|
1
|
|__ Value Added :
= "{b43cb0c0-84f2-11d6-a18e-00c0df043ba4}"
|
|
2
|
|__ Value Added :
autocfg = "01 00 00 00 00 00 00 00 01 00 00 00 56 62 61 33 32 47 75 69 2e 63 66 67 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 43 3a 5c 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00"
|
|
3
|
|__ Value Added :
localservice = "vba32ifs"
|
|
4
|
|__ Value Added :
localservice = "vba32pp3"
|
|
5
|
|__ Value Added :
localservice = "vba32pp3"
|
|
6
|
|__ Value Added :
localservice = "vba32ecm"
|
|
7
|
|__ Value Added :
= "psfactorybuffer"
|
|
8
|
|__ Value Added :
= "%programfiles%\vba32\sgsrvps.dll"
|
|
9
|
|__ Value Added :
threadingmodel = "both"
|
|
10
|
|__ Value Added :
= "%programfiles%\vba32\vba32sck.dll"
|
|
11
|
|__ Value Added :
threadingmodel = "both"
|
|
12
|
|__ Value Added :
appid = "{2af13c51-795a-11d6-a174-00c0df043ba4}"
|
|
13
|
|__ Value Added :
appid = "{4977316c-98a3-45c5-9faa-716269ffbac9}"
|
|
14
|
|__ Value Added :
= "%programfiles%\vba32\vbaolcfg.dll"
|
|
15
|
|__ Value Added :
threadingmodel = "both"
|
|
16
|
|__ Value Added :
= "%programfiles%\vba32\pp3conf.dll"
|
|
17
|
|__ Value Added :
threadingmodel = "both"
|
|
18
|
|__ Value Added :
appid = "{ae450adf-ea1c-46b2-9643-20aa21826c71}"
|
|
19
|
|__ Value Added :
= "%programfiles%\vba32\vba32shl.dll"
|
|
20
|
|__ Value Added :
threadingmodel = "both"
|
|
21
|
|__ Value Added :
originaldll = "%windir%\system32\vbscript.dll"
|
|
22
|
|__ Value Added :
originaldll = "%windir%\system32\vbscript.dll"
|
|
23
|
|__ Value Added :
originaldll = "%windir%\system32\vbscript.dll"
|
|
24
|
|__ Value Added :
= "vbarstgc.component.1"
|
|
25
|
|__ Value Added :
= "%programfiles%\vba32\vbarstgc.dll"
|
|
26
|
|__ Value Added :
threadingmodel = "both"
|
|
27
|
|__ Value Added :
= "vbarstgc.component.1"
|
|
28
|
|__ Value Added :
= "psfactorybuffer"
|
|
29
|
|__ Value Added :
= "%programfiles%\vba32\vba32eps.dll"
|
|
30
|
|__ Value Added :
threadingmodel = "both"
|
|
31
|
|__ Value Added :
appid = "{c8e02fd2-8825-11d6-a192-00c0df043ba4}"
|
|
32
|
|__ Value Added :
= "vba32stg.component.1"
|
|
33
|
|__ Value Added :
= "%programfiles%\vba32\vba32stg.dll"
|
|
34
|
|__ Value Added :
threadingmodel = "both"
|
|
35
|
|__ Value Added :
= "vba32stg.component.1"
|
|
36
|
|__ Value Added :
= "psfactorybuffer"
|
|
37
|
|__ Value Added :
= "%programfiles%\vba32\vbaifps.dll"
|
|
38
|
|__ Value Added :
threadingmodel = "both"
|
|
39
|
|__ Value Added :
originaldll = "%windir%\system32\jscript.dll"
|
|
40
|
|__ Value Added :
originaldll = "%windir%\system32\jscript.dll"
|
|
41
|
|__ Value Added :
= "{b43cb0c0-84f2-11d6-a18e-00c0df043ba4}"
|
|
42
|
|__ Value Added :
\device\0000003e.translated = "01 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 03 00 00 00 01 01 10 00 79 0a 00 00 00 00 00 00 01 00 00 00 01 01 10 00 79 02 00 00 00 00 00 00 01 00 00 00 01 01 10 00 74 02 00 00 00 00 00 00 04 00 00 00"
|
|
43
|
|__ Value Added :
\device\00000045.translated = "01 00 00 00 0f 00 00 00 00 00 00 00 00 00 00 00 03 00 00 00 01 01 11 00 60 00 00 00 00 00 00 00 01 00 00 00 01 01 11 00 64 00 00 00 00 00 00 00 01 00 00 00 02 01 01 00 08 00 00 00 93 01 00 00 01 00 00 00"
|
|
44
|
|__ Value Added :
autocfg = "01 00 00 00 00 00 00 00 01 00 00 00 56 62 61 33 32 47 75 69 2e 63 66 67 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 43 3a 5c 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00"
|
|
45
|
|__ Value Added :
vba32 plug-in = "4.0;%programfiles%\vba32\vbaolpl.dll;;01010111111"
|
|
46
|
|__ Value Added :
changed = "0"
|
|
47
|
|__ Value Added :
changed = "0"
|
|
48
|
|__ Value Added :
slowinfocache = "28 02 00 00 00 00 00 00 00 c8 0a 07 00 00 00 00 00 00 00 00 00 00 00 00 ff ff ff ff 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00"
|
|
49
|
|__ Value Added :
changed = "0"
|
|
50
|
|__ Value Added :
changed = "0"
|
|
51
|
|__ Value Added :
changed = "0"
|
|
52
|
|__ Value Added :
changed = "0"
|
|
53
|
|__ Value Added :
changed = "0"
|
|
54
|
|__ Value Added :
slowinfocache = "28 02 00 00 00 00 00 00 ff ff ff ff ff ff ff ff 00 00 00 00 00 00 00 00 ff ff ff ff 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00"
|
|
55
|
|__ Value Added :
changed = "0"
|
|
56
|
|__ Value Added :
changed = "0"
|
|
57
|
|__ Value Added :
changed = "0"
|
|
58
|
|__ Value Added :
vba32loader = ""%programfiles%\vba32\vba32ldr.exe""
|
|
59
|
|__ Value Added :
vba32loader = ""%programfiles%\vba32\vba32ldr.exe" /hidden"
|
|
60
|
|__ Value Added :
%windir%\system32\dllhook.dll = "1"
|
|
61
|
|__ Value Added :
authinfo = "41 56 d7 37 b0 0e fe 40 8c f1 52 6c f8 16 b5 71"
|
|
62
|
|__ Value Added :
config = "-2147483646"
|
|
63
|
|__ Value Added :
= "agent"
|
|
64
|
|__ Value Added :
installed = "0"
|
|
65
|
|__ Value Added :
= "antidial"
|
|
66
|
|__ Value Added :
installed = "0"
|
|
67
|
|__ Value Added :
installed = "1"
|
|
68
|
|__ Value Added :
= "common"
|
|
69
|
|__ Value Added :
installed = "1"
|
|
70
|
|__ Value Added :
= "dcon"
|
|
71
|
|__ Value Added :
installed = "0"
|
|
72
|
|__ Value Added :
= "explorer"
|
|
73
|
|__ Value Added :
installed = "1"
|
|
74
|
|__ Value Added :
setup = "4"
|
|
75
|
|__ Value Added :
= "gui"
|
|
76
|
|__ Value Added :
installed = "1"
|
|
77
|
|__ Value Added :
setup = "25"
|
|
78
|
|__ Value Added :
= "gui_nt4"
|
|
79
|
|__ Value Added :
installed = "0"
|
|
80
|
|__ Value Added :
= "gui_x64"
|
|
81
|
|__ Value Added :
installed = "0"
|
|
82
|
|__ Value Added :
= "kernel"
|
|
83
|
|__ Value Added :
installed = "1"
|
|
84
|
|__ Value Added :
