Malware Report - Results

This report shows all the different areas TAZER analyzes for the sample: Host, Network Activity, and Detection.

Malware Search Criteria:
  • MD5 =1685de687627bc33d910cda1dd19c5f9

  • Malware Report - Results

    File MD5SumSHA1SUMSHA256SUMFUZZY HASHFile Size
    1685de687627bc33d910cda1dd19c5f9190e234144f9f03d83ccbe54137845185feee724705118dec104119447587acdc34393f6e72ba9118b1ca837a280a618c6c01ab71536:yOhplcsHv1X6n0BQnouy8SaHNnj6jBLEMxqEWw:yOXpHv1O0GoutS6Nj53248

    File Results

    File Name
    win%5F7%5Fwinsock%5Freeninstaller.exe

    SNORT Results

    Snort ClassSnort AlertCount
    N/ANo snort alerts generated0

    AV Results

    AV AlertAV Vendor
    N/ASymantec
    N/AMcAfee
    N/AKaspersky

    Folders (Added) - ICC Results

    PathFolder Name

    Files (Added) - ICC Results

    PathFile Name
    c:/WINDOWS/PrefetchAUTOIT3.EXE-32361418.pf
    c:/WINDOWS/PrefetchIPCONFIG.EXE-2395F30B.pf
    c:/WINDOWS/PrefetchMSG.EXE-0A99DAA3.pf
    c:/WINDOWS/PrefetchNBTSTAT.EXE-050A2164.pf
    c:/WINDOWS/PrefetchNETSH.EXE-085CFFDE.pf
    c:/WINDOWS/PrefetchREG.EXE-0D2A95F7.pf
    c:/WINDOWS/PrefetchREGSHOT.EXE-010A5EE6.pf
    c:/WINDOWS/PrefetchROUTE.EXE-371D32DE.pf
    c:/WINDOWS/PrefetchSANDNET.EXE-2012C478.pf
    c:/WINDOWS/PrefetchXCOPY.EXE-21FC761A.pf
    c:/WINDOWS/SoftwareDistribution/DataStore/Logstmp.edb
    c:/WINDOWS/TempPerflib_Perfdata_258.dat

    Files (Deleted) - ICC Results

    ActionPathFile Name

    Files (Changed) - ICC Results

    ActionPathFile Name
    modifiedc:/Documents and Settings/dmc73144ntuser.dat.LOG
    modifiedc:/WINDOWS/PrefetchCMD.EXE-087B4001.pf
    modifiedc:/WINDOWS/PrefetchHSTART.EXE-221D72BF.pf
    modifiedc:/WINDOWS/PrefetchSH.EXE-00254D2B.pf
    modifiedc:/WINDOWS/PrefetchSLEEP.EXE-094A3D2A.pf
    modifiedc:/WINDOWS/PrefetchSSHD.EXE-298CA236.pf
    modifiedc:/WINDOWS/PrefetchSWITCH.EXE-0496EC21.pf
    modifiedc:/WINDOWS/PrefetchWMIPRVSE.EXE-28F301A9.pf
    modifiedc:/WINDOWS/PrefetchWUAUCLT.EXE-399A8E72.pf
    modifiedc:/WINDOWS/SoftwareDistribution/DataStoreDataStore.edb
    modifiedc:/WINDOWS/SoftwareDistribution/DataStore/Logsedb.chk
    modifiedc:/WINDOWS/SoftwareDistribution/DataStore/Logsedb.log
    modifiedc:/WINDOWS/system32/configsoftware.LOG
    modifiedc:/WINDOWS/system32/configSYSTEM
    modifiedc:/WINDOWS/system32/configsystem.LOG
    modifiedc:/WINDOWS/system32/drivers/etchosts
    modifiedc:/WINDOWSWindowsUpdate.log

    Registry Keys (Added) - ICC Results

    ActionPath
    addedHKLM/SOFTWARE/Microsoft/Tracing/FWCFG
    addedHKLM/SOFTWARE/Microsoft/Windows/CurrentVersion/WindowsUpdate/Reporting/RebootWatch
    addedHKLM/SYSTEM/ControlSet001/Services/Winsock/Setup Migration/Providers/Tcpip6
    addedHKLM/SYSTEM/ControlSet001/Services/WinSock2/Parameters/NameSpace_Catalog5/Catalog_Entries/000000000004
    addedHKLM/SYSTEM/ControlSet001/Services/WinSock2/Parameters/NameSpace_Catalog5/Catalog_Entries/000000000005
    addedHKLM/SYSTEM/ControlSet001/Services/WinSock2/Parameters/NameSpace_Catalog5/Catalog_Entries/000000000006
    addedHKLM/SYSTEM/ControlSet001/Services/WinSock2/Parameters/Protocol_Catalog9/Catalog_Entries/000000000012
    addedHKLM/SYSTEM/ControlSet001/Services/WinSock2/Parameters/Protocol_Catalog9/Catalog_Entries/000000000013
    addedHKLM/SYSTEM/ControlSet001/Services/WinSock2/Parameters/Protocol_Catalog9/Catalog_Entries/000000000014
    addedHKLM/SYSTEM/ControlSet001/Services/WinSock2/Parameters/AppId_Catalog
    addedHKLM/SYSTEM/ControlSet001/Services/WinSock2/Parameters/AppId_Catalog/06EBDCB1
    addedHKLM/SYSTEM/ControlSet001/Services/WinSock2/Parameters/AppId_Catalog/2C69D9F1-0F0A6651
    addedHKLM/SYSTEM/ControlSet001/Services/WinSock2/Parameters/AppId_Catalog/2C69D9F1-1F4968A0
    addedHKLM/SYSTEM/ControlSet001/Services/WinSock2/Parameters/AppId_Catalog/2C69D9F1-215FDCCA
    addedHKLM/SYSTEM/ControlSet001/Services/WinSock2/Parameters/AppId_Catalog/2C69D9F1-34FFF7C0
    addedHKLM/SYSTEM/ControlSet001/Services/WinSock2/Parameters/AppId_Catalog/343305C9
    addedHKLM/SYSTEM/ControlSet001/Services/TCPIP6
    addedHKLM/SYSTEM/ControlSet001/Services/TCPIP6/Linkage
    addedHKLM/SYSTEM/ControlSet001/Services/TCPIP6/Parameters
    addedHKLM/SYSTEM/ControlSet001/Services/TCPIP6/Parameters/Interfaces
    addedHKLM/SYSTEM/ControlSet001/Services/TCPIP6/Parameters/Winsock
    addedHKLM/SYSTEM/CurrentControlSet/Services/Winsock/Setup Migration/Providers/Tcpip6
    addedHKLM/SYSTEM/CurrentControlSet/Services/WinSock2/Parameters/NameSpace_Catalog5/Catalog_Entries/000000000004
    addedHKLM/SYSTEM/CurrentControlSet/Services/WinSock2/Parameters/NameSpace_Catalog5/Catalog_Entries/000000000005
    addedHKLM/SYSTEM/CurrentControlSet/Services/WinSock2/Parameters/NameSpace_Catalog5/Catalog_Entries/000000000006
    addedHKLM/SYSTEM/CurrentControlSet/Services/WinSock2/Parameters/Protocol_Catalog9/Catalog_Entries/000000000012
    addedHKLM/SYSTEM/CurrentControlSet/Services/WinSock2/Parameters/Protocol_Catalog9/Catalog_Entries/000000000013
    addedHKLM/SYSTEM/CurrentControlSet/Services/WinSock2/Parameters/Protocol_Catalog9/Catalog_Entries/000000000014
    addedHKLM/SYSTEM/CurrentControlSet/Services/WinSock2/Parameters/AppId_Catalog
    addedHKLM/SYSTEM/CurrentControlSet/Services/WinSock2/Parameters/AppId_Catalog/06EBDCB1
    addedHKLM/SYSTEM/CurrentControlSet/Services/WinSock2/Parameters/AppId_Catalog/2C69D9F1-0F0A6651
    addedHKLM/SYSTEM/CurrentControlSet/Services/WinSock2/Parameters/AppId_Catalog/2C69D9F1-1F4968A0
    addedHKLM/SYSTEM/CurrentControlSet/Services/WinSock2/Parameters/AppId_Catalog/2C69D9F1-215FDCCA
    addedHKLM/SYSTEM/CurrentControlSet/Services/WinSock2/Parameters/AppId_Catalog/2C69D9F1-34FFF7C0
    addedHKLM/SYSTEM/CurrentControlSet/Services/WinSock2/Parameters/AppId_Catalog/343305C9
    addedHKLM/SYSTEM/CurrentControlSet/Services/TCPIP6
    addedHKLM/SYSTEM/CurrentControlSet/Services/TCPIP6/Linkage
    addedHKLM/SYSTEM/CurrentControlSet/Services/TCPIP6/Parameters
    addedHKLM/SYSTEM/CurrentControlSet/Services/TCPIP6/Parameters/Interfaces
    addedHKLM/SYSTEM/CurrentControlSet/Services/TCPIP6/Parameters/Winsock

