HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders |
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\IMM |
HKEY_USERS\S-1-5-21-1547161642-507921405-839522115-1004\Software\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Layers |
HKEY_CURRENT_USER\SOFTWARE\Microsoft\CTF |
HKEY_LOCAL_MACHINE\Software\Microsoft\CTF\SystemShared |
HKEY_CURRENT_USER\Control Panel\Desktop |
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer |
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\ |
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer |
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer |
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\System |
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced |
HKEY_CURRENT_USER\Control Panel\Desktop\WindowMetrics |
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\comdlg32 |
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\comdlg32\PlacesBar |
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\FontSubstitutes |
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\ThemeManager |
HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\Tcpip\Parameters |
HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\DnsCache\Parameters |
HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows NT\DnsClient |
HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\System\DNSClient |
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run |
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run |
HKEY_USERS\S-1-5-21-1547161642-507921405-839522115-1004 |
HKEY_USERS\S-1-5-21-1547161642-507921405-839522115-1004\SOFTWARE\Microsoft\Cryptography\Providers\Type 001 |
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Cryptography\Defaults\Provider\Microsoft Strong Cryptographic Provider |
HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\Session Manager |
HKEY_LOCAL_MACHINE\Software\Microsoft\Cryptography\Offload |
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\ProfileList\S-1-5-21-1547161642-507921405-839522115-1004 |
HKEY_USERS\S-1-5-21-1547161642-507921405-839522115-1004\Software\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders |
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\ProfileList |
HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\Session Manager\Environment |
HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\ComputerName |
ActiveComputerName |
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion |
HKEY_USERS\S-1-5-21-1547161642-507921405-839522115-1004\Software\Microsoft\Windows NT\CurrentVersion\Winlogon |
HKEY_USERS\S-1-5-21-1547161642-507921405-839522115-1004\Environment |
HKEY_USERS\S-1-5-21-1547161642-507921405-839522115-1004\Volatile Environment |
HKEY_LOCAL_MACHINE\Software\Microsoft\Cryptography |
HKEY_USERS\S-1-5-21-1547161642-507921405-839522115-1004\Software\Microsoft\Cryptography\UserKeys\J2SE |
HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Cryptography |