= "language_bg"
|
|
85
|
|__ Value Added :
installed = "0"
|
|
86
|
|__ Value Added :
= "language_by"
|
|
87
|
|__ Value Added :
installed = "0"
|
|
88
|
|__ Value Added :
= "language_de"
|
|
89
|
|__ Value Added :
installed = "0"
|
|
90
|
|__ Value Added :
= "language_en"
|
|
91
|
|__ Value Added :
installed = "1"
|
|
92
|
|__ Value Added :
= "language_fr"
|
|
93
|
|__ Value Added :
installed = "0"
|
|
94
|
|__ Value Added :
= "language_jp"
|
|
95
|
|__ Value Added :
installed = "0"
|
|
96
|
|__ Value Added :
= "language_pt"
|
|
97
|
|__ Value Added :
installed = "0"
|
|
98
|
|__ Value Added :
= "language_ro"
|
|
99
|
|__ Value Added :
installed = "0"
|
|
100
|
|__ Value Added :
= "language_ru"
|
|
101
|
|__ Value Added :
installed = "1"
|
|
102
|
|__ Value Added :
= "language_sp"
|
|
103
|
|__ Value Added :
installed = "0"
|
|
104
|
|__ Value Added :
= "language_tr"
|
|
105
|
|__ Value Added :
installed = "0"
|
|
106
|
|__ Value Added :
= "language_ua"
|
|
107
|
|__ Value Added :
installed = "0"
|
|
108
|
|__ Value Added :
= "pop3"
|
|
109
|
|__ Value Added :
installed = "1"
|
|
110
|
|__ Value Added :
setup = "9"
|
|
111
|
|__ Value Added :
= "qtn"
|
|
112
|
|__ Value Added :
installed = "1"
|
|
113
|
|__ Value Added :
setup = "1"
|
|
114
|
|__ Value Added :
= "sound"
|
|
115
|
|__ Value Added :
installed = "1"
|
|
116
|
|__ Value Added :
= "thebat"
|
|
117
|
|__ Value Added :
installed = "0"
|
|
118
|
|__ Value Added :
= "txtdoc"
|
|
119
|
|__ Value Added :
installed = "1"
|
|
120
|
|__ Value Added :
= "vba32sck"
|
|
121
|
|__ Value Added :
installed = "1"
|
|
122
|
|__ Value Added :
setup = "1"
|
|
123
|
|__ Value Added :
= "vbaol"
|
|
124
|
|__ Value Added :
installed = "1"
|
|
125
|
|__ Value Added :
setup = "1"
|
|
126
|
|__ Value Added :
= "virbase"
|
|
127
|
|__ Value Added :
installed = "1"
|
|
128
|
|__ Value Added :
= "wcon"
|
|
129
|
|__ Value Added :
installed = "0"
|
|
130
|
|__ Value Added :
animation = "1"
|
|
131
|
|__ Value Added :
auto_check_autorun = "1"
|
|
132
|
|__ Value Added :
auto_check_boot = "0"
|
|
133
|
|__ Value Added :
auto_check_boot_floppy = "0"
|
|
134
|
|__ Value Added :
auto_check_memory = "1"
|
|
135
|
|__ Value Added :
auto_check_memory_fast = "1"
|
|
136
|
|__ Value Added :
auto_start = "1"
|
|
137
|
|__ Value Added :
language = "vba32en.lng"
|
|
138
|
|__ Value Added :
last_update = "d9 07 04 00 02 00 07 00 0c 00 1d 00 2d 00 13 02"
|
|
139
|
|__ Value Added :
last_update_attempt = "d9 07 04 00 02 00 07 00 0c 00 1d 00 2d 00 13 02"
|
|
140
|
|__ Value Added :
log = "1"
|
|
141
|
|__ Value Added :
log_add = "1"
|
|
142
|
|__ Value Added :
log_limit = "1"
|
|
143
|
|__ Value Added :
log_limit_value = "256"
|
|
144
|
|__ Value Added :
log_name = "vba32ldr.log"
|
|
145
|
|__ Value Added :
monitor_auto_start = "1"
|
|
146
|
|__ Value Added :
monitor_auto_start_param = "turn+"
|
|
147
|
|__ Value Added :
no_license_expire_message = "0"
|
|
148
|
|__ Value Added :
path = "%programfiles%\vba32"
|
|
149
|
|__ Value Added :
popup_loader = "1"
|
|
150
|
|__ Value Added :
protect_loader = "1"
|
|
151
|
|__ Value Added :
proxy_port = "8080"
|
|
152
|
|__ Value Added :
proxy_usage = "0"
|
|
153
|
|__ Value Added :
rootkit_search = "1"
|
|
154
|
|__ Value Added :
show_window = "0"
|
|
155
|
|__ Value Added :
sound = "1"
|
|
156
|
|__ Value Added :
update_folder = "http://www.anti-virus.by/update/"
|
|
157
|
|__ Value Added :
update_folder_list = "68 74 74 70 3a 2f 2f 75 70 64 61 74 65 73 2e 76 62 61 33 32 2e 64 65 2f 00 68 74 74 70 3a 2f 2f 76 69 72 75 73 75 2e 6e 65 74 2f 75 70 64 61 74 65 2f 00 00"
|
|
158
|
|__ Value Added :
update_interactive = "0"
|
|
159
|
|__ Value Added :
update_time = "1"
|
|
160
|
|__ Value Added :
update_time_value = "1"
|
|
161
|
|__ Value Added :
update_url_01 = "http://www.anti-virus.by/update/"
|
|
162
|
|__ Value Added :
update_url_02 = "http://updates.vba32.de/"
|
|
163
|
|__ Value Added :
update_url_03 = "http://virusu.net/update/"
|
|
164
|
|__ Value Added :
vba32pp3 = "{7e2d88ac-a2eb-498c-b666-61e5f38b553f}"
|
|
165
|
|__ Value Added :
vba32sck = "{114cabc1-f9cf-49ab-bdff-2ee55f4fc652}"
|
|
166
|
|__ Value Added :
vbaolpl = "{70c2bd0c-c48a-4921-8fb9-3050905ff76f}"
|
|
167
|
|__ Value Added :
add_to_report = "1"
|
|
168
|
|__ Value Added :
check_mode = "0"
|
|
169
|
|__ Value Added :
detect_riskware = "1"
|
|
170
|
|__ Value Added :
fast_mode = "0"
|
|
171
|
|__ Value Added :
heuristic = "1"
|
|
172
|
|__ Value Added :
idle_autorun = "1"
|
|
173
|
|__ Value Added :
idle_check = "0"
|
|
174
|
|__ Value Added :
idle_disk = "1"
|
|
175
|
|__ Value Added :
idle_disk_value = "20"
|
|
176
|
|__ Value Added :
idle_mouse = "1"
|
|
177
|
|__ Value Added :
idle_mouse_value = "50"
|
|
178
|
|__ Value Added :
idle_notebook = "1"
|
|
179
|
|__ Value Added :
idle_notebook_value = "90"
|
|
180
|
|__ Value Added :
idle_processor = "1"
|
|
181
|
|__ Value Added :
idle_processor_value = "20"
|
|
182
|
|__ Value Added :
idle_userfiles = "1"
|
|
183
|
|__ Value Added :
infectedaction1 = "2"
|
|
184
|
|__ Value Added :
infectedaction2 = "3"
|
|
185
|
|__ Value Added :
infectedaction3 = "3"
|
|
186
|
|__ Value Added :
infectedcopy1 = "1"
|
|
187
|
|__ Value Added :
infectedcopy2 = "1"
|
|
188
|
|__ Value Added :
infectedcopy3 = "0"
|
|
189
|
|__ Value Added :
limit_report = "1"
|
|
190
|
|__ Value Added :
limit_report_value = "256"
|
|
191
|
|__ Value Added :
notify = "1"
|
|
192
|
|__ Value Added :
report = "1"
|
|
193
|
|__ Value Added :
report_name = "vba32mnt.log"
|
|
194
|
|__ Value Added :
show_ok = "0"
|
|
195
|
|__ Value Added :
suspiciousaction1 = "0"
|
|
196
|
|__ Value Added :
suspiciousaction2 = "0"
|
|
197
|
|__ Value Added :
suspiciouscopy1 = "1"
|
|
198
|
|__ Value Added :
suspiciouscopy2 = "1"
|
|
199
|
|__ Value Added :
n000002090c070f080506040f0c030204 = "%windir%\system32\"
|
|
200
|
|__ Value Added :
n0b070a0f050b0f0c010d0b0e08080709 = "%windir%\"
|
|
201
|
|__ Value Added :
s01040a000e0d020a0d0c0a040c0f0e0c = "%programfiles%\"
|
|
202
|
|__ Value Added :
autosend = "0"
|
|
203
|
|__ Value Added :
inaractive_maint = "0"
|
|
204
|
|__ Value Added :
last_update = "2f 06 db 49 00 00 00 00 f4 01 b6 fe 00 00 00 00"
|
|
205
|
|__ Value Added :
maxsize = "1024"
|
|
206
|
|__ Value Added :
maxsizeex = "1"
|
|
207
|
|__ Value Added :
maxtime = "30"
|
|
208
|
|__ Value Added :
maxtimeex = "1"
|
|
209
|
|__ Value Added :
storagepath = "%programfiles%\vba32\qtn"
|
|
210
|
|__ Value Added :
timeout = "1"
|
|
211
|
|__ Value Added :
timeoutex = "1"
|
|
212
|
|__ Value Added :
useproxy = "0"
|
|
213
|
|__ Value Added :
activate = "1"
|
|
214
|
|__ Value Added :
detailed = "0"
|
|
215
|
|__ Value Added :
filename = "%programfiles%\vba32\vba32sck.log"
|
|
216
|
|__ Value Added :
filesize = "128"
|
|
217
|
|__ Value Added :
limitlog = "1"
|
|
218
|
|__ Value Added :
showwarn = "1"
|
|
219
|
|__ Value Added :
writelog = "1"
|
|
220
|
|__ Value Added :
check_read = "1"
|
|
221
|
|__ Value Added :
check_send = "1"
|
|
222
|
|__ Value Added :
heuristic_level = "2"
|
|
223
|
|__ Value Added :
infected_action1 = "1"
|
|
224
|
|__ Value Added :
infected_action2 = "2"
|
|
225
|
|__ Value Added :
infected_copy1 = "1"
|
|
226
|
|__ Value Added :
infected_copy2 = "1"
|
|
227
|
|__ Value Added :
show_res = "1"
|
|
228
|
|__ Value Added :
suspect_action = "2"
|
|
229
|
|__ Value Added :
suspect_copy = "1"
|
|
230
|
|__ Value Added :
enable = "1"
|
|
231
|
|__ Value Added :
heuristic_level = "2"
|
|
232
|
|__ Value Added :
hook_connections = "31 31 30 00 2a 00 31 34 33 00 2a 00 00"
|
|
233
|
|__ Value Added :
infected_action = "2"
|
|
234
|
|__ Value Added :
infected_copy = "1"
|
|
235
|
|__ Value Added :
suspect_action = "2"
|
|
236
|
|__ Value Added :
suspect_copy = "1"
|
|
237
|
|__ Value Added :
vba32 = "%programfiles%\vba32\"
|
|
238
|
|__ Value Added :
nextinstance = "1"
|
|
239
|
|__ Value Added :
class = "legacydriver"
|
|
240
|
|__ Value Added :
classguid = "{8ecc055d-047f-11d1-a537-0000f8753ed1}"
|
|
241
|
|__ Value Added :
configflags = "0"
|
|
242
|
|__ Value Added :
devicedesc = "vba32dnt"
|
|
243
|
|__ Value Added :
legacy = "1"
|
|
244
|
|__ Value Added :
service = "vba32dnt"
|
|
245
|
|__ Value Added :
activeservice = "vba32dnt"
|
|
246
|
|__ Value Added :
nextinstance = "1"
|
|
247
|
|__ Value Added :
class = "legacydriver"
|
|
248
|
|__ Value Added :
classguid = "{8ecc055d-047f-11d1-a537-0000f8753ed1}"
|
|
249
|
|__ Value Added :
configflags = "0"
|
|
250
|
|__ Value Added :
devicedesc = "vba32 loader service"
|
|
251
|
|__ Value Added :
legacy = "1"
|
|
252
|
|__ Value Added :
service = "vba32ldr"
|
|
253
|
|__ Value Added :
activeservice = "vba32ldr"
|
|
254
|
|__ Value Added :
nextinstance = "1"
|
|
255
|
|__ Value Added :
capabilities = "0"
|
|
256
|
|__ Value Added :
class = "legacydriver"
|
|
257
|
|__ Value Added :
classguid = "{8ecc055d-047f-11d1-a537-0000f8753ed1}"
|
|
258
|
|__ Value Added :
configflags = "0"
|
|
259
|
|__ Value Added :
devicedesc = "vba32mnt"
|
|
260
|
|__ Value Added :
legacy = "1"
|
|
261
|
|__ Value Added :
service = "vba32mnt"
|
|
262
|
|__ Value Added :
activeservice = "vba32mnt"
|
|
263
|
|__ Value Added :
nextinstance = "1"
|
|
264
|
|__ Value Added :
capabilities = "0"
|
|
265
|
|__ Value Added :
class = "legacydriver"
|
|
266
|
|__ Value Added :
classguid = "{8ecc055d-047f-11d1-a537-0000f8753ed1}"
|
|
267
|
|__ Value Added :
configflags = "0"
|
|
268
|
|__ Value Added :
devicedesc = "vba32prot"
|
|
269
|
|__ Value Added :
legacy = "1"
|
|
270
|
|__ Value Added :
service = "vba32prot"
|
|
271
|
|__ Value Added :
activeservice = "vba32prot"
|
|
272
|
|__ Value Added :
displayname = "vba32dnt"
|
|
273
|
|__ Value Added :
errorcontrol = "1"
|
|
274
|
|__ Value Added :
group = "filter"
|
|
275
|
|__ Value Added :
imagepath = "system32\drivers\vba32dnt.sys"
|
|
276
|
|__ Value Added :
start = "0"
|
|
277
|
|__ Value Added :
type = "2"
|
|
278
|
|__ Value Added :
0 = "root\legacy_vba32dnt\0000"
|
|
279
|
|__ Value Added :
count = "1"
|
|
280
|
|__ Value Added :
nextinstance = "1"
|
|
281
|
|__ Value Added :
dependongroup = "00"
|
|
282
|
|__ Value Added :
dependonservice = "52 70 63 73 73 00 56 62 61 33 32 4c 64 72 00 00"
|
|
283
|
|__ Value Added :
displayname = "vba32ecm"
|
|
284
|
|__ Value Added :
errorcontrol = "1"
|
|
285
|
|__ Value Added :
imagepath = ""%programfiles%\vba32\vba32ldr.exe""
|
|
286
|
|__ Value Added :
objectname = "localsystem"
|
|
287
|
|__ Value Added :
start = "3"
|
|
288
|
|__ Value Added :
type = "32"
|
|
289
|
|__ Value Added :
security = "01 00 14 80 bc 00 00 00 c8 00 00 00 14 00 00 00 30 00 00 00 02 00 1c 00 01 00 00 00 02 80 14 00 ff 01 0f 00 01 01 00 00 00 00 00 01 00 00 00 00 02 00 8c 00 06 00 00 00 00 00 14 00 9d 00 02 00 01 01 00 00 00 00 00 01 00 00 00 00 00 00 18 00 9d 00 02 00 01 02 00 00 00 00 00 05 20 00 00 00 22 02 00 00 00 00 14 00 fd 01 02 00 01 01 00 00 00 00 00 05 12 00 00 00 00 00 18 00 ff 01 0f 00 01 02 00 00 00 00 00 05 20 00 00 00 20 02 00 00 00 00 14 00 8d 01 02 00 01 01 00 00 00 00 00 05 0b 00 00 00 00 00 18 00 fd 01 02 00 01 02 00 00 00 00 00 05 20 00 00 00 23 02 00 00 01 01 00 00 00 00 00 05 12 00 00 00 01 01 00 00 00 00 00 05 12 00 00 00"
|
|
290
|
|__ Value Added :
dependongroup = "00"
|
|
291
|
|__ Value Added :
dependonservice = "52 70 63 73 73 00 56 62 61 33 32 4c 64 72 00 00"
|
|
292
|
|__ Value Added :
displayname = "vba32ifs"
|
|
293
|
|__ Value Added :
errorcontrol = "1"
|
|
294
|
|__ Value Added :
imagepath = ""%programfiles%\vba32\vba32ldr.exe""
|
|
295
|
|__ Value Added :
objectname = "localsystem"
|
|
296
|
|__ Value Added :
start = "3"
|
|
297
|
|__ Value Added :
type = "32"
|
|
298
|
|__ Value Added :
security = "01 00 14 80 bc 00 00 00 c8 00 00 00 14 00 00 00 30 00 00 00 02 00 1c 00 01 00 00 00 02 80 14 00 ff 01 0f 00 01 01 00 00 00 00 00 01 00 00 00 00 02 00 8c 00 06 00 00 00 00 00 14 00 9d 00 02 00 01 01 00 00 00 00 00 01 00 00 00 00 00 00 18 00 9d 00 02 00 01 02 00 00 00 00 00 05 20 00 00 00 22 02 00 00 00 00 14 00 fd 01 02 00 01 01 00 00 00 00 00 05 12 00 00 00 00 00 18 00 ff 01 0f 00 01 02 00 00 00 00 00 05 20 00 00 00 20 02 00 00 00 00 14 00 8d 01 02 00 01 01 00 00 00 00 00 05 0b 00 00 00 00 00 18 00 fd 01 02 00 01 02 00 00 00 00 00 05 20 00 00 00 23 02 00 00 01 01 00 00 00 00 00 05 12 00 00 00 01 01 00 00 00 00 00 05 12 00 00 00"
|
|
299
|
|__ Value Added :
dependongroup = "00"
|
|
300
|
|__ Value Added :
dependonservice = "52 70 63 73 73 00 00"
|
|
301
|
|__ Value Added :
displayname = "vba32 loader service"
|
|
302
|
|__ Value Added :
errorcontrol = "1"
|
|
303
|
|__ Value Added :
imagepath = ""%programfiles%\vba32\vba32ldr.exe""
|
|
304
|
|__ Value Added :
objectname = "localsystem"
|
|
305
|
|__ Value Added :
start = "2"
|
|
306
|
|__ Value Added :
type = "288"
|
|
307
|
|__ Value Added :
0 = "root\legacy_vba32ldr\0000"
|
|
308
|
|__ Value Added :
count = "1"
|
|
309
|
|__ Value Added :
nextinstance = "1"
|
|
310
|
|__ Value Added :
security = "01 00 14 80 bc 00 00 00 c8 00 00 00 14 00 00 00 30 00 00 00 02 00 1c 00 01 00 00 00 02 80 14 00 ff 01 0f 00 01 01 00 00 00 00 00 01 00 00 00 00 02 00 8c 00 06 00 00 00 00 00 14 00 9d 00 02 00 01 01 00 00 00 00 00 01 00 00 00 00 00 00 18 00 9d 00 02 00 01 02 00 00 00 00 00 05 20 00 00 00 22 02 00 00 00 00 14 00 9d 01 02 00 01 01 00 00 00 00 00 05 12 00 00 00 00 00 18 00 9f 01 0f 00 01 02 00 00 00 00 00 05 20 00 00 00 20 02 00 00 00 00 14 00 8d 01 02 00 01 01 00 00 00 00 00 05 0b 00 00 00 00 00 18 00 fd 01 02 00 01 02 00 00 00 00 00 05 20 00 00 00 23 02 00 00 01 01 00 00 00 00 00 05 12 00 00 00 01 01 00 00 00 00 00 05 12 00 00 00"
|
|
311
|
|__ Value Added :
displayname = "vba32mnt"
|
|
312
|
|__ Value Added :
errorcontrol = "1"
|
|
313
|
|__ Value Added :
imagepath = "\??\%programfiles%\vba32\vba32mnt.sys"
|
|
314
|
|__ Value Added :
start = "1"
|
|
315
|
|__ Value Added :
type = "1"
|
|
316
|
|__ Value Added :
0 = "root\legacy_vba32mnt\0000"
|
|
317
|
|__ Value Added :
count = "1"
|
|
318
|
|__ Value Added :
nextinstance = "1"
|
|
319
|
|__ Value Added :
dependongroup = "00"
|
|
320
|
|__ Value Added :
dependonservice = "52 70 63 73 73 00 56 62 61 33 32 4c 64 72 00 00"
|
|
321
|
|__ Value Added :
displayname = "vba32pp3"
|
|
322
|
|__ Value Added :
errorcontrol = "1"
|
|
323
|
|__ Value Added :
imagepath = ""%programfiles%\vba32\vba32ldr.exe""
|
|
324
|
|__ Value Added :
objectname = "localsystem"
|
|
325
|
|__ Value Added :
start = "3"
|
|
326
|
|__ Value Added :
type = "32"
|
|
327
|
|__ Value Added :
security = "01 00 14 80 bc 00 00 00 c8 00 00 00 14 00 00 00 30 00 00 00 02 00 1c 00 01 00 00 00 02 80 14 00 ff 01 0f 00 01 01 00 00 00 00 00 01 00 00 00 00 02 00 8c 00 06 00 00 00 00 00 14 00 9d 00 02 00 01 01 00 00 00 00 00 01 00 00 00 00 00 00 18 00 9d 00 02 00 01 02 00 00 00 00 00 05 20 00 00 00 22 02 00 00 00 00 14 00 fd 01 02 00 01 01 00 00 00 00 00 05 12 00 00 00 00 00 18 00 ff 01 0f 00 01 02 00 00 00 00 00 05 20 00 00 00 20 02 00 00 00 00 14 00 8d 01 02 00 01 01 00 00 00 00 00 05 0b 00 00 00 00 00 18 00 fd 01 02 00 01 02 00 00 00 00 00 05 20 00 00 00 23 02 00 00 01 01 00 00 00 00 00 05 12 00 00 00 01 01 00 00 00 00 00 05 12 00 00 00"
|
|
328
|
|__ Value Added :
displayname = "vba32prot"
|
|
329
|
|__ Value Added :
errorcontrol = "1"
|
|
330
|
|__ Value Added :
imagepath = "system32\drivers\vba32prot.sys"
|
|
331
|
|__ Value Added :
start = "1"
|
|
332
|
|__ Value Added :
type = "1"
|
|
333
|
|__ Value Added :
0 = "root\legacy_vba32prot\0000"
|
|
334
|
|__ Value Added :
count = "1"
|
|
335
|
|__ Value Added :
nextinstance = "1"
|
|
336
|
|__ Value Added :
security = "01 00 14 80 90 00 00 00 9c 00 00 00 14 00 00 00 30 00 00 00 02 00 1c 00 01 00 00 00 02 80 14 00 ff 01 0f 00 01 01 00 00 00 00 00 01 00 00 00 00 02 00 60 00 04 00 00 00 00 00 14 00 fd 01 02 00 01 01 00 00 00 00 00 05 12 00 00 00 00 00 18 00 ff 01 0f 00 01 02 00 00 00 00 00 05 20 00 00 00 20 02 00 00 00 00 14 00 8d 01 02 00 01 01 00 00 00 00 00 05 0b 00 00 00 00 00 18 00 fd 01 02 00 01 02 00 00 00 00 00 05 20 00 00 00 23 02 00 00 01 01 00 00 00 00 00 05 12 00 00 00 01 01 00 00 00 00 00 05 12 00 00 00"
|
|
337
|
|__ Value Added :
= "%programfiles%\vba32\keymgr.exe"
|
|
338
|
|__ Value Added :
= "%programfiles%\vba32\keymgr.exe "%1""
|
|
339
|
|__ Value Added :
= "vba32 storage vba32stgdb"
|
|
340
|
|__ Value Added :
= "{dd928ca9-5610-4297-8eab-8dce998afafd}"
|
|
341
|
|__ Value Added :
= "vba32stg.component.1"
|
|
342
|
|__ Value Added :
= "vba32 remote storage vbarstgc"
|
|
343
|
|__ Value Added :
= "{b9ac8227-4e37-42a0-96b1-8c4bc01cb424}"
|
|
344
|
|__ Value Added :
= "vbarstgc.component.1"
|