HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\IMM |
HKEY_USERS\S-1-5-21-1547161642-507921405-839522115-1004\Software\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Layers |
HKEY_CURRENT_USER\SOFTWARE\Microsoft\CTF |
HKEY_LOCAL_MACHINE\Software\Microsoft\CTF\SystemShared |
HKEY_LOCAL_MACHINE\Software\Microsoft\Ole |
HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\ComputerName |
ActiveComputerName |
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders |
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders |
HKEY_LOCAL_MACHINE\Software\Microsoft\COM3 |
HKEY_USERS\S-1-5-21-1547161642-507921405-839522115-1004_Classes |
HKEY_LOCAL_MACHINE\Software\Classes |
\REGISTRY\USER |
HKEY_LOCAL_MACHINE\Software\Classes\CLSID |
CLSID\{148BD52A-A2AB-11CE-B11F-00AA00530503} |
CLSID\{148BD52A-A2AB-11CE-B11F-00AA00530503}\TreatAs |
\CLSID\{148BD52A-A2AB-11CE-B11F-00AA00530503} |
\CLSID\{148BD52A-A2AB-11CE-B11F-00AA00530503}\InprocServer32 |
\CLSID\{148BD52A-A2AB-11CE-B11F-00AA00530503}\InprocServerX86 |
\CLSID\{148BD52A-A2AB-11CE-B11F-00AA00530503}\LocalServer32 |
\CLSID\{148BD52A-A2AB-11CE-B11F-00AA00530503}\InprocHandler32 |
\CLSID\{148BD52A-A2AB-11CE-B11F-00AA00530503}\InprocHandlerX86 |
\CLSID\{148BD52A-A2AB-11CE-B11F-00AA00530503}\LocalServer |
HKEY_CLASSES_ROOT\CLSID\{148BD52A-A2AB-11CE-B11F-00AA00530503} |
HKEY_CLASSES_ROOT\CLSID\{148BD52A-A2AB-11CE-B11F-00AA00530503}\TreatAs |
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer |
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer |
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellCompatibility\Objects\{20D04FE0-3AEA-1069-A2D8-08002B30309D} |
HKEY_CLASSES_ROOT\CLSID\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\InProcServer32 |
HKEY_CLASSES_ROOT\Drive\shellex\FolderExtensions |
HKEY_CLASSES_ROOT\Drive\shellex\FolderExtensions\{fbeb8a05-beee-4442-804e-409d6c4515e9} |
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings |
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\WinHttp |
HKEY_LOCAL_MACHINE\Software\Microsoft\windows\CurrentVersion\Internet Settings\Connections |
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\WinHttp\UnsafeSslApps |
CLSID\{F5078F32-C551-11D3-89B9-0000F81FE221} |
CLSID\{F5078F32-C551-11D3-89B9-0000F81FE221}\TreatAs |
\CLSID\{F5078F32-C551-11D3-89B9-0000F81FE221} |
\CLSID\{F5078F32-C551-11D3-89B9-0000F81FE221}\InprocServer32 |
\CLSID\{F5078F32-C551-11D3-89B9-0000F81FE221}\InprocServerX86 |
\CLSID\{F5078F32-C551-11D3-89B9-0000F81FE221}\LocalServer32 |
\CLSID\{F5078F32-C551-11D3-89B9-0000F81FE221}\InprocHandler32 |
\CLSID\{F5078F32-C551-11D3-89B9-0000F81FE221}\InprocHandlerX86 |
\CLSID\{F5078F32-C551-11D3-89B9-0000F81FE221}\LocalServer |
HKEY_CLASSES_ROOT\CLSID\{F5078F32-C551-11D3-89B9-0000F81FE221} |
HKEY_CLASSES_ROOT\CLSID\{F5078F32-C551-11D3-89B9-0000F81FE221}\TreatAs |
HKEY_USERS\S-1-5-21-1547161642-507921405-839522115-1004 |
HKEY_USERS\S-1-5-21-1547161642-507921405-839522115-1004\SOFTWARE\Microsoft\Cryptography\Providers\Type 024 |
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Cryptography\Defaults\Provider\Microsoft Enhanced RSA and AES Cryptographic Provider (Prototype) |
HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\Session Manager |
HKEY_LOCAL_MACHINE\Software\Microsoft\Cryptography |
HKEY_LOCAL_MACHINE\Software\Microsoft\Cryptography\Offload |
HKEY_LOCAL_MACHINE\Software\Microsoft\Cryptography\DESHashSessionKeyBackward |
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{B83AF3AB-4FED-45D1-A8B8-9E66F3411813} |