Advertisement
Not a member of Pastebin yet?
Sign Up,
it unlocks many cool features!
- ***** PANDA SECURITY *****
- ***** POLICE RESCUE UTILITY *****
- ---------------------------------
- ** Detecting hard disks!!
- Done!!
- ** 64 bits operative system : 0
- ** Finding Windows Registry!!
- Looking for in: /mnt/sda1/WINDOWS/system32/config/software
- Found!!
- Applying generic disinfection!!
- *******************
- reged version 0.1 110511, (c) Petter N Hagen
- Hive <./mnt/sda1/WINDOWS/system32/config/software> name (from header): <emRoot\System32\Config\SOFTWARE>
- ROOT KEY at offset: 0x001020 * Subkey indexing type is: 666c <lf>
- File size 33816576 [2040000] bytes, containing 7901 pages (+ 1 headerpage)
- Used for data: 602047/33422048 blocks/bytes, unused: 3793/35200 blocks/bytes.
- --- Import KEY <\Microsoft\Windows NT\CurrentVersion\Winlogon> with 1 values.
- --- Import KEY <\Microsoft\Windows NT\CurrentVersion\Winlogon> with 1 values.
- --- Import KEY <\Microsoft\Windows NT\CurrentVersion\Winlogon> with 1 values.
- --- Import KEY <\Microsoft\Windows NT\CurrentVersion\Winlogon> with 1 values.
- --- Import KEY <\Microsoft\Windows NT\CurrentVersion\Winlogon> with 1 values.
- --- Import KEY <\Microsoft\Windows NT\CurrentVersion\Winlogon>
- END OF IMPORT, file </root/policeWinlogon.reg>, operation SUCCEEDED!
- 6 keys
- 0 new keys added
- 6 values total
- Hives that have changed:
- # Name
- 0 <./mnt/sda1/WINDOWS/system32/config/software> - OK
- Modificadas claves HKLM\Software\Microsoft\Windows NT\CurrentVersion\Winlogon | Shell | State | Userinit | Taskman | taskman
- *******************
- reged version 0.1 110511, (c) Petter N Hagen
- Hive <./mnt/sda1/WINDOWS/system32/config/software> name (from header): <emRoot\System32\Config\SOFTWARE>
- ROOT KEY at offset: 0x001020 * Subkey indexing type is: 666c <lf>
- File size 33816576 [2040000] bytes, containing 7901 pages (+ 1 headerpage)
- Used for data: 602051/33422224 blocks/bytes, unused: 3795/35024 blocks/bytes.
- --- Import KEY <\Microsoft\Windows\CurrentVersion\Explorer> with 1 values.
- --- Import KEY <\Microsoft\Windows\CurrentVersion\Explorer> with 1 values.
- --- Import KEY <\Microsoft\Windows\CurrentVersion\Explorer>
- END OF IMPORT, file </root/policeExplorer.reg>, operation SUCCEEDED!
- 3 keys
- 0 new keys added
- 3 values total
- Hives that have changed:
- # Name
- 0 <./mnt/sda1/WINDOWS/system32/config/software> - OK
- Modificadas claves HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer | Expanded | Favorites | FullPath
- *******************
- ERROR: import_reg: failed to add (sub)key <explorer>
- reged version 0.1 110511, (c) Petter N Hagen
- Hive <./mnt/sda1/WINDOWS/system32/config/software> name (from header): <emRoot\System32\Config\SOFTWARE>
- ROOT KEY at offset: 0x001020 * Subkey indexing type is: 666c <lf>
- File size 33816576 [2040000] bytes, containing 7901 pages (+ 1 headerpage)
- Used for data: 602054/33422360 blocks/bytes, unused: 3795/34888 blocks/bytes.
- --- Import KEY <\Microsoft\Windows\CurrentVersion\explorer> add_key: key explorer already exists!
- END OF IMPORT, file </root/policeExplorerWvista.reg>, operation FAILED!
- 1 keys
- 0 new keys added
- 0 values total
- Hives that have changed:
- # Name
- None!
- Modificadas claves HKLM\Software\Microsoft\Windows\CurrentVersion\explorer | Expanded | Favorites | FullPath
- *******************
- reged version 0.1 110511, (c) Petter N Hagen
- Hive <./mnt/sda1/WINDOWS/system32/config/software> name (from header): <emRoot\System32\Config\SOFTWARE>
- ROOT KEY at offset: 0x001020 * Subkey indexing type is: 666c <lf>
- File size 33816576 [2040000] bytes, containing 7901 pages (+ 1 headerpage)
- Used for data: 602054/33422360 blocks/bytes, unused: 3795/34888 blocks/bytes.
- Exporting to file '/tmp/runRead.reg'...
- Exporting key 'Run' with 0 subkeys and 1 values...
- *******************
- Fichero /tmp/runRead.reg
- Windows Registry Editor Version 5.00
- [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
- "avgnt"="\"C:\\Archivos de programa\\Avira\\AntiVir Desktop\\avgnt.exe\" /min"
- *******************
- Fichero /tmp/runWrite.reg
- Windows Registry Editor Version 5.00
- [HKEY_LOCAL_MACHINESOFTWARE\Microsoft\Windows\CurrentVersion\Run]
- "avgnt"=
- *******************
- reged version 0.1 110511, (c) Petter N Hagen
- Hive <./mnt/sda1/WINDOWS/system32/config/software> name (from header): <emRoot\System32\Config\SOFTWARE>
- ROOT KEY at offset: 0x001020 * Subkey indexing type is: 666c <lf>
- File size 33816576 [2040000] bytes, containing 7901 pages (+ 1 headerpage)
- Used for data: 602054/33422360 blocks/bytes, unused: 3795/34888 blocks/bytes.
- --- Import KEY <\Microsoft\Windows\CurrentVersion\Run>
- END OF IMPORT, file </tmp/runWrite.reg>, operation SUCCEEDED!
- 1 keys
- 0 new keys added
- 1 values total
- Hives that have changed:
- # Name
- 0 <./mnt/sda1/WINDOWS/system32/config/software> - OK
- Modificada clave HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run | Todos los valores a vacio
- *******************
- reged version 0.1 110511, (c) Petter N Hagen
- Hive <./mnt/sda1/WINDOWS/system32/config/software> name (from header): <emRoot\System32\Config\SOFTWARE>
- ROOT KEY at offset: 0x001020 * Subkey indexing type is: 666c <lf>
- File size 33816576 [2040000] bytes, containing 7901 pages (+ 1 headerpage)
- Used for data: 602053/33422224 blocks/bytes, unused: 3796/35024 blocks/bytes.
- Exporting to file '/tmp/runRead.reg'...
- export_subkey: Key 'Microsoft\Windows\CurrentVersion\Policies\Explorer\Run' not found!
- *******************
- Fichero /tmp/runRead.reg
- Windows Registry Editor Version 5.00
- *******************
- Fichero /tmp/runWrite.reg
- Windows Registry Editor Version 5.00
- *******************
- reged version 0.1 110511, (c) Petter N Hagen
- Hive <./mnt/sda1/WINDOWS/system32/config/software> name (from header): <emRoot\System32\Config\SOFTWARE>
- ROOT KEY at offset: 0x001020 * Subkey indexing type is: 666c <lf>
- File size 33816576 [2040000] bytes, containing 7901 pages (+ 1 headerpage)
- Used for data: 602053/33422224 blocks/bytes, unused: 3796/35024 blocks/bytes.
- END OF IMPORT, file </tmp/runWrite.reg>, operation SUCCEEDED!
- 0 keys
- 0 new keys added
- 0 values total
- Hives that have changed:
- # Name
- None!
- Modificada clave HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run | Todos los valores a vacio
- *******************
- reged version 0.1 110511, (c) Petter N Hagen
- Hive <./mnt/sda1/WINDOWS/system32/config/software> name (from header): <emRoot\System32\Config\SOFTWARE>
- ROOT KEY at offset: 0x001020 * Subkey indexing type is: 666c <lf>
- File size 33816576 [2040000] bytes, containing 7901 pages (+ 1 headerpage)
- Used for data: 602053/33422224 blocks/bytes, unused: 3796/35024 blocks/bytes.
- Exporting to file '/tmp/runRead.reg'...
- export_subkey: Key 'Microsoft\Windows\CurrentVersion\policies\Explorer\Run' not found!
- *******************
- Fichero /tmp/runRead.reg
- Windows Registry Editor Version 5.00
- *******************
- Fichero /tmp/runWrite.reg
- Windows Registry Editor Version 5.00
- *******************
- reged version 0.1 110511, (c) Petter N Hagen
- Hive <./mnt/sda1/WINDOWS/system32/config/software> name (from header): <emRoot\System32\Config\SOFTWARE>
- ROOT KEY at offset: 0x001020 * Subkey indexing type is: 666c <lf>
- File size 33816576 [2040000] bytes, containing 7901 pages (+ 1 headerpage)
- Used for data: 602053/33422224 blocks/bytes, unused: 3796/35024 blocks/bytes.
- END OF IMPORT, file </tmp/runWrite.reg>, operation SUCCEEDED!
- 0 keys
- 0 new keys added
- 0 values total
- Hives that have changed:
- # Name
- None!
- Modificada clave HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\Run | Todos los valores a vacio
- *******************
- reged version 0.1 110511, (c) Petter N Hagen
- Hive <./mnt/sda1/WINDOWS/system32/config/software> name (from header): <emRoot\System32\Config\SOFTWARE>
- ROOT KEY at offset: 0x001020 * Subkey indexing type is: 666c <lf>
- File size 33816576 [2040000] bytes, containing 7901 pages (+ 1 headerpage)
- Used for data: 602053/33422224 blocks/bytes, unused: 3796/35024 blocks/bytes.
- Exporting to file '/tmp/runRead.reg'...
- export_subkey: Key 'Microsoft\Shared Tools\MSConfig\startupfolder' not found!
- *******************
- Fichero /tmp/runRead.reg
- Windows Registry Editor Version 5.00
- *******************
- Fichero /tmp/runWrite.reg
- Windows Registry Editor Version 5.00
- *******************
- reged version 0.1 110511, (c) Petter N Hagen
- Hive <./mnt/sda1/WINDOWS/system32/config/software> name (from header): <emRoot\System32\Config\SOFTWARE>
- ROOT KEY at offset: 0x001020 * Subkey indexing type is: 666c <lf>
- File size 33816576 [2040000] bytes, containing 7901 pages (+ 1 headerpage)
- Used for data: 602053/33422224 blocks/bytes, unused: 3796/35024 blocks/bytes.
- END OF IMPORT, file </tmp/runWrite.reg>, operation SUCCEEDED!
- 0 keys
- 0 new keys added
- 0 values total
- Hives that have changed:
- # Name
- None!
- Modificada clave HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupfolder | Todos los valores a vacio
- Applying user disinfection!!
- This step may take a while depending on the size of your hard disk!!
- *******************
- reged version 0.1 110511, (c) Petter N Hagen
- Hive <./mnt/sda1/WINDOWS/system32/config/software> name (from header): <emRoot\System32\Config\SOFTWARE>
- ROOT KEY at offset: 0x001020 * Subkey indexing type is: 666c <lf>
- File size 33816576 [2040000] bytes, containing 7901 pages (+ 1 headerpage)
- Used for data: 602053/33422224 blocks/bytes, unused: 3796/35024 blocks/bytes.
- Exporting to file '/tmp/users.reg'...
- Exporting key 'ProfileList' with 4 subkeys and 3 values...
- Exporting key 'S-1-5-18' with 0 subkeys and 5 values...
- Exporting key 'S-1-5-19' with 0 subkeys and 8 values...
- Exporting key 'S-1-5-20' with 0 subkeys and 8 values...
- Exporting key 'S-1-5-21-606747145-746137067-682003330-1003' with 0 subkeys and 10 values...
- User: S-1-5-18
- NTUSER: /mnt/sda1/Documents and Settings/Default User/NTUSER.DAT
- *******************
- reged version 0.1 110511, (c) Petter N Hagen
- Hive </mnt/sda1/Documents and Settings/Default User/NTUSER.DAT> name (from header): <ettings\Default User\NtUser.dat>
- ROOT KEY at offset: 0x001020 * Subkey indexing type is: 666c <lf>
- File size 262144 [40000] bytes, containing 59 pages (+ 1 headerpage)
- Used for data: 4190/234832 blocks/bytes, unused: 126/4944 blocks/bytes.
- Exporting to file '/tmp/runRead.reg'...
- Exporting key 'Run' with 0 subkeys and 1 values...
- *******************
- Fichero /tmp/runRead.reg
- Windows Registry Editor Version 5.00
- [HKEY_USERS\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Run]
- "CTFMON.EXE"="C:\\WINDOWS\\system32\\CTFMON.EXE"
- *******************
- Fichero /tmp/runWrite.reg
- Windows Registry Editor Version 5.00
- [HKEY_USERSS-1-5-18\Software\Microsoft\Windows\CurrentVersion\Run]
- "CTFMON.EXE"=
- *******************
- reged version 0.1 110511, (c) Petter N Hagen
- Hive </mnt/sda1/Documents and Settings/Default User/NTUSER.DAT> name (from header): <ettings\Default User\NtUser.dat>
- ROOT KEY at offset: 0x001020 * Subkey indexing type is: 666c <lf>
- File size 262144 [40000] bytes, containing 59 pages (+ 1 headerpage)
- Used for data: 4190/234832 blocks/bytes, unused: 126/4944 blocks/bytes.
- --- Import KEY <\Software\Microsoft\Windows\CurrentVersion\Run>
- END OF IMPORT, file </tmp/runWrite.reg>, operation SUCCEEDED!
- 1 keys
- 0 new keys added
- 1 values total
- Hives that have changed:
- # Name
- 0 </mnt/sda1/Documents and Settings/Default User/NTUSER.DAT> - OK
- Modificada clave HKEY_USERS\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Run | Todos los valores a vacio
- *******************
- reged version 0.1 110511, (c) Petter N Hagen
- Hive </mnt/sda1/Documents and Settings/Default User/NTUSER.DAT> name (from header): <ettings\Default User\NtUser.dat>
- ROOT KEY at offset: 0x001020 * Subkey indexing type is: 666c <lf>
- File size 262144 [40000] bytes, containing 59 pages (+ 1 headerpage)
- Used for data: 4189/234760 blocks/bytes, unused: 127/5016 blocks/bytes.
- --- Import KEY <\Software\Microsoft\Windows NT\CurrentVersion\Winlogon> with 2 values.
- --- Import KEY <\Software\Microsoft\Windows NT\CurrentVersion\Winlogon>
- END OF IMPORT, file </tmp/user.reg>, operation SUCCEEDED!
- 2 keys
- 0 new keys added
- 4 values total
- Hives that have changed:
- # Name
- 0 </mnt/sda1/Documents and Settings/Default User/NTUSER.DAT> - OK
- Modificada clave HKEY_USERS\S-1-5-18\Software\Microsoft\Windows NT\CurrentVersion\Winlogon | Shell | Userinit
- *******************
- reged version 0.1 110511, (c) Petter N Hagen
- Hive </mnt/sda1/Documents and Settings/Default User/NTUSER.DAT> name (from header): <ettings\Default User\NtUser.dat>
- ROOT KEY at offset: 0x001020 * Subkey indexing type is: 666c <lf>
- File size 262144 [40000] bytes, containing 59 pages (+ 1 headerpage)
- Used for data: 4193/234936 blocks/bytes, unused: 129/4840 blocks/bytes.
- --- Import KEY <\Software\Microsoft\Windows NT\CurrentVersion\Windows>
- END OF IMPORT, file </tmp/user.reg>, operation SUCCEEDED!
- 1 keys
- 0 new keys added
- 2 values total
- Hives that have changed:
- # Name
- 0 </mnt/sda1/Documents and Settings/Default User/NTUSER.DAT> - OK
- Modificada clave HKEY_USERS\S-1-5-18\Software\Microsoft\Windows NT\CurrentVersion\Windows | Load
- NTUSER: /mnt/sda1/Documents and Settings/LocalService/NTUSER.DAT
- *******************
- reged version 0.1 110511, (c) Petter N Hagen
- Hive </mnt/sda1/Documents and Settings/LocalService/NTUSER.DAT> name (from header): <ettings\LocalService\ntuser.dat>
- ROOT KEY at offset: 0x001020 * Subkey indexing type is: 666c <lf>
- File size 262144 [40000] bytes, containing 57 pages (+ 1 headerpage)
- Used for data: 4159/230144 blocks/bytes, unused: 141/1504 blocks/bytes.
- Exporting to file '/tmp/runRead.reg'...
- Exporting key 'Run' with 0 subkeys and 1 values...
- *******************
- Fichero /tmp/runRead.reg
- Windows Registry Editor Version 5.00
- [HKEY_USERS\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Run]
- "CTFMON.EXE"="C:\\WINDOWS\\system32\\CTFMON.EXE"
- *******************
- Fichero /tmp/runWrite.reg
- Windows Registry Editor Version 5.00
- [HKEY_USERSS-1-5-18\Software\Microsoft\Windows\CurrentVersion\Run]
- "CTFMON.EXE"=
- *******************
- reged version 0.1 110511, (c) Petter N Hagen
- Hive </mnt/sda1/Documents and Settings/LocalService/NTUSER.DAT> name (from header): <ettings\LocalService\ntuser.dat>
- ROOT KEY at offset: 0x001020 * Subkey indexing type is: 666c <lf>
- File size 262144 [40000] bytes, containing 57 pages (+ 1 headerpage)
- Used for data: 4159/230144 blocks/bytes, unused: 141/1504 blocks/bytes.
- --- Import KEY <\Software\Microsoft\Windows\CurrentVersion\Run>
- END OF IMPORT, file </tmp/runWrite.reg>, operation SUCCEEDED!
- 1 keys
- 0 new keys added
- 1 values total
- Hives that have changed:
- # Name
- 0 </mnt/sda1/Documents and Settings/LocalService/NTUSER.DAT> - OK
- Modificada clave HKEY_USERS\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Run | Todos los valores a vacio
- *******************
- reged version 0.1 110511, (c) Petter N Hagen
- Hive </mnt/sda1/Documents and Settings/LocalService/NTUSER.DAT> name (from header): <ettings\LocalService\ntuser.dat>
- ROOT KEY at offset: 0x001020 * Subkey indexing type is: 666c <lf>
- File size 262144 [40000] bytes, containing 57 pages (+ 1 headerpage)
- Used for data: 4158/230072 blocks/bytes, unused: 142/1576 blocks/bytes.
- --- Import KEY <\Software\Microsoft\Windows NT\CurrentVersion\Winlogon> with 2 values.
- --- Import KEY <\Software\Microsoft\Windows NT\CurrentVersion\Winlogon>
- END OF IMPORT, file </tmp/user.reg>, operation SUCCEEDED!
- 2 keys
- 0 new keys added
- 4 values total
- Hives that have changed:
- # Name
- 0 </mnt/sda1/Documents and Settings/LocalService/NTUSER.DAT> - OK
- Modificada clave HKEY_USERS\S-1-5-18\Software\Microsoft\Windows NT\CurrentVersion\Winlogon | Shell | Userinit
- *******************
- reged version 0.1 110511, (c) Petter N Hagen
- Hive </mnt/sda1/Documents and Settings/LocalService/NTUSER.DAT> name (from header): <ettings\LocalService\ntuser.dat>
- ROOT KEY at offset: 0x001020 * Subkey indexing type is: 666c <lf>
- File size 262144 [40000] bytes, containing 57 pages (+ 1 headerpage)
- Used for data: 4162/230248 blocks/bytes, unused: 144/1400 blocks/bytes.
- --- Import KEY <\Software\Microsoft\Windows NT\CurrentVersion\Windows>
- END OF IMPORT, file </tmp/user.reg>, operation SUCCEEDED!
- 1 keys
- 0 new keys added
- 2 values total
- Hives that have changed:
- # Name
- 0 </mnt/sda1/Documents and Settings/LocalService/NTUSER.DAT> - OK
- Modificada clave HKEY_USERS\S-1-5-18\Software\Microsoft\Windows NT\CurrentVersion\Windows | Load
- NTUSER: /mnt/sda1/Documents and Settings/NetworkService/NTUSER.DAT
- *******************
- reged version 0.1 110511, (c) Petter N Hagen
- Hive </mnt/sda1/Documents and Settings/NetworkService/NTUSER.DAT> name (from header): <tings\NetworkService\ntuser.dat>
- ROOT KEY at offset: 0x001020 * Subkey indexing type is: 666c <lf>
- File size 303104 [4a000] bytes, containing 57 pages (+ 1 headerpage)
- Used for data: 4127/294672 blocks/bytes, unused: 133/2512 blocks/bytes.
- Exporting to file '/tmp/runRead.reg'...
- Exporting key 'Run' with 0 subkeys and 1 values...
- *******************
- Fichero /tmp/runRead.reg
- Windows Registry Editor Version 5.00
- [HKEY_USERS\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Run]
- "CTFMON.EXE"="C:\\WINDOWS\\system32\\CTFMON.EXE"
- *******************
- Fichero /tmp/runWrite.reg
- Windows Registry Editor Version 5.00
- [HKEY_USERSS-1-5-18\Software\Microsoft\Windows\CurrentVersion\Run]
- "CTFMON.EXE"=
- *******************
- reged version 0.1 110511, (c) Petter N Hagen
- Hive </mnt/sda1/Documents and Settings/NetworkService/NTUSER.DAT> name (from header): <tings\NetworkService\ntuser.dat>
- ROOT KEY at offset: 0x001020 * Subkey indexing type is: 666c <lf>
- File size 303104 [4a000] bytes, containing 57 pages (+ 1 headerpage)
- Used for data: 4127/294672 blocks/bytes, unused: 133/2512 blocks/bytes.
- --- Import KEY <\Software\Microsoft\Windows\CurrentVersion\Run>
- END OF IMPORT, file </tmp/runWrite.reg>, operation SUCCEEDED!
- 1 keys
- 0 new keys added
- 1 values total
- Hives that have changed:
- # Name
- 0 </mnt/sda1/Documents and Settings/NetworkService/NTUSER.DAT> - OK
- Modificada clave HKEY_USERS\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Run | Todos los valores a vacio
- *******************
- reged version 0.1 110511, (c) Petter N Hagen
- Hive </mnt/sda1/Documents and Settings/NetworkService/NTUSER.DAT> name (from header): <tings\NetworkService\ntuser.dat>
- ROOT KEY at offset: 0x001020 * Subkey indexing type is: 666c <lf>
- File size 303104 [4a000] bytes, containing 57 pages (+ 1 headerpage)
- Used for data: 4126/294600 blocks/bytes, unused: 134/2584 blocks/bytes.
- --- Import KEY <\Software\Microsoft\Windows NT\CurrentVersion\Winlogon> with 2 values.
- --- Import KEY <\Software\Microsoft\Windows NT\CurrentVersion\Winlogon>
- END OF IMPORT, file </tmp/user.reg>, operation SUCCEEDED!
- 2 keys
- 0 new keys added
- 4 values total
- Hives that have changed:
- # Name
- 0 </mnt/sda1/Documents and Settings/NetworkService/NTUSER.DAT> - OK
- Modificada clave HKEY_USERS\S-1-5-18\Software\Microsoft\Windows NT\CurrentVersion\Winlogon | Shell | Userinit
- *******************
- reged version 0.1 110511, (c) Petter N Hagen
- Hive </mnt/sda1/Documents and Settings/NetworkService/NTUSER.DAT> name (from header): <tings\NetworkService\ntuser.dat>
- ROOT KEY at offset: 0x001020 * Subkey indexing type is: 666c <lf>
- File size 303104 [4a000] bytes, containing 57 pages (+ 1 headerpage)
- Used for data: 4130/294776 blocks/bytes, unused: 133/2408 blocks/bytes.
- --- Import KEY <\Software\Microsoft\Windows NT\CurrentVersion\Windows>
- END OF IMPORT, file </tmp/user.reg>, operation SUCCEEDED!
- 1 keys
- 0 new keys added
- 2 values total
- Hives that have changed:
- # Name
- 0 </mnt/sda1/Documents and Settings/NetworkService/NTUSER.DAT> - OK
- Modificada clave HKEY_USERS\S-1-5-18\Software\Microsoft\Windows NT\CurrentVersion\Windows | Load
- NTUSER: /mnt/sda1/Documents and Settings/vinagreta/NTUSER.DAT
- *******************
- reged version 0.1 110511, (c) Petter N Hagen
- Hive </mnt/sda1/Documents and Settings/vinagreta/NTUSER.DAT> name (from header): <d Settings\vinagreta\ntuser.dat>
- ROOT KEY at offset: 0x001020 * Subkey indexing type is: 666c <lf>
- File size 6029312 [5c0000] bytes, containing 1100 pages (+ 1 headerpage)
- Used for data: 99150/5792192 blocks/bytes, unused: 6567/140480 blocks/bytes.
- Exporting to file '/tmp/runRead.reg'...
- Exporting key 'Run' with 0 subkeys and 1 values...
- *******************
- Fichero /tmp/runRead.reg
- Windows Registry Editor Version 5.00
- [HKEY_USERS\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Run]
- "ctfmon.exe"="C:\\WINDOWS\\system32\\ctfmon.exe"
- *******************
- Fichero /tmp/runWrite.reg
- Windows Registry Editor Version 5.00
- [HKEY_USERSS-1-5-18\Software\Microsoft\Windows\CurrentVersion\Run]
- "ctfmon.exe"=
- *******************
- reged version 0.1 110511, (c) Petter N Hagen
- Hive </mnt/sda1/Documents and Settings/vinagreta/NTUSER.DAT> name (from header): <d Settings\vinagreta\ntuser.dat>
- ROOT KEY at offset: 0x001020 * Subkey indexing type is: 666c <lf>
- File size 6029312 [5c0000] bytes, containing 1100 pages (+ 1 headerpage)
- Used for data: 99150/5792192 blocks/bytes, unused: 6567/140480 blocks/bytes.
- --- Import KEY <\Software\Microsoft\Windows\CurrentVersion\Run>
- END OF IMPORT, file </tmp/runWrite.reg>, operation SUCCEEDED!
- 1 keys
- 0 new keys added
- 1 values total
- Hives that have changed:
- # Name
- 0 </mnt/sda1/Documents and Settings/vinagreta/NTUSER.DAT> - OK
- Modificada clave HKEY_USERS\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Run | Todos los valores a vacio
- *******************
- reged version 0.1 110511, (c) Petter N Hagen
- Hive </mnt/sda1/Documents and Settings/vinagreta/NTUSER.DAT> name (from header): <d Settings\vinagreta\ntuser.dat>
- ROOT KEY at offset: 0x001020 * Subkey indexing type is: 666c <lf>
- File size 6029312 [5c0000] bytes, containing 1100 pages (+ 1 headerpage)
- Used for data: 99149/5792120 blocks/bytes, unused: 6568/140552 blocks/bytes.
- --- Import KEY <\Software\Microsoft\Windows NT\CurrentVersion\Winlogon> with 2 values.
- --- Import KEY <\Software\Microsoft\Windows NT\CurrentVersion\Winlogon>
- END OF IMPORT, file </tmp/user.reg>, operation SUCCEEDED!
- 2 keys
- 0 new keys added
- 4 values total
- Hives that have changed:
- # Name
- 0 </mnt/sda1/Documents and Settings/vinagreta/NTUSER.DAT> - OK
- Modificada clave HKEY_USERS\S-1-5-18\Software\Microsoft\Windows NT\CurrentVersion\Winlogon | Shell | Userinit
- *******************
- reged version 0.1 110511, (c) Petter N Hagen
- Hive </mnt/sda1/Documents and Settings/vinagreta/NTUSER.DAT> name (from header): <d Settings\vinagreta\ntuser.dat>
- ROOT KEY at offset: 0x001020 * Subkey indexing type is: 666c <lf>
- File size 6029312 [5c0000] bytes, containing 1100 pages (+ 1 headerpage)
- Used for data: 99153/5792296 blocks/bytes, unused: 6568/140376 blocks/bytes.
- --- Import KEY <\Software\Microsoft\Windows NT\CurrentVersion\Windows>
- END OF IMPORT, file </tmp/user.reg>, operation SUCCEEDED!
- 1 keys
- 0 new keys added
- 2 values total
- Hives that have changed:
- # Name
- 0 </mnt/sda1/Documents and Settings/vinagreta/NTUSER.DAT> - OK
- Modificada clave HKEY_USERS\S-1-5-18\Software\Microsoft\Windows NT\CurrentVersion\Windows | Load
- NTUSER: /mnt/sda1/WINDOWS/system32/config/systemprofile/NtUser.dat
- *******************
- reged version 0.1 110511, (c) Petter N Hagen
- Hive </mnt/sda1/WINDOWS/system32/config/systemprofile/NtUser.dat> name (from header): <em32\config\SYSTEM~1\NtUser.dat>
- ROOT KEY at offset: 0x001020 * Subkey indexing type is: 666c <lf>
- File size 262144 [40000] bytes, containing 1 pages (+ 1 headerpage)
- Used for data: 2/264 blocks/bytes, unused: 1/3800 blocks/bytes.
