Action | Path | Val_Name | Val_Data |
---|
added | HKLM/SOFTWARE/Microsoft/Windows NT/CurrentVersion/Image File Execution Options/360hotfix.exe | Debugger | 6E 74 73 64 20 2D 64
|
added | HKLM/SOFTWARE/Microsoft/Windows NT/CurrentVersion/Image File Execution Options/360rp.exe | Debugger | 6E 74 73 64 20 2D 64
|
added | HKLM/SOFTWARE/Microsoft/Windows NT/CurrentVersion/Image File Execution Options/360rpt.exe | Debugger | 6E 74 73 64 20 2D 64
|
added | HKLM/SOFTWARE/Microsoft/Windows NT/CurrentVersion/Image File Execution Options/360Safe.exe | Debugger | 6E 74 73 64 20 2D 64
|
added | HKLM/SOFTWARE/Microsoft/Windows NT/CurrentVersion/Image File Execution Options/360safebox.exe | Debugger | 6E 74 73 64 20 2D 64
|
added | HKLM/SOFTWARE/Microsoft/Windows NT/CurrentVersion/Image File Execution Options/360sd.exe | Debugger | 6E 74 73 64 20 2D 64
|
added | HKLM/SOFTWARE/Microsoft/Windows NT/CurrentVersion/Image File Execution Options/360se.exe | Debugger | 6E 74 73 64 20 2D 64
|
added | HKLM/SOFTWARE/Microsoft/Windows NT/CurrentVersion/Image File Execution Options/360SoftMgrSvc.exe | Debugger | 6E 74 73 64 20 2D 64
|
added | HKLM/SOFTWARE/Microsoft/Windows NT/CurrentVersion/Image File Execution Options/360speedld.exe | Debugger | 6E 74 73 64 20 2D 64
|
added | HKLM/SOFTWARE/Microsoft/Windows NT/CurrentVersion/Image File Execution Options/360tray.exe | Debugger | 6E 74 73 64 20 2D 64
|
added | HKLM/SOFTWARE/Microsoft/Windows NT/CurrentVersion/Image File Execution Options/afwServ.exe | Debugger | 6E 74 73 64 20 2D 64
|
added | HKLM/SOFTWARE/Microsoft/Windows NT/CurrentVersion/Image File Execution Options/ast.exe | Debugger | 6E 74 73 64 20 2D 64
|
added | HKLM/SOFTWARE/Microsoft/Windows NT/CurrentVersion/Image File Execution Options/AvastUI.exe | Debugger | 6E 74 73 64 20 2D 64
|
added | HKLM/SOFTWARE/Microsoft/Windows NT/CurrentVersion/Image File Execution Options/avcenter.exe | Debugger | 6E 74 73 64 20 2D 64
|
added | HKLM/SOFTWARE/Microsoft/Windows NT/CurrentVersion/Image File Execution Options/avfwsvc.exe | Debugger | 6E 74 73 64 20 2D 64
|
added | HKLM/SOFTWARE/Microsoft/Windows NT/CurrentVersion/Image File Execution Options/avgnt.exe | Debugger | 6E 74 73 64 20 2D 64
|
added | HKLM/SOFTWARE/Microsoft/Windows NT/CurrentVersion/Image File Execution Options/avguard.exe | Debugger | 6E 74 73 64 20 2D 64
|
added | HKLM/SOFTWARE/Microsoft/Windows NT/CurrentVersion/Image File Execution Options/avmailc.exe | Debugger | 6E 74 73 64 20 2D 64
|
added | HKLM/SOFTWARE/Microsoft/Windows NT/CurrentVersion/Image File Execution Options/avp.exe | Debugger | 6E 74 73 64 20 2D 64
|
added | HKLM/SOFTWARE/Microsoft/Windows NT/CurrentVersion/Image File Execution Options/avshadow.exe | Debugger | 6E 74 73 64 20 2D 64
|
added | HKLM/SOFTWARE/Microsoft/Windows NT/CurrentVersion/Image File Execution Options/avwebgrd.exe | Debugger | 6E 74 73 64 20 2D 64
|
added | HKLM/SOFTWARE/Microsoft/Windows NT/CurrentVersion/Image File Execution Options/bdagent.exe | Debugger | 6E 74 73 64 20 2D 64
|
added | HKLM/SOFTWARE/Microsoft/Windows NT/CurrentVersion/Image File Execution Options/CCenter.exe | Debugger | 6E 74 73 64 20 2D 64
|
added | HKLM/SOFTWARE/Microsoft/Windows NT/CurrentVersion/Image File Execution Options/ccSvcHst.exe | Debugger | 6E 74 73 64 20 2D 64
|
added | HKLM/SOFTWARE/Microsoft/Windows NT/CurrentVersion/Image File Execution Options/dwengine.exe | Debugger | 6E 74 73 64 20 2D 64
|
added | HKLM/SOFTWARE/Microsoft/Windows NT/CurrentVersion/Image File Execution Options/egui.exe | Debugger | 6E 74 73 64 20 2D 64
|
added | HKLM/SOFTWARE/Microsoft/Windows NT/CurrentVersion/Image File Execution Options/ekrn.exe | Debugger | 6E 74 73 64 20 2D 64
|
added | HKLM/SOFTWARE/Microsoft/Windows NT/CurrentVersion/Image File Execution Options/FilMsg.exe | Debugger | 6E 74 73 64 20 2D 64
|
added | HKLM/SOFTWARE/Microsoft/Windows NT/CurrentVersion/Image File Execution Options/KAVStart.exe | Debugger | 6E 74 73 64 20 2D 64
|
added | HKLM/SOFTWARE/Microsoft/Windows NT/CurrentVersion/Image File Execution Options/kissvc.exe | Debugger | 6E 74 73 64 20 2D 64
|
added | HKLM/SOFTWARE/Microsoft/Windows NT/CurrentVersion/Image File Execution Options/KMailMon.exe | Debugger | 6E 74 73 64 20 2D 64
|
added | HKLM/SOFTWARE/Microsoft/Windows NT/CurrentVersion/Image File Execution Options/KPFW32.exe | Debugger | 6E 74 73 64 20 2D 64
|
added | HKLM/SOFTWARE/Microsoft/Windows NT/CurrentVersion/Image File Execution Options/KPFWSvc.exe | Debugger | 6E 74 73 64 20 2D 64
|
added | HKLM/SOFTWARE/Microsoft/Windows NT/CurrentVersion/Image File Execution Options/kpopserver.exe | Debugger | 6E 74 73 64 20 2D 64
|
added | HKLM/SOFTWARE/Microsoft/Windows NT/CurrentVersion/Image File Execution Options/krnl360svc.exe | Debugger | 6E 74 73 64 20 2D 64
|
added | HKLM/SOFTWARE/Microsoft/Windows NT/CurrentVersion/Image File Execution Options/ksmgui.exe | Debugger | 6E 74 73 64 20 2D 64
|
added | HKLM/SOFTWARE/Microsoft/Windows NT/CurrentVersion/Image File Execution Options/ksmsvc.exe | Debugger | 6E 74 73 64 20 2D 64
|
added | HKLM/SOFTWARE/Microsoft/Windows NT/CurrentVersion/Image File Execution Options/kswebshield.exe | Debugger | 6E 74 73 64 20 2D 64
|
added | HKLM/SOFTWARE/Microsoft/Windows NT/CurrentVersion/Image File Execution Options/KVMonXP.exe | Debugger | 6E 74 73 64 20 2D 64
|
