Not a member of Pastebin yet?
Sign Up,
it unlocks many cool features!
- SetValue [23]
- key \REGISTRY\MACHINE\SOFTWARE\Policies\Microsoft\Windows Defender
- process C:\Windows\System32\wscript.exe (v. 5.8.7600.16385)
- valueType REG_DWORD
- value DisableAntiSpyware
- valueDataSize 4
- data
- 00000001
- key \REGISTRY\MACHINE\SOFTWARE\Policies\Microsoft\Windows Defender\Real-Time Protection
- process C:\Windows\System32\wscript.exe (v. 5.8.7600.16385)
- valueType REG_DWORD
- value DisableBehaviorMonitoring
- valueDataSize 4
- data
- 00000001
- key \REGISTRY\MACHINE\SOFTWARE\Policies\Microsoft\Windows Defender\Real-Time Protection
- process C:\Windows\System32\wscript.exe (v. 5.8.7600.16385)
- valueType REG_DWORD
- value DisableOnAccessProtection
- valueDataSize 4
- data
- 00000001
- key \REGISTRY\MACHINE\SOFTWARE\Policies\Microsoft\Windows Defender\Real-Time Protection
- process C:\Windows\System32\wscript.exe (v. 5.8.7600.16385)
- valueType REG_DWORD
- value DisableScanOnRealtimeEnable
- valueDataSize 4
- data
- 00000001
- key \REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System
- process C:\Windows\System32\wscript.exe (v. 5.8.7600.16385)
- valueType REG_DWORD
- value EnableLUA
- valueDataSize 4
- data
- 00000000
- key \REGISTRY\MACHINE\SOFTWARE\Microsoft\Tracing\Wscript_RASAPI32
- process C:\Windows\System32\wscript.exe (v. 5.8.7600.16385)
- valueType REG_DWORD
- value EnableFileTracing
- valueDataSize 4
- data
- 00000000
- key \REGISTRY\MACHINE\SOFTWARE\Microsoft\Tracing\Wscript_RASAPI32
- process C:\Windows\System32\wscript.exe (v. 5.8.7600.16385)
- valueType REG_DWORD
- value EnableConsoleTracing
- valueDataSize 4
- data
- 00000000
- key \REGISTRY\MACHINE\SOFTWARE\Microsoft\Tracing\Wscript_RASAPI32
- process C:\Windows\System32\wscript.exe (v. 5.8.7600.16385)
- valueType REG_DWORD
- value FileTracingMask
- valueDataSize 4
- data
- ffff0000
- key \REGISTRY\MACHINE\SOFTWARE\Microsoft\Tracing\Wscript_RASAPI32
- process C:\Windows\System32\wscript.exe (v. 5.8.7600.16385)
- valueType REG_DWORD
- value ConsoleTracingMask
- valueDataSize 4
- data
- ffff0000
- key \REGISTRY\MACHINE\SOFTWARE\Microsoft\Tracing\Wscript_RASAPI32
- process C:\Windows\System32\wscript.exe (v. 5.8.7600.16385)
- valueType REG_DWORD
- value MaxFileSize
- valueDataSize 4
- data
- 00100000
- key \REGISTRY\MACHINE\SOFTWARE\Microsoft\Tracing\Wscript_RASAPI32
- process C:\Windows\System32\wscript.exe (v. 5.8.7600.16385)
- valueType REG_EXPAND_SZ
- value FileDirectory
- valueDataSize 34
- data
- %windir%\tracing
- key \REGISTRY\MACHINE\SOFTWARE\Microsoft\Tracing\Wscript_RASMANCS
- process C:\Windows\System32\wscript.exe (v. 5.8.7600.16385)
- valueType REG_DWORD
- value EnableFileTracing
- valueDataSize 4
- data
- 00000000
- key \REGISTRY\MACHINE\SOFTWARE\Microsoft\Tracing\Wscript_RASMANCS
- process C:\Windows\System32\wscript.exe (v. 5.8.7600.16385)
- valueType REG_DWORD
- value EnableConsoleTracing
- valueDataSize 4
- data
- 00000000
- key \REGISTRY\MACHINE\SOFTWARE\Microsoft\Tracing\Wscript_RASMANCS
- process C:\Windows\System32\wscript.exe (v. 5.8.7600.16385)
- valueType REG_DWORD
- value FileTracingMask
- valueDataSize 4
- data
- ffff0000
- key \REGISTRY\MACHINE\SOFTWARE\Microsoft\Tracing\Wscript_RASMANCS
- process C:\Windows\System32\wscript.exe (v. 5.8.7600.16385)
- valueType REG_DWORD
- value ConsoleTracingMask
- valueDataSize 4
- data
- ffff0000
- key \REGISTRY\MACHINE\SOFTWARE\Microsoft\Tracing\Wscript_RASMANCS
- process C:\Windows\System32\wscript.exe (v. 5.8.7600.16385)
- valueType REG_DWORD
- value MaxFileSize
- valueDataSize 4
- data
- 00100000
- key \REGISTRY\MACHINE\SOFTWARE\Microsoft\Tracing\Wscript_RASMANCS
- process C:\Windows\System32\wscript.exe (v. 5.8.7600.16385)
- valueType REG_EXPAND_SZ
- value FileDirectory
- valueDataSize 34
- data
- %windir%\tracing
- key \REGISTRY\USER\S-1-5-21-3558273304-2305715256-1486658336-1000\Software\Microsoft\Windows\CurrentVersion\Internet Settings
- process C:\Windows\System32\wscript.exe (v. 5.8.7600.16385)
- valueType REG_DWORD
- value ProxyEnable
- valueDataSize 4
- data
- 00000000
- key \REGISTRY\USER\S-1-5-21-3558273304-2305715256-1486658336-1000\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Connections
- process C:\Windows\System32\wscript.exe (v. 5.8.7600.16385)
- valueType REG_BINARY
- value SavedLegacySettings
- valueDataSize 312
- data
- 46000000ba000000090000000000000000000000000000000400000000000000c0a965f9998cd201000000000000000000000000020000001700000000000000fe80000000000000382e2adbe237c9510b000000000000001700000000000000fe80000000000000382e2adbe237c9510b000000000000001c00000000000000000000000000000000000000000000000000000000000000170000000000000000000000000000000000ffffc0a80167000000000000000002000000c0a801670000000000000000000000000000000000000000000000000c00000c3b23000070264600b0464500000000000400000000000000010000000300000000000000000000006c5b3b00feffffff0c00000002000000010000000000000080000000000000000000000000000000000000000000000000000000
- key \REGISTRY\USER\S-1-5-21-3558273304-2305715256-1486658336-1000\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
- process C:\Windows\System32\wscript.exe (v. 5.8.7600.16385)
- valueType REG_DWORD
- value UNCAsIntranet
- valueDataSize 4
- data
- 00000000
- key \REGISTRY\USER\S-1-5-21-3558273304-2305715256-1486658336-1000\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
- process C:\Windows\System32\wscript.exe (v. 5.8.7600.16385)
- valueType REG_DWORD
- value AutoDetect
- valueDataSize 4
- data
- 00000001
- key \REGISTRY\USER\S-1-5-21-3558273304-2305715256-1486658336-1000\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
- process C:\Windows\System32\wscript.exe (v. 5.8.7600.16385)
- valueType REG_DWORD
- value UNCAsIntranet
- valueDataSize 4
- data
- 00000000
- key \REGISTRY\USER\S-1-5-21-3558273304-2305715256-1486658336-1000\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
- process C:\Windows\System32\wscript.exe (v. 5.8.7600.16385)
- valueType REG_DWORD
- value AutoDetect
- valueDataSize 4
- data
- 00000001
- CreateKey [5]
- key \REGISTRY\MACHINE\SOFTWARE\Policies\Microsoft\Windows Defender
- process C:\Windows\System32\wscript.exe (v. 5.8.7600.16385)
- key \REGISTRY\MACHINE\SOFTWARE\Policies\Microsoft\Windows Defender\Real-Time Protection
- process C:\Windows\System32\wscript.exe (v. 5.8.7600.16385)
- key \REGISTRY\MACHINE\Software\Microsoft\Tracing\Wscript_RASAPI32
- process C:\Windows\System32\wscript.exe (v. 5.8.7600.16385)
- key \REGISTRY\MACHINE\Software\Microsoft\Tracing\Wscript_RASMANCS
- process C:\Windows\System32\wscript.exe (v. 5.8.7600.16385)
- key \REGISTRY\\REGISTRY\MACHINE\SYSTEM\ControlSet001\Services\Tcpip\Parameters
- process C:\Windows\System32\wscript.exe (v. 5.8.7600.16385)
- OpenKey [13]
- key \REGISTRY\USER\S-1-5-21-3558273304-2305715256-1486658336-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders
- process C:\Windows\System32\wscript.exe (v. 5.8.7600.16385)
- key \REGISTRY\MACHINE\Software\Microsoft\Windows NT\CurrentVersion\ProfileList\S-1-5-21-3558273304-2305715256-1486658336-1000
- process C:\Windows\System32\wscript.exe (v. 5.8.7600.16385)
- key \REGISTRY\USER\S-1-5-21-3558273304-2305715256-1486658336-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders
- process C:\Windows\System32\wscript.exe (v. 5.8.7600.16385)
- key \REGISTRY\MACHINE\Software\Microsoft\Windows NT\CurrentVersion\ProfileList
- process C:\Windows\System32\wscript.exe (v. 5.8.7600.16385)
- key \REGISTRY\MACHINE\Software\Microsoft\Windows NT\CurrentVersion\ProfileList
- process C:\Windows\System32\wscript.exe (v. 5.8.7600.16385)
- key \REGISTRY\MACHINE\Software\Microsoft\Windows NT\CurrentVersion\ProfileList
- process C:\Windows\System32\wscript.exe (v. 5.8.7600.16385)
- key \REGISTRY\USER\S-1-5-21-3558273304-2305715256-1486658336-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders
- process C:\Windows\System32\wscript.exe (v. 5.8.7600.16385)
- key \REGISTRY\MACHINE\Software\Microsoft\Windows NT\CurrentVersion\ProfileList\S-1-5-21-3558273304-2305715256-1486658336-1000
- process C:\Windows\System32\wscript.exe (v. 5.8.7600.16385)
- key \REGISTRY\USER\S-1-5-21-3558273304-2305715256-1486658336-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders
- process C:\Windows\System32\wscript.exe (v. 5.8.7600.16385)
- key \REGISTRY\MACHINE\Software\Microsoft\Windows NT\CurrentVersion\ProfileList\S-1-5-21-3558273304-2305715256-1486658336-1000
- process C:\Windows\System32\wscript.exe (v. 5.8.7600.16385)
- key \REGISTRY\USER\S-1-5-21-3558273304-2305715256-1486658336-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders
- process C:\Windows\System32\wscript.exe (v. 5.8.7600.16385)
- key \REGISTRY\MACHINE\Software\Microsoft\Windows NT\CurrentVersion\ProfileList\S-1-5-21-3558273304-2305715256-1486658336-1000
- process C:\Windows\System32\wscript.exe (v. 5.8.7600.16385)
- key \REGISTRY\USER\S-1-5-21-3558273304-2305715256-1486658336-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders
- process C:\Windows\System32\wscript.exe (v. 5.8.7600.16385)
Add Comment
Please, Sign In to add comment