onor 2009-6-25 11:55 PM
--------------------- LOCKED REGISTRY KEYS ---------------------
[HKEY_USERS\S-1-5-21-1275210071-776561741-725345543-1003\Software\Microsoft\Office\11.0\Common\Open Find\Microsoft Office Access\Settings\/SúQ *?™eh?*A*g*e*G*r*o*u*p*'* *?.*.*.*\File Name MRU]
"Value"=multi:"\00\00"
"Maximum Entries"=dword:0000000a
[HKEY_USERS\S-1-5-21-1275210071-776561741-725345543-1003\Software\Microsoft\Office\11.0\Common\Open Find\Microsoft Office Access\Settings\/SúQ *?™eh?*A*g*e*G*r*o*u*p*'* *?.*.*.*\View]
"Data"=hex:04,16,00,47,28,14,14,14,0d,01,02,01,00,18,41,00,0d,00,fa,08,00,00,
90,90,0d,00,fa,08,00,00,90,90,0d,00,fa,08,00,00,90,90,0d,00,fa,08,00,00,90,\
[HKEY_USERS\S-1-5-21-1275210071-776561741-725345543-1003\Software\Microsoft\Windows\CurrentVersion\Explorer\MenuOrder\Start Menu\Programs\Atari\!jìdjW3*]
"Order"=hex:08,00,00,00,02,00,00,00,0c,00,00,00,01,00,00,00,00,00,00,00
[HKEY_USERS\S-1-5-21-1275210071-776561741-725345543-1003\Software\Microsoft\Windows\CurrentVersion\Explorer\MenuOrder\Start Menu\Programs\"Y{^?™ó^2*]
"Order"=hex:08,00,00,00,02,00,00,00,70,01,00,00,01,00,00,00,03,00,00,00,7a,00,
00,00,00,00,00,00,6c,00,00,00,41,75,67,4d,02,00,00,00,01,00,00,00,5a,00,36,\
[HKEY_USERS\S-1-5-21-1275210071-776561741-725345543-1003\Software\Microsoft\Windows\CurrentVersion\Explorer\MenuOrder\Start Menu\Programs\‡[û\gY@l\ NW??³PV*]
"Order"=hex:08,00,00,00,02,00,00,00,7a,01,00,00,01,00,00,00,03,00,00,00,7c,00,
00,00,00,00,00,00,6e,00,00,00,41,75,67,4d,02,00,00,00,01,00,00,00,5c,00,36,\
[HKEY_USERS\S-1-5-21-1275210071-776561741-725345543-1003\Software\Microsoft\Windows\CurrentVersion\Explorer\MenuOrder\Start Menu\Programs\?q\Òk8?*2*0*0*7* *2–ÒkWY?\?f?eôc]
"Order"=hex:08,00,00,00,02,00,00,00,08,02,00,00,01,00,00,00,04,00,00,00,7e,00,
00,00,00,00,00,00,70,00,00,00,41,75,67,4d,02,00,00,00,01,00,00,00,5e,00,36,\
[HKEY_USERS\S-1-5-21-1275210071-776561741-725345543-1003\Software\Microsoft\Windows\CurrentVersion\Explorer\MenuOrder\Start Menu\Programs\?q\Òk8?*2*0*0*7* *2–ÒkWY?\?q\Òk8—å]wQ]
"Order"=hex:08,00,00,00,02,00,00,00,86,01,00,00,01,00,00,00,03,00,00,00,7a,00,
00,00,00,00,00,00,6c,00,00,00,41,75,67,4d,02,00,00,00,01,00,00,00,5a,00,36,\
[HKEY_USERS\S-1-5-21-1275210071-776561741-725345543-1003\Software\Microsoft\Windows\CurrentVersion\Explorer\MenuOrder\Start Menu\Programs\?¸^?àO³P-*®U_jHr]
"Order"=hex:08,00,00,00,02,00,00,00,06,01,00,00,01,00,00,00,02,00,00,00,7c,00,
00,00,00,00,00,00,6e,00,00,00,41,75,67,4d,02,00,00,00,01,00,00,00,5c,00,36,\
[HKEY_LOCAL_MACHINE\software\Classes\*\shell\(u(g?nd?Y+^2*0*0*7*ƒcÏc\Command]
@="c:\\Documents and Settings\\user\\®à±\\¤ì°¨²M°£¤j®v2007\\BeatTrojan.exe %1\00\00\00\00\00\00\00\00\00\00\00\00\00\00\00\00\00\00\00\00\00\00\00\00\00\00\00\00\00\00\00\00\00\00\00\00\00\00\00\00\00\00\00\00\00\00\00\00\00\00\00\00\00\00\00\00\00\00\00\00\00\00D[x\04\00\00\00\00€\00\00\00\00IME:2007-12-30 8:49"
[HKEY_LOCAL_MACHINE\software\Classes\B*D*A*T*u*n*e*r*.*CQöN\CLSID]
@="{809B6661-94C4-49E6-B6EC-3F0F862215AA}"
[HKEY_LOCAL_MACHINE\software\Classes\B*D*A*T*u*n*e*r*.*CQöN\CurVer]
@="BDATuner.¤¸¥ó.1"
[HKEY_LOCAL_MACHINE\software\Classes\Folder\shell\(u(g?nd?Y+^2*0*0*7*ƒcÏc\Command]
@="c:\\Documents and Settings\\user\\®à±\\¤ì°¨²M°£¤j®v2007\\BeatTrojan.exe %1\00\00\00\00\00\00\00\00\00\00\00\00\00\00\00\00\00\00\00\00\00\00\00\00\00\00\00\00\00\00\00\00\00\00\00\00\00\00\00\00\00\00\00\00\00\00\00\00\00\00\00\00\00\00\00\00\00\00\00\00\00\00D[x\04\00\00\00\00€\00\00\00\00IME:2007-12-30 8:49"
[HKEY_LOCAL_MACHINE\software\Classes\N*e*r*o*lxŸx™PýN‹WKa\DefaultIcon]
@="c:\\PROGRA~1\\Ahead\\Nero\\nero.exe,14"
[HKEY_LOCAL_MACHINE\software\Classes\N*e*r*o*lxŸx™PýN‹WKa\shell\open\command]
@="c:\\PROGRA~1\\Ahead\\Nero\\nero.exe \"%1\""
[HKEY_LOCAL_MACHINE\software\Classes\N*e*r*o*lxŸx™PýN‹WKa\shell\print\command]
@="c:\\PROGRA~1\\Ahead\\Nero\\nero.exe /p \"%1\""
[HKEY_LOCAL_MACHINE\software\Classes\N*e*r*o*lxŸx™PýN‹WKa\shell\printto\command]
@="c:\\PROGRA~1\\Ahead\\Nero\\nero.exe /pt \"%1\" \"%2\" \"%3\" \"%4\""
[HKEY_LOCAL_MACHINE\software\Microsoft\Windows\CurrentVersion\App Management\ARPCache\?_j³Pb-*-N‡eHr]
"SlowInfoCache"=hex:28,02,00,00,01,00,00,00,00,c0,0f,16,00,00,00,00,d4,2c,95,
2c,5a,8e,c6,01,00,00,00,00,65,00,3a,00,5c,00,8d,9f,5f,6a,b3,50,7f,62,5c,00,\
"Changed"=dword:00000000
[HKEY_LOCAL_MACHINE\software\Microsoft\Windows\CurrentVersion\Uninstall\?_j³Pb-*-N‡eHr]
"UninstallString"="c:\\WINDOWS\\IsUninst.exe -fe:\\Às¾÷¶Ç©Ó\\i\\ª±±o\\Uninst.isu"
"DisplayName"="Às¾÷¶Ç©Ó-¤¤¤åª©"
[HKEY_LOCAL_MACHINE\System\ControlSet004\Enum\Root\SYSTEM\0003]
@Denied: (Read) (LocalSystem)
@Allowed: (Read) (Administrators)
"DeviceDesc"="PnP BIOS Extension"
"ClassGUID"="{4D36E97D-E325-11CE-BFC1-08002BE10318}"
"Class"="System"
"HardwareID"=multi:"root\\d347bus\00\00"
"Driver"="{4D36E97D-E325-11CE-BFC1-08002BE10318}\\0025"
"Mfg"="(Standard system devices)"
"Service"="d347bus"
"ConfigFlags"=dword:00000000
"Capabilities"=dword:00000000
[HKEY_LOCAL_MACHINE\System\ControlSet004\Enum\Root\SYSTEM\0003\LogConf]
@Allowed: (Read) (Administrators)
.