• HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings
GlobalUserOffline = 6684751
• HKLM\Software\Microsoft\Windows\CurrentVersion\policies\system
EnableLUA = 6422625
[Vista User Access Control Disabled]
• HKLM\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List
[malware path] = [malware path]:*:Enabled:ipsec
[Windows Firewall Disabled]
• HKCU\Software\user914\1214104697
1919251317 = 3276857
• HKCU\Software\user914\1214104697
-456464662 = 3407926
• HKCU\Software\user914\1214104697
1462786655 = 3604530
• HKCU\Software\user914\1214104697
-912929324 = 3735602
• HKCU\Software\user914\1214104697
1006321993 = 3342390
• HKCU\Software\user914\1214104697
-1369393986 = 0600687474703A2F2F7777772E6D7573696B72616A742E736B2F6D61696E662E
67696600687474703A2F2F6D616365646F6E69612E6D79312E72752F6D61696E682E676966006874
74703A2F2F6A7273782E6A72652E6E65742E636E2F6C6F676F732E67696600687474
• HKCU\Software\user914\1214104697
549857331 = 865E52A75BF33F5D5AA15DAFA722193EDDA8540E6C496C04CF492EF296AFD1AFD
EDBC79CEA25E0F6F53B2D9CC0FA963F3A4CC745615E85AFE1E18AEA7E620D11174F3892E84
B5B5DD288784938E304B2D65C454E833D6AF929809110987E5B4B3E4D581071DA4948CB9F84
• HKCU\Software\user914
u1_0 = 655360
• HKCU\Software\user914
u2_0 = 655360
• HKCU\Software\user914
u3_0 = 655360
• HKCU\Software\user914
u4_0 = 655360
• HKLM\Software\Microsoft\Tracing\FWCFG
EnableFileTracing = 7471188
• HKLM\Software\Microsoft\Tracing\FWCFG
EnableConsoleTracing = 7471188
• HKLM\Software\Microsoft\Tracing\FWCFG
FileTracingMask = 7209065
• HKLM\Software\Microsoft\Tracing\FWCFG
ConsoleTracingMask = 7209065
• HKLM\Software\Microsoft\Tracing\FWCFG
MaxFileSize = 7077993
• HKLM\Software\Microsoft\Tracing\FWCFG
FileDirectory = %windir%\tracing
• HKLM\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile
EnableFirewall = 7471209
[Windows Firewall Disabled]
• HKLM\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile
DoNotAllowExceptions = 7340133
• HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced
Hidden = 4718592
• HKCU\Software\Microsoft\Windows\CurrentVersion\policies\system
DisableTaskMgr = 6357076
[Task Manager Disabled]
• HKCU\Software\Microsoft\Windows\CurrentVersion\policies\system
DisableRegistryTools = 7929970
[Registry Editor Disabled]
• HKLM\SOFTWARE\Microsoft\Security Center
AntiVirusOverride = 6619254
• HKLM\SOFTWARE\Microsoft\Security Center
AntiVirusDisableNotify = 5111909
[Alerts for no Antivirus Disabled]
• HKLM\SOFTWARE\Microsoft\Security Center
FirewallDisableNotify = 5111909
[Alerts for no Firewall Disabled]
• HKLM\SOFTWARE\Microsoft\Security Center
FirewallOverride = 6619254
• HKLM\SOFTWARE\Microsoft\Security Center
UpdatesDisableNotify = 5111909
[Alerts for no Windows-Updates Disabled]
• HKLM\SOFTWARE\Microsoft\Security Center
UacDisableNotify = 5111909
• HKLM\SOFTWARE\Microsoft\Security Center\Svc
AntiVirusOverride = 6619254
• HKLM\SOFTWARE\Microsoft\Security Center\Svc
AntiVirusDisableNotify = 5111909
[Alerts for no Antivirus Disabled]
• HKLM\SOFTWARE\Microsoft\Security Center\Svc
FirewallDisableNotify = 5111909
[Alerts for no Firewall Disabled]
• HKLM\SOFTWARE\Microsoft\Security Center\Svc
FirewallOverride = 6619254
• HKLM\SOFTWARE\Microsoft\Security Center\Svc
UpdatesDisableNotify = 5111909
[Alerts for no Windows-Updates Disabled]
• HKLM\SOFTWARE\Microsoft\Security Center\Svc
UacDisableNotify = 5111909