'
metaflows logo
Category Started On Completed On Duration Cuckoo Version
FILE 2016-11-08 11:51:21.901085 2016-11-08 11:54:05.349363 163 seconds 2.0-dev
Machine Label Manager Started On Shutdown On
win7cuckoo2 win7 Clone 2 VirtualBox 2016-11-08 11:51:22 2016-11-08 11:54:04

File Details

File name e93ac97e07178e7d342158d86f91a3688de73b3d.zip
File size 1098 bytes
File type Zip archive data, at least v2.0 to extract
CRC32 B91C1D42
MD5 e0b65cea9e51107ae2bb10cc7d16fc7c
SHA1 e93ac97e07178e7d342158d86f91a3688de73b3d
SHA256 59e420d18fe9c812c4b9ed190704d16b6deef50f213ca144df904ed01e50f829
SHA512 e855a21c16be7b4c323f3b6724f49def644778d9cf6804439c43a3f992acc92b69bc28cb8c75cb5babff44818dbca252eaedd3b9ebf1bd761e5767ca7051d70f
Ssdeep 24:9ApCv25+Vri+l6Occ7T5IlntsEjWKi0o71oj0jDSRsZQztkgXz59:9QC24Fljp7lYtzhs71olR/p919
PEiD None matched
Yara
  • PM_Zip_with_js ()
VirusTotal File not found on VirusTotal

MetaFlows Scores

Metaflows Analysis Results (Signatures=125, Anomalies=0, PEiD=0, Yara=2, VT[1478606074]=0): Snort Events=2, AV Events=2
Total Score=125

SNORT EVENTS:
ET POLICY PE EXE or DLL Windows file download HTTP
ET MALWARE Possible Windows executable sent when remote host claims to send a Text File

CLAMAV DETECTED:
Sanesecurity.Malware.26447.JsHeur.UNOFFICIAL FOUND
DROPPED FILE - NRV_089P9P3_.js: Sanesecurity.Malware.26447.JsHeur.UNOFFICIAL FOUND

Dropped File/Buffer Yara Signatures:
d719f68ef38d6b43f392a9dca233d1c8d694d899 [BUFFER]: shellcode
036e387d27e61850197d2042a422709a2df73925 [BUFFER]: Str_Win32_Http_API

Signatures

antivm_queries_computername details
recon_fingerprint details
antivm_memory_available details
dumped_buffer details
creates_doc details
antivm_network_adapters details
dumped_buffer2 details
antivm_vbox_files details
Windows_Proxy_Tinkering details
network_wscript_downloader details
persistence_ads details
antiav_detectfile details
exploit_heapspray details
malicious_document_urls details
network_document_file details
network_downloader_exe details
antivm_vbox_devices details
antivm_vbox_files details
modifies_files details

Screenshots

No screenshots available.

Static Analysis

Nothing to display.

Dropped Files

730bbfc4c49848e0_076e35c0-5e29-6be8-866d-58d7484f7380.thor

7c08a40592f2f282_076e35c0-5e29-6be8-b887-af7c2aad96e8.thor

ac036c0b1c5c5cf9_076e35c0-5e29-6be8-02c7-4946709e4204.thor

573f8d22aa670186_076e35c0-5e29-6be8-42cc-bfdc971d91fc.thor

b7f08de6a3f6327b_n9bbiqe8b.dll

2098007cee1e37f6_076e35c0-5e29-6be8-3b40-55095258659c.thor

fc4238d40aa75b6e_076e35c0-5e29-6be8-2289-226a0ad6b9a5.thor

c37e92e9a86b53d9_076e35c0-5e29-6be8-e3f0-f1b3e87ab6f4.thor

6b59e0401bb27949_076e35c0-5e29-6be8-53a2-6830c6f3ac99.thor

66e0b9da64595f2c_076e35c0-5e29-6be8-8ac4-04211b0121ff.thor

99601cc16c57b702_076e35c0-5e29-6be8-d1b9-b7dca3b0eaaa.thor

dee81a99da22450d_076e35c0-5e29-6be8-5e57-bd9c5ad5780e.thor

8941cf44a4c71200_076e35c0-5e29-6be8-657a-20c67b7648d7.thor

a1b20444ecee9d36_076e35c0-5e29-6be8-5908-7f3d23c2f341.thor

1e4b9ef81bcbc797_076e35c0-5e29-6be8-6c77-6a29dd84fda7.thor

3668319ae12ece7c_076e35c0-5e29-6be8-db3d-bfd1b27f5d30.thor

b025b73d6f980c43_076e35c0-5e29-6be8-2ccc-c9cb39ab19a7.thor

5189dd3cb1dbf2d3_076e35c0-5e29-6be8-8b29-8937bec9d6fb.thor

fc3b73f937e1c0c5_076e35c0-5e29-6be8-e505-6483c8c983a0.thor

4e1b4b35378b1a79_076e35c0-5e29-6be8-2d3c-044bfbce1514.thor

b78f89528860961f_076e35c0-5e29-6be8-566e-ef2c0a4fd76d.thor

100666ba13b6fc0d_076e35c0-5e29-6be8-4f7e-aac91ee634bf.thor

b9913d2275746fc6_076e35c0-5e29-6be8-15e4-dc6c0015b658.thor

0726c3a720823ea8_076e35c0-5e29-6be8-dea2-fa91f1960912.thor

3e7acf05599a9721_076e35c0-5e29-6be8-671a-ede896c701b1.thor

5d08d9f5da021f81_076e35c0-5e29-6be8-5a6b-bdc355c06291.thor

94d7fa7f3bcb3f75_076e35c0-5e29-6be8-da23-682d09b49dfe.thor

0d973cbcf8f78777_076e35c0-5e29-6be8-371e-7dff9a12e92b.thor

dd518c7de9665b1e_076e35c0-5e29-6be8-afb8-e027ff3fab5a.thor

62225cd0ac8de266_076e35c0-5e29-6be8-851f-bd0b36b5a37c.thor

aa0b0fb0871bcba5_076e35c0-5e29-6be8-a3d7-080e78529220.thor

61f8de9c517e404f_076e35c0-5e29-6be8-1aec-88039a518fc8.thor

71f189a171f223d0_076e35c0-5e29-6be8-82d8-5c09edf63ecf.thor

8219b99982bc8f78_076e35c0-5e29-6be8-6152-a645f46a6efe.thor

51c6b12d2251ca62_076e35c0-5e29-6be8-eeca-7318a52dcb6f.thor

0378aeab755e70e2__5_what_is.html

694489d8403586a2_076e35c0-5e29-6be8-f900-edd0501a0927.thor

d2dc33a7dc8df183_076e35c0-5e29-6be8-f041-a3daa503b8d4.thor

4119265cac94a2ef_076e35c0-5e29-6be8-2aa3-469178fb354f.thor

40ede0368209de82_076e35c0-5e29-6be8-7f39-5e0823a6cc2f.thor

cfc6f3584880e2c0_076e35c0-5e29-6be8-8012-35c0008200fc.thor

890711782d9bcdc6_076e35c0-5e29-6be8-f8f0-e7160bdaf835.thor

bfb032192c8c1756_076e35c0-5e29-6be8-1422-7ecf51728688.thor

2a46f5ca28a711cf_076e35c0-5e29-6be8-d327-7f6ba7f80fd6.thor

90f84987d4b621da_076e35c0-5e29-6be8-b460-d805e9187b44.thor

5f29b3de4357e7ba_076e35c0-5e29-6be8-7805-ccf59fcac108.thor

d4ab5801728c4c60_076e35c0-5e29-6be8-cf3a-f0b6e38e831a.thor

bbd331c5d72ed1f8_076e35c0-5e29-6be8-4e7c-f88d8862d98d.thor

7d40301601677c04_076e35c0-5e29-6be8-d534-445b054195f4.thor

a5b6bf6ac26e19fb_076e35c0-5e29-6be8-782b-b2cb8665bbe6.thor

a60d4a43202029e0_076e35c0-5e29-6be8-6e3a-a8e25b090728.thor

e1cdc044a352a51b_076e35c0-5e29-6be8-3680-957ed38d32e6.thor

8d4a62c219d73c54_076e35c0-5e29-6be8-4683-2313665c0f98.thor

cd5ecd6e6c88cd90_076e35c0-5e29-6be8-12bf-b7476e9b957f.thor

c5a372bfe3be1d8b_076e35c0-5e29-6be8-85ca-de7c1f500c53.thor

a712f95ad6d6715c_076e35c0-5e29-6be8-3802-8ea668fa73c1.thor

ff640d984c1a3e6b_076e35c0-5e29-6be8-713b-dc91741d468c.thor

c92b9882fa54b394_076e35c0-5e29-6be8-7560-0a7a0769a453.thor

2732416773151aca_076e35c0-5e29-6be8-cdfa-683ce3572fcb.thor

f77111e5318fd177_076e35c0-5e29-6be8-2dcd-5a4ca66c16d7.thor

6ed7beb20f22672b_076e35c0-5e29-6be8-6ec2-dca6777a4712.thor

2a83074c4e915019_076e35c0-5e29-6be8-1c1c-554bafa6a298.thor

4d9b43d5be2d09cb_076e35c0-5e29-6be8-1ebc-3d57ed6f3ec6.thor

87944562e01cae7c_076e35c0-5e29-6be8-0246-ef165e94cfab.thor

c5c0fbfc5ceacd1c_076e35c0-5e29-6be8-4048-b11a0ccb8989.thor

d85e6bd623102a1d_076e35c0-5e29-6be8-997c-7d573a04d512.thor

1114134b65bc3828_076e35c0-5e29-6be8-a162-6462f3f6ae98.thor

510d8faf495614c0_076e35c0-5e29-6be8-2cfd-78681e82e6d7.thor

e7954cead0658fa8_076e35c0-5e29-6be8-ae7b-f83958bbba05.thor

432f05680c5bcb34_076e35c0-5e29-6be8-02f8-f6673cd296a8.thor

03ba487a44254dbc_076e35c0-5e29-6be8-3f2c-c61c5b4db716.thor

39ed9377b24a89af_076e35c0-5e29-6be8-e9b2-f3434ef527c7.thor

41fed67cc40eca91_076e35c0-5e29-6be8-f2da-4798132851f7.thor

5725472b541fe3d6_076e35c0-5e29-6be8-43a1-04368a571e2f.thor

981c3a4058a09d91_076e35c0-5e29-6be8-7e66-22617b1a185b.thor

41d3eb450e480629_076e35c0-5e29-6be8-44c7-e02b74f0bf03.thor

9c18b759f105e169_076e35c0-5e29-6be8-22f1-8795d631c1ef.thor

85ee4dbd46299678_076e35c0-5e29-6be8-bce7-14be0f639a8b.thor

b31db841037ebe2f_076e35c0-5e29-6be8-3688-1e4c460ad7ab.thor

369e8e5be8cafe65_076e35c0-5e29-6be8-4031-435eb3430c19.thor

a099627a6009ebf3_076e35c0-5e29-6be8-2f3e-12bd2cf4e67c.thor

e53620b44f55cd1a_076e35c0-5e29-6be8-1118-994e99228849.thor

1d9d789e0cee0aa5_076e35c0-5e29-6be8-193d-3053ae32ccea.thor

d585f408e30b723c_076e35c0-5e29-6be8-b86f-2ba2454dcfb5.thor

f16fdeea5eb9565a_076e35c0-5e29-6be8-8b82-c78f8098baa4.thor

2715cf8d7a0a991d_076e35c0-5e29-6be8-1ac1-38b5da64312b.thor

212448f593a9dc04_076e35c0-5e29-6be8-0b5c-0c3935d37b4c.thor

25d081d11bf18968_076e35c0-5e29-6be8-3fdd-7e27dc56fafe.thor

19d7e442c7233cee_076e35c0-5e29-6be8-4745-2af0665ff292.thor

eca293bc86b4bfe6_076e35c0-5e29-6be8-b7aa-f1c61a23ea2e.thor

a9af0b9abdddab3b_076e35c0-5e29-6be8-1aa7-55cd3972225b.thor

84cce16542b69ec2_076e35c0-5e29-6be8-4289-1274108538fe.thor

6f4c9724e6c5d3a4_076e35c0-5e29-6be8-4454-d32f265f756e.thor

NRV_089P9P3_.js

Network Analysis

Hosts Involved

DNS Requests

HTTP Requests

Behavior Summary

File-Read
  • C:\Users\Harry Dresden\Desktop\desktop.ini
  • C:\Windows\System32\wshom.ocx
  • C:\Windows\System32\wscript.exe
  • C:\Windows\System32\msxml3.dll
  • C:\Users\Harry Dresden\AppData\Local\Temp\NRV_089P9P3_.js
  • UNC\KIDSROOM\Users\Public\Foxit Software\Foxit Reader\StartPage\advertisement\normal Edit and reflow paragraphs in PDF files.bmp
  • UNC\KIDSROOM\Users\Harry Dresden\Desktop\jiWIzyGIufc.ppt
  • c:\Python27\Lib\test\keycert3.pem
  • c:\Python27\include\pyexpat.h
  • UNC\KIDSROOM\Users\Public\Foxit Software\Foxit Reader\StartPage\advertisement\ribbon create pdf from scanner documents.bmp
  • c:\Python27\Lib\test\https_svn_python_org_root.pem
  • c:\Python27\Lib\test\ssl_cert.pem
  • c:\Python27\include\parsetok.h
  • UNC\KIDSROOM\Users\Public\Foxit Software\Foxit Reader\StartPage\start\en_us\version.xml
  • c:\qraimbuwvp\bin\cert.p12
  • c:\Python27\include\floatobject.h
  • c:\Python27\include\Python-ast.h
  • c:\Python27\include\osdefs.h
  • UNC\KIDSROOM\Users\Public\Foxit Software\Foxit Reader\StartPage\advertisement\normal Integrate PDF into your mobile apps.bmp
  • c:\Python27\include\pymacconfig.h
  • UNC\KIDSROOM\Users\Public\Foxit Software\Foxit Reader\StartPage\start\en_us\images\classic-16.png
  • UNC\KIDSROOM\Users\Public\Foxit Software\Foxit Reader\StartPage\start\en_us\Default\body_bg.jpg
  • UNC\KIDSROOM\Users\Public\Foxit Software\Foxit Reader\StartPage\start\en_us\images\classic-16-open.png
  • c:\Python27\include\import.h
  • \\?\PIPE\browser
  • c:\Python27\include\pythonrun.h
  • c:\Python27\include\structmember.h
  • c:\Python27\Lib\site-packages\pip\_vendor\requests\cacert.pem
  • c:\Python27\include\pyarena.h
  • c:\Python27\include\pygetopt.h
  • UNC\KIDSROOM\Users\Public\Music\Sample Music\Maid with the Flaxen Hair.mp3
  • c:\6cdeacda242012e0e5b593e657\1040\eula.rtf
  • UNC\KIDSROOM\Users\Public\Foxit Software\Foxit Reader\StartPage\advertisement\ribbon Create PDF from Office-convert PDF to office.bmp
  • c:\6cdeacda242012e0e5b593e657\1043\eula.rtf
  • UNC\KIDSROOM\Users\Public\Foxit Software\Foxit Reader\StartPage\advertisement\ribbon Protect Sensitive PDF Documents.bmp
  • c:\Python27\Lib\test\selfsigned_pythontestdotnet.pem
  • UNC\KIDSROOM\Users\Harry Dresden\Downloads\big-hero-6-2.jpg
  • c:\Python27\include\rangeobject.h
  • c:\Python27\include\pgenheaders.h
  • c:\Python27\include\pythread.h
  • UNC\KIDSROOM\Users\Public\Foxit Software\Foxit Reader\StartPage\advertisement\ribbon Integrate PDF into your application.bmp
  • UNC\KIDSROOM\Users\Harry Dresden\Desktop\OaOKXfzhUqn.doc
  • UNC\KIDSROOM\Users\Public\Foxit Software\Foxit Reader\StartPage\advertisement\ribbon Powerful Word Processor.bmp
  • c:\Python27\include\patchlevel.h
  • UNC\KIDSROOM\Users\Public\Foxit Software\Foxit Reader\StartPage\start\en_us\Default\tab.png
  • c:\6cdeacda242012e0e5b593e657\2070\eula.rtf
  • UNC\KIDSROOM\Users\Public\Foxit Software\Foxit Reader\StartPage\advertisement\normal Fastest PDF Search and Index.bmp
  • UNC\KIDSROOM\Users\Public\Foxit Software\Foxit Reader\StartPage\start\en_us\Default\show_con_bg.jpg
  • c:\6cdeacda242012e0e5b593e657\1042\eula.rtf
  • c:\Python27\include\funcobject.h
  • c:\Python27\include\listobject.h
  • c:\Python27\Lib\test\keycert.pem
  • UNC\KIDSROOM\Users\Public\Foxit Software\Foxit Reader\StartPage\advertisement\Profile.xml
  • UNC\KIDSROOM\Users\Harry Dresden\Desktop\taVvuxZeAvs.pptx
  • UNC\KIDSROOM\Users\Harry Dresden\Desktop\ZKGxrSkjfT.ppt
  • c:\6cdeacda242012e0e5b593e657\1044\eula.rtf
  • c:\Python27\include\frameobject.h
  • UNC\KIDSROOM\Users\Public\Foxit Software\Foxit Reader\StartPage\start\en_us\images\buy_phantom.png
  • UNC\KIDSROOM\Users\Public\Foxit Software\Foxit Reader\StartPage\advertisement\normal Protect your PDF files with AD RMS.bmp
  • c:\Python27\include\longintrepr.h
  • c:\Python27\include\opcode.h
  • UNC\KIDSROOM\Users\Public\Pictures\Sample Pictures\Koala.jpg
  • c:\Python27\Lib\test\badcert.pem
  • UNC\KIDSROOM\Users\Public\Music\Sample Music\Sleep Away.mp3
  • c:\6cdeacda242012e0e5b593e657\1025\eula.rtf
  • c:\Python27\include\sliceobject.h
  • c:\Python27\include\pgen.h
  • c:\Python27\Lib\test\wrongcert.pem
  • UNC\KIDSROOM\Users\Public\Foxit Software\Foxit Reader\StartPage\advertisement\normal Protect Sensitive PDF Documents.bmp
  • c:\Python27\include\moduleobject.h
  • UNC\KIDSROOM\Users\Public\Pictures\Sample Pictures\Chrysanthemum.jpg
  • c:\Python27\include\objimpl.h
  • c:\Python27\include\Python.h
  • c:\6cdeacda242012e0e5b593e657\1045\eula.rtf
  • c:\Python27\include\stringobject.h
  • c:\6cdeacda242012e0e5b593e657\1053\eula.rtf
  • c:\6cdeacda242012e0e5b593e657\1041\eula.rtf
  • c:\Python27\include\pyerrors.h
  • c:\Python27\include\intobject.h
  • UNC\KIDSROOM\Users\Public\Foxit Software\Foxit Reader\StartPage\advertisement\normal Integrate PDF into your application.bmp
  • UNC\KIDSROOM\Users\Harry Dresden\Desktop\nABioNnaBFJ.pptx
  • c:\Python27\include\pystate.h
  • c:\Python27\Lib\test\ssl_key.pem
  • c:\Python27\Lib\test\keycert.passwd.pem
  • UNC\KIDSROOM\Users\Public\Foxit Software\Foxit Reader\StartPage\advertisement\ribbon Fastest PDF Search and Index.bmp
  • c:\Python27\include\iterobject.h
  • c:\Python27\include\methodobject.h
  • UNC\KIDSROOM\Users\Public\Foxit Software\Foxit Reader\StartPage\advertisement\ribbon Edit and reflow paragraphs in PDF files.bmp
  • UNC\KIDSROOM\Users\Harry Dresden\Desktop\gDGKKpFAukuvGcz.txt
  • c:\Python27\include\object.h
  • c:\Python27\include\grammar.h
  • c:\Python27\include\pyconfig.h
  • UNC\KIDSROOM\Users\Public\Foxit Software\Foxit Reader\StartPage\advertisement\ProfileRibbon.xml
  • c:\Python27\include\structseq.h
  • c:\6cdeacda242012e0e5b593e657\1036\eula.rtf
  • \\?\PIPE\wkssvc
  • c:\Python27\include\pymath.h
  • UNC\KIDSROOM\Users\Harry Dresden\Desktop\OOGPUyjympUre.ppt
  • c:\6cdeacda242012e0e5b593e657\1038\eula.rtf
  • c:\Python27\include\node.h
  • UNC\KIDSROOM\Users\Public\Foxit Software\Foxit Reader\StartPage\start\en_us\tpl\history.txt
  • UNC\KIDSROOM\Users\Public\Pictures\Sample Pictures\Jellyfish.jpg
  • UNC\KIDSROOM\Users\Public\Foxit Software\Foxit Reader\StartPage\start\en_us\images\ribbon-16-open.png
  • UNC\KIDSROOM\Users\Harry Dresden\Desktop\pJEijfEAkF.docm
  • c:\6cdeacda242012e0e5b593e657\2052\eula.rtf
  • c:\Python27\Lib\test\ssl_key.passwd.pem
  • c:\Python27\Lib\test\keycert2.pem
  • c:\Python27\include\py_curses.h
  • c:\Python27\Lib\test\keycert4.pem
  • c:\Python27\include\pyport.h
  • c:\Python27\include\graminit.h
  • c:\6cdeacda242012e0e5b593e657\1037\eula.rtf
  • c:\Python27\include\pystrcmp.h
  • c:\Python27\include\symtable.h
  • c:\Python27\include\setobject.h
  • UNC\KIDSROOM\Users\Public\Foxit Software\Foxit Reader\StartPage\start\en_us\js\nor.js
  • c:\Python27\Lib\test\pycacert.pem
  • UNC\KIDSROOM\Users\Public\Foxit Software\Foxit Reader\StartPage\advertisement\ribbon Protect your PDF files with AD RMS.bmp
  • UNC\KIDSROOM\Users\Public\Foxit Software\Foxit Reader\StartPage\advertisement\normal Design form fields easily.bmp
  • UNC\KIDSROOM\Users\Public\Foxit Software\Foxit Reader\StartPage\advertisement\normal View and annotate PDFs.bmp
  • UNC\KIDSROOM\Users\Public\Pictures\Sample Pictures\Desert.jpg
  • c:\6cdeacda242012e0e5b593e657\1046\eula.rtf
  • c:\6cdeacda242012e0e5b593e657\1049\eula.rtf
  • UNC\KIDSROOM\Users\Public\Foxit Software\Foxit Reader\StartPage\start\en_us\Default\top_tb_bg.jpg
  • UNC\KIDSROOM\Users\Public\Pictures\Sample Pictures\Tulips.jpg
  • UNC\KIDSROOM\Users\Public\Foxit Software\Foxit Reader\StartPage\advertisement\normal Enterprise PDF Reader.bmp
  • c:\6cdeacda242012e0e5b593e657\3082\eula.rtf
  • UNC\KIDSROOM\Users\Public\Foxit Software\Foxit Reader\StartPage\advertisement\normal Powerful Word Processor.bmp
  • UNC\KIDSROOM\Users\Public\Foxit Software\Foxit Reader\StartPage\start\en_us\images\blank.gif
  • UNC\KIDSROOM\Users\Public\Foxit Software\Foxit Reader\StartPage\start\en_us\Default\line.jpg
  • c:\Python27\include\pystrtod.h
  • c:\Python27\include\longobject.h
  • UNC\KIDSROOM\Users\Public\Pictures\Sample Pictures\Penguins.jpg
  • UNC\KIDSROOM\Users\Public\Foxit Software\Foxit Reader\StartPage\advertisement\ribbon Enterprise PDF Reader.bmp
  • c:\Python27\Lib\test\badkey.pem
  • UNC\KIDSROOM\Users\Harry Dresden\Downloads\cleandesktop.py.txt
  • UNC\KIDSROOM\Users\Harry Dresden\Desktop\vpTbGEKRhU.txt
  • c:\Python27\include\pyctype.h
  • UNC\KIDSROOM\Users\Public\Foxit Software\Foxit Reader\StartPage\start\en_us\images\ribbon-16.png
  • UNC\KIDSROOM\Users\Public\Foxit Software\Foxit Reader\StartPage\start\en_us\images\phantomPDF_s.png
  • UNC\KIDSROOM\Users\Public\Foxit Software\Foxit Reader\StartPage\advertisement\ribbon Integrate PDF into your mobile apps.bmp
  • c:\Python27\include\pymactoolbox.h
  • UNC\KIDSROOM\Users\Public\Pictures\Sample Pictures\Lighthouse.jpg
  • UNC\KIDSROOM\Users\Public\Foxit Software\Foxit Reader\StartPage\advertisement\ribbon View PDFs on mobile devices.bmp
  • c:\Python27\Lib\test\nokia.pem
  • UNC\KIDSROOM\Users\Public\Foxit Software\Foxit Reader\StartPage\start\en_us\images\phantomPDF_b.png
  • UNC\KIDSROOM\Users\Public\Foxit Software\Foxit Reader\StartPage\start\en_us\Default\right_move_bg.jpg
  • c:\Python27\include\intrcheck.h
  • c:\Python27\include\pydebug.h
  • \\?\PIPE\lsarpc
  • UNC\KIDSROOM\Users\Public\Foxit Software\Foxit Reader\StartPage\start\en_us\Default\right_over_bg.jpg
  • c:\Python27\Lib\test\nullbytecert.pem
  • c:\Python27\include\pymem.h
  • c:\Python27\Lib\test\dh1024.pem
  • c:\6cdeacda242012e0e5b593e657\1055\eula.rtf
  • UNC\KIDSROOM\Users\Public\Foxit Software\Foxit Reader\StartPage\advertisement\normal View PDFs on mobile devices.bmp
  • UNC\KIDSROOM\Users\Public\Foxit Software\Foxit Reader\StartPage\start\en_us\Default\history_winbg.jpg
  • c:\Python27\Lib\test\sha256.pem
  • UNC\KIDSROOM\Users\Public\Foxit Software\Foxit Reader\StartPage\advertisement\ribbon View and annotate PDFs.bmp
  • UNC\KIDSROOM\Users\Public\Foxit Software\Foxit Reader\StartPage\start\en_us\Default\content_showbg.jpg
  • UNC\KIDSROOM\Users\Public\Foxit Software\Foxit Reader\StartPage\advertisement\normal Create PDF from Office-convert PDF to office.bmp
  • c:\Python27\include\pycapsule.h
  • UNC\KIDSROOM\Users\Public\Music\Sample Music\Kalimba.mp3
  • UNC\KIDSROOM\Users\Harry Dresden\Desktop\xoLqqScSdkaZfOj.ppt
  • UNC\KIDSROOM\Users\Public\Foxit Software\Foxit Reader\StartPage\advertisement\ribbon Design form fields easily.bmp
  • UNC\KIDSROOM\Users\Public\Pictures\Sample Pictures\Hydrangeas.jpg
  • UNC\KIDSROOM\Users\Public\Foxit Software\Foxit Reader\StartPage\start\en_us\js\DD_belatedPNG.js
  • UNC\KIDSROOM\Users\Public\Foxit Software\Foxit Reader\StartPage\advertisement\normal create pdf from scanner documents.bmp
  • c:\Python27\include\pyfpe.h
  • c:\Python27\include\genobject.h
File-Written
  • C:\Users\Harry Dresden\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\YLC2QM2Y\gnjeebt[1].txt
  • C:\Users\Harry Dresden\AppData\Local\Temp\n9Bbiqe8b.dll
  • c:\6cdeacda242012e0e5b593e657\1044\_11_WHAT_is.html
  • UNC\KIDSROOM\Users\Public\Foxit Software\Foxit Reader\StartPage\advertisement\normal Edit and reflow paragraphs in PDF files.bmp
  • c:\Python27\include\object.h
  • c:\6cdeacda242012e0e5b593e657\1042\_9_WHAT_is.html
  • UNC\KIDSROOM\Users\Harry Dresden\Desktop\jiWIzyGIufc.ppt
  • c:\Python27\Lib\test\keycert3.pem
  • c:\Python27\include\pyexpat.h
  • UNC\KIDSROOM\Users\Public\Foxit Software\Foxit Reader\StartPage\advertisement\ribbon create pdf from scanner documents.bmp
  • c:\Python27\Lib\test\https_svn_python_org_root.pem
  • c:\Python27\Lib\test\ssl_cert.pem
  • c:\Python27\include\parsetok.h
  • c:\Python27\Lib\test\nullcert.pem
  • UNC\KIDSROOM\Users\Public\Foxit Software\Foxit Reader\StartPage\start\en_us\version.xml
  • c:\qraimbuwvp\bin\cert.p12
  • c:\Python27\include\floatobject.h
  • c:\Python27\include\Python-ast.h
  • c:\6cdeacda242012e0e5b593e657\1049\_14_WHAT_is.html
  • UNC\KIDSROOM\Users\Public\Foxit Software\Foxit Reader\StartPage\advertisement\normal Integrate PDF into your mobile apps.bmp
  • c:\6cdeacda242012e0e5b593e657\1053\_15_WHAT_is.html
  • c:\Python27\include\pymacconfig.h
  • UNC\KIDSROOM\Users\Public\Foxit Software\Foxit Reader\StartPage\start\en_us\images\classic-16.png
  • UNC\KIDSROOM\Users\Public\Foxit Software\Foxit Reader\StartPage\start\en_us\Default\body_bg.jpg
  • UNC\KIDSROOM\Users\Public\Foxit Software\Foxit Reader\StartPage\start\en_us\images\classic-16-open.png
  • c:\Python27\include\import.h
  • \\?\PIPE\browser
  • c:\Python27\include\pythonrun.h
  • c:\Python27\include\structmember.h
  • c:\Python27\Lib\site-packages\pip\_vendor\requests\cacert.pem
  • c:\Python27\include\pyarena.h
  • c:\Python27\include\pygetopt.h
  • UNC\KIDSROOM\Users\Public\Music\Sample Music\Maid with the Flaxen Hair.mp3
  • c:\6cdeacda242012e0e5b593e657\1040\eula.rtf
  • UNC\KIDSROOM\Users\Public\Foxit Software\Foxit Reader\StartPage\advertisement\ribbon Create PDF from Office-convert PDF to office.bmp
  • c:\6cdeacda242012e0e5b593e657\1043\eula.rtf
  • UNC\KIDSROOM\Users\Public\Foxit Software\Foxit Reader\StartPage\advertisement\ribbon Protect Sensitive PDF Documents.bmp
  • c:\6cdeacda242012e0e5b593e657\2052\_17_WHAT_is.html
  • c:\Python27\Lib\test\selfsigned_pythontestdotnet.pem
  • UNC\KIDSROOM\Users\Harry Dresden\Downloads\big-hero-6-2.jpg
  • c:\6cdeacda242012e0e5b593e657\1036\_4_WHAT_is.html
  • c:\Python27\include\rangeobject.h
  • c:\Python27\include\pgenheaders.h
  • c:\Python27\include\pythread.h
  • UNC\KIDSROOM\Users\Public\Foxit Software\Foxit Reader\StartPage\advertisement\ribbon Integrate PDF into your application.bmp
  • UNC\KIDSROOM\Users\Harry Dresden\Desktop\OaOKXfzhUqn.doc
  • UNC\KIDSROOM\Users\Public\Foxit Software\Foxit Reader\StartPage\advertisement\ribbon Powerful Word Processor.bmp
  • c:\Python27\include\patchlevel.h
  • UNC\KIDSROOM\Users\Public\Foxit Software\Foxit Reader\StartPage\start\en_us\Default\tab.png
  • c:\6cdeacda242012e0e5b593e657\1049\eula.rtf
  • UNC\KIDSROOM\Users\Public\Music\Sample Music\_9_WHAT_is.html
  • UNC\KIDSROOM\Users\Public\Foxit Software\Foxit Reader\StartPage\advertisement\normal Fastest PDF Search and Index.bmp
  • UNC\KIDSROOM\Users\Public\Foxit Software\Foxit Reader\StartPage\start\en_us\Default\show_con_bg.jpg
  • c:\6cdeacda242012e0e5b593e657\1042\eula.rtf
  • UNC\KIDSROOM\Users\Public\Foxit Software\Foxit Reader\StartPage\start\en_us\images\buy_phantom.png
  • c:\Python27\include\funcobject.h
  • c:\Python27\include\listobject.h
  • c:\Python27\Lib\test\keycert.pem
  • UNC\KIDSROOM\Users\Public\Foxit Software\Foxit Reader\StartPage\start\en_us\_5_WHAT_is.html
  • UNC\KIDSROOM\Users\Public\Foxit Software\Foxit Reader\StartPage\advertisement\Profile.xml
  • UNC\KIDSROOM\Users\Harry Dresden\Desktop\taVvuxZeAvs.pptx
  • UNC\KIDSROOM\Users\Harry Dresden\Desktop\ZKGxrSkjfT.ppt
  • c:\6cdeacda242012e0e5b593e657\1044\eula.rtf
  • c:\6cdeacda242012e0e5b593e657\1046\_13_WHAT_is.html
  • c:\6cdeacda242012e0e5b593e657\1038\_6_WHAT_is.html
  • c:\Python27\include\frameobject.h
  • c:\Python27\Lib\test\_0_WHAT_is.html
  • UNC\KIDSROOM\Users\Public\Foxit Software\Foxit Reader\StartPage\advertisement\normal Protect your PDF files with AD RMS.bmp
  • c:\Python27\include\longintrepr.h
  • c:\6cdeacda242012e0e5b593e657\2070\_18_WHAT_is.html
  • c:\Python27\include\opcode.h
  • UNC\KIDSROOM\Users\Public\Pictures\Sample Pictures\Koala.jpg
  • c:\Python27\Lib\site-packages\pip\_vendor\requests\_1_WHAT_is.html
  • c:\Python27\Lib\test\badcert.pem
  • UNC\KIDSROOM\Users\Public\Music\Sample Music\Sleep Away.mp3
  • UNC\KIDSROOM\Users\Harry Dresden\Downloads\_2_WHAT_is.html
  • c:\6cdeacda242012e0e5b593e657\1025\eula.rtf
  • c:\Python27\include\sliceobject.h
  • c:\Python27\include\pgen.h
  • c:\Python27\Lib\test\wrongcert.pem
  • UNC\KIDSROOM\Users\Public\Foxit Software\Foxit Reader\StartPage\advertisement\normal Protect Sensitive PDF Documents.bmp
  • c:\Python27\include\moduleobject.h
  • UNC\KIDSROOM\Users\Public\Pictures\Sample Pictures\Chrysanthemum.jpg
  • c:\Python27\include\objimpl.h
  • c:\Python27\include\Python.h
  • c:\6cdeacda242012e0e5b593e657\1045\eula.rtf
  • c:\Python27\include\osdefs.h
  • c:\Python27\include\stringobject.h
  • c:\6cdeacda242012e0e5b593e657\1053\eula.rtf
  • c:\6cdeacda242012e0e5b593e657\1041\eula.rtf
  • c:\Python27\include\pyerrors.h
  • c:\qraimbuwvp\bin\_2_WHAT_is.html
  • UNC\KIDSROOM\Users\Public\Foxit Software\Foxit Reader\StartPage\start\en_us\Default\_6_WHAT_is.html
  • c:\6cdeacda242012e0e5b593e657\3082\_19_WHAT_is.html
  • c:\6cdeacda242012e0e5b593e657\2070\eula.rtf
  • UNC\KIDSROOM\Users\Public\Foxit Software\Foxit Reader\StartPage\advertisement\normal Integrate PDF into your application.bmp
  • UNC\KIDSROOM\Users\Harry Dresden\Desktop\nABioNnaBFJ.pptx
  • c:\Python27\include\pystate.h
  • c:\Python27\Lib\test\ssl_key.pem
  • c:\Python27\Lib\test\keycert.passwd.pem
  • UNC\KIDSROOM\Users\Public\Foxit Software\Foxit Reader\StartPage\advertisement\ribbon Fastest PDF Search and Index.bmp
  • c:\Python27\include\iterobject.h
  • c:\Python27\include\methodobject.h
  • UNC\KIDSROOM\Users\Public\Foxit Software\Foxit Reader\StartPage\advertisement\ribbon Edit and reflow paragraphs in PDF files.bmp
  • UNC\KIDSROOM\Users\Harry Dresden\Desktop\gDGKKpFAukuvGcz.txt
  • UNC\KIDSROOM\Users\Harry Dresden\Desktop\_0_WHAT_is.html
  • c:\Python27\include\grammar.h
  • c:\Python27\include\pyconfig.h
  • UNC\KIDSROOM\Users\Public\Foxit Software\Foxit Reader\StartPage\advertisement\ProfileRibbon.xml
  • c:\Python27\include\structseq.h
  • c:\6cdeacda242012e0e5b593e657\1036\eula.rtf
  • \\?\PIPE\wkssvc
  • c:\Python27\include\pymath.h
  • UNC\KIDSROOM\Users\Harry Dresden\Desktop\OOGPUyjympUre.ppt
  • c:\6cdeacda242012e0e5b593e657\1038\eula.rtf
  • c:\Python27\include\node.h
  • UNC\KIDSROOM\Users\Public\Foxit Software\Foxit Reader\StartPage\start\en_us\tpl\history.txt
  • UNC\KIDSROOM\Users\Public\Pictures\Sample Pictures\Jellyfish.jpg
  • UNC\KIDSROOM\Users\Public\Foxit Software\Foxit Reader\StartPage\start\en_us\images\ribbon-16-open.png
  • UNC\KIDSROOM\Users\Harry Dresden\Desktop\pJEijfEAkF.docm
  • c:\6cdeacda242012e0e5b593e657\2052\eula.rtf
  • UNC\KIDSROOM\Users\Public\Foxit Software\Foxit Reader\StartPage\advertisement\_3_WHAT_is.html
  • c:\Python27\Lib\test\ssl_key.passwd.pem
  • c:\Python27\Lib\test\keycert2.pem
  • c:\Python27\include\py_curses.h
  • c:\Python27\Lib\test\keycert4.pem
  • c:\6cdeacda242012e0e5b593e657\1043\_10_WHAT_is.html
  • c:\Python27\include\graminit.h
  • c:\Python27\include\pyport.h
  • c:\6cdeacda242012e0e5b593e657\1037\eula.rtf
  • c:\Python27\include\pystrcmp.h
  • c:\Python27\include\symtable.h
  • c:\Python27\include\setobject.h
  • UNC\KIDSROOM\Users\Public\Foxit Software\Foxit Reader\StartPage\start\en_us\js\nor.js
  • c:\Python27\Lib\test\pycacert.pem
  • UNC\KIDSROOM\Users\Public\Foxit Software\Foxit Reader\StartPage\advertisement\ribbon Protect your PDF files with AD RMS.bmp
  • UNC\KIDSROOM\Users\Public\Foxit Software\Foxit Reader\StartPage\advertisement\normal Design form fields easily.bmp
  • UNC\KIDSROOM\Users\Public\Foxit Software\Foxit Reader\StartPage\advertisement\normal View and annotate PDFs.bmp
  • UNC\KIDSROOM\Users\Public\Pictures\Sample Pictures\Desert.jpg
  • c:\6cdeacda242012e0e5b593e657\1046\eula.rtf
  • c:\Python27\include\_3_WHAT_is.html
  • UNC\KIDSROOM\Users\Public\Foxit Software\Foxit Reader\StartPage\start\en_us\Default\top_tb_bg.jpg
  • UNC\KIDSROOM\Users\Public\Pictures\Sample Pictures\Tulips.jpg
  • UNC\KIDSROOM\Users\Public\Foxit Software\Foxit Reader\StartPage\advertisement\normal Enterprise PDF Reader.bmp
  • c:\6cdeacda242012e0e5b593e657\3082\eula.rtf
  • UNC\KIDSROOM\Users\Public\Foxit Software\Foxit Reader\StartPage\advertisement\normal Powerful Word Processor.bmp
  • UNC\KIDSROOM\Users\Public\Foxit Software\Foxit Reader\StartPage\start\en_us\images\blank.gif
  • UNC\KIDSROOM\Users\Public\Foxit Software\Foxit Reader\StartPage\start\en_us\Default\line.jpg
  • c:\Python27\include\pystrtod.h
  • c:\Python27\include\longobject.h
  • c:\6cdeacda242012e0e5b593e657\1037\_5_WHAT_is.html
  • c:\6cdeacda242012e0e5b593e657\1045\_12_WHAT_is.html
  • UNC\KIDSROOM\Users\Public\Foxit Software\Foxit Reader\StartPage\start\en_us\images\_8_WHAT_is.html
  • UNC\KIDSROOM\Users\Public\Pictures\Sample Pictures\Penguins.jpg
  • UNC\KIDSROOM\Users\Public\Foxit Software\Foxit Reader\StartPage\advertisement\ribbon Enterprise PDF Reader.bmp
  • c:\Python27\Lib\test\badkey.pem
  • c:\Python27\include\intobject.h
  • UNC\KIDSROOM\Users\Harry Dresden\Downloads\cleandesktop.py.txt
  • UNC\KIDSROOM\Users\Harry Dresden\Desktop\vpTbGEKRhU.txt
  • c:\Python27\include\pyctype.h
  • UNC\KIDSROOM\Users\Public\Foxit Software\Foxit Reader\StartPage\start\en_us\images\ribbon-16.png
  • UNC\KIDSROOM\Users\Public\Foxit Software\Foxit Reader\StartPage\start\en_us\images\phantomPDF_s.png
  • UNC\KIDSROOM\Users\Public\Foxit Software\Foxit Reader\StartPage\advertisement\ribbon Integrate PDF into your mobile apps.bmp
  • c:\6cdeacda242012e0e5b593e657\1055\_16_WHAT_is.html
  • UNC\KIDSROOM\Users\Public\Pictures\Sample Pictures\Lighthouse.jpg
  • UNC\KIDSROOM\Users\Public\Foxit Software\Foxit Reader\StartPage\advertisement\ribbon View PDFs on mobile devices.bmp
  • c:\Python27\Lib\test\nokia.pem
  • UNC\KIDSROOM\Users\Public\Foxit Software\Foxit Reader\StartPage\start\en_us\images\phantomPDF_b.png
  • UNC\KIDSROOM\Users\Public\Foxit Software\Foxit Reader\StartPage\start\en_us\Default\right_move_bg.jpg
  • c:\Python27\include\intrcheck.h
  • c:\Python27\include\pydebug.h
  • UNC\KIDSROOM\Users\Public\Pictures\Sample Pictures\_7_WHAT_is.html
  • \\?\PIPE\lsarpc
  • UNC\KIDSROOM\Users\Public\Foxit Software\Foxit Reader\StartPage\start\en_us\Default\right_over_bg.jpg
  • c:\Python27\Lib\test\nullbytecert.pem
  • c:\Python27\include\pymem.h
  • c:\Python27\Lib\test\dh1024.pem
  • c:\Python27\include\pymactoolbox.h
  • c:\6cdeacda242012e0e5b593e657\1055\eula.rtf
  • c:\6cdeacda242012e0e5b593e657\1041\_8_WHAT_is.html
  • UNC\KIDSROOM\Users\Public\Foxit Software\Foxit Reader\StartPage\advertisement\normal View PDFs on mobile devices.bmp
  • UNC\KIDSROOM\Users\Public\Foxit Software\Foxit Reader\StartPage\start\en_us\Default\history_winbg.jpg
  • c:\Python27\Lib\test\sha256.pem
  • UNC\KIDSROOM\Users\Public\Foxit Software\Foxit Reader\StartPage\advertisement\ribbon View and annotate PDFs.bmp
  • UNC\KIDSROOM\Users\Public\Foxit Software\Foxit Reader\StartPage\start\en_us\Default\content_showbg.jpg
  • UNC\KIDSROOM\Users\Public\Foxit Software\Foxit Reader\StartPage\advertisement\normal Create PDF from Office-convert PDF to office.bmp
  • c:\Python27\include\pycapsule.h
  • UNC\KIDSROOM\Users\Public\Foxit Software\Foxit Reader\StartPage\start\en_us\tpl\_4_WHAT_is.html
  • UNC\KIDSROOM\Users\Public\Music\Sample Music\Kalimba.mp3
  • UNC\KIDSROOM\Users\Harry Dresden\Desktop\xoLqqScSdkaZfOj.ppt
  • UNC\KIDSROOM\Users\Public\Foxit Software\Foxit Reader\StartPage\advertisement\ribbon Design form fields easily.bmp
  • UNC\KIDSROOM\Users\Public\Foxit Software\Foxit Reader\StartPage\start\en_us\js\_1_WHAT_is.html
  • UNC\KIDSROOM\Users\Public\Pictures\Sample Pictures\Hydrangeas.jpg
  • UNC\KIDSROOM\Users\Public\Foxit Software\Foxit Reader\StartPage\start\en_us\js\DD_belatedPNG.js
  • c:\6cdeacda242012e0e5b593e657\1040\_7_WHAT_is.html
  • UNC\KIDSROOM\Users\Public\Foxit Software\Foxit Reader\StartPage\advertisement\normal create pdf from scanner documents.bmp
  • c:\Python27\include\pyfpe.h
  • c:\Python27\include\genobject.h
File-Opened
  • C:\Windows\System32\wshqos.dll
  • C:\Windows\System32\wshom.ocx
  • C:\
  • C:\Windows\Globalization\Sorting\sortdefault.nls
  • C:\Users\
  • C:\Users\Harry Dresden\
  • C:\Users\Harry Dresden\AppData\
  • C:\Users\Harry Dresden\AppData\Local\
  • C:\Windows\
  • C:\Users\Harry Dresden\AppData\Local\Microsoft\Windows\Caches\cversions.1.db
  • C:\Windows\System32\en-US\wshqos.dll.mui
  • C:\Users\Harry Dresden\Desktop\desktop.ini
  • C:\Windows\System32\en-US\wshtcpip.dll.mui
  • C:\Windows\SysWOW64\rundll32.exe
  • C:\Windows\System32\rsaenh.dll
  • C:\Windows\System32\msxml3.dll
  • C:\Windows\System32\en-US\wship6.dll.mui
  • C:\Windows\System32\wscript.exe
  • C:\Users\Harry Dresden\AppData\Local\Microsoft\Windows\Caches\{AFBF9F1A-8EE8-4C77-AF34-C647E37CA0D9}.1.ver0x0000000000000001.db
  • C:\Windows\SysWOW64\
  • C:\Users\Harry Dresden\AppData\Local\Temp\NRV_089P9P3_.js
  • c:\Python27\include\frameobject.h
  • UNC\KIDSROOM\Users\Public\Foxit Software\Foxit Reader\StartPage\advertisement\normal Edit and reflow paragraphs in PDF files.bmp
  • c:\Python27\Lib\ctypes
  • c:\Users\Default\Links
  • c:\ProgramData\Microsoft\Windows NT\MSFax\Common Coverpages
  • c:\Python27\Lib\site-packages\pip\_vendor\colorama
  • c:\ProgramData\Microsoft\Windows Defender\Scans\CleanStore\Resources
  • c:\Python27\DLLs
  • c:\Python27\Lib\site-packages\pip\_vendor\cachecontrol
  • c:\ProgramData\Microsoft\Event Viewer\Views\ApplicationViewsRootNode
  • c:\ProgramData\Adobe\Setup
  • UNC\KIDSROOM\Users\Default\Documents
  • UNC\KIDSROOM\Users\Public\Foxit Software\Foxit Reader\StartPage\advertisement\normal Integrate PDF into your mobile apps.bmp
  • c:\ProgramData\Microsoft\Assistance\Client\1.0\en-US
  • UNC\KIDSROOM\Users\Public\Foxit Software\Foxit Reader\StartPage\start\en_us\images\classic-16.png
  • c:\Python27\Lib\site-packages\pip\_vendor\requests\packages\urllib3\packages
  • UNC\KIDSROOM\Users\Public\Foxit Software\Foxit Reader\StartPage\start\en_us\js
  • c:\Users\Harry Dresden\OneDrive
  • c:\Python27\include\grammar.h
  • c:\ProgramData\Microsoft\PlayReady\Cache\S-1-5-21-3416602863-1947377224-293699093-1001
  • c:\Python27\include\import.h
  • c:\Users\Public\Libraries
  • \\?\PIPE\browser
  • c:\Python27\Lib\test\tracedmodules
  • c:\Python27\tcl\tcl8.5\tzdata\Indian
  • c:\Users\Public
  • UNC\KIDSROOM\Users\Public\Foxit Software\Foxit Reader\StartPage\advertisement\ribbon Create PDF from Office-convert PDF to office.bmp
  • c:\6cdeacda242012e0e5b593e657\1043\eula.rtf
  • c:\ProgramData\Microsoft\Windows NT\MSFax\Queue
  • c:\Users\Public\Foxit Software\Foxit Reader\StartPage\start\en_us\tpl
  • c:\ProgramData\Microsoft\Windows Defender\Scans\History\Results\Resource
  • c:\Python27\Lib
  • \??\VBoxMiniRdrDN
  • c:\ProgramData
  • c:\ProgramData\Microsoft\Device Stage\Device\{8702d817-5aad-4674-9ef3-4d3decd87120}
  • c:\Python27\Lib\site-packages\pip
  • UNC\KIDSROOM\Users\Harry Dresden\Desktop\OaOKXfzhUqn.doc
  • c:\ProgramData\Microsoft\Windows Defender\Scans\CleanStore\Resources\A5
  • c:\ProgramData\Microsoft\Windows Defender\Scans\CleanStore\Resources\A6
  • c:\Python27\Lib\ctypes\macholib
  • UNC\KIDSROOM\Users\Public\Foxit Software\Foxit Reader\StartPage\start\en_us\Default\show_con_bg.jpg
  • c:\ProgramData\Adobe\Acrobat\11.0\Replicate\Security
  • c:\6cdeacda242012e0e5b593e657\1042\eula.rtf
  • c:\inetpub\history\CFGHISTORY_0000000004\schema
  • c:\Python27\Lib\unittest\test
  • c:\ProgramData\Microsoft\PlayReady
  • c:\Python27\Lib\xml\dom
  • UNC\KIDSROOM\Users\Public\Foxit Software\Foxit Reader\StartPage\advertisement\Profile.xml
  • c:\Python27\Lib\site-packages\pip\models
  • UNC\KIDSROOM\Users\Public\Foxit Software\Foxit Reader\StartPage\advertisement\ribbon create pdf from scanner documents.bmp
  • c:\ProgramData\Adobe\Acrobat\11.0\Replicate
  • UNC\KIDSROOM\Users\Harry Dresden\Desktop\taVvuxZeAvs.pptx
  • c:\Python27\tcl\tcl8\8.4
  • c:\ProgramData\Microsoft\ClickToRun\MachineData\Catalog
  • c:\ProgramData\Microsoft\Crypto\Keys
  • UNC\KIDSROOM\Users\Public\Videos
  • c:\Python27\Lib\test
  • UNC\KIDSROOM\Users\Public\Videos\Sample Videos
  • c:\inetpub\wwwroot\aspnet_client\system_web\4_0_30319
  • c:\Python27\Lib\ctypes\test
  • c:\Users\Harry Dresden\Searches
  • c:\Python27\Lib\test\badcert.pem
  • c:\qraimbuwvp\lib\api
  • c:\Python27\Lib\ensurepip
  • c:\Python27\include\pgen.h
  • UNC\KIDSROOM\Users\Public\Pictures\Sample Pictures\Chrysanthemum.jpg
  • UNC\KIDSROOM\Users\Public\Foxit Software\Foxit Reader\StartPage\start\en_us\tpl
  • c:\Python27\Lib\test\wrongcert.pem
  • c:\Users\Harry Dresden\Downloads
  • c:\Python27\include\objimpl.h
  • UNC\KIDSROOM\Users\Public\Foxit Software\Foxit Reader\StartPage\advertisement\ribbon Enterprise PDF Reader.bmp
  • c:\ProgramData\Microsoft\eHome
  • c:\Python27\tcl\tk8.5\demos\images
  • c:\Python27\Lib\test\cjkencodings
  • c:\inetpub\wwwroot\aspnet_client\system_web
  • c:\Python27\tcl\tcl8.5\tzdata\America\Kentucky
  • c:\ProgramData\Microsoft\Device Stage\Task\{07deb856-fc6e-4fb9-8add-d8f2cf8722c9}\en-US
  • c:\Python27\include\moduleobject.h
  • c:\Python27\Lib\test\keycert.passwd.pem
  • UNC\KIDSROOM\Users\Harry Dresden\Desktop\gDGKKpFAukuvGcz.txt
  • c:\Python27\include\object.h
  • c:\Python27\tcl\tix8.4.3
  • c:\6cdeacda242012e0e5b593e657\1036\eula.rtf
  • c:\ProgramData\Microsoft\Network\Downloader
  • c:\Python27\include\Python-ast.h
  • c:\inetpub\history\CFGHISTORY_0000000005
  • c:\inetpub\history\CFGHISTORY_0000000004
  • c:\inetpub\history\CFGHISTORY_0000000001
  • c:\Python27\include\pydebug.h
  • c:\inetpub\history\CFGHISTORY_0000000003
  • c:\ProgramData\Microsoft\Vault\AC658CB4-9126-49BD-B877-31EEDAB3F204
  • c:\Users\Harry Dresden\Favorites\Links for United States
  • c:\Python27\Lib\lib2to3\tests\data\fixers
  • UNC\KIDSROOM\Users\Public\Foxit Software\Foxit Reader\StartPage\start\en_us\images\ribbon-16-open.png
  • c:\Python27\tcl\tcl8.5\tzdata\US
  • c:\Python27\tcl\tcl8.5\tzdata
  • c:\Python27\include\pyport.h
  • c:\Python27\Lib\email
  • c:\Python27\tcl\tix8.4.3\demos\samples
  • c:\Python27\Lib\lib-tk\test\test_tkinter
  • c:\qraimbuwvp\lib\common
  • c:\Python27\Tools\pynche
  • UNC\KIDSROOM\Users\Public\Foxit Software\Foxit Reader\StartPage\advertisement\normal Create PDF from Office-convert PDF to office.bmp
  • c:\Python27\Tools\webchecker
  • c:\Python27\tcl\tcl8.5\tzdata\America\North_Dakota
  • c:\Python27\Lib\test\crashers
  • c:\ProgramData\Microsoft\Windows Defender\LocalCopy
  • UNC\KIDSROOM\Users\Public\Foxit Software\Foxit Reader\StartPage\start\en_us\Default\body_bg.jpg
  • c:\Users\Harry Dresden\Contacts
  • c:\ProgramData\Microsoft\Windows Defender\Scans\CleanStore\Resources\E0
  • c:\PerfLogs
  • C:\Windows\SysWOW64\en-US\VssTrace.DLL.mui
  • UNC\KIDSROOM\Users\Public\Pictures\Sample Pictures\Desert.jpg
  • c:\ProgramData\Microsoft\Windows Defender\Scans\CleanStore\Entries
  • c:\Python27\Lib\site-packages\pip\_vendor\html5lib\treebuilders
  • c:\Python27\tcl\tcl8\8.5
  • c:\6cdeacda242012e0e5b593e657\3082\eula.rtf
  • c:\Python27\libs
  • c:\ProgramData\Microsoft\ClickToRun\MachineData
  • c:\Python27\include\pyexpat.h
  • c:\Python27\include\pystrtod.h
  • c:\Python27\include\longobject.h
  • UNC\KIDSROOM\Users\Public
  • c:\ProgramData\Microsoft\Assistance
  • c:\Python27\include\pyctype.h
  • c:\ProgramData\Microsoft\Windows Defender\Scans\History\Results
  • c:\Users\Harry Dresden\Videos
  • UNC\KIDSROOM\Users\Public\Foxit Software\Foxit Reader\StartPage\advertisement\ribbon Integrate PDF into your mobile apps.bmp
  • c:\Python27\Lib\pydoc_data
  • UNC\KIDSROOM\Users\Public\Foxit Software\Foxit Reader\StartPage\start\en_us\images\phantomPDF_s.png
  • c:\Python27\Lib\test\nokia.pem
  • UNC\KIDSROOM\Users\Public\Foxit Software\Foxit Reader\StartPage\start\en_us\images\phantomPDF_b.png
  • c:\ProgramData\Microsoft\Crypto\DSS
  • c:\ProgramData\Adobe\Acrobat
  • c:\Python27\tcl\tcl8.5\tzdata\Atlantic
  • c:\ProgramData\NovaTech Network\NovaBench\3.0.2.0
  • c:\qraimbuwvp\bin\cert.p12
  • UNC\KIDSROOM\Users\Public\Foxit Software\Foxit Reader\StartPage\start\en_us\Default\right_over_bg.jpg
  • UNC\KIDSROOM\Users\Public\Music\Sample Music\Sleep Away.mp3
  • c:\ProgramData\Microsoft\Network
  • c:\ProgramData\Microsoft\Windows Defender\Scans\CleanStore\ResourceData\1A
  • c:\ProgramData\Microsoft\Diagnosis\ETLLogs\AutoLogger
  • c:\Users\Default\Downloads
  • c:\Python27\Lib\xml
  • c:\Python27\tcl\tcl8.5\tzdata\Australia
  • c:\Users\Public\Foxit Software\Foxit Reader\StartPage
  • c:\ProgramData\Microsoft\Windows Defender\Scans\CleanStore\ResourceData\17
  • UNC\KIDSROOM\Users\Public\Foxit Software\Foxit Reader\StartPage\start\en_us\Default\history_winbg.jpg
  • c:\Python27\tcl\tk8.5
  • c:\ProgramData\Microsoft\PlayReady\Cache
  • c:\6cdeacda242012e0e5b593e657\3082
  • c:\Python27\Lib\site-packages\pip\compat
  • c:\Python27\Lib\test\leakers
  • c:\Python27\tcl\tcl8\8.4\platform
  • c:\ProgramData\regid.1991-06.com.microsoft
  • c:\ProgramData\Microsoft\Windows Defender\Scans\CleanStore\Resources\70
  • UNC\KIDSROOM\Users\Public\Foxit Software\Foxit Reader\StartPage\advertisement\ribbon Design form fields easily.bmp
  • c:\ProgramData\Microsoft\Windows Defender\Scans\CleanStore\ResourceData\DD
  • c:\Python27\Tools\pynche\X
  • c:\Python27\tcl\tix8.4.3\pref
  • c:\Python27\Tools\Scripts
  • c:\ProgramData\Microsoft\Windows Defender\Scans\CleanStore\Resources\35
  • c:\ProgramData\Microsoft\Windows Defender\Scans\CleanStore
  • c:\Python27\include\pyfpe.h
  • c:\qraimbuwvp\modules\packages
  • c:\6cdeacda242012e0e5b593e657\1040\eula.rtf
  • C:\Users\Harry Dresden\AppData\Local\Temp
  • UNC\KIDSROOM\Users\Harry Dresden\Desktop\jiWIzyGIufc.ppt
  • UNC\KIDSROOM\Users\Public\Foxit Software\Foxit Reader\StartPage\start\en_us\Default\right_move_bg.jpg
  • c:\Python27\tcl\tk8.5\images
  • c:\ProgramData\Microsoft\DRM
  • c:\ProgramData\Microsoft\Windows NT\MSFax\Common Coverpages\en-US
  • c:\Python27\Lib\idlelib\idle_test
  • c:\Python27\Lib\test\https_svn_python_org_root.pem
  • c:\Python27\include
  • c:\Python27\Lib\test\nullcert.pem
  • UNC\KIDSROOM\Users\Public\Foxit Software\Foxit Reader\StartPage\start\en_us\version.xml
  • c:\6cdeacda242012e0e5b593e657\1029
  • c:\6cdeacda242012e0e5b593e657\1028
  • c:\ProgramData\Microsoft\Device Stage\Task\{e35be42d-f742-4d96-a50a-1775fb1a7a42}
  • c:\Python27\Lib\site-packages\pip\commands
  • c:\Python27\Lib\lib2to3\tests\data\fixers\myfixes
  • c:\6cdeacda242012e0e5b593e657\1025
  • c:\Users\Public\Foxit Software\Foxit Reader\StartPage\start\en_us
  • c:\Python27\Lib\email\test\data
  • c:\ProgramData\Microsoft\Windows Defender\Support
  • c:\ProgramData\WebEx\WebEx
  • c:\6cdeacda242012e0e5b593e657\2052
  • c:\Python27\tcl\tcl8.5\opt0.4
  • c:\ProgramData\Microsoft\ClickToRun\ProductReleases
  • c:\Python27\include\pgenheaders.h
  • c:\ProgramData\Microsoft\Device Stage\Task\{e35be42d-f742-4d96-a50a-1775fb1a7a42}\en-US
  • c:\Python27\tcl\tcl8.5\encoding
  • c:\ProgramData\Microsoft\Diagnosis\ETLLogs
  • c:\Python27\Lib\msilib
  • c:\ProgramData\Microsoft\WwanSvc\Profiles
  • c:\Python27\Lib\encodings
  • c:\Python27\Lib\site-packages\pip\_vendor\distlib\_backport
  • c:\ProgramData\Microsoft\Assistance\Client
  • c:\ProgramData\Microsoft\Windows Defender\Scans\CleanStore\Resources\95
  • c:\6cdeacda242012e0e5b593e657\1046\eula.rtf
  • c:\ProgramData\Microsoft\ClickToRun\ProductReleases\C0D2A2B7-8AE4-4D06-93E4-F1A7BD5FEC3F
  • c:\Python27\Lib\site-packages\_markerlib
  • UNC\KIDSROOM\Users\Harry Dresden\Desktop\ZKGxrSkjfT.ppt
  • c:\ProgramData\Microsoft\Diagnosis\LocalTraceStore
  • c:\inetpub\custerr
  • c:\Python27\include\longintrepr.h
  • c:\inetpub\custerr\en-US
  • c:\Python27\Lib\site-packages\pip\_vendor\cachecontrol\caches
  • c:\Python27\include\opcode.h
  • c:\ProgramData\Microsoft\Crypto\RSA
  • UNC\KIDSROOM\Users\Public\Foxit Software\Foxit Reader\StartPage\start\en_us
  • c:\6cdeacda242012e0e5b593e657\1025\eula.rtf
  • c:\Python27\tcl\tk8.5\ttk
  • c:\ProgramData\Microsoft\Windows Defender\Scans\CleanStore\Resources\01
  • c:\Users\Default\Favorites
  • c:\inetpub\history
  • UNC\KIDSROOM\Users\Default\Desktop
  • c:\ProgramData\Microsoft\Windows NT
  • c:\Python27\Lib\site-packages\pip\_vendor\requests\packages\chardet
  • c:\ProgramData\Microsoft\Vault
  • c:\ProgramData\Microsoft\Windows Defender\Scans\CleanStore\ResourceData
  • UNC\KIDSROOM\Users\ruiner
  • UNC\KIDSROOM\Users\Public\Foxit Software\Foxit Reader\StartPage\start\en_us\Default\tab.png
  • c:\6cdeacda242012e0e5b593e657\1045\eula.rtf
  • c:\
  • c:\Python27\Lib\site-packages\pip\_vendor\requests\packages
  • UNC\KIDSROOM\Users\Public\Pictures\Sample Pictures\Lighthouse.jpg
  • c:\Python27\tcl\tk8.5\demos
  • c:\ProgramData\Mozilla\logs
  • c:\Python27\include\pycapsule.h
  • UNC\KIDSROOM\Users\Harry Dresden\Desktop\xoLqqScSdkaZfOj.ppt
  • c:\Python27\tcl\tcl8.5\tzdata\Mexico
  • c:\Python27\Lib\importlib
  • c:\ProgramData\Microsoft\Crypto
  • UNC\KIDSROOM\Users\Harry Dresden\Searches
  • c:\ProgramData\NovaTech Network\NovaBench\3.0.2.0\media
  • c:\Python27\tcl\tcl8.5
  • c:\Python27\tcl\tcl8.5\tzdata\Africa
  • UNC\KIDSROOM\Users\Harry Dresden\Music
  • c:\ProgramData\McAfee
  • UNC\KIDSROOM\Users\Public\Foxit Software\Foxit Reader\StartPage\start\en_us\tpl\history.txt
  • c:\Python27\Lib\site-packages\pip\vcs
  • c:\Python27\Lib\bsddb\test
  • c:\6cdeacda242012e0e5b593e657\2052\eula.rtf
  • c:\Python27\Lib\test\keycert2.pem
  • c:\ProgramData\Microsoft\Search\Data\Applications
  • c:\ProgramData\Microsoft\Windows Defender\Scans\CleanStore\Resources\F7
  • c:\Python27\include\py_curses.h
  • c:\ProgramData\Microsoft\Windows Defender\Scans\CleanStore\Resources\F3
  • c:\Python27\Lib\xml\parsers
  • UNC\KIDSROOM\Users\Public\Foxit Software\Foxit Reader
  • c:\Python27\Lib\test\keycert4.pem
  • c:\Python27\tcl\tcl8.5\msgs
  • c:\ProgramData\Microsoft\Windows NT\MSFax\Inbox
  • UNC\KIDSROOM\Users\Public\Foxit Software\Foxit Reader\StartPage
  • c:\Users\Harry Dresden
  • c:\Python27\include\symtable.h
  • c:\Python27\include\node.h
  • c:\ProgramData\McAfee\MCLOGS\Common\jxpiinstall
  • UNC\KIDSROOM\Users\Harry Dresden\Downloads
  • c:\ProgramData\Microsoft\Windows Defender\Quarantine
  • c:\Users\Public\Favorites
  • c:\Python27\Lib\site-packages\pkg_resources\_vendor
  • UNC\KIDSROOM\Users\Public\Foxit Software\Foxit Reader\StartPage\advertisement\normal View and annotate PDFs.bmp
  • c:\ProgramData\Microsoft\Office
  • c:\Python27\Lib\site-packages\pip\_vendor\requests
  • c:\Users\Public\Pictures
  • c:\ProgramData\NovaTech Network\NovaBench
  • UNC\KIDSROOM\Users\Harry Dresden\Documents
  • UNC\KIDSROOM\Users\Public\Foxit Software\Foxit Reader\StartPage\start\en_us\Default\top_tb_bg.jpg
  • c:\Python27\Lib\site-packages\pip\_vendor\_markerlib
  • c:\Python27\tcl\reg1.2
  • UNC\KIDSROOM\Users\Public\Desktop
  • c:\Users\ruiner
  • c:\Python27\Lib\xml\etree
  • c:\Python27\include\pymacconfig.h
  • UNC\KIDSROOM\Users\Public\Foxit Software\Foxit Reader\StartPage\start\en_us\images\blank.gif
  • UNC\KIDSROOM\Users\Public\Foxit Software\Foxit Reader\StartPage\start\en_us\Default\line.jpg
  • c:\ProgramData\Microsoft\Windows Defender\Scans\CleanStore\ResourceData\01
  • UNC\KIDSROOM\Users\Harry Dresden\Favorites\Links for United States
  • UNC\KIDSROOM\Users\Public\Foxit Software\Foxit Reader\StartPage\advertisement\normal create pdf from scanner documents.bmp
  • c:\ProgramData\Microsoft\ClickToRun\MachineData\Catalog\Packages
  • UNC\KIDSROOM\Users\Harry Dresden\Desktop\vpTbGEKRhU.txt
  • UNC\KIDSROOM\Users\Public\Foxit Software\Foxit Reader\StartPage\start\en_us\images\ribbon-16.png
  • c:\Python27\Lib\site-packages\pip\_vendor\requests\packages\urllib3\util
