Advertisement
Not a member of Pastebin yet?
Sign Up,
it unlocks many cool features!
- Regshot 1.8.2
- Comments:
- Datetime:2014/10/16 13:47:38 , 2014/10/16 13:48:21
- Computer:VM-40A11EDE3A0F , VM-40A11EDE3A0F
- Username:Administrator , Administrator
- ----------------------------------
- Keys deleted:85
- ----------------------------------
- HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\SearchProtect
- HKLM\SOFTWARE\SearchProtect
- HKLM\SYSTEM\ControlSet001\Enum\Root\LEGACY_CLTMNGSVC
- HKLM\SYSTEM\ControlSet001\Enum\Root\LEGACY_CLTMNGSVC\0000
- HKLM\SYSTEM\ControlSet001\Enum\Root\LEGACY_CLTMNGSVC\0000\Control
- HKLM\SYSTEM\ControlSet001\Services\CltMngSvc
- HKLM\SYSTEM\ControlSet001\Services\CltMngSvc\Security
- HKLM\SYSTEM\ControlSet001\Services\CltMngSvc\Enum
- HKLM\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_CLTMNGSVC
- HKLM\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_CLTMNGSVC\0000
- HKLM\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_CLTMNGSVC\0000\Control
- HKLM\SYSTEM\CurrentControlSet\Services\CltMngSvc
- HKLM\SYSTEM\CurrentControlSet\Services\CltMngSvc\Security
- HKLM\SYSTEM\CurrentControlSet\Services\CltMngSvc\Enum
- HKU\S-1-5-21-1993962763-1935655697-1060284298-500\Software\Microsoft\Internet Explorer\BrowserEmulation
- HKU\S-1-5-21-1993962763-1935655697-1060284298-500\Software\Microsoft\Internet Explorer\Default HTML Editor
- HKU\S-1-5-21-1993962763-1935655697-1060284298-500\Software\Microsoft\Internet Explorer\Desktop
- HKU\S-1-5-21-1993962763-1935655697-1060284298-500\Software\Microsoft\Internet Explorer\Desktop\Components
- HKU\S-1-5-21-1993962763-1935655697-1060284298-500\Software\Microsoft\Internet Explorer\Desktop\Components\0
- HKU\S-1-5-21-1993962763-1935655697-1060284298-500\Software\Microsoft\Internet Explorer\Desktop\General
- HKU\S-1-5-21-1993962763-1935655697-1060284298-500\Software\Microsoft\Internet Explorer\Desktop\Old WorkAreas
- HKU\S-1-5-21-1993962763-1935655697-1060284298-500\Software\Microsoft\Internet Explorer\Desktop\SafeMode
- HKU\S-1-5-21-1993962763-1935655697-1060284298-500\Software\Microsoft\Internet Explorer\Desktop\SafeMode\General
- HKU\S-1-5-21-1993962763-1935655697-1060284298-500\Software\Microsoft\Internet Explorer\Desktop\Scheme
- HKU\S-1-5-21-1993962763-1935655697-1060284298-500\Software\Microsoft\Internet Explorer\Document Windows
- HKU\S-1-5-21-1993962763-1935655697-1060284298-500\Software\Microsoft\Internet Explorer\Download
- HKU\S-1-5-21-1993962763-1935655697-1060284298-500\Software\Microsoft\Internet Explorer\Extensions
- HKU\S-1-5-21-1993962763-1935655697-1060284298-500\Software\Microsoft\Internet Explorer\Extensions\CmdMapping
- HKU\S-1-5-21-1993962763-1935655697-1060284298-500\Software\Microsoft\Internet Explorer\Help_Menu_URLs
- HKU\S-1-5-21-1993962763-1935655697-1060284298-500\Software\Microsoft\Internet Explorer\IETld
- HKU\S-1-5-21-1993962763-1935655697-1060284298-500\Software\Microsoft\Internet Explorer\International
- HKU\S-1-5-21-1993962763-1935655697-1060284298-500\Software\Microsoft\Internet Explorer\International\Scripts
- HKU\S-1-5-21-1993962763-1935655697-1060284298-500\Software\Microsoft\Internet Explorer\International\Scripts\10
- HKU\S-1-5-21-1993962763-1935655697-1060284298-500\Software\Microsoft\Internet Explorer\International\Scripts\11
- HKU\S-1-5-21-1993962763-1935655697-1060284298-500\Software\Microsoft\Internet Explorer\International\Scripts\12
- HKU\S-1-5-21-1993962763-1935655697-1060284298-500\Software\Microsoft\Internet Explorer\International\Scripts\13
- HKU\S-1-5-21-1993962763-1935655697-1060284298-500\Software\Microsoft\Internet Explorer\International\Scripts\14
- HKU\S-1-5-21-1993962763-1935655697-1060284298-500\Software\Microsoft\Internet Explorer\International\Scripts\15
- HKU\S-1-5-21-1993962763-1935655697-1060284298-500\Software\Microsoft\Internet Explorer\International\Scripts\16
- HKU\S-1-5-21-1993962763-1935655697-1060284298-500\Software\Microsoft\Internet Explorer\International\Scripts\17
- HKU\S-1-5-21-1993962763-1935655697-1060284298-500\Software\Microsoft\Internet Explorer\International\Scripts\18
- HKU\S-1-5-21-1993962763-1935655697-1060284298-500\Software\Microsoft\Internet Explorer\International\Scripts\19
- HKU\S-1-5-21-1993962763-1935655697-1060284298-500\Software\Microsoft\Internet Explorer\International\Scripts\20
- HKU\S-1-5-21-1993962763-1935655697-1060284298-500\Software\Microsoft\Internet Explorer\International\Scripts\21
- HKU\S-1-5-21-1993962763-1935655697-1060284298-500\Software\Microsoft\Internet Explorer\International\Scripts\22
- HKU\S-1-5-21-1993962763-1935655697-1060284298-500\Software\Microsoft\Internet Explorer\International\Scripts\23
- HKU\S-1-5-21-1993962763-1935655697-1060284298-500\Software\Microsoft\Internet Explorer\International\Scripts\24
- HKU\S-1-5-21-1993962763-1935655697-1060284298-500\Software\Microsoft\Internet Explorer\International\Scripts\25
- HKU\S-1-5-21-1993962763-1935655697-1060284298-500\Software\Microsoft\Internet Explorer\International\Scripts\26
- HKU\S-1-5-21-1993962763-1935655697-1060284298-500\Software\Microsoft\Internet Explorer\International\Scripts\27
- HKU\S-1-5-21-1993962763-1935655697-1060284298-500\Software\Microsoft\Internet Explorer\International\Scripts\28
- HKU\S-1-5-21-1993962763-1935655697-1060284298-500\Software\Microsoft\Internet Explorer\International\Scripts\29
- HKU\S-1-5-21-1993962763-1935655697-1060284298-500\Software\Microsoft\Internet Explorer\International\Scripts\3
- HKU\S-1-5-21-1993962763-1935655697-1060284298-500\Software\Microsoft\Internet Explorer\International\Scripts\30
- HKU\S-1-5-21-1993962763-1935655697-1060284298-500\Software\Microsoft\Internet Explorer\International\Scripts\34
- HKU\S-1-5-21-1993962763-1935655697-1060284298-500\Software\Microsoft\Internet Explorer\International\Scripts\35
- HKU\S-1-5-21-1993962763-1935655697-1060284298-500\Software\Microsoft\Internet Explorer\International\Scripts\37
- HKU\S-1-5-21-1993962763-1935655697-1060284298-500\Software\Microsoft\Internet Explorer\International\Scripts\38
- HKU\S-1-5-21-1993962763-1935655697-1060284298-500\Software\Microsoft\Internet Explorer\International\Scripts\39
- HKU\S-1-5-21-1993962763-1935655697-1060284298-500\Software\Microsoft\Internet Explorer\International\Scripts\4
- HKU\S-1-5-21-1993962763-1935655697-1060284298-500\Software\Microsoft\Internet Explorer\International\Scripts\5
- HKU\S-1-5-21-1993962763-1935655697-1060284298-500\Software\Microsoft\Internet Explorer\International\Scripts\6
- HKU\S-1-5-21-1993962763-1935655697-1060284298-500\Software\Microsoft\Internet Explorer\International\Scripts\7
- HKU\S-1-5-21-1993962763-1935655697-1060284298-500\Software\Microsoft\Internet Explorer\International\Scripts\8
- HKU\S-1-5-21-1993962763-1935655697-1060284298-500\Software\Microsoft\Internet Explorer\International\Scripts\9
- HKU\S-1-5-21-1993962763-1935655697-1060284298-500\Software\Microsoft\Internet Explorer\InternetRegistry
- HKU\S-1-5-21-1993962763-1935655697-1060284298-500\Software\Microsoft\Internet Explorer\LinksBar
- HKU\S-1-5-21-1993962763-1935655697-1060284298-500\Software\Microsoft\Internet Explorer\LowRegistry
- HKU\S-1-5-21-1993962763-1935655697-1060284298-500\Software\Microsoft\Internet Explorer\Main
- HKU\S-1-5-21-1993962763-1935655697-1060284298-500\Software\Microsoft\Internet Explorer\Main\WindowsSearch
- HKU\S-1-5-21-1993962763-1935655697-1060284298-500\Software\Microsoft\Internet Explorer\New Windows
- HKU\S-1-5-21-1993962763-1935655697-1060284298-500\Software\Microsoft\Internet Explorer\SearchScopes
- HKU\S-1-5-21-1993962763-1935655697-1060284298-500\Software\Microsoft\Internet Explorer\SearchScopes\{014DB5FA-EAFB-4592-A95B-F44D3EE87FA9}
- HKU\S-1-5-21-1993962763-1935655697-1060284298-500\Software\Microsoft\Internet Explorer\SearchUrl
- HKU\S-1-5-21-1993962763-1935655697-1060284298-500\Software\Microsoft\Internet Explorer\Security
- HKU\S-1-5-21-1993962763-1935655697-1060284298-500\Software\Microsoft\Internet Explorer\Security\P3Global
- HKU\S-1-5-21-1993962763-1935655697-1060284298-500\Software\Microsoft\Internet Explorer\Security\P3Sites
- HKU\S-1-5-21-1993962763-1935655697-1060284298-500\Software\Microsoft\Internet Explorer\Services
- HKU\S-1-5-21-1993962763-1935655697-1060284298-500\Software\Microsoft\Internet Explorer\Settings
- HKU\S-1-5-21-1993962763-1935655697-1060284298-500\Software\Microsoft\Internet Explorer\SQM
- HKU\S-1-5-21-1993962763-1935655697-1060284298-500\Software\Microsoft\Internet Explorer\TabbedBrowsing
- HKU\S-1-5-21-1993962763-1935655697-1060284298-500\Software\Microsoft\Internet Explorer\Toolbar
- HKU\S-1-5-21-1993962763-1935655697-1060284298-500\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser
- HKU\S-1-5-21-1993962763-1935655697-1060284298-500\Software\Microsoft\Internet Explorer\TypedURLs
- HKU\S-1-5-21-1993962763-1935655697-1060284298-500\Software\Microsoft\Internet Explorer\URLSearchHooks
- ----------------------------------
- Values deleted:218
- ----------------------------------
- HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\SearchProtect\DisplayName: "Search Protect"
- HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\SearchProtect\DisplayIcon: "C:\PROGRA~1\SearchProtect\SearchProtect\bin\cltmng.exe"
- HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\SearchProtect\DisplayVersion: "2.17.26.7"
- HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\SearchProtect\Publisher: "Client Connect LTD"
- HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\SearchProtect\UninstallString: ""C:\PROGRA~1\SearchProtect\Main\bin\uninstall.exe" /S"
- HKLM\SOFTWARE\SearchProtect\Environment: ""
- HKLM\SOFTWARE\SearchProtect\InstallDir: "C:\PROGRA~1\SearchProtect"
- HKLM\SYSTEM\ControlSet001\Enum\Root\LEGACY_CLTMNGSVC\0000\Control\ActiveService: "CltMngSvc"
- HKLM\SYSTEM\ControlSet001\Enum\Root\LEGACY_CLTMNGSVC\0000\Service: "CltMngSvc"
- HKLM\SYSTEM\ControlSet001\Enum\Root\LEGACY_CLTMNGSVC\0000\Legacy: 0x00000001
- HKLM\SYSTEM\ControlSet001\Enum\Root\LEGACY_CLTMNGSVC\0000\ConfigFlags: 0x00000000
- HKLM\SYSTEM\ControlSet001\Enum\Root\LEGACY_CLTMNGSVC\0000\Class: "LegacyDriver"
- HKLM\SYSTEM\ControlSet001\Enum\Root\LEGACY_CLTMNGSVC\0000\ClassGUID: "{8ECC055D-047F-11D1-A537-0000F8753ED1}"
- HKLM\SYSTEM\ControlSet001\Enum\Root\LEGACY_CLTMNGSVC\0000\DeviceDesc: "Search Protect Service"
- HKLM\SYSTEM\ControlSet001\Enum\Root\LEGACY_CLTMNGSVC\NextInstance: 0x00000001
- HKLM\SYSTEM\ControlSet001\Services\CltMngSvc\Enum\0: "Root\LEGACY_CLTMNGSVC\0000"
- HKLM\SYSTEM\ControlSet001\Services\CltMngSvc\Enum\Count: 0x00000001
- HKLM\SYSTEM\ControlSet001\Services\CltMngSvc\Enum\NextInstance: 0x00000001
- HKLM\SYSTEM\ControlSet001\Services\CltMngSvc\Security\Security: 01 00 14 80 90 00 00 00 9C 00 00 00 14 00 00 00 30 00 00 00 02 00 1C 00 01 00 00 00 02 80 14 00 FF 01 0F 00 01 01 00 00 00 00 00 01 00 00 00 00 02 00 60 00 04 00 00 00 00 00 14 00 FD 01 02 00 01 01 00 00 00 00 00 05 12 00 00 00 00 00 18 00 FF 01 0F 00 01 02 00 00 00 00 00 05 20 00 00 00 20 02 00 00 00 00 14 00 8D 01 02 00 01 01 00 00 00 00 00 05 0B 00 00 00 00 00 18 00 FD 01 02 00 01 02 00 00 00 00 00 05 20 00 00 00 23 02 00 00 01 01 00 00 00 00 00 05 12 00 00 00 01 01 00 00 00 00 00 05 12 00 00 00
- HKLM\SYSTEM\ControlSet001\Services\CltMngSvc\Type: 0x00000010
- HKLM\SYSTEM\ControlSet001\Services\CltMngSvc\Start: 0x00000002
- HKLM\SYSTEM\ControlSet001\Services\CltMngSvc\ErrorControl: 0x00000001
- HKLM\SYSTEM\ControlSet001\Services\CltMngSvc\ImagePath: "C:\PROGRA~1\SearchProtect\Main\bin\CltMngSvc.exe"
- HKLM\SYSTEM\ControlSet001\Services\CltMngSvc\DisplayName: "Search Protect Service"
- HKLM\SYSTEM\ControlSet001\Services\CltMngSvc\ObjectName: "LocalSystem"
- HKLM\SYSTEM\ControlSet001\Services\CltMngSvc\DependOnService: 'TermService'
- HKLM\SYSTEM\ControlSet001\Services\CltMngSvc\DependOnGroup: 00
- HKLM\SYSTEM\ControlSet001\Services\CltMngSvc\Description: "This service loads the Search Protector, which maintains your selected Search settings, and enables auto-updates."
- HKLM\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_CLTMNGSVC\0000\Control\ActiveService: "CltMngSvc"
- HKLM\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_CLTMNGSVC\0000\Service: "CltMngSvc"
- HKLM\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_CLTMNGSVC\0000\Legacy: 0x00000001
- HKLM\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_CLTMNGSVC\0000\ConfigFlags: 0x00000000
- HKLM\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_CLTMNGSVC\0000\Class: "LegacyDriver"
- HKLM\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_CLTMNGSVC\0000\ClassGUID: "{8ECC055D-047F-11D1-A537-0000F8753ED1}"
- HKLM\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_CLTMNGSVC\0000\DeviceDesc: "Search Protect Service"
- HKLM\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_CLTMNGSVC\NextInstance: 0x00000001
- HKLM\SYSTEM\CurrentControlSet\Services\CltMngSvc\Enum\0: "Root\LEGACY_CLTMNGSVC\0000"
- HKLM\SYSTEM\CurrentControlSet\Services\CltMngSvc\Enum\Count: 0x00000001
- HKLM\SYSTEM\CurrentControlSet\Services\CltMngSvc\Enum\NextInstance: 0x00000001
- HKLM\SYSTEM\CurrentControlSet\Services\CltMngSvc\Security\Security: 01 00 14 80 90 00 00 00 9C 00 00 00 14 00 00 00 30 00 00 00 02 00 1C 00 01 00 00 00 02 80 14 00 FF 01 0F 00 01 01 00 00 00 00 00 01 00 00 00 00 02 00 60 00 04 00 00 00 00 00 14 00 FD 01 02 00 01 01 00 00 00 00 00 05 12 00 00 00 00 00 18 00 FF 01 0F 00 01 02 00 00 00 00 00 05 20 00 00 00 20 02 00 00 00 00 14 00 8D 01 02 00 01 01 00 00 00 00 00 05 0B 00 00 00 00 00 18 00 FD 01 02 00 01 02 00 00 00 00 00 05 20 00 00 00 23 02 00 00 01 01 00 00 00 00 00 05 12 00 00 00 01 01 00 00 00 00 00 05 12 00 00 00
- HKLM\SYSTEM\CurrentControlSet\Services\CltMngSvc\Type: 0x00000010
- HKLM\SYSTEM\CurrentControlSet\Services\CltMngSvc\Start: 0x00000002
- HKLM\SYSTEM\CurrentControlSet\Services\CltMngSvc\ErrorControl: 0x00000001
- HKLM\SYSTEM\CurrentControlSet\Services\CltMngSvc\ImagePath: "C:\PROGRA~1\SearchProtect\Main\bin\CltMngSvc.exe"
- HKLM\SYSTEM\CurrentControlSet\Services\CltMngSvc\DisplayName: "Search Protect Service"
- HKLM\SYSTEM\CurrentControlSet\Services\CltMngSvc\ObjectName: "LocalSystem"
- HKLM\SYSTEM\CurrentControlSet\Services\CltMngSvc\DependOnService: 'TermService'
- HKLM\SYSTEM\CurrentControlSet\Services\CltMngSvc\DependOnGroup: 00
- HKLM\SYSTEM\CurrentControlSet\Services\CltMngSvc\Description: "This service loads the Search Protector, which maintains your selected Search settings, and enables auto-updates."
- HKU\S-1-5-21-1993962763-1935655697-1060284298-500\Software\Microsoft\Internet Explorer\BrowserEmulation\TLDUpdates: 0x00000001
- HKU\S-1-5-21-1993962763-1935655697-1060284298-500\Software\Microsoft\Internet Explorer\Default HTML Editor\Stubs: 'msohtmed.exe'
- HKU\S-1-5-21-1993962763-1935655697-1060284298-500\Software\Microsoft\Internet Explorer\Desktop\Components\0\Source: "About:Home"
- HKU\S-1-5-21-1993962763-1935655697-1060284298-500\Software\Microsoft\Internet Explorer\Desktop\Components\0\SubscribedURL: "About:Home"
- HKU\S-1-5-21-1993962763-1935655697-1060284298-500\Software\Microsoft\Internet Explorer\Desktop\Components\0\FriendlyName: "Die derzeitige Homepage"
- HKU\S-1-5-21-1993962763-1935655697-1060284298-500\Software\Microsoft\Internet Explorer\Desktop\Components\0\Flags: 0x00000002
- HKU\S-1-5-21-1993962763-1935655697-1060284298-500\Software\Microsoft\Internet Explorer\Desktop\Components\0\Position: 2C 00 00 00 3F 01 00 00 00 00 00 00 FF 04 00 00 A3 02 00 00 00 00 00 00 01 00 00 00 01 00 00 00 01 00 00 00 00 00 00 00 00 00 00 00
- HKU\S-1-5-21-1993962763-1935655697-1060284298-500\Software\Microsoft\Internet Explorer\Desktop\Components\0\CurrentState: 04 00 00 40
- HKU\S-1-5-21-1993962763-1935655697-1060284298-500\Software\Microsoft\Internet Explorer\Desktop\Components\0\OriginalStateInfo: 18 00 00 00 FF FF 00 00 FF FF 00 00 FF FF FF FF FF FF FF FF 04 00 00 00
- HKU\S-1-5-21-1993962763-1935655697-1060284298-500\Software\Microsoft\Internet Explorer\Desktop\Components\0\RestoredStateInfo: 18 00 00 00 6A 02 00 00 23 00 00 00 A4 00 00 00 9A 00 00 00 01 00 00 00
- HKU\S-1-5-21-1993962763-1935655697-1060284298-500\Software\Microsoft\Internet Explorer\Desktop\SafeMode\General\Wallpaper: "%SystemRoot%\Web\SafeMode.htt"
- HKU\S-1-5-21-1993962763-1935655697-1060284298-500\Software\Microsoft\Internet Explorer\Desktop\SafeMode\General\VisitGallery: 0x00000000
- HKU\S-1-5-21-1993962763-1935655697-1060284298-500\Software\Microsoft\Internet Explorer\Desktop\Scheme\Edit: ""
- HKU\S-1-5-21-1993962763-1935655697-1060284298-500\Software\Microsoft\Internet Explorer\Desktop\Scheme\Display: ""
- HKU\S-1-5-21-1993962763-1935655697-1060284298-500\Software\Microsoft\Internet Explorer\Desktop\Old WorkAreas\NoOfOldWorkAreas: 0x00000001
- HKU\S-1-5-21-1993962763-1935655697-1060284298-500\Software\Microsoft\Internet Explorer\Desktop\Old WorkAreas\OldWorkAreaRects: 00 00 00 00 00 00 00 00 3E 06 00 00 6F 02 00 00
- HKU\S-1-5-21-1993962763-1935655697-1060284298-500\Software\Microsoft\Internet Explorer\Desktop\General\BackupWallpaper: "%SystemRoot%\web\wallpaper\Grüne Idylle.bmp"
- HKU\S-1-5-21-1993962763-1935655697-1060284298-500\Software\Microsoft\Internet Explorer\Desktop\General\WallpaperFileTime: 00 58 8C 01 95 66 01 02
- HKU\S-1-5-21-1993962763-1935655697-1060284298-500\Software\Microsoft\Internet Explorer\Desktop\General\WallpaperLocalFileTime: 00 C0 50 63 9D 66 01 02
- HKU\S-1-5-21-1993962763-1935655697-1060284298-500\Software\Microsoft\Internet Explorer\Desktop\General\TileWallpaper: "0"
- HKU\S-1-5-21-1993962763-1935655697-1060284298-500\Software\Microsoft\Internet Explorer\Desktop\General\WallpaperStyle: "2"
- HKU\S-1-5-21-1993962763-1935655697-1060284298-500\Software\Microsoft\Internet Explorer\Desktop\General\Wallpaper: "%SystemRoot%\web\wallpaper\Grüne Idylle.bmp"
- HKU\S-1-5-21-1993962763-1935655697-1060284298-500\Software\Microsoft\Internet Explorer\Desktop\General\ComponentsPositioned: 0x00000001
- HKU\S-1-5-21-1993962763-1935655697-1060284298-500\Software\Microsoft\Internet Explorer\Desktop\Components\DeskHtmlVersion: 0x00000110
- HKU\S-1-5-21-1993962763-1935655697-1060284298-500\Software\Microsoft\Internet Explorer\Desktop\Components\DeskHtmlMinorVersion: 0x00000005
- HKU\S-1-5-21-1993962763-1935655697-1060284298-500\Software\Microsoft\Internet Explorer\Desktop\Components\Settings: 0x00000001
- HKU\S-1-5-21-1993962763-1935655697-1060284298-500\Software\Microsoft\Internet Explorer\Desktop\Components\GeneralFlags: 0x00000001
- HKU\S-1-5-21-1993962763-1935655697-1060284298-500\Software\Microsoft\Internet Explorer\Document Windows\Maximized: "no"
- HKU\S-1-5-21-1993962763-1935655697-1060284298-500\Software\Microsoft\Internet Explorer\Document Windows\height: 00 00 00 00
- HKU\S-1-5-21-1993962763-1935655697-1060284298-500\Software\Microsoft\Internet Explorer\Document Windows\width: 00 00 00 80
- HKU\S-1-5-21-1993962763-1935655697-1060284298-500\Software\Microsoft\Internet Explorer\Document Windows\x: 00 00 00 80
- HKU\S-1-5-21-1993962763-1935655697-1060284298-500\Software\Microsoft\Internet Explorer\Document Windows\y: 00 00 00 00
- HKU\S-1-5-21-1993962763-1935655697-1060284298-500\Software\Microsoft\Internet Explorer\Download\CheckExeSignatures: "yes"
- HKU\S-1-5-21-1993962763-1935655697-1060284298-500\Software\Microsoft\Internet Explorer\Extensions\CmdMapping\{e2e2dd38-d088-4134-82b7-f2ba38496583}: 0x00002000
- HKU\S-1-5-21-1993962763-1935655697-1060284298-500\Software\Microsoft\Internet Explorer\Extensions\CmdMapping\NextId: 0x00002002
- HKU\S-1-5-21-1993962763-1935655697-1060284298-500\Software\Microsoft\Internet Explorer\Extensions\CmdMapping\{FB5F1910-F110-11d2-BB9E-00C04F795683}: 0x00002001
- HKU\S-1-5-21-1993962763-1935655697-1060284298-500\Software\Microsoft\Internet Explorer\IETld\IETldDllVersionHigh: 0x00080000
- HKU\S-1-5-21-1993962763-1935655697-1060284298-500\Software\Microsoft\Internet Explorer\IETld\IETldDllVersionLow: 0x17714BBD
- HKU\S-1-5-21-1993962763-1935655697-1060284298-500\Software\Microsoft\Internet Explorer\IETld\IETldVersionHigh: 0x00000001
- HKU\S-1-5-21-1993962763-1935655697-1060284298-500\Software\Microsoft\Internet Explorer\IETld\IETldVersionLow: 0x00000008
- HKU\S-1-5-21-1993962763-1935655697-1060284298-500\Software\Microsoft\Internet Explorer\IETld\StaleIETldCache: 0x00000001
- HKU\S-1-5-21-1993962763-1935655697-1060284298-500\Software\Microsoft\Internet Explorer\International\Scripts\9\IEPropFontName: "Simplified Arabic"
- HKU\S-1-5-21-1993962763-1935655697-1060284298-500\Software\Microsoft\Internet Explorer\International\Scripts\9\IEFixedFontName: "Simplified Arabic Fixed"
- HKU\S-1-5-21-1993962763-1935655697-1060284298-500\Software\Microsoft\Internet Explorer\International\Scripts\8\IEPropFontName: "David"
- HKU\S-1-5-21-1993962763-1935655697-1060284298-500\Software\Microsoft\Internet Explorer\International\Scripts\8\IEFixedFontName: "Miriam Fixed"
- HKU\S-1-5-21-1993962763-1935655697-1060284298-500\Software\Microsoft\Internet Explorer\International\Scripts\7\IEPropFontName: "Sylfaen"
- HKU\S-1-5-21-1993962763-1935655697-1060284298-500\Software\Microsoft\Internet Explorer\International\Scripts\7\IEFixedFontName: "Sylfaen"
- HKU\S-1-5-21-1993962763-1935655697-1060284298-500\Software\Microsoft\Internet Explorer\International\Scripts\6\IEPropFontName: "Times New Roman"
- HKU\S-1-5-21-1993962763-1935655697-1060284298-500\Software\Microsoft\Internet Explorer\International\Scripts\6\IEFixedFontName: "Courier New"
- HKU\S-1-5-21-1993962763-1935655697-1060284298-500\Software\Microsoft\Internet Explorer\International\Scripts\5\IEPropFontName: "Times New Roman"
- HKU\S-1-5-21-1993962763-1935655697-1060284298-500\Software\Microsoft\Internet Explorer\International\Scripts\5\IEFixedFontName: "Courier New"
- HKU\S-1-5-21-1993962763-1935655697-1060284298-500\Software\Microsoft\Internet Explorer\International\Scripts\4\IEPropFontName: "Times New Roman"
- HKU\S-1-5-21-1993962763-1935655697-1060284298-500\Software\Microsoft\Internet Explorer\International\Scripts\4\IEFixedFontName: "Courier New"
- HKU\S-1-5-21-1993962763-1935655697-1060284298-500\Software\Microsoft\Internet Explorer\International\Scripts\39\IEPropFontName: "Mongolian Baiti"
- HKU\S-1-5-21-1993962763-1935655697-1060284298-500\Software\Microsoft\Internet Explorer\International\Scripts\39\IEFixedFontName: "Mongolian Baiti"
- HKU\S-1-5-21-1993962763-1935655697-1060284298-500\Software\Microsoft\Internet Explorer\International\Scripts\38\IEPropFontName: "MV Boli"
- HKU\S-1-5-21-1993962763-1935655697-1060284298-500\Software\Microsoft\Internet Explorer\International\Scripts\38\IEFixedFontName: "MV Boli"
- HKU\S-1-5-21-1993962763-1935655697-1060284298-500\Software\Microsoft\Internet Explorer\International\Scripts\37\IEPropFontName: "DaunPenh"
- HKU\S-1-5-21-1993962763-1935655697-1060284298-500\Software\Microsoft\Internet Explorer\International\Scripts\37\IEFixedFontName: "DaunPenh"
- HKU\S-1-5-21-1993962763-1935655697-1060284298-500\Software\Microsoft\Internet Explorer\International\Scripts\35\IEPropFontName: "Estrangelo Edessa"
- HKU\S-1-5-21-1993962763-1935655697-1060284298-500\Software\Microsoft\Internet Explorer\International\Scripts\35\IEFixedFontName: "Estrangelo Edessa"
- HKU\S-1-5-21-1993962763-1935655697-1060284298-500\Software\Microsoft\Internet Explorer\International\Scripts\34\IEPropFontName: "Iskoola Pota"
- HKU\S-1-5-21-1993962763-1935655697-1060284298-500\Software\Microsoft\Internet Explorer\International\Scripts\34\IEFixedFontName: "Iskoola Pota"
- HKU\S-1-5-21-1993962763-1935655697-1060284298-500\Software\Microsoft\Internet Explorer\International\Scripts\30\IEPropFontName: "Microsoft Yi Baiti"
- HKU\S-1-5-21-1993962763-1935655697-1060284298-500\Software\Microsoft\Internet Explorer\International\Scripts\30\IEFixedFontName: "Microsoft Yi Baiti"
- HKU\S-1-5-21-1993962763-1935655697-1060284298-500\Software\Microsoft\Internet Explorer\International\Scripts\3\IEPropFontName: "Times New Roman"
- HKU\S-1-5-21-1993962763-1935655697-1060284298-500\Software\Microsoft\Internet Explorer\International\Scripts\3\IEFixedFontName: "Courier New"
- HKU\S-1-5-21-1993962763-1935655697-1060284298-500\Software\Microsoft\Internet Explorer\International\Scripts\29\IEPropFontName: "Plantagenet Cherokee"
- HKU\S-1-5-21-1993962763-1935655697-1060284298-500\Software\Microsoft\Internet Explorer\International\Scripts\29\IEFixedFontName: "Plantagenet Cherokee"
- HKU\S-1-5-21-1993962763-1935655697-1060284298-500\Software\Microsoft\Internet Explorer\International\Scripts\28\IEPropFontName: "Euphemia"
- HKU\S-1-5-21-1993962763-1935655697-1060284298-500\Software\Microsoft\Internet Explorer\International\Scripts\28\IEFixedFontName: "Euphemia"
- HKU\S-1-5-21-1993962763-1935655697-1060284298-500\Software\Microsoft\Internet Explorer\International\Scripts\27\IEPropFontName: "Nyala"
- HKU\S-1-5-21-1993962763-1935655697-1060284298-500\Software\Microsoft\Internet Explorer\International\Scripts\27\IEFixedFontName: "Nyala"
- HKU\S-1-5-21-1993962763-1935655697-1060284298-500\Software\Microsoft\Internet Explorer\International\Scripts\26\IEPropFontName: "Simsun"
- HKU\S-1-5-21-1993962763-1935655697-1060284298-500\Software\Microsoft\Internet Explorer\International\Scripts\26\IEFixedFontName: "NSimsun"
- HKU\S-1-5-21-1993962763-1935655697-1060284298-500\Software\Microsoft\Internet Explorer\International\Scripts\25\IEPropFontName: "PMingLiu"
- HKU\S-1-5-21-1993962763-1935655697-1060284298-500\Software\Microsoft\Internet Explorer\International\Scripts\25\IEFixedFontName: "MingLiu"
- HKU\S-1-5-21-1993962763-1935655697-1060284298-500\Software\Microsoft\Internet Explorer\International\Scripts\24\IEPropFontName: "MS PGothic"
- HKU\S-1-5-21-1993962763-1935655697-1060284298-500\Software\Microsoft\Internet Explorer\International\Scripts\24\IEFixedFontName: "MS Gothic"
- HKU\S-1-5-21-1993962763-1935655697-1060284298-500\Software\Microsoft\Internet Explorer\International\Scripts\23\IEPropFontName: "Gulim"
- HKU\S-1-5-21-1993962763-1935655697-1060284298-500\Software\Microsoft\Internet Explorer\International\Scripts\23\IEFixedFontName: "GulimChe"
- HKU\S-1-5-21-1993962763-1935655697-1060284298-500\Software\Microsoft\Internet Explorer\International\Scripts\22\IEPropFontName: "Sylfaen"
- HKU\S-1-5-21-1993962763-1935655697-1060284298-500\Software\Microsoft\Internet Explorer\International\Scripts\22\IEFixedFontName: "Sylfaen"
- HKU\S-1-5-21-1993962763-1935655697-1060284298-500\Software\Microsoft\Internet Explorer\International\Scripts\21\IEPropFontName: "Microsoft Himalaya"
- HKU\S-1-5-21-1993962763-1935655697-1060284298-500\Software\Microsoft\Internet Explorer\International\Scripts\21\IEFixedFontName: "Microsoft Himalaya"
- HKU\S-1-5-21-1993962763-1935655697-1060284298-500\Software\Microsoft\Internet Explorer\International\Scripts\20\IEPropFontName: "DokChampa"
- HKU\S-1-5-21-1993962763-1935655697-1060284298-500\Software\Microsoft\Internet Explorer\International\Scripts\20\IEFixedFontName: "DokChampa"
- HKU\S-1-5-21-1993962763-1935655697-1060284298-500\Software\Microsoft\Internet Explorer\International\Scripts\19\IEPropFontName: "Tahoma"
- HKU\S-1-5-21-1993962763-1935655697-1060284298-500\Software\Microsoft\Internet Explorer\International\Scripts\19\IEFixedFontName: "Tahoma"
- HKU\S-1-5-21-1993962763-1935655697-1060284298-500\Software\Microsoft\Internet Explorer\International\Scripts\18\IEPropFontName: "Kartika"
- HKU\S-1-5-21-1993962763-1935655697-1060284298-500\Software\Microsoft\Internet Explorer\International\Scripts\18\IEFixedFontName: "Kartika"
- HKU\S-1-5-21-1993962763-1935655697-1060284298-500\Software\Microsoft\Internet Explorer\International\Scripts\17\IEPropFontName: "Tunga"
- HKU\S-1-5-21-1993962763-1935655697-1060284298-500\Software\Microsoft\Internet Explorer\International\Scripts\17\IEFixedFontName: "Tunga"
- HKU\S-1-5-21-1993962763-1935655697-1060284298-500\Software\Microsoft\Internet Explorer\International\Scripts\16\IEPropFontName: "Gautami"
- HKU\S-1-5-21-1993962763-1935655697-1060284298-500\Software\Microsoft\Internet Explorer\International\Scripts\16\IEFixedFontName: "Gautami"
- HKU\S-1-5-21-1993962763-1935655697-1060284298-500\Software\Microsoft\Internet Explorer\International\Scripts\15\IEPropFontName: "Latha"
- HKU\S-1-5-21-1993962763-1935655697-1060284298-500\Software\Microsoft\Internet Explorer\International\Scripts\15\IEFixedFontName: "Latha"
- HKU\S-1-5-21-1993962763-1935655697-1060284298-500\Software\Microsoft\Internet Explorer\International\Scripts\14\IEPropFontName: "Kalinga"
- HKU\S-1-5-21-1993962763-1935655697-1060284298-500\Software\Microsoft\Internet Explorer\International\Scripts\14\IEFixedFontName: "Kalinga"
- HKU\S-1-5-21-1993962763-1935655697-1060284298-500\Software\Microsoft\Internet Explorer\International\Scripts\13\IEPropFontName: "Shruti"
- HKU\S-1-5-21-1993962763-1935655697-1060284298-500\Software\Microsoft\Internet Explorer\International\Scripts\13\IEFixedFontName: "Shruti"
- HKU\S-1-5-21-1993962763-1935655697-1060284298-500\Software\Microsoft\Internet Explorer\International\Scripts\12\IEPropFontName: "Raavi"
- HKU\S-1-5-21-1993962763-1935655697-1060284298-500\Software\Microsoft\Internet Explorer\International\Scripts\12\IEFixedFontName: "Raavi"
- HKU\S-1-5-21-1993962763-1935655697-1060284298-500\Software\Microsoft\Internet Explorer\International\Scripts\11\IEPropFontName: "Vrinda"
- HKU\S-1-5-21-1993962763-1935655697-1060284298-500\Software\Microsoft\Internet Explorer\International\Scripts\11\IEFixedFontName: "Vrinda"
- HKU\S-1-5-21-1993962763-1935655697-1060284298-500\Software\Microsoft\Internet Explorer\International\Scripts\10\IEPropFontName: "Mangal"
- HKU\S-1-5-21-1993962763-1935655697-1060284298-500\Software\Microsoft\Internet Explorer\International\Scripts\10\IEFixedFontName: "Mangal"
- HKU\S-1-5-21-1993962763-1935655697-1060284298-500\Software\Microsoft\Internet Explorer\International\: ""
- HKU\S-1-5-21-1993962763-1935655697-1060284298-500\Software\Microsoft\Internet Explorer\International\CodePointToFontMap: 22 00 00 00 54 00 69 00 6D 00 65 00 73 00 20 00 4E 00 65 00 77 00 20 00 52 00 6F 00 6D 00 61 00 6E 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 4D 00 69 00 63 00 72 00 6F 00 73 00 6F 00 66 00 74 00 20 00 53 00 61 00 6E 00 73 00 20 00 53 00 65 00 72 00 69 00 66 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 4C 00 75 00 63 00 69 00 64 00 61 00 20 00 53 00 61 00 6E 00 73 00 20 00 55 00 6E 00 69 00 63 00 6F 00 64 00 65 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 53 00 79 00 6C 00 66 00 61 00 65 00 6E 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 45 00 73 00 74 00 72 00 61 00 6E 00 67 00 65 00 6C 00 6F 00 20 00 45 00 64 00 65 00 73 00 73 00 61 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 4D 00 56 00 20 00 42 00 6F 00 6C 00 69 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 4D 00 61 00 6E 00 67 00 61 00 6C 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 56 00 72 00 69 00 6E 00 64 00 61 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 52 00 61 00 61 00 76 00 69 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 53 00 68 00 72 00 75 00 74 00 69 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 4B 00 61 00 6C 00 69 00 6E 00 67 00 61 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 4C 00 61 00 74 00 68 00 61 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 47 00 61 00 75 00 74 00 61 00 6D 00 69 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 54 00 75 00 6E 00 67 00 61 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 4B 00 61 00 72 00 74 00 69 00 6B 00 61 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 49 00 73 00 6B 00 6F 00 6F 00 6C 00 61 00 20 00 50 00 6F 00 74 00 61 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 54 00 61 00 68 00 6F 00 6D 00 61 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 44 00 6F 00 6B 00 43 00 68 00 61 00 6D 00 70 00 61 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 53 00 69 00 6D 00 53 00 75 00 6E 00 2D 00 31 00 38 00 30 00 33 00 30 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 42 00 61 00 74 00 61 00 6E 00 67 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 4E 00 79 00 61 00 6C 00 61 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 50 00 6C 00 61 00 6E 00 74 00 61 00 67 00 65 00 6E 00 65 00 74 00 20 00 43 00 68 00 65 00 72 00 6F 00 6B 00 65 00 65 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 45 00 75 00 70 00 68 00 65 00 6D 00 69 00 61 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 44 00 61 00 75 00 6E 00 50 00 65 00 6E 00 68 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 4D 00 53 00 20 00 4D 00 69 00 6E 00 63 00 68 00 6F 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 50 00 4D 00 69 00 6E 00 67 00 4C 00 69 00 75 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 4D 00 65 00 69 00 72 00 79 00 6F 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 53 00 69 00 6D 00 53 00 75 00 6E 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 4D 00 69 00 6E 00 67 00 4C 00 69 00 55 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 50 00 4D 00 69 00 6E 00 67 00 4C 00 69 00 55 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 50 00 61 00 6C 00 61 00 74 00 69 00 6E 00 6F 00 20 00 4C 00 69 00 6E 00 6F 00 74 00 79 00 70 00 65 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 54 00 72 00 61 00 64 00 69 00 74 00 69 00 6F 00 6E 00 61 00 6C 00 20 00 41 00 72 00 61 00 62 00 69 00 63 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 53 00 69 00 6D 00 70 00 6C 00 69 00 66 00 69 00 65 00 64 00 20 00 41 00 72 00 61 00 62 00 69 00 63 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 4D 00 69 00 6E 00 67 00 4C 00 69 00 55 00 2D 00 45 00 78 00 74 00 42 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 5A 00 00 00 20 00 00 00 7F 00 00 00 00 A0 00 00 00 7F 01 00 00 00 80 01 00 00 AF 02 00 00 01 B0 02 00 00 FF 02 00 00 02 00 03 00 00 6F 03 00 00 01 70 03 00 00 7A 03 00 00 02 7B 03 00 00 CF 03 00 00 00 D0 03 00 00 2F 05 00 00 01 30 05 00 00 8F 05 00 00 03 B0 05 00 00 FF 06 00 00 00 00 07 00 00 4F 07 00 00 04 80 07 00 00 BF 07 00 00 05 00 09 00 00 7F 09 00 00 06 80 09 00 00 FF 09 00 00 07 00 0A 00 00 7F 0A 00 00 08 80 0A 00 00 FF 0A 00 00 09 00 0B 00 00 7F 0B 00 00 0A 80 0B 00 00 FF 0B 00 00 0B 00 0C 00 00 7F 0C 00 00 0C 80 0C 00 00 FF 0C 00 00 0D 00 0D 00 00 7F 0D 00 00 0E 80 0D 00 00 FF 0D 00 00 0F 00 0E 00 00 7F 0E 00 00 10 80 0E 00 00 FF 0E 00 00 11 00 0F 00 00 FF 0F 00 00 12 A0 10 00 00 FF 10 00 00 03 00 11 00 00 FF 11 00 00 13 00 12 00 00 9F 13 00 00 14 A0 13 00 00 FF 13 00 00 15 00 14 00 00 7F 16 00 00 16 80 17 00 00 FF 17 00 00 17 00 18 00 00 AF 18 00 00 12 E0 19 00 00 FF 19 00 00 17 00 1E 00 00 9F 1E 00 00 01 A0 1E 00 00 FF 1E 00 00 00 00 1F 00 00 FF 1F 00 00 01 00 20 00 00 3E 20 00 00 02 3F 20 00 00 5F 20 00 00 18 60 20 00 00 6F 20 00 00 00 70 20 00 00 9F 20 00 00 18 A0 20 00 00 CF 20 00 00 01 00 21 00 00 38 21 00 00 18 50 21 00 00 F1 22 00 00 18 00 23 00 00 06 23 00 00 02 07 23 00 00 07 23 00 00 19 08 23 00 00 0F 23 00 00 02 10 23 00 00 1F 23 00 00 18 20 23 00 00 3F 24 00 00 02 40 24 00 00 5F 24 00 00 1A 60 24 00 00 6F 26 00 00 18 70 26 00 00 FF 26 00 00 04 00 27 00 00 BF 27 00 00 18 80 2E 00 00 FF 2E 00 00 1B 00 2F 00 00 DF 2F 00 00 1A F0 2F 00 00 FF 2F 00 00 1B 00 30 00 00 20 30 00 00 18 21 30 00 00 2F 30 00 00 1B 30 30 00 00 37 30 00 00 18 3E 30 00 00 3F 30 00 00 12 40 30 00 00 FF 30 00 00 18 00 31 00 00 2F 31 00 00 1B 30 31 00 00 8F 31 00 00 13 90 31 00 00 9F 31 00 00 1C F0 31 00 00 FF 31 00 00 18 00 32 00 00 1F 32 00 00 13 20 32 00 00 43 32 00 00 18 60 32 00 00 7F 32 00 00 13 80 32 00 00 FF 33 00 00 18 00 34 00 00 BF 4D 00 00 12 00 4E 00 00 FF 9F 00 00 1B 00 A0 00 00 CF A4 00 00 12 00 AC 00 00 AF D7 00 00 13 00 F9 00 00 FF FA 00 00 1D 00 FB 00 00 0F FB 00 00 1E 10 FB 00 00 17 FB 00 00 03 18 FB 00 00 E7 FB 00 00 00 E8 FB 00 00 FB FB 00 00 12 FC FB 00 00 FF FB 00 00 00 00 FC 00 00 F0 FD 00 00 1F F2 FD 00 00 F2 FD 00 00 00 00 FE 00 00 0F FE 00 00 1B 30 FE 00 00 6F FE 00 00 1B 70 FE 00 00 7F FE 00 00 20 80 FE 00 00 FF FE 00 00 00 00 FF 00 00 E5 FF 00 00 18 E6 FF 00 00 E6 FF 00 00 13 E7 FF 00 00 EF FF 00 00 18 F0 FF 00 00 FF FF 00 00 00 00 00 02 00 DF A6 02 00 21 00 F8 02 00 1F FA 02 00 21
- HKU\S-1-5-21-1993962763-1935655697-1060284298-500\Software\Microsoft\Internet Explorer\LinksBar\LinksFolderMigrate: C2 B4 03 CB 52 DF CD 01
- HKU\S-1-5-21-1993962763-1935655697-1060284298-500\Software\Microsoft\Internet Explorer\Main\WindowsSearch\Version: "WS not installed"
- HKU\S-1-5-21-1993962763-1935655697-1060284298-500\Software\Microsoft\Internet Explorer\Main\NoUpdateCheck: 0x00000001
- HKU\S-1-5-21-1993962763-1935655697-1060284298-500\Software\Microsoft\Internet Explorer\Main\NoJITSetup: 0x00000001
- HKU\S-1-5-21-1993962763-1935655697-1060284298-500\Software\Microsoft\Internet Explorer\Main\Disable Script Debugger: "yes"
- HKU\S-1-5-21-1993962763-1935655697-1060284298-500\Software\Microsoft\Internet Explorer\Main\Show_ChannelBand: "No"
- HKU\S-1-5-21-1993962763-1935655697-1060284298-500\Software\Microsoft\Internet Explorer\Main\Anchor Underline: "yes"
- HKU\S-1-5-21-1993962763-1935655697-1060284298-500\Software\Microsoft\Internet Explorer\Main\Cache_Update_Frequency: "Once_Per_Session"
- HKU\S-1-5-21-1993962763-1935655697-1060284298-500\Software\Microsoft\Internet Explorer\Main\Display Inline Images: "yes"
- HKU\S-1-5-21-1993962763-1935655697-1060284298-500\Software\Microsoft\Internet Explorer\Main\Do404Search: 01 00 00 00
- HKU\S-1-5-21-1993962763-1935655697-1060284298-500\Software\Microsoft\Internet Explorer\Main\Local Page: "C:\WINDOWS\system32\blank.htm"
- HKU\S-1-5-21-1993962763-1935655697-1060284298-500\Software\Microsoft\Internet Explorer\Main\Save_Session_History_On_Exit: "no"
- HKU\S-1-5-21-1993962763-1935655697-1060284298-500\Software\Microsoft\Internet Explorer\Main\Show_FullURL: "no"
- HKU\S-1-5-21-1993962763-1935655697-1060284298-500\Software\Microsoft\Internet Explorer\Main\Show_StatusBar: "yes"
- HKU\S-1-5-21-1993962763-1935655697-1060284298-500\Software\Microsoft\Internet Explorer\Main\Show_ToolBar: "yes"
- HKU\S-1-5-21-1993962763-1935655697-1060284298-500\Software\Microsoft\Internet Explorer\Main\Show_URLinStatusBar: "yes"
- HKU\S-1-5-21-1993962763-1935655697-1060284298-500\Software\Microsoft\Internet Explorer\Main\Show_URLToolBar: "yes"
- HKU\S-1-5-21-1993962763-1935655697-1060284298-500\Software\Microsoft\Internet Explorer\Main\Start Page: "http://www.trovi.com/?gd=&ctid=CT3321459&octid=EB_ORIGINAL_CTID&ISID=MF8575A3C-5DCE-4DA0-AF5B-98266E835B28&SearchSource=55&CUI=&UM=6&UP=SP0FB0FC83-723F-4F4D-9219-C800358444A0&SSPV="
- HKU\S-1-5-21-1993962763-1935655697-1060284298-500\Software\Microsoft\Internet Explorer\Main\Use_DlgBox_Colors: "yes"
- HKU\S-1-5-21-1993962763-1935655697-1060284298-500\Software\Microsoft\Internet Explorer\Main\Search Page: "http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch"
- HKU\S-1-5-21-1993962763-1935655697-1060284298-500\Software\Microsoft\Internet Explorer\Main\NotifyDownloadComplete: "yes"
- HKU\S-1-5-21-1993962763-1935655697-1060284298-500\Software\Microsoft\Internet Explorer\Main\FullScreen: "no"
- HKU\S-1-5-21-1993962763-1935655697-1060284298-500\Software\Microsoft\Internet Explorer\Main\Window_Placement: 2C 00 00 00 02 00 00 00 03 00 00 00 FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF FF 16 00 00 00 1D 00 00 00 6E 02 00 00 B1 01 00 00
- HKU\S-1-5-21-1993962763-1935655697-1060284298-500\Software\Microsoft\Internet Explorer\Main\XMLHTTP: 0x00000001
- HKU\S-1-5-21-1993962763-1935655697-1060284298-500\Software\Microsoft\Internet Explorer\Main\UseClearType: "yes"
- HKU\S-1-5-21-1993962763-1935655697-1060284298-500\Software\Microsoft\Internet Explorer\Main\Enable Browser Extensions: "yes"
- HKU\S-1-5-21-1993962763-1935655697-1060284298-500\Software\Microsoft\Internet Explorer\Main\Play_Background_Sounds: "yes"
- HKU\S-1-5-21-1993962763-1935655697-1060284298-500\Software\Microsoft\Internet Explorer\Main\Play_Animations: "yes"
- HKU\S-1-5-21-1993962763-1935655697-1060284298-500\Software\Microsoft\Internet Explorer\New Windows\PopupMgr: "yes"
- HKU\S-1-5-21-1993962763-1935655697-1060284298-500\Software\Microsoft\Internet Explorer\New Windows\PlaySound: 0x00000001
- HKU\S-1-5-21-1993962763-1935655697-1060284298-500\Software\Microsoft\Internet Explorer\New Windows\UseSecBand: 0x00000001
- HKU\S-1-5-21-1993962763-1935655697-1060284298-500\Software\Microsoft\Internet Explorer\SearchScopes\{014DB5FA-EAFB-4592-A95B-F44D3EE87FA9}\URL: "http://www.trovi.com/Results.aspx?gd=&ctid=CT3321459&octid=EB_ORIGINAL_CTID&ISID=MF8575A3C-5DCE-4DA0-AF5B-98266E835B28&SearchSource=58&CUI=&UM=6&UP=SP0FB0FC83-723F-4F4D-9219-C800358444A0&q={searchTerms}&SSPV="
- HKU\S-1-5-21-1993962763-1935655697-1060284298-500\Software\Microsoft\Internet Explorer\SearchScopes\{014DB5FA-EAFB-4592-A95B-F44D3EE87FA9}\SuggestionsURL_JSON: "http://suggest.seccint.com/CSuggestJson.ashx?prefix={searchTerms}"
- HKU\S-1-5-21-1993962763-1935655697-1060284298-500\Software\Microsoft\Internet Explorer\SearchScopes\{014DB5FA-EAFB-4592-A95B-F44D3EE87FA9}\DisplayName: "Trovi search"
- HKU\S-1-5-21-1993962763-1935655697-1060284298-500\Software\Microsoft\Internet Explorer\SearchScopes\{014DB5FA-EAFB-4592-A95B-F44D3EE87FA9}\ShowSearchSuggestions: 0x00000001
- HKU\S-1-5-21-1993962763-1935655697-1060284298-500\Software\Microsoft\Internet Explorer\SearchScopes\{014DB5FA-EAFB-4592-A95B-F44D3EE87FA9}\Deleted: 0x00000000
- HKU\S-1-5-21-1993962763-1935655697-1060284298-500\Software\Microsoft\Internet Explorer\SearchScopes\ShowSearchSuggestionsInAddressGlobal: 0x00000001
- HKU\S-1-5-21-1993962763-1935655697-1060284298-500\Software\Microsoft\Internet Explorer\SearchScopes\DefaultScope: "{014DB5FA-EAFB-4592-A95B-F44D3EE87FA9}"
- HKU\S-1-5-21-1993962763-1935655697-1060284298-500\Software\Microsoft\Internet Explorer\SearchUrl\provider: ""
- HKU\S-1-5-21-1993962763-1935655697-1060284298-500\Software\Microsoft\Internet Explorer\Security\P3Global\Enabled: 0x00000001
- HKU\S-1-5-21-1993962763-1935655697-1060284298-500\Software\Microsoft\Internet Explorer\Security\Sending_Security: "Medium"
- HKU\S-1-5-21-1993962763-1935655697-1060284298-500\Software\Microsoft\Internet Explorer\Security\Viewing_Security: "Low"
- HKU\S-1-5-21-1993962763-1935655697-1060284298-500\Software\Microsoft\Internet Explorer\Security\Safety Warning Level: "Query"
- HKU\S-1-5-21-1993962763-1935655697-1060284298-500\Software\Microsoft\Internet Explorer\Services\: ""
- HKU\S-1-5-21-1993962763-1935655697-1060284298-500\Software\Microsoft\Internet Explorer\Settings\Anchor Color Visited: "128,0,128"
- HKU\S-1-5-21-1993962763-1935655697-1060284298-500\Software\Microsoft\Internet Explorer\Settings\Anchor Color: "0,0,255"
- HKU\S-1-5-21-1993962763-1935655697-1060284298-500\Software\Microsoft\Internet Explorer\Settings\Background Color: "192,192,192"
- HKU\S-1-5-21-1993962763-1935655697-1060284298-500\Software\Microsoft\Internet Explorer\Settings\Text Color: "0,0,0"
- HKU\S-1-5-21-1993962763-1935655697-1060284298-500\Software\Microsoft\Internet Explorer\Settings\Use Anchor Hover Color: "No"
- HKU\S-1-5-21-1993962763-1935655697-1060284298-500\Software\Microsoft\Internet Explorer\SQM\InstallDate: B4 19 D4 50 00 00 00 00
- HKU\S-1-5-21-1993962763-1935655697-1060284298-500\Software\Microsoft\Internet Explorer\TabbedBrowsing\NewTabPageShow: 0x00000000
- HKU\S-1-5-21-1993962763-1935655697-1060284298-500\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\{01E04581-4EEE-11D0-BFE9-00AA005B4383}: 81 45 E0 01 EE 4E D0 11 BF E9 00 AA 00 5B 43 83 10 00 00 00 00 00 00 00 01 E0 32 F4 01 00 00 00
- HKU\S-1-5-21-1993962763-1935655697-1060284298-500\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\{0E5CBF21-D15F-11D0-8301-00AA005B4383}: 21 BF 5C 0E 5F D1 D0 11 83 01 00 AA 00 5B 43 83 22 00 1C 00 08 00 00 00 06 00 00 00 01 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 4C 00 00 00 01 14 02 00 00 00 00 00 C0 00 00 00 00 00 00 46 81 00 00 00 10 00 00 00 10 8E C1 EB 9A 66 01 02 E0 75 5E D5 87 6A 01 02 80 CE 91 F3 9A 66 01 02 00 00 00 00 00 00 00 00 01 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 6B 01 14 00 1F 50 E0 4F D0 20 EA 3A 69 10 A2 D8 08 00 2B 30 30 9D 19 00 2F 43 3A 5C 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 66 00 31 00 00 00 00 00 87 9D 5C 41 10 00 44 4F 4B 55 4D 45 7E 31 00 00 4E 00 03 00 04 00 EF BE 84 9D 60 09 8C 9D 78 40 14 00 00 00 44 00 6F 00 6B 00 75 00 6D 00 65 00 6E 00 74 00 65 00 20 00 75 00 6E 00 64 00 20 00 45 00 69 00 6E 00 73 00 74 00 65 00 6C 00 6C 00 75 00 6E 00 67 00 65 00 6E 00 00 00 18 00 4A 00 31 00 00 00 00 00 87 9D 60 41 10 00 41 44 4D 49 4E 49 7E 31 00 00 32 00 03 00 04 00 EF BE 87 9D 5C 41 8C 9D 78 40 14 00 00 00 41 00 64 00 6D 00 69 00 6E 00 69 00 73 00 74 00 72 00 61 00 74 00 6F 00 72 00 00 00 18 00 56 00 31 00 00 00 00 00 87 9D 68 41 11 00 46 41 56 4F 52 49 7E 31 00 00 3E 00 03 00 04 00 EF BE 87 9D 5C 41 87 9D 68 41 14 00 28 00 46 00 61 00 76 00 6F 00 72 00 69 00 74 00 65 00 6E 00 00 00 40 73 68 65 6C 6C 33 32 2E 64 6C 6C 2C 2D 31 32 36 39 33 00 18 00 36 00 31 00 00 00 00 00 87 9D 68 41 10 00 4C 69 6E 6B 73 00 22 00 03 00 04 00 EF BE 87 9D 61 41 87 9D 11 43 14 00 00 00 4C 00 69 00 6E 00 6B 00 73 00 00 00 14 00 00 00 60 00 00 00 03 00 00 A0 58 00 00 00 00 00 00 00 76 6D 2D 34 30 61 31 31 65 64 65 33 61 30 66 00 62 0F 7B BA 96 4E 96 42 94 AD 1C E8 DC EC 5D AE A0 E5 70 56 90 D2 15 12 B3 B9 08 00 27 F6 31 03 62 0F 7B BA 96 4E 96 42 94 AD 1C E8 DC EC 5D AE A0 E5 70 56 90 D2 15 12 B3 B9 08 00 27 F6 31 03 00 00 00 00
- HKU\S-1-5-21-1993962763-1935655697-1060284298-500\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\ITBarLayout: 11 00 00 00 4C 00 00 00 00 00 00 00 34 00 00 00 1F 00 00 00 56 00 00 00 01 00 00 00 20 07 00 00 A0 0F 00 00 05 00 00 00 62 05 00 00 26 00 00 00 02 00 00 00 21 07 00 00 A0 0F 00 00 04 00 00 00 21 01 00 00 A0 0F 00 00 03 00 00 00 20 03 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
- HKU\S-1-5-21-1993962763-1935655697-1060284298-500\Software\Microsoft\Internet Explorer\Toolbar\LinksFolderName: "Links"
- HKU\S-1-5-21-1993962763-1935655697-1060284298-500\Software\Microsoft\Internet Explorer\Toolbar\Locked: 0x00000001
- HKU\S-1-5-21-1993962763-1935655697-1060284298-500\Software\Microsoft\Internet Explorer\Toolbar\SaveLinksOrder: 01 00 00 00
- HKU\S-1-5-21-1993962763-1935655697-1060284298-500\Software\Microsoft\Internet Explorer\TypedURLs\url1: "http://auto.search.msn.com/response.asp?MT=chrome+download&srch=3&prov=&utf8"
- HKU\S-1-5-21-1993962763-1935655697-1060284298-500\Software\Microsoft\Internet Explorer\TypedURLs\url2: "http://www.microsoft.com/isapi/redir.dll?prd=ie&pver=6&ar=msnhome"
- HKU\S-1-5-21-1993962763-1935655697-1060284298-500\Software\Microsoft\Internet Explorer\URLSearchHooks\{CFBFAE00-17A6-11D0-99CB-00C04FD64497}: ""
- ----------------------------------
- Values added:4
- ----------------------------------
- HKLM\SYSTEM\ControlSet001\Enum\Root\LEGACY_SCDEMU\0000\Capabilities: 0x00000000
- HKLM\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_SCDEMU\0000\Capabilities: 0x00000000
- HKU\S-1-5-21-1993962763-1935655697-1060284298-500\Software\Microsoft\Windows\ShellNoRoam\MUICache\C:\Dokumente und Einstellungen\Administrator\Desktop\conduitdisinfector.bat: "conduitdisinfector"
- HKU\S-1-5-21-1993962763-1935655697-1060284298-500\Software\Microsoft\Windows\ShellNoRoam\MUICache\C:\WINDOWS\system32\cmd.exe: "Windows-Befehlsprozessor"
- ----------------------------------
- Values modified:9
- ----------------------------------
- HKLM\SOFTWARE\Microsoft\Cryptography\RNG\Seed: AD C7 21 E6 AA EE DF DA 36 F7 C9 C8 B0 E5 3C C5 C7 08 8C F0 D5 AC 32 E7 C8 BB 2B 9A C4 B3 0A 4B 6A 33 08 64 97 BA 40 8D AE B9 C8 E2 5A 67 A8 78 05 D5 4D 2B 80 5C 3D E8 D1 0D 1F 75 F5 B7 1D 07 1A ED 9D 4F 18 9C 3A 34 EE 98 79 68 0D 0F 82 06
- HKLM\SOFTWARE\Microsoft\Cryptography\RNG\Seed: 45 52 82 56 C5 ED A3 81 87 CF BE 00 B2 85 47 BB CD 2D 3C B7 FA C0 B5 04 06 CB 25 9B E3 DC 98 E7 D7 F2 A9 9E AB 75 02 3B 6D D7 31 FD E9 2F 9E DA 83 33 CC C5 04 D5 B3 56 4E 7C 07 27 4A 15 9E 92 A1 B7 24 C4 92 48 3C 6B BC B7 55 EA 11 53 FA 86
- HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Prefetcher\TracesProcessed: 0x00000000
- HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Prefetcher\TracesProcessed: 0x0000000F
- HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Prefetcher\TracesSuccessful: 0x00000000
- HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Prefetcher\TracesSuccessful: 0x00000005
- HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Prefetcher\LastTraceFailure: 0x00000000
- HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Prefetcher\LastTraceFailure: 0x00000004
- HKLM\SOFTWARE\SPPDCOM\TS: 0x00000001
- HKLM\SOFTWARE\SPPDCOM\TS: 0x00000002
- HKU\S-1-5-21-1993962763-1935655697-1060284298-500\Software\Microsoft\Windows\CurrentVersion\Explorer\UserAssist\{75048700-EF1F-11D0-9888-006097DEACF9}\Count\HRZR_EHACNGU: 1B 00 00 00 46 01 00 00 C0 E8 0F BD 47 E9 CF 01
- HKU\S-1-5-21-1993962763-1935655697-1060284298-500\Software\Microsoft\Windows\CurrentVersion\Explorer\UserAssist\{75048700-EF1F-11D0-9888-006097DEACF9}\Count\HRZR_EHACNGU: 1B 00 00 00 47 01 00 00 F0 23 4F C2 47 E9 CF 01
- HKU\S-1-5-21-1993962763-1935655697-1060284298-500\Software\Microsoft\Windows\CurrentVersion\Explorer\UserAssist\{75048700-EF1F-11D0-9888-006097DEACF9}\Count\HRZR_HVFPHG: 1B 00 00 00 B8 00 00 00 10 D1 F5 BC 47 E9 CF 01
- HKU\S-1-5-21-1993962763-1935655697-1060284298-500\Software\Microsoft\Windows\CurrentVersion\Explorer\UserAssist\{75048700-EF1F-11D0-9888-006097DEACF9}\Count\HRZR_HVFPHG: 1B 00 00 00 B9 00 00 00 20 28 4D C2 47 E9 CF 01
- HKU\S-1-5-21-1993962763-1935655697-1060284298-500\Software\Microsoft\Windows\CurrentVersion\Explorer\UserAssist\{75048700-EF1F-11D0-9888-006097DEACF9}\Count\HRZR_EHACNGU:(ahyy): 16 00 00 00 11 00 00 00 10 82 EB 59 0F 3A CE 01
- HKU\S-1-5-21-1993962763-1935655697-1060284298-500\Software\Microsoft\Windows\CurrentVersion\Explorer\UserAssist\{75048700-EF1F-11D0-9888-006097DEACF9}\Count\HRZR_EHACNGU:(ahyy): 1B 00 00 00 11 00 00 00 F0 23 4F C2 47 E9 CF 01
- HKU\S-1-5-21-1993962763-1935655697-1060284298-500\SessionInformation\ProgramCount: 0x00000001
- HKU\S-1-5-21-1993962763-1935655697-1060284298-500\SessionInformation\ProgramCount: 0x00000002
- ----------------------------------
- Total changes:316
- ----------------------------------
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement