows\Offline Files

HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Schedule\Taskcache\Tree\Microsoft\Windows\Offline Files\Background Synchronization
    Id    REG_SZ    {D378D375-CAC7-474F-8B4B-82FF8391E306}
    Index    REG_DWORD    0x3

HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Schedule\Taskcache\Tree\Microsoft\Windows\Offline Files\Logon Synchronization
    Id    REG_SZ    {AEA35300-8D3F-4FFA-9243-5072A3D37166}
    Index    REG_DWORD    0x2

HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Schedule\Taskcache\Tree\Microsoft\Windows\PerfTrack

HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Schedule\Taskcache\Tree\Microsoft\Windows\PerfTrack\BackgroundConfigSurveyor
    Id    REG_SZ    {B0CBAB43-44FC-469B-A4CE-87426761FDCE}
    Index    REG_DWORD    0x3

HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Schedule\Taskcache\Tree\Microsoft\Windows\PLA

HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Schedule\Taskcache\Tree\Microsoft\Windows\PLA\System

HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Schedule\Taskcache\Tree\Microsoft\Windows\PLA\System\ConvertLogEntries
    Id    REG_SZ    {600F3312-A477-448A-936D-EB2DF977300B}
    Index    REG_DWORD    0x0

HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Schedule\Taskcache\Tree\Microsoft\Windows\Power Efficiency Diagnostics

HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Schedule\Taskcache\Tree\Microsoft\Windows\Power Efficiency Diagnostics\AnalyzeSystem
    Id    REG_SZ    {FB3C354D-297A-4EB2-9B58-090F6361906B}
    Index    REG_DWORD    0x3

HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Schedule\Taskcache\Tree\Microsoft\Windows\RAC

HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Schedule\Taskcache\Tree\Microsoft\Windows\RAC\RACAgent
    Id    REG_SZ    {7F9C951C-D364-4B70-8D07-D2C9B7F76E35}
    Index    REG_DWORD    0x0

HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Schedule\Taskcache\Tree\Microsoft\Windows\RAC\RacTask
    Id    REG_SZ    {EACA24FF-236C-401D-A1E7-B3D5267B8A50}
    Index    REG_DWORD    0x3

HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Schedule\Taskcache\Tree\Microsoft\Windows\Ras

HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Schedule\Taskcache\Tree\Microsoft\Windows\Ras\MobilityManager
    Id    REG_SZ    {AC668097-4D6B-4093-AC14-014C09DBF820}
    Index    REG_DWORD    0x3

HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Schedule\Taskcache\Tree\Microsoft\Windows\Registry

HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Schedule\Taskcache\Tree\Microsoft\Windows\Registry\RegIdleBackup
    Id    REG_SZ    {CA4B8FF2-A4D2-4D88-A52E-3A5BDAF7F56E}
    Index    REG_DWORD    0x3

HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Schedule\Taskcache\Tree\Microsoft\Windows\RemoteAssistance

HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Schedule\Taskcache\Tree\Microsoft\Windows\RemoteAssistance\RemoteAssistanceTask
    Id    REG_SZ    {CB3D64BF-C0C9-45FF-BFB0-FF1A8F680186}
    Index    REG_DWORD    0x3

HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Schedule\Taskcache\Tree\Microsoft\Windows\Setup

HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Schedule\Taskcache\Tree\Microsoft\Windows\Setup\gwx

HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Schedule\Taskcache\Tree\Microsoft\Windows\Setup\gwx\launchtrayprocess
    Id    REG_SZ    {4E123E26-F25D-4531-940D-1CE792873193}
    Index    REG_DWORD    0x2

HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Schedule\Taskcache\Tree\Microsoft\Windows\Setup\gwx\refreshgwxconfig
    Id    REG_SZ    {63383B41-CD22-4AEF-B02D-D120C179FF58}
    Index    REG_DWORD    0x3

HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Schedule\Taskcache\Tree\Microsoft\Windows\Setup\gwx\refreshgwxconfigandcontent
    Id    REG_SZ    {FC4403AB-CB2F-42A2-9F65-6CA817FDFEC4}
    Index    REG_DWORD    0x3

HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Schedule\Taskcache\Tree\Microsoft\Windows\Setup\gwx\refreshgwxcontent
    Id    REG_SZ    {7F946C6C-5401-4324-9B15-70C5B0892EE6}
    Index    REG_DWORD    0x3

HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Schedule\Taskcache\Tree\Microsoft\Windows\Setup\GWXTriggers

HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Schedule\Taskcache\Tree\Microsoft\Windows\Setup\GWXTriggers\refreshgwxconfig-B
    Id    REG_SZ    {51BE84C4-5631-4EF6-B076-5745D35B06F5}
    Index    REG_DWORD    0x3

HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Schedule\Taskcache\Tree\Microsoft\Windows\Shell

HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Schedule\Taskcache\Tree\Microsoft\Windows\Shell\CrawlStartPages
    Id    REG_SZ    {B936B1AF-0C7E-4C4D-84F1-CF67453259A1}
    Index    REG_DWORD    0x0

HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Schedule\Taskcache\Tree\Microsoft\Windows\Shell\WindowsParentalControls
    Id    REG_SZ    {5B42DD9C-5A26-4F27-BB95-34603F0997E5}
    Index    REG_DWORD    0x2

HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Schedule\Taskcache\Tree\Microsoft\Windows\Shell\WindowsParentalControlsMigration
    Id    REG_SZ    {486D715E-6AA2-44CF-BC48-B6990CBB53C6}
    Index    REG_DWORD    0x2

HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Schedule\Taskcache\Tree\Microsoft\Windows\SideShow

HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Schedule\Taskcache\Tree\Microsoft\Windows\SideShow\AutoWake
    Id    REG_SZ    {2D70F1F8-E61A-46C8-B602-8C0F8C536A9D}
    Index    REG_DWORD    0x2

HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Schedule\Taskcache\Tree\Microsoft\Windows\SideShow\GadgetManager
    Id    REG_SZ    {CBC80253-50BE-47AF-81EA-A8816005ABE4}
    Index    REG_DWORD    0x2

HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Schedule\Taskcache\Tree\Microsoft\Windows\SideShow\SessionAgent
    Id    REG_SZ    {0DC5362E-5BE5-491D-8F88-8E388E4759CD}
    Index    REG_DWORD    0x2

HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Schedule\Taskcache\Tree\Microsoft\Windows\SideShow\SystemDataProviders
    Id    REG_SZ    {8BDF0314-A8E0-4A71-9E60-0F7C1739DE56}
    Index    REG_DWORD    0x2

HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Schedule\Taskcache\Tree\Microsoft\Windows\SoftwareProtectionPlatform

HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Schedule\Taskcache\Tree\Microsoft\Windows\SoftwareProtectionPlatform\SvcRestartTask
    Id    REG_SZ    {DD9F510C-95F4-499A-90C8-BAC5BC372FF4}
    Index    REG_DWORD    0x3

HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Schedule\Taskcache\Tree\Microsoft\Windows\SystemRestore

HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Schedule\Taskcache\Tree\Microsoft\Windows\SystemRestore\SR
    Id    REG_SZ    {994C86AD-A929-4B2C-88A0-4E25A107A029}
    Index    REG_DWORD    0x1

HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Schedule\Taskcache\Tree\Microsoft\Windows\Task Manager

HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Schedule\Taskcache\Tree\Microsoft\Windows\Task Manager\Interactive
    Id    REG_SZ    {1F7B7221-AE8F-44F3-BA82-F7D260F51964}
    Index    REG_DWORD    0x3

HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Schedule\Taskcache\Tree\Microsoft\Windows\Tcpip

HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Schedule\Taskcache\Tree\Microsoft\Windows\Tcpip\IpAddressConflict1
    Id    REG_SZ    {088482FA-65B8-4E17-9ABF-1DCD48E8D373}
    Index    REG_DWORD    0x3

HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Schedule\Taskcache\Tree\Microsoft\Windows\Tcpip\IpAddressConflict2
    Id    REG_SZ    {09F06BFE-A3C8-40E3-846A-6E6F4000C238}
    Index    REG_DWORD    0x3

HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Schedule\Taskcache\Tree\Microsoft\Windows\TextServicesFramework

HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Schedule\Taskcache\Tree\Microsoft\Windows\TextServicesFramework\MsCtfMonitor
    Id    REG_SZ    {4C8B01A2-11FF-4C41-848F-508EF4F00CF7}
    Index    REG_DWORD    0x2

HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Schedule\Taskcache\Tree\Microsoft\Windows\Time Synchronization

HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Schedule\Taskcache\Tree\Microsoft\Windows\Time Synchronization\SynchronizeTime
    Id    REG_SZ    {044A6734-E90E-4F8F-B357-B2DC8AB3B5EC}
    Index    REG_DWORD    0x3

HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Schedule\Taskcache\Tree\Microsoft\Windows\UPnP

HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Schedule\Taskcache\Tree\Microsoft\Windows\UPnP\UPnPHostConfig
    Id    REG_SZ    {5A40E926-9E86-4B89-9CFD-B12311724371}
    Index    REG_DWORD    0x3

HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Schedule\Taskcache\Tree\Microsoft\Windows\User Profile Service

HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Schedule\Taskcache\Tree\Microsoft\Windows\User Profile Service\HiveUploadTask
    Id    REG_SZ    {6738BA6E-EA75-4B6B-B8B8-71F0336DD8EF}
    Index    REG_DWORD    0x3

HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Schedule\Taskcache\Tree\Microsoft\Windows\WDI

HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Schedule\Taskcache\Tree\Microsoft\Windows\WDI\ResolutionHost
    Id    REG_SZ    {9435F817-FED2-454E-88CD-7F78FDA62C48}
    Index    REG_DWORD    0x3

HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Schedule\Taskcache\Tree\Microsoft\Windows\Windows Activation Technologies

HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Schedule\Taskcache\Tree\Microsoft\Windows\Windows Activation Technologies\ValidationTask
    Id    REG_SZ    {880E621A-DD8A-497F-BED1-3311DA2C4FA1}
    Index    REG_DWORD    0x3

HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Schedule\Taskcache\Tree\Microsoft\Windows\Windows Activation Technologies\ValidationTaskDeadline
    Id    REG_SZ    {29BBD2BA-5D45-4CB7-965D-1CD982162CA3}
    Index    REG_DWORD    0x3

HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Schedule\Taskcache\Tree\Microsoft\Windows\Windows Error Reporting

HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Schedule\Taskcache\Tree\Microsoft\Windows\Windows Error Reporting\QueueReporting
    Id    REG_SZ    {D0250F3F-6480-484F-B719-42F659AC64D5}
    Index    REG_DWORD    0x2

HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Schedule\Taskcache\Tree\Microsoft\Windows\Windows Filtering Platform

HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Schedule\Taskcache\Tree\Microsoft\Windows\Windows Filtering Platform\BfeOnServiceStartTypeChange
    Id    REG_SZ    {E22A8667-F75B-4BA9-BA46-067ED4429DE8}
    Index    REG_DWORD    0x3

HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Schedule\Taskcache\Tree\Microsoft\Windows\Windows Media Sharing

HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Schedule\Taskcache\Tree\Microsoft\Windows\Windows Media Sharing\UpdateLibrary
    Id    REG_SZ    {753C47AE-EC5E-44B3-95A9-2C8E553F0E39}
    Index    REG_DWORD    0x3

HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Schedule\Taskcache\Tree\Microsoft\Windows\WindowsBackup

HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Schedule\Taskcache\Tree\Microsoft\Windows\WindowsBackup\ConfigNotification
    Id    REG_SZ    {2F57269B-1E09-4E2D-AB1E-B0FDAC7D279C}
    Index    REG_DWORD    0x3

HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Schedule\Taskcache\Tree\Microsoft\Windows\WindowsColorSystem

HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Schedule\Taskcache\Tree\Microsoft\Windows\WindowsColorSystem\Calibration Loader
    Id    REG_SZ    {A35BB7A6-5F0C-4C9F-8450-2B3BED532D51}
    Index    REG_DWORD    0x2

HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Schedule\Taskcache\Tree\Microsoft\Windows\Wininet

HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Schedule\Taskcache\Tree\Microsoft\Windows\Wininet\CacheTask
    Id    REG_SZ    {1CBB66B9-9E68-4ACE-8275-4E8796A4A18F}
    Index    REG_DWORD    0x2

HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Schedule\Taskcache\Tree\Microsoft\Windows Defender

HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Schedule\Taskcache\Tree\Norton Internet Security

HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Schedule\Taskcache\Tree\Norton Internet Security\Norton Error Analyzer
    Id    REG_SZ    {383EAD95-C762-4EB9-9AB8-78CCE1AF3C38}
    Index    REG_DWORD    0x3

HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Schedule\Taskcache\Tree\Norton Internet Security\Norton Error Processor
    Id    REG_SZ    {B96F52BC-A937-4670-8F16-886CE14EAD84}
    Index    REG_DWORD    0x3

HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Schedule\Taskcache\Tree\WPD

HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Schedule\Taskcache\Tree\WPD\SqmUpload_S-1-5-21-786217106-2830415026-3013700145-1000
    Id    REG_SZ    {278D9BE4-FE38-4141-9BA1-B3F35074E9E1}
    Index    REG_DWORD    0x3

 

========= End of Reg: =========


==== End of Fixlog 06:35:48 ====

 

 

Link to post
Share on other sites

5 minutes ago, tommybio said:

OK here is the file:

Fix result of Farbar Recovery Scan Tool (x64) Version: 20-08-2017
Ran by TomR (30-08-2017 06:35:46) Run:2
Running from C:\Users\TomR\Desktop
Loaded Profiles: TomR & UpdatusUser (Available Profiles: TomR & UpdatusUser)
Boot Mode: Normal
==============================================

fixlist content:
*****************
Task: {C035C4E6-38EC-4B00-B302-114AF66ED59D} - no filepath
Task: {C8D67D68-F559-44CC-8324-0A20E7FEA212} - no filepath

WMI_ActiveScriptEventConsumer_censoredyoumm2_consumer: <==== ATTENTION

REG: REG QUERY "HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\Taskcache\Tasks" /s
REG: REG QUERY "HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\Taskcache\Tree" /s
*****************

HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Boot\{C035C4E6-38EC-4B00-B302-114AF66ED59D} => key removed successfully
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{C035C4E6-38EC-4B00-B302-114AF66ED59D} => key removed successfully
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Boot\{C8D67D68-F559-44CC-8324-0A20E7FEA212} => key removed successfully
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{C8D67D68-F559-44CC-8324-0A20E7FEA212} => key removed successfully
WMI_ActiveScriptEventConsumer_censoredyoumm2_consumer: <==== ATTENTION => not found

========= REG QUERY "HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\Taskcache\Tasks" /s =========


HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Schedule\Taskcache\Tasks\{003DBEB6-92B4-41BC-A8DE-E766A3FB3C65}
    Path    REG_SZ    \Microsoft\Windows\Media Center\ehDRMInit
    Triggers    REG_BINARY    150000000000000000FFFFFFFFFFFFFFFFFFFFFFFFFFFFFF00FFFFFFFFFFFFFF00000000000000000021420248484848E8DDC73B484848480048484848484848004848484848484805000000484848480C000000484848480101000000000005130000004848484800000000484848480000000048484848
    DynamicInfo    REG_BINARY    0300000060EA3F4901DCCA0100000000000000000000000000000000
    Hash    REG_BINARY    9B2BFF8825669B3C372748418CC0EB39C719BDAEBCD676CC7B39E1022601A0BF

HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Schedule\Taskcache\Tasks\{034DF26D-DA1B-4161-9AE1-330409B21EE7}
    Path    REG_SZ    \Microsoft\Windows\Application Experience\ProgramDataUpdater
    Hash    REG_BINARY    A1AC57965B3F9A2A449EAED18D7C3EDAD8A5F295FF2D072E48B8CE64AF5D84EC
    Triggers    REG_BINARY    150000000000000001DD880000000000000CCFC53963CF0100DD880000000000FFFFFFFFFFFFFFFF7E214202484848488E08769D484848480048484848484848004848484848484805000000484848480C000000484848480101000000000005120000004848484800000000484848483800000048484848B40000007043010080F40300FFFFFFFF04000000000000000000000000000000000000000000000000000000000000000000000000000000DDDD00000000000001DD880000000000000CCFC53963CF0100000000000000000000000000000000000000000000000000000000000000000000000000000000FFFFFFFF0100000001000000000000000001000001000000201C000000000000
    DynamicInfo    REG_BINARY    0300000040906BAC3E1AD10100000000000000000000000000000000

HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Schedule\Taskcache\Tasks\{044A6734-E90E-4F8F-B357-B2DC8AB3B5EC}
    Path    REG_SZ    \Microsoft\Windows\Time Synchronization\SynchronizeTime
    Triggers    REG_BINARY    1500000000000000011272FBFE07000000E8E6379DEFC401001272FBFE070000FFFFFFFFFFFFFFFFE021420348484848DFDC7836484848480048484848484848004848484848484805000000484848480C000000484848480101000000000005130000004848484800000000484848480000000048484848DDDD000000000000011272FBFE07000000E8E6379DEFC40100000000000000000000000000000000000000000000000000000000000000000000000000000000FFFFFFFF02000000010001000000000000010000010000000000000000000000
    DynamicInfo    REG_BINARY    030000002D35042D4104CA0100000000000000000000000000000000
    Hash    REG_BINARY    17D3BD884BE1EAD4B4B32CC46D0707E468688A3FCDE1835573BF3A392D0BF65A

HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Schedule\Taskcache\Tasks\{059C454D-C82D-4FBA-ACA0-E0D20F84D4CD}
    Path    REG_SZ    \Microsoft\Windows\Media Center\RegisterSearch
    Triggers    REG_BINARY    150000000000000000FFFFFFFFFFFFFFFFFFFFFFFFFFFFFF00FFFFFFFFFFFFFF00000000000000000021420248484848A9A3FB23484848480048484848484848004848484848484805000000484848480C000000484848480101000000000005120000004848484800000000484848480000000048484848
    DynamicInfo    REG_BINARY    0300000000D6C24901DCCA0100000000000000000000000000000000
    Hash    REG_BINARY    3C0B66D64686766827850B149B5AFB544220673B5B4D47CB5556EF2C868E2381

HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Schedule\Taskcache\Tasks\{088482FA-65B8-4E17-9ABF-1DCD48E8D373}
    Path    REG_SZ    \Microsoft\Windows\Tcpip\IpAddressConflict1
    Triggers    REG_BINARY    1500000000000000001C24FBFE0700000000000000000000001C24FBFE070000FFFFFFFFFFFFFFFF38A1400348484848E99D6008484848480048484848484848004848484848484804000000484848481000000048484848010200000000000520000000210200000000000048484848380000004848484858020000100E000080F40300FFFFFFFF07000000000000000000000000000000000000000000000000000000000000000000000000000000CCCC000000000000001C24FBFE0700000000000000000000001C24FBFE070000FFFFFFFFFFFFFFFF00000000FFFFFFFF00000000000000000000000000000000010100000000000520000000000000008D000000000000003C00510075006500720079004C006900730074003E003C00510075006500720079002000490064003D00220030002200200050006100740068003D002200530079007300740065006D0022003E003C00530065006C00650063007400200050006100740068003D002200530079007300740065006D0022003E002A005B00530079007300740065006D005B00500072006F00760069006400650072005B0040004E0061006D0065003D0027005400630070006900700027005D00200061006E00640020004500760065006E007400490044003D0034003100390038005D005D003C002F00530065006C006500630074003E003C002F00510075006500720079003E003C002F00510075006500720079004C006900730074003E00000048484848000000000000000000000000000000000000000000000000
    DynamicInfo    REG_BINARY    030000008D96062D4104CA0100000000000000000000000000000000
    Hash    REG_BINARY    CEF4FD5DA04459B60C163CD71D538078A601EF7EE05832CECD2DD79D5213AF22

HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Schedule\Taskcache\Tasks\{09F06BFE-A3C8-40E3-846A-6E6F4000C238}
    Path    REG_SZ    \Microsoft\Windows\Tcpip\IpAddressConflict2
    Triggers    REG_BINARY    1500000000000000011272FBFE07000080294E129638C601001C24FBFE070000FFFFFFFFFFFFFFFF38A1400348484848A201FC43484848480048484848484848004848484848484804000000484848481000000048484848010200000000000520000000210200000000000048484848380000004848484858020000100E000080F40300FFFFFFFF07000000000000000000000000000000000000000000000000000000750070000000000000000000CCCC000000000000011272FBFE07000080294E129638C601001C24FBFE070000FFFFFFFFFFFFFFFF00000000FFFFFFFF00000000000000000000000000000000010100000000000520000000000000008D000000000000003C00510075006500720079004C006900730074003E003C00510075006500720079002000490064003D00220030002200200050006100740068003D002200530079007300740065006D0022003E003C00530065006C00650063007400200050006100740068003D002200530079007300740065006D0022003E002A005B00530079007300740065006D005B00500072006F00760069006400650072005B0040004E0061006D0065003D0027005400630070006900700027005D00200061006E00640020004500760065006E007400490044003D0034003100390039005D005D003C002F00530065006C006500630074003E003C002F00510075006500720079003E003C002F00510075006500720079004C006900730074003E00000048484848000000000000000000000000000000000000000000000000
    DynamicInfo    REG_BINARY    030000008D96062D4104CA0100000000000000000000000000000000
    Hash    REG_BINARY    4D3C72EE9B731BFCFC7022531B2870DEF28FF13FF8E0F089003E02AA0F40C05D

HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Schedule\Taskcache\Tasks\{0DC5362E-5BE5-491D-8F88-8E388E4759CD}
    Path    REG_SZ    \Microsoft\Windows\SideShow\SessionAgent
    Triggers    REG_BINARY    1500000000000000000000000000000000000000000000000000000000000000FFFFFFFFFFFFFFFF00850002484848483D09F37D484848480048484848484848004848484848484804000000484848481000000048484848010200000000000520000000210200000000000048484848380000004848484800000000FFFFFFFF00000000FFFFFFFF070000000000000000000000000000000000000000000000000000006D0022000000000000000000AAAA000000000000000000000000000000000000000000000000000000000000FFFFFFFFFFFFFFFF0F000000FFFFFFFF0000000000000000000000000000000001729D010000000005000000000000000148484848484848
    DynamicInfo    REG_BINARY    03000000E0A9F24701DCCA0100000000000000000000000000000000
    Hash    REG_BINARY    DBC065695455F16521C1F2CCB4FBA71757C53FC6D38C9B87FE41BF26F286E159

HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Schedule\Taskcache\Tasks\{1134D20D-324D-4391-86F5-75AFCFC9779A}
    Path    REG_SZ    \Microsoft\Windows\Media Center\StartRecording
    Triggers    REG_BINARY    150000000000000000FFFFFFFFFFFFFFFFFFFFFFFFFFFFFF00FFFFFFFFFFFFFF00000000000000004807420248484848FB7B73CB484848480048484848484848004848484848484805000000484848480C00000048484848010100000000000514000000484848480000000048484848380000004848484858020000100E000080F40300FFFFFFFF07000000000000000000000000000000000000000000000000000000000000000000000000000000
    DynamicInfo    REG_BINARY    03000000B803F6BB772FCB0100000000000000000000000000000000
    Hash    REG_BINARY    6F3251475E855FE31A519893A624488246E71775F85E8A3FF3D3B155D2685F76

HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Schedule\Taskcache\Tasks\{19DADAD5-F9EC-4AEF-946C-C0A576840830}
    Path    REG_SZ    \Microsoft\Windows\Media Center\PeriodicScanRetry
    Triggers    REG_BINARY    1500000000000000016C780100000000006ECFFE35D4C6010100000000000000006ECFFE35D4C6013021020248484848890E4413484848480048484848484848004848484848484805000000484848480C00000048484848010100000000000514000000484848480000000048484848380000004848484800000000FFFFFFFF80F40300FFFFFFFF07000000000000000000000000000000000000000000000000000000610073000000000000000000DDDD000000000000016C780100000000006ECFFE35D4C60100000000000000000000000000000000000000000000000000000000000000000000000000000000FFFFFFFF00000000000000000000000000000000010000000000000000000000
    DynamicInfo    REG_BINARY    03000000808FE14B01DCCA0100000000000000000000000000000000
    Hash    REG_BINARY    8E6911CA59C45F2EE0BF63453DCD580B285E92CE1BFE4589F956D67C57F75EA3

HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Schedule\Taskcache\Tasks\{1BA0AE97-C21E-48BB-9FF0-70BC9F299377}
    Path    REG_SZ    \Microsoft\Windows\MobilePC\HotStart
    Triggers    REG_BINARY    1500000000000000000000000000000000000000000000000000000000000000FFFFFFFFFFFFFFFF40854002484848487E9B658C484848480048484848484848004848484848484805000000484848480C0000004848484801010000000000050B000000484848480000000048484848380000004848484800000000FFFFFFFF00000000FFFFFFFF07000000000000000000000000000000000000000000000000000000000000000000000000000000AAAA000000000000000000000000000000000000000000000000000000000000FFFFFFFFFFFFFFFF00000000FFFFFFFF00000000000000000000000000000000010063006E002000300000006E0069000148484848484848
    DynamicInfo    REG_BINARY    030000002070514C01DCCA0100000000000000000000000000000000
    Hash    REG_BINARY    0651BF3B9923F80BE8B50E253E843A95B0CFB7EB97A3EE4E7C955B543DD190E9

HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Schedule\Taskcache\Tasks\{1CBB66B9-9E68-4ACE-8275-4E8796A4A18F}
    Path    REG_SZ    \Microsoft\Windows\Wininet\CacheTask
    Hash    REG_BINARY    B40015C2E03A4473C93284B4A79D0D10020C191C69D34B60D89B92D8942A01FC
    Triggers    REG_BINARY    1500000000000000000000000000000000000000000000000000000000000000FFFFFFFFFFFFFFFF008540024848484814F966A5484848480048484848484848004848484848484804000000484848481000000048484848010200000000000520000000210200000000000048484848380000004848484800000000FFFFFFFF00000000FFFFFFFF07000000000000000000000000000000000000000000000000000000000000000000000000000000AAAA000000000000000000000000000000000000000000000000000000000000FFFFFFFFFFFFFFFF00000000FFFFFFFF000000000000000000000000000000000100610073006B0000000000000000000148484848484848
    DynamicInfo    REG_BINARY    03000000E015C0BF0C21CE0100000000000000000000000000000000

HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Schedule\Taskcache\Tasks\{1F7B7221-AE8F-44F3-BA82-F7D260F51964}
    Path    REG_SZ    \Microsoft\Windows\Task Manager\Interactive
    Triggers    REG_BINARY    150000000000000000FFFFFFFFFFFFFFFFFFFFFFFFFFFFFF00FFFFFFFFFFFFFF00000000000000000085C0024848484819D7D458484848480048484848484848004848484848484805000000484848480C00000048484848010100000000000504000000484848480000000048484848380000004848484800000000FFFFFFFF00000000FFFFFFFF05000000000000000000000000000000000000000000000000000000750070000000000000000000
    DynamicInfo    REG_BINARY    03000000EEF7082D4104CA0100000000000000000000000000000000
    Hash    REG_BINARY    89DE49D146B9DA8A3F686F98CC965767AFCD9716B08A2FC65105DC7B0DDDC519

HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Schedule\Taskcache\Tasks\{2470470F-2634-478E-B181-571E98A789BB}
    Path    REG_SZ    \Microsoft\Windows\Multimedia\SystemSoundsService
    Triggers    REG_BINARY    1500000000000000001C24FBFE0700000000000000000000001C24FBFE070000FFFFFFFFFFFFFFFF00854002484848489D3512E9484848480048484848484848004848484848484804000000484848481000000048484848010200000000000520000000210200000000000048484848380000004848484800000000FFFFFFFF00000000FFFFFFFF07000000000000000000000000000000000000000000000000000000750070000000000000000000AAAA000000000000001C24FBFE0700000000000000000000001C24FBFE070000FFFFFFFFFFFFFFFF00000000FFFFFFFF00000000000000000000000000000000010000000000000000000000030000000148484848484848
    DynamicInfo    REG_BINARY    030000002B2AF12C4104CA0100000000000000000000000000000000
    Hash    REG_BINARY    FD7B51B9FB6DDD39374C586690F9E934EE65EB22FD61531B5408B20591031CE2

HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Schedule\Taskcache\Tasks\{25D544CB-69FF-4F6D-B01B-63541C25C654}
    Path    REG_SZ    \Microsoft\Windows\Application Experience\Microsoft Compatibility Appraiser
    Hash    REG_BINARY    125AC9D322ECEB8E929FBE2A6C24EF5649A4A91AB9FA268469CA74EB6BD15B3E
    Triggers    REG_BINARY    150000000000000001C8B6010000000000B894F18D62CF0100C8B60100000000FFFFFFFFFFFFFFFFC821420248484848C23136A2484848480048484848484848004848484848484805000000484848480C00000048484848010100000000000512000000484848480000000048484848380000004848484800000000FFFFFFFF00460500FFFFFFFF07000000000000000000000000000000000000000000000000000000000000000000000000000000DDDD00000000000001C8B6010000000000B894F18D62CF0100000000000000000000000000000000000000000000000000000000000000000000000000000000FFFFFFFF0100000001000000000000000001000001000000201C000000000000
    DynamicInfo    REG_BINARY    03000000E05AB5AC3E1AD10100000000000000000000000000000000

HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Schedule\Taskcache\Tasks\{278D9BE4-FE38-4141-9BA1-B3F35074E9E1}
    Path    REG_SZ    \WPD\SqmUpload_S-1-5-21-786217106-2830415026-3013700145-1000
    Hash    REG_BINARY    00B3986290489C16857629C3FEA18082A8A238256505965704C0BD590C31786D
    Triggers    REG_BINARY    15000000000000000115D3010000000000A0ABD56D4CC8010115D301000000000080D8FCAD84D001D221C102484848487D92DB1F484848480048484848484848004848484848484801000000484848481C0000004848484801050000000000051500000092B8DC2EB2B4B4A8316AA1B3E8030000484848481A0000004848484854006F006D0052002D00500043005C0054006F006D00520000004848484848483800000048484848580200007043010084030000FFFFFFFF07000000000000000000000000000000000000000000000000000000000000000000000000000000DDDD0000000000000115D3010000000000A0ABD56D4CC8010115D301000000000080D8FCAD84D001000000000000000000000000000000000000000000000000FFFFFFFF0100000001000000000000000001000001000000100E000000000000
    DynamicInfo    REG_BINARY    0300000060E4658F9BADD00100000000000000000000000000000000

HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Schedule\Taskcache\Tasks\{28011108-68DF-4C73-B91B-57427D501BBA}
    Path    REG_SZ    \Microsoft\Windows\Active Directory Rights Management Services Client\AD RMS Rights Policy Template Management (Manual)
    Triggers    REG_BINARY    1500000000000000001C24FBFE0700000000000000000000001C24FBFE070000FFFFFFFFFFFFFFFFF885400248484848CE52BAAA484848480048484848484848004848484848484805000000484848480C00000048484848010100000000000100000000484848480000000048484848380000004848484858020000100E0000100E0000FFFFFFFF07000000000000000000000000000000000000000000000000000000000000000000000000000000AAAA000000000000001C24FBFE0700000000000000000000001C24FBFE070000FFFFFFFFFFFFFFFF100E0000FFFFFFFF00000000000000000000000000000000000000000000000000000000030000000148484848484848
    DynamicInfo    REG_BINARY    030000008B8BF32C4104CA0100000000000000000000000000000000
    Hash    REG_BINARY    62050C0D7C474998414FA2C47E4D346ECE628D7D974F377EE3B8AE2E60982EE3

HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Schedule\Taskcache\Tasks\{29BBD2BA-5D45-4CB7-965D-1CD982162CA3}
    Path    REG_SZ    \Microsoft\Windows\Windows Activation Technologies\ValidationTaskDeadline
    Triggers    REG_BINARY    150000000000000000D33101000000008042E1735531D30100D3310100000000FFFFFFFFFFFFFFFFC821C20248484848D2DF9E46484848480048484848484848004848484848484805000000484848480C00000048484848010100000000000513000000484848480000000048484848380000004848484800000000FFFFFFFF00000000FFFFFFFF07000000000000000000000000000000000000000000000000000000000000000000000000000000DDDD00000000000000D33101000000008042E1735531D30100000000000000000000000000000000000000000000000000000000000000000000000000000000FFFFFFFF010000005A0000000000000000010000010000000000000000000000
    DynamicInfo    REG_BINARY    03000000A8AD199C4B2CCB0100000000000000000000000000000000
    Hash    REG_BINARY    151DE2425BDACEC8BFD009484E0BC200E42EBF3932C070471D0261D40FDB8956

HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Schedule\Taskcache\Tasks\{2D70F1F8-E61A-46C8-B602-8C0F8C536A9D}
    Path    REG_SZ    \Microsoft\Windows\SideShow\AutoWake
    Triggers    REG_BINARY    1500000000000000000000000000000000000000000000000000000000000000FFFFFFFFFFFFFFFF00210202484848481CE1E052484848480048484848484848004848484848484805000000484848480C00000048484848010100000000000513000000484848480000000048484848380000004848484800000000FFFFFFFF00000000FFFFFFFF07000000000000000000000000000000000000000000000000000000000000000000000000000000AAAA000000000000000000000000000000000000000000000000000000000000FFFFFFFFFFFFFFFF3C000000FFFFFFFF00000000000000000000000000000000010078010000000005000000000000000148484848484848
    DynamicInfo    REG_BINARY    030000008032CA4701DCCA0100000000000000000000000000000000
    Hash    REG_BINARY    F1F3647B90EF320699C2A4CC877553D0AF5FBC91CCA73EC5D21D2C69ABA97BE7

HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Schedule\Taskcache\Tasks\{2F57269B-1E09-4E2D-AB1E-B0FDAC7D279C}
    Path    REG_SZ    \Microsoft\Windows\WindowsBackup\ConfigNotification
    Triggers    REG_BINARY    1500000000000000018B38000000000000908A6739E1CA01008B380000000000FFFFFFFFFFFFFFFF48214202484848488E099A96484848480048484848484848004848484848484805000000484848480C00000048484848010100000000000513000000484848480000000048484848380000004848484800000000FFFFFFFF80F40300FFFFFFFF07000000000000000000000000000000000000000000000000000000720000000000000000000000DDDD000000000000018B38000000000000908A6739E1CA0100000000000000000000000000000000000000000000000000000000000000000000000000000000FFFFFFFF01000000010000000000000000010000010000000000000000000000
    DynamicInfo    REG_BINARY    030000004E590B2D4104CA0100000000000000000000000000000000
    Hash    REG_BINARY    D524823E731AD9050780CB39719985B52D72C1FE4B2343141EB6CBF421F49F9D

HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Schedule\Taskcache\Tasks\{2FEF85B2-6B9E-476C-A637-B03479D6C607}
    Path    REG_SZ    \Microsoft\Windows\Media Center\PBDADiscovery
    Triggers    REG_BINARY    150000000000000000FFFFFFFFFFFFFFFFFFFFFFFFFFFFFF00FFFFFFFFFFFFFF000000000000000000214202484848484AC29224484848480048484848484848004848484848484805000000484848480C000000484848480101000000000005120000004848484800000000484848480000000048484848
    DynamicInfo    REG_BINARY    0300000060B3E04801DCCA0100000000000000000000000000000000
    Hash    REG_BINARY    FD760AB16D2846C5BFB23557934499A525D5FCEC624AD083FD21DDE1326FAE9D

HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Schedule\Taskcache\Tasks\{383EAD95-C762-4EB9-9AB8-78CCE1AF3C38}
    Path    REG_SZ    \Norton Internet Security\Norton Error Analyzer
    Hash    REG_BINARY    E63BB14A6948B0D356808B8FF08BBAAC07D0171CE7599A41B06C46AC7B73B636
    Triggers    REG_BINARY    150000000000000000FFFFFFFFFFFFFFFFFFFFFFFFFFFFFF00FFFFFFFFFFFFFF00000000000000000805420148484848859C7E07484848480048484848484848004848484848484805000000484848480C00000048484848010100000000000512000000484848480000000048484848380000004848484858020000100E0000100E0000FFFFFFFF07000000000000000000000000000000000000000000000000000000000000000000000000000000

HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Schedule\Taskcache\Tasks\{3AF48B03-9CD2-4EDC-9FB4-A5EC0C31A32C}
    Path    REG_SZ    \Microsoft\Windows\Media Center\SqlLiteRecoveryTask
    Triggers    REG_BINARY    150000000000000000FFFFFFFFFFFFFFFFFFFFFFFFFFFFFF00FFFFFFFFFFFFFF00000000000000000005420248484848BB353C89484848480048484848484848004848484848484805000000484848480C000000484848480101000000000005140000004848484800000000484848480000000048484848
    DynamicInfo    REG_BINARY    03000000C0B36C4D01DCCA0100000000000000000000000000000000
    Hash    REG_BINARY    0582C3DC8E70BC6FAEEB500EB43EEBB03B2D607B40B61B59C0BC46292F5BE42A

HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Schedule\Taskcache\Tasks\{47536D45-EEEC-4BDC-8183-A4DC1F8DA9E4}
    Path    REG_SZ    \Microsoft\Windows\Customer Experience Improvement Program\UsbCeip
    Triggers    REG_BINARY    1500000000000000011272FBFE070000009C9EE073A6C801001272FBFE070000FFFFFFFFFFFFFFFF7021C2024848484863251B5D484848480048484848484848004848484848484805000000484848480C00000048484848010100000000000513000000484848480000000048484848380000004848484800000000FFFFFFFF80F40300FFFFFFFF070000008C0A00000100000000000000000000000000000000000000750070000000000000000000DDDD000000000000011272FBFE070000009C9EE073A6C80100000000000000000000000000000000000000000000000000000000000000000000000000000000FFFFFFFF01000000030000000000000000010000010000000000000000000000
    DynamicInfo    REG_BINARY    03000000AEBA0D2D4104CA0100000000000000000000000000000000
    Hash    REG_BINARY    AE1862BA409924248DC1736D23E327B7154018FC40A4DA695BC777D1135A5244

HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Schedule\Taskcache\Tasks\{486D715E-6AA2-44CF-BC48-B6990CBB53C6}
    Path    REG_SZ    \Microsoft\Windows\Shell\WindowsParentalControlsMigration
    Triggers    REG_BINARY    1500000000000000000000000000000000000000000000000000000000000000FFFFFFFFFFFFFFFF400582034848484879F2196C484848480048484848484848004848484848484805000000484848480C00000048484848010100000000000512000000484848480000000048484848380000004848484800000000FFFFFFFF00000000FFFFFFFF070000003C0000000100000000000000000000000000000000000000750070000000000000000000AAAA000000000000000000000000000000000000000000000000000000000000FFFFFFFFFFFFFFFF01000000FFFFFFFF00000000000000000000000000000000010041003B003B003B004200410029000148484848484848
    DynamicInfo    REG_BINARY    03000000ACAFFA2C4104CA0100000000000000000000000000000000
    Hash    REG_BINARY    6D5D71FCD9AF69DE33A5E47E6DE894CAD15A010944B2EF58C072C7F61EDB87E8

HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Schedule\Taskcache\Tasks\{4B4C6847-EB01-4D6B-858A-41F8352F8BC9}
    Path    REG_SZ    \Microsoft\Windows\Media Center\ObjectStoreRecoveryTask
    Triggers    REG_BINARY    150000000000000000FFFFFFFFFFFFFFFFFFFFFFFFFFFFFF00FFFFFFFFFFFFFF00000000000000000005420248484848073581F7484848480048484848484848004848484848484805000000484848480C000000484848480101000000000005140000004848484800000000484848480000000048484848
    DynamicInfo    REG_BINARY    03000000C092334D01DCCA0100000000000000000000000000000000
    Hash    REG_BINARY    0D7CE53B5DEDF3BB738E23E6AFCFF4829C8AF0A3B1179EFB42DD3DAFED865833

HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Schedule\Taskcache\Tasks\{4C8B01A2-11FF-4C41-848F-508EF4F00CF7}
    Path    REG_SZ    \Microsoft\Windows\TextServicesFramework\MsCtfMonitor
    Triggers    REG_BINARY    1500000000000000001624FBFE0700000000000000000000001624FBFE070000FFFFFFFFFFFFFFFF0085C00248484848E774F314484848480048484848484848004848484848484804000000484848481000000048484848010200000000000520000000210200000000000048484848380000004848484800000000FFFFFFFF00000000FFFFFFFF07000000000000000000000000000000000000000000000000000000750070000000000000000000AAAA000000000000001624FBFE0700000000000000000000001624FBFE070000FFFFFFFFFFFFFFFF00000000FFFFFFFF00000000000000000000000000000000010000000000000000000000030000000148484848484848
    DynamicInfo    REG_BINARY    030000000C11FD2C4104CA0100000000000000000000000000000000
    Hash    REG_BINARY    F7CCB39021E7E245CADCD75E426102522087DD3AC91AF7D4387D8D70ED6DDAB4

HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Schedule\Taskcache\Tasks\{4E123E26-F25D-4531-940D-1CE792873193}
    Path    REG_SZ    \Microsoft\Windows\Setup\gwx\launchtrayprocess
    Hash    REG_BINARY    93E30285FEF89B0B1703BB0FBAB52ACDA7984EB32E5D35CE5EAC8B9B19FBD193
    Triggers    REG_BINARY    1500000000000000000000000000000000000000000000000000000000000000FFFFFFFFFFFFFFFF40854002484848489F7D6B40484848480048484848484848004848484848484805000000484848480C00000048484848010100000000000504000000484848480000000048484848380000004848484800000000FFFFFFFF00000000FFFFFFFF0600000000000000000000000000000000000000000000000000000052006F000000000000000000AAAA00000000000001A2F5010000000000201676A646CE010000000000000000FFFFFFFFFFFFFFFF0F000000FFFFFFFF00000000000000000000000000000000010064006C006C002C002D003500300001484848484848488888000000000000000000000000000000000000000000000000000000000000FFFFFFFFFFFFFFFF00000000FFFFFFFF0000000000000000000000000007000001006F0072002E006500780065000000
    DynamicInfo    REG_BINARY    03000000C09C417A3B1AD10100000000000000000000000000000000

HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Schedule\Taskcache\Tasks\{51A295A6-300F-46E4-B98A-DF89A97815D3}
    Path    REG_SZ    \Microsoft\Windows\Media Center\PvrRecoveryTask
    Triggers    REG_BINARY    150000000000000000FFFFFFFFFFFFFFFFFFFFFFFFFFFFFF00FFFFFFFFFFFFFF0000000000000000000542024848484831C9DCAA484848480048484848484848004848484848484805000000484848480C000000484848480101000000000005140000004848484800000000484848480000000048484848
    DynamicInfo    REG_BINARY    03000000C07C0D4D01DCCA0100000000000000000000000000000000
    Hash    REG_BINARY    F18E7E603225B086AE1605B0EDDA4E41A11A6940F8C50583C566546D4753DBF9

HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Schedule\Taskcache\Tasks\{51BE84C4-5631-4EF6-B076-5745D35B06F5}
    Path    REG_SZ    \Microsoft\Windows\Setup\GWXTriggers\refreshgwxconfig-B
    Hash    REG_BINARY    556E06A2A3869023D1F169CD55A33855EFEE027AFA831F9F3901D14CDA3F3161
    Triggers    REG_BINARY    150000000000000001C8B6010000000000201676A646CE0100C8B60100000000FFFFFFFFFFFFFFFFC821420148484848925369A9484848480048484848484848004848484848484805000000484848480C00000048484848010100000000000512000000484848480000000048484848380000004848484800000000FFFFFFFF00000000FFFFFFFF07000000000000000000000000000000000000000000000000000000000000000000000000000000DDDD00000000000001C8B6010000000000201676A646CE010000000000000000000000000000000000000000000000000000000000000000C0A8000080510100FFFFFFFF0100000001000000000000000001000001000000C0A8000000000000
    DynamicInfo    REG_BINARY    030000007002FE107921D30100000000000000000000000000000000

HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Schedule\Taskcache\Tasks\{53BB7902-6E80-4F0D-B21C-501FE9C0E32E}
    Path    REG_SZ    \Microsoft\Windows\Media Center\RecordingRestart
    Triggers    REG_BINARY    1500000000000000000000000000000000000000000000000000000000000000FFFFFFFFFFFFFFFF60050202484848483E01CFAF484848480048484848484848004848484848484805000000484848480C00000048484848010100000000000514000000484848480000000048484848380000004848484800000000FFFFFFFF80F40300FFFFFFFF06000000000000000000000000000000000000000000000000000000000000000000000000000000FFFF000000000000000000000000000000000000000000000000000000000000FFFFFFFFFFFFFFFF00000000FFFFFFFF00000000000000000000000000070000010063006E002000300000006E006900
    DynamicInfo    REG_BINARY    03000000A021A74C01DCCA0100000000000000000000000000000000
    Hash    REG_BINARY    F5FE5470249EA95DE2CB01D9FA910FB31957ED0FB0F9E03208A37081A057AA08

HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Schedule\Taskcache\Tasks\{586D03C8-7997-4FDC-8F49-2F396233504A}
    Path    REG_SZ    \Microsoft\Windows\Media Center\ConfigureInternetTimeService
    Triggers    REG_BINARY    150000000000000000FFFFFFFFFFFFFFFFFFFFFFFFFFFFFF00FFFFFFFFFFFFFF00000000000000000021420248484848334EC699484848480048484848484848004848484848484805000000484848480C000000484848480101000000000005120000004848484800000000484848480000000048484848
    DynamicInfo    REG_BINARY    03000000803A934901DCCA0100000000000000000000000000000000
    Hash    REG_BINARY    1A61FB3046F2F771F436B66EDEC9EEC6E1E9E3F219AA4224495928E6BC347BEE

HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Schedule\Taskcache\Tasks\{59FCD788-0753-4F0B-A5CB-D300883F1B39}
    Path    REG_SZ    \Microsoft\Windows\Media Center\ActivateWindowsSearch
    Triggers    REG_BINARY    150000000000000000FFFFFFFFFFFFFFFFFFFFFFFFFFFFFF00FFFFFFFFFFFFFF000000000000000000214202484848489039649F484848480048484848484848004848484848484805000000484848480C000000484848480101000000000005120000004848484800000000484848480000000048484848
    DynamicInfo    REG_BINARY    03000000C0DA394A01DCCA0100000000000000000000000000000000
    Hash    REG_BINARY    440979398F3AB418F90B93DC0DD97070F5EF2337860AB42775202EF71D70B9E9

HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Schedule\Taskcache\Tasks\{5A40E926-9E86-4B89-9CFD-B12311724371}
    Path    REG_SZ    \Microsoft\Windows\UPnP\UPnPHostConfig
    Triggers    REG_BINARY    150000000000000000FFFFFFFFFFFFFFFFFFFFFFFFFFFFFF00FFFFFFFFFFFFFF0000000000000000102142024848484811E47727484848480048484848484848004848484848484805000000484848480C000000484848480101000000000005120000004848484800000000484848480000000048484848
    DynamicInfo    REG_BINARY    030000006F7D122D4104CA0100000000000000000000000000000000
    Hash    REG_BINARY    6A0C38920812DABEF61FED2083D14E9E085CDBD0F5459B3159F0F4504CC8B4B0

HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Schedule\Taskcache\Tasks\{5B42DD9C-5A26-4F27-BB95-34603F0997E5}
    Path    REG_SZ    \Microsoft\Windows\Shell\WindowsParentalControls
    Triggers    REG_BINARY    1500000000000000001624FBFE0700000000000000000000001624FBFE070000FFFFFFFFFFFFFFFF4085800248484848E149B4C1484848480048484848484848004848484848484805000000484848480C0000004848484801010000000000050B000000484848480000000048484848380000004848484800000000FFFFFFFF00000000FFFFFFFF070000003C0000000500000000000000000000000000000000000000750070000000000000000000AAAA000000000000001624FBFE0700000000000000000000001624FBFE070000FFFFFFFFFFFFFFFF01000000FFFFFFFF00000000000000000000000000000000000000000000000000000000030000000148484848484848
    DynamicInfo    REG_BINARY    030000000C11FD2C4104CA0100000000000000000000000000000000
    Hash    REG_BINARY    886511E7DEE4F447B2F704A04046BB942BD9BDA76152A12BB0AE3D9B56C6AAF5

HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Schedule\Taskcache\Tasks\{5F5A18EB-DC73-4E45-A11C-B59043598412}
    Path    REG_SZ    \Microsoft\Windows\CertificateServicesClient\SystemTask
    Triggers    REG_BINARY    1500000000000000001C24FBFE0700000000000000000000001C24FBFE070000FFFFFFFFFFFFFFFFC0054202484848484E9F42CE484848480048484848484848004848484848484805000000484848480C00000048484848010100000000000512000000484848480000000048484848380000004848484800000000FFFFFFFF00000000FFFFFFFF070000003C0000000500000000000000000000000000000000000000750070000000000000000000CCCC000000000000001C24FBFE0700000000000000000000001C24FBFE070000FFFFFFFFFFFFFFFF00000000FFFFFFFF00000000000000000000000000000000010100000000000520000000000000001B010000000000003C00510075006500720079004C006900730074003E000A0020002000200020002000200020002000200020002000200020002000200020003C00510075006500720079002000490064003D00220030002200200050006100740068003D002200530079007300740065006D0022003E000A00200020002000200020002000200020002000200020002000200020002000200020002000200020003C00530065006C00650063007400200050006100740068003D002200530079007300740065006D0022003E000A002000200020002000200020002000200020002000200020002000200020002000200020002000200020002000200020002A005B00530079007300740065006D005B00500072006F00760069006400650072005B0040004E0061006D0065003D0027004D006900630072006F0073006F00660074002D00570069006E0064006F00770073002D00470072006F007500700050006F006C0069006300790027005D00200061006E00640020004500760065006E007400490044003D0031003500300032005D005D000A00200020002000200020002000200020002000200020002000200020002000200020002000200020003C002F00530065006C006500630074003E000A0020002000200020002000200020002000200020002000200020002000200020003C002F00510075006500720079003E000A0020002000200020002000200020002000200020002000200020002000200020003C002F00510075006500720079004C006900730074003E0000000000000000000000000000000000000000000000000000008888000000000000001624FBFE0700000000000000000000001624FBFE070000FFFFFFFFFFFFFFFF00000000FFFFFFFF0000000000000000000000000000000001000000000000000000000003000000FFFF000000000000001624FBFE0700000000000000000000001624FBFE070000FFFFFFFFFFFFFFFF0A000000FFFFFFFF8070000000000000000000000000000001006500720073000000000003000000
    DynamicInfo    REG_BINARY    03000000C8BDDB2C4104CA0100000000000000000000000000000000
    Hash    REG_BINARY    5F1741F0E3673AEE6B7D983CDB718C34640A8C20B8D2F627B7AA491C12F16358

HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Schedule\Taskcache\Tasks\{613612BA-897D-44CE-8DC1-8FC283F9FD51}
    Path    REG_SZ    \Microsoft\Windows\Active Directory Rights Management Services Client\AD RMS Rights Policy Template Management (Automated)
    Triggers    REG_BINARY    1500000000000000001C24FBFE0700000000000000000000001272FBFE070000FFFFFFFFFFFFFFFFC8850002484848484F482AB2484848480048484848484848004848484848484805000000484848480C00000048484848010100000000000100000000484848480000000048484848380000004848484858020000100E0000100E0000FFFFFFFF07000000000000000000000000000000000000000000000000000000000000000000000000000000DDDD000000000000011272FBFE07000000781825AB03C70100000000000000000000000000000000000000000000000000000000000000000000000000000000FFFFFFFF0100000001000000000000000001000001000000100E000000000000AAAA000000000000001C24FBFE0700000000000000000000001C24FBFE070000FFFFFFFFFFFFFFFF100E0000FFFFFFFF00000000000000000000000000000000010000000000000000000000030000000148484848484848
    DynamicInfo    REG_BINARY    030000006D72FF2C4104CA0100000000000000000000000000000000
    Hash    REG_BINARY    5FEA8C5D590E391F05DC6BF182EE76FA80BE1EC03C9F02439F1A619A1D371CBB

HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Schedule\Taskcache\Tasks\{63383B41-CD22-4AEF-B02D-D120C179FF58}
    Path    REG_SZ    \Microsoft\Windows\Setup\gwx\refreshgwxconfig
    Hash    REG_BINARY    8E3E95B1B936442EC697E14E29BCDD20D6C8E76D53F0FB402C41506433374923
    Triggers    REG_BINARY    150000000000000000FFFFFFFFFFFFFFFFFFFFFFFFFFFFFF00FFFFFFFFFFFFFF0000000000000000C021420348484848E54F2727484848480048484848484848004848484848484805000000484848480C00000048484848010100000000000512000000484848480000000048484848380000004848484800000000FFFFFFFF00000000FFFFFFFF06000000000000000000000000000000000000000000000000000000000000000000000000000000
    DynamicInfo    REG_BINARY    0300000020B408783B1AD10100000000000000000000000000000000

HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Schedule\Taskcache\Tasks\{65D42D99-7EA2-4D6A-AB62-B6EAB8D72F33}
    Path    REG_SZ    \Microsoft\Windows\Media Center\InstallPlayReady
    Triggers    REG_BINARY    150000000000000000FFFFFFFFFFFFFFFFFFFFFFFFFFFFFF00FFFFFFFFFFFFFF000000000000000000054202484848484A08CFB1484848480048484848484848004848484848484805000000484848480C000000484848480101000000000005120000004848484800000000484848480000000048484848
    DynamicInfo    REG_BINARY    03000000604DEB4901DCCA0100000000000000000000000000000000
    Hash    REG_BINARY    FA87213DE12B497A787F46A1863343D4C9578E30570573918454DF0528610310

HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Schedule\Taskcache\Tasks\{6738BA6E-EA75-4B6B-B8B8-71F0336DD8EF}
    Path    REG_SZ    \Microsoft\Windows\User Profile Service\HiveUploadTask
    Triggers    REG_BINARY    1500000000000000011272FBFE07000000406A6006E9C701001272FBFE070000FFFFFFFFFFFFFFFFC2210202484848480C2AD3B9484848480048484848484848004848484848484805000000484848480C00000048484848010100000000000512000000484848480000000048484848380000004848484858020000201C000080F40300FFFFFFFF07000000780000000300000000000000000000000000000000000000000000000000000000000000DDDD000000000000011272FBFE07000000406A6006E9C7010000000000000000000000000000000000000000000000000000000000000000C0A8000000000000FFFFFFFF0000000000000000000000000001000001000000100E000000000000
    DynamicInfo    REG_BINARY    03000000B972832E4104CA0100000000000000000000000000000000
    Hash    REG_BINARY    22735240F634AF52EB496CAC7F58E85D9ED7AF876AD31D5AE4C1F57C234E5728

HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Schedule\Taskcache\Tasks\{72DB7465-BC54-491B-A92A-4637A28C9BBF}
    Path    REG_SZ    \Microsoft\Windows\AppID\VerifiedPublisherCertStoreCheck
    Triggers    REG_BINARY    1500000000000000001624FBFE0700000000000000000000001624FBFE070000FFFFFFFFFFFFFFFF7E11020248484848218D22DB484848480048484848484848004848484848484805000000484848480C000000484848480101000000000005130000004848484800000000484848483800000048484848B40000007043010080F40300FFFFFFFF0A000000000000000000000000000000000000000000000000000000750070000000000000000000FFFF000000000000001624FBFE0700000000000000000000001624FBFE070000FFFFFFFFFFFFFFFF08070000FFFFFFFF8051010000000000000000000000000001000000000000000000000003000000
    DynamicInfo    REG_BINARY    03000000291FDE2C4104CA0100000000000000000000000000000000
    Hash    REG_BINARY    A8559F6CCCA2DF09F1225F5DCFF67D8C6FF124FC5F85DCDF7F191DC7CF13EADE

HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Schedule\Taskcache\Tasks\{753C47AE-EC5E-44B3-95A9-2C8E553F0E39}
    Path    REG_SZ    \Microsoft\Windows\Windows Media Sharing\UpdateLibrary
    Triggers    REG_BINARY    1500000000000000001624FBFE0700000000000000000000001624FBFE070000FFFFFFFFFFFFFFFF4085400248484848EC26CB6D484848480048484848484848004848484848484805000000484848480C0000004848484801010000000000050B0000004848484800000000484848480000000048484848CCCC000000000000001624FBFE0700000000000000000000001624FBFE070000FFFFFFFFFFFFFFFF00000000FFFFFFFF00000000000000000000000000000000010100000000000520000000000000001E010000000000003C00510075006500720079004C006900730074003E000A00200020002000200020002000200020002000200020002000200020003C00510075006500720079000A00200020002000200020002000200020002000200020002000200020002000200020002000490064003D002200300022000A0020002000200020002000200020002000200020002000200020002000200020002000200050006100740068003D002200530079007300740065006D0022000A002000200020002000200020002000200020002000200020002000200020002000200020003E000A0020002000200020002000200020002000200020002000200020002000200020003C00530065006C00650063007400200050006100740068003D002200530079007300740065006D0022003E002A005B00530079007300740065006D005B00500072006F00760069006400650072005B0040004E0061006D0065003D0027004D006900630072006F0073006F00660074002D00570069006E0064006F00770073002D0057004D0050004E00530053002D00530065007200760069006300650027005D00200061006E006400200028004500760065006E007400490044003D003100340032003100300029005D005D003C002F00530065006C006500630074003E000A00200020002000200020002000200020002000200020002000200020003C002F00510075006500720079003E000A002000200020002000200020002000200020002000200020003C002F00510075006500720079004C006900730074003E0000004848000000000000000000000000000000000000000000000000
    DynamicInfo    REG_BINARY    030000007A35882E4104CA0100000000000000000000000000000000
    Hash    REG_BINARY    72A5683A40FAA291AA33CC4DD71A02E9E691D7C5A7BA213B817C759F7D4E24BE

HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Schedule\Taskcache\Tasks\{7AFCC0CA-7121-422A-AB45-B0E8D599FF08}
    Path    REG_SZ    \Microsoft\Windows\CertificateServicesClient\UserTask
    Triggers    REG_BINARY    1500000000000000001C24FBFE0700000000000000000000001C24FBFE070000FFFFFFFFFFFFFFFFC085400248484848965281FA484848480048484848484848004848484848484805000000484848480C00000048484848010100000000000504000000484848480000000048484848380000004848484800000000FFFFFFFF00000000FFFFFFFF070000003C0000000500000000000000000000000000000000000000000000000000000000000000CCCC000000000000001C24FBFE0700000000000000000000001C24FBFE070000FFFFFFFFFFFFFFFF00000000FFFFFFFF0000000000000000000000000000000001010000000000052000000000000000A5000000000000003C00510075006500720079004C006900730074003E003C00510075006500720079002000490064003D00220030002200200050006100740068003D002200530079007300740065006D0022003E003C00530065006C00650063007400200050006100740068003D002200530079007300740065006D0022003E002A005B00530079007300740065006D005B00500072006F00760069006400650072005B0040004E0061006D0065003D0027004D006900630072006F0073006F00660074002D00570069006E0064006F00770073002D00470072006F007500700050006F006C0069006300790027005D00200061006E00640020004500760065006E007400490044003D0031003500300033005D005D003C002F00530065006C006500630074003E003C002F00510075006500720079003E003C002F00510075006500720079004C006900730074003E000000484848480000000000000000000000000000000000000000000000008888000000000000001624FBFE0700000000000000000000001624FBFE070000FFFFFFFFFFFFFFFF00000000FFFFFFFF0000000000000000000000000000000001000000000000000000000003000000AAAA000000000000001624FBFE0700000000000000000000001624FBFE070000FFFFFFFFFFFFFFFF00000000FFFFFFFF80700000000000000000000000000000010000000000000000000000030000000148484848484848
    DynamicInfo    REG_BINARY    030000006D72FF2C4104CA0100000000000000000000000000000000
    Hash    REG_BINARY    DB89FE61B38CF541D584C34612B856A825EF9A287779F0CCBFAA95A0183E8781

HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Schedule\Taskcache\Tasks\{7D8D2001-718E-43EA-A986-73BDD46C6B6A}
    Path    REG_SZ    \Microsoft\Windows\Media Center\mcupdate
    Triggers    REG_BINARY    150000000000000000FFFFFFFFFFFFFFFFFFFFFFFFFFFFFF00FFFFFFFFFFFFFF00000000000000006005420248484848A548697F484848480048484848484848004848484848484805000000484848480C00000048484848010100000000000514000000484848480000000048484848380000004848484800000000FFFFFFFF80F40300FFFFFFFF060000000000000000000000000000000000000000000000000000002E0045000000000000000000
    DynamicInfo    REG_BINARY    030000006005E54C01DCCA0100000000000000000000000000000000
    Hash    REG_BINARY    D23B7887DFD927FA2B59E80B7E060FA80CAAA1E83153B4053EF49F210FFA35C6

HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Schedule\Taskcache\Tasks\{7D97DDB4-6C77-450C-BA4E-FB3ED96AA490}
    Path    REG_SZ    \Microsoft\Windows\Media Center\OCURDiscovery
    Triggers    REG_BINARY    150000000000000000FFFFFFFFFFFFFFFFFFFFFFFFFFFFFF00FFFFFFFFFFFFFF000000000000000000214202484848485C36CF06484848480048484848484848004848484848484805000000484848480C000000484848480101000000000005120000004848484800000000484848480000000048484848
    DynamicInfo    REG_BINARY    03000000A0DAB54801DCCA0100000000000000000000000000000000
    Hash    REG_BINARY    1FC092677FA581A6F0D9017D0F02E74681A0DA6B0AF0EEF0E204E92D1605757A

HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Schedule\Taskcache\Tasks\{7E5A4FEF-DD93-45B9-A363-8A68B88823C2}
    Path    REG_SZ    \Microsoft\Windows\Media Center\PvrScheduleTask
    Triggers    REG_BINARY    150000000000000000FFFFFFFFFFFFFFFFFFFFFFFFFFFFFF00FFFFFFFFFFFFFF000000000000000000054202484848483A1B96C3484848480048484848484848004848484848484805000000484848480C000000484848480101000000000005140000004848484800000000484848480000000048484848
    DynamicInfo    REG_BINARY    03000000C0C9924D01DCCA0100000000000000000000000000000000
    Hash    REG_BINARY    695AC268A441273AAAC43B4C25E863C354D8400FF37237317343CD29A22A2CEF

HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Schedule\Taskcache\Tasks\{7F946C6C-5401-4324-9B15-70C5B0892EE6}
    Path    REG_SZ    \Microsoft\Windows\Setup\gwx\refreshgwxcontent
    Hash    REG_BINARY    5EB89F171FFD3C8EDDDE4FBDD5495B9F9BD4CFF24E792B010108D2832B6079FA
    Triggers    REG_BINARY    150000000000000000FFFFFFFFFFFFFFFFFFFFFFFFFFFFFF00FFFFFFFFFFFFFF0000000000000000C021420348484848CDB5BFA9484848480048484848484848004848484848484805000000484848480C00000048484848010100000000000512000000484848480000000048484848380000004848484800000000FFFFFFFF00000000FFFFFFFF06000000000000000000000000000000000000000000000000000000000000000000000000000000
    DynamicInfo    REG_BINARY    03000000E0263E793B1AD10100000000000000000000000000000000

HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Schedule\Taskcache\Tasks\{81540B9F-B5BF-47EB-9C95-BE195BF2C664}
    Path    REG_SZ    \Microsoft\Windows\NetTrace\GatherNetworkInfo
    Triggers    REG_BINARY    150000000000000000FFFFFFFFFFFFFFFFFFFFFFFFFFFFFF00FFFFFFFFFFFFFF00000000000000000085400348484848A31C713A484848480048484848484848004848484848484804000000484848481000000048484848010200000000000520000000210200000000000048484848380000004848484800000000FFFFFFFF80F40300FFFFFFFF07000000000000000000000000000000000000000000000000000000750070000000000000000000
    DynamicInfo    REG_BINARY    030000001CDF982E4104CA0100000000000000000000000000000000
    Hash    REG_BINARY    9E154171408F80E0D5CEB4D8F775758B345B3FD705AD0B3058B1732870BE807F

HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Schedule\Taskcache\Tasks\{880E621A-DD8A-497F-BED1-3311DA2C4FA1}
    Path    REG_SZ    \Microsoft\Windows\Windows Activation Technologies\ValidationTask
    Triggers    REG_BINARY    150000000000000000D331010000000080C2BFCB7929D30100D3310100000000FFFFFFFFFFFFFFFFC221C202484848480F390555484848480048484848484848004848484848484805000000484848480C0000004848484801010000000000051300000048484848000000004848484838000000484848482C010000F0200D0000000000FFFFFFFF07000000000000000000000000000000000000000000000000000000000000000000000000000000DDDD00000000000000D331010000000080C2BFCB7929D30100000000000000000000000000000000000000000000000000000000000000000000000000000000FFFFFFFF010000005A0000000000000000010000010000000000000000000000
    DynamicInfo    REG_BINARY    03000000E8C9DB9B4B2CCB0100000000000000000000000000000000
    Hash    REG_BINARY    FAFBC0BF3A62F2E5CE150BD30A2BFF584DE2C3DE87739509360E32F0F83793C9

HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Schedule\Taskcache\Tasks\{8A9251B2-FAB7-49A1-BA84-9F104776E7A7}
    Path    REG_SZ    \Microsoft\Windows\Media Center\DispatchRecoveryTasks
    Triggers    REG_BINARY    150000000000000000FFFFFFFFFFFFFFFFFFFFFFFFFFFFFF00FFFFFFFFFFFFFF00000000000000000805420248484848F616133B484848480048484848484848004848484848484805000000484848480C00000048484848010100000000000512000000484848480000000048484848380000004848484800000000FFFFFFFF80F40300FFFFFFFF07000000000000000000000000000000000000000000000000000000000000000000000000000000
    DynamicInfo    REG_BINARY    03000000C0F05F4A01DCCA0100000000000000000000000000000000
    Hash    REG_BINARY    8DF1277ABA0042B7C7EB16962614C447A3CE1446BD29473CE630657F25F00AA9

HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Schedule\Taskcache\Tasks\{8BDF0314-A8E0-4A71-9E60-0F7C1739DE56}
    Path    REG_SZ    \Microsoft\Windows\SideShow\SystemDataProviders
    Triggers    REG_BINARY    1500000000000000000000000000000000000000000000000000000000000000FFFFFFFFFFFFFFFF002102024848484888275990484848480048484848484848004848484848484805000000484848480C00000048484848010100000000000513000000484848480000000048484848380000004848484800000000FFFFFFFF00000000FFFFFFFF07000000000000000000000000000000000000000000000000000000200020000000000000000000AAAA000000000000000000000000000000000000000000000000000000000000FFFFFFFFFFFFFFFF1E000000FFFFFFFF0000000000000000000000000000000001729D010000000005000000000000000148484848484848
    DynamicInfo    REG_BINARY    03000000C0599F4701DCCA0100000000000000000000000000000000
    Hash    REG_BINARY    8DFB2AAA49E262BC3CA3901D44152079D55567AAA637743E01E34DF36A5FB4C7

HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Schedule\Taskcache\Tasks\{92771DAF-0E34-4CC5-9653-7A6E793544E5}
    Path    REG_SZ    \CCleanerSkipUAC
    Hash    REG_BINARY    52DB621C8F667ECC9A412ECA970868065966AB48642819D8A8EA05C0FB01E9F7
    Triggers    REG_BINARY    15000000000000000009000000000000FFFFFFFFFFFFFFFF000900000000000000000000000000000805410148484848022B4C0A484848480048484848484848004848484848484801000000484848481C0000004848484801050000000000051500000092B8DC2EB2B4B4A8316AA1B3E8030000484848481A0000004848484854006F006D0052002D00500043005C0054006F006D0052000000484848484848380000004848484800000000FFFFFFFF80F40300FFFFFFFF07000000000000000000000000000000000000000000000000000000000000000000000000000000
    DynamicInfo    REG_BINARY    030000000000000000000000200CCB731C21D3010000000000000000

HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Schedule\Taskcache\Tasks\{9435F817-FED2-454E-88CD-7F78FDA62C48}
    Path    REG_SZ    \Microsoft\Windows\WDI\ResolutionHost
    Triggers    REG_BINARY    150000000000000000FFFFFFFFFFFFFFFFFFFFFFFFFFFFFF00FFFFFFFFFFFFFF00000000000000000085C003484848489D84F470484848480048484848484848004848484848484805000000484848480C00000048484848010100000000000504000000484848480000000048484848380000004848484800000000FFFFFFFF00000000FFFFFFFF0A000000000000000000000000000000000000000000000000000000750070000000000000000000
    DynamicInfo    REG_BINARY    030000007C409B2E4104CA0100000000000000000000000000000000
    Hash    REG_BINARY    7678F283CD528277951D5955D00319DC3E404F5D6AD8E0806B80DC781E7181CA

HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Schedule\Taskcache\Tasks\{994C86AD-A929-4B2C-88A0-4E25A107A029}
    Path    REG_SZ    \Microsoft\Windows\SystemRestore\SR
    Triggers    REG_BINARY    1500000000000000001C24FBFE0700000000000000000000001272FBFE070000FFFFFFFFFFFFFFFF5221420248484848EDD0741F484848480048484848484848004848484848484805000000484848480C000000484848480101000000000005120000004848484800000000484848483800000048484848580200007043010080F40300FFFFFFFF07000000000000000000000000000000000000000000000000000000220020000000000000000000DDDD000000000000011272FBFE0700000080E1017470C50100000000000000000000000000000000000000000000000000000000000000000000000000000000FFFFFFFF01000000010000000000000000010000010000000000000000000000FFFF000000000000001C24FBFE0700000000000000000000001C24FBFE070000FFFFFFFFFFFFFFFF08070000FFFFFFFF0000000000000000000000000000000001000000000000000000000003000000
    DynamicInfo    REG_BINARY    03000000E9E1E22C4104CA0100000000000000000000000000000000
    Hash    REG_BINARY    A2281A82814B04BF0AE2441991C482C4859EA3BFF19E695D72CDF0B8E25A481C

HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Schedule\Taskcache\Tasks\{9979CB83-103A-4105-9E5D-C74B0AF6D198}
    Path    REG_SZ    \Microsoft\Windows\CertificateServicesClient\UserTask-Roam
    Triggers    REG_BINARY    1500000000000000000000000000000000000000000000000000000000000000FFFFFFFFFFFFFFFF908500024848484824A4C7D0484848480048484848484848004848484848484805000000484848480C00000048484848010100000000000504000000484848480000000048484848380000004848484800000000FFFFFFFF00000000FFFFFFFF070000003C00000005000000000000000000000000000000000000000000000000000000000000007777000000000000000000000000000000000000000000000000000000000000FFFFFFFFFFFFFFFF00000000FFFFFFFF0000000000000000000000000000000001FFFFFF020000000100100000000000070000000000000001484848484848487777000000000000000000000000000000000000000000000000000000000000FFFFFFFFFFFFFFFF00000000FFFFFFFF0000000000000000000000000000000001665300000000000000000000000000080000008573C0010148484848484848
    DynamicInfo    REG_BINARY    03000000DCA19D2E4104CA0100000000000000000000000000000000
    Hash    REG_BINARY    F2CE6AB8C22DCF1780141867455A46FA6D08F08C5B5D482002372E5FDE059B43

HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Schedule\Taskcache\Tasks\{A35BB7A6-5F0C-4C9F-8450-2B3BED532D51}
    Path    REG_SZ    \Microsoft\Windows\WindowsColorSystem\Calibration Loader
    Triggers    REG_BINARY    1500000000000000000000000000000000000000000000000000000000000000FFFFFFFFFFFFFFFF0091000248484848A34B56BE484848480048484848484848004848484848484804000000484848481000000048484848010200000000000520000000210200000000000048484848380000004848484800000000FFFFFFFF00000000FFFFFFFF07000000000000000000000000000000000000000000000000000000750070000000000000000000AAAA000000000000000000000000000000000000000000000000000000000000FFFFFFFFFFFFFFFF00000000FFFFFFFF00000000000000000000000000000000010041003B003B003B0042004100290001484848484848487777000000000000000000000000000000000000000000000000000000000000FFFFFFFFFFFFFFFF00000000FFFFFFFF0000000000000000000000000000000001002D0065006E00650072006700790001000000000070000148484848484848
    DynamicInfo    REG_BINARY    03000000CDD3012D4104CA0100000000000000000000000000000000
    Hash    REG_BINARY    1C5E72CB821B89108191AC5B7FD3157B5CCE0474EDD44C9D1CEC819787F288AB

HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Schedule\Taskcache\Tasks\{A48CABBF-24C8-4B87-B00F-9261807C3B43}
    Path    REG_SZ    \Microsoft\Windows\AppID\PolicyConverter
    Triggers    REG_BINARY    150000000000000000FFFFFFFFFFFFFFFFFFFFFFFFFFFFFF00FFFFFFFFFFFFFF000000000000000040110202484848483498017A484848480048484848484848004848484848484805000000484848480C000000484848480101000000000005130000004848484800000000484848480000000048484848
    DynamicInfo    REG_BINARY    03000000D6017B2F4104CA0100000000000000000000000000000000
    Hash    REG_BINARY    C645BB8F8D8C5DE3EA7A893D785BD95FC06FA4D7810745FE4E78E392009FFFB8

HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Schedule\Taskcache\Tasks\{A6AF9377-77CE-47AB-AD7D-EC32CAD0C82D}
    Path    REG_SZ    \Microsoft\Windows\Location\Notifications
    Triggers    REG_BINARY    1500000000000000001624FBFE0700000000000000000000001624FBFE070000FFFFFFFFFFFFFFFF0085400248484848DFDD7976484848480048484848484848004848484848484805000000484848480C0000004848484801010000000000050B000000484848480000000048484848380000004848484800000000FFFFFFFF00000000FFFFFFFF07000000000000000000000000000000000000000000000000000000000000000000000000000000CCCC000000000000001624FBFE0700000000000000000000001624FBFE070000FFFFFFFFFFFFFFFF00000000FFFFFFFF0000000000000000000000000000000001010000000000052000000000000000A4000000000000003C00510075006500720079004C006900730074003E003C00510075006500720079002000490064003D00220030002200200050006100740068003D0022004100700070006C00690063006100740069006F006E0022003E003C00530065006C00650063007400200050006100740068003D0022004100700070006C00690063006100740069006F006E0022003E002A005B00530079007300740065006D005B00500072006F00760069006400650072005B0040004E0061006D0065003D0027004C006F0063006100740069006F006E004E006F00740069006600690063006100740069006F006E00730027005D00200061006E00640020004500760065006E007400490044003D0031005D005D003C002F00530065006C006500630074003E003C002F00510075006500720079003E003C002F00510075006500720079004C006900730074003E000000484848484848000000000000000000000000000000000000000000000000
    DynamicInfo    REG_BINARY    03000000D6017B2F4104CA0100000000000000000000000000000000
    Hash    REG_BINARY    E2EEC5DC638B16A8DCF4E83A3514F28DC7FFB5CA04854176D252D9095C29B343

HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Schedule\Taskcache\Tasks\{AC4E5ACF-89F7-4220-BA21-81EE183975E2}
    Path    REG_SZ    \Microsoft\Windows\Application Experience\AitAgent
    Triggers    REG_BINARY    1500000000000000011272FBFE0700000004C51F5309C801001272FBFE070000FFFFFFFFFFFFFFFF7E214202484848482774D537484848480048484848484848004848484848484805000000484848480C000000484848480101000000000005120000004848484800000000484848483800000048484848B40000006035010080F40300FFFFFFFF09000000000000000000000000000000000000000000000000000000000000000000000000000000DDDD000000000000011272FBFE0700000004C51F5309C80100000000000000000000000000000000000000000000000000000000000000000000000000000000FFFFFFFF01000000010000000000000000010000010000000000000000000000
    DynamicInfo    REG_BINARY    030000005787842F4104CA0100000000000000000000000000000000
    Hash    REG_BINARY    9A13FF7FB54C9212AAC3663AEE2889A6AFB0BA6898ABC3F9A811E6216987B833

HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Schedule\Taskcache\Tasks\{AC668097-4D6B-4093-AC14-014C09DBF820}
    Path    REG_SZ    \Microsoft\Windows\Ras\MobilityManager
    Triggers    REG_BINARY    1500000000000000001624FBFE0700000000000000000000001624FBFE070000FFFFFFFFFFFFFFFF40054202484848484716FF88484848480048484848484848004848484848484805000000484848480C000000484848480101000000000005130000004848484800000000484848480000000048484848CCCC000000000000001624FBFE0700000000000000000000001624FBFE070000FFFFFFFFFFFFFFFF00000000FFFFFFFF00000000000000000000000000000000010100000000000520000000000000002A010000000000003C00510075006500720079004C006900730074003E000A00200020002000200020002000200020002000200020002000200020003C00510075006500720079000A00200020002000200020002000200020002000200020002000200020002000200020002000490064003D002200300022000A0020002000200020002000200020002000200020002000200020002000200020002000200050006100740068003D0022004100700070006C00690063006100740069006F006E0022000A002000200020002000200020002000200020002000200020002000200020002000200020003E000A0020002000200020002000200020002000200020002000200020002000200020003C00530065006C00650063007400200050006100740068003D0022004100700070006C00690063006100740069006F006E0022003E002A005B00530079007300740065006D005B00500072006F00760069006400650072005B0040004E0061006D0065003D00270052006100730043006C00690065006E00740027005D00200061006E006400200028004C006500760065006C003D00340020006F00720020004C006500760065006C003D0030002900200061006E006400200028004500760065006E007400490044003D003200300032003800310029005D005D003C002F00530065006C006500630074003E000A00200020002000200020002000200020002000200020002000200020003C002F00510075006500720079003E000A002000200020002000200020002000200020002000200020003C002F00510075006500720079004C006900730074003E0000004848000000000000000000000000000000000000000000000000
    DynamicInfo    REG_BINARY    0300000098CF922F4104CA0100000000000000000000000000000000
    Hash    REG_BINARY    472F2F6E40D88458D92B946C81BA9225D63C0BD045FBAB63CAEF1904BC35BA73

HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Schedule\Taskcache\Tasks\{AEA35300-8D3F-4FFA-9243-5072A3D37166}
    Path    REG_SZ    \Microsoft\Windows\Offline Files\Logon Synchronization
    Triggers    REG_BINARY    1500000000000000000000000000000000000000000000000000000000000000FFFFFFFFFFFFFFFFF0A1000248484848532B4026484848480048484848484848004848484848484805000000484848480C0000004848484801010000000000050B000000484848480000000048484848380000004848484800000000FFFFFFFF80510100FFFFFFFF07000000000000000000000000000000000000000000000000000000200020000000000000000000AAAA000000000000000000000000000000000000000000000000000000000000FFFFFFFFFFFFFFFFF0000000FFFFFFFF00000000000000000000000000000000017261010000000005000000000000000148484848484848
    DynamicInfo    REG_BINARY    03000000A0506F4E1B2DCB0100000000000000000000000000000000
    Hash    REG_BINARY    6576A98588179A08B31C3D3999726FCF3761698BAAA53EC77A03A35E4108207A

HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Schedule\Taskcache\Tasks\{AF0E8862-B404-45B1-990F-A877CA74DB66}
    Path    REG_SZ    \Microsoft\Windows\Defrag\ScheduledDefrag
    Triggers    REG_BINARY    15000000000000000155E30100000000002872589541CB010055E30100000000FFFFFFFFFFFFFFFF7E214203484848481D68D4C0484848480048484848484848004848484848484805000000484848480C000000484848480101000000000005120000004848484800000000484848483800000048484848B4000000803A090080F40300FFFFFFFF07000000000000000000000000000000000000000000000000000000000000000000000000000000DDDD0000000000000155E30100000000002872589541CB0100000000000000000000000000000000000000000000000000000000000000000000000000000000FFFFFFFF02000000010008000000000000000000010000000000000000000000
    DynamicInfo    REG_BINARY    03000000E01293C53142CB0100000000000000000000000000000000
    Hash    REG_BINARY    FFF8896FE7EB448041E250147044839512AA48E312487CA47813AC6A94C4314C

HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Schedule\Taskcache\Tasks\{B0CBAB43-44FC-469B-A4CE-87426761FDCE}
    Path    REG_SZ    \Microsoft\Windows\PerfTrack\BackgroundConfigSurveyor
    Triggers    REG_BINARY    1500000000000000001C24FBFE0700000000000000000000001C24FBFE070000FFFFFFFFFFFFFFFF102182024848484803D61589484848480048484848484848004848484848484805000000484848480C000000484848480101000000000005130000004848484800000000484848480000000048484848EEEE000000000000001C24FBFE0700000000000000000000001C24FBFE070000FFFFFFFFFFFFFFFF00000000FFFFFFFF0000000000000000000000000000000001000000000000000000000003000000DDDD000000000000011272FBFE0700000078BA3F01C2C80100000000000000000000000000000000000000000000000000000000000000000000000000000000FFFFFFFF01000000010000000000000000010000010000000000000000000000
    DynamicInfo    REG_BINARY    03000000F930952F4104CA0100000000000000000000000000000000
    Hash    REG_BINARY    8A4BC3FB22E943EDE5A98456CCAF3453D4DDD613D1A3265017967ABC8C779E7D

HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Schedule\Taskcache\Tasks\{B5300C80-1852-4740-8577-DAD20107477F}
    Path    REG_SZ    \Microsoft\Windows\Media Center\PBDADiscoveryW1
    Triggers    REG_BINARY    150000000000000000FFFFFFFFFFFFFFFFFFFFFFFFFFFFFF00FFFFFFFFFFFFFF0000000000000000400542024848484820231FCE484848480048484848484848004848484848484805000000484848480C00000048484848010100000000000512000000484848480000000048484848380000004848484800000000FFFFFFFF100E0000FFFFFFFF07000000000000000000000000000000000000000000000000000000000000000000000000000000
    DynamicInfo    REG_BINARY    03000000009C194B01DCCA0100000000000000000000000000000000
    Hash    REG_BINARY    ED6C3AF77BC32514D0E4A46115FB377242E60FDE46F8FF3785AF624B20462691

HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Schedule\Taskcache\Tasks\{B96F52BC-A937-4670-8F16-886CE14EAD84}
    Path    REG_SZ    \Norton Internet Security\Norton Error Processor
    Hash    REG_BINARY    015A2CB8F9F9008E67D4301DE8CD262D2845B1DB5F70052D64F1E6806900117E
    Triggers    REG_BINARY    150000000000000000D799010000000000406D25EB53BF0100D79901000000000000647763712F0212214201484848481B1BCC84484848480048484848484848004848484848484805000000484848480C0000004848484801010000000000051200000048484848000000004848484838000000484848482C0100008033E10180F40300FFFFFFFF07000000000000000000000000000000000000000000000000000000000000000000000000000000DDDD00000000000000D799010000000000406D25EB53BF0100D79901000000000000647763712F02000000000000000000000000000000000000000000000000FFFFFFFF01000000010000000000000000010000010000008070000000000000
    DynamicInfo    REG_BINARY    03000000000B2B393462D001B0AC80950C4DD2012513040000000000

HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Schedule\Taskcache\Tasks\{BE669C13-8165-4536-96D0-6D6C39292AAE}
    Path    REG_SZ    \Microsoft\Windows\Diagnosis\Scheduled
    Triggers    REG_BINARY    1500000000000000011272FBFE0700000068B69402D0C301001272FBFE070000FFFFFFFFFFFFFFFF7289C00348484848AB8C36E4484848480048484848484848004848484848484805000000484848480C000000484848480101000000000005040000004848484800000000484848483800000048484848580200008070000080F40300FFFFFFFF07000000000000000000000000000000000000000000000000000000000000000000000000000000DDDD000000000000011272FBFE0700000068B69402D0C30100000000000000000000000000000000000000000000000000000000000000000000000000000000FFFFFFFF02000000010001000000000000010000010000000000000000000000
    DynamicInfo    REG_BINARY    03000000419ADC2F4104CA0100000000000000000000000000000000
    Hash    REG_BINARY    82EBD60108500FCD357BF28CCE5952EFB6FF943B38E8250A3AF34507C6162FAE

HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Schedule\Taskcache\Tasks\{C016366B-7126-46CA-B36B-592A3D95A60B}
    Path    REG_SZ    \Microsoft\Windows\Customer Experience Improvement Program\Consolidator
    Triggers    REG_BINARY    1500000000000000011272FBFE07000000C05B5DC3D0C301001272FBFE070000FFFFFFFFFFFFFFFF4021420248484848F3FE730B484848480048484848484848004848484848484805000000484848480C000000484848480101000000000005120000004848484800000000484848480000000048484848DDDD000000000000011272FBFE07000000C05B5DC3D0C3010000000000000000000000000000000000000000000000000000000000000000300B010000000000FFFFFFFF00000000000000000000000000010000010000000000000000000000
    DynamicInfo    REG_BINARY    03000000025DE12F4104CA0100000000000000000000000000000000
    Hash    REG_BINARY    555CD377BA0A0532A5630EBE96AE9DB1843E642B2A15BA07C40C8B67BE00E87F

HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Schedule\Taskcache\Tasks\{C27A0E7B-742B-4454-804E-44F3C2A92FCF}
    Path    REG_SZ    \Microsoft\Windows\Media Center\MediaCenterRecoveryTask
    Triggers    REG_BINARY    150000000000000000FFFFFFFFFFFFFFFFFFFFFFFFFFFFFF00FFFFFFFFFFFFFF0000000000000000000542024848484868DEB374484848480048484848484848004848484848484805000000484848480C000000484848480101000000000005120000004848484800000000484848480000000048484848
    DynamicInfo    REG_BINARY    030000004065C24D01DCCA0100000000000000000000000000000000
    Hash    REG_BINARY    EB514214B7FD8BCDF44B13E01117537348E099E5CC33A15A470C6C60FE50467D

HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Schedule\Taskcache\Tasks\{CA1C7F50-8959-4447-8A43-9AC256B76669}
    Path    REG_SZ    \Adobe Acrobat Update Task
    Hash    REG_BINARY    AB50DD7D6186360935326C8FC6DB5BAE6FA03211F389064705FB9A95F8CF6D17
    Triggers    REG_BINARY    150000000000000001D4B101000000000070C63BE5E7CD0101D4B1010000000000BE485FFDF8DD0178A1400048484848F1A2BF41484848480048484848484848004848484848484805000000484848480C00000048484848010100000000000504000000484848480000000048484848380000004848484858020000100E000080F40300FFFFFFFF07000000000000000000000000000000000000000000000000000000000000000000000000000000AAAA00000000000001D4B10100000000003EC458AF8ECE0101D4B1010000000000C06625DBF8DD01D0020000FFFFFFFF3831000000000000000000000000000001006900630065003A000000000000000148484848484848DDDD00000000000001D4B101000000000070C63BE5E7CD0101D4B1010000000000BE485FFDF8DD01000000000000000000000000000000000000000000000000FFFFFFFF01000000010000000000000000010000010000000000000000000000
    DynamicInfo    REG_BINARY    0300000010EBEFD8FB10D30100BB3A177A21D3010000000000000000

HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Schedule\Taskcache\Tasks\{CA4B8FF2-A4D2-4D88-A52E-3A5BDAF7F56E}
    Path    REG_SZ    \Microsoft\Windows\Registry\RegIdleBackup
    Triggers    REG_BINARY    1500000000000000011272FBFE07000000C07640094CC801001272FBFE070000FFFFFFFFFFFFFFFF4E20C20248484848C7925C29484848480048484848484848004848484848484805000000484848480C000000484848480101000000000005120000004848484800000000484848483800000048484848B40000007043010000000000FFFFFFFF05000000000000000000000000000000000000000000000000000000750070000000000000000000DDDD000000000000011272FBFE07000000C07640094CC80100000000000000000000000000000000000000000000000000000000000000000000000000000000FFFFFFFF010000000A000000000000000001000001000000100E000000000000
    DynamicInfo    REG_BINARY    03000000A81C18304104CA0100000000000000000000000000000000
    Hash    REG_BINARY    AE0DB2F31A30B208E0C50EF64C29948A828612AC605CA8F6B3E42F51EA6C09E1

HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Schedule\Taskcache\Tasks\{CB3D64BF-C0C9-45FF-BFB0-FF1A8F680186}
    Path    REG_SZ    \Microsoft\Windows\RemoteAssistance\RemoteAssistanceTask
    Triggers    REG_BINARY    1500000000000000001C24FBFE0700000000000000000000001C24FBFE070000FFFFFFFFFFFFFFFF2811C2034848484866D894B3484848480048484848484848004848484848484805000000484848480C00000048484848010100000000000512000000484848480000000048484848380000004848484858020000100E000080F40300FFFFFFFF0700000000000000000000000000000000000000000000000000000022436F6C0000000000000000CCCC000000000000001C24FBFE0700000000000000000000001C24FBFE070000FFFFFFFFFFFFFFFF0F000000FFFFFFFF0000000000000000000000000000000001010000000000052000000000000000A5000000000000003C00510075006500720079004C006900730074003E003C00510075006500720079002000490064003D00220030002200200050006100740068003D002200530079007300740065006D0022003E003C00530065006C00650063007400200050006100740068003D002200530079007300740065006D0022003E002A005B00530079007300740065006D005B00500072006F00760069006400650072005B0040004E0061006D0065003D0027004D006900630072006F0073006F00660074002D00570069006E0064006F00770073002D00470072006F007500700050006F006C0069006300790027005D00200061006E00640020004500760065006E007400490044003D0031003500300032005D005D003C002F00530065006C006500630074003E003C002F00510075006500720079003E003C002F00510075006500720079004C006900730074003E000000484848480000000000000000000000000000000000000000000000008888000000000000001624FBFE0700000000000000000000001624FBFE070000FFFFFFFFFFFFFFFF00000000FFFFFFFF0000000000000000000000000000000001000000000000000000000003000000
    DynamicInfo    REG_BINARY    03000000087E1A304104CA0100000000000000000000000000000000
    Hash    REG_BINARY    40F4A1B4CBF346720B7A186AAE912FCEA1FBE0DD82F48F51FCB9AD1A76BF2525

HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Schedule\Taskcache\Tasks\{CBC80253-50BE-47AF-81EA-A8816005ABE4}
    Path    REG_SZ    \Microsoft\Windows\SideShow\GadgetManager
    Triggers    REG_BINARY    1500000000000000000000000000000000000000000000000000000000000000FFFFFFFFFFFFFFFF009140024848484863DEF7F2484848480048484848484848004848484848484804000000484848481000000048484848010200000000000520000000210200000000000048484848380000004848484800000000FFFFFFFF80F40300FFFFFFFF07000000000000000000000000000000000000000000000000000000000000000000000000000000AAAA000000000000000000000000000000000000000000000000000000000000FFFFFFFFFFFFFFFF00000000FFFFFFFF00000000000000000000000000000000000078010000000005000000000000000148484848484848
    DynamicInfo    REG_BINARY    030000006045224801DCCA0100000000000000000000000000000000
    Hash    REG_BINARY    2B16A83D35908A64E898F2743328C16CBC44DE6C67AF392D6B0F19AE00829A72

HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Schedule\Taskcache\Tasks\{CC459BF8-7D00-4831-99CC-FE735B19F74A}
    Path    REG_SZ    \Microsoft\Windows\Media Center\UpdateRecordPath
    Triggers    REG_BINARY    150000000000000000FFFFFFFFFFFFFFFFFFFFFFFFFFFFFF00FFFFFFFFFFFFFF000000000000000000214202484848482E977B9B484848480048484848484848004848484848484805000000484848480C000000484848480101000000000005120000004848484800000000484848480000000048484848
    DynamicInfo    REG_BINARY    030000006000664901DCCA0100000000000000000000000000000000
    Hash    REG_BINARY    EB28225E5ADAD1323F85643ABEC315B0F6F9F15D232F4DA9D56085F77D31388C

HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Schedule\Taskcache\Tasks\{CEE64558-E1A7-4D9D-80A7-2001912BE5B5}
    Path    REG_SZ    \Microsoft\Windows\MemoryDiagnostic\CorruptionDetector
    Triggers    REG_BINARY    1500000000000000001C24FBFE0700000000000000000000001C24FBFE070000FFFFFFFFFFFFFFFF00A0C00248484848F1D7B9294848484800484848484848480048484848484848040000004848484810000000484848480102000000000005200000002102000000000000484848480000000048484848CCCC000000000000001C24FBFE0700000000000000000000001C24FBFE070000FFFFFFFFFFFFFFFF00000000FFFFFFFF000000000000000000000000000000000101000000000005200000000000000099000000000000003C00510075006500720079004C006900730074003E003C00510075006500720079002000490064003D00220030002200200050006100740068003D002200530079007300740065006D0022003E003C00530065006C00650063007400200050006100740068003D002200530079007300740065006D0022003E002A005B00530079007300740065006D005B00500072006F00760069006400650072005B0040004E0061006D0065003D0027004100700070006C00690063006100740069006F006E00200050006F0070007500700027005D00200061006E00640020004500760065006E007400490044003D0031003800300031005D005D003C002F00530065006C006500630074003E003C002F00510075006500720079003E003C002F00510075006500720079004C006900730074003E00000048484848000000000000000000000000000000000000000000000000
    DynamicInfo    REG_BINARY    0300000068DF1C304104CA0100000000000000000000000000000000
    Hash    REG_BINARY    39D0B04F356DF6650E076076255CE26CE27591428740C759241D2B1AEE37F612

HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Schedule\Taskcache\Tasks\{D0250F3F-6480-484F-B719-42F659AC64D5}
    Path    REG_SZ    \Microsoft\Windows\Windows Error Reporting\QueueReporting
    Triggers    REG_BINARY    1500000000000000001624FBFE0700000000000000000000001624FBFE070000FFFFFFFFFFFFFFFF40854002484848488A154A60484848480048484848484848004848484848484804000000484848481000000048484848010200000000000520000000210200000000000048484848380000004848484800000000FFFFFFFF80F40300FFFFFFFF05000000000000000000000000000000000000000000000000000000750070000000000000000000AAAA000000000000001624FBFE0700000000000000000000001624FBFE070000FFFFFFFFFFFFFFFF0C030000FFFFFFFF00000000000000000000000000000000010000000000000000000000030000000148484848484848
    DynamicInfo    REG_BINARY    030000002D35042D4104CA0100000000000000000000000000000000
    Hash    REG_BINARY    6EB7D50A0F0E813EF39052146B2AB58692ED68D82E0E8E733043ECC9334D16D1

HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Schedule\Taskcache\Tasks\{D1BC44FB-2193-40BF-AA4A-2E96D31F2BCE}
    Path    REG_SZ    \Microsoft\Windows\Media Center\ReindexSearchRoot
    Triggers    REG_BINARY    150000000000000000FFFFFFFFFFFFFFFFFFFFFFFFFFFFFF00FFFFFFFFFFFFFF00000000000000000021420248484848E17CF563484848480048484848484848004848484848484805000000484848480C000000484848480101000000000005120000004848484800000000484848480000000048484848
    DynamicInfo    REG_BINARY    030000006063114A01DCCA0100000000000000000000000000000000
    Hash    REG_BINARY    59500DAC2B3DF24DD8EBD096B081796CE15A4D699DE7F05B53C249612F21A974

HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Schedule\Taskcache\Tasks\{D378D375-CAC7-474F-8B4B-82FF8391E306}
    Path    REG_SZ    \Microsoft\Windows\Offline Files\Background Synchronization
    Triggers    REG_BINARY    1500000000000000016161010000000000C07640094CC8010061610100000000FFFFFFFFFFFFFFFFC0A10002484848481DE0FDD6484848480048484848484848004848484848484805000000484848480C0000004848484801010000000000050B000000484848480000000048484848380000004848484800000000FFFFFFFF80510100FFFFFFFF07000000000000000000000000000000000000000000000000000000640054000000000000000000DDDD000000000000016161010000000000C07640094CC80100000000000000000000000000000000000000000000000000000000000000006054000000000000FFFFFFFF0000000000000000000000000001000001000000100E000000000000
    DynamicInfo    REG_BINARY    0300000060F23A4E1B2DCB0100000000000000000000000000000000
    Hash    REG_BINARY    064E0B6C6170312965A1E23D7EE00BE494DA87892966284973711A6BDB4E0676

HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Schedule\Taskcache\Tasks\{D566BF98-A96D-49E6-B8C7-DD9C73666437}
    Path    REG_SZ    \Microsoft\Windows\DiskDiagnostic\Microsoft-Windows-DiskDiagnosticResolver
    Triggers    REG_BINARY    1500000000000000000000000000000000000000000000000000000000000000FFFFFFFFFFFFFFFF00858003484848481FCACD844848484800484848484848480048484848484848040000004848484810000000484848480102000000000005200000002102000000000000484848480000000048484848AAAA000000000000000000000000000000000000000000000000000000000000FFFFFFFFFFFFFFFF00000000FFFFFFFF00000000000000000000000000000000010078010000000005000000000000000148484848484848
    DynamicInfo    REG_BINARY    030000000076614701DCCA0100000000000000000000000000000000
    Hash    REG_BINARY    AC67DF7A4B9D1C8713C2D62FD8685113FB7749DE03811F77BBC4B4B06B74C2DA

HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Schedule\Taskcache\Tasks\{D7B6E81D-3CF4-432C-84D2-24213F4316E6}
    Path    REG_SZ    \Microsoft\Windows\Autochk\Proxy
    Triggers    REG_BINARY    1500000000000000001C24FBFE0700000000000000000000001C24FBFE070000FFFFFFFFFFFFFFFF4221420248484848B1B1AB59484848480048484848484848004848484848484805000000484848480C000000484848480101000000000005130000004848484800000000484848483800000048484848580200008033E10180F40300FFFFFFFF07000000000000000000000000000000000000000000000000000000000000000000000000000000FFFF000000000000001C24FBFE0700000000000000000000001C24FBFE070000FFFFFFFFFFFFFFFF08070000FFFFFFFF0000000000000000000000000000000001000000000000000000000003000000
    DynamicInfo    REG_BINARY    030000004A43E52C4104CA0100000000000000000000000000000000
    Hash    REG_BINARY    02E603F0F0B98221F070DD81A88B3DB67CE5DA315BC568423732F9EED15F3F79

HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Schedule\Taskcache\Tasks\{DA41DE71-8431-42FB-9DB0-EB64A961DEAD}
    Path    REG_SZ    \Microsoft\Windows\Maintenance\WinSAT
    Triggers    REG_BINARY    15000000000000000155B7010000000000283BA2114CC8010055B70100000000FFFFFFFFFFFFFFFF3AA1400348484848FD6ADDD0484848480048484848484848004848484848484804000000484848481000000048484848010200000000000520000000200200000000000048484848380000004848484800000000FFFFFFFF00000000FFFFFFFF07000000000000000000000000000000000000000000000000000000000000000000000000000000DDDD0000000000000155B7010000000000283BA2114CC80100000000000000000000000000000000000000000000000000000000000000000000000000000000FFFFFFFF02000000010001000000000000010000010000000000000000000000
    DynamicInfo    REG_BINARY    03000000C9401F304104CA0100000000000000000000000000000000
    Hash    REG_BINARY    66794E5D90FD8C6C013FA7BD65E976C09D408DBAC86B91069E6956EDBE709681

HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Schedule\Taskcache\Tasks\{DBABD243-12BD-48BF-AB79-4661514DB486}
    Path    REG_SZ    \Microsoft\Windows\Media Center\PBDADiscoveryW2
    Triggers    REG_BINARY    150000000000000000FFFFFFFFFFFFFFFFFFFFFFFFFFFFFF00FFFFFFFFFFFFFF00000000000000004005420248484848215727BB484848480048484848484848004848484848484805000000484848480C00000048484848010100000000000512000000484848480000000048484848380000004848484800000000FFFFFFFF100E0000FFFFFFFF07000000000000000000000000000000000000000000000000000000000000000000000000000000
    DynamicInfo    REG_BINARY    030000006013424B01DCCA0100000000000000000000000000000000
    Hash    REG_BINARY    D2B529269E9CD0C8E777506B13CBC3B9EC133ADCFA2160D03B795663C6D14D51

HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Schedule\Taskcache\Tasks\{DD9F510C-95F4-499A-90C8-BAC5BC372FF4}
    Path    REG_SZ    \Microsoft\Windows\SoftwareProtectionPlatform\SvcRestartTask
    Triggers    REG_BINARY    1500000000000000011272FBFE0700000000F232FACFC301001272FBFE070000FFFFFFFFFFFFFFFF4021820248484848217B8E98484848480048484848484848004848484848484805000000484848480C00000048484848010100000000000514000000484848480000000048484848380000004848484800000000FFFFFFFF00000000FFFFFFFF070000003C0000000300000000000000000000000000000000000000000000000000000000000000DDDD000000000000011272FBFE0700000000F232FACFC30100000000000000000000000000000000000000000000000000000000000000000000000000000000FFFFFFFF01000000010000000000000000010000010000000000000000000000
    DynamicInfo    REG_BINARY    0300000029A221304104CA0100000000000000000000000000000000
    Hash    REG_BINARY    FD59AA8FA7E6D6C681945135C99BCEAC82F3DB23B037253C8DAD1617F5C5E425

HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Schedule\Taskcache\Tasks\{E22A8667-F75B-4BA9-BA46-067ED4429DE8}
    Path    REG_SZ    \Microsoft\Windows\Windows Filtering Platform\BfeOnServiceStartTypeChange
    Triggers    REG_BINARY    1500000000000000001C24FBFE0700000000000000000000001C24FBFE070000FFFFFFFFFFFFFFFF0010C20248484848170F4F6E484848480048484848484848004848484848484805000000484848480C00000048484848010100000000000512000000484848480000000048484848380000004848484800000000FFFFFFFF80F40300FFFFFFFF07000000000000000000000000000000000000000000000000000000000000000000000000000000CCCC000000000000001C24FBFE0700000000000000000000001C24FBFE070000FFFFFFFFFFFFFFFF00000000FFFFFFFF0000000000000000000000000000000001010000000000052000000000000000D3000000000000003C00510075006500720079004C006900730074003E003C00510075006500720079002000490064003D00220030002200200050006100740068003D002200530079007300740065006D0022003E003C00530065006C00650063007400200050006100740068003D002200530079007300740065006D0022003E002A002F00530079007300740065006D002F00500072006F00760069006400650072005B0040004E0061006D0065003D0027005300650072007600690063006500200043006F006E00740072006F006C0020004D0061006E00610067006500720027005D00200061006E00640020002A002F00530079007300740065006D002F004500760065006E007400490044003D00270037003000340030002700200061006E00640020002A002F004500760065006E00740044006100740061002F0044006100740061005B0040004E0061006D0065003D00270070006100720061006D00340027005D003D00270042004600450027003C002F00530065006C006500630074003E003C002F00510075006500720079003E003C002F00510075006500720079004C006900730074003E000000000000000000000000000000000000000000000000000000
    DynamicInfo    REG_BINARY    0300000029A221304104CA0100000000000000000000000000000000
    Hash    REG_BINARY    CD3589987E9B5E1E6B4EEC849A5ADBBEECEA05CB35BB86B07AC66C4029EB0D6D

HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Schedule\Taskcache\Tasks\{E3163C33-301D-4730-A266-5518C5ED3967}
    Path    REG_SZ    \Microsoft\Windows\Bluetooth\UninstallDeviceTask
    Triggers    REG_BINARY    150000000000000000FFFFFFFFFFFFFFFFFFFFFFFFFFFFFF00FFFFFFFFFFFFFF000000000000000010054202484848480D99DFD7484848480048484848484848004848484848484805000000484848480C000000484848480101000000000005120000004848484800000000484848480000000048484848
    DynamicInfo    REG_BINARY    03000000890324304104CA0100000000000000000000000000000000
    Hash    REG_BINARY    90A6903C079DE796E0B72C7C3B740EA1AD655883DF0AC5468E3EB70311B7E7F7

HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Schedule\Taskcache\Tasks\{E711EFE2-5CFB-44B5-8A15-512E8C29E0A4}
    Path    REG_SZ    \Microsoft\Windows\DiskDiagnostic\Microsoft-Windows-DiskDiagnosticDataCollector
    Triggers    REG_BINARY    15000000000000000156ED01000000000068B69402D0C3010056ED0100000000FFFFFFFFFFFFFFFF52218202484848488ACEFD74484848480048484848484848004848484848484805000000484848480C000000484848480101000000000005120000004848484800000000484848480000000048484848DDDD0000000000000156ED01000000000068B69402D0C30100000000000000000000000000000000000000000000000000000000000000000000000000000000FFFFFFFF02000000020001000000000000010000010000000000000000000000
    DynamicInfo    REG_BINARY    03000000A0FE384701DCCA0100000000000000000000000000000000
    Hash    REG_BINARY    9615D02C18C2E20A2C5D63731D4143F49CD173A5C6E09584EA1A72DC9A6CFF48

HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Schedule\Taskcache\Tasks\{EACA24FF-236C-401D-A1E7-B3D5267B8A50}
    Path    REG_SZ    \Microsoft\Windows\RAC\RacTask
    Triggers    REG_BINARY    1500000000000000001C24FBFE0700000000000000000000001C24FBFE070000FFFFFFFFFFFFFFFF4021C20248484848E9C5E87D484848480048484848484848004848484848484805000000484848480C00000048484848010100000000000513000000484848480000000048484848380000004848484800000000FFFFFFFF00000000FFFFFFFF07000000000000000000000000000000000000000000000000000000000000000000000000000000CCCC000000000000001C24FBFE0700000000000000000000001C24FBFE070000FFFFFFFFFFFFFFFF00000000FFFFFFFF0000000000000000000000000000000001010000000000052000000000000000A8000000000000003C00510075006500720079004C006900730074003E003C00510075006500720079002000490064003D00220030002200200050006100740068003D0022004100700070006C00690063006100740069006F006E0022003E003C00530065006C00650063007400200050006100740068003D0022004100700070006C00690063006100740069006F006E0022003E002A005B00530079007300740065006D005B00500072006F00760069006400650072005B0040004E0061006D0065003D0027004D006900630072006F0073006F00660074002D00570069006E0064006F00770073002D00430045004900500027005D00200061006E00640020004500760065006E007400490044003D0031003000300037005D005D003C002F00530065006C006500630074003E003C002F00510075006500720079003E003C002F00510075006500720079004C006900730074003E000000484848484848000000000000000000000000000000000000000000000000DDDD000000000000001272FBFE0700000040A429C292C8010000000000000000000000000000000000000000000000000000000000000000100E000000000000FFFFFFFF00000000000000000000000000010000010000008403000000000000
    DynamicInfo    REG_BINARY    03000000890324304104CA0100000000000000000000000000000000
    Hash    REG_BINARY    E59879E1FF87CB7D11142664C919E0ADF61F5A9687D697C3F1C204FA4C56E303

HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Schedule\Taskcache\Tasks\{EB02381F-D652-4B1C-894A-712498C62C51}
    Path    REG_SZ    \Microsoft\Windows\MUI\LPRemove
    Triggers    REG_BINARY    1500000000000000001C24FBFE0700000000000000000000001C24FBFE070000FFFFFFFFFFFFFFFF12214203484848489B41D2D8484848480048484848484848004848484848484805000000484848480C00000048484848010100000000000512000000484848480000000048484848380000004848484858020000FFFFFFFF907E0000FFFFFFFF07000000000000000000000000000000000000000000000000000000000000000000000000000000FFFF000000000000001C24FBFE0700000000000000000000001C24FBFE070000FFFFFFFFFFFFFFFFDC050000FFFFFFFF0000000000000000000000000000000001000000000000000000000003000000
    DynamicInfo    REG_BINARY    030000004A43E52C4104CA0100000000000000000000000000000000
    Hash    REG_BINARY    47D45B031C1994B39C49EF36D6FE80FBEC111F7D6EF3E282476EF5D77E097DAB

HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Schedule\Taskcache\Tasks\{EC8DF7E1-FE52-4B24-9600-C98297AE2238}
    Path    REG_SZ    \Microsoft\Windows\Media Center\OCURActivate
    Triggers    REG_BINARY    150000000000000000FFFFFFFFFFFFFFFFFFFFFFFFFFFFFF00FFFFFFFFFFFFFF00000000000000000021420248484848C7422EAF484848480048484848484848004848484848484805000000484848480C000000484848480101000000000005120000004848484800000000484848480000000048484848
    DynamicInfo    REG_BINARY    03000000E04E104901DCCA0100000000000000000000000000000000
    Hash    REG_BINARY    21F0C71001FDAD4060D134F2914F036D1DAA814D9CF6206B8BBEA1D09AC5125B

HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Schedule\Taskcache\Tasks\{FA2BC0A6-8D4B-458A-85C8-2B8C72487513}
    Path    REG_SZ    \Microsoft\Windows\MemoryDiagnostic\DecompressionFailureDetector
    Triggers    REG_BINARY    1500000000000000001C24FBFE0700000000000000000000001C24FBFE070000FFFFFFFFFFFFFFFF00A0C00248484848AA4E8B9D4848484800484848484848480048484848484848040000004848484810000000484848480102000000000005200000002102000000000000484848480000000048484848CCCC000000000000001C24FBFE0700000000000000000000001C24FBFE070000FFFFFFFFFFFFFFFF00000000FFFFFFFF0000000000000000000000000000000001010000000000052000000000000000F4000000000000003C00510075006500720079004C006900730074003E003C00510075006500720079002000490064003D00220030002200200050006100740068003D0022004D006900630072006F0073006F00660074002D00570069006E0064006F00770073002D004B00650072006E0065006C002D00530074006F00720065004D00670072002F004F007000650072006100740069006F006E0061006C0022003E003C00530065006C00650063007400200050006100740068003D0022004D006900630072006F0073006F00660074002D00570069006E0064006F00770073002D004B00650072006E0065006C002D00530074006F00720065004D00670072002F004F007000650072006100740069006F006E0061006C0022003E002A005B00530079007300740065006D005B00500072006F00760069006400650072005B0040004E0061006D0065003D0027004D006900630072006F0073006F00660074002D00570069006E0064006F00770073002D004B00650072006E0065006C002D00530074006F00720065004D006700720027005D00200061006E00640020004500760065006E007400490044003D0036005D005D003C002F00530065006C006500630074003E003C002F00510075006500720079003E003C002F00510075006500720079004C006900730074003E000000484848484848000000000000000000000000000000000000000000000000
    DynamicInfo    REG_BINARY    03000000E96426304104CA0100000000000000000000000000000000
    Hash    REG_BINARY    CBB12F1ED12986181801A365A6F75001D31D2BB3CF7441BA8541894267D4CC42

HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Schedule\Taskcache\Tasks\{FB3C354D-297A-4EB2-9B58-090F6361906B}
    Path    REG_SZ    \Microsoft\Windows\Power Efficiency Diagnostics\AnalyzeSystem
    Triggers    REG_BINARY    1500000000000000011272FBFE0700000030118B3B4CC801001272FBFE070000FFFFFFFFFFFFFFFF4221420248484848D8D9932B484848480048484848484848004848484848484805000000484848480C0000004848484801010000000000051200000048484848000000004848484838000000484848482C010000201C00002C010000FFFFFFFF07000000000000000000000000000000000000000000000000000000750070000000000000000000DDDD000000000000011272FBFE0700000030118B3B4CC80100000000000000000000000000000000000000000000000000000000000000000000000000000000FFFFFFFF010000000E0000000000000000010000010000008070000000000000
    DynamicInfo    REG_BINARY    03000000AA272B304104CA0100000000000000000000000000000000
    Hash    REG_BINARY    9423B265CBAB426F81672F084E7D9866F685D983B62224712FF0DBC4FFEFE374

HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Schedule\Taskcache\Tasks\{FC4403AB-CB2F-42A2-9F65-6CA817FDFEC4}
    Path    REG_SZ    \Microsoft\Windows\Setup\gwx\refreshgwxconfigandcontent
    Hash    REG_BINARY    6DAEBDC0BC37F80D4A7BEB384C9CA705A0ADE59FE424F5B84CF10A66646DBEBF
    Triggers    REG_BINARY    15000000000000000000000000000000000000000000000000A2F50100000000FFFFFFFFFFFFFFFFC02142034848484870625DAF484848480048484848484848004848484848484805000000484848480C00000048484848010100000000000512000000484848480000000048484848380000004848484800000000FFFFFFFF00000000FFFFFFFF07000000000000000000000000000000000000000000000000000000000000000000000000000000DDDD00000000000001A2F5010000000000201676A646CE0100000000000000000000000000000000000000000000000000000000000000000000000000000000FFFFFFFF010000000100000000000000000100000100000080510100000000008888000000000000000000000000000000000000000000000000000000000000FFFFFFFFFFFFFFFF00000000FFFFFFFF00000000000000000000000000070000010064006C006C002C002D0035003000
    DynamicInfo    REG_BINARY    0300000000BF97763B1AD10100000000000000000000000000000000

HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Schedule\Taskcache\Tasks\{FDD56C73-F0D5-41B6-B767-6EFFD7966428}
    Path    REG_SZ    \Microsoft\Windows\Customer Experience Improvement Program\KernelCeipTask
    Triggers    REG_BINARY    1500000000000000011272FBFE070000002C7103E30BC901001272FBFE070000FFFFFFFFFFFFFFFF5221C20248484848D3FA1AB0484848480048484848484848004848484848484805000000484848480C000000484848480101000000000005130000004848484800000000484848483800000048484848B400000010EF000080F40300FFFFFFFF070000008C0A00000100000000000000000000000000000000000000000000000000800000000000DDDD000000000000011272FBFE070000002C7103E30BC90100000000000000000000000000000000000000000000000000000000000000000000000000000000FFFFFFFF02000000010010000000000000010000010000000000000000000000
    DynamicInfo    REG_BINARY    03000000AA272B304104CA0100000000000000000000000000000000
    Hash    REG_BINARY    AEB03F1BC169236F2C3BF019F9D9ED3C213D1E4A568F8C67F1FC3F2EC08649A6

 

========= End of Reg: =========


========= REG QUERY "HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\Taskcache\Tree" /s =========


HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Schedule\Taskcache\Tree\Adobe Acrobat Update Task
    Id    REG_SZ    {CA1C7F50-8959-4447-8A43-9AC256B76669}
    Index    REG_DWORD    0x2

HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Schedule\Taskcache\Tree\CCleanerSkipUAC
    Id    REG_SZ    {92771DAF-0E34-4CC5-9653-7A6E793544E5}
    Index    REG_DWORD    0x3

HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Schedule\Taskcache\Tree\Microsoft

HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Schedule\Taskcache\Tree\Microsoft\Windows

HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Schedule\Taskcache\Tree\Microsoft\Windows\Active Directory Rights Management Services Client

HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Schedule\Taskcache\Tree\Microsoft\Windows\Active Directory Rights Management Services Client\AD RMS Rights Policy Template Management (Automated)
    Id    REG_SZ    {613612BA-897D-44CE-8DC1-8FC283F9FD51}
    Index    REG_DWORD    0x2

HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Schedule\Taskcache\Tree\Microsoft\Windows\Active Directory Rights Management Services Client\AD RMS Rights Policy Template Management (Manual)
    Id    REG_SZ    {28011108-68DF-4C73-B91B-57427D501BBA}
    Index    REG_DWORD    0x2

HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Schedule\Taskcache\Tree\Microsoft\Windows\AppID

HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Schedule\Taskcache\Tree\Microsoft\Windows\AppID\PolicyConverter
    Id    REG_SZ    {A48CABBF-24C8-4B87-B00F-9261807C3B43}
    Index    REG_DWORD    0x3

HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Schedule\Taskcache\Tree\Microsoft\Windows\AppID\VerifiedPublisherCertStoreCheck
    Id    REG_SZ    {72DB7465-BC54-491B-A92A-4637A28C9BBF}
    Index    REG_DWORD    0x1

HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Schedule\Taskcache\Tree\Microsoft\Windows\Application Experience

HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Schedule\Taskcache\Tree\Microsoft\Windows\Application Experience\AitAgent
    Id    REG_SZ    {AC4E5ACF-89F7-4220-BA21-81EE183975E2}
    Index    REG_DWORD    0x3

HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Schedule\Taskcache\Tree\Microsoft\Windows\Application Experience\Microsoft Compatibility Appraiser
    Id    REG_SZ    {25D544CB-69FF-4F6D-B01B-63541C25C654}
    Index    REG_DWORD    0x3

HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Schedule\Taskcache\Tree\Microsoft\Windows\Application Experience\ProgramDataUpdater
    Id    REG_SZ    {034DF26D-DA1B-4161-9AE1-330409B21EE7}
    Index    REG_DWORD    0x3

HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Schedule\Taskcache\Tree\Microsoft\Windows\Autochk

HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Schedule\Taskcache\Tree\Microsoft\Windows\Autochk\Proxy
    Id    REG_SZ    {D7B6E81D-3CF4-432C-84D2-24213F4316E6}
    Index    REG_DWORD    0x1

HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Schedule\Taskcache\Tree\Microsoft\Windows\Bluetooth

HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Schedule\Taskcache\Tree\Microsoft\Windows\Bluetooth\UninstallDeviceTask
    Id    REG_SZ    {E3163C33-301D-4730-A266-5518C5ED3967}
    Index    REG_DWORD    0x3

HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Schedule\Taskcache\Tree\Microsoft\Windows\CertificateServicesClient

HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Schedule\Taskcache\Tree\Microsoft\Windows\CertificateServicesClient\SystemTask
    Id    REG_SZ    {5F5A18EB-DC73-4E45-A11C-B59043598412}
    Index    REG_DWORD    0x1

HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Schedule\Taskcache\Tree\Microsoft\Windows\CertificateServicesClient\UserTask
    Id    REG_SZ    {7AFCC0CA-7121-422A-AB45-B0E8D599FF08}
    Index    REG_DWORD    0x2

HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Schedule\Taskcache\Tree\Microsoft\Windows\CertificateServicesClient\UserTask-Roam
    Id    REG_SZ    {9979CB83-103A-4105-9E5D-C74B0AF6D198}
    Index    REG_DWORD    0x3

HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Schedule\Taskcache\Tree\Microsoft\Windows\Customer Experience Improvement Program

HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Schedule\Taskcache\Tree\Microsoft\Windows\Customer Experience Improvement Program\Consolidator
    Id    REG_SZ    {C016366B-7126-46CA-B36B-592A3D95A60B}
    Index    REG_DWORD    0x3

HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Schedule\Taskcache\Tree\Microsoft\Windows\Customer Experience Improvement Program\KernelCeipTask
    Id    REG_SZ    {FDD56C73-F0D5-41B6-B767-6EFFD7966428}
    Index    REG_DWORD    0x3

HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Schedule\Taskcache\Tree\Microsoft\Windows\Customer Experience Improvement Program\OptinNotification
    Id    REG_SZ    {A132EB1D-A1EA-48EF-8B69-9358EADF5BD3}
    Index    REG_DWORD    0x0

HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Schedule\Taskcache\Tree\Microsoft\Windows\Customer Experience Improvement Program\UsbCeip
    Id    REG_SZ    {47536D45-EEEC-4BDC-8183-A4DC1F8DA9E4}
    Index    REG_DWORD    0x3

HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Schedule\Taskcache\Tree\Microsoft\Windows\Defrag

HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Schedule\Taskcache\Tree\Microsoft\Windows\Defrag\ScheduledDefrag
    Id    REG_SZ    {AF0E8862-B404-45B1-990F-A877CA74DB66}
    Index    REG_DWORD    0x3

HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Schedule\Taskcache\Tree\Microsoft\Windows\Diagnosis

HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Schedule\Taskcache\Tree\Microsoft\Windows\Diagnosis\Scheduled
    Id    REG_SZ    {BE669C13-8165-4536-96D0-6D6C39292AAE}
    Index    REG_DWORD    0x3

HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Schedule\Taskcache\Tree\Microsoft\Windows\DiskDiagnostic

HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Schedule\Taskcache\Tree\Microsoft\Windows\DiskDiagnostic\Microsoft-Windows-DiskDiagnosticDataCollector
    Id    REG_SZ    {E711EFE2-5CFB-44B5-8A15-512E8C29E0A4}
    Index    REG_DWORD    0x3

HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Schedule\Taskcache\Tree\Microsoft\Windows\DiskDiagnostic\Microsoft-Windows-DiskDiagnosticResolver
    Id    REG_SZ    {D566BF98-A96D-49E6-B8C7-DD9C73666437}
    Index    REG_DWORD    0x2

HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Schedule\Taskcache\Tree\Microsoft\Windows\Location

HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Schedule\Taskcache\Tree\Microsoft\Windows\Location\Notifications
    Id    REG_SZ    {A6AF9377-77CE-47AB-AD7D-EC32CAD0C82D}
    Index    REG_DWORD    0x3

HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Schedule\Taskcache\Tree\Microsoft\Windows\Maintenance

HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Schedule\Taskcache\Tree\Microsoft\Windows\Maintenance\WinSAT
    Id    REG_SZ    {DA41DE71-8431-42FB-9DB0-EB64A961DEAD}
    Index    REG_DWORD    0x3

HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Schedule\Taskcache\Tree\Microsoft\Windows\Media Center

HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Schedule\Taskcache\Tree\Microsoft\Windows\Media Center\ActivateWindowsSearch
    Id    REG_SZ    {59FCD788-0753-4F0B-A5CB-D300883F1B39}
    Index    REG_DWORD    0x3

HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Schedule\Taskcache\Tree\Microsoft\Windows\Media Center\ConfigureInternetTimeService
    Id    REG_SZ    {586D03C8-7997-4FDC-8F49-2F396233504A}
    Index    REG_DWORD    0x3

HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Schedule\Taskcache\Tree\Microsoft\Windows\Media Center\DispatchRecoveryTasks
    Id    REG_SZ    {8A9251B2-FAB7-49A1-BA84-9F104776E7A7}
    Index    REG_DWORD    0x3

HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Schedule\Taskcache\Tree\Microsoft\Windows\Media Center\ehDRMInit
    Id    REG_SZ    {003DBEB6-92B4-41BC-A8DE-E766A3FB3C65}
    Index    REG_DWORD    0x3

HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Schedule\Taskcache\Tree\Microsoft\Windows\Media Center\InstallPlayReady
    Id    REG_SZ    {65D42D99-7EA2-4D6A-AB62-B6EAB8D72F33}
    Index    REG_DWORD    0x3

HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Schedule\Taskcache\Tree\Microsoft\Windows\Media Center\mcupdate
    Id    REG_SZ    {7D8D2001-718E-43EA-A986-73BDD46C6B6A}
    Index    REG_DWORD    0x3

HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Schedule\Taskcache\Tree\Microsoft\Windows\Media Center\MediaCenterRecoveryTask
    Id    REG_SZ    {C27A0E7B-742B-4454-804E-44F3C2A92FCF}
    Index    REG_DWORD    0x3

HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Schedule\Taskcache\Tree\Microsoft\Windows\Media Center\ObjectStoreRecoveryTask
    Id    REG_SZ    {4B4C6847-EB01-4D6B-858A-41F8352F8BC9}
    Index    REG_DWORD    0x3

HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Schedule\Taskcache\Tree\Microsoft\Windows\Media Center\OCURActivate
    Id    REG_SZ    {EC8DF7E1-FE52-4B24-9600-C98297AE2238}
    Index    REG_DWORD    0x3

HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Schedule\Taskcache\Tree\Microsoft\Windows\Media Center\OCURDiscovery
    Id    REG_SZ    {7D97DDB4-6C77-450C-BA4E-FB3ED96AA490}
    Index    REG_DWORD    0x3

HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Schedule\Taskcache\Tree\Microsoft\Windows\Media Center\PBDADiscovery
    Id    REG_SZ    {2FEF85B2-6B9E-476C-A637-B03479D6C607}
    Index    REG_DWORD    0x3

HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Schedule\Taskcache\Tree\Microsoft\Windows\Media Center\PBDADiscoveryW1
    Id    REG_SZ    {B5300C80-1852-4740-8577-DAD20107477F}
    Index    REG_DWORD    0x3

HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Schedule\Taskcache\Tree\Microsoft\Windows\Media Center\PBDADiscoveryW2
    Id    REG_SZ    {DBABD243-12BD-48BF-AB79-4661514DB486}
    Index    REG_DWORD    0x3

HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Schedule\Taskcache\Tree\Microsoft\Windows\Media Center\PeriodicScanRetry
    Id    REG_SZ    {19DADAD5-F9EC-4AEF-946C-C0A576840830}
    Index    REG_DWORD    0x3

HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Schedule\Taskcache\Tree\Microsoft\Windows\Media Center\PvrRecoveryTask
    Id    REG_SZ    {51A295A6-300F-46E4-B98A-DF89A97815D3}
    Index    REG_DWORD    0x3

HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Schedule\Taskcache\Tree\Microsoft\Windows\Media Center\PvrScheduleTask
    Id    REG_SZ    {7E5A4FEF-DD93-45B9-A363-8A68B88823C2}
    Index    REG_DWORD    0x3

HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Schedule\Taskcache\Tree\Microsoft\Windows\Media Center\RecordingRestart
    Id    REG_SZ    {53BB7902-6E80-4F0D-B21C-501FE9C0E32E}
    Index    REG_DWORD    0x1

HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Schedule\Taskcache\Tree\Microsoft\Windows\Media Center\RegisterSearch
    Id    REG_SZ    {059C454D-C82D-4FBA-ACA0-E0D20F84D4CD}
    Index    REG_DWORD    0x3

HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Schedule\Taskcache\Tree\Microsoft\Windows\Media Center\ReindexSearchRoot
    Id    REG_SZ    {D1BC44FB-2193-40BF-AA4A-2E96D31F2BCE}
    Index    REG_DWORD    0x3

HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Schedule\Taskcache\Tree\Microsoft\Windows\Media Center\SqlLiteRecoveryTask
    Id    REG_SZ    {3AF48B03-9CD2-4EDC-9FB4-A5EC0C31A32C}
    Index    REG_DWORD    0x3

HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Schedule\Taskcache\Tree\Microsoft\Windows\Media Center\StartRecording
    Id    REG_SZ    {1134D20D-324D-4391-86F5-75AFCFC9779A}
    Index    REG_DWORD    0x3

HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Schedule\Taskcache\Tree\Microsoft\Windows\Media Center\UpdateRecordPath
    Id    REG_SZ    {CC459BF8-7D00-4831-99CC-FE735B19F74A}
    Index    REG_DWORD    0x3

HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Schedule\Taskcache\Tree\Microsoft\Windows\MemoryDiagnostic

HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Schedule\Taskcache\Tree\Microsoft\Windows\MemoryDiagnostic\CorruptionDetector
    Id    REG_SZ    {CEE64558-E1A7-4D9D-80A7-2001912BE5B5}
    Index    REG_DWORD    0x3

HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Schedule\Taskcache\Tree\Microsoft\Windows\MemoryDiagnostic\DecompressionFailureDetector
    Id    REG_SZ    {FA2BC0A6-8D4B-458A-85C8-2B8C72487513}
    Index    REG_DWORD    0x3

HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Schedule\Taskcache\Tree\Microsoft\Windows\MemoryDiagnostic\MemUsageTask
    Id    REG_SZ    {C4375D81-FA72-45AC-85F2-3B86A11CCC7D}
    Index    REG_DWORD    0x0

HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Schedule\Taskcache\Tree\Microsoft\Windows\MobilePC

HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Schedule\Taskcache\Tree\Microsoft\Windows\MobilePC\HotStart
    Id    REG_SZ    {1BA0AE97-C21E-48BB-9FF0-70BC9F299377}
    Index    REG_DWORD    0x2

HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Schedule\Taskcache\Tree\Microsoft\Windows\MUI

HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Schedule\Taskcache\Tree\Microsoft\Windows\MUI\LPRemove
    Id    REG_SZ    {EB02381F-D652-4B1C-894A-712498C62C51}
    Index    REG_DWORD    0x1

HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Schedule\Taskcache\Tree\Microsoft\Windows\Multimedia

HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Schedule\Taskcache\Tree\Microsoft\Windows\Multimedia\SystemSoundsService
    Id    REG_SZ    {2470470F-2634-478E-B181-571E98A789BB}
    Index    REG_DWORD    0x2

HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Schedule\Taskcache\Tree\Microsoft\Windows\NetTrace

HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Schedule\Taskcache\Tree\Microsoft\Windows\NetTrace\GatherNetworkInfo
    Id    REG_SZ    {81540B9F-B5BF-47EB-9C95-BE195BF2C664}
    Index    REG_DWORD    0x3

HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Schedule\Taskcache\Tree\Microsoft\Windows\NetworkAccessProtection

HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Schedule\Taskcache\Tree\Microsoft\Windows\NetworkAccessProtection\NAPStatus UI
    Id    REG_SZ    {00BB5F5C-4A20-4FD6-8900-4699F989BF01}
    Index    REG_DWORD    0x0

HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Schedule\Taskcache\Tree\Microsoft\Windows\Offline Files

HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Schedule\Taskcache\Tree\Microsoft\Windows\Offline Files\Background Synchronization
    Id    REG_SZ    {D378D375-CAC7-474F-8B4B-82FF8391E306}
    Index    REG_DWORD    0x3

HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Schedule\Taskcache\Tree\Microsoft\Windows\Offline Files\Logon Synchronization
    Id    REG_SZ    {AEA35300-8D3F-4FFA-9243-5072A3D37166}
    Index    REG_DWORD    0x2

HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Schedule\Taskcache\Tree\Microsoft\Windows\PerfTrack

HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Schedule\Taskcache\Tree\Microsoft\Windows\PerfTrack\BackgroundConfigSurveyor
    Id    REG_SZ    {B0CBAB43-44FC-469B-A4CE-87426761FDCE}
    Index    REG_DWORD    0x3

HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Schedule\Taskcache\Tree\Microsoft\Windows\PLA

HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Schedule\Taskcache\Tree\Microsoft\Windows\PLA\System

HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Schedule\Taskcache\Tree\Microsoft\Windows\PLA\System\ConvertLogEntries
    Id    REG_SZ    {600F3312-A477-448A-936D-EB2DF977300B}
    Index    REG_DWORD    0x0

HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Schedule\Taskcache\Tree\Microsoft\Windows\Power Efficiency Diagnostics

HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Schedule\Taskcache\Tree\Microsoft\Windows\Power Efficiency Diagnostics\AnalyzeSystem
    Id    REG_SZ    {FB3C354D-297A-4EB2-9B58-090F6361906B}
    Index    REG_DWORD    0x3

HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Schedule\Taskcache\Tree\Microsoft\Windows\RAC

HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Schedule\Taskcache\Tree\Microsoft\Windows\RAC\RACAgent
    Id    REG_SZ    {7F9C951C-D364-4B70-8D07-D2C9B7F76E35}
    Index    REG_DWORD    0x0

HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Schedule\Taskcache\Tree\Microsoft\Windows\RAC\RacTask
    Id    REG_SZ    {EACA24FF-236C-401D-A1E7-B3D5267B8A50}
    Index    REG_DWORD    0x3

HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Schedule\Taskcache\Tree\Microsoft\Windows\Ras

HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Schedule\Taskcache\Tree\Microsoft\Windows\Ras\MobilityManager
    Id    REG_SZ    {AC668097-4D6B-4093-AC14-014C09DBF820}
    Index    REG_DWORD    0x3

HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Schedule\Taskcache\Tree\Microsoft\Windows\Registry

HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Schedule\Taskcache\Tree\Microsoft\Windows\Registry\RegIdleBackup
    Id    REG_SZ    {CA4B8FF2-A4D2-4D88-A52E-3A5BDAF7F56E}
    Index    REG_DWORD    0x3

HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Schedule\Taskcache\Tree\Microsoft\Windows\RemoteAssistance

HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Schedule\Taskcache\Tree\Microsoft\Windows\RemoteAssistance\RemoteAssistanceTask
    Id    REG_SZ    {CB3D64BF-C0C9-45FF-BFB0-FF1A8F680186}
    Index    REG_DWORD    0x3

HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Schedule\Taskcache\Tree\Microsoft\Windows\Setup

HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Schedule\Taskcache\Tree\Microsoft\Windows\Setup\gwx

HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Schedule\Taskcache\Tree\Microsoft\Windows\Setup\gwx\launchtrayprocess
    Id    REG_SZ    {4E123E26-F25D-4531-940D-1CE792873193}
    Index    REG_DWORD    0x2

HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Schedule\Taskcache\Tree\Microsoft\Windows\Setup\gwx\refreshgwxconfig
    Id    REG_SZ    {63383B41-CD22-4AEF-B02D-D120C179FF58}
    Index    REG_DWORD    0x3

HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Schedule\Taskcache\Tree\Microsoft\Windows\Setup\gwx\refreshgwxconfigandcontent
    Id    REG_SZ    {FC4403AB-CB2F-42A2-9F65-6CA817FDFEC4}
    Index    REG_DWORD    0x3

HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Schedule\Taskcache\Tree\Microsoft\Windows\Setup\gwx\refreshgwxcontent
    Id    REG_SZ    {7F946C6C-5401-4324-9B15-70C5B0892EE6}
    Index    REG_DWORD    0x3

HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Schedule\Taskcache\Tree\Microsoft\Windows\Setup\GWXTriggers

HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Schedule\Taskcache\Tree\Microsoft\Windows\Setup\GWXTriggers\refreshgwxconfig-B
    Id    REG_SZ    {51BE84C4-5631-4EF6-B076-5745D35B06F5}
    Index    REG_DWORD    0x3

HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Schedule\Taskcache\Tree\Microsoft\Windows\Shell

HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Schedule\Taskcache\Tree\Microsoft\Windows\Shell\CrawlStartPages
    Id    REG_SZ    {B936B1AF-0C7E-4C4D-84F1-CF67453259A1}
    Index    REG_DWORD    0x0

HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Schedule\Taskcache\Tree\Microsoft\Windows\Shell\WindowsParentalControls
    Id    REG_SZ    {5B42DD9C-5A26-4F27-BB95-34603F0997E5}
    Index    REG_DWORD    0x2

HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Schedule\Taskcache\Tree\Microsoft\Windows\Shell\WindowsParentalControlsMigration
    Id    REG_SZ    {486D715E-6AA2-44CF-BC48-B6990CBB53C6}
    Index    REG_DWORD    0x2

HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Schedule\Taskcache\Tree\Microsoft\Windows\SideShow

HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Schedule\Taskcache\Tree\Microsoft\Windows\SideShow\AutoWake
    Id    REG_SZ    {2D70F1F8-E61A-46C8-B602-8C0F8C536A9D}
    Index    REG_DWORD    0x2

HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Schedule\Taskcache\Tree\Microsoft\Windows\SideShow\GadgetManager
    Id    REG_SZ    {CBC80253-50BE-47AF-81EA-A8816005ABE4}
    Index    REG_DWORD    0x2

HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Schedule\Taskcache\Tree\Microsoft\Windows\SideShow\SessionAgent
    Id    REG_SZ    {0DC5362E-5BE5-491D-8F88-8E388E4759CD}
    Index    REG_DWORD    0x2

HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Schedule\Taskcache\Tree\Microsoft\Windows\SideShow\SystemDataProviders
    Id    REG_SZ    {8BDF0314-A8E0-4A71-9E60-0F7C1739DE56}
    Index    REG_DWORD    0x2

HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Schedule\Taskcache\Tree\Microsoft\Windows\SoftwareProtectionPlatform

HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Schedule\Taskcache\Tree\Microsoft\Windows\SoftwareProtectionPlatform\SvcRestartTask
    Id    REG_SZ    {DD9F510C-95F4-499A-90C8-BAC5BC372FF4}
    Index    REG_DWORD    0x3

HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Schedule\Taskcache\Tree\Microsoft\Windows\SystemRestore

HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Schedule\Taskcache\Tree\Microsoft\Windows\SystemRestore\SR
    Id    REG_SZ    {994C86AD-A929-4B2C-88A0-4E25A107A029}
    Index    REG_DWORD    0x1

HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Schedule\Taskcache\Tree\Microsoft\Windows\Task Manager

HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Schedule\Taskcache\Tree\Microsoft\Windows\Task Manager\Interactive
    Id    REG_SZ    {1F7B7221-AE8F-44F3-BA82-F7D260F51964}
    Index    REG_DWORD    0x3

HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Schedule\Taskcache\Tree\Microsoft\Windows\Tcpip

HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Schedule\Taskcache\Tree\Microsoft\Windows\Tcpip\IpAddressConflict1
    Id    REG_SZ    {088482FA-65B8-4E17-9ABF-1DCD48E8D373}
    Index    REG_DWORD    0x3

HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Schedule\Taskcache\Tree\Microsoft\Windows\Tcpip\IpAddressConflict2
    Id    REG_SZ    {09F06BFE-A3C8-40E3-846A-6E6F4000C238}
    Index    REG_DWORD    0x3

HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Schedule\Taskcache\Tree\Microsoft\Windows\TextServicesFramework

HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Schedule\Taskcache\Tree\Microsoft\Windows\TextServicesFramework\MsCtfMonitor
    Id    REG_SZ    {4C8B01A2-11FF-4C41-848F-508EF4F00CF7}
    Index    REG_DWORD    0x2

HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Schedule\Taskcache\Tree\Microsoft\Windows\Time Synchronization

HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Schedule\Taskcache\Tree\Microsoft\Windows\Time Synchronization\SynchronizeTime
    Id    REG_SZ    {044A6734-E90E-4F8F-B357-B2DC8AB3B5EC}
    Index    REG_DWORD    0x3

HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Schedule\Taskcache\Tree\Microsoft\Windows\UPnP

HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Schedule\Taskcache\Tree\Microsoft\Windows\UPnP\UPnPHostConfig
    Id    REG_SZ    {5A40E926-9E86-4B89-9CFD-B12311724371}
    Index    REG_DWORD    0x3

HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Schedule\Taskcache\Tree\Microsoft\Windows\User Profile Service

HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Schedule\Taskcache\Tree\Microsoft\Windows\User Profile Service\HiveUploadTask
    Id    REG_SZ    {6738BA6E-EA75-4B6B-B8B8-71F0336DD8EF}
    Index    REG_DWORD    0x3

HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Schedule\Taskcache\Tree\Microsoft\Windows\WDI

HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Schedule\Taskcache\Tree\Microsoft\Windows\WDI\ResolutionHost
    Id    REG_SZ    {9435F817-FED2-454E-88CD-7F78FDA62C48}
    Index    REG_DWORD    0x3

HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Schedule\Taskcache\Tree\Microsoft\Windows\Windows Activation Technologies

HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Schedule\Taskcache\Tree\Microsoft\Windows\Windows Activation Technologies\ValidationTask
    Id    REG_SZ    {880E621A-DD8A-497F-BED1-3311DA2C4FA1}
    Index    REG_DWORD    0x3

HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Schedule\Taskcache\Tree\Microsoft\Windows\Windows Activation Technologies\ValidationTaskDeadline
    Id    REG_SZ    {29BBD2BA-5D45-4CB7-965D-1CD982162CA3}
    Index    REG_DWORD    0x3

HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Schedule\Taskcache\Tree\Microsoft\Windows\Windows Error Reporting

HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Schedule\Taskcache\Tree\Microsoft\Windows\Windows Error Reporting\QueueReporting
    Id    REG_SZ    {D0250F3F-6480-484F-B719-42F659AC64D5}
    Index    REG_DWORD    0x2

HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Schedule\Taskcache\Tree\Microsoft\Windows\Windows Filtering Platform

HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Schedule\Taskcache\Tree\Microsoft\Windows\Windows Filtering Platform\BfeOnServiceStartTypeChange
    Id    REG_SZ    {E22A8667-F75B-4BA9-BA46-067ED4429DE8}
    Index    REG_DWORD    0x3

HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Schedule\Taskcache\Tree\Microsoft\Windows\Windows Media Sharing

HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Schedule\Taskcache\Tree\Microsoft\Windows\Windows Media Sharing\UpdateLibrary
    Id    REG_SZ    {753C47AE-EC5E-44B3-95A9-2C8E553F0E39}
    Index    REG_DWORD    0x3

HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Schedule\Taskcache\Tree\Microsoft\Windows\WindowsBackup

HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Schedule\Taskcache\Tree\Microsoft\Windows\WindowsBackup\ConfigNotification
    Id    REG_SZ    {2F57269B-1E09-4E2D-AB1E-B0FDAC7D279C}
    Index    REG_DWORD    0x3

HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Schedule\Taskcache\Tree\Microsoft\Windows\WindowsColorSystem

HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Schedule\Taskcache\Tree\Microsoft\Windows\WindowsColorSystem\Calibration Loader
    Id    REG_SZ    {A35BB7A6-5F0C-4C9F-8450-2B3BED532D51}
    Index    REG_DWORD    0x2

HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Schedule\Taskcache\Tree\Microsoft\Windows\Wininet

HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Schedule\Taskcache\Tree\Microsoft\Windows\Wininet\CacheTask
    Id    REG_SZ    {1CBB66B9-9E68-4ACE-8275-4E8796A4A18F}
    Index    REG_DWORD    0x2

HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Schedule\Taskcache\Tree\Microsoft\Windows Defender

HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Schedule\Taskcache\Tree\Norton Internet Security

HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Schedule\Taskcache\Tree\Norton Internet Security\Norton Error Analyzer
    Id    REG_SZ    {383EAD95-C762-4EB9-9AB8-78CCE1AF3C38}
    Index    REG_DWORD    0x3

HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Schedule\Taskcache\Tree\Norton Internet Security\Norton Error Processor
    Id    REG_SZ    {B96F52BC-A937-4670-8F16-886CE14EAD84}
    Index    REG_DWORD    0x3

HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Schedule\Taskcache\Tree\WPD

HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Schedule\Taskcache\Tree\WPD\SqmUpload_S-1-5-21-786217106-2830415026-3013700145-1000
    Id    REG_SZ    {278D9BE4-FE38-4141-9BA1-B3F35074E9E1}
    Index    REG_DWORD    0x3

 

========= End of Reg: =========


==== End of Fixlog 06:35:48 ====

 

 

I did notice something, before I did the second go around of using the FIX (above)  -  I noticed an icon link (with Chrome logo) on my desktop that would come up with a "side-by-side" error was fixed. The Chrome logo was gone.

I click on the link and now it goes the the website. That problem was a consequence of uninstalling Chrome.

I'm thankful for that.

 

 

 

Link to post
Share on other sites

So FRST still couldn't delete the WMI entry for X reason, stating that it wasn't found even though it is clearly there. I'll ask my colleagues if they ever encountered a similar situation. Otherwise, I'll have to make you remove that entry manually via wbemtest.exe.

Link to post
Share on other sites

28 minutes ago, Aura said:

So FRST still couldn't delete the WMI entry for X reason, stating that it wasn't found even though it is clearly there. I'll ask my colleagues if they ever encountered a similar situation. Otherwise, I'll have to make you remove that entry manually via wbemtest.exe.

Would running Adwcleaner help?

Link to post
Share on other sites

Guest
This topic is now closed to further replies.
 Share

  • Recently Browsing   0 members

    • No registered users viewing this page.
Back to top
×
×
  • Create New...

Important Information

This site uses cookies - We have placed cookies on your device to help make this website better. You can adjust your cookie settings, otherwise we'll assume you're okay to continue.