Action | Path | Val_Name | Val_Data |
---|
added | HKLM/SOFTWARE/Microsoft/Windows/CurrentVersion/Internet Settings | 6 | CA 45 8D 7A 61 F6
|
added | HKLM/SOFTWARE/Microsoft/Windows/CurrentVersion/policies/Explorer/run | oxtosr | "C:/WINDOWS/system32/perfmon8.exe"
|
added | HKLM/SOFTWARE/Microsoft/Windows/CurrentVersion/Run | conhost | "C:/Documents and Settings/dmc73144/Application Data/Microsoft/conhost.exe"
|
added | HKLM/SYSTEM/ControlSet001/Control/Session Manager | PendingFileRenameOperations | 5C 3F 3F 5C 43 3A 5C 44 4F 43 55 4D 45 7E 31 5C 64 6D 63 37 33 31 34 34 5C 4C 4F |
added | HKLM/SYSTEM/ControlSet001/Enum/Root/LEGACY_3BBA44C8/0000/Control | *NewlyCreated* | 0x00000000
|
added | HKLM/SYSTEM/ControlSet001/Enum/Root/LEGACY_3BBA44C8/0000/Control | ActiveService | "3bba44c8"
|
added | HKLM/SYSTEM/ControlSet001/Enum/Root/LEGACY_3BBA44C8/0000 | Service | "3bba44c8"
|
added | HKLM/SYSTEM/ControlSet001/Enum/Root/LEGACY_3BBA44C8/0000 | Legacy | 0x00000001
|
added | HKLM/SYSTEM/ControlSet001/Enum/Root/LEGACY_3BBA44C8/0000 | ConfigFlags | 0x00000000
|
added | HKLM/SYSTEM/ControlSet001/Enum/Root/LEGACY_3BBA44C8/0000 | Class | "LegacyDriver"
|
added | HKLM/SYSTEM/ControlSet001/Enum/Root/LEGACY_3BBA44C8/0000 | ClassGUID | "{8ECC055D-047F-11D1-A537-0000F8753ED1}"
|
added | HKLM/SYSTEM/ControlSet001/Enum/Root/LEGACY_3BBA44C8/0000 | DeviceDesc | "3bba44c8"
|
added | HKLM/SYSTEM/ControlSet001/Enum/Root/LEGACY_3BBA44C8 | NextInstance | 0x00000001
|
added | HKLM/SYSTEM/CurrentControlSet/Control/Session Manager | PendingFileRenameOperations | 5C 3F 3F 5C 43 3A 5C 44 4F 43 55 4D 45 7E 31 5C 64 6D 63 37 33 31 34 34 5C 4C 4F |
added | HKLM/SYSTEM/CurrentControlSet/Enum/Root/LEGACY_3BBA44C8/0000/Control | *NewlyCreated* | 0x00000000
|
added | HKLM/SYSTEM/CurrentControlSet/Enum/Root/LEGACY_3BBA44C8/0000/Control | ActiveService | "3bba44c8"
|
added | HKLM/SYSTEM/CurrentControlSet/Enum/Root/LEGACY_3BBA44C8/0000 | Service | "3bba44c8"
|
added | HKLM/SYSTEM/CurrentControlSet/Enum/Root/LEGACY_3BBA44C8/0000 | Legacy | 0x00000001
|
added | HKLM/SYSTEM/CurrentControlSet/Enum/Root/LEGACY_3BBA44C8/0000 | ConfigFlags | 0x00000000
|
added | HKLM/SYSTEM/CurrentControlSet/Enum/Root/LEGACY_3BBA44C8/0000 | Class | "LegacyDriver"
|
added | HKLM/SYSTEM/CurrentControlSet/Enum/Root/LEGACY_3BBA44C8/0000 | ClassGUID | "{8ECC055D-047F-11D1-A537-0000F8753ED1}"
|
added | HKLM/SYSTEM/CurrentControlSet/Enum/Root/LEGACY_3BBA44C8/0000 | DeviceDesc | "3bba44c8"
|
added | HKLM/SYSTEM/CurrentControlSet/Enum/Root/LEGACY_3BBA44C8 | NextInstance | 0x00000001
|
added | HKU/.DEFAULT/Software/Microsoft/Internet Explorer/Main/featurecontrol/FEATURE_BROWSER_EMULATION | svchost.exe | 0x000022B8
|
added | HKU/.DEFAULT/Software/Microsoft/Internet Explorer/international | acceptlanguage | "en-us"
|
added | HKU/.DEFAULT/Software/Microsoft/Windows/CurrentVersion/Internet Settings | maxhttpredirects | 0x0000270F
|
added | HKU/.DEFAULT/Software/Microsoft/Windows/CurrentVersion/Internet Settings | enablehttp1_1 | 0x00000001
|
added | HKU/.DEFAULT/Software/Microsoft/Windows/CurrentVersion/Internet Settings/Zones/3 | {AEBA21FA-782A-4A90-978D-B72164C80120} | 1A 37 61 59 23 52 35 0C 7A 5F 20 17 2F 1E 1A 19 0E 2B 01 73 13 37 13 12 14 1A 15 |
added | HKU/.DEFAULT/Software/Microsoft/Windows/CurrentVersion/Internet Settings/Zones/3 | {A8A88C49-5EB2-4990-A1A2-0876022C854F} | 1A 37 61 59 23 52 35 0C 7A 5F 20 17 2F 1E 1A 19 0E 2B 01 73 13 37 13 12 14 1A 15 |
added | HKU/.DEFAULT/Software/Microsoft/Windows/CurrentVersion/Internet Settings/Zones/3 | 1208 | 0x00000000
|
added | HKU/.DEFAULT/Software/Microsoft/Windows/CurrentVersion/Internet Settings/Zones/3 | 1209 | 0x00000000
|
added | HKU/S-1-5-21-1844237615-562591055-839522115-1004/Software/Microsoft/Windows/CurrentVersion/Internet Settings | ProxyServer | "http=127.0.0.1 |
added | HKU/S-1-5-21-1844237615-562591055-839522115-1004/Software/Microsoft/Windows/CurrentVersion/Internet Settings | 6 | CA 45 8D 7A 61 F6
|
added | HKU/S-1-5-21-1844237615-562591055-839522115-1004/Software/Microsoft/Windows/ShellNoRoam/MUICache | C://DOCUME~1//dmc73144//LOCALS~1//Temp//AV.EXE | "Realtek Audio Driver"
|
added | HKU/S-1-5-21-1844237615-562591055-839522115-1004/Software/Microsoft/Windows/ShellNoRoam/MUICache | C://DOCUME~1//dmc73144//LOCALS~1//Temp//AVS.EXE | "AVS"
|
added | HKU/S-1-5-21-1844237615-562591055-839522115-1004/Software/Microsoft/Windows/ShellNoRoam/MUICache | C://DOCUME~1//dmc73144//LOCALS~1//Temp//DB.EXE | "Snapin using common base classes"
|
added | HKU/S-1-5-21-1844237615-562591055-839522115-1004/Software/Microsoft/Windows/ShellNoRoam/MUICache | C://DOCUME~1//dmc73144//LOCALS~1//Temp//EN.EXE | "EN"
|
added | HKU/S-1-5-21-1844237615-562591055-839522115-1004/Software/Microsoft/Windows/ShellNoRoam/MUICache | C://DOCUME~1//dmc73144//LOCALS~1//Temp//GB.EXE | "GB"
|
added | HKU/S-1-5-21-1844237615-562591055-839522115-1004/Software/Microsoft/Windows/ShellNoRoam/MUICache | C://DOCUME~1//dmc73144//LOCALS~1//Temp//SB.EXE | "SB"
|
added | HKU/S-1-5-21-1844237615-562591055-839522115-1004/Software/Microsoft/Windows/ShellNoRoam/MUICache | C://WINDOWS//system32//ipconfig.exe | "IP Configuration Utility"
|
added | HKU/S-1-5-21-1844237615-562591055-839522115-1004/Software/Microsoft/Windows/ShellNoRoam/MUICache | C://DOCUME~1//dmc73144//LOCALS~1//Temp//EUO1FFC.tmp.cmd | "EUO1FFC.tmp"
|
added | HKU/S-1-5-21-1844237615-562591055-839522115-1004/Software/Microsoft/Windows/ShellNoRoam/MUICache | C://Documents and Settings//dmc73144xplore.exe | "dmc73144xplore"
|
added | HKU/S-1-5-21-1844237615-562591055-839522115-1004/Software/Microsoft/Windows/ShellNoRoam/MUICache | C://WINDOWS//system32//ntvdm.exe | "NTVDM.EXE"
|
added | HKU/S-1-5-18/Software/Microsoft/Internet Explorer/Main/featurecontrol/FEATURE_BROWSER_EMULATION | svchost.exe | 0x000022B8
|
added | HKU/S-1-5-18/Software/Microsoft/Internet Explorer/international | acceptlanguage | "en-us"
|
added | HKU/S-1-5-18/Software/Microsoft/Windows/CurrentVersion/Internet Settings | maxhttpredirects | 0x0000270F
|
added | HKU/S-1-5-18/Software/Microsoft/Windows/CurrentVersion/Internet Settings | enablehttp1_1 | 0x00000001
|
added | HKU/S-1-5-18/Software/Microsoft/Windows/CurrentVersion/Internet Settings/Zones/3 | {AEBA21FA-782A-4A90-978D-B72164C80120} | 1A 37 61 59 23 52 35 0C 7A 5F 20 17 2F 1E 1A 19 0E 2B 01 73 13 37 13 12 14 1A 15 |
added | HKU/S-1-5-18/Software/Microsoft/Windows/CurrentVersion/Internet Settings/Zones/3 | {A8A88C49-5EB2-4990-A1A2-0876022C854F} | 1A 37 61 59 23 52 35 0C 7A 5F 20 17 2F 1E 1A 19 0E 2B 01 73 13 37 13 12 14 1A 15 |
added | HKU/S-1-5-18/Software/Microsoft/Windows/CurrentVersion/Internet Settings/Zones/3 | 1208 | 0x00000000
|
added | HKU/S-1-5-18/Software/Microsoft/Windows/CurrentVersion/Internet Settings/Zones/3 | 1209 | 0x00000000
|
Action | Path | Val_Name | Val_Data | Mod_Val_Data |
---|
modified | HKLM/SOFTWARE/Microsoft/Cryptography/RNG | Seed | E3 E9 35 DE C1 21 D3 29 2B B2 1F C8 D7 22 76 12 7B 0D 1E C2 19 DE 41 27 B8 63 7A | 70 3A 68 51 20 E2 3E 81 A5 8E D3 DB 3E 9E 1D 2C C5 D4 3B 7F CD DE FC 8F 66 5E AE |
modified | HKLM/SOFTWARE/Microsoft/DirectDraw/MostRecentApplication | Name | "msoobe.exe" | "svchost.exe" |
modified | HKLM/SOFTWARE/Microsoft/DirectDraw/MostRecentApplication | ID | 0x3B7D853E | 0x41107ED6 |
modified | HKLM/SYSTEM/ControlSet001/Hardware Profiles/0001/Software/Microsoft/windows/CurrentVersion/Internet Settings | ProxyEnable | 0x00000000 | 0x00000001 |
modified | HKLM/SYSTEM/ControlSet001/Hardware Profiles/Current/Software/Microsoft/windows/CurrentVersion/Internet Settings | ProxyEnable | 0x00000000 | 0x00000001 |
modified | HKLM/SYSTEM/CurrentControlSet/Hardware Profiles/0001/Software/Microsoft/windows/CurrentVersion/Internet Settings | ProxyEnable | 0x00000000 | 0x00000001 |
modified | HKLM/SYSTEM/CurrentControlSet/Hardware Profiles/Current/Software/Microsoft/windows/CurrentVersion/Internet Settings | ProxyEnable | 0x00000000 | 0x00000001 |
modified | HKU/.DEFAULT/Software/Microsoft/Windows/CurrentVersion/Internet Settings/Zones/3 | CurrentLevel | 0x00011000 | 0x00000000 |
modified | HKU/.DEFAULT/Software/Microsoft/Windows/CurrentVersion/Internet Settings/Zones/3 | 1001 | 0x00000001 | 0x00000000 |
modified | HKU/.DEFAULT/Software/Microsoft/Windows/CurrentVersion/Internet Settings/Zones/3 | 1601 | 0x00000001 | 0x00000000 |
modified | HKU/.DEFAULT/Software/Microsoft/Windows/CurrentVersion/Internet Settings/Zones/3 | 1A10 | 0x00000001 | 0x00000000 |
modified | HKU/S-1-5-21-1844237615-562591055-839522115-1004/Software/Microsoft/Windows/CurrentVersion/Internet Settings | ProxyEnable | 0x00000000 | 0x00000001 |
modified | HKU/S-1-5-21-1844237615-562591055-839522115-1004/Software/Microsoft/Windows/CurrentVersion/Internet Settings/Connections | DefaultConnectionSettings | 3C 00 00 00 02 00 00 00 01 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 04 00 00 | 3C 00 00 00 03 00 00 00 03 00 00 00 14 00 00 00 68 74 74 70 3D 31 32 37 2E 30 2E |
modified | HKU/S-1-5-21-1844237615-562591055-839522115-1004/Software/Microsoft/Windows/CurrentVersion/Internet Settings/Connections | SavedLegacySettings | 3C 00 00 00 15 00 00 00 01 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 04 00 00 | 3C 00 00 00 1A 00 00 00 03 00 00 00 14 00 00 00 68 74 74 70 3D 31 32 37 2E 30 2E |
modified | HKU/S-1-5-21-1844237615-562591055-839522115-1004/SessionInformation | ProgramCount | 0x00000002 | 0x00000004 |
modified | HKU/S-1-5-18/Software/Microsoft/Windows/CurrentVersion/Internet Settings/Zones/3 | CurrentLevel | 0x00011000 | 0x00000000 |
modified | HKU/S-1-5-18/Software/Microsoft/Windows/CurrentVersion/Internet Settings/Zones/3 | 1001 | 0x00000001 | 0x00000000 |
modified | HKU/S-1-5-18/Software/Microsoft/Windows/CurrentVersion/Internet Settings/Zones/3 | 1601 | 0x00000001 | 0x00000000 |
modified | HKU/S-1-5-18/Software/Microsoft/Windows/CurrentVersion/Internet Settings/Zones/3 | 1A10 | 0x00000001 | 0x00000000 |