|
Key
|
Name
|
Value
|
Times
|
| HKLM\SOFTWARE\CLASSES\AUTOPROXYTYPES\APPLICATION/X-INTERNET-SIGNUP
|
Default |
0x00000000
|
1 |
| HKLM\SOFTWARE\CLASSES\AUTOPROXYTYPES\APPLICATION/X-INTERNET-SIGNUP
|
DllFile |
%SystemRoot%\system32\iedkcs32.dll
|
2 |
| HKLM\SOFTWARE\CLASSES\AUTOPROXYTYPES\APPLICATION/X-INTERNET-SIGNUP
|
FileExtensions |
.ins
|
2 |
| HKLM\SOFTWARE\CLASSES\AUTOPROXYTYPES\APPLICATION/X-NS-PROXY-AUTOCONFIG
|
Default |
0x01000000
|
1 |
| HKLM\SOFTWARE\CLASSES\AUTOPROXYTYPES\APPLICATION/X-NS-PROXY-AUTOCONFIG
|
DllFile |
%SystemRoot%\system32\jsproxy.dll
|
2 |
| HKLM\SOFTWARE\CLASSES\AUTOPROXYTYPES\APPLICATION/X-NS-PROXY-AUTOCONFIG
|
FileExtensions |
.pac;.jvs;.js
|
2 |
| HKLM\SOFTWARE\CLASSES\AUTOPROXYTYPES\APPLICATION/X-NS-PROXY-AUTOCONFIG
|
Flags |
0x01000000
|
1 |
| HKLM\SOFTWARE\Microsoft\CTF\SystemShared\
|
CUAS |
0
|
1 |
| HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings
|
UrlEncoding |
0x00000000
|
2 |
| HKLM\SYSTEM\CurrentControlSet\Control\Session Manager
|
CriticalSectionTimeout |
2592000
|
1 |
| HKLM\SYSTEM\Setup
|
SystemSetupInProgress |
0
|
1 |
| HKLM\SYSTEM\WPA\MediaCenter
|
Installed |
0
|
1 |
| HKLM\Software\Microsoft\AudioCompressionManager\DriverCache\msacm.iac2
|
aFormatTagCache |
0x01000000100000000204000014000000
|
1 |
| HKLM\Software\Microsoft\AudioCompressionManager\DriverCache\msacm.iac2
|
cFilterTags |
0
|
1 |
| HKLM\Software\Microsoft\AudioCompressionManager\DriverCache\msacm.iac2
|
cFormatTags |
2
|
1 |
| HKLM\Software\Microsoft\AudioCompressionManager\DriverCache\msacm.iac2
|
fdwSupport |
1
|
1 |
| HKLM\Software\Microsoft\AudioCompressionManager\DriverCache\msacm.imaadpcm
|
aFormatTagCache |
0x01000000100000001100000014000000
|
1 |
| HKLM\Software\Microsoft\AudioCompressionManager\DriverCache\msacm.imaadpcm
|
cFilterTags |
0
|
1 |
| HKLM\Software\Microsoft\AudioCompressionManager\DriverCache\msacm.imaadpcm
|
cFormatTags |
2
|
1 |
| HKLM\Software\Microsoft\AudioCompressionManager\DriverCache\msacm.imaadpcm
|
fdwSupport |
1
|
1 |
| HKLM\Software\Microsoft\AudioCompressionManager\DriverCache\msacm.l3acm
|
aFormatTagCache |
0x0100000010000000550000001e000000
|
1 |
| HKLM\Software\Microsoft\AudioCompressionManager\DriverCache\msacm.l3acm
|
cFilterTags |
0
|
1 |
| HKLM\Software\Microsoft\AudioCompressionManager\DriverCache\msacm.l3acm
|
cFormatTags |
2
|
1 |
| HKLM\Software\Microsoft\AudioCompressionManager\DriverCache\msacm.l3acm
|
fdwSupport |
1
|
1 |
| HKLM\Software\Microsoft\AudioCompressionManager\DriverCache\msacm.msadpcm
|
aFormatTagCache |
0x01000000100000000200000032000000
|
1 |
| HKLM\Software\Microsoft\AudioCompressionManager\DriverCache\msacm.msadpcm
|
cFilterTags |
0
|
1 |
| HKLM\Software\Microsoft\AudioCompressionManager\DriverCache\msacm.msadpcm
|
cFormatTags |
2
|
1 |
| HKLM\Software\Microsoft\AudioCompressionManager\DriverCache\msacm.msadpcm
|
fdwSupport |
1
|
1 |
| HKLM\Software\Microsoft\AudioCompressionManager\DriverCache\msacm.msaudio1
|
aFormatTagCache |
0x01000000120000006001000016000000610100001c000000
|
1 |
| HKLM\Software\Microsoft\AudioCompressionManager\DriverCache\msacm.msaudio1
|
cFilterTags |
0
|
1 |
| HKLM\Software\Microsoft\AudioCompressionManager\DriverCache\msacm.msaudio1
|
cFormatTags |
3
|
1 |
| HKLM\Software\Microsoft\AudioCompressionManager\DriverCache\msacm.msaudio1
|
fdwSupport |
1
|
1 |
| HKLM\Software\Microsoft\AudioCompressionManager\DriverCache\msacm.msg711
|
aFormatTagCache |
0x010000001000000006000000120000000700000012000000
|
1 |
| HKLM\Software\Microsoft\AudioCompressionManager\DriverCache\msacm.msg711
|
cFilterTags |
0
|
1 |
| HKLM\Software\Microsoft\AudioCompressionManager\DriverCache\msacm.msg711
|
cFormatTags |
3
|
1 |
| HKLM\Software\Microsoft\AudioCompressionManager\DriverCache\msacm.msg711
|
fdwSupport |
1
|
1 |
| HKLM\Software\Microsoft\AudioCompressionManager\DriverCache\msacm.msg723
|
aFormatTagCache |
0x0100000010000000420000001c000000
|
1 |
| HKLM\Software\Microsoft\AudioCompressionManager\DriverCache\msacm.msg723
|
cFilterTags |
0
|
1 |
| HKLM\Software\Microsoft\AudioCompressionManager\DriverCache\msacm.msg723
|
cFormatTags |
2
|
1 |
| HKLM\Software\Microsoft\AudioCompressionManager\DriverCache\msacm.msg723
|
fdwSupport |
1
|
1 |
| HKLM\Software\Microsoft\AudioCompressionManager\DriverCache\msacm.msgsm610
|
aFormatTagCache |
0x01000000100000003100000014000000
|
1 |
| HKLM\Software\Microsoft\AudioCompressionManager\DriverCache\msacm.msgsm610
|
cFilterTags |
0
|
1 |
| HKLM\Software\Microsoft\AudioCompressionManager\DriverCache\msacm.msgsm610
|
cFormatTags |
2
|
1 |
| HKLM\Software\Microsoft\AudioCompressionManager\DriverCache\msacm.msgsm610
|
fdwSupport |
1
|
1 |
| HKLM\Software\Microsoft\AudioCompressionManager\DriverCache\msacm.sl_anet
|
aFormatTagCache |
0x01000000100000003001000016000000
|
1 |
| HKLM\Software\Microsoft\AudioCompressionManager\DriverCache\msacm.sl_anet
|
cFilterTags |
0
|
1 |
| HKLM\Software\Microsoft\AudioCompressionManager\DriverCache\msacm.sl_anet
|
cFormatTags |
2
|
1 |
| HKLM\Software\Microsoft\AudioCompressionManager\DriverCache\msacm.sl_anet
|
fdwSupport |
1
|
1 |
| HKLM\Software\Microsoft\AudioCompressionManager\DriverCache\msacm.trspch
|
aFormatTagCache |
0x01000000100000002200000032000000
|
1 |
| HKLM\Software\Microsoft\AudioCompressionManager\DriverCache\msacm.trspch
|
cFilterTags |
0
|
1 |
| HKLM\Software\Microsoft\AudioCompressionManager\DriverCache\msacm.trspch
|
cFormatTags |
2
|
1 |
| HKLM\Software\Microsoft\AudioCompressionManager\DriverCache\msacm.trspch
|
fdwSupport |
1
|
1 |
| HKLM\Software\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_BEHAVIORS
|
* |
1
|
1 |
| HKLM\Software\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_DISABLE_MK_PROTOCOL
|
* |
1
|
1 |
| HKLM\Software\Microsoft\Tracing
|
EnableConsoleTracing |
0
|
1 |
| HKLM\Software\Microsoft\Tracing\RASAPI32
|
ConsoleTracingMask |
4294901760
|
2 |
| HKLM\Software\Microsoft\Tracing\RASAPI32
|
EnableConsoleTracing |
0
|
2 |
| HKLM\Software\Microsoft\Tracing\RASAPI32
|
EnableFileTracing |
0
|
2 |
| HKLM\Software\Microsoft\Tracing\RASAPI32
|
FileDirectory |
%windir%\tracing
|
4 |
| HKLM\Software\Microsoft\Tracing\RASAPI32
|
FileTracingMask |
4294901760
|
2 |
| HKLM\Software\Microsoft\Tracing\RASAPI32
|
MaxFileSize |
1048576
|
2 |
| HKLM\Software\Microsoft\Windows NT\CurrentVersion
|
DigitalProductId |
0xa40000000300000037363438372d3634302d313435373233362d32333833
|
1 |
| HKLM\Software\Microsoft\Windows NT\CurrentVersion\AeDebug
|
Debugger |
drwtsn32 -p %ld -e %ld -g
|
4 |
| HKLM\Software\Microsoft\Windows NT\CurrentVersion\Drivers32
|
midimapper |
|
2 |
| HKLM\Software\Microsoft\Windows NT\CurrentVersion\Drivers32
|
msacm.iac2 |
C:\WINDOWS\system32\iac25_32.ax
|
2 |
| HKLM\Software\Microsoft\Windows NT\CurrentVersion\Drivers32
|
msacm.imaadpcm |
imaadp32.acm
|
3 |
| HKLM\Software\Microsoft\Windows NT\CurrentVersion\Drivers32
|
msacm.l3acm |
|
2 |
| HKLM\Software\Microsoft\Windows NT\CurrentVersion\Drivers32
|
msacm.msadpcm |
|
3 |
| HKLM\Software\Microsoft\Windows NT\CurrentVersion\Drivers32
|
msacm.msaudio1 |
|
3 |
| HKLM\Software\Microsoft\Windows NT\CurrentVersion\Drivers32
|
msacm.msg711 |
|
3 |
| HKLM\Software\Microsoft\Windows NT\CurrentVersion\Drivers32
|
msacm.msg723 |
|
3 |
| HKLM\Software\Microsoft\Windows NT\CurrentVersion\Drivers32
|
msacm.msgsm610 |
msgsm32.acm
|
3 |
| HKLM\Software\Microsoft\Windows NT\CurrentVersion\Drivers32
|
msacm.sl_anet |
|
2 |
| HKLM\Software\Microsoft\Windows NT\CurrentVersion\Drivers32
|
msacm.trspch |
|
3 |
| HKLM\Software\Microsoft\Windows NT\CurrentVersion\Drivers32
|
vidc.I420 |
|
2 |
| HKLM\Software\Microsoft\Windows NT\CurrentVersion\Drivers32
|
vidc.M261 |
|
2 |
| HKLM\Software\Microsoft\Windows NT\CurrentVersion\Drivers32
|
vidc.M263 |
|
2 |
| HKLM\Software\Microsoft\Windows NT\CurrentVersion\Drivers32
|
vidc.cvid |
|
2 |
| HKLM\Software\Microsoft\Windows NT\CurrentVersion\Drivers32
|
vidc.iv31 |
|
2 |
| HKLM\Software\Microsoft\Windows NT\CurrentVersion\Drivers32
|
vidc.iv32 |
|
2 |
| HKLM\Software\Microsoft\Windows NT\CurrentVersion\Drivers32
|
vidc.iv41 |
|
2 |
| HKLM\Software\Microsoft\Windows NT\CurrentVersion\Drivers32
|
vidc.iv50 |
|
1 |
| HKLM\Software\Microsoft\Windows NT\CurrentVersion\Drivers32
|
vidc.iyuv |
|
2 |
| HKLM\Software\Microsoft\Windows NT\CurrentVersion\Drivers32
|
vidc.mrle |
|
2 |
| HKLM\Software\Microsoft\Windows NT\CurrentVersion\Drivers32
|
vidc.msvc |
|
2 |
| HKLM\Software\Microsoft\Windows NT\CurrentVersion\Drivers32
|
vidc.uyvy |
|
2 |
| HKLM\Software\Microsoft\Windows NT\CurrentVersion\Drivers32
|
vidc.yuy2 |
|
2 |
| HKLM\Software\Microsoft\Windows NT\CurrentVersion\Drivers32
|
vidc.yvu9 |
|
2 |
| HKLM\Software\Microsoft\Windows NT\CurrentVersion\Drivers32
|
vidc.yvyu |
|
2 |
| HKLM\Software\Microsoft\Windows NT\CurrentVersion\Drivers32
|
wavemapper |
|
2 |
| HKLM\Software\Microsoft\Windows NT\CurrentVersion\ProfileList
|
AllUsersProfile |
All Users
|
2 |
| HKLM\Software\Microsoft\Windows NT\CurrentVersion\ProfileList
|
DefaultUserProfile |
Default User
|
2 |
| HKLM\Software\Microsoft\Windows NT\CurrentVersion\ProfileList
|
ProfilesDirectory |
%SystemDrive%\Documents and Settings
|
4 |
| HKLM\Software\Microsoft\Windows NT\CurrentVersion\ProfileList\S-1-5-21-842925246-1425521274-308236825-500
|
ProfileImagePath |
%SystemDrive%\Documents and Settings\Administrator
|
2 |
| HKLM\Software\Microsoft\Windows NT\CurrentVersion\Windows
|
AppInit_DLLs |
|
1 |
| HKLM\Software\Microsoft\Windows\CurrentVersion
|
CommonFilesDir |
C:\Program Files\Common Files
|
3 |
| HKLM\Software\Microsoft\Windows\CurrentVersion
|
ProgramFilesDir |
C:\Program Files
|
3 |
| HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders
|
Common AppData |
%ALLUSERSPROFILE%\Application Data
|
1 |
| HKLM\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers
|
TransparentEnabled |
1
|
1 |
| HKLM\System\CurrentControlSet\Control\ComputerName\ActiveComputerName
|
ComputerName |
PC
|
5 |
| HKLM\System\CurrentControlSet\Control\MediaProperties\PrivateProperties\Joystick\Winmm
|
wheel |
1
|
1 |
| HKLM\System\CurrentControlSet\Control\ProductOptions
|
ProductType |
WinNT
|
1 |
| HKLM\System\CurrentControlSet\Control\Session Manager\Environment
|
ComSpec |
%SystemRoot%\system32\cmd.exe
|
4 |
| HKLM\System\CurrentControlSet\Control\Session Manager\Environment
|
FP_NO_HOST_CHECK |
NO
|
4 |
| HKLM\System\CurrentControlSet\Control\Session Manager\Environment
|
NUMBER_OF_PROCESSORS |
1
|
4 |
| HKLM\System\CurrentControlSet\Control\Session Manager\Environment
|
OS |
Windows_NT
|
4 |
| HKLM\System\CurrentControlSet\Control\Session Manager\Environment
|
PATHEXT |
.COM;.EXE;.BAT;.CMD;.VBS;.VBE;.JS;.JSE;.WSF;.WSH
|
4 |
| HKLM\System\CurrentControlSet\Control\Session Manager\Environment
|
PROCESSOR_ARCHITECTURE |
x86
|
4 |
| HKLM\System\CurrentControlSet\Control\Session Manager\Environment
|
PROCESSOR_IDENTIFIER |
x86 Family 6 Model 3 Stepping 3, GenuineIntel
|
4 |
| HKLM\System\CurrentControlSet\Control\Session Manager\Environment
|
PROCESSOR_LEVEL |
6
|
4 |
| HKLM\System\CurrentControlSet\Control\Session Manager\Environment
|
PROCESSOR_REVISION |
0303
|
4 |
| HKLM\System\CurrentControlSet\Control\Session Manager\Environment
|
Path |
%SystemRoot%\system32;%SystemRoot%;%SystemRoot%\System32\Wbem
|
4 |
| HKLM\System\CurrentControlSet\Control\Session Manager\Environment
|
TEMP |
%SystemRoot%\TEMP
|
4 |
| HKLM\System\CurrentControlSet\Control\Session Manager\Environment
|
TMP |
%SystemRoot%\TEMP
|
4 |
| HKLM\System\CurrentControlSet\Control\Session Manager\Environment
|
windir |
%SystemRoot%
|
4 |
| HKLM\System\CurrentControlSet\Control\Terminal Server
|
TSAppCompat |
0
|
3 |
| HKLM\System\CurrentControlSet\Control\Terminal Server
|
TSUserEnabled |
0
|
1 |
| HKLM\System\Setup
|
SystemSetupInProgress |
0
|
1 |
| HKU\S-1-5-21-842925246-1425521274-308236825-500\Environment
|
TEMP |
%USERPROFILE%\Local Settings\Temp
|
4 |
| HKU\S-1-5-21-842925246-1425521274-308236825-500\Environment
|
TMP |
%USERPROFILE%\Local Settings\Temp
|
4 |
| HKU\S-1-5-21-842925246-1425521274-308236825-500\Keyboard Layout\Toggle
|
Language Hotkey |
1
|
6 |
| HKU\S-1-5-21-842925246-1425521274-308236825-500\Keyboard Layout\Toggle
|
Layout Hotkey |
2
|
6 |
| HKU\S-1-5-21-842925246-1425521274-308236825-500\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings
|
EnableHttp1_1 |
1
|
1 |
| HKU\S-1-5-21-842925246-1425521274-308236825-500\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings
|
EnableNegotiate |
1
|
1 |
| HKU\S-1-5-21-842925246-1425521274-308236825-500\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings
|
MimeExclusionListForCache |
multipart/mixed multipart/x-mixed-replace multipart/x-byteranges
|
4 |
| HKU\S-1-5-21-842925246-1425521274-308236825-500\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings
|
WarnOnPost |
0x01000000
|
1 |
| HKU\S-1-5-21-842925246-1425521274-308236825-500\Software\Microsoft\Internet Explorer\Settings
|
Anchor Color |
0,0,255
|
4 |
| HKU\S-1-5-21-842925246-1425521274-308236825-500\Software\Microsoft\Multimedia\Audio
|
SystemFormats |
CD Quality,Radio Quality,Telephone Quality
|
1 |
| HKU\S-1-5-21-842925246-1425521274-308236825-500\Software\Microsoft\Windows NT\CurrentVersion\Winlogon
|
ParseAutoexec |
1
|
2 |
| HKU\S-1-5-21-842925246-1425521274-308236825-500\Software\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders
|
AppData |
%USERPROFILE%\Application Data
|
2 |
| HKU\S-1-5-21-842925246-1425521274-308236825-500\Software\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders
|
Cache |
%USERPROFILE%\Local Settings\Temporary Internet Files
|
3 |
| HKU\S-1-5-21-842925246-1425521274-308236825-500\Software\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders
|
Cookies |
%USERPROFILE%\Cookies
|
3 |
| HKU\S-1-5-21-842925246-1425521274-308236825-500\Software\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders
|
History |
%USERPROFILE%\Local Settings\History
|
3 |
| HKU\S-1-5-21-842925246-1425521274-308236825-500\Software\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders
|
Local Settings |
%USERPROFILE%\Local Settings
|
1 |
| HKU\S-1-5-21-842925246-1425521274-308236825-500\Software\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders
|
Personal |
%USERPROFILE%\My Documents
|
2 |
| HKU\S-1-5-21-842925246-1425521274-308236825-500\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache
|
Signature |
Client UrlCache MMF Ver 5.2
|
2 |
| HKU\S-1-5-21-842925246-1425521274-308236825-500\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Content
|
CacheLimit |
163410
|
1 |
| HKU\S-1-5-21-842925246-1425521274-308236825-500\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Content
|
CachePrefix |
|
2 |
| HKU\S-1-5-21-842925246-1425521274-308236825-500\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Content
|
PerUserItem |
1
|
1 |
| HKU\S-1-5-21-842925246-1425521274-308236825-500\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Cookies
|
CacheLimit |
8192
|
1 |
| HKU\S-1-5-21-842925246-1425521274-308236825-500\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Cookies
|
CachePrefix |
Cookie:
|
2 |
| HKU\S-1-5-21-842925246-1425521274-308236825-500\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Cookies
|
PerUserItem |
1
|
1 |
| HKU\S-1-5-21-842925246-1425521274-308236825-500\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\History
|
CacheLimit |
8192
|
1 |
| HKU\S-1-5-21-842925246-1425521274-308236825-500\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\History
|
CachePrefix |
Visited:
|
2 |
| HKU\S-1-5-21-842925246-1425521274-308236825-500\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\History
|
PerUserItem |
1
|
1 |
| HKU\S-1-5-21-842925246-1425521274-308236825-500\Software\Microsoft\windows\CurrentVersion\Internet Settings
|
MigrateProxy |
1
|
1 |
| HKU\S-1-5-21-842925246-1425521274-308236825-500\Software\Microsoft\windows\CurrentVersion\Internet Settings
|
ProxyEnable |
0
|
1 |
| HKU\S-1-5-21-842925246-1425521274-308236825-500\Software\Microsoft\windows\CurrentVersion\Internet Settings\Connections
|
DefaultConnectionSettings |
0x3c0000000200000009000000000000000000000000000000000000000000
|
2 |
| HKU\S-1-5-21-842925246-1425521274-308236825-500\Software\Microsoft\windows\CurrentVersion\Internet Settings\Connections
|
SavedLegacySettings |
0x3c0000000400000009000000000000000000000000000000000000000000
|
4 |
| HKU\S-1-5-21-842925246-1425521274-308236825-500\Volatile Environment
|
APPDATA |
C:\Documents and Settings\Administrator\Application Data
|
4 |
| HKU\S-1-5-21-842925246-1425521274-308236825-500\Volatile Environment
|
CLIENTNAME |
|
4 |
| HKU\S-1-5-21-842925246-1425521274-308236825-500\Volatile Environment
|
HOMEDRIVE |
C:
|
4 |
| HKU\S-1-5-21-842925246-1425521274-308236825-500\Volatile Environment
|
HOMEPATH |
\Documents and Settings\Administrator
|
4 |
| HKU\S-1-5-21-842925246-1425521274-308236825-500\Volatile Environment
|
HOMESHARE |
|
4 |
| HKU\S-1-5-21-842925246-1425521274-308236825-500\Volatile Environment
|
LOGONSERVER |
\\PC
|
4 |
| HKU\S-1-5-21-842925246-1425521274-308236825-500\Volatile Environment
|
SESSIONNAME |
Console
|
4 |