|
Key
|
Name
|
Value
|
Times
|
| HKLM\SOFTWARE\CLASSES\.ADE
|
|
Access.ADEFile.11
|
2 |
| HKLM\SOFTWARE\CLASSES\.ADP
|
|
Access.Project.11
|
2 |
| HKLM\SOFTWARE\CLASSES\.ASP
|
|
aspfile
|
2 |
| HKLM\SOFTWARE\CLASSES\.BAT
|
|
batfile
|
2 |
| HKLM\SOFTWARE\CLASSES\.CER
|
|
CERFile
|
2 |
| HKLM\SOFTWARE\CLASSES\.CHM
|
|
chm.file
|
2 |
| HKLM\SOFTWARE\CLASSES\.CMD
|
|
cmdfile
|
2 |
| HKLM\SOFTWARE\CLASSES\.COM
|
|
comfile
|
2 |
| HKLM\SOFTWARE\CLASSES\.CPL
|
|
cplfile
|
2 |
| HKLM\SOFTWARE\CLASSES\.CRT
|
|
CERFile
|
2 |
| HKLM\SOFTWARE\CLASSES\.EXE
|
|
exefile
|
5 |
| HKLM\SOFTWARE\CLASSES\CLSID\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\INPROCSERVER32
|
|
%SystemRoot%\system32\SHELL32.dll
|
2 |
| HKLM\SOFTWARE\CLASSES\CLSID\{7B8A2D94-0AC9-11D1-896C-00C04FB6BFC4}\INPROCSERVER32
|
|
C:\WINDOWS\system32\urlmon.dll
|
2 |
| HKLM\SOFTWARE\CLASSES\CLSID\{7B8A2D94-0AC9-11D1-896C-00C04FB6BFC4}\INPROCSERVER32
|
ThreadingModel |
Both
|
1 |
| HKLM\SOFTWARE\CLASSES\CLSID\{871C5380-42A0-1069-A2EA-08002B30309D}\INPROCSERVER32
|
|
C:\WINDOWS\system32\ieframe.dll
|
4 |
| HKLM\SOFTWARE\CLASSES\CLSID\{871C5380-42A0-1069-A2EA-08002B30309D}\INPROCSERVER32
|
ThreadingModel |
Apartment
|
2 |
| HKLM\SOFTWARE\CLASSES\CLSID\{871C5380-42A0-1069-A2EA-08002B30309D}\SHELLFOLDER
|
WantsParseDisplayName |
|
2 |
| HKLM\SOFTWARE\CLASSES\CLSID\{AEB6717E-7E19-11D0-97EE-00C04FD91972}\INPROCSERVER32
|
|
shell32.dll
|
2 |
| HKLM\SOFTWARE\CLASSES\DIRECTORY
|
AlwaysShowExt |
|
1 |
| HKLM\SOFTWARE\CLASSES\DRIVE\SHELLEX\FOLDEREXTENSIONS\{FBEB8A05-BEEE-4442-804E-409D6C4515E9}
|
DriveMask |
32
|
2 |
| HKLM\SOFTWARE\CLASSES\EXEFILE\SHELL\OPEN\COMMAND
|
|
"%1" %*
|
4 |
| HKLM\SOFTWARE\CLASSES\INTERFACE\{000214E6-0000-0000-C000-000000000046}\PROXYSTUBCLSID32
|
|
{bf50b68e-29b8-4386-ae9c-9734d5117cd5}
|
2 |
| HKLM\SOFTWARE\CLASSES\INTERFACE\{79EAC9C4-BAF9-11CE-8C82-00AA004BA90B}\PROXYSTUBCLSID32
|
|
{B8DA6310-E19B-11D0-933C-00A0C90DCAA9}
|
2 |
| HKLM\SOFTWARE\CLASSES\INTERFACE\{93F2F68C-1D1B-11D3-A30E-00C04F79ABD1}\PROXYSTUBCLSID32
|
|
{bf50b68e-29b8-4386-ae9c-9734d5117cd5}
|
2 |
| HKLM\SOFTWARE\CLASSES\INTERFACE\{B722BCCB-4E68-101B-A2BC-00AA00404770}\PROXYSTUBCLSID32
|
|
{B8DA6310-E19B-11D0-933C-00A0C90DCAA9}
|
2 |
| HKLM\SOFTWARE\CLASSES\INTERFACE\{EAB22AC1-30C1-11CF-A7EB-0000C05BAE0B}\TYPELIB
|
|
{EAB22AC0-30C1-11CF-A7EB-0000C05BAE0B}
|
2 |
| HKLM\SOFTWARE\Microsoft\CTF\SystemShared\
|
CUAS |
0
|
1 |
| HKLM\SOFTWARE\Microsoft\Internet Explorer\Setup
|
IExploreLastModifiedHigh |
29887276
|
2 |
| HKLM\SOFTWARE\Microsoft\Internet Explorer\Setup
|
IExploreLastModifiedLow |
2933474304
|
2 |
| HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\IEXPLORE.EXE
|
|
C:\Program Files\Internet Explorer\IEXPLORE.EXE
|
2 |
| HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings
|
EnablePunycode |
1
|
1 |
| HKLM\SYSTEM\CurrentControlSet\Control\Session Manager
|
CriticalSectionTimeout |
2592000
|
1 |
| HKLM\SYSTEM\Setup
|
OsLoaderPath |
\
|
2 |
| HKLM\SYSTEM\Setup
|
SystemPartition |
\Device\HarddiskVolume1
|
2 |
| HKLM\SYSTEM\WPA\MediaCenter
|
Installed |
0
|
4 |
| HKLM\Software\Classes\CLSID\{871c5380-42a0-1069-a2ea-08002b30309d}\InProcServer32
|
|
C:\WINDOWS\system32\ieframe.dll
|
2 |
| HKLM\Software\Microsoft\COM3
|
Com+Enabled |
1
|
4 |
| HKLM\Software\Microsoft\COM3
|
REGDBVersion |
0x0f00000000000000
|
6 |
| HKLM\Software\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_BEHAVIORS
|
* |
1
|
1 |
| HKLM\Software\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_DISABLE_MK_PROTOCOL
|
* |
1
|
1 |
| HKLM\Software\Microsoft\Windows\CurrentVersion
|
DevicePath |
%SystemRoot%\inf
|
1 |
| HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\FileAssociation
|
CutList |
0x4100700070006c00690063006100740069006f006e002000460069006c00
|
2 |
| HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks
|
{AEB6717E-7E19-11d0-97EE-00C04FD91972} |
|
2 |
| HKLM\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\\msn.com
|
|
|
1 |
| HKLM\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\\msn.com\related
|
http |
4
|
1 |
| HKLM\Software\Microsoft\Windows\CurrentVersion\Setup
|
DriverCachePath |
%SystemRoot%\Driver Cache
|
2 |
| HKLM\Software\Microsoft\Windows\CurrentVersion\Setup
|
LogLevel |
0
|
2 |
| HKLM\Software\Microsoft\Windows\CurrentVersion\Setup
|
ServicePackCachePath |
c:\windows\ServicePackFiles\ServicePackCache
|
2 |
| HKLM\Software\Microsoft\Windows\CurrentVersion\Setup
|
ServicePackSourcePath |
c:\windows\ServicePackFiles
|
2 |
| HKLM\Software\Microsoft\Windows\CurrentVersion\Setup
|
SourcePath |
D:\
|
2 |
| HKLM\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers
|
AuthenticodeEnabled |
0
|
1 |
| HKLM\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers
|
DefaultLevel |
262144
|
1 |
| HKLM\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers
|
PolicyScope |
0
|
1 |
| HKLM\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers
|
TransparentEnabled |
1
|
3 |
| HKLM\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Hashes\{349d35ab-37b5-462f-9b89-edd5fbde1328}
|
HashAlg |
32771
|
1 |
| HKLM\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Hashes\{349d35ab-37b5-462f-9b89-edd5fbde1328}
|
ItemData |
0x5eab304f957a49896a006c1c31154015
|
1 |
| HKLM\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Hashes\{349d35ab-37b5-462f-9b89-edd5fbde1328}
|
ItemSize |
779
|
1 |
| HKLM\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Hashes\{349d35ab-37b5-462f-9b89-edd5fbde1328}
|
SaferFlags |
0
|
1 |
| HKLM\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Hashes\{7fb9cd2e-3076-4df9-a57b-b813f72dbb91}
|
HashAlg |
32771
|
1 |
| HKLM\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Hashes\{7fb9cd2e-3076-4df9-a57b-b813f72dbb91}
|
ItemData |
0x67b0d48b343a3fd3bce9dc646704f394
|
1 |
| HKLM\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Hashes\{7fb9cd2e-3076-4df9-a57b-b813f72dbb91}
|
ItemSize |
517
|
1 |
| HKLM\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Hashes\{7fb9cd2e-3076-4df9-a57b-b813f72dbb91}
|
SaferFlags |
0
|
1 |
| HKLM\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Hashes\{81d1fe15-dd9d-4762-b16d-7c29ddecae3f}
|
HashAlg |
32771
|
1 |
| HKLM\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Hashes\{81d1fe15-dd9d-4762-b16d-7c29ddecae3f}
|
ItemData |
0x327802dcfef8c893dc8ab006dd847d1d
|
1 |
| HKLM\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Hashes\{81d1fe15-dd9d-4762-b16d-7c29ddecae3f}
|
ItemSize |
918
|
1 |
| HKLM\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Hashes\{81d1fe15-dd9d-4762-b16d-7c29ddecae3f}
|
SaferFlags |
0
|
1 |
| HKLM\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Hashes\{94e3e076-8f53-42a5-8411-085bcc18a68d}
|
HashAlg |
32771
|
1 |
| HKLM\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Hashes\{94e3e076-8f53-42a5-8411-085bcc18a68d}
|
ItemData |
0xbd9a2adb42ebd8560e250e4df8162f67
|
1 |
| HKLM\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Hashes\{94e3e076-8f53-42a5-8411-085bcc18a68d}
|
ItemSize |
229
|
1 |
| HKLM\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Hashes\{94e3e076-8f53-42a5-8411-085bcc18a68d}
|
SaferFlags |
0
|
1 |
| HKLM\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Hashes\{dc971ee5-44eb-4fe4-ae2e-b91490411bfc}
|
HashAlg |
32771
|
1 |
| HKLM\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Hashes\{dc971ee5-44eb-4fe4-ae2e-b91490411bfc}
|
ItemData |
0x386b085f84ecf669d36b956a22c01e80
|
1 |
| HKLM\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Hashes\{dc971ee5-44eb-4fe4-ae2e-b91490411bfc}
|
ItemSize |
370
|
1 |
| HKLM\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Hashes\{dc971ee5-44eb-4fe4-ae2e-b91490411bfc}
|
SaferFlags |
0
|
1 |
| HKLM\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Paths\{dda3f824-d8cb-441b-834d-be2efd2c1a33}
|
ItemData |
%HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders\Cache%OLK*
|
1 |
| HKLM\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Paths\{dda3f824-d8cb-441b-834d-be2efd2c1a33}
|
SaferFlags |
0
|
1 |
| HKLM\System\CurrentControlSet\Control\ComputerName\ActiveComputerName
|
ComputerName |
USER
|
2 |
| HKLM\System\CurrentControlSet\Services\Tcpip\Parameters
|
Domain |
|
1 |
| HKLM\System\CurrentControlSet\Services\Tcpip\Parameters
|
Hostname |
user
|
1 |
| HKLM\System\Setup
|
SystemSetupInProgress |
0
|
2 |
| HKLM\System\WPA\PnP
|
seed |
1374283966
|
1 |
| HKU\S-1-5-21-1229272821-1004336348-527237240-1003\Software\Microsoft\Windows\CurrentVersion\Explorer\
|
ShellState |
0x2400000033880000000000000000000000000000010000000d0000000000
|
2 |
| HKU\S-1-5-21-1229272821-1004336348-527237240-1003\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced
|
DontPrettyPath |
0
|
1 |
| HKU\S-1-5-21-1229272821-1004336348-527237240-1003\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced
|
Filter |
0
|
1 |
| HKU\S-1-5-21-1229272821-1004336348-527237240-1003\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced
|
Hidden |
1
|
1 |
| HKU\S-1-5-21-1229272821-1004336348-527237240-1003\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced
|
HideFileExt |
0
|
1 |
| HKU\S-1-5-21-1229272821-1004336348-527237240-1003\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced
|
HideIcons |
0
|
1 |
| HKU\S-1-5-21-1229272821-1004336348-527237240-1003\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced
|
MapNetDrvBtn |
0
|
1 |
| HKU\S-1-5-21-1229272821-1004336348-527237240-1003\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced
|
NoNetCrawling |
0
|
1 |
| HKU\S-1-5-21-1229272821-1004336348-527237240-1003\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced
|
SeparateProcess |
0
|
1 |
| HKU\S-1-5-21-1229272821-1004336348-527237240-1003\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced
|
ShowCompColor |
1
|
1 |
| HKU\S-1-5-21-1229272821-1004336348-527237240-1003\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced
|
ShowInfoTip |
1
|
1 |
| HKU\S-1-5-21-1229272821-1004336348-527237240-1003\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced
|
ShowSuperHidden |
1
|
1 |
| HKU\S-1-5-21-1229272821-1004336348-527237240-1003\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced
|
WebView |
0
|
1 |
| HKU\S-1-5-21-1229272821-1004336348-527237240-1003\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\CPC\Volume\{d14d83ce-7d74-11dc-97e2-806d6172696f}\
|
Data |
0x000000005c005c003f005c0049004400450023004300640052006f006d00
|
1 |
| HKU\S-1-5-21-1229272821-1004336348-527237240-1003\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\CPC\Volume\{d14d83ce-7d74-11dc-97e2-806d6172696f}\
|
Generation |
1
|
1 |
| HKU\S-1-5-21-1229272821-1004336348-527237240-1003\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\CPC\Volume\{d14d83cf-7d74-11dc-97e2-806d6172696f}\
|
Data |
0x000000005c005c003f005c00530054004f00520041004700450023005600
|
1 |
| HKU\S-1-5-21-1229272821-1004336348-527237240-1003\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\CPC\Volume\{d14d83cf-7d74-11dc-97e2-806d6172696f}\
|
Generation |
1
|
3 |
| HKU\S-1-5-21-1229272821-1004336348-527237240-1003\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders
|
Cache |
C:\Documents and Settings\user\Local Settings\Temporary Internet Files
|
1 |
| HKU\S-1-5-21-1229272821-1004336348-527237240-1003\Software\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders
|
Cache |
%USERPROFILE%\Local Settings\Temporary Internet Files
|
1 |
| HKU\S-1-5-21-1229272821-1004336348-527237240-1003\Software\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders
|
Cookies |
%USERPROFILE%\Cookies
|
1 |
| HKU\S-1-5-21-1229272821-1004336348-527237240-1003\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\\ProtocolDefaults\
|
|
|
1 |
| HKU\S-1-5-21-1229272821-1004336348-527237240-1003\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\\ProtocolDefaults\
|
@ivt |
1
|
1 |
| HKU\S-1-5-21-1229272821-1004336348-527237240-1003\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\\ProtocolDefaults\
|
file |
3
|
1 |
| HKU\S-1-5-21-1229272821-1004336348-527237240-1003\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\\ProtocolDefaults\
|
ftp |
3
|
1 |
| HKU\S-1-5-21-1229272821-1004336348-527237240-1003\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\\ProtocolDefaults\
|
http |
3
|
1 |
| HKU\S-1-5-21-1229272821-1004336348-527237240-1003\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\\ProtocolDefaults\
|
https |
3
|
1 |
| HKU\S-1-5-21-1229272821-1004336348-527237240-1003\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\\ProtocolDefaults\
|
shell |
0
|
1 |
| HKU\S-1-5-21-1229272821-1004336348-527237240-1003\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\0
|
1806 |
0
|
1 |
| HKU\S-1-5-21-1229272821-1004336348-527237240-1003\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\0
|
Flags |
33
|
2 |
| HKU\S-1-5-21-1229272821-1004336348-527237240-1003\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\1
|
Flags |
475
|
2 |
| HKU\S-1-5-21-1229272821-1004336348-527237240-1003\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\2
|
Flags |
71
|
2 |
| HKU\S-1-5-21-1229272821-1004336348-527237240-1003\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\3
|
Flags |
1
|
2 |
| HKU\S-1-5-21-1229272821-1004336348-527237240-1003\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\4
|
Flags |
3
|
2 |
| HKU\S-1-5-21-1229272821-1004336348-527237240-1003\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Cached
|
{871C5380-42A0-1069-A2EA-08002B30309D} {000214E6-0000-0000-C000-000000000046} 0x401 |
0x01000000310032003a893fef1312c801
|
2 |
| HKU\S-1-5-21-1229272821-1004336348-527237240-1003\Software\Microsoft\Windows\ShellNoRoam\MUICache
|
LangID |
0x0904
|
1 |
| HKU\S-1-5-21-1229272821-1004336348-527237240-1003\Software\Microsoft\Windows\ShellNoRoam\MUICache\
|
C:\WINDOWS\system32\taskkill.exe |
Kill Process
|
1 |