Advertisement
Not a member of Pastebin yet?
Sign Up,
it unlocks many cool features!
- Regshot 1.8.2 Comments:penguin command
- Datetime:2010/3/31 03:15:02 , 2010/3/31 03:19:58
- Computer:UBUNTUXP , UBUNTUXP
- Username: ,
- Keys added:10
- HKLM\SYSTEM\ControlSet001\Hardware
- Profiles\0001\System\CurrentControlSet\Enum\PCI\VEN_1002&DEV_4370&SUBSYS_2A25103C&REV_02\3&61AAA01&0&A5\DirectSound\Speaker
- Configuration
- HKLM\SYSTEM\ControlSet001\Hardware
- Profiles\Current\System\CurrentControlSet\Enum\PCI\VEN_1002&DEV_4370&SUBSYS_2A25103C&REV_02\3&61AAA01&0&A5\DirectSound\Speaker
- Configuration
- HKLM\SYSTEM\CurrentControlSet\Hardware
- Profiles\0001\System\CurrentControlSet\Enum\PCI\VEN_1002&DEV_4370&SUBSYS_2A25103C&REV_02\3&61AAA01&0&A5\DirectSound\Speaker
- Configuration
- HKLM\SYSTEM\CurrentControlSet\Hardware
- Profiles\Current\System\CurrentControlSet\Enum\PCI\VEN_1002&DEV_4370&SUBSYS_2A25103C&REV_02\3&61AAA01&0&A5\DirectSound\Speaker
- Configuration
- HKU\S-1-5-21-2510607830-722705957-866547821-1009\Software\Microsoft\Windows\ShellNoRoam\BagMRU\0\8\9
- HKU\S-1-5-21-2510607830-722705957-866547821-1009\Software\Microsoft\Windows\ShellNoRoam\BagMRU\0\8\9\0
- HKU\S-1-5-21-2510607830-722705957-866547821-1009\Software\Microsoft\Windows\ShellNoRoam\Bags\1025
- HKU\S-1-5-21-2510607830-722705957-866547821-1009\Software\Microsoft\Windows\ShellNoRoam\Bags\1025\Shell
- HKU\S-1-5-21-2510607830-722705957-866547821-1009\Software\Microsoft\Windows\ShellNoRoam\Bags\1026
- HKU\S-1-5-21-2510607830-722705957-866547821-1009\Software\Microsoft\Windows\ShellNoRoam\Bags\1026\Shell
- Values added:30
- HKLM\SYSTEM\ControlSet001\Hardware
- Profiles\0001\System\CurrentControlSet\Enum\PCI\VEN_1002&DEV_4370&SUBSYS_2A25103C&REV_02\3&61AAA01&0&A5\DirectSound\Speaker
- Configuration\Speaker Configuration: 0x00140004
- HKLM\SYSTEM\ControlSet001\Hardware
- Profiles\Current\System\CurrentControlSet\Enum\PCI\VEN_1002&DEV_4370&SUBSYS_2A25103C&REV_02\3&61AAA01&0&A5\DirectSound\Speaker
- Configuration\Speaker Configuration: 0x00140004
- HKLM\SYSTEM\CurrentControlSet\Hardware
- Profiles\0001\System\CurrentControlSet\Enum\PCI\VEN_1002&DEV_4370&SUBSYS_2A25103C&REV_02\3&61AAA01&0&A5\DirectSound\Speaker
- Configuration\Speaker Configuration: 0x00140004
- HKLM\SYSTEM\CurrentControlSet\Hardware
- Profiles\Current\System\CurrentControlSet\Enum\PCI\VEN_1002&DEV_4370&SUBSYS_2A25103C&REV_02\3&61AAA01&0&A5\DirectSound\Speaker
- Configuration\Speaker Configuration: 0x00140004
- HKU\S-1-5-21-2510607830-722705957-866547821-1009\Software\Microsoft\Windows\CurrentVersion\Explorer\UserAssist\{75048700-EF1F-11D0-9888-006097DEACF9}\Count\HRZR_EHACNGU:P:\Tnzrf\crathva-pbzznaq\crathva-pbzznaq.rkr:
- 30 00 00 00 07 00 00 00 F0 CD 33 C8 80 D0 CA 01
- HKU\S-1-5-21-2510607830-722705957-866547821-1009\Software\Microsoft\Windows\ShellNoRoam\BagMRU\0\8\9:
- 36 00 31 00 00 00 00 00 7F 3C EC 19 10 00 47 61 6D 65 73 00 22 00 03 00 04
- 00 EF BE 7F 3C EC 19 7F 3C EC 19 14 00 00 00 47 00 61 00 6D 00 65 00 73 00
- 00 00 14 00 00 00
- HKU\S-1-5-21-2510607830-722705957-866547821-1009\Software\Microsoft\Windows\ShellNoRoam\BagMRU\0\8\9\0\NodeSlot:
- 0x00000402
- HKU\S-1-5-21-2510607830-722705957-866547821-1009\Software\Microsoft\Windows\ShellNoRoam\BagMRU\0\8\9\0\MRUListEx:
- FF FF FF FF
- HKU\S-1-5-21-2510607830-722705957-866547821-1009\Software\Microsoft\Windows\ShellNoRoam\BagMRU\0\8\9\NodeSlot:
- 0x00000401
- HKU\S-1-5-21-2510607830-722705957-866547821-1009\Software\Microsoft\Windows\ShellNoRoam\BagMRU\0\8\9\MRUListEx:
- 00 00 00 00 FF FF FF FF
- HKU\S-1-5-21-2510607830-722705957-866547821-1009\Software\Microsoft\Windows\ShellNoRoam\BagMRU\0\8\9\0:
- 4E 00 31 00 00 00 00 00 7F 3C ED 19 10 00 50 45 4E 47 55 49 7E 31 00 00 36
