Windows Registry Editor Version 5.00
[HKEY_CLASSES_ROOT\{2C256447-3F0D-4CBB-9D12-575BB20CDA0A}]
[HKEY_CLASSES_ROOT\{2C256447-3F0D-4CBB-9D12-575BB20CDA0A}\ProgID]
@="FaultrepElevatedDataCollection"
[HKEY_CLASSES_ROOT\AppID\{2C256447-3F0D-4CBB-9D12-575BB20CDA0A}]
@="faultrep.dll"
"AccessPermission"=hex:01,00,04,80,60,00,00,00,70,00,00,00,00,00,00,00,14,00,\
00,00,02,00,4c,00,03,00,00,00,00,00,14,00,03,00,00,00,01,01,00,00,00,00,00,\
05,12,00,00,00,00,00,14,00,07,00,00,00,01,01,00,00,00,00,00,05,0a,00,00,00,\
00,00,14,00,03,00,00,00,01,01,00,00,00,00,00,05,04,00,00,00,cd,cd,cd,cd,cd,\
cd,cd,cd,01,02,00,00,00,00,00,05,20,00,00,00,20,02,00,00,01,02,00,00,00,00,\
00,05,20,00,00,00,20,02,00,00
"DllSurrogate"=""
"LaunchPermission"=hex:01,00,04,80,78,00,00,00,88,00,00,00,00,00,00,00,14,00,\
00,00,02,00,64,00,04,00,00,00,00,00,14,00,1f,00,00,00,01,01,00,00,00,00,00,\
05,12,00,00,00,00,00,18,00,1f,00,00,00,01,02,00,00,00,00,00,05,20,00,00,00,\
20,02,00,00,00,00,14,00,1f,00,00,00,01,01,00,00,00,00,00,05,04,00,00,00,00,\
00,14,00,0b,00,00,00,01,01,00,00,00,00,00,05,12,00,00,00,cd,cd,cd,cd,cd,cd,\
cd,cd,01,02,00,00,00,00,00,05,20,00,00,00,20,02,00,00,01,02,00,00,00,00,00,\
05,20,00,00,00,20,02,00,00
[HKEY_CLASSES_ROOT\CLSID\{2C256447-3F0D-4CBB-9D12-575BB20CDA0A}]
@="FaultrepElevatedDataCollection"
"AppId"="{2C256447-3F0D-4CBB-9D12-575BB20CDA0A}"
"LocalizedString"=hex(2):40,00,25,00,73,00,79,00,73,00,74,00,65,00,6d,00,72,00,\
6f,00,6f,00,74,00,25,00,5c,00,73,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,\
00,5c,00,66,00,61,00,75,00,6c,00,74,00,72,00,65,00,70,00,2e,00,64,00,6c,00,\
6c,00,2c,00,2d,00,35,00,30,00,30,00,30,00,00,00
[HKEY_CLASSES_ROOT\CLSID\{2C256447-3F0D-4CBB-9D12-575BB20CDA0A}\Elevation]
"Enabled"=dword:00000001
[HKEY_CLASSES_ROOT\CLSID\{2C256447-3F0D-4CBB-9D12-575BB20CDA0A}\InProcServer32]
@="C:\\Windows\\System32\\faultrep.dll"
"ThreadingModel"="Both"
[HKEY_CLASSES_ROOT\FaultrepElevatedDataCollection]
@="FaultrepElevatedDataCollection"
[HKEY_CLASSES_ROOT\FaultrepElevatedDataCollection\CLSID]
@="{2C256447-3F0D-4CBB-9D12-575BB20CDA0A}"
[HKEY_CLASSES_ROOT\Wow6432Node\AppID\{2C256447-3F0D-4CBB-9D12-575BB20CDA0A}]
@="faultrep.dll"
"AccessPermission"=hex:01,00,04,80,60,00,00,00,70,00,00,00,00,00,00,00,14,00,\
00,00,02,00,4c,00,03,00,00,00,00,00,14,00,03,00,00,00,01,01,00,00,00,00,00,\
05,12,00,00,00,00,00,14,00,07,00,00,00,01,01,00,00,00,00,00,05,0a,00,00,00,\
00,00,14,00,03,00,00,00,01,01,00,00,00,00,00,05,04,00,00,00,cd,cd,cd,cd,cd,\
cd,cd,cd,01,02,00,00,00,00,00,05,20,00,00,00,20,02,00,00,01,02,00,00,00,00,\
00,05,20,00,00,00,20,02,00,00
"DllSurrogate"=""
"LaunchPermission"=hex:01,00,04,80,78,00,00,00,88,00,00,00,00,00,00,00,14,00,\
00,00,02,00,64,00,04,00,00,00,00,00,14,00,1f,00,00,00,01,01,00,00,00,00,00,\
05,12,00,00,00,00,00,18,00,1f,00,00,00,01,02,00,00,00,00,00,05,20,00,00,00,\
20,02,00,00,00,00,14,00,1f,00,00,00,01,01,00,00,00,00,00,05,04,00,00,00,00,\
00,14,00,0b,00,00,00,01,01,00,00,00,00,00,05,12,00,00,00,cd,cd,cd,cd,cd,cd,\
cd,cd,01,02,00,00,00,00,00,05,20,00,00,00,20,02,00,00,01,02,00,00,00,00,00,\
05,20,00,00,00,20,02,00,00
[HKEY_CLASSES_ROOT\Wow6432Node\CLSID\{2C256447-3F0D-4CBB-9D12-575BB20CDA0A}]
@="FaultrepElevatedDataCollection"
"AppId"="{2C256447-3F0D-4CBB-9D12-575BB20CDA0A}"
"LocalizedString"=hex(2):40,00,25,00,73,00,79,00,73,00,74,00,65,00,6d,00,72,00,\
6f,00,6f,00,74,00,25,00,5c,00,73,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,\
00,5c,00,66,00,61,00,75,00,6c,00,74,00,72,00,65,00,70,00,2e,00,64,00,6c,00,\
6c,00,2c,00,2d,00,35,00,30,00,30,00,30,00,00,00
[HKEY_CLASSES_ROOT\Wow6432Node\CLSID\{2C256447-3F0D-4CBB-9D12-575BB20CDA0A}\Elevation]
"Enabled"=dword:00000001
[HKEY_CLASSES_ROOT\Wow6432Node\CLSID\{2C256447-3F0D-4CBB-9D12-575BB20CDA0A}\InProcServer32]
@="C:\\Windows\\SysWOW64\\faultrep.dll"
"ThreadingModel"="Both"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\{2C256447-3F0D-4CBB-9D12-575BB20CDA0A}]
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\{2C256447-3F0D-4CBB-9D12-575BB20CDA0A}\ProgID]
@="FaultrepElevatedDataCollection"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{2C256447-3F0D-4CBB-9D12-575BB20CDA0A}]
@="faultrep.dll"
"AccessPermission"=hex:01,00,04,80,60,00,00,00,70,00,00,00,00,00,00,00,14,00,\
00,00,02,00,4c,00,03,00,00,00,00,00,14,00,03,00,00,00,01,01,00,00,00,00,00,\
05,12,00,00,00,00,00,14,00,07,00,00,00,01,01,00,00,00,00,00,05,0a,00,00,00,\
00,00,14,00,03,00,00,00,01,01,00,00,00,00,00,05,04,00,00,00,cd,cd,cd,cd,cd,\
cd,cd,cd,01,02,00,00,00,00,00,05,20,00,00,00,20,02,00,00,01,02,00,00,00,00,\
00,05,20,00,00,00,20,02,00,00
"DllSurrogate"=""
"LaunchPermission"=hex:01,00,04,80,78,00,00,00,88,00,00,00,00,00,00,00,14,00,\
00,00,02,00,64,00,04,00,00,00,00,00,14,00,1f,00,00,00,01,01,00,00,00,00,00,\
05,12,00,00,00,00,00,18,00,1f,00,00,00,01,02,00,00,00,00,00,05,20,00,00,00,\
20,02,00,00,00,00,14,00,1f,00,00,00,01,01,00,00,00,00,00,05,04,00,00,00,00,\
00,14,00,0b,00,00,00,01,01,00,00,00,00,00,05,12,00,00,00,cd,cd,cd,cd,cd,cd,\
cd,cd,01,02,00,00,00,00,00,05,20,00,00,00,20,02,00,00,01,02,00,00,00,00,00,\
05,20,00,00,00,20,02,00,00
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{2C256447-3F0D-4CBB-9D12-575BB20CDA0A}]
@="FaultrepElevatedDataCollection"
"AppId"="{2C256447-3F0D-4CBB-9D12-575BB20CDA0A}"
"LocalizedString"=hex(2):40,00,25,00,73,00,79,00,73,00,74,00,65,00,6d,00,72,00,\
6f,00,6f,00,74,00,25,00,5c,00,73,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,\
00,5c,00,66,00,61,00,75,00,6c,00,74,00,72,00,65,00,70,00,2e,00,64,00,6c,00,\
6c,00,2c,00,2d,00,35,00,30,00,30,00,30,00,00,00
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{2C256447-3F0D-4CBB-9D12-575BB20CDA0A}\Elevation]
"Enabled"=dword:00000001
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{2C256447-3F0D-4CBB-9D12-575BB20CDA0A}\InProcServer32]
@="C:\\Windows\\System32\\faultrep.dll"
"ThreadingModel"="Both"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\FaultrepElevatedDataCollection]
@="FaultrepElevatedDataCollection"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\FaultrepElevatedDataCollection\CLSID]
@="{2C256447-3F0D-4CBB-9D12-575BB20CDA0A}"
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WOW6432Node\AppID\{2C256447-3F0D-4CBB-9D12-575BB20CDA0A}]
@="faultrep.dll"
"AccessPermission"=hex:01,00,04,80,60,00,00,00,70,00,00,00,00,00,00,00,14,00,\
00,00,02,00,4c,00,03,00,00,00,00,00,14,00,03,00,00,00,01,01,00,00,00,00,00,\
05,12,00,00,00,00,00,14,00,07,00,00,00,01,01,00,00,00,00,00,05,0a,00,00,00,\
00,00,14,00,03,00,00,00,01,01,00,00,00,00,00,05,04,00,00,00,cd,cd,cd,cd,cd,\
cd,cd,cd,01,02,00,00,00,00,00,05,20,00,00,00,20,02,00,00,01,02,00,00,00,00,\
00,05,20,00,00,00,20,02,00,00
"DllSurrogate"=""
"LaunchPermission"=hex:01,00,04,80,78,00,00,00,88,00,00,00,00,00,00,00,14,00,\
00,00,02,00,64,00,04,00,00,00,00,00,14,00,1f,00,00,00,01,01,00,00,00,00,00,\
05,12,00,00,00,00,00,18,00,1f,00,00,00,01,02,00,00,00,00,00,05,20,00,00,00,\
20,02,00,00,00,00,14,00,1f,00,00,00,01,01,00,00,00,00,00,05,04,00,00,00,00,\
00,14,00,0b,00,00,00,01,01,00,00,00,00,00,05,12,00,00,00,cd,cd,cd,cd,cd,cd,\
cd,cd,01,02,00,00,00,00,00,05,20,00,00,00,20,02,00,00,01,02,00,00,00,00,00,\
05,20,00,00,00,20,02,00,00
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WOW6432Node\CLSID\{2C256447-3F0D-4CBB-9D12-575BB20CDA0A}]
@="FaultrepElevatedDataCollection"
"AppId"="{2C256447-3F0D-4CBB-9D12-575BB20CDA0A}"
"LocalizedString"=hex(2):40,00,25,00,73,00,79,00,73,00,74,00,65,00,6d,00,72,00,\
6f,00,6f,00,74,00,25,00,5c,00,73,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,\
