Regshot 1.8.3-beta1V5 Comments: Datetime:2013/2/13 04:12:14 , 2013/2/13 04:14:25 Computer:UHA-68F2DDBE516 , UHA-68F2DDBE516 Username:Administrador , Administrador ---------------------------------- Keys added:2 ---------------------------------- HKLM\HARDWARE\IDE HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\RunServices ---------------------------------- Values added:29 ---------------------------------- HKLM\HARDWARE\IDE\w%xL@: "{ " HKLM\HARDWARE\IDE\hol)tu: "" HKLM\HARDWARE\IDE\ڮ'co: "$d" HKLM\HARDWARE\IDE\mOE : "Ym.]" HKLM\HARDWARE\IDE\ϲ)ui: "$d" HKLM\HARDWARE\IDE\ß: "MwD" HKLM\HARDWARE\IDE\Î : "$d" HKLM\HARDWARE\IDE\ϑ,xx: "$d" HKLM\HARDWARE\IDE\Ľ%r: "(3Ɩ" HKLM\HARDWARE\IDE\e0&: "x'" HKLM\HARDWARE\IDE\A[,8{Lɔ: "YiLVRq" HKLM\HARDWARE\IDE\6yj\J!=Q: "" HKLM\HARDWARE\IDE\EGX: "" HKLM\HARDWARE\IDE\Hz}6::: "* c" HKLM\HARDWARE\IDE\`ј11: "Bk4Ԙ" HKLM\HARDWARE\IDE\Ph?N: "~ " HKLM\HARDWARE\IDE\/%`x :z[: "" HKLM\HARDWARE\IDE\,~16LR: "" HKLM\HARDWARE\IDE\>o4gZĻKs: "" HKLM\HARDWARE\IDE\hqLƂ: "=n|" HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\RunServices\WinLoader: "hguyaprvcuf.exe" HKLM\SYSTEM\ControlSet001\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List\C:\WINDOWS\hguyaprvcuf.exe: "C:\WINDOWS\hguyaprvcuf.exe:*:Enabled:3.2.00" HKLM\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List\C:\WINDOWS\hguyaprvcuf.exe: "C:\WINDOWS\hguyaprvcuf.exe:*:Enabled:3.2.00" HKU\.DEFAULT\Software\Microsoft\Windows\ShellNoRoam\MUICache\C:\WINDOWS\hguyaprvcuf.exe: "3.2.00" HKU\S-1-5-21-73586283-616249376-1177238915-500\Software\Microsoft\Windows\CurrentVersion\Explorer\UserAssist\{75048700-EF1F-11D0-9888-006097DEACF9}\Count\HRZR_EHACNGU:P:\qbphzragbf\freire.rkr: 01 00 00 00 06 00 00 00 D0 58 7B 78 A0 09 CE 01 HKU\S-1-5-21-73586283-616249376-1177238915-500\Software\Microsoft\Windows\ShellNoRoam\MUICache\C:\documentos\server.exe: "3.2.00" HKU\S-1-5-21-73586283-616249376-1177238915-500\Software\Microsoft\Windows\ShellNoRoam\MUICache\C:\WINDOWS\hguyaprvcuf.exe: "3.2.00" HKU\S-1-5-21-73586283-616249376-1177238915-500\Software\Microsoft\Windows\ShellNoRoam\MUICache\@xpsp3res.dll,-20000: "Diagnstico de red para Windows XP" HKU\S-1-5-18\Software\Microsoft\Windows\ShellNoRoam\MUICache\C:\WINDOWS\hguyaprvcuf.exe: "3.2.00" ---------------------------------- Values modified:26 ---------------------------------- HKLM\SOFTWARE\Microsoft\Cryptography\RNG\Seed: 06 81 FF 24 43 C5 F5 10 74 47 75 62 17 06 D3 3B D1 0C 4E 0E 36 D4 FD D0 88 32 64 44 92 A0 E2 DD D4 B6 41 95 BA 11 80 56 66 53 80 13 78 2D C2 D2 38 3D F0 F4 9E 31 D3 AC A2 02 92 05 A7 94 B1 AF E0 CB F2 39 D6 F1 24 B5 0C 19 6B DC F7 6C 31 30 HKLM\SOFTWARE\Microsoft\Cryptography\RNG\Seed: 45 CE 42 89 D1 75 CD E5 0D E8 BE 21 15 73 68 71 12 38 94 08 B8 35 6D E5 42 D1 F2 95 03 4A 5D AD E4 17 51 6D 86 61 8C A6 DB 9C E5 AE 04 47 AE 78 37 27 56 B1 C0 F1 E6 45 E8 6B AA 0F 9B 95 40 BA 8D 21 08 F4 1A 47 55 C1 AA 61 B7 0C DE FB 58 E5 HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\UnableToDetectTime: "2012-12-18 01:06:27" HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\UnableToDetectTime: "2013-02-13 04:13:37" HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Reporting\SequenceNumber: 0x00000003 HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Reporting\SequenceNumber: 0x00000004 HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Prefetcher\TracesProcessed: 0x00000003 HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Prefetcher\TracesProcessed: 0x0000000F HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Prefetcher\TracesSuccessful: 0x00000002 HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Prefetcher\TracesSuccessful: 0x0000000B HKLM\SYSTEM\ControlSet001\Services\Dhcp\Parameters\{592EF604-1449-41AA-9D00-3A1F262B0400}: 06 00 00 00 00 00 00 00 04 00 00 00 00 00 00 00 1F DE CF 50 C0 A8 E0 01 0F 00 00 00 00 00 00 00 0B 00 00 00 00 00 00 00 1F DE CF 50 6C 6F 63 61 6C 64 6F 6D 61 69 6E 00 01 00 00 00 00 00 00 00 04 00 00 00 00 00 00 00 1F DE CF 50 FF FF FF 00 33 00 00 00 00 00 00 00 04 00 00 00 00 00 00 00 1F DE CF 50 00 00 07 08 36 00 00 00 00 00 00 00 04 00 00 00 00 00 00 00 1F DE CF 50 C0 A8 E0 FE 35 00 00 00 00 00 00 00 01 00 00 00 00 00 00 00 1F DE CF 50 05 00 00 00 HKLM\SYSTEM\ControlSet001\Services\Dhcp\Parameters\{592EF604-1449-41AA-9D00-3A1F262B0400}: 06 00 00 00 00 00 00 00 04 00 00 00 00 00 00 00 FA 19 1B 51 C0 A8 E0 01 0F 00 00 00 00 00 00 00 0B 00 00 00 00 00 00 00 FA 19 1B 51 6C 6F 63 61 6C 64 6F 6D 61 69 6E 00 01 00 00 00 00 00 00 00 04 00 00 00 00 00 00 00 FA 19 1B 51 FF FF FF 00 36 00 00 00 00 00 00 00 04 00 00 00 00 00 00 00 FA 19 1B 51 C0 A8 E0 FE 35 00 00 00 00 00 00 00 01 00 00 00 00 00 00 00 FA 19 1B 51 05 00 00 00 FC 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 F5 12 1B 51 33 00 00 00 00 00 00 00 04 00 00 00 00 00 00 00 FA 19 1B 51 00 00 07 08 HKLM\SYSTEM\ControlSet001\Services\SharedAccess\Epoch\Epoch: 0x00000040 HKLM\SYSTEM\ControlSet001\Services\SharedAccess\Epoch\Epoch: 0x00000046 HKLM\SYSTEM\ControlSet001\Services\Tcpip\Parameters\Interfaces\{592EF604-1449-41AA-9D00-3A1F262B0400}\LeaseObtainedTime: 0x50CFD717 HKLM\SYSTEM\ControlSet001\Services\Tcpip\Parameters\Interfaces\{592EF604-1449-41AA-9D00-3A1F262B0400}\LeaseObtainedTime: 0x511B12F2 HKLM\SYSTEM\ControlSet001\Services\Tcpip\Parameters\Interfaces\{592EF604-1449-41AA-9D00-3A1F262B0400}\T1: 0x50CFDA9B HKLM\SYSTEM\ControlSet001\Services\Tcpip\Parameters\Interfaces\{592EF604-1449-41AA-9D00-3A1F262B0400}\T1: 0x511B1676 HKLM\SYSTEM\ControlSet001\Services\Tcpip\Parameters\Interfaces\{592EF604-1449-41AA-9D00-3A1F262B0400}\T2: 0x50CFDD3E HKLM\SYSTEM\ControlSet001\Services\Tcpip\Parameters\Interfaces\{592EF604-1449-41AA-9D00-3A1F262B0400}\T2: 0x511B1919 HKLM\SYSTEM\ControlSet001\Services\Tcpip\Parameters\Interfaces\{592EF604-1449-41AA-9D00-3A1F262B0400}\LeaseTerminatesTime: 0x50CFDE1F HKLM\SYSTEM\ControlSet001\Services\Tcpip\Parameters\Interfaces\{592EF604-1449-41AA-9D00-3A1F262B0400}\LeaseTerminatesTime: 0x511B19FA HKLM\SYSTEM\ControlSet001\Services\{592EF604-1449-41AA-9D00-3A1F262B0400}\Parameters\Tcpip\LeaseObtainedTime: 0x50CFD717 HKLM\SYSTEM\ControlSet001\Services\{592EF604-1449-41AA-9D00-3A1F262B0400}\Parameters\Tcpip\LeaseObtainedTime: 0x511B12F2 HKLM\SYSTEM\ControlSet001\Services\{592EF604-1449-41AA-9D00-3A1F262B0400}\Parameters\Tcpip\T1: 0x50CFDA9B HKLM\SYSTEM\ControlSet001\Services\{592EF604-1449-41AA-9D00-3A1F262B0400}\Parameters\Tcpip\T1: 0x511B1676 HKLM\SYSTEM\ControlSet001\Services\{592EF604-1449-41AA-9D00-3A1F262B0400}\Parameters\Tcpip\T2: 0x50CFDD3E HKLM\SYSTEM\ControlSet001\Services\{592EF604-1449-41AA-9D00-3A1F262B0400}\Parameters\Tcpip\T2: 0x511B1919 HKLM\SYSTEM\ControlSet001\Services\{592EF604-1449-41AA-9D00-3A1F262B0400}\Parameters\Tcpip\LeaseTerminatesTime: 0x50CFDE1F HKLM\SYSTEM\ControlSet001\Services\{592EF604-1449-41AA-9D00-3A1F262B0400}\Parameters\Tcpip\LeaseTerminatesTime: 0x511B19FA HKLM\SYSTEM\CurrentControlSet\Services\Dhcp\Parameters\{592EF604-1449-41AA-9D00-3A1F262B0400}: 06 00 00 00 00 00 00 00 04 00 00 00 00 00 00 00 1F DE CF 50 C0 A8 E0 01 0F 00 00 00 00 00 00 00 0B 00 00 00 00 00 00 00 1F DE CF 50 6C 6F 63 61 6C 64 6F 6D 61 69 6E 00 01 00 00 00 00 00 00 00 04 00 00 00 00 00 00 00 1F DE CF 50 FF FF FF 00 33 00 00 00 00 00 00 00 04 00 00 00 00 00 00 00 1F DE CF 50 00 00 07 08 36 00 00 00 00 00 00 00 04 00 00 00 00 00 00 00 1F DE CF 50 C0 A8 E0 FE 35 00 00 00 00 00 00 00 01 00 00 00 00 00 00 00 1F DE CF 50 05 00 00 00 HKLM\SYSTEM\CurrentControlSet\Services\Dhcp\Parameters\{592EF604-1449-41AA-9D00-3A1F262B0400}: 06 00 00 00 00 00 00 00 04 00 00 00 00 00 00 00 FA 19 1B 51 C0 A8 E0 01 0F 00 00 00 00 00 00 00 0B 00 00 00 00 00 00 00 FA 19 1B 51 6C 6F 63 61 6C 64 6F 6D 61 69 6E 00 01 00 00 00 00 00 00 00 04 00 00 00 00 00 00 00 FA 19 1B 51 FF FF FF 00 36 00 00 00 00 00 00 00 04 00 00 00 00 00 00 00 FA 19 1B 51 C0 A8 E0 FE 35 00 00 00 00 00 00 00 01 00 00 00 00 00 00 00 FA 19 1B 51 05 00 00 00 FC 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 F5 12 1B 51 33 00 00 00 00 00 00 00 04 00 00 00 00 00 00 00 FA 19 1B 51 00 00 07 08 HKLM\SYSTEM\CurrentControlSet\Services\SharedAccess\Epoch\Epoch: 0x00000040 HKLM\SYSTEM\CurrentControlSet\Services\SharedAccess\Epoch\Epoch: 0x00000046 HKLM\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{592EF604-1449-41AA-9D00-3A1F262B0400}\LeaseObtainedTime: 0x50CFD717 HKLM\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{592EF604-1449-41AA-9D00-3A1F262B0400}\LeaseObtainedTime: 0x511B12F2 HKLM\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{592EF604-1449-41AA-9D00-3A1F262B0400}\T1: 0x50CFDA9B HKLM\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{592EF604-1449-41AA-9D00-3A1F262B0400}\T1: 0x511B1676 HKLM\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{592EF604-1449-41AA-9D00-3A1F262B0400}\T2: 0x50CFDD3E HKLM\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{592EF604-1449-41AA-9D00-3A1F262B0400}\T2: 0x511B1919 HKLM\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{592EF604-1449-41AA-9D00-3A1F262B0400}\LeaseTerminatesTime: 0x50CFDE1F HKLM\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{592EF604-1449-41AA-9D00-3A1F262B0400}\LeaseTerminatesTime: 0x511B19FA HKLM\SYSTEM\CurrentControlSet\Services\{592EF604-1449-41AA-9D00-3A1F262B0400}\Parameters\Tcpip\LeaseObtainedTime: 0x50CFD717 HKLM\SYSTEM\CurrentControlSet\Services\{592EF604-1449-41AA-9D00-3A1F262B0400}\Parameters\Tcpip\LeaseObtainedTime: 0x511B12F2 HKLM\SYSTEM\CurrentControlSet\Services\{592EF604-1449-41AA-9D00-3A1F262B0400}\Parameters\Tcpip\T1: 0x50CFDA9B HKLM\SYSTEM\CurrentControlSet\Services\{592EF604-1449-41AA-9D00-3A1F262B0400}\Parameters\Tcpip\T1: 0x511B1676 HKLM\SYSTEM\CurrentControlSet\Services\{592EF604-1449-41AA-9D00-3A1F262B0400}\Parameters\Tcpip\T2: 0x50CFDD3E HKLM\SYSTEM\CurrentControlSet\Services\{592EF604-1449-41AA-9D00-3A1F262B0400}\Parameters\Tcpip\T2: 0x511B1919 HKLM\SYSTEM\CurrentControlSet\Services\{592EF604-1449-41AA-9D00-3A1F262B0400}\Parameters\Tcpip\LeaseTerminatesTime: 0x50CFDE1F HKLM\SYSTEM\CurrentControlSet\Services\{592EF604-1449-41AA-9D00-3A1F262B0400}\Parameters\Tcpip\LeaseTerminatesTime: 0x511B19FA HKU\S-1-5-21-73586283-616249376-1177238915-500\Software\Microsoft\Windows\CurrentVersion\Explorer\UserAssist\{75048700-EF1F-11D0-9888-006097DEACF9}\Count\HRZR_EHACNGU: 01 00 00 00 61 00 00 00 00 5A D9 34 A0 09 CE 01 HKU\S-1-5-21-73586283-616249376-1177238915-500\Software\Microsoft\Windows\CurrentVersion\Explorer\UserAssist\{75048700-EF1F-11D0-9888-006097DEACF9}\Count\HRZR_EHACNGU: 01 00 00 00 62 00 00 00 D0 58 7B 78 A0 09 CE 01 ---------------------------------- Total changes:57 ----------------------------------