  • c:\ProgramData\Microsoft\OfficeSoftwareProtectionPlatform
  • c:\Python27\tcl\tcl8.5\tzdata\Antarctica
  • c:\Python27\Lib\xml\sax
  • c:\Python27\Lib\site-packages\pip\_vendor\html5lib\trie
  • c:\Users\Harry Dresden\Desktop
  • c:\Users\Public\Recorded TV
  • c:\ProgramData\Microsoft\Office\Heartbeat
  • c:\ProgramData\Microsoft\Windows Defender\Scans\CleanStore\Resources\42
  • c:\Python27\tcl\tcl8.5\tzdata\Etc
  • c:\Python27\Lib\bsddb
  • c:\ProgramData\Microsoft\Windows Defender\Scans\CleanStore\Resources\47
  • c:\ProgramData\Microsoft\Windows Defender\Scans\CleanStore\ResourceData\95
  • c:\Python27\Tools\i18n
  • UNC\KIDSROOM\Users\Public\Foxit Software\Foxit Reader\StartPage\start\en_us\js\nor.js
  • c:\qraimbuwvp\modules
  • c:\ProgramData\Microsoft\ClickToRun\MachineData\Integration\ShortcutBackups
  • c:\Python27\Lib\wsgiref
  • c:\Python27\Lib\site-packages\pip\_vendor\requests\packages\urllib3\contrib
  • c:\ProgramData\Microsoft\User Account Pictures
  • c:\ProgramData\Sun\Java\Java Update
  • c:\Python27\Lib\test\sha256.pem
  • c:\ProgramData\Microsoft\ClickToRun\ProductReleases\53955D98-F46F-4906-AE49-9B6F52BA18A9
  • c:\Recovery\015e7760-d44b-11e0-8947-954f09601788
  • c:\Users
  • UNC\KIDSROOM\Users\Public\Foxit Software
  • c:\Users\Default\Saved Games
  • c:\Python27\Lib\site-packages\pip\_vendor\pkg_resources
  • c:\inetpub\history\CFGHISTORY_0000000005\schema
  • UNC\KIDSROOM\Users\Public\Pictures\Sample Pictures\Hydrangeas.jpg
  • c:\inetpub
  • UNC\KIDSROOM\Users\Public\Foxit Software\Foxit Reader\StartPage\start\en_us\js\DD_belatedPNG.js
  • UNC\KIDSROOM\Users\Public\Favorites
  • c:\Users\Default
  • c:\Python27\tcl\tcl8.5\tzdata\Pacific
  • c:\ProgramData\Microsoft\Windows NT\MSFax\ActivityLog
  • c:\Python27\tcl\tk8.5\msgs
  • c:\Python27\tcl\tcl8.5\tzdata\America
  • c:\ProgramData\Microsoft\Diagnosis\DownloadedSettings
  • c:\ProgramData\Microsoft\Windows Defender\Definition Updates\{98101498-C465-4F51-8751-D1919E97D29D}
  • c:\Python27\Lib\multiprocessing\dummy
  • c:\ProgramData\Microsoft\ClickToRun\MachineData\Catalog\Packages\{9AC08E99-230B-47E8-9721-4577B7F124EA}\{1A8308C7-90D1-4200-B16E-646F163A08E8}
  • c:\ProgramData\Microsoft\MF
  • c:\Python27\Lib\test\keycert3.pem
  • UNC\KIDSROOM\Users\Default\Saved Games
  • c:\Users\Public\Downloads
  • c:\Python27\Lib\site-packages
  • c:\ProgramData\Microsoft\Device Stage\Task
  • UNC\KIDSROOM\Users\Public\Foxit Software\Foxit Reader\StartPage\start\en_us\images\buy_phantom.png
  • c:\Python27\include\pyerrors.h
  • c:\Python27\Lib\unittest
  • c:\6cdeacda242012e0e5b593e657\Graphics
  • c:\ProgramData\Microsoft\Device Stage\Task\{07deb856-fc6e-4fb9-8add-d8f2cf8722c9}
  • c:\Python27\Lib\test\capath
  • c:\Users\Public\Foxit Software\Foxit Reader\StartPage\start\en_us\Default
  • c:\Recovery
  • c:\ProgramData\Microsoft\Device Stage
  • c:\ProgramData\Microsoft\Crypto\RSA\S-1-5-18
  • c:\Python27\include\pyarena.h
  • c:\ProgramData\Microsoft\Assistance\Client\1.0
  • c:\Python27\include\pythonrun.h
  • c:\Python27\include\structmember.h
  • c:\ProgramData\Oracle
  • c:\Python27\include\pygetopt.h
  • UNC\KIDSROOM\Users\Public\Music\Sample Music\Maid with the Flaxen Hair.mp3
  • c:\Python27\Lib\distutils\tests
  • UNC\KIDSROOM\Users\Harry Dresden\Videos
  • c:\Python27\Lib\logging
  • c:\ProgramData\Microsoft\RAC
  • c:\Python27\Lib\site-packages\pip\req
  • c:\Users\Harry Dresden\Links
  • c:\ProgramData\Microsoft\DeviceSync
  • c:\Python27\Doc
  • UNC\KIDSROOM\Users\Harry Dresden\Desktop
  • UNC\KIDSROOM\Users\Harry Dresden\Downloads\big-hero-6-2.jpg
  • c:\Python27\tcl\tix8.4.3\demos\bitmaps
  • c:\ProgramData\Microsoft\ClickToRun\ProductReleases\53955D98-F46F-4906-AE49-9B6F52BA18A9\en-us.16
  • UNC\KIDSROOM\Users\Public\Foxit Software\Foxit Reader\StartPage\advertisement\ribbon Integrate PDF into your application.bmp
  • UNC\KIDSROOM\Users\Public\Foxit Software\Foxit Reader\StartPage\advertisement\ribbon Powerful Word Processor.bmp
  • c:\Python27\include\patchlevel.h
  • UNC\KIDSROOM\Users\Default\Favorites
  • c:\Python27\Lib\compiler
  • c:\Python27\Scripts
  • c:\ProgramData\Microsoft\Windows Defender\Scans\CleanStore\ResourceData\47
  • c:\ProgramData\Microsoft\Windows Defender\Scans\CleanStore\ResourceData\43
  • c:\ProgramData\Microsoft\Windows Defender\Scans\CleanStore\ResourceData\42
  • UNC\KIDSROOM\Users\Public\Foxit Software\Foxit Reader\StartPage\start\en_us\css
  • c:\ProgramData\Microsoft\Windows Defender\Scans\CleanStore\Resources\17
  • c:\Python27\Lib\test\keycert.pem
  • c:\Python27\tcl\dde1.3
  • c:\Python27\tcl\tcl8.5\tzdata\SystemV
  • c:\ProgramData\NovaTech Network
  • c:\6cdeacda242012e0e5b593e657\1044\eula.rtf
  • c:\ProgramData\Sun\Java
  • UNC\KIDSROOM\Users\Public\Recorded TV
  • UNC\KIDSROOM\Users\Public\Foxit Software\Foxit Reader\StartPage\advertisement\normal Protect your PDF files with AD RMS.bmp
  • c:\Users\Public\Foxit Software\Foxit Reader\StartPage\start\en_us\js
  • c:\ProgramData\Microsoft\Diagnosis\AsimovUploader
  • UNC\KIDSROOM\Users\Public\Documents
  • UNC\KIDSROOM\Users\Default\Pictures
  • c:\Users\Public\Foxit Software\Foxit Reader\StartPage\start\en_us\images
  • UNC\KIDSROOM\Users\Public\Libraries
  • c:\Python27\tcl\tcl8.5\tzdata\Chile
  • c:\ProgramData\Microsoft\ClickToRun\UserData
  • c:\Python27\Lib\test\xmltestdata
  • c:\ProgramData\Microsoft\WPD
  • c:\Python27\Lib\site-packages\pip\_vendor
  • c:\ProgramData\Sun
  • c:\Python27\include\Python.h
  • UNC\KIDSROOM\Users\Default\Videos
  • c:\6cdeacda242012e0e5b593e657\1041\eula.rtf
  • c:\ProgramData\Microsoft\Diagnosis\ETLLogs\ShutdownLogger
  • c:\Python27\Lib\site-packages\setuptools
  • UNC\KIDSROOM\Users\Public\Music\Sample Music
  • c:\Python27\include\pystate.h
  • c:\Users\Default\Desktop
  • UNC\KIDSROOM\Users\Public\Foxit Software\Foxit Reader\StartPage\advertisement\ribbon Fastest PDF Search and Index.bmp
  • UNC\KIDSROOM\Users\Default\Music
  • c:\ProgramData\Microsoft\Windows Defender\Scans\CleanStore\Resources\1A
  • c:\Python27\Lib\site-packages\pip\_vendor\html5lib\treewalkers
  • c:\ProgramData\Microsoft\Device Stage\Device\{113527a4-45d4-4b6f-b567-97838f1b04b0}
  • c:\ProgramData\Microsoft\WwanSvc
  • c:\Python27\include\pyconfig.h
  • UNC\KIDSROOM\Users\Public\Foxit Software\Foxit Reader\StartPage\advertisement\ProfileRibbon.xml
  • \\?\PIPE\wkssvc
  • c:\ProgramData\Microsoft\Event Viewer\Views
  • UNC\KIDSROOM\Users\Public\Foxit Software\Foxit Reader\StartPage\start
  • c:\Python27\Lib\json\tests
  • c:\Python27\Lib\site-packages\pip\_vendor\html5lib\serializer
  • UNC\KIDSROOM\Users\Public\Foxit Software\Foxit Reader\StartPage\start\en_us\Default
  • c:\Python27\include\osdefs.h
  • c:\Python27\Tools
  • c:\Users\Public\Videos\Sample Videos
  • UNC\KIDSROOM\Users\Public\Downloads
  • c:\ProgramData\Microsoft\IlsCache
  • c:\Python27\Lib\lib-tk
  • UNC\KIDSROOM\Users\Default
  • c:\ProgramData\Microsoft\Windows Defender\Scans\History\Store
  • c:\ProgramData\Microsoft\Windows NT\MSFax\SentItems
  • c:\Users\Public\Foxit Software\Foxit Reader
  • UNC\KIDSROOM\Users\Harry Dresden\Desktop\OOGPUyjympUre.ppt
  • c:\Python27\Lib\site-packages\pip\operations
  • c:\ProgramData\Microsoft\Windows NT\MSFax\VirtualInbox
  • c:\qraimbuwvp\lib
  • c:\Python27\Lib\site-packages\pip\_vendor\lockfile
  • c:\Python27\Lib\curses
  • c:\6cdeacda242012e0e5b593e657\1037\eula.rtf
  • c:\ProgramData\Microsoft\ClickToRun\MachineData\Catalog\Packages\{9AC08E99-230B-47E8-9721-4577B7F124EA}
  • c:\Python27\include\pystrcmp.h
  • c:\Python27\include\floatobject.h
  • c:\Python27\Lib\test\pycacert.pem
  • c:\Python27\Lib\site-packages\pip\_vendor\html5lib\filters
  • c:\Python27\include\pymactoolbox.h
  • c:\Python27\Lib\test\badkey.pem
  • UNC\KIDSROOM\Users\Public\Foxit Software\Foxit Reader\StartPage\advertisement\normal Design form fields easily.bmp
  • c:\ProgramData\Microsoft\ClickToRun\MachineData\Integration
  • c:\Users\Default\Music
  • c:\Python27\Lib\email\mime
  • c:\Users\Harry Dresden\Music
  • c:\6cdeacda242012e0e5b593e657\1053
  • c:\6cdeacda242012e0e5b593e657\1055
  • UNC\KIDSROOM\Users\Harry Dresden\Links
  • c:\Python27\Lib\site-packages\pip\_vendor\requests\packages\urllib3
  • c:\Python27\tcl\tcl8.5\tzdata\Asia
  • c:\Users\Public\Foxit Software\Foxit Reader\StartPage\start\en_us\css
  • c:\Python27\Lib\multiprocessing
  • c:\Users\Default\Documents
  • UNC\KIDSROOM\Users\Public\Pictures\Sample Pictures\Penguins.jpg
  • c:\Users\Public\Desktop
  • c:\ProgramData\Microsoft\User Account Pictures\Default Pictures
  • c:\Python27\Lib\lib-tk\test\test_ttk
  • c:\Users\Harry Dresden\Documents
  • c:\ProgramData\McAfee\MCLOGS\Common
  • UNC\KIDSROOM\Users\Public\Foxit Software\Foxit Reader\StartPage\advertisement\ribbon View PDFs on mobile devices.bmp
  • c:\ProgramData\Microsoft\ClickToRun\ProductReleases\C0D2A2B7-8AE4-4D06-93E4-F1A7BD5FEC3F\x-none.16
  • c:\ProgramData\Microsoft\IdentityCRL
  • c:\ProgramData\WebEx\WebEx\12_1324
  • c:\Python27\Lib\site-packages\pip\utils
  • c:\Python27\Lib\distutils\command
  • c:\Users\Harry Dresden\Saved Games
  • UNC\KIDSROOM\Users\Public\Foxit Software\Foxit Reader\StartPage\advertisement\normal View PDFs on mobile devices.bmp
  • UNC\KIDSROOM\Users\Public\Foxit Software\Foxit Reader\StartPage\start\en_us\Default\content_showbg.jpg
  • UNC\KIDSROOM\Users\Public\Music\Sample Music\Kalimba.mp3
  • c:\qraimbuwvp\bin
  • c:\ProgramData\Microsoft\Windows Defender
  • c:\Python27
  • c:\Python27\Lib\hotshot
  • UNC\KIDSROOM\Users\Harry Dresden
  • c:\Python27\include\genobject.h
  • c:\inetpub\wwwroot
  • c:\Python27\tcl\tcl8.5\tzdata\Canada
  • c:\Python27\Tools\versioncheck
  • c:\Python27\tcl\tcl8.5\tzdata\Arctic
  • c:\ProgramData\Microsoft\Windows Defender\Scans\CleanStore\ResourceData\F7
  • c:\Users\Public\Music
  • c:\ProgramData\Microsoft\Windows Defender\Scans\CleanStore\ResourceData\F3
  • c:\Python27\Lib\test\audiodata
  • UNC\KIDSROOM\Users\Default\Downloads
  • c:\Python27\Lib\site-packages\pip\_vendor\html5lib\treeadapters
  • c:\Python27\include\intrcheck.h
  • c:\ProgramData\Microsoft\Network\Connections
  • c:\ProgramData\Microsoft\ClickToRun\ProductReleases\53955D98-F46F-4906-AE49-9B6F52BA18A9\x-none.16
  • c:\Python27\Lib\sqlite3
  • c:\ProgramData\Microsoft\Crypto\RSA\MachineKeys
  • c:\Python27\Lib\test\ssl_cert.pem
  • c:\Python27\Lib\site-packages\pip\_vendor\html5lib
  • c:\ProgramData\Microsoft\Windows Defender\Scans\CleanStore\Resources\43
  • \\?\PIPE\lsarpc
  • c:\ProgramData\Microsoft\Diagnosis
  • c:\ProgramData\Microsoft\ClickToRun\ProductReleases\C0D2A2B7-8AE4-4D06-93E4-F1A7BD5FEC3F\en-us.16
  • c:\Python27\Lib\distutils
  • UNC\KIDSROOM\Users\Harry Dresden\Saved Games
  • c:\Python27\Lib\site-packages\pip\_vendor\pkg_resources\tests
  • c:\Python27\Lib\idlelib\Icons
  • c:\ProgramData\Microsoft\Device Stage\Device
  • c:\Python27\Lib\site-packages\pip\_vendor\distlib
  • c:\Python27\Lib\test\subprocessdata
  • UNC\KIDSROOM\Users\Public\Foxit Software\Foxit Reader\StartPage\start\en_us\images\classic-16-open.png
  • c:\ProgramData\Microsoft\Windows Defender\Scans\CleanStore\ResourceData\35
  • c:\Python27\include\pymem.h
  • c:\inetpub\wwwroot\aspnet_client
  • c:\Python27\Lib\site-packages\pip\_vendor\requests\cacert.pem
  • c:\ProgramData\Microsoft\RAC\PublishedData
  • c:\Users\Public\Foxit Software
  • c:\ProgramData\Microsoft\Windows Defender\Scans\History\Results\Quick
  • c:\ProgramData\Microsoft\Windows NT\MSScan
  • c:\Python27\Lib\lib2to3\tests
  • UNC\KIDSROOM\Users\Public\Foxit Software\Foxit Reader\StartPage\advertisement\ribbon Protect Sensitive PDF Documents.bmp
  • c:\Python27\Lib\site-packages\pip-7.0.1.dist-info
  • c:\Python27\Lib\test\selfsigned_pythontestdotnet.pem
  • c:\ProgramData\Microsoft OneDrive\setup
  • c:\ProgramData\Microsoft\Crypto\DSS\MachineKeys
  • c:\6cdeacda242012e0e5b593e657\2070\eula.rtf
  • UNC\KIDSROOM\Users
  • c:\Python27\Lib\site-packages\pkg_resources
  • UNC\KIDSROOM\Users\Harry Dresden\Contacts
  • c:\Python27\Lib\site-packages\setuptools-16.0.dist-info
  • c:\Python27\include\rangeobject.h
  • c:\Python27\tcl\tcl8.5\tzdata\Brazil
  • c:\Users\Harry Dresden\Favorites\Links
  • UNC\KIDSROOM\Users\Default\Links
  • c:\Python27\Lib\test\imghdrdata
  • c:\Python27\include\iterobject.h
  • c:\ProgramData\Microsoft\Windows Defender\Definition Updates\Updates
  • c:\Users\Public\Foxit Software\Foxit Reader\StartPage\advertisement
  • c:\ProgramData\Microsoft\RAC\Outbound
  • c:\Python27\Lib\test\nullbytecert.pem
  • c:\inetpub\history\CFGHISTORY_0000000002
  • c:\Python27\include\funcobject.h
  • c:\Python27\include\listobject.h
  • c:\ProgramData\Microsoft\NetFramework
  • c:\Users\Public\Recorded TV\Sample Media
  • c:\ProgramData\Microsoft
  • c:\Users\Public\Pictures\Sample Pictures
  • c:\ProgramData\Microsoft\Windows Defender\Scans\History\Service
  • c:\Users\Default\Videos
  • c:\ProgramData\Microsoft\Search\Data
  • c:\Python27\tcl
  • c:\Python27\Lib\json
  • UNC\KIDSROOM\Users\Public\Pictures
  • c:\ProgramData\Microsoft\Windows NT\MSFax\VirtualInbox\en-US
  • c:\Python27\include\pythread.h
  • c:\Python27\Lib\lib2to3\fixes
  • UNC\KIDSROOM\Users\Public\Pictures\Sample Pictures\Koala.jpg
  • c:\Python27\tcl\tix8.4.3\bitmaps
  • c:\Python27\Lib\site-packages\setuptools\command
  • c:\6cdeacda242012e0e5b593e657
  • c:\Python27\tcl\tcl8.5\tzdata\America\Indiana
  • c:\6cdeacda242012e0e5b593e657\2070
  • c:\Python27\include\sliceobject.h
  • c:\Users\Public\Videos
  • UNC\KIDSROOM\Users\Public\Foxit Software\Foxit Reader\StartPage\advertisement\normal Protect Sensitive PDF Documents.bmp
  • c:\Python27\Lib\test\decimaltestdata
  • c:\ProgramData\Microsoft\Windows Defender\Scans\CleanStore\Resources\DD
  • c:\ProgramData\Microsoft\Diagnosis\UIF
  • c:\ProgramData\Microsoft\Windows Defender\Scans\CleanStore\ResourceData\A6
  • c:\Python27\tcl\tcl8.5\tzdata\Europe
  • c:\ProgramData\Microsoft\Windows Defender\Scans\CleanStore\ResourceData\A5
  • c:\Python27\include\stringobject.h
  • c:\Python27\Lib\lib2to3
  • c:\Python27\include\intobject.h
  • c:\ProgramData\Microsoft\Event Viewer
  • c:\ProgramData\Adobe\Setup\{AC76BA86-7AD7-1033-7B44-AB0000000001}
  • UNC\KIDSROOM\Users\Public\Foxit Software\Foxit Reader\StartPage\advertisement\normal Integrate PDF into your application.bmp
  • UNC\KIDSROOM\Users\Harry Dresden\Desktop\nABioNnaBFJ.pptx
  • c:\Python27\Lib\test\ssl_key.pem
  • c:\ProgramData\Microsoft\ClickToRun
  • UNC\KIDSROOM\Users\Public\Pictures\Sample Pictures
  • c:\Python27\include\methodobject.h
  • UNC\KIDSROOM\Users\Public\Foxit Software\Foxit Reader\StartPage\advertisement\ribbon Edit and reflow paragraphs in PDF files.bmp
  • UNC\KIDSROOM\Users\Harry Dresden\Favorites
  • c:\qraimbuwvp
  • c:\Python27\include\structseq.h
  • c:\Python27\tcl\tcl8.5\http1.0
  • c:\Python27\include\pymath.h
  • c:\Users\Public\Foxit Software\Foxit Reader\StartPage\start
  • UNC\KIDSROOM\Users\Public\Foxit Software\Foxit Reader\StartPage\advertisement\normal Fastest PDF Search and Index.bmp
  • c:\6cdeacda242012e0e5b593e657\1038\eula.rtf
  • c:\Python27\include\parsetok.h
  • c:\ProgramData\Adobe\Acrobat\11.0
  • UNC\KIDSROOM\Users\Public\Pictures\Sample Pictures\Jellyfish.jpg
  • c:\Python27\Lib\ensurepip\_bundled
  • c:\Python27\Lib\test\ssl_key.passwd.pem
  • c:\Users\Public\Music\Sample Music
  • c:\Python27\tcl\tcl8
  • c:\ProgramData\Microsoft\Windows Defender\Scans\History\CacheManager
  • c:\Python27\Lib\lib2to3\tests\data
  • c:\ProgramData\Microsoft\OfficeSoftwareProtectionPlatform\Cache
  • c:\ProgramData\Microsoft\Windows Defender\Scans\CleanStore\ResourceData\70
  • c:\ProgramData\Microsoft OneDrive
  • c:\ProgramData\Microsoft\Media Player
  • c:\Python27\tcl\tcl8.5\tzdata\America\Argentina
  • c:\Python27\include\setobject.h
  • UNC\KIDSROOM\Users\Harry Dresden\Pictures
  • c:\Python27\Lib\idlelib
  • c:\PerfLogs\Admin
  • UNC\KIDSROOM\Users\Public\Foxit Software\Foxit Reader\StartPage\advertisement\ribbon Protect your PDF files with AD RMS.bmp
  • c:\Python27\include\graminit.h
  • UNC\KIDSROOM\Users\Public\Foxit Software\Foxit Reader\StartPage\start\en_us\images
  • c:\Python27\Lib\site-packages\pip\_vendor\progress
  • c:\Users\Harry Dresden\Pictures
  • c:\ProgramData\Microsoft\Diagnosis\Sideload
  • c:\qraimbuwvp\lib\core
  • c:\Python27\Lib\site-packages\pip\_vendor\requests\packages\urllib3\packages\ssl_match_hostname
  • c:\Users\Harry Dresden\Favorites
  • c:\ProgramData\Passmark
  • c:\Python27\Lib\lib-tk\test
  • c:\6cdeacda242012e0e5b593e657\1049\eula.rtf
  • c:\ProgramData\Adobe
  • UNC\KIDSROOM\Users\Public\Pictures\Sample Pictures\Tulips.jpg
  • UNC\KIDSROOM\Users\Harry Dresden\Favorites\Links
  • UNC\KIDSROOM\Users\Public\Foxit Software\Foxit Reader\StartPage\advertisement\normal Enterprise PDF Reader.bmp
  • c:\ProgramData\Microsoft\Search
  • c:\ProgramData\Passmark\PerformanceTest
  • UNC\KIDSROOM\Users\Public\Foxit Software\Foxit Reader\StartPage\advertisement\normal Powerful Word Processor.bmp
  • UNC\KIDSROOM\Users\Public\Music
  • c:\ProgramData\Microsoft\NetFramework\BreadcrumbStore
  • c:\Python27\Lib\email\test
  • c:\ProgramData\Microsoft\ClickToRun\{9AC08E99-230B-47e8-9721-4577B7F124EA}
  • c:\ProgramData\WebEx
  • c:\inetpub\wwwroot\msmq
  • UNC\KIDSROOM\Users\Harry Dresden\Downloads\cleandesktop.py.txt
  • c:\Python27\tcl\tix8.4.3\demos
  • UNC\KIDSROOM\Users\Public\Recorded TV\Sample Media
  • c:\6cdeacda242012e0e5b593e657\1053\eula.rtf
  • c:\Python27\Lib\site-packages\pkg_resources\_vendor\packaging
  • c:\ProgramData\McAfee\MCLOGS
  • c:\Users\Default\Pictures
  • c:\6cdeacda242012e0e5b593e657\1049
  • c:\Users\Public\Documents
  • c:\6cdeacda242012e0e5b593e657\1046
  • c:\6cdeacda242012e0e5b593e657\1045
  • c:\6cdeacda242012e0e5b593e657\1044
  • c:\6cdeacda242012e0e5b593e657\1043
  • c:\6cdeacda242012e0e5b593e657\1042
  • c:\6cdeacda242012e0e5b593e657\1041
  • c:\6cdeacda242012e0e5b593e657\1040
  • c:\Python27\Lib\site-packages\pip\_vendor\packaging
  • c:\ProgramData\Microsoft\eHome\logs
  • c:\ProgramData\Microsoft\Windows Defender\Scans
  • c:\ProgramData\Microsoft\Windows NT\MSFax
  • c:\qraimbuwvp\modules\auxiliary
  • c:\ProgramData\Microsoft\Windows Defender\Definition Updates\Backup
  • UNC\KIDSROOM\Users\Harry Dresden\Desktop\pJEijfEAkF.docm
  • c:\Python27\Lib\sqlite3\test
  • c:\Python27\Lib\test\dh1024.pem
  • c:\ProgramData\Mozilla
  • c:\6cdeacda242012e0e5b593e657\1055\eula.rtf
  • UNC\KIDSROOM\Users\Public\Foxit Software\Foxit Reader\StartPage\advertisement\ribbon View and annotate PDFs.bmp
  • c:\ProgramData\Microsoft\Windows Defender\Scans\CleanStore\ResourceData\E0
  • UNC\KIDSROOM\Users\Public\Foxit Software\Foxit Reader\StartPage\advertisement
  • c:\ProgramData\Microsoft\Windows Defender\Definition Updates
  • c:\Python27\Lib\lib2to3\pgen2
  • c:\ProgramData\Microsoft\Windows Defender\Scans\History
  • c:\ProgramData\Microsoft\RAC\StateData
  • c:\6cdeacda242012e0e5b593e657\1038
  • UNC\KIDSROOM\Users\Harry Dresden\OneDrive
  • c:\ProgramData\Microsoft\DRM\Server
  • c:\6cdeacda242012e0e5b593e657\1032
  • c:\6cdeacda242012e0e5b593e657\1033
  • c:\6cdeacda242012e0e5b593e657\1030
  • c:\6cdeacda242012e0e5b593e657\1031
  • c:\6cdeacda242012e0e5b593e657\1036
  • c:\6cdeacda242012e0e5b593e657\1037
  • c:\6cdeacda242012e0e5b593e657\1035
File-Moved
  • c:\Python27\Lib\test\badcert.pem -> c:\Python27\Lib\test\076E35C0-5E29-6BE8-1C1C-554BAFA6A298.thor
  • c:\Python27\include\graminit.h -> c:\Python27\include\076E35C0-5E29-6BE8-4E7C-F88D8862D98D.thor
  • \\KIDSROOM\Users\Public\Foxit Software\Foxit Reader\StartPage\start\en_us\tpl\history.txt -> \\KIDSROOM\Users\Public\Foxit Software\Foxit Reader\StartPage\start\en_us\tpl\076E35C0-5E29-6BE8-43C9-B307B532B134.thor
  • c:\Python27\include\pymactoolbox.h -> c:\Python27\include\076E35C0-5E29-6BE8-8AC4-04211B0121FF.thor
  • \\KIDSROOM\Users\Public\Foxit Software\Foxit Reader\StartPage\start\en_us\images\classic-16-open.png -> \\KIDSROOM\Users\Public\Foxit Software\Foxit Reader\StartPage\start\en_us\images\076E35C0-5E29-6BE8-0B40-AC635E00E052.thor
  • c:\Python27\include\pydebug.h -> c:\Python27\include\076E35C0-5E29-6BE8-F2DA-4798132851F7.thor
  • c:\Python27\include\Python.h -> c:\Python27\include\076E35C0-5E29-6BE8-43A1-04368A571E2F.thor
  • c:\6cdeacda242012e0e5b593e657\1046\eula.rtf -> c:\6cdeacda242012e0e5b593e657\1046\076E35C0-5E29-6BE8-7F39-5E0823A6CC2F.thor
  • c:\6cdeacda242012e0e5b593e657\1044\eula.rtf -> c:\6cdeacda242012e0e5b593e657\1044\076E35C0-5E29-6BE8-7805-CCF59FCAC108.thor
  • c:\Python27\Lib\test\keycert4.pem -> c:\Python27\Lib\test\076E35C0-5E29-6BE8-8B29-8937BEC9D6FB.thor
  • c:\6cdeacda242012e0e5b593e657\1037\eula.rtf -> c:\6cdeacda242012e0e5b593e657\1037\076E35C0-5E29-6BE8-F8F0-E7160BDAF835.thor
  • \\KIDSROOM\Users\Public\Foxit Software\Foxit Reader\StartPage\start\en_us\js\DD_belatedPNG.js -> \\KIDSROOM\Users\Public\Foxit Software\Foxit Reader\StartPage\start\en_us\js\076E35C0-5E29-6BE8-F5D9-DA117515F6FA.thor
  • \\KIDSROOM\Users\Harry Dresden\Desktop\pJEijfEAkF.docm -> \\KIDSROOM\Users\Harry Dresden\Desktop\076E35C0-5E29-6BE8-E50E-C90FD7F5176B.thor
  • \\KIDSROOM\Users\Public\Pictures\Sample Pictures\Koala.jpg -> \\KIDSROOM\Users\Public\Pictures\Sample Pictures\076E35C0-5E29-6BE8-0475-5E2226FF3186.thor
  • c:\Python27\include\pystrtod.h -> c:\Python27\include\076E35C0-5E29-6BE8-4683-2313665C0F98.thor
  • \\KIDSROOM\Users\Public\Pictures\Sample Pictures\Jellyfish.jpg -> \\KIDSROOM\Users\Public\Pictures\Sample Pictures\076E35C0-5E29-6BE8-9419-951C73882F97.thor
  • \\KIDSROOM\Users\Public\Foxit Software\Foxit Reader\StartPage\start\en_us\Default\right_over_bg.jpg -> \\KIDSROOM\Users\Public\Foxit Software\Foxit Reader\StartPage\start\en_us\Default\076E35C0-5E29-6BE8-835F-A454CA31BB5D.thor
  • c:\Python27\include\floatobject.h -> c:\Python27\include\076E35C0-5E29-6BE8-EECA-7318A52DCB6F.thor
  • c:\Python27\Lib\test\badkey.pem -> c:\Python27\Lib\test\076E35C0-5E29-6BE8-5908-7F3D23C2F341.thor
  • \\KIDSROOM\Users\Harry Dresden\Desktop\nABioNnaBFJ.pptx -> \\KIDSROOM\Users\Harry Dresden\Desktop\076E35C0-5E29-6BE8-D62E-14D7850C2D95.thor
  • \\KIDSROOM\Users\Public\Foxit Software\Foxit Reader\StartPage\start\en_us\images\classic-16.png -> \\KIDSROOM\Users\Public\Foxit Software\Foxit Reader\StartPage\start\en_us\images\076E35C0-5E29-6BE8-7DC9-F801C691EEE4.thor
  • \\KIDSROOM\Users\Harry Dresden\Desktop\xoLqqScSdkaZfOj.ppt -> \\KIDSROOM\Users\Harry Dresden\Desktop\076E35C0-5E29-6BE8-7A9B-0B44EC735A5C.thor
  • c:\Python27\include\pyport.h -> c:\Python27\include\076E35C0-5E29-6BE8-671A-EDE896C701B1.thor
  • c:\Python27\include\sliceobject.h -> c:\Python27\include\076E35C0-5E29-6BE8-85CA-DE7C1F500C53.thor
  • c:\Python27\Lib\test\keycert.passwd.pem -> c:\Python27\Lib\test\076E35C0-5E29-6BE8-8012-35C0008200FC.thor
  • c:\Python27\include\pymacconfig.h -> c:\Python27\include\076E35C0-5E29-6BE8-8B82-C78F8098BAA4.thor
  • \\KIDSROOM\Users\Public\Foxit Software\Foxit Reader\StartPage\advertisement\ribbon Edit and reflow paragraphs in PDF files.bmp -> \\KIDSROOM\Users\Public\Foxit Software\Foxit Reader\StartPage\advertisement\076E35C0-5E29-6BE8-4E50-39B99B7DFBE3.thor
  • c:\Python27\include\py_curses.h -> c:\Python27\include\076E35C0-5E29-6BE8-1AC1-38B5DA64312B.thor
  • c:\Python27\include\funcobject.h -> c:\Python27\include\076E35C0-5E29-6BE8-851F-BD0B36B5A37C.thor
  • c:\Python27\include\pystate.h -> c:\Python27\include\076E35C0-5E29-6BE8-4289-1274108538FE.thor
  • c:\Python27\include\parsetok.h -> c:\Python27\include\076E35C0-5E29-6BE8-1422-7ECF51728688.thor
  • c:\6cdeacda242012e0e5b593e657\1038\eula.rtf -> c:\6cdeacda242012e0e5b593e657\1038\076E35C0-5E29-6BE8-44C7-E02B74F0BF03.thor
  • c:\6cdeacda242012e0e5b593e657\1053\eula.rtf -> c:\6cdeacda242012e0e5b593e657\1053\076E35C0-5E29-6BE8-82D8-5C09EDF63ECF.thor
  • \\KIDSROOM\Users\Public\Foxit Software\Foxit Reader\StartPage\start\en_us\images\phantomPDF_s.png -> \\KIDSROOM\Users\Public\Foxit Software\Foxit Reader\StartPage\start\en_us\images\076E35C0-5E29-6BE8-A70D-2104B194FDC6.thor
  • c:\Python27\Lib\test\sha256.pem -> c:\Python27\Lib\test\076E35C0-5E29-6BE8-4031-435EB3430C19.thor
  • c:\Python27\include\genobject.h -> c:\Python27\include\076E35C0-5E29-6BE8-997C-7D573A04D512.thor
  • c:\Python27\include\intrcheck.h -> c:\Python27\include\076E35C0-5E29-6BE8-0246-EF165E94CFAB.thor
  • c:\Python27\Lib\test\selfsigned_pythontestdotnet.pem -> c:\Python27\Lib\test\076E35C0-5E29-6BE8-371E-7DFF9A12E92B.thor
  • \\KIDSROOM\Users\Public\Foxit Software\Foxit Reader\StartPage\start\en_us\Default\show_con_bg.jpg -> \\KIDSROOM\Users\Public\Foxit Software\Foxit Reader\StartPage\start\en_us\Default\076E35C0-5E29-6BE8-976B-BE5C7A2BEC02.thor
  • c:\6cdeacda242012e0e5b593e657\1043\eula.rtf -> c:\6cdeacda242012e0e5b593e657\1043\076E35C0-5E29-6BE8-1EBC-3D57ED6F3EC6.thor
  • c:\Python27\Lib\test\keycert2.pem -> c:\Python27\Lib\test\076E35C0-5E29-6BE8-B86F-2BA2454DCFB5.thor
  • c:\Python27\Lib\test\nullbytecert.pem -> c:\Python27\Lib\test\076E35C0-5E29-6BE8-AFB8-E027FF3FAB5A.thor
  • c:\Python27\include\frameobject.h -> c:\Python27\include\076E35C0-5E29-6BE8-15E4-DC6C0015B658.thor
  • \\KIDSROOM\Users\Public\Foxit Software\Foxit Reader\StartPage\start\en_us\version.xml -> \\KIDSROOM\Users\Public\Foxit Software\Foxit Reader\StartPage\start\en_us\076E35C0-5E29-6BE8-9A43-14D118FF4680.thor
  • \\KIDSROOM\Users\Public\Foxit Software\Foxit Reader\StartPage\advertisement\normal Fastest PDF Search and Index.bmp -> \\KIDSROOM\Users\Public\Foxit Software\Foxit Reader\StartPage\advertisement\076E35C0-5E29-6BE8-3E8B-CE6C7DA48CF9.thor
  • c:\Python27\include\patchlevel.h -> c:\Python27\include\076E35C0-5E29-6BE8-22F1-8795D631C1EF.thor
  • c:\6cdeacda242012e0e5b593e657\1041\eula.rtf -> c:\6cdeacda242012e0e5b593e657\1041\076E35C0-5E29-6BE8-2289-226A0AD6B9A5.thor
  • \\KIDSROOM\Users\Public\Foxit Software\Foxit Reader\StartPage\advertisement\ribbon Protect your PDF files with AD RMS.bmp -> \\KIDSROOM\Users\Public\Foxit Software\Foxit Reader\StartPage\advertisement\076E35C0-5E29-6BE8-E8FD-133D32B28814.thor
  • c:\Python27\include\pyctype.h -> c:\Python27\include\076E35C0-5E29-6BE8-F041-A3DAA503B8D4.thor
  • \\KIDSROOM\Users\Public\Foxit Software\Foxit Reader\StartPage\start\en_us\Default\history_winbg.jpg -> \\KIDSROOM\Users\Public\Foxit Software\Foxit Reader\StartPage\start\en_us\Default\076E35C0-5E29-6BE8-73AD-CA64E7F50B81.thor
  • c:\Python27\include\pyconfig.h -> c:\Python27\include\076E35C0-5E29-6BE8-B7AA-F1C61A23EA2E.thor
  • c:\Python27\include\pyfpe.h -> c:\Python27\include\076E35C0-5E29-6BE8-A3D7-080E78529220.thor
  • c:\Python27\Lib\test\dh1024.pem -> c:\Python27\Lib\test\076E35C0-5E29-6BE8-0B5C-0C3935D37B4C.thor
  • c:\Python27\Lib\test\pycacert.pem -> c:\Python27\Lib\test\076E35C0-5E29-6BE8-E9B2-F3434EF527C7.thor
  • c:\6cdeacda242012e0e5b593e657\2070\eula.rtf -> c:\6cdeacda242012e0e5b593e657\2070\076E35C0-5E29-6BE8-4F7E-AAC91EE634BF.thor
  • \\KIDSROOM\Users\Public\Foxit Software\Foxit Reader\StartPage\advertisement\ProfileRibbon.xml -> \\KIDSROOM\Users\Public\Foxit Software\Foxit Reader\StartPage\advertisement\076E35C0-5E29-6BE8-83AB-D9FCD8BE95A2.thor
  • c:\Python27\include\iterobject.h -> c:\Python27\include\076E35C0-5E29-6BE8-CF3A-F0B6E38E831A.thor
  • c:\Python27\Lib\test\https_svn_python_org_root.pem -> c:\Python27\Lib\test\076E35C0-5E29-6BE8-5E57-BD9C5AD5780E.thor
  • c:\Python27\include\listobject.h -> c:\Python27\include\076E35C0-5E29-6BE8-782B-B2CB8665BBE6.thor
  • \\KIDSROOM\Users\Harry Dresden\Desktop\OOGPUyjympUre.ppt -> \\KIDSROOM\Users\Harry Dresden\Desktop\076E35C0-5E29-6BE8-E960-BC4382CB689D.thor
  • \\KIDSROOM\Users\Public\Music\Sample Music\Maid with the Flaxen Hair.mp3 -> \\KIDSROOM\Users\Public\Music\Sample Music\076E35C0-5E29-6BE8-7C64-A33825FC6860.thor
  • c:\Python27\include\grammar.h -> c:\Python27\include\076E35C0-5E29-6BE8-6EC2-DCA6777A4712.thor
  • c:\Python27\include\opcode.h -> c:\Python27\include\076E35C0-5E29-6BE8-E3F0-F1B3E87AB6F4.thor
  • c:\Python27\include\node.h -> c:\Python27\include\076E35C0-5E29-6BE8-7E66-22617B1A185B.thor
  • c:\Python27\include\intobject.h -> c:\Python27\include\076E35C0-5E29-6BE8-4048-B11A0CCB8989.thor
  • \\KIDSROOM\Users\Public\Foxit Software\Foxit Reader\StartPage\advertisement\normal View PDFs on mobile devices.bmp -> \\KIDSROOM\Users\Public\Foxit Software\Foxit Reader\StartPage\advertisement\076E35C0-5E29-6BE8-DF51-657DBEA2FA85.thor
  • c:\6cdeacda242012e0e5b593e657\1055\eula.rtf -> c:\6cdeacda242012e0e5b593e657\1055\076E35C0-5E29-6BE8-3B40-55095258659C.thor
  • c:\Python27\include\pythonrun.h -> c:\Python27\include\076E35C0-5E29-6BE8-5A6B-BDC355C06291.thor
  • \\KIDSROOM\Users\Public\Foxit Software\Foxit Reader\StartPage\advertisement\ribbon Create PDF from Office-convert PDF to office.bmp -> \\KIDSROOM\Users\Public\Foxit Software\Foxit Reader\StartPage\advertisement\076E35C0-5E29-6BE8-23E4-6CC80117FF51.thor
  • c:\Python27\include\pymath.h -> c:\Python27\include\076E35C0-5E29-6BE8-D1B9-B7DCA3B0EAAA.thor
  • \\KIDSROOM\Users\Public\Pictures\Sample Pictures\Lighthouse.jpg -> \\KIDSROOM\Users\Public\Pictures\Sample Pictures\076E35C0-5E29-6BE8-6344-0D98082EE8AB.thor
  • \\KIDSROOM\Users\Public\Foxit Software\Foxit Reader\StartPage\advertisement\ribbon Powerful Word Processor.bmp -> \\KIDSROOM\Users\Public\Foxit Software\Foxit Reader\StartPage\advertisement\076E35C0-5E29-6BE8-9AAC-7327C2A05DAC.thor
  • \\KIDSROOM\Users\Public\Foxit Software\Foxit Reader\StartPage\advertisement\ribbon Enterprise PDF Reader.bmp -> \\KIDSROOM\Users\Public\Foxit Software\Foxit Reader\StartPage\advertisement\076E35C0-5E29-6BE8-D424-5A3084A53D61.thor
  • \\KIDSROOM\Users\Public\Foxit Software\Foxit Reader\StartPage\advertisement\ribbon Fastest PDF Search and Index.bmp -> \\KIDSROOM\Users\Public\Foxit Software\Foxit Reader\StartPage\advertisement\076E35C0-5E29-6BE8-3A37-C07BD25CABF6.thor
  • \\KIDSROOM\Users\Public\Foxit Software\Foxit Reader\StartPage\start\en_us\js\nor.js -> \\KIDSROOM\Users\Public\Foxit Software\Foxit Reader\StartPage\start\en_us\js\076E35C0-5E29-6BE8-636B-7EE91A152B75.thor
  • \\KIDSROOM\Users\Public\Foxit Software\Foxit Reader\StartPage\start\en_us\Default\line.jpg -> \\KIDSROOM\Users\Public\Foxit Software\Foxit Reader\StartPage\start\en_us\Default\076E35C0-5E29-6BE8-98AE-318ECD8155BA.thor
  • \\KIDSROOM\Users\Public\Foxit Software\Foxit Reader\StartPage\start\en_us\images\ribbon-16-open.png -> \\KIDSROOM\Users\Public\Foxit Software\Foxit Reader\StartPage\start\en_us\images\076E35C0-5E29-6BE8-86A6-532E33138295.thor
  • c:\Python27\Lib\test\ssl_key.pem -> c:\Python27\Lib\test\076E35C0-5E29-6BE8-2CCC-C9CB39AB19A7.thor
  • c:\6cdeacda242012e0e5b593e657\1025\eula.rtf -> c:\6cdeacda242012e0e5b593e657\1025\076E35C0-5E29-6BE8-566E-EF2C0A4FD76D.thor
  • \\KIDSROOM\Users\Public\Foxit Software\Foxit Reader\StartPage\start\en_us\Default\right_move_bg.jpg -> \\KIDSROOM\Users\Public\Foxit Software\Foxit Reader\StartPage\start\en_us\Default\076E35C0-5E29-6BE8-ED33-522933C3AE9B.thor
  • c:\qraimbuwvp\bin\cert.p12 -> c:\qraimbuwvp\bin\076E35C0-5E29-6BE8-3FDD-7E27DC56FAFE.thor
  • c:\Python27\include\pgen.h -> c:\Python27\include\076E35C0-5E29-6BE8-1118-994E99228849.thor
  • \\KIDSROOM\Users\Harry Dresden\Desktop\taVvuxZeAvs.pptx -> \\KIDSROOM\Users\Harry Dresden\Desktop\076E35C0-5E29-6BE8-DA5E-6FB43FF17124.thor
  • \\KIDSROOM\Users\Public\Foxit Software\Foxit Reader\StartPage\advertisement\normal Enterprise PDF Reader.bmp -> \\KIDSROOM\Users\Public\Foxit Software\Foxit Reader\StartPage\advertisement\076E35C0-5E29-6BE8-855C-EEE7189BF3CE.thor
  • c:\Python27\include\pgenheaders.h -> c:\Python27\include\076E35C0-5E29-6BE8-B887-AF7C2AAD96E8.thor
  • c:\6cdeacda242012e0e5b593e657\1042\eula.rtf -> c:\6cdeacda242012e0e5b593e657\1042\076E35C0-5E29-6BE8-3802-8EA668FA73C1.thor
  • \\KIDSROOM\Users\Public\Foxit Software\Foxit Reader\StartPage\advertisement\normal create pdf from scanner documents.bmp -> \\KIDSROOM\Users\Public\Foxit Software\Foxit Reader\StartPage\advertisement\076E35C0-5E29-6BE8-9AC6-D3B08A6DAB84.thor
  • c:\Python27\include\longobject.h -> c:\Python27\include\076E35C0-5E29-6BE8-657A-20C67B7648D7.thor
  • \\KIDSROOM\Users\Harry Dresden\Desktop\ZKGxrSkjfT.ppt -> \\KIDSROOM\Users\Harry Dresden\Desktop\076E35C0-5E29-6BE8-DAB0-5E89C1811372.thor
  • \\KIDSROOM\Users\Harry Dresden\Downloads\big-hero-6-2.jpg -> \\KIDSROOM\Users\Harry Dresden\Downloads\076E35C0-5E29-6BE8-5FC7-C4EF6D42D52C.thor
  • c:\Python27\include\pyerrors.h -> c:\Python27\include\076E35C0-5E29-6BE8-E505-6483C8C983A0.thor
  • \\KIDSROOM\Users\Public\Foxit Software\Foxit Reader\StartPage\advertisement\normal Integrate PDF into your mobile apps.bmp -> \\KIDSROOM\Users\Public\Foxit Software\Foxit Reader\StartPage\advertisement\076E35C0-5E29-6BE8-54E4-0DB5842CABBE.thor
  • \\KIDSROOM\Users\Public\Pictures\Sample Pictures\Hydrangeas.jpg -> \\KIDSROOM\Users\Public\Pictures\Sample Pictures\076E35C0-5E29-6BE8-C135-C12435007FBC.thor
  • c:\Python27\include\rangeobject.h -> c:\Python27\include\076E35C0-5E29-6BE8-7560-0A7A0769A453.thor
  • c:\Python27\Lib\test\nokia.pem -> c:\Python27\Lib\test\076E35C0-5E29-6BE8-4745-2AF0665FF292.thor
  • c:\Python27\include\import.h -> c:\Python27\include\076E35C0-5E29-6BE8-6152-A645F46A6EFE.thor
  • c:\Python27\include\structmember.h -> c:\Python27\include\076E35C0-5E29-6BE8-2CFD-78681E82E6D7.thor
  • \\KIDSROOM\Users\Public\Foxit Software\Foxit Reader\StartPage\start\en_us\Default\tab.png -> \\KIDSROOM\Users\Public\Foxit Software\Foxit Reader\StartPage\start\en_us\Default\076E35C0-5E29-6BE8-E654-F6372A1921FB.thor
  • \\KIDSROOM\Users\Public\Foxit Software\Foxit Reader\StartPage\advertisement\normal Edit and reflow paragraphs in PDF files.bmp -> \\KIDSROOM\Users\Public\Foxit Software\Foxit Reader\StartPage\advertisement\076E35C0-5E29-6BE8-52FA-007C91CCC1F6.thor
  • c:\6cdeacda242012e0e5b593e657\1045\eula.rtf -> c:\6cdeacda242012e0e5b593e657\1045\076E35C0-5E29-6BE8-D327-7F6BA7F80FD6.thor
  • c:\Python27\include\setobject.h -> c:\Python27\include\076E35C0-5E29-6BE8-3F2C-C61C5B4DB716.thor
  • c:\Python27\include\methodobject.h -> c:\Python27\include\076E35C0-5E29-6BE8-DEA2-FA91F1960912.thor
  • c:\Python27\include\pyarena.h -> c:\Python27\include\076E35C0-5E29-6BE8-2D3C-044BFBCE1514.thor
  • c:\Python27\include\Python-ast.h -> c:\Python27\include\076E35C0-5E29-6BE8-12BF-B7476E9B957F.thor
  • c:\Python27\Lib\test\keycert.pem -> c:\Python27\Lib\test\076E35C0-5E29-6BE8-6C77-6A29DD84FDA7.thor
  • c:\Python27\include\pythread.h -> c:\Python27\include\076E35C0-5E29-6BE8-1AEC-88039A518FC8.thor
  • c:\Python27\include\pyexpat.h -> c:\Python27\include\076E35C0-5E29-6BE8-3680-957ED38D32E6.thor
  • c:\Python27\Lib\site-packages\pip\_vendor\requests\cacert.pem -> c:\Python27\Lib\site-packages\pip\_vendor\requests\076E35C0-5E29-6BE8-A162-6462F3F6AE98.thor
  • \\KIDSROOM\Users\Public\Foxit Software\Foxit Reader\StartPage\start\en_us\images\phantomPDF_b.png -> \\KIDSROOM\Users\Public\Foxit Software\Foxit Reader\StartPage\start\en_us\images\076E35C0-5E29-6BE8-2183-84CDD1A4D15F.thor
  • \\KIDSROOM\Users\Public\Foxit Software\Foxit Reader\StartPage\start\en_us\images\ribbon-16.png -> \\KIDSROOM\Users\Public\Foxit Software\Foxit Reader\StartPage\start\en_us\images\076E35C0-5E29-6BE8-CABA-765757B98A0E.thor
  • c:\6cdeacda242012e0e5b593e657\1036\eula.rtf -> c:\6cdeacda242012e0e5b593e657\1036\076E35C0-5E29-6BE8-B460-D805E9187B44.thor
  • \\KIDSROOM\Users\Public\Music\Sample Music\Kalimba.mp3 -> \\KIDSROOM\Users\Public\Music\Sample Music\076E35C0-5E29-6BE8-BEF9-020199F538D0.thor
  • \\KIDSROOM\Users\Harry Dresden\Desktop\jiWIzyGIufc.ppt -> \\KIDSROOM\Users\Harry Dresden\Desktop\076E35C0-5E29-6BE8-0EAC-4A72658570C9.thor
  • c:\Python27\Lib\test\nullcert.pem -> c:\Python27\Lib\test\076E35C0-5E29-6BE8-DA23-682D09B49DFE.thor
  • c:\Python27\Lib\test\ssl_key.passwd.pem -> c:\Python27\Lib\test\076E35C0-5E29-6BE8-1AA7-55CD3972225B.thor
  • c:\Python27\include\pygetopt.h -> c:\Python27\include\076E35C0-5E29-6BE8-BCE7-14BE0F639A8B.thor
  • c:\6cdeacda242012e0e5b593e657\2052\eula.rtf -> c:\6cdeacda242012e0e5b593e657\2052\076E35C0-5E29-6BE8-2AA3-469178FB354F.thor
  • \\KIDSROOM\Users\Public\Foxit Software\Foxit Reader\StartPage\start\en_us\Default\content_showbg.jpg -> \\KIDSROOM\Users\Public\Foxit Software\Foxit Reader\StartPage\start\en_us\Default\076E35C0-5E29-6BE8-A11A-6CD1E9D48D6E.thor
  • \\KIDSROOM\Users\Harry Dresden\Desktop\gDGKKpFAukuvGcz.txt -> \\KIDSROOM\Users\Harry Dresden\Desktop\076E35C0-5E29-6BE8-CFC0-092954844304.thor
  • c:\Python27\include\symtable.h -> c:\Python27\include\076E35C0-5E29-6BE8-DB3D-BFD1B27F5D30.thor
  • \\KIDSROOM\Users\Public\Foxit Software\Foxit Reader\StartPage\advertisement\normal Powerful Word Processor.bmp -> \\KIDSROOM\Users\Public\Foxit Software\Foxit Reader\StartPage\advertisement\076E35C0-5E29-6BE8-35F4-81C24FBE8E5B.thor
  • \\KIDSROOM\Users\Harry Dresden\Desktop\vpTbGEKRhU.txt -> \\KIDSROOM\Users\Harry Dresden\Desktop\076E35C0-5E29-6BE8-B6A2-20E54D3B07B1.thor
  • \\KIDSROOM\Users\Public\Foxit Software\Foxit Reader\StartPage\advertisement\normal Design form fields easily.bmp -> \\KIDSROOM\Users\Public\Foxit Software\Foxit Reader\StartPage\advertisement\076E35C0-5E29-6BE8-6998-FF8BECE09B7A.thor
  • c:\Python27\include\moduleobject.h -> c:\Python27\include\076E35C0-5E29-6BE8-D534-445B054195F4.thor
  • c:\Python27\Lib\test\wrongcert.pem -> c:\Python27\Lib\test\076E35C0-5E29-6BE8-AE7B-F83958BBBA05.thor
  • \\KIDSROOM\Users\Public\Foxit Software\Foxit Reader\StartPage\advertisement\ribbon View and annotate PDFs.bmp -> \\KIDSROOM\Users\Public\Foxit Software\Foxit Reader\StartPage\advertisement\076E35C0-5E29-6BE8-2580-B79EE9354E76.thor
  • \\KIDSROOM\Users\Public\Pictures\Sample Pictures\Desert.jpg -> \\KIDSROOM\Users\Public\Pictures\Sample Pictures\076E35C0-5E29-6BE8-4936-DC2901551798.thor
  • c:\Python27\include\pymem.h -> c:\Python27\include\076E35C0-5E29-6BE8-866D-58D7484F7380.thor
  • \\KIDSROOM\Users\Public\Foxit Software\Foxit Reader\StartPage\advertisement\normal Protect your PDF files with AD RMS.bmp -> \\KIDSROOM\Users\Public\Foxit Software\Foxit Reader\StartPage\advertisement\076E35C0-5E29-6BE8-7817-AA697585984F.thor
  • \\KIDSROOM\Users\Public\Foxit Software\Foxit Reader\StartPage\advertisement\ribbon View PDFs on mobile devices.bmp -> \\KIDSROOM\Users\Public\Foxit Software\Foxit Reader\StartPage\advertisement\076E35C0-5E29-6BE8-75CF-B620EAA42693.thor
  • \\KIDSROOM\Users\Public\Foxit Software\Foxit Reader\StartPage\start\en_us\images\blank.gif -> \\KIDSROOM\Users\Public\Foxit Software\Foxit Reader\StartPage\start\en_us\images\076E35C0-5E29-6BE8-A0CF-5EAFB0065A84.thor
  • c:\Python27\include\object.h -> c:\Python27\include\076E35C0-5E29-6BE8-2DCD-5A4CA66C16D7.thor
  • c:\Python27\include\pystrcmp.h -> c:\Python27\include\076E35C0-5E29-6BE8-53A2-6830C6F3AC99.thor
  • \\KIDSROOM\Users\Public\Music\Sample Music\Sleep Away.mp3 -> \\KIDSROOM\Users\Public\Music\Sample Music\076E35C0-5E29-6BE8-C2F1-1E35B9AF107A.thor
  • \\KIDSROOM\Users\Public\Foxit Software\Foxit Reader\StartPage\advertisement\normal Integrate PDF into your application.bmp -> \\KIDSROOM\Users\Public\Foxit Software\Foxit Reader\StartPage\advertisement\076E35C0-5E29-6BE8-0484-997E8A856836.thor
  • \\KIDSROOM\Users\Public\Foxit Software\Foxit Reader\StartPage\advertisement\ribbon Protect Sensitive PDF Documents.bmp -> \\KIDSROOM\Users\Public\Foxit Software\Foxit Reader\StartPage\advertisement\076E35C0-5E29-6BE8-7274-67FDEC2792A1.thor
  • c:\6cdeacda242012e0e5b593e657\3082\eula.rtf -> c:\6cdeacda242012e0e5b593e657\3082\076E35C0-5E29-6BE8-4454-D32F265F756E.thor
  • \\KIDSROOM\Users\Public\Foxit Software\Foxit Reader\StartPage\advertisement\ribbon Integrate PDF into your mobile apps.bmp -> \\KIDSROOM\Users\Public\Foxit Software\Foxit Reader\StartPage\advertisement\076E35C0-5E29-6BE8-4D97-6E27044238F2.thor
  • \\KIDSROOM\Users\Public\Pictures\Sample Pictures\Tulips.jpg -> \\KIDSROOM\Users\Public\Pictures\Sample Pictures\076E35C0-5E29-6BE8-9B1D-52E4B2259F58.thor
  • c:\Python27\include\osdefs.h -> c:\Python27\include\076E35C0-5E29-6BE8-3688-1E4C460AD7AB.thor
  • \\KIDSROOM\Users\Public\Foxit Software\Foxit Reader\StartPage\advertisement\ribbon create pdf from scanner documents.bmp -> \\KIDSROOM\Users\Public\Foxit Software\Foxit Reader\StartPage\advertisement\076E35C0-5E29-6BE8-D1C7-77F5EAE65E4E.thor
  • \\KIDSROOM\Users\Public\Foxit Software\Foxit Reader\StartPage\advertisement\normal Create PDF from Office-convert PDF to office.bmp -> \\KIDSROOM\Users\Public\Foxit Software\Foxit Reader\StartPage\advertisement\076E35C0-5E29-6BE8-FC40-1E1B642DA0E4.thor
  • \\KIDSROOM\Users\Public\Foxit Software\Foxit Reader\StartPage\advertisement\normal View and annotate PDFs.bmp -> \\KIDSROOM\Users\Public\Foxit Software\Foxit Reader\StartPage\advertisement\076E35C0-5E29-6BE8-F4C3-A606BE0E4B6A.thor
  • c:\Python27\Lib\test\keycert3.pem -> c:\Python27\Lib\test\076E35C0-5E29-6BE8-2F3E-12BD2CF4E67C.thor
  • \\KIDSROOM\Users\Public\Foxit Software\Foxit Reader\StartPage\start\en_us\images\buy_phantom.png -> \\KIDSROOM\Users\Public\Foxit Software\Foxit Reader\StartPage\start\en_us\images\076E35C0-5E29-6BE8-9109-E87E2BC42C00.thor
  • c:\Python27\include\pycapsule.h -> c:\Python27\include\076E35C0-5E29-6BE8-F900-EDD0501A0927.thor
  • c:\Python27\include\stringobject.h -> c:\Python27\include\076E35C0-5E29-6BE8-713B-DC91741D468C.thor
  • \\KIDSROOM\Users\Public\Foxit Software\Foxit Reader\StartPage\advertisement\ribbon Design form fields easily.bmp -> \\KIDSROOM\Users\Public\Foxit Software\Foxit Reader\StartPage\advertisement\076E35C0-5E29-6BE8-890F-36B53FE85FEA.thor
  • \\KIDSROOM\Users\Harry Dresden\Desktop\OaOKXfzhUqn.doc -> \\KIDSROOM\Users\Harry Dresden\Desktop\076E35C0-5E29-6BE8-EAE2-690C5B99687B.thor
  • c:\6cdeacda242012e0e5b593e657\1040\eula.rtf -> c:\6cdeacda242012e0e5b593e657\1040\076E35C0-5E29-6BE8-02C7-4946709E4204.thor
  • \\KIDSROOM\Users\Public\Foxit Software\Foxit Reader\StartPage\advertisement\ribbon Integrate PDF into your application.bmp -> \\KIDSROOM\Users\Public\Foxit Software\Foxit Reader\StartPage\advertisement\076E35C0-5E29-6BE8-1D1A-26FB6E9585FA.thor
  • \\KIDSROOM\Users\Public\Pictures\Sample Pictures\Chrysanthemum.jpg -> \\KIDSROOM\Users\Public\Pictures\Sample Pictures\076E35C0-5E29-6BE8-125D-87B32452466A.thor
  • c:\6cdeacda242012e0e5b593e657\1049\eula.rtf -> c:\6cdeacda242012e0e5b593e657\1049\076E35C0-5E29-6BE8-42CC-BFDC971D91FC.thor
  • \\KIDSROOM\Users\Public\Foxit Software\Foxit Reader\StartPage\start\en_us\Default\body_bg.jpg -> \\KIDSROOM\Users\Public\Foxit Software\Foxit Reader\StartPage\start\en_us\Default\076E35C0-5E29-6BE8-8BB8-1D6FAD20B992.thor
  • c:\Python27\Lib\test\ssl_cert.pem -> c:\Python27\Lib\test\076E35C0-5E29-6BE8-6E3A-A8E25B090728.thor
  • \\KIDSROOM\Users\Public\Foxit Software\Foxit Reader\StartPage\start\en_us\Default\top_tb_bg.jpg -> \\KIDSROOM\Users\Public\Foxit Software\Foxit Reader\StartPage\start\en_us\Default\076E35C0-5E29-6BE8-A32E-8A121A570A2F.thor
  • \\KIDSROOM\Users\Public\Foxit Software\Foxit Reader\StartPage\advertisement\normal Protect Sensitive PDF Documents.bmp -> \\KIDSROOM\Users\Public\Foxit Software\Foxit Reader\StartPage\advertisement\076E35C0-5E29-6BE8-D945-D904EC0E32DB.thor
  • \\KIDSROOM\Users\Harry Dresden\Downloads\cleandesktop.py.txt -> \\KIDSROOM\Users\Harry Dresden\Downloads\076E35C0-5E29-6BE8-CB91-C8611B6690FD.thor
  • \\KIDSROOM\Users\Public\Foxit Software\Foxit Reader\StartPage\advertisement\Profile.xml -> \\KIDSROOM\Users\Public\Foxit Software\Foxit Reader\StartPage\advertisement\076E35C0-5E29-6BE8-C66F-6DB125745319.thor
  • \\KIDSROOM\Users\Public\Pictures\Sample Pictures\Penguins.jpg -> \\KIDSROOM\Users\Public\Pictures\Sample Pictures\076E35C0-5E29-6BE8-5AE6-B07B09153CE9.thor
  • c:\Python27\include\longintrepr.h -> c:\Python27\include\076E35C0-5E29-6BE8-02F8-F6673CD296A8.thor
  • c:\Python27\include\objimpl.h -> c:\Python27\include\076E35C0-5E29-6BE8-193D-3053AE32CCEA.thor
  • c:\Python27\include\structseq.h -> c:\Python27\include\076E35C0-5E29-6BE8-CDFA-683CE3572FCB.thor
Network-Connects Host
  • bst.tw
  • 185.67.0.102
  • 185.102.136.127
Directory-Created
  • C:\Users\Harry Dresden\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\YLC2QM2Y
  • C:\Users\Harry Dresden\AppData\Local\Microsoft\Windows\Caches
Directory-Enumerated
  • c:\Python27\Lib\site-packages\pip\*
  • c:\Python27\tcl\tcl8\8.5\*
  • c:\ProgramData\Sun\*
  • c:\ProgramData\Microsoft\ClickToRun\MachineData\Catalog\Packages\*
  • \\KIDSROOM\Users\Default\Saved Games\*
  • c:\Python27\tcl\tk8.5\demos\images\*
  • \\KIDSROOM\Users\Public\Foxit Software\Foxit Reader\StartPage\start\en_us\*
  • c:\Users\ruiner\*
  • c:\Recovery\015e7760-d44b-11e0-8947-954f09601788\*
  • c:\PerfLogs\*
  • c:\ProgramData\Microsoft\OfficeSoftwareProtectionPlatform\*
  • \\KIDSROOM\Users\Harry Dresden\Links\*
  • c:\ProgramData\Passmark\*
  • \\KIDSROOM\Users\Harry Dresden\Pictures\*
  • c:\ProgramData\Microsoft\Device Stage\Task\{e35be42d-f742-4d96-a50a-1775fb1a7a42}\*
  • c:\Python27\Tools\pynche\X\*
  • c:\Users\Public\Music\Sample Music\*
  • c:\Python27\Lib\importlib\*
  • c:\Python27\tcl\tcl8.5\http1.0\*
  • c:\Python27\Lib\bsddb\*
  • c:\ProgramData\Microsoft\Windows Defender\Scans\CleanStore\ResourceData\17\*
  • c:\inetpub\wwwroot\aspnet_client\*
  • c:\ProgramData\Microsoft\Windows Defender\Scans\CleanStore\Resources\43\*
  • c:\ProgramData\Microsoft\Windows NT\MSFax\ActivityLog\*
  • c:\Python27\tcl\tk8.5\ttk\*
  • c:\ProgramData\Microsoft\ClickToRun\MachineData\Catalog\Packages\{9AC08E99-230B-47E8-9721-4577B7F124EA}\{1A8308C7-90D1-4200-B16E-646F163A08E8}\*
  • c:\Python27\Lib\site-packages\pip\_vendor\requests\packages\chardet\*
  • c:\Users\Default\Saved Games\*
  • c:\Python27\tcl\tcl8.5\tzdata\Africa\*
  • c:\ProgramData\Microsoft\Windows NT\MSFax\Common Coverpages\en-US\*
  • c:\Python27\Tools\i18n\*
  • c:\ProgramData\Microsoft\ClickToRun\*
  • c:\Python27\Lib\site-packages\pip\_vendor\lockfile\*
  • c:\ProgramData\Microsoft\ClickToRun\ProductReleases\C0D2A2B7-8AE4-4D06-93E4-F1A7BD5FEC3F\en-us.16\*
  • c:\ProgramData\*
  • c:\6cdeacda242012e0e5b593e657\Graphics\*
  • \\KIDSROOM\Users\Harry Dresden\Contacts\*
  • c:\Python27\Lib\site-packages\pip\_vendor\html5lib\treebuilders\*
  • c:\Python27\Lib\compiler\*
  • \\KIDSROOM\Users\Default\Desktop\*
  • c:\ProgramData\Microsoft\Windows NT\MSFax\*
  • c:\Users\Public\Foxit Software\Foxit Reader\StartPage\start\en_us\js\*
  • \\KIDSROOM\Users\Public\Foxit Software\Foxit Reader\StartPage\advertisement\*
  • c:\Python27\Lib\unittest\*
  • c:\Users\Public\Foxit Software\Foxit Reader\StartPage\start\en_us\tpl\*
  • \\KIDSROOM\Users\Public\Foxit Software\Foxit Reader\StartPage\start\en_us\js\*
  • c:\Python27\Lib\test\capath\*
  • c:\Users\Harry Dresden\Music\*
  • \\KIDSROOM\Users\Default\Downloads\*
  • c:\Users\Harry Dresden\OneDrive\*
  • c:\Python27\tcl\tcl8.5\msgs\*
  • c:\ProgramData\Adobe\Acrobat\11.0\*
  • c:\ProgramData\Microsoft\Diagnosis\DownloadedSettings\*
  • c:\ProgramData\Microsoft\ClickToRun\MachineData\Catalog\*
  • c:\ProgramData\Microsoft\Windows Defender\Scans\*
  • c:\Python27\tcl\tcl8.5\*
  • c:\Python27\Lib\unittest\test\*
  • c:\inetpub\wwwroot\aspnet_client\system_web\4_0_30319\*
  • c:\ProgramData\Microsoft\Network\Connections\*
  • c:\Users\Public\Recorded TV\*
  • c:\Users\Harry Dresden\Contacts\*
  • c:\ProgramData\Microsoft\Windows Defender\Scans\CleanStore\ResourceData\42\*
  • c:\ProgramData\Microsoft\ClickToRun\ProductReleases\C0D2A2B7-8AE4-4D06-93E4-F1A7BD5FEC3F\x-none.16\*
  • c:\Python27\tcl\tk8.5\msgs\*
  • \\KIDSROOM\Users\Public\Foxit Software\Foxit Reader\*
  • c:\Python27\tcl\tcl8.5\tzdata\Atlantic\*
  • c:\Python27\tcl\tcl8.5\tzdata\Europe\*
  • c:\qraimbuwvp\*
  • c:\ProgramData\WebEx\WebEx\*
  • \\KIDSROOM\Users\Default\Pictures\*
  • c:\Python27\tcl\tk8.5\demos\*
  • c:\ProgramData\Microsoft\Windows Defender\*
  • c:\ProgramData\Microsoft\PlayReady\Cache\*
  • c:\Python27\Lib\site-packages\pip\_vendor\distlib\_backport\*
  • c:\ProgramData\Microsoft\Windows Defender\Scans\CleanStore\ResourceData\01\*
  • c:\ProgramData\NovaTech Network\NovaBench\*
  • c:\Python27\tcl\tix8.4.3\demos\samples\*
  • c:\ProgramData\Microsoft\Windows NT\MSFax\SentItems\*
  • c:\Python27\Lib\site-packages\pip\_vendor\html5lib\treewalkers\*
  • c:\ProgramData\Microsoft\PlayReady\Cache\S-1-5-21-3416602863-1947377224-293699093-1001\*
  • c:\6cdeacda242012e0e5b593e657\1037\*
  • c:\Python27\Lib\lib-tk\test\*
  • c:\Users\Default\Pictures\*
  • \\KIDSROOM\Users\Harry Dresden\Searches\*
  • c:\ProgramData\Microsoft\ClickToRun\MachineData\Integration\*
  • c:\Python27\Lib\site-packages\pip\_vendor\pkg_resources\tests\*
  • c:\Python27\Lib\site-packages\pip\_vendor\html5lib\serializer\*
  • c:\ProgramData\Microsoft\Windows Defender\Scans\CleanStore\ResourceData\95\*
  • c:\inetpub\custerr\*
  • c:\6cdeacda242012e0e5b593e657\1033\*
  • c:\ProgramData\Microsoft\Windows Defender\Scans\CleanStore\ResourceData\47\*
  • c:\Python27\Lib\site-packages\pip\_vendor\requests\packages\urllib3\packages\*
  • c:\Python27\Scripts\*
  • c:\Users\Public\Desktop\*
  • c:\ProgramData\Microsoft\Network\Downloader\*
  • c:\ProgramData\Microsoft\Vault\AC658CB4-9126-49BD-B877-31EEDAB3F204\*
  • c:\Python27\Tools\pynche\*
  • c:\Python27\Lib\email\test\*
  • c:\ProgramData\Mozilla\logs\*
  • c:\qraimbuwvp\bin\*
  • \\KIDSROOM\Users\Default\*
  • c:\ProgramData\Microsoft\IdentityCRL\*
  • c:\ProgramData\Microsoft\WPD\*
  • c:\ProgramData\Microsoft\Diagnosis\LocalTraceStore\*
  • c:\ProgramData\Microsoft\Event Viewer\*
  • c:\Users\Harry Dresden\Favorites\Links for United States\*
  • c:\Users\Default\*
  • c:\ProgramData\Sun\Java\Java Update\*
  • c:\ProgramData\Microsoft\Windows Defender\Scans\CleanStore\Resources\17\*
  • \\KIDSROOM\Users\Harry Dresden\Favorites\*
  • c:\ProgramData\Microsoft\Windows Defender\Scans\CleanStore\ResourceData\43\*
  • c:\Python27\tcl\dde1.3\*
  • c:\Python27\Lib\ensurepip\_bundled\*
  • c:\ProgramData\Microsoft\Windows Defender\Scans\CleanStore\Resources\95\*
  • c:\ProgramData\Microsoft\ClickToRun\ProductReleases\53955D98-F46F-4906-AE49-9B6F52BA18A9\x-none.16\*
  • \\KIDSROOM\Users\Harry Dresden\Music\*
  • c:\PerfLogs\Admin\*
  • c:\Python27\Lib\site-packages\pip\_vendor\html5lib\treeadapters\*
  • c:\Python27\Lib\idlelib\*
  • c:\Python27\Lib\site-packages\pip\models\*
  • c:\inetpub\*
  • c:\Users\Harry Dresden\Saved Games\*
  • c:\inetpub\wwwroot\msmq\*
  • c:\ProgramData\Microsoft\DRM\*
  • c:\ProgramData\Microsoft\Crypto\RSA\*
  • c:\6cdeacda242012e0e5b593e657\1025\*
  • c:\Python27\Lib\test\crashers\*
  • c:\ProgramData\Microsoft\Search\Data\Applications\*
  • c:\Python27\Lib\ctypes\test\*
  • c:\Users\Public\Libraries\*
  • c:\ProgramData\Microsoft\Device Stage\*
  • c:\ProgramData\Microsoft\Device Stage\Device\*
  • c:\ProgramData\Microsoft\Windows NT\*
  • c:\ProgramData\Microsoft\Windows Defender\Scans\CleanStore\Resources\01\*
  • c:\Python27\Lib\site-packages\setuptools-16.0.dist-info\*
  • c:\Python27\Lib\xml\etree\*
  • c:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\*
  • c:\ProgramData\Microsoft\Windows Defender\Scans\CleanStore\Resources\F3\*
  • c:\Python27\Lib\test\*
  • c:\ProgramData\Adobe\Acrobat\11.0\Replicate\Security\*
  • c:\Python27\Lib\ctypes\macholib\*
  • c:\Python27\Lib\msilib\*
  • c:\Python27\Lib\site-packages\pip\_vendor\distlib\*
  • c:\6cdeacda242012e0e5b593e657\1035\*
  • c:\ProgramData\Microsoft\Windows Defender\Scans\CleanStore\ResourceData\DD\*
  • c:\ProgramData\Microsoft\Windows Defender\Scans\CleanStore\ResourceData\70\*
  • c:\ProgramData\Microsoft\Windows Defender\Scans\History\*
  • c:\Users\Default\Videos\*
  • c:\ProgramData\McAfee\MCLOGS\Common\*
  • c:\Users\Public\Foxit Software\Foxit Reader\StartPage\start\en_us\images\*
  • c:\Users\Default\Documents\*
  • c:\6cdeacda242012e0e5b593e657\1031\*
  • c:\Python27\tcl\tcl8.5\tzdata\Pacific\*
  • c:\Python27\tcl\tcl8.5\tzdata\America\North_Dakota\*
  • \\KIDSROOM\Users\Harry Dresden\Downloads\*
  • c:\ProgramData\Microsoft\ClickToRun\MachineData\Catalog\Packages\{9AC08E99-230B-47E8-9721-4577B7F124EA}\*
  • c:\Python27\tcl\tcl8.5\tzdata\Etc\*
  • c:\ProgramData\Microsoft\Windows Defender\Scans\CleanStore\Resources\DD\*
  • c:\ProgramData\Adobe\*
  • c:\ProgramData\Microsoft\Windows Defender\Scans\History\Results\*
  • c:\ProgramData\Microsoft\Windows Defender\Scans\CleanStore\Resources\*
  • c:\inetpub\history\CFGHISTORY_0000000001\*
  • \\KIDSROOM\Users\Harry Dresden\*
  • c:\ProgramData\Microsoft\Windows Defender\Scans\CleanStore\ResourceData\A6\*
  • c:\Python27\Lib\site-packages\pip\_vendor\pkg_resources\*
  • c:\Python27\Tools\webchecker\*
  • c:\ProgramData\Microsoft\Device Stage\Device\{8702d817-5aad-4674-9ef3-4d3decd87120}\*
  • c:\ProgramData\Microsoft\Windows Defender\Scans\CleanStore\Resources\A5\*
  • c:\ProgramData\Adobe\Acrobat\11.0\Replicate\*
  • c:\ProgramData\Microsoft\Windows Defender\Scans\History\CacheManager\*
  • c:\inetpub\history\CFGHISTORY_0000000005\*
  • c:\Users\Harry Dresden\Favorites\Links\*
  • c:\ProgramData\Microsoft\Assistance\*
  • c:\ProgramData\Microsoft\Assistance\Client\1.0\en-US\*
  • c:\inetpub\wwwroot\*
  • c:\Users\Harry Dresden\*
  • c:\Python27\tcl\tcl8.5\tzdata\Antarctica\*
  • c:\Python27\Lib\site-packages\pip\_vendor\*
  • c:\ProgramData\Microsoft\Windows NT\MSFax\VirtualInbox\en-US\*
  • c:\ProgramData\Microsoft\Windows Defender\Scans\CleanStore\ResourceData\E0\*
  • \\KIDSROOM\Users\Public\Downloads\*
  • c:\Users\Public\Downloads\*
  • c:\6cdeacda242012e0e5b593e657\2070\*
  • c:\Python27\Lib\test\cjkencodings\*
  • c:\ProgramData\Microsoft\Assistance\Client\1.0\*
  • \\KIDSROOM\Users\Default\Videos\*
  • c:\ProgramData\Microsoft\Windows Defender\Support\*
  • c:\Python27\Lib\site-packages\pip\operations\*
  • c:\ProgramData\Microsoft\MF\*
  • c:\6cdeacda242012e0e5b593e657\1029\*
  • c:\ProgramData\Microsoft\ClickToRun\MachineData\Integration\ShortcutBackups\*
  • c:\ProgramData\Microsoft\Windows Defender\Scans\CleanStore\Resources\1A\*
  • c:\Python27\Lib\distutils\tests\*
  • c:\ProgramData\Microsoft\Office\*
  • c:\Users\Public\Music\*
  • c:\Python27\tcl\tcl8.5\tzdata\SystemV\*
  • c:\6cdeacda242012e0e5b593e657\1045\*
  • c:\Users\Public\Foxit Software\Foxit Reader\StartPage\start\en_us\css\*
  • c:\Users\Harry Dresden\Desktop\*
  • c:\ProgramData\Microsoft\Windows Defender\Scans\History\Results\Resource\*
  • c:\ProgramData\Microsoft\Crypto\*
  • \\KIDSROOM\Users\Public\Foxit Software\*
  • c:\Users\Public\Pictures\*
  • c:\ProgramData\Mozilla\*
  • c:\ProgramData\Microsoft\Windows Defender\Definition Updates\Updates\*
  • c:\Python27\include\*
  • \\KIDSROOM\Users\Public\Foxit Software\Foxit Reader\StartPage\start\en_us\images\*
  • c:\Python27\Lib\lib2to3\tests\data\fixers\*
  • c:\Python27\Lib\encodings\*
  • c:\Python27\Lib\site-packages\setuptools\*
  • c:\Python27\Lib\test\tracedmodules\*
  • c:\ProgramData\Microsoft\Diagnosis\AsimovUploader\*
  • c:\ProgramData\Microsoft\Device Stage\Task\{07deb856-fc6e-4fb9-8add-d8f2cf8722c9}\en-US\*
  • c:\6cdeacda242012e0e5b593e657\1049\*
  • c:\Users\Public\Foxit Software\Foxit Reader\StartPage\start\*
  • \\KIDSROOM\Users\Public\Recorded TV\Sample Media\*
  • c:\Users\Public\Foxit Software\Foxit Reader\StartPage\start\en_us\*
  • c:\Python27\tcl\tcl8.5\tzdata\Mexico\*
  • \\KIDSROOM\Users\Harry Dresden\Favorites\Links\*
  • c:\ProgramData\Microsoft\RAC\*
  • \\KIDSROOM\Users\Public\Pictures\*
  • c:\Python27\Lib\site-packages\pip\_vendor\html5lib\*
  • \\KIDSROOM\Users\Public\Music\*
  • c:\Python27\tcl\tcl8.5\tzdata\Arctic\*
  • c:\ProgramData\Oracle\*
  • c:\ProgramData\Microsoft\Windows Defender\Scans\CleanStore\ResourceData\35\*
  • c:\ProgramData\NovaTech Network\NovaBench\3.0.2.0\media\*
  • c:\ProgramData\Microsoft\Windows Defender\Quarantine\*
  • c:\Python27\tcl\tcl8\*
  • c:\ProgramData\Microsoft\Windows NT\MSFax\Queue\*
  • c:\ProgramData\Microsoft\RAC\Outbound\*
  • c:\ProgramData\WebEx\*
  • c:\inetpub\history\CFGHISTORY_0000000003\*
  • c:\Python27\Lib\site-packages\setuptools\command\*
  • c:\Python27\tcl\tcl8.5\tzdata\Indian\*
  • c:\ProgramData\Microsoft\Event Viewer\Views\*
  • c:\Users\Default\Favorites\*
  • c:\*
  • c:\Users\Default\Desktop\*
  • \\KIDSROOM\Users\Public\Pictures\Sample Pictures\*
  • c:\ProgramData\Microsoft\eHome\logs\*
  • c:\ProgramData\Microsoft\Network\*
  • c:\Python27\tcl\tcl8.5\tzdata\America\Kentucky\*
  • c:\Python27\Lib\lib-tk\test\test_ttk\*
  • c:\Python27\tcl\tcl8.5\tzdata\US\*
  • c:\ProgramData\Microsoft\ClickToRun\UserData\*
  • c:\ProgramData\Microsoft\ClickToRun\MachineData\*
  • c:\Users\Public\Pictures\Sample Pictures\*
  • c:\6cdeacda242012e0e5b593e657\1041\*
  • c:\Users\Default\Downloads\*
  • c:\Python27\Lib\site-packages\pip\_vendor\requests\packages\urllib3\packages\ssl_match_hostname\*
  • c:\Users\Harry Dresden\Links\*
  • c:\Python27\DLLs\*
  • c:\ProgramData\Microsoft\User Account Pictures\*
  • c:\Python27\Lib\site-packages\pip\_vendor\requests\packages\urllib3\contrib\*
  • \\KIDSROOM\Users\Harry Dresden\OneDrive\*
  • c:\qraimbuwvp\modules\auxiliary\*
  • c:\Python27\tcl\tcl8.5\tzdata\Asia\*
  • c:\Users\Harry Dresden\Downloads\*
  • c:\Python27\tcl\tcl8.5\opt0.4\*
  • c:\ProgramData\Microsoft\Windows Defender\Scans\CleanStore\Resources\42\*
  • c:\Users\Public\Videos\*
  • c:\Python27\tcl\tcl8\8.4\*
  • c:\6cdeacda242012e0e5b593e657\1055\*
  • c:\ProgramData\Microsoft\Windows Defender\Scans\CleanStore\Resources\70\*
  • c:\ProgramData\Microsoft\Windows Defender\Scans\History\Store\*
  • c:\Python27\Tools\versioncheck\*
  • c:\ProgramData\Microsoft\Windows Defender\Scans\CleanStore\Resources\F7\*
  • c:\Python27\Lib\xml\dom\*
  • c:\Python27\Lib\lib2to3\tests\data\*
  • c:\ProgramData\Microsoft\Windows Defender\Scans\History\Service\*
  • \\KIDSROOM\Users\Harry Dresden\Desktop\*
  • c:\Python27\tcl\tcl8.5\encoding\*
  • c:\ProgramData\McAfee\*
  • c:\ProgramData\Microsoft\DRM\Server\*
  • c:\ProgramData\Microsoft\Diagnosis\ETLLogs\ShutdownLogger\*
  • c:\ProgramData\Microsoft\User Account Pictures\Default Pictures\*
  • \\KIDSROOM\Users\Public\Favorites\*
  • c:\ProgramData\Microsoft\Windows Defender\Scans\CleanStore\Resources\47\*
  • \\KIDSROOM\Users\Public\Documents\*
  • c:\Python27\Lib\xml\parsers\*
  • c:\ProgramData\Microsoft\Windows Defender\Scans\CleanStore\*
  • c:\6cdeacda242012e0e5b593e657\1038\*
  • c:\Python27\tcl\tix8.4.3\*
  • c:\Python27\Lib\site-packages\pip\_vendor\html5lib\trie\*
  • c:\Python27\tcl\tcl8.5\tzdata\Canada\*
  • c:\ProgramData\NovaTech Network\*
  • c:\ProgramData\Microsoft\WwanSvc\*
  • \\KIDSROOM\Users\*
  • c:\6cdeacda242012e0e5b593e657\1053\*
  • c:\Users\Default\Music\*
  • c:\Python27\Lib\test\decimaltestdata\*
  • c:\Python27\Lib\test\xmltestdata\*
  • c:\ProgramData\Passmark\PerformanceTest\*
  • c:\ProgramData\Microsoft\Windows Defender\Scans\CleanStore\ResourceData\*
  • c:\ProgramData\Microsoft\ClickToRun\ProductReleases\*
  • c:\Python27\tcl\reg1.2\*
  • c:\qraimbuwvp\modules\packages\*
  • \\KIDSROOM\Users\Public\*
  • \\KIDSROOM\Users\Harry Dresden\Documents\*
  • \\KIDSROOM\Users\Public\Music\Sample Music\*
  • c:\ProgramData\Microsoft\Diagnosis\ETLLogs\*
  • c:\6cdeacda242012e0e5b593e657\2052\*
  • c:\Python27\Lib\logging\*
  • c:\ProgramData\Microsoft\eHome\*
  • c:\Users\Public\*
  • c:\6cdeacda242012e0e5b593e657\1043\*
  • c:\Python27\Lib\site-packages\*
  • c:\ProgramData\Microsoft\NetFramework\BreadcrumbStore\*
  • c:\ProgramData\Microsoft\Diagnosis\UIF\*
  • c:\Users\Harry Dresden\Searches\*
  • c:\Users\Public\Foxit Software\Foxit Reader\StartPage\advertisement\*
  • c:\Python27\tcl\tk8.5\*
  • c:\Python27\Lib\xml\sax\*
  • c:\ProgramData\Microsoft\Vault\*
  • c:\Users\Default\Links\*
  • c:\Python27\Lib\json\tests\*
  • c:\Python27\libs\*
  • c:\6cdeacda242012e0e5b593e657\1028\*
  • c:\Python27\Lib\lib-tk\test\test_tkinter\*
  • c:\Users\Public\Foxit Software\Foxit Reader\*
  • c:\ProgramData\Microsoft OneDrive\*
  • c:\ProgramData\Microsoft\Crypto\DSS\MachineKeys\*
  • c:\Python27\Lib\ctypes\*
  • c:\Users\Public\Recorded TV\Sample Media\*
  • c:\Python27\*
  • c:\ProgramData\Microsoft\Crypto\DSS\*
  • c:\ProgramData\Microsoft\Diagnosis\Sideload\*
  • c:\Python27\Lib\email\*
  • \\KIDSROOM\Users\Public\Foxit Software\Foxit Reader\StartPage\start\en_us\tpl\*
  • c:\ProgramData\Microsoft\Search\Data\*
  • c:\Users\Harry Dresden\Documents\*
  • c:\ProgramData\Adobe\Setup\*
  • c:\Python27\Lib\distutils\*
  • c:\ProgramData\Microsoft\Windows NT\MSFax\Common Coverpages\*
  • c:\ProgramData\Microsoft\Device Stage\Task\*
  • c:\Users\*
  • \\KIDSROOM\Users\Default\Links\*
  • c:\ProgramData\Adobe\Setup\{AC76BA86-7AD7-1033-7B44-AB0000000001}\*
  • c:\qraimbuwvp\modules\*
  • c:\Python27\Lib\sqlite3\*
  • c:\ProgramData\Sun\Java\*
  • c:\ProgramData\Microsoft\NetFramework\*
  • c:\ProgramData\Microsoft\Device Stage\Task\{e35be42d-f742-4d96-a50a-1775fb1a7a42}\en-US\*
  • \\KIDSROOM\Users\Public\Foxit Software\Foxit Reader\StartPage\start\en_us\Default\*
  • c:\ProgramData\Microsoft\Crypto\Keys\*
  • c:\Python27\Lib\site-packages\pip\_vendor\cachecontrol\*
  • c:\Python27\Lib\bsddb\test\*
  • c:\ProgramData\Microsoft\Windows Defender\Definition Updates\{98101498-C465-4F51-8751-D1919E97D29D}\*
  • c:\ProgramData\NovaTech Network\NovaBench\3.0.2.0\*
  • c:\Recovery\*
  • c:\Users\Public\Foxit Software\*
  • c:\ProgramData\Microsoft\Windows Defender\Scans\CleanStore\Resources\A6\*
  • c:\inetpub\history\CFGHISTORY_0000000002\*
  • c:\Python27\Lib\site-packages\pip\req\*
  • c:\Users\Harry Dresden\Videos\*
  • \\KIDSROOM\Users\Public\Videos\Sample Videos\*
  • c:\inetpub\wwwroot\aspnet_client\system_web\*
  • c:\Python27\tcl\tcl8.5\tzdata\Australia\*
  • c:\Users\Harry Dresden\Pictures\*
  • c:\ProgramData\Microsoft\DeviceSync\*
  • c:\ProgramData\WebEx\WebEx\12_1324\*
  • c:\ProgramData\Microsoft\Office\Heartbeat\*
  • c:\Python27\Lib\lib2to3\tests\data\fixers\myfixes\*
  • \\KIDSROOM\Users\Public\Libraries\*
  • c:\Python27\Tools\Scripts\*
  • c:\Python27\Lib\hotshot\*
  • c:\ProgramData\Microsoft\*
  • c:\ProgramData\Microsoft\PlayReady\*
  • c:\Python27\Lib\site-packages\pip\utils\*
  • c:\ProgramData\Microsoft\Windows Defender\Scans\CleanStore\Entries\*
  • \\KIDSROOM\Users\Public\Recorded TV\*
  • c:\Users\Public\Foxit Software\Foxit Reader\StartPage\*
  • c:\Python27\tcl\tcl8.5\tzdata\Brazil\*
  • c:\Python27\Lib\site-packages\pkg_resources\_vendor\packaging\*
  • \\KIDSROOM\Users\Public\Desktop\*
  • c:\Python27\Lib\lib2to3\*
  • \\KIDSROOM\Users\Public\Foxit Software\Foxit Reader\StartPage\start\en_us\css\*
  • c:\Python27\tcl\tcl8.5\tzdata\America\Argentina\*
  • c:\ProgramData\Microsoft\Windows Defender\Scans\CleanStore\Resources\E0\*
  • c:\ProgramData\Microsoft\WwanSvc\Profiles\*
  • c:\ProgramData\Microsoft\Windows NT\MSFax\VirtualInbox\*
  • c:\Python27\Lib\test\subprocessdata\*
  • \\KIDSROOM\Users\Default\Favorites\*
  • c:\ProgramData\Microsoft\Windows Defender\Scans\History\Results\Quick\*
  • c:\Python27\Lib\site-packages\pip-7.0.1.dist-info\*
  • c:\Python27\Lib\site-packages\pip\_vendor\progress\*
  • \\KIDSROOM\Users\Harry Dresden\Saved Games\*
  • c:\ProgramData\Microsoft\Event Viewer\Views\ApplicationViewsRootNode\*
  • c:\ProgramData\Microsoft\Windows NT\MSFax\Inbox\*
  • c:\Python27\Lib\xml\*
  • c:\ProgramData\Microsoft\Search\*
  • c:\ProgramData\Microsoft\IlsCache\*
  • c:\Python27\tcl\tk8.5\images\*
  • e:\*
  • c:\Python27\Lib\sqlite3\test\*
  • c:\ProgramData\McAfee\MCLOGS\*
  • c:\Python27\Lib\ensurepip\*
  • c:\Python27\Lib\idlelib\Icons\*
  • c:\Python27\Lib\test\imghdrdata\*
  • c:\ProgramData\Microsoft\Diagnosis\*
  • c:\6cdeacda242012e0e5b593e657\*
  • c:\Python27\tcl\tcl8.5\tzdata\America\*
  • c:\Python27\Lib\site-packages\pkg_resources\_vendor\*
  • c:\6cdeacda242012e0e5b593e657\1030\*
  • c:\ProgramData\Microsoft\Windows Defender\Definition Updates\Backup\*
  • c:\ProgramData\Microsoft\Device Stage\Device\{113527a4-45d4-4b6f-b567-97838f1b04b0}\*
  • c:\Python27\tcl\tcl8.5\tzdata\*
  • c:\ProgramData\Microsoft\RAC\PublishedData\*
  • c:\Python27\Lib\site-packages\pip\_vendor\requests\packages\*
  • c:\qraimbuwvp\lib\*
  • \\KIDSROOM\Users\Default\Documents\*
  • c:\Python27\Lib\multiprocessing\dummy\*
  • \\KIDSROOM\Users\ruiner\*
  • c:\Python27\Lib\email\mime\*
  • c:\ProgramData\Microsoft\Diagnosis\ETLLogs\AutoLogger\*
  • c:\Python27\tcl\tix8.4.3\demos\bitmaps\*
  • c:\ProgramData\Microsoft\ClickToRun\ProductReleases\53955D98-F46F-4906-AE49-9B6F52BA18A9\en-us.16\*
  • c:\Users\Public\Documents\*
  • c:\6cdeacda242012e0e5b593e657\3082\*
  • c:\ProgramData\Microsoft\Device Stage\Task\{07deb856-fc6e-4fb9-8add-d8f2cf8722c9}\*
  • c:\ProgramData\Microsoft\OfficeSoftwareProtectionPlatform\Cache\*
  • c:\Python27\Lib\lib-tk\*
  • c:\Users\Harry Dresden\Favorites\*
  • c:\Python27\Doc\*
  • c:\Python27\Lib\curses\*
  • c:\ProgramData\Microsoft\ClickToRun\ProductReleases\C0D2A2B7-8AE4-4D06-93E4-F1A7BD5FEC3F\*
  • c:\Python27\Lib\lib2to3\pgen2\*
  • c:\ProgramData\Microsoft\Windows Defender\Scans\CleanStore\ResourceData\1A\*
  • c:\ProgramData\Microsoft\Windows Defender\Scans\CleanStore\ResourceData\A5\*
  • c:\ProgramData\Adobe\Acrobat\*
  • c:\Python27\Lib\*
  • c:\inetpub\history\CFGHISTORY_0000000004\schema\*
  • c:\Python27\tcl\tix8.4.3\demos\*
  • c:\6cdeacda242012e0e5b593e657\1042\*
  • c:\Python27\Lib\test\audiodata\*
  • c:\inetpub\history\CFGHISTORY_0000000004\*
  • c:\Python27\Lib\site-packages\pip\_vendor\requests\*
  • c:\Python27\Lib\site-packages\pip\_vendor\_markerlib\*
  • \\KIDSROOM\Users\Harry Dresden\Videos\*
  • c:\Python27\tcl\tcl8\8.4\platform\*
  • c:\ProgramData\Microsoft\ClickToRun\{9AC08E99-230B-47e8-9721-4577B7F124EA}\*
  • c:\qraimbuwvp\lib\common\*
  • c:\Python27\Lib\site-packages\pip\vcs\*
  • c:\6cdeacda242012e0e5b593e657\1046\*
  • c:\Users\Public\Foxit Software\Foxit Reader\StartPage\start\en_us\Default\*
  • c:\Python27\tcl\tix8.4.3\pref\*
  • c:\Python27\Lib\site-packages\pip\compat\*
  • \\KIDSROOM\Users\Public\Foxit Software\Foxit Reader\StartPage\*
  • \\KIDSROOM\Users\Default\Music\*
  • c:\Python27\Lib\json\*
  • c:\Python27\Lib\lib2to3\fixes\*
  • \\KIDSROOM\Users\Harry Dresden\Favorites\Links for United States\*
  • c:\ProgramData\Microsoft\Windows Defender\LocalCopy\*
  • c:\ProgramData\Microsoft\Assistance\Client\*
  • c:\ProgramData\Microsoft\Crypto\RSA\S-1-5-18\*
  • c:\Python27\Lib\test\leakers\*
  • c:\Users\Public\Videos\Sample Videos\*
  • c:\ProgramData\Microsoft\Media Player\*
  • c:\ProgramData\McAfee\MCLOGS\Common\jxpiinstall\*
  • c:\Python27\Lib\site-packages\pip\_vendor\html5lib\filters\*
  • c:\Python27\Tools\*
  • c:\6cdeacda242012e0e5b593e657\1044\*
  • c:\6cdeacda242012e0e5b593e657\1036\*
  • c:\qraimbuwvp\lib\api\*
  • c:\inetpub\history\*
  • c:\6cdeacda242012e0e5b593e657\1032\*
  • c:\Python27\tcl\tcl8.5\tzdata\Chile\*
  • c:\Python27\Lib\site-packages\pip\_vendor\packaging\*
  • c:\ProgramData\Microsoft\Windows NT\MSScan\*
  • c:\Python27\Lib\email\test\data\*
  • c:\Python27\tcl\tix8.4.3\bitmaps\*
  • c:\Python27\Lib\site-packages\pip\_vendor\colorama\*
  • c:\Python27\Lib\lib2to3\tests\*
  • c:\ProgramData\Microsoft\ClickToRun\ProductReleases\53955D98-F46F-4906-AE49-9B6F52BA18A9\*
  • \\KIDSROOM\Users\Public\Videos\*
  • c:\ProgramData\regid.1991-06.com.microsoft\*
  • c:\ProgramData\Microsoft\Windows Defender\Scans\CleanStore\ResourceData\F7\*
  • c:\ProgramData\Microsoft OneDrive\setup\*
  • c:\inetpub\history\CFGHISTORY_0000000005\schema\*
  • c:\Python27\Lib\site-packages\pip\_vendor\cachecontrol\caches\*
  • c:\Python27\Lib\distutils\command\*
  • \\KIDSROOM\Users\Public\Foxit Software\Foxit Reader\StartPage\start\*
  • c:\Python27\Lib\site-packages\pip\_vendor\requests\packages\urllib3\*
  • c:\Python27\tcl\*
  • c:\Python27\Lib\site-packages\pip\commands\*
  • c:\Python27\Lib\site-packages\pkg_resources\*
  • c:\ProgramData\Microsoft\Windows Defender\Scans\CleanStore\ResourceData\F3\*
  • c:\Python27\Lib\multiprocessing\*
  • c:\Python27\Lib\wsgiref\*
  • c:\ProgramData\Microsoft\Windows Defender\Scans\CleanStore\Resources\35\*
  • c:\Users\Public\Favorites\*
  • c:\Python27\Lib\pydoc_data\*
  • c:\Python27\Lib\site-packages\pip\_vendor\requests\packages\urllib3\util\*
  • c:\ProgramData\Microsoft\RAC\StateData\*
  • c:\Python27\tcl\tcl8.5\tzdata\America\Indiana\*
  • c:\Python27\Lib\site-packages\_markerlib\*
  • c:\qraimbuwvp\lib\core\*
  • c:\Python27\Lib\idlelib\idle_test\*
  • c:\inetpub\custerr\en-US\*
  • c:\ProgramData\Microsoft\Windows Defender\Definition Updates\*
  • c:\6cdeacda242012e0e5b593e657\1040\*
Registry Key-Opened
  • HKEY_CLASSES_ROOT\PROTOCOLS\Name-Space Handler\http\
  • HKEY_CURRENT_USER\Software
  • HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_INITIALIZE_URLACTION_SHELLEXECUTE_TO_ALLOW_KB936610
  • HKEY_LOCAL_MACHINE\Software\Microsoft\COM3
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings
  • HKEY_CURRENT_USER\SOFTWARE\Classes\PROTOCOLS\Filter\text/plain
  • HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\User Agent
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\MAIN\FeatureControl\FEATURE_USE_IETLDLIST_FOR_DOMAIN_DETERMINATION
  • HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings
  • HKEY_CLASSES_ROOT\.js
  • HKEY_LOCAL_MACHINE\Software\Policies
  • HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_ZONES_DEFAULT_DRIVE_INTRANET_KB941000
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\3
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\MAIN\FeatureControl\FEATURE_INITIALIZE_URLACTION_SHELLEXECUTE_TO_ALLOW_KB936610
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\MAIN\FeatureControl\FEATURE_ALLOW_REVERSE_SOLIDUS_IN_USERINFO_KB932562
  • HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\User Agent
  • HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_LOCALMACHINE_LOCKDOWN
  • HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\Session Manager\Environment
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\MAIN\FeatureControl\FEATURE_IGNORE_POLICIES_ZONEMAP_IF_ESC_ENABLED_KB918915
  • HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_ZONES_CHECK_ZONEMAP_POLICY_KB941001
  • HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\User Agent
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\User Agent\Pre Platform
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\MAIN\FeatureControl\FEATURE_LOCALMACHINE_LOCKDOWN
  • HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Security
  • HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\{5F058833-0652-4B15-B7EA-02DD7798ACE8}\0a-00-27-00-00-00
  • HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Internet Settings
  • HKEY_CURRENT_USER\Software\Policies\Microsoft\Internet Explorer
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\MAIN\FeatureControl\FEATURE_MIME_HANDLING
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Security
  • HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_PROTOCOL_LOCKDOWN
  • HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_SHOW_CERT_WARNINGS_ON_POST_FROM_ISTREAM_KB2894776
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\MAIN\FeatureControl\FEATURE_ZONES_CHECK_ZONEMAP_POLICY_KB941001
  • HKEY_LOCAL_MACHINE\Software
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\User Agent\Pre Platform
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\MAIN\FeatureControl\FEATURE_PROTOCOL_LOCKDOWN
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\User Agent\Post Platform
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\{5F058833-0652-4B15-B7EA-02DD7798ACE8}
  • HKEY_CLASSES_ROOT\PROTOCOLS\Name-Space Handler\*\
  • HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_USE_IETLDLIST_FOR_DOMAIN_DETERMINATION
  • HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_IGNORE_POLICIES_ZONEMAP_IF_ESC_ENABLED_KB918915
  • HKEY_CURRENT_USER\Software\Microsoft\Windows Script Host\Settings
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\0
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\1
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\2
  • HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_URLMON_IQDA_SIZE
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\4
  • HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_ALLOW_REVERSE_SOLIDUS_IN_USERINFO_KB932562
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\User Agent
  • HKEY_CURRENT_USER\Software\Policies
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\MAIN\FeatureControl\FEATURE_MAXCONNECTIONSPERSERVER
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\MAIN\FeatureControl\FEATURE_MAXCONNECTIONSPER1_0SERVER
  • HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad
  • HKEY_LOCAL_MACHINE\Software\Microsoft\Windows Script Host\Settings
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\PROTOCOLS\Filter\text/plain
  • HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\KindMap
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\MAIN\FeatureControl\FEATURE_URLMON_IQDA_SIZE
  • HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Connections
  • HKEY_CURRENT_USER\Software\Policies\Microsoft\Internet Explorer\Main
  • HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_MAXCONNECTIONSPERSERVER
  • HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_MAXCONNECTIONSPER1_0SERVER
  • HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\0a-00-27-00-00-00
  • HKEY_CURRENT_USER\SOFTWARE\Policies\Microsoft\Windows\CurrentVersion\Internet Settings
  • HKEY_LOCAL_MACHINE\System\Setup
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\MAIN\FeatureControl\FEATURE_ZONES_DEFAULT_DRIVE_INTRANET_KB941000
  • HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Internet Explorer\Main
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\User Agent\Post Platform
  • HKEY_CLASSES_ROOT\PROTOCOLS\Name-Space Handler\
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\MAIN\FeatureControl\FEATURE_BROWSER_EMULATION
  • HKEY_CLASSES_ROOT\JSFile\ScriptEngine
  • HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\UrlMon Settings
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings
  • HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_BROWSER_EMULATION
  • HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_MIME_HANDLING
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\MAIN\FeatureControl\FEATURE_SHOW_CERT_WARNINGS_ON_POST_FROM_ISTREAM_KB2894776
  • HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings
  • HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
  • HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows NT\Rpc
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\control\NetworkProvider\HwOrder
  • HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\VSS\VssAccessControl
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VBoxSF\NetworkProvider
  • HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\RDPNP\NetworkProvider
  • HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\VSS\Diag\VssapiPublisher
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\MiniNT
  • HKEY_LOCAL_MACHINE\Software\Microsoft\Rpc
  • HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Safeboot\Option
  • HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\LSA\AccessProviders
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\RDPNP\NetworkProvider
  • HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\WebClient\NetworkProvider
  • HKEY_LOCAL_MACHINE\Software\Microsoft\Ole
  • HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\VSS\Diag
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\LanmanWorkstation\NetworkProvider
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WebClient\NetworkProvider
  • HKEY_CURRENT_USER\Network\E
  • HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\ProductOptions
  • HKEY_LOCAL_MACHINE\system\CurrentControlSet\Control\NetworkProvider\Notifyees
  • HKEY_CURRENT_USER\Network
  • HKEY_PERFORMANCE_DATA\(Default)
  • HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\LDAP
  • HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\LanmanWorkstation\NetworkProvider
  • HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System
  • HKEY_LOCAL_MACHINE\system\CurrentControlSet
Registry Key-Deleted
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ProxyOverride
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ProxyServer
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\AutoDetect
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\{5F058833-0652-4B15-B7EA-02DD7798ACE8}\WpadDetectedUrl
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\0a-00-27-00-00-00\WpadDetectedUrl
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\AutoConfigURL
Registry Key-Read
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Cryptography\Providers\Trust\Initialization\{00AAC56B-CD44-11D0-8CC2-00C04FC295EE}\$Function
  • HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_LOCALMACHINE_LOCKDOWN\*
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ReceiveTimeOut
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ConnectTimeOut
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\NoSetFolders
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{00000566-0000-0010-8000-00AA006D2EA4}\(Default)
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{B4BFCC3A-DB2C-424C-B029-7FE99A87C641}\LocalizedName
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\MAIN\FeatureControl\FEATURE_LOCALMACHINE_LOCKDOWN\wscript.exe
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\crypt32\DiagMatchAnyMask
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\User Agent\Platform
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{B4BFCC3A-DB2C-424C-B029-7FE99A87C641}\ParsingName
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Rpc\Extensions\RemoteRpcDll
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\ShellFolder\NoFileFolderJunction
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{BCD1DE7E-2DB1-418B-B047-4A74E101F8C1}\ProxyStubClsid32\(Default)
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\exefile\NeverShowExt
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\.cer\(Default)
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced\HideIcons
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ConnectTimeOut
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\POLICIES\EXPLORER\DisallowRun
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\MAIN\FeatureControl\FEATURE_MIME_HANDLING\wscript.exe
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced\AutoCheckSelect
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{72C24DD5-D70A-438B-8A42-98424B88AFB8}\InProcServer32\InprocServer32
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{00000566-0000-0010-8000-00AA006D2EA4}\InprocServer32\InprocServer32
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ProxyEnable
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{B4BFCC3A-DB2C-424C-B029-7FE99A87C641}\InitFolderHandler
  • HKEY_CURRENT_USER\Directory\AlwaysShowExt
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{1B3EA5DC-B587-4786-B4EF-BD1DC332AEAE}\PreCreate
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\CPC\Volume\{b9fc2740-d442-11e0-8ee6-806e6f6e6963}\Data
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\.exe\Content Type
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{F6D90F16-9C73-11D3-B32E-00C04F990BB4}\ProgID\(Default)
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\ShellFolder\RestrictedAttributes
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\MAIN\FeatureControl\FEATURE_MAXCONNECTIONSPERSERVER\wscript.exe
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\IntranetName
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AllFilesystemObjects\IsShortcut
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{B196B286-BAB4-101A-B69C-00AA00341D07}\InprocServer32\(Default)
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Script Host\Settings\IgnoreUserSettings
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\MAIN\FeatureControl\FEATURE_MAXCONNECTIONSPER1_0SERVER\wscript.exe
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\0\Flags
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AllFilesystemObjects\DocObject
  • HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main\AdminTabProcs
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{0D43FE01-F093-11CF-8940-00A0C9054228}\ProgID\(Default)
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{1B3EA5DC-B587-4786-B4EF-BD1DC332AEAE}\RelativePath
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\SystemFileAssociations\.exe\IsShortcut
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{1B3EA5DC-B587-4786-B4EF-BD1DC332AEAE}\FolderTypeID
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{1B3EA5DC-B587-4786-B4EF-BD1DC332AEAE}\InfoTip
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced\DontPrettyPath
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\AllowFileCLSIDJunctions
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\DevicePath
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\User Agent\(Default)
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced\WebView
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\MAIN\FeatureControl\FEATURE_BROWSER_EMULATION\*
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{B196B286-BAB4-101A-B69C-00AA00341D07}\InprocServer32\ThreadingModel
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\MAIN\FeatureControl\FEATURE_PROTOCOL_LOCKDOWN\wscript.exe
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\POLICIES\EXPLORER\RestrictRun
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\ADODB.Stream\CLSID\(Default)
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced\MapNetDrvBtn
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Cryptography\Providers\Trust\Certificate\{00AAC56B-CD44-11D0-8CC2-00C04FC295EE}\$Function
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\MAIN\FeatureControl\FEATURE_MAXCONNECTIONSPER1_0SERVER\*
  • HKEY_CURRENT_USER\Directory\NeverShowExt
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\ExtendedLocale\en-US
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\MigrateProxy
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\2\Flags
  • HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\safer\codeidentifiers\LogFileName
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{00000566-0000-0010-8000-00AA006D2EA4}\InprocServer32\ThreadingModel
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\.js\(Default)
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\.chm\(Default)
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Script Host\Settings\Enabled
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Cryptography\Providers\Trust\FinalPolicy\{00AAC56B-CD44-11D0-8CC2-00C04FC295EE}\$DLL
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced\ShowTypeOverlay
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced\HideFileExt
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Lsa\FipsAlgorithmPolicy
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{1B3EA5DC-B587-4786-B4EF-BD1DC332AEAE}\Name
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\exefile\IsShortcut
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\exefile\shell\open\command\(Default)
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\crypt32\DiagLevel
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\ShellFolder\MapNetDriveVerbs
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\SeparateProcess
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\SystemFileAssociations\.exe\AlwaysShowExt
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Script Host\Settings\Timeout
  • HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Cryptography\PrivKeyCachePurgeIntervalSeconds
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\NoWebView
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\OLE\MaximumAllowedAllocationSize
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\MAIN\TabProcGrowth
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\KindMap\.exe
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\0a-00-27-00-00-00\WpadDhcp
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{1B3EA5DC-B587-4786-B4EF-BD1DC332AEAE}\ParsingName
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ProxyServer
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\SendTimeOut
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders\{1B3EA5DC-B587-4786-B4EF-BD1DC332AEAE}
  • HKEY_LOCAL_MACHINE\SYSTEM\Setup\SystemSetupInProgress
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\SESSION MANAGER\Environment\PROCESSOR_ARCHITECTURE
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\0a-00-27-00-00-00\WpadDecisionReason
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Setup\SourcePath
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\LDAP\UseOldHostResolutionOrder
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\CPC\Volume\{b9fc273c-d442-11e0-8ee6-806e6f6e6963}\Generation
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Folder\NeverShowExt
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced\ShowInfoTip
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\ShellFolder\WantsParseDisplayName
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\AutoConfigURL
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\ProxyBypass
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{B4BFCC3A-DB2C-424C-B029-7FE99A87C641}\Attributes
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{B196B286-BAB4-101A-B69C-00AA00341D07}\(Default)
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\POLICIES\EXPLORER\DontShowSuperHidden
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{2A1C9EB2-DF62-4154-B800-63278FCB8037}\ProxyStubClsid32\(Default)
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{0D43FE01-F093-11CF-8940-00A0C9054228}\InprocServer32\InprocServer32
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\POLICIES\EXPLORER\AllowFileCLSIDJunctions
  • HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main\SessionMerging
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\.bat\(Default)
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{0D43FE01-F093-11CF-8940-00A0C9054228}\InprocServer32\ThreadingModel
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{B196B286-BAB4-101A-B69C-00AA00341D07}\InprocServer32\InprocServer32
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\NonEnum\{20D04FE0-3AEA-1069-A2D8-08002B30309D}
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Directory\AlwaysShowExt
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\Locale\00000409
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\SpecialFoldersCacheSize
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\MAIN\FeatureControl\FEATURE_BROWSER_EMULATION\wscript.exe
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\POLICIES\EXPLORER\NoSetFolders
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\NoCommonGroups
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{B4BFCC3A-DB2C-424C-B029-7FE99A87C641}\FolderTypeID
  • HKEY_CURRENT_USER\Software\Microsoft\Windows Script Host\Settings\DisplayLogo
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SQMClient\Windows\DisabledSessions\MachineThrottling
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Cryptography\Defaults\Provider\Microsoft Enhanced RSA and AES Cryptographic Provider\Type
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{00000566-0000-0010-8000-00AA006D2EA4}\InprocServer32\(Default)
  • HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\EnableUTF8
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\COM3\COM+Enabled
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\User Agent\Version
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\MAIN\FeatureControl\FEATURE_MAXCONNECTIONSPERSERVER\*
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{B4BFCC3A-DB2C-424C-B029-7FE99A87C641}\Roamable
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Directory\BrowseInPlace
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{1B3EA5DC-B587-4786-B4EF-BD1DC332AEAE}\PublishExpandedPath
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{72C24DD5-D70A-438B-8A42-98424B88AFB8}\ProgID\(Default)
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{1B3EA5DC-B587-4786-B4EF-BD1DC332AEAE}\Category
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\.com\(Default)
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\exefile\BrowseInPlace
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{00000134-0000-0000-C000-000000000046}\ProxyStubClsid32\(Default)
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced\ShowSuperHidden
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\ShellFolder\QueryForInfoTip
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders\Desktop
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{B4BFCC3A-DB2C-424C-B029-7FE99A87C641}\InfoTip
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{B4BFCC3A-DB2C-424C-B029-7FE99A87C641}\LocalRedirectOnly
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Cryptography\Providers\Trust\Cleanup\{00AAC56B-CD44-11D0-8CC2-00C04FC295EE}\$DLL
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced\ShowCompColor
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\MAIN\FrameTabWindow
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{8A40A45D-055C-4B62-ABD7-6D613E2CEAEC}\ProxyStubClsid32\(Default)
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Directory\IsShortcut
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\NoPropertiesRecycleBin
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{00000566-0000-0010-8000-00AA006D2EA4}\ProgID\(Default)
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Lsa\AccessProviders\MartaExtension
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\NoPropertiesMyComputer
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\MAIN\FeatureControl\FEATURE_MIME_HANDLING\*
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Srp\GP\RuleCount
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\WinTrust\Trust Providers\Software Publishing\State
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\ShellFolder\HasNavigationEnum
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{1B3EA5DC-B587-4786-B4EF-BD1DC332AEAE}\ParentFolder
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{72C24DD5-D70A-438B-8A42-98424B88AFB8}\InProcServer32\ThreadingModel
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\3\1A10
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{B4BFCC3A-DB2C-424C-B029-7FE99A87C641}\Description
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\ShellState
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{1B3EA5DC-B587-4786-B4EF-BD1DC332AEAE}\Roamable
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Cryptography\Providers\Trust\Cleanup\{00AAC56B-CD44-11D0-8CC2-00C04FC295EE}\$Function
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Directory\NeverShowExt
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Drive\shellex\FolderExtensions\{fbeb8a05-beee-4442-804e-409d6c4515e9}\DriveMask
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{B4BFCC3A-DB2C-424C-B029-7FE99A87C641}\PreCreate
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\CreateUriCacheSize
  • HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\safer\codeidentifiers\PolicyScope
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{F6D90F16-9C73-11D3-B32E-00C04F990BB4}\(Default)
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\POLICIES\EXPLORER\NoCommonGroups
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{B4BFCC3A-DB2C-424C-B029-7FE99A87C641}\Security
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\NoControlPanel
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\CPC\Volume\{b9fc273d-d442-11e0-8ee6-806e6f6e6963}\Generation
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Lsa\FipsAlgorithmPolicy\Enabled
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\POLICIES\EXPLORER\NoNetCrawling
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Cryptography\Providers\Trust\Certificate\{00AAC56B-CD44-11D0-8CC2-00C04FC295EE}\$DLL
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\POLICIES\EXPLORER\NoSimpleStartMenu
  • HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Security\Safety Warning Level
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\.ade\(Default)
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Cryptography\Defaults\Provider\Microsoft Strong Cryptographic Provider\Type
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FileAssociation\AllowedReservedCharacters
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\POLICIES\EXPLORER\NoControlPanel
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\MAIN\SessionMerging
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\ShellFolder\WantsFORPARSING
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\SystemFileAssociations\.exe\BrowseInPlace
  • HKEY_CURRENT_USER\Directory\DocObject
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\MAIN\FeatureControl\FEATURE_PROTOCOL_LOCKDOWN\*
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\User Agent\(Default)
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Filter
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\ShellFolder\QueryForOverlay
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\ShellFolder\UseDropHandler
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\NoInternetIcon
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Scripting.FileSystemObject\CLSID\(Default)
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{0D43FE01-F093-11CF-8940-00A0C9054228}\InprocServer32\(Default)
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\.crt\(Default)
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\ShellFolder\WantsAliasedNotifications
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\POLICIES\EXPLORER\ClassicShell
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{72C24DD5-D70A-438B-8A42-98424B88AFB8}\InProcServer32\(Default)
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Connections\DefaultConnectionSettings
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\1\Flags
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Cryptography\Providers\Trust\Signature\{00AAC56B-CD44-11D0-8CC2-00C04FC295EE}\$DLL
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{B4BFCC3A-DB2C-424C-B029-7FE99A87C641}\PublishExpandedPath
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\crypt32\DebugHeapFlags
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{B4BFCC3A-DB2C-424C-B029-7FE99A87C641}\StreamResource
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Cryptography\Providers\Trust\Initialization\{00AAC56B-CD44-11D0-8CC2-00C04FC295EE}\$DLL
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\AutoDetect
  • HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main\FrameTabWindow
  • HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\safer\codeidentifiers\DefaultLevel
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Cryptography\Providers\Trust\CertCheck\{00AAC56B-CD44-11D0-8CC2-00C04FC295EE}\$Function
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\JScript\CLSID\(Default)
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\DontShowSuperHidden
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\MSXML2.XMLHTTP\CLSID\(Default)
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\ShellFolder\HideOnDesktopPerUser
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\SESSION MANAGER\SafeProcessSearchMode
  • HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_LOCALMACHINE_LOCKDOWN\wscript.exe
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\SendTimeOut
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Security\DisableSecuritySettingsCheck
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\POLICIES\EXPLORER\NoPropertiesMyComputer
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{F6D90F16-9C73-11D3-B32E-00C04F990BB4}\InProcServer32\(Default)
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WScript.Shell\CLSID\(Default)
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{B4BFCC3A-DB2C-424C-B029-7FE99A87C641}\RelativePath
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\MAIN\FeatureControl\FEATURE_LOCALMACHINE_LOCKDOWN\*
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\.bas\(Default)
  • HKEY_CURRENT_USER\Directory\BrowseInPlace
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{B4BFCC3A-DB2C-424C-B029-7FE99A87C641}\Name
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\POLICIES\EXPLORER\NoPropertiesRecycleBin
  • HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_BROWSER_EMULATION\wscript.exe
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\ShellFolder\WantsFORDISPLAY
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Cryptography\Defaults\Provider\Microsoft Enhanced RSA and AES Cryptographic Provider\Image Path
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{0D43FE01-F093-11CF-8940-00A0C9054228}\(Default)
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\NoNetCrawling
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{B4BFCC3A-DB2C-424C-B029-7FE99A87C641}\Icon
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{1B3EA5DC-B587-4786-B4EF-BD1DC332AEAE}\Description
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\User Agent\Platform
  • HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main\TabProcGrowth
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{72C24DD5-D70A-438B-8A42-98424B88AFB8}\(Default)
  • HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\CreateUriCacheSize
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\ShellFolder\Attributes
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Cryptography\Providers\Trust\Message\{00AAC56B-CD44-11D0-8CC2-00C04FC295EE}\$DLL
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{1B3EA5DC-B587-4786-B4EF-BD1DC332AEAE}\LocalizedName
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{26656EAA-54EB-4E6F-8F85-4F0EF901A406}\ProxyStubClsid32\(Default)
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\exefile\shell\open\command\DelegateExecute
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{1B3EA5DC-B587-4786-B4EF-BD1DC332AEAE}\Attributes
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Cryptography\Providers\Trust\FinalPolicy\{00AAC56B-CD44-11D0-8CC2-00C04FC295EE}\$Function
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\ShellFolder\PinToNameSpaceTree
  • HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\safer\codeidentifiers\Levels
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\.cpl\(Default)
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\CreateUriCacheSize
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ProxyOverride
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\POLICIES\EXPLORER\NoInternetIcon
  • HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\EnablePunycode
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\en-US
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\CPC\Volume\{b9fc273d-d442-11e0-8ee6-806e6f6e6963}\Data
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{B4BFCC3A-DB2C-424C-B029-7FE99A87C641}\Category
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\InheritConsoleHandles
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Script Host\Settings\UseWINSAFER
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\exefile\AlwaysShowExt
  • HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Cryptography\PrivKeyCacheMaxItems
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SQMClient\Windows\DisabledSessions\GlobalSession
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\0\1806
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Directory\DocObject
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ReceiveTimeOut
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{1B3EA5DC-B587-4786-B4EF-BD1DC332AEAE}\Security
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders\AppData
  • HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\safer\codeidentifiers\SaferFlags
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{1B3EA5DC-B587-4786-B4EF-BD1DC332AEAE}\StreamResource
  • HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\EnablePunycode
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\MAIN\AdminTabProcs
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Script Host\Settings\TrustPolicy
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\User Agent\Compatible
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\User Agent\Version
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SQMClient\Windows\DisabledProcesses\DA0C75D6
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\ShellFolder\WantsUniversalDelegate
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\.adp\(Default)
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\exefile\shell\open\command\command
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\LDAP\UseHostnameAsAlias
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced\NoNetCrawling
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{1B3EA5DC-B587-4786-B4EF-BD1DC332AEAE}\InitFolderHandler
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\POLICIES\EXPLORER\SeparateProcess
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\SystemFileAssociations\.exe\DocObject
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Cryptography\Providers\Trust\Message\{00AAC56B-CD44-11D0-8CC2-00C04FC295EE}\$Function
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\exefile\shell\open\NoWorkingDirectory
  • HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\safer\codeidentifiers\TransparentEnabled
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\Language Groups\1
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{B4BFCC3A-DB2C-424C-B029-7FE99A87C641}\Stream
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\JSFile\ScriptEngine\(Default)
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\{5F058833-0652-4B15-B7EA-02DD7798ACE8}\WpadDecision
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\.cmd\(Default)
  • HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\SpecialFoldersCacheSize
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\ClassicShell
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\0a-00-27-00-00-00\WpadDecisionTime
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\0a-00-27-00-00-00\WpadDecision
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\0\1806
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\SpecialFoldersCacheSize
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Script Host\Settings\LogSecuritySuccesses
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\EnablePunycode
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Cryptography\Providers\Trust\CertCheck\{00AAC56B-CD44-11D0-8CC2-00C04FC295EE}\$DLL
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\CPC\Volume\{b9fc2740-d442-11e0-8ee6-806e6f6e6963}\Generation
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Cryptography\MachineGuid
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AllFilesystemObjects\BrowseInPlace
  • HKEY_CURRENT_USER\Directory\IsShortcut
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced\IconsOnly
  • HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Cryptography\PrivateKeyLifetimeSeconds
  • HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_BROWSER_EMULATION\*
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\3\Flags
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\LDAP\LdapClientIntegrity
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\AutoDetect
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\ShellFolder\HideInWebView
  • HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\SpecialFoldersCacheSize
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced\SeparateProcess
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{B4BFCC3A-DB2C-424C-B029-7FE99A87C641}\StreamResourceType
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{1B3EA5DC-B587-4786-B4EF-BD1DC332AEAE}\StreamResourceType
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\DisallowRun
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{B4BFCC3A-DB2C-424C-B029-7FE99A87C641}\ParentFolder
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Folder\DocObject
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\MAIN\FrameMerging
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Script Host\Settings\DisplayLogo
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Cryptography\Providers\Trust\Signature\{00AAC56B-CD44-11D0-8CC2-00C04FC295EE}\$Function
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\POLICIES\EXPLORER\NoWebView
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{F6D90F16-9C73-11D3-B32E-00C04F990BB4}\InProcServer32\ThreadingModel
  • HKEY_CURRENT_USER\Software\Microsoft\Windows Script Host\Settings\Timeout
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\User Agent\Compatible
  • HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\CreateUriCacheSize
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Cryptography\Defaults\Provider\Microsoft Strong Cryptographic Provider\Image Path
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{55272A00-42CB-11CE-8135-00AA004BB851}\ProxyStubClsid32\(Default)
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\POLICIES\EXPLORER\InheritConsoleHandles
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{F935DC20-1CF0-11D0-ADB9-00C04FD58A0B}\1.0\0\win64\(Default)
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{1B3EA5DC-B587-4786-B4EF-BD1DC332AEAE}\Icon
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{1B3EA5DC-B587-4786-B4EF-BD1DC332AEAE}\LocalRedirectOnly
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{F6D90F16-9C73-11D3-B32E-00C04F990BB4}\InProcServer32\InprocServer32
  • HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Security\DisableSecuritySettingsCheck
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\CPC\Volume\{b9fc273c-d442-11e0-8ee6-806e6f6e6963}\Data
  • HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main\FrameMerging
  • HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Security_HKLM_only
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\.asp\(Default)
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\exefile\shell\open\SetWorkingDirectoryFromTarget
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\0a-00-27-00-00-00\WpadDns
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\{5F058833-0652-4B15-B7EA-02DD7798ACE8}\WpadDecisionTime
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\.exe\(Default)
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\ShellFolder\HideFolderVerbs
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\GRE_Initialize\DisableMetaFiles
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\4\Flags
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Hidden
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AllFilesystemObjects\NeverShowExt
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\ShellFolder\CallForAttributes
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Folder\IsShortcut
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\WpadExpirationDays
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\NoSimpleStartMenu
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{1B3EA5DC-B587-4786-B4EF-BD1DC332AEAE}\Stream
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\RestrictRun
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Folder\BrowseInPlace
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Connections\SavedLegacySettings
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\exefile\DocObject
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\SystemFileAssociations\.exe\NeverShowExt
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\0a-00-27-00-00-00\WpadDetectedUrl
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WebClient\NetworkProvider\Name
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WebClient\NetworkProvider\ProviderPath
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Rpc\MaxRpcSize
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System\EnableLinkedConnections
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WebClient\NetworkProvider\Class
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\Locale\00000409
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\RDPNP\NetworkProvider\Class
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\LDAP\UseHostnameAsAlias
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WebClient\NetworkProvider\name
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\en-US
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VBoxSF\NetworkProvider\Class
  • HKEY_LOCAL_MACHINE\SYSTEM\Setup\SystemSetupInProgress
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\LDAP\LdapClientIntegrity
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VBoxSF\NetworkProvider\ProviderPath
  • HKEY_LOCAL_MACHINE\SYSTEM\Setup\OOBEInProgress
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\RDPNP\NetworkProvider\Name
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\RDPNP\NetworkProvider\ProviderPath
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\LanmanWorkstation\NetworkProvider\Name
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\(Default)
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\LDAP\UseOldHostResolutionOrder
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SQMClient\Windows\CEIPSampledIn
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\NetworkProvider\HwOrder\ProviderOrder
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\Language Groups\1
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SQMClient\Windows\CEIPEnable
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\ExtendedLocale\en-US
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\LanmanWorkstation\NetworkProvider\ProviderPath
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Lsa\AccessProviders\MartaExtension
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\ComputerName\ActiveComputerName\ComputerName
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\RDPNP\NetworkProvider\name
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\LanmanWorkstation\NetworkProvider\name
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\OLE\MaximumAllowedAllocationSize
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\ProductOptions\ProductType
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VBoxSF\NetworkProvider\name
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\LanmanWorkstation\NetworkProvider\Class
Registry Key-Written
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\{5F058833-0652-4B15-B7EA-02DD7798ACE8}\WpadDecisionReason
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\AutoDetect
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\ProxyBypass
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\{5F058833-0652-4B15-B7EA-02DD7798ACE8}\WpadDecision
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\{5F058833-0652-4B15-B7EA-02DD7798ACE8}\WpadDecisionTime
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ProxyEnable
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\IntranetName
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\{5F058833-0652-4B15-B7EA-02DD7798ACE8}\WpadNetworkName
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\0a-00-27-00-00-00\WpadDecision
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\UNCAsIntranet
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Connections\SavedLegacySettings
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\0a-00-27-00-00-00\WpadDecisionReason
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\0a-00-27-00-00-00\WpadDecisionTime
Mutex-Accessed
  • Local\ZonesCacheCounterMutex
  • Local\ZonesLockedCacheCounterMutex

Processes

registry filesystem process services network synchronization

C:\Windows\system32\lsass.exe PID: 460, Parent PID: 364

"C:\Windows\System32\wscript.exe" C:\Users\HARRYD~1\AppData\Local\Temp\NRV_089P9P3_.js PID: 5840, Parent PID: 5132

"C:\Windows\SysWOW64\rundll32.exe" C:\Users\HARRYD~1\AppData\Local\Temp\N9BBIQ~1.DLL,boobs PID: 6084, Parent PID: 5840

Volatility

Nothing to display.