ALOT Toolbar
Threat Scorecard
EnigmaSoft Threat Scorecard
EnigmaSoft Threat Scorecards are assessment reports for different malware threats which have been collected and analyzed by our research team. EnigmaSoft Threat Scorecards evaluate and rank threats using several metrics including real-world and potential risk factors, trends, frequency, prevalence, and persistence. EnigmaSoft Threat Scorecards are updated regularly based on our research data and metrics and are useful for a wide range of computer users, from end users seeking solutions to remove malware from their systems to security experts analyzing threats.
EnigmaSoft Threat Scorecards display a variety of useful information, including:
Popularity Rank: The ranking of a particular threat in EnigmaSoft’s Threat Database.
Severity Level: The determined severity level of an object, represented numerically, based on our risk modeling process and research, as explained in our Threat Assessment Criteria.
Infected Computers: The number of confirmed and suspected cases of a particular threat detected on infected computers as reported by SpyHunter.
See also Threat Assessment Criteria.
| Popularity Rank: | 10,931 |
| Threat Level: | 10 % (Normal) |
| Infected Computers: | 4,396 |
| First Seen: | July 24, 2009 |
| Last Seen: | February 2, 2026 |
| OS(es) Affected: | Windows |

ALOT Toolbar Image
ALOT Toolbar is a malevolent Trojan that embeds itself into your web browser as a Browser Helper Object (BHO). Once executed, ALOT Toolbar will create a search bar in Internet Explorer and redirect your browser to dangerous websites that promote and sell bogus anti-spyware programs. ALOT Toolbar will also attack your desktop with large amounts of extremely intrusive pop-up commercials. Immediate removal of ALOT Toolbar is strongly recommended, since it may not only interfere with your work flow, but also conduce to violation of your privacy and security.
ALOT Toolbar was created by a company that markets it as a search engine toolbar. Web search results are apt to being hijacked where the user may be lead to other unwanted and potential malicious sites.
ALOT Toolbar is also known to change web browser settings where the default homepage is modified. ALOT Toolbar ultimately limits users from utilizing certain web browsers as they normally would and it is recommended to be removed.![]()
![]()
Table of Contents
Aliases
1 security vendors flagged this file as malicious.
| Antivirus Vendor | Detection |
|---|---|
| Sophos | Alot Toolbar |
SpyHunter Detects & Remove ALOT Toolbar
File System Details
| # | File Name | MD5 |
Detections
Detections: The number of confirmed and suspected cases of a particular threat detected on
infected computers as reported by SpyHunter.
|
|---|---|---|---|
| 1. | alot.dll | 0cbd99c9d64cbd7b5b6d7c67e4a9ebbd | 230 |
| 2. | alotBHO.dll | 46722e2becff3bd427bbb7ee7852b234 | 26 |
| 3. | alotUninst.exe | c9a76e41c7ba9e0f62f9f3f42d84c597 | 0 |
Registry Details
Directories
ALOT Toolbar may create the following directory or directories:
| %ProgramFiles%\alot |
| %ProgramFiles%\alotappbar |
| %UserProfile%\AppData\LocalLow\alotappbar |
| %UserProfile%\AppData\LocalLow\alotservice |
Analysis Report
General information
| Family Name: | ALOT Toolbar |
|---|---|
| Signature status: | Self Signed |
Known Samples
Known Samples
This section lists other file samples believed to be associated with this family.|
MD5:
4bddf9ff9323512b8765ba612d790e85
SHA1:
c4d55686ae541659d1c19519c7d8807c3e6b17a6
File Size:
1.15 MB, 1151992 bytes
|
|
MD5:
c79d51a1b0262d657f28da1b79792e1d
SHA1:
0dd3d6685e0bb9e33fa9db2ee6de2d24bdd7b5d4
File Size:
917.90 KB, 917896 bytes
|
|
MD5:
f7978c563582492d78b308314daffe36
SHA1:
793571dd7a0ad4dfffeec28aaf6a443c511dcdad
SHA256:
38075FE1A7ECE53F11D0D787F9A6AEB3698DD829CF094CD59114D9537D0EAEE7
File Size:
1.15 MB, 1148176 bytes
|
|
MD5:
4453952f567224cd2743133a9c07c494
SHA1:
160c106b020fbeddbcf2c8cadf77111d2a43f63c
SHA256:
6C2000C4B486C81C9B5DA3109C4264CBB20AD09048881795F3A58CEA029EAEFE
File Size:
1.18 MB, 1175712 bytes
|
|
MD5:
fecd929dfba342ab91ba2ffd03463f9a
SHA1:
d43d62643b6763e01ff24943622802ec5aa45643
SHA256:
CF2C275AB55A75AB0BB5220444119672D4CA30498C0E0A385E332EC3417C5FAF
File Size:
702.19 KB, 702192 bytes
|
Show More
|
MD5:
19c162554933433e8304d38e7c30bed5
SHA1:
a254423cf63b6aa17fa12da86d219e75514bee9a
SHA256:
E58B0C637F81ACD276F8080844B342CC7FFD046912141BA8926B5D62154F24ED
File Size:
697.63 KB, 697632 bytes
|
|
MD5:
989b28b827f417b7f4a4d0c9311d040f
SHA1:
403fbd1a48b4d9d7f8b1739cbaec8ccfa33dd989
SHA256:
9D4FEEAED82DE7916FE3F74F1A85285CBDBEEAA0A8F8AA3D4B0A6B145F10B754
File Size:
703.51 KB, 703512 bytes
|
|
MD5:
c085de2e1689e456eb79a4944e16d91a
SHA1:
538f29d675a2cfb912991a4f827b384e1b7678b0
SHA256:
145AE9121F18ED45ACA1C9A8263D16FD1175E877CD98552348D4C5E92BBF77BD
File Size:
695.37 KB, 695368 bytes
|
|
MD5:
cc516531ca6db6637148c2823fa1cf5e
SHA1:
ecba1aac4837173e522b7fbe6061f9f39f33810a
SHA256:
7C7D50485735ED3AB383ED8586930B8CE216DFFF1C9D8DA5EECF7A8966F93F12
File Size:
1.19 MB, 1194576 bytes
|
|
MD5:
174644f4d122ce810d1047547a6bd984
SHA1:
62c7d240bb4f4518dca547cfe21630baf895dc80
SHA256:
A7AA4650D60995DDA18B42035BCFF2F7B0CB57C3AD885CC5A6B88320B38B8663
File Size:
536.60 KB, 536604 bytes
|
|
MD5:
c37aeaed524eb86a8063ab771eccfc31
SHA1:
ef50c68a7abc45a43010702330113d8c912cc4c9
SHA256:
B6B9516D893DDD3E9F5465668A5DF9413AA6540FE0C129BCF7B24C0041D8311D
File Size:
693.20 KB, 693200 bytes
|
|
MD5:
5ff3dc440da9a6cb5a785479fc6b0c16
SHA1:
0e6017beb2cb3a119cbc03d217753beade5057b1
SHA256:
DDE9AF3ACCECEF2F1FB3DEA5F7562EAA9771E8388197B760EC9F6BA1C874610A
File Size:
565.63 KB, 565635 bytes
|
Windows Portable Executable Attributes
- File doesn't have "Rich" header
- File doesn't have debug information
- File doesn't have exports table
- File doesn't have relocations information
- File doesn't have security information
- File is 32-bit executable
- File is either console or GUI application
- File is GUI application (IMAGE_SUBSYSTEM_WINDOWS_GUI)
- File is Native application (NOT .NET application)
- File is not packed
Show More
- IMAGE_FILE_DLL is not set inside PE header (Executable)
- IMAGE_FILE_EXECUTABLE_IMAGE is set inside PE header (Executable Image)
File Icons
File Icons
This section displays icon resources found within family samples. Malware often replicates icons commonly associated with legitimate software to mislead users into believing the malware is safe.Windows PE Version Information
Windows PE Version Information
This section displays values and attributes that have been set in the Windows file version information data structure for samples within this family. To mislead users, malware actors often add fake version information mimicking legitimate software.| Name | Value |
|---|---|
| Company Name |
|
| File Description |
|
| File Version |
|
| Legal Copyright |
|
| Product Name |
|
Digital Signatures
Digital Signatures
This section lists digital signatures that are attached to samples within this family. When analyzing and verifying digital signatures, it is important to confirm that the signature’s root authority is a well-known and trustworthy entity and that the status of the signature is good. Malware is often signed with non-trustworthy “Self Signed” digital signatures (which can be easily created by a malware author with no verification). Malware may also be signed by legitimate signatures that have an invalid status, and by signatures from questionable root authorities with fake or misleading “Signer” names.| Signer | Root | Status |
|---|---|---|
| Alot.com | VeriSign Class 3 Code Signing 2004 CA | Self Signed |
| Alot.com | VeriSign Class 3 Code Signing 2009-2 CA | Root Not Trusted |
| Alot.com | VeriSign Class 3 Code Signing 2009-2 CA | Self Signed |
Files Modified
Files Modified
This section lists files that were created, modified, moved and/or deleted by samples in this family. File system activity can provide valuable insight into how malware functions on the operating system.| File | Attributes |
|---|---|
| c:\installhelper.log | Generic Write,Read Attributes |
| c:\users\user\appdata\local\temp\nsa4a64.tmp | Generic Read,Write Data,Write Attributes,Write extended,Append data,Delete |
| c:\users\user\appdata\local\temp\nscdb30.tmp | Generic Read,Write Data,Write Attributes,Write extended,Append data,Delete |
| c:\users\user\appdata\local\temp\nsi9169.tmp\closeie.ini | Generic Read,Write Data,Write Attributes,Write extended,Append data |
| c:\users\user\appdata\local\temp\nsi9169.tmp\closeie.ini | Generic Write,Read Attributes |
| c:\users\user\appdata\local\temp\nsi9169.tmp\eula.html | Generic Write,Read Attributes |
| c:\users\user\appdata\local\temp\nsi9169.tmp\eula.ini | Generic Read,Write Data,Write Attributes,Write extended,Append data |
| c:\users\user\appdata\local\temp\nsi9169.tmp\eula.ini | Generic Write,Read Attributes |
| c:\users\user\appdata\local\temp\nsi9169.tmp\installagent.exe | Generic Write,Read Attributes |
| c:\users\user\appdata\local\temp\nsi9169.tmp\installhelper.dll | Generic Write,Read Attributes |
Show More
| c:\users\user\appdata\local\temp\nsi9169.tmp\installoptions.dll | Generic Write,Read Attributes |
| c:\users\user\appdata\local\temp\nsi9169.tmp\modern-header.bmp | Generic Write,Read Attributes |
| c:\users\user\appdata\local\temp\nsi9169.tmp\offerpage.bmp | Generic Write,Read Attributes |
| c:\users\user\appdata\local\temp\nsi9169.tmp\offerpage.ini | Generic Read,Write Data,Write Attributes,Write extended,Append data |
| c:\users\user\appdata\local\temp\nsi9169.tmp\offerpage.ini | Generic Write,Read Attributes |
| c:\users\user\appdata\local\temp\nsi9169.tmp\system.dll | Generic Write,Read Attributes |
| c:\users\user\appdata\local\temp\nsk4ba9.tmp\closeie.ini | Generic Read,Write Data,Write Attributes,Write extended,Append data |
| c:\users\user\appdata\local\temp\nsk4ba9.tmp\closeie.ini | Generic Write,Read Attributes |
| c:\users\user\appdata\local\temp\nsk4ba9.tmp\eula.ini | Generic Read,Write Data,Write Attributes,Write extended,Append data |
| c:\users\user\appdata\local\temp\nsk4ba9.tmp\eula.ini | Generic Write,Read Attributes |
| c:\users\user\appdata\local\temp\nsk4ba9.tmp\eula_pt-br.html | Generic Write,Read Attributes |
| c:\users\user\appdata\local\temp\nsk4ba9.tmp\installhelper.dll | Generic Write,Read Attributes |
| c:\users\user\appdata\local\temp\nsk4ba9.tmp\installoptions.dll | Generic Write,Read Attributes |
| c:\users\user\appdata\local\temp\nsk4ba9.tmp\modern-header.bmp | Generic Write,Read Attributes |
| c:\users\user\appdata\local\temp\nsk4ba9.tmp\system.dll | Generic Write,Read Attributes |
| c:\users\user\appdata\local\temp\nsl4e87.tmp | Generic Read,Write Data,Write Attributes,Write extended,Append data,Delete |
| c:\users\user\appdata\local\temp\nsld396.tmp\closeie.ini | Generic Read,Write Data,Write Attributes,Write extended,Append data |
| c:\users\user\appdata\local\temp\nsld396.tmp\closeie.ini | Generic Write,Read Attributes |
| c:\users\user\appdata\local\temp\nsld396.tmp\eula.html | Generic Write,Read Attributes |
| c:\users\user\appdata\local\temp\nsld396.tmp\eula.ini | Generic Read,Write Data,Write Attributes,Write extended,Append data |
| c:\users\user\appdata\local\temp\nsld396.tmp\eula.ini | Generic Write,Read Attributes |
| c:\users\user\appdata\local\temp\nsld396.tmp\installagent.exe | Generic Write,Read Attributes |
| c:\users\user\appdata\local\temp\nsld396.tmp\installhelper.dll | Generic Write,Read Attributes |
| c:\users\user\appdata\local\temp\nsld396.tmp\installoptions.dll | Generic Write,Read Attributes |
| c:\users\user\appdata\local\temp\nsld396.tmp\modern-header.bmp | Generic Write,Read Attributes |
| c:\users\user\appdata\local\temp\nsld396.tmp\offerpage.bmp | Generic Write,Read Attributes |
| c:\users\user\appdata\local\temp\nsld396.tmp\offerpage.ini | Generic Read,Write Data,Write Attributes,Write extended,Append data |
| c:\users\user\appdata\local\temp\nsld396.tmp\offerpage.ini | Generic Write,Read Attributes |
| c:\users\user\appdata\local\temp\nsld396.tmp\system.dll | Generic Write,Read Attributes |
| c:\users\user\appdata\local\temp\nsmaa3.tmp\closeie.ini | Generic Read,Write Data,Write Attributes,Write extended,Append data |
| c:\users\user\appdata\local\temp\nsmaa3.tmp\closeie.ini | Generic Write,Read Attributes |
| c:\users\user\appdata\local\temp\nsmaa3.tmp\eula.ini | Generic Read,Write Data,Write Attributes,Write extended,Append data |
| c:\users\user\appdata\local\temp\nsmaa3.tmp\eula.ini | Generic Write,Read Attributes |
| c:\users\user\appdata\local\temp\nsmaa3.tmp\eula_en.html | Generic Write,Read Attributes |
| c:\users\user\appdata\local\temp\nsmaa3.tmp\installhelper.dll | Generic Write,Read Attributes |
| c:\users\user\appdata\local\temp\nsmaa3.tmp\installoptions.dll | Generic Write,Read Attributes |
| c:\users\user\appdata\local\temp\nsmaa3.tmp\modern-header.bmp | Generic Write,Read Attributes |
| c:\users\user\appdata\local\temp\nsmaa3.tmp\system.dll | Generic Write,Read Attributes |
| c:\users\user\appdata\local\temp\nsmbf86.tmp | Generic Read,Write Data,Write Attributes,Write extended,Append data,Delete |
| c:\users\user\appdata\local\temp\nsmbf87.tmp\closeie.ini | Generic Read,Write Data,Write Attributes,Write extended,Append data |
| c:\users\user\appdata\local\temp\nsmbf87.tmp\closeie.ini | Generic Write,Read Attributes |
| c:\users\user\appdata\local\temp\nsmbf87.tmp\eula.ini | Generic Read,Write Data,Write Attributes,Write extended,Append data |
| c:\users\user\appdata\local\temp\nsmbf87.tmp\eula.ini | Generic Write,Read Attributes |
| c:\users\user\appdata\local\temp\nsmbf87.tmp\eula_en.html | Generic Write,Read Attributes |
| c:\users\user\appdata\local\temp\nsmbf87.tmp\installhelper.dll | Generic Write,Read Attributes |
| c:\users\user\appdata\local\temp\nsmbf87.tmp\installoptions.dll | Generic Write,Read Attributes |
| c:\users\user\appdata\local\temp\nsmbf87.tmp\modern-header.bmp | Generic Write,Read Attributes |
| c:\users\user\appdata\local\temp\nsmbf87.tmp\system.dll | Generic Write,Read Attributes |
| c:\users\user\appdata\local\temp\nsn9139.tmp | Generic Read,Write Data,Write Attributes,Write extended,Append data,Delete |
| c:\users\user\appdata\local\temp\nsp3c89.tmp | Generic Read,Write Data,Write Attributes,Write extended,Append data,Delete |
| c:\users\user\appdata\local\temp\nsp3c99.tmp\closeie.ini | Generic Read,Write Data,Write Attributes,Write extended,Append data |
| c:\users\user\appdata\local\temp\nsp3c99.tmp\closeie.ini | Generic Write,Read Attributes |
| c:\users\user\appdata\local\temp\nsp3c99.tmp\eula.ini | Generic Read,Write Data,Write Attributes,Write extended,Append data |
| c:\users\user\appdata\local\temp\nsp3c99.tmp\eula.ini | Generic Write,Read Attributes |
| c:\users\user\appdata\local\temp\nsp3c99.tmp\eula_fr.html | Generic Write,Read Attributes |
| c:\users\user\appdata\local\temp\nsp3c99.tmp\installhelper.dll | Generic Write,Read Attributes |
| c:\users\user\appdata\local\temp\nsp3c99.tmp\installoptions.dll | Generic Write,Read Attributes |
| c:\users\user\appdata\local\temp\nsp3c99.tmp\modern-header.bmp | Generic Write,Read Attributes |
| c:\users\user\appdata\local\temp\nsp3c99.tmp\system.dll | Generic Write,Read Attributes |
| c:\users\user\appdata\local\temp\nsp4ac1.tmp | Generic Read,Write Data,Write Attributes,Write extended,Append data,Delete |
| c:\users\user\appdata\local\temp\nsp4ac2.tmp\closeie.ini | Generic Read,Write Data,Write Attributes,Write extended,Append data |
| c:\users\user\appdata\local\temp\nsp4ac2.tmp\closeie.ini | Generic Write,Read Attributes |
| c:\users\user\appdata\local\temp\nsp4ac2.tmp\eula.ini | Generic Read,Write Data,Write Attributes,Write extended,Append data |
| c:\users\user\appdata\local\temp\nsp4ac2.tmp\eula.ini | Generic Write,Read Attributes |
| c:\users\user\appdata\local\temp\nsp4ac2.tmp\eula_pt-br.html | Generic Write,Read Attributes |
| c:\users\user\appdata\local\temp\nsp4ac2.tmp\installhelper.dll | Generic Write,Read Attributes |
| c:\users\user\appdata\local\temp\nsp4ac2.tmp\installoptions.dll | Generic Write,Read Attributes |
| c:\users\user\appdata\local\temp\nsp4ac2.tmp\modern-header.bmp | Generic Write,Read Attributes |
| c:\users\user\appdata\local\temp\nsp4ac2.tmp\system.dll | Generic Write,Read Attributes |
| c:\users\user\appdata\local\temp\nsqd366.tmp | Generic Read,Write Data,Write Attributes,Write extended,Append data,Delete |
| c:\users\user\appdata\local\temp\nsr4ea8.tmp\closeie.ini | Generic Read,Write Data,Write Attributes,Write extended,Append data |
| c:\users\user\appdata\local\temp\nsr4ea8.tmp\closeie.ini | Generic Write,Read Attributes |
| c:\users\user\appdata\local\temp\nsr4ea8.tmp\eula.html | Generic Write,Read Attributes |
| c:\users\user\appdata\local\temp\nsr4ea8.tmp\eula.ini | Generic Read,Write Data,Write Attributes,Write extended,Append data |
| c:\users\user\appdata\local\temp\nsr4ea8.tmp\eula.ini | Generic Write,Read Attributes |
| c:\users\user\appdata\local\temp\nsr4ea8.tmp\installagent.exe | Generic Write,Read Attributes |
| c:\users\user\appdata\local\temp\nsr4ea8.tmp\installhelper.dll | Generic Write,Read Attributes |
| c:\users\user\appdata\local\temp\nsr4ea8.tmp\installoptions.dll | Generic Write,Read Attributes |
| c:\users\user\appdata\local\temp\nsr4ea8.tmp\modern-header.bmp | Generic Write,Read Attributes |
| c:\users\user\appdata\local\temp\nsr4ea8.tmp\system.dll | Generic Write,Read Attributes |
| c:\users\user\appdata\local\temp\nsrdb40.tmp\closeie.ini | Generic Read,Write Data,Write Attributes,Write extended,Append data |
| c:\users\user\appdata\local\temp\nsrdb40.tmp\closeie.ini | Generic Write,Read Attributes |
| c:\users\user\appdata\local\temp\nsrdb40.tmp\eula.html | Generic Write,Read Attributes |
| c:\users\user\appdata\local\temp\nsrdb40.tmp\eula.ini | Generic Read,Write Data,Write Attributes,Write extended,Append data |
| c:\users\user\appdata\local\temp\nsrdb40.tmp\eula.ini | Generic Write,Read Attributes |
| c:\users\user\appdata\local\temp\nsrdb40.tmp\installhelper.dll | Generic Write,Read Attributes |
| c:\users\user\appdata\local\temp\nsrdb40.tmp\installoptions.dll | Generic Write,Read Attributes |
| c:\users\user\appdata\local\temp\nsrdb40.tmp\modern-header.bmp | Generic Write,Read Attributes |
| c:\users\user\appdata\local\temp\nsrdb40.tmp\system.dll | Generic Write,Read Attributes |
| c:\users\user\appdata\local\temp\nsu4b98.tmp | Generic Read,Write Data,Write Attributes,Write extended,Append data,Delete |
| c:\users\user\appdata\local\temp\nsv4a94.tmp\closeie.ini | Generic Read,Write Data,Write Attributes,Write extended,Append data |
| c:\users\user\appdata\local\temp\nsv4a94.tmp\closeie.ini | Generic Write,Read Attributes |
| c:\users\user\appdata\local\temp\nsv4a94.tmp\eula.html | Generic Write,Read Attributes |
| c:\users\user\appdata\local\temp\nsv4a94.tmp\eula.ini | Generic Read,Write Data,Write Attributes,Write extended,Append data |
| c:\users\user\appdata\local\temp\nsv4a94.tmp\eula.ini | Generic Write,Read Attributes |
| c:\users\user\appdata\local\temp\nsv4a94.tmp\installagent.exe | Generic Write,Read Attributes |
| c:\users\user\appdata\local\temp\nsv4a94.tmp\installhelper.dll | Generic Write,Read Attributes |
| c:\users\user\appdata\local\temp\nsv4a94.tmp\installoptions.dll | Generic Write,Read Attributes |
| c:\users\user\appdata\local\temp\nsv4a94.tmp\modern-header.bmp | Generic Write,Read Attributes |
| c:\users\user\appdata\local\temp\nsv4a94.tmp\system.dll | Generic Write,Read Attributes |
| c:\users\user\appdata\local\temp\nswa92.tmp | Generic Read,Write Data,Write Attributes,Write extended,Append data,Delete |
Registry Modifications
Registry Modifications
This section lists registry keys and values that were created, modified and/or deleted by samples in this family. Windows Registry activity can provide valuable insight into malware functionality. Additionally, malware often creates registry values to allow itself to automatically start and indefinitely persist after an initial infection has compromised the system.| Key::Value | Data | API Name |
|---|---|---|
| HKCU\software\microsoft\windows\currentversion\internet settings\zonemap::proxybypass | RegNtPreCreateKey | |
| HKCU\software\microsoft\windows\currentversion\internet settings\zonemap::intranetname | RegNtPreCreateKey | |
| HKCU\software\microsoft\windows\currentversion\internet settings\zonemap::uncasintranet | RegNtPreCreateKey | |
| HKCU\software\microsoft\windows\currentversion\internet settings\zonemap::autodetect | RegNtPreCreateKey | |
| HKCU\software\microsoft\windows\currentversion\internet settings\zonemap::proxybypass | RegNtPreCreateKey | |
| HKCU\software\microsoft\windows\currentversion\internet settings\zonemap::intranetname | RegNtPreCreateKey | |
| HKCU\software\microsoft\windows\currentversion\internet settings\zonemap::uncasintranet | RegNtPreCreateKey | |
| HKCU\software\microsoft\windows\currentversion\internet settings\zonemap::autodetect | RegNtPreCreateKey | |
| HKCU\software\microsoft\internet explorer\gpu::adapterinfo | vendorId="0x1414",deviceID="0x8c",subSysID="0x0",revision="0x0",version="10.0.19041.3570"hypervisor="Hypervisor detected (Micros | RegNtPreCreateKey |
| HKCU\software\microsoft\windows\currentversion\internet settings\5.0\cache\content::cacheprefix | RegNtPreCreateKey |
Show More
| HKCU\software\microsoft\windows\currentversion\internet settings\5.0\cache\cookies::cacheprefix | Cookie: | RegNtPreCreateKey |
| HKCU\software\microsoft\windows\currentversion\internet settings\5.0\cache\history::cacheprefix | Visited: | RegNtPreCreateKey |
| HKLM\software\microsoft\windows nt\currentversion\notifications\data::418a073aa3bc1c75 | RegNtPreCreateKey |