|
| Key Added |
| HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer |
| HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Network |
| HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Uninstall |
| HKLM\SYSTEM\CurrentControlSet\Control\Print\Printers |
| HKLM\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_FASTFAT\0000\Control |
| HKU\S-1-5-21-1214440339-854245398-2048386851-1003\Software\Microsoft\Windows\CurrentVersion\Policies\Network |
| HKU\S-1-5-21-1214440339-854245398-2048386851-1003\Software\Microsoft\Windows\CurrentVersion\Policies\System |
| HKU\S-1-5-21-1214440339-854245398-2048386851-1003\Software\Microsoft\Windows\CurrentVersion\Policies\Uninstall |
| HKU\S-1-5-21-1214440339-854245398-2048386851-1003\Software\Policies\Microsoft\Windows |
| HKU\S-1-5-21-1214440339-854245398-2048386851-1003\Software\Policies\Microsoft\Windows\System |
| Value Added |
| HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\system\DisableRegistryTools: 0x00000000 |
| HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\system\DisableTaskMgr: 0x00000000 |
| HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\system\NoDispCPL: 0x00000000 |
| HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\NoFolderOptions: 0x00000000 |
| HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\NoPropertiesMyComputer: 0x00000000 |
| HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\NoActiveDesktop: 0x00000000 |
| HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\NoControlPanel: 0x00000000 |
| HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\NoPrinters: 0x00000000 |
| HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\NoSetFolders: 0x00000000 |
| HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\NoViewContextMenu: 0x00000000 |
| HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\NoNetHood: 0x00000000 |
| HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\NoDesktop: 0x00000000 |
| HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\NoFileMenu: 0x00000000 |
| HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\NoRun: 0x00000000 |
| HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\NoFind: 0x00000000 |
| HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Network\NoNetSetup: 0x00000000 |
| HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Uninstall\NoAddRemovePrograms: 0x00000000 |
| HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Uninstall\NoRemovePage: 0x00000000 |
| HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Uninstall\NoAddPage: 0x00000000 |
| HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\USBcillin: "C:\WINDOWS\system32\USBcillin.exe" |
| HKLM\SYSTEM\CurrentControlSet\Control\Print\Printers\DefaultSpoolDirectory: "C:\WINDOWS\System32\spool\PRINTERS" |
| HKLM\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_FASTFAT\0000\Control\ActiveService: "Fastfat" |
| HKLM\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_NPF\0000\Control\ActiveService: "NPF" |
|
HKU\S-1-5-21-1214440339-854245398-2048386851-1003\Software\Microsoft\Internet
Explorer\Main\Window Title: "Windows Internet Explorer" |
|
HKU\S-1-5-21-1214440339-854245398-2048386851-1003\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\NoFolderOptions:
0x00000000 |
|
HKU\S-1-5-21-1214440339-854245398-2048386851-1003\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\NoPropertiesMyComputer:
0x00000000 |
|
HKU\S-1-5-21-1214440339-854245398-2048386851-1003\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\NoActiveDesktop:
0x00000000 |
|
HKU\S-1-5-21-1214440339-854245398-2048386851-1003\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\NoControlPanel:
0x00000000 |
|
HKU\S-1-5-21-1214440339-854245398-2048386851-1003\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\NoPrinters:
0x00000000 |
|
HKU\S-1-5-21-1214440339-854245398-2048386851-1003\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\NoSetFolders:
0x00000000 |
|
HKU\S-1-5-21-1214440339-854245398-2048386851-1003\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\NoViewContextMenu:
0x00000000 |
|
HKU\S-1-5-21-1214440339-854245398-2048386851-1003\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\NoNetHood:
0x00000000 |
|
HKU\S-1-5-21-1214440339-854245398-2048386851-1003\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\NoDesktop:
0x00000000 |
|
HKU\S-1-5-21-1214440339-854245398-2048386851-1003\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\NoFileMenu:
0x00000000 |
|
HKU\S-1-5-21-1214440339-854245398-2048386851-1003\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\NoRun:
0x00000000 |
|
HKU\S-1-5-21-1214440339-854245398-2048386851-1003\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\NoFind:
0x00000000 |
|
HKU\S-1-5-21-1214440339-854245398-2048386851-1003\Software\Microsoft\Windows\CurrentVersion\Policies\Network\NoNetSetup:
0x00000000 |
|
HKU\S-1-5-21-1214440339-854245398-2048386851-1003\Software\Microsoft\Windows\CurrentVersion\Policies\System\DisableRegistryTools:
0x00000000 |
|
HKU\S-1-5-21-1214440339-854245398-2048386851-1003\Software\Microsoft\Windows\CurrentVersion\Policies\System\DisableTaskMgr:
0x00000000 |
|
HKU\S-1-5-21-1214440339-854245398-2048386851-1003\Software\Microsoft\Windows\CurrentVersion\Policies\System\NoDispCPL:
0x00000000 |
|
HKU\S-1-5-21-1214440339-854245398-2048386851-1003\Software\Microsoft\Windows\CurrentVersion\Policies\Uninstall\NoAddRemovePrograms:
0x00000000 |
|
HKU\S-1-5-21-1214440339-854245398-2048386851-1003\Software\Microsoft\Windows\CurrentVersion\Policies\Uninstall\NoRemovePage:
0x00000000 |
|
HKU\S-1-5-21-1214440339-854245398-2048386851-1003\Software\Microsoft\Windows\CurrentVersion\Policies\Uninstall\NoAddPage:
0x00000000 |
| HKU\S-1-5-21-1214440339-854245398-2048386851-1003\Software\Policies\Microsoft\Windows\System\DisableCMD: 0x00000000 |
| Value Modified |
| HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Shell: "Explorer.exe" |
| HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Shell: "explorer.exe" |
| HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Userinit: "C:\WINDOWS\system32\userinit.exe," |
| HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Userinit: "C:\WINDOWS\system32\userinit.exe" |
| HKLM\SYSTEM\CurrentControlSet\Control\Print\Providers\LogonTime: 1C 79 3B 00 90 CF C9 01 |
| HKLM\SYSTEM\CurrentControlSet\Control\Print\Providers\LogonTime: 70 AE A0 7E 92 CF C9 01 |
|
HKU\S-1-5-21-1214440339-854245398-2048386851-1003\Software\Microsoft\Internet
Explorer\Main\Start Page:
"http://www.microsoft.com/isapi/redir.dll?prd=ie&pver=6&ar=msnhome"
|
| HKU\S-1-5-21-1214440339-854245398-2048386851-1003\Software\Microsoft\Internet Explorer\Main\Start Page: "about:blank" |