- Exporting to file '/tmp/runRead.reg'...
- export_subkey: Key 'Software\Microsoft\Windows\CurrentVersion\Run' not found!
- *******************
- Fichero /tmp/runRead.reg
- Windows Registry Editor Version 5.00
- *******************
- Fichero /tmp/runWrite.reg
- Windows Registry Editor Version 5.00
- *******************
- reged version 0.1 110511, (c) Petter N Hagen
- Hive </mnt/sda1/WINDOWS/system32/config/systemprofile/NtUser.dat> name (from header): <em32\config\SYSTEM~1\NtUser.dat>
- ROOT KEY at offset: 0x001020 * Subkey indexing type is: 666c <lf>
- File size 262144 [40000] bytes, containing 1 pages (+ 1 headerpage)
- Used for data: 2/264 blocks/bytes, unused: 1/3800 blocks/bytes.
- END OF IMPORT, file </tmp/runWrite.reg>, operation SUCCEEDED!
- 0 keys
- 0 new keys added
- 0 values total
- Hives that have changed:
- # Name
- None!
- Modificada clave HKEY_USERS\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Run | Todos los valores a vacio
- *******************
- reged version 0.1 110511, (c) Petter N Hagen
- Hive </mnt/sda1/WINDOWS/system32/config/systemprofile/NtUser.dat> name (from header): <em32\config\SYSTEM~1\NtUser.dat>
- ROOT KEY at offset: 0x001020 * Subkey indexing type is: 666c <lf>
- File size 262144 [40000] bytes, containing 1 pages (+ 1 headerpage)
- Used for data: 2/264 blocks/bytes, unused: 1/3800 blocks/bytes.
- --- Import KEY <\Software\Microsoft\Windows NT\CurrentVersion\Winlogon> [added <Software>] [added <Microsoft>] [added <Windows NT>] [added <CurrentVersion>] [added <Winlogon>] with 2 values.
- --- Import KEY <\Software\Microsoft\Windows NT\CurrentVersion\Winlogon>
- END OF IMPORT, file </tmp/user.reg>, operation SUCCEEDED!
- 2 keys
- 5 new keys added
- 4 values total
- Hives that have changed:
- # Name
- 0 </mnt/sda1/WINDOWS/system32/config/systemprofile/NtUser.dat> - OK
- Modificada clave HKEY_USERS\S-1-5-18\Software\Microsoft\Windows NT\CurrentVersion\Winlogon | Shell | Userinit
- *******************
- reged version 0.1 110511, (c) Petter N Hagen
- Hive </mnt/sda1/WINDOWS/system32/config/systemprofile/NtUser.dat> name (from header): <em32\config\SYSTEM~1\NtUser.dat>
- ROOT KEY at offset: 0x001020 * Subkey indexing type is: 666c <lf>
- File size 262144 [40000] bytes, containing 1 pages (+ 1 headerpage)
- Used for data: 17/1056 blocks/bytes, unused: 4/3008 blocks/bytes.
- --- Import KEY <\Software\Microsoft\Windows NT\CurrentVersion\Windows> [added <Windows>]
- END OF IMPORT, file </tmp/user.reg>, operation SUCCEEDED!
- 1 keys
- 1 new keys added
- 2 values total
- Hives that have changed:
- # Name
- 0 </mnt/sda1/WINDOWS/system32/config/systemprofile/NtUser.dat> - OK
- Modificada clave HKEY_USERS\S-1-5-18\Software\Microsoft\Windows NT\CurrentVersion\Windows | Load
- NTUSER: /mnt/sda1/WINDOWS/repair/ntuser.dat
- *******************
- reged version 0.1 110511, (c) Petter N Hagen
- Hive </mnt/sda1/WINDOWS/repair/ntuser.dat> name (from header): <>
- ROOT KEY at offset: 0x001020 * Subkey indexing type is: 666c <lf>
- File size 241664 [3b000] bytes, containing 58 pages (+ 1 headerpage)
- Used for data: 4185/234472 blocks/bytes, unused: 127/1240 blocks/bytes.
- Exporting to file '/tmp/runRead.reg'...
- Exporting key 'Run' with 0 subkeys and 1 values...
- *******************
- Fichero /tmp/runRead.reg
- Windows Registry Editor Version 5.00
- [HKEY_USERS\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Run]
- "CTFMON.EXE"="C:\\WINDOWS\\system32\\CTFMON.EXE"
- *******************
- Fichero /tmp/runWrite.reg
- Windows Registry Editor Version 5.00
- [HKEY_USERSS-1-5-18\Software\Microsoft\Windows\CurrentVersion\Run]
- "CTFMON.EXE"=
- *******************
- reged version 0.1 110511, (c) Petter N Hagen
- Hive </mnt/sda1/WINDOWS/repair/ntuser.dat> name (from header): <>
- ROOT KEY at offset: 0x001020 * Subkey indexing type is: 666c <lf>
- File size 241664 [3b000] bytes, containing 58 pages (+ 1 headerpage)
- Used for data: 4185/234472 blocks/bytes, unused: 127/1240 blocks/bytes.
- --- Import KEY <\Software\Microsoft\Windows\CurrentVersion\Run>
- END OF IMPORT, file </tmp/runWrite.reg>, operation SUCCEEDED!
- 1 keys
- 0 new keys added
- 1 values total
- Hives that have changed:
- # Name
- 0 </mnt/sda1/WINDOWS/repair/ntuser.dat> - OK
- Modificada clave HKEY_USERS\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Run | Todos los valores a vacio
- *******************
- reged version 0.1 110511, (c) Petter N Hagen
- Hive </mnt/sda1/WINDOWS/repair/ntuser.dat> name (from header): <>
- ROOT KEY at offset: 0x001020 * Subkey indexing type is: 666c <lf>
- File size 241664 [3b000] bytes, containing 58 pages (+ 1 headerpage)
- Used for data: 4184/234400 blocks/bytes, unused: 128/1312 blocks/bytes.
- --- Import KEY <\Software\Microsoft\Windows NT\CurrentVersion\Winlogon> with 2 values.
- --- Import KEY <\Software\Microsoft\Windows NT\CurrentVersion\Winlogon> alloc_block: failed to alloc 40 bytes, trying to expand hive..
- add_bin: request size = 40 [28], rounded to 4096 [1000]
- add_bin: old buffer size = 241664 [3b000]
- add_bin: firs nonbin off = 241664 [3b000]
- add_bin: free at end = 0 [0]
- add_bin: new buffer size = 262144 [40000]
- add_bin: adjusting size field in REGF: 241664 [3b000]
- END OF IMPORT, file </tmp/user.reg>, operation SUCCEEDED!
- 2 keys
- 0 new keys added
- 4 values total
- Hives that have changed:
- # Name
- 0 </mnt/sda1/WINDOWS/repair/ntuser.dat> - OK WARNING: File was expanded! Experimental! Use at own risk!
- Modificada clave HKEY_USERS\S-1-5-18\Software\Microsoft\Windows NT\CurrentVersion\Winlogon | Shell | Userinit
- *******************
- reged version 0.1 110511, (c) Petter N Hagen
- Hive </mnt/sda1/WINDOWS/repair/ntuser.dat> name (from header): <>
- ROOT KEY at offset: 0x001020 * Subkey indexing type is: 666c <lf>
- File size 262144 [40000] bytes, containing 59 pages (+ 1 headerpage)
- Used for data: 4188/234584 blocks/bytes, unused: 131/5192 blocks/bytes.
- --- Import KEY <\Software\Microsoft\Windows NT\CurrentVersion\Windows>
- END OF IMPORT, file </tmp/user.reg>, operation SUCCEEDED!
- 1 keys
- 0 new keys added
- 2 values total
- Hives that have changed:
- # Name
- 0 </mnt/sda1/WINDOWS/repair/ntuser.dat> - OK
- Modificada clave HKEY_USERS\S-1-5-18\Software\Microsoft\Windows NT\CurrentVersion\Windows | Load
- User: S-1-5-19
- NTUSER: /mnt/sda1/Documents and Settings/Default User/NTUSER.DAT
- *******************
- reged version 0.1 110511, (c) Petter N Hagen
- Hive </mnt/sda1/Documents and Settings/Default User/NTUSER.DAT> name (from header): <ettings\Default User\NtUser.dat>
- ROOT KEY at offset: 0x001020 * Subkey indexing type is: 666c <lf>
- File size 262144 [40000] bytes, containing 59 pages (+ 1 headerpage)
- Used for data: 4194/234976 blocks/bytes, unused: 129/4800 blocks/bytes.
- Exporting to file '/tmp/runRead.reg'...
- Exporting key 'Run' with 0 subkeys and 1 values...
- *******************
- Fichero /tmp/runRead.reg
- Windows Registry Editor Version 5.00
- [HKEY_USERS\S-1-5-19\Software\Microsoft\Windows\CurrentVersion\Run]
- "CTFMON.EXE"=""
- *******************
- Fichero /tmp/runWrite.reg
- Windows Registry Editor Version 5.00
- [HKEY_USERSS-1-5-19\Software\Microsoft\Windows\CurrentVersion\Run]
- "CTFMON.EXE"=
- *******************
- reged version 0.1 110511, (c) Petter N Hagen
- Hive </mnt/sda1/Documents and Settings/Default User/NTUSER.DAT> name (from header): <ettings\Default User\NtUser.dat>
- ROOT KEY at offset: 0x001020 * Subkey indexing type is: 666c <lf>
- File size 262144 [40000] bytes, containing 59 pages (+ 1 headerpage)
- Used for data: 4194/234976 blocks/bytes, unused: 129/4800 blocks/bytes.
- --- Import KEY <\Software\Microsoft\Windows\CurrentVersion\Run>
- END OF IMPORT, file </tmp/runWrite.reg>, operation SUCCEEDED!
- 1 keys
- 0 new keys added
- 1 values total
- Hives that have changed:
- # Name
- 0 </mnt/sda1/Documents and Settings/Default User/NTUSER.DAT> - OK
- Modificada clave HKEY_USERS\S-1-5-19\Software\Microsoft\Windows\CurrentVersion\Run | Todos los valores a vacio
- *******************
- reged version 0.1 110511, (c) Petter N Hagen
- Hive </mnt/sda1/Documents and Settings/Default User/NTUSER.DAT> name (from header): <ettings\Default User\NtUser.dat>
- ROOT KEY at offset: 0x001020 * Subkey indexing type is: 666c <lf>
- File size 262144 [40000] bytes, containing 59 pages (+ 1 headerpage)
- Used for data: 4194/234976 blocks/bytes, unused: 129/4800 blocks/bytes.
- --- Import KEY <\Software\Microsoft\Windows NT\CurrentVersion\Winlogon> with 2 values.
- --- Import KEY <\Software\Microsoft\Windows NT\CurrentVersion\Winlogon>
- END OF IMPORT, file </tmp/user.reg>, operation SUCCEEDED!
- 2 keys
- 0 new keys added
- 4 values total
- Hives that have changed:
- # Name
- 0 </mnt/sda1/Documents and Settings/Default User/NTUSER.DAT> - OK
- Modificada clave HKEY_USERS\S-1-5-19\Software\Microsoft\Windows NT\CurrentVersion\Winlogon | Shell | Userinit
- *******************
- reged version 0.1 110511, (c) Petter N Hagen
- Hive </mnt/sda1/Documents and Settings/Default User/NTUSER.DAT> name (from header): <ettings\Default User\NtUser.dat>
- ROOT KEY at offset: 0x001020 * Subkey indexing type is: 666c <lf>
- File size 262144 [40000] bytes, containing 59 pages (+ 1 headerpage)
- Used for data: 4194/234976 blocks/bytes, unused: 129/4800 blocks/bytes.
- --- Import KEY <\Software\Microsoft\Windows NT\CurrentVersion\Windows>
- END OF IMPORT, file </tmp/user.reg>, operation SUCCEEDED!
- 1 keys
- 0 new keys added
- 2 values total
- Hives that have changed:
- # Name
- 0 </mnt/sda1/Documents and Settings/Default User/NTUSER.DAT> - OK
- Modificada clave HKEY_USERS\S-1-5-19\Software\Microsoft\Windows NT\CurrentVersion\Windows | Load
- NTUSER: /mnt/sda1/Documents and Settings/LocalService/NTUSER.DAT
- *******************
- reged version 0.1 110511, (c) Petter N Hagen
- Hive </mnt/sda1/Documents and Settings/LocalService/NTUSER.DAT> name (from header): <ettings\LocalService\ntuser.dat>
- ROOT KEY at offset: 0x001020 * Subkey indexing type is: 666c <lf>
- File size 262144 [40000] bytes, containing 57 pages (+ 1 headerpage)
- Used for data: 4163/230280 blocks/bytes, unused: 144/1368 blocks/bytes.
- Exporting to file '/tmp/runRead.reg'...
- Exporting key 'Run' with 0 subkeys and 1 values...
- *******************
- Fichero /tmp/runRead.reg
- Windows Registry Editor Version 5.00
- [HKEY_USERS\S-1-5-19\Software\Microsoft\Windows\CurrentVersion\Run]
- "CTFMON.EXE"=""
- *******************
- Fichero /tmp/runWrite.reg
- Windows Registry Editor Version 5.00
- [HKEY_USERSS-1-5-19\Software\Microsoft\Windows\CurrentVersion\Run]
- "CTFMON.EXE"=
- *******************
- reged version 0.1 110511, (c) Petter N Hagen
- Hive </mnt/sda1/Documents and Settings/LocalService/NTUSER.DAT> name (from header): <ettings\LocalService\ntuser.dat>
- ROOT KEY at offset: 0x001020 * Subkey indexing type is: 666c <lf>
- File size 262144 [40000] bytes, containing 57 pages (+ 1 headerpage)
- Used for data: 4163/230280 blocks/bytes, unused: 144/1368 blocks/bytes.
- --- Import KEY <\Software\Microsoft\Windows\CurrentVersion\Run>
- END OF IMPORT, file </tmp/runWrite.reg>, operation SUCCEEDED!
- 1 keys
- 0 new keys added
- 1 values total
- Hives that have changed:
- # Name
- 0 </mnt/sda1/Documents and Settings/LocalService/NTUSER.DAT> - OK
- Modificada clave HKEY_USERS\S-1-5-19\Software\Microsoft\Windows\CurrentVersion\Run | Todos los valores a vacio
- *******************
- reged version 0.1 110511, (c) Petter N Hagen
- Hive </mnt/sda1/Documents and Settings/LocalService/NTUSER.DAT> name (from header): <ettings\LocalService\ntuser.dat>
- ROOT KEY at offset: 0x001020 * Subkey indexing type is: 666c <lf>
- File size 262144 [40000] bytes, containing 57 pages (+ 1 headerpage)
- Used for data: 4163/230280 blocks/bytes, unused: 144/1368 blocks/bytes.
- --- Import KEY <\Software\Microsoft\Windows NT\CurrentVersion\Winlogon> with 2 values.
- --- Import KEY <\Software\Microsoft\Windows NT\CurrentVersion\Winlogon>
- END OF IMPORT, file </tmp/user.reg>, operation SUCCEEDED!
- 2 keys
- 0 new keys added
- 4 values total
- Hives that have changed:
- # Name
- 0 </mnt/sda1/Documents and Settings/LocalService/NTUSER.DAT> - OK
- Modificada clave HKEY_USERS\S-1-5-19\Software\Microsoft\Windows NT\CurrentVersion\Winlogon | Shell | Userinit
- *******************
- reged version 0.1 110511, (c) Petter N Hagen
- Hive </mnt/sda1/Documents and Settings/LocalService/NTUSER.DAT> name (from header): <ettings\LocalService\ntuser.dat>
- ROOT KEY at offset: 0x001020 * Subkey indexing type is: 666c <lf>
- File size 262144 [40000] bytes, containing 57 pages (+ 1 headerpage)
- Used for data: 4163/230280 blocks/bytes, unused: 144/1368 blocks/bytes.
- --- Import KEY <\Software\Microsoft\Windows NT\CurrentVersion\Windows>
- END OF IMPORT, file </tmp/user.reg>, operation SUCCEEDED!
- 1 keys
- 0 new keys added
- 2 values total
- Hives that have changed:
- # Name
- 0 </mnt/sda1/Documents and Settings/LocalService/NTUSER.DAT> - OK
- Modificada clave HKEY_USERS\S-1-5-19\Software\Microsoft\Windows NT\CurrentVersion\Windows | Load
- NTUSER: /mnt/sda1/Documents and Settings/NetworkService/NTUSER.DAT
- *******************
- reged version 0.1 110511, (c) Petter N Hagen
- Hive </mnt/sda1/Documents and Settings/NetworkService/NTUSER.DAT> name (from header): <tings\NetworkService\ntuser.dat>
- ROOT KEY at offset: 0x001020 * Subkey indexing type is: 666c <lf>
- File size 303104 [4a000] bytes, containing 57 pages (+ 1 headerpage)
- Used for data: 4131/294808 blocks/bytes, unused: 133/2376 blocks/bytes.
- Exporting to file '/tmp/runRead.reg'...
- Exporting key 'Run' with 0 subkeys and 1 values...
- *******************
- Fichero /tmp/runRead.reg
- Windows Registry Editor Version 5.00
- [HKEY_USERS\S-1-5-19\Software\Microsoft\Windows\CurrentVersion\Run]
- "CTFMON.EXE"=""
- *******************
- Fichero /tmp/runWrite.reg
- Windows Registry Editor Version 5.00
- [HKEY_USERSS-1-5-19\Software\Microsoft\Windows\CurrentVersion\Run]
- "CTFMON.EXE"=
- *******************
- reged version 0.1 110511, (c) Petter N Hagen
- Hive </mnt/sda1/Documents and Settings/NetworkService/NTUSER.DAT> name (from header): <tings\NetworkService\ntuser.dat>
- ROOT KEY at offset: 0x001020 * Subkey indexing type is: 666c <lf>
- File size 303104 [4a000] bytes, containing 57 pages (+ 1 headerpage)
- Used for data: 4131/294808 blocks/bytes, unused: 133/2376 blocks/bytes.
- --- Import KEY <\Software\Microsoft\Windows\CurrentVersion\Run>
- END OF IMPORT, file </tmp/runWrite.reg>, operation SUCCEEDED!
- 1 keys
- 0 new keys added
- 1 values total
- Hives that have changed:
- # Name
- 0 </mnt/sda1/Documents and Settings/NetworkService/NTUSER.DAT> - OK
- Modificada clave HKEY_USERS\S-1-5-19\Software\Microsoft\Windows\CurrentVersion\Run | Todos los valores a vacio
- *******************
- reged version 0.1 110511, (c) Petter N Hagen
- Hive </mnt/sda1/Documents and Settings/NetworkService/NTUSER.DAT> name (from header): <tings\NetworkService\ntuser.dat>
- ROOT KEY at offset: 0x001020 * Subkey indexing type is: 666c <lf>
- File size 303104 [4a000] bytes, containing 57 pages (+ 1 headerpage)
- Used for data: 4131/294808 blocks/bytes, unused: 133/2376 blocks/bytes.
- --- Import KEY <\Software\Microsoft\Windows NT\CurrentVersion\Winlogon> with 2 values.
- --- Import KEY <\Software\Microsoft\Windows NT\CurrentVersion\Winlogon>
- END OF IMPORT, file </tmp/user.reg>, operation SUCCEEDED!
- 2 keys
- 0 new keys added
- 4 values total
- Hives that have changed:
- # Name
- 0 </mnt/sda1/Documents and Settings/NetworkService/NTUSER.DAT> - OK
- Modificada clave HKEY_USERS\S-1-5-19\Software\Microsoft\Windows NT\CurrentVersion\Winlogon | Shell | Userinit
- *******************
- reged version 0.1 110511, (c) Petter N Hagen
- Hive </mnt/sda1/Documents and Settings/NetworkService/NTUSER.DAT> name (from header): <tings\NetworkService\ntuser.dat>
- ROOT KEY at offset: 0x001020 * Subkey indexing type is: 666c <lf>
- File size 303104 [4a000] bytes, containing 57 pages (+ 1 headerpage)
- Used for data: 4131/294808 blocks/bytes, unused: 133/2376 blocks/bytes.
- --- Import KEY <\Software\Microsoft\Windows NT\CurrentVersion\Windows>
- END OF IMPORT, file </tmp/user.reg>, operation SUCCEEDED!
- 1 keys
- 0 new keys added
- 2 values total
- Hives that have changed:
- # Name
- 0 </mnt/sda1/Documents and Settings/NetworkService/NTUSER.DAT> - OK
- Modificada clave HKEY_USERS\S-1-5-19\Software\Microsoft\Windows NT\CurrentVersion\Windows | Load
- NTUSER: /mnt/sda1/Documents and Settings/vinagreta/NTUSER.DAT
- *******************
- reged version 0.1 110511, (c) Petter N Hagen
- Hive </mnt/sda1/Documents and Settings/vinagreta/NTUSER.DAT> name (from header): <d Settings\vinagreta\ntuser.dat>
- ROOT KEY at offset: 0x001020 * Subkey indexing type is: 666c <lf>
- File size 6029312 [5c0000] bytes, containing 1100 pages (+ 1 headerpage)
- Used for data: 99154/5792328 blocks/bytes, unused: 6567/140344 blocks/bytes.
- Exporting to file '/tmp/runRead.reg'...
- Exporting key 'Run' with 0 subkeys and 1 values...
- *******************
- Fichero /tmp/runRead.reg
- Windows Registry Editor Version 5.00
- [HKEY_USERS\S-1-5-19\Software\Microsoft\Windows\CurrentVersion\Run]
- "ctfmon.exe"=""
- *******************
- Fichero /tmp/runWrite.reg
- Windows Registry Editor Version 5.00
- [HKEY_USERSS-1-5-19\Software\Microsoft\Windows\CurrentVersion\Run]
- "ctfmon.exe"=
- *******************
- reged version 0.1 110511, (c) Petter N Hagen
- Hive </mnt/sda1/Documents and Settings/vinagreta/NTUSER.DAT> name (from header): <d Settings\vinagreta\ntuser.dat>
- ROOT KEY at offset: 0x001020 * Subkey indexing type is: 666c <lf>
- File size 6029312 [5c0000] bytes, containing 1100 pages (+ 1 headerpage)
- Used for data: 99154/5792328 blocks/bytes, unused: 6567/140344 blocks/bytes.
- --- Import KEY <\Software\Microsoft\Windows\CurrentVersion\Run>
- END OF IMPORT, file </tmp/runWrite.reg>, operation SUCCEEDED!
- 1 keys
- 0 new keys added
- 1 values total
- Hives that have changed:
- # Name
- 0 </mnt/sda1/Documents and Settings/vinagreta/NTUSER.DAT> - OK
- Modificada clave HKEY_USERS\S-1-5-19\Software\Microsoft\Windows\CurrentVersion\Run | Todos los valores a vacio
- *******************
- reged version 0.1 110511, (c) Petter N Hagen
- Hive </mnt/sda1/Documents and Settings/vinagreta/NTUSER.DAT> name (from header): <d Settings\vinagreta\ntuser.dat>
- ROOT KEY at offset: 0x001020 * Subkey indexing type is: 666c <lf>
- File size 6029312 [5c0000] bytes, containing 1100 pages (+ 1 headerpage)
- Used for data: 99154/5792328 blocks/bytes, unused: 6567/140344 blocks/bytes.
- --- Import KEY <\Software\Microsoft\Windows NT\CurrentVersion\Winlogon> with 2 values.
- --- Import KEY <\Software\Microsoft\Windows NT\CurrentVersion\Winlogon>
- END OF IMPORT, file </tmp/user.reg>, operation SUCCEEDED!
- 2 keys
- 0 new keys added
- 4 values total
- Hives that have changed:
- # Name
- 0 </mnt/sda1/Documents and Settings/vinagreta/NTUSER.DAT> - OK
- Modificada clave HKEY_USERS\S-1-5-19\Software\Microsoft\Windows NT\CurrentVersion\Winlogon | Shell | Userinit
- *******************
- reged version 0.1 110511, (c) Petter N Hagen
- Hive </mnt/sda1/Documents and Settings/vinagreta/NTUSER.DAT> name (from header): <d Settings\vinagreta\ntuser.dat>
- ROOT KEY at offset: 0x001020 * Subkey indexing type is: 666c <lf>
- File size 6029312 [5c0000] bytes, containing 1100 pages (+ 1 headerpage)
- Used for data: 99154/5792328 blocks/bytes, unused: 6567/140344 blocks/bytes.
- --- Import KEY <\Software\Microsoft\Windows NT\CurrentVersion\Windows>
- END OF IMPORT, file </tmp/user.reg>, operation SUCCEEDED!
- 1 keys
- 0 new keys added
- 2 values total
- Hives that have changed:
- # Name
- 0 </mnt/sda1/Documents and Settings/vinagreta/NTUSER.DAT> - OK
- Modificada clave HKEY_USERS\S-1-5-19\Software\Microsoft\Windows NT\CurrentVersion\Windows | Load
- NTUSER: /mnt/sda1/WINDOWS/system32/config/systemprofile/NtUser.dat
- *******************
- reged version 0.1 110511, (c) Petter N Hagen
- Hive </mnt/sda1/WINDOWS/system32/config/systemprofile/NtUser.dat> name (from header): <em32\config\SYSTEM~1\NtUser.dat>
- ROOT KEY at offset: 0x001020 * Subkey indexing type is: 666c <lf>
- File size 262144 [40000] bytes, containing 1 pages (+ 1 headerpage)
- Used for data: 21/1240 blocks/bytes, unused: 5/2824 blocks/bytes.
- Exporting to file '/tmp/runRead.reg'...
- export_subkey: Key 'Software\Microsoft\Windows\CurrentVersion\Run' not found!
- *******************
- Fichero /tmp/runRead.reg
- Windows Registry Editor Version 5.00
- *******************
- Fichero /tmp/runWrite.reg
- Windows Registry Editor Version 5.00
- *******************
- reged version 0.1 110511, (c) Petter N Hagen
- Hive </mnt/sda1/WINDOWS/system32/config/systemprofile/NtUser.dat> name (from header): <em32\config\SYSTEM~1\NtUser.dat>
- ROOT KEY at offset: 0x001020 * Subkey indexing type is: 666c <lf>
- File size 262144 [40000] bytes, containing 1 pages (+ 1 headerpage)
- Used for data: 21/1240 blocks/bytes, unused: 5/2824 blocks/bytes.
- END OF IMPORT, file </tmp/runWrite.reg>, operation SUCCEEDED!
- 0 keys
- 0 new keys added
- 0 values total
- Hives that have changed:
- # Name
- None!
- Modificada clave HKEY_USERS\S-1-5-19\Software\Microsoft\Windows\CurrentVersion\Run | Todos los valores a vacio
- *******************
- reged version 0.1 110511, (c) Petter N Hagen
- Hive </mnt/sda1/WINDOWS/system32/config/systemprofile/NtUser.dat> name (from header): <em32\config\SYSTEM~1\NtUser.dat>
- ROOT KEY at offset: 0x001020 * Subkey indexing type is: 666c <lf>
- File size 262144 [40000] bytes, containing 1 pages (+ 1 headerpage)
- Used for data: 21/1240 blocks/bytes, unused: 5/2824 blocks/bytes.
- --- Import KEY <\Software\Microsoft\Windows NT\CurrentVersion\Winlogon> with 2 values.
- --- Import KEY <\Software\Microsoft\Windows NT\CurrentVersion\Winlogon>
- END OF IMPORT, file </tmp/user.reg>, operation SUCCEEDED!
- 2 keys
- 0 new keys added
- 4 values total
- Hives that have changed:
- # Name
- 0 </mnt/sda1/WINDOWS/system32/config/systemprofile/NtUser.dat> - OK
- Modificada clave HKEY_USERS\S-1-5-19\Software\Microsoft\Windows NT\CurrentVersion\Winlogon | Shell | Userinit
- *******************
- reged version 0.1 110511, (c) Petter N Hagen
- Hive </mnt/sda1/WINDOWS/system32/config/systemprofile/NtUser.dat> name (from header): <em32\config\SYSTEM~1\NtUser.dat>
- ROOT KEY at offset: 0x001020 * Subkey indexing type is: 666c <lf>
- File size 262144 [40000] bytes, containing 1 pages (+ 1 headerpage)
- Used for data: 21/1240 blocks/bytes, unused: 5/2824 blocks/bytes.
- --- Import KEY <\Software\Microsoft\Windows NT\CurrentVersion\Windows>
- END OF IMPORT, file </tmp/user.reg>, operation SUCCEEDED!
- 1 keys
- 0 new keys added
- 2 values total
- Hives that have changed:
- # Name
- 0 </mnt/sda1/WINDOWS/system32/config/systemprofile/NtUser.dat> - OK
- Modificada clave HKEY_USERS\S-1-5-19\Software\Microsoft\Windows NT\CurrentVersion\Windows | Load
- NTUSER: /mnt/sda1/WINDOWS/repair/ntuser.dat
- *******************
- reged version 0.1 110511, (c) Petter N Hagen
- Hive </mnt/sda1/WINDOWS/repair/ntuser.dat> name (from header): <>
- ROOT KEY at offset: 0x001020 * Subkey indexing type is: 666c <lf>
- File size 262144 [40000] bytes, containing 59 pages (+ 1 headerpage)
- Used for data: 4189/234624 blocks/bytes, unused: 132/5152 blocks/bytes.
- Exporting to file '/tmp/runRead.reg'...
- Exporting key 'Run' with 0 subkeys and 1 values...
- *******************
- Fichero /tmp/runRead.reg
- Windows Registry Editor Version 5.00
- [HKEY_USERS\S-1-5-19\Software\Microsoft\Windows\CurrentVersion\Run]
- "CTFMON.EXE"=""
- *******************
- Fichero /tmp/runWrite.reg
- Windows Registry Editor Version 5.00
- [HKEY_USERSS-1-5-19\Software\Microsoft\Windows\CurrentVersion\Run]
- "CTFMON.EXE"=
- *******************
- reged version 0.1 110511, (c) Petter N Hagen
- Hive </mnt/sda1/WINDOWS/repair/ntuser.dat> name (from header): <>
- ROOT KEY at offset: 0x001020 * Subkey indexing type is: 666c <lf>
- File size 262144 [40000] bytes, containing 59 pages (+ 1 headerpage)
- Used for data: 4189/234624 blocks/bytes, unused: 132/5152 blocks/bytes.
- --- Import KEY <\Software\Microsoft\Windows\CurrentVersion\Run>
- END OF IMPORT, file </tmp/runWrite.reg>, operation SUCCEEDED!
- 1 keys
- 0 new keys added
- 1 values total
- Hives that have changed:
- # Name
- 0 </mnt/sda1/WINDOWS/repair/ntuser.dat> - OK
- Modificada clave HKEY_USERS\S-1-5-19\Software\Microsoft\Windows\CurrentVersion\Run | Todos los valores a vacio
- *******************
- reged version 0.1 110511, (c) Petter N Hagen
- Hive </mnt/sda1/WINDOWS/repair/ntuser.dat> name (from header): <>
- ROOT KEY at offset: 0x001020 * Subkey indexing type is: 666c <lf>
- File size 262144 [40000] bytes, containing 59 pages (+ 1 headerpage)
- Used for data: 4189/234624 blocks/bytes, unused: 132/5152 blocks/bytes.
- --- Import KEY <\Software\Microsoft\Windows NT\CurrentVersion\Winlogon> with 2 values.
- --- Import KEY <\Software\Microsoft\Windows NT\CurrentVersion\Winlogon>
- END OF IMPORT, file </tmp/user.reg>, operation SUCCEEDED!
- 2 keys
- 0 new keys added
- 4 values total
- Hives that have changed:
- # Name
- 0 </mnt/sda1/WINDOWS/repair/ntuser.dat> - OK
- Modificada clave HKEY_USERS\S-1-5-19\Software\Microsoft\Windows NT\CurrentVersion\Winlogon | Shell | Userinit
- *******************
- reged version 0.1 110511, (c) Petter N Hagen
- Hive </mnt/sda1/WINDOWS/repair/ntuser.dat> name (from header): <>
- ROOT KEY at offset: 0x001020 * Subkey indexing type is: 666c <lf>
- File size 262144 [40000] bytes, containing 59 pages (+ 1 headerpage)
- Used for data: 4189/234624 blocks/bytes, unused: 132/5152 blocks/bytes.
- --- Import KEY <\Software\Microsoft\Windows NT\CurrentVersion\Windows>
- END OF IMPORT, file </tmp/user.reg>, operation SUCCEEDED!
- 1 keys
- 0 new keys added
- 2 values total
- Hives that have changed:
- # Name
- 0 </mnt/sda1/WINDOWS/repair/ntuser.dat> - OK
- Modificada clave HKEY_USERS\S-1-5-19\Software\Microsoft\Windows NT\CurrentVersion\Windows | Load
- User: S-1-5-20
- NTUSER: /mnt/sda1/Documents and Settings/Default User/NTUSER.DAT
- *******************
- reged version 0.1 110511, (c) Petter N Hagen
- Hive </mnt/sda1/Documents and Settings/Default User/NTUSER.DAT> name (from header): <ettings\Default User\NtUser.dat>
- ROOT KEY at offset: 0x001020 * Subkey indexing type is: 666c <lf>
- File size 262144 [40000] bytes, containing 59 pages (+ 1 headerpage)
- Used for data: 4194/234976 blocks/bytes, unused: 129/4800 blocks/bytes.
- Exporting to file '/tmp/runRead.reg'...
- Exporting key 'Run' with 0 subkeys and 1 values...
- *******************
- Fichero /tmp/runRead.reg
- Windows Registry Editor Version 5.00
- [HKEY_USERS\S-1-5-20\Software\Microsoft\Windows\CurrentVersion\Run]
- "CTFMON.EXE"=""
- *******************
- Fichero /tmp/runWrite.reg
- Windows Registry Editor Version 5.00
- [HKEY_USERSS-1-5-20\Software\Microsoft\Windows\CurrentVersion\Run]
- "CTFMON.EXE"=
- *******************
- reged version 0.1 110511, (c) Petter N Hagen
- Hive </mnt/sda1/Documents and Settings/Default User/NTUSER.DAT> name (from header): <ettings\Default User\NtUser.dat>
- ROOT KEY at offset: 0x001020 * Subkey indexing type is: 666c <lf>
- File size 262144 [40000] bytes, containing 59 pages (+ 1 headerpage)
- Used for data: 4194/234976 blocks/bytes, unused: 129/4800 blocks/bytes.
- --- Import KEY <\Software\Microsoft\Windows\CurrentVersion\Run>
- END OF IMPORT, file </tmp/runWrite.reg>, operation SUCCEEDED!
- 1 keys
- 0 new keys added
- 1 values total
- Hives that have changed:
- # Name
- 0 </mnt/sda1/Documents and Settings/Default User/NTUSER.DAT> - OK
- Modificada clave HKEY_USERS\S-1-5-20\Software\Microsoft\Windows\CurrentVersion\Run | Todos los valores a vacio
- *******************
- reged version 0.1 110511, (c) Petter N Hagen
- Hive </mnt/sda1/Documents and Settings/Default User/NTUSER.DAT> name (from header): <ettings\Default User\NtUser.dat>
- ROOT KEY at offset: 0x001020 * Subkey indexing type is: 666c <lf>
- File size 262144 [40000] bytes, containing 59 pages (+ 1 headerpage)
- Used for data: 4194/234976 blocks/bytes, unused: 129/4800 blocks/bytes.
- --- Import KEY <\Software\Microsoft\Windows NT\CurrentVersion\Winlogon> with 2 values.
- --- Import KEY <\Software\Microsoft\Windows NT\CurrentVersion\Winlogon>
- END OF IMPORT, file </tmp/user.reg>, operation SUCCEEDED!
- 2 keys
- 0 new keys added
- 4 values total
- Hives that have changed:
- # Name
- 0 </mnt/sda1/Documents and Settings/Default User/NTUSER.DAT> - OK
- Modificada clave HKEY_USERS\S-1-5-20\Software\Microsoft\Windows NT\CurrentVersion\Winlogon | Shell | Userinit
- *******************
- reged version 0.1 110511, (c) Petter N Hagen
- Hive </mnt/sda1/Documents and Settings/Default User/NTUSER.DAT> name (from header): <ettings\Default User\NtUser.dat>
- ROOT KEY at offset: 0x001020 * Subkey indexing type is: 666c <lf>
- File size 262144 [40000] bytes, containing 59 pages (+ 1 headerpage)
- Used for data: 4194/234976 blocks/bytes, unused: 129/4800 blocks/bytes.
- --- Import KEY <\Software\Microsoft\Windows NT\CurrentVersion\Windows>
- END OF IMPORT, file </tmp/user.reg>, operation SUCCEEDED!
- 1 keys
- 0 new keys added
- 2 values total
- Hives that have changed:
- # Name
- 0 </mnt/sda1/Documents and Settings/Default User/NTUSER.DAT> - OK
- Modificada clave HKEY_USERS\S-1-5-20\Software\Microsoft\Windows NT\CurrentVersion\Windows | Load
- NTUSER: /mnt/sda1/Documents and Settings/LocalService/NTUSER.DAT
- *******************
- reged version 0.1 110511, (c) Petter N Hagen
- Hive </mnt/sda1/Documents and Settings/LocalService/NTUSER.DAT> name (from header): <ettings\LocalService\ntuser.dat>
- ROOT KEY at offset: 0x001020 * Subkey indexing type is: 666c <lf>
- File size 262144 [40000] bytes, containing 57 pages (+ 1 headerpage)
- Used for data: 4163/230280 blocks/bytes, unused: 144/1368 blocks/bytes.
- Exporting to file '/tmp/runRead.reg'...
- Exporting key 'Run' with 0 subkeys and 1 values...
- *******************
- Fichero /tmp/runRead.reg
- Windows Registry Editor Version 5.00
- [HKEY_USERS\S-1-5-20\Software\Microsoft\Windows\CurrentVersion\Run]
- "CTFMON.EXE"=""
- *******************
- Fichero /tmp/runWrite.reg
- Windows Registry Editor Version 5.00
- [HKEY_USERSS-1-5-20\Software\Microsoft\Windows\CurrentVersion\Run]
- "CTFMON.EXE"=
- *******************
- reged version 0.1 110511, (c) Petter N Hagen
- Hive </mnt/sda1/Documents and Settings/LocalService/NTUSER.DAT> name (from header): <ettings\LocalService\ntuser.dat>
- ROOT KEY at offset: 0x001020 * Subkey indexing type is: 666c <lf>
- File size 262144 [40000] bytes, containing 57 pages (+ 1 headerpage)
- Used for data: 4163/230280 blocks/bytes, unused: 144/1368 blocks/bytes.
- --- Import KEY <\Software\Microsoft\Windows\CurrentVersion\Run>
- END OF IMPORT, file </tmp/runWrite.reg>, operation SUCCEEDED!
- 1 keys
- 0 new keys added
- 1 values total
- Hives that have changed:
- # Name
- 0 </mnt/sda1/Documents and Settings/LocalService/NTUSER.DAT> - OK
- Modificada clave HKEY_USERS\S-1-5-20\Software\Microsoft\Windows\CurrentVersion\Run | Todos los valores a vacio
- *******************
- reged version 0.1 110511, (c) Petter N Hagen
- Hive </mnt/sda1/Documents and Settings/LocalService/NTUSER.DAT> name (from header): <ettings\LocalService\ntuser.dat>
- ROOT KEY at offset: 0x001020 * Subkey indexing type is: 666c <lf>
- File size 262144 [40000] bytes, containing 57 pages (+ 1 headerpage)
- Used for data: 4163/230280 blocks/bytes, unused: 144/1368 blocks/bytes.
- --- Import KEY <\Software\Microsoft\Windows NT\CurrentVersion\Winlogon> with 2 values.
- --- Import KEY <\Software\Microsoft\Windows NT\CurrentVersion\Winlogon>
- END OF IMPORT, file </tmp/user.reg>, operation SUCCEEDED!
- 2 keys
- 0 new keys added
- 4 values total
- Hives that have changed:
- # Name
- 0 </mnt/sda1/Documents and Settings/LocalService/NTUSER.DAT> - OK
- Modificada clave HKEY_USERS\S-1-5-20\Software\Microsoft\Windows NT\CurrentVersion\Winlogon | Shell | Userinit
- *******************
- reged version 0.1 110511, (c) Petter N Hagen
- Hive </mnt/sda1/Documents and Settings/LocalService/NTUSER.DAT> name (from header): <ettings\LocalService\ntuser.dat>
- ROOT KEY at offset: 0x001020 * Subkey indexing type is: 666c <lf>
- File size 262144 [40000] bytes, containing 57 pages (+ 1 headerpage)
- Used for data: 4163/230280 blocks/bytes, unused: 144/1368 blocks/bytes.
- --- Import KEY <\Software\Microsoft\Windows NT\CurrentVersion\Windows>
- END OF IMPORT, file </tmp/user.reg>, operation SUCCEEDED!
- 1 keys
- 0 new keys added
- 2 values total
- Hives that have changed:
- # Name
- 0 </mnt/sda1/Documents and Settings/LocalService/NTUSER.DAT> - OK
- Modificada clave HKEY_USERS\S-1-5-20\Software\Microsoft\Windows NT\CurrentVersion\Windows | Load
- NTUSER: /mnt/sda1/Documents and Settings/NetworkService/NTUSER.DAT
- *******************
- reged version 0.1 110511, (c) Petter N Hagen
- Hive </mnt/sda1/Documents and Settings/NetworkService/NTUSER.DAT> name (from header): <tings\NetworkService\ntuser.dat>
- ROOT KEY at offset: 0x001020 * Subkey indexing type is: 666c <lf>
- File size 303104 [4a000] bytes, containing 57 pages (+ 1 headerpage)
- Used for data: 4131/294808 blocks/bytes, unused: 133/2376 blocks/bytes.
- Exporting to file '/tmp/runRead.reg'...
- Exporting key 'Run' with 0 subkeys and 1 values...
- *******************
- Fichero /tmp/runRead.reg
- Windows Registry Editor Version 5.00
- [HKEY_USERS\S-1-5-20\Software\Microsoft\Windows\CurrentVersion\Run]
- "CTFMON.EXE"=""
- *******************
- Fichero /tmp/runWrite.reg
- Windows Registry Editor Version 5.00
- [HKEY_USERSS-1-5-20\Software\Microsoft\Windows\CurrentVersion\Run]
- "CTFMON.EXE"=
- *******************
- reged version 0.1 110511, (c) Petter N Hagen
- Hive </mnt/sda1/Documents and Settings/NetworkService/NTUSER.DAT> name (from header): <tings\NetworkService\ntuser.dat>
- ROOT KEY at offset: 0x001020 * Subkey indexing type is: 666c <lf>
- File size 303104 [4a000] bytes, containing 57 pages (+ 1 headerpage)
- Used for data: 4131/294808 blocks/bytes, unused: 133/2376 blocks/bytes.
- --- Import KEY <\Software\Microsoft\Windows\CurrentVersion\Run>
- END OF IMPORT, file </tmp/runWrite.reg>, operation SUCCEEDED!
- 1 keys
- 0 new keys added
- 1 values total
- Hives that have changed:
- # Name
- 0 </mnt/sda1/Documents and Settings/NetworkService/NTUSER.DAT> - OK
- Modificada clave HKEY_USERS\S-1-5-20\Software\Microsoft\Windows\CurrentVersion\Run | Todos los valores a vacio
- *******************
- reged version 0.1 110511, (c) Petter N Hagen
- Hive </mnt/sda1/Documents and Settings/NetworkService/NTUSER.DAT> name (from header): <tings\NetworkService\ntuser.dat>
- ROOT KEY at offset: 0x001020 * Subkey indexing type is: 666c <lf>
- File size 303104 [4a000] bytes, containing 57 pages (+ 1 headerpage)
- Used for data: 4131/294808 blocks/bytes, unused: 133/2376 blocks/bytes.
- --- Import KEY <\Software\Microsoft\Windows NT\CurrentVersion\Winlogon> with 2 values.
- --- Import KEY <\Software\Microsoft\Windows NT\CurrentVersion\Winlogon>
- END OF IMPORT, file </tmp/user.reg>, operation SUCCEEDED!
- 2 keys
- 0 new keys added
- 4 values total
- Hives that have changed:
- # Name
- 0 </mnt/sda1/Documents and Settings/NetworkService/NTUSER.DAT> - OK
- Modificada clave HKEY_USERS\S-1-5-20\Software\Microsoft\Windows NT\CurrentVersion\Winlogon | Shell | Userinit
- *******************
- reged version 0.1 110511, (c) Petter N Hagen
- Hive </mnt/sda1/Documents and Settings/NetworkService/NTUSER.DAT> name (from header): <tings\NetworkService\ntuser.dat>
- ROOT KEY at offset: 0x001020 * Subkey indexing type is: 666c <lf>
- File size 303104 [4a000] bytes, containing 57 pages (+ 1 headerpage)
- Used for data: 4131/294808 blocks/bytes, unused: 133/2376 blocks/bytes.
- --- Import KEY <\Software\Microsoft\Windows NT\CurrentVersion\Windows>
- END OF IMPORT, file </tmp/user.reg>, operation SUCCEEDED!
- 1 keys
- 0 new keys added
- 2 values total
- Hives that have changed:
- # Name
- 0 </mnt/sda1/Documents and Settings/NetworkService/NTUSER.DAT> - OK
- Modificada clave HKEY_USERS\S-1-5-20\Software\Microsoft\Windows NT\CurrentVersion\Windows | Load
- NTUSER: /mnt/sda1/Documents and Settings/vinagreta/NTUSER.DAT
- *******************
- reged version 0.1 110511, (c) Petter N Hagen
- Hive </mnt/sda1/Documents and Settings/vinagreta/NTUSER.DAT> name (from header): <d Settings\vinagreta\ntuser.dat>
- ROOT KEY at offset: 0x001020 * Subkey indexing type is: 666c <lf>
- File size 6029312 [5c0000] bytes, containing 1100 pages (+ 1 headerpage)
- Used for data: 99154/5792328 blocks/bytes, unused: 6567/140344 blocks/bytes.
- Exporting to file '/tmp/runRead.reg'...
- Exporting key 'Run' with 0 subkeys and 1 values...
- *******************
- Fichero /tmp/runRead.reg
- Windows Registry Editor Version 5.00
- [HKEY_USERS\S-1-5-20\Software\Microsoft\Windows\CurrentVersion\Run]
- "ctfmon.exe"=""
- *******************
- Fichero /tmp/runWrite.reg
- Windows Registry Editor Version 5.00
- [HKEY_USERSS-1-5-20\Software\Microsoft\Windows\CurrentVersion\Run]
- "ctfmon.exe"=
- *******************
- reged version 0.1 110511, (c) Petter N Hagen
- Hive </mnt/sda1/Documents and Settings/vinagreta/NTUSER.DAT> name (from header): <d Settings\vinagreta\ntuser.dat>
- ROOT KEY at offset: 0x001020 * Subkey indexing type is: 666c <lf>
- File size 6029312 [5c0000] bytes, containing 1100 pages (+ 1 headerpage)
- Used for data: 99154/5792328 blocks/bytes, unused: 6567/140344 blocks/bytes.
- --- Import KEY <\Software\Microsoft\Windows\CurrentVersion\Run>
- END OF IMPORT, file </tmp/runWrite.reg>, operation SUCCEEDED!
- 1 keys
- 0 new keys added
- 1 values total
- Hives that have changed:
- # Name
- 0 </mnt/sda1/Documents and Settings/vinagreta/NTUSER.DAT> - OK
- Modificada clave HKEY_USERS\S-1-5-20\Software\Microsoft\Windows\CurrentVersion\Run | Todos los valores a vacio
- *******************
- reged version 0.1 110511, (c) Petter N Hagen
- Hive </mnt/sda1/Documents and Settings/vinagreta/NTUSER.DAT> name (from header): <d Settings\vinagreta\ntuser.dat>
- ROOT KEY at offset: 0x001020 * Subkey indexing type is: 666c <lf>
- File size 6029312 [5c0000] bytes, containing 1100 pages (+ 1 headerpage)
- Used for data: 99154/5792328 blocks/bytes, unused: 6567/140344 blocks/bytes.
- --- Import KEY <\Software\Microsoft\Windows NT\CurrentVersion\Winlogon> with 2 values.
- --- Import KEY <\Software\Microsoft\Windows NT\CurrentVersion\Winlogon>
- END OF IMPORT, file </tmp/user.reg>, operation SUCCEEDED!
- 2 keys
- 0 new keys added
- 4 values total
- Hives that have changed:
- # Name
- 0 </mnt/sda1/Documents and Settings/vinagreta/NTUSER.DAT> - OK
- Modificada clave HKEY_USERS\S-1-5-20\Software\Microsoft\Windows NT\CurrentVersion\Winlogon | Shell | Userinit
- *******************
- reged version 0.1 110511, (c) Petter N Hagen
- Hive </mnt/sda1/Documents and Settings/vinagreta/NTUSER.DAT> name (from header): <d Settings\vinagreta\ntuser.dat>
- ROOT KEY at offset: 0x001020 * Subkey indexing type is: 666c <lf>
- File size 6029312 [5c0000] bytes, containing 1100 pages (+ 1 headerpage)
- Used for data: 99154/5792328 blocks/bytes, unused: 6567/140344 blocks/bytes.
- --- Import KEY <\Software\Microsoft\Windows NT\CurrentVersion\Windows>
- END OF IMPORT, file </tmp/user.reg>, operation SUCCEEDED!
- 1 keys
- 0 new keys added
- 2 values total
- Hives that have changed:
- # Name
- 0 </mnt/sda1/Documents and Settings/vinagreta/NTUSER.DAT> - OK
- Modificada clave HKEY_USERS\S-1-5-20\Software\Microsoft\Windows NT\CurrentVersion\Windows | Load
- NTUSER: /mnt/sda1/WINDOWS/system32/config/systemprofile/NtUser.dat
- *******************
- reged version 0.1 110511, (c) Petter N Hagen
- Hive </mnt/sda1/WINDOWS/system32/config/systemprofile/NtUser.dat> name (from header): <em32\config\SYSTEM~1\NtUser.dat>
- ROOT KEY at offset: 0x001020 * Subkey indexing type is: 666c <lf>
- File size 262144 [40000] bytes, containing 1 pages (+ 1 headerpage)
- Used for data: 21/1240 blocks/bytes, unused: 5/2824 blocks/bytes.
- Exporting to file '/tmp/runRead.reg'...
- export_subkey: Key 'Software\Microsoft\Windows\CurrentVersion\Run' not found!
- *******************
- Fichero /tmp/runRead.reg
- Windows Registry Editor Version 5.00
- *******************
- Fichero /tmp/runWrite.reg
- Windows Registry Editor Version 5.00
- *******************
- reged version 0.1 110511, (c) Petter N Hagen
- Hive </mnt/sda1/WINDOWS/system32/config/systemprofile/NtUser.dat> name (from header): <em32\config\SYSTEM~1\NtUser.dat>
- ROOT KEY at offset: 0x001020 * Subkey indexing type is: 666c <lf>
- File size 262144 [40000] bytes, containing 1 pages (+ 1 headerpage)
- Used for data: 21/1240 blocks/bytes, unused: 5/2824 blocks/bytes.
- END OF IMPORT, file </tmp/runWrite.reg>, operation SUCCEEDED!
- 0 keys
- 0 new keys added
- 0 values total
- Hives that have changed:
- # Name
- None!
- Modificada clave HKEY_USERS\S-1-5-20\Software\Microsoft\Windows\CurrentVersion\Run | Todos los valores a vacio
- *******************
- reged version 0.1 110511, (c) Petter N Hagen
- Hive </mnt/sda1/WINDOWS/system32/config/systemprofile/NtUser.dat> name (from header): <em32\config\SYSTEM~1\NtUser.dat>
- ROOT KEY at offset: 0x001020 * Subkey indexing type is: 666c <lf>
- File size 262144 [40000] bytes, containing 1 pages (+ 1 headerpage)
- Used for data: 21/1240 blocks/bytes, unused: 5/2824 blocks/bytes.
- --- Import KEY <\Software\Microsoft\Windows NT\CurrentVersion\Winlogon> with 2 values.
- --- Import KEY <\Software\Microsoft\Windows NT\CurrentVersion\Winlogon>
- END OF IMPORT, file </tmp/user.reg>, operation SUCCEEDED!
- 2 keys
- 0 new keys added
- 4 values total
- Hives that have changed:
- # Name
- 0 </mnt/sda1/WINDOWS/system32/config/systemprofile/NtUser.dat> - OK
- Modificada clave HKEY_USERS\S-1-5-20\Software\Microsoft\Windows NT\CurrentVersion\Winlogon | Shell | Userinit
- *******************
- reged version 0.1 110511, (c) Petter N Hagen
- Hive </mnt/sda1/WINDOWS/system32/config/systemprofile/NtUser.dat> name (from header): <em32\config\SYSTEM~1\NtUser.dat>
- ROOT KEY at offset: 0x001020 * Subkey indexing type is: 666c <lf>
- File size 262144 [40000] bytes, containing 1 pages (+ 1 headerpage)
- Used for data: 21/1240 blocks/bytes, unused: 5/2824 blocks/bytes.
- --- Import KEY <\Software\Microsoft\Windows NT\CurrentVersion\Windows>
- END OF IMPORT, file </tmp/user.reg>, operation SUCCEEDED!
- 1 keys
- 0 new keys added
- 2 values total
- Hives that have changed:
- # Name
- 0 </mnt/sda1/WINDOWS/system32/config/systemprofile/NtUser.dat> - OK
- Modificada clave HKEY_USERS\S-1-5-20\Software\Microsoft\Windows NT\CurrentVersion\Windows | Load
- NTUSER: /mnt/sda1/WINDOWS/repair/ntuser.dat
- *******************
- reged version 0.1 110511, (c) Petter N Hagen
- Hive </mnt/sda1/WINDOWS/repair/ntuser.dat> name (from header): <>
- ROOT KEY at offset: 0x001020 * Subkey indexing type is: 666c <lf>
- File size 262144 [40000] bytes, containing 59 pages (+ 1 headerpage)
- Used for data: 4189/234624 blocks/bytes, unused: 132/5152 blocks/bytes.
- Exporting to file '/tmp/runRead.reg'...
- Exporting key 'Run' with 0 subkeys and 1 values...
- *******************
- Fichero /tmp/runRead.reg
- Windows Registry Editor Version 5.00
- [HKEY_USERS\S-1-5-20\Software\Microsoft\Windows\CurrentVersion\Run]
- "CTFMON.EXE"=""
- *******************
- Fichero /tmp/runWrite.reg
- Windows Registry Editor Version 5.00
- [HKEY_USERSS-1-5-20\Software\Microsoft\Windows\CurrentVersion\Run]
- "CTFMON.EXE"=
- *******************
- reged version 0.1 110511, (c) Petter N Hagen
- Hive </mnt/sda1/WINDOWS/repair/ntuser.dat> name (from header): <>
- ROOT KEY at offset: 0x001020 * Subkey indexing type is: 666c <lf>
- File size 262144 [40000] bytes, containing 59 pages (+ 1 headerpage)
- Used for data: 4189/234624 blocks/bytes, unused: 132/5152 blocks/bytes.
- --- Import KEY <\Software\Microsoft\Windows\CurrentVersion\Run>
- END OF IMPORT, file </tmp/runWrite.reg>, operation SUCCEEDED!
- 1 keys
- 0 new keys added
- 1 values total
- Hives that have changed:
- # Name
- 0 </mnt/sda1/WINDOWS/repair/ntuser.dat> - OK
- Modificada clave HKEY_USERS\S-1-5-20\Software\Microsoft\Windows\CurrentVersion\Run | Todos los valores a vacio
- *******************
- reged version 0.1 110511, (c) Petter N Hagen
- Hive </mnt/sda1/WINDOWS/repair/ntuser.dat> name (from header): <>
- ROOT KEY at offset: 0x001020 * Subkey indexing type is: 666c <lf>
- File size 262144 [40000] bytes, containing 59 pages (+ 1 headerpage)
- Used for data: 4189/234624 blocks/bytes, unused: 132/5152 blocks/bytes.
- --- Import KEY <\Software\Microsoft\Windows NT\CurrentVersion\Winlogon> with 2 values.
- --- Import KEY <\Software\Microsoft\Windows NT\CurrentVersion\Winlogon>
- END OF IMPORT, file </tmp/user.reg>, operation SUCCEEDED!
- 2 keys
- 0 new keys added
- 4 values total
- Hives that have changed:
- # Name
- 0 </mnt/sda1/WINDOWS/repair/ntuser.dat> - OK
- Modificada clave HKEY_USERS\S-1-5-20\Software\Microsoft\Windows NT\CurrentVersion\Winlogon | Shell | Userinit
- *******************
- reged version 0.1 110511, (c) Petter N Hagen
- Hive </mnt/sda1/WINDOWS/repair/ntuser.dat> name (from header): <>
- ROOT KEY at offset: 0x001020 * Subkey indexing type is: 666c <lf>
- File size 262144 [40000] bytes, containing 59 pages (+ 1 headerpage)
- Used for data: 4189/234624 blocks/bytes, unused: 132/5152 blocks/bytes.
- --- Import KEY <\Software\Microsoft\Windows NT\CurrentVersion\Windows>
- END OF IMPORT, file </tmp/user.reg>, operation SUCCEEDED!
- 1 keys
- 0 new keys added
- 2 values total
- Hives that have changed:
- # Name
- 0 </mnt/sda1/WINDOWS/repair/ntuser.dat> - OK
- Modificada clave HKEY_USERS\S-1-5-20\Software\Microsoft\Windows NT\CurrentVersion\Windows | Load
- User: S-1-5-21-606747145-746137067-682003330-1003
- NTUSER: /mnt/sda1/Documents and Settings/Default User/NTUSER.DAT
- *******************
- reged version 0.1 110511, (c) Petter N Hagen
- Hive </mnt/sda1/Documents and Settings/Default User/NTUSER.DAT> name (from header): <ettings\Default User\NtUser.dat>
- ROOT KEY at offset: 0x001020 * Subkey indexing type is: 666c <lf>
- File size 262144 [40000] bytes, containing 59 pages (+ 1 headerpage)
- Used for data: 4194/234976 blocks/bytes, unused: 129/4800 blocks/bytes.
- Exporting to file '/tmp/runRead.reg'...
- Exporting key 'Run' with 0 subkeys and 1 values...
- *******************
- Fichero /tmp/runRead.reg
- Windows Registry Editor Version 5.00
- [HKEY_USERS\S-1-5-21-606747145-746137067-682003330-1003\Software\Microsoft\Windows\CurrentVersion\Run]
- "CTFMON.EXE"=""
- *******************
- Fichero /tmp/runWrite.reg
- Windows Registry Editor Version 5.00
- [HKEY_USERSS-1-5-21-606747145-746137067-682003330-1003\Software\Microsoft\Windows\CurrentVersion\Run]
- "CTFMON.EXE"=
- *******************
- reged version 0.1 110511, (c) Petter N Hagen
- Hive </mnt/sda1/Documents and Settings/Default User/NTUSER.DAT> name (from header): <ettings\Default User\NtUser.dat>
- ROOT KEY at offset: 0x001020 * Subkey indexing type is: 666c <lf>
- File size 262144 [40000] bytes, containing 59 pages (+ 1 headerpage)
- Used for data: 4194/234976 blocks/bytes, unused: 129/4800 blocks/bytes.
- --- Import KEY <\Software\Microsoft\Windows\CurrentVersion\Run>
- END OF IMPORT, file </tmp/runWrite.reg>, operation SUCCEEDED!
- 1 keys
- 0 new keys added
- 1 values total
- Hives that have changed:
- # Name
- 0 </mnt/sda1/Documents and Settings/Default User/NTUSER.DAT> - OK
- Modificada clave HKEY_USERS\S-1-5-21-606747145-746137067-682003330-1003\Software\Microsoft\Windows\CurrentVersion\Run | Todos los valores a vacio
- *******************
- reged version 0.1 110511, (c) Petter N Hagen
- Hive </mnt/sda1/Documents and Settings/Default User/NTUSER.DAT> name (from header): <ettings\Default User\NtUser.dat>
- ROOT KEY at offset: 0x001020 * Subkey indexing type is: 666c <lf>
- File size 262144 [40000] bytes, containing 59 pages (+ 1 headerpage)
- Used for data: 4194/234976 blocks/bytes, unused: 129/4800 blocks/bytes.
- --- Import KEY <\Software\Microsoft\Windows NT\CurrentVersion\Winlogon> with 2 values.
- --- Import KEY <\Software\Microsoft\Windows NT\CurrentVersion\Winlogon>
- END OF IMPORT, file </tmp/user.reg>, operation SUCCEEDED!
- 2 keys
- 0 new keys added
- 4 values total
- Hives that have changed:
- # Name
- 0 </mnt/sda1/Documents and Settings/Default User/NTUSER.DAT> - OK
- Modificada clave HKEY_USERS\S-1-5-21-606747145-746137067-682003330-1003\Software\Microsoft\Windows NT\CurrentVersion\Winlogon | Shell | Userinit
- *******************
- reged version 0.1 110511, (c) Petter N Hagen
- Hive </mnt/sda1/Documents and Settings/Default User/NTUSER.DAT> name (from header): <ettings\Default User\NtUser.dat>
- ROOT KEY at offset: 0x001020 * Subkey indexing type is: 666c <lf>
- File size 262144 [40000] bytes, containing 59 pages (+ 1 headerpage)
- Used for data: 4194/234976 blocks/bytes, unused: 129/4800 blocks/bytes.
- --- Import KEY <\Software\Microsoft\Windows NT\CurrentVersion\Windows>
- END OF IMPORT, file </tmp/user.reg>, operation SUCCEEDED!
- 1 keys
- 0 new keys added
- 2 values total
- Hives that have changed:
- # Name
- 0 </mnt/sda1/Documents and Settings/Default User/NTUSER.DAT> - OK
- Modificada clave HKEY_USERS\S-1-5-21-606747145-746137067-682003330-1003\Software\Microsoft\Windows NT\CurrentVersion\Windows | Load
- NTUSER: /mnt/sda1/Documents and Settings/LocalService/NTUSER.DAT
- *******************
- reged version 0.1 110511, (c) Petter N Hagen
- Hive </mnt/sda1/Documents and Settings/LocalService/NTUSER.DAT> name (from header): <ettings\LocalService\ntuser.dat>
- ROOT KEY at offset: 0x001020 * Subkey indexing type is: 666c <lf>
- File size 262144 [40000] bytes, containing 57 pages (+ 1 headerpage)
- Used for data: 4163/230280 blocks/bytes, unused: 144/1368 blocks/bytes.
- Exporting to file '/tmp/runRead.reg'...
- Exporting key 'Run' with 0 subkeys and 1 values...
- *******************
- Fichero /tmp/runRead.reg
- Windows Registry Editor Version 5.00
- [HKEY_USERS\S-1-5-21-606747145-746137067-682003330-1003\Software\Microsoft\Windows\CurrentVersion\Run]
- "CTFMON.EXE"=""
- *******************
- Fichero /tmp/runWrite.reg
- Windows Registry Editor Version 5.00
- [HKEY_USERSS-1-5-21-606747145-746137067-682003330-1003\Software\Microsoft\Windows\CurrentVersion\Run]
- "CTFMON.EXE"=
- *******************
- reged version 0.1 110511, (c) Petter N Hagen
- Hive </mnt/sda1/Documents and Settings/LocalService/NTUSER.DAT> name (from header): <ettings\LocalService\ntuser.dat>
- ROOT KEY at offset: 0x001020 * Subkey indexing type is: 666c <lf>
- File size 262144 [40000] bytes, containing 57 pages (+ 1 headerpage)
- Used for data: 4163/230280 blocks/bytes, unused: 144/1368 blocks/bytes.
- --- Import KEY <\Software\Microsoft\Windows\CurrentVersion\Run>
- END OF IMPORT, file </tmp/runWrite.reg>, operation SUCCEEDED!
- 1 keys
- 0 new keys added
- 1 values total
- Hives that have changed:
- # Name
- 0 </mnt/sda1/Documents and Settings/LocalService/NTUSER.DAT> - OK
- Modificada clave HKEY_USERS\S-1-5-21-606747145-746137067-682003330-1003\Software\Microsoft\Windows\CurrentVersion\Run | Todos los valores a vacio
- *******************
- reged version 0.1 110511, (c) Petter N Hagen
- Hive </mnt/sda1/Documents and Settings/LocalService/NTUSER.DAT> name (from header): <ettings\LocalService\ntuser.dat>
- ROOT KEY at offset: 0x001020 * Subkey indexing type is: 666c <lf>
- File size 262144 [40000] bytes, containing 57 pages (+ 1 headerpage)
- Used for data: 4163/230280 blocks/bytes, unused: 144/1368 blocks/bytes.
- --- Import KEY <\Software\Microsoft\Windows NT\CurrentVersion\Winlogon> with 2 values.
- --- Import KEY <\Software\Microsoft\Windows NT\CurrentVersion\Winlogon>
- END OF IMPORT, file </tmp/user.reg>, operation SUCCEEDED!
- 2 keys
- 0 new keys added
- 4 values total
- Hives that have changed:
- # Name
- 0 </mnt/sda1/Documents and Settings/LocalService/NTUSER.DAT> - OK
- Modificada clave HKEY_USERS\S-1-5-21-606747145-746137067-682003330-1003\Software\Microsoft\Windows NT\CurrentVersion\Winlogon | Shell | Userinit
- *******************
- reged version 0.1 110511, (c) Petter N Hagen
- Hive </mnt/sda1/Documents and Settings/LocalService/NTUSER.DAT> name (from header): <ettings\LocalService\ntuser.dat>
- ROOT KEY at offset: 0x001020 * Subkey indexing type is: 666c <lf>
- File size 262144 [40000] bytes, containing 57 pages (+ 1 headerpage)
- Used for data: 4163/230280 blocks/bytes, unused: 144/1368 blocks/bytes.
- --- Import KEY <\Software\Microsoft\Windows NT\CurrentVersion\Windows>
- END OF IMPORT, file </tmp/user.reg>, operation SUCCEEDED!
- 1 keys
- 0 new keys added
- 2 values total
- Hives that have changed:
- # Name
- 0 </mnt/sda1/Documents and Settings/LocalService/NTUSER.DAT> - OK
- Modificada clave HKEY_USERS\S-1-5-21-606747145-746137067-682003330-1003\Software\Microsoft\Windows NT\CurrentVersion\Windows | Load
- NTUSER: /mnt/sda1/Documents and Settings/NetworkService/NTUSER.DAT
- *******************
- reged version 0.1 110511, (c) Petter N Hagen
- Hive </mnt/sda1/Documents and Settings/NetworkService/NTUSER.DAT> name (from header): <tings\NetworkService\ntuser.dat>
- ROOT KEY at offset: 0x001020 * Subkey indexing type is: 666c <lf>
- File size 303104 [4a000] bytes, containing 57 pages (+ 1 headerpage)
- Used for data: 4131/294808 blocks/bytes, unused: 133/2376 blocks/bytes.
- Exporting to file '/tmp/runRead.reg'...
- Exporting key 'Run' with 0 subkeys and 1 values...
- *******************
- Fichero /tmp/runRead.reg
- Windows Registry Editor Version 5.00
- [HKEY_USERS\S-1-5-21-606747145-746137067-682003330-1003\Software\Microsoft\Windows\CurrentVersion\Run]
- "CTFMON.EXE"=""
- *******************
- Fichero /tmp/runWrite.reg
- Windows Registry Editor Version 5.00
- [HKEY_USERSS-1-5-21-606747145-746137067-682003330-1003\Software\Microsoft\Windows\CurrentVersion\Run]
- "CTFMON.EXE"=
- *******************
- reged version 0.1 110511, (c) Petter N Hagen
- Hive </mnt/sda1/Documents and Settings/NetworkService/NTUSER.DAT> name (from header): <tings\NetworkService\ntuser.dat>
- ROOT KEY at offset: 0x001020 * Subkey indexing type is: 666c <lf>
- File size 303104 [4a000] bytes, containing 57 pages (+ 1 headerpage)
- Used for data: 4131/294808 blocks/bytes, unused: 133/2376 blocks/bytes.
- --- Import KEY <\Software\Microsoft\Windows\CurrentVersion\Run>
- END OF IMPORT, file </tmp/runWrite.reg>, operation SUCCEEDED!
- 1 keys
- 0 new keys added
- 1 values total
- Hives that have changed:
- # Name
- 0 </mnt/sda1/Documents and Settings/NetworkService/NTUSER.DAT> - OK
- Modificada clave HKEY_USERS\S-1-5-21-606747145-746137067-682003330-1003\Software\Microsoft\Windows\CurrentVersion\Run | Todos los valores a vacio
- *******************
- reged version 0.1 110511, (c) Petter N Hagen
- Hive </mnt/sda1/Documents and Settings/NetworkService/NTUSER.DAT> name (from header): <tings\NetworkService\ntuser.dat>
- ROOT KEY at offset: 0x001020 * Subkey indexing type is: 666c <lf>
- File size 303104 [4a000] bytes, containing 57 pages (+ 1 headerpage)
- Used for data: 4131/294808 blocks/bytes, unused: 133/2376 blocks/bytes.
- --- Import KEY <\Software\Microsoft\Windows NT\CurrentVersion\Winlogon> with 2 values.
- --- Import KEY <\Software\Microsoft\Windows NT\CurrentVersion\Winlogon>
- END OF IMPORT, file </tmp/user.reg>, operation SUCCEEDED!
- 2 keys
- 0 new keys added
- 4 values total
- Hives that have changed:
- # Name
- 0 </mnt/sda1/Documents and Settings/NetworkService/NTUSER.DAT> - OK
- Modificada clave HKEY_USERS\S-1-5-21-606747145-746137067-682003330-1003\Software\Microsoft\Windows NT\CurrentVersion\Winlogon | Shell | Userinit
- *******************
- reged version 0.1 110511, (c) Petter N Hagen
- Hive </mnt/sda1/Documents and Settings/NetworkService/NTUSER.DAT> name (from header): <tings\NetworkService\ntuser.dat>
- ROOT KEY at offset: 0x001020 * Subkey indexing type is: 666c <lf>
- File size 303104 [4a000] bytes, containing 57 pages (+ 1 headerpage)
- Used for data: 4131/294808 blocks/bytes, unused: 133/2376 blocks/bytes.
- --- Import KEY <\Software\Microsoft\Windows NT\CurrentVersion\Windows>
- END OF IMPORT, file </tmp/user.reg>, operation SUCCEEDED!
- 1 keys
- 0 new keys added
- 2 values total
- Hives that have changed:
- # Name
- 0 </mnt/sda1/Documents and Settings/NetworkService/NTUSER.DAT> - OK
- Modificada clave HKEY_USERS\S-1-5-21-606747145-746137067-682003330-1003\Software\Microsoft\Windows NT\CurrentVersion\Windows | Load
- NTUSER: /mnt/sda1/Documents and Settings/vinagreta/NTUSER.DAT
- *******************
- reged version 0.1 110511, (c) Petter N Hagen
- Hive </mnt/sda1/Documents and Settings/vinagreta/NTUSER.DAT> name (from header): <d Settings\vinagreta\ntuser.dat>
- ROOT KEY at offset: 0x001020 * Subkey indexing type is: 666c <lf>
- File size 6029312 [5c0000] bytes, containing 1100 pages (+ 1 headerpage)
- Used for data: 99154/5792328 blocks/bytes, unused: 6567/140344 blocks/bytes.
- Exporting to file '/tmp/runRead.reg'...
- Exporting key 'Run' with 0 subkeys and 1 values...
- *******************
- Fichero /tmp/runRead.reg
- Windows Registry Editor Version 5.00
- [HKEY_USERS\S-1-5-21-606747145-746137067-682003330-1003\Software\Microsoft\Windows\CurrentVersion\Run]
- "ctfmon.exe"=""
- *******************
- Fichero /tmp/runWrite.reg
- Windows Registry Editor Version 5.00
- [HKEY_USERSS-1-5-21-606747145-746137067-682003330-1003\Software\Microsoft\Windows\CurrentVersion\Run]
- "ctfmon.exe"=
- *******************
- reged version 0.1 110511, (c) Petter N Hagen
- Hive </mnt/sda1/Documents and Settings/vinagreta/NTUSER.DAT> name (from header): <d Settings\vinagreta\ntuser.dat>
- ROOT KEY at offset: 0x001020 * Subkey indexing type is: 666c <lf>
- File size 6029312 [5c0000] bytes, containing 1100 pages (+ 1 headerpage)
- Used for data: 99154/5792328 blocks/bytes, unused: 6567/140344 blocks/bytes.
- --- Import KEY <\Software\Microsoft\Windows\CurrentVersion\Run>
- END OF IMPORT, file </tmp/runWrite.reg>, operation SUCCEEDED!
- 1 keys
- 0 new keys added
- 1 values total
- Hives that have changed:
- # Name
- 0 </mnt/sda1/Documents and Settings/vinagreta/NTUSER.DAT> - OK
- Modificada clave HKEY_USERS\S-1-5-21-606747145-746137067-682003330-1003\Software\Microsoft\Windows\CurrentVersion\Run | Todos los valores a vacio
- *******************
- reged version 0.1 110511, (c) Petter N Hagen
- Hive </mnt/sda1/Documents and Settings/vinagreta/NTUSER.DAT> name (from header): <d Settings\vinagreta\ntuser.dat>
- ROOT KEY at offset: 0x001020 * Subkey indexing type is: 666c <lf>
- File size 6029312 [5c0000] bytes, containing 1100 pages (+ 1 headerpage)
- Used for data: 99154/5792328 blocks/bytes, unused: 6567/140344 blocks/bytes.
- --- Import KEY <\Software\Microsoft\Windows NT\CurrentVersion\Winlogon> with 2 values.
- --- Import KEY <\Software\Microsoft\Windows NT\CurrentVersion\Winlogon>
- END OF IMPORT, file </tmp/user.reg>, operation SUCCEEDED!
- 2 keys
- 0 new keys added
- 4 values total
- Hives that have changed:
- # Name
- 0 </mnt/sda1/Documents and Settings/vinagreta/NTUSER.DAT> - OK
- Modificada clave HKEY_USERS\S-1-5-21-606747145-746137067-682003330-1003\Software\Microsoft\Windows NT\CurrentVersion\Winlogon | Shell | Userinit
- *******************
- reged version 0.1 110511, (c) Petter N Hagen
- Hive </mnt/sda1/Documents and Settings/vinagreta/NTUSER.DAT> name (from header): <d Settings\vinagreta\ntuser.dat>
- ROOT KEY at offset: 0x001020 * Subkey indexing type is: 666c <lf>
- File size 6029312 [5c0000] bytes, containing 1100 pages (+ 1 headerpage)
- Used for data: 99154/5792328 blocks/bytes, unused: 6567/140344 blocks/bytes.
- --- Import KEY <\Software\Microsoft\Windows NT\CurrentVersion\Windows>
- END OF IMPORT, file </tmp/user.reg>, operation SUCCEEDED!
- 1 keys
- 0 new keys added
- 2 values total
- Hives that have changed:
- # Name
- 0 </mnt/sda1/Documents and Settings/vinagreta/NTUSER.DAT> - OK
- Modificada clave HKEY_USERS\S-1-5-21-606747145-746137067-682003330-1003\Software\Microsoft\Windows NT\CurrentVersion\Windows | Load
- NTUSER: /mnt/sda1/WINDOWS/system32/config/systemprofile/NtUser.dat
- *******************
- reged version 0.1 110511, (c) Petter N Hagen
- Hive </mnt/sda1/WINDOWS/system32/config/systemprofile/NtUser.dat> name (from header): <em32\config\SYSTEM~1\NtUser.dat>
- ROOT KEY at offset: 0x001020 * Subkey indexing type is: 666c <lf>
- File size 262144 [40000] bytes, containing 1 pages (+ 1 headerpage)
- Used for data: 21/1240 blocks/bytes, unused: 5/2824 blocks/bytes.
- Exporting to file '/tmp/runRead.reg'...
- export_subkey: Key 'Software\Microsoft\Windows\CurrentVersion\Run' not found!
- *******************
- Fichero /tmp/runRead.reg
- Windows Registry Editor Version 5.00
- *******************
- Fichero /tmp/runWrite.reg
- Windows Registry Editor Version 5.00
- *******************
- reged version 0.1 110511, (c) Petter N Hagen
- Hive </mnt/sda1/WINDOWS/system32/config/systemprofile/NtUser.dat> name (from header): <em32\config\SYSTEM~1\NtUser.dat>
- ROOT KEY at offset: 0x001020 * Subkey indexing type is: 666c <lf>
- File size 262144 [40000] bytes, containing 1 pages (+ 1 headerpage)
- Used for data: 21/1240 blocks/bytes, unused: 5/2824 blocks/bytes.
- END OF IMPORT, file </tmp/runWrite.reg>, operation SUCCEEDED!
- 0 keys
- 0 new keys added
- 0 values total
- Hives that have changed:
- # Name
- None!
- Modificada clave HKEY_USERS\S-1-5-21-606747145-746137067-682003330-1003\Software\Microsoft\Windows\CurrentVersion\Run | Todos los valores a vacio
- *******************
- reged version 0.1 110511, (c) Petter N Hagen
- Hive </mnt/sda1/WINDOWS/system32/config/systemprofile/NtUser.dat> name (from header): <em32\config\SYSTEM~1\NtUser.dat>
- ROOT KEY at offset: 0x001020 * Subkey indexing type is: 666c <lf>
- File size 262144 [40000] bytes, containing 1 pages (+ 1 headerpage)
- Used for data: 21/1240 blocks/bytes, unused: 5/2824 blocks/bytes.
- --- Import KEY <\Software\Microsoft\Windows NT\CurrentVersion\Winlogon> with 2 values.
- --- Import KEY <\Software\Microsoft\Windows NT\CurrentVersion\Winlogon>
- END OF IMPORT, file </tmp/user.reg>, operation SUCCEEDED!
- 2 keys
- 0 new keys added
- 4 values total
- Hives that have changed:
- # Name
- 0 </mnt/sda1/WINDOWS/system32/config/systemprofile/NtUser.dat> - OK
- Modificada clave HKEY_USERS\S-1-5-21-606747145-746137067-682003330-1003\Software\Microsoft\Windows NT\CurrentVersion\Winlogon | Shell | Userinit
- *******************
- reged version 0.1 110511, (c) Petter N Hagen
- Hive </mnt/sda1/WINDOWS/system32/config/systemprofile/NtUser.dat> name (from header): <em32\config\SYSTEM~1\NtUser.dat>
- ROOT KEY at offset: 0x001020 * Subkey indexing type is: 666c <lf>
- File size 262144 [40000] bytes, containing 1 pages (+ 1 headerpage)
- Used for data: 21/1240 blocks/bytes, unused: 5/2824 blocks/bytes.
- --- Import KEY <\Software\Microsoft\Windows NT\CurrentVersion\Windows>
- END OF IMPORT, file </tmp/user.reg>, operation SUCCEEDED!
- 1 keys
- 0 new keys added
- 2 values total
- Hives that have changed:
- # Name
- 0 </mnt/sda1/WINDOWS/system32/config/systemprofile/NtUser.dat> - OK
- Modificada clave HKEY_USERS\S-1-5-21-606747145-746137067-682003330-1003\Software\Microsoft\Windows NT\CurrentVersion\Windows | Load
- NTUSER: /mnt/sda1/WINDOWS/repair/ntuser.dat
- *******************
- reged version 0.1 110511, (c) Petter N Hagen
- Hive </mnt/sda1/WINDOWS/repair/ntuser.dat> name (from header): <>
- ROOT KEY at offset: 0x001020 * Subkey indexing type is: 666c <lf>
- File size 262144 [40000] bytes, containing 59 pages (+ 1 headerpage)
- Used for data: 4189/234624 blocks/bytes, unused: 132/5152 blocks/bytes.
- Exporting to file '/tmp/runRead.reg'...
- Exporting key 'Run' with 0 subkeys and 1 values...
- *******************
- Fichero /tmp/runRead.reg
- Windows Registry Editor Version 5.00
- [HKEY_USERS\S-1-5-21-606747145-746137067-682003330-1003\Software\Microsoft\Windows\CurrentVersion\Run]
- "CTFMON.EXE"=""
- *******************
- Fichero /tmp/runWrite.reg
- Windows Registry Editor Version 5.00
- [HKEY_USERSS-1-5-21-606747145-746137067-682003330-1003\Software\Microsoft\Windows\CurrentVersion\Run]
- "CTFMON.EXE"=
- *******************
- reged version 0.1 110511, (c) Petter N Hagen
- Hive </mnt/sda1/WINDOWS/repair/ntuser.dat> name (from header): <>
- ROOT KEY at offset: 0x001020 * Subkey indexing type is: 666c <lf>
- File size 262144 [40000] bytes, containing 59 pages (+ 1 headerpage)
- Used for data: 4189/234624 blocks/bytes, unused: 132/5152 blocks/bytes.
- --- Import KEY <\Software\Microsoft\Windows\CurrentVersion\Run>
- END OF IMPORT, file </tmp/runWrite.reg>, operation SUCCEEDED!
- 1 keys
- 0 new keys added
- 1 values total
- Hives that have changed:
- # Name
- 0 </mnt/sda1/WINDOWS/repair/ntuser.dat> - OK
- Modificada clave HKEY_USERS\S-1-5-21-606747145-746137067-682003330-1003\Software\Microsoft\Windows\CurrentVersion\Run | Todos los valores a vacio
- *******************
- reged version 0.1 110511, (c) Petter N Hagen
- Hive </mnt/sda1/WINDOWS/repair/ntuser.dat> name (from header): <>
- ROOT KEY at offset: 0x001020 * Subkey indexing type is: 666c <lf>
- File size 262144 [40000] bytes, containing 59 pages (+ 1 headerpage)
- Used for data: 4189/234624 blocks/bytes, unused: 132/5152 blocks/bytes.
- --- Import KEY <\Software\Microsoft\Windows NT\CurrentVersion\Winlogon> with 2 values.
- --- Import KEY <\Software\Microsoft\Windows NT\CurrentVersion\Winlogon>
- END OF IMPORT, file </tmp/user.reg>, operation SUCCEEDED!
- 2 keys
- 0 new keys added
- 4 values total
- Hives that have changed:
- # Name
- 0 </mnt/sda1/WINDOWS/repair/ntuser.dat> - OK
- Modificada clave HKEY_USERS\S-1-5-21-606747145-746137067-682003330-1003\Software\Microsoft\Windows NT\CurrentVersion\Winlogon | Shell | Userinit
- *******************
- reged version 0.1 110511, (c) Petter N Hagen
- Hive </mnt/sda1/WINDOWS/repair/ntuser.dat> name (from header): <>
- ROOT KEY at offset: 0x001020 * Subkey indexing type is: 666c <lf>
- File size 262144 [40000] bytes, containing 59 pages (+ 1 headerpage)
- Used for data: 4189/234624 blocks/bytes, unused: 132/5152 blocks/bytes.
- --- Import KEY <\Software\Microsoft\Windows NT\CurrentVersion\Windows>
- END OF IMPORT, file </tmp/user.reg>, operation SUCCEEDED!
- 1 keys
- 0 new keys added
- 2 values total
- Hives that have changed:
- # Name
- 0 </mnt/sda1/WINDOWS/repair/ntuser.dat> - OK
- Modificada clave HKEY_USERS\S-1-5-21-606747145-746137067-682003330-1003\Software\Microsoft\Windows NT\CurrentVersion\Windows | Load
- Done!!
- Looking for in: /mnt/sda1/WINDOWS/system32/config/system
- Found!!
- Applying system disinfection!!
- *******************
- reged version 0.1 110511, (c) Petter N Hagen
- Hive <./mnt/sda1/WINDOWS/system32/config/system> name (from header): <SYSTEM>
- ROOT KEY at offset: 0x001020 * Subkey indexing type is: 666c <lf>
- File size 5242880 [500000] bytes, containing 1241 pages (+ 1 headerpage)
- Used for data: 89253/5166080 blocks/bytes, unused: 2140/24800 blocks/bytes.
- Exporting to file '/tmp/runRead.reg'...
- Exporting key 'Select' with 0 subkeys and 4 values...
- *******************
- reged version 0.1 110511, (c) Petter N Hagen
- Hive <./mnt/sda1/WINDOWS/system32/config/system> name (from header): <SYSTEM>
- ROOT KEY at offset: 0x001020 * Subkey indexing type is: 666c <lf>
- File size 5242880 [500000] bytes, containing 1241 pages (+ 1 headerpage)
- Used for data: 89253/5166080 blocks/bytes, unused: 2140/24800 blocks/bytes.
- --- Import KEY <\ControlSet001\Control\SafeBoot>
- END OF IMPORT, file </root/policeSafeBoot.reg>, operation SUCCEEDED!
- 1 keys
- 0 new keys added
- 0 values total
- Hives that have changed:
- # Name
- None!
- Modificadas claves HKLM\SYSTEM\ControlSet001\Control\SafeBoot | AlternateShell
- Done!!
- Looking for in: /mnt/sda5/WINDOWS/system32/config/software
- Looking for in: /mnt/sda5/WINDOWS/system32/config/system
- Looking for in: /mnt/sdb1/WINDOWS/system32/config/software
- Found!!
- Applying generic disinfection!!
- *******************
- reged version 0.1 110511, (c) Petter N Hagen
- Hive <./mnt/sdb1/WINDOWS/system32/config/software> name (from header): <emRoot\System32\Config\SOFTWARE>
- ROOT KEY at offset: 0x001020 * Subkey indexing type is: 666c <lf>
- File size 33292288 [1fc0000] bytes, containing 7756 pages (+ 1 headerpage)
- Used for data: 590036/32784304 blocks/bytes, unused: 3961/79568 blocks/bytes.
- --- Import KEY <\Microsoft\Windows NT\CurrentVersion\Winlogon> with 1 values.
- --- Import KEY <\Microsoft\Windows NT\CurrentVersion\Winlogon> with 1 values.
- --- Import KEY <\Microsoft\Windows NT\CurrentVersion\Winlogon> with 1 values.
- --- Import KEY <\Microsoft\Windows NT\CurrentVersion\Winlogon> with 1 values.
- --- Import KEY <\Microsoft\Windows NT\CurrentVersion\Winlogon> with 1 values.
- --- Import KEY <\Microsoft\Windows NT\CurrentVersion\Winlogon>
- END OF IMPORT, file </root/policeWinlogon.reg>, operation SUCCEEDED!
- 6 keys
- 0 new keys added
- 6 values total
- Hives that have changed:
- # Name
- 0 <./mnt/sdb1/WINDOWS/system32/config/software> - OK
- Modificadas claves HKLM\Software\Microsoft\Windows NT\CurrentVersion\Winlogon | Shell | State | Userinit | Taskman | taskman
- *******************
- reged version 0.1 110511, (c) Petter N Hagen
- Hive <./mnt/sdb1/WINDOWS/system32/config/software> name (from header): <emRoot\System32\Config\SOFTWARE>
- ROOT KEY at offset: 0x001020 * Subkey indexing type is: 666c <lf>
- File size 33292288 [1fc0000] bytes, containing 7756 pages (+ 1 headerpage)
- Used for data: 590040/32784480 blocks/bytes, unused: 3961/79392 blocks/bytes.
- --- Import KEY <\Microsoft\Windows\CurrentVersion\Explorer> with 1 values.
- --- Import KEY <\Microsoft\Windows\CurrentVersion\Explorer> with 1 values.
- --- Import KEY <\Microsoft\Windows\CurrentVersion\Explorer>
- END OF IMPORT, file </root/policeExplorer.reg>, operation SUCCEEDED!
- 3 keys
- 0 new keys added
- 3 values total
- Hives that have changed:
- # Name
- 0 <./mnt/sdb1/WINDOWS/system32/config/software> - OK
- Modificadas claves HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer | Expanded | Favorites | FullPath
- *******************
- ERROR: import_reg: failed to add (sub)key <explorer>
- reged version 0.1 110511, (c) Petter N Hagen
- Hive <./mnt/sdb1/WINDOWS/system32/config/software> name (from header): <emRoot\System32\Config\SOFTWARE>
- ROOT KEY at offset: 0x001020 * Subkey indexing type is: 666c <lf>
- File size 33292288 [1fc0000] bytes, containing 7756 pages (+ 1 headerpage)
- Used for data: 590044/32784616 blocks/bytes, unused: 3960/79256 blocks/bytes.
- --- Import KEY <\Microsoft\Windows\CurrentVersion\explorer> add_key: key explorer already exists!
- END OF IMPORT, file </root/policeExplorerWvista.reg>, operation FAILED!
- 1 keys
- 0 new keys added
- 0 values total
- Hives that have changed:
- # Name
- None!
- Modificadas claves HKLM\Software\Microsoft\Windows\CurrentVersion\explorer | Expanded | Favorites | FullPath
- *******************
- reged version 0.1 110511, (c) Petter N Hagen
- Hive <./mnt/sdb1/WINDOWS/system32/config/software> name (from header): <emRoot\System32\Config\SOFTWARE>
- ROOT KEY at offset: 0x001020 * Subkey indexing type is: 666c <lf>
- File size 33292288 [1fc0000] bytes, containing 7756 pages (+ 1 headerpage)
- Used for data: 590044/32784616 blocks/bytes, unused: 3960/79256 blocks/bytes.
- Exporting to file '/tmp/runRead.reg'...
- Exporting key 'Run' with 0 subkeys and 1 values...
- *******************
- Fichero /tmp/runRead.reg
- Windows Registry Editor Version 5.00
- [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
- "avgnt"="\"C:\\Archivos de programa\\Avira\\AntiVir Desktop\\avgnt.exe\" /min"
- *******************
- Fichero /tmp/runWrite.reg
- Windows Registry Editor Version 5.00
- [HKEY_LOCAL_MACHINESOFTWARE\Microsoft\Windows\CurrentVersion\Run]
- "avgnt"=
- *******************
- reged version 0.1 110511, (c) Petter N Hagen
- Hive <./mnt/sdb1/WINDOWS/system32/config/software> name (from header): <emRoot\System32\Config\SOFTWARE>
- ROOT KEY at offset: 0x001020 * Subkey indexing type is: 666c <lf>
- File size 33292288 [1fc0000] bytes, containing 7756 pages (+ 1 headerpage)
- Used for data: 590044/32784616 blocks/bytes, unused: 3960/79256 blocks/bytes.
- --- Import KEY <\Microsoft\Windows\CurrentVersion\Run>
- END OF IMPORT, file </tmp/runWrite.reg>, operation SUCCEEDED!
- 1 keys
- 0 new keys added
- 1 values total
- Hives that have changed:
- # Name
- 0 <./mnt/sdb1/WINDOWS/system32/config/software> - OK
- Modificada clave HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run | Todos los valores a vacio
- *******************
- reged version 0.1 110511, (c) Petter N Hagen
- Hive <./mnt/sdb1/WINDOWS/system32/config/software> name (from header): <emRoot\System32\Config\SOFTWARE>
- ROOT KEY at offset: 0x001020 * Subkey indexing type is: 666c <lf>
- File size 33292288 [1fc0000] bytes, containing 7756 pages (+ 1 headerpage)
- Used for data: 590043/32784480 blocks/bytes, unused: 3961/79392 blocks/bytes.
- Exporting to file '/tmp/runRead.reg'...
- export_subkey: Key 'Microsoft\Windows\CurrentVersion\Policies\Explorer\Run' not found!
- *******************
- Fichero /tmp/runRead.reg
- Windows Registry Editor Version 5.00
- *******************
- Fichero /tmp/runWrite.reg
- Windows Registry Editor Version 5.00
- *******************
- reged version 0.1 110511, (c) Petter N Hagen
- Hive <./mnt/sdb1/WINDOWS/system32/config/software> name (from header): <emRoot\System32\Config\SOFTWARE>
- ROOT KEY at offset: 0x001020 * Subkey indexing type is: 666c <lf>
- File size 33292288 [1fc0000] bytes, containing 7756 pages (+ 1 headerpage)
- Used for data: 590043/32784480 blocks/bytes, unused: 3961/79392 blocks/bytes.
- END OF IMPORT, file </tmp/runWrite.reg>, operation SUCCEEDED!
- 0 keys
- 0 new keys added
- 0 values total
- Hives that have changed:
- # Name
- None!
- Modificada clave HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run | Todos los valores a vacio
- *******************
- reged version 0.1 110511, (c) Petter N Hagen
- Hive <./mnt/sdb1/WINDOWS/system32/config/software> name (from header): <emRoot\System32\Config\SOFTWARE>
- ROOT KEY at offset: 0x001020 * Subkey indexing type is: 666c <lf>
- File size 33292288 [1fc0000] bytes, containing 7756 pages (+ 1 headerpage)
- Used for data: 590043/32784480 blocks/bytes, unused: 3961/79392 blocks/bytes.
- Exporting to file '/tmp/runRead.reg'...
- export_subkey: Key 'Microsoft\Windows\CurrentVersion\policies\Explorer\Run' not found!
- *******************
- Fichero /tmp/runRead.reg
- Windows Registry Editor Version 5.00
- *******************
- Fichero /tmp/runWrite.reg
- Windows Registry Editor Version 5.00
- *******************
- reged version 0.1 110511, (c) Petter N Hagen
- Hive <./mnt/sdb1/WINDOWS/system32/config/software> name (from header): <emRoot\System32\Config\SOFTWARE>
- ROOT KEY at offset: 0x001020 * Subkey indexing type is: 666c <lf>
- File size 33292288 [1fc0000] bytes, containing 7756 pages (+ 1 headerpage)
- Used for data: 590043/32784480 blocks/bytes, unused: 3961/79392 blocks/bytes.
- END OF IMPORT, file </tmp/runWrite.reg>, operation SUCCEEDED!
- 0 keys
- 0 new keys added
- 0 values total
- Hives that have changed:
- # Name
- None!
- Modificada clave HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\Run | Todos los valores a vacio
- *******************
- reged version 0.1 110511, (c) Petter N Hagen
- Hive <./mnt/sdb1/WINDOWS/system32/config/software> name (from header): <emRoot\System32\Config\SOFTWARE>
- ROOT KEY at offset: 0x001020 * Subkey indexing type is: 666c <lf>
- File size 33292288 [1fc0000] bytes, containing 7756 pages (+ 1 headerpage)
- Used for data: 590043/32784480 blocks/bytes, unused: 3961/79392 blocks/bytes.
- Exporting to file '/tmp/runRead.reg'...
- export_subkey: Key 'Microsoft\Shared Tools\MSConfig\startupfolder' not found!
- *******************
- Fichero /tmp/runRead.reg
- Windows Registry Editor Version 5.00
- *******************
- Fichero /tmp/runWrite.reg
- Windows Registry Editor Version 5.00
- *******************
- reged version 0.1 110511, (c) Petter N Hagen
- Hive <./mnt/sdb1/WINDOWS/system32/config/software> name (from header): <emRoot\System32\Config\SOFTWARE>
- ROOT KEY at offset: 0x001020 * Subkey indexing type is: 666c <lf>
- File size 33292288 [1fc0000] bytes, containing 7756 pages (+ 1 headerpage)
- Used for data: 590043/32784480 blocks/bytes, unused: 3961/79392 blocks/bytes.
- END OF IMPORT, file </tmp/runWrite.reg>, operation SUCCEEDED!
- 0 keys
- 0 new keys added
- 0 values total
- Hives that have changed:
- # Name
- None!
- Modificada clave HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupfolder | Todos los valores a vacio
- Applying user disinfection!!
- This step may take a while depending on the size of your hard disk!!
- *******************
- reged version 0.1 110511, (c) Petter N Hagen
- Hive <./mnt/sdb1/WINDOWS/system32/config/software> name (from header): <emRoot\System32\Config\SOFTWARE>
- ROOT KEY at offset: 0x001020 * Subkey indexing type is: 666c <lf>
- File size 33292288 [1fc0000] bytes, containing 7756 pages (+ 1 headerpage)
- Used for data: 590043/32784480 blocks/bytes, unused: 3961/79392 blocks/bytes.
- Exporting to file '/tmp/users.reg'...
- Exporting key 'ProfileList' with 4 subkeys and 3 values...
- Exporting key 'S-1-5-18' with 0 subkeys and 5 values...
- Exporting key 'S-1-5-19' with 0 subkeys and 8 values...
- Exporting key 'S-1-5-20' with 0 subkeys and 8 values...
- Exporting key 'S-1-5-21-606747145-746137067-682003330-1003' with 0 subkeys and 10 values...
- User: S-1-5-18
- NTUSER: /mnt/sdb1/Documents and Settings/Default User/NTUSER.DAT
- *******************
- reged version 0.1 110511, (c) Petter N Hagen
- Hive </mnt/sdb1/Documents and Settings/Default User/NTUSER.DAT> name (from header): <ettings\Default User\NtUser.dat>
- ROOT KEY at offset: 0x001020 * Subkey indexing type is: 666c <lf>
- File size 262144 [40000] bytes, containing 59 pages (+ 1 headerpage)
- Used for data: 4190/234832 blocks/bytes, unused: 126/4944 blocks/bytes.
- Exporting to file '/tmp/runRead.reg'...
- Exporting key 'Run' with 0 subkeys and 1 values...
- *******************
- Fichero /tmp/runRead.reg
- Windows Registry Editor Version 5.00
- [HKEY_USERS\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Run]
- "CTFMON.EXE"="C:\\WINDOWS\\system32\\CTFMON.EXE"
- *******************
- Fichero /tmp/runWrite.reg
- Windows Registry Editor Version 5.00
- [HKEY_USERSS-1-5-18\Software\Microsoft\Windows\CurrentVersion\Run]
- "CTFMON.EXE"=
- *******************
- reged version 0.1 110511, (c) Petter N Hagen
- Hive </mnt/sdb1/Documents and Settings/Default User/NTUSER.DAT> name (from header): <ettings\Default User\NtUser.dat>
- ROOT KEY at offset: 0x001020 * Subkey indexing type is: 666c <lf>
- File size 262144 [40000] bytes, containing 59 pages (+ 1 headerpage)
- Used for data: 4190/234832 blocks/bytes, unused: 126/4944 blocks/bytes.
- --- Import KEY <\Software\Microsoft\Windows\CurrentVersion\Run>
- END OF IMPORT, file </tmp/runWrite.reg>, operation SUCCEEDED!
- 1 keys
- 0 new keys added
- 1 values total
- Hives that have changed:
- # Name
- 0 </mnt/sdb1/Documents and Settings/Default User/NTUSER.DAT> - OK
- Modificada clave HKEY_USERS\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Run | Todos los valores a vacio
- *******************
- reged version 0.1 110511, (c) Petter N Hagen
- Hive </mnt/sdb1/Documents and Settings/Default User/NTUSER.DAT> name (from header): <ettings\Default User\NtUser.dat>
- ROOT KEY at offset: 0x001020 * Subkey indexing type is: 666c <lf>
- File size 262144 [40000] bytes, containing 59 pages (+ 1 headerpage)
- Used for data: 4189/234760 blocks/bytes, unused: 127/5016 blocks/bytes.
- --- Import KEY <\Software\Microsoft\Windows NT\CurrentVersion\Winlogon> with 2 values.
- --- Import KEY <\Software\Microsoft\Windows NT\CurrentVersion\Winlogon>
- END OF IMPORT, file </tmp/user.reg>, operation SUCCEEDED!
- 2 keys
- 0 new keys added
- 4 values total
- Hives that have changed:
- # Name
- 0 </mnt/sdb1/Documents and Settings/Default User/NTUSER.DAT> - OK
- Modificada clave HKEY_USERS\S-1-5-18\Software\Microsoft\Windows NT\CurrentVersion\Winlogon | Shell | Userinit
- *******************
- reged version 0.1 110511, (c) Petter N Hagen
- Hive </mnt/sdb1/Documents and Settings/Default User/NTUSER.DAT> name (from header): <ettings\Default User\NtUser.dat>
- ROOT KEY at offset: 0x001020 * Subkey indexing type is: 666c <lf>
- File size 262144 [40000] bytes, containing 59 pages (+ 1 headerpage)
- Used for data: 4193/234936 blocks/bytes, unused: 129/4840 blocks/bytes.
- --- Import KEY <\Software\Microsoft\Windows NT\CurrentVersion\Windows>
- END OF IMPORT, file </tmp/user.reg>, operation SUCCEEDED!
- 1 keys
- 0 new keys added
- 2 values total
- Hives that have changed:
- # Name
- 0 </mnt/sdb1/Documents and Settings/Default User/NTUSER.DAT> - OK
- Modificada clave HKEY_USERS\S-1-5-18\Software\Microsoft\Windows NT\CurrentVersion\Windows | Load
- NTUSER: /mnt/sdb1/Documents and Settings/LocalService/NTUSER.DAT
- *******************
- reged version 0.1 110511, (c) Petter N Hagen
- Hive </mnt/sdb1/Documents and Settings/LocalService/NTUSER.DAT> name (from header): <ettings\LocalService\ntuser.dat>
- ROOT KEY at offset: 0x001020 * Subkey indexing type is: 666c <lf>
- File size 262144 [40000] bytes, containing 58 pages (+ 1 headerpage)
- Used for data: 4163/230672 blocks/bytes, unused: 139/5040 blocks/bytes.
- Exporting to file '/tmp/runRead.reg'...
- Exporting key 'Run' with 0 subkeys and 1 values...
- *******************
- Fichero /tmp/runRead.reg
- Windows Registry Editor Version 5.00
- [HKEY_USERS\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Run]
- "CTFMON.EXE"="C:\\WINDOWS\\system32\\CTFMON.EXE"
- *******************
- Fichero /tmp/runWrite.reg
- Windows Registry Editor Version 5.00
- [HKEY_USERSS-1-5-18\Software\Microsoft\Windows\CurrentVersion\Run]
- "CTFMON.EXE"=
- *******************
- reged version 0.1 110511, (c) Petter N Hagen
- Hive </mnt/sdb1/Documents and Settings/LocalService/NTUSER.DAT> name (from header): <ettings\LocalService\ntuser.dat>
- ROOT KEY at offset: 0x001020 * Subkey indexing type is: 666c <lf>
- File size 262144 [40000] bytes, containing 58 pages (+ 1 headerpage)
- Used for data: 4163/230672 blocks/bytes, unused: 139/5040 blocks/bytes.
- --- Import KEY <\Software\Microsoft\Windows\CurrentVersion\Run>
- END OF IMPORT, file </tmp/runWrite.reg>, operation SUCCEEDED!
- 1 keys
- 0 new keys added
- 1 values total
- Hives that have changed:
- # Name
- 0 </mnt/sdb1/Documents and Settings/LocalService/NTUSER.DAT> - OK
- Modificada clave HKEY_USERS\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Run | Todos los valores a vacio
- *******************
- reged version 0.1 110511, (c) Petter N Hagen
- Hive </mnt/sdb1/Documents and Settings/LocalService/NTUSER.DAT> name (from header): <ettings\LocalService\ntuser.dat>
- ROOT KEY at offset: 0x001020 * Subkey indexing type is: 666c <lf>
- File size 262144 [40000] bytes, containing 58 pages (+ 1 headerpage)
- Used for data: 4162/230600 blocks/bytes, unused: 140/5112 blocks/bytes.
- --- Import KEY <\Software\Microsoft\Windows NT\CurrentVersion\Winlogon> with 2 values.
- --- Import KEY <\Software\Microsoft\Windows NT\CurrentVersion\Winlogon>
- END OF IMPORT, file </tmp/user.reg>, operation SUCCEEDED!
- 2 keys
- 0 new keys added
- 4 values total
- Hives that have changed:
- # Name
- 0 </mnt/sdb1/Documents and Settings/LocalService/NTUSER.DAT> - OK
- Modificada clave HKEY_USERS\S-1-5-18\Software\Microsoft\Windows NT\CurrentVersion\Winlogon | Shell | Userinit
- *******************
- reged version 0.1 110511, (c) Petter N Hagen
- Hive </mnt/sdb1/Documents and Settings/LocalService/NTUSER.DAT> name (from header): <ettings\LocalService\ntuser.dat>
- ROOT KEY at offset: 0x001020 * Subkey indexing type is: 666c <lf>
- File size 262144 [40000] bytes, containing 58 pages (+ 1 headerpage)
- Used for data: 4166/230776 blocks/bytes, unused: 142/4936 blocks/bytes.
- --- Import KEY <\Software\Microsoft\Windows NT\CurrentVersion\Windows>
- END OF IMPORT, file </tmp/user.reg>, operation SUCCEEDED!
- 1 keys
- 0 new keys added
- 2 values total
- Hives that have changed:
- # Name
- 0 </mnt/sdb1/Documents and Settings/LocalService/NTUSER.DAT> - OK
- Modificada clave HKEY_USERS\S-1-5-18\Software\Microsoft\Windows NT\CurrentVersion\Windows | Load
- NTUSER: /mnt/sdb1/Documents and Settings/NetworkService/NTUSER.DAT
- *******************
- reged version 0.1 110511, (c) Petter N Hagen
- Hive </mnt/sdb1/Documents and Settings/NetworkService/NTUSER.DAT> name (from header): <tings\NetworkService\ntuser.dat>
- ROOT KEY at offset: 0x001020 * Subkey indexing type is: 666c <lf>
- File size 303104 [4a000] bytes, containing 57 pages (+ 1 headerpage)
- Used for data: 4131/295200 blocks/bytes, unused: 139/1984 blocks/bytes.
- Exporting to file '/tmp/runRead.reg'...
- Exporting key 'Run' with 0 subkeys and 1 values...
- *******************
- Fichero /tmp/runRead.reg
- Windows Registry Editor Version 5.00
- [HKEY_USERS\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Run]
- "CTFMON.EXE"="C:\\WINDOWS\\system32\\CTFMON.EXE"
- *******************
- Fichero /tmp/runWrite.reg
- Windows Registry Editor Version 5.00
- [HKEY_USERSS-1-5-18\Software\Microsoft\Windows\CurrentVersion\Run]
- "CTFMON.EXE"=
- *******************
- reged version 0.1 110511, (c) Petter N Hagen
- Hive </mnt/sdb1/Documents and Settings/NetworkService/NTUSER.DAT> name (from header): <tings\NetworkService\ntuser.dat>
- ROOT KEY at offset: 0x001020 * Subkey indexing type is: 666c <lf>
- File size 303104 [4a000] bytes, containing 57 pages (+ 1 headerpage)
- Used for data: 4131/295200 blocks/bytes, unused: 139/1984 blocks/bytes.
- --- Import KEY <\Software\Microsoft\Windows\CurrentVersion\Run>
- END OF IMPORT, file </tmp/runWrite.reg>, operation SUCCEEDED!
- 1 keys
- 0 new keys added
- 1 values total
- Hives that have changed:
- # Name
- 0 </mnt/sdb1/Documents and Settings/NetworkService/NTUSER.DAT> - OK
- Modificada clave HKEY_USERS\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Run | Todos los valores a vacio
- *******************
- reged version 0.1 110511, (c) Petter N Hagen
- Hive </mnt/sdb1/Documents and Settings/NetworkService/NTUSER.DAT> name (from header): <tings\NetworkService\ntuser.dat>
- ROOT KEY at offset: 0x001020 * Subkey indexing type is: 666c <lf>
- File size 303104 [4a000] bytes, containing 57 pages (+ 1 headerpage)
- Used for data: 4130/295128 blocks/bytes, unused: 140/2056 blocks/bytes.
- --- Import KEY <\Software\Microsoft\Windows NT\CurrentVersion\Winlogon> with 2 values.
- --- Import KEY <\Software\Microsoft\Windows NT\CurrentVersion\Winlogon>
- END OF IMPORT, file </tmp/user.reg>, operation SUCCEEDED!
- 2 keys
- 0 new keys added
- 4 values total
- Hives that have changed:
- # Name
- 0 </mnt/sdb1/Documents and Settings/NetworkService/NTUSER.DAT> - OK
- Modificada clave HKEY_USERS\S-1-5-18\Software\Microsoft\Windows NT\CurrentVersion\Winlogon | Shell | Userinit
- *******************
- reged version 0.1 110511, (c) Petter N Hagen
- Hive </mnt/sdb1/Documents and Settings/NetworkService/NTUSER.DAT> name (from header): <tings\NetworkService\ntuser.dat>
- ROOT KEY at offset: 0x001020 * Subkey indexing type is: 666c <lf>
- File size 303104 [4a000] bytes, containing 57 pages (+ 1 headerpage)
- Used for data: 4134/295304 blocks/bytes, unused: 140/1880 blocks/bytes.
- --- Import KEY <\Software\Microsoft\Windows NT\CurrentVersion\Windows>
- END OF IMPORT, file </tmp/user.reg>, operation SUCCEEDED!
- 1 keys
- 0 new keys added
- 2 values total
- Hives that have changed:
- # Name
- 0 </mnt/sdb1/Documents and Settings/NetworkService/NTUSER.DAT> - OK
- Modificada clave HKEY_USERS\S-1-5-18\Software\Microsoft\Windows NT\CurrentVersion\Windows | Load
- NTUSER: /mnt/sdb1/Documents and Settings/vinagreta/NTUSER.DAT
- *******************
- reged version 0.1 110511, (c) Petter N Hagen
- Hive </mnt/sdb1/Documents and Settings/vinagreta/NTUSER.DAT> name (from header): <d Settings\vinagreta\ntuser.dat>
- ROOT KEY at offset: 0x001020 * Subkey indexing type is: 666c <lf>
- File size 5767168 [580000] bytes, containing 1210 pages (+ 1 headerpage)
- Used for data: 103925/5499760 blocks/bytes, unused: 8508/134480 blocks/bytes.
- Exporting to file '/tmp/runRead.reg'...
- Exporting key 'Run' with 0 subkeys and 1 values...
- *******************
- Fichero /tmp/runRead.reg
- Windows Registry Editor Version 5.00
- [HKEY_USERS\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Run]
- "ctfmon.exe"="C:\\WINDOWS\\system32\\ctfmon.exe"
- *******************
- Fichero /tmp/runWrite.reg
- Windows Registry Editor Version 5.00
- [HKEY_USERSS-1-5-18\Software\Microsoft\Windows\CurrentVersion\Run]
- "ctfmon.exe"=
- *******************
- reged version 0.1 110511, (c) Petter N Hagen
- Hive </mnt/sdb1/Documents and Settings/vinagreta/NTUSER.DAT> name (from header): <d Settings\vinagreta\ntuser.dat>
- ROOT KEY at offset: 0x001020 * Subkey indexing type is: 666c <lf>
- File size 5767168 [580000] bytes, containing 1210 pages (+ 1 headerpage)
- Used for data: 103925/5499760 blocks/bytes, unused: 8508/134480 blocks/bytes.
- --- Import KEY <\Software\Microsoft\Windows\CurrentVersion\Run>
- END OF IMPORT, file </tmp/runWrite.reg>, operation SUCCEEDED!
- 1 keys
- 0 new keys added
- 1 values total
- Hives that have changed:
- # Name
- 0 </mnt/sdb1/Documents and Settings/vinagreta/NTUSER.DAT> - OK
- Modificada clave HKEY_USERS\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Run | Todos los valores a vacio
- *******************
- reged version 0.1 110511, (c) Petter N Hagen
- Hive </mnt/sdb1/Documents and Settings/vinagreta/NTUSER.DAT> name (from header): <d Settings\vinagreta\ntuser.dat>
- ROOT KEY at offset: 0x001020 * Subkey indexing type is: 666c <lf>
- File size 5767168 [580000] bytes, containing 1210 pages (+ 1 headerpage)
- Used for data: 103924/5499688 blocks/bytes, unused: 8509/134552 blocks/bytes.
- --- Import KEY <\Software\Microsoft\Windows NT\CurrentVersion\Winlogon> with 2 values.
- --- Import KEY <\Software\Microsoft\Windows NT\CurrentVersion\Winlogon>
- END OF IMPORT, file </tmp/user.reg>, operation SUCCEEDED!
- 2 keys
- 0 new keys added
- 4 values total
- Hives that have changed:
- # Name
- 0 </mnt/sdb1/Documents and Settings/vinagreta/NTUSER.DAT> - OK
- Modificada clave HKEY_USERS\S-1-5-18\Software\Microsoft\Windows NT\CurrentVersion\Winlogon | Shell | Userinit
- *******************
- reged version 0.1 110511, (c) Petter N Hagen
- Hive </mnt/sdb1/Documents and Settings/vinagreta/NTUSER.DAT> name (from header): <d Settings\vinagreta\ntuser.dat>
- ROOT KEY at offset: 0x001020 * Subkey indexing type is: 666c <lf>
- File size 5767168 [580000] bytes, containing 1210 pages (+ 1 headerpage)
- Used for data: 103928/5499864 blocks/bytes, unused: 8511/134376 blocks/bytes.
- --- Import KEY <\Software\Microsoft\Windows NT\CurrentVersion\Windows>
- END OF IMPORT, file </tmp/user.reg>, operation SUCCEEDED!
- 1 keys
- 0 new keys added
- 2 values total
- Hives that have changed:
- # Name
- 0 </mnt/sdb1/Documents and Settings/vinagreta/NTUSER.DAT> - OK
- Modificada clave HKEY_USERS\S-1-5-18\Software\Microsoft\Windows NT\CurrentVersion\Windows | Load
- NTUSER: /mnt/sdb1/WINDOWS/system32/config/systemprofile/NtUser.dat
- *******************
- reged version 0.1 110511, (c) Petter N Hagen
- Hive </mnt/sdb1/WINDOWS/system32/config/systemprofile/NtUser.dat> name (from header): <em32\config\SYSTEM~1\NtUser.dat>
- ROOT KEY at offset: 0x001020 * Subkey indexing type is: 666c <lf>
- File size 262144 [40000] bytes, containing 1 pages (+ 1 headerpage)
- Used for data: 2/264 blocks/bytes, unused: 1/3800 blocks/bytes.
- Exporting to file '/tmp/runRead.reg'...
