Action | Path | Val_Name | Val_Data | Mod_Val_Data |
---|
modified | HKLM/SOFTWARE/Microsoft/Cryptography/RNG | Seed | 1A 39 E3 0A 2F 92 E3 1A 23 52 02 6F D0 9C D2 35 4E C7 0F EF 0B 42 03 1C 9C AD F0 | 52 D8 AD 1C 31 83 CD 2A 70 64 C1 CB 25 C6 6B 6A 11 B5 3A 15 0B 3E 02 86 50 45 D |
modified | HKU/S-1-5-21-1844237615-562591055-839522115-1004/Software/Microsoft/Internet Explorer/Main | Window_Placement | 2C 00 00 00 02 00 00 00 03 00 00 00 FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF | 2C 00 00 00 00 00 00 00 01 00 00 00 FF FF FF FF FF FF FF FF FF FF FF FF FF FF F |
modified | HKU/S-1-5-21-1844237615-562591055-839522115-1004/Software/Microsoft/Windows/CurrentVersion/Explorer/UserAssist/{5E6AB780-7743-11CF-A12B-00AA004AE837}/Count | HRZR_PGYFRFFVBA | 89 C3 53 0E 0D 00 00 00 | 9B 74 62 0E 0E 00 00 00 |
modified | HKU/S-1-5-21-1844237615-562591055-839522115-1004/Software/Microsoft/Windows/CurrentVersion/Ext/Stats/{06849E9F-C8D7-4D59-B87D-784B7D6BE0B3}/iexplore | Count | 0x00000007 | 0x00000008 |
modified | HKU/S-1-5-21-1844237615-562591055-839522115-1004/Software/Microsoft/Windows/CurrentVersion/Ext/Stats/{06849E9F-C8D7-4D59-B87D-784B7D6BE0B3}/iexplore | Time | D9 07 0C 00 03 00 09 00 03 00 0C 00 36 00 51 02 | DB 07 07 00 06 00 1E 00 08 00 22 00 04 00 13 02 |
modified | HKU/S-1-5-21-1844237615-562591055-839522115-1004/Software/Microsoft/Windows/CurrentVersion/Internet Settings/Connections | SavedLegacySettings | 3C 00 00 00 15 00 00 00 01 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 04 00 00 | 3C 00 00 00 16 00 00 00 01 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 04 00 0 |
modified | HKU/S-1-5-21-1844237615-562591055-839522115-1004/Software/Microsoft/Windows/ShellNoRoam/BagMRU | MRUListEx | 01 00 00 00 00 00 00 00 02 00 00 00 04 00 00 00 03 00 00 00 FF FF FF FF | 00 00 00 00 01 00 00 00 02 00 00 00 04 00 00 00 03 00 00 00 FF FF FF FF |
modified | HKU/S-1-5-21-1844237615-562591055-839522115-1004/Software/Microsoft/Windows/ShellNoRoam/Bags/1/Shell | WFlags | 0x00000002 | 0x00000000 |
modified | HKU/S-1-5-21-1844237615-562591055-839522115-1004/Software/Microsoft/Windows/ShellNoRoam/Bags/1/Shell | ShowCmd | 0x00000003 | 0x00000001 |