- SystemScan - www.suspectfile.com - ver. 3.6.7 (code: holifay & bReAkdOWn)
- Running on: Windows XP PROFESSIONAL Edition, Service Pack 3 (2600.5.1)
- System directory: C:\WINDOWS
- SystemScan file: C:\Documents and Settings\XPSP3VLGen\Documenti\Downloads\sys44784.exe
- Running in: User mode
- Date: 08/08/2012
- Time: 15.55.27
- Output limited to:
- -PC accounts
- -Recent files
- -Duplicates in BAK folders
- -Registry Run Keys
- -Autoplay settings (autorun.inf)
- -Scheduled jobs
- -Services and Drivers (all)
- -Svchost.exe instances
- -Loaded Dlls
- -Alternate Data Streams
- -Encrypted Files
- -Hidden objects
- -Master Boot Record
- -Network settings
- -Include HOSTS file
- -Suspicious Files
- -Installed Applications
- ===================== ACCOUNTS ON THIS PC =====================
- Users on this computer:
- Is Admin? | Username
- ------------------
- | ASPNET
- | Guest (Disabled)
- | HelpAssistant (Disabled)
- | SUPPORT_388945a0 (Disabled)
- | UpdatusUser
- Yes | XPSP3VLGen
- ### users folders
- 13/12/2011 20.01.34 (DIR) 0 byte 239 days old -- Default User
- 14/03/2012 16.35.40 (DIR) 0 byte 147 days old -- UpdatusUser
- 16/06/2012 00.04.01 (DIR) 0 byte 53 days old -- All Users
- 13/07/2012 03.50.36 (DIR) 0 byte 26 days old -- XPSP3VLGen
- 08/08/2012 11.29.08 (DIR) 0 byte 0 days old -- LocalService
- 08/08/2012 11.29.08 (DIR) 0 byte 0 days old -- NetworkService
- ### startup files in users folders
- C:\documents and settings\All Users\Menu Avvio\Programmi\Esecuzione automatica\desktop.ini
- C:\documents and settings\All Users\Menu Avvio\Programmi\Esecuzione automatica\NETGEAR WG111v2 Smart Wizard.lnk
- C:\documents and settings\Default User\Menu Avvio\Programmi\Esecuzione automatica\desktop.ini
- C:\documents and settings\UpdatusUser\Menu Avvio\Programmi\Esecuzione automatica\desktop.ini
- C:\documents and settings\XPSP3VLGen\Menu Avvio\Programmi\Esecuzione automatica\desktop.ini
- C:\documents and settings\XPSP3VLGen\Menu Avvio\Programmi\Esecuzione automatica\Dropbox.lnk
- ===================== RECENT FILES =====================
- Listing files newer than 60 days
- ---- recent files in C:\
- 15/04/2010 20:34:35 -- 08/08/2012 15:53:52 (DIR) ---- 0 days old -- C:\Config.Msi
- 18/03/2010 13:54:21 -- 08/08/2012 15:53:40 (DIR) --R- 0 days old -- C:\Programmi
- 08/08/2012 10:20:06 -- 08/08/2012 11:29:14 (DIR) ---- 0 days old -- C:\ComboFix
- 31/12/2001 22:36:04 -- 08/08/2012 11:29:12 (DIR) ---A 0 days old -- C:\Qoobox
- 18/03/2010 13:46:38 -- 08/08/2012 11:19:15 (DIR) ---- 0 days old -- C:\WINDOWS
- 11/07/2011 01:10:02 -- 18/06/2012 01:25:58 (DIR) ---- 51 days old -- C:\Only_Game
- 08/08/2012 11:29:04 -- 08/08/2012 11:29:04 18900 ---A 0 days old -- C:\ComboFix.txt
- 18/03/2010 13:46:37 -- 08/08/2012 11:18:172145386496 HS-A 0 days old -- C:\pagefile.sys
- 09/07/2012 11:24:05 -- 09/07/2012 11:24:05 139252 ---A 30 days old -- C:\fraglist.html
- 09/07/2012 10:10:58 -- 09/07/2012 10:10:58 89954 ---A 30 days old -- C:\fraglist.luar
- ---- recent files in C:\DOCUME~1\XPSP3V~1\IMPOST~1\Temp\
- 08/08/2012 15:54:21 -- 08/08/2012 15:55:30 (DIR) ---- 0 days old -- C:\DOCUME~1\XPSP3V~1\IMPOST~1\Temp\nstE91.tmp
- 08/08/2012 12:23:56 -- 08/08/2012 12:23:56 (DIR) ---- 0 days old -- C:\DOCUME~1\XPSP3V~1\IMPOST~1\Temp\CRX_75DAF8CB7768
- 08/08/2012 15:54:23 -- 08/08/2012 15:54:23 16384 ---A 0 days old -- C:\DOCUME~1\XPSP3V~1\IMPOST~1\Temp\~DF4A4B.tmp
- 08/08/2012 15:50:03 -- 08/08/2012 15:54:21 69 ---A 0 days old -- C:\DOCUME~1\XPSP3V~1\IMPOST~1\Temp\systemscan.ini
- 08/08/2012 14:55:21 -- 08/08/2012 15:06:54 32 ---A 0 days old -- C:\DOCUME~1\XPSP3V~1\IMPOST~1\Temp\REG6F3.tmp
- 08/08/2012 14:55:21 -- 08/08/2012 15:06:54 820 ---A 0 days old -- C:\DOCUME~1\XPSP3V~1\IMPOST~1\Temp\REG6F2.tmp
- 08/08/2012 14:53:44 -- 08/08/2012 14:53:45 820 ---A 0 days old -- C:\DOCUME~1\XPSP3V~1\IMPOST~1\Temp\REG6D9.tmp
- 08/08/2012 14:53:44 -- 08/08/2012 14:53:45 32 ---A 0 days old -- C:\DOCUME~1\XPSP3V~1\IMPOST~1\Temp\REG6DA.tmp
- 08/08/2012 13:52:25 -- 08/08/2012 14:46:04 32 ---A 0 days old -- C:\DOCUME~1\XPSP3V~1\IMPOST~1\Temp\REG5C4.tmp
- 08/08/2012 13:52:25 -- 08/08/2012 14:46:04 820 ---A 0 days old -- C:\DOCUME~1\XPSP3V~1\IMPOST~1\Temp\REG5C3.tmp
- 08/08/2012 13:41:18 -- 08/08/2012 13:45:03 820 ---A 0 days old -- C:\DOCUME~1\XPSP3V~1\IMPOST~1\Temp\REG50B.tmp
- 08/08/2012 13:41:18 -- 08/08/2012 13:45:03 32 ---A 0 days old -- C:\DOCUME~1\XPSP3V~1\IMPOST~1\Temp\REG50C.tmp
- 08/08/2012 13:37:04 -- 08/08/2012 13:39:45 820 ---A 0 days old -- C:\DOCUME~1\XPSP3V~1\IMPOST~1\Temp\REG4D4.tmp
- 08/08/2012 13:37:04 -- 08/08/2012 13:39:45 32 ---A 0 days old -- C:\DOCUME~1\XPSP3V~1\IMPOST~1\Temp\REG4D5.tmp
- 08/08/2012 13:35:59 -- 08/08/2012 13:39:44 820 ---A 0 days old -- C:\DOCUME~1\XPSP3V~1\IMPOST~1\Temp\REG4BB.tmp
- 08/08/2012 13:35:59 -- 08/08/2012 13:39:44 32 ---A 0 days old -- C:\DOCUME~1\XPSP3V~1\IMPOST~1\Temp\REG4BC.tmp
- 08/08/2012 12:49:39 -- 08/08/2012 13:26:36 32 ---A 0 days old -- C:\DOCUME~1\XPSP3V~1\IMPOST~1\Temp\REG28D.tmp
- 08/08/2012 12:49:39 -- 08/08/2012 13:26:36 820 ---A 0 days old -- C:\DOCUME~1\XPSP3V~1\IMPOST~1\Temp\REG28C.tmp
- 08/08/2012 12:26:53 -- 08/08/2012 12:34:44 32 ---A 0 days old -- C:\DOCUME~1\XPSP3V~1\IMPOST~1\Temp\REGB9.tmp
- 08/08/2012 12:26:52 -- 08/08/2012 12:34:44 820 ---A 0 days old -- C:\DOCUME~1\XPSP3V~1\IMPOST~1\Temp\REGB8.tmp
- ---- recent files in C:\WINDOWS\
- 18/03/2010 13:04:47 -- 08/08/2012 15:55:29 (DIR) ---- 0 days old -- C:\WINDOWS\Prefetch
- 18/03/2010 13:46:38 -- 08/08/2012 15:55:28 (DIR) ---- 0 days old -- C:\WINDOWS\Temp
- 18/03/2010 13:54:26 -- 08/08/2012 15:53:43 (DIR) HS-- 0 days old -- C:\WINDOWS\Installer
- 18/03/2010 12:59:57 -- 08/08/2012 15:34:45 (DIR) -S-- 0 days old -- C:\WINDOWS\Tasks
- 31/12/2001 22:44:48 -- 08/08/2012 11:13:30 (DIR) ---- 0 days old -- C:\WINDOWS\ERDNT
- 18/03/2010 13:46:38 -- 08/08/2012 11:10:41 (DIR) ---- 0 days old -- C:\WINDOWS\system32
- 18/03/2010 13:46:38 -- 08/08/2012 11:03:51 (DIR) ---- 0 days old -- C:\WINDOWS\AppPatch
- 29/01/2011 12:04:23 -- 05/08/2012 18:26:22 (DIR) ---- 2 days old -- C:\WINDOWS\Minidump
- 17/02/2012 12:01:27 -- 14/07/2012 23:54:19 (DIR) ---- 24 days old -- C:\WINDOWS\pss
- 09/07/2012 03:41:40 -- 09/07/2012 03:42:44 (DIR) ---- 30 days old -- C:\WINDOWS\UltraDefrag
- 30/06/2012 20:30:53 -- 30/06/2012 20:30:53 (DIR) ---- 38 days old -- C:\WINDOWS\DEA314C409294250BC9298E4C105F28D.TMP
- 18/03/2010 13:46:38 -- 16/06/2012 08:14:10 (DIR) H--- 53 days old -- C:\WINDOWS\inf
- 05/11/2010 17:03:17 -- 08/08/2012 15:37:19 50 ---A 0 days old -- C:\WINDOWS\wiaservc.log
- 18/03/2010 13:00:33 -- 08/08/2012 11:27:33 378084 ---A 0 days old -- C:\WINDOWS\WindowsUpdate.log
- 05/11/2010 17:03:17 -- 08/08/2012 11:21:29 159 ---A 0 days old -- C:\WINDOWS\wiadebug.log
- 22/06/2012 08:35:59 -- 08/08/2012 11:21:25 0 ---A 0 days old -- C:\WINDOWS\0.log
- 19/08/2004 16:30:00 -- 08/08/2012 11:19:14 227 ---A 0 days old -- C:\WINDOWS\system.ini
- 18/03/2010 13:03:34 -- 08/08/2012 11:18:34 2048 -S-A 0 days old -- C:\WINDOWS\bootstat.dat
- 18/03/2010 13:04:47 -- 08/08/2012 10:20:57 32366 ---A 0 days old -- C:\WINDOWS\SchedLgU.Txt
- 08/08/2012 10:15:12 -- 08/08/2012 10:15:39 345 ---A 0 days old -- C:\WINDOWS\OEWABLog.txt
- 10/07/2012 08:59:53 -- 08/08/2012 10:15:27 7076 ---A 0 days old -- C:\WINDOWS\wmsetup.log
- 07/08/2012 23:23:21 -- 07/08/2012 23:20:52 143872 ---A 0 days old -- C:\WINDOWS\system32javacpl.cpl
- 06/07/2012 12:14:44 -- 28/07/2012 10:14:25 35755 ---A 11 days old -- C:\WINDOWS\setupapi.log
- 27/07/2012 06:18:53 -- 27/07/2012 06:18:54 262 ---A 12 days old -- C:\WINDOWS\cdplayer.ini
- 27/07/2012 06:05:13 -- 27/07/2012 06:05:33 561 ---A 12 days old -- C:\WINDOWS\wmsetup10.log
- 19/07/2012 14:42:02 -- 19/07/2012 14:44:49 79274 ---A 20 days old -- C:\WINDOWS\ntbtlog.txt
- 19/08/2004 16:30:00 -- 24/06/2012 01:50:58 793 ---A 45 days old -- C:\WINDOWS\win.ini
- ---- recent files in C:\WINDOWS\system\
- ---- recent files in C:\WINDOWS\system32\
- 18/03/2010 13:46:38 -- 08/08/2012 11:29:11 (DIR) ---- 0 days old -- C:\WINDOWS\system32\drivers
