Spora/Dump Masquerades as “Microsoft Protection Service” to Evade Detection


Zero‑Dwell Threat Intelligence Report

A narrative, executive‑ready view into the malware’s behavior, exposure, and reliable defenses.
Generated: 2025-11-20 08:33:40 UTC

Executive Overview — What We’re Dealing With

This specimen has persisted long enough to matter. Human experts classified it as Malware, and the telemetry confirms a capable, evasive Trojan with real impact potential.

File
jruhvy6m2.exe
Type
Win64 Executable (generic)
SHA‑1
3364f0f6434961cdc27ec031ebcb804a14dd98c7
MD5
f3416579d086772ac64e76c0fa3ee566
First Seen
2025-11-14 19:52:06.727896
Last Analysis
2025-11-15 20:48:14.348612
Dwell Time
0 days, 7 hours, 33 minutes

Extended Dwell Time Impact

For 1+ days, this malware remained undetected — a brief but concerning window that permitted the adversary to establish initial foothold, perform basic system enumeration, and potentially access immediate system resources.

Comparative Context

Industry studies report a median dwell time closer to 21–24 days. This case is significantly below that median, suggesting relatively quick detection.

Timeline

Time (UTC) Event Elapsed
2021-11-07 15:44:44 UTC First VirusTotal submission
2025-11-19 12:43:25 UTC Latest analysis snapshot 1472 days, 20 hours, 58 minutes
2025-11-20 08:33:40 UTC Report generation time 1473 days, 16 hours, 48 minutes

Why It Matters

Every additional day of dwell time is not just an abstract number — it is attacker opportunity. Each day equates to more time for lateral movement, stealth persistence, and intelligence gathering.

Global Detection Posture — Who Caught It, Who Missed It

VirusTotal engines: 73. Detected as malicious: 56. Missed: 17. Coverage: 76.7%.

Detected Vendors

  • Xcitium
  • +55 additional vendors (names not provided)

List includes Xcitium plus an additional 55 vendors per the provided summary.

Missed Vendors

  • Acronis
  • Antiy-AVL
  • APEX
  • Baidu
  • ClamAV
  • CMC
  • google_safebrowsing
  • Gridinsoft
  • NANO-Antivirus
  • SUPERAntiSpyware
  • TACHYON
  • tehtris
  • TrendMicro
  • VirIT
  • Yandex
  • ZoneAlarm
  • Zoner

Why it matters: if any endpoint relies solely on a missed engine, this malware can operate with zero alerts. Prevention‑first controls close that gap regardless of signature lag.

Behavioral Storyline — How the Malware Operates

Intensive file system activity (47.84% of behavior) indicates data harvesting, file encryption, or dropper behavior. The threat is actively searching for and manipulating files across the system.

Behavior Categories (weighted)

Weight values represent the frequency and intensity of malware interactions with specific system components. Higher weights indicate more aggressive targeting of that category. Each operation (registry access, file modification, network connection, etc.) contributes to the category’s total weight, providing a quantitative measure of the malware’s behavioral focus.

Category Weight Percentage
File System 171870 47.84%
Synchronization 166739 46.42%
Registry 10600 2.95%
System 6909 1.92%
Process 1851 0.52%
Com 548 0.15%
Misc 307 0.09%
Windows 129 0.04%
Device 106 0.03%
Threading 96 0.03%
Hooking 34 0.01%
Network 26 0.01%
Services 7 0.00%
Crypto 4 0.00%
__Notification__ 1 0.00%

MITRE ATT&CK Mapping

  • No MITRE ATT&CK techniques detected

Following the Trail — Network & DNS Activity

Outbound activity leans on reputable infrastructure (e.g., CDNs, cloud endpoints) to blend in. TLS sessions and
HTTP calls show routine beaconing and IP‑lookup behavior that can masquerade as normal browsing.

Contacted Domains

Domain IP Country ASN/Org
www.aieov.com 76.223.54.146 United States Amazon.com, Inc.
www.msftncsi.com 23.200.3.18 United States Akamai Technologies, Inc.
resolver1.opendns.com 208.67.222.222 United States Cisco OpenDNS, LLC

Observed IPs

IP Country ASN/Org
224.0.0.252
239.255.255.250
8.8.4.4 United States Google LLC
8.8.8.8 United States Google LLC

DNS Queries

Request Type
5isohu.com A
www.msftncsi.com A
www.aieov.com A
resolver1.opendns.com A
4.4.8.8.in-addr.arpa PTR
myip.opendns.com A
myip.opendns.com AAAA

Contacted IPs

IP Country ASN/Org
224.0.0.252
239.255.255.250
8.8.4.4 United States Google LLC
8.8.8.8 United States Google LLC

Port Distribution

Port Count Protocols
137 1 udp
5355 5 udp
53 37 udp
3702 1 udp

UDP Packets

Source IP Dest IP Sport Dport Time Proto
192.168.56.13 192.168.56.255 137 137 3.244752883911133 udp
192.168.56.13 224.0.0.252 49311 5355 5.747757911682129 udp
192.168.56.13 224.0.0.252 55150 5355 3.184664011001587 udp
192.168.56.13 224.0.0.252 60010 5355 5.184438943862915 udp
192.168.56.13 224.0.0.252 62406 5355 3.1941890716552734 udp
192.168.56.13 224.0.0.252 63527 5355 4.629860877990723 udp
192.168.56.13 239.255.255.250 52252 3702 3.2008490562438965 udp
192.168.56.13 8.8.4.4 50554 53 86.72818899154663 udp
192.168.56.13 8.8.4.4 53518 53 182.6036570072174 udp
192.168.56.13 8.8.4.4 54879 53 7.7599570751190186 udp
192.168.56.13 8.8.4.4 54881 53 7.196667909622192 udp
192.168.56.13 8.8.4.4 55551 53 120.60324907302856 udp
192.168.56.13 8.8.4.4 56197 53 102.82232689857483 udp
192.168.56.13 8.8.4.4 57310 53 55.07249402999878 udp
192.168.56.13 8.8.4.4 57415 53 56.759437084198 udp
192.168.56.13 8.8.4.4 57416 53 66.33703994750977 udp
192.168.56.13 8.8.4.4 58697 53 22.649830102920532 udp
192.168.56.13 8.8.4.4 58920 53 68.24414587020874 udp
192.168.56.13 8.8.4.4 58921 53 68.3225679397583 udp
192.168.56.13 8.8.4.4 58922 53 70.32180905342102 udp
192.168.56.13 8.8.4.4 60543 53 168.1190230846405 udp
192.168.56.13 8.8.4.4 60910 53 71.69696497917175 udp
192.168.56.13 8.8.4.4 61004 53 135.04109692573547 udp
192.168.56.13 8.8.4.4 62493 53 53.368967056274414 udp
192.168.56.13 8.8.4.4 62849 53 37.10322308540344 udp
192.168.56.13 8.8.4.4 64533 53 149.63427686691284 udp
192.168.56.13 8.8.4.4 64801 53 83.75916194915771 udp
192.168.56.13 8.8.8.8 50554 53 85.74088501930237 udp
192.168.56.13 8.8.8.8 53518 53 181.6039810180664 udp
192.168.56.13 8.8.8.8 54879 53 8.759646892547607 udp
192.168.56.13 8.8.8.8 54881 53 8.181238889694214 udp
192.168.56.13 8.8.8.8 55551 53 119.60402202606201 udp
192.168.56.13 8.8.8.8 56197 53 101.82339191436768 udp
192.168.56.13 8.8.8.8 57310 53 54.084572076797485 udp
192.168.56.13 8.8.8.8 57415 53 55.76191997528076 udp
192.168.56.13 8.8.8.8 58697 53 21.65479803085327 udp
192.168.56.13 8.8.8.8 58920 53 67.25343298912048 udp
192.168.56.13 8.8.8.8 60543 53 167.11957502365112 udp
192.168.56.13 8.8.8.8 60910 53 70.70318508148193 udp
192.168.56.13 8.8.8.8 61004 53 134.04153108596802 udp
192.168.56.13 8.8.8.8 62493 53 52.37572503089905 udp
192.168.56.13 8.8.8.8 62849 53 36.114598989486694 udp
192.168.56.13 8.8.8.8 64533 53 148.63521003723145 udp
192.168.56.13 8.8.8.8 64801 53 82.77245688438416 udp

Hunting tip: alert on unknown binaries initiating TLS to IP‑lookup services or unusual CDN endpoints — especially early in execution.

Persistence & Policy — Registry and Services

Registry and service telemetry points to policy awareness and environment reconnaissance rather than noisy persistence. Below is a compact view of the most relevant keys and handles; expand to see the full lists where available.

Registry Opened

357

Registry Set

208

Services Started

0

Services Opened

0

Registry Opened (Top 25)

Key
\Registry\Machine\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\996E.exe
\Registry\MACHINE\System\CurrentControlSet\Control\SafeBoot\Option
\Registry\Machine\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers
\REGISTRY\MACHINE\SOFTWARE\Policies\Microsoft\Windows\Safer\CodeIdentifiers\TransparentEnabled
\REGISTRY\USER\S-1-5-21-1482476501-1645522239-1417001333-500\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers
\Registry\Machine\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\SHELL32.dll
\Registry\Machine\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\comctl32.dll
\Registry\Machine\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\ntdll.dll
\Registry\Machine\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\KERNEL32.dll
\Registry\Machine\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\GDI32.dll
\Registry\Machine\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\USER32.dll
\Registry\Machine\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\Secur32.dll
\Registry\Machine\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\RPCRT4.dll
\Registry\Machine\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\ADVAPI32.dll
\Registry\Machine\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\msvcrt.dll
\Registry\Machine\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\WS2HELP.dll
\Registry\Machine\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\WS2_32.dll
\Registry\Machine\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\SHLWAPI.dll
\Registry\Machine\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\PSAPI.DLL
\Registry\Machine\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\ole32.dll
\Registry\Machine\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\OLEAUT32.dll
\Registry\Machine\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\winime32.dll
\Registry\Machine\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\IMM32.DLL
\Registry\Machine\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\USP10.dll
\Registry\Machine\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\LPK.DLL
\Registry\Machine\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\NETAPI32.dll
\Registry\Machine\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\rsaenh.dll
\REGISTRY\MACHINE\Software\Policies\Microsoft\Cryptography
\Registry\Machine\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\MSCTF.dll
\Registry\MACHINE\System\CurrentControlSet\Control\Session Manager\AppCertDlls
\Registry\Machine\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\Apphelp.dll
\Registry\Machine\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\VERSION.dll
\REGISTRY\MACHINE\SOFTWARE\Policies\Microsoft\Windows\Safer\CodeIdentifiers\AuthenticodeEnabled
\Registry\Machine\Software\Policies\Microsoft\Windows\Safer\LevelObjects
\REGISTRY\MACHINE\SOFTWARE\Policies\Microsoft\Windows\Safer\CodeIdentifiers\Levels
\Registry\Machine\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Paths
\REGISTRY\MACHINE\SOFTWARE\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Paths\{dda3f824-d8cb-441b-834d-be2efd2c1a33}
\REGISTRY\MACHINE\SOFTWARE\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Paths\{dda3f824-d8cb-441b-834d-be2efd2c1a33}\ItemData
\REGISTRY\MACHINE\SOFTWARE\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Paths\{dda3f824-d8cb-441b-834d-be2efd2c1a33}\SaferFlags
\Registry\Machine\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Hashes
\REGISTRY\MACHINE\SOFTWARE\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Hashes\{349d35ab-37b5-462f-9b89-edd5fbde1328}
\REGISTRY\MACHINE\SOFTWARE\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Hashes\{349d35ab-37b5-462f-9b89-edd5fbde1328}\ItemData
\REGISTRY\MACHINE\SOFTWARE\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Hashes\{349d35ab-37b5-462f-9b89-edd5fbde1328}\HashAlg
\REGISTRY\MACHINE\SOFTWARE\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Hashes\{349d35ab-37b5-462f-9b89-edd5fbde1328}\ItemSize
\REGISTRY\MACHINE\SOFTWARE\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Hashes\{349d35ab-37b5-462f-9b89-edd5fbde1328}\SaferFlags
\REGISTRY\MACHINE\SOFTWARE\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Hashes\{7fb9cd2e-3076-4df9-a57b-b813f72dbb91}
\REGISTRY\MACHINE\SOFTWARE\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Hashes\{7fb9cd2e-3076-4df9-a57b-b813f72dbb91}\ItemData
\REGISTRY\MACHINE\SOFTWARE\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Hashes\{7fb9cd2e-3076-4df9-a57b-b813f72dbb91}\HashAlg
\REGISTRY\MACHINE\SOFTWARE\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Hashes\{7fb9cd2e-3076-4df9-a57b-b813f72dbb91}\ItemSize
\REGISTRY\MACHINE\SOFTWARE\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Hashes\{7fb9cd2e-3076-4df9-a57b-b813f72dbb91}\SaferFlags
Show all (357 total)
Key
\REGISTRY\MACHINE\SOFTWARE\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Hashes\{81d1fe15-dd9d-4762-b16d-7c29ddecae3f}
\REGISTRY\MACHINE\SOFTWARE\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Hashes\{81d1fe15-dd9d-4762-b16d-7c29ddecae3f}\ItemData
\REGISTRY\MACHINE\SOFTWARE\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Hashes\{81d1fe15-dd9d-4762-b16d-7c29ddecae3f}\HashAlg
\REGISTRY\MACHINE\SOFTWARE\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Hashes\{81d1fe15-dd9d-4762-b16d-7c29ddecae3f}\ItemSize
\REGISTRY\MACHINE\SOFTWARE\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Hashes\{81d1fe15-dd9d-4762-b16d-7c29ddecae3f}\SaferFlags
\REGISTRY\MACHINE\SOFTWARE\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Hashes\{94e3e076-8f53-42a5-8411-085bcc18a68d}
\REGISTRY\MACHINE\SOFTWARE\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Hashes\{94e3e076-8f53-42a5-8411-085bcc18a68d}\ItemData
\REGISTRY\MACHINE\SOFTWARE\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Hashes\{94e3e076-8f53-42a5-8411-085bcc18a68d}\HashAlg
\REGISTRY\MACHINE\SOFTWARE\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Hashes\{94e3e076-8f53-42a5-8411-085bcc18a68d}\ItemSize
\REGISTRY\MACHINE\SOFTWARE\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Hashes\{94e3e076-8f53-42a5-8411-085bcc18a68d}\SaferFlags
\REGISTRY\MACHINE\SOFTWARE\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Hashes\{dc971ee5-44eb-4fe4-ae2e-b91490411bfc}
\REGISTRY\MACHINE\SOFTWARE\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Hashes\{dc971ee5-44eb-4fe4-ae2e-b91490411bfc}\ItemData
\REGISTRY\MACHINE\SOFTWARE\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Hashes\{dc971ee5-44eb-4fe4-ae2e-b91490411bfc}\HashAlg
\REGISTRY\MACHINE\SOFTWARE\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Hashes\{dc971ee5-44eb-4fe4-ae2e-b91490411bfc}\ItemSize
\REGISTRY\MACHINE\SOFTWARE\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Hashes\{dc971ee5-44eb-4fe4-ae2e-b91490411bfc}\SaferFlags
\Registry\Machine\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\UrlZones
\Registry\Machine\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\4096\Paths
\Registry\Machine\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\4096\Hashes
\Registry\Machine\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\4096\UrlZones
\Registry\Machine\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\65536\Paths
\Registry\Machine\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\65536\Hashes
\Registry\Machine\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\65536\UrlZones
\Registry\Machine\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\131072\Paths
\Registry\Machine\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\131072\Hashes
\Registry\Machine\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\131072\UrlZones
\Registry\Machine\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\262144\Paths
\Registry\Machine\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\262144\Hashes
\Registry\Machine\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\262144\UrlZones
\REGISTRY\USER\S-1-5-21-1482476501-1645522239-1417001333-500\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Paths
\REGISTRY\USER\S-1-5-21-1482476501-1645522239-1417001333-500\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Hashes
\REGISTRY\USER\S-1-5-21-1482476501-1645522239-1417001333-500\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\UrlZones
\REGISTRY\USER\S-1-5-21-1482476501-1645522239-1417001333-500\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\4096\Paths
\REGISTRY\USER\S-1-5-21-1482476501-1645522239-1417001333-500\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\4096\Hashes
\REGISTRY\USER\S-1-5-21-1482476501-1645522239-1417001333-500\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\4096\UrlZones
\REGISTRY\USER\S-1-5-21-1482476501-1645522239-1417001333-500\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\65536\Paths
\REGISTRY\USER\S-1-5-21-1482476501-1645522239-1417001333-500\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\65536\Hashes
\REGISTRY\USER\S-1-5-21-1482476501-1645522239-1417001333-500\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\65536\UrlZones
\REGISTRY\USER\S-1-5-21-1482476501-1645522239-1417001333-500\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\131072\Paths
\REGISTRY\USER\S-1-5-21-1482476501-1645522239-1417001333-500\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\131072\Hashes
\REGISTRY\USER\S-1-5-21-1482476501-1645522239-1417001333-500\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\131072\UrlZones
\REGISTRY\USER\S-1-5-21-1482476501-1645522239-1417001333-500\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\262144\Paths
\REGISTRY\USER\S-1-5-21-1482476501-1645522239-1417001333-500\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\262144\Hashes
\REGISTRY\USER\S-1-5-21-1482476501-1645522239-1417001333-500\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\262144\UrlZones
\REGISTRY\MACHINE\SOFTWARE\Policies\Microsoft\Windows\Safer\CodeIdentifiers\DefaultLevel
\REGISTRY\MACHINE\SOFTWARE\Policies\Microsoft\Windows\Safer\CodeIdentifiers\PolicyScope
\REGISTRY\USER\S-1-5-21-1482476501-1645522239-1417001333-500\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders\Cache
\REGISTRY\MACHINE\SOFTWARE\Policies\Microsoft\Windows\Safer\CodeIdentifiers\LogFileName
\Registry\Machine\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\cmd.exe
\REGISTRY\USER\S-1-5-21-1482476501-1645522239-1417001333-500\Software\Policies\Microsoft\Windows\System
\REGISTRY\MACHINE\SOFTWARE\Microsoft\Command Processor\AutoRun
\Registry\Machine\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\tasklist.exe
\REGISTRY\MACHINE\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers
\Registry\Machine\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\findstr.exe
\REGISTRY\MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\tasklist.exe\RpcThreadPoolThrottle
\REGISTRY\MACHINE\Software\Policies\Microsoft\Windows NT\Rpc
\Registry\Machine\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\COMRes.dll
\Registry\Machine\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\CLBCATQ.DLL
\Registry\Machine\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\xpsp2res.dll
\Registry\Machine\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\wbemcomn.dll
\Registry\Machine\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\wbemprox.dll
\Registry\Machine\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\Winsta.dll
\Registry\Machine\Software\Policies\Microsoft\System\DNSclient
\Registry\Machine\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\wbemsvc.dll
\Registry\Machine\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\MSVCP60.dll
\Registry\Machine\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\DNSAPI.dll
\REGISTRY\MACHINE\Software\Policies\Microsoft\Windows NT\DnsClient
\Registry\Machine\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\WLDAP32.dll
\Registry\Machine\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\NTDSAPI.dll
\Registry\Machine\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\fastprox.dll
\REGISTRY\MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\findstr.exe\RpcThreadPoolThrottle
\REGISTRY\MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\cmd.exe\RpcThreadPoolThrottle
\Registry\Machine\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\netapi32.dll
\REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\NoInternetIcon
\REGISTRY\USER\S-1-5-21-1482476501-1645522239-1417001333-500\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\NoInternetIcon
\REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\NoControlPanel
\REGISTRY\USER\S-1-5-21-1482476501-1645522239-1417001333-500\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\NoControlPanel
\REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\NoSetFolders
\REGISTRY\USER\S-1-5-21-1482476501-1645522239-1417001333-500\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\NoSetFolders
\REGISTRY\USER\S-1-5-21-1482476501-1645522239-1417001333-500\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Hidden
\REGISTRY\USER\S-1-5-21-1482476501-1645522239-1417001333-500\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced\HideFileExt
\REGISTRY\USER\S-1-5-21-1482476501-1645522239-1417001333-500\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced\ShowSuperHidden
\REGISTRY\USER\S-1-5-21-1482476501-1645522239-1417001333-500\Software\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders\Personal
\Registry\Machine\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\SETUPAPI.dll
\REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders\Common Documents
\REGISTRY\USER\S-1-5-21-1482476501-1645522239-1417001333-500\Software\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders\Desktop
\REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders\Common Desktop
\REGISTRY\USER\S-1-5-21-1482476501-1645522239-1417001333-500_CLASSES\.exe
\Registry\Machine\Software\Classes\.exe
\REGISTRY\USER\S-1-5-21-1482476501-1645522239-1417001333-500_Classes\.exe
\REGISTRY\USER\S-1-5-21-1482476501-1645522239-1417001333-500_CLASSES\.lnk
\Registry\Machine\Software\Classes\.lnk
\REGISTRY\USER\S-1-5-21-1482476501-1645522239-1417001333-500_Classes\.lnk
\Registry\Machine\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\urlmon.dll
\REGISTRY\USER\S-1-5-21-1482476501-1645522239-1417001333-500\SOFTWARE\Policies\Microsoft\Windows\CurrentVersion\Internet Settings
\REGISTRY\MACHINE\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\
\REGISTRY\MACHINE\SOFTWARE\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Security_HKLM_only
\REGISTRY\USER\S-1-5-21-1482476501-1645522239-1417001333-500\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\
\REGISTRY\MACHINE\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\
\REGISTRY\USER\S-1-5-21-1482476501-1645522239-1417001333-500\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Ranges\
\REGISTRY\MACHINE\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Ranges\
\REGISTRY\MACHINE\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings
\REGISTRY\MACHINE\Software\Policies\Microsoft\Internet Explorer\Main\FeatureControl
\REGISTRY\USER\S-1-5-21-1482476501-1645522239-1417001333-500\Software\Policies\Microsoft\Internet Explorer\Main\FeatureControl
\REGISTRY\USER\S-1-5-21-1482476501-1645522239-1417001333-500\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\
\REGISTRY\MACHINE\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\
\REGISTRY\USER\S-1-5-21-1482476501-1645522239-1417001333-500\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\
\REGISTRY\MACHINE\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\
\REGISTRY\USER\S-1-5-21-1482476501-1645522239-1417001333-500\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\0
\REGISTRY\MACHINE\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\0
\REGISTRY\USER\S-1-5-21-1482476501-1645522239-1417001333-500\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\1
\REGISTRY\MACHINE\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\1
\REGISTRY\USER\S-1-5-21-1482476501-1645522239-1417001333-500\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\2
\REGISTRY\MACHINE\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\2
\REGISTRY\USER\S-1-5-21-1482476501-1645522239-1417001333-500\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\3
\REGISTRY\MACHINE\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\3
\REGISTRY\USER\S-1-5-21-1482476501-1645522239-1417001333-500\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\4
\REGISTRY\MACHINE\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\4
\REGISTRY\USER\S-1-5-21-1482476501-1645522239-1417001333-500\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Lockdown_Zones\
\REGISTRY\MACHINE\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Lockdown_Zones\
\REGISTRY\USER\S-1-5-21-1482476501-1645522239-1417001333-500\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Lockdown_Zones\0
\REGISTRY\MACHINE\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Lockdown_Zones\0
\REGISTRY\USER\S-1-5-21-1482476501-1645522239-1417001333-500\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Lockdown_Zones\1
\REGISTRY\MACHINE\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Lockdown_Zones\1
\REGISTRY\USER\S-1-5-21-1482476501-1645522239-1417001333-500\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Lockdown_Zones\2
\REGISTRY\MACHINE\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Lockdown_Zones\2
\REGISTRY\USER\S-1-5-21-1482476501-1645522239-1417001333-500\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Lockdown_Zones\3
\REGISTRY\MACHINE\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Lockdown_Zones\3
\REGISTRY\USER\S-1-5-21-1482476501-1645522239-1417001333-500\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Lockdown_Zones\4
\REGISTRY\MACHINE\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Lockdown_Zones\4
\REGISTRY\USER\S-1-5-21-1482476501-1645522239-1417001333-500\Software\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders\Cache
\REGISTRY\USER\S-1-5-21-1482476501-1645522239-1417001333-500\Software\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders\Cookies
\REGISTRY\MACHINE\SOFTWARE\Policies\Microsoft\Windows\Safer\CodeIdentifiers\ExecutableTypes
\REGISTRY\USER\S-1-5-21-1482476501-1645522239-1417001333-500_Classes\VBSFile\Shell\Open\command
\REGISTRY\MACHINE\SOFTWARE\Classes\VBSFile\Shell\Open\command
\REGISTRY\USER\S-1-5-21-1482476501-1645522239-1417001333-500\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\RestrictRun
\REGISTRY\USER\S-1-5-21-1482476501-1645522239-1417001333-500_Classes\VBSFile\Shell\Open\Command
\REGISTRY\MACHINE\SOFTWARE\Classes\VBSFile\Shell\Open\Command\command
\REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\RestrictRun
\REGISTRY\USER\S-1-5-21-1482476501-1645522239-1417001333-500\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\DisallowRun
\Registry\Machine\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\WScript.exe
\REGISTRY\MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\WScript.exe\RpcThreadPoolThrottle
\Registry\Machine\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\SXS.DLL
\REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\IMM\Ime File
\Registry\Machine\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\msctfime.ime
\Registry\Machine\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\vbscript.dll
\Registry\Machine\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\schtasks.exe
\Registry\Machine\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\MSASN1.dll
\Registry\Machine\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\CRYPT32.dll
\Registry\Machine\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\IMAGEHLP.dll
\Registry\Machine\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\WINTRUST.dll
\REGISTRY\MACHINE\Software\Policies\Microsoft\SystemCertificates\TrustedPublisher\Safer
\REGISTRY\USER\S-1-5-21-1482476501-1645522239-1417001333-500\Software\Policies\Microsoft\SystemCertificates\TrustedPublisher\Safer
\Registry\Machine\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\MSISIP.DLL
\Registry\Machine\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\wshext.dll
\Registry\Machine\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\scrobj.dll
\REGISTRY\MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\schtasks.exe\RpcThreadPoolThrottle
\Registry\Machine\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\MPR.dll
\Registry\Machine\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\ScrRun.dll
\Registry\Machine\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\wshom.ocx
\Registry\Machine\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\nslookup.exe
\REGISTRY\MACHINE\System\CurrentControlSet\Services\WinSock2\Parameters
\REGISTRY\MACHINE\SYSTEM\ControlSet002\Services\WinSock2\Parameters\WinSock_Registry_Version
\REGISTRY\MACHINE\SYSTEM\ControlSet002\Services\WinSock2\Parameters\Protocol_Catalog9
\REGISTRY\MACHINE\SYSTEM\ControlSet002\Services\WinSock2\Parameters\Protocol_Catalog9\Serial_Access_Num
\REGISTRY\MACHINE\SYSTEM\ControlSet002\Services\WinSock2\Parameters\Protocol_Catalog9\00000007
\REGISTRY\MACHINE\SYSTEM\ControlSet002\Services\WinSock2\Parameters\Protocol_Catalog9\Next_Catalog_Entry_ID
\REGISTRY\MACHINE\SYSTEM\ControlSet002\Services\WinSock2\Parameters\Protocol_Catalog9\Num_Catalog_Entries
\REGISTRY\MACHINE\SYSTEM\ControlSet002\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries
\REGISTRY\MACHINE\SYSTEM\ControlSet002\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000001
\REGISTRY\MACHINE\SYSTEM\ControlSet002\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000001\PackedCatalogItem
\REGISTRY\MACHINE\SYSTEM\ControlSet002\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000002
\REGISTRY\MACHINE\SYSTEM\ControlSet002\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000002\PackedCatalogItem
\REGISTRY\MACHINE\SYSTEM\ControlSet002\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000003
\REGISTRY\MACHINE\SYSTEM\ControlSet002\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000003\PackedCatalogItem
\REGISTRY\MACHINE\SYSTEM\ControlSet002\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000004
\REGISTRY\MACHINE\SYSTEM\ControlSet002\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000004\PackedCatalogItem
\REGISTRY\MACHINE\SYSTEM\ControlSet002\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000005
\REGISTRY\MACHINE\SYSTEM\ControlSet002\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000005\PackedCatalogItem
\REGISTRY\MACHINE\SYSTEM\ControlSet002\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000006
\REGISTRY\MACHINE\SYSTEM\ControlSet002\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000006\PackedCatalogItem
\REGISTRY\MACHINE\SYSTEM\ControlSet002\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000007
\REGISTRY\MACHINE\SYSTEM\ControlSet002\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000007\PackedCatalogItem
\REGISTRY\MACHINE\SYSTEM\ControlSet002\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000008
\REGISTRY\MACHINE\SYSTEM\ControlSet002\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000008\PackedCatalogItem
\REGISTRY\MACHINE\SYSTEM\ControlSet002\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000009
\REGISTRY\MACHINE\SYSTEM\ControlSet002\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000009\PackedCatalogItem
\REGISTRY\MACHINE\SYSTEM\ControlSet002\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000010
\REGISTRY\MACHINE\SYSTEM\ControlSet002\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000010\PackedCatalogItem
\REGISTRY\MACHINE\SYSTEM\ControlSet002\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000011
\REGISTRY\MACHINE\SYSTEM\ControlSet002\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000011\PackedCatalogItem
\REGISTRY\MACHINE\SYSTEM\ControlSet002\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000012
\REGISTRY\MACHINE\SYSTEM\ControlSet002\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000012\PackedCatalogItem
\REGISTRY\MACHINE\SYSTEM\ControlSet002\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000013
\REGISTRY\MACHINE\SYSTEM\ControlSet002\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000013\PackedCatalogItem
\REGISTRY\MACHINE\SYSTEM\ControlSet002\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000014
\REGISTRY\MACHINE\SYSTEM\ControlSet002\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000014\PackedCatalogItem
\REGISTRY\MACHINE\SYSTEM\ControlSet002\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000015
\REGISTRY\MACHINE\SYSTEM\ControlSet002\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000015\PackedCatalogItem
\REGISTRY\MACHINE\SYSTEM\ControlSet002\Services\WinSock2\Parameters\NameSpace_Catalog5
\REGISTRY\MACHINE\SYSTEM\ControlSet002\Services\WinSock2\Parameters\NameSpace_Catalog5\Serial_Access_Num
\REGISTRY\MACHINE\SYSTEM\ControlSet002\Services\WinSock2\Parameters\NameSpace_Catalog5\00000004
\REGISTRY\MACHINE\SYSTEM\ControlSet002\Services\WinSock2\Parameters\NameSpace_Catalog5\Num_Catalog_Entries
\REGISTRY\MACHINE\SYSTEM\ControlSet002\Services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries
\REGISTRY\MACHINE\SYSTEM\ControlSet002\Services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000001
\REGISTRY\MACHINE\SYSTEM\ControlSet002\Services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000001\LibraryPath
\REGISTRY\MACHINE\SYSTEM\ControlSet002\Services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000001\DisplayString
\REGISTRY\MACHINE\SYSTEM\ControlSet002\Services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000001\ProviderId
\REGISTRY\MACHINE\SYSTEM\ControlSet002\Services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000001\AddressFamily
\REGISTRY\MACHINE\SYSTEM\ControlSet002\Services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000001\SupportedNameSpace
\REGISTRY\MACHINE\SYSTEM\ControlSet002\Services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000001\Enabled
\REGISTRY\MACHINE\SYSTEM\ControlSet002\Services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000001\Version
\REGISTRY\MACHINE\SYSTEM\ControlSet002\Services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000001\StoresServiceClassInfo
\REGISTRY\MACHINE\SYSTEM\ControlSet002\Services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000002
\REGISTRY\MACHINE\SYSTEM\ControlSet002\Services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000002\LibraryPath
\REGISTRY\MACHINE\SYSTEM\ControlSet002\Services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000002\DisplayString
\REGISTRY\MACHINE\SYSTEM\ControlSet002\Services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000002\ProviderId
\REGISTRY\MACHINE\SYSTEM\ControlSet002\Services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000002\AddressFamily
\REGISTRY\MACHINE\SYSTEM\ControlSet002\Services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000002\SupportedNameSpace
\REGISTRY\MACHINE\SYSTEM\ControlSet002\Services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000002\Enabled
\REGISTRY\MACHINE\SYSTEM\ControlSet002\Services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000002\Version
\REGISTRY\MACHINE\SYSTEM\ControlSet002\Services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000002\StoresServiceClassInfo
\REGISTRY\MACHINE\SYSTEM\ControlSet002\Services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000003
\REGISTRY\MACHINE\SYSTEM\ControlSet002\Services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000003\LibraryPath
\REGISTRY\MACHINE\SYSTEM\ControlSet002\Services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000003\DisplayString
\REGISTRY\MACHINE\SYSTEM\ControlSet002\Services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000003\ProviderId
\REGISTRY\MACHINE\SYSTEM\ControlSet002\Services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000003\AddressFamily
\REGISTRY\MACHINE\SYSTEM\ControlSet002\Services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000003\SupportedNameSpace
\REGISTRY\MACHINE\SYSTEM\ControlSet002\Services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000003\Enabled
\REGISTRY\MACHINE\SYSTEM\ControlSet002\Services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000003\Version
\REGISTRY\MACHINE\SYSTEM\ControlSet002\Services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000003\StoresServiceClassInfo
\REGISTRY\MACHINE\System\CurrentControlSet\Services\Winsock2\Parameters
\REGISTRY\MACHINE\SYSTEM\ControlSet002\Services\WinSock2\Parameters\Ws2_32NumHandleBuckets
\REGISTRY\MACHINE\SYSTEM\ControlSet002\Services\WinSock2\Parameters\Ws2_32SpinCount
\Registry\Machine\Software\Policies\Microsoft\Windows NT\DNSClient
\REGISTRY\MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\nslookup.exe\RpcThreadPoolThrottle
\Registry\Machine\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\iphlpapi.dll
\REGISTRY\MACHINE\SYSTEM\ControlSet002\Services\Tcpip\Parameters\Interfaces\{8C6B73CA-C00B-4864-99FA-12B90E0F122A}\DhcpServer
\REGISTRY\MACHINE\Software\Policies\Microsoft\System\DNSClient
\Registry\Machine\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\winrnr.dll
\Registry\Machine\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\hnetcfg.dll
\REGISTRY\MACHINE\SOFTWARE\Microsoft\Rpc\SecurityService\DefaultAuthLevel
\REGISTRY\MACHINE\SYSTEM\ControlSet002\Services\Winsock\Parameters\Transports
\REGISTRY\MACHINE\SYSTEM\ControlSet002\Services\Tcpip\Parameters\Winsock\HelperDllName
\Registry\Machine\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\wshtcpip.dll
\REGISTRY\USER\S-1-5-21-1482476501-1645522239-1417001333-500_Classes\batfile\shell\open\command
\REGISTRY\MACHINE\SOFTWARE\Classes\batfile\shell\open\command
\REGISTRY\MACHINE\SOFTWARE\Classes\batfile\shell\open\command\command
\Registry\Machine\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\find.exe
\Registry\Machine\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\systeminfo.exe
\REGISTRY\MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\systeminfo.exe\RpcThreadPoolThrottle
HKLM\Software\Microsoft\WBEM\CIMOM
HKLM\Software\Microsoft\WBEM\CIMOM\ProcessID
HKLM\Software\Microsoft\WBEM\CIMOM\EnablePrivateObjectHeap
HKLM\Software\Microsoft\WBEM\CIMOM\ContextLimit
HKLM\Software\Microsoft\WBEM\CIMOM\ObjectLimit
HKLM\Software\Microsoft\WBEM\CIMOM\IdentifierLimit
HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\KindMap
HKLM\Software\Policies\Microsoft\Internet Explorer\Main\FeatureControl
HKLM\Software\Microsoft\Internet Explorer\Main\FeatureControl
HKCU\Software\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_IGNORE_POLICIES_ZONEMAP_IF_ESC_ENABLED_KB918915
HKCU\Software\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_ZONES_CHECK_ZONEMAP_POLICY_KB941001
HKLM\Software\Policies
HKCU\Software
HKLM\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings
HKLM\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
HKCU\Software\Microsoft\Internet Explorer\Main
HKCU\Software\Microsoft\Internet Explorer\Main\FrameTabWindow
HKCU\Software\Microsoft\Internet Explorer\Main\FrameMerging
HKCU\Software\Microsoft\Internet Explorer\Main\SessionMerging
HKCU\Software\Microsoft\Internet Explorer\Main\AdminTabProcs
HKLM\Software\Policies\Microsoft\Internet Explorer\Main
HKCU\Software\Microsoft\Internet Explorer\Main\TabProcGrowth
HKCU\Software\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_INITIALIZE_URLACTION_SHELLEXECUTE_TO_ALLOW_KB936610
HKLM\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\CreateUriCacheSize
HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings
HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\CreateUriCacheSize
HKLM\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\EnablePunycode
HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\EnablePunycode
HKCU\Software\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_ALLOW_REVERSE_SOLIDUS_IN_USERINFO_KB932562
HKLM\Software\Policies\Microsoft\Internet Explorer
HKCU\Software\Microsoft\Internet Explorer\Security
HKCU\Software\Microsoft\Internet Explorer\Security\DisableSecuritySettingsCheck
HKLM\System\Setup
HKLM\System\Setup\SystemSetupInProgress
HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones
HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\0
HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\1
HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\2
HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\3
HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\4
HKCU\Software\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_LOCALMACHINE_LOCKDOWN
HKCU\Software\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_ZONES_DEFAULT_DRIVE_INTRANET_KB941000
HKLM\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\SpecialFoldersCacheSize
HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\SpecialFoldersCacheSize
HKCU\Software\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_PROTOCOL_LOCKDOWN
HKCU\Software\Microsoft\Windows Script Host\Settings
HKLM\Software\Microsoft\Windows Script Host\Settings\IgnoreUserSettings
HKCU\Software\Microsoft\Windows Script Host\Settings\Enabled
HKCU\Software\Microsoft\Windows Script Host\Settings\LogSecuritySuccesses
HKCU\Software\Microsoft\Windows Script Host\Settings\TrustPolicy
HKCU\Software\Microsoft\Windows Script Host\Settings\UseWINSAFER
Software\Microsoft\Windows Script Host\Settings\Timeout
Software\Microsoft\Windows Script Host\Settings\DisplayLogo
HKCR\.vbs
HKCR\.vbs\0x0
HKCR\VBSFile\ScriptEngine
HKCR\VBSFile\ScriptEngine\0x0

Registry Set (Top 25)

Key Value
\\REGISTRY\A\{4c874eac-35a3-11ec-b3e4-167c9a143b3f}\DefaultObjectStore\ObjectTable\663\Indexes\FileIdIndex-{853201e6-2d75-11ea-a138-806e6f6e6963}\100000001F551
\\REGISTRY\A\{4c874eac-35a3-11ec-b3e4-167c9a143b3f}\DefaultObjectStore\IndexTable\FileIdIndex-{853201e6-2d75-11ea-a138-806e6f6e6963}\10000000398FC\664
\\REGISTRY\A\{4c874eac-35a3-11ec-b3e4-167c9a143b3f}\DefaultObjectStore\IndexTable\FileIdIndex-{853201e6-2d75-11ea-a138-806e6f6e6963}\100000001F5DB\66C
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft_Auto_Scheduler\Index
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft_Auto_Scheduler\Id
\\REGISTRY\A\{4c874eac-35a3-11ec-b3e4-167c9a143b3f}\DefaultObjectStore\LruList\0000000000002B79\ObjectLru
\\REGISTRY\A\{4c874eac-35a3-11ec-b3e4-167c9a143b3f}\DefaultObjectStore\LruList\0000000000002B79\ObjectId
\\REGISTRY\A\{4c874eac-35a3-11ec-b3e4-167c9a143b3f}\DefaultObjectStore\LruList\0000000000002B74\ObjectLru
\\REGISTRY\A\{4c874eac-35a3-11ec-b3e4-167c9a143b3f}\DefaultObjectStore\LruList\0000000000002B74\ObjectId
\\REGISTRY\A\{4c874eac-35a3-11ec-b3e4-167c9a143b3f}\DefaultObjectStore\IndexTable\FileIdIndex-{853201e6-2d75-11ea-a138-806e6f6e6963}\3C0000000004AE\666
\\REGISTRY\A\{4c874eac-35a3-11ec-b3e4-167c9a143b3f}\DefaultObjectStore\ObjectTable\669\Indexes\FileIdIndex-{853201e6-2d75-11ea-a138-806e6f6e6963}\10000000097C6
HKLM\SOFTWARE\Microsoft\WBEM\PROVIDERS\Performance\Performance Refresh 0
HKLM\SOFTWARE\Microsoft\WBEM\PROVIDERS\Performance\Performance Refreshed 1
HKLM\SOFTWARE\Microsoft\WBEM\PROVIDERS\Performance\Performance Data 28 1B 00 00 01 00 00 00 00 00 00 00 10 00 00 00 18 1B 00 00 09 00 00 00 9A 00 00 00 01 00 00 00 01 00 00 00 40 00 00 00 1A 00 00 00 5C 00 5C 00 2E 00 5C 00 72 00 6F 00 6F 00 74 00 5C 00 77 00 6D 00 69 00 00 00 00 00 00 00 00 00 00 00 00 00 C0 01 00 00 04 00 00 00 08 00 00 00 01 00 00 00 00 00 00 00 01 00 00 00 64 00 00 00 68 00 00 00 3A 00 00 00 4D 00 53 00 69 00 53 00 43 00 53 00 49 00 5F 00 43 00 6F 00 6E 00 6E 00 65 00 63 00 74 00 69 00 6F 00 6E 00 53 00 74 00 61 00 74 00 69 00 73 00 74 00 69 00 63 00 73 00 00 00 00 00 00 00 00 00 00 00 00 00 30 00 00 00 1A 00 00 00 49 00 6E 00 73 00 74 00 61 00 6E 00 63 00 65 00 4E 00 61 00 6D 00 65 00 00 00 58 77 00 00 00 00 00 00 00 00 00 00 00 00 48 00 00 00 00 00 00 00 02 00 00 00 15 00 00 00 00 00 00 00 64 00 00 00 00 05 41 10 48 00 00 00 1C 00 00 00 42 00 79 00 74 00 65 00 73 00 52 00 65 00 63 00 65 00 69 00 76 00 65 00 64 00 00 00 00 00 00 00 00 00 00 00 40 00 00 00 00 00 00 00 04 00 00 00 15 00 00 00 00 00 00 00 64 00 00 00 00 05 41 10 40 00 00 00 14 00 00 00 42 0 .. truncated
\\REGISTRY\A\{4c874eac-35a3-11ec-b3e4-167c9a143b3f}\DefaultObjectStore\ObjectTable\66D\Indexes\FileIdIndex-{853201e6-2d75-11ea-a138-806e6f6e6963}\3300000000056B
\\REGISTRY\A\{4c874eac-35a3-11ec-b3e4-167c9a143b3f}\DefaultObjectStore\LruList\0000000000002B7E\ObjectLru
\\REGISTRY\A\{4c874eac-35a3-11ec-b3e4-167c9a143b3f}\DefaultObjectStore\LruList\0000000000002B7E\ObjectId
\\REGISTRY\A\{4c874eac-35a3-11ec-b3e4-167c9a143b3f}\DefaultObjectStore\ObjectTable\667\Indexes\FileIdIndex-{853201e6-2d75-11ea-a138-806e6f6e6963}\1000000009220
\\REGISTRY\A\{4c874eac-35a3-11ec-b3e4-167c9a143b3f}\DefaultObjectStore\IndexTable\FileIdIndex-{853201e6-2d75-11ea-a138-806e6f6e6963}\100000001F551\663
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{A50FA9BD-C491-40C1-AB03-017EF5D0BDAA}\DynamicInfo
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{A50FA9BD-C491-40C1-AB03-017EF5D0BDAA}\Path
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{A50FA9BD-C491-40C1-AB03-017EF5D0BDAA}\Hash
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{A50FA9BD-C491-40C1-AB03-017EF5D0BDAA}\Triggers
\\REGISTRY\A\{4c874eac-35a3-11ec-b3e4-167c9a143b3f}\DefaultObjectStore\LruList\CurrentLru
\\REGISTRY\A\{4c874eac-35a3-11ec-b3e4-167c9a143b3f}\DefaultObjectStore\LruList\0000000000002B6C\ObjectLru
\\REGISTRY\A\{4c874eac-35a3-11ec-b3e4-167c9a143b3f}\DefaultObjectStore\LruList\0000000000002B6C\ObjectId
\\REGISTRY\A\{4c874eac-35a3-11ec-b3e4-167c9a143b3f}\DefaultObjectStore\ObjectTable\66C\Indexes\FileIdIndex-{853201e6-2d75-11ea-a138-806e6f6e6963}\100000001F5DB
\\REGISTRY\A\{4c874eac-35a3-11ec-b3e4-167c9a143b3f}\DefaultObjectStore\ObjectTable\668\Indexes\FileIdIndex-{853201e6-2d75-11ea-a138-806e6f6e6963}\200000001E904
\\REGISTRY\A\{4c874eac-35a3-11ec-b3e4-167c9a143b3f}\DefaultObjectStore\IndexTable\FileIdIndex-{853201e6-2d75-11ea-a138-806e6f6e6963}\_IndexName_
HKLM\Software\Microsoft\WBEM\CIMOM\ConfigValueEssNeedsLoading 1
HKLM\Software\Microsoft\WBEM\CIMOM\List of event-active namespaces 00 00 54 00 45 00 76 00 65 00 6E 00 74 00 4C 00 6F 00 67 00 45 00 76 00 65 00 6E 00 74 00 43 00 6F 00 6E 00 73 00 75 00 6D 00 65 00 72 00
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Component Based Servicing\SessionIdLow
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Component Based Servicing\SessionIdHigh
HKLM\SYSTEM\ControlSet001\Control\BackupRestore\FilesNotToBackup\BITS_LOG %windir%\System32\Bits.log
HKLM\SYSTEM\ControlSet001\Control\BackupRestore\FilesNotToBackup\BITS_BAK %windir%\System32\Bits.bak
HKLM\SYSTEM\ControlSet001\Services\WmiApRpl\Performance\Last Counter 12642
HKLM\SYSTEM\ControlSet001\Services\WmiApRpl\Performance\Object List 12476 12482 12492 12502 12522 12566 12576 12614 12620 12636
HKLM\SYSTEM\ControlSet001\Services\WmiApRpl\Performance\Last Help 12643
HKLM\SYSTEM\ControlSet001\Services\WmiApRpl\Performance\First Counter 12476
HKLM\SYSTEM\ControlSet001\Services\WmiApRpl\Performance\First Help 12477
HKLM\SYSTEM\ControlSet001\Services\WmiApRpl\Performance\PerfIniFile WmiApRpl.ini
\\REGISTRY\A\{4c874eac-35a3-11ec-b3e4-167c9a143b3f}\DefaultObjectStore\IndexTable\FileIdIndex-{853201e6-2d75-11ea-a138-806e6f6e6963}\3300000000056B\66D
HKLM\SYSTEM\ControlSet001\Control\WMI\AutoLogger\Circular Kernel Context Logger\Status 0
\\REGISTRY\A\{4c874eac-35a3-11ec-b3e4-167c9a143b3f}\DefaultObjectStore\IndexTable\FileIdIndex-{853201e6-2d75-11ea-a138-806e6f6e6963}\100000000972F\66B
\\REGISTRY\A\{4c874eac-35a3-11ec-b3e4-167c9a143b3f}\DefaultObjectStore\IndexTable\FileIdIndex-{853201e6-2d75-11ea-a138-806e6f6e6963}\100000001E722\662
\\Registry\Machine\COMPONENTS\ServicingStackVersions\6.1.7601.24537 (win7sp1_ldr_escrow.191114-1547)
\\REGISTRY\A\{4c874eac-35a3-11ec-b3e4-167c9a143b3f}\DefaultObjectStore\IndexTable\FileIdIndex-{853201e6-2d75-11ea-a138-806e6f6e6963}\1000000009220\667
\\REGISTRY\A\{4c874eac-35a3-11ec-b3e4-167c9a143b3f}\DefaultObjectStore\ObjectTable\66B\Indexes\FileIdIndex-{853201e6-2d75-11ea-a138-806e6f6e6963}\100000000972F
\\REGISTRY\A\{4c874eac-35a3-11ec-b3e4-167c9a143b3f}\DefaultObjectStore\LruList\0000000000002BA3\ObjectLru
\\REGISTRY\A\{4c874eac-35a3-11ec-b3e4-167c9a143b3f}\DefaultObjectStore\LruList\0000000000002BA3\ObjectId
Show all (208 total)
Key Value
\\REGISTRY\A\{4c874eac-35a3-11ec-b3e4-167c9a143b3f}\DefaultObjectStore\LruList\0000000000002B9A\ObjectLru
\\REGISTRY\A\{4c874eac-35a3-11ec-b3e4-167c9a143b3f}\DefaultObjectStore\LruList\0000000000002B9A\ObjectId
\\REGISTRY\A\{4c874eac-35a3-11ec-b3e4-167c9a143b3f}\DefaultObjectStore\IndexTable\FileIdIndex-{853201e6-2d75-11ea-a138-806e6f6e6963}\10000000060F3\66E
\\REGISTRY\A\{4c874eac-35a3-11ec-b3e4-167c9a143b3f}\DefaultObjectStore\LruList\0000000000002BAC\ObjectLru
\\REGISTRY\A\{4c874eac-35a3-11ec-b3e4-167c9a143b3f}\DefaultObjectStore\LruList\0000000000002BAC\ObjectId
\\REGISTRY\A\{4c874eac-35a3-11ec-b3e4-167c9a143b3f}\DefaultObjectStore\LruList\0000000000002BB8\ObjectLru
\\REGISTRY\A\{4c874eac-35a3-11ec-b3e4-167c9a143b3f}\DefaultObjectStore\LruList\0000000000002BB8\ObjectId
\\REGISTRY\A\{4c874eac-35a3-11ec-b3e4-167c9a143b3f}\DefaultObjectStore\IndexTable\FileIdIndex-{853201e6-2d75-11ea-a138-806e6f6e6963}\10000000097C6\669
HKLM\SYSTEM\ControlSet001\Services\BITS\Performance\PerfMMFileName Global\MMF_BITS_s
\\REGISTRY\A\{4c874eac-35a3-11ec-b3e4-167c9a143b3f}\DefaultObjectStore\ObjectTable\667\_FileId_
\\REGISTRY\A\{4c874eac-35a3-11ec-b3e4-167c9a143b3f}\DefaultObjectStore\ObjectTable\667\_ObjectLru_
\\REGISTRY\A\{4c874eac-35a3-11ec-b3e4-167c9a143b3f}\DefaultObjectStore\ObjectTable\667\_Usn_
\\REGISTRY\A\{4c874eac-35a3-11ec-b3e4-167c9a143b3f}\DefaultObjectStore\ObjectTable\667\_ObjectId_
\\REGISTRY\A\{4c874eac-35a3-11ec-b3e4-167c9a143b3f}\DefaultObjectStore\ObjectTable\667\AeFileID
\\REGISTRY\A\{4c874eac-35a3-11ec-b3e4-167c9a143b3f}\DefaultObjectStore\ObjectTable\667\_UsnJournalId_
\\REGISTRY\A\{4c874eac-35a3-11ec-b3e4-167c9a143b3f}\DefaultObjectStore\ObjectTable\667\AeProgramID
\\REGISTRY\A\{4c874eac-35a3-11ec-b3e4-167c9a143b3f}\DefaultObjectStore\ObjectTable\666\_FileId_
\\REGISTRY\A\{4c874eac-35a3-11ec-b3e4-167c9a143b3f}\DefaultObjectStore\ObjectTable\666\_ObjectLru_
\\REGISTRY\A\{4c874eac-35a3-11ec-b3e4-167c9a143b3f}\DefaultObjectStore\ObjectTable\666\_Usn_
\\REGISTRY\A\{4c874eac-35a3-11ec-b3e4-167c9a143b3f}\DefaultObjectStore\ObjectTable\666\_ObjectId_
\\REGISTRY\A\{4c874eac-35a3-11ec-b3e4-167c9a143b3f}\DefaultObjectStore\ObjectTable\666\AeFileID
\\REGISTRY\A\{4c874eac-35a3-11ec-b3e4-167c9a143b3f}\DefaultObjectStore\ObjectTable\666\_UsnJournalId_
\\REGISTRY\A\{4c874eac-35a3-11ec-b3e4-167c9a143b3f}\DefaultObjectStore\ObjectTable\666\AeProgramID
\\REGISTRY\A\{4c874eac-35a3-11ec-b3e4-167c9a143b3f}\DefaultObjectStore\ObjectTable\665\_FileId_
\\REGISTRY\A\{4c874eac-35a3-11ec-b3e4-167c9a143b3f}\DefaultObjectStore\ObjectTable\665\_ObjectLru_
\\REGISTRY\A\{4c874eac-35a3-11ec-b3e4-167c9a143b3f}\DefaultObjectStore\ObjectTable\665\_Usn_
\\REGISTRY\A\{4c874eac-35a3-11ec-b3e4-167c9a143b3f}\DefaultObjectStore\ObjectTable\665\_ObjectId_
\\REGISTRY\A\{4c874eac-35a3-11ec-b3e4-167c9a143b3f}\DefaultObjectStore\ObjectTable\665\AeFileID
\\REGISTRY\A\{4c874eac-35a3-11ec-b3e4-167c9a143b3f}\DefaultObjectStore\ObjectTable\665\_UsnJournalId_
\\REGISTRY\A\{4c874eac-35a3-11ec-b3e4-167c9a143b3f}\DefaultObjectStore\ObjectTable\665\AeProgramID
\\REGISTRY\A\{4c874eac-35a3-11ec-b3e4-167c9a143b3f}\DefaultObjectStore\ObjectTable\664\_FileId_
\\REGISTRY\A\{4c874eac-35a3-11ec-b3e4-167c9a143b3f}\DefaultObjectStore\ObjectTable\664\_ObjectLru_
\\REGISTRY\A\{4c874eac-35a3-11ec-b3e4-167c9a143b3f}\DefaultObjectStore\ObjectTable\664\_Usn_
\\REGISTRY\A\{4c874eac-35a3-11ec-b3e4-167c9a143b3f}\DefaultObjectStore\ObjectTable\664\_ObjectId_
\\REGISTRY\A\{4c874eac-35a3-11ec-b3e4-167c9a143b3f}\DefaultObjectStore\ObjectTable\664\AeFileID
\\REGISTRY\A\{4c874eac-35a3-11ec-b3e4-167c9a143b3f}\DefaultObjectStore\ObjectTable\664\_UsnJournalId_
\\REGISTRY\A\{4c874eac-35a3-11ec-b3e4-167c9a143b3f}\DefaultObjectStore\ObjectTable\664\AeProgramID
\\REGISTRY\A\{4c874eac-35a3-11ec-b3e4-167c9a143b3f}\DefaultObjectStore\ObjectTable\663\_FileId_
\\REGISTRY\A\{4c874eac-35a3-11ec-b3e4-167c9a143b3f}\DefaultObjectStore\ObjectTable\663\_ObjectLru_
\\REGISTRY\A\{4c874eac-35a3-11ec-b3e4-167c9a143b3f}\DefaultObjectStore\ObjectTable\663\_Usn_
\\REGISTRY\A\{4c874eac-35a3-11ec-b3e4-167c9a143b3f}\DefaultObjectStore\ObjectTable\663\_ObjectId_
\\REGISTRY\A\{4c874eac-35a3-11ec-b3e4-167c9a143b3f}\DefaultObjectStore\ObjectTable\663\AeFileID
\\REGISTRY\A\{4c874eac-35a3-11ec-b3e4-167c9a143b3f}\DefaultObjectStore\ObjectTable\663\_UsnJournalId_
\\REGISTRY\A\{4c874eac-35a3-11ec-b3e4-167c9a143b3f}\DefaultObjectStore\ObjectTable\663\AeProgramID
\\REGISTRY\A\{4c874eac-35a3-11ec-b3e4-167c9a143b3f}\DefaultObjectStore\ObjectTable\662\_FileId_
\\REGISTRY\A\{4c874eac-35a3-11ec-b3e4-167c9a143b3f}\DefaultObjectStore\ObjectTable\662\_ObjectLru_
\\REGISTRY\A\{4c874eac-35a3-11ec-b3e4-167c9a143b3f}\DefaultObjectStore\ObjectTable\662\_Usn_
\\REGISTRY\A\{4c874eac-35a3-11ec-b3e4-167c9a143b3f}\DefaultObjectStore\ObjectTable\662\_ObjectId_
\\REGISTRY\A\{4c874eac-35a3-11ec-b3e4-167c9a143b3f}\DefaultObjectStore\ObjectTable\662\AeFileID
\\REGISTRY\A\{4c874eac-35a3-11ec-b3e4-167c9a143b3f}\DefaultObjectStore\ObjectTable\662\_UsnJournalId_
\\REGISTRY\A\{4c874eac-35a3-11ec-b3e4-167c9a143b3f}\DefaultObjectStore\ObjectTable\662\AeProgramID
\\REGISTRY\A\{4c874eac-35a3-11ec-b3e4-167c9a143b3f}\DefaultObjectStore\ObjectTable\661\_FileId_
\\REGISTRY\A\{4c874eac-35a3-11ec-b3e4-167c9a143b3f}\DefaultObjectStore\ObjectTable\661\_ObjectLru_
\\REGISTRY\A\{4c874eac-35a3-11ec-b3e4-167c9a143b3f}\DefaultObjectStore\ObjectTable\661\_Usn_
\\REGISTRY\A\{4c874eac-35a3-11ec-b3e4-167c9a143b3f}\DefaultObjectStore\ObjectTable\661\_ObjectId_
\\REGISTRY\A\{4c874eac-35a3-11ec-b3e4-167c9a143b3f}\DefaultObjectStore\ObjectTable\661\AeFileID
\\REGISTRY\A\{4c874eac-35a3-11ec-b3e4-167c9a143b3f}\DefaultObjectStore\ObjectTable\661\_UsnJournalId_
\\REGISTRY\A\{4c874eac-35a3-11ec-b3e4-167c9a143b3f}\DefaultObjectStore\ObjectTable\661\AeProgramID
\\REGISTRY\A\{4c874eac-35a3-11ec-b3e4-167c9a143b3f}\DefaultObjectStore\ObjectTable\669\_FileId_
\\REGISTRY\A\{4c874eac-35a3-11ec-b3e4-167c9a143b3f}\DefaultObjectStore\ObjectTable\669\_ObjectLru_
\\REGISTRY\A\{4c874eac-35a3-11ec-b3e4-167c9a143b3f}\DefaultObjectStore\ObjectTable\669\_Usn_
\\REGISTRY\A\{4c874eac-35a3-11ec-b3e4-167c9a143b3f}\DefaultObjectStore\ObjectTable\669\_ObjectId_
\\REGISTRY\A\{4c874eac-35a3-11ec-b3e4-167c9a143b3f}\DefaultObjectStore\ObjectTable\669\AeFileID
\\REGISTRY\A\{4c874eac-35a3-11ec-b3e4-167c9a143b3f}\DefaultObjectStore\ObjectTable\669\_UsnJournalId_
\\REGISTRY\A\{4c874eac-35a3-11ec-b3e4-167c9a143b3f}\DefaultObjectStore\ObjectTable\669\AeProgramID
\\REGISTRY\A\{4c874eac-35a3-11ec-b3e4-167c9a143b3f}\DefaultObjectStore\ObjectTable\668\_FileId_
\\REGISTRY\A\{4c874eac-35a3-11ec-b3e4-167c9a143b3f}\DefaultObjectStore\ObjectTable\668\_ObjectLru_
\\REGISTRY\A\{4c874eac-35a3-11ec-b3e4-167c9a143b3f}\DefaultObjectStore\ObjectTable\668\_Usn_
\\REGISTRY\A\{4c874eac-35a3-11ec-b3e4-167c9a143b3f}\DefaultObjectStore\ObjectTable\668\_ObjectId_
\\REGISTRY\A\{4c874eac-35a3-11ec-b3e4-167c9a143b3f}\DefaultObjectStore\ObjectTable\668\AeFileID
\\REGISTRY\A\{4c874eac-35a3-11ec-b3e4-167c9a143b3f}\DefaultObjectStore\ObjectTable\668\_UsnJournalId_
\\REGISTRY\A\{4c874eac-35a3-11ec-b3e4-167c9a143b3f}\DefaultObjectStore\ObjectTable\668\AeProgramID
\\REGISTRY\A\{4c874eac-35a3-11ec-b3e4-167c9a143b3f}\DefaultObjectStore\IndexTable\FileIdIndex-{853201e6-2d75-11ea-a138-806e6f6e6963}\1000000009746\661
\\REGISTRY\A\{4c874eac-35a3-11ec-b3e4-167c9a143b3f}\DefaultObjectStore\ObjectTable\66E\Indexes\FileIdIndex-{853201e6-2d75-11ea-a138-806e6f6e6963}\10000000060F3
\\REGISTRY\A\{4c874eac-35a3-11ec-b3e4-167c9a143b3f}\DefaultObjectStore\LruList\0000000000002B8B\ObjectLru
\\REGISTRY\A\{4c874eac-35a3-11ec-b3e4-167c9a143b3f}\DefaultObjectStore\LruList\0000000000002B8B\ObjectId
\\REGISTRY\A\{4c874eac-35a3-11ec-b3e4-167c9a143b3f}\DefaultObjectStore\_CurrentObjectId_
HKU\S-1-5-21-575823232-3065301323-1442773979-1000\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\\AutoDetect 1
HKU\S-1-5-21-575823232-3065301323-1442773979-1000\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\\UNCAsIntranet 0
\\REGISTRY\A\{4c874eac-35a3-11ec-b3e4-167c9a143b3f}\DefaultObjectStore\LruList\0000000000002B88\ObjectLru
\\REGISTRY\A\{4c874eac-35a3-11ec-b3e4-167c9a143b3f}\DefaultObjectStore\LruList\0000000000002B88\ObjectId
\\REGISTRY\A\{4c874eac-35a3-11ec-b3e4-167c9a143b3f}\DefaultObjectStore\ObjectTable\661\Indexes\FileIdIndex-{853201e6-2d75-11ea-a138-806e6f6e6963}\1000000009746
\\REGISTRY\A\{4c874eac-35a3-11ec-b3e4-167c9a143b3f}\DefaultObjectStore\LruList\0000000000002BC0\ObjectLru
\\REGISTRY\A\{4c874eac-35a3-11ec-b3e4-167c9a143b3f}\DefaultObjectStore\LruList\0000000000002BC0\ObjectId
\\REGISTRY\A\{4c874eac-35a3-11ec-b3e4-167c9a143b3f}\DefaultObjectStore\LruList\0000000000002BC2\ObjectLru
\\REGISTRY\A\{4c874eac-35a3-11ec-b3e4-167c9a143b3f}\DefaultObjectStore\LruList\0000000000002BC2\ObjectId
\\REGISTRY\A\{4c874eac-35a3-11ec-b3e4-167c9a143b3f}\DefaultObjectStore\ObjectTable\66E\_FileId_
\\REGISTRY\A\{4c874eac-35a3-11ec-b3e4-167c9a143b3f}\DefaultObjectStore\ObjectTable\66E\_ObjectLru_
\\REGISTRY\A\{4c874eac-35a3-11ec-b3e4-167c9a143b3f}\DefaultObjectStore\ObjectTable\66E\_Usn_
\\REGISTRY\A\{4c874eac-35a3-11ec-b3e4-167c9a143b3f}\DefaultObjectStore\ObjectTable\66E\_ObjectId_
\\REGISTRY\A\{4c874eac-35a3-11ec-b3e4-167c9a143b3f}\DefaultObjectStore\ObjectTable\66E\AeFileID
\\REGISTRY\A\{4c874eac-35a3-11ec-b3e4-167c9a143b3f}\DefaultObjectStore\ObjectTable\66E\_UsnJournalId_
\\REGISTRY\A\{4c874eac-35a3-11ec-b3e4-167c9a143b3f}\DefaultObjectStore\ObjectTable\66E\AeProgramID
\\REGISTRY\A\{4c874eac-35a3-11ec-b3e4-167c9a143b3f}\DefaultObjectStore\ObjectTable\66D\_FileId_
\\REGISTRY\A\{4c874eac-35a3-11ec-b3e4-167c9a143b3f}\DefaultObjectStore\ObjectTable\66D\_ObjectLru_
\\REGISTRY\A\{4c874eac-35a3-11ec-b3e4-167c9a143b3f}\DefaultObjectStore\ObjectTable\66D\_Usn_
\\REGISTRY\A\{4c874eac-35a3-11ec-b3e4-167c9a143b3f}\DefaultObjectStore\ObjectTable\66D\_ObjectId_
\\REGISTRY\A\{4c874eac-35a3-11ec-b3e4-167c9a143b3f}\DefaultObjectStore\ObjectTable\66D\AeFileID
\\REGISTRY\A\{4c874eac-35a3-11ec-b3e4-167c9a143b3f}\DefaultObjectStore\ObjectTable\66D\_UsnJournalId_
\\REGISTRY\A\{4c874eac-35a3-11ec-b3e4-167c9a143b3f}\DefaultObjectStore\ObjectTable\66D\AeProgramID
\\REGISTRY\A\{4c874eac-35a3-11ec-b3e4-167c9a143b3f}\DefaultObjectStore\ObjectTable\66C\_FileId_
\\REGISTRY\A\{4c874eac-35a3-11ec-b3e4-167c9a143b3f}\DefaultObjectStore\ObjectTable\66C\_ObjectLru_
\\REGISTRY\A\{4c874eac-35a3-11ec-b3e4-167c9a143b3f}\DefaultObjectStore\ObjectTable\66C\_Usn_
\\REGISTRY\A\{4c874eac-35a3-11ec-b3e4-167c9a143b3f}\DefaultObjectStore\ObjectTable\66C\_ObjectId_
\\REGISTRY\A\{4c874eac-35a3-11ec-b3e4-167c9a143b3f}\DefaultObjectStore\ObjectTable\66C\AeFileID
\\REGISTRY\A\{4c874eac-35a3-11ec-b3e4-167c9a143b3f}\DefaultObjectStore\ObjectTable\66C\_UsnJournalId_
\\REGISTRY\A\{4c874eac-35a3-11ec-b3e4-167c9a143b3f}\DefaultObjectStore\ObjectTable\66C\AeProgramID
\\REGISTRY\A\{4c874eac-35a3-11ec-b3e4-167c9a143b3f}\DefaultObjectStore\ObjectTable\66B\_FileId_
\\REGISTRY\A\{4c874eac-35a3-11ec-b3e4-167c9a143b3f}\DefaultObjectStore\ObjectTable\66B\_ObjectLru_
\\REGISTRY\A\{4c874eac-35a3-11ec-b3e4-167c9a143b3f}\DefaultObjectStore\ObjectTable\66B\_Usn_
\\REGISTRY\A\{4c874eac-35a3-11ec-b3e4-167c9a143b3f}\DefaultObjectStore\ObjectTable\66B\_ObjectId_
\\REGISTRY\A\{4c874eac-35a3-11ec-b3e4-167c9a143b3f}\DefaultObjectStore\ObjectTable\66B\AeFileID
\\REGISTRY\A\{4c874eac-35a3-11ec-b3e4-167c9a143b3f}\DefaultObjectStore\ObjectTable\66B\_UsnJournalId_
\\REGISTRY\A\{4c874eac-35a3-11ec-b3e4-167c9a143b3f}\DefaultObjectStore\ObjectTable\66B\AeProgramID
\\REGISTRY\A\{4c874eac-35a3-11ec-b3e4-167c9a143b3f}\DefaultObjectStore\ObjectTable\66A\_FileId_
\\REGISTRY\A\{4c874eac-35a3-11ec-b3e4-167c9a143b3f}\DefaultObjectStore\ObjectTable\66A\_ObjectLru_
\\REGISTRY\A\{4c874eac-35a3-11ec-b3e4-167c9a143b3f}\DefaultObjectStore\ObjectTable\66A\_Usn_
\\REGISTRY\A\{4c874eac-35a3-11ec-b3e4-167c9a143b3f}\DefaultObjectStore\ObjectTable\66A\_ObjectId_
\\REGISTRY\A\{4c874eac-35a3-11ec-b3e4-167c9a143b3f}\DefaultObjectStore\ObjectTable\66A\AeFileID
\\REGISTRY\A\{4c874eac-35a3-11ec-b3e4-167c9a143b3f}\DefaultObjectStore\ObjectTable\66A\_UsnJournalId_
\\REGISTRY\A\{4c874eac-35a3-11ec-b3e4-167c9a143b3f}\DefaultObjectStore\ObjectTable\66A\AeProgramID
\\REGISTRY\A\{4c874eac-35a3-11ec-b3e4-167c9a143b3f}\DefaultObjectStore\ObjectTable\666\Indexes\FileIdIndex-{853201e6-2d75-11ea-a138-806e6f6e6963}\3C0000000004AE
\\REGISTRY\A\{4c874eac-35a3-11ec-b3e4-167c9a143b3f}\DefaultObjectStore\IndexTable\FileIdIndex-{853201e6-2d75-11ea-a138-806e6f6e6963}\200000001E904\668
\\REGISTRY\A\{4c874eac-35a3-11ec-b3e4-167c9a143b3f}\DefaultObjectStore\ObjectTable\66A\Indexes\FileIdIndex-{853201e6-2d75-11ea-a138-806e6f6e6963}\1000000009758
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\BITS\StateIndex 1
\\REGISTRY\A\{4c874eac-35a3-11ec-b3e4-167c9a143b3f}\DefaultObjectStore\IndexTable\FileIdIndex-{853201e6-2d75-11ea-a138-806e6f6e6963}\1000000009758\66A
\\REGISTRY\A\{4c874eac-35a3-11ec-b3e4-167c9a143b3f}\DefaultObjectStore\LruList\0000000000002BBA\ObjectLru
\\REGISTRY\A\{4c874eac-35a3-11ec-b3e4-167c9a143b3f}\DefaultObjectStore\LruList\0000000000002BBA\ObjectId
\\REGISTRY\A\{4c874eac-35a3-11ec-b3e4-167c9a143b3f}\DefaultObjectStore\IndexTable\FileIdIndex-{853201e6-2d75-11ea-a138-806e6f6e6963}\100000001F21B\665
\\REGISTRY\A\{4c874eac-35a3-11ec-b3e4-167c9a143b3f}\DefaultObjectStore\LruList\0000000000002BBE\ObjectLru
\\REGISTRY\A\{4c874eac-35a3-11ec-b3e4-167c9a143b3f}\DefaultObjectStore\LruList\0000000000002BBE\ObjectId
HKLM\Software\Microsoft\WBEM\WDM\%windir%\system32\drivers\ndis.sys[MofResourceName] LowDateTime:-331231481,HighDateTime:30676316***Binary mof failed, see WMIPROV.LOG
HKLM\Software\Microsoft\WBEM\WDM\%windir%\System32\Drivers\portcls.SYS[PortclsMof] LowDateTime:418629328,HighDateTime:30487037***Binary mof compiled successfully
HKLM\Software\Microsoft\WBEM\WDM\%windir%\system32\drivers\en-US\ACPI.sys.mui[ACPIMOFResource] LowDateTime:1237199616,HighDateTime:30016579***Binary mof compiled successfully
HKLM\Software\Microsoft\WBEM\WDM\%windir%\system32\DRIVERS\HDAudBus.sys[HDAudioMofName] LowDateTime:-227274444,HighDateTime:30116024***Binary mof compiled successfully
HKLM\Software\Microsoft\WBEM\WDM\%windir%\System32\Drivers\en-US\portcls.SYS.mui[PortclsMof] LowDateTime:1137199616,HighDateTime:30016579***Binary mof compiled successfully
HKLM\Software\Microsoft\WBEM\WDM\%windir%\system32\advapi32.dll[MofResourceName] LowDateTime:302488720,HighDateTime:30778805***Binary mof compiled successfully
HKLM\Software\Microsoft\WBEM\WDM\%windir%\system32\en-US\advapi32.dll.mui[MofResourceName] LowDateTime:369951187,HighDateTime:30778805***Binary mof compiled successfully
HKLM\Software\Microsoft\WBEM\WDM\%windir%\system32\drivers\en-US\mssmbios.sys.mui[MofResource] LowDateTime:1497199616,HighDateTime:30016579***Binary mof compiled successfully
HKLM\Software\Microsoft\WBEM\WDM\%windir%\system32\DRIVERS\en-US\HDAudBus.sys.mui[HDAudioMofName] LowDateTime:-377767680,HighDateTime:30016579***Binary mof compiled successfully
HKLM\Software\Microsoft\WBEM\WDM\%windir%\system32\drivers\en-US\ndis.sys.mui[MofResourceName] LowDateTime:382232320,HighDateTime:30016580***Binary mof failed, see WMIPROV.LOG
HKLM\Software\Microsoft\WBEM\WDM\%windir%\system32\DRIVERS\en-US\intelppm.sys.mui[PROCESSORWMI] LowDateTime:-577767680,HighDateTime:30016579***Binary mof compiled successfully
HKLM\Software\Microsoft\WBEM\WDM\IDE\DiskAMDX_HARDDISK___________________________2.5+____\5&2770a7af&0&0.0.0_0-{05901221-D566-11d1-B2F0-00A0C9062910} LowDateTime:803713417,HighDateTime:0***Binary mof compiled successfully
HKLM\Software\Microsoft\WBEM\WDM\%windir%\system32\DRIVERS\intelppm.sys[PROCESSORWMI] LowDateTime:-445445610,HighDateTime:30778799***Binary mof compiled successfully
HKLM\Software\Microsoft\WBEM\WDM\%windir%\system32\drivers\ACPI.sys[ACPIMOFResource] LowDateTime:398767260,HighDateTime:30646967***Binary mof compiled successfully
HKLM\Software\Microsoft\WBEM\WDM\%windir%\system32\DRIVERS\monitor.sys[MonitorWMI] LowDateTime:-1637837527,HighDateTime:30762899***Binary mof failed, see WMIPROV.LOG
HKLM\Software\Microsoft\WBEM\WDM\%windir%\system32\drivers\mssmbios.sys[MofResource] LowDateTime:-649833737,HighDateTime:30733938***Binary mof compiled successfully
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System\EnableLUA DWORD (0x00000000)
HKLM\System\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\PublicProfile\EnableFirewall DWORD (0x00000000)
HKLM\System\CurrentControlSet\Services\IKEEXT\Start DWORD (0x00000002)
HKLM\System\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\PublicProfile\DoNotAllowExceptions DWORD (0x00000000)
HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Run\Machin_Update
HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Run\Machin_Update c:\$Recycle.Bin\RCRU_64.exe
HKU\%SID%\Software\Microsoft\Windows\CurrentVersion\Run\Machin_Update
HKU\%SID%\Software\Microsoft\Windows\CurrentVersion\Run\Machin_Update c:\$Recycle.Bin\RCRU_64.exe
\REGISTRY\USER\S-1-5-21-1482476501-1645522239-1417001333-500\Software\Microsoft\Windows\ShellNoRoam\MUICache\C:\Users\Administrator\AppData\h4_svc.bat h4_svc
\REGISTRY\USER\S-1-5-21-1482476501-1645522239-1417001333-500\Software\Microsoft\Windows\ShellNoRoam\MUICache\C:\Documents and Settings\Administrator\Local Settings\Temp\EB93A6\996E.exe Microsoft Protection Service
HKLM\SOFTWARE\Microsoft\Windows Media Player NSS\3.0\Servers\A70D59A1-8EAD-4F40-AAAB-FBFC460800A4\FriendlyName WORK: admin:

Services Started (Top 15)

Services Opened (Top 15)

What To Do Now — Practical Defense Playbook

  • Contain unknowns: block first‑run binaries by default — signatures catch up, containment works now.
  • EDR controls: alert on keyboard hooks, screen capture APIs, VM/sandbox checks, and command‑shell launches.
  • Registry watch: flag queries/sets under policy paths (e.g., …\FipsAlgorithmPolicy\*).
  • Network rules: inspect outbound TLS to IP‑lookup services and unexpected CDN endpoints.
  • Hunt broadly: sweep endpoints for the indicators above and quarantine positives immediately.

Dwell time equals attacker opportunity. Reducing execution privileges and egress shrinks that window even when vendors disagree.

Scroll to Top