|
Key
|
Name
|
Value
|
Times
|
| HKLM\SOFTWARE\MICROSOFT\TRACING\NETSHELL
|
ConsoleTracingMask |
4294901760
|
1 |
| HKLM\SOFTWARE\MICROSOFT\TRACING\NETSHELL
|
EnableConsoleTracing |
0
|
1 |
| HKLM\SOFTWARE\MICROSOFT\TRACING\NETSHELL
|
EnableFileTracing |
0
|
1 |
| HKLM\SOFTWARE\MICROSOFT\TRACING\NETSHELL
|
FileDirectory |
%windir%\tracing
|
2 |
| HKLM\SOFTWARE\MICROSOFT\TRACING\NETSHELL
|
FileTracingMask |
4294901760
|
1 |
| HKLM\SOFTWARE\MICROSOFT\TRACING\NETSHELL
|
MaxFileSize |
1048576
|
1 |
| HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings
|
UrlEncoding |
0x00000000
|
2 |
| HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\User Agent\Post Platform
|
.NET CLR 1.1.4322 |
|
1 |
| HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\User Agent\Post Platform
|
.NET CLR 2.0.50727 |
|
1 |
| HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\User Agent\Post Platform
|
.NET CLR 3.0.04506.30 |
|
1 |
| HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\User Agent\Post Platform
|
.NET CLR 3.0.04506.648 |
|
1 |
| HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\User Agent\Post Platform
|
.NET CLR 3.5.21022 |
|
1 |
| HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\User Agent\Post Platform
|
.NET4.0C |
|
1 |
| HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\User Agent\Post Platform
|
.NET4.0E |
|
1 |
| HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\User Agent\Post Platform
|
SV1 |
|
1 |
| HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\User Agent\UA Tokens
|
|
|
1 |
| HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\User Agent\UA Tokens
|
MSN 2.0 |
|
1 |
| HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\User Agent\UA Tokens
|
MSN 2.5 |
|
1 |
| HKLM\SYSTEM\CurrentControlSet\Services\Winsock\Parameters
|
Transports |
0x5400630070006900700000004e0065007400420049004f00530000000000
|
2 |
| HKLM\Software\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_MIME_HANDLING
|
Explorer.EXE |
1
|
1 |
| HKLM\Software\Microsoft\Tracing\RASAPI32
|
ConsoleTracingMask |
4294901760
|
2 |
| HKLM\Software\Microsoft\Tracing\RASAPI32
|
EnableConsoleTracing |
0
|
2 |
| HKLM\Software\Microsoft\Tracing\RASAPI32
|
EnableFileTracing |
0
|
2 |
| HKLM\Software\Microsoft\Tracing\RASAPI32
|
FileDirectory |
%windir%\tracing
|
4 |
| HKLM\Software\Microsoft\Tracing\RASAPI32
|
FileTracingMask |
4294901760
|
2 |
| HKLM\Software\Microsoft\Tracing\RASAPI32
|
MaxFileSize |
1048576
|
2 |
| HKLM\Software\Microsoft\Windows NT\CurrentVersion\ProfileList
|
AllUsersProfile |
All Users
|
1 |
| HKLM\Software\Microsoft\Windows NT\CurrentVersion\ProfileList
|
DefaultUserProfile |
Default User
|
1 |
| HKLM\Software\Microsoft\Windows NT\CurrentVersion\ProfileList
|
ProfilesDirectory |
%SystemDrive%\Documents and Settings
|
2 |
| HKLM\Software\Microsoft\Windows NT\CurrentVersion\ProfileList\S-1-5-21-842925246-1425521274-308236825-500
|
ProfileImagePath |
%SystemDrive%\Documents and Settings\Administrator
|
1 |
| HKLM\Software\Microsoft\Windows\CurrentVersion
|
CommonFilesDir |
C:\Program Files\Common Files
|
1 |
| HKLM\Software\Microsoft\Windows\CurrentVersion
|
ProgramFilesDir |
C:\Program Files
|
1 |
| HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders
|
Common AppData |
%ALLUSERSPROFILE%\Application Data
|
1 |
| HKLM\System\CurrentControlSet\Control\ComputerName\ActiveComputerName
|
ComputerName |
PC
|
1 |
| HKLM\System\CurrentControlSet\Control\Session Manager\Environment
|
ComSpec |
%SystemRoot%\system32\cmd.exe
|
2 |
| HKLM\System\CurrentControlSet\Control\Session Manager\Environment
|
FP_NO_HOST_CHECK |
NO
|
2 |
| HKLM\System\CurrentControlSet\Control\Session Manager\Environment
|
NUMBER_OF_PROCESSORS |
1
|
2 |
| HKLM\System\CurrentControlSet\Control\Session Manager\Environment
|
OS |
Windows_NT
|
2 |
| HKLM\System\CurrentControlSet\Control\Session Manager\Environment
|
PATHEXT |
.COM;.EXE;.BAT;.CMD;.VBS;.VBE;.JS;.JSE;.WSF;.WSH
|
2 |
| HKLM\System\CurrentControlSet\Control\Session Manager\Environment
|
PROCESSOR_ARCHITECTURE |
x86
|
2 |
| HKLM\System\CurrentControlSet\Control\Session Manager\Environment
|
PROCESSOR_IDENTIFIER |
x86 Family 6 Model 3 Stepping 3, GenuineIntel
|
2 |
| HKLM\System\CurrentControlSet\Control\Session Manager\Environment
|
PROCESSOR_LEVEL |
6
|
2 |
| HKLM\System\CurrentControlSet\Control\Session Manager\Environment
|
PROCESSOR_REVISION |
0303
|
2 |
| HKLM\System\CurrentControlSet\Control\Session Manager\Environment
|
Path |
%SystemRoot%\system32;%SystemRoot%;%SystemRoot%\System32\Wbem
|
2 |
| HKLM\System\CurrentControlSet\Control\Session Manager\Environment
|
TEMP |
%SystemRoot%\TEMP
|
2 |
| HKLM\System\CurrentControlSet\Control\Session Manager\Environment
|
TMP |
%SystemRoot%\TEMP
|
2 |
| HKLM\System\CurrentControlSet\Control\Session Manager\Environment
|
windir |
%SystemRoot%
|
2 |
| HKLM\System\CurrentControlSet\Services\Tcpip\Parameters\Winsock
|
HelperDllName |
%SystemRoot%\System32\wshtcpip.dll
|
1 |
| HKLM\System\CurrentControlSet\Services\Tcpip\Parameters\Winsock
|
Mapping |
0x0b0000000300000002000000010000000600000002000000010000000000
|
1 |
| HKLM\System\CurrentControlSet\Services\Tcpip\Parameters\Winsock
|
MaxSockaddrLength |
16
|
1 |
| HKLM\System\CurrentControlSet\Services\Tcpip\Parameters\Winsock
|
MinSockaddrLength |
16
|
1 |
| HKLM\System\CurrentControlSet\Services\Tcpip\Parameters\Winsock
|
UseDelayedAcceptance |
0
|
1 |
| HKLM\System\CurrentControlSet\Services\WinSock2\Parameters
|
WinSock_Registry_Version |
2.0
|
2 |
| HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\NameSpace_Catalog5
|
Num_Catalog_Entries |
3
|
1 |
| HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\NameSpace_Catalog5
|
Serial_Access_Num |
4
|
2 |
| HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000001
|
DisplayString |
Tcpip
|
4 |
| HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000001
|
Enabled |
1
|
1 |
| HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000001
|
LibraryPath |
%SystemRoot%\System32\mswsock.dll
|
2 |
| HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000001
|
ProviderId |
0x409d05229e7ecf11ae5a00aa00a7112b
|
1 |
| HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000001
|
StoresServiceClassInfo |
0
|
1 |
| HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000001
|
SupportedNameSpace |
12
|
1 |
| HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000001
|
Version |
0
|
1 |
| HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000002
|
DisplayString |
NTDS
|
4 |
| HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000002
|
Enabled |
1
|
1 |
| HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000002
|
LibraryPath |
%SystemRoot%\System32\winrnr.dll
|
2 |
| HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000002
|
ProviderId |
0xee37263b80e5cf11a55500c04fd8d4ac
|
1 |
| HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000002
|
StoresServiceClassInfo |
0
|
1 |
| HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000002
|
SupportedNameSpace |
32
|
1 |
| HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000002
|
Version |
0
|
1 |
| HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000003
|
DisplayString |
Network Location Awareness (NLA) Namespace
|
4 |
| HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000003
|
Enabled |
1
|
1 |
| HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000003
|
LibraryPath |
%SystemRoot%\System32\mswsock.dll
|
2 |
| HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000003
|
ProviderId |
0x3a244266a83ba64abaa52e0bd71fdd83
|
1 |
| HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000003
|
StoresServiceClassInfo |
0
|
1 |
| HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000003
|
SupportedNameSpace |
15
|
1 |
| HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000003
|
Version |
0
|
1 |
| HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9
|
Next_Catalog_Entry_ID |
1020
|
1 |
| HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9
|
Num_Catalog_Entries |
13
|
1 |
| HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9
|
Serial_Access_Num |
6
|
2 |
| HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000001
|
PackedCatalogItem |
%SystemRoot%\system32\mswsock.
|
1 |
| HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000002
|
PackedCatalogItem |
%SystemRoot%\system32\mswsock.
|
1 |
| HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000003
|
PackedCatalogItem |
%SystemRoot%\system32\mswsock.
|
1 |
| HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000004
|
PackedCatalogItem |
%SystemRoot%\system32\rsvpsp.d
|
1 |
| HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000005
|
PackedCatalogItem |
%SystemRoot%\system32\rsvpsp.d
|
1 |
| HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000006
|
PackedCatalogItem |
%SystemRoot%\system32\mswsock.
|
1 |
| HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000007
|
PackedCatalogItem |
%SystemRoot%\system32\mswsock.
|
1 |
| HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000008
|
PackedCatalogItem |
%SystemRoot%\system32\mswsock.
|
1 |
| HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000009
|
PackedCatalogItem |
%SystemRoot%\system32\mswsock.
|
1 |
| HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000010
|
PackedCatalogItem |
%SystemRoot%\system32\mswsock.
|
1 |
| HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000011
|
PackedCatalogItem |
%SystemRoot%\system32\mswsock.
|
1 |
| HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000012
|
PackedCatalogItem |
%SystemRoot%\system32\mswsock.
|
1 |
| HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000013
|
PackedCatalogItem |
%SystemRoot%\system32\mswsock.
|
1 |
| HKU\S-1-5-21-842925246-1425521274-308236825-500\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\INTERNET SETTINGS
|
EnableNegotiate |
1
|
1 |
| HKU\S-1-5-21-842925246-1425521274-308236825-500\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\INTERNET SETTINGS
|
MimeExclusionListForCache |
multipart/mixed multipart/x-mixed-replace multipart/x-byteranges
|
4 |
| HKU\S-1-5-21-842925246-1425521274-308236825-500\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\INTERNET SETTINGS
|
WarnOnPost |
0x01000000
|
1 |
| HKU\S-1-5-21-842925246-1425521274-308236825-500\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings
|
EnableHttp1_1 |
1
|
1 |
| HKU\S-1-5-21-842925246-1425521274-308236825-500\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings
|
User Agent |
Mozilla/4.0 (compatible; MSIE 6.0; Win32)
|
2 |
| HKU\S-1-5-21-842925246-1425521274-308236825-500\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\0
|
1406 |
0
|
1 |
| HKU\S-1-5-21-842925246-1425521274-308236825-500\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\0
|
1609 |
1
|
1 |
| HKU\S-1-5-21-842925246-1425521274-308236825-500\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\1
|
1406 |
1
|
1 |
| HKU\S-1-5-21-842925246-1425521274-308236825-500\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\1
|
1609 |
1
|
1 |
| HKU\S-1-5-21-842925246-1425521274-308236825-500\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\2
|
1406 |
0
|
1 |
| HKU\S-1-5-21-842925246-1425521274-308236825-500\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\2
|
1609 |
1
|
1 |
| HKU\S-1-5-21-842925246-1425521274-308236825-500\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\3
|
1406 |
3
|
1 |
| HKU\S-1-5-21-842925246-1425521274-308236825-500\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\3
|
1609 |
1
|
1 |
| HKU\S-1-5-21-842925246-1425521274-308236825-500\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\4
|
1406 |
3
|
1 |
| HKU\S-1-5-21-842925246-1425521274-308236825-500\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\4
|
1609 |
1
|
1 |
| HKU\S-1-5-21-842925246-1425521274-308236825-500\Software\Microsoft\windows\CurrentVersion\Internet Settings
|
MigrateProxy |
1
|
1 |