Comments: |
Datetime:2004/9/29 03:19:01 | 2004/9/29 03:24:08 |
Computer:ZONEALARM | ZONEALARM |
Username: | |
Keys deleted:2 |
HKEY_USERS\S-1-5-21-1659004503-1682526488-839522115-500\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\MSHist012004032420040325 HKEY_USERS\S-1-5-21-1659004503-1682526488-839522115-500\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\MSHist012004032620040327 |
Keys added:5 |
HKEY_USERS\S-1-5-21-1659004503-1682526488-839522115-500\Software\Microsoft\Windows\CurrentVersion\Explorer\ComDlg32\OpenSaveMRU\LOG HKEY_USERS\S-1-5-21-1659004503-1682526488-839522115-500\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.LOG HKEY_USERS\S-1-5-21-1659004503-1682526488-839522115-500\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.LOG\OpenWithList HKEY_USERS\S-1-5-21-1659004503-1682526488-839522115-500\Software\Microsoft\Windows\CurrentVersion\Explorer\RecentDocs\.LOG HKEY_USERS\S-1-5-21-1659004503-1682526488-839522115-500\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\MSHist012004092820040929 |
Values deleted:10 |
HKEY_USERS\S-1-5-21-1659004503-1682526488-839522115-500\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\MSHist012004032420040325\CachePath: "%USERPROFILE%\Local Settings\History\History.IE5\MSHist012004032420040325\" HKEY_USERS\S-1-5-21-1659004503-1682526488-839522115-500\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\MSHist012004032420040325\CachePrefix: ":2004032420040325: " HKEY_USERS\S-1-5-21-1659004503-1682526488-839522115-500\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\MSHist012004032420040325\CacheLimit: 0x00002000 HKEY_USERS\S-1-5-21-1659004503-1682526488-839522115-500\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\MSHist012004032420040325\CacheOptions: 0x0000000B HKEY_USERS\S-1-5-21-1659004503-1682526488-839522115-500\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\MSHist012004032420040325\CacheRepair: 0x00000000 HKEY_USERS\S-1-5-21-1659004503-1682526488-839522115-500\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\MSHist012004032620040327\CachePath: "%USERPROFILE%\Local Settings\History\History.IE5\MSHist012004032620040327\" HKEY_USERS\S-1-5-21-1659004503-1682526488-839522115-500\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\MSHist012004032620040327\CachePrefix: ":2004032620040327: " HKEY_USERS\S-1-5-21-1659004503-1682526488-839522115-500\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\MSHist012004032620040327\CacheLimit: 0x00002000 HKEY_USERS\S-1-5-21-1659004503-1682526488-839522115-500\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\MSHist012004032620040327\CacheOptions: 0x0000000B HKEY_USERS\S-1-5-21-1659004503-1682526488-839522115-500\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\MSHist012004032620040327\CacheRepair: 0x00000000 |
Values added:26 |
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\RaDa: "C:\RaDa\bin\RaDa.exe" HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\SW\{b7eafdc0-a680-11d0-96d8-00aa0051e51d}\{9B365890-165F-11D0-A195-0020AFD156E4}\Control\DeviceReference: 0x81562F10 HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\kmixer\Enum\0: "SW\{b7eafdc0-a680-11d0-96d8-00aa0051e51d}\{9B365890-165F-11D0-A195-0020AFD156E4}" HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\SW\{b7eafdc0-a680-11d0-96d8-00aa0051e51d}\{9B365890-165F-11D0-A195-0020AFD156E4}\Control\DeviceReference: 0x81562F10 HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\kmixer\Enum\0: "SW\{b7eafdc0-a680-11d0-96d8-00aa0051e51d}\{9B365890-165F-11D0-A195-0020AFD156E4}" HKEY_USERS\S-1-5-21-1659004503-1682526488-839522115-500\Software\Microsoft\Windows\CurrentVersion\Explorer\ComDlg32\LastVisitedMRU\c: 52 00 65 00 67 00 6D 00 6F 00 6E 00 2E 00 65 00 78 00 65 00 00 00 43 00 3A 00 5C 00 44 00 6F 00 63 00 75 00 6D 00 65 00 6E 00 74 00 73 00 20 00 61 00 6E 00 64 00 20 00 53 00 65 00 74 00 74 00 69 00 6E 00 67 00 73 00 5C 00 41 00 64 00 6D 00 69 00 6E 00 69 00 73 00 74 00 72 00 61 00 74 00 6F 00 72 00 5C 00 4D 00 79 00 20 00 44 00 6F 00 63 00 75 00 6D 00 65 00 6E 00 74 00 73 00 00 00 HKEY_USERS\S-1-5-21-1659004503-1682526488-839522115-500\Software\Microsoft\Windows\CurrentVersion\Explorer\ComDlg32\LastVisitedMRU\d: 46 00 69 00 6C 00 65 00 6D 00 6F 00 6E 00 2E 00 65 00 78 00 65 00 00 00 43 00 3A 00 5C 00 44 00 6F 00 63 00 75 00 6D 00 65 00 6E 00 74 00 73 00 20 00 61 00 6E 00 64 00 20 00 53 00 65 00 74 00 74 00 69 00 6E 00 67 00 73 00 5C 00 41 00 64 00 6D 00 69 00 6E 00 69 00 73 00 74 00 72 00 61 00 74 00 6F 00 72 00 5C 00 4D 00 79 00 20 00 44 00 6F 00 63 00 75 00 6D 00 65 00 6E 00 74 00 73 00 00 00 HKEY_USERS\S-1-5-21-1659004503-1682526488-839522115-500\Software\Microsoft\Windows\CurrentVersion\Explorer\ComDlg32\OpenSaveMRU\*\f: "C:\Documents and Settings\Administrator\My Documents\Regmon1.LOG" HKEY_USERS\S-1-5-21-1659004503-1682526488-839522115-500\Software\Microsoft\Windows\CurrentVersion\Explorer\ComDlg32\OpenSaveMRU\*\g: "C:\Documents and Settings\Administrator\My Documents\Filemon1.LOG" HKEY_USERS\S-1-5-21-1659004503-1682526488-839522115-500\Software\Microsoft\Windows\CurrentVersion\Explorer\ComDlg32\OpenSaveMRU\LOG\a: "C:\Documents and Settings\Administrator\My Documents\Regmon1.LOG" HKEY_USERS\S-1-5-21-1659004503-1682526488-839522115-500\Software\Microsoft\Windows\CurrentVersion\Explorer\ComDlg32\OpenSaveMRU\LOG\MRUList: "ba" HKEY_USERS\S-1-5-21-1659004503-1682526488-839522115-500\Software\Microsoft\Windows\CurrentVersion\Explorer\ComDlg32\OpenSaveMRU\LOG\b: "C:\Documents and Settings\Administrator\My Documents\Filemon1.LOG" HKEY_USERS\S-1-5-21-1659004503-1682526488-839522115-500\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.LOG\OpenWithList\a: "Regmon.exe" HKEY_USERS\S-1-5-21-1659004503-1682526488-839522115-500\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.LOG\OpenWithList\MRUList: "ba" HKEY_USERS\S-1-5-21-1659004503-1682526488-839522115-500\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.LOG\OpenWithList\b: "Filemon.exe" HKEY_USERS\S-1-5-21-1659004503-1682526488-839522115-500\Software\Microsoft\Windows\CurrentVersion\Explorer\RecentDocs\m: 52 00 65 00 67 00 6D 00 6F 00 6E 00 31 00 2E 00 4C 00 4F 00 47 00 00 00 1F 00 32 00 00 00 00 00 00 00 00 00 00 00 52 65 67 6D 6F 6E 31 2E 4C 4F 47 2E 6C 6E 6B 00 00 00 00 HKEY_USERS\S-1-5-21-1659004503-1682526488-839522115-500\Software\Microsoft\Windows\CurrentVersion\Explorer\RecentDocs\n: 46 00 69 00 6C 00 65 00 6D 00 6F 00 6E 00 31 00 2E 00 4C 00 4F 00 47 00 00 00 20 00 32 00 00 00 00 00 00 00 00 00 00 00 46 69 6C 65 6D 6F 6E 31 2E 4C 4F 47 2E 6C 6E 6B 00 00 00 00 HKEY_USERS\S-1-5-21-1659004503-1682526488-839522115-500\Software\Microsoft\Windows\CurrentVersion\Explorer\RecentDocs\.LOG\a: 52 00 65 00 67 00 6D 00 6F 00 6E 00 31 00 2E 00 4C 00 4F 00 47 00 00 00 1F 00 32 00 00 00 00 00 00 00 00 00 00 00 52 65 67 6D 6F 6E 31 2E 4C 4F 47 2E 6C 6E 6B 00 00 00 00 HKEY_USERS\S-1-5-21-1659004503-1682526488-839522115-500\Software\Microsoft\Windows\CurrentVersion\Explorer\RecentDocs\.LOG\MRUList: "ba" HKEY_USERS\S-1-5-21-1659004503-1682526488-839522115-500\Software\Microsoft\Windows\CurrentVersion\Explorer\RecentDocs\.LOG\b: 46 00 69 00 6C 00 65 00 6D 00 6F 00 6E 00 31 00 2E 00 4C 00 4F 00 47 00 00 00 20 00 32 00 00 00 00 00 00 00 00 00 00 00 46 69 6C 65 6D 6F 6E 31 2E 4C 4F 47 2E 6C 6E 6B 00 00 00 00 HKEY_USERS\S-1-5-21-1659004503-1682526488-839522115-500\Software\Microsoft\Windows\CurrentVersion\Explorer\UserAssist\{75048700-EF1F-11D0-9888-006097DEACF9}\Count\HRZR_EHACNGU:P:\Cebwrpgf\ubarlarg\EnQn.rkr: 08 00 00 00 06 00 00 00 70 22 2C 89 D3 A5 C4 01 HKEY_USERS\S-1-5-21-1659004503-1682526488-839522115-500\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\MSHist012004092820040929\CachePath: "%USERPROFILE%\Local Settings\History\History.IE5\MSHist012004092820040929\" HKEY_USERS\S-1-5-21-1659004503-1682526488-839522115-500\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\MSHist012004092820040929\CachePrefix: ":2004092820040929: " HKEY_USERS\S-1-5-21-1659004503-1682526488-839522115-500\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\MSHist012004092820040929\CacheLimit: 0x00002000 HKEY_USERS\S-1-5-21-1659004503-1682526488-839522115-500\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\MSHist012004092820040929\CacheOptions: 0x0000000B HKEY_USERS\S-1-5-21-1659004503-1682526488-839522115-500\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\MSHist012004092820040929\CacheRepair: 0x00000000 |
Values modified:11 |
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Cryptography\RNG\Seed: 97 0D 19 4E B8 84 A5 88 15 27 67 F3 86 12 91 4C B6 66 95 CC 5C E1 6B F9 26 2B 88 DE E4 8F 46 8D 73 12 C9 50 2D CE 37 78 39 E2 0D 05 19 C0 F2 63 A6 99 CD 02 AA BF DC 35 83 C5 69 EB FC B7 5C 3C 50 6A DB 98 59 37 58 CB 6E AB 82 05 1B 36 56 E4 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Cryptography\RNG\Seed: 14 F3 8E 60 97 F3 85 EF 02 0E D4 18 4E 18 D4 09 AD D6 43 73 50 A8 E7 7E 41 9E 4D B3 B1 4E 49 51 87 23 36 78 D2 08 86 E8 59 B2 4C 9B CC 45 49 9B 0F E9 08 48 D2 FD 62 53 42 28 C9 55 A5 BA 92 E1 FF FF D0 73 39 AD 23 B0 9F 04 1F 44 F1 43 10 91 HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\kmixer\Enum\Count: 0x00000000 HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\kmixer\Enum\Count: 0x00000001 HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\kmixer\Enum\NextInstance: 0x00000000 HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\kmixer\Enum\NextInstance: 0x00000001 HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\kmixer\Enum\Count: 0x00000000 HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\kmixer\Enum\Count: 0x00000001 HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\kmixer\Enum\NextInstance: 0x00000000 HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\kmixer\Enum\NextInstance: 0x00000001 HKEY_USERS\S-1-5-21-1659004503-1682526488-839522115-500\Software\Microsoft\Windows\CurrentVersion\Explorer\ComDlg32\LastVisitedMRU\MRUList: "ab" HKEY_USERS\S-1-5-21-1659004503-1682526488-839522115-500\Software\Microsoft\Windows\CurrentVersion\Explorer\ComDlg32\LastVisitedMRU\MRUList: "dcab" HKEY_USERS\S-1-5-21-1659004503-1682526488-839522115-500\Software\Microsoft\Windows\CurrentVersion\Explorer\ComDlg32\OpenSaveMRU\*\MRUList: "edcba" HKEY_USERS\S-1-5-21-1659004503-1682526488-839522115-500\Software\Microsoft\Windows\CurrentVersion\Explorer\ComDlg32\OpenSaveMRU\*\MRUList: "gfedcba" HKEY_USERS\S-1-5-21-1659004503-1682526488-839522115-500\Software\Microsoft\Windows\CurrentVersion\Explorer\RecentDocs\MRUList: "lkjighfedcba" HKEY_USERS\S-1-5-21-1659004503-1682526488-839522115-500\Software\Microsoft\Windows\CurrentVersion\Explorer\RecentDocs\MRUList: "nmlkjighfedcba" HKEY_USERS\S-1-5-21-1659004503-1682526488-839522115-500\Software\Microsoft\Windows\CurrentVersion\Explorer\StreamMRU\MRUListEx: 0E 00 00 00 0D 00 00 00 0C 00 00 00 16 00 00 00 01 00 00 00 15 00 00 00 1A 00 00 00 00 00 00 00 19 00 00 00 06 00 00 00 11 00 00 00 05 00 00 00 10 00 00 00 0F 00 00 00 12 00 00 00 13 00 00 00 18 00 00 00 17 00 00 00 14 00 00 00 02 00 00 00 0B 00 00 00 0A 00 00 00 08 00 00 00 07 00 00 00 09 00 00 00 04 00 00 00 03 00 00 00 FF FF FF FF HKEY_USERS\S-1-5-21-1659004503-1682526488-839522115-500\Software\Microsoft\Windows\CurrentVersion\Explorer\StreamMRU\MRUListEx: 06 00 00 00 0E 00 00 00 0D 00 00 00 0C 00 00 00 16 00 00 00 01 00 00 00 15 00 00 00 1A 00 00 00 00 00 00 00 19 00 00 00 11 00 00 00 05 00 00 00 10 00 00 00 0F 00 00 00 12 00 00 00 13 00 00 00 18 00 00 00 17 00 00 00 14 00 00 00 02 00 00 00 0B 00 00 00 0A 00 00 00 08 00 00 00 07 00 00 00 09 00 00 00 04 00 00 00 03 00 00 00 FF FF FF FF HKEY_USERS\S-1-5-21-1659004503-1682526488-839522115-500\Software\Microsoft\Windows\CurrentVersion\Explorer\UserAssist\{75048700-EF1F-11D0-9888-006097DEACF9}\Count\HRZR_EHACNGU: 08 00 00 00 3F 00 00 00 90 4F A9 47 D2 A5 C4 01 HKEY_USERS\S-1-5-21-1659004503-1682526488-839522115-500\Software\Microsoft\Windows\CurrentVersion\Explorer\UserAssist\{75048700-EF1F-11D0-9888-006097DEACF9}\Count\HRZR_EHACNGU: 08 00 00 00 40 00 00 00 20 B0 DF 88 D3 A5 C4 01 HKEY_USERS\S-1-5-21-1659004503-1682526488-839522115-500\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Connections\SavedLegacySettings: 3C 00 00 00 31 00 00 00 01 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 01 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 HKEY_USERS\S-1-5-21-1659004503-1682526488-839522115-500\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Connections\SavedLegacySettings: 3C 00 00 00 32 00 00 00 01 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 01 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 |
Total changes:54 |