- 00 03 00 04 00 EF BE 7F 3C EC 19 7F 3C ED 19 14 00 00 00 70 00 65 00 6E 00
- 67 00 75 00 69 00 6E 00 2D 00 63 00 6F 00 6D 00 6D 00 61 00 6E 00 64 00 00
- 00 18 00 00 00
- HKU\S-1-5-21-2510607830-722705957-866547821-1009\Software\Microsoft\Windows\ShellNoRoam\Bags\1025\Shell\FolderType:
- "Documents"
- HKU\S-1-5-21-2510607830-722705957-866547821-1009\Software\Microsoft\Windows\ShellNoRoam\Bags\1025\Shell\Mode:
- 0x00000004
- HKU\S-1-5-21-2510607830-722705957-866547821-1009\Software\Microsoft\Windows\ShellNoRoam\Bags\1025\Shell\ScrollPos1280x1024(1).x:
- 0x00000000
- HKU\S-1-5-21-2510607830-722705957-866547821-1009\Software\Microsoft\Windows\ShellNoRoam\Bags\1025\Shell\ScrollPos1280x1024(1).y:
- 0x00000000
- HKU\S-1-5-21-2510607830-722705957-866547821-1009\Software\Microsoft\Windows\ShellNoRoam\Bags\1025\Shell\Sort:
- 0x00000000
- HKU\S-1-5-21-2510607830-722705957-866547821-1009\Software\Microsoft\Windows\ShellNoRoam\Bags\1025\Shell\SortDir:
- 0x00000001
- HKU\S-1-5-21-2510607830-722705957-866547821-1009\Software\Microsoft\Windows\ShellNoRoam\Bags\1025\Shell\Col:
- 0xFFFFFFFF
- HKU\S-1-5-21-2510607830-722705957-866547821-1009\Software\Microsoft\Windows\ShellNoRoam\Bags\1025\Shell\ColInfo:
- 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 FD DF DF FD 0F 00 08 00 30
- 00 10 00 40 00 64 00 00 00 00 00 01 00 00 00 02 00 00 00 03 00 00 00 04 00
- 00 00 05 00 00 00 06 00 00 00 07 00 00 00 B4 00 60 00 78 00 78 00 B4 00 B4
- 00 1E 00 5A 00 00 00 00 00 01 00 00 00 02 00 00 00 10 00 00 00 11 00 00 00
- 12 00 00 00 13 00 00 00 15 00 00 00 FF FF FF FF 00 00 00 00 00 00 00 00 00
- 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
- 00 00
- HKU\S-1-5-21-2510607830-722705957-866547821-1009\Software\Microsoft\Windows\ShellNoRoam\Bags\1026\Shell\FolderType:
- "Documents"
- HKU\S-1-5-21-2510607830-722705957-866547821-1009\Software\Microsoft\Windows\ShellNoRoam\Bags\1026\Shell\Mode:
- 0x00000004
- HKU\S-1-5-21-2510607830-722705957-866547821-1009\Software\Microsoft\Windows\ShellNoRoam\Bags\1026\Shell\ScrollPos1280x1024(1).x:
- 0x00000000
- HKU\S-1-5-21-2510607830-722705957-866547821-1009\Software\Microsoft\Windows\ShellNoRoam\Bags\1026\Shell\ScrollPos1280x1024(1).y:
- 0x00000000
- HKU\S-1-5-21-2510607830-722705957-866547821-1009\Software\Microsoft\Windows\ShellNoRoam\Bags\1026\Shell\Sort:
- 0x00000000
- HKU\S-1-5-21-2510607830-722705957-866547821-1009\Software\Microsoft\Windows\ShellNoRoam\Bags\1026\Shell\SortDir:
- 0x00000001
- HKU\S-1-5-21-2510607830-722705957-866547821-1009\Software\Microsoft\Windows\ShellNoRoam\Bags\1026\Shell\Col:
- 0xFFFFFFFF
- HKU\S-1-5-21-2510607830-722705957-866547821-1009\Software\Microsoft\Windows\ShellNoRoam\Bags\1026\Shell\ColInfo:
- 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 FD DF DF FD 0F 00 08 00 30
- 00 10 00 40 00 64 00 00 00 00 00 01 00 00 00 02 00 00 00 03 00 00 00 04 00
- 00 00 05 00 00 00 06 00 00 00 07 00 00 00 B4 00 60 00 78 00 78 00 B4 00 B4
- 00 1E 00 5A 00 00 00 00 00 01 00 00 00 02 00 00 00 10 00 00 00 11 00 00 00
- 12 00 00 00 13 00 00 00 15 00 00 00 FF FF FF FF 00 00 00 00 00 00 00 00 00
- 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
- 00 00
- HKU\S-1-5-21-2510607830-722705957-866547821-1009\Software\Microsoft\Windows\ShellNoRoam\MUICache\C:\Documents
- and Settings\Compaq_Owner\Desktop\penguin-command.exe: "penguin-command"
- HKU\S-1-5-21-2510607830-722705957-866547821-1009\Software\Microsoft\Windows\ShellNoRoam\MUICache\C:\Games\penguin-command\penguin-command.exe:
- "penguin-command"
- HKU\S-1-5-21-2510607830-722705957-866547821-1009\Software\Microsoft\Windows\ShellNoRoam\MUICache\@shell32.dll,-31275:
- "This section displays the size, file type, and other information about a
- selected item."