    Registry Values (Added) - ICC Results

    ActionPathVal_NameVal_Data
    addedHKLM/SOFTWARE/Microsoft/Tracing/FWCFGEnableFileTracing0x00000000
    addedHKLM/SOFTWARE/Microsoft/Tracing/FWCFGEnableConsoleTracing0x00000000
    addedHKLM/SOFTWARE/Microsoft/Tracing/FWCFGFileTracingMask0xFFFF0000
    addedHKLM/SOFTWARE/Microsoft/Tracing/FWCFGConsoleTracingMask0xFFFF0000
    addedHKLM/SOFTWARE/Microsoft/Tracing/FWCFGMaxFileSize0x00100000
    addedHKLM/SOFTWARE/Microsoft/Tracing/FWCFGFileDirectory"%windir%tracing"
    addedHKLM/SYSTEM/ControlSet001/Services/TcpipBootFlags0x00000001
    addedHKLM/SYSTEM/ControlSet001/Services/TcpipNdisMajorVersion0x00000006
    addedHKLM/SYSTEM/ControlSet001/Services/TcpipNdisMinorVersion0x00000014
    addedHKLM/SYSTEM/ControlSet001/Services/Tcpip/PerformanceLibrary"%SystemRoot%System32Perfctrs.dll"
    addedHKLM/SYSTEM/ControlSet001/Services/Winsock/Setup Migration/Providers/Tcpip6WinSock 1.1 Provider Data66 10 00 00 17 00 00 00 1C 00 00 00 1C 00 00 00 01 00 00 00 06 00 00 00 00 00 00
    addedHKLM/SYSTEM/ControlSet001/Services/Winsock/Setup Migration/Providers/Tcpip6WinSock 2.0 Provider IDC0 B0 EA F9 D4 26 D0 11 BB BF 00 AA 00 6C 34 E4
    addedHKLM/SYSTEM/ControlSet001/Services/WinSock2/ParametersNameSpace_Callout"%SystemRoot%System32fwpuclnt.dll"
    addedHKLM/SYSTEM/ControlSet001/Services/WinSock2/ParametersAutodialDLL"rasadhlp.dll"
    addedHKLM/SYSTEM/ControlSet001/Services/WinSock2/Parameters/NameSpace_Catalog5/Catalog_Entries/000000000001ProviderInfo
    addedHKLM/SYSTEM/ControlSet001/Services/WinSock2/Parameters/NameSpace_Catalog5/Catalog_Entries/000000000002ProviderInfo
    addedHKLM/SYSTEM/ControlSet001/Services/WinSock2/Parameters/NameSpace_Catalog5/Catalog_Entries/000000000003ProviderInfo
    addedHKLM/SYSTEM/ControlSet001/Services/WinSock2/Parameters/NameSpace_Catalog5/Catalog_Entries/000000000004LibraryPath"%SystemRoot%system32napinsp.dll"
    addedHKLM/SYSTEM/ControlSet001/Services/WinSock2/Parameters/NameSpace_Catalog5/Catalog_Entries/000000000004DisplayString"@%SystemRoot%system32napinsp.dll,-1000"
    addedHKLM/SYSTEM/ControlSet001/Services/WinSock2/Parameters/NameSpace_Catalog5/Catalog_Entries/000000000004ProviderIdA2 CB 4A 96 BC B2 EB 40 8C 6A A6 DB 40 16 1C AE
    addedHKLM/SYSTEM/ControlSet001/Services/WinSock2/Parameters/NameSpace_Catalog5/Catalog_Entries/000000000004SupportedNameSpace0x00000025
    addedHKLM/SYSTEM/ControlSet001/Services/WinSock2/Parameters/NameSpace_Catalog5/Catalog_Entries/000000000004Enabled0x00000001
    addedHKLM/SYSTEM/ControlSet001/Services/WinSock2/Parameters/NameSpace_Catalog5/Catalog_Entries/000000000004Version0x00000000
    addedHKLM/SYSTEM/ControlSet001/Services/WinSock2/Parameters/NameSpace_Catalog5/Catalog_Entries/000000000004StoresServiceClassInfo0x00000000
    addedHKLM/SYSTEM/ControlSet001/Services/WinSock2/Parameters/NameSpace_Catalog5/Catalog_Entries/000000000004ProviderInfo
    addedHKLM/SYSTEM/ControlSet001/Services/WinSock2/Parameters/NameSpace_Catalog5/Catalog_Entries/000000000005LibraryPath"%SystemRoot%system32pnrpnsp.dll"
    addedHKLM/SYSTEM/ControlSet001/Services/WinSock2/Parameters/NameSpace_Catalog5/Catalog_Entries/000000000005DisplayString"@%SystemRoot%system32pnrpnsp.dll,-1000"
    addedHKLM/SYSTEM/ControlSet001/Services/WinSock2/Parameters/NameSpace_Catalog5/Catalog_Entries/000000000005ProviderIdCE 89 FE 03 6D 76 76 49 B9 C1 BB 9B C4 2C 7B 4D
    addedHKLM/SYSTEM/ControlSet001/Services/WinSock2/Parameters/NameSpace_Catalog5/Catalog_Entries/000000000005SupportedNameSpace0x00000027
    addedHKLM/SYSTEM/ControlSet001/Services/WinSock2/Parameters/NameSpace_Catalog5/Catalog_Entries/000000000005Enabled0x00000001
    addedHKLM/SYSTEM/ControlSet001/Services/WinSock2/Parameters/NameSpace_Catalog5/Catalog_Entries/000000000005Version0x00000000
    addedHKLM/SYSTEM/ControlSet001/Services/WinSock2/Parameters/NameSpace_Catalog5/Catalog_Entries/000000000005StoresServiceClassInfo0x00000000
    addedHKLM/SYSTEM/ControlSet001/Services/WinSock2/Parameters/NameSpace_Catalog5/Catalog_Entries/000000000005ProviderInfo
    addedHKLM/SYSTEM/ControlSet001/Services/WinSock2/Parameters/NameSpace_Catalog5/Catalog_Entries/000000000006LibraryPath"%SystemRoot%system32pnrpnsp.dll"
    addedHKLM/SYSTEM/ControlSet001/Services/WinSock2/Parameters/NameSpace_Catalog5/Catalog_Entries/000000000006DisplayString"@%SystemRoot%system32pnrpnsp.dll,-1001"
    addedHKLM/SYSTEM/ControlSet001/Services/WinSock2/Parameters/NameSpace_Catalog5/Catalog_Entries/000000000006ProviderIdCD 89 FE 03 6D 76 76 49 B9 C1 BB 9B C4 2C 7B 4D
    addedHKLM/SYSTEM/ControlSet001/Services/WinSock2/Parameters/NameSpace_Catalog5/Catalog_Entries/000000000006SupportedNameSpace0x00000026
    addedHKLM/SYSTEM/ControlSet001/Services/WinSock2/Parameters/NameSpace_Catalog5/Catalog_Entries/000000000006Enabled0x00000001
    addedHKLM/SYSTEM/ControlSet001/Services/WinSock2/Parameters/NameSpace_Catalog5/Catalog_Entries/000000000006Version0x00000000
    addedHKLM/SYSTEM/ControlSet001/Services/WinSock2/Parameters/NameSpace_Catalog5/Catalog_Entries/000000000006StoresServiceClassInfo0x00000000
    addedHKLM/SYSTEM/ControlSet001/Services/WinSock2/Parameters/NameSpace_Catalog5/Catalog_Entries/000000000006ProviderInfo
    addedHKLM/SYSTEM/ControlSet001/Services/WinSock2/Parameters/Protocol_Catalog9/Catalog_Entries/000000000012PackedCatalogItem25 53 79 73 74 65 6D 52 6F 6F 74 25 5C 73 79 73 74 65 6D 33 32 5C 6D 73 77 73 6F
    addedHKLM/SYSTEM/ControlSet001/Services/WinSock2/Parameters/Protocol_Catalog9/Catalog_Entries/000000000013PackedCatalogItem25 53 79 73 74 65 6D 52 6F 6F 74 25 5C 73 79 73 74 65 6D 33 32 5C 72 73 76 70 73
    addedHKLM/SYSTEM/ControlSet001/Services/WinSock2/Parameters/Protocol_Catalog9/Catalog_Entries/000000000014PackedCatalogItem25 53 79 73 74 65 6D 52 6F 6F 74 25 5C 73 79 73 74 65 6D 33 32 5C 72 73 76 70 73
    addedHKLM/SYSTEM/ControlSet001/Services/WinSock2/Parameters/AppId_Catalog/343305C9AppFullPath "C:/Windows/system32/lsass.exe"
    addedHKLM/SYSTEM/ControlSet001/Services/WinSock2/Parameters/AppId_Catalog/343305C9PermittedLspCategories0x80000000
    addedHKLM/SYSTEM/ControlSet001/Services/WinSock2/Parameters/AppId_Catalog/2C69D9F1-34FFF7C0AppFullPath "C:/Windows/system32/svchost.exe"
    addedHKLM/SYSTEM/ControlSet001/Services/WinSock2/Parameters/AppId_Catalog/2C69D9F1-34FFF7C0AppArgs"-k LocalService"
    addedHKLM/SYSTEM/ControlSet001/Services/WinSock2/Parameters/AppId_Catalog/2C69D9F1-34FFF7C0PermittedLspCategories0x80000044
    addedHKLM/SYSTEM/ControlSet001/Services/WinSock2/Parameters/AppId_Catalog/2C69D9F1-215FDCCAAppFullPath "C:/Windows/system32/svchost.exe"
    addedHKLM/SYSTEM/ControlSet001/Services/WinSock2/Parameters/AppId_Catalog/2C69D9F1-215FDCCAAppArgs"-k LocalServiceAndNoImpersonation"
    addedHKLM/SYSTEM/ControlSet001/Services/WinSock2/Parameters/AppId_Catalog/2C69D9F1-215FDCCAPermittedLspCategories0x80000044
    addedHKLM/SYSTEM/ControlSet001/Services/WinSock2/Parameters/AppId_Catalog/2C69D9F1-1F4968A0AppFullPath "C:/Windows/system32/svchost.exe"
    addedHKLM/SYSTEM/ControlSet001/Services/WinSock2/Parameters/AppId_Catalog/2C69D9F1-1F4968A0AppArgs"-k LocalServiceNetworkRestricted"
    addedHKLM/SYSTEM/ControlSet001/Services/WinSock2/Parameters/AppId_Catalog/2C69D9F1-1F4968A0PermittedLspCategories0x80000040
    addedHKLM/SYSTEM/ControlSet001/Services/WinSock2/Parameters/AppId_Catalog/2C69D9F1-0F0A6651AppFullPath "C:/Windows/system32/svchost.exe"
    addedHKLM/SYSTEM/ControlSet001/Services/WinSock2/Parameters/AppId_Catalog/2C69D9F1-0F0A6651AppArgs"-k NetworkService"
    addedHKLM/SYSTEM/ControlSet001/Services/WinSock2/Parameters/AppId_Catalog/2C69D9F1-0F0A6651PermittedLspCategories0x80000044
    addedHKLM/SYSTEM/ControlSet001/Services/WinSock2/Parameters/AppId_Catalog/06EBDCB1AppFullPath "C:/Windows/system32/wininit.exe"
    addedHKLM/SYSTEM/ControlSet001/Services/WinSock2/Parameters/AppId_Catalog/06EBDCB1PermittedLspCategories0x80000040
    addedHKLM/SYSTEM/ControlSet001/Services/TCPIP6/Parameters/WinsockUseDelayedAcceptance0x00000000
    addedHKLM/SYSTEM/ControlSet001/Services/TCPIP6/Parameters/WinsockHelperDllName"%SystemRoot%System32wship6.dll"
    addedHKLM/SYSTEM/ControlSet001/Services/TCPIP6/Parameters/WinsockMaxSockAddrLength0x0000001C
    addedHKLM/SYSTEM/ControlSet001/Services/TCPIP6/Parameters/WinsockMinSockAddrLength0x0000001C
    addedHKLM/SYSTEM/ControlSet001/Services/TCPIP6/Parameters/WinsockMapping08 00 00 00 03 00 00 00 17 00 00 00 01 00 00 00 06 00 00 00 17 00 00 00 01 00 00
    addedHKLM/SYSTEM/ControlSet001/Services/TCPIP6/ParametersDhcpv6DUID00 01 00 01 15 30 57 6B 08 00 27 10 1D D9
    addedHKLM/SYSTEM/ControlSet001/Services/TCPIP6/LinkageRoute{9CB52EDF-596B-47D0-A4D4-DB97F0D73500}{40460492-6FD8-4919-A298-6B49AC95B3AD}{9E7
    addedHKLM/SYSTEM/ControlSet001/Services/TCPIP6NdisMajorVersion0x00000006
    addedHKLM/SYSTEM/ControlSet001/Services/TCPIP6NdisMinorVersion0x00000014
    addedHKLM/SYSTEM/ControlSet001/Services/TCPIP6Type0x00000001
    addedHKLM/SYSTEM/ControlSet001/Services/TCPIP6Start0x00000003
    addedHKLM/SYSTEM/ControlSet001/Services/TCPIP6ErrorControl0x00000001
    addedHKLM/SYSTEM/ControlSet001/Services/TCPIP6ImagePath"system32DRIVERStcpip.sys"
    addedHKLM/SYSTEM/ControlSet001/Services/TCPIP6TextModeFlags0x00000001
    addedHKLM/SYSTEM/CurrentControlSet/Services/TcpipBootFlags0x00000001
    addedHKLM/SYSTEM/CurrentControlSet/Services/TcpipNdisMajorVersion0x00000006
    addedHKLM/SYSTEM/CurrentControlSet/Services/TcpipNdisMinorVersion0x00000014
    addedHKLM/SYSTEM/CurrentControlSet/Services/Tcpip/PerformanceLibrary"%SystemRoot%System32Perfctrs.dll"
    addedHKLM/SYSTEM/CurrentControlSet/Services/Winsock/Setup Migration/Providers/Tcpip6WinSock 1.1 Provider Data66 10 00 00 17 00 00 00 1C 00 00 00 1C 00 00 00 01 00 00 00 06 00 00 00 00 00 00
    addedHKLM/SYSTEM/CurrentControlSet/Services/Winsock/Setup Migration/Providers/Tcpip6WinSock 2.0 Provider IDC0 B0 EA F9 D4 26 D0 11 BB BF 00 AA 00 6C 34 E4
    addedHKLM/SYSTEM/CurrentControlSet/Services/WinSock2/ParametersNameSpace_Callout"%SystemRoot%System32fwpuclnt.dll"
    addedHKLM/SYSTEM/CurrentControlSet/Services/WinSock2/ParametersAutodialDLL"rasadhlp.dll"
    addedHKLM/SYSTEM/CurrentControlSet/Services/WinSock2/Parameters/NameSpace_Catalog5/Catalog_Entries/000000000001ProviderInfo
    addedHKLM/SYSTEM/CurrentControlSet/Services/WinSock2/Parameters/NameSpace_Catalog5/Catalog_Entries/000000000002ProviderInfo
    addedHKLM/SYSTEM/CurrentControlSet/Services/WinSock2/Parameters/NameSpace_Catalog5/Catalog_Entries/000000000003ProviderInfo
    addedHKLM/SYSTEM/CurrentControlSet/Services/WinSock2/Parameters/NameSpace_Catalog5/Catalog_Entries/000000000004LibraryPath"%SystemRoot%system32napinsp.dll"
    addedHKLM/SYSTEM/CurrentControlSet/Services/WinSock2/Parameters/NameSpace_Catalog5/Catalog_Entries/000000000004DisplayString"@%SystemRoot%system32napinsp.dll,-1000"
    addedHKLM/SYSTEM/CurrentControlSet/Services/WinSock2/Parameters/NameSpace_Catalog5/Catalog_Entries/000000000004ProviderIdA2 CB 4A 96 BC B2 EB 40 8C 6A A6 DB 40 16 1C AE
    addedHKLM/SYSTEM/CurrentControlSet/Services/WinSock2/Parameters/NameSpace_Catalog5/Catalog_Entries/000000000004SupportedNameSpace0x00000025
    addedHKLM/SYSTEM/CurrentControlSet/Services/WinSock2/Parameters/NameSpace_Catalog5/Catalog_Entries/000000000004Enabled0x00000001
    addedHKLM/SYSTEM/CurrentControlSet/Services/WinSock2/Parameters/NameSpace_Catalog5/Catalog_Entries/000000000004Version0x00000000
    addedHKLM/SYSTEM/CurrentControlSet/Services/WinSock2/Parameters/NameSpace_Catalog5/Catalog_Entries/000000000004StoresServiceClassInfo0x00000000
    addedHKLM/SYSTEM/CurrentControlSet/Services/WinSock2/Parameters/NameSpace_Catalog5/Catalog_Entries/000000000004ProviderInfo
    addedHKLM/SYSTEM/CurrentControlSet/Services/WinSock2/Parameters/NameSpace_Catalog5/Catalog_Entries/000000000005LibraryPath"%SystemRoot%system32pnrpnsp.dll"
    addedHKLM/SYSTEM/CurrentControlSet/Services/WinSock2/Parameters/NameSpace_Catalog5/Catalog_Entries/000000000005DisplayString"@%SystemRoot%system32pnrpnsp.dll,-1000"
    addedHKLM/SYSTEM/CurrentControlSet/Services/WinSock2/Parameters/NameSpace_Catalog5/Catalog_Entries/000000000005ProviderIdCE 89 FE 03 6D 76 76 49 B9 C1 BB 9B C4 2C 7B 4D
    addedHKLM/SYSTEM/CurrentControlSet/Services/WinSock2/Parameters/NameSpace_Catalog5/Catalog_Entries/000000000005SupportedNameSpace0x00000027
    addedHKLM/SYSTEM/CurrentControlSet/Services/WinSock2/Parameters/NameSpace_Catalog5/Catalog_Entries/000000000005Enabled0x00000001
    addedHKLM/SYSTEM/CurrentControlSet/Services/WinSock2/Parameters/NameSpace_Catalog5/Catalog_Entries/000000000005Version0x00000000
    addedHKLM/SYSTEM/CurrentControlSet/Services/WinSock2/Parameters/NameSpace_Catalog5/Catalog_Entries/000000000005StoresServiceClassInfo0x00000000
    addedHKLM/SYSTEM/CurrentControlSet/Services/WinSock2/Parameters/NameSpace_Catalog5/Catalog_Entries/000000000005ProviderInfo
    addedHKLM/SYSTEM/CurrentControlSet/Services/WinSock2/Parameters/NameSpace_Catalog5/Catalog_Entries/000000000006LibraryPath"%SystemRoot%system32pnrpnsp.dll"
    addedHKLM/SYSTEM/CurrentControlSet/Services/WinSock2/Parameters/NameSpace_Catalog5/Catalog_Entries/000000000006DisplayString"@%SystemRoot%system32pnrpnsp.dll,-1001"
    addedHKLM/SYSTEM/CurrentControlSet/Services/WinSock2/Parameters/NameSpace_Catalog5/Catalog_Entries/000000000006ProviderIdCD 89 FE 03 6D 76 76 49 B9 C1 BB 9B C4 2C 7B 4D
    addedHKLM/SYSTEM/CurrentControlSet/Services/WinSock2/Parameters/NameSpace_Catalog5/Catalog_Entries/000000000006SupportedNameSpace0x00000026
    addedHKLM/SYSTEM/CurrentControlSet/Services/WinSock2/Parameters/NameSpace_Catalog5/Catalog_Entries/000000000006Enabled0x00000001
    addedHKLM/SYSTEM/CurrentControlSet/Services/WinSock2/Parameters/NameSpace_Catalog5/Catalog_Entries/000000000006Version0x00000000
    addedHKLM/SYSTEM/CurrentControlSet/Services/WinSock2/Parameters/NameSpace_Catalog5/Catalog_Entries/000000000006StoresServiceClassInfo0x00000000
    addedHKLM/SYSTEM/CurrentControlSet/Services/WinSock2/Parameters/NameSpace_Catalog5/Catalog_Entries/000000000006ProviderInfo
    addedHKLM/SYSTEM/CurrentControlSet/Services/WinSock2/Parameters/Protocol_Catalog9/Catalog_Entries/000000000012PackedCatalogItem25 53 79 73 74 65 6D 52 6F 6F 74 25 5C 73 79 73 74 65 6D 33 32 5C 6D 73 77 73 6F
    addedHKLM/SYSTEM/CurrentControlSet/Services/WinSock2/Parameters/Protocol_Catalog9/Catalog_Entries/000000000013PackedCatalogItem25 53 79 73 74 65 6D 52 6F 6F 74 25 5C 73 79 73 74 65 6D 33 32 5C 72 73 76 70 73
    addedHKLM/SYSTEM/CurrentControlSet/Services/WinSock2/Parameters/Protocol_Catalog9/Catalog_Entries/000000000014PackedCatalogItem25 53 79 73 74 65 6D 52 6F 6F 74 25 5C 73 79 73 74 65 6D 33 32 5C 72 73 76 70 73
    addedHKLM/SYSTEM/CurrentControlSet/Services/WinSock2/Parameters/AppId_Catalog/343305C9AppFullPath "C:/Windows/system32/lsass.exe"
    addedHKLM/SYSTEM/CurrentControlSet/Services/WinSock2/Parameters/AppId_Catalog/343305C9PermittedLspCategories0x80000000
    addedHKLM/SYSTEM/CurrentControlSet/Services/WinSock2/Parameters/AppId_Catalog/2C69D9F1-34FFF7C0AppFullPath "C:/Windows/system32/svchost.exe"
    addedHKLM/SYSTEM/CurrentControlSet/Services/WinSock2/Parameters/AppId_Catalog/2C69D9F1-34FFF7C0AppArgs"-k LocalService"
    addedHKLM/SYSTEM/CurrentControlSet/Services/WinSock2/Parameters/AppId_Catalog/2C69D9F1-34FFF7C0PermittedLspCategories0x80000044
    addedHKLM/SYSTEM/CurrentControlSet/Services/WinSock2/Parameters/AppId_Catalog/2C69D9F1-215FDCCAAppFullPath "C:/Windows/system32/svchost.exe"
    addedHKLM/SYSTEM/CurrentControlSet/Services/WinSock2/Parameters/AppId_Catalog/2C69D9F1-215FDCCAAppArgs"-k LocalServiceAndNoImpersonation"
    addedHKLM/SYSTEM/CurrentControlSet/Services/WinSock2/Parameters/AppId_Catalog/2C69D9F1-215FDCCAPermittedLspCategories0x80000044
    addedHKLM/SYSTEM/CurrentControlSet/Services/WinSock2/Parameters/AppId_Catalog/2C69D9F1-1F4968A0AppFullPath "C:/Windows/system32/svchost.exe"
    addedHKLM/SYSTEM/CurrentControlSet/Services/WinSock2/Parameters/AppId_Catalog/2C69D9F1-1F4968A0AppArgs"-k LocalServiceNetworkRestricted"
    addedHKLM/SYSTEM/CurrentControlSet/Services/WinSock2/Parameters/AppId_Catalog/2C69D9F1-1F4968A0PermittedLspCategories0x80000040
    addedHKLM/SYSTEM/CurrentControlSet/Services/WinSock2/Parameters/AppId_Catalog/2C69D9F1-0F0A6651AppFullPath "C:/Windows/system32/svchost.exe"
    addedHKLM/SYSTEM/CurrentControlSet/Services/WinSock2/Parameters/AppId_Catalog/2C69D9F1-0F0A6651AppArgs"-k NetworkService"
    addedHKLM/SYSTEM/CurrentControlSet/Services/WinSock2/Parameters/AppId_Catalog/2C69D9F1-0F0A6651PermittedLspCategories0x80000044
    addedHKLM/SYSTEM/CurrentControlSet/Services/WinSock2/Parameters/AppId_Catalog/06EBDCB1AppFullPath "C:/Windows/system32/wininit.exe"
    addedHKLM/SYSTEM/CurrentControlSet/Services/WinSock2/Parameters/AppId_Catalog/06EBDCB1PermittedLspCategories0x80000040
    addedHKLM/SYSTEM/CurrentControlSet/Services/TCPIP6/Parameters/WinsockUseDelayedAcceptance0x00000000
    addedHKLM/SYSTEM/CurrentControlSet/Services/TCPIP6/Parameters/WinsockHelperDllName"%SystemRoot%System32wship6.dll"
    addedHKLM/SYSTEM/CurrentControlSet/Services/TCPIP6/Parameters/WinsockMaxSockAddrLength0x0000001C
    addedHKLM/SYSTEM/CurrentControlSet/Services/TCPIP6/Parameters/WinsockMinSockAddrLength0x0000001C
    addedHKLM/SYSTEM/CurrentControlSet/Services/TCPIP6/Parameters/WinsockMapping08 00 00 00 03 00 00 00 17 00 00 00 01 00 00 00 06 00 00 00 17 00 00 00 01 00 00
    addedHKLM/SYSTEM/CurrentControlSet/Services/TCPIP6/ParametersDhcpv6DUID00 01 00 01 15 30 57 6B 08 00 27 10 1D D9
    addedHKLM/SYSTEM/CurrentControlSet/Services/TCPIP6/LinkageRoute{9CB52EDF-596B-47D0-A4D4-DB97F0D73500}{40460492-6FD8-4919-A298-6B49AC95B3AD}{9E7
    addedHKLM/SYSTEM/CurrentControlSet/Services/TCPIP6NdisMajorVersion0x00000006
    addedHKLM/SYSTEM/CurrentControlSet/Services/TCPIP6NdisMinorVersion0x00000014
    addedHKLM/SYSTEM/CurrentControlSet/Services/TCPIP6Type0x00000001
    addedHKLM/SYSTEM/CurrentControlSet/Services/TCPIP6Start0x00000003
    addedHKLM/SYSTEM/CurrentControlSet/Services/TCPIP6ErrorControl0x00000001
    addedHKLM/SYSTEM/CurrentControlSet/Services/TCPIP6ImagePath"system32DRIVERStcpip.sys"
    addedHKLM/SYSTEM/CurrentControlSet/Services/TCPIP6TextModeFlags0x00000001
    addedHKU/S-1-5-21-1844237615-562591055-839522115-1004/Software/Microsoft/Windows/ShellNoRoam/MUICacheC://Documents and Settings//dmc73144//Local Settings//Temp//1.tmp//winsock.bat "winsock"

    Registry Values (Deleted) - ICC Results

    ActionPathVal_NameVal_TypeMod_Val_TypeVal_DataMod_Val_Data
    deletedHKLM/SYSTEM/ControlSet001/Services/Tcpip/Performance/Library: "Perfctrs.dll" N/A
    deletedHKLM/SYSTEM/CurrentControlSet/Services/Tcpip/Performance/Library: "Perfctrs.dll" N/A

    Registry Values (Changed) - ICC Results

    ActionPathVal_NameVal_DataMod_Val_Data
    modifiedHKLM/SOFTWARE/Microsoft/Cryptography/RNGSeed72 94 74 79 6A B3 E3 04 38 95 AF 7C A3 61 51 3F 6E 43 8A 3F 50 EB 2F 5F 99 96 8766 5C 9B 6B 04 B6 6C E3 98 7F 36 37 BB 6A 89 85 99 B0 4D 7A 28 95 79 8A 18 75 DA
    modifiedHKLM/SYSTEM/ControlSet001/Services/Eventlog/Application/ESENTEventMessageFile"c"C:WINDOWSsystem32ESENT.dll"
    modifiedHKLM/SYSTEM/ControlSet001/Services/Eventlog/Application/ESENTCategoryMessageFile"c"C:WINDOWSsystem32ESENT.dll"
    modifiedHKLM/SYSTEM/ControlSet001/Services/TcpipStart0x000000010x00000000
    modifiedHKLM/SYSTEM/ControlSet001/Services/TcpipImagePath"system32DRIVERStcpip.sys""System32driverstcpip.sys"
    modifiedHKLM/SYSTEM/ControlSet001/Services/TcpipDisplayName"TCP/IP Protocol Driver""@%SystemRoot%system32tcpipcfg.dll,-50003"
    modifiedHKLM/SYSTEM/ControlSet001/Services/TcpipDescription"TCP/IP Protocol Driver""@%SystemRoot%system32tcpipcfg.dll,-50003"
    modifiedHKLM/SYSTEM/ControlSet001/Services/Tcpip/LinkageRoute{9B7E3E9B-6887-4894-8EE4-B4EFDC3EBE75}NdisWanIp{9E702D9C-6C82-499E-A802-29EC61B09C31}
    modifiedHKLM/SYSTEM/ControlSet001/Services/Tcpip/Parameters/WinsockMapping0B 00 00 00 03 00 00 00 02 00 00 00 01 00 00 00 06 00 00 00 02 00 00 00 01 00 0008 00 00 00 03 00 00 00 02 00 00 00 01 00 00 00 06 00 00 00 02 00 00 00 01 00 00
    modifiedHKLM/SYSTEM/ControlSet001/Services/Tcpip/PerformanceObject List"502 510 546 582 638 658""502 510 546 548 582 638 658 1530 1532 1534"
    modifiedHKLM/SYSTEM/ControlSet001/Services/WinSock2/Parameters/NameSpace_Catalog5Num_Catalog_Entries0x000000030x00000006
    modifiedHKLM/SYSTEM/ControlSet001/Services/WinSock2/Parameters/NameSpace_Catalog5Serial_Access_Num0x000000040x00000008
    modifiedHKLM/SYSTEM/ControlSet001/Services/WinSock2/Parameters/NameSpace_Catalog5/Catalog_Entries/000000000001LibraryPath"%SystemRoot%System32mswsock.dll""%SystemRoot%system32NLAapi.dll"
    modifiedHKLM/SYSTEM/ControlSet001/Services/WinSock2/Parameters/NameSpace_Catalog5/Catalog_Entries/000000000001DisplayString"Tcpip""@%SystemRoot%system32nlasvc.dll,-1000"
    modifiedHKLM/SYSTEM/ControlSet001/Services/WinSock2/Parameters/NameSpace_Catalog5/Catalog_Entries/000000000001ProviderId40 9D 05 22 9E 7E CF 11 AE 5A 00 AA 00 A7 11 2B3A 24 42 66 A8 3B A6 4A BA A5 2E 0B D7 1F DD 83
    modifiedHKLM/SYSTEM/ControlSet001/Services/WinSock2/Parameters/NameSpace_Catalog5/Catalog_Entries/000000000001SupportedNameSpace0x0000000C0x0000000F
    modifiedHKLM/SYSTEM/ControlSet001/Services/WinSock2/Parameters/NameSpace_Catalog5/Catalog_Entries/000000000002LibraryPath"%SystemRoot%System32winrnr.dll""%SystemRoot%System32mswsock.dll"
    modifiedHKLM/SYSTEM/ControlSet001/Services/WinSock2/Parameters/NameSpace_Catalog5/Catalog_Entries/000000000002DisplayString"NTDS""@%SystemRoot%system32wshtcpip.dll,-60103"
    modifiedHKLM/SYSTEM/ControlSet001/Services/WinSock2/Parameters/NameSpace_Catalog5/Catalog_Entries/000000000002ProviderIdEE 37 26 3B 80 E5 CF 11 A5 55 00 C0 4F D8 D4 AC40 9D 05 22 9E 7E CF 11 AE 5A 00 AA 00 A7 11 2B
    modifiedHKLM/SYSTEM/ControlSet001/Services/WinSock2/Parameters/NameSpace_Catalog5/Catalog_Entries/000000000002SupportedNameSpace0x000000200x0000000C
    modifiedHKLM/SYSTEM/ControlSet001/Services/WinSock2/Parameters/NameSpace_Catalog5/Catalog_Entries/000000000002StoresServiceClassInfo0x000000000x00000001
    modifiedHKLM/SYSTEM/ControlSet001/Services/WinSock2/Parameters/NameSpace_Catalog5/Catalog_Entries/000000000003LibraryPath"%SystemRoot%System32mswsock.dll""%SystemRoot%System32winrnr.dll"
    modifiedHKLM/SYSTEM/ControlSet001/Services/WinSock2/Parameters/NameSpace_Catalog5/Catalog_Entries/000000000003DisplayString"Network Location Awareness (NLA) Namespace""NTDS"
    modifiedHKLM/SYSTEM/ControlSet001/Services/WinSock2/Parameters/NameSpace_Catalog5/Catalog_Entries/000000000003ProviderId3A 24 42 66 A8 3B A6 4A BA A5 2E 0B D7 1F DD 83EE 37 26 3B 80 E5 CF 11 A5 55 00 C0 4F D8 D4 AC
    modifiedHKLM/SYSTEM/ControlSet001/Services/WinSock2/Parameters/NameSpace_Catalog5/Catalog_Entries/000000000003SupportedNameSpace0x0000000F0x00000020
    modifiedHKLM/SYSTEM/ControlSet001/Services/WinSock2/Parameters/Protocol_Catalog9Num_Catalog_Entries0x0000000B0x0000000E
    modifiedHKLM/SYSTEM/ControlSet001/Services/WinSock2/Parameters/Protocol_Catalog9Next_Catalog_Entry_ID0x000003F40x000003F7
    modifiedHKLM/SYSTEM/ControlSet001/Services/WinSock2/Parameters/Protocol_Catalog9Serial_Access_Num0x000000040x00000005
    modifiedHKLM/SYSTEM/ControlSet001/Services/WinSock2/Parameters/Protocol_Catalog9/Catalog_Entries/000000000001PackedCatalogItem25 53 79 73 74 65 6D 52 6F 6F 74 25 5C 73 79 73 74 65 6D 33 32 5C 6D 73 77 73 6F25 53 79 73 74 65 6D 52 6F 6F 74 25 5C 73 79 73 74 65 6D 33 32 5C 6D 73 77 73 6F
    modifiedHKLM/SYSTEM/ControlSet001/Services/WinSock2/Parameters/Protocol_Catalog9/Catalog_Entries/000000000002PackedCatalogItem25 53 79 73 74 65 6D 52 6F 6F 74 25 5C 73 79 73 74 65 6D 33 32 5C 6D 73 77 73 6F25 53 79 73 74 65 6D 52 6F 6F 74 25 5C 73 79 73 74 65 6D 33 32 5C 6D 73 77 73 6F
    modifiedHKLM/SYSTEM/ControlSet001/Services/WinSock2/Parameters/Protocol_Catalog9/Catalog_Entries/000000000003PackedCatalogItem25 53 79 73 74 65 6D 52 6F 6F 74 25 5C 73 79 73 74 65 6D 33 32 5C 6D 73 77 73 6F25 53 79 73 74 65 6D 52 6F 6F 74 25 5C 73 79 73 74 65 6D 33 32 5C 6D 73 77 73 6F
    modifiedHKLM/SYSTEM/ControlSet001/Services/WinSock2/Parameters/Protocol_Catalog9/Catalog_Entries/000000000004PackedCatalogItem25 53 79 73 74 65 6D 52 6F 6F 74 25 5C 73 79 73 74 65 6D 33 32 5C 72 73 76 70 7325 53 79 73 74 65 6D 52 6F 6F 74 25 5C 73 79 73 74 65 6D 33 32 5C 6D 73 77 73 6F
    modifiedHKLM/SYSTEM/ControlSet001/Services/WinSock2/Parameters/Protocol_Catalog9/Catalog_Entries/000000000005PackedCatalogItem25 53 79 73 74 65 6D 52 6F 6F 74 25 5C 73 79 73 74 65 6D 33 32 5C 72 73 76 70 7325 53 79 73 74 65 6D 52 6F 6F 74 25 5C 73 79 73 74 65 6D 33 32 5C 6D 73 77 73 6F
    modifiedHKLM/SYSTEM/ControlSet001/Services/WinSock2/Parameters/Protocol_Catalog9/Catalog_Entries/000000000006PackedCatalogItem25 53 79 73 74 65 6D 52 6F 6F 74 25 5C 73 79 73 74 65 6D 33 32 5C 6D 73 77 73 6F25 53 79 73 74 65 6D 52 6F 6F 74 25 5C 73 79 73 74 65 6D 33 32 5C 6D 73 77 73 6F
    modifiedHKLM/SYSTEM/ControlSet001/Services/WinSock2/Parameters/Protocol_Catalog9/Catalog_Entries/000000000007PackedCatalogItem25 53 79 73 74 65 6D 52 6F 6F 74 25 5C 73 79 73 74 65 6D 33 32 5C 6D 73 77 73 6F25 53 79 73 74 65 6D 52 6F 6F 74 25 5C 73 79 73 74 65 6D 33 32 5C 6D 73 77 73 6F
    modifiedHKLM/SYSTEM/ControlSet001/Services/WinSock2/Parameters/Protocol_Catalog9/Catalog_Entries/000000000008PackedCatalogItem25 53 79 73 74 65 6D 52 6F 6F 74 25 5C 73 79 73 74 65 6D 33 32 5C 6D 73 77 73 6F25 53 79 73 74 65 6D 52 6F 6F 74 25 5C 73 79 73 74 65 6D 33 32 5C 6D 73 77 73 6F
    modifiedHKLM/SYSTEM/ControlSet001/Services/WinSock2/Parameters/Protocol_Catalog9/Catalog_Entries/000000000009PackedCatalogItem25 53 79 73 74 65 6D 52 6F 6F 74 25 5C 73 79 73 74 65 6D 33 32 5C 6D 73 77 73 6F25 53 79 73 74 65 6D 52 6F 6F 74 25 5C 73 79 73 74 65 6D 33 32 5C 6D 73 77 73 6F
    modifiedHKLM/SYSTEM/ControlSet001/Services/WinSock2/Parameters/Protocol_Catalog9/Catalog_Entries/000000000010PackedCatalogItem25 53 79 73 74 65 6D 52 6F 6F 74 25 5C 73 79 73 74 65 6D 33 32 5C 6D 73 77 73 6F25 53 79 73 74 65 6D 52 6F 6F 74 25 5C 73 79 73 74 65 6D 33 32 5C 6D 73 77 73 6F
    modifiedHKLM/SYSTEM/ControlSet001/Services/WinSock2/Parameters/Protocol_Catalog9/Catalog_Entries/000000000011PackedCatalogItem25 53 79 73 74 65 6D 52 6F 6F 74 25 5C 73 79 73 74 65 6D 33 32 5C 6D 73 77 73 6F25 53 79 73 74 65 6D 52 6F 6F 74 25 5C 73 79 73 74 65 6D 33 32 5C 6D 73 77 73 6F
    modifiedHKLM/SYSTEM/CurrentControlSet/Services/Eventlog/Application/ESENTEventMessageFile"c"C:WINDOWSsystem32ESENT.dll"
    modifiedHKLM/SYSTEM/CurrentControlSet/Services/Eventlog/Application/ESENTCategoryMessageFile"c"C:WINDOWSsystem32ESENT.dll"
    modifiedHKLM/SYSTEM/CurrentControlSet/Services/TcpipStart0x000000010x00000000
    modifiedHKLM/SYSTEM/CurrentControlSet/Services/TcpipImagePath"system32DRIVERStcpip.sys""System32driverstcpip.sys"
    modifiedHKLM/SYSTEM/CurrentControlSet/Services/TcpipDisplayName"TCP/IP Protocol Driver""@%SystemRoot%system32tcpipcfg.dll,-50003"
    modifiedHKLM/SYSTEM/CurrentControlSet/Services/TcpipDescription"TCP/IP Protocol Driver""@%SystemRoot%system32tcpipcfg.dll,-50003"
    modifiedHKLM/SYSTEM/CurrentControlSet/Services/Tcpip/LinkageRoute{9B7E3E9B-6887-4894-8EE4-B4EFDC3EBE75}NdisWanIp{9E702D9C-6C82-499E-A802-29EC61B09C31}
    modifiedHKLM/SYSTEM/CurrentControlSet/Services/Tcpip/Parameters/WinsockMapping0B 00 00 00 03 00 00 00 02 00 00 00 01 00 00 00 06 00 00 00 02 00 00 00 01 00 0008 00 00 00 03 00 00 00 02 00 00 00 01 00 00 00 06 00 00 00 02 00 00 00 01 00 00
    modifiedHKLM/SYSTEM/CurrentControlSet/Services/Tcpip/PerformanceObject List"502 510 546 582 638 658""502 510 546 548 582 638 658 1530 1532 1534"
    modifiedHKLM/SYSTEM/CurrentControlSet/Services/WinSock2/Parameters/NameSpace_Catalog5Num_Catalog_Entries0x000000030x00000006
    modifiedHKLM/SYSTEM/CurrentControlSet/Services/WinSock2/Parameters/NameSpace_Catalog5Serial_Access_Num0x000000040x00000008
    modifiedHKLM/SYSTEM/CurrentControlSet/Services/WinSock2/Parameters/NameSpace_Catalog5/Catalog_Entries/000000000001LibraryPath"%SystemRoot%System32mswsock.dll""%SystemRoot%system32NLAapi.dll"
    modifiedHKLM/SYSTEM/CurrentControlSet/Services/WinSock2/Parameters/NameSpace_Catalog5/Catalog_Entries/000000000001DisplayString"Tcpip""@%SystemRoot%system32nlasvc.dll,-1000"
    modifiedHKLM/SYSTEM/CurrentControlSet/Services/WinSock2/Parameters/NameSpace_Catalog5/Catalog_Entries/000000000001ProviderId40 9D 05 22 9E 7E CF 11 AE 5A 00 AA 00 A7 11 2B3A 24 42 66 A8 3B A6 4A BA A5 2E 0B D7 1F DD 83
    modifiedHKLM/SYSTEM/CurrentControlSet/Services/WinSock2/Parameters/NameSpace_Catalog5/Catalog_Entries/000000000001SupportedNameSpace0x0000000C0x0000000F
    modifiedHKLM/SYSTEM/CurrentControlSet/Services/WinSock2/Parameters/NameSpace_Catalog5/Catalog_Entries/000000000002LibraryPath"%SystemRoot%System32winrnr.dll""%SystemRoot%System32mswsock.dll"
    modifiedHKLM/SYSTEM/CurrentControlSet/Services/WinSock2/Parameters/NameSpace_Catalog5/Catalog_Entries/000000000002DisplayString"NTDS""@%SystemRoot%system32wshtcpip.dll,-60103"
    modifiedHKLM/SYSTEM/CurrentControlSet/Services/WinSock2/Parameters/NameSpace_Catalog5/Catalog_Entries/000000000002ProviderIdEE 37 26 3B 80 E5 CF 11 A5 55 00 C0 4F D8 D4 AC40 9D 05 22 9E 7E CF 11 AE 5A 00 AA 00 A7 11 2B
    modifiedHKLM/SYSTEM/CurrentControlSet/Services/WinSock2/Parameters/NameSpace_Catalog5/Catalog_Entries/000000000002SupportedNameSpace0x000000200x0000000C
    modifiedHKLM/SYSTEM/CurrentControlSet/Services/WinSock2/Parameters/NameSpace_Catalog5/Catalog_Entries/000000000002StoresServiceClassInfo0x000000000x00000001
    modifiedHKLM/SYSTEM/CurrentControlSet/Services/WinSock2/Parameters/NameSpace_Catalog5/Catalog_Entries/000000000003LibraryPath"%SystemRoot%System32mswsock.dll""%SystemRoot%System32winrnr.dll"
    modifiedHKLM/SYSTEM/CurrentControlSet/Services/WinSock2/Parameters/NameSpace_Catalog5/Catalog_Entries/000000000003DisplayString"Network Location Awareness (NLA) Namespace""NTDS"
    modifiedHKLM/SYSTEM/CurrentControlSet/Services/WinSock2/Parameters/NameSpace_Catalog5/Catalog_Entries/000000000003ProviderId3A 24 42 66 A8 3B A6 4A BA A5 2E 0B D7 1F DD 83EE 37 26 3B 80 E5 CF 11 A5 55 00 C0 4F D8 D4 AC
    modifiedHKLM/SYSTEM/CurrentControlSet/Services/WinSock2/Parameters/NameSpace_Catalog5/Catalog_Entries/000000000003SupportedNameSpace0x0000000F0x00000020
    modifiedHKLM/SYSTEM/CurrentControlSet/Services/WinSock2/Parameters/Protocol_Catalog9Num_Catalog_Entries0x0000000B0x0000000E
    modifiedHKLM/SYSTEM/CurrentControlSet/Services/WinSock2/Parameters/Protocol_Catalog9Next_Catalog_Entry_ID0x000003F40x000003F7
    modifiedHKLM/SYSTEM/CurrentControlSet/Services/WinSock2/Parameters/Protocol_Catalog9Serial_Access_Num0x000000040x00000005
    modifiedHKLM/SYSTEM/CurrentControlSet/Services/WinSock2/Parameters/Protocol_Catalog9/Catalog_Entries/000000000001PackedCatalogItem25 53 79 73 74 65 6D 52 6F 6F 74 25 5C 73 79 73 74 65 6D 33 32 5C 6D 73 77 73 6F25 53 79 73 74 65 6D 52 6F 6F 74 25 5C 73 79 73 74 65 6D 33 32 5C 6D 73 77 73 6F
    modifiedHKLM/SYSTEM/CurrentControlSet/Services/WinSock2/Parameters/Protocol_Catalog9/Catalog_Entries/000000000002PackedCatalogItem25 53 79 73 74 65 6D 52 6F 6F 74 25 5C 73 79 73 74 65 6D 33 32 5C 6D 73 77 73 6F25 53 79 73 74 65 6D 52 6F 6F 74 25 5C 73 79 73 74 65 6D 33 32 5C 6D 73 77 73 6F
    modifiedHKLM/SYSTEM/CurrentControlSet/Services/WinSock2/Parameters/Protocol_Catalog9/Catalog_Entries/000000000003PackedCatalogItem25 53 79 73 74 65 6D 52 6F 6F 74 25 5C 73 79 73 74 65 6D 33 32 5C 6D 73 77 73 6F25 53 79 73 74 65 6D 52 6F 6F 74 25 5C 73 79 73 74 65 6D 33 32 5C 6D 73 77 73 6F
    modifiedHKLM/SYSTEM/CurrentControlSet/Services/WinSock2/Parameters/Protocol_Catalog9/Catalog_Entries/000000000004PackedCatalogItem25 53 79 73 74 65 6D 52 6F 6F 74 25 5C 73 79 73 74 65 6D 33 32 5C 72 73 76 70 7325 53 79 73 74 65 6D 52 6F 6F 74 25 5C 73 79 73 74 65 6D 33 32 5C 6D 73 77 73 6F
    modifiedHKLM/SYSTEM/CurrentControlSet/Services/WinSock2/Parameters/Protocol_Catalog9/Catalog_Entries/000000000005PackedCatalogItem25 53 79 73 74 65 6D 52 6F 6F 74 25 5C 73 79 73 74 65 6D 33 32 5C 72 73 76 70 7325 53 79 73 74 65 6D 52 6F 6F 74 25 5C 73 79 73 74 65 6D 33 32 5C 6D 73 77 73 6F
    modifiedHKLM/SYSTEM/CurrentControlSet/Services/WinSock2/Parameters/Protocol_Catalog9/Catalog_Entries/000000000006PackedCatalogItem25 53 79 73 74 65 6D 52 6F 6F 74 25 5C 73 79 73 74 65 6D 33 32 5C 6D 73 77 73 6F25 53 79 73 74 65 6D 52 6F 6F 74 25 5C 73 79 73 74 65 6D 33 32 5C 6D 73 77 73 6F
    modifiedHKLM/SYSTEM/CurrentControlSet/Services/WinSock2/Parameters/Protocol_Catalog9/Catalog_Entries/000000000007PackedCatalogItem25 53 79 73 74 65 6D 52 6F 6F 74 25 5C 73 79 73 74 65 6D 33 32 5C 6D 73 77 73 6F25 53 79 73 74 65 6D 52 6F 6F 74 25 5C 73 79 73 74 65 6D 33 32 5C 6D 73 77 73 6F
    modifiedHKLM/SYSTEM/CurrentControlSet/Services/WinSock2/Parameters/Protocol_Catalog9/Catalog_Entries/000000000008PackedCatalogItem25 53 79 73 74 65 6D 52 6F 6F 74 25 5C 73 79 73 74 65 6D 33 32 5C 6D 73 77 73 6F25 53 79 73 74 65 6D 52 6F 6F 74 25 5C 73 79 73 74 65 6D 33 32 5C 6D 73 77 73 6F
    modifiedHKLM/SYSTEM/CurrentControlSet/Services/WinSock2/Parameters/Protocol_Catalog9/Catalog_Entries/000000000009PackedCatalogItem25 53 79 73 74 65 6D 52 6F 6F 74 25 5C 73 79 73 74 65 6D 33 32 5C 6D 73 77 73 6F25 53 79 73 74 65 6D 52 6F 6F 74 25 5C 73 79 73 74 65 6D 33 32 5C 6D 73 77 73 6F
    modifiedHKLM/SYSTEM/CurrentControlSet/Services/WinSock2/Parameters/Protocol_Catalog9/Catalog_Entries/000000000010PackedCatalogItem25 53 79 73 74 65 6D 52 6F 6F 74 25 5C 73 79 73 74 65 6D 33 32 5C 6D 73 77 73 6F25 53 79 73 74 65 6D 52 6F 6F 74 25 5C 73 79 73 74 65 6D 33 32 5C 6D 73 77 73 6F
    modifiedHKLM/SYSTEM/CurrentControlSet/Services/WinSock2/Parameters/Protocol_Catalog9/Catalog_Entries/000000000011PackedCatalogItem25 53 79 73 74 65 6D 52 6F 6F 74 25 5C 73 79 73 74 65 6D 33 32 5C 6D 73 77 73 6F25 53 79 73 74 65 6D 52 6F 6F 74 25 5C 73 79 73 74 65 6D 33 32 5C 6D 73 77 73 6F

    DNS Results

    DNSDNS Response

    URL Results

    DstIPHTTP_HOSTHTTP_REQUEST_URIHTTP_USER_AGENTPROTOCOL

    ARGUS PROTOCOL Results

    PROTOCOLSRC_PKTSDST_PKTSSRC_BYTESDST_BYTES

    ARGUS DPORT Results

    DPORTPROTOCOLSRC_PKTSDST_PKTSSRC_BYTESDST_BYTES

    ARGUS DATA Results

    TimeDateProtocolSrcIPDstIPDirFlagsSportDportPktsBytes

    Packer Results

    Packer Name

    HoneyTrap Results

    Honey Trap Log File Location

    PTFB Results

    PTFB Log File Location