'
metaflows logo
Category Started On Completed On Duration Cuckoo Version
FILE 2016-12-08 22:10:04.550118 2016-12-08 22:12:21.194980 136 seconds 2.0-dev
Machine Label Manager Started On Shutdown On
win7cuckoo win7 Clone 1 VirtualBox 2016-12-08 22:10:04 2016-12-08 22:12:20

File Details

File name 029b94d6d3d39529ee154cb30abf85cf3eccb16b.zip
File size 3419 bytes
File type Zip archive data, at least v2.0 to extract
CRC32 A114AC88
MD5 ee229679b19759afdcf97ac50bbbd118
SHA1 029b94d6d3d39529ee154cb30abf85cf3eccb16b
SHA256 785dbf93b1a89248fe1d930ceaeafb03da47bbe5c70540c4df5a4fc13f9b3f1e
SHA512 bb37647020470ecd38d0a1ea37754db8952a7c307a1bbea1dc261526b12fd5fbff312fda3388fc26ab806dee2457a6c50c304290b0bf24bfde7ed41162eb88f6
Ssdeep 96:hsohm8dAM6n452Sq+xtKp148X9DFVHp9HuRkGJSZKst:UEAM6nfB+xtKp+Q/HpwRkGM4st
PEiD None matched
Yara
  • PM_Zip_with_js ()
VirusTotal Permalink
VirusTotal Scan Date: 2016-12-08 21:57:10
Detection Rate: 3/56 (Expand)

MetaFlows Scores

Metaflows Analysis Results (Signatures=125, Anomalies=0, PEiD=0, Yara=2, VT[1481235164]=0): Snort Events=0, AV Events=0
Total Score=125

Dropped File/Buffer Yara Signatures:
7b59935fa5839fb7dc2cde4c13a8b67c0a39b6f7 [BUFFER]: Str_Win32_Http_API

Signatures

antivm_queries_computername details
recon_fingerprint details
antivm_memory_available details
dumped_buffer details
creates_doc details
antivm_network_adapters details
dumped_buffer2 details
antivm_vbox_files details
Windows_Proxy_Tinkering details
network_wscript_downloader details
persistence_ads details
antiav_detectfile details
exploit_heapspray details
malicious_document_urls details
network_document_file details
antivm_vbox_devices details
antivm_vbox_files details
modifies_files details

Screenshots

No screenshots available.

Static Analysis

Nothing to display.

Dropped Files

48e1d5cf2db9ac14_076e35c0--5e29--6be8--b8720fed--b3cf9af5789d.osiris

5ec46c51eac961dc_076e35c0--5e29--6be8--e1153321--b791aae94986.osiris

07122202ed489ac2_076e35c0--5e29--6be8--7409a823--41c76bb46930.osiris

30dc2373d0d084bb_076e35c0--5e29--6be8--6e84b0ba--cddac52f52bd.osiris

9acc6f761e592cde_076e35c0--5e29--6be8--b0f0b337--00962ad1a984.osiris

7ded0a5aaf459c36_076e35c0--5e29--6be8--0efe5d3c--3cff321466ec.osiris

623daa6db61216f3_076e35c0--5e29--6be8--310fbef1--89a5e238fd83.osiris

3982124a51401f13_076e35c0--5e29--6be8--0cfcb0f1--42c1ef457881.osiris

2e09fd20f36dcd2b_076e35c0--5e29--6be8--f98276a8--ad207cbfd3a5.osiris

94700353a9ada62f_076e35c0--5e29--6be8--988115c0--e17713c02f87.osiris

d9aa983d8ad25eea_076e35c0--5e29--6be8--daa939b1--a7b82699241d.osiris

68632a2fd5aecc75_076e35c0--5e29--6be8--d6697fea--f352676a30a6.osiris

36e302a42202adab_076e35c0--5e29--6be8--c1e9f0a8--be3a12315225.osiris

50ec1349046aa884_076e35c0--5e29--6be8--a6245f9b--43596877162b.osiris

d0787c7be13339af_076e35c0--5e29--6be8--50cf6252--02af60e2a914.osiris

fa5fdc16a4579f15_076e35c0--5e29--6be8--be9ead13--2049cb29ffb6.osiris

c742eb2b4e2625f3_076e35c0--5e29--6be8--11eb7198--d0a54d9658b9.osiris

fabb0f65d792486d_076e35c0--5e29--6be8--be3948a3--54beb4b99c94.osiris

79ba7d1765a116f8_076e35c0--5e29--6be8--02daa69e--bf321c23a6b7.osiris

e5eb712d6f19ff84_076e35c0--5e29--6be8--9accd888--ee522d2b82ff.osiris

a96587643afac597_076e35c0--5e29--6be8--dcdda6a4--33de0113f0ea.osiris

96c839f2957c1a1e_076e35c0--5e29--6be8--8fe95800--614ed385143f.osiris

987aa12913ff3892_076e35c0--5e29--6be8--b0350204--96ed822fcef0.osiris

572f5283083e0f99_076e35c0--5e29--6be8--16a96608--be696e5960ea.osiris

9a162f6283c44285_076e35c0--5e29--6be8--f1795e3a--351026e6947a.osiris

cf7ad15f4629aaa4_076e35c0--5e29--6be8--acc53b55--2448ff1b41ca.osiris

d28a9578d53a894f_076e35c0--5e29--6be8--1046941c--740011efd72b.osiris

4166d095259be48d_076e35c0--5e29--6be8--c4d94f3c--ff224327b07b.osiris

d9aafb5e87e06f36_076e35c0--5e29--6be8--bea3b724--6b38d8cafad9.osiris

0a18fe22b28f756c_076e35c0--5e29--6be8--752836cd--81d11065b34f.osiris

eb58ae5bc22e6cd9_076e35c0--5e29--6be8--351618ce--4f9e14ff66e7.osiris

3f8777bff943f10b_076e35c0--5e29--6be8--fe02b529--9f6d7e1f66c4.osiris

d89136d9a820fa27_076e35c0--5e29--6be8--b098603a--2e967a519d02.osiris

faad65ced63559ca_076e35c0--5e29--6be8--edfef249--a8ff50c500a4.osiris

2c65bad6e91d4bf7_076e35c0--5e29--6be8--360b24eb--1d7043826129.osiris

991cab0b7c04a53d_076e35c0--5e29--6be8--39ba852d--a82da5762cae.osiris

d774ebdef8e4261b_076e35c0--5e29--6be8--698e7b14--974cce6cbca2.osiris

10e02fae7693301a_076e35c0--5e29--6be8--98ec6e2f--ad77606d0279.osiris

bbacd8f66f0c621e_076e35c0--5e29--6be8--38595078--f4658c495915.osiris

40086abf76dc6ac5_076e35c0--5e29--6be8--471c9857--4cc55572aa36.osiris

c5391b6040c17d15_sdtqn9ol3egi

a77f3e9ac9ff840b_076e35c0--5e29--6be8--136bc325--f8f78a7f3a1d.osiris

31b5d7bbf4102969_076e35c0--5e29--6be8--3ee8ec70--913981e3df8f.osiris

d556c0557b857642_076e35c0--5e29--6be8--b4ac325a--15f58b38f83f.osiris

5530c93a67e3482a_076e35c0--5e29--6be8--f06089d1--b9015b64f8b7.osiris

50b7bee6dae4e769_076e35c0--5e29--6be8--6c09a162--04c46e070425.osiris

1612675d11c026a9_076e35c0--5e29--6be8--d5648ca7--738ab0e50881.osiris

5f2d9ed441f386b7_sdtqn9ol3egi.zk

0d0b21a8af8d6aeb_076e35c0--5e29--6be8--69e00089--624e5d4fa4d2.osiris

81c121546775d328_076e35c0--5e29--6be8--1d4143bd--2047304009df.osiris

938f5d856734d519_076e35c0--5e29--6be8--3f2eff18--31bbc21f2692.osiris

cc3b34bfa540db87_076e35c0--5e29--6be8--23292f4b--c6ebb010703b.osiris

880bb9a1234caca3_076e35c0--5e29--6be8--e474743e--6f05bf2e8999.osiris

1f1ce08b53420ebe_076e35c0--5e29--6be8--43c3a412--95bc87d36131.osiris

31b22800e0a4005a_076e35c0--5e29--6be8--803316b2--8f762e2aeafc.osiris

d852adbf05588c94_076e35c0--5e29--6be8--c513e701--ed0ceeee88aa.osiris

267a86b9cbbb95cc_076e35c0--5e29--6be8--c8bf8cc9--eca5a66dbbb6.osiris

d05a86078bb358b3_076e35c0--5e29--6be8--4948b0b7--0da93b164132.osiris

41f80ac3fb41cf9b_076e35c0--5e29--6be8--181b46e0--519d70977123.osiris

2d30bf6b314f9818_076e35c0--5e29--6be8--30a6ab30--5d8aae287323.osiris

7a6158c469306376_076e35c0--5e29--6be8--471b035c--6a7d8dd8f1dc.osiris

7d1a9d94df74df5f_076e35c0--5e29--6be8--b45caf34--d15ae0f903c9.osiris

713c5dc70756e531_076e35c0--5e29--6be8--d4d6000a--76c3df036bfd.osiris

84a3535ed7674bcd_076e35c0--5e29--6be8--8e2c0b2c--0bf6eb5d0460.osiris

1797d7ddd2e1c8d7_076e35c0--5e29--6be8--160df83a--371f649f4e3f.osiris

f72b136878c74cb5_076e35c0--5e29--6be8--3f40a127--94046850bba7.osiris

ab42bba97fa1fbf7_076e35c0--5e29--6be8--204f54fa--7165ec3c2e40.osiris

d2305406168fd109_076e35c0--5e29--6be8--b8e7ed32--95c9026af0d6.osiris

27d4bc81d6f0e39f_076e35c0--5e29--6be8--303d1b89--a97539e9a0eb.osiris

1e613f294eaa35ba_076e35c0--5e29--6be8--178d6d37--91463e34c082.osiris

627afa1e1dc0d58c_076e35c0--5e29--6be8--3dc3520b--9acd7c9307d5.osiris

df3f8c06f4105e14_076e35c0--5e29--6be8--1d836000--e63c39069234.osiris

067841d19360248d_076e35c0--5e29--6be8--50f8b6b5--81828ccd5b6f.osiris

5f82339d1ab4e81e_076e35c0--5e29--6be8--4e3f2987--dd3fb0f7a196.osiris

7a319335a6956bf3_076e35c0--5e29--6be8--74939f1d--41d0d614c708.osiris

2f79c45bd15ce025_076e35c0--5e29--6be8--81746ddf--f29ab01e2b5b.osiris

4985d1d66d1d1e7e_076e35c0--5e29--6be8--b83d855d--ed4567e8c26a.osiris

f0416d1eb549a534_076e35c0--5e29--6be8--f2c2ca1b--d5e31b12f8e7.osiris

c6f01d41dcf808a8_076e35c0--5e29--6be8--7633ded3--106422e17388.osiris

c7c087636f276b85_076e35c0--5e29--6be8--b684498b--4de08427ea65.osiris

26a6d006c92322f9_076e35c0--5e29--6be8--193a0aab--2ed532808d6b.osiris

903624c5adf441d9_076e35c0--5e29--6be8--8f184bab--f93919116041.osiris

3ce417278f3258eb_076e35c0--5e29--6be8--49bd282b--57d5614dd114.osiris

c6b1966fd70890c4_076e35c0--5e29--6be8--71cf9386--de1d6fda2267.osiris

98fdade758ae01fd_076e35c0--5e29--6be8--efb28267--454dfff93745.osiris

22a4cf9c9616c98a_076e35c0--5e29--6be8--dc33005d--c411141d181c.osiris

96889dc240fc29ca_076e35c0--5e29--6be8--5095b489--7639e49839cc.osiris

6b62561b8e1fbe12_076e35c0--5e29--6be8--6cd2b81a--a3b192f71c22.osiris

e76f464f4141425b_076e35c0--5e29--6be8--aaae4661--f5d5ed101145.osiris

b9b5d2e1ed55901f_076e35c0--5e29--6be8--a891bd53--69ccb81ee1a0.osiris

e008fe57f1c8a44c_076e35c0--5e29--6be8--6df60e48--abaf8d757ca8.osiris

897743af05aa5557_076e35c0--5e29--6be8--d2375b13--e2a421e2868d.osiris

e577e073e532303d_076e35c0--5e29--6be8--920574c3--d096f6d42841.osiris

9f4dd9ccf76ccbb7_076e35c0--5e29--6be8--3ce29387--217f1ec504fd.osiris

0356ac48a114f6ed_076e35c0--5e29--6be8--01345012--b658a319d8c1.osiris

42ff9ec89fcd17a2_076e35c0--5e29--6be8--94750715--3d2f33419409.osiris

77b4c224f710c260_076e35c0--5e29--6be8--616db204--1ed907b2bbc7.osiris

2d1fbaf5bb09d202_076e35c0--5e29--6be8--74b8c39f--d7d7c30209f3.osiris

d4964e1590b6d612_076e35c0--5e29--6be8--2d67c50c--426eeee1e0a2.osiris

288f62ab07de8405_076e35c0--5e29--6be8--8fab088b--9b61b1b10daf.osiris

70133fec452f4bb8_076e35c0--5e29--6be8--9603beea--4141a9571c4b.osiris

2924f0cab44e324b_osiris-0c4e.htm

8ce1c531d8e90540_076e35c0--5e29--6be8--b153e938--0e3bcda956b5.osiris

cbab0daa8653f7b8_076e35c0--5e29--6be8--cc245a2c--19adcb9c5c65.osiris

0612b9b623cc1f74_076e35c0--5e29--6be8--b3b23066--ac55b541c152.osiris

ce90ee674a5018eb_076e35c0--5e29--6be8--4ac59cc3--09906b0f3cf6.osiris

~4066KG2TA4Y15BWI3D10KFX7.js

Network Analysis

Hosts Involved

DNS Requests

HTTP Requests

Behavior Summary

File-Read
  • C:\Users\Harry Dresden\AppData\Local\Temp\sdtqn9ol3egI.zk
  • C:\Users\Harry Dresden\AppData\Local\Temp\~4066KG2TA4Y15BWI3D10KFX7.js
  • C:\Windows\System32\wshom.ocx
  • C:\Users\Harry Dresden\AppData\Local\Temp\sdtqn9ol3egI
  • C:\Windows\System32\msxml3.dll
  • C:\Users\Harry Dresden\Desktop\desktop.ini
  • C:\Windows\System32\wscript.exe
  • UNC\SHARDREALM\Users\Harry Dresden\Downloads\cleandesktop.py.txt
  • c:\Python27\include\pyexpat.h
  • c:\Python27\include\object.h
  • UNC\SHARDREALM\Users\Public\Foxit Software\Foxit Reader\StartPage\start\en_us\Default\line.jpg
  • c:\Python27\Lib\test\keycert3.pem
  • UNC\SHARDREALM\Users\Public\Pictures\Sample Pictures\Desert.jpg
  • UNC\SHARDREALM\Users\Public\Foxit Software\Foxit Reader\StartPage\advertisement\ribbon Protect Sensitive PDF Documents.bmp
  • c:\Python27\Lib\test\https_svn_python_org_root.pem
  • c:\Python27\Lib\test\ssl_cert.pem
  • UNC\SHARDREALM\Users\Public\Foxit Software\Foxit Reader\StartPage\start\en_us\images\phantomPDF_b.png
  • UNC\SHARDREALM\Users\Public\Foxit Software\Foxit Reader\StartPage\advertisement\ribbon Fastest PDF Search and Index.bmp
  • c:\Python27\include\pyerrors.h
  • UNC\SHARDREALM\Users\Public\Foxit Software\Foxit Reader\StartPage\advertisement\normal Protect your PDF files with AD RMS.bmp
  • UNC\SHARDREALM\Users\Public\Foxit Software\Foxit Reader\StartPage\advertisement\ribbon Protect your PDF files with AD RMS.bmp
  • c:\Python27\include\descrobject.h
  • c:\Python27\include\Python-ast.h
  • c:\Python27\include\osdefs.h
  • UNC\SHARDREALM\Users\Public\Foxit Software\Foxit Reader\StartPage\start\en_us\js\nor.js
  • UNC\SHARDREALM\Users\Public\Foxit Software\Foxit Reader\StartPage\start\en_us\images\blank.gif
  • c:\Python27\include\pymacconfig.h
  • c:\Python27\include\ceval.h
  • \\?\PIPE\browser
  • c:\Python27\include\pythonrun.h
  • c:\Python27\include\pymem.h
  • c:\Python27\Lib\site-packages\pip\_vendor\requests\cacert.pem
  • c:\Python27\include\pyarena.h
  • UNC\SHARDREALM\Users\Harry Dresden\Desktop\eHPRzxmJiIkx.rtf
  • UNC\SHARDREALM\Users\Public\Foxit Software\Foxit Reader\StartPage\start\en_us\Default\right_over_bg.jpg
  • c:\6cdeacda242012e0e5b593e657\1040\eula.rtf
  • UNC\SHARDREALM\Users\Harry Dresden\Desktop\ljLRyCpcWs.txt
  • c:\6cdeacda242012e0e5b593e657\1043\eula.rtf
  • UNC\SHARDREALM\Users\Harry Dresden\Desktop\QklFQHQmyNiNvWOam.doc
  • c:\Python27\Lib\test\selfsigned_pythontestdotnet.pem
  • UNC\SHARDREALM\Users\Public\Foxit Software\Foxit Reader\StartPage\advertisement\ribbon Integrate PDF into your mobile apps.bmp
  • UNC\SHARDREALM\Users\Public\Foxit Software\Foxit Reader\StartPage\advertisement\ribbon Create PDF from Office-convert PDF to office.bmp
  • c:\Python27\include\ast.h
  • c:\Python27\tcl\tix8.4.3\pref\Blue.cs
  • UNC\SHARDREALM\Users\Public\Foxit Software\Foxit Reader\StartPage\advertisement\normal Integrate PDF into your application.bmp
  • UNC\SHARDREALM\Users\Public\Foxit Software\Foxit Reader\StartPage\advertisement\Profile.xml
  • c:\Python27\include\pgenheaders.h
  • c:\Python27\include\pythread.h
  • UNC\SHARDREALM\Users\Harry Dresden\Desktop\NZZNgxshHiXH.docm
  • UNC\SHARDREALM\Users\Public\Foxit Software\Foxit Reader\StartPage\start\en_us\images\classic-16-open.png
  • c:\Python27\include\patchlevel.h
  • c:\6cdeacda242012e0e5b593e657\2070\eula.rtf
  • c:\Python27\include\iterobject.h
  • UNC\SHARDREALM\Users\Public\Foxit Software\Foxit Reader\StartPage\advertisement\normal Create PDF from Office-convert PDF to office.bmp
  • c:\6cdeacda242012e0e5b593e657\1042\eula.rtf
  • UNC\SHARDREALM\Users\Public\Pictures\Sample Pictures\Penguins.jpg
  • c:\Python27\include\listobject.h
  • c:\Python27\Lib\test\keycert.pem
  • UNC\SHARDREALM\Users\Harry Dresden\Desktop\HzwwphkzJpxtFEf.ppt
  • UNC\SHARDREALM\Users\Public\Foxit Software\Foxit Reader\StartPage\start\en_us\tpl\history.txt
  • c:\Python27\include\marshal.h
  • UNC\SHARDREALM\Users\Public\Foxit Software\Foxit Reader\StartPage\start\en_us\images\ribbon-16-open.png
  • UNC\SHARDREALM\Users\Public\Foxit Software\Foxit Reader\StartPage\start\en_us\images\ribbon-16.png
  • c:\6cdeacda242012e0e5b593e657\1044\eula.rtf
  • UNC\SHARDREALM\Users\Public\Foxit Software\Foxit Reader\StartPage\advertisement\ribbon Powerful Word Processor.bmp
  • c:\Python27\include\longintrepr.h
  • UNC\SHARDREALM\Users\Public\Foxit Software\Foxit Reader\StartPage\start\en_us\images\buy_phantom.png
  • c:\Python27\include\opcode.h
  • c:\Python27\include\parsetok.h
  • c:\Python27\Lib\test\badcert.pem
  • c:\6cdeacda242012e0e5b593e657\1025\eula.rtf
  • c:\Python27\include\pgen.h
  • c:\Python27\Lib\test\wrongcert.pem
  • c:\Python27\include\moduleobject.h
  • c:\Python27\include\memoryobject.h
  • c:\Python27\include\objimpl.h
  • c:\Python27\include\Python.h
  • UNC\SHARDREALM\Users\Harry Dresden\Desktop\adTQZDoJeOeg.docx
  • c:\6cdeacda242012e0e5b593e657\1045\eula.rtf
  • c:\6cdeacda242012e0e5b593e657\1053\eula.rtf
  • c:\6cdeacda242012e0e5b593e657\1041\eula.rtf
  • c:\ypliys\bin\cert.p12
  • UNC\SHARDREALM\Users\Public\Foxit Software\Foxit Reader\StartPage\advertisement\ribbon View PDFs on mobile devices.bmp
  • c:\Python27\include\bitset.h
  • c:\Python27\include\bytes_methods.h
  • UNC\SHARDREALM\Users\Public\Foxit Software\Foxit Reader\StartPage\advertisement\normal Enterprise PDF Reader.bmp
  • c:\Python27\tcl\tix8.4.3\pref\Gray.cs
  • c:\Python27\include\pystate.h
  • c:\Python27\Lib\test\ssl_key.pem
  • c:\Python27\Lib\test\keycert.passwd.pem
  • c:\Python27\include\methodobject.h
  • UNC\SHARDREALM\Users\Public\Foxit Software\Foxit Reader\StartPage\start\en_us\version.xml
  • c:\Python27\include\pyconfig.h
  • c:\Python27\include\cobject.h
  • c:\6cdeacda242012e0e5b593e657\1036\eula.rtf
  • \\?\PIPE\wkssvc
  • c:\Python27\include\pymath.h
  • UNC\SHARDREALM\Users\Public\Pictures\Sample Pictures\Koala.jpg
  • c:\6cdeacda242012e0e5b593e657\1038\eula.rtf
  • UNC\SHARDREALM\Users\Harry Dresden\Desktop\bqsEpYOgZP.pptx
  • c:\6cdeacda242012e0e5b593e657\2052\eula.rtf
  • UNC\SHARDREALM\Users\Public\Foxit Software\Foxit Reader\StartPage\start\en_us\Default\content_showbg.jpg
  • UNC\SHARDREALM\Users\Public\Foxit Software\Foxit Reader\StartPage\start\en_us\Default\show_con_bg.jpg
  • c:\Python27\Lib\test\ssl_key.passwd.pem
  • c:\Python27\Lib\test\keycert2.pem
  • c:\Python27\Lib\test\keycert4.pem
  • c:\Python27\include\pyport.h
  • UNC\SHARDREALM\Users\Public\Foxit Software\Foxit Reader\StartPage\advertisement\normal Integrate PDF into your mobile apps.bmp
  • UNC\SHARDREALM\Users\Public\Foxit Software\Foxit Reader\StartPage\start\en_us\Default\right_move_bg.jpg
  • c:\6cdeacda242012e0e5b593e657\1037\eula.rtf
  • c:\Python27\include\pystrcmp.h
  • c:\Python27\include\node.h
  • c:\Python27\include\boolobject.h
  • c:\Python27\Lib\test\pycacert.pem
  • UNC\SHARDREALM\Users\Public\Foxit Software\Foxit Reader\StartPage\start\en_us\Default\top_tb_bg.jpg
  • c:\Python27\include\code.h
  • c:\Python27\include\asdl.h
  • UNC\SHARDREALM\Users\Public\Foxit Software\Foxit Reader\StartPage\advertisement\ProfileRibbon.xml
  • UNC\SHARDREALM\Users\Public\Foxit Software\Foxit Reader\StartPage\advertisement\normal Powerful Word Processor.bmp
  • UNC\SHARDREALM\Users\Harry Dresden\Downloads\big-hero-6-2.jpg
  • UNC\SHARDREALM\Users\Public\Foxit Software\Foxit Reader\StartPage\start\en_us\Default\tab.png
  • c:\Python27\include\complexobject.h
  • c:\6cdeacda242012e0e5b593e657\1046\eula.rtf
  • UNC\SHARDREALM\Users\Public\Pictures\Sample Pictures\Tulips.jpg
  • c:\6cdeacda242012e0e5b593e657\1049\eula.rtf
  • UNC\SHARDREALM\Users\Public\Foxit Software\Foxit Reader\StartPage\advertisement\normal create pdf from scanner documents.bmp
  • UNC\SHARDREALM\Users\Public\Foxit Software\Foxit Reader\StartPage\start\en_us\Default\history_winbg.jpg
  • UNC\SHARDREALM\Users\Public\Foxit Software\Foxit Reader\StartPage\advertisement\normal View PDFs on mobile devices.bmp
  • c:\6cdeacda242012e0e5b593e657\3082\eula.rtf
  • UNC\SHARDREALM\Users\Public\Foxit Software\Foxit Reader\StartPage\advertisement\normal Fastest PDF Search and Index.bmp
  • UNC\SHARDREALM\Users\Public\Foxit Software\Foxit Reader\StartPage\advertisement\ribbon create pdf from scanner documents.bmp
  • c:\Python27\include\bytearrayobject.h
  • UNC\SHARDREALM\Users\Public\Foxit Software\Foxit Reader\StartPage\advertisement\normal Protect Sensitive PDF Documents.bmp
  • c:\Python27\include\pystrtod.h
  • c:\Python27\include\longobject.h
  • c:\Python27\Lib\test\badkey.pem
  • c:\Python27\include\cStringIO.h
  • c:\Python27\tcl\tix8.4.3\pref\Bisque.cs
  • UNC\SHARDREALM\Users\Public\Foxit Software\Foxit Reader\StartPage\start\en_us\js\DD_belatedPNG.js
  • UNC\SHARDREALM\Users\Public\Foxit Software\Foxit Reader\StartPage\advertisement\normal View and annotate PDFs.bmp
  • c:\Python27\include\bytesobject.h
  • c:\Python27\include\pyctype.h
  • c:\Python27\include\pymactoolbox.h
  • UNC\SHARDREALM\Users\Public\Foxit Software\Foxit Reader\StartPage\advertisement\normal Design form fields easily.bmp
  • c:\Python27\Lib\test\nokia.pem
  • c:\Python27\include\intrcheck.h
  • c:\Python27\include\pydebug.h
  • \\?\PIPE\lsarpc
  • UNC\SHARDREALM\Users\Public\Pictures\Sample Pictures\Lighthouse.jpg
  • c:\Python27\include\abstract.h
  • UNC\SHARDREALM\Users\Public\Pictures\Sample Pictures\Jellyfish.jpg
  • UNC\SHARDREALM\Users\Public\Foxit Software\Foxit Reader\StartPage\start\en_us\Default\body_bg.jpg
  • c:\ProgramData\WebEx\WebEx\12_1324\gpc.php
  • c:\Python27\Lib\test\nullbytecert.pem
  • UNC\SHARDREALM\Users\Public\Foxit Software\Foxit Reader\StartPage\start\en_us\images\classic-16.png
  • c:\Python27\Lib\test\dh1024.pem
  • UNC\SHARDREALM\Users\Public\Pictures\Sample Pictures\Hydrangeas.jpg
  • c:\6cdeacda242012e0e5b593e657\1055\eula.rtf
  • UNC\SHARDREALM\Users\Public\Foxit Software\Foxit Reader\StartPage\advertisement\normal Edit and reflow paragraphs in PDF files.bmp
  • c:\Python27\Lib\test\sha256.pem
  • UNC\SHARDREALM\Users\Public\Pictures\Sample Pictures\Chrysanthemum.jpg
  • UNC\SHARDREALM\Users\Public\Foxit Software\Foxit Reader\StartPage\start\en_us\images\phantomPDF_s.png
  • c:\Python27\include\pycapsule.h
  • c:\Python27\include\modsupport.h
  • c:\Python27\include\classobject.h
  • c:\Python27\include\pygetopt.h
  • c:\Python27\include\bufferobject.h
  • c:\Python27\include\datetime.h
  • UNC\SHARDREALM\Users\Public\Foxit Software\Foxit Reader\StartPage\advertisement\ribbon Enterprise PDF Reader.bmp
  • c:\Python27\include\cellobject.h
  • c:\Python27\include\metagrammar.h
  • c:\Python27\include\pyfpe.h
  • UNC\SHARDREALM\Users\Public\Foxit Software\Foxit Reader\StartPage\advertisement\ribbon View and annotate PDFs.bmp
  • c:\Python27\include\compile.h
  • UNC\SHARDREALM\Users\Public\Foxit Software\Foxit Reader\StartPage\advertisement\ribbon Integrate PDF into your application.bmp
  • c:\Python27\include\codecs.h
File-Written
  • C:\Users\Harry Dresden\AppData\Local\Temp\sdtqn9ol3egI
  • C:\Users\Harry Dresden\AppData\Local\Temp\sdtqn9ol3egI.zk
  • C:\Users\Harry Dresden\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\YLC2QM2Y\asy3u9[1].txt
  • UNC\SHARDREALM\Users\Harry Dresden\Downloads\cleandesktop.py.txt
  • c:\Python27\include\pyexpat.h
  • c:\Python27\include\object.h
  • UNC\SHARDREALM\Users\Public\Foxit Software\Foxit Reader\StartPage\start\en_us\Default\line.jpg
  • c:\Python27\Lib\test\keycert3.pem
  • UNC\SHARDREALM\Users\Public\Pictures\Sample Pictures\Desert.jpg
  • c:\Python27\include\intrcheck.h
  • c:\Python27\Lib\test\https_svn_python_org_root.pem
  • c:\Python27\Lib\test\ssl_cert.pem
  • UNC\SHARDREALM\Users\Public\Foxit Software\Foxit Reader\StartPage\start\en_us\images\phantomPDF_b.png
  • c:\6cdeacda242012e0e5b593e657\1025\OSIRIS-c6d6.htm
  • UNC\SHARDREALM\Users\Public\Foxit Software\Foxit Reader\StartPage\advertisement\ribbon Fastest PDF Search and Index.bmp
  • c:\Python27\include\pyerrors.h
  • UNC\SHARDREALM\Users\Public\Foxit Software\Foxit Reader\StartPage\advertisement\normal Protect your PDF files with AD RMS.bmp
  • UNC\SHARDREALM\Users\Public\Foxit Software\Foxit Reader\StartPage\advertisement\ribbon Protect your PDF files with AD RMS.bmp
  • c:\Python27\include\descrobject.h
  • c:\Python27\include\Python-ast.h
  • c:\Python27\include\osdefs.h
  • UNC\SHARDREALM\Users\Public\Foxit Software\Foxit Reader\StartPage\start\en_us\js\nor.js
  • c:\Python27\include\OSIRIS-3a0f.htm
  • UNC\SHARDREALM\Users\Public\Foxit Software\Foxit Reader\StartPage\start\en_us\images\blank.gif
  • c:\Python27\include\pymacconfig.h
  • UNC\SHARDREALM\Users\Public\Foxit Software\Foxit Reader\StartPage\start\en_us\tpl\OSIRIS-fece.htm
  • c:\Python27\include\ceval.h
  • \\?\PIPE\browser
  • c:\Python27\include\pythonrun.h
  • c:\Python27\include\pymem.h
  • c:\Python27\Lib\site-packages\pip\_vendor\requests\cacert.pem
  • c:\Python27\include\pyarena.h
  • UNC\SHARDREALM\Users\Harry Dresden\Desktop\eHPRzxmJiIkx.rtf
  • UNC\SHARDREALM\Users\Public\Foxit Software\Foxit Reader\StartPage\start\en_us\Default\right_over_bg.jpg
  • c:\6cdeacda242012e0e5b593e657\1040\eula.rtf
  • UNC\SHARDREALM\Users\Harry Dresden\Desktop\ljLRyCpcWs.txt
  • c:\6cdeacda242012e0e5b593e657\1043\eula.rtf
  • c:\Python27\Lib\test\nullcert.pem
  • UNC\SHARDREALM\Users\Harry Dresden\Desktop\QklFQHQmyNiNvWOam.doc
  • c:\Python27\Lib\test\selfsigned_pythontestdotnet.pem
  • UNC\SHARDREALM\Users\Public\Foxit Software\Foxit Reader\StartPage\advertisement\ribbon Integrate PDF into your mobile apps.bmp
  • UNC\SHARDREALM\Users\Public\Foxit Software\Foxit Reader\StartPage\advertisement\ribbon Create PDF from Office-convert PDF to office.bmp
  • c:\Python27\include\ast.h
  • c:\6cdeacda242012e0e5b593e657\1043\OSIRIS-0935.htm
  • c:\Python27\tcl\tix8.4.3\pref\Blue.cs
  • UNC\SHARDREALM\Users\Public\Foxit Software\Foxit Reader\StartPage\advertisement\normal Integrate PDF into your application.bmp
  • UNC\SHARDREALM\Users\Public\Foxit Software\Foxit Reader\StartPage\advertisement\Profile.xml
  • UNC\SHARDREALM\Users\Public\Foxit Software\Foxit Reader\StartPage\advertisement\normal Powerful Word Processor.bmp
  • c:\Python27\include\pgenheaders.h
  • c:\Python27\include\pythread.h
  • c:\Python27\Lib\site-packages\pip\_vendor\requests\OSIRIS-73e6.htm
  • UNC\SHARDREALM\Users\Harry Dresden\Desktop\NZZNgxshHiXH.docm
  • UNC\SHARDREALM\Users\Public\Foxit Software\Foxit Reader\StartPage\start\en_us\images\classic-16-open.png
  • c:\Python27\include\patchlevel.h
  • c:\6cdeacda242012e0e5b593e657\2070\eula.rtf
  • c:\Python27\include\iterobject.h
  • c:\ProgramData\WebEx\WebEx\12_1324\gpc.php
  • UNC\SHARDREALM\Users\Public\Foxit Software\Foxit Reader\StartPage\advertisement\normal Create PDF from Office-convert PDF to office.bmp
  • c:\6cdeacda242012e0e5b593e657\1042\eula.rtf
  • c:\Python27\include\pycapsule.h
  • UNC\SHARDREALM\Users\Public\Pictures\Sample Pictures\Penguins.jpg
  • c:\Python27\include\listobject.h
  • c:\Python27\Lib\test\keycert.pem
  • UNC\SHARDREALM\Users\Public\Foxit Software\Foxit Reader\StartPage\start\en_us\OSIRIS-27e1.htm
  • UNC\SHARDREALM\Users\Public\Foxit Software\Foxit Reader\StartPage\start\en_us\tpl\history.txt
  • c:\Python27\include\marshal.h
  • UNC\SHARDREALM\Users\Public\Foxit Software\Foxit Reader\StartPage\start\en_us\images\ribbon-16-open.png
  • c:\6cdeacda242012e0e5b593e657\1036\OSIRIS-0c4e.htm
  • UNC\SHARDREALM\Users\Public\Foxit Software\Foxit Reader\StartPage\start\en_us\images\ribbon-16.png
  • c:\6cdeacda242012e0e5b593e657\1044\eula.rtf
  • c:\ypliys\bin\OSIRIS-eb72.htm
  • UNC\SHARDREALM\Users\Public\Foxit Software\Foxit Reader\StartPage\advertisement\ribbon Powerful Word Processor.bmp
  • c:\6cdeacda242012e0e5b593e657\1055\OSIRIS-5df7.htm
  • UNC\SHARDREALM\Users\Harry Dresden\Desktop\OSIRIS-7920.htm
  • c:\Python27\include\longintrepr.h
  • UNC\SHARDREALM\Users\Public\Foxit Software\Foxit Reader\StartPage\start\en_us\images\buy_phantom.png
  • c:\Python27\include\opcode.h
  • c:\6cdeacda242012e0e5b593e657\1045\OSIRIS-01ba.htm
  • c:\Python27\Lib\test\badcert.pem
  • UNC\SHARDREALM\Users\Public\Foxit Software\Foxit Reader\StartPage\start\en_us\js\OSIRIS-d8a4.htm
  • c:\Python27\tcl\tix8.4.3\pref\OSIRIS-35f9.htm
  • c:\6cdeacda242012e0e5b593e657\1025\eula.rtf
  • c:\Python27\include\pgen.h
  • c:\Python27\Lib\test\wrongcert.pem
  • c:\Python27\include\moduleobject.h
  • c:\Python27\include\memoryobject.h
  • c:\Python27\include\objimpl.h
  • c:\Python27\include\Python.h
  • UNC\SHARDREALM\Users\Harry Dresden\Desktop\adTQZDoJeOeg.docx
  • c:\6cdeacda242012e0e5b593e657\1045\eula.rtf
  • c:\6cdeacda242012e0e5b593e657\1053\eula.rtf
  • c:\6cdeacda242012e0e5b593e657\1041\eula.rtf
  • c:\ypliys\bin\cert.p12
  • UNC\SHARDREALM\Users\Public\Foxit Software\Foxit Reader\StartPage\advertisement\ribbon View PDFs on mobile devices.bmp
  • c:\Python27\include\bitset.h
  • c:\Python27\include\bytes_methods.h
  • UNC\SHARDREALM\Users\Public\Foxit Software\Foxit Reader\StartPage\advertisement\normal Enterprise PDF Reader.bmp
  • c:\Python27\tcl\tix8.4.3\pref\Gray.cs
  • c:\Python27\include\pystate.h
  • c:\Python27\Lib\test\ssl_key.pem
  • c:\Python27\Lib\test\keycert.passwd.pem
  • c:\Python27\include\methodobject.h
  • UNC\SHARDREALM\Users\Public\Foxit Software\Foxit Reader\StartPage\start\en_us\version.xml
  • c:\6cdeacda242012e0e5b593e657\1038\OSIRIS-41ae.htm
  • c:\Python27\include\pyconfig.h
  • c:\Python27\include\cobject.h
  • c:\6cdeacda242012e0e5b593e657\1036\eula.rtf
  • \\?\PIPE\wkssvc
  • c:\Python27\include\pymath.h
  • UNC\SHARDREALM\Users\Public\Pictures\Sample Pictures\Koala.jpg
  • c:\6cdeacda242012e0e5b593e657\1038\eula.rtf
  • c:\Python27\include\parsetok.h
  • UNC\SHARDREALM\Users\Public\Pictures\Sample Pictures\OSIRIS-b7f2.htm
  • UNC\SHARDREALM\Users\Harry Dresden\Desktop\bqsEpYOgZP.pptx
  • c:\6cdeacda242012e0e5b593e657\2052\eula.rtf
  • UNC\SHARDREALM\Users\Public\Foxit Software\Foxit Reader\StartPage\start\en_us\Default\content_showbg.jpg
  • UNC\SHARDREALM\Users\Public\Foxit Software\Foxit Reader\StartPage\start\en_us\Default\show_con_bg.jpg
  • c:\Python27\include\classobject.h
  • c:\Python27\Lib\test\ssl_key.passwd.pem
  • c:\6cdeacda242012e0e5b593e657\1040\OSIRIS-a956.htm
  • c:\Python27\Lib\test\keycert2.pem
  • c:\Python27\Lib\test\keycert4.pem
  • c:\Python27\include\pyport.h
  • c:\6cdeacda242012e0e5b593e657\1041\OSIRIS-e1b0.htm
  • UNC\SHARDREALM\Users\Public\Foxit Software\Foxit Reader\StartPage\advertisement\normal Integrate PDF into your mobile apps.bmp
  • UNC\SHARDREALM\Users\Public\Foxit Software\Foxit Reader\StartPage\start\en_us\Default\right_move_bg.jpg
  • c:\6cdeacda242012e0e5b593e657\1037\eula.rtf
  • c:\Python27\include\pystrcmp.h
  • c:\6cdeacda242012e0e5b593e657\1042\OSIRIS-bec2.htm
  • UNC\SHARDREALM\Users\Harry Dresden\Downloads\OSIRIS-5ee0.htm
  • c:\Python27\include\boolobject.h
  • c:\Python27\Lib\test\pycacert.pem
  • UNC\SHARDREALM\Users\Public\Foxit Software\Foxit Reader\StartPage\start\en_us\Default\top_tb_bg.jpg
  • c:\Python27\include\code.h
  • c:\6cdeacda242012e0e5b593e657\3082\OSIRIS-fd0d.htm
  • c:\Python27\include\asdl.h
  • c:\6cdeacda242012e0e5b593e657\2070\OSIRIS-9240.htm
  • UNC\SHARDREALM\Users\Public\Foxit Software\Foxit Reader\StartPage\advertisement\ProfileRibbon.xml
  • c:\ProgramData\WebEx\WebEx\12_1324\OSIRIS-e52b.htm
  • UNC\SHARDREALM\Users\Harry Dresden\Downloads\big-hero-6-2.jpg
  • UNC\SHARDREALM\Users\Public\Foxit Software\Foxit Reader\StartPage\start\en_us\Default\tab.png
  • c:\Python27\include\complexobject.h
  • c:\6cdeacda242012e0e5b593e657\1046\eula.rtf
  • UNC\SHARDREALM\Users\Public\Foxit Software\Foxit Reader\StartPage\start\en_us\Default\OSIRIS-d035.htm
  • UNC\SHARDREALM\Users\Public\Pictures\Sample Pictures\Tulips.jpg
  • c:\6cdeacda242012e0e5b593e657\1049\eula.rtf
  • UNC\SHARDREALM\Users\Public\Foxit Software\Foxit Reader\StartPage\advertisement\normal create pdf from scanner documents.bmp
  • UNC\SHARDREALM\Users\Public\Foxit Software\Foxit Reader\StartPage\start\en_us\Default\history_winbg.jpg
  • UNC\SHARDREALM\Users\Public\Foxit Software\Foxit Reader\StartPage\advertisement\normal View PDFs on mobile devices.bmp
  • c:\6cdeacda242012e0e5b593e657\3082\eula.rtf
  • UNC\SHARDREALM\Users\Public\Foxit Software\Foxit Reader\StartPage\advertisement\normal Fastest PDF Search and Index.bmp
  • UNC\SHARDREALM\Users\Public\Foxit Software\Foxit Reader\StartPage\advertisement\ribbon create pdf from scanner documents.bmp
  • c:\Python27\include\bytearrayobject.h
  • c:\6cdeacda242012e0e5b593e657\1044\OSIRIS-6237.htm
  • UNC\SHARDREALM\Users\Public\Foxit Software\Foxit Reader\StartPage\advertisement\normal Protect Sensitive PDF Documents.bmp
  • c:\Python27\include\pystrtod.h
  • c:\Python27\include\longobject.h
  • c:\Python27\include\node.h
  • c:\Python27\Lib\test\badkey.pem
  • c:\Python27\include\cStringIO.h
  • UNC\SHARDREALM\Users\Harry Dresden\Desktop\HzwwphkzJpxtFEf.ppt
  • c:\Python27\tcl\tix8.4.3\pref\Bisque.cs
  • UNC\SHARDREALM\Users\Public\Foxit Software\Foxit Reader\StartPage\start\en_us\js\DD_belatedPNG.js
  • UNC\SHARDREALM\Users\Public\Foxit Software\Foxit Reader\StartPage\advertisement\normal View and annotate PDFs.bmp
  • c:\Python27\include\bytesobject.h
  • c:\Python27\include\pyctype.h
  • c:\6cdeacda242012e0e5b593e657\1037\OSIRIS-b104.htm
  • c:\Python27\include\pymactoolbox.h
  • UNC\SHARDREALM\Users\Public\Foxit Software\Foxit Reader\StartPage\advertisement\normal Design form fields easily.bmp
  • c:\Python27\Lib\test\nokia.pem
  • UNC\SHARDREALM\Users\Public\Foxit Software\Foxit Reader\StartPage\advertisement\ribbon Protect Sensitive PDF Documents.bmp
  • c:\Python27\include\pydebug.h
  • \\?\PIPE\lsarpc
  • UNC\SHARDREALM\Users\Public\Pictures\Sample Pictures\Lighthouse.jpg
  • UNC\SHARDREALM\Users\Public\Foxit Software\Foxit Reader\StartPage\start\en_us\images\OSIRIS-cc78.htm
  • c:\Python27\include\abstract.h
  • UNC\SHARDREALM\Users\Public\Pictures\Sample Pictures\Jellyfish.jpg
  • UNC\SHARDREALM\Users\Public\Foxit Software\Foxit Reader\StartPage\start\en_us\Default\body_bg.jpg
  • c:\Python27\Lib\test\OSIRIS-0f18.htm
  • UNC\SHARDREALM\Users\Public\Foxit Software\Foxit Reader\StartPage\advertisement\OSIRIS-13f8.htm
  • c:\Python27\Lib\test\nullbytecert.pem
  • UNC\SHARDREALM\Users\Public\Foxit Software\Foxit Reader\StartPage\start\en_us\images\classic-16.png
  • c:\Python27\Lib\test\dh1024.pem
  • UNC\SHARDREALM\Users\Public\Pictures\Sample Pictures\Hydrangeas.jpg
  • c:\6cdeacda242012e0e5b593e657\1055\eula.rtf
  • UNC\SHARDREALM\Users\Public\Foxit Software\Foxit Reader\StartPage\advertisement\normal Edit and reflow paragraphs in PDF files.bmp
  • c:\Python27\Lib\test\sha256.pem
  • c:\6cdeacda242012e0e5b593e657\1049\OSIRIS-8784.htm
  • UNC\SHARDREALM\Users\Public\Pictures\Sample Pictures\Chrysanthemum.jpg
  • UNC\SHARDREALM\Users\Public\Foxit Software\Foxit Reader\StartPage\start\en_us\images\phantomPDF_s.png
  • c:\6cdeacda242012e0e5b593e657\1046\OSIRIS-a611.htm
  • c:\6cdeacda242012e0e5b593e657\2052\OSIRIS-12e3.htm
  • c:\Python27\include\modsupport.h
  • c:\6cdeacda242012e0e5b593e657\1053\OSIRIS-d440.htm
  • c:\Python27\include\pygetopt.h
  • c:\Python27\include\bufferobject.h
  • c:\Python27\include\datetime.h
  • UNC\SHARDREALM\Users\Public\Foxit Software\Foxit Reader\StartPage\advertisement\ribbon Enterprise PDF Reader.bmp
  • c:\Python27\include\cellobject.h
  • c:\Python27\include\metagrammar.h
  • c:\Python27\include\pyfpe.h
  • UNC\SHARDREALM\Users\Public\Foxit Software\Foxit Reader\StartPage\advertisement\ribbon View and annotate PDFs.bmp
  • c:\Python27\include\compile.h
  • UNC\SHARDREALM\Users\Public\Foxit Software\Foxit Reader\StartPage\advertisement\ribbon Integrate PDF into your application.bmp
  • c:\Python27\include\codecs.h
File-Deleted
  • C:\Users\Harry Dresden\AppData\Local\Microsoft\Windows\Caches\{AFBF9F1A-8EE8-4C77-AF34-C647E37CA0D9}.1.ver0x0000000000000000.db
File-Opened
  • C:\Users\Harry Dresden\AppData\Local\Temp\sdtqn9ol3egI.zk
  • C:\Windows\System32\rundll32.exe
  • C:\Windows\System32\wshqos.dll
  • C:\
  • C:\Users\Harry Dresden\AppData\Local\
  • C:\Windows\System32\msxml3.dll
  • C:\Users\Harry Dresden\Desktop\desktop.ini
  • C:\Windows\System32
  • C:\Users\Harry Dresden\AppData\Local\Temp\~4066KG2TA4Y15BWI3D10KFX7.js
  • C:\Windows\System32\wshom.ocx
  • C:\Users\
  • C:\Users\Harry Dresden\
  • C:\Users\Harry Dresden\AppData\
  • C:\Windows\System32\en-US\wshtcpip.dll.mui
  • C:\Windows\winsxs\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac
  • C:\Windows\System32\en-US\wshqos.dll.mui
  • C:\Windows\
  • C:\Windows\System32\en-US\wship6.dll.mui
  • C:\Windows\System32\wscript.exe
  • C:\Windows\Globalization\Sorting\sortdefault.nls
  • C:\Users\Harry Dresden\AppData\Local\Temp\sdtqn9ol3egI
  • C:\Windows\System32\
  • C:\Users\Harry Dresden\AppData\Local\Temp\
  • C:\Windows\System32\rsaenh.dll
  • C:\Windows
  • C:\Windows\System32\ieframe.dll
  • c:\Python27\include\pyexpat.h
  • c:\Python27\Lib\ctypes
  • UNC\SHARDREALM\Users\Harry Dresden\Documents
  • c:\Users\Default\Links
  • c:\ProgramData\Microsoft\Windows NT\MSFax\Common Coverpages
  • c:\Python27\include\pymacconfig.h
  • c:\Python27\include\ast.h
  • c:\Python27\include\memoryobject.h
  • c:\ypliys\modules
  • c:\Python27\Lib\site-packages\pip\_vendor\colorama
  • c:\ProgramData\Microsoft\Windows Defender\Scans\CleanStore\Resources
  • c:\Python27\DLLs
  • c:\Python27\Lib\site-packages\pip\_vendor\cachecontrol
  • UNC\SHARDREALM\Users\Harry Dresden\Favorites\Links for United States
  • c:\ProgramData\Microsoft\Event Viewer\Views\ApplicationViewsRootNode
  • UNC\SHARDREALM\Users\Public\Foxit Software\Foxit Reader\StartPage\advertisement\normal Enterprise PDF Reader.bmp
  • c:\ProgramData\Adobe\Setup
  • UNC\SHARDREALM\Users\Public\Foxit Software\Foxit Reader\StartPage\start\en_us\Default\content_showbg.jpg
  • c:\ProgramData\Microsoft\Assistance\Client\1.0\en-US
  • c:\Python27\Lib\site-packages\pip\_vendor\requests\packages\urllib3\packages
  • UNC\SHARDREALM\Users\Harry Dresden\OneDrive
  • c:\Users\Harry Dresden\OneDrive
  • c:\ProgramData\Microsoft\PlayReady\Cache\S-1-5-21-3416602863-1947377224-293699093-1001
  • c:\Users\Public\Libraries
  • \\?\PIPE\browser
  • c:\Python27\Lib\test\tracedmodules
  • c:\ProgramData\Adobe\ARM
  • c:\Python27\tcl\tcl8.5\tzdata\Indian
  • c:\Users\Public
  • c:\6cdeacda242012e0e5b593e657\1043\eula.rtf
  • c:\ProgramData\Microsoft\Windows NT\MSFax\Queue
  • c:\Users\Public\Foxit Software\Foxit Reader\StartPage\start\en_us\tpl
  • c:\ProgramData\Microsoft\Windows Defender\Scans\History\Results\Resource
  • c:\Python27\Lib
  • \??\VBoxMiniRdrDN
  • UNC\SHARDREALM\Users\Harry Dresden\Desktop\QklFQHQmyNiNvWOam.doc
  • UNC\SHARDREALM\Users\Public\Foxit Software\Foxit Reader\StartPage\advertisement\ribbon Integrate PDF into your mobile apps.bmp
  • c:\ProgramData
  • c:\Python27\tcl\tix8.4.3\pref\Blue.cs
  • c:\ProgramData\Microsoft\Device Stage\Device\{8702d817-5aad-4674-9ef3-4d3decd87120}
  • c:\Python27\Lib\site-packages\pip
  • UNC\SHARDREALM\Users\Public\Foxit Software\Foxit Reader\StartPage\start\en_us\images\classic-16-open.png
  • c:\ProgramData\Microsoft\Windows Defender\Scans\CleanStore\Resources\A5
  • c:\ProgramData\Microsoft\Windows Defender\Scans\CleanStore\Resources\A6
  • c:\Python27\Lib\ctypes\macholib
  • c:\ProgramData\Adobe\Acrobat\11.0\Replicate\Security
  • c:\6cdeacda242012e0e5b593e657\1042\eula.rtf
  • c:\inetpub\history\CFGHISTORY_0000000004\schema
  • c:\Python27\Lib\unittest\test
  • c:\ProgramData\Microsoft\PlayReady
  • c:\Python27\Lib\xml\dom
  • c:\ProgramData\Microsoft\ClickToRun\ProductReleases\9E1D94D2-471F-4DC3-9EBD-E31E1E099E00
  • c:\Python27\Lib\site-packages\pip\models
  • UNC\SHARDREALM\Users\Public\Foxit Software\Foxit Reader\StartPage\start\en_us\tpl\history.txt
  • c:\Python27\include\marshal.h
  • UNC\SHARDREALM\Users\Public\Foxit Software
  • c:\ProgramData\Adobe\Acrobat\11.0\Replicate
  • c:\Python27\Tools\i18n
  • UNC\SHARDREALM\Users\Public\Foxit Software\Foxit Reader\StartPage\advertisement\ribbon create pdf from scanner documents.bmp
  • c:\Python27\tcl\tcl8\8.4
  • c:\ProgramData\Microsoft\ClickToRun\MachineData\Catalog
  • c:\ProgramData\Microsoft\Crypto\Keys
  • UNC\SHARDREALM\Users\Public\Music\Sample Music
  • c:\inetpub\wwwroot\aspnet_client\system_web\4_0_30319
  • c:\Python27\Lib\ctypes\test
  • c:\Users\Harry Dresden\Searches
  • c:\Python27\Lib\test\badcert.pem
  • c:\ProgramData\Adobe\ARM\S
  • c:\Python27\Lib\ensurepip
  • c:\Python27\include\pgen.h
  • UNC\SHARDREALM\Users
  • c:\Python27\tcl\tcl8.5\tzdata\Canada
  • c:\Python27\Lib\test\wrongcert.pem
  • c:\Users\Harry Dresden\Downloads
  • c:\Python27\include\objimpl.h
  • UNC\SHARDREALM\Users\Harry Dresden\Desktop\adTQZDoJeOeg.docx
  • c:\ProgramData\Microsoft\eHome
  • c:\Python27\tcl\tk8.5\demos\images
  • UNC\SHARDREALM\Users\Public\Foxit Software\Foxit Reader\StartPage\start\en_us\images
  • c:\Python27\Lib\test\cjkencodings
  • c:\inetpub\wwwroot\aspnet_client\system_web
  • UNC\SHARDREALM\Users\Public\Music
  • c:\Python27\tcl\tcl8.5\tzdata\America\Kentucky
  • c:\ProgramData\Microsoft\Device Stage\Task\{07deb856-fc6e-4fb9-8add-d8f2cf8722c9}\en-US
  • c:\Python27\include\abstract.h
  • c:\ypliys\lib\common
  • c:\Python27\Lib\test\keycert.passwd.pem
  • UNC\SHARDREALM\Users\Public\Foxit Software\Foxit Reader\StartPage\start\en_us\images\ribbon-16.png
  • c:\ypliys
  • c:\Python27\include\object.h
  • c:\Python27\tcl\tix8.4.3
  • c:\6cdeacda242012e0e5b593e657\1036\eula.rtf
  • c:\ProgramData\Microsoft\RAC\PublishedData
  • UNC\SHARDREALM\Users\Harry Dresden\Links
  • c:\inetpub\history\CFGHISTORY_0000000005
  • c:\inetpub\history\CFGHISTORY_0000000004
  • c:\inetpub\history\CFGHISTORY_0000000001
  • c:\Python27\include\pydebug.h
  • c:\inetpub\history\CFGHISTORY_0000000003
  • c:\ProgramData\Microsoft\Vault\AC658CB4-9126-49BD-B877-31EEDAB3F204
  • c:\Users\Harry Dresden\Favorites\Links for United States
  • c:\Python27\Lib\lib2to3\tests\data\fixers
  • UNC\SHARDREALM\Users\Harry Dresden\Desktop\bqsEpYOgZP.pptx
  • c:\Python27\tcl\tcl8.5\tzdata\US
  • c:\Python27\tcl\tcl8.5\tzdata
  • UNC\SHARDREALM\Users\Public\Videos
  • UNC\SHARDREALM\Users\Public\Foxit Software\Foxit Reader\StartPage\advertisement\normal create pdf from scanner documents.bmp
  • c:\Python27\include\pyport.h
  • c:\6cdeacda242012e0e5b593e657\1045\eula.rtf
  • UNC\SHARDREALM\Users\Public\Documents
  • c:\ypliys\modules\packages
  • c:\Python27\Lib\email
  • c:\Python27\tcl\tix8.4.3\demos\samples
  • c:\Python27\Lib\lib-tk\test\test_tkinter
  • c:\6cdeacda242012e0e5b593e657\1053\eula.rtf
  • UNC\SHARDREALM\Users\Harry Dresden\Music
  • c:\Python27\Tools\webchecker
  • c:\Python27\tcl\tcl8.5\tzdata\America\North_Dakota
  • c:\Python27\Lib\test\crashers
  • c:\ProgramData\Microsoft\Windows Defender\LocalCopy
  • c:\Python27\include\asdl.h
  • UNC\SHARDREALM\Users\Public\Foxit Software\Foxit Reader\StartPage\advertisement\ProfileRibbon.xml
  • c:\Users\Harry Dresden\Contacts
  • c:\ProgramData\Microsoft\Windows Defender\Scans\CleanStore\Resources\E0
  • c:\PerfLogs
  • UNC\SHARDREALM\Users\Public\Libraries
  • c:\
  • c:\Python27\include\complexobject.h
  • c:\ProgramData\Microsoft\Windows Defender\Scans\CleanStore\Entries
  • c:\Python27\tcl\tix8.4.3\pref\Bisque.cs
  • c:\Python27\Lib\site-packages\pip\_vendor\html5lib\treebuilders
  • c:\Python27\tcl\tcl8\8.5
  • UNC\SHARDREALM\Users\Default\Desktop
  • UNC\SHARDREALM\Users\Public\Foxit Software\Foxit Reader\StartPage\start\en_us\js\DD_belatedPNG.js
  • UNC\SHARDREALM\Users\Public\Foxit Software\Foxit Reader\StartPage\start\en_us\Default\history_winbg.jpg
  • c:\6cdeacda242012e0e5b593e657\3082\eula.rtf
  • c:\Python27\libs
  • c:\ProgramData\Microsoft\ClickToRun\MachineData
  • UNC\SHARDREALM\Users\Public\Foxit Software\Foxit Reader\StartPage\advertisement\normal Protect Sensitive PDF Documents.bmp
  • c:\Python27\include\pystrtod.h
  • c:\Python27\include\longobject.h
  • c:\ProgramData\Microsoft\Assistance
  • c:\Python27\include\bytesobject.h
  • c:\Python27\include\pyctype.h
  • c:\ProgramData\Microsoft\Windows Defender\Scans\History\Results
  • c:\Users\Harry Dresden\Videos
  • c:\Python27\Lib\pydoc_data
  • UNC\SHARDREALM\Users\Default\Music
  • c:\ProgramData\Microsoft\Crypto\DSS
  • c:\ProgramData\Adobe\Acrobat
  • c:\Python27\tcl\tcl8.5\tzdata\Atlantic
  • c:\ProgramData\NovaTech Network\NovaBench\3.0.2.0
  • c:\ProgramData\Microsoft\Network
  • c:\ProgramData\Microsoft\Windows Defender\Scans\CleanStore\ResourceData\1A
  • c:\ProgramData\Microsoft\Diagnosis\ETLLogs\AutoLogger
  • c:\Users\Default\Downloads
  • c:\Python27\Lib\xml
  • c:\Python27\tcl\tcl8.5\tzdata\Australia
  • c:\Users\Public\Foxit Software\Foxit Reader\StartPage
  • c:\ProgramData\Microsoft\Windows Defender\Scans\CleanStore\ResourceData\17
  • c:\Python27\tcl\tk8.5
  • c:\ProgramData\Microsoft\PlayReady\Cache
  • c:\6cdeacda242012e0e5b593e657\3082
  • c:\Python27\Lib\site-packages\pip\compat
  • c:\Python27\Lib\test\leakers
  • c:\Python27\tcl\tcl8\8.4\platform
  • c:\Python27\include\modsupport.h
  • c:\ProgramData\regid.1991-06.com.microsoft
  • c:\Python27\Lib\site-packages\pip\_vendor\html5lib\filters
  • c:\ProgramData\Microsoft\ClickToRun\ProductReleases\9E1D94D2-471F-4DC3-9EBD-E31E1E099E00\x-none.16
  • c:\ProgramData\Microsoft\Windows Defender\Scans\CleanStore\ResourceData\DD
  • c:\Python27\Tools\pynche\X
  • c:\Python27\include\bufferobject.h
  • c:\Python27\Tools\Scripts
  • UNC\SHARDREALM\Users\Public\Foxit Software\Foxit Reader\StartPage\advertisement\ribbon Enterprise PDF Reader.bmp
  • c:\ProgramData\Microsoft\Windows Defender\Scans\CleanStore\Resources\35
  • c:\ProgramData\Microsoft\Windows Defender\Scans\CleanStore
  • c:\Python27\Lib\test\nokia.pem
  • c:\Python27\include\compile.h
  • c:\6cdeacda242012e0e5b593e657\1040\eula.rtf
  • C:\Users\Harry Dresden\AppData\Local\Temp
  • UNC\SHARDREALM\Users\Public\Foxit Software\Foxit Reader\StartPage\start\en_us\Default\line.jpg
  • c:\Python27\tcl\tk8.5\images
  • c:\ProgramData\Microsoft\DRM
  • UNC\SHARDREALM\Users\Harry Dresden\Videos
  • c:\ProgramData\Microsoft\Windows NT\MSFax\Common Coverpages\en-US
  • c:\Python27\Lib\idlelib\idle_test
  • c:\Python27\Lib\test\https_svn_python_org_root.pem
  • c:\Python27\include
  • c:\Python27\Lib\test\nullcert.pem
  • c:\Python27\Lib\site-packages\setuptools
  • UNC\SHARDREALM\Users\Public\Foxit Software\Foxit Reader\StartPage\advertisement\ribbon Protect your PDF files with AD RMS.bmp
  • c:\6cdeacda242012e0e5b593e657\1029
  • c:\6cdeacda242012e0e5b593e657\1028
  • c:\ProgramData\Microsoft\Device Stage\Task\{e35be42d-f742-4d96-a50a-1775fb1a7a42}
  • c:\Python27\Lib\site-packages\pip\commands
  • c:\Python27\Lib\lib2to3\tests\data\fixers\myfixes
  • c:\6cdeacda242012e0e5b593e657\1025
  • c:\Users\Public\Foxit Software\Foxit Reader\StartPage\start\en_us
  • UNC\SHARDREALM\Users\Default\Favorites
  • c:\Python27\Lib\email\test\data
  • c:\ProgramData\Microsoft\Windows Defender\Support
  • c:\ProgramData\WebEx\WebEx
  • UNC\SHARDREALM\Users\Harry Dresden\Desktop\ljLRyCpcWs.txt
  • c:\6cdeacda242012e0e5b593e657\2052
  • UNC\SHARDREALM\Users\Default\Saved Games
  • c:\Python27\tcl\tcl8.5\opt0.4
  • c:\ProgramData\Microsoft\ClickToRun\ProductReleases
  • c:\Python27\include\pgenheaders.h
  • c:\ProgramData\Microsoft\Device Stage\Task\{e35be42d-f742-4d96-a50a-1775fb1a7a42}\en-US
  • c:\Python27\tcl\tcl8.5\encoding
  • c:\ProgramData\Microsoft\Diagnosis\ETLLogs
  • c:\Python27\Lib\msilib
  • c:\ProgramData\Microsoft\WwanSvc\Profiles
  • UNC\SHARDREALM\Users\Harry Dresden\Contacts
  • c:\Python27\Lib\encodings
  • c:\Python27\Lib\site-packages\pip\_vendor\distlib\_backport
  • c:\ProgramData\Microsoft\Assistance\Client
  • UNC\SHARDREALM\Users\Default\Pictures
  • c:\ProgramData\Microsoft\Windows Defender\Scans\CleanStore\Resources\95
  • c:\6cdeacda242012e0e5b593e657\1046\eula.rtf
  • c:\Python27\Lib\site-packages\_markerlib
  • c:\ProgramData\Microsoft\Diagnosis\LocalTraceStore
  • c:\inetpub\custerr
  • c:\Python27\include\longintrepr.h
  • c:\ypliys\modules\auxiliary
  • c:\inetpub\custerr\en-US
  • c:\Python27\Lib\site-packages\pip\_vendor\cachecontrol\caches
  • c:\Python27\include\opcode.h
  • UNC\SHARDREALM\Users\Public\Foxit Software\Foxit Reader\StartPage\start\en_us\Default\tab.png
  • c:\ProgramData\Microsoft\Crypto\RSA
  • c:\6cdeacda242012e0e5b593e657\1025\eula.rtf
  • c:\Python27\tcl\tk8.5\ttk
  • c:\ProgramData\Microsoft\Windows Defender\Scans\CleanStore\Resources\01
  • c:\Users\Default\Favorites
  • c:\inetpub\history
  • c:\Python27\include\moduleobject.h
  • c:\ProgramData\Microsoft\Windows NT
  • c:\Python27\Lib\site-packages\pip\_vendor\requests\packages\chardet
  • c:\ProgramData\Microsoft\Vault
  • c:\ProgramData\Microsoft\Windows Defender\Scans\CleanStore\ResourceData
  • UNC\SHARDREALM\Users\Harry Dresden\Pictures
  • c:\6cdeacda242012e0e5b593e657\2052\eula.rtf
  • c:\Python27\include\boolobject.h
  • C:\Windows\SysWOW64\en-US\VssTrace.DLL.mui
  • UNC\SHARDREALM\Users\Default\Videos
  • c:\Python27\include\bitset.h
  • c:\Python27\Lib\site-packages\pip\_vendor\requests\packages
  • UNC\SHARDREALM\Users\Harry Dresden
  • c:\ProgramData\Mozilla\logs
  • c:\ProgramData\Microsoft\Search\Data\Applications
  • c:\Python27\include\pycapsule.h
  • c:\ProgramData\Microsoft\Windows Defender\Scans\CleanStore\Resources\70
  • c:\Python27\tcl\tcl8.5\tzdata\Mexico
  • c:\Python27\Lib\importlib
  • c:\ProgramData\Microsoft\Crypto
  • c:\ProgramData\NovaTech Network\NovaBench\3.0.2.0\media
  • c:\Python27\tcl\tcl8.5
  • UNC\SHARDREALM\Users\Public\Pictures\Sample Pictures\Koala.jpg
  • c:\Python27\tcl\tcl8.5\tzdata\Africa
  • UNC\SHARDREALM\Users\Public\Foxit Software\Foxit Reader\StartPage\advertisement\normal Create PDF from Office-convert PDF to office.bmp
  • c:\ProgramData\McAfee
  • c:\Python27\Lib\site-packages\pip\vcs
  • c:\Python27\Lib\bsddb\test
  • c:\ProgramData\Microsoft\Windows Defender\Scans\CleanStore\ResourceData\43
  • c:\Python27\Lib\test\keycert2.pem
  • UNC\SHARDREALM\Users\Public\Recorded TV
  • c:\ProgramData\Microsoft\Windows Defender\Scans\CleanStore\Resources\F7
  • c:\ProgramData\Microsoft\Windows Defender\Scans\CleanStore\Resources\F3
  • c:\Python27\Lib\xml\parsers
  • c:\Python27\Lib\test\keycert4.pem
  • UNC\SHARDREALM\Users\Public\Foxit Software\Foxit Reader\StartPage\advertisement\normal Integrate PDF into your mobile apps.bmp
  • c:\Python27\tcl\tcl8.5\msgs
  • UNC\SHARDREALM\Users\Public\Foxit Software\Foxit Reader\StartPage\start\en_us\Default\right_move_bg.jpg
  • c:\ProgramData\Microsoft\Windows NT\MSFax\Inbox
  • c:\Users\Harry Dresden
  • c:\ProgramData\Microsoft\Windows Defender
  • c:\Python27\include\node.h
  • UNC\SHARDREALM\Users\Public\Foxit Software\Foxit Reader\StartPage\start\en_us\images\phantomPDF_b.png
  • c:\ProgramData\McAfee\MCLOGS\Common\jxpiinstall
  • c:\ProgramData\Microsoft\Windows Defender\Quarantine
  • c:\Users\Public\Favorites
  • c:\Python27\Lib\site-packages\pkg_resources\_vendor
  • UNC\SHARDREALM\Users\Public\Pictures\Sample Pictures\Penguins.jpg
  • c:\ProgramData\Microsoft\Office
  • UNC\SHARDREALM\Users\Harry Dresden\Downloads\big-hero-6-2.jpg
  • UNC\SHARDREALM\Users\Public
  • c:\ProgramData\NovaTech Network\NovaBench
  • UNC\SHARDREALM\Users\Public\Pictures\Sample Pictures\Tulips.jpg
  • c:\Python27\Lib\site-packages\pip\_vendor\_markerlib
  • c:\Python27\tcl\reg1.2
  • c:\Users\ruiner
  • c:\Python27\Lib\xml\etree
  • UNC\SHARDREALM\Users\Public\Foxit Software\Foxit Reader\StartPage\advertisement\normal Fastest PDF Search and Index.bmp
  • c:\ProgramData\Microsoft\Media Player
  • UNC\SHARDREALM\Users\Public\Foxit Software\Foxit Reader\StartPage\start\en_us\tpl
  • c:\Users\Public\Videos\Sample Videos
  • UNC\SHARDREALM\Users\Harry Dresden\Favorites
  • c:\ProgramData\Microsoft\Windows Defender\Scans\CleanStore\ResourceData\01
  • c:\Python27\include\cStringIO.h
  • c:\ProgramData\Microsoft\ClickToRun\MachineData\Catalog\Packages
  • c:\Python27\Lib\site-packages\pip\_vendor\requests\packages\urllib3\util
  • c:\ProgramData\Microsoft\OfficeSoftwareProtectionPlatform
  • c:\ypliys\bin\cert.p12
  • UNC\SHARDREALM\Users\Public\Foxit Software\Foxit Reader\StartPage\advertisement\normal Design form fields easily.bmp
  • c:\Python27\tcl\tcl8.5\tzdata\Antarctica
  • c:\Python27\Lib\xml\sax
  • c:\Python27\Lib\site-packages\pip\_vendor\html5lib\trie
  • c:\Users\Harry Dresden\Desktop
  • c:\Users\Public\Recorded TV
  • c:\ProgramData\Microsoft\Office\Heartbeat
  • c:\ProgramData\Microsoft\Windows Defender\Scans\CleanStore\Resources\42
  • c:\Python27\tcl\tcl8.5\tzdata\Etc
  • c:\Python27\Lib\bsddb
  • c:\ProgramData\Microsoft\Windows Defender\Scans\CleanStore\Resources\47
  • c:\ProgramData\Microsoft\Windows Defender\Scans\CleanStore\ResourceData\95
  • UNC\SHARDREALM\Users\Public\Pictures\Sample Pictures\Jellyfish.jpg
  • c:\ProgramData\Microsoft\ClickToRun\MachineData\Integration\ShortcutBackups
  • c:\Python27\Lib\wsgiref
  • c:\6cdeacda242012e0e5b593e657\1044\eula.rtf
  • c:\Python27\Lib\site-packages\pip\_vendor\requests\packages\urllib3\contrib
  • c:\Python27\include\pyfpe.h
  • c:\ProgramData\Microsoft\User Account Pictures
  • c:\ProgramData\Sun\Java\Java Update
  • c:\Python27\Lib\test\sha256.pem
  • UNC\SHARDREALM\Users\Public\Foxit Software\Foxit Reader\StartPage\start\en_us\images\phantomPDF_s.png
  • c:\Users
  • c:\Users\Default\Saved Games
  • c:\Python27\Lib\site-packages\pip\_vendor\pkg_resources
  • c:\inetpub\history\CFGHISTORY_0000000005\schema
  • c:\Python27\include\datetime.h
  • c:\inetpub
  • c:\Users\Default
  • c:\Python27\tcl\tcl8.5\tzdata\Pacific
  • c:\ProgramData\Microsoft\Windows NT\MSFax\ActivityLog
  • c:\Python27\tcl\tk8.5\msgs
  • c:\Python27\tcl\tcl8.5\tzdata\America
  • c:\ProgramData\Microsoft\Diagnosis\DownloadedSettings
  • c:\ProgramData\Microsoft\Windows Defender\Definition Updates\{98101498-C465-4F51-8751-D1919E97D29D}
  • c:\inetpub\wwwroot
  • c:\Python27\Lib\multiprocessing\dummy
  • UNC\SHARDREALM\Users\Public\Foxit Software\Foxit Reader\StartPage\advertisement\ribbon Integrate PDF into your application.bmp
  • c:\ProgramData\Microsoft\ClickToRun\MachineData\Catalog\Packages\{9AC08E99-230B-47E8-9721-4577B7F124EA}\{1A8308C7-90D1-4200-B16E-646F163A08E8}
  • c:\ProgramData\Microsoft\MF
  • c:\Python27\Lib\test
  • c:\Python27\Lib\test\keycert3.pem
  • c:\Users\Public\Downloads
  • c:\Python27\Lib\site-packages
  • UNC\SHARDREALM\Users\Public\Foxit Software\Foxit Reader\StartPage
  • c:\ProgramData\Microsoft\Device Stage\Task
  • UNC\SHARDREALM\Users\Public\Foxit Software\Foxit Reader\StartPage\advertisement\ribbon Fastest PDF Search and Index.bmp
  • c:\Python27\include\pyerrors.h
  • c:\Python27\Lib\unittest
  • c:\6cdeacda242012e0e5b593e657\Graphics
  • c:\ProgramData\Microsoft\Device Stage\Task\{07deb856-fc6e-4fb9-8add-d8f2cf8722c9}
  • c:\Python27\Lib\test\capath
  • c:\Users\Public\Foxit Software\Foxit Reader\StartPage\start\en_us\Default
  • UNC\SHARDREALM\Users\Public\Foxit Software\Foxit Reader\StartPage\start\en_us\images\blank.gif
  • c:\Recovery
  • c:\ProgramData\Microsoft\Device Stage
  • c:\Python27\tcl\tk8.5\demos
  • c:\Python27\include\ceval.h
  • c:\ProgramData\Microsoft\Crypto\RSA\S-1-5-18
  • UNC\SHARDREALM\Users\Public\Desktop
  • c:\ProgramData\Microsoft\Assistance\Client\1.0
  • c:\Python27\include\pythonrun.h
  • UNC\SHARDREALM\Users\Public\Foxit Software\Foxit Reader\StartPage\start\en_us\images\classic-16.png
  • c:\ProgramData\Oracle
  • c:\Python27\include\pygetopt.h
  • c:\Python27\Lib\distutils\tests
  • c:\Python27\include\codecs.h
  • c:\Python27\Lib\logging
  • c:\ProgramData\Microsoft\RAC
  • c:\Python27\Lib\site-packages\pip\req
  • c:\Users\Harry Dresden\Links
  • c:\ProgramData\Microsoft\DeviceSync
  • c:\Python27\Doc
  • c:\Users\Public\Pictures
  • c:\Python27\tcl\tix8.4.3\demos\bitmaps
  • UNC\SHARDREALM\Users\Public\Foxit Software\Foxit Reader\StartPage\advertisement\Profile.xml
  • c:\Python27\Lib\site-packages\pip\_vendor\requests
  • c:\Python27\include\patchlevel.h
  • c:\Python27\include\bytes_methods.h
  • c:\Python27\Lib\compiler
  • c:\Python27\Scripts
  • c:\ProgramData\Microsoft\Windows Defender\Scans\CleanStore\ResourceData\47
  • UNC\SHARDREALM\Users\Harry Dresden\Desktop
  • c:\ProgramData\Microsoft\Windows Defender\Scans\CleanStore\ResourceData\42
  • c:\ProgramData\Microsoft\Windows Defender\Scans\CleanStore\Resources\17
  • c:\Users\Public\Recorded TV\Sample Media
  • c:\Python27\Lib\test\keycert.pem
  • c:\Python27\tcl\dde1.3
  • c:\Python27\tcl\tcl8.5\tzdata\SystemV
  • c:\ProgramData\NovaTech Network
  • \\?\PIPE\lsarpc
  • UNC\SHARDREALM\Users\Public\Foxit Software\Foxit Reader\StartPage\advertisement\ribbon Powerful Word Processor.bmp
  • UNC\SHARDREALM\Users\ruiner
  • c:\ProgramData\Sun\Java
  • c:\Python27\Lib\test\ssl_cert.pem
  • c:\Users\Public\Foxit Software\Foxit Reader\StartPage\start\en_us\js
  • c:\ProgramData\Microsoft\Diagnosis\AsimovUploader
  • UNC\SHARDREALM\Users\Public\Foxit Software\Foxit Reader\StartPage\start\en_us\images\buy_phantom.png
  • c:\Users\Public\Foxit Software\Foxit Reader\StartPage\start\en_us\images
  • c:\Python27\tcl\tcl8.5\tzdata\Chile
  • c:\ProgramData\Microsoft\ClickToRun\UserData
  • c:\Python27\Lib\test\xmltestdata
  • c:\ProgramData\Microsoft\WPD
  • UNC\SHARDREALM\Users\Public\Foxit Software\Foxit Reader\StartPage\advertisement\normal View PDFs on mobile devices.bmp
  • c:\Python27\Lib\site-packages\pip\_vendor
  • c:\ProgramData\Sun
  • c:\Python27\include\Python.h
  • UNC\SHARDREALM\Users\Default\Documents
  • c:\6cdeacda242012e0e5b593e657\1041\eula.rtf
  • c:\ProgramData\Microsoft\Diagnosis\ETLLogs\ShutdownLogger
  • UNC\SHARDREALM\Users\Public\Foxit Software\Foxit Reader\StartPage\advertisement\ribbon View PDFs on mobile devices.bmp
  • c:\Python27\include\metagrammar.h
  • UNC\SHARDREALM\Users\Public\Foxit Software\Foxit Reader\StartPage\advertisement\normal Protect your PDF files with AD RMS.bmp
  • c:\Python27\include\pystate.h
  • c:\Users\Default\Desktop
  • c:\ProgramData\Microsoft\Windows Defender\Scans\CleanStore\Resources\1A
  • c:\Python27\Lib\site-packages\pip\_vendor\html5lib\treewalkers
  • UNC\SHARDREALM\Users\Public\Foxit Software\Foxit Reader\StartPage\start\en_us\version.xml
  • c:\ProgramData\Microsoft\Device Stage\Device\{113527a4-45d4-4b6f-b567-97838f1b04b0}
  • c:\ProgramData\Microsoft\WwanSvc
  • c:\Python27\include\pyconfig.h
  • \\?\PIPE\wkssvc
  • c:\ProgramData\Microsoft\Event Viewer\Views
  • c:\Python27\Lib\json\tests
  • c:\Python27\Lib\site-packages\pip\_vendor\html5lib\serializer
  • c:\Python27\include\osdefs.h
  • c:\Python27\Tools
  • UNC\SHARDREALM\Users\Public\Foxit Software\Foxit Reader\StartPage\start\en_us\css
  • c:\ProgramData\Microsoft\IlsCache
  • c:\Python27\Lib\lib-tk
  • c:\ProgramData\Microsoft\Windows Defender\Scans\History\Store
  • c:\ProgramData\Microsoft\Windows NT\MSFax\SentItems
  • UNC\SHARDREALM\Users\Public\Foxit Software\Foxit Reader\StartPage\start\en_us\js\nor.js
  • c:\ProgramData\Microsoft\ClickToRun\ProductReleases\9E1D94D2-471F-4DC3-9EBD-E31E1E099E00\en-us.16
  • c:\Python27\Lib\site-packages\pip\operations
  • c:\ProgramData\Microsoft\Windows NT\MSFax\VirtualInbox
  • c:\Python27\Lib\site-packages\pip\_vendor\lockfile
  • c:\Python27\Lib\curses
  • c:\6cdeacda242012e0e5b593e657\1037\eula.rtf
  • c:\ProgramData\Microsoft\ClickToRun\MachineData\Catalog\Packages\{9AC08E99-230B-47E8-9721-4577B7F124EA}
  • UNC\SHARDREALM\Users\Public\Pictures\Sample Pictures
  • c:\Python27\include\pystrcmp.h
  • c:\Python27\Lib\test\pycacert.pem
  • UNC\SHARDREALM\Users\Public\Foxit Software\Foxit Reader\StartPage\start\en_us\Default\top_tb_bg.jpg
  • c:\Python27\include\pymactoolbox.h
  • c:\Python27\Lib\test\badkey.pem
  • c:\ProgramData\Microsoft\ClickToRun\MachineData\Integration
  • UNC\SHARDREALM\Users\Public\Foxit Software\Foxit Reader\StartPage\advertisement\normal Powerful Word Processor.bmp
  • c:\Users\Default\Music
  • c:\Python27\Lib\email\mime
  • c:\Users\Harry Dresden\Music
  • c:\6cdeacda242012e0e5b593e657\1053
  • c:\6cdeacda242012e0e5b593e657\1055
  • UNC\SHARDREALM\Users\Public\Favorites
  • c:\Python27\Lib\site-packages\pip\_vendor\requests\packages\urllib3
  • c:\Python27\tcl\tcl8.5\tzdata\Asia
  • UNC\SHARDREALM\Users\Public\Downloads
  • c:\Users\Public\Foxit Software\Foxit Reader\StartPage\start\en_us\css
  • c:\Python27\Lib\multiprocessing
  • c:\Users\Default\Documents
  • c:\Python27\Tools\pynche
  • c:\Users\Public\Desktop
  • c:\ProgramData\Microsoft\User Account Pictures\Default Pictures
  • UNC\SHARDREALM\Users\Harry Dresden\Downloads
  • c:\Python27\Lib\lib-tk\test\test_ttk
  • c:\Users\Harry Dresden\Documents
  • c:\ProgramData\McAfee\MCLOGS\Common
  • UNC\SHARDREALM\Users\Harry Dresden\Favorites\Links
  • UNC\SHARDREALM\Users\Public\Foxit Software\Foxit Reader\StartPage\advertisement\ribbon Protect Sensitive PDF Documents.bmp
  • c:\ProgramData\Microsoft\IdentityCRL
  • c:\ProgramData\WebEx\WebEx\12_1324
  • c:\ypliys\bin
  • c:\ProgramData\WebEx\WebEx\12_1324\gpc.php
  • c:\Python27\Lib\site-packages\pip\utils
  • c:\Python27\Lib\distutils\command
  • c:\Users\Harry Dresden\Saved Games
  • UNC\SHARDREALM\Users\Public\Foxit Software\Foxit Reader\StartPage\advertisement\normal Edit and reflow paragraphs in PDF files.bmp
  • UNC\SHARDREALM\Users\Default
  • c:\Python27\include\pyarena.h
  • UNC\SHARDREALM\Users\Public\Recorded TV\Sample Media
  • UNC\SHARDREALM\Users\Public\Foxit Software\Foxit Reader\StartPage\start\en_us\Default\right_over_bg.jpg
  • c:\Python27
  • c:\Python27\Lib\hotshot
  • UNC\SHARDREALM\Users\Public\Foxit Software\Foxit Reader
  • UNC\SHARDREALM\Users\Harry Dresden\Downloads\cleandesktop.py.txt
  • c:\Python27\Tools\versioncheck
  • c:\Python27\tcl\tcl8.5\tzdata\Arctic
  • c:\ProgramData\Microsoft\Windows Defender\Scans\CleanStore\ResourceData\F7
  • c:\Users\Public\Music
  • c:\ProgramData\Microsoft\Windows Defender\Scans\CleanStore\ResourceData\F3
  • c:\Python27\Lib\test\audiodata
  • UNC\SHARDREALM\Users\Public\Pictures\Sample Pictures\Desert.jpg
  • c:\Python27\Lib\site-packages\pip\_vendor\html5lib\treeadapters
  • c:\Python27\include\intrcheck.h
  • c:\ProgramData\Microsoft\Network\Connections
  • c:\Python27\Lib\sqlite3
  • c:\ProgramData\Microsoft\Crypto\RSA\MachineKeys
  • UNC\SHARDREALM\Users\Public\Pictures
  • c:\Python27\Lib\site-packages\pip\_vendor\html5lib
  • c:\ProgramData\Microsoft\Windows Defender\Scans\CleanStore\Resources\43
  • UNC\SHARDREALM\Users\Public\Foxit Software\Foxit Reader\StartPage\start\en_us\js
  • UNC\SHARDREALM\Users\Default\Downloads
  • UNC\SHARDREALM\Users\Default\Links
  • UNC\SHARDREALM\Users\Public\Pictures\Sample Pictures\Lighthouse.jpg
  • c:\ProgramData\Microsoft\Diagnosis
  • c:\Python27\Lib\distutils
  • c:\Python27\Lib\site-packages\pip\_vendor\pkg_resources\tests
  • c:\Python27\Lib\idlelib\Icons
  • c:\ProgramData\Microsoft\Device Stage\Device
  • c:\Python27\Lib\site-packages\pip\_vendor\distlib
  • c:\Python27\Lib\test\subprocessdata
  • c:\ProgramData\Microsoft\Windows Defender\Scans\CleanStore\ResourceData\35
  • c:\Python27\include\pymem.h
  • c:\inetpub\wwwroot\aspnet_client
  • c:\Python27\Lib\site-packages\pip\_vendor\requests\cacert.pem
  • c:\ProgramData\Microsoft\Network\Downloader
  • UNC\SHARDREALM\Users\Harry Dresden\Desktop\eHPRzxmJiIkx.rtf
  • c:\Users\Public\Foxit Software
  • c:\ProgramData\Microsoft\Windows Defender\Scans\History\Results\Quick
  • c:\ProgramData\Microsoft\Windows NT\MSScan
  • c:\Python27\Lib\lib2to3\tests
  • c:\Python27\Lib\site-packages\pip-7.0.1.dist-info
  • UNC\SHARDREALM\Users\Public\Foxit Software\Foxit Reader\StartPage\advertisement\ribbon Create PDF from Office-convert PDF to office.bmp
  • c:\Python27\Lib\test\selfsigned_pythontestdotnet.pem
  • c:\ProgramData\Microsoft OneDrive\setup
  • c:\ypliys\lib\api
  • c:\ProgramData\Microsoft\Crypto\DSS\MachineKeys
  • c:\6cdeacda242012e0e5b593e657\2070\eula.rtf
  • c:\Python27\Lib\site-packages\pkg_resources
  • c:\Users\Public\Foxit Software\Foxit Reader\StartPage\advertisement
  • c:\Python27\Lib\site-packages\setuptools-16.0.dist-info
  • c:\Python27\include\Python-ast.h
  • c:\Python27\tcl\tcl8.5\tzdata\Brazil
  • UNC\SHARDREALM\Users\Harry Dresden\Desktop\NZZNgxshHiXH.docm
  • c:\Users\Harry Dresden\Favorites\Links
  • c:\Python27\Lib\test\imghdrdata
  • c:\Python27\include\iterobject.h
  • c:\ProgramData\Microsoft\Windows Defender\Definition Updates\Updates
  • UNC\SHARDREALM\Users\Harry Dresden\Saved Games
  • c:\ProgramData\Microsoft\RAC\Outbound
  • UNC\SHARDREALM\Users\Public\Foxit Software\Foxit Reader\StartPage\advertisement\normal Integrate PDF into your application.bmp
  • c:\inetpub\history\CFGHISTORY_0000000002
  • c:\Python27\include\listobject.h
  • c:\ProgramData\Microsoft\NetFramework
  • c:\ProgramData\Adobe\ARM\Reader_11.0.10
  • c:\ProgramData\Microsoft
  • UNC\SHARDREALM\Users\Harry Dresden\Desktop\HzwwphkzJpxtFEf.ppt
  • c:\ProgramData\Microsoft\Windows Defender\Scans\History\Service
  • c:\ypliys\lib
  • UNC\SHARDREALM\Users\Public\Foxit Software\Foxit Reader\StartPage\start\en_us\images\ribbon-16-open.png
  • c:\Users\Default\Videos
  • c:\ProgramData\Microsoft\Search\Data
  • c:\Python27\tcl
  • c:\Python27\Lib\json
  • c:\ProgramData\Microsoft\Windows NT\MSFax\VirtualInbox\en-US
  • c:\Python27\include\pythread.h
  • UNC\SHARDREALM\Users\Public\Foxit Software\Foxit Reader\StartPage\advertisement
  • c:\Python27\Lib\lib2to3\fixes
  • c:\Python27\tcl\tix8.4.3\bitmaps
  • c:\Python27\Lib\site-packages\setuptools\command
  • c:\6cdeacda242012e0e5b593e657
  • c:\Python27\tcl\tcl8.5\tzdata\America\Indiana
  • c:\6cdeacda242012e0e5b593e657\2070
  • c:\Users\Public\Pictures\Sample Pictures
  • c:\Users\Public\Videos
  • c:\Python27\Lib\test\decimaltestdata
  • c:\ProgramData\Microsoft\Windows Defender\Scans\CleanStore\Resources\DD
  • c:\Python27\include\descrobject.h
  • c:\ProgramData\Microsoft\Diagnosis\UIF
  • c:\ProgramData\Microsoft\Windows Defender\Scans\CleanStore\ResourceData\A6
  • c:\Python27\tcl\tcl8.5\tzdata\Europe
  • c:\ProgramData\Microsoft\Windows Defender\Scans\CleanStore\ResourceData\A5
  • c:\Python27\Lib\lib2to3
  • UNC\SHARDREALM\Users\Public\Foxit Software\Foxit Reader\StartPage\start
  • UNC\SHARDREALM\Users\Public\Foxit Software\Foxit Reader\StartPage\start\en_us\Default
  • c:\ProgramData\Microsoft\Event Viewer
  • c:\ProgramData\Adobe\Setup\{AC76BA86-7AD7-1033-7B44-AB0000000001}
  • c:\Python27\tcl\tix8.4.3\pref\Gray.cs
  • c:\Python27\Lib\test\ssl_key.pem
  • c:\ProgramData\Microsoft\ClickToRun
  • c:\Python27\tcl\tix8.4.3\pref
  • c:\Python27\include\methodobject.h
  • c:\Python27\include\cobject.h
  • c:\ProgramData\Adobe\ARM\S\5521
  • c:\Python27\tcl\tcl8.5\http1.0
  • c:\Python27\include\pymath.h
  • c:\Users\Public\Foxit Software\Foxit Reader\StartPage\start
  • c:\6cdeacda242012e0e5b593e657\1038\eula.rtf
  • c:\Python27\include\parsetok.h
  • c:\ProgramData\Adobe\Acrobat\11.0
  • c:\Python27\Lib\ensurepip\_bundled
  • UNC\SHARDREALM\Users\Public\Foxit Software\Foxit Reader\StartPage\start\en_us\Default\show_con_bg.jpg
  • c:\Python27\include\classobject.h
  • UNC\SHARDREALM\Users\Public\Foxit Software\Foxit Reader\StartPage\start\en_us
  • c:\Python27\Lib\test\ssl_key.passwd.pem
  • c:\Users\Public\Music\Sample Music
  • c:\Python27\tcl\tcl8
  • c:\ProgramData\Microsoft\Windows Defender\Scans\History\CacheManager
  • c:\Python27\Lib\lib2to3\tests\data
  • c:\ProgramData\Microsoft\OfficeSoftwareProtectionPlatform\Cache
  • c:\ProgramData\Microsoft\Windows Defender\Scans\CleanStore\ResourceData\70
  • c:\ProgramData\Microsoft OneDrive
  • UNC\SHARDREALM\Users\Harry Dresden\Searches
  • c:\Python27\tcl\tcl8.5\tzdata\America\Argentina
  • c:\Recovery\015e7760-d44b-11e0-8947-954f09601788
  • c:\Python27\Lib\idlelib
  • c:\PerfLogs\Admin
  • c:\Python27\Lib\site-packages\pip\_vendor\progress
  • c:\Users\Harry Dresden\Pictures
  • c:\ProgramData\Microsoft\Diagnosis\Sideload
  • c:\Python27\Lib\site-packages\pip\_vendor\requests\packages\urllib3\packages\ssl_match_hostname
  • c:\Users\Harry Dresden\Favorites
  • c:\ProgramData\Passmark
  • c:\Python27\Lib\lib-tk\test
  • c:\6cdeacda242012e0e5b593e657\1049\eula.rtf
  • c:\ProgramData\Adobe
  • c:\Users\Public\Foxit Software\Foxit Reader
  • c:\ProgramData\Microsoft\Search
  • c:\ProgramData\Passmark\PerformanceTest
  • UNC\SHARDREALM\Users\Public\Videos\Sample Videos
  • c:\Python27\include\bytearrayobject.h
  • c:\ProgramData\Microsoft\NetFramework\BreadcrumbStore
  • c:\Python27\Lib\email\test
  • c:\ProgramData\Microsoft\ClickToRun\{9AC08E99-230B-47e8-9721-4577B7F124EA}
  • c:\ProgramData\WebEx
  • c:\ypliys\lib\core
  • c:\inetpub\wwwroot\msmq
  • c:\Python27\tcl\tix8.4.3\demos
  • UNC\SHARDREALM\Users\Public\Foxit Software\Foxit Reader\StartPage\advertisement\normal View and annotate PDFs.bmp
  • c:\Python27\Lib\site-packages\pkg_resources\_vendor\packaging
  • c:\ProgramData\McAfee\MCLOGS
  • c:\Users\Default\Pictures
  • c:\6cdeacda242012e0e5b593e657\1049
  • c:\Users\Public\Documents
  • c:\6cdeacda242012e0e5b593e657\1046
  • c:\6cdeacda242012e0e5b593e657\1045
  • c:\6cdeacda242012e0e5b593e657\1044
  • c:\6cdeacda242012e0e5b593e657\1043
  • c:\6cdeacda242012e0e5b593e657\1042
  • c:\6cdeacda242012e0e5b593e657\1041
  • c:\6cdeacda242012e0e5b593e657\1040
  • c:\Python27\Lib\site-packages\pip\_vendor\packaging
  • c:\ProgramData\Microsoft\eHome\logs
  • c:\ProgramData\Microsoft\Windows Defender\Scans
  • c:\ProgramData\Microsoft\Windows NT\MSFax
  • c:\ProgramData\Microsoft\Windows Defender\Definition Updates\Backup
  • UNC\SHARDREALM\Users\Public\Foxit Software\Foxit Reader\StartPage\start\en_us\Default\body_bg.jpg
  • c:\Python27\Lib\test\nullbytecert.pem
  • c:\Python27\Lib\sqlite3\test
  • c:\Python27\Lib\test\dh1024.pem
  • c:\ProgramData\Mozilla
  • UNC\SHARDREALM\Users\Public\Pictures\Sample Pictures\Hydrangeas.jpg
  • c:\6cdeacda242012e0e5b593e657\1055\eula.rtf
  • UNC\SHARDREALM\Users\Public\Pictures\Sample Pictures\Chrysanthemum.jpg
  • c:\ProgramData\Microsoft\Windows Defender\Scans\CleanStore\ResourceData\E0
  • UNC\SHARDREALM\Users\Public\Foxit Software\Foxit Reader\StartPage\advertisement\ribbon View and annotate PDFs.bmp
  • c:\ProgramData\Microsoft\Windows Defender\Definition Updates
  • c:\Python27\Lib\lib2to3\pgen2
  • c:\ProgramData\Microsoft\Windows Defender\Scans\History
  • c:\Python27\include\code.h
  • c:\Python27\include\cellobject.h
  • c:\ProgramData\Microsoft\RAC\StateData
  • c:\6cdeacda242012e0e5b593e657\1038
  • c:\ProgramData\Microsoft\DRM\Server
  • c:\6cdeacda242012e0e5b593e657\1032
  • c:\6cdeacda242012e0e5b593e657\1033
  • c:\6cdeacda242012e0e5b593e657\1030
  • c:\6cdeacda242012e0e5b593e657\1031
  • c:\6cdeacda242012e0e5b593e657\1036
  • c:\6cdeacda242012e0e5b593e657\1037
  • c:\6cdeacda242012e0e5b593e657\1035
File-Moved
  • c:\Python27\include\pyerrors.h -> c:\Python27\include\076E35C0--5E29--6BE8--920574C3--D096F6D42841.osiris
  • \\SHARDREALM\Users\Harry Dresden\Desktop\bqsEpYOgZP.pptx -> \\SHARDREALM\Users\Harry Dresden\Desktop\076E35C0--5E29--6BE8--0052E066--2BA06D13E418.osiris
  • \\SHARDREALM\Users\Public\Foxit Software\Foxit Reader\StartPage\start\en_us\js\DD_belatedPNG.js -> \\SHARDREALM\Users\Public\Foxit Software\Foxit Reader\StartPage\start\en_us\js\076E35C0--5E29--6BE8--8CDC6344--0E46841FF45A.osiris
  • c:\Python27\include\ast.h -> c:\Python27\include\076E35C0--5E29--6BE8--B0350204--96ED822FCEF0.osiris
  • c:\Python27\include\pyctype.h -> c:\Python27\include\076E35C0--5E29--6BE8--3CE29387--217F1EC504FD.osiris
  • c:\Python27\include\bytesobject.h -> c:\Python27\include\076E35C0--5E29--6BE8--988115C0--E17713C02F87.osiris
  • \\SHARDREALM\Users\Public\Foxit Software\Foxit Reader\StartPage\advertisement\ribbon Integrate PDF into your application.bmp -> \\SHARDREALM\Users\Public\Foxit Software\Foxit Reader\StartPage\advertisement\076E35C0--5E29--6BE8--D0D614B2--1B64387C350F.osiris
  • c:\Python27\include\pyconfig.h -> c:\Python27\include\076E35C0--5E29--6BE8--8FAB088B--9B61B1B10DAF.osiris
  • \\SHARDREALM\Users\Public\Foxit Software\Foxit Reader\StartPage\start\en_us\Default\content_showbg.jpg -> \\SHARDREALM\Users\Public\Foxit Software\Foxit Reader\StartPage\start\en_us\Default\076E35C0--5E29--6BE8--2350FC82--93F29E1AD7EE.osiris
  • c:\Python27\tcl\tix8.4.3\pref\Gray.cs -> c:\Python27\tcl\tix8.4.3\pref\076E35C0--5E29--6BE8--303D1B89--A97539E9A0EB.osiris
  • \\SHARDREALM\Users\Public\Foxit Software\Foxit Reader\StartPage\start\en_us\images\ribbon-16.png -> \\SHARDREALM\Users\Public\Foxit Software\Foxit Reader\StartPage\start\en_us\images\076E35C0--5E29--6BE8--39DC4EA1--747EFF6B8A04.osiris
  • c:\Python27\include\listobject.h -> c:\Python27\include\076E35C0--5E29--6BE8--71CF9386--DE1D6FDA2267.osiris
  • \\SHARDREALM\Users\Public\Pictures\Sample Pictures\Tulips.jpg -> \\SHARDREALM\Users\Public\Pictures\Sample Pictures\076E35C0--5E29--6BE8--6844B42D--66092FBD1DA7.osiris
  • \\SHARDREALM\Users\Public\Pictures\Sample Pictures\Desert.jpg -> \\SHARDREALM\Users\Public\Pictures\Sample Pictures\076E35C0--5E29--6BE8--83ED97CE--64457E242FA3.osiris
  • \\SHARDREALM\Users\Public\Pictures\Sample Pictures\Chrysanthemum.jpg -> \\SHARDREALM\Users\Public\Pictures\Sample Pictures\076E35C0--5E29--6BE8--02B31118--4B1F48587552.osiris
  • c:\6cdeacda242012e0e5b593e657\1044\eula.rtf -> c:\6cdeacda242012e0e5b593e657\1044\076E35C0--5E29--6BE8--B3B23066--AC55B541C152.osiris
  • c:\Python27\include\pyport.h -> c:\Python27\include\076E35C0--5E29--6BE8--178D6D37--91463E34C082.osiris
  • c:\Python27\include\pythonrun.h -> c:\Python27\include\076E35C0--5E29--6BE8--4E3F2987--DD3FB0F7A196.osiris
  • \\SHARDREALM\Users\Public\Foxit Software\Foxit Reader\StartPage\advertisement\normal Create PDF from Office-convert PDF to office.bmp -> \\SHARDREALM\Users\Public\Foxit Software\Foxit Reader\StartPage\advertisement\076E35C0--5E29--6BE8--6066B048--29E0FA833EFE.osiris
  • \\SHARDREALM\Users\Public\Foxit Software\Foxit Reader\StartPage\advertisement\ribbon Integrate PDF into your mobile apps.bmp -> \\SHARDREALM\Users\Public\Foxit Software\Foxit Reader\StartPage\advertisement\076E35C0--5E29--6BE8--66132EE7--32D285A3E75C.osiris
  • \\SHARDREALM\Users\Public\Foxit Software\Foxit Reader\StartPage\advertisement\normal Powerful Word Processor.bmp -> \\SHARDREALM\Users\Public\Foxit Software\Foxit Reader\StartPage\advertisement\076E35C0--5E29--6BE8--2D4FEBCC--C482B75B0337.osiris
  • \\SHARDREALM\Users\Public\Foxit Software\Foxit Reader\StartPage\advertisement\normal Integrate PDF into your mobile apps.bmp -> \\SHARDREALM\Users\Public\Foxit Software\Foxit Reader\StartPage\advertisement\076E35C0--5E29--6BE8--92C21825--777666DB9D78.osiris
  • c:\Python27\include\pydebug.h -> c:\Python27\include\076E35C0--5E29--6BE8--D5648CA7--738AB0E50881.osiris
  • \\SHARDREALM\Users\Public\Foxit Software\Foxit Reader\StartPage\start\en_us\Default\right_over_bg.jpg -> \\SHARDREALM\Users\Public\Foxit Software\Foxit Reader\StartPage\start\en_us\Default\076E35C0--5E29--6BE8--89E074D3--0BE8C2EBF085.osiris
  • c:\Python27\include\opcode.h -> c:\Python27\include\076E35C0--5E29--6BE8--01345012--B658A319D8C1.osiris
  • c:\6cdeacda242012e0e5b593e657\2070\eula.rtf -> c:\6cdeacda242012e0e5b593e657\2070\076E35C0--5E29--6BE8--AAAE4661--F5D5ED101145.osiris
  • c:\Python27\include\intrcheck.h -> c:\Python27\include\076E35C0--5E29--6BE8--5095B489--7639E49839CC.osiris
  • c:\Python27\include\pymactoolbox.h -> c:\Python27\include\076E35C0--5E29--6BE8--ACC53B55--2448FF1B41CA.osiris
  • c:\Python27\include\pygetopt.h -> c:\Python27\include\076E35C0--5E29--6BE8--81746DDF--F29AB01E2B5B.osiris
  • c:\Python27\include\pyexpat.h -> c:\Python27\include\076E35C0--5E29--6BE8--6DF60E48--ABAF8D757CA8.osiris
  • c:\Python27\include\abstract.h -> c:\Python27\include\076E35C0--5E29--6BE8--DAA939B1--A7B82699241D.osiris
  • c:\Python27\include\iterobject.h -> c:\Python27\include\076E35C0--5E29--6BE8--B4AC325A--15F58B38F83F.osiris
  • c:\Python27\Lib\test\ssl_cert.pem -> c:\Python27\Lib\test\076E35C0--5E29--6BE8--A891BD53--69CCB81EE1A0.osiris
  • c:\Python27\include\Python-ast.h -> c:\Python27\include\076E35C0--5E29--6BE8--0EFE5D3C--3CFF321466EC.osiris
  • \\SHARDREALM\Users\Harry Dresden\Downloads\big-hero-6-2.jpg -> \\SHARDREALM\Users\Harry Dresden\Downloads\076E35C0--5E29--6BE8--52B5D5F3--862B004C4E90.osiris
  • \\SHARDREALM\Users\Public\Pictures\Sample Pictures\Jellyfish.jpg -> \\SHARDREALM\Users\Public\Pictures\Sample Pictures\076E35C0--5E29--6BE8--81729940--9E22A6493951.osiris
  • c:\6cdeacda242012e0e5b593e657\1046\eula.rtf -> c:\6cdeacda242012e0e5b593e657\1046\076E35C0--5E29--6BE8--8F184BAB--F93919116041.osiris
  • \\SHARDREALM\Users\Public\Foxit Software\Foxit Reader\StartPage\advertisement\ProfileRibbon.xml -> \\SHARDREALM\Users\Public\Foxit Software\Foxit Reader\StartPage\advertisement\076E35C0--5E29--6BE8--308AF5AD--878471AC98F9.osiris
  • \\SHARDREALM\Users\Public\Foxit Software\Foxit Reader\StartPage\advertisement\normal Enterprise PDF Reader.bmp -> \\SHARDREALM\Users\Public\Foxit Software\Foxit Reader\StartPage\advertisement\076E35C0--5E29--6BE8--D9FA3AE4--D9E660BA0AD4.osiris
  • c:\Python27\include\datetime.h -> c:\Python27\include\076E35C0--5E29--6BE8--6CD2B81A--A3B192F71C22.osiris
  • \\SHARDREALM\Users\Public\Foxit Software\Foxit Reader\StartPage\advertisement\normal View PDFs on mobile devices.bmp -> \\SHARDREALM\Users\Public\Foxit Software\Foxit Reader\StartPage\advertisement\076E35C0--5E29--6BE8--9B378F27--CDBB3F28269A.osiris
  • c:\6cdeacda242012e0e5b593e657\1042\eula.rtf -> c:\6cdeacda242012e0e5b593e657\1042\076E35C0--5E29--6BE8--B45CAF34--D15AE0F903C9.osiris
  • c:\Python27\include\pgen.h -> c:\Python27\include\076E35C0--5E29--6BE8--616DB204--1ED907B2BBC7.osiris
  • c:\Python27\include\pymacconfig.h -> c:\Python27\include\076E35C0--5E29--6BE8--39BA852D--A82DA5762CAE.osiris
  • c:\Python27\include\code.h -> c:\Python27\include\076E35C0--5E29--6BE8--8FE95800--614ED385143F.osiris
  • \\SHARDREALM\Users\Public\Foxit Software\Foxit Reader\StartPage\start\en_us\Default\line.jpg -> \\SHARDREALM\Users\Public\Foxit Software\Foxit Reader\StartPage\start\en_us\Default\076E35C0--5E29--6BE8--417D17B0--F23CB45EF051.osiris
  • c:\Python27\include\cellobject.h -> c:\Python27\include\076E35C0--5E29--6BE8--1D4143BD--2047304009DF.osiris
  • c:\6cdeacda242012e0e5b593e657\1037\eula.rtf -> c:\6cdeacda242012e0e5b593e657\1037\076E35C0--5E29--6BE8--BE9EAD13--2049CB29FFB6.osiris
  • \\SHARDREALM\Users\Harry Dresden\Desktop\adTQZDoJeOeg.docx -> \\SHARDREALM\Users\Harry Dresden\Desktop\076E35C0--5E29--6BE8--DE079E22--948E003A51D3.osiris
  • \\SHARDREALM\Users\Public\Foxit Software\Foxit Reader\StartPage\start\en_us\version.xml -> \\SHARDREALM\Users\Public\Foxit Software\Foxit Reader\StartPage\start\en_us\076E35C0--5E29--6BE8--18DC7338--CA574AEC4F31.osiris
  • c:\Python27\include\pystrtod.h -> c:\Python27\include\076E35C0--5E29--6BE8--0CFCB0F1--42C1EF457881.osiris
  • c:\Python27\include\cobject.h -> c:\Python27\include\076E35C0--5E29--6BE8--BEA3B724--6B38D8CAFAD9.osiris
  • \\SHARDREALM\Users\Harry Dresden\Desktop\eHPRzxmJiIkx.rtf -> \\SHARDREALM\Users\Harry Dresden\Desktop\076E35C0--5E29--6BE8--56BB32EB--0E9B50D89ABD.osiris
  • \\SHARDREALM\Users\Public\Foxit Software\Foxit Reader\StartPage\start\en_us\images\blank.gif -> \\SHARDREALM\Users\Public\Foxit Software\Foxit Reader\StartPage\start\en_us\images\076E35C0--5E29--6BE8--31493E1D--370739F15364.osiris
  • \\SHARDREALM\Users\Public\Foxit Software\Foxit Reader\StartPage\start\en_us\images\phantomPDF_s.png -> \\SHARDREALM\Users\Public\Foxit Software\Foxit Reader\StartPage\start\en_us\images\076E35C0--5E29--6BE8--1ACDCF1F--49F2454409AF.osiris
  • \\SHARDREALM\Users\Public\Foxit Software\Foxit Reader\StartPage\start\en_us\images\classic-16.png -> \\SHARDREALM\Users\Public\Foxit Software\Foxit Reader\StartPage\start\en_us\images\076E35C0--5E29--6BE8--EE5F5C00--5A25410D5D79.osiris
  • c:\Python27\include\codecs.h -> c:\Python27\include\076E35C0--5E29--6BE8--50F8B6B5--81828CCD5B6F.osiris
  • \\SHARDREALM\Users\Public\Foxit Software\Foxit Reader\StartPage\start\en_us\images\phantomPDF_b.png -> \\SHARDREALM\Users\Public\Foxit Software\Foxit Reader\StartPage\start\en_us\images\076E35C0--5E29--6BE8--818341AD--1CF2F55C0834.osiris
  • \\SHARDREALM\Users\Public\Pictures\Sample Pictures\Koala.jpg -> \\SHARDREALM\Users\Public\Pictures\Sample Pictures\076E35C0--5E29--6BE8--D8E23C2F--AD2C0F3C04D4.osiris
  • \\SHARDREALM\Users\Harry Dresden\Downloads\cleandesktop.py.txt -> \\SHARDREALM\Users\Harry Dresden\Downloads\076E35C0--5E29--6BE8--20C86054--A5916EE60056.osiris
  • c:\Python27\Lib\test\keycert.passwd.pem -> c:\Python27\Lib\test\076E35C0--5E29--6BE8--D4D6000A--76C3DF036BFD.osiris
  • c:\6cdeacda242012e0e5b593e657\1049\eula.rtf -> c:\6cdeacda242012e0e5b593e657\1049\076E35C0--5E29--6BE8--3EE8EC70--913981E3DF8F.osiris
  • c:\Python27\Lib\test\keycert3.pem -> c:\Python27\Lib\test\076E35C0--5E29--6BE8--B8720FED--B3CF9AF5789D.osiris
  • c:\Python27\tcl\tix8.4.3\pref\Bisque.cs -> c:\Python27\tcl\tix8.4.3\pref\076E35C0--5E29--6BE8--160DF83A--371F649F4E3F.osiris
  • c:\6cdeacda242012e0e5b593e657\1043\eula.rtf -> c:\6cdeacda242012e0e5b593e657\1043\076E35C0--5E29--6BE8--98EC6E2F--AD77606D0279.osiris
  • c:\Python27\Lib\test\selfsigned_pythontestdotnet.pem -> c:\Python27\Lib\test\076E35C0--5E29--6BE8--C1E9F0A8--BE3A12315225.osiris
  • c:\Python27\include\ceval.h -> c:\Python27\include\076E35C0--5E29--6BE8--F98276A8--AD207CBFD3A5.osiris
  • c:\Python27\include\bytes_methods.h -> c:\Python27\include\076E35C0--5E29--6BE8--D2375B13--E2A421E2868D.osiris
  • c:\Python27\include\modsupport.h -> c:\Python27\include\076E35C0--5E29--6BE8--6E84B0BA--CDDAC52F52BD.osiris
  • c:\Python27\Lib\test\ssl_key.pem -> c:\Python27\Lib\test\076E35C0--5E29--6BE8--E1153321--B791AAE94986.osiris
  • \\SHARDREALM\Users\Public\Foxit Software\Foxit Reader\StartPage\advertisement\normal Integrate PDF into your application.bmp -> \\SHARDREALM\Users\Public\Foxit Software\Foxit Reader\StartPage\advertisement\076E35C0--5E29--6BE8--275E9E42--2F3AE2F044B6.osiris
  • c:\Python27\Lib\test\nokia.pem -> c:\Python27\Lib\test\076E35C0--5E29--6BE8--69E00089--624E5D4FA4D2.osiris
  • c:\Python27\include\pymem.h -> c:\Python27\include\076E35C0--5E29--6BE8--698E7B14--974CCE6CBCA2.osiris
  • \\SHARDREALM\Users\Public\Foxit Software\Foxit Reader\StartPage\start\en_us\Default\top_tb_bg.jpg -> \\SHARDREALM\Users\Public\Foxit Software\Foxit Reader\StartPage\start\en_us\Default\076E35C0--5E29--6BE8--E9A62015--FA8DE6A57988.osiris
  • \\SHARDREALM\Users\Harry Dresden\Desktop\HzwwphkzJpxtFEf.ppt -> \\SHARDREALM\Users\Harry Dresden\Desktop\076E35C0--5E29--6BE8--37A22110--421FCCB50CA7.osiris
  • \\SHARDREALM\Users\Public\Foxit Software\Foxit Reader\StartPage\advertisement\ribbon Powerful Word Processor.bmp -> \\SHARDREALM\Users\Public\Foxit Software\Foxit Reader\StartPage\advertisement\076E35C0--5E29--6BE8--C0423566--DE4CB4B5E614.osiris
  • \\SHARDREALM\Users\Public\Pictures\Sample Pictures\Penguins.jpg -> \\SHARDREALM\Users\Public\Pictures\Sample Pictures\076E35C0--5E29--6BE8--6DA342A2--E144B710EB70.osiris
  • c:\6cdeacda242012e0e5b593e657\1055\eula.rtf -> c:\6cdeacda242012e0e5b593e657\1055\076E35C0--5E29--6BE8--B0F0B337--00962AD1A984.osiris
  • c:\Python27\include\marshal.h -> c:\Python27\include\076E35C0--5E29--6BE8--310FBEF1--89A5E238FD83.osiris
  • c:\Python27\Lib\test\nullcert.pem -> c:\Python27\Lib\test\076E35C0--5E29--6BE8--4AC59CC3--09906B0F3CF6.osiris
  • \\SHARDREALM\Users\Harry Dresden\Desktop\QklFQHQmyNiNvWOam.doc -> \\SHARDREALM\Users\Harry Dresden\Desktop\076E35C0--5E29--6BE8--9A1AD706--A363B739C7A9.osiris
  • c:\Python27\include\classobject.h -> c:\Python27\include\076E35C0--5E29--6BE8--B83D855D--ED4567E8C26A.osiris
  • c:\Python27\Lib\test\ssl_key.passwd.pem -> c:\Python27\Lib\test\076E35C0--5E29--6BE8--803316B2--8F762E2AEAFC.osiris
  • \\SHARDREALM\Users\Public\Foxit Software\Foxit Reader\StartPage\start\en_us\Default\history_winbg.jpg -> \\SHARDREALM\Users\Public\Foxit Software\Foxit Reader\StartPage\start\en_us\Default\076E35C0--5E29--6BE8--30397F18--AA8F25200062.osiris
  • c:\Python27\include\bitset.h -> c:\Python27\include\076E35C0--5E29--6BE8--16A96608--BE696E5960EA.osiris
  • \\SHARDREALM\Users\Harry Dresden\Desktop\NZZNgxshHiXH.docm -> \\SHARDREALM\Users\Harry Dresden\Desktop\076E35C0--5E29--6BE8--E9D5837C--4E31BD1BCBEE.osiris
  • \\SHARDREALM\Users\Public\Foxit Software\Foxit Reader\StartPage\advertisement\normal View and annotate PDFs.bmp -> \\SHARDREALM\Users\Public\Foxit Software\Foxit Reader\StartPage\advertisement\076E35C0--5E29--6BE8--172F1968--3602680622B8.osiris
  • c:\Python27\include\pyarena.h -> c:\Python27\include\076E35C0--5E29--6BE8--43C3A412--95BC87D36131.osiris
  • c:\Python27\include\metagrammar.h -> c:\Python27\include\076E35C0--5E29--6BE8--F06089D1--B9015B64F8B7.osiris
  • \\SHARDREALM\Users\Public\Foxit Software\Foxit Reader\StartPage\start\en_us\Default\right_move_bg.jpg -> \\SHARDREALM\Users\Public\Foxit Software\Foxit Reader\StartPage\start\en_us\Default\076E35C0--5E29--6BE8--F8FD7765--6954A1425E84.osiris
  • c:\Python27\Lib\site-packages\pip\_vendor\requests\cacert.pem -> c:\Python27\Lib\site-packages\pip\_vendor\requests\076E35C0--5E29--6BE8--1D836000--E63C39069234.osiris
  • c:\Python27\include\node.h -> c:\Python27\include\076E35C0--5E29--6BE8--4948B0B7--0DA93B164132.osiris
  • c:\Python27\Lib\test\badcert.pem -> c:\Python27\Lib\test\076E35C0--5E29--6BE8--9ACCD888--EE522D2B82FF.osiris
  • c:\Python27\include\longobject.h -> c:\Python27\include\076E35C0--5E29--6BE8--8E2C0B2C--0BF6EB5D0460.osiris
  • c:\Python27\include\methodobject.h -> c:\Python27\include\076E35C0--5E29--6BE8--3DC3520B--9ACD7C9307D5.osiris
  • c:\6cdeacda242012e0e5b593e657\1041\eula.rtf -> c:\6cdeacda242012e0e5b593e657\1041\076E35C0--5E29--6BE8--7633DED3--106422E17388.osiris
  • \\SHARDREALM\Users\Public\Foxit Software\Foxit Reader\StartPage\start\en_us\images\buy_phantom.png -> \\SHARDREALM\Users\Public\Foxit Software\Foxit Reader\StartPage\start\en_us\images\076E35C0--5E29--6BE8--548C22E9--162DB5E2089E.osiris
  • \\SHARDREALM\Users\Public\Foxit Software\Foxit Reader\StartPage\start\en_us\Default\body_bg.jpg -> \\SHARDREALM\Users\Public\Foxit Software\Foxit Reader\StartPage\start\en_us\Default\076E35C0--5E29--6BE8--3B7004FD--D00118AA7D06.osiris
  • \\SHARDREALM\Users\Public\Pictures\Sample Pictures\Hydrangeas.jpg -> \\SHARDREALM\Users\Public\Pictures\Sample Pictures\076E35C0--5E29--6BE8--C0F4DDDB--C11D2DAAFA1E.osiris
  • \\SHARDREALM\Users\Public\Foxit Software\Foxit Reader\StartPage\advertisement\normal Protect Sensitive PDF Documents.bmp -> \\SHARDREALM\Users\Public\Foxit Software\Foxit Reader\StartPage\advertisement\076E35C0--5E29--6BE8--F01FD029--380C1D863837.osiris
  • c:\ProgramData\WebEx\WebEx\12_1324\gpc.php -> c:\ProgramData\WebEx\WebEx\12_1324\076E35C0--5E29--6BE8--F2C2CA1B--D5E31B12F8E7.osiris
  • \\SHARDREALM\Users\Public\Foxit Software\Foxit Reader\StartPage\start\en_us\images\classic-16-open.png -> \\SHARDREALM\Users\Public\Foxit Software\Foxit Reader\StartPage\start\en_us\images\076E35C0--5E29--6BE8--A7FD6701--76606114A871.osiris
  • \\SHARDREALM\Users\Harry Dresden\Desktop\ljLRyCpcWs.txt -> \\SHARDREALM\Users\Harry Dresden\Desktop\076E35C0--5E29--6BE8--8BC18A0E--F35E9D5700D8.osiris
  • \\SHARDREALM\Users\Public\Foxit Software\Foxit Reader\StartPage\advertisement\normal Protect your PDF files with AD RMS.bmp -> \\SHARDREALM\Users\Public\Foxit Software\Foxit Reader\StartPage\advertisement\076E35C0--5E29--6BE8--679C94CE--8F9836F826F0.osiris
  • c:\6cdeacda242012e0e5b593e657\1045\eula.rtf -> c:\6cdeacda242012e0e5b593e657\1045\076E35C0--5E29--6BE8--EDFEF249--A8FF50C500A4.osiris
  • \\SHARDREALM\Users\Public\Foxit Software\Foxit Reader\StartPage\advertisement\ribbon View PDFs on mobile devices.bmp -> \\SHARDREALM\Users\Public\Foxit Software\Foxit Reader\StartPage\advertisement\076E35C0--5E29--6BE8--C67F07D8--C1C50757ED89.osiris
  • \\SHARDREALM\Users\Public\Foxit Software\Foxit Reader\StartPage\start\en_us\Default\show_con_bg.jpg -> \\SHARDREALM\Users\Public\Foxit Software\Foxit Reader\StartPage\start\en_us\Default\076E35C0--5E29--6BE8--FD32DF9B--8EC7FA8A8198.osiris
  • c:\Python27\Lib\test\dh1024.pem -> c:\Python27\Lib\test\076E35C0--5E29--6BE8--C8BF8CC9--ECA5A66DBBB6.osiris
  • c:\Python27\include\pgenheaders.h -> c:\Python27\include\076E35C0--5E29--6BE8--351618CE--4F9E14FF66E7.osiris
  • \\SHARDREALM\Users\Public\Foxit Software\Foxit Reader\StartPage\start\en_us\js\nor.js -> \\SHARDREALM\Users\Public\Foxit Software\Foxit Reader\StartPage\start\en_us\js\076E35C0--5E29--6BE8--86D868D9--A54221859C1B.osiris
  • c:\Python27\include\objimpl.h -> c:\Python27\include\076E35C0--5E29--6BE8--360B24EB--1D7043826129.osiris
  • \\SHARDREALM\Users\Public\Foxit Software\Foxit Reader\StartPage\start\en_us\images\ribbon-16-open.png -> \\SHARDREALM\Users\Public\Foxit Software\Foxit Reader\StartPage\start\en_us\images\076E35C0--5E29--6BE8--83DBDF45--F2FEC2978D29.osiris
  • c:\Python27\Lib\test\keycert2.pem -> c:\Python27\Lib\test\076E35C0--5E29--6BE8--B684498B--4DE08427EA65.osiris
  • c:\Python27\Lib\test\keycert.pem -> c:\Python27\Lib\test\076E35C0--5E29--6BE8--6C09A162--04C46E070425.osiris
  • c:\Python27\include\longintrepr.h -> c:\Python27\include\076E35C0--5E29--6BE8--DCDDA6A4--33DE0113F0EA.osiris
  • c:\Python27\include\complexobject.h -> c:\Python27\include\076E35C0--5E29--6BE8--471B035C--6A7D8DD8F1DC.osiris
  • c:\Python27\include\bytearrayobject.h -> c:\Python27\include\076E35C0--5E29--6BE8--3F2EFF18--31BBC21F2692.osiris
  • \\SHARDREALM\Users\Public\Foxit Software\Foxit Reader\StartPage\start\en_us\Default\tab.png -> \\SHARDREALM\Users\Public\Foxit Software\Foxit Reader\StartPage\start\en_us\Default\076E35C0--5E29--6BE8--4C90C90F--36199C4706D7.osiris
  • c:\Python27\include\pystrcmp.h -> c:\Python27\include\076E35C0--5E29--6BE8--11EB7198--D0A54D9658B9.osiris
  • c:\Python27\include\parsetok.h -> c:\Python27\include\076E35C0--5E29--6BE8--7409A823--41C76BB46930.osiris
  • c:\Python27\include\pythread.h -> c:\Python27\include\076E35C0--5E29--6BE8--136BC325--F8F78A7F3A1D.osiris
  • c:\Python27\include\boolobject.h -> c:\Python27\include\076E35C0--5E29--6BE8--50CF6252--02AF60E2A914.osiris
  • c:\Python27\Lib\test\pycacert.pem -> c:\Python27\Lib\test\076E35C0--5E29--6BE8--2D67C50C--426EEEE1E0A2.osiris
  • c:\Python27\Lib\test\badkey.pem -> c:\Python27\Lib\test\076E35C0--5E29--6BE8--74939F1D--41D0D614C708.osiris
  • c:\Python27\include\descrobject.h -> c:\Python27\include\076E35C0--5E29--6BE8--1046941C--740011EFD72B.osiris
  • c:\6cdeacda242012e0e5b593e657\1040\eula.rtf -> c:\6cdeacda242012e0e5b593e657\1040\076E35C0--5E29--6BE8--204F54FA--7165EC3C2E40.osiris
  • \\SHARDREALM\Users\Public\Foxit Software\Foxit Reader\StartPage\start\en_us\tpl\history.txt -> \\SHARDREALM\Users\Public\Foxit Software\Foxit Reader\StartPage\start\en_us\tpl\076E35C0--5E29--6BE8--99F9D009--5426505FBD2A.osiris
  • \\SHARDREALM\Users\Public\Foxit Software\Foxit Reader\StartPage\advertisement\normal Design form fields easily.bmp -> \\SHARDREALM\Users\Public\Foxit Software\Foxit Reader\StartPage\advertisement\076E35C0--5E29--6BE8--372FAEAC--31B2D1E06E62.osiris
  • c:\6cdeacda242012e0e5b593e657\2052\eula.rtf -> c:\6cdeacda242012e0e5b593e657\2052\076E35C0--5E29--6BE8--3F40A127--94046850BBA7.osiris
  • c:\Python27\include\osdefs.h -> c:\Python27\include\076E35C0--5E29--6BE8--02DAA69E--BF321C23A6B7.osiris
  • c:\Python27\include\compile.h -> c:\Python27\include\076E35C0--5E29--6BE8--181B46E0--519D70977123.osiris
  • \\SHARDREALM\Users\Public\Pictures\Sample Pictures\Lighthouse.jpg -> \\SHARDREALM\Users\Public\Pictures\Sample Pictures\076E35C0--5E29--6BE8--A432D6C1--7F08EAA40FB1.osiris
  • c:\Python27\Lib\test\keycert4.pem -> c:\Python27\Lib\test\076E35C0--5E29--6BE8--A6245F9B--43596877162B.osiris
  • \\SHARDREALM\Users\Public\Foxit Software\Foxit Reader\StartPage\advertisement\ribbon Enterprise PDF Reader.bmp -> \\SHARDREALM\Users\Public\Foxit Software\Foxit Reader\StartPage\advertisement\076E35C0--5E29--6BE8--E5533576--DF23D498FDEA.osiris
  • \\SHARDREALM\Users\Public\Foxit Software\Foxit Reader\StartPage\advertisement\ribbon create pdf from scanner documents.bmp -> \\SHARDREALM\Users\Public\Foxit Software\Foxit Reader\StartPage\advertisement\076E35C0--5E29--6BE8--98185A0C--DE13E47C9216.osiris
  • \\SHARDREALM\Users\Public\Foxit Software\Foxit Reader\StartPage\advertisement\normal create pdf from scanner documents.bmp -> \\SHARDREALM\Users\Public\Foxit Software\Foxit Reader\StartPage\advertisement\076E35C0--5E29--6BE8--50D3FFB2--C7F585495B69.osiris
  • c:\Python27\include\Python.h -> c:\Python27\include\076E35C0--5E29--6BE8--B153E938--0E3BCDA956B5.osiris
  • \\SHARDREALM\Users\Public\Foxit Software\Foxit Reader\StartPage\advertisement\ribbon Protect Sensitive PDF Documents.bmp -> \\SHARDREALM\Users\Public\Foxit Software\Foxit Reader\StartPage\advertisement\076E35C0--5E29--6BE8--E172368D--1DBA27365BC9.osiris
  • \\SHARDREALM\Users\Public\Foxit Software\Foxit Reader\StartPage\advertisement\normal Fastest PDF Search and Index.bmp -> \\SHARDREALM\Users\Public\Foxit Software\Foxit Reader\StartPage\advertisement\076E35C0--5E29--6BE8--751C696C--F422738F0D99.osiris
  • c:\Python27\include\patchlevel.h -> c:\Python27\include\076E35C0--5E29--6BE8--B8E7ED32--95C9026AF0D6.osiris
  • c:\Python27\include\pyfpe.h -> c:\Python27\include\076E35C0--5E29--6BE8--EFB28267--454DFFF93745.osiris
  • c:\Python27\include\bufferobject.h -> c:\Python27\include\076E35C0--5E29--6BE8--CC245A2C--19ADCB9C5C65.osiris
  • \\SHARDREALM\Users\Public\Foxit Software\Foxit Reader\StartPage\advertisement\ribbon Create PDF from Office-convert PDF to office.bmp -> \\SHARDREALM\Users\Public\Foxit Software\Foxit Reader\StartPage\advertisement\076E35C0--5E29--6BE8--DDDBCBE7--4206EC320B81.osiris
  • c:\Python27\include\moduleobject.h -> c:\Python27\include\076E35C0--5E29--6BE8--94750715--3D2F33419409.osiris
  • c:\6cdeacda242012e0e5b593e657\1036\eula.rtf -> c:\6cdeacda242012e0e5b593e657\1036\076E35C0--5E29--6BE8--B098603A--2E967A519D02.osiris
  • c:\Python27\include\pymath.h -> c:\Python27\include\076E35C0--5E29--6BE8--D6697FEA--F352676A30A6.osiris
  • c:\Python27\include\asdl.h -> c:\Python27\include\076E35C0--5E29--6BE8--BE3948A3--54BEB4B99C94.osiris
  • c:\Python27\Lib\test\nullbytecert.pem -> c:\Python27\Lib\test\076E35C0--5E29--6BE8--9603BEEA--4141A9571C4B.osiris
  • c:\Python27\include\cStringIO.h -> c:\Python27\include\076E35C0--5E29--6BE8--23292F4B--C6EBB010703B.osiris
  • c:\Python27\include\object.h -> c:\Python27\include\076E35C0--5E29--6BE8--38595078--F4658C495915.osiris
  • \\SHARDREALM\Users\Public\Foxit Software\Foxit Reader\StartPage\advertisement\ribbon Protect your PDF files with AD RMS.bmp -> \\SHARDREALM\Users\Public\Foxit Software\Foxit Reader\StartPage\advertisement\076E35C0--5E29--6BE8--21C9B0C7--9BE31DEAD767.osiris
  • c:\6cdeacda242012e0e5b593e657\1025\eula.rtf -> c:\6cdeacda242012e0e5b593e657\1025\076E35C0--5E29--6BE8--30A6AB30--5D8AAE287323.osiris
  • c:\Python27\Lib\test\sha256.pem -> c:\Python27\Lib\test\076E35C0--5E29--6BE8--C4D94F3C--FF224327B07B.osiris
  • \\SHARDREALM\Users\Public\Foxit Software\Foxit Reader\StartPage\advertisement\Profile.xml -> \\SHARDREALM\Users\Public\Foxit Software\Foxit Reader\StartPage\advertisement\076E35C0--5E29--6BE8--05903C18--9CBB008FA4DB.osiris
  • c:\Python27\Lib\test\wrongcert.pem -> c:\Python27\Lib\test\076E35C0--5E29--6BE8--FE02B529--9F6D7E1F66C4.osiris
  • \\SHARDREALM\Users\Public\Foxit Software\Foxit Reader\StartPage\advertisement\normal Edit and reflow paragraphs in PDF files.bmp -> \\SHARDREALM\Users\Public\Foxit Software\Foxit Reader\StartPage\advertisement\076E35C0--5E29--6BE8--4265CCA1--019E17D2DACC.osiris
  • \\SHARDREALM\Users\Public\Foxit Software\Foxit Reader\StartPage\advertisement\ribbon View and annotate PDFs.bmp -> \\SHARDREALM\Users\Public\Foxit Software\Foxit Reader\StartPage\advertisement\076E35C0--5E29--6BE8--2D4FDA34--DC644918F76C.osiris
  • \\SHARDREALM\Users\Public\Foxit Software\Foxit Reader\StartPage\advertisement\ribbon Fastest PDF Search and Index.bmp -> \\SHARDREALM\Users\Public\Foxit Software\Foxit Reader\StartPage\advertisement\076E35C0--5E29--6BE8--F7D55203--FB1632CECED2.osiris
  • c:\6cdeacda242012e0e5b593e657\1053\eula.rtf -> c:\6cdeacda242012e0e5b593e657\1053\076E35C0--5E29--6BE8--471C9857--4CC55572AA36.osiris
  • c:\6cdeacda242012e0e5b593e657\1038\eula.rtf -> c:\6cdeacda242012e0e5b593e657\1038\076E35C0--5E29--6BE8--193A0AAB--2ED532808D6B.osiris
  • c:\Python27\include\memoryobject.h -> c:\Python27\include\076E35C0--5E29--6BE8--49BD282B--57D5614DD114.osiris
  • c:\6cdeacda242012e0e5b593e657\3082\eula.rtf -> c:\6cdeacda242012e0e5b593e657\3082\076E35C0--5E29--6BE8--F1795E3A--351026E6947A.osiris
  • c:\Python27\tcl\tix8.4.3\pref\Blue.cs -> c:\Python27\tcl\tix8.4.3\pref\076E35C0--5E29--6BE8--752836CD--81D11065B34F.osiris
  • c:\Python27\include\pystate.h -> c:\Python27\include\076E35C0--5E29--6BE8--E474743E--6F05BF2E8999.osiris
  • c:\ypliys\bin\cert.p12 -> c:\ypliys\bin\076E35C0--5E29--6BE8--74B8C39F--D7D7C30209F3.osiris
  • c:\Python27\Lib\test\https_svn_python_org_root.pem -> c:\Python27\Lib\test\076E35C0--5E29--6BE8--C513E701--ED0CEEEE88AA.osiris
  • c:\Python27\include\pycapsule.h -> c:\Python27\include\076E35C0--5E29--6BE8--DC33005D--C411141D181C.osiris
Network-Connects Host
  • weihutech.cn
  • 51.254.141.213
  • 178.159.42.248
Directory-Created
  • C:\Users\Harry Dresden\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\YLC2QM2Y
  • C:\Users\Harry Dresden\AppData\Local\Microsoft\Windows\Caches
Directory-Enumerated
  • c:\Python27\Lib\site-packages\pip\*
  • c:\Python27\tcl\tcl8\8.5\*
  • c:\ProgramData\Sun\*
  • c:\ProgramData\Microsoft\ClickToRun\MachineData\Catalog\Packages\*
  • c:\Python27\tcl\tk8.5\demos\images\*
  • c:\Users\ruiner\*
  • c:\Recovery\015e7760-d44b-11e0-8947-954f09601788\*
  • c:\PerfLogs\*
  • c:\ProgramData\Microsoft\OfficeSoftwareProtectionPlatform\*
  • c:\ProgramData\Passmark\*
  • c:\ProgramData\Microsoft\Device Stage\Task\{e35be42d-f742-4d96-a50a-1775fb1a7a42}\*
  • c:\Python27\Tools\pynche\X\*
  • c:\Users\Public\Music\Sample Music\*
  • c:\Python27\Lib\importlib\*
  • c:\Python27\tcl\tcl8.5\http1.0\*
  • c:\Python27\Lib\bsddb\*
  • \\SHARDREALM\Users\Harry Dresden\Pictures\*
  • c:\ProgramData\Microsoft\Windows Defender\Scans\CleanStore\ResourceData\17\*
  • c:\inetpub\wwwroot\aspnet_client\*
  • c:\ProgramData\Microsoft\Windows Defender\Scans\CleanStore\Resources\43\*
  • c:\ProgramData\Microsoft\Windows NT\MSFax\ActivityLog\*
  • c:\Python27\Lib\site-packages\pip\_vendor\pkg_resources\tests\*
  • c:\Python27\tcl\tk8.5\ttk\*
  • c:\ProgramData\Microsoft\ClickToRun\MachineData\Catalog\Packages\{9AC08E99-230B-47E8-9721-4577B7F124EA}\{1A8308C7-90D1-4200-B16E-646F163A08E8}\*
  • c:\Users\Default\Saved Games\*
  • c:\Python27\tcl\tcl8.5\tzdata\Africa\*
  • c:\ProgramData\Microsoft\Windows NT\MSFax\Common Coverpages\en-US\*
  • c:\Python27\Tools\i18n\*
  • c:\ProgramData\Microsoft\ClickToRun\*
  • c:\Python27\Lib\site-packages\pip\_vendor\lockfile\*
  • c:\ProgramData\*
  • c:\ypliys\modules\auxiliary\*
  • c:\6cdeacda242012e0e5b593e657\Graphics\*
  • c:\Python27\Lib\site-packages\pip\_vendor\html5lib\treebuilders\*
  • c:\Python27\Lib\compiler\*
  • c:\ProgramData\Microsoft\Windows NT\MSFax\*
  • c:\Users\Public\Foxit Software\Foxit Reader\StartPage\start\en_us\js\*
  • c:\Python27\Lib\unittest\*
  • c:\ProgramData\Microsoft\Windows Defender\Scans\CleanStore\ResourceData\35\*
  • c:\Python27\Lib\test\capath\*
  • c:\Users\Harry Dresden\OneDrive\*
  • \\SHARDREALM\Users\Public\Foxit Software\Foxit Reader\StartPage\start\en_us\tpl\*
  • c:\ProgramData\Adobe\Acrobat\11.0\*
  • c:\ProgramData\Microsoft\Diagnosis\DownloadedSettings\*
  • c:\ProgramData\Microsoft\ClickToRun\MachineData\Catalog\*
  • c:\ProgramData\Microsoft\Windows Defender\Scans\*
  • c:\ypliys\lib\core\*
  • c:\Python27\tcl\tcl8.5\*
  • c:\Python27\Lib\unittest\test\*
  • c:\inetpub\wwwroot\aspnet_client\system_web\4_0_30319\*
  • c:\Users\Public\Videos\Sample Videos\*
  • c:\ProgramData\Microsoft\Network\Connections\*
  • c:\Users\Public\Recorded TV\*
  • c:\Users\Harry Dresden\Contacts\*
  • c:\ProgramData\Microsoft\Windows Defender\Scans\CleanStore\ResourceData\42\*
  • c:\Python27\tcl\tk8.5\msgs\*
  • c:\ProgramData\Microsoft\Device Stage\Task\{e35be42d-f742-4d96-a50a-1775fb1a7a42}\en-US\*
  • c:\Python27\tcl\tcl8.5\tzdata\Atlantic\*
  • c:\Python27\tcl\tcl8.5\tzdata\Europe\*
  • c:\ProgramData\WebEx\WebEx\*
  • c:\Python27\tcl\tk8.5\demos\*
  • c:\ProgramData\Microsoft\Windows Defender\*
  • c:\ProgramData\Microsoft\PlayReady\Cache\*
  • c:\Python27\Lib\site-packages\pip\_vendor\distlib\_backport\*
  • c:\ProgramData\Microsoft\Windows Defender\Scans\CleanStore\ResourceData\01\*
  • c:\inetpub\history\CFGHISTORY_0000000005\*
  • c:\Python27\tcl\tix8.4.3\demos\samples\*
  • c:\ProgramData\Microsoft\Windows NT\MSFax\SentItems\*
  • c:\Python27\Lib\site-packages\pip\_vendor\html5lib\treewalkers\*
  • \\SHARDREALM\Users\Harry Dresden\Favorites\*
  • c:\ProgramData\Microsoft\PlayReady\Cache\S-1-5-21-3416602863-1947377224-293699093-1001\*
  • c:\6cdeacda242012e0e5b593e657\1037\*
  • c:\Python27\Lib\pydoc_data\*
  • c:\Users\Default\Pictures\*
  • \\SHARDREALM\Users\Default\Links\*
  • c:\ProgramData\Microsoft\ClickToRun\MachineData\Integration\*
  • \\SHARDREALM\Users\Public\Music\*
  • c:\Python27\Lib\site-packages\pip\_vendor\html5lib\serializer\*
  • c:\ProgramData\Microsoft\Windows Defender\Scans\CleanStore\ResourceData\95\*
  • c:\inetpub\custerr\*
  • c:\6cdeacda242012e0e5b593e657\1033\*
  • c:\ProgramData\Microsoft\Windows Defender\Scans\CleanStore\ResourceData\47\*
  • c:\Python27\Lib\site-packages\pip\_vendor\requests\packages\urllib3\packages\*
  • c:\ProgramData\Microsoft\Windows Defender\Definition Updates\Backup\*
  • \\SHARDREALM\Users\Harry Dresden\Links\*
  • c:\Python27\Scripts\*
  • c:\Users\Public\Desktop\*
  • \\SHARDREALM\Users\Harry Dresden\Videos\*
  • c:\ProgramData\Microsoft\Network\Downloader\*
  • c:\ProgramData\Microsoft\Vault\AC658CB4-9126-49BD-B877-31EEDAB3F204\*
  • c:\Python27\Tools\pynche\*
  • c:\Python27\Lib\email\test\*
  • c:\ProgramData\Mozilla\logs\*
  • c:\ProgramData\Microsoft\IdentityCRL\*
  • c:\ProgramData\Microsoft\WPD\*
  • c:\ProgramData\Microsoft\Diagnosis\LocalTraceStore\*
  • c:\ProgramData\Microsoft\Event Viewer\*
  • c:\Users\Harry Dresden\Favorites\Links for United States\*
  • c:\Users\Default\*
  • c:\ProgramData\Sun\Java\Java Update\*
  • c:\ProgramData\Microsoft\Windows Defender\Scans\CleanStore\Resources\17\*
  • c:\ProgramData\Microsoft\Windows Defender\Scans\CleanStore\ResourceData\43\*
  • c:\Python27\tcl\dde1.3\*
  • c:\Python27\Lib\ensurepip\_bundled\*
  • c:\ProgramData\Microsoft\Windows Defender\Scans\CleanStore\Resources\95\*
  • c:\PerfLogs\Admin\*
  • c:\Python27\Lib\site-packages\pip\_vendor\html5lib\treeadapters\*
  • c:\Python27\Lib\idlelib\*
  • c:\Python27\Lib\site-packages\pip\models\*
  • c:\inetpub\*
  • \\SHARDREALM\Users\Harry Dresden\Music\*
  • c:\Users\Harry Dresden\Saved Games\*
  • c:\inetpub\wwwroot\msmq\*
  • c:\ProgramData\Microsoft\DRM\*
  • c:\ProgramData\Microsoft\Crypto\RSA\*
  • c:\6cdeacda242012e0e5b593e657\1025\*
  • c:\Python27\Lib\test\crashers\*
  • c:\ProgramData\Microsoft\Search\Data\Applications\*
  • c:\Python27\Lib\ctypes\test\*
  • c:\Users\Public\Libraries\*
  • c:\ProgramData\Microsoft\Device Stage\*
  • \\SHARDREALM\Users\Harry Dresden\Searches\*
  • c:\ProgramData\Microsoft\Windows NT\*
  • c:\ProgramData\Microsoft\Windows Defender\Scans\CleanStore\Resources\01\*
  • c:\Python27\Lib\site-packages\setuptools-16.0.dist-info\*
  • \\SHARDREALM\Users\Public\Foxit Software\Foxit Reader\*
  • \\SHARDREALM\Users\Public\Videos\Sample Videos\*
  • c:\Python27\Lib\xml\etree\*
  • c:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\*
  • c:\ProgramData\Microsoft\Windows Defender\Scans\CleanStore\Resources\F3\*
  • c:\Python27\Lib\test\*
  • c:\ProgramData\Adobe\Acrobat\11.0\Replicate\Security\*
  • \\SHARDREALM\Users\Public\Libraries\*
  • c:\Python27\Lib\ctypes\macholib\*
  • c:\Python27\Lib\msilib\*
  • c:\Python27\Lib\site-packages\pip\_vendor\distlib\*
  • \\SHARDREALM\Users\Harry Dresden\Desktop\*
  • c:\6cdeacda242012e0e5b593e657\1035\*
  • c:\ProgramData\Microsoft\Windows Defender\Scans\CleanStore\ResourceData\DD\*
  • \\SHARDREALM\Users\Harry Dresden\Contacts\*
  • c:\ProgramData\Adobe\ARM\S\*
  • c:\ProgramData\Microsoft\Windows Defender\Scans\CleanStore\ResourceData\70\*
  • c:\ProgramData\Microsoft\Windows Defender\Scans\History\*
  • c:\Users\Default\Videos\*
  • c:\ProgramData\McAfee\MCLOGS\Common\*
  • \\SHARDREALM\Users\Public\Foxit Software\Foxit Reader\StartPage\start\en_us\js\*
  • c:\Users\Default\Documents\*
  • c:\6cdeacda242012e0e5b593e657\1031\*
  • c:\Python27\tcl\tcl8.5\tzdata\Pacific\*
  • \\SHARDREALM\Users\*
  • c:\Python27\tcl\tcl8.5\tzdata\America\North_Dakota\*
  • c:\ProgramData\Microsoft\ClickToRun\MachineData\Catalog\Packages\{9AC08E99-230B-47E8-9721-4577B7F124EA}\*
  • c:\Python27\tcl\tcl8.5\tzdata\Etc\*
  • c:\ProgramData\Microsoft\Windows Defender\Scans\CleanStore\Resources\DD\*
  • c:\ProgramData\Adobe\*
  • c:\ProgramData\Microsoft\Windows Defender\Scans\CleanStore\Resources\*
  • c:\inetpub\history\CFGHISTORY_0000000001\*
  • c:\Python27\Lib\site-packages\pip\_vendor\requests\packages\chardet\*
  • \\SHARDREALM\Users\Default\Music\*
  • c:\ProgramData\Microsoft\Windows Defender\Scans\CleanStore\ResourceData\A6\*
  • c:\Python27\Lib\site-packages\pip\_vendor\pkg_resources\*
  • \\SHARDREALM\Users\Public\Foxit Software\Foxit Reader\StartPage\start\en_us\*
  • \\SHARDREALM\Users\Default\Favorites\*
  • c:\Python27\Tools\webchecker\*
  • c:\ProgramData\Microsoft\Device Stage\Device\{8702d817-5aad-4674-9ef3-4d3decd87120}\*
  • c:\ProgramData\Microsoft\Windows Defender\Scans\CleanStore\Resources\A5\*
  • c:\ProgramData\Adobe\Acrobat\11.0\Replicate\*
  • c:\ProgramData\Microsoft\Windows Defender\Scans\History\CacheManager\*
  • c:\ProgramData\NovaTech Network\NovaBench\*
  • \\SHARDREALM\Users\Public\Music\Sample Music\*
  • c:\Users\Harry Dresden\Favorites\Links\*
  • c:\ProgramData\Microsoft\Assistance\*
  • c:\ProgramData\Microsoft\Assistance\Client\1.0\en-US\*
  • c:\inetpub\wwwroot\*
  • c:\Users\Harry Dresden\*
  • c:\Python27\tcl\tcl8.5\tzdata\Antarctica\*
  • c:\Python27\Lib\site-packages\pip\_vendor\*
  • c:\ProgramData\Microsoft\Windows NT\MSFax\VirtualInbox\en-US\*
  • c:\ProgramData\Microsoft\Windows Defender\Scans\CleanStore\ResourceData\E0\*
  • c:\ypliys\lib\*
  • c:\ProgramData\Adobe\ARM\S\5521\*
  • \\SHARDREALM\Users\Public\Foxit Software\*
  • c:\Users\Public\Downloads\*
  • c:\6cdeacda242012e0e5b593e657\2070\*
  • c:\ProgramData\Microsoft\ClickToRun\ProductReleases\9E1D94D2-471F-4DC3-9EBD-E31E1E099E00\x-none.16\*
  • c:\Python27\Lib\test\cjkencodings\*
  • c:\ProgramData\Microsoft\Assistance\Client\1.0\*
  • c:\ProgramData\Microsoft\Windows Defender\Support\*
  • c:\Python27\Lib\site-packages\pip\operations\*
  • \\SHARDREALM\Users\Harry Dresden\*
  • c:\ProgramData\Microsoft\MF\*
  • c:\6cdeacda242012e0e5b593e657\1029\*
  • c:\ProgramData\Microsoft\ClickToRun\MachineData\Integration\ShortcutBackups\*
  • c:\ProgramData\Microsoft\Windows Defender\Scans\CleanStore\Resources\1A\*
  • c:\Python27\Lib\distutils\tests\*
  • c:\ProgramData\Microsoft\Office\*
  • c:\Users\Public\Music\*
  • c:\ProgramData\Microsoft\ClickToRun\MachineData\*
  • c:\6cdeacda242012e0e5b593e657\1045\*
  • c:\Users\Public\Foxit Software\Foxit Reader\StartPage\start\en_us\css\*
  • c:\Users\Harry Dresden\Desktop\*
  • c:\ProgramData\Microsoft\Windows Defender\Scans\History\Results\Resource\*
  • c:\ProgramData\Microsoft\Crypto\*
  • \\SHARDREALM\Users\Public\Recorded TV\Sample Media\*
  • c:\Users\Public\Pictures\*
  • c:\ProgramData\Microsoft\Windows Defender\Scans\CleanStore\Resources\42\*
  • c:\ProgramData\Microsoft\Windows Defender\Definition Updates\Updates\*
  • c:\Python27\include\*
  • c:\Python27\Lib\lib2to3\tests\data\fixers\*
  • c:\Python27\Lib\encodings\*
  • c:\Python27\Lib\site-packages\setuptools\*
  • c:\Python27\Lib\test\tracedmodules\*
  • c:\ProgramData\Microsoft\DRM\Server\*
  • c:\ProgramData\Microsoft\Device Stage\Task\{07deb856-fc6e-4fb9-8add-d8f2cf8722c9}\en-US\*
  • c:\ypliys\bin\*
  • c:\Python27\tcl\tcl8.5\tzdata\SystemV\*
  • c:\6cdeacda242012e0e5b593e657\1049\*
  • c:\Users\Public\Foxit Software\Foxit Reader\StartPage\start\*
  • c:\Users\Harry Dresden\Music\*
  • c:\Users\Public\Foxit Software\Foxit Reader\StartPage\start\en_us\*
  • c:\Python27\tcl\tcl8.5\tzdata\Mexico\*
  • c:\ProgramData\Microsoft\RAC\*
  • c:\Python27\Lib\site-packages\pip\_vendor\html5lib\*
  • c:\ProgramData\Microsoft\WwanSvc\*
  • c:\Python27\tcl\tcl8.5\tzdata\Arctic\*
  • c:\ProgramData\Oracle\*
  • c:\ProgramData\NovaTech Network\NovaBench\3.0.2.0\media\*
  • c:\ProgramData\Microsoft\Windows Defender\Quarantine\*
  • \\SHARDREALM\Users\Default\Pictures\*
  • c:\ProgramData\Microsoft\Windows NT\MSFax\Queue\*
  • c:\ProgramData\Microsoft\RAC\Outbound\*
  • c:\ProgramData\WebEx\*
  • c:\inetpub\history\CFGHISTORY_0000000003\*
  • c:\Python27\Lib\site-packages\setuptools\command\*
  • c:\Python27\tcl\tcl8.5\tzdata\Indian\*
  • c:\ProgramData\Microsoft\Event Viewer\Views\*
  • c:\Users\Default\Favorites\*
  • c:\*
  • c:\Users\Default\Desktop\*
  • \\SHARDREALM\Users\Default\Desktop\*
  • c:\ProgramData\Microsoft\eHome\logs\*
  • c:\ProgramData\Microsoft\Network\*
  • c:\Python27\tcl\tcl8.5\tzdata\America\Kentucky\*
  • \\SHARDREALM\Users\Harry Dresden\Favorites\Links\*
  • c:\Python27\Lib\lib-tk\test\test_ttk\*
  • c:\Python27\tcl\tcl8.5\tzdata\US\*
  • c:\ProgramData\Microsoft\ClickToRun\UserData\*
  • c:\ypliys\lib\api\*
  • c:\ProgramData\Microsoft\ClickToRun\ProductReleases\9E1D94D2-471F-4DC3-9EBD-E31E1E099E00\*
  • c:\Users\Public\Pictures\Sample Pictures\*
  • c:\Python27\tcl\tcl8.5\msgs\*
  • c:\6cdeacda242012e0e5b593e657\1041\*
  • c:\Users\Default\Downloads\*
  • c:\Python27\Lib\site-packages\pip\_vendor\requests\packages\urllib3\packages\ssl_match_hostname\*
  • c:\Users\Harry Dresden\Links\*
  • \\SHARDREALM\Users\Harry Dresden\Favorites\Links for United States\*
  • c:\Python27\DLLs\*
  • \\SHARDREALM\Users\Default\Documents\*
  • c:\ProgramData\Microsoft\User Account Pictures\*
  • c:\Python27\Lib\site-packages\pip\_vendor\requests\packages\urllib3\contrib\*
  • c:\Python27\tcl\tcl8.5\tzdata\Asia\*
  • c:\Users\Harry Dresden\Downloads\*
  • c:\Python27\tcl\tcl8.5\opt0.4\*
  • c:\ProgramData\Mozilla\*
  • c:\Users\Public\Videos\*
  • c:\Python27\tcl\tcl8\8.4\*
  • c:\6cdeacda242012e0e5b593e657\1055\*
  • c:\ProgramData\Microsoft\Windows Defender\Scans\CleanStore\Resources\70\*
  • c:\ProgramData\Microsoft\Windows Defender\Scans\History\Store\*
  • c:\Python27\Tools\versioncheck\*
  • c:\Python27\tcl\reg1.2\*
  • c:\ProgramData\Microsoft\Windows Defender\Scans\CleanStore\Resources\F7\*
  • c:\Python27\Lib\xml\dom\*
  • c:\Python27\Lib\lib2to3\tests\data\*
  • c:\ProgramData\Microsoft\Windows Defender\Scans\History\Service\*
  • \\SHARDREALM\Users\Public\Foxit Software\Foxit Reader\StartPage\advertisement\*
  • c:\Python27\tcl\tcl8.5\encoding\*
  • c:\ProgramData\McAfee\*
  • c:\ProgramData\Microsoft\Diagnosis\AsimovUploader\*
  • c:\ProgramData\Microsoft\Diagnosis\ETLLogs\ShutdownLogger\*
  • c:\ProgramData\Microsoft\User Account Pictures\Default Pictures\*
  • c:\Users\Public\Foxit Software\Foxit Reader\StartPage\start\en_us\images\*
  • c:\ProgramData\Microsoft\Windows Defender\Scans\CleanStore\Resources\47\*
  • c:\ProgramData\Microsoft\Windows Defender\Scans\History\Results\*
  • \\SHARDREALM\Users\Public\Documents\*
  • c:\Python27\Lib\xml\parsers\*
  • c:\ProgramData\Microsoft\Windows Defender\Scans\CleanStore\*
  • c:\6cdeacda242012e0e5b593e657\1038\*
  • c:\Python27\tcl\tix8.4.3\*
  • c:\Python27\Lib\site-packages\pip\_vendor\html5lib\trie\*
  • c:\Python27\tcl\tcl8.5\tzdata\Canada\*
  • c:\ProgramData\NovaTech Network\*
  • \\SHARDREALM\Users\Public\Foxit Software\Foxit Reader\StartPage\start\*
  • c:\Python27\tcl\tcl8\*
  • c:\6cdeacda242012e0e5b593e657\1053\*
  • c:\Users\Default\Music\*
  • c:\Python27\Lib\test\decimaltestdata\*
  • c:\Python27\Lib\test\xmltestdata\*
  • \\SHARDREALM\Users\Public\Desktop\*
  • c:\ProgramData\Passmark\PerformanceTest\*
  • c:\ProgramData\Microsoft\Windows Defender\Scans\CleanStore\ResourceData\*
  • c:\ProgramData\Microsoft\ClickToRun\ProductReleases\*
  • \\SHARDREALM\Users\Harry Dresden\OneDrive\*
  • c:\ProgramData\Adobe\ARM\*
  • c:\ProgramData\Microsoft\Diagnosis\ETLLogs\*
  • \\SHARDREALM\Users\Harry Dresden\Documents\*
  • c:\6cdeacda242012e0e5b593e657\2052\*
  • c:\Python27\Lib\logging\*
  • c:\ProgramData\Microsoft\eHome\*
  • c:\Users\Public\*
  • c:\6cdeacda242012e0e5b593e657\1043\*
  • c:\Python27\Lib\site-packages\*
  • c:\ProgramData\Microsoft\NetFramework\BreadcrumbStore\*
  • c:\ProgramData\Microsoft\Diagnosis\UIF\*
  • c:\Users\Harry Dresden\Searches\*
  • c:\Users\Public\Foxit Software\Foxit Reader\StartPage\advertisement\*
  • c:\Python27\tcl\tk8.5\*
  • \\SHARDREALM\Users\Public\*
  • c:\ypliys\*
  • c:\Python27\Lib\xml\sax\*
  • c:\ProgramData\Microsoft\Device Stage\Device\*
  • c:\ProgramData\Microsoft\Vault\*
  • c:\Users\Default\Links\*
  • c:\Python27\Lib\json\tests\*
  • c:\Python27\libs\*
  • c:\6cdeacda242012e0e5b593e657\1028\*
  • c:\Python27\Lib\lib-tk\test\test_tkinter\*
  • c:\ProgramData\Microsoft OneDrive\*
  • c:\ProgramData\Microsoft\Crypto\DSS\MachineKeys\*
  • c:\Python27\Lib\ctypes\*
  • c:\Users\Public\Recorded TV\Sample Media\*
  • \\SHARDREALM\Users\Harry Dresden\Downloads\*
  • c:\Python27\*
  • c:\ProgramData\Microsoft\Crypto\DSS\*
  • c:\ProgramData\Microsoft\Diagnosis\Sideload\*
  • c:\Python27\Lib\email\*
  • c:\ProgramData\Microsoft\Search\Data\*
  • c:\Users\Harry Dresden\Documents\*
  • c:\ProgramData\Adobe\Setup\*
  • c:\Python27\Lib\distutils\*
  • c:\ProgramData\Microsoft\Windows NT\MSFax\Common Coverpages\*
  • c:\ProgramData\Microsoft\Device Stage\Task\*
  • c:\Users\*
  • \\SHARDREALM\Users\Public\Favorites\*
  • c:\ProgramData\Adobe\Setup\{AC76BA86-7AD7-1033-7B44-AB0000000001}\*
  • c:\Users\Public\Foxit Software\Foxit Reader\StartPage\start\en_us\tpl\*
  • c:\Python27\Lib\sqlite3\*
  • c:\ProgramData\Sun\Java\*
  • c:\ProgramData\Microsoft\NetFramework\*
  • c:\ProgramData\Microsoft\Crypto\Keys\*
  • c:\Python27\Lib\site-packages\pip\_vendor\cachecontrol\*
  • c:\Python27\Lib\bsddb\test\*
  • c:\ProgramData\Microsoft\Windows Defender\Definition Updates\{98101498-C465-4F51-8751-D1919E97D29D}\*
  • c:\ProgramData\NovaTech Network\NovaBench\3.0.2.0\*
  • \\SHARDREALM\Users\ruiner\*
  • c:\Recovery\*
  • c:\Users\Public\Foxit Software\*
  • c:\ProgramData\Microsoft\Windows Defender\Scans\CleanStore\Resources\A6\*
  • c:\inetpub\history\CFGHISTORY_0000000002\*
  • c:\Python27\Lib\site-packages\pip\req\*
  • c:\Users\Harry Dresden\Videos\*
  • \\SHARDREALM\Users\Default\Downloads\*
  • c:\inetpub\wwwroot\aspnet_client\system_web\*
  • c:\Python27\tcl\tcl8.5\tzdata\Australia\*
  • c:\Users\Harry Dresden\Pictures\*
  • c:\ProgramData\Microsoft\DeviceSync\*
  • c:\ProgramData\WebEx\WebEx\12_1324\*
  • c:\ProgramData\Microsoft\Office\Heartbeat\*
  • c:\Python27\Lib\lib2to3\tests\data\fixers\myfixes\*
  • c:\Python27\Tools\Scripts\*
  • c:\Python27\Lib\hotshot\*
  • \\SHARDREALM\Users\Public\Videos\*
  • c:\ProgramData\Microsoft\*
  • c:\ProgramData\Microsoft\PlayReady\*
  • c:\Python27\Lib\site-packages\pip\utils\*
  • c:\ProgramData\Microsoft\Windows Defender\Scans\CleanStore\Entries\*
  • c:\Users\Public\Foxit Software\Foxit Reader\StartPage\*
  • c:\Python27\tcl\tcl8.5\tzdata\Brazil\*
  • \\SHARDREALM\Users\Public\Foxit Software\Foxit Reader\StartPage\*
  • c:\Python27\Lib\site-packages\pkg_resources\_vendor\packaging\*
  • c:\Python27\Lib\lib2to3\*
  • c:\Python27\tcl\tcl8.5\tzdata\America\Argentina\*
  • c:\ProgramData\Microsoft\Windows Defender\Scans\CleanStore\Resources\E0\*
  • c:\ProgramData\Microsoft\WwanSvc\Profiles\*
  • c:\ProgramData\Microsoft\Windows NT\MSFax\VirtualInbox\*
  • c:\Python27\Lib\test\subprocessdata\*
  • c:\ProgramData\Microsoft\Windows Defender\Scans\History\Results\Quick\*
  • c:\Python27\Lib\site-packages\pip-7.0.1.dist-info\*
  • c:\Python27\Lib\site-packages\pip\_vendor\progress\*
  • c:\Users\Public\Foxit Software\Foxit Reader\*
  • c:\ProgramData\Microsoft\Event Viewer\Views\ApplicationViewsRootNode\*
  • c:\ProgramData\Microsoft\Windows NT\MSFax\Inbox\*
  • c:\Python27\Lib\xml\*
  • c:\ProgramData\Microsoft\Search\*
  • c:\ProgramData\Microsoft\IlsCache\*
  • c:\Python27\tcl\tk8.5\images\*
  • e:\*
  • c:\Python27\Lib\sqlite3\test\*
  • c:\ProgramData\McAfee\MCLOGS\*
  • c:\Python27\Lib\ensurepip\*
  • c:\Python27\Lib\idlelib\Icons\*
  • \\SHARDREALM\Users\Public\Foxit Software\Foxit Reader\StartPage\start\en_us\Default\*
  • c:\Python27\Lib\test\imghdrdata\*
  • c:\ProgramData\Microsoft\ClickToRun\ProductReleases\9E1D94D2-471F-4DC3-9EBD-E31E1E099E00\en-us.16\*
  • c:\ProgramData\Microsoft\Diagnosis\*
  • c:\6cdeacda242012e0e5b593e657\*
  • \\SHARDREALM\Users\Default\Saved Games\*
  • c:\Python27\tcl\tcl8.5\tzdata\America\*
  • c:\Python27\Lib\site-packages\pkg_resources\_vendor\*
  • c:\6cdeacda242012e0e5b593e657\1030\*
  • \\SHARDREALM\Users\Default\Videos\*
  • c:\ProgramData\Microsoft\Device Stage\Device\{113527a4-45d4-4b6f-b567-97838f1b04b0}\*
  • \\SHARDREALM\Users\Public\Downloads\*
  • c:\ProgramData\Microsoft\RAC\PublishedData\*
  • c:\Python27\Lib\site-packages\pip\_vendor\requests\packages\*
  • c:\ypliys\lib\common\*
  • c:\Python27\Lib\multiprocessing\dummy\*
  • c:\Python27\Lib\email\mime\*
  • c:\ProgramData\Microsoft\Diagnosis\ETLLogs\AutoLogger\*
  • c:\Python27\tcl\tix8.4.3\demos\bitmaps\*
  • c:\Users\Public\Documents\*
  • c:\ProgramData\Microsoft\Windows Defender\Scans\CleanStore\Resources\35\*
  • c:\ProgramData\Microsoft\Device Stage\Task\{07deb856-fc6e-4fb9-8add-d8f2cf8722c9}\*
  • c:\ProgramData\Microsoft\OfficeSoftwareProtectionPlatform\Cache\*
  • c:\ypliys\modules\packages\*
  • c:\Python27\Lib\lib-tk\*
  • c:\Users\Harry Dresden\Favorites\*
  • c:\Python27\Doc\*
  • c:\ypliys\modules\*
  • c:\Python27\Lib\curses\*
  • c:\Python27\Lib\lib2to3\pgen2\*
  • c:\ProgramData\Microsoft\Windows Defender\Scans\CleanStore\ResourceData\1A\*
  • c:\ProgramData\Microsoft\Windows Defender\Scans\CleanStore\ResourceData\A5\*
  • c:\ProgramData\Adobe\Acrobat\*
  • c:\Python27\Lib\*
  • c:\inetpub\history\CFGHISTORY_0000000004\schema\*
  • c:\Python27\tcl\tix8.4.3\demos\*
  • \\SHARDREALM\Users\Public\Pictures\Sample Pictures\*
  • c:\6cdeacda242012e0e5b593e657\1042\*
  • c:\Python27\Lib\test\audiodata\*
  • c:\inetpub\history\CFGHISTORY_0000000004\*
  • c:\Python27\Lib\site-packages\pip\_vendor\requests\*
  • c:\Python27\tcl\tcl8.5\tzdata\*
  • c:\Python27\Lib\site-packages\pip\_vendor\_markerlib\*
  • c:\Python27\tcl\tcl8\8.4\platform\*
  • c:\ProgramData\Microsoft\ClickToRun\{9AC08E99-230B-47e8-9721-4577B7F124EA}\*
  • \\SHARDREALM\Users\Public\Foxit Software\Foxit Reader\StartPage\start\en_us\css\*
  • c:\Python27\Lib\site-packages\pip\vcs\*
  • c:\6cdeacda242012e0e5b593e657\1046\*
  • c:\Users\Public\Foxit Software\Foxit Reader\StartPage\start\en_us\Default\*
  • c:\Python27\tcl\tix8.4.3\pref\*
  • c:\Python27\Lib\site-packages\pip\compat\*
  • \\SHARDREALM\Users\Public\Pictures\*
  • c:\Python27\Lib\json\*
  • c:\Python27\Lib\lib2to3\fixes\*
  • c:\ProgramData\Microsoft\Windows Defender\LocalCopy\*
  • c:\ProgramData\Microsoft\Assistance\Client\*
  • c:\ProgramData\Microsoft\Crypto\RSA\S-1-5-18\*
  • \\SHARDREALM\Users\Default\*
  • c:\Python27\Lib\test\leakers\*
  • \\SHARDREALM\Users\Harry Dresden\Saved Games\*
  • c:\ProgramData\Microsoft\Media Player\*
  • c:\ProgramData\McAfee\MCLOGS\Common\jxpiinstall\*
  • c:\Python27\Lib\site-packages\pip\_vendor\html5lib\filters\*
  • c:\Python27\Tools\*
  • c:\6cdeacda242012e0e5b593e657\1044\*
  • c:\6cdeacda242012e0e5b593e657\1036\*
  • c:\inetpub\history\*
  • c:\6cdeacda242012e0e5b593e657\1032\*
  • c:\Python27\tcl\tcl8.5\tzdata\Chile\*
  • c:\Python27\Lib\site-packages\pip\_vendor\packaging\*
  • \\SHARDREALM\Users\Public\Recorded TV\*
  • c:\ProgramData\Microsoft\Windows NT\MSScan\*
  • c:\Python27\Lib\email\test\data\*
  • c:\Python27\tcl\tix8.4.3\bitmaps\*
  • c:\Python27\Lib\site-packages\pip\_vendor\colorama\*
  • c:\Python27\Lib\lib2to3\tests\*
  • c:\ProgramData\regid.1991-06.com.microsoft\*
  • c:\ProgramData\Microsoft\Windows Defender\Scans\CleanStore\ResourceData\F7\*
  • c:\ProgramData\Microsoft OneDrive\setup\*
  • c:\inetpub\history\CFGHISTORY_0000000005\schema\*
  • c:\Python27\Lib\site-packages\pip\_vendor\cachecontrol\caches\*
  • c:\Python27\Lib\distutils\command\*
  • c:\Python27\Lib\site-packages\pip\_vendor\requests\packages\urllib3\*
  • c:\Python27\tcl\*
  • c:\Python27\Lib\site-packages\pip\commands\*
  • c:\Python27\Lib\site-packages\pkg_resources\*
  • c:\ProgramData\Microsoft\Windows Defender\Scans\CleanStore\ResourceData\F3\*
  • c:\Python27\Lib\multiprocessing\*
  • c:\Python27\Lib\wsgiref\*
  • c:\6cdeacda242012e0e5b593e657\3082\*
  • c:\Users\Public\Favorites\*
  • c:\Python27\Lib\lib-tk\test\*
  • c:\Python27\Lib\site-packages\pip\_vendor\requests\packages\urllib3\util\*
  • c:\ProgramData\Microsoft\RAC\StateData\*
  • c:\Python27\tcl\tcl8.5\tzdata\America\Indiana\*
  • c:\Python27\Lib\site-packages\_markerlib\*
  • \\SHARDREALM\Users\Public\Foxit Software\Foxit Reader\StartPage\start\en_us\images\*
  • c:\Python27\Lib\idlelib\idle_test\*
  • c:\ProgramData\Adobe\ARM\Reader_11.0.10\*
  • c:\inetpub\custerr\en-US\*
  • c:\ProgramData\Microsoft\Windows Defender\Definition Updates\*
  • c:\6cdeacda242012e0e5b593e657\1040\*
Registry Key-Opened
  • HKEY_CLASSES_ROOT\PROTOCOLS\Name-Space Handler\http\
  • HKEY_CURRENT_USER\Software
  • HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_INITIALIZE_URLACTION_SHELLEXECUTE_TO_ALLOW_KB936610
  • HKEY_LOCAL_MACHINE\Software\Microsoft\COM3
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings
  • HKEY_CURRENT_USER\SOFTWARE\Classes\PROTOCOLS\Filter\text/plain
  • HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\User Agent
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\MAIN\FeatureControl\FEATURE_USE_IETLDLIST_FOR_DOMAIN_DETERMINATION
  • HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings
  • HKEY_CLASSES_ROOT\.js
  • HKEY_LOCAL_MACHINE\Software\Policies
  • HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_ZONES_DEFAULT_DRIVE_INTRANET_KB941000
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\3
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\MAIN\FeatureControl\FEATURE_INITIALIZE_URLACTION_SHELLEXECUTE_TO_ALLOW_KB936610
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\MAIN\FeatureControl\FEATURE_ALLOW_REVERSE_SOLIDUS_IN_USERINFO_KB932562
  • HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\User Agent
  • HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_LOCALMACHINE_LOCKDOWN
  • HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_USE_IETLDLIST_FOR_DOMAIN_DETERMINATION
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\MAIN\FeatureControl\FEATURE_IGNORE_POLICIES_ZONEMAP_IF_ESC_ENABLED_KB918915
  • HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_ZONES_CHECK_ZONEMAP_POLICY_KB941001
  • HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\User Agent
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\User Agent\Pre Platform
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\MAIN\FeatureControl\FEATURE_LOCALMACHINE_LOCKDOWN
  • HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Security
  • HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\{5F058833-0652-4B15-B7EA-02DD7798ACE8}\0a-00-27-00-00-00
  • HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Internet Settings
  • HKEY_CURRENT_USER\Software\Policies\Microsoft\Internet Explorer
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\MAIN\FeatureControl\FEATURE_MIME_HANDLING
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Security
  • HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_PROTOCOL_LOCKDOWN
  • HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_SHOW_CERT_WARNINGS_ON_POST_FROM_ISTREAM_KB2894776
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\MAIN\FeatureControl\FEATURE_ZONES_CHECK_ZONEMAP_POLICY_KB941001
  • HKEY_LOCAL_MACHINE\Software
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\User Agent\Pre Platform
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\MAIN\FeatureControl\FEATURE_PROTOCOL_LOCKDOWN
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\User Agent\Post Platform
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\{5F058833-0652-4B15-B7EA-02DD7798ACE8}
  • HKEY_CLASSES_ROOT\PROTOCOLS\Name-Space Handler\*\
  • HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_IGNORE_POLICIES_ZONEMAP_IF_ESC_ENABLED_KB918915
  • HKEY_CURRENT_USER\Software\Microsoft\Windows Script Host\Settings
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\0
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\1
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\2
  • HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_URLMON_IQDA_SIZE
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\4
  • HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_ALLOW_REVERSE_SOLIDUS_IN_USERINFO_KB932562
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\User Agent
  • HKEY_CURRENT_USER\Software\Policies
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\MAIN\FeatureControl\FEATURE_MAXCONNECTIONSPERSERVER
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\MAIN\FeatureControl\FEATURE_MAXCONNECTIONSPER1_0SERVER
  • HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad
  • HKEY_LOCAL_MACHINE\Software\Microsoft\Windows Script Host\Settings
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\PROTOCOLS\Filter\text/plain
  • HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\KindMap
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\MAIN\FeatureControl\FEATURE_URLMON_IQDA_SIZE
  • HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Connections
  • HKEY_CURRENT_USER\Software\Policies\Microsoft\Internet Explorer\Main
  • HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_MAXCONNECTIONSPERSERVER
  • HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_MAXCONNECTIONSPER1_0SERVER
  • HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\0a-00-27-00-00-00
  • HKEY_CURRENT_USER\SOFTWARE\Policies\Microsoft\Windows\CurrentVersion\Internet Settings
  • HKEY_LOCAL_MACHINE\System\Setup
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\MAIN\FeatureControl\FEATURE_ZONES_DEFAULT_DRIVE_INTRANET_KB941000
  • HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Internet Explorer\Main
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\User Agent\Post Platform
  • HKEY_CLASSES_ROOT\PROTOCOLS\Name-Space Handler\
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\MAIN\FeatureControl\FEATURE_BROWSER_EMULATION
  • HKEY_CLASSES_ROOT\JSFile\ScriptEngine
  • HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\UrlMon Settings
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings
  • HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_BROWSER_EMULATION
  • HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_MIME_HANDLING
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\MAIN\FeatureControl\FEATURE_SHOW_CERT_WARNINGS_ON_POST_FROM_ISTREAM_KB2894776
  • HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings
  • HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
  • HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows NT\Rpc
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\control\NetworkProvider\HwOrder
  • HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\VSS\VssAccessControl
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VBoxSF\NetworkProvider
  • HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\RDPNP\NetworkProvider
  • HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\VSS\Diag\VssapiPublisher
  • HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\WebClient\NetworkProvider
  • HKEY_LOCAL_MACHINE\Software\Microsoft\Rpc
  • HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Safeboot\Option
  • HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\LSA\AccessProviders
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\RDPNP\NetworkProvider
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\MiniNT
  • HKEY_LOCAL_MACHINE\Software\Microsoft\Ole
  • HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\VSS\Diag
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\LanmanWorkstation\NetworkProvider
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WebClient\NetworkProvider
  • HKEY_CURRENT_USER\Network\E
  • HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\ProductOptions
  • HKEY_LOCAL_MACHINE\system\CurrentControlSet\Control\NetworkProvider\Notifyees
  • HKEY_CURRENT_USER\Network
  • HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\LDAP
  • HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\FileSystem
  • HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\LanmanWorkstation\NetworkProvider
  • HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System
  • HKEY_LOCAL_MACHINE\system\CurrentControlSet
Registry Key-Deleted
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ProxyOverride
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ProxyServer
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\AutoDetect
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\{5F058833-0652-4B15-B7EA-02DD7798ACE8}\WpadDetectedUrl
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\0a-00-27-00-00-00\WpadDetectedUrl
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\AutoConfigURL
Registry Key-Read
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\NonEnum\{04731B67-D933-450A-90E6-4ACD2E9408FE}
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Cryptography\Providers\Trust\Initialization\{00AAC56B-CD44-11D0-8CC2-00C04FC295EE}\$Function
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{BD7A2E7B-21CB-41B2-A086-B309680C6B7E}\ShellFolder\PinToNameSpaceTree
  • HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_LOCALMACHINE_LOCKDOWN\*
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{138508BC-1E03-49EA-9C8F-EA9E1D05D65D}\ShellFolder\WantsFORDISPLAY
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ReceiveTimeOut
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{89D83576-6BD1-4C86-9454-BEB04E94C819}\ShellFolder\RestrictedAttributes
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{208D2C60-3AEA-1069-A2D7-08002B30309D}\ShellFolder\WantsFORPARSING
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FileAssociation\AllowedReservedCharacters
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{B4FB3F98-C1EA-428D-A78A-D1F5659CBA93}\ShellFolder\NoFileFolderJunction
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\NonEnum\{031E4825-7B94-4DC3-B131-E946B44C8DD5}
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ConnectTimeOut
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{031E4825-7B94-4DC3-B131-E946B44C8DD5}\ShellFolder\MapNetDriveVerbs
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{5399E694-6CE5-4D6C-8FCE-1D8870FDCBA0}\ShellFolder\WantsParseDisplayName
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{645FF040-5081-101B-9F08-00AA002F954E}\ShellFolder\RestrictedAttributes
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\NoSetFolders
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{00000566-0000-0010-8000-00AA006D2EA4}\(Default)
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{B4BFCC3A-DB2C-424C-B029-7FE99A87C641}\LocalizedName
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\MAIN\FeatureControl\FEATURE_LOCALMACHINE_LOCKDOWN\wscript.exe
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{DAF95313-E44D-46AF-BE1B-CBACEA2C3065}\ShellFolder\WantsFORPARSING
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\NoSimpleStartMenu
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\crypt32\DiagMatchAnyMask
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\User Agent\Platform
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{450D8FBA-AD25-11D0-98A8-0800361B1103}\ShellFolder\HideFolderVerbs
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\CPC\Volume\{b9fc2740-d442-11e0-8ee6-806e6f6e6963}\Generation
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{B4BFCC3A-DB2C-424C-B029-7FE99A87C641}\ParsingName
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{DAF95313-E44D-46AF-BE1B-CBACEA2C3065}\ShellFolder\WantsFORDISPLAY
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\NonEnum\{ED228FDF-9EA8-4870-83B1-96B02CFE0D52}
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{BD7A2E7B-21CB-41B2-A086-B309680C6B7E}\ShellFolder\HasNavigationEnum
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{B4FB3F98-C1EA-428D-A78A-D1F5659CBA93}\ShellFolder\WantsFORDISPLAY
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{E345F35F-9397-435C-8F95-4E922C26259E}\ShellFolder\HideOnDesktopPerUser
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{9343812E-1C37-4A49-A12E-4B2D810D956B}\ShellFolder\MapNetDriveVerbs
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Rpc\Extensions\RemoteRpcDll
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\ShellFolder\NoFileFolderJunction
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{031E4825-7B94-4DC3-B131-E946B44C8DD5}\ShellFolder\HideInWebView
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\CLSID\{871C5380-42A0-1069-A2EA-08002B30309D}\ShellFolder\Attributes
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{208D2C60-3AEA-1069-A2D7-08002B30309D}\ShellFolder\NoFileFolderJunction
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{BCD1DE7E-2DB1-418B-B047-4A74E101F8C1}\ProxyStubClsid32\(Default)
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{4336A54D-038B-4685-AB02-99BB52D3FB8B}\ShellFolder\WantsFORPARSING
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{BD7A2E7B-21CB-41B2-A086-B309680C6B7E}\ShellFolder\MapNetDriveVerbs
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\.ade\(Default)
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{871C5380-42A0-1069-A2EA-08002B30309D}\ShellFolder\MapNetDriveVerbs
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{26EE0668-A00A-44D7-9371-BEB064C98683}\ShellFolder\WantsFORDISPLAY
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{450D8FBA-AD25-11D0-98A8-0800361B1103}\ShellFolder\QueryForOverlay
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{0875DCB6-C686-4243-9432-ADCCF0B9F2D7}\ShellFolder\HideInWebView
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{F3F5824C-AD58-4728-AF59-A1EBE3392799}\ShellFolder\HideInWebView
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{F3F5824C-AD58-4728-AF59-A1EBE3392799}\ShellFolder\WantsUniversalDelegate
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{138508BC-1E03-49EA-9C8F-EA9E1D05D65D}\ShellFolder\HasNavigationEnum
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\.cer\(Default)
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced\HideIcons
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ConnectTimeOut
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\NonEnum\{4336A54D-038B-4685-AB02-99BB52D3FB8B}
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{871C5380-42A0-1069-A2EA-08002B30309D}\ShellFolder\HasNavigationEnum
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{F3F5824C-AD58-4728-AF59-A1EBE3392799}\ShellFolder\RestrictedAttributes
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{450D8FBA-AD25-11D0-98A8-0800361B1103}\ShellFolder\HideInWebView
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\MAIN\FeatureControl\FEATURE_MIME_HANDLING\wscript.exe
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced\AutoCheckSelect
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{04731B67-D933-450A-90E6-4ACD2E9408FE}\ShellFolder\NoFileFolderJunction
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{DAF95313-E44D-46AF-BE1B-CBACEA2C3065}\ShellFolder\WantsUniversalDelegate
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{72C24DD5-D70A-438B-8A42-98424B88AFB8}\InProcServer32\InprocServer32
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{89D83576-6BD1-4C86-9454-BEB04E94C819}\ShellFolder\PinToNameSpaceTree
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{8FD8B88D-30E1-4F25-AC2B-553D3D65F0EA}\ShellFolder\WantsAliasedNotifications
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{00000566-0000-0010-8000-00AA006D2EA4}\InprocServer32\InprocServer32
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{11016101-E366-4D22-BC06-4ADA335C892B}\ShellFolder\Attributes
  • HKEY_CURRENT_USER\Directory\IsShortcut
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ProxyEnable
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{B4BFCC3A-DB2C-424C-B029-7FE99A87C641}\InitFolderHandler
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{0875DCB6-C686-4243-9432-ADCCF0B9F2D7}\ShellFolder\HideFolderVerbs
  • HKEY_CURRENT_USER\Directory\AlwaysShowExt
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{1B3EA5DC-B587-4786-B4EF-BD1DC332AEAE}\PreCreate
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\CPC\Volume\{b9fc2740-d442-11e0-8ee6-806e6f6e6963}\Data
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{8FD8B88D-30E1-4F25-AC2B-553D3D65F0EA}\ShellFolder\WantsFORPARSING
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\.exe\Content Type
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{59031A47-3F72-44A7-89C5-5595FE6B30EE}\ShellFolder\PinToNameSpaceTree
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{11016101-E366-4D22-BC06-4ADA335C892B}\ShellFolder\UseDropHandler
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{5399E694-6CE5-4D6C-8FCE-1D8870FDCBA0}\ShellFolder\HideInWebView
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{F6D90F16-9C73-11D3-B32E-00C04F990BB4}\ProgID\(Default)
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\ShellFolder\RestrictedAttributes
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\MAIN\FeatureControl\FEATURE_MAXCONNECTIONSPERSERVER\wscript.exe
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\IntranetName
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{645FF040-5081-101B-9F08-00AA002F954E}\ShellFolder\HideOnDesktopPerUser
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AllFilesystemObjects\IsShortcut
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{F02C1A0D-BE21-4350-88B0-7367FC96EF3C}\ShellFolder\WantsFORPARSING
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{11016101-E366-4D22-BC06-4ADA335C892B}\ShellFolder\HideInWebView
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{98D99750-0B8A-4C59-9151-589053683D73}\ShellFolder\RestrictedAttributes
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{98D99750-0B8A-4C59-9151-589053683D73}\ShellFolder\HasNavigationEnum
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{E345F35F-9397-435C-8F95-4E922C26259E}\ShellFolder\RestrictedAttributes
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{645FF040-5081-101B-9F08-00AA002F954E}\ShellFolder\WantsUniversalDelegate
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\NonEnum\{645FF040-5081-101B-9F08-00AA002F954E}
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Script Host\Settings\IgnoreUserSettings
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\MAIN\FeatureControl\FEATURE_MAXCONNECTIONSPER1_0SERVER\wscript.exe
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{89D83576-6BD1-4C86-9454-BEB04E94C819}\ShellFolder\Attributes
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{59031A47-3F72-44A7-89C5-5595FE6B30EE}\ShellFolder\MapNetDriveVerbs
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\0\Flags
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{BD7A2E7B-21CB-41B2-A086-B309680C6B7E}\ShellFolder\HideInWebView
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{450D8FBA-AD25-11D0-98A8-0800361B1103}\ShellFolder\WantsFORDISPLAY
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AllFilesystemObjects\DocObject
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{E345F35F-9397-435C-8F95-4E922C26259E}\ShellFolder\WantsAliasedNotifications
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{F02C1A0D-BE21-4350-88B0-7367FC96EF3C}\ShellFolder\WantsUniversalDelegate
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\NonEnum\{9343812E-1C37-4A49-A12E-4B2D810D956B}
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{04731B67-D933-450A-90E6-4ACD2E9408FE}\ShellFolder\MapNetDriveVerbs
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{1B3EA5DC-B587-4786-B4EF-BD1DC332AEAE}\RelativePath
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{B4FB3F98-C1EA-428D-A78A-D1F5659CBA93}\ShellFolder\HasNavigationEnum
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{208D2C60-3AEA-1069-A2D7-08002B30309D}\ShellFolder\MapNetDriveVerbs
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Desktop\NameSpace\{BD7A2E7B-21CB-41b2-A086-B309680C6B7E}\SuppressionPolicy
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{031E4825-7B94-4DC3-B131-E946B44C8DD5}\ShellFolder\UseDropHandler
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{59031A47-3F72-44A7-89C5-5595FE6B30EE}\ShellFolder\CallForAttributes
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Desktop\NameSpace\{450D8FBA-AD25-11D0-98A8-0800361B1103}\SuppressionPolicy
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{04731B67-D933-450A-90E6-4ACD2E9408FE}\ShellFolder\HideFolderVerbs
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{E345F35F-9397-435C-8F95-4E922C26259E}\ShellFolder\WantsUniversalDelegate
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced\DontPrettyPath
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{9343812E-1C37-4A49-A12E-4B2D810D956B}\ShellFolder\WantsParseDisplayName
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{F3F5824C-AD58-4728-AF59-A1EBE3392799}\ShellFolder\PinToNameSpaceTree
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\DevicePath
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{DAF95313-E44D-46AF-BE1B-CBACEA2C3065}\ShellFolder\QueryForInfoTip
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{B4FB3F98-C1EA-428D-A78A-D1F5659CBA93}\ShellFolder\MapNetDriveVerbs
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\User Agent\(Default)
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{9343812E-1C37-4A49-A12E-4B2D810D956B}\ShellFolder\WantsAliasedNotifications
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Script Host\Settings\LogSecuritySuccesses
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{031E4825-7B94-4DC3-B131-E946B44C8DD5}\ShellFolder\WantsUniversalDelegate
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{E345F35F-9397-435C-8F95-4E922C26259E}\ShellFolder\WantsFORDISPLAY
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\MAIN\FeatureControl\FEATURE_BROWSER_EMULATION\*
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{B196B286-BAB4-101A-B69C-00AA00341D07}\InprocServer32\ThreadingModel
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{871C5380-42A0-1069-A2EA-08002B30309D}\InProcServer32\(Default)
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{871C5380-42A0-1069-A2EA-08002B30309D}\ShellFolder\QueryForInfoTip
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{871C5380-42A0-1069-A2EA-08002B30309D}\ShellFolder\WantsUniversalDelegate
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{031E4825-7B94-4DC3-B131-E946B44C8DD5}\ShellFolder\WantsParseDisplayName
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{208D2C60-3AEA-1069-A2D7-08002B30309D}\ShellFolder\UseDropHandler
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{9343812E-1C37-4A49-A12E-4B2D810D956B}\ShellFolder\WantsUniversalDelegate
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{26EE0668-A00A-44D7-9371-BEB064C98683}\ShellFolder\HasNavigationEnum
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{F02C1A0D-BE21-4350-88B0-7367FC96EF3C}\ShellFolder\WantsParseDisplayName
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{BD7A2E7B-21CB-41B2-A086-B309680C6B7E}\ShellFolder\HideFolderVerbs
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{645FF040-5081-101B-9F08-00AA002F954E}\ShellFolder\UseDropHandler
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced\ShowTypeOverlay
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{F02C1A0D-BE21-4350-88B0-7367FC96EF3C}\ShellFolder\UseDropHandler
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced\MapNetDrvBtn
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Cryptography\Providers\Trust\Certificate\{00AAC56B-CD44-11D0-8CC2-00C04FC295EE}\$Function
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\MAIN\FeatureControl\FEATURE_MAXCONNECTIONSPER1_0SERVER\*
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Filter
  • HKEY_CURRENT_USER\Directory\NeverShowExt
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{F02C1A0D-BE21-4350-88B0-7367FC96EF3C}\ShellFolder\PinToNameSpaceTree
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Desktop\NameSpace\{138508bc-1e03-49ea-9c8f-ea9e1d05d65d}\SuppressionPolicy
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\ExtendedLocale\en-US
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{8FD8B88D-30E1-4F25-AC2B-553D3D65F0EA}\ShellFolder\HideInWebView
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\MigrateProxy
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{F3F5824C-AD58-4728-AF59-A1EBE3392799}\ShellFolder\CallForAttributes
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{5399E694-6CE5-4D6C-8FCE-1D8870FDCBA0}\ShellFolder\PinToNameSpaceTree
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\2\Flags
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{4336A54D-038B-4685-AB02-99BB52D3FB8B}\ShellFolder\QueryForInfoTip
  • HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\safer\codeidentifiers\LogFileName
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\NoWebView
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{59031A47-3F72-44A7-89C5-5595FE6B30EE}\ShellFolder\QueryForInfoTip
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{00000566-0000-0010-8000-00AA006D2EA4}\InprocServer32\ThreadingModel
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{59031A47-3F72-44A7-89C5-5595FE6B30EE}\ShellFolder\WantsFORPARSING
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{8FD8B88D-30E1-4F25-AC2B-553D3D65F0EA}\ShellFolder\QueryForOverlay
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{89D83576-6BD1-4C86-9454-BEB04E94C819}\ShellFolder\WantsFORDISPLAY
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{5399E694-6CE5-4D6C-8FCE-1D8870FDCBA0}\ShellFolder\WantsUniversalDelegate
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\.js\(Default)
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{B4BFCC3A-DB2C-424C-B029-7FE99A87C641}\Roamable
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{B4FB3F98-C1EA-428D-A78A-D1F5659CBA93}\ShellFolder\HideInWebView
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Script Host\Settings\Enabled
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Cryptography\Providers\Trust\FinalPolicy\{00AAC56B-CD44-11D0-8CC2-00C04FC295EE}\$DLL
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{645FF040-5081-101B-9F08-00AA002F954E}\ShellFolder\WantsAliasedNotifications
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{031E4825-7B94-4DC3-B131-E946B44C8DD5}\ShellFolder\HideOnDesktopPerUser
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{26EE0668-A00A-44D7-9371-BEB064C98683}\ShellFolder\QueryForInfoTip
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\ADODB.Stream\CLSID\(Default)
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Desktop\NameSpace\{89D83576-6BD1-4c86-9454-BEB04E94C819}\SuppressionPolicy
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Desktop\NameSpace\{98D99750-0B8A-4c59-9151-589053683D73}\SuppressionPolicy
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{E345F35F-9397-435C-8F95-4E922C26259E}\ShellFolder\PinToNameSpaceTree
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Lsa\FipsAlgorithmPolicy
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{645FF040-5081-101B-9F08-00AA002F954E}\ShellFolder\PinToNameSpaceTree
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\NonEnum\{450D8FBA-AD25-11D0-98A8-0800361B1103}
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{F3F5824C-AD58-4728-AF59-A1EBE3392799}\ShellFolder\WantsFORPARSING
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{98D99750-0B8A-4C59-9151-589053683D73}\ShellFolder\WantsFORPARSING
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\exefile\IsShortcut
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{4336A54D-038B-4685-AB02-99BB52D3FB8B}\ShellFolder\HideFolderVerbs
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{F02C1A0D-BE21-4350-88B0-7367FC96EF3C}\ShellFolder\HideFolderVerbs
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{208D2C60-3AEA-1069-A2D7-08002B30309D}\ShellFolder\HideInWebView
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\exefile\shell\open\command\(Default)
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\crypt32\DiagLevel
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{0875DCB6-C686-4243-9432-ADCCF0B9F2D7}\ShellFolder\MapNetDriveVerbs
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{DAF95313-E44D-46AF-BE1B-CBACEA2C3065}\ShellFolder\WantsParseDisplayName
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{0875DCB6-C686-4243-9432-ADCCF0B9F2D7}\ShellFolder\WantsFORDISPLAY
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{5399E694-6CE5-4D6C-8FCE-1D8870FDCBA0}\ShellFolder\QueryForInfoTip
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{F3F5824C-AD58-4728-AF59-A1EBE3392799}\ShellFolder\WantsFORDISPLAY
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{F3F5824C-AD58-4728-AF59-A1EBE3392799}\ShellFolder\WantsAliasedNotifications
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{98D99750-0B8A-4C59-9151-589053683D73}\ShellFolder\HideFolderVerbs
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\ShellFolder\MapNetDriveVerbs
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{59031A47-3F72-44A7-89C5-5595FE6B30EE}\ShellFolder\QueryForOverlay
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\SeparateProcess
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\SystemFileAssociations\.exe\AlwaysShowExt
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{9343812E-1C37-4A49-A12E-4B2D810D956B}\ShellFolder\CallForAttributes
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Hidden
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Script Host\Settings\Timeout
  • HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Cryptography\PrivKeyCachePurgeIntervalSeconds
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\NonEnum\{DAF95313-E44D-46AF-BE1B-CBACEA2C3065}
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{B4FB3F98-C1EA-428D-A78A-D1F5659CBA93}\ShellFolder\QueryForOverlay
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{DAF95313-E44D-46AF-BE1B-CBACEA2C3065}\ShellFolder\MapNetDriveVerbs
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{450D8FBA-AD25-11D0-98A8-0800361B1103}\ShellFolder\HasNavigationEnum
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\NoWebView
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\OLE\MaximumAllowedAllocationSize
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{871C5380-42A0-1069-A2EA-08002B30309D}\ShellFolder\WantsFORDISPLAY
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{208D2C60-3AEA-1069-A2D7-08002B30309D}\ShellFolder\QueryForOverlay
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{4336A54D-038B-4685-AB02-99BB52D3FB8B}\ShellFolder\RestrictedAttributes
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{138508BC-1E03-49EA-9C8F-EA9E1D05D65D}\ShellFolder\RestrictedAttributes
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\NonEnum\{208D2C60-3AEA-1069-A2D7-08002B30309D}
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{138508BC-1E03-49EA-9C8F-EA9E1D05D65D}\ShellFolder\HideInWebView
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{89D83576-6BD1-4C86-9454-BEB04E94C819}\ShellFolder\NoFileFolderJunction
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\KindMap\.exe
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\0a-00-27-00-00-00\WpadDhcp
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{1B3EA5DC-B587-4786-B4EF-BD1DC332AEAE}\ParsingName
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\DisallowRun
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ProxyServer
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{5399E694-6CE5-4D6C-8FCE-1D8870FDCBA0}\ShellFolder\HideFolderVerbs
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\SendTimeOut
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{BD7A2E7B-21CB-41B2-A086-B309680C6B7E}\ShellFolder\WantsFORPARSING
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{E345F35F-9397-435C-8F95-4E922C26259E}\ShellFolder\HideInWebView
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{645FF040-5081-101B-9F08-00AA002F954E}\ShellFolder\NoFileFolderJunction
  • HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\International\AcceptLanguage
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{4336A54D-038B-4685-AB02-99BB52D3FB8B}\ShellFolder\WantsParseDisplayName
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{E345F35F-9397-435C-8F95-4E922C26259E}\ShellFolder\HideFolderVerbs
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{138508BC-1E03-49EA-9C8F-EA9E1D05D65D}\ShellFolder\MapNetDriveVerbs
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{031E4825-7B94-4DC3-B131-E946B44C8DD5}\ShellFolder\NoFileFolderJunction
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders\{1B3EA5DC-B587-4786-B4EF-BD1DC332AEAE}
  • HKEY_LOCAL_MACHINE\SYSTEM\Setup\SystemSetupInProgress
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\DontShowSuperHidden
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{04731B67-D933-450A-90E6-4ACD2E9408FE}\ShellFolder\WantsParseDisplayName
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{26EE0668-A00A-44D7-9371-BEB064C98683}\ShellFolder\CallForAttributes
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{04731B67-D933-450A-90E6-4ACD2E9408FE}\ShellFolder\Attributes
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced\ShowInfoTip
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{4336A54D-038B-4685-AB02-99BB52D3FB8B}\ShellFolder\WantsUniversalDelegate
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{138508BC-1E03-49EA-9C8F-EA9E1D05D65D}\ShellFolder\Attributes
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\0a-00-27-00-00-00\WpadDecisionReason
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\NonEnum\{F3F5824C-AD58-4728-AF59-A1EBE3392799}
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Setup\SourcePath
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{04731B67-D933-450A-90E6-4ACD2E9408FE}\ShellFolder\QueryForInfoTip
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{98D99750-0B8A-4C59-9151-589053683D73}\ShellFolder\NoFileFolderJunction
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{4336A54D-038B-4685-AB02-99BB52D3FB8B}\ShellFolder\WantsFORDISPLAY
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{138508BC-1E03-49EA-9C8F-EA9E1D05D65D}\ShellFolder\CallForAttributes
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{138508BC-1E03-49EA-9C8F-EA9E1D05D65D}\ShellFolder\HideFolderVerbs
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{04731B67-D933-450A-90E6-4ACD2E9408FE}\ShellFolder\PinToNameSpaceTree
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Folder\NeverShowExt
  • HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\safer\codeidentifiers\SaferFlags
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\ShellFolder\WantsParseDisplayName
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{26EE0668-A00A-44D7-9371-BEB064C98683}\ShellFolder\HideFolderVerbs
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\AutoConfigURL
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{F3F5824C-AD58-4728-AF59-A1EBE3392799}\ShellFolder\WantsParseDisplayName
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{98D99750-0B8A-4C59-9151-589053683D73}\ShellFolder\PinToNameSpaceTree
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\exefile\NeverShowExt
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\ProxyBypass
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{8FD8B88D-30E1-4F25-AC2B-553D3D65F0EA}\ShellFolder\HideFolderVerbs
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{B196B286-BAB4-101A-B69C-00AA00341D07}\(Default)
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{2A1C9EB2-DF62-4154-B800-63278FCB8037}\ProxyStubClsid32\(Default)
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{98D99750-0B8A-4C59-9151-589053683D73}\ShellFolder\QueryForOverlay
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{208D2C60-3AEA-1069-A2D7-08002B30309D}\ShellFolder\WantsUniversalDelegate
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{4336A54D-038B-4685-AB02-99BB52D3FB8B}\ShellFolder\QueryForOverlay
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{0875DCB6-C686-4243-9432-ADCCF0B9F2D7}\ShellFolder\QueryForInfoTip
  • HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main\SessionMerging
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{B4FB3F98-C1EA-428D-A78A-D1F5659CBA93}\ShellFolder\HideFolderVerbs
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\.bat\(Default)
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{F02C1A0D-BE21-4350-88B0-7367FC96EF3C}\ShellFolder\RestrictedAttributes
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{4336A54D-038B-4685-AB02-99BB52D3FB8B}\ShellFolder\Attributes
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{0D43FE01-F093-11CF-8940-00A0C9054228}\InprocServer32\ThreadingModel
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{F02C1A0D-BE21-4350-88B0-7367FC96EF3C}\ShellFolder\HasNavigationEnum
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{B196B286-BAB4-101A-B69C-00AA00341D07}\InprocServer32\InprocServer32
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{031E4825-7B94-4DC3-B131-E946B44C8DD5}\ShellFolder\HasNavigationEnum
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\NonEnum\{20D04FE0-3AEA-1069-A2D8-08002B30309D}
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{89D83576-6BD1-4C86-9454-BEB04E94C819}\ShellFolder\HideFolderVerbs
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Directory\AlwaysShowExt
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\Locale\00000409
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{B4BFCC3A-DB2C-424C-B029-7FE99A87C641}\InfoTip
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Desktop\NameSpace\{4336a54d-038b-4685-ab02-99bb52d3fb8b}\SuppressionPolicy
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{0875DCB6-C686-4243-9432-ADCCF0B9F2D7}\ShellFolder\QueryForOverlay
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{F02C1A0D-BE21-4350-88B0-7367FC96EF3C}\ShellFolder\Attributes
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{59031A47-3F72-44A7-89C5-5595FE6B30EE}\ShellFolder\HideFolderVerbs
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\MAIN\FeatureControl\FEATURE_BROWSER_EMULATION\wscript.exe
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{59031A47-3F72-44A7-89C5-5595FE6B30EE}\ShellFolder\Attributes
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{138508BC-1E03-49EA-9C8F-EA9E1D05D65D}\ShellFolder\UseDropHandler
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{208D2C60-3AEA-1069-A2D7-08002B30309D}\ShellFolder\WantsParseDisplayName
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{208D2C60-3AEA-1069-A2D7-08002B30309D}\ShellFolder\QueryForInfoTip
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\NoCommonGroups
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{F02C1A0D-BE21-4350-88B0-7367FC96EF3C}\ShellFolder\NoFileFolderJunction
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{B4BFCC3A-DB2C-424C-B029-7FE99A87C641}\FolderTypeID
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{F6D90F16-9C73-11D3-B32E-00C04F990BB4}\InProcServer32\ThreadingModel
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\.crt\(Default)
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{89D83576-6BD1-4C86-9454-BEB04E94C819}\ShellFolder\QueryForInfoTip
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SQMClient\Windows\DisabledSessions\MachineThrottling
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{F02C1A0D-BE21-4350-88B0-7367FC96EF3C}\ShellFolder\MapNetDriveVerbs
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Cryptography\Defaults\Provider\Microsoft Enhanced RSA and AES Cryptographic Provider\Type
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{00000566-0000-0010-8000-00AA006D2EA4}\InprocServer32\(Default)
  • HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\EnableUTF8
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{11016101-E366-4D22-BC06-4ADA335C892B}\ShellFolder\RestrictedAttributes
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\COM3\COM+Enabled
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{04731B67-D933-450A-90E6-4ACD2E9408FE}\ShellFolder\WantsFORPARSING
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{1B3EA5DC-B587-4786-B4EF-BD1DC332AEAE}\Name
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{04731B67-D933-450A-90E6-4ACD2E9408FE}\ShellFolder\HideInWebView
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{208D2C60-3AEA-1069-A2D7-08002B30309D}\ShellFolder\RestrictedAttributes
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders\Desktop
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{0875DCB6-C686-4243-9432-ADCCF0B9F2D7}\ShellFolder\WantsFORPARSING
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\MAIN\FeatureControl\FEATURE_MAXCONNECTIONSPERSERVER\*
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{8FD8B88D-30E1-4F25-AC2B-553D3D65F0EA}\ShellFolder\CallForAttributes
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Desktop\NameSpace\{11016101-E366-4D22-BC06-4ADA335C892B}\SuppressionPolicy
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{0875DCB6-C686-4243-9432-ADCCF0B9F2D7}\ShellFolder\WantsParseDisplayName
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Desktop\NameSpace\{e345f35f-9397-435c-8f95-4e922c26259e}\SuppressionPolicy
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Directory\BrowseInPlace
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{1B3EA5DC-B587-4786-B4EF-BD1DC332AEAE}\PublishExpandedPath
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{0875DCB6-C686-4243-9432-ADCCF0B9F2D7}\ShellFolder\CallForAttributes
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{72C24DD5-D70A-438B-8A42-98424B88AFB8}\ProgID\(Default)
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\.bas\(Default)
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{208D2C60-3AEA-1069-A2D7-08002B30309D}\ShellFolder\HideFolderVerbs
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{1B3EA5DC-B587-4786-B4EF-BD1DC332AEAE}\Category
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\.com\(Default)
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{98D99750-0B8A-4C59-9151-589053683D73}\ShellFolder\Attributes
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\exefile\BrowseInPlace
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Desktop\NameSpace\{645FF040-5081-101B-9F08-00AA002F954E}\SuppressionPolicy
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{00000134-0000-0000-C000-000000000046}\ProxyStubClsid32\(Default)
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{0875DCB6-C686-4243-9432-ADCCF0B9F2D7}\ShellFolder\NoFileFolderJunction
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{ED228FDF-9EA8-4870-83B1-96B02CFE0D52}\ShellFolder\WantsFORPARSING
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{871C5380-42A0-1069-A2EA-08002B30309D}\ShellFolder\WantsParseDisplayName
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{645FF040-5081-101B-9F08-00AA002F954E}\ShellFolder\MapNetDriveVerbs
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{ED228FDF-9EA8-4870-83B1-96B02CFE0D52}\ShellFolder\CallForAttributes
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\ShellFolder\QueryForInfoTip
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\User Agent\Version
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{26EE0668-A00A-44D7-9371-BEB064C98683}\ShellFolder\WantsFORPARSING
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{5399E694-6CE5-4D6C-8FCE-1D8870FDCBA0}\ShellFolder\WantsFORPARSING
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{8FD8B88D-30E1-4F25-AC2B-553D3D65F0EA}\ShellFolder\Attributes
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{BD7A2E7B-21CB-41B2-A086-B309680C6B7E}\ShellFolder\UseDropHandler
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{B4BFCC3A-DB2C-424C-B029-7FE99A87C641}\LocalRedirectOnly
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Cryptography\Providers\Trust\Cleanup\{00AAC56B-CD44-11D0-8CC2-00C04FC295EE}\$DLL
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\DisallowRun
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced\ShowCompColor
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\MAIN\FrameTabWindow
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{5399E694-6CE5-4D6C-8FCE-1D8870FDCBA0}\ShellFolder\HideOnDesktopPerUser
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{8A40A45D-055C-4B62-ABD7-6D613E2CEAEC}\ProxyStubClsid32\(Default)
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{ED228FDF-9EA8-4870-83B1-96B02CFE0D52}\ShellFolder\HideInWebView
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{DAF95313-E44D-46AF-BE1B-CBACEA2C3065}\ShellFolder\PinToNameSpaceTree
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{1B3EA5DC-B587-4786-B4EF-BD1DC332AEAE}\Description
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{11016101-E366-4D22-BC06-4ADA335C892B}\ShellFolder\QueryForInfoTip
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{F3F5824C-AD58-4728-AF59-A1EBE3392799}\ShellFolder\QueryForOverlay
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{1B3EA5DC-B587-4786-B4EF-BD1DC332AEAE}\Icon
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\NoPropertiesRecycleBin
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{89D83576-6BD1-4C86-9454-BEB04E94C819}\ShellFolder\WantsFORPARSING
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{00000566-0000-0010-8000-00AA006D2EA4}\ProgID\(Default)
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{450D8FBA-AD25-11D0-98A8-0800361B1103}\ShellFolder\QueryForInfoTip
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\NoPropertiesMyComputer
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{5399E694-6CE5-4D6C-8FCE-1D8870FDCBA0}\ShellFolder\WantsFORDISPLAY
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Desktop\NameSpace\{59031a47-3f72-44a7-89c5-5595fe6b30ee}\SuppressionPolicy
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Srp\GP\RuleCount
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{138508BC-1E03-49EA-9C8F-EA9E1D05D65D}\ShellFolder\WantsAliasedNotifications
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{B4BFCC3A-DB2C-424C-B029-7FE99A87C641}\Category
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{F3F5824C-AD58-4728-AF59-A1EBE3392799}\ShellFolder\HasNavigationEnum
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{208D2C60-3AEA-1069-A2D7-08002B30309D}\ShellFolder\HasNavigationEnum
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\WinTrust\Trust Providers\Software Publishing\State
  • HKEY_CURRENT_USER\Software\Microsoft\Windows Script Host\Settings\DisplayLogo
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{1B3EA5DC-B587-4786-B4EF-BD1DC332AEAE}\ParentFolder
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{72C24DD5-D70A-438B-8A42-98424B88AFB8}\InProcServer32\ThreadingModel
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\3\1A10
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{B4BFCC3A-DB2C-424C-B029-7FE99A87C641}\Description
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\ShellState
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{E345F35F-9397-435C-8F95-4E922C26259E}\ShellFolder\QueryForOverlay
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\MAIN\TabProcGrowth
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{04731B67-D933-450A-90E6-4ACD2E9408FE}\ShellFolder\WantsAliasedNotifications
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{8FD8B88D-30E1-4F25-AC2B-553D3D65F0EA}\ShellFolder\MapNetDriveVerbs
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{DAF95313-E44D-46AF-BE1B-CBACEA2C3065}\ShellFolder\WantsAliasedNotifications
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{26EE0668-A00A-44D7-9371-BEB064C98683}\ShellFolder\HideOnDesktopPerUser
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\NoCommonGroups
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{138508BC-1E03-49EA-9C8F-EA9E1D05D65D}\ShellFolder\WantsUniversalDelegate
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\NonEnum\{138508BC-1E03-49EA-9C8F-EA9E1D05D65D}
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{9343812E-1C37-4A49-A12E-4B2D810D956B}\ShellFolder\HideFolderVerbs
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{645FF040-5081-101B-9F08-00AA002F954E}\ShellFolder\WantsFORDISPLAY
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{ED228FDF-9EA8-4870-83B1-96B02CFE0D52}\ShellFolder\NoFileFolderJunction
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{645FF040-5081-101B-9F08-00AA002F954E}\ShellFolder\WantsFORPARSING
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{89D83576-6BD1-4C86-9454-BEB04E94C819}\ShellFolder\MapNetDriveVerbs
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{11016101-E366-4D22-BC06-4ADA335C892B}\ShellFolder\MapNetDriveVerbs
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{DAF95313-E44D-46AF-BE1B-CBACEA2C3065}\ShellFolder\UseDropHandler
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{11016101-E366-4D22-BC06-4ADA335C892B}\ShellFolder\NoFileFolderJunction
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{9343812E-1C37-4A49-A12E-4B2D810D956B}\ShellFolder\Attributes
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{26EE0668-A00A-44D7-9371-BEB064C98683}\ShellFolder\QueryForOverlay
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\NoPropertiesMyComputer
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Cryptography\Providers\Trust\Cleanup\{00AAC56B-CD44-11D0-8CC2-00C04FC295EE}\$Function
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{26EE0668-A00A-44D7-9371-BEB064C98683}\ShellFolder\WantsUniversalDelegate
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Directory\NeverShowExt
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{DAF95313-E44D-46AF-BE1B-CBACEA2C3065}\ShellFolder\RestrictedAttributes
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{4336A54D-038B-4685-AB02-99BB52D3FB8B}\ShellFolder\WantsAliasedNotifications
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{9343812E-1C37-4A49-A12E-4B2D810D956B}\ShellFolder\QueryForInfoTip
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Drive\shellex\FolderExtensions\{fbeb8a05-beee-4442-804e-409d6c4515e9}\DriveMask
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{B4BFCC3A-DB2C-424C-B029-7FE99A87C641}\PublishExpandedPath
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{B4BFCC3A-DB2C-424C-B029-7FE99A87C641}\PreCreate
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{89D83576-6BD1-4C86-9454-BEB04E94C819}\ShellFolder\QueryForOverlay
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\NoPropertiesRecycleBin
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{450D8FBA-AD25-11D0-98A8-0800361B1103}\ShellFolder\WantsUniversalDelegate
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\CreateUriCacheSize
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{26EE0668-A00A-44D7-9371-BEB064C98683}\ShellFolder\PinToNameSpaceTree
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{F6D90F16-9C73-11D3-B32E-00C04F990BB4}\(Default)
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{8FD8B88D-30E1-4F25-AC2B-553D3D65F0EA}\ShellFolder\RestrictedAttributes
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{DAF95313-E44D-46AF-BE1B-CBACEA2C3065}\ShellFolder\CallForAttributes
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{98D99750-0B8A-4C59-9151-589053683D73}\ShellFolder\WantsParseDisplayName
  • HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\safer\codeidentifiers\PolicyScope
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\NoControlPanel
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\CPC\Volume\{b9fc273d-d442-11e0-8ee6-806e6f6e6963}\Generation
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{0875DCB6-C686-4243-9432-ADCCF0B9F2D7}\ShellFolder\PinToNameSpaceTree
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\RestrictRun
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Lsa\FipsAlgorithmPolicy\Enabled
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Desktop\NameSpace\{8FD8B88D-30E1-4F25-AC2B-553D3D65F0EA}\SuppressionPolicy
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{BD7A2E7B-21CB-41B2-A086-B309680C6B7E}\ShellFolder\WantsFORDISPLAY
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Cryptography\Providers\Trust\Certificate\{00AAC56B-CD44-11D0-8CC2-00C04FC295EE}\$DLL
  • HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Security\Safety Warning Level
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{59031A47-3F72-44A7-89C5-5595FE6B30EE}\ShellFolder\RestrictedAttributes
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{9343812E-1C37-4A49-A12E-4B2D810D956B}\ShellFolder\HasNavigationEnum
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Connections\SavedLegacySettings
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Cryptography\Defaults\Provider\Microsoft Strong Cryptographic Provider\Type
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{871C5380-42A0-1069-A2EA-08002B30309D}\ShellFolder\CallForAttributes
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{ED228FDF-9EA8-4870-83B1-96B02CFE0D52}\ShellFolder\MapNetDriveVerbs
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{11016101-E366-4D22-BC06-4ADA335C892B}\ShellFolder\QueryForOverlay
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{DAF95313-E44D-46AF-BE1B-CBACEA2C3065}\ShellFolder\HideInWebView
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{B4FB3F98-C1EA-428D-A78A-D1F5659CBA93}\ShellFolder\RestrictedAttributes
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{4336A54D-038B-4685-AB02-99BB52D3FB8B}\ShellFolder\HasNavigationEnum
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\MAIN\SessionMerging
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\ShellFolder\WantsFORPARSING
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\SystemFileAssociations\.exe\BrowseInPlace
  • HKEY_CURRENT_USER\Directory\DocObject
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{ED228FDF-9EA8-4870-83B1-96B02CFE0D52}\ShellFolder\Attributes
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced\SeparateProcess
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{98D99750-0B8A-4C59-9151-589053683D73}\ShellFolder\MapNetDriveVerbs
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\MAIN\FeatureControl\FEATURE_PROTOCOL_LOCKDOWN\*
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{8FD8B88D-30E1-4F25-AC2B-553D3D65F0EA}\ShellFolder\UseDropHandler
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\User Agent\(Default)
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\MAIN\FeatureControl\FEATURE_MIME_HANDLING\*
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{9343812E-1C37-4A49-A12E-4B2D810D956B}\ShellFolder\WantsFORDISPLAY
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{59031A47-3F72-44A7-89C5-5595FE6B30EE}\ShellFolder\WantsUniversalDelegate
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{208D2C60-3AEA-1069-A2D7-08002B30309D}\ShellFolder\HideOnDesktopPerUser
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\NonEnum\{11016101-E366-4D22-BC06-4ADA335C892B}
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Desktop\NameSpace\{9343812e-1c37-4a49-a12e-4b2d810d956b}\SuppressionPolicy
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\ShellFolder\QueryForOverlay
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{871C5380-42A0-1069-A2EA-08002B30309D}\ShellFolder\HideInWebView
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{04731B67-D933-450A-90E6-4ACD2E9408FE}\ShellFolder\HideOnDesktopPerUser
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{89D83576-6BD1-4C86-9454-BEB04E94C819}\ShellFolder\WantsParseDisplayName
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{26EE0668-A00A-44D7-9371-BEB064C98683}\ShellFolder\Attributes
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{4336A54D-038B-4685-AB02-99BB52D3FB8B}\ShellFolder\HideOnDesktopPerUser
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{DAF95313-E44D-46AF-BE1B-CBACEA2C3065}\ShellFolder\QueryForOverlay
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\NonEnum\{8FD8B88D-30E1-4F25-AC2B-553D3D65F0EA}
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{98D99750-0B8A-4C59-9151-589053683D73}\ShellFolder\CallForAttributes
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{ED228FDF-9EA8-4870-83B1-96B02CFE0D52}\ShellFolder\WantsFORDISPLAY
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{ED228FDF-9EA8-4870-83B1-96B02CFE0D52}\ShellFolder\PinToNameSpaceTree
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\ShellFolder\UseDropHandler
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{645FF040-5081-101B-9F08-00AA002F954E}\ShellFolder\QueryForInfoTip
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{5399E694-6CE5-4D6C-8FCE-1D8870FDCBA0}\ShellFolder\QueryForOverlay
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{DAF95313-E44D-46AF-BE1B-CBACEA2C3065}\ShellFolder\NoFileFolderJunction
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\NoInternetIcon
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Scripting.FileSystemObject\CLSID\(Default)
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\DontShowSuperHidden
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{E345F35F-9397-435C-8F95-4E922C26259E}\ShellFolder\CallForAttributes
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{98D99750-0B8A-4C59-9151-589053683D73}\ShellFolder\HideOnDesktopPerUser
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{0D43FE01-F093-11CF-8940-00A0C9054228}\InprocServer32\(Default)
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{138508BC-1E03-49EA-9C8F-EA9E1D05D65D}\ShellFolder\HideOnDesktopPerUser
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{26EE0668-A00A-44D7-9371-BEB064C98683}\ShellFolder\UseDropHandler
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\NoSetFolders
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\ShellFolder\WantsAliasedNotifications
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{72C24DD5-D70A-438B-8A42-98424B88AFB8}\InProcServer32\(Default)
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{4336A54D-038B-4685-AB02-99BB52D3FB8B}\ShellFolder\NoFileFolderJunction
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{04731B67-D933-450A-90E6-4ACD2E9408FE}\ShellFolder\CallForAttributes
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{B196B286-BAB4-101A-B69C-00AA00341D07}\InprocServer32\(Default)
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\ShellFolder\HasNavigationEnum
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Connections\DefaultConnectionSettings
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Desktop\NameSpace\{daf95313-e44d-46af-be1b-cbacea2c3065}\SuppressionPolicy
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{BD7A2E7B-21CB-41B2-A086-B309680C6B7E}\ShellFolder\WantsParseDisplayName
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\1\Flags
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Cryptography\Providers\Trust\Signature\{00AAC56B-CD44-11D0-8CC2-00C04FC295EE}\$DLL
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{8FD8B88D-30E1-4F25-AC2B-553D3D65F0EA}\ShellFolder\WantsParseDisplayName
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Directory\IsShortcut
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{1B3EA5DC-B587-4786-B4EF-BD1DC332AEAE}\FolderTypeID
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{98D99750-0B8A-4C59-9151-589053683D73}\ShellFolder\UseDropHandler
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\crypt32\DebugHeapFlags
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{B4BFCC3A-DB2C-424C-B029-7FE99A87C641}\StreamResource
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{B4FB3F98-C1EA-428D-A78A-D1F5659CBA93}\ShellFolder\Attributes
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Cryptography\Providers\Trust\Initialization\{00AAC56B-CD44-11D0-8CC2-00C04FC295EE}\$DLL
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\AutoDetect
  • HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main\FrameTabWindow
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{11016101-E366-4D22-BC06-4ADA335C892B}\ShellFolder\HideFolderVerbs
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Desktop\NameSpace\{5399E694-6CE5-4D6C-8FCE-1D8870FDCBA0}\SuppressionPolicy
  • HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\safer\codeidentifiers\DefaultLevel
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{E345F35F-9397-435C-8F95-4E922C26259E}\ShellFolder\UseDropHandler
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Desktop\NameSpace\{B4FB3F98-C1EA-428D-A78A-D1F5659CBA93}\SuppressionPolicy
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Cryptography\Providers\Trust\CertCheck\{00AAC56B-CD44-11D0-8CC2-00C04FC295EE}\$Function
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\JScript\CLSID\(Default)
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{89D83576-6BD1-4C86-9454-BEB04E94C819}\ShellFolder\HasNavigationEnum
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{ED228FDF-9EA8-4870-83B1-96B02CFE0D52}\ShellFolder\WantsUniversalDelegate
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{871C5380-42A0-1069-A2EA-08002B30309D}\InProcServer32\LoadWithoutCOM
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{11016101-E366-4D22-BC06-4ADA335C892B}\ShellFolder\HideOnDesktopPerUser
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\NonEnum\{E345F35F-9397-435C-8F95-4E922C26259E}
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\MSXML2.XMLHTTP\CLSID\(Default)
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{26EE0668-A00A-44D7-9371-BEB064C98683}\ShellFolder\NoFileFolderJunction
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\ShellFolder\HideOnDesktopPerUser
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{B4BFCC3A-DB2C-424C-B029-7FE99A87C641}\Security
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{BD7A2E7B-21CB-41B2-A086-B309680C6B7E}\ShellFolder\QueryForInfoTip
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\SESSION MANAGER\SafeProcessSearchMode
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{BD7A2E7B-21CB-41B2-A086-B309680C6B7E}\ShellFolder\HideOnDesktopPerUser
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{031E4825-7B94-4DC3-B131-E946B44C8DD5}\ShellFolder\QueryForOverlay
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{BD7A2E7B-21CB-41B2-A086-B309680C6B7E}\ShellFolder\CallForAttributes
  • HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_LOCALMACHINE_LOCKDOWN\wscript.exe
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{26EE0668-A00A-44D7-9371-BEB064C98683}\ShellFolder\WantsAliasedNotifications
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\SendTimeOut
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Security\DisableSecuritySettingsCheck
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{98D99750-0B8A-4C59-9151-589053683D73}\ShellFolder\WantsFORDISPLAY
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{450D8FBA-AD25-11D0-98A8-0800361B1103}\ShellFolder\PinToNameSpaceTree
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{DAF95313-E44D-46AF-BE1B-CBACEA2C3065}\ShellFolder\Attributes
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{98D99750-0B8A-4C59-9151-589053683D73}\ShellFolder\WantsUniversalDelegate
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{11016101-E366-4D22-BC06-4ADA335C892B}\ShellFolder\WantsFORPARSING
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{871C5380-42A0-1069-A2EA-08002B30309D}\ShellFolder\Attributes
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{1B3EA5DC-B587-4786-B4EF-BD1DC332AEAE}\InitFolderHandler
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{F6D90F16-9C73-11D3-B32E-00C04F990BB4}\InProcServer32\(Default)
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{59031A47-3F72-44A7-89C5-5595FE6B30EE}\ShellFolder\WantsParseDisplayName
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{0875DCB6-C686-4243-9432-ADCCF0B9F2D7}\ShellFolder\HasNavigationEnum
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WScript.Shell\CLSID\(Default)
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{B4BFCC3A-DB2C-424C-B029-7FE99A87C641}\RelativePath
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\MAIN\FeatureControl\FEATURE_LOCALMACHINE_LOCKDOWN\*
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ReceiveTimeOut
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{4336A54D-038B-4685-AB02-99BB52D3FB8B}\ShellFolder\HideInWebView
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{450D8FBA-AD25-11D0-98A8-0800361B1103}\ShellFolder\UseDropHandler
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{450D8FBA-AD25-11D0-98A8-0800361B1103}\ShellFolder\WantsAliasedNotifications
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\NonEnum\{5399E694-6CE5-4D6C-8FCE-1D8870FDCBA0}
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{138508BC-1E03-49EA-9C8F-EA9E1D05D65D}\ShellFolder\QueryForInfoTip
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{04731B67-D933-450A-90E6-4ACD2E9408FE}\ShellFolder\RestrictedAttributes
  • HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_BROWSER_EMULATION\wscript.exe
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\ShellFolder\WantsFORDISPLAY
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{450D8FBA-AD25-11D0-98A8-0800361B1103}\ShellFolder\RestrictedAttributes
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{BD7A2E7B-21CB-41B2-A086-B309680C6B7E}\ShellFolder\WantsAliasedNotifications
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Cryptography\Defaults\Provider\Microsoft Enhanced RSA and AES Cryptographic Provider\Image Path
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{BD7A2E7B-21CB-41B2-A086-B309680C6B7E}\ShellFolder\RestrictedAttributes
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{0D43FE01-F093-11CF-8940-00A0C9054228}\(Default)
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\NoNetCrawling
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{B4BFCC3A-DB2C-424C-B029-7FE99A87C641}\Icon
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{89D83576-6BD1-4C86-9454-BEB04E94C819}\ShellFolder\CallForAttributes
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{B4FB3F98-C1EA-428D-A78A-D1F5659CBA93}\ShellFolder\WantsAliasedNotifications
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{031E4825-7B94-4DC3-B131-E946B44C8DD5}\ShellFolder\WantsFORDISPLAY
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\NonEnum\{0875DCB6-C686-4243-9432-ADCCF0B9F2D7}
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\User Agent\Platform
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{11016101-E366-4D22-BC06-4ADA335C892B}\ShellFolder\PinToNameSpaceTree
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{59031A47-3F72-44A7-89C5-5595FE6B30EE}\ShellFolder\WantsAliasedNotifications
  • HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main\TabProcGrowth
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{26EE0668-A00A-44D7-9371-BEB064C98683}\ShellFolder\RestrictedAttributes
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Desktop\NameSpace\{F3F5824C-AD58-4728-AF59-A1EBE3392799}\SuppressionPolicy
  • HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\CreateUriCacheSize
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{89D83576-6BD1-4C86-9454-BEB04E94C819}\ShellFolder\UseDropHandler
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{645FF040-5081-101B-9F08-00AA002F954E}\ShellFolder\CallForAttributes
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\ShellFolder\Attributes
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Cryptography\Providers\Trust\Message\{00AAC56B-CD44-11D0-8CC2-00C04FC295EE}\$DLL
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{138508BC-1E03-49EA-9C8F-EA9E1D05D65D}\ShellFolder\QueryForOverlay
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{26EE0668-A00A-44D7-9371-BEB064C98683}\ShellFolder\HideInWebView
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{1B3EA5DC-B587-4786-B4EF-BD1DC332AEAE}\LocalizedName
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{26656EAA-54EB-4E6F-8F85-4F0EF901A406}\ProxyStubClsid32\(Default)
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\exefile\shell\open\command\DelegateExecute
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{1B3EA5DC-B587-4786-B4EF-BD1DC332AEAE}\Attributes
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\InheritConsoleHandles
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{871C5380-42A0-1069-A2EA-08002B30309D}\ShellFolder\WantsAliasedNotifications
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{8FD8B88D-30E1-4F25-AC2B-553D3D65F0EA}\ShellFolder\WantsFORDISPLAY
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Cryptography\Providers\Trust\FinalPolicy\{00AAC56B-CD44-11D0-8CC2-00C04FC295EE}\$Function
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{ED228FDF-9EA8-4870-83B1-96B02CFE0D52}\ShellFolder\HideFolderVerbs
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\ShellFolder\PinToNameSpaceTree
  • HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\safer\codeidentifiers\Levels
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\NonEnum\{89D83576-6BD1-4C86-9454-BEB04E94C819}
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{871C5380-42A0-1069-A2EA-08002B30309D}\ShellFolder\PinToNameSpaceTree
  • HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main\AdminTabProcs
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\CreateUriCacheSize
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{645FF040-5081-101B-9F08-00AA002F954E}\ShellFolder\WantsParseDisplayName
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{11016101-E366-4D22-BC06-4ADA335C892B}\ShellFolder\CallForAttributes
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{645FF040-5081-101B-9F08-00AA002F954E}\ShellFolder\HideFolderVerbs
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ProxyOverride
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{5399E694-6CE5-4D6C-8FCE-1D8870FDCBA0}\ShellFolder\NoFileFolderJunction
  • HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\EnablePunycode
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{208D2C60-3AEA-1069-A2D7-08002B30309D}\ShellFolder\Attributes
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\exefile\AlwaysShowExt
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{11016101-E366-4D22-BC06-4ADA335C892B}\ShellFolder\WantsParseDisplayName
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{8FD8B88D-30E1-4F25-AC2B-553D3D65F0EA}\ShellFolder\NoFileFolderJunction
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{ED228FDF-9EA8-4870-83B1-96B02CFE0D52}\ShellFolder\WantsParseDisplayName
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{031E4825-7B94-4DC3-B131-E946B44C8DD5}\ShellFolder\WantsAliasedNotifications
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\exefile\shell\open\NoWorkingDirectory
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{B4FB3F98-C1EA-428D-A78A-D1F5659CBA93}\ShellFolder\WantsFORPARSING
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{9343812E-1C37-4A49-A12E-4B2D810D956B}\ShellFolder\QueryForOverlay
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{04731B67-D933-450A-90E6-4ACD2E9408FE}\ShellFolder\QueryForOverlay
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{F3F5824C-AD58-4728-AF59-A1EBE3392799}\ShellFolder\HideFolderVerbs
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\NonEnum\{F02C1A0D-BE21-4350-88B0-7367FC96EF3C}
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\en-US
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\SystemFileAssociations\.exe\IsShortcut
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{59031A47-3F72-44A7-89C5-5595FE6B30EE}\ShellFolder\WantsFORDISPLAY
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{0875DCB6-C686-4243-9432-ADCCF0B9F2D7}\ShellFolder\WantsAliasedNotifications
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\CPC\Volume\{b9fc273d-d442-11e0-8ee6-806e6f6e6963}\Data
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{E345F35F-9397-435C-8F95-4E922C26259E}\ShellFolder\QueryForInfoTip
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{8FD8B88D-30E1-4F25-AC2B-553D3D65F0EA}\ShellFolder\HasNavigationEnum
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\InheritConsoleHandles
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{89D83576-6BD1-4C86-9454-BEB04E94C819}\ShellFolder\HideInWebView
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{F02C1A0D-BE21-4350-88B0-7367FC96EF3C}\ShellFolder\WantsFORDISPLAY
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{89D83576-6BD1-4C86-9454-BEB04E94C819}\ShellFolder\WantsUniversalDelegate
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Script Host\Settings\UseWINSAFER
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{0D43FE01-F093-11CF-8940-00A0C9054228}\InprocServer32\InprocServer32
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{E345F35F-9397-435C-8F95-4E922C26259E}\ShellFolder\Attributes
  • HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Cryptography\PrivKeyCacheMaxItems
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{F3F5824C-AD58-4728-AF59-A1EBE3392799}\ShellFolder\QueryForInfoTip
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SQMClient\Windows\DisabledSessions\GlobalSession
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{BD7A2E7B-21CB-41B2-A086-B309680C6B7E}\ShellFolder\WantsUniversalDelegate
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\0\1806
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Directory\DocObject
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\CPC\Volume\{b9fc273c-d442-11e0-8ee6-806e6f6e6963}\Generation
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{031E4825-7B94-4DC3-B131-E946B44C8DD5}\ShellFolder\HideFolderVerbs
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{72C24DD5-D70A-438B-8A42-98424B88AFB8}\(Default)
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{ED228FDF-9EA8-4870-83B1-96B02CFE0D52}\ShellFolder\QueryForInfoTip
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SQMClient\Windows\CEIPSampledIn
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{450D8FBA-AD25-11D0-98A8-0800361B1103}\ShellFolder\WantsParseDisplayName
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{450D8FBA-AD25-11D0-98A8-0800361B1103}\ShellFolder\MapNetDriveVerbs
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders\AppData
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{0D43FE01-F093-11CF-8940-00A0C9054228}\ProgID\(Default)
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{1B3EA5DC-B587-4786-B4EF-BD1DC332AEAE}\StreamResource
  • HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\EnablePunycode
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{F02C1A0D-BE21-4350-88B0-7367FC96EF3C}\ShellFolder\CallForAttributes
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Desktop\NameSpace\{031E4825-7B94-4dc3-B131-E946B44C8DD5}\SuppressionPolicy
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{0875DCB6-C686-4243-9432-ADCCF0B9F2D7}\ShellFolder\Attributes
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{5399E694-6CE5-4D6C-8FCE-1D8870FDCBA0}\ShellFolder\MapNetDriveVerbs
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\MAIN\AdminTabProcs
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Script Host\Settings\TrustPolicy
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{ED228FDF-9EA8-4870-83B1-96B02CFE0D52}\ShellFolder\QueryForOverlay
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{0875DCB6-C686-4243-9432-ADCCF0B9F2D7}\ShellFolder\HideOnDesktopPerUser
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\User Agent\Compatible
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\User Agent\Version
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SQMClient\Windows\DisabledProcesses\DA0C75D6
  • HKEY_CURRENT_USER\Directory\BrowseInPlace
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\ShellFolder\WantsUniversalDelegate
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\.exe\(Default)
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{138508BC-1E03-49EA-9C8F-EA9E1D05D65D}\ShellFolder\WantsFORPARSING
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{B4BFCC3A-DB2C-424C-B029-7FE99A87C641}\Name
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\NonEnum\{BD7A2E7B-21CB-41B2-A086-B309680C6B7E}
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{031E4825-7B94-4DC3-B131-E946B44C8DD5}\ShellFolder\PinToNameSpaceTree
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{4336A54D-038B-4685-AB02-99BB52D3FB8B}\ShellFolder\MapNetDriveVerbs
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{4336A54D-038B-4685-AB02-99BB52D3FB8B}\ShellFolder\CallForAttributes
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\NonEnum\{B4FB3F98-C1EA-428D-A78A-D1F5659CBA93}
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced\HideFileExt
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{1B3EA5DC-B587-4786-B4EF-BD1DC332AEAE}\InfoTip
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\.adp\(Default)
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\exefile\shell\open\command\command
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\NonEnum\{26EE0668-A00A-44D7-9371-BEB064C98683}
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{5399E694-6CE5-4D6C-8FCE-1D8870FDCBA0}\ShellFolder\UseDropHandler
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced\NoNetCrawling
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{89D83576-6BD1-4C86-9454-BEB04E94C819}\ShellFolder\WantsAliasedNotifications
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{138508BC-1E03-49EA-9C8F-EA9E1D05D65D}\ShellFolder\PinToNameSpaceTree
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{871C5380-42A0-1069-A2EA-08002B30309D}\ShellFolder\NoFileFolderJunction
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{04731B67-D933-450A-90E6-4ACD2E9408FE}\ShellFolder\UseDropHandler
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{ED228FDF-9EA8-4870-83B1-96B02CFE0D52}\ShellFolder\UseDropHandler
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\GRE_Initialize\DisableMetaFiles
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{11016101-E366-4D22-BC06-4ADA335C892B}\ShellFolder\HasNavigationEnum
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{04731B67-D933-450A-90E6-4ACD2E9408FE}\ShellFolder\WantsUniversalDelegate
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{031E4825-7B94-4DC3-B131-E946B44C8DD5}\ShellFolder\WantsFORPARSING
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{E345F35F-9397-435C-8F95-4E922C26259E}\ShellFolder\HasNavigationEnum
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\SystemFileAssociations\.exe\DocObject
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{208D2C60-3AEA-1069-A2D7-08002B30309D}\ShellFolder\CallForAttributes
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Cryptography\Providers\Trust\Message\{00AAC56B-CD44-11D0-8CC2-00C04FC295EE}\$Function
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{E345F35F-9397-435C-8F95-4E922C26259E}\ShellFolder\NoFileFolderJunction
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Desktop\NameSpace\{F02C1A0D-BE21-4350-88B0-7367FC96EF3C}\SuppressionPolicy
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{871C5380-42A0-1069-A2EA-08002B30309D}\ShellFolder\QueryForOverlay
  • HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\safer\codeidentifiers\TransparentEnabled
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\AllowFileCLSIDJunctions
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\NonEnum\{98D99750-0B8A-4C59-9151-589053683D73}
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{871C5380-42A0-1069-A2EA-08002B30309D}\ShellFolder\UseDropHandler
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{9343812E-1C37-4A49-A12E-4B2D810D956B}\ShellFolder\UseDropHandler
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\NoInternetIcon
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{04731B67-D933-450A-90E6-4ACD2E9408FE}\ShellFolder\WantsFORDISPLAY
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\Language Groups\1
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{ED228FDF-9EA8-4870-83B1-96B02CFE0D52}\ShellFolder\WantsAliasedNotifications
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{B4FB3F98-C1EA-428D-A78A-D1F5659CBA93}\ShellFolder\QueryForInfoTip
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{5399E694-6CE5-4D6C-8FCE-1D8870FDCBA0}\ShellFolder\Attributes
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{F3F5824C-AD58-4728-AF59-A1EBE3392799}\ShellFolder\HideOnDesktopPerUser
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\.cpl\(Default)
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{8FD8B88D-30E1-4F25-AC2B-553D3D65F0EA}\ShellFolder\QueryForInfoTip
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{B4BFCC3A-DB2C-424C-B029-7FE99A87C641}\Stream
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{138508BC-1E03-49EA-9C8F-EA9E1D05D65D}\ShellFolder\WantsParseDisplayName
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{DAF95313-E44D-46AF-BE1B-CBACEA2C3065}\ShellFolder\HasNavigationEnum
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\JSFile\ScriptEngine\(Default)
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\{5F058833-0652-4B15-B7EA-02DD7798ACE8}\WpadDecision
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{450D8FBA-AD25-11D0-98A8-0800361B1103}\ShellFolder\WantsFORPARSING
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{5399E694-6CE5-4D6C-8FCE-1D8870FDCBA0}\ShellFolder\WantsAliasedNotifications
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\.cmd\(Default)
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{F02C1A0D-BE21-4350-88B0-7367FC96EF3C}\ShellFolder\QueryForOverlay
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{F3F5824C-AD58-4728-AF59-A1EBE3392799}\ShellFolder\MapNetDriveVerbs
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{B4BFCC3A-DB2C-424C-B029-7FE99A87C641}\StreamResourceType
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{9343812E-1C37-4A49-A12E-4B2D810D956B}\ShellFolder\HideInWebView
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{8FD8B88D-30E1-4F25-AC2B-553D3D65F0EA}\ShellFolder\PinToNameSpaceTree
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{26EE0668-A00A-44D7-9371-BEB064C98683}\ShellFolder\WantsParseDisplayName
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{031E4825-7B94-4DC3-B131-E946B44C8DD5}\ShellFolder\QueryForInfoTip
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{11016101-E366-4D22-BC06-4ADA335C892B}\ShellFolder\WantsAliasedNotifications
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{ED228FDF-9EA8-4870-83B1-96B02CFE0D52}\ShellFolder\RestrictedAttributes
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{450D8FBA-AD25-11D0-98A8-0800361B1103}\ShellFolder\HideOnDesktopPerUser
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{DAF95313-E44D-46AF-BE1B-CBACEA2C3065}\ShellFolder\HideFolderVerbs
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{B4BFCC3A-DB2C-424C-B029-7FE99A87C641}\Attributes
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\ClassicShell
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{1B3EA5DC-B587-4786-B4EF-BD1DC332AEAE}\Roamable
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{031E4825-7B94-4DC3-B131-E946B44C8DD5}\ShellFolder\RestrictedAttributes
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{0875DCB6-C686-4243-9432-ADCCF0B9F2D7}\ShellFolder\RestrictedAttributes
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\0a-00-27-00-00-00\WpadDecisionTime
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\0a-00-27-00-00-00\WpadDecision
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{031E4825-7B94-4DC3-B131-E946B44C8DD5}\ShellFolder\CallForAttributes
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{BD7A2E7B-21CB-41B2-A086-B309680C6B7E}\ShellFolder\Attributes
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{11016101-E366-4D22-BC06-4ADA335C892B}\ShellFolder\WantsUniversalDelegate
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\SpecialFoldersCacheSize
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{450D8FBA-AD25-11D0-98A8-0800361B1103}\ShellFolder\NoFileFolderJunction
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced\WebView
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{DAF95313-E44D-46AF-BE1B-CBACEA2C3065}\ShellFolder\HideOnDesktopPerUser
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{F02C1A0D-BE21-4350-88B0-7367FC96EF3C}\ShellFolder\WantsAliasedNotifications
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\EnablePunycode
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{26EE0668-A00A-44D7-9371-BEB064C98683}\ShellFolder\MapNetDriveVerbs
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\NoNetCrawling
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Cryptography\Providers\Trust\CertCheck\{00AAC56B-CD44-11D0-8CC2-00C04FC295EE}\$DLL
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{5399E694-6CE5-4D6C-8FCE-1D8870FDCBA0}\ShellFolder\CallForAttributes
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{138508BC-1E03-49EA-9C8F-EA9E1D05D65D}\ShellFolder\NoFileFolderJunction
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Cryptography\MachineGuid
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{F02C1A0D-BE21-4350-88B0-7367FC96EF3C}\ShellFolder\QueryForInfoTip
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AllFilesystemObjects\BrowseInPlace
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{B4FB3F98-C1EA-428D-A78A-D1F5659CBA93}\ShellFolder\WantsUniversalDelegate
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced\IconsOnly
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{F3F5824C-AD58-4728-AF59-A1EBE3392799}\ShellFolder\Attributes
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\NoControlPanel
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{9343812E-1C37-4A49-A12E-4B2D810D956B}\ShellFolder\WantsFORPARSING
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{59031A47-3F72-44A7-89C5-5595FE6B30EE}\ShellFolder\HideInWebView
  • HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Cryptography\PrivateKeyLifetimeSeconds
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\.chm\(Default)
  • HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_BROWSER_EMULATION\*
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{871C5380-42A0-1069-A2EA-08002B30309D}\ShellFolder\RestrictedAttributes
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\3\Flags
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\NonEnum\{59031A47-3F72-44A7-89C5-5595FE6B30EE}
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{F02C1A0D-BE21-4350-88B0-7367FC96EF3C}\ShellFolder\HideInWebView
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{9343812E-1C37-4A49-A12E-4B2D810D956B}\ShellFolder\RestrictedAttributes
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{031E4825-7B94-4DC3-B131-E946B44C8DD5}\ShellFolder\Attributes
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\AutoDetect
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\ShellFolder\HideInWebView
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{645FF040-5081-101B-9F08-00AA002F954E}\ShellFolder\HasNavigationEnum
  • HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\SpecialFoldersCacheSize
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{450D8FBA-AD25-11D0-98A8-0800361B1103}\ShellFolder\Attributes
  • HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\SpecialFoldersCacheSize
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\NonEnum\{871C5380-42A0-1069-A2EA-08002B30309D}
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SQMClient\Windows\CEIPEnable
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{1B3EA5DC-B587-4786-B4EF-BD1DC332AEAE}\StreamResourceType
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{1B3EA5DC-B587-4786-B4EF-BD1DC332AEAE}\Security
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{BD7A2E7B-21CB-41B2-A086-B309680C6B7E}\ShellFolder\NoFileFolderJunction
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\SeparateProcess
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{B4BFCC3A-DB2C-424C-B029-7FE99A87C641}\ParentFolder
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{450D8FBA-AD25-11D0-98A8-0800361B1103}\ShellFolder\CallForAttributes
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Folder\DocObject
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\MAIN\FrameMerging
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{BD7A2E7B-21CB-41B2-A086-B309680C6B7E}\ShellFolder\QueryForOverlay
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{98D99750-0B8A-4C59-9151-589053683D73}\ShellFolder\QueryForInfoTip
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Script Host\Settings\DisplayLogo
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Cryptography\Providers\Trust\Signature\{00AAC56B-CD44-11D0-8CC2-00C04FC295EE}\$Function
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{208D2C60-3AEA-1069-A2D7-08002B30309D}\ShellFolder\PinToNameSpaceTree
  • HKEY_CURRENT_USER\Software\Microsoft\Windows Script Host\Settings\Timeout
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{F3F5824C-AD58-4728-AF59-A1EBE3392799}\ShellFolder\NoFileFolderJunction
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\User Agent\Compatible
  • HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\CreateUriCacheSize
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\NoSimpleStartMenu
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{0875DCB6-C686-4243-9432-ADCCF0B9F2D7}\ShellFolder\WantsUniversalDelegate
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{59031A47-3F72-44A7-89C5-5595FE6B30EE}\ShellFolder\UseDropHandler
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\ClassicShell
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{871C5380-42A0-1069-A2EA-08002B30309D}\ShellFolder\HideFolderVerbs
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{55272A00-42CB-11CE-8135-00AA004BB851}\ProxyStubClsid32\(Default)
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{5399E694-6CE5-4D6C-8FCE-1D8870FDCBA0}\ShellFolder\HasNavigationEnum
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{B4FB3F98-C1EA-428D-A78A-D1F5659CBA93}\ShellFolder\UseDropHandler
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{B4FB3F98-C1EA-428D-A78A-D1F5659CBA93}\ShellFolder\CallForAttributes
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\MAIN\FeatureControl\FEATURE_PROTOCOL_LOCKDOWN\wscript.exe
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{5399E694-6CE5-4D6C-8FCE-1D8870FDCBA0}\ShellFolder\RestrictedAttributes
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{F935DC20-1CF0-11D0-ADB9-00C04FD58A0B}\1.0\0\win64\(Default)
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{F02C1A0D-BE21-4350-88B0-7367FC96EF3C}\ShellFolder\HideOnDesktopPerUser
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Desktop\NameSpace\{04731B67-D933-450a-90E6-4ACD2E9408FE}\SuppressionPolicy
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{59031A47-3F72-44A7-89C5-5595FE6B30EE}\ShellFolder\HasNavigationEnum
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\AllowFileCLSIDJunctions
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{871C5380-42A0-1069-A2EA-08002B30309D}\ShellFolder\HideOnDesktopPerUser
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{1B3EA5DC-B587-4786-B4EF-BD1DC332AEAE}\LocalRedirectOnly
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{F6D90F16-9C73-11D3-B32E-00C04F990BB4}\InProcServer32\InprocServer32
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Desktop\NameSpace\{0875DCB6-C686-4243-9432-ADCCF0B9F2D7}\SuppressionPolicy
  • HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Security\DisableSecuritySettingsCheck
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{98D99750-0B8A-4C59-9151-589053683D73}\ShellFolder\HideInWebView
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\CPC\Volume\{b9fc273c-d442-11e0-8ee6-806e6f6e6963}\Data
  • HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main\FrameMerging
  • HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Security_HKLM_only
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{B4FB3F98-C1EA-428D-A78A-D1F5659CBA93}\ShellFolder\WantsParseDisplayName
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{645FF040-5081-101B-9F08-00AA002F954E}\ShellFolder\HideInWebView
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{E345F35F-9397-435C-8F95-4E922C26259E}\ShellFolder\WantsFORPARSING
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\SpecialFoldersCacheSize
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{ED228FDF-9EA8-4870-83B1-96B02CFE0D52}\ShellFolder\HasNavigationEnum
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{8FD8B88D-30E1-4F25-AC2B-553D3D65F0EA}\ShellFolder\HideOnDesktopPerUser
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{E345F35F-9397-435C-8F95-4E922C26259E}\ShellFolder\WantsParseDisplayName
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{B4FB3F98-C1EA-428D-A78A-D1F5659CBA93}\ShellFolder\HideOnDesktopPerUser
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{11016101-E366-4D22-BC06-4ADA335C892B}\ShellFolder\WantsFORDISPLAY
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{4336A54D-038B-4685-AB02-99BB52D3FB8B}\ShellFolder\UseDropHandler
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{B4FB3F98-C1EA-428D-A78A-D1F5659CBA93}\ShellFolder\PinToNameSpaceTree
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\.asp\(Default)
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\exefile\shell\open\SetWorkingDirectoryFromTarget
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\0a-00-27-00-00-00\WpadDns
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\{5F058833-0652-4B15-B7EA-02DD7798ACE8}\WpadDecisionTime
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Desktop\NameSpace\{26EE0668-A00A-44D7-9371-BEB064C98683}\SuppressionPolicy
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{59031A47-3F72-44A7-89C5-5595FE6B30EE}\ShellFolder\NoFileFolderJunction
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{89D83576-6BD1-4C86-9454-BEB04E94C819}\ShellFolder\HideOnDesktopPerUser
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{9343812E-1C37-4A49-A12E-4B2D810D956B}\ShellFolder\HideOnDesktopPerUser
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\0\1806
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\ShellFolder\HideFolderVerbs
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Desktop\NameSpace\{ED228FDF-9EA8-4870-83B1-96B02CFE0D52}\SuppressionPolicy
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\SystemFileAssociations\.exe\NeverShowExt
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\4\Flags
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{8FD8B88D-30E1-4F25-AC2B-553D3D65F0EA}\ShellFolder\WantsUniversalDelegate
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{871C5380-42A0-1069-A2EA-08002B30309D}\ShellFolder\WantsFORPARSING
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{9343812E-1C37-4A49-A12E-4B2D810D956B}\ShellFolder\NoFileFolderJunction
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced\ShowSuperHidden
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{F3F5824C-AD58-4728-AF59-A1EBE3392799}\ShellFolder\UseDropHandler
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{E345F35F-9397-435C-8F95-4E922C26259E}\ShellFolder\MapNetDriveVerbs
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AllFilesystemObjects\NeverShowExt
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\ShellFolder\CallForAttributes
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Cached\{871C5380-42A0-1069-A2EA-08002B30309D} {000214E6-0000-0000-C000-000000000046} 0xFFFF
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Folder\IsShortcut
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{645FF040-5081-101B-9F08-00AA002F954E}\ShellFolder\QueryForOverlay
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\WpadExpirationDays
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{ED228FDF-9EA8-4870-83B1-96B02CFE0D52}\ShellFolder\HideOnDesktopPerUser
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{04731B67-D933-450A-90E6-4ACD2E9408FE}\ShellFolder\HasNavigationEnum
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Cryptography\Defaults\Provider\Microsoft Strong Cryptographic Provider\Image Path
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{59031A47-3F72-44A7-89C5-5595FE6B30EE}\ShellFolder\HideOnDesktopPerUser
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FolderDescriptions\{1B3EA5DC-B587-4786-B4EF-BD1DC332AEAE}\Stream
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\RestrictRun
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{208D2C60-3AEA-1069-A2D7-08002B30309D}\ShellFolder\WantsAliasedNotifications
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Folder\BrowseInPlace
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{98D99750-0B8A-4C59-9151-589053683D73}\ShellFolder\WantsAliasedNotifications
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{645FF040-5081-101B-9F08-00AA002F954E}\ShellFolder\Attributes
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\exefile\DocObject
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{208D2C60-3AEA-1069-A2D7-08002B30309D}\ShellFolder\WantsFORDISPLAY
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{0875DCB6-C686-4243-9432-ADCCF0B9F2D7}\ShellFolder\UseDropHandler
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\0a-00-27-00-00-00\WpadDetectedUrl
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{9343812E-1C37-4A49-A12E-4B2D810D956B}\ShellFolder\PinToNameSpaceTree
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{4336A54D-038B-4685-AB02-99BB52D3FB8B}\ShellFolder\PinToNameSpaceTree
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WebClient\NetworkProvider\Name
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WebClient\NetworkProvider\ProviderPath
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Rpc\MaxRpcSize
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System\EnableLinkedConnections
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WebClient\NetworkProvider\Class
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\Locale\00000409
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\RDPNP\NetworkProvider\Class
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\LDAP\UseHostnameAsAlias
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WebClient\NetworkProvider\name
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\en-US
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VBoxSF\NetworkProvider\Class
  • HKEY_LOCAL_MACHINE\SYSTEM\Setup\SystemSetupInProgress
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\LDAP\LdapClientIntegrity
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VBoxSF\NetworkProvider\ProviderPath
  • HKEY_LOCAL_MACHINE\SYSTEM\Setup\OOBEInProgress
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\RDPNP\NetworkProvider\Name
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\RDPNP\NetworkProvider\ProviderPath
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\LanmanWorkstation\NetworkProvider\Name
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\FileSystem\Win31FileSystem
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\(Default)
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\LDAP\UseOldHostResolutionOrder
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SQMClient\Windows\CEIPSampledIn
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\NetworkProvider\HwOrder\ProviderOrder
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\Language Groups\1
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SQMClient\Windows\CEIPEnable
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\ExtendedLocale\en-US
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\LanmanWorkstation\NetworkProvider\ProviderPath
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Lsa\AccessProviders\MartaExtension
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\ComputerName\ActiveComputerName\ComputerName
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\RDPNP\NetworkProvider\name
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\LanmanWorkstation\NetworkProvider\name
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\OLE\MaximumAllowedAllocationSize
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\ProductOptions\ProductType
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VBoxSF\NetworkProvider\name
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\LanmanWorkstation\NetworkProvider\Class
Registry Key-Written
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\{5F058833-0652-4B15-B7EA-02DD7798ACE8}\WpadDecisionReason
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\AutoDetect
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\ProxyBypass
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\{5F058833-0652-4B15-B7EA-02DD7798ACE8}\WpadDecision
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\{5F058833-0652-4B15-B7EA-02DD7798ACE8}\WpadDecisionTime
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ProxyEnable
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\IntranetName
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\{5F058833-0652-4B15-B7EA-02DD7798ACE8}\WpadNetworkName
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\0a-00-27-00-00-00\WpadDecision
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\UNCAsIntranet
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Connections\SavedLegacySettings
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\0a-00-27-00-00-00\WpadDecisionReason
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\0a-00-27-00-00-00\WpadDecisionTime
Mutex-Accessed
  • Local\ZonesCacheCounterMutex
  • Local\ZonesLockedCacheCounterMutex

Processes

registry filesystem process services network synchronization

C:\Windows\system32\lsass.exe PID: 456, Parent PID: 352

"C:\Windows\System32\wscript.exe" C:\Users\HARRYD~1\AppData\Local\Temp\~4066KG2TA4Y15BWI3D10KFX7.js PID: 852, Parent PID: 3232

"C:\Windows\System32\rundll32.exe" C:\Users\HARRYD~1\AppData\Local\Temp\SDTQN9~1.ZK,f7 PID: 3076, Parent PID: 852

"C:\Windows\System32\rundll32.exe" C:\Users\HARRYD~1\AppData\Local\Temp\SDTQN9~1.ZK,f7 PID: 1736, Parent PID: 3076

Volatility

Nothing to display.