- Values modified:23
- HKLM\SOFTWARE\Microsoft\Cryptography\RNG\Seed: FF 05 A2 CB 2C 2D 37 67 59
- 06 68 AE 5B 72 2D 34 F2 3F E9 92 1C 05 1C EF B0 FB 88 7E C3 A5 21 B1 8E 6E
- FE F2 06 4B CA AB 25 F9 9A 75 04 D8 C5 73 58 63 7C 92 F7 4D 8C A9 37 6B D2
- C7 34 C3 2D 01 5D 61 01 01 90 1F CC 7D 45 03 03 5E 59 2C 24 69
- HKLM\SOFTWARE\Microsoft\Cryptography\RNG\Seed: 39 1B 00 72 2A 73 DB 94 AA
- 4A 7E 7D 86 39 21 45 A7 3D B8 07 20 39 C0 5F 89 19 AE B6 ED E3 7A 9B 24 4D
- CC 13 96 6B 1E A0 C1 D0 D2 6A 91 35 8D 38 44 36 B6 09 E1 01 EF 96 0B 6D 36
- A3 66 94 F8 99 8B AE 0E E6 A0 FD 3F 74 78 90 CF F5 BA 6B 21 D6
- HKLM\SOFTWARE\Microsoft\DirectDraw\MostRecentApplication\Name:
- "IEXPLORE.EXE"
- HKLM\SOFTWARE\Microsoft\DirectDraw\MostRecentApplication\Name:
- "penguin-command.exe"
- HKLM\SOFTWARE\Microsoft\DirectDraw\MostRecentApplication\ID: 0x49B3AD2E
- HKLM\SOFTWARE\Microsoft\DirectDraw\MostRecentApplication\ID: 0x3C5060B4
- HKLM\SOFTWARE\Microsoft\Microsoft SQL
- Server\MICROSOFTBCM\MSSQLServer\uptime_time_utc: 70 31 97 36 80 D0 CA 01
- HKLM\SOFTWARE\Microsoft\Microsoft SQL
- Server\MICROSOFTBCM\MSSQLServer\uptime_time_utc: 86 65 9E E9 80 D0 CA 01
- HKU\S-1-5-21-2510607830-722705957-866547821-1009\Software\Microsoft\DirectInput\MostRecentApplication\MostRecentStart:
- 1E FD 51 64 69 D0 CA 01
- HKU\S-1-5-21-2510607830-722705957-866547821-1009\Software\Microsoft\DirectInput\MostRecentApplication\MostRecentStart:
- 72 DA 5E C8 80 D0 CA 01
- HKU\S-1-5-21-2510607830-722705957-866547821-1009\Software\Microsoft\Windows\CurrentVersion\Explorer\UserAssist\{75048700-EF1F-11D0-9888-006097DEACF9}\Count\HRZR_EHACNGU:
- 30 00 00 00 2C 0F 00 00 A0 65 71 9A 7E D0 CA 01
- HKU\S-1-5-21-2510607830-722705957-866547821-1009\Software\Microsoft\Windows\CurrentVersion\Explorer\UserAssist\{75048700-EF1F-11D0-9888-006097DEACF9}\Count\HRZR_EHACNGU:
- 30 00 00 00 30 0F 00 00 F0 CD 33 C8 80 D0 CA 01
- HKU\S-1-5-21-2510607830-722705957-866547821-1009\Software\Microsoft\Windows\CurrentVersion\Explorer\UserAssist\{75048700-EF1F-11D0-9888-006097DEACF9}\Count\HRZR_HVFPHG:
- 30 00 00 00 CD 05 00 00 E0 0D F3 99 7E D0 CA 01
- HKU\S-1-5-21-2510607830-722705957-866547821-1009\Software\Microsoft\Windows\CurrentVersion\Explorer\UserAssist\{75048700-EF1F-11D0-9888-006097DEACF9}\Count\HRZR_HVFPHG:
- 30 00 00 00 CF 05 00 00 60 7D A2 6C 80 D0 CA 01
- HKU\S-1-5-21-2510607830-722705957-866547821-1009\Software\Microsoft\Windows\CurrentVersion\Explorer\UserAssist\{75048700-EF1F-11D0-9888-006097DEACF9}\Count\HRZR_EHACNGU:::{20Q04SR0-3NRN-1069-N2Q8-08002O30309Q}:
- 30 00 00 00 BE 00 00 00 B0 15 B2 8F 7E D0 CA 01
- HKU\S-1-5-21-2510607830-722705957-866547821-1009\Software\Microsoft\Windows\CurrentVersion\Explorer\UserAssist\{75048700-EF1F-11D0-9888-006097DEACF9}\Count\HRZR_EHACNGU:::{20Q04SR0-3NRN-1069-N2Q8-08002O30309Q}:
- 30 00 00 00 BF 00 00 00 60 7D A2 6C 80 D0 CA 01
- HKU\S-1-5-21-2510607830-722705957-866547821-1009\Software\Microsoft\Windows\CurrentVersion\Explorer\UserAssist\{75048700-EF1F-11D0-9888-006097DEACF9}\Count\HRZR_EHACNGU:P:\Qbphzragf
- naq Frggvatf\Pbzcnd_Bjare\Qrfxgbc\crathva-pbzznaq.rkr: 2F 00 00 00 08 00
- 00 00 70 86 59 16 D5 CF CA 01
- HKU\S-1-5-21-2510607830-722705957-866547821-1009\Software\Microsoft\Windows\CurrentVersion\Explorer\UserAssist\{75048700-EF1F-11D0-9888-006097DEACF9}\Count\HRZR_EHACNGU:P:\Qbphzragf
- naq Frggvatf\Pbzcnd_Bjare\Qrfxgbc\crathva-pbzznaq.rkr: 30 00 00 00 09 00
- 00 00 D0 1E 5D 5F 80 D0 CA 01
- HKU\S-1-5-21-2510607830-722705957-866547821-1009\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{3049C3E9-B461-4BC5-8870-4C09146192CA}\iexplore\Count:
