Action | Path | Val_Name | Val_Data |
---|
added | HKLM/SOFTWARE/Microsoft/Windows/CurrentVersion/policies/Explorer/run | Update service | "C:/DOCUME~1/dmc73144/LOCALS~1/Temp/winsvchost/svchost.exe"
|
added | HKLM/SYSTEM/ControlSet001/Enum/Root/LEGACY_TRANSCENDQUICKLOAD/0000/Control | *NewlyCreated* | 0x00000000
|
added | HKLM/SYSTEM/ControlSet001/Enum/Root/LEGACY_TRANSCENDQUICKLOAD/0000/Control | ActiveService | "TranscendQuickLoad"
|
added | HKLM/SYSTEM/ControlSet001/Enum/Root/LEGACY_TRANSCENDQUICKLOAD/0000 | Service | "TranscendQuickLoad"
|
added | HKLM/SYSTEM/ControlSet001/Enum/Root/LEGACY_TRANSCENDQUICKLOAD/0000 | Legacy | 0x00000001
|
added | HKLM/SYSTEM/ControlSet001/Enum/Root/LEGACY_TRANSCENDQUICKLOAD/0000 | ConfigFlags | 0x00000000
|
added | HKLM/SYSTEM/ControlSet001/Enum/Root/LEGACY_TRANSCENDQUICKLOAD/0000 | Class | "LegacyDriver"
|
added | HKLM/SYSTEM/ControlSet001/Enum/Root/LEGACY_TRANSCENDQUICKLOAD/0000 | ClassGUID | "{8ECC055D-047F-11D1-A537-0000F8753ED1}"
|
added | HKLM/SYSTEM/ControlSet001/Enum/Root/LEGACY_TRANSCENDQUICKLOAD/0000 | DeviceDesc | "Transcend Quick Load Service"
|
added | HKLM/SYSTEM/ControlSet001/Enum/Root/LEGACY_TRANSCENDQUICKLOAD | NextInstance | 0x00000001
|
added | HKLM/SYSTEM/ControlSet001/Services/SharedAccess/Parameters/FirewallPolicy/StandardProfile/GloballyOpenPorts/List | 8364 | TCP |
added | HKLM/SYSTEM/ControlSet001/Services/SharedAccess/Parameters/FirewallPolicy/StandardProfile/GloballyOpenPorts/List | 8008 | TCP |
added | HKLM/SYSTEM/ControlSet001/Services/TranscendQuickLoad/Enum | 0 | "RootLEGACY_TRANSCENDQUICKLOAD0000"
|
added | HKLM/SYSTEM/ControlSet001/Services/TranscendQuickLoad/Enum | Count | 0x00000001
|
added | HKLM/SYSTEM/ControlSet001/Services/TranscendQuickLoad/Enum | NextInstance | 0x00000001
|
added | HKLM/SYSTEM/ControlSet001/Services/TranscendQuickLoad/Security | Security | 01 00 14 80 90 00 00 00 9C 00 00 00 14 00 00 00 30 00 00 00 02 00 1C 00 01 00 00 |
added | HKLM/SYSTEM/ControlSet001/Services/TranscendQuickLoad | Type | 0x00000010
|
added | HKLM/SYSTEM/ControlSet001/Services/TranscendQuickLoad | Start | 0x00000002
|
added | HKLM/SYSTEM/ControlSet001/Services/TranscendQuickLoad | ErrorControl | 0x00000000
|
added | HKLM/SYSTEM/ControlSet001/Services/TranscendQuickLoad | ImagePath | "C:/WINDOWS/system32/TranscL.exe"
|
added | HKLM/SYSTEM/ControlSet001/Services/TranscendQuickLoad | DisplayName | "Transcend Quick Load Service"
|
added | HKLM/SYSTEM/ControlSet001/Services/TranscendQuickLoad | ObjectName | "LocalSystem"
|
added | HKLM/SYSTEM/ControlSet001/Services/TranscendQuickLoad | Description | "Transcend Quick Load"
|
added | HKLM/SYSTEM/CurrentControlSet/Enum/Root/LEGACY_TRANSCENDQUICKLOAD/0000/Control | *NewlyCreated* | 0x00000000
|
added | HKLM/SYSTEM/CurrentControlSet/Enum/Root/LEGACY_TRANSCENDQUICKLOAD/0000/Control | ActiveService | "TranscendQuickLoad"
|
added | HKLM/SYSTEM/CurrentControlSet/Enum/Root/LEGACY_TRANSCENDQUICKLOAD/0000 | Service | "TranscendQuickLoad"
|
added | HKLM/SYSTEM/CurrentControlSet/Enum/Root/LEGACY_TRANSCENDQUICKLOAD/0000 | Legacy | 0x00000001
|
added | HKLM/SYSTEM/CurrentControlSet/Enum/Root/LEGACY_TRANSCENDQUICKLOAD/0000 | ConfigFlags | 0x00000000
|
added | HKLM/SYSTEM/CurrentControlSet/Enum/Root/LEGACY_TRANSCENDQUICKLOAD/0000 | Class | "LegacyDriver"
|
added | HKLM/SYSTEM/CurrentControlSet/Enum/Root/LEGACY_TRANSCENDQUICKLOAD/0000 | ClassGUID | "{8ECC055D-047F-11D1-A537-0000F8753ED1}"
|
added | HKLM/SYSTEM/CurrentControlSet/Enum/Root/LEGACY_TRANSCENDQUICKLOAD/0000 | DeviceDesc | "Transcend Quick Load Service"
|
added | HKLM/SYSTEM/CurrentControlSet/Enum/Root/LEGACY_TRANSCENDQUICKLOAD | NextInstance | 0x00000001
|
added | HKLM/SYSTEM/CurrentControlSet/Services/SharedAccess/Parameters/FirewallPolicy/StandardProfile/GloballyOpenPorts/List | 8364 | TCP |
added | HKLM/SYSTEM/CurrentControlSet/Services/SharedAccess/Parameters/FirewallPolicy/StandardProfile/GloballyOpenPorts/List | 8008 | TCP |
added | HKLM/SYSTEM/CurrentControlSet/Services/TranscendQuickLoad/Enum | 0 | "RootLEGACY_TRANSCENDQUICKLOAD0000"
|
added | HKLM/SYSTEM/CurrentControlSet/Services/TranscendQuickLoad/Enum | Count | 0x00000001
|
added | HKLM/SYSTEM/CurrentControlSet/Services/TranscendQuickLoad/Enum | NextInstance | 0x00000001
|
added | HKLM/SYSTEM/CurrentControlSet/Services/TranscendQuickLoad/Security | Security | 01 00 14 80 90 00 00 00 9C 00 00 00 14 00 00 00 30 00 00 00 02 00 1C 00 01 00 00 |
added | HKLM/SYSTEM/CurrentControlSet/Services/TranscendQuickLoad | Type | 0x00000010
|
added | HKLM/SYSTEM/CurrentControlSet/Services/TranscendQuickLoad | Start | 0x00000002
|
added | HKLM/SYSTEM/CurrentControlSet/Services/TranscendQuickLoad | ErrorControl | 0x00000000
|
added | HKLM/SYSTEM/CurrentControlSet/Services/TranscendQuickLoad | ImagePath | "C:/WINDOWS/system32/TranscL.exe"
|
added | HKLM/SYSTEM/CurrentControlSet/Services/TranscendQuickLoad | DisplayName | "Transcend Quick Load Service"
|
added | HKLM/SYSTEM/CurrentControlSet/Services/TranscendQuickLoad | ObjectName | "LocalSystem"
|
added | HKLM/SYSTEM/CurrentControlSet/Services/TranscendQuickLoad | Description | "Transcend Quick Load"
|
added | HKU/S-1-5-21-1844237615-562591055-839522115-1004/Software/Microsoft/Windows/ShellNoRoam/MUICache | C://WINDOWS//system32//drivers//etc//Start.exe | "Start"
|
added | HKU/S-1-5-21-1844237615-562591055-839522115-1004/Software/Microsoft/Windows/ShellNoRoam/MUICache | C://WINDOWS//system32//drivers//etc//file1.exe | "file1"
|
added | HKU/S-1-5-21-1844237615-562591055-839522115-1004/Software/Microsoft/Windows/ShellNoRoam/MUICache | C://WINDOWS//system32//drivers//etc//file2.exe | "file2"
|
added | HKU/S-1-5-21-1844237615-562591055-839522115-1004/Software/Microsoft/Windows/ShellNoRoam/MUICache | C://WINDOWS//system32//drivers//etc//file3.exe | "Crosby Mauritania TampaAudreyOttawaSunnyvale"
|
added | HKU/S-1-5-21-1844237615-562591055-839522115-1004/Software/Microsoft/Windows/ShellNoRoam/MUICache | C://DOCUME~1//dmc73144//LOCALS~1//Temp//winsvchost//svchost.exe | "Crosby Mauritania TampaAudreyOttawaSunnyvale"
|
added | HKU/S-1-5-21-1844237615-562591055-839522115-1004/Software/WinRAR SFX | C%%WINDOWS%system32%drivers%etc | "C:/WINDOWS/system32/drivers/etc"
|