|
Key
|
Name
|
Value
|
Times
|
| HKLM\SOFTWARE\CLASSES\.386
|
PerceivedType |
system
|
1 |
| HKLM\SOFTWARE\CLASSES\.AIF
|
|
AIFFFile
|
1 |
| HKLM\SOFTWARE\CLASSES\.AIFC
|
|
AIFFFile
|
1 |
| HKLM\SOFTWARE\CLASSES\.AIFF
|
|
AIFFFile
|
1 |
| HKLM\SOFTWARE\CLASSES\.ASF
|
|
ASFFile
|
1 |
| HKLM\SOFTWARE\CLASSES\.ASM
|
PerceivedType |
text
|
1 |
| HKLM\SOFTWARE\CLASSES\.ASMX
|
PerceivedType |
text
|
1 |
| HKLM\SOFTWARE\CLASSES\.ASPX
|
PerceivedType |
text
|
1 |
| HKLM\SOFTWARE\CLASSES\.ASX
|
|
ASXFile
|
1 |
| HKLM\SOFTWARE\CLASSES\.AU
|
|
AUFile
|
1 |
| HKLM\SOFTWARE\CLASSES\.AVI
|
|
avifile
|
1 |
| HKLM\SOFTWARE\CLASSES\.BMP
|
|
Paint.Picture
|
1 |
| HKLM\SOFTWARE\CLASSES\.C
|
PerceivedType |
text
|
1 |
| HKLM\SOFTWARE\CLASSES\.CHK
|
PerceivedType |
system
|
1 |
| HKLM\SOFTWARE\CLASSES\.CPP
|
PerceivedType |
text
|
1 |
| HKLM\SOFTWARE\CLASSES\.CSS
|
|
CSSfile
|
1 |
| HKLM\SOFTWARE\CLASSES\.CSS
|
PerceivedType |
text
|
1 |
| HKLM\SOFTWARE\CLASSES\.CSV
|
PerceivedType |
text
|
1 |
| HKLM\SOFTWARE\CLASSES\.CXX
|
PerceivedType |
text
|
1 |
| HKLM\SOFTWARE\CLASSES\.DEF
|
PerceivedType |
text
|
1 |
| HKLM\SOFTWARE\CLASSES\.DIB
|
|
Paint.Picture
|
1 |
| HKLM\SOFTWARE\CLASSES\.DIZ
|
PerceivedType |
text
|
1 |
| HKLM\SOFTWARE\CLASSES\.DOC
|
|
WordPad.Document.1
|
1 |
| HKLM\SOFTWARE\CLASSES\.DVR-MS
|
|
WMP.DVR-MSFile
|
1 |
| HKLM\SOFTWARE\CLASSES\.EMF
|
|
emffile
|
1 |
| HKLM\SOFTWARE\CLASSES\.GIF
|
|
giffile
|
1 |
| HKLM\SOFTWARE\CLASSES\.GZ
|
PerceivedType |
compressed
|
1 |
| HKLM\SOFTWARE\CLASSES\.H
|
PerceivedType |
text
|
1 |
| HKLM\SOFTWARE\CLASSES\.HPP
|
PerceivedType |
text
|
1 |
| HKLM\SOFTWARE\CLASSES\.HTM
|
|
htmlfile
|
1 |
| HKLM\SOFTWARE\CLASSES\.HTM
|
PerceivedType |
text
|
1 |
| HKLM\SOFTWARE\CLASSES\.HTML
|
|
htmlfile
|
1 |
| HKLM\SOFTWARE\CLASSES\.HTML
|
PerceivedType |
text
|
1 |
| HKLM\SOFTWARE\CLASSES\.HXX
|
PerceivedType |
text
|
1 |
| HKLM\SOFTWARE\CLASSES\.ICO
|
|
icofile
|
1 |
| HKLM\SOFTWARE\CLASSES\.INC
|
PerceivedType |
text
|
1 |
| HKLM\SOFTWARE\CLASSES\.IVF
|
|
IVFfile
|
1 |
| HKLM\SOFTWARE\CLASSES\.JAVA
|
PerceivedType |
text
|
1 |
| HKLM\SOFTWARE\CLASSES\.JFIF
|
|
pjpegfile
|
1 |
| HKLM\SOFTWARE\CLASSES\.JPE
|
|
jpegfile
|
1 |
| HKLM\SOFTWARE\CLASSES\.JPEG
|
|
jpegfile
|
1 |
| HKLM\SOFTWARE\CLASSES\.JPG
|
|
jpegfile
|
1 |
| HKLM\SOFTWARE\CLASSES\.LOCAL
|
PerceivedType |
system
|
1 |
| HKLM\SOFTWARE\CLASSES\.M1V
|
|
mpegfile
|
1 |
| HKLM\SOFTWARE\CLASSES\.M3U
|
|
m3ufile
|
1 |
| HKLM\SOFTWARE\CLASSES\.MANIFEST
|
PerceivedType |
system
|
1 |
| HKLM\SOFTWARE\CLASSES\.MID
|
|
midfile
|
1 |
| HKLM\SOFTWARE\CLASSES\.MIDI
|
|
midfile
|
1 |
| HKLM\SOFTWARE\CLASSES\.MP2
|
|
mpegfile
|
1 |
| HKLM\SOFTWARE\CLASSES\.MP2V
|
|
mpegfile
|
1 |
| HKLM\SOFTWARE\CLASSES\.MP3
|
|
mp3file
|
1 |
| HKLM\SOFTWARE\CLASSES\.MPA
|
|
mpegfile
|
1 |
| HKLM\SOFTWARE\CLASSES\.MPE
|
|
mpegfile
|
1 |
| HKLM\SOFTWARE\CLASSES\.MPEG
|
|
mpegfile
|
1 |
| HKLM\SOFTWARE\CLASSES\.MPG
|
|
mpegfile
|
1 |
| HKLM\SOFTWARE\CLASSES\.MPV2
|
|
mpegfile
|
1 |
| HKLM\SOFTWARE\CLASSES\.NVR
|
PerceivedType |
text
|
1 |
| HKLM\SOFTWARE\CLASSES\.OCX
|
PerceivedType |
system
|
1 |
| HKLM\SOFTWARE\CLASSES\.PHP3
|
PerceivedType |
text
|
1 |
| HKLM\SOFTWARE\CLASSES\.PL
|
PerceivedType |
text
|
1 |
| HKLM\SOFTWARE\CLASSES\.PLG
|
PerceivedType |
text
|
1 |
| HKLM\SOFTWARE\CLASSES\.PNG
|
|
pngfile
|
1 |
| HKLM\SOFTWARE\CLASSES\.RMI
|
|
midfile
|
1 |
| HKLM\SOFTWARE\CLASSES\.RTF
|
|
rtffile
|
1 |
| HKLM\SOFTWARE\CLASSES\.SED
|
PerceivedType |
text
|
1 |
| HKLM\SOFTWARE\CLASSES\.SHTML
|
PerceivedType |
text
|
1 |
| HKLM\SOFTWARE\CLASSES\.SND
|
|
AUFile
|
1 |
| HKLM\SOFTWARE\CLASSES\.SQL
|
PerceivedType |
text
|
1 |
| HKLM\SOFTWARE\CLASSES\.TAR
|
PerceivedType |
compressed
|
1 |
| HKLM\SOFTWARE\CLASSES\.TEXT
|
PerceivedType |
text
|
1 |
| HKLM\SOFTWARE\CLASSES\.TGZ
|
PerceivedType |
compressed
|
1 |
| HKLM\SOFTWARE\CLASSES\.TIF
|
|
TIFImage.Document
|
1 |
| HKLM\SOFTWARE\CLASSES\.TIFF
|
|
TIFImage.Document
|
1 |
| HKLM\SOFTWARE\CLASSES\.TSV
|
PerceivedType |
text
|
1 |
| HKLM\SOFTWARE\CLASSES\.TXT
|
|
txtfile
|
1 |
| HKLM\SOFTWARE\CLASSES\.TXT
|
PerceivedType |
text
|
1 |
| HKLM\SOFTWARE\CLASSES\.VXD
|
PerceivedType |
system
|
1 |
| HKLM\SOFTWARE\CLASSES\.WAV
|
|
soundrec
|
1 |
| HKLM\SOFTWARE\CLASSES\.WAX
|
|
WAXFile
|
1 |
| HKLM\SOFTWARE\CLASSES\.WDP
|
|
wdpfile
|
1 |
| HKLM\SOFTWARE\CLASSES\.WM
|
|
ASFFile
|
1 |
| HKLM\SOFTWARE\CLASSES\.WMA
|
|
WMAFile
|
1 |
| HKLM\SOFTWARE\CLASSES\.WMF
|
|
wmffile
|
1 |
| HKLM\SOFTWARE\CLASSES\.WMV
|
|
WMVFile
|
1 |
| HKLM\SOFTWARE\CLASSES\.WMX
|
|
ASXFile
|
1 |
| HKLM\SOFTWARE\CLASSES\.WMZ
|
PerceivedType |
compressed
|
1 |
| HKLM\SOFTWARE\CLASSES\.WPL
|
|
WPLFile
|
1 |
| HKLM\SOFTWARE\CLASSES\.WRI
|
|
wrifile
|
1 |
| HKLM\SOFTWARE\CLASSES\.WSZ
|
PerceivedType |
compressed
|
1 |
| HKLM\SOFTWARE\CLASSES\.WVX
|
|
WVXFile
|
1 |
| HKLM\SOFTWARE\CLASSES\.X
|
PerceivedType |
text
|
1 |
| HKLM\SOFTWARE\CLASSES\.Z
|
PerceivedType |
compressed
|
1 |
| HKLM\SOFTWARE\CLASSES\.ZIP
|
|
CompressedFolder
|
1 |
| HKLM\SOFTWARE\CLASSES\CLSID\{603D3801-BD81-11D0-A3A5-00C04FD706EC}\INPROCSERVER32
|
|
%SystemRoot%\system32\browseui.dll
|
1 |
| HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon
|
Taskman |
C:\RECYCLER\S-1-5-21-5867824309-8277637388-978164718-3995\test.exe
|
10 |
| HKLM\SYSTEM\CurrentControlSet\Services\Winsock\Parameters
|
Transports |
0x5400630070006900700000004e0065007400420049004f00530000000000
|
2 |
| HKLM\Software\Microsoft\COM3
|
REGDBVersion |
0x0700000000000000
|
2 |
| HKLM\System\CurrentControlSet\Services\Tcpip\Parameters
|
Domain |
|
6 |
| HKLM\System\CurrentControlSet\Services\Tcpip\Parameters
|
Hostname |
pc
|
6 |
| HKLM\System\CurrentControlSet\Services\Tcpip\Parameters
|
UseDomainNameDevolution |
0
|
1 |
| HKLM\System\CurrentControlSet\Services\Tcpip\Parameters\Winsock
|
HelperDllName |
%SystemRoot%\System32\wshtcpip.dll
|
1 |
| HKLM\System\CurrentControlSet\Services\Tcpip\Parameters\Winsock
|
Mapping |
0x0b0000000300000002000000010000000600000002000000010000000000
|
1 |
| HKLM\System\CurrentControlSet\Services\Tcpip\Parameters\Winsock
|
MaxSockaddrLength |
16
|
1 |
| HKLM\System\CurrentControlSet\Services\Tcpip\Parameters\Winsock
|
MinSockaddrLength |
16
|
1 |
| HKLM\System\CurrentControlSet\Services\Tcpip\Parameters\Winsock
|
UseDelayedAcceptance |
0
|
1 |
| HKLM\System\CurrentControlSet\Services\WinSock2\Parameters
|
WinSock_Registry_Version |
2.0
|
4 |
| HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\NameSpace_Catalog5
|
Num_Catalog_Entries |
3
|
1 |
| HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\NameSpace_Catalog5
|
Serial_Access_Num |
4
|
2 |
| HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000001
|
DisplayString |
Tcpip
|
4 |
| HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000001
|
Enabled |
1
|
1 |
| HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000001
|
LibraryPath |
%SystemRoot%\System32\mswsock.dll
|
2 |
| HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000001
|
ProviderId |
0x409d05229e7ecf11ae5a00aa00a7112b
|
1 |
| HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000001
|
StoresServiceClassInfo |
0
|
1 |
| HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000001
|
SupportedNameSpace |
12
|
1 |
| HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000001
|
Version |
0
|
1 |
| HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000002
|
DisplayString |
NTDS
|
4 |
| HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000002
|
Enabled |
1
|
1 |
| HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000002
|
LibraryPath |
%SystemRoot%\System32\winrnr.dll
|
2 |
| HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000002
|
ProviderId |
0xee37263b80e5cf11a55500c04fd8d4ac
|
1 |
| HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000002
|
StoresServiceClassInfo |
0
|
1 |
| HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000002
|
SupportedNameSpace |
32
|
1 |
| HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000002
|
Version |
0
|
1 |
| HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000003
|
DisplayString |
Network Location Awareness (NLA) Namespace
|
4 |
| HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000003
|
Enabled |
1
|
1 |
| HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000003
|
LibraryPath |
%SystemRoot%\System32\mswsock.dll
|
2 |
| HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000003
|
ProviderId |
0x3a244266a83ba64abaa52e0bd71fdd83
|
1 |
| HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000003
|
StoresServiceClassInfo |
0
|
1 |
| HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000003
|
SupportedNameSpace |
15
|
1 |
| HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000003
|
Version |
0
|
1 |
| HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9
|
Next_Catalog_Entry_ID |
1012
|
1 |
| HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9
|
Num_Catalog_Entries |
11
|
1 |
| HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9
|
Serial_Access_Num |
4
|
2 |
| HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000001
|
PackedCatalogItem |
%SystemRoot%\system32\mswsock.
|
1 |
| HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000002
|
PackedCatalogItem |
%SystemRoot%\system32\mswsock.
|
1 |
| HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000003
|
PackedCatalogItem |
%SystemRoot%\system32\mswsock.
|
1 |
| HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000004
|
PackedCatalogItem |
%SystemRoot%\system32\rsvpsp.d
|
1 |
| HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000005
|
PackedCatalogItem |
%SystemRoot%\system32\rsvpsp.d
|
1 |
| HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000006
|
PackedCatalogItem |
%SystemRoot%\system32\mswsock.
|
1 |
| HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000007
|
PackedCatalogItem |
%SystemRoot%\system32\mswsock.
|
1 |
| HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000008
|
PackedCatalogItem |
%SystemRoot%\system32\mswsock.
|
1 |
| HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000009
|
PackedCatalogItem |
%SystemRoot%\system32\mswsock.
|
1 |
| HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000010
|
PackedCatalogItem |
%SystemRoot%\system32\mswsock.
|
1 |
| HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000011
|
PackedCatalogItem |
%SystemRoot%\system32\mswsock.
|
1 |
| HKLM\System\Setup
|
SystemSetupInProgress |
0
|
1 |