SearchRover Adware Profile
Title: SearchRover
Also Known as: Adware-Toolbar.SearchRover, SearchRover Toolbar
Severity scale:
SearchRover is an adware program disguised as a toolbar add-on for your browser. It was first discovered on May 10 of 2006. It is distributed by MivaDirect, and is powered by the web server, http://www.searchrover.net/. This website is currently shut down, but it is not indicative of MivaDirect going out of business or the removal of the SearchRover threat.
SearchRover is installed on your computer manually or as part of a freeware bundle supported by advertisements. While it doesn’t have spyware capabilities, it hijacks your browser. It resets your home page to its website at http://www.searchrover.net/ and redirects all your searches to its website. It also displays pop-up advertising.
The activity of SearchRover can seriously slow down your computer’s performance. It can also potentially cause your Internet browser to crash. Any supposed benefits it offers are not worth compromising the functionality of your computer.
If you are infected with this program, you should remove it immediately with SpyZooka. While there are other means to remove SearchRover, SpyZooka has proven to consistently and completely remove this threat from your computer.
Also Known As:
Adware-Toolbar.SearchRover,
SearchRover Toolbar,
ToolBar.SearchRover,
Adw.SearchRover,
Search Rover,
Adware.Win32.SearchRover
Adware Type: Toolbar, Browser Hijacker
Associated Files:
C:\Program Files\Search Rover\brand.bmp
C:\Program Files\Search Rover\SearchRoverConfig.xml
C:\Program Files\Search Rover\SearchRoverUninstall.exe
C:\Program Files\Search Rover\bin\SearchRover.dll
C:\Program Files\Search Rover\icons\star_16.ico
%allusersprofile%\application data\search rover\buttons\blocker.cur
%allusersprofile%\application data\search rover\buttons\buddyicons.bmp
%allusersprofile%\application data\search rover\buttons\logo.bmp
%allusersprofile%\application data\search rover\buttons\logoxp.bmp
%allusersprofile%\application data\search rover\buttons\newsreadericon.bmp
%allusersprofile%\application data\search rover\buttons\newsreadericon_over.bmp
%allusersprofile%\application data\search rover\buttons\newsreadericonxp.png
%allusersprofile%\application data\search rover\buttons\newsreadericonxp_over.png
%allusersprofile%\application data\search rover\buttons\newssearchicon.bmp
%allusersprofile%\application data\search rover\buttons\newssearchicon_over.bmp
%allusersprofile%\application data\search rover\buttons\newssearchiconxp.png
%allusersprofile%\application data\search rover\buttons\newssearchiconxp_over.png
%allusersprofile%\application data\search rover\buttons\popupblocker.bmp
%allusersprofile%\application data\search rover\buttons\popupblockerhot.bmp
%allusersprofile%\application data\search rover\buttons\popupblockerhotxp.png
%allusersprofile%\application data\search rover\buttons\popupblockerxp.png
%allusersprofile%\application data\search rover\buttons\smiley.bmp
%allusersprofile%\application data\search rover\buttons\smileyxp.png
%allusersprofile%\application data\search rover\contexts\error.xml
%allusersprofile%\application data\search rover\contexts\related.xml
%allusersprofile%\application data\search rover\contexts\travel.xml
%allusersprofile%\application data\search rover\news\all_feeds_summary.xsl
%allusersprofile%\application data\search rover\news\atom_0_3_to_rss_2_0.xsl
%allusersprofile%\application data\search rover\news\date_time.xsl
%allusersprofile%\application data\search rover\news\get_feed_format.xsl
%allusersprofile%\application data\search rover\news\rss_1_0_to_rss_2_0.xsl
%allusersprofile%\application data\search rover\news\w3cdtf_to_rfc822.xsl
%allusersprofile%\application data\search rover\simpleupdate\productmessagingconfig.xml
%allusersprofile%\application data\search rover\simpleupdate\productmessagingconfig.xml.backup
%allusersprofile%\application data\search rover\simpleupdate\simpleupdateconfig.xml
%allusersprofile%\application data\search rover\simpleupdate\simpleupdateconfig.xml.backup
%allusersprofile%\application data\search rover\simpleupdate\timermanagerconfig.xml
%allusersprofile%\application data\searchrover\simpleupdate\timermanagerconfig.xml.backup
%homepath%\desktop\ssearchrover_10000.exe
%programfiles%\search rover\bin\searchrover.dll
%programfiles%\search rover\brand.bmp
%programfiles%\search rover\icons\star_16.ico
%programfiles%\search rover\searchroverconfig.xml
%programfiles%\search rover\searchroveruninstall.exe
%userprofile%\application data\search rover\browsersearch\browsersearch.xml
%userprofile%\application data\search rover\browsersearch\browsersearch.xml.backup
%userprofile%\application data\search rover\buddyicons\buddyiconsoptions.xml
%userprofile%\application data\search rover\buddyicons\buddyiconsoptions.xml.backup
%userprofile%\application data\search rover\configurator\configuratoroptions.xml
%userprofile%\application data\search rover\configurator\configuratoroptions.xml.backup
%userprofile%\application data\search rover\errorsearch\errorsearchoptions.xml
%userprofile%\application data\search rover\errorsearch\errorsearchoptions.xml.backup
%userprofile%\application data\search rover\layouts\preferenceslayout.xml
%userprofile%\application data\search rover\layouts\preferenceslayout.xml.backup
%userprofile%\application data\search rover\layouts\toolbarlayout.xml
%userprofile%\application data\search rover\layouts\toolbarlayout.xml.backup
%userprofile%\application data\search rover\manager\manageroptions.xml
%userprofile%\application data\search rover\manager\manageroptions.xml.backup
%userprofile%\application data\search rover\news\feeds\feed_0.xml
%userprofile%\application data\search rover\news\feeds\feed_1.xml
%userprofile%\application data\search rover\news\feeds\feed_10.xml
%userprofile%\application data\search rover\news\feeds\feed_11.xml
%userprofile%\application data\search rover\news\feeds\feed_12.xml
%userprofile%\application data\search rover\news\feeds\feed_13.xml
%userprofile%\application data\search rover\news\feeds\feed_14.xml
%userprofile%\application data\search rover\news\feeds\feed_15.xml
%userprofile%\application data\search rover\news\feeds\feed_2.xml
%userprofile%\application data\search rover\news\feeds\feed_3.xml
%userprofile%\application data\search rover\news\feeds\feed_4.xml
%userprofile%\application data\search rover\news\feeds\feed_5.xml
%userprofile%\application data\search rover\news\feeds\feed_6.xml
%userprofile%\application data\search rover\news\feeds\feed_7.xml
%userprofile%\application data\search rover\news\feeds\feed_8.xml
%userprofile%\application data\search rover\news\feeds\feed_9.xml
%userprofile%\application data\search rover\news\newsoptions.xml
%userprofile%\application data\search rover\news\newsoptions.xml.backup
%userprofile%\application data\search rover\newssearch\newssearchoptions.xml
%userprofile%\application data\search rover\newssearch\newssearchoptions.xml.backup
%userprofile%\application data\search rover\popupblocker\popupblockeroptions.xml
%userprofile%\application data\search rover\popupblocker\popupblockeroptions.xml.backup
%userprofile%\application data\search rover\reference\referenceoptions.xml
%userprofile%\application data\search rover\reference\referenceoptions.xml.backup
%userprofile%\application data\search rover\relatedsearch\relatedsearchoptions.xml
%userprofile%\application data\search rover\relatedsearch\relatedsearchoptions.xml.backup
%userprofile%\application data\search rover\screensavers\screensaversoptions.xml
%userprofile%\application data\search rover\screensavers\screensaversoptions.xml.backup
%userprofile%\application data\search rover\searchmatch\searchmatchoptions.xml
%userprofile%\application data\search rover\searchmatch\searchmatchoptions.xml.backup
%userprofile%\application data\search rover\smileytown\smileytownoptions.xml
%userprofile%\application data\search rover\smileytown\smileytownoptions.xml.backup
%userprofile%\application data\search rover\toolbar\tbproductsoptions.xml
%userprofile%\application data\search rover\toolbar\tbproductsoptions.xml.backup
%userprofile%\application data\search rover\toolbarlogo\toolbarlogooptions.xml
%userprofile%\application data\search rover\toolbarlogo\toolbarlogooptions.xml.backup
%userprofile%\application data\search rover\toolbarsearch\toolbarsearchoptions.xml
%userprofile%\application data\search rover\toolbarsearch\toolbarsearchoptions.xml.backup
%userprofile%\application data\search rover\travelsearch\travelsearchoptions.xml
%userprofile%\application data\search rover\travelsearch\travelsearchoptions.xml.backup
%userprofile%\application data\search rover\weather\alertarchive.xml
%userprofile%\application data\search rover\weather\weatheroptions.xml
%userprofile%\application data\search rover\weather\weatheroptions.xml.backup
%windir%\prefetch\ssearchrover_10000.exe-2c742658.pf
%allusersprofile%\application data\search rover\buttons\findit.bmp
%allusersprofile%\application data\search rover\buttons\findithot.bmp
%allusersprofile%\application data\search rover\buttons\findithotxp.png
%allusersprofile%\application data\search rover\buttons\finditxp.png
%allusersprofile%\application data\search rover\buttons\highlight.bmp
%allusersprofile%\application data\search rover\buttons\highlighthot.bmp
%allusersprofile%\application data\search rover\buttons\highlighthotxp.png
%allusersprofile%\application data\search rover\buttons\highlightxp.png
%allusersprofile%\application data\search rover\buttons\reference.bmp
%allusersprofile%\application data\search rover\buttons\referencehot.bmp
%allusersprofile%\application data\search rover\buttons\referencehotxp.png
%allusersprofile%\application data\search rover\buttons\referencexp.png
%allusersprofile%\application data\search rover\buttons\screensaver.bmp
%allusersprofile%\application data\search rover\buttons\weather.bmp
%allusersprofile%\application data\search rover\buttons\weatherhotxp.png
%allusersprofile%\application data\search rover\buttons\weatherxp.png
HKEY_CLASSES_ROOT\CLSID\{0A0DCA4C-F72F-49f9-B7B3-480AE39CA062}
HKEY_CLASSES_ROOT\CLSID\{0A0DCA4C-F72F-49f9-B7B3-480AE39CA062}\InprocServer32
HKEY_CLASSES_ROOT\CLSID\{1D0E3B89-0D7F-488b-B890-CD1104F88EE0}
HKEY_CLASSES_ROOT\CLSID\{1D0E3B89-0D7F-488b-B890-CD1104F88EE0}\Implemented Categories
HKEY_CLASSES_ROOT\CLSID\{1D0E3B89-0D7F-488b-B890-CD1104F88EE0}\Implemented Categories\{00021493-0000-0000-C000-000000000046}
HKEY_CLASSES_ROOT\CLSID\{1D0E3B89-0D7F-488b-B890-CD1104F88EE0}\InprocServer32
HKEY_CLASSES_ROOT\CLSID\{95FA921C-D08D-4a81-8454-11B73D795C3C}
HKEY_CLASSES_ROOT\CLSID\{95FA921C-D08D-4a81-8454-11B73D795C3C}\Implemented Categories
HKEY_CLASSES_ROOT\CLSID\{95FA921C-D08D-4a81-8454-11B73D795C3C}\Implemented Categories\{00021494-0000-0000-C000-000000000046}
HKEY_CLASSES_ROOT\CLSID\{95FA921C-D08D-4a81-8454-11B73D795C3C}\InprocServer32
HKEY_CLASSES_ROOT\CLSID\{FC17BFE4-B5E4-4a7b-A71C-2DF28849C4BE}
HKEY_CLASSES_ROOT\CLSID\{FC17BFE4-B5E4-4a7b-A71C-2DF28849C4BE}\InprocServer32
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{0A0DCA4C-F72F-49F9-B7B3-480AE39CA062}
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{0A0DCA4C-F72F-49F9-B7B3-480AE39CA062}\iexplore
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{FC17BFE4-B5E4-4A7B-A71C-2DF28849C4BE}
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{FC17BFE4-B5E4-4A7B-A71C-2DF28849C4BE}\iexplore
HKEY_CURRENT_USER\Software\Search Rover
HKEY_CURRENT_USER\Software\Search Rover\Options
HKEY_CURRENT_USER\Software\Search Rover\OriginalSearchAssistant
HKEY_CURRENT_USER\Software\Search Rover\OriginalURLSearchHooks
HKEY_CURRENT_USER\Software\Search Rover\SearchAssistant
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{FC17BFE4-B5E4-4a7b-A71C-2DF28849C4BE}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Search Rover
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SecurityProviders\SCHANNEL\Ciphers\RC2 56/128
HKEY_CLASSES_ROOT\CLSID\{0A0DCA4C-F72F-49f9-B7B3-480AE39CA062}\InprocServer32 ThreadingModel = “Apartment”
HKEY_CLASSES_ROOT\CLSID\{1D0E3B89-0D7F-488b-B890-CD1104F88EE0}\InprocServer32 ThreadingModel = “Apartment”
HKEY_CLASSES_ROOT\CLSID\{95FA921C-D08D-4a81-8454-11B73D795C3C}\InprocServer32 ThreadingModel = “Apartment”
HKEY_CLASSES_ROOT\CLSID\{FC17BFE4-B5E4-4a7b-A71C-2DF28849C4BE}\InprocServer32 ThreadingModel = “Apartment”
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser :
{0A0DCA4C-F72F-49F9-B7B3-480AE39CA062} = “4C CA 0D 0A 2F F7 F9 49 B7 B3 48 0A E3 9C A0 62″
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{0A0DCA4C-F72F-49F9-B7B3-480AE39CA062}\iexplore Count = “1″
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{0A0DCA4C-F72F-49F9-B7B3-480AE39CA062}\iexplore Time = “D7 07 01 00 03 00 11 00 04 00 38 00 34 00 22 02″
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{0A0DCA4C-F72F-49F9-B7B3-480AE39CA062}\iexplore Type = “2″
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{FC17BFE4-B5E4-4A7B-A71C-2DF28849C4BE}\iexplore Count = “1″
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{FC17BFE4-B5E4-4A7B-A71C-2DF28849C4BE}\iexplore Time = “D7 07 01 00 03 00 11 00 04 00 38 00 31 00 C5 01″
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{FC17BFE4-B5E4-4A7B-A71C-2DF28849C4BE}\iexplore Type = “3″
HKEY_CURRENT_USER\Software\Search Rover\Options ShowToolbar = “true”
HKEY_CURRENT_USER\Software\Search Rover\OriginalSearchAssistant SearchAssistant = “http://ie.search.msn.com/{SUB_RFC1766}/srchasst/srchasst.htm”
HKEY_CURRENT_USER\Software\Search Rover\OriginalSearchAssistant Use Custom Search URL = “0″
HKEY_CURRENT_USER\Software\Search Rover\OriginalSearchAssistant Use Search Asst = “”
HKEY_CURRENT_USER\Software\Search Rover\OriginalURLSearchHooks {CFBFAE00-17A6-11D0-99CB-00C04FD64497} = “”
HKEY_CURRENT_USER\Software\Search Rover\SearchAssistant SearchAssistant = “http://as.searchrover.net/dp/search?x=wKX1ILEOi+Vh7AfA98Gm4Me69ZMbubcDsnJKz/X5Xzp3ZXlIIllchBtKnmAALj1fBUkKcZka9wC3IQkxEkfOdc/UP46VDrMWWjbbZsbP2N6i7UoXWVTlHY9OFCf37WkTB8/7H9rFCM/y8WlaORhZI6ith5k+vKiYa0kRZORap+U=”
HKEY_CURRENT_USER\Software\Search Rover\SearchAssistant Use Custom Search URL = “0″
HKEY_CURRENT_USER\Software\Search Rover\SearchAssistant Use Search Asst = “no”
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{0A0DCA4C-F72F-49f9-B7B3-480AE39CA062}\InprocServer32 ThreadingModel = “Apartment”
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{1D0E3B89-0D7F-488b-B890-CD1104F88EE0}\InprocServer32 ThreadingModel = “Apartment”
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{95FA921C-D08D-4a81-8454-11B73D795C3C}\InprocServer32 ThreadingModel = “Apartment”
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{FC17BFE4-B5E4-4a7b-A71C-2DF28849C4BE}\InprocServer32 ThreadingModel = “Apartment”
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar {0A0DCA4C-F72F-49f9-B7B3-480AE39CA062} = “Search Rover”
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Search Rover DisplayIcon = “%PROGRAMFILES%\Search Rover\icons\star_16.ico”
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Search Rover DisplayName = “Search Rover 4.1.2.0″
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Search Rover UninstallString = “%PROGRAMFILES%\Search Rover\SearchRoverUninstall.exe”
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Ext\Stats
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\DownloadManager
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SecurityProviders\SCHANNEL
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SecurityProviders\SCHANNEL\Ciphers
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SecurityProviders\SCHANNEL\Ciphers\DES 56/56
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SecurityProviders\SCHANNEL\Ciphers\NULL
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SecurityProviders\SCHANNEL\Ciphers\RC2 128/128
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SecurityProviders\SCHANNEL\Ciphers\RC2 40/128
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SecurityProviders\SCHANNEL\Ciphers\RC4 128/128
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SecurityProviders\SCHANNEL\Ciphers\RC4 40/128
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SecurityProviders\SCHANNEL\Ciphers\RC4 56/128
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SecurityProviders\SCHANNEL\Ciphers\Triple DES 168/168
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SecurityProviders\SCHANNEL\Hashes
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SecurityProviders\SCHANNEL\Hashes\MD5
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SecurityProviders\SCHANNEL\Hashes\SHA
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SecurityProviders\SCHANNEL\KeyExchangeAlgorithms
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SecurityProviders\SCHANNEL\KeyExchangeAlgorithms\Diffie-Hellman
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SecurityProviders\SCHANNEL\KeyExchangeAlgorithms\PKCS
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SecurityProviders\SCHANNEL\Protocols
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SecurityProviders\SCHANNEL\Protocols\Multi-Protocol Unified Hello
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SecurityProviders\SCHANNEL\Protocols\Multi-Protocol Unified Hello\Client
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SecurityProviders\SCHANNEL\Protocols\Multi-Protocol Unified Hello\Server
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SecurityProviders\SCHANNEL\Protocols\PCT 1.0
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SecurityProviders\SCHANNEL\Protocols\PCT 1.0\Client
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SecurityProviders\SCHANNEL\Protocols\PCT 1.0\Server
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SecurityProviders\SCHANNEL\Protocols\SSL 2.0
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SecurityProviders\SCHANNEL\Protocols\SSL 2.0\Client
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SecurityProviders\SCHANNEL\Protocols\SSL 2.0\Server
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SecurityProviders\SCHANNEL\Protocols\SSL 3.0
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SecurityProviders\SCHANNEL\Protocols\SSL 3.0\Client
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SecurityProviders\SCHANNEL\Protocols\SSL 3.0\Server
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SecurityProviders\SCHANNEL\Protocols\TLS 1.0
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SecurityProviders\SCHANNEL\Protocols\TLS 1.0\Client
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SecurityProviders\SCHANNEL\Protocols\TLS 1.0\Server
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Eventlog\System\Schannel
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main Use Custom Search URL
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main Use Search Asst
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SecurityProviders\SCHANNEL EventLogging
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Eventlog\System\Schannel EventMessageFile
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Eventlog\System\Schannel TypesSupported