added | HKLM/SOFTWARE/Microsoft/Windows NT/CurrentVersion/Image File Execution Options/KVMonXP.kxp | Debugger | 6E 74 73 64 20 2D 64
|
added | HKLM/SOFTWARE/Microsoft/Windows NT/CurrentVersion/Image File Execution Options/KVSrvXP.exe | Debugger | 6E 74 73 64 20 2D 64
|
added | HKLM/SOFTWARE/Microsoft/Windows NT/CurrentVersion/Image File Execution Options/KWatch.exe | Debugger | 6E 74 73 64 20 2D 64
|
added | HKLM/SOFTWARE/Microsoft/Windows NT/CurrentVersion/Image File Execution Options/kwstray.exe | Debugger | 6E 74 73 64 20 2D 64
|
added | HKLM/SOFTWARE/Microsoft/Windows NT/CurrentVersion/Image File Execution Options/kxedefend.exe | Debugger | 6E 74 73 64 20 2D 64
|
added | HKLM/SOFTWARE/Microsoft/Windows NT/CurrentVersion/Image File Execution Options/kxesapp.exe | Debugger | 6E 74 73 64 20 2D 64
|
added | HKLM/SOFTWARE/Microsoft/Windows NT/CurrentVersion/Image File Execution Options/kxescore.exe | Debugger | 6E 74 73 64 20 2D 64
|
added | HKLM/SOFTWARE/Microsoft/Windows NT/CurrentVersion/Image File Execution Options/kxeserv.exe | Debugger | 6E 74 73 64 20 2D 64
|
added | HKLM/SOFTWARE/Microsoft/Windows NT/CurrentVersion/Image File Execution Options/kxetray.exe | Debugger | 6E 74 73 64 20 2D 64
|
added | HKLM/SOFTWARE/Microsoft/Windows NT/CurrentVersion/Image File Execution Options/livesrv.exe | Debugger | 6E 74 73 64 20 2D 64
|
added | HKLM/SOFTWARE/Microsoft/Windows NT/CurrentVersion/Image File Execution Options/Mcagent.exe | Debugger | 6E 74 73 64 20 2D 64
|
added | HKLM/SOFTWARE/Microsoft/Windows NT/CurrentVersion/Image File Execution Options/mcmscsvc.exe | Debugger | 6E 74 73 64 20 2D 64
|
added | HKLM/SOFTWARE/Microsoft/Windows NT/CurrentVersion/Image File Execution Options/McNASvc.exe | Debugger | 6E 74 73 64 20 2D 64
|
added | HKLM/SOFTWARE/Microsoft/Windows NT/CurrentVersion/Image File Execution Options/Mcods.exe | Debugger | 6E 74 73 64 20 2D 64
|
added | HKLM/SOFTWARE/Microsoft/Windows NT/CurrentVersion/Image File Execution Options/McProxy.exe | Debugger | 6E 74 73 64 20 2D 64
|
added | HKLM/SOFTWARE/Microsoft/Windows NT/CurrentVersion/Image File Execution Options/McSACore.exe | Debugger | 6E 74 73 64 20 2D 64
|
added | HKLM/SOFTWARE/Microsoft/Windows NT/CurrentVersion/Image File Execution Options/Mcshield.exe | Debugger | 6E 74 73 64 20 2D 64
|
added | HKLM/SOFTWARE/Microsoft/Windows NT/CurrentVersion/Image File Execution Options/mcsysmon.exe | Debugger | 6E 74 73 64 20 2D 64
|
added | HKLM/SOFTWARE/Microsoft/Windows NT/CurrentVersion/Image File Execution Options/mcvsshld.exe | Debugger | 6E 74 73 64 20 2D 64
|
added | HKLM/SOFTWARE/Microsoft/Windows NT/CurrentVersion/Image File Execution Options/MpfSrv.exe | Debugger | 6E 74 73 64 20 2D 64
|
added | HKLM/SOFTWARE/Microsoft/Windows NT/CurrentVersion/Image File Execution Options/MPMon.exe | Debugger | 6E 74 73 64 20 2D 64
|
added | HKLM/SOFTWARE/Microsoft/Windows NT/CurrentVersion/Image File Execution Options/MPSVC.exe | Debugger | 6E 74 73 64 20 2D 64
|
added | HKLM/SOFTWARE/Microsoft/Windows NT/CurrentVersion/Image File Execution Options/MPSVC1.exe | Debugger | 6E 74 73 64 20 2D 64
|
added | HKLM/SOFTWARE/Microsoft/Windows NT/CurrentVersion/Image File Execution Options/MPSVC2.exe | Debugger | 6E 74 73 64 20 2D 64
|
added | HKLM/SOFTWARE/Microsoft/Windows NT/CurrentVersion/Image File Execution Options/msksrver.exe | Debugger | 6E 74 73 64 20 2D 64
|
added | HKLM/SOFTWARE/Microsoft/Windows NT/CurrentVersion/Image File Execution Options/qutmserv.exe | Debugger | 6E 74 73 64 20 2D 64
|
added | HKLM/SOFTWARE/Microsoft/Windows NT/CurrentVersion/Image File Execution Options/RavMonD.exe | Debugger | 6E 74 73 64 20 2D 64
|
added | HKLM/SOFTWARE/Microsoft/Windows NT/CurrentVersion/Image File Execution Options/RavTask.exe | Debugger | 6E 74 73 64 20 2D 64
|
added | HKLM/SOFTWARE/Microsoft/Windows NT/CurrentVersion/Image File Execution Options/RsAgent.exe | Debugger | 6E 74 73 64 20 2D 64
|
added | HKLM/SOFTWARE/Microsoft/Windows NT/CurrentVersion/Image File Execution Options/rsnetsvr.exe | Debugger | 6E 74 73 64 20 2D 64
|
added | HKLM/SOFTWARE/Microsoft/Windows NT/CurrentVersion/Image File Execution Options/RsTray.exe | Debugger | 6E 74 73 64 20 2D 64
|
added | HKLM/SOFTWARE/Microsoft/Windows NT/CurrentVersion/Image File Execution Options/safeboxTray.exe | Debugger | 6E 74 73 64 20 2D 64
|
added | HKLM/SOFTWARE/Microsoft/Windows NT/CurrentVersion/Image File Execution Options/ScanFrm.exe | Debugger | 6E 74 73 64 20 2D 64
|
added | HKLM/SOFTWARE/Microsoft/Windows NT/CurrentVersion/Image File Execution Options/sched.exe | Debugger | 6E 74 73 64 20 2D 64
|
added | HKLM/SOFTWARE/Microsoft/Windows NT/CurrentVersion/Image File Execution Options/seccenter.exe | Debugger | 6E 74 73 64 20 2D 64
|
added | HKLM/SOFTWARE/Microsoft/Windows NT/CurrentVersion/Image File Execution Options/SfCtlCom.exe | Debugger | 6E 74 73 64 20 2D 64
|
added | HKLM/SOFTWARE/Microsoft/Windows NT/CurrentVersion/Image File Execution Options/spideragent.exe | Debugger | 6E 74 73 64 20 2D 64
|
added | HKLM/SOFTWARE/Microsoft/Windows NT/CurrentVersion/Image File Execution Options/SpIDerMl.exe | Debugger | 6E 74 73 64 20 2D 64
|
added | HKLM/SOFTWARE/Microsoft/Windows NT/CurrentVersion/Image File Execution Options/spidernt.exe | Debugger | 6E 74 73 64 20 2D 64
|
added | HKLM/SOFTWARE/Microsoft/Windows NT/CurrentVersion/Image File Execution Options/spiderui.exe | Debugger | 6E 74 73 64 20 2D 64
|
added | HKLM/SOFTWARE/Microsoft/Windows NT/CurrentVersion/Image File Execution Options/TMBMSRV.exe | Debugger | 6E 74 73 64 20 2D 64
|
added | HKLM/SOFTWARE/Microsoft/Windows NT/CurrentVersion/Image File Execution Options/TmProxy.exe | Debugger | 6E 74 73 64 20 2D 64
|
added | HKLM/SOFTWARE/Microsoft/Windows NT/CurrentVersion/Image File Execution Options/Twister.exe | Debugger | 6E 74 73 64 20 2D 64
|
added | HKLM/SOFTWARE/Microsoft/Windows NT/CurrentVersion/Image File Execution Options/UfSeAgnt.exe | Debugger | 6E 74 73 64 20 2D 64
|
added | HKLM/SOFTWARE/Microsoft/Windows NT/CurrentVersion/Image File Execution Options/vsserv.exe | Debugger | 6E 74 73 64 20 2D 64
|
added | HKLM/SOFTWARE/Microsoft/Windows NT/CurrentVersion/Image File Execution Options/zhudongfangyu.exe | Debugger | 6E 74 73 64 20 2D 64
|
added | HKLM/SOFTWARE/Microsoft/Windows NT/CurrentVersion/Image File Execution Options/ÐÞ¸´¹¤¾ß.exe | Debugger | 6E 74 73 64 20 2D 64
|
added | HKLM/SYSTEM/ControlSet001/Enum/Root/LEGACY_BITS/0000/Control | ActiveService | "BITS"
|
added | HKLM/SYSTEM/ControlSet001/Enum/Root/LEGACY_FASTFAT/0000/Control | ActiveService | "Fastfat"
|
added | HKLM/SYSTEM/ControlSet001/Services/{9B7E3E9B-6887-4894-8EE4-B4EFDC3EBE75}/Parameters/Tcpip | EnableDHCP | 0x00000000
|
added | HKLM/SYSTEM/ControlSet001/Services/{9B7E3E9B-6887-4894-8EE4-B4EFDC3EBE75}/Parameters/Tcpip | DhcpIPAddress | "0.0.0.0"
|
added | HKLM/SYSTEM/ControlSet001/Services/{9B7E3E9B-6887-4894-8EE4-B4EFDC3EBE75}/Parameters/Tcpip | DhcpSubnetMask | "255.0.0.0"
|
added | HKLM/SYSTEM/ControlSet001/Services/{9B7E3E9B-6887-4894-8EE4-B4EFDC3EBE75}/Parameters/Tcpip | DhcpServer | "255.255.255.255"
|
added | HKLM/SYSTEM/ControlSet001/Services/{9B7E3E9B-6887-4894-8EE4-B4EFDC3EBE75}/Parameters/Tcpip | Lease | 0x00000E10
|
added | HKLM/SYSTEM/ControlSet001/Services/{9B7E3E9B-6887-4894-8EE4-B4EFDC3EBE75}/Parameters/Tcpip | LeaseObtainedTime | 0x4A449F0E
|
added | HKLM/SYSTEM/ControlSet001/Services/{9B7E3E9B-6887-4894-8EE4-B4EFDC3EBE75}/Parameters/Tcpip | T1 | 0x4A44A616
|
added | HKLM/SYSTEM/ControlSet001/Services/{9B7E3E9B-6887-4894-8EE4-B4EFDC3EBE75}/Parameters/Tcpip | T2 | 0x4A44AB5C
|
added | HKLM/SYSTEM/ControlSet001/Services/{9B7E3E9B-6887-4894-8EE4-B4EFDC3EBE75}/Parameters/Tcpip | LeaseTerminatesTime | 0x4A44AD1E
|
added | HKLM/SYSTEM/ControlSet001/Services/{9B7E3E9B-6887-4894-8EE4-B4EFDC3EBE75}/Parameters/Tcpip | EnableDHCP | 0x00000000
|
added | HKLM/SYSTEM/ControlSet001/Services/{9B7E3E9B-6887-4894-8EE4-B4EFDC3EBE75}/Parameters/Tcpip | DhcpIPAddress | "0.0.0.0"
|
added | HKLM/SYSTEM/ControlSet001/Services/{9B7E3E9B-6887-4894-8EE4-B4EFDC3EBE75}/Parameters/Tcpip | DhcpSubnetMask | "255.0.0.0"
|
added | HKLM/SYSTEM/ControlSet001/Services/{9B7E3E9B-6887-4894-8EE4-B4EFDC3EBE75}/Parameters/Tcpip | DhcpServer | "255.255.255.255"
|
added | HKLM/SYSTEM/ControlSet001/Services/{9B7E3E9B-6887-4894-8EE4-B4EFDC3EBE75}/Parameters/Tcpip | Lease | 0x00000E10
|
added | HKLM/SYSTEM/ControlSet001/Services/{9B7E3E9B-6887-4894-8EE4-B4EFDC3EBE75}/Parameters/Tcpip | LeaseObtainedTime | 0x4A449F0E
|
added | HKLM/SYSTEM/ControlSet001/Services/{9B7E3E9B-6887-4894-8EE4-B4EFDC3EBE75}/Parameters/Tcpip | T1 | 0x4A44A616
|
added | HKLM/SYSTEM/ControlSet001/Services/{9B7E3E9B-6887-4894-8EE4-B4EFDC3EBE75}/Parameters/Tcpip | T2 | 0x4A44AB5C
|
added | HKLM/SYSTEM/ControlSet001/Services/{9B7E3E9B-6887-4894-8EE4-B4EFDC3EBE75}/Parameters/Tcpip | LeaseTerminatesTime | 0x4A44AD1E
|
added | HKLM/SYSTEM/CurrentControlSet/Enum/Root/LEGACY_BITS/0000/Control | ActiveService | "BITS"
|
added | HKLM/SYSTEM/CurrentControlSet/Enum/Root/LEGACY_FASTFAT/0000/Control | ActiveService | "Fastfat"
|
added | HKLM/SYSTEM/CurrentControlSet/Services/{9B7E3E9B-6887-4894-8EE4-B4EFDC3EBE75}/Parameters/Tcpip | EnableDHCP | 0x00000000
|
added | HKLM/SYSTEM/CurrentControlSet/Services/{9B7E3E9B-6887-4894-8EE4-B4EFDC3EBE75}/Parameters/Tcpip | DhcpIPAddress | "0.0.0.0"
|
added | HKLM/SYSTEM/CurrentControlSet/Services/{9B7E3E9B-6887-4894-8EE4-B4EFDC3EBE75}/Parameters/Tcpip | DhcpSubnetMask | "255.0.0.0"
|
added | HKLM/SYSTEM/CurrentControlSet/Services/{9B7E3E9B-6887-4894-8EE4-B4EFDC3EBE75}/Parameters/Tcpip | DhcpServer | "255.255.255.255"
|
added | HKLM/SYSTEM/CurrentControlSet/Services/{9B7E3E9B-6887-4894-8EE4-B4EFDC3EBE75}/Parameters/Tcpip | Lease | 0x00000E10
|
added | HKLM/SYSTEM/CurrentControlSet/Services/{9B7E3E9B-6887-4894-8EE4-B4EFDC3EBE75}/Parameters/Tcpip | LeaseObtainedTime | 0x4A449F0E
|
added | HKLM/SYSTEM/CurrentControlSet/Services/{9B7E3E9B-6887-4894-8EE4-B4EFDC3EBE75}/Parameters/Tcpip | T1 | 0x4A44A616
|
added | HKLM/SYSTEM/CurrentControlSet/Services/{9B7E3E9B-6887-4894-8EE4-B4EFDC3EBE75}/Parameters/Tcpip | T2 | 0x4A44AB5C
|
added | HKLM/SYSTEM/CurrentControlSet/Services/{9B7E3E9B-6887-4894-8EE4-B4EFDC3EBE75}/Parameters/Tcpip | LeaseTerminatesTime | 0x4A44AD1E
|
added | HKLM/SYSTEM/CurrentControlSet/Services/{9B7E3E9B-6887-4894-8EE4-B4EFDC3EBE75}/Parameters/Tcpip | EnableDHCP | 0x00000000
|
added | HKLM/SYSTEM/CurrentControlSet/Services/{9B7E3E9B-6887-4894-8EE4-B4EFDC3EBE75}/Parameters/Tcpip | DhcpIPAddress | "0.0.0.0"
|
added | HKLM/SYSTEM/CurrentControlSet/Services/{9B7E3E9B-6887-4894-8EE4-B4EFDC3EBE75}/Parameters/Tcpip | DhcpSubnetMask | "255.0.0.0"
|
added | HKLM/SYSTEM/CurrentControlSet/Services/{9B7E3E9B-6887-4894-8EE4-B4EFDC3EBE75}/Parameters/Tcpip | DhcpServer | "255.255.255.255"
|
added | HKLM/SYSTEM/CurrentControlSet/Services/{9B7E3E9B-6887-4894-8EE4-B4EFDC3EBE75}/Parameters/Tcpip | Lease | 0x00000E10
|
added | HKLM/SYSTEM/CurrentControlSet/Services/{9B7E3E9B-6887-4894-8EE4-B4EFDC3EBE75}/Parameters/Tcpip | LeaseObtainedTime | 0x4A449F0E
|
added | HKLM/SYSTEM/CurrentControlSet/Services/{9B7E3E9B-6887-4894-8EE4-B4EFDC3EBE75}/Parameters/Tcpip | T1 | 0x4A44A616
|
added | HKLM/SYSTEM/CurrentControlSet/Services/{9B7E3E9B-6887-4894-8EE4-B4EFDC3EBE75}/Parameters/Tcpip | T2 | 0x4A44AB5C
|
added | HKLM/SYSTEM/CurrentControlSet/Services/{9B7E3E9B-6887-4894-8EE4-B4EFDC3EBE75}/Parameters/Tcpip | LeaseTerminatesTime | 0x4A44AD1E
|
added | HKU/.DEFAULT/Software/Microsoft/Internet Explorer/Extensions/CmdMapping | {08B0E5C0-4FCB-11CF-AAA5-00401C608501} | 0x00002000
|
added | HKU/.DEFAULT/Software/Microsoft/Internet Explorer/Extensions/CmdMapping | NextId | 0x00002002
|
added | HKU/.DEFAULT/Software/Microsoft/Internet Explorer/Extensions/CmdMapping | {FB5F1910-F110-11d2-BB9E-00C04F795683} | 0x00002001
|
added | HKU/.DEFAULT/Software/Microsoft/Internet Explorer/Security/P3Global | Enabled | 0x00000001
|
added | HKU/.DEFAULT/Software/Microsoft/Internet Explorer/Toolbar | Locked | 0x00000001
|
added | HKU/.DEFAULT/Software/Microsoft/Windows/CurrentVersion/Explorer/CabinetState | Settings | 0C 00 02 00 0B 01 F8 75 60 00 00 00
|
added | HKU/.DEFAULT/Software/Microsoft/Windows/CurrentVersion/Explorer/MenuOrder/Favorites/Links | Order | 08 00 00 00 02 00 00 00 0C 00 00 00 01 00 00 00 00 00 00 00
|
added | HKU/.DEFAULT/Software/Microsoft/Windows/CurrentVersion/Internet Settings | ProxyEnable | 0x00000000
|
added | HKU/.DEFAULT/Software/Microsoft/Windows/CurrentVersion/Internet Settings/Connections | SavedLegacySettings | 3C 00 00 00 03 00 00 00 01 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 04 00 00 |
added | HKU/.DEFAULT/Software/Microsoft/Windows/CurrentVersion/Internet Settings/Connections | DefaultConnectionSettings | 3C 00 00 00 01 00 00 00 01 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 04 00 00 |
added | HKU/.DEFAULT/Software/Microsoft/Windows/CurrentVersion/Ext/Stats/{06849E9F-C8D7-4D59-B87D-784B7D6BE0B3}/iexplore | Type | 0x00000003
|
added | HKU/.DEFAULT/Software/Microsoft/Windows/CurrentVersion/Ext/Stats/{06849E9F-C8D7-4D59-B87D-784B7D6BE0B3}/iexplore | Count | 0x00000001
|
added | HKU/.DEFAULT/Software/Microsoft/Windows/CurrentVersion/Ext/Stats/{06849E9F-C8D7-4D59-B87D-784B7D6BE0B3}/iexplore | Time | DB 07 0A 00 05 00 07 00 07 00 09 00 33 00 45 03
|
added | HKU/.DEFAULT/Software/Microsoft/Windows/CurrentVersion/Ext/Stats/{08B0E5C0-4FCB-11CF-AAA5-00401C608501}/iexplore | Type | 0x00000004
|
added | HKU/.DEFAULT/Software/Microsoft/Windows/CurrentVersion/Ext/Stats/{08B0E5C0-4FCB-11CF-AAA5-00401C608501}/iexplore | Count | 0x00000001
|
added | HKU/.DEFAULT/Software/Microsoft/Windows/CurrentVersion/Ext/Stats/{08B0E5C0-4FCB-11CF-AAA5-00401C608501}/iexplore | Time | DB 07 0A 00 05 00 07 00 07 00 09 00 33 00 D2 03
|
added | HKU/.DEFAULT/Software/Microsoft/Windows/CurrentVersion/Ext/Stats/{FB5F1910-F110-11D2-BB9E-00C04F795683}/iexplore | Type | 0x00000004
|
added | HKU/.DEFAULT/Software/Microsoft/Windows/CurrentVersion/Ext/Stats/{FB5F1910-F110-11D2-BB9E-00C04F795683}/iexplore | Count | 0x00000001
|
added | HKU/.DEFAULT/Software/Microsoft/Windows/CurrentVersion/Ext/Stats/{FB5F1910-F110-11D2-BB9E-00C04F795683}/iexplore | Time | DB 07 0A 00 05 00 07 00 07 00 09 00 33 00 D2 03
|
added | HKU/.DEFAULT/Software/Microsoft/Windows/ShellNoRoam/MUICache | @shell32.dll,-12693: | "Favorites"
|
added | HKU/.DEFAULT/Software/Microsoft/Windows/ShellNoRoam/BagMRU | NodeSlots |
|
added | HKU/.DEFAULT/Software/Microsoft/Windows/ShellNoRoam/BagMRU | MRUListEx | FF FF FF FF
|
added | HKU/.DEFAULT/Software/Microsoft/Internet Connection Wizard | ShellNext | "http |
added | HKU/.DEFAULT/Software/Microsoft/Internet Connection Wizard | Completed | 01 00 00 00
|
added | HKU/S-1-5-18/Software/Microsoft/Internet Explorer/Extensions/CmdMapping | {08B0E5C0-4FCB-11CF-AAA5-00401C608501} | 0x00002000
|
added | HKU/S-1-5-18/Software/Microsoft/Internet Explorer/Extensions/CmdMapping | NextId | 0x00002002
|
added | HKU/S-1-5-18/Software/Microsoft/Internet Explorer/Extensions/CmdMapping | {FB5F1910-F110-11d2-BB9E-00C04F795683} | 0x00002001
|
added | HKU/S-1-5-18/Software/Microsoft/Internet Explorer/Security/P3Global | Enabled | 0x00000001
|
added | HKU/S-1-5-18/Software/Microsoft/Internet Explorer/Toolbar | Locked | 0x00000001
|
added | HKU/S-1-5-18/Software/Microsoft/Windows/CurrentVersion/Explorer/CabinetState | Settings | 0C 00 02 00 0B 01 F8 75 60 00 00 00
|
added | HKU/S-1-5-18/Software/Microsoft/Windows/CurrentVersion/Explorer/MenuOrder/Favorites/Links | Order | 08 00 00 00 02 00 00 00 0C 00 00 00 01 00 00 00 00 00 00 00
|
added | HKU/S-1-5-18/Software/Microsoft/Windows/CurrentVersion/Internet Settings | ProxyEnable | 0x00000000
|
added | HKU/S-1-5-18/Software/Microsoft/Windows/CurrentVersion/Internet Settings/Connections | SavedLegacySettings | 3C 00 00 00 03 00 00 00 01 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 04 00 00 |
added | HKU/S-1-5-18/Software/Microsoft/Windows/CurrentVersion/Internet Settings/Connections | DefaultConnectionSettings | 3C 00 00 00 01 00 00 00 01 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 04 00 00 |
added | HKU/S-1-5-18/Software/Microsoft/Windows/CurrentVersion/Ext/Stats/{06849E9F-C8D7-4D59-B87D-784B7D6BE0B3}/iexplore | Type | 0x00000003
|
added | HKU/S-1-5-18/Software/Microsoft/Windows/CurrentVersion/Ext/Stats/{06849E9F-C8D7-4D59-B87D-784B7D6BE0B3}/iexplore | Count | 0x00000001
|
added | HKU/S-1-5-18/Software/Microsoft/Windows/CurrentVersion/Ext/Stats/{06849E9F-C8D7-4D59-B87D-784B7D6BE0B3}/iexplore | Time | DB 07 0A 00 05 00 07 00 07 00 09 00 33 00 45 03
|
added | HKU/S-1-5-18/Software/Microsoft/Windows/CurrentVersion/Ext/Stats/{08B0E5C0-4FCB-11CF-AAA5-00401C608501}/iexplore | Type | 0x00000004
|
added | HKU/S-1-5-18/Software/Microsoft/Windows/CurrentVersion/Ext/Stats/{08B0E5C0-4FCB-11CF-AAA5-00401C608501}/iexplore | Count | 0x00000001
|
added | HKU/S-1-5-18/Software/Microsoft/Windows/CurrentVersion/Ext/Stats/{08B0E5C0-4FCB-11CF-AAA5-00401C608501}/iexplore | Time | DB 07 0A 00 05 00 07 00 07 00 09 00 33 00 D2 03
|
added | HKU/S-1-5-18/Software/Microsoft/Windows/CurrentVersion/Ext/Stats/{FB5F1910-F110-11D2-BB9E-00C04F795683}/iexplore | Type | 0x00000004
|
added | HKU/S-1-5-18/Software/Microsoft/Windows/CurrentVersion/Ext/Stats/{FB5F1910-F110-11D2-BB9E-00C04F795683}/iexplore | Count | 0x00000001
|
added | HKU/S-1-5-18/Software/Microsoft/Windows/CurrentVersion/Ext/Stats/{FB5F1910-F110-11D2-BB9E-00C04F795683}/iexplore | Time | DB 07 0A 00 05 00 07 00 07 00 09 00 33 00 D2 03
|
added | HKU/S-1-5-18/Software/Microsoft/Windows/ShellNoRoam/MUICache | @shell32.dll,-12693: | "Favorites"
|
added | HKU/S-1-5-18/Software/Microsoft/Windows/ShellNoRoam/BagMRU | NodeSlots |
|
added | HKU/S-1-5-18/Software/Microsoft/Windows/ShellNoRoam/BagMRU | MRUListEx | FF FF FF FF
|
added | HKU/S-1-5-18/Software/Microsoft/Internet Connection Wizard | ShellNext | "http |
added | HKU/S-1-5-18/Software/Microsoft/Internet Connection Wizard | Completed | 01 00 00 00
|
Action | Path | Val_Name | Val_Type | Mod_Val_Type | Val_Data | Mod_Val_Data |
---|
deleted | HKLM/SYSTEM/ControlSet001/Enum/Root/LEGACY_APPMGMT/0000/Service: "AppMgmt"
| | N/A | |
deleted | HKLM/SYSTEM/ControlSet001/Enum/Root/LEGACY_APPMGMT/0000/Legacy: 0x00000001
| | N/A | |
deleted | HKLM/SYSTEM/ControlSet001/Enum/Root/LEGACY_APPMGMT/0000/ConfigFlags: 0x00000000
| | N/A | |
deleted | HKLM/SYSTEM/ControlSet001/Enum/Root/LEGACY_APPMGMT/0000/Class: "LegacyDriver"
| | N/A | |
deleted | HKLM/SYSTEM/ControlSet001/Enum/Root/LEGACY_APPMGMT/0000/ClassGUID: "{8ECC055D-047F-11D1-A537-0000F8753ED1}"
| | N/A | |
deleted | HKLM/SYSTEM/ControlSet001/Enum/Root/LEGACY_APPMGMT/0000/DeviceDesc: "Application Management"
| | N/A | |
deleted | HKLM/SYSTEM/ControlSet001/Enum/Root/LEGACY_APPMGMT/NextInstance: 0x00000001
| | N/A | |
deleted | HKLM/SYSTEM/ControlSet001/Services/AppMgmt/Enum/0: "Root/LEGACY_APPMGMT/0000"
| | N/A | |
deleted | HKLM/SYSTEM/ControlSet001/Services/AppMgmt/Enum/Count: 0x00000001
| | N/A | |
deleted | HKLM/SYSTEM/ControlSet001/Services/AppMgmt/Enum/NextInstance: 0x00000001
| | N/A | |
deleted | HKLM/SYSTEM/ControlSet001/Services/AppMgmt/Parameters/ServiceDll: "%SystemRoot%/System32/appmgmts.dll"
| | N/A | |
deleted | HKLM/SYSTEM/ControlSet001/Services/AppMgmt/Parameters/ServiceDllUnloadOnStop: 0x00000001
| | N/A | |
deleted | HKLM/SYSTEM/ControlSet001/Services/AppMgmt/Description: "Provides software installation services such as Assign, Publish, and Remove."
| | N/A | |
deleted | HKLM/SYSTEM/ControlSet001/Services/AppMgmt/DisplayName: "Application Management"
| | N/A | |
deleted | HKLM/SYSTEM/ControlSet001/Services/AppMgmt/ErrorControl: 0x00000001
| | N/A | |
deleted | HKLM/SYSTEM/ControlSet001/Services/AppMgmt/ImagePath: "%SystemRoot%/system32/svchost.exe -k netsvcs"
| | N/A | |
deleted | HKLM/SYSTEM/ControlSet001/Services/AppMgmt/ObjectName: "LocalSystem"
| | N/A | |
deleted | HKLM/SYSTEM/ControlSet001/Services/AppMgmt/Start: 0x00000003
| | N/A | |
deleted | HKLM/SYSTEM/ControlSet001/Services/AppMgmt/Type: 0x00000020
| | N/A | |
deleted | HKLM/SYSTEM/CurrentControlSet/Enum/Root/LEGACY_APPMGMT/0000/Service: "AppMgmt"
| | N/A | |
deleted | HKLM/SYSTEM/CurrentControlSet/Enum/Root/LEGACY_APPMGMT/0000/Legacy: 0x00000001
| | N/A | |
deleted | HKLM/SYSTEM/CurrentControlSet/Enum/Root/LEGACY_APPMGMT/0000/ConfigFlags: 0x00000000
| | N/A | |
deleted | HKLM/SYSTEM/CurrentControlSet/Enum/Root/LEGACY_APPMGMT/0000/Class: "LegacyDriver"
| | N/A | |
deleted | HKLM/SYSTEM/CurrentControlSet/Enum/Root/LEGACY_APPMGMT/0000/ClassGUID: "{8ECC055D-047F-11D1-A537-0000F8753ED1}"
| | N/A | |
deleted | HKLM/SYSTEM/CurrentControlSet/Enum/Root/LEGACY_APPMGMT/0000/DeviceDesc: "Application Management"
| | N/A | |
deleted | HKLM/SYSTEM/CurrentControlSet/Enum/Root/LEGACY_APPMGMT/NextInstance: 0x00000001
| | N/A | |
deleted | HKLM/SYSTEM/CurrentControlSet/Services/AppMgmt/Enum/0: "Root/LEGACY_APPMGMT/0000"
| | N/A | |
deleted | HKLM/SYSTEM/CurrentControlSet/Services/AppMgmt/Enum/Count: 0x00000001
| | N/A | |
deleted | HKLM/SYSTEM/CurrentControlSet/Services/AppMgmt/Enum/NextInstance: 0x00000001
| | N/A | |
deleted | HKLM/SYSTEM/CurrentControlSet/Services/AppMgmt/Parameters/ServiceDll: "%SystemRoot%/System32/appmgmts.dll"
| | N/A | |
deleted | HKLM/SYSTEM/CurrentControlSet/Services/AppMgmt/Parameters/ServiceDllUnloadOnStop: 0x00000001
| | N/A | |
deleted | HKLM/SYSTEM/CurrentControlSet/Services/AppMgmt/Description: "Provides software installation services such as Assign, Publish, and Remove."
| | N/A | |
deleted | HKLM/SYSTEM/CurrentControlSet/Services/AppMgmt/DisplayName: "Application Management"
| | N/A | |
deleted | HKLM/SYSTEM/CurrentControlSet/Services/AppMgmt/ErrorControl: 0x00000001
| | N/A | |
deleted | HKLM/SYSTEM/CurrentControlSet/Services/AppMgmt/ImagePath: "%SystemRoot%/system32/svchost.exe -k netsvcs"
| | N/A | |
deleted | HKLM/SYSTEM/CurrentControlSet/Services/AppMgmt/ObjectName: "LocalSystem"
| | N/A | |
deleted | HKLM/SYSTEM/CurrentControlSet/Services/AppMgmt/Start: 0x00000003
| | N/A | |
deleted | HKLM/SYSTEM/CurrentControlSet/Services/AppMgmt/Type: 0x00000020
| | N/A | |
Action | Path | Val_Name | Val_Data | Mod_Val_Data |
---|
modified | HKLM/SOFTWARE/Microsoft/Cryptography/RNG | Seed | F4 84 91 A0 EF C8 B0 CD 5B D0 5D 9D DE B2 D3 FC C7 D4 DC 62 65 38 41 78 05 A2 14 | 49 C3 56 3C 94 75 F7 9B 0C B3 9B 5B 13 B3 AD 00 5D 35 65 72 6A F5 18 92 A1 65 04 |
modified | HKLM/SOFTWARE/Microsoft/SystemCertificates/AuthRoot/Certificates/0048F8D37B153F6EA2798C323EF4F318A5624A9E | Blob | 14 00 00 00 01 00 00 00 14 00 00 00 A4 A5 D4 D1 5F A0 C9 A8 4B 20 8D AC 4B 71 64 | 04 00 00 00 01 00 00 00 10 00 00 00 15 B2 98 A3 54 70 40 48 70 3A 37 55 82 C4 5A |
modified | HKLM/SOFTWARE/Microsoft/SystemCertificates/AuthRoot/Certificates/00EA522C8A9C06AA3ECCE0B4FA6CDC21D92E8099 | Blob | 14 00 00 00 01 00 00 00 14 00 00 00 AB 06 44 40 2A 02 F0 56 E2 92 05 07 47 7D 02 | 04 00 00 00 01 00 00 00 10 00 00 00 3E 80 17 5B AD D7 7C 10 4B F9 41 B0 CF 16 42 |
modified | HKLM/SOFTWARE/Microsoft/SystemCertificates/AuthRoot/Certificates/0483ED3399AC3608058722EDBC5E4600E3BEF9D7 | Blob | 14 00 00 00 01 00 00 00 14 00 00 00 A1 72 5F 26 1B 28 98 43 95 5D 07 37 D5 85 96 | 04 00 00 00 01 00 00 00 10 00 00 00 4C 56 41 E5 0D BB 2B E8 CA A3 ED 18 08 AD 43 |
modified | HKLM/SOFTWARE/Microsoft/SystemCertificates/AuthRoot/Certificates/049811056AFE9FD0F5BE01685AACE6A5D1C4454C | Blob | 14 00 00 00 01 00 00 00 14 00 00 00 B7 57 67 50 94 4C 16 3A 48 80 6E EA FF 4C EC | 04 00 00 00 01 00 00 00 10 00 00 00 F2 7D E9 54 E4 A3 22 0D 76 9F E7 0B BB B3 24 |
modified | HKLM/SOFTWARE/Microsoft/SystemCertificates/AuthRoot/Certificates/0B77BEBBCB7AA24705DECC0FBD6A02FC7ABD9B52 | Blob | 14 00 00 00 01 00 00 00 14 00 00 00 98 E6 9D 04 2E 46 A9 CC E3 20 AC 94 2E B6 99 | 04 00 00 00 01 00 00 00 10 00 00 00 26 6D 2C 19 98 B6 70 68 38 50 54 19 EC 90 34 |
modified | HKLM/SOFTWARE/Microsoft/SystemCertificates/AuthRoot/Certificates/1331F48A5DA8E01DAACA1BB0C17044ACFEF755BB | Blob | 14 00 00 00 01 00 00 00 14 00 00 00 F2 55 78 4F A3 28 20 86 9D 43 A6 23 59 2A 15 | 04 00 00 00 01 00 00 00 10 00 00 00 50 E1 41 9D 59 73 8B 46 73 2D 7F 7F CF 5C 44 |
modified | HKLM/SOFTWARE/Microsoft/SystemCertificates/AuthRoot/Certificates/1F55E8839BAC30728BE7108EDE7B0BB0D3298224 | Blob | 14 00 00 00 01 00 00 00 14 00 00 00 D1 B1 5F 41 79 73 79 20 58 C9 2F A2 A8 47 C7 | 04 00 00 00 01 00 00 00 10 00 00 00 8C D7 9F EB C7 B8 14 4C 54 78 A7 90 3B A9 35 |
modified | HKLM/SOFTWARE/Microsoft/SystemCertificates/AuthRoot/Certificates/209900B63D955728140CD13622D8C687A4EB0085 | Blob | 14 00 00 00 01 00 00 00 14 00 00 00 72 49 C2 73 34 C6 55 F4 0B 76 72 81 7E 77 F4 | 04 00 00 00 01 00 00 00 10 00 00 00 1E 74 C3 86 3C 0C 35 C5 3E C2 7F EF 3C AA 3C |
modified | HKLM/SOFTWARE/Microsoft/SystemCertificates/AuthRoot/Certificates/216B2A29E62A00CE820146D8244141B92511B279 | Blob | 14 00 00 00 01 00 00 00 14 00 00 00 86 E1 E1 81 71 BF 6A 12 F1 0A F2 01 E4 C8 FB | 04 00 00 00 01 00 00 00 10 00 00 00 E1 4B 52 73 D7 1B DB 93 30 E5 BD E4 09 6E BE |
modified | HKLM/SOFTWARE/Microsoft/SystemCertificates/AuthRoot/Certificates/23E594945195F2414803B4D564D2A3A3F5D88B8C | Blob | 14 00 00 00 01 00 00 00 14 00 00 00 07 15 28 6D 70 73 AA B2 8A 7C 0F 86 CE 38 93 | 04 00 00 00 01 00 00 00 10 00 00 00 C5 70 C4 A2 ED 53 78 0C C8 10 53 81 64 CB D0 |
modified | HKLM/SOFTWARE/Microsoft/SystemCertificates/AuthRoot/Certificates/24A40A1F573643A67F0A4B0749F6A22BF28ABB6B | Blob | 14 00 00 00 01 00 00 00 14 00 00 00 90 2F 82 A3 7C 47 97 01 1E 0F 4B A5 AF 13 13 | 04 00 00 00 01 00 00 00 10 00 00 00 DD 75 3F 56 BF BB C5 A1 7A 15 53 C6 90 F9 FB |
modified | HKLM/SOFTWARE/Microsoft/SystemCertificates/AuthRoot/Certificates/24BA6D6C8A5B5837A48DB5FAE919EA675C94D217 | Blob | 14 00 00 00 01 00 00 00 14 00 00 00 28 C8 72 9E DB C9 73 51 D3 5D 0E 2D 99 44 DD | 04 00 00 00 01 00 00 00 10 00 00 00 7B B5 08 99 9A 8C 18 BF 85 27 7D 0E AE DA B2 |
modified | HKLM/SOFTWARE/Microsoft/SystemCertificates/AuthRoot/Certificates/273EE12457FDC4F90C55E82B56167F62F532E547 | Blob | 14 00 00 00 01 00 00 00 14 00 00 00 B7 57 67 50 94 4C 16 3A 48 80 6E EA FF 4C EC | 04 00 00 00 01 00 00 00 10 00 00 00 DB 23 3D F9 69 FA 4B B9 95 80 44 73 5E 7D 41 |
modified | HKLM/SOFTWARE/Microsoft/SystemCertificates/AuthRoot/Certificates/284F55C41A1A7A3F8328D4C262FB376ED6096F24 | Blob | 14 00 00 00 01 00 00 00 2C 00 00 00 43 3D 20 46 52 2C 20 4F 3D 20 43 65 72 74 69 | 04 00 00 00 01 00 00 00 10 00 00 00 01 1A 3F 4D B5 F8 14 C5 68 48 AD 08 3E B9 C8 |
modified | HKLM/SOFTWARE/Microsoft/SystemCertificates/AuthRoot/Certificates/2F173F7DE99667AFA57AF80AA2D1B12FAC830338 | Blob | 14 00 00 00 01 00 00 00 14 00 00 00 60 7B 66 1A 45 0D 97 CA 89 50 2F 7D 04 CD 34 | 04 00 00 00 01 00 00 00 10 00 00 00 AB BF EA E3 6B 29 A6 CC A6 78 35 99 EF AD 2B |
modified | HKLM/SOFTWARE/Microsoft/SystemCertificates/AuthRoot/Certificates/317A2AD07F2B335EF5A1C34E4B57E8B7D8F1FCA6 | Blob | 14 00 00 00 01 00 00 00 14 00 00 00 A8 48 B4 24 2F C6 EA 24 A0 D7 8E 3C B9 3C 5C | 04 00 00 00 01 00 00 00 10 00 00 00 A9 23 75 9B BA 49 36 6E 31 C2 DB F2 E7 66 BA |
modified | HKLM/SOFTWARE/Microsoft/SystemCertificates/AuthRoot/Certificates/36863563FD5128C7BEA6F005CFE9B43668086CCE | Blob | 14 00 00 00 01 00 00 00 14 00 00 00 E8 4E E5 C9 ED 84 83 53 9A E1 42 0E D5 4E C2 | 04 00 00 00 01 00 00 00 10 00 00 00 3A B2 DE 22 9A 20 93 49 F9 ED C8 D2 8A E7 68 |
modified | HKLM/SOFTWARE/Microsoft/SystemCertificates/AuthRoot/Certificates/394FF6850B06BE52E51856CC10E180E882B385CC | Blob | 14 00 00 00 01 00 00 00 14 00 00 00 50 9E 0B EA AF 5E B9 20 48 A6 50 6A CB FD D8 | 04 00 00 00 01 00 00 00 10 00 00 00 AA BF BF 64 97 DA 98 1D 6F C6 08 3A 95 70 33 |
modified | HKLM/SOFTWARE/Microsoft/SystemCertificates/AuthRoot/Certificates/3F85F2BB4A62B0B58BE1614ABB0D4631B4BEF8BA | Blob | 14 00 00 00 01 00 00 00 14 00 00 00 98 E6 9D 04 2E 46 A9 CC E3 20 AC 94 2E B6 99 | 04 00 00 00 01 00 00 00 10 00 00 00 2A 5D 00 37 39 46 94 75 39 7B 11 A6 F2 93 41 |
modified | HKLM/SOFTWARE/Microsoft/SystemCertificates/AuthRoot/Certificates/4072BA31FEC351438480F62E6CB95508461EAB2F | Blob | 14 00 00 00 01 00 00 00 14 00 00 00 A6 B8 20 C9 16 4B 8F 4F 5C 0C C3 C3 EE 98 0D | 04 00 00 00 01 00 00 00 10 00 00 00 70 B5 7C 48 81 95 3E 80 DC 28 9B BA EF 1E E4 |
modified | HKLM/SOFTWARE/Microsoft/SystemCertificates/AuthRoot/Certificates/40E78C1D523D1CD9954FAC1A1AB3BD3CBAA15BFC | Blob | 14 00 00 00 01 00 00 00 14 00 00 00 AF C6 45 72 AB D9 E8 B3 88 94 2D BA E6 62 FA | 04 00 00 00 01 00 00 00 10 00 00 00 E6 0B D2 C9 CA 2D 88 DB 1A 71 0E 4B 78 EB 02 |
modified | HKLM/SOFTWARE/Microsoft/SystemCertificates/AuthRoot/Certificates/43DDB1FFF3B49B73831407F6BC8B975023D07C50 | Blob | 14 00 00 00 01 00 00 00 14 00 00 00 BD E1 53 2F BA FB 23 6C 5F 52 3F B8 82 2E 22 | 04 00 00 00 01 00 00 00 10 00 00 00 00 53 1D 1D 72 01 D4 23 C8 20 D0 0B 60 88 C5 |
modified | HKLM/SOFTWARE/Microsoft/SystemCertificates/AuthRoot/Certificates/43F9B110D5BAFD48225231B0D0082B372FEF9A54 | Blob | 14 00 00 00 01 00 00 00 14 00 00 00 40 9A 76 44 97 74 07 C4 AC 14 CB 1E 8D 4F 3A | 04 00 00 00 01 00 00 00 10 00 00 00 25 9D CF 5E B3 25 9D 95 B9 3F 00 86 5F 47 94 |
modified | HKLM/SOFTWARE/Microsoft/SystemCertificates/AuthRoot/Certificates/4463C531D7CCC1006794612BB656D3BF8257846F | Blob | 14 00 00 00 01 00 00 00 14 00 00 00 15 A1 44 60 3A 5E 09 FC 21 B2 92 E9 6D 5C 47 | 04 00 00 00 01 00 00 00 10 00 00 00 74 7B 82 03 43 F0 00 9E 6B B3 EC 47 BF 85 A5 |
modified | HKLM/SOFTWARE/Microsoft/SystemCertificates/AuthRoot/Certificates/47AFB915CDA26D82467B97FA42914468726138DD | Blob | 14 00 00 00 01 00 00 00 14 00 00 00 04 CD E1 16 DC 67 36 A9 0B C5 4F 75 10 4A 59 | 04 00 00 00 01 00 00 00 10 00 00 00 50 19 3E 2F E8 B6 F4 05 54 49 F3 AE C9 8B 3E |
modified | HKLM/SOFTWARE/Microsoft/SystemCertificates/AuthRoot/Certificates/4B421F7515F6AE8A6ECEF97F6982A400A4D9224E | Blob | 14 00 00 00 01 00 00 00 14 00 00 00 60 F8 5F 2F DB 3A B6 4B 69 41 D7 7C 22 FE 3D | 04 00 00 00 01 00 00 00 10 00 00 00 5A 11 B9 22 85 02 89 E1 C3 F2 2C E1 4E C1 01 |
modified | HKLM/SOFTWARE/Microsoft/SystemCertificates/AuthRoot/Certificates/4BA7B9DDD68788E12FF852E1A024204BF286A8F6 | Blob | 14 00 00 00 01 00 00 00 14 00 00 00 D0 63 94 ED 80 09 0B 27 9F E0 4F B6 FB 5C 27 | 04 00 00 00 01 00 00 00 10 00 00 00 18 AE 69 5D 15 CA B9 17 67 32 67 D5 97 B2 60 |
modified | HKLM/SOFTWARE/Microsoft/SystemCertificates/AuthRoot/Certificates/4C95A9902ABE0777CED18D6ACCC3372D2748381E | Blob | 14 00 00 00 01 00 00 00 14 00 00 00 64 C6 DC F7 32 68 0B B2 6C EA 4A CB 5E 6E 53 | 04 00 00 00 01 00 00 00 10 00 00 00 4B 1C 56 8C A0 E8 C7 9E 1E F5 EE 32 93 99 65 |
modified | HKLM/SOFTWARE/Microsoft/SystemCertificates/AuthRoot/Certificates/4EF2E6670AC9B5091FE06BE0E5483EAAD6BA32D9 | Blob | 14 00 00 00 01 00 00 00 14 00 00 00 55 E5 E7 94 62 B6 49 0D C6 3C BC 71 22 36 12 | 04 00 00 00 01 00 00 00 10 00 00 00 03 42 87 D7 C1 16 7D 18 AF A4 70 3C B8 31 2C |
modified | HKLM/SOFTWARE/Microsoft/SystemCertificates/AuthRoot/Certificates/4EFCED9C6BDD0C985CA3C7D253063C5BE6FC620C | Blob | 14 00 00 00 01 00 00 00 14 00 00 00 B8 C1 5A 24 EC EF 44 DA 73 7A 98 D7 CC C7 A8 | 04 00 00 00 01 00 00 00 10 00 00 00 85 2F F4 76 4C D5 42 6C CB 5E 7D F7 17 E8 35 |
modified | HKLM/SOFTWARE/Microsoft/SystemCertificates/CA/Certificates/E5215D3460C2C20BBE2D9FE5FB665DAA2C0E225C | Blob | 14 00 00 00 01 00 00 00 14 00 00 00 87 DB D4 5F B0 92 8D 4E 1D F8 15 67 E7 F2 AB | 04 00 00 00 01 00 00 00 10 00 00 00 6F 7E 74 A3 A1 3A CA BB 63 CF 74 04 17 05 FA |
modified | HKLM/SOFTWARE/Microsoft/SystemCertificates/CA/Certificates/FEE449EE0E3965A5246F000E87FDE2A065FD89D4 | Blob | 14 00 00 00 01 00 00 00 14 00 00 00 9A A6 58 7F 94 DD 91 D9 1E 63 DF D3 F0 CE 5F | 04 00 00 00 01 00 00 00 10 00 00 00 C0 A7 23 F0 DA 35 02 6B 21 ED B1 75 97 F1 D4 |
modified | HKLM/SOFTWARE/Microsoft/Windows/CurrentVersion/Internet Settings/Cache/Paths | Directory | "C | "C:Documents and SettingsNetworkServiceLocal SettingsTemporary Internet FilesCon |
modified | HKLM/SOFTWARE/Microsoft/Windows/CurrentVersion/Internet Settings/Cache/Paths/path1 | CachePath | "C | "C:Documents and SettingsNetworkServiceLocal SettingsTemporary Internet FilesCon |
modified | HKLM/SOFTWARE/Microsoft/Windows/CurrentVersion/Internet Settings/Cache/Paths/path2 | CachePath | "C | "C:Documents and SettingsNetworkServiceLocal SettingsTemporary Internet FilesCon |
modified | HKLM/SOFTWARE/Microsoft/Windows/CurrentVersion/Internet Settings/Cache/Paths/path3 | CachePath | "C | "C:Documents and SettingsNetworkServiceLocal SettingsTemporary Internet FilesCon |
modified | HKLM/SOFTWARE/Microsoft/Windows/CurrentVersion/Internet Settings/Cache/Paths/path4 | CachePath | "C | "C:Documents and SettingsNetworkServiceLocal SettingsTemporary Internet FilesCon |
modified | HKLM/SYSTEM/ControlSet001/Services/BITS | Start | 0x00000003 | 0x00000002 |
modified | HKLM/SYSTEM/ControlSet001/Services/BITS/Parameters | ServiceDll | "C | "C:WINDOWSsystem32RxmutlC.dll" |
modified | HKLM/SYSTEM/ControlSet001/Services/Eventlog/Application/ESENT | EventMessageFile | "c | "C:WINDOWSsystem32ESENT.dll" |
modified | HKLM/SYSTEM/ControlSet001/Services/Eventlog/Application/ESENT | CategoryMessageFile | "c | "C:WINDOWSsystem32ESENT.dll" |
modified | HKLM/SYSTEM/CurrentControlSet/Services/BITS | Start | 0x00000003 | 0x00000002 |
modified | HKLM/SYSTEM/CurrentControlSet/Services/BITS/Parameters | ServiceDll | "C | "C:WINDOWSsystem32RxmutlC.dll" |
modified | HKLM/SYSTEM/CurrentControlSet/Services/Eventlog/Application/ESENT | EventMessageFile | "c | "C:WINDOWSsystem32ESENT.dll" |
modified | HKLM/SYSTEM/CurrentControlSet/Services/Eventlog/Application/ESENT | CategoryMessageFile | "c | "C:WINDOWSsystem32ESENT.dll" |
modified | HKU/.DEFAULT/Software/Microsoft/Windows/CurrentVersion/Explorer/Shell Folders | AppData | "C | "C:Documents and SettingsNetworkServiceApplication Data" |
modified | HKU/.DEFAULT/Software/Microsoft/Windows/CurrentVersion/Explorer/Shell Folders | Cookies | "C | "C:Documents and SettingsNetworkServiceCookies" |
modified | HKU/.DEFAULT/Software/Microsoft/Windows/CurrentVersion/Explorer/Shell Folders | Desktop | "C | "" |
modified | HKU/.DEFAULT/Software/Microsoft/Windows/CurrentVersion/Explorer/Shell Folders | Favorites | "C | "C:Documents and SettingsNetworkServiceFavorites" |
modified | HKU/.DEFAULT/Software/Microsoft/Windows/CurrentVersion/Explorer/Shell Folders | Cache | "C | "C:Documents and SettingsNetworkServiceLocal SettingsTemporary Internet Files" |
modified | HKU/.DEFAULT/Software/Microsoft/Windows/CurrentVersion/Explorer/Shell Folders | History | "C | "C:Documents and SettingsNetworkServiceLocal SettingsHistory" |
modified | HKU/S-1-5-21-1844237615-562591055-839522115-1004/Software/Microsoft/Windows/CurrentVersion/Internet Settings/Connections | SavedLegacySettings | 3C 00 00 00 15 00 00 00 01 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 04 00 00 | 3C 00 00 00 16 00 00 00 01 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 04 00 00 |
modified | HKU/S-1-5-18/Software/Microsoft/Windows/CurrentVersion/Explorer/Shell Folders | AppData | "C | "C:Documents and SettingsNetworkServiceApplication Data" |
modified | HKU/S-1-5-18/Software/Microsoft/Windows/CurrentVersion/Explorer/Shell Folders | Cookies | "C | "C:Documents and SettingsNetworkServiceCookies" |
modified | HKU/S-1-5-18/Software/Microsoft/Windows/CurrentVersion/Explorer/Shell Folders | Desktop | "C | "" |
modified | HKU/S-1-5-18/Software/Microsoft/Windows/CurrentVersion/Explorer/Shell Folders | Favorites | "C | "C:Documents and SettingsNetworkServiceFavorites" |
modified | HKU/S-1-5-18/Software/Microsoft/Windows/CurrentVersion/Explorer/Shell Folders | Cache | "C | "C:Documents and SettingsNetworkServiceLocal SettingsTemporary Internet Files" |
modified | HKU/S-1-5-18/Software/Microsoft/Windows/CurrentVersion/Explorer/Shell Folders | History | "C | "C:Documents and SettingsNetworkServiceLocal SettingsHistory" |