- export_subkey: Key 'Software\Microsoft\Windows\CurrentVersion\Run' not found!
- *******************
- Fichero /tmp/runRead.reg
- Windows Registry Editor Version 5.00
- *******************
- Fichero /tmp/runWrite.reg
- Windows Registry Editor Version 5.00
- *******************
- reged version 0.1 110511, (c) Petter N Hagen
- Hive </mnt/sdb1/WINDOWS/system32/config/systemprofile/NtUser.dat> name (from header): <em32\config\SYSTEM~1\NtUser.dat>
- ROOT KEY at offset: 0x001020 * Subkey indexing type is: 666c <lf>
- File size 262144 [40000] bytes, containing 1 pages (+ 1 headerpage)
- Used for data: 2/264 blocks/bytes, unused: 1/3800 blocks/bytes.
- END OF IMPORT, file </tmp/runWrite.reg>, operation SUCCEEDED!
- 0 keys
- 0 new keys added
- 0 values total
- Hives that have changed:
- # Name
- None!
- Modificada clave HKEY_USERS\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Run | Todos los valores a vacio
- *******************
- reged version 0.1 110511, (c) Petter N Hagen
- Hive </mnt/sdb1/WINDOWS/system32/config/systemprofile/NtUser.dat> name (from header): <em32\config\SYSTEM~1\NtUser.dat>
- ROOT KEY at offset: 0x001020 * Subkey indexing type is: 666c <lf>
- File size 262144 [40000] bytes, containing 1 pages (+ 1 headerpage)
- Used for data: 2/264 blocks/bytes, unused: 1/3800 blocks/bytes.
- --- Import KEY <\Software\Microsoft\Windows NT\CurrentVersion\Winlogon> [added <Software>] [added <Microsoft>] [added <Windows NT>] [added <CurrentVersion>] [added <Winlogon>] with 2 values.
- --- Import KEY <\Software\Microsoft\Windows NT\CurrentVersion\Winlogon>
- END OF IMPORT, file </tmp/user.reg>, operation SUCCEEDED!
- 2 keys
- 5 new keys added
- 4 values total
- Hives that have changed:
- # Name
- 0 </mnt/sdb1/WINDOWS/system32/config/systemprofile/NtUser.dat> - OK
- Modificada clave HKEY_USERS\S-1-5-18\Software\Microsoft\Windows NT\CurrentVersion\Winlogon | Shell | Userinit
- *******************
- reged version 0.1 110511, (c) Petter N Hagen
- Hive </mnt/sdb1/WINDOWS/system32/config/systemprofile/NtUser.dat> name (from header): <em32\config\SYSTEM~1\NtUser.dat>
- ROOT KEY at offset: 0x001020 * Subkey indexing type is: 666c <lf>
- File size 262144 [40000] bytes, containing 1 pages (+ 1 headerpage)
- Used for data: 17/1056 blocks/bytes, unused: 4/3008 blocks/bytes.
- --- Import KEY <\Software\Microsoft\Windows NT\CurrentVersion\Windows> [added <Windows>]
- END OF IMPORT, file </tmp/user.reg>, operation SUCCEEDED!
- 1 keys
- 1 new keys added
- 2 values total
- Hives that have changed:
- # Name
- 0 </mnt/sdb1/WINDOWS/system32/config/systemprofile/NtUser.dat> - OK
- Modificada clave HKEY_USERS\S-1-5-18\Software\Microsoft\Windows NT\CurrentVersion\Windows | Load
- NTUSER: /mnt/sdb1/WINDOWS/repair/ntuser.dat
- *******************
- reged version 0.1 110511, (c) Petter N Hagen
- Hive </mnt/sdb1/WINDOWS/repair/ntuser.dat> name (from header): <>
- ROOT KEY at offset: 0x001020 * Subkey indexing type is: 666c <lf>
- File size 241664 [3b000] bytes, containing 58 pages (+ 1 headerpage)
- Used for data: 4185/234472 blocks/bytes, unused: 127/1240 blocks/bytes.
- Exporting to file '/tmp/runRead.reg'...
- Exporting key 'Run' with 0 subkeys and 1 values...
- *******************
- Fichero /tmp/runRead.reg
- Windows Registry Editor Version 5.00
- [HKEY_USERS\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Run]
- "CTFMON.EXE"="C:\\WINDOWS\\system32\\CTFMON.EXE"
- *******************
- Fichero /tmp/runWrite.reg
- Windows Registry Editor Version 5.00
- [HKEY_USERSS-1-5-18\Software\Microsoft\Windows\CurrentVersion\Run]
- "CTFMON.EXE"=
- *******************
- reged version 0.1 110511, (c) Petter N Hagen
- Hive </mnt/sdb1/WINDOWS/repair/ntuser.dat> name (from header): <>
- ROOT KEY at offset: 0x001020 * Subkey indexing type is: 666c <lf>
- File size 241664 [3b000] bytes, containing 58 pages (+ 1 headerpage)
- Used for data: 4185/234472 blocks/bytes, unused: 127/1240 blocks/bytes.
- --- Import KEY <\Software\Microsoft\Windows\CurrentVersion\Run>
- END OF IMPORT, file </tmp/runWrite.reg>, operation SUCCEEDED!
- 1 keys
- 0 new keys added
- 1 values total
- Hives that have changed:
- # Name
- 0 </mnt/sdb1/WINDOWS/repair/ntuser.dat> - OK
- Modificada clave HKEY_USERS\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Run | Todos los valores a vacio
- *******************
- reged version 0.1 110511, (c) Petter N Hagen
- Hive </mnt/sdb1/WINDOWS/repair/ntuser.dat> name (from header): <>
- ROOT KEY at offset: 0x001020 * Subkey indexing type is: 666c <lf>
- File size 241664 [3b000] bytes, containing 58 pages (+ 1 headerpage)
- Used for data: 4184/234400 blocks/bytes, unused: 128/1312 blocks/bytes.
- --- Import KEY <\Software\Microsoft\Windows NT\CurrentVersion\Winlogon> with 2 values.
- --- Import KEY <\Software\Microsoft\Windows NT\CurrentVersion\Winlogon> alloc_block: failed to alloc 40 bytes, trying to expand hive..
- add_bin: request size = 40 [28], rounded to 4096 [1000]
- add_bin: old buffer size = 241664 [3b000]
- add_bin: firs nonbin off = 241664 [3b000]
- add_bin: free at end = 0 [0]
- add_bin: new buffer size = 262144 [40000]
- add_bin: adjusting size field in REGF: 241664 [3b000]
- END OF IMPORT, file </tmp/user.reg>, operation SUCCEEDED!
- 2 keys
- 0 new keys added
- 4 values total
- Hives that have changed:
- # Name
- 0 </mnt/sdb1/WINDOWS/repair/ntuser.dat> - OK WARNING: File was expanded! Experimental! Use at own risk!
- Modificada clave HKEY_USERS\S-1-5-18\Software\Microsoft\Windows NT\CurrentVersion\Winlogon | Shell | Userinit
- *******************
- reged version 0.1 110511, (c) Petter N Hagen
- Hive </mnt/sdb1/WINDOWS/repair/ntuser.dat> name (from header): <>
- ROOT KEY at offset: 0x001020 * Subkey indexing type is: 666c <lf>
- File size 262144 [40000] bytes, containing 59 pages (+ 1 headerpage)
- Used for data: 4188/234584 blocks/bytes, unused: 131/5192 blocks/bytes.
- --- Import KEY <\Software\Microsoft\Windows NT\CurrentVersion\Windows>
- END OF IMPORT, file </tmp/user.reg>, operation SUCCEEDED!
- 1 keys
- 0 new keys added
- 2 values total
- Hives that have changed:
- # Name
- 0 </mnt/sdb1/WINDOWS/repair/ntuser.dat> - OK
- Modificada clave HKEY_USERS\S-1-5-18\Software\Microsoft\Windows NT\CurrentVersion\Windows | Load
- User: S-1-5-19
- NTUSER: /mnt/sdb1/Documents and Settings/Default User/NTUSER.DAT
- *******************
- reged version 0.1 110511, (c) Petter N Hagen
- Hive </mnt/sdb1/Documents and Settings/Default User/NTUSER.DAT> name (from header): <ettings\Default User\NtUser.dat>
- ROOT KEY at offset: 0x001020 * Subkey indexing type is: 666c <lf>
- File size 262144 [40000] bytes, containing 59 pages (+ 1 headerpage)
- Used for data: 4194/234976 blocks/bytes, unused: 129/4800 blocks/bytes.
- Exporting to file '/tmp/runRead.reg'...
- Exporting key 'Run' with 0 subkeys and 1 values...
- *******************
- Fichero /tmp/runRead.reg
- Windows Registry Editor Version 5.00
- [HKEY_USERS\S-1-5-19\Software\Microsoft\Windows\CurrentVersion\Run]
- "CTFMON.EXE"=""
- *******************
- Fichero /tmp/runWrite.reg
- Windows Registry Editor Version 5.00
- [HKEY_USERSS-1-5-19\Software\Microsoft\Windows\CurrentVersion\Run]
- "CTFMON.EXE"=
- *******************
- reged version 0.1 110511, (c) Petter N Hagen
- Hive </mnt/sdb1/Documents and Settings/Default User/NTUSER.DAT> name (from header): <ettings\Default User\NtUser.dat>
- ROOT KEY at offset: 0x001020 * Subkey indexing type is: 666c <lf>
- File size 262144 [40000] bytes, containing 59 pages (+ 1 headerpage)
- Used for data: 4194/234976 blocks/bytes, unused: 129/4800 blocks/bytes.
- --- Import KEY <\Software\Microsoft\Windows\CurrentVersion\Run>
- END OF IMPORT, file </tmp/runWrite.reg>, operation SUCCEEDED!
- 1 keys
- 0 new keys added
- 1 values total
- Hives that have changed:
- # Name
- 0 </mnt/sdb1/Documents and Settings/Default User/NTUSER.DAT> - OK
- Modificada clave HKEY_USERS\S-1-5-19\Software\Microsoft\Windows\CurrentVersion\Run | Todos los valores a vacio
- *******************
- reged version 0.1 110511, (c) Petter N Hagen
- Hive </mnt/sdb1/Documents and Settings/Default User/NTUSER.DAT> name (from header): <ettings\Default User\NtUser.dat>
- ROOT KEY at offset: 0x001020 * Subkey indexing type is: 666c <lf>
- File size 262144 [40000] bytes, containing 59 pages (+ 1 headerpage)
- Used for data: 4194/234976 blocks/bytes, unused: 129/4800 blocks/bytes.
- --- Import KEY <\Software\Microsoft\Windows NT\CurrentVersion\Winlogon> with 2 values.
- --- Import KEY <\Software\Microsoft\Windows NT\CurrentVersion\Winlogon>
- END OF IMPORT, file </tmp/user.reg>, operation SUCCEEDED!
- 2 keys
- 0 new keys added
- 4 values total
- Hives that have changed:
- # Name
- 0 </mnt/sdb1/Documents and Settings/Default User/NTUSER.DAT> - OK
- Modificada clave HKEY_USERS\S-1-5-19\Software\Microsoft\Windows NT\CurrentVersion\Winlogon | Shell | Userinit
- *******************
- reged version 0.1 110511, (c) Petter N Hagen
- Hive </mnt/sdb1/Documents and Settings/Default User/NTUSER.DAT> name (from header): <ettings\Default User\NtUser.dat>
- ROOT KEY at offset: 0x001020 * Subkey indexing type is: 666c <lf>
- File size 262144 [40000] bytes, containing 59 pages (+ 1 headerpage)
- Used for data: 4194/234976 blocks/bytes, unused: 129/4800 blocks/bytes.
- --- Import KEY <\Software\Microsoft\Windows NT\CurrentVersion\Windows>
- END OF IMPORT, file </tmp/user.reg>, operation SUCCEEDED!
- 1 keys
- 0 new keys added
- 2 values total
- Hives that have changed:
- # Name
- 0 </mnt/sdb1/Documents and Settings/Default User/NTUSER.DAT> - OK
- Modificada clave HKEY_USERS\S-1-5-19\Software\Microsoft\Windows NT\CurrentVersion\Windows | Load
- NTUSER: /mnt/sdb1/Documents and Settings/LocalService/NTUSER.DAT
- *******************
- reged version 0.1 110511, (c) Petter N Hagen
- Hive </mnt/sdb1/Documents and Settings/LocalService/NTUSER.DAT> name (from header): <ettings\LocalService\ntuser.dat>
- ROOT KEY at offset: 0x001020 * Subkey indexing type is: 666c <lf>
- File size 262144 [40000] bytes, containing 58 pages (+ 1 headerpage)
- Used for data: 4167/230808 blocks/bytes, unused: 142/4904 blocks/bytes.
- Exporting to file '/tmp/runRead.reg'...
- Exporting key 'Run' with 0 subkeys and 1 values...
- *******************
- Fichero /tmp/runRead.reg
- Windows Registry Editor Version 5.00
- [HKEY_USERS\S-1-5-19\Software\Microsoft\Windows\CurrentVersion\Run]
- "CTFMON.EXE"=""
- *******************
- Fichero /tmp/runWrite.reg
- Windows Registry Editor Version 5.00
- [HKEY_USERSS-1-5-19\Software\Microsoft\Windows\CurrentVersion\Run]
- "CTFMON.EXE"=
- *******************
- reged version 0.1 110511, (c) Petter N Hagen
- Hive </mnt/sdb1/Documents and Settings/LocalService/NTUSER.DAT> name (from header): <ettings\LocalService\ntuser.dat>
- ROOT KEY at offset: 0x001020 * Subkey indexing type is: 666c <lf>
- File size 262144 [40000] bytes, containing 58 pages (+ 1 headerpage)
- Used for data: 4167/230808 blocks/bytes, unused: 142/4904 blocks/bytes.
- --- Import KEY <\Software\Microsoft\Windows\CurrentVersion\Run>
- END OF IMPORT, file </tmp/runWrite.reg>, operation SUCCEEDED!
- 1 keys
- 0 new keys added
- 1 values total
- Hives that have changed:
- # Name
- 0 </mnt/sdb1/Documents and Settings/LocalService/NTUSER.DAT> - OK
- Modificada clave HKEY_USERS\S-1-5-19\Software\Microsoft\Windows\CurrentVersion\Run | Todos los valores a vacio
- *******************
- reged version 0.1 110511, (c) Petter N Hagen
- Hive </mnt/sdb1/Documents and Settings/LocalService/NTUSER.DAT> name (from header): <ettings\LocalService\ntuser.dat>
- ROOT KEY at offset: 0x001020 * Subkey indexing type is: 666c <lf>
- File size 262144 [40000] bytes, containing 58 pages (+ 1 headerpage)
- Used for data: 4167/230808 blocks/bytes, unused: 142/4904 blocks/bytes.
- --- Import KEY <\Software\Microsoft\Windows NT\CurrentVersion\Winlogon> with 2 values.
- --- Import KEY <\Software\Microsoft\Windows NT\CurrentVersion\Winlogon>
- END OF IMPORT, file </tmp/user.reg>, operation SUCCEEDED!
- 2 keys
- 0 new keys added
- 4 values total
- Hives that have changed:
- # Name
- 0 </mnt/sdb1/Documents and Settings/LocalService/NTUSER.DAT> - OK
- Modificada clave HKEY_USERS\S-1-5-19\Software\Microsoft\Windows NT\CurrentVersion\Winlogon | Shell | Userinit
- *******************
- reged version 0.1 110511, (c) Petter N Hagen
- Hive </mnt/sdb1/Documents and Settings/LocalService/NTUSER.DAT> name (from header): <ettings\LocalService\ntuser.dat>
- ROOT KEY at offset: 0x001020 * Subkey indexing type is: 666c <lf>
- File size 262144 [40000] bytes, containing 58 pages (+ 1 headerpage)
- Used for data: 4167/230808 blocks/bytes, unused: 142/4904 blocks/bytes.
- --- Import KEY <\Software\Microsoft\Windows NT\CurrentVersion\Windows>
- END OF IMPORT, file </tmp/user.reg>, operation SUCCEEDED!
- 1 keys
- 0 new keys added
- 2 values total
- Hives that have changed:
- # Name
- 0 </mnt/sdb1/Documents and Settings/LocalService/NTUSER.DAT> - OK
- Modificada clave HKEY_USERS\S-1-5-19\Software\Microsoft\Windows NT\CurrentVersion\Windows | Load
- NTUSER: /mnt/sdb1/Documents and Settings/NetworkService/NTUSER.DAT
- *******************
- reged version 0.1 110511, (c) Petter N Hagen
- Hive </mnt/sdb1/Documents and Settings/NetworkService/NTUSER.DAT> name (from header): <tings\NetworkService\ntuser.dat>
- ROOT KEY at offset: 0x001020 * Subkey indexing type is: 666c <lf>
- File size 303104 [4a000] bytes, containing 57 pages (+ 1 headerpage)
- Used for data: 4135/295336 blocks/bytes, unused: 140/1848 blocks/bytes.
- Exporting to file '/tmp/runRead.reg'...
- Exporting key 'Run' with 0 subkeys and 1 values...
- *******************
- Fichero /tmp/runRead.reg
- Windows Registry Editor Version 5.00
- [HKEY_USERS\S-1-5-19\Software\Microsoft\Windows\CurrentVersion\Run]
- "CTFMON.EXE"=""
- *******************
- Fichero /tmp/runWrite.reg
- Windows Registry Editor Version 5.00
- [HKEY_USERSS-1-5-19\Software\Microsoft\Windows\CurrentVersion\Run]
- "CTFMON.EXE"=
- *******************
- reged version 0.1 110511, (c) Petter N Hagen
- Hive </mnt/sdb1/Documents and Settings/NetworkService/NTUSER.DAT> name (from header): <tings\NetworkService\ntuser.dat>
- ROOT KEY at offset: 0x001020 * Subkey indexing type is: 666c <lf>
- File size 303104 [4a000] bytes, containing 57 pages (+ 1 headerpage)
- Used for data: 4135/295336 blocks/bytes, unused: 140/1848 blocks/bytes.
- --- Import KEY <\Software\Microsoft\Windows\CurrentVersion\Run>
- END OF IMPORT, file </tmp/runWrite.reg>, operation SUCCEEDED!
- 1 keys
- 0 new keys added
- 1 values total
- Hives that have changed:
- # Name
- 0 </mnt/sdb1/Documents and Settings/NetworkService/NTUSER.DAT> - OK
- Modificada clave HKEY_USERS\S-1-5-19\Software\Microsoft\Windows\CurrentVersion\Run | Todos los valores a vacio
- *******************
- reged version 0.1 110511, (c) Petter N Hagen
- Hive </mnt/sdb1/Documents and Settings/NetworkService/NTUSER.DAT> name (from header): <tings\NetworkService\ntuser.dat>
- ROOT KEY at offset: 0x001020 * Subkey indexing type is: 666c <lf>
- File size 303104 [4a000] bytes, containing 57 pages (+ 1 headerpage)
- Used for data: 4135/295336 blocks/bytes, unused: 140/1848 blocks/bytes.
- --- Import KEY <\Software\Microsoft\Windows NT\CurrentVersion\Winlogon> with 2 values.
- --- Import KEY <\Software\Microsoft\Windows NT\CurrentVersion\Winlogon>
- END OF IMPORT, file </tmp/user.reg>, operation SUCCEEDED!
- 2 keys
- 0 new keys added
- 4 values total
- Hives that have changed:
- # Name
- 0 </mnt/sdb1/Documents and Settings/NetworkService/NTUSER.DAT> - OK
- Modificada clave HKEY_USERS\S-1-5-19\Software\Microsoft\Windows NT\CurrentVersion\Winlogon | Shell | Userinit
- *******************
- reged version 0.1 110511, (c) Petter N Hagen
- Hive </mnt/sdb1/Documents and Settings/NetworkService/NTUSER.DAT> name (from header): <tings\NetworkService\ntuser.dat>
- ROOT KEY at offset: 0x001020 * Subkey indexing type is: 666c <lf>
- File size 303104 [4a000] bytes, containing 57 pages (+ 1 headerpage)
- Used for data: 4135/295336 blocks/bytes, unused: 140/1848 blocks/bytes.
- --- Import KEY <\Software\Microsoft\Windows NT\CurrentVersion\Windows>
- END OF IMPORT, file </tmp/user.reg>, operation SUCCEEDED!
- 1 keys
- 0 new keys added
- 2 values total
- Hives that have changed:
- # Name
- 0 </mnt/sdb1/Documents and Settings/NetworkService/NTUSER.DAT> - OK
- Modificada clave HKEY_USERS\S-1-5-19\Software\Microsoft\Windows NT\CurrentVersion\Windows | Load
- NTUSER: /mnt/sdb1/Documents and Settings/vinagreta/NTUSER.DAT
- *******************
- reged version 0.1 110511, (c) Petter N Hagen
- Hive </mnt/sdb1/Documents and Settings/vinagreta/NTUSER.DAT> name (from header): <d Settings\vinagreta\ntuser.dat>
- ROOT KEY at offset: 0x001020 * Subkey indexing type is: 666c <lf>
- File size 5767168 [580000] bytes, containing 1210 pages (+ 1 headerpage)
- Used for data: 103929/5499896 blocks/bytes, unused: 8510/134344 blocks/bytes.
- Exporting to file '/tmp/runRead.reg'...
- Exporting key 'Run' with 0 subkeys and 1 values...
- *******************
- Fichero /tmp/runRead.reg
- Windows Registry Editor Version 5.00
- [HKEY_USERS\S-1-5-19\Software\Microsoft\Windows\CurrentVersion\Run]
- "ctfmon.exe"=""
- *******************
- Fichero /tmp/runWrite.reg
- Windows Registry Editor Version 5.00
- [HKEY_USERSS-1-5-19\Software\Microsoft\Windows\CurrentVersion\Run]
- "ctfmon.exe"=
- *******************
- reged version 0.1 110511, (c) Petter N Hagen
- Hive </mnt/sdb1/Documents and Settings/vinagreta/NTUSER.DAT> name (from header): <d Settings\vinagreta\ntuser.dat>
- ROOT KEY at offset: 0x001020 * Subkey indexing type is: 666c <lf>
- File size 5767168 [580000] bytes, containing 1210 pages (+ 1 headerpage)
- Used for data: 103929/5499896 blocks/bytes, unused: 8510/134344 blocks/bytes.
- --- Import KEY <\Software\Microsoft\Windows\CurrentVersion\Run>
- END OF IMPORT, file </tmp/runWrite.reg>, operation SUCCEEDED!
- 1 keys
- 0 new keys added
- 1 values total
- Hives that have changed:
- # Name
- 0 </mnt/sdb1/Documents and Settings/vinagreta/NTUSER.DAT> - OK
- Modificada clave HKEY_USERS\S-1-5-19\Software\Microsoft\Windows\CurrentVersion\Run | Todos los valores a vacio
- *******************
- reged version 0.1 110511, (c) Petter N Hagen
- Hive </mnt/sdb1/Documents and Settings/vinagreta/NTUSER.DAT> name (from header): <d Settings\vinagreta\ntuser.dat>
- ROOT KEY at offset: 0x001020 * Subkey indexing type is: 666c <lf>
- File size 5767168 [580000] bytes, containing 1210 pages (+ 1 headerpage)
- Used for data: 103929/5499896 blocks/bytes, unused: 8510/134344 blocks/bytes.
- --- Import KEY <\Software\Microsoft\Windows NT\CurrentVersion\Winlogon> with 2 values.
- --- Import KEY <\Software\Microsoft\Windows NT\CurrentVersion\Winlogon>
- END OF IMPORT, file </tmp/user.reg>, operation SUCCEEDED!
- 2 keys
- 0 new keys added
- 4 values total
- Hives that have changed:
- # Name
- 0 </mnt/sdb1/Documents and Settings/vinagreta/NTUSER.DAT> - OK
- Modificada clave HKEY_USERS\S-1-5-19\Software\Microsoft\Windows NT\CurrentVersion\Winlogon | Shell | Userinit
- *******************
- reged version 0.1 110511, (c) Petter N Hagen
- Hive </mnt/sdb1/Documents and Settings/vinagreta/NTUSER.DAT> name (from header): <d Settings\vinagreta\ntuser.dat>
- ROOT KEY at offset: 0x001020 * Subkey indexing type is: 666c <lf>
- File size 5767168 [580000] bytes, containing 1210 pages (+ 1 headerpage)
- Used for data: 103929/5499896 blocks/bytes, unused: 8510/134344 blocks/bytes.
- --- Import KEY <\Software\Microsoft\Windows NT\CurrentVersion\Windows>
- END OF IMPORT, file </tmp/user.reg>, operation SUCCEEDED!
- 1 keys
- 0 new keys added
- 2 values total
- Hives that have changed:
- # Name
- 0 </mnt/sdb1/Documents and Settings/vinagreta/NTUSER.DAT> - OK
- Modificada clave HKEY_USERS\S-1-5-19\Software\Microsoft\Windows NT\CurrentVersion\Windows | Load
- NTUSER: /mnt/sdb1/WINDOWS/system32/config/systemprofile/NtUser.dat
- *******************
- reged version 0.1 110511, (c) Petter N Hagen
- Hive </mnt/sdb1/WINDOWS/system32/config/systemprofile/NtUser.dat> name (from header): <em32\config\SYSTEM~1\NtUser.dat>
- ROOT KEY at offset: 0x001020 * Subkey indexing type is: 666c <lf>
- File size 262144 [40000] bytes, containing 1 pages (+ 1 headerpage)
- Used for data: 21/1240 blocks/bytes, unused: 5/2824 blocks/bytes.
- Exporting to file '/tmp/runRead.reg'...
- export_subkey: Key 'Software\Microsoft\Windows\CurrentVersion\Run' not found!
- *******************
- Fichero /tmp/runRead.reg
- Windows Registry Editor Version 5.00
- *******************
- Fichero /tmp/runWrite.reg
- Windows Registry Editor Version 5.00
- *******************
- reged version 0.1 110511, (c) Petter N Hagen
- Hive </mnt/sdb1/WINDOWS/system32/config/systemprofile/NtUser.dat> name (from header): <em32\config\SYSTEM~1\NtUser.dat>
- ROOT KEY at offset: 0x001020 * Subkey indexing type is: 666c <lf>
- File size 262144 [40000] bytes, containing 1 pages (+ 1 headerpage)
- Used for data: 21/1240 blocks/bytes, unused: 5/2824 blocks/bytes.
- END OF IMPORT, file </tmp/runWrite.reg>, operation SUCCEEDED!
- 0 keys
- 0 new keys added
- 0 values total
- Hives that have changed:
- # Name
- None!
- Modificada clave HKEY_USERS\S-1-5-19\Software\Microsoft\Windows\CurrentVersion\Run | Todos los valores a vacio
- *******************
- reged version 0.1 110511, (c) Petter N Hagen
- Hive </mnt/sdb1/WINDOWS/system32/config/systemprofile/NtUser.dat> name (from header): <em32\config\SYSTEM~1\NtUser.dat>
- ROOT KEY at offset: 0x001020 * Subkey indexing type is: 666c <lf>
- File size 262144 [40000] bytes, containing 1 pages (+ 1 headerpage)
- Used for data: 21/1240 blocks/bytes, unused: 5/2824 blocks/bytes.
- --- Import KEY <\Software\Microsoft\Windows NT\CurrentVersion\Winlogon> with 2 values.
- --- Import KEY <\Software\Microsoft\Windows NT\CurrentVersion\Winlogon>
- END OF IMPORT, file </tmp/user.reg>, operation SUCCEEDED!
- 2 keys
- 0 new keys added
- 4 values total
- Hives that have changed:
- # Name
- 0 </mnt/sdb1/WINDOWS/system32/config/systemprofile/NtUser.dat> - OK
- Modificada clave HKEY_USERS\S-1-5-19\Software\Microsoft\Windows NT\CurrentVersion\Winlogon | Shell | Userinit
- *******************
- reged version 0.1 110511, (c) Petter N Hagen
- Hive </mnt/sdb1/WINDOWS/system32/config/systemprofile/NtUser.dat> name (from header): <em32\config\SYSTEM~1\NtUser.dat>
- ROOT KEY at offset: 0x001020 * Subkey indexing type is: 666c <lf>
- File size 262144 [40000] bytes, containing 1 pages (+ 1 headerpage)
- Used for data: 21/1240 blocks/bytes, unused: 5/2824 blocks/bytes.
- --- Import KEY <\Software\Microsoft\Windows NT\CurrentVersion\Windows>
- END OF IMPORT, file </tmp/user.reg>, operation SUCCEEDED!
- 1 keys
- 0 new keys added
- 2 values total
- Hives that have changed:
- # Name
- 0 </mnt/sdb1/WINDOWS/system32/config/systemprofile/NtUser.dat> - OK
- Modificada clave HKEY_USERS\S-1-5-19\Software\Microsoft\Windows NT\CurrentVersion\Windows | Load
- NTUSER: /mnt/sdb1/WINDOWS/repair/ntuser.dat
- *******************
- reged version 0.1 110511, (c) Petter N Hagen
- Hive </mnt/sdb1/WINDOWS/repair/ntuser.dat> name (from header): <>
- ROOT KEY at offset: 0x001020 * Subkey indexing type is: 666c <lf>
- File size 262144 [40000] bytes, containing 59 pages (+ 1 headerpage)
- Used for data: 4189/234624 blocks/bytes, unused: 132/5152 blocks/bytes.
- Exporting to file '/tmp/runRead.reg'...
- Exporting key 'Run' with 0 subkeys and 1 values...
- *******************
- Fichero /tmp/runRead.reg
- Windows Registry Editor Version 5.00
- [HKEY_USERS\S-1-5-19\Software\Microsoft\Windows\CurrentVersion\Run]
- "CTFMON.EXE"=""
- *******************
- Fichero /tmp/runWrite.reg
- Windows Registry Editor Version 5.00
- [HKEY_USERSS-1-5-19\Software\Microsoft\Windows\CurrentVersion\Run]
- "CTFMON.EXE"=
- *******************
- reged version 0.1 110511, (c) Petter N Hagen
- Hive </mnt/sdb1/WINDOWS/repair/ntuser.dat> name (from header): <>
- ROOT KEY at offset: 0x001020 * Subkey indexing type is: 666c <lf>
- File size 262144 [40000] bytes, containing 59 pages (+ 1 headerpage)
- Used for data: 4189/234624 blocks/bytes, unused: 132/5152 blocks/bytes.
- --- Import KEY <\Software\Microsoft\Windows\CurrentVersion\Run>
- END OF IMPORT, file </tmp/runWrite.reg>, operation SUCCEEDED!
- 1 keys
- 0 new keys added
- 1 values total
- Hives that have changed:
- # Name
- 0 </mnt/sdb1/WINDOWS/repair/ntuser.dat> - OK
- Modificada clave HKEY_USERS\S-1-5-19\Software\Microsoft\Windows\CurrentVersion\Run | Todos los valores a vacio
- *******************
- reged version 0.1 110511, (c) Petter N Hagen
- Hive </mnt/sdb1/WINDOWS/repair/ntuser.dat> name (from header): <>
- ROOT KEY at offset: 0x001020 * Subkey indexing type is: 666c <lf>
- File size 262144 [40000] bytes, containing 59 pages (+ 1 headerpage)
- Used for data: 4189/234624 blocks/bytes, unused: 132/5152 blocks/bytes.
- --- Import KEY <\Software\Microsoft\Windows NT\CurrentVersion\Winlogon> with 2 values.
- --- Import KEY <\Software\Microsoft\Windows NT\CurrentVersion\Winlogon>
- END OF IMPORT, file </tmp/user.reg>, operation SUCCEEDED!
- 2 keys
- 0 new keys added
- 4 values total
- Hives that have changed:
- # Name
- 0 </mnt/sdb1/WINDOWS/repair/ntuser.dat> - OK
- Modificada clave HKEY_USERS\S-1-5-19\Software\Microsoft\Windows NT\CurrentVersion\Winlogon | Shell | Userinit
- *******************
- reged version 0.1 110511, (c) Petter N Hagen
- Hive </mnt/sdb1/WINDOWS/repair/ntuser.dat> name (from header): <>
- ROOT KEY at offset: 0x001020 * Subkey indexing type is: 666c <lf>
- File size 262144 [40000] bytes, containing 59 pages (+ 1 headerpage)
- Used for data: 4189/234624 blocks/bytes, unused: 132/5152 blocks/bytes.
- --- Import KEY <\Software\Microsoft\Windows NT\CurrentVersion\Windows>
- END OF IMPORT, file </tmp/user.reg>, operation SUCCEEDED!
- 1 keys
- 0 new keys added
- 2 values total
- Hives that have changed:
- # Name
- 0 </mnt/sdb1/WINDOWS/repair/ntuser.dat> - OK
- Modificada clave HKEY_USERS\S-1-5-19\Software\Microsoft\Windows NT\CurrentVersion\Windows | Load
- User: S-1-5-20
- NTUSER: /mnt/sdb1/Documents and Settings/Default User/NTUSER.DAT
- *******************
- reged version 0.1 110511, (c) Petter N Hagen
- Hive </mnt/sdb1/Documents and Settings/Default User/NTUSER.DAT> name (from header): <ettings\Default User\NtUser.dat>
- ROOT KEY at offset: 0x001020 * Subkey indexing type is: 666c <lf>
- File size 262144 [40000] bytes, containing 59 pages (+ 1 headerpage)
- Used for data: 4194/234976 blocks/bytes, unused: 129/4800 blocks/bytes.
- Exporting to file '/tmp/runRead.reg'...
- Exporting key 'Run' with 0 subkeys and 1 values...
- *******************
- Fichero /tmp/runRead.reg
- Windows Registry Editor Version 5.00
- [HKEY_USERS\S-1-5-20\Software\Microsoft\Windows\CurrentVersion\Run]
- "CTFMON.EXE"=""
- *******************
- Fichero /tmp/runWrite.reg
- Windows Registry Editor Version 5.00
- [HKEY_USERSS-1-5-20\Software\Microsoft\Windows\CurrentVersion\Run]
- "CTFMON.EXE"=
- *******************
- reged version 0.1 110511, (c) Petter N Hagen
- Hive </mnt/sdb1/Documents and Settings/Default User/NTUSER.DAT> name (from header): <ettings\Default User\NtUser.dat>
- ROOT KEY at offset: 0x001020 * Subkey indexing type is: 666c <lf>
- File size 262144 [40000] bytes, containing 59 pages (+ 1 headerpage)
- Used for data: 4194/234976 blocks/bytes, unused: 129/4800 blocks/bytes.
- --- Import KEY <\Software\Microsoft\Windows\CurrentVersion\Run>
- END OF IMPORT, file </tmp/runWrite.reg>, operation SUCCEEDED!
- 1 keys
- 0 new keys added
- 1 values total
- Hives that have changed:
- # Name
- 0 </mnt/sdb1/Documents and Settings/Default User/NTUSER.DAT> - OK
- Modificada clave HKEY_USERS\S-1-5-20\Software\Microsoft\Windows\CurrentVersion\Run | Todos los valores a vacio
- *******************
- reged version 0.1 110511, (c) Petter N Hagen
- Hive </mnt/sdb1/Documents and Settings/Default User/NTUSER.DAT> name (from header): <ettings\Default User\NtUser.dat>
- ROOT KEY at offset: 0x001020 * Subkey indexing type is: 666c <lf>
- File size 262144 [40000] bytes, containing 59 pages (+ 1 headerpage)
- Used for data: 4194/234976 blocks/bytes, unused: 129/4800 blocks/bytes.
- --- Import KEY <\Software\Microsoft\Windows NT\CurrentVersion\Winlogon> with 2 values.
- --- Import KEY <\Software\Microsoft\Windows NT\CurrentVersion\Winlogon>
- END OF IMPORT, file </tmp/user.reg>, operation SUCCEEDED!
- 2 keys
- 0 new keys added
- 4 values total
- Hives that have changed:
- # Name
- 0 </mnt/sdb1/Documents and Settings/Default User/NTUSER.DAT> - OK
- Modificada clave HKEY_USERS\S-1-5-20\Software\Microsoft\Windows NT\CurrentVersion\Winlogon | Shell | Userinit
- *******************
- reged version 0.1 110511, (c) Petter N Hagen
- Hive </mnt/sdb1/Documents and Settings/Default User/NTUSER.DAT> name (from header): <ettings\Default User\NtUser.dat>
- ROOT KEY at offset: 0x001020 * Subkey indexing type is: 666c <lf>
- File size 262144 [40000] bytes, containing 59 pages (+ 1 headerpage)
- Used for data: 4194/234976 blocks/bytes, unused: 129/4800 blocks/bytes.
- --- Import KEY <\Software\Microsoft\Windows NT\CurrentVersion\Windows>
- END OF IMPORT, file </tmp/user.reg>, operation SUCCEEDED!
- 1 keys
- 0 new keys added
- 2 values total
- Hives that have changed:
- # Name
- 0 </mnt/sdb1/Documents and Settings/Default User/NTUSER.DAT> - OK
- Modificada clave HKEY_USERS\S-1-5-20\Software\Microsoft\Windows NT\CurrentVersion\Windows | Load
- NTUSER: /mnt/sdb1/Documents and Settings/LocalService/NTUSER.DAT
- *******************
- reged version 0.1 110511, (c) Petter N Hagen
- Hive </mnt/sdb1/Documents and Settings/LocalService/NTUSER.DAT> name (from header): <ettings\LocalService\ntuser.dat>
- ROOT KEY at offset: 0x001020 * Subkey indexing type is: 666c <lf>
- File size 262144 [40000] bytes, containing 58 pages (+ 1 headerpage)
- Used for data: 4167/230808 blocks/bytes, unused: 142/4904 blocks/bytes.
- Exporting to file '/tmp/runRead.reg'...
- Exporting key 'Run' with 0 subkeys and 1 values...
- *******************
- Fichero /tmp/runRead.reg
- Windows Registry Editor Version 5.00
- [HKEY_USERS\S-1-5-20\Software\Microsoft\Windows\CurrentVersion\Run]
- "CTFMON.EXE"=""
- *******************
- Fichero /tmp/runWrite.reg
- Windows Registry Editor Version 5.00
- [HKEY_USERSS-1-5-20\Software\Microsoft\Windows\CurrentVersion\Run]
- "CTFMON.EXE"=
- *******************
- reged version 0.1 110511, (c) Petter N Hagen
- Hive </mnt/sdb1/Documents and Settings/LocalService/NTUSER.DAT> name (from header): <ettings\LocalService\ntuser.dat>
- ROOT KEY at offset: 0x001020 * Subkey indexing type is: 666c <lf>
- File size 262144 [40000] bytes, containing 58 pages (+ 1 headerpage)
- Used for data: 4167/230808 blocks/bytes, unused: 142/4904 blocks/bytes.
- --- Import KEY <\Software\Microsoft\Windows\CurrentVersion\Run>
- END OF IMPORT, file </tmp/runWrite.reg>, operation SUCCEEDED!
- 1 keys
- 0 new keys added
- 1 values total
- Hives that have changed:
- # Name
- 0 </mnt/sdb1/Documents and Settings/LocalService/NTUSER.DAT> - OK
- Modificada clave HKEY_USERS\S-1-5-20\Software\Microsoft\Windows\CurrentVersion\Run | Todos los valores a vacio
- *******************
- reged version 0.1 110511, (c) Petter N Hagen
- Hive </mnt/sdb1/Documents and Settings/LocalService/NTUSER.DAT> name (from header): <ettings\LocalService\ntuser.dat>
- ROOT KEY at offset: 0x001020 * Subkey indexing type is: 666c <lf>
- File size 262144 [40000] bytes, containing 58 pages (+ 1 headerpage)
- Used for data: 4167/230808 blocks/bytes, unused: 142/4904 blocks/bytes.
- --- Import KEY <\Software\Microsoft\Windows NT\CurrentVersion\Winlogon> with 2 values.
- --- Import KEY <\Software\Microsoft\Windows NT\CurrentVersion\Winlogon>
- END OF IMPORT, file </tmp/user.reg>, operation SUCCEEDED!
- 2 keys
- 0 new keys added
- 4 values total
- Hives that have changed:
- # Name
- 0 </mnt/sdb1/Documents and Settings/LocalService/NTUSER.DAT> - OK
- Modificada clave HKEY_USERS\S-1-5-20\Software\Microsoft\Windows NT\CurrentVersion\Winlogon | Shell | Userinit
- *******************
- reged version 0.1 110511, (c) Petter N Hagen
- Hive </mnt/sdb1/Documents and Settings/LocalService/NTUSER.DAT> name (from header): <ettings\LocalService\ntuser.dat>
- ROOT KEY at offset: 0x001020 * Subkey indexing type is: 666c <lf>
- File size 262144 [40000] bytes, containing 58 pages (+ 1 headerpage)
- Used for data: 4167/230808 blocks/bytes, unused: 142/4904 blocks/bytes.
- --- Import KEY <\Software\Microsoft\Windows NT\CurrentVersion\Windows>
- END OF IMPORT, file </tmp/user.reg>, operation SUCCEEDED!
- 1 keys
- 0 new keys added
- 2 values total
- Hives that have changed:
- # Name
- 0 </mnt/sdb1/Documents and Settings/LocalService/NTUSER.DAT> - OK
- Modificada clave HKEY_USERS\S-1-5-20\Software\Microsoft\Windows NT\CurrentVersion\Windows | Load
- NTUSER: /mnt/sdb1/Documents and Settings/NetworkService/NTUSER.DAT
- *******************
- reged version 0.1 110511, (c) Petter N Hagen
- Hive </mnt/sdb1/Documents and Settings/NetworkService/NTUSER.DAT> name (from header): <tings\NetworkService\ntuser.dat>
- ROOT KEY at offset: 0x001020 * Subkey indexing type is: 666c <lf>
- File size 303104 [4a000] bytes, containing 57 pages (+ 1 headerpage)
- Used for data: 4135/295336 blocks/bytes, unused: 140/1848 blocks/bytes.
- Exporting to file '/tmp/runRead.reg'...
- Exporting key 'Run' with 0 subkeys and 1 values...
- *******************
- Fichero /tmp/runRead.reg
- Windows Registry Editor Version 5.00
- [HKEY_USERS\S-1-5-20\Software\Microsoft\Windows\CurrentVersion\Run]
- "CTFMON.EXE"=""
- *******************
- Fichero /tmp/runWrite.reg
- Windows Registry Editor Version 5.00
- [HKEY_USERSS-1-5-20\Software\Microsoft\Windows\CurrentVersion\Run]
- "CTFMON.EXE"=
- *******************
- reged version 0.1 110511, (c) Petter N Hagen
- Hive </mnt/sdb1/Documents and Settings/NetworkService/NTUSER.DAT> name (from header): <tings\NetworkService\ntuser.dat>
- ROOT KEY at offset: 0x001020 * Subkey indexing type is: 666c <lf>
- File size 303104 [4a000] bytes, containing 57 pages (+ 1 headerpage)
- Used for data: 4135/295336 blocks/bytes, unused: 140/1848 blocks/bytes.
- --- Import KEY <\Software\Microsoft\Windows\CurrentVersion\Run>
- END OF IMPORT, file </tmp/runWrite.reg>, operation SUCCEEDED!
- 1 keys
- 0 new keys added
- 1 values total
- Hives that have changed:
- # Name
- 0 </mnt/sdb1/Documents and Settings/NetworkService/NTUSER.DAT> - OK
- Modificada clave HKEY_USERS\S-1-5-20\Software\Microsoft\Windows\CurrentVersion\Run | Todos los valores a vacio
- *******************
- reged version 0.1 110511, (c) Petter N Hagen
- Hive </mnt/sdb1/Documents and Settings/NetworkService/NTUSER.DAT> name (from header): <tings\NetworkService\ntuser.dat>
- ROOT KEY at offset: 0x001020 * Subkey indexing type is: 666c <lf>
- File size 303104 [4a000] bytes, containing 57 pages (+ 1 headerpage)
- Used for data: 4135/295336 blocks/bytes, unused: 140/1848 blocks/bytes.
- --- Import KEY <\Software\Microsoft\Windows NT\CurrentVersion\Winlogon> with 2 values.
- --- Import KEY <\Software\Microsoft\Windows NT\CurrentVersion\Winlogon>
- END OF IMPORT, file </tmp/user.reg>, operation SUCCEEDED!
- 2 keys
- 0 new keys added
- 4 values total
- Hives that have changed:
- # Name
- 0 </mnt/sdb1/Documents and Settings/NetworkService/NTUSER.DAT> - OK
- Modificada clave HKEY_USERS\S-1-5-20\Software\Microsoft\Windows NT\CurrentVersion\Winlogon | Shell | Userinit
- *******************
- reged version 0.1 110511, (c) Petter N Hagen
- Hive </mnt/sdb1/Documents and Settings/NetworkService/NTUSER.DAT> name (from header): <tings\NetworkService\ntuser.dat>
- ROOT KEY at offset: 0x001020 * Subkey indexing type is: 666c <lf>
- File size 303104 [4a000] bytes, containing 57 pages (+ 1 headerpage)
- Used for data: 4135/295336 blocks/bytes, unused: 140/1848 blocks/bytes.
- --- Import KEY <\Software\Microsoft\Windows NT\CurrentVersion\Windows>
- END OF IMPORT, file </tmp/user.reg>, operation SUCCEEDED!
- 1 keys
- 0 new keys added
- 2 values total
- Hives that have changed:
- # Name
- 0 </mnt/sdb1/Documents and Settings/NetworkService/NTUSER.DAT> - OK
- Modificada clave HKEY_USERS\S-1-5-20\Software\Microsoft\Windows NT\CurrentVersion\Windows | Load
- NTUSER: /mnt/sdb1/Documents and Settings/vinagreta/NTUSER.DAT
- *******************
- reged version 0.1 110511, (c) Petter N Hagen
- Hive </mnt/sdb1/Documents and Settings/vinagreta/NTUSER.DAT> name (from header): <d Settings\vinagreta\ntuser.dat>
- ROOT KEY at offset: 0x001020 * Subkey indexing type is: 666c <lf>
- File size 5767168 [580000] bytes, containing 1210 pages (+ 1 headerpage)
- Used for data: 103929/5499896 blocks/bytes, unused: 8510/134344 blocks/bytes.
- Exporting to file '/tmp/runRead.reg'...
- Exporting key 'Run' with 0 subkeys and 1 values...
- *******************
- Fichero /tmp/runRead.reg
- Windows Registry Editor Version 5.00
- [HKEY_USERS\S-1-5-20\Software\Microsoft\Windows\CurrentVersion\Run]
- "ctfmon.exe"=""
- *******************
- Fichero /tmp/runWrite.reg
- Windows Registry Editor Version 5.00
- [HKEY_USERSS-1-5-20\Software\Microsoft\Windows\CurrentVersion\Run]
- "ctfmon.exe"=
- *******************
- reged version 0.1 110511, (c) Petter N Hagen
- Hive </mnt/sdb1/Documents and Settings/vinagreta/NTUSER.DAT> name (from header): <d Settings\vinagreta\ntuser.dat>
- ROOT KEY at offset: 0x001020 * Subkey indexing type is: 666c <lf>
- File size 5767168 [580000] bytes, containing 1210 pages (+ 1 headerpage)
- Used for data: 103929/5499896 blocks/bytes, unused: 8510/134344 blocks/bytes.
- --- Import KEY <\Software\Microsoft\Windows\CurrentVersion\Run>
- END OF IMPORT, file </tmp/runWrite.reg>, operation SUCCEEDED!
- 1 keys
- 0 new keys added
- 1 values total
- Hives that have changed:
- # Name
- 0 </mnt/sdb1/Documents and Settings/vinagreta/NTUSER.DAT> - OK
- Modificada clave HKEY_USERS\S-1-5-20\Software\Microsoft\Windows\CurrentVersion\Run | Todos los valores a vacio
- *******************
- reged version 0.1 110511, (c) Petter N Hagen
- Hive </mnt/sdb1/Documents and Settings/vinagreta/NTUSER.DAT> name (from header): <d Settings\vinagreta\ntuser.dat>
- ROOT KEY at offset: 0x001020 * Subkey indexing type is: 666c <lf>
- File size 5767168 [580000] bytes, containing 1210 pages (+ 1 headerpage)
- Used for data: 103929/5499896 blocks/bytes, unused: 8510/134344 blocks/bytes.
- --- Import KEY <\Software\Microsoft\Windows NT\CurrentVersion\Winlogon> with 2 values.
- --- Import KEY <\Software\Microsoft\Windows NT\CurrentVersion\Winlogon>
- END OF IMPORT, file </tmp/user.reg>, operation SUCCEEDED!
- 2 keys
- 0 new keys added
- 4 values total
- Hives that have changed:
- # Name
- 0 </mnt/sdb1/Documents and Settings/vinagreta/NTUSER.DAT> - OK
- Modificada clave HKEY_USERS\S-1-5-20\Software\Microsoft\Windows NT\CurrentVersion\Winlogon | Shell | Userinit
- *******************
- reged version 0.1 110511, (c) Petter N Hagen
- Hive </mnt/sdb1/Documents and Settings/vinagreta/NTUSER.DAT> name (from header): <d Settings\vinagreta\ntuser.dat>
- ROOT KEY at offset: 0x001020 * Subkey indexing type is: 666c <lf>
- File size 5767168 [580000] bytes, containing 1210 pages (+ 1 headerpage)
- Used for data: 103929/5499896 blocks/bytes, unused: 8510/134344 blocks/bytes.
- --- Import KEY <\Software\Microsoft\Windows NT\CurrentVersion\Windows>
- END OF IMPORT, file </tmp/user.reg>, operation SUCCEEDED!
- 1 keys
- 0 new keys added
- 2 values total
- Hives that have changed:
- # Name
- 0 </mnt/sdb1/Documents and Settings/vinagreta/NTUSER.DAT> - OK
- Modificada clave HKEY_USERS\S-1-5-20\Software\Microsoft\Windows NT\CurrentVersion\Windows | Load
- NTUSER: /mnt/sdb1/WINDOWS/system32/config/systemprofile/NtUser.dat
- *******************
- reged version 0.1 110511, (c) Petter N Hagen
- Hive </mnt/sdb1/WINDOWS/system32/config/systemprofile/NtUser.dat> name (from header): <em32\config\SYSTEM~1\NtUser.dat>
- ROOT KEY at offset: 0x001020 * Subkey indexing type is: 666c <lf>
- File size 262144 [40000] bytes, containing 1 pages (+ 1 headerpage)
- Used for data: 21/1240 blocks/bytes, unused: 5/2824 blocks/bytes.
- Exporting to file '/tmp/runRead.reg'...
- export_subkey: Key 'Software\Microsoft\Windows\CurrentVersion\Run' not found!
- *******************
- Fichero /tmp/runRead.reg
- Windows Registry Editor Version 5.00
- *******************
- Fichero /tmp/runWrite.reg
- Windows Registry Editor Version 5.00
- *******************
- reged version 0.1 110511, (c) Petter N Hagen
- Hive </mnt/sdb1/WINDOWS/system32/config/systemprofile/NtUser.dat> name (from header): <em32\config\SYSTEM~1\NtUser.dat>
- ROOT KEY at offset: 0x001020 * Subkey indexing type is: 666c <lf>
- File size 262144 [40000] bytes, containing 1 pages (+ 1 headerpage)
- Used for data: 21/1240 blocks/bytes, unused: 5/2824 blocks/bytes.
- END OF IMPORT, file </tmp/runWrite.reg>, operation SUCCEEDED!
- 0 keys
- 0 new keys added
- 0 values total
- Hives that have changed:
- # Name
- None!
- Modificada clave HKEY_USERS\S-1-5-20\Software\Microsoft\Windows\CurrentVersion\Run | Todos los valores a vacio
- *******************
- reged version 0.1 110511, (c) Petter N Hagen
- Hive </mnt/sdb1/WINDOWS/system32/config/systemprofile/NtUser.dat> name (from header): <em32\config\SYSTEM~1\NtUser.dat>
- ROOT KEY at offset: 0x001020 * Subkey indexing type is: 666c <lf>
- File size 262144 [40000] bytes, containing 1 pages (+ 1 headerpage)
- Used for data: 21/1240 blocks/bytes, unused: 5/2824 blocks/bytes.
- --- Import KEY <\Software\Microsoft\Windows NT\CurrentVersion\Winlogon> with 2 values.
- --- Import KEY <\Software\Microsoft\Windows NT\CurrentVersion\Winlogon>
- END OF IMPORT, file </tmp/user.reg>, operation SUCCEEDED!
- 2 keys
- 0 new keys added
- 4 values total
- Hives that have changed:
- # Name
- 0 </mnt/sdb1/WINDOWS/system32/config/systemprofile/NtUser.dat> - OK
- Modificada clave HKEY_USERS\S-1-5-20\Software\Microsoft\Windows NT\CurrentVersion\Winlogon | Shell | Userinit
- *******************
- reged version 0.1 110511, (c) Petter N Hagen
- Hive </mnt/sdb1/WINDOWS/system32/config/systemprofile/NtUser.dat> name (from header): <em32\config\SYSTEM~1\NtUser.dat>
- ROOT KEY at offset: 0x001020 * Subkey indexing type is: 666c <lf>
- File size 262144 [40000] bytes, containing 1 pages (+ 1 headerpage)
- Used for data: 21/1240 blocks/bytes, unused: 5/2824 blocks/bytes.
- --- Import KEY <\Software\Microsoft\Windows NT\CurrentVersion\Windows>
- END OF IMPORT, file </tmp/user.reg>, operation SUCCEEDED!
- 1 keys
- 0 new keys added
- 2 values total
- Hives that have changed:
- # Name
- 0 </mnt/sdb1/WINDOWS/system32/config/systemprofile/NtUser.dat> - OK
- Modificada clave HKEY_USERS\S-1-5-20\Software\Microsoft\Windows NT\CurrentVersion\Windows | Load
- NTUSER: /mnt/sdb1/WINDOWS/repair/ntuser.dat
- *******************
- reged version 0.1 110511, (c) Petter N Hagen
- Hive </mnt/sdb1/WINDOWS/repair/ntuser.dat> name (from header): <>
- ROOT KEY at offset: 0x001020 * Subkey indexing type is: 666c <lf>
- File size 262144 [40000] bytes, containing 59 pages (+ 1 headerpage)
- Used for data: 4189/234624 blocks/bytes, unused: 132/5152 blocks/bytes.
- Exporting to file '/tmp/runRead.reg'...
- Exporting key 'Run' with 0 subkeys and 1 values...
- *******************
- Fichero /tmp/runRead.reg
- Windows Registry Editor Version 5.00
- [HKEY_USERS\S-1-5-20\Software\Microsoft\Windows\CurrentVersion\Run]
- "CTFMON.EXE"=""
- *******************
- Fichero /tmp/runWrite.reg
- Windows Registry Editor Version 5.00
- [HKEY_USERSS-1-5-20\Software\Microsoft\Windows\CurrentVersion\Run]
- "CTFMON.EXE"=
- *******************
- reged version 0.1 110511, (c) Petter N Hagen
- Hive </mnt/sdb1/WINDOWS/repair/ntuser.dat> name (from header): <>
- ROOT KEY at offset: 0x001020 * Subkey indexing type is: 666c <lf>
- File size 262144 [40000] bytes, containing 59 pages (+ 1 headerpage)
- Used for data: 4189/234624 blocks/bytes, unused: 132/5152 blocks/bytes.
- --- Import KEY <\Software\Microsoft\Windows\CurrentVersion\Run>
- END OF IMPORT, file </tmp/runWrite.reg>, operation SUCCEEDED!
- 1 keys
- 0 new keys added
- 1 values total
- Hives that have changed:
- # Name
- 0 </mnt/sdb1/WINDOWS/repair/ntuser.dat> - OK
- Modificada clave HKEY_USERS\S-1-5-20\Software\Microsoft\Windows\CurrentVersion\Run | Todos los valores a vacio
- *******************
- reged version 0.1 110511, (c) Petter N Hagen
- Hive </mnt/sdb1/WINDOWS/repair/ntuser.dat> name (from header): <>
- ROOT KEY at offset: 0x001020 * Subkey indexing type is: 666c <lf>
- File size 262144 [40000] bytes, containing 59 pages (+ 1 headerpage)
- Used for data: 4189/234624 blocks/bytes, unused: 132/5152 blocks/bytes.
- --- Import KEY <\Software\Microsoft\Windows NT\CurrentVersion\Winlogon> with 2 values.
- --- Import KEY <\Software\Microsoft\Windows NT\CurrentVersion\Winlogon>
- END OF IMPORT, file </tmp/user.reg>, operation SUCCEEDED!
- 2 keys
- 0 new keys added
- 4 values total
- Hives that have changed:
- # Name
- 0 </mnt/sdb1/WINDOWS/repair/ntuser.dat> - OK
- Modificada clave HKEY_USERS\S-1-5-20\Software\Microsoft\Windows NT\CurrentVersion\Winlogon | Shell | Userinit
- *******************
- reged version 0.1 110511, (c) Petter N Hagen
- Hive </mnt/sdb1/WINDOWS/repair/ntuser.dat> name (from header): <>
- ROOT KEY at offset: 0x001020 * Subkey indexing type is: 666c <lf>
- File size 262144 [40000] bytes, containing 59 pages (+ 1 headerpage)
- Used for data: 4189/234624 blocks/bytes, unused: 132/5152 blocks/bytes.
- --- Import KEY <\Software\Microsoft\Windows NT\CurrentVersion\Windows>
- END OF IMPORT, file </tmp/user.reg>, operation SUCCEEDED!
- 1 keys
- 0 new keys added
- 2 values total
- Hives that have changed:
- # Name
- 0 </mnt/sdb1/WINDOWS/repair/ntuser.dat> - OK
- Modificada clave HKEY_USERS\S-1-5-20\Software\Microsoft\Windows NT\CurrentVersion\Windows | Load
- User: S-1-5-21-606747145-746137067-682003330-1003
- NTUSER: /mnt/sdb1/Documents and Settings/Default User/NTUSER.DAT
- *******************
- reged version 0.1 110511, (c) Petter N Hagen
- Hive </mnt/sdb1/Documents and Settings/Default User/NTUSER.DAT> name (from header): <ettings\Default User\NtUser.dat>
- ROOT KEY at offset: 0x001020 * Subkey indexing type is: 666c <lf>
- File size 262144 [40000] bytes, containing 59 pages (+ 1 headerpage)
- Used for data: 4194/234976 blocks/bytes, unused: 129/4800 blocks/bytes.
- Exporting to file '/tmp/runRead.reg'...
- Exporting key 'Run' with 0 subkeys and 1 values...
- *******************
- Fichero /tmp/runRead.reg
- Windows Registry Editor Version 5.00
- [HKEY_USERS\S-1-5-21-606747145-746137067-682003330-1003\Software\Microsoft\Windows\CurrentVersion\Run]
- "CTFMON.EXE"=""
- *******************
- Fichero /tmp/runWrite.reg
- Windows Registry Editor Version 5.00
- [HKEY_USERSS-1-5-21-606747145-746137067-682003330-1003\Software\Microsoft\Windows\CurrentVersion\Run]
- "CTFMON.EXE"=
- *******************
- reged version 0.1 110511, (c) Petter N Hagen
- Hive </mnt/sdb1/Documents and Settings/Default User/NTUSER.DAT> name (from header): <ettings\Default User\NtUser.dat>
- ROOT KEY at offset: 0x001020 * Subkey indexing type is: 666c <lf>
- File size 262144 [40000] bytes, containing 59 pages (+ 1 headerpage)
- Used for data: 4194/234976 blocks/bytes, unused: 129/4800 blocks/bytes.
- --- Import KEY <\Software\Microsoft\Windows\CurrentVersion\Run>
- END OF IMPORT, file </tmp/runWrite.reg>, operation SUCCEEDED!
- 1 keys
- 0 new keys added
- 1 values total
- Hives that have changed:
- # Name
- 0 </mnt/sdb1/Documents and Settings/Default User/NTUSER.DAT> - OK
- Modificada clave HKEY_USERS\S-1-5-21-606747145-746137067-682003330-1003\Software\Microsoft\Windows\CurrentVersion\Run | Todos los valores a vacio
- *******************
- reged version 0.1 110511, (c) Petter N Hagen
- Hive </mnt/sdb1/Documents and Settings/Default User/NTUSER.DAT> name (from header): <ettings\Default User\NtUser.dat>
- ROOT KEY at offset: 0x001020 * Subkey indexing type is: 666c <lf>
- File size 262144 [40000] bytes, containing 59 pages (+ 1 headerpage)
- Used for data: 4194/234976 blocks/bytes, unused: 129/4800 blocks/bytes.
- --- Import KEY <\Software\Microsoft\Windows NT\CurrentVersion\Winlogon> with 2 values.
- --- Import KEY <\Software\Microsoft\Windows NT\CurrentVersion\Winlogon>
- END OF IMPORT, file </tmp/user.reg>, operation SUCCEEDED!
- 2 keys
- 0 new keys added
- 4 values total
- Hives that have changed:
- # Name
- 0 </mnt/sdb1/Documents and Settings/Default User/NTUSER.DAT> - OK
- Modificada clave HKEY_USERS\S-1-5-21-606747145-746137067-682003330-1003\Software\Microsoft\Windows NT\CurrentVersion\Winlogon | Shell | Userinit
- *******************
- reged version 0.1 110511, (c) Petter N Hagen
- Hive </mnt/sdb1/Documents and Settings/Default User/NTUSER.DAT> name (from header): <ettings\Default User\NtUser.dat>
- ROOT KEY at offset: 0x001020 * Subkey indexing type is: 666c <lf>
- File size 262144 [40000] bytes, containing 59 pages (+ 1 headerpage)
- Used for data: 4194/234976 blocks/bytes, unused: 129/4800 blocks/bytes.
- --- Import KEY <\Software\Microsoft\Windows NT\CurrentVersion\Windows>
- END OF IMPORT, file </tmp/user.reg>, operation SUCCEEDED!
- 1 keys
- 0 new keys added
- 2 values total
- Hives that have changed:
- # Name
- 0 </mnt/sdb1/Documents and Settings/Default User/NTUSER.DAT> - OK
- Modificada clave HKEY_USERS\S-1-5-21-606747145-746137067-682003330-1003\Software\Microsoft\Windows NT\CurrentVersion\Windows | Load
- NTUSER: /mnt/sdb1/Documents and Settings/LocalService/NTUSER.DAT
- *******************
- reged version 0.1 110511, (c) Petter N Hagen
- Hive </mnt/sdb1/Documents and Settings/LocalService/NTUSER.DAT> name (from header): <ettings\LocalService\ntuser.dat>
- ROOT KEY at offset: 0x001020 * Subkey indexing type is: 666c <lf>
- File size 262144 [40000] bytes, containing 58 pages (+ 1 headerpage)
- Used for data: 4167/230808 blocks/bytes, unused: 142/4904 blocks/bytes.
- Exporting to file '/tmp/runRead.reg'...
- Exporting key 'Run' with 0 subkeys and 1 values...
- *******************
- Fichero /tmp/runRead.reg
- Windows Registry Editor Version 5.00
- [HKEY_USERS\S-1-5-21-606747145-746137067-682003330-1003\Software\Microsoft\Windows\CurrentVersion\Run]
- "CTFMON.EXE"=""
- *******************
- Fichero /tmp/runWrite.reg
- Windows Registry Editor Version 5.00
- [HKEY_USERSS-1-5-21-606747145-746137067-682003330-1003\Software\Microsoft\Windows\CurrentVersion\Run]
- "CTFMON.EXE"=
- *******************
- reged version 0.1 110511, (c) Petter N Hagen
- Hive </mnt/sdb1/Documents and Settings/LocalService/NTUSER.DAT> name (from header): <ettings\LocalService\ntuser.dat>
- ROOT KEY at offset: 0x001020 * Subkey indexing type is: 666c <lf>
- File size 262144 [40000] bytes, containing 58 pages (+ 1 headerpage)
- Used for data: 4167/230808 blocks/bytes, unused: 142/4904 blocks/bytes.
- --- Import KEY <\Software\Microsoft\Windows\CurrentVersion\Run>
- END OF IMPORT, file </tmp/runWrite.reg>, operation SUCCEEDED!
- 1 keys
- 0 new keys added
- 1 values total
- Hives that have changed:
- # Name
- 0 </mnt/sdb1/Documents and Settings/LocalService/NTUSER.DAT> - OK
- Modificada clave HKEY_USERS\S-1-5-21-606747145-746137067-682003330-1003\Software\Microsoft\Windows\CurrentVersion\Run | Todos los valores a vacio
- *******************
- reged version 0.1 110511, (c) Petter N Hagen
- Hive </mnt/sdb1/Documents and Settings/LocalService/NTUSER.DAT> name (from header): <ettings\LocalService\ntuser.dat>
- ROOT KEY at offset: 0x001020 * Subkey indexing type is: 666c <lf>
- File size 262144 [40000] bytes, containing 58 pages (+ 1 headerpage)
- Used for data: 4167/230808 blocks/bytes, unused: 142/4904 blocks/bytes.
- --- Import KEY <\Software\Microsoft\Windows NT\CurrentVersion\Winlogon> with 2 values.
- --- Import KEY <\Software\Microsoft\Windows NT\CurrentVersion\Winlogon>
- END OF IMPORT, file </tmp/user.reg>, operation SUCCEEDED!
- 2 keys
- 0 new keys added
- 4 values total
- Hives that have changed:
- # Name
- 0 </mnt/sdb1/Documents and Settings/LocalService/NTUSER.DAT> - OK
- Modificada clave HKEY_USERS\S-1-5-21-606747145-746137067-682003330-1003\Software\Microsoft\Windows NT\CurrentVersion\Winlogon | Shell | Userinit
- *******************
- reged version 0.1 110511, (c) Petter N Hagen
- Hive </mnt/sdb1/Documents and Settings/LocalService/NTUSER.DAT> name (from header): <ettings\LocalService\ntuser.dat>
- ROOT KEY at offset: 0x001020 * Subkey indexing type is: 666c <lf>
- File size 262144 [40000] bytes, containing 58 pages (+ 1 headerpage)
- Used for data: 4167/230808 blocks/bytes, unused: 142/4904 blocks/bytes.
- --- Import KEY <\Software\Microsoft\Windows NT\CurrentVersion\Windows>
- END OF IMPORT, file </tmp/user.reg>, operation SUCCEEDED!
- 1 keys
- 0 new keys added
- 2 values total
- Hives that have changed:
- # Name
- 0 </mnt/sdb1/Documents and Settings/LocalService/NTUSER.DAT> - OK
- Modificada clave HKEY_USERS\S-1-5-21-606747145-746137067-682003330-1003\Software\Microsoft\Windows NT\CurrentVersion\Windows | Load
- NTUSER: /mnt/sdb1/Documents and Settings/NetworkService/NTUSER.DAT
- *******************
- reged version 0.1 110511, (c) Petter N Hagen
- Hive </mnt/sdb1/Documents and Settings/NetworkService/NTUSER.DAT> name (from header): <tings\NetworkService\ntuser.dat>
- ROOT KEY at offset: 0x001020 * Subkey indexing type is: 666c <lf>
- File size 303104 [4a000] bytes, containing 57 pages (+ 1 headerpage)
- Used for data: 4135/295336 blocks/bytes, unused: 140/1848 blocks/bytes.
- Exporting to file '/tmp/runRead.reg'...
- Exporting key 'Run' with 0 subkeys and 1 values...
- *******************
- Fichero /tmp/runRead.reg
- Windows Registry Editor Version 5.00
- [HKEY_USERS\S-1-5-21-606747145-746137067-682003330-1003\Software\Microsoft\Windows\CurrentVersion\Run]
- "CTFMON.EXE"=""
- *******************
- Fichero /tmp/runWrite.reg
- Windows Registry Editor Version 5.00
- [HKEY_USERSS-1-5-21-606747145-746137067-682003330-1003\Software\Microsoft\Windows\CurrentVersion\Run]
- "CTFMON.EXE"=
- *******************
- reged version 0.1 110511, (c) Petter N Hagen
- Hive </mnt/sdb1/Documents and Settings/NetworkService/NTUSER.DAT> name (from header): <tings\NetworkService\ntuser.dat>
- ROOT KEY at offset: 0x001020 * Subkey indexing type is: 666c <lf>
- File size 303104 [4a000] bytes, containing 57 pages (+ 1 headerpage)
- Used for data: 4135/295336 blocks/bytes, unused: 140/1848 blocks/bytes.
- --- Import KEY <\Software\Microsoft\Windows\CurrentVersion\Run>
- END OF IMPORT, file </tmp/runWrite.reg>, operation SUCCEEDED!
- 1 keys
- 0 new keys added
- 1 values total
- Hives that have changed:
- # Name
- 0 </mnt/sdb1/Documents and Settings/NetworkService/NTUSER.DAT> - OK
- Modificada clave HKEY_USERS\S-1-5-21-606747145-746137067-682003330-1003\Software\Microsoft\Windows\CurrentVersion\Run | Todos los valores a vacio
- *******************
- reged version 0.1 110511, (c) Petter N Hagen
- Hive </mnt/sdb1/Documents and Settings/NetworkService/NTUSER.DAT> name (from header): <tings\NetworkService\ntuser.dat>
- ROOT KEY at offset: 0x001020 * Subkey indexing type is: 666c <lf>
- File size 303104 [4a000] bytes, containing 57 pages (+ 1 headerpage)
- Used for data: 4135/295336 blocks/bytes, unused: 140/1848 blocks/bytes.
- --- Import KEY <\Software\Microsoft\Windows NT\CurrentVersion\Winlogon> with 2 values.
- --- Import KEY <\Software\Microsoft\Windows NT\CurrentVersion\Winlogon>
- END OF IMPORT, file </tmp/user.reg>, operation SUCCEEDED!
- 2 keys
- 0 new keys added
- 4 values total
- Hives that have changed:
- # Name
- 0 </mnt/sdb1/Documents and Settings/NetworkService/NTUSER.DAT> - OK
- Modificada clave HKEY_USERS\S-1-5-21-606747145-746137067-682003330-1003\Software\Microsoft\Windows NT\CurrentVersion\Winlogon | Shell | Userinit
- *******************
- reged version 0.1 110511, (c) Petter N Hagen
- Hive </mnt/sdb1/Documents and Settings/NetworkService/NTUSER.DAT> name (from header): <tings\NetworkService\ntuser.dat>
- ROOT KEY at offset: 0x001020 * Subkey indexing type is: 666c <lf>
- File size 303104 [4a000] bytes, containing 57 pages (+ 1 headerpage)
- Used for data: 4135/295336 blocks/bytes, unused: 140/1848 blocks/bytes.
- --- Import KEY <\Software\Microsoft\Windows NT\CurrentVersion\Windows>
- END OF IMPORT, file </tmp/user.reg>, operation SUCCEEDED!
- 1 keys
- 0 new keys added
- 2 values total
- Hives that have changed:
- # Name
- 0 </mnt/sdb1/Documents and Settings/NetworkService/NTUSER.DAT> - OK
- Modificada clave HKEY_USERS\S-1-5-21-606747145-746137067-682003330-1003\Software\Microsoft\Windows NT\CurrentVersion\Windows | Load
- NTUSER: /mnt/sdb1/Documents and Settings/vinagreta/NTUSER.DAT
- *******************
- reged version 0.1 110511, (c) Petter N Hagen
- Hive </mnt/sdb1/Documents and Settings/vinagreta/NTUSER.DAT> name (from header): <d Settings\vinagreta\ntuser.dat>
- ROOT KEY at offset: 0x001020 * Subkey indexing type is: 666c <lf>
- File size 5767168 [580000] bytes, containing 1210 pages (+ 1 headerpage)
- Used for data: 103929/5499896 blocks/bytes, unused: 8510/134344 blocks/bytes.
- Exporting to file '/tmp/runRead.reg'...
- Exporting key 'Run' with 0 subkeys and 1 values...
- *******************
- Fichero /tmp/runRead.reg
- Windows Registry Editor Version 5.00
- [HKEY_USERS\S-1-5-21-606747145-746137067-682003330-1003\Software\Microsoft\Windows\CurrentVersion\Run]
- "ctfmon.exe"=""
- *******************
- Fichero /tmp/runWrite.reg
- Windows Registry Editor Version 5.00
- [HKEY_USERSS-1-5-21-606747145-746137067-682003330-1003\Software\Microsoft\Windows\CurrentVersion\Run]
- "ctfmon.exe"=
- *******************
- reged version 0.1 110511, (c) Petter N Hagen
- Hive </mnt/sdb1/Documents and Settings/vinagreta/NTUSER.DAT> name (from header): <d Settings\vinagreta\ntuser.dat>
- ROOT KEY at offset: 0x001020 * Subkey indexing type is: 666c <lf>
- File size 5767168 [580000] bytes, containing 1210 pages (+ 1 headerpage)
- Used for data: 103929/5499896 blocks/bytes, unused: 8510/134344 blocks/bytes.
- --- Import KEY <\Software\Microsoft\Windows\CurrentVersion\Run>
- END OF IMPORT, file </tmp/runWrite.reg>, operation SUCCEEDED!
- 1 keys
- 0 new keys added
- 1 values total
- Hives that have changed:
- # Name
- 0 </mnt/sdb1/Documents and Settings/vinagreta/NTUSER.DAT> - OK
- Modificada clave HKEY_USERS\S-1-5-21-606747145-746137067-682003330-1003\Software\Microsoft\Windows\CurrentVersion\Run | Todos los valores a vacio
- *******************
- reged version 0.1 110511, (c) Petter N Hagen
- Hive </mnt/sdb1/Documents and Settings/vinagreta/NTUSER.DAT> name (from header): <d Settings\vinagreta\ntuser.dat>
- ROOT KEY at offset: 0x001020 * Subkey indexing type is: 666c <lf>
- File size 5767168 [580000] bytes, containing 1210 pages (+ 1 headerpage)
- Used for data: 103929/5499896 blocks/bytes, unused: 8510/134344 blocks/bytes.
- --- Import KEY <\Software\Microsoft\Windows NT\CurrentVersion\Winlogon> with 2 values.
- --- Import KEY <\Software\Microsoft\Windows NT\CurrentVersion\Winlogon>
- END OF IMPORT, file </tmp/user.reg>, operation SUCCEEDED!
- 2 keys
- 0 new keys added
- 4 values total
- Hives that have changed:
- # Name
- 0 </mnt/sdb1/Documents and Settings/vinagreta/NTUSER.DAT> - OK
- Modificada clave HKEY_USERS\S-1-5-21-606747145-746137067-682003330-1003\Software\Microsoft\Windows NT\CurrentVersion\Winlogon | Shell | Userinit
- *******************
- reged version 0.1 110511, (c) Petter N Hagen
- Hive </mnt/sdb1/Documents and Settings/vinagreta/NTUSER.DAT> name (from header): <d Settings\vinagreta\ntuser.dat>
- ROOT KEY at offset: 0x001020 * Subkey indexing type is: 666c <lf>
- File size 5767168 [580000] bytes, containing 1210 pages (+ 1 headerpage)
- Used for data: 103929/5499896 blocks/bytes, unused: 8510/134344 blocks/bytes.
- --- Import KEY <\Software\Microsoft\Windows NT\CurrentVersion\Windows>
- END OF IMPORT, file </tmp/user.reg>, operation SUCCEEDED!
- 1 keys
- 0 new keys added
- 2 values total
- Hives that have changed:
- # Name
- 0 </mnt/sdb1/Documents and Settings/vinagreta/NTUSER.DAT> - OK
- Modificada clave HKEY_USERS\S-1-5-21-606747145-746137067-682003330-1003\Software\Microsoft\Windows NT\CurrentVersion\Windows | Load
- NTUSER: /mnt/sdb1/WINDOWS/system32/config/systemprofile/NtUser.dat
- *******************
- reged version 0.1 110511, (c) Petter N Hagen
- Hive </mnt/sdb1/WINDOWS/system32/config/systemprofile/NtUser.dat> name (from header): <em32\config\SYSTEM~1\NtUser.dat>
- ROOT KEY at offset: 0x001020 * Subkey indexing type is: 666c <lf>
- File size 262144 [40000] bytes, containing 1 pages (+ 1 headerpage)
- Used for data: 21/1240 blocks/bytes, unused: 5/2824 blocks/bytes.
- Exporting to file '/tmp/runRead.reg'...
- export_subkey: Key 'Software\Microsoft\Windows\CurrentVersion\Run' not found!
- *******************
- Fichero /tmp/runRead.reg
- Windows Registry Editor Version 5.00
- *******************
- Fichero /tmp/runWrite.reg
- Windows Registry Editor Version 5.00
- *******************
- reged version 0.1 110511, (c) Petter N Hagen
- Hive </mnt/sdb1/WINDOWS/system32/config/systemprofile/NtUser.dat> name (from header): <em32\config\SYSTEM~1\NtUser.dat>
- ROOT KEY at offset: 0x001020 * Subkey indexing type is: 666c <lf>
- File size 262144 [40000] bytes, containing 1 pages (+ 1 headerpage)
- Used for data: 21/1240 blocks/bytes, unused: 5/2824 blocks/bytes.
- END OF IMPORT, file </tmp/runWrite.reg>, operation SUCCEEDED!
- 0 keys
- 0 new keys added
- 0 values total
- Hives that have changed:
- # Name
- None!
- Modificada clave HKEY_USERS\S-1-5-21-606747145-746137067-682003330-1003\Software\Microsoft\Windows\CurrentVersion\Run | Todos los valores a vacio
- *******************
- reged version 0.1 110511, (c) Petter N Hagen
- Hive </mnt/sdb1/WINDOWS/system32/config/systemprofile/NtUser.dat> name (from header): <em32\config\SYSTEM~1\NtUser.dat>
- ROOT KEY at offset: 0x001020 * Subkey indexing type is: 666c <lf>
- File size 262144 [40000] bytes, containing 1 pages (+ 1 headerpage)
- Used for data: 21/1240 blocks/bytes, unused: 5/2824 blocks/bytes.
- --- Import KEY <\Software\Microsoft\Windows NT\CurrentVersion\Winlogon> with 2 values.
- --- Import KEY <\Software\Microsoft\Windows NT\CurrentVersion\Winlogon>
- END OF IMPORT, file </tmp/user.reg>, operation SUCCEEDED!
- 2 keys
- 0 new keys added
- 4 values total
- Hives that have changed:
- # Name
- 0 </mnt/sdb1/WINDOWS/system32/config/systemprofile/NtUser.dat> - OK
- Modificada clave HKEY_USERS\S-1-5-21-606747145-746137067-682003330-1003\Software\Microsoft\Windows NT\CurrentVersion\Winlogon | Shell | Userinit
- *******************
- reged version 0.1 110511, (c) Petter N Hagen
- Hive </mnt/sdb1/WINDOWS/system32/config/systemprofile/NtUser.dat> name (from header): <em32\config\SYSTEM~1\NtUser.dat>
- ROOT KEY at offset: 0x001020 * Subkey indexing type is: 666c <lf>
- File size 262144 [40000] bytes, containing 1 pages (+ 1 headerpage)
- Used for data: 21/1240 blocks/bytes, unused: 5/2824 blocks/bytes.
- --- Import KEY <\Software\Microsoft\Windows NT\CurrentVersion\Windows>
- END OF IMPORT, file </tmp/user.reg>, operation SUCCEEDED!
- 1 keys
- 0 new keys added
- 2 values total
- Hives that have changed:
- # Name
- 0 </mnt/sdb1/WINDOWS/system32/config/systemprofile/NtUser.dat> - OK
- Modificada clave HKEY_USERS\S-1-5-21-606747145-746137067-682003330-1003\Software\Microsoft\Windows NT\CurrentVersion\Windows | Load
- NTUSER: /mnt/sdb1/WINDOWS/repair/ntuser.dat
- *******************
- reged version 0.1 110511, (c) Petter N Hagen
- Hive </mnt/sdb1/WINDOWS/repair/ntuser.dat> name (from header): <>
- ROOT KEY at offset: 0x001020 * Subkey indexing type is: 666c <lf>
- File size 262144 [40000] bytes, containing 59 pages (+ 1 headerpage)
- Used for data: 4189/234624 blocks/bytes, unused: 132/5152 blocks/bytes.
- Exporting to file '/tmp/runRead.reg'...
- Exporting key 'Run' with 0 subkeys and 1 values...
- *******************
- Fichero /tmp/runRead.reg
- Windows Registry Editor Version 5.00
- [HKEY_USERS\S-1-5-21-606747145-746137067-682003330-1003\Software\Microsoft\Windows\CurrentVersion\Run]
- "CTFMON.EXE"=""
- *******************
- Fichero /tmp/runWrite.reg
- Windows Registry Editor Version 5.00
- [HKEY_USERSS-1-5-21-606747145-746137067-682003330-1003\Software\Microsoft\Windows\CurrentVersion\Run]
- "CTFMON.EXE"=
- *******************
- reged version 0.1 110511, (c) Petter N Hagen
- Hive </mnt/sdb1/WINDOWS/repair/ntuser.dat> name (from header): <>
- ROOT KEY at offset: 0x001020 * Subkey indexing type is: 666c <lf>
- File size 262144 [40000] bytes, containing 59 pages (+ 1 headerpage)
- Used for data: 4189/234624 blocks/bytes, unused: 132/5152 blocks/bytes.
- --- Import KEY <\Software\Microsoft\Windows\CurrentVersion\Run>
- END OF IMPORT, file </tmp/runWrite.reg>, operation SUCCEEDED!
- 1 keys
- 0 new keys added
- 1 values total
- Hives that have changed:
- # Name
- 0 </mnt/sdb1/WINDOWS/repair/ntuser.dat> - OK
- Modificada clave HKEY_USERS\S-1-5-21-606747145-746137067-682003330-1003\Software\Microsoft\Windows\CurrentVersion\Run | Todos los valores a vacio
- *******************
- reged version 0.1 110511, (c) Petter N Hagen
- Hive </mnt/sdb1/WINDOWS/repair/ntuser.dat> name (from header): <>
- ROOT KEY at offset: 0x001020 * Subkey indexing type is: 666c <lf>
- File size 262144 [40000] bytes, containing 59 pages (+ 1 headerpage)
- Used for data: 4189/234624 blocks/bytes, unused: 132/5152 blocks/bytes.
- --- Import KEY <\Software\Microsoft\Windows NT\CurrentVersion\Winlogon> with 2 values.
- --- Import KEY <\Software\Microsoft\Windows NT\CurrentVersion\Winlogon>
- END OF IMPORT, file </tmp/user.reg>, operation SUCCEEDED!
- 2 keys
- 0 new keys added
- 4 values total
- Hives that have changed:
- # Name
- 0 </mnt/sdb1/WINDOWS/repair/ntuser.dat> - OK
- Modificada clave HKEY_USERS\S-1-5-21-606747145-746137067-682003330-1003\Software\Microsoft\Windows NT\CurrentVersion\Winlogon | Shell | Userinit
- *******************
- reged version 0.1 110511, (c) Petter N Hagen
- Hive </mnt/sdb1/WINDOWS/repair/ntuser.dat> name (from header): <>
- ROOT KEY at offset: 0x001020 * Subkey indexing type is: 666c <lf>
- File size 262144 [40000] bytes, containing 59 pages (+ 1 headerpage)
- Used for data: 4189/234624 blocks/bytes, unused: 132/5152 blocks/bytes.
- --- Import KEY <\Software\Microsoft\Windows NT\CurrentVersion\Windows>
- END OF IMPORT, file </tmp/user.reg>, operation SUCCEEDED!
- 1 keys
- 0 new keys added
- 2 values total
- Hives that have changed:
- # Name
- 0 </mnt/sdb1/WINDOWS/repair/ntuser.dat> - OK
- Modificada clave HKEY_USERS\S-1-5-21-606747145-746137067-682003330-1003\Software\Microsoft\Windows NT\CurrentVersion\Windows | Load
- Done!!
- Looking for in: /mnt/sdb1/WINDOWS/system32/config/system
- Found!!
- Applying system disinfection!!
- *******************
- reged version 0.1 110511, (c) Petter N Hagen
- Hive <./mnt/sdb1/WINDOWS/system32/config/system> name (from header): <SYSTEM>
- ROOT KEY at offset: 0x001020 * Subkey indexing type is: 666c <lf>
- File size 6291456 [600000] bytes, containing 1402 pages (+ 1 headerpage)
- Used for data: 101720/5970168 blocks/bytes, unused: 2030/22472 blocks/bytes.
- Exporting to file '/tmp/runRead.reg'...
- Exporting key 'Select' with 0 subkeys and 4 values...
- *******************
- reged version 0.1 110511, (c) Petter N Hagen
- Hive <./mnt/sdb1/WINDOWS/system32/config/system> name (from header): <SYSTEM>
- ROOT KEY at offset: 0x001020 * Subkey indexing type is: 666c <lf>
- File size 6291456 [600000] bytes, containing 1402 pages (+ 1 headerpage)
- Used for data: 101720/5970168 blocks/bytes, unused: 2030/22472 blocks/bytes.
- --- Import KEY <\ControlSet001\Control\SafeBoot>
- END OF IMPORT, file </root/policeSafeBoot.reg>, operation SUCCEEDED!
- 1 keys
- 0 new keys added
- 0 values total
- Hives that have changed:
- # Name
- None!
- Modificadas claves HKLM\SYSTEM\ControlSet001\Control\SafeBoot | AlternateShell
- Done!!
- Looking for in: /mnt/sdb5/WINDOWS/system32/config/software
- Looking for in: /mnt/sdb5/WINDOWS/system32/config/system
- Looking for in: /mnt/sdc1/WINDOWS/system32/config/software
- Looking for in: /mnt/sdc1/WINDOWS/system32/config/system
- Done!!
- Thank you for trust in PANDA SECURITY.
- bye!!
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement