Regshot 1.8.3-beta1V5 Comments: Datetime:2012/8/22 03:53:36 , 2012/8/22 03:56:13 Computer:UHA-68F2DDBE516 , UHA-68F2DDBE516 Username:Administrador , Administrador ---------------------------------- Values added:10 ---------------------------------- HKLM\SYSTEM\ControlSet001\Services\Schedule\AtTaskMaxHours: 0x00000048 HKLM\SYSTEM\CurrentControlSet\Services\Schedule\AtTaskMaxHours: 0x00000048 HKU\S-1-5-21-73586283-616249376-1177238915-500\Software\Microsoft\Internet Explorer\Main\DisableScriptDebuggerIE: "yes" HKU\S-1-5-21-73586283-616249376-1177238915-500\Software\Microsoft\Internet Explorer\Main\Error Dlg Displayed On Every Error: "no" HKU\S-1-5-21-73586283-616249376-1177238915-500\Software\Microsoft\Internet Explorer\Main\NoProtectedModeBanner: 0x00000001 HKU\S-1-5-21-73586283-616249376-1177238915-500\Software\Microsoft\Windows\CurrentVersion\Explorer\UserAssist\{75048700-EF1F-11D0-9888-006097DEACF9}\Count\HRZR_EHACNGU:P:\qbphzragbf\Fnzcyrf\boibq\boibq.rkr: 01 00 00 00 06 00 00 00 90 71 F1 BC 19 80 CD 01 HKU\S-1-5-21-73586283-616249376-1177238915-500\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\3\2500: 0x00000003 HKU\S-1-5-21-73586283-616249376-1177238915-500\Software\Microsoft\Windows\ShellNoRoam\MUICache\C:\documentos\Samples\obvod\obvod.exe: "obvod" HKU\S-1-5-21-73586283-616249376-1177238915-500\Software\Microsoft\Windows\ShellNoRoam\MUICache\C:\Documents and Settings\All Users\Datos de programa\oP5u2JBx.exe: "oP5u2JBx" HKU\S-1-5-21-73586283-616249376-1177238915-500\Software\Microsoft\Windows\ShellNoRoam\MUICache\C:\WINDOWS\system32\taskmgr.exe: "Administrador de tareas de Windows" ---------------------------------- Values modified:28 ---------------------------------- HKLM\SOFTWARE\Microsoft\Cryptography\RNG\Seed: E8 5B 5E 21 25 8F DA CE A1 2F 64 E7 E7 AE EE D9 26 98 EA AB 7D 14 3D CC 6B BA 14 9C 4F 02 03 A3 16 DD D7 82 E1 ED 1A 63 36 00 F6 07 B7 36 0A B1 6A E2 80 52 7A AE 13 41 27 AE B9 9E F7 C0 88 45 E5 D4 65 E5 C7 F9 FC 0C 09 E6 59 61 0D 7C AE ED HKLM\SOFTWARE\Microsoft\Cryptography\RNG\Seed: E1 39 41 5D BE 85 01 93 5C B2 B4 8A 28 74 D1 78 63 11 24 00 CF 22 63 8E 7E AF 6E B5 76 2A 2F 70 85 92 24 64 A0 87 78 F8 00 35 3B 52 AA 0B 59 32 D2 29 FA F4 C4 69 87 7D BA 11 C6 37 5D 20 1A B3 9A 8B D9 49 3F 08 2A BB 80 F4 D6 33 44 A1 8D 06 HKLM\SYSTEM\ControlSet001\Services\Dhcp\Parameters\{592EF604-1449-41AA-9D00-3A1F262B0400}: 06 00 00 00 00 00 00 00 04 00 00 00 00 00 00 00 C4 5B 34 50 C0 A8 E0 01 0F 00 00 00 00 00 00 00 0B 00 00 00 00 00 00 00 C4 5B 34 50 6C 6F 63 61 6C 64 6F 6D 61 69 6E 00 01 00 00 00 00 00 00 00 04 00 00 00 00 00 00 00 C4 5B 34 50 FF FF FF 00 33 00 00 00 00 00 00 00 04 00 00 00 00 00 00 00 C4 5B 34 50 00 00 07 08 36 00 00 00 00 00 00 00 04 00 00 00 00 00 00 00 C4 5B 34 50 C0 A8 E0 FE 35 00 00 00 00 00 00 00 01 00 00 00 00 00 00 00 C4 5B 34 50 05 00 00 00 HKLM\SYSTEM\ControlSet001\Services\Dhcp\Parameters\{592EF604-1449-41AA-9D00-3A1F262B0400}: 06 00 00 00 00 00 00 00 04 00 00 00 00 00 00 00 48 5F 34 50 C0 A8 E0 01 0F 00 00 00 00 00 00 00 0B 00 00 00 00 00 00 00 48 5F 34 50 6C 6F 63 61 6C 64 6F 6D 61 69 6E 00 01 00 00 00 00 00 00 00 04 00 00 00 00 00 00 00 48 5F 34 50 FF FF FF 00 33 00 00 00 00 00 00 00 04 00 00 00 00 00 00 00 48 5F 34 50 00 00 07 08 36 00 00 00 00 00 00 00 04 00 00 00 00 00 00 00 48 5F 34 50 C0 A8 E0 FE 35 00 00 00 00 00 00 00 01 00 00 00 00 00 00 00 48 5F 34 50 05 00 00 00 HKLM\SYSTEM\ControlSet001\Services\Schedule\NextAtJobId: 0x00000001 HKLM\SYSTEM\ControlSet001\Services\Schedule\NextAtJobId: 0x00000031 HKLM\SYSTEM\ControlSet001\Services\SharedAccess\Epoch\Epoch: 0x00000035 HKLM\SYSTEM\ControlSet001\Services\SharedAccess\Epoch\Epoch: 0x00000036 HKLM\SYSTEM\ControlSet001\Services\Tcpip\Parameters\Interfaces\{592EF604-1449-41AA-9D00-3A1F262B0400}\LeaseObtainedTime: 0x503454BC HKLM\SYSTEM\ControlSet001\Services\Tcpip\Parameters\Interfaces\{592EF604-1449-41AA-9D00-3A1F262B0400}\LeaseObtainedTime: 0x50345840 HKLM\SYSTEM\ControlSet001\Services\Tcpip\Parameters\Interfaces\{592EF604-1449-41AA-9D00-3A1F262B0400}\T1: 0x50345840 HKLM\SYSTEM\ControlSet001\Services\Tcpip\Parameters\Interfaces\{592EF604-1449-41AA-9D00-3A1F262B0400}\T1: 0x50345BC4 HKLM\SYSTEM\ControlSet001\Services\Tcpip\Parameters\Interfaces\{592EF604-1449-41AA-9D00-3A1F262B0400}\T2: 0x50345AE3 HKLM\SYSTEM\ControlSet001\Services\Tcpip\Parameters\Interfaces\{592EF604-1449-41AA-9D00-3A1F262B0400}\T2: 0x50345E67 HKLM\SYSTEM\ControlSet001\Services\Tcpip\Parameters\Interfaces\{592EF604-1449-41AA-9D00-3A1F262B0400}\LeaseTerminatesTime: 0x50345BC4 HKLM\SYSTEM\ControlSet001\Services\Tcpip\Parameters\Interfaces\{592EF604-1449-41AA-9D00-3A1F262B0400}\LeaseTerminatesTime: 0x50345F48 HKLM\SYSTEM\ControlSet001\Services\Tcpip\Parameters\Interfaces\{592EF604-1449-41AA-9D00-3A1F262B0400}\DhcpRetryTime: 0x00000384 HKLM\SYSTEM\ControlSet001\Services\Tcpip\Parameters\Interfaces\{592EF604-1449-41AA-9D00-3A1F262B0400}\DhcpRetryTime: 0x00000383 HKLM\SYSTEM\ControlSet001\Services\{592EF604-1449-41AA-9D00-3A1F262B0400}\Parameters\Tcpip\LeaseObtainedTime: 0x503454BC HKLM\SYSTEM\ControlSet001\Services\{592EF604-1449-41AA-9D00-3A1F262B0400}\Parameters\Tcpip\LeaseObtainedTime: 0x50345840 HKLM\SYSTEM\ControlSet001\Services\{592EF604-1449-41AA-9D00-3A1F262B0400}\Parameters\Tcpip\T1: 0x50345840 HKLM\SYSTEM\ControlSet001\Services\{592EF604-1449-41AA-9D00-3A1F262B0400}\Parameters\Tcpip\T1: 0x50345BC4 HKLM\SYSTEM\ControlSet001\Services\{592EF604-1449-41AA-9D00-3A1F262B0400}\Parameters\Tcpip\T2: 0x50345AE3 HKLM\SYSTEM\ControlSet001\Services\{592EF604-1449-41AA-9D00-3A1F262B0400}\Parameters\Tcpip\T2: 0x50345E67 HKLM\SYSTEM\ControlSet001\Services\{592EF604-1449-41AA-9D00-3A1F262B0400}\Parameters\Tcpip\LeaseTerminatesTime: 0x50345BC4 HKLM\SYSTEM\ControlSet001\Services\{592EF604-1449-41AA-9D00-3A1F262B0400}\Parameters\Tcpip\LeaseTerminatesTime: 0x50345F48 HKLM\SYSTEM\CurrentControlSet\Services\Dhcp\Parameters\{592EF604-1449-41AA-9D00-3A1F262B0400}: 06 00 00 00 00 00 00 00 04 00 00 00 00 00 00 00 C4 5B 34 50 C0 A8 E0 01 0F 00 00 00 00 00 00 00 0B 00 00 00 00 00 00 00 C4 5B 34 50 6C 6F 63 61 6C 64 6F 6D 61 69 6E 00 01 00 00 00 00 00 00 00 04 00 00 00 00 00 00 00 C4 5B 34 50 FF FF FF 00 33 00 00 00 00 00 00 00 04 00 00 00 00 00 00 00 C4 5B 34 50 00 00 07 08 36 00 00 00 00 00 00 00 04 00 00 00 00 00 00 00 C4 5B 34 50 C0 A8 E0 FE 35 00 00 00 00 00 00 00 01 00 00 00 00 00 00 00 C4 5B 34 50 05 00 00 00 HKLM\SYSTEM\CurrentControlSet\Services\Dhcp\Parameters\{592EF604-1449-41AA-9D00-3A1F262B0400}: 06 00 00 00 00 00 00 00 04 00 00 00 00 00 00 00 48 5F 34 50 C0 A8 E0 01 0F 00 00 00 00 00 00 00 0B 00 00 00 00 00 00 00 48 5F 34 50 6C 6F 63 61 6C 64 6F 6D 61 69 6E 00 01 00 00 00 00 00 00 00 04 00 00 00 00 00 00 00 48 5F 34 50 FF FF FF 00 33 00 00 00 00 00 00 00 04 00 00 00 00 00 00 00 48 5F 34 50 00 00 07 08 36 00 00 00 00 00 00 00 04 00 00 00 00 00 00 00 48 5F 34 50 C0 A8 E0 FE 35 00 00 00 00 00 00 00 01 00 00 00 00 00 00 00 48 5F 34 50 05 00 00 00 HKLM\SYSTEM\CurrentControlSet\Services\Schedule\NextAtJobId: 0x00000001 HKLM\SYSTEM\CurrentControlSet\Services\Schedule\NextAtJobId: 0x00000031 HKLM\SYSTEM\CurrentControlSet\Services\SharedAccess\Epoch\Epoch: 0x00000035 HKLM\SYSTEM\CurrentControlSet\Services\SharedAccess\Epoch\Epoch: 0x00000036 HKLM\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{592EF604-1449-41AA-9D00-3A1F262B0400}\LeaseObtainedTime: 0x503454BC HKLM\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{592EF604-1449-41AA-9D00-3A1F262B0400}\LeaseObtainedTime: 0x50345840 HKLM\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{592EF604-1449-41AA-9D00-3A1F262B0400}\T1: 0x50345840 HKLM\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{592EF604-1449-41AA-9D00-3A1F262B0400}\T1: 0x50345BC4 HKLM\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{592EF604-1449-41AA-9D00-3A1F262B0400}\T2: 0x50345AE3 HKLM\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{592EF604-1449-41AA-9D00-3A1F262B0400}\T2: 0x50345E67 HKLM\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{592EF604-1449-41AA-9D00-3A1F262B0400}\LeaseTerminatesTime: 0x50345BC4 HKLM\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{592EF604-1449-41AA-9D00-3A1F262B0400}\LeaseTerminatesTime: 0x50345F48 HKLM\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{592EF604-1449-41AA-9D00-3A1F262B0400}\DhcpRetryTime: 0x00000384 HKLM\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{592EF604-1449-41AA-9D00-3A1F262B0400}\DhcpRetryTime: 0x00000383 HKLM\SYSTEM\CurrentControlSet\Services\{592EF604-1449-41AA-9D00-3A1F262B0400}\Parameters\Tcpip\LeaseObtainedTime: 0x503454BC HKLM\SYSTEM\CurrentControlSet\Services\{592EF604-1449-41AA-9D00-3A1F262B0400}\Parameters\Tcpip\LeaseObtainedTime: 0x50345840 HKLM\SYSTEM\CurrentControlSet\Services\{592EF604-1449-41AA-9D00-3A1F262B0400}\Parameters\Tcpip\T1: 0x50345840 HKLM\SYSTEM\CurrentControlSet\Services\{592EF604-1449-41AA-9D00-3A1F262B0400}\Parameters\Tcpip\T1: 0x50345BC4 HKLM\SYSTEM\CurrentControlSet\Services\{592EF604-1449-41AA-9D00-3A1F262B0400}\Parameters\Tcpip\T2: 0x50345AE3 HKLM\SYSTEM\CurrentControlSet\Services\{592EF604-1449-41AA-9D00-3A1F262B0400}\Parameters\Tcpip\T2: 0x50345E67 HKLM\SYSTEM\CurrentControlSet\Services\{592EF604-1449-41AA-9D00-3A1F262B0400}\Parameters\Tcpip\LeaseTerminatesTime: 0x50345BC4 HKLM\SYSTEM\CurrentControlSet\Services\{592EF604-1449-41AA-9D00-3A1F262B0400}\Parameters\Tcpip\LeaseTerminatesTime: 0x50345F48 HKU\S-1-5-21-73586283-616249376-1177238915-500\Software\Microsoft\Windows\CurrentVersion\Explorer\UserAssist\{75048700-EF1F-11D0-9888-006097DEACF9}\Count\HRZR_EHACNGU: 01 00 00 00 52 00 00 00 20 B8 CA B2 19 80 CD 01 HKU\S-1-5-21-73586283-616249376-1177238915-500\Software\Microsoft\Windows\CurrentVersion\Explorer\UserAssist\{75048700-EF1F-11D0-9888-006097DEACF9}\Count\HRZR_EHACNGU: 01 00 00 00 53 00 00 00 90 71 F1 BC 19 80 CD 01 HKU\S-1-5-21-73586283-616249376-1177238915-500\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Connections\SavedLegacySettings: 46 00 00 00 07 00 00 00 01 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 04 00 00 00 00 00 00 00 30 18 DF CA 34 5A CD 01 00 00 00 00 00 00 00 00 00 00 00 00 01 00 00 00 02 00 00 00 C0 A8 C8 83 00 00 00 00 00 00 00 00 96 C9 23 AA 30 B2 59 16 00 00 00 00 02 00 00 00 00 00 00 00 44 01 00 00 18 04 00 00 03 00 00 00 1B 9A 07 00 1B 9A 07 00 00 00 00 00 48 00 00 00 50 00 00 00 48 02 00 00 00 00 00 00 01 00 02 00 10 00 00 00 02 00 01 00 06 00 00 00 EF 9B 07 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 02 00 00 00 1B 9A 07 00 HKU\S-1-5-21-73586283-616249376-1177238915-500\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Connections\SavedLegacySettings: 46 00 00 00 0D 00 00 00 01 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 04 00 00 00 00 00 00 00 30 18 DF CA 34 5A CD 01 00 00 00 00 00 00 00 00 00 00 00 00 01 00 00 00 02 00 00 00 C0 A8 C8 83 00 00 00 00 00 00 00 00 96 C9 23 AA 30 B2 59 16 00 00 00 00 02 00 00 00 00 00 00 00 44 01 00 00 18 04 00 00 03 00 00 00 1B 9A 07 00 1B 9A 07 00 00 00 00 00 48 00 00 00 50 00 00 00 48 02 00 00 00 00 00 00 01 00 02 00 10 00 00 00 02 00 01 00 06 00 00 00 EF 9B 07 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 02 00 00 00 1B 9A 07 00 HKU\S-1-5-21-73586283-616249376-1177238915-500\SessionInformation\ProgramCount: 0x00000002 HKU\S-1-5-21-73586283-616249376-1177238915-500\SessionInformation\ProgramCount: 0x00000003 ---------------------------------- Total changes:38 ----------------------------------