分析任务

分析类型 虚拟机标签 开始时间 结束时间 持续时间
文件 (Windows) win7-sp1-x64-hpdapp01-1 2019-06-20 03:43:59 2019-06-20 03:46:58 179 秒

魔盾分数

10.0

危险的

文件详细信息

文件名 CF-灵动透视自瞄.exe
文件大小 8224545 字节
文件类型 PE32 executable (GUI) Intel 80386, for MS Windows, UPX compressed
MD5 a8a130d235bd58e2115618ec2f85d1b6
SHA1 fef34b63d9224edbc30313479fce244bbd0ead33
SHA256 4c9c935e0a860e590e22a6d3cbe8d96cae5272f2e4e7bb773b720786eccc12ef
SHA512 a2bb0d23906d315ea05cf1f4cf0859188c7abaed2c6f0b5254f80d7467fce6c4bba8ec522230828653a58d16043f940ba4134e52a0546cdf1c85a6b1e635fbab
CRC32 60D61F0A
Ssdeep 196608:qyk7Rw7sSulxiUbejxqzdcVjllvvjiCsWOnaUO52qfNgH/b:KisSulTbsAhIjfjiRnaUQ2qfNgD
Yara
  • Detected 32bit PE signature
  • Detected Entropy signature
  • Detected Overlay signature
  • Detected Rich Signature
  • Create a new process
  • Detects malicious behaviors from a small size app
  • Detected no presence of any attachment
  • Detected no presence of any image
  • Detected no presence of any url
  • Detected UPX. Commonly used by RAT!
样本下载 提交误报

特征低危险等级 中危险等级 高危险等级

创建RWX内存
魔盾wping.org IP地址信誉系统
Greylist: 85.17.167.196
二进制文件可能包含加密或压缩数据
section: name: UPX1, entropy: 7.88, characteristics: IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_EXECUTE|IMAGE_SCN_MEM_READ|IMAGE_SCN_MEM_WRITE, raw_size: 0x00009000, virtual_size: 0x00009000
section: name: .rsrc, entropy: 7.89, characteristics: IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_EXECUTE|IMAGE_SCN_MEM_READ|IMAGE_SCN_MEM_WRITE, raw_size: 0x00015000, virtual_size: 0x00015000
样本投放可执行文件到临时目录
魔盾安全Yara规则检测结果 - 安全告警
Informational: Detected Entropy signature
Informational: Detected Overlay signature
Informational: Detected Rich Signature
Warning: Create a new process
Critical: Detects malicious behaviors from a small size app
Informational: Detected no presence of any attachment
Warning: possible_includes_base64_packed_functions
Informational: Detected no presence of any image
Informational: Detected no presence of any url
Warning: Detected UPX. Commonly used by RAT!
可执行文件被使用UPX压缩
section: name: UPX0, entropy: 0.00, characteristics: IMAGE_SCN_CNT_UNINITIALIZED_DATA|IMAGE_SCN_MEM_EXECUTE|IMAGE_SCN_MEM_READ|IMAGE_SCN_MEM_WRITE, raw_size: 0x00000000, virtual_size: 0x0000f000
在一个远程进程中注入代码(CreateRemoteThread)
将自己装载到Windows开机自动启动项目
file: C:\Windows\system.ini
对一些具体的运行中的进程呈现出兴趣
process: iexplore.exe
通过进程尝试长时间延迟分析任务
Process: CF-__________________.exe tried to sleep 649 seconds, actually delayed analysis time by 0 seconds
对本地防火墙的策略和设置进行操作
尝试禁止UAC
尝试修改Windows桌面进程以防止隐藏文件被显示
尝试更改或禁止安全中心报警

运行截图

没有可用的屏幕截图

访问主机纪录 (可点击查询WPING实时安全评级)

直接 IP 安全评级 地理位置
201.24.159.221 巴西
85.17.167.196 荷兰
88.248.141.201 土耳其

域名解析 (可点击查询WPING实时安全评级)

无域名信息.


摘要

C:\Windows\Globalization\Sorting\sortdefault.nls
C:\Users\test\AppData\Local\Temp\00386795_Rar
C:\Users\test\AppData\Local\Temp\CF-__________________.exe
C:\Users\test\AppData\Local\Temp\00386795_Rar\CF-__________________.exe
C:\Users\test\AppData\Local\Temp\MPR.DLL
C:\Windows\System32\mpr.dll
C:\Windows\system.ini
C:\Users\test\AppData\Local\Temp\sfc.DLL
C:\Windows\System32\sfc.dll
C:\Users\test\AppData\Local\Temp\*
\Device\KsecDD
C:\Windows\SysWOW64\shell32.dll
C:\
C:\Users
C:
C:\Users\test
C:\Users\test\AppData
C:\Users\test\AppData\Local
C:\Users\test\AppData\Local\Temp
C:\Users\test\AppData\Local\Temp\Temp
C:\Users\test\AppData\Local\Temp\Temp\CF\xe7\x81\xb5\xe5\x8a\xa8\xe9\x80\x8f\xe8\xa7\x86\xe8\x87\xaa\xe7\x9e\x84.exe
C:\Users\test\AppData\Local\Microsoft\Windows\Caches
C:\Users\test\AppData\Local\Microsoft\Windows\Caches\cversions.1.db
C:\Users\test\AppData\Local\Temp\Temp\1wf3xon57hkk4hjw_007.exe
C:\Users\test\AppData\Local\Microsoft\Windows\Caches\{AFBF9F1A-8EE8-4C77-AF34-C647E37CA0D9}.1.ver0x0000000000000052.db
C:\Users\desktop.ini
\??\MountPointManager
C:\Windows\SysWOW64\propsys.dll
C:\Windows\sysnative\propsys.dll
C:\Windows\System32\ntshrui.dll
C:\Windows\AppPatch\sysmain.sdb
C:\Windows\System32\
C:\Windows\SysWOW64\ntshrui.dll
C:\Windows
C:\Windows\System32
C:\Windows\System32\*.*
C:\Windows\Globalization\Sorting\sortdefault.nls
C:\Users\test\AppData\Local\Temp\CF-__________________.exe
C:\Users\test\AppData\Local\Temp\00386795_Rar\CF-__________________.exe
C:\Windows\System32\mpr.dll
C:\Windows\system.ini
C:\Windows\System32\sfc.dll
\Device\KsecDD
C:\Windows\SysWOW64\shell32.dll
C:\
C:\Users\test\AppData\Local\Microsoft\Windows\Caches\cversions.1.db
C:\Users\test\AppData\Local\Microsoft\Windows\Caches\{AFBF9F1A-8EE8-4C77-AF34-C647E37CA0D9}.1.ver0x0000000000000052.db
C:\Users\desktop.ini
C:\Users
C:\Users\test
C:\Users\test\AppData
C:\Users\test\AppData\Local
C:\Users\test\AppData\Local\Temp
C:\Users\test\AppData\Local\Temp\00386795_Rar
C:\Windows\System32\ntshrui.dll
C:\Windows\AppPatch\sysmain.sdb
C:\Windows\System32\
C:\Users\test\AppData\Local\Temp\00386795_Rar\CF-__________________.exe
C:\Windows\system.ini
C:\Users\test\AppData\Local\Temp\Temp\CF\xe7\x81\xb5\xe5\x8a\xa8\xe9\x80\x8f\xe8\xa7\x86\xe8\x87\xaa\xe7\x9e\x84.exe
C:\Users\test\AppData\Local\Temp\Temp\1wf3xon57hkk4hjw_007.exe
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Hidden
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Security Center\AntiVirusOverride
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Security Center\AntiVirusDisableNotify
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Security Center\FirewallDisableNotify
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Security Center\FirewallOverride
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Security Center\UpdatesDisableNotify
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Security Center\UacDisableNotify
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Security Center\Svc\AntiVirusOverride
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Security Center\Svc\AntiVirusDisableNotify
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Security Center\Svc\FirewallDisableNotify
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Security Center\Svc\FirewallOverride
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Security Center\Svc\UpdatesDisableNotify
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Security Center\Svc\UacDisableNotify
HKEY_LOCAL_MACHINE\system\CurrentControlSet\control\NetworkProvider\HwOrder
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\GlobalUserOffline
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\policies\system
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System\EnableLUA
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\EnableFirewall
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\DoNotAllowExceptions
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\DisableNotifications
HKEY_CURRENT_USER\Software\Abfx\-1001785200
HKEY_CURRENT_USER\Software\Abfx\-1001785200\1953719668
HKEY_CURRENT_USER\Software\Abfx\-1001785200\-387527960
HKEY_CURRENT_USER\Software\Abfx\-1001785200\1566191708
HKEY_CURRENT_USER\Software\Abfx\-1001785200\-775055920
HKEY_CURRENT_USER\Software\Abfx\-1001785200\1178663748
HKEY_CURRENT_USER\Software\Abfx\-1001785200\-1162583880
HKEY_CURRENT_USER\Software\Abfx\-1001785200\791135788
HKEY_CURRENT_USER\Software\Abfx
HKEY_CURRENT_USER\Software\Abfx\t1_0
HKEY_CURRENT_USER\Software\Abfx\t2_0
HKEY_CURRENT_USER\Software\Abfx\t3_0
HKEY_CURRENT_USER\Software\Abfx\t4_0
HKEY_CURRENT_USER\Software\Abfx\t1_1
HKEY_CURRENT_USER\Software\Abfx\t2_1
HKEY_CURRENT_USER\Software\Abfx\t3_1
HKEY_CURRENT_USER\Software\Abfx\t4_1
HKEY_CURRENT_USER\Software\Abfx\t1_2
HKEY_CURRENT_USER\Software\Abfx\t2_2
HKEY_CURRENT_USER\Software\Abfx\t3_2
HKEY_CURRENT_USER\Software\Abfx\t4_2
HKEY_CURRENT_USER\Software\Abfx\t1_3
HKEY_CURRENT_USER\Software\Abfx\t2_3
HKEY_CURRENT_USER\Software\Abfx\t3_3
HKEY_CURRENT_USER\Software\Abfx\t4_3
HKEY_CURRENT_USER\Software\Abfx\t1_4
HKEY_CURRENT_USER\Software\Abfx\t2_4
HKEY_CURRENT_USER\Software\Abfx\t3_4
HKEY_CURRENT_USER\Software\Abfx\t4_4
HKEY_CURRENT_USER\Software\Abfx\t1_5
HKEY_CURRENT_USER\Software\Abfx\t2_5
HKEY_CURRENT_USER\Software\Abfx\t3_5
HKEY_CURRENT_USER\Software\Abfx\t4_5
HKEY_CURRENT_USER\Software\Abfx\t1_6
HKEY_CURRENT_USER\Software\Abfx\t2_6
HKEY_CURRENT_USER\Software\Abfx\t3_6
HKEY_CURRENT_USER\Software\Abfx\t4_6
HKEY_CURRENT_USER\Software\Abfx\t1_7
HKEY_CURRENT_USER\Software\Abfx\t2_7
HKEY_CURRENT_USER\Software\Abfx\t3_7
HKEY_CURRENT_USER\Software\Abfx\t4_7
HKEY_CURRENT_USER\Software\Abfx\t1_8
HKEY_CURRENT_USER\Software\Abfx\t2_8
HKEY_CURRENT_USER\Software\Abfx\t3_8
HKEY_CURRENT_USER\Software\Abfx\t4_8
HKEY_CURRENT_USER\Software\Abfx\t1_9
HKEY_CURRENT_USER\Software\Abfx\t2_9
HKEY_CURRENT_USER\Software\Abfx\t3_9
HKEY_CURRENT_USER\Software\Abfx\t4_9
HKEY_CURRENT_USER\Software\Abfx\t1_10
HKEY_CURRENT_USER\Software\Abfx\t2_10
HKEY_CURRENT_USER\Software\Abfx\t3_10
HKEY_CURRENT_USER\Software\Abfx\t4_10
HKEY_CURRENT_USER\Software\Abfx\t1_11
HKEY_CURRENT_USER\Software\Abfx\t2_11
HKEY_CURRENT_USER\Software\Abfx\t3_11
HKEY_CURRENT_USER\Software\Abfx\t4_11
HKEY_CURRENT_USER\Software\Abfx\t1_12
HKEY_CURRENT_USER\Software\Abfx\t2_12
HKEY_CURRENT_USER\Software\Abfx\t3_12
HKEY_CURRENT_USER\Software\Abfx\t4_12
HKEY_CURRENT_USER\Software\Abfx\t1_13
HKEY_CURRENT_USER\Software\Abfx\t2_13
HKEY_CURRENT_USER\Software\Abfx\t3_13
HKEY_CURRENT_USER\Software\Abfx\t4_13
HKEY_CURRENT_USER\Software\Abfx\t1_14
HKEY_CURRENT_USER\Software\Abfx\t2_14
HKEY_CURRENT_USER\Software\Abfx\t3_14
HKEY_CURRENT_USER\Software\Abfx\t4_14
HKEY_CURRENT_USER\Software\Abfx\t1_15
HKEY_CURRENT_USER\Software\Abfx\t2_15
HKEY_CURRENT_USER\Software\Abfx\t3_15
HKEY_CURRENT_USER\Software\Abfx\t4_15
HKEY_CURRENT_USER\Software\Abfx\t1_16
HKEY_CURRENT_USER\Software\Abfx\t2_16
HKEY_CURRENT_USER\Software\Abfx\t3_16
HKEY_CURRENT_USER\Software\Abfx\t4_16
HKEY_CURRENT_USER\Software\Abfx\t1_17
HKEY_CURRENT_USER\Software\Abfx\t2_17
HKEY_CURRENT_USER\Software\Abfx\t3_17
HKEY_CURRENT_USER\Software\Abfx\t4_17
HKEY_CURRENT_USER\Software\Abfx\t1_18
HKEY_CURRENT_USER\Software\Abfx\t2_18
HKEY_CURRENT_USER\Software\Abfx\t3_18
HKEY_CURRENT_USER\Software\Abfx\t4_18
HKEY_CURRENT_USER\Software\Abfx\t1_19
HKEY_CURRENT_USER\Software\Abfx\t2_19
HKEY_CURRENT_USER\Software\Abfx\t3_19
HKEY_CURRENT_USER\Software\Abfx\t4_19
HKEY_CURRENT_USER\Software\Abfx\t1_20
HKEY_CURRENT_USER\Software\Abfx\t2_20
HKEY_CURRENT_USER\Software\Abfx\t3_20
HKEY_CURRENT_USER\Software\Abfx\t4_20
HKEY_CURRENT_USER\Software\Abfx\t1_21
HKEY_CURRENT_USER\Software\Abfx\t2_21
HKEY_CURRENT_USER\Software\Abfx\t3_21
HKEY_CURRENT_USER\Software\Abfx\t4_21
HKEY_CURRENT_USER\Software\Abfx\t1_22
HKEY_CURRENT_USER\Software\Abfx\t2_22
HKEY_CURRENT_USER\Software\Abfx\t3_22
HKEY_CURRENT_USER\Software\Abfx\t4_22
HKEY_CURRENT_USER\Software\Abfx\t1_23
HKEY_CURRENT_USER\Software\Abfx\t2_23
HKEY_CURRENT_USER\Software\Abfx\t3_23
HKEY_CURRENT_USER\Software\Abfx\t4_23
HKEY_CURRENT_USER\Software\Abfx\t1_24
HKEY_CURRENT_USER\Software\Abfx\t2_24
HKEY_CURRENT_USER\Software\Abfx\t3_24
HKEY_CURRENT_USER\Software\Abfx\t4_24
HKEY_CURRENT_USER\Software\Abfx\t1_25
HKEY_CURRENT_USER\Software\Abfx\t2_25
HKEY_CURRENT_USER\Software\Abfx\t3_25
HKEY_CURRENT_USER\Software\Abfx\t4_25
HKEY_CURRENT_USER\Software\Abfx\t1_26
HKEY_CURRENT_USER\Software\Abfx\t2_26
HKEY_CURRENT_USER\Software\Abfx\t3_26
HKEY_CURRENT_USER\Software\Abfx\t4_26
HKEY_CURRENT_USER\Software\Abfx\t1_27
HKEY_CURRENT_USER\Software\Abfx\t2_27
HKEY_CURRENT_USER\Software\Abfx\t3_27
HKEY_CURRENT_USER\Software\Abfx\t4_27
HKEY_CURRENT_USER\Software\Abfx\t1_28
HKEY_CURRENT_USER\Software\Abfx\t2_28
HKEY_CURRENT_USER\Software\Abfx\t3_28
HKEY_CURRENT_USER\Software\Abfx\t4_28
HKEY_CURRENT_USER\Software\Abfx\t1_29
HKEY_CURRENT_USER\Software\Abfx\t2_29
HKEY_CURRENT_USER\Software\Abfx\t3_29
HKEY_CURRENT_USER\Software\Abfx\t4_29
HKEY_CURRENT_USER\Software\Abfx\t1_30
HKEY_CURRENT_USER\Software\Abfx\t2_30
HKEY_CURRENT_USER\Software\Abfx\t3_30
HKEY_CURRENT_USER\Software\Abfx\t4_30
HKEY_CURRENT_USER\Software\Abfx\t1_31
HKEY_CURRENT_USER\Software\Abfx\t2_31
HKEY_CURRENT_USER\Software\Abfx\t3_31
HKEY_CURRENT_USER\Software\Abfx\t4_31
HKEY_CURRENT_USER\Software\Abfx\t1_32
HKEY_CURRENT_USER\Software\Abfx\t2_32
HKEY_CURRENT_USER\Software\Abfx\t3_32
HKEY_CURRENT_USER\Software\Abfx\t4_32
HKEY_CURRENT_USER\Software\Abfx\t1_33
HKEY_CURRENT_USER\Software\Abfx\t2_33
HKEY_CURRENT_USER\Software\Abfx\t3_33
HKEY_CURRENT_USER\Software\Abfx\t4_33
HKEY_CURRENT_USER\Software\Abfx\t1_34
HKEY_CURRENT_USER\Software\Abfx\t2_34
HKEY_CURRENT_USER\Software\Abfx\t3_34
HKEY_CURRENT_USER\Software\Abfx\t4_34
HKEY_CURRENT_USER\Software\Abfx\t1_35
HKEY_CURRENT_USER\Software\Abfx\t2_35
HKEY_CURRENT_USER\Software\Abfx\t3_35
HKEY_CURRENT_USER\Software\Abfx\t4_35
HKEY_CURRENT_USER\Software\Abfx\t1_36
HKEY_CURRENT_USER\Software\Abfx\t2_36
HKEY_CURRENT_USER\Software\Abfx\t3_36
HKEY_CURRENT_USER\Software\Abfx\t4_36
HKEY_CURRENT_USER\Software\Abfx\t1_37
HKEY_CURRENT_USER\Software\Abfx\t2_37
HKEY_CURRENT_USER\Software\Abfx\t3_37
HKEY_CURRENT_USER\Software\Abfx\t4_37
HKEY_CURRENT_USER\Software\Abfx\t1_38
HKEY_CURRENT_USER\Software\Abfx\t2_38
HKEY_CURRENT_USER\Software\Abfx\t3_38
HKEY_CURRENT_USER\Software\Abfx\t4_38
HKEY_CURRENT_USER\Software\Abfx\t1_39
HKEY_CURRENT_USER\Software\Abfx\t2_39
HKEY_CURRENT_USER\Software\Abfx\t3_39
HKEY_CURRENT_USER\Software\Abfx\t4_39
HKEY_CURRENT_USER\Software\Abfx\t1_40
HKEY_CURRENT_USER\Software\Abfx\t2_40
HKEY_CURRENT_USER\Software\Abfx\t3_40
HKEY_CURRENT_USER\Software\Abfx\t4_40
HKEY_CURRENT_USER\Software\Abfx\t1_41
HKEY_CURRENT_USER\Software\Abfx\t2_41
HKEY_CURRENT_USER\Software\Abfx\t3_41
HKEY_CURRENT_USER\Software\Abfx\t4_41
HKEY_CURRENT_USER\Software\Abfx\t1_42
HKEY_CURRENT_USER\Software\Abfx\t2_42
HKEY_CURRENT_USER\Software\Abfx\t3_42
HKEY_CURRENT_USER\Software\Abfx\t4_42
HKEY_CURRENT_USER\Software\Abfx\t1_43
HKEY_CURRENT_USER\Software\Abfx\t2_43
HKEY_CURRENT_USER\Software\Abfx\t3_43
HKEY_CURRENT_USER\Software\Abfx\t4_43
HKEY_CURRENT_USER\Software\Abfx\t1_44
HKEY_CURRENT_USER\Software\Abfx\t2_44
HKEY_CURRENT_USER\Software\Abfx\t3_44
HKEY_CURRENT_USER\Software\Abfx\t4_44
HKEY_CURRENT_USER\Software\Abfx\t1_45
HKEY_CURRENT_USER\Software\Abfx\t2_45
HKEY_CURRENT_USER\Software\Abfx\t3_45
HKEY_CURRENT_USER\Software\Abfx\t4_45
HKEY_CURRENT_USER\Software\Abfx\t1_46
HKEY_CURRENT_USER\Software\Abfx\t2_46
HKEY_CURRENT_USER\Software\Abfx\t3_46
HKEY_CURRENT_USER\Software\Abfx\t4_46
HKEY_CURRENT_USER\Software\Abfx\t1_47
HKEY_CURRENT_USER\Software\Abfx\t2_47
HKEY_CURRENT_USER\Software\Abfx\t3_47
HKEY_CURRENT_USER\Software\Abfx\t4_47
HKEY_CURRENT_USER\Software\Abfx\t1_48
HKEY_CURRENT_USER\Software\Abfx\t2_48
HKEY_CURRENT_USER\Software\Abfx\t3_48
HKEY_CURRENT_USER\Software\Abfx\t4_48
HKEY_CURRENT_USER\Software\Abfx\t1_49
HKEY_CURRENT_USER\Software\Abfx\t2_49
HKEY_CURRENT_USER\Software\Abfx\t3_49
HKEY_CURRENT_USER\Software\Abfx\t4_49
HKEY_CURRENT_USER\Software\Abfx\t1_50
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\SideBySide
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\ShellState
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\NoWebView
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\NoWebView
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\ClassicShell
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\ClassicShell
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\DontShowSuperHidden
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\DontShowSuperHidden
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\SeparateProcess
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\SeparateProcess
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\NoNetCrawling
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\NoNetCrawling
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\NoSimpleStartMenu
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\NoSimpleStartMenu
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced\ShowCompColor
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced\HideFileExt
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced\DontPrettyPath
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced\ShowInfoTip
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced\HideIcons
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced\MapNetDrvBtn
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced\WebView
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Filter
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced\ShowSuperHidden
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced\SeparateProcess
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced\NoNetCrawling
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced\AutoCheckSelect
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced\IconsOnly
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced\ShowTypeOverlay
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\ConfirmFileDelete
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\ConfirmFileDelete
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\NoFileFolderConnection
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\NoPropertiesMyComputer
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\NoPropertiesMyComputer
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\NoPropertiesRecycleBin
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\NoPropertiesRecycleBin
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\NoControlPanel
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\NoControlPanel
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\NoSetFolders
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\NoSetFolders
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\NoInternetIcon
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\NoInternetIcon
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellCompatibility\Applications\CF-__________________.exe
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\NoCommonGroups
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\NoCommonGroups
HKEY_CLASSES_ROOT\CLSID\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\ShellFolder
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\ShellFolder\Attributes
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\ShellFolder\CallForAttributes
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\ShellFolder\RestrictedAttributes
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\ShellFolder\WantsFORDISPLAY
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\ShellFolder\HideFolderVerbs
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\ShellFolder\UseDropHandler
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\ShellFolder\WantsFORPARSING
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\ShellFolder\WantsParseDisplayName
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\ShellFolder\QueryForOverlay
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\ShellFolder\MapNetDriveVerbs
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\ShellFolder\QueryForInfoTip
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\ShellFolder\HideInWebView
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\ShellFolder\HideOnDesktopPerUser
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\ShellFolder\WantsAliasedNotifications
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\ShellFolder\WantsUniversalDelegate
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\ShellFolder\NoFileFolderJunction
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\ShellFolder\PinToNameSpaceTree
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\ShellFolder\HasNavigationEnum
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\CLSID\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\ShellFolder
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\CLSID\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\ShellFolder
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\NonEnum
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\NonEnum
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\NonEnum\{20D04FE0-3AEA-1069-A2D8-08002B30309D}
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\CPC\Volume
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\CPC\Volume\{372941a4-1bd9-11e5-9838-806e6f6e6963}\
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\CPC\Volume\{372941a4-1bd9-11e5-9838-806e6f6e6963}\Data
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\CPC\Volume\{372941a4-1bd9-11e5-9838-806e6f6e6963}\Generation
HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows\Explorer
HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\Explorer
HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\LSA\AccessProviders
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Lsa\AccessProviders\MartaExtension
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\CPC\Volume\{372941a3-1bd9-11e5-9838-806e6f6e6963}\
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\CPC\Volume\{372941a3-1bd9-11e5-9838-806e6f6e6963}\Data
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\CPC\Volume\{372941a3-1bd9-11e5-9838-806e6f6e6963}\Generation
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\Shell\RegisteredApplications\UrlAssociations\Directory\OpenWithProgids
HKEY_CURRENT_USER\Software\Microsoft\Windows\Shell\Associations\UrlAssociations\Directory
HKEY_CLASSES_ROOT\Directory
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Directory\CurVer
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Directory\
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Directory\ShellEx\IconHandler
HKEY_CLASSES_ROOT\Folder
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Folder\ShellEx\IconHandler
HKEY_CLASSES_ROOT\AllFilesystemObjects
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AllFilesystemObjects\ShellEx\IconHandler
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Directory\DocObject
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Folder\DocObject
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AllFilesystemObjects\DocObject
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Directory\BrowseInPlace
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Folder\BrowseInPlace
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AllFilesystemObjects\BrowseInPlace
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Directory\Clsid
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Folder\Clsid
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AllFilesystemObjects\Clsid
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Directory\IsShortcut
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Folder\IsShortcut
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AllFilesystemObjects\IsShortcut
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Directory\AlwaysShowExt
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Directory\NeverShowExt
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Folder\NeverShowExt
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AllFilesystemObjects\NeverShowExt
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Directory\ShellEx\PropertyHandler
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Folder\ShellEx\PropertyHandler
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AllFilesystemObjects\ShellEx\PropertyHandler
HKEY_CLASSES_ROOT\.exe
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\.exe\(Default)
HKEY_CLASSES_ROOT\.exe\OpenWithProgids
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.exe\OpenWithProgids
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.exe
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.exe\
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.exe\UserChoice
HKEY_CLASSES_ROOT\exefile
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\exefile\CurVer
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\exefile\
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\exefile\ShellEx\IconHandler
HKEY_CLASSES_ROOT\SystemFileAssociations\.exe
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\SystemFileAssociations\.exe\ShellEx\IconHandler
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\exefile\DocObject
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\SystemFileAssociations\.exe\DocObject
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\exefile\BrowseInPlace
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\SystemFileAssociations\.exe\BrowseInPlace
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\.exe\Content Type
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\exefile\Clsid
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\SystemFileAssociations\.exe\Clsid
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\exefile\IsShortcut
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\SystemFileAssociations\.exe\IsShortcut
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\exefile\AlwaysShowExt
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\SystemFileAssociations\.exe\AlwaysShowExt
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\exefile\NeverShowExt
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\SystemFileAssociations\.exe\NeverShowExt
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced\MaxUndoItems
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\Advanced\MaxUndoItems
HKEY_CLASSES_ROOT\Directory\shellex\CopyHookHandlers
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Directory\shellex\CopyHookHandlers\FileSystem
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Directory\shellex\CopyHookHandlers\FileSystem\(Default)
HKEY_CLASSES_ROOT\CLSID\{217FC9C0-3AEA-1069-A2DB-08002B30309D}\InProcServer32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{217FC9C0-3AEA-1069-A2DB-08002B30309D}\InProcServer32\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Directory\shellex\CopyHookHandlers\Sharing
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Directory\shellex\CopyHookHandlers\Sharing\(Default)
HKEY_CLASSES_ROOT\CLSID\{40DD6E20-7C17-11CE-A804-00AA003CA9F6}\InProcServer32
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{40DD6E20-7C17-11CE-A804-00AA003CA9F6}\InProcServer32\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{40DD6E20-7C17-11CE-A804-00AA003CA9F6}\InProcServer32\LoadWithoutCOM
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Blocked
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Blocked
HKEY_LOCAL_MACHINE\Software\Classes\CLSID\{40dd6e20-7c17-11ce-a804-00aa003ca9f6}\InProcServer32
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders\Cache
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Layers
HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Layers
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Custom\ntshrui.dll
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Cached
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Cached\{40DD6E20-7C17-11CE-A804-00AA003CA9F6} {000214FC-0000-0000-C000-000000000046} 0xFFFF
HKEY_CURRENT_USER\Software\Abfx\t1_0
HKEY_CURRENT_USER\Software\Abfx\t2_0
HKEY_CURRENT_USER\Software\Abfx\t3_0
HKEY_CURRENT_USER\Software\Abfx\t4_0
HKEY_CURRENT_USER\Software\Abfx\t1_1
HKEY_CURRENT_USER\Software\Abfx\t2_1
HKEY_CURRENT_USER\Software\Abfx\t3_1
HKEY_CURRENT_USER\Software\Abfx\t4_1
HKEY_CURRENT_USER\Software\Abfx\t1_2
HKEY_CURRENT_USER\Software\Abfx\t2_2
HKEY_CURRENT_USER\Software\Abfx\t3_2
HKEY_CURRENT_USER\Software\Abfx\t4_2
HKEY_CURRENT_USER\Software\Abfx\t1_3
HKEY_CURRENT_USER\Software\Abfx\t2_3
HKEY_CURRENT_USER\Software\Abfx\t3_3
HKEY_CURRENT_USER\Software\Abfx\t4_3
HKEY_CURRENT_USER\Software\Abfx\t1_4
HKEY_CURRENT_USER\Software\Abfx\t2_4
HKEY_CURRENT_USER\Software\Abfx\t3_4
HKEY_CURRENT_USER\Software\Abfx\t4_4
HKEY_CURRENT_USER\Software\Abfx\t1_5
HKEY_CURRENT_USER\Software\Abfx\t2_5
HKEY_CURRENT_USER\Software\Abfx\t3_5
HKEY_CURRENT_USER\Software\Abfx\t4_5
HKEY_CURRENT_USER\Software\Abfx\t1_6
HKEY_CURRENT_USER\Software\Abfx\t2_6
HKEY_CURRENT_USER\Software\Abfx\t3_6
HKEY_CURRENT_USER\Software\Abfx\t4_6
HKEY_CURRENT_USER\Software\Abfx\t1_7
HKEY_CURRENT_USER\Software\Abfx\t2_7
HKEY_CURRENT_USER\Software\Abfx\t3_7
HKEY_CURRENT_USER\Software\Abfx\t4_7
HKEY_CURRENT_USER\Software\Abfx\t1_8
HKEY_CURRENT_USER\Software\Abfx\t2_8
HKEY_CURRENT_USER\Software\Abfx\t3_8
HKEY_CURRENT_USER\Software\Abfx\t4_8
HKEY_CURRENT_USER\Software\Abfx\t1_9
HKEY_CURRENT_USER\Software\Abfx\t2_9
HKEY_CURRENT_USER\Software\Abfx\t3_9
HKEY_CURRENT_USER\Software\Abfx\t4_9
HKEY_CURRENT_USER\Software\Abfx\t1_10
HKEY_CURRENT_USER\Software\Abfx\t2_10
HKEY_CURRENT_USER\Software\Abfx\t3_10
HKEY_CURRENT_USER\Software\Abfx\t4_10
HKEY_CURRENT_USER\Software\Abfx\t1_11
HKEY_CURRENT_USER\Software\Abfx\t2_11
HKEY_CURRENT_USER\Software\Abfx\t3_11
HKEY_CURRENT_USER\Software\Abfx\t4_11
HKEY_CURRENT_USER\Software\Abfx\t1_12
HKEY_CURRENT_USER\Software\Abfx\t2_12
HKEY_CURRENT_USER\Software\Abfx\t3_12
HKEY_CURRENT_USER\Software\Abfx\t4_12
HKEY_CURRENT_USER\Software\Abfx\t1_13
HKEY_CURRENT_USER\Software\Abfx\t2_13
HKEY_CURRENT_USER\Software\Abfx\t3_13
HKEY_CURRENT_USER\Software\Abfx\t4_13
HKEY_CURRENT_USER\Software\Abfx\t1_14
HKEY_CURRENT_USER\Software\Abfx\t2_14
HKEY_CURRENT_USER\Software\Abfx\t3_14
HKEY_CURRENT_USER\Software\Abfx\t4_14
HKEY_CURRENT_USER\Software\Abfx\t1_15
HKEY_CURRENT_USER\Software\Abfx\t2_15
HKEY_CURRENT_USER\Software\Abfx\t3_15
HKEY_CURRENT_USER\Software\Abfx\t4_15
HKEY_CURRENT_USER\Software\Abfx\t1_16
HKEY_CURRENT_USER\Software\Abfx\t2_16
HKEY_CURRENT_USER\Software\Abfx\t3_16
HKEY_CURRENT_USER\Software\Abfx\t4_16
HKEY_CURRENT_USER\Software\Abfx\t1_17
HKEY_CURRENT_USER\Software\Abfx\t2_17
HKEY_CURRENT_USER\Software\Abfx\t3_17
HKEY_CURRENT_USER\Software\Abfx\t4_17
HKEY_CURRENT_USER\Software\Abfx\t1_18
HKEY_CURRENT_USER\Software\Abfx\t2_18
HKEY_CURRENT_USER\Software\Abfx\t3_18
HKEY_CURRENT_USER\Software\Abfx\t4_18
HKEY_CURRENT_USER\Software\Abfx\t1_19
HKEY_CURRENT_USER\Software\Abfx\t2_19
HKEY_CURRENT_USER\Software\Abfx\t3_19
HKEY_CURRENT_USER\Software\Abfx\t4_19
HKEY_CURRENT_USER\Software\Abfx\t1_20
HKEY_CURRENT_USER\Software\Abfx\t2_20
HKEY_CURRENT_USER\Software\Abfx\t3_20
HKEY_CURRENT_USER\Software\Abfx\t4_20
HKEY_CURRENT_USER\Software\Abfx\t1_21
HKEY_CURRENT_USER\Software\Abfx\t2_21
HKEY_CURRENT_USER\Software\Abfx\t3_21
HKEY_CURRENT_USER\Software\Abfx\t4_21
HKEY_CURRENT_USER\Software\Abfx\t1_22
HKEY_CURRENT_USER\Software\Abfx\t2_22
HKEY_CURRENT_USER\Software\Abfx\t3_22
HKEY_CURRENT_USER\Software\Abfx\t4_22
HKEY_CURRENT_USER\Software\Abfx\t1_23
HKEY_CURRENT_USER\Software\Abfx\t2_23
HKEY_CURRENT_USER\Software\Abfx\t3_23
HKEY_CURRENT_USER\Software\Abfx\t4_23
HKEY_CURRENT_USER\Software\Abfx\t1_24
HKEY_CURRENT_USER\Software\Abfx\t2_24
HKEY_CURRENT_USER\Software\Abfx\t3_24
HKEY_CURRENT_USER\Software\Abfx\t4_24
HKEY_CURRENT_USER\Software\Abfx\t1_25
HKEY_CURRENT_USER\Software\Abfx\t2_25
HKEY_CURRENT_USER\Software\Abfx\t3_25
HKEY_CURRENT_USER\Software\Abfx\t4_25
HKEY_CURRENT_USER\Software\Abfx\t1_26
HKEY_CURRENT_USER\Software\Abfx\t2_26
HKEY_CURRENT_USER\Software\Abfx\t3_26
HKEY_CURRENT_USER\Software\Abfx\t4_26
HKEY_CURRENT_USER\Software\Abfx\t1_27
HKEY_CURRENT_USER\Software\Abfx\t2_27
HKEY_CURRENT_USER\Software\Abfx\t3_27
HKEY_CURRENT_USER\Software\Abfx\t4_27
HKEY_CURRENT_USER\Software\Abfx\t1_28
HKEY_CURRENT_USER\Software\Abfx\t2_28
HKEY_CURRENT_USER\Software\Abfx\t3_28
HKEY_CURRENT_USER\Software\Abfx\t4_28
HKEY_CURRENT_USER\Software\Abfx\t1_29
HKEY_CURRENT_USER\Software\Abfx\t2_29
HKEY_CURRENT_USER\Software\Abfx\t3_29
HKEY_CURRENT_USER\Software\Abfx\t4_29
HKEY_CURRENT_USER\Software\Abfx\t1_30
HKEY_CURRENT_USER\Software\Abfx\t2_30
HKEY_CURRENT_USER\Software\Abfx\t3_30
HKEY_CURRENT_USER\Software\Abfx\t4_30
HKEY_CURRENT_USER\Software\Abfx\t1_31
HKEY_CURRENT_USER\Software\Abfx\t2_31
HKEY_CURRENT_USER\Software\Abfx\t3_31
HKEY_CURRENT_USER\Software\Abfx\t4_31
HKEY_CURRENT_USER\Software\Abfx\t1_32
HKEY_CURRENT_USER\Software\Abfx\t2_32
HKEY_CURRENT_USER\Software\Abfx\t3_32
HKEY_CURRENT_USER\Software\Abfx\t4_32
HKEY_CURRENT_USER\Software\Abfx\t1_33
HKEY_CURRENT_USER\Software\Abfx\t2_33
HKEY_CURRENT_USER\Software\Abfx\t3_33
HKEY_CURRENT_USER\Software\Abfx\t4_33
HKEY_CURRENT_USER\Software\Abfx\t1_34
HKEY_CURRENT_USER\Software\Abfx\t2_34
HKEY_CURRENT_USER\Software\Abfx\t3_34
HKEY_CURRENT_USER\Software\Abfx\t4_34
HKEY_CURRENT_USER\Software\Abfx\t1_35
HKEY_CURRENT_USER\Software\Abfx\t2_35
HKEY_CURRENT_USER\Software\Abfx\t3_35
HKEY_CURRENT_USER\Software\Abfx\t4_35
HKEY_CURRENT_USER\Software\Abfx\t1_36
HKEY_CURRENT_USER\Software\Abfx\t2_36
HKEY_CURRENT_USER\Software\Abfx\t3_36
HKEY_CURRENT_USER\Software\Abfx\t4_36
HKEY_CURRENT_USER\Software\Abfx\t1_37
HKEY_CURRENT_USER\Software\Abfx\t2_37
HKEY_CURRENT_USER\Software\Abfx\t3_37
HKEY_CURRENT_USER\Software\Abfx\t4_37
HKEY_CURRENT_USER\Software\Abfx\t1_38
HKEY_CURRENT_USER\Software\Abfx\t2_38
HKEY_CURRENT_USER\Software\Abfx\t3_38
HKEY_CURRENT_USER\Software\Abfx\t4_38
HKEY_CURRENT_USER\Software\Abfx\t1_39
HKEY_CURRENT_USER\Software\Abfx\t2_39
HKEY_CURRENT_USER\Software\Abfx\t3_39
HKEY_CURRENT_USER\Software\Abfx\t4_39
HKEY_CURRENT_USER\Software\Abfx\t1_40
HKEY_CURRENT_USER\Software\Abfx\t2_40
HKEY_CURRENT_USER\Software\Abfx\t3_40
HKEY_CURRENT_USER\Software\Abfx\t4_40
HKEY_CURRENT_USER\Software\Abfx\t1_41
HKEY_CURRENT_USER\Software\Abfx\t2_41
HKEY_CURRENT_USER\Software\Abfx\t3_41
HKEY_CURRENT_USER\Software\Abfx\t4_41
HKEY_CURRENT_USER\Software\Abfx\t1_42
HKEY_CURRENT_USER\Software\Abfx\t2_42
HKEY_CURRENT_USER\Software\Abfx\t3_42
HKEY_CURRENT_USER\Software\Abfx\t4_42
HKEY_CURRENT_USER\Software\Abfx\t1_43
HKEY_CURRENT_USER\Software\Abfx\t2_43
HKEY_CURRENT_USER\Software\Abfx\t3_43
HKEY_CURRENT_USER\Software\Abfx\t4_43
HKEY_CURRENT_USER\Software\Abfx\t1_44
HKEY_CURRENT_USER\Software\Abfx\t2_44
HKEY_CURRENT_USER\Software\Abfx\t3_44
HKEY_CURRENT_USER\Software\Abfx\t4_44
HKEY_CURRENT_USER\Software\Abfx\t1_45
HKEY_CURRENT_USER\Software\Abfx\t2_45
HKEY_CURRENT_USER\Software\Abfx\t3_45
HKEY_CURRENT_USER\Software\Abfx\t4_45
HKEY_CURRENT_USER\Software\Abfx\t1_46
HKEY_CURRENT_USER\Software\Abfx\t2_46
HKEY_CURRENT_USER\Software\Abfx\t3_46
HKEY_CURRENT_USER\Software\Abfx\t4_46
HKEY_CURRENT_USER\Software\Abfx\t1_47
HKEY_CURRENT_USER\Software\Abfx\t2_47
HKEY_CURRENT_USER\Software\Abfx\t3_47
HKEY_CURRENT_USER\Software\Abfx\t4_47
HKEY_CURRENT_USER\Software\Abfx\t1_48
HKEY_CURRENT_USER\Software\Abfx\t2_48
HKEY_CURRENT_USER\Software\Abfx\t3_48
HKEY_CURRENT_USER\Software\Abfx\t4_48
HKEY_CURRENT_USER\Software\Abfx\t1_49
HKEY_CURRENT_USER\Software\Abfx\t2_49
HKEY_CURRENT_USER\Software\Abfx\t3_49
HKEY_CURRENT_USER\Software\Abfx\t4_49
HKEY_CURRENT_USER\Software\Abfx\t1_50
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\ShellState
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\NoWebView
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\NoWebView
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\ClassicShell
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\ClassicShell
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\DontShowSuperHidden
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\DontShowSuperHidden
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\SeparateProcess
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\SeparateProcess
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\NoNetCrawling
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\NoNetCrawling
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\NoSimpleStartMenu
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\NoSimpleStartMenu
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Hidden
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced\ShowCompColor
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced\HideFileExt
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced\DontPrettyPath
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced\ShowInfoTip
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced\HideIcons
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced\MapNetDrvBtn
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced\WebView
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Filter
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced\ShowSuperHidden
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced\SeparateProcess
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced\NoNetCrawling
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced\AutoCheckSelect
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced\IconsOnly
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced\ShowTypeOverlay
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\ConfirmFileDelete
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\ConfirmFileDelete
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\NoFileFolderConnection
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\NoPropertiesMyComputer
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\NoPropertiesMyComputer
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\NoPropertiesRecycleBin
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\NoPropertiesRecycleBin
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\NoControlPanel
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\NoControlPanel
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\NoSetFolders
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\NoSetFolders
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\NoInternetIcon
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\NoInternetIcon
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\NoCommonGroups
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\NoCommonGroups
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\ShellFolder\Attributes
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\ShellFolder\CallForAttributes
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\ShellFolder\RestrictedAttributes
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\ShellFolder\WantsFORDISPLAY
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\ShellFolder\HideFolderVerbs
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\ShellFolder\UseDropHandler
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\ShellFolder\WantsFORPARSING
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\ShellFolder\WantsParseDisplayName
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\ShellFolder\QueryForOverlay
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\ShellFolder\MapNetDriveVerbs
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\ShellFolder\QueryForInfoTip
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\ShellFolder\HideInWebView
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\ShellFolder\HideOnDesktopPerUser
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\ShellFolder\WantsAliasedNotifications
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\ShellFolder\WantsUniversalDelegate
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\ShellFolder\NoFileFolderJunction
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\ShellFolder\PinToNameSpaceTree
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\ShellFolder\HasNavigationEnum
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\NonEnum\{20D04FE0-3AEA-1069-A2D8-08002B30309D}
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\CPC\Volume\{372941a4-1bd9-11e5-9838-806e6f6e6963}\Data
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\CPC\Volume\{372941a4-1bd9-11e5-9838-806e6f6e6963}\Generation
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Lsa\AccessProviders\MartaExtension
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\CPC\Volume\{372941a3-1bd9-11e5-9838-806e6f6e6963}\Data
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\CPC\Volume\{372941a3-1bd9-11e5-9838-806e6f6e6963}\Generation
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Directory\DocObject
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Folder\DocObject
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AllFilesystemObjects\DocObject
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Directory\BrowseInPlace
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Folder\BrowseInPlace
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AllFilesystemObjects\BrowseInPlace
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Directory\IsShortcut
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Folder\IsShortcut
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AllFilesystemObjects\IsShortcut
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Directory\AlwaysShowExt
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Directory\NeverShowExt
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Folder\NeverShowExt
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AllFilesystemObjects\NeverShowExt
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\.exe\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\exefile\DocObject
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\SystemFileAssociations\.exe\DocObject
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\exefile\BrowseInPlace
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\SystemFileAssociations\.exe\BrowseInPlace
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\.exe\Content Type
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\exefile\IsShortcut
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\SystemFileAssociations\.exe\IsShortcut
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\exefile\AlwaysShowExt
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\SystemFileAssociations\.exe\AlwaysShowExt
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\exefile\NeverShowExt
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\SystemFileAssociations\.exe\NeverShowExt
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced\MaxUndoItems
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\Advanced\MaxUndoItems
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Directory\shellex\CopyHookHandlers\FileSystem\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{217FC9C0-3AEA-1069-A2DB-08002B30309D}\InProcServer32\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Directory\shellex\CopyHookHandlers\Sharing\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{40DD6E20-7C17-11CE-A804-00AA003CA9F6}\InProcServer32\(Default)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{40DD6E20-7C17-11CE-A804-00AA003CA9F6}\InProcServer32\LoadWithoutCOM
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders\Cache
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Cached\{40DD6E20-7C17-11CE-A804-00AA003CA9F6} {000214FC-0000-0000-C000-000000000046} 0xFFFF
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Hidden
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Security Center\AntiVirusOverride
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Security Center\AntiVirusDisableNotify
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Security Center\FirewallDisableNotify
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Security Center\FirewallOverride
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Security Center\UpdatesDisableNotify
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Security Center\UacDisableNotify
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Security Center\Svc\AntiVirusOverride
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Security Center\Svc\AntiVirusDisableNotify
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Security Center\Svc\FirewallDisableNotify
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Security Center\Svc\FirewallOverride
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Security Center\Svc\UpdatesDisableNotify
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Security Center\Svc\UacDisableNotify
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\GlobalUserOffline
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System\EnableLUA
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\EnableFirewall
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\DoNotAllowExceptions
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\DisableNotifications
HKEY_CURRENT_USER\Software\Abfx\-1001785200
HKEY_CURRENT_USER\Software\Abfx\-1001785200\1953719668
HKEY_CURRENT_USER\Software\Abfx\-1001785200\-387527960
HKEY_CURRENT_USER\Software\Abfx\-1001785200\1566191708
HKEY_CURRENT_USER\Software\Abfx\-1001785200\-775055920
HKEY_CURRENT_USER\Software\Abfx\-1001785200\1178663748
HKEY_CURRENT_USER\Software\Abfx\-1001785200\-1162583880
HKEY_CURRENT_USER\Software\Abfx\-1001785200\791135788
HKEY_CURRENT_USER\Software\Abfx\t1_0
HKEY_CURRENT_USER\Software\Abfx\t2_0
HKEY_CURRENT_USER\Software\Abfx\t3_0
HKEY_CURRENT_USER\Software\Abfx\t4_0
HKEY_CURRENT_USER\Software\Abfx\t1_1
HKEY_CURRENT_USER\Software\Abfx\t2_1
HKEY_CURRENT_USER\Software\Abfx\t3_1
HKEY_CURRENT_USER\Software\Abfx\t4_1
HKEY_CURRENT_USER\Software\Abfx\t1_2
HKEY_CURRENT_USER\Software\Abfx\t2_2
HKEY_CURRENT_USER\Software\Abfx\t3_2
HKEY_CURRENT_USER\Software\Abfx\t4_2
HKEY_CURRENT_USER\Software\Abfx\t1_3
HKEY_CURRENT_USER\Software\Abfx\t2_3
HKEY_CURRENT_USER\Software\Abfx\t3_3
HKEY_CURRENT_USER\Software\Abfx\t4_3
HKEY_CURRENT_USER\Software\Abfx\t1_4
HKEY_CURRENT_USER\Software\Abfx\t2_4
HKEY_CURRENT_USER\Software\Abfx\t3_4
HKEY_CURRENT_USER\Software\Abfx\t4_4
HKEY_CURRENT_USER\Software\Abfx\t1_5
HKEY_CURRENT_USER\Software\Abfx\t2_5
HKEY_CURRENT_USER\Software\Abfx\t3_5
HKEY_CURRENT_USER\Software\Abfx\t4_5
HKEY_CURRENT_USER\Software\Abfx\t1_6
HKEY_CURRENT_USER\Software\Abfx\t2_6
HKEY_CURRENT_USER\Software\Abfx\t3_6
HKEY_CURRENT_USER\Software\Abfx\t4_6
HKEY_CURRENT_USER\Software\Abfx\t1_7
HKEY_CURRENT_USER\Software\Abfx\t2_7
HKEY_CURRENT_USER\Software\Abfx\t3_7
HKEY_CURRENT_USER\Software\Abfx\t4_7
HKEY_CURRENT_USER\Software\Abfx\t1_8
HKEY_CURRENT_USER\Software\Abfx\t2_8
HKEY_CURRENT_USER\Software\Abfx\t3_8
HKEY_CURRENT_USER\Software\Abfx\t4_8
HKEY_CURRENT_USER\Software\Abfx\t1_9
HKEY_CURRENT_USER\Software\Abfx\t2_9
HKEY_CURRENT_USER\Software\Abfx\t3_9
HKEY_CURRENT_USER\Software\Abfx\t4_9
HKEY_CURRENT_USER\Software\Abfx\t1_10
HKEY_CURRENT_USER\Software\Abfx\t2_10
HKEY_CURRENT_USER\Software\Abfx\t3_10
HKEY_CURRENT_USER\Software\Abfx\t4_10
HKEY_CURRENT_USER\Software\Abfx\t1_11
HKEY_CURRENT_USER\Software\Abfx\t2_11
HKEY_CURRENT_USER\Software\Abfx\t3_11
HKEY_CURRENT_USER\Software\Abfx\t4_11
HKEY_CURRENT_USER\Software\Abfx\t1_12
HKEY_CURRENT_USER\Software\Abfx\t2_12
HKEY_CURRENT_USER\Software\Abfx\t3_12
HKEY_CURRENT_USER\Software\Abfx\t4_12
HKEY_CURRENT_USER\Software\Abfx\t1_13
HKEY_CURRENT_USER\Software\Abfx\t2_13
HKEY_CURRENT_USER\Software\Abfx\t3_13
HKEY_CURRENT_USER\Software\Abfx\t4_13
HKEY_CURRENT_USER\Software\Abfx\t1_14
HKEY_CURRENT_USER\Software\Abfx\t2_14
HKEY_CURRENT_USER\Software\Abfx\t3_14
HKEY_CURRENT_USER\Software\Abfx\t4_14
HKEY_CURRENT_USER\Software\Abfx\t1_15
HKEY_CURRENT_USER\Software\Abfx\t2_15
HKEY_CURRENT_USER\Software\Abfx\t3_15
HKEY_CURRENT_USER\Software\Abfx\t4_15
HKEY_CURRENT_USER\Software\Abfx\t1_16
HKEY_CURRENT_USER\Software\Abfx\t2_16
HKEY_CURRENT_USER\Software\Abfx\t3_16
HKEY_CURRENT_USER\Software\Abfx\t4_16
HKEY_CURRENT_USER\Software\Abfx\t1_17
HKEY_CURRENT_USER\Software\Abfx\t2_17
HKEY_CURRENT_USER\Software\Abfx\t3_17
HKEY_CURRENT_USER\Software\Abfx\t4_17
HKEY_CURRENT_USER\Software\Abfx\t1_18
HKEY_CURRENT_USER\Software\Abfx\t2_18
HKEY_CURRENT_USER\Software\Abfx\t3_18
HKEY_CURRENT_USER\Software\Abfx\t4_18
HKEY_CURRENT_USER\Software\Abfx\t1_19
HKEY_CURRENT_USER\Software\Abfx\t2_19
HKEY_CURRENT_USER\Software\Abfx\t3_19
HKEY_CURRENT_USER\Software\Abfx\t4_19
HKEY_CURRENT_USER\Software\Abfx\t1_20
HKEY_CURRENT_USER\Software\Abfx\t2_20
HKEY_CURRENT_USER\Software\Abfx\t3_20
HKEY_CURRENT_USER\Software\Abfx\t4_20
HKEY_CURRENT_USER\Software\Abfx\t1_21
HKEY_CURRENT_USER\Software\Abfx\t2_21
HKEY_CURRENT_USER\Software\Abfx\t3_21
HKEY_CURRENT_USER\Software\Abfx\t4_21
HKEY_CURRENT_USER\Software\Abfx\t1_22
HKEY_CURRENT_USER\Software\Abfx\t2_22
HKEY_CURRENT_USER\Software\Abfx\t3_22
HKEY_CURRENT_USER\Software\Abfx\t4_22
HKEY_CURRENT_USER\Software\Abfx\t1_23
HKEY_CURRENT_USER\Software\Abfx\t2_23
HKEY_CURRENT_USER\Software\Abfx\t3_23
HKEY_CURRENT_USER\Software\Abfx\t4_23
HKEY_CURRENT_USER\Software\Abfx\t1_24
HKEY_CURRENT_USER\Software\Abfx\t2_24
HKEY_CURRENT_USER\Software\Abfx\t3_24
HKEY_CURRENT_USER\Software\Abfx\t4_24
HKEY_CURRENT_USER\Software\Abfx\t1_25
HKEY_CURRENT_USER\Software\Abfx\t2_25
HKEY_CURRENT_USER\Software\Abfx\t3_25
HKEY_CURRENT_USER\Software\Abfx\t4_25
HKEY_CURRENT_USER\Software\Abfx\t1_26
HKEY_CURRENT_USER\Software\Abfx\t2_26
HKEY_CURRENT_USER\Software\Abfx\t3_26
HKEY_CURRENT_USER\Software\Abfx\t4_26
HKEY_CURRENT_USER\Software\Abfx\t1_27
HKEY_CURRENT_USER\Software\Abfx\t2_27
HKEY_CURRENT_USER\Software\Abfx\t3_27
HKEY_CURRENT_USER\Software\Abfx\t4_27
HKEY_CURRENT_USER\Software\Abfx\t1_28
HKEY_CURRENT_USER\Software\Abfx\t2_28
HKEY_CURRENT_USER\Software\Abfx\t3_28
HKEY_CURRENT_USER\Software\Abfx\t4_28
HKEY_CURRENT_USER\Software\Abfx\t1_29
HKEY_CURRENT_USER\Software\Abfx\t2_29
HKEY_CURRENT_USER\Software\Abfx\t3_29
HKEY_CURRENT_USER\Software\Abfx\t4_29
HKEY_CURRENT_USER\Software\Abfx\t1_30
HKEY_CURRENT_USER\Software\Abfx\t2_30
HKEY_CURRENT_USER\Software\Abfx\t3_30
HKEY_CURRENT_USER\Software\Abfx\t4_30
HKEY_CURRENT_USER\Software\Abfx\t1_31
HKEY_CURRENT_USER\Software\Abfx\t2_31
HKEY_CURRENT_USER\Software\Abfx\t3_31
HKEY_CURRENT_USER\Software\Abfx\t4_31
HKEY_CURRENT_USER\Software\Abfx\t1_32
HKEY_CURRENT_USER\Software\Abfx\t2_32
HKEY_CURRENT_USER\Software\Abfx\t3_32
HKEY_CURRENT_USER\Software\Abfx\t4_32
HKEY_CURRENT_USER\Software\Abfx\t1_33
HKEY_CURRENT_USER\Software\Abfx\t2_33
HKEY_CURRENT_USER\Software\Abfx\t3_33
HKEY_CURRENT_USER\Software\Abfx\t4_33
HKEY_CURRENT_USER\Software\Abfx\t1_34
HKEY_CURRENT_USER\Software\Abfx\t2_34
HKEY_CURRENT_USER\Software\Abfx\t3_34
HKEY_CURRENT_USER\Software\Abfx\t4_34
HKEY_CURRENT_USER\Software\Abfx\t1_35
HKEY_CURRENT_USER\Software\Abfx\t2_35
HKEY_CURRENT_USER\Software\Abfx\t3_35
HKEY_CURRENT_USER\Software\Abfx\t4_35
HKEY_CURRENT_USER\Software\Abfx\t1_36
HKEY_CURRENT_USER\Software\Abfx\t2_36
HKEY_CURRENT_USER\Software\Abfx\t3_36
HKEY_CURRENT_USER\Software\Abfx\t4_36
HKEY_CURRENT_USER\Software\Abfx\t1_37
HKEY_CURRENT_USER\Software\Abfx\t2_37
HKEY_CURRENT_USER\Software\Abfx\t3_37
HKEY_CURRENT_USER\Software\Abfx\t4_37
HKEY_CURRENT_USER\Software\Abfx\t1_38
HKEY_CURRENT_USER\Software\Abfx\t2_38
HKEY_CURRENT_USER\Software\Abfx\t3_38
HKEY_CURRENT_USER\Software\Abfx\t4_38
HKEY_CURRENT_USER\Software\Abfx\t1_39
HKEY_CURRENT_USER\Software\Abfx\t2_39
HKEY_CURRENT_USER\Software\Abfx\t3_39
HKEY_CURRENT_USER\Software\Abfx\t4_39
HKEY_CURRENT_USER\Software\Abfx\t1_40
HKEY_CURRENT_USER\Software\Abfx\t2_40
HKEY_CURRENT_USER\Software\Abfx\t3_40
HKEY_CURRENT_USER\Software\Abfx\t4_40
HKEY_CURRENT_USER\Software\Abfx\t1_41
HKEY_CURRENT_USER\Software\Abfx\t2_41
HKEY_CURRENT_USER\Software\Abfx\t3_41
HKEY_CURRENT_USER\Software\Abfx\t4_41
HKEY_CURRENT_USER\Software\Abfx\t1_42
HKEY_CURRENT_USER\Software\Abfx\t2_42
HKEY_CURRENT_USER\Software\Abfx\t3_42
HKEY_CURRENT_USER\Software\Abfx\t4_42
HKEY_CURRENT_USER\Software\Abfx\t1_43
HKEY_CURRENT_USER\Software\Abfx\t2_43
HKEY_CURRENT_USER\Software\Abfx\t3_43
HKEY_CURRENT_USER\Software\Abfx\t4_43
HKEY_CURRENT_USER\Software\Abfx\t1_44
HKEY_CURRENT_USER\Software\Abfx\t2_44
HKEY_CURRENT_USER\Software\Abfx\t3_44
HKEY_CURRENT_USER\Software\Abfx\t4_44
HKEY_CURRENT_USER\Software\Abfx\t1_45
HKEY_CURRENT_USER\Software\Abfx\t2_45
HKEY_CURRENT_USER\Software\Abfx\t3_45
HKEY_CURRENT_USER\Software\Abfx\t4_45
HKEY_CURRENT_USER\Software\Abfx\t1_46
HKEY_CURRENT_USER\Software\Abfx\t2_46
HKEY_CURRENT_USER\Software\Abfx\t3_46
HKEY_CURRENT_USER\Software\Abfx\t4_46
HKEY_CURRENT_USER\Software\Abfx\t1_47
HKEY_CURRENT_USER\Software\Abfx\t2_47
HKEY_CURRENT_USER\Software\Abfx\t3_47
HKEY_CURRENT_USER\Software\Abfx\t4_47
HKEY_CURRENT_USER\Software\Abfx\t1_48
HKEY_CURRENT_USER\Software\Abfx\t2_48
HKEY_CURRENT_USER\Software\Abfx\t3_48
HKEY_CURRENT_USER\Software\Abfx\t4_48
HKEY_CURRENT_USER\Software\Abfx\t1_49
HKEY_CURRENT_USER\Software\Abfx\t2_49
HKEY_CURRENT_USER\Software\Abfx\t3_49
HKEY_CURRENT_USER\Software\Abfx\t4_49
kernel32.dll.CloseHandle
kernel32.dll.CreateFileMappingA
kernel32.dll.CreateMutexA
kernel32.dll.CreateThread
kernel32.dll.SetErrorMode
kernel32.dll.VirtualAlloc
kernel32.dll.lstrlenA
kernel32.dll.ReleaseMutex
kernel32.dll.GetLastError
kernel32.dll.MapViewOfFile
kernel32.dll.Sleep
kernel32.dll.GetModuleFileNameA
kernel32.dll.GetTempPathA
kernel32.dll.CopyFileA
kernel32.dll.CreateFileA
kernel32.dll.CreateFileW
kernel32.dll.OpenFile
kernel32.dll.GetFileSize
kernel32.dll.UnmapViewOfFile
kernel32.dll.SetFilePointer
kernel32.dll.SetEndOfFile
kernel32.dll.lstrcmpiA
kernel32.dll.lstrcatA
kernel32.dll.GetTickCount
kernel32.dll.CreateDirectoryA
kernel32.dll.WideCharToMultiByte
kernel32.dll.ExitProcess
kernel32.dll._lopen
kernel32.dll.LoadLibraryA
kernel32.dll.GetProcAddress
kernel32.dll.VirtualProtect
advapi32.dll.RegCloseKey
msvcrt.dll.tolower
shell32.dll.SHFileOperationA
user32.dll.wsprintfA
kernel32.dll.WriteFile
kernel32.dll.ReadFile
kernel32.dll.GetStringTypeW
kernel32.dll.GetStringTypeA
kernel32.dll.GetModuleHandleA
kernel32.dll.GetStartupInfoA
kernel32.dll.GetCommandLineA
kernel32.dll.GetVersion
kernel32.dll.HeapAlloc
kernel32.dll.HeapFree
kernel32.dll.TerminateProcess
kernel32.dll.GetCurrentProcess
kernel32.dll.UnhandledExceptionFilter
kernel32.dll.FreeEnvironmentStringsA
kernel32.dll.FreeEnvironmentStringsW
kernel32.dll.GetEnvironmentStrings
kernel32.dll.GetEnvironmentStringsW
kernel32.dll.SetHandleCount
kernel32.dll.GetStdHandle
kernel32.dll.GetFileType
kernel32.dll.GetEnvironmentVariableA
kernel32.dll.GetVersionExA
kernel32.dll.HeapDestroy
kernel32.dll.HeapCreate
kernel32.dll.VirtualFree
kernel32.dll.RtlUnwind
kernel32.dll.HeapReAlloc
kernel32.dll.GetCPInfo
kernel32.dll.GetACP
kernel32.dll.GetOEMCP
kernel32.dll.SetStdHandle
kernel32.dll.MultiByteToWideChar
kernel32.dll.LCMapStringA
kernel32.dll.LCMapStringW
kernel32.dll.FlushFileBuffers
shell32.dll.ShellExecuteA
kernel32.dll.SortGetHandle
kernel32.dll.SortCloseHandle
kernel32.dll.InterlockedDecrement
kernel32.dll.InterlockedIncrement
kernel32.dll.lstrcpynA
kernel32.dll.DeleteFileA
kernel32.dll.SetFileAttributesA
kernel32.dll.GetSystemDirectoryA
kernel32.dll.FreeLibrary
kernel32.dll.LoadLibraryExA
kernel32.dll.OpenProcess
kernel32.dll.Module32Next
kernel32.dll.Module32First
kernel32.dll.CreateToolhelp32Snapshot
kernel32.dll.Process32Next
kernel32.dll.Process32First
kernel32.dll.GetFileAttributesA
kernel32.dll.RemoveDirectoryA
kernel32.dll.FindClose
kernel32.dll.FindNextFileA
kernel32.dll.FindFirstFileA
kernel32.dll.WritePrivateProfileStringA
kernel32.dll.GetPrivateProfileStringA
kernel32.dll.SetFileTime
kernel32.dll.IsBadWritePtr
kernel32.dll.GetFileTime
kernel32.dll.GetLocalTime
kernel32.dll.CreateProcessA
kernel32.dll.GetDriveTypeA
kernel32.dll.CreateRemoteThread
kernel32.dll.WriteProcessMemory
kernel32.dll.VirtualAllocEx
kernel32.dll.GetProcessHeap
kernel32.dll.GetCurrentThread
kernel32.dll.SystemTimeToFileTime
kernel32.dll.GetSystemTime
kernel32.dll.FileTimeToSystemTime
kernel32.dll.GetLogicalDrives
kernel32.dll.GetWindowsDirectoryA
kernel32.dll.GetComputerNameA
kernel32.dll.InitializeCriticalSection
kernel32.dll.GlobalAlloc
kernel32.dll.GlobalFree
kernel32.dll.lstrcpyA
kernel32.dll.InterlockedExchange
kernel32.dll.WaitForSingleObject
kernel32.dll.ExitThread
kernel32.dll.EnterCriticalSection
kernel32.dll.LeaveCriticalSection
advapi32.dll.AdjustTokenPrivileges
advapi32.dll.LookupAccountSidA
advapi32.dll.RegEnumKeyExA
advapi32.dll.RegDeleteKeyA
advapi32.dll.RegEnumValueA
advapi32.dll.RegDeleteValueA
advapi32.dll.RegQueryValueExA
advapi32.dll.GetUserNameA
advapi32.dll.RegOpenKeyExA
advapi32.dll.RegCreateKeyA
advapi32.dll.RegSetValueExA
advapi32.dll.LookupPrivilegeValueA
advapi32.dll.OpenProcessToken
advapi32.dll.OpenThreadToken
advapi32.dll.GetTokenInformation
msvcrt.dll._except_handler3
user32.dll.CharUpperA
user32.dll.CharLowerA
ws2_32.dll.#20
ws2_32.dll.#23
ws2_32.dll.#18
ws2_32.dll.#9
ws2_32.dll.#2
ws2_32.dll.#21
ws2_32.dll.#52
ws2_32.dll.#11
ws2_32.dll.#115
ws2_32.dll.#17
ws2_32.dll.#3
ws2_32.dll.#15
mpr.dll.WNetEnumResourceA
mpr.dll.WNetOpenEnumA
mpr.dll.WNetCloseEnum
wininet.dll.InternetCloseHandle
wininet.dll.InternetReadFile
wininet.dll.InternetOpenUrlA
wininet.dll.InternetOpenA
sfc.dll.SfcIsFileProtected
sechost.dll.LookupAccountSidLocalA
oleaut32.dll.#200
ole32.dll.CoInitializeEx
cryptbase.dll.SystemFunction036
comctl32.dll.#385
comctl32.dll.#320
comctl32.dll.#324
comctl32.dll.#323
ole32.dll.CreateBindCtx
ole32.dll.CoTaskMemAlloc
ole32.dll.CoGetApartmentType
ole32.dll.CoRegisterInitializeSpy
ole32.dll.CoTaskMemFree
comctl32.dll.#236
oleaut32.dll.#6
ole32.dll.CoGetMalloc
ole32.dll.StringFromGUID2
comctl32.dll.#328
comctl32.dll.#334
oleaut32.dll.#2
ole32.dll.CoCreateInstance
setupapi.dll.CM_Get_Device_Interface_List_Size_ExW
setupapi.dll.CM_Get_Device_Interface_List_ExW
advapi32.dll.InitializeSecurityDescriptor
advapi32.dll.SetEntriesInAclW
ntmarta.dll.GetMartaExtensionInterface
advapi32.dll.SetSecurityDescriptorDacl
advapi32.dll.IsTextUnicode
comctl32.dll.#332
comctl32.dll.#338
comctl32.dll.#339
comctl32.dll.#386
shell32.dll.#102
propsys.dll.PSLookupPropertyHandlerCLSID
propsys.dll.PSCreatePropertyStoreFromObject
propsys.dll.#417
propsys.dll.PropVariantToStringAlloc
ole32.dll.PropVariantClear
propsys.dll.PropVariantToBoolean
propsys.dll.VariantToUInt64
propsys.dll.InitPropVariantFromBuffer
propsys.dll.PropVariantToBuffer
uxJLpe1m
smss.exeM_208_
csrss.exeM_284_
wininit.exeM_332_
csrss.exeM_340_
winlogon.exeM_368_
services.exeM_428_
lsass.exeM_436_
lsm.exeM_444_
svchost.exeM_540_
svchost.exeM_620_
svchost.exeM_716_
svchost.exeM_768_
svchost.exeM_792_
svchost.exeM_900_
svchost.exeM_1004_
svchost.exeM_524_
imedictupdate.exeM_1028_
msiexec.exeM_1092_
taskhost.exeM_1384_
svchost.exeM_1520_
dwm.exeM_1552_
explorer.exeM_1600_
wscript.exeM_1916_
iexplore.exeM_2044_
winword.exeM_292_
acrord32.exeM_276_
excel.exeM_1152_
powerpnt.exeM_1248_
cmd.exeM_1404_
conhost.exeM_568_
iexplore.exeM_1228_

PE 信息

初始地址 0x00400000
入口地址 0x00418ca0
声明校验值 0x00000000
实际校验值 0x007de169
最低操作系统版本要求 4.0
编译时间 2009-11-06 14:21:39
载入哈希 575ea90c069471216fa3adaba586119e

PE 数据组成

名称 虚拟地址 虚拟大小 原始数据大小 特征 熵(Entropy)
UPX0 0x00001000 0x0000f000 0x00000000 IMAGE_SCN_CNT_UNINITIALIZED_DATA|IMAGE_SCN_MEM_EXECUTE|IMAGE_SCN_MEM_READ|IMAGE_SCN_MEM_WRITE 0.00
UPX1 0x00010000 0x00009000 0x00009000 IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_EXECUTE|IMAGE_SCN_MEM_READ|IMAGE_SCN_MEM_WRITE 7.88
.rsrc 0x00019000 0x00015000 0x00015000 IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_EXECUTE|IMAGE_SCN_MEM_READ|IMAGE_SCN_MEM_WRITE 7.89

覆盖

偏移量 0x0001e400
大小 0x007b9b21

导入

库: KERNEL32.DLL:
0x41b6a0 LoadLibraryA
0x41b6a4 GetProcAddress
0x41b6a8 VirtualProtect
0x41b6ac ExitProcess
库: SHELL32.dll:
0x41b6b4 ShellExecuteA

$BN}"DNRich|"DN
.rsrc
ba[}+
c^Oat1
KERNEL32.DLL
SHELL32.dll
LoadLibraryA
GetProcAddress
VirtualProtect
ExitProcess
ShellExecuteA
xX\H*
GyoTx
没有防病毒引擎扫描信息!

进程树


CF-__________________.exe, PID: 2644, 上一级进程 PID: 2296

访问主机纪录 (可点击查询WPING实时安全评级)

直接 IP 安全评级 地理位置
201.24.159.221 巴西
85.17.167.196 荷兰
88.248.141.201 土耳其

TCP

无TCP连接纪录.

UDP

源地址 源端口 目标地址 目标端口
192.168.122.201 59259 201.24.159.221 8590
192.168.122.201 59258 85.17.167.196 9832
192.168.122.201 59260 88.248.141.201 6018

域名解析 (可点击查询WPING实时安全评级)

无域名信息.

TCP

无TCP连接纪录.

UDP

源地址 源端口 目标地址 目标端口
192.168.122.201 59259 201.24.159.221 8590
192.168.122.201 59258 85.17.167.196 9832
192.168.122.201 59260 88.248.141.201 6018

HTTP 请求

未发现HTTP请求.

SMTP 流量

无SMTP流量.

IRC 流量

无IRC请求.

ICMP 流量

源地址 目标地址 ICMP类型 数据
81.17.33.109 192.168.122.201 3

CIF 报告

无 CIF 结果

网络警报

无警报

TLS

No TLS

Suricata HTTP

No Suricata HTTP

未发现网络提取文件
抱歉! 没有任何文件投放。
没有发现相似的分析.
HTML 总结报告
(需15-60分钟同步)
下载

Processing ( 48.197 seconds )

  • 19.318 Static
  • 15.546 Suricata
  • 9.52 TargetInfo
  • 1.408 VirusTotal
  • 1.377 NetworkAnalysis
  • 0.462 BehaviorAnalysis
  • 0.44 peid
  • 0.085 AnalysisInfo
  • 0.023 config_decoder
  • 0.015 Strings
  • 0.003 Memory

Signatures ( 0.386 seconds )

  • 0.052 antiav_detectreg
  • 0.023 infostealer_ftp
  • 0.021 api_spamming
  • 0.021 md_domain_bl
  • 0.02 md_url_bl
  • 0.017 stealth_timeout
  • 0.015 stealth_decoy_document
  • 0.014 anomaly_persistence_autorun
  • 0.013 infostealer_im
  • 0.01 antianalysis_detectreg
  • 0.009 antiav_detectfile
  • 0.007 infostealer_mail
  • 0.007 ransomware_extensions
  • 0.007 ransomware_files
  • 0.006 infostealer_bitcoin
  • 0.005 antivm_generic_scsi
  • 0.005 disables_browser_warn
  • 0.004 ransomware_dmalocker
  • 0.004 mimics_filetime
  • 0.004 sets_autoconfig_url
  • 0.004 kovter_behavior
  • 0.004 antivm_vbox_files
  • 0.004 geodo_banking_trojan
  • 0.003 tinba_behavior
  • 0.003 antiemu_wine_func
  • 0.003 bootkit
  • 0.003 dridex_behavior
  • 0.003 stealth_file
  • 0.003 anomaly_persistence_bootexecute
  • 0.003 anomaly_reset_winsock
  • 0.003 kelihos_behavior
  • 0.003 betabot_behavior
  • 0.003 reads_self
  • 0.003 kibex_behavior
  • 0.003 antivm_generic_disk
  • 0.003 infostealer_browser_password
  • 0.003 vawtrak_behavior
  • 0.003 virus
  • 0.003 antivm_xen_keys
  • 0.003 browser_security
  • 0.003 md_bad_drop
  • 0.002 banker_prinimalka
  • 0.002 rat_nanocore
  • 0.002 antivm_generic_services
  • 0.002 creates_largekey
  • 0.002 anormaly_invoke_kills
  • 0.002 cerber_behavior
  • 0.002 injection_runpe
  • 0.002 pony_behavior
  • 0.002 hancitor_behavior
  • 0.002 antivm_parallels_keys
  • 0.002 browser_addon
  • 0.002 modify_proxy
  • 0.002 darkcomet_regkeys
  • 0.002 recon_fingerprint
  • 0.001 network_tor
  • 0.001 antivm_vbox_libs
  • 0.001 injection_createremotethread
  • 0.001 ursnif_behavior
  • 0.001 shifu_behavior
  • 0.001 exec_crash
  • 0.001 maldun_suspicious
  • 0.001 antianalysis_detectfile
  • 0.001 antidbg_devices
  • 0.001 antisandbox_productid
  • 0.001 antivm_generic_diskreg
  • 0.001 antivm_xen_keys
  • 0.001 antivm_vbox_acpi
  • 0.001 antivm_vmware_keys
  • 0.001 antivm_vpc_keys
  • 0.001 banker_zeus_mutex
  • 0.001 bot_drive
  • 0.001 bot_drive2
  • 0.001 disables_system_restore
  • 0.001 disables_windows_defender
  • 0.001 malicious_drop_executable_file_to_temp_folder
  • 0.001 office_security
  • 0.001 packer_armadillo_regkey
  • 0.001 ransomware_radamant
  • 0.001 rat_pcclient
  • 0.001 rat_spynet
  • 0.001 stealth_hide_notifications
  • 0.001 stealth_modify_uac_prompt

Reporting ( 1.128 seconds )

  • 0.858 ReportHTMLSummary
  • 0.27 Malheur
Task ID 312247
Mongo ID 5d0a916e2f8f2e42515e2d5c
Cuckoo release 1.4-Maldun