00,5c,00,66,00,61,00,75,00,6c,00,74,00,72,00,65,00,70,00,2e,00,64,00,6c,00,\
6c,00,2c,00,2d,00,35,00,30,00,30,00,30,00,00,00
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WOW6432Node\CLSID\{2C256447-3F0D-4CBB-9D12-575BB20CDA0A}\Elevation]
"Enabled"=dword:00000001
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WOW6432Node\CLSID\{2C256447-3F0D-4CBB-9D12-575BB20CDA0A}\InProcServer32]
@="C:\\Windows\\SysWOW64\\faultrep.dll"
"ThreadingModel"="Both"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\UAC\COMAutoApprovalList]
"{2C256447-3F0D-4CBB-9D12-575BB20CDA0A}"=dword:00000001
[HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Classes\AppID\{2C256447-3F0D-4CBB-9D12-575BB20CDA0A}]
@="faultrep.dll"
"AccessPermission"=hex:01,00,04,80,60,00,00,00,70,00,00,00,00,00,00,00,14,00,\
00,00,02,00,4c,00,03,00,00,00,00,00,14,00,03,00,00,00,01,01,00,00,00,00,00,\
05,12,00,00,00,00,00,14,00,07,00,00,00,01,01,00,00,00,00,00,05,0a,00,00,00,\
00,00,14,00,03,00,00,00,01,01,00,00,00,00,00,05,04,00,00,00,cd,cd,cd,cd,cd,\
cd,cd,cd,01,02,00,00,00,00,00,05,20,00,00,00,20,02,00,00,01,02,00,00,00,00,\
00,05,20,00,00,00,20,02,00,00
"DllSurrogate"=""
"LaunchPermission"=hex:01,00,04,80,78,00,00,00,88,00,00,00,00,00,00,00,14,00,\
00,00,02,00,64,00,04,00,00,00,00,00,14,00,1f,00,00,00,01,01,00,00,00,00,00,\
05,12,00,00,00,00,00,18,00,1f,00,00,00,01,02,00,00,00,00,00,05,20,00,00,00,\
20,02,00,00,00,00,14,00,1f,00,00,00,01,01,00,00,00,00,00,05,04,00,00,00,00,\
00,14,00,0b,00,00,00,01,01,00,00,00,00,00,05,12,00,00,00,cd,cd,cd,cd,cd,cd,\
cd,cd,01,02,00,00,00,00,00,05,20,00,00,00,20,02,00,00,01,02,00,00,00,00,00,\
05,20,00,00,00,20,02,00,00
[HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Classes\CLSID\{2C256447-3F0D-4CBB-9D12-575BB20CDA0A}]
@="FaultrepElevatedDataCollection"
"AppId"="{2C256447-3F0D-4CBB-9D12-575BB20CDA0A}"
"LocalizedString"=hex(2):40,00,25,00,73,00,79,00,73,00,74,00,65,00,6d,00,72,00,\
6f,00,6f,00,74,00,25,00,5c,00,73,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,\
00,5c,00,66,00,61,00,75,00,6c,00,74,00,72,00,65,00,70,00,2e,00,64,00,6c,00,\
6c,00,2c,00,2d,00,35,00,30,00,30,00,30,00,00,00
[HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Classes\CLSID\{2C256447-3F0D-4CBB-9D12-575BB20CDA0A}\Elevation]
"Enabled"=dword:00000001
[HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Classes\CLSID\{2C256447-3F0D-4CBB-9D12-575BB20CDA0A}\InProcServer32]
@="C:\\Windows\\SysWOW64\\faultrep.dll"
"ThreadingModel"="Both"