Jump to content

Welcome to Geeks to Go - Register now for FREE

Geeks To Go is a helpful hub, where thousands of volunteer geeks quickly serve friendly answers and support. Check out the forums and get free advice from the experts. Register now to gain access to all of our features, it's FREE and only takes one minute. Once registered and logged in, you will be able to create topics, post replies to existing threads, give reputation to your fellow members, get your own private messenger, post status updates, manage your profile and so much more.

Create Account How it Works
Photo

COM Error crashes computer when trying to email


  • Please log in to reply

#46
shorthaul99

shorthaul99

    Member

  • Topic Starter
  • Member
  • PipPip
  • 93 posts

Here is the exact screenshot of what I get and it does this twice after I click the close/OK button. I will attempt to use a different logon to capture a clean log but it will take a few more seconds while I type in password to email etc.

 

 

COMcrash.jpg


  • 0

Advertisements


#47
shorthaul99

shorthaul99

    Member

  • Topic Starter
  • Member
  • PipPip
  • 93 posts

Here is a clean log while running different logon and emails did go through properly

 

 

https://www.dropbox....ogfile.PML?dl=0


  • 0

#48
RKinner

RKinner

    Malware Expert

  • Expert
  • 20,001 posts
  • MVP

Do you still have the failed process monitor log?  My Firefox was opening them directly in  Process Monitor and not saving and when I went back to get the first one the newest one was the only one in dropbox.


  • 0

#49
shorthaul99

shorthaul99

    Member

  • Topic Starter
  • Member
  • PipPip
  • 93 posts

WELL, I feel like an amateur at this point...when I saved the new log file, it defaulted to the exact same name and I didn't catch it and DropBox automatically overwrote the file content and updated it with the newest info and I can't retrieve the old file unless you have a trick up your sleeve?   :yeah: Maybe somewhere it did save a shadow copy of some sort?


  • 0

#50
shorthaul99

shorthaul99

    Member

  • Topic Starter
  • Member
  • PipPip
  • 93 posts

I finished invoices and ran QB on the main profile and everything executed like normal and did not crash. I started the PC monitor before running to capture all the data and here is a fresh copy of a clean capture under my normal login ID...

 

 

https://www.dropbox....ogin#1.PML?dl=0


  • 0

#51
RKinner

RKinner

    Malware Expert

  • Expert
  • 20,001 posts
  • MVP

I guess that's good news that it worked this time.

 

I'm looking at your last log.  At:

 

12:10:38.5628252 AM

 

It starts the mail process.

 

It looks in the registry for:

 

HKCU\SOFTWARE\Clients\Mail

then

HKCU\Software\Clients\Mail\(Default) where it finds: Microsoft Outlook

 

so it knows to use Outlook to mail with.

 

It then finds:

 

HKCR\Outlook.Application\CurVer

and

 

HKCR\Outlook.Application\CurVer\(Default) value = Outlook.Application.16

 

after first looking in HKCU for the same thing.  This is normal behavior.  Stuff in HKCR is for everyone while HKCU is specific to the current user so it always checks HKCU first.

 

Then it looks for the file:

 

C:\Program Files (x86)\Intuit\QuickBooks 2018\MAPI32.DLL

 

but doesn't find it so it uses the file in:

 

C:\Windows\SysWOW64\mapi32.dll

 

This is the generic 32 bit version of mapi32.dll since it's in SysWOW64.  (There is another in System32 but it's the 64 bit version which we don't need because QB is 32 bit ( it's in Program Files x86 - 64 bit programs live in Program Files)

 

It seems to do everything twice I guess to make sure it read it correctly.

 

Then we reread

 

C:\ProgramData\Intuit\QuickBooks 2018\qbw.ini

 

which we have read many times in the past.

 

Not sure what it is looking for in qbw.in but it seems happy with what it findsi.  Appears to be a big file.

 

Then we read:

 

HKCU\Software\Clients\Mail\(Default) and find: Microsoft Outlook
 

we repeat the whole process again then load mapi32.dll

 

then move on to HKLM\Software\Policies\Microsoft\SQMClient\Windows

 

SQMClient is Software Quality Management (SQM)  Client.

 

We check for and don't find: HKLM\SOFTWARE\Policies\Microsoft\SQMClient\Windows\CEIPEnable

This is the Windows Customer Experience Improvement Program

which is MS's spy system that reports problems back to the mothership

but it doesn't need it so it continues.

 

 

 

It looks for:  HKLM\SOFTWARE\Microsoft\Office\16.0\Outlook (not found)

Then goes back and looks for: HKLM\SOFTWARE\Microsoft\SQMClient\Windows\CEIPSampledIn (finds it but the value is 0 so guess it doesn't apply)

 

Now we look in:  HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows Messaging Subsystem\MSMapiApps  which tells it to use:

 

msab32.dll

 

and SearchProtocolHost.exe
to find    Microsoft Outlook

 

and also to use:

outstore.dll

inetsw95.exe

choosusr.dll

 

 

Now we look in:

 

HKLM\SOFTWARE\Clients\Mail\Microsoft Outlook\MSIInstallOnWTS (0)

 

HKLM\SOFTWARE\Clients\Mail\Microsoft Outlook\MSIApplicationLCID (Microsoft\Office\16.0\Outlook, LastUILanguage)

 

HKLM\SOFTWARE\Clients\Mail\Microsoft Outlook\MSIOfficeLCID (buffer overflow means there is more data than our standard storage space can handle so it repeats the read with a bigger buffer and finds:Microsoft\Office\16.0\Common\LanguageResources, UILanguageTag, PreferredEditingLanguage.)

 

Now we read: HKLM\SOFTWARE\Clients\Mail\Microsoft Outlook\MSIComponentID

and find: {6DB1921F-8B40-4406-A18B-E906DBEEF0C9}
 

 

Now we look for:  HKCU\Software\Microsoft\Office\16.0\Outlook\LastUILanguage

and find 1033 which is English (US)

 

HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\Managed\S-1-5-21-2577112198-3913129868-2286876578-1000\Installer\Components\F1291BD604B860441AB89E60BDEE0F9C isn't there which I think means there are no restrictions on your user using this program.

 

Next it finds:  HKCR\Installer\Components\F1291BD604B860441AB89E60BDEE0F9C

 

and looks in:

 

HKCR\Installer\Components\F1291BD604B860441AB89E60BDEE0F9C\1033\NT

 

where it finds:  Vz`gY,3K,?HcCDN2wW9tOutlookMAPI2Intl_1033>,q'UeJk{_8e~.C`QpoDt

 

Not sure what the odd stuff means - perhaps it is a series of flags (one bit yea or nay that tell it something that just look like ASCII but aren't).  Assume it makes sense to it since it doesn't complain.

 

Next we read: HKCR\Installer\Features\99E80CA9B0328E74791254777B1F42AE\OutlookMAPI2Intl_1033

but there is nothing special there.

Then: HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\99E80CA9B0328E74791254777B1F42AE\Features\OutlookMAPI2Intl_1033

and find:  ,q'UeJk{_8e~.C`QpoDt

 

Then we go to:

HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\AF1555CB0248D304997DE1CA911196AE\99E80CA9B0328E74791254777B1F42AE

where we find:  C:\Program Files (x86)\Microsoft Office\root\VFS\ProgramFilesCommonX86\SYSTEM\MSMAPI\1033\MSMAPI32.DLL

 

C:\Program Files (x86)\Microsoft Office\root\vfs\ProgramFilesCommonX86\SYSTEM\MSMAPI\1033\MSMAPI32.DLL has File Attributes = ASF

 

Now we get serious and start using:

 

C:\Program Files (x86)\Microsoft Office\root\vfs\ProgramFilesCommonX86\SYSTEM\MSMAPI\1033\MSMAPI32.DLL

 

Now we check:  HKLM\Software\Microsoft\Office\16.0\ClickToRunStore\Packages

 

Apparently your version of Offices uses click to run to check the subscription is paid.

 

It finds:  C:\Program Files (x86)\Microsoft Office

  {9AC08E99-230B-47e8-9721-4577B7F124EA}

 

so I guess you are good to go.

 

Opens:  C:\Program Files (x86)\Microsoft Office\root\Office16\JitV.dll

 

Next we look for:

 

C:\Windows\SysWOW64\api-ms-win-core-fibers-l1-1-1.DLL

C:\Windows\SysWOW64\api-ms-win-core-localization-l1-2-1.DLL

but they aren't there which appears normal.

 

Now we check:  C:\Program Files (x86)\Microsoft Office\root\Office16\AppvIsvSubsystems32.dll

 

That's all I have time for this morning.  Dog needs to go for a walk.

 

 


  • 0

#52
shorthaul99

shorthaul99

    Member

  • Topic Starter
  • Member
  • PipPip
  • 93 posts

I was positive we were going to finish out clean tonight and emails send like normal then BAM! COM ERROR again and I recorded it for your viewing.

 

 

https://www.dropbox....ogin#1.PML?dl=0

 

TRULY thank you for all of your help and patience on this issue!!   :cheers:


  • 0

#53
RKinner

RKinner

    Malware Expert

  • Expert
  • 20,001 posts
  • MVP

Can you attach or post on dropbox:

 

C:\Users\JB\AppData\Local\Intuit\QuickBooks\Log\28.0\QBWin.log ?

 

This is a hidden location so you may need to tell windows to let you see it:

 

Control Panel, (View By:  Large Icons)  Folder Options, View.

Uncheck Hide Extensions for Known File Types
Uncheck Hide Protected System Files
Check Show Hidden Files,Folders and Drives.
OK

 

Also

Copy the next 5 lines:

 

ipconfig /all > \junk.txt

netstat -es >> \junk.txt

reg query "HKLM\System\CurrentControlSet\Services\Tcpip\Parameters\Interfaces" /s >> \junk.txt

reg query "HKCU\Software\Microsoft\windows\CurrentVersion\Internet Settings" /s >> \junk.txt

notepad \junk.txt

 

 

open an elevated command prompt.

 

(Start, All Programs, Accessories right click on command prompt and run as admin)

right click and Paste (or Edit then Paste) and the copied lines will appear.  If notepad does not open hit Enter.  Copy and paste the text to  (or attach c:\junk.txt)


  • 0

#54
shorthaul99

shorthaul99

    Member

  • Topic Starter
  • Member
  • PipPip
  • 93 posts

Windows IP Configuration

   Host Name . . . . . . . . . . . . : JB-HP
   Primary Dns Suffix  . . . . . . . :
   Node Type . . . . . . . . . . . . : Hybrid
   IP Routing Enabled. . . . . . . . : No
   WINS Proxy Enabled. . . . . . . . : No
   DNS Suffix Search List. . . . . . : attlocal.net

Ethernet adapter Bluetooth Network Connection 2:

   Media State . . . . . . . . . . . : Media disconnected
   Connection-specific DNS Suffix  . :
   Description . . . . . . . . . . . : Bluetooth Device (Personal Area Network) #2
   Physical Address. . . . . . . . . : D8-5D-E2-93-6B-3C
   DHCP Enabled. . . . . . . . . . . : Yes
   Autoconfiguration Enabled . . . . : Yes

Ethernet adapter Local Area Connection:

   Connection-specific DNS Suffix  . : attlocal.net
   Description . . . . . . . . . . . : Realtek PCIe GBE Family Controller
   Physical Address. . . . . . . . . : D8-97-BA-80-37-2A
   DHCP Enabled. . . . . . . . . . . : Yes
   Autoconfiguration Enabled . . . . : Yes
   IPv4 Address. . . . . . . . . . . : 192.168.7.81(Preferred)
   Subnet Mask . . . . . . . . . . . : 255.255.255.0
   Lease Obtained. . . . . . . . . . : Monday, December 04, 2017 6:20:56 PM
   Lease Expires . . . . . . . . . . : Tuesday, December 05, 2017 6:20:53 PM
   Default Gateway . . . . . . . . . : 192.168.7.254
   DHCP Server . . . . . . . . . . . : 192.168.7.254
   DNS Servers . . . . . . . . . . . : 192.168.7.254
   NetBIOS over Tcpip. . . . . . . . : Enabled

Tunnel adapter Teredo Tunneling Pseudo-Interface:

   Media State . . . . . . . . . . . : Media disconnected
   Connection-specific DNS Suffix  . :
   Description . . . . . . . . . . . : Teredo Tunneling Pseudo-Interface
   Physical Address. . . . . . . . . : 00-00-00-00-00-00-00-E0
   DHCP Enabled. . . . . . . . . . . : No
   Autoconfiguration Enabled . . . . : Yes

Tunnel adapter Local Area Connection* 13:

   Media State . . . . . . . . . . . : Media disconnected
   Connection-specific DNS Suffix  . :
   Description . . . . . . . . . . . : Microsoft 6to4 Adapter
   Physical Address. . . . . . . . . : 00-00-00-00-00-00-00-E0
   DHCP Enabled. . . . . . . . . . . : No
   Autoconfiguration Enabled . . . . : Yes

Tunnel adapter isatap.attlocal.net:

   Media State . . . . . . . . . . . : Media disconnected
   Connection-specific DNS Suffix  . : attlocal.net
   Description . . . . . . . . . . . : Microsoft ISATAP Adapter
   Physical Address. . . . . . . . . : 00-00-00-00-00-00-00-E0
   DHCP Enabled. . . . . . . . . . . : No
   Autoconfiguration Enabled . . . . : Yes

Tunnel adapter isatap.{A63CE4CE-29FA-47BB-9ECC-397415ED8C7D}:

   Media State . . . . . . . . . . . : Media disconnected
   Connection-specific DNS Suffix  . :
   Description . . . . . . . . . . . : Microsoft ISATAP Adapter #3
   Physical Address. . . . . . . . . : 00-00-00-00-00-00-00-E0
   DHCP Enabled. . . . . . . . . . . : No
   Autoconfiguration Enabled . . . . : Yes
Interface Statistics

                           Received            Sent

Bytes                     383655320        13065332
Unicast packets              265764          155068
Non-unicast packets            2132             740
Discards                          0               0
Errors                            0               0
Unknown protocols                 0

IPv4 Statistics

  Packets Received                   = 66578
  Received Header Errors             = 0
  Received Address Errors            = 0
  Datagrams Forwarded                = 0
  Unknown Protocols Received         = 0
  Received Packets Discarded         = 76
  Received Packets Delivered         = 66947
  Output Requests                    = 39112
  Routing Discards                   = 0
  Discarded Output Packets           = 0
  Output Packet No Route             = 0
  Reassembly Required                = 4
  Reassembly Successful              = 2
  Reassembly Failures                = 0
  Datagrams Successfully Fragmented  = 0
  Datagrams Failing Fragmentation    = 0
  Fragments Created                  = 0

IPv6 Statistics

  Packets Received                   = 0
  Received Header Errors             = 0
  Received Address Errors            = 0
  Datagrams Forwarded                = 0
  Unknown Protocols Received         = 0
  Received Packets Discarded         = 0
  Received Packets Delivered         = 6
  Output Requests                    = 14
  Routing Discards                   = 0
  Discarded Output Packets           = 0
  Output Packet No Route             = 2
  Reassembly Required                = 0
  Reassembly Successful              = 0
  Reassembly Failures                = 0
  Datagrams Successfully Fragmented  = 0
  Datagrams Failing Fragmentation    = 0
  Fragments Created                  = 0

ICMPv4 Statistics

                            Received    Sent
  Messages                  7           7        
  Errors                    0           0        
  Destination Unreachable   7           7        
  Time Exceeded             0           0        
  Parameter Problems        0           0        
  Source Quenches           0           0        
  Redirects                 0           0        
  Echo Replies              0           0        
  Echos                     0           0        
  Timestamps                0           0        
  Timestamp Replies         0           0        
  Address Masks             0           0        
  Address Mask Replies      0           0        
  Router Solicitations      0           0        
  Router Advertisements     0           0        

ICMPv6 Statistics

                            Received    Sent
  Messages                  0           0        
  Errors                    0           0        
  Destination Unreachable   0           0        
  Packet Too Big            0           0        
  Time Exceeded             0           0        
  Parameter Problems        0           0        
  Echos                     0           0        
  Echo Replies              0           0        
  MLD Queries               0           0        
  MLD Reports               0           0        
  MLD Dones                 0           0        
  Router Solicitations      0           0        
  Router Advertisements     0           0        
  Neighbor Solicitations    0           0        
  Neighbor Advertisements   0           0        
  Redirects                 0           0        
  Router Renumberings       0           0        

TCP Statistics for IPv4

  Active Opens                        = 386
  Passive Opens                       = 19
  Failed Connection Attempts          = 13
  Reset Connections                   = 139
  Current Connections                 = 35
  Segments Received                   = 66479
  Segments Sent                       = 38935
  Segments Retransmitted              = 124

TCP Statistics for IPv6

  Active Opens                        = 0
  Passive Opens                       = 0
  Failed Connection Attempts          = 0
  Reset Connections                   = 0
  Current Connections                 = 0
  Segments Received                   = 0
  Segments Sent                       = 0
  Segments Retransmitted              = 0

UDP Statistics for IPv4

  Datagrams Received    = 367
  No Ports              = 76
  Receive Errors        = 149
  Datagrams Sent        = 476

UDP Statistics for IPv6

  Datagrams Received    = 6
  No Ports              = 0
  Receive Errors        = 0
  Datagrams Sent        = 8

HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{426660DF-605F-426A-8A35-2758FE3DD89C}
    UseZeroBroadcast    REG_DWORD    0x0
    EnableDeadGWDetect    REG_DWORD    0x1
    EnableDHCP    REG_DWORD    0x1
    NameServer    REG_SZ   
    Domain    REG_SZ   
    RegistrationEnabled    REG_DWORD    0x1
    RegisterAdapterName    REG_DWORD    0x0
    DhcpIPAddress    REG_SZ    0.0.0.0
    DhcpSubnetMask    REG_SZ    255.0.0.0
    DhcpServer    REG_SZ    255.255.255.255
    Lease    REG_DWORD    0x0
    LeaseObtainedTime    REG_DWORD    0x0
    T1    REG_DWORD    0x0
    T2    REG_DWORD    0x0
    LeaseTerminatesTime    REG_DWORD    0x0
    AddressType    REG_DWORD    0x0
    IsServerNapAware    REG_DWORD    0x0
    DhcpConnForceBroadcastFlag    REG_DWORD    0x0

HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{5A134DD5-9609-460B-876D-D6D240D948BF}
    UseZeroBroadcast    REG_DWORD    0x0
    EnableDeadGWDetect    REG_DWORD    0x1
    EnableDHCP    REG_DWORD    0x1
    NameServer    REG_SZ   
    Domain    REG_SZ   
    RegistrationEnabled    REG_DWORD    0x1
    RegisterAdapterName    REG_DWORD    0x0
    DhcpIPAddress    REG_SZ    172.20.10.6
    DhcpSubnetMask    REG_SZ    255.255.255.240
    DhcpServer    REG_SZ    172.20.10.1
    Lease    REG_DWORD    0x14e20
    LeaseObtainedTime    REG_DWORD    0x57dc6416
    T1    REG_DWORD    0x57dd0b26
    T2    REG_DWORD    0x57dd8872
    LeaseTerminatesTime    REG_DWORD    0x57ddb236
    AddressType    REG_DWORD    0x0
    IsServerNapAware    REG_DWORD    0x0
    DhcpConnForceBroadcastFlag    REG_DWORD    0x0
    DhcpInterfaceOptions    REG_BINARY    0600000000000000040000000000000036B2DD57AC140A010300000000000000040000000000000036B2DD57AC140A010100000000000000040000000000000036B2DD57FFFFFFF03600000000000000040000000000000036B2DD57AC140A013500000000000000010000000000000036B2DD5705000000FC0000000000000000000000000000001A64DC573300000000000000040000000000000036B2DD5700014E20
    DhcpGatewayHardware    REG_BINARY    AC140A0106000000EE20E8606C64
    DhcpGatewayHardwareCount    REG_DWORD    0x1
    DhcpNameServer    REG_SZ    172.20.10.1
    DhcpDefaultGateway    REG_MULTI_SZ    172.20.10.1
    DhcpSubnetMaskOpt    REG_MULTI_SZ    255.255.255.240

HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{7B7BE31E-87D8-463A-AADD-383A303528BD}
    UseZeroBroadcast    REG_DWORD    0x0
    EnableDeadGWDetect    REG_DWORD    0x1
    EnableDHCP    REG_DWORD    0x1
    NameServer    REG_SZ   
    Domain    REG_SZ   
    RegistrationEnabled    REG_DWORD    0x1
    RegisterAdapterName    REG_DWORD    0x0
    DhcpIPAddress    REG_SZ    0.0.0.0
    DhcpSubnetMask    REG_SZ    255.0.0.0
    DhcpServer    REG_SZ    255.255.255.255
    Lease    REG_DWORD    0x0
    LeaseObtainedTime    REG_DWORD    0x0
    T1    REG_DWORD    0x0
    T2    REG_DWORD    0x0
    LeaseTerminatesTime    REG_DWORD    0x0
    AddressType    REG_DWORD    0x0
    IsServerNapAware    REG_DWORD    0x0
    DhcpConnForceBroadcastFlag    REG_DWORD    0x0

HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{846ee342-7039-11de-9d20-806e6f6e6963}

HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{A63CE4CE-29FA-47BB-9ECC-397415ED8C7D}
    UseZeroBroadcast    REG_DWORD    0x0
    EnableDeadGWDetect    REG_DWORD    0x1
    EnableDHCP    REG_DWORD    0x1
    NameServer    REG_SZ   
    Domain    REG_SZ   
    RegistrationEnabled    REG_DWORD    0x1
    RegisterAdapterName    REG_DWORD    0x0
    DhcpIPAddress    REG_SZ    0.0.0.0
    DhcpSubnetMask    REG_SZ    255.0.0.0
    DhcpServer    REG_SZ    255.255.255.255
    Lease    REG_DWORD    0x0
    LeaseObtainedTime    REG_DWORD    0x0
    T1    REG_DWORD    0x0
    T2    REG_DWORD    0x0
    LeaseTerminatesTime    REG_DWORD    0x0
    AddressType    REG_DWORD    0x0
    IsServerNapAware    REG_DWORD    0x0
    DhcpConnForceBroadcastFlag    REG_DWORD    0x0
    DhcpGatewayHardware    REG_BINARY    AC140A0106000000BA53AC6DC964
    DhcpGatewayHardwareCount    REG_DWORD    0x1

HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{D2D4F5EB-AB89-4FFB-ADEA-8610198B42F4}
    UseZeroBroadcast    REG_DWORD    0x0
    EnableDeadGWDetect    REG_DWORD    0x1
    EnableDHCP    REG_DWORD    0x1
    NameServer    REG_SZ   
    Domain    REG_SZ   
    RegistrationEnabled    REG_DWORD    0x1
    RegisterAdapterName    REG_DWORD    0x0
    DhcpIPAddress    REG_SZ    192.168.7.81
    DhcpSubnetMask    REG_SZ    255.255.255.0
    DhcpServer    REG_SZ    192.168.7.254
    Lease    REG_DWORD    0x15180
    LeaseObtainedTime    REG_DWORD    0x5a25e668
    T1    REG_DWORD    0x5a268f28
    T2    REG_DWORD    0x5a270db8
    LeaseTerminatesTime    REG_DWORD    0x5a2737e8
    AddressType    REG_DWORD    0x0
    IsServerNapAware    REG_DWORD    0x0
    DhcpConnForceBroadcastFlag    REG_DWORD    0x1
    DhcpInterfaceOptions    REG_BINARY    7D000000000000002500000000000000E837275A00000DE9200406303031453436050E333038373334333633333737363006064E564735393500000006000000000000000400000000000000E837275AC0A807FE03000000000000000400000000000000E837275AC0A807FE0F000000000000000C00000000000000E837275A6174746C6F63616C2E6E657401000000000000000400000000000000E837275AFFFFFF0036000000000000000400000000000000E837275AC0A807FE35000000000000000100000000000000E837275A05000000FC000000000000000000000000000000B2E8255A3B000000000000000400000000000000E837275A000127503A000000000000000400000000000000E837275A0000A8C033000000000000000400000000000000E837275A00015180
    DhcpGatewayHardware    REG_BINARY    C0A807FE060000001C144834B660
    DhcpGatewayHardwareCount    REG_DWORD    0x1
    DhcpNameServer    REG_SZ    192.168.7.254
    DhcpDefaultGateway    REG_MULTI_SZ    192.168.7.254
    DhcpDomain    REG_SZ    attlocal.net
    DhcpSubnetMaskOpt    REG_MULTI_SZ    255.255.255.0

HKEY_CURRENT_USER\Software\Microsoft\windows\CurrentVersion\Internet Settings
    IE5_UA_Backup_Flag    REG_SZ    5.0
    User Agent    REG_SZ    Mozilla/4.0 (compatible; MSIE 8.0; Win32)
    EmailName    REG_SZ    [email protected]
    PrivDiscUiShown    REG_DWORD    0x1
    EnableHttp1_1    REG_DWORD    0x1
    WarnOnIntranet    REG_DWORD    0x1
    MimeExclusionListForCache    REG_SZ    multipart/mixed multipart/x-mixed-replace multipart/x-byteranges
    AutoConfigProxy    REG_SZ    wininet.dll
    UseSchannelDirectly    REG_BINARY    01000000
    WarnOnPost    REG_BINARY    01000000
    UrlEncoding    REG_DWORD    0x0
    SecureProtocols    REG_DWORD    0xa80
    PrivacyAdvanced    REG_DWORD    0x0
    ZonesSecurityUpgrade    REG_BINARY    272599064813D101
    DisableCachingOfSSLPages    REG_DWORD    0x0
    WarnonZoneCrossing    REG_DWORD    0x0
    CertificateRevocation    REG_DWORD    0x1
    EnableNegotiate    REG_DWORD    0x1
    MigrateProxy    REG_DWORD    0x1
    ProxyEnable    REG_DWORD    0x0
    EnableAutodial    REG_DWORD    0x0
    NoNetAutodial    REG_DWORD    0x0
    ProxyHttp1.1    REG_DWORD    0x1
    EnableSPDY3_0    REG_DWORD    0x0
    BackgroundConnections    REG_DWORD    0x1
    EnableSSL3Fallback    REG_DWORD    0x1
    EnablePunycode    REG_DWORD    0x1
    ShowPunycode    REG_DWORD    0x0
    CreateUriCacheSize    REG_DWORD    0x50
    CoInternetCombineIUriCacheSize    REG_DWORD    0x50
    SecurityIdIUriCacheSize    REG_DWORD    0x1e
    SpecialFoldersCacheSize    REG_DWORD    0x8
    SyncMode5    REG_DWORD    0x4
    DisableIDNPrompt    REG_DWORD    0x0
    WarnonBadCertRecving    REG_DWORD    0x1
    WarnOnPostRedirect    REG_DWORD    0x1

HKEY_CURRENT_USER\Software\Microsoft\windows\CurrentVersion\Internet Settings\5.0

HKEY_CURRENT_USER\Software\Microsoft\windows\CurrentVersion\Internet Settings\5.0\Cache
    Version    REG_DWORD    0x1
    ContentLimit    REG_DWORD    0xfa
    TotalContentLimit    REG_DWORD    0x0
    AppContainerTotalContentLimit    REG_DWORD    0x3e8
    AppContainerContentLimit    REG_DWORD    0x32

HKEY_CURRENT_USER\Software\Microsoft\windows\CurrentVersion\Internet Settings\5.0\Cache\Content
    CachePrefix    REG_SZ   
    CacheLimit    REG_DWORD    0x3e800

HKEY_CURRENT_USER\Software\Microsoft\windows\CurrentVersion\Internet Settings\5.0\Cache\Cookies
    CachePrefix    REG_SZ    Cookie:
    CacheLimit    REG_DWORD    0x1

HKEY_CURRENT_USER\Software\Microsoft\windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache

HKEY_CURRENT_USER\Software\Microsoft\windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\DNTException
    CachePrefix    REG_SZ    DNTException:
    CachePath    REG_EXPAND_SZ    %APPDATA%\Microsoft\Windows\DNTException
    CacheOptions    REG_DWORD    0x300
    CacheRepair    REG_DWORD    0x0
    CacheLimit    REG_DWORD    0x1

HKEY_CURRENT_USER\Software\Microsoft\windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\DOMStore
    CachePrefix    REG_SZ    DOMStore
    CachePath    REG_EXPAND_SZ    %USERPROFILE%\AppData\Local\Microsoft\Internet Explorer\DOMStore
    CacheOptions    REG_DWORD    0x8
    CacheRepair    REG_DWORD    0x0
    CacheLimit    REG_DWORD    0x3e8

HKEY_CURRENT_USER\Software\Microsoft\windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\EmieSiteList
    CachePrefix    REG_SZ    EmieSiteList:
    CachePath    REG_EXPAND_SZ    %USERPROFILE%\AppData\Local\Microsoft\Internet Explorer\EmieSiteList
    CacheOptions    REG_DWORD    0x300
    CacheRepair    REG_DWORD    0x0
    CacheLimit    REG_DWORD    0x1

HKEY_CURRENT_USER\Software\Microsoft\windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\EmieUserList
    CachePrefix    REG_SZ    EmieUserList:
    CachePath    REG_EXPAND_SZ    %USERPROFILE%\AppData\Local\Microsoft\Internet Explorer\EmieUserList
    CacheOptions    REG_DWORD    0x300
    CacheRepair    REG_DWORD    0x0
    CacheLimit    REG_DWORD    0x1

HKEY_CURRENT_USER\Software\Microsoft\windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\feedplat
    CachePrefix    REG_SZ    feedplat:
    CachePath    REG_EXPAND_SZ    %USERPROFILE%\AppData\Local\Microsoft\Feeds Cache
    CacheOptions    REG_DWORD    0x0
    CacheRepair    REG_DWORD    0x0
    CacheLimit    REG_DWORD    0x1

HKEY_CURRENT_USER\Software\Microsoft\windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\iecompat
    CachePrefix    REG_SZ    iecompat:
    CachePath    REG_EXPAND_SZ    %APPDATA%\Microsoft\Windows\IECompatCache
    CacheOptions    REG_DWORD    0x309
    CacheRepair    REG_DWORD    0x0
    CacheLimit    REG_DWORD    0x1

HKEY_CURRENT_USER\Software\Microsoft\windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\iecompatua
    CachePrefix    REG_SZ    iecompatua:
    CachePath    REG_EXPAND_SZ    %APPDATA%\Microsoft\Windows\iecompatuaCache
    CacheOptions    REG_DWORD    0x309
    CacheRepair    REG_DWORD    0x0
    CacheLimit    REG_DWORD    0x1

HKEY_CURRENT_USER\Software\Microsoft\windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\iedownload
    CachePrefix    REG_SZ    iedownload:
    CachePath    REG_EXPAND_SZ    %APPDATA%\Microsoft\Windows\IEDownloadHistory
    CacheOptions    REG_DWORD    0x9
    CacheRepair    REG_DWORD    0x0
    CacheLimit    REG_DWORD    0x1

HKEY_CURRENT_USER\Software\Microsoft\windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\MSHist012017120420171205
    CachePrefix    REG_SZ    :2017120420171205:
    CachePath    REG_EXPAND_SZ    %USERPROFILE%\AppData\Local\Microsoft\Windows\History\History.IE5\MSHist012017120420171205
    CacheOptions    REG_DWORD    0xb
    CacheRepair    REG_DWORD    0x0
    CacheLimit    REG_DWORD    0x1

HKEY_CURRENT_USER\Software\Microsoft\windows\CurrentVersion\Internet Settings\5.0\Cache\History
    CachePrefix    REG_SZ    Visited:
    CacheLimit    REG_DWORD    0x1

HKEY_CURRENT_USER\Software\Microsoft\windows\CurrentVersion\Internet Settings\5.0\LowCache

HKEY_CURRENT_USER\Software\Microsoft\windows\CurrentVersion\Internet Settings\5.0\LowCache\Content
    CachePrefix    REG_SZ   
    CacheLimit    REG_DWORD    0x3e800

HKEY_CURRENT_USER\Software\Microsoft\windows\CurrentVersion\Internet Settings\5.0\LowCache\Cookies
    CachePrefix    REG_SZ    Cookie:
    CacheLimit    REG_DWORD    0x1

HKEY_CURRENT_USER\Software\Microsoft\windows\CurrentVersion\Internet Settings\5.0\LowCache\Extensible Cache

HKEY_CURRENT_USER\Software\Microsoft\windows\CurrentVersion\Internet Settings\5.0\LowCache\Extensible Cache\DNTException
    CachePrefix    REG_SZ    DNTException:
    CachePath    REG_EXPAND_SZ    %APPDATA%\Microsoft\Windows\DNTException\Low
    CacheOptions    REG_DWORD    0x300
    CacheRepair    REG_DWORD    0x0
    CacheLimit    REG_DWORD    0x1

HKEY_CURRENT_USER\Software\Microsoft\windows\CurrentVersion\Internet Settings\5.0\LowCache\Extensible Cache\DOMStore
    CachePrefix    REG_SZ    DOMStore
    CachePath    REG_EXPAND_SZ    %USERPROFILE%\AppData\LocalLow\Microsoft\Internet Explorer\DOMStore
    CacheOptions    REG_DWORD    0x8
    CacheRepair    REG_DWORD    0x0
    CacheLimit    REG_DWORD    0x3e8

HKEY_CURRENT_USER\Software\Microsoft\windows\CurrentVersion\Internet Settings\5.0\LowCache\Extensible Cache\EmieBrowserModeList
    CachePrefix    REG_SZ    EmieBrowserModeList:
    CachePath    REG_EXPAND_SZ    %USERPROFILE%\AppData\LocalLow\Microsoft\Internet Explorer\EmieBrowserModeList
    CacheOptions    REG_DWORD    0x300
    CacheRepair    REG_DWORD    0x0
    CacheLimit    REG_DWORD    0x1

HKEY_CURRENT_USER\Software\Microsoft\windows\CurrentVersion\Internet Settings\5.0\LowCache\Extensible Cache\EmieSiteList
    CachePrefix    REG_SZ    EmieSiteList:
    CachePath    REG_EXPAND_SZ    %USERPROFILE%\AppData\LocalLow\Microsoft\Internet Explorer\EmieSiteList
    CacheOptions    REG_DWORD    0x300
    CacheRepair    REG_DWORD    0x0
    CacheLimit    REG_DWORD    0x1

HKEY_CURRENT_USER\Software\Microsoft\windows\CurrentVersion\Internet Settings\5.0\LowCache\Extensible Cache\EmieUserList
    CachePrefix    REG_SZ    EmieUserList:
    CachePath    REG_EXPAND_SZ    %USERPROFILE%\AppData\LocalLow\Microsoft\Internet Explorer\EmieUserList
    CacheOptions    REG_DWORD    0x300
    CacheRepair    REG_DWORD    0x0
    CacheLimit    REG_DWORD    0x1

HKEY_CURRENT_USER\Software\Microsoft\windows\CurrentVersion\Internet Settings\5.0\LowCache\Extensible Cache\feedplat
    CachePrefix    REG_SZ    feedplat:
    CachePath    REG_EXPAND_SZ    %USERPROFILE%\AppData\Local\Microsoft\Feeds Cache
    CacheOptions    REG_DWORD    0x0
    CacheRepair    REG_DWORD    0x0
    CacheLimit    REG_DWORD    0x1

HKEY_CURRENT_USER\Software\Microsoft\windows\CurrentVersion\Internet Settings\5.0\LowCache\Extensible Cache\iecompat
    CachePrefix    REG_SZ    iecompat:
    CachePath    REG_EXPAND_SZ    %APPDATA%\Microsoft\Windows\IECompatCache\Low
    CacheOptions    REG_DWORD    0x309
    CacheRepair    REG_DWORD    0x0
    CacheLimit    REG_DWORD    0x1

HKEY_CURRENT_USER\Software\Microsoft\windows\CurrentVersion\Internet Settings\5.0\LowCache\Extensible Cache\iecompatua
    CachePrefix    REG_SZ    iecompatua:
    CachePath    REG_EXPAND_SZ    %APPDATA%\Microsoft\Windows\iecompatuaCache\Low
    CacheOptions    REG_DWORD    0x309
    CacheRepair    REG_DWORD    0x0
    CacheLimit    REG_DWORD    0x1

HKEY_CURRENT_USER\Software\Microsoft\windows\CurrentVersion\Internet Settings\5.0\LowCache\Extensible Cache\iedownload
    CachePrefix    REG_SZ    iedownload:
    CachePath    REG_EXPAND_SZ    %APPDATA%\Microsoft\Windows\IEDownloadHistory
    CacheOptions    REG_DWORD    0x9
    CacheRepair    REG_DWORD    0x0
    CacheLimit    REG_DWORD    0x1

HKEY_CURRENT_USER\Software\Microsoft\windows\CurrentVersion\Internet Settings\5.0\LowCache\Extensible Cache\UserData
    CachePrefix    REG_SZ    UserData
    CachePath    REG_EXPAND_SZ    %APPDATA%\Microsoft\Internet Explorer\UserData\Low
    CacheOptions    REG_DWORD    0x8
    CacheRepair    REG_DWORD    0x0
    CacheLimit    REG_DWORD    0x3e8

HKEY_CURRENT_USER\Software\Microsoft\windows\CurrentVersion\Internet Settings\5.0\LowCache\History
    CachePrefix    REG_SZ    Visited:
    CacheLimit    REG_DWORD    0x1

HKEY_CURRENT_USER\Software\Microsoft\windows\CurrentVersion\Internet Settings\5.0\NSCookieUpgrade

HKEY_CURRENT_USER\Software\Microsoft\windows\CurrentVersion\Internet Settings\5.0\User Agent

HKEY_CURRENT_USER\Software\Microsoft\windows\CurrentVersion\Internet Settings\5.0\User Agent\Post Platform

HKEY_CURRENT_USER\Software\Microsoft\windows\CurrentVersion\Internet Settings\Activities

HKEY_CURRENT_USER\Software\Microsoft\windows\CurrentVersion\Internet Settings\CACHE
    Persistent    REG_DWORD    0x1
    LastScavenge    REG_DWORD    0x0

HKEY_CURRENT_USER\Software\Microsoft\windows\CurrentVersion\Internet Settings\Connections
    DefaultConnectionSettings    REG_BINARY    460000006C0B000009000000000000000000000000000000040000000000000000000000000000000000000000000000000000000100000002000000C0A80751000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000
    SavedLegacySettings    REG_BINARY    46000000F50D000009000000000000000000000000000000040000000000000000000000000000000000000000000000000000000100000002000000C0A80751000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000

HKEY_CURRENT_USER\Software\Microsoft\windows\CurrentVersion\Internet Settings\Http Filters

HKEY_CURRENT_USER\Software\Microsoft\windows\CurrentVersion\Internet Settings\Lockdown_Zones

HKEY_CURRENT_USER\Software\Microsoft\windows\CurrentVersion\Internet Settings\Lockdown_Zones\0
    (Default)    REG_SZ   
    DisplayName    REG_SZ    Computer
    PMDisplayName    REG_SZ    Computer [Protected Mode]
    Description    REG_SZ    Your computer
    Icon    REG_SZ    shell32.dll#0016
    LowIcon    REG_SZ    inetcpl.cpl#005422
    CurrentLevel    REG_DWORD    0x0
    Flags    REG_DWORD    0x21
    1200    REG_DWORD    0x3
    1400    REG_DWORD    0x1
    1001    REG_DWORD    0x0
    1004    REG_DWORD    0x3
    1201    REG_DWORD    0x3
    1206    REG_DWORD    0x0
    1207    REG_DWORD    0x3
    1402    REG_DWORD    0x0
    1405    REG_DWORD    0x0
    1406    REG_DWORD    0x0
    1407    REG_DWORD    0x0
    1408    REG_DWORD    0x3
    1409    REG_DWORD    0x3
    140A    REG_DWORD    0x0
    1601    REG_DWORD    0x0
    1604    REG_DWORD    0x0
    1605    REG_DWORD    0x0
    1606    REG_DWORD    0x0
    1607    REG_DWORD    0x0
    1608    REG_DWORD    0x0
    1609    REG_DWORD    0x1
    160A    REG_DWORD    0x0
    160B    REG_DWORD    0x0
    1802    REG_DWORD    0x0
    1803    REG_DWORD    0x0
    1804    REG_DWORD    0x0
    1805    REG_DWORD    0x0
    1806    REG_DWORD    0x0
    1807    REG_DWORD    0x0
    1808    REG_DWORD    0x0
    1809    REG_DWORD    0x3
    1812    REG_DWORD    0x0
    1A00    REG_DWORD    0x0
    1A02    REG_DWORD    0x0
    1A03    REG_DWORD    0x0
    1A04    REG_DWORD    0x3
    1A05    REG_DWORD    0x0
    1A06    REG_DWORD    0x0
    1A10    REG_DWORD    0x0
    1C00    REG_DWORD    0x0
    2000    REG_DWORD    0x10000
    2005    REG_DWORD    0x3
    2100    REG_DWORD    0x3
    2101    REG_DWORD    0x3
    2102    REG_DWORD    0x3
    2200    REG_DWORD    0x3
    2201    REG_DWORD    0x3
    1208    REG_DWORD    0x3
    1209    REG_DWORD    0x3
    120A    REG_DWORD    0x3
    120B    REG_DWORD    0x0
    180A    REG_DWORD    0x0
    180C    REG_DWORD    0x0
    180D    REG_DWORD    0x0
    1810    REG_DWORD    0x3
    2301    REG_DWORD    0x3
    2302    REG_DWORD    0x3
    2103    REG_DWORD    0x3
    2104    REG_DWORD    0x3
    2105    REG_DWORD    0x3
    2106    REG_DWORD    0x3
    2107    REG_DWORD    0x3
    2108    REG_DWORD    0x3
    2400    REG_DWORD    0x0
    2401    REG_DWORD    0x0
    2402    REG_DWORD    0x0
    2600    REG_DWORD    0x0
    2500    REG_DWORD    0x3
    2700    REG_DWORD    0x3
    2701    REG_DWORD    0x3
    2702    REG_DWORD    0x3
    2703    REG_DWORD    0x3
    2704    REG_DWORD    0x3
    2707    REG_DWORD    0x3
    2708    REG_DWORD    0x3
    2709    REG_DWORD    0x3
    270B    REG_DWORD    0x3
    270C    REG_DWORD    0x3
    270D    REG_DWORD    0x3

HKEY_CURRENT_USER\Software\Microsoft\windows\CurrentVersion\Internet Settings\Lockdown_Zones\1
    (Default)    REG_SZ   
    DisplayName    REG_SZ    Local intranet
    PMDisplayName    REG_SZ    Local intranet [Protected Mode]
    Description    REG_SZ    This zone contains all Web sites that are on your organization's intranet.
    Icon    REG_SZ    shell32.dll#0018
    LowIcon    REG_SZ    inetcpl.cpl#005423
    CurrentLevel    REG_DWORD    0x0
    Flags    REG_DWORD    0xdb
    1200    REG_DWORD    0x3
    1400    REG_DWORD    0x1
    1001    REG_DWORD    0x1
    1004    REG_DWORD    0x3
    1201    REG_DWORD    0x3
    1206    REG_DWORD    0x0
    1207    REG_DWORD    0x3
    1402    REG_DWORD    0x0
    1405    REG_DWORD    0x0
    1406    REG_DWORD    0x1
    1407    REG_DWORD    0x0
    1408    REG_DWORD    0x3
    1409    REG_DWORD    0x3
    140A    REG_DWORD    0x0
    1601    REG_DWORD    0x0
    1604    REG_DWORD    0x0
    1605    REG_DWORD    0x0
    1606    REG_DWORD    0x0
    1607    REG_DWORD    0x0
    1608    REG_DWORD    0x0
    1609    REG_DWORD    0x1
    160A    REG_DWORD    0x3
    160B    REG_DWORD    0x0
    1802    REG_DWORD    0x0
    1803    REG_DWORD    0x0
    1804    REG_DWORD    0x1
    1805    REG_DWORD    0x0
    1806    REG_DWORD    0x0
    1807    REG_DWORD    0x0
    1808    REG_DWORD    0x0
    1809    REG_DWORD    0x3
    1812    REG_DWORD    0x0
    1A00    REG_DWORD    0x20000
    1A02    REG_DWORD    0x0
    1A03    REG_DWORD    0x0
    1A04    REG_DWORD    0x3
    1A05    REG_DWORD    0x0
    1A06    REG_DWORD    0x0
    1A10    REG_DWORD    0x0
    1C00    REG_DWORD    0x0
    2000    REG_DWORD    0x10000
    2005    REG_DWORD    0x3
    2100    REG_DWORD    0x3
    2101    REG_DWORD    0x3
    2102    REG_DWORD    0x3
    2200    REG_DWORD    0x3
    2201    REG_DWORD    0x3
    1208    REG_DWORD    0x3
    1209    REG_DWORD    0x3
    120A    REG_DWORD    0x3
    120B    REG_DWORD    0x0
    180A    REG_DWORD    0x0
    180C    REG_DWORD    0x0
    180D    REG_DWORD    0x0
    1810    REG_DWORD    0x3
    2301    REG_DWORD    0x3
    2302    REG_DWORD    0x3
    2103    REG_DWORD    0x3
    2104    REG_DWORD    0x3
    2105    REG_DWORD    0x3
    2106    REG_DWORD    0x3
    2107    REG_DWORD    0x3
    2108    REG_DWORD    0x3
    2400    REG_DWORD    0x0
    2401    REG_DWORD    0x0
    2402    REG_DWORD    0x0
    2600    REG_DWORD    0x0
    2500    REG_DWORD    0x3
    2700    REG_DWORD    0x0
    2701    REG_DWORD    0x3
    2702    REG_DWORD    0x3
    2703    REG_DWORD    0x0
    2704    REG_DWORD    0x3
    2707    REG_DWORD    0x3
    2708    REG_DWORD    0x3
    2709    REG_DWORD    0x3
    270B    REG_DWORD    0x0
    270C    REG_DWORD    0x0
    270D    REG_DWORD    0x3

HKEY_CURRENT_USER\Software\Microsoft\windows\CurrentVersion\Internet Settings\Lockdown_Zones\2
    (Default)    REG_SZ   
    DisplayName    REG_SZ    Trusted sites
    PMDisplayName    REG_SZ    Trusted sites [Protected Mode]
    Description    REG_SZ    This zone contains Web sites that you trust not to damage your computer or data.
    Icon    REG_SZ    inetcpl.cpl#00004480
    LowIcon    REG_SZ    inetcpl.cpl#005424
    CurrentLevel    REG_DWORD    0x0
    Flags    REG_DWORD    0x21
    1200    REG_DWORD    0x3
    1400    REG_DWORD    0x1
    1001    REG_DWORD    0x0
    1004    REG_DWORD    0x3
    1201    REG_DWORD    0x3
    1206    REG_DWORD    0x0
    1207    REG_DWORD    0x3
    1402    REG_DWORD    0x0
    1405    REG_DWORD    0x0
    1406    REG_DWORD    0x0
    1407    REG_DWORD    0x0
    1408    REG_DWORD    0x3
    1409    REG_DWORD    0x0
    140A    REG_DWORD    0x0
    1601    REG_DWORD    0x0
    1604    REG_DWORD    0x0
    1605    REG_DWORD    0x0
    1606    REG_DWORD    0x0
    1607    REG_DWORD    0x0
    1608    REG_DWORD    0x0
    1609    REG_DWORD    0x1
    160A    REG_DWORD    0x3
    160B    REG_DWORD    0x0
    1802    REG_DWORD    0x0
    1803    REG_DWORD    0x0
    1804    REG_DWORD    0x0
    1805    REG_DWORD    0x0
    1806    REG_DWORD    0x0
    1807    REG_DWORD    0x0
    1808    REG_DWORD    0x0
    1809    REG_DWORD    0x3
    1812    REG_DWORD    0x0
    1A00    REG_DWORD    0x0
    1A02    REG_DWORD    0x0
    1A03    REG_DWORD    0x0
    1A04    REG_DWORD    0x3
    1A05    REG_DWORD    0x1
    1A06    REG_DWORD    0x0
    1A10    REG_DWORD    0x0
    1C00    REG_DWORD    0x0
    2000    REG_DWORD    0x10000
    2005    REG_DWORD    0x3
    2100    REG_DWORD    0x3
    2101    REG_DWORD    0x3
    2102    REG_DWORD    0x3
    2200    REG_DWORD    0x3
    2201    REG_DWORD    0x3
    1208    REG_DWORD    0x3
    1209    REG_DWORD    0x3
    120A    REG_DWORD    0x3
    120B    REG_DWORD    0x0
    180A    REG_DWORD    0x3
    180C    REG_DWORD    0x0
    180D    REG_DWORD    0x0
    1810    REG_DWORD    0x3
    2301    REG_DWORD    0x0
    2302    REG_DWORD    0x3
    2103    REG_DWORD    0x3
    2104    REG_DWORD    0x3
    2105    REG_DWORD    0x3
    2106    REG_DWORD    0x3
    2107    REG_DWORD    0x3
    2108    REG_DWORD    0x3
    2400    REG_DWORD    0x0
    2401    REG_DWORD    0x0
    2402    REG_DWORD    0x0
    2600    REG_DWORD    0x0
    2500    REG_DWORD    0x3
    2700    REG_DWORD    0x0
    2701    REG_DWORD    0x0
    2702    REG_DWORD    0x0
    2703    REG_DWORD    0x0
    2704    REG_DWORD    0x0
    2707    REG_DWORD    0x3
    2708    REG_DWORD    0x3
    2709    REG_DWORD    0x3
    270B    REG_DWORD    0x0
    270C    REG_DWORD    0x0
    270D    REG_DWORD    0x3

HKEY_CURRENT_USER\Software\Microsoft\windows\CurrentVersion\Internet Settings\Lockdown_Zones\3
    (Default)    REG_SZ   
    DisplayName    REG_SZ    Internet
    PMDisplayName    REG_SZ    Internet [Protected Mode]
    Description    REG_SZ    This zone contains all Web sites you haven't placed in other zones
    Icon    REG_SZ    inetcpl.cpl#001313
    LowIcon    REG_SZ    inetcpl.cpl#005425
    CurrentLevel    REG_DWORD    0x0
    Flags    REG_DWORD    0x21
    1200    REG_DWORD    0x3
    1400    REG_DWORD    0x1
    1001    REG_DWORD    0x1
    1004    REG_DWORD    0x3
    1201    REG_DWORD    0x3
    1206    REG_DWORD    0x3
    1207    REG_DWORD    0x3
    1402    REG_DWORD    0x0
    1405    REG_DWORD    0x0
    1406    REG_DWORD    0x3
    1407    REG_DWORD    0x0
    1408    REG_DWORD    0x3
    1409    REG_DWORD    0x0
    140A    REG_DWORD    0x0
    1601    REG_DWORD    0x1
    1604    REG_DWORD    0x0
    1605    REG_DWORD    0x0
    1606    REG_DWORD    0x0
    1607    REG_DWORD    0x0
    1608    REG_DWORD    0x0
    1609    REG_DWORD    0x1
    160A    REG_DWORD    0x3
    160B    REG_DWORD    0x0
    1802    REG_DWORD    0x0
    1803    REG_DWORD    0x0
    1804    REG_DWORD    0x1
    1805    REG_DWORD    0x1
    1806    REG_DWORD    0x1
    1807    REG_DWORD    0x1
    1808    REG_DWORD    0x0
    1809    REG_DWORD    0x0
    1812    REG_DWORD    0x1
    1A00    REG_DWORD    0x20000
    1A02    REG_DWORD    0x0
    1A03    REG_DWORD    0x0
    1A04    REG_DWORD    0x3
    1A05    REG_DWORD    0x1
    1A06    REG_DWORD    0x0
    1A10    REG_DWORD    0x1
    1C00    REG_DWORD    0x0
    2000    REG_DWORD    0x10000
    2005    REG_DWORD    0x3
    2100    REG_DWORD    0x3
    2101    REG_DWORD    0x3
    2102    REG_DWORD    0x3
    2200    REG_DWORD    0x3
    2201    REG_DWORD    0x3
    1208    REG_DWORD    0x3
    1209    REG_DWORD    0x3
    120A    REG_DWORD    0x3
    120B    REG_DWORD    0x3
    180A    REG_DWORD    0x3
    180C    REG_DWORD    0x3
    180D    REG_DWORD    0x1
    1810    REG_DWORD    0x3
    2301    REG_DWORD    0x0
    2302    REG_DWORD    0x3
    2103    REG_DWORD    0x3
    2104    REG_DWORD    0x3
    2105    REG_DWORD    0x3
    2106    REG_DWORD    0x3
    2107    REG_DWORD    0x3
    2108    REG_DWORD    0x3
    2400    REG_DWORD    0x0
    2401    REG_DWORD    0x0
    2402    REG_DWORD    0x0
    2600    REG_DWORD    0x0
    2500    REG_DWORD    0x0
    2700    REG_DWORD    0x0
    2701    REG_DWORD    0x3
    2702    REG_DWORD    0x0
    2703    REG_DWORD    0x3
    2704    REG_DWORD    0x3
    2707    REG_DWORD    0x3
    2708    REG_DWORD    0x3
    2709    REG_DWORD    0x3
    270B    REG_DWORD    0x3
    270C    REG_DWORD    0x0
    270D    REG_DWORD    0x3

HKEY_CURRENT_USER\Software\Microsoft\windows\CurrentVersion\Internet Settings\Lockdown_Zones\4
    (Default)    REG_SZ   
    DisplayName    REG_SZ    Restricted sites
    PMDisplayName    REG_SZ    Restricted sites [Protected Mode]
    Description    REG_SZ    This zone contains Web sites that could potentially damage your computer or data.
    Icon    REG_SZ    inetcpl.cpl#00004481
    LowIcon    REG_SZ    inetcpl.cpl#005426
    CurrentLevel    REG_DWORD    0x0
    Flags    REG_DWORD    0x21
    1200    REG_DWORD    0x3
    1400    REG_DWORD    0x3
    1001    REG_DWORD    0x3
    1004    REG_DWORD    0x3
    1201    REG_DWORD    0x3
    1206    REG_DWORD    0x3
    1207    REG_DWORD    0x3
    1402    REG_DWORD    0x3
    1405    REG_DWORD    0x3
    1406    REG_DWORD    0x3
    1407    REG_DWORD    0x3
    1408    REG_DWORD    0x3
    1409    REG_DWORD    0x0
    140A    REG_DWORD    0x0
    1601    REG_DWORD    0x1
    1604    REG_DWORD    0x1
    1605    REG_DWORD    0x0
    1606    REG_DWORD    0x3
    1607    REG_DWORD    0x3
    1608    REG_DWORD    0x3
    1609    REG_DWORD    0x1
    160A    REG_DWORD    0x3
    160B    REG_DWORD    0x0
    1802    REG_DWORD    0x1
    1803    REG_DWORD    0x3
    1804    REG_DWORD    0x3
    1805    REG_DWORD    0x1
    1806    REG_DWORD    0x3
    1807    REG_DWORD    0x1
    1808    REG_DWORD    0x0
    1809    REG_DWORD    0x0
    180B    REG_DWORD    0x3
    1812    REG_DWORD    0x1
    1A00    REG_DWORD    0x10000
    1A02    REG_DWORD    0x3
    1A03    REG_DWORD    0x3
    1A04    REG_DWORD    0x3
    1A05    REG_DWORD    0x3
    1A06    REG_DWORD    0x3
    1A10    REG_DWORD    0x3
    1C00    REG_DWORD    0x0
    2000    REG_DWORD    0x3
    2005    REG_DWORD    0x3
    2100    REG_DWORD    0x3
    2101    REG_DWORD    0x3
    2102    REG_DWORD    0x3
    2200    REG_DWORD    0x3
    2201    REG_DWORD    0x3
    1208    REG_DWORD    0x3
    1209    REG_DWORD    0x3
    120A    REG_DWORD    0x3
    120B    REG_DWORD    0x3
    180A    REG_DWORD    0x3
    180C    REG_DWORD    0x3
    180D    REG_DWORD    0x1
    1810    REG_DWORD    0x3
    2301    REG_DWORD    0x0
    2302    REG_DWORD    0x3
    2103    REG_DWORD    0x3
    2104    REG_DWORD    0x3
    2105    REG_DWORD    0x3
    2106    REG_DWORD    0x3
    2107    REG_DWORD    0x3
    2108    REG_DWORD    0x3
    2400    REG_DWORD    0x3
    2401    REG_DWORD    0x3
    2402    REG_DWORD    0x3
    2600    REG_DWORD    0x3
    2500    REG_DWORD    0x0
    2700    REG_DWORD    0x0
    2701    REG_DWORD    0x3
    2702    REG_DWORD    0x0
    2703    REG_DWORD    0x3
    2704    REG_DWORD    0x3
    2707    REG_DWORD    0x3
    2708    REG_DWORD    0x3
    2709    REG_DWORD    0x3
    270B    REG_DWORD    0x3
    270C    REG_DWORD    0x0
    270D    REG_DWORD    0x3

HKEY_CURRENT_USER\Software\Microsoft\windows\CurrentVersion\Internet Settings\P3P

HKEY_CURRENT_USER\Software\Microsoft\windows\CurrentVersion\Internet Settings\P3P\History

HKEY_CURRENT_USER\Software\Microsoft\windows\CurrentVersion\Internet Settings\Passport
    NumRegistrationRuns    REG_DWORD    0x6

HKEY_CURRENT_USER\Software\Microsoft\windows\CurrentVersion\Internet Settings\Passport\LowDAMap

HKEY_CURRENT_USER\Software\Microsoft\windows\CurrentVersion\Internet Settings\Protocols

HKEY_CURRENT_USER\Software\Microsoft\windows\CurrentVersion\Internet Settings\Protocols\Mailto
    UTF8Encoding    REG_DWORD    0x1

HKEY_CURRENT_USER\Software\Microsoft\windows\CurrentVersion\Internet Settings\TemplatePolicies

HKEY_CURRENT_USER\Software\Microsoft\windows\CurrentVersion\Internet Settings\TemplatePolicies\High
    1400    REG_DWORD    0x3

HKEY_CURRENT_USER\Software\Microsoft\windows\CurrentVersion\Internet Settings\Url History
    DaysToKeep    REG_DWORD    0x0

HKEY_CURRENT_USER\Software\Microsoft\windows\CurrentVersion\Internet Settings\WebSocket

HKEY_CURRENT_USER\Software\Microsoft\windows\CurrentVersion\Internet Settings\Wpad

HKEY_CURRENT_USER\Software\Microsoft\windows\CurrentVersion\Internet Settings\Wpad\1c-14-48-34-b6-60
    WpadDecisionReason    REG_DWORD    0x1
    WpadDecisionTime    REG_BINARY    F466815D606DD301
    WpadDecision    REG_DWORD    0x0

HKEY_CURRENT_USER\Software\Microsoft\windows\CurrentVersion\Internet Settings\Wpad\e0-22-02-29-f2-f9
    WpadDecisionReason    REG_DWORD    0x1
    WpadDecisionTime    REG_BINARY    6BF25686C563D301
    WpadDecision    REG_DWORD    0x0
    WpadDetectedUrl    REG_SZ   

HKEY_CURRENT_USER\Software\Microsoft\windows\CurrentVersion\Internet Settings\Wpad\{7DCEFE5C-CFD1-4BEC-970C-AC237C6C1B96}
    WpadDecisionReason    REG_DWORD    0x1
    WpadDecisionTime    REG_BINARY    F466815D606DD301
    WpadDecision    REG_DWORD    0x0
    WpadNetworkName    REG_SZ    Network

HKEY_CURRENT_USER\Software\Microsoft\windows\CurrentVersion\Internet Settings\Wpad\{7DCEFE5C-CFD1-4BEC-970C-AC237C6C1B96}\1c-14-48-34-b6-60

HKEY_CURRENT_USER\Software\Microsoft\windows\CurrentVersion\Internet Settings\Wpad\{817DBBA2-1AD9-43CF-BFC5-61CA28DF7402}
    WpadDecisionReason    REG_DWORD    0x1
    WpadDecisionTime    REG_BINARY    6BF25686C563D301
    WpadDecision    REG_DWORD    0x0
    WpadNetworkName    REG_SZ    Network  3

HKEY_CURRENT_USER\Software\Microsoft\windows\CurrentVersion\Internet Settings\Wpad\{817DBBA2-1AD9-43CF-BFC5-61CA28DF7402}\e0-22-02-29-f2-f9

HKEY_CURRENT_USER\Software\Microsoft\windows\CurrentVersion\Internet Settings\ZoneMap
    ProxyBypass    REG_DWORD    0x1
    IntranetName    REG_DWORD    0x1
    UNCAsIntranet    REG_DWORD    0x1
    AutoDetect    REG_DWORD    0x0
    (Default)    REG_SZ   

HKEY_CURRENT_USER\Software\Microsoft\windows\CurrentVersion\Internet Settings\ZoneMap\Domains
    (Default)    REG_SZ   

HKEY_CURRENT_USER\Software\Microsoft\windows\CurrentVersion\Internet Settings\ZoneMap\EscDomains

HKEY_CURRENT_USER\Software\Microsoft\windows\CurrentVersion\Internet Settings\ZoneMap\EscDomains\microsoft.com

HKEY_CURRENT_USER\Software\Microsoft\windows\CurrentVersion\Internet Settings\ZoneMap\EscDomains\microsoft.com\*.update
    http    REG_DWORD    0x2
    https    REG_DWORD    0x2

HKEY_CURRENT_USER\Software\Microsoft\windows\CurrentVersion\Internet Settings\ZoneMap\ProtocolDefaults
    (Default)    REG_SZ   
    http    REG_DWORD    0x3
    https    REG_DWORD    0x3
    ftp    REG_DWORD    0x3
    file    REG_DWORD    0x3
    @ivt    REG_DWORD    0x1
    shell    REG_DWORD    0x0
    knownfolder    REG_DWORD    0x0

HKEY_CURRENT_USER\Software\Microsoft\windows\CurrentVersion\Internet Settings\ZoneMap\Ranges
    (Default)    REG_SZ   

HKEY_CURRENT_USER\Software\Microsoft\windows\CurrentVersion\Internet Settings\Zones
    (Default)    REG_SZ   
    SecuritySafe    REG_DWORD    0x1

HKEY_CURRENT_USER\Software\Microsoft\windows\CurrentVersion\Internet Settings\Zones\0
    2004    REG_DWORD    0x3
    2001    REG_DWORD    0x3
    2007    REG_DWORD    0x3
    (Default)    REG_SZ   
    DisplayName    REG_SZ    Computer
    PMDisplayName    REG_SZ    Computer [Protected Mode]
    Description    REG_SZ    Your computer
    Icon    REG_SZ    shell32.dll#0016
    LowIcon    REG_SZ    inetcpl.cpl#005422
    CurrentLevel    REG_DWORD    0x0
    Flags    REG_DWORD    0x21
    1200    REG_DWORD    0x0
    1400    REG_DWORD    0x0
    1001    REG_DWORD    0x0
    1405    REG_DWORD    0x0
    1004    REG_DWORD    0x1
    1201    REG_DWORD    0x1
    1206    REG_DWORD    0x0
    1207    REG_DWORD    0x0
    1402    REG_DWORD    0x0
    1406    REG_DWORD    0x0
    1407    REG_DWORD    0x0
    1408    REG_DWORD    0x0
    1409    REG_DWORD    0x3
    140A    REG_DWORD    0x0
    1601    REG_DWORD    0x0
    1604    REG_DWORD    0x0
    1605    REG_DWORD    0x0
    1606    REG_DWORD    0x0
    1607    REG_DWORD    0x0
    1608    REG_DWORD    0x0
    1609    REG_DWORD    0x1
    160A    REG_DWORD    0x0
    160B    REG_DWORD    0x0
    1802    REG_DWORD    0x0
    1803    REG_DWORD    0x0
    1804    REG_DWORD    0x0
    1805    REG_DWORD    0x0
    1806    REG_DWORD    0x0
    1807    REG_DWORD    0x0
    1808    REG_DWORD    0x0
    1809    REG_DWORD    0x3
    1812    REG_DWORD    0x0
    1A00    REG_DWORD    0x0
    1A02    REG_DWORD    0x0
    1A03    REG_DWORD    0x0
    1A04    REG_DWORD    0x0
    1A05    REG_DWORD    0x0
    1A06    REG_DWORD    0x0
    1A10    REG_DWORD    0x0
    1C00    REG_DWORD    0x20000
    2100    REG_DWORD    0x0
    2101    REG_DWORD    0x3
    2102    REG_DWORD    0x0
    2200    REG_DWORD    0x0
    2201    REG_DWORD    0x0
    2300    REG_DWORD    0x1
    2000    REG_DWORD    0x0
    2005    REG_DWORD    0x0
    1208    REG_DWORD    0x0
    1209    REG_DWORD    0x0
    120A    REG_DWORD    0x0
    120B    REG_DWORD    0x0
    180A    REG_DWORD    0x0
    180C    REG_DWORD    0x0
    180D    REG_DWORD    0x0
    1810    REG_DWORD    0x3
    2301    REG_DWORD    0x3
    2302    REG_DWORD    0x3
    2103    REG_DWORD    0x0
    2104    REG_DWORD    0x0
    2105    REG_DWORD    0x0
    2106    REG_DWORD    0x0
    2107    REG_DWORD    0x0
    2108    REG_DWORD    0x3
    2400    REG_DWORD    0x0
    2401    REG_DWORD    0x0
    2402    REG_DWORD    0x0
    2600    REG_DWORD    0x0
    2500    REG_DWORD    0x3
    2700    REG_DWORD    0x3
    2701    REG_DWORD    0x0
    2702    REG_DWORD    0x3
    2703    REG_DWORD    0x3
    2704    REG_DWORD    0x0
    2707    REG_DWORD    0x3
    2708    REG_DWORD    0x3
    2709    REG_DWORD    0x3
    270B    REG_DWORD    0x3
    270C    REG_DWORD    0x3
    270D    REG_DWORD    0x0

HKEY_CURRENT_USER\Software\Microsoft\windows\CurrentVersion\Internet Settings\Zones\1
    2004    REG_DWORD    0x0
    2001    REG_DWORD    0x0
    2007    REG_DWORD    0x10000
    (Default)    REG_SZ   
    DisplayName    REG_SZ    Local intranet
    PMDisplayName    REG_SZ    Local intranet [Protected Mode]
    Description    REG_SZ    This zone contains all websites that are on your organization's intranet.
    Icon    REG_SZ    shell32.dll#0018
    LowIcon    REG_SZ    inetcpl.cpl#005423
    CurrentLevel    REG_DWORD    0x10500
    Flags    REG_DWORD    0xdb
    1200    REG_DWORD    0x0
    1400    REG_DWORD    0x0
    2500    REG_DWORD    0x3
    1001    REG_DWORD    0x1
    1004    REG_DWORD    0x3
    1201    REG_DWORD    0x3
    1206    REG_DWORD    0x0
    1207    REG_DWORD    0x0
    1402    REG_DWORD    0x0
    1405    REG_DWORD    0x0
    1406    REG_DWORD    0x1
    1407    REG_DWORD    0x0
    1408    REG_DWORD    0x0
    1409    REG_DWORD    0x3
    140A    REG_DWORD    0x0
    1601    REG_DWORD    0x0
    1604    REG_DWORD    0x0
    1605    REG_DWORD    0x0
    1606    REG_DWORD    0x0
    1607    REG_DWORD    0x0
    1608    REG_DWORD    0x0
    1609    REG_DWORD    0x1
    160A    REG_DWORD    0x0
    160B    REG_DWORD    0x0
    1802    REG_DWORD    0x0
    1803    REG_DWORD    0x0
    1804    REG_DWORD    0x1
    1805    REG_DWORD    0x0
    1806    REG_DWORD    0x0
    1807    REG_DWORD    0x0
    1808    REG_DWORD    0x0
    1809    REG_DWORD    0x3
    1812    REG_DWORD    0x0
    1A00    REG_DWORD    0x20000
    1A02    REG_DWORD    0x0
    1A03    REG_DWORD    0x0
    1A04    REG_DWORD    0x0
    1A05    REG_DWORD    0x0
    1A06    REG_DWORD    0x0
    1A10    REG_DWORD    0x0
    1C00    REG_DWORD    0x20000
    2100    REG_DWORD    0x0
    2101    REG_DWORD    0x0
    2102    REG_DWORD    0x0
    2200    REG_DWORD    0x0
    2201    REG_DWORD    0x0
    2300    REG_DWORD    0x1
    2000    REG_DWORD    0x0
    2005    REG_DWORD    0x0
    1208    REG_DWORD    0x0
    1209    REG_DWORD    0x0
    120A    REG_DWORD    0x3
    120B    REG_DWORD    0x0
    180A    REG_DWORD    0x0
    180C    REG_DWORD    0x0
    180D    REG_DWORD    0x0
    1810    REG_DWORD    0x3
    2301    REG_DWORD    0x3
    2302    REG_DWORD    0x3
    2103    REG_DWORD    0x0
    2104    REG_DWORD    0x0
    2105    REG_DWORD    0x0
    2106    REG_DWORD    0x0
    2107    REG_DWORD    0x0
    2108    REG_DWORD    0x3
    2400    REG_DWORD    0x0
    2401    REG_DWORD    0x0
    2402    REG_DWORD    0x0
    2600    REG_DWORD    0x0
    2700    REG_DWORD    0x3
    2701    REG_DWORD    0x0
    2702    REG_DWORD    0x3
    2703    REG_DWORD    0x0
    2704    REG_DWORD    0x0
    2707    REG_DWORD    0x3
    2708    REG_DWORD    0x3
    2709    REG_DWORD    0x3
    270B    REG_DWORD    0x0
    270C    REG_DWORD    0x3
    270D    REG_DWORD    0x0
    140C    REG_DWORD    0x0

HKEY_CURRENT_USER\Software\Microsoft\windows\CurrentVersion\Internet Settings\Zones\2
    2001    REG_DWORD    0x0
    2004    REG_DWORD    0x0
    2007    REG_DWORD    0x10000
    (Default)    REG_SZ   
    DisplayName    REG_SZ    Trusted sites
    PMDisplayName    REG_SZ    Trusted sites [Protected Mode]
    Description    REG_SZ    This zone contains websites that you trust not to damage your computer or data.
    Icon    REG_SZ    inetcpl.cpl#00004480
    LowIcon    REG_SZ    inetcpl.cpl#005424
    CurrentLevel    REG_DWORD    0x11000
    Flags    REG_DWORD    0x47
    1200    REG_DWORD    0x0
    1400    REG_DWORD    0x0
    1001    REG_DWORD    0x0
    1004    REG_DWORD    0x3
    1201    REG_DWORD    0x3
    1206    REG_DWORD    0x3
    1207    REG_DWORD    0x0
    1208    REG_DWORD    0x0
    1209    REG_DWORD    0x3
    120A    REG_DWORD    0x3
    120B    REG_DWORD    0x0
    1402    REG_DWORD    0x0
    1405    REG_DWORD    0x0
    1406    REG_DWORD    0x3
    1407    REG_DWORD    0x1
    1408    REG_DWORD    0x0
    1409    REG_DWORD    0x0
    1601    REG_DWORD    0x0
    1604    REG_DWORD    0x0
    1605    REG_DWORD    0x0
    1606    REG_DWORD    0x0
    1607    REG_DWORD    0x3
    1608    REG_DWORD    0x0
    1609    REG_DWORD    0x1
    160A    REG_DWORD    0x0
    1802    REG_DWORD    0x0
    1803    REG_DWORD    0x0
    1804    REG_DWORD    0x1
    1809    REG_DWORD    0x0
    1A00    REG_DWORD    0x20000
    1A02    REG_DWORD    0x0
    1A03    REG_DWORD    0x0
    1A04    REG_DWORD    0x3
    1A05    REG_DWORD    0x1
    1A06    REG_DWORD    0x0
    1C00    REG_DWORD    0x10000
    2000    REG_DWORD    0x0
    2005    REG_DWORD    0x0
    2100    REG_DWORD    0x0
    2101    REG_DWORD    0x0
    2102    REG_DWORD    0x3
    2103    REG_DWORD    0x0
    2104    REG_DWORD    0x0
    2105    REG_DWORD    0x0
    2106    REG_DWORD    0x0
    2200    REG_DWORD    0x3
    2201    REG_DWORD    0x3
    2300    REG_DWORD    0x1
    2301    REG_DWORD    0x0
    2400    REG_DWORD    0x0
    2401    REG_DWORD    0x0
    2402    REG_DWORD    0x0
    2600    REG_DWORD    0x0
    2700    REG_DWORD    0x3
    2107    REG_DWORD    0x0
    140A    REG_DWORD    0x0
    2302    REG_DWORD    0x3
    270B    REG_DWORD    0x0
    160B    REG_DWORD    0x0
    270C    REG_DWORD    0x3
    270D    REG_DWORD    0x0
    2701    REG_DWORD    0x0
    2702    REG_DWORD    0x0
    2703    REG_DWORD    0x0
    2704    REG_DWORD    0x0
    2708    REG_DWORD    0x3
    2709    REG_DWORD    0x3
    1812    REG_DWORD    0x0
    2108    REG_DWORD    0x3
    1805    REG_DWORD    0x0
    1806    REG_DWORD    0x0
    1807    REG_DWORD    0x0
    1808    REG_DWORD    0x0
    1A10    REG_DWORD    0x0
    180A    REG_DWORD    0x3
    180C    REG_DWORD    0x0
    180D    REG_DWORD    0x0
    1810    REG_DWORD    0x3
    2500    REG_DWORD    0x3
    2707    REG_DWORD    0x3
    140C    REG_DWORD    0x0

HKEY_CURRENT_USER\Software\Microsoft\windows\CurrentVersion\Internet Settings\Zones\3
    2004    REG_DWORD    0x0
    2001    REG_DWORD    0x0
    2007    REG_DWORD    0x10000
    {AEBA21FA-782A-4A90-978D-B72164C80120}    REG_BINARY    1A3761592352350C7A5F20172F1E1A190E2B01731E281A041B0C3BC22127530D36052C05043D4F3A4A44333A0A061268537C2013355D4C102701567A2D3F384F790F162675531C3100567A3E32244F791B0033714D2332297C6A35313440723B012E5D4C2A07154872381200567A3E163C714D2433357C72350E3C1A4144190F313A567A2E3E310C7C6A10270C055D4C3919121561542E003332405203251F055D4C2C0C0A1561541A261F055D4C10211D1B714D3B243A216D7224163C324072210F3A1A41441B1E0101714D322330276D4D1F28103C567A2F2E32167C6A3A123B2875530B3F1201714D2332292775531230321E4F7912381701714D303E37276D7238123F0441440A0E3228495F1C240B1B3621417B5B2439317C6A2B0E2575531A2E264172341626714D30303A7C6A07331A567A3A0033714D2332297C6A1A261A4052243F1A6D4D1C2228755313252041440A0E327553080720714D10270D055D4C241A1E1B714D3F203F216D4D10270C055D4C3919123A567A3A202C0C7C6A3E0C370775531230323A567A252D230C7C6A2B08213A567A223A323A5672241E261A4144071F031B75531C310101714D322330276D72341E300441441B1E3B28495F0733121B5D4C350B0A1F75530B00342840723B012D04414401053428405222360434487238123F0441440A0E1F01714D24333527061C685349142101405210270D40522C29056D4D1F2805567A2F2E32755307331240523F3A196D72200034714D1A261A4052243F1A6D723508385D4C2D0118487A27231F567A3B2F3F4F790839011B7172331F393A567A2E3E310C7C72350E3F1A41440A0A353A567A3A202C0C7C6A03251F055D4C2C0C0A156154270534324052102109055D4C2D0118156154073717055D4C1C24031B714D30303B276D7233173F284072341E300441441B1E0001714D2F2C2C276D4D0B263F3C567A3A2023167C6A35053328755312301701714D303E372775531325201E4F791F291F01714D243335270621417B5B3D24377C6A2B0E254072331F395D72341E305D4C2A0D18487A27123B714D2332125672200C2E5D4C2C0C0A75531A261F40723508385D4C2D011875530F21274144071F3E61543D06223240522C2905324872341E051B714D10270C055D4C39191A1B714D233224216D4D03251F055D4C2C0C0A3A567A252D230C7C6A2B08210775531325203A567A3E3E3B0C7C6A3F0F233A567A2F2E3D3C5672331F390441441A0E050175531C310001714D2F2C2C276D72200C2D04414406182A28495F1A261A1B5D4C2C0C0F1F75531C1C3E28407238123F0441440A163C2840523E3906342121417B5B23273C7C6A17371740523224056D4D0E212C75530B31317553083E214144071E3C6154173717055D4C00331E1B714D2E393B216D72200632324072210F3C1A41441A0E1F01714D202C30276D4D0E212C3C567A3A2E2D167C6A3F0722286E02684A7C2109265D4C291D1F567A3F32384F791E3001567A3A2E2D4F79140722714D24303B7C6A2A1E2F0775530C2D263A567A31253D0C7C6A3E0E353A567A3B2F3D3A5672341E260441440B0A1E0175530E380101714D23302B276D72210F3C04281B676B5F00221075531F212741440B0A3175530E1D22714D03271D40523E3908755308312141441A0E323A567A3F32380C7C6A063E0D055D4C350D091561542907223240521737171B5D4C3A19161F6154063E0D1B5D4C03271101714D24333B27062141734111251D567A2E3E3B4F7918123F714D2E393B7C6A3E0E354072210F3C5D4C360D194872341E1F1B714D003316055D4C3804011B714D23302B216D4D1C240D055D4C291D173C567A3F3238167C6A3909250975530B31313C567A3B2F3D1615395F7B4203380240202C1E4F37417B5B23273C7C1407226E14684A7C2013355D3037080637417B5B23273C7C1B391D30027C50683A3B344F1B1E3B6E146873410B220A5612303228096773410B222A412C0C0F2137417B5B23273C7C081C3E660E444F560613056127231F4F3F5B537C2013355D3E3906060A68537C2109265D32123F6E14684A443E37026D1C24014F3F5B7341083827413804196E14684A443E37026D3E0E353B37417B5B2439317C0839004F3F7C50683B1D3C71252D2C203A7C50683B253B4F011D2A6E14684A443E37026D102109291F5E45671430074912163C660E44734108382741360A1B213F427341103B2D4100331E4F3F5B535E2E071D75210722660E7C50682324314F0D15014F3F5B535E2E071D480B183C6E14684A4426360C6D2B06256637417B5B142101403A31241537417B5B3C3E3F7C1238174F3F5B535E2E071D75350838360356767437081940073717291F7C50682324314F071F3E16177C5068203A397525123F660E444F561C121D561C240D2937417B5B3D24377C1E1D22660E444F561C1230612313114F3F5B535E2F01154810270C6E14684A7C3612385D243F196E14684A44212C046D350534660E444F561C121D561C3B252809676B5F012C2875241E263637417B5B3D24377C143A0B3037417B5B360C7C
    1A10    REG_DWORD    0x1
    {A8A88C49-5EB2-4990-A1A2-0876022C854F}    REG_BINARY    1A3761592352350C7A5F20172F1E1A190E2B01731E281A041B0C3BC2212D534907250F29017C50683A3B344F7908390D4972331F395D4C173705567A2F2E324F791F123B75530B3F12567A3A20234F79120533714D3A31297C6A2B0821407238123F5D4C391D174872210F03567A2F06223240522C29053A567A2E3E310C7C6A2B06253240523324013275530B3F32044F791B3B1F0C40723B012D1A755312303F044F79083F090C7553132520047553073717055D4C360A1B3A5672350E3C3C567A2D3F38167C6A1737011B5D4C2A0D181F615412123B2840523F3A19344872200C1701714D1A261A1B5D4C2C0C1701714D303E37276D4D1B3B0C1B5D4C391D173C567A3B2F3F1615395F7B42291D3C714D300622714D3223307C6A2A1E1975531C3120417224123B714D2332247C6A032517567A250533714D3A31297C6A1021094052272C0B6D4D0F282A7553083E2341441B1E3C3A567A1234160575531F212D044F7910270C055D4C3919121575530B3F32044F791B0034324052243F1932487A2C10171B714D301C3E324052272C0B32487A27163C3240523E07203A567A2F2E3D167C6A12341E01714D1737011B5D4C2A0D183C567A3E3224167C6A3E0C340975530B3F3F1E4F791238120171723B012E3C567A2F2439167C7238123F0441440A0E323C567A3B2F3F1615397C50682324314F7908390D495F1234164052173701405222380B6D4D0F341A567A3A202C755303251F4052243F196D723B0534714D1021094052272C0B6D72241E265D4C360A1B487A3613011B714D322330216D4D1737013A567A2F06253240523324013A567A3A202C0C7C6A3E0034324052243F1932755312303F044F79083F090C407238123F1A75530F2127044F79143A0B0C75531C31211E75531234161B5D4C291D1D3C5672350E3F3C567A3E3224167C6A03251A1B5D4C350B0F1F6154270533284052243F1A34487235081D01714D1B3B0C1B5D4C391D1F01714D24333527061C7C5068203A394F79080622714D3223307C6A2A1E194072350E3F5D72241A255D4C350B0A487A230034714D3A311256723B012E5D4C2A071575531B3B0C4072241E265D4C360A1B75531C3121044F790A2A060C4072341E301A41441B1E3B3A567A0733120575530B3F32044F7903251F055D4C2C0C0A15755312303F044F79081C3E324052272C0B32487A27231F1B714D24072032405222380834487A34173F2840522316263C567A2F2E32167C6A07331A01714D03251A1B5D4C350B0F3C567A252D2C167C6A3531370975531C3B251E4F79133500017172241E263C567A3B2F3F161521417B5B23273C7C6A2A163C714D202C307C6A063E0D40523F38186D4D08272C755308312175531F2127044F79182D060C75530E382104755303271D055D4C360A193A5672341E263C567A3F3238167C6A063E0D1B5D4C350D091F61542907222829015E456714301F567A1737174072251A395D4C380401567A3A2E2D4F79143A01567A3B2E3D4F790F163C32405232240532487A1828011B714D2306323240523E390832487A37163C28405232123F3C567A31253D167C6A03271101714D1C240D1B361D56767414210140522328026D4D0C342B75530E38214144061E2C7553080722714D1C270D40522328023A567A3F32380C7C6A391D223240523F3818327553083E21044F790F2907024072251A390475530E38211E4F791B391D027553083E211E6E027C5068203A394F790F163C75530C2D1E567A31253D4F791B0632714D24333B7C6A3F0E254072341E261A41440B0A313A567A063E0D0575530B3131044F791C240D055D4C291D171F75530C2D261E4F791E1D222840523F381834487A22120101661C4473410B222A413A1916212D4273410B222A411C24014F2D5B535E351E2275271D22661C7C50683A3B344F061E114F2D5B535E351E22481C182D6E02684A443F2D316D3505336621417B5B033802403A31291521417B5B23273C7C083F1D4F2D5B535E351E2275241E26361D5676743E031C401C240B29017C50683B253B4F0B0A3116057C50683B253B75210722661C444F5607151F56063E0D2921417B5B2439317C1B0632661C444F56071532613613004F2D5B535E360417481A261A6E02684A7C2109265D243F1A6E02684A443E37026D2B1C3E661C444F5607151F560F2127281B676B5F08212A75210F3A3621417B5B3C3E3F7C182D063021417B5B3C3E05561C240D29015E45670C1C267527093C6E02684A4426360C6D03271D29015E45670C3F31493D0625661C444F561F1438753B01124F2D5B7341103B2D412C0C174F2D5B535E2E071D4810210929015E45670C1C26713E3E3B2028744E682A290556083E236E02684A44212C046D3B1A206E02684A44211A3E75210F3C361D567674153B1D560E38014F2D5B535E2F011575200E2C361D5676742802214010270C29015E45670D351D56120533661C7C5068203A394F010534661C444F561C123075350838361D567674153B09402F203115395F7B42201A3E713B2F034F2D5B535E203974
    (Default)    REG_SZ   
    DisplayName    REG_SZ    Internet
    PMDisplayName    REG_SZ    Internet [Protected Mode]
    Description    REG_SZ    This zone contains all websites you haven't placed in other zones
    Icon    REG_SZ    inetcpl.cpl#001313
    LowIcon    REG_SZ    inetcpl.cpl#005425
    CurrentLevel    REG_DWORD    0x11500
    Flags    REG_DWORD    0x1
    1200    REG_DWORD    0x0
    1400    REG_DWORD    0x0
    1001    REG_DWORD    0x1
    1004    REG_DWORD    0x3
    1201    REG_DWORD    0x3
    1206    REG_DWORD    0x3
    1207    REG_DWORD    0x3
    1208    REG_DWORD    0x3
    1209    REG_DWORD    0x3
    120A    REG_DWORD    0x3
    120B    REG_DWORD    0x3
    1402    REG_DWORD    0x0
    1405    REG_DWORD    0x0
    1406    REG_DWORD    0x3
    1407    REG_DWORD    0x1
    1408    REG_DWORD    0x3
    1409    REG_DWORD    0x0
    1601    REG_DWORD    0x0
    1604    REG_DWORD    0x0
    1605    REG_DWORD    0x0
    1606    REG_DWORD    0x0
    1607    REG_DWORD    0x3
    1608    REG_DWORD    0x0
    1609    REG_DWORD    0x1
    160A    REG_DWORD    0x3
    1802    REG_DWORD    0x0
    1803    REG_DWORD    0x0
    1804    REG_DWORD    0x1
    1809    REG_DWORD    0x0
    1A00    REG_DWORD    0x20000
    1A02    REG_DWORD    0x0
    1A03    REG_DWORD    0x0
    1A04    REG_DWORD    0x3
    1A05    REG_DWORD    0x1
    1A06    REG_DWORD    0x0
    1C00    REG_DWORD    0x10000
    2000    REG_DWORD    0x0
    2005    REG_DWORD    0x3
    2100    REG_DWORD    0x0
    2101    REG_DWORD    0x0
    2102    REG_DWORD    0x3
    2103    REG_DWORD    0x3
    2104    REG_DWORD    0x3
    2105    REG_DWORD    0x3
    2106    REG_DWORD    0x0
    2200    REG_DWORD    0x3
    2201    REG_DWORD    0x3
    2300    REG_DWORD    0x1
    2301    REG_DWORD    0x0
    2400    REG_DWORD    0x3
    2401    REG_DWORD    0x0
    2402    REG_DWORD    0x3
    2600    REG_DWORD    0x0
    2700    REG_DWORD    0x0
    2107    REG_DWORD    0x3
    140A    REG_DWORD    0x0
    2302    REG_DWORD    0x3
    270B    REG_DWORD    0x3
    160B    REG_DWORD    0x0
    270C    REG_DWORD    0x0
    270D    REG_DWORD    0x3
    2701    REG_DWORD    0x0
    2702    REG_DWORD    0x0
    2703    REG_DWORD    0x3
    2704    REG_DWORD    0x0
    2708    REG_DWORD    0x3
    2709    REG_DWORD    0x3
    1812    REG_DWORD    0x1
    1805    REG_DWORD    0x1
    1806    REG_DWORD    0x1
    1807    REG_DWORD    0x1
    1808    REG_DWORD    0x0
    2108    REG_DWORD    0x3
    180A    REG_DWORD    0x3
    180C    REG_DWORD    0x3
    180D    REG_DWORD    0x1
    1810    REG_DWORD    0x3
    2500    REG_DWORD    0x0
    2707    REG_DWORD    0x3
    140C    REG_DWORD    0x0

HKEY_CURRENT_USER\Software\Microsoft\windows\CurrentVersion\Internet Settings\Zones\4
    2004    REG_DWORD    0x3
    2001    REG_DWORD    0x3
    2007    REG_DWORD    0x3
    1400    REG_DWORD    0x3
    1C00    REG_DWORD    0x0
    {AEBA21FA-782A-4A90-978D-B72164C80120}    REG_BINARY    1A3761592352350C7A5F20172F1E1A190E2B017313371312141A1539
    1A10    REG_DWORD    0x3
    {A8A88C49-5EB2-4990-A1A2-0876022C854F}    REG_BINARY    1A3761592352350C7A5F20172F1E1A190E2B017313371312141A1539
    (Default)    REG_SZ   
    DisplayName    REG_SZ    Restricted sites
    PMDisplayName    REG_SZ    Restricted sites [Protected Mode]
    Description    REG_SZ    This zone contains websites that could potentially damage your computer or data.
    Icon    REG_SZ    inetcpl.cpl#00004481
    LowIcon    REG_SZ    inetcpl.cpl#005426
    CurrentLevel    REG_DWORD    0x12000
    Flags    REG_DWORD    0x3
    1200    REG_DWORD    0x3
    1001    REG_DWORD    0x3
    1004    REG_DWORD    0x3
    1201    REG_DWORD    0x3
    1206    REG_DWORD    0x3
    1207    REG_DWORD    0x3
    1402    REG_DWORD    0x3
    1405    REG_DWORD    0x3
    1406    REG_DWORD    0x3
    1407    REG_DWORD    0x3
    1408    REG_DWORD    0x3
    1409    REG_DWORD    0x0
    140A    REG_DWORD    0x0
    1601    REG_DWORD    0x1
    1604    REG_DWORD    0x3
    1605    REG_DWORD    0x0
    1606    REG_DWORD    0x3
    1607    REG_DWORD    0x3
    1608    REG_DWORD    0x3
    1609    REG_DWORD    0x1
    160A    REG_DWORD    0x3
    160B    REG_DWORD    0x0
    1802    REG_DWORD    0x1
    1803    REG_DWORD    0x3
    1804    REG_DWORD    0x3
    1805    REG_DWORD    0x1
    1806    REG_DWORD    0x3
    1807    REG_DWORD    0x1
    1808    REG_DWORD    0x0
    1809    REG_DWORD    0x0
    180B    REG_DWORD    0x1
    1812    REG_DWORD    0x1
    1A00    REG_DWORD    0x10000
    1A02    REG_DWORD    0x3
    1A03    REG_DWORD    0x3
    1A04    REG_DWORD    0x3
    1A05    REG_DWORD    0x3
    1A06    REG_DWORD    0x3
    2100    REG_DWORD    0x3
    2101    REG_DWORD    0x3
    2102    REG_DWORD    0x3
    2200    REG_DWORD    0x3
    2201    REG_DWORD    0x3
    2300    REG_DWORD    0x3
    2000    REG_DWORD    0x3
    2005    REG_DWORD    0x3
    1208    REG_DWORD    0x3
    1209    REG_DWORD    0x3
    120A    REG_DWORD    0x3
    120B    REG_DWORD    0x3
    2103    REG_DWORD    0x3
    2104    REG_DWORD    0x3
    2105    REG_DWORD    0x3
    2106    REG_DWORD    0x3
    2107    REG_DWORD    0x3
    2108    REG_DWORD    0x3
    2301    REG_DWORD    0x0
    2302    REG_DWORD    0x3
    2400    REG_DWORD    0x3
    2401    REG_DWORD    0x3
    2402    REG_DWORD    0x3
    2600    REG_DWORD    0x3
    180A    REG_DWORD    0x3
    180C    REG_DWORD    0x3
    180D    REG_DWORD    0x1
    1810    REG_DWORD    0x3
    2500    REG_DWORD    0x0
    2700    REG_DWORD    0x0
    2701    REG_DWORD    0x3
    2702    REG_DWORD    0x0
    2703    REG_DWORD    0x3
    2704    REG_DWORD    0x3
    2707    REG_DWORD    0x3
    2708    REG_DWORD    0x3
    2709    REG_DWORD    0x3
    270B    REG_DWORD    0x3
    270C    REG_DWORD    0x0
    270D    REG_DWORD    0x3
    140C    REG_DWORD    0x0

 


  • 0

#55
RKinner

RKinner

    Malware Expert

  • Expert
  • 20,001 posts
  • MVP

Can you attach or post on dropbox:

 

C:\Users\JB\AppData\Local\Intuit\QuickBooks\Log\28.0\QBWin.log ?

 

This is a hidden location so you may need to tell windows to let you see it:

 

Control Panel, (View By:  Large Icons)  Folder Options, View.

Uncheck Hide Extensions for Known File Types
Uncheck Hide Protected System Files
Check Show Hidden Files,Folders and Drives.
OK


  • 0

Advertisements







Similar Topics

0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users

As Featured On:

Microsoft Yahoo BBC MSN PC Magazine Washington Post HP