- 0x00000715
- HKU\S-1-5-21-2510607830-722705957-866547821-1009\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{3049C3E9-B461-4BC5-8870-4C09146192CA}\iexplore\Count:
- 0x00000716
- HKU\S-1-5-21-2510607830-722705957-866547821-1009\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{3049C3E9-B461-4BC5-8870-4C09146192CA}\iexplore\Time:
- DA 07 03 00 03 00 1F 00 03 00 02 00 0C 00 99 03
- HKU\S-1-5-21-2510607830-722705957-866547821-1009\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{3049C3E9-B461-4BC5-8870-4C09146192CA}\iexplore\Time:
- DA 07 03 00 03 00 1F 00 03 00 0F 00 21 00 5D 00
- HKU\S-1-5-21-2510607830-722705957-866547821-1009\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{5C255C8A-E604-49B4-9D64-90988571CECB}\iexplore\Count:
- 0x000006AE
- HKU\S-1-5-21-2510607830-722705957-866547821-1009\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{5C255C8A-E604-49B4-9D64-90988571CECB}\iexplore\Count:
- 0x000006AF
- HKU\S-1-5-21-2510607830-722705957-866547821-1009\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{5C255C8A-E604-49B4-9D64-90988571CECB}\iexplore\Time:
- DA 07 03 00 03 00 1F 00 03 00 02 00 0C 00 99 03
- HKU\S-1-5-21-2510607830-722705957-866547821-1009\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{5C255C8A-E604-49B4-9D64-90988571CECB}\iexplore\Time:
- DA 07 03 00 03 00 1F 00 03 00 0F 00 21 00 5D 00
- HKU\S-1-5-21-2510607830-722705957-866547821-1009\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{AA58ED58-01DD-4D91-8333-CF10577473F7}\iexplore\Count:
- 0x0000071F
- HKU\S-1-5-21-2510607830-722705957-866547821-1009\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{AA58ED58-01DD-4D91-8333-CF10577473F7}\iexplore\Count:
- 0x00000720
- HKU\S-1-5-21-2510607830-722705957-866547821-1009\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{AA58ED58-01DD-4D91-8333-CF10577473F7}\iexplore\Time:
- DA 07 03 00 03 00 1F 00 03 00 02 00 0C 00 99 03
- HKU\S-1-5-21-2510607830-722705957-866547821-1009\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{AA58ED58-01DD-4D91-8333-CF10577473F7}\iexplore\Time:
- DA 07 03 00 03 00 1F 00 03 00 0F 00 21 00 5D 00
- HKU\S-1-5-21-2510607830-722705957-866547821-1009\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{AF69DE43-7D58-4638-B6FA-CE66B5AD205D}\iexplore\Count:
- 0x0000071F
- HKU\S-1-5-21-2510607830-722705957-866547821-1009\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{AF69DE43-7D58-4638-B6FA-CE66B5AD205D}\iexplore\Count:
- 0x00000720
- HKU\S-1-5-21-2510607830-722705957-866547821-1009\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{AF69DE43-7D58-4638-B6FA-CE66B5AD205D}\iexplore\Time:
- DA 07 03 00 03 00 1F 00 03 00 02 00 0C 00 99 03
- HKU\S-1-5-21-2510607830-722705957-866547821-1009\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{AF69DE43-7D58-4638-B6FA-CE66B5AD205D}\iexplore\Time:
- DA 07 03 00 03 00 1F 00 03 00 0F 00 21 00 5D 00
- HKU\S-1-5-21-2510607830-722705957-866547821-1009\Software\Microsoft\Windows\CurrentVersion\Shell
- Extensions\Cached\{2559A1F4-21D7-11D4-BDAF-00C04F60B9F0}
- {000214E6-0000-0000-C000-000000000046} 0x401: 00 00 00 00 7C 6C 9C 7C 00
- AB 64 4F 7C D0 CA 01
- HKU\S-1-5-21-2510607830-722705957-866547821-1009\Software\Microsoft\Windows\CurrentVersion\Shell
- Extensions\Cached\{2559A1F4-21D7-11D4-BDAF-00C04F60B9F0}
- {000214E6-0000-0000-C000-000000000046} 0x401: 00 00 00 00 7C 6C 9C 7C 16
- 57 DA FE 80 D0 CA 01
- HKU\S-1-5-21-2510607830-722705957-866547821-1009\Software\Microsoft\Windows\CurrentVersion\Shell
- Extensions\Cached\{2559A1F5-21D7-11D4-BDAF-00C04F60B9F0}
- {000214E6-0000-0000-C000-000000000046} 0x401: 00 00 00 00 32 00 35 00 7E
- 0A A5 4F 7C D0 CA 01
- HKU\S-1-5-21-2510607830-722705957-866547821-1009\Software\Microsoft\Windows\CurrentVersion\Shell
- Extensions\Cached\{2559A1F5-21D7-11D4-BDAF-00C04F60B9F0}
- {000214E6-0000-0000-C000-000000000046} 0x401: 00 00 00 00 32 00 35 00 86
- 8F 13 FF 80 D0 CA 01
- HKU\S-1-5-21-2510607830-722705957-866547821-1009\Software\Microsoft\Windows\ShellNoRoam\BagMRU\NodeSlots:
- 02 02 02 02 02 02 02 02 02 02 02 02 02 02 02 02 02 02 02 02 02 02 02 02 02
- 02 02 02 02 02 02 02 02 02 02 02 02 02 02 02 02 02 02 02 02 02 02 02 02 02
- 02 02 02 02 02 02 02 02 02 02 02 02 02 02 02 02 02 02 02 02 02 02 02 02 02
- 02 02 02 02 02 02 02 02 02 02 02 02 02 02 02 02 02 02 02 02 02 02 02 02 02
- 02 02 02 02 02 02 02 02 02 02 02 02 02 02 02 02 02 02 02 02 02 02 02 02 02
- 02 02 02 02 02 02 02 02 02 02 02 02 02 02 02 02 02 02 02 02 02 02 02 02 02
- 02 02 02 02 02 02 02 02 02 02 02 02 02 02 02 02 02 02 02 02 02 02 02 02 02
- 02 02 02 02 02 02 02 02 02 02 02 02 02 02 02 02 02 02 02 02 02 02 02 02 02
- 02 02 02 02 02 02 02 02 02 02 02 02 02 02 02 02 02 02 02 02 02 02 02 02 02
- 02 02 02 02 02 02 02 02 02 02 02 02 02 02 02 02 02 02 02 02 02 02 02 02 02
- 02 02 02 02 02 02 02 02 02 02 02 02 02 02 02 02 02 02 02 02 02 02 02 02 02
- 02 02 02 02 02 02 02 02 02 02 02 02 02 02 02 02 02 02 02 02 02 02 02
- 02 02 02 02 02 02 02 02 02 02 02 02 02 02 02 02 02 02 02 02 02 02 02 02 02
- 02 02 02 02 02 02 02 02 02 02 02 02 02 02 02 02 02 02 02 02 02 02 02 02 02
- 02 02 02 02 02 02 02 02 02 02 02 02 02 02 02 02 02 02 02 02 02 02 02 02 02
- 02 02 02 02 02 02 02 02 02 02 02 02 02 02 02 02 02 02 02 02 02 02 02 02 02
- 02 02 02 02 02 02 02 02 02 02 02 02 02 02 02 02 02 02 02 02 02 02 02 02 02
- 02 02 02 02 02 02 02 02 02 02 02 02 02 02 02 02 02 02 02 02 02 02 02 02 02
- 02 02 02 02 02 02 02 02 02 02 02 02 02 02 02 02 02 02 02 02 02 02 02 02 02
- 02 02 02 02 02 02 02 02 02 02 02 02 02 02 02 02 02 02 02 02 02 02 02 02 02
- 02 02 02 02 02 02 02 02 02 02 02 02 02 02 02 02 02 02 02 02 02 02 02 02 02
- 02 02 02 02 02 02 02 02 02 02 02 02 02 02 02 02 02 02 02 02 02 02 02 02 02
- 02 02 02 02 02 02 02 02 02 02 02 02 02 02 02 02 02 02 02 02 02 02 02 02 02
- 02 02 02 02 02 02 02 02 02 02 02 02 02 02 02 02 02 02 02 02 02 02 02 02 02
- 02 02 02 02 02 02 02 02 02 02 02 02 02 02 02 02 02 02 02 02 02 02 02 02 02
- 02 02 02 02 02 02 02 02 0
- 2 02 02 02 02 02 02 02 02 02 02 02 02 02 02 02 02 02 02 02 02 02 02 02 02
- 02 02 02 02 02 02 02 02 02 02 02 02 02 02 02 02 02 02 02 02 02 02 02 02 02
- 02 02 02 02 02 02 02 02 02 02 02 02 02 02 02 02 02 02 02 02 02 02 02 02 02
- 02 02 02 02 02 02 02 02 02 02 02 02 02 02 02 02 02 02 02 02 02 02 02 02 02
- 02 02 02 02 02 02 02 02 02 02 02 02 02 02 02 02 02 02 02 02 02 02 02 02 02
- 02 02 02 02 02 02 02 02 02 02 02 02 02 02 02 02 02 02 02 02 02 02 02 02 02
- 02 02 02 02 02 02 02 02 02 02 02 02 02 02 02 02 02 02 02 02 02 02 02 02 02
- 02 02 02 02 02 02 02 02 02 02 02 02 02 02 02 02 02 02 02 02 02 02 02 02 02
- 02 02 02 02 02 02 02 02 02 02 02 02 02 02 02 02 02 02 02 02 02 02 02 02 02
- 02 02 02 02 02 02 02 02 02 02 02 02 02 02 02 02 02 02 02 02 02 02 02 02 02
- 02 02 02 02 02 02 02 02 02 02 02 02 02 02 02 02 02 02 02 02 02 02 02 02 02
- 02 02 02 02 02 02 02 02 02 02 02 02 02 02 02 02 02 02 02 02 02 02 02 02 02
- 02 02 02 02 02 02 02 02 02 02 02 02 02 02 02 02 02 02 02 02 02 02 02 02 02
- 02 02 02 02 02 02 02 02 02
- 02 02 02 02 02 02 02 02 02 02 02 02 02 02 02 02 02 02 02 02 02 02 02 02 02
