| Key |
Name |
Value |
| HKLM\SOFTWARE\CLASSES\.ADE
|
|
Access.ADEFile.11
|
| HKLM\SOFTWARE\CLASSES\.ADP
|
|
Access.Project.11
|
| HKLM\SOFTWARE\CLASSES\.ASP
|
|
aspfile
|
| HKLM\SOFTWARE\CLASSES\.BAT
|
|
batfile
|
| HKLM\SOFTWARE\CLASSES\.CER
|
|
CERFile
|
| HKLM\SOFTWARE\CLASSES\.CHM
|
|
chm.file
|
| HKLM\SOFTWARE\CLASSES\.CMD
|
|
cmdfile
|
| HKLM\SOFTWARE\CLASSES\.COM
|
|
comfile
|
| HKLM\SOFTWARE\CLASSES\.CPL
|
|
cplfile
|
| HKLM\SOFTWARE\CLASSES\.CRT
|
|
CERFile
|
| HKLM\SOFTWARE\CLASSES\.EXE
|
|
exefile
|
| HKLM\SOFTWARE\CLASSES\CLSID\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\INPROCSERVER32
|
|
%SystemRoot%\system32\SHELL32.dll
|
| HKLM\SOFTWARE\CLASSES\CLSID\{7B8A2D94-0AC9-11D1-896C-00C04FB6BFC4}\INPROCSERVER32
|
|
C:\WINDOWS\system32\urlmon.dll
|
| HKLM\SOFTWARE\CLASSES\CLSID\{7B8A2D94-0AC9-11D1-896C-00C04FB6BFC4}\INPROCSERVER32
|
ThreadingModel |
Both
|
| HKLM\SOFTWARE\CLASSES\CLSID\{AEB6717E-7E19-11D0-97EE-00C04FD91972}\INPROCSERVER32
|
|
shell32.dll
|
| HKLM\SOFTWARE\CLASSES\DIRECTORY
|
AlwaysShowExt |
|
| HKLM\SOFTWARE\CLASSES\DRIVE\SHELLEX\FOLDEREXTENSIONS\{FBEB8A05-BEEE-4442-804E-409D6C4515E9}
|
DriveMask |
32
|
| HKLM\SOFTWARE\CLASSES\EXEFILE\SHELL\OPEN\COMMAND
|
|
"%1" %*
|
| HKLM\SOFTWARE\CLASSES\MIME\DATABASE\CONTENT TYPE\TEXT/HTML
|
Extension |
.htm
|
| HKLM\SOFTWARE\CLASSES\MIME\DATABASE\CONTENT TYPE\TEXT/PLAIN
|
Extension |
.txt
|
| HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings
|
EnablePunycode |
1
|
| HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings
|
UrlEncoding |
0x00000000
|
| HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\User Agent\Post Platform
|
.NET CLR 1.1.4322 |
|
| HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\User Agent\Post Platform
|
.NET CLR 2.0.50727 |
|
| HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\User Agent\Post Platform
|
.NET CLR 3.0.04506.30 |
|
| HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\User Agent\Post Platform
|
InfoPath.1 |
|
| HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\User
Agent\UA Tokens
|
|
|
| HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\User
Agent\UA Tokens
|
MSN 2.0 |
|
| HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\User
Agent\UA Tokens
|
MSN 2.5 |
|
| HKLM\SYSTEM\CurrentControlSet\Services\Winsock\Parameters
|
Transports |
0x5400630070006900700000004e0065007400420049004f00530000000000
|
| HKLM\Software\Microsoft\COM3
|
Com+Enabled |
1
|
| HKLM\Software\Microsoft\COM3
|
REGDBVersion |
0x0f00000000000000
|
| HKLM\Software\Microsoft\Tracing
|
EnableConsoleTracing |
0
|
| HKLM\Software\Microsoft\Tracing\RASAPI32
|
ConsoleTracingMask |
4294901760
|
| HKLM\Software\Microsoft\Tracing\RASAPI32
|
EnableConsoleTracing |
0
|
| HKLM\Software\Microsoft\Tracing\RASAPI32
|
EnableFileTracing |
0
|
| HKLM\Software\Microsoft\Tracing\RASAPI32
|
FileDirectory |
%windir%\tracing
|
| HKLM\Software\Microsoft\Tracing\RASAPI32
|
FileTracingMask |
4294901760
|
| HKLM\Software\Microsoft\Tracing\RASAPI32
|
MaxFileSize |
1048576
|
| HKLM\Software\Microsoft\Windows NT\CurrentVersion\ProfileList
|
AllUsersProfile |
All Users
|
| HKLM\Software\Microsoft\Windows NT\CurrentVersion\ProfileList
|
DefaultUserProfile |
Default User
|
| HKLM\Software\Microsoft\Windows NT\CurrentVersion\ProfileList
|
ProfilesDirectory |
%SystemDrive%\Documents and Settings
|
| HKLM\Software\Microsoft\Windows NT\CurrentVersion\ProfileList\S-1-5-21-1229272821-1004336348-527237240-1003
|
ProfileImagePath |
%SystemDrive%\Documents and Settings\user
|
| HKLM\Software\Microsoft\Windows\CurrentVersion
|
CommonFilesDir |
C:\Program Files\Common Files
|
| HKLM\Software\Microsoft\Windows\CurrentVersion
|
ProgramFilesDir |
C:\Program Files
|
| HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks
|
{AEB6717E-7E19-11d0-97EE-00C04FD91972} |
|
| HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders
|
Common AppData |
%ALLUSERSPROFILE%\Application Data
|
| HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders
|
Common Desktop |
%ALLUSERSPROFILE%\Desktop
|
| HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders
|
Common Documents |
%ALLUSERSPROFILE%\Documents
|
| HKLM\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Content
|
PerUserItem |
1
|
| HKLM\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Cookies
|
PerUserItem |
1
|
| HKLM\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\History
|
PerUserItem |
1
|
| HKLM\Software\Microsoft\Windows\CurrentVersion\Internet
Settings\ZoneMap\Domains\\msn.com
|
|
|
| HKLM\Software\Microsoft\Windows\CurrentVersion\Internet
Settings\ZoneMap\Domains\\msn.com\related
|
http |
4
|
| HKLM\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers
|
TransparentEnabled |
1
|
| HKLM\System\CurrentControlSet\Control\ComputerName\ActiveComputerName
|
ComputerName |
USER
|
| HKLM\System\CurrentControlSet\Control\Session Manager\Environment
|
ComSpec |
%SystemRoot%\system32\cmd.exe
|
| HKLM\System\CurrentControlSet\Control\Session Manager\Environment
|
FP_NO_HOST_CHECK |
NO
|
| HKLM\System\CurrentControlSet\Control\Session Manager\Environment
|
NUMBER_OF_PROCESSORS |
1
|
| HKLM\System\CurrentControlSet\Control\Session Manager\Environment
|
OS |
Windows_NT
|
| HKLM\System\CurrentControlSet\Control\Session Manager\Environment
|
PATHEXT |
.COM;.EXE;.BAT;.CMD;.VBS;.VBE;.JS;.JSE;.WSF;.WSH
|
| HKLM\System\CurrentControlSet\Control\Session Manager\Environment
|
PROCESSOR_ARCHITECTURE |
x86
|
| HKLM\System\CurrentControlSet\Control\Session Manager\Environment
|
PROCESSOR_IDENTIFIER |
x86 Family 6 Model 3 Stepping 3, GenuineIntel
|
| HKLM\System\CurrentControlSet\Control\Session Manager\Environment
|
PROCESSOR_LEVEL |
6
|
| HKLM\System\CurrentControlSet\Control\Session Manager\Environment
|
PROCESSOR_REVISION |
0303
|
| HKLM\System\CurrentControlSet\Control\Session Manager\Environment
|
Path |
%SystemRoot%\system32;%SystemRoot%;%SystemRoot%\System32\Wbem
|
| HKLM\System\CurrentControlSet\Control\Session Manager\Environment
|
TEMP |
%SystemRoot%\TEMP
|
| HKLM\System\CurrentControlSet\Control\Session Manager\Environment
|
TMP |
%SystemRoot%\TEMP
|
| HKLM\System\CurrentControlSet\Control\Session Manager\Environment
|
_NT_SYMBOL_PATH |
srv*C:\Symbols*http://msdl.microsoft.com/download/symbols
|
| HKLM\System\CurrentControlSet\Control\Session Manager\Environment
|
windir |
%SystemRoot%
|
| HKLM\System\CurrentControlSet\Services\Tcpip\Parameters
|
Domain |
|
| HKLM\System\CurrentControlSet\Services\Tcpip\Parameters
|
Hostname |
user
|
| HKLM\System\CurrentControlSet\Services\Tcpip\Parameters\Winsock
|
HelperDllName |
%SystemRoot%\System32\wshtcpip.dll
|
| HKLM\System\CurrentControlSet\Services\Tcpip\Parameters\Winsock
|
Mapping |
0x0b0000000300000002000000010000000600000002000000010000000000
|
| HKLM\System\CurrentControlSet\Services\Tcpip\Parameters\Winsock
|
MaxSockaddrLength |
16
|
| HKLM\System\CurrentControlSet\Services\Tcpip\Parameters\Winsock
|
MinSockaddrLength |
16
|
| HKLM\System\CurrentControlSet\Services\Tcpip\Parameters\Winsock
|
UseDelayedAcceptance |
0
|
| HKLM\System\CurrentControlSet\Services\WinSock2\Parameters
|
WinSock_Registry_Version |
2.0
|
| HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\NameSpace_Catalog5
|
Num_Catalog_Entries |
3
|
| HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\NameSpace_Catalog5
|
Serial_Access_Num |
4
|
| HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000001
|
DisplayString |
Tcpip
|
| HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000001
|
Enabled |
1
|
| HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000001
|
LibraryPath |
%SystemRoot%\System32\mswsock.dll
|
| HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000001
|
ProviderId |
0x409d05229e7ecf11ae5a00aa00a7112b
|
| HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000001
|
StoresServiceClassInfo |
0
|
| HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000001
|
SupportedNameSpace |
12
|
| HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000001
|
Version |
0
|
| HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000002
|
DisplayString |
NTDS
|
| HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000002
|
Enabled |
1
|
| HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000002
|
LibraryPath |
%SystemRoot%\System32\winrnr.dll
|
| HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000002
|
ProviderId |
0xee37263b80e5cf11a55500c04fd8d4ac
|
| HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000002
|
StoresServiceClassInfo |
0
|
| HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000002
|
SupportedNameSpace |
32
|
| HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000002
|
Version |
0
|
| HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000003
|
DisplayString |
Network Location Awareness (NLA) Namespace
|
| HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000003
|
Enabled |
1
|
| HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000003
|
LibraryPath |
%SystemRoot%\System32\mswsock.dll
|
| HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000003
|
ProviderId |
0x3a244266a83ba64abaa52e0bd71fdd83
|
| HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000003
|
StoresServiceClassInfo |
0
|
| HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000003
|
SupportedNameSpace |
15
|
| HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000003
|
Version |
0
|
| HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9
|
Next_Catalog_Entry_ID |
1012
|
| HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9
|
Num_Catalog_Entries |
11
|
| HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9
|
Serial_Access_Num |
4
|
| HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000001
|
PackedCatalogItem |
%SystemRoot%\system32\mswsock.
|
| HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000002
|
PackedCatalogItem |
%SystemRoot%\system32\mswsock.
|
| HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000003
|
PackedCatalogItem |
%SystemRoot%\system32\mswsock.
|
| HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000004
|
PackedCatalogItem |
%SystemRoot%\system32\rsvpsp.d
|
| HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000005
|
PackedCatalogItem |
%SystemRoot%\system32\rsvpsp.d
|
| HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000006
|
PackedCatalogItem |
%SystemRoot%\system32\mswsock.
|
| HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000007
|
PackedCatalogItem |
%SystemRoot%\system32\mswsock.
|
| HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000008
|
PackedCatalogItem |
%SystemRoot%\system32\mswsock.
|
| HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000009
|
PackedCatalogItem |
%SystemRoot%\system32\mswsock.
|
| HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000010
|
PackedCatalogItem |
%SystemRoot%\system32\mswsock.
|
| HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000011
|
PackedCatalogItem |
%SystemRoot%\system32\mswsock.
|
| HKLM\System\Setup
|
SystemSetupInProgress |
0
|
| HKU\S-1-5-21-1229272821-1004336348-527237240-1003\Environment
|
TEMP |
%USERPROFILE%\Local Settings\Temp
|
| HKU\S-1-5-21-1229272821-1004336348-527237240-1003\Environment
|
TMP |
%USERPROFILE%\Local Settings\Temp
|
| HKU\S-1-5-21-1229272821-1004336348-527237240-1003\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings
|
CertificateRevocation |
0
|
| HKU\S-1-5-21-1229272821-1004336348-527237240-1003\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings
|
DisableCachingOfSSLPages |
0
|
| HKU\S-1-5-21-1229272821-1004336348-527237240-1003\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings
|
EnableHttp1_1 |
1
|
| HKU\S-1-5-21-1229272821-1004336348-527237240-1003\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings
|
EnableNegotiate |
1
|
| HKU\S-1-5-21-1229272821-1004336348-527237240-1003\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings
|
MimeExclusionListForCache |
multipart/mixed multipart/x-mixed-replace multipart/x-byteranges
|
| HKU\S-1-5-21-1229272821-1004336348-527237240-1003\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings
|
SecureProtocols |
160
|
| HKU\S-1-5-21-1229272821-1004336348-527237240-1003\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings
|
User Agent |
Mozilla/4.0 (compatible; MSIE 7.0; Win32)
|
| HKU\S-1-5-21-1229272821-1004336348-527237240-1003\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings
|
WarnOnPost |
0x01000000
|
| HKU\S-1-5-21-1229272821-1004336348-527237240-1003\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings
|
WarnOnZoneCrossing |
0
|
| HKU\S-1-5-21-1229272821-1004336348-527237240-1003\Software\Microsoft\Windows NT\CurrentVersion\Winlogon
|
ParseAutoexec |
1
|
| HKU\S-1-5-21-1229272821-1004336348-527237240-1003\Software\Microsoft\Windows\CurrentVersion\Explorer\
|
ShellState |
0x2400000033880000000000000000000000000000010000000d0000000000
|
| HKU\S-1-5-21-1229272821-1004336348-527237240-1003\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced
|
DontPrettyPath |
0
|
| HKU\S-1-5-21-1229272821-1004336348-527237240-1003\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced
|
Filter |
0
|
| HKU\S-1-5-21-1229272821-1004336348-527237240-1003\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced
|
Hidden |
1
|
| HKU\S-1-5-21-1229272821-1004336348-527237240-1003\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced
|
HideFileExt |
0
|
| HKU\S-1-5-21-1229272821-1004336348-527237240-1003\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced
|
HideIcons |
0
|
| HKU\S-1-5-21-1229272821-1004336348-527237240-1003\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced
|
MapNetDrvBtn |
0
|
| HKU\S-1-5-21-1229272821-1004336348-527237240-1003\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced
|
NoNetCrawling |
0
|
| HKU\S-1-5-21-1229272821-1004336348-527237240-1003\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced
|
SeparateProcess |
0
|
| HKU\S-1-5-21-1229272821-1004336348-527237240-1003\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced
|
ShowCompColor |
1
|
| HKU\S-1-5-21-1229272821-1004336348-527237240-1003\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced
|
ShowInfoTip |
1
|
| HKU\S-1-5-21-1229272821-1004336348-527237240-1003\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced
|
ShowSuperHidden |
1
|
| HKU\S-1-5-21-1229272821-1004336348-527237240-1003\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced
|
WebView |
0
|
| HKU\S-1-5-21-1229272821-1004336348-527237240-1003\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\CPC\Volume\{d14d83ce-7d74-11dc-97e2-806d6172696f}\
|
Data |
0x000000005c005c003f005c0049004400450023004300640052006f006d00
|
| HKU\S-1-5-21-1229272821-1004336348-527237240-1003\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\CPC\Volume\{d14d83ce-7d74-11dc-97e2-806d6172696f}\
|
Generation |
1
|
| HKU\S-1-5-21-1229272821-1004336348-527237240-1003\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\CPC\Volume\{d14d83cf-7d74-11dc-97e2-806d6172696f}\
|
Data |
0x000000005c005c003f005c00530054004f00520041004700450023005600
|
| HKU\S-1-5-21-1229272821-1004336348-527237240-1003\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\CPC\Volume\{d14d83cf-7d74-11dc-97e2-806d6172696f}\
|
Generation |
1
|
| HKU\S-1-5-21-1229272821-1004336348-527237240-1003\Software\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders
|
AppData |
%USERPROFILE%\Application Data
|
| HKU\S-1-5-21-1229272821-1004336348-527237240-1003\Software\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders
|
Cache |
%USERPROFILE%\Local Settings\Temporary Internet Files
|
| HKU\S-1-5-21-1229272821-1004336348-527237240-1003\Software\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders
|
Cookies |
%USERPROFILE%\Cookies
|
| HKU\S-1-5-21-1229272821-1004336348-527237240-1003\Software\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders
|
Desktop |
%USERPROFILE%\Desktop
|
| HKU\S-1-5-21-1229272821-1004336348-527237240-1003\Software\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders
|
History |
%USERPROFILE%\Local Settings\History
|
| HKU\S-1-5-21-1229272821-1004336348-527237240-1003\Software\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders
|
Personal |
%USERPROFILE%\My Documents
|
| HKU\S-1-5-21-1229272821-1004336348-527237240-1003\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache
|
Signature |
Client UrlCache MMF Ver 5.2
|
| HKU\S-1-5-21-1229272821-1004336348-527237240-1003\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Content
|
CacheLimit |
163410
|
| HKU\S-1-5-21-1229272821-1004336348-527237240-1003\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Content
|
CachePrefix |
|
| HKU\S-1-5-21-1229272821-1004336348-527237240-1003\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Cookies
|
CacheLimit |
8192
|
| HKU\S-1-5-21-1229272821-1004336348-527237240-1003\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Cookies
|
CachePrefix |
Cookie:
|
| HKU\S-1-5-21-1229272821-1004336348-527237240-1003\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\MSHist012007101520071022
|
CacheLimit |
8192
|
| HKU\S-1-5-21-1229272821-1004336348-527237240-1003\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\MSHist012007101520071022
|
CacheOptions |
11
|
| HKU\S-1-5-21-1229272821-1004336348-527237240-1003\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\MSHist012007101520071022
|
CachePath |
%USERPROFILE%\Local Settings\History\History.IE5\MSHist012007101520071022
|
| HKU\S-1-5-21-1229272821-1004336348-527237240-1003\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\MSHist012007101520071022
|
CachePrefix |
:2007101520071022:
|
| HKU\S-1-5-21-1229272821-1004336348-527237240-1003\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\MSHist012007101520071022
|
CacheRepair |
0
|
| HKU\S-1-5-21-1229272821-1004336348-527237240-1003\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\MSHist012007102220071029
|
CacheLimit |
8192
|
| HKU\S-1-5-21-1229272821-1004336348-527237240-1003\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\MSHist012007102220071029
|
CacheOptions |
11
|
| HKU\S-1-5-21-1229272821-1004336348-527237240-1003\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\MSHist012007102220071029
|
CachePath |
%USERPROFILE%\Local Settings\History\History.IE5\MSHist012007102220071029
|
| HKU\S-1-5-21-1229272821-1004336348-527237240-1003\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\MSHist012007102220071029
|
CachePrefix |
:2007102220071029:
|
| HKU\S-1-5-21-1229272821-1004336348-527237240-1003\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\MSHist012007102220071029
|
CacheRepair |
0
|
| HKU\S-1-5-21-1229272821-1004336348-527237240-1003\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\MSHist012007110120071102
|
CacheLimit |
8192
|
| HKU\S-1-5-21-1229272821-1004336348-527237240-1003\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\MSHist012007110120071102
|
CacheOptions |
11
|
| HKU\S-1-5-21-1229272821-1004336348-527237240-1003\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\MSHist012007110120071102
|
CachePath |
%USERPROFILE%\Local Settings\History\History.IE5\MSHist012007110120071102
|
| HKU\S-1-5-21-1229272821-1004336348-527237240-1003\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\MSHist012007110120071102
|
CachePrefix |
:2007110120071102:
|
| HKU\S-1-5-21-1229272821-1004336348-527237240-1003\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\MSHist012007110120071102
|
CacheRepair |
0
|
| HKU\S-1-5-21-1229272821-1004336348-527237240-1003\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible
Cache\UserData
|
CacheLimit |
1000
|
| HKU\S-1-5-21-1229272821-1004336348-527237240-1003\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible
Cache\UserData
|
CacheOptions |
8
|
| HKU\S-1-5-21-1229272821-1004336348-527237240-1003\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible
Cache\UserData
|
CachePath |
%USERPROFILE%\UserData
|
| HKU\S-1-5-21-1229272821-1004336348-527237240-1003\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible
Cache\UserData
|
CachePrefix |
UserData
|
| HKU\S-1-5-21-1229272821-1004336348-527237240-1003\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible
Cache\UserData
|
CacheRepair |
0
|
| HKU\S-1-5-21-1229272821-1004336348-527237240-1003\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible
Cache\feedplat
|
CacheLimit |
8192
|
| HKU\S-1-5-21-1229272821-1004336348-527237240-1003\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible
Cache\feedplat
|
CacheOptions |
0
|
| HKU\S-1-5-21-1229272821-1004336348-527237240-1003\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible
Cache\feedplat
|
CachePath |
%USERPROFILE%\Local Settings\Application Data\Microsoft\Feeds Cache
|
| HKU\S-1-5-21-1229272821-1004336348-527237240-1003\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible
Cache\feedplat
|
CachePrefix |
feedplat:
|
| HKU\S-1-5-21-1229272821-1004336348-527237240-1003\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible
Cache\feedplat
|
CacheRepair |
0
|
| HKU\S-1-5-21-1229272821-1004336348-527237240-1003\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\History
|
CacheLimit |
8192
|
| HKU\S-1-5-21-1229272821-1004336348-527237240-1003\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\History
|
CachePrefix |
Visited:
|
| HKU\S-1-5-21-1229272821-1004336348-527237240-1003\Software\Microsoft\Windows\CurrentVersion\Internet
Settings\ZoneMap\
|
AutoDetect |
1
|
| HKU\S-1-5-21-1229272821-1004336348-527237240-1003\Software\Microsoft\Windows\CurrentVersion\Internet
Settings\ZoneMap\\ProtocolDefaults\
|
|
|
| HKU\S-1-5-21-1229272821-1004336348-527237240-1003\Software\Microsoft\Windows\CurrentVersion\Internet
Settings\ZoneMap\\ProtocolDefaults\
|
@ivt |
1
|
| HKU\S-1-5-21-1229272821-1004336348-527237240-1003\Software\Microsoft\Windows\CurrentVersion\Internet
Settings\ZoneMap\\ProtocolDefaults\
|
file |
3
|
| HKU\S-1-5-21-1229272821-1004336348-527237240-1003\Software\Microsoft\Windows\CurrentVersion\Internet
Settings\ZoneMap\\ProtocolDefaults\
|
ftp |
3
|
| HKU\S-1-5-21-1229272821-1004336348-527237240-1003\Software\Microsoft\Windows\CurrentVersion\Internet
Settings\ZoneMap\\ProtocolDefaults\
|
http |
3
|
| HKU\S-1-5-21-1229272821-1004336348-527237240-1003\Software\Microsoft\Windows\CurrentVersion\Internet
Settings\ZoneMap\\ProtocolDefaults\
|
https |
3
|
| HKU\S-1-5-21-1229272821-1004336348-527237240-1003\Software\Microsoft\Windows\CurrentVersion\Internet
Settings\ZoneMap\\ProtocolDefaults\
|
shell |
0
|
| HKU\S-1-5-21-1229272821-1004336348-527237240-1003\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\0
|
1806 |
0
|
| HKU\S-1-5-21-1229272821-1004336348-527237240-1003\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\0
|
Flags |
33
|
| HKU\S-1-5-21-1229272821-1004336348-527237240-1003\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\1
|
Flags |
475
|
| HKU\S-1-5-21-1229272821-1004336348-527237240-1003\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\2
|
Flags |
71
|
| HKU\S-1-5-21-1229272821-1004336348-527237240-1003\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\3
|
1A10 |
1
|
| HKU\S-1-5-21-1229272821-1004336348-527237240-1003\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\3
|
Flags |
1
|
| HKU\S-1-5-21-1229272821-1004336348-527237240-1003\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\4
|
Flags |
3
|
| HKU\S-1-5-21-1229272821-1004336348-527237240-1003\Software\Microsoft\Windows\ShellNoRoam
|
|
USER
|
| HKU\S-1-5-21-1229272821-1004336348-527237240-1003\Software\Microsoft\Windows\ShellNoRoam\MUICache
|
LangID |
0x0904
|
| HKU\S-1-5-21-1229272821-1004336348-527237240-1003\Software\Microsoft\Windows\ShellNoRoam\MUICache\
|
C:\WINDOWS\system32\cmd.exe |
Windows Command Processor
|
| HKU\S-1-5-21-1229272821-1004336348-527237240-1003\Software\Microsoft\windows\CurrentVersion\Internet Settings
|
MigrateProxy |
1
|
| HKU\S-1-5-21-1229272821-1004336348-527237240-1003\Software\Microsoft\windows\CurrentVersion\Internet Settings
|
ProxyEnable |
0
|
| HKU\S-1-5-21-1229272821-1004336348-527237240-1003\Software\Microsoft\windows\CurrentVersion\Internet Settings\Connections
|
DefaultConnectionSettings |
0x3c0000000200000001000000000000000000000000000000040000000000
|
| HKU\S-1-5-21-1229272821-1004336348-527237240-1003\Software\Microsoft\windows\CurrentVersion\Internet Settings\Connections
|
SavedLegacySettings |
0x460000005e00000001000000000000000000000000000000040000000000
|
| HKU\S-1-5-21-1229272821-1004336348-527237240-1003\Volatile Environment
|
APPDATA |
C:\Documents and Settings\user\Application Data
|
| HKU\S-1-5-21-1229272821-1004336348-527237240-1003\Volatile Environment
|
CLIENTNAME |
Console
|
| HKU\S-1-5-21-1229272821-1004336348-527237240-1003\Volatile Environment
|
HOMEDRIVE |
C:
|
| HKU\S-1-5-21-1229272821-1004336348-527237240-1003\Volatile Environment
|
HOMEPATH |
\Documents and Settings\user
|
| HKU\S-1-5-21-1229272821-1004336348-527237240-1003\Volatile Environment
|
HOMESHARE |
|
| HKU\S-1-5-21-1229272821-1004336348-527237240-1003\Volatile Environment
|
LOGONSERVER |
\\USER
|
| HKU\S-1-5-21-1229272821-1004336348-527237240-1003\Volatile Environment
|
SESSIONNAME |
Console
|