Action | Path | Val_Name | Val_Data |
---|
added | HKLM/SYSTEM/ControlSet001/Services/Tcpip/Parameters/Interfaces/{2379147B-6370-49A1-81EC-749CAFE9626A} | NameServer | "8.8.8.8,8.8.8.4"
|
added | HKLM/SYSTEM/ControlSet001/Services/Tcpip/Parameters/Interfaces/{42A772D2-FB5D-4B58-999A-7AD4C8696A02} | NameServer | "8.8.8.8,8.8.8.4"
|
added | HKLM/SYSTEM/CurrentControlSet/Services/Tcpip/Parameters/Interfaces/{2379147B-6370-49A1-81EC-749CAFE9626A} | NameServer | "8.8.8.8,8.8.8.4"
|
added | HKLM/SYSTEM/CurrentControlSet/Services/Tcpip/Parameters/Interfaces/{42A772D2-FB5D-4B58-999A-7AD4C8696A02} | NameServer | "8.8.8.8,8.8.8.4"
|
added | HKU/S-1-5-21-1844237615-562591055-839522115-1004/Software/Microsoft/Windows/CurrentVersion/Run | dwm.exe | "C:/Documents and Settings/dmc73144/Application Data/Microsoft/dwm.exe"
|
added | HKU/S-1-5-21-1844237615-562591055-839522115-1004/Software/Microsoft/Windows/ShellNoRoam/MUICache | C://windows//system32//sandnet.exe | "sandnet"
|
added | HKU/S-1-5-21-1844237615-562591055-839522115-1004/Software/Microsoft/Windows/ShellNoRoam/MUICache | C://Documents and Settings//dmc73144//Application Data//Microsoft//dwm.exe | "dwm"
|
Action | Path | Val_Name | Val_Data | Mod_Val_Data |
---|
modified | HKLM/SOFTWARE/Microsoft/Cryptography/RNG | Seed | C8 40 C9 DC FE CC 13 CE 8A C6 6F 7D 26 D3 D7 87 18 C8 86 6E C3 33 9F DB 8A 53 CA | 6C 5B 7D 04 7C 8F 25 AE 00 5F 89 6A BC 98 C9 2B 95 0B 65 16 D4 36 77 9B 90 05 D1 |
modified | HKLM/SYSTEM/ControlSet001/Services/Eventlog/Application/ESENT | EventMessageFile | "c | "C:WINDOWSsystem32ESENT.dll" |
modified | HKLM/SYSTEM/ControlSet001/Services/Eventlog/Application/ESENT | CategoryMessageFile | "c | "C:WINDOWSsystem32ESENT.dll" |
modified | HKLM/SYSTEM/ControlSet001/Services/Tcpip/Parameters/Interfaces/{9B7E3E9B-6887-4894-8EE4-B4EFDC3EBE75} | NameServer | "10.10.10.2" | "8.8.8.8,8.8.8.4" |
modified | HKLM/SYSTEM/CurrentControlSet/Services/Eventlog/Application/ESENT | EventMessageFile | "c | "C:WINDOWSsystem32ESENT.dll" |
modified | HKLM/SYSTEM/CurrentControlSet/Services/Eventlog/Application/ESENT | CategoryMessageFile | "c | "C:WINDOWSsystem32ESENT.dll" |
modified | HKLM/SYSTEM/CurrentControlSet/Services/Tcpip/Parameters/Interfaces/{9B7E3E9B-6887-4894-8EE4-B4EFDC3EBE75} | NameServer | "10.10.10.2" | "8.8.8.8,8.8.8.4" |
modified | HKU/S-1-5-21-1844237615-562591055-839522115-1004/Software/Microsoft/Internet Explorer/Main | Start Page | "about | "http://www.google.com.tr" |
modified | HKU/S-1-5-21-1844237615-562591055-839522115-1004/Software/Microsoft/Windows/CurrentVersion/Internet Settings/Connections | SavedLegacySettings | 3C 00 00 00 15 00 00 00 01 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 04 00 00 | 3C 00 00 00 17 00 00 00 01 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 04 00 00 |