Advertisement
Not a member of Pastebin yet?
Sign Up,
it unlocks many cool features!
- [HKEY_LOCAL_MACHINE\SAM\SAM\Domains\Builtin\Aliases\Members\S-1-5-80-956008885-3418522649-1831038044-1853292631]
- @=""
- 876402C0(2271478464) = Ƞ
- [HKEY_LOCAL_MACHINE\SAM\SAM\Domains\Builtin\Aliases\Members\S-1-5-80-956008885-3418522649-1831038044-1853292631\876402C0]
- @="Ƞ"
- TrustedInstaller RID (LUID)
- CLEARLY THE -PART(501,1000,ETC)
- S-1-5-80-956008885-3418522649-1831038044-1853292631
- FULL DOMAIN (THE SID HAS THE ENDING SUFFIX 2271478464
- S-1-5-80-956008885-3418522649-1831038044-1853292631-2271478464
- *********** FULL TRUSTED INSTALLER SID *************
- **** ROOT UNICODE DESTROYS THE DOMAIN ****
- **** DATA IN '.REG' FORMAT AS ORIGINAL IN NOTEPAD LINE BREAKS/SPACING ***
- [HKEY_LOCAL_MACHINE\SAM\SAM\Domains\Builtin\Aliases\Members\S-1-5]
- @=hex:
- 00000004] SZ
- @="ȡ"
- 0000000B] SZ
- @="ȡ"
- 00000011] SZ
- @="ȸ"
- Windows Registry Editor Version 5.00
- [HKEY_LOCAL_MACHINE\SAM\SAM\Domains\Builtin\Aliases\Members\S-1-5\000003E7]
- @="ϩ"
- [HKEY_LOCAL_MACHINE\SAM\SAM\Domains\Builtin\Aliases\Members\S-1-5-21-3947544656-2014248660-3822616995\000003E7]
- @="ϩ"
- -----------------------------------------------
- \S-1-5-21-3857256076-1075314236-4170261994]
- @=hex(5):
- 000001F4(500) = Ƞ REG_SZ, LIKE TRUSTEDINSTALLER
- \000001F4] WHICH IT CREATED ITSELF
- @="Ƞ" ALONG WITH S1580 DOMAIN
- 000001F5(501) = Ƞ REG_SZ
- \000001F5]
- @="Ƞ"
- 000001F7(503) = Ʌ REG_SZ
- \000001F7]
- @="Ʌ"
- 000003EB(1003) = ȡ , REG_EXPAND_SZ
- 000003EB]
- @=hex(2):21,02,00,00,20,02,00,00
- 000003EC(1004) = ȡ , REG_SZ, LIKE THE S1580
- \000003EC] DOMAIN ALIAS ONE, AUTO-
- @="ȡ" CREATED, AND ALSO A SZ
- THIS WAS WHERE TRUSTED-
- INSTALLER WENT FIRST,
- SIMULTANEOUSLY CLONED
- INTO THE S1580 DOMAIN
- *** REMOVES INSTANTLY 'TRUSTEDINSTALLER' *** BY LUSRMGR AUTOMATICALLY
- REPLACING IN ITS HEX/RID/LUID STATE INTO THE S1580 DOMAIN ALIAS BELOW
- Registry Key Change Type Value Name Value Data Value Type Data Length Value Data Changed To Value Type Changed To Data Length Changed To Key Modified Time 1 Key Modified Time 2
- HKEY_LOCAL_MACHINE\SAM\SAM\Domains\Account\Users\000003EC Removed Key 3/31/2024 11:18:47 PM
- HKEY_LOCAL_MACHINE\SAM\SAM\Domains\Account\Users\Names\TRUSTEDINSTALLER Removed Key 3/31/2024 11:18:47 PM
- A REVERSE HEXIDECIMAL STRING
- FROM ITS DOMAIN (NT SERVICE)
- S-1-5-80-956, MEANING IT USES
- ITS DOMAIN NEVER ITS RID
- AS WE DO AS GUEST/"SYSTEM"
- TAKEOWN = DESKTOP-12384
- 876402C0
- WHICH IS 2271478464, THE LAST
- STRING IN ITS DOMAIN SID
- THAT MEANS THE RID OF TRUSTED IS
- HIDDEN WITHIN THE DOMAIN SID ITSELF
- SO REFERENCES TO IT MAY BE SHORTER
- TO ACCOUNT FOR THAT SIGNIFICANT DIFF
- IN SID LENGTH.
