Action | Path | Val_Name | Val_Data |
---|
added | HKU/S-1-5-21-1844237615-562591055-839522115-1004/Software/Microsoft/Windows/CurrentVersion/Explorer/RecentDocs | 9 | 30 00 30 00 30 00 30 00 71 00 30 00 68 00 62 00 2E 00 6A 00 70 00 67 00 00 00 58 |
added | HKU/S-1-5-21-1844237615-562591055-839522115-1004/Software/Microsoft/Windows/CurrentVersion/Explorer/RecentDocs | 10 | 64 00 6D 00 63 00 37 00 33 00 31 00 34 00 34 00 00 00 4C 00 32 00 00 00 00 00 00 |
added | HKU/S-1-5-21-1844237615-562591055-839522115-1004/Software/Microsoft/Windows/CurrentVersion/Explorer/RecentDocs/Folder | 4 | 64 00 6D 00 63 00 37 00 33 00 31 00 34 00 34 00 00 00 4C 00 32 00 00 00 00 00 00 |
added | HKU/S-1-5-21-1844237615-562591055-839522115-1004/Software/Microsoft/Windows/CurrentVersion/Explorer/RecentDocs/.jpg | 0 | 30 00 30 00 30 00 30 00 71 00 30 00 68 00 62 00 2E 00 6A 00 70 00 67 00 00 00 58 |
added | HKU/S-1-5-21-1844237615-562591055-839522115-1004/Software/Microsoft/Windows/CurrentVersion/Explorer/RecentDocs/.jpg | MRUListEx | 00 00 00 00 FF FF FF FF
|
added | HKU/S-1-5-21-1844237615-562591055-839522115-1004/Software/Microsoft/Windows/CurrentVersion/Internet Settings/5.0/Cache/Extensible Cache/MSHist012011100520111006 | CachePath | "%USERPROFILE%Local SettingsHistoryHistory.IE5MSHist012011100520111006"
|
added | HKU/S-1-5-21-1844237615-562591055-839522115-1004/Software/Microsoft/Windows/CurrentVersion/Internet Settings/5.0/Cache/Extensible Cache/MSHist012011100520111006 | CachePrefix | ":2011100520111006: "
|
added | HKU/S-1-5-21-1844237615-562591055-839522115-1004/Software/Microsoft/Windows/CurrentVersion/Internet Settings/5.0/Cache/Extensible Cache/MSHist012011100520111006 | CacheLimit | 0x00002000
|
added | HKU/S-1-5-21-1844237615-562591055-839522115-1004/Software/Microsoft/Windows/CurrentVersion/Internet Settings/5.0/Cache/Extensible Cache/MSHist012011100520111006 | CacheOptions | 0x0000000B
|
added | HKU/S-1-5-21-1844237615-562591055-839522115-1004/Software/Microsoft/Windows/CurrentVersion/Internet Settings/5.0/Cache/Extensible Cache/MSHist012011100520111006 | CacheRepair | 0x00000000
|
added | HKU/S-1-5-21-1844237615-562591055-839522115-1004/Software/Microsoft/Windows/ShellNoRoam/MUICache | C://Documents and Settings//dmc73144//rnm.exe | "rnm"
|
added | HKU/S-1-5-21-1844237615-562591055-839522115-1004/Software/WinRAR SFX | C%%Documents and Settings%dmc73144 | "C:/Documents and Settings/dmc73144"
|
Action | Path | Val_Name | Val_Data | Mod_Val_Data |
---|
modified | HKLM/SOFTWARE/Microsoft/Cryptography/RNG | Seed | EA 9C B7 7E 03 1A 85 47 7D 09 C6 78 09 D1 C5 A4 A6 8A 43 11 26 EE 5A 22 15 12 F3 | A6 06 77 7E C6 9F 3A 47 12 F4 75 88 D6 D6 45 6D B2 15 32 7C 39 C3 18 A6 64 BD 41 |
modified | HKLM/SYSTEM/ControlSet001/Services/Eventlog/Application/ESENT | EventMessageFile | "c | "C:WINDOWSsystem32ESENT.dll" |
modified | HKLM/SYSTEM/ControlSet001/Services/Eventlog/Application/ESENT | CategoryMessageFile | "c | "C:WINDOWSsystem32ESENT.dll" |
modified | HKLM/SYSTEM/CurrentControlSet/Services/Eventlog/Application/ESENT | EventMessageFile | "c | "C:WINDOWSsystem32ESENT.dll" |
modified | HKLM/SYSTEM/CurrentControlSet/Services/Eventlog/Application/ESENT | CategoryMessageFile | "c | "C:WINDOWSsystem32ESENT.dll" |
modified | HKU/S-1-5-21-1844237615-562591055-839522115-1004/Software/Microsoft/Windows/CurrentVersion/Explorer/RecentDocs | MRUListEx | 03 00 00 00 02 00 00 00 00 00 00 00 08 00 00 00 07 00 00 00 06 00 00 00 05 00 00 | 0A 00 00 00 09 00 00 00 03 00 00 00 02 00 00 00 00 00 00 00 08 00 00 00 07 00 00 |
modified | HKU/S-1-5-21-1844237615-562591055-839522115-1004/Software/Microsoft/Windows/CurrentVersion/Explorer/RecentDocs/Folder | MRUListEx | 01 00 00 00 03 00 00 00 02 00 00 00 00 00 00 00 FF FF FF FF | 04 00 00 00 01 00 00 00 03 00 00 00 02 00 00 00 00 00 00 00 FF FF FF FF |