- 02 02 02 02 02 02 02 02 02 02 02 02 02 02 02 02 02 02 02 02 02 02 02 02 02
- 02 02 02 02 02 02 02 02 02
- HKU\S-1-5-21-2510607830-722705957-866547821-1009\Software\Microsoft\Windows\ShellNoRoam\BagMRU\NodeSlots:
- 02 02 02 02 02 02 02 02 02 02 02 02 02 02 02 02 02 02 02 02 02 02 02 02 02
- 02 02 02 02 02 02 02 02 02 02 02 02 02 02 02 02 02 02 02 02 02 02 02 02 02
- 02 02 02 02 02 02 02 02 02 02 02 02 02 02 02 02 02 02 02 02 02 02 02 02 02
- 02 02 02 02 02 02 02 02 02 02 02 02 02 02 02 02 02 02 02 02 02 02 02 02 02
- 02 02 02 02 02 02 02 02 02 02 02 02 02 02 02 02 02 02 02 02 02 02 02 02 02
- 02 02 02 02 02 02 02 02 02 02 02 02 02 02 02 02 02 02 02 02 02 02 02 02 02
- 02 02 02 02 02 02 02 02 02 02 02 02 02 02 02 02 02 02 02 02 02 02 02 02 02
- 02 02 02 02 02 02 02 02 02 02 02 02 02 02 02 02 02 02 02 02 02 02 02 02 02
- 02 02 02 02 02 02 02 02 02 02 02 02 02 02 02 02 02 02 02 02 02 02 02 02 02
- 02 02 02 02 02 02 02 02 02 02 02 02 02 02 02 02 02 02 02 02 02 02 02 02 02
- 02 02 02 02 02 02 02 02 02 02 02 02 02 02 02 02 02 02 02 02 02 02 02 02 02
- 02 02 02 02 02 02 02 02 02 02 02 02 02 02 02 02 02 02 02 02 02 02 02
- 02 02 02 02 02 02 02 02 02 02 02 02 02 02 02 02 02 02 02 02 02 02 02 02 02
- 02 02 02 02 02 02 02 02 02 02 02 02 02 02 02 02 02 02 02 02 02 02 02 02 02
- 02 02 02 02 02 02 02 02 02 02 02 02 02 02 02 02 02 02 02 02 02 02 02 02 02
- 02 02 02 02 02 02 02 02 02 02 02 02 02 02 02 02 02 02 02 02 02 02 02 02 02
- 02 02 02 02 02 02 02 02 02 02 02 02 02 02 02 02 02 02 02 02 02 02 02 02 02
- 02 02 02 02 02 02 02 02 02 02 02 02 02 02 02 02 02 02 02 02 02 02 02 02 02
- 02 02 02 02 02 02 02 02 02 02 02 02 02 02 02 02 02 02 02 02 02 02 02 02 02
- 02 02 02 02 02 02 02 02 02 02 02 02 02 02 02 02 02 02 02 02 02 02 02 02 02
- 02 02 02 02 02 02 02 02 02 02 02 02 02 02 02 02 02 02 02 02 02 02 02 02 02
- 02 02 02 02 02 02 02 02 02 02 02 02 02 02 02 02 02 02 02 02 02 02 02 02 02
- 02 02 02 02 02 02 02 02 02 02 02 02 02 02 02 02 02 02 02 02 02 02 02 02 02
- 02 02 02 02 02 02 02 02 02 02 02 02 02 02 02 02 02 02 02 02 02 02 02 02 02
- 02 02 02 02 02 02 02 02 02 02 02 02 02 02 02 02 02 02 02 02 02 02 02 02 02
- 02 02 02 02 02 02 02 02 0
- 2 02 02 02 02 02 02 02 02 02 02 02 02 02 02 02 02 02 02 02 02 02 02 02 02
- 02 02 02 02 02 02 02 02 02 02 02 02 02 02 02 02 02 02 02 02 02 02 02 02 02
- 02 02 02 02 02 02 02 02 02 02 02 02 02 02 02 02 02 02 02 02 02 02 02 02 02
- 02 02 02 02 02 02 02 02 02 02 02 02 02 02 02 02 02 02 02 02 02 02 02 02 02
- 02 02 02 02 02 02 02 02 02 02 02 02 02 02 02 02 02 02 02 02 02 02 02 02 02
- 02 02 02 02 02 02 02 02 02 02 02 02 02 02 02 02 02 02 02 02 02 02 02 02 02
- 02 02 02 02 02 02 02 02 02 02 02 02 02 02 02 02 02 02 02 02 02 02 02 02 02
- 02 02 02 02 02 02 02 02 02 02 02 02 02 02 02 02 02 02 02 02 02 02 02 02 02
- 02 02 02 02 02 02 02 02 02 02 02 02 02 02 02 02 02 02 02 02 02 02 02 02 02
- 02 02 02 02 02 02 02 02 02 02 02 02 02 02 02 02 02 02 02 02 02 02 02 02 02
- 02 02 02 02 02 02 02 02 02 02 02 02 02 02 02 02 02 02 02 02 02 02 02 02 02
- 02 02 02 02 02 02 02 02 02 02 02 02 02 02 02 02 02 02 02 02 02 02 02 02 02
- 02 02 02 02 02 02 02 02 02 02 02 02 02 02 02 02 02 02 02 02 02 02 02 02 02
- 02 02 02 02 02 02 02 02 02
- 02 02 02 02 02 02 02 02 02 02 02 02 02 02 02 02 02 02 02 02 02 02 02 02 02
- 02 02 02 02 02 02 02 02 02 02 02 02 02 02 02 02 02 02 02 02 02 02 02 02 02
- 02 02 02 02 02 02 02 02 02 02 02
- HKU\S-1-5-21-2510607830-722705957-866547821-1009\Software\Microsoft\Windows\ShellNoRoam\BagMRU\0\MRUListEx:
- 04 00 00 00 08 00 00 00 06 00 00 00 05 00 00 00 0B 00 00 00 02 00 00 00 01
- 00 00 00 00 00 00 00 09 00 00 00 0C 00 00 00 03 00 00 00 0A 00 00 00 07 00
- 00 00 FF FF FF FF
- HKU\S-1-5-21-2510607830-722705957-866547821-1009\Software\Microsoft\Windows\ShellNoRoam\BagMRU\0\MRUListEx:
- 08 00 00 00 04 00 00 00 06 00 00 00 05 00 00 00 0B 00 00 00 02 00 00 00 01
- 00 00 00 00 00 00 00 09 00 00 00 0C 00 00 00 03 00 00 00 0A 00 00 00 07 00
- 00 00 FF FF FF FF
- HKU\S-1-5-21-2510607830-722705957-866547821-1009\Software\Microsoft\Windows\ShellNoRoam\BagMRU\0\8\MRUListEx:
- 00 00 00 00 01 00 00 00 07 00 00 00 04 00 00 00 02 00 00 00 03 00 00 00 08
- 00 00 00 06 00 00 00 05 00 00 00 FF FF FF FF
- HKU\S-1-5-21-2510607830-722705957-866547821-1009\Software\Microsoft\Windows\ShellNoRoam\BagMRU\0\8\MRUListEx:
- 09 00 00 00 00 00 00 00 01 00 00 00 07 00 00 00 04 00 00 00 02 00 00 00 03
- 00 00 00 08 00 00 00 06 00 00 00 05 00 00 00 FF FF FF FF
- HKU\S-1-5-21-2510607830-722705957-866547821-1009\Software\Microsoft\Windows\ShellNoRoam\Bags\1\Shell\ScrollPos1280x1024(1).y:
- 0x00000021
- HKU\S-1-5-21-2510607830-722705957-866547821-1009\Software\Microsoft\Windows\ShellNoRoam\Bags\1\Shell\ScrollPos1280x1024(1).y:
- 0x00000000
- Files added:114
- C:\WINDOWS\Prefetch\PENGUIN-COMMAND.EXE-2232EC29.pf
- C:\WINDOWS\Prefetch\PENGUIN-COMMAND.EXE-24604741.pf
- C:\Games\penguin-command\authors
- C:\Games\penguin-command\copying
- C:\Games\penguin-command\data\gfx\10explo.png
- C:\Games\penguin-command\data\gfx\10flyer.png
- C:\Games\penguin-command\data\gfx\11explo.png
- C:\Games\penguin-command\data\gfx\11flyer.png
- C:\Games\penguin-command\data\gfx\12explo.png
- C:\Games\penguin-command\data\gfx\12flyer.png
- C:\Games\penguin-command\data\gfx\13explo.png
- C:\Games\penguin-command\data\gfx\13flyer.png
- C:\Games\penguin-command\data\gfx\14explo.png
- C:\Games\penguin-command\data\gfx\14flyer.png
- C:\Games\penguin-command\data\gfx\15explo.png
- C:\Games\penguin-command\data\gfx\15flyer.png
- C:\Games\penguin-command\data\gfx\16explo.png
- C:\Games\penguin-command\data\gfx\16flyer.png
- C:\Games\penguin-command\data\gfx\17explo.png
- C:\Games\penguin-command\data\gfx\18explo.png
- C:\Games\penguin-command\data\gfx\19explo.png
- C:\Games\penguin-command\data\gfx\1cursor.png
- C:\Games\penguin-command\data\gfx\1explo.png
- C:\Games\penguin-command\data\gfx\1flyer.png
- C:\Games\penguin-command\data\gfx\20explo.png
- C:\Games\penguin-command\data\gfx\2cursor.png
- C:\Games\penguin-command\data\gfx\2explo.png
- C:\Games\penguin-command\data\gfx\2flyer.png
- C:\Games\penguin-command\data\gfx\3cursor.png
- C:\Games\penguin-command\data\gfx\3explo.png
- C:\Games\penguin-command\data\gfx\3flyer.png
- C:\Games\penguin-command\data\gfx\4cursor.png
- C:\Games\penguin-command\data\gfx\4explo.png
- C:\Games\penguin-command\data\gfx\4flyer.png
- C:\Games\penguin-command\data\gfx\5cursor.png
- C:\Games\penguin-command\data\gfx\5explo.png
- C:\Games\penguin-command\data\gfx\5flyer.png
- C:\Games\penguin-command\data\gfx\6cursor.png
- C:\Games\penguin-command\data\gfx\6explo.png
- C:\Games\penguin-command\data\gfx\6flyer.png
- C:\Games\penguin-command\data\gfx\7cursor.png
- C:\Games\penguin-command\data\gfx\7explo.png
- C:\Games\penguin-command\data\gfx\7flyer.png
- C:\Games\penguin-command\data\gfx\8cursor.png
- C:\Games\penguin-command\data\gfx\8explo.png
- C:\Games\penguin-command\data\gfx\8flyer.png
- C:\Games\penguin-command\data\gfx\9cursor.png
- C:\Games\penguin-command\data\gfx\9explo.png
- C:\Games\penguin-command\data\gfx\9flyer.png
- C:\Games\penguin-command\data\gfx\abc.png
- C:\Games\penguin-command\data\gfx\back.jpg
- C:\Games\penguin-command\data\gfx\bomb1.png
- C:\Games\penguin-command\data\gfx\bomb10.png
- C:\Games\penguin-command\data\gfx\bomb2.png
- C:\Games\penguin-command\data\gfx\bomb3.png
- C:\Games\penguin-command\data\gfx\bomb4.png
- C:\Games\penguin-command\data\gfx\bomb5.png
- C:\Games\penguin-command\data\gfx\bomb6.png
- C:\Games\penguin-command\data\gfx\bomb7.png
- C:\Games\penguin-command\data\gfx\bomb8.png
- C:\Games\penguin-command\data\gfx\bomb9.png
- C:\Games\penguin-command\data\gfx\cannon1.png
- C:\Games\penguin-command\data\gfx\cannon10.png
- C:\Games\penguin-command\data\gfx\cannon11.png
- C:\Games\penguin-command\data\gfx\cannon12.png
- C:\Games\penguin-command\data\gfx\cannon13.png
- C:\Games\penguin-command\data\gfx\cannon14.png
- C:\Games\penguin-command\data\gfx\cannon15.png
- C:\Games\penguin-command\data\gfx\cannon16.png
- C:\Games\penguin-command\data\gfx\cannon17.png
- C:\Games\penguin-command\data\gfx\cannon18.png
- C:\Games\penguin-command\data\gfx\cannon19.png
- C:\Games\penguin-command\data\gfx\cannon2.png
- C:\Games\penguin-command\data\gfx\cannon20.png
- C:\Games\penguin-command\data\gfx\cannon21.png
- C:\Games\penguin-command\data\gfx\cannon3.png
- C:\Games\penguin-command\data\gfx\cannon4.png
- C:\Games\penguin-command\data\gfx\cannon5.png
- C:\Games\penguin-command\data\gfx\cannon6.png
- C:\Games\penguin-command\data\gfx\cannon7.png
- C:\Games\penguin-command\data\gfx\cannon8.png
- C:\Games\penguin-command\data\gfx\cannon9.png
- C:\Games\penguin-command\data\gfx\cannonhit.png
- C:\Games\penguin-command\data\gfx\city.png
- C:\Games\penguin-command\data\gfx\cityhit.png
- C:\Games\penguin-command\data\gfx\cursor.xbm
- C:\Games\penguin-command\data\gfx\cursor_mask.xbm
- C:\Games\penguin-command\data\gfx\cursor_mask1.xbm
- C:\Games\penguin-command\data\gfx\cursor_mask2.xbm
- C:\Games\penguin-command\data\gfx\cursor_mask3.xbm
- C:\Games\penguin-command\data\gfx\cursor_mask4.xbm
- C:\Games\penguin-command\data\gfx\cursor_mask5.xbm
- C:\Games\penguin-command\data\gfx\cursor_mask6.xbm
- C:\Games\penguin-command\data\gfx\icon.png
- C:\Games\penguin-command\data\gfx\shot.png
- C:\Games\penguin-command\data\gfx\title.jpg
- C:\Games\penguin-command\data\sound\bombex.wav
- C:\Games\penguin-command\data\sound\click.wav
- C:\Games\penguin-command\data\sound\datajack.s3m
- C:\Games\penguin-command\data\sound\icefront.s3m
- C:\Games\penguin-command\data\sound\Machine.wav
- C:\Games\penguin-command\data\sound\missex.wav
- C:\Games\penguin-command\data\sound\pennight.mod
- C:\Games\penguin-command\data\sound\ramagard.s3m
- C:\Games\penguin-command\data\sound\Wooeep.wav
- C:\Games\penguin-command\jpeg.dll
- C:\Games\penguin-command\news
- C:\Games\penguin-command\penguin-command.dat
- C:\Games\penguin-command\penguin-command.exe
- C:\Games\penguin-command\png.dll
- C:\Games\penguin-command\readme
- C:\Games\penguin-command\SDL.dll
- C:\Games\penguin-command\stdout.txt
- C:\Games\penguin-command\z.dll
- Files [attributes?] modified:5
- C:\Documents and Settings\All Users\Application
- Data\Sunbelt\AntiMalware\FW History\Stats_WS_20100330.xml
- C:\Documents and Settings\Compaq_Owner\ntuser.dat.LOG
- C:\WINDOWS\Prefetch\VERCLSID.EXE-28F52AD2.pf
- C:\WINDOWS\system32\config\software.LOG
- C:\WINDOWS\system32\config\system.LOG
- Folders added:5
- C:\Games
- C:\Games\penguin-command
- C:\Games\penguin-command\data
- C:\Games\penguin-command\data\gfx
- C:\Games\penguin-command\data\sound
- Total changes:187
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement