Windows Registry Editor Version 5.00

[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\safer\codeidentifiers\262144\Hashes\{ba366c9d-0187-4dfe-aa15-314d443ef889}]
"Description"="%TEMP%\\????.tmp.node"
"ItemSize"=hex(b):00,3e,1a,00,00,00,00,00
"HashAlg"=dword:00008003
"ItemData"=hex:c2,ff,31,12,25,67,a9,ad,ae,0b,90,ad,3f,cc,05,c1
"FriendlyName"="NOW TV Player executable"

[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\safer\codeidentifiers\262144\Hashes\{ba366c9d-0187-4dfe-aa15-314d443ef889}\SHA256]
"HashAlg"=dword:0000800c
"ItemData"=hex:8f,36,f2,43,e2,b6,84,52,80,74,a7,ae,f0,af,e0,53,3a,0f,b1,a9,ae,\
  8c,f5,57,d6,1a,23,03,aa,19,c9,7b

[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\safer\codeidentifiers\262144\Paths\{ba366c9d-0187-4dfe-aa15-314d443ef887}]
"Description"="%HKEY_CURRENT_USER\\Volatile Environment\\APPDATA%Sky Ticket/"
"ItemData"=hex(2):25,00,48,00,4b,00,45,00,59,00,5f,00,43,00,55,00,52,00,52,00,\
  45,00,4e,00,54,00,5f,00,55,00,53,00,45,00,52,00,5c,00,56,00,6f,00,6c,00,61,\
  00,74,00,69,00,6c,00,65,00,20,00,45,00,6e,00,76,00,69,00,72,00,6f,00,6e,00,\
  6d,00,65,00,6e,00,74,00,5c,00,41,00,50,00,50,00,44,00,41,00,54,00,41,00,25,\
  00,53,00,6b,00,79,00,20,00,54,00,69,00,63,00,6b,00,65,00,74,00,2f,00,00,00

[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\safer\codeidentifiers\262144\Paths\{ba366c9d-0187-4dfe-aa15-314d443ef888}]
"Description"="%HKEY_CURRENT_USER\\Volatile Environment\\LOCALAPPDATA%Cisco/VideoGuardPlayer/"
"ItemData"=hex(2):25,00,48,00,4b,00,45,00,59,00,5f,00,43,00,55,00,52,00,52,00,\
  45,00,4e,00,54,00,5f,00,55,00,53,00,45,00,52,00,5c,00,56,00,6f,00,6c,00,61,\
  00,74,00,69,00,6c,00,65,00,20,00,45,00,6e,00,76,00,69,00,72,00,6f,00,6e,00,\
  6d,00,65,00,6e,00,74,00,5c,00,4c,00,4f,00,43,00,41,00,4c,00,41,00,50,00,50,\
  00,44,00,41,00,54,00,41,00,25,00,43,00,69,00,73,00,63,00,6f,00,2f,00,56,00,\
  69,00,64,00,65,00,6f,00,47,00,75,00,61,00,72,00,64,00,50,00,6c,00,61,00,79,\
  00,65,00,72,00,2f,00,00,00

