'
metaflows logo
Category Started On Completed On Duration Cuckoo Version
FILE 2016-09-13 14:30:05.129057 2016-09-13 14:32:12.849370 127 seconds 2.0-dev
Machine Label Manager Started On Shutdown On
win7cuckoo win7 Clone 1 VirtualBox 2016-09-13 14:30:05 2016-09-13 14:32:10

File Details

File name 0a1f7795b1de042f3782bb229931a09ee36eecb7.exe
File size 1420402 bytes
File type PE32 executable for MS Windows (GUI) Intel 80386 32-bit
CRC32 5F0616A4
MD5 6e4cb7283b87a2a9ba09451d98512794
SHA1 0a1f7795b1de042f3782bb229931a09ee36eecb7
SHA256 d7f4f97b7fb74273505e5449d642cf58a685e0c728ebd026cb33845e4de125d5
SHA512 e95dc209e184dced2c99d4cdbf4c68ef3cd905f69cab841407c1752c1c847976846486775c32d98e03dc5986e960fb8dbd443c7208cc8b453def7c16274a3a1c
Ssdeep 24576:Ida7VjCLYRFsrOkZIw157ta+YBPbjV84Iv6k4v+zg:ZILSNkF7AbB+6ky+c
PEiD None matched
Yara
  • Str_Win32_Wininet_Library (Match Windows Inet API library declaration)
  • Str_Win32_Internet_API (Match Windows Inet API call)
  • Str_Win32_Http_API (Match Windows Http API call)
VirusTotal File not found on VirusTotal

MetaFlows Scores

Metaflows Analysis Results (Signatures=75, Anomalies=0, PEiD=0, Yara=6, VT[1473777168]=0): Snort Events=0, AV Events=0
Total Score=75

Dropped File/Buffer Yara Signatures:
5cda6eaa2ee6a2b8_0a1f7795b1de042f3782bb229931a09ee36eecb7.exe: Str_Win32_Wininet_Library

Signatures

has_pdb details
antivm_memory_available details
Long_Alphanum_Exe_Name details
dropper details
antisandbox_idletime details
antisandbox_mouse_hook details

Screenshots

No screenshots available.

Static Analysis

Version Infos

Sections

Resources

Imports

Strings

Dropped Files

8e069b1722a4fc49_mbapreq.wxl

e5b064589d741bdb_bootstrappercore.dll

a64afbd95664554c_mbapreq.wxl

245c5c505bea3475_expressba.resources.dll

606321d3412f7198_expressba.resources.dll

5e80e78dd7d25c91_expressba.resources.dll

8c8899c6cc0da276_expressba.resources.dll

d47a140dcd36d438_mbapreq.wxl

8189239e8c4e3dc3_expressba.resources.dll

557f37db09369a0a_expressba.resources.dll

13635769db1f48f0_mbapreq.wxl

6b94d0789038e37c_bootstrapperapplicationdata.xml

f7a78463bb471614_expressba.resources.dll

02214224fab8ac96_expressba.resources.dll

a17d2de5cc82a44c_mbapreq.wxl

1209aa66a4f99a46_expressba.resources.dll

106555dd49231ffb_mbapreq.wxl

41d9d93639357027_mbapreq.wxl

865b78292087a71a_expressba.resources.dll

baac9792a8d480c6_expressba.resources.dll

48646b31688aa7a8_expressba.resources.dll

7ead3191307cce1e_expressba.resources.dll

704239fbc742f1da_expressba.resources.dll

136ae18ef0d7268b_expressba.resources.dll

3e67b7accb5815df_expressba.resources.dll

ff8b6c6ba9a5c180_mbapreq.wxl

ce4768bb69b98d68_expressba.dll

f8c3a03f47f0b9b3_mbapreq.thm

ca7cd1bf6d433ae8_mbapreq.wxl

666985e3b9f78ab4_garmin_express_20160913101006.log

182de3bf34a1ea92_expressba.resources.dll

189d0cf7bcebec2a_bootstrappercore.config

5b02e79837ddaed7_expressba.resources.dll

b148d406d9a0ca2d_expressba.resources.dll

9ff48acb76f4ebe9_mbapreq.wxl

ae7aa89299f00e43_mbapreq.wxl

6adc2a6b25dea736_mbahost.dll

f944fe7d8473ed6a_mbapreq.wxl

5567e3f35457e450_expressba.resources.dll

c35dedc4e685ecb6_expressba.resources.dll

705ae382f2adbc7c_mbapreq.wxl

94607e2517ec48bb_expressba.resources.dll

166801eff4a826bf_mbapreq.wxl

95b9735a8065ef79_expressba.resources.dll

43e00163c060a09c_mbapreq.wxl

b85ef6be00a1095e_expressba.resources.dll

9216632cdf31c511_mbapreq.dll

5743ff67726d2f19_expressba.resources.dll

a401a225addaf891_mbapreq.png

ebc2bf04a4f378ae_mbapreq.wxl

7ac12316806282d4_expressba.resources.dll

ae9f8e1a8856b18b_mbapreq.wxl

632ced5010ddc08c_eula_enu.rtf

da766c1e526eea01_expressba.resources.dll

1f38ed0bca95c18d_expressba.resources.dll

bdf44a835be92644_mbapreq.wxl

c1aeb5416db9e5cc_expressba.resources.dll

b6b1f82ce3d1c901_expressba.resources.dll

be8e22b102a9a21a_mbapreq.wxl

ef078b55d5ddd3cb_expressba.resources.dll

c5f1d0966ef65843_mbapreq.wxl

7b3b038a6bf9372b_expressba.resources.dll

58f46d0ee5bdfb3f_expressba.resources.dll

01e4ae06981c8270_expressba.resources.dll

3dbd6bc3779f577a_mbapreq.wxl

ad4cf22947472ffd_mbapreq.wxl

f43f4e542822026a_expressba.resources.dll

00a5f823904e2d68_mbapreq.wxl

b7b749ff06d7b4fa_expressba.resources.dll

5cda6eaa2ee6a2b8_0a1f7795b1de042f3782bb229931a09ee36eecb7.exe

90680e9500a20141_mbapreq.wxl

Network Analysis

Hosts Involved

DNS Requests

HTTP Requests

Behavior Summary

File-Read
  • C:\Users\Harry Dresden\AppData\Local\Temp\0a1f7795b1de042f3782bb229931a09ee36eecb7.exe
  • C:\Windows\Microsoft.NET\Framework\v4.0.30319\Config\machine.config
  • C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Xaml\f246b71bfd9c1537167b7f6d4f18cd01\System.Xaml.ni.dll.aux
  • C:\Windows\System32\mscoree.dll
  • C:\Windows\assembly\NativeImages_v4.0.30319_32\System\b75ba99f72f116d8951b0f2bba8c276a\System.ni.dll.aux
  • C:\Windows\assembly\NativeImages_v4.0.30319_32\UIAutomationTypes\232495ea0368dada2d208c51f0e5349c\UIAutomationTypes.ni.dll.aux
  • C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Configuration\7ece7799d670cdfc1393b98b0668a046\System.Configuration.ni.dll.aux
  • C:\Windows\assembly\NativeImages_v4.0.30319_32\mscorlib\d1265d6159ea876f9d63ea4c1361b587\mscorlib.ni.dll.aux
  • C:\Windows\System32\spool\drivers\color\sRGB Color Space Profile.icm
  • C:\Windows\assembly\NativeImages_v4.0.30319_32\Presentatio5ae0f00f#\613fd0f86fc699adfe3184b2e746aa18\PresentationFramework.ni.dll.aux
  • C:\Windows\assembly\NativeImages_v4.0.30319_32\Presentatiod51afaa5#\1fd09756ffa6623e208e3b5460f374e9\PresentationFramework.classic.ni.dll.aux
  • C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Xml\668bc5e53fd656dc16c9f40ea15e872e\System.Xml.ni.dll.aux
  • C:\Windows\assembly\NativeImages_v4.0.30319_32\Presentatio84a6349c#\8cab93eb361220e093cbecce13cc796e\PresentationFramework-SystemCore.ni.dll.aux
  • C:\Users\Harry Dresden\AppData\Local\Temp\{5145A569-B485-4CF9-9A72-357221B266D4}\.ba\BootstrapperCore.config
  • C:\Windows\assembly\NativeImages_v4.0.30319_32\WindowsBase\a40acfa4a0c4bb0dbf824ace588583ba\WindowsBase.ni.dll.aux
  • C:\Windows\assembly\NativeImages_v4.0.30319_32\PresentationCore\eed4ad7c1049e7cf47606479d68ec1de\PresentationCore.ni.dll.aux
  • C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Core\e0fea191b75897ec38735bfc31b89fe0\System.Core.ni.dll.aux
  • C:\Users\Harry Dresden\AppData\Local\Temp\{106E1EE6-51E7-4E35-B476-988FD9971676}\.cr\0a1f7795b1de042f3782bb229931a09ee36eecb7.exe
File-Written
  • C:\Users\Harry Dresden\AppData\Local\Temp\{106E1EE6-51E7-4E35-B476-988FD9971676}\.cr\0a1f7795b1de042f3782bb229931a09ee36eecb7.exe
  • C:\Users\Harry Dresden\AppData\Local\Temp\{5145A569-B485-4CF9-9A72-357221B266D4}\.ba\sr\ExpressBA.resources.dll
  • C:\Users\Harry Dresden\AppData\Local\Temp\{5145A569-B485-4CF9-9A72-357221B266D4}\.ba\th\ExpressBA.resources.dll
  • C:\Users\Harry Dresden\AppData\Local\Temp\{5145A569-B485-4CF9-9A72-357221B266D4}\.ba\BootstrapperCore.dll
  • C:\Users\Harry Dresden\AppData\Local\Temp\{5145A569-B485-4CF9-9A72-357221B266D4}\.ba\mbahost.dll
  • C:\Users\Harry Dresden\AppData\Local\Temp\{5145A569-B485-4CF9-9A72-357221B266D4}\.ba\ms-my\ExpressBA.resources.dll
  • C:\Users\Harry Dresden\AppData\Local\Temp\{5145A569-B485-4CF9-9A72-357221B266D4}\.ba\zh-tw\ExpressBA.resources.dll
  • C:\Users\Harry Dresden\AppData\Local\Temp\{5145A569-B485-4CF9-9A72-357221B266D4}\.ba\1032\mbapreq.wxl
  • C:\Users\Harry Dresden\AppData\Local\Temp\{5145A569-B485-4CF9-9A72-357221B266D4}\.ba\zh-cn\ExpressBA.resources.dll
  • C:\Users\Harry Dresden\AppData\Local\Temp\{5145A569-B485-4CF9-9A72-357221B266D4}\.ba\mbapreq.png
  • C:\Users\Harry Dresden\AppData\Local\Temp\{5145A569-B485-4CF9-9A72-357221B266D4}\.ba\mbapreq.wxl
  • C:\Users\Harry Dresden\AppData\Local\Temp\{5145A569-B485-4CF9-9A72-357221B266D4}\.ba\1042\mbapreq.wxl
  • C:\Users\Harry Dresden\AppData\Local\Temp\{5145A569-B485-4CF9-9A72-357221B266D4}\.ba\sk\ExpressBA.resources.dll
  • C:\Users\Harry Dresden\AppData\Local\Temp\{5145A569-B485-4CF9-9A72-357221B266D4}\.ba\1049\mbapreq.wxl
  • C:\Users\Harry Dresden\AppData\Local\Temp\{5145A569-B485-4CF9-9A72-357221B266D4}\.ba\he\ExpressBA.resources.dll
  • C:\Users\Harry Dresden\AppData\Local\Temp\{5145A569-B485-4CF9-9A72-357221B266D4}\.ba\sl\ExpressBA.resources.dll
  • C:\Users\Harry Dresden\AppData\Local\Temp\{5145A569-B485-4CF9-9A72-357221B266D4}\.ba\lt\ExpressBA.resources.dll
  • C:\Users\Harry Dresden\AppData\Local\Temp\{5145A569-B485-4CF9-9A72-357221B266D4}\.ba\hu\ExpressBA.resources.dll
  • C:\Users\Harry Dresden\AppData\Local\Temp\{5145A569-B485-4CF9-9A72-357221B266D4}\.ba\1041\mbapreq.wxl
  • C:\Users\Harry Dresden\AppData\Local\Temp\{5145A569-B485-4CF9-9A72-357221B266D4}\.ba\pt\ExpressBA.resources.dll
  • C:\Users\Harry Dresden\AppData\Local\Temp\{5145A569-B485-4CF9-9A72-357221B266D4}\.ba\lv\ExpressBA.resources.dll
  • C:\Users\Harry Dresden\AppData\Local\Temp\{5145A569-B485-4CF9-9A72-357221B266D4}\.ba\1046\mbapreq.wxl
  • C:\Users\Harry Dresden\AppData\Local\Temp\{5145A569-B485-4CF9-9A72-357221B266D4}\.ba\1036\mbapreq.wxl
  • C:\Users\Harry Dresden\AppData\Local\Temp\{5145A569-B485-4CF9-9A72-357221B266D4}\.ba\pl\ExpressBA.resources.dll
  • C:\Users\Harry Dresden\AppData\Local\Temp\{5145A569-B485-4CF9-9A72-357221B266D4}\.ba\cs\ExpressBA.resources.dll
  • C:\Users\Harry Dresden\AppData\Local\Temp\{5145A569-B485-4CF9-9A72-357221B266D4}\.ba\ja\ExpressBA.resources.dll
  • C:\Users\Harry Dresden\AppData\Local\Temp\{5145A569-B485-4CF9-9A72-357221B266D4}\.ba\bg\ExpressBA.resources.dll
  • C:\Users\Harry Dresden\AppData\Local\Temp\{5145A569-B485-4CF9-9A72-357221B266D4}\.ba\fr\ExpressBA.resources.dll
  • C:\Users\Harry Dresden\AppData\Local\Temp\{5145A569-B485-4CF9-9A72-357221B266D4}\.ba\1044\mbapreq.wxl
  • C:\Users\Harry Dresden\AppData\Local\Temp\{5145A569-B485-4CF9-9A72-357221B266D4}\.ba\ko\ExpressBA.resources.dll
  • C:\Users\Harry Dresden\AppData\Local\Temp\{5145A569-B485-4CF9-9A72-357221B266D4}\.ba\de\ExpressBA.resources.dll
  • C:\Users\Harry Dresden\AppData\Local\Temp\{5145A569-B485-4CF9-9A72-357221B266D4}\.ba\ru\ExpressBA.resources.dll
  • C:\Users\Harry Dresden\AppData\Local\Temp\{5145A569-B485-4CF9-9A72-357221B266D4}\.ba\1060\mbapreq.wxl
  • C:\Users\Harry Dresden\AppData\Local\Temp\{5145A569-B485-4CF9-9A72-357221B266D4}\.ba\ro\ExpressBA.resources.dll
  • C:\Users\Harry Dresden\AppData\Local\Temp\{5145A569-B485-4CF9-9A72-357221B266D4}\.ba\1040\mbapreq.wxl
  • C:\Users\Harry Dresden\AppData\Local\Temp\{5145A569-B485-4CF9-9A72-357221B266D4}\.ba\1030\mbapreq.wxl
  • C:\Users\Harry Dresden\AppData\Local\Temp\{5145A569-B485-4CF9-9A72-357221B266D4}\.ba\uk\ExpressBA.resources.dll
  • C:\Users\Harry Dresden\AppData\Local\Temp\{5145A569-B485-4CF9-9A72-357221B266D4}\.ba\no\ExpressBA.resources.dll
  • C:\Users\Harry Dresden\AppData\Local\Temp\{5145A569-B485-4CF9-9A72-357221B266D4}\.ba\2052\mbapreq.wxl
  • C:\Users\Harry Dresden\AppData\Local\Temp\{5145A569-B485-4CF9-9A72-357221B266D4}\.ba\et\ExpressBA.resources.dll
  • C:\Users\Harry Dresden\AppData\Local\Temp\{5145A569-B485-4CF9-9A72-357221B266D4}\.ba\mbapreq.thm
  • C:\Users\Harry Dresden\AppData\Local\Temp\{5145A569-B485-4CF9-9A72-357221B266D4}\.ba\id\ExpressBA.resources.dll
  • C:\Users\Harry Dresden\AppData\Local\Temp\Garmin_Express_20160913101006.log
  • C:\Users\Harry Dresden\AppData\Local\Temp\{5145A569-B485-4CF9-9A72-357221B266D4}\.ba\es\ExpressBA.resources.dll
  • C:\Users\Harry Dresden\AppData\Local\Temp\{5145A569-B485-4CF9-9A72-357221B266D4}\.ba\mbapreq.dll
  • C:\Users\Harry Dresden\AppData\Local\Temp\{5145A569-B485-4CF9-9A72-357221B266D4}\.ba\el\ExpressBA.resources.dll
  • C:\Users\Harry Dresden\AppData\Local\Temp\{5145A569-B485-4CF9-9A72-357221B266D4}\.ba\tr\ExpressBA.resources.dll
  • C:\Users\Harry Dresden\AppData\Local\Temp\{5145A569-B485-4CF9-9A72-357221B266D4}\.ba\1051\mbapreq.wxl
  • C:\Users\Harry Dresden\AppData\Local\Temp\{5145A569-B485-4CF9-9A72-357221B266D4}\.ba\ar\ExpressBA.resources.dll
  • C:\Users\Harry Dresden\AppData\Local\Temp\{5145A569-B485-4CF9-9A72-357221B266D4}\.ba\da\ExpressBA.resources.dll
  • C:\Users\Harry Dresden\AppData\Local\Temp\{5145A569-B485-4CF9-9A72-357221B266D4}\.ba\nl\ExpressBA.resources.dll
  • C:\Users\Harry Dresden\AppData\Local\Temp\{5145A569-B485-4CF9-9A72-357221B266D4}\.ba\2070\mbapreq.wxl
  • C:\Users\Harry Dresden\AppData\Local\Temp\{5145A569-B485-4CF9-9A72-357221B266D4}\.ba\BootstrapperApplicationData.xml
  • C:\Users\Harry Dresden\AppData\Local\Temp\{5145A569-B485-4CF9-9A72-357221B266D4}\.ba\3082\mbapreq.wxl
  • C:\Users\Harry Dresden\AppData\Local\Temp\{5145A569-B485-4CF9-9A72-357221B266D4}\.ba\1043\mbapreq.wxl
  • C:\Users\Harry Dresden\AppData\Local\Temp\{5145A569-B485-4CF9-9A72-357221B266D4}\.ba\1028\mbapreq.wxl
  • C:\Users\Harry Dresden\AppData\Local\Temp\{5145A569-B485-4CF9-9A72-357221B266D4}\.ba\pt-br\ExpressBA.resources.dll
  • C:\Users\Harry Dresden\AppData\Local\Temp\{5145A569-B485-4CF9-9A72-357221B266D4}\.ba\1055\mbapreq.wxl
  • C:\Users\Harry Dresden\AppData\Local\Temp\{5145A569-B485-4CF9-9A72-357221B266D4}\.ba\1029\mbapreq.wxl
  • C:\Users\Harry Dresden\AppData\Local\Temp\{5145A569-B485-4CF9-9A72-357221B266D4}\.ba\ExpressBA.dll
  • C:\Users\Harry Dresden\AppData\Local\Temp\{5145A569-B485-4CF9-9A72-357221B266D4}\.ba\1038\mbapreq.wxl
  • C:\Users\Harry Dresden\AppData\Local\Temp\{5145A569-B485-4CF9-9A72-357221B266D4}\.ba\sv\ExpressBA.resources.dll
  • C:\Users\Harry Dresden\AppData\Local\Temp\{5145A569-B485-4CF9-9A72-357221B266D4}\.ba\fi\ExpressBA.resources.dll
  • C:\Users\Harry Dresden\AppData\Local\Temp\{5145A569-B485-4CF9-9A72-357221B266D4}\.ba\1031\mbapreq.wxl
  • C:\Users\Harry Dresden\AppData\Local\Temp\{5145A569-B485-4CF9-9A72-357221B266D4}\.ba\BootstrapperCore.config
  • C:\Users\Harry Dresden\AppData\Local\Temp\{5145A569-B485-4CF9-9A72-357221B266D4}\.ba\1053\mbapreq.wxl
  • C:\Users\Harry Dresden\AppData\Local\Temp\{5145A569-B485-4CF9-9A72-357221B266D4}\.ba\hr\ExpressBA.resources.dll
  • C:\Users\Harry Dresden\AppData\Local\Temp\{5145A569-B485-4CF9-9A72-357221B266D4}\.ba\it\ExpressBA.resources.dll
  • C:\Users\Harry Dresden\AppData\Local\Temp\{5145A569-B485-4CF9-9A72-357221B266D4}\.ba\EULA_ENU.rtf
  • C:\Users\Harry Dresden\AppData\Local\Temp\{5145A569-B485-4CF9-9A72-357221B266D4}\.ba\1035\mbapreq.wxl
  • C:\Users\Harry Dresden\AppData\Local\Temp\{5145A569-B485-4CF9-9A72-357221B266D4}\.ba\1045\mbapreq.wxl
File-Opened
  • C:\Windows\Globalization\Sorting\sortdefault.nls
  • C:\Users\Harry Dresden\AppData\Local\Temp\0a1f7795b1de042f3782bb229931a09ee36eecb7.exe
  • C:\Windows\Globalization\Sorting\sortdefault.nls
  • C:\Windows\Microsoft.NET\Framework\v4.0.30319\Config\machine.config
  • C:\Users\Harry Dresden\AppData\Local\Temp\{5145A569-B485-4CF9-9A72-357221B266D4}\.ba\BootstrapperCore.dll
  • C:\Windows\AppPatch\sysmain.sdb
  • C:\
  • C:\Windows\System32\mscoree.dll
  • C:\Windows\System32\spool\drivers\color\sRGB Color Space Profile.icm
  • C:\Windows\Fonts\tahoma.ttf
  • C:\Windows\assembly\NativeImages_v4.0.30319_32\Presentatiod51afaa5#\1fd09756ffa6623e208e3b5460f374e9\PresentationFramework.classic.ni.dll.aux
  • C:\Users\Harry Dresden\AppData\Local\Temp\{106E1EE6-51E7-4E35-B476-988FD9971676}\.cr\0a1f7795b1de042f3782bb229931a09ee36eecb7.exe
  • C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorwks.dll
  • C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorrc.dll
  • C:\Windows\
  • C:\Windows\Microsoft.NET\Framework\v4.0.30319\SortDefault.nlp
  • C:\Windows\assembly\NativeImages_v4.0.30319_32\System\b75ba99f72f116d8951b0f2bba8c276a\System.ni.dll.aux
  • C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Configuration\7ece7799d670cdfc1393b98b0668a046\System.Configuration.ni.dll.aux
  • C:\Windows\assembly\pubpol40.dat
  • C:\Windows\assembly\NativeImages_v4.0.30319_32\Presentatio5ae0f00f#\613fd0f86fc699adfe3184b2e746aa18\PresentationFramework.ni.dll.aux
  • C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Xaml\f246b71bfd9c1537167b7f6d4f18cd01\System.Xaml.ni.dll.aux
  • C:\Windows\assembly\NativeImages_v4.0.30319_32\mscorlib\d1265d6159ea876f9d63ea4c1361b587\mscorlib.ni.dll.aux
  • C:\Windows\assembly\NativeImages_v4.0.30319_32\Presentatio84a6349c#\8cab93eb361220e093cbecce13cc796e\PresentationFramework-SystemCore.ni.dll.aux
  • C:\Windows\assembly\NativeImages_v4.0.30319_32\WindowsBase\a40acfa4a0c4bb0dbf824ace588583ba\WindowsBase.ni.dll.aux
  • C:\Windows\assembly\NativeImages_v4.0.30319_32\PresentationCore\eed4ad7c1049e7cf47606479d68ec1de\PresentationCore.ni.dll.aux
  • C:\Windows\System32\oleaccrc.dll
  • C:\Users\Harry Dresden\AppData\Local\Temp\{5145A569-B485-4CF9-9A72-357221B266D4}\.ba\ExpressBA.dll
  • C:\Windows\Globalization\Sorting\sortdefault.nls
  • C:\Windows\assembly\NativeImages_v4.0.30319_32\UIAutomationTypes\232495ea0368dada2d208c51f0e5349c\UIAutomationTypes.ni.dll.aux
  • C:\Windows\System32\
  • C:\Windows\Microsoft.NET\Framework\v4.0.30319\clr.dll
  • C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Xml\668bc5e53fd656dc16c9f40ea15e872e\System.Xml.ni.dll.aux
  • C:\Users\Harry Dresden\AppData\Local\Temp\{5145A569-B485-4CF9-9A72-357221B266D4}\.ba\BootstrapperCore.config
  • C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Core\e0fea191b75897ec38735bfc31b89fe0\System.Core.ni.dll.aux
Directory-Created
  • C:\Users\Harry Dresden\AppData\Local\Temp\{106E1EE6-51E7-4E35-B476-988FD9971676}\
  • C:\Users\Harry Dresden\AppData\Local\Temp\{106E1EE6-51E7-4E35-B476-988FD9971676}\.cr
  • C:\Users\Harry Dresden\AppData\Local\Temp\{5145A569-B485-4CF9-9A72-357221B266D4}\.ba\1043\
  • C:\Users\Harry Dresden\AppData\Local\Temp\{5145A569-B485-4CF9-9A72-357221B266D4}\.ba\1028\
  • C:\Users\Harry Dresden\AppData\Local\Temp\{5145A569-B485-4CF9-9A72-357221B266D4}\.ba\et\
  • C:\Users\Harry Dresden\AppData\Local\Temp\{5145A569-B485-4CF9-9A72-357221B266D4}\.ba\2052\
  • C:\Users\Harry Dresden\AppData\Local\Temp\{5145A569-B485-4CF9-9A72-357221B266D4}\.ba\no\
  • C:\Users\Harry Dresden\AppData\Local\Temp\{5145A569-B485-4CF9-9A72-357221B266D4}\.ba\1060\
  • C:\Users\Harry Dresden\AppData\Local\Temp\{5145A569-B485-4CF9-9A72-357221B266D4}\.ba\nl\
  • C:\Users\Harry Dresden\AppData\Local\Temp\{5145A569-B485-4CF9-9A72-357221B266D4}\.ba\da\
  • C:\Users\Harry Dresden\AppData\Local\Temp\{5145A569-B485-4CF9-9A72-357221B266D4}\.ba\hu\
  • C:\Users\Harry Dresden\AppData\Local\Temp\{5145A569-B485-4CF9-9A72-357221B266D4}\.ba\lv\
  • C:\Users\Harry Dresden\AppData\Local\Temp\{5145A569-B485-4CF9-9A72-357221B266D4}\.ba\1055\
  • C:\Users\Harry Dresden\AppData\Local\Temp\{5145A569-B485-4CF9-9A72-357221B266D4}\.ba\de\
  • C:\Users\Harry Dresden\AppData\Local\Temp\{5145A569-B485-4CF9-9A72-357221B266D4}\.ba\1045\
  • C:\Users\Harry Dresden\AppData\Local\Temp\{5145A569-B485-4CF9-9A72-357221B266D4}\.ba\1031\
  • C:\Users\Harry Dresden\AppData\Local\Temp\{5145A569-B485-4CF9-9A72-357221B266D4}\.ba\1041\
  • C:\Users\Harry Dresden\AppData\Local\Temp\{5145A569-B485-4CF9-9A72-357221B266D4}\.ba\1035\
  • C:\Users\Harry Dresden\AppData\Local\Temp\{5145A569-B485-4CF9-9A72-357221B266D4}\.ba\ja\
  • C:\Users\Harry Dresden\AppData\Local\Temp\{5145A569-B485-4CF9-9A72-357221B266D4}\
  • C:\Users\Harry Dresden\AppData\Local\Temp\{5145A569-B485-4CF9-9A72-357221B266D4}\.ba\zh-tw\
  • C:\Users\Harry Dresden\AppData\Local\Temp\{5145A569-B485-4CF9-9A72-357221B266D4}\.ba\sl\
  • C:\Users\Harry Dresden\AppData\Local\Temp\{5145A569-B485-4CF9-9A72-357221B266D4}\.ba\1029\
  • C:\Users\Harry Dresden\AppData\Local\Temp\{5145A569-B485-4CF9-9A72-357221B266D4}\.ba\1051\
  • C:\Users\Harry Dresden\AppData\Local\Temp\
  • C:\Users\Harry Dresden\AppData\Local\Temp\{5145A569-B485-4CF9-9A72-357221B266D4}\.ba\bg\
  • C:\Users\Harry Dresden\AppData\Local\Temp\{5145A569-B485-4CF9-9A72-357221B266D4}\.ba\lt\
  • C:\Users\Harry Dresden\AppData\Local\Temp\{5145A569-B485-4CF9-9A72-357221B266D4}\.ba\he\
  • C:\Users\Harry Dresden\AppData\Local\Temp\{5145A569-B485-4CF9-9A72-357221B266D4}\.ba\1049\
  • C:\Users\Harry Dresden\AppData\Local\Temp\{5145A569-B485-4CF9-9A72-357221B266D4}\.ba\pl\
  • C:\Users\Harry Dresden\AppData\Local\Temp\{5145A569-B485-4CF9-9A72-357221B266D4}\.ba\cs\
  • C:\Users\Harry Dresden\AppData\Local\Temp\{5145A569-B485-4CF9-9A72-357221B266D4}\.ba\zh-cn\
  • C:\Users\Harry Dresden\AppData\Local\Temp\{5145A569-B485-4CF9-9A72-357221B266D4}\.ba\
  • C:\Users\Harry Dresden\AppData\Local\Temp\{5145A569-B485-4CF9-9A72-357221B266D4}\.ba\ru\
  • C:\Users\Harry Dresden\AppData\Local\Temp\{5145A569-B485-4CF9-9A72-357221B266D4}\.ba\3082\
  • C:\Users\Harry Dresden\AppData\Local\Temp\{5145A569-B485-4CF9-9A72-357221B266D4}\.ba\el\
  • C:\Users\Harry Dresden\AppData\Local\Temp\{5145A569-B485-4CF9-9A72-357221B266D4}\.ba\1038\
  • C:\Users\Harry Dresden\AppData\Local\Temp\{5145A569-B485-4CF9-9A72-357221B266D4}\.ba\th\
  • C:\Users\Harry Dresden\AppData\Local\Temp\{5145A569-B485-4CF9-9A72-357221B266D4}\.ba\ko\
  • C:\Users\Harry Dresden\AppData\Local\Temp\{5145A569-B485-4CF9-9A72-357221B266D4}\.ba\1053\
  • C:\Users\Harry Dresden\AppData\Local\Temp\{5145A569-B485-4CF9-9A72-357221B266D4}\.ba\fi\
  • C:\Users\Harry Dresden\AppData\Local\Temp\{5145A569-B485-4CF9-9A72-357221B266D4}\.ba\fr\
  • C:\Users\Harry Dresden\AppData\Local\Temp\{5145A569-B485-4CF9-9A72-357221B266D4}\.ba\1046\
  • C:\Users\Harry Dresden\AppData\Local\Temp\{5145A569-B485-4CF9-9A72-357221B266D4}\.ba\es\
  • C:\Users\Harry Dresden\AppData\Local\Temp\{5145A569-B485-4CF9-9A72-357221B266D4}\.ba\1030\
  • C:\Users\Harry Dresden\AppData\Local\Temp\{5145A569-B485-4CF9-9A72-357221B266D4}\.ba\1044\
  • C:\Users\Harry Dresden\AppData\Local\Temp\{5145A569-B485-4CF9-9A72-357221B266D4}\.ba\hr\
  • C:\Users\Harry Dresden\AppData\Local\Temp\{5145A569-B485-4CF9-9A72-357221B266D4}\.ba\it\
  • C:\Users\Harry Dresden\AppData\Local\Temp\{5145A569-B485-4CF9-9A72-357221B266D4}\.ba\id\
  • C:\Users\Harry Dresden\AppData\Local\Temp\{5145A569-B485-4CF9-9A72-357221B266D4}\.ba\1040\
  • C:\Users\Harry Dresden\AppData\Local\Temp\{5145A569-B485-4CF9-9A72-357221B266D4}\.ba\pt-br\
  • C:\Users\Harry Dresden\AppData\Local\Temp\{5145A569-B485-4CF9-9A72-357221B266D4}\.ba\sv\
  • C:\Users\Harry Dresden\AppData\Local\Temp\{5145A569-B485-4CF9-9A72-357221B266D4}\.ba\ro\
  • C:\Users\Harry Dresden\AppData\Local\Temp\{5145A569-B485-4CF9-9A72-357221B266D4}\.ba\1032\
  • C:\Users\Harry Dresden\AppData\Local\Temp\{5145A569-B485-4CF9-9A72-357221B266D4}\.ba\sr\
  • C:\Users\Harry Dresden\AppData\Local\Temp\{5145A569-B485-4CF9-9A72-357221B266D4}\.ba\1036\
  • C:\Users\Harry Dresden\AppData\Local\Temp\{5145A569-B485-4CF9-9A72-357221B266D4}\.ba\1042\
  • C:\Users\Harry Dresden\AppData\Local\Temp\{5145A569-B485-4CF9-9A72-357221B266D4}\.ba\uk\
  • C:\Users\Harry Dresden\AppData\Local\Temp\{5145A569-B485-4CF9-9A72-357221B266D4}\.ba\pt\
  • C:\Users\Harry Dresden\AppData\Local\Temp\{5145A569-B485-4CF9-9A72-357221B266D4}\.ba\ar\
  • C:\Users\Harry Dresden\AppData\Local\Temp\{5145A569-B485-4CF9-9A72-357221B266D4}\.ba\sk\
  • C:\Users\Harry Dresden\AppData\Local\Temp\{5145A569-B485-4CF9-9A72-357221B266D4}\.ba\ms-my\
  • C:\Users\Harry Dresden\AppData\Local\Temp\{5145A569-B485-4CF9-9A72-357221B266D4}\.ba\tr\
  • C:\Users\Harry Dresden\AppData\Local\Temp\{5145A569-B485-4CF9-9A72-357221B266D4}\.ba\2070\
Directory-Enumerated
  • C:\Windows\assembly\NativeImages_v4.0.30319_32\Presentatiod51afaa5#\*
  • C:\Windows\System32\*.*
  • C:\Windows\System32\mscoree.dll
  • C:\Windows\assembly\NativeImages_v4.0.30319_32\PresentationCore\*
  • C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Xml\*
  • C:\Windows\assembly\NativeImages_v4.0.30319_32\mscorlib\*
  • C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Xaml\*
  • C:\Windows\assembly\NativeImages_v4.0.30319_32\BootstrapperCore\*
  • C:\Windows\assembly\NativeImages_v4.0.30319_32\Presentatio5ae0f00f#\*
  • C:\Windows\assembly\NativeImages_v4.0.30319_32\UIAutomationTypes\*
  • C:\Windows\assembly\NativeImages_v4.0.30319_32\System\*
  • C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscoreei.dll
  • C:\Users
  • C:\Windows\System32
  • C:\Windows\assembly\NativeImages_v4.0.30319_32\Presentatio84a6349c#\*
  • C:\Windows\assembly\NativeImages_v4.0.30319_32\WindowsBase\*
  • C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Core\*
  • C:\Windows\assembly\NativeImages_v4.0.30319_32\ExpressBA\*
  • C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Configuration\*
  • C:\Users\Harry Dresden
  • C:\Windows\Microsoft.NET\Framework\*
  • C:\Windows
Registry Key-Opened
  • HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\TabletPC
  • HKEY_LOCAL_MACHINE\Software\Microsoft\Wisp\Pen\SysEventParameters
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\PenService\9A979A3F-92BB-49e9-8F2E-4EB423A9BFC9\Static
  • HKEY_CURRENT_USER\Software\Microsoft\Wisp\Pen\Persist
  • HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\TabletPC\DisplayOrientations
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\PenService\1EC353D2-7EE4-4cbe-A63A-4BFE68DBC65A
  • HKEY_LOCAL_MACHINE\MultiTouchEnabled
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\PenService\1CAD86A5-8A18-4297-A3FF-5A110325FA12
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\PenService\E5129A69-FF3A-4129-AE69-9C2E280AAA4B\com.alias.TPWin32SketchView
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\PenService\30988F51-D107-4f3b-97A8-60953D29EA39
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\PenService\36D1B905-CC62-4ab0-9C08-118B66D6DB90
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\PenService\30988F51-D107-4f3b-97A8-60953D29EA39\xpUnicodeWindow
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\PenService
  • HKEY_LOCAL_MACHINE\Software\Microsoft\Wisp\MultiTouch
  • HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\TabletPC\AssociationData
  • HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\AppCompatFlags
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\PenService\36D1B905-CC62-4ab0-9C08-118B66D6DB90\VISIOD
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\PenService\36D1B905-CC62-4ab0-9C08-118B66D6DB90\VISIOG
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\PenService\1CAD86A5-8A18-4297-A3FF-5A110325FA12\PSViewC
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\PenService\596fd73c-fff3-4d3f-81d3-8af2955f3547
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\PenService\1EC353D2-7EE4-4cbe-A63A-4BFE68DBC65A\paneClassDC
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\PenService\596fd73c-fff3-4d3f-81d3-8af2955f3547\Internet Explorer_Server
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\PenService\36D1B905-CC62-4ab0-9C08-118B66D6DB90\ListBox
  • HKEY_CURRENT_USER\Software\Microsoft\Wisp\Pen\SysEventParameters
  • HKEY_CURRENT_USER\Software\Microsoft\Wisp\Pen\Profile
  • HKEY_LOCAL_MACHINE\Software\Microsoft\Wisp\Touch
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\PenService\E5129A69-FF3A-4129-AE69-9C2E280AAA4B
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\PenService\21A8443D-F741-4d5d-954D-5FE60196A5E8\MDocument
  • HKEY_CURRENT_USER\Software\Microsoft\Wisp\MultiTouch
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\PenService\9A979A3F-92BB-49e9-8F2E-4EB423A9BFC9
  • HKEY_CURRENT_USER\Software\Microsoft\Wisp\Touch
  • HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\TabletPC\ExtendedButtonActions
  • HKEY_CURRENT_USER\SOFTWARE\Policies\Microsoft\TabletPC
  • HKEY_CURRENT_USER\Software\Microsoft\Wisp\Pen\Persist\0
  • HKEY_CURRENT_USER\Software\Microsoft\Wisp\Pen\Persist\0\1
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\PenService\21A8443D-F741-4d5d-954D-5FE60196A5E8
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{F6D90F11-9C73-11D3-B32E-00C04F990BB4}\InprocServer32
  • HKEY_CURRENT_USER\CLSID\{F6D90F11-9C73-11D3-B32E-00C04F990BB4}
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{F6D90F11-9C73-11D3-B32E-00C04F990BB4}\Progid
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{F6D90F11-9C73-11D3-B32E-00C04F990BB4}\TreatAs
  • HKEY_LOCAL_MACHINE\SOFTWARE\Policies\WiX\Burn
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{F6D90F11-9C73-11D3-B32E-00C04F990BB4}\InprocHandler32
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{F6D90F11-9C73-11D3-B32E-00C04F990BB4}\InprocHandler
  • HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\FileSystem
  • HKEY_LOCAL_MACHINE\Software\Microsoft\COM3
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Msxml2.DOMDocument\CLSID
  • HKEY_CURRENT_USER\Msxml2.DOMDocument
  • HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Setup
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\MAIN\FeatureControl\FEATURE_ALLOW_REVERSE_SOLIDUS_IN_USERINFO_KB932562
  • HKEY_CURRENT_USER\Software\Microsoft\Installer\UpgradeCodes\A0467937E2A5A89409D20E64F8640D9F
  • HKEY_LOCAL_MACHINE\Software\Classes\Installer\UpgradeCodes\C36A0D91BD55D7540994A61CDC6153E4
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\CTF\TIP
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\CTF\TIP\{E429B25A-E5D3-4D1F-9BE3-0C608477E3A1}\Category\Category\{6302DE22-A5CF-4B02-BFE8-4D72B2BED3C6}
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{F6D90F11-9C73-11D3-B32E-00C04F990BB4}\InprocHandler
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{AF44BF80-36DD-4118-B4CF-8B1E3F4FB9CE}\ProxyStubClsid32
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{AF44BF80-36DD-4118-B4CF-8B1E3F4FB9CE}\Progid
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\policy.4.0.System.Core__b77a5c561934e089
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{90160000-008C-0000-0000-0000000FF1CE}
  • HKEY_LOCAL_MACHINE\Software\Microsoft\CTF\TIP\{0000897b-83df-4b96-be07-0fb58b01c4a4}\LanguageProfile\0x00000000\{0001bea3-ed56-483d-a2e2-aeae25577436}
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\NET Framework Setup\NDP\v4\Full
  • HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Installer\Managed\S-1-5-21-3416602863-1947377224-293699093-1003\Installer\UpgradeCodes\2E8D14B368C20A647B6CB17EE9689EB8
  • HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main\FeatureControl
  • HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\FontCache\Parameters
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{AF44BF80-36DD-4118-B4CF-8B1E3F4FB9CE}\Progid
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Uninstall\OneDriveSetup.exe
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\CTF\TIP\{DCBD6FA8-032F-11D3-B5B1-00C04FC324A1}\Category\Category\{6302DE22-A5CF-4B02-BFE8-4D72B2BED3C6}
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\CTF\KnownClasses
  • HKEY_LOCAL_MACHINE\Software\Classes\Installer\UpgradeCodes\BBED9B58097CAA746B924CB27661E248
  • HKEY_LOCAL_MACHINE\SOFTWARE\Policies\WiX\Burn
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{C247F616-BBEB-406A-AED3-F75E656599AE}\ProxyStubClsid32
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{E2B51919-207A-43EB-AE78-733F9C6797C2}
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\policy.4.0.UIAutomationProvider__31bf3856ad364e35
  • HKEY_LOCAL_MACHINE\Software\Microsoft\Rpc\Extensions
  • HKEY_CURRENT_USER\Software\Microsoft\Direct3D\Drivers
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\COM3
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\v4.0_policy.4.0.PresentationUI__31bf3856ad364e35
  • HKEY_LOCAL_MACHINE\Software\Classes\Installer\UpgradeCodes\B5CBFE3AFBF6D9843A5BE217240CD2FE
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\CTF\
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\Assemblies\Global
  • HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\BFE
  • HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options
  • HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main\FeatureControl
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{90160000-008C-0409-0000-0000000FF1CE}
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\IE5BAKEX
  • HKEY_LOCAL_MACHINE\Software\Microsoft\Rpc
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{AF44BF80-36DD-4118-B4CF-8B1E3F4FB9CE}\InprocServer32
  • HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\Installer
  • HKEY_CURRENT_USER\Software\Microsoft\Avalon.Graphics
  • HKEY_CURRENT_USER\Software\Microsoft\Direct3D\MostRecentApplication
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\v4.0_policy.4.0.Accessibility__b03f5f7f11d50a3a
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{AC76BA86-0804-1033-1959-001824166751}
  • HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Installer\Managed\S-1-5-21-3416602863-1947377224-293699093-1003\Installer\UpgradeCodes\B5CBFE3AFBF6D9843A5BE217240CD2FE
  • HKEY_CURRENT_USER\Software\Microsoft\Installer\Assemblies\C:|Users|HARRYD~1|AppData|Local|Temp|{5145A569-B485-4CF9-9A72-357221B266D4}|.ba|BootstrapperCore.config
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\CPC\Volume
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\CTF\TIP\{07EB03D6-B001-41DF-9192-BF9B841EE71F}\Category\Category\{6302DE22-A5CF-4B02-BFE8-4D72B2BED3C6}
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{AC76BA86-7AD7-1033-7B44-AB0000000001}
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\WIC
  • HKEY_LOCAL_MACHINE\Software\Garmin\Express
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\CTF\TIP\{F25E9F57-2FC8-4EB3-A41A-CCE5F08541E6}\Category\Category\{6302DE22-A5CF-4B02-BFE8-4D72B2BED3C6}
  • HKEY_LOCAL_MACHINE\Software\Microsoft\DirectDraw\GammaCalibrator
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{1CB2EFC3-ABC7-4172-8FCB-3BC9CB93E29F}\ProxyStubClsid32
  • HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Installer\Managed\S-1-5-21-3416602863-1947377224-293699093-1003\Installer\UpgradeCodes\BBED9B58097CAA746B924CB27661E248
  • HKEY_LOCAL_MACHINE\Software\Classes\Installer\Products\209291F4143A123438F89BE2304DD472
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{5b45c228-dcb1-4a0b-a9de-3b4b683ef15d}
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{F6D90F11-9C73-11D3-B32E-00C04F990BB4}\TreatAs
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\policy.4.0.System.Xaml__b77a5c561934e089
  • HKEY_CLASSES_ROOT\CLSID\{FAE3D380-FEA4-4623-8C75-C6B61110B681}\Instance
  • HKEY_CURRENT_USER\System\CurrentControlSet\Control\GraphicsDrivers\Scheduler
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\v4.0_policy.4.0.WindowsBase__31bf3856ad364e35
  • HKEY_CURRENT_USER\Interface\{EF9953C6-B472-4B02-9D22-D0E247ADE0E8}
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\policy.4.0.WindowsBase__31bf3856ad364e35
  • HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ICM\RegisteredProfiles
  • HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion
  • HKEY_LOCAL_MACHINE\Software\Classes\Installer\Products\FBCA0A92B051C824B8467D5FD1E3149D
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\CTF\Compatibility\0a1f7795b1de042f3782bb229931a09ee36eecb7.exe
  • HKEY_CURRENT_USER\Interface\{997A992E-8B6C-4945-BC17-A1EE563B3AB7}
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\IEData
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\Fontcore
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\v4.0_policy.4.0.System.Numerics__b77a5c561934e089
  • HKEY_CURRENT_USER\Interface\{C247F616-BBEB-406A-AED3-F75E656599AE}
  • HKEY_CURRENT_USER\CLSID\{F6D90F11-9C73-11D3-B32E-00C04F990BB4}
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\policy.4.0.System.Numerics__b77a5c561934e089
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\.NETFRAMEWORK\Policy\v4.0
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\policy.4.0.System.Configuration__b03f5f7f11d50a3a
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{90850409-6000-11D3-8CFE-0150048383C9}
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\Connection Manager
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\v4.0_policy.4.0.System.Printing__31bf3856ad364e35
  • HKEY_LOCAL_MACHINE\Software\Microsoft\.NETFramework\Policy\
  • \Policy\Standards
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\.NETFramework\Policy\Servicing
  • HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\49F9D5E0755A3584CAD460E63A605BDC\InstallProperties
  • HKEY_CURRENT_USER\Interface\{00000134-0000-0000-C000-000000000046}
  • HKEY_LOCAL_MACHINE\Software\Microsoft\Direct3D\Drivers\Direct3D HAL
  • HKEY_LOCAL_MACHINE\Software\Classes\Installer\UpgradeCodes\A0467937E2A5A89409D20E64F8640D9F
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{EF9953C6-B472-4B02-9D22-D0E247ADE0E8}\ProxyStubClsid32
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}.KB2467173
  • HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Installer\Managed\S-1-5-21-3416602863-1947377224-293699093-1003\Installer\UpgradeCodes\C36A0D91BD55D7540994A61CDC6153E4
  • HKEY_CURRENT_USER\Software\Microsoft\Installer\UpgradeCodes\BBED9B58097CAA746B924CB27661E248
  • HKEY_LOCAL_MACHINE\Software\Classes\Installer\Dependencies\{72BA52D1-77C6-403A-82E2-346D91CB08DD}
  • HKEY_CURRENT_USER\Software\Microsoft\Installer\UpgradeCodes\C36A0D91BD55D7540994A61CDC6153E4
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\policy.4.0.PresentationCore__31bf3856ad364e35
  • HKEY_CURRENT_USER\CLSID\{AF44BF80-36DD-4118-B4CF-8B1E3F4FB9CE}
  • HKEY_CURRENT_USER\Software\Microsoft\Fusion
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\policy.4.0.System.Security__b03f5f7f11d50a3a
  • HKEY_CURRENT_USER\Software\Microsoft\Installer\UpgradeCodes\D5BAC2C114ED1AC47AA0BF5146D9D692
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\Mozilla Firefox 12.0 (x86 en-US)
  • HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\Video\{F468E916-830A-459C-99C9-5CDE065A72E5}\0000
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}.KB2565063
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\CTF\TIP\{0000897b-83df-4b96-be07-0fb58b01c4a4}\LanguageProfile
  • HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\GraphicsDrivers\Scheduler
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\policy.4.0.ReachFramework__31bf3856ad364e35
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\v4.0_policy.4.0.System__b77a5c561934e089
  • HKEY_LOCAL_MACHINE\Software\Microsoft\Fusion
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\v4.0_policy.4.0.System.Configuration__b03f5f7f11d50a3a
  • HKEY_LOCAL_MACHINE\Software\Microsoft\Direct3D\Drivers\RGB Emulation
  • HKEY_CURRENT_USER\Interface\{AF44BF80-36DD-4118-B4CF-8B1E3F4FB9CE}
  • HKEY_LOCAL_MACHINE\Software\Classes\Installer\UpgradeCodes\0D313D3ED7241A24EA49756DD2D01F10
  • HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\1D25AB276C77A304282E43D619BC80DD\InstallProperties
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\policy.4.0.System.Xml__b77a5c561934e089
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\AddressBook
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\Adobe Flash Player Plugin
  • HKEY_LOCAL_MACHINE\Software\Microsoft\StrongName
  • HKEY_CURRENT_USER\Software\Microsoft\Wisp\Pen\SysEventParameters
  • HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Installer\Managed\S-1-5-21-3416602863-1947377224-293699093-1003\Installer\UpgradeCodes\D5BAC2C114ED1AC47AA0BF5146D9D692
  • HKEY_CURRENT_USER\Msxml2.DOMDocument
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{F6D90F11-9C73-11D3-B32E-00C04F990BB4}\InprocServer32
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\v4.0_policy.4.0.PresentationCore__31bf3856ad364e35
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{00000134-0000-0000-C000-000000000046}\ProxyStubClsid32
  • HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows\Installer
  • HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\.NETFRAMEWORK\Policy\Standards\v4.0
  • HKEY_LOCAL_MACHINE\Software\Microsoft\.NETFramework
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\CTF\TIP\{0000897b-83df-4b96-be07-0fb58b01c4a4}\LanguageProfile\0x00000000
  • HKEY_CURRENT_USER\Software\Policies\Microsoft\Internet Explorer\Main\FeatureControl
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}.KB2151757
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}.KB2549743
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{88603FC0-6B3C-442D-981E-E3D49F083548}_is1
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\CTF\TIP\{0000897b-83df-4b96-be07-0fb58b01c4a4}\LanguageProfile\0x00000000\{0001bea3-ed56-483d-a2e2-aeae25577436}
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\v4.0_policy.4.0.System.Data.SqlXml__b77a5c561934e089
  • HKEY_CURRENT_USER\SOFTWARE\Microsoft\CTF\CUAS\DefaultCompositionWindow
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Managed\S-1-5-21-3416602863-1947377224-293699093-1003\Installer\Assemblies\C:|Users|HARRYD~1|AppData|Local|Temp|{5145A569-B485-4CF9-9A72-357221B266D4}|.ba|BootstrapperCore.config
  • HKEY_LOCAL_MACHINE\Software\Classes\Installer\Dependencies\{4F192902-A341-4321-838F-B92E03D44D27}
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\policy.4.0.System.Data.SqlXml__b77a5c561934e089
  • HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows NT\Rpc
  • HKEY_CLASSES_ROOT\Interface\{C247F616-BBEB-406A-AED3-F75E656599AE}
  • HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\0a1f7795b1de042f3782bb229931a09ee36eecb7.exe
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{975C3A93-2491-3D44-A071-F6CBF153E46D}
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}.KB2544655
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\policy.4.0.System__b77a5c561934e089
  • HKEY_CURRENT_USER\Software\Microsoft\CTF
  • HKEY_LOCAL_MACHINE\Software\Microsoft\Avalon.Graphics
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\CTF\TIP\{FA445657-9379-11D6-B41A-00065B83EE53}\Category\Category\{6302DE22-A5CF-4B02-BFE8-4D72B2BED3C6}
  • HKEY_LOCAL_MACHINE\Software\Microsoft\Net Framework Setup\NDP\v4\Client
  • HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\CTF\TIP\{F89E9E58-BD2F-4008-9AC2-0F816C09F4EE}\Category\Category\{6302DE22-A5CF-4B02-BFE8-4D72B2BED3C6}
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\MozillaMaintenanceService
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\v4.0_policy.4.0.System.Security__b03f5f7f11d50a3a
  • HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\209291F4143A123438F89BE2304DD472\InstallProperties
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}.KB2524860
  • HKEY_CURRENT_USER\Software\Microsoft\Installer\Assemblies\Global
  • HKEY_CLASSES_ROOT\CLSID\{AE6BE008-07FB-400D-8BEB-337A64F7051F}\InProcServer32
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\Foxit Reader_is1
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\CPC\Volume\{b9fc2740-d442-11e0-8ee6-806e6f6e6963}\
  • HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Installer\Managed\S-1-5-21-3416602863-1947377224-293699093-1003\Installer\UpgradeCodes\A0467937E2A5A89409D20E64F8640D9F
  • HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\FBCA0A92B051C824B8467D5FD1E3149D\InstallProperties
  • HKEY_LOCAL_MACHINE\Software\Microsoft\.NETFramework\NGen\Policy\v4.0
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\v4.0_policy.4.0.System.Xml__b77a5c561934e089
  • HKEY_CURRENT_USER\Interface\{BAD4B6E9-99AF-42F8-A767-FBCFC5FCA397}
  • HKEY_LOCAL_MACHINE\Software\Classes\Installer\Products\49F9D5E0755A3584CAD460E63A605BDC
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\CTF\TIP\
  • HKEY_CLASSES_ROOT\CLSID\{FAE3D380-FEA4-4623-8C75-C6B61110B681}\Instance\Disabled
  • HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_ALLOW_REVERSE_SOLIDUS_IN_USERINFO_KB932562
  • HKEY_CURRENT_USER\Software\Microsoft\Installer\UpgradeCodes\B5CBFE3AFBF6D9843A5BE217240CD2FE
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\DirectDrawEx
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\v4.0_policy.4.0.PresentationFramework__31bf3856ad364e35
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\v4.0_policy.4.0.PresentationFramework.classic__31bf3856ad364e35
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ICM\ICMatchers
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\CTF\TIP\{0000897b-83df-4b96-be07-0fb58b01c4a4}\Category\Category\{6302DE22-A5CF-4B02-BFE8-4D72B2BED3C6}
  • HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings
  • HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Internet Settings
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\policy.4.0.System.Printing__31bf3856ad364e35
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{997A992E-8B6C-4945-BC17-A1EE563B3AB7}\ProxyStubClsid32
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\policy.4.0.UIAutomationTypes__31bf3856ad364e35
  • HKEY_LOCAL_MACHINE\Software\Microsoft\.NETFramework\Windows Presentation Foundation\Features
  • HKEY_CURRENT_USER\Software\Microsoft\.NETFramework
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\CTF\TIP\{78CB5B0E-26ED-4FCC-854C-77E8F3D1AA80}\Category\Category\{6302DE22-A5CF-4B02-BFE8-4D72B2BED3C6}
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\v4.0_policy.4.0.System.Xaml__b77a5c561934e089
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Cryptography\Defaults\Provider Types\Type 024
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{F6D90F11-9C73-11D3-B32E-00C04F990BB4}\Progid
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\MobileOptionPack
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{95120000-003F-0409-0000-0000000FF1CE}
  • HKEY_LOCAL_MACHINE\Software\Microsoft\Direct3D\Drivers
  • HKEY_LOCAL_MACHINE\Software\Classes\Installer\Dependencies\{29A0ACBF-150B-428C-8B64-D7F51D3E41D9}
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\CTF\TIP\{A028AE76-01B1-46C2-99C4-ACD9858AE02F}\Category\Category\{6302DE22-A5CF-4B02-BFE8-4D72B2BED3C6}
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{AF44BF80-36DD-4118-B4CF-8B1E3F4FB9CE}\TreatAs
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{95140000-00AF-0409-0000-0000000FF1CE}
  • HKEY_CURRENT_USER\Software\Microsoft\Tracing\WPF
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\CTF\TIP\{03B5835F-F03C-411B-9CE2-AA23E1171E36}\Category\Category\{6302DE22-A5CF-4B02-BFE8-4D72B2BED3C6}
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\v4.0_policy.4.0.System.Core__b77a5c561934e089
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\policy.4.0.System.Deployment__b03f5f7f11d50a3a
  • HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Internet Explorer\Main\FeatureControl
  • HKEY_CURRENT_USER\Software\Microsoft\Installer\UpgradeCodes\0D313D3ED7241A24EA49756DD2D01F10
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\.NETFramework\Policy\APTCA
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\Assemblies\C:|Users|HARRYD~1|AppData|Local|Temp|{5145A569-B485-4CF9-9A72-357221B266D4}|.ba|BootstrapperCore.config
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\CPC\Volume\{b9fc273c-d442-11e0-8ee6-806e6f6e6963}\
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\v4.0_policy.4.0.UIAutomationTypes__31bf3856ad364e35
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\v4.0_policy.4.0.ReachFramework__31bf3856ad364e35
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\CTF\TIP\{531FDEBF-9B4C-4A43-A2AA-960E8FCDC732}\Category\Category\{6302DE22-A5CF-4B02-BFE8-4D72B2BED3C6}
  • HKEY_LOCAL_MACHINE\Software\Microsoft\Direct3D\DX6TextureEnumInclusionList
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\CTF\TIP\{C1EE01F2-B3B6-4A6A-9DDD-E988C088EC82}\Category\Category\{6302DE22-A5CF-4B02-BFE8-4D72B2BED3C6}
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{F6D90F11-9C73-11D3-B32E-00C04F990BB4}\InprocHandler32
  • HKEY_CURRENT_USER\Interface\{1CB2EFC3-ABC7-4172-8FCB-3BC9CB93E29F}
  • HKEY_LOCAL_MACHINE\Software\Microsoft\Direct3D
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\PerformanceTest 7_is1
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Managed\S-1-5-21-3416602863-1947377224-293699093-1003\Installer\Assemblies\Global
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\policy.4.0.PresentationUI__31bf3856ad364e35
  • HKEY_LOCAL_MACHINE\Software\Microsoft\COM3
  • HKEY_LOCAL_MACHINE\Software\Microsoft\Avalon.Graphics\MultiAdapterSupport
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\IE4Data
  • HKEY_LOCAL_MACHINE\Software\Classes\Installer\Products\1D25AB276C77A304282E43D619BC80DD
  • HKEY_CURRENT_USER\Software\Microsoft\Direct3D
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\policy.4.0.System.Windows.Input.Manipulations__b77a5c561934e089
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{AF44BF80-36DD-4118-B4CF-8B1E3F4FB9CE}\InprocHandler32
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{AF44BF80-36DD-4118-B4CF-8B1E3F4FB9CE}\InprocHandler
  • HKEY_CLASSES_ROOT\.png
  • HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\393B1E51ACC3B5C41A78CACB6310E937\InstallProperties
  • HKEY_LOCAL_MACHINE\Software\Classes\Installer\Dependencies\{5b45c228-dcb1-4a0b-a9de-3b4b683ef15d}
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\policy.4.0.PresentationFramework.classic__31bf3856ad364e35
  • HKEY_CURRENT_USER\Software\Microsoft\Avalon.Graphics\MultiAdapterSupport
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\v4.0_policy.4.0.UIAutomationProvider__31bf3856ad364e35
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\policy.4.0.Accessibility__b03f5f7f11d50a3a
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\CPC\Volume\{b9fc273d-d442-11e0-8ee6-806e6f6e6963}\
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{5b45c228-dcb1-4a0b-a9de-3b4b683ef15d}.RebootRequired
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Msxml2.DOMDocument\CLSID
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{41914D8B-9D6E-4764-A1F9-BC43FB6782C1}_is1
  • HKEY_CLASSES_ROOT\CLSID\{7ED96837-96F0-4812-B211-F13C24117ED3}\Instance
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{26A24AE4-039D-4CA4-87B4-2F03217067FF}
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\v4.0_policy.4.0.System.Windows.Input.Manipulations__b77a5c561934e089
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{BAD4B6E9-99AF-42F8-A767-FBCFC5FCA397}\ProxyStubClsid32
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\IE40
  • HKEY_LOCAL_MACHINE\Software\Classes\Installer\Dependencies\{15E1B393-3CCA-4C5B-A187-ACBC36019E73}
  • HKEY_LOCAL_MACHINE\Software\Classes\Installer\UpgradeCodes\D5BAC2C114ED1AC47AA0BF5146D9D692
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\CTF\TIP\{AE6BE008-07FB-400D-8BEB-337A64F7051F}\Category\Category\{6302DE22-A5CF-4B02-BFE8-4D72B2BED3C6}
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\SchedulingAgent
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\v4.0_policy.4.0.System.Deployment__b03f5f7f11d50a3a
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\v4.0_policy.3.0.BootstrapperCore__ce35f76fcda82bad
  • HKEY_LOCAL_MACHINE\Software\Classes\Installer\Dependencies\{0E5D9F94-A557-4853-AC4D-066EA306B5CD}
  • HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\ClusSvc
  • HKEY_LOCAL_MACHINE\Software\Microsoft\Fusion\PublisherPolicy\Default
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\CTF\TIP\{3697C5FA-60DD-4B56-92D4-74A569205C16}\Category\Category\{6302DE22-A5CF-4B02-BFE8-4D72B2BED3C6}
  • HKEY_LOCAL_MACHINE\Software\Classes\Installer\UpgradeCodes\2E8D14B368C20A647B6CB17EE9689EB8
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}.KB982573
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{4A03706F-666A-4037-7777-5F2748764D10}
  • HKEY_CURRENT_USER\Software\Microsoft\Installer\UpgradeCodes\2E8D14B368C20A647B6CB17EE9689EB8
  • HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Installer\Managed\S-1-5-21-3416602863-1947377224-293699093-1003\Installer\UpgradeCodes\0D313D3ED7241A24EA49756DD2D01F10
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\policy.4.0.PresentationFramework-SystemCore__b77a5c561934e089
  • HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\WinSAT
  • HKEY_CURRENT_USER\SOFTWARE\Microsoft\CTF\TIP\{0000897b-83df-4b96-be07-0fb58b01c4a4}\LanguageProfile
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\CTF\TIP\{8613E14C-D0C0-4161-AC0F-1DD2563286BC}\Category\Category\{6302DE22-A5CF-4B02-BFE8-4D72B2BED3C6}
  • HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\FileSystem
  • HKEY_LOCAL_MACHINE\Software\Classes\Installer\Products\393B1E51ACC3B5C41A78CACB6310E937
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\policy.4.0.PresentationFramework__31bf3856ad364e35
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\CTF\TIP\{81D4E9C9-1D3B-41BC-9E6C-4B40BF79E35E}\Category\Category\{6302DE22-A5CF-4B02-BFE8-4D72B2BED3C6}
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\.NETFRAMEWORK\Policy\Standards
  • HKEY_LOCAL_MACHINE\Software\Microsoft\Direct3D\Drivers\Ramp Emulation
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ICM\RegisteredProfiles
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\v4.0_policy.4.0.PresentationFramework-SystemCore__b77a5c561934e089
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\policy.3.0.BootstrapperCore__ce35f76fcda82bad
Registry Key-Read
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\PenService\21A8443D-F741-4d5d-954D-5FE60196A5E8\MDocument\DisableGestureTwoFingerZoom
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\PenService\21A8443D-F741-4d5d-954D-5FE60196A5E8\MDocument\DisableGestureSingleFingerPan
  • HKEY_CURRENT_USER\Software\Microsoft\Wisp\Touch\TouchMode_t1Dtap
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\PenService\E5129A69-FF3A-4129-AE69-9C2E280AAA4B\com.alias.TPWin32SketchView\DisableFlicksSmoothScrolling
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{C247F616-BBEB-406A-AED3-F75E656599AE}\ProxyStubClsid32\(Default)
  • HKEY_CURRENT_USER\Software\Microsoft\Wisp\Touch\Friction
  • HKEY_CURRENT_USER\Software\Microsoft\Wisp\Touch\TouchMode_tFadeout
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Wisp\Touch\TouchModeN_DtapTime
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{997A992E-8B6C-4945-BC17-A1EE563B3AB7}\ProxyStubClsid32\(Default)
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Wisp\Touch\TouchDisableConfidenceUsage
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\PenService\1EC353D2-7EE4-4cbe-A63A-4BFE68DBC65A\paneClassDC\DisableGesturePressAndTap
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Wisp\Pen\SysEventParameters\Move
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Wisp\Touch\PanningDisabled
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\PenService\36D1B905-CC62-4ab0-9C08-118B66D6DB90\VISIOD\DisableGesturePressAndTap
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Wisp\Pen\SysEventParameters\Splash.max
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\PenService\1EC353D2-7EE4-4cbe-A63A-4BFE68DBC65A\paneClassDC\EnableFlickLearningMode
  • HKEY_CURRENT_USER\Software\Microsoft\Wisp\Touch\TouchDisableConfidenceUsage
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Wisp\Pen\SysEventParameters\Splash.min
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Wisp\Pen\SysEventParameters\WaitTime
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\PenService\9A979A3F-92BB-49e9-8F2E-4EB423A9BFC9\Static\DisableGestureTwoFingerPan
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\PenService\E5129A69-FF3A-4129-AE69-9C2E280AAA4B\com.alias.TPWin32SketchView\EnableFlicksWhileInking
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Wisp\Pen\SysEventParameters\HoverMinTimeNotIn
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\PenService\9A979A3F-92BB-49e9-8F2E-4EB423A9BFC9\Static\DisableFlickGestureDetection
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\PenService\30988F51-D107-4f3b-97A8-60953D29EA39\xpUnicodeWindow\DisablePenTapFeedback
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\PenService\9A979A3F-92BB-49e9-8F2E-4EB423A9BFC9\Static\DisableGestureSingleFingerPan
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Wisp\Pen\SysEventParameters\DblTime_Between
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\PenService\596fd73c-fff3-4d3f-81d3-8af2955f3547\Internet Explorer_Server\DisableFlickFallbackKeys
  • HKEY_CURRENT_USER\Software\Microsoft\Wisp\Touch\TouchModeN_HoldTime_BeforeAnimation
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\PenService\596fd73c-fff3-4d3f-81d3-8af2955f3547\Internet Explorer_Server\TouchPointerOff
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{9E358D23-02B2-4CCD-9FEE-6B75EE8DD5CA}\InProcServer32\(Default)
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\PenService\36D1B905-CC62-4ab0-9C08-118B66D6DB90\ListBox\DisableGesturePressAndTap
  • HKEY_CURRENT_USER\Software\Microsoft\Wisp\Touch\TouchMode_tActivation
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\PenService\596fd73c-fff3-4d3f-81d3-8af2955f3547\Internet Explorer_Server\EnableFlicksWhileInking
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Wisp\Pen\SysEventParameters\DblDist_Stroke1
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\PenService\30988F51-D107-4f3b-97A8-60953D29EA39\xpUnicodeWindow\DisableFlickGestureDetection
  • HKEY_CURRENT_USER\Software\Microsoft\Wisp\Touch\TouchModeN_DtapTime
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Wisp\Pen\SysEventParameters\HoverCount
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\PenService\36D1B905-CC62-4ab0-9C08-118B66D6DB90\ListBox\EnableFlicksWhileInking
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\PenService\596fd73c-fff3-4d3f-81d3-8af2955f3547\Internet Explorer_Server\DisableFlickGestureDetection
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\PenService\E5129A69-FF3A-4129-AE69-9C2E280AAA4B\com.alias.TPWin32SketchView\EnableFlickLearningMode
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\PenService\1EC353D2-7EE4-4cbe-A63A-4BFE68DBC65A\paneClassDC\TouchPointerOff
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\PenService\1CAD86A5-8A18-4297-A3FF-5A110325FA12\PSViewC\TouchPointerOff
  • HKEY_CURRENT_USER\Software\Microsoft\Wisp\Touch\TouchMode_tTolerateLcps0_Disconnected
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Wisp\Pen\SysEventParameters\HoverVelocityThreshold
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SQMClient\Windows\CEIPSampledIn
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Wisp\Touch\TouchMode_directIfNoUI
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\PenService\36D1B905-CC62-4ab0-9C08-118B66D6DB90\ListBox\DisablePressAndHold
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Wisp\Touch\TouchMode_tFadeout
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\PenService\36D1B905-CC62-4ab0-9C08-118B66D6DB90\VISIOD\TouchPointerOff
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\PenService\1CAD86A5-8A18-4297-A3FF-5A110325FA12\PSViewC\DisableGestureTwoFingerZoom
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Wisp\Touch\TouchMode_tHold0
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\PenService\E5129A69-FF3A-4129-AE69-9C2E280AAA4B\com.alias.TPWin32SketchView\DisableGesturePressAndTap
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Wisp\Pen\SysEventParameters\DblDist.max
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Wisp\Touch\Inertia
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Wisp\Pen\SysEventParameters\ShakeSize
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Wisp\Pen\SysEventParameters\SingleTapMode
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\PenService\36D1B905-CC62-4ab0-9C08-118B66D6DB90\VISIOG\DisableGestureTwoFingerPan
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Wisp\Touch\TouchMode_useEdgeFlipGuides
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Wisp\Pen\SysEventParameters\EraseEnable
  • HKEY_CURRENT_USER\Software\Microsoft\Wisp\Touch\TouchModeN_HoldTime_Animation
  • HKEY_CURRENT_USER\Software\Microsoft\Wisp\Touch\TouchDisablePalmRejection
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\PenService\21A8443D-F741-4d5d-954D-5FE60196A5E8\MDocument\DisablePenBarrelFeedback
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Wisp\Pen\SysEventParameters\DblDist.min
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\PenService\21A8443D-F741-4d5d-954D-5FE60196A5E8\MDocument\DisableFlickGestureDetection
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{A5B020FD-E04B-4E67-B65A-E7DEED25B2CF}\(Default)
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\PenService\9A979A3F-92BB-49e9-8F2E-4EB423A9BFC9\Static\DisableFlickFallbackKeys
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Wisp\Touch\Bouncing
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Wisp\Pen\SysEventParameters\DblTime_Stroke1
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{764DE8AA-1867-47C1-8F6A-122445ABD89A}\ProxyStubClsid32\(Default)
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Wisp\Pen\SysEventParameters\DoubleTapMode
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\PenService\9A979A3F-92BB-49e9-8F2E-4EB423A9BFC9\Static\TouchPointerOff
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Wisp\Pen\SysEventParameters\TouchFlickTolerance
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\PenService\E5129A69-FF3A-4129-AE69-9C2E280AAA4B\com.alias.TPWin32SketchView\DisablePressAndHold
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\PenService\36D1B905-CC62-4ab0-9C08-118B66D6DB90\VISIOD\DisableFlicksSmoothScrolling
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Wisp\Pen\SysEventParameters\Move.min
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Wisp\Pen\SysEventParameters\DblTime.max
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Wisp\Pen\SysEventParameters\ShakeAngle.min
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\PenService\36D1B905-CC62-4ab0-9C08-118B66D6DB90\VISIOD\DisablePenBarrelFeedback
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\PenService\36D1B905-CC62-4ab0-9C08-118B66D6DB90\VISIOD\DisableFlickFallbackKeys
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\PenService\1CAD86A5-8A18-4297-A3FF-5A110325FA12\PSViewC\EnableFlickLearningMode
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\PenService\1EC353D2-7EE4-4cbe-A63A-4BFE68DBC65A\paneClassDC\EnableFlicksWhileInking
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\PenService\30988F51-D107-4f3b-97A8-60953D29EA39\xpUnicodeWindow\DisablePressAndHold
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Wisp\Pen\SysEventParameters\DblTime.min
  • HKEY_CURRENT_USER\Software\Microsoft\Wisp\Touch\TouchMode_directIfNoUI
  • HKEY_CURRENT_USER\Software\Microsoft\Wisp\Pen\SysEventParameters\ShakeAngle
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Wisp\Pen\SysEventParameters\DblDist_Between
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\crypt32\DebugHeapFlags
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Wisp\Pen\SysEventParameters\DblTime
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Wisp\Touch\TouchMode_tHold
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Wisp\Pen\SysEventParameters\FlickMode
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\PenService\9A979A3F-92BB-49e9-8F2E-4EB423A9BFC9\Static\DisableFlicksSmoothScrolling
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Wisp\Pen\SysEventParameters\Splash
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Wisp\Touch\TouchMode_tTolerateLcps0_Connected
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Wisp\Pen\SysEventParameters\UIFeedbackMode
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\PenService\1EC353D2-7EE4-4cbe-A63A-4BFE68DBC65A\paneClassDC\DisableGestureTwoFingerPan
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\PenService\21A8443D-F741-4d5d-954D-5FE60196A5E8\MDocument\DisableFlickFallbackKeys
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\PenService\9A979A3F-92BB-49e9-8F2E-4EB423A9BFC9\Static\DisableGesturePressAndTap
  • HKEY_CURRENT_USER\Software\Microsoft\Wisp\Touch\TouchMode_dv1Dtap
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Wisp\Pen\SysEventParameters\ShakeAngle.max
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\PenService\36D1B905-CC62-4ab0-9C08-118B66D6DB90\VISIOG\DisableFlicksSmoothScrolling
  • HKEY_CURRENT_USER\Software\Microsoft\Wisp\Touch\TouchMode_dvbDtap
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Wisp\Touch\TouchDisablePalmRejection
  • HKEY_CURRENT_USER\Software\Microsoft\Wisp\Touch\TouchMode_tFadeoutDuration
  • HKEY_CURRENT_USER\Software\Microsoft\Wisp\Touch\TouchMode_tHold
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\PenService\1CAD86A5-8A18-4297-A3FF-5A110325FA12\PSViewC\DisableGestureTwoFingerPan
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\PenService\36D1B905-CC62-4ab0-9C08-118B66D6DB90\VISIOD\DisablePressAndHold
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Wisp\Pen\SysEventParameters\MouseInputResolutionY
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Wisp\Pen\SysEventParameters\MouseInputResolutionX
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Wisp\Pen\SysEventParameters\MouseInputFrequency
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\PenService\36D1B905-CC62-4ab0-9C08-118B66D6DB90\ListBox\DisableFlicksSmoothScrolling
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\PenService\21A8443D-F741-4d5d-954D-5FE60196A5E8\MDocument\TouchPointerOff
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Wisp\Pen\SysEventParameters\CloseTime.min
  • HKEY_CURRENT_USER\Software\Microsoft\Wisp\Touch\Bouncing
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Wisp\Touch\TouchMode_fadeoutCurve
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Wisp\MultiTouch\MultiTouchEnabled
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\PenService\36D1B905-CC62-4ab0-9C08-118B66D6DB90\ListBox\DisableFlickFallbackKeys
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\PenService\1EC353D2-7EE4-4cbe-A63A-4BFE68DBC65A\paneClassDC\DisableGestureTwoFingerZoom
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Wisp\Pen\SysEventParameters\ShakeCount
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\PenService\1EC353D2-7EE4-4cbe-A63A-4BFE68DBC65A\paneClassDC\DisablePenTapFeedback
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Wisp\Touch\TouchMode_dtbDtap
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Wisp\Touch\Friction
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\PenService\30988F51-D107-4f3b-97A8-60953D29EA39\xpUnicodeWindow\TouchPointerOff
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Wisp\Pen\SysEventParameters\WaitTime.max
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Wisp\Touch\TouchGateHardwareButton
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\PenService\1CAD86A5-8A18-4297-A3FF-5A110325FA12\PSViewC\DisableGesturePressAndTap
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\PenService\21A8443D-F741-4d5d-954D-5FE60196A5E8\MDocument\DisableGesturePressAndTap
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\PenService\30988F51-D107-4f3b-97A8-60953D29EA39\xpUnicodeWindow\DisableGestureTwoFingerZoom
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\PenService\36D1B905-CC62-4ab0-9C08-118B66D6DB90\VISIOD\DisablePenTapFeedback
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Wisp\Pen\SysEventParameters\ShakeRate
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\PenService\E5129A69-FF3A-4129-AE69-9C2E280AAA4B\com.alias.TPWin32SketchView\TouchPointerOff
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\PenService\36D1B905-CC62-4ab0-9C08-118B66D6DB90\VISIOG\DisableFlickFallbackKeys
  • HKEY_CURRENT_USER\Software\Microsoft\Wisp\Touch\TouchModeN_DtapDist
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\PenService\36D1B905-CC62-4ab0-9C08-118B66D6DB90\VISIOD\DisableGestureTwoFingerZoom
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Wisp\Pen\SysEventParameters\WaitTime.min
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\PenService\1EC353D2-7EE4-4cbe-A63A-4BFE68DBC65A\paneClassDC\DisableGestureSingleFingerPan
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\PenService\596fd73c-fff3-4d3f-81d3-8af2955f3547\Internet Explorer_Server\DisableGestureTwoFingerZoom
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Wisp\Pen\SysEventParameters\Move.max
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Wisp\Pen\SysEventParameters\RightMaskEnable
  • HKEY_CURRENT_USER\Software\Microsoft\Wisp\Touch\PanningDisabled
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\PenService\9A979A3F-92BB-49e9-8F2E-4EB423A9BFC9\Static\DisablePenTapFeedback
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\PenService\36D1B905-CC62-4ab0-9C08-118B66D6DB90\VISIOD\DisableFlickGestureDetection
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Wisp\Pen\SysEventParameters\Cancel.max
  • HKEY_CURRENT_USER\Software\Microsoft\Wisp\Touch\TouchGateHardwareButton
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Wisp\Touch\TouchMode_dvbDtap
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\PenService\9A979A3F-92BB-49e9-8F2E-4EB423A9BFC9\Static\DisablePenBarrelFeedback
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\PenService\1CAD86A5-8A18-4297-A3FF-5A110325FA12\PSViewC\DisablePenTapFeedback
  • HKEY_CURRENT_USER\Software\Microsoft\Wisp\Touch\TouchMode_dtbDtap
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\PenService\21A8443D-F741-4d5d-954D-5FE60196A5E8\MDocument\DisablePenTapFeedback
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\PenService\30988F51-D107-4f3b-97A8-60953D29EA39\xpUnicodeWindow\EnableFlickLearningMode
  • HKEY_CURRENT_USER\Software\Microsoft\Wisp\Pen\SysEventParameters\FlickMode
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Wisp\Touch\TouchMode_tFadeoutDuration
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\PenService\596fd73c-fff3-4d3f-81d3-8af2955f3547\Internet Explorer_Server\DisableGestureSingleFingerPan
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Wisp\Touch\TouchMode_rHold
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\PenService\36D1B905-CC62-4ab0-9C08-118B66D6DB90\VISIOD\EnableFlicksWhileInking
  • HKEY_CURRENT_USER\Software\Microsoft\Wisp\Pen\SysEventParameters\FlickTolerance
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{1CB2EFC3-ABC7-4172-8FCB-3BC9CB93E29F}\ProxyStubClsid32\(Default)
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Wisp\Touch\TouchGate
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\TabletPC\ExtendedButtonActions\(Default)
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Wisp\Touch\TouchMode_hold
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Wisp\Pen\SysEventParameters\HoverCount.min
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\PenService\36D1B905-CC62-4ab0-9C08-118B66D6DB90\VISIOG\TouchPointerOff
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Wisp\Pen\SysEventParameters\CloseTime
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\PenService\1CAD86A5-8A18-4297-A3FF-5A110325FA12\PSViewC\DisableFlickGestureDetection
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\PenService\E5129A69-FF3A-4129-AE69-9C2E280AAA4B\com.alias.TPWin32SketchView\DisablePenBarrelFeedback
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\PenService\36D1B905-CC62-4ab0-9C08-118B66D6DB90\VISIOG\DisableGestureSingleFingerPan
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\PenService\36D1B905-CC62-4ab0-9C08-118B66D6DB90\VISIOD\DisableGestureSingleFingerPan
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\PenService\596fd73c-fff3-4d3f-81d3-8af2955f3547\Internet Explorer_Server\DisableGesturePressAndTap
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Wisp\Pen\SysEventParameters\HoldTime.min
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Wisp\Pen\SysEventParameters\HoverCount.max
  • HKEY_CURRENT_USER\Software\Microsoft\Wisp\Touch\TouchMode
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\PenService\1CAD86A5-8A18-4297-A3FF-5A110325FA12\PSViewC\EnableFlicksWhileInking
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Wisp\Pen\SysEventParameters\CloseTime.max
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\PenService\36D1B905-CC62-4ab0-9C08-118B66D6DB90\ListBox\DisablePenTapFeedback
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\PenService\36D1B905-CC62-4ab0-9C08-118B66D6DB90\ListBox\EnableFlickLearningMode
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\PenService\596fd73c-fff3-4d3f-81d3-8af2955f3547\Internet Explorer_Server\DisableFlicksSmoothScrolling
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Wisp\Pen\SysEventParameters\ShakeTime
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\PenService\1CAD86A5-8A18-4297-A3FF-5A110325FA12\PSViewC\DisableFlickFallbackKeys
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\PenService\E5129A69-FF3A-4129-AE69-9C2E280AAA4B\com.alias.TPWin32SketchView\DisablePenTapFeedback
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Wisp\Pen\SysEventParameters\Cancel.min
  • HKEY_CURRENT_USER\Software\Microsoft\Wisp\Touch\TouchUI
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Wisp\Touch\TouchUI
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\PenService\21A8443D-F741-4d5d-954D-5FE60196A5E8\MDocument\DisableGestureTwoFingerPan
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Wisp\Touch\TouchModeN_HoldTime_BeforeAnimation
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\PenService\1EC353D2-7EE4-4cbe-A63A-4BFE68DBC65A\paneClassDC\DisableFlicksSmoothScrolling
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Wisp\Pen\SysEventParameters\HoverLimit.min
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Wisp\Pen\SysEventParameters\ShakeRate.min
  • HKEY_CURRENT_USER\Software\Microsoft\Wisp\Touch\TouchGate
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\PenService\36D1B905-CC62-4ab0-9C08-118B66D6DB90\VISIOG\EnableFlickLearningMode
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Wisp\Pen\SysEventParameters\HoldMode
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Wisp\Touch\TouchMode_dvOrientationFlip
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Wisp\Pen\SysEventParameters\ShakeTime.min
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Wisp\Pen\SysEventParameters\ShakeCount.min
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Wisp\Pen\SysEventParameters\ShakeSize.max
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\PenService\21A8443D-F741-4d5d-954D-5FE60196A5E8\MDocument\EnableFlickLearningMode
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Wisp\Pen\SysEventParameters\Cancel
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Wisp\Pen\SysEventParameters\ShakeSize.min
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Wisp\Touch\TouchMode
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\PenService\1EC353D2-7EE4-4cbe-A63A-4BFE68DBC65A\paneClassDC\DisableFlickGestureDetection
  • HKEY_CURRENT_USER\Software\Microsoft\Wisp\Touch\TouchMode_fadeoutCurve
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Wisp\Touch\TouchModeN_DtapDist
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Wisp\Pen\SysEventParameters\HoldTime.max
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\PenService\36D1B905-CC62-4ab0-9C08-118B66D6DB90\ListBox\TouchPointerOff
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\PenService\E5129A69-FF3A-4129-AE69-9C2E280AAA4B\com.alias.TPWin32SketchView\DisableGestureSingleFingerPan
  • HKEY_CURRENT_USER\Software\Microsoft\Wisp\Touch\TouchUIFlipVelocity
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\PenService\36D1B905-CC62-4ab0-9C08-118B66D6DB90\VISIOG\DisablePenBarrelFeedback
  • HK