ÿþ<html dir="ltr" xmlns:v="urn:schemas-microsoft-com:vml" gpmc_reportInitialized="false"> <head> <meta http-equiv="Content-Type" content="text/html; charset=UTF-16" /> <title>FCPS - Blacklisted Software - GPO</title> <!-- Styles --> <style type="text/css"> body { background-color:#FFFFFF; border:1px solid #666666; color:#000000; font-size:68%; font-family:MS Shell Dlg; margin:0,0,10px,0; word-break:normal; word-wrap:break-word; } table { font-size:100%; table-layout:fixed; width:100%; } td,th { overflow:visible; text-align:left; vertical-align:top; white-space:normal; } .title { background:#FFFFFF; border:none; color:#333333; display:block; height:24px; margin:0px,0px,-1px,0px; padding-top:4px; position:relative; table-layout:fixed; width:100%; z-index:5; } .he0_expanded { background-color:#FEF7D6; border:1px solid #BBBBBB; color:#3333CC; cursor:hand; display:block; font-family:MS Shell Dlg; font-size:100%; font-weight:bold; height:2.25em; margin-bottom:-1px; margin-left:0px; margin-right:0px; padding-left:8px; padding-right:5em; padding-top:4px; position:relative; width:100%; } .he1_expanded { background-color:#A0BACB; border:1px solid #BBBBBB; color:#000000; cursor:hand; display:block; font-family:MS Shell Dlg; font-size:100%; font-weight:bold; height:2.25em; margin-bottom:-1px; margin-left:20px; margin-right:0px; padding-left:8px; padding-right:5em; padding-top:4px; position:relative; width:100%; } .he1h_expanded { background-color: #7197B3; border: 1px solid #BBBBBB; color: #000000; cursor: hand; display: block; font-family: MS Shell Dlg; font-size: 100%; font-weight: bold; height: 2.25em; margin-bottom: -1px; margin-left: 10px; margin-right: 0px; padding-left: 8px; padding-right: 5em; padding-top: 4px; position: relative; width: 100%; } .he1 { background-color:#A0BACB; border:1px solid #BBBBBB; color:#000000; cursor:hand; display:block; font-family:MS Shell Dlg; font-size:100%; font-weight:bold; height:2.25em; margin-bottom:-1px; margin-left:20px; margin-right:0px; padding-left:8px; padding-right:5em; padding-top:4px; position:relative; width:100%; } .he2 { background-color:#C0D2DE; border:1px solid #BBBBBB; color:#000000; cursor:hand; display:block; font-family:MS Shell Dlg; font-size:100%; font-weight:bold; height:2.25em; margin-bottom:-1px; margin-left:30px; margin-right:0px; padding-left:8px; padding-right:5em; padding-top:4px; position:relative; width:100%; } .he3 { background-color:#D9E3EA; border:1px solid #BBBBBB; color:#000000; cursor:hand; display:block; font-family:MS Shell Dlg; font-size:100%; font-weight:bold; height:2.25em; margin-bottom:-1px; margin-left:40px; margin-right:0px; padding-left:11px; padding-right:5em; padding-top:4px; position:relative; width:100%; } .he4 { background-color:#E8E8E8; border:1px solid #BBBBBB; color:#000000; cursor:hand; display:block; font-family:MS Shell Dlg; font-size:100%; font-weight:bold; height:2.25em; margin-bottom:-1px; margin-left:50px; margin-right:0px; padding-left:11px; padding-right:5em; padding-top:4px; position:relative; width:100%; } .he4h { background-color:#E8E8E8; border:1px solid #BBBBBB; color:#000000; cursor:hand; display:block; font-family:MS Shell Dlg; font-size:100%; font-weight:bold; height:2.25em; margin-bottom:-1px; margin-left:55px; margin-right:0px; padding-left:11px; padding-right:5em; padding-top:4px; position:relative; width:100%; } .he4i { background-color:#F9F9F9; border:1px solid #BBBBBB; color:#000000; display:block; font-family:MS Shell Dlg; font-size:100%; margin-bottom:-1px; margin-left:55px; margin-right:0px; padding-bottom:5px; padding-left:21px; padding-top:4px; position:relative; width:100%; } .he5 { background-color:#E8E8E8; border:1px solid #BBBBBB; color:#000000; cursor:hand; display:block; font-family:MS Shell Dlg; font-size:100%; font-weight:bold; height:2.25em; margin-bottom:-1px; margin-left:60px; margin-right:0px; padding-left:11px; padding-right:5em; padding-top:4px; position:relative; width:100%; } .he5h { background-color:#E8E8E8; border:1px solid #BBBBBB; color:#000000; cursor:hand; display:block; font-family:MS Shell Dlg; font-size:100%; padding-left:11px; padding-right:5em; padding-top:4px; margin-bottom:-1px; margin-left:65px; margin-right:0px; position:relative; width:100%; } .he5i { background-color:#F9F9F9; border:1px solid #BBBBBB; color:#000000; display:block; font-family:MS Shell Dlg; font-size:100%; margin-bottom:-1px; margin-left:65px; margin-right:0px; padding-left:21px; padding-bottom:5px; padding-top: 4px; position:relative; width:100%; } DIV .expando { color:#000000; text-decoration:none; display:block; font-family:MS Shell Dlg; font-size:100%; font-weight:normal; position:absolute; right:10px; text-decoration:underline; z-index: 0; } .he0 .expando { font-size:100%; } .info, .info3, .info4, .disalign { line-height:1.6em; padding:0px,0px,0px,0px; margin:0px,0px,0px,0px; } .disalign TD { padding-bottom:5px; padding-right:10px; } .info TD { padding-right:10px; width:50%; } .info3 TD { padding-right:10px; width:33%; } .info4 TD, .info4 TH { padding-right:10px; width:25%; } .info TH, .info3 TH, .info4 TH, .disalign TH { border-bottom:1px solid #CCCCCC; padding-right:10px; } .subtable, .subtable3 { border:1px solid #CCCCCC; margin-left:0px; background:#FFFFFF; margin-bottom:10px; } .subtable TD, .subtable3 TD { padding-left:10px; padding-right:5px; padding-top:3px; padding-bottom:3px; line-height:1.1em; width:10%; } .subtable TH, .subtable3 TH { border-bottom:1px solid #CCCCCC; font-weight:normal; padding-left:10px; line-height:1.6em; } .subtable .footnote { border-top:1px solid #CCCCCC; } .subtable3 .footnote, .subtable .footnote { border-top:1px solid #CCCCCC; } .subtable_frame { background:#D9E3EA; border:1px solid #CCCCCC; margin-bottom:10px; margin-left:15px; } .subtable_frame TD { line-height:1.1em; padding-bottom:3px; padding-left:10px; padding-right:15px; padding-top:3px; } .subtable_frame TH { border-bottom:1px solid #CCCCCC; font-weight:normal; padding-left:10px; line-height:1.6em; } .subtableInnerHead { border-bottom:1px solid #CCCCCC; border-top:1px solid #CCCCCC; } .explainlink { color:#000000; text-decoration:none; cursor:hand; } .explainlink:hover { color:#0000FF; text-decoration:underline; } .spacer { background:transparent; border:1px solid #BBBBBB; color:#FFFFFF; display:block; font-family:MS Shell Dlg; font-size:100%; height:10px; margin-bottom:-1px; margin-left:43px; margin-right:0px; padding-top: 4px; position:relative; } .filler { background:transparent; border:none; color:#FFFFFF; display:block; font:100% MS Shell Dlg; line-height:8px; margin-bottom:-1px; margin-left:53px; margin-right:0px; padding-top:4px; position:relative; } .container { display:block; position:relative; } .rsopheader { background-color:#A0BACB; border-bottom:1px solid black; color:#333333; font-family:MS Shell Dlg; font-size:130%; font-weight:bold; padding-bottom:5px; text-align:center; } .rsopname { color:#333333; font-family:MS Shell Dlg; font-size:130%; font-weight:bold; padding-left:11px; } .gponame{ color:#333333; font-family:MS Shell Dlg; font-size:130%; font-weight:bold; padding-left:11px; } .gpotype{ color:#333333; font-family:MS Shell Dlg; font-size:100%; font-weight:bold; padding-left:11px; } #uri { color:#333333; font-family:MS Shell Dlg; font-size:100%; padding-left:11px; } #dtstamp{ color:#333333; font-family:MS Shell Dlg; font-size:100%; padding-left:11px; text-align:left; width:30%; } #objshowhide { color:#000000; cursor:hand; font-family:MS Shell Dlg; font-size:100%; font-weight:bold; margin-right:0px; padding-right:10px; text-align:right; text-decoration:underline; z-index:2; word-wrap:normal; } #gposummary { display:block; } #gpoinformation { display:block; } @media print { #objshowhide{ display:none; } body { color:#000000; border:1px solid #000000; } .title { color:#000000; border:1px solid #000000; } .he0_expanded { color:#000000; border:1px solid #000000; } .he1h_expanded { color:#000000; border:1px solid #000000; } .he1_expanded { color:#000000; border:1px solid #000000; } .he1 { color:#000000; border:1px solid #000000; } .he2 { color:#000000; background:#EEEEEE; border:1px solid #000000; } .he3 { color:#000000; border:1px solid #000000; } .he4 { color:#000000; border:1px solid #000000; } .he4h { color:#000000; border:1px solid #000000; } .he4i { color:#000000; border:1px solid #000000; } .he5 { color:#000000; border:1px solid #000000; } .he5h { color:#000000; border:1px solid #000000; } .he5i { color:#000000; border:1px solid #000000; } } v\:* {behavior:url(#default#VML);} </style> <!-- Script 1 --> <script language="vbscript"> <!-- '================================================================================ ' String "strShowHide(0/1)" ' 0 = Hide all mode. ' 1 = Show all mode. strShowHide = 1 'Localized strings strShow = "show" strHide = "hide" strShowAll = "show all" strHideAll = "hide all" strShown = "shown" strHidden = "hidden" strExpandoNumPixelsFromEdge = "10px" Function IsSectionHeader(obj) IsSectionHeader = (obj.className = "he0_expanded") Or (obj.className = "he1h_expanded") Or (obj.className = "he1_expanded") Or (obj.className = "he1") Or (obj.className = "he2") Or (obj.className = "he3") Or (obj.className = "he4") Or (obj.className = "he4h") Or (obj.className = "he5") Or (obj.className = "he5h") End Function Function IsSectionExpandedByDefault(objHeader) IsSectionExpandedByDefault = (Right(objHeader.className, Len("_expanded")) = "_expanded") End Function ' strState must be show | hide | toggle Sub SetSectionState(objHeader, strState) ' Get the container object for the section. It's the first one after the header obj. i = objHeader.sourceIndex Set all = objHeader.parentElement.document.all While (all(i).className <> "container") i = i + 1 Wend Set objContainer = all(i) If strState = "toggle" Then If objContainer.style.display = "none" Then SetSectionState objHeader, "show" Else SetSectionState objHeader, "hide" End If Else Set objExpando = objHeader.children.item(1) If strState = "show" Then objContainer.style.display = "block" objExpando.innerText = strHide ElseIf strState = "hide" Then objContainer.style.display = "none" objExpando.innerText = strShow End If End If End Sub Sub ShowSection(objHeader) SetSectionState objHeader, "show" End Sub Sub HideSection(objHeader) SetSectionState objHeader, "hide" End Sub Sub ToggleSection(objHeader) SetSectionState objHeader, "toggle" End Sub '================================================================================ ' When user clicks anywhere in the document body, determine if user is clicking ' on a header element. '================================================================================ Function document_onclick() Set strsrc = window.event.srcElement While (strsrc.className = "sectionTitle" Or strsrc.className = "expando" Or strsrc.className = "vmlimage") Set strsrc = strsrc.parentElement Wend ' Only handle clicks on headers. If Not IsSectionHeader(strsrc) Then Exit Function ToggleSection strsrc window.event.returnValue = False End Function '================================================================================ ' link at the top of the page to collapse/expand all collapsable elements '================================================================================ Function objshowhide_onClick() Set objBody = document.body.all Select Case strShowHide Case 0 strShowHide = 1 objshowhide.innerText = strShowAll For Each obji In objBody If IsSectionHeader(obji) Then HideSection obji End If Next Case 1 strShowHide = 0 objshowhide.innerText = strHideAll For Each obji In objBody If IsSectionHeader(obji) Then ShowSection obji End If Next End Select End Function '================================================================================ ' onload collapse all except the first two levels of headers (he0, he1) '================================================================================ Function window_onload() ' Only initialize once. The UI may reinsert a report into the webbrowser control, ' firing onLoad multiple times. If UCase(document.documentElement.getAttribute("gpmc_reportInitialized")) <> "TRUE" Then ' Set text direction Call fDetDir(UCase(document.dir)) ' Initialize sections to default expanded/collapsed state. Set objBody = document.body.all For Each obji in objBody If IsSectionHeader(obji) Then If IsSectionExpandedByDefault(obji) Then ShowSection obji Else HideSection obji End If End If Next objshowhide.innerText = strShowAll document.documentElement.setAttribute "gpmc_reportInitialized", "true" End If End Function '================================================================================ ' When direction (LTR/RTL) changes, change adjust for readability '================================================================================ Function document_onPropertyChange() If window.event.propertyName = "dir" Then Call fDetDir(UCase(document.dir)) End If End Function Function fDetDir(strDir) strDir = UCase(strDir) Select Case strDir Case "LTR" Set colRules = document.styleSheets(0).rules For i = 0 To colRules.length -1 Set nug = colRules.item(i) strClass = nug.selectorText If nug.style.textAlign = "right" Then nug.style.textAlign = "left" End If Select Case strClass Case "DIV .expando" nug.style.Left = "" nug.style.right = strExpandoNumPixelsFromEdge Case "#objshowhide" nug.style.textAlign = "right" End Select Next Case "RTL" Set colRules = document.styleSheets(0).rules For i = 0 To colRules.length -1 Set nug = colRules.item(i) strClass = nug.selectorText If nug.style.textAlign = "left" Then nug.style.textAlign = "right" End If Select Case strClass Case "DIV .expando" nug.style.Left = strExpandoNumPixelsFromEdge nug.style.right = "" Case "#objshowhide" nug.style.textAlign = "left" End Select Next End Select End Function '================================================================================ 'When printing reports, if a given section is expanded, let's says "shown" (instead of "hide" in the UI). '================================================================================ Function window_onbeforeprint() For Each obji In document.all If obji.className = "expando" Then If obji.innerText = strHide Then obji.innerText = strShown If obji.innerText = strShow Then obji.innerText = strHidden End If Next End Function '================================================================================ 'If a section is collapsed, change to "hidden" in the printout (instead of "show"). '================================================================================ Function window_onafterprint() For Each obji In document.all If obji.className = "expando" Then If obji.innerText = strShown Then obji.innerText = strHide If obji.innerText = strHidden Then obji.innerText = strShow End If Next End Function '================================================================================ ' Adding keypress support for accessibility '================================================================================ Function document_onKeyPress() If window.event.keyCode = "32" Or window.event.keyCode = "13" Or window.event.keyCode = "10" Then 'space bar (32) or carriage return (13) or line feed (10) If window.event.srcElement.className = "expando" Then Call document_onclick() : window.event.returnValue = false If window.event.srcElement.className = "sectionTitle" Then Call document_onclick() : window.event.returnValue = false If window.event.srcElement.id = "objshowhide" Then Call objshowhide_onClick() : window.event.returnValue = false End If End Function --> </script> <!-- Script 2 --> <script language="javascript"> <!-- function getExplainWindowTitle() { return document.getElementById("explainText_windowTitle").innerHTML; } function getExplainWindowStyles() { return document.getElementById("explainText_windowStyles").innerHTML; } function getExplainWindowSettingPathLabel() { return document.getElementById("explainText_settingPathLabel").innerHTML; } function getExplainWindowExplainTextLabel() { return document.getElementById("explainText_explainTextLabel").innerHTML; } function getExplainWindowPrintButton() { return document.getElementById("explainText_printButton").innerHTML; } function getExplainWindowCloseButton() { return document.getElementById("explainText_closeButton").innerHTML; } function getNoExplainTextAvailable() { return document.getElementById("explainText_noExplainTextAvailable").innerHTML; } function getExplainWindowSupportedLabel() { return document.getElementById("explainText_supportedLabel").innerHTML; } function getNoSupportedTextAvailable() { return document.getElementById("explainText_noSupportedTextAvailable").innerHTML; } function showExplainText(srcElement) { var strSettingName = srcElement.getAttribute("gpmc_settingName"); var strSettingPath = srcElement.getAttribute("gpmc_settingPath"); var strSettingDescription = srcElement.getAttribute("gpmc_settingDescription"); if (strSettingDescription == "") { strSettingDescription = getNoExplainTextAvailable(); } var strSupported = srcElement.getAttribute("gpmc_supported"); if (strSupported == "") { strSupported = getNoSupportedTextAvailable(); } var strHtml = "<html>\n"; strHtml += "<head>\n"; strHtml += "<title>" + getExplainWindowTitle() + "</title>\n"; strHtml += "<style type='text/css'>\n" + getExplainWindowStyles() + "</style>\n"; strHtml += "</head>\n"; strHtml += "<body>\n"; strHtml += "<div class='head'>" + strSettingName +"</div>\n"; strHtml += "<div class='path'><b>" + getExplainWindowSettingPathLabel() + "</b><br/>" + strSettingPath +"</div>\n"; strHtml += "<div class='path'><b>" + getExplainWindowSupportedLabel() + "</b><br/>" + strSupported +"</div>\n"; strHtml += "<div class='info'>\n"; strHtml += "<div class='hdr'>" + getExplainWindowExplainTextLabel() + "</div>\n"; strHtml += "<div class='bdy'>" + strSettingDescription + "</div>\n"; strHtml += "<div class='btn'>"; strHtml += getExplainWindowPrintButton(); strHtml += getExplainWindowCloseButton(); strHtml += "</div></body></html>"; var strDiagArgs = "height=360px, width=630px, status=no, toolbar=no, scrollbars=yes, resizable=yes "; var expWin = window.open("", "expWin", strDiagArgs); expWin.document.write(""); expWin.document.close(); expWin.document.write(strHtml); expWin.document.close(); expWin.focus(); //cancels navigation for IE. if(navigator.userAgent.indexOf("MSIE") > 0) { window.event.returnValue = false; } return false; } --> </script> </head> <body> <!-- HTML resources --> <div style="display:none;"> <div id="explainText_windowTitle">Group Policy Management</div> <div id="explainText_windowStyles"> body { font-size:68%;font-family:MS Shell Dlg; margin:0px,0px,0px,0px; border: 1px solid #666666; background:#F6F6F6; width:100%; word-break:normal; word-wrap:break-word; } .head { font-weight:bold; font-size:160%; font-family:MS Shell Dlg; width:100%; color:#6587DC; background:#E3EAF9; border:1px solid #5582D2; padding-left:8px; height:24px; } .path { margin-left: 10px; margin-top: 10px; margin-bottom:5px;width:100%; } .info { padding-left:10px;width:100%; } table { font-size:100%; width:100%; border:1px solid #999999; } th { border-bottom:1px solid #999999; text-align:left; padding-left:10px; height:24px; } td { background:#FFFFFF; padding-left:10px; padding-bottom:10px; padding-top:10px; } .btn { width:100%; text-align:right; margin-top:16px; } .hdr { font-weight:bold; border:1px solid #999999; text-align:left; padding-top: 4px; padding-left:10px; height:24px; margin-bottom:-1px; width:100%; } .bdy { width:100%; height:182px; display:block; overflow:scroll; z-index:2; background:#FFFFFF; padding-left:10px; padding-bottom:10px; padding-top:10px; border:1px solid #999999; } button { width:6.9em; height:2.1em; font-size:100%; font-family:MS Shell Dlg; margin-right:15px; } @media print { .bdy { display:block; overflow:visible; } button { display:none; } .head { color:#000000; background:#FFFFFF; border:1px solid #000000; } } </div> <div id="explainText_settingPathLabel">Setting Path:</div> <div id="explainText_explainTextLabel">Explanation</div> <div id="explainText_printButton"> <button name="Print" onClick="window.print()" accesskey="P"><u>P</u>rint</button> </div> <div id="explainText_closeButton"> <button name="Close" onClick="window.close()" accesskey="C"><u>C</u>lose</button> </div> <div id="explainText_noExplainTextAvailable">No explanation is available for this setting.</div> <div id="explainText_supportedLabel">Supported On:</div> <div id="explainText_noSupportedTextAvailable">Not available</div> </div><table class="title" cellpadding="0" cellspacing="0"> <tr><td colspan="2" class="gponame">FCPS - Blacklisted Software - GPO</td></tr> <tr> <td id="dtstamp">Data collected on: 10/29/2010 9:54:58 AM</td> <td><div id="objshowhide" tabindex="0"></div></td> </tr> </table> <div class="gposummary"> <div class="he0_expanded"><span class="sectionTitle" tabindex="0">General</span><a class="expando" href="#"></a></div> <div class="container"><div class="he1"><span class="sectionTitle" tabindex="0">Details</span><a class="expando" href="#"></a></div> <div class="container"><div class="he4i"><table class="info" cellpadding="0" cellspacing="0"> <tr><td scope="row">Domain</td><td>fcps.edu</td></tr> <tr><td scope="row">Owner</td><td>FCPSEDU\Domain Admins</td></tr> <tr><td scope="row">Created</td><td>2/15/2007 1:42:26 PM</td></tr> <tr><td scope="row">Modified</td><td>3/30/2010 4:06:06 PM</td></tr> <tr><td scope="row">User Revisions</td><td>170 (AD), 170 (sysvol)</td></tr> <tr><td scope="row">Computer Revisions</td><td>212 (AD), 212 (sysvol)</td></tr> <tr><td scope="row">Unique ID</td><td>{49FC9C48-211E-44EB-8CCE-453472052038}</td></tr> <tr><td scope="row">GPO Status</td><td>User settings disabled</td></tr> </table></div></div> <div class="filler"></div> <div class="he1"><span class="sectionTitle" tabindex="0">Links</span><a class="expando" href="#"></a></div> <div class="container"><div class="he4i"><table class="info3" cellpadding="0" cellspacing="0"><tr><th scope="col">Location</th><th scope="col">Enforced</th><th scope="col">Link Status</th><th scope="col">Path</th></tr> <tr><td>fcps</td><td>No</td><td>Enabled</td><td>fcps.edu</td></tr> </table> <br/>This list only includes links in the domain of the GPO.</div></div> <div class="filler"></div> <div class="he1"><span class="sectionTitle" tabindex="0">Security Filtering</span><a class="expando" href="#"></a></div> <div class="container"><div class="he4i"><b>The settings in this GPO can only apply to the following groups, users, and computers:</b></div> <div class="he4i"> <table class="info" cellpadding="0" cellspacing="0"><tr><th scope="col">Name</th></tr><tr><td>NT AUTHORITY\Authenticated Users</td></tr></table> </div> </div> <div class="filler"></div> <div class="filler"></div> <div class="he1"><span class="sectionTitle" tabindex="0">Delegation</span><a class="expando" href="#"></a></div> <div class="container"><div class="he4i"><b>These groups and users have the specified permission for this GPO</b></div> <div class="he4i"> <table class="info3" cellpadding="0" cellspacing="0"> <tr><th scope="col">Name</th><th scope="col">Allowed Permissions</th><th scope="col">Inherited</th></tr> <tr><td>FCPSEDU\Domain Admins</td><td>Edit settings, delete, modify security</td><td>No</td></tr> <tr><td>FCPSEDU\Enterprise Admins</td><td>Edit settings, delete, modify security</td><td>No</td></tr> <tr><td>NT AUTHORITY\Authenticated Users</td><td>Read (from Security Filtering)</td><td>No</td></tr> <tr><td>NT AUTHORITY\ENTERPRISE DOMAIN CONTROLLERS</td><td>Custom</td><td>No</td></tr> <tr><td>NT AUTHORITY\SYSTEM</td><td>Edit settings, delete, modify security</td><td>No</td></tr> <tr><td>S-1-5-21-527237240-764733703-725345543-1083258</td><td>Custom</td><td>No</td></tr> </table> </div></div></div> <div class="filler"></div> </div> <div class="he0_expanded"><span class="sectionTitle" tabindex="0">Computer Configuration (Enabled)</span><a class="expando" href="#"></a></div> <div class="container"><div class="he1h_expanded"><span class="sectionTitle" tabindex="0">Policies</span><a class="expando" href="#"></a></div> <div class="container"><div class="he1_expanded"><span class="sectionTitle" tabindex="0">Windows Settings</span><a class="expando" href="#"></a></div> <div class="container"><div class="he2"><span class="sectionTitle" tabindex="0">Security Settings</span><a class="expando" href="#"></a></div> <div class="container"><div class="he4i"><b>An error has occurred while collecting data for Software Restriction Policies.</b><br/><br/> <table class="subtable" cellpadding="0" cellspacing="0"> <tr><th>This error impacts the following settings:</th></tr> <tr><td>Software Restriction Policies<br/> Software Restriction Policies/Security Levels<br/> Software Restriction Policies/Additional Rules </td></tr> <tr><td class="subtableInnerHead">The following errors apply to all of the above settings:</td></tr> <tr><td>An unknown error occurred while data was gathered for this extension. Details: Unable to cast object of type 'System.String[]' to type 'Microsoft.GroupPolicy.Reporting.Extensions.Registry.UnknownType'.</td></tr> </table></div><div class="he3"><span class="sectionTitle" tabindex="0">Local Policies/Audit Policy</span><a class="expando" href="#"></a></div> <div class="container"><div class="he4i"><table class="info" cellpadding="0" cellspacing="0"> <tr><th scope="col">Policy</th><th scope="col">Setting</th></tr> <tr><td>Audit account logon events</td><td>Success, Failure</td></tr> <tr><td>Audit account management</td><td>Success, Failure</td></tr> <tr><td>Audit directory service access</td><td>Success, Failure</td></tr> <tr><td>Audit logon events</td><td>Success, Failure</td></tr> <tr><td>Audit object access</td><td>Success, Failure</td></tr> <tr><td>Audit policy change</td><td>Success, Failure</td></tr> <tr><td>Audit privilege use</td><td>Success, Failure</td></tr> <tr><td>Audit process tracking</td><td>Success, Failure</td></tr> <tr><td>Audit system events</td><td>Success, Failure</td></tr> </table> </div></div><div class="he3"><span class="sectionTitle" tabindex="0">Public Key Policies/Trusted Root Certification Authorities</span><a class="expando" href="#"></a></div> <div class="container"><div class="he4h"><span class="sectionTitle" tabindex="0">Properties</span><a class="expando" href="#"></a></div> <div class="container"><div class="he4i"> <table class="subtable" cellpadding="0" cellspacing="0"> <tr><th scope="col">Policy</th><th scope="col">Setting</th></tr> <tr><td>Allow users to select new root certification authorities (CAs) to trust</td><td>Enabled</td></tr> <tr><td>Client computers can trust the following certificate stores</td><td>Third-Party Root Certification Authorities and Enterprise Root Certification Authorities</td></tr> <tr><td>To perform certificate-based authentication of users and computers, CAs must meet the following criteria</td><td>Registered in Active Directory only</td></tr> </table> </div></div></div></div></div><div class="filler"></div> <div class="he1"><span class="sectionTitle" tabindex="0">Administrative Templates</span><a class="expando" href="#"></a></div> <div class="container"><div class="he4i">Policy definitions (ADMX files) retrieved from the central store.</div><div class="he3"><span class="sectionTitle" tabindex="0">Extra Registry Settings</span><a class="expando" href="#"></a></div> <div class="container"><div class="he4i">Display names for some settings cannot be found. You might be able to resolve this issue by updating the .ADM files used by Group Policy Management.<br/><br/><table class="info" cellpadding="0" cellspacing="0"> <tr><th scope="col">Setting</th><th scope="col">State</th></tr> <tr><td>Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Hashes\{01ef2f01-269f-4b15-89b5-64df5582461d}\Description</td><td></td></tr> <tr><td>Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Hashes\{01ef2f01-269f-4b15-89b5-64df5582461d}\FriendlyName</td><td> (3.1.0.27) WinPcap 3.1 installer WinPcap 3.1 CACE Technologies</td></tr> <tr><td>Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Hashes\{01ef2f01-269f-4b15-89b5-64df5582461d}\HashAlg</td><td>32771</td></tr> <tr><td>Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Hashes\{01ef2f01-269f-4b15-89b5-64df5582461d}\ItemData</td><td>Unknown data format</td></tr> <tr><td>Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Hashes\{01ef2f01-269f-4b15-89b5-64df5582461d}\ItemSize</td><td>467181</td></tr> <tr><td>Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Hashes\{01ef2f01-269f-4b15-89b5-64df5582461d}\LastModified</td><td>128697804749522166</td></tr> <tr><td>Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Hashes\{01ef2f01-269f-4b15-89b5-64df5582461d}\SaferFlags</td><td>0</td></tr> <tr><td>Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Hashes\{073ab610-0062-4ec7-b791-413780f282dd}\Description</td><td>copies the contents of all usb thumb drives that are plugged into a computer</td></tr> <tr><td>Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Hashes\{073ab610-0062-4ec7-b791-413780f282dd}\FriendlyName</td><td>USBDumper.exe 45 KB 2/19/2006 6:58:36 PM</td></tr> <tr><td>Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Hashes\{073ab610-0062-4ec7-b791-413780f282dd}\HashAlg</td><td>32771</td></tr> <tr><td>Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Hashes\{073ab610-0062-4ec7-b791-413780f282dd}\ItemData</td><td>Unknown data format</td></tr> <tr><td>Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Hashes\{073ab610-0062-4ec7-b791-413780f282dd}\ItemSize</td><td>45056</td></tr> <tr><td>Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Hashes\{073ab610-0062-4ec7-b791-413780f282dd}\LastModified</td><td>128808430337392716</td></tr> <tr><td>Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Hashes\{073ab610-0062-4ec7-b791-413780f282dd}\SaferFlags</td><td>0</td></tr> <tr><td>Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Hashes\{0a36c23f-2d49-4049-96f2-443ef5f8da6b}\Description</td><td></td></tr> <tr><td>Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Hashes\{0a36c23f-2d49-4049-96f2-443ef5f8da6b}\FriendlyName</td><td>privoxy.exe (3.0.6.0) Privoxy Privoxy Privoxy The Privoxy team - www.privoxy.org</td></tr> <tr><td>Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Hashes\{0a36c23f-2d49-4049-96f2-443ef5f8da6b}\HashAlg</td><td>32771</td></tr> <tr><td>Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Hashes\{0a36c23f-2d49-4049-96f2-443ef5f8da6b}\ItemData</td><td>Unknown data format</td></tr> <tr><td>Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Hashes\{0a36c23f-2d49-4049-96f2-443ef5f8da6b}\ItemSize</td><td>250368</td></tr> <tr><td>Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Hashes\{0a36c23f-2d49-4049-96f2-443ef5f8da6b}\LastModified</td><td>128697806577169680</td></tr> <tr><td>Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Hashes\{0a36c23f-2d49-4049-96f2-443ef5f8da6b}\SaferFlags</td><td>0</td></tr> <tr><td>Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Hashes\{0d591533-4c10-43b4-9d9c-820794508543}\Description</td><td>firefox password stealer</td></tr> <tr><td>Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Hashes\{0d591533-4c10-43b4-9d9c-820794508543}\FriendlyName</td><td>FirePassword.exe 41 KB 3/6/2009 2:23:18 PM</td></tr> <tr><td>Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Hashes\{0d591533-4c10-43b4-9d9c-820794508543}\HashAlg</td><td>32771</td></tr> <tr><td>Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Hashes\{0d591533-4c10-43b4-9d9c-820794508543}\ItemData</td><td>Unknown data format</td></tr> <tr><td>Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Hashes\{0d591533-4c10-43b4-9d9c-820794508543}\ItemSize</td><td>40960</td></tr> <tr><td>Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Hashes\{0d591533-4c10-43b4-9d9c-820794508543}\LastModified</td><td>128808416431209260</td></tr> <tr><td>Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Hashes\{0d591533-4c10-43b4-9d9c-820794508543}\SaferFlags</td><td>0</td></tr> <tr><td>Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Hashes\{138d17b0-5669-4adc-82b0-8f6f8c3b431d}\Description</td><td></td></tr> <tr><td>Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Hashes\{138d17b0-5669-4adc-82b0-8f6f8c3b431d}\FriendlyName</td><td>NTcrack.exe 36 KB 3/29/1997 9:04:44 PM</td></tr> <tr><td>Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Hashes\{138d17b0-5669-4adc-82b0-8f6f8c3b431d}\HashAlg</td><td>32771</td></tr> <tr><td>Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Hashes\{138d17b0-5669-4adc-82b0-8f6f8c3b431d}\ItemData</td><td>Unknown data format</td></tr> <tr><td>Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Hashes\{138d17b0-5669-4adc-82b0-8f6f8c3b431d}\ItemSize</td><td>36203</td></tr> <tr><td>Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Hashes\{138d17b0-5669-4adc-82b0-8f6f8c3b431d}\LastModified</td><td>128697802478857180</td></tr> <tr><td>Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Hashes\{138d17b0-5669-4adc-82b0-8f6f8c3b431d}\SaferFlags</td><td>0</td></tr> <tr><td>Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Hashes\{2398f60f-206f-468b-83d2-70c35351878b}\Description</td><td>steals wireless passwords</td></tr> <tr><td>Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Hashes\{2398f60f-206f-468b-83d2-70c35351878b}\FriendlyName</td><td>WirelessKeyView.exe (1.0.0.0) WirelessKeyView WirelessKeyView WirelessKeyView NirSoft</td></tr> <tr><td>Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Hashes\{2398f60f-206f-468b-83d2-70c35351878b}\HashAlg</td><td>32771</td></tr> <tr><td>Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Hashes\{2398f60f-206f-468b-83d2-70c35351878b}\ItemData</td><td>Unknown data format</td></tr> <tr><td>Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Hashes\{2398f60f-206f-468b-83d2-70c35351878b}\ItemSize</td><td>36864</td></tr> <tr><td>Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Hashes\{2398f60f-206f-468b-83d2-70c35351878b}\LastModified</td><td>128808424918953016</td></tr> <tr><td>Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Hashes\{2398f60f-206f-468b-83d2-70c35351878b}\SaferFlags</td><td>0</td></tr> <tr><td>Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Hashes\{2b1bdc0f-64f1-40e9-b492-df78d6075999}\Description</td><td></td></tr> <tr><td>Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Hashes\{2b1bdc0f-64f1-40e9-b492-df78d6075999}\FriendlyName</td><td>WinDump-3.9.3.exe 545 KB 1/16/2006 12:58:36 PM</td></tr> <tr><td>Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Hashes\{2b1bdc0f-64f1-40e9-b492-df78d6075999}\HashAlg</td><td>32771</td></tr> <tr><td>Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Hashes\{2b1bdc0f-64f1-40e9-b492-df78d6075999}\ItemData</td><td>Unknown data format</td></tr> <tr><td>Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Hashes\{2b1bdc0f-64f1-40e9-b492-df78d6075999}\ItemSize</td><td>557056</td></tr> <tr><td>Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Hashes\{2b1bdc0f-64f1-40e9-b492-df78d6075999}\LastModified</td><td>128697804003622858</td></tr> <tr><td>Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Hashes\{2b1bdc0f-64f1-40e9-b492-df78d6075999}\SaferFlags</td><td>0</td></tr> <tr><td>Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Hashes\{37cc1ce8-7812-4b11-8ff3-bc292b032661}\Description</td><td></td></tr> <tr><td>Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Hashes\{37cc1ce8-7812-4b11-8ff3-bc292b032661}\FriendlyName</td><td>stub32i.exe (2.11.15.0) stub32i.exe LC5 @stake</td></tr> <tr><td>Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Hashes\{37cc1ce8-7812-4b11-8ff3-bc292b032661}\HashAlg</td><td>32771</td></tr> <tr><td>Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Hashes\{37cc1ce8-7812-4b11-8ff3-bc292b032661}\ItemData</td><td>Unknown data format</td></tr> <tr><td>Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Hashes\{37cc1ce8-7812-4b11-8ff3-bc292b032661}\ItemSize</td><td>5694786</td></tr> <tr><td>Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Hashes\{37cc1ce8-7812-4b11-8ff3-bc292b032661}\LastModified</td><td>128697801472502458</td></tr> <tr><td>Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Hashes\{37cc1ce8-7812-4b11-8ff3-bc292b032661}\SaferFlags</td><td>0</td></tr> <tr><td>Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Hashes\{3ca9a827-935c-4968-95f6-26ec7cb5955a}\Description</td><td></td></tr> <tr><td>Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Hashes\{3ca9a827-935c-4968-95f6-26ec7cb5955a}\FriendlyName</td><td> (0.0.11.0) </td></tr> <tr><td>Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Hashes\{3ca9a827-935c-4968-95f6-26ec7cb5955a}\HashAlg</td><td>32771</td></tr> <tr><td>Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Hashes\{3ca9a827-935c-4968-95f6-26ec7cb5955a}\ItemData</td><td>Unknown data format</td></tr> <tr><td>Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Hashes\{3ca9a827-935c-4968-95f6-26ec7cb5955a}\ItemSize</td><td>11891712</td></tr> <tr><td>Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Hashes\{3ca9a827-935c-4968-95f6-26ec7cb5955a}\LastModified</td><td>128697806802843776</td></tr> <tr><td>Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Hashes\{3ca9a827-935c-4968-95f6-26ec7cb5955a}\SaferFlags</td><td>0</td></tr> <tr><td>Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Hashes\{3d5e1ca0-e334-4646-945a-dff07c557eea}\Description</td><td></td></tr> <tr><td>Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Hashes\{3d5e1ca0-e334-4646-945a-dff07c557eea}\FriendlyName</td><td>lsadump2.exe 33 KB 3/29/2000 3:19:00 PM</td></tr> <tr><td>Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Hashes\{3d5e1ca0-e334-4646-945a-dff07c557eea}\HashAlg</td><td>32771</td></tr> <tr><td>Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Hashes\{3d5e1ca0-e334-4646-945a-dff07c557eea}\ItemData</td><td>Unknown data format</td></tr> <tr><td>Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Hashes\{3d5e1ca0-e334-4646-945a-dff07c557eea}\ItemSize</td><td>32768</td></tr> <tr><td>Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Hashes\{3d5e1ca0-e334-4646-945a-dff07c557eea}\LastModified</td><td>128697801801391868</td></tr> <tr><td>Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Hashes\{3d5e1ca0-e334-4646-945a-dff07c557eea}\SaferFlags</td><td>0</td></tr> <tr><td>Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Hashes\{410752fe-a5bb-4664-8d1c-4dae8907b789}\Description</td><td></td></tr> <tr><td>Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Hashes\{410752fe-a5bb-4664-8d1c-4dae8907b789}\FriendlyName</td><td> (5.0.4.0) </td></tr> <tr><td>Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Hashes\{410752fe-a5bb-4664-8d1c-4dae8907b789}\HashAlg</td><td>32771</td></tr> <tr><td>Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Hashes\{410752fe-a5bb-4664-8d1c-4dae8907b789}\ItemData</td><td>Unknown data format</td></tr> <tr><td>Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Hashes\{410752fe-a5bb-4664-8d1c-4dae8907b789}\ItemSize</td><td>2396672</td></tr> <tr><td>Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Hashes\{410752fe-a5bb-4664-8d1c-4dae8907b789}\LastModified</td><td>128697801649993370</td></tr> <tr><td>Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Hashes\{410752fe-a5bb-4664-8d1c-4dae8907b789}\SaferFlags</td><td>0</td></tr> <tr><td>Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Hashes\{46bb9475-8e60-47e1-a34a-9a9528d69b42}\Description</td><td></td></tr> <tr><td>Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Hashes\{46bb9475-8e60-47e1-a34a-9a9528d69b42}\FriendlyName</td><td>john-386.exe 164 KB 4/26/2007 12:36:20 PM</td></tr> <tr><td>Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Hashes\{46bb9475-8e60-47e1-a34a-9a9528d69b42}\HashAlg</td><td>32771</td></tr> <tr><td>Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Hashes\{46bb9475-8e60-47e1-a34a-9a9528d69b42}\ItemData</td><td>Unknown data format</td></tr> <tr><td>Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Hashes\{46bb9475-8e60-47e1-a34a-9a9528d69b42}\ItemSize</td><td>167424</td></tr> <tr><td>Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Hashes\{46bb9475-8e60-47e1-a34a-9a9528d69b42}\LastModified</td><td>128697800586454076</td></tr> <tr><td>Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Hashes\{46bb9475-8e60-47e1-a34a-9a9528d69b42}\SaferFlags</td><td>0</td></tr> <tr><td>Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Hashes\{5139e468-f07a-4549-83ad-73f6a88a9639}\Description</td><td></td></tr> <tr><td>Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Hashes\{5139e468-f07a-4549-83ad-73f6a88a9639}\FriendlyName</td><td>iepv.exe (1.0.0.0) IE PassView Internet Explorer Passwords Viewer IE PassView NirSoft</td></tr> <tr><td>Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Hashes\{5139e468-f07a-4549-83ad-73f6a88a9639}\HashAlg</td><td>32771</td></tr> <tr><td>Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Hashes\{5139e468-f07a-4549-83ad-73f6a88a9639}\ItemData</td><td>Unknown data format</td></tr> <tr><td>Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Hashes\{5139e468-f07a-4549-83ad-73f6a88a9639}\ItemSize</td><td>39424</td></tr> <tr><td>Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Hashes\{5139e468-f07a-4549-83ad-73f6a88a9639}\LastModified</td><td>128808417853120266</td></tr> <tr><td>Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Hashes\{5139e468-f07a-4549-83ad-73f6a88a9639}\SaferFlags</td><td>0</td></tr> <tr><td>Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Hashes\{5a33ffd2-1979-4a72-9dc5-a3a3b88b312d}\Description</td><td></td></tr> <tr><td>Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Hashes\{5a33ffd2-1979-4a72-9dc5-a3a3b88b312d}\FriendlyName</td><td>tor.exe 1201 KB 12/14/2006 9:21:44 PM</td></tr> <tr><td>Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Hashes\{5a33ffd2-1979-4a72-9dc5-a3a3b88b312d}\HashAlg</td><td>32771</td></tr> <tr><td>Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Hashes\{5a33ffd2-1979-4a72-9dc5-a3a3b88b312d}\ItemData</td><td>Unknown data format</td></tr> <tr><td>Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Hashes\{5a33ffd2-1979-4a72-9dc5-a3a3b88b312d}\ItemSize</td><td>1228800</td></tr> <tr><td>Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Hashes\{5a33ffd2-1979-4a72-9dc5-a3a3b88b312d}\LastModified</td><td>128697806687506184</td></tr> <tr><td>Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Hashes\{5a33ffd2-1979-4a72-9dc5-a3a3b88b312d}\SaferFlags</td><td>0</td></tr> <tr><td>Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Hashes\{5b2fc713-dbc2-40ce-ad16-cfcd72f54b38}\Description</td><td></td></tr> <tr><td>Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Hashes\{5b2fc713-dbc2-40ce-ad16-cfcd72f54b38}\FriendlyName</td><td>john.exe 125 KB 12/3/1998 4:19:08 AM</td></tr> <tr><td>Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Hashes\{5b2fc713-dbc2-40ce-ad16-cfcd72f54b38}\HashAlg</td><td>32771</td></tr> <tr><td>Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Hashes\{5b2fc713-dbc2-40ce-ad16-cfcd72f54b38}\ItemData</td><td>Unknown data format</td></tr> <tr><td>Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Hashes\{5b2fc713-dbc2-40ce-ad16-cfcd72f54b38}\ItemSize</td><td>127488</td></tr> <tr><td>Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Hashes\{5b2fc713-dbc2-40ce-ad16-cfcd72f54b38}\LastModified</td><td>128697800781600334</td></tr> <tr><td>Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Hashes\{5b2fc713-dbc2-40ce-ad16-cfcd72f54b38}\SaferFlags</td><td>0</td></tr> <tr><td>Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Hashes\{5fbf2626-5b70-44a5-9246-2bcfb9f5c2e1}\Description</td><td></td></tr> <tr><td>Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Hashes\{5fbf2626-5b70-44a5-9246-2bcfb9f5c2e1}\FriendlyName</td><td>nemesis.exe 133 KB 10/6/2004 10:25:16 PM</td></tr> <tr><td>Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Hashes\{5fbf2626-5b70-44a5-9246-2bcfb9f5c2e1}\HashAlg</td><td>32771</td></tr> <tr><td>Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Hashes\{5fbf2626-5b70-44a5-9246-2bcfb9f5c2e1}\ItemData</td><td>Unknown data format</td></tr> <tr><td>Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Hashes\{5fbf2626-5b70-44a5-9246-2bcfb9f5c2e1}\ItemSize</td><td>135189</td></tr> <tr><td>Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Hashes\{5fbf2626-5b70-44a5-9246-2bcfb9f5c2e1}\LastModified</td><td>128697802115750772</td></tr> <tr><td>Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Hashes\{5fbf2626-5b70-44a5-9246-2bcfb9f5c2e1}\SaferFlags</td><td>0</td></tr> <tr><td>Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Hashes\{733ff4c7-d9f3-4f07-b7b1-2ea88db1970d}\Description</td><td>alternative command shell with other functionality</td></tr> <tr><td>Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Hashes\{733ff4c7-d9f3-4f07-b7b1-2ea88db1970d}\FriendlyName</td><td>NirCmd.exe (1.8.2.151) NirCmd NirCmd NirCmd NirSoft</td></tr> <tr><td>Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Hashes\{733ff4c7-d9f3-4f07-b7b1-2ea88db1970d}\HashAlg</td><td>32771</td></tr> <tr><td>Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Hashes\{733ff4c7-d9f3-4f07-b7b1-2ea88db1970d}\ItemData</td><td>Unknown data format</td></tr> <tr><td>Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Hashes\{733ff4c7-d9f3-4f07-b7b1-2ea88db1970d}\ItemSize</td><td>25600</td></tr> <tr><td>Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Hashes\{733ff4c7-d9f3-4f07-b7b1-2ea88db1970d}\LastModified</td><td>128808420457250493</td></tr> <tr><td>Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Hashes\{733ff4c7-d9f3-4f07-b7b1-2ea88db1970d}\SaferFlags</td><td>0</td></tr> <tr><td>Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Hashes\{7375366a-03af-46d3-a7cb-338f1b5e902a}\Description</td><td></td></tr> <tr><td>Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Hashes\{7375366a-03af-46d3-a7cb-338f1b5e902a}\FriendlyName</td><td>l0phtcrackv4.00winntxpkeygencore[1].zip 162 KB 5/2/2005 1:13:04 PM</td></tr> <tr><td>Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Hashes\{7375366a-03af-46d3-a7cb-338f1b5e902a}\HashAlg</td><td>32771</td></tr> <tr><td>Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Hashes\{7375366a-03af-46d3-a7cb-338f1b5e902a}\ItemData</td><td>Unknown data format</td></tr> <tr><td>Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Hashes\{7375366a-03af-46d3-a7cb-338f1b5e902a}\ItemSize</td><td>165255</td></tr> <tr><td>Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Hashes\{7375366a-03af-46d3-a7cb-338f1b5e902a}\LastModified</td><td>128697801380319678</td></tr> <tr><td>Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Hashes\{7375366a-03af-46d3-a7cb-338f1b5e902a}\SaferFlags</td><td>0</td></tr> <tr><td>Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Hashes\{740c44dd-2bb7-49d1-9048-7a55f8255969}\Description</td><td></td></tr> <tr><td>Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Hashes\{740c44dd-2bb7-49d1-9048-7a55f8255969}\FriendlyName</td><td>nc.exe 61 KB 9/6/2006 11:42:38 AM</td></tr> <tr><td>Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Hashes\{740c44dd-2bb7-49d1-9048-7a55f8255969}\HashAlg</td><td>32771</td></tr> <tr><td>Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Hashes\{740c44dd-2bb7-49d1-9048-7a55f8255969}\ItemData</td><td>Unknown data format</td></tr> <tr><td>Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Hashes\{740c44dd-2bb7-49d1-9048-7a55f8255969}\ItemSize</td><td>61440</td></tr> <tr><td>Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Hashes\{740c44dd-2bb7-49d1-9048-7a55f8255969}\LastModified</td><td>128697802273086466</td></tr> <tr><td>Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Hashes\{740c44dd-2bb7-49d1-9048-7a55f8255969}\SaferFlags</td><td>0</td></tr> <tr><td>Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Hashes\{742399de-2334-4ccd-99ba-b6c6dc7c1415}\Description</td><td></td></tr> <tr><td>Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Hashes\{742399de-2334-4ccd-99ba-b6c6dc7c1415}\FriendlyName</td><td>wireshark-setup-0.99.5.exe 17714 KB 4/10/2007 11:16:50 AM</td></tr> <tr><td>Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Hashes\{742399de-2334-4ccd-99ba-b6c6dc7c1415}\HashAlg</td><td>32771</td></tr> <tr><td>Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Hashes\{742399de-2334-4ccd-99ba-b6c6dc7c1415}\ItemData</td><td>Unknown data format</td></tr> <tr><td>Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Hashes\{742399de-2334-4ccd-99ba-b6c6dc7c1415}\ItemSize</td><td>18138441</td></tr> <tr><td>Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Hashes\{742399de-2334-4ccd-99ba-b6c6dc7c1415}\LastModified</td><td>128697806348057336</td></tr> <tr><td>Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Hashes\{742399de-2334-4ccd-99ba-b6c6dc7c1415}\SaferFlags</td><td>0</td></tr> <tr><td>Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Hashes\{79e214f5-70c2-4ab3-b9a7-6abc1a59ca90}\Description</td><td>rainbow table password cracking tool</td></tr> <tr><td>Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Hashes\{79e214f5-70c2-4ab3-b9a7-6abc1a59ca90}\FriendlyName</td><td>rcrack.exe 173 KB 2/11/2009 9:47:30 PM</td></tr> <tr><td>Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Hashes\{79e214f5-70c2-4ab3-b9a7-6abc1a59ca90}\HashAlg</td><td>32771</td></tr> <tr><td>Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Hashes\{79e214f5-70c2-4ab3-b9a7-6abc1a59ca90}\ItemData</td><td>Unknown data format</td></tr> <tr><td>Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Hashes\{79e214f5-70c2-4ab3-b9a7-6abc1a59ca90}\ItemSize</td><td>176128</td></tr> <tr><td>Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Hashes\{79e214f5-70c2-4ab3-b9a7-6abc1a59ca90}\LastModified</td><td>128808422815755197</td></tr> <tr><td>Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Hashes\{79e214f5-70c2-4ab3-b9a7-6abc1a59ca90}\SaferFlags</td><td>0</td></tr> <tr><td>Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Hashes\{7aeabc68-a6aa-4cec-8f68-74d47ca65bc8}\Description</td><td></td></tr> <tr><td>Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Hashes\{7aeabc68-a6aa-4cec-8f68-74d47ca65bc8}\FriendlyName</td><td>pwservice.exe 45 KB 1/19/2001 12:48:56 PM</td></tr> <tr><td>Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Hashes\{7aeabc68-a6aa-4cec-8f68-74d47ca65bc8}\HashAlg</td><td>32771</td></tr> <tr><td>Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Hashes\{7aeabc68-a6aa-4cec-8f68-74d47ca65bc8}\ItemData</td><td>Unknown data format</td></tr> <tr><td>Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Hashes\{7aeabc68-a6aa-4cec-8f68-74d47ca65bc8}\ItemSize</td><td>45056</td></tr> <tr><td>Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Hashes\{7aeabc68-a6aa-4cec-8f68-74d47ca65bc8}\LastModified</td><td>128697802822433338</td></tr> <tr><td>Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Hashes\{7aeabc68-a6aa-4cec-8f68-74d47ca65bc8}\SaferFlags</td><td>0</td></tr> <tr><td>Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Hashes\{822f0b07-a12f-4b56-b38c-6ed530c2088c}\Description</td><td></td></tr> <tr><td>Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Hashes\{822f0b07-a12f-4b56-b38c-6ed530c2088c}\FriendlyName</td><td>PwDump3.exe 61 KB 2/23/2001 8:04:34 AM</td></tr> <tr><td>Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Hashes\{822f0b07-a12f-4b56-b38c-6ed530c2088c}\HashAlg</td><td>32771</td></tr> <tr><td>Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Hashes\{822f0b07-a12f-4b56-b38c-6ed530c2088c}\ItemData</td><td>Unknown data format</td></tr> <tr><td>Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Hashes\{822f0b07-a12f-4b56-b38c-6ed530c2088c}\ItemSize</td><td>61440</td></tr> <tr><td>Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Hashes\{822f0b07-a12f-4b56-b38c-6ed530c2088c}\LastModified</td><td>128697802722594700</td></tr> <tr><td>Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Hashes\{822f0b07-a12f-4b56-b38c-6ed530c2088c}\SaferFlags</td><td>0</td></tr> <tr><td>Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Hashes\{8aec5a35-e089-496f-bceb-9a139ec48264}\Description</td><td></td></tr> <tr><td>Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Hashes\{8aec5a35-e089-496f-bceb-9a139ec48264}\FriendlyName</td><td> (3.0.0.1) Metasploit 3 Windows Installer Metasploit Framework Metasploit LLC</td></tr> <tr><td>Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Hashes\{8aec5a35-e089-496f-bceb-9a139ec48264}\HashAlg</td><td>32771</td></tr> <tr><td>Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Hashes\{8aec5a35-e089-496f-bceb-9a139ec48264}\ItemData</td><td>Unknown data format</td></tr> <tr><td>Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Hashes\{8aec5a35-e089-496f-bceb-9a139ec48264}\ItemSize</td><td>9840774</td></tr> <tr><td>Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Hashes\{8aec5a35-e089-496f-bceb-9a139ec48264}\LastModified</td><td>128697801951227946</td></tr> <tr><td>Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Hashes\{8aec5a35-e089-496f-bceb-9a139ec48264}\SaferFlags</td><td>0</td></tr> <tr><td>Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Hashes\{8bc209eb-fb0a-4925-9952-a46dbeddbd60}\Description</td><td></td></tr> <tr><td>Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Hashes\{8bc209eb-fb0a-4925-9952-a46dbeddbd60}\FriendlyName</td><td>WINDUMP_.EXE 389 KB 12/9/2002 11:20:51 PM</td></tr> <tr><td>Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Hashes\{8bc209eb-fb0a-4925-9952-a46dbeddbd60}\HashAlg</td><td>32771</td></tr> <tr><td>Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Hashes\{8bc209eb-fb0a-4925-9952-a46dbeddbd60}\ItemData</td><td>Unknown data format</td></tr> <tr><td>Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Hashes\{8bc209eb-fb0a-4925-9952-a46dbeddbd60}\ItemSize</td><td>397312</td></tr> <tr><td>Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Hashes\{8bc209eb-fb0a-4925-9952-a46dbeddbd60}\LastModified</td><td>128697804230954968</td></tr> <tr><td>Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Hashes\{8bc209eb-fb0a-4925-9952-a46dbeddbd60}\SaferFlags</td><td>0</td></tr> <tr><td>Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Hashes\{93c83079-9242-4f16-bbf6-62c1eaece1cc}\Description</td><td></td></tr> <tr><td>Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Hashes\{93c83079-9242-4f16-bbf6-62c1eaece1cc}\FriendlyName</td><td>PWD_CHNG.EXE 69 KB 12/13/2006 4:59:00 PM</td></tr> <tr><td>Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Hashes\{93c83079-9242-4f16-bbf6-62c1eaece1cc}\HashAlg</td><td>32771</td></tr> <tr><td>Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Hashes\{93c83079-9242-4f16-bbf6-62c1eaece1cc}\ItemData</td><td>Unknown data format</td></tr> <tr><td>Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Hashes\{93c83079-9242-4f16-bbf6-62c1eaece1cc}\ItemSize</td><td>70590</td></tr> <tr><td>Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Hashes\{93c83079-9242-4f16-bbf6-62c1eaece1cc}\LastModified</td><td>128697799738841226</td></tr> <tr><td>Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Hashes\{93c83079-9242-4f16-bbf6-62c1eaece1cc}\SaferFlags</td><td>0</td></tr> <tr><td>Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Hashes\{99d8eec6-e233-4d55-b5b5-2efe958ed813}\Description</td><td></td></tr> <tr><td>Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Hashes\{99d8eec6-e233-4d55-b5b5-2efe958ed813}\FriendlyName</td><td>kerbcrack.exe 53 KB 4/25/2005 11:54:26 AM</td></tr> <tr><td>Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Hashes\{99d8eec6-e233-4d55-b5b5-2efe958ed813}\HashAlg</td><td>32771</td></tr> <tr><td>Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Hashes\{99d8eec6-e233-4d55-b5b5-2efe958ed813}\ItemData</td><td>Unknown data format</td></tr> <tr><td>Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Hashes\{99d8eec6-e233-4d55-b5b5-2efe958ed813}\ItemSize</td><td>53248</td></tr> <tr><td>Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Hashes\{99d8eec6-e233-4d55-b5b5-2efe958ed813}\LastModified</td><td>128697800987058564</td></tr> <tr><td>Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Hashes\{99d8eec6-e233-4d55-b5b5-2efe958ed813}\SaferFlags</td><td>0</td></tr> <tr><td>Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Hashes\{9dfced32-31ca-49c4-9d3d-89164f7a2aae}\Description</td><td></td></tr> <tr><td>Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Hashes\{9dfced32-31ca-49c4-9d3d-89164f7a2aae}\FriendlyName</td><td> (1.0.0.0) Brutus AET 2 Brutus - AET2 HooBie Inc.</td></tr> <tr><td>Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Hashes\{9dfced32-31ca-49c4-9d3d-89164f7a2aae}\HashAlg</td><td>32771</td></tr> <tr><td>Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Hashes\{9dfced32-31ca-49c4-9d3d-89164f7a2aae}\ItemData</td><td>Unknown data format</td></tr> <tr><td>Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Hashes\{9dfced32-31ca-49c4-9d3d-89164f7a2aae}\ItemSize</td><td>679424</td></tr> <tr><td>Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Hashes\{9dfced32-31ca-49c4-9d3d-89164f7a2aae}\LastModified</td><td>128697799944455698</td></tr> <tr><td>Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Hashes\{9dfced32-31ca-49c4-9d3d-89164f7a2aae}\SaferFlags</td><td>0</td></tr> <tr><td>Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Hashes\{a14f18cc-c63b-4b0d-8903-74976c1b5863}\Description</td><td></td></tr> <tr><td>Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Hashes\{a14f18cc-c63b-4b0d-8903-74976c1b5863}\FriendlyName</td><td>WinPcap.exe 680 KB 5/1/2001 5:51:20 AM</td></tr> <tr><td>Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Hashes\{a14f18cc-c63b-4b0d-8903-74976c1b5863}\HashAlg</td><td>32771</td></tr> <tr><td>Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Hashes\{a14f18cc-c63b-4b0d-8903-74976c1b5863}\ItemData</td><td>Unknown data format</td></tr> <tr><td>Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Hashes\{a14f18cc-c63b-4b0d-8903-74976c1b5863}\ItemSize</td><td>695958</td></tr> <tr><td>Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Hashes\{a14f18cc-c63b-4b0d-8903-74976c1b5863}\LastModified</td><td>128697804341574304</td></tr> <tr><td>Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Hashes\{a14f18cc-c63b-4b0d-8903-74976c1b5863}\SaferFlags</td><td>0</td></tr> <tr><td>Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Hashes\{a8063527-1467-4cba-9ecc-e1f149200bc6}\Description</td><td></td></tr> <tr><td>Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Hashes\{a8063527-1467-4cba-9ecc-e1f149200bc6}\FriendlyName</td><td>blat.exe (2.5.0.0) blat A Win32 command line eMail tool Blat http://www.blat.net/</td></tr> <tr><td>Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Hashes\{a8063527-1467-4cba-9ecc-e1f149200bc6}\HashAlg</td><td>32771</td></tr> <tr><td>Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Hashes\{a8063527-1467-4cba-9ecc-e1f149200bc6}\ItemData</td><td>Unknown data format</td></tr> <tr><td>Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Hashes\{a8063527-1467-4cba-9ecc-e1f149200bc6}\ItemSize</td><td>103936</td></tr> <tr><td>Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Hashes\{a8063527-1467-4cba-9ecc-e1f149200bc6}\LastModified</td><td>128808413448725160</td></tr> <tr><td>Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Hashes\{a8063527-1467-4cba-9ecc-e1f149200bc6}\SaferFlags</td><td>0</td></tr> <tr><td>Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Hashes\{ac1e6c4f-4393-4212-ad6d-7f671e087738}\Description</td><td></td></tr> <tr><td>Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Hashes\{ac1e6c4f-4393-4212-ad6d-7f671e087738}\FriendlyName</td><td>WinPcap_3_1_beta4.exe 474 KB 11/6/2004 3:06:08 AM</td></tr> <tr><td>Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Hashes\{ac1e6c4f-4393-4212-ad6d-7f671e087738}\HashAlg</td><td>32771</td></tr> <tr><td>Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Hashes\{ac1e6c4f-4393-4212-ad6d-7f671e087738}\ItemData</td><td>Unknown data format</td></tr> <tr><td>Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Hashes\{ac1e6c4f-4393-4212-ad6d-7f671e087738}\ItemSize</td><td>484652</td></tr> <tr><td>Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Hashes\{ac1e6c4f-4393-4212-ad6d-7f671e087738}\LastModified</td><td>128697804888577546</td></tr> <tr><td>Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Hashes\{ac1e6c4f-4393-4212-ad6d-7f671e087738}\SaferFlags</td><td>0</td></tr> <tr><td>Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Hashes\{b309950a-6c24-4995-89a8-1f5546da8af4}\Description</td><td></td></tr> <tr><td>Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Hashes\{b309950a-6c24-4995-89a8-1f5546da8af4}\FriendlyName</td><td>WINPCAP_.EXE 327 KB 12/9/2002 11:20:52 PM</td></tr> <tr><td>Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Hashes\{b309950a-6c24-4995-89a8-1f5546da8af4}\HashAlg</td><td>32771</td></tr> <tr><td>Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Hashes\{b309950a-6c24-4995-89a8-1f5546da8af4}\ItemData</td><td>Unknown data format</td></tr> <tr><td>Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Hashes\{b309950a-6c24-4995-89a8-1f5546da8af4}\ItemSize</td><td>334628</td></tr> <tr><td>Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Hashes\{b309950a-6c24-4995-89a8-1f5546da8af4}\LastModified</td><td>128697805078099092</td></tr> <tr><td>Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Hashes\{b309950a-6c24-4995-89a8-1f5546da8af4}\SaferFlags</td><td>0</td></tr> <tr><td>Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Hashes\{b5fdfa33-bf91-4987-80bf-e7312926f747}\Description</td><td></td></tr> <tr><td>Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Hashes\{b5fdfa33-bf91-4987-80bf-e7312926f747}\FriendlyName</td><td>dsniff.exe 241 KB 5/4/2000 1:06:48 AM</td></tr> <tr><td>Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Hashes\{b5fdfa33-bf91-4987-80bf-e7312926f747}\HashAlg</td><td>32771</td></tr> <tr><td>Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Hashes\{b5fdfa33-bf91-4987-80bf-e7312926f747}\ItemData</td><td>Unknown data format</td></tr> <tr><td>Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Hashes\{b5fdfa33-bf91-4987-80bf-e7312926f747}\ItemSize</td><td>245760</td></tr> <tr><td>Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Hashes\{b5fdfa33-bf91-4987-80bf-e7312926f747}\LastModified</td><td>128697800337716812</td></tr> <tr><td>Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Hashes\{b5fdfa33-bf91-4987-80bf-e7312926f747}\SaferFlags</td><td>0</td></tr> <tr><td>Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Hashes\{b67508b3-60d3-4d3f-af4c-97ac8b5b2307}\Description</td><td></td></tr> <tr><td>Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Hashes\{b67508b3-60d3-4d3f-af4c-97ac8b5b2307}\FriendlyName</td><td>windump.exe 277 KB 12/9/2002 11:20:48 PM</td></tr> <tr><td>Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Hashes\{b67508b3-60d3-4d3f-af4c-97ac8b5b2307}\HashAlg</td><td>32771</td></tr> <tr><td>Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Hashes\{b67508b3-60d3-4d3f-af4c-97ac8b5b2307}\ItemData</td><td>Unknown data format</td></tr> <tr><td>Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Hashes\{b67508b3-60d3-4d3f-af4c-97ac8b5b2307}\ItemSize</td><td>282624</td></tr> <tr><td>Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Hashes\{b67508b3-60d3-4d3f-af4c-97ac8b5b2307}\LastModified</td><td>128697804110804870</td></tr> <tr><td>Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Hashes\{b67508b3-60d3-4d3f-af4c-97ac8b5b2307}\SaferFlags</td><td>0</td></tr> <tr><td>Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Hashes\{b85ca0ae-154f-4a7c-b0d9-26489e38822e}\Description</td><td></td></tr> <tr><td>Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Hashes\{b85ca0ae-154f-4a7c-b0d9-26489e38822e}\FriendlyName</td><td>WinPcap_3_1_beta_3.exe 475 KB 6/11/2004 1:54:06 PM</td></tr> <tr><td>Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Hashes\{b85ca0ae-154f-4a7c-b0d9-26489e38822e}\HashAlg</td><td>32771</td></tr> <tr><td>Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Hashes\{b85ca0ae-154f-4a7c-b0d9-26489e38822e}\ItemData</td><td>Unknown data format</td></tr> <tr><td>Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Hashes\{b85ca0ae-154f-4a7c-b0d9-26489e38822e}\ItemSize</td><td>485810</td></tr> <tr><td>Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Hashes\{b85ca0ae-154f-4a7c-b0d9-26489e38822e}\LastModified</td><td>128697804977791728</td></tr> <tr><td>Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Hashes\{b85ca0ae-154f-4a7c-b0d9-26489e38822e}\SaferFlags</td><td>0</td></tr> <tr><td>Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Hashes\{b91f83be-66d1-4dcd-8c6f-7bfb79f8e264}\Description</td><td></td></tr> <tr><td>Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Hashes\{b91f83be-66d1-4dcd-8c6f-7bfb79f8e264}\FriendlyName</td><td>WinPcap_2_3.exe 327 KB 1/22/2003 5:05:16 AM</td></tr> <tr><td>Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Hashes\{b91f83be-66d1-4dcd-8c6f-7bfb79f8e264}\HashAlg</td><td>32771</td></tr> <tr><td>Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Hashes\{b91f83be-66d1-4dcd-8c6f-7bfb79f8e264}\ItemData</td><td>Unknown data format</td></tr> <tr><td>Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Hashes\{b91f83be-66d1-4dcd-8c6f-7bfb79f8e264}\ItemSize</td><td>334628</td></tr> <tr><td>Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Hashes\{b91f83be-66d1-4dcd-8c6f-7bfb79f8e264}\LastModified</td><td>128697804526096106</td></tr> <tr><td>Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Hashes\{b91f83be-66d1-4dcd-8c6f-7bfb79f8e264}\SaferFlags</td><td>0</td></tr> <tr><td>Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Hashes\{ce9242f2-a132-453f-bc7e-146c6d15fc10}\Description</td><td></td></tr> <tr><td>Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Hashes\{ce9242f2-a132-453f-bc7e-146c6d15fc10}\FriendlyName</td><td>avkill.exe (1.0.0.0) avkill AVKILL </td></tr> <tr><td>Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Hashes\{ce9242f2-a132-453f-bc7e-146c6d15fc10}\HashAlg</td><td>32771</td></tr> <tr><td>Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Hashes\{ce9242f2-a132-453f-bc7e-146c6d15fc10}\ItemData</td><td>Unknown data format</td></tr> <tr><td>Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Hashes\{ce9242f2-a132-453f-bc7e-146c6d15fc10}\ItemSize</td><td>28672</td></tr> <tr><td>Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Hashes\{ce9242f2-a132-453f-bc7e-146c6d15fc10}\LastModified</td><td>128808415702140241</td></tr> <tr><td>Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Hashes\{ce9242f2-a132-453f-bc7e-146c6d15fc10}\SaferFlags</td><td>0</td></tr> <tr><td>Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Hashes\{d020d949-b37d-4d18-980b-eb477a2dd938}\Description</td><td></td></tr> <tr><td>Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Hashes\{d020d949-b37d-4d18-980b-eb477a2dd938}\FriendlyName</td><td>netpass.exe (1.0.3.0) NetPass Network Password Recovery Network Password Recovery NirSoft</td></tr> <tr><td>Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Hashes\{d020d949-b37d-4d18-980b-eb477a2dd938}\HashAlg</td><td>32771</td></tr> <tr><td>Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Hashes\{d020d949-b37d-4d18-980b-eb477a2dd938}\ItemData</td><td>Unknown data format</td></tr> <tr><td>Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Hashes\{d020d949-b37d-4d18-980b-eb477a2dd938}\ItemSize</td><td>39936</td></tr> <tr><td>Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Hashes\{d020d949-b37d-4d18-980b-eb477a2dd938}\LastModified</td><td>128808419591861651</td></tr> <tr><td>Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Hashes\{d020d949-b37d-4d18-980b-eb477a2dd938}\SaferFlags</td><td>0</td></tr> <tr><td>Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Hashes\{d47413b5-92a3-4f9d-8343-20cc638aca56}\Description</td><td></td></tr> <tr><td>Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Hashes\{d47413b5-92a3-4f9d-8343-20cc638aca56}\FriendlyName</td><td>mspass.exe (1.0.8.120) MessenPass Instant Messengers Password Recovery MessenPass NirSoft</td></tr> <tr><td>Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Hashes\{d47413b5-92a3-4f9d-8343-20cc638aca56}\HashAlg</td><td>32771</td></tr> <tr><td>Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Hashes\{d47413b5-92a3-4f9d-8343-20cc638aca56}\ItemData</td><td>Unknown data format</td></tr> <tr><td>Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Hashes\{d47413b5-92a3-4f9d-8343-20cc638aca56}\ItemSize</td><td>81408</td></tr> <tr><td>Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Hashes\{d47413b5-92a3-4f9d-8343-20cc638aca56}\LastModified</td><td>128808418525974925</td></tr> <tr><td>Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Hashes\{d47413b5-92a3-4f9d-8343-20cc638aca56}\SaferFlags</td><td>0</td></tr> <tr><td>Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Hashes\{d6755bb1-6471-481e-bc57-0917512d668f}\Description</td><td></td></tr> <tr><td>Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Hashes\{d6755bb1-6471-481e-bc57-0917512d668f}\FriendlyName</td><td>pwservice.exe 44 KB 3/6/2009 2:23:26 PM</td></tr> <tr><td>Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Hashes\{d6755bb1-6471-481e-bc57-0917512d668f}\HashAlg</td><td>32771</td></tr> <tr><td>Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Hashes\{d6755bb1-6471-481e-bc57-0917512d668f}\ItemData</td><td>Unknown data format</td></tr> <tr><td>Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Hashes\{d6755bb1-6471-481e-bc57-0917512d668f}\ItemSize</td><td>44544</td></tr> <tr><td>Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Hashes\{d6755bb1-6471-481e-bc57-0917512d668f}\LastModified</td><td>128808421507678270</td></tr> <tr><td>Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Hashes\{d6755bb1-6471-481e-bc57-0917512d668f}\SaferFlags</td><td>0</td></tr> <tr><td>Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Hashes\{e93d1114-34a4-4e2b-a62c-9b78a0ff0982}\Description</td><td></td></tr> <tr><td>Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Hashes\{e93d1114-34a4-4e2b-a62c-9b78a0ff0982}\FriendlyName</td><td>kerbsniff.exe 45 KB 4/25/2005 11:53:36 AM</td></tr> <tr><td>Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Hashes\{e93d1114-34a4-4e2b-a62c-9b78a0ff0982}\HashAlg</td><td>32771</td></tr> <tr><td>Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Hashes\{e93d1114-34a4-4e2b-a62c-9b78a0ff0982}\ItemData</td><td>Unknown data format</td></tr> <tr><td>Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Hashes\{e93d1114-34a4-4e2b-a62c-9b78a0ff0982}\ItemSize</td><td>45056</td></tr> <tr><td>Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Hashes\{e93d1114-34a4-4e2b-a62c-9b78a0ff0982}\LastModified</td><td>128697801084084846</td></tr> <tr><td>Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Hashes\{e93d1114-34a4-4e2b-a62c-9b78a0ff0982}\SaferFlags</td><td>0</td></tr> <tr><td>Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Hashes\{eb71b2e7-1900-4345-8373-45a2d70771dd}\Description</td><td></td></tr> <tr><td>Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Hashes\{eb71b2e7-1900-4345-8373-45a2d70771dd}\FriendlyName</td><td>WinPcap_3_0.exe 431 KB 2/8/2004 2:27:32 PM</td></tr> <tr><td>Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Hashes\{eb71b2e7-1900-4345-8373-45a2d70771dd}\HashAlg</td><td>32771</td></tr> <tr><td>Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Hashes\{eb71b2e7-1900-4345-8373-45a2d70771dd}\ItemData</td><td>Unknown data format</td></tr> <tr><td>Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Hashes\{eb71b2e7-1900-4345-8373-45a2d70771dd}\ItemSize</td><td>440557</td></tr> <tr><td>Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Hashes\{eb71b2e7-1900-4345-8373-45a2d70771dd}\LastModified</td><td>128697804622809904</td></tr> <tr><td>Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Hashes\{eb71b2e7-1900-4345-8373-45a2d70771dd}\SaferFlags</td><td>0</td></tr> <tr><td>Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Hashes\{fac40d56-ba52-4818-b108-665e22d2c793}\Description</td><td></td></tr> <tr><td>Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Hashes\{fac40d56-ba52-4818-b108-665e22d2c793}\FriendlyName</td><td>ca_setup.exe 5218 KB 8/25/2005 5:04:37 PM</td></tr> <tr><td>Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Hashes\{fac40d56-ba52-4818-b108-665e22d2c793}\HashAlg</td><td>32771</td></tr> <tr><td>Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Hashes\{fac40d56-ba52-4818-b108-665e22d2c793}\ItemData</td><td>Unknown data format</td></tr> <tr><td>Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Hashes\{fac40d56-ba52-4818-b108-665e22d2c793}\ItemSize</td><td>5342578</td></tr> <tr><td>Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Hashes\{fac40d56-ba52-4818-b108-665e22d2c793}\LastModified</td><td>128697800166319338</td></tr> <tr><td>Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Hashes\{fac40d56-ba52-4818-b108-665e22d2c793}\SaferFlags</td><td>0</td></tr> <tr><td>Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Hashes\{fb401362-d333-4f59-98a7-10b04764ccf4}\Description</td><td></td></tr> <tr><td>Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Hashes\{fb401362-d333-4f59-98a7-10b04764ccf4}\FriendlyName</td><td>2.02-WinDump.exe 193 KB 7/11/2001 9:40:02 AM</td></tr> <tr><td>Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Hashes\{fb401362-d333-4f59-98a7-10b04764ccf4}\HashAlg</td><td>32771</td></tr> <tr><td>Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Hashes\{fb401362-d333-4f59-98a7-10b04764ccf4}\ItemData</td><td>Unknown data format</td></tr> <tr><td>Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Hashes\{fb401362-d333-4f59-98a7-10b04764ccf4}\ItemSize</td><td>196608</td></tr> <tr><td>Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Hashes\{fb401362-d333-4f59-98a7-10b04764ccf4}\LastModified</td><td>128697803803164372</td></tr> <tr><td>Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Hashes\{fb401362-d333-4f59-98a7-10b04764ccf4}\SaferFlags</td><td>0</td></tr> <tr><td>Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Hashes\{fffe6a44-ed1b-423d-8685-ee39f238635a}\Description</td><td>W32/CONFICKER.WORM.GEN.B</td></tr> <tr><td>Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Hashes\{fffe6a44-ed1b-423d-8685-ee39f238635a}\FriendlyName</td><td>xeakps.dll 157 KB 4/16/2007 10:52:54 AM</td></tr> <tr><td>Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Hashes\{fffe6a44-ed1b-423d-8685-ee39f238635a}\HashAlg</td><td>32771</td></tr> <tr><td>Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Hashes\{fffe6a44-ed1b-423d-8685-ee39f238635a}\ItemData</td><td>Unknown data format</td></tr> <tr><td>Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Hashes\{fffe6a44-ed1b-423d-8685-ee39f238635a}\ItemSize</td><td>159975</td></tr> <tr><td>Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Hashes\{fffe6a44-ed1b-423d-8685-ee39f238635a}\LastModified</td><td>128759970387487226</td></tr> <tr><td>Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Hashes\{fffe6a44-ed1b-423d-8685-ee39f238635a}\SaferFlags</td><td>0</td></tr> <tr><td>Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Paths\{17ae1512-7788-46ec-a677-36d2c85e24d9}\Description</td><td>tool which puts a network card into promiscuous sniffing mode</td></tr> <tr><td>Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Paths\{17ae1512-7788-46ec-a677-36d2c85e24d9}\ItemData</td><td>rpcapd.exe</td></tr> <tr><td>Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Paths\{17ae1512-7788-46ec-a677-36d2c85e24d9}\LastModified</td><td>128696875251430542</td></tr> <tr><td>Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Paths\{17ae1512-7788-46ec-a677-36d2c85e24d9}\SaferFlags</td><td>0</td></tr> <tr><td>Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Paths\{2a34252d-41cb-4f2a-8008-f1c304002a84}\Description</td><td></td></tr> <tr><td>Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Paths\{2a34252d-41cb-4f2a-8008-f1c304002a84}\ItemData</td><td>netpass.exe</td></tr> <tr><td>Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Paths\{2a34252d-41cb-4f2a-8008-f1c304002a84}\LastModified</td><td>128808419825932000</td></tr> <tr><td>Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Paths\{2a34252d-41cb-4f2a-8008-f1c304002a84}\SaferFlags</td><td>0</td></tr> <tr><td>Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Paths\{2f2fc91d-f471-4fd0-a4c4-ff3e274b9358}\Description</td><td>freely available tool for creating custom packets</td></tr> <tr><td>Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Paths\{2f2fc91d-f471-4fd0-a4c4-ff3e274b9358}\ItemData</td><td>nemesis.exe</td></tr> <tr><td>Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Paths\{2f2fc91d-f471-4fd0-a4c4-ff3e274b9358}\LastModified</td><td>128696877665681926</td></tr> <tr><td>Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Paths\{2f2fc91d-f471-4fd0-a4c4-ff3e274b9358}\SaferFlags</td><td>0</td></tr> <tr><td>Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Paths\{31929d12-f3e0-42f5-a571-392d7c6c78b4}\Description</td><td>password cracking tool ****had to use wildcard because the underscore was preventing this from working</td></tr> <tr><td>Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Paths\{31929d12-f3e0-42f5-a571-392d7c6c78b4}\ItemData</td><td>pwd_chnge*</td></tr> <tr><td>Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Paths\{31929d12-f3e0-42f5-a571-392d7c6c78b4}\LastModified</td><td>128696867299285568</td></tr> <tr><td>Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Paths\{31929d12-f3e0-42f5-a571-392d7c6c78b4}\SaferFlags</td><td>0</td></tr> <tr><td>Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Paths\{3650831b-b91f-440c-9485-9d9021f82702}\Description</td><td>hack tool that is used to gather Windows password hashes from computers</td></tr> <tr><td>Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Paths\{3650831b-b91f-440c-9485-9d9021f82702}\ItemData</td><td>lsadump*</td></tr> <tr><td>Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Paths\{3650831b-b91f-440c-9485-9d9021f82702}\LastModified</td><td>128696870047932091</td></tr> <tr><td>Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Paths\{3650831b-b91f-440c-9485-9d9021f82702}\SaferFlags</td><td>0</td></tr> <tr><td>Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Paths\{3725707a-473a-48d5-8c2e-cb368bcee383}\Description</td><td>cross-platform controller GUI for Tor</td></tr> <tr><td>Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Paths\{3725707a-473a-48d5-8c2e-cb368bcee383}\ItemData</td><td>vidalia.exe</td></tr> <tr><td>Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Paths\{3725707a-473a-48d5-8c2e-cb368bcee383}\LastModified</td><td>128696879447153210</td></tr> <tr><td>Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Paths\{3725707a-473a-48d5-8c2e-cb368bcee383}\SaferFlags</td><td>0</td></tr> <tr><td>Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Paths\{37fc2e66-b399-4974-91f8-617459d1fd3d}\Description</td><td>popular Windows based password cracking suite</td></tr> <tr><td>Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Paths\{37fc2e66-b399-4974-91f8-617459d1fd3d}\ItemData</td><td>l0phtcrack.exe</td></tr> <tr><td>Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Paths\{37fc2e66-b399-4974-91f8-617459d1fd3d}\LastModified</td><td>128696867772107146</td></tr> <tr><td>Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Paths\{37fc2e66-b399-4974-91f8-617459d1fd3d}\SaferFlags</td><td>0</td></tr> <tr><td>Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Paths\{4805e166-bc66-479b-ae73-911e6803b357}\Description</td><td>password cracking service</td></tr> <tr><td>Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Paths\{4805e166-bc66-479b-ae73-911e6803b357}\ItemData</td><td>pwservice.exe</td></tr> <tr><td>Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Paths\{4805e166-bc66-479b-ae73-911e6803b357}\LastModified</td><td>128697803176633952</td></tr> <tr><td>Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Paths\{4805e166-bc66-479b-ae73-911e6803b357}\SaferFlags</td><td>0</td></tr> <tr><td>Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Paths\{4875caf7-1081-4ccd-abc5-84684c322075}\Description</td><td>copies the contents of all usb thumb drives that are plugged into a computer</td></tr> <tr><td>Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Paths\{4875caf7-1081-4ccd-abc5-84684c322075}\ItemData</td><td>usbdumper.exe</td></tr> <tr><td>Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Paths\{4875caf7-1081-4ccd-abc5-84684c322075}\LastModified</td><td>128808430622212140</td></tr> <tr><td>Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Paths\{4875caf7-1081-4ccd-abc5-84684c322075}\SaferFlags</td><td>0</td></tr> <tr><td>Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Paths\{57c057b5-1015-446e-b7e3-2d351155f7fb}\Description</td><td>graphical tool which is used to hack vulnerable computers</td></tr> <tr><td>Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Paths\{57c057b5-1015-446e-b7e3-2d351155f7fb}\ItemData</td><td>*metasploit*</td></tr> <tr><td>Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Paths\{57c057b5-1015-446e-b7e3-2d351155f7fb}\LastModified</td><td>128696878174249636</td></tr> <tr><td>Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Paths\{57c057b5-1015-446e-b7e3-2d351155f7fb}\SaferFlags</td><td>0</td></tr> <tr><td>Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Paths\{590226ca-a44a-4186-959f-6371209928a9}\Description</td><td>tool which puts a network card into promiscuous sniffing mode</td></tr> <tr><td>Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Paths\{590226ca-a44a-4186-959f-6371209928a9}\ItemData</td><td>npf_mgm.exe</td></tr> <tr><td>Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Paths\{590226ca-a44a-4186-959f-6371209928a9}\LastModified</td><td>128696875004568182</td></tr> <tr><td>Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Paths\{590226ca-a44a-4186-959f-6371209928a9}\SaferFlags</td><td>0</td></tr> <tr><td>Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Paths\{5ca1fd93-3b99-405e-925f-6f5e40b8e125}\Description</td><td>One piece of the cain and abel program</td></tr> <tr><td>Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Paths\{5ca1fd93-3b99-405e-925f-6f5e40b8e125}\ItemData</td><td>abel*</td></tr> <tr><td>Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Paths\{5ca1fd93-3b99-405e-925f-6f5e40b8e125}\LastModified</td><td>128696871279290176</td></tr> <tr><td>Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Paths\{5ca1fd93-3b99-405e-925f-6f5e40b8e125}\SaferFlags</td><td>0</td></tr> <tr><td>Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Paths\{616dc0ba-dad2-4e18-8165-017cb3fbd41f}\Description</td><td>firefox password stealer</td></tr> <tr><td>Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Paths\{616dc0ba-dad2-4e18-8165-017cb3fbd41f}\ItemData</td><td>firepassword.exe</td></tr> <tr><td>Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Paths\{616dc0ba-dad2-4e18-8165-017cb3fbd41f}\LastModified</td><td>128808416884671764</td></tr> <tr><td>Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Paths\{616dc0ba-dad2-4e18-8165-017cb3fbd41f}\SaferFlags</td><td>0</td></tr> <tr><td>Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Paths\{68af23f0-bc1e-4a08-8c0c-b4733b15914b}\Description</td><td></td></tr> <tr><td>Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Paths\{68af23f0-bc1e-4a08-8c0c-b4733b15914b}\ItemData</td><td>nircmd.exe</td></tr> <tr><td>Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Paths\{68af23f0-bc1e-4a08-8c0c-b4733b15914b}\LastModified</td><td>128808420850126409</td></tr> <tr><td>Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Paths\{68af23f0-bc1e-4a08-8c0c-b4733b15914b}\SaferFlags</td><td>0</td></tr> <tr><td>Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Paths\{6ac13341-5ecd-40d6-b5a5-cb8612aa3553}\Description</td><td>password cracking program</td></tr> <tr><td>Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Paths\{6ac13341-5ecd-40d6-b5a5-cb8612aa3553}\ItemData</td><td>john-386.exe</td></tr> <tr><td>Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Paths\{6ac13341-5ecd-40d6-b5a5-cb8612aa3553}\LastModified</td><td>128696872719841416</td></tr> <tr><td>Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Paths\{6ac13341-5ecd-40d6-b5a5-cb8612aa3553}\SaferFlags</td><td>0</td></tr> <tr><td>Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Paths\{6c9f6c0c-2e0e-4e63-aa76-b6a68a96493e}\Description</td><td>tool which puts a network card into promiscuous sniffing mode</td></tr> <tr><td>Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Paths\{6c9f6c0c-2e0e-4e63-aa76-b6a68a96493e}\ItemData</td><td>wpcap*</td></tr> <tr><td>Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Paths\{6c9f6c0c-2e0e-4e63-aa76-b6a68a96493e}\LastModified</td><td>128696874795516386</td></tr> <tr><td>Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Paths\{6c9f6c0c-2e0e-4e63-aa76-b6a68a96493e}\SaferFlags</td><td>0</td></tr> <tr><td>Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Paths\{815375b3-d2ed-4201-999b-4faef04b734e}\Description</td><td>windows based brute force password cracker</td></tr> <tr><td>Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Paths\{815375b3-d2ed-4201-999b-4faef04b734e}\ItemData</td><td>brutus*</td></tr> <tr><td>Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Paths\{815375b3-d2ed-4201-999b-4faef04b734e}\LastModified</td><td>128696870893997404</td></tr> <tr><td>Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Paths\{815375b3-d2ed-4201-999b-4faef04b734e}\SaferFlags</td><td>0</td></tr> <tr><td>Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Paths\{83b59b48-f219-44da-9c42-6aeb13a882fe}\Description</td><td>e-mail engine</td></tr> <tr><td>Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Paths\{83b59b48-f219-44da-9c42-6aeb13a882fe}\ItemData</td><td>blat.exe</td></tr> <tr><td>Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Paths\{83b59b48-f219-44da-9c42-6aeb13a882fe}\LastModified</td><td>128808415252737663</td></tr> <tr><td>Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Paths\{83b59b48-f219-44da-9c42-6aeb13a882fe}\SaferFlags</td><td>0</td></tr> <tr><td>Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Paths\{88492e98-5f44-4016-a8a5-68137e7f8433}\Description</td><td>steals wireless passwords</td></tr> <tr><td>Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Paths\{88492e98-5f44-4016-a8a5-68137e7f8433}\ItemData</td><td>wirelesskeyview.exe</td></tr> <tr><td>Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Paths\{88492e98-5f44-4016-a8a5-68137e7f8433}\LastModified</td><td>128808425274352692</td></tr> <tr><td>Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Paths\{88492e98-5f44-4016-a8a5-68137e7f8433}\SaferFlags</td><td>0</td></tr> <tr><td>Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Paths\{962fd7c9-6d44-4d6a-ad8e-93a6a2199b1d}\Description</td><td>tool which cracks passwords dumped with pwdump</td></tr> <tr><td>Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Paths\{962fd7c9-6d44-4d6a-ad8e-93a6a2199b1d}\ItemData</td><td>ntcrack.exe</td></tr> <tr><td>Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Paths\{962fd7c9-6d44-4d6a-ad8e-93a6a2199b1d}\LastModified</td><td>128696854646230134</td></tr> <tr><td>Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Paths\{962fd7c9-6d44-4d6a-ad8e-93a6a2199b1d}\SaferFlags</td><td>0</td></tr> <tr><td>Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Paths\{9cf5e30e-4232-44bd-8611-2ae1546b1d08}\Description</td><td>tool which puts a network card into promiscuous sniffing mode</td></tr> <tr><td>Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Paths\{9cf5e30e-4232-44bd-8611-2ae1546b1d08}\ItemData</td><td>*winpcap*</td></tr> <tr><td>Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Paths\{9cf5e30e-4232-44bd-8611-2ae1546b1d08}\LastModified</td><td>128696878494545736</td></tr> <tr><td>Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Paths\{9cf5e30e-4232-44bd-8611-2ae1546b1d08}\SaferFlags</td><td>0</td></tr> <tr><td>Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Paths\{a7a93223-0dc0-4160-8dab-e2adc84833e5}\Description</td><td></td></tr> <tr><td>Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Paths\{a7a93223-0dc0-4160-8dab-e2adc84833e5}\ItemData</td><td>mspass.exe</td></tr> <tr><td>Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Paths\{a7a93223-0dc0-4160-8dab-e2adc84833e5}\LastModified</td><td>128808418798302269</td></tr> <tr><td>Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Paths\{a7a93223-0dc0-4160-8dab-e2adc84833e5}\SaferFlags</td><td>0</td></tr> <tr><td>Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Paths\{abcfa143-be45-4bbf-b69e-14e5ae04a5ae}\Description</td><td>web proxy program</td></tr> <tr><td>Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Paths\{abcfa143-be45-4bbf-b69e-14e5ae04a5ae}\ItemData</td><td>privoxy.exe</td></tr> <tr><td>Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Paths\{abcfa143-be45-4bbf-b69e-14e5ae04a5ae}\LastModified</td><td>128696879952127354</td></tr> <tr><td>Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Paths\{abcfa143-be45-4bbf-b69e-14e5ae04a5ae}\SaferFlags</td><td>0</td></tr> <tr><td>Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Paths\{b175ff7f-64e1-4138-a2e1-7037ef0b77dc}\Description</td><td>tool which sniffs Kerberos passwords from network traffic</td></tr> <tr><td>Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Paths\{b175ff7f-64e1-4138-a2e1-7037ef0b77dc}\ItemData</td><td>kerbsniff.exe</td></tr> <tr><td>Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Paths\{b175ff7f-64e1-4138-a2e1-7037ef0b77dc}\LastModified</td><td>128696865473469263</td></tr> <tr><td>Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Paths\{b175ff7f-64e1-4138-a2e1-7037ef0b77dc}\SaferFlags</td><td>0</td></tr> <tr><td>Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Paths\{b35ea5ce-a33e-4a82-99db-333877081621}\Description</td><td>this is a generic term which catches popular key loggers</td></tr> <tr><td>Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Paths\{b35ea5ce-a33e-4a82-99db-333877081621}\ItemData</td><td>keylog*</td></tr> <tr><td>Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Paths\{b35ea5ce-a33e-4a82-99db-333877081621}\LastModified</td><td>128696876361373710</td></tr> <tr><td>Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Paths\{b35ea5ce-a33e-4a82-99db-333877081621}\SaferFlags</td><td>0</td></tr> <tr><td>Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Paths\{b4b1d127-1157-420f-9368-90aede6c5ee9}\Description</td><td>tool which dumps password hashes for cracking</td></tr> <tr><td>Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Paths\{b4b1d127-1157-420f-9368-90aede6c5ee9}\ItemData</td><td>pwdump.exe</td></tr> <tr><td>Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Paths\{b4b1d127-1157-420f-9368-90aede6c5ee9}\LastModified</td><td>128696853457301057</td></tr> <tr><td>Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Paths\{b4b1d127-1157-420f-9368-90aede6c5ee9}\SaferFlags</td><td>0</td></tr> <tr><td>Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Paths\{b966b366-a987-49c6-9715-6d01c748f3e5}\Description</td><td>tool which sniffs passwords from network traffic</td></tr> <tr><td>Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Paths\{b966b366-a987-49c6-9715-6d01c748f3e5}\ItemData</td><td>dsniff.exe</td></tr> <tr><td>Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Paths\{b966b366-a987-49c6-9715-6d01c748f3e5}\LastModified</td><td>128696855975943164</td></tr> <tr><td>Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Paths\{b966b366-a987-49c6-9715-6d01c748f3e5}\SaferFlags</td><td>0</td></tr> <tr><td>Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Paths\{bbfc1fa5-f8d9-4ffc-b2c1-88a286922fef}\Description</td><td>This is one piece of the cain and abel program</td></tr> <tr><td>Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Paths\{bbfc1fa5-f8d9-4ffc-b2c1-88a286922fef}\ItemData</td><td>cain.exe</td></tr> <tr><td>Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Paths\{bbfc1fa5-f8d9-4ffc-b2c1-88a286922fef}\LastModified</td><td>128696848942370622</td></tr> <tr><td>Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Paths\{bbfc1fa5-f8d9-4ffc-b2c1-88a286922fef}\SaferFlags</td><td>0</td></tr> <tr><td>Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Paths\{cb7d5b8e-7ed4-4ec0-ac8f-599a83ea7ff3}\Description</td><td>rainbow table password cracking tool</td></tr> <tr><td>Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Paths\{cb7d5b8e-7ed4-4ec0-ac8f-599a83ea7ff3}\ItemData</td><td>rcrack.exe</td></tr> <tr><td>Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Paths\{cb7d5b8e-7ed4-4ec0-ac8f-599a83ea7ff3}\LastModified</td><td>128808423077308122</td></tr> <tr><td>Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Paths\{cb7d5b8e-7ed4-4ec0-ac8f-599a83ea7ff3}\SaferFlags</td><td>0</td></tr> <tr><td>Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Paths\{dc5a8556-46e1-47f1-aac5-6fb862274c4d}\Description</td><td>tool which dumps network traffic to a file</td></tr> <tr><td>Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Paths\{dc5a8556-46e1-47f1-aac5-6fb862274c4d}\ItemData</td><td>windump.exe</td></tr> <tr><td>Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Paths\{dc5a8556-46e1-47f1-aac5-6fb862274c4d}\LastModified</td><td>128696875542978114</td></tr> <tr><td>Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Paths\{dc5a8556-46e1-47f1-aac5-6fb862274c4d}\SaferFlags</td><td>0</td></tr> <tr><td>Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Paths\{ddcaaf9e-24ca-4198-9851-2e0beba0772f}\Description</td><td>Password Cracker</td></tr> <tr><td>Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Paths\{ddcaaf9e-24ca-4198-9851-2e0beba0772f}\ItemData</td><td>*ophcrack*</td></tr> <tr><td>Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Paths\{ddcaaf9e-24ca-4198-9851-2e0beba0772f}\LastModified</td><td>128802214741868775</td></tr> <tr><td>Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Paths\{ddcaaf9e-24ca-4198-9851-2e0beba0772f}\SaferFlags</td><td>0</td></tr> <tr><td>Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Paths\{e166a9a3-1445-41f3-b158-83f35ee7b7e7}\Description</td><td></td></tr> <tr><td>Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Paths\{e166a9a3-1445-41f3-b158-83f35ee7b7e7}\ItemData</td><td>iepv.exe</td></tr> <tr><td>Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Paths\{e166a9a3-1445-41f3-b158-83f35ee7b7e7}\LastModified</td><td>128808418132786707</td></tr> <tr><td>Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Paths\{e166a9a3-1445-41f3-b158-83f35ee7b7e7}\SaferFlags</td><td>0</td></tr> <tr><td>Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Paths\{e3fe6dd3-0dba-43a3-8ac9-96f6ce96eb64}\Description</td><td>anonymize web browsing and publishing, instant messaging, IRC, SSH, and other applications that use the TCP protocol</td></tr> <tr><td>Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Paths\{e3fe6dd3-0dba-43a3-8ac9-96f6ce96eb64}\ItemData</td><td>tor.exe</td></tr> <tr><td>Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Paths\{e3fe6dd3-0dba-43a3-8ac9-96f6ce96eb64}\LastModified</td><td>128696878742345548</td></tr> <tr><td>Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Paths\{e3fe6dd3-0dba-43a3-8ac9-96f6ce96eb64}\SaferFlags</td><td>0</td></tr> <tr><td>Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Paths\{ef0cb1d5-ae17-4bfc-95d9-f97c7b15f3de}\Description</td><td>tool which cracks Kerberos passwords</td></tr> <tr><td>Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Paths\{ef0cb1d5-ae17-4bfc-95d9-f97c7b15f3de}\ItemData</td><td>kerbcrack.exe</td></tr> <tr><td>Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Paths\{ef0cb1d5-ae17-4bfc-95d9-f97c7b15f3de}\LastModified</td><td>128696868789314176</td></tr> <tr><td>Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Paths\{ef0cb1d5-ae17-4bfc-95d9-f97c7b15f3de}\SaferFlags</td><td>0</td></tr> <tr><td>Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Paths\{f039906e-90b2-46da-9692-f27f60f741ed}\Description</td><td>packet capture tool</td></tr> <tr><td>Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Paths\{f039906e-90b2-46da-9692-f27f60f741ed}\ItemData</td><td>wireshark.exe</td></tr> <tr><td>Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Paths\{f039906e-90b2-46da-9692-f27f60f741ed}\LastModified</td><td>128696876870566388</td></tr> <tr><td>Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Paths\{f039906e-90b2-46da-9692-f27f60f741ed}\SaferFlags</td><td>0</td></tr> <tr><td>Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Paths\{f084205d-897a-4a1f-b03b-1d7c7b4d302a}\Description</td><td>password cracking program</td></tr> <tr><td>Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Paths\{f084205d-897a-4a1f-b03b-1d7c7b4d302a}\ItemData</td><td>lcp.exe</td></tr> <tr><td>Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Paths\{f084205d-897a-4a1f-b03b-1d7c7b4d302a}\LastModified</td><td>128696871915038874</td></tr> <tr><td>Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Paths\{f084205d-897a-4a1f-b03b-1d7c7b4d302a}\SaferFlags</td><td>0</td></tr> <tr><td>Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Paths\{f0c141d0-0668-4d51-a17b-5a9bbcbd544f}\Description</td><td>Password Cracker</td></tr> <tr><td>Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Paths\{f0c141d0-0668-4d51-a17b-5a9bbcbd544f}\ItemData</td><td>*ophtcrack*</td></tr> <tr><td>Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Paths\{f0c141d0-0668-4d51-a17b-5a9bbcbd544f}\LastModified</td><td>128802215011235155</td></tr> <tr><td>Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Paths\{f0c141d0-0668-4d51-a17b-5a9bbcbd544f}\SaferFlags</td><td>0</td></tr> <tr><td>Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Paths\{f9a66e23-225c-4504-bb52-86547563f1f4}\Description</td><td>popular  Swiss Army Knife tool for back-dooring machines</td></tr> <tr><td>Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Paths\{f9a66e23-225c-4504-bb52-86547563f1f4}\ItemData</td><td>nc.exe</td></tr> <tr><td>Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Paths\{f9a66e23-225c-4504-bb52-86547563f1f4}\LastModified</td><td>128696873334966170</td></tr> <tr><td>Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Paths\{f9a66e23-225c-4504-bb52-86547563f1f4}\SaferFlags</td><td>0</td></tr> <tr><td>Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\262144\Paths\{191cd7fa-f240-4a17-8986-94d480a6c8ca}\Description</td><td></td></tr> <tr><td>Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\262144\Paths\{191cd7fa-f240-4a17-8986-94d480a6c8ca}\ItemData</td><td>%HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot%</td></tr> <tr><td>Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\262144\Paths\{191cd7fa-f240-4a17-8986-94d480a6c8ca}\LastModified</td><td>128630263411769296</td></tr> <tr><td>Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\262144\Paths\{191cd7fa-f240-4a17-8986-94d480a6c8ca}\SaferFlags</td><td>0</td></tr> <tr><td>Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\262144\Paths\{7272edfb-af9f-4ddf-b65b-e4282f2deefc}\Description</td><td></td></tr> <tr><td>Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\262144\Paths\{7272edfb-af9f-4ddf-b65b-e4282f2deefc}\ItemData</td><td>%HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot%*.exe</td></tr> <tr><td>Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\262144\Paths\{7272edfb-af9f-4ddf-b65b-e4282f2deefc}\LastModified</td><td>128630263411769296</td></tr> <tr><td>Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\262144\Paths\{7272edfb-af9f-4ddf-b65b-e4282f2deefc}\SaferFlags</td><td>0</td></tr> <tr><td>Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\262144\Paths\{8868b733-4b3a-48f8-9136-aa6d05d4fc83}\Description</td><td></td></tr> <tr><td>Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\262144\Paths\{8868b733-4b3a-48f8-9136-aa6d05d4fc83}\ItemData</td><td>%HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot%System32\*.exe</td></tr> <tr><td>Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\262144\Paths\{8868b733-4b3a-48f8-9136-aa6d05d4fc83}\LastModified</td><td>128630263411769296</td></tr> <tr><td>Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\262144\Paths\{8868b733-4b3a-48f8-9136-aa6d05d4fc83}\SaferFlags</td><td>0</td></tr> <tr><td>Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\262144\Paths\{d2c34ab2-529a-46b2-b293-fc853fce72ea}\Description</td><td></td></tr> <tr><td>Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\262144\Paths\{d2c34ab2-529a-46b2-b293-fc853fce72ea}\ItemData</td><td>%HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ProgramFilesDir%</td></tr> <tr><td>Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\262144\Paths\{d2c34ab2-529a-46b2-b293-fc853fce72ea}\LastModified</td><td>128630263411769296</td></tr> <tr><td>Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\262144\Paths\{d2c34ab2-529a-46b2-b293-fc853fce72ea}\SaferFlags</td><td>0</td></tr> <tr><td>Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\DefaultLevel</td><td>262144</td></tr> <tr><td>Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\ExecutableTypes</td><td>ADE<br/>ADP<br/>BAS<br/>BAT<br/>CHM<br/>CMD<br/>COM<br/>CPL<br/>CRT<br/>EXE<br/>HLP<br/>HTA<br/>INF<br/>INS<br/>ISP<br/>LNK<br/>MDB<br/>MDE<br/>MSC<br/>MSI<br/>MSP<br/>MST<br/>OCX<br/>PCD<br/>PIF<br/>REG<br/>SCR<br/>SHS<br/>URL<br/>VB<br/>WSC</td></tr> <tr><td>Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\PolicyScope</td><td>0</td></tr> <tr><td>Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\TransparentEnabled</td><td>1</td></tr> </table> </div></div></div></div></div> <div class="filler"></div> <div class="he0_expanded"><span class="sectionTitle" tabindex="0">User Configuration (Disabled)</span><a class="expando" href="#"></a></div> <div class="container"><div class="he1h_expanded"><span class="sectionTitle" tabindex="0">Policies</span><a class="expando" href="#"></a></div> <div class="container"><div class="he1_expanded"><span class="sectionTitle" tabindex="0">Windows Settings</span><a class="expando" href="#"></a></div> <div class="container"><div class="he2"><span class="sectionTitle" tabindex="0">Security Settings</span><a class="expando" href="#"></a></div> <div class="container"><div class="he4i"><b>An error has occurred while collecting data for Software Restriction Policies.</b><br/><br/> <table class="subtable" cellpadding="0" cellspacing="0"> <tr><th>This error impacts the following settings:</th></tr> <tr><td>Software Restriction Policies<br/> Software Restriction Policies/Security Levels<br/> Software Restriction Policies/Additional Rules </td></tr> <tr><td class="subtableInnerHead">The following errors apply to all of the above settings:</td></tr> <tr><td>An unknown error occurred while data was gathered for this extension. Details: Unable to cast object of type 'System.String[]' to type 'Microsoft.GroupPolicy.Reporting.Extensions.Registry.UnknownType'.</td></tr> </table></div></div></div><div class="filler"></div> <div class="he1"><span class="sectionTitle" tabindex="0">Administrative Templates</span><a class="expando" href="#"></a></div> <div class="container"><div class="he4i">Policy definitions (ADMX files) retrieved from the central store.</div><div class="he3"><span class="sectionTitle" tabindex="0">Extra Registry Settings</span><a class="expando" href="#"></a></div> <div class="container"><div class="he4i">Display names for some settings cannot be found. You might be able to resolve this issue by updating the .ADM files used by Group Policy Management.<br/><br/><table class="info" cellpadding="0" cellspacing="0"> <tr><th scope="col">Setting</th><th scope="col">State</th></tr> <tr><td>Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Hashes\{01d78d5e-66ce-4852-ab21-cb35ab68b563}\Description</td><td></td></tr> <tr><td>Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Hashes\{01d78d5e-66ce-4852-ab21-cb35ab68b563}\FriendlyName</td><td>pwservice.exe 45 KB 1/19/2001 12:48:56 PM</td></tr> <tr><td>Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Hashes\{01d78d5e-66ce-4852-ab21-cb35ab68b563}\HashAlg</td><td>32771</td></tr> <tr><td>Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Hashes\{01d78d5e-66ce-4852-ab21-cb35ab68b563}\ItemData</td><td>Unknown data format</td></tr> <tr><td>Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Hashes\{01d78d5e-66ce-4852-ab21-cb35ab68b563}\ItemSize</td><td>45056</td></tr> <tr><td>Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Hashes\{01d78d5e-66ce-4852-ab21-cb35ab68b563}\LastModified</td><td>128697809549222508</td></tr> <tr><td>Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Hashes\{01d78d5e-66ce-4852-ab21-cb35ab68b563}\SaferFlags</td><td>0</td></tr> <tr><td>Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Hashes\{09862ef4-97ff-4535-9f4a-ca364446572e}\Description</td><td>copies the contents of all usb thumb drives that are plugged into a computer</td></tr> <tr><td>Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Hashes\{09862ef4-97ff-4535-9f4a-ca364446572e}\FriendlyName</td><td>USBDumper.exe 45 KB 2/19/2006 6:58:36 PM</td></tr> <tr><td>Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Hashes\{09862ef4-97ff-4535-9f4a-ca364446572e}\HashAlg</td><td>32771</td></tr> <tr><td>Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Hashes\{09862ef4-97ff-4535-9f4a-ca364446572e}\ItemData</td><td>Unknown data format</td></tr> <tr><td>Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Hashes\{09862ef4-97ff-4535-9f4a-ca364446572e}\ItemSize</td><td>45056</td></tr> <tr><td>Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Hashes\{09862ef4-97ff-4535-9f4a-ca364446572e}\LastModified</td><td>128808430905938507</td></tr> <tr><td>Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Hashes\{09862ef4-97ff-4535-9f4a-ca364446572e}\SaferFlags</td><td>0</td></tr> <tr><td>Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Hashes\{16325656-7e25-4039-8672-f7645b07200d}\Description</td><td></td></tr> <tr><td>Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Hashes\{16325656-7e25-4039-8672-f7645b07200d}\FriendlyName</td><td> (3.0.0.1) Metasploit 3 Windows Installer Metasploit Framework Metasploit LLC</td></tr> <tr><td>Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Hashes\{16325656-7e25-4039-8672-f7645b07200d}\HashAlg</td><td>32771</td></tr> <tr><td>Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Hashes\{16325656-7e25-4039-8672-f7645b07200d}\ItemData</td><td>Unknown data format</td></tr> <tr><td>Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Hashes\{16325656-7e25-4039-8672-f7645b07200d}\ItemSize</td><td>9840774</td></tr> <tr><td>Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Hashes\{16325656-7e25-4039-8672-f7645b07200d}\LastModified</td><td>128697808823283328</td></tr> <tr><td>Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Hashes\{16325656-7e25-4039-8672-f7645b07200d}\SaferFlags</td><td>0</td></tr> <tr><td>Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Hashes\{299adfbd-0351-411c-9a61-21c78d943b0c}\Description</td><td></td></tr> <tr><td>Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Hashes\{299adfbd-0351-411c-9a61-21c78d943b0c}\FriendlyName</td><td>kerbsniff.exe 45 KB 4/25/2005 11:53:36 AM</td></tr> <tr><td>Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Hashes\{299adfbd-0351-411c-9a61-21c78d943b0c}\HashAlg</td><td>32771</td></tr> <tr><td>Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Hashes\{299adfbd-0351-411c-9a61-21c78d943b0c}\ItemData</td><td>Unknown data format</td></tr> <tr><td>Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Hashes\{299adfbd-0351-411c-9a61-21c78d943b0c}\ItemSize</td><td>45056</td></tr> <tr><td>Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Hashes\{299adfbd-0351-411c-9a61-21c78d943b0c}\LastModified</td><td>128697808254878420</td></tr> <tr><td>Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Hashes\{299adfbd-0351-411c-9a61-21c78d943b0c}\SaferFlags</td><td>0</td></tr> <tr><td>Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Hashes\{2c0d60dd-ee18-4da5-8aa2-87621cd8a3be}\Description</td><td></td></tr> <tr><td>Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Hashes\{2c0d60dd-ee18-4da5-8aa2-87621cd8a3be}\FriendlyName</td><td>l0phtcrackv4.00winntxpkeygencore[1].zip 162 KB 5/2/2005 1:13:04 PM</td></tr> <tr><td>Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Hashes\{2c0d60dd-ee18-4da5-8aa2-87621cd8a3be}\HashAlg</td><td>32771</td></tr> <tr><td>Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Hashes\{2c0d60dd-ee18-4da5-8aa2-87621cd8a3be}\ItemData</td><td>Unknown data format</td></tr> <tr><td>Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Hashes\{2c0d60dd-ee18-4da5-8aa2-87621cd8a3be}\ItemSize</td><td>165255</td></tr> <tr><td>Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Hashes\{2c0d60dd-ee18-4da5-8aa2-87621cd8a3be}\LastModified</td><td>128697808400222540</td></tr> <tr><td>Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Hashes\{2c0d60dd-ee18-4da5-8aa2-87621cd8a3be}\SaferFlags</td><td>0</td></tr> <tr><td>Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Hashes\{309da424-8f53-4ff7-bf43-7f60dad20169}\Description</td><td></td></tr> <tr><td>Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Hashes\{309da424-8f53-4ff7-bf43-7f60dad20169}\FriendlyName</td><td>netpass.exe (1.0.3.0) NetPass Network Password Recovery Network Password Recovery NirSoft</td></tr> <tr><td>Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Hashes\{309da424-8f53-4ff7-bf43-7f60dad20169}\HashAlg</td><td>32771</td></tr> <tr><td>Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Hashes\{309da424-8f53-4ff7-bf43-7f60dad20169}\ItemData</td><td>Unknown data format</td></tr> <tr><td>Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Hashes\{309da424-8f53-4ff7-bf43-7f60dad20169}\ItemSize</td><td>39936</td></tr> <tr><td>Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Hashes\{309da424-8f53-4ff7-bf43-7f60dad20169}\LastModified</td><td>128808419702728861</td></tr> <tr><td>Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Hashes\{309da424-8f53-4ff7-bf43-7f60dad20169}\SaferFlags</td><td>0</td></tr> <tr><td>Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Hashes\{3b5642c2-be7a-4a57-a716-7d0157e2fe61}\Description</td><td></td></tr> <tr><td>Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Hashes\{3b5642c2-be7a-4a57-a716-7d0157e2fe61}\FriendlyName</td><td>WinPcap.exe 680 KB 5/1/2001 5:51:20 AM</td></tr> <tr><td>Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Hashes\{3b5642c2-be7a-4a57-a716-7d0157e2fe61}\HashAlg</td><td>32771</td></tr> <tr><td>Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Hashes\{3b5642c2-be7a-4a57-a716-7d0157e2fe61}\ItemData</td><td>Unknown data format</td></tr> <tr><td>Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Hashes\{3b5642c2-be7a-4a57-a716-7d0157e2fe61}\ItemSize</td><td>695958</td></tr> <tr><td>Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Hashes\{3b5642c2-be7a-4a57-a716-7d0157e2fe61}\LastModified</td><td>128697810170607692</td></tr> <tr><td>Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Hashes\{3b5642c2-be7a-4a57-a716-7d0157e2fe61}\SaferFlags</td><td>0</td></tr> <tr><td>Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Hashes\{46715e77-615a-428b-8c15-e8e0ed1f4f3c}\Description</td><td></td></tr> <tr><td>Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Hashes\{46715e77-615a-428b-8c15-e8e0ed1f4f3c}\FriendlyName</td><td>WinPcap_3_1_beta_3.exe 475 KB 6/11/2004 1:54:06 PM</td></tr> <tr><td>Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Hashes\{46715e77-615a-428b-8c15-e8e0ed1f4f3c}\HashAlg</td><td>32771</td></tr> <tr><td>Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Hashes\{46715e77-615a-428b-8c15-e8e0ed1f4f3c}\ItemData</td><td>Unknown data format</td></tr> <tr><td>Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Hashes\{46715e77-615a-428b-8c15-e8e0ed1f4f3c}\ItemSize</td><td>485810</td></tr> <tr><td>Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Hashes\{46715e77-615a-428b-8c15-e8e0ed1f4f3c}\LastModified</td><td>128697811080336856</td></tr> <tr><td>Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Hashes\{46715e77-615a-428b-8c15-e8e0ed1f4f3c}\SaferFlags</td><td>0</td></tr> <tr><td>Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Hashes\{47418b2d-7c75-4ce1-bebd-48d2907fec19}\Description</td><td></td></tr> <tr><td>Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Hashes\{47418b2d-7c75-4ce1-bebd-48d2907fec19}\FriendlyName</td><td>tor.exe 1201 KB 12/14/2006 9:21:44 PM</td></tr> <tr><td>Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Hashes\{47418b2d-7c75-4ce1-bebd-48d2907fec19}\HashAlg</td><td>32771</td></tr> <tr><td>Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Hashes\{47418b2d-7c75-4ce1-bebd-48d2907fec19}\ItemData</td><td>Unknown data format</td></tr> <tr><td>Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Hashes\{47418b2d-7c75-4ce1-bebd-48d2907fec19}\ItemSize</td><td>1228800</td></tr> <tr><td>Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Hashes\{47418b2d-7c75-4ce1-bebd-48d2907fec19}\LastModified</td><td>128697811862538276</td></tr> <tr><td>Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Hashes\{47418b2d-7c75-4ce1-bebd-48d2907fec19}\SaferFlags</td><td>0</td></tr> <tr><td>Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Hashes\{4b1ac0dc-0018-4aa9-b4e5-cb321dd605f6}\Description</td><td>alternative command shell with other functionality</td></tr> <tr><td>Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Hashes\{4b1ac0dc-0018-4aa9-b4e5-cb321dd605f6}\FriendlyName</td><td>NirCmd.exe (1.8.2.151) NirCmd NirCmd NirCmd NirSoft</td></tr> <tr><td>Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Hashes\{4b1ac0dc-0018-4aa9-b4e5-cb321dd605f6}\HashAlg</td><td>32771</td></tr> <tr><td>Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Hashes\{4b1ac0dc-0018-4aa9-b4e5-cb321dd605f6}\ItemData</td><td>Unknown data format</td></tr> <tr><td>Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Hashes\{4b1ac0dc-0018-4aa9-b4e5-cb321dd605f6}\ItemSize</td><td>25600</td></tr> <tr><td>Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Hashes\{4b1ac0dc-0018-4aa9-b4e5-cb321dd605f6}\LastModified</td><td>128808420606218547</td></tr> <tr><td>Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Hashes\{4b1ac0dc-0018-4aa9-b4e5-cb321dd605f6}\SaferFlags</td><td>0</td></tr> <tr><td>Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Hashes\{54646fc6-8ffe-4a26-8f6d-7b7ed0dc5e97}\Description</td><td></td></tr> <tr><td>Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Hashes\{54646fc6-8ffe-4a26-8f6d-7b7ed0dc5e97}\FriendlyName</td><td>nemesis.exe 133 KB 10/6/2004 10:25:16 PM</td></tr> <tr><td>Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Hashes\{54646fc6-8ffe-4a26-8f6d-7b7ed0dc5e97}\HashAlg</td><td>32771</td></tr> <tr><td>Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Hashes\{54646fc6-8ffe-4a26-8f6d-7b7ed0dc5e97}\ItemData</td><td>Unknown data format</td></tr> <tr><td>Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Hashes\{54646fc6-8ffe-4a26-8f6d-7b7ed0dc5e97}\ItemSize</td><td>135189</td></tr> <tr><td>Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Hashes\{54646fc6-8ffe-4a26-8f6d-7b7ed0dc5e97}\LastModified</td><td>128697808976910500</td></tr> <tr><td>Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Hashes\{54646fc6-8ffe-4a26-8f6d-7b7ed0dc5e97}\SaferFlags</td><td>0</td></tr> <tr><td>Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Hashes\{548db5f2-63b6-40b7-9aa7-9071f46f98b8}\Description</td><td></td></tr> <tr><td>Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Hashes\{548db5f2-63b6-40b7-9aa7-9071f46f98b8}\FriendlyName</td><td>blat.exe (2.5.0.0) blat A Win32 command line eMail tool Blat http://www.blat.net/</td></tr> <tr><td>Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Hashes\{548db5f2-63b6-40b7-9aa7-9071f46f98b8}\HashAlg</td><td>32771</td></tr> <tr><td>Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Hashes\{548db5f2-63b6-40b7-9aa7-9071f46f98b8}\ItemData</td><td>Unknown data format</td></tr> <tr><td>Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Hashes\{548db5f2-63b6-40b7-9aa7-9071f46f98b8}\ItemSize</td><td>103936</td></tr> <tr><td>Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Hashes\{548db5f2-63b6-40b7-9aa7-9071f46f98b8}\LastModified</td><td>128808413882668789</td></tr> <tr><td>Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Hashes\{548db5f2-63b6-40b7-9aa7-9071f46f98b8}\SaferFlags</td><td>0</td></tr> <tr><td>Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Hashes\{58512cb1-8d68-495f-bc48-0c8e99c8997c}\Description</td><td></td></tr> <tr><td>Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Hashes\{58512cb1-8d68-495f-bc48-0c8e99c8997c}\FriendlyName</td><td>WinPcap_3_0.exe 431 KB 2/8/2004 2:27:32 PM</td></tr> <tr><td>Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Hashes\{58512cb1-8d68-495f-bc48-0c8e99c8997c}\HashAlg</td><td>32771</td></tr> <tr><td>Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Hashes\{58512cb1-8d68-495f-bc48-0c8e99c8997c}\ItemData</td><td>Unknown data format</td></tr> <tr><td>Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Hashes\{58512cb1-8d68-495f-bc48-0c8e99c8997c}\ItemSize</td><td>440557</td></tr> <tr><td>Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Hashes\{58512cb1-8d68-495f-bc48-0c8e99c8997c}\LastModified</td><td>128697810430039132</td></tr> <tr><td>Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Hashes\{58512cb1-8d68-495f-bc48-0c8e99c8997c}\SaferFlags</td><td>0</td></tr> <tr><td>Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Hashes\{5b0da3f4-9a93-4589-850a-388ff38dc70f}\Description</td><td></td></tr> <tr><td>Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Hashes\{5b0da3f4-9a93-4589-850a-388ff38dc70f}\FriendlyName</td><td>WinDump-3.9.3.exe 545 KB 1/16/2006 12:58:36 PM</td></tr> <tr><td>Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Hashes\{5b0da3f4-9a93-4589-850a-388ff38dc70f}\HashAlg</td><td>32771</td></tr> <tr><td>Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Hashes\{5b0da3f4-9a93-4589-850a-388ff38dc70f}\ItemData</td><td>Unknown data format</td></tr> <tr><td>Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Hashes\{5b0da3f4-9a93-4589-850a-388ff38dc70f}\ItemSize</td><td>557056</td></tr> <tr><td>Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Hashes\{5b0da3f4-9a93-4589-850a-388ff38dc70f}\LastModified</td><td>128697809795682376</td></tr> <tr><td>Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Hashes\{5b0da3f4-9a93-4589-850a-388ff38dc70f}\SaferFlags</td><td>0</td></tr> <tr><td>Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Hashes\{5d201311-3b2b-4c38-b950-da2cad99cea1}\Description</td><td></td></tr> <tr><td>Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Hashes\{5d201311-3b2b-4c38-b950-da2cad99cea1}\FriendlyName</td><td>WinPcap_3_1_beta4.exe 474 KB 11/6/2004 3:06:08 AM</td></tr> <tr><td>Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Hashes\{5d201311-3b2b-4c38-b950-da2cad99cea1}\HashAlg</td><td>32771</td></tr> <tr><td>Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Hashes\{5d201311-3b2b-4c38-b950-da2cad99cea1}\ItemData</td><td>Unknown data format</td></tr> <tr><td>Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Hashes\{5d201311-3b2b-4c38-b950-da2cad99cea1}\ItemSize</td><td>484652</td></tr> <tr><td>Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Hashes\{5d201311-3b2b-4c38-b950-da2cad99cea1}\LastModified</td><td>128697810846379708</td></tr> <tr><td>Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Hashes\{5d201311-3b2b-4c38-b950-da2cad99cea1}\SaferFlags</td><td>0</td></tr> <tr><td>Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Hashes\{5f017c9e-58e8-4125-8a72-6626beb1bb0c}\Description</td><td></td></tr> <tr><td>Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Hashes\{5f017c9e-58e8-4125-8a72-6626beb1bb0c}\FriendlyName</td><td> (1.0.0.0) Brutus AET 2 Brutus - AET2 HooBie Inc.</td></tr> <tr><td>Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Hashes\{5f017c9e-58e8-4125-8a72-6626beb1bb0c}\HashAlg</td><td>32771</td></tr> <tr><td>Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Hashes\{5f017c9e-58e8-4125-8a72-6626beb1bb0c}\ItemData</td><td>Unknown data format</td></tr> <tr><td>Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Hashes\{5f017c9e-58e8-4125-8a72-6626beb1bb0c}\ItemSize</td><td>679424</td></tr> <tr><td>Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Hashes\{5f017c9e-58e8-4125-8a72-6626beb1bb0c}\LastModified</td><td>128697807467207060</td></tr> <tr><td>Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Hashes\{5f017c9e-58e8-4125-8a72-6626beb1bb0c}\SaferFlags</td><td>0</td></tr> <tr><td>Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Hashes\{66f9a139-4567-463f-9de1-69b7304353a5}\Description</td><td>rainbow table password cracking tool</td></tr> <tr><td>Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Hashes\{66f9a139-4567-463f-9de1-69b7304353a5}\FriendlyName</td><td>rcrack.exe 173 KB 2/11/2009 9:47:30 PM</td></tr> <tr><td>Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Hashes\{66f9a139-4567-463f-9de1-69b7304353a5}\HashAlg</td><td>32771</td></tr> <tr><td>Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Hashes\{66f9a139-4567-463f-9de1-69b7304353a5}\ItemData</td><td>Unknown data format</td></tr> <tr><td>Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Hashes\{66f9a139-4567-463f-9de1-69b7304353a5}\ItemSize</td><td>176128</td></tr> <tr><td>Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Hashes\{66f9a139-4567-463f-9de1-69b7304353a5}\LastModified</td><td>128808423344794785</td></tr> <tr><td>Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Hashes\{66f9a139-4567-463f-9de1-69b7304353a5}\SaferFlags</td><td>0</td></tr> <tr><td>Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Hashes\{679ae5e4-d46d-44bf-aaaa-8e1fba6cd9bd}\Description</td><td></td></tr> <tr><td>Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Hashes\{679ae5e4-d46d-44bf-aaaa-8e1fba6cd9bd}\FriendlyName</td><td>WINDUMP_.EXE 389 KB 12/9/2002 11:20:51 PM</td></tr> <tr><td>Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Hashes\{679ae5e4-d46d-44bf-aaaa-8e1fba6cd9bd}\HashAlg</td><td>32771</td></tr> <tr><td>Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Hashes\{679ae5e4-d46d-44bf-aaaa-8e1fba6cd9bd}\ItemData</td><td>Unknown data format</td></tr> <tr><td>Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Hashes\{679ae5e4-d46d-44bf-aaaa-8e1fba6cd9bd}\ItemSize</td><td>397312</td></tr> <tr><td>Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Hashes\{679ae5e4-d46d-44bf-aaaa-8e1fba6cd9bd}\LastModified</td><td>128697809985567436</td></tr> <tr><td>Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Hashes\{679ae5e4-d46d-44bf-aaaa-8e1fba6cd9bd}\SaferFlags</td><td>0</td></tr> <tr><td>Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Hashes\{713909ff-4cec-47cd-a337-2b9895a2c14d}\Description</td><td></td></tr> <tr><td>Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Hashes\{713909ff-4cec-47cd-a337-2b9895a2c14d}\FriendlyName</td><td>iepv.exe (1.0.0.0) IE PassView Internet Explorer Passwords Viewer IE PassView NirSoft</td></tr> <tr><td>Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Hashes\{713909ff-4cec-47cd-a337-2b9895a2c14d}\HashAlg</td><td>32771</td></tr> <tr><td>Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Hashes\{713909ff-4cec-47cd-a337-2b9895a2c14d}\ItemData</td><td>Unknown data format</td></tr> <tr><td>Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Hashes\{713909ff-4cec-47cd-a337-2b9895a2c14d}\ItemSize</td><td>39424</td></tr> <tr><td>Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Hashes\{713909ff-4cec-47cd-a337-2b9895a2c14d}\LastModified</td><td>128808417999902206</td></tr> <tr><td>Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Hashes\{713909ff-4cec-47cd-a337-2b9895a2c14d}\SaferFlags</td><td>0</td></tr> <tr><td>Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Hashes\{74a4ea49-5ed6-445b-a5b0-68181e03c6a8}\Description</td><td></td></tr> <tr><td>Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Hashes\{74a4ea49-5ed6-445b-a5b0-68181e03c6a8}\FriendlyName</td><td>windump.exe 277 KB 12/9/2002 11:20:48 PM</td></tr> <tr><td>Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Hashes\{74a4ea49-5ed6-445b-a5b0-68181e03c6a8}\HashAlg</td><td>32771</td></tr> <tr><td>Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Hashes\{74a4ea49-5ed6-445b-a5b0-68181e03c6a8}\ItemData</td><td>Unknown data format</td></tr> <tr><td>Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Hashes\{74a4ea49-5ed6-445b-a5b0-68181e03c6a8}\ItemSize</td><td>282624</td></tr> <tr><td>Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Hashes\{74a4ea49-5ed6-445b-a5b0-68181e03c6a8}\LastModified</td><td>128697809891797036</td></tr> <tr><td>Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Hashes\{74a4ea49-5ed6-445b-a5b0-68181e03c6a8}\SaferFlags</td><td>0</td></tr> <tr><td>Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Hashes\{75694881-1de4-43c7-92dd-aadcef852568}\Description</td><td></td></tr> <tr><td>Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Hashes\{75694881-1de4-43c7-92dd-aadcef852568}\FriendlyName</td><td>WinPcap_2_3.exe 327 KB 1/22/2003 5:05:16 AM</td></tr> <tr><td>Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Hashes\{75694881-1de4-43c7-92dd-aadcef852568}\HashAlg</td><td>32771</td></tr> <tr><td>Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Hashes\{75694881-1de4-43c7-92dd-aadcef852568}\ItemData</td><td>Unknown data format</td></tr> <tr><td>Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Hashes\{75694881-1de4-43c7-92dd-aadcef852568}\ItemSize</td><td>334628</td></tr> <tr><td>Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Hashes\{75694881-1de4-43c7-92dd-aadcef852568}\LastModified</td><td>128697810347833748</td></tr> <tr><td>Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Hashes\{75694881-1de4-43c7-92dd-aadcef852568}\SaferFlags</td><td>0</td></tr> <tr><td>Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Hashes\{87ba674c-563c-41ce-936f-570896ce08da}\Description</td><td></td></tr> <tr><td>Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Hashes\{87ba674c-563c-41ce-936f-570896ce08da}\FriendlyName</td><td>NTcrack.exe 36 KB 3/29/1997 9:04:44 PM</td></tr> <tr><td>Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Hashes\{87ba674c-563c-41ce-936f-570896ce08da}\HashAlg</td><td>32771</td></tr> <tr><td>Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Hashes\{87ba674c-563c-41ce-936f-570896ce08da}\ItemData</td><td>Unknown data format</td></tr> <tr><td>Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Hashes\{87ba674c-563c-41ce-936f-570896ce08da}\ItemSize</td><td>36203</td></tr> <tr><td>Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Hashes\{87ba674c-563c-41ce-936f-570896ce08da}\LastModified</td><td>128697809293229316</td></tr> <tr><td>Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Hashes\{87ba674c-563c-41ce-936f-570896ce08da}\SaferFlags</td><td>0</td></tr> <tr><td>Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Hashes\{8a8e4448-8eed-4363-8686-cac8e0297350}\Description</td><td></td></tr> <tr><td>Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Hashes\{8a8e4448-8eed-4363-8686-cac8e0297350}\FriendlyName</td><td>WINPCAP_.EXE 327 KB 12/9/2002 11:20:52 PM</td></tr> <tr><td>Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Hashes\{8a8e4448-8eed-4363-8686-cac8e0297350}\HashAlg</td><td>32771</td></tr> <tr><td>Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Hashes\{8a8e4448-8eed-4363-8686-cac8e0297350}\ItemData</td><td>Unknown data format</td></tr> <tr><td>Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Hashes\{8a8e4448-8eed-4363-8686-cac8e0297350}\ItemSize</td><td>334628</td></tr> <tr><td>Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Hashes\{8a8e4448-8eed-4363-8686-cac8e0297350}\LastModified</td><td>128697811165511636</td></tr> <tr><td>Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Hashes\{8a8e4448-8eed-4363-8686-cac8e0297350}\SaferFlags</td><td>0</td></tr> <tr><td>Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Hashes\{8c247c4d-6cb5-4a36-bf08-b9b14522df18}\Description</td><td></td></tr> <tr><td>Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Hashes\{8c247c4d-6cb5-4a36-bf08-b9b14522df18}\FriendlyName</td><td> (5.0.4.0) </td></tr> <tr><td>Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Hashes\{8c247c4d-6cb5-4a36-bf08-b9b14522df18}\HashAlg</td><td>32771</td></tr> <tr><td>Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Hashes\{8c247c4d-6cb5-4a36-bf08-b9b14522df18}\ItemData</td><td>Unknown data format</td></tr> <tr><td>Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Hashes\{8c247c4d-6cb5-4a36-bf08-b9b14522df18}\ItemSize</td><td>2396672</td></tr> <tr><td>Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Hashes\{8c247c4d-6cb5-4a36-bf08-b9b14522df18}\LastModified</td><td>128697808587450772</td></tr> <tr><td>Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Hashes\{8c247c4d-6cb5-4a36-bf08-b9b14522df18}\SaferFlags</td><td>0</td></tr> <tr><td>Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Hashes\{8e694b2a-2be1-4075-8a1c-d23efbbce8c7}\Description</td><td>W32/CONFICKER.WORM.GEN.B</td></tr> <tr><td>Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Hashes\{8e694b2a-2be1-4075-8a1c-d23efbbce8c7}\FriendlyName</td><td>xeakps.dll 157 KB 4/16/2007 10:52:54 AM</td></tr> <tr><td>Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Hashes\{8e694b2a-2be1-4075-8a1c-d23efbbce8c7}\HashAlg</td><td>32771</td></tr> <tr><td>Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Hashes\{8e694b2a-2be1-4075-8a1c-d23efbbce8c7}\ItemData</td><td>Unknown data format</td></tr> <tr><td>Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Hashes\{8e694b2a-2be1-4075-8a1c-d23efbbce8c7}\ItemSize</td><td>159975</td></tr> <tr><td>Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Hashes\{8e694b2a-2be1-4075-8a1c-d23efbbce8c7}\LastModified</td><td>128759970701689888</td></tr> <tr><td>Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Hashes\{8e694b2a-2be1-4075-8a1c-d23efbbce8c7}\SaferFlags</td><td>0</td></tr> <tr><td>Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Hashes\{96915238-8c3c-40c4-ac3c-116e39d19c2e}\Description</td><td></td></tr> <tr><td>Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Hashes\{96915238-8c3c-40c4-ac3c-116e39d19c2e}\FriendlyName</td><td> (0.0.11.0) </td></tr> <tr><td>Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Hashes\{96915238-8c3c-40c4-ac3c-116e39d19c2e}\HashAlg</td><td>32771</td></tr> <tr><td>Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Hashes\{96915238-8c3c-40c4-ac3c-116e39d19c2e}\ItemData</td><td>Unknown data format</td></tr> <tr><td>Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Hashes\{96915238-8c3c-40c4-ac3c-116e39d19c2e}\ItemSize</td><td>11891712</td></tr> <tr><td>Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Hashes\{96915238-8c3c-40c4-ac3c-116e39d19c2e}\LastModified</td><td>128697811944274808</td></tr> <tr><td>Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Hashes\{96915238-8c3c-40c4-ac3c-116e39d19c2e}\SaferFlags</td><td>0</td></tr> <tr><td>Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Hashes\{99124f21-051b-4392-ac8a-6121c343110b}\Description</td><td></td></tr> <tr><td>Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Hashes\{99124f21-051b-4392-ac8a-6121c343110b}\FriendlyName</td><td>wireshark-setup-0.99.5.exe 17714 KB 4/10/2007 11:16:50 AM</td></tr> <tr><td>Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Hashes\{99124f21-051b-4392-ac8a-6121c343110b}\HashAlg</td><td>32771</td></tr> <tr><td>Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Hashes\{99124f21-051b-4392-ac8a-6121c343110b}\ItemData</td><td>Unknown data format</td></tr> <tr><td>Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Hashes\{99124f21-051b-4392-ac8a-6121c343110b}\ItemSize</td><td>18138441</td></tr> <tr><td>Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Hashes\{99124f21-051b-4392-ac8a-6121c343110b}\LastModified</td><td>128697811574038012</td></tr> <tr><td>Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Hashes\{99124f21-051b-4392-ac8a-6121c343110b}\SaferFlags</td><td>0</td></tr> <tr><td>Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Hashes\{9ef030cc-b298-4f3b-a060-0e863600e846}\Description</td><td></td></tr> <tr><td>Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Hashes\{9ef030cc-b298-4f3b-a060-0e863600e846}\FriendlyName</td><td>pwservice.exe 44 KB 3/6/2009 2:23:26 PM</td></tr> <tr><td>Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Hashes\{9ef030cc-b298-4f3b-a060-0e863600e846}\HashAlg</td><td>32771</td></tr> <tr><td>Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Hashes\{9ef030cc-b298-4f3b-a060-0e863600e846}\ItemData</td><td>Unknown data format</td></tr> <tr><td>Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Hashes\{9ef030cc-b298-4f3b-a060-0e863600e846}\ItemSize</td><td>44544</td></tr> <tr><td>Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Hashes\{9ef030cc-b298-4f3b-a060-0e863600e846}\LastModified</td><td>128808421264238861</td></tr> <tr><td>Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Hashes\{9ef030cc-b298-4f3b-a060-0e863600e846}\SaferFlags</td><td>0</td></tr> <tr><td>Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Hashes\{a00d522f-296b-4b95-a53e-f47522bec6c1}\Description</td><td></td></tr> <tr><td>Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Hashes\{a00d522f-296b-4b95-a53e-f47522bec6c1}\FriendlyName</td><td>lsadump2.exe 33 KB 3/29/2000 3:19:00 PM</td></tr> <tr><td>Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Hashes\{a00d522f-296b-4b95-a53e-f47522bec6c1}\HashAlg</td><td>32771</td></tr> <tr><td>Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Hashes\{a00d522f-296b-4b95-a53e-f47522bec6c1}\ItemData</td><td>Unknown data format</td></tr> <tr><td>Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Hashes\{a00d522f-296b-4b95-a53e-f47522bec6c1}\ItemSize</td><td>32768</td></tr> <tr><td>Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Hashes\{a00d522f-296b-4b95-a53e-f47522bec6c1}\LastModified</td><td>128697808706226612</td></tr> <tr><td>Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Hashes\{a00d522f-296b-4b95-a53e-f47522bec6c1}\SaferFlags</td><td>0</td></tr> <tr><td>Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Hashes\{a7aeca97-d84b-4eb5-8c78-37706c2961c9}\Description</td><td></td></tr> <tr><td>Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Hashes\{a7aeca97-d84b-4eb5-8c78-37706c2961c9}\FriendlyName</td><td> (3.1.0.27) WinPcap 3.1 installer WinPcap 3.1 CACE Technologies</td></tr> <tr><td>Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Hashes\{a7aeca97-d84b-4eb5-8c78-37706c2961c9}\HashAlg</td><td>32771</td></tr> <tr><td>Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Hashes\{a7aeca97-d84b-4eb5-8c78-37706c2961c9}\ItemData</td><td>Unknown data format</td></tr> <tr><td>Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Hashes\{a7aeca97-d84b-4eb5-8c78-37706c2961c9}\ItemSize</td><td>467181</td></tr> <tr><td>Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Hashes\{a7aeca97-d84b-4eb5-8c78-37706c2961c9}\LastModified</td><td>128697810543501316</td></tr> <tr><td>Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Hashes\{a7aeca97-d84b-4eb5-8c78-37706c2961c9}\SaferFlags</td><td>0</td></tr> <tr><td>Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Hashes\{aeb4ee04-7e58-481f-8a99-2f05fc195a0e}\Description</td><td></td></tr> <tr><td>Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Hashes\{aeb4ee04-7e58-481f-8a99-2f05fc195a0e}\FriendlyName</td><td>PwDump3.exe 61 KB 2/23/2001 8:04:34 AM</td></tr> <tr><td>Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Hashes\{aeb4ee04-7e58-481f-8a99-2f05fc195a0e}\HashAlg</td><td>32771</td></tr> <tr><td>Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Hashes\{aeb4ee04-7e58-481f-8a99-2f05fc195a0e}\ItemData</td><td>Unknown data format</td></tr> <tr><td>Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Hashes\{aeb4ee04-7e58-481f-8a99-2f05fc195a0e}\ItemSize</td><td>61440</td></tr> <tr><td>Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Hashes\{aeb4ee04-7e58-481f-8a99-2f05fc195a0e}\LastModified</td><td>128697809470767940</td></tr> <tr><td>Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Hashes\{aeb4ee04-7e58-481f-8a99-2f05fc195a0e}\SaferFlags</td><td>0</td></tr> <tr><td>Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Hashes\{b538229d-e330-4e3e-9118-e05604229dfd}\Description</td><td></td></tr> <tr><td>Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Hashes\{b538229d-e330-4e3e-9118-e05604229dfd}\FriendlyName</td><td>john.exe 125 KB 12/3/1998 4:19:08 AM</td></tr> <tr><td>Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Hashes\{b538229d-e330-4e3e-9118-e05604229dfd}\HashAlg</td><td>32771</td></tr> <tr><td>Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Hashes\{b538229d-e330-4e3e-9118-e05604229dfd}\ItemData</td><td>Unknown data format</td></tr> <tr><td>Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Hashes\{b538229d-e330-4e3e-9118-e05604229dfd}\ItemSize</td><td>127488</td></tr> <tr><td>Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Hashes\{b538229d-e330-4e3e-9118-e05604229dfd}\LastModified</td><td>128697808024203236</td></tr> <tr><td>Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Hashes\{b538229d-e330-4e3e-9118-e05604229dfd}\SaferFlags</td><td>0</td></tr> <tr><td>Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Hashes\{b69d2f8b-da66-440a-bde4-1e2c68e61c58}\Description</td><td></td></tr> <tr><td>Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Hashes\{b69d2f8b-da66-440a-bde4-1e2c68e61c58}\FriendlyName</td><td>john-386.exe 164 KB 4/26/2007 12:36:20 PM</td></tr> <tr><td>Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Hashes\{b69d2f8b-da66-440a-bde4-1e2c68e61c58}\HashAlg</td><td>32771</td></tr> <tr><td>Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Hashes\{b69d2f8b-da66-440a-bde4-1e2c68e61c58}\ItemData</td><td>Unknown data format</td></tr> <tr><td>Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Hashes\{b69d2f8b-da66-440a-bde4-1e2c68e61c58}\ItemSize</td><td>167424</td></tr> <tr><td>Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Hashes\{b69d2f8b-da66-440a-bde4-1e2c68e61c58}\LastModified</td><td>128697807856197936</td></tr> <tr><td>Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Hashes\{b69d2f8b-da66-440a-bde4-1e2c68e61c58}\SaferFlags</td><td>0</td></tr> <tr><td>Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Hashes\{b766da57-49c2-4a24-a0ad-158912ae7d3a}\Description</td><td></td></tr> <tr><td>Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Hashes\{b766da57-49c2-4a24-a0ad-158912ae7d3a}\FriendlyName</td><td>avkill.exe (1.0.0.0) avkill AVKILL </td></tr> <tr><td>Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Hashes\{b766da57-49c2-4a24-a0ad-158912ae7d3a}\HashAlg</td><td>32771</td></tr> <tr><td>Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Hashes\{b766da57-49c2-4a24-a0ad-158912ae7d3a}\ItemData</td><td>Unknown data format</td></tr> <tr><td>Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Hashes\{b766da57-49c2-4a24-a0ad-158912ae7d3a}\ItemSize</td><td>28672</td></tr> <tr><td>Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Hashes\{b766da57-49c2-4a24-a0ad-158912ae7d3a}\LastModified</td><td>128808415972906075</td></tr> <tr><td>Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Hashes\{b766da57-49c2-4a24-a0ad-158912ae7d3a}\SaferFlags</td><td>0</td></tr> <tr><td>Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Hashes\{c73f5f52-f257-4f66-85a8-33f7b9d11207}\Description</td><td></td></tr> <tr><td>Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Hashes\{c73f5f52-f257-4f66-85a8-33f7b9d11207}\FriendlyName</td><td>stub32i.exe (2.11.15.0) stub32i.exe LC5 @stake</td></tr> <tr><td>Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Hashes\{c73f5f52-f257-4f66-85a8-33f7b9d11207}\HashAlg</td><td>32771</td></tr> <tr><td>Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Hashes\{c73f5f52-f257-4f66-85a8-33f7b9d11207}\ItemData</td><td>Unknown data format</td></tr> <tr><td>Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Hashes\{c73f5f52-f257-4f66-85a8-33f7b9d11207}\ItemSize</td><td>5694786</td></tr> <tr><td>Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Hashes\{c73f5f52-f257-4f66-85a8-33f7b9d11207}\LastModified</td><td>128697808479458528</td></tr> <tr><td>Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Hashes\{c73f5f52-f257-4f66-85a8-33f7b9d11207}\SaferFlags</td><td>0</td></tr> <tr><td>Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Hashes\{c79b7f8b-739f-4c0f-a445-588f8a243843}\Description</td><td></td></tr> <tr><td>Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Hashes\{c79b7f8b-739f-4c0f-a445-588f8a243843}\FriendlyName</td><td>dsniff.exe 241 KB 5/4/2000 1:06:48 AM</td></tr> <tr><td>Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Hashes\{c79b7f8b-739f-4c0f-a445-588f8a243843}\HashAlg</td><td>32771</td></tr> <tr><td>Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Hashes\{c79b7f8b-739f-4c0f-a445-588f8a243843}\ItemData</td><td>Unknown data format</td></tr> <tr><td>Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Hashes\{c79b7f8b-739f-4c0f-a445-588f8a243843}\ItemSize</td><td>245760</td></tr> <tr><td>Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Hashes\{c79b7f8b-739f-4c0f-a445-588f8a243843}\LastModified</td><td>128697807691787168</td></tr> <tr><td>Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Hashes\{c79b7f8b-739f-4c0f-a445-588f8a243843}\SaferFlags</td><td>0</td></tr> <tr><td>Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Hashes\{ca820d7e-ebe2-40d7-9ee1-5552897ff672}\Description</td><td>firefox password stealer</td></tr> <tr><td>Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Hashes\{ca820d7e-ebe2-40d7-9ee1-5552897ff672}\FriendlyName</td><td>FirePassword.exe 41 KB 3/6/2009 2:23:18 PM</td></tr> <tr><td>Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Hashes\{ca820d7e-ebe2-40d7-9ee1-5552897ff672}\HashAlg</td><td>32771</td></tr> <tr><td>Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Hashes\{ca820d7e-ebe2-40d7-9ee1-5552897ff672}\ItemData</td><td>Unknown data format</td></tr> <tr><td>Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Hashes\{ca820d7e-ebe2-40d7-9ee1-5552897ff672}\ItemSize</td><td>40960</td></tr> <tr><td>Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Hashes\{ca820d7e-ebe2-40d7-9ee1-5552897ff672}\LastModified</td><td>128808416624680349</td></tr> <tr><td>Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Hashes\{ca820d7e-ebe2-40d7-9ee1-5552897ff672}\SaferFlags</td><td>0</td></tr> <tr><td>Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Hashes\{cdf7c117-40f2-4c6e-97a8-aeb293a4b5d0}\Description</td><td></td></tr> <tr><td>Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Hashes\{cdf7c117-40f2-4c6e-97a8-aeb293a4b5d0}\FriendlyName</td><td>mspass.exe (1.0.8.120) MessenPass Instant Messengers Password Recovery MessenPass NirSoft</td></tr> <tr><td>Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Hashes\{cdf7c117-40f2-4c6e-97a8-aeb293a4b5d0}\HashAlg</td><td>32771</td></tr> <tr><td>Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Hashes\{cdf7c117-40f2-4c6e-97a8-aeb293a4b5d0}\ItemData</td><td>Unknown data format</td></tr> <tr><td>Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Hashes\{cdf7c117-40f2-4c6e-97a8-aeb293a4b5d0}\ItemSize</td><td>81408</td></tr> <tr><td>Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Hashes\{cdf7c117-40f2-4c6e-97a8-aeb293a4b5d0}\LastModified</td><td>128808418643400477</td></tr> <tr><td>Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Hashes\{cdf7c117-40f2-4c6e-97a8-aeb293a4b5d0}\SaferFlags</td><td>0</td></tr> <tr><td>Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Hashes\{d5433747-7aff-4ba5-bedf-006f09a344bc}\Description</td><td></td></tr> <tr><td>Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Hashes\{d5433747-7aff-4ba5-bedf-006f09a344bc}\FriendlyName</td><td> (3.1.0.27) WinPcap 3.1 installer WinPcap 3.1 CACE Technologies</td></tr> <tr><td>Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Hashes\{d5433747-7aff-4ba5-bedf-006f09a344bc}\HashAlg</td><td>32771</td></tr> <tr><td>Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Hashes\{d5433747-7aff-4ba5-bedf-006f09a344bc}\ItemData</td><td>Unknown data format</td></tr> <tr><td>Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Hashes\{d5433747-7aff-4ba5-bedf-006f09a344bc}\ItemSize</td><td>467181</td></tr> <tr><td>Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Hashes\{d5433747-7aff-4ba5-bedf-006f09a344bc}\LastModified</td><td>128697810736355772</td></tr> <tr><td>Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Hashes\{d5433747-7aff-4ba5-bedf-006f09a344bc}\SaferFlags</td><td>0</td></tr> <tr><td>Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Hashes\{d58ed129-adae-443f-8912-e852cd005fae}\Description</td><td></td></tr> <tr><td>Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Hashes\{d58ed129-adae-443f-8912-e852cd005fae}\FriendlyName</td><td>nc.exe 61 KB 9/6/2006 11:42:38 AM</td></tr> <tr><td>Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Hashes\{d58ed129-adae-443f-8912-e852cd005fae}\HashAlg</td><td>32771</td></tr> <tr><td>Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Hashes\{d58ed129-adae-443f-8912-e852cd005fae}\ItemData</td><td>Unknown data format</td></tr> <tr><td>Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Hashes\{d58ed129-adae-443f-8912-e852cd005fae}\ItemSize</td><td>61440</td></tr> <tr><td>Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Hashes\{d58ed129-adae-443f-8912-e852cd005fae}\LastModified</td><td>128697809122410904</td></tr> <tr><td>Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Hashes\{d58ed129-adae-443f-8912-e852cd005fae}\SaferFlags</td><td>0</td></tr> <tr><td>Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Hashes\{daaa8aa1-5734-4663-8235-1c27eeade8ef}\Description</td><td></td></tr> <tr><td>Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Hashes\{daaa8aa1-5734-4663-8235-1c27eeade8ef}\FriendlyName</td><td>kerbcrack.exe 53 KB 4/25/2005 11:54:26 AM</td></tr> <tr><td>Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Hashes\{daaa8aa1-5734-4663-8235-1c27eeade8ef}\HashAlg</td><td>32771</td></tr> <tr><td>Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Hashes\{daaa8aa1-5734-4663-8235-1c27eeade8ef}\ItemData</td><td>Unknown data format</td></tr> <tr><td>Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Hashes\{daaa8aa1-5734-4663-8235-1c27eeade8ef}\ItemSize</td><td>53248</td></tr> <tr><td>Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Hashes\{daaa8aa1-5734-4663-8235-1c27eeade8ef}\LastModified</td><td>128697808188770288</td></tr> <tr><td>Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Hashes\{daaa8aa1-5734-4663-8235-1c27eeade8ef}\SaferFlags</td><td>0</td></tr> <tr><td>Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Hashes\{def3e5df-db52-446e-9a0b-39787d00cec8}\Description</td><td></td></tr> <tr><td>Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Hashes\{def3e5df-db52-446e-9a0b-39787d00cec8}\FriendlyName</td><td>2.02-WinDump.exe 193 KB 7/11/2001 9:40:02 AM</td></tr> <tr><td>Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Hashes\{def3e5df-db52-446e-9a0b-39787d00cec8}\HashAlg</td><td>32771</td></tr> <tr><td>Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Hashes\{def3e5df-db52-446e-9a0b-39787d00cec8}\ItemData</td><td>Unknown data format</td></tr> <tr><td>Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Hashes\{def3e5df-db52-446e-9a0b-39787d00cec8}\ItemSize</td><td>196608</td></tr> <tr><td>Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Hashes\{def3e5df-db52-446e-9a0b-39787d00cec8}\LastModified</td><td>128697809696598320</td></tr> <tr><td>Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Hashes\{def3e5df-db52-446e-9a0b-39787d00cec8}\SaferFlags</td><td>0</td></tr> <tr><td>Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Hashes\{e761bdcf-3396-4ccf-8117-ed1329bb73fa}\Description</td><td>steals wireless passwords</td></tr> <tr><td>Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Hashes\{e761bdcf-3396-4ccf-8117-ed1329bb73fa}\FriendlyName</td><td>WirelessKeyView.exe (1.0.0.0) WirelessKeyView WirelessKeyView WirelessKeyView NirSoft</td></tr> <tr><td>Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Hashes\{e761bdcf-3396-4ccf-8117-ed1329bb73fa}\HashAlg</td><td>32771</td></tr> <tr><td>Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Hashes\{e761bdcf-3396-4ccf-8117-ed1329bb73fa}\ItemData</td><td>Unknown data format</td></tr> <tr><td>Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Hashes\{e761bdcf-3396-4ccf-8117-ed1329bb73fa}\ItemSize</td><td>36864</td></tr> <tr><td>Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Hashes\{e761bdcf-3396-4ccf-8117-ed1329bb73fa}\LastModified</td><td>128808425618041043</td></tr> <tr><td>Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Hashes\{e761bdcf-3396-4ccf-8117-ed1329bb73fa}\SaferFlags</td><td>0</td></tr> <tr><td>Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Hashes\{ed03b4c3-8dbc-4c89-b51e-ebeee52c8f12}\Description</td><td></td></tr> <tr><td>Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Hashes\{ed03b4c3-8dbc-4c89-b51e-ebeee52c8f12}\FriendlyName</td><td>privoxy.exe (3.0.6.0) Privoxy Privoxy Privoxy The Privoxy team - www.privoxy.org</td></tr> <tr><td>Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Hashes\{ed03b4c3-8dbc-4c89-b51e-ebeee52c8f12}\HashAlg</td><td>32771</td></tr> <tr><td>Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Hashes\{ed03b4c3-8dbc-4c89-b51e-ebeee52c8f12}\ItemData</td><td>Unknown data format</td></tr> <tr><td>Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Hashes\{ed03b4c3-8dbc-4c89-b51e-ebeee52c8f12}\ItemSize</td><td>250368</td></tr> <tr><td>Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Hashes\{ed03b4c3-8dbc-4c89-b51e-ebeee52c8f12}\LastModified</td><td>128697811681405120</td></tr> <tr><td>Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Hashes\{ed03b4c3-8dbc-4c89-b51e-ebeee52c8f12}\SaferFlags</td><td>0</td></tr> <tr><td>Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Hashes\{ef5654a9-0ec2-4e65-af0c-02f1e5d5404b}\Description</td><td></td></tr> <tr><td>Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Hashes\{ef5654a9-0ec2-4e65-af0c-02f1e5d5404b}\FriendlyName</td><td>PWD_CHNG.EXE 69 KB 12/13/2006 4:59:00 PM</td></tr> <tr><td>Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Hashes\{ef5654a9-0ec2-4e65-af0c-02f1e5d5404b}\HashAlg</td><td>32771</td></tr> <tr><td>Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Hashes\{ef5654a9-0ec2-4e65-af0c-02f1e5d5404b}\ItemData</td><td>Unknown data format</td></tr> <tr><td>Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Hashes\{ef5654a9-0ec2-4e65-af0c-02f1e5d5404b}\ItemSize</td><td>70590</td></tr> <tr><td>Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Hashes\{ef5654a9-0ec2-4e65-af0c-02f1e5d5404b}\LastModified</td><td>128697807364372188</td></tr> <tr><td>Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Hashes\{ef5654a9-0ec2-4e65-af0c-02f1e5d5404b}\SaferFlags</td><td>0</td></tr> <tr><td>Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Hashes\{f7555247-8997-481f-b4f6-adf36dce1fa8}\Description</td><td></td></tr> <tr><td>Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Hashes\{f7555247-8997-481f-b4f6-adf36dce1fa8}\FriendlyName</td><td>ca_setup.exe 5218 KB 8/25/2005 5:04:37 PM</td></tr> <tr><td>Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Hashes\{f7555247-8997-481f-b4f6-adf36dce1fa8}\HashAlg</td><td>32771</td></tr> <tr><td>Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Hashes\{f7555247-8997-481f-b4f6-adf36dce1fa8}\ItemData</td><td>Unknown data format</td></tr> <tr><td>Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Hashes\{f7555247-8997-481f-b4f6-adf36dce1fa8}\ItemSize</td><td>5342578</td></tr> <tr><td>Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Hashes\{f7555247-8997-481f-b4f6-adf36dce1fa8}\LastModified</td><td>128697807583951208</td></tr> <tr><td>Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Hashes\{f7555247-8997-481f-b4f6-adf36dce1fa8}\SaferFlags</td><td>0</td></tr> <tr><td>Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Paths\{002ef509-f419-4deb-8901-4414cff56f48}\Description</td><td>tool which puts a network card into promiscuous sniffing mode</td></tr> <tr><td>Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Paths\{002ef509-f419-4deb-8901-4414cff56f48}\ItemData</td><td>rpcapd.exe</td></tr> <tr><td>Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Paths\{002ef509-f419-4deb-8901-4414cff56f48}\LastModified</td><td>128697774753089312</td></tr> <tr><td>Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Paths\{002ef509-f419-4deb-8901-4414cff56f48}\SaferFlags</td><td>0</td></tr> <tr><td>Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Paths\{03c1b2e7-3760-47e8-9ecd-b80ae62b35bd}\Description</td><td>One piece of the cain and abel program</td></tr> <tr><td>Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Paths\{03c1b2e7-3760-47e8-9ecd-b80ae62b35bd}\ItemData</td><td>abel*</td></tr> <tr><td>Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Paths\{03c1b2e7-3760-47e8-9ecd-b80ae62b35bd}\LastModified</td><td>128697769863339680</td></tr> <tr><td>Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Paths\{03c1b2e7-3760-47e8-9ecd-b80ae62b35bd}\SaferFlags</td><td>0</td></tr> <tr><td>Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Paths\{0c292d08-2c4d-4c34-b9f8-b05b5e06baef}\Description</td><td>windows based brute force password cracker</td></tr> <tr><td>Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Paths\{0c292d08-2c4d-4c34-b9f8-b05b5e06baef}\ItemData</td><td>brutus*</td></tr> <tr><td>Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Paths\{0c292d08-2c4d-4c34-b9f8-b05b5e06baef}\LastModified</td><td>128697770126138724</td></tr> <tr><td>Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Paths\{0c292d08-2c4d-4c34-b9f8-b05b5e06baef}\SaferFlags</td><td>0</td></tr> <tr><td>Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Paths\{0e86cbf4-f8a3-4895-bb09-249d01377a4b}\Description</td><td></td></tr> <tr><td>Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Paths\{0e86cbf4-f8a3-4895-bb09-249d01377a4b}\ItemData</td><td>*ophtcrack*</td></tr> <tr><td>Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Paths\{0e86cbf4-f8a3-4895-bb09-249d01377a4b}\LastModified</td><td>128802215827302790</td></tr> <tr><td>Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Paths\{0e86cbf4-f8a3-4895-bb09-249d01377a4b}\SaferFlags</td><td>0</td></tr> <tr><td>Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Paths\{0fe3db88-8606-452e-a5d1-353958db7980}\Description</td><td></td></tr> <tr><td>Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Paths\{0fe3db88-8606-452e-a5d1-353958db7980}\ItemData</td><td>nircmd.exe</td></tr> <tr><td>Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Paths\{0fe3db88-8606-452e-a5d1-353958db7980}\LastModified</td><td>128808420972392642</td></tr> <tr><td>Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Paths\{0fe3db88-8606-452e-a5d1-353958db7980}\SaferFlags</td><td>0</td></tr> <tr><td>Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Paths\{14f81b8e-22ce-487b-9d06-a161dce02445}\Description</td><td>packet capture tool</td></tr> <tr><td>Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Paths\{14f81b8e-22ce-487b-9d06-a161dce02445}\ItemData</td><td>wireshark.exe</td></tr> <tr><td>Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Paths\{14f81b8e-22ce-487b-9d06-a161dce02445}\LastModified</td><td>128697796351670908</td></tr> <tr><td>Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Paths\{14f81b8e-22ce-487b-9d06-a161dce02445}\SaferFlags</td><td>0</td></tr> <tr><td>Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Paths\{1e96028e-84ed-498e-a0b2-bd6eaf1db2d8}\Description</td><td>web proxy program</td></tr> <tr><td>Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Paths\{1e96028e-84ed-498e-a0b2-bd6eaf1db2d8}\ItemData</td><td>privoxy.exe</td></tr> <tr><td>Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Paths\{1e96028e-84ed-498e-a0b2-bd6eaf1db2d8}\LastModified</td><td>128697773817355974</td></tr> <tr><td>Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Paths\{1e96028e-84ed-498e-a0b2-bd6eaf1db2d8}\SaferFlags</td><td>0</td></tr> <tr><td>Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Paths\{35d7e903-99a3-4574-9bc2-d94307cbbbe3}\Description</td><td>tool which puts a network card into promiscuous sniffing mode</td></tr> <tr><td>Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Paths\{35d7e903-99a3-4574-9bc2-d94307cbbbe3}\ItemData</td><td>*winpcap*</td></tr> <tr><td>Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Paths\{35d7e903-99a3-4574-9bc2-d94307cbbbe3}\LastModified</td><td>128697769616321078</td></tr> <tr><td>Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Paths\{35d7e903-99a3-4574-9bc2-d94307cbbbe3}\SaferFlags</td><td>0</td></tr> <tr><td>Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Paths\{37836df4-133f-471b-b2a2-1e25a05fa756}\Description</td><td>tool which sniffs Kerberos passwords from network traffic</td></tr> <tr><td>Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Paths\{37836df4-133f-471b-b2a2-1e25a05fa756}\ItemData</td><td>kerbsniff.exe</td></tr> <tr><td>Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Paths\{37836df4-133f-471b-b2a2-1e25a05fa756}\LastModified</td><td>128697771402792106</td></tr> <tr><td>Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Paths\{37836df4-133f-471b-b2a2-1e25a05fa756}\SaferFlags</td><td>0</td></tr> <tr><td>Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Paths\{3ae509aa-ef33-4da2-a17e-473382d9b73f}\Description</td><td>tool which dumps password hashes for cracking</td></tr> <tr><td>Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Paths\{3ae509aa-ef33-4da2-a17e-473382d9b73f}\ItemData</td><td>pwdump.exe</td></tr> <tr><td>Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Paths\{3ae509aa-ef33-4da2-a17e-473382d9b73f}\LastModified</td><td>128697774417637738</td></tr> <tr><td>Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Paths\{3ae509aa-ef33-4da2-a17e-473382d9b73f}\SaferFlags</td><td>0</td></tr> <tr><td>Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Paths\{4a40a440-56a8-4007-a415-bc8cfe388b6c}\Description</td><td>tool which cracks passwords dumped with pwdump</td></tr> <tr><td>Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Paths\{4a40a440-56a8-4007-a415-bc8cfe388b6c}\ItemData</td><td>ntcrack.exe</td></tr> <tr><td>Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Paths\{4a40a440-56a8-4007-a415-bc8cfe388b6c}\LastModified</td><td>128697773560494126</td></tr> <tr><td>Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Paths\{4a40a440-56a8-4007-a415-bc8cfe388b6c}\SaferFlags</td><td>0</td></tr> <tr><td>Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Paths\{548203d1-07cc-4e0b-a2ab-31ae511ec60c}\Description</td><td>rainbow table password cracking tool</td></tr> <tr><td>Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Paths\{548203d1-07cc-4e0b-a2ab-31ae511ec60c}\ItemData</td><td>rcrack.exe</td></tr> <tr><td>Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Paths\{548203d1-07cc-4e0b-a2ab-31ae511ec60c}\LastModified</td><td>128808423627115793</td></tr> <tr><td>Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Paths\{548203d1-07cc-4e0b-a2ab-31ae511ec60c}\SaferFlags</td><td>0</td></tr> <tr><td>Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Paths\{548c215d-8346-483d-9176-4d1888718297}\Description</td><td>password cracking service</td></tr> <tr><td>Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Paths\{548c215d-8346-483d-9176-4d1888718297}\ItemData</td><td>pwservice.exe</td></tr> <tr><td>Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Paths\{548c215d-8346-483d-9176-4d1888718297}\LastModified</td><td>128697803396466446</td></tr> <tr><td>Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Paths\{548c215d-8346-483d-9176-4d1888718297}\SaferFlags</td><td>0</td></tr> <tr><td>Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Paths\{54946b01-62fa-4a9a-bdd8-3b305dcadc26}\Description</td><td></td></tr> <tr><td>Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Paths\{54946b01-62fa-4a9a-bdd8-3b305dcadc26}\ItemData</td><td>mspass.exe</td></tr> <tr><td>Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Paths\{54946b01-62fa-4a9a-bdd8-3b305dcadc26}\LastModified</td><td>128808419210072456</td></tr> <tr><td>Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Paths\{54946b01-62fa-4a9a-bdd8-3b305dcadc26}\SaferFlags</td><td>0</td></tr> <tr><td>Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Paths\{5894933e-c50c-4666-8b90-04915e29ebf8}\Description</td><td>password cracking program</td></tr> <tr><td>Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Paths\{5894933e-c50c-4666-8b90-04915e29ebf8}\ItemData</td><td>john-386.exe</td></tr> <tr><td>Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Paths\{5894933e-c50c-4666-8b90-04915e29ebf8}\LastModified</td><td>128697770919379358</td></tr> <tr><td>Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Paths\{5894933e-c50c-4666-8b90-04915e29ebf8}\SaferFlags</td><td>0</td></tr> <tr><td>Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Paths\{6c7f2fbb-94dc-48a1-b3a6-f75e33524ddc}\Description</td><td>e-mail engine</td></tr> <tr><td>Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Paths\{6c7f2fbb-94dc-48a1-b3a6-f75e33524ddc}\ItemData</td><td>blat.exe</td></tr> <tr><td>Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Paths\{6c7f2fbb-94dc-48a1-b3a6-f75e33524ddc}\LastModified</td><td>128808415490243334</td></tr> <tr><td>Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Paths\{6c7f2fbb-94dc-48a1-b3a6-f75e33524ddc}\SaferFlags</td><td>0</td></tr> <tr><td>Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Paths\{81dc66cd-ffed-48e0-9b31-6cd024353e40}\Description</td><td>graphical tool which is used to hack vulnerable computers</td></tr> <tr><td>Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Paths\{81dc66cd-ffed-48e0-9b31-6cd024353e40}\ItemData</td><td>*metasploit*</td></tr> <tr><td>Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Paths\{81dc66cd-ffed-48e0-9b31-6cd024353e40}\LastModified</td><td>128697767221756186</td></tr> <tr><td>Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Paths\{81dc66cd-ffed-48e0-9b31-6cd024353e40}\SaferFlags</td><td>0</td></tr> <tr><td>Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Paths\{8fd4e63b-4504-44f6-bd58-6dc1168268e1}\Description</td><td>steals wireless passwords</td></tr> <tr><td>Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Paths\{8fd4e63b-4504-44f6-bd58-6dc1168268e1}\ItemData</td><td>wirelesskeyview.exe</td></tr> <tr><td>Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Paths\{8fd4e63b-4504-44f6-bd58-6dc1168268e1}\LastModified</td><td>128808425917070208</td></tr> <tr><td>Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Paths\{8fd4e63b-4504-44f6-bd58-6dc1168268e1}\SaferFlags</td><td>0</td></tr> <tr><td>Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Paths\{91852e58-6127-48e8-bd25-0c0b1aa5f0b9}\Description</td><td>popular  Swiss Army Knife tool for back-dooring machines</td></tr> <tr><td>Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Paths\{91852e58-6127-48e8-bd25-0c0b1aa5f0b9}\ItemData</td><td>nc.exe</td></tr> <tr><td>Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Paths\{91852e58-6127-48e8-bd25-0c0b1aa5f0b9}\LastModified</td><td>128697772844280798</td></tr> <tr><td>Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Paths\{91852e58-6127-48e8-bd25-0c0b1aa5f0b9}\SaferFlags</td><td>0</td></tr> <tr><td>Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Paths\{9bea879e-3230-41f5-ab4f-c3d31630b811}\Description</td><td>password cracking tool ****had to use wildcard because the underscore was preventing this from working</td></tr> <tr><td>Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Paths\{9bea879e-3230-41f5-ab4f-c3d31630b811}\ItemData</td><td>pwd_chnge*</td></tr> <tr><td>Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Paths\{9bea879e-3230-41f5-ab4f-c3d31630b811}\LastModified</td><td>128697774074530306</td></tr> <tr><td>Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Paths\{9bea879e-3230-41f5-ab4f-c3d31630b811}\SaferFlags</td><td>0</td></tr> <tr><td>Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Paths\{9d5f22f8-84f2-4f29-9439-49aca99f6e1a}\Description</td><td>Password Cracker</td></tr> <tr><td>Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Paths\{9d5f22f8-84f2-4f29-9439-49aca99f6e1a}\ItemData</td><td>*ophcrack*</td></tr> <tr><td>Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Paths\{9d5f22f8-84f2-4f29-9439-49aca99f6e1a}\LastModified</td><td>128802215678401305</td></tr> <tr><td>Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Paths\{9d5f22f8-84f2-4f29-9439-49aca99f6e1a}\SaferFlags</td><td>0</td></tr> <tr><td>Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Paths\{a36a31e0-721a-4716-be08-1bf3b5e1e1fa}\Description</td><td>hack tool that is used to gather Windows password hashes from computers</td></tr> <tr><td>Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Paths\{a36a31e0-721a-4716-be08-1bf3b5e1e1fa}\ItemData</td><td>lsadump*</td></tr> <tr><td>Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Paths\{a36a31e0-721a-4716-be08-1bf3b5e1e1fa}\LastModified</td><td>128697772618667350</td></tr> <tr><td>Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Paths\{a36a31e0-721a-4716-be08-1bf3b5e1e1fa}\SaferFlags</td><td>0</td></tr> <tr><td>Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Paths\{a48e87a0-8e83-4ec8-a297-84bcebcca503}\Description</td><td>firefox password stealer</td></tr> <tr><td>Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Paths\{a48e87a0-8e83-4ec8-a297-84bcebcca503}\ItemData</td><td>firepassword.exe</td></tr> <tr><td>Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Paths\{a48e87a0-8e83-4ec8-a297-84bcebcca503}\LastModified</td><td>128808417479294772</td></tr> <tr><td>Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Paths\{a48e87a0-8e83-4ec8-a297-84bcebcca503}\SaferFlags</td><td>0</td></tr> <tr><td>Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Paths\{b8972759-98aa-406f-ac36-c3fc9d410772}\Description</td><td>tool which sniffs passwords from network traffic</td></tr> <tr><td>Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Paths\{b8972759-98aa-406f-ac36-c3fc9d410772}\ItemData</td><td>dsniff.exe</td></tr> <tr><td>Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Paths\{b8972759-98aa-406f-ac36-c3fc9d410772}\LastModified</td><td>128697770677360500</td></tr> <tr><td>Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Paths\{b8972759-98aa-406f-ac36-c3fc9d410772}\SaferFlags</td><td>0</td></tr> <tr><td>Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Paths\{b99ca45e-fa73-48fb-834f-7236968435a0}\Description</td><td>popular Windows based password cracking suite</td></tr> <tr><td>Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Paths\{b99ca45e-fa73-48fb-834f-7236968435a0}\ItemData</td><td>l0phtcrack.exe</td></tr> <tr><td>Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Paths\{b99ca45e-fa73-48fb-834f-7236968435a0}\LastModified</td><td>128697771932608728</td></tr> <tr><td>Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Paths\{b99ca45e-fa73-48fb-834f-7236968435a0}\SaferFlags</td><td>0</td></tr> <tr><td>Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Paths\{bf802e3f-57e2-48b3-b302-7c197be192ec}\Description</td><td>tool which cracks Kerberos passwords</td></tr> <tr><td>Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Paths\{bf802e3f-57e2-48b3-b302-7c197be192ec}\ItemData</td><td>kerbcrack.exe</td></tr> <tr><td>Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Paths\{bf802e3f-57e2-48b3-b302-7c197be192ec}\LastModified</td><td>128697771158273376</td></tr> <tr><td>Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Paths\{bf802e3f-57e2-48b3-b302-7c197be192ec}\SaferFlags</td><td>0</td></tr> <tr><td>Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Paths\{c092942c-ad74-4a99-aecc-8f1c28801718}\Description</td><td>anonymize web browsing and publishing, instant messaging, IRC, SSH, and other applications that use the TCP protocol</td></tr> <tr><td>Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Paths\{c092942c-ad74-4a99-aecc-8f1c28801718}\ItemData</td><td>tor.exe</td></tr> <tr><td>Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Paths\{c092942c-ad74-4a99-aecc-8f1c28801718}\LastModified</td><td>128697775038699688</td></tr> <tr><td>Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Paths\{c092942c-ad74-4a99-aecc-8f1c28801718}\SaferFlags</td><td>0</td></tr> <tr><td>Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Paths\{c35c9a36-ebf3-4509-83a4-60e26cf5195d}\Description</td><td></td></tr> <tr><td>Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Paths\{c35c9a36-ebf3-4509-83a4-60e26cf5195d}\ItemData</td><td>netpass.exe</td></tr> <tr><td>Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Paths\{c35c9a36-ebf3-4509-83a4-60e26cf5195d}\LastModified</td><td>128808419995511986</td></tr> <tr><td>Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Paths\{c35c9a36-ebf3-4509-83a4-60e26cf5195d}\SaferFlags</td><td>0</td></tr> <tr><td>Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Paths\{c4903246-ee4c-4b89-9559-6043b0b2396d}\Description</td><td>anonymize web browsing and publishing, instant messaging, IRC, SSH, and other applications that use the TCP protocol</td></tr> <tr><td>Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Paths\{c4903246-ee4c-4b89-9559-6043b0b2396d}\ItemData</td><td>vidalia.exe</td></tr> <tr><td>Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Paths\{c4903246-ee4c-4b89-9559-6043b0b2396d}\LastModified</td><td>128697795828416450</td></tr> <tr><td>Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Paths\{c4903246-ee4c-4b89-9559-6043b0b2396d}\SaferFlags</td><td>0</td></tr> <tr><td>Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Paths\{d5972308-edf3-4a1d-b875-93434424a3b0}\Description</td><td>tool which puts a network card into promiscuous sniffing mode</td></tr> <tr><td>Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Paths\{d5972308-edf3-4a1d-b875-93434424a3b0}\ItemData</td><td>npf_mgm.exe</td></tr> <tr><td>Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Paths\{d5972308-edf3-4a1d-b875-93434424a3b0}\LastModified</td><td>128697773357535768</td></tr> <tr><td>Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Paths\{d5972308-edf3-4a1d-b875-93434424a3b0}\SaferFlags</td><td>0</td></tr> <tr><td>Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Paths\{d9fa62d3-eaea-4e8a-917c-3c4d1ef6d7f2}\Description</td><td>This is one piece of the cain and abel program</td></tr> <tr><td>Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Paths\{d9fa62d3-eaea-4e8a-917c-3c4d1ef6d7f2}\ItemData</td><td>cain.exe</td></tr> <tr><td>Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Paths\{d9fa62d3-eaea-4e8a-917c-3c4d1ef6d7f2}\LastModified</td><td>128697770410186680</td></tr> <tr><td>Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Paths\{d9fa62d3-eaea-4e8a-917c-3c4d1ef6d7f2}\SaferFlags</td><td>0</td></tr> <tr><td>Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Paths\{da0e8a8b-13a1-4bfb-b903-d6649b218f78}\Description</td><td>tool which puts a network card into promiscuous sniffing mode</td></tr> <tr><td>Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Paths\{da0e8a8b-13a1-4bfb-b903-d6649b218f78}\ItemData</td><td>wpcap*</td></tr> <tr><td>Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Paths\{da0e8a8b-13a1-4bfb-b903-d6649b218f78}\LastModified</td><td>128697796586658876</td></tr> <tr><td>Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Paths\{da0e8a8b-13a1-4bfb-b903-d6649b218f78}\SaferFlags</td><td>0</td></tr> <tr><td>Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Paths\{e40efda1-9130-4862-a33e-d6b8f0758a03}\Description</td><td>tool which dumps network traffic to a file </td></tr> <tr><td>Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Paths\{e40efda1-9130-4862-a33e-d6b8f0758a03}\ItemData</td><td>windump.exe</td></tr> <tr><td>Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Paths\{e40efda1-9130-4862-a33e-d6b8f0758a03}\LastModified</td><td>128697796118714086</td></tr> <tr><td>Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Paths\{e40efda1-9130-4862-a33e-d6b8f0758a03}\SaferFlags</td><td>0</td></tr> <tr><td>Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Paths\{ebcdc76c-dbc3-48ef-8dfa-61ae7b4151b7}\Description</td><td>freely available tool for creating custom packets</td></tr> <tr><td>Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Paths\{ebcdc76c-dbc3-48ef-8dfa-61ae7b4151b7}\ItemData</td><td>nemesis.exe</td></tr> <tr><td>Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Paths\{ebcdc76c-dbc3-48ef-8dfa-61ae7b4151b7}\LastModified</td><td>128697773104736212</td></tr> <tr><td>Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Paths\{ebcdc76c-dbc3-48ef-8dfa-61ae7b4151b7}\SaferFlags</td><td>0</td></tr> <tr><td>Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Paths\{ed8199d9-0df2-44ad-ad6b-68723a6c33dd}\Description</td><td>this is a generic term which catches popular key loggers</td></tr> <tr><td>Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Paths\{ed8199d9-0df2-44ad-ad6b-68723a6c33dd}\ItemData</td><td>keylog*</td></tr> <tr><td>Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Paths\{ed8199d9-0df2-44ad-ad6b-68723a6c33dd}\LastModified</td><td>128697771695277130</td></tr> <tr><td>Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Paths\{ed8199d9-0df2-44ad-ad6b-68723a6c33dd}\SaferFlags</td><td>0</td></tr> <tr><td>Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Paths\{ef063e3d-16d3-4fa3-9627-084e04ae866f}\Description</td><td>password cracking program</td></tr> <tr><td>Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Paths\{ef063e3d-16d3-4fa3-9627-084e04ae866f}\ItemData</td><td>lcp.exe</td></tr> <tr><td>Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Paths\{ef063e3d-16d3-4fa3-9627-084e04ae866f}\LastModified</td><td>128697772389460336</td></tr> <tr><td>Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Paths\{ef063e3d-16d3-4fa3-9627-084e04ae866f}\SaferFlags</td><td>0</td></tr> <tr><td>Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Paths\{fa595500-7094-4f7f-9cc5-b1edca00427b}\Description</td><td></td></tr> <tr><td>Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Paths\{fa595500-7094-4f7f-9cc5-b1edca00427b}\ItemData</td><td>iepv.exe</td></tr> <tr><td>Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Paths\{fa595500-7094-4f7f-9cc5-b1edca00427b}\LastModified</td><td>128808418329849269</td></tr> <tr><td>Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\0\Paths\{fa595500-7094-4f7f-9cc5-b1edca00427b}\SaferFlags</td><td>0</td></tr> <tr><td>Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\262144\Paths\{191cd7fa-f240-4a17-8986-94d480a6c8ca}\Description</td><td></td></tr> <tr><td>Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\262144\Paths\{191cd7fa-f240-4a17-8986-94d480a6c8ca}\ItemData</td><td>%HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot%</td></tr> <tr><td>Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\262144\Paths\{191cd7fa-f240-4a17-8986-94d480a6c8ca}\LastModified</td><td>128697766492887256</td></tr> <tr><td>Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\262144\Paths\{191cd7fa-f240-4a17-8986-94d480a6c8ca}\SaferFlags</td><td>0</td></tr> <tr><td>Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\262144\Paths\{7272edfb-af9f-4ddf-b65b-e4282f2deefc}\Description</td><td></td></tr> <tr><td>Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\262144\Paths\{7272edfb-af9f-4ddf-b65b-e4282f2deefc}\ItemData</td><td>%HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot%*.exe</td></tr> <tr><td>Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\262144\Paths\{7272edfb-af9f-4ddf-b65b-e4282f2deefc}\LastModified</td><td>128697766492887256</td></tr> <tr><td>Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\262144\Paths\{7272edfb-af9f-4ddf-b65b-e4282f2deefc}\SaferFlags</td><td>0</td></tr> <tr><td>Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\262144\Paths\{8868b733-4b3a-48f8-9136-aa6d05d4fc83}\Description</td><td></td></tr> <tr><td>Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\262144\Paths\{8868b733-4b3a-48f8-9136-aa6d05d4fc83}\ItemData</td><td>%HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot%System32\*.exe</td></tr> <tr><td>Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\262144\Paths\{8868b733-4b3a-48f8-9136-aa6d05d4fc83}\LastModified</td><td>128697766492887256</td></tr> <tr><td>Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\262144\Paths\{8868b733-4b3a-48f8-9136-aa6d05d4fc83}\SaferFlags</td><td>0</td></tr> <tr><td>Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\262144\Paths\{d2c34ab2-529a-46b2-b293-fc853fce72ea}\Description</td><td></td></tr> <tr><td>Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\262144\Paths\{d2c34ab2-529a-46b2-b293-fc853fce72ea}\ItemData</td><td>%HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ProgramFilesDir%</td></tr> <tr><td>Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\262144\Paths\{d2c34ab2-529a-46b2-b293-fc853fce72ea}\LastModified</td><td>128697766492887256</td></tr> <tr><td>Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\262144\Paths\{d2c34ab2-529a-46b2-b293-fc853fce72ea}\SaferFlags</td><td>0</td></tr> <tr><td>Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\DefaultLevel</td><td>262144</td></tr> <tr><td>Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\ExecutableTypes</td><td>ADE<br/>ADP<br/>BAS<br/>BAT<br/>CHM<br/>CMD<br/>COM<br/>CPL<br/>CRT<br/>EXE<br/>HLP<br/>HTA<br/>INF<br/>INS<br/>ISP<br/>LNK<br/>MDB<br/>MDE<br/>MSC<br/>MSI<br/>MSP<br/>MST<br/>OCX<br/>PCD<br/>PIF<br/>REG<br/>SCR<br/>SHS<br/>URL<br/>VB<br/>WSC</td></tr> <tr><td>Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\PolicyScope</td><td>0</td></tr> <tr><td>Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers\TransparentEnabled</td><td>1</td></tr> </table> </div></div></div></div></div> </body></html>