'
metaflows logo
Category Started On Completed On Duration Cuckoo Version
FILE 2016-08-22 19:55:03.611526 2016-08-22 19:58:10.673098 187 seconds 2.0-dev
Machine Label Manager Started On Shutdown On
win7cuckoo2 win7 Clone 2 VirtualBox 2016-08-22 19:55:04 2016-08-22 19:58:10

File Details

File name d25e226428fe4ab0f62813be8818dbfdd081294b.exe
File size 626856 bytes
File type PE32 executable for MS Windows (GUI) Intel 80386 32-bit
CRC32 2E4E565A
MD5 ce5b1f802e9c23ed5df2ffbddf104de9
SHA1 d25e226428fe4ab0f62813be8818dbfdd081294b
SHA256 5ec7cfc6cc334a7bf29f99a353975c1c6e803498d75557a13018de663c5b4f97
SHA512 0a6bb298b7166e5d9eaac83265e04b098c2a67d989cfd34e8bba4a08e662a3e8304368fef19fbc26a34f03f3ecf1dbab8be6d201bdb6d8e0ea4085914734f285
Ssdeep 12288:c0gNQTKfVI9kwLiPc2tWWlT4ii+v6ESIpZauOyUn8//etv8wH:38QTS/C2mc9pZaGk8/2W
PEiD None matched
Yara None matched
VirusTotal Permalink
VirusTotal Scan Date: 2016-08-14 16:27:29
Detection Rate: 1/55 (Expand)

MetaFlows Scores

Metaflows Analysis Results (Signatures=75, Anomalies=0, PEiD=0, Yara=0, VT[1471896229]=0): Snort Events=1, AV Events=0
Total Score=75

SNORT EVENTS:
ET POLICY PE EXE or DLL Windows file download HTTP

Dropped File/Buffer Yara Signatures:
99021d0d8032dcc8_p2phttp.dll: Str_Win32_Winsock2_Library
4337ac4dd4e15db8_InstallHelper.dll: Str_Win32_Wininet_Library
7e5f65e6b9cb6373_apdmon.dll: Str_Win32_Winsock2_Library
a70355629b18f6d1_exceptcatch.dll: Str_Win32_Wininet_Library
9b3a5009a757b753_ffmpegsumo.dll: vmdetect
2a263ac90893b2e7_qqmusicservice.exe: GenerateTLSClientHelloPacket_Test
dcb6b5200a8e6c89_uninstall.exe: Str_Win32_Winsock2_Library
72f92b6eede02b09_qqmusic_databasemgr_old.dll: spyeye
dfe70875c14d2176_qqmusic_databasemgr.dll: spyeye
5dcf9242b9d3be90_QQMusicCommon.dll: Str_Win32_Winsock2_Library
2241bd9c51895019_qqmusicmminstaller.dll: Str_Win32_Winsock2_Library
13eef31119853f39_qqmusic_protocol.dll: Str_Win32_Winsock2_Library
1916bb9662d3a24f_qqmusic_login.dll: spyeye
f6ad7547bd6d4c12_p2plog.dll: Str_Win32_Winsock2_Library
3e6b8b73eba26296_kinst.dll: Str_Win32_Winsock2_Library
ba1db1d0c6de1cec_installplugin.dll: Str_Win32_Winsock2_Library
0ffcc75e05a3da41_qqmusicsvr.exe: Str_Win32_Winsock2_Library
ed828838a10e6a47_ssoluicontrol.dll: Str_Win32_Wininet_Library
25248b7edfd6834b_npssoaxctrlforptlogin.dll: Str_Win32_Wininet_Library
1f1085a6cbbcee1f_qqmusicplayer.dll: Str_Win32_Winsock2_Library
1b7fe3eac3cf6d50_QQMusicResource.dll: spyeye_plugins
d7a43b17b9a9e5ce_androiddevice.dll: Str_Win32_Wininet_Library
e04e0c822cf0263e_ssocommon.dll: Str_Win32_Winsock2_Library
219ce3ccd565eebe_datatransformex.exe: with_sqlite
e08e3ac1e4a92f97_p2p.dll: Str_Win32_Winsock2_Library
26a4f7d1bd920e8e_p2papp.dll: Str_Win32_Winsock2_Library
01d0f01146e688ad_qqpcdetector.dll: Str_Win32_Winsock2_Library
2c6ab490717218d3_qplaysupport.dll: Str_Win32_Winsock2_Library
900ee9443cb15aa3_qqmusicapi.dll: Str_Win32_Winsock2_Library
5d22937831aed5ec_InstallHelper.dll: Str_Win32_Winsock2_Library
b27a6067dbe797b3_qbcore.dll: GlassesCode
ec492537a1dcd34c_bck.dll: Str_Win32_Winsock2_Library
659b9fb0540d072a_qbclient.dll: Str_Win32_Winsock2_Library
7cf59d03c6e08845_qqmusic.dll: Str_Win32_Winsock2_Library
09d8a2129544d9f5_pepflashplayer.dll: QuarianCode
18b869ca31f2dbe3_qqmusic_qmpmgr.dll: spyeye
cf5fea7939fefbb8_sqlite.dll: with_sqlite
0f7dc750471894c5_libeay32.dll: Str_Win32_Winsock2_Library
7ddfd1b180c196d2_diagtools.exe: Str_Win32_Wininet_Library
4050849dee043613_tnproxy.dll: Str_Win32_Winsock2_Library
7034ecdeb8e5eb33_qbclient.exe: Str_Win32_Winsock2_Library
c3492c95dae1cd33_p2papi.dll: Str_Win32_Winsock2_Library
c9730d57c100bada_ssoplatform.dll: Str_Win32_Winsock2_Library
2de91bc2960edb0d_QMNetwork.dll: Str_Win32_Winsock2_Library
108d300eea5a6daa_qqmusicup.exe: Str_Win32_Winsock2_Library
5ce1ad9085692476_txupnp.dll: Str_Win32_Winsock2_Library
6bbd42293cc2f13c_musicinst.dll: Str_Win32_Winsock2_Library
343fc6abe7a95203_common.dll: Str_Win32_Winsock2_Library
13f0d9c0dccd0acf_bugreport.exe: Str_Win32_Winsock2_Library
52a93003150cae1c_qqmusicdldex.dll: Str_Win32_Winsock2_Library
30b7d90c4700c17a_mole.dll: Str_Win32_Winsock2_Library
0431acb90d4db360_qqmusic_network.dll: Str_Win32_Winsock2_Library
880ae67b388a6746_tadb.exe: Str_Win32_Winsock2_Library
d9a4d5389f6ada8d_p2pcore.dll: Str_Win32_Winsock2_Library
ba701ce2a8b0220d_libfftw3f-3.dll: spyeye
a7a685ab6e485fdd_qxmatrix.dll: Str_Win32_Winsock2_Library

Signatures

antivm_queries_computername details
recon_fingerprint details
locates_browser details
Executable_Deleted details
Long_Alphanum_Exe_Name details
Roaming_Profile_Modified details
Startup_File_Accessed details
Windows_Connection_Settings_Accessed details
antisandbox_foregroundwindows details
suspicious_process details
uses_windows_utilities details
MF_Heuristic details
known_malware_mutex details
Windows_Proxy_Tinkering details
persistence_ads details
dexter details
exploit_heapspray details

Screenshots

No screenshots available.

Static Analysis

Version Infos

Sections

Resources

Imports

Strings

Dropped Files

9635d61bf446ace4_manifest.json

99021d0d8032dcc8_p2phttp.dll

a0ace22b71def791_installerror.xml

4337ac4dd4e15db8_InstallHelper.dll

ed0170d3de86da33_msvcr90.dll

51bf1594e2fd95c3_adbwinusbapi.dll

617c77baf106f98f_DataTransformex(1273.3461)20160822221639.log

7e5f65e6b9cb6373_apdmon.dll

37af3bc579048877_libjpegturbo.dll

a70355629b18f6d1_exceptcatch.dll

6aa42fd47fab54e9_qmp_wsapi.dll

9b3a5009a757b753_ffmpegsumo.dll

2a263ac90893b2e7_qqmusicservice.exe

dcb6b5200a8e6c89_uninstall.exe

72f92b6eede02b09_qqmusic_databasemgr_old.dll

dfe70875c14d2176_qqmusic_databasemgr.dll

aa80361f8d77464f_qqmusic_win7feature2.dll

5dcf9242b9d3be90_QQMusicCommon.dll

e3b0c44298fc1c14_nsq1F2A.tmp

2241bd9c51895019_qqmusicmminstaller.dll

ab230e9aa4914055_lr.data

6e5559c8d22e41be_natives_blob.bin

96345ba68aa91003_desktopprojection64.dll

1e7ea6e1a197fe60_qqmusicinstall.log

b8d3d54dfc9f9122_instok

e63c15fd320cfc52_box2

aede6e800e1189b3_autopoweroff.exe

1477d0092990b335_qmp_dts.dll

13eef31119853f39_qqmusic_protocol.dll

2df446bf28fa27d5_qqmusicsvr(1273.3461)20160822221639.log.zip

74b7c86b75cfaf51_atl100.dll

32f912e1eceb0000_ssoconfig.xml

1916bb9662d3a24f_qqmusic_login.dll

05cc3b6630936db2_TestCache5728.dat

f6ad7547bd6d4c12_p2plog.dll

3e6b8b73eba26296_kinst.dll

1fd3494aad127ce0_zlib.dll

75718cd05a70fa23_QQMusicAgent(1273.3461)20160822221649.log

74115b9a308974c0_qmp_mp3.dll

8b07d6035173c83b_xgraphic32.dll

ba1db1d0c6de1cec_installplugin.dll

0ffcc75e05a3da41_qqmusicsvr.exe

660e1ada6ed43b4c_qqmusichelpersetup.exe

c57c8a18c8f094fb_msdmo.dll

5615d855e82f79d0_qmp_ape.dll

ed828838a10e6a47_ssoluicontrol.dll

25248b7edfd6834b_npssoaxctrlforptlogin.dll

1f1085a6cbbcee1f_qqmusicplayer.dll

7851cb12fa4131f1_System.dll

14eb8359817d84e2_QQMusicAgent(1273.3461)20160822221644.log

001921464e21a470_com.qq.qqmusichelper.json

1b7fe3eac3cf6d50_QQMusicResource.dll

5b8a35fcaa7d4d62_qqmusicuninst.exe

d7a43b17b9a9e5ce_androiddevice.dll

b54cc863483102e4_gf.dll

e04e0c822cf0263e_ssocommon.dll

219ce3ccd565eebe_datatransformex.exe

153fbc9053df3864_arkfs.dll

3255f77e0e13a460_qmp_asf.dll

3383a19bfcb5873d_qplay_1.jpg

33af29e7051ad054_QQMusic2011Setup9828.exe

5213a2c914bc5ad6_extapp.xml

cfd0254778bedeb7_qmp_ogg.dll

e08e3ac1e4a92f97_p2p.dll

7abd3986d6212572_qmp_alac.dll

26a4f7d1bd920e8e_p2papp.dll

01d0f01146e688ad_qqpcdetector.dll

2c6ab490717218d3_qplaysupport.dll

d075d81f706b363d_qqmusicgslbweb.dll

02b0b24b4bcbb33e_auzip.dll

1ec00b405beaf72e_svm_snr15_random_noise.dat

cdc146575f31400f_qqmusichelper.dll

2b52d72ae65076d4_qqmusic_gfwrapper.dll

e21086aaaa10d432_mini.dll

900ee9443cb15aa3_qqmusicapi.dll

5d22937831aed5ec_InstallHelper.dll

b61d0b7d06b34632_qqmusicagent(1273.3461)20160822221644.log.zip

e90667b8d82cb1e1_arkimage.dll

fef3c6dfc6e854e3_{548be2ed-0258-4e24-9923-0f3d52a09f8e}.tmp

90543f89686813da_qqmusicagent.exe

79f86458cf0f50db_snapshot_blob.bin

67ed6160488b5c42_resource.rdb

9e0220511d4ebdb0_microsoft.vc90.crt.manifest

29c1bcca947b09a5_rl.data

0b09122a656d77ce_nmqqmusichelper.exe

b371af3ce6cb5d0b_msvcm90.dll

c893f1eab716005a_zh-cn.pak

f691037111793c2e_filter.xml

3c97da7b12ac5191_tssafeedit.dat

b27a6067dbe797b3_qbcore.dll

3251416f76b32df3_tinyxml.dll

f1f5643b7b91d04c_qb_200_percent.pak

4f7ed27b532888ce_msvcp90.dll

ec492537a1dcd34c_bck.dll

dcea5f5ae719ed9a_qmp_songrecognition.dll

659b9fb0540d072a_qbclient.dll

a909494b78e47b79_rr.data

7cf59d03c6e08845_qqmusic.dll

088b5e80759c3f15_qqaudiohookservice.dll

09d8a2129544d9f5_pepflashplayer.dll

4d35a90ad81b36a8_qb_100_percent.pak

38f4e3c1668960aa_qqmusicagent(1273.3461)20160822221649.log.zip

18b869ca31f2dbe3_qqmusic_qmpmgr.dll

cf5fea7939fefbb8_sqlite.dll

0f7dc750471894c5_libeay32.dll

5f8946b7df0792c4_musicwrapper.dll

d769fafa2b3232de_msvcp100.dll

f55a5eac7d62b8e9_qqmusicdownloader.exe

b9cc9105a21f48f4_qqmusicdownloader.exe

7ddfd1b180c196d2_diagtools.exe

4050849dee043613_tnproxy.dll

7034ecdeb8e5eb33_qbclient.exe

7f00b89105713727_qqmusichelperuninst.exe

a6e6471462ee4050_box

dff79c4ee60ff528_qqmusiclaunch.prf

4d4429279c3d8725_qmp_flac.dll

c3492c95dae1cd33_p2papi.dll

b6d53cb6d4ec73d6_asynctask.dll

c9730d57c100bada_ssoplatform.dll

9fa31b7814a2e596_qqmusic2011setup9828(0.0)20160822221556.log

2de91bc2960edb0d_QMNetwork.dll

57abf44be4b19f79_desktopprojection32.dll

638db6e8d18efbc4_arkgraphic.dll

d29afce2588d8dd7_nsExec.dll

108d300eea5a6daa_qqmusicup.exe

1c3db78d04ab7cc7_atl100.dll

5ce1ad9085692476_txupnp.dll

28ca565552481591_npqqmusichelper.dll

49559ccddf12544a_qb.pak

764f1bf95ddd77b4_mul_http_download.log

eb37eb6258961d6f_qqmusicexternal.exe

68abecd31d73f65a_qmp_aac.dll

6bbd42293cc2f13c_musicinst.dll

69bb4cf9a63a6509_mtpwrapper.dll

61cdd96805f31eea_qqmusic_lyric.dll

343fc6abe7a95203_common.dll

fe2f101b1e73c7c5_qqmusic_download_url_new[1].ini

baff1849b5e2ab55_startdesktopprojection64.exe

eb43a91460569c8c_setuplog.log

13f0d9c0dccd0acf_bugreport.exe

b36cdbb77750267d_bfmqbtgzwakppha.lnk

1701a94e84681722_qqmusicinstaller.log

52a93003150cae1c_qqmusicdldex.dll

e677ae0378d567ee_qplay.html

95ea5059cd629bbc_en-us.pak

429403fda6b8d91a_ssostringbundle.xml

bed63e5f28f171de_pofpvbvltdtuaeh.lnk

30b7d90c4700c17a_mole.dll

0762a98f575b83de_qmp_common.dll

01f1cb8a66f3f75a_libimagequant.dll

df2600ef84ead18b_cqydudadacdjjrn.lnk

cb9e1542b1653702_ll.data

3382d91c1d0b12b5_qqmusicmminstaller.exe

c6fb27e5f0fa3d4d_datatransformex(1273.3461)20160822221639.log.zip

d006b8f50ed92878_adbwinapi.dll

0431acb90d4db360_qqmusic_network.dll

14049ea2e2810df3_wmadmod.dll

9b789fd1ecd3381d_p2pdata.dll

57dad84650cabd01_niilguqpgsv.lnk

640de24aff1bbf0c_icudtl.dat

a62e8ae4a82bbe46_vcomp100.dll

b52dba809709f9ce_arkiostub.dll

dc3ce1dd10cb91a9_capfbcaltvc.lnk

60c06e0fa4449314_msvcr100.dll

2775e47ac1e5cbd4_qqmusic.exe

a65ebb71978a94d0_QQMusicSvr(1273.3461)20160822221639.log

16811aa2765f9b30_insttxsso.exe

ee3049b7b0d27596_qqmediaplayer.dll

b7fb58296b7d261b_startdesktopprojection32.exe

673eb178dae8cf3a_pgfstringbundle.xml

880ae67b388a6746_tadb.exe

d9a4d5389f6ada8d_p2pcore.dll

ba701ce2a8b0220d_libfftw3f-3.dll

92855063bf6f3a35_libpng.dll

ccf1efd5b461e4e0_device.xml

0b5c8ccff2b9d85e_addin.ini

70e894067fb47816_libexpat.dll

132c40aae781e466_qplay_2.jpg

a7a685ab6e485fdd_qxmatrix.dll

a9a98fc7062262a4_microsoft.vc90.atl.manifest

Network Analysis

Hosts Involved

DNS Requests

HTTP Requests

Behavior Summary

File-Read
  • C:\Users\Harry Dresden\AppData\Roaming\Tencent\QQMusic\QQMusicCache\Log\QQMusicAgent\QQMusicAgent(1273.3461)20160822221644.log
  • C:\Program Files (x86)\Tencent\QQmusic\QQMusic1273.22.15.58\QQMusicSvr.exe
  • C:\Users\Harry Dresden\AppData\Roaming\Tencent\QQMusic\QQMusicCache\Log\QQMusicSvr\QQMusicSvr(1273.3461)20160822221639.log
  • C:\Users\Harry Dresden\AppData\Roaming\Tencent\QQMusic\QQMusicCache\Log\QQMusicAgent\QQMusicAgent(1273.3461)20160822221649.log
  • C:\Users\Harry Dresden\AppData\Local\Temp\d25e226428fe4ab0f62813be8818dbfdd081294b.exe
  • C:\Users\Harry Dresden\Documents\desktop.ini
  • C:\Users\Harry Dresden\Links\desktop.ini
  • C:\Users\Harry Dresden\Contacts\desktop.ini
  • C:\Users\Harry Dresden\Saved Games\desktop.ini
  • C:\Users\desktop.ini
  • C:\Users\Harry Dresden\Pictures\desktop.ini
  • C:\Users\Harry Dresden\Searches\desktop.ini
  • C:\Users\Harry Dresden\Music\desktop.ini
  • C:\Users\Harry Dresden\Favorites\desktop.ini
  • C:\Users\Harry Dresden\Videos\desktop.ini
  • C:\Users\Harry Dresden\Desktop\desktop.ini
  • C:\Users\Harry Dresden\Downloads\desktop.ini
  • C:\Windows\System32\shdocvw.dll
  • C:\Users\Harry Dresden\Documents\desktop.ini
  • C:\Users\Harry Dresden\Links\desktop.ini
  • C:\Users\Harry Dresden\Contacts\desktop.ini
  • C:\Users\Harry Dresden\Saved Games\desktop.ini
  • C:\Users\desktop.ini
  • C:\Users\Harry Dresden\AppData\Roaming\Tencent\QQMusicMMInstallCache\mul_http_download.log
  • C:\Users\Harry Dresden\Pictures\desktop.ini
  • C:\Users\Harry Dresden\Searches\desktop.ini
  • C:\Users\Harry Dresden\Music\desktop.ini
  • C:\Users\Harry Dresden\Favorites\desktop.ini
  • C:\Windows\System32\shdocvw.dll
  • C:\Users\Harry Dresden\Videos\desktop.ini
  • C:\Users\Harry Dresden\Desktop\desktop.ini
  • C:\Users\Harry Dresden\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\YLC2QM2Y\qqmusic_download_url_new[1].ini
  • C:\Users\Harry Dresden\Downloads\desktop.ini
  • C:\Users\Harry Dresden\AppData\Roaming\Tencent\QQMusicMMInstallCache\QQMusic2011Setup9828.exe
  • C:\Windows\System32\ntshrui.dll
  • C:\Program Files (x86)\desktop.ini
  • C:\Program Files (x86)\Common Files\Tencent\TXSSO\1.2.3.15\bin\npSSOAxCtrlForPTLogin.dll
  • C:\Users\Harry Dresden\AppData\Roaming\Tencent\QQMusic\QQMusicCache\Log\DataTransformex\DataTransformex(1273.3461)20160822221639.log
  • C:\Program Files (x86)\Tencent\QQmusic\QQMusic1273.22.15.58\QQMusic_Login.dll
  • C:\Users\Harry Dresden\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\Windows Explorer.lnk
  • C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories\Desktop.ini
  • \\?\PIPE\samr
  • C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Administrative Tools\desktop.ini
  • C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Games\Desktop.ini
  • C:\Users\Public\Desktop\听歌识曲.lnk
  • C:\Users\Public\Desktop\Adobe Reader XI.lnk
  • C:\Users\Public\Desktop\desktop.ini
  • C:\Users\Harry Dresden\Desktop\desktop.ini
  • C:\Users\Harry Dresden\AppData\Roaming\Microsoft\Windows\Recent\desktop.ini
  • C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\desktop.ini
  • C:\Users\Harry Dresden\AppData\Roaming\Microsoft\Windows\Start Menu\desktop.ini
  • C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Maintenance\Desktop.ini
  • C:\Users\Harry Dresden\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\Windows Media Player.lnk
  • C:\ProgramData\Microsoft\Windows\Start Menu\desktop.ini
  • C:\Users\Harry Dresden\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\Internet Explorer.lnk
  • C:\Users\desktop.ini
  • C:\Program Files (x86)\Tencent\QQmusic\QQMusic1273.22.15.58\QQMusic.exe
  • C:\Users\Public\Desktop\QQ音乐.lnk
  • C:\Users\Harry Dresden\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\desktop.ini
  • C:\Users\Harry Dresden\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\Mozilla Firefox.lnk
  • C:\Users\Public\Desktop\Mozilla Firefox.lnk
  • C:\Users\Harry Dresden\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\desktop.ini
  • c:\Windows\installer\{ac76ba86-7ad7-1033-7b44-ab0000000001}\sc_reader.ico
  • C:\Program Files\desktop.ini
  • C:\Users\Public\Desktop\Foxit Reader.lnk
  • C:\Users\Public\desktop.ini
  • C:\ProgramData\Microsoft\Windows\Start Menu\Programs\desktop.ini
  • C:\Program Files (x86)\Mozilla Firefox\firefox.exe
  • C:\Program Files (x86)\desktop.ini
  • C:\Users\Harry Dresden\Desktop\desktop.ini
  • C:\Program Files (x86)\Tencent\QQMusicHelper\QQMusicHelper1257.22.16.26\QQMusicHelper.dll
  • C:\Program Files (x86)\Tencent\QQmusic\QQMusic1273.22.15.58\QQMusicHelperSetup.exe
  • C:\Program Files (x86)\desktop.ini
  • C:\Users\Harry Dresden\AppData\Local\Temp\nsq277.tmp
  • C:\Program Files (x86)\Common Files\Tencent\TXSSO\1.2.3.15\bin\SSOLUIControl.dll
  • C:\Program Files (x86)\Tencent\QQmusic\QQMusicInstall\QQMusicMMInstaller.dll
  • C:\Program Files (x86)\Common Files\Tencent\TXSSO\1.2.3.15\bin\SSOCommon.dll
File-Written
  • C:\Users\Harry Dresden\AppData\Roaming\Tencent\QQMusic\QQMusicCache\TestCache4260.dat
  • C:\Users\Harry Dresden\AppData\Roaming\Tencent\QQMusic\QQMusicCache\Log\QQMusicAgent\QQMusicAgent(1273.3461)20160822221644.log.zip
  • C:\Users\Harry Dresden\AppData\Roaming\Tencent\QQMusic\QQMusicCache\Log\QQMusicAgent\QQMusicAgent(1273.3461)20160822221644.log
  • C:\Users\Harry Dresden\AppData\Roaming\Tencent\QQMusic\QQMusicCache\Log\QQMusicSvr\QQMusicSvr(1273.3461)20160822221639.log.zip
  • C:\Users\Harry Dresden\AppData\Roaming\Tencent\QQMusic\QQMusicCache\TestCache5348.dat
  • C:\Users\Harry Dresden\AppData\Roaming\Tencent\QQMusic\QQMusicCache\Log\QQMusicSvr\QQMusicSvr(1273.3461)20160822221639.log
  • C:\Users\Harry Dresden\AppData\Roaming\Tencent\QQMusic\QQMusicCache\Log\QQMusicAgent\QQMusicAgent(1273.3461)20160822221649.log
  • C:\Users\Harry Dresden\AppData\Roaming\Tencent\QQMusic\QQMusicCache\TestCache5160.dat
  • C:\Users\Harry Dresden\AppData\Roaming\Tencent\QQMusic\QQMusicCache\Log\QQMusicAgent\QQMusicAgent(1273.3461)20160822221649.log.zip
  • C:\Program Files (x86)\Tencent\QQmusic\QQMusicInstall\QQMusicMMInstaller.exe
  • C:\Users\Harry Dresden\AppData\Roaming\Tencent\QQMusic\Log\QQMusicInstall\QQMusicInstall.log
  • C:\Users\Harry Dresden\AppData\Local\Temp\nsa2A47.tmp\InstallHelper.dll
  • C:\Program Files (x86)\Tencent\QQmusic\QQMusicInstall\QQMusicMMInstaller.dll
  • C:\Users\Harry Dresden\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\YLC2QM2Y\qqmusic_download_url_new[1].ini
  • C:\Users\Harry Dresden\AppData\Roaming\Tencent\QQMusic\Temp\{548BE2ED-0258-4E24-9923-0F3D52A09F8E}.tmp
  • C:\Users\Harry Dresden\AppData\Roaming\Tencent\QQMusicMMInstallCache\QQMusic2011Setup9828.exe
  • C:\Users\Harry Dresden\AppData\Roaming\Tencent\QQMusicMMInstallCache\mul_http_download.log
  • C:\Users\Harry Dresden\AppData\Roaming\Tencent\TXSSO\SetupLogs\setuplog.log
  • C:\Users\Harry Dresden\AppData\Roaming\Tencent\QQMusic\QQMusicCache\Log\DataTransformex\DataTransformex(1273.3461)20160822221639.log
  • C:\Users\Harry Dresden\AppData\Roaming\Tencent\QQMusic\QQMusicCache\Log\DataTransformex\DataTransformex(1273.3461)20160822221639.log.zip
  • C:\Users\Harry Dresden\AppData\Roaming\Tencent\QQMusic\QQMusicCache\TestCache1828.dat
  • C:\Users\Harry Dresden\AppData\Roaming\Microsoft\Windows\Recent\nIIlGuqpgSV.lnk
  • \\?\PIPE\samr
  • C:\Users\Harry Dresden\AppData\Roaming\Microsoft\Windows\Recent\bFMQBtgZwakpPHA.lnk
  • C:\Users\Harry Dresden\AppData\Roaming\Microsoft\Windows\Recent\CQyDuDaDacDjjRn.lnk
  • C:\Users\Harry Dresden\AppData\Roaming\Microsoft\Windows\Recent\capFbCalTvc.lnk
  • C:\Users\Harry Dresden\AppData\Roaming\Microsoft\Windows\Recent\pOfpVBVLtDTuaeH.lnk
  • C:\Users\Harry Dresden\AppData\Local\Temp\nsq277.tmp
  • C:\Program Files (x86)\Tencent\QQMusicHelper\QQMusicHelper1257.22.16.26\QQMusicDownloader.exe
  • C:\Program Files (x86)\Tencent\QQMusicHelper\QQMusicHelper1257.22.16.26\com.qq.qqmusichelper.json
  • C:\Users\Harry Dresden\AppData\Local\Temp\nsa2B6.tmp\System.dll
  • C:\Program Files (x86)\Tencent\QQMusicHelper\QQMusicHelper1257.22.16.26\msvcr100.dll
  • C:\Program Files (x86)\Tencent\QQMusicHelper\QQMusicHelper1257.22.16.26\npQQMusicHelper.dll
  • C:\Program Files (x86)\Tencent\QQMusicHelper\QQMusicHelper1257.22.16.26\QQMusicHelperUninst.exe
  • C:\Program Files (x86)\Tencent\QQMusicHelper\QQMusicHelper1257.22.16.26\QQMusicHelper.dll
  • C:\Program Files (x86)\Tencent\QQMusicHelper\QQMusicHelper1257.22.16.26\msvcp100.dll
  • C:\Users\Harry Dresden\AppData\Local\Temp\nsa2B6.tmp\nsExec.dll
  • C:\Program Files (x86)\Tencent\QQMusicHelper\QQMusicHelper1257.22.16.26\atl100.dll
  • C:\Program Files (x86)\Tencent\QQMusicHelper\QQMusicHelper1257.22.16.26\nmQQMusicHelper.exe
File-Deleted
  • C:\Users\Harry Dresden\AppData\Roaming\Tencent\QQMusic\QQMusicCache\TestCache4260.dat
  • C:\Users\Harry Dresden\AppData\Roaming\Tencent\QQMusic\QQMusicCache\Log\QQMusicAgent\QQMusicAgent(1273.3461)20160822221644.log
  • C:\Users\Harry Dresden\AppData\Roaming\Tencent\QQMusic\QQMusicCache\TestCache5348.dat
  • C:\Users\Harry Dresden\AppData\Roaming\Tencent\QQMusic\QQMusicCache\Log\QQMusicSvr\QQMusicSvr(1273.3461)20160822221639.log
  • C:\Users\Harry Dresden\AppData\Roaming\Tencent\QQMusic\QQMusicCache\Log\QQMusicAgent\QQMusicAgent(1273.3461)20160822221649.log
  • C:\Users\Harry Dresden\AppData\Roaming\Tencent\QQMusic\QQMusicCache\TestCache5160.dat
  • C:\Users\Harry Dresden\AppData\Local\Temp\nsq1F2A.tmp
  • C:\Users\Harry Dresden\AppData\Local\Temp\nsa2A47.tmp
  • C:\Users\Harry Dresden\AppData\Local\Temp\nsa2A47.tmp\InstallHelper.dll
  • C:\Users\Harry Dresden\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\YLC2QM2Y\qqmusic_download_url_new[1].ini
  • C:\Users\Harry Dresden\AppData\Roaming\Tencent\QQMusicMMInstallCache\QQMusic2011Setup9828.exe
  • C:\Users\Harry Dresden\AppData\Roaming\Tencent\QQMusic\QQMusicCache\Log\DataTransformex\DataTransformex(1273.3461)20160822221639.log
  • C:\Users\Harry Dresden\AppData\Roaming\Tencent\QQMusic\QQMusicCache\TestCache1828.dat
  • C:\Users\Harry Dresden\AppData\Local\Temp\nsa2B6.tmp\nsExec.dll
  • C:\Users\Harry Dresden\AppData\Local\Temp\nsa2B6.tmp
  • C:\Users\Harry Dresden\AppData\Local\Temp\nsa2B6.tmp\System.dll
  • C:\Users\Harry Dresden\AppData\Local\Temp\nsk208.tmp
File-Opened
  • C:\Windows\System32\en-US\napipsec.dll.mui
  • C:\Windows\SysWOW64\en-US\DhcpQEC.dll.mui
  • C:\Windows\System32\EAPQEC.DLL
  • C:\Windows\System32\en-US\eapqec.dll.mui
  • C:\Windows\System32\napipsec.dll
  • C:\Windows\System32\en-US\tsgqec.dll.mui
  • C:\Windows\System32\DHCPQEC.DLL
  • C:\Windows\System32\tsgqec.dll
  • C:\Windows\Globalization\Sorting\sortdefault.nls
  • C:\Users\Harry Dresden\AppData\Roaming\Tencent\QQMusic\QQMusicCache\Log\QQMusicAgent\QQMusicAgent(1273.3461)20160822221644.log
  • \??\C:
  • C:\Users\Harry Dresden\AppData\Roaming\Tencent\QQMusic\QQMusicCache\Log\QQMusicSvr\QQMusicSvr(1273.3461)20160822221639.log
  • C:\Program Files (x86)\Tencent\QQmusic\QQMusic1273.22.15.58\QQMusicSvr.exe
  • \??\C:
  • C:\Users\Harry Dresden\AppData\Roaming\Tencent\QQMusic\QQMusicCache\Log\QQMusicAgent\QQMusicAgent(1273.3461)20160822221649.log
  • \??\C:
  • C:\Windows\AppPatch\sysmain.sdb
  • C:\
  • C:\Windows\System32\en-US\shdocvw.dll.mui
  • C:\Users\Harry Dresden\AppData\Local
  • C:\Users\Harry Dresden\Pictures\desktop.ini
  • C:\Windows\System32\winnsi.dll
  • C:\Users\Harry Dresden\Favorites\desktop.ini
  • C:\Users\Harry Dresden\Desktop\desktop.ini
  • C:\Users\Harry Dresden\Links\desktop.ini
  • C:\Users\Harry Dresden\AppData\Local\Temp\nsa2A47.tmp\InstallHelper.dll
  • C:\Users\Harry Dresden\AppData\Local\Temp\d25e226428fe4ab0f62813be8818dbfdd081294b.exe
  • C:\Users\Harry Dresden\Saved Games\desktop.ini
  • C:\Windows\System32\IPHLPAPI.DLL
  • C:\Users\Harry Dresden\Searches\desktop.ini
  • C:\Users\Harry Dresden\Music\desktop.ini
  • C:\Windows\System32\pnrpnsp.dll
  • C:\Users
  • C:\Users\Harry Dresden\Downloads\desktop.ini
  • C:\Windows\System32\NapiNSP.dll
  • C:\Users\Harry Dresden\AppData\Local\Microsoft\Windows\Caches\{AFBF9F1A-8EE8-4C77-AF34-C647E37CA0D9}.1.ver0x0000000000000001.db
  • C:\Windows\System32\shdocvw.dll
  • C:\Users\Harry Dresden\Contacts\desktop.ini
  • C:\Windows\System32\rasadhlp.dll
  • C:\Users\desktop.ini
  • C:\Windows\System32\dnsapi.dll
  • C:\Users\Harry Dresden\Videos\desktop.ini
  • C:\Users\Harry Dresden\Documents\desktop.ini
  • C:\Program Files (x86)\Tencent\QQmusic\QQMusicInstall
  • C:\Windows\System32\winrnr.dll
  • C:\Windows\System32\nlaapi.dll
  • C:\Users\Harry Dresden
  • C:\Windows\System32\FWPUCLNT.DLL
  • C:\Windows\Globalization\Sorting\sortdefault.nls
  • C:\Users\Harry Dresden\AppData\Local\Temp\nsa2A47.tmp\
  • C:\Windows\System32\
  • C:\Users\Harry Dresden\AppData\Local\Microsoft\Windows\Caches\cversions.1.db
  • C:\Users\Harry Dresden\AppData
  • C:\Windows\System32\wshqos.dll
  • C:\Windows\AppPatch\sysmain.sdb
  • C:\
  • C:\Windows\System32\en-US\shdocvw.dll.mui
  • C:\Users\Harry Dresden\Pictures\desktop.ini
  • C:\Windows\System32\en-US\wship6.dll.mui
  • C:\Users\Harry Dresden\Favorites\desktop.ini
  • C:\Users\Harry Dresden\Desktop\desktop.ini
  • C:\Windows\System32\shdocvw.dll
  • C:\Users\Harry Dresden\Saved Games\desktop.ini
  • C:\Users\Harry Dresden\Searches\desktop.ini
  • C:\Users\Harry Dresden\Music\desktop.ini
  • C:\Users
  • C:\Users\Harry Dresden\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\YLC2QM2Y\qqmusic_download_url_new[1].ini
  • C:\Users\Harry Dresden\AppData\Local\Microsoft\Windows\Caches\{AFBF9F1A-8EE8-4C77-AF34-C647E37CA0D9}.1.ver0x0000000000000001.db
  • C:\Windows\AppPatch\pcamain.sdb
  • C:\Users\Harry Dresden\Links\desktop.ini
  • C:\Users\Harry Dresden\Contacts\desktop.ini
  • C:\Windows\System32\en-US\wshqos.dll.mui
  • C:\Users\desktop.ini
  • C:\Users\Harry Dresden\AppData\Roaming\Tencent\QQMusicMMInstallCache\mul_http_download.log
  • C:\Users\Harry Dresden\Videos\desktop.ini
  • C:\Users\Harry Dresden\Documents\desktop.ini
  • C:\Users\Harry Dresden\Downloads\desktop.ini
  • C:\Users\Harry Dresden
  • C:\Windows\System32\
  • C:\Users\Harry Dresden\AppData\Local\Microsoft\Windows\Caches\cversions.1.db
  • C:\Users\Harry Dresden\AppData\Roaming\Tencent\QQMusicMMInstallCache\
  • C:\Windows\System32\en-US\wshtcpip.dll.mui
  • C:\Users\Harry Dresden\AppData\Roaming\Tencent\QQMusicMMInstallCache\QQMusic2011Setup9828.exe
  • C:\Program Files (x86)\Tencent\QQmusic\QQMusic1273.22.15.58\TXSSO\I18N\2052\PGFStringBundle.xml
  • C:\Windows\AppPatch\sysmain.sdb
  • C:\
  • C:\Program Files (x86)\Common Files\Tencent
  • C:\Windows\System32\en-US\ntshrui.dll.mui
  • C:\Program Files (x86)\Tencent\QQmusic\QQMusic1273.22.15.58\TXSSO
  • C:\Program Files (x86)\Tencent
  • C:\Program Files (x86)\Tencent\QQmusic\QQMusic1273.22.15.58
  • C:\Program Files (x86)\Common Files
  • C:\Windows\SysWOW64\en-US\SHELL32.dll.mui
  • C:\Program Files (x86)\Tencent\QQmusic\QQMusic1273.22.15.58\TXSSO\InstTXSSO.exe
  • C:\Program Files (x86)\Common Files\Tencent\TXSSO
  • C:\Program Files (x86)\Tencent\QQmusic
  • C:\Users\Harry Dresden\AppData\Roaming\Tencent\TXSSO\SetupLogs\setuplog.log
  • C:\Program Files (x86)\Tencent\QQmusic\QQMusic1273.22.15.58\TXSSO\bin\SSOPlatform.dll
  • C:\Program Files (x86)\Tencent\QQmusic\QQMusic1273.22.15.58\TXSSO\I18N\2052\SSOStringBundle.xml
  • C:\Program Files (x86)
  • C:\Program Files (x86)\Tencent\QQmusic\QQMusic1273.22.15.58\TXSSO\I18N\SSOConfig.xml
  • C:\Windows\System32\ntshrui.dll
  • C:\Program Files (x86)\Tencent\QQmusic\QQMusic1273.22.15.58\TXSSO\bin\SSOCommon.dll
  • C:\Windows\System32\
  • C:\Program Files (x86)\Tencent\QQmusic\QQMusic1273.22.15.58\TXSSO\I18N\2052
  • C:\Program Files (x86)\Tencent\QQmusic\QQMusic1273.22.15.58\TXSSO\I18N
  • C:\Program Files (x86)\Tencent\QQmusic\QQMusic1273.22.15.58\TXSSO\bin
  • C:\Program Files (x86)\desktop.ini
  • C:\Program Files (x86)\Tencent\QQmusic\QQMusic1273.22.15.58\TXSSO\bin\npSSOAxCtrlForPTLogin.dll
  • C:\Program Files (x86)\Tencent\QQmusic\QQMusic1273.22.15.58\TXSSO\bin\SSOLUIControl.dll
  • C:\Program Files (x86)\Common Files\Tencent\TXSSO\1.2.3.15\bin\npSSOAxCtrlForPTLogin.dll
  • C:\Users\Harry Dresden\AppData\Roaming\Tencent\QQMusic\QQMusicCache\Log\DataTransformex\DataTransformex(1273.3461)20160822221639.log
  • \??\C:
  • C:\Program Files (x86)\Tencent\QQmusic\QQMusic1273.22.15.58\QQMusic_Login.dll
  • C:\Windows\Globalization\Sorting\sortdefault.nls
  • C:\Users\Harry Dresden\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\Windows Explorer.lnk
  • C:\ProgramData
  • C:\
  • C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Administrative Tools\desktop.ini
  • c:\program files (x86)\mozilla firefox\firefox.exe
  • C:\Program Files (x86)\Mozilla Firefox\
  • C:\Users\Harry Dresden\AppData\Local\Microsoft\Windows\Explorer\thumbcache_sr.db
  • C:\Users\Harry Dresden\
  • C:\Users\Harry Dresden\AppData\
  • C:\Users\Harry Dresden\AppData\Roaming\Microsoft\Windows\Recent\AutomaticDestinations\1b4dd67f29cb1962.automaticDestinations-ms
  • C:\ProgramData\Microsoft\Windows\Start Menu\desktop.ini
  • c:\program files (x86)\microsoft office\root\VFS\Windows\installer\{90160000-000f-0000-0000-0000000ff1ce}\wordicon.exe
  • C:\Program Files (x86)\Microsoft Office\
  • C:\Users\Harry Dresden\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\Internet Explorer.lnk
  • C:\Program Files (x86)\windows media player\wmplayer.exe
  • C:\Users\Harry Dresden\Desktop\CQyDuDaDacDjjRn.docm
  • C:\Windows\explorer.exe
  • C:\Windows\System32\en-US\imageres.dll.mui
  • C:\ProgramData\Microsoft\Windows\Start Menu
  • C:\Users\Harry Dresden\AppData\Roaming
  • C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Maintenance\Desktop.ini
  • C:\Program Files (x86)\Microsoft Office\root\Office16\
  • C:\Users\Harry Dresden\Desktop\
  • C:\Users\Harry Dresden\Desktop\pOfpVBVLtDTuaeH.rtf
  • C:\Users\Public\Desktop\Foxit Reader.lnk
  • C:\Users\Public\desktop.ini
  • C:\Program Files (x86)\Microsoft Office\root\
  • C:\Users\Harry Dresden\AppData\Roaming\Microsoft
  • C:\ProgramData\Microsoft\Windows\Start Menu\Programs\desktop.ini
  • C:\Windows\System32\imageres.dll
  • C:\Windows\AppPatch\sysmain.sdb
  • c:\program files (x86)\Tencent\QQmusic\qqmusic1273.22.15.58\QQMusic.exe
  • \\?\PIPE\samr
  • C:\Users\Public\Desktop\听歌识曲.lnk
  • C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AcroRd32.exe
  • c:\program files\internet explorer\en-US\iexplore.exe.mui
  • C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\desktop.ini
  • C:\Program Files (x86)\windows media player\en-US\wmplayer.exe.mui
  • C:\Program Files (x86)\Tencent\QQmusic\QQMusic1273.22.15.58\QQMusic.exe
  • C:\Users\Harry Dresden\Desktop\nIIlGuqpgSV.pptx
  • C:\Users\Harry Dresden\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\desktop.ini
  • C:\Users\Harry Dresden\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\Mozilla Firefox.lnk
  • C:\Users\Public\Desktop\Mozilla Firefox.lnk
  • C:\ProgramData\Microsoft\Windows
  • c:\Windows\installer\{ac76ba86-7ad7-1033-7b44-ab0000000001}\sc_reader.ico
  • C:\Users\Harry Dresden
  • C:\Users\Public\Desktop
  • C:\ProgramData\Microsoft\Windows\Start Menu\Programs\腾讯软件
  • C:\Users\Harry Dresden\AppData\Local\Microsoft\Windows\Explorer\thumbcache_32.db
  • C:\Users\Harry Dresden\AppData\Roaming\Microsoft\Internet Explorer
  • C:\Users\Harry Dresden\Desktop\bFMQBtgZwakpPHA.docm
  • C:\Program Files (x86)\desktop.ini
  • C:\Python27\
  • C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Games\Desktop.ini
  • C:\Users\Harry Dresden\AppData\Roaming\Microsoft\Windows\Recent\AutomaticDestinations\431a5b43435cc60b.automaticDestinations-ms
  • C:\Users\Harry Dresden\Desktop\capFbCalTvc.docx
  • C:\Users\Public\Desktop\desktop.ini
  • C:\Program Files\Microsoft Games\Solitaire\solitaire.exe
  • c:\program files\internet explorer\iexplore.exe
  • C:\Users\Harry Dresden\AppData\Local\Microsoft\Windows\Explorer\thumbcache_256.db
  • C:\Users\Harry Dresden\AppData\Roaming\Microsoft\Windows\Recent\desktop.ini
  • C:\Users\
  • C:\Program Files (x86)\Windows Media Player\wmplayer.exe
  • C:\Users
  • C:\Program Files\Windows NT\Accessories\
  • C:\Program Files (x86)\Tencent\
  • C:\Users\Public\Desktop\QQ音乐.lnk
  • C:\Users\desktop.ini
  • C:\Windows\System32\ShellStyle.dll
  • C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories
  • c:\program files (x86)\foxit software\foxit reader\foxit reader.exe
  • C:\Users\Harry Dresden\AppData\Local\Microsoft\Windows\Explorer\thumbcache_96.db
  • C:\Users\Public\Desktop\Adobe Reader XI.lnk
  • C:\ProgramData\Microsoft\Windows\Start Menu\Programs
  • C:\Program Files (x86)\Mozilla Firefox\firefox.exe
  • C:\ProgramData\Microsoft\Windows\Start Menu\Programs\7-Zip
  • C:\Program Files (x86)\Foxit Software\Foxit Reader\Foxit Reader.exe
  • C:\Users\Harry Dresden\AppData\Roaming\Microsoft\Windows\Start Menu
  • C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories\Desktop.ini
  • C:\Users\Harry Dresden\AppData\Local\
  • C:\Program Files (x86)\Tencent\QQmusic\QQMusic1273.22.15.58\
  • C:\Users\Harry Dresden\AppData\Roaming\Microsoft\Windows\Start Menu\Programs
  • C:\Users\Harry Dresden\Desktop
  • C:\Users\Harry Dresden\Desktop\desktop.ini
  • C:\Windows\
  • C:\Users\Harry Dresden\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch
  • C:\Users\Harry Dresden\AppData\Roaming\Microsoft\Windows\Start Menu\desktop.ini
  • C:\Users\Harry Dresden\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\Windows Media Player.lnk
  • C:\Users\Public
  • C:\ProgramData\Microsoft
  • C:\Users\Harry Dresden\AppData\Roaming\Microsoft\Windows
  • C:\Program Files (x86)\
  • C:\ProgramData\Microsoft\Windows\Start Menu\Programs\腾讯软件\QQ音乐
  • C:\Users\Harry Dresden\AppData\Local\Microsoft\Windows\Explorer\thumbcache_idx.db
  • C:\Users\Harry Dresden\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\desktop.ini
  • C:\Program Files\desktop.ini
  • C:\Users\Harry Dresden\AppData\Local\Microsoft\Windows\Explorer\thumbcache_1024.db
  • C:\Program Files\Internet Explorer\iexplore.exe
  • C:\Users\Harry Dresden\AppData
  • \Device\NamedPipe\
  • C:\Program Files (x86)\Tencent\QQmusic
  • C:\
  • C:\Windows\Globalization\Sorting\sortdefault.nls
  • C:\Users\Harry Dresden\AppData\Local\Microsoft\Windows\Caches\cversions.1.db
  • C:\Program Files (x86)\Tencent\QQMusicHelper\QQMusicHelper1257.22.16.26\QQMusicHelper.dll
  • C:\Program Files (x86)
  • C:\Program Files (x86)\Tencent\QQMusicHelper\QQMusicHelper1257.22.16.26
  • C:\Users\Harry Dresden\Desktop\desktop.ini
  • C:\Program Files (x86)\Tencent\QQmusic\QQMusic1273.22.15.58\QQMusicHelperSetup.exe
  • C:\Program Files (x86)\desktop.ini
  • C:\Program Files (x86)\Tencent
  • C:\Users\Harry Dresden\AppData\Local\Microsoft\Windows\Caches\{AFBF9F1A-8EE8-4C77-AF34-C647E37CA0D9}.1.ver0x0000000000000001.db
  • C:\Program Files (x86)\Common Files\Tencent\TXSSO\1.2.3.15\bin\SSOLUIControl.dll
  • C:\Program Files (x86)\Tencent\QQmusic\QQMusicInstall\QQMusicMMInstaller.dll
  • C:\Windows\Globalization\Sorting\sortdefault.nls
  • C:\Program Files (x86)\Common Files\Tencent\TXSSO\1.2.3.15\bin\SSOCommon.dll
File-Moved
  • C:\Users\Harry Dresden\AppData\Local\Temp\nsa2B6.tmp\ ->
  • C:\Users\Harry Dresden\AppData\Local\Temp\nsa2B6.tmp\nsExec.dll ->
Network-Connects IP
  • 174.35.25.75
  • 174.35.25.70
Network-Connects Host
  • s.plcloud.music.qq.com
  • dldir1.qq.com
Directory-Created
  • C:\Users\Harry Dresden\AppData\Roaming\Tencent\QQMusic\QQMusicCache\Log\QQMusicAgent
  • C:\Users\Harry Dresden\AppData\Roaming\Tencent\QQMusic\QQMusicCache\Log\QQMusicSvr
  • C:\Users\Harry Dresden\AppData\Roaming\Tencent\QQMusic\QQMusicCache\Log\QQMusicAgent
  • C:\Users\Harry Dresden
  • C:\Users\Harry Dresden\AppData\Local\Microsoft\Windows\Caches
  • C:\Users\Harry Dresden\AppData\Local\Temp
  • C:\Users\Harry Dresden\AppData\Roaming\Tencent\QQMusic\Log
  • C:\Users\Harry Dresden\AppData\Roaming
  • C:\Users\Harry Dresden\AppData\Roaming\Tencent
  • C:\Users\Harry Dresden\AppData\Local\Temp\nsa2A47.tmp
  • C:\Users\Harry Dresden\AppData\Local
  • C:\Users\Harry Dresden\AppData\Local\Temp\
  • C:\Program Files (x86)\Tencent\QQmusic
  • C:\Users\Harry Dresden\AppData\Roaming\Tencent\QQMusic
  • C:\Program Files (x86)
  • C:\Users
  • C:\Users\Harry Dresden\AppData\Roaming\Tencent\QQMusic\Log\QQMusicInstall
  • C:\Program Files (x86)\Tencent\QQmusic\QQMusicInstall
  • C:\Program Files (x86)\Tencent
  • C:\Users\Harry Dresden\AppData
  • C:\Users\Harry Dresden
  • C:\Users\Harry Dresden\AppData\Local\Microsoft\Windows\Caches
  • C:\Users\Harry Dresden\AppData\Roaming\Tencent\QQMusicMMInstallCache
  • C:\Users\Harry Dresden\AppData\Roaming\Tencent\QQMusic\Temp\
  • C:\Users\Harry Dresden\AppData\Roaming\Tencent
  • C:\Users\Harry Dresden\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\YLC2QM2Y
  • C:\Users
  • C:\Users\Harry Dresden\AppData\Roaming
  • C:\Users\Harry Dresden\AppData
  • C:\Program Files (x86)\Common Files\Tencent\TXSSO\1.2.3.15
  • C:\Users\Harry Dresden\AppData\Roaming\Tencent\TXSSO\
  • C:\Program Files (x86)\Common Files
  • C:\Program Files (x86)\Common Files\Tencent\TXSSO\I18N\
  • C:\Program Files (x86)\Common Files\Tencent
  • C:\Program Files (x86)\Common Files\Tencent\TXSSO\Bin\
  • C:\Program Files (x86)\Common Files\Tencent\TXSSO\1.2.3.15\
  • C:\Program Files (x86)
  • C:\Users\Harry Dresden\AppData\Roaming\Tencent\
  • C:\Users\Harry Dresden\AppData\Roaming\Tencent\TXSSO\SetupLogs\
  • C:\Program Files (x86)\Common Files\Tencent\TXSSO
  • C:\Users\Harry Dresden\AppData\Roaming\Tencent\Logs\
  • C:\Users\Harry Dresden\AppData\Roaming\Tencent\
  • C:\Users\Harry Dresden\AppData\Roaming\Tencent\QQMusic\QQMusicCache\Log\DataTransformex
  • C:\Users\Harry Dresden
  • C:\Users\Harry Dresden\AppData\Local\Microsoft\Windows\Explorer
  • C:\Users\Harry Dresden\AppData\Roaming
  • C:\Users\Harry Dresden\AppData\Roaming\Microsoft\Windows\Recent\AutomaticDestinations
  • C:\Users\Harry Dresden\AppData\Roaming\Microsoft\Windows\Recent
  • C:\Users\Harry Dresden
  • C:\Users\Harry Dresden\AppData\Local\Microsoft\Windows\Caches
  • C:\Users\Harry Dresden\AppData\Local\Temp
  • C:\Program Files (x86)\Tencent\QQMusicHelper\QQMusicHelper1257.22.16.26
  • C:\Users\Harry Dresden\AppData\Local
  • C:\Users\Harry Dresden\AppData\Local\Temp\nsa2B6.tmp
  • C:\Users\Harry Dresden\AppData\Local\Temp\
  • C:\Program Files (x86)
  • C:\Users
  • C:\Program Files (x86)\Tencent
  • C:\Users\Harry Dresden\AppData
  • C:\Program Files (x86)\Tencent\QQMusicHelper
  • C:\Users\Harry Dresden\AppData\Roaming\Tencent\Logs\
  • C:\Users\Harry Dresden\AppData\Roaming\Tencent\
  • C:\Users\Harry Dresden\AppData\Roaming\Tencent\Logs\
  • C:\Users\Harry Dresden\AppData\Roaming\Tencent\
  • C:\Program Files (x86)\Common Files\Tencent\QQMusic\
Directory-Removed
  • C:\Users\Harry Dresden\AppData\Local\Temp\nsa2A47.tmp\
  • C:\Users\Harry Dresden\AppData\Local\Temp\nsa2B6.tmp\
Directory-Enumerated
  • C:\Program Files (x86)\Tencent\QQMusicHelper
  • C:\Windows\System32\netsh.*
  • C:\Program Files (x86)\Tencent\QQMusicHelper\QQMusicHelper1257.22.16.26\netsh.*
  • C:\Program Files (x86)\Tencent\QQMusicHelper\QQMusicHelper1257.22.16.26\netsh
  • C:\Program Files (x86)
  • C:\Windows\System32\netsh.COM
  • C:\Program Files (x86)\Tencent\QQMusicHelper\QQMusicHelper1257.22.16.26
  • C:\Program Files (x86)\Tencent
  • C:\Windows\System32\netsh.exe
  • C:\Users\Harry Dresden
  • C:\Users\Harry Dresden\AppData\Local\Temp
  • C:\Users\Harry Dresden\AppData
  • C:\Users\Harry Dresden\AppData\Local
  • C:\Users
  • C:\Program Files (x86)\Tencent\QQmusic\*.*
  • C:\Users\Harry Dresden
  • C:\Program Files (x86)\Tencent\QQmusic
  • C:\Windows\System32\*.*
  • C:\Users\Harry Dresden\AppData\Local\Temp\nsa2A47.tmp\*.*
  • C:\Users\Harry Dresden\AppData\Local\Temp
  • C:\Users\Harry Dresden\AppData\Local
  • C:\Windows
  • C:\Users
  • C:\Users\Harry Dresden\AppData\Local\Temp\nsa2A47.tmp
  • C:\Windows\System32
  • C:\Program Files (x86)\Tencent
  • C:\Users\Harry Dresden\AppData
  • C:\Windows\System32\shdocvw.dll
  • C:\Users\Harry Dresden\AppData\Roaming\Tencent
  • C:\Users\Harry Dresden\AppData\Roaming\Tencent\QQMusicMMInstallCache\*.*
  • C:\Windows\System32\shdocvw.dll
  • C:\Program Files (x86)\Tencent\QQmusic
  • C:\Program Files (x86)\Tencent
  • C:\Users
  • C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscoreei.dll
  • C:\Users\Harry Dresden\AppData\Roaming\Tencent\QQMusicMMInstallCache\*.exe
  • C:\Windows
  • C:\Users\Harry Dresden\AppData\Roaming\Tencent\QQMusicMMInstallCache\*.tdl
  • C:\Windows\System32\*.*
  • C:\Users\Harry Dresden\AppData\Roaming
  • C:\Users\Harry Dresden\AppData
  • C:\Windows\System32
  • C:\Windows\System32\ntshrui.dll
  • C:\Program Files (x86)\Common Files\Tencent\TXSSO\*
  • C:\Windows\System32\*.*
  • C:\Windows
  • C:\Windows\System32
  • C:\Users\Harry Dresden\AppData\Roaming\Tencent\Logs\regsvr32.tlg
  • C:\Users\Harry Dresden
  • C:\Program Files (x86)\Tencent\QQMusicHelper\*.*
  • C:\Users\Harry Dresden\AppData\Local\Temp
  • C:\Users\Harry Dresden\AppData\Local\Temp\nsa2B6.tmp\*.*
  • C:\Users\Harry Dresden\AppData\Local
  • C:\Users\Harry Dresden\AppData
  • C:\Program Files (x86)
  • C:\Users
  • C:\Program Files (x86)\Tencent
  • C:\Users\Harry Dresden\AppData\Local\Temp\nsa2B6.tmp
  • C:\Program Files (x86)\Tencent\QQMusicHelper
  • C:\Users\Harry Dresden\AppData\Roaming\Tencent\Logs\regsvr32.tlg
  • C:\Users\Harry Dresden\AppData\Roaming\Tencent\Logs\regsvr32.tlg
Registry Key-Opened
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Cryptography\Defaults\Provider\Microsoft Strong Cryptographic Provider
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\napagent\LocalConfig\Qecs\79619
  • HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Tcpip6\Parameters
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\napagent\LocalConfig\Qecs\79617
  • HKEY_LOCAL_MACHINE\Software\Microsoft\Cryptography\OID\EncodingType 0\CryptDllFindOIDInfo\1.3.6.1.4.1.311.44.3.4!7
  • HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\IPSEC\Policy\Local
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Cryptography\Defaults\Provider\Microsoft Base Cryptographic Provider v1.0
  • HKEY_CURRENT_USER\Interface\{00000134-0000-0000-C000-000000000046}
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Cryptography\Defaults\Provider\Microsoft DH SChannel Cryptographic Provider
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Cryptography\Defaults\Provider
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Cryptography\Defaults\Provider\Microsoft Enhanced Cryptographic Provider v1.0
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Cryptography\Defaults\Provider\Microsoft Base DSS Cryptographic Provider
  • HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\crypt32
  • HKEY_LOCAL_MACHINE\Software\Microsoft\Cryptography\OID\EncodingType 0\CryptDllFindOIDInfo\1.3.6.1.4.1.311.64.1.1!7
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\napagent\Qecs\79621
  • HKEY_LOCAL_MACHINE\Software\Microsoft\Cryptography\OID
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\napagent\LocalConfig\Enroll\HcsGroups\(Default)
  • HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\BFE
  • HKEY_LOCAL_MACHINE\System\Setup
  • HKEY_LOCAL_MACHINE\Software\Microsoft\Rpc\SecurityService
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Cryptography\Defaults\Provider\Microsoft RSA SChannel Cryptographic Provider
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Cryptography\OID\EncodingType 0\CryptDllFindOIDInfo
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Cryptography\OID\EncodingType 0\CryptDllFindOIDInfo\1.3.6.1.4.1.311.47.1.1!7
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Cryptography\OID\EncodingType 0\CryptDllFindOIDInfo\1.3.6.1.4.1.311.64.1.1!7
  • HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\NapAgent\LocalConfig
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Cryptography\Defaults\Provider\Microsoft Base Smart Card Crypto Provider
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\napagent\LocalConfig\Qecs\79621
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\napagent\LocalConfig\Qecs\79623
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Cryptography\OID\EncodingType 0\CryptDllFindOIDInfo\1.3.6.1.4.1.311.44.3.4!7
  • HKEY_LOCAL_MACHINE\SYSTEM\Setup
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Cryptography\Defaults\Provider\Microsoft Base DSS and Diffie-Hellman Cryptographic Provider
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\napagent\LocalConfig\UI
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Cryptography\Defaults\Provider\Microsoft Enhanced RSA and AES Cryptographic Provider
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\napagent\Qecs\79623
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Cryptography\Defaults\Provider\Microsoft Enhanced DSS and Diffie-Hellman Cryptographic Provider
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\napagent\Qecs\79617
  • HKEY_LOCAL_MACHINE\Software\Microsoft\Cryptography\OID\EncodingType 0\CryptDllFindOIDInfo\1.3.6.1.4.1.311.47.1.1!7
  • HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\LDAP
  • HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\iphlpsvc\Config
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\napagent\LocalConfig\Enroll\HcsGroups
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\napagent\Qecs\79619
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\napagent\LocalConfig\(Default)
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\NetSh
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{00000134-0000-0000-C000-000000000046}\ProxyStubClsid32
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Cryptography\OID\EncodingType 0
  • HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\System
  • HKEY_CURRENT_USER\Software\Microsoft\Command Processor
  • HKEY_LOCAL_MACHINE\Software\Microsoft\Command Processor
  • HKEY_CLASSES_ROOT\QQMusic.aac\Shell\open\Command
  • HKEY_CLASSES_ROOT\QQMusic.cue\DefaultIcon
  • HKEY_CLASSES_ROOT\.ogg
  • HKEY_CLASSES_ROOT\Directory
  • HKEY_CLASSES_ROOT\QQMusic.dts\Shell\QQMusic.2.Add
  • HKEY_CLASSES_ROOT\QQMusic.lrc\Shell\QQMusic.2.Add
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.wav\UserChoice
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.ape\OpenWithProgids
  • HKEY_CLASSES_ROOT\.aac
  • HKEY_CLASSES_ROOT\.lrc
  • HKEY_CLASSES_ROOT\QQMusic.ac3\Shell\open\Command
  • HKEY_CLASSES_ROOT\QQMusic.tac\DefaultIcon
  • HKEY_CLASSES_ROOT\QQMusic.mp3\Shell\open\Command
  • HKEY_CLASSES_ROOT\.flac
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.mp3\OpenWithProgids
  • HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\App Paths\QQMusicAgent.exe
  • HKEY_CLASSES_ROOT\QQMusic.ogg\DefaultIcon
  • HKEY_CLASSES_ROOT\QQMusic.flac\Shell\open\Command
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.caf\OpenWithProgids
  • HKEY_CLASSES_ROOT\QQMusic.mp3\Shell\QQMusic.2.Add\Command
  • HKEY_CLASSES_ROOT\QQMusic.wav
  • HKEY_CLASSES_ROOT\QQMusic.lrc\DefaultIcon
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.cue\UserChoice
  • HKEY_CLASSES_ROOT\QQMusic.lrc\Shell\open\Command
  • HKEY_CLASSES_ROOT\QQMusic.mp3\Shell\open
  • HKEY_CLASSES_ROOT\Drive\shellex\FolderExtensions
  • HKEY_CLASSES_ROOT\QQMusic.ape\Shell\QQMusic.2.Add\Command
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.wav\OpenWithList
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.tac\OpenWithProgids
  • HKEY_CLASSES_ROOT\.tac
  • HKEY_CLASSES_ROOT\QQMusic.tta\DefaultIcon
  • HKEY_CLASSES_ROOT\QQMusic.aac\Shell\open
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.lrc\UserChoice
  • HKEY_CLASSES_ROOT\QQMusic.mp3\DefaultIcon
  • HKEY_CURRENT_USER\SOFTWARE\Tencent\QQMusic\LogConfig
  • HKEY_CLASSES_ROOT\QQMusic.flac\Shell\QQMusic.2.Add\Command
  • HKEY_CLASSES_ROOT\Directory\Shell\QQMusic.1.Play
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.AAC\OpenWithProgids
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.mp3
  • HKEY_CLASSES_ROOT\.cue
  • HKEY_CLASSES_ROOT\QQMusic.tta
  • HKEY_CLASSES_ROOT\QQMusic.m4a\Shell\QQMusic.2.Add
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.ogg\OpenWithProgids
  • HKEY_CLASSES_ROOT\CLSID\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\ShellFolder
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.ac3\UserChoice
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.qrc
  • HKEY_CLASSES_ROOT\QQMusic.lrc\Shell
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\
  • HKEY_CLASSES_ROOT\QQMusic.ac3\Shell\QQMusic.2.Add
  • HKEY_CLASSES_ROOT\QQMusic.cue\Shell\open
  • HKEY_CLASSES_ROOT\Directory\Shell\QQMusic.2.Add\Command
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.dts\OpenWithList
  • HKEY_CLASSES_ROOT\QQMusic.qrc\Shell\open
  • HKEY_CLASSES_ROOT\QQMusic.ogg\Shell\QQMusic.2.Add\Command
  • HKEY_CLASSES_ROOT\QQMusic.qrc\DefaultIcon
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellCompatibility\Applications\QQMusicAgent.exe
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.ac3\OpenWithList
  • HKEY_CLASSES_ROOT\QQMusic.caf\Shell
  • HKEY_CLASSES_ROOT\QQMusic.dts\Shell
  • HKEY_CLASSES_ROOT\QQMusic.aac\DefaultIcon
  • HKEY_CLASSES_ROOT\QQMusic.tac\Shell
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.flac
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.m4a
  • HKEY_CLASSES_ROOT\applications
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.wma\UserChoice
  • HKEY_CLASSES_ROOT\QQMusic.ac3\Shell
  • HKEY_CLASSES_ROOT\QQMusic.ogg\Shell\open
  • HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer
  • HKEY_CLASSES_ROOT\QQMusic.qrc\Shell\QQMusic.2.Add\Command
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.flac\OpenWithProgids
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.wma
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.aac\OpenWithList
  • HKEY_CLASSES_ROOT\QQMusic.tta\Shell
  • HKEY_CLASSES_ROOT\QQMusic.wma\Shell
  • HKEY_CLASSES_ROOT\.wav
  • HKEY_CLASSES_ROOT\.m4a
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.tac\OpenWithList
  • HKEY_CLASSES_ROOT\QQMusic.wma\Shell\open\Command
  • HKEY_CLASSES_ROOT\QQMusic.m4a\Shell\open\Command
  • HKEY_CLASSES_ROOT\QQMusic.wma\DefaultIcon
  • HKEY_CLASSES_ROOT\QQMusic.lrc\Shell\open
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.dts\OpenWithProgids
  • HKEY_CLASSES_ROOT\QQMusic.ape\Shell
  • HKEY_CLASSES_ROOT\QQMusic.ogg\Shell\QQMusic.2.Add
  • HKEY_CLASSES_ROOT\QQMusic.caf
  • HKEY_CLASSES_ROOT\QQMusic.flac\DefaultIcon
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.flac\OpenWithList
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.lrc
  • HKEY_CLASSES_ROOT\QQMusic.qrc\Shell\QQMusic.2.Add
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.qrc\UserChoice
  • HKEY_CLASSES_ROOT\QQMusic.cue\Shell\QQMusic.2.Add\Command
  • HKEY_CLASSES_ROOT\QQMusic.cue\Shell\open\Command
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.wav\OpenWithProgids
  • HKEY_CLASSES_ROOT\QQMusic.aac\Shell
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.m4a\OpenWithProgids
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.ogg
  • HKEY_CLASSES_ROOT\QQMusic.wma\Shell\open
  • HKEY_CLASSES_ROOT\QQMusic.ac3
  • HKEY_CLASSES_ROOT\QQMusic.lrc\Shell\QQMusic.2.Add\Command
  • HKEY_CLASSES_ROOT\QQMusic.wav\Shell\QQMusic.2.Add\Command
  • HKEY_CLASSES_ROOT\QQMusic.tac\Shell\QQMusic.2.Add\Command
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.qrc\OpenWithProgids
  • HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\App Paths\QQMusicAgent.exe
  • HKEY_CLASSES_ROOT\.wma
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.m4a\OpenWithList
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.ac3\OpenWithProgids
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\CLSID\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\ShellFolder
  • HKEY_CLASSES_ROOT\QQMusic.ogg
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.tta\OpenWithProgids
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.mp3\OpenWithList
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\NonEnum
  • HKEY_CLASSES_ROOT\QQMusic.dts
  • HKEY_CLASSES_ROOT\.dts
  • HKEY_CLASSES_ROOT\QQMusic.aac
  • HKEY_CLASSES_ROOT\QQMusic.tac\Shell\QQMusic.2.Add
  • HKEY_CLASSES_ROOT\QQMusic.tac\Shell\open
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.tta\OpenWithList
  • HKEY_CURRENT_USER\SOFTWARE\TENCENT\QQMusic\LogConfig
  • HKEY_CLASSES_ROOT\QQMusic.tta\Shell\QQMusic.2.Add
  • HKEY_CLASSES_ROOT\Drive\shellex\FolderExtensions\{fbeb8a05-beee-4442-804e-409d6c4515e9}
  • HKEY_CLASSES_ROOT\QQMusic.flac\Shell\open
  • HKEY_CLASSES_ROOT\QQMusic.wav\Shell
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.wma\OpenWithProgids
  • HKEY_CLASSES_ROOT\.caf
  • HKEY_CLASSES_ROOT\QQMusic.flac\Shell
  • HKEY_CLASSES_ROOT\Directory\Shell
  • HKEY_CLASSES_ROOT\QQMusic.tta\Shell\open\Command
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.ogg\OpenWithList
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.ac3
  • HKEY_CLASSES_ROOT\QQMusic.caf\Shell\open
  • HKEY_CLASSES_ROOT\.tta
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.cue\OpenWithProgids
  • HKEY_CLASSES_ROOT\QQMusic.m4a
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.caf\OpenWithList
  • HKEY_CLASSES_ROOT\QQMusic.wav\DefaultIcon
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.qrc\OpenWithList
  • HKEY_CLASSES_ROOT\QQMusic.wav\Shell\QQMusic.2.Add
  • HKEY_CURRENT_USER\Applications\QQMusic.exe
  • HKEY_CLASSES_ROOT\QQMusic.wav\Shell\open
  • HKEY_CLASSES_ROOT\Directory\Shell\QQMusic.2.Add
  • HKEY_CLASSES_ROOT\QQMusic.ape\Shell\open
  • HKEY_CLASSES_ROOT\QQMusic.dts\Shell\open
  • HKEY_CLASSES_ROOT\QQMusic.wma
  • HKEY_CLASSES_ROOT\QQMusic.tta\Shell\QQMusic.2.Add\Command
  • HKEY_CLASSES_ROOT\QQMusic.aac\Shell\QQMusic.2.Add\Command
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.lrc\OpenWithProgids
  • HKEY_CLASSES_ROOT\QQMusic.tac\Shell\open\Command
  • HKEY_CLASSES_ROOT\QQMusic.tac
  • HKEY_CLASSES_ROOT\QQMusic.dts\DefaultIcon
  • HKEY_CLASSES_ROOT\QQMusic.aac\Shell\QQMusic.2.Add
  • HKEY_CLASSES_ROOT\QQMusic.caf\DefaultIcon
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.dts\UserChoice
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.ape\OpenWithList
  • HKEY_CLASSES_ROOT\QQMusic.ape\DefaultIcon
  • HKEY_CLASSES_ROOT\QQMusic.flac\Shell\QQMusic.2.Add
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.cue\OpenWithList
  • HKEY_CLASSES_ROOT\QQMusic.ac3\Shell\QQMusic.2.Add\Command
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.tta\UserChoice
  • HKEY_CLASSES_ROOT\QQMusic.m4a\Shell\open
  • HKEY_CLASSES_ROOT\QQMusic.dts\Shell\open\Command
  • HKEY_CLASSES_ROOT\QQMusic.caf\Shell\QQMusic.2.Add
  • HKEY_CLASSES_ROOT\QQMusic.ape
  • HKEY_CLASSES_ROOT\QQMusic.lrc
  • HKEY_CLASSES_ROOT\QQMusic.m4a\DefaultIcon
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.aac\OpenWithProgids
  • HKEY_CLASSES_ROOT\Directory\Shell\QQMusic.1.Play\Command
  • HKEY_CLASSES_ROOT\.ape
  • HKEY_CLASSES_ROOT\QQMusic.mp3\Shell\QQMusic.2.Add
  • HKEY_CLASSES_ROOT\QQMusic.m4a\Shell\QQMusic.2.Add\Command
  • HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\CLSID\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\ShellFolder
  • HKEY_CLASSES_ROOT\.qrc
  • HKEY_CLASSES_ROOT\QQMusic.m4a\Shell
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.mp3\UserChoice
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.wav
  • HKEY_CLASSES_ROOT\QQMusic.ape\Shell\QQMusic.2.Add
  • HKEY_CLASSES_ROOT\QQMusic.qrc
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.dts
  • HKEY_CLASSES_ROOT\QQMusic.qrc\Shell
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.tta
  • HKEY_CLASSES_ROOT\QQMusic.ac3\Shell\open
  • HKEY_CLASSES_ROOT\QQMusic.wav\Shell\open\Command
  • HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\NonEnum
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.tac\UserChoice
  • HKEY_CLASSES_ROOT\QQMusic.mp3\Shell
  • HKEY_CLASSES_ROOT\QQMusic.ogg\Shell
  • HKEY_CLASSES_ROOT\QQMusic.mp3
  • HKEY_CLASSES_ROOT\.mp3
  • HKEY_CLASSES_ROOT\QQMusic.ac3\DefaultIcon
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.tac
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.ogg\UserChoice
  • HKEY_CLASSES_ROOT\QQMusic.cue\Shell\QQMusic.2.Add
  • HKEY_CLASSES_ROOT\QQMusic.tta\Shell\open
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.aac\UserChoice
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.cue
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.caf
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.ape\UserChoice
  • HKEY_CLASSES_ROOT\QQMusic.wma\Shell\QQMusic.2.Add
  • HKEY_CLASSES_ROOT\QQMusic.ogg\Shell\open\Command
  • HKEY_CLASSES_ROOT\QQMusic.cue\Shell
  • HKEY_CLASSES_ROOT\QQMusic.cue
  • HKEY_CLASSES_ROOT\QQMusic.ape\Shell\open\Command
  • HKEY_CLASSES_ROOT\QQMusic.qrc\Shell\open\Command
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.aac
  • HKEY_CLASSES_ROOT\QQMusic.dts\Shell\QQMusic.2.Add\Command
  • HKEY_CLASSES_ROOT\QQMusic.wma\Shell\QQMusic.2.Add\Command
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.caf\UserChoice
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.wma\OpenWithList
  • HKEY_CLASSES_ROOT\QQMusic.caf\Shell\QQMusic.2.Add\Command
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.ape
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.m4a\UserChoice
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.lrc\OpenWithList
  • HKEY_CLASSES_ROOT\.ac3
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.flac\UserChoice
  • HKEY_CLASSES_ROOT\QQMusic.caf\Shell\open\Command
  • HKEY_CLASSES_ROOT\QQMusic.flac
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{B07CCA0D-7B19-4921-868C-46B6C837825D}\ProxyStubClsid32
  • HKEY_CLASSES_ROOT\QQMusicSvr.QQMusicCreator
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{26531F78-5FBE-4961-8E0E-46ADE4614A3B}\LocalServer32
  • HKEY_CURRENT_USER\Wow6432Node\Interface\{DE5BCB71-1D17-49AF-9864-54A0706BF406}
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\QQMusicSvr.QQMusicControl\CurVer
  • HKEY_CLASSES_ROOT\QQMusicSvr.QQMusicControl
  • HKEY_CURRENT_USER\AppID\{CB9BCD4B-03B5-4487-AC8F-6164DD6433AB}
  • HKEY_CURRENT_USER\Interface\{E0044E80-24E6-401E-A45A-EFD702538ACA}
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\QQMusicSvr.QQMusicControl\CLSID
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{26531F78-5FBE-4961-8E0E-46ADE4614A3B}\TypeLib
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\QQMusicSvr.QQMusicPlayer\CurVer
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{6927992D-6A89-4549-8A32-95901BF5D920}\VersionIndependentProgID
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{5DECBE69-994F-45BA-B010-FD604F4B1E8A}\Programmable
  • HKEY_CURRENT_USER\Interface\{D521927A-0430-4BE0-ABE7-817A77E833FD}
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{F9D51BBE-F69E-4D7E-8A36-9D65B534F508}\ProxyStubClsid32
  • HKEY_CURRENT_USER\Wow6432Node\Interface\{F9D51BBE-F69E-4D7E-8A36-9D65B534F509}
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{6927992D-6A89-4549-8A32-95901BF5D920}\TypeLib
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D4C131B2-5B11-47FF-ABC5-081AB498EA5D}\Programmable
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D4C131B2-5B11-47FF-ABC5-081AB498EA5D}\VersionIndependentProgID
  • HKEY_CURRENT_USER\TypeLib\{C4549B07-549D-46C4-AAF6-49CC54B99F69}
  • HKEY_CURRENT_USER\Wow6432Node\Interface\{10126174-A34C-4DA4-9B5A-B71DE87EDD34}
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{D521927A-0430-4BE0-ABE7-817A77E833FD}\TypeLib
  • HKEY_CURRENT_USER\Interface
  • HKEY_CURRENT_USER\Interface\{10126174-A34C-4DA4-9B5A-B71DE87EDD34}
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{F9D51BBE-F69E-4D7E-8A36-9D65B534F509}\TypeLib
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{26531F78-5FBE-4961-8E0E-46ADE4614A3B}\VersionIndependentProgID
  • HKEY_CURRENT_USER\Wow6432Node\Interface\{C44022F3-7CB2-401A-A6B9-C380F22D4754}
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{FB6ADB8F-B2F9-41BB-9B4F-ACD09FA1360F}\ProgID
  • HKEY_CURRENT_USER\Interface\{D521927A-0430-4BE0-ABE7-817A77E833FC}
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{D521927A-0430-4BE0-ABE7-817A77E833FC}\TypeLib
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{5DECBE69-994F-45BA-B010-FD604F4B1E8A}\ProgID
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{6927992D-6A89-4549-8A32-95901BF5D920}\LocalServer32
  • HKEY_CURRENT_USER\Interface\{F9D51BBE-F69E-4D7E-8A36-9D65B534F508}
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{C4549B07-549D-46C4-AAF6-49CC54B99F69}\1.0\0\win32
  • HKEY_CURRENT_USER\Wow6432Node\Interface\{D521927A-0430-4BE0-ABE7-817A77E833FC}
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{D521927A-0430-4BE0-ABE7-817A77E833FD}\ProxyStubClsid32
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D4C131B2-5B11-47FF-ABC5-081AB498EA5D}\LocalServer32
  • HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer
  • HKEY_CURRENT_USER\Interface\{C44022F3-7CB2-401A-A6B9-C380F22D4754}
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{F9D51BBE-F69E-4D7E-8A36-9D65B534F508}\TypeLib
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{10126174-A34C-4DA4-9B5A-B71DE87EDD34}\TypeLib
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer
  • HKEY_CLASSES_ROOT\QQMusicSvr.QQMusicCreator.1
  • HKEY_CLASSES_ROOT\QQMusicSvr.QQMusicPlayer.1
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{FB6ADB8F-B2F9-41BB-9B4F-ACD09FA1360F}\Programmable
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{DE5BCB71-1D17-49AF-9864-54A0706BF406}\ProxyStubClsid32
  • HKEY_CLASSES_ROOT\QQMusicSvr2.QQMusicPlayer2
  • HKEY_CLASSES_ROOT\CLSID\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\ShellFolder
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{B07CCA0D-7B19-4921-868C-46B6C837825D}\TypeLib
  • HKEY_CURRENT_USER\Interface\{F9D51BBE-F69E-4D7E-8A36-9D65B534F509}
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{DE5BCB71-1D17-49AF-9864-54A0706BF406}\TypeLib
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\QQMusicSvr.QQMusicCreator\CurVer
  • HKEY_CURRENT_USER\Interface\{B07CCA0D-7B19-4921-868C-46B6C837825D}
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{5DECBE69-994F-45BA-B010-FD604F4B1E8A}\VersionIndependentProgID
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\QQMusicSvr.QQMusicLyric.1\CLSID
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{FB6ADB8F-B2F9-41BB-9B4F-ACD09FA1360F}\LocalServer32
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\QQMusicSvr.QQMusicPlayer\CLSID
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\CLSID\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\ShellFolder
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\QQMusicSvr.QQMusicLyric\CurVer
  • HKEY_CURRENT_USER\Interface\{DE5BCB71-1D17-49AF-9864-54A0706BF406}
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{B07CCA0D-7B19-4921-868C-46B6C837825D}\TypeLib
  • HKEY_CLASSES_ROOT\QQMusicSvr.QQMusicLyric.1
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{E0044E80-24E6-401E-A45A-EFD702538ACA}\ProxyStubClsid32
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{D521927A-0430-4BE0-ABE7-817A77E833FC}\ProxyStubClsid32
  • HKEY_CURRENT_USER\Wow6432Node\Interface\{D521927A-0430-4BE0-ABE7-817A77E833FD}
  • HKEY_CURRENT_USER\Wow6432Node\CLSID\{FB6ADB8F-B2F9-41BB-9B4F-ACD09FA1360F}
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{5DECBE69-994F-45BA-B010-FD604F4B1E8A}\LocalServer32
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{E0044E80-24E6-401E-A45A-EFD702538ACA}\TypeLib
  • HKEY_CLASSES_ROOT\QQMusicSvr.QQMusicControl.1
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{D521927A-0430-4BE0-ABE7-817A77E833FD}\ProxyStubClsid32
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\NonEnum
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{6927992D-6A89-4549-8A32-95901BF5D920}\ProgID
  • HKEY_CURRENT_USER\Wow6432Node\Interface\{E0044E80-24E6-401E-A45A-EFD702538ACA}
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\App Paths\QQMusicSvr.exe
  • HKEY_CURRENT_USER\SOFTWARE\TENCENT\QQMusic\LogConfig
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{D521927A-0430-4BE0-ABE7-817A77E833FD}\TypeLib
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{DE5BCB71-1D17-49AF-9864-54A0706BF406}\ProxyStubClsid32
  • HKEY_CLASSES_ROOT\Drive\shellex\FolderExtensions\{fbeb8a05-beee-4442-804e-409d6c4515e9}
  • HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\App Paths\QQMusicSvr.exe
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{10126174-A34C-4DA4-9B5A-B71DE87EDD34}\TypeLib
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{C4549B07-549D-46C4-AAF6-49CC54B99F69}\1.0\0
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{DE5BCB71-1D17-49AF-9864-54A0706BF406}\TypeLib
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{FB6ADB8F-B2F9-41BB-9B4F-ACD09FA1360F}\VersionIndependentProgID
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{C4549B07-549D-46C4-AAF6-49CC54B99F69}\1.0
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{F9D51BBE-F69E-4D7E-8A36-9D65B534F508}\TypeLib
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{C44022F3-7CB2-401A-A6B9-C380F22D4754}\ProxyStubClsid32
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D4C131B2-5B11-47FF-ABC5-081AB498EA5D}\ProgID
  • HKEY_CURRENT_USER\Wow6432Node\CLSID\{D4C131B2-5B11-47FF-ABC5-081AB498EA5D}
  • HKEY_LOCAL_MACHINE\SOFTWARE\TENCENT\QQMusic
  • HKEY_CLASSES_ROOT\AppID
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{F9D51BBE-F69E-4D7E-8A36-9D65B534F509}\ProxyStubClsid32
  • HKEY_CURRENT_USER\Wow6432Node\CLSID\{6927992D-6A89-4549-8A32-95901BF5D920}
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{10126174-A34C-4DA4-9B5A-B71DE87EDD34}\ProxyStubClsid32
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{C4549B07-549D-46C4-AAF6-49CC54B99F69}\1.0\HELPDIR
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D4C131B2-5B11-47FF-ABC5-081AB498EA5D}\TypeLib
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{6927992D-6A89-4549-8A32-95901BF5D920}\Programmable
  • HKEY_CLASSES_ROOT\QQMusicSvr.QQMusicLyric
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\QQMusicSvr2.QQMusicPlayer2\CurVer
  • HKEY_CLASSES_ROOT\CLSID
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{B07CCA0D-7B19-4921-868C-46B6C837825D}\ProxyStubClsid32
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{5DECBE69-994F-45BA-B010-FD604F4B1E8A}\TypeLib
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{C44022F3-7CB2-401A-A6B9-C380F22D4754}\TypeLib
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\QQMusicSvr2.QQMusicPlayer2.1\CLSID
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\QQMusicSvr.QQMusicControl.1\CLSID
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{D521927A-0430-4BE0-ABE7-817A77E833FC}\TypeLib
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{D521927A-0430-4BE0-ABE7-817A77E833FC}\ProxyStubClsid32
  • HKEY_CLASSES_ROOT\Drive\shellex\FolderExtensions
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{C44022F3-7CB2-401A-A6B9-C380F22D4754}\ProxyStubClsid32
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{26531F78-5FBE-4961-8E0E-46ADE4614A3B}\ProgID
  • HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\CLSID\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\ShellFolder
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\QQMusicSvr.QQMusicCreator\CLSID
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\QQMusicSvr.QQMusicPlayer.1\CLSID
  • HKEY_CURRENT_USER\Wow6432Node\CLSID\{26531F78-5FBE-4961-8E0E-46ADE4614A3B}
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\QQMusicSvr2.QQMusicPlayer2\CLSID
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{E0044E80-24E6-401E-A45A-EFD702538ACA}\ProxyStubClsid32
  • HKEY_CLASSES_ROOT\QQMusicSvr.QQMusicPlayer
  • HKEY_CURRENT_USER\Wow6432Node\CLSID\{5DECBE69-994F-45BA-B010-FD604F4B1E8A}
  • HKEY_CLASSES_ROOT\QQMusicSvr2.QQMusicPlayer2.1
  • HKEY_CURRENT_USER\Wow6432Node\Interface\{B07CCA0D-7B19-4921-868C-46B6C837825D}
  • HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\NonEnum
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{C44022F3-7CB2-401A-A6B9-C380F22D4754}\TypeLib
  • HKEY_CURRENT_USER\AppID\QQMusicSvr.EXE
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{C4549B07-549D-46C4-AAF6-49CC54B99F69}\1.0\FLAGS
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{F9D51BBE-F69E-4D7E-8A36-9D65B534F509}\ProxyStubClsid32
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\OLEAUT
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellCompatibility\Applications\QQMusicSvr.exe
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{26531F78-5FBE-4961-8E0E-46ADE4614A3B}\Programmable
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{F9D51BBE-F69E-4D7E-8A36-9D65B534F509}\TypeLib
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\QQMusicSvr.QQMusicCreator.1\CLSID
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{FB6ADB8F-B2F9-41BB-9B4F-ACD09FA1360F}\TypeLib
  • HKEY_CURRENT_USER\Wow6432Node\Interface\{F9D51BBE-F69E-4D7E-8A36-9D65B534F508}
  • HKEY_CURRENT_USER\SOFTWARE\Tencent\QQMusic\LogConfig
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{10126174-A34C-4DA4-9B5A-B71DE87EDD34}\ProxyStubClsid32
  • HKEY_CURRENT_USER\TypeLib
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{E0044E80-24E6-401E-A45A-EFD702538ACA}\TypeLib
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\QQMusicSvr.QQMusicLyric\CLSID
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{F9D51BBE-F69E-4D7E-8A36-9D65B534F508}\ProxyStubClsid32
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Cryptography\Defaults\Provider\Microsoft Strong Cryptographic Provider
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\napagent\LocalConfig\Qecs\79619
  • HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Tcpip6\Parameters
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\napagent\LocalConfig\Qecs\79617
  • HKEY_LOCAL_MACHINE\Software\Microsoft\Cryptography\OID\EncodingType 0\CryptDllFindOIDInfo\1.3.6.1.4.1.311.44.3.4!7
  • HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\IPSEC\Policy\Local
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Cryptography\Defaults\Provider\Microsoft Base Cryptographic Provider v1.0
  • HKEY_CURRENT_USER\Interface\{00000134-0000-0000-C000-000000000046}
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Cryptography\Defaults\Provider\Microsoft DH SChannel Cryptographic Provider
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Cryptography\Defaults\Provider
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Cryptography\Defaults\Provider\Microsoft Enhanced Cryptographic Provider v1.0
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Cryptography\Defaults\Provider\Microsoft Base DSS Cryptographic Provider
  • HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\crypt32
  • HKEY_LOCAL_MACHINE\Software\Microsoft\Cryptography\OID\EncodingType 0\CryptDllFindOIDInfo\1.3.6.1.4.1.311.64.1.1!7
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\napagent\Qecs\79621
  • HKEY_LOCAL_MACHINE\Software\Microsoft\Cryptography\OID
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\napagent\LocalConfig\Enroll\HcsGroups\(Default)
  • HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\BFE
  • HKEY_LOCAL_MACHINE\System\Setup
  • HKEY_LOCAL_MACHINE\Software\Microsoft\Rpc\SecurityService
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Cryptography\Defaults\Provider\Microsoft RSA SChannel Cryptographic Provider
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Cryptography\OID\EncodingType 0\CryptDllFindOIDInfo
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Cryptography\OID\EncodingType 0\CryptDllFindOIDInfo\1.3.6.1.4.1.311.47.1.1!7
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Cryptography\OID\EncodingType 0\CryptDllFindOIDInfo\1.3.6.1.4.1.311.64.1.1!7
  • HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\NapAgent\LocalConfig
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Cryptography\Defaults\Provider\Microsoft Base Smart Card Crypto Provider
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\napagent\LocalConfig\Qecs\79621
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\napagent\LocalConfig\Qecs\79623
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Cryptography\OID\EncodingType 0\CryptDllFindOIDInfo\1.3.6.1.4.1.311.44.3.4!7
  • HKEY_LOCAL_MACHINE\SYSTEM\Setup
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Cryptography\Defaults\Provider\Microsoft Base DSS and Diffie-Hellman Cryptographic Provider
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\napagent\LocalConfig\UI
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Cryptography\Defaults\Provider\Microsoft Enhanced RSA and AES Cryptographic Provider
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\napagent\Qecs\79623
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Cryptography\Defaults\Provider\Microsoft Enhanced DSS and Diffie-Hellman Cryptographic Provider
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\napagent\Qecs\79617
  • HKEY_LOCAL_MACHINE\Software\Microsoft\Cryptography\OID\EncodingType 0\CryptDllFindOIDInfo\1.3.6.1.4.1.311.47.1.1!7
  • HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\LDAP
  • HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\iphlpsvc\Config
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\napagent\LocalConfig\Enroll\HcsGroups
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\napagent\Qecs\79619
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\napagent\LocalConfig\(Default)
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\NetSh
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{00000134-0000-0000-C000-000000000046}\ProxyStubClsid32
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Cryptography\OID\EncodingType 0
  • HKEY_LOCAL_MACHINE\SOFTWARE\Tencent\QQMusic
  • HKEY_CURRENT_USER\SOFTWARE\Tencent\QQMusic\LogConfig
  • HKEY_CURRENT_USER\SOFTWARE\TENCENT\QQMusic\LogConfig
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{FDD39AD0-238F-46AF-ADB4-6C85480369C7}\PropertyBag
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{E555AB60-153B-4D17-9F04-A5FE99FC15EC}
  • HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\UsersFiles\NameSpace
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{6F0CD92B-2E97-45D1-88FF-B0D186B8DEDD}
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{C4900540-2379-4C75-844B-64E6FAF8716B}\PropertyBag
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{A302545D-DEFF-464B-ABE8-61C8648D939B}\PropertyBag
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{B88F4DAA-E7BD-49A9-B74D-02885A5DC765}
  • HKEY_CLASSES_ROOT\Directory
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{724EF170-A42D-4FEF-9F26-B60E846FBA4F}
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{A4115719-D62E-491D-AA7C-E74B8BE3B067}\PropertyBag
  • HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{7C5A40EF-A0FB-4BFC-874A-C0F2E0B9FA8E}\PropertyBag
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{D0384E7D-BAC3-4797-8F14-CBA229B392B5}\PropertyBag
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{724EF170-A42D-4FEF-9F26-B60E846FBA4F}\PropertyBag
  • HKEY_CURRENT_USER\Directory\DocObject
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{2A00375E-224C-49DE-B8D1-440DF7EF3DDC}
  • HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\ProfileList\S-1-5-21-3416602863-1947377224-293699093-1003
  • HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\UsersFiles\NameSpace\DelegateFolders
  • HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\CLSID\{59031A47-3F72-44A7-89C5-5595FE6B30EE}\ShellFolder
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{F1B32785-6FBA-4FCF-9D55-7B8E7F157091}
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{9E52AB10-F80D-49DF-ACB8-4330F5687855}
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{56784854-C6CB-462B-8169-88E350ACB882}
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{8983036C-27C0-404B-8F08-102D10DCFD74}
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{859EAD94-2E85-48AD-A71A-0969CB56A6CD}
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{859EAD94-2E85-48AD-A71A-0969CB56A6CD}\PropertyBag
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{69D2CF90-FC33-4FB7-9A0C-EBB0F0FCB43C}
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{F1B32785-6FBA-4FCF-9D55-7B8E7F157091}\PropertyBag
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{DEBF2536-E1A8-4C59-B6A2-414586476AEA}\PropertyBag
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{4BD8D571-6D19-48D3-BE97-422220080E43}\PropertyBag
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{3214FAB5-9757-4298-BB61-92A9DEAA44FF}\PropertyBag
  • HKEY_CLASSES_ROOT\Folder
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{374DE290-123F-4565-9164-39C4925E467B}\PropertyBag
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{C1BAE2D0-10DF-4334-BEDD-7AA20B227A9D}\PropertyBag
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AllFilesystemObjects\Clsid
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{0762D272-C50A-4BB0-A382-697DCD729B80}
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{DE974D24-D9C6-4D3E-BF91-F4455120B917}
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{DEBF2536-E1A8-4C59-B6A2-414586476AEA}
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{8AD10C31-2ADB-4296-A8F7-E4701232C972}
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{C4AA340D-F20F-4863-AFEF-F87EF2E6BA25}\PropertyBag
  • HKEY_CLASSES_ROOT\Drive\shellex\FolderExtensions
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{B250C668-F57D-4EE1-A63C-290EE7D1AA1F}
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{9E52AB10-F80D-49DF-ACB8-4330F5687855}\PropertyBag
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{DE92C1C7-837F-4F69-A3BB-86E631204A23}\PropertyBag
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{2B0F765D-C0E9-4171-908E-08A611B84FF6}\PropertyBag
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{DE61D971-5EBC-4F02-A3A9-6C82895E5C04}
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{D0384E7D-BAC3-4797-8F14-CBA229B392B5}
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{0AC0837C-BBF8-452A-850D-79D08E667CA7}
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\CPC\Volume
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{915221FB-9EFE-4BDA-8FD7-F78DCA774F87}
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Folder\ShellEx\IconHandler
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{0AC0837C-BBF8-452A-850D-79D08E667CA7}\PropertyBag
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{8983036C-27C0-404B-8F08-102D10DCFD74}\PropertyBag
  • HKEY_CLASSES_ROOT\CLSID\{DFFACDC5-679F-4156-8947-C5C76BC0B67F}\InProcServer32
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{A305CE99-F527-492B-8B1A-7E76FA98D6E4}
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{BFB9D5E0-C6A9-404C-B2B2-AE6DB6AF4968}
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{C1BAE2D0-10DF-4334-BEDD-7AA20B227A9D}
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{B94237E7-57AC-4347-9151-B08C6C32D1F7}
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{98EC0E18-2098-4D44-8644-66979315A281}
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{52A4F021-7B75-48A9-9F6B-4B87A210BC8F}
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\(Default)
  • HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\Explorer
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{3D644C9B-1FB8-4F30-9B45-F670235F79C0}
  • HKEY_CLASSES_ROOT\CLSID\{DFFACDC5-679F-4156-8947-C5C76BC0B67F}\ShellFolder
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{D20BEEC4-5CA8-4905-AE3B-BF251EA09B53}\PropertyBag
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{A990AE9F-A03B-4E80-94BC-9912D7504104}\PropertyBag
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{D65231B0-B2F1-4857-A4CE-A8E7C6EA7D27}
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{4D9F7874-4E0C-4904-967B-40B0D20C3E4B}\PropertyBag
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{DE974D24-D9C6-4D3E-BF91-F4455120B917}\PropertyBag
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{5CE4A5E9-E4EB-479D-B89F-130C02886155}\PropertyBag
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Folder\Clsid
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{B4BFCC3A-DB2C-424C-B029-7FE99A87C641}
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{352481E8-33BE-4251-BA85-6007CAEDCF9D}\PropertyBag
  • HKEY_CURRENT_USER\Directory\CurVer
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{4BD8D571-6D19-48D3-BE97-422220080E43}
  • HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Blocked
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{48DAF80B-E6CF-4F4E-B800-0E69D84EE384}\PropertyBag
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{7B396E54-9EC5-4300-BE0A-2482EBAE1A26}\PropertyBag
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\CPC\Volume\{b9fc273d-d442-11e0-8ee6-806e6f6e6963}\
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{3D644C9B-1FB8-4F30-9B45-F670235F79C0}\PropertyBag
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{2112AB0A-C86A-4FFE-A368-0DE96E47012E}\PropertyBag
  • HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows\Explorer
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\Shell\Associations\UrlAssociations\Directory
  • HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{7B396E54-9EC5-4300-BE0A-2482EBAE1A26}
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{C4AA340D-F20F-4863-AFEF-F87EF2E6BA25}
  • HKEY_LOCAL_MACHINE\Software\Microsoft\Rpc\SecurityService
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{4D9F7874-4E0C-4904-967B-40B0D20C3E4B}
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{A520A1A4-1780-4FF6-BD18-167343C5AF16}
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{A75D362E-50FC-4FB7-AC2C-A8BEAA314493}\PropertyBag
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{054FAE61-4DD8-4787-80B6-090220C4B700}
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{54EED2E0-E7CA-4FDB-9148-0F4247291CFA}\PropertyBag
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{82A5EA35-D9CD-47C5-9629-E15D2F714E6E}
  • HKEY_CLASSES_ROOT\CLSID\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\ShellFolder
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{DFDF76A2-C82A-4D63-906A-5644AC457385}
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\SessionInfo\1\UsersFiles\NameSpace\DelegateFolders
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AllFilesystemObjects\BrowseInPlace
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{E555AB60-153B-4D17-9F04-A5FE99FC15EC}\PropertyBag
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{2112AB0A-C86A-4FFE-A368-0DE96E47012E}
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{BCB5256F-79F6-4CEE-B725-DC34E402FD46}\PropertyBag
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{190337D1-B8CA-4121-A639-6D472D16972A}\PropertyBag
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{BFB9D5E0-C6A9-404C-B2B2-AE6DB6AF4968}\PropertyBag
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{5CD7AEE2-2219-4A67-B85D-6C9CE15660CB}\PropertyBag
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{69D2CF90-FC33-4FB7-9A0C-EBB0F0FCB43C}\PropertyBag
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\CLSID\{59031A47-3F72-44A7-89C5-5595FE6B30EE}\ShellFolder
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AllFilesystemObjects\DocObject
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{A77F5D77-2E2B-44C3-A6A2-ABA601054A51}\PropertyBag
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{3EB685DB-65F9-4CF6-A03A-E3EF65729F3D}
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\CLSID\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\ShellFolder
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{A75D362E-50FC-4FB7-AC2C-A8BEAA314493}
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{6F0CD92B-2E97-45D1-88FF-B0D186B8DEDD}\PropertyBag
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{5E6C858F-0E22-4760-9AFE-EA3317B67173}\PropertyBag
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{DFDF76A2-C82A-4D63-906A-5644AC457385}\PropertyBag
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{C870044B-F49E-4126-A9C3-B52A1FF411E8}
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{3EB685DB-65F9-4CF6-A03A-E3EF65729F3D}\PropertyBag
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{4BFEFB45-347D-4006-A5BE-AC0CB0567192}\PropertyBag
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{ED4824AF-DCE4-45A8-81E2-FC7965083634}
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{76FC4E2D-D6AD-4519-A663-37BD56068185}\PropertyBag
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{1B3EA5DC-B587-4786-B4EF-BD1DC332AEAE}
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{62AB5D82-FDC1-4DC3-A9DD-070D1D495D97}
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{62AB5D82-FDC1-4DC3-A9DD-070D1D495D97}\PropertyBag
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{B94237E7-57AC-4347-9151-B08C6C32D1F7}\PropertyBag
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{F3CE0F7C-4901-4ACC-8648-D5D44B04EF8F}
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\SessionInfo\1
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{76FC4E2D-D6AD-4519-A663-37BD56068185}
  • HKEY_CURRENT_USER\Directory\BrowseInPlace
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{1AC14E77-02E7-4E5D-B744-2EB1AE5198B7}\PropertyBag
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{33E28130-4E1E-4676-835A-98395C3BC3BB}
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\NonEnum
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{CAC52C1A-B53D-4EDC-92D7-6B2E8AC19434}\PropertyBag
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{B88F4DAA-E7BD-49A9-B74D-02885A5DC765}\PropertyBag
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{2A00375E-224C-49DE-B8D1-440DF7EF3DDC}\PropertyBag
  • HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows NT\Rpc
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Folder\DocObject
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{7D1D3A04-DEBB-4115-95CF-2F29DA2920DA}
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{43668BF8-C14E-49B2-97C9-747784D784B7}
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{0F214138-B1D3-4A90-BBA9-27CBC0C5389A}
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\SessionInfo\1\KnownFolders
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{9E3995AB-1F9C-4F13-B827-48B24B6C7174}
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{18989B1D-99B5-455B-841C-AB7C74E4DDFC}
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{15CA69B3-30EE-49C1-ACE1-6B5EC372AFB5}\PropertyBag
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{5E6C858F-0E22-4760-9AFE-EA3317B67173}
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\CPC\Volume\{b9fc2740-d442-11e0-8ee6-806e6f6e6963}\
  • HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\Shell\RegisteredApplications\UrlAssociations\Directory\OpenWithProgids
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{7D1D3A04-DEBB-4115-95CF-2F29DA2920DA}\PropertyBag
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{B250C668-F57D-4EE1-A63C-290EE7D1AA1F}\PropertyBag
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{B7534046-3ECB-4C18-BE4E-64CD4CB7D6AC}\PropertyBag
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{F7F1ED05-9F6D-47A2-AAAE-29D317C6F066}\PropertyBag
  • HKEY_CLASSES_ROOT\Drive\shellex\FolderExtensions\{fbeb8a05-beee-4442-804e-409d6c4515e9}
  • HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\App Paths\d25e226428fe4ab0f62813be8818dbfdd081294b.exe
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{10C07CD0-EF91-4567-B850-448B77CB37F9}
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{98EC0E18-2098-4D44-8644-66979315A281}\PropertyBag
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{B4BFCC3A-DB2C-424C-B029-7FE99A87C641}\PropertyBag
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{7C5A40EF-A0FB-4BFC-874A-C0F2E0B9FA8E}
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\SessionInfo\1\UsersFiles\NameSpace
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{DF7266AC-9274-4867-8D55-3BD661DE872D}
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{DF7266AC-9274-4867-8D55-3BD661DE872D}\PropertyBag
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{190337D1-B8CA-4121-A639-6D472D16972A}
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{CAC52C1A-B53D-4EDC-92D7-6B2E8AC19434}
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{2400183A-6185-49FB-A2D8-4A392A602BA3}\PropertyBag
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{A520A1A4-1780-4FF6-BD18-167343C5AF16}\PropertyBag
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{A302545D-DEFF-464B-ABE8-61C8648D939B}
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{8AD10C31-2ADB-4296-A8F7-E4701232C972}\PropertyBag
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{289A9A43-BE44-4057-A41B-587A76D7E7F9}
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{625B53C3-AB48-4EC1-BA1F-A1EF4146FC19}\PropertyBag
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{625B53C3-AB48-4EC1-BA1F-A1EF4146FC19}
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellCompatibility\Objects\{DFFACDC5-679F-4156-8947-C5C76BC0B67F}
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{B7534046-3ECB-4C18-BE4E-64CD4CB7D6AC}
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{FD228CB7-AE11-4AE3-864C-16F3910AB8FE}
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{52528A6B-B9E3-4ADD-B60D-588C2DBA842D}\PropertyBag
  • HKEY_CURRENT_USER\Directory\(Default)
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{B6EBFB86-6907-413C-9AF7-4FC2ABF07CC5}
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{5CE4A5E9-E4EB-479D-B89F-130C02886155}
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\UsersFiles\NameSpace\DelegateFolders\{DFFACDC5-679F-4156-8947-C5C76BC0B67F}
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{52A4F021-7B75-48A9-9F6B-4B87A210BC8F}\PropertyBag
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{BCBD3057-CA5C-4622-B42D-BC56DB0AE516}
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{52528A6B-B9E3-4ADD-B60D-588C2DBA842D}
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{0762D272-C50A-4BB0-A382-697DCD729B80}\PropertyBag
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{D65231B0-B2F1-4857-A4CE-A8E7C6EA7D27}\PropertyBag
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{4C5C32FF-BB9D-43B0-B5B4-2D72E54EAAA4}\PropertyBag
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{82A74AEB-AEB4-465C-A014-D097EE346D63}
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{1B3EA5DC-B587-4786-B4EF-BD1DC332AEAE}\PropertyBag
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{4C5C32FF-BB9D-43B0-B5B4-2D72E54EAAA4}
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellCompatibility\Applications\d25e226428fe4ab0f62813be8818dbfdd081294b.exe
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{10C07CD0-EF91-4567-B850-448B77CB37F9}\PropertyBag
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{905E63B6-C1BF-494E-B29C-65B732D3D21A}
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\UsersFiles\NameSpace
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{915221FB-9EFE-4BDA-8FD7-F78DCA774F87}\PropertyBag
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{7B0DB17D-9CD2-4A93-9733-46CC89022E7C}
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{2400183A-6185-49FB-A2D8-4A392A602BA3}
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{1A6FDBA2-F42D-4358-A798-B74D745926C5}
  • HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\LDAP
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{2B0F765D-C0E9-4171-908E-08A611B84FF6}
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{48DAF80B-E6CF-4F4E-B800-0E69D84EE384}
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\UsersFiles\NameSpace\DelegateFolders
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{FDD39AD0-238F-46AF-ADB4-6C85480369C7}
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{5CD7AEE2-2219-4A67-B85D-6C9CE15660CB}
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{15CA69B3-30EE-49C1-ACE1-6B5EC372AFB5}
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{2C36C0AA-5812-4B87-BFD0-4CD0DFB19B39}
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{D9DC8A3B-B784-432E-A781-5A1130A75963}\PropertyBag
  • HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Blocked
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{43668BF8-C14E-49B2-97C9-747784D784B7}\PropertyBag
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\CPC\Volume\{b9fc273c-d442-11e0-8ee6-806e6f6e6963}\
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{FD228CB7-AE11-4AE3-864C-16F3910AB8FE}\PropertyBag
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{B97D20BB-F46A-4C97-BA10-5E3608430854}
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders
  • HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\CLSID\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\ShellFolder
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{289A9A43-BE44-4057-A41B-587A76D7E7F9}\PropertyBag
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{EE32E446-31CA-4ABA-814F-A5EBD2FD6D5E}
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{DE61D971-5EBC-4F02-A3A9-6C82895E5C04}\PropertyBag
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{491E922F-5643-4AF4-A7EB-4E7A138D8174}
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{F38BF404-1D43-42F2-9305-67DE0B28FC23}
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{B97D20BB-F46A-4C97-BA10-5E3608430854}\PropertyBag
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{82A74AEB-AEB4-465C-A014-D097EE346D63}\PropertyBag
  • HKEY_CURRENT_USER\Directory\Clsid
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AllFilesystemObjects\ShellEx\IconHandler
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{0139D44E-6AFE-49F2-8690-3DAFCAE6FFB8}\PropertyBag
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{A77F5D77-2E2B-44C3-A6A2-ABA601054A51}
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{ED4824AF-DCE4-45A8-81E2-FC7965083634}\PropertyBag
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{352481E8-33BE-4251-BA85-6007CAEDCF9D}
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{0F214138-B1D3-4A90-BBA9-27CBC0C5389A}\PropertyBag
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{F38BF404-1D43-42F2-9305-67DE0B28FC23}\PropertyBag
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{9274BD8D-CFD1-41C3-B35E-B13F55A758F4}\PropertyBag
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{7B0DB17D-9CD2-4A93-9733-46CC89022E7C}\PropertyBag
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{C5ABBF53-E17F-4121-8900-86626FC2C973}
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{C5ABBF53-E17F-4121-8900-86626FC2C973}\PropertyBag
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{9E3995AB-1F9C-4F13-B827-48B24B6C7174}\PropertyBag
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{3214FAB5-9757-4298-BB61-92A9DEAA44FF}
  • HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\NonEnum
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{A4115719-D62E-491D-AA7C-E74B8BE3B067}
  • HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\CLSID\{DFFACDC5-679F-4156-8947-C5C76BC0B67F}\ShellFolder
  • HKEY_LOCAL_MACHINE\Software\Microsoft\Rpc
  • HKEY_CURRENT_USER\Directory\ShellEx\IconHandler
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{82A5EA35-D9CD-47C5-9629-E15D2F714E6E}\PropertyBag
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{C4900540-2379-4C75-844B-64E6FAF8716B}
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\UsersFiles\NameSpace\DelegateFolders
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{BCBD3057-CA5C-4622-B42D-BC56DB0AE516}\PropertyBag
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{054FAE61-4DD8-4787-80B6-090220C4B700}\PropertyBag
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{54EED2E0-E7CA-4FDB-9148-0F4247291CFA}
  • HKEY_CLASSES_ROOT\AllFilesystemObjects
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{A63293E8-664E-48DB-A079-DF759E0509F7}
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{0139D44E-6AFE-49F2-8690-3DAFCAE6FFB8}
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{F7F1ED05-9F6D-47A2-AAAE-29D317C6F066}
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{C870044B-F49E-4126-A9C3-B52A1FF411E8}\PropertyBag
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{AE50C081-EBD2-438A-8655-8A092E34987A}
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{DE92C1C7-837F-4F69-A3BB-86E631204A23}
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{9274BD8D-CFD1-41C3-B35E-B13F55A758F4}
  • HKEY_CLASSES_ROOT\CLSID\{59031A47-3F72-44A7-89C5-5595FE6B30EE}\ShellFolder
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{1777F761-68AD-4D8A-87BD-30B759FA33DD}\PropertyBag
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{905E63B6-C1BF-494E-B29C-65B732D3D21A}\PropertyBag
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{AE50C081-EBD2-438A-8655-8A092E34987A}\PropertyBag
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{33E28130-4E1E-4676-835A-98395C3BC3BB}\PropertyBag
  • HKEY_LOCAL_MACHINE\SOFTWARE\Tencent\QQMusic
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\App Paths\d25e226428fe4ab0f62813be8818dbfdd081294b.exe
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{1777F761-68AD-4D8A-87BD-30B759FA33DD}
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{491E922F-5643-4AF4-A7EB-4E7A138D8174}\PropertyBag
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{BCB5256F-79F6-4CEE-B725-DC34E402FD46}
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{A63293E8-664E-48DB-A079-DF759E0509F7}\PropertyBag
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{D9DC8A3B-B784-432E-A781-5A1130A75963}
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{4BFEFB45-347D-4006-A5BE-AC0CB0567192}
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{B6EBFB86-6907-413C-9AF7-4FC2ABF07CC5}\PropertyBag
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{D20BEEC4-5CA8-4905-AE3B-BF251EA09B53}
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{374DE290-123F-4565-9164-39C4925E467B}
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{F3CE0F7C-4901-4ACC-8648-D5D44B04EF8F}\PropertyBag
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\CLSID\{DFFACDC5-679F-4156-8947-C5C76BC0B67F}\ShellFolder
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Folder\BrowseInPlace
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{56784854-C6CB-462B-8169-88E350ACB882}\PropertyBag
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\FolderDescriptions\{A990AE9F-A03B-4E80-94BC-9912D7504104}