- 18/03/2010 13:52:02 -- 08/08/2012 11:22:02 (DIR) ---- 0 days old -- C:\WINDOWS\system32\CatRoot2
- 18/03/2010 13:46:38 -- 08/08/2012 11:15:16 (DIR) ---- 0 days old -- C:\WINDOWS\system32\config
- 05/09/2010 20:41:06 -- 22/06/2012 08:35:58 (DIR) ---- 47 days old -- C:\WINDOWS\system32\LogFiles
- 18/03/2010 13:00:16 -- 16/06/2012 08:14:12 (DIR) ---- 53 days old -- C:\WINDOWS\system32\DirectX
- 07/08/2012 23:22:18 -- 05/07/2012 22:06:48 227760 ---A 0 days old -- C:\WINDOWS\system32\javaws.exe
- 07/08/2012 23:21:34 -- 07/08/2012 23:20:52 174064 ---A 0 days old -- C:\WINDOWS\system32\javaw.exe
- 07/08/2012 23:21:34 -- 07/08/2012 23:20:51 174064 ---A 0 days old -- C:\WINDOWS\system32\java.exe
- 07/08/2012 23:19:10 -- 05/07/2012 22:07:08 143872 ---A 0 days old -- C:\WINDOWS\system32\javacpl.cpl
- 19/08/2004 16:30:00 -- 07/08/2012 22:51:05 2206 ---A 0 days old -- C:\WINDOWS\system32\wpa.dbl
- 27/07/2012 06:19:48 -- 13/04/2008 19:13:58 221184 ---A 12 days old -- C:\WINDOWS\system32\wmpns.dll
- 19/08/2004 16:30:00 -- 23/07/2012 15:58:42 555408 ---A 15 days old -- C:\WINDOWS\system32\perfh010.dat
- 19/08/2004 16:30:00 -- 23/07/2012 15:58:41 504866 ---A 15 days old -- C:\WINDOWS\system32\perfh009.dat
- 19/08/2004 16:30:00 -- 23/07/2012 15:58:41 88520 ---A 15 days old -- C:\WINDOWS\system32\perfc009.dat
- 19/08/2004 16:30:00 -- 23/07/2012 15:58:41 104736 ---A 15 days old -- C:\WINDOWS\system32\perfc010.dat
- 18/03/2010 13:54:26 -- 23/07/2012 15:58:31 1271856 ---A 15 days old -- C:\WINDOWS\system32\PerfStringBackup.INI
- 08/01/2012 01:38:01 -- 05/07/2012 22:06:30 772544 ---A 33 days old -- C:\WINDOWS\system32\npdeployJava1.dll
- 27/11/2010 20:57:56 -- 05/07/2012 22:06:20 687544 ---A 33 days old -- C:\WINDOWS\system32\deployJava1.dll
- 30/06/2012 21:15:28 -- 30/06/2012 21:15:29 670816 ---A 38 days old -- C:\WINDOWS\system32\xsherlock.xem
- 30/06/2012 20:43:49 -- 27/03/2012 19:13:02 230920 ---A 38 days old -- C:\WINDOWS\system32\EPWZCmnCtrl.dll
- 20/06/2012 19:31:12 -- 20/06/2012 19:31:12 31232 ---A 48 days old -- C:\WINDOWS\system32\udefrag.exe
- 20/06/2012 19:31:10 -- 20/06/2012 19:31:10 6144 ---A 48 days old -- C:\WINDOWS\system32\hibernate4win.exe
- 20/06/2012 19:31:06 -- 20/06/2012 19:31:06 9728 ---A 48 days old -- C:\WINDOWS\system32\bootexctrl.exe
- 20/06/2012 19:31:04 -- 20/06/2012 19:31:04 22016 ---A 48 days old -- C:\WINDOWS\system32\wgx.dll
- 20/06/2012 19:30:48 -- 20/06/2012 19:30:48 93696 ---A 48 days old -- C:\WINDOWS\system32\lua5.1a.dll
- 20/06/2012 19:30:40 -- 20/06/2012 19:30:40 47616 ---A 48 days old -- C:\WINDOWS\system32\udefrag.dll
- 20/06/2012 19:30:38 -- 20/06/2012 19:30:38 65024 ---A 48 days old -- C:\WINDOWS\system32\zenwinx.dll
- 20/06/2012 19:30:36 -- 20/06/2012 19:30:36 115712 ---A 48 days old -- C:\WINDOWS\system32\defrag_native.exe
- ---- recent files in C:\WINDOWS\system32\drivers\
- 18/03/2010 13:46:38 -- 08/08/2012 11:18:52 (DIR) ---- 0 days old -- C:\WINDOWS\system32\drivers\etc
- ---- recent files in C:\WINDOWS\temp\
- 08/08/2012 12:56:51 -- 08/08/2012 12:18:12 32 HS-A 0 days old -- C:\WINDOWS\temp\4ac2025
- 08/08/2012 12:15:52 -- 08/08/2012 12:45:34 5509 ---A 0 days old -- C:\WINDOWS\temp\hpqddsvc.log
- 08/08/2012 11:21:22 -- 08/08/2012 11:21:22 16384 ---A 0 days old -- C:\WINDOWS\temp\Perflib_Perfdata_824.dat
- 17/06/2012 02:12:48 -- 08/08/2012 11:18:57 36337 HS-A 0 days old -- C:\WINDOWS\temp\9bbe6d0
- 17/06/2012 02:29:14 -- 06/08/2012 10:03:50 10257216 HS-A 2 days old -- C:\WINDOWS\temp\98fceea4
- 17/06/2012 02:47:43 -- 06/08/2012 10:03:50 44 ---A 2 days old -- C:\WINDOWS\temp\91ba7d85
- 17/06/2012 02:09:31 -- 17/06/2012 02:59:36 36 ---A 52 days old -- C:\WINDOWS\temp\369c411
- ---- recent files in C:\Programmi\
- 08/08/2012 15:53:40 -- 08/08/2012 15:53:40 (DIR) ---- 0 days old -- C:\Programmi\hij
- 22/11/2011 16:39:02 -- 08/08/2012 11:21:38 (DIR) ---- 0 days old -- C:\Programmi\PC Tools Firewall Plus
- 18/03/2010 13:54:21 -- 08/08/2012 11:03:44 (DIR) ---- 0 days old -- C:\Programmi\File comuni
- 08/01/2012 01:40:13 -- 07/08/2012 23:23:54 (DIR) ---- 0 days old -- C:\Programmi\Oracle
- 19/04/2010 07:07:00 -- 07/08/2012 23:02:08 (DIR) ---- 0 days old -- C:\Programmi\Spybot - Search & Destroy
- 09/05/2010 19:48:32 -- 28/07/2012 06:06:28 (DIR) ---- 11 days old -- C:\Programmi\JDownloader
- 27/07/2012 06:09:24 -- 27/07/2012 06:09:25 (DIR) ---- 12 days old -- C:\Programmi\FreeRIP
- 11/04/2011 17:48:12 -- 26/07/2012 09:37:16 (DIR) ---- 13 days old -- C:\Programmi\Wakfu
- 06/07/2010 17:36:59 -- 10/07/2012 22:29:30 (DIR) ---- 28 days old -- C:\Programmi\uTorrent
- 07/07/2012 16:48:58 -- 07/07/2012 16:49:07 (DIR) ---- 31 days old -- C:\Programmi\Dropbox
- 16/06/2012 00:03:34 -- 30/06/2012 22:16:56 (DIR) ---- 38 days old -- C:\Programmi\Hi-Rez Studios
- 18/03/2010 13:14:02 -- 30/06/2012 22:16:51 (DIR) H--- 38 days old -- C:\Programmi\InstallShield Installation Information
- 30/06/2012 19:28:56 -- 30/06/2012 20:43:49 (DIR) ---- 38 days old -- C:\Programmi\WEBZEN
- 14/09/2010 22:10:07 -- 26/06/2012 09:17:27 (DIR) ---- 43 days old -- C:\Programmi\Microsoft Silverlight
- 25/04/2012 00:04:26 -- 18/06/2012 01:25:58 (DIR) ---- 51 days old -- C:\Programmi\Mozilla Maintenance Service
- 18/03/2010 13:47:44 -- 16/06/2012 18:21:30 (DIR) ---- 52 days old -- C:\Programmi\Mozilla Firefox
- ---- recent files in C:\Programmi\File comuni\
- 31/08/2010 17:49:57 -- 08/08/2012 11:22:53 (DIR) ---- 0 days old -- C:\Programmi\File comuni\Akamai
- 07/08/2012 23:32:44 -- 07/08/2012 23:32:44 (DIR) ---- 0 days old -- C:\Programmi\File comuni\Java
- 11/04/2011 10:03:10 -- 30/06/2012 20:30:22 (DIR) ---- 38 days old -- C:\Programmi\File comuni\Wise Installation Wizard
- ---- recent files in C:\Documents and Settings\XPSP3VLGen\Dati applicazioni\
- 18/03/2010 13:04:56 -- 08/08/2012 15:53:47 (DIR) -S-- 0 days old -- C:\Documents and Settings\XPSP3VLGen\Dati applicazioni\Microsoft
- 08/07/2010 18:25:23 -- 08/08/2012 14:57:11 (DIR) ---- 0 days old -- C:\Documents and Settings\XPSP3VLGen\Dati applicazioni\Skype
- 13/12/2011 14:29:37 -- 08/08/2012 12:16:18 (DIR) ---- 0 days old -- C:\Documents and Settings\XPSP3VLGen\Dati applicazioni\Dropbox
- 15/04/2010 23:26:12 -- 08/08/2012 09:43:51 (DIR) ---- 0 days old -- C:\Documents and Settings\XPSP3VLGen\Dati applicazioni\HPAppData
- 18/06/2010 22:04:51 -- 08/08/2012 01:38:20 (DIR) ---- 0 days old -- C:\Documents and Settings\XPSP3VLGen\Dati applicazioni\vlc
- 18/03/2010 13:48:36 -- 05/08/2012 17:00:12 (DIR) ---- 2 days old -- C:\Documents and Settings\XPSP3VLGen\Dati applicazioni\Mozilla
- 06/07/2010 17:36:27 -- 19/07/2012 04:05:29 (DIR) ---- 20 days old -- C:\Documents and Settings\XPSP3VLGen\Dati applicazioni\uTorrent
- 24/07/2011 08:27:03 -- 06/07/2012 13:19:41 (DIR) ---- 33 days old -- C:\Documents and Settings\XPSP3VLGen\Dati applicazioni\ESET
- ---- recent files in C:\Documents and Settings\XPSP3VLGen\Impostazioni locali\Dati applicazioni\
- 05/01/2011 13:33:27 -- 07/08/2012 13:35:36 (DIR) ---- 1 days old -- C:\Documents and Settings\XPSP3VLGen\Impostazioni locali\Dati applicazioni\PMB Files
- 06/07/2011 21:02:44 -- 12/07/2012 00:18:42 (DIR) ---- 27 days old -- C:\Documents and Settings\XPSP3VLGen\Impostazioni locali\Dati applicazioni\Temp
- 30/06/2012 20:31:04 -- 30/06/2012 20:31:09 (DIR) ---- 38 days old -- C:\Documents and Settings\XPSP3VLGen\Impostazioni locali\Dati applicazioni\Overwolf
- 04/11/2011 03:50:01 -- 24/06/2012 11:12:41 (DIR) ---- 45 days old -- C:\Documents and Settings\XPSP3VLGen\Impostazioni locali\Dati applicazioni\Akamai
- 19/04/2010 07:21:19 -- 18/06/2012 15:32:45 118272 ---A 51 days old -- C:\Documents and Settings\XPSP3VLGen\Impostazioni locali\Dati applicazioni\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
- ===================== DUPLICATE FILES IN BAK FOLDERS =====================
- No BAK folders found
- ===================== REGISTRY SCAN =====================
- -----HKLM\Software\Microsoft\Windows\CurrentVersion\Run-----
- [Run]
- "RTHDCPL"="RTHDCPL.EXE"
- "SkyTel"="SkyTel.EXE"
- "TkBellExe"="\"C:\Programmi\File comuni\Real\Update_OB\realsched.exe\" -osboot"
- "Adobe Reader Speed Launcher"="\"C:\Programmi\Adobe\Reader 9.0\Reader\Reader_sl.exe\""
- "NvCplDaemon"="RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup"
- "NvMediaCenter"="RunDLL32.exe NvMCTray.dll,NvTaskbarInit -login"
- "nwiz"="C:\Programmi\NVIDIA Corporation\nview\nwiz.exe /installquiet"
- "QuickTime Task"="\"C:\Programmi\QuickTime\QTTask.exe\" -atboottime"
- "SunJavaUpdateSched"="\"C:\Programmi\File comuni\Java\Java Update\jusched.exe\""
- [Run\OptionalComponents]
- @=""
- [Run\OptionalComponents\IMAIL]
- @=""
- "Installed"="1"
- [Run\OptionalComponents\MAPI]
- @=""
- "Installed"="1"
- "NoChange"="1"
- [Run\OptionalComponents\MSFS]
- @=""
- "Installed"="1"
- -----HKCU\Software\Microsoft\Windows\CurrentVersion\Run-----
- [Run]
- "Akamai NetSession Interface"="\"C:\Documents and Settings\XPSP3VLGen\Impostazioni locali\Dati applicazioni\Akamai\netsession_win.exe\""
- "SpybotSD TeaTimer"="C:\Programmi\Spybot - Search & Destroy\TeaTimer.exe"
- "ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe"
- -----HKEY_USERS\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Run-----
- [Run]
- "CTFMON.EXE"="C:\WINDOWS\system32\CTFMON.EXE"
- -----HKLM\Software\Microsoft\Windows\CurrentVersion\policies\Explorer\Run-----
- [run]
- -----HKCU\Software\Microsoft\Windows\CurrentVersion\policies\Explorer\Run-----
- [Run]
- -----HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows-----
- [Windows]
- -----HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad-----
- [ShellServiceObjectDelayLoad]
- "PostBootReminder"="{7849596a-48ea-486e-8937-a2a3009f31a9}"
- #### HKCR\CLSID\{7849596a-48ea-486e-8937-a2a3009f31a9}\InprocServer32 @=expand:"%SystemRoot%\system32\shell32.dll"
- "CDBurn"="{fbeb8a05-beee-4442-804e-409d6c4515e9}"
- #### HKCR\CLSID\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InprocServer32 @=expand:"%SystemRoot%\system32\SHELL32.dll"
- "WebCheck"="{E6FB5E20-DE35-11CF-9C87-00AA005127ED}"
- #### HKCR\CLSID\{E6FB5E20-DE35-11CF-9C87-00AA005127ED}\InprocServer32 @=expand:"%Systemroot%\system32\webcheck.dll"
- "SysTray"="{35CEC8A3-2BE6-11D2-8773-92E220524153}"
- #### HKCR\CLSID\{35CEC8A3-2BE6-11D2-8773-92E220524153}\InprocServer32 @=expand:"%systemroot%\system32\stobject.dll"
- "WPDShServiceObj"="{AAA288BA-9A4C-45B0-95D7-94D524869DB5}"
- #### HKCR\CLSID\{AAA288BA-9A4C-45B0-95D7-94D524869DB5}\InprocServer32 @="C:\WINDOWS\system32\WPDShServiceObj.dll"
- -----HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks-----
- [ShellExecuteHooks]
- "{AEB6717E-7E19-11d0-97EE-00C04FD91972}"=""
- #### HKCR\CLSID\{AEB6717E-7E19-11d0-97EE-00C04FD91972}\InprocServer32 @="shell32.dll"
- -----HKLM\Software\Microsoft\Windows NT\CurrentVersion\Winlogon-----
- [Winlogon]
- "Shell"="Explorer.exe"
- "System"=""
- "Userinit"="C:\WINDOWS\system32\userinit.exe,"
- "VmApplet"="rundll32 shell32,Control_RunDLL \"sysdm.cpl\""
- "UIHost"=expand:"logonui.exe"
- "LogonType"=dword:00000001
- "WinStationsDisabled"="0"
- [Winlogon\GPExtensions]
- [Winlogon\GPExtensions\{0ACDD40C-75AC-47ab-BAA0-BF6DE7E7FE63}]
- "@="Senza fili"
- "DllName"=expand:"gptext.dll"
- [Winlogon\GPExtensions\{25537BA6-77A8-11D2-9B6C-0000F8080861}]
- "@="Folder Redirection"
- "DllName"=expand:"fdeploy.dll"
- [Winlogon\GPExtensions\{3610eda5-77ef-11d2-8dc5-00c04fa31a66}]
- "@="Quota disco Microsoft"
- "DllName"=expand:"dskquota.dll"
- [Winlogon\GPExtensions\{426031c0-0b47-4852-b0ca-ac3d37bfcb39}]
- "@="Utilità di pianificazione pacchetti QoS"
- "DllName"=expand:"gptext.dll"
- [Winlogon\GPExtensions\{42B5FAAE-6536-11d2-AE5A-0000F87571E3}]
- "@="Script"
- "DllName"=expand:"gptext.dll"
- [Winlogon\GPExtensions\{4CFB60C1-FAA6-47f1-89AA-0B18730C9FD3}]
- "@="Internet Explorer Zonemapping"
- "DllName"="C:\WINDOWS\system32\iedkcs32.dll"
- [Winlogon\GPExtensions\{7B849a69-220F-451E-B3FE-2CB811AF94AE}]
- "@="Internet Explorer User Accelerators"
- "DllName"="C:\WINDOWS\system32\iedkcs32.dll"
- [Winlogon\GPExtensions\{827D319E-6EAC-11D2-A4EA-00C04F79F83A}]
- "DllName"=expand:"scecli.dll"
- "@="Security"
- [Winlogon\GPExtensions\{A2E30F80-D7DE-11d2-BBDE-00C04F86AE3B}]
- "DllName"="C:\WINDOWS\system32\iedkcs32.dll"
- "@="Internet Explorer Branding"
- [Winlogon\GPExtensions\{B1BE8D72-6EAC-11D2-A4EA-00C04F79F83A}]
- "DllName"=expand:"scecli.dll"
- "@="EFS recovery"
- [Winlogon\GPExtensions\{B587E2B1-4D59-4e7e-AED9-22B9DF11D053}]
- "@="802.3 Group Policy"
- "DllName"=expand:"dot3gpclnt.dll"
- [Winlogon\GPExtensions\{C631DF4C-088F-4156-B058-4375F0853CD8}]
- "@="Microsoft Offline Files"
- "DllName"=expand:"%SystemRoot%\System32\cscui.dll"
- [Winlogon\GPExtensions\{c6dc5466-785a-11d2-84d0-00c04fb169f7}]
- "@="Installazione software"
- "DllName"=expand:"appmgmts.dll"
- [Winlogon\GPExtensions\{CF7639F3-ABA2-41DB-97F2-81E2C5DBFC5D}]
- "@="Internet Explorer Machine Accelerators"
- "DllName"="C:\WINDOWS\system32\iedkcs32.dll"
- [Winlogon\GPExtensions\{e437bc1c-aa7d-11d2-a382-00c04f991e27}]
- "@="Protezione IP"
- "DllName"=expand:"gptext.dll"
- [Winlogon\Notify]
- [Winlogon\Notify\crypt32chain]
- "DllName"=expand:"crypt32.dll"
- [Winlogon\Notify\cryptnet]
- "DllName"=expand:"cryptnet.dll"
- [Winlogon\Notify\cscdll]
- "DLLName"="cscdll.dll"
- [Winlogon\Notify\dimsntfy]
- "DllName"=expand:"%SystemRoot%\System32\dimsntfy.dll"
- [Winlogon\Notify\ScCertProp]
- "DLLName"="wlnotify.dll"
- [Winlogon\Notify\Schedule]
- "DllName"=expand:"wlnotify.dll"
- [Winlogon\Notify\sclgntfy]
- "DllName"=expand:"sclgntfy.dll"
- [Winlogon\Notify\SensLogn]
- "DLLName"="WlNotify.dll"
- [Winlogon\Notify\termsrv]
- "DllName"=expand:"wlnotify.dll"
- [Winlogon\Notify\TPSvc]
- [Winlogon\Notify\WgaLogon]
- [Winlogon\Notify\WgaLogon\Settings]
- [Winlogon\Notify\wlballoon]
- "DLLName"="wlnotify.dll"
- [Winlogon\SpecialAccounts]
- [Winlogon\SpecialAccounts\UserList]
- "HelpAssistant"=dword:00000000
- "TsInternetUser"=dword:00000000
- "SQLAgentCmdExec"=dword:00000000
- "NetShowServices"=dword:00000000
- "IWAM_"=dword:00010000
- "IUSR_"=dword:00010000
- "VUSR_"=dword:00010000
- "ASPNET"=dword:00000000
- -----HKCU\Software\Microsoft\Windows NT\CurrentVersion\Winlogon-----
- [Winlogon]
- "ParseAutoexec"="1"
- "ExcludeProfileDirs"="Impostazioni locali;Temporary Internet Files;Cronologia;Temp;Impostazioni locali\Dati applicazioni\Microsoft\Outlook"
- "BuildNumber"=dword:00000a28
- -----HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options-----
- [Image File Execution Options\Your Image File Name Here without a path]
- "Debugger"="ntsd -d"
- -----HKLM\System\CurrentControlSet\Control\Session Manager\-----
- [Session Manager]
- "BootExecute"=multi:"autocheck autochk *\00\00"
- [Session Manager\SubSystems]
- "Windows"=expand:"%SystemRoot%\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,3072,512 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=winsrv:ConServerDllInitialization,2 ProfileControl=Off MaxRequestThreads=16"
- -----HKLM\SYSTEM\CurrentControlSet\Control\WOW-----
- [WOW]
- "cmdline"=expand:"%SystemRoot%\system32\ntvdm.exe"
- "wowcmdline"=expand:"%SystemRoot%\system32\ntvdm.exe -a %SystemRoot%\system32\krnl386"
- -----HKLM\Software\Microsoft\Windows NT\CurrentVersion\Run-----
- -----HKLM\Software\Microsoft\Windows\CurrentVersion\RunOnce-----
- [RunOnce]
- -----HKLM\Software\Microsoft\Windows\CurrentVersion\RunOnceEx-----
- [runonceex]
- -----HKLM\Software\Microsoft\Windows\CurrentVersion\RunServices-----
- -----HKLM\Software\Microsoft\Windows\CurrentVersion\RunServicesOnce-----
- [RunServicesOnce]
- -----HKCU\Software\Microsoft\Windows\CurrentVersion\RunOnce-----
- [runonce]
- -----HKCU\Software\Microsoft\Windows\CurrentVersion\RunOnceEx-----
- -----HKCU\Software\Microsoft\Windows\CurrentVersion\RunServices-----
- [RunServices]
- -----HKCU\Software\Microsoft\Windows NT\CurrentVersion\Run-----
- -----HKCU\Software\Microsoft\Windows\CurrentVersion\RunServicesOnce-----
- [RunServicesOnce]
- -----HKLM\Software\Microsoft\Command Processor\Autorun-----
- -----HKCU\Software\Microsoft\Command Processor\Autorun-----
- -----HKCU\Software\Microsoft\Windows NT\CurrentVersion\Windows\Load-----
- -----HKLM\Software\Policies\Microsoft\Windows\System\Scripts\Startup-----
- -----HKCU\Software\Policies\Microsoft\Windows\System\Scripts\Logon-----
- -----HKLM\Software\Policies\Microsoft\Windows\System\Scripts\Logon-----
- -----HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\TerminalServer\Install\Software\Microsoft\Windows\CurrentVersion\Runonce-----
- -----HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\TerminalServer\Install\Software\Microsoft\Windows\CurrentVersion\Run-----
- -----HKLM\System\CurrentControlSet\Control\Terminal Server\Wds\rdpwd\StartupPrograms-----
- -----HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\TerminalServer\Install\Software\Microsoft\Windows\CurrentVersion\Runonce-----
- -----HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler-----
- [SharedTaskScheduler]
- "{438755C2-A8BA-11D1-B96B-00A0C90312E1}"="Precaricatore Browseui"
- #### HKCR\CLSID\{438755C2-A8BA-11D1-B96B-00A0C90312E1}\InprocServer32 @=expand:"%SystemRoot%\system32\browseui.dll"
- "{8C7461EF-2B13-11d2-BE35-3078302C2030}"="Daemon di cache delle categorie di componenti"
- #### HKCR\CLSID\{8C7461EF-2B13-11d2-BE35-3078302C2030}\InprocServer32 @=expand:"%SystemRoot%\system32\browseui.dll"
- -----HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects-----
- [Browser Helper Objects]
- [Browser Helper Objects\{02478D38-C3F9-4efb-9B51-7695ECA05670}]
- [Browser Helper Objects\{02478D38-C3F9-4efb-9B51-7695ECA05670}\NoExplorer]
- @=dword:00000001
- [Browser Helper Objects\{0347C33E-8762-4905-BF09-768834316C61}]
- #### HKCR\CLSID\{0347C33E-8762-4905-BF09-768834316C61}\InprocServer32 @="C:\Programmi\HP\Digital Imaging\Smart Web Printing\hpswp_printenhancer.dll"
- @="HP Print Enhancer"
- [Browser Helper Objects\{18DF081C-E8AD-4283-A596-FA578C2EBDC3}]
- #### HKCR\CLSID\{18DF081C-E8AD-4283-A596-FA578C2EBDC3}\InprocServer32 @="C:\Programmi\File comuni\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll"
- @="AcroIEHelperStub"
- "NoExplorer"=dword:00000001
- [Browser Helper Objects\{3049C3E9-B461-4BC5-8870-4C09146192CA}]
- #### HKCR\CLSID\{3049C3E9-B461-4BC5-8870-4C09146192CA}\InprocServer32 @="C:\Documents and Settings\All Users\Dati applicazioni\Real\RealPlayer\BrowserRecordPlugin\IE\rpbrowserrecordplugin.dll"
- [Browser Helper Objects\{53707962-6F74-2D53-2644-206D7942484F}]
- #### HKCR\CLSID\{53707962-6F74-2D53-2644-206D7942484F}\InprocServer32 @="C:\PROGRA~1\SPYBOT~1\SDHelper.dll"
- [Browser Helper Objects\{5C255C8A-E604-49b4-9D64-90988571CECB}]
- @=""
- [Browser Helper Objects\{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}]
- #### HKCR\CLSID\{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}\InprocServer32 @="C:\Programmi\Oracle\JavaFX 2.1 Runtime\bin\ssv.dll"
- "NoExplorer"=dword:00000001
- [Browser Helper Objects\{9030D464-4C02-4ABF-8ECC-5164760863C6}]
- #### HKCR\CLSID\{9030D464-4C02-4ABF-8ECC-5164760863C6}\InprocServer32 @="C:\Programmi\File comuni\Microsoft Shared\Windows Live\WindowsLiveLogin.dll"
- [Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
- #### HKCR\CLSID\{DBC80044-A445-435b-BC74-9C25C1C588A9}\InprocServer32 @="C:\Programmi\Oracle\JavaFX 2.1 Runtime\bin\jp2ssv.dll"
- "NoExplorer"=dword:00000001
- [Browser Helper Objects\{E7E6F031-17CE-4C07-BC86-EABFE594F69C}]
- #### HKCR\CLSID\{E7E6F031-17CE-4C07-BC86-EABFE594F69C}\InprocServer32 @="C:\Programmi\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll"
- @="JQSIEStartDetectorImpl"
- "NoExplorer"=dword:00000001
- [Browser Helper Objects\{FFFFFFFF-CF4E-4F2B-BDC2-0E72E116A856}]
- #### HKCR\CLSID\{FFFFFFFF-CF4E-4F2B-BDC2-0E72E116A856}\InprocServer32 @="C:\Programmi\HP\Digital Imaging\Smart Web Printing\hpswp_BHO.dll"
- @="HP Smart BHO Class"
- "NoExplorer"=dword:00000001
- -----HKCU\Software\Microsoft\Internet Explorer\URLSearchHooks-----
- [URLSearchHooks]
- "{CFBFAE00-17A6-11D0-99CB-00C04FD64497}"=""
- #### HKCR\CLSID\{CFBFAE00-17A6-11D0-99CB-00C04FD64497}\InprocServer32 @="C:\WINDOWS\system32\ieframe.dll"
- -----HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig-----
- [MSConfig]
- [MSConfig\startupfolder]
- [MSConfig\startupfolder\C:^Documents and Settings^XPSP3VLGen^Menu Avvio^Programmi^Esecuzione automatica^Dropbox.lnk]
- "item"="Dropbox"
- "path"="C:\Documents and Settings\XPSP3VLGen\Menu Avvio\Programmi\Esecuzione automatica\Dropbox.lnk"
- "backup"="C:\WINDOWS\pss\Dropbox.lnkStartup"
- "location"="Startup"
- "command"="C:\DOCUME~1\XPSP3V~1\DATIAP~1\Dropbox\bin\Dropbox.exe"
- [MSConfig\startupreg]
- [MSConfig\startupreg\00PCTFW]
- "key"="SOFTWARE\Microsoft\Windows\CurrentVersion\Run"
- "item"="00PCTFW"
- "hkey"="HKLM"
- "command"="\"C:\Programmi\PC Tools Firewall Plus\FirewallGUI.exe\" -s"
- "inimapping"="0"
- [MSConfig\startupreg\APSDaemon]
- "key"="SOFTWARE\Microsoft\Windows\CurrentVersion\Run"
- "item"="APSDaemon"
- "hkey"="HKLM"
- "command"="\"C:\Programmi\File comuni\Apple\Apple Application Support\APSDaemon.exe\""
- "inimapping"="0"
- [MSConfig\startupreg\HostManager]
- "key"="SOFTWARE\Microsoft\Windows\CurrentVersion\Run"
- "item"="HostManager"
- "hkey"="HKLM"
- "command"="C:\Programmi\File comuni\AOL\1285280360\ee\AOLSoftware.exe"
- "inimapping"="0"
- [MSConfig\startupreg\Sony Ericsson PC Companion]
- "key"="SOFTWARE\Microsoft\Windows\CurrentVersion\Run"
- "item"="Sony Ericsson PC Companion"
- "hkey"="HKCU"
- "command"="\"C:\Programmi\Sony Ericsson\Sony Ericsson PC Companion\PCCompanion.exe\" /Background"
- "inimapping"="0"
- -----HKCU\Control Panel\Desktop\-----
- [Desktop]
- [Desktop\WindowMetrics]
- -----HKEY_CLASSES_ROOT\exefile\shell\open\command-----
- [command]
- @="\"%1\" %*"
- -----HKEY_CLASSES_ROOT\comfile\shell\open\command-----
- [command]
- @="\"%1\" %*"
- -----HKEY_CLASSES_ROOT\batfile\shell\open\command-----
- [command]
- @="\"%1\" %*"
- -----HKEY_CLASSES_ROOT\piffile\shell\open\command-----
- [command]
- @="\"%1\" %*"
- -----HKEY_CLASSES_ROOT\scrFile\shell\open\command-----
- [command]
- @="\"%1\" /S"
- -----HKEY_CLASSES_ROOT\htafile\shell\open\command-----
- [Command]
- @="C:\WINDOWS\system32\mshta.exe \"%1\" %*"
- -----HKEY_CLASSES_ROOT\logfile\shell\open\command-----
- -----HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\URL-----
- [URL]
- [URL\DefaultPrefix]
- @="http://"
- [URL\Prefixes]
- "ftp"="ftp://"
- "gopher"="gopher://"
- "home"="http://"
- "mosaic"="http://"
- "www"="http://"
- -----HKLM\SYSTEM\CurrentControlSet\Control\Lsa-----
- [Lsa]
- [Lsa\AccessProviders]
- [Lsa\AccessProviders\Windows NT Access Provider]
- "ProviderPath"=expand:"%SystemRoot%\system32\ntmarta.dll"
- [Lsa\Audit]
- [Lsa\Audit\PerUserAuditing]
- [Lsa\Audit\PerUserAuditing\System]
- [Lsa\Data]
- [Lsa\SSO]
- [Lsa\SSO\Passport1.4]
- "SSOURL"="http://www.passport.com"
- [Lsa\SspiCache]
- [Lsa\SspiCache\digest.dll]
- "Name"="Digest"
- "Comment"="Digest SSPI Authentication Package"
- [Lsa\SspiCache\msapsspc.dll]
- "Name"="DPA"
- "Comment"="DPA Security Package"
- [Lsa\SspiCache\msnsspc.dll]
- "Name"="MSN"
- "Comment"="MSN Security Package"
- -----HKLM\SYSTEM\CurrentControlSet\Services\SharedAccess-----
- [SharedAccess]
- "Type"=dword:00000020
- "Start"=dword:00000002
- "ErrorControl"=dword:00000001
- "ImagePath"=expand:"%SystemRoot%\System32\svchost.exe -k netsvcs"
- "DependOnGroup"=multi:"\00"
- "ObjectName"="LocalSystem"
- [SharedAccess\Enum]
- "0"="Root\LEGACY_SHAREDACCESS\0000"
- "Count"=dword:00000001
- "NextInstance"=dword:00000001
- [SharedAccess\Epoch]
- "Epoch"=dword:00002ce0
- [SharedAccess\Parameters]
- "ServiceDll"=expand:"%SystemRoot%\System32\ipnathlp.dll"
- [SharedAccess\Parameters\FirewallPolicy]
- [SharedAccess\Parameters\FirewallPolicy\DomainProfile]
- "EnableFirewall"=dword:00000000
- [SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications]
- [SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]
- "%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enaxxxxx@xxxxxres.dll,-22019"
- [SharedAccess\Parameters\FirewallPolicy\DomainProfile\GloballyOpenPorts]
- [SharedAccess\Parameters\FirewallPolicy\DomainProfile\GloballyOpenPorts\List]
- "3389:TCP"="3389:TCP:*:Enabled:Remote Desktop"
- "65533:TCP"="65533:TCP:*:Enabled:Services"
- "52344:TCP"="52344:TCP:*:Enabled:Services"
- [SharedAccess\Parameters\FirewallPolicy\StandardProfile]
- "EnableFirewall"=dword:00000000
- [SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications]
- [SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
- "%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enaxxxxx@xxxxxres.dll,-22019"
- "C:\Documents and Settings\XPSP3VLGen\Impostazioni locali\Dati applicazioni\Akamai\netsession_win.exe"="C:\Documents and Settings\XPSP3VLGen\Impostazioni locali\Dati applicazioni\Akamai\netsession_win.exe:*:Disabled:Akamai NetSession Client"
- "C:\Documents and Settings\XPSP3VLGen\Desktop\gw2\Gw2.exe"="C:\Documents and Settings\XPSP3VLGen\Desktop\gw2\Gw2.exe:*:Enabled:Guild Wars 2 Game Client"
- "C:\Programmi\Pando Networks\Media Booster\PMB.exe"="C:\Programmi\Pando Networks\Media Booster\PMB.exe:*:Enabled:Pando Media Booster"
- "C:\Documents and Settings\XPSP3VLGen\Impostazioni locali\Dati applicazioni\Google\Google Talk Plugin\googletalkplugin.exe"="C:\Documents and Settings\XPSP3VLGen\Impostazioni locali\Dati applicazioni\Google\Google Talk Plugin\googletalkplugin.exe:*:Enabled:Google Talk Plugin"
- "C:\Programmi\uTorrent\uTorrent.exe"="C:\Programmi\uTorrent\uTorrent.exe:*:Enabled:µTorrent"
- "C:\CyberStep\CosmicBreak_eng\programs\cosmic.exe"="C:\CyberStep\CosmicBreak_eng\programs\cosmic.exe:*:Enabled:????????"
- "C:\Programmi\OGPlanet\SD Gundam Capsule Fighter\GOnline.exe"="C:\Programmi\OGPlanet\SD Gundam Capsule Fighter\GOnline.exe:*:Enabled:zoa_core DLL"
- "C:\CherryDeGames\Dragon Nest\DragonNest.exe"="C:\CherryDeGames\Dragon Nest\DragonNest.exe:*:Enabled:Dragon Nest"
- "C:\Documents and Settings\XPSP3VLGen\Dati applicazioni\Dropbox\bin\Dropbox.exe"="C:\Documents and Settings\XPSP3VLGen\Dati applicazioni\Dropbox\bin\Dropbox.exe:*:Enabled:Dropbox"
- "C:\Programmi\Java\jre7\bin\javaw.exe"="C:\Programmi\Java\jre7\bin\javaw.exe:*:Enabled:Java(TM) Platform SE binary"
- [SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts]
- [SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List]
- "3389:TCP"="3389:TCP:*:Enabled:Remote Desktop"
- "65533:TCP"="65533:TCP:*:Enabled:Services"
- "52344:TCP"="52344:TCP:*:Enabled:Services"
- "2300:TCP"="2300:TCP:*:Enabled:Akamai NetSession Interface"
- "5000:UDP"="5000:UDP:*:Enabled:Akamai NetSession Interface"
- [SharedAccess\Setup]
- "ServiceUpgrade"=dword:00000001
- -----HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows Firewall\-----
- -----HKEY_LOCAL_MACHINE\SOFTWARE\Winsock2-----
- -----HKLM\Software\Microsoft\Ole-----
- [Ole]
- "DefaultLaunchPermission"=hex:01,00,04,80,5c,00,00,00,6c,00,00,00,00,00,00,00,\
- "MachineLaunchRestriction"=hex:01,00,04,80,48,00,00,00,58,00,00,00,00,00,00,00,\
- "MachineAccessRestriction"=hex:01,00,04,80,44,00,00,00,54,00,00,00,00,00,00,00,\
- "EnableDCOM"="Y"
- [Ole\AppCompat]
- [Ole\AppCompat\ActivationSecurityCheckExemptionList]
- "{A50398B8-9075-4FBF-A7A1-456BF21937AD}"="1"
- "{AD65A69D-3831-40D7-9629-9B0B50A93843}"="1"
- "{0040D221-54A1-11D1-9DE0-006097042D69}"="1"
- "{2A6D72F1-6E7E-4702-B99C-E40D3DED33C3}"="1"
- [Ole\NONREDIST]
- "System.EnterpriseServices.Thunk.dll"=""
- -----HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows\WindowsUpdate\AU\-----
- [AU]
- -----HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\System\-----
- [System]
- -----HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\-----
- [Security Center]
- "FirstRunDisabled"=dword:00000001
- "AntiVirusDisableNotify"=dword:00000001
- "FirewallDisableNotify"=dword:00000001
- "UpdatesDisableNotify"=dword:00000001
- "AntiVirusOverride"=dword:00000000
- "FirewallOverride"=dword:00000000
- [Security Center\Monitoring]
- [Security Center\Monitoring\AhnlabAntiVirus]
- [Security Center\Monitoring\ComputerAssociatesAntiVirus]
- [Security Center\Monitoring\KasperskyAntiVirus]
- [Security Center\Monitoring\McAfeeAntiVirus]
- [Security Center\Monitoring\McAfeeFirewall]
- [Security Center\Monitoring\PandaAntiVirus]
- [Security Center\Monitoring\PandaFirewall]
- [Security Center\Monitoring\SophosAntiVirus]
- [Security Center\Monitoring\SymantecAntiVirus]
- [Security Center\Monitoring\SymantecFirewall]
- [Security Center\Monitoring\TinyFirewall]
- [Security Center\Monitoring\TrendAntiVirus]
- [Security Center\Monitoring\TrendFirewall]
- [Security Center\Monitoring\ZoneLabsFirewall]
- -----HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRestore\-----
- [SystemRestore]
- "DisableSR"=dword:00000000
- "CreateFirstRunRp"=dword:00000001
- "DSMin"=dword:000000c8
- "DSMax"=dword:00000190
- "RPSessionInterval"=dword:00000000
- "RPGlobalInterval"=dword:00015180
- "RPLifeInterval"=dword:0076a700
- "CompressionBurst"=dword:0000003c
- "TimerInterval"=dword:00000078
- "DiskPercent"=dword:0000000c
- "ThawInterval"=dword:00000384
- "RestoreDiskSpaceError"=dword:00000000
- [SystemRestore\Cfg]
- "DiskPercent"=dword:0000000c
- "MachineGuid"="{B8615ACE-FF6B-4F1E-8990-09F7B77651F1}"
- [SystemRestore\SnapshotCallbacks]
- @=""
- -----HKEY_CURRENT_USER\Software\VB and VBA Program Settings-----
- [VB and VBA Program Settings]
- [VB and VBA Program Settings\Euro Add-in]
- [VB and VBA Program Settings\Euro Add-in\Wizard Options]
- -----HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\-----
- -----HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\AdvancedOptions-----
- [AdvancedOptions]
- -----HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\AdvancedOptions-----
- -----HKLM\Software\Microsoft\Active Setup\Installed Components-----
- [Installed Components]
- [Installed Components\<{12d0ed0d-0ee0-4f90-8827-78cefb8f4988}]
- "@="Internet Explorer - Aggiornamento versione"
- "ComponentID"="IEUDINIT"
- "StubPath"="C:\WINDOWS\system32\ieudinit.exe"
- [Installed Components\>{22d6f312-b0f6-11d0-94ab-0080c74c7e95}]
- #### HKCR\CLSID\{22d6f312-b0f6-11d0-94ab-0080c74c7e95}\InprocServer32 @="C:\WINDOWS\system32\wmpdxm.dll"
- "Stubpath"="C:\WINDOWS\inf\unregmp2.exe /ShowWMP"
- "@="Microsoft Windows Media Player"
- "ComponentID"="WMPACCESS"
- [Installed Components\>{26923b43-4d38-484f-9b9e-de460746276c}]
- "@="Internet Explorer"
- "ComponentID"="IEACCESS"
- "StubPath"="C:\WINDOWS\system32\ie4uinit.exe -UserIconConfig"
- [Installed Components\>{60B49E34-C7CC-11D0-8953-00A0C90347FF}]
- "@="Browser Customizations"
- "ComponentiD"="BRANDING.CAB"
- "StubPath"="\"C:\WINDOWS\system32\rundll32.exe\" \"C:\WINDOWS\system32\iedkcs32.dll\",BrandIEActiveSetup SIGNUP"
- [Installed Components\>{60B49E34-C7CC-11D0-8953-00A0C90347FF}MICROS]
- "@="Personalizzazione del browser"
- "ComponentID"="BRANDING.CAB"
- "StubPath"="RunDLL32 IEDKCS32.DLL,BrandIE4 SIGNUP"
- [Installed Components\>{881dd1c5-3dcf-431b-b061-f3f88e8be88a}]
- "@="Outlook Express"
- "ComponentID"="OEACCESS"
- "StubPath"=expand:"%systemroot%\system32\shmgrate.exe OCInstallUserConfigOE"
- [Installed Components\{03F998B2-0E00-11D3-A498-00104B6EB52E}]
- #### HKCR\CLSID\{03F998B2-0E00-11D3-A498-00104B6EB52E}\InprocServer32 @="C:\Programmi\Viewpoint\Viewpoint Experience Technology\AxMetaStream.dll"
- "@="Viewpoint Media Player"
- "ComponentID"="Viewpoint"
- [Installed Components\{08B0E5C0-4FCB-11CF-AAA5-00401C608500}]
- "@="Java (Sun)"
- "ComponentID"="JAVAVM"
- "KeyFileName"="C:\Programmi\Java\jre6\bin\regutils.dll"
- [Installed Components\{10072CEC-8CC1-11D1-986E-00A0C955B42F}]
- "@="Rendering grafica vettoriale (VML)"
- "ComponentID"="MSVML"
- [Installed Components\{1B00725B-C455-4DE6-BFB6-AD540AD427CD}]
- #### HKCR\CLSID\{1B00725B-C455-4DE6-BFB6-AD540AD427CD}\InprocServer32 @="C:\Programmi\Viewpoint\Viewpoint Experience Technology\AxMetaStream.dll"
- "@="Viewpoint Media Player"
- "ComponentID"="Viewpoint"
- [Installed Components\{2179C5D3-EBFF-11CF-B6FD-00AA00B4E220}]
- #### HKCR\CLSID\{2179C5D3-EBFF-11CF-B6FD-00AA00B4E220}\InprocServer32 @="C:\WINDOWS\system32\wmpdxm.dll"
- "ComponentID"="NetShow"
- "StubPath"=""
- [Installed Components\{22d6f312-b0f6-11d0-94ab-0080c74c7e95}]
- #### HKCR\CLSID\{22d6f312-b0f6-11d0-94ab-0080c74c7e95}\InprocServer32 @="C:\WINDOWS\system32\wmpdxm.dll"
- "ComponentID"="Microsoft Windows Media Player"
- "StubPath"=""
- "@="Microsoft Windows Media Player 6.4"
- [Installed Components\{283807B5-2C60-11D0-A31D-00AA00B92C03}]
- "@="DirectAnimation"
- "ComponentID"="DirectAnimation"
- [Installed Components\{2C7339CF-2B09-4501-B3F3-F3508C9228ED}]
- "@="Themes Setup"
- "ComponentID"="Theme Component"
- "StubPath"=expand:"%SystemRoot%\system32\regsvr32.exe /s /n /i:/UserInstall %SystemRoot%\system32\themeui.dll"
- [Installed Components\{36f8ec70-c29a-11d1-b5c7-0000f8051515}]
- "@="Binding dati Dynamic HTML per Java"
- "ComponentID"="TridataJava"
- [Installed Components\{3af36230-a269-11d1-b5bf-0000f8051515}]
- "@="Offline Browsing Pack"
- "ComponentID"="MobilePk"
- [Installed Components\{3bf42070-b3b1-11d1-b5c5-0000f8051515}]
- "@="Uniscribe"
- "ComponentID"="USP10"
- [Installed Components\{3C3901C5-3455-3E0A-A214-0B093A5070A6}]
- "ComponentID"=".NETFramework"
- "@=".NET Framework"
- [Installed Components\{411EDCF7-755D-414E-A74B-3DCD6583F589}]
- "ComponentID"="S867460"
- "@="Microsoft .NET Framework 1.1 Service Pack 1 (KB867460)"
- [Installed Components\{4278c270-a269-11d1-b5bf-0000f8051515}]
- "@="Creazione avanzata"
- "ComponentID"="AdvAuth"
- [Installed Components\{44BBA840-CC51-11CF-AAFA-00AA00B6015C}]
- "@="Microsoft Outlook Express 6"
- "ComponentID"="MailNews"
- "StubPath"=expand:"\"%ProgramFiles%\Outlook Express\setup50.exe\" /APP:OE /CALLER:WINNT /user /install"
- [Installed Components\{44BBA842-CC51-11CF-AAFA-00AA00B6015B}]
- "@="NetMeeting 3.01"
- "ComponentID"="NetMeeting"
- "StubPath"="rundll32.exe advpack.dll,LaunchINFSection C:\WINDOWS\INF\msnetmtg.inf,NetMtg.Install.PerUser.NT"
- [Installed Components\{44BBA848-CC51-11CF-AAFA-00AA00B6015C}]
- "@="DirectShow"
- "ComponentID"="activemovie"
- [Installed Components\{44BBA855-CC51-11CF-AAFA-00AA00B6015F}]
- "@="DirectDrawEx"
- "ComponentID"="DirectDrawEx"
- [Installed Components\{45ea75a0-a269-11d1-b5bf-0000f8051515}]
- "@="Internet Explorer Help"
- "ComponentID"="HelpCont"
- [Installed Components\{4f216970-c90c-11d1-b5c7-0000f8051515}]
- "@="Classi Java DirectAnimation"
- "ComponentID"="DAJava"
- [Installed Components\{4f645220-306d-11d2-995d-00c04f98bbc9}]
- "@="Microsoft Windows Script 5.8"
- "ComponentID"="MSVBScript"
- [Installed Components\{5945c046-1e7d-11d1-bc44-00c04fd912be}]
- "KeyFileName"="C:\Programmi\Messenger\msmsgs.exe"
- "@="Windows Messenger 4.7"
- "ComponentID"="Messenger"
- "StubPath"="rundll32.exe advpack.dll,LaunchINFSection C:\WINDOWS\INF\msmsgs.inf,BLC.QuietInstall.PerUser"
- [Installed Components\{5A8D6EE0-3E18-11D0-821E-444553540000}]
- "(Default)"="Internet Connection Wizard"
- "ComponentID"="ICW"
- [Installed Components\{5fd399c0-a70a-11d1-9948-00c04f98bbc9}]
- "@="Internet Explorer Setup Tools"
- "ComponentID"="GenSetup"
- [Installed Components\{630b1da0-b465-11d1-9948-00c04f98bbc9}]
- "@="Browsing Enhancements"
- "ComponentID"="ExtraPack"
- "KeyFileName"="C:\WINDOWS\system32\msieftp.dll"
- [Installed Components\{6BF52A52-394A-11d3-B153-00C04F79FAA6}]
- #### HKCR\CLSID\{6BF52A52-394A-11d3-B153-00C04F79FAA6}\InprocServer32 @="C:\WINDOWS\system32\wmp.dll"
- "@="Microsoft Windows Media Player"
- "ComponentID"="Microsoft Windows Media Player"
- "StubPath"="rundll32.exe advpack.dll,LaunchINFSection C:\WINDOWS\INF\wmp.inf,PerUserStub"
- [Installed Components\{6fab99d0-bab8-11d1-994a-00c04f98bbc9}]
- "@="MSN Site Access"
- "ComponentID"="MSN_Auth"
- [Installed Components\{71CB2612-627C-3D58-8D82-B77444B27B6A}]
- "@=".NET Framework"
- "ComponentID"=".NETFramework"
- [Installed Components\{73FA19D0-2D75-11D2-995D-00C04F98BBC9}]
- "@="Web Folders"
- "ComponentID"="WebFolders"
- "StubPath"=""
- [Installed Components\{7790769C-0471-11d2-AF11-00C04FA35D02}]
- "@="Rubrica 6"
- "ComponentID"="WAB"
- "StubPath"=expand:"\"%ProgramFiles%\Outlook Express\setup50.exe\" /APP:WAB /CALLER:WINNT /user /install"
- [Installed Components\{89820200-ECBD-11cf-8B85-00AA005B4340}]
- "@="Windows Desktop Update"
- "ComponentID"="IE4Shell_NT"
- "StubPath"=expand:"regsvr32.exe /s /n /i:U shell32.dll"
- [Installed Components\{89820200-ECBD-11cf-8B85-00AA005B4383}]
- "@="Internet Explorer"
- "ComponentID"="BASEIE40_W2K"
- "StubPath"="C:\WINDOWS\system32\ie4uinit.exe -BaseSettings"
- [Installed Components\{89820200-ECBD-11cf-8B85-00AA005B4383}\AuthorizedCDFPrefix]
- [Installed Components\{89B4C1CD-B018-4511-B0A1-5476DBF70820}]
- "StubPath"="C:\WINDOWS\system32\Rundll32.exe C:\WINDOWS\system32\mscories.dll,Install"
- "ComponentID"="DOTNETFRAMEWORKS"
- [Installed Components\{9381D8F2-0288-11D0-9501-00AA00B911A5}]
- "@="Dynamic HTML Data Binding"
- "ComponentID"="Tridata"
- [Installed Components\{ACC563BC-4266-43f0-B6ED-9D38C4202C7E}]
- [Installed Components\{B508B3F1-A24A-32C0-B310-85786919EF28}]
- "ComponentID"=".NETFramework"
- "@=".NET Framework"
- [Installed Components\{C09FB3CD-3D0C-3F2D-899A-6A1D67F2073F}]
- "ComponentID"=".NETFramework"
- "@=".NET Framework"
- [Installed Components\{C9E9A340-D1F1-11D0-821E-444553540600}]
- "@="Internet Explorer Core Fonts"
- "ComponentID"="Fontcore"
- [Installed Components\{CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1}]
- "ComponentID"=".NETFramework"
- "@=".NET Framework"
- [Installed Components\{CC2A9BA0-3BDD-11D0-821E-444553540000}]
- "@="Utilità di pianificazione"
- "ComponentID"="MSTASK"
- [Installed Components\{CDD7975E-60F8-41d5-8149-19E51D6F71D0}]
- "ComponentID"="Windows Movie Maker v2.1"
- [Installed Components\{D27CDB6E-AE6D-11cf-96B8-444553540000}]
- "@="Adobe Flash Player"
- "ComponentID"="Flash"
- [Installed Components\{de5aed00-a4bf-11d1-9948-00c04f98bbc9}]
- "@="HTML Help"
- "ComponentID"="HTMLHelp"
- [Installed Components\{E92B03AB-B707-11d2-9CBD-0000F87A369E}]
- "@="Active Directory Service Interface"
- "ComponentID"="ADSI"
- -----Comparing registry keys CCS1 vs CCS2 -----
- < Value: HKEY_LOCAL_MACHINE\system\controlset001\services\sptd Start REG_DWORD 0 (0x0)
- > Value: HKEY_LOCAL_MACHINE\system\controlset002\services\sptd Start REG_DWORD 4 (0x4)
- > Value: HKEY_LOCAL_MACHINE\system\controlset002\services\sptd\Cfg
- < Value: HKEY_LOCAL_MACHINE\system\controlset001\services\srservice\Parameters ServiceDll REG_EXPAND_SZ C:\WINDOWS\system32\srsvc.dll
- > Value: HKEY_LOCAL_MACHINE\system\controlset002\services\srservice\Parameters ServiceDll REG_EXPAND_SZ %SystemRoot%\system32\srsvc.dll
- < Value: HKEY_LOCAL_MACHINE\system\controlset001\services\Tcpip\Linkage Export REG_MULTI_SZ \Device\Tcpip_{0AD0ED61-DF38-416C-AD16-F08F89A6EC1A}\0\Device\Tcpip_{009FDEF4-483C-49C6-880D-64EC2A853013}\0\Device\Tcpip_{85719925-8EC6-4EC1-AE56-00A50D48D9A7}\0\Device\Tcpip_{C10C7495-1534-4ED4-92C9-920BE1FBD7FF}\0\0
- > Value: HKEY_LOCAL_MACHINE\system\controlset002\services\Tcpip\Linkage Export REG_MULTI_SZ \Device\Tcpip_{0AD0ED61-DF38-416C-AD16-F08F89A6EC1A}\0\Device\Tcpip_{009FDEF4-483C-49C6-880D-64EC2A853013}\0\Device\Tcpip_{85719925-8EC6-4EC1-AE56-00A50D48D9A7}\0\Device\Tcpip_{C10C7495-1534-4ED4-92C9-920BE1FBD7FF}\0\Device\Tcpip_{22396612-00BB-4A4F-B86D-50CC27A73AE1}\0\Device\Tcpip_{0F456099-C162-4E82-A495-1CDD6D8C2C31}\0\0
- < Value: HKEY_LOCAL_MACHINE\system\controlset001\services\Tcpip\Parameters NameServer REG_SZ
- < Value: HKEY_LOCAL_MACHINE\system\controlset001\services\Tcpip\Parameters EnableICMPRedirect REG_DWORD 1 (0x1)
- < Value: HKEY_LOCAL_MACHINE\system\controlset001\services\Tcpip\Parameters EnableSecurityFilters REG_DWORD 0 (0x0)
- > Value: HKEY_LOCAL_MACHINE\system\controlset002\services\Tcpip\Parameters TcpMaxDataRetransmissions REG_DWORD 5 (0x5)
- < Value: HKEY_LOCAL_MACHINE\system\controlset001\services\Tcpip\Parameters\Adapters\NdisWanIp IpConfig REG_MULTI_SZ Tcpip\Parameters\Interfaces\{85719925-8EC6-4EC1-AE56-00A50D48D9A7}\0Tcpip\Parameters\Interfaces\{C10C7495-1534-4ED4-92C9-920BE1FBD7FF}\0\0
- > Value: HKEY_LOCAL_MACHINE\system\controlset002\services\Tcpip\Parameters\Adapters\NdisWanIp IpConfig REG_MULTI_SZ Tcpip\Parameters\Interfaces\{85719925-8EC6-4EC1-AE56-00A50D48D9A7}\0Tcpip\Parameters\Interfaces\{C10C7495-1534-4ED4-92C9-920BE1FBD7FF}\0Tcpip\Parameters\Interfaces\{22396612-00BB-4A4F-B86D-50CC27A73AE1}\0Tcpip\Parameters\Interfaces\{0F456099-C162-4E82-A495-1CDD6D8C2C31}\0\0
- < Value: HKEY_LOCAL_MACHINE\system\controlset001\services\Tcpip\Parameters\Adapters\NdisWanIp NumInterfaces REG_DWORD 2 (0x2)
- > Value: HKEY_LOCAL_MACHINE\system\controlset002\services\Tcpip\Parameters\Adapters\NdisWanIp NumInterfaces REG_DWORD 4 (0x4)
- < Value: HKEY_LOCAL_MACHINE\system\controlset001\services\Tcpip\Parameters\Adapters\NdisWanIp IpInterfaces REG_BINARY 25997185C68EC14EAE5600A50D48D9A795740CC13415D44E92C9920BE1FBD7FF
- > Value: HKEY_LOCAL_MACHINE\system\controlset002\services\Tcpip\Parameters\Adapters\NdisWanIp IpInterfaces REG_BINARY 25997185C68EC14EAE5600A50D48D9A795740CC13415D44E92C9920BE1FBD7FF12663922BB004F4AB86D50CC27A73AE19960450F62C1824EA4951CDD6D8C2C31
- < Value: HKEY_LOCAL_MACHINE\system\controlset001\services\Tcpip\Parameters\Interfaces\{009FDEF4-483C-49C6-880D-64EC2A853013} NTEContextList REG_MULTI_SZ 0x00000002\0\0
- > Value: HKEY_LOCAL_MACHINE\system\controlset002\services\Tcpip\Parameters\Interfaces\{009FDEF4-483C-49C6-880D-64EC2A853013} NTEContextList REG_MULTI_SZ 0x00000003\0\0
- < Value: HKEY_LOCAL_MACHINE\system\controlset001\services\Tcpip\Parameters\Interfaces\{0AD0ED61-DF38-416C-AD16-F08F89A6EC1A} NTEContextList REG_MULTI_SZ 0x00000003\0\0
- > Value: HKEY_LOCAL_MACHINE\system\controlset002\services\Tcpip\Parameters\Interfaces\{0AD0ED61-DF38-416C-AD16-F08F89A6EC1A} NTEContextList REG_MULTI_SZ 0x00000002\00x00000004\0\0
- < Value: HKEY_LOCAL_MACHINE\system\controlset001\services\Tcpip\Parameters\Interfaces\{0AD0ED61-DF38-416C-AD16-F08F89A6EC1A} LeaseObtainedTime REG_DWORD 1278669190 (0x4C36F186)
- > Value: HKEY_LOCAL_MACHINE\system\controlset002\services\Tcpip\Parameters\Interfaces\{0AD0ED61-DF38-416C-AD16-F08F89A6EC1A} LeaseObtainedTime REG_DWORD 1341410748 (0x4FF44DBC)
- < Value: HKEY_LOCAL_MACHINE\system\controlset001\services\Tcpip\Parameters\Interfaces\{0AD0ED61-DF38-416C-AD16-F08F89A6EC1A} T1 REG_DWORD 1278798790 (0x4C38EBC6)
- > Value: HKEY_LOCAL_MACHINE\system\controlset002\services\Tcpip\Parameters\Interfaces\{0AD0ED61-DF38-416C-AD16-F08F89A6EC1A} T1 REG_DWORD 1341540348 (0x4FF647FC)
- < Value: HKEY_LOCAL_MACHINE\system\controlset001\services\Tcpip\Parameters\Interfaces\{0AD0ED61-DF38-416C-AD16-F08F89A6EC1A} T2 REG_DWORD 1278895990 (0x4C3A6776)
- > Value: HKEY_LOCAL_MACHINE\system\controlset002\services\Tcpip\Parameters\Interfaces\{0AD0ED61-DF38-416C-AD16-F08F89A6EC1A} T2 REG_DWORD 1341637548 (0x4FF7C3AC)
- < Value: HKEY_LOCAL_MACHINE\system\controlset001\services\Tcpip\Parameters\Interfaces\{0AD0ED61-DF38-416C-AD16-F08F89A6EC1A} LeaseTerminatesTime REG_DWORD 1278928390 (0x4C3AE606)
- > Value: HKEY_LOCAL_MACHINE\system\controlset002\services\Tcpip\Parameters\Interfaces\{0AD0ED61-DF38-416C-AD16-F08F89A6EC1A} LeaseTerminatesTime REG_DWORD 1341669948 (0x4FF8423C)
- < Value: HKEY_LOCAL_MACHINE\system\controlset001\services\Tcpip\Parameters\Interfaces\{0AD0ED61-DF38-416C-AD16-F08F89A6EC1A} IPAutoconfigurationSeed REG_DWORD 82782028 (0x4EF274C)
- > Value: HKEY_LOCAL_MACHINE\system\controlset002\services\Tcpip\Parameters\Interfaces\{0AD0ED61-DF38-416C-AD16-F08F89A6EC1A} IPAutoconfigurationSeed REG_DWORD -1243345876 (0xB5E40C2C)
- < Value: HKEY_LOCAL_MACHINE\system\controlset001\services\Tcpip\Parameters\Interfaces\{0AD0ED61-DF38-416C-AD16-F08F89A6EC1A} DhcpIPAddress REG_SZ 192.168.0.100
- > Value: HKEY_LOCAL_MACHINE\system\controlset002\services\Tcpip\Parameters\Interfaces\{0AD0ED61-DF38-416C-AD16-F08F89A6EC1A} DhcpIPAddress REG_SZ 192.168.0.102
- > Value: HKEY_LOCAL_MACHINE\system\controlset002\services\Tcpip\Parameters\Interfaces\{0AD0ED61-DF38-416C-AD16-F08F89A6EC1A} DhcpRetryTime REG_DWORD 129597 (0x1FA3D)
- > Value: HKEY_LOCAL_MACHINE\system\controlset002\services\Tcpip\Parameters\Interfaces\{0AD0ED61-DF38-416C-AD16-F08F89A6EC1A} DhcpRetryStatus REG_DWORD 0 (0x0)
- > Value: HKEY_LOCAL_MACHINE\system\controlset002\services\Tcpip\Parameters\Interfaces\{C10C7495-1534-4ED4-92C9-920BE1FBD7FF} NTEContextList REG_MULTI_SZ \0
- > Value: HKEY_LOCAL_MACHINE\system\controlset002\services\Tcpip\Parameters\Interfaces\{C10C7495-1534-4ED4-92C9-920BE1FBD7FF} DhcpClassIdBin REG_BINARY
- > Value: HKEY_LOCAL_MACHINE\system\controlset002\services\Tcpip\Parameters\Interfaces\{C10C7495-1534-4ED4-92C9-920BE1FBD7FF} DhcpIPAddress REG_SZ 0.0.0.0
- > Value: HKEY_LOCAL_MACHINE\system\controlset002\services\Tcpip\Parameters\Interfaces\{C10C7495-1534-4ED4-92C9-920BE1FBD7FF} DhcpSubnetMask REG_SZ 0.0.0.0
- > Value: HKEY_LOCAL_MACHINE\system\controlset002\services\Tcpip\Parameters\Interfaces\{C10C7495-1534-4ED4-92C9-920BE1FBD7FF} Domain REG_SZ
- > Value: HKEY_LOCAL_MACHINE\system\controlset002\services\Tcpip\Parameters\Interfaces\{C10C7495-1534-4ED4-92C9-920BE1FBD7FF} NameServer REG_SZ
- > Value: HKEY_LOCAL_MACHINE\system\controlset002\services\Tcpip\Parameters\Interfaces\{C10C7495-1534-4ED4-92C9-920BE1FBD7FF} RegistrationEnabled REG_DWORD 0 (0x0)
- > Value: HKEY_LOCAL_MACHINE\system\controlset002\services\Tcpip\Parameters\Interfaces\{C10C7495-1534-4ED4-92C9-920BE1FBD7FF} RegisterAdapterName REG_DWORD 0 (0x0)
- < Value: HKEY_LOCAL_MACHINE\system\controlset001\services\TermService Start REG_DWORD 3 (0x3)
- > Value: HKEY_LOCAL_MACHINE\system\controlset002\services\TermService Start REG_DWORD 2 (0x2)
- < Value: HKEY_LOCAL_MACHINE\system\controlset001\services\TermService ImagePath REG_EXPAND_SZ %SystemRoot%\System32\svchost -k DComLaunch
- > Value: HKEY_LOCAL_MACHINE\system\controlset002\services\TermService ImagePath REG_EXPAND_SZ %SystemRoot%\System32\svchost.exe -k DComLaunch
- < Value: HKEY_LOCAL_MACHINE\system\controlset001\services\TlntSvr Start REG_DWORD 4 (0x4)
- > Value: HKEY_LOCAL_MACHINE\system\controlset002\services\TlntSvr Start REG_DWORD 3 (0x3)
- > Value: HKEY_LOCAL_MACHINE\system\controlset002\services\UPS Port REG_SZ COM1
- > Value: HKEY_LOCAL_MACHINE\system\controlset002\services\UPS Options REG_DWORD 126 (0x7E)
- > Value: HKEY_LOCAL_MACHINE\system\controlset002\services\UPS FirstMessageDelay REG_DWORD 5 (0x5)
- > Value: HKEY_LOCAL_MACHINE\system\controlset002\services\UPS MessageInterval REG_DWORD 120 (0x78)
- < Value: HKEY_LOCAL_MACHINE\system\controlset001\services\W32Time\Parameters ServiceDll REG_EXPAND_SZ C:\WINDOWS\system32\w32time.dll
- > Value: HKEY_LOCAL_MACHINE\system\controlset002\services\W32Time\Parameters ServiceDll REG_EXPAND_SZ %systemroot%\system32\w32time.dll
- < Value: HKEY_LOCAL_MACHINE\system\controlset001\services\W32Time\TimeProviders\NtpClient SpecialPollTimeRemaining REG_MULTI_SZ time.windows.com,7b3dfd5\0\0\0\0\0\0\0\0\0\0\0\0
- > Value: HKEY_LOCAL_MACHINE\system\controlset002\services\W32Time\TimeProviders\NtpClient SpecialPollTimeRemaining REG_MULTI_SZ time.windows.com,7bd743b\0\0\0\0\0\0\0\0\0\0\0\0
- < Value: HKEY_LOCAL_MACHINE\system\controlset001\services\Windows Workflow Foundation 3.0.0.0\Performance WbemAdapFileSignature REG_BINARY 29A5C01E8846529D0A6C8D88735A31E6
- > Value: HKEY_LOCAL_MACHINE\system\controlset002\services\Windows Workflow Foundation 3.0.0.0\Performance WbemAdapFileSignature REG_BINARY 349C17B1EB3E88AE18C10309ABA446B5
- < Value: HKEY_LOCAL_MACHINE\system\controlset001\services\Windows Workflow Foundation 3.0.0.0\Performance WbemAdapFileTime REG_BINARY 005EA77AD715C801
- > Value: HKEY_LOCAL_MACHINE\system\controlset002\services\Windows Workflow Foundation 3.0.0.0\Performance WbemAdapFileTime REG_BINARY 001E98A57AC6CA01
- < Value: HKEY_LOCAL_MACHINE\system\controlset001\services\Windows Workflow Foundation 3.0.0.0\Performance WbemAdapFileSize REG_DWORD 41984 (0xA400)
- > Value: HKEY_LOCAL_MACHINE\system\controlset002\services\Windows Workflow Foundation 3.0.0.0\Performance WbemAdapFileSize REG_DWORD 49488 (0xC150)
- < Value: HKEY_LOCAL_MACHINE\system\controlset001\services\Winsock\Setup Migration\Providers\NetBIOS WinSock 1.1 Provider Data REG_BINARY 0E10000011000000140000001400000005000000FDFFFFFF00FA00003A0400000912000011000000140000001400000002000000FDFFFFFF00FA0000C40300000E100000110000001400000014000000050000000000008000FA00004E03000009120000110000001400000014000000020000000000008000FA0000D80200000E10000011000000140000001400000005000000FFFFFFFF00FA0000620200000912000011000000140000001400000002000000FFFFFFFF00FA0000EC0100000E10000011000000140000001400000005000000FEFFFFFF00FA0000760100000912000011000000140000001400000002000000FEFFFFFF00FA0000000100005C004400650076006900630065005C004E0065007400420054005F00540063007000690070005F007B00430031003000430037003400390035002D0031003500330034002D0034004500440034002D0039003200430039002D003900320030004200450031004600420044003700460046007D0000005C004400650076006900630065005C004E0065007400420054005F00540063007000690070005F007B00430031003000430037003400390035002D0031003500330034002D0034004500440034002D0039003200430039002D003900320030004200450031004600420044003700460046007D0000005C004400650076006900630065005C004E0065007400420054005F00540063007000690070005F007B00380035003700310039003900320035002D0038004500430036002D0034004500430031002D0041004500350036002D003000300041003500300044003400380044003900410037007D0000005C004400650076006900630065005C004E0065007400420054005F00540063007000690070005F007B00380035003700310039003900320035002D0038004500430036002D0034004500430031002D0041004500350036002D003000300041003500300044003400380044003900410037007D0000005C004400650076006900630065005C004E0065007400420054005F00540063007000690070005F007B00300030003900460044004500460034002D0034003800330043002D0034003900430036002D0038003800300044002D003600340045004300320041003800350033003000310033007D0000005C004400650076006900630065005C004E0065007400420054005F00540063007000690070005F007B00300030003900460044004500460034002D0034003800330043002D0034003900430036002D0038003800300044002D003600340045004300320041003800350033003000310033007D0000005C004400650076006900630065005C004E0065007400420054005F00540063007000690070005F007B00300041004400300045004400360031002D0044004600330038002D0034003100360043002D0041004400310036002D004600300038004600380039004100360045004300310041007D0000005C004400650076006900630065005C004E0065007400420054005F00540063007000690070005F007B00300041004400300045004400360031002D0044004600330038002D0034003100360043002D0041004400310036002D004600300038004600380039004100360045004300310041007D000000
- > Value: HKEY_LOCAL_MACHINE\system\controlset002\services\Winsock\Setup Migration\Providers\NetBIOS WinSock 1.1 Provider Data REG_BINARY 0E10000011000000140000001400000005000000FDFFFFFF00FA0000920600000912000011000000140000001400000002000000FDFFFFFF00FA00001C0600000E100000110000001400000014000000050000000000008000FA0000A605000009120000110000001400000014000000020000000000008000FA0000300500000E10000011000000140000001400000005000000FFFFFFFF00FA0000BA0400000912000011000000140000001400000002000000FFFFFFFF00FA0000440400000E10000011000000140000001400000005000000FEFFFFFF00FA0000CE0300000912000011000000140000001400000002000000FEFFFFFF00FA0000580300000E10000011000000140000001400000005000000FCFFFFFF00FA0000E20200000912000011000000140000001400000002000000FCFFFFFF00FA00006C0200000E10000011000000140000001400000005000000FBFFFFFF00FA0000F60100000912000011000000140000001400000002000000FBFFFFFF00FA0000800100005C004400650076006900630065005C004E0065007400420054005F00540063007000690070005F007B00300046003400350036003000390039002D0043003100360032002D0034004500380032002D0041003400390035002D003100430044004400360044003800430032004300330031007D0000005C004400650076006900630065005C004E0065007400420054005F00540063007000690070005F007B00300046003400350036003000390039002D0043003100360032002D0034004500380032002D0041003400390035002D003100430044004400360044003800430032004300330031007D0000005C004400650076006900630065005C004E0065007400420054005F00540063007000690070005F007B00320032003300390036003600310032002D0030003000420042002D0034004100340046002D0042003800360044002D003500300043004300320037004100370033004100450031007D0000005C004400650076006900630065005C004E0065007400420054005F00540063007000690070005F007B00320032003300390036003600310032002D0030003000420042002D0034004100340046002D0042003800360044002D003500300043004300320037004100370033004100450031007D0000005C004400650076006900630065005C004E0065007400420054005F00540063007000690070005F007B00430031003000430037003400390035002D0031003500330034002D0034004500440034002D0039003200430039002D003900320030004200450031004600420044003700460046007D0000005C004400650076006900630065005C004E0065007400420054005F00540063007000690070005F007B00430031003000430037003400390035002D0031003500330034002D0034004500440034002D0039003200430039002D003900320030004200450031004600420044003700460046007D0000005C004400650076006900630065005C004E0065007400420054005F00540063007000690070005F007B00380035003700310039003900320035002D0038004500430036002D0034004500430031002D0041004500350036002D003000300041003500300044003400380044003900410037007D0000005C004400650076006900630065005C004E0065007400420054005F00540063007000690070005F007B00380035003700310039003900320035002D0038004500430036002D0034004500430031002D0041004500350036002D003000300041003500300044003400380044003900410037007D0000005C004400650076006900630065005C004E0065007400420054005F00540063007000690070005F007B00300030003900460044004500460034002D0034003800330043002D0034003900430036002D0038003800300044002D003600340045004300320041003800350033003000310033007D0000005C004400650076006900630065005C004E0065007400420054005F00540063007000690070005F007B00300030003900460044004500460034002D0034003800330043002D0034003900430036002D0038003800300044002D003600340045004300320041003800350033003000310033007D0000005C004400650076006900630065005C004E0065007400420054005F00540063007000690070005F007B00300041004400300045004400360031002D0044004600330038002D0034003100360043002D0041004400310036002D004600300038004600380039004100360045004300310041007D0000005C004400650076006900630065005C004E0065007400420054005F00540063007000690070005F007B00300041004400300045004400360031002D0044004600330038002D0034003100360043002D0041004400310036002D004600300038004600380039004100360045004300310041007D000000
- < Value: HKEY_LOCAL_MACHINE\system\controlset001\services\WinSock2\Parameters\NameSpace_Catalog5 Serial_Access_Num REG_DWORD 4 (0x4)
- > Value: HKEY_LOCAL_MACHINE\system\controlset002\services\WinSock2\Parameters\NameSpace_Catalog5 Serial_Access_Num REG_DWORD 9 (0x9)
- < Value: HKEY_LOCAL_MACHINE\system\controlset001\services\WinSock2\Parameters\Protocol_Catalog9 Num_Catalog_Entries REG_DWORD 13 (0xD)
- > Value: HKEY_LOCAL_MACHINE\system\controlset002\services\WinSock2\Parameters\Protocol_Catalog9 Num_Catalog_Entries REG_DWORD 17 (0x11)
- < Value: HKEY_LOCAL_MACHINE\system\controlset001\services\WinSock2\Parameters\Protocol_Catalog9 Next_Catalog_Entry_ID REG_DWORD 1024 (0x400)
- > Value: HKEY_LOCAL_MACHINE\system\controlset002\services\WinSock2\Parameters\Protocol_Catalog9 Next_Catalog_Entry_ID REG_DWORD 1074 (0x432)
- < Value: HKEY_LOCAL_MACHINE\system\controlset001\services\WinSock2\Parameters\Protocol_Catalog9 Serial_Access_Num REG_DWORD 8 (0x8)
- > Value: HKEY_LOCAL_MACHINE\system\controlset002\services\WinSock2\Parameters\Protocol_Catalog9 Serial_Access_Num REG_DWORD 22 (0x16)
- < Value: HKEY_LOCAL_MACHINE\system\controlset001\services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000006 PackedCatalogItem REG_BINARY 2553797374656D526F6F74255C73797374656D33325C6D7377736F636B2E646C6C0000000000000000000000000000000000000000000000000000000000000000000000000000000
FREE TEXT HOST
You can save codes, scripts, sources & general debugging text and share / access / use them at any time (anonymously).You can even set yourself a password if you want to keep it just for yourself.