General Info

File name

ph_exec.exe

Full analysis
https://app.any.run/tasks/57eb67e4-a401-484b-a452-06864c8de4fe
Verdict
Malicious activity
Analysis date
8/13/2019, 16:05:26
OS:
Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Tags:

ransomware

Indicators:

MIME:
application/x-dosexec
File info:
PE32 executable (GUI) Intel 80386, for MS Windows
MD5

d52eea7435d25e92e86047ba97890d0a

SHA1

9202a17cf9fdfabd21c42f54d13c79d74efd7e58

SHA256

f6b7a8b51983af246a3bdd70af8b15944000c932d981d8c9d77960aef7048abe

SSDEEP

768:1gZRUSqFU+qJck+fO+lJ8f9ICGjI4t1hg0v861NR/uWiuKBUnLX0WS43+zc7METw:+RvoU+XfE9ICf4t1OwruWiyX09NzcAk

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distored by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.

Software environment set and analysis options

Launch configuration

Task duration
180 seconds
Additional time used
120 seconds
Fakenet option
off
Heavy Evaision option
off
MITM proxy
off
Route via Tor
off
Network geolocation
off
Privacy
Public submission
Autoconfirmation of UAC
on

Software preset

  • Internet Explorer 8.0.7601.17514
  • Adobe Acrobat Reader DC MUI (15.023.20070)
  • Adobe Flash Player 26 ActiveX (26.0.0.131)
  • Adobe Flash Player 26 NPAPI (26.0.0.131)
  • Adobe Flash Player 26 PPAPI (26.0.0.131)
  • Adobe Refresh Manager (1.8.0)
  • CCleaner (5.35)
  • FileZilla Client 3.36.0 (3.36.0)
  • Google Chrome (75.0.3770.100)
  • Google Update Helper (1.3.34.7)
  • Java 8 Update 92 (8.0.920.14)
  • Java Auto Updater (2.8.92.14)
  • Microsoft .NET Framework 4.7.2 (4.7.03062)
  • Microsoft Office Access MUI (English) 2010 (14.0.6029.1000)
  • Microsoft Office Access Setup Metadata MUI (English) 2010 (14.0.6029.1000)
  • Microsoft Office Excel MUI (English) 2010 (14.0.6029.1000)
  • Microsoft Office OneNote MUI (English) 2010 (14.0.6029.1000)
  • Microsoft Office Outlook MUI (English) 2010 (14.0.6029.1000)
  • Microsoft Office PowerPoint MUI (English) 2010 (14.0.6029.1000)
  • Microsoft Office Professional 2010 (14.0.6029.1000)
  • Microsoft Office Proof (English) 2010 (14.0.6029.1000)
  • Microsoft Office Proof (French) 2010 (14.0.6029.1000)
  • Microsoft Office Proof (Spanish) 2010 (14.0.6029.1000)
  • Microsoft Office Proofing (English) 2010 (14.0.6029.1000)
  • Microsoft Office Publisher MUI (English) 2010 (14.0.6029.1000)
  • Microsoft Office Shared MUI (English) 2010 (14.0.6029.1000)
  • Microsoft Office Shared Setup Metadata MUI (English) 2010 (14.0.6029.1000)
  • Microsoft Office Single Image 2010 (14.0.6029.1000)
  • Microsoft Office Word MUI (English) 2010 (14.0.6029.1000)
  • Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (9.0.30729.6161)
  • Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 (10.0.40219)
  • Microsoft Visual C++ 2013 Redistributable (x86) - 12.0.30501 (12.0.30501.0)
  • Microsoft Visual C++ 2013 x86 Additional Runtime - 12.0.21005 (12.0.21005)
  • Microsoft Visual C++ 2013 x86 Minimum Runtime - 12.0.21005 (12.0.21005)
  • Microsoft Visual C++ 2015-2019 Redistributable (x86) - 14.21.27702 (14.21.27702.2)
  • Microsoft Visual C++ 2019 X86 Additional Runtime - 14.21.27702 (14.21.27702)
  • Microsoft Visual C++ 2019 X86 Minimum Runtime - 14.21.27702 (14.21.27702)
  • Mozilla Firefox 68.0.1 (x86 en-US) (68.0.1)
  • Notepad++ (32-bit x86) (7.5.1)
  • Opera 12.15 (12.15.1748)
  • Skype version 8.29 (8.29)
  • Update for Microsoft .NET Framework 4.7.2 (KB4087364) (1)
  • VLC media player (2.2.6)
  • WinRAR 5.60 (32-bit) (5.60.0)

Hotfixes

  • Client LanguagePack Package
  • Client Refresh LanguagePack Package
  • CodecPack Basic Package
  • Foundation Package
  • IE Troubleshooters Package
  • InternetExplorer Optional Package
  • KB2534111
  • KB2999226
  • KB4019990
  • KB976902
  • LocalPack AU Package
  • LocalPack CA Package
  • LocalPack GB Package
  • LocalPack US Package
  • LocalPack ZA Package
  • ProfessionalEdition
  • UltimateEdition

Behavior activities

MALICIOUS SUSPICIOUS INFO
Dropped file may contain instructions of ransomware
  • ph_exec.exe (PID: 2972)
Changes the autorun value in the registry
  • ph_exec.exe (PID: 2596)
  • ph_exec.exe (PID: 2972)
Runs app for hidden code execution
  • ph_exec.exe (PID: 2972)
Turns off the firewall via NETSH.EXE
  • cmd.exe (PID: 876)
Writes to a start menu file
  • ph_exec.exe (PID: 2972)
Actions looks like stealing of personal data
  • ph_exec.exe (PID: 2972)
Renames files like Ransomware
  • ph_exec.exe (PID: 2972)
Modifies files in Chrome extension folder
  • ph_exec.exe (PID: 2972)
Creates files in the program directory
  • SearchIndexer.exe (PID: 2644)
  • SearchIndexer.exe (PID: 2868)
  • ph_exec.exe (PID: 2972)
Executed as Windows Service
  • SearchIndexer.exe (PID: 2644)
  • SearchIndexer.exe (PID: 2868)
Creates files in the user directory
  • mshta.exe (PID: 2244)
  • ph_exec.exe (PID: 2972)
Starts MSHTA.EXE for opening HTA or HTMLS files
  • ph_exec.exe (PID: 2972)
Reads the cookies of Google Chrome
  • ph_exec.exe (PID: 2972)
Reads the cookies of Mozilla Firefox
  • ph_exec.exe (PID: 2972)
Executable content was dropped or overwritten
  • ph_exec.exe (PID: 2596)
  • ph_exec.exe (PID: 2972)
Uses NETSH.EXE for network configuration
  • cmd.exe (PID: 876)
Starts CMD.EXE for commands execution
  • ph_exec.exe (PID: 2972)
Application launched itself
  • ph_exec.exe (PID: 1344)
Writes to a desktop.ini file (may be used to cloak folders)
  • ph_exec.exe (PID: 2972)
Reads internet explorer settings
  • mshta.exe (PID: 3564)
  • mshta.exe (PID: 2244)
  • mshta.exe (PID: 2176)
Writes to a desktop.ini file (may be used to cloak folders)
  • mshta.exe (PID: 2244)
Manual execution by user
  • rundll32.exe (PID: 3936)

Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report

Static information

TRiD
.exe
|   Win64 Executable (generic) (64.6%)
.dll
|   Win32 Dynamic Link Library (generic) (15.4%)
.exe
|   Win32 Executable (generic) (10.5%)
.exe
|   Generic Win/DOS Executable (4.6%)
.exe
|   DOS Executable Generic (4.6%)
EXIF
EXE
MachineType:
Intel 386 or later, and compatibles
TimeStamp:
2019:06:19 10:00:06+02:00
PEType:
PE32
LinkerVersion:
10
CodeSize:
31744
InitializedDataSize:
15360
UninitializedDataSize:
null
EntryPoint:
0x2518
OSVersion:
5.1
ImageVersion:
null
SubsystemVersion:
5.1
Subsystem:
Windows GUI
Summary
Architecture:
IMAGE_FILE_MACHINE_I386
Subsystem:
IMAGE_SUBSYSTEM_WINDOWS_GUI
Compilation Date:
19-Jun-2019 08:00:06
DOS Header
Magic number:
MZ
Bytes on last page of file:
0x0090
Pages in file:
0x0003
Relocations:
0x0000
Size of header:
0x0004
Min extra paragraphs:
0x0000
Max extra paragraphs:
0xFFFF
Initial SS value:
0x0000
Initial SP value:
0x00B8
Checksum:
0x0000
Initial IP value:
0x0000
Initial CS value:
0x0000
Overlay number:
0x0000
OEM identifier:
0x0000
OEM information:
0x0000
Address of NE header:
0x000000E0
PE Headers
Signature:
PE
Machine:
IMAGE_FILE_MACHINE_I386
Number of sections:
5
Time date stamp:
19-Jun-2019 08:00:06
Pointer to Symbol Table:
0x00000000
Number of symbols:
0
Size of Optional Header:
0x00E0
Characteristics
IMAGE_FILE_32BIT_MACHINE
IMAGE_FILE_EXECUTABLE_IMAGE
Sections
Name Virtual Address Virtual Size Raw Size Charateristics Entropy
.text 0x00001000 0x00007BB8 0x00007C00 IMAGE_SCN_CNT_CODE,IMAGE_SCN_MEM_EXECUTE,IMAGE_SCN_MEM_READ 6.6211
.rdata 0x00009000 0x00000C4A 0x00000E00 IMAGE_SCN_CNT_INITIALIZED_DATA,IMAGE_SCN_MEM_READ 5.22085
.data 0x0000A000 0x00002719 0x00000600 IMAGE_SCN_CNT_INITIALIZED_DATA,IMAGE_SCN_MEM_READ,IMAGE_SCN_MEM_WRITE 6.39656
.reloc 0x0000D000 0x00000558 0x00000600 IMAGE_SCN_CNT_INITIALIZED_DATA,IMAGE_SCN_MEM_DISCARDABLE,IMAGE_SCN_MEM_READ 5.28469
.cdata 0x0000E000 0x0000360C 0x00003800 IMAGE_SCN_CNT_INITIALIZED_DATA,IMAGE_SCN_MEM_READ,IMAGE_SCN_MEM_WRITE 7.81833
Resources

No resources.

Imports
    MPR.dll

    WS2_32.dll

    IPHLPAPI.DLL

    KERNEL32.dll

    USER32.dll

    ADVAPI32.dll

    SHELL32.dll

    ole32.dll

Exports

    No exports.

Screenshots

Processes

Total processes
59
Monitored processes
15
Malicious processes
4
Suspicious processes
2

Behavior graph

+
drop and start start ph_exec.exe ph_exec.exe no specs ph_exec.exe cmd.exe no specs netsh.exe no specs netsh.exe no specs rundll32.exe no specs mshta.exe no specs mshta.exe no specs mshta.exe no specs searchindexer.exe no specs searchindexer.exe no specs searchprotocolhost.exe no specs searchfilterhost.exe no specs searchprotocolhost.exe no specs
Specs description
Program did not start
Integrity level elevation
Task сontains an error or was rebooted
Process has crashed
Task contains several apps running
Executable file was dropped
Debug information is available
Process was injected
Network attacks were detected
Application downloaded the executable file
Actions similar to stealing personal data
Behavior similar to exploiting the vulnerability
Inspected object has sucpicious PE structure
File is detected by antivirus software
CPU overrun
RAM overrun
Process starts the services
Process was added to the startup
Behavior similar to spam
Low-level access to the HDD
Probably Tor was used
System was rebooted
Connects to the network
Known threat

Process information

Click at the process to see the details.

PID
2596
CMD
"C:\Users\admin\AppData\Local\Temp\ph_exec.exe"
Path
C:\Users\admin\AppData\Local\Temp\ph_exec.exe
Indicators
Parent process
––
User
admin
Integrity Level
MEDIUM
Version:
Company
Description
Version
Modules
Image
c:\users\admin\appdata\local\temp\ph_exec.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\mpr.dll
c:\windows\system32\ws2_32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\nsi.dll
c:\windows\system32\iphlpapi.dll
c:\windows\system32\winnsi.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\shell32.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\ole32.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\drprov.dll
c:\windows\system32\winsta.dll
c:\windows\system32\ntlanman.dll
c:\windows\system32\davclnt.dll
c:\windows\system32\davhlpr.dll
c:\windows\system32\wkscli.dll
c:\windows\system32\cscapi.dll
c:\windows\system32\netutils.dll
c:\windows\system32\browcli.dll
c:\windows\system32\dhcpcsvc6.dll
c:\windows\system32\dhcpcsvc.dll
c:\windows\system32\mswsock.dll
c:\windows\system32\wshtcpip.dll
c:\windows\system32\srvcli.dll

PID
1344
CMD
C:\Users\admin\AppData\Local\Temp\ph_exec.exe
Path
C:\Users\admin\AppData\Local\Temp\ph_exec.exe
Indicators
No indicators
Parent process
ph_exec.exe
User
admin
Integrity Level
MEDIUM
Exit code
0
Version:
Company
Description
Version
Modules
Image
c:\users\admin\appdata\local\temp\ph_exec.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\mpr.dll
c:\windows\system32\ws2_32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\nsi.dll
c:\windows\system32\iphlpapi.dll
c:\windows\system32\winnsi.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\shell32.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\ole32.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\windows\system32\cryptbase.dll
c:\windows\system32\propsys.dll
c:\windows\system32\oleaut32.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll
c:\windows\system32\clbcatq.dll
c:\windows\system32\ntmarta.dll
c:\windows\system32\wldap32.dll
c:\windows\system32\profapi.dll
c:\windows\system32\setupapi.dll
c:\windows\system32\cfgmgr32.dll
c:\windows\system32\devobj.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\shdocvw.dll
c:\windows\system32\urlmon.dll
c:\windows\system32\wininet.dll
c:\windows\system32\iertutil.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\msasn1.dll
c:\windows\system32\sspicli.dll

PID
2972
CMD
"C:\Users\admin\AppData\Local\Temp\ph_exec.exe"
Path
C:\Users\admin\AppData\Local\Temp\ph_exec.exe
Indicators
Parent process
ph_exec.exe
User
admin
Integrity Level
HIGH
Version:
Company
Description
Version
Modules
Image
c:\users\admin\appdata\local\temp\ph_exec.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\mpr.dll
c:\windows\system32\ws2_32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\nsi.dll
c:\windows\system32\iphlpapi.dll
c:\windows\system32\winnsi.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\shell32.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\ole32.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\cryptbase.dll
c:\windows\system32\propsys.dll
c:\windows\system32\oleaut32.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll
c:\windows\system32\clbcatq.dll
c:\windows\system32\urlmon.dll
c:\windows\system32\wininet.dll
c:\windows\system32\iertutil.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\msasn1.dll
c:\windows\system32\sspicli.dll
c:\windows\system32\mshta.exe
c:\windows\system32\setupapi.dll
c:\windows\system32\cfgmgr32.dll
c:\windows\system32\devobj.dll
c:\windows\system32\profapi.dll
c:\windows\system32\wpdshext.dll
c:\windows\system32\winmm.dll
c:\windows\winsxs\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7601.17514_none_72d18a4386696c80\gdiplus.dll
c:\windows\system32\shdocvw.dll
c:\windows\system32\ieframe.dll
c:\windows\system32\psapi.dll
c:\windows\system32\oleacc.dll

PID
876
CMD
"C:\Windows\system32\cmd.exe"
Path
C:\Windows\system32\cmd.exe
Indicators
No indicators
Parent process
ph_exec.exe
User
admin
Integrity Level
HIGH
Exit code
0
Version:
Company
Microsoft Corporation
Description
Windows Command Processor
Version
6.1.7601.17514 (win7sp1_rtm.101119-1850)
Modules
Image
c:\windows\system32\cmd.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\winbrand.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\windows\system32\apphelp.dll

PID
3708
CMD
netsh advfirewall set currentprofile state off
Path
C:\Windows\system32\netsh.exe
Indicators
No indicators
Parent process
cmd.exe
User
admin
Integrity Level
HIGH
Exit code
0
Version:
Company
Microsoft Corporation
Description
Network Command Shell
Version
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Image
c:\windows\system32\netsh.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\credui.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\mpr.dll
c:\windows\system32\ole32.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\rasmontr.dll
c:\windows\system32\mprapi.dll
c:\windows\system32\rasapi32.dll
c:\windows\system32\rasman.dll
c:\windows\system32\ws2_32.dll
c:\windows\system32\nsi.dll
c:\windows\system32\fwpuclnt.dll
c:\windows\system32\mfc42u.dll
c:\windows\system32\odbc32.dll
c:\windows\system32\iphlpapi.dll
c:\windows\system32\winnsi.dll
c:\windows\system32\odbcint.dll
c:\windows\system32\nshwfp.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\msasn1.dll
c:\windows\system32\slc.dll
c:\windows\system32\dhcpcmonitor.dll
c:\windows\system32\dhcpcsvc.dll
c:\windows\system32\dhcpcsvc6.dll
c:\windows\system32\dhcpqec.dll
c:\windows\system32\qutil.dll
c:\windows\system32\wevtapi.dll
c:\windows\system32\wshelper.dll
c:\windows\system32\ws2help.dll
c:\windows\system32\mswsock.dll
c:\windows\system32\nshhttp.dll
c:\windows\system32\httpapi.dll
c:\windows\system32\fwcfg.dll
c:\windows\system32\firewallapi.dll
c:\windows\system32\version.dll
c:\windows\system32\authfwcfg.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\winipsec.dll
c:\windows\system32\ifmon.dll
c:\windows\system32\setupapi.dll
c:\windows\system32\cfgmgr32.dll
c:\windows\system32\devobj.dll
c:\windows\system32\nci.dll
c:\windows\system32\devrtl.dll
c:\windows\system32\netiohlp.dll
c:\windows\system32\dnsapi.dll
c:\windows\system32\whhelper.dll
c:\windows\system32\winhttp.dll
c:\windows\system32\webio.dll
c:\windows\system32\hnetmon.dll
c:\windows\system32\netshell.dll
c:\windows\system32\shell32.dll
c:\windows\system32\nlaapi.dll
c:\windows\system32\rpcnsh.dll
c:\windows\system32\dot3cfg.dll
c:\windows\system32\dot3api.dll
c:\windows\system32\atl.dll
c:\windows\system32\eappcfg.dll
c:\windows\system32\onex.dll
c:\windows\system32\eappprxy.dll
c:\windows\system32\napmontr.dll
c:\windows\system32\certcli.dll
c:\windows\system32\wldap32.dll
c:\windows\system32\nshipsec.dll
c:\windows\system32\netapi32.dll
c:\windows\system32\netutils.dll
c:\windows\system32\srvcli.dll
c:\windows\system32\wkscli.dll
c:\windows\system32\logoncli.dll
c:\windows\system32\userenv.dll
c:\windows\system32\profapi.dll
c:\windows\system32\activeds.dll
c:\windows\system32\adsldpc.dll
c:\windows\system32\polstore.dll
c:\windows\system32\nettrace.dll
c:\windows\system32\ndfapi.dll
c:\windows\system32\wdi.dll
c:\windows\system32\secur32.dll
c:\windows\system32\sspicli.dll
c:\windows\system32\tdh.dll
c:\windows\system32\wcnnetsh.dll
c:\windows\system32\wlanapi.dll
c:\windows\system32\wlanutil.dll
c:\windows\system32\p2pnetsh.dll
c:\windows\system32\p2p.dll
c:\windows\system32\p2pcollab.dll
c:\windows\system32\wlancfg.dll
c:\windows\system32\wlanhlp.dll
c:\windows\system32\wwancfg.dll
c:\windows\system32\wwapi.dll
c:\windows\system32\peerdistsh.dll
c:\windows\system32\cryptbase.dll
c:\windows\system32\cryptsp.dll
c:\windows\system32\clbcatq.dll
c:\windows\system32\qagent.dll
c:\windows\system32\napipsec.dll
c:\windows\system32\tsgqec.dll
c:\windows\system32\eapqec.dll
c:\windows\system32\rsaenh.dll
c:\windows\system32\rpcrtremote.dll
c:\windows\system32\gpapi.dll
c:\windows\system32\bcryptprimitives.dll

PID
3076
CMD
netsh firewall set opmode mode=disable
Path
C:\Windows\system32\netsh.exe
Indicators
No indicators
Parent process
cmd.exe
User
admin
Integrity Level
HIGH
Exit code
0
Version:
Company
Microsoft Corporation
Description
Network Command Shell
Version
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Image
c:\windows\system32\netsh.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\credui.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\mpr.dll
c:\windows\system32\ole32.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\rasmontr.dll
c:\windows\system32\mprapi.dll
c:\windows\system32\rasapi32.dll
c:\windows\system32\rasman.dll
c:\windows\system32\ws2_32.dll
c:\windows\system32\nsi.dll
c:\windows\system32\fwpuclnt.dll
c:\windows\system32\mfc42u.dll
c:\windows\system32\odbc32.dll
c:\windows\system32\iphlpapi.dll
c:\windows\system32\winnsi.dll
c:\windows\system32\odbcint.dll
c:\windows\system32\nshwfp.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\msasn1.dll
c:\windows\system32\slc.dll
c:\windows\system32\dhcpcmonitor.dll
c:\windows\system32\dhcpcsvc.dll
c:\windows\system32\dhcpcsvc6.dll
c:\windows\system32\dhcpqec.dll
c:\windows\system32\qutil.dll
c:\windows\system32\wevtapi.dll
c:\windows\system32\wshelper.dll
c:\windows\system32\ws2help.dll
c:\windows\system32\mswsock.dll
c:\windows\system32\nshhttp.dll
c:\windows\system32\httpapi.dll
c:\windows\system32\fwcfg.dll
c:\windows\system32\firewallapi.dll
c:\windows\system32\version.dll
c:\windows\system32\authfwcfg.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\winipsec.dll
c:\windows\system32\ifmon.dll
c:\windows\system32\setupapi.dll
c:\windows\system32\cfgmgr32.dll
c:\windows\system32\devobj.dll
c:\windows\system32\nci.dll
c:\windows\system32\devrtl.dll
c:\windows\system32\netiohlp.dll
c:\windows\system32\dnsapi.dll
c:\windows\system32\whhelper.dll
c:\windows\system32\winhttp.dll
c:\windows\system32\webio.dll
c:\windows\system32\hnetmon.dll
c:\windows\system32\netshell.dll
c:\windows\system32\shell32.dll
c:\windows\system32\nlaapi.dll
c:\windows\system32\rpcnsh.dll
c:\windows\system32\dot3cfg.dll
c:\windows\system32\dot3api.dll
c:\windows\system32\atl.dll
c:\windows\system32\eappcfg.dll
c:\windows\system32\onex.dll
c:\windows\system32\eappprxy.dll
c:\windows\system32\napmontr.dll
c:\windows\system32\certcli.dll
c:\windows\system32\wldap32.dll
c:\windows\system32\nshipsec.dll
c:\windows\system32\netapi32.dll
c:\windows\system32\netutils.dll
c:\windows\system32\srvcli.dll
c:\windows\system32\wkscli.dll
c:\windows\system32\logoncli.dll
c:\windows\system32\userenv.dll
c:\windows\system32\profapi.dll
c:\windows\system32\activeds.dll
c:\windows\system32\adsldpc.dll
c:\windows\system32\polstore.dll
c:\windows\system32\nettrace.dll
c:\windows\system32\ndfapi.dll
c:\windows\system32\wdi.dll
c:\windows\system32\secur32.dll
c:\windows\system32\sspicli.dll
c:\windows\system32\tdh.dll
c:\windows\system32\wcnnetsh.dll
c:\windows\system32\wlanapi.dll
c:\windows\system32\wlanutil.dll
c:\windows\system32\p2pnetsh.dll
c:\windows\system32\p2p.dll
c:\windows\system32\p2pcollab.dll
c:\windows\system32\wlancfg.dll
c:\windows\system32\wlanhlp.dll
c:\windows\system32\wwancfg.dll
c:\windows\system32\wwapi.dll
c:\windows\system32\peerdistsh.dll
c:\windows\system32\cryptbase.dll
c:\windows\system32\cryptsp.dll
c:\windows\system32\clbcatq.dll
c:\windows\system32\qagent.dll
c:\windows\system32\rsaenh.dll
c:\windows\system32\rpcrtremote.dll
c:\windows\system32\gpapi.dll
c:\windows\system32\bcryptprimitives.dll

PID
3936
CMD
"C:\Windows\system32\rundll32.exe" C:\Windows\system32\shell32.dll,OpenAs_RunDLL C:\autoexec.bat.id[C4BA3647-2261].[[email protected]].Adair
Path
C:\Windows\system32\rundll32.exe
Indicators
No indicators
Parent process
––
User
admin
Integrity Level
MEDIUM
Exit code
0
Version:
Company
Microsoft Corporation
Description
Windows host process (Rundll32)
Version
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Image
c:\windows\system32\rundll32.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\imagehlp.dll
c:\windows\system32\apphelp.dll
c:\windows\apppatch\aclayers.dll
c:\windows\system32\sspicli.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\shell32.dll
c:\windows\system32\ole32.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\userenv.dll
c:\windows\system32\profapi.dll
c:\windows\system32\winspool.drv
c:\windows\system32\mpr.dll
c:\windows\system32\msctf.dll
c:\windows\system32\imm32.dll
c:\windows\system32\cryptbase.dll
c:\windows\system32\propsys.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll
c:\windows\system32\uxtheme.dll
c:\windows\system32\clbcatq.dll

PID
2244
CMD
"C:\Windows\System32\mshta.exe" "C:\Users\admin\Desktop\info.hta"
Path
C:\Windows\System32\mshta.exe
Indicators
No indicators
Parent process
ph_exec.exe
User
admin
Integrity Level
HIGH
Version:
Company
Microsoft Corporation
Description
Microsoft (R) HTML Application host
Version
8.00.7600.16385 (win7_rtm.090713-1255)
Modules
Image
c:\windows\system32\mshta.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\mshtml.dll
c:\windows\system32\psapi.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\ole32.dll
c:\windows\system32\urlmon.dll
c:\windows\system32\wininet.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\iertutil.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\msasn1.dll
c:\windows\system32\msls31.dll
c:\windows\system32\version.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\windows\system32\cryptbase.dll
c:\windows\system32\ntmarta.dll
c:\windows\system32\wldap32.dll
c:\windows\system32\clbcatq.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll
c:\windows\system32\sspicli.dll
c:\windows\system32\shell32.dll
c:\windows\system32\msimtf.dll
c:\windows\system32\mlang.dll
c:\windows\system32\oleacc.dll
c:\windows\system32\cryptsp.dll
c:\windows\system32\rsaenh.dll
c:\windows\system32\rpcrtremote.dll
c:\windows\system32\sxs.dll
c:\windows\system32\ieframe.dll
c:\windows\system32\msiexec.exe
c:\windows\system32\jscript.dll
c:\windows\system32\imgutil.dll
c:\windows\system32\pngfilt.dll
c:\windows\system32\profapi.dll

PID
2176
CMD
"C:\Windows\System32\mshta.exe" "C:\users\public\desktop\info.hta"
Path
C:\Windows\System32\mshta.exe
Indicators
No indicators
Parent process
ph_exec.exe
User
admin
Integrity Level
HIGH
Version:
Company
Microsoft Corporation
Description
Microsoft (R) HTML Application host
Version
8.00.7600.16385 (win7_rtm.090713-1255)
Modules
Image
c:\windows\system32\mshta.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\mshtml.dll
c:\windows\system32\psapi.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\ole32.dll
c:\windows\system32\wininet.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\iertutil.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\urlmon.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\msasn1.dll
c:\windows\system32\msls31.dll
c:\windows\system32\version.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\windows\system32\cryptbase.dll
c:\windows\system32\clbcatq.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll
c:\windows\system32\sspicli.dll
c:\windows\system32\shell32.dll
c:\windows\system32\msimtf.dll
c:\windows\system32\mlang.dll
c:\windows\system32\oleacc.dll
c:\windows\system32\cryptsp.dll
c:\windows\system32\rsaenh.dll
c:\windows\system32\rpcrtremote.dll
c:\windows\system32\sxs.dll
c:\windows\system32\ieframe.dll
c:\windows\system32\msiexec.exe
c:\windows\system32\jscript.dll
c:\windows\system32\imgutil.dll
c:\windows\system32\ntmarta.dll
c:\windows\system32\wldap32.dll
c:\windows\system32\pngfilt.dll
c:\windows\system32\profapi.dll
c:\windows\system32\uxtheme.dll
c:\windows\system32\msimg32.dll

PID
3564
CMD
"C:\Windows\System32\mshta.exe" "C:\info.hta"
Path
C:\Windows\System32\mshta.exe
Indicators
No indicators
Parent process
ph_exec.exe
User
admin
Integrity Level
HIGH
Version:
Company
Microsoft Corporation
Description
Microsoft (R) HTML Application host
Version
8.00.7600.16385 (win7_rtm.090713-1255)
Modules
Image
c:\windows\system32\mshta.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\psapi.dll
c:\windows\system32\mshtml.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\wininet.dll
c:\windows\system32\user32.dll
c:\windows\system32\usp10.dll
c:\windows\system32\ole32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\urlmon.dll
c:\windows\system32\iertutil.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msasn1.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\msls31.dll
c:\windows\system32\version.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\windows\system32\cryptbase.dll
c:\windows\system32\clbcatq.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll
c:\windows\system32\sspicli.dll
c:\windows\system32\shell32.dll
c:\windows\system32\mlang.dll
c:\windows\system32\msimtf.dll
c:\windows\system32\oleacc.dll
c:\windows\system32\cryptsp.dll
c:\windows\system32\rsaenh.dll
c:\windows\system32\rpcrtremote.dll
c:\windows\system32\sxs.dll
c:\windows\system32\ieframe.dll
c:\windows\system32\msiexec.exe
c:\windows\system32\jscript.dll
c:\windows\system32\imgutil.dll
c:\windows\system32\ntmarta.dll
c:\windows\system32\wldap32.dll
c:\windows\system32\pngfilt.dll
c:\windows\system32\profapi.dll
c:\windows\system32\uxtheme.dll
c:\windows\system32\msimg32.dll

PID
2644
CMD
C:\Windows\system32\SearchIndexer.exe /Embedding
Path
C:\Windows\system32\SearchIndexer.exe
Indicators
No indicators
Parent process
––
User
SYSTEM
Integrity Level
SYSTEM
Exit code
0
Version:
Company
Microsoft Corporation
Description
Microsoft Windows Search Indexer
Version
7.00.7600.16385 (win7_rtm.090713-1255)
Modules
Image
c:\windows\system32\searchindexer.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\ole32.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\tquery.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\mssrch.dll
c:\windows\system32\esent.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\windows\system32\psapi.dll
c:\windows\system32\shell32.dll
c:\windows\system32\profapi.dll
c:\windows\system32\cryptbase.dll
c:\windows\system32\secur32.dll
c:\windows\system32\sspicli.dll
c:\windows\system32\cryptsp.dll
c:\windows\system32\credssp.dll
c:\windows\system32\clbcatq.dll
c:\windows\system32\msidle.dll
c:\windows\system32\kbdus.dll
c:\windows\system32\powrprof.dll
c:\windows\system32\setupapi.dll
c:\windows\system32\cfgmgr32.dll
c:\windows\system32\devobj.dll
c:\windows\system32\rsaenh.dll
c:\windows\system32\rpcrtremote.dll
c:\windows\system32\en-us\tquery.dll.mui

PID
2868
CMD
C:\Windows\system32\SearchIndexer.exe /Embedding
Path
C:\Windows\system32\SearchIndexer.exe
Indicators
No indicators
Parent process
––
User
SYSTEM
Integrity Level
SYSTEM
Version:
Company
Microsoft Corporation
Description
Microsoft Windows Search Indexer
Version
7.00.7600.16385 (win7_rtm.090713-1255)
Modules
Image
c:\windows\system32\searchindexer.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\ole32.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\tquery.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\mssrch.dll
c:\windows\system32\esent.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\windows\system32\psapi.dll
c:\windows\system32\shell32.dll
c:\windows\system32\profapi.dll
c:\windows\system32\cryptbase.dll
c:\windows\system32\secur32.dll
c:\windows\system32\sspicli.dll
c:\windows\system32\cryptsp.dll
c:\windows\system32\credssp.dll
c:\windows\system32\clbcatq.dll
c:\windows\system32\msidle.dll
c:\windows\system32\kbdus.dll
c:\windows\system32\powrprof.dll
c:\windows\system32\setupapi.dll
c:\windows\system32\cfgmgr32.dll
c:\windows\system32\devobj.dll
c:\windows\system32\rsaenh.dll
c:\windows\system32\rpcrtremote.dll
c:\windows\system32\mssprxy.dll
c:\windows\system32\ntmarta.dll
c:\windows\system32\wldap32.dll
c:\windows\system32\vssapi.dll
c:\windows\system32\atl.dll
c:\windows\system32\vsstrace.dll
c:\windows\system32\samcli.dll
c:\windows\system32\samlib.dll
c:\windows\system32\netutils.dll
c:\windows\system32\es.dll
c:\windows\system32\propsys.dll
c:\windows\system32\en-us\tquery.dll.mui
c:\windows\system32\userenv.dll
c:\windows\system32\ktmw32.dll
c:\windows\system32\searchprotocolhost.exe
c:\windows\system32\apphelp.dll
c:\windows\system32\wtsapi32.dll
c:\windows\system32\winsta.dll
c:\windows\system32\sxs.dll
c:\windows\system32\naturallanguage6.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\msasn1.dll
c:\windows\system32\nlsdata0009.dll
c:\windows\system32\nlslexicons0009.dll
c:\windows\system32\elscore.dll
c:\windows\system32\elstrans.dll
c:\windows\system32\elslad.dll
c:\windows\system32\nlsdata0026.dll
c:\windows\system32\nlslexicons0026.dll
c:\windows\system32\nlsdata0000.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll
c:\windows\system32\nlsdata000c.dll
c:\windows\system32\nlslexicons000c.dll
c:\windows\system32\nlsdata0416.dll
c:\windows\system32\nlslexicons0416.dll
c:\windows\system32\nlsdata0007.dll
c:\windows\system32\nlslexicons0007.dll
c:\windows\system32\nlsdata0019.dll
c:\windows\system32\nlslexicons0019.dll
c:\windows\system32\nlsdata0003.dll
c:\windows\system32\nlslexicons0003.dll
c:\windows\system32\nlsdata0013.dll
c:\windows\system32\nlslexicons0013.dll

PID
2144
CMD
"C:\Windows\system32\SearchProtocolHost.exe" Global\UsGthrFltPipeMssGthrPipe1_ Global\UsGthrCtrlFltPipeMssGthrPipe1 1 -2147483646 "Software\Microsoft\Windows Search" "Mozilla/4.0 (compatible; MSIE 6.0; Windows NT; MS Search 4.0 Robot)" "C:\ProgramData\Microsoft\Search\Data\Temp\usgthrsvc" "DownLevelDaemon"
Path
C:\Windows\system32\SearchProtocolHost.exe
Indicators
No indicators
Parent process
SearchIndexer.exe
User
SYSTEM
Integrity Level
SYSTEM
Version:
Company
Microsoft Corporation
Description
Microsoft Windows Search Protocol Host
Version
7.00.7600.16385 (win7_rtm.090713-1255)
Modules
Image
c:\windows\system32\searchprotocolhost.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\ole32.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\tquery.dll
c:\windows\system32\msshooks.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\windows\system32\cryptbase.dll
c:\windows\system32\msidle.dll
c:\windows\system32\clbcatq.dll
c:\windows\system32\cryptsp.dll
c:\windows\system32\rsaenh.dll
c:\windows\system32\rpcrtremote.dll
c:\windows\system32\mssprxy.dll
c:\windows\system32\mssph.dll
c:\windows\system32\mapi32.dll
c:\windows\system32\authz.dll
c:\windows\system32\ntmarta.dll
c:\windows\system32\wldap32.dll
c:\windows\system32\shell32.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll
c:\windows\system32\propsys.dll
c:\windows\system32\setupapi.dll
c:\windows\system32\cfgmgr32.dll
c:\windows\system32\devobj.dll
c:\windows\system32\profapi.dll
c:\windows\system32\ntshrui.dll
c:\windows\system32\srvcli.dll
c:\windows\system32\cscapi.dll
c:\windows\system32\slc.dll
c:\windows\system32\notepad.exe
c:\windows\system32\mshta.exe
c:\windows\system32\version.dll
c:\programdata\microsoft\windows\start menu\programs\startup\ph_exec.exe

PID
3696
CMD
"C:\Windows\system32\SearchFilterHost.exe" 0 516 520 528 65536 524
Path
C:\Windows\system32\SearchFilterHost.exe
Indicators
No indicators
Parent process
SearchIndexer.exe
User
SYSTEM
Integrity Level
MEDIUM
Version:
Company
Microsoft Corporation
Description
Microsoft Windows Search Filter Host
Version
7.00.7600.16385 (win7_rtm.090713-1255)
Modules
Image
c:\windows\system32\searchfilterhost.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\ole32.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\tquery.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\msctf.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msshooks.dll
c:\windows\system32\mscoree.dll
c:\windows\microsoft.net\framework\v4.0.30319\mscoreei.dll
c:\windows\system32\cryptbase.dll
c:\windows\system32\clbcatq.dll
c:\windows\system32\cryptsp.dll
c:\windows\system32\rsaenh.dll
c:\windows\system32\rpcrtremote.dll
c:\windows\system32\mssprxy.dll
c:\windows\system32\sxs.dll
c:\windows\system32\query.dll
c:\windows\system32\shell32.dll
c:\windows\system32\nlhtml.dll
c:\windows\system32\mlang.dll

PID
868
CMD
"C:\Windows\system32\SearchProtocolHost.exe" Global\UsGthrFltPipeMssGthrPipe_S-1-5-21-1302019708-1500728564-335382590-10002_ Global\UsGthrCtrlFltPipeMssGthrPipe_S-1-5-21-1302019708-1500728564-335382590-10002 1 -2147483646 "Software\Microsoft\Windows Search" "Mozilla/4.0 (compatible; MSIE 6.0; Windows NT; MS Search 4.0 Robot)" "C:\ProgramData\Microsoft\Search\Data\Temp\usgthrsvc" "DownLevelDaemon" "1"
Path
C:\Windows\system32\SearchProtocolHost.exe
Indicators
No indicators
Parent process
SearchIndexer.exe
User
admin
Integrity Level
MEDIUM
Version:
Company
Microsoft Corporation
Description
Microsoft Windows Search Protocol Host
Version
7.00.7600.16385 (win7_rtm.090713-1255)
Modules
Image
c:\windows\system32\searchprotocolhost.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\ole32.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\tquery.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\msshooks.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\windows\system32\cryptbase.dll
c:\windows\system32\msidle.dll
c:\windows\system32\clbcatq.dll
c:\windows\system32\cryptsp.dll
c:\windows\system32\rsaenh.dll
c:\windows\system32\rpcrtremote.dll
c:\windows\system32\mssprxy.dll
c:\windows\system32\ieframe.dll
c:\windows\system32\psapi.dll
c:\windows\system32\oleacc.dll
c:\windows\system32\shell32.dll
c:\windows\system32\iertutil.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll
c:\windows\system32\sspicli.dll
c:\windows\system32\mlang.dll
c:\windows\system32\wininet.dll
c:\windows\system32\urlmon.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\msasn1.dll
c:\windows\system32\profapi.dll
c:\windows\system32\mssvp.dll
c:\windows\system32\mapi32.dll
c:\windows\system32\cscapi.dll

Registry activity

Total events
3809
Read events
2127
Write events
1484
Delete events
198

Modification events

PID
Process
Operation
Key
Name
Value
2596
ph_exec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
ph_exec
C:\Users\admin\AppData\Local\ph_exec.exe
2596
ph_exec.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run
ph_exec
C:\Users\admin\AppData\Local\ph_exec.exe
1344
ph_exec.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
UNCAsIntranet
0
1344
ph_exec.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
AutoDetect
1
2972
ph_exec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
ph_exec
C:\Users\admin\AppData\Local\ph_exec.exe
2972
ph_exec.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run
ph_exec
C:\Users\admin\AppData\Local\ph_exec.exe
2972
ph_exec.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
UNCAsIntranet
0
2972
ph_exec.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
AutoDetect
1
3708
netsh.exe
write
HKEY_CLASSES_ROOT\Local Settings\MuiCache\72\52C64B7E
LanguageList
en-US
3708
netsh.exe
write
HKEY_CLASSES_ROOT\Local Settings\MuiCache\72\52C64B7E
@%SystemRoot%\system32\dhcpqec.dll,-100
DHCP Quarantine Enforcement Client
3708
netsh.exe
write
HKEY_CLASSES_ROOT\Local Settings\MuiCache\72\52C64B7E
@%SystemRoot%\system32\dhcpqec.dll,-101
Provides DHCP based enforcement for NAP
3708
netsh.exe
write
HKEY_CLASSES_ROOT\Local Settings\MuiCache\72\52C64B7E
@%SystemRoot%\system32\dhcpqec.dll,-103
1.0
3708
netsh.exe
write
HKEY_CLASSES_ROOT\Local Settings\MuiCache\72\52C64B7E
@%SystemRoot%\system32\dhcpqec.dll,-102
Microsoft Corporation
3708
netsh.exe
write
HKEY_CLASSES_ROOT\Local Settings\MuiCache\72\52C64B7E
@%SystemRoot%\system32\napipsec.dll,-1
IPsec Relying Party
3708
netsh.exe
write
HKEY_CLASSES_ROOT\Local Settings\MuiCache\72\52C64B7E
@%SystemRoot%\system32\napipsec.dll,-2
Provides IPsec based enforcement for Network Access Protection
3708
netsh.exe
write
HKEY_CLASSES_ROOT\Local Settings\MuiCache\72\52C64B7E
@%SystemRoot%\system32\napipsec.dll,-4
1.0
3708
netsh.exe
write
HKEY_CLASSES_ROOT\Local Settings\MuiCache\72\52C64B7E
@%SystemRoot%\system32\napipsec.dll,-3
Microsoft Corporation
3708
netsh.exe
write
HKEY_CLASSES_ROOT\Local Settings\MuiCache\72\52C64B7E
@%SystemRoot%\system32\tsgqec.dll,-100
RD Gateway Quarantine Enforcement Client
3708
netsh.exe
write
HKEY_CLASSES_ROOT\Local Settings\MuiCache\72\52C64B7E
@%SystemRoot%\system32\tsgqec.dll,-101
Provides RD Gateway enforcement for NAP
3708
netsh.exe
write
HKEY_CLASSES_ROOT\Local Settings\MuiCache\72\52C64B7E
@%SystemRoot%\system32\tsgqec.dll,-102
1.0
3708
netsh.exe
write
HKEY_CLASSES_ROOT\Local Settings\MuiCache\72\52C64B7E
@%SystemRoot%\system32\tsgqec.dll,-103
Microsoft Corporation
3708
netsh.exe
write
HKEY_CLASSES_ROOT\Local Settings\MuiCache\72\52C64B7E
@%SystemRoot%\system32\eapqec.dll,-100
EAP Quarantine Enforcement Client
3708
netsh.exe
write
HKEY_CLASSES_ROOT\Local Settings\MuiCache\72\52C64B7E
@%SystemRoot%\system32\eapqec.dll,-101
Provides Network Access Protection enforcement for EAP authenticated network connections, such as those used with 802.1X and VPN technologies.
3708
netsh.exe
write
HKEY_CLASSES_ROOT\Local Settings\MuiCache\72\52C64B7E
@%SystemRoot%\system32\eapqec.dll,-102
1.0
3708
netsh.exe
write
HKEY_CLASSES_ROOT\Local Settings\MuiCache\72\52C64B7E
@%SystemRoot%\system32\eapqec.dll,-103
Microsoft Corporation
3076
netsh.exe
write
HKEY_CLASSES_ROOT\Local Settings\MuiCache\72\52C64B7E
LanguageList
en-US
2244
mshta.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
UNCAsIntranet
0
2244
mshta.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
AutoDetect
1
2244
mshta.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\International\CpMRU
Enable
1
2244
mshta.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\International\CpMRU
Size
10
2244
mshta.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\International\CpMRU
InitHits
100
2244
mshta.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\International\CpMRU
Factor
20
2176
mshta.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
UNCAsIntranet
0
2176
mshta.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
AutoDetect
1
3564
mshta.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
UNCAsIntranet
0
3564
mshta.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
AutoDetect
1
2644
SearchIndexer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Search\Gathering Manager
UseSystemTemp
0
2644
SearchIndexer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Search\Tracing\EventThrottleState
00001b80
01000000A3F804BC030C00000100000000000000
2644
SearchIndexer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Search
RebuildIndex
3
2644
SearchIndexer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Search\Tracing\EventThrottleState
00001b82
01000000B3F804BC030C00000100000000000000
2644
SearchIndexer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Search\Gather\Windows\SystemIndex
SystemLcid
1033
2644
SearchIndexer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Search\Gather\Windows\SystemIndex\StartPages\0
CrawlControl
0
2644
SearchIndexer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Search\Gather\Windows\SystemIndex\StartPages\1
CrawlControl
0
2644
SearchIndexer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Search\Gather\Windows\SystemIndex\StartPages\2
CrawlControl
0
2644
SearchIndexer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Search\Gather\Windows\SystemIndex\StartPages\3
CrawlControl
0
2644
SearchIndexer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Search\Gather\Windows\SystemIndex\StartPages\5
CrawlControl
0
2644
SearchIndexer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Search\Gather\Windows\SystemIndex\StartPages\6
CrawlControl
0
2644
SearchIndexer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Search\Gather\Windows\SystemIndex\StartPages\7
CrawlControl
0
2644
SearchIndexer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Search\Gather\Windows\SystemIndex\Extensions
IncludedExtensions
0
2644
SearchIndexer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Search\Gather\Windows\SystemIndex\Protocols\Csc\0
ProgIdHandler
Search.CscHandler.1
2644
SearchIndexer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Search\Gather\Windows\SystemIndex\Protocols\File\0
ProgIdHandler
Search.FileHandler.1
2644
SearchIndexer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Search\Gather\Windows\SystemIndex\Protocols\Mapi\0
ProgIdHandler
Outlook.Search.MAPIHandler.1
2644
SearchIndexer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Search\Gather\Windows\SystemIndex\Protocols\StickyNotes\0
ProgIdHandler
Search.StickyNotesHandler.1
2644
SearchIndexer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Search\Gather\Windows\SystemIndex\StreamLog
StreamLogCount
2
2644
SearchIndexer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Search\Tracing\EventThrottleState
00000bd5
010000000AFA04BC030C00000100000000000000
2644
SearchIndexer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Search\Tracing\EventThrottleState
00000bd5
010000000AFA04BC030C00000200000000000000
2644
SearchIndexer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Search\Tracing\EventThrottleState
00000bd4
010000001AFA04BC030C00000100000000000000
2644
SearchIndexer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Search\Tracing\EventThrottleState
00000bf2
010000001AFA04BC030C00000100000000000000
2644
SearchIndexer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Search\Tracing\EventThrottleState
00001b62
010000002AFA04BC030C00000100000000000000
2644
SearchIndexer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Search\Tracing\EventThrottleState
00001b80
01000000A3F804BC030C00000200000000000000
2644
SearchIndexer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Search\Tracing\EventThrottleState
00001b82
01000000B3F804BC030C00000200000000000000
2644
SearchIndexer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Search\Tracing\EventThrottleState
000003f5
0100000039FA04BC030C00000100000000000000
2868
SearchIndexer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Search\CrawlScopeManager_PreviousVersion\Windows\SystemIndex\DefaultRules\0
URL
file:///C:\Users\*\AppData\Local\Microsoft\Windows\Temporary Internet Files\*
2868
SearchIndexer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Search\CrawlScopeManager_PreviousVersion\Windows\SystemIndex\DefaultRules\0
Include
0
2868
SearchIndexer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Search\CrawlScopeManager_PreviousVersion\Windows\SystemIndex\DefaultRules\0
Suppress
0
2868
SearchIndexer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Search\CrawlScopeManager_PreviousVersion\Windows\SystemIndex\DefaultRules\0
Default
1
2868
SearchIndexer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Search\CrawlScopeManager_PreviousVersion\Windows\SystemIndex\DefaultRules\0
Policy
0
2868
SearchIndexer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Search\CrawlScopeManager_PreviousVersion\Windows\SystemIndex\DefaultRules\1
URL
file:///C:\Users\*\AppData\Local\Temp\*
2868
SearchIndexer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Search\CrawlScopeManager_PreviousVersion\Windows\SystemIndex\DefaultRules\1
Include
0
2868
SearchIndexer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Search\CrawlScopeManager_PreviousVersion\Windows\SystemIndex\DefaultRules\1
Suppress
0
2868
SearchIndexer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Search\CrawlScopeManager_PreviousVersion\Windows\SystemIndex\DefaultRules\1
Default
1
2868
SearchIndexer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Search\CrawlScopeManager_PreviousVersion\Windows\SystemIndex\DefaultRules\1
Policy
0
2868
SearchIndexer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Search\CrawlScopeManager_PreviousVersion\Windows\SystemIndex\DefaultRules\10
URL
file:///C:\ProgramData\*
2868
SearchIndexer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Search\CrawlScopeManager_PreviousVersion\Windows\SystemIndex\DefaultRules\10
Include
0
2868
SearchIndexer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Search\CrawlScopeManager_PreviousVersion\Windows\SystemIndex\DefaultRules\10
Suppress
0
2868
SearchIndexer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Search\CrawlScopeManager_PreviousVersion\Windows\SystemIndex\DefaultRules\10
Default
1
2868
SearchIndexer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Search\CrawlScopeManager_PreviousVersion\Windows\SystemIndex\DefaultRules\10
Policy
0
2868
SearchIndexer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Search\CrawlScopeManager_PreviousVersion\Windows\SystemIndex\DefaultRules\11
URL
file:///C:\Users\
2868
SearchIndexer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Search\CrawlScopeManager_PreviousVersion\Windows\SystemIndex\DefaultRules\11
Include
1
2868
SearchIndexer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Search\CrawlScopeManager_PreviousVersion\Windows\SystemIndex\DefaultRules\11
Suppress
0
2868
SearchIndexer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Search\CrawlScopeManager_PreviousVersion\Windows\SystemIndex\DefaultRules\11
Default
1
2868
SearchIndexer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Search\CrawlScopeManager_PreviousVersion\Windows\SystemIndex\DefaultRules\11
Policy
0
2868
SearchIndexer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Search\CrawlScopeManager_PreviousVersion\Windows\SystemIndex\DefaultRules\12
URL
file:///C:\Windows\*
2868
SearchIndexer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Search\CrawlScopeManager_PreviousVersion\Windows\SystemIndex\DefaultRules\12
Include
0
2868
SearchIndexer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Search\CrawlScopeManager_PreviousVersion\Windows\SystemIndex\DefaultRules\12
Suppress
0
2868
SearchIndexer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Search\CrawlScopeManager_PreviousVersion\Windows\SystemIndex\DefaultRules\12
Default
1
2868
SearchIndexer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Search\CrawlScopeManager_PreviousVersion\Windows\SystemIndex\DefaultRules\12
Policy
0
2868
SearchIndexer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Search\CrawlScopeManager_PreviousVersion\Windows\SystemIndex\DefaultRules\13
URL
file:///C:\Windows.*\*
2868
SearchIndexer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Search\CrawlScopeManager_PreviousVersion\Windows\SystemIndex\DefaultRules\13
Include
0
2868
SearchIndexer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Search\CrawlScopeManager_PreviousVersion\Windows\SystemIndex\DefaultRules\13
Suppress
0
2868
SearchIndexer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Search\CrawlScopeManager_PreviousVersion\Windows\SystemIndex\DefaultRules\13
Default
1
2868
SearchIndexer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Search\CrawlScopeManager_PreviousVersion\Windows\SystemIndex\DefaultRules\13
Policy
0
2868
SearchIndexer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Search\CrawlScopeManager_PreviousVersion\Windows\SystemIndex\DefaultRules\14
URL
file:///*\$RECYCLE.BIN\*
2868
SearchIndexer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Search\CrawlScopeManager_PreviousVersion\Windows\SystemIndex\DefaultRules\14
Include
0
2868
SearchIndexer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Search\CrawlScopeManager_PreviousVersion\Windows\SystemIndex\DefaultRules\14
Suppress
0
2868
SearchIndexer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Search\CrawlScopeManager_PreviousVersion\Windows\SystemIndex\DefaultRules\14
Default
1
2868
SearchIndexer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Search\CrawlScopeManager_PreviousVersion\Windows\SystemIndex\DefaultRules\14
Policy
0
2868
SearchIndexer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Search\CrawlScopeManager_PreviousVersion\Windows\SystemIndex\DefaultRules\15
URL
file:///*\DfsrPrivate\*
2868
SearchIndexer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Search\CrawlScopeManager_PreviousVersion\Windows\SystemIndex\DefaultRules\15
Include
0
2868
SearchIndexer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Search\CrawlScopeManager_PreviousVersion\Windows\SystemIndex\DefaultRules\15
Suppress
0
2868
SearchIndexer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Search\CrawlScopeManager_PreviousVersion\Windows\SystemIndex\DefaultRules\15
Default
1
2868
SearchIndexer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Search\CrawlScopeManager_PreviousVersion\Windows\SystemIndex\DefaultRules\15
Policy
0
2868
SearchIndexer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Search\CrawlScopeManager_PreviousVersion\Windows\SystemIndex\DefaultRules\16
URL
file:///*\System Volume Information\*
2868
SearchIndexer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Search\CrawlScopeManager_PreviousVersion\Windows\SystemIndex\DefaultRules\16
Include
0
2868
SearchIndexer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Search\CrawlScopeManager_PreviousVersion\Windows\SystemIndex\DefaultRules\16
Suppress
0
2868
SearchIndexer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Search\CrawlScopeManager_PreviousVersion\Windows\SystemIndex\DefaultRules\16
Default
1
2868
SearchIndexer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Search\CrawlScopeManager_PreviousVersion\Windows\SystemIndex\DefaultRules\16
Policy
0
2868
SearchIndexer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Search\CrawlScopeManager_PreviousVersion\Windows\SystemIndex\DefaultRules\17
URL
csc://{S-1-5-21-1302019708-1500728564-335382590-1000}/
2868
SearchIndexer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Search\CrawlScopeManager_PreviousVersion\Windows\SystemIndex\DefaultRules\17
Include
1
2868
SearchIndexer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Search\CrawlScopeManager_PreviousVersion\Windows\SystemIndex\DefaultRules\17
Suppress
0
2868
SearchIndexer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Search\CrawlScopeManager_PreviousVersion\Windows\SystemIndex\DefaultRules\17
Default
1
2868
SearchIndexer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Search\CrawlScopeManager_PreviousVersion\Windows\SystemIndex\DefaultRules\17
Policy
0
2868
SearchIndexer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Search\CrawlScopeManager_PreviousVersion\Windows\SystemIndex\DefaultRules\18
URL
csc://{S-1-5-21-1302019708-1500728564-335382590-500}/
2868
SearchIndexer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Search\CrawlScopeManager_PreviousVersion\Windows\SystemIndex\DefaultRules\18
Include
1
2868
SearchIndexer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Search\CrawlScopeManager_PreviousVersion\Windows\SystemIndex\DefaultRules\18
Suppress
0
2868
SearchIndexer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Search\CrawlScopeManager_PreviousVersion\Windows\SystemIndex\DefaultRules\18
Default
1
2868
SearchIndexer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Search\CrawlScopeManager_PreviousVersion\Windows\SystemIndex\DefaultRules\18
Policy
0
2868
SearchIndexer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Search\CrawlScopeManager_PreviousVersion\Windows\SystemIndex\DefaultRules\19
URL
iehistory://{S-1-5-21-1302019708-1500728564-335382590-1000}/
2868
SearchIndexer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Search\CrawlScopeManager_PreviousVersion\Windows\SystemIndex\DefaultRules\19
Include
1
2868
SearchIndexer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Search\CrawlScopeManager_PreviousVersion\Windows\SystemIndex\DefaultRules\19
Suppress
0
2868
SearchIndexer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Search\CrawlScopeManager_PreviousVersion\Windows\SystemIndex\DefaultRules\19
Default
1
2868
SearchIndexer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Search\CrawlScopeManager_PreviousVersion\Windows\SystemIndex\DefaultRules\19
Policy
0
2868
SearchIndexer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Search\CrawlScopeManager_PreviousVersion\Windows\SystemIndex\DefaultRules\2
URL
file:///C:\ProgramData\Microsoft\Search\Data\*
2868
SearchIndexer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Search\CrawlScopeManager_PreviousVersion\Windows\SystemIndex\DefaultRules\2
Include
0
2868
SearchIndexer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Search\CrawlScopeManager_PreviousVersion\Windows\SystemIndex\DefaultRules\2
Suppress
0
2868
SearchIndexer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Search\CrawlScopeManager_PreviousVersion\Windows\SystemIndex\DefaultRules\2
Default
1
2868
SearchIndexer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Search\CrawlScopeManager_PreviousVersion\Windows\SystemIndex\DefaultRules\2
Policy
0
2868
SearchIndexer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Search\CrawlScopeManager_PreviousVersion\Windows\SystemIndex\DefaultRules\3
URL
file:///C:\ProgramData\Microsoft\Windows\Start Menu\
2868
SearchIndexer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Search\CrawlScopeManager_PreviousVersion\Windows\SystemIndex\DefaultRules\3
Include
1
2868
SearchIndexer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Search\CrawlScopeManager_PreviousVersion\Windows\SystemIndex\DefaultRules\3
Suppress
0
2868
SearchIndexer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Search\CrawlScopeManager_PreviousVersion\Windows\SystemIndex\DefaultRules\3
Default
1
2868
SearchIndexer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Search\CrawlScopeManager_PreviousVersion\Windows\SystemIndex\DefaultRules\3
Policy
0
2868
SearchIndexer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Search\CrawlScopeManager_PreviousVersion\Windows\SystemIndex\DefaultRules\4
URL
file:///C:\Users\admin\AppData\*
2868
SearchIndexer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Search\CrawlScopeManager_PreviousVersion\Windows\SystemIndex\DefaultRules\4
Include
0
2868
SearchIndexer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Search\CrawlScopeManager_PreviousVersion\Windows\SystemIndex\DefaultRules\4
Suppress
0
2868
SearchIndexer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Search\CrawlScopeManager_PreviousVersion\Windows\SystemIndex\DefaultRules\4
Default
1
2868
SearchIndexer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Search\CrawlScopeManager_PreviousVersion\Windows\SystemIndex\DefaultRules\4
Policy
0
2868
SearchIndexer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Search\CrawlScopeManager_PreviousVersion\Windows\SystemIndex\DefaultRules\5
URL
file:///C:\Users\admin\Favorites\
2868
SearchIndexer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Search\CrawlScopeManager_PreviousVersion\Windows\SystemIndex\DefaultRules\5
Include
1
2868
SearchIndexer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Search\CrawlScopeManager_PreviousVersion\Windows\SystemIndex\DefaultRules\5
Suppress
0
2868
SearchIndexer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Search\CrawlScopeManager_PreviousVersion\Windows\SystemIndex\DefaultRules\5
Default
1
2868
SearchIndexer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Search\CrawlScopeManager_PreviousVersion\Windows\SystemIndex\DefaultRules\5
Policy
0
2868
SearchIndexer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Search\CrawlScopeManager_PreviousVersion\Windows\SystemIndex\DefaultRules\6
URL
file:///C:\Users\Administrator\AppData\*
2868
SearchIndexer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Search\CrawlScopeManager_PreviousVersion\Windows\SystemIndex\DefaultRules\6
Include
0
2868
SearchIndexer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Search\CrawlScopeManager_PreviousVersion\Windows\SystemIndex\DefaultRules\6
Suppress
0
2868
SearchIndexer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Search\CrawlScopeManager_PreviousVersion\Windows\SystemIndex\DefaultRules\6
Default
1
2868
SearchIndexer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Search\CrawlScopeManager_PreviousVersion\Windows\SystemIndex\DefaultRules\6
Policy
0
2868
SearchIndexer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Search\CrawlScopeManager_PreviousVersion\Windows\SystemIndex\DefaultRules\7
URL
file:///C:\Users\Default\AppData\*
2868
SearchIndexer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Search\CrawlScopeManager_PreviousVersion\Windows\SystemIndex\DefaultRules\7
Include
0
2868
SearchIndexer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Search\CrawlScopeManager_PreviousVersion\Windows\SystemIndex\DefaultRules\7
Suppress
0
2868
SearchIndexer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Search\CrawlScopeManager_PreviousVersion\Windows\SystemIndex\DefaultRules\7
Default
1
2868
SearchIndexer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Search\CrawlScopeManager_PreviousVersion\Windows\SystemIndex\DefaultRules\7
Policy
0
2868
SearchIndexer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Search\CrawlScopeManager_PreviousVersion\Windows\SystemIndex\DefaultRules\8
URL
file:///C:\Windows\*\temp\*
2868
SearchIndexer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Search\CrawlScopeManager_PreviousVersion\Windows\SystemIndex\DefaultRules\8
Include
0
2868
SearchIndexer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Search\CrawlScopeManager_PreviousVersion\Windows\SystemIndex\DefaultRules\8
Suppress
0
2868
SearchIndexer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Search\CrawlScopeManager_PreviousVersion\Windows\SystemIndex\DefaultRules\8
Default
1
2868
SearchIndexer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Search\CrawlScopeManager_PreviousVersion\Windows\SystemIndex\DefaultRules\8
Policy
0
2868
SearchIndexer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Search\CrawlScopeManager_PreviousVersion\Windows\SystemIndex\DefaultRules\9
URL
file:///C:\Windows\CSC\*
2868
SearchIndexer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Search\CrawlScopeManager_PreviousVersion\Windows\SystemIndex\DefaultRules\9
Include
0
2868
SearchIndexer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Search\CrawlScopeManager_PreviousVersion\Windows\SystemIndex\DefaultRules\9
Suppress
0
2868
SearchIndexer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Search\CrawlScopeManager_PreviousVersion\Windows\SystemIndex\DefaultRules\9
Default
1
2868
SearchIndexer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Search\CrawlScopeManager_PreviousVersion\Windows\SystemIndex\DefaultRules\9
Policy
0
2868
SearchIndexer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Search\CrawlScopeManager_PreviousVersion\Windows\SystemIndex\DefaultRules
ItemCount
20
2868
SearchIndexer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Search\CrawlScopeManager_PreviousVersion\Windows\SystemIndex\SearchRoots\0
URL
csc://{S-1-5-21-1302019708-1500728564-335382590-1000}/
2868
SearchIndexer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Search\CrawlScopeManager_PreviousVersion\Windows\SystemIndex\SearchRoots\0
ProvidesNotifications
1
2868
SearchIndexer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Search\CrawlScopeManager_PreviousVersion\Windows\SystemIndex\SearchRoots\1
URL
csc://{S-1-5-21-1302019708-1500728564-335382590-500}/
2868
SearchIndexer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Search\CrawlScopeManager_PreviousVersion\Windows\SystemIndex\SearchRoots\1
ProvidesNotifications
1
2868
SearchIndexer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Search\CrawlScopeManager_PreviousVersion\Windows\SystemIndex\SearchRoots\2
URL
defaultroot://{S-1-5-21-1302019708-1500728564-335382590-1000}/
2868
SearchIndexer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Search\CrawlScopeManager_PreviousVersion\Windows\SystemIndex\SearchRoots\2
ProvidesNotifications
0
2868
SearchIndexer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Search\CrawlScopeManager_PreviousVersion\Windows\SystemIndex\SearchRoots\3
URL
defaultroot://{S-1-5-21-1302019708-1500728564-335382590-500}/
2868
SearchIndexer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Search\CrawlScopeManager_PreviousVersion\Windows\SystemIndex\SearchRoots\3
ProvidesNotifications
0
2868
SearchIndexer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Search\CrawlScopeManager_PreviousVersion\Windows\SystemIndex\SearchRoots\4
URL
file:///C:\
2868
SearchIndexer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Search\CrawlScopeManager_PreviousVersion\Windows\SystemIndex\SearchRoots\4
ProvidesNotifications
1
2868
SearchIndexer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Search\CrawlScopeManager_PreviousVersion\Windows\SystemIndex\SearchRoots\5
URL
iehistory://{S-1-5-21-1302019708-1500728564-335382590-1000}/
2868
SearchIndexer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Search\CrawlScopeManager_PreviousVersion\Windows\SystemIndex\SearchRoots\5
ProvidesNotifications
1
2868
SearchIndexer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Search\CrawlScopeManager_PreviousVersion\Windows\SystemIndex\SearchRoots\6
URL
mapi://{S-1-5-21-1302019708-1500728564-335382590-1000}/
2868
SearchIndexer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Search\CrawlScopeManager_PreviousVersion\Windows\SystemIndex\SearchRoots\6
ProvidesNotifications
1
2868
SearchIndexer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Search\CrawlScopeManager_PreviousVersion\Windows\SystemIndex\SearchRoots\7
URL
ONEINDEX14://{S-1-5-21-1302019708-1500728564-335382590-1000}/
2868
SearchIndexer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Search\CrawlScopeManager_PreviousVersion\Windows\SystemIndex\SearchRoots\7
ProvidesNotifications
1
2868
SearchIndexer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Search\CrawlScopeManager_PreviousVersion\Windows\SystemIndex\SearchRoots
ItemCount
8
2868
SearchIndexer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Search\CrawlScopeManager_PreviousVersion\Windows\SystemIndex\WorkingSetRules\0
URL
file:///C:\Users\*\AppData\Local\Microsoft\Windows\Temporary Internet Files\*
2868
SearchIndexer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Search\CrawlScopeManager_PreviousVersion\Windows\SystemIndex\WorkingSetRules\0
Include
0
2868
SearchIndexer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Search\CrawlScopeManager_PreviousVersion\Windows\SystemIndex\WorkingSetRules\0
Suppress
0
2868
SearchIndexer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Search\CrawlScopeManager_PreviousVersion\Windows\SystemIndex\WorkingSetRules\0
Default
1
2868
SearchIndexer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Search\CrawlScopeManager_PreviousVersion\Windows\SystemIndex\WorkingSetRules\0
Policy
0
2868
SearchIndexer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Search\CrawlScopeManager_PreviousVersion\Windows\SystemIndex\WorkingSetRules\1
URL
file:///C:\Users\*\AppData\Local\Temp\*
2868
SearchIndexer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Search\CrawlScopeManager_PreviousVersion\Windows\SystemIndex\WorkingSetRules\1
Include
0
2868
SearchIndexer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Search\CrawlScopeManager_PreviousVersion\Windows\SystemIndex\WorkingSetRules\1
Suppress
0
2868
SearchIndexer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Search\CrawlScopeManager_PreviousVersion\Windows\SystemIndex\WorkingSetRules\1
Default
1
2868
SearchIndexer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Search\CrawlScopeManager_PreviousVersion\Windows\SystemIndex\WorkingSetRules\1
Policy
0
2868
SearchIndexer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Search\CrawlScopeManager_PreviousVersion\Windows\SystemIndex\WorkingSetRules\10
URL
file:///C:\ProgramData\*
2868
SearchIndexer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Search\CrawlScopeManager_PreviousVersion\Windows\SystemIndex\WorkingSetRules\10
Include
0
2868
SearchIndexer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Search\CrawlScopeManager_PreviousVersion\Windows\SystemIndex\WorkingSetRules\10
Suppress
0
2868
SearchIndexer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Search\CrawlScopeManager_PreviousVersion\Windows\SystemIndex\WorkingSetRules\10
Default
1
2868
SearchIndexer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Search\CrawlScopeManager_PreviousVersion\Windows\SystemIndex\WorkingSetRules\10
Policy
0
2868
SearchIndexer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Search\CrawlScopeManager_PreviousVersion\Windows\SystemIndex\WorkingSetRules\11
URL
file:///C:\Users\
2868
SearchIndexer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Search\CrawlScopeManager_PreviousVersion\Windows\SystemIndex\WorkingSetRules\11
Include
1
2868
SearchIndexer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Search\CrawlScopeManager_PreviousVersion\Windows\SystemIndex\WorkingSetRules\11
Suppress
0
2868
SearchIndexer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Search\CrawlScopeManager_PreviousVersion\Windows\SystemIndex\WorkingSetRules\11
Default
1
2868
SearchIndexer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Search\CrawlScopeManager_PreviousVersion\Windows\SystemIndex\WorkingSetRules\11
Policy
0
2868
SearchIndexer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Search\CrawlScopeManager_PreviousVersion\Windows\SystemIndex\WorkingSetRules\12
URL
file:///C:\Windows\*
2868
SearchIndexer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Search\CrawlScopeManager_PreviousVersion\Windows\SystemIndex\WorkingSetRules\12
Include
0
2868
SearchIndexer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Search\CrawlScopeManager_PreviousVersion\Windows\SystemIndex\WorkingSetRules\12
Suppress
0
2868
SearchIndexer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Search\CrawlScopeManager_PreviousVersion\Windows\SystemIndex\WorkingSetRules\12
Default
1
2868
SearchIndexer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Search\CrawlScopeManager_PreviousVersion\Windows\SystemIndex\WorkingSetRules\12
Policy
0
2868
SearchIndexer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Search\CrawlScopeManager_PreviousVersion\Windows\SystemIndex\WorkingSetRules\13
URL
file:///C:\Windows.*\*
2868
SearchIndexer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Search\CrawlScopeManager_PreviousVersion\Windows\SystemIndex\WorkingSetRules\13
Include
0
2868
SearchIndexer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Search\CrawlScopeManager_PreviousVersion\Windows\SystemIndex\WorkingSetRules\13
Suppress
0
2868
SearchIndexer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Search\CrawlScopeManager_PreviousVersion\Windows\SystemIndex\WorkingSetRules\13
Default
1
2868
SearchIndexer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Search\CrawlScopeManager_PreviousVersion\Windows\SystemIndex\WorkingSetRules\13
Policy
0
2868
SearchIndexer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Search\CrawlScopeManager_PreviousVersion\Windows\SystemIndex\WorkingSetRules\14
URL
file:///*\$RECYCLE.BIN\*
2868
SearchIndexer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Search\CrawlScopeManager_PreviousVersion\Windows\SystemIndex\WorkingSetRules\14
Include
0
2868
SearchIndexer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Search\CrawlScopeManager_PreviousVersion\Windows\SystemIndex\WorkingSetRules\14
Suppress
0
2868
SearchIndexer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Search\CrawlScopeManager_PreviousVersion\Windows\SystemIndex\WorkingSetRules\14
Default
1
2868
SearchIndexer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Search\CrawlScopeManager_PreviousVersion\Windows\SystemIndex\WorkingSetRules\14
Policy
0
2868
SearchIndexer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Search\CrawlScopeManager_PreviousVersion\Windows\SystemIndex\WorkingSetRules\15
URL
file:///*\DfsrPrivate\*
2868
SearchIndexer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Search\CrawlScopeManager_PreviousVersion\Windows\SystemIndex\WorkingSetRules\15
Include
0
2868
SearchIndexer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Search\CrawlScopeManager_PreviousVersion\Windows\SystemIndex\WorkingSetRules\15
Suppress
0
2868
SearchIndexer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Search\CrawlScopeManager_PreviousVersion\Windows\SystemIndex\WorkingSetRules\15
Default
1
2868
SearchIndexer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Search\CrawlScopeManager_PreviousVersion\Windows\SystemIndex\WorkingSetRules\15
Policy
0
2868
SearchIndexer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Search\CrawlScopeManager_PreviousVersion\Windows\SystemIndex\WorkingSetRules\16
URL
file:///*\System Volume Information\*
2868
SearchIndexer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Search\CrawlScopeManager_PreviousVersion\Windows\SystemIndex\WorkingSetRules\16
Include
0
2868
SearchIndexer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Search\CrawlScopeManager_PreviousVersion\Windows\SystemIndex\WorkingSetRules\16
Suppress
0
2868
SearchIndexer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Search\CrawlScopeManager_PreviousVersion\Windows\SystemIndex\WorkingSetRules\16
Default
1
2868
SearchIndexer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Search\CrawlScopeManager_PreviousVersion\Windows\SystemIndex\WorkingSetRules\16
Policy
0
2868
SearchIndexer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Search\CrawlScopeManager_PreviousVersion\Windows\SystemIndex\WorkingSetRules\17
URL
csc://{S-1-5-21-1302019708-1500728564-335382590-1000}/
2868
SearchIndexer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Search\CrawlScopeManager_PreviousVersion\Windows\SystemIndex\WorkingSetRules\17
Include
1
2868
SearchIndexer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Search\CrawlScopeManager_PreviousVersion\Windows\SystemIndex\WorkingSetRules\17
Suppress
0
2868
SearchIndexer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Search\CrawlScopeManager_PreviousVersion\Windows\SystemIndex\WorkingSetRules\17
Default
1
2868
SearchIndexer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Search\CrawlScopeManager_PreviousVersion\Windows\SystemIndex\WorkingSetRules\17
Policy
0
2868
SearchIndexer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Search\CrawlScopeManager_PreviousVersion\Windows\SystemIndex\WorkingSetRules\18
URL
csc://{S-1-5-21-1302019708-1500728564-335382590-500}/
2868
SearchIndexer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Search\CrawlScopeManager_PreviousVersion\Windows\SystemIndex\WorkingSetRules\18
Include
1
2868
SearchIndexer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Search\CrawlScopeManager_PreviousVersion\Windows\SystemIndex\WorkingSetRules\18
Suppress
0
2868
SearchIndexer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Search\CrawlScopeManager_PreviousVersion\Windows\SystemIndex\WorkingSetRules\18
Default
1
2868
SearchIndexer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Search\CrawlScopeManager_PreviousVersion\Windows\SystemIndex\WorkingSetRules\18
Policy
0
2868
SearchIndexer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Search\CrawlScopeManager_PreviousVersion\Windows\SystemIndex\WorkingSetRules\19
URL
iehistory://{S-1-5-21-1302019708-1500728564-335382590-1000}/
2868
SearchIndexer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Search\CrawlScopeManager_PreviousVersion\Windows\SystemIndex\WorkingSetRules\19
Include
1
2868
SearchIndexer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Search\CrawlScopeManager_PreviousVersion\Windows\SystemIndex\WorkingSetRules\19
Suppress
0
2868
SearchIndexer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Search\CrawlScopeManager_PreviousVersion\Windows\SystemIndex\WorkingSetRules\19
Default
1
2868
SearchIndexer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Search\CrawlScopeManager_PreviousVersion\Windows\SystemIndex\WorkingSetRules\19
Policy
0
2868
SearchIndexer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Search\CrawlScopeManager_PreviousVersion\Windows\SystemIndex\WorkingSetRules\2
URL
file:///C:\ProgramData\Microsoft\Search\Data\*
2868
SearchIndexer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Search\CrawlScopeManager_PreviousVersion\Windows\SystemIndex\WorkingSetRules\2
Include
0
2868
SearchIndexer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Search\CrawlScopeManager_PreviousVersion\Windows\SystemIndex\WorkingSetRules\2
Suppress
0
2868
SearchIndexer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Search\CrawlScopeManager_PreviousVersion\Windows\SystemIndex\WorkingSetRules\2
Default
1
2868
SearchIndexer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Search\CrawlScopeManager_PreviousVersion\Windows\SystemIndex\WorkingSetRules\2
Policy
0
2868
SearchIndexer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Search\CrawlScopeManager_PreviousVersion\Windows\SystemIndex\WorkingSetRules\20
URL
mapi://{S-1-5-21-1302019708-1500728564-335382590-1000}/
2868
SearchIndexer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Search\CrawlScopeManager_PreviousVersion\Windows\SystemIndex\WorkingSetRules\20
Include
1
2868
SearchIndexer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Search\CrawlScopeManager_PreviousVersion\Windows\SystemIndex\WorkingSetRules\20
Suppress
0
2868
SearchIndexer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Search\CrawlScopeManager_PreviousVersion\Windows\SystemIndex\WorkingSetRules\20
Default
0
2868
SearchIndexer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Search\CrawlScopeManager_PreviousVersion\Windows\SystemIndex\WorkingSetRules\20
Policy
0
2868
SearchIndexer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Search\CrawlScopeManager_PreviousVersion\Windows\SystemIndex\WorkingSetRules\21
URL
ONEINDEX14://{S-1-5-21-1302019708-1500728564-335382590-1000}/
2868
SearchIndexer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Search\CrawlScopeManager_PreviousVersion\Windows\SystemIndex\WorkingSetRules\21
Include
1
2868
SearchIndexer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Search\CrawlScopeManager_PreviousVersion\Windows\SystemIndex\WorkingSetRules\21
Suppress
0
2868
SearchIndexer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Search\CrawlScopeManager_PreviousVersion\Windows\SystemIndex\WorkingSetRules\21
Default
0
2868
SearchIndexer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Search\CrawlScopeManager_PreviousVersion\Windows\SystemIndex\WorkingSetRules\21
Policy
0
2868
SearchIndexer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Search\CrawlScopeManager_PreviousVersion\Windows\SystemIndex\WorkingSetRules\3
URL
file:///C:\ProgramData\Microsoft\Windows\Start Menu\
2868
SearchIndexer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Search\CrawlScopeManager_PreviousVersion\Windows\SystemIndex\WorkingSetRules\3
Include
1
2868
SearchIndexer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Search\CrawlScopeManager_PreviousVersion\Windows\SystemIndex\WorkingSetRules\3
Suppress
0
2868
SearchIndexer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Search\CrawlScopeManager_PreviousVersion\Windows\SystemIndex\WorkingSetRules\3
Default
1
2868
SearchIndexer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Search\CrawlScopeManager_PreviousVersion\Windows\SystemIndex\WorkingSetRules\3
Policy
0
2868
SearchIndexer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Search\CrawlScopeManager_PreviousVersion\Windows\SystemIndex\WorkingSetRules\4
URL
file:///C:\Users\admin\AppData\*
2868
SearchIndexer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Search\CrawlScopeManager_PreviousVersion\Windows\SystemIndex\WorkingSetRules\4
Include
0
2868
SearchIndexer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Search\CrawlScopeManager_PreviousVersion\Windows\SystemIndex\WorkingSetRules\4
Suppress
0
2868
SearchIndexer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Search\CrawlScopeManager_PreviousVersion\Windows\SystemIndex\WorkingSetRules\4
Default
1
2868
SearchIndexer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Search\CrawlScopeManager_PreviousVersion\Windows\SystemIndex\WorkingSetRules\4
Policy
0
2868
SearchIndexer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Search\CrawlScopeManager_PreviousVersion\Windows\SystemIndex\WorkingSetRules\5
URL
file:///C:\Users\admin\Favorites\
2868
SearchIndexer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Search\CrawlScopeManager_PreviousVersion\Windows\SystemIndex\WorkingSetRules\5
Include
1
2868
SearchIndexer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Search\CrawlScopeManager_PreviousVersion\Windows\SystemIndex\WorkingSetRules\5
Suppress
0
2868
SearchIndexer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Search\CrawlScopeManager_PreviousVersion\Windows\SystemIndex\WorkingSetRules\5
Default
1
2868
SearchIndexer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Search\CrawlScopeManager_PreviousVersion\Windows\SystemIndex\WorkingSetRules\5
Policy
0
2868
SearchIndexer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Search\CrawlScopeManager_PreviousVersion\Windows\SystemIndex\WorkingSetRules\6
URL
file:///C:\Users\Administrator\AppData\*
2868
SearchIndexer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Search\CrawlScopeManager_PreviousVersion\Windows\SystemIndex\WorkingSetRules\6
Include
0
2868
SearchIndexer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Search\CrawlScopeManager_PreviousVersion\Windows\SystemIndex\WorkingSetRules\6
Suppress
0
2868
SearchIndexer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Search\CrawlScopeManager_PreviousVersion\Windows\SystemIndex\WorkingSetRules\6
Default
1
2868
SearchIndexer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Search\CrawlScopeManager_PreviousVersion\Windows\SystemIndex\WorkingSetRules\6
Policy
0
2868
SearchIndexer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Search\CrawlScopeManager_PreviousVersion\Windows\SystemIndex\WorkingSetRules\7
URL
file:///C:\Users\Default\AppData\*
2868
SearchIndexer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Search\CrawlScopeManager_PreviousVersion\Windows\SystemIndex\WorkingSetRules\7
Include
0
2868
SearchIndexer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Search\CrawlScopeManager_PreviousVersion\Windows\SystemIndex\WorkingSetRules\7
Suppress
0
2868
SearchIndexer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Search\CrawlScopeManager_PreviousVersion\Windows\SystemIndex\WorkingSetRules\7
Default
1
2868
SearchIndexer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Search\CrawlScopeManager_PreviousVersion\Windows\SystemIndex\WorkingSetRules\7
Policy
0
2868
SearchIndexer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Search\CrawlScopeManager_PreviousVersion\Windows\SystemIndex\WorkingSetRules\8
URL
file:///C:\Windows\*\temp\*
2868
SearchIndexer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Search\CrawlScopeManager_PreviousVersion\Windows\SystemIndex\WorkingSetRules\8
Include
0
2868
SearchIndexer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Search\CrawlScopeManager_PreviousVersion\Windows\SystemIndex\WorkingSetRules\8
Suppress
0
2868
SearchIndexer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Search\CrawlScopeManager_PreviousVersion\Windows\SystemIndex\WorkingSetRules\8
Default
1
2868
SearchIndexer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Search\CrawlScopeManager_PreviousVersion\Windows\SystemIndex\WorkingSetRules\8
Policy
0
2868
SearchIndexer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Search\CrawlScopeManager_PreviousVersion\Windows\SystemIndex\WorkingSetRules\9
URL
file:///C:\Windows\CSC\*
2868
SearchIndexer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Search\CrawlScopeManager_PreviousVersion\Windows\SystemIndex\WorkingSetRules\9
Include
0
2868
SearchIndexer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Search\CrawlScopeManager_PreviousVersion\Windows\SystemIndex\WorkingSetRules\9
Suppress
0
2868
SearchIndexer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Search\CrawlScopeManager_PreviousVersion\Windows\SystemIndex\WorkingSetRules\9
Default
1
2868
SearchIndexer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Search\CrawlScopeManager_PreviousVersion\Windows\SystemIndex\WorkingSetRules\9
Policy
0
2868
SearchIndexer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Search\CrawlScopeManager_PreviousVersion\Windows\SystemIndex\WorkingSetRules
ItemCount
22
2868
SearchIndexer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Search\PreviousSettings\Extensions
IncludedExtensions
0
2868
SearchIndexer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Search
SetupCompletedSuccessfully
0
2868
SearchIndexer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Search\Tracing\EventThrottleState
000003f0
01000000737005BC030C00000100000000000000
2868
SearchIndexer.exe
delete key
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Search\Applications\Windows
2868
SearchIndexer.exe
delete key
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Search\CatalogNames\Windows\SystemIndex
2868
SearchIndexer.exe
delete key
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Search\CatalogNames\Windows
2868
SearchIndexer.exe
delete key
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Search\Databases\Windows
2868
SearchIndexer.exe
delete key
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Search\Gather\Windows\SystemIndex\Crawls
2868
SearchIndexer.exe
delete key
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Search\Gather\Windows\SystemIndex\Extensions\ExtensionList
2868
SearchIndexer.exe
delete key
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Search\Gather\Windows\SystemIndex\Extensions
2868
SearchIndexer.exe
delete key
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Search\Gather\Windows\SystemIndex\Mappings
2868
SearchIndexer.exe
delete key
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Search\Gather\Windows\SystemIndex\Protocols\Csc\0
2868
SearchIndexer.exe
delete key
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Search\Gather\Windows\SystemIndex\Protocols\Csc
2868
SearchIndexer.exe
delete key
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Search\Gather\Windows\SystemIndex\Protocols\File\0
2868
SearchIndexer.exe
delete key
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Search\Gather\Windows\SystemIndex\Protocols\File
2868
SearchIndexer.exe
delete key
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Search\Gather\Windows\SystemIndex\Protocols\IEHistory\0
2868
SearchIndexer.exe
delete key
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Search\Gather\Windows\SystemIndex\Protocols\IEHistory
2868
SearchIndexer.exe
delete key
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Search\Gather\Windows\SystemIndex\Protocols\IERSS\0
2868
SearchIndexer.exe
delete key
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Search\Gather\Windows\SystemIndex\Protocols\IERSS
2868
SearchIndexer.exe
delete key
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Search\Gather\Windows\SystemIndex\Protocols\Mapi\0
2868
SearchIndexer.exe
delete key
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Search\Gather\Windows\SystemIndex\Protocols\Mapi
2868
SearchIndexer.exe
delete key
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Search\Gather\Windows\SystemIndex\Protocols\OneIndex14\0
2868
SearchIndexer.exe
delete key
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Search\Gather\Windows\SystemIndex\Protocols\OneIndex14
2868
SearchIndexer.exe
delete key
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Search\Gather\Windows\SystemIndex\Protocols\StickyNotes\0
2868
SearchIndexer.exe
delete key
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Search\Gather\Windows\SystemIndex\Protocols\StickyNotes
2868
SearchIndexer.exe
delete key
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Search\Gather\Windows\SystemIndex\Protocols
2868
SearchIndexer.exe
delete key
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Search\Gather\Windows\SystemIndex\Sites\LocalHost\Paths\0
2868
SearchIndexer.exe
delete key
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Search\Gather\Windows\SystemIndex\Sites\LocalHost\Paths\1
2868
SearchIndexer.exe
delete key
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Search\Gather\Windows\SystemIndex\Sites\LocalHost\Paths\10
2868
SearchIndexer.exe
delete key
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Search\Gather\Windows\SystemIndex\Sites\LocalHost\Paths\11
2868
SearchIndexer.exe
delete key
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Search\Gather\Windows\SystemIndex\Sites\LocalHost\Paths\12
2868
SearchIndexer.exe
delete key
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Search\Gather\Windows\SystemIndex\Sites\LocalHost\Paths\13
2868
SearchIndexer.exe
delete key
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Search\Gather\Windows\SystemIndex\Sites\LocalHost\Paths\14
2868
SearchIndexer.exe
delete key
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Search\Gather\Windows\SystemIndex\Sites\LocalHost\Paths\15
2868
SearchIndexer.exe
delete key
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Search\Gather\Windows\SystemIndex\Sites\LocalHost\Paths\2
2868
SearchIndexer.exe
delete key
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Search\Gather\Windows\SystemIndex\Sites\LocalHost\Paths\3
2868
SearchIndexer.exe
delete key
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Search\Gather\Windows\SystemIndex\Sites\LocalHost\Paths\4
2868
SearchIndexer.exe
delete key
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Search\Gather\Windows\SystemIndex\Sites\LocalHost\Paths\5
2868
SearchIndexer.exe
delete key
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Search\Gather\Windows\SystemIndex\Sites\LocalHost\Paths\6
2868
SearchIndexer.exe
delete key
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Search\Gather\Windows\SystemIndex\Sites\LocalHost\Paths\7
2868
SearchIndexer.exe
delete key
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Search\Gather\Windows\SystemIndex\Sites\LocalHost\Paths\8
2868
SearchIndexer.exe
delete key
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Search\Gather\Windows\SystemIndex\Sites\LocalHost\Paths\9
2868
SearchIndexer.exe
delete key
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Search\Gather\Windows\SystemIndex\Sites\LocalHost\Paths
2868
SearchIndexer.exe
delete key
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Search\Gather\Windows\SystemIndex\Sites\LocalHost
2868
SearchIndexer.exe
delete key
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Search\Gather\Windows\SystemIndex\Sites\{S-1-5-21-1302019708-1500728564-335382590-1000}\Paths\0
2868
SearchIndexer.exe
delete key
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Search\Gather\Windows\SystemIndex\Sites\{S-1-5-21-1302019708-1500728564-335382590-1000}\Paths\1
2868
SearchIndexer.exe
delete key
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Search\Gather\Windows\SystemIndex\Sites\{S-1-5-21-1302019708-1500728564-335382590-1000}\Paths\2
2868
SearchIndexer.exe
delete key
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Search\Gather\Windows\SystemIndex\Sites\{S-1-5-21-1302019708-1500728564-335382590-1000}\Paths\3
2868
SearchIndexer.exe
delete key
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Search\Gather\Windows\SystemIndex\Sites\{S-1-5-21-1302019708-1500728564-335382590-1000}\Paths
2868
SearchIndexer.exe
delete key
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Search\Gather\Windows\SystemIndex\Sites\{S-1-5-21-1302019708-1500728564-335382590-1000}
2868
SearchIndexer.exe
delete key
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Search\Gather\Windows\SystemIndex\Sites\{S-1-5-21-1302019708-1500728564-335382590-500}\Paths\0
2868
SearchIndexer.exe
delete key
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Search\Gather\Windows\SystemIndex\Sites\{S-1-5-21-1302019708-1500728564-335382590-500}\Paths
2868
SearchIndexer.exe
delete key
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Search\Gather\Windows\SystemIndex\Sites\{S-1-5-21-1302019708-1500728564-335382590-500}
2868
SearchIndexer.exe
delete key
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Search\Gather\Windows\SystemIndex\Sites
2868
SearchIndexer.exe
delete key
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Search\Gather\Windows\SystemIndex\StartPages\0
2868
SearchIndexer.exe
delete key
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Search\Gather\Windows\SystemIndex\StartPages\1
2868
SearchIndexer.exe
delete key
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Search\Gather\Windows\SystemIndex\StartPages\2
2868
SearchIndexer.exe
delete key
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Search\Gather\Windows\SystemIndex\StartPages\3
2868
SearchIndexer.exe
delete key
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Search\Gather\Windows\SystemIndex\StartPages\5
2868
SearchIndexer.exe
delete key
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Search\Gather\Windows\SystemIndex\StartPages\6
2868
SearchIndexer.exe
delete key
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Search\Gather\Windows\SystemIndex\StartPages\7
2868
SearchIndexer.exe
delete key
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Search\Gather\Windows\SystemIndex\StartPages
2868
SearchIndexer.exe
delete key
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Search\Gather\Windows\SystemIndex\StreamLog
2868
SearchIndexer.exe
delete key
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Search\Gather\Windows\SystemIndex
2868
SearchIndexer.exe
delete key
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Search\Gather\Windows
2868
SearchIndexer.exe
delete key
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Search\Gathering Manager\Applications\Windows\PluginManagers\0
2868
SearchIndexer.exe
delete key
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Search\Gathering Manager\Applications\Windows\PluginManagers\1
2868
SearchIndexer.exe
delete key
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Search\Gathering Manager\Applications\Windows\PluginManagers\2
2868
SearchIndexer.exe
delete key
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Search\Gathering Manager\Applications\Windows\PluginManagers
2868
SearchIndexer.exe
delete key
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Search\Gathering Manager\Applications\Windows\Projects\SystemIndex\ActivePlugins\0
2868
SearchIndexer.exe
delete key
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Search\Gathering Manager\Applications\Windows\Projects\SystemIndex\ActivePlugins
2868
SearchIndexer.exe
delete key
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Search\Gathering Manager\Applications\Windows\Projects\SystemIndex\Plugins\0
2868
SearchIndexer.exe
delete key
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Search\Gathering Manager\Applications\Windows\Projects\SystemIndex\Plugins\1
2868
SearchIndexer.exe
delete key
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Search\Gathering Manager\Applications\Windows\Projects\SystemIndex\Plugins
2868
SearchIndexer.exe
delete key
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Search\Gathering Manager\Applications\Windows\Projects\SystemIndex
2868
SearchIndexer.exe
delete key
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Search\Gathering Manager\Applications\Windows\Projects
2868
SearchIndexer.exe
delete key
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Search\Gathering Manager\Applications\Windows
2868
SearchIndexer.exe
delete key
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Search\UsnNotifier\Windows\Catalogs\SystemIndex
2868
SearchIndexer.exe
delete key
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Search\UsnNotifier\Windows\Catalogs
2868
SearchIndexer.exe
delete key
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Search\UsnNotifier\Windows\Volumes\{E1A82DB4-A9F0-11E7-B142-806E6F6E6963}
2868
SearchIndexer.exe
delete key
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Search\UsnNotifier\Windows\Volumes
2868
SearchIndexer.exe
delete key
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Search\UsnNotifier\Windows
2868
SearchIndexer.exe
delete key
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Search\CrawlScopeManager\Windows\SystemIndex\DefaultRules\0
2868
SearchIndexer.exe
delete key
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Search\CrawlScopeManager\Windows\SystemIndex\DefaultRules\1
2868
SearchIndexer.exe
delete key
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Search\CrawlScopeManager\Windows\SystemIndex\DefaultRules\10
2868
SearchIndexer.exe
delete key
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Search\CrawlScopeManager\Windows\SystemIndex\DefaultRules\11
2868
SearchIndexer.exe
delete key
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Search\CrawlScopeManager\Windows\SystemIndex\DefaultRules\12
2868
SearchIndexer.exe
delete key
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Search\CrawlScopeManager\Windows\SystemIndex\DefaultRules\13
2868
SearchIndexer.exe
delete key
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Search\CrawlScopeManager\Windows\SystemIndex\DefaultRules\14
2868
SearchIndexer.exe
delete key
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Search\CrawlScopeManager\Windows\SystemIndex\DefaultRules\15
2868
SearchIndexer.exe
delete key
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Search\CrawlScopeManager\Windows\SystemIndex\DefaultRules\16
2868
SearchIndexer.exe
delete key
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Search\CrawlScopeManager\Windows\SystemIndex\DefaultRules\17
2868
SearchIndexer.exe
delete key
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Search\CrawlScopeManager\Windows\SystemIndex\DefaultRules\18
2868
SearchIndexer.exe
delete key
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Search\CrawlScopeManager\Windows\SystemIndex\DefaultRules\19
2868
SearchIndexer.exe
delete key
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Search\CrawlScopeManager\Windows\SystemIndex\DefaultRules\2
2868
SearchIndexer.exe
delete key
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Search\CrawlScopeManager\Windows\SystemIndex\DefaultRules\3
2868
SearchIndexer.exe
delete key
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Search\CrawlScopeManager\Windows\SystemIndex\DefaultRules\4
2868
SearchIndexer.exe
delete key
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Search\CrawlScopeManager\Windows\SystemIndex\DefaultRules\5
2868
SearchIndexer.exe
delete key
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Search\CrawlScopeManager\Windows\SystemIndex\DefaultRules\6
2868
SearchIndexer.exe
delete key
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Search\CrawlScopeManager\Windows\SystemIndex\DefaultRules\7
2868
SearchIndexer.exe
delete key
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Search\CrawlScopeManager\Windows\SystemIndex\DefaultRules\8
2868
SearchIndexer.exe
delete key
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Search\CrawlScopeManager\Windows\SystemIndex\DefaultRules\9
2868
SearchIndexer.exe
delete key
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Search\CrawlScopeManager\Windows\SystemIndex\DefaultRules
2868
SearchIndexer.exe
delete key
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Search\CrawlScopeManager\Windows\SystemIndex\SearchRoots\0
2868
SearchIndexer.exe
delete key
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Search\CrawlScopeManager\Windows\SystemIndex\SearchRoots\1
2868
SearchIndexer.exe
delete key
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Search\CrawlScopeManager\Windows\SystemIndex\SearchRoots\2
2868
SearchIndexer.exe
delete key
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Search\CrawlScopeManager\Windows\SystemIndex\SearchRoots\3
2868
SearchIndexer.exe
delete key
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Search\CrawlScopeManager\Windows\SystemIndex\SearchRoots\4
2868
SearchIndexer.exe
delete key
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Search\CrawlScopeManager\Windows\SystemIndex\SearchRoots\5
2868
SearchIndexer.exe
delete key
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Search\CrawlScopeManager\Windows\SystemIndex\SearchRoots\6
2868
SearchIndexer.exe
delete key
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Search\CrawlScopeManager\Windows\SystemIndex\SearchRoots\7
2868
SearchIndexer.exe
delete key
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Search\CrawlScopeManager\Windows\SystemIndex\SearchRoots
2868
SearchIndexer.exe
delete key
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Search\CrawlScopeManager\Windows\SystemIndex\WorkingSetRules\0
2868
SearchIndexer.exe
delete key
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Search\CrawlScopeManager\Windows\SystemIndex\WorkingSetRules\1
2868
SearchIndexer.exe
delete key
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Search\CrawlScopeManager\Windows\SystemIndex\WorkingSetRules\10
2868
SearchIndexer.exe
delete key
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Search\CrawlScopeManager\Windows\SystemIndex\WorkingSetRules\11
2868
SearchIndexer.exe
delete key
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Search\CrawlScopeManager\Windows\SystemIndex\WorkingSetRules\12
2868
SearchIndexer.exe
delete key
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Search\CrawlScopeManager\Windows\SystemIndex\WorkingSetRules\13
2868
SearchIndexer.exe
delete key
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Search\CrawlScopeManager\Windows\SystemIndex\WorkingSetRules\14
2868
SearchIndexer.exe
delete key
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Search\CrawlScopeManager\Windows\SystemIndex\WorkingSetRules\15
2868
SearchIndexer.exe
delete key
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Search\CrawlScopeManager\Windows\SystemIndex\WorkingSetRules\16
2868
SearchIndexer.exe
delete key
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Search\CrawlScopeManager\Windows\SystemIndex\WorkingSetRules\17
2868
SearchIndexer.exe
delete key
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Search\CrawlScopeManager\Windows\SystemIndex\WorkingSetRules\18
2868
SearchIndexer.exe
delete key
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Search\CrawlScopeManager\Windows\SystemIndex\WorkingSetRules\19
2868
SearchIndexer.exe
delete key
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Search\CrawlScopeManager\Windows\SystemIndex\WorkingSetRules\2
2868
SearchIndexer.exe
delete key
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Search\CrawlScopeManager\Windows\SystemIndex\WorkingSetRules\20
2868
SearchIndexer.exe
delete key
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Search\CrawlScopeManager\Windows\SystemIndex\WorkingSetRules\21
2868
SearchIndexer.exe
delete key
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Search\CrawlScopeManager\Windows\SystemIndex\WorkingSetRules\3
2868
SearchIndexer.exe
delete key
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Search\CrawlScopeManager\Windows\SystemIndex\WorkingSetRules\4
2868
SearchIndexer.exe
delete key
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Search\CrawlScopeManager\Windows\SystemIndex\WorkingSetRules\5
2868
SearchIndexer.exe
delete key
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Search\CrawlScopeManager\Windows\SystemIndex\WorkingSetRules\6
2868
SearchIndexer.exe
delete key
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Search\CrawlScopeManager\Windows\SystemIndex\WorkingSetRules\7
2868
SearchIndexer.exe
delete key
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Search\CrawlScopeManager\Windows\SystemIndex\WorkingSetRules\8
2868
SearchIndexer.exe
delete key
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Search\CrawlScopeManager\Windows\SystemIndex\WorkingSetRules\9
2868
SearchIndexer.exe
delete key
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Search\CrawlScopeManager\Windows\SystemIndex\WorkingSetRules
2868
SearchIndexer.exe
delete key
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Search\CrawlScopeManager\Windows\SystemIndex
2868
SearchIndexer.exe
delete key
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Search\CrawlScopeManager\Windows
2868
SearchIndexer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Search\Tracing\EventThrottleState
000003f2
010000002E7105BC030C00000100000000000000
2868
SearchIndexer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Search\Gathering Manager
UseSystemTemp
0
2868
SearchIndexer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Search\Tracing\EventThrottleState
000003ec
010000007D7105BC030C00000100000000000000
2868
SearchIndexer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Search
SystemIndexNormalization
1
2868
SearchIndexer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Search\Gathering Manager\Applications\Windows
GathererPlugin
Search.Gatherer
2868
SearchIndexer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Search\Gathering Manager\Applications\Windows
ApplicationPath
C:\ProgramData\Microsoft\Search\Data\Applications\Windows\
2868
SearchIndexer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Search\Gathering Manager\Applications\Windows
DefaultProjectPath
C:\ProgramData\Microsoft\Search\Data\Applications\Windows\Projects
2868
SearchIndexer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Search\Gathering Manager\Applications\Windows
DefaultCatalogConfigUrl
Software\Microsoft\Windows Search
2868
SearchIndexer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Search\Gathering Manager\Applications\Windows
GatherLogsPath
C:\ProgramData\Microsoft\Search\Data\Applications\Windows\GatherLogs
2868
SearchIndexer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Search\Gathering Manager\Applications\Windows
DisplayName
Windows
2868
SearchIndexer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Search\Gathering Manager\Applications\Windows
DataTimeout
0
2868
SearchIndexer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Search\Gathering Manager\Applications\Windows
ConnectTimeout
0
2868
SearchIndexer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Search\Gathering Manager\Applications\Windows
RetryLimit
0
2868
SearchIndexer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Search\Gathering Manager\Applications\Windows
UseClustering
0
2868
SearchIndexer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Search\Gathering Manager\Applications\Windows
FilterSecurity
1
2868
SearchIndexer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Search\Gathering Manager\Applications\Windows
AccessControl
99CABADE02000000020000000000000000000000070000000100000000000000000000000700000000000000
2868
SearchIndexer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Search\Gathering Manager\Applications\Windows
AccessControl
99CABADE0300000002000000000000000000000007000000010000000000000000000000070000000000000000000000000000000100000002000000
2868
SearchIndexer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Search\Applications\Windows
PropStoreDB
Windows
2868
SearchIndexer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Search\Databases\Windows
FileName
C:\ProgramData\Microsoft\Search\Data\\Windows\Windows.edb
2868
SearchIndexer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Search\Databases\Windows
LogPath
C:\ProgramData\Microsoft\Search\Data\\Windows\
2868
SearchIndexer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Search\Databases\Windows
FileName
C:\ProgramData\Microsoft\Search\Data\Applications\Windows\Windows.edb
2868
SearchIndexer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Search\Databases\Windows
LogPath
C:\ProgramData\Microsoft\Search\Data\Applications\Windows\
2868
SearchIndexer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Search\Gathering Manager\Applications\Windows\PluginManagers\0
ProgId
Search.JetPropStore
2868
SearchIndexer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Search\Gathering Manager\Applications\Windows\PluginManagers\1
ProgId
Search.TripoliIndexer
2868
SearchIndexer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Search\Gathering Manager\Applications\Windows\PluginManagers\2
ProgId
Search.MapPI
2868
SearchIndexer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Search\CatalogNames\Windows
gatherer:use-check-points
4294967295
2868
SearchIndexer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Search\CatalogNames\Windows\SystemIndex
CatalogID
1
2868
SearchIndexer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Search\CatalogNames\Windows
CatalogID
2
2868
SearchIndexer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Search\CatalogNames\Windows\SystemIndex
CatalogURL
Software\Microsoft\Windows Search
2868
SearchIndexer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Search\CatalogNames\Windows\SystemIndex
StartAddressConfigURL
2868
SearchIndexer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Search\Gathering Manager\Applications\Windows\Projects\SystemIndex
WorkingDirectory
C:\ProgramData\Microsoft\Search\Data\Applications\Windows\Projects\SystemIndex
2868
SearchIndexer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Search\Gathering Manager\Applications\Windows\Projects\SystemIndex
LazyLoad
0
2868
SearchIndexer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Search\Gathering Manager\Applications\Windows\Projects\SystemIndex
CrawlInterval
0
2868
SearchIndexer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Search\Gathering Manager\Applications\Windows\Projects\SystemIndex
AccessControl
99CABADE02000000020000000000000000000000070000000100000000000000000000000700000000000000
2868
SearchIndexer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Search\Gathering Manager\Applications\Windows\Projects\SystemIndex
AccessControl
99CABADE0300000002000000000000000000000007000000010000000000000000000000070000000000000000000000000000000100000002000000
2868
SearchIndexer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Search\CatalogNames\Windows\SystemIndex
IgnoreShortcuts
0
2868
SearchIndexer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Search\Gather\Windows\SystemIndex\Extensions
IncludedExtensions
0
2868
SearchIndexer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Search\Gather\Windows\SystemIndex\StartPages
NewStartPageIdentifier
0
2868
SearchIndexer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Search\Gather\Windows\SystemIndex\Protocols\Csc\0
Included
1
2868
SearchIndexer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Search\Gather\Windows\SystemIndex\Protocols\Csc\0
ProgIdHandler
Search.CscHandler.1
2868
SearchIndexer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Search\Gather\Windows\SystemIndex\Protocols\File\0
Included
1
2868
SearchIndexer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Search\Gather\Windows\SystemIndex\Protocols\File\0
ProgIdHandler
Search.FileHandler.1
2868
SearchIndexer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Search\Gather\Windows\SystemIndex\Protocols\Mapi\0
Included
1
2868
SearchIndexer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Search\Gather\Windows\SystemIndex\Protocols\Mapi\0
ProgIdHandler
Outlook.Search.MAPIHandler.1
2868
SearchIndexer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Search\Gather\Windows\SystemIndex\Protocols\StickyNotes\0
Included
1
2868
SearchIndexer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Search\Gather\Windows\SystemIndex\Protocols\StickyNotes\0
ProgIdHandler
Search.StickyNotesHandler.1
2868
SearchIndexer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Search\Gather\Windows\SystemIndex\Protocols\IEHistory\0
Included
1
2868
SearchIndexer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Search\Gather\Windows\SystemIndex\Protocols\IEHistory\0
ProgIdHandler
IEPH.HistoryHandler
2868
SearchIndexer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Search\Gather\Windows\SystemIndex\Protocols\IERSS\0
Included
1
2868
SearchIndexer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Search\Gather\Windows\SystemIndex\Protocols\IERSS\0
ProgIdHandler
IEPH.RSSHandler
2868
SearchIndexer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Search\Gather\Windows\SystemIndex\Protocols\OneIndex14\0
Included
1
2868
SearchIndexer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Search\Gather\Windows\SystemIndex\Protocols\OneIndex14\0
ProgIdHandler
Search.OneIndexHandler.2
2868
SearchIndexer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Search\Gather\Windows\SystemIndex
LogDirectory
C:\ProgramData\Microsoft\Search\Data\Applications\Windows\Projects\SystemIndex
2868
SearchIndexer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Search\Gather\Windows\SystemIndex
StreamLogsDirectory
C:\ProgramData\Microsoft\Search\Data\Applications\Windows\GatherLogs
2868
SearchIndexer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Search\Gather\Windows\SystemIndex\StreamLog
CurrentStreamLog
1
2868
SearchIndexer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Search\Gather\Windows\SystemIndex\StreamLog
MaxLogs
5
2868
SearchIndexer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Search\Gather\Windows\SystemIndex\StreamLog
StreamLogCount
0
2868
SearchIndexer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Search\Gather\Windows\SystemIndex\StreamLog
CurrentStreamLog
2
2868
SearchIndexer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Search\Gather\Windows\SystemIndex\StreamLog
StreamLogCount
1
2868
SearchIndexer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Search\Gather\Windows\SystemIndex
NewCrawlNumber
0
2868
SearchIndexer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Search\Gather\Windows\SystemIndex
NewClientID
1
2868
SearchIndexer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Search\Gather\Windows\SystemIndex
SystemLcid
1033
2868
SearchIndexer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Search\Gather\Windows\SystemIndex
LogSuccess
0
2868
SearchIndexer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Search\Gather\Windows\SystemIndex
FollowComplexUrls
0
2868
SearchIndexer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Search\Gather\Windows\SystemIndex
DisableRecovery
0
2868
SearchIndexer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Search\Gather\Windows\SystemIndex
DisableRobotsExclusion
0
2868
SearchIndexer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Search\Gather\Windows\SystemIndex
NormalizeUrls
1
2868
SearchIndexer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Search\Gather\Windows\SystemIndex
CaseSensitiveUrls
0
2868
SearchIndexer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Search\Gather\Windows\SystemIndex
UseIncrementalCrawlDirIter
0
2868
SearchIndexer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Search\Gather\Windows\SystemIndex
ACContentSync
90
2868
SearchIndexer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Search\Gather\Windows\SystemIndex
ACRejects
0
2868
SearchIndexer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Search\Gather\Windows\SystemIndex
ACTotal
0
2868
SearchIndexer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Search\Gather\Windows\SystemIndex
ACErrorEst
4294967295
2868
SearchIndexer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Search\Gather\Windows\SystemIndex
ACErrors
0
2868
SearchIndexer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Search\Gather\Windows\SystemIndex
ACErrorSamples
0
2868
SearchIndexer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Search\Gather\Windows\SystemIndex
ACMaxNoAccess
1209600
2868
SearchIndexer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Search\Gather\Windows\SystemIndex
FilterAlways
0
2868
SearchIndexer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Search\Gather\Windows\SystemIndex
FailureUpdateInterval
86400
2868
SearchIndexer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Search\Gather\Windows\SystemIndex
LazyCheckPointUpdateInterval
86400
2868
SearchIndexer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Search\Gather\Windows\SystemIndex
EnableCheckPoint
1
2868
SearchIndexer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Search\Gather\Windows\SystemIndex
LogProviderProgId
Search.GathererLogFileProvider.1
2868
SearchIndexer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Search\Gather\Windows\SystemIndex
ACActiveProfile
ED58813CED58813CED58813CED58813CED58813CED58813CED58813CED58813CED58813CED58813CED58813CED58813CED58813CED58813CED58813CED58813CED58813CED58813CED58813C3333333F0000000000000000000000000000000000000000
2868
SearchIndexer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Search\Gather\Windows\SystemIndex
ACTrainingProfile
C6892934C6892934C6892934C6892934C6892934C6892934C6892934C6892934C6892934C6892934C6892934C6892934C6892934C6892934C6892934C6892934C6892934C6892934C68929348AE1EA360000000000000000000000000000000000000000
2868
SearchIndexer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Search\Gather\Windows\SystemIndex
CatalogResetSignature
2924af81-d204-4f46-847a-de3b68e7d9a3
2868
SearchIndexer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Search\Gather\Windows\SystemIndex
CheckPointSignature
77a9feb3-ec2f-4900-9612-360766a14c5c
2868
SearchIndexer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Search\Gather\Windows\SystemIndex
CheckPointNumber
0
2868
SearchIndexer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Search\Gathering Manager\Applications\Windows\Projects\SystemIndex\ActivePlugins
NewPluginIdentifier
0
2868
SearchIndexer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Search\Gathering Manager\Applications\Windows\Projects\SystemIndex\Plugins
NewPluginIdentifier
0
2868
SearchIndexer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Search\Gather\Windows\SystemIndex
CheckPointNumber
1
2868
SearchIndexer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Search\Gathering Manager\Applications\Windows\Projects\SystemIndex\Plugins
NewPluginIdentifier
1
2868
SearchIndexer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Search\Gathering Manager\Applications\Windows\Projects\SystemIndex\Plugins\0
ProgId
Search.JetPropStore
2868
SearchIndexer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Search\Gathering Manager\Applications\Windows\Projects\SystemIndex\Plugins\0
CreationFlags
1
2868
SearchIndexer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Search\Gathering Manager\Applications\Windows\Projects\SystemIndex\Plugins\0
PluginIdentifier
0
2868
SearchIndexer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Search\Gathering Manager\Applications\Windows\Projects\SystemIndex\Plugins\0
Disabled
0
2868
SearchIndexer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Search\Gathering Manager\Applications\Windows\Projects\SystemIndex\Plugins
NewPluginIdentifier
2
2868
SearchIndexer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Search\Gathering Manager\Applications\Windows\Projects\SystemIndex\Plugins\1
ProgId
Search.TripoliIndexer
2868
SearchIndexer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Search\Gathering Manager\Applications\Windows\Projects\SystemIndex\Plugins\1
CreationFlags
1
2868
SearchIndexer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Search\Gathering Manager\Applications\Windows\Projects\SystemIndex\Plugins\1
PluginIdentifier
1
2868
SearchIndexer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Search\Gathering Manager\Applications\Windows\Projects\SystemIndex\Plugins\1
Disabled
0
2868
SearchIndexer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Search\Gathering Manager\Applications\Windows\Projects\SystemIndex\ActivePlugins
NewPluginIdentifier
1
2868
SearchIndexer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Search\Gathering Manager\Applications\Windows\Projects\SystemIndex\ActivePlugins\0
ProgId
Search.MapPI
2868
SearchIndexer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Search\Gathering Manager\Applications\Windows\Projects\SystemIndex\ActivePlugins\0
CreationFlags
1
2868
SearchIndexer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Search\Gathering Manager\Applications\Windows\Projects\SystemIndex\ActivePlugins\0
PluginIdentifier
0
2868
SearchIndexer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Search\Gathering Manager\Applications\Windows\Projects\SystemIndex\ActivePlugins\0
Disabled
0
2868
SearchIndexer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Search\Gathering Manager\Applications\Windows
CrawlScopeVersion
1
2868
SearchIndexer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Search\Gather\Windows\SystemIndex\Sites\LocalHost
Included
1
2868
SearchIndexer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Search\Gather\Windows\SystemIndex\Sites\LocalHost
FollowComplexUrls
0
2868
SearchIndexer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Search\Gather\Windows\SystemIndex\Sites\LocalHost
ApplyToDavHref
1
2868
SearchIndexer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Search\Gather\Windows\SystemIndex\Sites\LocalHost
EvaluationOrder
0
2868
SearchIndexer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Search\Gather\Windows\SystemIndex\Sites\LocalHost
AccessControl
99CABADE0300000002000000000000000000000007000000020000000000000000000000070000000100000000000000000000000700000000000000
2868
SearchIndexer.exe
delete key
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Search\CrawlScopeManager_PreviousVersion\Windows\SystemIndex\DefaultRules\0
2868
SearchIndexer.exe
delete key
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Search\CrawlScopeManager_PreviousVersion\Windows\SystemIndex\DefaultRules\1
2868
SearchIndexer.exe
delete key
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Search\CrawlScopeManager_PreviousVersion\Windows\SystemIndex\DefaultRules\10
2868
SearchIndexer.exe
delete key
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Search\CrawlScopeManager_PreviousVersion\Windows\SystemIndex\DefaultRules\11
2868
SearchIndexer.exe
delete key
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Search\CrawlScopeManager_PreviousVersion\Windows\SystemIndex\DefaultRules\12
2868
SearchIndexer.exe
delete key
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Search\CrawlScopeManager_PreviousVersion\Windows\SystemIndex\DefaultRules\13
2868
SearchIndexer.exe
delete key
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Search\CrawlScopeManager_PreviousVersion\Windows\SystemIndex\DefaultRules\14
2868
SearchIndexer.exe
delete key
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Search\CrawlScopeManager_PreviousVersion\Windows\SystemIndex\DefaultRules\15
2868
SearchIndexer.exe
delete key
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Search\CrawlScopeManager_PreviousVersion\Windows\SystemIndex\DefaultRules\16
2868
SearchIndexer.exe
delete key
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Search\CrawlScopeManager_PreviousVersion\Windows\SystemIndex\DefaultRules\17
2868
SearchIndexer.exe
delete key
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Search\CrawlScopeManager_PreviousVersion\Windows\SystemIndex\DefaultRules\18
2868
SearchIndexer.exe
delete key
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Search\CrawlScopeManager_PreviousVersion\Windows\SystemIndex\DefaultRules\19
2868
SearchIndexer.exe
delete key
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Search\CrawlScopeManager_PreviousVersion\Windows\SystemIndex\DefaultRules\2
2868
SearchIndexer.exe
delete key
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Search\CrawlScopeManager_PreviousVersion\Windows\SystemIndex\DefaultRules\3
2868
SearchIndexer.exe
delete key
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Search\CrawlScopeManager_PreviousVersion\Windows\SystemIndex\DefaultRules\4
2868
SearchIndexer.exe
delete key
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Search\CrawlScopeManager_PreviousVersion\Windows\SystemIndex\DefaultRules\5
2868
SearchIndexer.exe
delete key
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Search\CrawlScopeManager_PreviousVersion\Windows\SystemIndex\DefaultRules\6
2868
SearchIndexer.exe
delete key
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Search\CrawlScopeManager_PreviousVersion\Windows\SystemIndex\DefaultRules\7
2868
SearchIndexer.exe
delete key
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Search\CrawlScopeManager_PreviousVersion\Windows\SystemIndex\DefaultRules\8
2868
SearchIndexer.exe
delete key
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Search\CrawlScopeManager_PreviousVersion\Windows\SystemIndex\DefaultRules\9
2868
SearchIndexer.exe
delete key
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Search\CrawlScopeManager_PreviousVersion\Windows\SystemIndex\DefaultRules
2868
SearchIndexer.exe
delete key
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Search\CrawlScopeManager_PreviousVersion\Windows\SystemIndex\SearchRoots\0
2868
SearchIndexer.exe
delete key
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Search\CrawlScopeManager_PreviousVersion\Windows\SystemIndex\SearchRoots\1
2868
SearchIndexer.exe
delete key
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Search\CrawlScopeManager_PreviousVersion\Windows\SystemIndex\SearchRoots\2
2868
SearchIndexer.exe
delete key
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Search\CrawlScopeManager_PreviousVersion\Windows\SystemIndex\SearchRoots\3
2868
SearchIndexer.exe
delete key
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Search\CrawlScopeManager_PreviousVersion\Windows\SystemIndex\SearchRoots\4
2868
SearchIndexer.exe
delete key
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Search\CrawlScopeManager_PreviousVersion\Windows\SystemIndex\SearchRoots\5
2868
SearchIndexer.exe
delete key
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Search\CrawlScopeManager_PreviousVersion\Windows\SystemIndex\SearchRoots\6
2868
SearchIndexer.exe
delete key
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Search\CrawlScopeManager_PreviousVersion\Windows\SystemIndex\SearchRoots\7
2868
SearchIndexer.exe
delete key
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Search\CrawlScopeManager_PreviousVersion\Windows\SystemIndex\SearchRoots
2868
SearchIndexer.exe
delete key
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Search\CrawlScopeManager_PreviousVersion\Windows\SystemIndex\WorkingSetRules\0
2868
SearchIndexer.exe
delete key
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Search\CrawlScopeManager_PreviousVersion\Windows\SystemIndex\WorkingSetRules\1
2868
SearchIndexer.exe
delete key
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Search\CrawlScopeManager_PreviousVersion\Windows\SystemIndex\WorkingSetRules\10
2868
SearchIndexer.exe
delete key
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Search\CrawlScopeManager_PreviousVersion\Windows\SystemIndex\WorkingSetRules\11
2868
SearchIndexer.exe
delete key
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Search\CrawlScopeManager_PreviousVersion\Windows\SystemIndex\WorkingSetRules\12
2868
SearchIndexer.exe
delete key
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Search\CrawlScopeManager_PreviousVersion\Windows\SystemIndex\WorkingSetRules\13
2868
SearchIndexer.exe
delete key
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Search\CrawlScopeManager_PreviousVersion\Windows\SystemIndex\WorkingSetRules\14
2868
SearchIndexer.exe
delete key
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Search\CrawlScopeManager_PreviousVersion\Windows\SystemIndex\WorkingSetRules\15
2868
SearchIndexer.exe
delete key
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Search\CrawlScopeManager_PreviousVersion\Windows\SystemIndex\WorkingSetRules\16
2868
SearchIndexer.exe
delete key
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Search\CrawlScopeManager_PreviousVersion\Windows\SystemIndex\WorkingSetRules\17
2868
SearchIndexer.exe
delete key
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Search\CrawlScopeManager_PreviousVersion\Windows\SystemIndex\WorkingSetRules\18
2868
SearchIndexer.exe
delete key
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Search\CrawlScopeManager_PreviousVersion\Windows\SystemIndex\WorkingSetRules\19
2868
SearchIndexer.exe
delete key
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Search\CrawlScopeManager_PreviousVersion\Windows\SystemIndex\WorkingSetRules\2
2868
SearchIndexer.exe
delete key
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Search\CrawlScopeManager_PreviousVersion\Windows\SystemIndex\WorkingSetRules\20
2868
SearchIndexer.exe
delete key
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Search\CrawlScopeManager_PreviousVersion\Windows\SystemIndex\WorkingSetRules\21
2868
SearchIndexer.exe
delete key
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Search\CrawlScopeManager_PreviousVersion\Windows\SystemIndex\WorkingSetRules\3
2868
SearchIndexer.exe
delete key
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Search\CrawlScopeManager_PreviousVersion\Windows\SystemIndex\WorkingSetRules\4
2868
SearchIndexer.exe
delete key
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Search\CrawlScopeManager_PreviousVersion\Windows\SystemIndex\WorkingSetRules\5
2868
SearchIndexer.exe
delete key
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Search\CrawlScopeManager_PreviousVersion\Windows\SystemIndex\WorkingSetRules\6
2868
SearchIndexer.exe
delete key
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Search\CrawlScopeManager_PreviousVersion\Windows\SystemIndex\WorkingSetRules\7
2868
SearchIndexer.exe
delete key
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Search\CrawlScopeManager_PreviousVersion\Windows\SystemIndex\WorkingSetRules\8
2868
SearchIndexer.exe
delete key
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Search\CrawlScopeManager_PreviousVersion\Windows\SystemIndex\WorkingSetRules\9
2868
SearchIndexer.exe
delete key
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Search\CrawlScopeManager_PreviousVersion\Windows\SystemIndex\WorkingSetRules
2868
SearchIndexer.exe
delete key
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Search\CrawlScopeManager_PreviousVersion\Windows\SystemIndex
2868
SearchIndexer.exe
delete key
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Search\CrawlScopeManager_PreviousVersion\Windows
2868
SearchIndexer.exe
delete key
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Search\CrawlScopeManager_PreviousVersion
2868
SearchIndexer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Search\CrawlScopeManager\Windows\SystemIndex\DefaultRules\0
URL
file:///C:\Users\*\AppData\Local\Microsoft\Windows\Temporary Internet Files\*
2868
SearchIndexer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Search\CrawlScopeManager\Windows\SystemIndex\DefaultRules\0
Include
0
2868
SearchIndexer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Search\CrawlScopeManager\Windows\SystemIndex\DefaultRules\0
Suppress
0
2868
SearchIndexer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Search\CrawlScopeManager\Windows\SystemIndex\DefaultRules\0
Default
1
2868
SearchIndexer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Search\CrawlScopeManager\Windows\SystemIndex\DefaultRules\0
Policy
0
2868
SearchIndexer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Search\CrawlScopeManager\Windows\SystemIndex\DefaultRules\1
URL
file:///C:\Users\*\AppData\Local\Temp\*
2868
SearchIndexer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Search\CrawlScopeManager\Windows\SystemIndex\DefaultRules\1
Include
0
2868
SearchIndexer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Search\CrawlScopeManager\Windows\SystemIndex\DefaultRules\1
Suppress
0
2868
SearchIndexer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Search\CrawlScopeManager\Windows\SystemIndex\DefaultRules\1
Default
1
2868
SearchIndexer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Search\CrawlScopeManager\Windows\SystemIndex\DefaultRules\1
Policy
0
2868
SearchIndexer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Search\CrawlScopeManager\Windows\SystemIndex\DefaultRules\2
URL
file:///C:\ProgramData\Microsoft\Search\Data\*
2868
SearchIndexer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Search\CrawlScopeManager\Windows\SystemIndex\DefaultRules\2
Include
0
2868
SearchIndexer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Search\CrawlScopeManager\Windows\SystemIndex\DefaultRules\2
Suppress
0
2868
SearchIndexer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Search\CrawlScopeManager\Windows\SystemIndex\DefaultRules\2
Default
1
2868
SearchIndexer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Search\CrawlScopeManager\Windows\SystemIndex\DefaultRules\2
Policy
0
2868
SearchIndexer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Search\CrawlScopeManager\Windows\SystemIndex\DefaultRules\3
URL
file:///C:\ProgramData\Microsoft\Windows\Start Menu\
2868
SearchIndexer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Search\CrawlScopeManager\Windows\SystemIndex\DefaultRules\3
Include
1
2868
SearchIndexer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Search\CrawlScopeManager\Windows\SystemIndex\DefaultRules\3
Suppress
0
2868
SearchIndexer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Search\CrawlScopeManager\Windows\SystemIndex\DefaultRules\3
Default
1
2868
SearchIndexer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Search\CrawlScopeManager\Windows\SystemIndex\DefaultRules\3
Policy
0
2868
SearchIndexer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Search\CrawlScopeManager\Windows\SystemIndex\DefaultRules\4
URL
file:///C:\Users\admin\AppData\*
2868
SearchIndexer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Search\CrawlScopeManager\Windows\SystemIndex\DefaultRules\4
Include
0
2868
SearchIndexer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Search\CrawlScopeManager\Windows\SystemIndex\DefaultRules\4
Suppress
0
2868
SearchIndexer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Search\CrawlScopeManager\Windows\SystemIndex\DefaultRules\4
Default
1
2868
SearchIndexer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Search\CrawlScopeManager\Windows\SystemIndex\DefaultRules\4
Policy
0
2868
SearchIndexer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Search\CrawlScopeManager\Windows\SystemIndex\DefaultRules\5
URL
file:///C:\Users\admin\Favorites\
2868
SearchIndexer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Search\CrawlScopeManager\Windows\SystemIndex\DefaultRules\5
Include
1
2868
SearchIndexer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Search\CrawlScopeManager\Windows\SystemIndex\DefaultRules\5
Suppress
0
2868
SearchIndexer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Search\CrawlScopeManager\Windows\SystemIndex\DefaultRules\5
Default
1
2868
SearchIndexer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Search\CrawlScopeManager\Windows\SystemIndex\DefaultRules\5
Policy
0
2868
SearchIndexer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Search\CrawlScopeManager\Windows\SystemIndex\DefaultRules\6
URL
file:///C:\Users\Administrator\AppData\*
2868
SearchIndexer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Search\CrawlScopeManager\Windows\SystemIndex\DefaultRules\6
Include
0
2868
SearchIndexer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Search\CrawlScopeManager\Windows\SystemIndex\DefaultRules\6
Suppress
0
2868
SearchIndexer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Search\CrawlScopeManager\Windows\SystemIndex\DefaultRules\6
Default
1
2868
SearchIndexer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Search\CrawlScopeManager\Windows\SystemIndex\DefaultRules\6
Policy
0
2868
SearchIndexer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Search\CrawlScopeManager\Windows\SystemIndex\DefaultRules\7
URL
file:///C:\Users\Default\AppData\*
2868
SearchIndexer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Search\CrawlScopeManager\Windows\SystemIndex\DefaultRules\7
Include
0
2868
SearchIndexer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Search\CrawlScopeManager\Windows\SystemIndex\DefaultRules\7
Suppress
0
2868
SearchIndexer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Search\CrawlScopeManager\Windows\SystemIndex\DefaultRules\7
Default
1
2868
SearchIndexer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Search\CrawlScopeManager\Windows\SystemIndex\DefaultRules\7
Policy
0
2868
SearchIndexer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Search\CrawlScopeManager\Windows\SystemIndex\DefaultRules\8
URL
file:///C:\Windows\*\temp\*
2868
SearchIndexer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Search\CrawlScopeManager\Windows\SystemIndex\DefaultRules\8
Include
0
2868
SearchIndexer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Search\CrawlScopeManager\Windows\SystemIndex\DefaultRules\8
Suppress
0
2868
SearchIndexer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Search\CrawlScopeManager\Windows\SystemIndex\DefaultRules\8
Default
1
2868
SearchIndexer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Search\CrawlScopeManager\Windows\SystemIndex\DefaultRules\8
Policy
0
2868
SearchIndexer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Search\CrawlScopeManager\Windows\SystemIndex\DefaultRules\9
URL
file:///C:\Windows\CSC\*
2868
SearchIndexer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Search\CrawlScopeManager\Windows\SystemIndex\DefaultRules\9
Include
0
2868
SearchIndexer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Search\CrawlScopeManager\Windows\SystemIndex\DefaultRules\9
Suppress
0
2868
SearchIndexer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Search\CrawlScopeManager\Windows\SystemIndex\DefaultRules\9
Default
1
2868
SearchIndexer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Search\CrawlScopeManager\Windows\SystemIndex\DefaultRules\9
Policy
0
2868
SearchIndexer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Search\CrawlScopeManager\Windows\SystemIndex\DefaultRules\10
URL
file:///C:\ProgramData\*
2868
SearchIndexer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Search\CrawlScopeManager\Windows\SystemIndex\DefaultRules\10
Include
0
2868
SearchIndexer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Search\CrawlScopeManager\Windows\SystemIndex\DefaultRules\10
Suppress
0
2868
SearchIndexer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Search\CrawlScopeManager\Windows\SystemIndex\DefaultRules\10
Default
1
2868
SearchIndexer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Search\CrawlScopeManager\Windows\SystemIndex\DefaultRules\10
Policy
0
2868
SearchIndexer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Search\CrawlScopeManager\Windows\SystemIndex\DefaultRules\11
URL
file:///C:\Users\
2868
SearchIndexer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Search\CrawlScopeManager\Windows\SystemIndex\DefaultRules\11
Include
1
2868
SearchIndexer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Search\CrawlScopeManager\Windows\SystemIndex\DefaultRules\11
Suppress
0
2868
SearchIndexer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Search\CrawlScopeManager\Windows\SystemIndex\DefaultRules\11
Default
1
2868
SearchIndexer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Search\CrawlScopeManager\Windows\SystemIndex\DefaultRules\11
Policy
0
2868
SearchIndexer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Search\CrawlScopeManager\Windows\SystemIndex\DefaultRules\12
URL
file:///C:\Windows\*
2868
SearchIndexer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Search\CrawlScopeManager\Windows\SystemIndex\DefaultRules\12
Include
0
2868
SearchIndexer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Search\CrawlScopeManager\Windows\SystemIndex\DefaultRules\12
Suppress
0
2868
SearchIndexer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Search\CrawlScopeManager\Windows\SystemIndex\DefaultRules\12
Default
1
2868
SearchIndexer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Search\CrawlScopeManager\Windows\SystemIndex\DefaultRules\12
Policy
0
2868
SearchIndexer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Search\CrawlScopeManager\Windows\SystemIndex\DefaultRules\13
URL
file:///C:\Windows.*\*
2868
SearchIndexer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Search\CrawlScopeManager\Windows\SystemIndex\DefaultRules\13
Include
0
2868
SearchIndexer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Search\CrawlScopeManager\Windows\SystemIndex\DefaultRules\13
Suppress
0
2868
SearchIndexer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Search\CrawlScopeManager\Windows\SystemIndex\DefaultRules\13
Default
1
2868
SearchIndexer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Search\CrawlScopeManager\Windows\SystemIndex\DefaultRules\13
Policy
0
2868
SearchIndexer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Search\CrawlScopeManager\Windows\SystemIndex\DefaultRules\14
URL
file:///*\$RECYCLE.BIN\*
2868
SearchIndexer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Search\CrawlScopeManager\Windows\SystemIndex\DefaultRules\14
Include
0
2868
SearchIndexer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Search\CrawlScopeManager\Windows\SystemIndex\DefaultRules\14
Suppress
0
2868
SearchIndexer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Search\CrawlScopeManager\Windows\SystemIndex\DefaultRules\14
Default
1
2868
SearchIndexer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Search\CrawlScopeManager\Windows\SystemIndex\DefaultRules\14
Policy
0
2868
SearchIndexer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Search\CrawlScopeManager\Windows\SystemIndex\DefaultRules\15
URL
file:///*\DfsrPrivate\*
2868
SearchIndexer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Search\CrawlScopeManager\Windows\SystemIndex\DefaultRules\15
Include
0
2868
SearchIndexer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Search\CrawlScopeManager\Windows\SystemIndex\DefaultRules\15
Suppress
0
2868
SearchIndexer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Search\CrawlScopeManager\Windows\SystemIndex\DefaultRules\15
Default
1
2868
SearchIndexer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Search\CrawlScopeManager\Windows\SystemIndex\DefaultRules\15
Policy
0
2868
SearchIndexer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Search\CrawlScopeManager\Windows\SystemIndex\DefaultRules\16
URL
file:///*\System Volume Information\*
2868
SearchIndexer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Search\CrawlScopeManager\Windows\SystemIndex\DefaultRules\16
Include
0
2868
SearchIndexer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Search\CrawlScopeManager\Windows\SystemIndex\DefaultRules\16
Suppress
0
2868
SearchIndexer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Search\CrawlScopeManager\Windows\SystemIndex\DefaultRules\16
Default
1
2868
SearchIndexer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Search\CrawlScopeManager\Windows\SystemIndex\DefaultRules\16
Policy
0
2868
SearchIndexer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Search\CrawlScopeManager\Windows\SystemIndex\DefaultRules\17
URL
csc://{S-1-5-21-1302019708-1500728564-335382590-1000}/
2868
SearchIndexer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Search\CrawlScopeManager\Windows\SystemIndex\DefaultRules\17
Include
1
2868
SearchIndexer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Search\CrawlScopeManager\Windows\SystemIndex\DefaultRules\17
Suppress
0
2868
SearchIndexer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Search\CrawlScopeManager\Windows\SystemIndex\DefaultRules\17
Default
1
2868
SearchIndexer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Search\CrawlScopeManager\Windows\SystemIndex\DefaultRules\17
Policy
0
2868
SearchIndexer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Search\CrawlScopeManager\Windows\SystemIndex\DefaultRules\18
URL
csc://{S-1-5-21-1302019708-1500728564-335382590-500}/
2868
SearchIndexer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Search\CrawlScopeManager\Windows\SystemIndex\DefaultRules\18
Include
1
2868
SearchIndexer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Search\CrawlScopeManager\Windows\SystemIndex\DefaultRules\18
Suppress
0
2868
SearchIndexer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Search\CrawlScopeManager\Windows\SystemIndex\DefaultRules\18
Default
1
2868
SearchIndexer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Search\CrawlScopeManager\Windows\SystemIndex\DefaultRules\18
Policy
0
2868
SearchIndexer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Search\CrawlScopeManager\Windows\SystemIndex\DefaultRules\19
URL
iehistory://{S-1-5-21-1302019708-1500728564-335382590-1000}/
2868
SearchIndexer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Search\CrawlScopeManager\Windows\SystemIndex\DefaultRules\19
Include
1
2868
SearchIndexer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Search\CrawlScopeManager\Windows\SystemIndex\DefaultRules\19
Suppress
0
2868
SearchIndexer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Search\CrawlScopeManager\Windows\SystemIndex\DefaultRules\19
Default
1
2868
SearchIndexer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Search\CrawlScopeManager\Windows\SystemIndex\DefaultRules\19
Policy
0
2868
SearchIndexer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Search\CrawlScopeManager\Windows\SystemIndex\DefaultRules
ItemCount
20
2868
SearchIndexer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Search\CrawlScopeManager\Windows\SystemIndex\WorkingSetRules\0
URL
file:///C:\Users\*\AppData\Local\Microsoft\Windows\Temporary Internet Files\*
2868
SearchIndexer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Search\CrawlScopeManager\Windows\SystemIndex\WorkingSetRules\0
Include
0
2868
SearchIndexer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Search\CrawlScopeManager\Windows\SystemIndex\WorkingSetRules\0
Suppress
0
2868
SearchIndexer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Search\CrawlScopeManager\Windows\SystemIndex\WorkingSetRules\0
Default
1
2868
SearchIndexer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Search\CrawlScopeManager\Windows\SystemIndex\WorkingSetRules\0
Policy
0
2868
SearchIndexer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Search\CrawlScopeManager\Windows\SystemIndex\WorkingSetRules\1
URL
file:///C:\Users\*\AppData\Local\Temp\*
2868
SearchIndexer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Search\CrawlScopeManager\Windows\SystemIndex\WorkingSetRules\1
Include
0
2868
SearchIndexer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Search\CrawlScopeManager\Windows\SystemIndex\WorkingSetRules\1
Suppress
0
2868
SearchIndexer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Search\CrawlScopeManager\Windows\SystemIndex\WorkingSetRules\1
Default
1
2868
SearchIndexer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Search\CrawlScopeManager\Windows\SystemIndex\WorkingSetRules\1
Policy
0
2868
SearchIndexer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Search\CrawlScopeManager\Windows\SystemIndex\WorkingSetRules\2
URL
file:///C:\ProgramData\Microsoft\Search\Data\*
2868
SearchIndexer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Search\CrawlScopeManager\Windows\SystemIndex\WorkingSetRules\2
Include
0
2868
SearchIndexer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Search\CrawlScopeManager\Windows\SystemIndex\WorkingSetRules\2
Suppress
0
2868
SearchIndexer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Search\CrawlScopeManager\Windows\SystemIndex\WorkingSetRules\2
Default
1
2868
SearchIndexer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Search\CrawlScopeManager\Windows\SystemIndex\WorkingSetRules\2
Policy
0
2868
SearchIndexer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Search\CrawlScopeManager\Windows\SystemIndex\WorkingSetRules\3
URL
file:///C:\ProgramData\Microsoft\Windows\Start Menu\
2868
SearchIndexer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Search\CrawlScopeManager\Windows\SystemIndex\WorkingSetRules\3
Include
1
2868
SearchIndexer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Search\CrawlScopeManager\Windows\SystemIndex\WorkingSetRules\3
Suppress
0
2868
SearchIndexer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Search\CrawlScopeManager\Windows\SystemIndex\WorkingSetRules\3
Default
1
2868
SearchIndexer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Search\CrawlScopeManager\Windows\SystemIndex\WorkingSetRules\3
Policy
0
2868
SearchIndexer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Search\CrawlScopeManager\Windows\SystemIndex\WorkingSetRules\4
URL
file:///C:\Users\admin\AppData\*
2868
SearchIndexer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Search\CrawlScopeManager\Windows\SystemIndex\WorkingSetRules\4
Include
0
2868
SearchIndexer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Search\CrawlScopeManager\Windows\SystemIndex\WorkingSetRules\4
Suppress
0
2868
SearchIndexer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Search\CrawlScopeManager\Windows\SystemIndex\WorkingSetRules\4
Default
1
2868
SearchIndexer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Search\CrawlScopeManager\Windows\SystemIndex\WorkingSetRules\4
Policy
0
2868
SearchIndexer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Search\CrawlScopeManager\Windows\SystemIndex\WorkingSetRules\5
URL
file:///C:\Users\admin\Favorites\
2868
SearchIndexer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Search\CrawlScopeManager\Windows\SystemIndex\WorkingSetRules\5
Include
1
2868
SearchIndexer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Search\CrawlScopeManager\Windows\SystemIndex\WorkingSetRules\5
Suppress
0
2868
SearchIndexer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Search\CrawlScopeManager\Windows\SystemIndex\WorkingSetRules\5
Default
1
2868
SearchIndexer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Search\CrawlScopeManager\Windows\SystemIndex\WorkingSetRules\5
Policy
0
2868
SearchIndexer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Search\CrawlScopeManager\Windows\SystemIndex\WorkingSetRules\6
URL
file:///C:\Users\Administrator\AppData\*
2868
SearchIndexer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Search\CrawlScopeManager\Windows\SystemIndex\WorkingSetRules\6
Include
0
2868
SearchIndexer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Search\CrawlScopeManager\Windows\SystemIndex\WorkingSetRules\6
Suppress
0
2868
SearchIndexer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Search\CrawlScopeManager\Windows\SystemIndex\WorkingSetRules\6
Default
1
2868
SearchIndexer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Search\CrawlScopeManager\Windows\SystemIndex\WorkingSetRules\6
Policy
0
2868
SearchIndexer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Search\CrawlScopeManager\Windows\SystemIndex\WorkingSetRules\7
URL
file:///C:\Users\Default\AppData\*
2868
SearchIndexer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Search\CrawlScopeManager\Windows\SystemIndex\WorkingSetRules\7
Include
0
2868
SearchIndexer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Search\CrawlScopeManager\Windows\SystemIndex\WorkingSetRules\7
Suppress
0
2868
SearchIndexer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Search\CrawlScopeManager\Windows\SystemIndex\WorkingSetRules\7
Default
1
2868
SearchIndexer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Search\CrawlScopeManager\Windows\SystemIndex\WorkingSetRules\7
Policy
0
2868
SearchIndexer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Search\CrawlScopeManager\Windows\SystemIndex\WorkingSetRules\8
URL
file:///C:\Windows\*\temp\*
2868
SearchIndexer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Search\CrawlScopeManager\Windows\SystemIndex\WorkingSetRules\8
Include
0
2868
SearchIndexer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Search\CrawlScopeManager\Windows\SystemIndex\WorkingSetRules\8
Suppress
0
2868
SearchIndexer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Search\CrawlScopeManager\Windows\SystemIndex\WorkingSetRules\8
Default
1
2868
SearchIndexer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Search\CrawlScopeManager\Windows\SystemIndex\WorkingSetRules\8
Policy
0
2868
SearchIndexer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Search\CrawlScopeManager\Windows\SystemIndex\WorkingSetRules\9
URL
file:///C:\Windows\CSC\*
2868
SearchIndexer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Search\CrawlScopeManager\Windows\SystemIndex\WorkingSetRules\9
Include
0
2868
SearchIndexer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Search\CrawlScopeManager\Windows\SystemIndex\WorkingSetRules\9
Suppress
0
2868
SearchIndexer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Search\CrawlScopeManager\Windows\SystemIndex\WorkingSetRules\9
Default
1
2868
SearchIndexer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Search\CrawlScopeManager\Windows\SystemIndex\WorkingSetRules\9
Policy
0
2868
SearchIndexer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Search\CrawlScopeManager\Windows\SystemIndex\WorkingSetRules\10
URL
file:///C:\ProgramData\*
2868
SearchIndexer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Search\CrawlScopeManager\Windows\SystemIndex\WorkingSetRules\10
Include
0
2868
SearchIndexer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Search\CrawlScopeManager\Windows\SystemIndex\WorkingSetRules\10
Suppress
0
2868
SearchIndexer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Search\CrawlScopeManager\Windows\SystemIndex\WorkingSetRules\10
Default
1
2868
SearchIndexer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Search\CrawlScopeManager\Windows\SystemIndex\WorkingSetRules\10
Policy
0
2868
SearchIndexer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Search\CrawlScopeManager\Windows\SystemIndex\WorkingSetRules\11
URL
file:///C:\Users\
2868
SearchIndexer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Search\CrawlScopeManager\Windows\SystemIndex\WorkingSetRules\11
Include
1
2868
SearchIndexer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Search\CrawlScopeManager\Windows\SystemIndex\WorkingSetRules\11
Suppress
0
2868
SearchIndexer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Search\CrawlScopeManager\Windows\SystemIndex\WorkingSetRules\11
Default
1
2868
SearchIndexer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Search\CrawlScopeManager\Windows\SystemIndex\WorkingSetRules\11
Policy
0
2868
SearchIndexer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Search\CrawlScopeManager\Windows\SystemIndex\WorkingSetRules\12
URL
file:///C:\Windows\*
2868
SearchIndexer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Search\CrawlScopeManager\Windows\SystemIndex\WorkingSetRules\12
Include
0
2868
SearchIndexer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Search\CrawlScopeManager\Windows\SystemIndex\WorkingSetRules\12
Suppress
0
2868
SearchIndexer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Search\CrawlScopeManager\Windows\SystemIndex\WorkingSetRules\12
Default
1
2868
SearchIndexer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Search\CrawlScopeManager\Windows\SystemIndex\WorkingSetRules\12
Policy
0
2868
SearchIndexer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Search\CrawlScopeManager\Windows\SystemIndex\WorkingSetRules\13
URL
file:///C:\Windows.*\*
2868
SearchIndexer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Search\CrawlScopeManager\Windows\SystemIndex\WorkingSetRules\13
Include
0
2868
SearchIndexer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Search\CrawlScopeManager\Windows\SystemIndex\WorkingSetRules\13
Suppress
0
2868
SearchIndexer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Search\CrawlScopeManager\Windows\SystemIndex\WorkingSetRules\13
Default
1
2868
SearchIndexer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Search\CrawlScopeManager\Windows\SystemIndex\WorkingSetRules\13
Policy
0
2868
SearchIndexer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Search\CrawlScopeManager\Windows\SystemIndex\WorkingSetRules\14
URL
file:///*\$RECYCLE.BIN\*
2868
SearchIndexer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Search\CrawlScopeManager\Windows\SystemIndex\WorkingSetRules\14
Include
0
2868
SearchIndexer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Search\CrawlScopeManager\Windows\SystemIndex\WorkingSetRules\14
Suppress
0
2868
SearchIndexer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Search\CrawlScopeManager\Windows\SystemIndex\WorkingSetRules\14
Default
1
2868
SearchIndexer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Search\CrawlScopeManager\Windows\SystemIndex\WorkingSetRules\14
Policy
0
2868
SearchIndexer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Search\CrawlScopeManager\Windows\SystemIndex\WorkingSetRules\15
URL
file:///*\DfsrPrivate\*
2868
SearchIndexer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Search\CrawlScopeManager\Windows\SystemIndex\WorkingSetRules\15
Include
0
2868
SearchIndexer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Search\CrawlScopeManager\Windows\SystemIndex\WorkingSetRules\15
Suppress
0
2868
SearchIndexer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Search\CrawlScopeManager\Windows\SystemIndex\WorkingSetRules\15
Default
1
2868
SearchIndexer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Search\CrawlScopeManager\Windows\SystemIndex\WorkingSetRules\15
Policy
0
2868
SearchIndexer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Search\CrawlScopeManager\Windows\SystemIndex\WorkingSetRules\16
URL
file:///*\System Volume Information\*
2868
SearchIndexer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Search\CrawlScopeManager\Windows\SystemIndex\WorkingSetRules\16
Include
0
2868
SearchIndexer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Search\CrawlScopeManager\Windows\SystemIndex\WorkingSetRules\16
Suppress
0
2868
SearchIndexer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Search\CrawlScopeManager\Windows\SystemIndex\WorkingSetRules\16
Default
1
2868
SearchIndexer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Search\CrawlScopeManager\Windows\SystemIndex\WorkingSetRules\16
Policy
0
2868
SearchIndexer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Search\CrawlScopeManager\Windows\SystemIndex\WorkingSetRules\17
URL
csc://{S-1-5-21-1302019708-1500728564-335382590-1000}/
2868
SearchIndexer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Search\CrawlScopeManager\Windows\SystemIndex\WorkingSetRules\17
Include
1
2868
SearchIndexer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Search\CrawlScopeManager\Windows\SystemIndex\WorkingSetRules\17
Suppress
0
2868
SearchIndexer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Search\CrawlScopeManager\Windows\SystemIndex\WorkingSetRules\17
Default
1
2868
SearchIndexer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Search\CrawlScopeManager\Windows\SystemIndex\WorkingSetRules\17
Policy
0
2868
SearchIndexer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Search\CrawlScopeManager\Windows\SystemIndex\WorkingSetRules\18
URL
csc://{S-1-5-21-1302019708-1500728564-335382590-500}/
2868
SearchIndexer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Search\CrawlScopeManager\Windows\SystemIndex\WorkingSetRules\18
Include
1
2868
SearchIndexer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Search\CrawlScopeManager\Windows\SystemIndex\WorkingSetRules\18
Suppress
0
2868
SearchIndexer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Search\CrawlScopeManager\Windows\SystemIndex\WorkingSetRules\18
Default
1
2868
SearchIndexer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Search\CrawlScopeManager\Windows\SystemIndex\WorkingSetRules\18
Policy
0
2868
SearchIndexer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Search\CrawlScopeManager\Windows\SystemIndex\WorkingSetRules\19
URL
iehistory://{S-1-5-21-1302019708-1500728564-335382590-1000}/
2868
SearchIndexer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Search\CrawlScopeManager\Windows\SystemIndex\WorkingSetRules\19
Include
1
2868
SearchIndexer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Search\CrawlScopeManager\Windows\SystemIndex\WorkingSetRules\19
Suppress
0
2868
SearchIndexer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Search\CrawlScopeManager\Windows\SystemIndex\WorkingSetRules\19
Default
1
2868
SearchIndexer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Search\CrawlScopeManager\Windows\SystemIndex\WorkingSetRules\19
Policy
0
2868
SearchIndexer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Search\CrawlScopeManager\Windows\SystemIndex\WorkingSetRules\20
URL
mapi://{S-1-5-21-1302019708-1500728564-335382590-1000}/
2868
SearchIndexer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Search\CrawlScopeManager\Windows\SystemIndex\WorkingSetRules\20
Include
1
2868
SearchIndexer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Search\CrawlScopeManager\Windows\SystemIndex\WorkingSetRules\20
Suppress
0
2868
SearchIndexer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Search\CrawlScopeManager\Windows\SystemIndex\WorkingSetRules\20
Default
0
2868
SearchIndexer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Search\CrawlScopeManager\Windows\SystemIndex\WorkingSetRules\20
Policy
0
2868
SearchIndexer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Search\CrawlScopeManager\Windows\SystemIndex\WorkingSetRules\21
URL
ONEINDEX14://{S-1-5-21-1302019708-1500728564-335382590-1000}/
2868
SearchIndexer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Search\CrawlScopeManager\Windows\SystemIndex\WorkingSetRules\21
Include
1
2868
SearchIndexer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Search\CrawlScopeManager\Windows\SystemIndex\WorkingSetRules\21
Suppress
0
2868
SearchIndexer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Search\CrawlScopeManager\Windows\SystemIndex\WorkingSetRules\21
Default
0
2868
SearchIndexer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Search\CrawlScopeManager\Windows\SystemIndex\WorkingSetRules\21
Policy
0
2868
SearchIndexer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Search\CrawlScopeManager\Windows\SystemIndex\WorkingSetRules
ItemCount
22
2868
SearchIndexer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Search\CrawlScopeManager\Windows\SystemIndex\SearchRoots\0
URL
csc://{S-1-5-21-1302019708-1500728564-335382590-1000}/
2868
SearchIndexer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Search\CrawlScopeManager\Windows\SystemIndex\SearchRoots\0
ProvidesNotifications
1
2868
SearchIndexer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Search\CrawlScopeManager\Windows\SystemIndex\SearchRoots\1
URL
csc://{S-1-5-21-1302019708-1500728564-335382590-500}/
2868
SearchIndexer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Search\CrawlScopeManager\Windows\SystemIndex\SearchRoots\1
ProvidesNotifications
1
2868
SearchIndexer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Search\CrawlScopeManager\Windows\SystemIndex\SearchRoots\2
URL
defaultroot://{S-1-5-21-1302019708-1500728564-335382590-1000}/
2868
SearchIndexer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Search\CrawlScopeManager\Windows\SystemIndex\SearchRoots\2
ProvidesNotifications
0
2868
SearchIndexer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Search\CrawlScopeManager\Windows\SystemIndex\SearchRoots\3
URL
defaultroot://{S-1-5-21-1302019708-1500728564-335382590-500}/
2868
SearchIndexer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Search\CrawlScopeManager\Windows\SystemIndex\SearchRoots\3
ProvidesNotifications
0
2868
SearchIndexer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Search\CrawlScopeManager\Windows\SystemIndex\SearchRoots\4
URL
file:///C:\
2868
SearchIndexer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Search\CrawlScopeManager\Windows\SystemIndex\SearchRoots\4
ProvidesNotifications
1
2868
SearchIndexer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Search\CrawlScopeManager\Windows\SystemIndex\SearchRoots\5
URL
iehistory://{S-1-5-21-1302019708-1500728564-335382590-1000}/
2868
SearchIndexer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Search\CrawlScopeManager\Windows\SystemIndex\SearchRoots\5
ProvidesNotifications
1
2868
SearchIndexer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Search\CrawlScopeManager\Windows\SystemIndex\SearchRoots\6
URL
mapi://{S-1-5-21-1302019708-1500728564-335382590-1000}/
2868
SearchIndexer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Search\CrawlScopeManager\Windows\SystemIndex\SearchRoots\6
ProvidesNotifications
1
2868
SearchIndexer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Search\CrawlScopeManager\Windows\SystemIndex\SearchRoots\7
URL
ONEINDEX14://{S-1-5-21-1302019708-1500728564-335382590-1000}/
2868
SearchIndexer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Search\CrawlScopeManager\Windows\SystemIndex\SearchRoots\7
ProvidesNotifications
1
2868
SearchIndexer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Search\CrawlScopeManager\Windows\SystemIndex\SearchRoots
ItemCount
8
2868
SearchIndexer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Search\Gather\Windows\SystemIndex\StartPages
NewStartPageIdentifier
1
2868
SearchIndexer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Search\Gather\Windows\SystemIndex\StartPages\0
URL
C:\ProgramData\Microsoft\Windows\Start Menu\
2868
SearchIndexer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Search\Gather\Windows\SystemIndex\StartPages\0
HostDepth
0
2868
SearchIndexer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Search\Gather\Windows\SystemIndex\StartPages\0
EnumerationDepth
4294967295
2868
SearchIndexer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Search\Gather\Windows\SystemIndex\StartPages\0
FollowDirectories
0
2868
SearchIndexer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Search\Gather\Windows\SystemIndex\StartPages\0
StartPageIdentifier
0
2868
SearchIndexer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Search\Gather\Windows\SystemIndex\StartPages\0
CrawlNumberInProgress
4294967295
2868
SearchIndexer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Search\Gather\Windows\SystemIndex\StartPages\0
CrawlNumberScheduled
4294967295
2868
SearchIndexer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Search\Gather\Windows\SystemIndex\StartPages\0
ForceFullCrawl
1
2868
SearchIndexer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Search\Gather\Windows\SystemIndex\StartPages\0
ForceFullCrawlExternal
0
2868
SearchIndexer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Search\Gather\Windows\SystemIndex\StartPages\0
LastCrawlStopped
0
2868
SearchIndexer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Search\Gather\Windows\SystemIndex\StartPages\0
Type
2
2868
SearchIndexer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Search\Gather\Windows\SystemIndex\StartPages\0
CrawlControl
0
2868
SearchIndexer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Search\Gather\Windows\SystemIndex\StartPages\0
LastCrawlType
0
2868
SearchIndexer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Search\Gather\Windows\SystemIndex\StartPages\0
IncludeInProjectCrawls
1
2868
SearchIndexer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Search\Gather\Windows\SystemIndex\StartPages\0
LastCrawlTime
0000000000000000
2868
SearchIndexer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Search\Gather\Windows\SystemIndex\StartPages\0
LastStartCrawlTime
0000000000000000
2868
SearchIndexer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Search\Gather\Windows\SystemIndex\StartPages\0
AccessControl
99CABADE0300000002000000000000000000000007000000010000000000000000000000070000000000000000000000000000000700000002000000
2868
SearchIndexer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Search\Gather\Windows\SystemIndex\StartPages\0
NotificationHRes
0
2868
SearchIndexer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Search\CatalogNames\Windows\SystemIndex
IsBuildDone
0
2868
SearchIndexer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Search\Gather\Windows\SystemIndex\StartPages\0
FollowDirectories
1
2868
SearchIndexer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Search\Gather\Windows\SystemIndex\StartPages\0
Type
0
2868
SearchIndexer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Search\UsnNotifier\Windows\Volumes\{E1A82DB4-A9F0-11E7-B142-806E6F6E6963}
VolumePath
C:\
2868
SearchIndexer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Search\UsnNotifier\Windows\Volumes\{E1A82DB4-A9F0-11E7-B142-806E6F6E6963}
VolumeJournal
131516973783906250
2868
SearchIndexer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Search\UsnNotifier\Windows\Catalogs\SystemIndex
{E1A82DB4-A9F0-11E7-B142-806E6F6E6963}
66268872
2868
SearchIndexer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Search\Gather\Windows\SystemIndex\Crawls\0
CrawlType
1
2868
SearchIndexer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Search\Gather\Windows\SystemIndex\Crawls\0
InProgress
0
2868
SearchIndexer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Search\Gather\Windows\SystemIndex\Crawls\0
DoneAddingCrawlSeeds
0
2868
SearchIndexer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Search\Gather\Windows\SystemIndex\Crawls\0
IsCatalogLevel
0
2868
SearchIndexer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Search\Gather\Windows\SystemIndex\Crawls\0
LogStartAddId
65535
2868
SearchIndexer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Search\Gather\Windows\SystemIndex
NewCrawlNumber
1
2868
SearchIndexer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Search\Gather\Windows\SystemIndex\StartPages\0
ForceFullCrawl
0
2868
SearchIndexer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Search\Gather\Windows\SystemIndex\StartPages\0
CrawlNumberInProgress
0
2868
SearchIndexer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Search\Gather\Windows\SystemIndex\Crawls\0
InProgress
1
2868
SearchIndexer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Search\Gather\Windows\SystemIndex
PersistedFullCrawlCount
1
2868
SearchIndexer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Search\Gather\Windows\SystemIndex\Crawls\0
LogStartAddId
0
2868
SearchIndexer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Search\Gather\Windows\SystemIndex\StartPages
NewStartPageIdentifier
2
2868
SearchIndexer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Search\Gather\Windows\SystemIndex\StartPages\1
URL
C:\Users\
2868
SearchIndexer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Search\Gather\Windows\SystemIndex\StartPages\0
LastStartCrawlTime
5F000296E051D501
2868
SearchIndexer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Search\Gather\Windows\SystemIndex\StartPages\1
HostDepth
0
2868
SearchIndexer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Search\Gather\Windows\SystemIndex\StartPages\1
EnumerationDepth
4294967295
2868
SearchIndexer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Search\Gather\Windows\SystemIndex\StartPages\1
FollowDirectories
0
2868
SearchIndexer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Search\Gather\Windows\SystemIndex\StartPages\1
StartPageIdentifier
1
2868
SearchIndexer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Search\Gather\Windows\SystemIndex\StartPages\1
CrawlNumberInProgress
4294967295
2868
SearchIndexer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Search\Gather\Windows\SystemIndex\StartPages\1
CrawlNumberScheduled
4294967295
2868
SearchIndexer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Search\Gather\Windows\SystemIndex\StartPages\1
ForceFullCrawl
1
2868
SearchIndexer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Search\Gather\Windows\SystemIndex\StartPages\1
ForceFullCrawlExternal
0
2868
SearchIndexer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Search\Gather\Windows\SystemIndex\StartPages\1
LastCrawlStopped
0
2868
SearchIndexer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Search\Gather\Windows\SystemIndex\StartPages\1
Type
2
2868
SearchIndexer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Search\Gather\Windows\SystemIndex\StartPages\1
CrawlControl
0
2868
SearchIndexer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Search\Gather\Windows\SystemIndex\StartPages\1
LastCrawlType
0
2868
SearchIndexer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Search\Gather\Windows\SystemIndex\StartPages\1
IncludeInProjectCrawls
1
2868
SearchIndexer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Search\Gather\Windows\SystemIndex\StartPages\1
LastCrawlTime
0000000000000000
2868
SearchIndexer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Search\Gather\Windows\SystemIndex\StartPages\1
LastStartCrawlTime
0000000000000000
2868
SearchIndexer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Search\Gather\Windows\SystemIndex\StartPages\1
AccessControl
99CABADE0300000002000000000000000000000007000000010000000000000000000000070000000000000000000000000000000700000002000000
2868
SearchIndexer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Search\Gather\Windows\SystemIndex\StartPages\1
NotificationHRes
0
2868
SearchIndexer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Search\Gather\Windows\SystemIndex\StartPages\1
FollowDirectories
1
2868
SearchIndexer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Search\Gather\Windows\SystemIndex\StartPages\1
Type
0
2868
SearchIndexer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Search\Gather\Windows\SystemIndex\Crawls\0
DoneAddingCrawlSeeds
1
2868
SearchIndexer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Search\Gather\Windows\SystemIndex\StartPages
NewStartPageIdentifier
3
2868
SearchIndexer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Search\Gather\Windows\SystemIndex\StartPages\2
URL
csc://{S-1-5-21-1302019708-1500728564-335382590-1000}/
2868
SearchIndexer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Search\Gather\Windows\SystemIndex\StartPages\2
HostDepth
0
2868
SearchIndexer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Search\Gather\Windows\SystemIndex\StartPages\2
EnumerationDepth
4294967295
2868
SearchIndexer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Search\Gather\Windows\SystemIndex\StartPages\2
FollowDirectories
0
2868
SearchIndexer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Search\Gather\Windows\SystemIndex\StartPages\2
StartPageIdentifier
2
2868
SearchIndexer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Search\Gather\Windows\SystemIndex\StartPages\2
CrawlNumberInProgress
4294967295
2868
SearchIndexer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Search\Gather\Windows\SystemIndex\StartPages\2
CrawlNumberScheduled
4294967295
2868
SearchIndexer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Search\Gather\Windows\SystemIndex\StartPages\2
ForceFullCrawl
1
2868
SearchIndexer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Search\Gather\Windows\SystemIndex\StartPages\2
ForceFullCrawlExternal
0
2868
SearchIndexer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Search\Gather\Windows\SystemIndex\StartPages\2
LastCrawlStopped
0
2868
SearchIndexer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Search\Gather\Windows\SystemIndex\StartPages\2
Type
2
2868
SearchIndexer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Search\Gather\Windows\SystemIndex\StartPages\2
CrawlControl
0
2868
SearchIndexer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Search\Gather\Windows\SystemIndex\StartPages\2
LastCrawlType
0
2868
SearchIndexer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Search\Gather\Windows\SystemIndex\StartPages\2
IncludeInProjectCrawls
1
2868
SearchIndexer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Search\Gather\Windows\SystemIndex\StartPages\2
LastCrawlTime
0000000000000000
2868
SearchIndexer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Search\Gather\Windows\SystemIndex\StartPages\2
LastStartCrawlTime
0000000000000000
2868
SearchIndexer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Search\Gather\Windows\SystemIndex\StartPages\2
AccessControl
99CABADE03000000020000000000000000000000070000000100000000000000000000000700000000000000000000000000000007000000060000002D00000053002D0031002D0035002D00320031002D0031003300300032003000310039003700300038002D0031003500300030003700320038003500360034002D003300330035003300380032003500390030002D0031003000300030005C001C0000000105000000000005150000007C3E9B4DF44C73593E88FD13E8030000
2868
SearchIndexer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Search\Gather\Windows\SystemIndex\StartPages\2
NotificationHRes
0
2868
SearchIndexer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Search\Gather\Windows\SystemIndex\StartPages\2
FollowDirectories
1
2868
SearchIndexer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Search\Gather\Windows\SystemIndex\StartPages\2
Type
0
2868
SearchIndexer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Search\Gather\Windows\SystemIndex\StartPages
NewStartPageIdentifier
4
2868
SearchIndexer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Search\Gather\Windows\SystemIndex\StartPages\3
URL
csc://{S-1-5-21-1302019708-1500728564-335382590-500}/
2868
SearchIndexer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Search\Gather\Windows\SystemIndex\StartPages\3
HostDepth
0
2868
SearchIndexer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Search\Gather\Windows\SystemIndex\StartPages\3
EnumerationDepth
4294967295
2868
SearchIndexer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Search\Gather\Windows\SystemIndex\StartPages\3
FollowDirectories
0
2868
SearchIndexer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Search\Gather\Windows\SystemIndex\StartPages\3
StartPageIdentifier
3
2868
SearchIndexer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Search\Gather\Windows\SystemIndex\StartPages\3
CrawlNumberInProgress
4294967295
2868
SearchIndexer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Search\Gather\Windows\SystemIndex\StartPages\3
CrawlNumberScheduled
4294967295
2868
SearchIndexer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Search\Gather\Windows\SystemIndex\StartPages\3
ForceFullCrawl
1
2868
SearchIndexer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Search\Gather\Windows\SystemIndex\StartPages\3
ForceFullCrawlExternal
0
2868
SearchIndexer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Search\Gather\Windows\SystemIndex\StartPages\3
LastCrawlStopped
0
2868
SearchIndexer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Search\Gather\Windows\SystemIndex\StartPages\3
Type
2
2868
SearchIndexer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Search\Gather\Windows\SystemIndex\StartPages\3
CrawlControl
0
2868
SearchIndexer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Search\Gather\Windows\SystemIndex\StartPages\3
LastCrawlType
0
2868
SearchIndexer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Search\Gather\Windows\SystemIndex\StartPages\3
IncludeInProjectCrawls
1
2868
SearchIndexer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Search\Gather\Windows\SystemIndex\StartPages\3
LastCrawlTime
0000000000000000
2868
SearchIndexer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Search\Gather\Windows\SystemIndex\StartPages\3
LastStartCrawlTime
0000000000000000
2868
SearchIndexer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Search\Gather\Windows\SystemIndex\StartPages\3
AccessControl
99CABADE03000000020000000000000000000000070000000100000000000000000000000700000000000000000000000000000007000000060000002C00000053002D0031002D0035002D00320031002D0031003300300032003000310039003700300038002D0031003500300030003700320038003500360034002D003300330035003300380032003500390030002D003500300030001C0000000105000000000005150000007C3E9B4DF44C73593E88FD13F4010000
2868
SearchIndexer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Search\Gather\Windows\SystemIndex\StartPages\3
NotificationHRes
0
2868
SearchIndexer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Search\Gather\Windows\SystemIndex\StartPages\3
FollowDirectories
1
2868
SearchIndexer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Search\Gather\Windows\SystemIndex\StartPages\3
Type
0
2868
SearchIndexer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Search\Gather\Windows\SystemIndex\StartPages
NewStartPageIdentifier
5
2868
SearchIndexer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Search\Gather\Windows\SystemIndex\StartPages\4
URL
iehistory://{S-1-5-21-1302019708-1500728564-335382590-1000}/
2868
SearchIndexer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Search\Gather\Windows\SystemIndex\StartPages\4
HostDepth
0
2868
SearchIndexer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Search\Gather\Windows\SystemIndex\StartPages\4
EnumerationDepth
4294967295
2868
SearchIndexer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Search\Gather\Windows\SystemIndex\StartPages\4
FollowDirectories
0
2868
SearchIndexer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Search\Gather\Windows\SystemIndex\StartPages\4
StartPageIdentifier
4
2868
SearchIndexer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Search\Gather\Windows\SystemIndex\StartPages\4
CrawlNumberInProgress
4294967295
2868
SearchIndexer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Search\Gather\Windows\SystemIndex\StartPages\4
CrawlNumberScheduled
4294967295
2868
SearchIndexer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Search\Gather\Windows\SystemIndex\StartPages\4
ForceFullCrawl
1
2868
SearchIndexer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Search\Gather\Windows\SystemIndex\StartPages\4
ForceFullCrawlExternal
0
2868
SearchIndexer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Search\Gather\Windows\SystemIndex\StartPages\4
LastCrawlStopped
0
2868
SearchIndexer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Search\Gather\Windows\SystemIndex\StartPages\4
Type
2
2868
SearchIndexer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Search\Gather\Windows\SystemIndex\StartPages\4
CrawlControl
0
2868
SearchIndexer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Search\Gather\Windows\SystemIndex\StartPages\4
LastCrawlType
0
2868
SearchIndexer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Search\Gather\Windows\SystemIndex\StartPages\4
IncludeInProjectCrawls
1
2868
SearchIndexer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Search\Gather\Windows\SystemIndex\StartPages\4
LastCrawlTime
0000000000000000
2868
SearchIndexer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Search\Gather\Windows\SystemIndex\StartPages\4
LastStartCrawlTime
0000000000000000
2868
SearchIndexer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Search\Gather\Windows\SystemIndex\StartPages\4
AccessControl
99CABADE03000000020000000000000000000000070000000100000000000000000000000700000000000000000000000000000007000000060000002D00000053002D0031002D0035002D00320031002D0031003300300032003000310039003700300038002D0031003500300030003700320038003500360034002D003300330035003300380032003500390030002D00310030003000300000001C0000000105000000000005150000007C3E9B4DF44C73593E88FD13E8030000
2868
SearchIndexer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Search\Gather\Windows\SystemIndex\StartPages\4
NotificationHRes
0
2868
SearchIndexer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Search\Gather\Windows\SystemIndex\StartPages\4
FollowDirectories
1
2868
SearchIndexer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Search\Gather\Windows\SystemIndex\StartPages\4
Type
0
2868
SearchIndexer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Search\Gather\Windows\SystemIndex\StartPages
NewStartPageIdentifier
6
2868
SearchIndexer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Search\Gather\Windows\SystemIndex\StartPages\5
URL
mapi://{S-1-5-21-1302019708-1500728564-335382590-1000}/
2868
SearchIndexer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Search\Gather\Windows\SystemIndex\StartPages\5
HostDepth
0
2868
SearchIndexer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Search\Gather\Windows\SystemIndex\StartPages\5
EnumerationDepth
4294967295
2868
SearchIndexer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Search\Gather\Windows\SystemIndex\StartPages\5
FollowDirectories
0
2868
SearchIndexer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Search\Gather\Windows\SystemIndex\StartPages\5
StartPageIdentifier
5
2868
SearchIndexer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Search\Gather\Windows\SystemIndex\StartPages\5
CrawlNumberInProgress
4294967295
2868
SearchIndexer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Search\Gather\Windows\SystemIndex\StartPages\5
CrawlNumberScheduled
4294967295
2868
SearchIndexer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Search\Gather\Windows\SystemIndex\StartPages\5
ForceFullCrawl
1
2868
SearchIndexer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Search\Gather\Windows\SystemIndex\StartPages\5
ForceFullCrawlExternal
0
2868
SearchIndexer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Search\Gather\Windows\SystemIndex\StartPages\5
LastCrawlStopped
0
2868
SearchIndexer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Search\Gather\Windows\SystemIndex\StartPages\5
Type
2
2868
SearchIndexer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Search\Gather\Windows\SystemIndex\StartPages\5
CrawlControl
0
2868
SearchIndexer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Search\Gather\Windows\SystemIndex\StartPages\5
LastCrawlType
0
2868
SearchIndexer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Search\Gather\Windows\SystemIndex\StartPages\5
IncludeInProjectCrawls
1
2868
SearchIndexer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Search\Gather\Windows\SystemIndex\StartPages\5
LastCrawlTime
0000000000000000
2868
SearchIndexer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Search\Gather\Windows\SystemIndex\StartPages\5
LastStartCrawlTime
0000000000000000
2868
SearchIndexer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Search\Gather\Windows\SystemIndex\StartPages\5
AccessControl
99CABADE03000000020000000000000000000000070000000100000000000000000000000700000000000000000000000000000007000000060000002D00000053002D0031002D0035002D00320031002D0031003300300032003000310039003700300038002D0031003500300030003700320038003500360034002D003300330035003300380032003500390030002D00310030003000300000001C0000000105000000000005150000007C3E9B4DF44C73593E88FD13E8030000
2868
SearchIndexer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Search\Gather\Windows\SystemIndex\StartPages\5
NotificationHRes
0
2868
SearchIndexer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Search\Gather\Windows\SystemIndex\StartPages\5
FollowDirectories
1
2868
SearchIndexer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Search\Gather\Windows\SystemIndex\StartPages\5
Type
0
2868
SearchIndexer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Search\Gather\Windows\SystemIndex\StartPages
NewStartPageIdentifier
7
2868
SearchIndexer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Search\Gather\Windows\SystemIndex\StartPages\6
URL
ONEINDEX14://{S-1-5-21-1302019708-1500728564-335382590-1000}/
2868
SearchIndexer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Search\Gather\Windows\SystemIndex\StartPages\6
HostDepth
0
2868
SearchIndexer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Search\Gather\Windows\SystemIndex\StartPages\6
EnumerationDepth
4294967295
2868
SearchIndexer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Search\Gather\Windows\SystemIndex\StartPages\6
FollowDirectories
0
2868
SearchIndexer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Search\Gather\Windows\SystemIndex\StartPages\6
StartPageIdentifier
6
2868
SearchIndexer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Search\Gather\Windows\SystemIndex\StartPages\6
CrawlNumberInProgress
4294967295
2868
SearchIndexer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Search\Gather\Windows\SystemIndex\StartPages\6
CrawlNumberScheduled
4294967295
2868
SearchIndexer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Search\Gather\Windows\SystemIndex\StartPages\6
ForceFullCrawl
1
2868
SearchIndexer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Search\Gather\Windows\SystemIndex\StartPages\6
ForceFullCrawlExternal
0
2868
SearchIndexer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Search\Gather\Windows\SystemIndex\StartPages\6
LastCrawlStopped
0
2868
SearchIndexer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Search\Gather\Windows\SystemIndex\StartPages\6
Type
2
2868
SearchIndexer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Search\Gather\Windows\SystemIndex\StartPages\6
CrawlControl
0
2868
SearchIndexer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Search\Gather\Windows\SystemIndex\StartPages\6
LastCrawlType
0
2868
SearchIndexer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Search\Gather\Windows\SystemIndex\StartPages\6
IncludeInProjectCrawls
1
2868
SearchIndexer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Search\Gather\Windows\SystemIndex\StartPages\6
LastCrawlTime
0000000000000000
2868
SearchIndexer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Search\Gather\Windows\SystemIndex\StartPages\6
LastStartCrawlTime
0000000000000000
2868
SearchIndexer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Search\Gather\Windows\SystemIndex\StartPages\6
AccessControl
99CABADE03000000020000000000000000000000070000000100000000000000000000000700000000000000000000000000000007000000060000002D00000053002D0031002D0035002D00320031002D0031003300300032003000310039003700300038002D0031003500300030003700320038003500360034002D003300330035003300380032003500390030002D00310030003000300000001C0000000105000000000005150000007C3E9B4DF44C73593E88FD13E8030000
2868
SearchIndexer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Search\Gather\Windows\SystemIndex\StartPages\6
NotificationHRes
0
2868
SearchIndexer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Search\Gather\Windows\SystemIndex\StartPages\6
FollowDirectories
1
2868
SearchIndexer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Search\Gather\Windows\SystemIndex\StartPages\6
Type
0
2868
SearchIndexer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Search\Gather\Windows\SystemIndex\Sites\LocalHost\Paths\0
Path
file:///C:\Users\*\AppData\Local\Microsoft\Windows\Temporary Internet Files\*
2868
SearchIndexer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Search\Gather\Windows\SystemIndex\Sites\LocalHost\Paths\0
Included
0
2868
SearchIndexer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Search\Gather\Windows\SystemIndex\Sites\LocalHost\Paths\0
EvaluationOrder
0
2868
SearchIndexer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Search\Gather\Windows\SystemIndex\Sites\LocalHost\Paths\0
IncludeSubdirs
1
2868
SearchIndexer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Search\Gather\Windows\SystemIndex\Sites\LocalHost\Paths\0
SuppressIndex
0
2868
SearchIndexer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Search\Gather\Windows\SystemIndex\Sites\LocalHost\Paths\0
ContentClass
2868
SearchIndexer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Search\Gather\Windows\SystemIndex\Sites\LocalHost\Paths\0
SearchPropertyMappingUrl
2868
SearchIndexer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Search\Gather\Windows\SystemIndex\Sites\LocalHost\Paths\0
FollowComplexUrls
0
2868
SearchIndexer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Search\Gather\Windows\SystemIndex\Sites\LocalHost\Paths\0
ApplyToDavHref
1
2868
SearchIndexer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Search\Gather\Windows\SystemIndex\Sites\LocalHost\Paths\0
Default
0
2868
SearchIndexer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Search\Gather\Windows\SystemIndex\Sites\LocalHost\Paths\0
Pattern
0
2868
SearchIndexer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Search\Gather\Windows\SystemIndex\Sites\LocalHost\Paths\0
Hierarchical
1
2868
SearchIndexer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Search\Gather\Windows\SystemIndex\Sites\LocalHost\Paths\0
AccessControl
99CABADE0300000002000000000000000000000007000000010000000000000000000000070000000000000000000000000000000700000002000000
2868
SearchIndexer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Search\Gather\Windows\SystemIndex\Sites\LocalHost\Paths\0
Default
1
2868
SearchIndexer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Search\Gather\Windows\SystemIndex\Sites\LocalHost\Paths\1
Path
file:///C:\Users\*\AppData\Local\Temp\*
2868
SearchIndexer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Search\Gather\Windows\SystemIndex\Sites\LocalHost\Paths\1
Included
0
2868
SearchIndexer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Search\Gather\Windows\SystemIndex\Sites\LocalHost\Paths\1
EvaluationOrder
1
2868
SearchIndexer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Search\Gather\Windows\SystemIndex\Sites\LocalHost\Paths\1
IncludeSubdirs
1
2868
SearchIndexer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Search\Gather\Windows\SystemIndex\Sites\LocalHost\Paths\1
SuppressIndex
0
2868
SearchIndexer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Search\Gather\Windows\SystemIndex\Sites\LocalHost\Paths\1
ContentClass
2868
SearchIndexer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Search\Gather\Windows\SystemIndex\Sites\LocalHost\Paths\1
SearchPropertyMappingUrl
2868
SearchIndexer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Search\Gather\Windows\SystemIndex\Sites\LocalHost\Paths\1
FollowComplexUrls
0
2868
SearchIndexer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Search\Gather\Windows\SystemIndex\Sites\LocalHost\Paths\1
ApplyToDavHref
1
2868
SearchIndexer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Search\Gather\Windows\SystemIndex\Sites\LocalHost\Paths\1
Default
0
2868
SearchIndexer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Search\Gather\Windows\SystemIndex\Sites\LocalHost\Paths\1
Pattern
0
2868
SearchIndexer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Search\Gather\Windows\SystemIndex\Sites\LocalHost\Paths\1
Hierarchical
1
2868
SearchIndexer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Search\Gather\Windows\SystemIndex\Sites\LocalHost\Paths\1
AccessControl
99CABADE0300000002000000000000000000000007000000010000000000000000000000070000000000000000000000000000000700000002000000
2868
SearchIndexer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Search\Gather\Windows\SystemIndex\Sites\LocalHost\Paths\1
Default
1
2868
SearchIndexer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Search\Gather\Windows\SystemIndex\Sites\LocalHost\Paths\2
Path
file:///C:\ProgramData\Microsoft\Search\Data\*
2868
SearchIndexer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Search\Gather\Windows\SystemIndex\Sites\LocalHost\Paths\2
Included
0
2868
SearchIndexer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Search\Gather\Windows\SystemIndex\Sites\LocalHost\Paths\2
EvaluationOrder
2
2868
SearchIndexer.exe
write
HKEY_LO