魔盾安全分析报告

分析类型 开始时间 结束时间 持续时间 分析引擎版本
FILE 2020-04-26 12:25:06 2020-04-26 12:25:44 38 秒 1.4-Maldun
虚拟机机器名 标签 虚拟机管理 开机时间 关机时间
win7-sp1-x64-shaapp01-1 win7-sp1-x64-shaapp01-1 KVM 2020-04-26 12:25:09 None
魔盾分数

10.0

恶意的

文件详细信息

文件名 Plants_Vs_Zombies_V1.0.0.1051_CN_V2.exe
文件大小 27593846 字节
文件类型 PE32 executable (GUI) Intel 80386, for MS Windows, RAR self-extracting archive
CRC32 6A7CD787
MD5 91fa4faf6b80c90f4bc4ac6d2d4ac4cc
SHA1 4f616cfdac52173cff00870eed89ba65eb9849b7
SHA256 11e992381be482c9337ca2162759b316297a46f4f371e9ffd61ecc093bfd10f6
SHA512 fe39195f3bd2bd2ad0b166e21051dbd48ef95c00bac4a304055b58b1886db532023f930dfa6e0ec8be653eb6c310707b337c05e2c361e0118854fb776f7f1a02
Ssdeep 786432:oh5ROUg0W6tjYMJlVXQNgxGTvEeW++O2jhyK5vpVrax:IOUg3ktJl6NgxkMt+MNTVrY
PEiD 无匹配
Yara
  • winrar_sfx (Winrar SFX Archive)
  • DebuggerTiming__Ticks (Detected timing ticks function)
  • screenshot (Detected take screenshot function)
  • create_process (Detection function for creating a new process)
  • escalate_priv (Detected escalate priviledges function)
  • win_registry (Detected system registries modification function)
  • change_win_registry (Change registries to affect system)
  • win_token (Affect system token)
  • win_files_operation (Affect private profile)
  • Maldun_Anomoly_Combined_Activities_7 (Spotted potential malicious behaviors from a small size target, like process manipultion, privilege, token and files)
  • with_images (Detected the presence of an or several images)
  • with_urls (Detected the presence of an or several urls)
  • CRC32_poly_Constant (Look for CRC32 [poly])
  • RIPEMD160_Constants (Look for RIPEMD-160 constants)
  • SHA1_Constants (Look for SHA1 constants)
  • IsPE32 (Detected a 32bit PE sample)
  • IsWindowsGUI (Detected a Windows GUI sample)
  • IsPacked (Detected Entropy signature)
  • HasOverlay (Detected Overlay signature)
  • HasDebugData (Detected Debug Data)
  • HasRichSignature (Detected Rich Signature)
VirusTotal VirusTotal链接
VirusTotal扫描时间: 2020-04-14 08:13:33
扫描结果: 1/73

特征

样本投放可执行文件到临时目录
从文件自身的二进制镜像中读取数据
self_read: process: Plants_Vs_Zombies_V1.0.0.1051_CN_V2.exe, pid: 2728, offset: 0x00000000, length: 0x00000007
self_read: process: Plants_Vs_Zombies_V1.0.0.1051_CN_V2.exe, pid: 2728, offset: 0x00000000, length: 0x00002000
self_read: process: Plants_Vs_Zombies_V1.0.0.1051_CN_V2.exe, pid: 2728, offset: 0x00000007, length: 0x0007fff0
self_read: process: Plants_Vs_Zombies_V1.0.0.1051_CN_V2.exe, pid: 2728, offset: 0x00001ff0, length: 0x00002000
self_read: process: Plants_Vs_Zombies_V1.0.0.1051_CN_V2.exe, pid: 2728, offset: 0x00003fe0, length: 0x00002000
self_read: process: Plants_Vs_Zombies_V1.0.0.1051_CN_V2.exe, pid: 2728, offset: 0x00005fd0, length: 0x00002000
self_read: process: Plants_Vs_Zombies_V1.0.0.1051_CN_V2.exe, pid: 2728, offset: 0x00007fc0, length: 0x00002000
self_read: process: Plants_Vs_Zombies_V1.0.0.1051_CN_V2.exe, pid: 2728, offset: 0x00009fb0, length: 0x00002000
self_read: process: Plants_Vs_Zombies_V1.0.0.1051_CN_V2.exe, pid: 2728, offset: 0x0000bfa0, length: 0x00002000
self_read: process: Plants_Vs_Zombies_V1.0.0.1051_CN_V2.exe, pid: 2728, offset: 0x0000df90, length: 0x00002000
self_read: process: Plants_Vs_Zombies_V1.0.0.1051_CN_V2.exe, pid: 2728, offset: 0x0000ff80, length: 0x00002000
self_read: process: Plants_Vs_Zombies_V1.0.0.1051_CN_V2.exe, pid: 2728, offset: 0x00011f70, length: 0x00002000
self_read: process: Plants_Vs_Zombies_V1.0.0.1051_CN_V2.exe, pid: 2728, offset: 0x00013f60, length: 0x00002000
self_read: process: Plants_Vs_Zombies_V1.0.0.1051_CN_V2.exe, pid: 2728, offset: 0x00015f50, length: 0x00002000
self_read: process: Plants_Vs_Zombies_V1.0.0.1051_CN_V2.exe, pid: 2728, offset: 0x00016a00, length: 0x0002b763
self_read: process: Plants_Vs_Zombies_V1.0.0.1051_CN_V2.exe, pid: 2728, offset: 0x0004a163, length: 0x01a06b0c
创建一个隐藏文件或系统文件
file: C:\Users\test\AppData\Local\Temp\Plants_Vs_Zombies_V1.0.0.1051_CN_V2\images\Thumbs.db
魔盾安全Yara规则检测结果 - 安全告警
Informational: Winrar SFX Archive
Critical: Spotted potential malicious behaviors from a small size target, like process manipultion, privilege, token and files
文件已被至少一个VirusTotal上的反病毒引擎检测为病毒
Trapmine: malicious.high.ml.score
检测到样本尝试模糊或欺骗文件类型
可能是恶意的样本写入可疑的执行文件并混淆扩展名
Suspicious: c:\users\test\appdata\local\temp\plants_vs_zombies_v1.0.0.1051_cn_v2\cached
Suspicious: c:\users\test\appdata\local\temp\plants_vs_zombies_v1.0.0.1051_cn_v2\cached
Suspicious: c:\users\test\appdata\local\temp\plants_vs_zombies_v1.0.0.1051_cn_v2\cached
Suspicious: c:\users\test\appdata\local\temp\plants_vs_zombies_v1.0.0.1051_cn_v2\cached
Suspicious: c:\users\test\appdata\local\temp\plants_vs_zombies_v1.0.0.1051_cn_v2\cached
Suspicious: c:\users\test\appdata\local\temp\plants_vs_zombies_v1.0.0.1051_cn_v2\cached
Suspicious: c:\users\test\appdata\local\temp\plants_vs_zombies_v1.0.0.1051_cn_v2\cached
Suspicious: c:\users\test\appdata\local\temp\plants_vs_zombies_v1.0.0.1051_cn_v2\cached
Suspicious: c:\users\test\appdata\local\temp\plants_vs_zombies_v1.0.0.1051_cn_v2\cached
Suspicious: c:\users\test\appdata\local\temp\plants_vs_zombies_v1.0.0.1051_cn_v2\cached
Suspicious: c:\users\test\appdata\local\temp\plants_vs_zombies_v1.0.0.1051_cn_v2\cached
Suspicious: c:\users\test\appdata\local\temp\plants_vs_zombies_v1.0.0.1051_cn_v2\cached
Suspicious: c:\users\test\appdata\local\temp\plants_vs_zombies_v1.0.0.1051_cn_v2\cached
Suspicious: c:\users\test\appdata\local\temp\plants_vs_zombies_v1.0.0.1051_cn_v2\cached
Suspicious: c:\users\test\appdata\local\temp\plants_vs_zombies_v1.0.0.1051_cn_v2\cached
Suspicious: c:\users\test\appdata\local\temp\plants_vs_zombies_v1.0.0.1051_cn_v2\cached
Suspicious: c:\users\test\appdata\local\temp\plants_vs_zombies_v1.0.0.1051_cn_v2\cached
Suspicious: c:\users\test\appdata\local\temp\plants_vs_zombies_v1.0.0.1051_cn_v2\cached
Suspicious: c:\users\test\appdata\local\temp\plants_vs_zombies_v1.0.0.1051_cn_v2\cached
Suspicious: c:\users\test\appdata\local\temp\plants_vs_zombies_v1.0.0.1051_cn_v2\cached
Suspicious: c:\users\test\appdata\local\temp\plants_vs_zombies_v1.0.0.1051_cn_v2\cached
Suspicious: c:\users\test\appdata\local\temp\plants_vs_zombies_v1.0.0.1051_cn_v2\cached
Suspicious: c:\users\test\appdata\local\temp\plants_vs_zombies_v1.0.0.1051_cn_v2\cached
Suspicious: c:\users\test\appdata\local\temp\plants_vs_zombies_v1.0.0.1051_cn_v2\cached
Suspicious: c:\users\test\appdata\local\temp\plants_vs_zombies_v1.0.0.1051_cn_v2\cached
Suspicious: c:\users\test\appdata\local\temp\plants_vs_zombies_v1.0.0.1051_cn_v2\cached
Suspicious: c:\users\test\appdata\local\temp\plants_vs_zombies_v1.0.0.1051_cn_v2\cached
Suspicious: c:\users\test\appdata\local\temp\plants_vs_zombies_v1.0.0.1051_cn_v2\cached
Suspicious: c:\users\test\appdata\local\temp\plants_vs_zombies_v1.0.0.1051_cn_v2\cached
Suspicious: c:\users\test\appdata\local\temp\plants_vs_zombies_v1.0.0.1051_cn_v2\cached
Suspicious: c:\users\test\appdata\local\temp\plants_vs_zombies_v1.0.0.1051_cn_v2\cached
Suspicious: c:\users\test\appdata\local\temp\plants_vs_zombies_v1.0.0.1051_cn_v2\cached
Suspicious: c:\users\test\appdata\local\temp\plants_vs_zombies_v1.0.0.1051_cn_v2\cached
Suspicious: c:\users\test\appdata\local\temp\plants_vs_zombies_v1.0.0.1051_cn_v2\cached
Suspicious: c:\users\test\appdata\local\temp\plants_vs_zombies_v1.0.0.1051_cn_v2\cached
Suspicious: c:\users\test\appdata\local\temp\plants_vs_zombies_v1.0.0.1051_cn_v2\cached
Suspicious: c:\users\test\appdata\local\temp\plants_vs_zombies_v1.0.0.1051_cn_v2\cached
Suspicious: c:\users\test\appdata\local\temp\plants_vs_zombies_v1.0.0.1051_cn_v2\cached
Suspicious: c:\users\test\appdata\local\temp\plants_vs_zombies_v1.0.0.1051_cn_v2\cached
Suspicious: c:\users\test\appdata\local\temp\plants_vs_zombies_v1.0.0.1051_cn_v2\cached
Suspicious: c:\users\test\appdata\local\temp\plants_vs_zombies_v1.0.0.1051_cn_v2\cached
Suspicious: c:\users\test\appdata\local\temp\plants_vs_zombies_v1.0.0.1051_cn_v2\cached
Suspicious: c:\users\test\appdata\local\temp\plants_vs_zombies_v1.0.0.1051_cn_v2\cached
Suspicious: c:\users\test\appdata\local\temp\plants_vs_zombies_v1.0.0.1051_cn_v2\cached
Suspicious: c:\users\test\appdata\local\temp\plants_vs_zombies_v1.0.0.1051_cn_v2\cached
Suspicious: c:\users\test\appdata\local\temp\plants_vs_zombies_v1.0.0.1051_cn_v2\cached
Suspicious: c:\users\test\appdata\local\temp\plants_vs_zombies_v1.0.0.1051_cn_v2\cached
Suspicious: c:\users\test\appdata\local\temp\plants_vs_zombies_v1.0.0.1051_cn_v2\cached
Suspicious: c:\users\test\appdata\local\temp\plants_vs_zombies_v1.0.0.1051_cn_v2\cached
Suspicious: c:\users\test\appdata\local\temp\plants_vs_zombies_v1.0.0.1051_cn_v2\cached
Suspicious: c:\users\test\appdata\local\temp\plants_vs_zombies_v1.0.0.1051_cn_v2\cached
Suspicious: c:\users\test\appdata\local\temp\plants_vs_zombies_v1.0.0.1051_cn_v2\cached
Suspicious: c:\users\test\appdata\local\temp\plants_vs_zombies_v1.0.0.1051_cn_v2\cached
Suspicious: c:\users\test\appdata\local\temp\plants_vs_zombies_v1.0.0.1051_cn_v2\cached
Suspicious: c:\users\test\appdata\local\temp\plants_vs_zombies_v1.0.0.1051_cn_v2\cached
Suspicious: c:\users\test\appdata\local\temp\plants_vs_zombies_v1.0.0.1051_cn_v2\cached
Suspicious: c:\users\test\appdata\local\temp\plants_vs_zombies_v1.0.0.1051_cn_v2\cached
Suspicious: c:\users\test\appdata\local\temp\plants_vs_zombies_v1.0.0.1051_cn_v2\cached
Suspicious: c:\users\test\appdata\local\temp\plants_vs_zombies_v1.0.0.1051_cn_v2\cached
Suspicious: c:\users\test\appdata\local\temp\plants_vs_zombies_v1.0.0.1051_cn_v2\cached
Suspicious: c:\users\test\appdata\local\temp\plants_vs_zombies_v1.0.0.1051_cn_v2\cached
Suspicious: c:\users\test\appdata\local\temp\plants_vs_zombies_v1.0.0.1051_cn_v2\cached
Suspicious: c:\users\test\appdata\local\temp\plants_vs_zombies_v1.0.0.1051_cn_v2\cached
Suspicious: c:\users\test\appdata\local\temp\plants_vs_zombies_v1.0.0.1051_cn_v2\cached
Suspicious: c:\users\test\appdata\local\temp\plants_vs_zombies_v1.0.0.1051_cn_v2\cached
Suspicious: c:\users\test\appdata\local\temp\plants_vs_zombies_v1.0.0.1051_cn_v2\cached
Suspicious: c:\users\test\appdata\local\temp\plants_vs_zombies_v1.0.0.1051_cn_v2\cached
Suspicious: c:\users\test\appdata\local\temp\plants_vs_zombies_v1.0.0.1051_cn_v2\cached
Suspicious: c:\users\test\appdata\local\temp\plants_vs_zombies_v1.0.0.1051_cn_v2\cached
Suspicious: c:\users\test\appdata\local\temp\plants_vs_zombies_v1.0.0.1051_cn_v2\cached
Suspicious: c:\users\test\appdata\local\temp\plants_vs_zombies_v1.0.0.1051_cn_v2\cached
Suspicious: c:\users\test\appdata\local\temp\plants_vs_zombies_v1.0.0.1051_cn_v2\cached
Suspicious: c:\users\test\appdata\local\temp\plants_vs_zombies_v1.0.0.1051_cn_v2\cached
Suspicious: c:\users\test\appdata\local\temp\plants_vs_zombies_v1.0.0.1051_cn_v2\cached
Suspicious: c:\users\test\appdata\local\temp\plants_vs_zombies_v1.0.0.1051_cn_v2\cached
Suspicious: c:\users\test\appdata\local\temp\plants_vs_zombies_v1.0.0.1051_cn_v2\cached
Suspicious: c:\users\test\appdata\local\temp\plants_vs_zombies_v1.0.0.1051_cn_v2\cached
Suspicious: c:\users\test\appdata\local\temp\plants_vs_zombies_v1.0.0.1051_cn_v2\cached
Suspicious: c:\users\test\appdata\local\temp\plants_vs_zombies_v1.0.0.1051_cn_v2\cached
Suspicious: c:\users\test\appdata\local\temp\plants_vs_zombies_v1.0.0.1051_cn_v2\cached
Suspicious: c:\users\test\appdata\local\temp\plants_vs_zombies_v1.0.0.1051_cn_v2\cached
Suspicious: c:\users\test\appdata\local\temp\plants_vs_zombies_v1.0.0.1051_cn_v2\cached
Suspicious: c:\users\test\appdata\local\temp\plants_vs_zombies_v1.0.0.1051_cn_v2\cached
Suspicious: c:\users\test\appdata\local\temp\plants_vs_zombies_v1.0.0.1051_cn_v2\cached
Suspicious: c:\users\test\appdata\local\temp\plants_vs_zombies_v1.0.0.1051_cn_v2\cached
Suspicious: c:\users\test\appdata\local\temp\plants_vs_zombies_v1.0.0.1051_cn_v2\cached
Suspicious: c:\users\test\appdata\local\temp\plants_vs_zombies_v1.0.0.1051_cn_v2\cached
Suspicious: c:\users\test\appdata\local\temp\plants_vs_zombies_v1.0.0.1051_cn_v2\cached
Suspicious: c:\users\test\appdata\local\temp\plants_vs_zombies_v1.0.0.1051_cn_v2\cached
Suspicious: c:\users\test\appdata\local\temp\plants_vs_zombies_v1.0.0.1051_cn_v2\cached
Suspicious: c:\users\test\appdata\local\temp\plants_vs_zombies_v1.0.0.1051_cn_v2\cached
Suspicious: c:\users\test\appdata\local\temp\plants_vs_zombies_v1.0.0.1051_cn_v2\cached
Suspicious: c:\users\test\appdata\local\temp\plants_vs_zombies_v1.0.0.1051_cn_v2\cached
Suspicious: c:\users\test\appdata\local\temp\plants_vs_zombies_v1.0.0.1051_cn_v2\cached
Suspicious: c:\users\test\appdata\local\temp\plants_vs_zombies_v1.0.0.1051_cn_v2\cached
Suspicious: c:\users\test\appdata\local\temp\plants_vs_zombies_v1.0.0.1051_cn_v2\cached
Suspicious: c:\users\test\appdata\local\temp\plants_vs_zombies_v1.0.0.1051_cn_v2\cached
Suspicious: c:\users\test\appdata\local\temp\plants_vs_zombies_v1.0.0.1051_cn_v2\cached
Suspicious: c:\users\test\appdata\local\temp\plants_vs_zombies_v1.0.0.1051_cn_v2\cached
Suspicious: c:\users\test\appdata\local\temp\plants_vs_zombies_v1.0.0.1051_cn_v2\cached
Suspicious: c:\users\test\appdata\local\temp\plants_vs_zombies_v1.0.0.1051_cn_v2\cached
Suspicious: c:\users\test\appdata\local\temp\plants_vs_zombies_v1.0.0.1051_cn_v2\cached
Suspicious: c:\users\test\appdata\local\temp\plants_vs_zombies_v1.0.0.1051_cn_v2\cached
Suspicious: c:\users\test\appdata\local\temp\plants_vs_zombies_v1.0.0.1051_cn_v2\cached
Suspicious: c:\users\test\appdata\local\temp\plants_vs_zombies_v1.0.0.1051_cn_v2\cached
Suspicious: c:\users\test\appdata\local\temp\plants_vs_zombies_v1.0.0.1051_cn_v2\cached
Suspicious: c:\users\test\appdata\local\temp\plants_vs_zombies_v1.0.0.1051_cn_v2\cached
Suspicious: c:\users\test\appdata\local\temp\plants_vs_zombies_v1.0.0.1051_cn_v2\cached
Suspicious: c:\users\test\appdata\local\temp\plants_vs_zombies_v1.0.0.1051_cn_v2\cached
Suspicious: c:\users\test\appdata\local\temp\plants_vs_zombies_v1.0.0.1051_cn_v2\cached
Suspicious: c:\users\test\appdata\local\temp\plants_vs_zombies_v1.0.0.1051_cn_v2\cached
Suspicious: c:\users\test\appdata\local\temp\plants_vs_zombies_v1.0.0.1051_cn_v2\cached
Suspicious: c:\users\test\appdata\local\temp\plants_vs_zombies_v1.0.0.1051_cn_v2\cached
Suspicious: c:\users\test\appdata\local\temp\plants_vs_zombies_v1.0.0.1051_cn_v2\cached
Suspicious: c:\users\test\appdata\local\temp\plants_vs_zombies_v1.0.0.1051_cn_v2\cached
Suspicious: c:\users\test\appdata\local\temp\plants_vs_zombies_v1.0.0.1051_cn_v2\cached
Suspicious: c:\users\test\appdata\local\temp\plants_vs_zombies_v1.0.0.1051_cn_v2\cached
Suspicious: c:\users\test\appdata\local\temp\plants_vs_zombies_v1.0.0.1051_cn_v2\cached
Suspicious: c:\users\test\appdata\local\temp\plants_vs_zombies_v1.0.0.1051_cn_v2\cached
Suspicious: c:\users\test\appdata\local\temp\plants_vs_zombies_v1.0.0.1051_cn_v2\cached
Suspicious: c:\users\test\appdata\local\temp\plants_vs_zombies_v1.0.0.1051_cn_v2\cached
Suspicious: c:\users\test\appdata\local\temp\plants_vs_zombies_v1.0.0.1051_cn_v2\cached
Suspicious: c:\users\test\appdata\local\temp\plants_vs_zombies_v1.0.0.1051_cn_v2\cached
Suspicious: c:\users\test\appdata\local\temp\plants_vs_zombies_v1.0.0.1051_cn_v2\cached
Suspicious: c:\users\test\appdata\local\temp\plants_vs_zombies_v1.0.0.1051_cn_v2\cached
Suspicious: c:\users\test\appdata\local\temp\plants_vs_zombies_v1.0.0.1051_cn_v2\cached
Suspicious: c:\users\test\appdata\local\temp\plants_vs_zombies_v1.0.0.1051_cn_v2\cached
Suspicious: c:\users\test\appdata\local\temp\plants_vs_zombies_v1.0.0.1051_cn_v2\cached
Suspicious: c:\users\test\appdata\local\temp\plants_vs_zombies_v1.0.0.1051_cn_v2\cached
Suspicious: c:\users\test\appdata\local\temp\plants_vs_zombies_v1.0.0.1051_cn_v2\cached
Suspicious: c:\users\test\appdata\local\temp\plants_vs_zombies_v1.0.0.1051_cn_v2\cached
Suspicious: c:\users\test\appdata\local\temp\plants_vs_zombies_v1.0.0.1051_cn_v2\cached
Suspicious: c:\users\test\appdata\local\temp\plants_vs_zombies_v1.0.0.1051_cn_v2\cached
Suspicious: c:\users\test\appdata\local\temp\plants_vs_zombies_v1.0.0.1051_cn_v2\cached
Suspicious: c:\users\test\appdata\local\temp\plants_vs_zombies_v1.0.0.1051_cn_v2\cached
Suspicious: c:\users\test\appdata\local\temp\plants_vs_zombies_v1.0.0.1051_cn_v2\cached
Suspicious: c:\users\test\appdata\local\temp\plants_vs_zombies_v1.0.0.1051_cn_v2\cached
Suspicious: c:\users\test\appdata\local\temp\plants_vs_zombies_v1.0.0.1051_cn_v2\cached
Suspicious: c:\users\test\appdata\local\temp\plants_vs_zombies_v1.0.0.1051_cn_v2\cached
Suspicious: c:\users\test\appdata\local\temp\plants_vs_zombies_v1.0.0.1051_cn_v2\cached
Suspicious: c:\users\test\appdata\local\temp\plants_vs_zombies_v1.0.0.1051_cn_v2\cached
Suspicious: c:\users\test\appdata\local\temp\plants_vs_zombies_v1.0.0.1051_cn_v2\cached
Suspicious: c:\users\test\appdata\local\temp\plants_vs_zombies_v1.0.0.1051_cn_v2\cached
Suspicious: c:\users\test\appdata\local\temp\plants_vs_zombies_v1.0.0.1051_cn_v2\cached
Suspicious: c:\users\test\appdata\local\temp\plants_vs_zombies_v1.0.0.1051_cn_v2\cached
Suspicious: c:\users\test\appdata\local\temp\plants_vs_zombies_v1.0.0.1051_cn_v2\cached
Suspicious: c:\users\test\appdata\local\temp\plants_vs_zombies_v1.0.0.1051_cn_v2\cached
Suspicious: c:\users\test\appdata\local\temp\plants_vs_zombies_v1.0.0.1051_cn_v2\cached
Suspicious: c:\users\test\appdata\local\temp\plants_vs_zombies_v1.0.0.1051_cn_v2\cached
Suspicious: c:\users\test\appdata\local\temp\plants_vs_zombies_v1.0.0.1051_cn_v2\cached
Suspicious: c:\users\test\appdata\local\temp\plants_vs_zombies_v1.0.0.1051_cn_v2\cached
Suspicious: c:\users\test\appdata\local\temp\plants_vs_zombies_v1.0.0.1051_cn_v2\cached
Suspicious: c:\users\test\appdata\local\temp\plants_vs_zombies_v1.0.0.1051_cn_v2\cached
Suspicious: c:\users\test\appdata\local\temp\plants_vs_zombies_v1.0.0.1051_cn_v2\cached
Suspicious: c:\users\test\appdata\local\temp\plants_vs_zombies_v1.0.0.1051_cn_v2\cached
Suspicious: c:\users\test\appdata\local\temp\plants_vs_zombies_v1.0.0.1051_cn_v2\cached
Suspicious: c:\users\test\appdata\local\temp\plants_vs_zombies_v1.0.0.1051_cn_v2\cached
Suspicious: c:\users\test\appdata\local\temp\plants_vs_zombies_v1.0.0.1051_cn_v2\cached
Suspicious: c:\users\test\appdata\local\temp\plants_vs_zombies_v1.0.0.1051_cn_v2\cached
Suspicious: c:\users\test\appdata\local\temp\plants_vs_zombies_v1.0.0.1051_cn_v2\cached
Suspicious: c:\users\test\appdata\local\temp\plants_vs_zombies_v1.0.0.1051_cn_v2\cached
Suspicious: c:\users\test\appdata\local\temp\plants_vs_zombies_v1.0.0.1051_cn_v2\cached
Suspicious: c:\users\test\appdata\local\temp\plants_vs_zombies_v1.0.0.1051_cn_v2\cached
Suspicious: c:\users\test\appdata\local\temp\plants_vs_zombies_v1.0.0.1051_cn_v2\cached
Suspicious: c:\users\test\appdata\local\temp\plants_vs_zombies_v1.0.0.1051_cn_v2\cached
Suspicious: c:\users\test\appdata\local\temp\plants_vs_zombies_v1.0.0.1051_cn_v2\cached
Suspicious: c:\users\test\appdata\local\temp\plants_vs_zombies_v1.0.0.1051_cn_v2\cached
Suspicious: c:\users\test\appdata\local\temp\plants_vs_zombies_v1.0.0.1051_cn_v2\cached
Suspicious: c:\users\test\appdata\local\temp\plants_vs_zombies_v1.0.0.1051_cn_v2\cached
Suspicious: c:\users\test\appdata\local\temp\plants_vs_zombies_v1.0.0.1051_cn_v2\cached
Suspicious: c:\users\test\appdata\local\temp\plants_vs_zombies_v1.0.0.1051_cn_v2\cached
Suspicious: c:\users\test\appdata\local\temp\plants_vs_zombies_v1.0.0.1051_cn_v2\cached
Suspicious: c:\users\test\appdata\local\temp\plants_vs_zombies_v1.0.0.1051_cn_v2\cached
Suspicious: c:\users\test\appdata\local\temp\plants_vs_zombies_v1.0.0.1051_cn_v2\cached
Suspicious: c:\users\test\appdata\local\temp\plants_vs_zombies_v1.0.0.1051_cn_v2\cached
Suspicious: c:\users\test\appdata\local\temp\plants_vs_zombies_v1.0.0.1051_cn_v2\cached
Suspicious: c:\users\test\appdata\local\temp\plants_vs_zombies_v1.0.0.1051_cn_v2\cached
Suspicious: c:\users\test\appdata\local\temp\plants_vs_zombies_v1.0.0.1051_cn_v2\cached
Suspicious: c:\users\test\appdata\local\temp\plants_vs_zombies_v1.0.0.1051_cn_v2\cached
Suspicious: c:\users\test\appdata\local\temp\plants_vs_zombies_v1.0.0.1051_cn_v2\cached
Suspicious: c:\users\test\appdata\local\temp\plants_vs_zombies_v1.0.0.1051_cn_v2\cached
Suspicious: c:\users\test\appdata\local\temp\plants_vs_zombies_v1.0.0.1051_cn_v2\cached
Suspicious: c:\users\test\appdata\local\temp\plants_vs_zombies_v1.0.0.1051_cn_v2\cached
Suspicious: c:\users\test\appdata\local\temp\plants_vs_zombies_v1.0.0.1051_cn_v2\cached
Suspicious: c:\users\test\appdata\local\temp\plants_vs_zombies_v1.0.0.1051_cn_v2\cached
Suspicious: c:\users\test\appdata\local\temp\plants_vs_zombies_v1.0.0.1051_cn_v2\cached
Suspicious: c:\users\test\appdata\local\temp\plants_vs_zombies_v1.0.0.1051_cn_v2\cached
Suspicious: c:\users\test\appdata\local\temp\plants_vs_zombies_v1.0.0.1051_cn_v2\cached
Suspicious: c:\users\test\appdata\local\temp\plants_vs_zombies_v1.0.0.1051_cn_v2\cached
Suspicious: c:\users\test\appdata\local\temp\plants_vs_zombies_v1.0.0.1051_cn_v2\cached
Suspicious: c:\users\test\appdata\local\temp\plants_vs_zombies_v1.0.0.1051_cn_v2\cached
Suspicious: c:\users\test\appdata\local\temp\plants_vs_zombies_v1.0.0.1051_cn_v2\cached
Suspicious: c:\users\test\appdata\local\temp\plants_vs_zombies_v1.0.0.1051_cn_v2\cached
Suspicious: c:\users\test\appdata\local\temp\plants_vs_zombies_v1.0.0.1051_cn_v2\cached
Suspicious: c:\users\test\appdata\local\temp\plants_vs_zombies_v1.0.0.1051_cn_v2\cached
Suspicious: c:\users\test\appdata\local\temp\plants_vs_zombies_v1.0.0.1051_cn_v2\cached
Suspicious: c:\users\test\appdata\local\temp\plants_vs_zombies_v1.0.0.1051_cn_v2\cached
Suspicious: c:\users\test\appdata\local\temp\plants_vs_zombies_v1.0.0.1051_cn_v2\cached
Suspicious: c:\users\test\appdata\local\temp\plants_vs_zombies_v1.0.0.1051_cn_v2\cached
Suspicious: c:\users\test\appdata\local\temp\plants_vs_zombies_v1.0.0.1051_cn_v2\cached
Suspicious: c:\users\test\appdata\local\temp\plants_vs_zombies_v1.0.0.1051_cn_v2\cached
Suspicious: c:\users\test\appdata\local\temp\plants_vs_zombies_v1.0.0.1051_cn_v2\cached
Suspicious: c:\users\test\appdata\local\temp\plants_vs_zombies_v1.0.0.1051_cn_v2\cached
Suspicious: c:\users\test\appdata\local\temp\plants_vs_zombies_v1.0.0.1051_cn_v2\cached
Suspicious: c:\users\test\appdata\local\temp\plants_vs_zombies_v1.0.0.1051_cn_v2\cached
Suspicious: c:\users\test\appdata\local\temp\plants_vs_zombies_v1.0.0.1051_cn_v2\cached
Suspicious: c:\users\test\appdata\local\temp\plants_vs_zombies_v1.0.0.1051_cn_v2\cached
Suspicious: c:\users\test\appdata\local\temp\plants_vs_zombies_v1.0.0.1051_cn_v2\cached
Suspicious: c:\users\test\appdata\local\temp\plants_vs_zombies_v1.0.0.1051_cn_v2\cached
Suspicious: c:\users\test\appdata\local\temp\plants_vs_zombies_v1.0.0.1051_cn_v2\cached
Suspicious: c:\users\test\appdata\local\temp\plants_vs_zombies_v1.0.0.1051_cn_v2\cached
Suspicious: c:\users\test\appdata\local\temp\plants_vs_zombies_v1.0.0.1051_cn_v2\cached
Suspicious: c:\users\test\appdata\local\temp\plants_vs_zombies_v1.0.0.1051_cn_v2\cached
Suspicious: c:\users\test\appdata\local\temp\plants_vs_zombies_v1.0.0.1051_cn_v2\cached
Suspicious: c:\users\test\appdata\local\temp\plants_vs_zombies_v1.0.0.1051_cn_v2\cached
Suspicious: c:\users\test\appdata\local\temp\plants_vs_zombies_v1.0.0.1051_cn_v2\cached
Suspicious: c:\users\test\appdata\local\temp\plants_vs_zombies_v1.0.0.1051_cn_v2\cached
Suspicious: c:\users\test\appdata\local\temp\plants_vs_zombies_v1.0.0.1051_cn_v2\cached
Suspicious: c:\users\test\appdata\local\temp\plants_vs_zombies_v1.0.0.1051_cn_v2\cached
Suspicious: c:\users\test\appdata\local\temp\plants_vs_zombies_v1.0.0.1051_cn_v2\cached
Suspicious: c:\users\test\appdata\local\temp\plants_vs_zombies_v1.0.0.1051_cn_v2\cached
Suspicious: c:\users\test\appdata\local\temp\plants_vs_zombies_v1.0.0.1051_cn_v2\cached
Suspicious: c:\users\test\appdata\local\temp\plants_vs_zombies_v1.0.0.1051_cn_v2\cached
Suspicious: c:\users\test\appdata\local\temp\plants_vs_zombies_v1.0.0.1051_cn_v2\cached
Suspicious: c:\users\test\appdata\local\temp\plants_vs_zombies_v1.0.0.1051_cn_v2\cached
Suspicious: c:\users\test\appdata\local\temp\plants_vs_zombies_v1.0.0.1051_cn_v2\cached
Suspicious: c:\users\test\appdata\local\temp\plants_vs_zombies_v1.0.0.1051_cn_v2\cached
Suspicious: c:\users\test\appdata\local\temp\plants_vs_zombies_v1.0.0.1051_cn_v2\cached
Suspicious: c:\users\test\appdata\local\temp\plants_vs_zombies_v1.0.0.1051_cn_v2\cached
Suspicious: c:\users\test\appdata\local\temp\plants_vs_zombies_v1.0.0.1051_cn_v2\cached
Suspicious: c:\users\test\appdata\local\temp\plants_vs_zombies_v1.0.0.1051_cn_v2\cached
Suspicious: c:\users\test\appdata\local\temp\plants_vs_zombies_v1.0.0.1051_cn_v2\cached
Suspicious: c:\users\test\appdata\local\temp\plants_vs_zombies_v1.0.0.1051_cn_v2\cached
Suspicious: c:\users\test\appdata\local\temp\plants_vs_zombies_v1.0.0.1051_cn_v2\cached
Suspicious: c:\users\test\appdata\local\temp\plants_vs_zombies_v1.0.0.1051_cn_v2\cached
Suspicious: c:\users\test\appdata\local\temp\plants_vs_zombies_v1.0.0.1051_cn_v2\cached
Suspicious: c:\users\test\appdata\local\temp\plants_vs_zombies_v1.0.0.1051_cn_v2\cached
Suspicious: c:\users\test\appdata\local\temp\plants_vs_zombies_v1.0.0.1051_cn_v2\cached
Suspicious: c:\users\test\appdata\local\temp\plants_vs_zombies_v1.0.0.1051_cn_v2\cached
Suspicious: c:\users\test\appdata\local\temp\plants_vs_zombies_v1.0.0.1051_cn_v2\cached
Suspicious: c:\users\test\appdata\local\temp\plants_vs_zombies_v1.0.0.1051_cn_v2\cached
Suspicious: c:\users\test\appdata\local\temp\plants_vs_zombies_v1.0.0.1051_cn_v2\cached
Suspicious: c:\users\test\appdata\local\temp\plants_vs_zombies_v1.0.0.1051_cn_v2\cached
Suspicious: c:\users\test\appdata\local\temp\plants_vs_zombies_v1.0.0.1051_cn_v2\cached
Suspicious: c:\users\test\appdata\local\temp\plants_vs_zombies_v1.0.0.1051_cn_v2\cached
Suspicious: c:\users\test\appdata\local\temp\plants_vs_zombies_v1.0.0.1051_cn_v2\cached
Suspicious: c:\users\test\appdata\local\temp\plants_vs_zombies_v1.0.0.1051_cn_v2\cached
Suspicious: c:\users\test\appdata\local\temp\plants_vs_zombies_v1.0.0.1051_cn_v2\cached
Suspicious: c:\users\test\appdata\local\temp\plants_vs_zombies_v1.0.0.1051_cn_v2\cached
Suspicious: c:\users\test\appdata\local\temp\plants_vs_zombies_v1.0.0.1051_cn_v2\cached
Suspicious: c:\users\test\appdata\local\temp\plants_vs_zombies_v1.0.0.1051_cn_v2\cached
Suspicious: c:\users\test\appdata\local\temp\plants_vs_zombies_v1.0.0.1051_cn_v2\cached
Suspicious: c:\users\test\appdata\local\temp\plants_vs_zombies_v1.0.0.1051_cn_v2\cached
Suspicious: c:\users\test\appdata\local\temp\plants_vs_zombies_v1.0.0.1051_cn_v2\cached
Suspicious: c:\users\test\appdata\local\temp\plants_vs_zombies_v1.0.0.1051_cn_v2\cached
Suspicious: c:\users\test\appdata\local\temp\plants_vs_zombies_v1.0.0.1051_cn_v2\cached
Suspicious: c:\users\test\appdata\local\temp\plants_vs_zombies_v1.0.0.1051_cn_v2\cached
Suspicious: c:\users\test\appdata\local\temp\plants_vs_zombies_v1.0.0.1051_cn_v2\cached
Suspicious: c:\users\test\appdata\local\temp\plants_vs_zombies_v1.0.0.1051_cn_v2\cached
Suspicious: c:\users\test\appdata\local\temp\plants_vs_zombies_v1.0.0.1051_cn_v2\cached
Suspicious: c:\users\test\appdata\local\temp\plants_vs_zombies_v1.0.0.1051_cn_v2\cached
Suspicious: c:\users\test\appdata\local\temp\plants_vs_zombies_v1.0.0.1051_cn_v2\cached
Suspicious: c:\users\test\appdata\local\temp\plants_vs_zombies_v1.0.0.1051_cn_v2\cached
Suspicious: c:\users\test\appdata\local\temp\plants_vs_zombies_v1.0.0.1051_cn_v2\cached
Suspicious: c:\users\test\appdata\local\temp\plants_vs_zombies_v1.0.0.1051_cn_v2\cached
Suspicious: c:\users\test\appdata\local\temp\plants_vs_zombies_v1.0.0.1051_cn_v2\cached
Suspicious: c:\users\test\appdata\local\temp\plants_vs_zombies_v1.0.0.1051_cn_v2\cached
Suspicious: c:\users\test\appdata\local\temp\plants_vs_zombies_v1.0.0.1051_cn_v2\cached
Suspicious: c:\users\test\appdata\local\temp\plants_vs_zombies_v1.0.0.1051_cn_v2\cached
Suspicious: c:\users\test\appdata\local\temp\plants_vs_zombies_v1.0.0.1051_cn_v2\cached
Suspicious: c:\users\test\appdata\local\temp\plants_vs_zombies_v1.0.0.1051_cn_v2\cached
Suspicious: c:\users\test\appdata\local\temp\plants_vs_zombies_v1.0.0.1051_cn_v2\cached
Suspicious: c:\users\test\appdata\local\temp\plants_vs_zombies_v1.0.0.1051_cn_v2\cached
Suspicious: c:\users\test\appdata\local\temp\plants_vs_zombies_v1.0.0.1051_cn_v2\cached
Suspicious: c:\users\test\appdata\local\temp\plants_vs_zombies_v1.0.0.1051_cn_v2\cached
Suspicious: c:\users\test\appdata\local\temp\plants_vs_zombies_v1.0.0.1051_cn_v2\cached
Suspicious: c:\users\test\appdata\local\temp\plants_vs_zombies_v1.0.0.1051_cn_v2\cached
Suspicious: c:\users\test\appdata\local\temp\plants_vs_zombies_v1.0.0.1051_cn_v2\cached
Suspicious: c:\users\test\appdata\local\temp\plants_vs_zombies_v1.0.0.1051_cn_v2\cached
Suspicious: c:\users\test\appdata\local\temp\plants_vs_zombies_v1.0.0.1051_cn_v2\cached
Suspicious: c:\users\test\appdata\local\temp\plants_vs_zombies_v1.0.0.1051_cn_v2\cached
Suspicious: c:\users\test\appdata\local\temp\plants_vs_zombies_v1.0.0.1051_cn_v2\cached
Suspicious: c:\users\test\appdata\local\temp\plants_vs_zombies_v1.0.0.1051_cn_v2\cached
Suspicious: c:\users\test\appdata\local\temp\plants_vs_zombies_v1.0.0.1051_cn_v2\cached
Suspicious: c:\users\test\appdata\local\temp\plants_vs_zombies_v1.0.0.1051_cn_v2\cached
Suspicious: c:\users\test\appdata\local\temp\plants_vs_zombies_v1.0.0.1051_cn_v2\cached
Suspicious: c:\users\test\appdata\local\temp\plants_vs_zombies_v1.0.0.1051_cn_v2\cached
Suspicious: c:\users\test\appdata\local\temp\plants_vs_zombies_v1.0.0.1051_cn_v2\cached
Suspicious: c:\users\test\appdata\local\temp\plants_vs_zombies_v1.0.0.1051_cn_v2\cached
Suspicious: c:\users\test\appdata\local\temp\plants_vs_zombies_v1.0.0.1051_cn_v2\cached
Suspicious: c:\users\test\appdata\local\temp\plants_vs_zombies_v1.0.0.1051_cn_v2\cached
Suspicious: c:\users\test\appdata\local\temp\plants_vs_zombies_v1.0.0.1051_cn_v2\cached
Suspicious: c:\users\test\appdata\local\temp\plants_vs_zombies_v1.0.0.1051_cn_v2\cached
Suspicious: c:\users\test\appdata\local\temp\plants_vs_zombies_v1.0.0.1051_cn_v2\cached
Suspicious: c:\users\test\appdata\local\temp\plants_vs_zombies_v1.0.0.1051_cn_v2\cached
Suspicious: c:\users\test\appdata\local\temp\plants_vs_zombies_v1.0.0.1051_cn_v2\cached
Suspicious: c:\users\test\appdata\local\temp\plants_vs_zombies_v1.0.0.1051_cn_v2\cached
Suspicious: c:\users\test\appdata\local\temp\plants_vs_zombies_v1.0.0.1051_cn_v2\cached
Suspicious: c:\users\test\appdata\local\temp\plants_vs_zombies_v1.0.0.1051_cn_v2\cached
Suspicious: c:\users\test\appdata\local\temp\plants_vs_zombies_v1.0.0.1051_cn_v2\cached
Suspicious: c:\users\test\appdata\local\temp\plants_vs_zombies_v1.0.0.1051_cn_v2\cached
Suspicious: c:\users\test\appdata\local\temp\plants_vs_zombies_v1.0.0.1051_cn_v2\cached
Suspicious: c:\users\test\appdata\local\temp\plants_vs_zombies_v1.0.0.1051_cn_v2\cached
Suspicious: c:\users\test\appdata\local\temp\plants_vs_zombies_v1.0.0.1051_cn_v2\cached
Suspicious: c:\users\test\appdata\local\temp\plants_vs_zombies_v1.0.0.1051_cn_v2\cached
Suspicious: c:\users\test\appdata\local\temp\plants_vs_zombies_v1.0.0.1051_cn_v2\cached
Suspicious: c:\users\test\appdata\local\temp\plants_vs_zombies_v1.0.0.1051_cn_v2\cached
Suspicious: c:\users\test\appdata\local\temp\plants_vs_zombies_v1.0.0.1051_cn_v2\cached
Suspicious: c:\users\test\appdata\local\temp\plants_vs_zombies_v1.0.0.1051_cn_v2\cached
Suspicious: c:\users\test\appdata\local\temp\plants_vs_zombies_v1.0.0.1051_cn_v2\cached
Suspicious: c:\users\test\appdata\local\temp\plants_vs_zombies_v1.0.0.1051_cn_v2\cached
Suspicious: c:\users\test\appdata\local\temp\plants_vs_zombies_v1.0.0.1051_cn_v2\cached
Suspicious: c:\users\test\appdata\local\temp\plants_vs_zombies_v1.0.0.1051_cn_v2\cached
Suspicious: c:\users\test\appdata\local\temp\plants_vs_zombies_v1.0.0.1051_cn_v2\cached
Suspicious: c:\users\test\appdata\local\temp\plants_vs_zombies_v1.0.0.1051_cn_v2\cached
Suspicious: c:\users\test\appdata\local\temp\plants_vs_zombies_v1.0.0.1051_cn_v2\cached
Suspicious: c:\users\test\appdata\local\temp\plants_vs_zombies_v1.0.0.1051_cn_v2\cached
Suspicious: c:\users\test\appdata\local\temp\plants_vs_zombies_v1.0.0.1051_cn_v2\cached

运行截图

网络分析

无信息

静态分析

PE 信息

初始地址 0x00400000
入口地址 0x0040a7b1
声明校验值 0x000236e4
实际校验值 0x01a53dc9
最低操作系统版本要求 5.0
PDB路径 d:\Projects\WinRAR\SFX\build\sfxrar32\Release\sfxrar.pdb
编译时间 2010-03-15 14:27:50
载入哈希 9402b48d966c911f0785b076b349b5ef
图标
图标精确哈希值 3e02527e67af010d267e693e882cb3da
图标相似性哈希值 a0355d3e8cef586bb6e00314ed096af5

PE数据组成

名称 虚拟地址 虚拟大小 原始数据大小 特征 熵(Entropy)
.text 0x00001000 0x0001076e 0x00010800 IMAGE_SCN_CNT_CODE|IMAGE_SCN_MEM_EXECUTE|IMAGE_SCN_MEM_READ 6.58
.rdata 0x00012000 0x00001865 0x00001a00 IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ 5.33
.data 0x00014000 0x0000bff4 0x00000200 IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ|IMAGE_SCN_MEM_WRITE 3.55
.CRT 0x00020000 0x00000010 0x00000200 IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ 0.21
.rsrc 0x00021000 0x00003e60 0x00004000 IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ 4.69

覆盖

偏移量: 0x00016a00
大小: 0x01a3a276

资源

名称 偏移量 大小 语言 子语言 熵(Entropy) 文件类型
RT_BITMAP 0x0002148c 0x00000bb6 LANG_CHINESE SUBLANG_CHINESE_SIMPLIFIED 4.19 data
RT_ICON 0x000229bc 0x000008a8 LANG_CHINESE SUBLANG_CHINESE_SIMPLIFIED 4.69 data
RT_ICON 0x000229bc 0x000008a8 LANG_CHINESE SUBLANG_CHINESE_SIMPLIFIED 4.69 data
RT_ICON 0x000229bc 0x000008a8 LANG_CHINESE SUBLANG_CHINESE_SIMPLIFIED 4.69 data
RT_ICON 0x000229bc 0x000008a8 LANG_CHINESE SUBLANG_CHINESE_SIMPLIFIED 4.69 data
RT_DIALOG 0x000238f4 0x0000019e LANG_CHINESE SUBLANG_CHINESE_SIMPLIFIED 3.81 data
RT_DIALOG 0x000238f4 0x0000019e LANG_CHINESE SUBLANG_CHINESE_SIMPLIFIED 3.81 data
RT_DIALOG 0x000238f4 0x0000019e LANG_CHINESE SUBLANG_CHINESE_SIMPLIFIED 3.81 data
RT_DIALOG 0x000238f4 0x0000019e LANG_CHINESE SUBLANG_CHINESE_SIMPLIFIED 3.81 data
RT_DIALOG 0x000238f4 0x0000019e LANG_CHINESE SUBLANG_CHINESE_SIMPLIFIED 3.81 data
RT_DIALOG 0x000238f4 0x0000019e LANG_CHINESE SUBLANG_CHINESE_SIMPLIFIED 3.81 data
RT_STRING 0x00023f5c 0x0000002c LANG_CHINESE SUBLANG_CHINESE_SIMPLIFIED 1.97 data
RT_STRING 0x00023f5c 0x0000002c LANG_CHINESE SUBLANG_CHINESE_SIMPLIFIED 1.97 data
RT_STRING 0x00023f5c 0x0000002c LANG_CHINESE SUBLANG_CHINESE_SIMPLIFIED 1.97 data
RT_STRING 0x00023f5c 0x0000002c LANG_CHINESE SUBLANG_CHINESE_SIMPLIFIED 1.97 data
RT_STRING 0x00023f5c 0x0000002c LANG_CHINESE SUBLANG_CHINESE_SIMPLIFIED 1.97 data
RT_GROUP_ICON 0x00023f88 0x0000003e LANG_CHINESE SUBLANG_CHINESE_SIMPLIFIED 2.65 MS Windows icon resource - 4 icons, 16x16, 16 colors
RT_MANIFEST 0x00023fc8 0x000005b8 LANG_CHINESE SUBLANG_CHINESE_SIMPLIFIED 5.21 XML 1.0 document, ASCII text, with CRLF line terminators

导入

库 COMCTL32.dll:
0x41202c - None
库 KERNEL32.dll:
0x412068 - DeleteFileA
0x41206c - DeleteFileW
0x412070 - CreateDirectoryA
0x412074 - CreateDirectoryW
0x412078 - FindClose
0x41207c - FindNextFileA
0x412080 - FindFirstFileA
0x412084 - FindNextFileW
0x412088 - FindFirstFileW
0x41208c - GetTickCount
0x412090 - WideCharToMultiByte
0x412094 - MultiByteToWideChar
0x412098 - GetVersionExA
0x41209c - GlobalAlloc
0x4120a0 - lstrlenA
0x4120a4 - GetModuleFileNameA
0x4120a8 - FindResourceA
0x4120ac - GetModuleHandleA
0x4120b0 - HeapAlloc
0x4120b4 - GetProcessHeap
0x4120b8 - HeapFree
0x4120bc - HeapReAlloc
0x4120c0 - CompareStringA
0x4120c4 - ExitProcess
0x4120c8 - GetLocaleInfoA
0x4120cc - GetNumberFormatA
0x4120d0 - lstrcmpiA
0x4120d4 - GetProcAddress
0x4120d8 - GetDateFormatA
0x4120dc - GetTimeFormatA
0x4120e0 - FileTimeToSystemTime
0x4120e4 - FileTimeToLocalFileTime
0x4120e8 - ExpandEnvironmentStringsA
0x4120ec - WaitForSingleObject
0x4120f0 - SetCurrentDirectoryA
0x4120f4 - Sleep
0x4120f8 - GetTempPathA
0x4120fc - MoveFileExA
0x412100 - UnmapViewOfFile
0x412104 - GetCommandLineA
0x412108 - MapViewOfFile
0x41210c - CreateFileMappingA
0x412110 - GetModuleFileNameW
0x412114 - SetEnvironmentVariableA
0x412118 - OpenFileMappingA
0x41211c - LocalFileTimeToFileTime
0x412120 - SystemTimeToFileTime
0x412124 - GetSystemTime
0x412128 - IsDBCSLeadByte
0x41212c - GetCPInfo
0x412130 - FreeLibrary
0x412134 - LoadLibraryA
0x412138 - GetCurrentDirectoryA
0x41213c - GetFullPathNameA
0x412140 - SetFileAttributesW
0x412144 - SetFileAttributesA
0x412148 - GetFileAttributesW
0x41214c - GetFileAttributesA
0x412150 - WriteFile
0x412154 - SetLastError
0x412158 - GetStdHandle
0x41215c - ReadFile
0x412160 - CreateFileW
0x412164 - CreateFileA
0x412168 - GetFileType
0x41216c - SetEndOfFile
0x412170 - SetFilePointer
0x412174 - MoveFileA
0x412178 - SetFileTime
0x41217c - GetCurrentProcess
0x412180 - CloseHandle
0x412184 - GetLastError
0x412188 - DosDateTimeToFileTime
库 USER32.dll:
0x4121bc - ReleaseDC
0x4121c0 - GetDC
0x4121c4 - SendMessageA
0x4121c8 - wsprintfA
0x4121cc - SetDlgItemTextA
0x4121d0 - EndDialog
0x4121d4 - DestroyIcon
0x4121d8 - SendDlgItemMessageA
0x4121dc - GetDlgItemTextA
0x4121e0 - DialogBoxParamA
0x4121e4 - IsWindowVisible
0x4121e8 - WaitForInputIdle
0x4121ec - GetSysColor
0x4121f0 - PostMessageA
0x4121f4 - SetMenu
0x4121f8 - SetFocus
0x4121fc - LoadBitmapA
0x412200 - LoadIconA
0x412204 - CharToOemA
0x412208 - OemToCharA
0x41220c - GetClassNameA
0x412210 - CharUpperA
0x412214 - GetWindowRect
0x412218 - GetParent
0x41221c - MapWindowPoints
0x412220 - CreateWindowExA
0x412224 - UpdateWindow
0x412228 - SetWindowTextA
0x41222c - LoadCursorA
0x412230 - RegisterClassExA
0x412234 - SetWindowLongA
0x412238 - GetWindowLongA
0x41223c - DefWindowProcA
0x412240 - PeekMessageA
0x412244 - GetMessageA
0x412248 - TranslateMessage
0x41224c - DispatchMessageA
0x412250 - GetClientRect
0x412254 - CopyRect
0x412258 - IsWindow
0x41225c - MessageBoxA
0x412260 - ShowWindow
0x412264 - GetDlgItem
0x412268 - EnableWindow
0x41226c - FindWindowExA
0x412270 - wvsprintfA
0x412274 - CharToOemBuffA
0x412278 - LoadStringA
0x41227c - SetWindowPos
0x412280 - GetWindowTextA
0x412284 - GetWindow
0x412288 - GetSystemMetrics
0x41228c - OemToCharBuffA
0x412290 - DestroyWindow
库 GDI32.dll:
0x412044 - GetDeviceCaps
0x412048 - GetObjectA
0x41204c - CreateCompatibleBitmap
0x412050 - SelectObject
0x412054 - StretchBlt
0x412058 - CreateCompatibleDC
0x41205c - DeleteObject
0x412060 - DeleteDC
库 COMDLG32.dll:
0x412034 - GetSaveFileNameA
0x412038 - CommDlgExtendedError
0x41203c - GetOpenFileNameA
库 ADVAPI32.dll:
0x412000 - LookupPrivilegeValueA
0x412004 - RegOpenKeyExA
0x412008 - RegQueryValueExA
0x41200c - RegCreateKeyExA
0x412010 - RegSetValueExA
0x412014 - RegCloseKey
0x412018 - SetFileSecurityW
0x41201c - SetFileSecurityA
0x412020 - OpenProcessToken
0x412024 - AdjustTokenPrivileges
库 SHELL32.dll:
0x412198 - ShellExecuteExA
0x41219c - SHFileOperationA
0x4121a0 - SHGetFileInfoA
0x4121a4 - SHGetSpecialFolderLocation
0x4121a8 - SHGetMalloc
0x4121ac - SHBrowseForFolderA
0x4121b0 - SHGetPathFromIDListA
0x4121b4 - SHChangeNotify
库 ole32.dll:
0x412298 - CreateStreamOnHGlobal
0x41229c - OleInitialize
0x4122a0 - CoCreateInstance
0x4122a4 - OleUninitialize
0x4122a8 - CLSIDFromString
库 OLEAUT32.dll:
0x412190 - VariantInit

投放文件

无信息

行为分析

互斥量(Mutexes)
  • DefaultTabtip-MainUI
  • Local\MSCTF.Asm.MutexDefault1
  • Local\ZonesCounterMutex
  • Local\!IETld!Mutex
  • Local\ZoneAttributeCacheCounterMutex
  • Local\ZonesCacheCounterMutex
  • Local\ZonesLockedCacheCounterMutex
执行的命令 无信息
创建的服务 无信息
启动的服务 无信息

进程

Plants_Vs_Zombies_V1.0.0.1051_CN_V2.exe PID: 2728, 上一级进程 PID: 2348

访问的文件
  • \Device\KsecDD
  • C:\Users\test\AppData\Local\Temp\Plants_Vs_Zombies_V1.0.0.1051_CN_V2.exe
  • C:\Windows\win.ini
  • C:\Windows\SysWOW64\shell32.dll
  • C:\Windows\WindowsShell.manifest
  • C:\Windows\Fonts\staticcache.dat
  • C:\Windows\sysnative\C_1250.NLS
  • C:\Windows\sysnative\C_1251.NLS
  • C:\Windows\sysnative\C_1253.NLS
  • C:\Windows\sysnative\C_1254.NLS
  • C:\Windows\sysnative\C_1255.NLS
  • C:\Windows\sysnative\C_1256.NLS
  • C:\Windows\sysnative\C_1257.NLS
  • C:\Windows\sysnative\C_1258.NLS
  • C:\Windows\sysnative\C_874.NLS
  • C:\Windows\sysnative\C_932.NLS
  • C:\Windows\sysnative\C_949.NLS
  • C:\Windows\sysnative\C_950.NLS
  • C:\Windows\sysnative\C_1361.NLS
  • C:
  • C:\Users
  • C:\Users\test
  • C:\Users\test\AppData
  • C:\Users\test\AppData\Local
  • C:\Users\test\AppData\Local\Temp
  • C:\Users\test\AppData\Local\Temp\__tmp_rar_sfx_access_check_22216566
  • C:\Users\test\AppData\Local\Temp\Plants_Vs_Zombies_V1.0.0.1051_CN_V2\bass.dll
  • C:\Users\test\AppData\Local\Temp\Plants_Vs_Zombies_V1.0.0.1051_CN_V2
  • C:\Users\test\AppData\Local\Temp\Plants_Vs_Zombies_V1.0.0.1051_CN_V2\cached
  • C:\Users\test\AppData\Local\Temp\Plants_Vs_Zombies_V1.0.0.1051_CN_V2\data\BrianneTod12.txt
  • C:\Users\test\AppData\Local\Temp\Plants_Vs_Zombies_V1.0.0.1051_CN_V2\data
  • C:\Users\test\AppData\Local\Temp\Plants_Vs_Zombies_V1.0.0.1051_CN_V2\data\BrianneTod16.txt
  • C:\Users\test\AppData\Local\Temp\Plants_Vs_Zombies_V1.0.0.1051_CN_V2\data\BrianneTod32.txt
  • C:\Users\test\AppData\Local\Temp\Plants_Vs_Zombies_V1.0.0.1051_CN_V2\data\BrianneTod32Black.txt
  • C:\Users\test\AppData\Local\Temp\Plants_Vs_Zombies_V1.0.0.1051_CN_V2\data\ContinuumBold14.txt
  • C:\Users\test\AppData\Local\Temp\Plants_Vs_Zombies_V1.0.0.1051_CN_V2\data\ContinuumBold14outback.txt
  • C:\Users\test\AppData\Local\Temp\Plants_Vs_Zombies_V1.0.0.1051_CN_V2\data\DwarvenTodcraft12.txt
  • C:\Users\test\AppData\Local\Temp\Plants_Vs_Zombies_V1.0.0.1051_CN_V2\data\DwarvenTodcraft15.txt
  • C:\Users\test\AppData\Local\Temp\Plants_Vs_Zombies_V1.0.0.1051_CN_V2\data\DwarvenTodcraft18.txt
  • C:\Users\test\AppData\Local\Temp\Plants_Vs_Zombies_V1.0.0.1051_CN_V2\data\DwarvenTodcraft18BrightGreenInset.txt
  • C:\Users\test\AppData\Local\Temp\Plants_Vs_Zombies_V1.0.0.1051_CN_V2\data\DwarvenTodcraft18GreenInset.txt
  • C:\Users\test\AppData\Local\Temp\Plants_Vs_Zombies_V1.0.0.1051_CN_V2\data\DwarvenTodcraft18Yellow.txt
  • C:\Users\test\AppData\Local\Temp\Plants_Vs_Zombies_V1.0.0.1051_CN_V2\data\DwarvenTodcraft24.txt
  • C:\Users\test\AppData\Local\Temp\Plants_Vs_Zombies_V1.0.0.1051_CN_V2\data\DwarvenTodcraft36BrightGreenInset.txt
  • C:\Users\test\AppData\Local\Temp\Plants_Vs_Zombies_V1.0.0.1051_CN_V2\data\DwarvenTodcraft36GreenInset.txt
  • C:\Users\test\AppData\Local\Temp\Plants_Vs_Zombies_V1.0.0.1051_CN_V2\data\HouseofTerror16.txt
  • C:\Users\test\AppData\Local\Temp\Plants_Vs_Zombies_V1.0.0.1051_CN_V2\data\HouseofTerror20.txt
  • C:\Users\test\AppData\Local\Temp\Plants_Vs_Zombies_V1.0.0.1051_CN_V2\data\HouseofTerror28.png
  • C:\Users\test\AppData\Local\Temp\Plants_Vs_Zombies_V1.0.0.1051_CN_V2\data\HouseofTerror28.txt
  • C:\Users\test\AppData\Local\Temp\Plants_Vs_Zombies_V1.0.0.1051_CN_V2\data\Pico129.txt
  • C:\Users\test\AppData\Local\Temp\Plants_Vs_Zombies_V1.0.0.1051_CN_V2\data\Pix118Bold.txt
  • C:\Users\test\AppData\Local\Temp\Plants_Vs_Zombies_V1.0.0.1051_CN_V2\data\_HouseofTerror16.png
  • C:\Users\test\AppData\Local\Temp\Plants_Vs_Zombies_V1.0.0.1051_CN_V2\font\font1.bin
  • C:\Users\test\AppData\Local\Temp\Plants_Vs_Zombies_V1.0.0.1051_CN_V2\font
  • C:\Users\test\AppData\Local\Temp\Plants_Vs_Zombies_V1.0.0.1051_CN_V2\font\font1.dds
  • C:\Users\test\AppData\Local\Temp\Plants_Vs_Zombies_V1.0.0.1051_CN_V2\font\font2.bin
  • C:\Users\test\AppData\Local\Temp\Plants_Vs_Zombies_V1.0.0.1051_CN_V2\font\font2.dds
  • C:\Users\test\AppData\Local\Temp\Plants_Vs_Zombies_V1.0.0.1051_CN_V2\font\font3.bin
  • C:\Users\test\AppData\Local\Temp\Plants_Vs_Zombies_V1.0.0.1051_CN_V2\font\font3.dds
  • C:\Users\test\AppData\Local\Temp\Plants_Vs_Zombies_V1.0.0.1051_CN_V2\font\font4.bin
  • C:\Users\test\AppData\Local\Temp\Plants_Vs_Zombies_V1.0.0.1051_CN_V2\font\font4.dds
  • C:\Users\test\AppData\Local\Temp\Plants_Vs_Zombies_V1.0.0.1051_CN_V2\font\font5.bin
  • C:\Users\test\AppData\Local\Temp\Plants_Vs_Zombies_V1.0.0.1051_CN_V2\font\font5.dds
  • C:\Users\test\AppData\Local\Temp\Plants_Vs_Zombies_V1.0.0.1051_CN_V2\font\font6.bin
  • C:\Users\test\AppData\Local\Temp\Plants_Vs_Zombies_V1.0.0.1051_CN_V2\font\font6.dds
  • C:\Users\test\AppData\Local\Temp\Plants_Vs_Zombies_V1.0.0.1051_CN_V2\gdi42.dll
  • C:\Users\test\AppData\Local\Temp\Plants_Vs_Zombies_V1.0.0.1051_CN_V2\images\Almanac.png
  • C:\Users\test\AppData\Local\Temp\Plants_Vs_Zombies_V1.0.0.1051_CN_V2\images
  • C:\Users\test\AppData\Local\Temp\Plants_Vs_Zombies_V1.0.0.1051_CN_V2\images\Almanac_IndexBack.jpg
  • C:\Users\test\AppData\Local\Temp\Plants_Vs_Zombies_V1.0.0.1051_CN_V2\images\Credits_ZombieNote.png
  • C:\Users\test\AppData\Local\Temp\Plants_Vs_Zombies_V1.0.0.1051_CN_V2\images\FlagMeterLevelProgress.png
  • C:\Users\test\AppData\Local\Temp\Plants_Vs_Zombies_V1.0.0.1051_CN_V2\images\options_menuback.jpg
  • C:\Users\test\AppData\Local\Temp\Plants_Vs_Zombies_V1.0.0.1051_CN_V2\images\PvZ_Logo.jpg
  • C:\Users\test\AppData\Local\Temp\Plants_Vs_Zombies_V1.0.0.1051_CN_V2\images\PvZ_Logo_.png
  • C:\Users\test\AppData\Local\Temp\Plants_Vs_Zombies_V1.0.0.1051_CN_V2\images\SelectorScreen_Almanac.png
  • C:\Users\test\AppData\Local\Temp\Plants_Vs_Zombies_V1.0.0.1051_CN_V2\images\SelectorScreen_AlmanacHighlight.png
  • C:\Users\test\AppData\Local\Temp\Plants_Vs_Zombies_V1.0.0.1051_CN_V2\images\SelectorScreen_Help1.png
  • C:\Users\test\AppData\Local\Temp\Plants_Vs_Zombies_V1.0.0.1051_CN_V2\images\SelectorScreen_Help2.png
  • C:\Users\test\AppData\Local\Temp\Plants_Vs_Zombies_V1.0.0.1051_CN_V2\images\SelectorScreen_Options1.png
  • C:\Users\test\AppData\Local\Temp\Plants_Vs_Zombies_V1.0.0.1051_CN_V2\images\SelectorScreen_Options2.png
  • C:\Users\test\AppData\Local\Temp\Plants_Vs_Zombies_V1.0.0.1051_CN_V2\images\SelectorScreen_Quit1.png
  • C:\Users\test\AppData\Local\Temp\Plants_Vs_Zombies_V1.0.0.1051_CN_V2\images\SelectorScreen_Quit2.png
  • C:\Users\test\AppData\Local\Temp\Plants_Vs_Zombies_V1.0.0.1051_CN_V2\images\SelectorScreen_Store.png
  • C:\Users\test\AppData\Local\Temp\Plants_Vs_Zombies_V1.0.0.1051_CN_V2\images\SelectorScreen_StoreHighlight.png
  • C:\Users\test\AppData\Local\Temp\Plants_Vs_Zombies_V1.0.0.1051_CN_V2\images\SelectorScreen_ZenGarden.png
  • C:\Users\test\AppData\Local\Temp\Plants_Vs_Zombies_V1.0.0.1051_CN_V2\images\SelectorScreen_ZenGardenHighlight.png
  • C:\Users\test\AppData\Local\Temp\Plants_Vs_Zombies_V1.0.0.1051_CN_V2\images\Store_NextButton.png
  • C:\Users\test\AppData\Local\Temp\Plants_Vs_Zombies_V1.0.0.1051_CN_V2\images\Store_NextButtonHighlight.png
  • C:\Users\test\AppData\Local\Temp\Plants_Vs_Zombies_V1.0.0.1051_CN_V2\images\Store_PrevButton.png
  • C:\Users\test\AppData\Local\Temp\Plants_Vs_Zombies_V1.0.0.1051_CN_V2\images\Store_PrevButtonHighlight.png
  • C:\Users\test\AppData\Local\Temp\Plants_Vs_Zombies_V1.0.0.1051_CN_V2\images\Store_Sign.png
  • C:\Users\test\AppData\Local\Temp\Plants_Vs_Zombies_V1.0.0.1051_CN_V2\images\Thumbs.db
  • C:\Users\test\AppData\Local\Temp\Plants_Vs_Zombies_V1.0.0.1051_CN_V2\images\Tombstones.jpg
  • C:\Users\test\AppData\Local\Temp\Plants_Vs_Zombies_V1.0.0.1051_CN_V2\images\zenshopbutton.png
  • C:\Users\test\AppData\Local\Temp\Plants_Vs_Zombies_V1.0.0.1051_CN_V2\images\zenshopbutton_highlight.png
  • C:\Users\test\AppData\Local\Temp\Plants_Vs_Zombies_V1.0.0.1051_CN_V2\images\Zombiefinalnote.png
  • C:\Users\test\AppData\Local\Temp\Plants_Vs_Zombies_V1.0.0.1051_CN_V2\images\ZombieNote1.png
  • C:\Users\test\AppData\Local\Temp\Plants_Vs_Zombies_V1.0.0.1051_CN_V2\images\ZombieNote2.png
  • C:\Users\test\AppData\Local\Temp\Plants_Vs_Zombies_V1.0.0.1051_CN_V2\images\ZombieNote3.png
  • C:\Users\test\AppData\Local\Temp\Plants_Vs_Zombies_V1.0.0.1051_CN_V2\images\ZombieNote4.png
  • C:\Users\test\AppData\Local\Temp\Plants_Vs_Zombies_V1.0.0.1051_CN_V2\images\ZombieNoteHelp.png
  • C:\Users\test\AppData\Local\Temp\Plants_Vs_Zombies_V1.0.0.1051_CN_V2\images\Zombie_bobsled1.png
  • C:\Users\test\AppData\Local\Temp\Plants_Vs_Zombies_V1.0.0.1051_CN_V2\images\Zombie_bobsled2.png
  • C:\Users\test\AppData\Local\Temp\Plants_Vs_Zombies_V1.0.0.1051_CN_V2\images\Zombie_bobsled3.png
  • C:\Users\test\AppData\Local\Temp\Plants_Vs_Zombies_V1.0.0.1051_CN_V2\images\Zombie_bobsled4.png
  • C:\Users\test\AppData\Local\Temp\Plants_Vs_Zombies_V1.0.0.1051_CN_V2\main.pak
  • C:\Users\test\AppData\Local\Temp\Plants_Vs_Zombies_V1.0.0.1051_CN_V2\particles\Doom.png
  • C:\Users\test\AppData\Local\Temp\Plants_Vs_Zombies_V1.0.0.1051_CN_V2\particles
  • C:\Users\test\AppData\Local\Temp\Plants_Vs_Zombies_V1.0.0.1051_CN_V2\particles\ExplosionPowie.png
  • C:\Users\test\AppData\Local\Temp\Plants_Vs_Zombies_V1.0.0.1051_CN_V2\particles\ExplosionSpudow.png
  • C:\Users\test\AppData\Local\Temp\Plants_Vs_Zombies_V1.0.0.1051_CN_V2\particles\Pow.png
  • C:\Users\test\AppData\Local\Temp\Plants_Vs_Zombies_V1.0.0.1051_CN_V2\particles\Sproing.png
  • C:\Users\test\AppData\Local\Temp\Plants_Vs_Zombies_V1.0.0.1051_CN_V2\PlantsVsZombies.exe
  • C:\Users\test\AppData\Local\Temp\Plants_Vs_Zombies_V1.0.0.1051_CN_V2\properties\LawnStrings.txt
  • C:\Users\test\AppData\Local\Temp\Plants_Vs_Zombies_V1.0.0.1051_CN_V2\properties
  • C:\Users\test\AppData\Local\Temp\Plants_Vs_Zombies_V1.0.0.1051_CN_V2\properties\partner.xml
  • C:\Users\test\AppData\Local\Temp\Plants_Vs_Zombies_V1.0.0.1051_CN_V2\properties\partner.xml.sig
  • C:\Users\test\AppData\Local\Temp\Plants_Vs_Zombies_V1.0.0.1051_CN_V2\properties\partner_logo.jpg
  • C:\Users\test\AppData\Local\Temp\Plants_Vs_Zombies_V1.0.0.1051_CN_V2\reanim\Credits_MTV.png
  • C:\Users\test\AppData\Local\Temp\Plants_Vs_Zombies_V1.0.0.1051_CN_V2\reanim
  • C:\Users\test\AppData\Local\Temp\Plants_Vs_Zombies_V1.0.0.1051_CN_V2\reanim\Credits_wearetheundead.jpg
  • C:\Users\test\AppData\Local\Temp\Plants_Vs_Zombies_V1.0.0.1051_CN_V2\reanim\Credits_wearetheundead_.png
  • C:\Users\test\AppData\Local\Temp\Plants_Vs_Zombies_V1.0.0.1051_CN_V2\reanim\FinalWave.png
  • C:\Users\test\AppData\Local\Temp\Plants_Vs_Zombies_V1.0.0.1051_CN_V2\reanim\SelectorScreen_Adventure_button.png
  • C:\Users\test\AppData\Local\Temp\Plants_Vs_Zombies_V1.0.0.1051_CN_V2\reanim\SelectorScreen_Adventure_highlight.png
  • C:\Users\test\AppData\Local\Temp\Plants_Vs_Zombies_V1.0.0.1051_CN_V2\reanim\SelectorScreen_BG_Right.jpg
  • C:\Users\test\AppData\Local\Temp\Plants_Vs_Zombies_V1.0.0.1051_CN_V2\reanim\SelectorScreen_Challenges_button.png
  • C:\Users\test\AppData\Local\Temp\Plants_Vs_Zombies_V1.0.0.1051_CN_V2\reanim\SelectorScreen_Challenges_highlight.png
  • C:\Users\test\AppData\Local\Temp\Plants_Vs_Zombies_V1.0.0.1051_CN_V2\reanim\SelectorScreen_StartAdventure_Button1.png
  • C:\Users\test\AppData\Local\Temp\Plants_Vs_Zombies_V1.0.0.1051_CN_V2\reanim\SelectorScreen_StartAdventure_Highlight.png
  • C:\Users\test\AppData\Local\Temp\Plants_Vs_Zombies_V1.0.0.1051_CN_V2\reanim\SelectorScreen_Survival_button.png
  • C:\Users\test\AppData\Local\Temp\Plants_Vs_Zombies_V1.0.0.1051_CN_V2\reanim\SelectorScreen_Survival_highlight.png
  • C:\Users\test\AppData\Local\Temp\Plants_Vs_Zombies_V1.0.0.1051_CN_V2\reanim\SelectorScreen_Vasebreaker_button.png
  • C:\Users\test\AppData\Local\Temp\Plants_Vs_Zombies_V1.0.0.1051_CN_V2\reanim\SelectorScreen_vasebreaker_highlight.png
  • C:\Users\test\AppData\Local\Temp\Plants_Vs_Zombies_V1.0.0.1051_CN_V2\reanim\SelectorScreen_WoodSign1.png
  • C:\Users\test\AppData\Local\Temp\Plants_Vs_Zombies_V1.0.0.1051_CN_V2\reanim\SelectorScreen_WoodSign2.png
  • C:\Users\test\AppData\Local\Temp\Plants_Vs_Zombies_V1.0.0.1051_CN_V2\reanim\SelectorScreen_WoodSign2_press.png
  • C:\Users\test\AppData\Local\Temp\Plants_Vs_Zombies_V1.0.0.1051_CN_V2\reanim\StartPlant.png
  • C:\Users\test\AppData\Local\Temp\Plants_Vs_Zombies_V1.0.0.1051_CN_V2\reanim\StartReady.png
  • C:\Users\test\AppData\Local\Temp\Plants_Vs_Zombies_V1.0.0.1051_CN_V2\reanim\StartSet.png
  • C:\Users\test\AppData\Local\Temp\Plants_Vs_Zombies_V1.0.0.1051_CN_V2\reanim\ZombiesWon.jpg
  • C:\Users\test\AppData\Local\Temp\Plants_Vs_Zombies_V1.0.0.1051_CN_V2\reanim\ZombiesWon_.png
读取的文件
  • \Device\KsecDD
  • C:\Users\test\AppData\Local\Temp\Plants_Vs_Zombies_V1.0.0.1051_CN_V2.exe
  • C:\Windows\win.ini
  • C:\Windows\SysWOW64\shell32.dll
  • C:\Windows\WindowsShell.manifest
  • C:\Windows\Fonts\staticcache.dat
  • C:\Users\test\AppData\Local\Temp\__tmp_rar_sfx_access_check_22216566
  • C:\Users\test\AppData\Local\Temp\Plants_Vs_Zombies_V1.0.0.1051_CN_V2\bass.dll
  • C:\Users\test\AppData\Local\Temp\Plants_Vs_Zombies_V1.0.0.1051_CN_V2\cached
  • C:\Users\test\AppData\Local\Temp\Plants_Vs_Zombies_V1.0.0.1051_CN_V2\data\BrianneTod12.txt
  • C:\Users\test\AppData\Local\Temp\Plants_Vs_Zombies_V1.0.0.1051_CN_V2\data\BrianneTod16.txt
  • C:\Users\test\AppData\Local\Temp\Plants_Vs_Zombies_V1.0.0.1051_CN_V2\data\BrianneTod32.txt
  • C:\Users\test\AppData\Local\Temp\Plants_Vs_Zombies_V1.0.0.1051_CN_V2\data\BrianneTod32Black.txt
  • C:\Users\test\AppData\Local\Temp\Plants_Vs_Zombies_V1.0.0.1051_CN_V2\data\ContinuumBold14.txt
  • C:\Users\test\AppData\Local\Temp\Plants_Vs_Zombies_V1.0.0.1051_CN_V2\data\ContinuumBold14outback.txt
  • C:\Users\test\AppData\Local\Temp\Plants_Vs_Zombies_V1.0.0.1051_CN_V2\data\DwarvenTodcraft12.txt
  • C:\Users\test\AppData\Local\Temp\Plants_Vs_Zombies_V1.0.0.1051_CN_V2\data\DwarvenTodcraft15.txt
  • C:\Users\test\AppData\Local\Temp\Plants_Vs_Zombies_V1.0.0.1051_CN_V2\data\DwarvenTodcraft18.txt
  • C:\Users\test\AppData\Local\Temp\Plants_Vs_Zombies_V1.0.0.1051_CN_V2\data\DwarvenTodcraft18BrightGreenInset.txt
  • C:\Users\test\AppData\Local\Temp\Plants_Vs_Zombies_V1.0.0.1051_CN_V2\data\DwarvenTodcraft18GreenInset.txt
  • C:\Users\test\AppData\Local\Temp\Plants_Vs_Zombies_V1.0.0.1051_CN_V2\data\DwarvenTodcraft18Yellow.txt
  • C:\Users\test\AppData\Local\Temp\Plants_Vs_Zombies_V1.0.0.1051_CN_V2\data\DwarvenTodcraft24.txt
  • C:\Users\test\AppData\Local\Temp\Plants_Vs_Zombies_V1.0.0.1051_CN_V2\data\DwarvenTodcraft36BrightGreenInset.txt
  • C:\Users\test\AppData\Local\Temp\Plants_Vs_Zombies_V1.0.0.1051_CN_V2\data\DwarvenTodcraft36GreenInset.txt
  • C:\Users\test\AppData\Local\Temp\Plants_Vs_Zombies_V1.0.0.1051_CN_V2\data\HouseofTerror16.txt
  • C:\Users\test\AppData\Local\Temp\Plants_Vs_Zombies_V1.0.0.1051_CN_V2\data\HouseofTerror20.txt
  • C:\Users\test\AppData\Local\Temp\Plants_Vs_Zombies_V1.0.0.1051_CN_V2\data\HouseofTerror28.png
  • C:\Users\test\AppData\Local\Temp\Plants_Vs_Zombies_V1.0.0.1051_CN_V2\data\HouseofTerror28.txt
  • C:\Users\test\AppData\Local\Temp\Plants_Vs_Zombies_V1.0.0.1051_CN_V2\data\Pico129.txt
  • C:\Users\test\AppData\Local\Temp\Plants_Vs_Zombies_V1.0.0.1051_CN_V2\data\Pix118Bold.txt
  • C:\Users\test\AppData\Local\Temp\Plants_Vs_Zombies_V1.0.0.1051_CN_V2\data\_HouseofTerror16.png
  • C:\Users\test\AppData\Local\Temp\Plants_Vs_Zombies_V1.0.0.1051_CN_V2\font\font1.bin
  • C:\Users\test\AppData\Local\Temp\Plants_Vs_Zombies_V1.0.0.1051_CN_V2\font\font1.dds
  • C:\Users\test\AppData\Local\Temp\Plants_Vs_Zombies_V1.0.0.1051_CN_V2\font\font2.bin
  • C:\Users\test\AppData\Local\Temp\Plants_Vs_Zombies_V1.0.0.1051_CN_V2\font\font2.dds
  • C:\Users\test\AppData\Local\Temp\Plants_Vs_Zombies_V1.0.0.1051_CN_V2\font\font3.bin
  • C:\Users\test\AppData\Local\Temp\Plants_Vs_Zombies_V1.0.0.1051_CN_V2\font\font3.dds
  • C:\Users\test\AppData\Local\Temp\Plants_Vs_Zombies_V1.0.0.1051_CN_V2\font\font4.bin
  • C:\Users\test\AppData\Local\Temp\Plants_Vs_Zombies_V1.0.0.1051_CN_V2\font\font4.dds
  • C:\Users\test\AppData\Local\Temp\Plants_Vs_Zombies_V1.0.0.1051_CN_V2\font\font5.bin
  • C:\Users\test\AppData\Local\Temp\Plants_Vs_Zombies_V1.0.0.1051_CN_V2\font\font5.dds
  • C:\Users\test\AppData\Local\Temp\Plants_Vs_Zombies_V1.0.0.1051_CN_V2\font\font6.bin
  • C:\Users\test\AppData\Local\Temp\Plants_Vs_Zombies_V1.0.0.1051_CN_V2\font\font6.dds
  • C:\Users\test\AppData\Local\Temp\Plants_Vs_Zombies_V1.0.0.1051_CN_V2\gdi42.dll
  • C:\Users\test\AppData\Local\Temp\Plants_Vs_Zombies_V1.0.0.1051_CN_V2\images\Almanac.png
  • C:\Users\test\AppData\Local\Temp\Plants_Vs_Zombies_V1.0.0.1051_CN_V2\images\Almanac_IndexBack.jpg
  • C:\Users\test\AppData\Local\Temp\Plants_Vs_Zombies_V1.0.0.1051_CN_V2\images\Credits_ZombieNote.png
  • C:\Users\test\AppData\Local\Temp\Plants_Vs_Zombies_V1.0.0.1051_CN_V2\images\FlagMeterLevelProgress.png
  • C:\Users\test\AppData\Local\Temp\Plants_Vs_Zombies_V1.0.0.1051_CN_V2\images\options_menuback.jpg
  • C:\Users\test\AppData\Local\Temp\Plants_Vs_Zombies_V1.0.0.1051_CN_V2\images\PvZ_Logo.jpg
  • C:\Users\test\AppData\Local\Temp\Plants_Vs_Zombies_V1.0.0.1051_CN_V2\images\PvZ_Logo_.png
  • C:\Users\test\AppData\Local\Temp\Plants_Vs_Zombies_V1.0.0.1051_CN_V2\images\SelectorScreen_Almanac.png
  • C:\Users\test\AppData\Local\Temp\Plants_Vs_Zombies_V1.0.0.1051_CN_V2\images\SelectorScreen_AlmanacHighlight.png
  • C:\Users\test\AppData\Local\Temp\Plants_Vs_Zombies_V1.0.0.1051_CN_V2\images\SelectorScreen_Help1.png
  • C:\Users\test\AppData\Local\Temp\Plants_Vs_Zombies_V1.0.0.1051_CN_V2\images\SelectorScreen_Help2.png
  • C:\Users\test\AppData\Local\Temp\Plants_Vs_Zombies_V1.0.0.1051_CN_V2\images\SelectorScreen_Options1.png
  • C:\Users\test\AppData\Local\Temp\Plants_Vs_Zombies_V1.0.0.1051_CN_V2\images\SelectorScreen_Options2.png
  • C:\Users\test\AppData\Local\Temp\Plants_Vs_Zombies_V1.0.0.1051_CN_V2\images\SelectorScreen_Quit1.png
  • C:\Users\test\AppData\Local\Temp\Plants_Vs_Zombies_V1.0.0.1051_CN_V2\images\SelectorScreen_Quit2.png
  • C:\Users\test\AppData\Local\Temp\Plants_Vs_Zombies_V1.0.0.1051_CN_V2\images\SelectorScreen_Store.png
  • C:\Users\test\AppData\Local\Temp\Plants_Vs_Zombies_V1.0.0.1051_CN_V2\images\SelectorScreen_StoreHighlight.png
  • C:\Users\test\AppData\Local\Temp\Plants_Vs_Zombies_V1.0.0.1051_CN_V2\images\SelectorScreen_ZenGarden.png
  • C:\Users\test\AppData\Local\Temp\Plants_Vs_Zombies_V1.0.0.1051_CN_V2\images\SelectorScreen_ZenGardenHighlight.png
  • C:\Users\test\AppData\Local\Temp\Plants_Vs_Zombies_V1.0.0.1051_CN_V2\images\Store_NextButton.png
  • C:\Users\test\AppData\Local\Temp\Plants_Vs_Zombies_V1.0.0.1051_CN_V2\images\Store_NextButtonHighlight.png
  • C:\Users\test\AppData\Local\Temp\Plants_Vs_Zombies_V1.0.0.1051_CN_V2\images\Store_PrevButton.png
  • C:\Users\test\AppData\Local\Temp\Plants_Vs_Zombies_V1.0.0.1051_CN_V2\images\Store_PrevButtonHighlight.png
  • C:\Users\test\AppData\Local\Temp\Plants_Vs_Zombies_V1.0.0.1051_CN_V2\images\Store_Sign.png
  • C:\Users\test\AppData\Local\Temp\Plants_Vs_Zombies_V1.0.0.1051_CN_V2\images\Thumbs.db
  • C:\Users\test\AppData\Local\Temp\Plants_Vs_Zombies_V1.0.0.1051_CN_V2\images\Tombstones.jpg
  • C:\Users\test\AppData\Local\Temp\Plants_Vs_Zombies_V1.0.0.1051_CN_V2\images\zenshopbutton.png
  • C:\Users\test\AppData\Local\Temp\Plants_Vs_Zombies_V1.0.0.1051_CN_V2\images\zenshopbutton_highlight.png
  • C:\Users\test\AppData\Local\Temp\Plants_Vs_Zombies_V1.0.0.1051_CN_V2\images\Zombiefinalnote.png
  • C:\Users\test\AppData\Local\Temp\Plants_Vs_Zombies_V1.0.0.1051_CN_V2\images\ZombieNote1.png
  • C:\Users\test\AppData\Local\Temp\Plants_Vs_Zombies_V1.0.0.1051_CN_V2\images\ZombieNote2.png
  • C:\Users\test\AppData\Local\Temp\Plants_Vs_Zombies_V1.0.0.1051_CN_V2\images\ZombieNote3.png
  • C:\Users\test\AppData\Local\Temp\Plants_Vs_Zombies_V1.0.0.1051_CN_V2\images\ZombieNote4.png
  • C:\Users\test\AppData\Local\Temp\Plants_Vs_Zombies_V1.0.0.1051_CN_V2\images\ZombieNoteHelp.png
  • C:\Users\test\AppData\Local\Temp\Plants_Vs_Zombies_V1.0.0.1051_CN_V2\images\Zombie_bobsled1.png
  • C:\Users\test\AppData\Local\Temp\Plants_Vs_Zombies_V1.0.0.1051_CN_V2\images\Zombie_bobsled2.png
  • C:\Users\test\AppData\Local\Temp\Plants_Vs_Zombies_V1.0.0.1051_CN_V2\images\Zombie_bobsled3.png
  • C:\Users\test\AppData\Local\Temp\Plants_Vs_Zombies_V1.0.0.1051_CN_V2\images\Zombie_bobsled4.png
  • C:\Users\test\AppData\Local\Temp\Plants_Vs_Zombies_V1.0.0.1051_CN_V2\main.pak
  • C:\Users\test\AppData\Local\Temp\Plants_Vs_Zombies_V1.0.0.1051_CN_V2\particles\Doom.png
  • C:\Users\test\AppData\Local\Temp\Plants_Vs_Zombies_V1.0.0.1051_CN_V2\particles\ExplosionPowie.png
  • C:\Users\test\AppData\Local\Temp\Plants_Vs_Zombies_V1.0.0.1051_CN_V2\particles\ExplosionSpudow.png
  • C:\Users\test\AppData\Local\Temp\Plants_Vs_Zombies_V1.0.0.1051_CN_V2\particles\Pow.png
  • C:\Users\test\AppData\Local\Temp\Plants_Vs_Zombies_V1.0.0.1051_CN_V2\particles\Sproing.png
  • C:\Users\test\AppData\Local\Temp\Plants_Vs_Zombies_V1.0.0.1051_CN_V2\PlantsVsZombies.exe
  • C:\Users\test\AppData\Local\Temp\Plants_Vs_Zombies_V1.0.0.1051_CN_V2\properties\LawnStrings.txt
  • C:\Users\test\AppData\Local\Temp\Plants_Vs_Zombies_V1.0.0.1051_CN_V2\properties\partner.xml
  • C:\Users\test\AppData\Local\Temp\Plants_Vs_Zombies_V1.0.0.1051_CN_V2\properties\partner.xml.sig
  • C:\Users\test\AppData\Local\Temp\Plants_Vs_Zombies_V1.0.0.1051_CN_V2\properties\partner_logo.jpg
  • C:\Users\test\AppData\Local\Temp\Plants_Vs_Zombies_V1.0.0.1051_CN_V2\reanim\Credits_MTV.png
  • C:\Users\test\AppData\Local\Temp\Plants_Vs_Zombies_V1.0.0.1051_CN_V2\reanim\Credits_wearetheundead.jpg
  • C:\Users\test\AppData\Local\Temp\Plants_Vs_Zombies_V1.0.0.1051_CN_V2\reanim\Credits_wearetheundead_.png
  • C:\Users\test\AppData\Local\Temp\Plants_Vs_Zombies_V1.0.0.1051_CN_V2\reanim\FinalWave.png
  • C:\Users\test\AppData\Local\Temp\Plants_Vs_Zombies_V1.0.0.1051_CN_V2\reanim\SelectorScreen_Adventure_button.png
  • C:\Users\test\AppData\Local\Temp\Plants_Vs_Zombies_V1.0.0.1051_CN_V2\reanim\SelectorScreen_Adventure_highlight.png
  • C:\Users\test\AppData\Local\Temp\Plants_Vs_Zombies_V1.0.0.1051_CN_V2\reanim\SelectorScreen_BG_Right.jpg
  • C:\Users\test\AppData\Local\Temp\Plants_Vs_Zombies_V1.0.0.1051_CN_V2\reanim\SelectorScreen_Challenges_button.png
  • C:\Users\test\AppData\Local\Temp\Plants_Vs_Zombies_V1.0.0.1051_CN_V2\reanim\SelectorScreen_Challenges_highlight.png
  • C:\Users\test\AppData\Local\Temp\Plants_Vs_Zombies_V1.0.0.1051_CN_V2\reanim\SelectorScreen_StartAdventure_Button1.png
  • C:\Users\test\AppData\Local\Temp\Plants_Vs_Zombies_V1.0.0.1051_CN_V2\reanim\SelectorScreen_StartAdventure_Highlight.png
  • C:\Users\test\AppData\Local\Temp\Plants_Vs_Zombies_V1.0.0.1051_CN_V2\reanim\SelectorScreen_Survival_button.png
  • C:\Users\test\AppData\Local\Temp\Plants_Vs_Zombies_V1.0.0.1051_CN_V2\reanim\SelectorScreen_Survival_highlight.png
  • C:\Users\test\AppData\Local\Temp\Plants_Vs_Zombies_V1.0.0.1051_CN_V2\reanim\SelectorScreen_Vasebreaker_button.png
  • C:\Users\test\AppData\Local\Temp\Plants_Vs_Zombies_V1.0.0.1051_CN_V2\reanim\SelectorScreen_vasebreaker_highlight.png
  • C:\Users\test\AppData\Local\Temp\Plants_Vs_Zombies_V1.0.0.1051_CN_V2\reanim\SelectorScreen_WoodSign1.png
  • C:\Users\test\AppData\Local\Temp\Plants_Vs_Zombies_V1.0.0.1051_CN_V2\reanim\SelectorScreen_WoodSign2.png
  • C:\Users\test\AppData\Local\Temp\Plants_Vs_Zombies_V1.0.0.1051_CN_V2\reanim\SelectorScreen_WoodSign2_press.png
  • C:\Users\test\AppData\Local\Temp\Plants_Vs_Zombies_V1.0.0.1051_CN_V2\reanim\StartPlant.png
  • C:\Users\test\AppData\Local\Temp\Plants_Vs_Zombies_V1.0.0.1051_CN_V2\reanim\StartReady.png
  • C:\Users\test\AppData\Local\Temp\Plants_Vs_Zombies_V1.0.0.1051_CN_V2\reanim\StartSet.png
  • C:\Users\test\AppData\Local\Temp\Plants_Vs_Zombies_V1.0.0.1051_CN_V2\reanim\ZombiesWon.jpg
  • C:\Users\test\AppData\Local\Temp\Plants_Vs_Zombies_V1.0.0.1051_CN_V2\reanim\ZombiesWon_.png
修改的文件
  • C:\Users\test\AppData\Local\Temp\__tmp_rar_sfx_access_check_22216566
  • C:\Users\test\AppData\Local\Temp\Plants_Vs_Zombies_V1.0.0.1051_CN_V2\bass.dll
  • C:\Users\test\AppData\Local\Temp\Plants_Vs_Zombies_V1.0.0.1051_CN_V2\cached
  • C:\Users\test\AppData\Local\Temp\Plants_Vs_Zombies_V1.0.0.1051_CN_V2\data\BrianneTod12.txt
  • C:\Users\test\AppData\Local\Temp\Plants_Vs_Zombies_V1.0.0.1051_CN_V2\data\BrianneTod16.txt
  • C:\Users\test\AppData\Local\Temp\Plants_Vs_Zombies_V1.0.0.1051_CN_V2\data\BrianneTod32.txt
  • C:\Users\test\AppData\Local\Temp\Plants_Vs_Zombies_V1.0.0.1051_CN_V2\data\BrianneTod32Black.txt
  • C:\Users\test\AppData\Local\Temp\Plants_Vs_Zombies_V1.0.0.1051_CN_V2\data\ContinuumBold14.txt
  • C:\Users\test\AppData\Local\Temp\Plants_Vs_Zombies_V1.0.0.1051_CN_V2\data\ContinuumBold14outback.txt
  • C:\Users\test\AppData\Local\Temp\Plants_Vs_Zombies_V1.0.0.1051_CN_V2\data\DwarvenTodcraft12.txt
  • C:\Users\test\AppData\Local\Temp\Plants_Vs_Zombies_V1.0.0.1051_CN_V2\data\DwarvenTodcraft15.txt
  • C:\Users\test\AppData\Local\Temp\Plants_Vs_Zombies_V1.0.0.1051_CN_V2\data\DwarvenTodcraft18.txt
  • C:\Users\test\AppData\Local\Temp\Plants_Vs_Zombies_V1.0.0.1051_CN_V2\data\DwarvenTodcraft18BrightGreenInset.txt
  • C:\Users\test\AppData\Local\Temp\Plants_Vs_Zombies_V1.0.0.1051_CN_V2\data\DwarvenTodcraft18GreenInset.txt
  • C:\Users\test\AppData\Local\Temp\Plants_Vs_Zombies_V1.0.0.1051_CN_V2\data\DwarvenTodcraft18Yellow.txt
  • C:\Users\test\AppData\Local\Temp\Plants_Vs_Zombies_V1.0.0.1051_CN_V2\data\DwarvenTodcraft24.txt
  • C:\Users\test\AppData\Local\Temp\Plants_Vs_Zombies_V1.0.0.1051_CN_V2\data\DwarvenTodcraft36BrightGreenInset.txt
  • C:\Users\test\AppData\Local\Temp\Plants_Vs_Zombies_V1.0.0.1051_CN_V2\data\DwarvenTodcraft36GreenInset.txt
  • C:\Users\test\AppData\Local\Temp\Plants_Vs_Zombies_V1.0.0.1051_CN_V2\data\HouseofTerror16.txt
  • C:\Users\test\AppData\Local\Temp\Plants_Vs_Zombies_V1.0.0.1051_CN_V2\data\HouseofTerror20.txt
  • C:\Users\test\AppData\Local\Temp\Plants_Vs_Zombies_V1.0.0.1051_CN_V2\data\HouseofTerror28.png
  • C:\Users\test\AppData\Local\Temp\Plants_Vs_Zombies_V1.0.0.1051_CN_V2\data\HouseofTerror28.txt
  • C:\Users\test\AppData\Local\Temp\Plants_Vs_Zombies_V1.0.0.1051_CN_V2\data\Pico129.txt
  • C:\Users\test\AppData\Local\Temp\Plants_Vs_Zombies_V1.0.0.1051_CN_V2\data\Pix118Bold.txt
  • C:\Users\test\AppData\Local\Temp\Plants_Vs_Zombies_V1.0.0.1051_CN_V2\data\_HouseofTerror16.png
  • C:\Users\test\AppData\Local\Temp\Plants_Vs_Zombies_V1.0.0.1051_CN_V2\font\font1.bin
  • C:\Users\test\AppData\Local\Temp\Plants_Vs_Zombies_V1.0.0.1051_CN_V2\font\font1.dds
  • C:\Users\test\AppData\Local\Temp\Plants_Vs_Zombies_V1.0.0.1051_CN_V2\font\font2.bin
  • C:\Users\test\AppData\Local\Temp\Plants_Vs_Zombies_V1.0.0.1051_CN_V2\font\font2.dds
  • C:\Users\test\AppData\Local\Temp\Plants_Vs_Zombies_V1.0.0.1051_CN_V2\font\font3.bin
  • C:\Users\test\AppData\Local\Temp\Plants_Vs_Zombies_V1.0.0.1051_CN_V2\font\font3.dds
  • C:\Users\test\AppData\Local\Temp\Plants_Vs_Zombies_V1.0.0.1051_CN_V2\font\font4.bin
  • C:\Users\test\AppData\Local\Temp\Plants_Vs_Zombies_V1.0.0.1051_CN_V2\font\font4.dds
  • C:\Users\test\AppData\Local\Temp\Plants_Vs_Zombies_V1.0.0.1051_CN_V2\font\font5.bin
  • C:\Users\test\AppData\Local\Temp\Plants_Vs_Zombies_V1.0.0.1051_CN_V2\font\font5.dds
  • C:\Users\test\AppData\Local\Temp\Plants_Vs_Zombies_V1.0.0.1051_CN_V2\font\font6.bin
  • C:\Users\test\AppData\Local\Temp\Plants_Vs_Zombies_V1.0.0.1051_CN_V2\font\font6.dds
  • C:\Users\test\AppData\Local\Temp\Plants_Vs_Zombies_V1.0.0.1051_CN_V2\gdi42.dll
  • C:\Users\test\AppData\Local\Temp\Plants_Vs_Zombies_V1.0.0.1051_CN_V2\images\Almanac.png
  • C:\Users\test\AppData\Local\Temp\Plants_Vs_Zombies_V1.0.0.1051_CN_V2\images\Almanac_IndexBack.jpg
  • C:\Users\test\AppData\Local\Temp\Plants_Vs_Zombies_V1.0.0.1051_CN_V2\images\Credits_ZombieNote.png
  • C:\Users\test\AppData\Local\Temp\Plants_Vs_Zombies_V1.0.0.1051_CN_V2\images\FlagMeterLevelProgress.png
  • C:\Users\test\AppData\Local\Temp\Plants_Vs_Zombies_V1.0.0.1051_CN_V2\images\options_menuback.jpg
  • C:\Users\test\AppData\Local\Temp\Plants_Vs_Zombies_V1.0.0.1051_CN_V2\images\PvZ_Logo.jpg
  • C:\Users\test\AppData\Local\Temp\Plants_Vs_Zombies_V1.0.0.1051_CN_V2\images\PvZ_Logo_.png
  • C:\Users\test\AppData\Local\Temp\Plants_Vs_Zombies_V1.0.0.1051_CN_V2\images\SelectorScreen_Almanac.png
  • C:\Users\test\AppData\Local\Temp\Plants_Vs_Zombies_V1.0.0.1051_CN_V2\images\SelectorScreen_AlmanacHighlight.png
  • C:\Users\test\AppData\Local\Temp\Plants_Vs_Zombies_V1.0.0.1051_CN_V2\images\SelectorScreen_Help1.png
  • C:\Users\test\AppData\Local\Temp\Plants_Vs_Zombies_V1.0.0.1051_CN_V2\images\SelectorScreen_Help2.png
  • C:\Users\test\AppData\Local\Temp\Plants_Vs_Zombies_V1.0.0.1051_CN_V2\images\SelectorScreen_Options1.png
  • C:\Users\test\AppData\Local\Temp\Plants_Vs_Zombies_V1.0.0.1051_CN_V2\images\SelectorScreen_Options2.png
  • C:\Users\test\AppData\Local\Temp\Plants_Vs_Zombies_V1.0.0.1051_CN_V2\images\SelectorScreen_Quit1.png
  • C:\Users\test\AppData\Local\Temp\Plants_Vs_Zombies_V1.0.0.1051_CN_V2\images\SelectorScreen_Quit2.png
  • C:\Users\test\AppData\Local\Temp\Plants_Vs_Zombies_V1.0.0.1051_CN_V2\images\SelectorScreen_Store.png
  • C:\Users\test\AppData\Local\Temp\Plants_Vs_Zombies_V1.0.0.1051_CN_V2\images\SelectorScreen_StoreHighlight.png
  • C:\Users\test\AppData\Local\Temp\Plants_Vs_Zombies_V1.0.0.1051_CN_V2\images\SelectorScreen_ZenGarden.png
  • C:\Users\test\AppData\Local\Temp\Plants_Vs_Zombies_V1.0.0.1051_CN_V2\images\SelectorScreen_ZenGardenHighlight.png
  • C:\Users\test\AppData\Local\Temp\Plants_Vs_Zombies_V1.0.0.1051_CN_V2\images\Store_NextButton.png
  • C:\Users\test\AppData\Local\Temp\Plants_Vs_Zombies_V1.0.0.1051_CN_V2\images\Store_NextButtonHighlight.png
  • C:\Users\test\AppData\Local\Temp\Plants_Vs_Zombies_V1.0.0.1051_CN_V2\images\Store_PrevButton.png
  • C:\Users\test\AppData\Local\Temp\Plants_Vs_Zombies_V1.0.0.1051_CN_V2\images\Store_PrevButtonHighlight.png
  • C:\Users\test\AppData\Local\Temp\Plants_Vs_Zombies_V1.0.0.1051_CN_V2\images\Store_Sign.png
  • C:\Users\test\AppData\Local\Temp\Plants_Vs_Zombies_V1.0.0.1051_CN_V2\images\Thumbs.db
  • C:\Users\test\AppData\Local\Temp\Plants_Vs_Zombies_V1.0.0.1051_CN_V2\images\Tombstones.jpg
  • C:\Users\test\AppData\Local\Temp\Plants_Vs_Zombies_V1.0.0.1051_CN_V2\images\zenshopbutton.png
  • C:\Users\test\AppData\Local\Temp\Plants_Vs_Zombies_V1.0.0.1051_CN_V2\images\zenshopbutton_highlight.png
  • C:\Users\test\AppData\Local\Temp\Plants_Vs_Zombies_V1.0.0.1051_CN_V2\images\Zombiefinalnote.png
  • C:\Users\test\AppData\Local\Temp\Plants_Vs_Zombies_V1.0.0.1051_CN_V2\images\ZombieNote1.png
  • C:\Users\test\AppData\Local\Temp\Plants_Vs_Zombies_V1.0.0.1051_CN_V2\images\ZombieNote2.png
  • C:\Users\test\AppData\Local\Temp\Plants_Vs_Zombies_V1.0.0.1051_CN_V2\images\ZombieNote3.png
  • C:\Users\test\AppData\Local\Temp\Plants_Vs_Zombies_V1.0.0.1051_CN_V2\images\ZombieNote4.png
  • C:\Users\test\AppData\Local\Temp\Plants_Vs_Zombies_V1.0.0.1051_CN_V2\images\ZombieNoteHelp.png
  • C:\Users\test\AppData\Local\Temp\Plants_Vs_Zombies_V1.0.0.1051_CN_V2\images\Zombie_bobsled1.png
  • C:\Users\test\AppData\Local\Temp\Plants_Vs_Zombies_V1.0.0.1051_CN_V2\images\Zombie_bobsled2.png
  • C:\Users\test\AppData\Local\Temp\Plants_Vs_Zombies_V1.0.0.1051_CN_V2\images\Zombie_bobsled3.png
  • C:\Users\test\AppData\Local\Temp\Plants_Vs_Zombies_V1.0.0.1051_CN_V2\images\Zombie_bobsled4.png
  • C:\Users\test\AppData\Local\Temp\Plants_Vs_Zombies_V1.0.0.1051_CN_V2\main.pak
  • C:\Users\test\AppData\Local\Temp\Plants_Vs_Zombies_V1.0.0.1051_CN_V2\particles\Doom.png
  • C:\Users\test\AppData\Local\Temp\Plants_Vs_Zombies_V1.0.0.1051_CN_V2\particles\ExplosionPowie.png
  • C:\Users\test\AppData\Local\Temp\Plants_Vs_Zombies_V1.0.0.1051_CN_V2\particles\ExplosionSpudow.png
  • C:\Users\test\AppData\Local\Temp\Plants_Vs_Zombies_V1.0.0.1051_CN_V2\particles\Pow.png
  • C:\Users\test\AppData\Local\Temp\Plants_Vs_Zombies_V1.0.0.1051_CN_V2\particles\Sproing.png
  • C:\Users\test\AppData\Local\Temp\Plants_Vs_Zombies_V1.0.0.1051_CN_V2\PlantsVsZombies.exe
  • C:\Users\test\AppData\Local\Temp\Plants_Vs_Zombies_V1.0.0.1051_CN_V2\properties\LawnStrings.txt
  • C:\Users\test\AppData\Local\Temp\Plants_Vs_Zombies_V1.0.0.1051_CN_V2\properties\partner.xml
  • C:\Users\test\AppData\Local\Temp\Plants_Vs_Zombies_V1.0.0.1051_CN_V2\properties\partner.xml.sig
  • C:\Users\test\AppData\Local\Temp\Plants_Vs_Zombies_V1.0.0.1051_CN_V2\properties\partner_logo.jpg
  • C:\Users\test\AppData\Local\Temp\Plants_Vs_Zombies_V1.0.0.1051_CN_V2\reanim\Credits_MTV.png
  • C:\Users\test\AppData\Local\Temp\Plants_Vs_Zombies_V1.0.0.1051_CN_V2\reanim\Credits_wearetheundead.jpg
  • C:\Users\test\AppData\Local\Temp\Plants_Vs_Zombies_V1.0.0.1051_CN_V2\reanim\Credits_wearetheundead_.png
  • C:\Users\test\AppData\Local\Temp\Plants_Vs_Zombies_V1.0.0.1051_CN_V2\reanim\FinalWave.png
  • C:\Users\test\AppData\Local\Temp\Plants_Vs_Zombies_V1.0.0.1051_CN_V2\reanim\SelectorScreen_Adventure_button.png
  • C:\Users\test\AppData\Local\Temp\Plants_Vs_Zombies_V1.0.0.1051_CN_V2\reanim\SelectorScreen_Adventure_highlight.png
  • C:\Users\test\AppData\Local\Temp\Plants_Vs_Zombies_V1.0.0.1051_CN_V2\reanim\SelectorScreen_BG_Right.jpg
  • C:\Users\test\AppData\Local\Temp\Plants_Vs_Zombies_V1.0.0.1051_CN_V2\reanim\SelectorScreen_Challenges_button.png
  • C:\Users\test\AppData\Local\Temp\Plants_Vs_Zombies_V1.0.0.1051_CN_V2\reanim\SelectorScreen_Challenges_highlight.png
  • C:\Users\test\AppData\Local\Temp\Plants_Vs_Zombies_V1.0.0.1051_CN_V2\reanim\SelectorScreen_StartAdventure_Button1.png
  • C:\Users\test\AppData\Local\Temp\Plants_Vs_Zombies_V1.0.0.1051_CN_V2\reanim\SelectorScreen_StartAdventure_Highlight.png
  • C:\Users\test\AppData\Local\Temp\Plants_Vs_Zombies_V1.0.0.1051_CN_V2\reanim\SelectorScreen_Survival_button.png
  • C:\Users\test\AppData\Local\Temp\Plants_Vs_Zombies_V1.0.0.1051_CN_V2\reanim\SelectorScreen_Survival_highlight.png
  • C:\Users\test\AppData\Local\Temp\Plants_Vs_Zombies_V1.0.0.1051_CN_V2\reanim\SelectorScreen_Vasebreaker_button.png
  • C:\Users\test\AppData\Local\Temp\Plants_Vs_Zombies_V1.0.0.1051_CN_V2\reanim\SelectorScreen_vasebreaker_highlight.png
  • C:\Users\test\AppData\Local\Temp\Plants_Vs_Zombies_V1.0.0.1051_CN_V2\reanim\SelectorScreen_WoodSign1.png
  • C:\Users\test\AppData\Local\Temp\Plants_Vs_Zombies_V1.0.0.1051_CN_V2\reanim\SelectorScreen_WoodSign2.png
  • C:\Users\test\AppData\Local\Temp\Plants_Vs_Zombies_V1.0.0.1051_CN_V2\reanim\SelectorScreen_WoodSign2_press.png
  • C:\Users\test\AppData\Local\Temp\Plants_Vs_Zombies_V1.0.0.1051_CN_V2\reanim\StartPlant.png
  • C:\Users\test\AppData\Local\Temp\Plants_Vs_Zombies_V1.0.0.1051_CN_V2\reanim\StartReady.png
  • C:\Users\test\AppData\Local\Temp\Plants_Vs_Zombies_V1.0.0.1051_CN_V2\reanim\StartSet.png
  • C:\Users\test\AppData\Local\Temp\Plants_Vs_Zombies_V1.0.0.1051_CN_V2\reanim\ZombiesWon.jpg
  • C:\Users\test\AppData\Local\Temp\Plants_Vs_Zombies_V1.0.0.1051_CN_V2\reanim\ZombiesWon_.png
  • C:\Users\test\AppData\Local\Temp\Plants_Vs_Zombies_V1.0.0.1051_CN_V2\data
  • C:\Users\test\AppData\Local\Temp\Plants_Vs_Zombies_V1.0.0.1051_CN_V2\font
  • C:\Users\test\AppData\Local\Temp\Plants_Vs_Zombies_V1.0.0.1051_CN_V2\images
  • C:\Users\test\AppData\Local\Temp\Plants_Vs_Zombies_V1.0.0.1051_CN_V2\particles
  • C:\Users\test\AppData\Local\Temp\Plants_Vs_Zombies_V1.0.0.1051_CN_V2\properties
  • C:\Users\test\AppData\Local\Temp\Plants_Vs_Zombies_V1.0.0.1051_CN_V2\reanim
  • C:\Users\test\AppData\Local\Temp\Plants_Vs_Zombies_V1.0.0.1051_CN_V2
删除的文件
  • C:\Users\test\AppData\Local\Temp\__tmp_rar_sfx_access_check_22216566
注册表键
  • HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\Nls\Locale
  • HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\Nls\Locale\Alternate Sorts
  • HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\Nls\Language Groups
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\Locale\00000804
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\Language Groups\a
  • HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\Nls\CustomLocale
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\en-US
  • HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\Nls\ExtendedLocale
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\ExtendedLocale\en-US
  • HKEY_CURRENT_USER
  • HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows
  • HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows\ScrollInset
  • HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows\DragDelay
  • HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows\DragMinDist
  • HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows\ScrollDelay
  • HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows\ScrollInterval
  • HKEY_LOCAL_MACHINE\Software\Policies
  • HKEY_CURRENT_USER\Software\Policies
  • HKEY_CURRENT_USER\Software
  • HKEY_LOCAL_MACHINE\Software
  • HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\CurrentVersion\Explorer\AutoComplete
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\AutoComplete
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\AutoComplete\Append Completion
  • HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\CurrentVersion\Explorer\AutoComplete
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\AutoComplete\AutoSuggest
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\AutoComplete\Always Use Tab
  • HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\AutoComplete
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\AutoComplete\Always Use Tab
  • HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\SideBySide
  • HKEY_CLASSES_ROOT\CLSID\{03C036F1-A186-11D0-824A-00AA005B4383}\InProcServer32
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{03C036F1-A186-11D0-824A-00AA005B4383}\InProcServer32\(Default)
  • HKEY_CLASSES_ROOT\CLSID\{00BB2763-6A77-11D0-A535-00C04FD7D062}\InProcServer32
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{00BB2763-6A77-11D0-A535-00C04FD7D062}\InProcServer32\(Default)
  • HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\AutoComplete\Client\
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\AutoComplete\Client\(Default)
  • HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\Windows Error Reporting\WMR
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\Windows Error Reporting\WMR\Disable
  • HKEY_CURRENT_USER\Software\Classes
  • HKEY_CURRENT_USER\Software\Classes\Shell.Explorer
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Shell.Explorer\CLSID
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Shell.Explorer\CLSID\(Default)
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\CTF\Compatibility\Plants_Vs_Zombies_V1.0.0.1051_CN_V2.exe
  • HKEY_LOCAL_MACHINE\Software\Microsoft\CTF\TIP\{0000897b-83df-4b96-be07-0fb58b01c4a4}\LanguageProfile\0x00000000\{0001bea3-ed56-483d-a2e2-aeae25577436}
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\CTF\TIP\{0000897b-83df-4b96-be07-0fb58b01c4a4}\LanguageProfile\0x00000000\{0001bea3-ed56-483d-a2e2-aeae25577436}\Enable
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\CTF\TIP\
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\CTF\TIP\{0000897b-83df-4b96-be07-0fb58b01c4a4}\Category\Category\{534C48C1-0607-4098-A521-4FC899C73E90}
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\CTF\TIP\{03B5835F-F03C-411B-9CE2-AA23E1171E36}\Category\Category\{534C48C1-0607-4098-A521-4FC899C73E90}
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\CTF\TIP\{07EB03D6-B001-41DF-9192-BF9B841EE71F}\Category\Category\{534C48C1-0607-4098-A521-4FC899C73E90}
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\CTF\TIP\{3697C5FA-60DD-4B56-92D4-74A569205C16}\Category\Category\{534C48C1-0607-4098-A521-4FC899C73E90}
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\CTF\TIP\{3FC47A08-E5C9-4BCA-A2C7-BC9A282AED14}\Category\Category\{534C48C1-0607-4098-A521-4FC899C73E90}
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\CTF\TIP\{531FDEBF-9B4C-4A43-A2AA-960E8FCDC732}\Category\Category\{534C48C1-0607-4098-A521-4FC899C73E90}
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\CTF\TIP\{78CB5B0E-26ED-4FCC-854C-77E8F3D1AA80}\Category\Category\{534C48C1-0607-4098-A521-4FC899C73E90}
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\CTF\TIP\{81D4E9C9-1D3B-41BC-9E6C-4B40BF79E35E}\Category\Category\{534C48C1-0607-4098-A521-4FC899C73E90}
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\CTF\TIP\{8613E14C-D0C0-4161-AC0F-1DD2563286BC}\Category\Category\{534C48C1-0607-4098-A521-4FC899C73E90}
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\CTF\TIP\{A028AE76-01B1-46C2-99C4-ACD9858AE02F}\Category\Category\{534C48C1-0607-4098-A521-4FC899C73E90}
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\CTF\TIP\{AE6BE008-07FB-400D-8BEB-337A64F7051F}\Category\Category\{534C48C1-0607-4098-A521-4FC899C73E90}
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\CTF\TIP\{C1EE01F2-B3B6-4A6A-9DDD-E988C088EC82}\Category\Category\{534C48C1-0607-4098-A521-4FC899C73E90}
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\CTF\TIP\{DCBD6FA8-032F-11D3-B5B1-00C04FC324A1}\Category\Category\{534C48C1-0607-4098-A521-4FC899C73E90}
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\CTF\TIP\{E429B25A-E5D3-4D1F-9BE3-0C608477E3A1}\Category\Category\{534C48C1-0607-4098-A521-4FC899C73E90}
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\CTF\TIP\{F25E9F57-2FC8-4EB3-A41A-CCE5F08541E6}\Category\Category\{534C48C1-0607-4098-A521-4FC899C73E90}
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\CTF\TIP\{F89E9E58-BD2F-4008-9AC2-0F816C09F4EE}\Category\Category\{534C48C1-0607-4098-A521-4FC899C73E90}
  • HKEY_CURRENT_USER\Keyboard Layout\Toggle
  • HKEY_CURRENT_USER\Keyboard Layout\Toggle\Language Hotkey
  • HKEY_CURRENT_USER\Keyboard Layout\Toggle\Hotkey
  • HKEY_CURRENT_USER\Keyboard Layout\Toggle\Layout Hotkey
  • HKEY_CURRENT_USER\Software\Microsoft\CTF\DirectSwitchHotkeys
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\CTF\
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\CTF\EnableAnchorContext
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\CTF\KnownClasses
  • HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings
  • HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\CreateUriCacheSize
  • HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings
  • HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\CreateUriCacheSize
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\CreateUriCacheSize
  • HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Internet Settings
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Internet Settings\CreateUriCacheSize
  • HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\EnablePunycode
  • HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\EnablePunycode
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\EnablePunycode
  • HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_HTTP_USERNAME_PASSWORD_DISABLE
  • HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_HTTP_USERNAME_PASSWORD_DISABLE
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\MAIN\FeatureControl\FEATURE_HTTP_USERNAME_PASSWORD_DISABLE\Plants_Vs_Zombies_V1.0.0.1051_CN_V2.exe
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\MAIN\FeatureControl\FEATURE_HTTP_USERNAME_PASSWORD_DISABLE\*
  • HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Security_HKLM_only
  • HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Internet Explorer\Main\FeatureControl
  • HKEY_CURRENT_USER\Software\Policies\Microsoft\Internet Explorer\Main\FeatureControl
  • HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main\FeatureControl
  • HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main\FeatureControl
  • HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_ALLOW_REVERSE_SOLIDUS_IN_USERINFO_KB932562
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\MAIN\FeatureControl\FEATURE_ALLOW_REVERSE_SOLIDUS_IN_USERINFO_KB932562
  • HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main
  • HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main\FrameTabWindow
  • HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\MAIN\FrameTabWindow
  • HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main\FrameMerging
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\MAIN\FrameMerging
  • HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main\SessionMerging
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\MAIN\SessionMerging
  • HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main\AdminTabProcs
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\MAIN\AdminTabProcs
  • HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Internet Explorer\Main
  • HKEY_CURRENT_USER\Software\Policies\Microsoft\Internet Explorer\Main
  • HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main\TabProcGrowth
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\MAIN\TabProcGrowth
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\MAIN
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\MAIN\NavigationDelay
  • HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\NoPropertiesMyComputer
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\NoPropertiesMyComputer
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\NoPropertiesRecycleBin
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\NoPropertiesRecycleBin
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\NoControlPanel
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\NoControlPanel
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\NoSetFolders
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\NoSetFolders
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\NoInternetIcon
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\NoInternetIcon
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellCompatibility\Applications\Plants_Vs_Zombies_V1.0.0.1051_CN_V2.exe
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\NoCommonGroups
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\NoCommonGroups
  • HKEY_CLASSES_ROOT\CLSID\{871C5380-42A0-1069-A2EA-08002B30309D}\ShellFolder
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{871C5380-42A0-1069-A2EA-08002B30309D}\ShellFolder\Attributes
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{871C5380-42A0-1069-A2EA-08002B30309D}\ShellFolder\CallForAttributes
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{871C5380-42A0-1069-A2EA-08002B30309D}\ShellFolder\RestrictedAttributes
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{871C5380-42A0-1069-A2EA-08002B30309D}\ShellFolder\WantsFORDISPLAY
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{871C5380-42A0-1069-A2EA-08002B30309D}\ShellFolder\HideFolderVerbs
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{871C5380-42A0-1069-A2EA-08002B30309D}\ShellFolder\UseDropHandler
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{871C5380-42A0-1069-A2EA-08002B30309D}\ShellFolder\WantsFORPARSING
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{871C5380-42A0-1069-A2EA-08002B30309D}\ShellFolder\WantsParseDisplayName
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{871C5380-42A0-1069-A2EA-08002B30309D}\ShellFolder\QueryForOverlay
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{871C5380-42A0-1069-A2EA-08002B30309D}\ShellFolder\MapNetDriveVerbs
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{871C5380-42A0-1069-A2EA-08002B30309D}\ShellFolder\QueryForInfoTip
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{871C5380-42A0-1069-A2EA-08002B30309D}\ShellFolder\HideInWebView
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{871C5380-42A0-1069-A2EA-08002B30309D}\ShellFolder\HideOnDesktopPerUser
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{871C5380-42A0-1069-A2EA-08002B30309D}\ShellFolder\WantsAliasedNotifications
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{871C5380-42A0-1069-A2EA-08002B30309D}\ShellFolder\WantsUniversalDelegate
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{871C5380-42A0-1069-A2EA-08002B30309D}\ShellFolder\NoFileFolderJunction
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{871C5380-42A0-1069-A2EA-08002B30309D}\ShellFolder\PinToNameSpaceTree
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{871C5380-42A0-1069-A2EA-08002B30309D}\ShellFolder\HasNavigationEnum
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\CLSID\{871C5380-42A0-1069-A2EA-08002B30309D}\ShellFolder
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\CLSID\{871C5380-42A0-1069-A2EA-08002B30309D}\ShellFolder\Attributes
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\NonEnum
  • HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\NonEnum
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\NonEnum\{871C5380-42A0-1069-A2EA-08002B30309D}
  • HKEY_CLASSES_ROOT\CLSID\{871C5380-42A0-1069-A2EA-08002B30309D}\InProcServer32
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{871C5380-42A0-1069-A2EA-08002B30309D}\InProcServer32\(Default)
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{871C5380-42A0-1069-A2EA-08002B30309D}\InProcServer32\LoadWithoutCOM
  • HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Blocked
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Blocked
  • HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\SafeBoot\Option
  • HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\Session Manager\AppCompatibility
  • HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows\AppCompat
  • HKEY_LOCAL_MACHINE\Software\Classes\CLSID\{871c5380-42a0-1069-a2ea-08002b30309d}\InProcServer32
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Cached
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Cached\{871C5380-42A0-1069-A2EA-08002B30309D} {000214E6-0000-0000-C000-000000000046} 0xFFFF
  • HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\SQMClient\Windows
  • HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\SQMClient\Windows\CEIPEnable
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellCompatibility\Objects\{871C5380-42A0-1069-A2EA-08002B30309D}
  • HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_IEDDE_REGISTER_PROTOCOL
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\MAIN\FeatureControl\FEATURE_IEDDE_REGISTER_PROTOCOL
  • HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Internet Explorer\BrowserEmulation
  • HKEY_CURRENT_USER\Software\Policies\Microsoft\Internet Explorer\BrowserEmulation
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\NoFileMenu
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\NoFileMenu
  • HKEY_CLASSES_ROOT\PROTOCOLS\Name-Space Handler\
  • HKEY_CLASSES_ROOT\PROTOCOLS\Name-Space Handler\about\
  • HKEY_CLASSES_ROOT\PROTOCOLS\Name-Space Handler\*\
  • HKEY_CURRENT_USER\SOFTWARE\Classes\PROTOCOLS\Handler\about
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\PROTOCOLS\Handler\about
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\PROTOCOLS\Handler\about\CLSID
  • HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\MediaTypeClass
  • HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Accepted Documents
  • HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\Ratings
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Ratings\Key
  • HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_SHOW_FAILED_CONNECT_CONTENT_KB942615
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\MAIN\FeatureControl\FEATURE_SHOW_FAILED_CONNECT_CONTENT_KB942615
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\UrlEncoding
  • HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\
  • HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_IGNORE_POLICIES_ZONEMAP_IF_ESC_ENABLED_KB918915
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\MAIN\FeatureControl\FEATURE_IGNORE_POLICIES_ZONEMAP_IF_ESC_ENABLED_KB918915
  • HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\
  • HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\
  • HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Ranges\
  • HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Ranges\
  • HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_UNC_SAVEDFILECHECK
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\MAIN\FeatureControl\FEATURE_UNC_SAVEDFILECHECK
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\MAIN\FeatureControl\FEATURE_UNC_SAVEDFILECHECK\Plants_Vs_Zombies_V1.0.0.1051_CN_V2.exe
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\MAIN\FeatureControl\FEATURE_UNC_SAVEDFILECHECK\*
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\
  • HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_ZONES_CHECK_ZONEMAP_POLICY_KB941001
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\MAIN\FeatureControl\FEATURE_ZONES_CHECK_ZONEMAP_POLICY_KB941001
  • HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
  • HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Ranges\
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\ProtocolDefaults\
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\alipay.com
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\alisoft.com
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\taobao.com
  • HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_USE_IETLDLIST_FOR_DOMAIN_DETERMINATION
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\MAIN\FeatureControl\FEATURE_USE_IETLDLIST_FOR_DOMAIN_DETERMINATION
  • HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\LSA\AccessProviders
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Lsa\AccessProviders\MartaExtension
  • HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\IETld
  • HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\IETld\IETldDllVersionLow
  • HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\IETld\IETldDllVersionHigh
  • HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\IETld\IETldVersionLow
  • HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\IETld\IETldVersionHigh
  • HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\
  • HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Internet Explorer
  • HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Internet Explorer\Security
  • HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Internet Explorer\Security\DisableSecuritySettingsCheck
  • HKEY_LOCAL_MACHINE\System\Setup
  • HKEY_LOCAL_MACHINE\SYSTEM\Setup\SystemSetupInProgress
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\0
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\1
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\2
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\3
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\4
  • HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\
  • HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\
  • HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\0
  • HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\0
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\0\Flags
  • HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\1
  • HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\1
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\1\Flags
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\ProxyBypass
  • HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\ProxyBypass
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\IntranetName
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\IntranetName
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\UNCAsIntranet
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\AutoDetect
  • HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\2
  • HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\2
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\2\Flags
  • HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\3
  • HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\3
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\3\Flags
  • HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\4
  • HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\4
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\4\Flags
  • HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_LOCALMACHINE_LOCKDOWN
  • HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_LOCALMACHINE_LOCKDOWN\Plants_Vs_Zombies_V1.0.0.1051_CN_V2.exe
  • HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_LOCALMACHINE_LOCKDOWN\*
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\MAIN\FeatureControl\FEATURE_LOCALMACHINE_LOCKDOWN
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\MAIN\FeatureControl\FEATURE_LOCALMACHINE_LOCKDOWN\Plants_Vs_Zombies_V1.0.0.1051_CN_V2.exe
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\MAIN\FeatureControl\FEATURE_LOCALMACHINE_LOCKDOWN\*
  • HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Lockdown_Zones\
  • HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Lockdown_Zones\
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Lockdown_Zones\
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Lockdown_Zones\0
  • HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Lockdown_Zones\0
  • HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Lockdown_Zones\0
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Lockdown_Zones\1
  • HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Lockdown_Zones\1
  • HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Lockdown_Zones\1
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Lockdown_Zones\2
  • HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Lockdown_Zones\2
  • HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Lockdown_Zones\2
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Lockdown_Zones\3
  • HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Lockdown_Zones\3
  • HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Lockdown_Zones\3
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Lockdown_Zones\4
  • HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Lockdown_Zones\4
  • HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Lockdown_Zones\4
  • HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer
  • HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\No3DBorder
  • HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\No3DBorder
  • HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\UrlEncoding
  • HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\UrlEncoding
  • HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_MIME_HANDLING
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\MAIN\FeatureControl\FEATURE_MIME_HANDLING
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\MAIN\FeatureControl\FEATURE_MIME_HANDLING\Plants_Vs_Zombies_V1.0.0.1051_CN_V2.exe
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\MAIN\FeatureControl\FEATURE_MIME_HANDLING\*
  • HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_RESTRICT_ABOUT_PROTOCOL_IE7
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\MAIN\FeatureControl\FEATURE_RESTRICT_ABOUT_PROTOCOL_IE7
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\MAIN\FeatureControl\FEATURE_RESTRICT_ABOUT_PROTOCOL_IE7\Plants_Vs_Zombies_V1.0.0.1051_CN_V2.exe
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\MAIN\FeatureControl\FEATURE_RESTRICT_ABOUT_PROTOCOL_IE7\*
  • HKEY_CURRENT_USER\SOFTWARE\Classes\PROTOCOLS\Filter\text/html
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\PROTOCOLS\Filter\text/html
  • HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_MIME_SNIFFING
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\MAIN\FeatureControl\FEATURE_MIME_SNIFFING
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\MAIN\FeatureControl\FEATURE_MIME_SNIFFING\Plants_Vs_Zombies_V1.0.0.1051_CN_V2.exe
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\MAIN\FeatureControl\FEATURE_MIME_SNIFFING\*
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\IsTextPlainHonored
  • HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_FEEDS
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\MAIN\FeatureControl\FEATURE_FEEDS
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\MAIN\FeatureControl\FEATURE_FEEDS\Plants_Vs_Zombies_V1.0.0.1051_CN_V2.exe
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\MAIN\FeatureControl\FEATURE_FEEDS\*
  • HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main\FeatureControl\Feature_Enable_Compat_Logging
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\MAIN\FeatureControl\Feature_Enable_Compat_Logging
  • HKEY_CLASSES_ROOT\MIME\Database\Content Type\text/html
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ProxyEnable
  • HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_SAFE_BINDTOOBJECT
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\MAIN\FeatureControl\FEATURE_SAFE_BINDTOOBJECT
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\MAIN\FeatureControl\FEATURE_SAFE_BINDTOOBJECT\Plants_Vs_Zombies_V1.0.0.1051_CN_V2.exe
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\MAIN\FeatureControl\FEATURE_SAFE_BINDTOOBJECT\*
  • HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows\DragScrollInset
  • HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows\DragScrollDelay
  • HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows\DragScrollInterval
  • HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_MANAGE_SCRIPT_CIRCULAR_REFS
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\MAIN\FeatureControl\FEATURE_MANAGE_SCRIPT_CIRCULAR_REFS
  • HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_RESTRICT_FILEDOWNLOAD
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\MAIN\FeatureControl\FEATURE_RESTRICT_FILEDOWNLOAD
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\MAIN\FeatureControl\FEATURE_RESTRICT_FILEDOWNLOAD\Plants_Vs_Zombies_V1.0.0.1051_CN_V2.exe
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\MAIN\FeatureControl\FEATURE_RESTRICT_FILEDOWNLOAD\*
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Security\Floppy Access
  • HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Security\Adv AddrBar Spoof Detection
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Security\Adv AddrBar Spoof Detection
  • HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_DOCUMENT_COMPATIBLE_MODE
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\MAIN\FeatureControl\FEATURE_DOCUMENT_COMPATIBLE_MODE
  • HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_PROTOCOL_LOCKDOWN
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\MAIN\FeatureControl\FEATURE_PROTOCOL_LOCKDOWN
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\MAIN\FeatureControl\FEATURE_PROTOCOL_LOCKDOWN\Plants_Vs_Zombies_V1.0.0.1051_CN_V2.exe
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\MAIN\FeatureControl\FEATURE_PROTOCOL_LOCKDOWN\*
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\3\2106
  • HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Internet Explorer\Zoom
  • HKEY_CURRENT_USER\Software\Policies\Microsoft\Internet Explorer\Zoom
  • HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Zoom
  • HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Zoom\ZoomDisabled
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Zoom
  • HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_WEBOC_DOCUMENT_ZOOM
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\MAIN\FeatureControl\FEATURE_WEBOC_DOCUMENT_ZOOM
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\AboutURLs
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\AboutURLs\blank
  • HKEY_CLASSES_ROOT\PROTOCOLS\Name-Space Handler\res\
  • HKEY_CURRENT_USER\SOFTWARE\Classes\PROTOCOLS\Handler\res
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\PROTOCOLS\Handler\res
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\PROTOCOLS\Handler\res\CLSID
  • HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_IPERSISTMONIKER_LOAD_REDIRECTED_URL_KB976425
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\MAIN\FeatureControl\FEATURE_IPERSISTMONIKER_LOAD_REDIRECTED_URL_KB976425
  • HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Internet Explorer\SmartDithering
  • HKEY_CURRENT_USER\Software\Policies\Microsoft\Internet Explorer
  • HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SmartDithering
  • HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\RtfConverterFlags
  • HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main\UseClearType
  • HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main\Page_Transitions
  • HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main\Use_DlgBox_Colors
  • HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main\Anchor Underline
  • HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main\CSS_Compat
  • HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main\Expand Alt Text
  • HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main\Display Inline Images
  • HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main\Display Inline Videos
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\MAIN\Display Inline Videos
  • HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main\Play_Background_Sounds
  • HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main\Play_Animations
  • HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main\Print_Background
  • HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main\Use Stylesheets
  • HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main\SmoothScroll
  • HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main\XMLHTTP
  • HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main\Show image placeholders
  • HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main\Disable Script Debugger
  • HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main\DisableScriptDebuggerIE
  • HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main\Move System Caret
  • HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main\Force Offscreen Composition
  • HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main\Enable AutoImageResize
  • HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main\UseThemes
  • HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main\UseHR
  • HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main\Q300829
  • HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main\Cleanup HTCs
  • HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main\XDomainRequest
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\MAIN\XDomainRequest
  • HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main\DOMStorage
  • HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\International
  • HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\International\Default_CodePage
  • HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\International\AutoDetect
  • HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Internet Explorer\International\Scripts
  • HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\International\Scripts
  • HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\International\Scripts\Default_IEFontSizePrivate
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\International\Scripts
  • HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Internet Explorer\Settings
  • HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Settings
  • HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Settings\Anchor Color
  • HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Settings\Anchor Color Visited
  • HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Settings\Anchor Color Hover
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Settings
  • HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Settings\Always Use My Colors
  • HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Settings\Always Use My Font Size
  • HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Settings\Always Use My Font Face
  • HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Settings\Disable Visited Hyperlinks
  • HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Settings\Use Anchor Hover Color
  • HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Settings\MiscFlags
  • HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Styles
  • HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Styles\Use My Stylesheet
  • HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Styles\MaxScriptStatements
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\ActiveDesktop
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Allow Programmatic Cut_Copy_Paste
  • HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\DisableCachingOfSSLPages
  • HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\DisableCachingOfSSLPages
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\DisableCachingOfSSLPages
  • HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\PageSetup
  • HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\PageSetup\Print_Background
  • HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\MenuExt
  • HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\MenuExt\\xe5\x8f\x91\xe9\x80\x81\xe8\x87\xb3 OneNote(&N)
  • HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\MenuExt\\xe5\x8f\x91\xe9\x80\x81\xe8\x87\xb3 OneNote(&N)\(Default)
  • HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\MenuExt\\xe5\x8f\x91\xe9\x80\x81\xe8\x87\xb3 OneNote(&N)\Flags
  • HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\MenuExt\\xe5\x8f\x91\xe9\x80\x81\xe8\x87\xb3 OneNote(&N)\Contexts
  • HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\MenuExt\\xe5\xaf\xbc\xe5\x87\xba\xe5\x88\xb0 Microsoft Excel(&X)
  • HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\MenuExt\\xe5\xaf\xbc\xe5\x87\xba\xe5\x88\xb0 Microsoft Excel(&X)\(Default)
  • HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\MenuExt\\xe5\xaf\xbc\xe5\x87\xba\xe5\x88\xb0 Microsoft Excel(&X)\Flags
  • HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\MenuExt\\xe5\xaf\xbc\xe5\x87\xba\xe5\x88\xb0 Microsoft Excel(&X)\Contexts
  • HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Nls\CodePage
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CodePage\950
  • HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\International\Scripts\3
  • HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\International\Scripts\3\IEFontSize
  • HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\International\Scripts\3\IEFontSizePrivate
  • HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\International\Scripts\3\IEPropFontName
  • HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\International\Scripts\3\IEFixedFontName
  • HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\International\AcceptLanguage
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\TravelLog
  • HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\TravelLog
  • HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Version Vector
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Version Vector\VML
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Version Vector\IE
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Version Vector\WindowsEdition
  • HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_ZONE_ELEVATION
  • HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_ZONE_ELEVATION
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\MAIN\FeatureControl\FEATURE_ZONE_ELEVATION\Plants_Vs_Zombies_V1.0.0.1051_CN_V2.exe
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\MAIN\FeatureControl\FEATURE_ZONE_ELEVATION\*
  • HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_SSLUX
  • HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_SSLUX
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\MAIN\FeatureControl\FEATURE_SSLUX\Plants_Vs_Zombies_V1.0.0.1051_CN_V2.exe
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\MAIN\FeatureControl\FEATURE_SSLUX\*
  • HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_BROWSER_EMULATION
  • HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_BROWSER_EMULATION\Plants_Vs_Zombies_V1.0.0.1051_CN_V2.exe
  • HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_BROWSER_EMULATION\*
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\MAIN\FeatureControl\FEATURE_BROWSER_EMULATION
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\MAIN\FeatureControl\FEATURE_BROWSER_EMULATION\Plants_Vs_Zombies_V1.0.0.1051_CN_V2.exe
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\MAIN\FeatureControl\FEATURE_BROWSER_EMULATION\*
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\3\2700
  • HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_XSSFILTER
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\MAIN\FeatureControl\FEATURE_XSSFILTER
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\MAIN\FeatureControl\FEATURE_XSSFILTER\Plants_Vs_Zombies_V1.0.0.1051_CN_V2.exe
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\MAIN\FeatureControl\FEATURE_XSSFILTER\*
  • HKEY_CURRENT_USER\Software\Microsoft\windows\CurrentVersion\Internet Settings\Zones
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\SecuritySafe
  • HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main\NoProtectedModeBanner
  • HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_ADDITIONAL_IE8_MEMORY_CLEANUP
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\MAIN\FeatureControl\FEATURE_ADDITIONAL_IE8_MEMORY_CLEANUP
  • HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_MIME_TREAT_IMAGE_AS_AUTHORITATIVE
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\MAIN\FeatureControl\FEATURE_MIME_TREAT_IMAGE_AS_AUTHORITATIVE
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\FontLink\SystemLink
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\DataStore_V1.0
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\DataStore_V1.0\Disable
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\DataStore_V1.0\DataFilePath
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Plane1
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Plane2
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Plane3
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Plane4
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Plane5
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Plane6
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Plane7
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Plane8
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Plane9
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Plane10
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Plane11
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Plane12
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Plane13
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Plane14
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Plane15
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Plane16
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\SimSun
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\SimSun\Plane1
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\SimSun\Plane2
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\SimSun\Plane3
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\SimSun\Plane4
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\SimSun\Plane5
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\SimSun\Plane6
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\SimSun\Plane7
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\SimSun\Plane8
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\SimSun\Plane9
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\SimSun\Plane10
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\SimSun\Plane11
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\SimSun\Plane12
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\SimSun\Plane13
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\SimSun\Plane14
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\SimSun\Plane15
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\SimSun\Plane16
  • HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_MSHTML_AUTOLOAD_IEFRAME
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\MAIN\FeatureControl\FEATURE_MSHTML_AUTOLOAD_IEFRAME
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\MAIN\FeatureControl\FEATURE_MSHTML_AUTOLOAD_IEFRAME\Plants_Vs_Zombies_V1.0.0.1051_CN_V2.exe
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\MAIN\FeatureControl\FEATURE_MSHTML_AUTOLOAD_IEFRAME\*
  • HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Internet Explorer\DxTrans
  • HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\DxTrans
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\DxTrans
  • HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\CoInternetCombineIUriCacheSize
  • HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\CoInternetCombineIUriCacheSize
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\CoInternetCombineIUriCacheSize
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Internet Settings\CoInternetCombineIUriCacheSize
  • HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_SHIM_MSHELP_COMBINE
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\MAIN\FeatureControl\FEATURE_SHIM_MSHELP_COMBINE
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\MAIN\FeatureControl\FEATURE_SHIM_MSHELP_COMBINE\Plants_Vs_Zombies_V1.0.0.1051_CN_V2.exe
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\MAIN\FeatureControl\FEATURE_SHIM_MSHELP_COMBINE\*
  • HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\WarnOnIntranet
  • HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\
  • HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\WarnOnIntranet
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\WarnOnIntranet
  • HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\
  • HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\
  • HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Internet Explorer\Restrictions
  • HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Internet Explorer\Restrictions\NoNavButtons
  • HKEY_CURRENT_USER\Software\Policies\Microsoft\Internet Explorer\Restrictions
  • HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\Nls\Codepage
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CodePage\1250
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CodePage\1251
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CodePage\1253
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CodePage\1254
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CodePage\1255
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CodePage\1256
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CodePage\1257
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CodePage\1258
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CodePage\874
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CodePage\932
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CodePage\949
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CodePage\1361
  • HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\International\Scripts\26
  • HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\International\Scripts\26\IEFontSize
  • HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\International\Scripts\26\IEFontSizePrivate
  • HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\International\Scripts\26\IEPropFontName
  • HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\International\Scripts\26\IEFixedFontName
  • HKEY_CURRENT_USER\Software\Policies\Microsoft\Internet Explorer\Control Panel
  • HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Url History
  • HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Url History
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Url History
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Internet Settings\Url History
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Internet Settings\Url History\DaysToKeep
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache
  • HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_IEDDE_REGISTER_URLECHO
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\MAIN\FeatureControl\FEATURE_IEDDE_REGISTER_URLECHO
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\3\2000
  • HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Feed Discovery
  • HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Feed Discovery
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Feed Discovery\Sound
  • HKEY_CURRENT_USER\Software\Microsoft\Ftp
  • HKEY_CURRENT_USER\Software\Microsoft\FTP\Use Web Based FTP
  • HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Internet Explorer\Services
  • HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Services
  • HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Services\SelectionActivityButtonDisable
  • HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Internet Explorer\Activities
  • HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Activities
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Activities
  • HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Internet Explorer\Infodelivery\Restrictions
  • HKEY_CURRENT_USER\Software\Policies\Microsoft\Internet Explorer\Infodelivery\Restrictions
  • HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Internet Explorer\Suggested Sites
  • HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Suggested Sites
  • HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Suggested Sites\Enabled
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\CTF\TIP\{0000897b-83df-4b96-be07-0fb58b01c4a4}\Category\Item\{A48FA74E-F767-44E4-BFBC-169E8B38FF58}
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\CTF\TIP\{03B5835F-F03C-411B-9CE2-AA23E1171E36}\Category\Item\{A48FA74E-F767-44E4-BFBC-169E8B38FF58}
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\CTF\TIP\{07EB03D6-B001-41DF-9192-BF9B841EE71F}\Category\Item\{A48FA74E-F767-44E4-BFBC-169E8B38FF58}
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\CTF\TIP\{3697C5FA-60DD-4B56-92D4-74A569205C16}\Category\Item\{A48FA74E-F767-44E4-BFBC-169E8B38FF58}
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\CTF\TIP\{3FC47A08-E5C9-4BCA-A2C7-BC9A282AED14}\Category\Item\{A48FA74E-F767-44E4-BFBC-169E8B38FF58}
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\CTF\TIP\{531FDEBF-9B4C-4A43-A2AA-960E8FCDC732}\Category\Item\{A48FA74E-F767-44E4-BFBC-169E8B38FF58}
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\CTF\TIP\{78CB5B0E-26ED-4FCC-854C-77E8F3D1AA80}\Category\Item\{A48FA74E-F767-44E4-BFBC-169E8B38FF58}
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\CTF\TIP\{81D4E9C9-1D3B-41BC-9E6C-4B40BF79E35E}\Category\Item\{A48FA74E-F767-44E4-BFBC-169E8B38FF58}
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\CTF\TIP\{8613E14C-D0C0-4161-AC0F-1DD2563286BC}\Category\Item\{A48FA74E-F767-44E4-BFBC-169E8B38FF58}
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\CTF\TIP\{A028AE76-01B1-46C2-99C4-ACD9858AE02F}\Category\Item\{A48FA74E-F767-44E4-BFBC-169E8B38FF58}
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\CTF\TIP\{AE6BE008-07FB-400D-8BEB-337A64F7051F}\Category\Item\{A48FA74E-F767-44E4-BFBC-169E8B38FF58}
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\CTF\TIP\{C1EE01F2-B3B6-4A6A-9DDD-E988C088EC82}\Category\Item\{A48FA74E-F767-44E4-BFBC-169E8B38FF58}
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\CTF\TIP\{DCBD6FA8-032F-11D3-B5B1-00C04FC324A1}\Category\Item\{A48FA74E-F767-44E4-BFBC-169E8B38FF58}
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\CTF\TIP\{E429B25A-E5D3-4D1F-9BE3-0C608477E3A1}\Category\Item\{A48FA74E-F767-44E4-BFBC-169E8B38FF58}
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\CTF\TIP\{F25E9F57-2FC8-4EB3-A41A-CCE5F08541E6}\Category\Item\{A48FA74E-F767-44E4-BFBC-169E8B38FF58}
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\CTF\TIP\{F89E9E58-BD2F-4008-9AC2-0F816C09F4EE}\Category\Item\{A48FA74E-F767-44E4-BFBC-169E8B38FF58}
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\MAIN\MaxRenderLine
  • HKEY_CURRENT_USER\Software\Microsoft\CTF\LayoutIcon\0804\00000804
  • HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_SKIP_LEAK_CLEANUP_AT_SHUTDOWN_KB835183
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\MAIN\FeatureControl\FEATURE_SKIP_LEAK_CLEANUP_AT_SHUTDOWN_KB835183
读取的注册表键
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\Locale\00000804
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\Language Groups\a
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\en-US
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\ExtendedLocale\en-US
  • HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows\ScrollInset
  • HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows\DragDelay
  • HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows\DragMinDist
  • HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows\ScrollDelay
  • HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows\ScrollInterval
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\AutoComplete\Append Completion
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\AutoComplete\AutoSuggest
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\AutoComplete\Always Use Tab
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\AutoComplete\Always Use Tab
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{03C036F1-A186-11D0-824A-00AA005B4383}\InProcServer32\(Default)
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{00BB2763-6A77-11D0-A535-00C04FD7D062}\InProcServer32\(Default)
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\AutoComplete\Client\(Default)
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\Windows Error Reporting\WMR\Disable
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Shell.Explorer\CLSID\(Default)
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\CTF\TIP\{0000897b-83df-4b96-be07-0fb58b01c4a4}\LanguageProfile\0x00000000\{0001bea3-ed56-483d-a2e2-aeae25577436}\Enable
  • HKEY_CURRENT_USER\Keyboard Layout\Toggle\Language Hotkey
  • HKEY_CURRENT_USER\Keyboard Layout\Toggle\Hotkey
  • HKEY_CURRENT_USER\Keyboard Layout\Toggle\Layout Hotkey
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\CTF\EnableAnchorContext
  • HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\CreateUriCacheSize
  • HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\CreateUriCacheSize
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\CreateUriCacheSize
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Internet Settings\CreateUriCacheSize
  • HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\EnablePunycode
  • HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\EnablePunycode
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\EnablePunycode
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\MAIN\FeatureControl\FEATURE_HTTP_USERNAME_PASSWORD_DISABLE\Plants_Vs_Zombies_V1.0.0.1051_CN_V2.exe
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\MAIN\FeatureControl\FEATURE_HTTP_USERNAME_PASSWORD_DISABLE\*
  • HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Security_HKLM_only
  • HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main\FrameTabWindow
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\MAIN\FrameTabWindow
  • HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main\FrameMerging
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\MAIN\FrameMerging
  • HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main\SessionMerging
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\MAIN\SessionMerging
  • HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main\AdminTabProcs
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\MAIN\AdminTabProcs
  • HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main\TabProcGrowth
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\MAIN\TabProcGrowth
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\MAIN\NavigationDelay
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\NoPropertiesMyComputer
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\NoPropertiesMyComputer
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\NoPropertiesRecycleBin
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\NoPropertiesRecycleBin
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\NoControlPanel
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\NoControlPanel
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\NoSetFolders
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\NoSetFolders
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\NoInternetIcon
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\NoInternetIcon
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\NoCommonGroups
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\NoCommonGroups
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{871C5380-42A0-1069-A2EA-08002B30309D}\ShellFolder\Attributes
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{871C5380-42A0-1069-A2EA-08002B30309D}\ShellFolder\CallForAttributes
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{871C5380-42A0-1069-A2EA-08002B30309D}\ShellFolder\RestrictedAttributes
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{871C5380-42A0-1069-A2EA-08002B30309D}\ShellFolder\WantsFORDISPLAY
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{871C5380-42A0-1069-A2EA-08002B30309D}\ShellFolder\HideFolderVerbs
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{871C5380-42A0-1069-A2EA-08002B30309D}\ShellFolder\UseDropHandler
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{871C5380-42A0-1069-A2EA-08002B30309D}\ShellFolder\WantsFORPARSING
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{871C5380-42A0-1069-A2EA-08002B30309D}\ShellFolder\WantsParseDisplayName
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{871C5380-42A0-1069-A2EA-08002B30309D}\ShellFolder\QueryForOverlay
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{871C5380-42A0-1069-A2EA-08002B30309D}\ShellFolder\MapNetDriveVerbs
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{871C5380-42A0-1069-A2EA-08002B30309D}\ShellFolder\QueryForInfoTip
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{871C5380-42A0-1069-A2EA-08002B30309D}\ShellFolder\HideInWebView
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{871C5380-42A0-1069-A2EA-08002B30309D}\ShellFolder\HideOnDesktopPerUser
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{871C5380-42A0-1069-A2EA-08002B30309D}\ShellFolder\WantsAliasedNotifications
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{871C5380-42A0-1069-A2EA-08002B30309D}\ShellFolder\WantsUniversalDelegate
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{871C5380-42A0-1069-A2EA-08002B30309D}\ShellFolder\NoFileFolderJunction
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{871C5380-42A0-1069-A2EA-08002B30309D}\ShellFolder\PinToNameSpaceTree
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{871C5380-42A0-1069-A2EA-08002B30309D}\ShellFolder\HasNavigationEnum
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\CLSID\{871C5380-42A0-1069-A2EA-08002B30309D}\ShellFolder\Attributes
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\NonEnum\{871C5380-42A0-1069-A2EA-08002B30309D}
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{871C5380-42A0-1069-A2EA-08002B30309D}\InProcServer32\(Default)
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{871C5380-42A0-1069-A2EA-08002B30309D}\InProcServer32\LoadWithoutCOM
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Cached\{871C5380-42A0-1069-A2EA-08002B30309D} {000214E6-0000-0000-C000-000000000046} 0xFFFF
  • HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\SQMClient\Windows\CEIPEnable
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\NoFileMenu
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\NoFileMenu
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\PROTOCOLS\Handler\about\CLSID
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Ratings\Key
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\UrlEncoding
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\MAIN\FeatureControl\FEATURE_UNC_SAVEDFILECHECK\Plants_Vs_Zombies_V1.0.0.1051_CN_V2.exe
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\MAIN\FeatureControl\FEATURE_UNC_SAVEDFILECHECK\*
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Lsa\AccessProviders\MartaExtension
  • HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\IETld\IETldDllVersionLow
  • HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\IETld\IETldDllVersionHigh
  • HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\IETld\IETldVersionLow
  • HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\IETld\IETldVersionHigh
  • HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Internet Explorer\Security\DisableSecuritySettingsCheck
  • HKEY_LOCAL_MACHINE\SYSTEM\Setup\SystemSetupInProgress
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\0\Flags
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\1\Flags
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\2\Flags
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\3\Flags
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\4\Flags
  • HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_LOCALMACHINE_LOCKDOWN\Plants_Vs_Zombies_V1.0.0.1051_CN_V2.exe
  • HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_LOCALMACHINE_LOCKDOWN\*
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\MAIN\FeatureControl\FEATURE_LOCALMACHINE_LOCKDOWN\Plants_Vs_Zombies_V1.0.0.1051_CN_V2.exe
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\MAIN\FeatureControl\FEATURE_LOCALMACHINE_LOCKDOWN\*
  • HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\No3DBorder
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\No3DBorder
  • HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\UrlEncoding
  • HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\UrlEncoding
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\MAIN\FeatureControl\FEATURE_MIME_HANDLING\Plants_Vs_Zombies_V1.0.0.1051_CN_V2.exe
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\MAIN\FeatureControl\FEATURE_MIME_HANDLING\*
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\MAIN\FeatureControl\FEATURE_RESTRICT_ABOUT_PROTOCOL_IE7\Plants_Vs_Zombies_V1.0.0.1051_CN_V2.exe
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\MAIN\FeatureControl\FEATURE_RESTRICT_ABOUT_PROTOCOL_IE7\*
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\MAIN\FeatureControl\FEATURE_MIME_SNIFFING\Plants_Vs_Zombies_V1.0.0.1051_CN_V2.exe
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\MAIN\FeatureControl\FEATURE_MIME_SNIFFING\*
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\IsTextPlainHonored
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\MAIN\FeatureControl\FEATURE_FEEDS\Plants_Vs_Zombies_V1.0.0.1051_CN_V2.exe
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\MAIN\FeatureControl\FEATURE_FEEDS\*
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ProxyEnable
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\MAIN\FeatureControl\FEATURE_SAFE_BINDTOOBJECT\Plants_Vs_Zombies_V1.0.0.1051_CN_V2.exe
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\MAIN\FeatureControl\FEATURE_SAFE_BINDTOOBJECT\*
  • HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows\DragScrollInset
  • HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows\DragScrollDelay
  • HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows\DragScrollInterval
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\MAIN\FeatureControl\FEATURE_RESTRICT_FILEDOWNLOAD\Plants_Vs_Zombies_V1.0.0.1051_CN_V2.exe
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\MAIN\FeatureControl\FEATURE_RESTRICT_FILEDOWNLOAD\*
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\MAIN\FeatureControl\FEATURE_PROTOCOL_LOCKDOWN\Plants_Vs_Zombies_V1.0.0.1051_CN_V2.exe
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\MAIN\FeatureControl\FEATURE_PROTOCOL_LOCKDOWN\*
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\3\2106
  • HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Zoom\ZoomDisabled
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\AboutURLs\blank
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\PROTOCOLS\Handler\res\CLSID
  • HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Internet Explorer\SmartDithering
  • HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SmartDithering
  • HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\RtfConverterFlags
  • HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main\UseClearType
  • HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main\Page_Transitions
  • HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main\Use_DlgBox_Colors
  • HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main\Anchor Underline
  • HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main\CSS_Compat
  • HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main\Expand Alt Text
  • HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main\Display Inline Images
  • HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main\Display Inline Videos
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\MAIN\Display Inline Videos
  • HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main\Play_Background_Sounds
  • HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main\Play_Animations
  • HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main\Print_Background
  • HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main\Use Stylesheets
  • HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main\SmoothScroll
  • HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main\XMLHTTP
  • HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main\Show image placeholders
  • HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main\Disable Script Debugger
  • HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main\DisableScriptDebuggerIE
  • HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main\Move System Caret
  • HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main\Force Offscreen Composition
  • HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main\Enable AutoImageResize
  • HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main\UseThemes
  • HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main\UseHR
  • HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main\Q300829
  • HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main\Cleanup HTCs
  • HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main\XDomainRequest
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\MAIN\XDomainRequest
  • HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main\DOMStorage
  • HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\International\Default_CodePage
  • HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\International\AutoDetect
  • HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\International\Scripts\Default_IEFontSizePrivate
  • HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Settings\Anchor Color
  • HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Settings\Anchor Color Visited
  • HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Settings\Anchor Color Hover
  • HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Settings\Always Use My Colors
  • HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Settings\Always Use My Font Size
  • HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Settings\Always Use My Font Face
  • HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Settings\Disable Visited Hyperlinks
  • HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Settings\Use Anchor Hover Color
  • HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Settings\MiscFlags
  • HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Styles\Use My Stylesheet
  • HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Styles\MaxScriptStatements
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Allow Programmatic Cut_Copy_Paste
  • HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\DisableCachingOfSSLPages
  • HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\DisableCachingOfSSLPages
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\DisableCachingOfSSLPages
  • HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\PageSetup\Print_Background
  • HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\MenuExt\\xe5\x8f\x91\xe9\x80\x81\xe8\x87\xb3 OneNote(&N)\(Default)
  • HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\MenuExt\\xe5\x8f\x91\xe9\x80\x81\xe8\x87\xb3 OneNote(&N)\Flags
  • HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\MenuExt\\xe5\x8f\x91\xe9\x80\x81\xe8\x87\xb3 OneNote(&N)\Contexts
  • HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\MenuExt\\xe5\xaf\xbc\xe5\x87\xba\xe5\x88\xb0 Microsoft Excel(&X)\(Default)
  • HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\MenuExt\\xe5\xaf\xbc\xe5\x87\xba\xe5\x88\xb0 Microsoft Excel(&X)\Flags
  • HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\MenuExt\\xe5\xaf\xbc\xe5\x87\xba\xe5\x88\xb0 Microsoft Excel(&X)\Contexts
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CodePage\950
  • HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\International\Scripts\3\IEFontSize
  • HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\International\Scripts\3\IEFontSizePrivate
  • HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\International\Scripts\3\IEPropFontName
  • HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\International\Scripts\3\IEFixedFontName
  • HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\International\AcceptLanguage
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Version Vector\VML
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Version Vector\IE
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Version Vector\WindowsEdition
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\MAIN\FeatureControl\FEATURE_ZONE_ELEVATION\Plants_Vs_Zombies_V1.0.0.1051_CN_V2.exe
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\MAIN\FeatureControl\FEATURE_ZONE_ELEVATION\*
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\MAIN\FeatureControl\FEATURE_SSLUX\Plants_Vs_Zombies_V1.0.0.1051_CN_V2.exe
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\MAIN\FeatureControl\FEATURE_SSLUX\*
  • HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_BROWSER_EMULATION\Plants_Vs_Zombies_V1.0.0.1051_CN_V2.exe
  • HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_BROWSER_EMULATION\*
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\MAIN\FeatureControl\FEATURE_BROWSER_EMULATION\Plants_Vs_Zombies_V1.0.0.1051_CN_V2.exe
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\MAIN\FeatureControl\FEATURE_BROWSER_EMULATION\*
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\3\2700
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\MAIN\FeatureControl\FEATURE_XSSFILTER\Plants_Vs_Zombies_V1.0.0.1051_CN_V2.exe
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\MAIN\FeatureControl\FEATURE_XSSFILTER\*
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\SecuritySafe
  • HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main\NoProtectedModeBanner
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\DataStore_V1.0\Disable
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\DataStore_V1.0\DataFilePath
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Plane1
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Plane2
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Plane3
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Plane4
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Plane5
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Plane6
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Plane7
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Plane8
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Plane9
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Plane10
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Plane11
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Plane12
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Plane13
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Plane14
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Plane15
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Plane16
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\SimSun\Plane1
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\SimSun\Plane2
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\SimSun\Plane3
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\SimSun\Plane4
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\SimSun\Plane5
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\SimSun\Plane6
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\SimSun\Plane7
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\SimSun\Plane8
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\SimSun\Plane9
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\SimSun\Plane10
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\SimSun\Plane11
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\SimSun\Plane12
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\SimSun\Plane13
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\SimSun\Plane14
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\SimSun\Plane15
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\SimSun\Plane16
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\MAIN\FeatureControl\FEATURE_MSHTML_AUTOLOAD_IEFRAME\Plants_Vs_Zombies_V1.0.0.1051_CN_V2.exe
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\MAIN\FeatureControl\FEATURE_MSHTML_AUTOLOAD_IEFRAME\*
  • HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\CoInternetCombineIUriCacheSize
  • HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\CoInternetCombineIUriCacheSize
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\CoInternetCombineIUriCacheSize
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Internet Settings\CoInternetCombineIUriCacheSize
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\MAIN\FeatureControl\FEATURE_SHIM_MSHELP_COMBINE\Plants_Vs_Zombies_V1.0.0.1051_CN_V2.exe
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\MAIN\FeatureControl\FEATURE_SHIM_MSHELP_COMBINE\*
  • HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\WarnOnIntranet
  • HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\WarnOnIntranet
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\WarnOnIntranet
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\AutoDetect
  • HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Internet Explorer\Restrictions\NoNavButtons
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CodePage\1250
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CodePage\1251
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CodePage\1253
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CodePage\1254
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CodePage\1255
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CodePage\1256
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CodePage\1257
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CodePage\1258
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CodePage\874
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CodePage\932
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CodePage\949
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CodePage\1361
  • HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\International\Scripts\26\IEFontSize
  • HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\International\Scripts\26\IEFontSizePrivate
  • HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\International\Scripts\26\IEPropFontName
  • HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\International\Scripts\26\IEFixedFontName
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Internet Settings\Url History\DaysToKeep
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\3\2000
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Feed Discovery\Sound
  • HKEY_CURRENT_USER\Software\Microsoft\FTP\Use Web Based FTP
  • HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Services\SelectionActivityButtonDisable
  • HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Suggested Sites\Enabled
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\MAIN\MaxRenderLine
修改的注册表键
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\UNCAsIntranet
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\AutoDetect
删除的注册表键
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\ProxyBypass
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\ProxyBypass
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\IntranetName
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\IntranetName
API解析
  • cryptbase.dll.SystemFunction036
  • comctl32.dll.InitCommonControlsEx
  • ole32.dll.CoGetMalloc
  • comctl32.dll.RegisterClassNameW
  • uxtheme.dll.EnableThemeDialogTexture
  • uxtheme.dll.OpenThemeData
  • uxtheme.dll.SetWindowTheme
  • imm32.dll.ImmIsIME
  • shlwapi.dll.SHAutoComplete
  • ole32.dll.CoCreateInstance
  • comctl32.dll.#320
  • comctl32.dll.#324
  • comctl32.dll.#411
  • comctl32.dll.#410
  • ole32.dll.CLSIDFromString
  • urlmon.dll.#414
  • ole32.dll.CoInitializeEx
  • ole32.dll.CoUninitialize
  • ole32.dll.CoRegisterInitializeSpy
  • ole32.dll.CoRevokeInitializeSpy
  • urlmon.dll.CreateUri
  • kernel32.dll.InitializeSRWLock
  • kernel32.dll.AcquireSRWLockExclusive
  • kernel32.dll.AcquireSRWLockShared
  • kernel32.dll.ReleaseSRWLockExclusive
  • kernel32.dll.ReleaseSRWLockShared
  • ole32.dll.CoTaskMemAlloc
  • ole32.dll.CoGetApartmentType
  • ole32.dll.CoTaskMemFree
  • comctl32.dll.#236
  • oleaut32.dll.#6
  • ole32.dll.StringFromGUID2
  • comctl32.dll.#323
  • apphelp.dll.ApphelpCheckShellObject
  • urlmon.dll.CreateURLMonikerEx
  • urlmon.dll.CreateAsyncBindCtxEx
  • urlmon.dll.RegisterBindStatusCallback
  • urlmon.dll.CreateFormatEnumerator
  • wininet.dll.InternetGetConnectedState
  • rasapi32.dll.RasConnectionNotificationW
  • sechost.dll.NotifyServiceStatusChangeA
  • urlmon.dll.UrlMkGetSessionOption
  • urlmon.dll.CoInternetCreateSecurityManager
  • advapi32.dll.AddMandatoryAce
  • ntmarta.dll.GetMartaExtensionInterface
  • version.dll.GetFileVersionInfoSizeW
  • version.dll.GetFileVersionInfoW
  • version.dll.VerQueryValueW
  • oleaut32.dll.#201
  • urlmon.dll.CoInternetQueryInfo
  • oleaut32.dll.#7
  • urlmon.dll.CoInternetIsFeatureEnabled
  • iphlpapi.dll.GetAdaptersAddresses
  • oleaut32.dll.#8
  • ieframe.dll.#302
  • urlmon.dll.RegisterFormatEnumerator
  • urlmon.dll.RevokeBindStatusCallback
  • urlmon.dll.#101
  • ieframe.dll.#234
  • comctl32.dll.#413
  • imm32.dll.ImmGetContext
  • imm32.dll.ImmLockIMC
  • imm32.dll.ImmUnlockIMC
  • imm32.dll.ImmReleaseContext
  • imm32.dll.ImmSetCompositionFontW
  • gdi32.dll.GetLayout
  • gdi32.dll.GdiRealizationInfo
  • gdi32.dll.FontIsLinked
  • advapi32.dll.RegOpenKeyExW
  • advapi32.dll.RegQueryInfoKeyW
  • gdi32.dll.GetTextFaceAliasW
  • advapi32.dll.RegEnumValueW
  • advapi32.dll.RegCloseKey
  • advapi32.dll.RegQueryValueExW
  • advapi32.dll.RegQueryValueExA
  • advapi32.dll.RegEnumKeyExW
  • gdi32.dll.GetTextExtentExPointWPri
  • imm32.dll.ImmGetCompositionWindow
  • imm32.dll.ImmSetCompositionWindow
  • gdi32.dll.GetFontAssocStatus
  • gdi32.dll.GdiIsMetaPrintDC
  • uxtheme.dll.BufferedPaintInit
  • uxtheme.dll.BufferedPaintRenderAnimation
  • uxtheme.dll.BeginBufferedAnimation
  • uxtheme.dll.EndBufferedAnimation
  • uxtheme.dll.BeginBufferedPaint
  • oleaut32.dll.#2
  • oleaut32.dll.VariantClear
  • kernel32.dll.GetThreadUILanguage
  • mlang.dll.#112
  • wininet.dll.GetUrlCacheEntryInfoA
  • oleaut32.dll.#147
  • oleaut32.dll.#4
  • comctl32.dll.ImageList_Create
  • comctl32.dll.ImageList_ReplaceIcon
  • urlmon.dll.#330
  • wininet.dll.GetUrlCacheEntryInfoExW
  • msimtf.dll.MsimtfIsWindowFiltered
  • imm32.dll.ImmNotifyIME
  • uxtheme.dll.EndBufferedPaint
  • uxtheme.dll.IsAppThemed
  • oleaut32.dll.SysAllocString
  • oleaut32.dll.SysStringLen
  • oleaut32.dll.SysFreeString
  • imm32.dll.ImmGetDefaultIMEWnd
  • comctl32.dll.ImageList_Destroy
  • comctl32.dll.#412
  • comctl32.dll.#388
  • uxtheme.dll.BufferedPaintUnInit
  • uxtheme.dll.BufferedPaintStopAllAnimations
  • rpcrt4.dll.RpcBindingFree
  • comctl32.dll.#321