- C0026487 IN DECI:
- 3221382279
- S-1-5- 80 = 50
- 21 02 00 00 00 00 00 00 00 01 00 00 03 00 01 00 00 01 00 00 0A 00 00 00 00 00 00 00 0C 01 00 00 D6 00 00 00 00 00 00 00 E4 01 00 00 34 00 00 00 03 00 00 00 01 00 14 80 E0 00 00 00 F0 00 00 00 14 00 00 00 44 00 00 00 02 00 30 00 02 00 00 00 02 C0 14 00 13 00 05 01 01 01 00 00 00 00 00 01 00 00 00 00 02 C0 14 00 FF FF 1F 00 01 01 00 00 00 00 00 05 07 00 00 00 02 00 9C 00 05 00 00 00 00 00 14 00 0C 00 02 00 01 01 00 00 00 00 00 01 00 00 00 00 00 00 18 00 1F 00 0F 00 01 02 00 00 00 00 00 05 20 00 00 00 20 02 00 00 00 00 18 00 1F 00 0F 00 01 02 00 00 00 00 00 05 20 00 00 00 24 02 00 00 00 00 18 00 1F 00 0F 00 01 02 00 00 00 00 00 05 20 00 00 00 23 02 00 00 00 00 38 00 0C 00 02 00 01 0A 00 00 00 00 00 0F 03 00 00 00 00 04 00 00 DE A2 28 67 21 3E D2 AF 19 AD 5D 79 B0 C1 07 29 27 56 FC 20 D8 AD 66 F6 10 F2 68 FA DF 2A F8 0F 01 02 00 00 00 00 00 05 20 00 00 00 20 02 00 00 01 02 00 00 00 00 00 05 20 00 00 00 20 02 00 00 55 00 73 00 65 00 72 00 73 00 00 00 55 00 73 00 65 00 72 00 73 00 20 00 61 00 72 00 65 00 20 00 70 00 72 00 65 00 76 00 65 00 6E 00 74 00 65 00 64 00 20 00 66 00 72 00 6F 00 6D 00 20 00 6D 00 61 00 6B 00 69 00 6E 00 67 00 20 00 61 00 63 00 63 00 69 00 64 00 65 00 6E 00 74 00 61 00 6C 00 20 00 6F 00 72 00 20 00 69 00 6E 00 74 00 65 00 6E 00 74 00 69 00 6F 00 6E 00 61 00 6C 00 20 00 73 00 79 00 73 00 74 00 65 00 6D 00 2D 00 77 00 69 00 64 00 65 00 20 00 63 00 68 00 61 00 6E 00 67 00 65 00 73 00 20 00 61 00 6E 00 64 00 20 00 63 00 61 00 6E 00 20 00 72 00 75 00 6E 00 20 00 6D 00 6F 00 73 00 74 00 20 00 61 00 70 00 70 00 6C 00 69 00 63 00 61 00 74 00 69 00 6F 00 6E 00 73 00 00 00 01 01 00 00 00 00 00 05 04 00 00 00 01 01 00 00 00 00 00 05 0B 00 00 00 01 05 00 00 00 00 00 05 15 00 00 00 8C 0E E9 E5 3C FE 17 40 EA 25 91 F8 EB 03 00 00
- TRUSTEDINSTALLER IN USERS ONLY
- NOTE QUITE "NT SERVICE" YET
- DESPITE THE DOMAIN THERE
- IT HAS NO "ALIAS"
- NOW TO ADD A GENERIC GROUP, AND GET THE
- BINARY IT ASSOCIATES WITH THE DOMAIN
- SID INSTEAD OF THE NEW ONE IT WILL CREATE *
- ----------------------
- [HKEY_LOCAL_MACHINE\SAM\SAM\Domains\Builtin\Aliases\Members\S-1-5-80-956008885-3418522649-1831038044-1853292631]
- @=""
- 876402C0(2271478464) = Ƞ
- [HKEY_LOCAL_MACHINE\SAM\SAM\Domains\Builtin\Aliases\Members\S-1-5-80-956008885-3418522649-1831038044-1853292631\876402C0]
- @="Ƞ"
- TrustedInstaller RID (LUID)
- CLEARLY THE -PART(501,1000,ETC)
- S-1-5-80-956008885-3418522649-1831038044-1853292631
- FULL DOMAIN (THE SID HAS THE ENDING SUFFIX 2271478464
- S-1-5-80-956008885-3418522649-1831038044-1853292631-2271478464
- *********** FULL TRUSTED INSTALLER SID *************
- **** ROOT UNICODE DESTROYS THE DOMAIN ****
- **** DATA IN '.REG' FORMAT AS ORIGINAL IN NOTEPAD LINE BREAKS/SPACING ***
- [HKEY_LOCAL_MACHINE\SAM\SAM\Domains\Builtin\Aliases\Members\S-1-5]
- @=hex:
- 00000004] SZ
- @="ȡ"
- 0000000B] SZ
- @="ȡ"
- 00000011] SZ
- @="ȸ"
- -----------------------------------------------
- \S-1-5-21-3857256076-1075314236-4170261994]
- @=hex(5):
- 000001F4(500) = Ƞ REG_SZ, LIKE TRUSTEDINSTALLER
- \000001F4] WHICH IT CREATED ITSELF
- @="Ƞ" ALONG WITH S1580 DOMAIN
- 000001F5(501) = Ƞ REG_SZ
- \000001F5]
- @="Ƞ"
- 000001F7(503) = Ʌ REG_SZ
- \000001F7]
- @="Ʌ"
- 000003EB(1003) = ȡ , REG_EXPAND_SZ
- 000003EB]
- @=hex(2):21,02,00,00,20,02,00,00
- 000003EC(1004) = ȡ , REG_SZ, LIKE THE S1580
- \000003EC] DOMAIN ALIAS ONE, AUTO-
- @="ȡ" CREATED, AND ALSO A SZ
- THIS WAS WHERE TRUSTED-
- INSTALLER WENT FIRST,
- SIMULTANEOUSLY CLONED
- INTO THE S1580 DOMAIN
- *** REMOVES INSTANTLY 'TRUSTEDINSTALLER' *** BY LUSRMGR AUTOMATICALLY
- REPLACING IN ITS HEX/RID/LUID STATE INTO THE S1580 DOMAIN ALIAS BELOW
- Registry Key Change Type Value Name Value Data Value Type Data Length Value Data Changed To Value Type Changed To Data Length Changed To Key Modified Time 1 Key Modified Time 2
- HKEY_LOCAL_MACHINE\SAM\SAM\Domains\Account\Users\000003EC Removed Key 3/31/2024 11:18:47 PM
- HKEY_LOCAL_MACHINE\SAM\SAM\Domains\Account\Users\Names\TRUSTEDINSTALLER Removed Key 3/31/2024 11:18:47 PM
- A REVERSE HEXIDECIMAL STRING
- FROM ITS DOMAIN (NT SERVICE)
- S-1-5-80-956, MEANING IT USES
- ITS DOMAIN NEVER ITS RID
- AS WE DO AS GUEST/"SYSTEM"
- TAKEOWN = DESKTOP-12384
- 876402C0
- WHICH IS 2271478464, THE LAST
- STRING IN ITS DOMAIN SID
- THAT MEANS THE RID OF TRUSTED IS
- HIDDEN WITHIN THE DOMAIN SID ITSELF
- SO REFERENCES TO IT MAY BE SHORTER
- TO ACCOUNT FOR THAT SIGNIFICANT DIFF
- IN SID LENGTH.
- C0026487 IN DECI:
- 3221382279
- S-1-5- 80 = 50
- 21 02 00 00 00 00 00 00 00 01 00 00 03 00 01 00 00 01 00 00 0A 00 00 00 00 00 00 00 0C 01 00 00 D6 00 00 00 00 00 00 00 E4 01 00 00 34 00 00 00 03 00 00 00 01 00 14 80 E0 00 00 00 F0 00 00 00 14 00 00 00 44 00 00 00 02 00 30 00 02 00 00 00 02 C0 14 00 13 00 05 01 01 01 00 00 00 00 00 01 00 00 00 00 02 C0 14 00 FF FF 1F 00 01 01 00 00 00 00 00 05 07 00 00 00 02 00 9C 00 05 00 00 00 00 00 14 00 0C 00 02 00 01 01 00 00 00 00 00 01 00 00 00 00 00 00 18 00 1F 00 0F 00 01 02 00 00 00 00 00 05 20 00 00 00 20 02 00 00 00 00 18 00 1F 00 0F 00 01 02 00 00 00 00 00 05 20 00 00 00 24 02 00 00 00 00 18 00 1F 00 0F 00 01 02 00 00 00 00 00 05 20 00 00 00 23 02 00 00 00 00 38 00 0C 00 02 00 01 0A 00 00 00 00 00 0F 03 00 00 00 00 04 00 00 DE A2 28 67 21 3E D2 AF 19 AD 5D 79 B0 C1 07 29 27 56 FC 20 D8 AD 66 F6 10 F2 68 FA DF 2A F8 0F 01 02 00 00 00 00 00 05 20 00 00 00 20 02 00 00 01 02 00 00 00 00 00 05 20 00 00 00 20 02 00 00 55 00 73 00 65 00 72 00 73 00 00 00 55 00 73 00 65 00 72 00 73 00 20 00 61 00 72 00 65 00 20 00 70 00 72 00 65 00 76 00 65 00 6E 00 74 00 65 00 64 00 20 00 66 00 72 00 6F 00 6D 00 20 00 6D 00 61 00 6B 00 69 00 6E 00 67 00 20 00 61 00 63 00 63 00 69 00 64 00 65 00 6E 00 74 00 61 00 6C 00 20 00 6F 00 72 00 20 00 69 00 6E 00 74 00 65 00 6E 00 74 00 69 00 6F 00 6E 00 61 00 6C 00 20 00 73 00 79 00 73 00 74 00 65 00 6D 00 2D 00 77 00 69 00 64 00 65 00 20 00 63 00 68 00 61 00 6E 00 67 00 65 00 73 00 20 00 61 00 6E 00 64 00 20 00 63 00 61 00 6E 00 20 00 72 00 75 00 6E 00 20 00 6D 00 6F 00 73 00 74 00 20 00 61 00 70 00 70 00 6C 00 69 00 63 00 61 00 74 00 69 00 6F 00 6E 00 73 00 00 00 01 01 00 00 00 00 00 05 04 00 00 00 01 01 00 00 00 00 00 05 0B 00 00 00 01 05 00 00 00 00 00 05 15 00 00 00 8C 0E E9 E5 3C FE 17 40 EA 25 91 F8 EB 03 00 00
- TRUSTEDINSTALLER IN USERS ONLY
- NOTE QUITE "NT SERVICE" YET
- DESPITE THE DOMAIN THERE
- IT HAS NO "ALIAS"
- NOW TO ADD A GENERIC GROUP, AND GET THE
- BINARY IT ASSOCIATES WITH THE DOMAIN
- SID INSTEAD OF THE NEW ONE IT WILL CREATE *
- ----------------------
- Windows Registry Editor Version 5.00
- [HKEY_LOCAL_MACHINE\0\SAM\Domains\Account\Aliases\Members\S-1-5\00000012]
- @=hex(2):e9,03,00,00,ea,03,00,00
- [HKEY_LOCAL_MACHINE\0\SAM\Domains\Account\Users\00000012]
- "F"=hex:03,00,01,00,00,00,00,00,d7,de,9d,7a,ba,8c,da,01,00,00,00,00,00,00,00,\
- 00,c6,5c,ed,99,01,8c,da,01,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
- f4,01,00,00,01,02,00,00,10,02,00,00,00,00,00,00,00,00,01,00,01,00,00,00,00,\
- 00,00,00,00,00,04,00
- "V"=hex:00,00,00,00,f4,00,00,00,03,00,01,00,f4,00,00,00,1a,00,00,00,00,00,00,\
- 00,10,01,00,00,00,00,00,00,00,00,00,00,10,01,00,00,6c,00,00,00,00,00,00,00,\
- 7c,01,00,00,00,00,00,00,00,00,00,00,7c,01,00,00,00,00,00,00,00,00,00,00,7c,\
- 01,00,00,00,00,00,00,00,00,00,00,7c,01,00,00,00,00,00,00,00,00,00,00,7c,01,\
- 00,00,00,00,00,00,00,00,00,00,7c,01,00,00,00,00,00,00,00,00,00,00,7c,01,00,\
- 00,00,00,00,00,00,00,00,00,7c,01,00,00,15,00,00,00,a8,00,00,00,94,01,00,00,\
- 08,00,00,00,01,00,00,00,9c,01,00,00,18,00,00,00,00,00,00,00,b4,01,00,00,38,\
- 00,00,00,00,00,00,00,ec,01,00,00,18,00,00,00,00,00,00,00,04,02,00,00,18,00,\
- 00,00,00,00,00,00,01,00,14,80,d4,00,00,00,e4,00,00,00,14,00,00,00,44,00,00,\
- 00,02,00,30,00,02,00,00,00,02,c0,14,00,44,00,05,01,01,01,00,00,00,00,00,01,\
- 00,00,00,00,02,c0,14,00,ff,ff,1f,00,01,01,00,00,00,00,00,05,07,00,00,00,02,\
- 00,90,00,04,00,00,00,00,00,14,00,5b,03,02,00,01,01,00,00,00,00,00,01,00,00,\
- 00,00,00,00,18,00,ff,07,0f,00,01,02,00,00,00,00,00,05,20,00,00,00,20,02,00,\
- 00,00,00,38,00,1b,03,02,00,01,0a,00,00,00,00,00,0f,03,00,00,00,00,04,00,00,\
- de,a2,28,67,21,3e,d2,af,19,ad,5d,79,b0,c1,07,29,27,56,fc,20,d8,ad,66,f6,10,\
- f2,68,fa,df,2a,f8,0f,00,00,24,00,44,00,02,00,01,05,00,00,00,00,00,05,15,00,\
- 00,00,50,c0,4a,eb,d4,fe,0e,78,a3,81,d8,e3,f4,01,00,00,01,02,00,00,00,00,00,\
- 05,20,00,00,00,20,02,00,00,01,02,00,00,00,00,00,05,20,00,00,00,20,02,00,00,\
- 41,00,64,00,6d,00,69,00,6e,00,69,00,73,00,74,00,72,00,61,00,74,00,6f,00,72,\
- 00,64,00,42,00,75,00,69,00,6c,00,74,00,2d,00,69,00,6e,00,20,00,61,00,63,00,\
- 63,00,6f,00,75,00,6e,00,74,00,20,00,66,00,6f,00,72,00,20,00,61,00,64,00,6d,\
- 00,69,00,6e,00,69,00,73,00,74,00,65,00,72,00,69,00,6e,00,67,00,20,00,74,00,\
- 68,00,65,00,20,00,63,00,6f,00,6d,00,70,00,75,00,74,00,65,00,72,00,2f,00,64,\
- 00,6f,00,6d,00,61,00,69,00,6e,00,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,\
- ff,ff,ff,ff,ff,ff,ff,d4,bb,97,01,02,00,00,07,00,00,00,02,00,02,00,00,00,00,\
- 00,39,dd,25,26,fa,83,d5,38,47,2b,34,b6,43,41,20,02,02,00,02,00,10,00,00,00,\
- ac,c3,5a,2a,57,88,cb,34,c2,b2,29,61,94,26,ea,0d,62,b9,e2,c3,a7,ec,1d,2a,5a,\
- a6,4f,2a,b2,34,c5,27,23,29,46,df,8b,1f,d3,e7,74,c8,72,fd,30,08,f1,bf,02,00,\
- 02,00,00,00,00,00,7b,57,8e,72,f4,b8,0a,dd,1f,44,da,db,4d,90,ae,71,02,00,02,\
- 00,00,00,00,00,9b,45,aa,10,82,b6,15,e8,f3,d2,6b,49,68,80,83,a3
- "SupplementalCredentials"=hex:00,00,00,00,34,04,00,00,02,00,02,00,40,04,00,00,\
- e9,24,6c,60,54,cb,1e,67,b5,a5,5c,cf,ed,79,af,db,a5,42,97,ae,c7,07,b5,81,52,\
- 37,d8,b6,f9,f7,87,99,ef,70,d2,e0,12,2d,82,76,60,ed,6a,db,3a,b6,a4,38,91,63,\
- 36,f7,a0,92,54,b8,e5,3a,a7,d6,53,06,99,27,10,62,ef,05,ac,41,45,78,91,18,58,\
- b1,aa,a4,3c,90,7a,6a,dd,2d,00,17,0e,86,80,99,be,44,2a,a7,73,ed,c0,e8,21,8c,\
- ca,d0,0b,a4,1b,c1,3c,32,12,d1,eb,6e,5b,8d,ec,db,7f,31,f6,64,f5,a1,bd,60,4e,\
- a1,b8,f2,40,10,d8,94,63,ba,65,be,db,f1,ee,25,51,59,60,36,04,17,bb,d3,e0,e5,\
- 92,a4,bb,71,96,46,4b,3d,9b,7d,b1,0d,b5,d3,3a,ff,ea,08,27,e7,22,a5,ee,c2,ab,\
- f2,e2,b6,a4,d1,d2,7e,d8,79,cf,9f,4c,61,96,de,3b,51,6d,67,c4,51,2d,ec,c7,89,\
- 4a,ff,f0,60,d7,1d,c9,00,f9,8f,13,06,ee,6d,5a,51,20,12,3d,66,fc,6c,47,2b,8a,\
- de,da,ad,3d,ec,44,94,b7,10,c2,ca,6d,ce,d0,84,b5,9d,19,91,cc,b3,26,ab,df,bb,\
- c1,25,e9,a2,b0,1b,6e,95,e5,0e,da,18,11,26,0f,4a,51,55,93,4c,11,cb,de,d6,bc,\
- 10,73,2e,e2,75,e2,cc,8e,90,34,4d,c4,ee,ed,2a,fb,50,86,cd,f1,70,cc,7f,34,25,\
- 17,aa,a0,87,f7,a4,51,11,44,28,c4,9c,71,4d,78,86,44,38,1d,49,0a,01,3c,54,45,\
- 6d,3d,f5,4c,4d,48,06,f1,e5,f6,e6,82,76,3f,c8,2c,f6,68,31,82,df,c0,bc,66,87,\
- 2e,34,0f,d8,96,38,67,fb,30,f0,5b,de,7e,d6,f4,8a,c8,76,89,db,76,03,21,d0,99,\
- ca,11,9c,d1,e2,fc,fb,73,fe,e5,1d,c9,10,2d,d5,af,3d,8f,c1,a2,26,e0,e0,26,b9,\
- f9,36,0d,a2,6d,65,95,56,8a,60,0a,81,c4,34,90,1a,d2,1f,1a,4c,3f,1c,68,b7,f2,\
- f0,6a,fa,3f,c1,e0,ae,89,39,3f,94,87,70,fa,88,43,03,ac,6e,7d,69,d3,97,a4,43,\
- 4d,c6,68,b7,1c,6b,ec,15,3b,53,85,04,40,b8,a0,69,e4,a2,ef,b7,10,dd,2a,b5,f3,\
- 79,24,d1,8d,ba,f7,05,83,08,ba,79,08,18,e2,48,53,90,3f,33,4b,1e,e2,81,49,17,\
- 51,46,3f,6d,c0,6f,50,1a,52,cb,18,01,99,9f,38,93,19,17,fb,ee,60,70,f4,8d,a0,\
- e9,65,72,99,bf,87,d8,e4,77,91,fb,b2,06,b9,6b,b2,72,fa,16,bd,a5,b8,c8,db,5c,\
- 8f,bd,cd,e0,0c,ac,6c,6f,b6,d5,a6,3c,53,d9,2c,05,92,e9,cc,e1,86,11,86,ab,21,\
- b9,7c,68,96,1c,df,97,bb,74,78,f6,b3,31,19,fe,e5,81,9c,81,11,9c,a6,d6,21,2e,\
- c7,e9,5f,d8,62,fb,e2,82,67,75,6c,e5,d9,92,12,3e,af,b4,d7,dd,4f,16,c4,1e,ca,\
- 37,1f,9b,a7,0f,fc,c6,3b,b1,68,75,2f,03,fc,51,67,ae,20,f7,93,8d,39,8d,47,73,\
- e9,d1,f3,08,47,89,6a,c5,bd,92,bc,72,5e,c2,0e,de,68,3b,56,17,93,5e,e4,10,7f,\
- b8,2b,29,b1,42,d8,88,85,cd,12,fa,a9,36,b9,78,0f,d9,48,a3,45,a5,47,ab,db,47,\
- fb,dc,1d,bc,c5,0e,f6,7b,49,82,01,ef,9f,c5,d5,e2,e3,69,15,f5,60,6c,c4,dd,bb,\
- 5c,68,ec,cf,7e,43,1f,f4,de,a1,e7,bc,f9,2c,c9,4c,a6,07,6b,dc,10,fc,8a,51,f2,\
- 4e,e0,cf,40,20,e0,13,0d,15,87,fc,a3,b8,e4,66,bb,61,37,8e,b0,27,37,3c,0f,ac,\
- 48,bd,64,5c,cd,18,f1,42,fc,11,55,59,b6,cc,05,98,f2,3d,fe,61,2a,cf,17,3f,68,\
- 20,15,45,9c,27,15,1f,1a,2e,05,2b,c0,69,67,1e,6a,35,1f,a2,68,d6,18,ab,24,d0,\
- a1,aa,70,a8,07,e2,a1,61,35,ea,9a,04,96,27,46,33,d7,e5,2c,57,66,99,4c,0c,e8,\
- fe,6e,32,a5,42,3a,85,9d,85,1d,42,fc,59,94,ce,d9,00,a8,6f,75,cf,57,7a,61,34,\
- 90,3e,d9,16,ee,94,5a,4b,f8,a1,c8,74,2c,92,46,59,47,c8,cd,d6,3f,38,42,d4,0b,\
- 9d,fa,e0,b5,63,48,22,5f,9a,e8,07,c2,10,80,75,a2,dc,0f,21,fd,28,a9,bd,2f,44,\
- 14,c9,5e,27,c8,3c,39,3f,6b,a8,2c,32,3a,18,9d,73,f3,02,00,09,37,e1,f4,b5,b0,\
- 60,3e,f8,06,22,d2,14,8f,62,51,85,b2,6d,c3,7a,8a,18,51,1b,10,3d,e0,ee,6a,40,\
- c4,94,43,37,c7,4a,fa,a2,85,ae,56,e6,14,e8,59,d4,0b,ca,03,d4,e1,99,2d,27,bc,\
- 0f,62,91,82,63,2b,51,5a,21,d0,1e,c0,1d,03,49,98,bc,63,e8,cd,37,22,90,18,10,\
- f4,ae,22,74,73,65,b3,6d,f9,6d,d9,39,1e,98,92,00,f1,f1,a5,3f,2c,4e,ca,74,d1,\
- a1,a4,60,fc,d1,77,44,03,54,72,80,96,7c,f3,59,87,e4,3e,51,33,13,8f,68,19,c2,\
- c3,3b,3f,74,32,78,05,72,7b,b8,3d,47,83,b8,2d,ba,b8,08,63,6f,9c,a1,61,34,5a,\
- 67,d8,60,c9,b1,ce,d4,b4,4d,94,e8,8f,ca,8a,14,b2,2d,a3,6c,e8
- [HKEY_LOCAL_MACHINE\0\SAM\Domains\Account\Users\Names\SYSTEM]
- @=hex(012):
- [HKEY_LOCAL_MACHINE\0\SAM\Domains\Builtin\Aliases\Members\S-1-5\00000004]
- @="ϩ"
- [HKEY_LOCAL_MACHINE\0\SAM\Domains\Builtin\Aliases\Members\S-1-5\0000000B]
- @="ϩ"
- [HKEY_LOCAL_MACHINE\0\SAM\Domains\Builtin\Aliases\Members\S-1-5\00000011]
- @="ϩ"
- [HKEY_LOCAL_MACHINE\0\SAM\Domains\Builtin\Aliases\Members\S-1-5\000001F4]
- @="ϩ"
- [HKEY_LOCAL_MACHINE\0\SAM\Domains\Builtin\Aliases\Members\S-1-5\000001F5]
- @="ϩ"
- [HKEY_LOCAL_MACHINE\0\SAM\Domains\Builtin\Aliases\Members\S-1-5\000001F7]
- @="ϩ"
- [HKEY_LOCAL_MACHINE\0\SAM\Domains\Builtin\Aliases\Members\S-1-5\000001F8]
- @="ϩ"
- [HKEY_LOCAL_MACHINE\0\SAM\Domains\Builtin\Aliases\Members\S-1-5\00000012]
- @="ϩ"
- [HKEY_LOCAL_MACHINE\0\SAM\Domains\Builtin\Aliases\Members\S-1-5-21-1273946008-2210384159-1861864491\000001F4]
- @="ϩ"
- [HKEY_LOCAL_MACHINE\0\SAM\Domains\Builtin\Aliases\Members\S-1-5-21-1273946008-2210384159-1861864491\000001F5]
- @="ϩ"
- [HKEY_LOCAL_MACHINE\0\SAM\Domains\Builtin\Aliases\Members\S-1-5-21-1273946008-2210384159-1861864491\000001F7]
- @="ϩ"
- [HKEY_LOCAL_MACHINE\0\SAM\Domains\Builtin\Aliases\Members\S-1-5-21-1273946008-2210384159-1861864491\000001F8]
- @="ϩ"
- [HKEY_LOCAL_MACHINE\0\SAM\Domains\Builtin\Aliases\Members\S-1-5-21-1273946008-2210384159-1861864491\00000012]
- @="ϩ"
- [HKEY_LOCAL_MACHINE\0\SAM\Domains\Builtin\Aliases\Members\S-1-5-21-1273946008-2210384159-1861864491\00000004]
- @="ϩ"
- [HKEY_LOCAL_MACHINE\0\SAM\Domains\Builtin\Aliases\Members\S-1-5-21-1273946008-2210384159-1861864491\0000000B]
- @="ϩ"
- [HKEY_LOCAL_MACHINE\0\SAM\Domains\Builtin\Aliases\Members\S-1-5-21-1273946008-2210384159-1861864491\00000011]
- @="ϩ"
- Windows Registry Editor Version 5.00
- [HKEY_LOCAL_MACHINE\SAM\SAM\Domains\Builtin\Aliases\Members\S-1-5\00000012]
- @="ϩ"
- [HKEY_LOCAL_MACHINE\SAM\SAM\Domains\Builtin\Aliases\Members\S-1-5-21-3947544656-2014248660-3822616995\00000012]
- @="ϩ"
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement