Advertisement
Not a member of Pastebin yet?
Sign Up,
it unlocks many cool features!
- "summary": {
- "file_created": [
- "C:\\Documents and Settings\\user\\Local Settings\\History\\History.IE5\\MSHist012018022320180224\\index.dat",
- "C:\\Documents and Settings\\user\\Local Settings\\History\\History.IE5\\MSHist012018021220180219\\index.dat"
- ],
- "regkey_written": [
- "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Ext\\Stats\\{E2E2DD38-D088-4134-82B7-F2BA38496583}\\iexplore\\Type",
- "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\ShellNoRoam\\BagMRU\\0\\MRUListEx",
- "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\5.0\\Cache\\Extensible Cache\\MSHist012018021220180219\\CachePrefix",
- "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\ShellNoRoam\\MUICache\\C:\\WINDOWS\\system32\\shimgvw.dll",
- "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\5.0\\Cache\\Extensible Cache\\MSHist012018022320180224\\CacheOptions",
- "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\5.0\\Cache\\Extensible Cache\\MSHist012018022320180224\\CachePrefix",
- "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\ZoneMap\\UNCAsIntranet",
- "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\5.0\\Cache\\Extensible Cache\\MSHist012018022320180224\\CachePath",
- "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\ShellNoRoam\\MUICache\\@explorer.exe,-7004",
- "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\ShellNoRoam\\MUICache\\@explorer.exe,-7005",
- "HKEY_CURRENT_USER\\Software\\Microsoft\\Internet Explorer\\Toolbar\\Locked",
- "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\ShellNoRoam\\MUICache\\@explorer.exe,-7001",
- "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\5.0\\Cache\\Extensible Cache\\MSHist012018022320180224\\CacheRepair",
- "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\ZoneMap\\IntranetName",
- "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\ShellNoRoam\\MUICache\\C:\\WINDOWS\\system32\\mspaint.exe",
- "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\5.0\\Cache\\Extensible Cache\\MSHist012018021220180219\\CacheLimit",
- "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\ShellNoRoam\\MUICache\\C:\\WINDOWS\\system32\\NOTEPAD.EXE",
- "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\ShellNoRoam\\MUICache\\C:\\Program Files\\Windows NT\\Accessories\\WORDPAD.EXE",
- "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Ext\\Stats\\{E2E2DD38-D088-4134-82B7-F2BA38496583}\\iexplore\\Time",
- "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\MountPoints2\\{ef61f5f0-1227-11e8-94f0-806d6172696f}\\BaseClass",
- "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Ext\\Stats\\{E2E2DD38-D088-4134-82B7-F2BA38496583}\\iexplore\\Count",
- "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\5.0\\Cache\\Extensible Cache\\MSHist012018021220180219\\CacheRepair",
- "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\ShellNoRoam\\BagMRU\\NodeSlots",
- "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\ShellNoRoam\\MUICache\\@%SystemRoot%\\system32\\usmt\\migwiz.exe,-203",
- "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\ZoneMap\\ProxyBypass",
- "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\5.0\\Cache\\Extensible Cache\\MSHist012018022320180224\\CacheLimit",
- "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\5.0\\Cache\\Extensible Cache\\MSHist012018021220180219\\CachePath",
- "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\MountPoints2\\{ef61f5f2-1227-11e8-94f0-806d6172696f}\\BaseClass",
- "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\ShellNoRoam\\BagMRU\\MRUListEx",
- "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\5.0\\Cache\\Extensible Cache\\MSHist012018021220180219\\CacheOptions",
- "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\ShellNoRoam\\MUICache\\C:\\Program Files\\Internet Explorer\\iexplore.exe"
- ],
- "dll_loaded": [
- "C:\\WINDOWS\\system32\\IMM32.DLL",
- "C:\\WINDOWS\\system32\\SHELL32.dll",
- "urlmon.dll",
- "xpsp2res.dll",
- "UxTheme.dll",
- "oleaut32.dll",
- "C:\\WINDOWS\\system32\\browselc.dll",
- "USER32.DLL",
- "C:\\WINDOWS\\system32\\shdoclc.dll",
- "C:\\WINDOWS\\system32\\shell32.dll",
- "URLMON.DLL",
- "SHDOCVW.dll",
- "WININET.dll",
- "BROWSEUI.dll",
- "explorer.exe",
- "OLE32",
- "MLANG.dll",
- "ole32.dll",
- "comctl32.dll",
- "IMM32.DLL",
- "shdocvw.dll",
- "C:\\WINDOWS\\system32\\urlmon.dll",
- "SHELL32.DLL",
- "uxtheme.dll",
- "OLEAUT32.dll",
- "mlang.dll",
- "SHELL32.dll",
- "COMCTL32.dll",
- "VERSION.dll",
- "appHelp.dll",
- "C:\\WINDOWS\\system32\\uxtheme.dll",
- "OLEAUT32",
- "shell32.dll",
- "OLE32.DLL",
- "SETUPAPI.dll"
- ],
- "file_opened": [
- "C:\\Documents and Settings\\All Users\\Start Menu\\Programs\\Python 2.7\\Python (command line).lnk",
- "C:\\Documents and Settings\\user\\Local Settings\\History\\History.IE5\\MSHist012018021220180219\\index.dat",
- "C:\\WINDOWS\\explorer.exe",
- "C:\\Documents and Settings\\user\\Local Settings\\History\\History.IE5\\MSHist012018022320180224\\index.dat",
- "C:\\Documents and Settings\\user\\Local Settings\\History\\History.IE5\\MSHist012018021620180217\\index.dat",
- "C:\\Program Files\\Internet Explorer\\IEXPLORE.EXE",
- "C:\\WINDOWS\\system32\\shell32.dll",
- "C:\\Documents and Settings\\All Users\\Start Menu\\Programs\\MSN.lnk",
- "C:\\WINDOWS\\system32\\mspaint.exe",
- "C:\\Python27\\python.exe",
- "C:\\Documents and Settings\\user\\Local Settings\\Temp\\test",
- "C:\\Documents and Settings\\user\\Local Settings\\History\\desktop.ini",
- "C:\\Documents and Settings\\user\\Local Settings\\History\\History.IE5\\MSHist012018021520180216\\index.dat",
- "C:\\WINDOWS\\system32\\shimgvw.dll",
- "C:\\Documents and Settings\\user\\Desktop",
- "C:\\WINDOWS\\system32\\url.dll",
- "C:\\WINDOWS\\system32\\comctl32.dll",
- "C:\\WINDOWS\\system32\\usmt\\migwiz.exe",
- "C:\\WINDOWS\\system32\\notepad.exe",
- "C:\\Documents and Settings\\All Users\\Start Menu\\Programs\\Accessories\\System Tools\\Files and Settings Transfer Wizard.lnk",
- "C:\\Program Files\\Windows NT\\Accessories\\wordpad.exe",
- "C:\\WINDOWS\\system32\\mshtml.dll",
- "C:\\WINDOWS\\system32\\cscui.dll"
- ],
- "regkey_opened": [
- "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\App Paths\\rundll32.exe",
- "HKEY_CLASSES_ROOT\\PROTOCOLS\\Name-Space Handler\\about\\",
- "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Internet Explorer\\International",
- "HKEY_CLASSES_ROOT\\Directory",
- "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Internet Explorer\\Security\\Adv AddrBar Spoof Detection",
- "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Policies\\Ext\\",
- "HKEY_CURRENT_USER\\SOFTWARE\\Microsoft\\Internet Explorer\\Security\\P3Global",
- "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\Browser Helper Objects",
- "HKEY_CLASSES_ROOT\\Applications\\msimn.exe",
- "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer",
- "HKEY_CLASSES_ROOT\\CLSID\\{FF393560-C2A7-11CF-BFF4-444553540000}",
- "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Internet Explorer\\Main\\FeatureControl\\FEATURE_TEMPORARYFILES_FOR_NOCACHE_840386",
- "HKEY_CLASSES_ROOT\\Applications\\faxcover.exe",
- "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Applications\\moviemk.exe\\shell",
- "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Internet Explorer\\Main\\FeatureControl\\FEATURE_UNC_SAVEDFILECHECK",
- "HKEY_CLASSES_ROOT\\Drive\\shellex\\FolderExtensions",
- "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\Zones\\1",
- "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\Zones\\2",
- "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\Zones\\3",
- "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\Zones\\4",
- "HKEY_CLASSES_ROOT\\Applications\\cag.exe",
- "HKEY_CLASSES_ROOT\\\u0004",
- "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Internet Explorer\\Main\\FeatureControl\\FEATURE_ADDON_MANAGEMENT",
- "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\{FF393560-C2A7-11CF-BFF4-444553540000}\\ShellEx\\IconHandler",
- "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\ShellCompatibility\\Applications\\iexplore.exe",
- "HKEY_CLASSES_ROOT\\CLSID\\{FF393560-C2A7-11CF-BFF4-444553540000}\\InProcServer32",
- "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Applications\\navwnt.exe\\shell",
- "HKEY_CLASSES_ROOT\\.",
- "HKEY_CLASSES_ROOT\\CLSID\\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\\ShellFolder",
- "HKEY_CLASSES_ROOT\\*",
- "HKEY_CLASSES_ROOT\\Applications\\wab.exe",
- "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Shell Extensions\\Blocked",
- "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\ShellCompatibility\\Objects\\{2559A1F0-21D7-11D4-BDAF-00C04F60B9F0}",
- "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\{2559a1f4-21d7-11d4-bdaf-00c04f60b9f0}\\(Default)",
- "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Internet Explorer\\Main\\FeatureControl\\FEATURE_AnchorsMarkedVisited_KB918965",
- "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\{25336920-03F9-11CF-8FD0-00AA00686F13}\\LocalServer",
- "HKEY_CLASSES_ROOT\\Applications\\WB32.EXE",
- "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Applications\\mspaint.exe\\shell",
- "HKEY_CLASSES_ROOT\\Applications\\explorer.exe",
- "HKEY_CURRENT_USER\\AppEvents\\Schemes\\Apps\\.Default\\MenuPopup\\.current",
- "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\htmlfile\\CurVer",
- "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\Policies\\Explorer",
- "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\ShellNoRoam\\MUICache",
- "HKEY_CLASSES_ROOT\\Applications\\ARTGALRY.EXE",
- "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\PROTOCOLS\\Handler\\about",
- "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion",
- "HKEY_CLASSES_ROOT\\CLSID\\{7B8A2D94-0AC9-11D1-896C-00C04FB6BFC4}\\InProcServer32",
- "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Applications\\mobsync.exe\\(Default)",
- "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\Advanced",
- "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Internet Explorer\\Main\\FeatureControl\\FEATURE_DISABLE_MK_PROTOCOL",
- "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Applications\\WINWORD.EXE\\shell",
- "HKEY_CLASSES_ROOT\\Applications\\wpnpinst.exe",
- "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\SystemFileAssociations\\text\\ShellEx\\IconHandler",
- "HKEY_CURRENT_USER\\SOFTWARE\\Classes\\PROTOCOLS\\Handler\\C",
- "HKEY_CLASSES_ROOT\\CLSID\\{750FDF0E-2A26-11D1-A3EA-080036587F03}\\InProcServer32",
- "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Internet Explorer\\Security\\Floppy Access",
- "HKEY_CLASSES_ROOT\\Applications\\dsquery.dll",
- "HKEY_CLASSES_ROOT\\MIME\\Database\\Content Type\\text/plain",
- "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Internet Explorer\\Toolbar",
- "HKEY_CLASSES_ROOT\\Applications\\shdocvw.dll",
- "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Applications\\iexplore.exe\\TaskbarExceptionsIcons",
- "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\{2559a1f3-21d7-11d4-bdaf-00c04f60b9f0}\\(Default)",
- "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FileExts\\OpenWithList",
- "HKEY_CLASSES_ROOT\\CLSID\\{25336920-03F9-11cf-8FD0-00AA00686F13}\\Implemented Categories\\{00021490-0000-0000-C000-000000000046}",
- "HKEY_LOCAL_MACHINE\\Software\\Policies\\Microsoft\\Windows\\CurrentVersion\\Internet Settings",
- "HKEY_CLASSES_ROOT\\OpenWithList",
- "HKEY_CURRENT_USER\\Software\\Microsoft\\Internet Explorer\\Styles",
- "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Directory\\ShellEx\\IconHandler",
- "HKEY_CURRENT_USER\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Policies\\Ext\\CLSID",
- "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\*\\ShellEx\\{10DF43C8-1DBE-11D3-8B34-006097DF5BD4}",
- "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\{2559a1f0-21d7-11d4-bdaf-00c04f60b9f0}\\(Default)",
- "HKEY_CLASSES_ROOT\\Applications\\Ttxmpc97.exe",
- "HKEY_CLASSES_ROOT\\Applications\\depends.exe",
- "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\CLSID\\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\\ShellFolder",
- "HKEY_CLASSES_ROOT\\Applications\\inoculan.exe",
- "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\.lnk\\ShellEx\\{00021500-0000-0000-C000-000000000046}",
- "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\ShellCompatibility\\Objects\\{2559A1F7-21D7-11D4-BDAF-00C04F60B9F0}",
- "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\ZoneMap\\Domains\\blank",
- "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Applications\\shimgvw.dll\\shell\\open\\command",
- "HKEY_CURRENT_USER\\Control Panel\\Desktop\\WindowMetrics",
- "HKEY_CURRENT_USER\\Software\\Microsoft\\Internet Explorer\\Settings",
- "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Internet Explorer\\Main",
- "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Directory\\Clsid",
- "HKEY_CLASSES_ROOT\\CLSID\\{BDEADE7F-C265-11d0-BCED-00A0C90AB50F}\\Implemented Categories\\{00021494-0000-0000-C000-000000000046}",
- "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\TravelLog",
- "HKEY_CLASSES_ROOT\\Applications\\CChat.exe",
- "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\5.0\\Cache\\Extensible Cache",
- "HKEY_CLASSES_ROOT\\Applications\\grpconv.exe",
- "HKEY_CURRENT_USER\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Ext\\Settings\\{E2E2DD38-D088-4134-82B7-F2BA38496583}",
- "HKEY_CLASSES_ROOT\\CLSID\\{2227A280-3AEA-1069-A2DE-08002B30309D}\\ShellFolder",
- "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Internet Explorer\\Main\\FeatureControl\\FEATURE_CLOSE_EMPTY_BROWSER_KB920982",
- "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\CLSID\\{2559A1F5-21D7-11D4-BDAF-00C04F60B9F0}\\ShellFolder",
- "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer",
- "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows NT\\CurrentVersion\\FontSubstitutes",
- "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\CLSID\\{20D04FE0-3AEA-1069-A2D8-08002B30309D}",
- "HKEY_CLASSES_ROOT\\Applications\\mshta.exe",
- "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\CLSID\\{2559A1F5-21D7-11D4-BDAF-00C04F60B9F0}\\ShellFolder",
- "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\Zones\\0",
- "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Internet Explorer\\Main\\FeatureControl\\FEATURE_PROTOCOL_LOCKDOWN",
- "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\CLSID\\{2559A1F1-21D7-11D4-BDAF-00C04F60B9F0}\\ShellFolder",
- "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\{0002DF01-0000-0000-C000-000000000046}\\LocalServer32",
- "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\htmlfile\\DefaultIcon",
- "HKEY_CLASSES_ROOT\\Applications\\mobsync.exe",
- "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FileExts\\.exe",
- "HKEY_CURRENT_USER\\Software\\Microsoft\\Internet Explorer\\International",
- "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\Shell Extensions\\Cached",
- "HKEY_CLASSES_ROOT\\Applications\\zipfldr.dll",
- "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\*\\ShellEx\\{000214F9-0000-0000-C000-000000000046}",
- "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\CLSID\\{2559A1F4-21D7-11D4-BDAF-00C04F60B9F0}\\ShellFolder",
- "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\ShellNoRoam\\BagMRU\\0\\1\\0",
- "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Internet Explorer\\Main\\FeatureControl\\FEATURE_INTELLIFORMS_ALTERNATE_RELEASE_KB924301",
- "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\CLSID\\{2559A1F0-21D7-11D4-BDAF-00C04F60B9F0}\\ShellFolder",
- "HKEY_CURRENT_USER\\Software\\Microsoft\\windows\\CurrentVersion\\Explorer\\AutoComplete",
- "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Directory\\(Default)",
- "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FileExts\\.",
- "HKEY_CLASSES_ROOT\\Applications\\mspaint.exe",
- "HKEY_CURRENT_USER\\Software\\Microsoft\\Internet Explorer\\New Windows",
- "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Applications\\navwnt.exe\\(Default)",
- "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Internet Explorer\\MediaTypeClass",
- "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\{0002DF01-0000-0000-C000-000000000046}\\InprocServerX86",
- "HKEY_CURRENT_USER\\SOFTWARE\\Policies\\Microsoft\\Windows\\CurrentVersion\\Internet Settings",
- "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\MountPoints2\\CPC\\Volume\\{ef61f5f0-1227-11e8-94f0-806d6172696f}\\",
- "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Applications\\moviemk.exe\\shell\\open",
- "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Applications\\shimgvw.dll\\shell",
- "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\ShellCompatibility\\Objects\\{FF393560-C2A7-11CF-BFF4-444553540000}",
- "HKEY_CLASSES_ROOT\\Applications",
- "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Applications\\sndvol32.exe\\shell",
- "HKEY_CLASSES_ROOT\\Applications\\wordpad.exe",
- "HKEY_CLASSES_ROOT\\.htm",
- "HKEY_CLASSES_ROOT\\CLSID\\{2559A1F0-21D7-11D4-BDAF-00C04F60B9F0}\\ShellFolder",
- "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\{0002DF01-0000-0000-C000-000000000046}\\InprocHandlerX86",
- "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\{FF393560-C2A7-11CF-BFF4-444553540000}\\Clsid",
- "HKEY_CLASSES_ROOT\\Applications\\WINWORD.EXE",
- "HKEY_CLASSES_ROOT\\Drive\\shellex\\FolderExtensions\\{fbeb8a05-beee-4442-804e-409d6c4515e9}",
- "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\CLSID\\{2559A1F3-21D7-11D4-BDAF-00C04F60B9F0}",
- "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\CLSID\\{2559A1F0-21D7-11D4-BDAF-00C04F60B9F0}\\ShellFolder",
- "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\{2559a1f5-21d7-11d4-bdaf-00c04f60b9f0}\\(Default)",
- "HKEY_CLASSES_ROOT\\Applications\\msrating.dll",
- "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\htmlfile\\ShellEx\\IconHandler",
- "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Policies\\ActiveDesktop",
- "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\{25336920-03F9-11CF-8FD0-00AA00686F13}\\InprocServerX86",
- "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\exefile\\Clsid",
- "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Applications\\icwconn1.exe\\shell",
- "HKEY_CLASSES_ROOT\\Folder",
- "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Applications\\python.exe\\shell\\open\\command",
- "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Applications\\notepad.exe\\shell",
- "HKEY_CLASSES_ROOT\\Applications\\ORGCHART.EXE",
- "HKEY_CLASSES_ROOT\\Applications\\cryptext.dll",
- "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\windows\\CurrentVersion\\Internet Settings\\Url History",
- "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\htmlfile\\(Default)",
- "HKEY_CLASSES_ROOT\\Applications\\shell32.dll",
- "HKEY_CLASSES_ROOT\\.html",
- "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\(Default)",
- "HKEY_CLASSES_ROOT\\PROTOCOLS\\Name-Space Handler\\",
- "HKEY_CLASSES_ROOT\\Applications\\CMMGR32.EXE",
- "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\{2227A280-3AEA-1069-A2DE-08002B30309D}\\(Default)",
- "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Applications\\icwconn1.exe\\(Default)",
- "HKEY_CURRENT_USER\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Ext\\Stats\\{E2E2DD38-D088-4134-82B7-F2BA38496583}\\iexplore",
- "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\ShellNoRoam\\Bags\\1\\Shell\\Inherit",
- "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\windows\\CurrentVersion\\Explorer\\AutoComplete",
- "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\{25336920-03F9-11CF-8FD0-00AA00686F13}\\TreatAs",
- "HKEY_CLASSES_ROOT\\SystemFileAssociations\\text",
- "HKEY_CLASSES_ROOT\\Applications\\perfmon.exe",
- "HKEY_LOCAL_MACHINE\\System\\Setup",
- "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\CLSID\\{2559A1F1-21D7-11D4-BDAF-00C04F60B9F0}",
- "HKEY_CLASSES_ROOT\\CLSID\\{450D8FBA-AD25-11D0-98A8-0800361B1103}",
- "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\ShellNoRoam\\BagMRU",
- "HKEY_CLASSES_ROOT\\CLSID\\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\\InProcServer32",
- "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FileExts",
- "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\Shell",
- "HKEY_CLASSES_ROOT\\Applications\\sndvol32.exe",
- "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\Lockdown_Zones\\0",
- "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\SystemFileAssociations\\text\\shell\\edit",
- "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\ShellCompatibility\\Objects\\{2559A1F1-21D7-11D4-BDAF-00C04F60B9F0}",
- "HKEY_CURRENT_USER\\Software\\Policies\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\ZoneMap\\",
- "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Internet Explorer\\Main\\FeatureControl\\FEATURE_RESTRICT_FILEDOWNLOAD",
- "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FileExts\\OpenWithProgids",
- "HKEY_CURRENT_USER\\Software\\Policies\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\ZoneMap\\Domains\\",
- "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Internet Explorer\\Main\\FeatureControl\\FEATURE_LOCALMACHINE_LOCKDOWN",
- "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Internet Explorer\\Main\\FeatureControl\\FEATURE_MIME_HANDLING",
- "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Internet Explorer\\Main\\FeatureControl\\FEATURE_FILEPROTOCOL_NOFINDFIRST_KB947853",
- "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Applications\\python.exe\\(Default)",
- "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FileAssociation",
- "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\{25336920-03F9-11CF-8FD0-00AA00686F13}\\InprocHandler32",
- "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\Setup",
- "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\lnkfile\\ShellEx\\{00021500-0000-0000-C000-000000000046}",
- "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\ZoneMap\\Ranges\\",
- "HKEY_CURRENT_USER\\Software\\Microsoft\\Internet Explorer\\Extensions\\{E2E2DD38-D088-4134-82B7-F2BA38496583}",
- "HKEY_CURRENT_USER\\Software\\Microsoft\\Internet Explorer\\Extensions\\CmdMapping",
- "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\BrowseNewProcess",
- "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Applications\\mspaint.exe\\(Default)",
- "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\{25336920-03F9-11CF-8FD0-00AA00686F13}\\Progid",
- "HKEY_CLASSES_ROOT\\Applications\\icwconn1.exe",
- "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Setup\\AppLogLevels",
- "HKEY_CLASSES_ROOT\\Applications\\shscrap.dll",
- "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\ShellNoRoam\\Bags\\4\\Shell\\Inherit",
- "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Internet Explorer\\Main\\FeatureControl\\FEATURE_VALIDATE_NAVIGATE_URL",
- "HKEY_CLASSES_ROOT\\Applications\\drwatson.exe",
- "HKEY_LOCAL_MACHINE\\System\\WPA\\PnP",
- "HKEY_CLASSES_ROOT\\Applications\\python.exe",
- "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\ShellNoRoam\\MUICache\\(Default)",
- "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Internet Explorer\\Extensions",
- "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows NT\\CurrentVersion\\ProfileList\\S-1-5-21-839522115-813497703-1060284298-1003",
- "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Internet Explorer\\Printing",
- "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\{0002DF01-0000-0000-C000-000000000046}\\InprocHandler32",
- "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\CLSID\\{2559A1F7-21D7-11D4-BDAF-00C04F60B9F0}\\ShellFolder",
- "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\ShellCompatibility\\Objects\\{20D04FE0-3AEA-1069-A2D8-08002B30309D}",
- "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Applications\\shimgvw.dll\\(Default)",
- "HKEY_CLASSES_ROOT\\PROTOCOLS\\Name-Space Handler\\*\\",
- "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\ShellCompatibility\\Objects\\{450D8FBA-AD25-11D0-98A8-0800361B1103}",
- "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\Accepted Documents",
- "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Applications\\iexplore.exe\\(Default)",
- "HKEY_LOCAL_MACHINE\\Software\\Policies\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\ZoneMap\\Ranges\\",
- "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\CLSID\\{450D8FBA-AD25-11D0-98A8-0800361B1103}",
- "HKEY_CLASSES_ROOT\\Applications\\notepad.exe",
- "HKEY_CLASSES_ROOT\\Applications\\Outlook.EXE",
- "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\PROTOCOLS\\Handler\\C",
- "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\5.0\\Cache\\Extensible Cache\\MSHist012018021620180217",
- "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Applications\\mobsync.exe\\shell",
- "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\*\\DefaultIcon",
- "HKEY_CURRENT_USER\\Software\\Policies\\Microsoft\\Internet Explorer\\Restrictions",
- "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\TravelLog",
- "HKEY_CURRENT_USER\\software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\Advanced",
- "HKEY_CURRENT_USER\\Software\\Policies\\Microsoft\\Internet Explorer\\Control Panel",
- "HKEY_CLASSES_ROOT\\Applications\\finder.exe",
- "HKEY_LOCAL_MACHINE\\Software\\Policies\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\ZoneMap\\",
- "HKEY_CLASSES_ROOT\\Applications\\helpctr.exe",
- "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\exefile\\ShellEx\\IconHandler",
- "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\{2559a1f1-21d7-11d4-bdaf-00c04f60b9f0}\\(Default)",
- "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\CLSID\\{450D8FBA-AD25-11D0-98A8-0800361B1103}\\ShellFolder",
- "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\MountPoints2\\CPC\\Volume\\{ef61f5f2-1227-11e8-94f0-806d6172696f}\\",
- "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\5.0\\Cache\\Extensible Cache\\MSHist012018022320180224",
- "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Applications\\wordpad.exe\\shell",
- "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\ZoneMap\\ProtocolDefaults\\",
- "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Internet Explorer\\Main\\FeatureControl\\FEATURE_COMPLETE_PROGRESSBAR_ONFLASH_925973",
- "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Applications\\inoculan.exe\\shell",
- "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\*\\shell",
- "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Applications\\wordpad.exe\\(Default)",
- "HKEY_LOCAL_MACHINE\\SYSTEM\\Setup",
- "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\MountPoints2\\{ef61f5f0-1227-11e8-94f0-806d6172696f}\\",
- "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\Shell\\LocalizedResourceName",
- "HKEY_CLASSES_ROOT\\exefile",
- "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Applications\\realmon.exe\\(Default)",
- "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\{25336920-03F9-11CF-8FD0-00AA00686F13}\\LocalServer32",
- "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Internet Explorer\\Main\\FeatureControl\\FEATURE_GET_URL_DOM_FILEPATH_UNENCODED",
- "HKEY_CLASSES_ROOT\\Applications\\OSA.EXE",
- "HKEY_CLASSES_ROOT\\Applications\\accwiz.exe",
- "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\Policies\\Ratings",
- "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Internet Explorer\\Main\\FeatureControl\\FEATURE_WINDOW_RESTRICTIONS",
- "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Internet Explorer\\Main\\FeatureControl\\FEATURE_OBJECT_CACHING",
- "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Applications\\iexplore.exe\\shell\\open",
- "HKEY_CLASSES_ROOT\\Applications\\datainst.exe",
- "HKEY_CLASSES_ROOT\\CLSID\\{2227A280-3AEA-1069-A2DE-08002B30309D}",
- "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Applications\\python.exe\\shell\\open",
- "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\{0002DF01-0000-0000-C000-000000000046}\\InprocServer32",
- "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\CLSID\\{2559A1F7-21D7-11D4-BDAF-00C04F60B9F0}",
- "HKEY_CLASSES_ROOT\\Applications\\msiexec.exe",
- "HKEY_CURRENT_USER\\Software\\Microsoft\\Internet Explorer\\Main\\FeatureControl",
- "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\{450D8FBA-AD25-11D0-98A8-0800361B1103}\\(Default)",
- "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Internet Explorer\\Main",
- "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Internet Explorer\\Main\\FeatureControl\\FEATURE_MIME_SNIFFING",
- "HKEY_CLASSES_ROOT\\Applications\\rnaui.dll",
- "HKEY_CLASSES_ROOT\\.lnk",
- "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Internet Explorer\\Version Vector",
- "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Shell Extensions\\Cached",
- "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\MountPoints2\\CPC\\Volume",
- "HKEY_CLASSES_ROOT\\Applications\\regedit.exe",
- "HKEY_CLASSES_ROOT\\Applications\\shimgvw.dll",
- "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Internet Explorer\\Main\\FeatureControl\\FEATURE_VALIDATE_URLHOSTNAME",
- "HKEY_CLASSES_ROOT\\CLSID\\{2559A1F0-21D7-11D4-BDAF-00C04F60B9F0}",
- "HKEY_CLASSES_ROOT\\Applications\\mplayer.exe",
- "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\ShellIconOverlayIdentifiers\\Offline Files",
- "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\{0002DF01-0000-0000-C000-000000000046}\\TreatAs",
- "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\{25336920-03F9-11CF-8FD0-00AA00686F13}\\InprocHandlerX86",
- "HKEY_CLASSES_ROOT\\Applications\\moviemk.exe",
- "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\\(Default)",
- "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\ShellCompatibility\\Objects\\{21EC2020-3AEA-1069-A2DD-08002B30309D}",
- "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\ShellNoRoam\\(Default)",
- "HKEY_CURRENT_USER\\Software\\Microsoft\\Internet Explorer\\International\\Scripts\\3",
- "HKEY_CURRENT_USER\\Software\\Policies\\Microsoft\\Internet Explorer\\PhotoSupport",
- "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\CLSID\\{2559A1F1-21D7-11D4-BDAF-00C04F60B9F0}\\ShellFolder",
- "HKEY_CLASSES_ROOT\\CLSID\\{2559A1F4-21D7-11D4-BDAF-00C04F60B9F0}\\ShellFolder",
- "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\CLSID\\{450D8FBA-AD25-11D0-98A8-0800361B1103}\\ShellFolder",
- "HKEY_CURRENT_USER\\Software\\Microsoft\\Internet Explorer\\MenuExt",
- "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\ShellNoRoam",
- "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\ShellIconOverlayIdentifiers",
- "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\BrowseNewProcess",
- "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\ShellCompatibility\\Objects\\{2559A1F3-21D7-11D4-BDAF-00C04F60B9F0}",
- "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings",
- "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Applications\\mspaint.exe\\shell\\edit\\command",
- "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Applications\\mspaint.exe\\shell\\open",
- "HKEY_CLASSES_ROOT\\Applications\\hh.exe",
- "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\ShellNoRoam\\Bags\\8\\Shell\\Inherit",
- "HKEY_CLASSES_ROOT\\CLSID\\{2559A1F4-21D7-11D4-BDAF-00C04F60B9F0}",
- "HKEY_CURRENT_USER\\Software\\Microsoft\\windows\\CurrentVersion\\Internet Settings",
- "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\ShellCompatibility\\Objects\\{2559A1F5-21D7-11D4-BDAF-00C04F60B9F0}",
- "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\ZoneMap\\Domains\\blank",
- "HKEY_CURRENT_USER\\Software\\Policies\\Microsoft\\Internet Explorer\\Main\\FeatureControl",
- "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Applications\\wordpad.exe\\shell\\open",
- "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\CLSID\\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\\ShellFolder",
- "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\MountPoints2\\{ef61f5f2-1227-11e8-94f0-806d6172696f}\\",
- "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Policies\\NonEnum",
- "HKEY_CLASSES_ROOT\\Applications\\WScript.exe",
- "HKEY_CLASSES_ROOT\\Applications\\HYPERTRM.EXE",
- "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Internet Explorer\\Main\\FeatureControl\\FEATURE_RESPECT_OBJECTSAFETY_POLICY_KB905547",
- "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Internet Explorer\\Main\\FeatureControl\\FEATURE_HTTP_USERNAME_PASSWORD_DISABLE",
- "HKEY_LOCAL_MACHINE\\Software\\Clients\\News",
- "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Control\\MiniNT",
- "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Internet Explorer\\Extensions\\{e2e2dd38-d088-4134-82b7-f2ba38496583}\\Lang0409",
- "HKEY_CURRENT_USER\\Software\\Microsoft\\Internet Explorer",
- "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\ShellNoRoam\\Bags\\AllFolders\\Shell",
- "HKEY_CLASSES_ROOT\\Applications\\inetcpl.cpl",
- "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\SmallIcons",
- "HKEY_CLASSES_ROOT\\CLSID\\{FF393560-C2A7-11CF-BFF4-444553540000}\\shell",
- "HKEY_CLASSES_ROOT\\Applications\\realmon.exe",
- "HKEY_CURRENT_USER\\SOFTWARE\\Microsoft\\Internet Explorer\\Security\\P3Sites",
- "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Internet Explorer\\New Windows",
- "HKEY_CLASSES_ROOT\\Applications\\wltmime.exe",
- "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Applications\\notepad.exe\\shell\\open",
- "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Ole",
- "HKEY_CLASSES_ROOT\\Applications\\cdfview.dll",
- "HKEY_CLASSES_ROOT\\Applications\\clipbrd.exe",
- "HKEY_CURRENT_USER\\Software\\Microsoft\\Internet Explorer\\Main",
- "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FileExts\\.htm",
- "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\lnkfile\\(Default)",
- "HKEY_CURRENT_USER\\Software\\Microsoft\\windows\\CurrentVersion\\Internet Settings\\Url History",
- "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\5.0\\Cache\\Extensible Cache\\MSHist012018021220180219",
- "HKEY_CLASSES_ROOT\\SystemFileAssociations\\.exe",
- "HKEY_CLASSES_ROOT\\Applications\\netshell.dll",
- "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Internet Explorer\\Extensions\\{E2E2DD38-D088-4134-82B7-F2BA38496583}",
- "HKEY_LOCAL_MACHINE\\Software\\Policies\\Microsoft\\Internet Explorer\\Main\\FeatureControl",
- "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\5.0\\Cache",
- "HKEY_CLASSES_ROOT\\CLSID\\{2559A1F1-21D7-11D4-BDAF-00C04F60B9F0}\\ShellFolder",
- "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\RunMRU",
- "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Internet Settings",
- "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Internet Explorer\\Main\\FeatureControl\\FEATURE_ZONE_ELEVATION",
- "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\ZoneMap\\",
- "HKEY_CLASSES_ROOT\\Applications\\url.dll",
- "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\COM3",
- "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Applications\\notepad.exe\\(Default)",
- "HKEY_CLASSES_ROOT\\Applications\\rasphone.exe",
- "HKEY_CLASSES_ROOT\\SystemFileAssociations\\application",
- "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings",
- "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\Shell\\Bags\\AllFolders\\Shell",
- "HKEY_CURRENT_USER\\Software\\Microsoft\\Internet Explorer\\International\\Scripts",
- "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\Policies\\NonEnum",
- "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\CLSID\\{2227A280-3AEA-1069-A2DE-08002B30309D}",
- "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Applications\\realmon.exe\\shell",
- "HKEY_CLASSES_ROOT\\.exe",
- "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\Shell Icons",
- "HKEY_CLASSES_ROOT\\Applications\\graflink.exe",
- "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Applications\\iexplore.exe\\shell",
- "HKEY_CLASSES_ROOT\\SystemFileAssociations\\.htm",
- "HKEY_CLASSES_ROOT\\CLSID\\{450D8FBA-AD25-11D0-98A8-0800361B1103}\\ShellFolder",
- "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Internet Explorer",
- "HKEY_CURRENT_USER\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Internet Settings",
- "HKEY_CURRENT_USER",
- "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\SystemFileAssociations\\text\\shell\\edit\\command",
- "HKEY_CLASSES_ROOT\\Applications\\navwnt.exe",
- "HKEY_CLASSES_ROOT\\CLSID\\{2559A1F3-21D7-11D4-BDAF-00C04F60B9F0}\\ShellFolder",
- "HKEY_CURRENT_USER\\SOFTWARE\\Classes\\PROTOCOLS\\Handler\\about",
- "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\Performance",
- "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Applications\\wordpad.exe\\shell\\open\\command",
- "HKEY_CLASSES_ROOT\\http\\DefaultIcon",
- "HKEY_CURRENT_USER\\Software\\Policies\\Microsoft\\Internet Explorer\\Toolbars\\Restrictions",
- "HKEY_CLASSES_ROOT\\CLSID\\{2559A1F5-21D7-11D4-BDAF-00C04F60B9F0}",
- "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Internet Explorer\\Main\\FeatureControl\\FEATURE_SAFE_BINDTOOBJECT",
- "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\{25336920-03F9-11CF-8FD0-00AA00686F13}\\InprocServer32",
- "HKEY_CURRENT_USER\\Software\\Microsoft\\Internet Explorer\\Toolbar\\ShellBrowser",
- "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion",
- "HKEY_CLASSES_ROOT\\SystemFileAssociations\\.",
- "HKEY_CLASSES_ROOT\\Applications\\msconf.dll",
- "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\Streams",
- "HKEY_CLASSES_ROOT\\Applications\\themes.exe",
- "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Applications\\moviemk.exe\\(Default)",
- "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Internet Explorer\\Main\\FeatureControl\\FEATURE_SECURITYBAND",
- "HKEY_CLASSES_ROOT\\Applications\\fontview.exe",
- "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\exefile\\CurVer",
- "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\CLSID\\{2559A1F0-21D7-11D4-BDAF-00C04F60B9F0}",
- "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\ZoneMap\\ProtocolDefaults\\",
- "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\windows\\CurrentVersion\\Internet Settings",
- "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Internet Explorer\\Main\\FeatureControl\\FEATURE_RESTRICT_ACTIVEXINSTALL",
- "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Ext\\Settings\\{E2E2DD38-D088-4134-82B7-F2BA38496583}",
- "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\Shell\\(Default)",
- "HKEY_LOCAL_MACHINE\\software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\Advanced",
- "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Applications\\notepad.exe\\shell\\open\\command",
- "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\{2559a1f7-21d7-11d4-bdaf-00c04f60b9f0}\\(Default)",
- "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Internet Explorer\\Extensions\\{e2e2dd38-d088-4134-82b7-f2ba38496583}",
- "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\{25336920-03F9-11CF-8FD0-00AA00686F13}\\DocObject",
- "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\CLSID\\{2227A280-3AEA-1069-A2DE-08002B30309D}\\ShellFolder",
- "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\ZoneMap",
- "HKEY_CLASSES_ROOT\\Applications\\snapview.exe",
- "HKEY_CLASSES_ROOT\\Applications\\awdvstub.exe",
- "HKEY_CLASSES_ROOT\\Applications\\MSInfo32.exe",
- "HKEY_CLASSES_ROOT\\CLSID\\{2559A1F3-21D7-11D4-BDAF-00C04F60B9F0}",
- "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Internet Explorer\\Main\\FeatureControl\\FEATURE_WEBOC_POPUPMANAGEMENT",
- "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Folder\\Clsid",
- "HKEY_LOCAL_MACHINE\\Software\\Policies\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\",
- "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\ShellCompatibility\\Objects\\{2559A1F4-21D7-11D4-BDAF-00C04F60B9F0}",
- "HKEY_CLASSES_ROOT\\lnkfile",
- "HKEY_LOCAL_MACHINE\\Software\\Policies\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\ZoneMap\\Domains\\",
- "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Policies\\Explorer",
- "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\htmlfile\\shell\\edit",
- "HKEY_CLASSES_ROOT\\Applications\\winhlp32.exe",
- "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\ShellCompatibility\\Objects\\{2227A280-3AEA-1069-A2DE-08002B30309D}",
- "HKEY_CURRENT_USER\\SOFTWARE\\Microsoft\\Internet Explorer\\Main",
- "HKEY_CURRENT_USER\\CLSID\\{25336920-03F9-11CF-8FD0-00AA00686F13}",
- "HKEY_CLASSES_ROOT\\CLSID\\{20D04FE0-3AEA-1069-A2D8-08002B30309D}",
- "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\CLSID\\{2559A1F3-21D7-11D4-BDAF-00C04F60B9F0}\\ShellFolder",
- "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Applications\\python.exe\\shell",
- "HKEY_CURRENT_USER\\Software\\Microsoft\\Internet Explorer\\Toolbar",
- "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\CLSID\\{2559A1F7-21D7-11D4-BDAF-00C04F60B9F0}\\ShellFolder",
- "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Applications\\shimgvw.dll\\shell\\open",
- "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Directory\\CurVer",
- "HKEY_CURRENT_USER\\CLSID\\{FBF23B42-E3F0-101B-8488-00AA003E56F8}\\InProcServer32",
- "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Applications\\WINWORD.EXE\\(Default)",
- "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Applications\\iexplore.exe\\shell\\open\\command",
- "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\CLSID\\{2559A1F4-21D7-11D4-BDAF-00C04F60B9F0}\\ShellFolder",
- "HKEY_CURRENT_USER\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Policies\\IEAK",
- "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\Lockdown_Zones\\0",
- "HKEY_CLASSES_ROOT\\PROTOCOLS\\Name-Space Handler\\C\\",
- "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\ShellNoRoam\\BagMRU\\0",
- "HKEY_CURRENT_USER\\CLSID\\{0002DF01-0000-0000-C000-000000000046}",
- "HKEY_CLASSES_ROOT\\CLSID\\{2559A1F7-21D7-11D4-BDAF-00C04F60B9F0}",
- "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Applications\\inoculan.exe\\(Default)",
- "HKEY_CURRENT_USER\\Control Panel\\International",
- "HKEY_CURRENT_USER\\(Default)",
- "HKEY_CLASSES_ROOT\\Applications\\ntbackup.exe",
- "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\Shell Extensions\\Blocked",
- "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\SmallIcons",
- "HKEY_CLASSES_ROOT\\CLSID\\{2559A1F1-21D7-11D4-BDAF-00C04F60B9F0}",
- "HKEY_CURRENT_USER\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Policies\\Ext\\",
- "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Internet Explorer\\Main\\FeatureControl\\FEATURE_BEHAVIORS",
- "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\*\\Clsid",
- "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\ShellNoRoam\\BagMRU\\0\\1",
- "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Applications\\sndvol32.exe\\(Default)",
- "HKEY_CURRENT_USER\\Software\\Microsoft\\Internet Explorer\\TypedURLs",
- "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Applications\\mspaint.exe\\shell\\edit",
- "HKEY_CLASSES_ROOT\\OpenWithProgids",
- "HKEY_CLASSES_ROOT\\htmlfile",
- "HKEY_CLASSES_ROOT\\Applications\\kodakprv.EXE",
- "HKEY_CURRENT_USER\\Software\\Microsoft\\Internet Explorer\\Extensions",
- "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\lnkfile\\CurVer",
- "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\CLSID\\{2227A280-3AEA-1069-A2DE-08002B30309D}\\ShellFolder",
- "HKEY_CLASSES_ROOT\\Applications\\oledb32.dll",
- "HKEY_CLASSES_ROOT\\Applications\\iexplore.exe",
- "HKEY_CLASSES_ROOT\\CLSID\\{25336920-03F9-11CF-8FD0-00AA00686F13}",
- "HKEY_CLASSES_ROOT\\CLSID\\{2559A1F5-21D7-11D4-BDAF-00C04F60B9F0}\\ShellFolder",
- "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FileExts\\.lnk",
- "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Internet Explorer\\Main\\FeatureControl",
- "HKEY_LOCAL_MACHINE\\Software\\Policies\\Microsoft\\Internet Explorer\\Toolbars\\Restrictions",
- "HKEY_CURRENT_USER\\Software\\Policies\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\ZoneMap\\Ranges\\",
- "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Policies\\IEAK",
- "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\5.0\\Cache\\Extensible Cache\\MSHist012018021520180216",
- "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Policies\\Ext\\CLSID",
- "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\CLSID\\{2559A1F3-21D7-11D4-BDAF-00C04F60B9F0}\\ShellFolder",
- "HKEY_CLASSES_ROOT\\Applications\\ISIGNUP.EXE",
- "HKEY_CLASSES_ROOT\\CLSID\\{2559A1F7-21D7-11D4-BDAF-00C04F60B9F0}\\ShellFolder",
- "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\htmlfile\\Clsid",
- "HKEY_LOCAL_MACHINE\\Software\\Policies\\Microsoft\\Internet Explorer\\Restrictions",
- "HKEY_CLASSES_ROOT\\Applications\\MMC.exe",
- "HKEY_LOCAL_MACHINE\\System\\CurrentControlSet\\Control\\Nls\\CodePage",
- "HKEY_CLASSES_ROOT\\PROTOCOLS\\Name-Space Handler\\file\\",
- "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\exefile\\(Default)",
- "HKEY_CLASSES_ROOT\\Applications\\fpidcwiz.exe",
- "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Policies",
- "HKEY_CLASSES_ROOT\\Applications\\mnyimprt.exe"
- ],
- "command_line": [
- "\"C:\\WINDOWS\\system32\\rundll32.exe\" C:\\WINDOWS\\system32\\shell32.dll,OpenAs_RunDLL C:\\DOCUME~1\\user\\LOCALS~1\\Temp\\test",
- "\"C:\\Program Files\\Internet Explorer\\iexplore.exe\" C:\\DOCUME~1\\user\\LOCALS~1\\Temp\\test",
- "C:\\Documents and Settings\\user\\Local Settings\\Temp\\test"
- ],
- "regkey_deleted": [
- "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\5.0\\Cache\\Extensible Cache\\MSHist012018021520180216",
- "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\5.0\\Cache\\Extensible Cache\\MSHist012018021620180217"
- ],
- "file_deleted": [
- "C:\\Documents and Settings\\user\\Local Settings\\History\\History.IE5\\MSHist012018021520180216\\index.dat",
- "C:\\Documents and Settings\\user\\Local Settings\\History\\History.IE5\\MSHist012018021620180217\\index.dat"
- ],
- "directory_removed": [
- "C:\\Documents and Settings\\user\\Local Settings\\History\\History.IE5\\MSHist012018021620180217\\",
- "C:\\Documents and Settings\\user\\Local Settings\\History\\History.IE5\\MSHist012018021520180216\\"
- ],
- "file_exists": [
- "C:\\WINDOWS\\Installer\\{16E52445-1392-469F-9ADB-FC03AF00CD61}\\python_icon.exe",
- "C:\\WINDOWS\\system32\\rundll32.exe",
- "C:\\Program Files\\Internet Explorer\\IEXPLORE.EXE",
- "C:\\WINDOWS\\system32\\shell32.dll",
- "C:\\Documents and Settings\\user\\Desktop\\shell32.dll",
- "C:\\WINDOWS\\system32\\mspaint.exe",
- "C:\\Python27\\python.exe",
- "C:\\Documents and Settings\\user\\Local Settings\\Temp\\test",
- "C:\\Documents and Settings\\user\\Local Settings\\History\\desktop.ini",
- "C:\\Documents and Settings\\user\\Local Settings\\History\\History.IE5\\MSHist012018021620180217\\",
- "C:\\Documents and Settings\\user\\Local Settings\\History\\History.IE5\\MSHist012018022320180224\\",
- "C:\\Documents and Settings\\user\\Local Settings\\History\\History.IE5\\MSHist012018021520180216\\",
- "C:\\WINDOWS\\system32\\shimgvw.dll",
- "C:\\WINDOWS\\system32\\url.dll",
- "C:\\Documents and Settings\\user\\Local Settings\\History\\History.IE5\\MSHist012018021520180216\\desktop.ini",
- "C:\\Documents and Settings\\user\\Local Settings\\History\\History.IE5\\MSHist012018021620180217\\desktop.ini",
- "C:\\WINDOWS\\Installer\\desktop.ini",
- "C:\\WINDOWS\\system32\\usmt\\migwiz.exe",
- "C:\\WINDOWS\\system32\\notepad.exe",
- "C:\\WINDOWS\\system32\\shell32.dll.manifest",
- "C:\\WINDOWS\\",
- "C:\\Documents and Settings\\user\\Local Settings\\History\\History.IE5\\MSHist012018021220180219\\",
- "C:\\Program Files\\Windows NT\\Accessories\\wordpad.exe",
- "C:\\Documents and Settings\\user\\Local Settings\\Temp\\test:Zone.Identifier",
- "C:\\WINDOWS\\system32\\mshtml.dll"
- ],
- "mutex": [
- "c:!documents and settings!user!local settings!history!history.ie5!mshist012018021220180219!",
- "ZonesCacheCounterMutex",
- "c:!documents and settings!user!local settings!history!history.ie5!mshist012018021520180216!",
- "Shell.CMruPidlList",
- "c:!documents and settings!user!local settings!history!history.ie5!mshist012018022320180224!",
- "ZonesCounterMutex",
- "ZonesLockedCacheCounterMutex"
- ],
- "file_failed": [
- "C:\\WINDOWS\\system32\\comctl32.dll.124.Config",
- "C:\\WINDOWS\\system32\\comctl32.dll.124.Manifest"
- ],
- "guid": [
- "{00000000-0000-0000-0000-000000000000}",
- "{a5aca655-7fb8-43dc-a433-8d87b69c70a0}",
- "{062e1261-a60e-11d0-82c2-00c04fd5ae38}",
- "{9ba05972-f6a8-11cf-a442-00a0c90a8f39}",
- "{0c6c4200-c589-11d0-999a-00c04fd655e1}",
- "{25336920-03f9-11cf-8fd0-00aa00686f13}",
- "{5b4dae26-b807-11d0-9815-00c04fd91972}",
- "{42aedc87-2188-41fd-b9a3-0c966feabec1}",
- "{00000000-0000-0000-c000-000000000046}",
- "{38f69b16-f583-40fb-b262-5c764de868e8}",
- "{79eac9ee-baf9-11ce-8c82-00aa004ba90b}",
- "{01e04581-4eee-11d0-bfe9-00aa005b4383}",
- "{eb0fe172-1a3a-11d0-89b3-00a0c90a90ac}",
- "{000214e6-0000-0000-c000-000000000046}",
- "{00000001-0000-0000-c000-000000000046}",
- "{ff393560-c2a7-11cf-bff4-444553540000}",
- "{47851649-a2ef-4e67-baec-c6a153ac72ec}",
- "{750fdf0e-2a26-11d1-a3ea-080036587f03}",
- "{a5e46e3a-8849-11d1-9d8c-00c04fc99d61}",
- "{85cb6900-4d95-11cf-960c-0080c7f4ee85}",
- "{7eb5fbe4-2100-49e6-8593-17e130122f91}",
- "{fadb55b4-d382-4fc4-81d7-abb325c7f12a}",
- "{79eac9ef-baf9-11ce-8c82-00aa004ba90b}",
- "{50d5107a-d278-4871-8989-f4ceaaf59cfc}",
- "{7b8a2d95-0ac9-11d1-896c-00c04fb6bfc4}",
- "{7b8a2d94-0ac9-11d1-896c-00c04fb6bfc4}",
- "{ee1f7637-e138-11d1-8379-00c04fd918d0}",
- "{3050f406-98b5-11cf-bb82-00aa00bdce0b}",
- "{08c0e040-62d1-11d1-9326-0060b067b86e}"
- ],
- "file_read": [
- "C:\\Documents and Settings\\All Users\\Start Menu\\Programs\\Python 2.7\\Python (command line).lnk",
- "C:\\Program Files\\Internet Explorer\\IEXPLORE.EXE",
- "C:\\WINDOWS\\system32\\shell32.dll",
- "C:\\Documents and Settings\\All Users\\Start Menu\\Programs\\MSN.lnk",
- "C:\\WINDOWS\\system32\\shimgvw.dll",
- "C:\\WINDOWS\\system32\\url.dll",
- "C:\\Documents and Settings\\user\\Local Settings\\History\\desktop.ini",
- "C:\\WINDOWS\\explorer.exe",
- "C:\\WINDOWS\\system32\\mspaint.exe",
- "C:\\Program Files\\Windows NT\\Accessories\\wordpad.exe",
- "C:\\Python27\\python.exe",
- "C:\\WINDOWS\\system32\\notepad.exe",
- "C:\\Documents and Settings\\user\\Local Settings\\Temp\\test",
- "C:\\WINDOWS\\system32\\mshtml.dll",
- "C:\\Documents and Settings\\All Users\\Start Menu\\Programs\\Accessories\\System Tools\\Files and Settings Transfer Wizard.lnk"
- ],
- "regkey_read": [
- "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\ShellNoRoam\\MUICache\\@explorer.exe,-7005",
- "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\{450D8FBA-AD25-11D0-98A8-0800361B1103}\\ShellFolder\\HideFolderVerbs",
- "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Applications\\accwiz.exe\\NoOpenWith",
- "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Applications\\wordpad.exe\\shell\\open\\FriendlyAppName",
- "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\5.0\\Cache\\Extensible Cache\\MSHist012018022320180224\\CachePrefix",
- "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\{25336920-03F9-11CF-8FD0-00AA00686F13}\\ProgID\\(Default)",
- "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\Zones\\1\\RecommendedLevel",
- "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\{FF393560-C2A7-11CF-BFF4-444553540000}\\DocObject",
- "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\htmlfile\\IsShortcut",
- "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\policies\\NonEnum\\{450D8FBA-AD25-11D0-98A8-0800361B1103}",
- "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Applications\\ORGCHART.EXE\\NoOpenWith",
- "HKEY_CURRENT_USER\\Software\\Microsoft\\Internet Explorer\\International\\Scripts\\3\\IEFontSize",
- "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\BrowseNewProcess\\BrowseNewProcess",
- "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\Lockdown_Zones\\0\\RecommendedLevel",
- "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\{2559a1f7-21d7-11d4-bdaf-00c04f60b9f0}\\ShellFolder\\CallForAttributes",
- "HKEY_CURRENT_USER\\Software\\Microsoft\\Internet Explorer\\Toolbar\\(Default)",
- "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Services\\Tcpip\\Parameters\\Hostname",
- "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\IEHardenWarnOnNav",
- "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\{2559a1f1-21d7-11d4-bdaf-00c04f60b9f0}\\InfoTip",
- "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\CLSID\\{450D8FBA-AD25-11D0-98A8-0800361B1103}\\(Default)",
- "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\ShellNoRoam\\BagMRU\\0\\0",
- "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\Url History\\DaysToKeep",
- "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\exefile\\NeverShowExt",
- "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Internet Explorer\\Main\\FeatureControl\\FEATURE_MIME_HANDLING\\iexplore.exe",
- "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\policies\\NonEnum\\{2559A1F4-21D7-11D4-BDAF-00C04F60B9F0}",
- "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Applications\\snapview.exe\\NoOpenWith",
- "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\SystemFileAssociations\\text\\IsShortcut",
- "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Policies\\Explorer\\NoNetConnectDisconnect",
- "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\{2559a1f3-21d7-11d4-bdaf-00c04f60b9f0}\\ShellFolder\\WantsFORDISPLAY",
- "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Applications\\mshta.exe\\NoOpenWith",
- "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\ProxyEnable",
- "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\{25336920-03F9-11CF-8FD0-00AA00686F13}\\AppID",
- "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\Zones\\3\\Icon",
- "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\UrlEncoding",
- "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\policies\\NonEnum\\{2559A1F7-21D7-11D4-BDAF-00C04F60B9F0}",
- "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Applications\\MSInfo32.exe\\NoOpenWith",
- "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\{2559a1f5-21d7-11d4-bdaf-00c04f60b9f0}\\ShellFolder\\Attributes",
- "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\ZoneMap\\ProtocolDefaults\\about",
- "HKEY_CURRENT_USER\\Software\\Microsoft\\Internet Explorer\\Main\\Display Inline Images",
- "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Applications\\msimn.exe\\NoOpenWith",
- "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\Zones\\0\\Flags",
- "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\PROTOCOLS\\Handler\\about\\CLSID",
- "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\{450D8FBA-AD25-11D0-98A8-0800361B1103}\\ShellFolder\\WantsFORDISPLAY",
- "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\ShellNoRoam\\MUICache\\C:\\WINDOWS\\system32\\shimgvw.dll",
- "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Applications\\perfmon.exe\\NoOpenWith",
- "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\{A5E46E3A-8849-11D1-9D8C-00C04FC99D61}\\InProcServer32\\(Default)",
- "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\{2559a1f3-21d7-11d4-bdaf-00c04f60b9f0}\\ShellFolder\\Attributes",
- "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\ShellNoRoam\\BagMRU\\0\\1\\0\\NodeSlot",
- "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Applications\\mobsync.exe\\NoOpenWith",
- "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Applications\\mspaint.exe\\NoOpenWith",
- "HKEY_CURRENT_USER\\Software\\Microsoft\\Internet Explorer\\Toolbar\\Layout",
- "HKEY_CURRENT_USER\\Software\\Microsoft\\Internet Explorer\\Toolbar\\ShowDiscussionButton",
- "HKEY_CLASSES_ROOT\\PerceivedType",
- "HKEY_CURRENT_USER\\Software\\Microsoft\\Internet Explorer\\International\\Scripts\\3\\IEFixedFontName",
- "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\{7b8a2d94-0ac9-11d1-896c-00c04Fb6bfc4}\\InprocServer32\\(Default)",
- "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\Zones\\4\\DisplayName",
- "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\.htm\\PerceivedType",
- "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\{2559a1f7-21d7-11d4-bdaf-00c04f60b9f0}\\ShellFolder\\Attributes",
- "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Internet Explorer\\Main\\CheckDocumentForProgID",
- "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\DevicePath",
- "HKEY_CURRENT_USER\\Software\\Microsoft\\Internet Explorer\\Toolbar\\SmallBitmap",
- "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\IEHardenWarnOnNav",
- "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\Zones\\1\\MinLevel",
- "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Applications\\icwconn1.exe\\NoOpenWith",
- "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\\InProcServer32\\(Default)",
- "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\5.0\\Cache\\Extensible Cache\\MSHist012018022320180224\\CachePath",
- "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\UrlEncoding",
- "HKEY_CURRENT_USER\\Software\\Microsoft\\Internet Explorer\\Main\\AlwaysAllowExecCommand",
- "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\FontSubstitutes\\MS Shell Dlg 2",
- "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\LockDown_zones\\0\\RecommendedLevel",
- "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\Advanced\\MapNetDrvBtn",
- "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\ShellNoRoam\\MUICache\\@shell32.dll,-21779",
- "HKEY_CURRENT_USER\\Software\\Microsoft\\Internet Explorer\\Main\\Use Stylesheets",
- "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\5.0\\Cache\\Extensible Cache\\MSHist012018021520180216\\CachePath",
- "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\Zones\\2\\Flags",
- "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\{2227A280-3AEA-1069-A2DE-08002B30309D}\\LocalizedString",
- "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Control\\Nls\\CodePage\\950",
- "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Policies\\Explorer\\NoToolbarCustomize",
- "HKEY_CURRENT_USER\\Software\\Microsoft\\Internet Explorer\\Extensions\\CmdMapping\\{e2e2dd38-d088-4134-82b7-f2ba38496583}",
- "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\ShellNoRoam\\MUICache\\@C:\\WINDOWS\\system32\\SHELL32.dll,-9319",
- "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Internet Explorer\\Main\\Enable Browser Extensions",
- "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\Zones\\4\\Description",
- "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\ShellNoRoam\\BagMRU\\0\\NodeSlot",
- "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\Zones\\3\\MinLevel",
- "HKEY_CURRENT_USER\\Software\\Microsoft\\Internet Explorer\\Settings\\Always Use My Font Size",
- "HKEY_CURRENT_USER\\Software\\Microsoft\\Internet Explorer\\Main\\Q300829",
- "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\SystemFileAssociations\\text\\shell\\edit\\command\\(Default)",
- "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Applications\\zipfldr.dll\\NoOpenWith",
- "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\ZoneMap\\IEharden",
- "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Applications\\mplayer.exe\\NoOpenWith",
- "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\exefile\\IsShortcut",
- "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\{2559a1f1-21d7-11d4-bdaf-00c04f60b9f0}\\ShellFolder\\CallForAttributes",
- "HKEY_CURRENT_USER\\Software\\Microsoft\\Internet Explorer\\Toolbar\\Locked",
- "HKEY_CURRENT_USER\\Software\\Microsoft\\Internet Explorer\\Main\\Enable AutoImageResize",
- "HKEY_LOCAL_MACHINE\\SYSTEM\\Setup\\SystemPartition",
- "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\Zones\\4\\CurrentLevel",
- "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\ShellNoRoam\\BagMRU\\0\\1\\0",
- "HKEY_CURRENT_USER\\Software\\Microsoft\\Internet Explorer\\Security\\P3Global\\Enabled",
- "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\htmlfile\\BrowseInPlace",
- "HKEY_CURRENT_USER\\Control Panel\\Desktop\\SmoothScroll",
- "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\Advanced\\ListviewShadow",
- "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Services\\Tcpip\\Parameters\\Domain",
- "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\.lnk\\(Default)",
- "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\5.0\\Cache\\Extensible Cache\\MSHist012018021220180219\\CacheOptions",
- "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Applications\\moviemk.exe\\NoOpenWith",
- "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\{2559a1f4-21d7-11d4-bdaf-00c04f60b9f0}\\ShellFolder\\CallForAttributes",
- "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Shell Extensions\\Cached\\{FF393560-C2A7-11CF-BFF4-444553540000} {062E1261-A60E-11D0-82C2-00C04FD5AE38} 0x401",
- "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\{2559a1f1-21d7-11d4-bdaf-00c04f60b9f0}\\ShellFolder\\WantsFORDISPLAY",
- "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\Advanced\\ListviewAlphaSelect",
- "HKEY_LOCAL_MACHINE\\SOFTWARE\\Clients\\News\\(Default)",
- "HKEY_CURRENT_USER\\Software\\Microsoft\\Internet Explorer\\International\\AcceptLanguage",
- "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Applications\\shscrap.dll\\NoOpenWith",
- "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Applications\\graflink.exe\\NoOpenWith",
- "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Internet Explorer\\International\\CheckVersion",
- "HKEY_CURRENT_USER\\Software\\Microsoft\\Internet Explorer\\Main\\ShowGoButton",
- "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\{0002DF01-0000-0000-C000-000000000046}\\LocalServer32\\LocalServer32",
- "HKEY_LOCAL_MACHINE\\SYSTEM\\Setup\\SystemSetupInProgress",
- "HKEY_CURRENT_USER\\Software\\Microsoft\\Internet Explorer\\Toolbar\\NoText",
- "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Internet Explorer\\Extensions\\{e2e2dd38-d088-4134-82b7-f2ba38496583}\\ButtonText",
- "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Applications\\wpnpinst.exe\\NoOpenWith",
- "HKEY_CURRENT_USER\\AppEvents\\Schemes\\Apps\\.Default\\MenuPopup\\.Current\\(Default)",
- "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\5.0\\Cache\\Extensible Cache\\MSHist012018021620180217\\CachePath",
- "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Internet Explorer\\Main\\ShowGoButton",
- "HKEY_CURRENT_USER\\Software\\Microsoft\\Internet Explorer\\Show_FullURL",
- "HKEY_CURRENT_USER\\Software\\Microsoft\\Internet Explorer\\New Windows\\EnableHooks",
- "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\{2559a1f1-21d7-11d4-bdaf-00c04f60b9f0}\\ShellFolder\\Attributes",
- "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\{750fdf0e-2a26-11d1-a3ea-080036587f03}\\InProcServer32\\LoadWithoutCOM",
- "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Internet Explorer\\Main\\FeatureControl\\FEATURE_DISABLE_MK_PROTOCOL\\iexplore.exe",
- "HKEY_CURRENT_USER\\Software\\Microsoft\\Internet Explorer\\Main\\Q331869",
- "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Shell Extensions\\Blocked\\{FF393560-C2A7-11CF-BFF4-444553540000}",
- "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Applications\\CMMGR32.EXE\\NoOpenWith",
- "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\FontSubstitutes\\Tahoma",
- "HKEY_CURRENT_USER\\Software\\Microsoft\\Internet Explorer\\Main\\Move System Caret",
- "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Applications\\msconf.dll\\NoOpenWith",
- "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\{0002DF01-0000-0000-C000-000000000046}\\LocalServer32\\(Default)",
- "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Applications\\sndvol32.exe\\NoOpenWith",
- "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\ShellIconOverlayIdentifiers\\Offline Files\\(Default)",
- "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\{450D8FBA-AD25-11D0-98A8-0800361B1103}\\LocalizedString",
- "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\ProfileList\\S-1-5-21-839522115-813497703-1060284298-1003\\Flags",
- "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\{FBF23B42-E3F0-101B-8488-00AA003E56F8}\\InProcServer32\\(Default)",
- "HKEY_CURRENT_USER\\Software\\Microsoft\\Internet Explorer\\Settings\\Anchor Color Visited",
- "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Directory\\AlwaysShowExt",
- "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Ext\\Stats\\{E2E2DD38-D088-4134-82B7-F2BA38496583}\\iexplore\\Count",
- "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\Lockdown_Zones\\0\\2100",
- "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\Zones\\2\\MinLevel",
- "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Applications\\faxcover.exe\\NoOpenWith",
- "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Applications\\datainst.exe\\NoOpenWith",
- "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\{750fdf0e-2a26-11d1-a3ea-080036587f03}\\InProcServer32\\(Default)",
- "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Applications\\Ttxmpc97.exe\\NoOpenWith",
- "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\ShellNoRoam\\BagMRU\\NodeSlot",
- "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\ShellNoRoam\\MUICache\\@explorer.exe,-7004",
- "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Applications\\helpctr.exe\\NoOpenWith",
- "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\ShellNoRoam\\MUICache\\@explorer.exe,-7001",
- "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\ShellNoRoam\\BagMRU\\MRUListEx",
- "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Applications\\mspaint.exe\\shell\\edit\\command\\(Default)",
- "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\{2227A280-3AEA-1069-A2DE-08002B30309D}\\ShellFolder\\WantsFORDISPLAY",
- "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\MountPoints2\\CPC\\Volume\\{ef61f5f2-1227-11e8-94f0-806d6172696f}\\Data",
- "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\ProfileList\\S-1-5-21-839522115-813497703-1060284298-1003\\UserPreference",
- "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\policies\\NonEnum\\{2559A1F5-21D7-11D4-BDAF-00C04F60B9F0}",
- "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\ShellNoRoam\\BagMRU\\NodeSlots",
- "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Internet Explorer\\IntegratedBrowser",
- "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Control\\Session Manager\\AppCompatibility\\DisableAppCompat",
- "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\{FF393560-C2A7-11CF-BFF4-444553540000}\\BrowseInPlace",
- "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Applications\\Outlook.EXE\\NoOpenWith",
- "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Applications\\cryptext.dll\\NoOpenWith",
- "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\DisableCachingOfSSLPages",
- "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Directory\\BrowseInPlace",
- "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\exefile\\BrowseInPlace",
- "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Applications\\MMC.exe\\NoOpenWith",
- "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Applications\\realmon.exe\\NoOpenWith",
- "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Applications\\regedit.exe\\NoOpenWith",
- "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Applications\\CChat.exe\\NoOpenWith",
- "HKEY_CURRENT_USER\\Software\\Microsoft\\Internet Explorer\\Toolbar\\BackBitmapShell",
- "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Applications\\rasphone.exe\\NoOpenWith",
- "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\SystemFileAssociations\\text\\NeverShowExt",
- "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Applications\\shimgvw.dll\\shell\\open\\FriendlyAppName",
- "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\RunMRU\\a",
- "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\policies\\NonEnum\\{2559A1F0-21D7-11D4-BDAF-00C04F60B9F0}",
- "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\ShellNoRoam\\MUICache\\@explorer.exe,-7020",
- "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\MIME\\Database\\Content Type\\text/plain\\CLSID",
- "HKEY_CURRENT_USER\\Software\\Microsoft\\Internet Explorer\\Settings\\MiscFlags",
- "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\{2227A280-3AEA-1069-A2DE-08002B30309D}\\ShellFolder\\CallForAttributes",
- "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\{7b8a2d95-0ac9-11d1-896c-00c04Fb6bfc4}\\InprocServer32\\(Default)",
- "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\{2559a1f5-21d7-11d4-bdaf-00c04f60b9f0}\\ShellFolder\\CallForAttributes",
- "HKEY_CURRENT_USER\\Software\\Microsoft\\Internet Explorer\\Main\\Enable Browser Extensions",
- "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\htmlfile\\DefaultIcon\\(Default)",
- "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\Zones\\2\\RecommendedLevel",
- "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\ProfileList\\S-1-5-21-839522115-813497703-1060284298-1003\\ProfileImagePath",
- "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Directory\\IsShortcut",
- "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\SystemFileAssociations\\text\\DocObject",
- "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\5.0\\Cache\\Extensible Cache\\MSHist012018021520180216\\CacheLimit",
- "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\Zones\\3\\RecommendedLevel",
- "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Applications\\navwnt.exe\\NoOpenWith",
- "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\5.0\\Cache\\Extensible Cache\\MSHist012018021220180219\\CacheRepair",
- "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\policies\\NonEnum\\{2559A1F3-21D7-11D4-BDAF-00C04F60B9F0}",
- "HKEY_CURRENT_USER\\Software\\Microsoft\\Internet Explorer\\Main\\Disable_Local_Machine_Navigate",
- "HKEY_CURRENT_USER\\Software\\Microsoft\\Internet Explorer\\Main\\UseHR",
- "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\5.0\\Cache\\Extensible Cache\\MSHist012018021620180217\\CachePrefix",
- "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\Zones\\3\\CurrentLevel",
- "HKEY_CURRENT_USER\\Software\\Microsoft\\Internet Explorer\\Main\\Force Offscreen Composition",
- "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Applications\\dsquery.dll\\NoOpenWith",
- "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Applications\\url.dll\\NoOpenWith",
- "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Policies\\Explorer\\NoCommonGroups",
- "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\Zones\\4\\Icon",
- "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Setup\\DriverCachePath",
- "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\Lockdown_Zones\\0\\Description",
- "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\DisableImprovedZoneCheck",
- "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\5.0\\Cache\\Extensible Cache\\MSHist012018022320180224\\CacheLimit",
- "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\LockDown_zones\\0\\MinLevel",
- "HKEY_CURRENT_USER\\Software\\Microsoft\\Internet Explorer\\Main\\Disable Script Debugger",
- "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\{01E04581-4EEE-11d0-BFE9-00AA005B4383}\\InProcServer32\\(Default)",
- "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Policies\\Explorer\\NoPropertiesMyComputer",
- "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\Zones\\1\\Description",
- "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Directory\\NeverShowExt",
- "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\Zones\\2\\Icon",
- "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Applications\\python.exe\\shell\\open\\command\\(Default)",
- "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Applications\\shell32.dll\\NoOpenWith",
- "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Policies\\Explorer\\NoNetHood",
- "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\{FF393560-C2A7-11CF-BFF4-444553540000}\\InProcServer32\\(Default)",
- "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Applications\\notepad.exe\\shell\\open\\command\\(Default)",
- "HKEY_CURRENT_USER\\Software\\Microsoft\\Internet Explorer\\RtfConverterFlags",
- "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\htmlfile\\CLSID\\(Default)",
- "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Internet Explorer\\Extensions\\{e2e2dd38-d088-4134-82b7-f2ba38496583}\\MenuStatusBar",
- "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\Lockdown_Zones\\0\\MinLevel",
- "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Applications\\depends.exe\\NoOpenWith",
- "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Applications\\oledb32.dll\\NoOpenWith",
- "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Applications\\mnyimprt.exe\\NoOpenWith",
- "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\Zones\\2\\DisplayName",
- "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Applications\\shdocvw.dll\\NoOpenWith",
- "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\{2559a1f4-21d7-11d4-bdaf-00c04f60b9f0}\\ShellFolder\\Attributes",
- "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\ShellNoRoam\\BagMRU\\0\\4",
- "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Internet Explorer\\Extensions\\{e2e2dd38-d088-4134-82b7-f2ba38496583}\\MenuText",
- "HKEY_CURRENT_USER\\Software\\Microsoft\\Internet Explorer\\Main\\Play_Animations",
- "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\ShellNoRoam\\BagMRU\\0\\1\\MRUListEx",
- "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Applications\\WINWORD.EXE\\NoOpenWith",
- "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\policies\\NonEnum\\{2227A280-3AEA-1069-A2DE-08002B30309D}",
- "HKEY_CURRENT_USER\\Software\\Microsoft\\Internet Explorer\\Settings\\Use Anchor Hover Color",
- "HKEY_CURRENT_USER\\Software\\Microsoft\\Internet Explorer\\International\\Default_CodePage",
- "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\exefile\\AlwaysShowExt",
- "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Internet Explorer\\Extensions\\{e2e2dd38-d088-4134-82b7-f2ba38496583}\\clsid",
- "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Applications\\grpconv.exe\\NoOpenWith",
- "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Applications\\winhlp32.exe\\NoOpenWith",
- "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\htmlfile\\NeverShowExt",
- "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\{2559a1f0-21d7-11d4-bdaf-00c04f60b9f0}\\ShellFolder\\CallForAttributes",
- "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Shell Extensions\\Cached\\{FF393560-C2A7-11CF-BFF4-444553540000} {000214E6-0000-0000-C000-000000000046} 0x401",
- "HKEY_CURRENT_USER\\Software\\Microsoft\\Internet Explorer\\International\\Scripts\\Default_IEFontSize",
- "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Applications\\WB32.EXE\\NoOpenWith",
- "HKEY_CURRENT_USER\\Software\\Microsoft\\Internet Explorer\\Settings\\Anchor Color",
- "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\5.0\\Cache\\Extensible Cache\\MSHist012018021520180216\\CacheRepair",
- "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\.htm\\Content Type",
- "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\Advanced\\ListviewWatermark",
- "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\{2559a1f1-21d7-11d4-bdaf-00c04f60b9f0}\\QueryForInfoTip",
- "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\COM3\\REGDBVersion",
- "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\http\\DefaultIcon\\(Default)",
- "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\ShellNoRoam\\MUICache\\@xpsp1res.dll,-10077",
- "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Applications\\inoculan.exe\\NoOpenWith",
- "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Policies\\Explorer\\CompareJunctionness",
- "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Policies\\Explorer\\NoShellSearchButton",
- "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\ShellNoRoam\\MUICache\\C:\\WINDOWS\\system32\\mspaint.exe",
- "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Policies\\Explorer\\NoSetFolders",
- "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\{FF393560-C2A7-11CF-BFF4-444553540000}\\InProcServer32\\LoadWithoutCOM",
- "HKEY_CURRENT_USER\\Software\\Microsoft\\Internet Explorer\\Main\\Print_Background",
- "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\{2559a1f0-21d7-11d4-bdaf-00c04f60b9f0}\\ShellFolder\\Attributes",
- "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Applications\\notepad.exe\\shell\\(Default)",
- "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\Zones\\4\\MinLevel",
- "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Applications\\shimgvw.dll\\shell\\(Default)",
- "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FileAssociation\\CutList",
- "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\Zones\\1\\Flags",
- "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Applications\\python.exe\\NoOpenWith",
- "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\Zones\\1\\CurrentLevel",
- "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Applications\\OSA.EXE\\NoOpenWith",
- "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\Lockdown_Zones\\0\\CurrentLevel",
- "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Policies\\Explorer\\SpecifyDefaultButtons",
- "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FileExts\\.htm\\Application",
- "HKEY_LOCAL_MACHINE\\SYSTEM\\WPA\\PnP\\seed",
- "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Applications\\notepad.exe\\shell\\open\\FriendlyAppName",
- "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\ShellNoRoam\\MUICache\\@xpsp3res.dll,-20001",
- "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Internet Explorer\\Main\\FeatureControl\\FEATURE_BEHAVIORS\\iexplore.exe",
- "HKEY_CURRENT_USER\\Software\\Microsoft\\Internet Explorer\\Main\\Play_Background_Sounds",
- "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\{25336920-03F9-11CF-8FD0-00AA00686F13}\\InProcServer32\\InprocServer32",
- "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Shell Extensions\\Cached\\{FF393560-C2A7-11CF-BFF4-444553540000} {062E1261-A60E-11D0-82C2-00C04FD5AE38} 0x401",
- "HKEY_CURRENT_USER\\Software\\Microsoft\\Internet Explorer\\Toolbar\\ShowFonts",
- "HKEY_CURRENT_USER\\Software\\Microsoft\\Internet Explorer\\Main\\Display Inline Videos",
- "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\ShellIconOverlayIdentifiers\\Offline Files\\SuppressionPolicy",
- "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\5.0\\Cache\\Extensible Cache\\MSHist012018021520180216\\CachePrefix",
- "HKEY_CURRENT_USER\\Software\\Microsoft\\Internet Explorer\\Toolbar\\{1E796980-9CC5-11D1-A83F-00C04FC99D61}",
- "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Applications\\hh.exe\\NoOpenWith",
- "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\Zones\\4\\RecommendedLevel",
- "HKEY_CURRENT_USER\\Software\\Microsoft\\Internet Explorer\\Main\\Q051873",
- "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Applications\\ARTGALRY.EXE\\NoOpenWith",
- "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\\ShellFolder\\WantsFORDISPLAY",
- "HKEY_CURRENT_USER\\Control Panel\\International\\NumShape",
- "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\Zones\\2\\Description",
- "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\Lockdown_Zones\\0\\1809",
- "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Applications\\wordpad.exe\\NoOpenWith",
- "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\ZoneMap\\ProtocolDefaults\\*",
- "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\{2559a1f4-21d7-11d4-bdaf-00c04f60b9f0}\\QueryForInfoTip",
- "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\{2559a1f0-21d7-11d4-bdaf-00c04f60b9f0}\\LocalizedString",
- "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Policies\\Explorer\\SmallIcons",
- "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\policies\\NonEnum\\{2559A1F1-21D7-11D4-BDAF-00C04F60B9F0}",
- "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Setup\\LogPath",
- "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Policies\\Explorer\\AllowFileCLSIDJunctions",
- "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Applications\\shimgvw.dll\\NoOpenWith",
- "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\\ShellFolder\\Attributes",
- "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\Max Cached Icons",
- "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Applications\\wab.exe\\NoOpenWith",
- "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\5.0\\Cache\\Extensible Cache\\MSHist012018021620180217\\CacheOptions",
- "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Shell Extensions\\Blocked\\{FF393560-C2A7-11CF-BFF4-444553540000}",
- "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\ShellNoRoam\\MUICache\\@%SystemRoot%\\system32\\usmt\\migwiz.exe,-203",
- "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Applications\\netshell.dll\\NoOpenWith",
- "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\5.0\\Cache\\Extensible Cache\\MSHist012018021620180217\\CacheLimit",
- "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Applications\\wordpad.exe\\shell\\(Default)",
- "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\SystemFileAssociations\\text\\BrowseInPlace",
- "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Internet Explorer\\Extensions\\{e2e2dd38-d088-4134-82b7-f2ba38496583}\\Script",
- "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\5.0\\Cache\\Extensible Cache\\MSHist012018022320180224\\CacheOptions",
- "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\Advanced\\UseDoubleClickTimer",
- "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\policies\\NonEnum\\{20D04FE0-3AEA-1069-A2D8-08002B30309D}",
- "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows NT\\CurrentVersion\\Windows\\DragDelay",
- "HKEY_CURRENT_USER\\Software\\Microsoft\\Internet Explorer\\Settings\\Always Use My Font Face",
- "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\IsTextPlainHonored",
- "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Applications\\clipbrd.exe\\NoOpenWith",
- "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Setup\\SourcePath",
- "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\Zones\\1\\DisplayName",
- "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\Advanced\\ListviewScrollOver",
- "HKEY_CURRENT_USER\\Control Panel\\Desktop\\WindowMetrics\\Shell Small Icon Size",
- "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Applications\\mspaint.exe\\shell\\edit\\FriendlyAppName",
- "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\ShellNoRoam\\MUICache\\C:\\Python27\\python.exe",
- "HKEY_CURRENT_USER\\Software\\Microsoft\\Internet Explorer\\Toolbar\\BackBitmap",
- "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Applications\\finder.exe\\NoOpenWith",
- "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\ShellNoRoam\\BagMRU\\0\\1\\0\\MRUListEx",
- "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Applications\\mspaint.exe\\shell\\(Default)",
- "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\5.0\\Cache\\Extensible Cache\\MSHist012018022320180224\\CacheRepair",
- "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\5.0\\Cache\\Extensible Cache\\MSHist012018021220180219\\CacheLimit",
- "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\.html\\Content Type",
- "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\{5b4dae26-b807-11d0-9815-00c04fd91972}\\InProcServer32\\(Default)",
- "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\{FF393560-C2A7-11CF-BFF4-444553540000}\\NeverShowExt",
- "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Applications\\shimgvw.dll\\shell\\open\\command\\(Default)",
- "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\ZoneMap\\ProtocolDefaults\\*",
- "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\{2559a1f1-21d7-11d4-bdaf-00c04f60b9f0}\\LocalizedString",
- "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Directory\\DocObject",
- "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\ShellNoRoam\\MUICache\\@shell32.dll,-21790",
- "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Internet Explorer\\Main\\FeatureControl\\FEATURE_OBJECT_CACHING\\iexplore.exe",
- "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Policies\\Explorer\\NoInternetIcon",
- "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Applications\\rnaui.dll\\NoOpenWith",
- "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Policies\\Explorer\\NoFileAssociate",
- "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Applications\\iexplore.exe\\shell\\(Default)",
- "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Policies\\Explorer\\NoRecentDocsHistory",
- "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Shell Extensions\\Cached\\{FF393560-C2A7-11CF-BFF4-444553540000} {000214E6-0000-0000-C000-000000000046} 0x401",
- "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\Advanced\\ClassicViewState",
- "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\ShellNoRoam\\BagMRU\\0\\1\\NodeSlot",
- "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\Zones\\2\\CurrentLevel",
- "HKEY_CURRENT_USER\\Software\\Microsoft\\Internet Explorer\\SmartDithering",
- "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Policies\\Explorer\\UsePathEnvVarForCommandTemplates",
- "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Applications\\fpidcwiz.exe\\NoOpenWith",
- "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\ProfileList\\S-1-5-21-839522115-813497703-1060284298-1003\\ProfileLoadTimeLow",
- "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\ShellNoRoam\\BagMRU Size",
- "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\Advanced\\ListviewScrollOver",
- "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Internet Explorer\\Main\\FeatureControl\\FEATURE_LOCALMACHINE_LOCKDOWN\\iexplore.exe",
- "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\.lnk\\ShellEx\\{00021500-0000-0000-C000-000000000046}\\(Default)",
- "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Policies\\Explorer\\NoInternetOpenWith",
- "HKEY_CURRENT_USER\\Software\\Microsoft\\Internet Explorer\\New Windows\\PopupMgr",
- "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Applications\\awdvstub.exe\\NoOpenWith",
- "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\ZoneMap\\ProtocolDefaults\\about",
- "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\{2227A280-3AEA-1069-A2DE-08002B30309D}\\ShellFolder\\Attributes",
- "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Applications\\iexplore.exe\\NoOpenWith",
- "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\RunMRU\\MRUList",
- "HKEY_CURRENT_USER\\Software\\Microsoft\\Internet Explorer\\International\\AutoDetect",
- "HKEY_CURRENT_USER\\Software\\Microsoft\\Internet Explorer\\Main\\StatusBarWeb",
- "HKEY_CURRENT_USER\\Software\\Microsoft\\Internet Explorer\\Toolbar\\BrandBitmap",
- "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Internet Explorer\\Main\\FeatureControl\\FEATURE_ZONE_ELEVATION\\iexplore.exe",
- "HKEY_CURRENT_USER\\Software\\Microsoft\\Internet Explorer\\Main\\Anchor Underline",
- "HKEY_CURRENT_USER\\Software\\Microsoft\\Internet Explorer\\Main\\Page_Transitions",
- "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Setup\\ServicePackSourcePath",
- "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\ShellNoRoam\\MUICache\\C:\\Program Files\\Windows NT\\Accessories\\WORDPAD.EXE",
- "HKEY_CURRENT_USER\\Control Panel\\Desktop\\WindowMetrics\\Shell Icon Size",
- "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Applications\\drwatson.exe\\NoOpenWith",
- "HKEY_CURRENT_USER\\Software\\Microsoft\\Internet Explorer\\Toolbar\\BigBitmap",
- "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\{FF393560-C2A7-11CF-BFF4-444553540000}\\IsShortcut",
- "HKEY_CURRENT_USER\\Software\\Microsoft\\Internet Explorer\\Main\\Use_DlgBox_Colors",
- "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Applications\\ISIGNUP.EXE\\NoOpenWith",
- "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Drive\\shellex\\FolderExtensions\\{fbeb8a05-beee-4442-804e-409d6c4515e9}\\DriveMask",
- "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FileExts\\.htm\\Progid",
- "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Applications\\WScript.exe\\NoOpenWith",
- "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\5.0\\Cache\\Extensible Cache\\MSHist012018021620180217\\CacheRepair",
- "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Applications\\iexplore.exe\\shell\\open\\command\\(Default)",
- "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\{2559a1f4-21d7-11d4-bdaf-00c04f60b9f0}\\InfoTip",
- "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\ShellNoRoam\\BagMRU\\0\\1\\0\\0",
- "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Policies\\Explorer\\NoneLegacyShellMode",
- "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\Lockdown_Zones\\0\\DisplayName",
- "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\htmlfile\\AlwaysShowExt",
- "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\{2559a1f5-21d7-11d4-bdaf-00c04f60b9f0}\\QueryForInfoTip",
- "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Internet Explorer\\Main\\FeatureControl\\FEATURE_WINDOW_RESTRICTIONS\\iexplore.exe",
- "HKEY_LOCAL_MACHINE\\SYSTEM\\Setup\\OsLoaderPath",
- "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Applications\\cdfview.dll\\NoOpenWith",
- "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Policies\\Allow Programmatic Cut_Copy_Paste",
- "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\5.0\\Cache\\Extensible Cache\\MSHist012018021520180216\\CacheOptions",
- "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Applications\\msiexec.exe\\NoOpenWith",
- "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Internet Explorer\\Main\\FeatureControl\\FEATURE_WEBOC_POPUPMANAGEMENT\\iexplore.exe",
- "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\{2227A280-3AEA-1069-A2DE-08002B30309D}\\ShellFolder\\HideFolderVerbs",
- "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\ProfileList\\S-1-5-21-839522115-813497703-1060284298-1003\\State",
- "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Applications\\iexplore.exe\\shell\\open\\FriendlyAppName",
- "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Applications\\HYPERTRM.EXE\\NoOpenWith",
- "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\{2559a1f7-21d7-11d4-bdaf-00c04f60b9f0}\\ShellFolder\\WantsFORDISPLAY",
- "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\ShellNoRoam\\MUICache\\C:\\WINDOWS\\system32\\NOTEPAD.EXE",
- "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Policies\\Explorer\\NoControlPanel",
- "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Setup\\LogLevel",
- "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\MountPoints2\\CPC\\Volume\\{ef61f5f2-1227-11e8-94f0-806d6172696f}\\Generation",
- "HKEY_CURRENT_USER\\Software\\Microsoft\\Internet Explorer\\Main\\DisableScriptDebuggerIE",
- "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\ShellNoRoam\\MUICache\\@C:\\WINDOWS\\system32\\SHELL32.dll,-9227",
- "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\Zones\\3\\Flags",
- "HKEY_CURRENT_USER\\Software\\Microsoft\\Internet Explorer\\Settings\\Always Use My Colors",
- "HKEY_CURRENT_USER\\Software\\Microsoft\\Internet Explorer\\Settings\\Anchor Color Hover",
- "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Applications\\ntbackup.exe\\NoOpenWith",
- "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows NT\\CurrentVersion\\Windows\\DragScrollInterval",
- "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\{450D8FBA-AD25-11D0-98A8-0800361B1103}\\ShellFolder\\Attributes",
- "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\5.0\\Cache\\Extensible Cache\\MSHist012018021220180219\\CachePath",
- "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\{2559a1f3-21d7-11d4-bdaf-00c04f60b9f0}\\LocalizedString",
- "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Policies\\Explorer\\EnforceShellExtensionSecurity",
- "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Applications\\themes.exe\\NoOpenWith",
- "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\Zones\\3\\Description",
- "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows NT\\CurrentVersion\\Windows\\DragScrollInset",
- "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\ShellNoRoam\\BagMRU\\0",
- "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\Zones\\1\\Icon",
- "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\\LocalizedString",
- "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Internet Explorer\\Extensions\\{e2e2dd38-d088-4134-82b7-f2ba38496583}\\Exec",
- "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\*\\EditFlags",
- "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\5.0\\Cache\\Extensible Cache\\MSHist012018021220180219\\CachePrefix",
- "HKEY_CURRENT_USER\\Software\\Microsoft\\Internet Explorer\\Main\\Cleanup HTCs",
- "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\htmlfile\\DocObject",
- "HKEY_CURRENT_USER\\Control Panel\\Desktop\\WindowMetrics\\Shell Icon Bpp",
- "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\{25336920-03F9-11CF-8FD0-00AA00686F13}\\InProcServer32\\(Default)",
- "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows NT\\CurrentVersion\\Windows\\DragScrollDelay",
- "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\ShellNoRoam\\MUICache\\LangID",
- "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Internet Explorer\\Main\\FeatureControl\\FEATURE_MIME_SNIFFING\\iexplore.exe",
- "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Ole\\MaximumAllowedAllocationSize",
- "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\{9BA05972-F6A8-11CF-A442-00A0C90A8F39}\\InProcServer32\\(Default)",
- "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Applications\\notepad.exe\\NoOpenWith",
- "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\SystemFileAssociations\\text\\AlwaysShowExt",
- "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\ShellNoRoam\\MUICache\\@explorer.exe,-7021",
- "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\ShellNoRoam\\MUICache\\@explorer.exe,-7023",
- "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\.html\\(Default)",
- "HKEY_CURRENT_USER\\Software\\Microsoft\\Internet Explorer\\Main\\SmoothScroll",
- "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Policies\\Explorer\\AllowCLSIDPROGIDMapping",
- "HKEY_CURRENT_USER\\Software\\Microsoft\\Internet Explorer\\Main\\Enable_MyPics_Hoverbar",
- "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Applications\\kodakprv.EXE\\NoOpenWith",
- "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Internet Explorer\\Extensions\\{e2e2dd38-d088-4134-82b7-f2ba38496583}\\MenuCustomize",
- "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\ShellNoRoam\\BagMRU\\0\\1",
- "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Applications\\python.exe\\shell\\(Default)",
- "HKEY_CURRENT_USER\\Software\\Microsoft\\Internet Explorer\\Main\\Show image placeholders",
- "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Applications\\inetcpl.cpl\\NoOpenWith",
- "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Applications\\moviemk.exe\\shell\\(Default)",
- "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Applications\\python.exe\\shell\\open\\FriendlyAppName",
- "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FileExts\\OpenWithList\\MRUList",
- "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Applications\\wltmime.exe\\NoOpenWith",
- "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Applications\\fontview.exe\\NoOpenWith",
- "HKEY_CLASSES_ROOT\\(Default)",
- "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\MountPoints2\\CPC\\Volume\\{ef61f5f0-1227-11e8-94f0-806d6172696f}\\Generation",
- "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\.htm\\(Default)",
- "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\{2559a1f3-21d7-11d4-bdaf-00c04f60b9f0}\\ShellFolder\\CallForAttributes",
- "HKEY_CURRENT_USER\\Software\\Microsoft\\Internet Explorer\\Main\\Expand Alt Text",
- "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\Streams\\Settings",
- "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Applications\\cag.exe\\NoOpenWith",
- "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\{FF393560-C2A7-11CF-BFF4-444553540000}\\AlwaysShowExt",
- "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\ShellNoRoam\\BagMRU\\0\\MRUListEx",
- "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\ProfileList\\S-1-5-21-839522115-813497703-1060284298-1003\\ProfileLoadTimeHigh",
- "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\{2559a1f7-21d7-11d4-bdaf-00c04f60b9f0}\\LocalizedString",
- "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\MountPoints2\\CPC\\Volume\\{ef61f5f0-1227-11e8-94f0-806d6172696f}\\Data",
- "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Applications\\msrating.dll\\NoOpenWith",
- "HKEY_CURRENT_USER\\Software\\Microsoft\\Internet Explorer\\Main\\CheckDocumentForProgID",
- "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Applications\\explorer.exe\\NoOpenWith",
- "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Policies\\Explorer\\NoFileMenu",
- "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\.exe\\(Default)",
- "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\\ShellFolder\\HideFolderVerbs",
- "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\GRE_Initialize\\DisableMetaFiles",
- "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Internet Explorer\\Main\\FeatureControl\\FEATURE_PROTOCOL_LOCKDOWN\\iexplore.exe",
- "HKEY_CURRENT_USER\\Software\\Microsoft\\Internet Explorer\\Toolbar\\VisibleBands",
- "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Internet Explorer\\Main\\FeatureControl\\FEATURE_SAFE_BINDTOOBJECT\\iexplore.exe",
- "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\Zones\\4\\Flags",
- "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Applications\\wordpad.exe\\shell\\open\\command\\(Default)",
- "HKEY_CURRENT_USER\\Software\\Microsoft\\Internet Explorer\\Main\\UseThemes",
- "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\Zones\\3\\DisplayName",
- "HKEY_CURRENT_USER\\Software\\Microsoft\\Internet Explorer\\International\\Scripts\\3\\IEPropFontName",
- "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\Lockdown_Zones\\0\\Icon",
- "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\ProfileList\\S-1-5-21-839522115-813497703-1060284298-1003\\CentralProfile",
- "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\policies\\Ratings\\Key",
- "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Setup\\ServicePackCachePath",
- "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\\ShellFolder\\CallForAttributes",
- "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Control\\ComputerName\\ActiveComputerName\\ComputerName",
- "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\ShellNoRoam\\MUICache\\@C:\\WINDOWS\\system32\\SHELL32.dll,-9216",
- "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\{2559a1f0-21d7-11d4-bdaf-00c04f60b9f0}\\ShellFolder\\WantsFORDISPLAY",
- "HKEY_CURRENT_USER\\Software\\Microsoft\\Internet Explorer\\Toolbar\\SmBrandBitmap",
- "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\exefile\\DocObject",
- "HKEY_CURRENT_USER\\Software\\Microsoft\\Internet Explorer\\Main\\CSS_Compat",
- "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\{2559a1f5-21d7-11d4-bdaf-00c04f60b9f0}\\InfoTip",
- "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\ShellNoRoam\\MUICache\\C:\\Program Files\\Internet Explorer\\iexplore.exe"
- ],
- "directory_enumerated": [
- "C:\\Documents and Settings",
- "C:\\Documents and Settings\\user\\Local Settings\\History\\History.IE5\\MSHist012018021620180217\\*.*",
- "C:\\Documents and Settings\\user",
- "C:\\Documents and Settings\\user\\Local Settings\\History\\History.IE5\\MSHist012018021520180216\\*.*",
- "C:\\Documents and Settings\\user\\Local Settings\\Temp",
- "C:\\Documents and Settings\\user\\Local Settings\\History",
- "C:\\WINDOWS\\Installer\\{16E52445-1392-469F-9ADB-FC03AF00CD61}\\python_icon.exe",
- "C:\\Documents and Settings\\user\\Local Settings\\Temp\\test",
- "C:\\WINDOWS",
- "C:\\Documents and Settings\\user\\Local Settings",
- "C:\\WINDOWS\\Installer\\{16E52445-1392-469F-9ADB-FC03AF00CD61}",
- "C:\\WINDOWS\\Installer"
- ],
- "directory_created": [
- "C:\\Documents and Settings\\user\\Local Settings\\History\\History.IE5\\MSHist012018021220180219\\",
- "C:\\Documents and Settings\\user\\Local Settings\\History\\History.IE5\\MSHist012018022320180224\\"
- ]
- }
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement