HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders |
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\IMM |
HKEY_USERS\S-1-5-21-1547161642-507921405-839522115-1004\Software\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Layers |
HKEY_CURRENT_USER\SOFTWARE\Microsoft\CTF |
HKEY_LOCAL_MACHINE\Software\Microsoft\CTF\SystemShared |
HKEY_CURRENT_USER\Control Panel\Desktop |
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer |
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\ |
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer |
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer |
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\System |
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced |
HKEY_CURRENT_USER\Control Panel\Desktop\WindowMetrics |
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\comdlg32 |
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\comdlg32\PlacesBar |
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\FontSubstitutes |
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\ThemeManager |
HKEY_USERS\S-1-5-21-1547161642-507921405-839522115-1004 |
HKEY_USERS\S-1-5-21-1547161642-507921405-839522115-1004\SOFTWARE\Microsoft\Cryptography\Providers\Type 001 |
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Cryptography\Defaults\Provider\Microsoft Strong Cryptographic Provider |
HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\Session Manager |
HKEY_LOCAL_MACHINE\Software\Microsoft\Cryptography\Offload |
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\ProfileList\S-1-5-21-1547161642-507921405-839522115-1004 |
HKEY_USERS\S-1-5-21-1547161642-507921405-839522115-1004\Software\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders |
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\ProfileList |
HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\Session Manager\Environment |
HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\ComputerName |
ActiveComputerName |
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion |
HKEY_USERS\S-1-5-21-1547161642-507921405-839522115-1004\Software\Microsoft\Windows NT\CurrentVersion\Winlogon |
HKEY_USERS\S-1-5-21-1547161642-507921405-839522115-1004\Environment |
HKEY_USERS\S-1-5-21-1547161642-507921405-839522115-1004\Volatile Environment |
HKEY_LOCAL_MACHINE\Software\Microsoft\Cryptography |
HKEY_USERS\S-1-5-21-1547161642-507921405-839522115-1004\Software\Microsoft\Cryptography\UserKeys\J2SE |
HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Cryptography |
HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\Tcpip\Parameters |
HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\DnsCache\Parameters |
HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows NT\DnsClient |
HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\System\DNSClient |
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run |
HKEY_LOCAL_MACHINE\Software\Microsoft\Ole |
HKEY_LOCAL_MACHINE\Software\Microsoft\COM3 |
HKEY_USERS\S-1-5-21-1547161642-507921405-839522115-1004_Classes |
HKEY_LOCAL_MACHINE\Software\Classes |
\REGISTRY\USER |
HKEY_LOCAL_MACHINE\Software\Classes\CLSID |
CLSID\{4590F811-1D3A-11D0-891F-00AA004B2E24} |
CLSID\{4590F811-1D3A-11D0-891F-00AA004B2E24}\TreatAs |
\CLSID\{4590F811-1D3A-11D0-891F-00AA004B2E24} |
\CLSID\{4590F811-1D3A-11D0-891F-00AA004B2E24}\InprocServer32 |
\CLSID\{4590F811-1D3A-11D0-891F-00AA004B2E24}\InprocServerX86 |
\CLSID\{4590F811-1D3A-11D0-891F-00AA004B2E24}\LocalServer32 |
\CLSID\{4590F811-1D3A-11D0-891F-00AA004B2E24}\InprocHandler32 |
\CLSID\{4590F811-1D3A-11D0-891F-00AA004B2E24}\InprocHandlerX86 |
\CLSID\{4590F811-1D3A-11D0-891F-00AA004B2E24}\LocalServer |
HKEY_CLASSES_ROOT\CLSID\{4590F811-1D3A-11D0-891F-00AA004B2E24} |
HKEY_CLASSES_ROOT\CLSID\{4590F811-1D3A-11D0-891F-00AA004B2E24}\TreatAs |
HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\System\DNSclient |
CLSID\{8BC3F05E-D86B-11D0-A075-00C04FB68820} |
CLSID\{8BC3F05E-D86B-11D0-A075-00C04FB68820}\TreatAs |
\CLSID\{8BC3F05E-D86B-11D0-A075-00C04FB68820} |
\CLSID\{8BC3F05E-D86B-11D0-A075-00C04FB68820}\InprocServer32 |
\CLSID\{8BC3F05E-D86B-11D0-A075-00C04FB68820}\InprocServerX86 |
\CLSID\{8BC3F05E-D86B-11D0-A075-00C04FB68820}\LocalServer32 |
\CLSID\{8BC3F05E-D86B-11D0-A075-00C04FB68820}\InprocHandler32 |
\CLSID\{8BC3F05E-D86B-11D0-A075-00C04FB68820}\InprocHandlerX86 |
\CLSID\{8BC3F05E-D86B-11D0-A075-00C04FB68820}\LocalServer |
\AppID\{8BC3F05E-D86B-11D0-A075-00C04FB68820} |
HKEY_CLASSES_ROOT\Interface\{F309AD18-D86A-11D0-A075-00C04FB68820} |
HKEY_CLASSES_ROOT\Interface\{F309AD18-D86A-11D0-A075-00C04FB68820}\ProxyStubClsid32 |
CLSID\{7C857801-7381-11CF-884D-00AA004B2E24} |
CLSID\{7C857801-7381-11CF-884D-00AA004B2E24}\TreatAs |
\CLSID\{7C857801-7381-11CF-884D-00AA004B2E24} |
\CLSID\{7C857801-7381-11CF-884D-00AA004B2E24}\InprocServer32 |
\CLSID\{7C857801-7381-11CF-884D-00AA004B2E24}\InprocServerX86 |
\CLSID\{7C857801-7381-11CF-884D-00AA004B2E24}\LocalServer32 |
\CLSID\{7C857801-7381-11CF-884D-00AA004B2E24}\InprocHandler32 |
\CLSID\{7C857801-7381-11CF-884D-00AA004B2E24}\InprocHandlerX86 |
\CLSID\{7C857801-7381-11CF-884D-00AA004B2E24}\LocalServer |
HKEY_CLASSES_ROOT\CLSID\{7C857801-7381-11CF-884D-00AA004B2E24} |
HKEY_CLASSES_ROOT\CLSID\{7C857801-7381-11CF-884D-00AA004B2E24}\TreatAs |
HKEY_CLASSES_ROOT\Interface\{D4781CD6-E5D3-44DF-AD94-930EFE48A887} |
HKEY_CLASSES_ROOT\Interface\{D4781CD6-E5D3-44DF-AD94-930EFE48A887}\ProxyStubClsid32 |
HKEY_CLASSES_ROOT\Interface\{9556DC99-828C-11CF-A37E-00AA003240C7} |
HKEY_CLASSES_ROOT\Interface\{9556DC99-828C-11CF-A37E-00AA003240C7}\ProxyStubClsid32 |
CLSID\{D68AF00A-29CB-43FA-8504-CE99A996D9EA} |
CLSID\{D68AF00A-29CB-43FA-8504-CE99A996D9EA}\TreatAs |
\CLSID\{D68AF00A-29CB-43FA-8504-CE99A996D9EA} |
\CLSID\{D68AF00A-29CB-43FA-8504-CE99A996D9EA}\InprocServer32 |
\CLSID\{D68AF00A-29CB-43FA-8504-CE99A996D9EA}\InprocServerX86 |
\CLSID\{D68AF00A-29CB-43FA-8504-CE99A996D9EA}\LocalServer32 |
\CLSID\{D68AF00A-29CB-43FA-8504-CE99A996D9EA}\InprocHandler32 |
\CLSID\{D68AF00A-29CB-43FA-8504-CE99A996D9EA}\InprocHandlerX86 |
\CLSID\{D68AF00A-29CB-43FA-8504-CE99A996D9EA}\LocalServer |
HKEY_CLASSES_ROOT\CLSID\{D68AF00A-29CB-43FA-8504-CE99A996D9EA} |
HKEY_CLASSES_ROOT\CLSID\{D68AF00A-29CB-43FA-8504-CE99A996D9EA}\TreatAs |
HKEY_CLASSES_ROOT\Interface\{027947E1-D731-11CE-A357-000000000001} |
HKEY_CLASSES_ROOT\Interface\{027947E1-D731-11CE-A357-000000000001}\ProxyStubClsid32 |
CLSID\{1B1CAD8C-2DAB-11D2-B604-00104B703EFD} |
CLSID\{1B1CAD8C-2DAB-11D2-B604-00104B703EFD}\TreatAs |
\CLSID\{1B1CAD8C-2DAB-11D2-B604-00104B703EFD} |
\CLSID\{1B1CAD8C-2DAB-11D2-B604-00104B703EFD}\InprocServer32 |
\CLSID\{1B1CAD8C-2DAB-11D2-B604-00104B703EFD}\InprocServerX86 |
\CLSID\{1B1CAD8C-2DAB-11D2-B604-00104B703EFD}\LocalServer32 |
\CLSID\{1B1CAD8C-2DAB-11D2-B604-00104B703EFD}\InprocHandler32 |
\CLSID\{1B1CAD8C-2DAB-11D2-B604-00104B703EFD}\InprocHandlerX86 |
\CLSID\{1B1CAD8C-2DAB-11D2-B604-00104B703EFD}\LocalServer |
HKEY_CLASSES_ROOT\CLSID\{1B1CAD8C-2DAB-11D2-B604-00104B703EFD} |
HKEY_CLASSES_ROOT\CLSID\{1B1CAD8C-2DAB-11D2-B604-00104B703EFD}\TreatAs |
HKEY_CLASSES_ROOT\Interface\{1C1C45EE-4395-11D2-B60B-00104B703EFD} |
HKEY_CLASSES_ROOT\Interface\{1C1C45EE-4395-11D2-B60B-00104B703EFD}\ProxyStubClsid32 |
HKEY_CLASSES_ROOT\Interface\{423EC01E-2E35-11D2-B604-00104B703EFD} |
HKEY_CLASSES_ROOT\Interface\{423EC01E-2E35-11D2-B604-00104B703EFD}\ProxyStubClsid32 |
CLSID\{4590F812-1D3A-11D0-891F-00AA004B2E24} |
CLSID\{4590F812-1D3A-11D0-891F-00AA004B2E24}\TreatAs |
\CLSID\{4590F812-1D3A-11D0-891F-00AA004B2E24} |
\CLSID\{4590F812-1D3A-11D0-891F-00AA004B2E24}\InprocServer32 |
\CLSID\{4590F812-1D3A-11D0-891F-00AA004B2E24}\InprocServerX86 |
\CLSID\{4590F812-1D3A-11D0-891F-00AA004B2E24}\LocalServer32 |
\CLSID\{4590F812-1D3A-11D0-891F-00AA004B2E24}\InprocHandler32 |
\CLSID\{4590F812-1D3A-11D0-891F-00AA004B2E24}\InprocHandlerX86 |
\CLSID\{4590F812-1D3A-11D0-891F-00AA004B2E24}\LocalServer |
HKEY_CLASSES_ROOT\CLSID\{4590F812-1D3A-11D0-891F-00AA004B2E24} |
HKEY_CLASSES_ROOT\CLSID\{4590F812-1D3A-11D0-891F-00AA004B2E24}\TreatAs |
HKEY_LOCAL_MACHINE\Software\Microsoft\WBEM\CIMOM |