|
| Key Added |
| HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Folder\Hidden\HideFileExt |
| HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Folder\Hidden\ShowFullPath |
| HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Folder\Hidden\ShowFullPathAddress |
| HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Folder\Hidden\SuperHidden |
| HKU\S-1-5-21-1214440339-854245398-2048386851-1003\Software\Microsoft\Windows\CurrentVersion\Policies\System |
| Value Added |
| HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Folder\Hidden\HideFileExt\CheckedValue: 0x00000002 |
| HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Folder\Hidden\HideFileExt\DefaultValue: 0x00000002 |
| HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Folder\Hidden\HideFileExt\UncheckedValue: 0x00000002 |
| HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Folder\Hidden\ShowFullPath\DefaultValue: 0x00000000 |
| HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Folder\Hidden\ShowFullPath\CheckedValue: 0x00000000 |
| HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Folder\Hidden\ShowFullPath\UncheckedValue: 0x00000000 |
| HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Folder\Hidden\ShowFullPathAddress\CheckedValue: 0x00000000 |
| HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Folder\Hidden\ShowFullPathAddress\DefaultValue: 0x00000000 |
| HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Folder\Hidden\ShowFullPathAddress\UncheckedValue: 0x00000000 |
| HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Folder\Hidden\SuperHidden\DefaultValue: 0x00000002 |
| HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Folder\Hidden\SuperHidden\CheckedValue: 0x00000002 |
| HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Folder\Hidden\SuperHidden\UncheckedValue: 0x00000002 |
| HKLM\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_NPF\0000\Control\ActiveService: "NPF" |
| HKU\S-1-5-21-1214440339-854245398-2048386851-1003\Software\Microsoft\Command Processor\Autorun: "exit" |
|
HKU\S-1-5-21-1214440339-854245398-2048386851-1003\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\NoFolderOptions:
0x00000001 |
|
HKU\S-1-5-21-1214440339-854245398-2048386851-1003\Software\Microsoft\Windows\CurrentVersion\Policies\System\DisableRegistryTools:
0x00000001 |
|
HKU\S-1-5-21-1214440339-854245398-2048386851-1003\Software\Microsoft\Windows
NT\CurrentVersion\Winlogon\shell: "explorer.exe script.exe" |
| Value Modified |
| HKLM\SOFTWARE\Microsoft\Command Processor\AutoRun: "" |
| HKLM\SOFTWARE\Microsoft\Command Processor\AutoRun: "exit" |
| HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Folder\Hidden\SHOWALL\CheckedValue: 0x00000001 |
| HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Folder\Hidden\SHOWALL\CheckedValue: 0x00000000 |
| HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Folder\Hidden\SHOWALL\DefaultValue: 0x00000002 |
| HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Folder\Hidden\SHOWALL\DefaultValue: 0x00000000 |
| HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Shell: "Explorer.exe" |
| HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Shell: "explorer.exe script.exe" |
|
HKU\S-1-5-21-1214440339-854245398-2048386851-1003\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Hidden:
0x00000001 |
|
HKU\S-1-5-21-1214440339-854245398-2048386851-1003\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Hidden:
0x00000002 |
|
HKU\S-1-5-21-1214440339-854245398-2048386851-1003\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced\HideFileExt:
0x00000000 |
|
HKU\S-1-5-21-1214440339-854245398-2048386851-1003\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced\HideFileExt:
0x00000001 |
|
HKU\S-1-5-21-1214440339-854245398-2048386851-1003\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced\SuperHidden:
0x00000000 |
|
HKU\S-1-5-21-1214440339-854245398-2048386851-1003\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced\SuperHidden:
0x00000001 |
|
HKU\S-1-5-21-1214440339-854245398-2048386851-1003\Software\Microsoft\Windows\CurrentVersion\Explorer\CabinetState\FullPathAddress:
0x00000001 |
|
HKU\S-1-5-21-1214440339-854245398-2048386851-1003\Software\Microsoft\Windows\CurrentVersion\Explorer\CabinetState\FullPathAddress:
0x00000000 |