魔盾安全分析报告

分析类型 开始时间 结束时间 持续时间 分析引擎版本
FILE 2019-12-09 18:13:02 2019-12-09 18:15:38 156 秒 1.4-Maldun
虚拟机机器名 标签 虚拟机管理 开机时间 关机时间
win7-sp1-x64-hpdapp01-1 win7-sp1-x64-hpdapp01-1 KVM 2019-12-09 18:13:21 2019-12-09 18:15:39
魔盾分数

10.0

恶意的

文件详细信息

文件名 MasterZ_Custom_93.exe
文件大小 10454664 字节
文件类型 PE32 executable (GUI) Intel 80386, for MS Windows, Nullsoft Installer self-extracting archive
CRC32 8F240AE4
MD5 70028b45526712f0a0e2e303c9832ad3
SHA1 59d669e7beae9d90d1cbd67a7422446bb85e80a4
SHA256 9a7d4bdcf84cec14b83c9442bbc97aeac78429273bb313c70d5bc8f203be2b0a
SHA512 693f13e85ded9b60a417b463bb246d3ece24b90bac9aea68203ad0fa2a342ae5d6ef7b32cf740f4a96b8ad47be923249c5ce99f47c89e025e1d5067de7c72ee8
Ssdeep 196608:oIOwfMKp3AN4Jzt4x7QC/lp+9xSH94pqWKCjagaGnDSO0uUXlYpVILJ8:oIEKp3g4ht4xSmHOqij0Gni+VI
PEiD 无匹配
Yara
  • DebuggerTiming__Ticks (Detected timing ticks function)
  • screenshot (Detected take screenshot function)
  • create_process (Detection function for creating a new process)
  • escalate_priv (Detected escalate priviledges function)
  • win_registry (Detected system registries modification function)
  • win_token (Affect system token)
  • win_files_operation (Affect private profile)
  • Maldun_Anomoly_Combined_Activities_7 (Spotted potential malicious behaviors from a small size target, like process manipultion, privilege, token and files)
  • with_urls (Detected the presence of an or several urls)
  • CRC32_poly_Constant (Look for CRC32 [poly])
  • IsPE32 (Detected a 32bit PE sample)
  • IsWindowsGUI (Detected a Windows GUI sample)
  • IsPacked (Detected Entropy signature)
  • HasOverlay (Detected Overlay signature)
  • HasDigitalSignature (Detected Digital Signature)
  • HasRichSignature (Detected Rich Signature)
VirusTotal VirusTotal链接
VirusTotal扫描时间: 2019-12-09 10:01:14
扫描结果: 2/70

特征

样本的签名证书合法
创建RWX内存
魔盾安全Yara检测结果 - 普通
Critical: Spotted potential malicious behaviors from a small size target, like process manipultion, privilege, token and files
生成可疑网络流量,可能被用来进行恶意活动
signature: SURICATA Applayer Detect protocol only one direction
多次尝试建立挂起的进程
强制将一个创建的进程加载为另一个不相关进程的子进程
装载一个驱动器
driver service name: \Registry\Machine\System\CurrentControlSet\Services\HTTP
一个进程创建了一个隐藏窗口
Process: MasterZ_Custom_93.exe -> taskkill
Process: MasterZ_Custom_93.exe -> taskkill
文件已被至少一个VirusTotal上的反病毒引擎检测为病毒
VIPRE: Dialer.Win32.GBDialer.i (v)
DrWeb: DLOADER.Trojan
检测到样本尝试异常命令
Anomaly: C:\Users\test\AppData\Roaming\szw\MasterZ\bin\KillService.bat executed
异常的多次引用终止程序实例
通过进程尝试长时间延迟分析任务
Process: taskkill.exe tried to sleep 120 seconds, actually delayed analysis time by 0 seconds
Process: netsh.exe tried to sleep 1500 seconds, actually delayed analysis time by 0 seconds
异常的多次调用CMD
Command: cmd.exe /c net stop autorunser
Command: cmd.exe /c "c:\users\test\appdata\roaming\szw\masterz\bin\deamon.exe" -remove
可能是恶意的样本写入可疑的执行文件并混淆扩展名
Suspicious: c:\users\test\appdata\local\temp\nse53bc.tmp
Suspicious: c:\users\test\appdata\local\temp\nsz628c.tmp
Suspicious: c:\users\test\appdata\local\temp\nsz628c.tmp
Suspicious: c:\users\test\appdata\local\temp\nsz628c.tmp
Suspicious: c:\users\test\appdata\local\temp\nsz628c.tmp
Suspicious: c:\users\test\appdata\local\temp\nsz628c.tmp
Suspicious: c:\users\test\appdata\local\temp\nsz628c.tmp
Suspicious: c:\users\test\appdata\local\temp\nsz628c.tmp
Suspicious: c:\users\test\appdata\local\temp\nsz628c.tmp
Suspicious: c:\users\test\appdata\local\temp\nsz628c.tmp
Suspicious: c:\users\test\appdata\local\temp\nsz628c.tmp
Suspicious: c:\users\test\appdata\local\temp\nsz628c.tmp
Suspicious: c:\users\test\appdata\local\temp\nsz628c.tmp
Suspicious: c:\users\test\appdata\local\temp\nsz628c.tmp
Suspicious: c:\users\test\appdata\local\temp\nsz628c.tmp
Suspicious: c:\users\test\appdata\local\temp\nsz628c.tmp
Suspicious: c:\users\test\appdata\local\temp\nsz628c.tmp
Suspicious: c:\users\test\appdata\local\temp\nsz628c.tmp
Suspicious: c:\users\test\appdata\local\temp\nsz628c.tmp
Suspicious: c:\users\test\appdata\local\temp\nsz628c.tmp
Suspicious: c:\users\test\appdata\local\temp\nsz628c.tmp
Suspicious: c:\users\test\appdata\local\temp\nsz628c.tmp
Suspicious: c:\users\test\appdata\local\temp\nsz628c.tmp
Suspicious: c:\users\test\appdata\local\temp\nsz628c.tmp
Suspicious: c:\users\test\appdata\local\temp\nsz628c.tmp
Suspicious: c:\users\test\appdata\local\temp\nsz628c.tmp
Suspicious: c:\users\test\appdata\local\temp\nsz628c.tmp
Suspicious: c:\users\test\appdata\local\temp\nsz628c.tmp
Suspicious: c:\users\test\appdata\local\temp\nsz628c.tmp
Suspicious: c:\users\test\appdata\local\temp\nsz628c.tmp
Suspicious: c:\users\test\appdata\local\temp\nsz628c.tmp
Suspicious: c:\users\test\appdata\local\temp\nsz628c.tmp
Suspicious: c:\users\test\appdata\local\temp\nsz628c.tmp
Suspicious: c:\users\test\appdata\local\temp\nsz628c.tmp
Suspicious: c:\users\test\appdata\local\temp\nsz628c.tmp
Suspicious: c:\users\test\appdata\local\temp\nsz628c.tmp
Suspicious: c:\users\test\appdata\local\temp\nsz628c.tmp
Suspicious: c:\users\test\appdata\local\temp\nsz628c.tmp
Suspicious: c:\users\test\appdata\local\temp\nsz628c.tmp
Suspicious: c:\users\test\appdata\local\temp\nsz628c.tmp
Suspicious: c:\users\test\appdata\local\temp\nsz628c.tmp
Suspicious: c:\users\test\appdata\local\temp\nsz628c.tmp
Suspicious: c:\users\test\appdata\local\temp\nsz628c.tmp
Suspicious: c:\users\test\appdata\local\temp\nsz628c.tmp
Suspicious: c:\users\test\appdata\local\temp\nsz628c.tmp
Suspicious: c:\users\test\appdata\local\temp\nsz628c.tmp
Suspicious: c:\users\test\appdata\local\temp\nsz628c.tmp
Suspicious: c:\users\test\appdata\local\temp\nsz628c.tmp
Suspicious: c:\users\test\appdata\local\temp\nsz628c.tmp
Suspicious: c:\users\test\appdata\local\temp\nsz628c.tmp
Suspicious: c:\users\test\appdata\local\temp\nsz628c.tmp
Suspicious: c:\users\test\appdata\local\temp\nsz628c.tmp
Suspicious: c:\users\test\appdata\local\temp\nsz628c.tmp
Suspicious: c:\users\test\appdata\local\temp\nsz628c.tmp
Suspicious: c:\users\test\appdata\local\temp\nsz628c.tmp
Suspicious: c:\users\test\appdata\local\temp\nsz628c.tmp
Suspicious: c:\users\test\appdata\local\temp\nsz628c.tmp
Suspicious: c:\users\test\appdata\local\temp\nsz628c.tmp
Suspicious: c:\users\test\appdata\local\temp\nsz628c.tmp
Suspicious: c:\users\test\appdata\local\temp\nsz628c.tmp
Suspicious: c:\users\test\appdata\local\temp\nsz628c.tmp
Suspicious: c:\users\test\appdata\local\temp\nsz628c.tmp
Suspicious: c:\users\test\appdata\local\temp\nsz628c.tmp
Suspicious: c:\users\test\appdata\local\temp\nsz628c.tmp
Suspicious: c:\users\test\appdata\local\temp\nsz628c.tmp
Suspicious: c:\users\test\appdata\local\temp\nsz628c.tmp
Suspicious: c:\users\test\appdata\local\temp\nsz628c.tmp
Suspicious: c:\users\test\appdata\local\temp\nsz628c.tmp
Suspicious: c:\users\test\appdata\local\temp\nsz628c.tmp
Suspicious: c:\users\test\appdata\local\temp\nsz628c.tmp
Suspicious: c:\users\test\appdata\local\temp\nsz628c.tmp
Suspicious: c:\users\test\appdata\local\temp\nsz628c.tmp
Suspicious: c:\users\test\appdata\local\temp\nsz628c.tmp
Suspicious: c:\users\test\appdata\local\temp\nsz628c.tmp
Suspicious: c:\users\test\appdata\local\temp\nsz628c.tmp
Suspicious: c:\users\test\appdata\local\temp\nsz628c.tmp
Suspicious: c:\users\test\appdata\local\temp\nsz628c.tmp
Suspicious: c:\users\test\appdata\local\temp\nsz628c.tmp
Suspicious: c:\users\test\appdata\local\temp\nsz628c.tmp
Suspicious: c:\users\test\appdata\local\temp\nsz628c.tmp
Suspicious: c:\users\test\appdata\local\temp\nsz628c.tmp
Suspicious: c:\users\test\appdata\local\temp\nsz628c.tmp
Suspicious: c:\users\test\appdata\local\temp\nsz628c.tmp
Suspicious: c:\users\test\appdata\local\temp\nsz628c.tmp
Suspicious: c:\users\test\appdata\local\temp\nsz628c.tmp
Suspicious: c:\users\test\appdata\local\temp\nsz628c.tmp
Suspicious: c:\users\test\appdata\local\temp\nsz628c.tmp
Suspicious: c:\users\test\appdata\local\temp\nsz628c.tmp
Suspicious: c:\users\test\appdata\local\temp\nsz628c.tmp
Suspicious: c:\users\test\appdata\local\temp\nsz628c.tmp
Suspicious: c:\users\test\appdata\local\temp\nsz628c.tmp
Suspicious: c:\users\test\appdata\local\temp\nsz628c.tmp
Suspicious: c:\users\test\appdata\local\temp\nsz628c.tmp
Suspicious: c:\users\test\appdata\local\temp\nsz628c.tmp
Suspicious: c:\users\test\appdata\local\temp\nsz628c.tmp
Suspicious: c:\users\test\appdata\local\temp\nsz628c.tmp
Suspicious: c:\users\test\appdata\local\temp\nsz628c.tmp
Suspicious: c:\users\test\appdata\local\temp\nsz628c.tmp
Suspicious: c:\users\test\appdata\local\temp\nsz628c.tmp
Suspicious: c:\users\test\appdata\local\temp\nsz628c.tmp
Suspicious: c:\users\test\appdata\local\temp\nsz628c.tmp
Suspicious: c:\users\test\appdata\local\temp\nsz628c.tmp
Suspicious: c:\users\test\appdata\local\temp\nsz628c.tmp
Suspicious: c:\users\test\appdata\local\temp\nsz628c.tmp
Suspicious: c:\users\test\appdata\local\temp\nsz628c.tmp
Suspicious: c:\users\test\appdata\local\temp\nsz628c.tmp
Suspicious: c:\users\test\appdata\local\temp\nsz628c.tmp
Suspicious: c:\users\test\appdata\local\temp\nsz628c.tmp
Suspicious: c:\users\test\appdata\local\temp\nsz628c.tmp
Suspicious: c:\users\test\appdata\local\temp\nsz628c.tmp
Suspicious: c:\users\test\appdata\local\temp\nsz628c.tmp
Suspicious: c:\users\test\appdata\local\temp\nsz628c.tmp
Suspicious: c:\users\test\appdata\local\temp\nsz628c.tmp
Suspicious: c:\users\test\appdata\local\temp\nsz628c.tmp
Suspicious: c:\users\test\appdata\local\temp\nsz628c.tmp
Suspicious: c:\users\test\appdata\local\temp\nsz628c.tmp
Suspicious: c:\users\test\appdata\local\temp\nsz628c.tmp
Suspicious: c:\users\test\appdata\local\temp\nsz628c.tmp
Suspicious: c:\users\test\appdata\local\temp\nsz628c.tmp
Suspicious: c:\users\test\appdata\local\temp\nsz628c.tmp
Suspicious: c:\users\test\appdata\local\temp\nsz628c.tmp
Suspicious: c:\users\test\appdata\local\temp\nsz628c.tmp
Suspicious: c:\users\test\appdata\local\temp\nsz628c.tmp
Suspicious: c:\users\test\appdata\local\temp\nsz628c.tmp
Suspicious: c:\users\test\appdata\local\temp\nsz628c.tmp
Suspicious: c:\users\test\appdata\local\temp\nsz628c.tmp
Suspicious: c:\users\test\appdata\local\temp\nsz628c.tmp
Suspicious: c:\users\test\appdata\local\temp\nsz628c.tmp
Suspicious: c:\users\test\appdata\local\temp\nsz628c.tmp
Suspicious: c:\users\test\appdata\local\temp\nsz628c.tmp
Suspicious: c:\users\test\appdata\local\temp\nsz628c.tmp
Suspicious: c:\users\test\appdata\local\temp\nsz628c.tmp
Suspicious: c:\users\test\appdata\local\temp\nsz628c.tmp
Suspicious: c:\users\test\appdata\local\temp\nsz628c.tmp
Suspicious: c:\users\test\appdata\local\temp\nsz628c.tmp
Suspicious: c:\users\test\appdata\local\temp\nsz628c.tmp
Suspicious: c:\users\test\appdata\local\temp\nsz628c.tmp
Suspicious: c:\users\test\appdata\local\temp\nsz628c.tmp
Suspicious: c:\users\test\appdata\local\temp\nsz628c.tmp
Suspicious: c:\users\test\appdata\local\temp\nsz628c.tmp
Suspicious: c:\users\test\appdata\local\temp\nsz628c.tmp
Suspicious: c:\users\test\appdata\local\temp\nsz628c.tmp
Suspicious: c:\users\test\appdata\local\temp\nsz628c.tmp
Suspicious: c:\users\test\appdata\local\temp\nsz628c.tmp
Suspicious: c:\users\test\appdata\local\temp\nsz628c.tmp
Suspicious: c:\users\test\appdata\local\temp\nsz628c.tmp
Suspicious: c:\users\test\appdata\local\temp\nsz628c.tmp
Suspicious: c:\users\test\appdata\local\temp\nsz628c.tmp
Suspicious: c:\users\test\appdata\local\temp\nsz628c.tmp
Suspicious: c:\users\test\appdata\local\temp\nsz628c.tmp
Suspicious: c:\users\test\appdata\local\temp\nsz628c.tmp
Suspicious: c:\users\test\appdata\local\temp\nsz628c.tmp
Suspicious: c:\users\test\appdata\local\temp\nsz628c.tmp
Suspicious: c:\users\test\appdata\local\temp\nsz628c.tmp
Suspicious: c:\users\test\appdata\local\temp\nsz628c.tmp
Suspicious: c:\users\test\appdata\local\temp\nsz628c.tmp
Suspicious: c:\users\test\appdata\local\temp\nsz628c.tmp
Suspicious: c:\users\test\appdata\local\temp\nsz628c.tmp
Suspicious: c:\users\test\appdata\local\temp\nsz628c.tmp
Suspicious: c:\users\test\appdata\local\temp\nsz628c.tmp
Suspicious: c:\users\test\appdata\local\temp\nsz628c.tmp
Suspicious: c:\users\test\appdata\local\temp\nsz628c.tmp
Suspicious: c:\users\test\appdata\local\temp\nsz628c.tmp
Suspicious: c:\users\test\appdata\local\temp\nsz628c.tmp
Suspicious: c:\users\test\appdata\local\temp\nsz628c.tmp
Suspicious: c:\users\test\appdata\local\temp\nsz628c.tmp
Suspicious: c:\users\test\appdata\local\temp\nsz628c.tmp
Suspicious: c:\users\test\appdata\local\temp\nsz628c.tmp
Suspicious: c:\users\test\appdata\local\temp\nsz628c.tmp
Suspicious: c:\users\test\appdata\local\temp\nsz628c.tmp
Suspicious: c:\users\test\appdata\local\temp\nsz628c.tmp
Suspicious: c:\users\test\appdata\local\temp\nsz628c.tmp
Suspicious: c:\users\test\appdata\local\temp\nsz628c.tmp
Suspicious: c:\users\test\appdata\local\temp\nsz628c.tmp
Suspicious: c:\users\test\appdata\local\temp\nsz628c.tmp
Suspicious: c:\users\test\appdata\local\temp\nsz628c.tmp
Suspicious: c:\users\test\appdata\local\temp\nsz628c.tmp
Suspicious: c:\users\test\appdata\local\temp\nsz628c.tmp
Suspicious: c:\users\test\appdata\local\temp\nsz628c.tmp
Suspicious: c:\users\test\appdata\local\temp\nsz628c.tmp
Suspicious: c:\users\test\appdata\local\temp\nsz628c.tmp
Suspicious: c:\users\test\appdata\local\temp\nsz628c.tmp
Suspicious: c:\users\test\appdata\local\temp\nsz628c.tmp
Suspicious: c:\users\test\appdata\local\temp\nsz628c.tmp
Suspicious: c:\users\test\appdata\local\temp\nsz628c.tmp
Suspicious: c:\users\test\appdata\local\temp\nsz628c.tmp
Suspicious: c:\users\test\appdata\local\temp\nsz628c.tmp
Suspicious: c:\users\test\appdata\local\temp\nsz628c.tmp
Suspicious: c:\users\test\appdata\local\temp\nsz628c.tmp
Suspicious: c:\users\test\appdata\local\temp\nsz628c.tmp
Suspicious: c:\users\test\appdata\local\temp\nsz628c.tmp
Suspicious: c:\users\test\appdata\local\temp\nsz628c.tmp
Suspicious: c:\users\test\appdata\local\temp\nsz628c.tmp
Suspicious: c:\users\test\appdata\local\temp\nsz628c.tmp
Suspicious: c:\users\test\appdata\local\temp\nsz628c.tmp
Suspicious: c:\users\test\appdata\local\temp\nsz628c.tmp
Suspicious: c:\users\test\appdata\local\temp\nsz628c.tmp
Suspicious: c:\users\test\appdata\local\temp\nsz628c.tmp
Suspicious: c:\users\test\appdata\local\temp\nsz628c.tmp
Suspicious: c:\users\test\appdata\local\temp\nsz628c.tmp
Suspicious: c:\users\test\appdata\local\temp\nsz628c.tmp
Suspicious: c:\users\test\appdata\local\temp\nsz628c.tmp
Suspicious: c:\users\test\appdata\local\temp\nsz628c.tmp
Suspicious: c:\users\test\appdata\local\temp\nsz628c.tmp
Suspicious: c:\users\test\appdata\local\temp\nsz628c.tmp
Suspicious: c:\users\test\appdata\local\temp\nsz628c.tmp
Suspicious: c:\users\test\appdata\local\temp\nsz628c.tmp
Suspicious: c:\users\test\appdata\local\temp\nsz628c.tmp
Suspicious: c:\users\test\appdata\local\temp\nsz628c.tmp
Suspicious: c:\users\test\appdata\local\temp\nsz628c.tmp
Suspicious: c:\users\test\appdata\local\temp\nsz628c.tmp
Suspicious: c:\users\test\appdata\local\temp\nsz628c.tmp
Suspicious: c:\users\test\appdata\local\temp\nsz628c.tmp
Suspicious: c:\users\test\appdata\local\temp\nsz628c.tmp
Suspicious: c:\users\test\appdata\local\temp\nsz628c.tmp
Suspicious: c:\users\test\appdata\local\temp\nsz628c.tmp
Suspicious: c:\users\test\appdata\local\temp\nsz628c.tmp
Suspicious: c:\users\test\appdata\local\temp\nsz628c.tmp
Suspicious: c:\users\test\appdata\local\temp\nsz628c.tmp
Suspicious: c:\users\test\appdata\local\temp\nsz628c.tmp
Suspicious: c:\users\test\appdata\local\temp\nsz628c.tmp
Suspicious: c:\users\test\appdata\local\temp\nsz628c.tmp
Suspicious: c:\users\test\appdata\local\temp\nsz628c.tmp
Suspicious: c:\users\test\appdata\local\temp\nsz628c.tmp
Suspicious: c:\users\test\appdata\local\temp\nsz628c.tmp
Suspicious: c:\users\test\appdata\local\temp\nsz628c.tmp
Suspicious: c:\users\test\appdata\local\temp\nsz628c.tmp
Suspicious: c:\users\test\appdata\local\temp\nsz628c.tmp
Suspicious: c:\users\test\appdata\local\temp\nsz628c.tmp
Suspicious: c:\users\test\appdata\local\temp\nsz628c.tmp
Suspicious: c:\users\test\appdata\local\temp\nsz628c.tmp
Suspicious: c:\users\test\appdata\local\temp\nsz628c.tmp
Suspicious: c:\users\test\appdata\local\temp\nsz628c.tmp
Suspicious: c:\users\test\appdata\local\temp\nsz628c.tmp
Suspicious: c:\users\test\appdata\local\temp\nsz628c.tmp
Suspicious: c:\users\test\appdata\local\temp\nsz628c.tmp
Suspicious: c:\users\test\appdata\local\temp\nsz628c.tmp
Suspicious: c:\users\test\appdata\local\temp\nsz628c.tmp
Suspicious: c:\users\test\appdata\local\temp\nsz628c.tmp
Suspicious: c:\users\test\appdata\local\temp\nsz628c.tmp
Suspicious: c:\users\test\appdata\local\temp\nsz628c.tmp
Suspicious: c:\users\test\appdata\local\temp\nsz628c.tmp
Suspicious: c:\users\test\appdata\local\temp\nsz628c.tmp
Suspicious: c:\users\test\appdata\local\temp\nsz628c.tmp
Suspicious: c:\users\test\appdata\local\temp\nsz628c.tmp
Suspicious: c:\users\test\appdata\local\temp\nsz628c.tmp
Suspicious: c:\users\test\appdata\local\temp\nsz628c.tmp
Suspicious: c:\users\test\appdata\local\temp\nsz628c.tmp
Suspicious: c:\users\test\appdata\local\temp\nsz628c.tmp
Suspicious: c:\users\test\appdata\local\temp\nsz628c.tmp
Suspicious: c:\users\test\appdata\local\temp\nsz628c.tmp
Suspicious: c:\users\test\appdata\local\temp\nsz628c.tmp
Suspicious: c:\users\test\appdata\local\temp\nsz628c.tmp
Suspicious: c:\users\test\appdata\local\temp\nsz628c.tmp
Suspicious: c:\users\test\appdata\local\temp\nsz628c.tmp
Suspicious: c:\users\test\appdata\local\temp\nsz628c.tmp
Suspicious: c:\users\test\appdata\local\temp\nsz628c.tmp
Suspicious: c:\users\test\appdata\local\temp\nsz628c.tmp
Suspicious: c:\users\test\appdata\local\temp\nsz628c.tmp
Suspicious: c:\users\test\appdata\local\temp\nsz628c.tmp
Suspicious: c:\users\test\appdata\local\temp\nsz628c.tmp
Suspicious: c:\users\test\appdata\local\temp\nsz628c.tmp
Suspicious: c:\users\test\appdata\local\temp\nsz628c.tmp
Suspicious: c:\users\test\appdata\local\temp\nsz628c.tmp
Suspicious: c:\users\test\appdata\local\temp\nsz628c.tmp
Suspicious: c:\users\test\appdata\local\temp\nsz628c.tmp
Suspicious: c:\users\test\appdata\local\temp\nsz628c.tmp
Suspicious: c:\users\test\appdata\local\temp\nsz628c.tmp
Suspicious: c:\users\test\appdata\local\temp\nsz628c.tmp
Suspicious: c:\users\test\appdata\local\temp\nsz628c.tmp
Suspicious: c:\users\test\appdata\local\temp\nsz628c.tmp
Suspicious: c:\users\test\appdata\local\temp\nsz628c.tmp
Suspicious: c:\users\test\appdata\local\temp\nsz628c.tmp
Suspicious: c:\users\test\appdata\local\temp\nsz628c.tmp
Suspicious: c:\users\test\appdata\local\temp\nsz628c.tmp
Suspicious: c:\users\test\appdata\local\temp\nsz628c.tmp
Suspicious: c:\users\test\appdata\local\temp\nsz628c.tmp
Suspicious: c:\users\test\appdata\local\temp\nsz628c.tmp
Suspicious: c:\users\test\appdata\local\temp\nsz628c.tmp
Suspicious: c:\users\test\appdata\local\temp\nsz628c.tmp
Suspicious: c:\users\test\appdata\local\temp\nsz628c.tmp
Suspicious: c:\users\test\appdata\local\temp\nsz628c.tmp
Suspicious: c:\users\test\appdata\local\temp\nsz628c.tmp
Suspicious: c:\users\test\appdata\local\temp\nsz628c.tmp
Suspicious: c:\users\test\appdata\local\temp\nsz628c.tmp
Suspicious: c:\users\test\appdata\local\temp\nsz628c.tmp
Suspicious: c:\users\test\appdata\local\temp\nsz628c.tmp
Suspicious: c:\users\test\appdata\local\temp\nsz628c.tmp
Suspicious: c:\users\test\appdata\local\temp\nsz628c.tmp
Suspicious: c:\users\test\appdata\local\temp\nsz628c.tmp
Suspicious: c:\users\test\appdata\local\temp\nsz628c.tmp
Suspicious: c:\users\test\appdata\local\temp\nsz628c.tmp
Suspicious: c:\users\test\appdata\local\temp\nsz628c.tmp
Suspicious: c:\users\test\appdata\local\temp\nsz628c.tmp
Suspicious: c:\users\test\appdata\local\temp\nsz628c.tmp
Suspicious: c:\users\test\appdata\local\temp\nsz628c.tmp
Suspicious: c:\users\test\appdata\local\temp\nsz628c.tmp
Suspicious: c:\users\test\appdata\local\temp\nsz628c.tmp
Suspicious: c:\users\test\appdata\local\temp\nsz628c.tmp
Suspicious: c:\users\test\appdata\local\temp\nsz628c.tmp
Suspicious: c:\users\test\appdata\local\temp\nsz628c.tmp
Suspicious: c:\users\test\appdata\local\temp\nsz628c.tmp
Suspicious: c:\users\test\appdata\local\temp\nsz628c.tmp
Suspicious: c:\users\test\appdata\local\temp\nsz628c.tmp
Suspicious: c:\users\test\appdata\local\temp\nsz628c.tmp
Suspicious: c:\users\test\appdata\local\temp\nsz628c.tmp
Suspicious: c:\users\test\appdata\local\temp\nsz628c.tmp
Suspicious: c:\users\test\appdata\local\temp\nsz628c.tmp
Suspicious: c:\users\test\appdata\local\temp\nsz628c.tmp
Suspicious: c:\users\test\appdata\local\temp\nsz628c.tmp
Suspicious: c:\users\test\appdata\local\temp\nsz628c.tmp
Suspicious: c:\users\test\appdata\local\temp\nsz628c.tmp
Suspicious: c:\users\test\appdata\local\temp\nsz628c.tmp
Suspicious: c:\users\test\appdata\local\temp\nsz628c.tmp
Suspicious: c:\users\test\appdata\local\temp\nsz628c.tmp
Suspicious: c:\users\test\appdata\local\temp\nsz628c.tmp
Suspicious: c:\users\test\appdata\local\temp\nsz628c.tmp
Suspicious: c:\users\test\appdata\local\temp\nsz628c.tmp
Suspicious: c:\users\test\appdata\local\temp\nsz628c.tmp
Suspicious: c:\users\test\appdata\local\temp\nsz628c.tmp
Suspicious: c:\users\test\appdata\local\temp\nsz628c.tmp
Suspicious: c:\users\test\appdata\local\temp\nsz628c.tmp
Suspicious: c:\users\test\appdata\local\temp\nsz628c.tmp
Suspicious: c:\users\test\appdata\local\temp\nsz628c.tmp
Suspicious: c:\users\test\appdata\local\temp\nsz628c.tmp
Suspicious: c:\users\test\appdata\local\temp\nsz628c.tmp
Suspicious: c:\users\test\appdata\local\temp\nsz628c.tmp
Suspicious: c:\users\test\appdata\local\temp\nsz628c.tmp
Suspicious: c:\users\test\appdata\local\temp\nsz628c.tmp
Suspicious: c:\users\test\appdata\local\temp\nsz628c.tmp
Suspicious: c:\users\test\appdata\local\temp\nsz628c.tmp
Suspicious: c:\users\test\appdata\local\temp\nsz628c.tmp
Suspicious: c:\users\test\appdata\local\temp\nsz628c.tmp
Suspicious: c:\users\test\appdata\local\temp\nsz628c.tmp
Suspicious: c:\users\test\appdata\local\temp\nsz628c.tmp
Suspicious: c:\users\test\appdata\local\temp\nsz628c.tmp
Suspicious: c:\users\test\appdata\local\temp\nsz628c.tmp
Suspicious: c:\users\test\appdata\local\temp\nsz628c.tmp
Suspicious: c:\users\test\appdata\local\temp\nsz628c.tmp
Suspicious: c:\users\test\appdata\local\temp\nsz628c.tmp
Suspicious: c:\users\test\appdata\local\temp\nsz628c.tmp
Suspicious: c:\users\test\appdata\local\temp\nsz628c.tmp
Suspicious: c:\users\test\appdata\local\temp\nsz628c.tmp
Suspicious: c:\users\test\appdata\local\temp\nsz628c.tmp
Suspicious: c:\users\test\appdata\local\temp\nsz628c.tmp
Suspicious: c:\users\test\appdata\local\temp\nsz628c.tmp
Suspicious: c:\users\test\appdata\local\temp\nsz628c.tmp
Suspicious: c:\users\test\appdata\local\temp\nsz628c.tmp
Suspicious: c:\users\test\appdata\local\temp\nsz628c.tmp
Suspicious: c:\users\test\appdata\local\temp\nsz628c.tmp
Suspicious: c:\users\test\appdata\local\temp\nsz628c.tmp
Suspicious: c:\users\test\appdata\local\temp\nsz628c.tmp
Suspicious: c:\users\test\appdata\local\temp\nsz628c.tmp
Suspicious: c:\users\test\appdata\local\temp\nsz628c.tmp
Suspicious: c:\users\test\appdata\local\temp\nsz628c.tmp
Suspicious: c:\users\test\appdata\local\temp\nsz628c.tmp
Suspicious: c:\users\test\appdata\local\temp\nsz628c.tmp
Suspicious: c:\users\test\appdata\local\temp\nsz628c.tmp
Suspicious: c:\users\test\appdata\roaming\szw\masterz\bin\skin\problemlist.xml
Suspicious: c:\users\test\appdata\roaming\szw\masterz\bin\skin\problemlist.xml
Suspicious: c:\users\test\appdata\roaming\szw\masterz\bin\skin\problemlist.xml
Suspicious: c:\users\test\appdata\roaming\szw\masterz\bin\skin\problemlist.xml
Suspicious: c:\users\test\appdata\local\temp\nsz628c.tmp
Suspicious: c:\users\test\appdata\local\temp\nsz628c.tmp
Suspicious: c:\users\test\appdata\local\temp\nsz628c.tmp
Suspicious: c:\users\test\appdata\local\temp\nsz628c.tmp
Suspicious: c:\users\test\appdata\local\temp\nsz628c.tmp
Suspicious: c:\users\test\appdata\local\temp\nsz628c.tmp
Suspicious: c:\users\test\appdata\local\temp\nsz628c.tmp
Suspicious: c:\users\test\appdata\local\temp\nsz628c.tmp
Suspicious: c:\users\test\appdata\local\temp\nsz628c.tmp
Suspicious: c:\users\test\appdata\local\temp\nsz628c.tmp
Suspicious: c:\users\test\appdata\local\temp\nsz628c.tmp
Suspicious: c:\users\test\appdata\local\temp\nsz628c.tmp
Suspicious: c:\users\test\appdata\local\temp\nsz628c.tmp
Suspicious: c:\users\test\appdata\local\temp\nsz628c.tmp
Suspicious: c:\users\test\appdata\local\temp\nsz628c.tmp
Suspicious: c:\users\test\appdata\local\temp\nsz628c.tmp
Suspicious: c:\users\test\appdata\local\temp\nsz628c.tmp
Suspicious: c:\users\test\appdata\local\temp\nsz628c.tmp
Suspicious: c:\users\test\appdata\local\temp\nsz628c.tmp
Suspicious: c:\users\test\appdata\local\temp\nsz628c.tmp
Suspicious: c:\users\test\appdata\local\temp\nsz628c.tmp
Suspicious: c:\users\test\appdata\local\temp\nsz628c.tmp
Suspicious: c:\users\test\appdata\local\temp\nsz628c.tmp
Suspicious: c:\users\test\appdata\local\temp\nsz628c.tmp
Suspicious: c:\users\test\appdata\local\temp\nsz628c.tmp
Suspicious: c:\users\test\appdata\local\temp\nsz628c.tmp
Suspicious: c:\users\test\appdata\local\temp\nsz628c.tmp
Suspicious: c:\users\test\appdata\local\temp\nsz628c.tmp
Suspicious: c:\users\test\appdata\local\temp\nsz628c.tmp
Suspicious: c:\users\test\appdata\local\temp\nsz628c.tmp
Suspicious: c:\users\test\appdata\local\temp\nsz628c.tmp
Suspicious: c:\users\test\appdata\local\temp\nsz628c.tmp
Suspicious: c:\users\test\appdata\local\temp\nsz628c.tmp
Suspicious: c:\users\test\appdata\local\temp\nsz628c.tmp
Suspicious: c:\users\test\appdata\local\temp\nsz628c.tmp
Suspicious: c:\users\test\appdata\local\temp\nsz628c.tmp
Suspicious: c:\users\test\appdata\local\temp\nsz628c.tmp
Suspicious: c:\users\test\appdata\local\temp\nsz628c.tmp
Suspicious: c:\users\test\appdata\local\temp\nsz628c.tmp
Suspicious: c:\users\test\appdata\local\temp\nsz628c.tmp
Suspicious: c:\users\test\appdata\local\temp\nsz628c.tmp
Suspicious: c:\users\test\appdata\local\temp\nsz628c.tmp
Suspicious: c:\users\test\appdata\local\temp\nsz628c.tmp
Suspicious: c:\users\test\appdata\local\temp\nsz628c.tmp
Suspicious: c:\users\test\appdata\local\temp\nsz628c.tmp
Suspicious: c:\users\test\appdata\local\temp\nsz628c.tmp
Suspicious: c:\users\test\appdata\local\temp\nsz628c.tmp
Suspicious: c:\users\test\appdata\local\temp\nsz628c.tmp
Suspicious: c:\users\test\appdata\local\temp\nsz628c.tmp
Suspicious: c:\users\test\appdata\local\temp\nsz628c.tmp
Suspicious: c:\users\test\appdata\local\temp\nsz628c.tmp
Suspicious: c:\users\test\appdata\local\temp\nsz628c.tmp
Suspicious: c:\users\test\appdata\local\temp\nsz628c.tmp
Suspicious: c:\users\test\appdata\local\temp\nsz628c.tmp
Suspicious: c:\users\test\appdata\local\temp\nsz628c.tmp
Suspicious: c:\users\test\appdata\local\temp\nsz628c.tmp
Suspicious: c:\users\test\appdata\local\temp\nsz628c.tmp
Suspicious: c:\users\test\appdata\local\temp\nsz628c.tmp
Suspicious: c:\users\test\appdata\local\temp\nsz628c.tmp
Suspicious: c:\users\test\appdata\local\temp\nsz628c.tmp
Suspicious: c:\users\test\appdata\local\temp\nsz628c.tmp
Suspicious: c:\users\test\appdata\local\temp\nsz628c.tmp
Suspicious: c:\users\test\appdata\local\temp\nsz628c.tmp
Suspicious: c:\users\test\appdata\local\temp\nsz628c.tmp
Suspicious: c:\users\test\appdata\local\temp\nsz628c.tmp
Suspicious: c:\users\test\appdata\local\temp\nsz628c.tmp
Suspicious: c:\users\test\appdata\local\temp\nsz628c.tmp
Suspicious: c:\users\test\appdata\local\temp\nsz628c.tmp
Suspicious: c:\users\test\appdata\local\temp\nsz628c.tmp
Suspicious: c:\users\test\appdata\local\temp\nsz628c.tmp
Suspicious: c:\users\test\appdata\local\temp\nsz628c.tmp
Suspicious: c:\users\test\appdata\local\temp\nsz628c.tmp
Suspicious: c:\users\test\appdata\local\temp\nsz628c.tmp
Suspicious: c:\users\test\appdata\local\temp\nsz628c.tmp
Suspicious: c:\users\test\appdata\local\temp\nsz628c.tmp
Suspicious: c:\users\test\appdata\local\temp\nsz628c.tmp
Suspicious: c:\users\test\appdata\local\temp\nsz628c.tmp
Suspicious: c:\users\test\appdata\local\temp\nsz628c.tmp
Suspicious: c:\users\test\appdata\local\temp\nsz628c.tmp
Suspicious: c:\users\test\appdata\local\temp\nsz628c.tmp
Suspicious: c:\users\test\appdata\local\temp\nsz628c.tmp
Suspicious: c:\users\test\appdata\local\temp\nsz628c.tmp
Suspicious: c:\users\test\appdata\local\temp\nsz628c.tmp
Suspicious: c:\users\test\appdata\local\temp\nsz628c.tmp
Suspicious: c:\users\test\appdata\local\temp\nsz628c.tmp
Suspicious: c:\users\test\appdata\local\temp\nsz628c.tmp
Suspicious: c:\users\test\appdata\local\temp\nsz628c.tmp
Suspicious: c:\users\test\appdata\local\temp\nsz628c.tmp
Suspicious: c:\users\test\appdata\local\temp\nsz628c.tmp
Suspicious: c:\users\test\appdata\local\temp\nsz628c.tmp
Suspicious: c:\users\test\appdata\local\temp\nsz628c.tmp
Suspicious: c:\users\test\appdata\local\temp\nsz628c.tmp
Suspicious: c:\users\test\appdata\local\temp\nsz628c.tmp
Suspicious: c:\users\test\appdata\local\temp\nsz628c.tmp
Suspicious: c:\users\test\appdata\local\temp\nsz628c.tmp
Suspicious: c:\users\test\appdata\local\temp\nsz628c.tmp
Suspicious: c:\users\test\appdata\local\temp\nsz628c.tmp
Suspicious: c:\users\test\appdata\local\temp\nsz628c.tmp
Suspicious: c:\users\test\appdata\local\temp\nsz628c.tmp
Suspicious: c:\users\test\appdata\local\temp\nsz628c.tmp
Suspicious: c:\users\test\appdata\local\temp\nsz628c.tmp
Suspicious: c:\users\test\appdata\local\temp\nsz628c.tmp
Suspicious: c:\users\test\appdata\local\temp\nsz628c.tmp
Suspicious: c:\users\test\appdata\local\temp\nsz628c.tmp
Suspicious: c:\users\test\appdata\local\temp\nsz628c.tmp
Suspicious: c:\users\test\appdata\local\temp\nsz628c.tmp
Suspicious: c:\users\test\appdata\local\temp\nsz628c.tmp
Suspicious: c:\users\test\appdata\local\temp\nsz628c.tmp
Suspicious: c:\users\test\appdata\local\temp\nsz628c.tmp
Suspicious: c:\users\test\appdata\local\temp\nsz628c.tmp
Suspicious: c:\users\test\appdata\local\temp\nsz628c.tmp
Suspicious: c:\users\test\appdata\local\temp\nsz628c.tmp
Suspicious: c:\users\test\appdata\local\temp\nsz628c.tmp
Suspicious: c:\users\test\appdata\local\temp\nsz628c.tmp
Suspicious: c:\users\test\appdata\local\temp\nsz628c.tmp
Suspicious: c:\users\test\appdata\local\temp\nsz628c.tmp
Suspicious: c:\users\test\appdata\local\temp\nsz628c.tmp
Suspicious: c:\users\test\appdata\local\temp\nsz628c.tmp
Suspicious: c:\users\test\appdata\local\temp\nsz628c.tmp
Suspicious: c:\users\test\appdata\local\temp\nsz628c.tmp
Suspicious: c:\users\test\appdata\local\temp\nsz628c.tmp
Suspicious: c:\users\test\appdata\local\temp\nsz628c.tmp
Suspicious: c:\users\test\appdata\local\temp\nsz628c.tmp
Suspicious: c:\users\test\appdata\local\temp\nsz628c.tmp
Suspicious: c:\users\test\appdata\local\temp\nsz628c.tmp
Suspicious: c:\users\test\appdata\local\temp\nsz628c.tmp
Suspicious: c:\users\test\appdata\local\temp\nsz628c.tmp
Suspicious: c:\users\test\appdata\local\temp\nsz628c.tmp
Suspicious: c:\users\test\appdata\local\temp\nsz628c.tmp
Suspicious: c:\users\test\appdata\local\temp\nsz628c.tmp
Suspicious: c:\users\test\appdata\local\temp\nsz628c.tmp
Suspicious: c:\users\test\appdata\local\temp\nsz628c.tmp
Suspicious: c:\users\test\appdata\local\temp\nsz628c.tmp
Suspicious: c:\users\test\appdata\local\temp\nsz628c.tmp
Suspicious: c:\users\test\appdata\local\temp\nsz628c.tmp
Suspicious: c:\users\test\appdata\local\temp\nsz628c.tmp
Suspicious: c:\users\test\appdata\local\temp\nsz628c.tmp
Suspicious: c:\users\test\appdata\local\temp\nsz628c.tmp
Suspicious: c:\users\test\appdata\local\temp\nsz628c.tmp
Suspicious: c:\users\test\appdata\local\temp\nsz628c.tmp
Suspicious: c:\users\test\appdata\local\temp\nsz628c.tmp
Suspicious: c:\users\test\appdata\local\temp\nsz628c.tmp
Suspicious: c:\users\test\appdata\local\temp\nsz628c.tmp
Suspicious: c:\users\test\appdata\local\temp\nsz628c.tmp
Suspicious: c:\users\test\appdata\local\temp\nsz628c.tmp
Suspicious: c:\users\test\appdata\local\temp\nsz628c.tmp
Suspicious: c:\users\test\appdata\local\temp\nsz628c.tmp
Suspicious: c:\users\test\appdata\local\temp\nsz628c.tmp
Suspicious: c:\users\test\appdata\local\temp\nsz628c.tmp
Suspicious: c:\users\test\appdata\local\temp\nsz628c.tmp
Suspicious: c:\users\test\appdata\local\temp\nsz628c.tmp
Suspicious: c:\users\test\appdata\local\temp\nsz628c.tmp
Suspicious: c:\users\test\appdata\local\temp\nsz628c.tmp
Suspicious: c:\users\test\appdata\local\temp\nsz628c.tmp
Suspicious: c:\users\test\appdata\local\temp\nsz628c.tmp
Suspicious: c:\users\test\appdata\local\temp\nsz628c.tmp
Suspicious: c:\users\test\appdata\local\temp\nsz628c.tmp
Suspicious: c:\users\test\appdata\local\temp\nsz628c.tmp
Suspicious: c:\users\test\appdata\local\temp\nsz628c.tmp
Suspicious: c:\users\test\appdata\local\temp\nsz628c.tmp
Suspicious: c:\users\test\appdata\local\temp\nsz628c.tmp
Suspicious: c:\users\test\appdata\local\temp\nsz628c.tmp
Suspicious: c:\users\test\appdata\local\temp\nsz628c.tmp
Suspicious: c:\users\test\appdata\local\temp\nsz628c.tmp
Suspicious: c:\users\test\appdata\local\temp\nsz628c.tmp
Suspicious: c:\users\test\appdata\local\temp\nsz628c.tmp
Suspicious: c:\users\test\appdata\local\temp\nsz628c.tmp
Suspicious: c:\users\test\appdata\local\temp\nsz628c.tmp
Suspicious: c:\users\test\appdata\local\temp\nsz628c.tmp
Suspicious: c:\users\test\appdata\local\temp\nsz628c.tmp
Suspicious: c:\users\test\appdata\local\temp\nsz628c.tmp
Suspicious: c:\users\test\appdata\local\temp\nsz628c.tmp
Suspicious: c:\users\test\appdata\local\temp\nsz628c.tmp
Suspicious: c:\users\test\appdata\local\temp\nsz628c.tmp
Suspicious: c:\users\test\appdata\local\temp\nsz628c.tmp
Suspicious: c:\users\test\appdata\local\temp\nsz628c.tmp
Suspicious: c:\users\test\appdata\local\temp\nsz628c.tmp
Suspicious: c:\users\test\appdata\local\temp\nsz628c.tmp
Suspicious: c:\users\test\appdata\local\temp\nsz628c.tmp
Suspicious: c:\users\test\appdata\local\temp\nsz628c.tmp
Suspicious: c:\users\test\appdata\local\temp\nsz628c.tmp
Suspicious: c:\users\test\appdata\local\temp\nsz628c.tmp
Suspicious: c:\users\test\appdata\local\temp\nsz628c.tmp
Suspicious: c:\users\test\appdata\local\temp\nsz628c.tmp
Suspicious: c:\users\test\appdata\local\temp\nsz628c.tmp
Suspicious: c:\users\test\appdata\local\temp\nsz628c.tmp
Suspicious: c:\users\test\appdata\local\temp\nsz628c.tmp
Suspicious: c:\users\test\appdata\local\temp\nsz628c.tmp
Suspicious: c:\users\test\appdata\local\temp\nsz628c.tmp
Suspicious: c:\users\test\appdata\local\temp\nsz628c.tmp
Suspicious: c:\users\test\appdata\local\temp\nsz628c.tmp
Suspicious: c:\users\test\appdata\local\temp\nsz628c.tmp
Suspicious: c:\users\test\appdata\local\temp\nsz628c.tmp
Suspicious: c:\users\test\appdata\local\temp\nsz628c.tmp
Suspicious: c:\users\test\appdata\local\temp\nsz628c.tmp
Suspicious: c:\users\test\appdata\local\temp\nsz628c.tmp
Suspicious: c:\users\test\appdata\local\temp\nsz628c.tmp
Suspicious: c:\users\test\appdata\local\temp\nsz628c.tmp
Suspicious: c:\users\test\appdata\local\temp\nsz628c.tmp
Suspicious: c:\users\test\appdata\local\temp\nsz628c.tmp
Suspicious: c:\users\test\appdata\local\temp\nsz628c.tmp
Suspicious: c:\users\test\appdata\local\temp\nsz628c.tmp
Suspicious: c:\users\test\appdata\local\temp\nsz628c.tmp
Suspicious: c:\users\test\appdata\local\temp\nsz628c.tmp
Suspicious: c:\users\test\appdata\roaming\szw\masterz\bin\skin\problemlist.xml
Suspicious: c:\users\test\appdata\roaming\szw\masterz\bin\skin\problemlist.xml
Suspicious: c:\users\test\appdata\roaming\szw\masterz\bin\skin\problemlist.xml
Suspicious: c:\users\test\appdata\roaming\szw\masterz\bin\skin\problemlist.xml
Suspicious: c:\users\test\appdata\local\temp\nsz628c.tmp
Suspicious: c:\users\test\appdata\local\temp\nsz628c.tmp
Suspicious: c:\users\test\appdata\local\temp\nsz628c.tmp
Suspicious: c:\users\test\appdata\local\temp\nsz628c.tmp
Suspicious: c:\users\test\appdata\local\temp\nsz628c.tmp
Suspicious: c:\users\test\appdata\local\temp\nsz628c.tmp
Suspicious: c:\users\test\appdata\local\temp\nsz628c.tmp
Suspicious: c:\users\test\appdata\local\temp\nsz628c.tmp
Suspicious: c:\users\test\appdata\local\temp\nsz628c.tmp
Suspicious: c:\users\test\appdata\local\temp\nsz628c.tmp
Suspicious: c:\users\test\appdata\local\temp\nsz628c.tmp
Suspicious: c:\users\test\appdata\local\temp\nsz628c.tmp
Suspicious: c:\users\test\appdata\local\temp\nsz628c.tmp
Suspicious: c:\users\test\appdata\local\temp\nsz628c.tmp
Suspicious: c:\users\test\appdata\local\temp\nsz628c.tmp
Suspicious: c:\users\test\appdata\local\temp\nsz628c.tmp
Suspicious: c:\users\test\appdata\local\temp\nsz628c.tmp
Suspicious: c:\users\test\appdata\local\temp\nsz628c.tmp
Suspicious: c:\users\test\appdata\local\temp\nsz628c.tmp
Suspicious: c:\users\test\appdata\local\temp\nsz628c.tmp
Suspicious: c:\users\test\appdata\local\temp\nsz628c.tmp
Suspicious: c:\users\test\appdata\local\temp\nsz628c.tmp
Suspicious: c:\users\test\appdata\local\temp\nsz628c.tmp
Suspicious: c:\users\test\appdata\local\temp\nsz628c.tmp
Suspicious: c:\users\test\appdata\local\temp\nsz628c.tmp
Suspicious: c:\users\test\appdata\local\temp\nsz628c.tmp
Suspicious: c:\users\test\appdata\local\temp\nsz628c.tmp
Suspicious: c:\users\test\appdata\local\temp\nsz628c.tmp
Suspicious: c:\users\test\appdata\local\temp\nsz628c.tmp
Suspicious: c:\users\test\appdata\local\temp\nsz628c.tmp
Suspicious: c:\users\test\appdata\local\temp\nsz628c.tmp
Suspicious: c:\users\test\appdata\local\temp\nsz628c.tmp
Suspicious: c:\users\test\appdata\local\temp\nsz628c.tmp
Suspicious: c:\users\test\appdata\local\temp\nsz628c.tmp
Suspicious: c:\users\test\appdata\local\temp\nsz628c.tmp
Suspicious: c:\users\test\appdata\local\temp\nsz628c.tmp
Suspicious: c:\users\test\appdata\local\temp\nsz628c.tmp
Suspicious: c:\users\test\appdata\local\temp\nsz628c.tmp
Suspicious: c:\users\test\appdata\local\temp\nsz628c.tmp
Suspicious: c:\users\test\appdata\local\temp\nsz628c.tmp
Suspicious: c:\users\test\appdata\local\temp\nsz628c.tmp
Suspicious: c:\users\test\appdata\local\temp\nsz628c.tmp
Suspicious: c:\users\test\appdata\local\temp\nsz628c.tmp
Suspicious: c:\users\test\appdata\local\temp\nsz628c.tmp
Suspicious: c:\users\test\appdata\local\temp\nsz628c.tmp
Suspicious: c:\users\test\appdata\local\temp\nsz628c.tmp
Suspicious: c:\users\test\appdata\local\temp\nsz628c.tmp
Suspicious: c:\users\test\appdata\local\temp\nsz628c.tmp
Suspicious: c:\users\test\appdata\local\temp\nsz628c.tmp
Suspicious: c:\users\test\appdata\local\temp\nsz628c.tmp
Suspicious: c:\users\test\appdata\local\temp\nsz628c.tmp
Suspicious: c:\users\test\appdata\local\temp\nsz628c.tmp
Suspicious: c:\users\test\appdata\local\temp\nsz628c.tmp
Suspicious: c:\users\test\appdata\local\temp\nsz628c.tmp
Suspicious: c:\users\test\appdata\local\temp\nsz628c.tmp
Suspicious: c:\users\test\appdata\local\temp\nsz628c.tmp
Suspicious: c:\users\test\appdata\local\temp\nsz628c.tmp
Suspicious: c:\users\test\appdata\local\temp\nsz628c.tmp
Suspicious: c:\users\test\appdata\local\temp\nsz628c.tmp
Suspicious: c:\users\test\appdata\local\temp\nsz628c.tmp
Suspicious: c:\users\test\appdata\local\temp\nsz628c.tmp
Suspicious: c:\users\test\appdata\local\temp\nsz628c.tmp
Suspicious: c:\users\test\appdata\local\temp\nsz628c.tmp
Suspicious: c:\users\test\appdata\local\temp\nsz628c.tmp
Suspicious: c:\users\test\appdata\local\temp\nsz628c.tmp
Suspicious: c:\users\test\appdata\local\temp\nsz628c.tmp
Suspicious: c:\users\test\appdata\local\temp\nsz628c.tmp
Suspicious: c:\users\test\appdata\local\temp\nsz628c.tmp
Suspicious: c:\users\test\appdata\local\temp\nsz628c.tmp
Suspicious: c:\users\test\appdata\local\temp\nsz628c.tmp
Suspicious: c:\users\test\appdata\local\temp\nsz628c.tmp
Suspicious: c:\users\test\appdata\local\temp\nsz628c.tmp
Suspicious: c:\users\test\appdata\local\temp\nsz628c.tmp
Suspicious: c:\users\test\appdata\local\temp\nsz628c.tmp
Suspicious: c:\users\test\appdata\local\temp\nsz628c.tmp
Suspicious: c:\users\test\appdata\local\temp\nsz628c.tmp
Suspicious: c:\users\test\appdata\local\temp\nsz628c.tmp
Suspicious: c:\users\test\appdata\local\temp\nsz628c.tmp
Suspicious: c:\users\test\appdata\local\temp\nsz628c.tmp
Suspicious: c:\users\test\appdata\local\temp\nsz628c.tmp
Suspicious: c:\users\test\appdata\local\temp\nsz628c.tmp
Suspicious: c:\users\test\appdata\local\temp\nsz628c.tmp
Suspicious: c:\users\test\appdata\local\temp\nsz628c.tmp
Suspicious: c:\users\test\appdata\local\temp\nsz628c.tmp
Suspicious: c:\users\test\appdata\local\temp\nsz628c.tmp
Suspicious: c:\users\test\appdata\local\temp\nsz628c.tmp
Suspicious: c:\users\test\appdata\local\temp\nsz628c.tmp
Suspicious: c:\users\test\appdata\local\temp\nsz628c.tmp
Suspicious: c:\users\test\appdata\local\temp\nsz628c.tmp
Suspicious: c:\users\test\appdata\local\temp\nsz628c.tmp
Suspicious: c:\users\test\appdata\local\temp\nsz628c.tmp
Suspicious: c:\users\test\appdata\local\temp\nsz628c.tmp
Suspicious: c:\users\test\appdata\local\temp\nsz628c.tmp
Suspicious: c:\users\test\appdata\local\temp\nsz628c.tmp
Suspicious: c:\users\test\appdata\local\temp\nsz628c.tmp
Suspicious: c:\users\test\appdata\local\temp\nsz628c.tmp
Suspicious: c:\users\test\appdata\local\temp\nsz628c.tmp
Suspicious: c:\users\test\appdata\local\temp\nsz628c.tmp
Suspicious: c:\users\test\appdata\local\temp\nsz628c.tmp
Suspicious: c:\users\test\appdata\local\temp\nsz628c.tmp
Suspicious: c:\users\test\appdata\local\temp\nsz628c.tmp
Suspicious: c:\users\test\appdata\local\temp\nsz628c.tmp
Suspicious: c:\users\test\appdata\local\temp\nsz628c.tmp
Suspicious: c:\users\test\appdata\local\temp\nsz628c.tmp
Suspicious: c:\users\test\appdata\local\temp\nsz628c.tmp
Suspicious: c:\users\test\appdata\local\temp\nsz628c.tmp
Suspicious: c:\users\test\appdata\local\temp\nsz628c.tmp
Suspicious: c:\users\test\appdata\local\temp\nsz628c.tmp
Suspicious: c:\users\test\appdata\local\temp\nsz628c.tmp
Suspicious: c:\users\test\appdata\local\temp\nsz628c.tmp
Suspicious: c:\users\test\appdata\local\temp\nsz628c.tmp
Suspicious: c:\users\test\appdata\local\temp\nsz628c.tmp
Suspicious: c:\users\test\appdata\local\temp\nsz628c.tmp
Suspicious: c:\users\test\appdata\local\temp\nsz628c.tmp
Suspicious: c:\users\test\appdata\local\temp\nsz628c.tmp
Suspicious: c:\users\test\appdata\local\temp\nsz628c.tmp
Suspicious: c:\users\test\appdata\local\temp\nsz628c.tmp
Suspicious: c:\users\test\appdata\local\temp\nsz628c.tmp
Suspicious: c:\users\test\appdata\local\temp\nsz628c.tmp
Suspicious: c:\users\test\appdata\local\temp\nsz628c.tmp
Suspicious: c:\users\test\appdata\local\temp\nsz628c.tmp
Suspicious: c:\users\test\appdata\local\temp\nsz628c.tmp
Suspicious: c:\users\test\appdata\local\temp\nsz628c.tmp
Suspicious: c:\users\test\appdata\local\temp\nsz628c.tmp
Suspicious: c:\users\test\appdata\local\temp\nsz628c.tmp
Suspicious: c:\users\test\appdata\local\temp\nsz628c.tmp
Suspicious: c:\users\test\appdata\local\temp\nsz628c.tmp
Suspicious: c:\users\test\appdata\local\temp\nsz628c.tmp
Suspicious: c:\users\test\appdata\local\temp\nsz628c.tmp
Suspicious: c:\users\test\appdata\local\temp\nsz628c.tmp
Suspicious: c:\users\test\appdata\local\temp\nsz628c.tmp
Suspicious: c:\users\test\appdata\local\temp\nsz628c.tmp
Suspicious: c:\users\test\appdata\local\temp\nsz628c.tmp
Suspicious: c:\users\test\appdata\local\temp\nsz628c.tmp
Suspicious: c:\users\test\appdata\local\temp\nsz628c.tmp
Suspicious: c:\users\test\appdata\local\temp\nsz628c.tmp
Suspicious: c:\users\test\appdata\local\temp\nsz628c.tmp
Suspicious: c:\users\test\appdata\local\temp\nsz628c.tmp
Suspicious: c:\users\test\appdata\local\temp\nsz628c.tmp
Suspicious: c:\users\test\appdata\local\temp\nsz628c.tmp
Suspicious: c:\users\test\appdata\local\temp\nsz628c.tmp
Suspicious: c:\users\test\appdata\local\temp\nsz628c.tmp
Suspicious: c:\users\test\appdata\local\temp\nsz628c.tmp
Suspicious: c:\users\test\appdata\local\temp\nsz628c.tmp
Suspicious: c:\users\test\appdata\local\temp\nsz628c.tmp
Suspicious: c:\users\test\appdata\local\temp\nsz628c.tmp
Suspicious: c:\users\test\appdata\local\temp\nsz628c.tmp
Suspicious: c:\users\test\appdata\local\temp\nsz628c.tmp
Suspicious: c:\users\test\appdata\local\temp\nsz628c.tmp
Suspicious: c:\users\test\appdata\local\temp\nsz628c.tmp
Suspicious: c:\users\test\appdata\local\temp\nsz628c.tmp
Suspicious: c:\users\test\appdata\local\temp\nsz628c.tmp
Suspicious: c:\users\test\appdata\local\temp\nsz628c.tmp
Suspicious: c:\users\test\appdata\roaming\szw\masterz\bin\skin\problemlist.xml
Suspicious: c:\users\test\appdata\roaming\szw\masterz\bin\skin\problemlist.xml
Suspicious: c:\users\test\appdata\roaming\szw\masterz\bin\skin\problemlist.xml
Suspicious: c:\users\test\appdata\roaming\szw\masterz\bin\skin\problemlist.xml
Suspicious: c:\users\test\appdata\roaming\szw\masterz\bin\skin\problemlist.xml
Suspicious: c:\users\test\appdata\roaming\szw\masterz\bin\skin\problemlist.xml
Suspicious: c:\users\test\appdata\roaming\szw\masterz\bin\skin\problemlist.xml
Suspicious: c:\users\test\appdata\roaming\szw\masterz\bin\skin\problemlist.xml
Suspicious: c:\users\test\appdata\roaming\szw\masterz\bin\skin\problemlist.xml
Suspicious: c:\users\test\appdata\roaming\szw\masterz\bin\skin\problemlist.xml
Suspicious: c:\users\test\appdata\roaming\szw\masterz\bin\skin\problemlist.xml
Suspicious: c:\users\test\appdata\roaming\szw\masterz\bin\skin\problemlist.xml
Suspicious: c:\users\test\appdata\roaming\szw\masterz\bin\skin\problemlist.xml
Suspicious: c:\users\test\appdata\roaming\szw\masterz\bin\skin\problemlist.xml
Suspicious: c:\users\test\appdata\roaming\szw\masterz\bin\skin\problemlist.xml
Suspicious: c:\users\test\appdata\roaming\szw\masterz\bin\skin\problemlist.xml
Suspicious: c:\users\test\appdata\roaming\szw\masterz\bin\skin\problemlist.xml
Suspicious: c:\users\test\appdata\roaming\szw\masterz\bin\skin\problemlist.xml
Suspicious: c:\users\test\appdata\roaming\szw\masterz\bin\skin\problemlist.xml
Suspicious: c:\users\test\appdata\roaming\szw\masterz\bin\skin\problemlist.xml
Suspicious: c:\users\test\appdata\roaming\szw\masterz\bin\skin\problemlist.xml
Suspicious: c:\users\test\appdata\roaming\szw\masterz\bin\skin\problemlist.xml
Suspicious: c:\users\test\appdata\roaming\szw\masterz\bin\skin\problemlist.xml
Suspicious: c:\users\test\appdata\roaming\szw\masterz\bin\skin\problemlist.xml
Suspicious: c:\users\test\appdata\roaming\szw\masterz\bin\skin\problemlist.xml
Suspicious: c:\users\test\appdata\roaming\szw\masterz\bin\skin\problemlist.xml
Suspicious: c:\users\test\appdata\local\temp\nsz628c.tmp
Suspicious: c:\users\test\appdata\local\temp\nsz628c.tmp
Suspicious: c:\users\test\appdata\local\temp\nsz628c.tmp
Suspicious: c:\users\test\appdata\local\temp\nsz628c.tmp
Suspicious: c:\users\test\appdata\local\temp\nsz628c.tmp
Suspicious: c:\users\test\appdata\local\temp\nsz628c.tmp
Suspicious: c:\users\test\appdata\local\temp\nsz628c.tmp
Suspicious: c:\users\test\appdata\local\temp\nsz628c.tmp
Suspicious: c:\users\test\appdata\local\temp\nsz628c.tmp
Suspicious: c:\users\test\appdata\local\temp\nsz628c.tmp
Suspicious: c:\users\test\appdata\local\temp\nsz628c.tmp
Suspicious: c:\users\test\appdata\local\temp\nsz628c.tmp
Suspicious: c:\users\test\appdata\local\temp\nsz628c.tmp
Suspicious: c:\users\test\appdata\local\temp\nsz628c.tmp
Suspicious: c:\users\test\appdata\local\temp\nsz628c.tmp
Suspicious: c:\users\test\appdata\local\temp\nsz628c.tmp
Suspicious: c:\users\test\appdata\local\temp\nsz628c.tmp
Suspicious: c:\users\test\appdata\local\temp\nsz628c.tmp
Suspicious: c:\users\test\appdata\local\temp\nsz628c.tmp
Suspicious: c:\users\test\appdata\local\temp\nsz628c.tmp
Suspicious: c:\users\test\appdata\local\temp\nsz628c.tmp
Suspicious: c:\users\test\appdata\local\temp\nsz628c.tmp
Suspicious: c:\users\test\appdata\local\temp\nsz628c.tmp
Suspicious: c:\users\test\appdata\local\temp\nsz628c.tmp
Suspicious: c:\users\test\appdata\local\temp\nsz628c.tmp
Suspicious: c:\users\test\appdata\local\temp\nsz628c.tmp
Suspicious: c:\users\test\appdata\local\temp\nsz628c.tmp
Suspicious: c:\users\test\appdata\local\temp\nsz628c.tmp
Suspicious: c:\users\test\appdata\local\temp\nsz628c.tmp
Suspicious: c:\users\test\appdata\local\temp\nsz628c.tmp
Suspicious: c:\users\test\appdata\local\temp\nsz628c.tmp
Suspicious: c:\users\test\appdata\local\temp\nsz628c.tmp
Suspicious: c:\users\test\appdata\local\temp\nsz628c.tmp
Suspicious: c:\users\test\appdata\local\temp\nsz628c.tmp
Suspicious: c:\users\test\appdata\local\temp\nsz628c.tmp
Suspicious: c:\users\test\appdata\local\temp\nsz628c.tmp
Suspicious: c:\users\test\appdata\local\temp\nsz628c.tmp
Suspicious: c:\users\test\appdata\local\temp\nsz628c.tmp
Suspicious: c:\users\test\appdata\local\temp\nsz628c.tmp
Suspicious: c:\users\test\appdata\local\temp\nsz628c.tmp
Suspicious: c:\users\test\appdata\local\temp\nsz628c.tmp
Suspicious: c:\users\test\appdata\local\temp\nsz628c.tmp
Suspicious: c:\users\test\appdata\local\temp\nsz628c.tmp
Suspicious: c:\users\test\appdata\local\temp\nsz628c.tmp
Suspicious: c:\users\test\appdata\local\temp\nsz628c.tmp
Suspicious: c:\users\test\appdata\local\temp\nsz628c.tmp
Suspicious: c:\users\test\appdata\local\temp\nsz628c.tmp
Suspicious: c:\users\test\appdata\local\temp\nsz628c.tmp
Suspicious: c:\users\test\appdata\local\temp\nsz628c.tmp
Suspicious: c:\users\test\appdata\local\temp\nsz628c.tmp
Suspicious: c:\users\test\appdata\local\temp\nsz628c.tmp
Suspicious: c:\users\test\appdata\local\temp\nsz628c.tmp
Suspicious: c:\users\test\appdata\local\temp\nsz628c.tmp
Suspicious: c:\users\test\appdata\local\temp\nsz628c.tmp
Suspicious: c:\users\test\appdata\local\temp\nsz628c.tmp
Suspicious: c:\users\test\appdata\local\temp\nsz628c.tmp
Suspicious: c:\users\test\appdata\local\temp\nsz628c.tmp
Suspicious: c:\users\test\appdata\local\temp\nsz628c.tmp
Suspicious: c:\users\test\appdata\local\temp\nsz628c.tmp
Suspicious: c:\users\test\appdata\local\temp\nsz628c.tmp
Suspicious: c:\users\test\appdata\local\temp\nsz628c.tmp
Suspicious: c:\users\test\appdata\local\temp\nsz628c.tmp
Suspicious: c:\users\test\appdata\local\temp\nsz628c.tmp
Suspicious: c:\users\test\appdata\local\temp\nsz628c.tmp
Suspicious: c:\users\test\appdata\local\temp\nsz628c.tmp
Suspicious: c:\users\test\appdata\local\temp\nsz628c.tmp
Suspicious: c:\users\test\appdata\local\temp\nsz628c.tmp
Suspicious: c:\users\test\appdata\local\temp\nsz628c.tmp
Suspicious: c:\users\test\appdata\local\temp\nsz628c.tmp
Suspicious: c:\users\test\appdata\local\temp\nsz628c.tmp
Suspicious: c:\users\test\appdata\local\temp\nsz628c.tmp
Suspicious: c:\users\test\appdata\local\temp\nsz628c.tmp
Suspicious: c:\users\test\appdata\local\temp\nsz628c.tmp
Suspicious: c:\users\test\appdata\local\temp\nsz628c.tmp
Suspicious: c:\users\test\appdata\local\temp\nsz628c.tmp
Suspicious: c:\users\test\appdata\local\temp\nsz628c.tmp
Suspicious: c:\users\test\appdata\local\temp\nsz628c.tmp
Suspicious: c:\users\test\appdata\local\temp\nsz628c.tmp
Suspicious: c:\users\test\appdata\local\temp\nsz628c.tmp
Suspicious: c:\users\test\appdata\local\temp\nsz628c.tmp
Suspicious: c:\users\test\appdata\local\temp\nsz628c.tmp
Suspicious: c:\users\test\appdata\local\temp\nsz628c.tmp
Suspicious: c:\users\test\appdata\local\temp\nsz628c.tmp
Suspicious: c:\users\test\appdata\local\temp\nsz628c.tmp
Suspicious: c:\users\test\appdata\local\temp\nsz628c.tmp
Suspicious: c:\users\test\appdata\local\temp\nsz628c.tmp
Suspicious: c:\users\test\appdata\local\temp\nsz628c.tmp
Suspicious: c:\users\test\appdata\local\temp\nsz628c.tmp
Suspicious: c:\users\test\appdata\local\temp\nsz628c.tmp
Suspicious: c:\users\test\appdata\local\temp\nsz628c.tmp
Suspicious: c:\users\test\appdata\local\temp\nsz628c.tmp
Suspicious: c:\users\test\appdata\local\temp\nsz628c.tmp
Suspicious: c:\users\test\appdata\local\temp\nsz628c.tmp
Suspicious: c:\users\test\appdata\local\temp\nsz628c.tmp
Suspicious: c:\users\test\appdata\local\temp\nsz628c.tmp
Suspicious: c:\users\test\appdata\local\temp\nsz628c.tmp
Suspicious: c:\users\test\appdata\local\temp\nsz628c.tmp
Suspicious: c:\users\test\appdata\local\temp\nsz628c.tmp
Suspicious: c:\users\test\appdata\local\temp\nsz628c.tmp
Suspicious: c:\users\test\appdata\local\temp\nsz628c.tmp
Suspicious: c:\users\test\appdata\local\temp\nsz628c.tmp
Suspicious: c:\users\test\appdata\local\temp\nsz628c.tmp
Suspicious: c:\users\test\appdata\local\temp\nsz628c.tmp
Suspicious: c:\users\test\appdata\local\temp\nsz628c.tmp
Suspicious: c:\users\test\appdata\local\temp\nsz628c.tmp
Suspicious: c:\users\test\appdata\local\temp\nsz628c.tmp
Suspicious: c:\users\test\appdata\local\temp\nsz628c.tmp
Suspicious: c:\users\test\appdata\local\temp\nsz628c.tmp
Suspicious: c:\users\test\appdata\local\temp\nsz628c.tmp
Suspicious: c:\users\test\appdata\local\temp\nsz628c.tmp
Suspicious: c:\users\test\appdata\local\temp\nsz628c.tmp
Suspicious: c:\users\test\appdata\local\temp\nsz628c.tmp
Suspicious: c:\users\test\appdata\local\temp\nsz628c.tmp
Suspicious: c:\users\test\appdata\local\temp\nsz628c.tmp
Suspicious: c:\users\test\appdata\local\temp\nsz628c.tmp
Suspicious: c:\users\test\appdata\local\temp\nsz628c.tmp
Suspicious: c:\users\test\appdata\local\temp\nsz628c.tmp
Suspicious: c:\users\test\appdata\local\temp\nsz628c.tmp
Suspicious: c:\users\test\appdata\local\temp\nsz628c.tmp
Suspicious: c:\users\test\appdata\local\temp\nsz628c.tmp
Suspicious: c:\users\test\appdata\local\temp\nsz628c.tmp
Suspicious: c:\users\test\appdata\local\temp\nsz628c.tmp
Suspicious: c:\users\test\appdata\local\temp\nsz628c.tmp
Suspicious: c:\users\test\appdata\local\temp\nsz628c.tmp
Suspicious: c:\users\test\appdata\local\temp\nsz628c.tmp
Suspicious: c:\users\test\appdata\local\temp\nsz628c.tmp
Suspicious: c:\users\test\appdata\local\temp\nsz628c.tmp
Suspicious: c:\users\test\appdata\local\temp\nsz628c.tmp
Suspicious: c:\users\test\appdata\local\temp\nsz628c.tmp
Suspicious: c:\users\test\appdata\local\temp\nsz628c.tmp
Suspicious: c:\users\test\appdata\local\temp\nsz628c.tmp
Suspicious: c:\users\test\appdata\local\temp\nsz628c.tmp
Suspicious: c:\users\test\appdata\local\temp\nsz628c.tmp
Suspicious: c:\users\test\appdata\local\temp\nsz628c.tmp
Suspicious: c:\users\test\appdata\local\temp\nsz628c.tmp
Suspicious: c:\users\test\appdata\local\temp\nsz628c.tmp
Suspicious: c:\users\test\appdata\local\temp\nsz628c.tmp
Suspicious: c:\users\test\appdata\local\temp\nsz628c.tmp
Suspicious: c:\users\test\appdata\local\temp\nsz628c.tmp
Suspicious: c:\users\test\appdata\local\temp\nsz628c.tmp
Suspicious: c:\users\test\appdata\local\temp\nsz628c.tmp
Suspicious: c:\users\test\appdata\local\temp\nsz628c.tmp
Suspicious: c:\users\test\appdata\local\temp\nsz628c.tmp
Suspicious: c:\users\test\appdata\local\temp\nsz628c.tmp
Suspicious: c:\users\test\appdata\local\temp\nsz628c.tmp
Suspicious: c:\users\test\appdata\local\temp\nsz628c.tmp
Suspicious: c:\users\test\appdata\local\temp\nsz628c.tmp
Suspicious: c:\users\test\appdata\local\temp\nsz628c.tmp
Suspicious: c:\users\test\appdata\local\temp\nsz628c.tmp
Suspicious: c:\users\test\appdata\local\temp\nsz628c.tmp
Suspicious: c:\users\test\appdata\local\temp\nsz628c.tmp
Suspicious: c:\users\test\appdata\local\temp\nsz628c.tmp
Suspicious: c:\users\test\appdata\local\temp\nsz628c.tmp
Suspicious: c:\users\test\appdata\local\temp\nsz628c.tmp
Suspicious: c:\users\test\appdata\local\temp\nsz628c.tmp
Suspicious: c:\users\test\appdata\local\temp\nsz628c.tmp
Suspicious: c:\users\test\appdata\local\temp\nsz628c.tmp
Suspicious: c:\users\test\appdata\local\temp\nsz628c.tmp
Suspicious: c:\users\test\appdata\local\temp\nsz628c.tmp
Suspicious: c:\users\test\appdata\local\temp\nsz628c.tmp
Suspicious: c:\users\test\appdata\local\temp\nsz628c.tmp
Suspicious: c:\users\test\appdata\local\temp\nsz628c.tmp
Suspicious: c:\users\test\appdata\local\temp\nsz628c.tmp
Suspicious: c:\users\test\appdata\local\temp\nsz628c.tmp
Suspicious: c:\users\test\appdata\local\temp\nsz628c.tmp
Suspicious: c:\users\test\appdata\local\temp\nsz628c.tmp
Suspicious: c:\users\test\appdata\local\temp\nsz628c.tmp
Suspicious: c:\users\test\appdata\local\temp\nsz628c.tmp
Suspicious: c:\users\test\appdata\local\temp\nsz628c.tmp
Suspicious: c:\users\test\appdata\local\temp\nsz628c.tmp
Suspicious: c:\users\test\appdata\local\temp\nsz628c.tmp
Suspicious: c:\users\test\appdata\local\temp\nsz628c.tmp
Suspicious: c:\users\test\appdata\local\temp\nsz628c.tmp
Suspicious: c:\users\test\appdata\local\temp\nsz628c.tmp
Suspicious: c:\users\test\appdata\local\temp\nsz628c.tmp
Suspicious: c:\users\test\appdata\local\temp\nsz628c.tmp
Suspicious: c:\users\test\appdata\local\temp\nsz628c.tmp
Suspicious: c:\users\test\appdata\local\temp\nsz628c.tmp
Suspicious: c:\users\test\appdata\local\temp\nsz628c.tmp
Suspicious: c:\users\test\appdata\local\temp\nsz628c.tmp
Suspicious: c:\users\test\appdata\local\temp\nsz628c.tmp
Suspicious: c:\users\test\appdata\local\temp\nsz628c.tmp
Suspicious: c:\users\test\appdata\local\temp\nsz628c.tmp
Suspicious: c:\users\test\appdata\local\temp\nsz628c.tmp
Suspicious: c:\users\test\appdata\local\temp\nsz628c.tmp
Suspicious: c:\users\test\appdata\local\temp\nsz628c.tmp
Suspicious: c:\users\test\appdata\local\temp\nsz628c.tmp
Suspicious: c:\users\test\appdata\local\temp\nsz628c.tmp
Suspicious: c:\users\test\appdata\local\temp\nsz628c.tmp
Suspicious: c:\users\test\appdata\local\temp\nsz628c.tmp
Suspicious: c:\users\test\appdata\local\temp\nsz628c.tmp
Suspicious: c:\users\test\appdata\local\temp\nsz628c.tmp
Suspicious: c:\users\test\appdata\local\temp\nsz628c.tmp
Suspicious: c:\users\test\appdata\local\temp\nsz628c.tmp
Suspicious: c:\users\test\appdata\local\temp\nsz628c.tmp
Suspicious: c:\users\test\appdata\local\temp\nsz628c.tmp
Suspicious: c:\users\test\appdata\local\temp\nsz628c.tmp
Suspicious: c:\users\test\appdata\local\temp\nsz628c.tmp
Suspicious: c:\users\test\appdata\local\temp\nsz628c.tmp
Suspicious: c:\users\test\appdata\local\temp\nsz628c.tmp
Suspicious: c:\users\test\appdata\local\temp\nsz628c.tmp
Suspicious: c:\users\test\appdata\local\temp\nsz628c.tmp
Suspicious: c:\users\test\appdata\local\temp\nsz628c.tmp
Suspicious: c:\users\test\appdata\local\temp\nsz628c.tmp
Suspicious: c:\users\test\appdata\local\temp\nsz628c.tmp
Suspicious: c:\users\test\appdata\local\temp\nsz628c.tmp
Suspicious: c:\users\test\appdata\local\temp\nsz628c.tmp
Suspicious: c:\users\test\appdata\local\temp\nsz628c.tmp
Suspicious: c:\users\test\appdata\local\temp\nsz628c.tmp
Suspicious: c:\users\test\appdata\local\temp\nsz628c.tmp
Suspicious: c:\users\test\appdata\local\temp\nsz628c.tmp
Suspicious: c:\users\test\appdata\local\temp\nsz628c.tmp
Suspicious: c:\users\test\appdata\local\temp\nsz628c.tmp
Suspicious: c:\users\test\appdata\local\temp\nsz628c.tmp
Suspicious: c:\users\test\appdata\local\temp\nsz628c.tmp
Suspicious: c:\users\test\appdata\local\temp\nsz628c.tmp
Suspicious: c:\users\test\appdata\local\temp\nsz628c.tmp
Suspicious: c:\users\test\appdata\local\temp\nsz628c.tmp
Suspicious: c:\users\test\appdata\local\temp\nsz628c.tmp
Suspicious: c:\users\test\appdata\local\temp\nsz628c.tmp
Suspicious: c:\users\test\appdata\local\temp\nsz628c.tmp
Suspicious: c:\users\test\appdata\local\temp\nsz628c.tmp
Suspicious: c:\users\test\appdata\local\temp\nsz628c.tmp
Suspicious: c:\users\test\appdata\local\temp\nsz628c.tmp
Suspicious: c:\users\test\appdata\local\temp\nsz628c.tmp
Suspicious: c:\users\test\appdata\local\temp\nsz628c.tmp
Suspicious: c:\users\test\appdata\local\temp\nsz628c.tmp
Suspicious: c:\users\test\appdata\local\temp\nsz628c.tmp
Suspicious: c:\users\test\appdata\local\temp\nsz628c.tmp
Suspicious: c:\users\test\appdata\local\temp\nsz628c.tmp
Suspicious: c:\users\test\appdata\local\temp\nsz628c.tmp
Suspicious: c:\users\test\appdata\local\temp\nsz628c.tmp
Suspicious: c:\users\test\appdata\local\temp\nsz628c.tmp
Suspicious: c:\users\test\appdata\local\temp\nsz628c.tmp
Suspicious: c:\users\test\appdata\local\temp\nsz628c.tmp
Suspicious: c:\users\test\appdata\local\temp\nsz628c.tmp
Suspicious: c:\users\test\appdata\local\temp\nsz628c.tmp
Suspicious: c:\users\test\appdata\local\temp\nsz628c.tmp
Suspicious: c:\users\test\appdata\local\temp\nsz628c.tmp
Suspicious: c:\users\test\appdata\local\temp\nsz628c.tmp
Suspicious: c:\users\test\appdata\local\temp\nsz628c.tmp
Suspicious: c:\users\test\appdata\local\temp\nsz628c.tmp
Suspicious: c:\users\test\appdata\local\temp\nsz628c.tmp
Suspicious: c:\users\test\appdata\local\temp\nsz628c.tmp
Suspicious: c:\users\test\appdata\local\temp\nsz628c.tmp
Suspicious: c:\users\test\appdata\local\temp\nsz628c.tmp
Suspicious: c:\users\test\appdata\local\temp\nsz628c.tmp
Suspicious: c:\users\test\appdata\local\temp\nsz628c.tmp
Suspicious: c:\users\test\appdata\local\temp\nsz628c.tmp
Suspicious: c:\users\test\appdata\local\temp\nsz628c.tmp
Suspicious: c:\users\test\appdata\local\temp\nsz628c.tmp
Suspicious: c:\users\test\appdata\local\temp\nsz628c.tmp
Suspicious: c:\users\test\appdata\local\temp\nsz628c.tmp
Suspicious: c:\users\test\appdata\local\temp\nsz628c.tmp
Suspicious: c:\users\test\appdata\local\temp\nsz628c.tmp
Suspicious: c:\users\test\appdata\local\temp\nsz628c.tmp
Suspicious: c:\users\test\appdata\local\temp\nsz628c.tmp
Suspicious: c:\users\test\appdata\local\temp\nsz628c.tmp
Suspicious: c:\users\test\appdata\local\temp\nsz628c.tmp
Suspicious: c:\users\test\appdata\local\temp\nsz628c.tmp
Suspicious: c:\users\test\appdata\local\temp\nsz628c.tmp
Suspicious: c:\users\test\appdata\local\temp\nsz628c.tmp
Suspicious: c:\users\test\appdata\local\temp\nsz628c.tmp
Suspicious: c:\users\test\appdata\local\temp\nsz628c.tmp
Suspicious: c:\users\test\appdata\local\temp\nsz628c.tmp
Suspicious: c:\users\test\appdata\local\temp\nsz628c.tmp
Suspicious: c:\users\test\appdata\local\temp\nsz628c.tmp
Suspicious: c:\users\test\appdata\local\temp\nsz628c.tmp
Suspicious: c:\users\test\appdata\local\temp\nsz628c.tmp
Suspicious: c:\users\test\appdata\local\temp\nsz628c.tmp
Suspicious: c:\users\test\appdata\local\temp\nsz628c.tmp
Suspicious: c:\users\test\appdata\local\temp\nsz628c.tmp
Suspicious: c:\users\test\appdata\local\temp\nsz628c.tmp
Suspicious: c:\users\test\appdata\local\temp\nsz628c.tmp
Suspicious: c:\users\test\appdata\local\temp\nsz628c.tmp
Suspicious: c:\users\test\appdata\local\temp\nsz628c.tmp
Suspicious: c:\users\test\appdata\local\temp\nsz628c.tmp
Suspicious: c:\users\test\appdata\local\temp\nsz628c.tmp
Suspicious: c:\users\test\appdata\local\temp\nsz628c.tmp
Suspicious: c:\users\test\appdata\local\temp\nsz628c.tmp
Suspicious: c:\users\test\appdata\local\temp\nsz628c.tmp
Suspicious: c:\users\test\appdata\local\temp\nsz628c.tmp
Suspicious: c:\users\test\appdata\local\temp\nsz628c.tmp
Suspicious: c:\users\test\appdata\local\temp\nsz628c.tmp
Suspicious: c:\users\test\appdata\local\temp\nsz628c.tmp
Suspicious: c:\users\test\appdata\local\temp\nsz628c.tmp
Suspicious: c:\users\test\appdata\local\temp\nsz628c.tmp
Suspicious: c:\users\test\appdata\local\temp\nsz628c.tmp
Suspicious: c:\users\test\appdata\local\temp\nsz628c.tmp
Suspicious: c:\users\test\appdata\local\temp\nsz628c.tmp
Suspicious: c:\users\test\appdata\local\temp\nsz628c.tmp
Suspicious: c:\users\test\appdata\local\temp\nsz628c.tmp
Suspicious: c:\users\test\appdata\local\temp\nsz628c.tmp
Suspicious: c:\users\test\appdata\local\temp\nsz628c.tmp
Suspicious: c:\users\test\appdata\local\temp\nsz628c.tmp
Suspicious: c:\users\test\appdata\local\temp\nsz628c.tmp
Suspicious: c:\users\test\appdata\local\temp\nsz628c.tmp
Suspicious: c:\users\test\appdata\local\temp\nsz628c.tmp
Suspicious: c:\users\test\appdata\local\temp\nsz628c.tmp
Suspicious: c:\users\test\appdata\local\temp\nsz628c.tmp
Suspicious: c:\users\test\appdata\local\temp\nsz628c.tmp
Suspicious: c:\users\test\appdata\local\temp\nsz628c.tmp
Suspicious: c:\users\test\appdata\local\temp\nsz628c.tmp
Suspicious: c:\users\test\appdata\local\temp\nsz628c.tmp
Suspicious: c:\users\test\appdata\local\temp\nsz628c.tmp
Suspicious: c:\users\test\appdata\local\temp\nsz628c.tmp

运行截图

网络分析

TCP连接

IP地址 端口
192.168.122.201 49207
192.168.122.201 49208
192.168.122.201 49209
192.168.122.201 49210
192.168.122.201 49211
192.168.122.201 49212
192.168.122.201 49213
192.168.122.201 49214
192.168.122.201 49215
192.168.122.201 49216
192.168.122.201 49217
192.168.122.201 49218
192.168.122.201 49219
192.168.122.201 49220
192.168.122.201 49221
192.168.122.201 49222
192.168.122.201 49223
192.168.122.201 49224
192.168.122.201 49225
192.168.122.201 49226
192.168.122.201 49227
192.168.122.201 49228
192.168.122.201 49229
192.168.122.201 49230
192.168.122.201 49231
192.168.122.201 49232
192.168.122.201 49233
192.168.122.201 49234
192.168.122.201 49235
192.168.122.201 49236
192.168.122.201 49237
192.168.122.201 49238
192.168.122.201 49239
192.168.122.201 49240
192.168.122.201 49241
192.168.122.201 49242
192.168.122.201 49243
192.168.122.201 49244
192.168.122.201 49245
192.168.122.201 49246
192.168.122.201 49247
192.168.122.201 49248
192.168.122.201 49249
192.168.122.201 49250
192.168.122.201 49251
192.168.122.201 49252
192.168.122.201 49253
192.168.122.201 49254
192.168.122.201 49255
192.168.122.201 49256
192.168.122.201 49257
192.168.122.201 49258
192.168.122.201 49259
192.168.122.201 49260
192.168.122.201 49261
192.168.122.201 49262
192.168.122.201 49263
192.168.122.201 49264
192.168.122.201 49265
192.168.122.201 49266
192.168.122.201 49267
192.168.122.201 49268
192.168.122.201 49269
192.168.122.201 49270
192.168.122.201 49271
192.168.122.201 49272
192.168.122.201 49273
192.168.122.201 49274
192.168.122.201 49275
192.168.122.201 49276
192.168.122.201 49277
192.168.122.201 49278
192.168.122.201 49279
192.168.122.201 49280
192.168.122.201 49281
192.168.122.201 49282
192.168.122.201 49283
192.168.122.201 49284
192.168.122.201 49285
192.168.122.201 49286
192.168.122.201 49287
192.168.122.201 49288
192.168.122.201 49289
192.168.122.201 49290
192.168.122.201 49291
192.168.122.201 49292
192.168.122.201 49293
192.168.122.201 49294
192.168.122.201 49295
192.168.122.201 49296
192.168.122.201 49297
192.168.122.201 49298
192.168.122.201 49299
192.168.122.201 49300
192.168.122.201 49301
192.168.122.201 49302
192.168.122.201 49303
192.168.122.201 49304
192.168.122.201 49305
无信息

静态分析

PE 信息

初始地址 0x00400000
入口地址 0x0040354b
声明校验值 0x009fabc1
实际校验值 0x009fabc1
最低操作系统版本要求 5.0
编译时间 2010-04-10 20:19:31
载入哈希 b729b61eb1515fcf7b3e511e4e66258b

版本信息

LegalCopyright: \u7248\u6743\u6240\u6709 (C)
ProductName: \u6807\u51c6\u4ef6
ProductVersion: 1.2.1.0
FileDescription: \u5b89\u88c5\u5305
Translation: 0x0000 0x03a8

PE数据组成

名称 虚拟地址 虚拟大小 原始数据大小 特征 熵(Entropy)
.text 0x00001000 0x000063a2 0x00006400 IMAGE_SCN_CNT_CODE|IMAGE_SCN_MEM_EXECUTE|IMAGE_SCN_MEM_READ 6.48
.rdata 0x00008000 0x000018f2 0x00001a00 IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ 4.89
.data 0x0000a000 0x0006669c 0x00000200 IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ|IMAGE_SCN_MEM_WRITE 1.43
.ndata 0x00071000 0x000a1000 0x00000000 IMAGE_SCN_CNT_UNINITIALIZED_DATA|IMAGE_SCN_MEM_READ|IMAGE_SCN_MEM_WRITE 0.00
.rsrc 0x00112000 0x00006ee8 0x00007000 IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ 5.76

导入

库 KERNEL32.dll:
0x408060 - SetFileTime
0x408064 - CompareFileTime
0x408068 - SearchPathW
0x40806c - GetShortPathNameW
0x408070 - GetFullPathNameW
0x408074 - MoveFileW
0x408078 - SetCurrentDirectoryW
0x40807c - GetFileAttributesW
0x408080 - GetLastError
0x408084 - CreateDirectoryW
0x408088 - SetFileAttributesW
0x40808c - Sleep
0x408090 - GetTickCount
0x408094 - CreateFileW
0x408098 - GetFileSize
0x40809c - GetModuleFileNameW
0x4080a0 - GetCurrentProcess
0x4080a4 - CopyFileW
0x4080a8 - ExitProcess
0x4080ac - GetWindowsDirectoryW
0x4080b0 - GetTempPathW
0x4080b4 - GetCommandLineW
0x4080b8 - SetErrorMode
0x4080bc - CloseHandle
0x4080c0 - lstrlenW
0x4080c4 - lstrcpynW
0x4080c8 - GetDiskFreeSpaceW
0x4080cc - GlobalUnlock
0x4080d0 - GlobalLock
0x4080d4 - CreateThread
0x4080d8 - LoadLibraryW
0x4080dc - CreateProcessW
0x4080e0 - lstrcmpiA
0x4080e4 - GetTempFileNameW
0x4080e8 - lstrcatW
0x4080ec - GetProcAddress
0x4080f0 - LoadLibraryA
0x4080f4 - GetModuleHandleA
0x4080f8 - OpenProcess
0x4080fc - lstrcpyW
0x408100 - GetVersionExW
0x408104 - GetSystemDirectoryW
0x408108 - GetVersion
0x40810c - lstrcpyA
0x408110 - RemoveDirectoryW
0x408114 - lstrcmpiW
0x408118 - lstrcmpW
0x40811c - ExpandEnvironmentStringsW
0x408120 - GlobalAlloc
0x408124 - WaitForSingleObject
0x408128 - GetExitCodeProcess
0x40812c - GlobalFree
0x408130 - GetModuleHandleW
0x408134 - LoadLibraryExW
0x408138 - FreeLibrary
0x40813c - WritePrivateProfileStringW
0x408140 - GetPrivateProfileStringW
0x408144 - WideCharToMultiByte
0x408148 - MulDiv
0x40814c - lstrlenA
0x408150 - WriteFile
0x408154 - ReadFile
0x408158 - MultiByteToWideChar
0x40815c - SetFilePointer
0x408160 - FindClose
0x408164 - FindNextFileW
0x408168 - FindFirstFileW
0x40816c - DeleteFileW
0x408170 - lstrcpynA
库 USER32.dll:
0x408194 - ScreenToClient
0x408198 - GetMessagePos
0x40819c - CallWindowProcW
0x4081a0 - IsWindowVisible
0x4081a4 - LoadBitmapW
0x4081a8 - CloseClipboard
0x4081ac - SetClipboardData
0x4081b0 - EmptyClipboard
0x4081b4 - OpenClipboard
0x4081b8 - TrackPopupMenu
0x4081bc - GetWindowRect
0x4081c0 - AppendMenuW
0x4081c4 - CreatePopupMenu
0x4081c8 - GetSystemMetrics
0x4081cc - EndDialog
0x4081d0 - EnableMenuItem
0x4081d4 - GetSystemMenu
0x4081d8 - SetClassLongW
0x4081dc - IsWindowEnabled
0x4081e0 - SetWindowPos
0x4081e4 - DialogBoxParamW
0x4081e8 - CheckDlgButton
0x4081ec - CreateWindowExW
0x4081f0 - SystemParametersInfoW
0x4081f4 - RegisterClassW
0x4081f8 - SetDlgItemTextW
0x4081fc - GetDlgItemTextW
0x408200 - MessageBoxIndirectW
0x408204 - CharNextA
0x408208 - CharUpperW
0x40820c - CharPrevW
0x408210 - DispatchMessageW
0x408214 - PeekMessageW
0x408218 - wsprintfA
0x40821c - DestroyWindow
0x408220 - CreateDialogParamW
0x408224 - SetTimer
0x408228 - SetWindowTextW
0x40822c - PostQuitMessage
0x408230 - SetForegroundWindow
0x408234 - ShowWindow
0x408238 - wsprintfW
0x40823c - SendMessageTimeoutW
0x408240 - LoadCursorW
0x408244 - SetCursor
0x408248 - GetWindowLongW
0x40824c - GetSysColor
0x408250 - CharNextW
0x408254 - GetClassInfoW
0x408258 - ExitWindowsEx
0x40825c - FindWindowExW
0x408260 - GetDlgItem
0x408264 - SetWindowLongW
0x408268 - LoadImageW
0x40826c - GetDC
0x408270 - EnableWindow
0x408274 - InvalidateRect
0x408278 - SendMessageW
0x40827c - DefWindowProcW
0x408280 - BeginPaint
0x408284 - GetClientRect
0x408288 - FillRect
0x40828c - DrawTextW
0x408290 - EndPaint
0x408294 - IsWindow
库 GDI32.dll:
0x40803c - SetBkColor
0x408040 - GetDeviceCaps
0x408044 - DeleteObject
0x408048 - CreateBrushIndirect
0x40804c - CreateFontIndirectW
0x408050 - SetBkMode
0x408054 - SetTextColor
0x408058 - SelectObject
库 SHELL32.dll:
0x408178 - SHBrowseForFolderW
0x40817c - SHGetPathFromIDListW
0x408180 - SHGetFileInfoW
0x408184 - ShellExecuteW
0x408188 - SHFileOperationW
0x40818c - SHGetSpecialFolderLocation
库 ADVAPI32.dll:
0x408000 - RegEnumKeyW
0x408004 - RegOpenKeyExW
0x408008 - RegCloseKey
0x40800c - RegDeleteKeyW
0x408010 - RegDeleteValueW
0x408014 - RegCreateKeyExW
0x408018 - RegSetValueExW
0x40801c - RegQueryValueExW
0x408020 - RegEnumValueW
库 COMCTL32.dll:
0x408028 - ImageList_AddMasked
0x40802c - ImageList_Destroy
0x408030 - None
0x408034 - ImageList_Create
库 ole32.dll:
0x4082ac - CoTaskMemFree
0x4082b0 - OleInitialize
0x4082b4 - OleUninitialize
0x4082b8 - CoCreateInstance
库 VERSION.dll:
0x40829c - GetFileVersionInfoSizeW
0x4082a0 - GetFileVersionInfoW
0x4082a4 - VerQueryValueW

投放文件

无信息

行为分析

互斥量(Mutexes)
  • Local\MSCTF.Asm.MutexDefault1
  • MASTERZSetup
  • Local\ZoneAttributeCacheCounterMutex
  • Local\ZonesCacheCounterMutex
  • Local\ZonesLockedCacheCounterMutex
  • Sumszw_mc.dat
  • DBWinMutex
  • _MASTERZ_CLIENT_GUI_
  • data_update_4kernel
执行的命令
  • "C:\Windows\System32\taskkill.exe" /f /im MasterZ.exe
  • taskkill /f /im MasterZ.exe
  • C:\Users\test\AppData\Roaming\szw\MasterZ\bin\KillService.bat
  • cmd.exe /c net stop autorunser
  • cmd.exe /c "C:\Users\test\AppData\Roaming\szw\MasterZ\bin\Deamon.exe" -remove
  • netsh advfirewall firewall delete rule name="\xe8\x88\x9f\xe5\xa4\xa7\xe5\xb8\x88" dir=in program="C:\Users\test\AppData\Roaming\Suminfo\BizExpressQY2.0\bin\BizClient2.0.exe"
  • netsh advfirewall firewall delete rule name="\xe8\x88\x9f\xe5\xa4\xa7\xe5\xb8\x88\xe4\xb8\xbb\xe6\x8e\xa7\xe7\xa8\x8b\xe5\xba\x8f" dir=in program="C:\Users\test\AppData\Roaming\Suminfo\BizExpressQY2.0\bin\webMcProc.exe"
  • netsh advfirewall firewall delete rule name="\xe8\x88\x9f\xe5\xa4\xa7\xe5\xb8\x88\xe5\x86\x85\xe6\xa0\xb8\xe7\xa8\x8b\xe5\xba\x8f" dir=in program="C:\Users\test\AppData\Roaming\Suminfo\BizExpressQY2.0\bin\Sumengine2.exe"
  • netsh advfirewall firewall delete rule name="\xe8\x88\x9f\xe5\xa4\xa7\xe5\xb8\x88SearchKeyWord" dir=in program="C:\Users\test\AppData\Roaming\Suminfo\BizExpressQY2.0\bin\SearchKeyWord.exe"
  • netsh advfirewall firewall delete rule name="\xe8\x88\x9f\xe5\xa4\xa7\xe5\xb8\x88DatUpdate" dir=in program="C:\Users\test\AppData\Roaming\Suminfo\BizExpressQY2.0\bin\DatUpdate.exe"
  • netsh advfirewall firewall delete rule name="webMcProc.exe" program="C:\Users\test\AppData\Roaming\Suminfo\BizExpressQY2.0\bin\webMcProc.exe"
  • netsh advfirewall firewall delete rule name="BizClient2.0.exe" program="C:\Users\test\AppData\Roaming\Suminfo\BizExpressQY2.0\bin\BizClient2.0.exe"
  • netsh advfirewall firewall delete rule name="Sumengine2.exe" program="C:\Users\test\AppData\Roaming\Suminfo\BizExpressQY2.0\bin\Sumengine2.exe"
  • netsh advfirewall firewall delete rule name="SearchKeyWord.exe" program="C:\Users\test\AppData\Roaming\Suminfo\BizExpressQY2.0\bin\SearchKeyWord.exe"
  • netsh advfirewall firewall delete rule name="DatUpdate.exe" program="C:\Users\test\AppData\Roaming\Suminfo\BizExpressQY2.0\bin\DatUpdate.exe"
  • netsh advfirewall firewall delete rule name="\xe7\xb2\xbe\xe5\x87\x86\xe8\x90\xa5\xe9\x94\x80\xe6\x8e\xa8\xe5\xb9\xbf\xe5\xb7\xa5\xe5\x85\xb7" dir=in program="C:\Users\test\AppData\Roaming\szw\MasterZ\bin\MasterZ.exe"
  • netsh advfirewall firewall delete rule name="\xe7\xb2\xbe\xe5\x87\x86\xe8\x90\xa5\xe9\x94\x80\xe6\x8e\xa8\xe5\xb9\xbf\xe5\xb7\xa5\xe5\x85\xb7\xe4\xb8\xbb\xe6\x8e\xa7\xe7\xa8\x8b\xe5\xba\x8f" dir=in program="C:\Users\test\AppData\Roaming\szw\MasterZ\bin\MC.exe"
  • netsh advfirewall firewall delete rule name="\xe7\xb2\xbe\xe5\x87\x86\xe8\x90\xa5\xe9\x94\x80\xe6\x8e\xa8\xe5\xb9\xbf\xe5\xb7\xa5\xe5\x85\xb7\xe5\x86\x85\xe6\xa0\xb8\xe7\xa8\x8b\xe5\xba\x8f" dir=in program="C:\Users\test\AppData\Roaming\szw\MasterZ\bin\Engine.exe"
  • netsh advfirewall firewall delete rule name="\xe7\xb2\xbe\xe5\x87\x86\xe8\x90\xa5\xe9\x94\x80\xe6\x8e\xa8\xe5\xb9\xbf\xe5\xb7\xa5\xe5\x85\xb7SeekWord" dir=in program="C:\Users\test\AppData\Roaming\szw\MasterZ\bin\SeekWord.exe"
  • netsh advfirewall firewall delete rule name="\xe7\xb2\xbe\xe5\x87\x86\xe8\x90\xa5\xe9\x94\x80\xe6\x8e\xa8\xe5\xb9\xbf\xe5\xb7\xa5\xe5\x85\xb7SyncDat" dir=in program="C:\Users\test\AppData\Roaming\szw\MasterZ\bin\SyncDat.exe"
  • netsh advfirewall firewall delete rule name="MC.exe" program="C:\Users\test\AppData\Roaming\szw\MasterZ\bin\MC.exe"
  • netsh advfirewall firewall delete rule name="MasterZ.exe" program="C:\Users\test\AppData\Roaming\szw\MasterZ\bin\MasterZ.exe"
  • netsh advfirewall firewall delete rule name="Engine.exe" program="C:\Users\test\AppData\Roaming\szw\MasterZ\bin\Engine.exe"
  • netsh advfirewall firewall delete rule name="SeekWord.exe" program="C:\Users\test\AppData\Roaming\szw\MasterZ\bin\SeekWord.exe"
  • netsh advfirewall firewall delete rule name="SyncDat.exe" program="C:\Users\test\AppData\Roaming\szw\MasterZ\bin\SyncDat.exe"
  • netsh advfirewall firewall add rule name="\xe7\xb2\xbe\xe5\x87\x86\xe8\x90\xa5\xe9\x94\x80\xe6\x8e\xa8\xe5\xb9\xbf\xe5\xb7\xa5\xe5\x85\xb7" description="\xe7\xb2\xbe\xe5\x87\x86\xe8\x90\xa5\xe9\x94\x80\xe6\x8e\xa8\xe5\xb9\xbf\xe5\xb7\xa5\xe5\x85\xb7\xe5\xae\xa2\xe6\x88\xb7\xe7\xab\xaf\xe7\xa8\x8b\xe5\xba\x8f" dir=in program="C:\Users\test\AppData\Roaming\szw\MasterZ\bin\MasterZ.exe" action=allow
  • netsh advfirewall firewall add rule name="\xe7\xb2\xbe\xe5\x87\x86\xe8\x90\xa5\xe9\x94\x80\xe6\x8e\xa8\xe5\xb9\xbf\xe5\xb7\xa5\xe5\x85\xb7\xe4\xb8\xbb\xe6\x8e\xa7\xe7\xa8\x8b\xe5\xba\x8f" description="\xe7\xb2\xbe\xe5\x87\x86\xe8\x90\xa5\xe9\x94\x80\xe6\x8e\xa8\xe5\xb9\xbf\xe5\xb7\xa5\xe5\x85\xb7\xe4\xb8\xbb\xe6\x8e\xa7\xe7\xa8\x8b\xe5\xba\x8f" dir=in program="C:\Users\test\AppData\Roaming\szw\MasterZ\bin\MC.exe" action=allow
  • netsh advfirewall firewall add rule name="\xe7\xb2\xbe\xe5\x87\x86\xe8\x90\xa5\xe9\x94\x80\xe6\x8e\xa8\xe5\xb9\xbf\xe5\xb7\xa5\xe5\x85\xb7\xe5\x86\x85\xe6\xa0\xb8\xe7\xa8\x8b\xe5\xba\x8f" description="\xe7\xb2\xbe\xe5\x87\x86\xe8\x90\xa5\xe9\x94\x80\xe6\x8e\xa8\xe5\xb9\xbf\xe5\xb7\xa5\xe5\x85\xb7\xe5\x86\x85\xe6\xa0\xb8\xe7\xa8\x8b\xe5\xba\x8f" dir=in program="C:\Users\test\AppData\Roaming\szw\MasterZ\bin\Engine.exe" action=allow
  • netsh advfirewall firewall add rule name="\xe7\xb2\xbe\xe5\x87\x86\xe8\x90\xa5\xe9\x94\x80\xe6\x8e\xa8\xe5\xb9\xbf\xe5\xb7\xa5\xe5\x85\xb7SeekWord" description="\xe7\xb2\xbe\xe5\x87\x86\xe8\x90\xa5\xe9\x94\x80\xe6\x8e\xa8\xe5\xb9\xbf\xe5\xb7\xa5\xe5\x85\xb7SeekWord.exe" dir=in program="C:\Users\test\AppData\Roaming\szw\MasterZ\bin\SeekWord.exe" action=allow
  • netsh advfirewall firewall add rule name="\xe7\xb2\xbe\xe5\x87\x86\xe8\x90\xa5\xe9\x94\x80\xe6\x8e\xa8\xe5\xb9\xbf\xe5\xb7\xa5\xe5\x85\xb7SyncDat" description="\xe7\xb2\xbe\xe5\x87\x86\xe8\x90\xa5\xe9\x94\x80\xe6\x8e\xa8\xe5\xb9\xbf\xe5\xb7\xa5\xe5\x85\xb7SyncDat.exe" dir=in program="C:\Users\test\AppData\Roaming\szw\MasterZ\bin\SyncDat.exe" action=allow
  • regsvr32 "C:\Users\test\AppData\Roaming\szw\MasterZ\plugins\npszwplugin.dll" /s
  • regsvr32 "C:\Users\test\AppData\Roaming\szw\MasterZ\plugins\ieplugin.dll" /s
  • regsvr32 "C:\Users\test\AppData\Roaming\szw\MasterZ\bin\msxml3.dll" /s
  • "C:\Users\test\AppData\Roaming\szw\MasterZ\bin\MasterZ.exe" /Auto
  • C:\Users\test\AppData\Roaming\szw\MasterZ\bin\SyncDat.exe
  • net stop autorunser
  • C:\Windows\system32\net1 stop autorunser
  • C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe
  • C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe
  • C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
  • C:\Windows\system32\sppsvc.exe
创建的服务 无信息
启动的服务
  • HTTP

进程

MasterZ_Custom_93.exe PID: 2504, 上一级进程 PID: 2348

taskkill.exe PID: 2640, 上一级进程 PID: 2504

cmd.exe PID: 2716, 上一级进程 PID: 2504

net.exe PID: 2808, 上一级进程 PID: 2716

net1.exe PID: 2876, 上一级进程 PID: 2808

cmd.exe PID: 2988, 上一级进程 PID: 2504

netsh.exe PID: 1404, 上一级进程 PID: 2504

services.exe PID: 428, 上一级进程 PID: 332

netsh.exe PID: 2516, 上一级进程 PID: 2504

netsh.exe PID: 2680, 上一级进程 PID: 2504

netsh.exe PID: 1368, 上一级进程 PID: 2504

netsh.exe PID: 2976, 上一级进程 PID: 2504

netsh.exe PID: 3040, 上一级进程 PID: 2504

netsh.exe PID: 1940, 上一级进程 PID: 2504

netsh.exe PID: 1840, 上一级进程 PID: 2504

netsh.exe PID: 2660, 上一级进程 PID: 2504

netsh.exe PID: 1376, 上一级进程 PID: 2504

taskkill.exe PID: 2832, 上一级进程 PID: 2504

cmd.exe PID: 912, 上一级进程 PID: 2504

net.exe PID: 3048, 上一级进程 PID: 912

net1.exe PID: 3064, 上一级进程 PID: 3048

cmd.exe PID: 1192, 上一级进程 PID: 2504

netsh.exe PID: 2732, 上一级进程 PID: 2504

netsh.exe PID: 2572, 上一级进程 PID: 2504

netsh.exe PID: 252, 上一级进程 PID: 2504

netsh.exe PID: 2768, 上一级进程 PID: 2504

netsh.exe PID: 2220, 上一级进程 PID: 2504

netsh.exe PID: 2788, 上一级进程 PID: 2504

netsh.exe PID: 2664, 上一级进程 PID: 2504

netsh.exe PID: 2712, 上一级进程 PID: 2504

netsh.exe PID: 2892, 上一级进程 PID: 2504

netsh.exe PID: 2300, 上一级进程 PID: 2504

netsh.exe PID: 1716, 上一级进程 PID: 2504

netsh.exe PID: 960, 上一级进程 PID: 2504

netsh.exe PID: 1996, 上一级进程 PID: 2504

netsh.exe PID: 1256, 上一级进程 PID: 2504

netsh.exe PID: 1048, 上一级进程 PID: 2504

mscorsvw.exe PID: 2376, 上一级进程 PID: 428

mscorsvw.exe PID: 1144, 上一级进程 PID: 428

regsvr32.exe PID: 1460, 上一级进程 PID: 2504

regsvr32.exe PID: 3044, 上一级进程 PID: 2504

regsvr32.exe PID: 2388, 上一级进程 PID: 2504

MasterZ.exe PID: 1456, 上一级进程 PID: 2504

SyncDat.exe PID: 1912, 上一级进程 PID: 2504

访问的文件
  • \Device\KsecDD
  • C:\Users\test\AppData\Local\Temp\SHFOLDER.DLL
  • C:\Windows\System32\shfolder.dll
  • \??\MountPointManager
  • C:\Users\test\AppData\Local\Temp\
  • C:\Users\test\AppData\Local\Temp
  • C:\Users\test\AppData\Local\Temp\nso52C0.tmp
  • C:\Users\test\AppData\Local\Temp\MasterZ_Custom_93.exe
  • C:\Users\test\AppData\Local\Temp\nso53AB.tmp
  • C:\Users\test\AppData\Local\Temp\nse53BC.tmp
  • C:\Users
  • C:\Users\test
  • C:\Users\test\AppData
  • C:\Users\test\AppData\Local
  • C:\Users\test\AppData\Local\Temp\nse53BC.tmp\nsTBCIASkinEngine.dll
  • C:\Users\test\AppData\Local\Temp\nse53BC.tmp\RICHED20.dll
  • C:\Windows\System32\riched20.dll
  • C:\NUL
  • C:\Users\test\AppData\Local\Temp\nse53BC.tmp\System.dll
  • C:\Windows\Fonts\staticcache.dat
  • C:
  • C:\Users\test\AppData\Roaming
  • C:\Users\test\AppData\Roaming\szw
  • C:\Users\test\AppData\Local\Temp\nsz628C.tmp
  • C:\Users\test\AppData\Local\Temp\MasterZdll
  • C:\Users\test\AppData\Local\Temp\MasterZdll\ieplugin.dll
  • C:\Users\test\AppData\Local\Temp\MasterZdll\npszwplugin.dll
  • C:\Users\test\AppData\Local\Temp\nse53BC.tmp\ioSpecial.ini
  • C:\Users\test\AppData\Local\Temp\nse53BC.tmp\modern-wizard.bmp
  • C:\Users\test\AppData\Local\Temp\nse53BC.tmp\modern-header.bmp
  • C:\Users\test\AppData\Local\Temp\MasterZTMP
  • C:\
  • C:\Users\test\AppData\Local\Temp\MasterZTMP\*.*
  • C:\Users\test\AppData\Roaming\szw\MasterBK
  • C:\Users\test\AppData\Roaming\szw\MasterBK\*.*
  • C:\Windows\SysWOW64\ieframe.dll
  • C:\Users\test\AppData\Local\Temp\MasterZdll\taskkill.*
  • C:\Windows\System32\taskkill.*
  • C:\Windows
  • C:\Windows\System32
  • C:\Windows\SysWOW64\taskkill.exe
  • C:\Windows\SysWOW64\propsys.dll
  • C:\Windows\sysnative\propsys.dll
  • C:\Windows\System32\taskkill.exe
  • C:\Windows\System32\taskkill.exe:Zone.Identifier
  • C:\Users\test\AppData\Local\Temp\nse53BC.tmp\FindProcDLL.dll
  • C:\Users\test\AppData\Local\Temp\nse53BC.tmp\nsExec.dll
  • \Device\NamedPipe\
  • C:\Users\test\AppData\Roaming\Suminfo\BizExpressQY2.0
  • C:\Users\test\AppData\Roaming\Suminfo
  • C:\Users\test\AppData\Roaming\Suminfo\BizExpressQY2.0\*.*
  • C:\Users\test\AppData\Roaming\szw\MasterBK\data2\customize.dat
  • C:\Users\test\AppData\Roaming\szw\MasterBK\data2
  • C:\Users\test\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\\xe5\x8d\xb8\xe8\xbd\xbd.lnk
  • C:\Users\test\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\
  • C:\Users\test\AppData\Roaming\Microsoft\Windows\Start Menu\Programs
  • C:\Users\test\AppData\Roaming\Microsoft\Windows\Start Menu
  • C:\Users\test\AppData\Roaming\Microsoft\Windows
  • C:\Users\test\AppData\Roaming\Microsoft
  • C:\Users\test\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\\xe8\x88\x9f\xe5\xa4\xa7\xe5\xb8\x88\\xe5\x8d\xb8\xe8\xbd\xbd\xe8\x88\x9f\xe5\xa4\xa7\xe5\xb8\x88.lnk
  • C:\Users\test\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\\xe8\x88\x9f\xe5\xa4\xa7\xe5\xb8\x88
  • C:\Users\test\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\\xe8\x88\x9f\xe5\xa4\xa7\xe5\xb8\x88\\xe8\x88\x9f\xe5\xa4\xa7\xe5\xb8\x88.lnk
  • C:\Users\test\Desktop\\xe8\x88\x9f\xe5\xa4\xa7\xe5\xb8\x88.lnk
  • C:\Users\test\Desktop
  • \Device\NamedPipe
  • C:\Users\test\AppData\Roaming\szw\MasterZ\data2\customize.dat
  • C:\Users\test\AppData\Roaming\szw\MasterZ\data2
  • C:\Users\test\AppData\Roaming\szw\MasterZ
  • C:\Users\test\AppData\Roaming\szw\MasterZ\*.*
  • C:\Users\test\AppData\Roaming\szw\MasterZ\plugins\ieplugin.dll
  • C:\Users\test\AppData\Roaming\szw\MasterZ\plugins\npszwplugin.dll
  • C:\Users\test\AppData\Roaming\szw\MasterZ\CleanLog.bat
  • C:\Users\test\AppData\Roaming\szw\MasterZ\6
  • C:\Users\test\AppData\Roaming\szw\MasterZ\bin
  • C:\Users\test\AppData\Roaming\szw\MasterZ\bin\AutoRunService.exe
  • C:\Users\test\AppData\Roaming\szw\MasterZ\bin\AutomaticSearch.exe
  • C:\Users\test\AppData\Roaming\szw\MasterZ\bin\BugReport.dll
  • C:\Users\test\AppData\Roaming\szw\MasterZ\bin\CheckSystemDllExist.dat
  • C:\Users\test\AppData\Roaming\szw\MasterZ\bin\CheckSystemDllExist.exe
  • C:\Users\test\AppData\Roaming\szw\MasterZ\bin\CodeOCR.DLL
  • C:\Users\test\AppData\Roaming\szw\MasterZ\bin\CtrlUserTask.exe
  • C:\Users\test\AppData\Roaming\szw\MasterZ\bin\DataExchange.dll
  • C:\Users\test\AppData\Roaming\szw\MasterZ\bin\Deamon.exe
  • C:\Users\test\AppData\Roaming\szw\MasterZ\bin\Engine.exe
  • C:\Users\test\AppData\Roaming\szw\MasterZ\bin\ExTool.dll
  • C:\Users\test\AppData\Roaming\szw\MasterZ\bin\FastVerCode.dll
  • C:\Users\test\AppData\Roaming\szw\MasterZ\bin\GetRank.exe
  • C:\Users\test\AppData\Roaming\szw\MasterZ\bin\IAWS.dll
  • C:\Users\test\AppData\Roaming\szw\MasterZ\bin\InputOCR.dll
  • C:\Users\test\AppData\Roaming\szw\MasterZ\bin\KeyRW.dll
  • C:\Users\test\AppData\Roaming\szw\MasterZ\bin\KillProcess.exe
  • C:\Users\test\AppData\Roaming\szw\MasterZ\bin\KillService.bat
  • C:\Users\test\AppData\Roaming\szw\MasterZ\bin\MC.exe
  • C:\Users\test\AppData\Roaming\szw\MasterZ\bin\MSVCP71.DLL
  • C:\Users\test\AppData\Roaming\szw\MasterZ\bin\MasterZ.exe
  • C:\Users\test\AppData\Roaming\szw\MasterZ\bin\PreData.dll
  • C:\Users\test\AppData\Roaming\szw\MasterZ\bin\ProcessTask.dll
  • C:\Users\test\AppData\Roaming\szw\MasterZ\bin\RunService.bat
  • C:\Users\test\AppData\Roaming\szw\MasterZ\bin\RuoKuaiDLL.dll
  • C:\Users\test\AppData\Roaming\szw\MasterZ\bin\STGUI.dll
  • C:\Users\test\AppData\Roaming\szw\MasterZ\bin\SVCAR.dll
  • C:\Users\test\AppData\Roaming\szw\MasterZ\bin\SeekWord.exe
  • C:\Users\test\AppData\Roaming\szw\MasterZ\bin\SyncDat.dll
  • C:\Users\test\AppData\Roaming\szw\MasterZ\bin\SyncDat.exe
  • C:\Users\test\AppData\Roaming\szw\MasterZ\bin\SzwANN.dll
  • C:\Users\test\AppData\Roaming\szw\MasterZ\bin\TaskCtrl.dll
  • C:\Users\test\AppData\Roaming\szw\MasterZ\bin\UUWiseHelper.dll
  • C:\Users\test\AppData\Roaming\szw\MasterZ\bin\UpdateOL.bat
  • C:\Users\test\AppData\Roaming\szw\MasterZ\bin\UpdateOL.dll
  • C:\Users\test\AppData\Roaming\szw\MasterZ\bin\UpdateRank.dll
  • C:\Users\test\AppData\Roaming\szw\MasterZ\bin\UpdateRank.exe
  • C:\Users\test\AppData\Roaming\szw\MasterZ\bin\Utility.dll
  • C:\Users\test\AppData\Roaming\szw\MasterZ\bin\XMLRW.dll
  • C:\Users\test\AppData\Roaming\szw\MasterZ\bin\YunTask.dll
  • C:\Users\test\AppData\Roaming\szw\MasterZ\bin\gpsvc.dll
  • C:\Users\test\AppData\Roaming\szw\MasterZ\bin\ieshims.dll
  • C:\Users\test\AppData\Roaming\szw\MasterZ\bin\install.flag
  • C:\Users\test\AppData\Roaming\szw\MasterZ\bin\libapr-1.dll
  • C:\Users\test\AppData\Roaming\szw\MasterZ\bin\libaprutil-1.dll
  • C:\Users\test\AppData\Roaming\szw\MasterZ\bin\libcurl.dll
  • C:\Users\test\AppData\Roaming\szw\MasterZ\bin\libeay32.dll
  • C:\Users\test\AppData\Roaming\szw\MasterZ\bin\mfc120u.dll
  • C:\Users\test\AppData\Roaming\szw\MasterZ\bin\msvcp120.dll
  • C:\Users\test\AppData\Roaming\szw\MasterZ\bin\msvcr120.dll
  • C:\Users\test\AppData\Roaming\szw\MasterZ\bin\msvcr71.dll
  • C:\Users\test\AppData\Roaming\szw\MasterZ\bin\mxml1.dll
  • C:\Users\test\AppData\Roaming\szw\MasterZ\bin\sqlite3.dll
  • C:\Users\test\AppData\Roaming\szw\MasterZ\bin\ssleay32.dll
  • C:\Users\test\AppData\Roaming\szw\MasterZ\bin\yundamaAPI.dll
  • C:\Users\test\AppData\Roaming\szw\MasterZ\bin\zlib1.dll
  • C:\Users\test\AppData\Roaming\szw\MasterZ\bin\skin
  • C:\Users\test\AppData\Roaming\szw\MasterZ\bin\skin\ProblemList.xml
  • C:\Users\test\AppData\Roaming\szw\MasterZ\bin\skin\skin.zip
  • C:\Users\test\AppData\Roaming\szw\MasterZ\bin\skin\FusionCharts
  • C:\Users\test\AppData\Roaming\szw\MasterZ\bin\skin\FusionCharts\ZhenCiTemplate.html
  • C:\Users\test\AppData\Roaming\szw\MasterZ\bin\skin\FusionCharts\keyword.html
  • C:\Users\test\AppData\Roaming\szw\MasterZ\bin\skin\FusionCharts\noexposuredata.html
  • C:\Users\test\AppData\Roaming\szw\MasterZ\bin\skin\FusionCharts\nokeyworddata.html
  • C:\Users\test\AppData\Roaming\szw\MasterZ\bin\skin\FusionCharts\images
  • C:\Users\test\AppData\Roaming\szw\MasterZ\bin\skin\FusionCharts\images\close.png
  • C:\Users\test\AppData\Roaming\szw\MasterZ\bin\skin\FusionCharts\images\see.png
  • C:\Users\test\AppData\Roaming\szw\MasterZ\bin\skin\FusionCharts\js
  • C:\Users\test\AppData\Roaming\szw\MasterZ\bin\skin\FusionCharts\js\Common.js
  • C:\Users\test\AppData\Roaming\szw\MasterZ\bin\skin\FusionCharts\js\echarts.js
  • C:\Users\test\AppData\Roaming\szw\MasterZ\bin\skin\FusionCharts\js\jquery-1.11.2.min.js
  • C:\Users\test\AppData\Roaming\szw\MasterZ\bin\skin\FusionCharts\js\chart
  • C:\Users\test\AppData\Roaming\szw\MasterZ\bin\skin\FusionCharts\js\chart\bar.js
  • C:\Users\test\AppData\Roaming\szw\MasterZ\bin\skin\FusionCharts\js\chart\line.js
  • C:\Users\test\AppData\Roaming\szw\MasterZ\data
  • C:\Users\test\AppData\Roaming\szw\MasterZ\data2\AutoProgram.ini
  • C:\Users\test\AppData\Roaming\szw\MasterZ\data2\Key.dat
  • C:\Users\test\AppData\Roaming\szw\MasterZ\data2\ParamData.dat
  • C:\Users\test\AppData\Roaming\szw\MasterZ\data2\ReferenceList.dat
  • C:\Users\test\AppData\Roaming\szw\MasterZ\data2\UpdateOL.dat
  • C:\Users\test\AppData\Roaming\szw\MasterZ\data2\YunTask.dat
  • C:\Users\test\AppData\Roaming\szw\MasterZ\data2\component.dat
  • C:\Users\test\AppData\Roaming\szw\MasterZ\data2\engine.dat
  • C:\Users\test\AppData\Roaming\szw\MasterZ\data2\mc.dat
  • C:\Users\test\AppData\Roaming\szw\MasterZ\data2\updaterank.dat
  • C:\Users\test\AppData\Roaming\szw\MasterZ\db
  • C:\Users\test\AppData\Roaming\szw\MasterZ\image
  • C:\Users\test\AppData\Roaming\szw\MasterZ\image\code
  • C:\Users\test\AppData\Roaming\szw\MasterZ\image\keyword
  • C:\Users\test\AppData\Roaming\szw\MasterZ\image\result
  • C:\Users\test\AppData\Roaming\szw\MasterZ\image\user
  • C:\Users\test\AppData\Roaming\szw\MasterZ\log
  • C:\Users\test\AppData\Roaming\szw\MasterZ\log\core
  • C:\Users\test\AppData\Roaming\szw\MasterZ\mod
  • C:\Users\test\AppData\Roaming\szw\MasterZ\mod\Quest.dat
  • C:\Users\test\AppData\Roaming\szw\MasterZ\mod\sum40000501.Mod
  • C:\Users\test\AppData\Roaming\szw\MasterZ\mod\sum40000511.Mod
  • C:\Users\test\AppData\Roaming\szw\MasterZ\mod\sum40000747.Mod
  • C:\Users\test\AppData\Roaming\szw\MasterZ\mod\sum40020637.Mod
  • C:\Users\test\AppData\Roaming\szw\MasterZ\mod\sum40043398.Mod
  • C:\Users\test\AppData\Roaming\szw\MasterZ\plugins
  • C:\Users\test\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\\xe6\xa0\x87\xe5\x87\x86\xe4\xbb\xb6
  • C:\Users\desktop.ini
  • C:\Users\test\AppData\Roaming\szw\MasterZ\uninst.exe
  • \??\Volume{372941a4-1bd9-11e5-9838-806e6f6e6963}\
  • C:\Users\test\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\\xe6\xa0\x87\xe5\x87\x86\xe4\xbb\xb6\\xe5\x8d\xb8\xe8\xbd\xbd\xe6\xa0\x87\xe5\x87\x86\xe4\xbb\xb6.lnk
  • C:\Users\test\AppData\Local\Temp\nse53BC.tmp\InstallOptions.dll
  • C:\Windows\SysWOW64\zh-CN\KERNELBASE.dll.mui
  • C:\Windows\Globalization\Sorting\sortdefault.nls
  • C:\Users\test\AppData\Local\Temp\MasterZdll\net.*
  • C:\Users\test\AppData\Local\Temp\MasterZdll\net
  • C:\ProgramData\Oracle\Java\javapath\net.*
  • C:\ProgramData\Oracle\Java\javapath\net
  • C:\Windows\System32\net.*
  • C:\Windows\System32\net.COM
  • C:\Windows\System32\net.exe
  • C:\Windows\SysWOW64\netmsg.dll
  • \Device\Http\Communication
  • C:\Windows\System32\p2pcollab.dll
  • C:\Windows\System32\qagentrt.dll
  • C:\Windows\System32\dnsapi.dll
  • C:\Windows\System32\DHCPQEC.DLL
  • C:\Windows\System32\napipsec.dll
  • C:\Windows\System32\zh-CN\napipsec.dll.mui
  • C:\Windows\System32\tsgqec.dll
  • C:\Windows\System32\EAPQEC.DLL
  • C:\Windows\System32\zh-CN\eapqec.dll.mui
  • C:\Windows\SysWOW64\zh-CN\P2PNETSH.DLL.mui
  • C:\Windows\SysWOW64\zh-CN\AUTHFWCFG.DLL.mui
  • C:\Windows\Temp
  • C:\Windows\ServiceProfiles\LocalService\AppData\Local\Temp
  • C:\Windows\ServiceProfiles
  • C:\Windows\ServiceProfiles\LocalService
  • C:\Windows\ServiceProfiles\NetworkService\AppData\Local\Temp
  • C:\Windows\ServiceProfiles\NetworkService
  • C:\Windows\Microsoft.NET\Framework\v4.0.30319\ndpsetup.bat
  • C:\Windows\Microsoft.NET\Framework\v4.0.30319\ngenservicelock.dat
  • C:\Windows\Microsoft.NET\Framework\v4.0.30319\ngenrootstorelock.dat
  • C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ndpsetup.bat
  • C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ngenservicelock.dat
  • C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ngenrootstorelock.dat
  • C:\Users\test\AppData\Roaming\szw\MasterZ\plugins\IPHLPAPI.DLL
  • C:\Windows\System32\IPHLPAPI.DLL
  • C:\Users\test\AppData\Roaming\szw\MasterZ\plugins\WINNSI.DLL
  • C:\Windows\System32\winnsi.dll
  • C:\Users\test\AppData\Roaming\szw\MasterZ\plugins\WSOCK32.dll
  • C:\Windows\System32\wsock32.dll
  • C:\Users\test\AppData\Roaming\szw\MasterZ\bin\msxml3.dll
  • C:\Users\test\AppData\Roaming\szw\MasterZ\bin\XMLRWCHS.dll
  • C:\Users\test\AppData\Roaming\szw\MasterZ\bin\XMLRWCHS.dll.DLL
  • C:\Users\test\AppData\Roaming\szw\MasterZ\bin\XMLRWENU.dll
  • C:\Users\test\AppData\Roaming\szw\MasterZ\bin\XMLRWENU.dll.DLL
  • C:\Users\test\AppData\Roaming\szw\MasterZ\bin\XMLRWLOC.dll
  • C:\Users\test\AppData\Roaming\szw\MasterZ\bin\XMLRWLOC.dll.DLL
  • C:\Users\test\AppData\Roaming\szw\MasterZ\bin\KeyRWCHS.dll
  • C:\Users\test\AppData\Roaming\szw\MasterZ\bin\KeyRWCHS.dll.DLL
  • C:\Users\test\AppData\Roaming\szw\MasterZ\bin\KeyRWENU.dll
  • C:\Users\test\AppData\Roaming\szw\MasterZ\bin\KeyRWENU.dll.DLL
  • C:\Users\test\AppData\Roaming\szw\MasterZ\bin\KeyRWLOC.dll
  • C:\Users\test\AppData\Roaming\szw\MasterZ\bin\KeyRWLOC.dll.DLL
  • C:\Users\test\AppData\Roaming\szw\MasterZ\log\runlog.log
  • C:\Users\test\AppData\Roaming\szw\MasterZ\data2\version.dat
  • C:\Users\test\AppData\Roaming\szw\MasterZ\bin\UxTheme.dll
  • C:\Windows\System32\uxtheme.dll
  • C:\Users\test\AppData\Roaming\szw\MasterZ\bin\MFC120CHS.DLL
  • C:\Users\test\AppData\Roaming\szw\MasterZ\bin\MFC120CHS.DLL.DLL
  • C:\Users\test\AppData\Roaming\szw\MasterZ\bin\MFC120ENU.DLL
  • C:\Users\test\AppData\Roaming\szw\MasterZ\bin\MFC120ENU.DLL.DLL
  • C:\Users\test\AppData\Roaming\szw\MasterZ\log\DatSync.log
  • C:\Users\test\AppData\Roaming\szw\MasterZ\6\0.bin
  • C:\Users\test\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\CB4GP22D\0[1].bin
  • C:\Users\test\AppData\Roaming\szw\MasterZ\6\1.bin
  • C:\Users\test\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\EHDRIWWS\1[1].bin
  • C:\Users\test\AppData\Roaming\szw\MasterZ\6\SiteList.txt
  • C:\Users\test\AppData\Roaming\szw\MasterZ\6\StationLastupdate.txt
  • C:\Users\test\AppData\Roaming\szw\MasterZ\data\40000002.dat
  • C:\Users\test\AppData\Roaming\szw\MasterZ\data\40000002.bin
  • C:\Users\test\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\HEL4YQ7U\40000002[1].bin
  • C:\Users\test\AppData\Roaming\szw\MasterZ\data\40000003.dat
  • C:\Users\test\AppData\Roaming\szw\MasterZ\data\40000003.bin
  • C:\Users\test\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\CB4GP22D\40000003[1].bin
  • C:\Users\test\AppData\Roaming\szw\MasterZ\data\40000502.dat
  • C:\Users\test\AppData\Roaming\szw\MasterZ\data\40000502.bin
  • C:\Users\test\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\EHDRIWWS\40000502[1].bin
  • C:\Users\test\AppData\Roaming\szw\MasterZ\data\40000503.dat
  • C:\Users\test\AppData\Roaming\szw\MasterZ\data\40000503.bin
  • C:\Users\test\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\IDL4J1KW\40000503[1].bin
  • C:\Users\test\AppData\Roaming\szw\MasterZ\data\40000505.dat
  • C:\Users\test\AppData\Roaming\szw\MasterZ\data\40000505.bin
  • C:\Users\test\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\HEL4YQ7U\40000505[1].bin
  • C:\Users\test\AppData\Roaming\szw\MasterZ\data\40000506.dat
  • C:\Users\test\AppData\Roaming\szw\MasterZ\data\40000506.bin
  • C:\Users\test\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\CB4GP22D\40000506[1].bin
  • C:\Users\test\AppData\Roaming\szw\MasterZ\data\40000507.dat
  • C:\Users\test\AppData\Roaming\szw\MasterZ\data\40000507.bin
  • C:\Users\test\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\EHDRIWWS\40000507[1].bin
  • C:\Users\test\AppData\Roaming\szw\MasterZ\data\40000508.dat
  • C:\Users\test\AppData\Roaming\szw\MasterZ\data\40000508.bin
  • C:\Users\test\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\IDL4J1KW\40000508[1].bin
  • C:\Users\test\AppData\Roaming\szw\MasterZ\data\40000510.dat
  • C:\Users\test\AppData\Roaming\szw\MasterZ\data\40000510.bin
  • C:\Users\test\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\HEL4YQ7U\40000510[1].bin
  • C:\Users\test\AppData\Roaming\szw\MasterZ\data\40000515.dat
  • C:\Users\test\AppData\Roaming\szw\MasterZ\data\40000515.bin
  • C:\Users\test\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\CB4GP22D\40000515[1].bin
  • C:\Users\test\AppData\Roaming\szw\MasterZ\data\40000527.dat
  • C:\Users\test\AppData\Roaming\szw\MasterZ\data\40000527.bin
  • C:\Users\test\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\EHDRIWWS\40000527[1].bin
  • C:\Users\test\AppData\Roaming\szw\MasterZ\data\40000530.dat
  • C:\Users\test\AppData\Roaming\szw\MasterZ\data\40000530.bin
  • C:\Users\test\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\IDL4J1KW\40000530[1].bin
  • C:\Users\test\AppData\Roaming\szw\MasterZ\data\40000531.dat
  • C:\Users\test\AppData\Roaming\szw\MasterZ\data\40000531.bin
  • C:\Users\test\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\HEL4YQ7U\40000531[1].bin
  • C:\Users\test\AppData\Roaming\szw\MasterZ\data\40000534.dat
  • C:\Users\test\AppData\Roaming\szw\MasterZ\data\40000534.bin
  • C:\Users\test\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\CB4GP22D\40000534[1].bin
  • C:\Users\test\AppData\Roaming\szw\MasterZ\data\40000540.dat
  • C:\Users\test\AppData\Roaming\szw\MasterZ\data\40000540.bin
  • C:\Users\test\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\EHDRIWWS\40000540[1].bin
  • C:\Users\test\AppData\Roaming\szw\MasterZ\data\40000547.dat
  • C:\Users\test\AppData\Roaming\szw\MasterZ\data\40000547.bin
  • C:\Users\test\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\IDL4J1KW\40000547[1].bin
  • C:\Users\test\AppData\Roaming\szw\MasterZ\data\40000554.dat
  • C:\Users\test\AppData\Roaming\szw\MasterZ\data\40000554.bin
  • C:\Users\test\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\HEL4YQ7U\40000554[1].bin
  • C:\Users\test\AppData\Roaming\szw\MasterZ\data\40000555.dat
  • C:\Users\test\AppData\Roaming\szw\MasterZ\data\40000555.bin
  • C:\Users\test\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\CB4GP22D\40000555[1].bin
  • C:\Users\test\AppData\Roaming\szw\MasterZ\data\40000557.dat
  • C:\Users\test\AppData\Roaming\szw\MasterZ\data\40000557.bin
  • C:\Users\test\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\EHDRIWWS\40000557[1].bin
  • C:\Users\test\AppData\Roaming\szw\MasterZ\data\40000559.dat
  • C:\Users\test\AppData\Roaming\szw\MasterZ\data\40000559.bin
  • C:\Users\test\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\IDL4J1KW\40000559[1].bin
  • C:\Users\test\AppData\Roaming\szw\MasterZ\data\40000560.dat
  • C:\Users\test\AppData\Roaming\szw\MasterZ\data\40000560.bin
  • C:\Users\test\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\HEL4YQ7U\40000560[1].bin
  • C:\Users\test\AppData\Roaming\szw\MasterZ\data\40000564.dat
  • C:\Users\test\AppData\Roaming\szw\MasterZ\data\40000564.bin
  • C:\Users\test\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\CB4GP22D\40000564[1].bin
  • C:\Users\test\AppData\Roaming\szw\MasterZ\data\40000570.dat
  • C:\Users\test\AppData\Roaming\szw\MasterZ\data\40000570.bin
  • C:\Users\test\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\EHDRIWWS\40000570[1].bin
  • C:\Users\test\AppData\Roaming\szw\MasterZ\data\40000571.dat
  • C:\Users\test\AppData\Roaming\szw\MasterZ\data\40000571.bin
  • C:\Users\test\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\IDL4J1KW\40000571[1].bin
  • C:\Users\test\AppData\Roaming\szw\MasterZ\data\40000577.dat
  • C:\Users\test\AppData\Roaming\szw\MasterZ\data\40000577.bin
  • C:\Users\test\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\HEL4YQ7U\40000577[1].bin
  • C:\Users\test\AppData\Roaming\szw\MasterZ\data\40000581.dat
  • C:\Users\test\AppData\Roaming\szw\MasterZ\data\40000581.bin
  • C:\Users\test\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\CB4GP22D\40000581[1].bin
  • C:\Users\test\AppData\Roaming\szw\MasterZ\data\40000582.dat
  • C:\Users\test\AppData\Roaming\szw\MasterZ\data\40000582.bin
  • C:\Users\test\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\EHDRIWWS\40000582[1].bin
  • C:\Users\test\AppData\Roaming\szw\MasterZ\data\40000584.dat
  • C:\Users\test\AppData\Roaming\szw\MasterZ\data\40000584.bin
  • C:\Users\test\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\IDL4J1KW\40000584[1].bin
  • C:\Users\test\AppData\Roaming\szw\MasterZ\data\40000588.dat
  • C:\Users\test\AppData\Roaming\szw\MasterZ\data\40000588.bin
  • C:\Users\test\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\HEL4YQ7U\40000588[1].bin
  • C:\Users\test\AppData\Roaming\szw\MasterZ\data\40000596.dat
  • C:\Users\test\AppData\Roaming\szw\MasterZ\data\40000596.bin
  • C:\Users\test\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\CB4GP22D\40000596[1].bin
  • C:\Users\test\AppData\Roaming\szw\MasterZ\data\40000598.dat
  • C:\Users\test\AppData\Roaming\szw\MasterZ\data\40000598.bin
  • C:\Users\test\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\EHDRIWWS\40000598[1].bin
  • C:\Users\test\AppData\Roaming\szw\MasterZ\data\40000600.dat
  • C:\Users\test\AppData\Roaming\szw\MasterZ\data\40000600.bin
  • C:\Users\test\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\IDL4J1KW\40000600[1].bin
  • C:\Users\test\AppData\Roaming\szw\MasterZ\data\40000609.dat
  • C:\Users\test\AppData\Roaming\szw\MasterZ\data\40000609.bin
  • C:\Users\test\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\HEL4YQ7U\40000609[1].bin
  • C:\Users\test\AppData\Roaming\szw\MasterZ\data\40000619.dat
  • C:\Users\test\AppData\Roaming\szw\MasterZ\data\40000619.bin
  • C:\Users\test\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\CB4GP22D\40000619[1].bin
  • C:\Users\test\AppData\Roaming\szw\MasterZ\data\40000622.dat
  • C:\Users\test\AppData\Roaming\szw\MasterZ\data\40000622.bin
  • C:\Users\test\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\EHDRIWWS\40000622[1].bin
  • C:\Users\test\AppData\Roaming\szw\MasterZ\data\40000626.dat
  • C:\Users\test\AppData\Roaming\szw\MasterZ\data\40000626.bin
  • C:\Users\test\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\IDL4J1KW\40000626[1].bin
  • C:\Users\test\AppData\Roaming\szw\MasterZ\data\40000634.dat
  • C:\Users\test\AppData\Roaming\szw\MasterZ\data\40000634.bin
  • C:\Users\test\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\HEL4YQ7U\40000634[1].bin
  • C:\Users\test\AppData\Roaming\szw\MasterZ\data\40000637.dat
  • C:\Users\test\AppData\Roaming\szw\MasterZ\data\40000637.bin
  • C:\Users\test\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\CB4GP22D\40000637[1].bin
  • C:\Users\test\AppData\Roaming\szw\MasterZ\data\40000638.dat
  • C:\Users\test\AppData\Roaming\szw\MasterZ\data\40000638.bin
  • C:\Users\test\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\EHDRIWWS\40000638[1].bin
  • C:\Users\test\AppData\Roaming\szw\MasterZ\data\40000639.dat
  • C:\Users\test\AppData\Roaming\szw\MasterZ\data\40000639.bin
  • C:\Users\test\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\IDL4J1KW\40000639[1].bin
  • C:\Users\test\AppData\Roaming\szw\MasterZ\data\40000643.dat
  • C:\Users\test\AppData\Roaming\szw\MasterZ\data\40000643.bin
  • C:\Users\test\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\HEL4YQ7U\40000643[1].bin
  • C:\Users\test\AppData\Roaming\szw\MasterZ\data\40000656.dat
  • C:\Users\test\AppData\Roaming\szw\MasterZ\data\40000656.bin
  • C:\Users\test\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\CB4GP22D\40000656[1].bin
  • C:\Users\test\AppData\Roaming\szw\MasterZ\data\40000658.dat
  • C:\Users\test\AppData\Roaming\szw\MasterZ\data\40000658.bin
  • C:\Users\test\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\EHDRIWWS\40000658[1].bin
  • C:\Users\test\AppData\Roaming\szw\MasterZ\data\40000670.dat
  • C:\Users\test\AppData\Roaming\szw\MasterZ\data\40000670.bin
  • C:\Users\test\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\IDL4J1KW\40000670[1].bin
  • C:\Users\test\AppData\Roaming\szw\MasterZ\data\40000707.dat
  • C:\Users\test\AppData\Roaming\szw\MasterZ\data\40000707.bin
  • C:\Users\test\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\HEL4YQ7U\40000707[1].bin
  • C:\Users\test\AppData\Roaming\szw\MasterZ\data\40000714.dat
  • C:\Users\test\AppData\Roaming\szw\MasterZ\data\40000714.bin
  • C:\Users\test\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\CB4GP22D\40000714[1].bin
  • C:\Users\test\AppData\Roaming\szw\MasterZ\data\40000722.dat
  • C:\Users\test\AppData\Roaming\szw\MasterZ\data\40000722.bin
  • C:\Users\test\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\EHDRIWWS\40000722[1].bin
  • C:\Users\test\AppData\Roaming\szw\MasterZ\data\40000725.dat
  • C:\Users\test\AppData\Roaming\szw\MasterZ\data\40000725.bin
  • C:\Users\test\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\IDL4J1KW\40000725[1].bin
  • C:\Users\test\AppData\Roaming\szw\MasterZ\data\40000740.dat
  • C:\Users\test\AppData\Roaming\szw\MasterZ\data\40000740.bin
  • C:\Users\test\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\HEL4YQ7U\40000740[1].bin
  • C:\Users\test\AppData\Roaming\szw\MasterZ\data\40000748.dat
  • C:\Users\test\AppData\Roaming\szw\MasterZ\data\40000748.bin
  • C:\Users\test\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\CB4GP22D\40000748[1].bin
  • C:\Users\test\AppData\Roaming\szw\MasterZ\data\40000760.dat
  • C:\Users\test\AppData\Roaming\szw\MasterZ\data\40000760.bin
  • C:\Users\test\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\EHDRIWWS\40000760[1].bin
  • C:\Users\test\AppData\Roaming\szw\MasterZ\data\40000767.dat
  • C:\Users\test\AppData\Roaming\szw\MasterZ\data\40000767.bin
  • C:\Users\test\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\IDL4J1KW\40000767[1].bin
  • C:\Users\test\AppData\Roaming\szw\MasterZ\data\40000777.dat
  • C:\Users\test\AppData\Roaming\szw\MasterZ\data\40000777.bin
  • C:\Users\test\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\HEL4YQ7U\40000777[1].bin
  • C:\Users\test\AppData\Roaming\szw\MasterZ\data\40000790.dat
  • C:\Users\test\AppData\Roaming\szw\MasterZ\data\40000790.bin
  • C:\Users\test\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\CB4GP22D\40000790[1].bin
  • C:\Users\test\AppData\Roaming\szw\MasterZ\data\40000791.dat
  • C:\Users\test\AppData\Roaming\szw\MasterZ\data\40000791.bin
  • C:\Users\test\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\EHDRIWWS\40000791[1].bin
  • C:\Users\test\AppData\Roaming\szw\MasterZ\data\40000806.dat
  • C:\Users\test\AppData\Roaming\szw\MasterZ\data\40000806.bin
  • C:\Users\test\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\IDL4J1KW\40000806[1].bin
  • C:\Users\test\AppData\Roaming\szw\MasterZ\data\40000807.dat
  • C:\Users\test\AppData\Roaming\szw\MasterZ\data\40000807.bin
  • C:\Users\test\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\HEL4YQ7U\40000807[1].bin
  • C:\Users\test\AppData\Roaming\szw\MasterZ\data\40000808.dat
  • C:\Users\test\AppData\Roaming\szw\MasterZ\data\40000808.bin
  • C:\Users\test\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\CB4GP22D\40000808[1].bin
  • C:\Users\test\AppData\Roaming\szw\MasterZ\data\40000809.dat
  • C:\Users\test\AppData\Roaming\szw\MasterZ\data\40000809.bin
  • C:\Users\test\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\EHDRIWWS\40000809[1].bin
  • C:\Users\test\AppData\Roaming\szw\MasterZ\data\40000810.dat
  • C:\Users\test\AppData\Roaming\szw\MasterZ\data\40000810.bin
  • C:\Users\test\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\IDL4J1KW\40000810[1].bin
  • C:\Users\test\AppData\Roaming\szw\MasterZ\data\40000821.dat
  • C:\Users\test\AppData\Roaming\szw\MasterZ\data\40000821.bin
  • C:\Users\test\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\HEL4YQ7U\40000821[1].bin
  • C:\Users\test\AppData\Roaming\szw\MasterZ\data\40000822.dat
  • C:\Users\test\AppData\Roaming\szw\MasterZ\data\40000822.bin
  • C:\Users\test\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\CB4GP22D\40000822[1].bin
  • C:\Users\test\AppData\Roaming\szw\MasterZ\data\40000830.dat
  • C:\Users\test\AppData\Roaming\szw\MasterZ\data\40000830.bin
  • C:\Users\test\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\EHDRIWWS\40000830[1].bin
  • C:\Users\test\AppData\Roaming\szw\MasterZ\data\40000831.dat
  • C:\Users\test\AppData\Roaming\szw\MasterZ\data\40000831.bin
  • C:\Users\test\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\IDL4J1KW\40000831[1].bin
  • C:\Users\test\AppData\Roaming\szw\MasterZ\data\40000834.dat
  • C:\Users\test\AppData\Roaming\szw\MasterZ\data\40000834.bin
  • C:\Users\test\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\HEL4YQ7U\40000834[1].bin
  • C:\Users\test\AppData\Roaming\szw\MasterZ\data\40000835.dat
  • C:\Users\test\AppData\Roaming\szw\MasterZ\data\40000835.bin
  • C:\Users\test\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\CB4GP22D\40000835[1].bin
  • C:\Users\test\AppData\Roaming\szw\MasterZ\data\40000836.dat
  • C:\Users\test\AppData\Roaming\szw\MasterZ\data\40000836.bin
  • C:\Users\test\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\EHDRIWWS\40000836[1].bin
  • C:\Users\test\AppData\Roaming\szw\MasterZ\data\40000837.dat
  • C:\Users\test\AppData\Roaming\szw\MasterZ\data\40000837.bin
  • C:\Users\test\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\IDL4J1KW\40000837[1].bin
  • C:\Users\test\AppData\Roaming\szw\MasterZ\data\40000838.dat
  • C:\Users\test\AppData\Roaming\szw\MasterZ\data\40000838.bin
  • C:\Users\test\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\HEL4YQ7U\40000838[1].bin
  • C:\Users\test\AppData\Roaming\szw\MasterZ\data\40000849.dat
  • C:\Users\test\AppData\Roaming\szw\MasterZ\data\40000849.bin
  • C:\Users\test\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\CB4GP22D\40000849[1].bin
  • C:\Users\test\AppData\Roaming\szw\MasterZ\data\40000851.dat
  • C:\Users\test\AppData\Roaming\szw\MasterZ\data\40000851.bin
  • C:\Users\test\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\EHDRIWWS\40000851[1].bin
  • C:\Users\test\AppData\Roaming\szw\MasterZ\data\40000852.dat
  • C:\Users\test\AppData\Roaming\szw\MasterZ\data\40000852.bin
  • C:\Users\test\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\IDL4J1KW\40000852[1].bin
  • C:\Users\test\AppData\Roaming\szw\MasterZ\data\40000856.dat
  • C:\Users\test\AppData\Roaming\szw\MasterZ\data\40000856.bin
  • C:\Users\test\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\HEL4YQ7U\40000856[1].bin
  • C:\Users\test\AppData\Roaming\szw\MasterZ\data\40000859.dat
  • C:\Users\test\AppData\Roaming\szw\MasterZ\data\40000859.bin
  • C:\Users\test\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\CB4GP22D\40000859[1].bin
  • C:\Users\test\AppData\Roaming\szw\MasterZ\data\40000863.dat
  • C:\Users\test\AppData\Roaming\szw\MasterZ\data\40000863.bin
  • C:\Users\test\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\EHDRIWWS\40000863[1].bin
  • C:\Users\test\AppData\Roaming\szw\MasterZ\data\40000864.dat
  • C:\Users\test\AppData\Roaming\szw\MasterZ\data\40000864.bin
  • C:\Users\test\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\IDL4J1KW\40000864[1].bin
  • C:\Users\test\AppData\Roaming\szw\MasterZ\data\40000865.dat
  • C:\Users\test\AppData\Roaming\szw\MasterZ\data\40000865.bin
  • C:\Users\test\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\HEL4YQ7U\40000865[1].bin
  • C:\Users\test\AppData\Roaming\szw\MasterZ\data\40000866.dat
  • C:\Users\test\AppData\Roaming\szw\MasterZ\data\40000866.bin
  • C:\Users\test\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\CB4GP22D\40000866[1].bin
  • C:\Users\test\AppData\Roaming\szw\MasterZ\data\40000875.dat
  • C:\Users\test\AppData\Roaming\szw\MasterZ\data\40000875.bin
  • C:\Users\test\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\EHDRIWWS\40000875[1].bin
  • C:\Users\test\AppData\Roaming\szw\MasterZ\data\40000878.dat
  • C:\Users\test\AppData\Roaming\szw\MasterZ\data\40000878.bin
  • C:\Users\test\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\IDL4J1KW\40000878[1].bin
  • C:\Users\test\AppData\Roaming\szw\MasterZ\data\40000879.dat
  • C:\Users\test\AppData\Roaming\szw\MasterZ\data\40000879.bin
  • C:\Users\test\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\HEL4YQ7U\40000879[1].bin
  • C:\Users\test\AppData\Roaming\szw\MasterZ\data\40000880.dat
  • C:\Users\test\AppData\Roaming\szw\MasterZ\data\40000880.bin
  • C:\Users\test\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\CB4GP22D\40000880[1].bin
  • C:\Users\test\AppData\Roaming\szw\MasterZ\data\40000893.dat
  • C:\Users\test\AppData\Roaming\szw\MasterZ\data\40000893.bin
  • C:\Users\test\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\EHDRIWWS\40000893[1].bin
  • C:\Users\test\AppData\Roaming\szw\MasterZ\data\40000894.dat
  • C:\Users\test\AppData\Roaming\szw\MasterZ\data\40000894.bin
  • C:\Users\test\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\IDL4J1KW\40000894[1].bin
  • C:\Users\test\AppData\Roaming\szw\MasterZ\data\40000895.dat
  • C:\Users\test\AppData\Roaming\szw\MasterZ\data\40000895.bin
  • C:\Users\test\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\HEL4YQ7U\40000895[1].bin
  • C:\Users\test\AppData\Roaming\szw\MasterZ\data\40000896.dat
  • C:\Users\test\AppData\Roaming\szw\MasterZ\data\40000896.bin
  • C:\Users\test\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\CB4GP22D\40000896[1].bin
  • C:\Users\test\AppData\Roaming\szw\MasterZ\data\40000897.dat
  • C:\Users\test\AppData\Roaming\szw\MasterZ\data\40000897.bin
  • C:\Users\test\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\EHDRIWWS\40000897[1].bin
  • C:\Users\test\AppData\Roaming\szw\MasterZ\data\40000907.dat
  • C:\Users\test\AppData\Roaming\szw\MasterZ\data\40000907.bin
  • C:\Users\test\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\IDL4J1KW\40000907[1].bin
  • C:\Users\test\AppData\Roaming\szw\MasterZ\data\40000908.dat
  • C:\Users\test\AppData\Roaming\szw\MasterZ\data\40000908.bin
  • C:\Users\test\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\HEL4YQ7U\40000908[1].bin
  • C:\Users\test\AppData\Roaming\szw\MasterZ\data\40000909.dat
  • C:\Users\test\AppData\Roaming\szw\MasterZ\data\40000909.bin
  • C:\Users\test\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\CB4GP22D\40000909[1].bin
  • C:\Users\test\AppData\Roaming\szw\MasterZ\data\40000917.dat
  • C:\Users\test\AppData\Roaming\szw\MasterZ\data\40000917.bin
  • C:\Users\test\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\EHDRIWWS\40000917[1].bin
  • C:\Users\test\AppData\Roaming\szw\MasterZ\data\40000918.dat
  • C:\Users\test\AppData\Roaming\szw\MasterZ\data\40000918.bin
  • C:\Users\test\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\IDL4J1KW\40000918[1].bin
  • C:\Users\test\AppData\Roaming\szw\MasterZ\data\40000919.dat
  • C:\Users\test\AppData\Roaming\szw\MasterZ\data\40000919.bin
  • C:\Users\test\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\HEL4YQ7U\40000919[1].bin
  • C:\Users\test\AppData\Roaming\szw\MasterZ\data\40000922.dat
  • C:\Users\test\AppData\Roaming\szw\MasterZ\data\40000922.bin
  • C:\Users\test\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\CB4GP22D\40000922[1].bin
  • C:\Users\test\AppData\Roaming\szw\MasterZ\data\40000923.dat
  • C:\Users\test\AppData\Roaming\szw\MasterZ\data\40000923.bin
  • C:\Users\test\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\EHDRIWWS\40000923[1].bin
  • C:\Users\test\AppData\Roaming\szw\MasterZ\data\40000924.dat
  • C:\Users\test\AppData\Roaming\szw\MasterZ\data\40000924.bin
  • C:\Users\test\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\IDL4J1KW\40000924[1].bin
读取的文件
  • \Device\KsecDD
  • C:\Windows\System32\shfolder.dll
  • C:\Users\test\AppData\Local\Temp\nso52C0.tmp
  • C:\Users\test\AppData\Local\Temp\MasterZ_Custom_93.exe
  • C:\Users\test\AppData\Local\Temp\nso53AB.tmp
  • C:\Users\test\AppData\Local\Temp\nse53BC.tmp
  • C:\Users\test\AppData\Local\Temp\nse53BC.tmp\nsTBCIASkinEngine.dll
  • C:\Windows\System32\riched20.dll
  • C:\Windows\Fonts\staticcache.dat
  • C:\Users\test\AppData\Local\Temp\nse53BC.tmp\System.dll
  • C:\Users\test\AppData\Local\Temp\nsz628C.tmp
  • C:\Users\test\AppData\Local\Temp\nse53BC.tmp\ioSpecial.ini
  • C:\Users\test\AppData\Local\Temp\nse53BC.tmp\modern-header.bmp
  • C:\Windows\SysWOW64\ieframe.dll
  • C:\
  • C:\Windows
  • C:\Windows\System32
  • C:\Users\test\AppData\Local\Temp\nse53BC.tmp\FindProcDLL.dll
  • C:\Users\test\AppData\Local\Temp\nse53BC.tmp\nsExec.dll
  • \Device\NamedPipe\
  • C:\Users\desktop.ini
  • C:\Users
  • C:\Users\test
  • C:\Users\test\AppData
  • C:\Users\test\AppData\Roaming
  • C:\Users\test\AppData\Roaming\szw
  • C:\Users\test\AppData\Roaming\szw\MasterZ
  • C:\Users\test\AppData\Roaming\szw\MasterZ\uninst.exe
  • C:\Users\test\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\\xe6\xa0\x87\xe5\x87\x86\xe4\xbb\xb6\\xe5\x8d\xb8\xe8\xbd\xbd\xe6\xa0\x87\xe5\x87\x86\xe4\xbb\xb6.lnk
  • C:\Users\test\AppData\Local\Temp\nse53BC.tmp\InstallOptions.dll
  • C:\Users\test\AppData\Local\Temp\nse53BC.tmp\modern-wizard.bmp
  • C:\Windows\SysWOW64\zh-CN\KERNELBASE.dll.mui
  • C:\Windows\Globalization\Sorting\sortdefault.nls
  • C:\Windows\SysWOW64\netmsg.dll
  • \Device\Http\Communication
  • C:\Windows\System32\DHCPQEC.DLL
  • C:\Windows\System32\napipsec.dll
  • C:\Windows\System32\zh-CN\napipsec.dll.mui
  • C:\Windows\System32\tsgqec.dll
  • C:\Windows\System32\EAPQEC.DLL
  • C:\Windows\System32\zh-CN\eapqec.dll.mui
  • C:\Windows\SysWOW64\zh-CN\P2PNETSH.DLL.mui
  • C:\Windows\SysWOW64\zh-CN\AUTHFWCFG.DLL.mui
  • C:\Users\test\AppData\Roaming\szw\MasterZ\plugins\npszwplugin.dll
  • C:\Windows\System32\IPHLPAPI.DLL
  • C:\Windows\System32\winnsi.dll
  • C:\Users\test\AppData\Roaming\szw\MasterZ\plugins\ieplugin.dll
  • C:\Windows\System32\wsock32.dll
  • C:\Users\test\AppData\Roaming\szw\MasterZ\bin\XMLRW.dll
  • C:\Users\test\AppData\Roaming\szw\MasterZ\data2\mc.dat
  • C:\Users\test\AppData\Roaming\szw\MasterZ\bin\KeyRW.dll
  • C:\Users\test\AppData\Roaming\szw\MasterZ\log\runlog.log
  • C:\Users\test\AppData\Roaming\szw\MasterZ\data2\customize.dat
  • C:\Users\test\AppData\Roaming\szw\MasterZ\data2\version.dat
  • C:\Users\test\AppData\Roaming\szw\MasterZ\bin\BugReport.dll
  • C:\Users\test\AppData\Roaming\szw\MasterZ\bin\skin\skin.zip
  • C:\Users\test\AppData\Roaming\szw\MasterZ\bin\mfc120u.dll
  • C:\Windows\System32\uxtheme.dll
  • C:\Users\test\AppData\Roaming\szw\MasterZ\log\DatSync.log
  • C:\Users\test\AppData\Roaming\szw\MasterZ\6\0.bin
  • C:\Users\test\AppData\Roaming\szw\MasterZ\6\1.bin
  • C:\Users\test\AppData\Roaming\szw\MasterZ\6\StationLastupdate.txt
  • C:\Users\test\AppData\Roaming\szw\MasterZ\data\40000002.dat
  • C:\Users\test\AppData\Roaming\szw\MasterZ\data\40000002.bin
  • C:\Users\test\AppData\Roaming\szw\MasterZ\data\40000003.dat
  • C:\Users\test\AppData\Roaming\szw\MasterZ\data\40000003.bin
  • C:\Users\test\AppData\Roaming\szw\MasterZ\data\40000502.dat
  • C:\Users\test\AppData\Roaming\szw\MasterZ\data\40000502.bin
  • C:\Users\test\AppData\Roaming\szw\MasterZ\data\40000503.dat
  • C:\Users\test\AppData\Roaming\szw\MasterZ\data\40000503.bin
  • C:\Users\test\AppData\Roaming\szw\MasterZ\data\40000505.dat
  • C:\Users\test\AppData\Roaming\szw\MasterZ\data\40000505.bin
  • C:\Users\test\AppData\Roaming\szw\MasterZ\data\40000506.dat
  • C:\Users\test\AppData\Roaming\szw\MasterZ\data\40000506.bin
  • C:\Users\test\AppData\Roaming\szw\MasterZ\data\40000507.dat
  • C:\Users\test\AppData\Roaming\szw\MasterZ\data\40000507.bin
  • C:\Users\test\AppData\Roaming\szw\MasterZ\data\40000508.dat
  • C:\Users\test\AppData\Roaming\szw\MasterZ\data\40000508.bin
  • C:\Users\test\AppData\Roaming\szw\MasterZ\data\40000510.dat
  • C:\Users\test\AppData\Roaming\szw\MasterZ\data\40000510.bin
  • C:\Users\test\AppData\Roaming\szw\MasterZ\data\40000515.dat
  • C:\Users\test\AppData\Roaming\szw\MasterZ\data\40000515.bin
  • C:\Users\test\AppData\Roaming\szw\MasterZ\data\40000527.dat
  • C:\Users\test\AppData\Roaming\szw\MasterZ\data\40000527.bin
  • C:\Users\test\AppData\Roaming\szw\MasterZ\data\40000530.dat
  • C:\Users\test\AppData\Roaming\szw\MasterZ\data\40000530.bin
  • C:\Users\test\AppData\Roaming\szw\MasterZ\data\40000531.dat
  • C:\Users\test\AppData\Roaming\szw\MasterZ\data\40000531.bin
  • C:\Users\test\AppData\Roaming\szw\MasterZ\data\40000534.dat
  • C:\Users\test\AppData\Roaming\szw\MasterZ\data\40000534.bin
  • C:\Users\test\AppData\Roaming\szw\MasterZ\data\40000540.dat
  • C:\Users\test\AppData\Roaming\szw\MasterZ\data\40000540.bin
  • C:\Users\test\AppData\Roaming\szw\MasterZ\data\40000547.dat
  • C:\Users\test\AppData\Roaming\szw\MasterZ\data\40000547.bin
  • C:\Users\test\AppData\Roaming\szw\MasterZ\data\40000554.dat
  • C:\Users\test\AppData\Roaming\szw\MasterZ\data\40000554.bin
  • C:\Users\test\AppData\Roaming\szw\MasterZ\data\40000555.dat
  • C:\Users\test\AppData\Roaming\szw\MasterZ\data\40000555.bin
  • C:\Users\test\AppData\Roaming\szw\MasterZ\data\40000557.dat
  • C:\Users\test\AppData\Roaming\szw\MasterZ\data\40000557.bin
  • C:\Users\test\AppData\Roaming\szw\MasterZ\data\40000559.dat
  • C:\Users\test\AppData\Roaming\szw\MasterZ\data\40000559.bin
  • C:\Users\test\AppData\Roaming\szw\MasterZ\data\40000560.dat
  • C:\Users\test\AppData\Roaming\szw\MasterZ\data\40000560.bin
  • C:\Users\test\AppData\Roaming\szw\MasterZ\data\40000564.dat
  • C:\Users\test\AppData\Roaming\szw\MasterZ\data\40000564.bin
  • C:\Users\test\AppData\Roaming\szw\MasterZ\data\40000570.dat
  • C:\Users\test\AppData\Roaming\szw\MasterZ\data\40000570.bin
  • C:\Users\test\AppData\Roaming\szw\MasterZ\data\40000571.dat
  • C:\Users\test\AppData\Roaming\szw\MasterZ\data\40000571.bin
  • C:\Users\test\AppData\Roaming\szw\MasterZ\data\40000577.dat
  • C:\Users\test\AppData\Roaming\szw\MasterZ\data\40000577.bin
  • C:\Users\test\AppData\Roaming\szw\MasterZ\data\40000581.dat
  • C:\Users\test\AppData\Roaming\szw\MasterZ\data\40000581.bin
  • C:\Users\test\AppData\Roaming\szw\MasterZ\data\40000582.dat
  • C:\Users\test\AppData\Roaming\szw\MasterZ\data\40000582.bin
  • C:\Users\test\AppData\Roaming\szw\MasterZ\data\40000584.dat
  • C:\Users\test\AppData\Roaming\szw\MasterZ\data\40000584.bin
  • C:\Users\test\AppData\Roaming\szw\MasterZ\data\40000588.dat
  • C:\Users\test\AppData\Roaming\szw\MasterZ\data\40000588.bin
  • C:\Users\test\AppData\Roaming\szw\MasterZ\data\40000596.dat
  • C:\Users\test\AppData\Roaming\szw\MasterZ\data\40000596.bin
  • C:\Users\test\AppData\Roaming\szw\MasterZ\data\40000598.dat
  • C:\Users\test\AppData\Roaming\szw\MasterZ\data\40000598.bin
  • C:\Users\test\AppData\Roaming\szw\MasterZ\data\40000600.dat
  • C:\Users\test\AppData\Roaming\szw\MasterZ\data\40000600.bin
  • C:\Users\test\AppData\Roaming\szw\MasterZ\data\40000609.dat
  • C:\Users\test\AppData\Roaming\szw\MasterZ\data\40000609.bin
  • C:\Users\test\AppData\Roaming\szw\MasterZ\data\40000619.dat
  • C:\Users\test\AppData\Roaming\szw\MasterZ\data\40000619.bin
  • C:\Users\test\AppData\Roaming\szw\MasterZ\data\40000622.dat
  • C:\Users\test\AppData\Roaming\szw\MasterZ\data\40000622.bin
  • C:\Users\test\AppData\Roaming\szw\MasterZ\data\40000626.dat
  • C:\Users\test\AppData\Roaming\szw\MasterZ\data\40000626.bin
  • C:\Users\test\AppData\Roaming\szw\MasterZ\data\40000634.dat
  • C:\Users\test\AppData\Roaming\szw\MasterZ\data\40000634.bin
  • C:\Users\test\AppData\Roaming\szw\MasterZ\data\40000637.dat
  • C:\Users\test\AppData\Roaming\szw\MasterZ\data\40000637.bin
  • C:\Users\test\AppData\Roaming\szw\MasterZ\data\40000638.dat
  • C:\Users\test\AppData\Roaming\szw\MasterZ\data\40000638.bin
  • C:\Users\test\AppData\Roaming\szw\MasterZ\data\40000639.dat
  • C:\Users\test\AppData\Roaming\szw\MasterZ\data\40000639.bin
  • C:\Users\test\AppData\Roaming\szw\MasterZ\data\40000643.dat
  • C:\Users\test\AppData\Roaming\szw\MasterZ\data\40000643.bin
  • C:\Users\test\AppData\Roaming\szw\MasterZ\data\40000656.dat
  • C:\Users\test\AppData\Roaming\szw\MasterZ\data\40000656.bin
  • C:\Users\test\AppData\Roaming\szw\MasterZ\data\40000658.dat
  • C:\Users\test\AppData\Roaming\szw\MasterZ\data\40000658.bin
  • C:\Users\test\AppData\Roaming\szw\MasterZ\data\40000670.dat
  • C:\Users\test\AppData\Roaming\szw\MasterZ\data\40000670.bin
  • C:\Users\test\AppData\Roaming\szw\MasterZ\data\40000707.dat
  • C:\Users\test\AppData\Roaming\szw\MasterZ\data\40000707.bin
  • C:\Users\test\AppData\Roaming\szw\MasterZ\data\40000714.dat
  • C:\Users\test\AppData\Roaming\szw\MasterZ\data\40000714.bin
  • C:\Users\test\AppData\Roaming\szw\MasterZ\data\40000722.dat
  • C:\Users\test\AppData\Roaming\szw\MasterZ\data\40000722.bin
  • C:\Users\test\AppData\Roaming\szw\MasterZ\data\40000725.dat
  • C:\Users\test\AppData\Roaming\szw\MasterZ\data\40000725.bin
  • C:\Users\test\AppData\Roaming\szw\MasterZ\data\40000740.dat
  • C:\Users\test\AppData\Roaming\szw\MasterZ\data\40000740.bin
  • C:\Users\test\AppData\Roaming\szw\MasterZ\data\40000748.dat
  • C:\Users\test\AppData\Roaming\szw\MasterZ\data\40000748.bin
  • C:\Users\test\AppData\Roaming\szw\MasterZ\data\40000760.dat
  • C:\Users\test\AppData\Roaming\szw\MasterZ\data\40000760.bin
  • C:\Users\test\AppData\Roaming\szw\MasterZ\data\40000767.dat
  • C:\Users\test\AppData\Roaming\szw\MasterZ\data\40000767.bin
  • C:\Users\test\AppData\Roaming\szw\MasterZ\data\40000777.dat
  • C:\Users\test\AppData\Roaming\szw\MasterZ\data\40000777.bin
  • C:\Users\test\AppData\Roaming\szw\MasterZ\data\40000790.dat
  • C:\Users\test\AppData\Roaming\szw\MasterZ\data\40000790.bin
  • C:\Users\test\AppData\Roaming\szw\MasterZ\data\40000791.dat
  • C:\Users\test\AppData\Roaming\szw\MasterZ\data\40000791.bin
  • C:\Users\test\AppData\Roaming\szw\MasterZ\data\40000806.dat
  • C:\Users\test\AppData\Roaming\szw\MasterZ\data\40000806.bin
  • C:\Users\test\AppData\Roaming\szw\MasterZ\data\40000807.dat
  • C:\Users\test\AppData\Roaming\szw\MasterZ\data\40000807.bin
  • C:\Users\test\AppData\Roaming\szw\MasterZ\data\40000808.dat
  • C:\Users\test\AppData\Roaming\szw\MasterZ\data\40000808.bin
  • C:\Users\test\AppData\Roaming\szw\MasterZ\data\40000809.dat
  • C:\Users\test\AppData\Roaming\szw\MasterZ\data\40000809.bin
  • C:\Users\test\AppData\Roaming\szw\MasterZ\data\40000810.dat
  • C:\Users\test\AppData\Roaming\szw\MasterZ\data\40000810.bin
  • C:\Users\test\AppData\Roaming\szw\MasterZ\data\40000821.dat
  • C:\Users\test\AppData\Roaming\szw\MasterZ\data\40000821.bin
  • C:\Users\test\AppData\Roaming\szw\MasterZ\data\40000822.dat
  • C:\Users\test\AppData\Roaming\szw\MasterZ\data\40000822.bin
  • C:\Users\test\AppData\Roaming\szw\MasterZ\data\40000830.dat
  • C:\Users\test\AppData\Roaming\szw\MasterZ\data\40000830.bin
  • C:\Users\test\AppData\Roaming\szw\MasterZ\data\40000831.dat
  • C:\Users\test\AppData\Roaming\szw\MasterZ\data\40000831.bin
  • C:\Users\test\AppData\Roaming\szw\MasterZ\data\40000834.dat
  • C:\Users\test\AppData\Roaming\szw\MasterZ\data\40000834.bin
  • C:\Users\test\AppData\Roaming\szw\MasterZ\data\40000835.dat
  • C:\Users\test\AppData\Roaming\szw\MasterZ\data\40000835.bin
  • C:\Users\test\AppData\Roaming\szw\MasterZ\data\40000836.dat
  • C:\Users\test\AppData\Roaming\szw\MasterZ\data\40000836.bin
  • C:\Users\test\AppData\Roaming\szw\MasterZ\data\40000837.dat
  • C:\Users\test\AppData\Roaming\szw\MasterZ\data\40000837.bin
  • C:\Users\test\AppData\Roaming\szw\MasterZ\data\40000838.dat
  • C:\Users\test\AppData\Roaming\szw\MasterZ\data\40000838.bin
  • C:\Users\test\AppData\Roaming\szw\MasterZ\data\40000849.dat
  • C:\Users\test\AppData\Roaming\szw\MasterZ\data\40000849.bin
  • C:\Users\test\AppData\Roaming\szw\MasterZ\data\40000851.dat
  • C:\Users\test\AppData\Roaming\szw\MasterZ\data\40000851.bin
  • C:\Users\test\AppData\Roaming\szw\MasterZ\data\40000852.dat
  • C:\Users\test\AppData\Roaming\szw\MasterZ\data\40000852.bin
  • C:\Users\test\AppData\Roaming\szw\MasterZ\data\40000856.dat
  • C:\Users\test\AppData\Roaming\szw\MasterZ\data\40000856.bin
  • C:\Users\test\AppData\Roaming\szw\MasterZ\data\40000859.dat
  • C:\Users\test\AppData\Roaming\szw\MasterZ\data\40000859.bin
  • C:\Users\test\AppData\Roaming\szw\MasterZ\data\40000863.dat
  • C:\Users\test\AppData\Roaming\szw\MasterZ\data\40000863.bin
  • C:\Users\test\AppData\Roaming\szw\MasterZ\data\40000864.dat
  • C:\Users\test\AppData\Roaming\szw\MasterZ\data\40000864.bin
  • C:\Users\test\AppData\Roaming\szw\MasterZ\data\40000865.dat
  • C:\Users\test\AppData\Roaming\szw\MasterZ\data\40000865.bin
  • C:\Users\test\AppData\Roaming\szw\MasterZ\data\40000866.dat
  • C:\Users\test\AppData\Roaming\szw\MasterZ\data\40000866.bin
  • C:\Users\test\AppData\Roaming\szw\MasterZ\data\40000875.dat
  • C:\Users\test\AppData\Roaming\szw\MasterZ\data\40000875.bin
  • C:\Users\test\AppData\Roaming\szw\MasterZ\data\40000878.dat
  • C:\Users\test\AppData\Roaming\szw\MasterZ\data\40000878.bin
  • C:\Users\test\AppData\Roaming\szw\MasterZ\data\40000879.dat
  • C:\Users\test\AppData\Roaming\szw\MasterZ\data\40000879.bin
  • C:\Users\test\AppData\Roaming\szw\MasterZ\data\40000880.dat
  • C:\Users\test\AppData\Roaming\szw\MasterZ\data\40000880.bin
  • C:\Users\test\AppData\Roaming\szw\MasterZ\data\40000893.dat
  • C:\Users\test\AppData\Roaming\szw\MasterZ\data\40000893.bin
  • C:\Users\test\AppData\Roaming\szw\MasterZ\data\40000894.dat
  • C:\Users\test\AppData\Roaming\szw\MasterZ\data\40000894.bin
  • C:\Users\test\AppData\Roaming\szw\MasterZ\data\40000895.dat
  • C:\Users\test\AppData\Roaming\szw\MasterZ\data\40000895.bin
  • C:\Users\test\AppData\Roaming\szw\MasterZ\data\40000896.dat
  • C:\Users\test\AppData\Roaming\szw\MasterZ\data\40000896.bin
  • C:\Users\test\AppData\Roaming\szw\MasterZ\data\40000897.dat
  • C:\Users\test\AppData\Roaming\szw\MasterZ\data\40000897.bin
  • C:\Users\test\AppData\Roaming\szw\MasterZ\data\40000907.dat
  • C:\Users\test\AppData\Roaming\szw\MasterZ\data\40000907.bin
  • C:\Users\test\AppData\Roaming\szw\MasterZ\data\40000908.dat
  • C:\Users\test\AppData\Roaming\szw\MasterZ\data\40000908.bin
  • C:\Users\test\AppData\Roaming\szw\MasterZ\data\40000909.dat
  • C:\Users\test\AppData\Roaming\szw\MasterZ\data\40000909.bin
  • C:\Users\test\AppData\Roaming\szw\MasterZ\data\40000917.dat
  • C:\Users\test\AppData\Roaming\szw\MasterZ\data\40000917.bin
  • C:\Users\test\AppData\Roaming\szw\MasterZ\data\40000918.dat
  • C:\Users\test\AppData\Roaming\szw\MasterZ\data\40000918.bin
  • C:\Users\test\AppData\Roaming\szw\MasterZ\data\40000919.dat
  • C:\Users\test\AppData\Roaming\szw\MasterZ\data\40000919.bin
  • C:\Users\test\AppData\Roaming\szw\MasterZ\data\40000922.dat
  • C:\Users\test\AppData\Roaming\szw\MasterZ\data\40000922.bin
  • C:\Users\test\AppData\Roaming\szw\MasterZ\data\40000923.dat
  • C:\Users\test\AppData\Roaming\szw\MasterZ\data\40000923.bin
  • C:\Users\test\AppData\Roaming\szw\MasterZ\data\40000924.dat
  • C:\Users\test\AppData\Roaming\szw\MasterZ\data\40000924.bin
修改的文件
  • C:\Users\test\AppData\Local\Temp\nso53AB.tmp
  • C:\Users\test\AppData\Local\Temp\nse53BC.tmp\nsTBCIASkinEngine.dll
  • C:\Users\test\AppData\Local\Temp\nse53BC.tmp\System.dll
  • C:\Users\test\AppData\Local\Temp\MasterZdll\ieplugin.dll
  • C:\Users\test\AppData\Local\Temp\MasterZdll\npszwplugin.dll
  • C:\Users\test\AppData\Local\Temp\nse53BC.tmp\ioSpecial.ini
  • C:\Users\test\AppData\Local\Temp\nse53BC.tmp\modern-wizard.bmp
  • C:\Users\test\AppData\Local\Temp\nse53BC.tmp\modern-header.bmp
  • C:\Users\test\AppData\Local\Temp\nse53BC.tmp\FindProcDLL.dll
  • C:\Users\test\AppData\Local\Temp\nse53BC.tmp\nsExec.dll
  • \Device\NamedPipe
  • C:\Users\test\AppData\Roaming\szw\MasterZ\CleanLog.bat
  • C:\Users\test\AppData\Roaming\szw\MasterZ\bin\AutoRunService.exe
  • C:\Users\test\AppData\Roaming\szw\MasterZ\bin\AutomaticSearch.exe
  • C:\Users\test\AppData\Roaming\szw\MasterZ\bin\BugReport.dll
  • C:\Users\test\AppData\Roaming\szw\MasterZ\bin\CheckSystemDllExist.dat
  • C:\Users\test\AppData\Roaming\szw\MasterZ\bin\CheckSystemDllExist.exe
  • C:\Users\test\AppData\Roaming\szw\MasterZ\bin\CodeOCR.DLL
  • C:\Users\test\AppData\Roaming\szw\MasterZ\bin\CtrlUserTask.exe
  • C:\Users\test\AppData\Roaming\szw\MasterZ\bin\DataExchange.dll
  • C:\Users\test\AppData\Roaming\szw\MasterZ\bin\Deamon.exe
  • C:\Users\test\AppData\Roaming\szw\MasterZ\bin\Engine.exe
  • C:\Users\test\AppData\Roaming\szw\MasterZ\bin\ExTool.dll
  • C:\Users\test\AppData\Roaming\szw\MasterZ\bin\FastVerCode.dll
  • C:\Users\test\AppData\Roaming\szw\MasterZ\bin\GetRank.exe
  • C:\Users\test\AppData\Roaming\szw\MasterZ\bin\IAWS.dll
  • C:\Users\test\AppData\Roaming\szw\MasterZ\bin\InputOCR.dll
  • C:\Users\test\AppData\Roaming\szw\MasterZ\bin\KeyRW.dll
  • C:\Users\test\AppData\Roaming\szw\MasterZ\bin\KillProcess.exe
  • C:\Users\test\AppData\Roaming\szw\MasterZ\bin\KillService.bat
  • C:\Users\test\AppData\Roaming\szw\MasterZ\bin\MC.exe
  • C:\Users\test\AppData\Roaming\szw\MasterZ\bin\MSVCP71.DLL
  • C:\Users\test\AppData\Roaming\szw\MasterZ\bin\MasterZ.exe
  • C:\Users\test\AppData\Roaming\szw\MasterZ\bin\PreData.dll
  • C:\Users\test\AppData\Roaming\szw\MasterZ\bin\ProcessTask.dll
  • C:\Users\test\AppData\Roaming\szw\MasterZ\bin\RunService.bat
  • C:\Users\test\AppData\Roaming\szw\MasterZ\bin\RuoKuaiDLL.dll
  • C:\Users\test\AppData\Roaming\szw\MasterZ\bin\STGUI.dll
  • C:\Users\test\AppData\Roaming\szw\MasterZ\bin\SVCAR.dll
  • C:\Users\test\AppData\Roaming\szw\MasterZ\bin\SeekWord.exe
  • C:\Users\test\AppData\Roaming\szw\MasterZ\bin\SyncDat.dll
  • C:\Users\test\AppData\Roaming\szw\MasterZ\bin\SyncDat.exe
  • C:\Users\test\AppData\Roaming\szw\MasterZ\bin\SzwANN.dll
  • C:\Users\test\AppData\Roaming\szw\MasterZ\bin\TaskCtrl.dll
  • C:\Users\test\AppData\Roaming\szw\MasterZ\bin\UUWiseHelper.dll
  • C:\Users\test\AppData\Roaming\szw\MasterZ\bin\UpdateOL.bat
  • C:\Users\test\AppData\Roaming\szw\MasterZ\bin\UpdateOL.dll
  • C:\Users\test\AppData\Roaming\szw\MasterZ\bin\UpdateRank.dll
  • C:\Users\test\AppData\Roaming\szw\MasterZ\bin\UpdateRank.exe
  • C:\Users\test\AppData\Roaming\szw\MasterZ\bin\Utility.dll
  • C:\Users\test\AppData\Roaming\szw\MasterZ\bin\XMLRW.dll
  • C:\Users\test\AppData\Roaming\szw\MasterZ\bin\YunTask.dll
  • C:\Users\test\AppData\Roaming\szw\MasterZ\bin\gpsvc.dll
  • C:\Users\test\AppData\Roaming\szw\MasterZ\bin\ieshims.dll
  • C:\Users\test\AppData\Roaming\szw\MasterZ\bin\install.flag
  • C:\Users\test\AppData\Roaming\szw\MasterZ\bin\libapr-1.dll
  • C:\Users\test\AppData\Roaming\szw\MasterZ\bin\libaprutil-1.dll
  • C:\Users\test\AppData\Roaming\szw\MasterZ\bin\libcurl.dll
  • C:\Users\test\AppData\Roaming\szw\MasterZ\bin\libeay32.dll
  • C:\Users\test\AppData\Roaming\szw\MasterZ\bin\mfc120u.dll
  • C:\Users\test\AppData\Roaming\szw\MasterZ\bin\msvcp120.dll
  • C:\Users\test\AppData\Roaming\szw\MasterZ\bin\msvcr120.dll
  • C:\Users\test\AppData\Roaming\szw\MasterZ\bin\msvcr71.dll
  • C:\Users\test\AppData\Roaming\szw\MasterZ\bin\mxml1.dll
  • C:\Users\test\AppData\Roaming\szw\MasterZ\bin\sqlite3.dll
  • C:\Users\test\AppData\Roaming\szw\MasterZ\bin\ssleay32.dll
  • C:\Users\test\AppData\Roaming\szw\MasterZ\bin\yundamaAPI.dll
  • C:\Users\test\AppData\Roaming\szw\MasterZ\bin\zlib1.dll
  • C:\Users\test\AppData\Roaming\szw\MasterZ\bin\skin\ProblemList.xml
  • C:\Users\test\AppData\Roaming\szw\MasterZ\bin\skin\skin.zip
  • C:\Users\test\AppData\Roaming\szw\MasterZ\bin\skin\FusionCharts\ZhenCiTemplate.html
  • C:\Users\test\AppData\Roaming\szw\MasterZ\bin\skin\FusionCharts\keyword.html
  • C:\Users\test\AppData\Roaming\szw\MasterZ\bin\skin\FusionCharts\noexposuredata.html
  • C:\Users\test\AppData\Roaming\szw\MasterZ\bin\skin\FusionCharts\nokeyworddata.html
  • C:\Users\test\AppData\Roaming\szw\MasterZ\bin\skin\FusionCharts\images\close.png
  • C:\Users\test\AppData\Roaming\szw\MasterZ\bin\skin\FusionCharts\images\see.png
  • C:\Users\test\AppData\Roaming\szw\MasterZ\bin\skin\FusionCharts\js\Common.js
  • C:\Users\test\AppData\Roaming\szw\MasterZ\bin\skin\FusionCharts\js\echarts.js
  • C:\Users\test\AppData\Roaming\szw\MasterZ\bin\skin\FusionCharts\js\jquery-1.11.2.min.js
  • C:\Users\test\AppData\Roaming\szw\MasterZ\bin\skin\FusionCharts\js\chart\bar.js
  • C:\Users\test\AppData\Roaming\szw\MasterZ\bin\skin\FusionCharts\js\chart\line.js
  • C:\Users\test\AppData\Roaming\szw\MasterZ\data2\AutoProgram.ini
  • C:\Users\test\AppData\Roaming\szw\MasterZ\data2\Key.dat
  • C:\Users\test\AppData\Roaming\szw\MasterZ\data2\ParamData.dat
  • C:\Users\test\AppData\Roaming\szw\MasterZ\data2\ReferenceList.dat
  • C:\Users\test\AppData\Roaming\szw\MasterZ\data2\UpdateOL.dat
  • C:\Users\test\AppData\Roaming\szw\MasterZ\data2\YunTask.dat
  • C:\Users\test\AppData\Roaming\szw\MasterZ\data2\component.dat
  • C:\Users\test\AppData\Roaming\szw\MasterZ\data2\customize.dat
  • C:\Users\test\AppData\Roaming\szw\MasterZ\data2\engine.dat
  • C:\Users\test\AppData\Roaming\szw\MasterZ\data2\mc.dat
  • C:\Users\test\AppData\Roaming\szw\MasterZ\data2\updaterank.dat
  • C:\Users\test\AppData\Roaming\szw\MasterZ\mod\Quest.dat
  • C:\Users\test\AppData\Roaming\szw\MasterZ\mod\sum40000501.Mod
  • C:\Users\test\AppData\Roaming\szw\MasterZ\mod\sum40000511.Mod
  • C:\Users\test\AppData\Roaming\szw\MasterZ\mod\sum40000747.Mod
  • C:\Users\test\AppData\Roaming\szw\MasterZ\mod\sum40020637.Mod
  • C:\Users\test\AppData\Roaming\szw\MasterZ\mod\sum40043398.Mod
  • C:\Users\test\AppData\Roaming\szw\MasterZ\plugins\ieplugin.dll
  • C:\Users\test\AppData\Roaming\szw\MasterZ\plugins\npszwplugin.dll
  • C:\Users\test\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\\xe6\xa0\x87\xe5\x87\x86\xe4\xbb\xb6\\xe5\x8d\xb8\xe8\xbd\xbd\xe6\xa0\x87\xe5\x87\x86\xe4\xbb\xb6.lnk
  • C:\Users\test\AppData\Roaming\szw\MasterZ\uninst.exe
  • C:\Users\test\AppData\Local\Temp\nse53BC.tmp\InstallOptions.dll
  • \Device\Http\Communication
  • C:\Windows\Microsoft.NET\Framework\v4.0.30319\ngenservicelock.dat
  • C:\Windows\Microsoft.NET\Framework\v4.0.30319\ngenrootstorelock.dat
  • C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ngenservicelock.dat
  • C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ngenrootstorelock.dat
  • C:\Users\test\AppData\Roaming\szw\MasterZ\log\runlog.log
  • C:\Users\test\AppData\Roaming\szw\MasterZ\data2\version.dat
  • C:\Users\test\AppData\Roaming\szw\MasterZ\log\DatSync.log
  • C:\Users\test\AppData\Roaming\szw\MasterZ\6\0.bin
  • C:\Users\test\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\CB4GP22D\0[1].bin
  • C:\Users\test\AppData\Roaming\szw\MasterZ\6\1.bin
  • C:\Users\test\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\EHDRIWWS\1[1].bin
  • C:\Users\test\AppData\Roaming\szw\MasterZ\6\SiteList.txt
  • C:\Users\test\AppData\Roaming\szw\MasterZ\6\StationLastupdate.txt
  • C:\Users\test\AppData\Roaming\szw\MasterZ\data\40000002.bin
  • C:\Users\test\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\HEL4YQ7U\40000002[1].bin
  • C:\Users\test\AppData\Roaming\szw\MasterZ\data\40000002.dat
  • C:\Users\test\AppData\Roaming\szw\MasterZ\data\40000003.bin
  • C:\Users\test\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\CB4GP22D\40000003[1].bin
  • C:\Users\test\AppData\Roaming\szw\MasterZ\data\40000003.dat
  • C:\Users\test\AppData\Roaming\szw\MasterZ\data\40000502.bin
  • C:\Users\test\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\EHDRIWWS\40000502[1].bin
  • C:\Users\test\AppData\Roaming\szw\MasterZ\data\40000502.dat
  • C:\Users\test\AppData\Roaming\szw\MasterZ\data\40000503.bin
  • C:\Users\test\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\IDL4J1KW\40000503[1].bin
  • C:\Users\test\AppData\Roaming\szw\MasterZ\data\40000503.dat
  • C:\Users\test\AppData\Roaming\szw\MasterZ\data\40000505.bin
  • C:\Users\test\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\HEL4YQ7U\40000505[1].bin
  • C:\Users\test\AppData\Roaming\szw\MasterZ\data\40000505.dat
  • C:\Users\test\AppData\Roaming\szw\MasterZ\data\40000506.bin
  • C:\Users\test\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\CB4GP22D\40000506[1].bin
  • C:\Users\test\AppData\Roaming\szw\MasterZ\data\40000506.dat
  • C:\Users\test\AppData\Roaming\szw\MasterZ\data\40000507.bin
  • C:\Users\test\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\EHDRIWWS\40000507[1].bin
  • C:\Users\test\AppData\Roaming\szw\MasterZ\data\40000507.dat
  • C:\Users\test\AppData\Roaming\szw\MasterZ\data\40000508.bin
  • C:\Users\test\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\IDL4J1KW\40000508[1].bin
  • C:\Users\test\AppData\Roaming\szw\MasterZ\data\40000508.dat
  • C:\Users\test\AppData\Roaming\szw\MasterZ\data\40000510.bin
  • C:\Users\test\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\HEL4YQ7U\40000510[1].bin
  • C:\Users\test\AppData\Roaming\szw\MasterZ\data\40000510.dat
  • C:\Users\test\AppData\Roaming\szw\MasterZ\data\40000515.bin
  • C:\Users\test\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\CB4GP22D\40000515[1].bin
  • C:\Users\test\AppData\Roaming\szw\MasterZ\data\40000515.dat
  • C:\Users\test\AppData\Roaming\szw\MasterZ\data\40000527.bin
  • C:\Users\test\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\EHDRIWWS\40000527[1].bin
  • C:\Users\test\AppData\Roaming\szw\MasterZ\data\40000527.dat
  • C:\Users\test\AppData\Roaming\szw\MasterZ\data\40000530.bin
  • C:\Users\test\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\IDL4J1KW\40000530[1].bin
  • C:\Users\test\AppData\Roaming\szw\MasterZ\data\40000530.dat
  • C:\Users\test\AppData\Roaming\szw\MasterZ\data\40000531.bin
  • C:\Users\test\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\HEL4YQ7U\40000531[1].bin
  • C:\Users\test\AppData\Roaming\szw\MasterZ\data\40000531.dat
  • C:\Users\test\AppData\Roaming\szw\MasterZ\data\40000534.bin
  • C:\Users\test\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\CB4GP22D\40000534[1].bin
  • C:\Users\test\AppData\Roaming\szw\MasterZ\data\40000534.dat
  • C:\Users\test\AppData\Roaming\szw\MasterZ\data\40000540.bin
  • C:\Users\test\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\EHDRIWWS\40000540[1].bin
  • C:\Users\test\AppData\Roaming\szw\MasterZ\data\40000540.dat
  • C:\Users\test\AppData\Roaming\szw\MasterZ\data\40000547.bin
  • C:\Users\test\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\IDL4J1KW\40000547[1].bin
  • C:\Users\test\AppData\Roaming\szw\MasterZ\data\40000547.dat
  • C:\Users\test\AppData\Roaming\szw\MasterZ\data\40000554.bin
  • C:\Users\test\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\HEL4YQ7U\40000554[1].bin
  • C:\Users\test\AppData\Roaming\szw\MasterZ\data\40000554.dat
  • C:\Users\test\AppData\Roaming\szw\MasterZ\data\40000555.bin
  • C:\Users\test\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\CB4GP22D\40000555[1].bin
  • C:\Users\test\AppData\Roaming\szw\MasterZ\data\40000555.dat
  • C:\Users\test\AppData\Roaming\szw\MasterZ\data\40000557.bin
  • C:\Users\test\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\EHDRIWWS\40000557[1].bin
  • C:\Users\test\AppData\Roaming\szw\MasterZ\data\40000557.dat
  • C:\Users\test\AppData\Roaming\szw\MasterZ\data\40000559.bin
  • C:\Users\test\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\IDL4J1KW\40000559[1].bin
  • C:\Users\test\AppData\Roaming\szw\MasterZ\data\40000559.dat
  • C:\Users\test\AppData\Roaming\szw\MasterZ\data\40000560.bin
  • C:\Users\test\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\HEL4YQ7U\40000560[1].bin
  • C:\Users\test\AppData\Roaming\szw\MasterZ\data\40000560.dat
  • C:\Users\test\AppData\Roaming\szw\MasterZ\data\40000564.bin
  • C:\Users\test\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\CB4GP22D\40000564[1].bin
  • C:\Users\test\AppData\Roaming\szw\MasterZ\data\40000564.dat
  • C:\Users\test\AppData\Roaming\szw\MasterZ\data\40000570.bin
  • C:\Users\test\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\EHDRIWWS\40000570[1].bin
  • C:\Users\test\AppData\Roaming\szw\MasterZ\data\40000570.dat
  • C:\Users\test\AppData\Roaming\szw\MasterZ\data\40000571.bin
  • C:\Users\test\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\IDL4J1KW\40000571[1].bin
  • C:\Users\test\AppData\Roaming\szw\MasterZ\data\40000571.dat
  • C:\Users\test\AppData\Roaming\szw\MasterZ\data\40000577.bin
  • C:\Users\test\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\HEL4YQ7U\40000577[1].bin
  • C:\Users\test\AppData\Roaming\szw\MasterZ\data\40000577.dat
  • C:\Users\test\AppData\Roaming\szw\MasterZ\data\40000581.bin
  • C:\Users\test\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\CB4GP22D\40000581[1].bin
  • C:\Users\test\AppData\Roaming\szw\MasterZ\data\40000581.dat
  • C:\Users\test\AppData\Roaming\szw\MasterZ\data\40000582.bin
  • C:\Users\test\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\EHDRIWWS\40000582[1].bin
  • C:\Users\test\AppData\Roaming\szw\MasterZ\data\40000582.dat
  • C:\Users\test\AppData\Roaming\szw\MasterZ\data\40000584.bin
  • C:\Users\test\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\IDL4J1KW\40000584[1].bin
  • C:\Users\test\AppData\Roaming\szw\MasterZ\data\40000584.dat
  • C:\Users\test\AppData\Roaming\szw\MasterZ\data\40000588.bin
  • C:\Users\test\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\HEL4YQ7U\40000588[1].bin
  • C:\Users\test\AppData\Roaming\szw\MasterZ\data\40000588.dat
  • C:\Users\test\AppData\Roaming\szw\MasterZ\data\40000596.bin
  • C:\Users\test\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\CB4GP22D\40000596[1].bin
  • C:\Users\test\AppData\Roaming\szw\MasterZ\data\40000596.dat
  • C:\Users\test\AppData\Roaming\szw\MasterZ\data\40000598.bin
  • C:\Users\test\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\EHDRIWWS\40000598[1].bin
  • C:\Users\test\AppData\Roaming\szw\MasterZ\data\40000598.dat
  • C:\Users\test\AppData\Roaming\szw\MasterZ\data\40000600.bin
  • C:\Users\test\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\IDL4J1KW\40000600[1].bin
  • C:\Users\test\AppData\Roaming\szw\MasterZ\data\40000600.dat
  • C:\Users\test\AppData\Roaming\szw\MasterZ\data\40000609.bin
  • C:\Users\test\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\HEL4YQ7U\40000609[1].bin
  • C:\Users\test\AppData\Roaming\szw\MasterZ\data\40000609.dat
  • C:\Users\test\AppData\Roaming\szw\MasterZ\data\40000619.bin
  • C:\Users\test\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\CB4GP22D\40000619[1].bin
  • C:\Users\test\AppData\Roaming\szw\MasterZ\data\40000619.dat
  • C:\Users\test\AppData\Roaming\szw\MasterZ\data\40000622.bin
  • C:\Users\test\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\EHDRIWWS\40000622[1].bin
  • C:\Users\test\AppData\Roaming\szw\MasterZ\data\40000622.dat
  • C:\Users\test\AppData\Roaming\szw\MasterZ\data\40000626.bin
  • C:\Users\test\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\IDL4J1KW\40000626[1].bin
  • C:\Users\test\AppData\Roaming\szw\MasterZ\data\40000626.dat
  • C:\Users\test\AppData\Roaming\szw\MasterZ\data\40000634.bin
  • C:\Users\test\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\HEL4YQ7U\40000634[1].bin
  • C:\Users\test\AppData\Roaming\szw\MasterZ\data\40000634.dat
  • C:\Users\test\AppData\Roaming\szw\MasterZ\data\40000637.bin
  • C:\Users\test\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\CB4GP22D\40000637[1].bin
  • C:\Users\test\AppData\Roaming\szw\MasterZ\data\40000637.dat
  • C:\Users\test\AppData\Roaming\szw\MasterZ\data\40000638.bin
  • C:\Users\test\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\EHDRIWWS\40000638[1].bin
  • C:\Users\test\AppData\Roaming\szw\MasterZ\data\40000638.dat
  • C:\Users\test\AppData\Roaming\szw\MasterZ\data\40000639.bin
  • C:\Users\test\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\IDL4J1KW\40000639[1].bin
  • C:\Users\test\AppData\Roaming\szw\MasterZ\data\40000639.dat
  • C:\Users\test\AppData\Roaming\szw\MasterZ\data\40000643.bin
  • C:\Users\test\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\HEL4YQ7U\40000643[1].bin
  • C:\Users\test\AppData\Roaming\szw\MasterZ\data\40000643.dat
  • C:\Users\test\AppData\Roaming\szw\MasterZ\data\40000656.bin
  • C:\Users\test\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\CB4GP22D\40000656[1].bin
  • C:\Users\test\AppData\Roaming\szw\MasterZ\data\40000656.dat
  • C:\Users\test\AppData\Roaming\szw\MasterZ\data\40000658.bin
  • C:\Users\test\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\EHDRIWWS\40000658[1].bin
  • C:\Users\test\AppData\Roaming\szw\MasterZ\data\40000658.dat
  • C:\Users\test\AppData\Roaming\szw\MasterZ\data\40000670.bin
  • C:\Users\test\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\IDL4J1KW\40000670[1].bin
  • C:\Users\test\AppData\Roaming\szw\MasterZ\data\40000670.dat
  • C:\Users\test\AppData\Roaming\szw\MasterZ\data\40000707.bin
  • C:\Users\test\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\HEL4YQ7U\40000707[1].bin
  • C:\Users\test\AppData\Roaming\szw\MasterZ\data\40000707.dat
  • C:\Users\test\AppData\Roaming\szw\MasterZ\data\40000714.bin
  • C:\Users\test\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\CB4GP22D\40000714[1].bin
  • C:\Users\test\AppData\Roaming\szw\MasterZ\data\40000714.dat
  • C:\Users\test\AppData\Roaming\szw\MasterZ\data\40000722.bin
  • C:\Users\test\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\EHDRIWWS\40000722[1].bin
  • C:\Users\test\AppData\Roaming\szw\MasterZ\data\40000722.dat
  • C:\Users\test\AppData\Roaming\szw\MasterZ\data\40000725.bin
  • C:\Users\test\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\IDL4J1KW\40000725[1].bin
  • C:\Users\test\AppData\Roaming\szw\MasterZ\data\40000725.dat
  • C:\Users\test\AppData\Roaming\szw\MasterZ\data\40000740.bin
  • C:\Users\test\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\HEL4YQ7U\40000740[1].bin
  • C:\Users\test\AppData\Roaming\szw\MasterZ\data\40000740.dat
  • C:\Users\test\AppData\Roaming\szw\MasterZ\data\40000748.bin
  • C:\Users\test\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\CB4GP22D\40000748[1].bin
  • C:\Users\test\AppData\Roaming\szw\MasterZ\data\40000748.dat
  • C:\Users\test\AppData\Roaming\szw\MasterZ\data\40000760.bin
  • C:\Users\test\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\EHDRIWWS\40000760[1].bin
  • C:\Users\test\AppData\Roaming\szw\MasterZ\data\40000760.dat
  • C:\Users\test\AppData\Roaming\szw\MasterZ\data\40000767.bin
  • C:\Users\test\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\IDL4J1KW\40000767[1].bin
  • C:\Users\test\AppData\Roaming\szw\MasterZ\data\40000767.dat
  • C:\Users\test\AppData\Roaming\szw\MasterZ\data\40000777.bin
  • C:\Users\test\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\HEL4YQ7U\40000777[1].bin
  • C:\Users\test\AppData\Roaming\szw\MasterZ\data\40000777.dat
  • C:\Users\test\AppData\Roaming\szw\MasterZ\data\40000790.bin
  • C:\Users\test\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\CB4GP22D\40000790[1].bin
  • C:\Users\test\AppData\Roaming\szw\MasterZ\data\40000790.dat
  • C:\Users\test\AppData\Roaming\szw\MasterZ\data\40000791.bin
  • C:\Users\test\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\EHDRIWWS\40000791[1].bin
  • C:\Users\test\AppData\Roaming\szw\MasterZ\data\40000791.dat
  • C:\Users\test\AppData\Roaming\szw\MasterZ\data\40000806.bin
  • C:\Users\test\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\IDL4J1KW\40000806[1].bin
  • C:\Users\test\AppData\Roaming\szw\MasterZ\data\40000806.dat
  • C:\Users\test\AppData\Roaming\szw\MasterZ\data\40000807.bin
  • C:\Users\test\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\HEL4YQ7U\40000807[1].bin
  • C:\Users\test\AppData\Roaming\szw\MasterZ\data\40000807.dat
  • C:\Users\test\AppData\Roaming\szw\MasterZ\data\40000808.bin
  • C:\Users\test\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\CB4GP22D\40000808[1].bin
  • C:\Users\test\AppData\Roaming\szw\MasterZ\data\40000808.dat
  • C:\Users\test\AppData\Roaming\szw\MasterZ\data\40000809.bin
  • C:\Users\test\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\EHDRIWWS\40000809[1].bin
  • C:\Users\test\AppData\Roaming\szw\MasterZ\data\40000809.dat
  • C:\Users\test\AppData\Roaming\szw\MasterZ\data\40000810.bin
  • C:\Users\test\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\IDL4J1KW\40000810[1].bin
  • C:\Users\test\AppData\Roaming\szw\MasterZ\data\40000810.dat
  • C:\Users\test\AppData\Roaming\szw\MasterZ\data\40000821.bin
  • C:\Users\test\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\HEL4YQ7U\40000821[1].bin
  • C:\Users\test\AppData\Roaming\szw\MasterZ\data\40000821.dat
  • C:\Users\test\AppData\Roaming\szw\MasterZ\data\40000822.bin
  • C:\Users\test\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\CB4GP22D\40000822[1].bin
  • C:\Users\test\AppData\Roaming\szw\MasterZ\data\40000822.dat
  • C:\Users\test\AppData\Roaming\szw\MasterZ\data\40000830.bin
  • C:\Users\test\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\EHDRIWWS\40000830[1].bin
  • C:\Users\test\AppData\Roaming\szw\MasterZ\data\40000830.dat
  • C:\Users\test\AppData\Roaming\szw\MasterZ\data\40000831.bin
  • C:\Users\test\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\IDL4J1KW\40000831[1].bin
  • C:\Users\test\AppData\Roaming\szw\MasterZ\data\40000831.dat
  • C:\Users\test\AppData\Roaming\szw\MasterZ\data\40000834.bin
  • C:\Users\test\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\HEL4YQ7U\40000834[1].bin
  • C:\Users\test\AppData\Roaming\szw\MasterZ\data\40000834.dat
  • C:\Users\test\AppData\Roaming\szw\MasterZ\data\40000835.bin
  • C:\Users\test\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\CB4GP22D\40000835[1].bin
  • C:\Users\test\AppData\Roaming\szw\MasterZ\data\40000835.dat
  • C:\Users\test\AppData\Roaming\szw\MasterZ\data\40000836.bin
  • C:\Users\test\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\EHDRIWWS\40000836[1].bin
  • C:\Users\test\AppData\Roaming\szw\MasterZ\data\40000836.dat
  • C:\Users\test\AppData\Roaming\szw\MasterZ\data\40000837.bin
  • C:\Users\test\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\IDL4J1KW\40000837[1].bin
  • C:\Users\test\AppData\Roaming\szw\MasterZ\data\40000837.dat
  • C:\Users\test\AppData\Roaming\szw\MasterZ\data\40000838.bin
  • C:\Users\test\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\HEL4YQ7U\40000838[1].bin
  • C:\Users\test\AppData\Roaming\szw\MasterZ\data\40000838.dat
  • C:\Users\test\AppData\Roaming\szw\MasterZ\data\40000849.bin
  • C:\Users\test\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\CB4GP22D\40000849[1].bin
  • C:\Users\test\AppData\Roaming\szw\MasterZ\data\40000849.dat
  • C:\Users\test\AppData\Roaming\szw\MasterZ\data\40000851.bin
  • C:\Users\test\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\EHDRIWWS\40000851[1].bin
  • C:\Users\test\AppData\Roaming\szw\MasterZ\data\40000851.dat
  • C:\Users\test\AppData\Roaming\szw\MasterZ\data\40000852.bin
  • C:\Users\test\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\IDL4J1KW\40000852[1].bin
  • C:\Users\test\AppData\Roaming\szw\MasterZ\data\40000852.dat
  • C:\Users\test\AppData\Roaming\szw\MasterZ\data\40000856.bin
  • C:\Users\test\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\HEL4YQ7U\40000856[1].bin
  • C:\Users\test\AppData\Roaming\szw\MasterZ\data\40000856.dat
  • C:\Users\test\AppData\Roaming\szw\MasterZ\data\40000859.bin
  • C:\Users\test\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\CB4GP22D\40000859[1].bin
  • C:\Users\test\AppData\Roaming\szw\MasterZ\data\40000859.dat
  • C:\Users\test\AppData\Roaming\szw\MasterZ\data\40000863.bin
  • C:\Users\test\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\EHDRIWWS\40000863[1].bin
  • C:\Users\test\AppData\Roaming\szw\MasterZ\data\40000863.dat
  • C:\Users\test\AppData\Roaming\szw\MasterZ\data\40000864.bin
  • C:\Users\test\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\IDL4J1KW\40000864[1].bin
  • C:\Users\test\AppData\Roaming\szw\MasterZ\data\40000864.dat
  • C:\Users\test\AppData\Roaming\szw\MasterZ\data\40000865.bin
  • C:\Users\test\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\HEL4YQ7U\40000865[1].bin
  • C:\Users\test\AppData\Roaming\szw\MasterZ\data\40000865.dat
  • C:\Users\test\AppData\Roaming\szw\MasterZ\data\40000866.bin
  • C:\Users\test\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\CB4GP22D\40000866[1].bin
  • C:\Users\test\AppData\Roaming\szw\MasterZ\data\40000866.dat
  • C:\Users\test\AppData\Roaming\szw\MasterZ\data\40000875.bin
  • C:\Users\test\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\EHDRIWWS\40000875[1].bin
  • C:\Users\test\AppData\Roaming\szw\MasterZ\data\40000875.dat
  • C:\Users\test\AppData\Roaming\szw\MasterZ\data\40000878.bin
  • C:\Users\test\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\IDL4J1KW\40000878[1].bin
  • C:\Users\test\AppData\Roaming\szw\MasterZ\data\40000878.dat
  • C:\Users\test\AppData\Roaming\szw\MasterZ\data\40000879.bin
  • C:\Users\test\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\HEL4YQ7U\40000879[1].bin
  • C:\Users\test\AppData\Roaming\szw\MasterZ\data\40000879.dat
  • C:\Users\test\AppData\Roaming\szw\MasterZ\data\40000880.bin
  • C:\Users\test\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\CB4GP22D\40000880[1].bin
  • C:\Users\test\AppData\Roaming\szw\MasterZ\data\40000880.dat
  • C:\Users\test\AppData\Roaming\szw\MasterZ\data\40000893.bin
  • C:\Users\test\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\EHDRIWWS\40000893[1].bin
  • C:\Users\test\AppData\Roaming\szw\MasterZ\data\40000893.dat
  • C:\Users\test\AppData\Roaming\szw\MasterZ\data\40000894.bin
  • C:\Users\test\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\IDL4J1KW\40000894[1].bin
  • C:\Users\test\AppData\Roaming\szw\MasterZ\data\40000894.dat
  • C:\Users\test\AppData\Roaming\szw\MasterZ\data\40000895.bin
  • C:\Users\test\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\HEL4YQ7U\40000895[1].bin
  • C:\Users\test\AppData\Roaming\szw\MasterZ\data\40000895.dat
  • C:\Users\test\AppData\Roaming\szw\MasterZ\data\40000896.bin
  • C:\Users\test\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\CB4GP22D\40000896[1].bin
  • C:\Users\test\AppData\Roaming\szw\MasterZ\data\40000896.dat
  • C:\Users\test\AppData\Roaming\szw\MasterZ\data\40000897.bin
  • C:\Users\test\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\EHDRIWWS\40000897[1].bin
  • C:\Users\test\AppData\Roaming\szw\MasterZ\data\40000897.dat
  • C:\Users\test\AppData\Roaming\szw\MasterZ\data\40000907.bin
  • C:\Users\test\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\IDL4J1KW\40000907[1].bin
  • C:\Users\test\AppData\Roaming\szw\MasterZ\data\40000907.dat
  • C:\Users\test\AppData\Roaming\szw\MasterZ\data\40000908.bin
  • C:\Users\test\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\HEL4YQ7U\40000908[1].bin
  • C:\Users\test\AppData\Roaming\szw\MasterZ\data\40000908.dat
  • C:\Users\test\AppData\Roaming\szw\MasterZ\data\40000909.bin
  • C:\Users\test\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\CB4GP22D\40000909[1].bin
  • C:\Users\test\AppData\Roaming\szw\MasterZ\data\40000909.dat
  • C:\Users\test\AppData\Roaming\szw\MasterZ\data\40000917.bin
  • C:\Users\test\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\EHDRIWWS\40000917[1].bin
  • C:\Users\test\AppData\Roaming\szw\MasterZ\data\40000917.dat
  • C:\Users\test\AppData\Roaming\szw\MasterZ\data\40000918.bin
  • C:\Users\test\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\IDL4J1KW\40000918[1].bin
  • C:\Users\test\AppData\Roaming\szw\MasterZ\data\40000918.dat
  • C:\Users\test\AppData\Roaming\szw\MasterZ\data\40000919.bin
  • C:\Users\test\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\HEL4YQ7U\40000919[1].bin
  • C:\Users\test\AppData\Roaming\szw\MasterZ\data\40000919.dat
  • C:\Users\test\AppData\Roaming\szw\MasterZ\data\40000922.bin
  • C:\Users\test\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\CB4GP22D\40000922[1].bin
  • C:\Users\test\AppData\Roaming\szw\MasterZ\data\40000922.dat
  • C:\Users\test\AppData\Roaming\szw\MasterZ\data\40000923.bin
  • C:\Users\test\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\EHDRIWWS\40000923[1].bin
  • C:\Users\test\AppData\Roaming\szw\MasterZ\data\40000923.dat
  • C:\Users\test\AppData\Roaming\szw\MasterZ\data\40000924.bin
  • C:\Users\test\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\IDL4J1KW\40000924[1].bin
  • C:\Users\test\AppData\Roaming\szw\MasterZ\data\40000924.dat
删除的文件
  • C:\Users\test\AppData\Local\Temp\nso52C0.tmp
  • C:\Users\test\AppData\Local\Temp\nse53BC.tmp
  • C:\Users\test\AppData\Local\Temp\nsz628C.tmp
  • C:\Users\test\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\
  • C:\Users\test\AppData\Roaming\szw\MasterZ\data\40000002.bin
  • C:\Users\test\AppData\Roaming\szw\MasterZ\data\40000003.bin
  • C:\Users\test\AppData\Roaming\szw\MasterZ\data\40000502.bin
  • C:\Users\test\AppData\Roaming\szw\MasterZ\data\40000503.bin
  • C:\Users\test\AppData\Roaming\szw\MasterZ\data\40000505.bin
  • C:\Users\test\AppData\Roaming\szw\MasterZ\data\40000506.bin
  • C:\Users\test\AppData\Roaming\szw\MasterZ\data\40000507.bin
  • C:\Users\test\AppData\Roaming\szw\MasterZ\data\40000508.bin
  • C:\Users\test\AppData\Roaming\szw\MasterZ\data\40000510.bin
  • C:\Users\test\AppData\Roaming\szw\MasterZ\data\40000515.bin
  • C:\Users\test\AppData\Roaming\szw\MasterZ\data\40000527.bin
  • C:\Users\test\AppData\Roaming\szw\MasterZ\data\40000530.bin
  • C:\Users\test\AppData\Roaming\szw\MasterZ\data\40000531.bin
  • C:\Users\test\AppData\Roaming\szw\MasterZ\data\40000534.bin
  • C:\Users\test\AppData\Roaming\szw\MasterZ\data\40000540.bin
  • C:\Users\test\AppData\Roaming\szw\MasterZ\data\40000547.bin
  • C:\Users\test\AppData\Roaming\szw\MasterZ\data\40000554.bin
  • C:\Users\test\AppData\Roaming\szw\MasterZ\data\40000555.bin
  • C:\Users\test\AppData\Roaming\szw\MasterZ\data\40000557.bin
  • C:\Users\test\AppData\Roaming\szw\MasterZ\data\40000559.bin
  • C:\Users\test\AppData\Roaming\szw\MasterZ\data\40000560.bin
  • C:\Users\test\AppData\Roaming\szw\MasterZ\data\40000564.bin
  • C:\Users\test\AppData\Roaming\szw\MasterZ\data\40000570.bin
  • C:\Users\test\AppData\Roaming\szw\MasterZ\data\40000571.bin
  • C:\Users\test\AppData\Roaming\szw\MasterZ\data\40000577.bin
  • C:\Users\test\AppData\Roaming\szw\MasterZ\data\40000581.bin
  • C:\Users\test\AppData\Roaming\szw\MasterZ\data\40000582.bin
  • C:\Users\test\AppData\Roaming\szw\MasterZ\data\40000584.bin
  • C:\Users\test\AppData\Roaming\szw\MasterZ\data\40000588.bin
  • C:\Users\test\AppData\Roaming\szw\MasterZ\data\40000596.bin
  • C:\Users\test\AppData\Roaming\szw\MasterZ\data\40000598.bin
  • C:\Users\test\AppData\Roaming\szw\MasterZ\data\40000600.bin
  • C:\Users\test\AppData\Roaming\szw\MasterZ\data\40000609.bin
  • C:\Users\test\AppData\Roaming\szw\MasterZ\data\40000619.bin
  • C:\Users\test\AppData\Roaming\szw\MasterZ\data\40000622.bin
  • C:\Users\test\AppData\Roaming\szw\MasterZ\data\40000626.bin
  • C:\Users\test\AppData\Roaming\szw\MasterZ\data\40000634.bin
  • C:\Users\test\AppData\Roaming\szw\MasterZ\data\40000637.bin
  • C:\Users\test\AppData\Roaming\szw\MasterZ\data\40000638.bin
  • C:\Users\test\AppData\Roaming\szw\MasterZ\data\40000639.bin
  • C:\Users\test\AppData\Roaming\szw\MasterZ\data\40000643.bin
  • C:\Users\test\AppData\Roaming\szw\MasterZ\data\40000656.bin
  • C:\Users\test\AppData\Roaming\szw\MasterZ\data\40000658.bin
  • C:\Users\test\AppData\Roaming\szw\MasterZ\data\40000670.bin
  • C:\Users\test\AppData\Roaming\szw\MasterZ\data\40000707.bin
  • C:\Users\test\AppData\Roaming\szw\MasterZ\data\40000714.bin
  • C:\Users\test\AppData\Roaming\szw\MasterZ\data\40000722.bin
  • C:\Users\test\AppData\Roaming\szw\MasterZ\data\40000725.bin
  • C:\Users\test\AppData\Roaming\szw\MasterZ\data\40000740.bin
  • C:\Users\test\AppData\Roaming\szw\MasterZ\data\40000748.bin
  • C:\Users\test\AppData\Roaming\szw\MasterZ\data\40000760.bin
  • C:\Users\test\AppData\Roaming\szw\MasterZ\data\40000767.bin
  • C:\Users\test\AppData\Roaming\szw\MasterZ\data\40000777.bin
  • C:\Users\test\AppData\Roaming\szw\MasterZ\data\40000790.bin
  • C:\Users\test\AppData\Roaming\szw\MasterZ\data\40000791.bin
  • C:\Users\test\AppData\Roaming\szw\MasterZ\data\40000806.bin
  • C:\Users\test\AppData\Roaming\szw\MasterZ\data\40000807.bin
  • C:\Users\test\AppData\Roaming\szw\MasterZ\data\40000808.bin
  • C:\Users\test\AppData\Roaming\szw\MasterZ\data\40000809.bin
  • C:\Users\test\AppData\Roaming\szw\MasterZ\data\40000810.bin
  • C:\Users\test\AppData\Roaming\szw\MasterZ\data\40000821.bin
  • C:\Users\test\AppData\Roaming\szw\MasterZ\data\40000822.bin
  • C:\Users\test\AppData\Roaming\szw\MasterZ\data\40000830.bin
  • C:\Users\test\AppData\Roaming\szw\MasterZ\data\40000831.bin
  • C:\Users\test\AppData\Roaming\szw\MasterZ\data\40000834.bin
  • C:\Users\test\AppData\Roaming\szw\MasterZ\data\40000835.bin
  • C:\Users\test\AppData\Roaming\szw\MasterZ\data\40000836.bin
  • C:\Users\test\AppData\Roaming\szw\MasterZ\data\40000837.bin
  • C:\Users\test\AppData\Roaming\szw\MasterZ\data\40000838.bin
  • C:\Users\test\AppData\Roaming\szw\MasterZ\data\40000849.bin
  • C:\Users\test\AppData\Roaming\szw\MasterZ\data\40000851.bin
  • C:\Users\test\AppData\Roaming\szw\MasterZ\data\40000852.bin
  • C:\Users\test\AppData\Roaming\szw\MasterZ\data\40000856.bin
  • C:\Users\test\AppData\Roaming\szw\MasterZ\data\40000859.bin
  • C:\Users\test\AppData\Roaming\szw\MasterZ\data\40000863.bin
  • C:\Users\test\AppData\Roaming\szw\MasterZ\data\40000864.bin
  • C:\Users\test\AppData\Roaming\szw\MasterZ\data\40000865.bin
  • C:\Users\test\AppData\Roaming\szw\MasterZ\data\40000866.bin
  • C:\Users\test\AppData\Roaming\szw\MasterZ\data\40000875.bin
  • C:\Users\test\AppData\Roaming\szw\MasterZ\data\40000878.bin
  • C:\Users\test\AppData\Roaming\szw\MasterZ\data\40000879.bin
  • C:\Users\test\AppData\Roaming\szw\MasterZ\data\40000880.bin
  • C:\Users\test\AppData\Roaming\szw\MasterZ\data\40000893.bin
  • C:\Users\test\AppData\Roaming\szw\MasterZ\data\40000894.bin
  • C:\Users\test\AppData\Roaming\szw\MasterZ\data\40000895.bin
  • C:\Users\test\AppData\Roaming\szw\MasterZ\data\40000896.bin
  • C:\Users\test\AppData\Roaming\szw\MasterZ\data\40000897.bin
  • C:\Users\test\AppData\Roaming\szw\MasterZ\data\40000907.bin
  • C:\Users\test\AppData\Roaming\szw\MasterZ\data\40000908.bin
  • C:\Users\test\AppData\Roaming\szw\MasterZ\data\40000909.bin
  • C:\Users\test\AppData\Roaming\szw\MasterZ\data\40000917.bin
  • C:\Users\test\AppData\Roaming\szw\MasterZ\data\40000918.bin
  • C:\Users\test\AppData\Roaming\szw\MasterZ\data\40000919.bin
  • C:\Users\test\AppData\Roaming\szw\MasterZ\data\40000922.bin
  • C:\Users\test\AppData\Roaming\szw\MasterZ\data\40000923.bin
  • C:\Users\test\AppData\Roaming\szw\MasterZ\data\40000924.bin
注册表键
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\CPC\Volume
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\CPC\Volume\{372941a3-1bd9-11e5-9838-806e6f6e6963}\
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\CPC\Volume\{372941a3-1bd9-11e5-9838-806e6f6e6963}\Data
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\CPC\Volume\{372941a3-1bd9-11e5-9838-806e6f6e6963}\Generation
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\CPC\Volume\{372941a4-1bd9-11e5-9838-806e6f6e6963}\
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\CPC\Volume\{372941a4-1bd9-11e5-9838-806e6f6e6963}\Data
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\CPC\Volume\{372941a4-1bd9-11e5-9838-806e6f6e6963}\Generation
  • HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Uninstall\\xe6\xa0\x87\xe5\x87\x86\xe4\xbb\xb6
  • HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\Nls\Locale
  • HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\Nls\Locale\Alternate Sorts
  • HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\Nls\Language Groups
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\Locale\00000804
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\Language Groups\a
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\CTF\Compatibility\MasterZ_Custom_93.exe
  • HKEY_LOCAL_MACHINE\Software\Microsoft\CTF\TIP\{0000897b-83df-4b96-be07-0fb58b01c4a4}\LanguageProfile\0x00000000\{0001bea3-ed56-483d-a2e2-aeae25577436}
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\CTF\TIP\{0000897b-83df-4b96-be07-0fb58b01c4a4}\LanguageProfile\0x00000000\{0001bea3-ed56-483d-a2e2-aeae25577436}\Enable
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\CTF\TIP\
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\CTF\TIP\{0000897b-83df-4b96-be07-0fb58b01c4a4}\Category\Category\{534C48C1-0607-4098-A521-4FC899C73E90}
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\CTF\TIP\{03B5835F-F03C-411B-9CE2-AA23E1171E36}\Category\Category\{534C48C1-0607-4098-A521-4FC899C73E90}
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\CTF\TIP\{07EB03D6-B001-41DF-9192-BF9B841EE71F}\Category\Category\{534C48C1-0607-4098-A521-4FC899C73E90}
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\CTF\TIP\{3697C5FA-60DD-4B56-92D4-74A569205C16}\Category\Category\{534C48C1-0607-4098-A521-4FC899C73E90}
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\CTF\TIP\{3FC47A08-E5C9-4BCA-A2C7-BC9A282AED14}\Category\Category\{534C48C1-0607-4098-A521-4FC899C73E90}
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\CTF\TIP\{531FDEBF-9B4C-4A43-A2AA-960E8FCDC732}\Category\Category\{534C48C1-0607-4098-A521-4FC899C73E90}
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\CTF\TIP\{78CB5B0E-26ED-4FCC-854C-77E8F3D1AA80}\Category\Category\{534C48C1-0607-4098-A521-4FC899C73E90}
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\CTF\TIP\{81D4E9C9-1D3B-41BC-9E6C-4B40BF79E35E}\Category\Category\{534C48C1-0607-4098-A521-4FC899C73E90}
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\CTF\TIP\{8613E14C-D0C0-4161-AC0F-1DD2563286BC}\Category\Category\{534C48C1-0607-4098-A521-4FC899C73E90}
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\CTF\TIP\{A028AE76-01B1-46C2-99C4-ACD9858AE02F}\Category\Category\{534C48C1-0607-4098-A521-4FC899C73E90}
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\CTF\TIP\{AE6BE008-07FB-400D-8BEB-337A64F7051F}\Category\Category\{534C48C1-0607-4098-A521-4FC899C73E90}
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\CTF\TIP\{C1EE01F2-B3B6-4A6A-9DDD-E988C088EC82}\Category\Category\{534C48C1-0607-4098-A521-4FC899C73E90}
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\CTF\TIP\{DCBD6FA8-032F-11D3-B5B1-00C04FC324A1}\Category\Category\{534C48C1-0607-4098-A521-4FC899C73E90}
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\CTF\TIP\{E429B25A-E5D3-4D1F-9BE3-0C608477E3A1}\Category\Category\{534C48C1-0607-4098-A521-4FC899C73E90}
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\CTF\TIP\{F25E9F57-2FC8-4EB3-A41A-CCE5F08541E6}\Category\Category\{534C48C1-0607-4098-A521-4FC899C73E90}
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\CTF\TIP\{F89E9E58-BD2F-4008-9AC2-0F816C09F4EE}\Category\Category\{534C48C1-0607-4098-A521-4FC899C73E90}
  • HKEY_CURRENT_USER
  • HKEY_CURRENT_USER\Keyboard Layout\Toggle
  • HKEY_CURRENT_USER\Keyboard Layout\Toggle\Language Hotkey
  • HKEY_CURRENT_USER\Keyboard Layout\Toggle\Hotkey
  • HKEY_CURRENT_USER\Keyboard Layout\Toggle\Layout Hotkey
  • HKEY_CURRENT_USER\Software\Microsoft\CTF\DirectSwitchHotkeys
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\CTF\
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\CTF\EnableAnchorContext
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\CTF\KnownClasses
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\FontLink\SystemLink
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\DataStore_V1.0
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\DataStore_V1.0\Disable
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\DataStore_V1.0\DataFilePath
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Plane1
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Plane2
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Plane3
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Plane4
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Plane5
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Plane6
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Plane7
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Plane8
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Plane9
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Plane10
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Plane11
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Plane12
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Plane13
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Plane14
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Plane15
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Plane16
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\SimSun
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\SimSun\Plane1
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\SimSun\Plane2
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\SimSun\Plane3
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\SimSun\Plane4
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\SimSun\Plane5
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\SimSun\Plane6
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\SimSun\Plane7
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\SimSun\Plane8
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\SimSun\Plane9
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\SimSun\Plane10
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\SimSun\Plane11
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\SimSun\Plane12
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\SimSun\Plane13
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\SimSun\Plane14
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\SimSun\Plane15
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\SimSun\Plane16
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\DllNXOptions
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\DllNXOptions\UseFilter
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\DllNXOptions\System.dll
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\SESSION MANAGER\SafeProcessSearchMode
  • HKEY_CURRENT_USER\Control Panel\Desktop
  • HKEY_CURRENT_USER\Control Panel\Desktop\SmoothScroll
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced\EnableBalloonTips
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced\ListviewAlphaSelect
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced\ListviewShadow
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced\AccListViewV6
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced\UseDoubleClickTimer
  • HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\FontSubstitutes
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\FontSubstitutes\\xe5\xae\x8b\xe4\xbd\x93
  • HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\Nls\CustomLocale
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\en-US
  • HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\Nls\ExtendedLocale
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\ExtendedLocale\en-US
  • HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Desktop\NameSpace\DelegateFolders
  • HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Desktop\NameSpace
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\Desktop\NameSpace\{031E4825-7B94-4dc3-B131-E946B44C8DD5}
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\Desktop\NameSpace\{031E4825-7B94-4dc3-B131-E946B44C8DD5}\SuppressionPolicy
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\Desktop\NameSpace\{04731B67-D933-450a-90E6-4ACD2E9408FE}
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\Desktop\NameSpace\{04731B67-D933-450a-90E6-4ACD2E9408FE}\SuppressionPolicy
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\Desktop\NameSpace\{11016101-E366-4D22-BC06-4ADA335C892B}
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\Desktop\NameSpace\{11016101-E366-4D22-BC06-4ADA335C892B}\SuppressionPolicy
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\Desktop\NameSpace\{138508bc-1e03-49ea-9c8f-ea9e1d05d65d}
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\Desktop\NameSpace\{138508bc-1e03-49ea-9c8f-ea9e1d05d65d}\SuppressionPolicy
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\Desktop\NameSpace\{26EE0668-A00A-44D7-9371-BEB064C98683}
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\Desktop\NameSpace\{26EE0668-A00A-44D7-9371-BEB064C98683}\SuppressionPolicy
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\Desktop\NameSpace\{4336a54d-038b-4685-ab02-99bb52d3fb8b}
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\Desktop\NameSpace\{4336a54d-038b-4685-ab02-99bb52d3fb8b}\SuppressionPolicy
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\Desktop\NameSpace\{450D8FBA-AD25-11D0-98A8-0800361B1103}
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\Desktop\NameSpace\{450D8FBA-AD25-11D0-98A8-0800361B1103}\SuppressionPolicy
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\Desktop\NameSpace\{5399E694-6CE5-4D6C-8FCE-1D8870FDCBA0}
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\Desktop\NameSpace\{5399E694-6CE5-4D6C-8FCE-1D8870FDCBA0}\SuppressionPolicy
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\Desktop\NameSpace\{59031a47-3f72-44a7-89c5-5595fe6b30ee}
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\Desktop\NameSpace\{59031a47-3f72-44a7-89c5-5595fe6b30ee}\SuppressionPolicy
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\Desktop\NameSpace\{645FF040-5081-101B-9F08-00AA002F954E}
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\Desktop\NameSpace\{645FF040-5081-101B-9F08-00AA002F954E}\SuppressionPolicy
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\Desktop\NameSpace\{89D83576-6BD1-4c86-9454-BEB04E94C819}
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\Desktop\NameSpace\{89D83576-6BD1-4c86-9454-BEB04E94C819}\SuppressionPolicy
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\Desktop\NameSpace\{9343812e-1c37-4a49-a12e-4b2d810d956b}
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\Desktop\NameSpace\{9343812e-1c37-4a49-a12e-4b2d810d956b}\SuppressionPolicy
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\Desktop\NameSpace\{B0FBD52D-C4A7-4a19-985D-11309D1AC8AE}
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\Desktop\NameSpace\{B0FBD52D-C4A7-4a19-985D-11309D1AC8AE}\SuppressionPolicy
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\Desktop\NameSpace\{B4FB3F98-C1EA-428d-A78A-D1F5659CBA93}
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\Desktop\NameSpace\{B4FB3F98-C1EA-428d-A78A-D1F5659CBA93}\SuppressionPolicy
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\Desktop\NameSpace\{BD7A2E7B-21CB-41b2-A086-B309680C6B7E}
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\Desktop\NameSpace\{BD7A2E7B-21CB-41b2-A086-B309680C6B7E}\SuppressionPolicy
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\Desktop\NameSpace\{daf95313-e44d-46af-be1b-cbacea2c3065}
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\Desktop\NameSpace\{daf95313-e44d-46af-be1b-cbacea2c3065}\SuppressionPolicy
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\Desktop\NameSpace\{e345f35f-9397-435c-8f95-4e922c26259e}
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\Desktop\NameSpace\{e345f35f-9397-435c-8f95-4e922c26259e}\SuppressionPolicy
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\Desktop\NameSpace\{ED228FDF-9EA8-4870-83b1-96b02CFE0D52}
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\Desktop\NameSpace\{ED228FDF-9EA8-4870-83b1-96b02CFE0D52}\SuppressionPolicy
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\Desktop\NameSpace\{F02C1A0D-BE21-4350-88B0-7367FC96EF3C}
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\Desktop\NameSpace\{F02C1A0D-BE21-4350-88B0-7367FC96EF3C}\SuppressionPolicy
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Desktop\NameSpace
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Desktop\NameSpace\DelegateFolders
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\SessionInfo\1
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\SessionInfo\1\Desktop\NameSpace
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\SessionInfo\1\Desktop\NameSpace\DelegateFolders
  • HKEY_CLASSES_ROOT\CLSID\{208D2C60-3AEA-1069-A2D7-08002B30309D}\ShellFolder
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{208D2C60-3AEA-1069-A2D7-08002B30309D}\ShellFolder\Attributes
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{208D2C60-3AEA-1069-A2D7-08002B30309D}\ShellFolder\CallForAttributes
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{208D2C60-3AEA-1069-A2D7-08002B30309D}\ShellFolder\RestrictedAttributes
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{208D2C60-3AEA-1069-A2D7-08002B30309D}\ShellFolder\WantsFORDISPLAY
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{208D2C60-3AEA-1069-A2D7-08002B30309D}\ShellFolder\HideFolderVerbs
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{208D2C60-3AEA-1069-A2D7-08002B30309D}\ShellFolder\UseDropHandler
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{208D2C60-3AEA-1069-A2D7-08002B30309D}\ShellFolder\WantsFORPARSING
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{208D2C60-3AEA-1069-A2D7-08002B30309D}\ShellFolder\WantsParseDisplayName
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{208D2C60-3AEA-1069-A2D7-08002B30309D}\ShellFolder\QueryForOverlay
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{208D2C60-3AEA-1069-A2D7-08002B30309D}\ShellFolder\MapNetDriveVerbs
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{208D2C60-3AEA-1069-A2D7-08002B30309D}\ShellFolder\QueryForInfoTip
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{208D2C60-3AEA-1069-A2D7-08002B30309D}\ShellFolder\HideInWebView
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{208D2C60-3AEA-1069-A2D7-08002B30309D}\ShellFolder\HideOnDesktopPerUser
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{208D2C60-3AEA-1069-A2D7-08002B30309D}\ShellFolder\WantsAliasedNotifications
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{208D2C60-3AEA-1069-A2D7-08002B30309D}\ShellFolder\WantsUniversalDelegate
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{208D2C60-3AEA-1069-A2D7-08002B30309D}\ShellFolder\NoFileFolderJunction
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{208D2C60-3AEA-1069-A2D7-08002B30309D}\ShellFolder\PinToNameSpaceTree
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{208D2C60-3AEA-1069-A2D7-08002B30309D}\ShellFolder\HasNavigationEnum
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\CLSID\{208D2C60-3AEA-1069-A2D7-08002B30309D}\ShellFolder
  • HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\CLSID\{208D2C60-3AEA-1069-A2D7-08002B30309D}\ShellFolder
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\NonEnum
  • HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\NonEnum
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\NonEnum\{208D2C60-3AEA-1069-A2D7-08002B30309D}
  • HKEY_CLASSES_ROOT\CLSID\{871C5380-42A0-1069-A2EA-08002B30309D}\ShellFolder
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{871C5380-42A0-1069-A2EA-08002B30309D}\ShellFolder\Attributes
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{871C5380-42A0-1069-A2EA-08002B30309D}\ShellFolder\CallForAttributes
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{871C5380-42A0-1069-A2EA-08002B30309D}\ShellFolder\RestrictedAttributes
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{871C5380-42A0-1069-A2EA-08002B30309D}\ShellFolder\WantsFORDISPLAY
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{871C5380-42A0-1069-A2EA-08002B30309D}\ShellFolder\HideFolderVerbs
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{871C5380-42A0-1069-A2EA-08002B30309D}\ShellFolder\UseDropHandler
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{871C5380-42A0-1069-A2EA-08002B30309D}\ShellFolder\WantsFORPARSING
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{871C5380-42A0-1069-A2EA-08002B30309D}\ShellFolder\WantsParseDisplayName
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{871C5380-42A0-1069-A2EA-08002B30309D}\ShellFolder\QueryForOverlay
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{871C5380-42A0-1069-A2EA-08002B30309D}\ShellFolder\MapNetDriveVerbs
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{871C5380-42A0-1069-A2EA-08002B30309D}\ShellFolder\QueryForInfoTip
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{871C5380-42A0-1069-A2EA-08002B30309D}\ShellFolder\HideInWebView
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{871C5380-42A0-1069-A2EA-08002B30309D}\ShellFolder\HideOnDesktopPerUser
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{871C5380-42A0-1069-A2EA-08002B30309D}\ShellFolder\WantsAliasedNotifications
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{871C5380-42A0-1069-A2EA-08002B30309D}\ShellFolder\WantsUniversalDelegate
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{871C5380-42A0-1069-A2EA-08002B30309D}\ShellFolder\NoFileFolderJunction
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{871C5380-42A0-1069-A2EA-08002B30309D}\ShellFolder\PinToNameSpaceTree
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{871C5380-42A0-1069-A2EA-08002B30309D}\ShellFolder\HasNavigationEnum
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\CLSID\{871C5380-42A0-1069-A2EA-08002B30309D}\ShellFolder
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\CLSID\{871C5380-42A0-1069-A2EA-08002B30309D}\ShellFolder\Attributes
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\NonEnum\{871C5380-42A0-1069-A2EA-08002B30309D}
  • HKEY_CLASSES_ROOT\CLSID\{871C5380-42A0-1069-A2EA-08002B30309D}\InProcServer32
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{871C5380-42A0-1069-A2EA-08002B30309D}\InProcServer32\(Default)
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{871C5380-42A0-1069-A2EA-08002B30309D}\InProcServer32\LoadWithoutCOM
  • HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Blocked
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Blocked
  • HKEY_LOCAL_MACHINE\Software\Classes\CLSID\{871c5380-42a0-1069-a2ea-08002b30309d}\InProcServer32
  • HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion
  • HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Layers
  • HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\AppCompatFlags
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Custom\ieframe.dll
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Cached
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Cached\{871C5380-42A0-1069-A2EA-08002B30309D} {000214E6-0000-0000-C000-000000000046} 0xFFFF
  • HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\SQMClient\Windows
  • HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\SQMClient\Windows\CEIPEnable
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellCompatibility\Objects\{871C5380-42A0-1069-A2EA-08002B30309D}
  • HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings
  • HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\CreateUriCacheSize
  • HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings
  • HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\CreateUriCacheSize
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\CreateUriCacheSize
  • HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Internet Settings
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Internet Settings\CreateUriCacheSize
  • HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\EnablePunycode
  • HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\EnablePunycode
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\EnablePunycode
  • HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_HTTP_USERNAME_PASSWORD_DISABLE
  • HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_HTTP_USERNAME_PASSWORD_DISABLE
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\MAIN\FeatureControl\FEATURE_HTTP_USERNAME_PASSWORD_DISABLE\MasterZ_Custom_93.exe
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\MAIN\FeatureControl\FEATURE_HTTP_USERNAME_PASSWORD_DISABLE\*
  • HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Security_HKLM_only
  • HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Internet Explorer\Main\FeatureControl
  • HKEY_CURRENT_USER\Software\Policies\Microsoft\Internet Explorer\Main\FeatureControl
  • HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main\FeatureControl
  • HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main\FeatureControl
  • HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_ALLOW_REVERSE_SOLIDUS_IN_USERINFO_KB932562
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\MAIN\FeatureControl\FEATURE_ALLOW_REVERSE_SOLIDUS_IN_USERINFO_KB932562
  • HKEY_CLASSES_ROOT\CLSID\{645FF040-5081-101B-9F08-00AA002F954E}\ShellFolder
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{645FF040-5081-101B-9F08-00AA002F954E}\ShellFolder\Attributes
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{645FF040-5081-101B-9F08-00AA002F954E}\ShellFolder\CallForAttributes
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{645FF040-5081-101B-9F08-00AA002F954E}\ShellFolder\RestrictedAttributes
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{645FF040-5081-101B-9F08-00AA002F954E}\ShellFolder\WantsFORDISPLAY
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{645FF040-5081-101B-9F08-00AA002F954E}\ShellFolder\HideFolderVerbs
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{645FF040-5081-101B-9F08-00AA002F954E}\ShellFolder\UseDropHandler
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{645FF040-5081-101B-9F08-00AA002F954E}\ShellFolder\WantsFORPARSING
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{645FF040-5081-101B-9F08-00AA002F954E}\ShellFolder\WantsParseDisplayName
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{645FF040-5081-101B-9F08-00AA002F954E}\ShellFolder\QueryForOverlay
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{645FF040-5081-101B-9F08-00AA002F954E}\ShellFolder\MapNetDriveVerbs
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{645FF040-5081-101B-9F08-00AA002F954E}\ShellFolder\QueryForInfoTip
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{645FF040-5081-101B-9F08-00AA002F954E}\ShellFolder\HideInWebView
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{645FF040-5081-101B-9F08-00AA002F954E}\ShellFolder\HideOnDesktopPerUser
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{645FF040-5081-101B-9F08-00AA002F954E}\ShellFolder\WantsAliasedNotifications
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{645FF040-5081-101B-9F08-00AA002F954E}\ShellFolder\WantsUniversalDelegate
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{645FF040-5081-101B-9F08-00AA002F954E}\ShellFolder\NoFileFolderJunction
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{645FF040-5081-101B-9F08-00AA002F954E}\ShellFolder\PinToNameSpaceTree
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{645FF040-5081-101B-9F08-00AA002F954E}\ShellFolder\HasNavigationEnum
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\CLSID\{645FF040-5081-101B-9F08-00AA002F954E}\ShellFolder
  • HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\CLSID\{645FF040-5081-101B-9F08-00AA002F954E}\ShellFolder
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\NonEnum\{645FF040-5081-101B-9F08-00AA002F954E}
  • HKEY_CLASSES_ROOT\CLSID\{26EE0668-A00A-44D7-9371-BEB064C98683}\ShellFolder
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{26EE0668-A00A-44D7-9371-BEB064C98683}\ShellFolder\Attributes
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{26EE0668-A00A-44D7-9371-BEB064C98683}\ShellFolder\CallForAttributes
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{26EE0668-A00A-44D7-9371-BEB064C98683}\ShellFolder\RestrictedAttributes
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{26EE0668-A00A-44D7-9371-BEB064C98683}\ShellFolder\WantsFORDISPLAY
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{26EE0668-A00A-44D7-9371-BEB064C98683}\ShellFolder\HideFolderVerbs
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{26EE0668-A00A-44D7-9371-BEB064C98683}\ShellFolder\UseDropHandler
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{26EE0668-A00A-44D7-9371-BEB064C98683}\ShellFolder\WantsFORPARSING
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{26EE0668-A00A-44D7-9371-BEB064C98683}\ShellFolder\WantsParseDisplayName
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{26EE0668-A00A-44D7-9371-BEB064C98683}\ShellFolder\QueryForOverlay
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{26EE0668-A00A-44D7-9371-BEB064C98683}\ShellFolder\MapNetDriveVerbs
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{26EE0668-A00A-44D7-9371-BEB064C98683}\ShellFolder\QueryForInfoTip
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{26EE0668-A00A-44D7-9371-BEB064C98683}\ShellFolder\HideInWebView
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{26EE0668-A00A-44D7-9371-BEB064C98683}\ShellFolder\HideOnDesktopPerUser
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{26EE0668-A00A-44D7-9371-BEB064C98683}\ShellFolder\WantsAliasedNotifications
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{26EE0668-A00A-44D7-9371-BEB064C98683}\ShellFolder\WantsUniversalDelegate
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{26EE0668-A00A-44D7-9371-BEB064C98683}\ShellFolder\NoFileFolderJunction
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{26EE0668-A00A-44D7-9371-BEB064C98683}\ShellFolder\PinToNameSpaceTree
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{26EE0668-A00A-44D7-9371-BEB064C98683}\ShellFolder\HasNavigationEnum
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\CLSID\{26EE0668-A00A-44D7-9371-BEB064C98683}\ShellFolder
  • HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\CLSID\{26EE0668-A00A-44D7-9371-BEB064C98683}\ShellFolder
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\NonEnum\{26EE0668-A00A-44D7-9371-BEB064C98683}
  • HKEY_CLASSES_ROOT\CLSID\{031E4825-7B94-4DC3-B131-E946B44C8DD5}\ShellFolder
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{031E4825-7B94-4DC3-B131-E946B44C8DD5}\ShellFolder\Attributes
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{031E4825-7B94-4DC3-B131-E946B44C8DD5}\ShellFolder\CallForAttributes
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{031E4825-7B94-4DC3-B131-E946B44C8DD5}\ShellFolder\RestrictedAttributes
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{031E4825-7B94-4DC3-B131-E946B44C8DD5}\ShellFolder\WantsFORDISPLAY
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{031E4825-7B94-4DC3-B131-E946B44C8DD5}\ShellFolder\HideFolderVerbs
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{031E4825-7B94-4DC3-B131-E946B44C8DD5}\ShellFolder\UseDropHandler
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{031E4825-7B94-4DC3-B131-E946B44C8DD5}\ShellFolder\WantsFORPARSING
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{031E4825-7B94-4DC3-B131-E946B44C8DD5}\ShellFolder\WantsParseDisplayName
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{031E4825-7B94-4DC3-B131-E946B44C8DD5}\ShellFolder\QueryForOverlay
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{031E4825-7B94-4DC3-B131-E946B44C8DD5}\ShellFolder\MapNetDriveVerbs
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{031E4825-7B94-4DC3-B131-E946B44C8DD5}\ShellFolder\QueryForInfoTip
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{031E4825-7B94-4DC3-B131-E946B44C8DD5}\ShellFolder\HideInWebView
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{031E4825-7B94-4DC3-B131-E946B44C8DD5}\ShellFolder\HideOnDesktopPerUser
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{031E4825-7B94-4DC3-B131-E946B44C8DD5}\ShellFolder\WantsAliasedNotifications
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{031E4825-7B94-4DC3-B131-E946B44C8DD5}\ShellFolder\WantsUniversalDelegate
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{031E4825-7B94-4DC3-B131-E946B44C8DD5}\ShellFolder\NoFileFolderJunction
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{031E4825-7B94-4DC3-B131-E946B44C8DD5}\ShellFolder\PinToNameSpaceTree
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{031E4825-7B94-4DC3-B131-E946B44C8DD5}\ShellFolder\HasNavigationEnum
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\CLSID\{031E4825-7B94-4DC3-B131-E946B44C8DD5}\ShellFolder
  • HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\CLSID\{031E4825-7B94-4DC3-B131-E946B44C8DD5}\ShellFolder
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\NonEnum\{031E4825-7B94-4DC3-B131-E946B44C8DD5}
  • HKEY_CLASSES_ROOT\CLSID\{04731B67-D933-450A-90E6-4ACD2E9408FE}\ShellFolder
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{04731B67-D933-450A-90E6-4ACD2E9408FE}\ShellFolder\Attributes
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{04731B67-D933-450A-90E6-4ACD2E9408FE}\ShellFolder\CallForAttributes
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{04731B67-D933-450A-90E6-4ACD2E9408FE}\ShellFolder\RestrictedAttributes
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{04731B67-D933-450A-90E6-4ACD2E9408FE}\ShellFolder\WantsFORDISPLAY
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{04731B67-D933-450A-90E6-4ACD2E9408FE}\ShellFolder\HideFolderVerbs
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{04731B67-D933-450A-90E6-4ACD2E9408FE}\ShellFolder\UseDropHandler
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{04731B67-D933-450A-90E6-4ACD2E9408FE}\ShellFolder\WantsFORPARSING
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{04731B67-D933-450A-90E6-4ACD2E9408FE}\ShellFolder\WantsParseDisplayName
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{04731B67-D933-450A-90E6-4ACD2E9408FE}\ShellFolder\QueryForOverlay
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{04731B67-D933-450A-90E6-4ACD2E9408FE}\ShellFolder\MapNetDriveVerbs
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{04731B67-D933-450A-90E6-4ACD2E9408FE}\ShellFolder\QueryForInfoTip
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{04731B67-D933-450A-90E6-4ACD2E9408FE}\ShellFolder\HideInWebView
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{04731B67-D933-450A-90E6-4ACD2E9408FE}\ShellFolder\HideOnDesktopPerUser
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{04731B67-D933-450A-90E6-4ACD2E9408FE}\ShellFolder\WantsAliasedNotifications
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{04731B67-D933-450A-90E6-4ACD2E9408FE}\ShellFolder\WantsUniversalDelegate
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{04731B67-D933-450A-90E6-4ACD2E9408FE}\ShellFolder\NoFileFolderJunction
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{04731B67-D933-450A-90E6-4ACD2E9408FE}\ShellFolder\PinToNameSpaceTree
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{04731B67-D933-450A-90E6-4ACD2E9408FE}\ShellFolder\HasNavigationEnum
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\CLSID\{04731B67-D933-450A-90E6-4ACD2E9408FE}\ShellFolder
  • HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\CLSID\{04731B67-D933-450A-90E6-4ACD2E9408FE}\ShellFolder
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\NonEnum\{04731B67-D933-450A-90E6-4ACD2E9408FE}
  • HKEY_CLASSES_ROOT\CLSID\{11016101-E366-4D22-BC06-4ADA335C892B}\ShellFolder
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{11016101-E366-4D22-BC06-4ADA335C892B}\ShellFolder\Attributes
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{11016101-E366-4D22-BC06-4ADA335C892B}\ShellFolder\CallForAttributes
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{11016101-E366-4D22-BC06-4ADA335C892B}\ShellFolder\RestrictedAttributes
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{11016101-E366-4D22-BC06-4ADA335C892B}\ShellFolder\WantsFORDISPLAY
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{11016101-E366-4D22-BC06-4ADA335C892B}\ShellFolder\HideFolderVerbs
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{11016101-E366-4D22-BC06-4ADA335C892B}\ShellFolder\UseDropHandler
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{11016101-E366-4D22-BC06-4ADA335C892B}\ShellFolder\WantsFORPARSING
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{11016101-E366-4D22-BC06-4ADA335C892B}\ShellFolder\WantsParseDisplayName
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{11016101-E366-4D22-BC06-4ADA335C892B}\ShellFolder\QueryForOverlay
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{11016101-E366-4D22-BC06-4ADA335C892B}\ShellFolder\MapNetDriveVerbs
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{11016101-E366-4D22-BC06-4ADA335C892B}\ShellFolder\QueryForInfoTip
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{11016101-E366-4D22-BC06-4ADA335C892B}\ShellFolder\HideInWebView
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{11016101-E366-4D22-BC06-4ADA335C892B}\ShellFolder\HideOnDesktopPerUser
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{11016101-E366-4D22-BC06-4ADA335C892B}\ShellFolder\WantsAliasedNotifications
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{11016101-E366-4D22-BC06-4ADA335C892B}\ShellFolder\WantsUniversalDelegate
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{11016101-E366-4D22-BC06-4ADA335C892B}\ShellFolder\NoFileFolderJunction
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{11016101-E366-4D22-BC06-4ADA335C892B}\ShellFolder\PinToNameSpaceTree
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{11016101-E366-4D22-BC06-4ADA335C892B}\ShellFolder\HasNavigationEnum
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\CLSID\{11016101-E366-4D22-BC06-4ADA335C892B}\ShellFolder
  • HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\CLSID\{11016101-E366-4D22-BC06-4ADA335C892B}\ShellFolder
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\NonEnum\{11016101-E366-4D22-BC06-4ADA335C892B}
  • HKEY_CLASSES_ROOT\CLSID\{138508BC-1E03-49EA-9C8F-EA9E1D05D65D}\ShellFolder
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{138508BC-1E03-49EA-9C8F-EA9E1D05D65D}\ShellFolder\Attributes
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{138508BC-1E03-49EA-9C8F-EA9E1D05D65D}\ShellFolder\CallForAttributes
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{138508BC-1E03-49EA-9C8F-EA9E1D05D65D}\ShellFolder\RestrictedAttributes
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{138508BC-1E03-49EA-9C8F-EA9E1D05D65D}\ShellFolder\WantsFORDISPLAY
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{138508BC-1E03-49EA-9C8F-EA9E1D05D65D}\ShellFolder\HideFolderVerbs
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{138508BC-1E03-49EA-9C8F-EA9E1D05D65D}\ShellFolder\UseDropHandler
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{138508BC-1E03-49EA-9C8F-EA9E1D05D65D}\ShellFolder\WantsFORPARSING
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{138508BC-1E03-49EA-9C8F-EA9E1D05D65D}\ShellFolder\WantsParseDisplayName
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{138508BC-1E03-49EA-9C8F-EA9E1D05D65D}\ShellFolder\QueryForOverlay
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{138508BC-1E03-49EA-9C8F-EA9E1D05D65D}\ShellFolder\MapNetDriveVerbs
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{138508BC-1E03-49EA-9C8F-EA9E1D05D65D}\ShellFolder\QueryForInfoTip
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{138508BC-1E03-49EA-9C8F-EA9E1D05D65D}\ShellFolder\HideInWebView
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{138508BC-1E03-49EA-9C8F-EA9E1D05D65D}\ShellFolder\HideOnDesktopPerUser
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{138508BC-1E03-49EA-9C8F-EA9E1D05D65D}\ShellFolder\WantsAliasedNotifications
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{138508BC-1E03-49EA-9C8F-EA9E1D05D65D}\ShellFolder\WantsUniversalDelegate
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{138508BC-1E03-49EA-9C8F-EA9E1D05D65D}\ShellFolder\NoFileFolderJunction
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{138508BC-1E03-49EA-9C8F-EA9E1D05D65D}\ShellFolder\PinToNameSpaceTree
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{138508BC-1E03-49EA-9C8F-EA9E1D05D65D}\ShellFolder\HasNavigationEnum
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\CLSID\{138508BC-1E03-49EA-9C8F-EA9E1D05D65D}\ShellFolder
  • HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\CLSID\{138508BC-1E03-49EA-9C8F-EA9E1D05D65D}\ShellFolder
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\NonEnum\{138508BC-1E03-49EA-9C8F-EA9E1D05D65D}
  • HKEY_CLASSES_ROOT\CLSID\{4336A54D-038B-4685-AB02-99BB52D3FB8B}\ShellFolder
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{4336A54D-038B-4685-AB02-99BB52D3FB8B}\ShellFolder\Attributes
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{4336A54D-038B-4685-AB02-99BB52D3FB8B}\ShellFolder\CallForAttributes
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{4336A54D-038B-4685-AB02-99BB52D3FB8B}\ShellFolder\RestrictedAttributes
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{4336A54D-038B-4685-AB02-99BB52D3FB8B}\ShellFolder\WantsFORDISPLAY
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{4336A54D-038B-4685-AB02-99BB52D3FB8B}\ShellFolder\HideFolderVerbs
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{4336A54D-038B-4685-AB02-99BB52D3FB8B}\ShellFolder\UseDropHandler
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{4336A54D-038B-4685-AB02-99BB52D3FB8B}\ShellFolder\WantsFORPARSING
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{4336A54D-038B-4685-AB02-99BB52D3FB8B}\ShellFolder\WantsParseDisplayName
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{4336A54D-038B-4685-AB02-99BB52D3FB8B}\ShellFolder\QueryForOverlay
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{4336A54D-038B-4685-AB02-99BB52D3FB8B}\ShellFolder\MapNetDriveVerbs
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{4336A54D-038B-4685-AB02-99BB52D3FB8B}\ShellFolder\QueryForInfoTip
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{4336A54D-038B-4685-AB02-99BB52D3FB8B}\ShellFolder\HideInWebView
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{4336A54D-038B-4685-AB02-99BB52D3FB8B}\ShellFolder\HideOnDesktopPerUser
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{4336A54D-038B-4685-AB02-99BB52D3FB8B}\ShellFolder\WantsAliasedNotifications
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{4336A54D-038B-4685-AB02-99BB52D3FB8B}\ShellFolder\WantsUniversalDelegate
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{4336A54D-038B-4685-AB02-99BB52D3FB8B}\ShellFolder\NoFileFolderJunction
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{4336A54D-038B-4685-AB02-99BB52D3FB8B}\ShellFolder\PinToNameSpaceTree
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{4336A54D-038B-4685-AB02-99BB52D3FB8B}\ShellFolder\HasNavigationEnum
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\CLSID\{4336A54D-038B-4685-AB02-99BB52D3FB8B}\ShellFolder
  • HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\CLSID\{4336A54D-038B-4685-AB02-99BB52D3FB8B}\ShellFolder
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\NonEnum\{4336A54D-038B-4685-AB02-99BB52D3FB8B}
  • HKEY_CLASSES_ROOT\CLSID\{450D8FBA-AD25-11D0-98A8-0800361B1103}\ShellFolder
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{450D8FBA-AD25-11D0-98A8-0800361B1103}\ShellFolder\Attributes
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{450D8FBA-AD25-11D0-98A8-0800361B1103}\ShellFolder\CallForAttributes
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{450D8FBA-AD25-11D0-98A8-0800361B1103}\ShellFolder\RestrictedAttributes
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{450D8FBA-AD25-11D0-98A8-0800361B1103}\ShellFolder\WantsFORDISPLAY
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{450D8FBA-AD25-11D0-98A8-0800361B1103}\ShellFolder\HideFolderVerbs
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{450D8FBA-AD25-11D0-98A8-0800361B1103}\ShellFolder\UseDropHandler
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{450D8FBA-AD25-11D0-98A8-0800361B1103}\ShellFolder\WantsFORPARSING
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{450D8FBA-AD25-11D0-98A8-0800361B1103}\ShellFolder\WantsParseDisplayName
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{450D8FBA-AD25-11D0-98A8-0800361B1103}\ShellFolder\QueryForOverlay
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{450D8FBA-AD25-11D0-98A8-0800361B1103}\ShellFolder\MapNetDriveVerbs
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{450D8FBA-AD25-11D0-98A8-0800361B1103}\ShellFolder\QueryForInfoTip
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{450D8FBA-AD25-11D0-98A8-0800361B1103}\ShellFolder\HideInWebView
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{450D8FBA-AD25-11D0-98A8-0800361B1103}\ShellFolder\HideOnDesktopPerUser
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{450D8FBA-AD25-11D0-98A8-0800361B1103}\ShellFolder\WantsAliasedNotifications
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{450D8FBA-AD25-11D0-98A8-0800361B1103}\ShellFolder\WantsUniversalDelegate
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{450D8FBA-AD25-11D0-98A8-0800361B1103}\ShellFolder\NoFileFolderJunction
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{450D8FBA-AD25-11D0-98A8-0800361B1103}\ShellFolder\PinToNameSpaceTree
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{450D8FBA-AD25-11D0-98A8-0800361B1103}\ShellFolder\HasNavigationEnum
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\CLSID\{450D8FBA-AD25-11D0-98A8-0800361B1103}\ShellFolder
  • HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\CLSID\{450D8FBA-AD25-11D0-98A8-0800361B1103}\ShellFolder
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\NonEnum\{450D8FBA-AD25-11D0-98A8-0800361B1103}
  • HKEY_CLASSES_ROOT\CLSID\{5399E694-6CE5-4D6C-8FCE-1D8870FDCBA0}\ShellFolder
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{5399E694-6CE5-4D6C-8FCE-1D8870FDCBA0}\ShellFolder\Attributes
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{5399E694-6CE5-4D6C-8FCE-1D8870FDCBA0}\ShellFolder\CallForAttributes
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{5399E694-6CE5-4D6C-8FCE-1D8870FDCBA0}\ShellFolder\RestrictedAttributes
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{5399E694-6CE5-4D6C-8FCE-1D8870FDCBA0}\ShellFolder\WantsFORDISPLAY
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{5399E694-6CE5-4D6C-8FCE-1D8870FDCBA0}\ShellFolder\HideFolderVerbs
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{5399E694-6CE5-4D6C-8FCE-1D8870FDCBA0}\ShellFolder\UseDropHandler
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{5399E694-6CE5-4D6C-8FCE-1D8870FDCBA0}\ShellFolder\WantsFORPARSING
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{5399E694-6CE5-4D6C-8FCE-1D8870FDCBA0}\ShellFolder\WantsParseDisplayName
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{5399E694-6CE5-4D6C-8FCE-1D8870FDCBA0}\ShellFolder\QueryForOverlay
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{5399E694-6CE5-4D6C-8FCE-1D8870FDCBA0}\ShellFolder\MapNetDriveVerbs
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{5399E694-6CE5-4D6C-8FCE-1D8870FDCBA0}\ShellFolder\QueryForInfoTip
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{5399E694-6CE5-4D6C-8FCE-1D8870FDCBA0}\ShellFolder\HideInWebView
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{5399E694-6CE5-4D6C-8FCE-1D8870FDCBA0}\ShellFolder\HideOnDesktopPerUser
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{5399E694-6CE5-4D6C-8FCE-1D8870FDCBA0}\ShellFolder\WantsAliasedNotifications
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{5399E694-6CE5-4D6C-8FCE-1D8870FDCBA0}\ShellFolder\WantsUniversalDelegate
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{5399E694-6CE5-4D6C-8FCE-1D8870FDCBA0}\ShellFolder\NoFileFolderJunction
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{5399E694-6CE5-4D6C-8FCE-1D8870FDCBA0}\ShellFolder\PinToNameSpaceTree
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{5399E694-6CE5-4D6C-8FCE-1D8870FDCBA0}\ShellFolder\HasNavigationEnum
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\CLSID\{5399E694-6CE5-4D6C-8FCE-1D8870FDCBA0}\ShellFolder
  • HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\CLSID\{5399E694-6CE5-4D6C-8FCE-1D8870FDCBA0}\ShellFolder
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\NonEnum\{5399E694-6CE5-4D6C-8FCE-1D8870FDCBA0}
  • HKEY_CLASSES_ROOT\CLSID\{89D83576-6BD1-4C86-9454-BEB04E94C819}\ShellFolder
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{89D83576-6BD1-4C86-9454-BEB04E94C819}\ShellFolder\Attributes
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{89D83576-6BD1-4C86-9454-BEB04E94C819}\ShellFolder\CallForAttributes
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{89D83576-6BD1-4C86-9454-BEB04E94C819}\ShellFolder\RestrictedAttributes
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{89D83576-6BD1-4C86-9454-BEB04E94C819}\ShellFolder\WantsFORDISPLAY
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{89D83576-6BD1-4C86-9454-BEB04E94C819}\ShellFolder\HideFolderVerbs
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{89D83576-6BD1-4C86-9454-BEB04E94C819}\ShellFolder\UseDropHandler
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{89D83576-6BD1-4C86-9454-BEB04E94C819}\ShellFolder\WantsFORPARSING
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{89D83576-6BD1-4C86-9454-BEB04E94C819}\ShellFolder\WantsParseDisplayName
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{89D83576-6BD1-4C86-9454-BEB04E94C819}\ShellFolder\QueryForOverlay
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{89D83576-6BD1-4C86-9454-BEB04E94C819}\ShellFolder\MapNetDriveVerbs
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{89D83576-6BD1-4C86-9454-BEB04E94C819}\ShellFolder\QueryForInfoTip
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{89D83576-6BD1-4C86-9454-BEB04E94C819}\ShellFolder\HideInWebView
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{89D83576-6BD1-4C86-9454-BEB04E94C819}\ShellFolder\HideOnDesktopPerUser
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{89D83576-6BD1-4C86-9454-BEB04E94C819}\ShellFolder\WantsAliasedNotifications
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{89D83576-6BD1-4C86-9454-BEB04E94C819}\ShellFolder\WantsUniversalDelegate
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{89D83576-6BD1-4C86-9454-BEB04E94C819}\ShellFolder\NoFileFolderJunction
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{89D83576-6BD1-4C86-9454-BEB04E94C819}\ShellFolder\PinToNameSpaceTree
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{89D83576-6BD1-4C86-9454-BEB04E94C819}\ShellFolder\HasNavigationEnum
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\CLSID\{89D83576-6BD1-4C86-9454-BEB04E94C819}\ShellFolder
  • HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\CLSID\{89D83576-6BD1-4C86-9454-BEB04E94C819}\ShellFolder
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\NonEnum\{89D83576-6BD1-4C86-9454-BEB04E94C819}
  • HKEY_CLASSES_ROOT\CLSID\{9343812E-1C37-4A49-A12E-4B2D810D956B}\ShellFolder
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{9343812E-1C37-4A49-A12E-4B2D810D956B}\ShellFolder\Attributes
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{9343812E-1C37-4A49-A12E-4B2D810D956B}\ShellFolder\CallForAttributes
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{9343812E-1C37-4A49-A12E-4B2D810D956B}\ShellFolder\RestrictedAttributes
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{9343812E-1C37-4A49-A12E-4B2D810D956B}\ShellFolder\WantsFORDISPLAY
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{9343812E-1C37-4A49-A12E-4B2D810D956B}\ShellFolder\HideFolderVerbs
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{9343812E-1C37-4A49-A12E-4B2D810D956B}\ShellFolder\UseDropHandler
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{9343812E-1C37-4A49-A12E-4B2D810D956B}\ShellFolder\WantsFORPARSING
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{9343812E-1C37-4A49-A12E-4B2D810D956B}\ShellFolder\WantsParseDisplayName
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{9343812E-1C37-4A49-A12E-4B2D810D956B}\ShellFolder\QueryForOverlay
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{9343812E-1C37-4A49-A12E-4B2D810D956B}\ShellFolder\MapNetDriveVerbs
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{9343812E-1C37-4A49-A12E-4B2D810D956B}\ShellFolder\QueryForInfoTip
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{9343812E-1C37-4A49-A12E-4B2D810D956B}\ShellFolder\HideInWebView
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{9343812E-1C37-4A49-A12E-4B2D810D956B}\ShellFolder\HideOnDesktopPerUser
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{9343812E-1C37-4A49-A12E-4B2D810D956B}\ShellFolder\WantsAliasedNotifications
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{9343812E-1C37-4A49-A12E-4B2D810D956B}\ShellFolder\WantsUniversalDelegate
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{9343812E-1C37-4A49-A12E-4B2D810D956B}\ShellFolder\NoFileFolderJunction
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{9343812E-1C37-4A49-A12E-4B2D810D956B}\ShellFolder\PinToNameSpaceTree
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{9343812E-1C37-4A49-A12E-4B2D810D956B}\ShellFolder\HasNavigationEnum
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\CLSID\{9343812E-1C37-4A49-A12E-4B2D810D956B}\ShellFolder
  • HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\CLSID\{9343812E-1C37-4A49-A12E-4B2D810D956B}\ShellFolder
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\NonEnum\{9343812E-1C37-4A49-A12E-4B2D810D956B}
  • HKEY_CLASSES_ROOT\CLSID\{B0FBD52D-C4A7-4A19-985D-11309D1AC8AE}\ShellFolder
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{B0FBD52D-C4A7-4A19-985D-11309D1AC8AE}\ShellFolder\Attributes
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{B0FBD52D-C4A7-4A19-985D-11309D1AC8AE}\ShellFolder\CallForAttributes
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{B0FBD52D-C4A7-4A19-985D-11309D1AC8AE}\ShellFolder\RestrictedAttributes
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{B0FBD52D-C4A7-4A19-985D-11309D1AC8AE}\ShellFolder\WantsFORDISPLAY
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{B0FBD52D-C4A7-4A19-985D-11309D1AC8AE}\ShellFolder\HideFolderVerbs
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{B0FBD52D-C4A7-4A19-985D-11309D1AC8AE}\ShellFolder\UseDropHandler
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{B0FBD52D-C4A7-4A19-985D-11309D1AC8AE}\ShellFolder\WantsFORPARSING
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{B0FBD52D-C4A7-4A19-985D-11309D1AC8AE}\ShellFolder\WantsParseDisplayName
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{B0FBD52D-C4A7-4A19-985D-11309D1AC8AE}\ShellFolder\QueryForOverlay
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{B0FBD52D-C4A7-4A19-985D-11309D1AC8AE}\ShellFolder\MapNetDriveVerbs
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{B0FBD52D-C4A7-4A19-985D-11309D1AC8AE}\ShellFolder\QueryForInfoTip
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{B0FBD52D-C4A7-4A19-985D-11309D1AC8AE}\ShellFolder\HideInWebView
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{B0FBD52D-C4A7-4A19-985D-11309D1AC8AE}\ShellFolder\HideOnDesktopPerUser
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{B0FBD52D-C4A7-4A19-985D-11309D1AC8AE}\ShellFolder\WantsAliasedNotifications
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{B0FBD52D-C4A7-4A19-985D-11309D1AC8AE}\ShellFolder\WantsUniversalDelegate
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{B0FBD52D-C4A7-4A19-985D-11309D1AC8AE}\ShellFolder\NoFileFolderJunction
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{B0FBD52D-C4A7-4A19-985D-11309D1AC8AE}\ShellFolder\PinToNameSpaceTree
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{B0FBD52D-C4A7-4A19-985D-11309D1AC8AE}\ShellFolder\HasNavigationEnum
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\CLSID\{B0FBD52D-C4A7-4A19-985D-11309D1AC8AE}\ShellFolder
  • HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\CLSID\{B0FBD52D-C4A7-4A19-985D-11309D1AC8AE}\ShellFolder
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\NonEnum\{B0FBD52D-C4A7-4A19-985D-11309D1AC8AE}
  • HKEY_CLASSES_ROOT\CLSID\{B4FB3F98-C1EA-428D-A78A-D1F5659CBA93}\ShellFolder
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{B4FB3F98-C1EA-428D-A78A-D1F5659CBA93}\ShellFolder\Attributes
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{B4FB3F98-C1EA-428D-A78A-D1F5659CBA93}\ShellFolder\CallForAttributes
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{B4FB3F98-C1EA-428D-A78A-D1F5659CBA93}\ShellFolder\RestrictedAttributes
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{B4FB3F98-C1EA-428D-A78A-D1F5659CBA93}\ShellFolder\WantsFORDISPLAY
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{B4FB3F98-C1EA-428D-A78A-D1F5659CBA93}\ShellFolder\HideFolderVerbs
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{B4FB3F98-C1EA-428D-A78A-D1F5659CBA93}\ShellFolder\UseDropHandler
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{B4FB3F98-C1EA-428D-A78A-D1F5659CBA93}\ShellFolder\WantsFORPARSING
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{B4FB3F98-C1EA-428D-A78A-D1F5659CBA93}\ShellFolder\WantsParseDisplayName
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{B4FB3F98-C1EA-428D-A78A-D1F5659CBA93}\ShellFolder\QueryForOverlay
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{B4FB3F98-C1EA-428D-A78A-D1F5659CBA93}\ShellFolder\MapNetDriveVerbs
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{B4FB3F98-C1EA-428D-A78A-D1F5659CBA93}\ShellFolder\QueryForInfoTip
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{B4FB3F98-C1EA-428D-A78A-D1F5659CBA93}\ShellFolder\HideInWebView
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{B4FB3F98-C1EA-428D-A78A-D1F5659CBA93}\ShellFolder\HideOnDesktopPerUser
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{B4FB3F98-C1EA-428D-A78A-D1F5659CBA93}\ShellFolder\WantsAliasedNotifications
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{B4FB3F98-C1EA-428D-A78A-D1F5659CBA93}\ShellFolder\WantsUniversalDelegate
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{B4FB3F98-C1EA-428D-A78A-D1F5659CBA93}\ShellFolder\NoFileFolderJunction
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{B4FB3F98-C1EA-428D-A78A-D1F5659CBA93}\ShellFolder\PinToNameSpaceTree
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{B4FB3F98-C1EA-428D-A78A-D1F5659CBA93}\ShellFolder\HasNavigationEnum
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\CLSID\{B4FB3F98-C1EA-428D-A78A-D1F5659CBA93}\ShellFolder
  • HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\CLSID\{B4FB3F98-C1EA-428D-A78A-D1F5659CBA93}\ShellFolder
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\NonEnum\{B4FB3F98-C1EA-428D-A78A-D1F5659CBA93}
  • HKEY_CLASSES_ROOT\CLSID\{BD7A2E7B-21CB-41B2-A086-B309680C6B7E}\ShellFolder
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{BD7A2E7B-21CB-41B2-A086-B309680C6B7E}\ShellFolder\Attributes
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{BD7A2E7B-21CB-41B2-A086-B309680C6B7E}\ShellFolder\CallForAttributes
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{BD7A2E7B-21CB-41B2-A086-B309680C6B7E}\ShellFolder\RestrictedAttributes
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{BD7A2E7B-21CB-41B2-A086-B309680C6B7E}\ShellFolder\WantsFORDISPLAY
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{BD7A2E7B-21CB-41B2-A086-B309680C6B7E}\ShellFolder\HideFolderVerbs
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{BD7A2E7B-21CB-41B2-A086-B309680C6B7E}\ShellFolder\UseDropHandler
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{BD7A2E7B-21CB-41B2-A086-B309680C6B7E}\ShellFolder\WantsFORPARSING
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{BD7A2E7B-21CB-41B2-A086-B309680C6B7E}\ShellFolder\WantsParseDisplayName
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{BD7A2E7B-21CB-41B2-A086-B309680C6B7E}\ShellFolder\QueryForOverlay
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{BD7A2E7B-21CB-41B2-A086-B309680C6B7E}\ShellFolder\MapNetDriveVerbs
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{BD7A2E7B-21CB-41B2-A086-B309680C6B7E}\ShellFolder\QueryForInfoTip
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{BD7A2E7B-21CB-41B2-A086-B309680C6B7E}\ShellFolder\HideInWebView
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{BD7A2E7B-21CB-41B2-A086-B309680C6B7E}\ShellFolder\HideOnDesktopPerUser
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{BD7A2E7B-21CB-41B2-A086-B309680C6B7E}\ShellFolder\WantsAliasedNotifications
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{BD7A2E7B-21CB-41B2-A086-B309680C6B7E}\ShellFolder\WantsUniversalDelegate
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{BD7A2E7B-21CB-41B2-A086-B309680C6B7E}\ShellFolder\NoFileFolderJunction
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{BD7A2E7B-21CB-41B2-A086-B309680C6B7E}\ShellFolder\PinToNameSpaceTree
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{BD7A2E7B-21CB-41B2-A086-B309680C6B7E}\ShellFolder\HasNavigationEnum
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\CLSID\{BD7A2E7B-21CB-41B2-A086-B309680C6B7E}\ShellFolder
  • HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\CLSID\{BD7A2E7B-21CB-41B2-A086-B309680C6B7E}\ShellFolder
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\NonEnum\{BD7A2E7B-21CB-41B2-A086-B309680C6B7E}
  • HKEY_CLASSES_ROOT\CLSID\{DAF95313-E44D-46AF-BE1B-CBACEA2C3065}\ShellFolder
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{DAF95313-E44D-46AF-BE1B-CBACEA2C3065}\ShellFolder\Attributes
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{DAF95313-E44D-46AF-BE1B-CBACEA2C3065}\ShellFolder\CallForAttributes
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{DAF95313-E44D-46AF-BE1B-CBACEA2C3065}\ShellFolder\RestrictedAttributes
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{DAF95313-E44D-46AF-BE1B-CBACEA2C3065}\ShellFolder\WantsFORDISPLAY
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{DAF95313-E44D-46AF-BE1B-CBACEA2C3065}\ShellFolder\HideFolderVerbs
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{DAF95313-E44D-46AF-BE1B-CBACEA2C3065}\ShellFolder\UseDropHandler
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{DAF95313-E44D-46AF-BE1B-CBACEA2C3065}\ShellFolder\WantsFORPARSING
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{DAF95313-E44D-46AF-BE1B-CBACEA2C3065}\ShellFolder\WantsParseDisplayName
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{DAF95313-E44D-46AF-BE1B-CBACEA2C3065}\ShellFolder\QueryForOverlay
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{DAF95313-E44D-46AF-BE1B-CBACEA2C3065}\ShellFolder\MapNetDriveVerbs
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{DAF95313-E44D-46AF-BE1B-CBACEA2C3065}\ShellFolder\QueryForInfoTip
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{DAF95313-E44D-46AF-BE1B-CBACEA2C3065}\ShellFolder\HideInWebView
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{DAF95313-E44D-46AF-BE1B-CBACEA2C3065}\ShellFolder\HideOnDesktopPerUser
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{DAF95313-E44D-46AF-BE1B-CBACEA2C3065}\ShellFolder\WantsAliasedNotifications
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{DAF95313-E44D-46AF-BE1B-CBACEA2C3065}\ShellFolder\WantsUniversalDelegate
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{DAF95313-E44D-46AF-BE1B-CBACEA2C3065}\ShellFolder\NoFileFolderJunction
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{DAF95313-E44D-46AF-BE1B-CBACEA2C3065}\ShellFolder\PinToNameSpaceTree
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{DAF95313-E44D-46AF-BE1B-CBACEA2C3065}\ShellFolder\HasNavigationEnum
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\CLSID\{DAF95313-E44D-46AF-BE1B-CBACEA2C3065}\ShellFolder
  • HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\CLSID\{DAF95313-E44D-46AF-BE1B-CBACEA2C3065}\ShellFolder
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\NonEnum\{DAF95313-E44D-46AF-BE1B-CBACEA2C3065}
  • HKEY_CLASSES_ROOT\CLSID\{E345F35F-9397-435C-8F95-4E922C26259E}\ShellFolder
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{E345F35F-9397-435C-8F95-4E922C26259E}\ShellFolder\Attributes
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{E345F35F-9397-435C-8F95-4E922C26259E}\ShellFolder\CallForAttributes
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{E345F35F-9397-435C-8F95-4E922C26259E}\ShellFolder\RestrictedAttributes
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{E345F35F-9397-435C-8F95-4E922C26259E}\ShellFolder\WantsFORDISPLAY
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{E345F35F-9397-435C-8F95-4E922C26259E}\ShellFolder\HideFolderVerbs
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{E345F35F-9397-435C-8F95-4E922C26259E}\ShellFolder\UseDropHandler
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{E345F35F-9397-435C-8F95-4E922C26259E}\ShellFolder\WantsFORPARSING
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{E345F35F-9397-435C-8F95-4E922C26259E}\ShellFolder\WantsParseDisplayName
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{E345F35F-9397-435C-8F95-4E922C26259E}\ShellFolder\QueryForOverlay
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{E345F35F-9397-435C-8F95-4E922C26259E}\ShellFolder\MapNetDriveVerbs
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{E345F35F-9397-435C-8F95-4E922C26259E}\ShellFolder\QueryForInfoTip
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{E345F35F-9397-435C-8F95-4E922C26259E}\ShellFolder\HideInWebView
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{E345F35F-9397-435C-8F95-4E922C26259E}\ShellFolder\HideOnDesktopPerUser
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{E345F35F-9397-435C-8F95-4E922C26259E}\ShellFolder\WantsAliasedNotifications
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{E345F35F-9397-435C-8F95-4E922C26259E}\ShellFolder\WantsUniversalDelegate
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{E345F35F-9397-435C-8F95-4E922C26259E}\ShellFolder\NoFileFolderJunction
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{E345F35F-9397-435C-8F95-4E922C26259E}\ShellFolder\PinToNameSpaceTree
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{E345F35F-9397-435C-8F95-4E922C26259E}\ShellFolder\HasNavigationEnum
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\CLSID\{E345F35F-9397-435C-8F95-4E922C26259E}\ShellFolder
  • HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\CLSID\{E345F35F-9397-435C-8F95-4E922C26259E}\ShellFolder
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\NonEnum\{E345F35F-9397-435C-8F95-4E922C26259E}
  • HKEY_CLASSES_ROOT\CLSID\{ED228FDF-9EA8-4870-83B1-96B02CFE0D52}\ShellFolder
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{ED228FDF-9EA8-4870-83B1-96B02CFE0D52}\ShellFolder\Attributes
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{ED228FDF-9EA8-4870-83B1-96B02CFE0D52}\ShellFolder\CallForAttributes
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{ED228FDF-9EA8-4870-83B1-96B02CFE0D52}\ShellFolder\RestrictedAttributes
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{ED228FDF-9EA8-4870-83B1-96B02CFE0D52}\ShellFolder\WantsFORDISPLAY
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{ED228FDF-9EA8-4870-83B1-96B02CFE0D52}\ShellFolder\HideFolderVerbs
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{ED228FDF-9EA8-4870-83B1-96B02CFE0D52}\ShellFolder\UseDropHandler
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{ED228FDF-9EA8-4870-83B1-96B02CFE0D52}\ShellFolder\WantsFORPARSING
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{ED228FDF-9EA8-4870-83B1-96B02CFE0D52}\ShellFolder\WantsParseDisplayName
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{ED228FDF-9EA8-4870-83B1-96B02CFE0D52}\ShellFolder\QueryForOverlay
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{ED228FDF-9EA8-4870-83B1-96B02CFE0D52}\ShellFolder\MapNetDriveVerbs
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{ED228FDF-9EA8-4870-83B1-96B02CFE0D52}\ShellFolder\QueryForInfoTip
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{ED228FDF-9EA8-4870-83B1-96B02CFE0D52}\ShellFolder\HideInWebView
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{ED228FDF-9EA8-4870-83B1-96B02CFE0D52}\ShellFolder\HideOnDesktopPerUser
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{ED228FDF-9EA8-4870-83B1-96B02CFE0D52}\ShellFolder\WantsAliasedNotifications
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{ED228FDF-9EA8-4870-83B1-96B02CFE0D52}\ShellFolder\WantsUniversalDelegate
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{ED228FDF-9EA8-4870-83B1-96B02CFE0D52}\ShellFolder\NoFileFolderJunction
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{ED228FDF-9EA8-4870-83B1-96B02CFE0D52}\ShellFolder\PinToNameSpaceTree
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{ED228FDF-9EA8-4870-83B1-96B02CFE0D52}\ShellFolder\HasNavigationEnum
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\CLSID\{ED228FDF-9EA8-4870-83B1-96B02CFE0D52}\ShellFolder
  • HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\CLSID\{ED228FDF-9EA8-4870-83B1-96B02CFE0D52}\ShellFolder
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\NonEnum\{ED228FDF-9EA8-4870-83B1-96B02CFE0D52}
  • HKEY_CLASSES_ROOT\CLSID\{F02C1A0D-BE21-4350-88B0-7367FC96EF3C}\ShellFolder
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{F02C1A0D-BE21-4350-88B0-7367FC96EF3C}\ShellFolder\Attributes
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{F02C1A0D-BE21-4350-88B0-7367FC96EF3C}\ShellFolder\CallForAttributes
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{F02C1A0D-BE21-4350-88B0-7367FC96EF3C}\ShellFolder\RestrictedAttributes
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{F02C1A0D-BE21-4350-88B0-7367FC96EF3C}\ShellFolder\WantsFORDISPLAY
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{F02C1A0D-BE21-4350-88B0-7367FC96EF3C}\ShellFolder\HideFolderVerbs
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{F02C1A0D-BE21-4350-88B0-7367FC96EF3C}\ShellFolder\UseDropHandler
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{F02C1A0D-BE21-4350-88B0-7367FC96EF3C}\ShellFolder\WantsFORPARSING
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{F02C1A0D-BE21-4350-88B0-7367FC96EF3C}\ShellFolder\WantsParseDisplayName
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{F02C1A0D-BE21-4350-88B0-7367FC96EF3C}\ShellFolder\QueryForOverlay
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{F02C1A0D-BE21-4350-88B0-7367FC96EF3C}\ShellFolder\MapNetDriveVerbs
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{F02C1A0D-BE21-4350-88B0-7367FC96EF3C}\ShellFolder\QueryForInfoTip
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{F02C1A0D-BE21-4350-88B0-7367FC96EF3C}\ShellFolder\HideInWebView
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{F02C1A0D-BE21-4350-88B0-7367FC96EF3C}\ShellFolder\HideOnDesktopPerUser
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{F02C1A0D-BE21-4350-88B0-7367FC96EF3C}\ShellFolder\WantsAliasedNotifications
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{F02C1A0D-BE21-4350-88B0-7367FC96EF3C}\ShellFolder\WantsUniversalDelegate
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{F02C1A0D-BE21-4350-88B0-7367FC96EF3C}\ShellFolder\NoFileFolderJunction
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{F02C1A0D-BE21-4350-88B0-7367FC96EF3C}\ShellFolder\PinToNameSpaceTree
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{F02C1A0D-BE21-4350-88B0-7367FC96EF3C}\ShellFolder\HasNavigationEnum
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\CLSID\{F02C1A0D-BE21-4350-88B0-7367FC96EF3C}\ShellFolder
  • HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\CLSID\{F02C1A0D-BE21-4350-88B0-7367FC96EF3C}\ShellFolder
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\NonEnum\{F02C1A0D-BE21-4350-88B0-7367FC96EF3C}
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\App Paths\taskkill.exe
  • HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\App Paths\taskkill.exe
  • HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\AllowFileCLSIDJunctions
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\AllowFileCLSIDJunctions
  • HKEY_CLASSES_ROOT\.exe
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\.exe\(Default)
  • HKEY_CLASSES_ROOT\.exe\OpenWithProgids
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.exe\OpenWithProgids
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.exe
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.exe\
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.exe\UserChoice
  • HKEY_CLASSES_ROOT\exefile
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\exefile\CurVer
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\exefile\
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\exefile\ShellEx\IconHandler
  • HKEY_CLASSES_ROOT\SystemFileAssociations\.exe
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\SystemFileAssociations\.exe\ShellEx\IconHandler
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\exefile\DocObject
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\SystemFileAssociations\.exe\DocObject
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\exefile\BrowseInPlace
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\SystemFileAssociations\.exe\BrowseInPlace
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\.exe\Content Type
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\exefile\Clsid
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\SystemFileAssociations\.exe\Clsid
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\exefile\IsShortcut
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\SystemFileAssociations\.exe\IsShortcut
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\exefile\AlwaysShowExt
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\SystemFileAssociations\.exe\AlwaysShowExt
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\exefile\NeverShowExt
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\SystemFileAssociations\.exe\NeverShowExt
  • HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\KindMap
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\KindMap\.exe
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\exefile\shell\open
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\exefile\shell\open\
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\exefile\shell\open\command
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\exefile\shell\open\command\DelegateExecute
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\exefile\shell\open\DropTarget
  • HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\Associations
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Associations
  • HKEY_CLASSES_ROOT\.ade
  • HKEY_CLASSES_ROOT\.adp
  • HKEY_CLASSES_ROOT\.app
  • HKEY_CLASSES_ROOT\.asp
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\.asp\(Default)
  • HKEY_CLASSES_ROOT\.bas
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\.bas\(Default)
  • HKEY_CLASSES_ROOT\.bat
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\.bat\(Default)
  • HKEY_CLASSES_ROOT\.cer
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\.cer\(Default)
  • HKEY_CLASSES_ROOT\.chm
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\.chm\(Default)
  • HKEY_CLASSES_ROOT\.cmd
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\.cmd\(Default)
  • HKEY_CLASSES_ROOT\.com
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\.com\(Default)
  • HKEY_CLASSES_ROOT\.cpl
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\.cpl\(Default)
  • HKEY_CLASSES_ROOT\.crt
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\.crt\(Default)
  • HKEY_CLASSES_ROOT\.csh
  • HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_INITIALIZE_URLACTION_SHELLEXECUTE_TO_ALLOW_KB936610
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\MAIN\FeatureControl\FEATURE_INITIALIZE_URLACTION_SHELLEXECUTE_TO_ALLOW_KB936610
  • HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Internet Explorer
  • HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Internet Explorer\Security
  • HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Internet Explorer\Security\DisableSecuritySettingsCheck
  • HKEY_LOCAL_MACHINE\System\Setup
  • HKEY_LOCAL_MACHINE\SYSTEM\Setup\SystemSetupInProgress
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\0
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\1
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\2
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\3
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\4
  • HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\
  • HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\
  • HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\0
  • HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\0
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\0\Flags
  • HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\1
  • HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\1
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\1\Flags
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\ProxyBypass
  • HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\ProxyBypass
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\IntranetName
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\IntranetName
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\UNCAsIntranet
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\AutoDetect
  • HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\2
  • HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\2
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\2\Flags
  • HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\3
  • HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\3
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\3\Flags
  • HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\4
  • HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\4
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\4\Flags
  • HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_LOCALMACHINE_LOCKDOWN
  • HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_LOCALMACHINE_LOCKDOWN\MasterZ_Custom_93.exe
  • HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_LOCALMACHINE_LOCKDOWN\*
  • HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_LOCALMACHINE_LOCKDOWN
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\MAIN\FeatureControl\FEATURE_LOCALMACHINE_LOCKDOWN\MasterZ_Custom_93.exe
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\MAIN\FeatureControl\FEATURE_LOCALMACHINE_LOCKDOWN\*
  • HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Lockdown_Zones\
  • HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Lockdown_Zones\
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Lockdown_Zones\
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Lockdown_Zones\0
  • HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Lockdown_Zones\0
  • HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Lockdown_Zones\0
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Lockdown_Zones\1
  • HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Lockdown_Zones\1
  • HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Lockdown_Zones\1
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Lockdown_Zones\2
  • HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Lockdown_Zones\2
  • HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Lockdown_Zones\2
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Lockdown_Zones\3
  • HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Lockdown_Zones\3
  • HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Lockdown_Zones\3
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Lockdown_Zones\4
  • HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Lockdown_Zones\4
  • HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Lockdown_Zones\4
  • HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_ZONES_DEFAULT_DRIVE_INTRANET_KB941000
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\MAIN\FeatureControl\FEATURE_ZONES_DEFAULT_DRIVE_INTRANET_KB941000
  • HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\SpecialFoldersCacheSize
  • HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\SpecialFoldersCacheSize
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\SpecialFoldersCacheSize
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Internet Settings\SpecialFoldersCacheSize
  • HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_PROTOCOL_LOCKDOWN
  • HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_PROTOCOL_LOCKDOWN
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\MAIN\FeatureControl\FEATURE_PROTOCOL_LOCKDOWN\MasterZ_Custom_93.exe
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\MAIN\FeatureControl\FEATURE_PROTOCOL_LOCKDOWN\*
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\0\1806
  • HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\0
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\0\1806
  • HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers
  • HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\safer\codeidentifiers\TransparentEnabled
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\exefile\shell\open\command\command
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\exefile\shell\open\command\(Default)
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\exefile\Progid
  • HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellCompatibility\ProgIDs\exefile
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\InheritConsoleHandles
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\InheritConsoleHandles
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\exefile\shell\open\ddeexec
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\RestrictRun
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\RestrictRun
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\DisallowRun
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\DisallowRun
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\exefile\shell\open\SetWorkingDirectoryFromTarget
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\exefile\shell\open\NoWorkingDirectory
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\DllNXOptions\FindProcDLL.dll
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\DllNXOptions\nsExec.dll
  • HKEY_CURRENT_USER\Software\suminfo\BizExpressQY2.0\Setups\00000000
  • HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Session Manager
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\SESSION MANAGER\PendingFileRenameOperations
  • HKEY_CURRENT_USER\Software\suminfo\BizExpressQY2.0
  • HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Uninstall\
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\7-Zip
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\AddressBook
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\Adobe Flash Player ActiveX
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\Adobe Flash Player NPAPI
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\Alipay security control_is1
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\Alipay security plugin_is1
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\Connection Manager
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\DirectDrawEx
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\Fontcore
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\IE40
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\IE4Data
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\IE5BAKEX
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\IEData
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\MobileOptionPack
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\Mozilla Firefox 10.0.9 (x86 zh-CN)
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\Office14.PROPLUS
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\SchedulingAgent
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\WIC
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\WinAce Archiver
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\WinRAR archiver
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\winscp3_is1
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{1b103cea-f037-4504-81de-956057b442c3}
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{26A24AE4-039D-4CA4-87B4-2F32180121F0}
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{4A03706F-666A-4037-7777-5F2748764D10}
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{6c6356fe-cbfa-4944-9bed-a9e99f45cb7a}
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{90140000-0011-0000-0000-0000000FF1CE}
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{90140000-0015-0804-0000-0000000FF1CE}
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{90140000-0016-0804-0000-0000000FF1CE}
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{90140000-0018-0804-0000-0000000FF1CE}
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{90140000-0019-0804-0000-0000000FF1CE}
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{90140000-001A-0804-0000-0000000FF1CE}
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{90140000-001B-0804-0000-0000000FF1CE}
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{90140000-001F-0409-0000-0000000FF1CE}
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{90140000-001F-0804-0000-0000000FF1CE}
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{90140000-0028-0804-0000-0000000FF1CE}
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{90140000-002C-0804-0000-0000000FF1CE}
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{90140000-0044-0804-0000-0000000FF1CE}
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{90140000-006E-0804-0000-0000000FF1CE}
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{90140000-00A1-0804-0000-0000000FF1CE}
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{90140000-00BA-0804-0000-0000000FF1CE}
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{9bd48a22-fe5a-457c-8f10-da6c2be89eee}
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{AC76BA86-7AD7-2052-7B44-AB0000000001}
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{AC76BA86-7AD7-2530-0000-A00000000049}
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{D93BD08F-2C69-4FD6-8538-09B6597ADA8C}
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{E2B51919-207A-43EB-AE78-733F9C6797C2}
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\MAIN\FeatureControl\FEATURE_BROWSER_EMULATION
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\MAIN\FeatureControl\FEATURE_BROWSER_EMULATION\Sumengine2.exe
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\MAIN\FeatureControl\FEATURE_BROWSER_EMULATION\webMcProc.exe
  • HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\MasterZ
  • HKEY_CURRENT_USER\Software\szw\MasterZ\Setup
  • HKEY_CLASSES_ROOT\Drive\shellex\FolderExtensions
  • HKEY_CLASSES_ROOT\Drive\shellex\FolderExtensions\{fbeb8a05-beee-4442-804e-409d6c4515e9}
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Drive\shellex\FolderExtensions\{fbeb8a05-beee-4442-804e-409d6c4515e9}\DriveMask
  • HKEY_CURRENT_USER\Control Panel\International
  • HKEY_CURRENT_USER\Control Panel\International\sCountry
  • HKEY_CURRENT_USER\Control Panel\International\Locale
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\SessionInfo\1\KnownFolders
  • HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\User Shell Folders\Common Desktop
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\User Shell Folders\Common Documents
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\User Shell Folders\CommonPictures
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\User Shell Folders\CommonMusic
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\User Shell Folders\CommonVideo
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders\{DE92C1C7-837F-4F69-A3BB-86E631204A23}
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders\My Music
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\User Shell Folders\{3D644C9B-1FB8-4F30-9B45-F670235F79C0}
  • HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\ProfileList
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ProfileList\ProfilesDirectory
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders\Startup
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\User Shell Folders\Common Startup
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ProfileList\Public
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\User Shell Folders\Common Programs
  • HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\ProgramFilesDir
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\CommonFilesDir
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders\{52A4F021-7B75-48A9-9F6B-4B87A210BC8F}
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders\AppData
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\App Paths\MasterZ_Custom_93.exe
  • HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\App Paths\MasterZ_Custom_93.exe
  • HKEY_CURRENT_USER\Software\szw\MasterZ
  • HKEY_CURRENT_USER\Software\szw\MasterZ\StationLastupdateTime
  • HKEY_CURRENT_USER\Software\szw\MasterZ\Setup\AxLog
  • HKEY_CURRENT_USER\Software\szw\MasterZ\Setup\AxLogFile
  • HKEY_CURRENT_USER\Software\szw\MasterZ\Setup\Client
  • HKEY_CURRENT_USER\Software\szw\MasterZ\Setup\DownLoad Path
  • HKEY_CURRENT_USER\Software\szw\MasterZ\Setup\Install Path
  • HKEY_CURRENT_USER\Software\szw\MasterZ\Setup\MCProc
  • HKEY_CURRENT_USER\Software\szw\MasterZ\Setup\KWproc
  • HKEY_CURRENT_USER\Software\szw\MasterZ\Setup\registerfileTime
  • HKEY_CURRENT_USER\Software\szw\MasterZ\Setup\version
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\16898.cc
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\16898.cc\http
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\sumszw.com\www
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\sumszw.com\www\http
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\MAIN\FeatureControl\FEATURE_BROWSER_EMULATION\Engine.exe
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\MAIN\FeatureControl\FEATURE_BROWSER_EMULATION\MC.exe
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run\MasterZ
  • HKEY_CURRENT_USER\Software\MozillaPlugins\sumszw.com/szwplugin
  • HKEY_CURRENT_USER\Software\MozillaPlugins\sumszw.com/szwplugin\Path
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\\xe6\xa0\x87\xe5\x87\x86\xe4\xbb\xb6\DisplayName
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\\xe6\xa0\x87\xe5\x87\x86\xe4\xbb\xb6\UninstallString
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\\xe6\xa0\x87\xe5\x87\x86\xe4\xbb\xb6\DisplayIcon
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\\xe6\xa0\x87\xe5\x87\x86\xe4\xbb\xb6\URLInfoAbout
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\\xe6\xa0\x87\xe5\x87\x86\xe4\xbb\xb6\Publisher
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\DllNXOptions\InstallOptions.dll
  • HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\Windows Error Reporting\WMR
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\Windows Error Reporting\WMR\Disable
  • HKEY_CURRENT_USER\Software\Classes
  • HKEY_CURRENT_USER\Software\Classes\AppID\taskkill.exe
  • HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\Tcpip\Parameters
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\Hostname
  • HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\System\DNSclient
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\Domain
  • HKEY_CURRENT_USER\Software\Classes\Interface\{D4781CD6-E5D3-44DF-AD94-930EFE48A887}
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{D4781CD6-E5D3-44DF-AD94-930EFE48A887}\ProxyStubClsid32
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{D4781CD6-E5D3-44DF-AD94-930EFE48A887}\ProxyStubClsid32\(Default)
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\zh-Hans
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\ExtendedLocale\zh-Hans
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\zh
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\ExtendedLocale\zh
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\en
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\ExtendedLocale\en
  • HKEY_CURRENT_USER\Software\Classes\Interface\{9556DC99-828C-11CF-A37E-00AA003240C7}
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{9556DC99-828C-11CF-A37E-00AA003240C7}\ProxyStubClsid32
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{9556DC99-828C-11CF-A37E-00AA003240C7}\ProxyStubClsid32\(Default)
  • HKEY_CURRENT_USER\Software\Classes\CLSID\{D68AF00A-29CB-43FA-8504-CE99A996D9EA}
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D68AF00A-29CB-43FA-8504-CE99A996D9EA}\TreatAs
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D68AF00A-29CB-43FA-8504-CE99A996D9EA}\Progid
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{D68AF00A-29CB-43FA-8504-CE99A996D9EA}\Progid
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D68AF00A-29CB-43FA-8504-CE99A996D9EA}\(Default)
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D68AF00A-29CB-43FA-8504-CE99A996D9EA}\InprocServer32
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D68AF00A-29CB-43FA-8504-CE99A996D9EA}\InprocServer32\InprocServer32
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D68AF00A-29CB-43FA-8504-CE99A996D9EA}\InprocServer32\(Default)
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D68AF00A-29CB-43FA-8504-CE99A996D9EA}\InprocServer32\ThreadingModel
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D68AF00A-29CB-43FA-8504-CE99A996D9EA}\InprocHandler32
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D68AF00A-29CB-43FA-8504-CE99A996D9EA}\InprocHandler
  • HKEY_CURRENT_USER\Software\Classes\Interface\{027947E1-D731-11CE-A357-000000000001}
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{027947E1-D731-11CE-A357-000000000001}\ProxyStubClsid32
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{027947E1-D731-11CE-A357-000000000001}\ProxyStubClsid32\(Default)
  • HKEY_CURRENT_USER\Software\Classes\CLSID\{1B1CAD8C-2DAB-11D2-B604-00104B703EFD}
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{1B1CAD8C-2DAB-11D2-B604-00104B703EFD}\TreatAs
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{1B1CAD8C-2DAB-11D2-B604-00104B703EFD}\Progid
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{1B1CAD8C-2DAB-11D2-B604-00104B703EFD}\Progid
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{1B1CAD8C-2DAB-11D2-B604-00104B703EFD}\(Default)
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{1B1CAD8C-2DAB-11D2-B604-00104B703EFD}\InprocServer32
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{1B1CAD8C-2DAB-11D2-B604-00104B703EFD}\InprocServer32\InprocServer32
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{1B1CAD8C-2DAB-11D2-B604-00104B703EFD}\InprocServer32\(Default)
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{1B1CAD8C-2DAB-11D2-B604-00104B703EFD}\InprocServer32\ThreadingModel
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{1B1CAD8C-2DAB-11D2-B604-00104B703EFD}\InprocHandler32
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{1B1CAD8C-2DAB-11D2-B604-00104B703EFD}\InprocHandler
  • HKEY_CURRENT_USER\Software\Classes\Interface\{1C1C45EE-4395-11D2-B60B-00104B703EFD}
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{1C1C45EE-4395-11D2-B60B-00104B703EFD}\ProxyStubClsid32
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{1C1C45EE-4395-11D2-B60B-00104B703EFD}\ProxyStubClsid32\(Default)
  • HKEY_CURRENT_USER\Software\Classes\Interface\{423EC01E-2E35-11D2-B604-00104B703EFD}
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{423EC01E-2E35-11D2-B604-00104B703EFD}\ProxyStubClsid32
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{423EC01E-2E35-11D2-B604-00104B703EFD}\ProxyStubClsid32\(Default)
  • HKEY_LOCAL_MACHINE\Software\Microsoft\WBEM\CIMOM
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\WBEM\CIMOM\EnableObjectValidation
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\CIMOM
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\WBEM\CIMOM\Logging
  • HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\GRE_Initialize
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\GRE_Initialize\DisableMetaFiles
  • HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\System
  • HKEY_LOCAL_MACHINE\Software\Microsoft\Command Processor
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Command Processor\DisableUNCCheck
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Command Processor\EnableExtensions
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Command Processor\DelayedExpansion
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Command Processor\DefaultColor
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Command Processor\CompletionChar
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Command Processor\PathCompletionChar
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Command Processor\AutoRun
  • HKEY_CURRENT_USER\Software\Microsoft\Command Processor
  • HKEY_CURRENT_USER\Software\Microsoft\Command Processor\DisableUNCCheck
  • HKEY_CURRENT_USER\Software\Microsoft\Command Processor\EnableExtensions
  • HKEY_CURRENT_USER\Software\Microsoft\Command Processor\DelayedExpansion
  • HKEY_CURRENT_USER\Software\Microsoft\Command Processor\DefaultColor
  • HKEY_CURRENT_USER\Software\Microsoft\Command Processor\CompletionChar
  • HKEY_CURRENT_USER\Software\Microsoft\Command Processor\PathCompletionChar
  • HKEY_CURRENT_USER\Software\Microsoft\Command Processor\AutoRun
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\NetSh
  • HKEY_LOCAL_MACHINE
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows NT\CurrentVersion\CurrentBuildNumber
  • HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Tcpip6\Parameters
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\TCPIP6\Parameters\DisabledComponents
  • HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\IPSEC\Policy\Local
  • HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\iphlpsvc\Config
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\iphlpsvc\config\Connectivity_Platform_Enabled
  • HKEY_LOCAL_MACHINE\Software\Microsoft\Cryptography\OID
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Cryptography\OID\EncodingType 0
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Cryptography\OID\EncodingType 0\CryptDllFindOIDInfo
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Cryptography\OID\EncodingType 0\CryptDllFindOIDInfo\1.3.6.1.4.1.311.44.3.4!7
  • HKEY_LOCAL_MACHINE\Software\Microsoft\Cryptography\OID\EncodingType 0\CryptDllFindOIDInfo\1.3.6.1.4.1.311.44.3.4!7
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Cryptography\OID\EncodingType 0\CryptDllFindOIDInfo\1.3.6.1.4.1.311.44.3.4!7\Name
  • HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\MUI\StringCacheSettings
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\MUI\StringCacheSettings\StringCacheGeneration
  • HKEY_CURRENT_USER\Software\Classes\Local Settings\MuiCache\4b\AAF68885
  • HKEY_CURRENT_USER\Software\Classes\Local Settings\MuiCache\4B\AAF68885\LanguageList
  • HKEY_CURRENT_USER\Software\Classes\Local Settings\MuiCache\4B\AAF68885\@%SystemRoot%\system32\p2pcollab.dll,-8042
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Cryptography\OID\EncodingType 0\CryptDllFindOIDInfo\1.3.6.1.4.1.311.47.1.1!7
  • HKEY_LOCAL_MACHINE\Software\Microsoft\Cryptography\OID\EncodingType 0\CryptDllFindOIDInfo\1.3.6.1.4.1.311.47.1.1!7
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Cryptography\OID\EncodingType 0\CryptDllFindOIDInfo\1.3.6.1.4.1.311.47.1.1!7\Name
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Cryptography\OID\EncodingType 0\CryptDllFindOIDInfo\1.3.6.1.4.1.311.64.1.1!7
  • HKEY_LOCAL_MACHINE\Software\Microsoft\Cryptography\OID\EncodingType 0\CryptDllFindOIDInfo\1.3.6.1.4.1.311.64.1.1!7
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Cryptography\OID\EncodingType 0\CryptDllFindOIDInfo\1.3.6.1.4.1.311.64.1.1!7\Name
  • HKEY_CURRENT_USER\Software\Classes\Local Settings\MuiCache\4B\AAF68885\@%SystemRoot%\system32\dnsapi.dll,-103
  • HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\NapAgent\LocalConfig
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\napagent\LocalConfig\
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\napagent\LocalConfig\Enroll\HcsGroups
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\napagent\LocalConfig\Enroll\HcsGroups\
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\napagent\LocalConfig\Enable Tracing
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\napagent\LocalConfig\Tracing Level
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\napagent\Qecs\79617
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\napagent\Qecs\79617\Friendly Name
  • HKEY_CURRENT_USER\Software\Classes\Local Settings\MuiCache\4B\AAF68885\@%SystemRoot%\system32\dhcpqec.dll,-100
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\napagent\Qecs\79617\Description
  • HKEY_CURRENT_USER\Software\Classes\Local Settings\MuiCache\4B\AAF68885\@%SystemRoot%\system32\dhcpqec.dll,-101
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\napagent\Qecs\79617\Version
  • HKEY_CURRENT_USER\Software\Classes\Local Settings\MuiCache\4B\AAF68885\@%SystemRoot%\system32\dhcpqec.dll,-103
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\napagent\Qecs\79617\Enabled
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\napagent\Qecs\79617\Vendor Name
  • HKEY_CURRENT_USER\Software\Classes\Local Settings\MuiCache\4B\AAF68885\@%SystemRoot%\system32\dhcpqec.dll,-102
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\napagent\Qecs\79617\Info Clsid
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\napagent\Qecs\79617\Config Clsid
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\napagent\Qecs\79617\Validator Clsid
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\napagent\Qecs\79617\Registration Date
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\napagent\Qecs\79617\Component Type
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\napagent\Qecs\79619
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\napagent\Qecs\79619\Friendly Name
  • HKEY_CURRENT_USER\Software\Classes\Local Settings\MuiCache\4B\AAF68885\@%SystemRoot%\system32\napipsec.dll,-1
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\napagent\Qecs\79619\Description
  • HKEY_CURRENT_USER\Software\Classes\Local Settings\MuiCache\4B\AAF68885\@%SystemRoot%\system32\napipsec.dll,-2
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\napagent\Qecs\79619\Version
  • HKEY_CURRENT_USER\Software\Classes\Local Settings\MuiCache\4B\AAF68885\@%SystemRoot%\system32\napipsec.dll,-4
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\napagent\Qecs\79619\Enabled
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\napagent\Qecs\79619\Vendor Name
  • HKEY_CURRENT_USER\Software\Classes\Local Settings\MuiCache\4B\AAF68885\@%SystemRoot%\system32\napipsec.dll,-3
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\napagent\Qecs\79619\Info Clsid
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\napagent\Qecs\79619\Config Clsid
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\napagent\Qecs\79619\Validator Clsid
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\napagent\Qecs\79619\Registration Date
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\napagent\Qecs\79619\Component Type
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\napagent\Qecs\79621
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\napagent\Qecs\79621\Friendly Name
  • HKEY_CURRENT_USER\Software\Classes\Local Settings\MuiCache\4B\AAF68885\@%SystemRoot%\system32\tsgqec.dll,-100
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\napagent\Qecs\79621\Description
  • HKEY_CURRENT_USER\Software\Classes\Local Settings\MuiCache\4B\AAF68885\@%SystemRoot%\system32\tsgqec.dll,-101
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\napagent\Qecs\79621\Version
  • HKEY_CURRENT_USER\Software\Classes\Local Settings\MuiCache\4B\AAF68885\@%SystemRoot%\system32\tsgqec.dll,-102
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\napagent\Qecs\79621\Enabled
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\napagent\Qecs\79621\Vendor Name
  • HKEY_CURRENT_USER\Software\Classes\Local Settings\MuiCache\4B\AAF68885\@%SystemRoot%\system32\tsgqec.dll,-103
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\napagent\Qecs\79621\Info Clsid
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\napagent\Qecs\79621\Config Clsid
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\napagent\Qecs\79621\Validator Clsid
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\napagent\Qecs\79621\Registration Date
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\napagent\Qecs\79621\Component Type
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\napagent\Qecs\79623
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\napagent\Qecs\79623\Friendly Name
  • HKEY_CURRENT_USER\Software\Classes\Local Settings\MuiCache\4B\AAF68885\@%SystemRoot%\system32\eapqec.dll,-100
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\napagent\Qecs\79623\Description
  • HKEY_CURRENT_USER\Software\Classes\Local Settings\MuiCache\4B\AAF68885\@%SystemRoot%\system32\eapqec.dll,-101
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\napagent\Qecs\79623\Version
  • HKEY_CURRENT_USER\Software\Classes\Local Settings\MuiCache\4B\AAF68885\@%SystemRoot%\system32\eapqec.dll,-102
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\napagent\Qecs\79623\Enabled
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\napagent\Qecs\79623\Vendor Name
  • HKEY_CURRENT_USER\Software\Classes\Local Settings\MuiCache\4B\AAF68885\@%SystemRoot%\system32\eapqec.dll,-103
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\napagent\Qecs\79623\Info Clsid
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\napagent\Qecs\79623\Config Clsid
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\napagent\Qecs\79623\Validator Clsid
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\napagent\Qecs\79623\Registration Date
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\napagent\Qecs\79623\Component Type
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\napagent\LocalConfig\Qecs\79617
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\napagent\LocalConfig\PlumbIpsecPolicy
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\napagent\LocalConfig\Qecs\79619
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\napagent\LocalConfig\Qecs\79621
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\napagent\LocalConfig\Qecs\79623
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\napagent\LocalConfig\UI
  • HKEY_CURRENT_USER\Software\Classes\AppID\netsh.exe
  • HKEY_LOCAL_MACHINE\Software\Microsoft\OLE\AppCompat
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\OLE\AppCompat\RaiseDefaultAuthnLevel
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\OLE
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\OLE\DefaultAccessPermission
  • HKEY_CURRENT_USER\Software\Classes\Interface\{00000134-0000-0000-C000-000000000046}
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{00000134-0000-0000-C000-000000000046}\ProxyStubClsid32
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{00000134-0000-0000-C000-000000000046}\ProxyStubClsid32\(Default)
  • HKEY_LOCAL_MACHINE\Software\Microsoft\Rpc\Extensions
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Rpc\Extensions\RemoteRpcDll
  • HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\BFE
  • HKEY_LOCAL_MACHINE\Software\Microsoft\SQMClient\Windows\DisabledProcesses\
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SQMClient\Windows\DisabledProcesses\F6C4EC9A
  • HKEY_LOCAL_MACHINE\Software\Microsoft\SQMClient\Windows\DisabledSessions\
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SQMClient\Windows\DisabledSessions\MachineThrottling
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SQMClient\Windows\DisabledSessions\GlobalSession
  • HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\PeerDist
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\PeerDist\PolicyProvider
  • HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Diagnostics
  • HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows NT\CurrentVersion\Winlogon\UserenvDebugLevel
  • HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows\System
  • HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\System\GpSvcDebugLevel
  • HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\PeerDist
  • HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\PeerDist\Service
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\PeerDist\Service
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\PeerDist\Service\Enable
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\PeerDist\Service\PolicyRefreshInProgress
  • HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\PeerDist\DownloadManager
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\PeerDist\DownloadManager
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\PeerDist\DownloadManager\TransportDllPath
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\PeerDist\DownloadManager\CryptoAlgo
  • HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\PeerDist\DownloadManager\Protocol
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\PeerDist\DownloadManager\Protocol
  • HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\PeerDist\DownloadManager\Download
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\PeerDist\DownloadManager\Download
  • HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\PeerDist\DownloadManager\Discovery
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\PeerDist\DownloadManager\Discovery
  • HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\PeerDist\DownloadManager\Upload
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\PeerDist\DownloadManager\Upload
  • HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\PeerDist\DownloadManager\UtilityIndex
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\PeerDist\DownloadManager\UtilityIndex
  • HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\PeerDist\DownloadManager\Peers\Connection
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\PeerDist\DownloadManager\Peers\Connection
  • HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\PeerDist\SecurityManager
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\PeerDist\SecurityManager
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\PeerDist\SecurityManager\BlockSize
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\PeerDist\SecurityManager\NumBlocksPerSegment
  • HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\PeerDist\SecurityManager\Restricted
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\PeerDist\SecurityManager\Restricted
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\PeerDist\SecurityManager\Restricted\Seed
  • HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\PeerDist\CacheMgr\Republication
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\PeerDist\CacheMgr\Republication
  • HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\PeerDist\CacheMgr\Publication
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\PeerDist\CacheMgr\Publication
  • HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\PeerDist\HandleMgr
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\PeerDist\HandleMgr
  • HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\PeerDist\HostedCache\Connection
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\PeerDist\HostedCache\Connection
  • HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\PeerDist\HostedCache
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\PeerDist\HostedCache
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\PeerDist\HostedCache\ServerRole
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\PeerDist\HostedCache\ClientAuth
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\PeerDist\HostedCache\TransportDllPath
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\PeerDist\HostedCache\MaxSimultaneousDownloads
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\PeerDist\HostedCache\MaxSimultaneousUploads
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\PeerDist\HostedCache\MaxPendingOffers
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\PeerDist\HostedCache\MaxPendingDownloads
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\PeerDist\HostedCache\DoNotUseSSL
  • HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\PeerDist\CooperativeCaching
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\PeerDist\CooperativeCaching
  • HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\PeerDist\DiscoveryManager
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\PeerDist\DiscoveryManager
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\PeerDist\DiscoveryManager\RepubQuorumSize
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\PeerDist\DiscoveryManager\MinBackoffWindow
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\PeerDist\DiscoveryManager\DiscoveryProviderDllPath
  • HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\PeerDist\Publisher
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\PeerDist\Publisher
  • HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\PeerDist\Roaming
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\PeerDist\Roaming
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\PeerDist\Roaming\ForceRoamingDetect
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\PeerDist\Roaming\RefreshDllName
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\PeerDist\Roaming\RefreshProcName
  • HKEY_LOCAL_MACHINE\Software\Microsoft\Rpc\SecurityService
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Rpc\SecurityService\DefaultAuthLevel
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\HTTP
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\HTTP\ObjectName
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\napagent
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\napagent\ImagePath
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\napagent\Type
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\napagent\Start
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\napagent\ErrorControl
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\napagent\Tag
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\napagent\DependOnService
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\napagent\DependOnGroup
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\napagent\Group
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\napagent\ObjectName
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\gpsvc
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\gpsvc\ImagePath
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\gpsvc\Type
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\gpsvc\Start
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\gpsvc\ErrorControl
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\gpsvc\Tag
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\gpsvc\DependOnService
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\gpsvc\DependOnGroup
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\gpsvc\Group
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\gpsvc\ObjectName
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\DcomLaunch
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\DcomLaunch\ObjectName
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\RpcEptMapper
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\RpcEptMapper\ObjectName
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\RpcSs
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\RpcSs\ObjectName
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\EventSystem
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\EventSystem\ObjectName
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\BITS
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\BITS\ObjectName
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\BITS\ImagePath
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\BITS\WOW64
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\BITS\RequiredPrivileges
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\BITS\Type
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\BITS\Start
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\BITS\ErrorControl
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\BITS\Tag
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\BITS\DependOnService
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\BITS\DependOnGroup
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\BITS\Group
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\clr_optimization_v4.0.30319_32
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\clr_optimization_v4.0.30319_32\ObjectName
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\clr_optimization_v4.0.30319_32\ImagePath
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\clr_optimization_v4.0.30319_32\WOW64
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ProfileList\ProgramData
  • HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\Session Manager\Environment
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ProfileList\Default
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ProgramFilesDir
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\CommonFilesDir
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ProgramFilesDir (x86)
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\CommonFilesDir (x86)
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ProgramW6432Dir
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\CommonW6432Dir
  • HKEY_USERS\S-1-5-18
  • HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\ProfileList\S-1-5-18
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ProfileList\S-1-5-18\ProfileImagePath
  • HKEY_USERS\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders
  • HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders\AppData
  • HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders\Local AppData
  • HKEY_USERS\.DEFAULT\Environment
  • HKEY_USERS\.DEFAULT\Volatile Environment
  • HKEY_USERS\.DEFAULT\Volatile Environment\0
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\clr_optimization_v4.0.30319_32\Environment
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\clr_optimization_v4.0.30319_32\RequiredPrivileges
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\clr_optimization_v4.0.30319_64
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\clr_optimization_v4.0.30319_64\ObjectName
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\clr_optimization_v4.0.30319_64\ImagePath
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\clr_optimization_v4.0.30319_64\WOW64
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\clr_optimization_v4.0.30319_64\Environment
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\clr_optimization_v4.0.30319_64\RequiredPrivileges
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\FontCache
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\FontCache\ObjectName
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\FontCache\ImagePath
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\FontCache\WOW64
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\AppIDSvc
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\AppIDSvc\ImagePath
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\AppIDSvc\WOW64
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Appinfo
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Appinfo\ImagePath
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Appinfo\WOW64
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\AppMgmt
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\AppMgmt\ImagePath
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\AppMgmt\WOW64
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\AxInstSV
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\AxInstSV\ImagePath
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\AxInstSV\WOW64
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\BDESVC
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\BDESVC\ImagePath
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\BDESVC\WOW64
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\bthserv
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\bthserv\ImagePath
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\bthserv\WOW64
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\dot3svc
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\dot3svc\ImagePath
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\dot3svc\WOW64
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\EapHost
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\EapHost\ImagePath
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\EapHost\WOW64
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\EFS
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\EFS\ImagePath
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\EFS\WOW64
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\fdPHost
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\fdPHost\ImagePath
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\fdPHost\WOW64
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\FDResPub
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\FDResPub\ImagePath
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\FDResPub\WOW64
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\hidserv
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\hidserv\ImagePath
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\hidserv\WOW64
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\hkmsvc
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\hkmsvc\ImagePath
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\hkmsvc\WOW64
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\HomeGroupListener
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\HomeGroupListener\ImagePath
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\HomeGroupListener\WOW64
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\HomeGroupProvider
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\HomeGroupProvider\ImagePath
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\HomeGroupProvider\WOW64
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\idsvc
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\idsvc\ImagePath
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\idsvc\WOW64
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\IPBusEnum
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\IPBusEnum\ImagePath
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\IPBusEnum\WOW64
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\KeyIso
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\KeyIso\ImagePath
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\KeyIso\WOW64
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\KtmRm
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\KtmRm\ImagePath
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\KtmRm\WOW64
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\lltdsvc
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\lltdsvc\ImagePath
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\lltdsvc\WOW64
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Mcx2Svc
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Mcx2Svc\ImagePath
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Mcx2Svc\WOW64
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\MpsSvc
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\MpsSvc\ImagePath
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\MpsSvc\WOW64
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\MSiSCSI
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\MSiSCSI\ImagePath
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\MSiSCSI\WOW64
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\napagent\WOW64
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Netlogon
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Netlogon\ImagePath
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Netlogon\WOW64
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\NetMsmqActivator
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\NetMsmqActivator\ImagePath
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\NetMsmqActivator\WOW64
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\NetPipeActivator
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\NetPipeActivator\ImagePath
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\NetPipeActivator\WOW64
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\NetTcpActivator
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\NetTcpActivator\ImagePath
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\NetTcpActivator\WOW64
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\NetTcpPortSharing
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\NetTcpPortSharing\ImagePath
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\NetTcpPortSharing\WOW64
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\p2pimsvc
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\p2pimsvc\ImagePath
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\p2pimsvc\WOW64
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\p2psvc
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\p2psvc\ImagePath
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\p2psvc\WOW64
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\PeerDistSvc
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\PeerDistSvc\ImagePath
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\PeerDistSvc\WOW64
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\pla
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\pla\ImagePath
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\pla\WOW64
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\PNRPAutoReg
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\PNRPAutoReg\ImagePath
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\PNRPAutoReg\WOW64
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\PNRPsvc
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\PNRPsvc\ImagePath
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\PNRPsvc\WOW64
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\ProtectedStorage
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\ProtectedStorage\ImagePath
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\ProtectedStorage\WOW64
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\QWAVE
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\QWAVE\ImagePath
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\QWAVE\WOW64
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\RasAuto
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\RasAuto\ImagePath
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\RasAuto\WOW64
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\RasMan
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\RasMan\ImagePath
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\RasMan\WOW64
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\RemoteAccess
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\RemoteAccess\ImagePath
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\RemoteAccess\WOW64
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\RemoteRegistry
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\RemoteRegistry\ImagePath
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\RemoteRegistry\WOW64
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\SCardSvr
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\SCardSvr\ImagePath
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\SCardSvr\WOW64
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\SCPolicySvc
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\SCPolicySvc\ImagePath
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\SCPolicySvc\WOW64
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\seclogon
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\seclogon\ImagePath
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\seclogon\WOW64
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\SensrSvc
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\SensrSvc\ImagePath
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\SensrSvc\WOW64
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\SharedAccess
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\SharedAccess\ImagePath
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\SharedAccess\WOW64
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\sppuinotify
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\sppuinotify\ImagePath
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\sppuinotify\WOW64
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\SSDPSRV
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\SSDPSRV\ImagePath
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\SSDPSRV\WOW64
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\SstpSvc
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\SstpSvc\ImagePath
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\SstpSvc\WOW64
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\SysMain
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\SysMain\ImagePath
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\SysMain\WOW64
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\TabletInputService
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\TabletInputService\ImagePath
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\TabletInputService\WOW64
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\TapiSrv
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\TapiSrv\ImagePath
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\TapiSrv\WOW64
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\TBS
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\TBS\ImagePath
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\TBS\WOW64
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\THREADORDER
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\THREADORDER\ImagePath
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\THREADORDER\WOW64
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\upnphost
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\upnphost\ImagePath
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\upnphost\WOW64
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VaultSvc
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VaultSvc\ImagePath
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VaultSvc\WOW64
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\W32Time
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\W32Time\ImagePath
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\W32Time\WOW64
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WbioSrvc
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WbioSrvc\ImagePath
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WbioSrvc\WOW64
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\wcncsvc
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\wcncsvc\ImagePath
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\wcncsvc\WOW64
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WcsPlugInService
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WcsPlugInService\ImagePath
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WcsPlugInService\WOW64
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WebClient
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WebClient\ImagePath
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WebClient\WOW64
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Wecsvc
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Wecsvc\ImagePath
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Wecsvc\WOW64
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\wercplsupport
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\wercplsupport\ImagePath
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\wercplsupport\WOW64
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WerSvc
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WerSvc\ImagePath
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WerSvc\WOW64
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WinDefend
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WinDefend\ImagePath
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WinDefend\WOW64
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WinHttpAutoProxySvc
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WinHttpAutoProxySvc\ImagePath
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WinHttpAutoProxySvc\WOW64
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WinRM
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WinRM\ImagePath
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WinRM\WOW64
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Wlansvc
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Wlansvc\ImagePath
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Wlansvc\WOW64
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WPCSvc
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WPCSvc\ImagePath
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WPCSvc\WOW64
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WPDBusEnum
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WPDBusEnum\ImagePath
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WPDBusEnum\WOW64
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\wscsvc
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\wscsvc\ImagePath
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\wscsvc\WOW64
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\wuauserv
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\wuauserv\ImagePath
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\wuauserv\WOW64
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\wudfsvc
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\wudfsvc\ImagePath
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\wudfsvc\WOW64
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WwanSvc
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WwanSvc\ImagePath
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WwanSvc\WOW64
  • HKEY_USERS\S-1-5-19
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\AppIDSvc\RequiredPrivileges
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\FDResPub\RequiredPrivileges
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\FontCache\RequiredPrivileges
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Mcx2Svc\RequiredPrivileges
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\QWAVE\RequiredPrivileges
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\SCardSvr\RequiredPrivileges
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\SensrSvc\RequiredPrivileges
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\SSDPSRV\RequiredPrivileges
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\TBS\RequiredPrivileges
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\upnphost\RequiredPrivileges
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\wcncsvc\RequiredPrivileges
  • HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\ProfileList\S-1-5-19
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ProfileList\S-1-5-19\ProfileImagePath
  • HKEY_USERS\S-1-5-19\Software\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders
  • HKEY_USERS\S-1-5-19\Software\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders\AppData
  • HKEY_USERS\S-1-5-19\Software\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders\Local AppData
  • HKEY_USERS\S-1-5-19\Environment
  • HKEY_USERS\S-1-5-19\Volatile Environment
  • HKEY_USERS\S-1-5-19\Volatile Environment\0
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\FontCache\Environment
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\sppsvc
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\sppsvc\ObjectName
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\sppsvc\ImagePath
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\sppsvc\WOW64
  • HKEY_USERS\S-1-5-20
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\sppsvc\RequiredPrivileges
  • HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\ProfileList\S-1-5-20
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ProfileList\S-1-5-20\ProfileImagePath
  • HKEY_USERS\S-1-5-20\Software\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders
  • HKEY_USERS\S-1-5-20\Software\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders\AppData
  • HKEY_USERS\S-1-5-20\Software\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders\Local AppData
  • HKEY_USERS\S-1-5-20\Environment
  • HKEY_USERS\S-1-5-20\Volatile Environment
  • HKEY_USERS\S-1-5-20\Volatile Environment\0
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\sppsvc\Environment
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Winmgmt
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Winmgmt\ObjectName
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\wscsvc\ObjectName
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\wscsvc\RequiredPrivileges
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\wuauserv\Type
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\wuauserv\Start
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\wuauserv\ErrorControl
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\wuauserv\Tag
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\wuauserv\DependOnService
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\wuauserv\DependOnGroup
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\wuauserv\Group
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\wuauserv\ObjectName
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\wscsvc\Type
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\wscsvc\Start
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\wscsvc\ErrorControl
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\wscsvc\Tag
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\wscsvc\DependOnService
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\wscsvc\DependOnGroup
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\wscsvc\Group
  • HKEY_CURRENT_USER\Software\Microsoft\.NETFramework
  • HKEY_LOCAL_MACHINE\Software\Microsoft\.NETFramework
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\.NETFramework\NGenServiceDebugLog
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\.NETFramework\NicPath
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\.NETFramework\RegistryRoot
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\.NETFramework\AssemblyPath
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\.NETFramework\AssemblyPath2
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\NET Framework Setup\NDP\v4\Client
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\NET Framework Setup\NDP\v4\Client\Install
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\.NETFramework\NGEN_USE_PRIVATE_STORE
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\.NETFramework\DefaultVersion
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\.NETFramework\Version
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\.NETFramework\ZapSet
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\.NetFramework\v2.0.50727\NGenService\Roots
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\.NETFramework\v2.0.50727\NGENService\Roots\WorkPending
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\.NetFramework\v2.0.50727\NGENService\State
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\.NETFramework\v2.0.50727\NGENService\State\PendingUpdate
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\.NETFramework\NGenQueue\WIN32\Default
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\.NETFramework\NGenQueueMSI\WIN32\Default
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\.NETFramework\NGenServiceDebugLog
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\.NETFramework\NicPath
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\.NETFramework\RegistryRoot
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\.NETFramework\AssemblyPath
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\.NETFramework\AssemblyPath2
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\NET Framework Setup\NDP\v4\Client\Install
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\.NETFramework\NGEN_USE_PRIVATE_STORE
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\.NETFramework\DefaultVersion
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\.NETFramework\Version
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\.NETFramework\ZapSet
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\.NETFramework\v2.0.50727\NGENService\Roots\WorkPending
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\.NETFramework\v2.0.50727\NGENService\State\PendingUpdate
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\.NETFramework\NGenQueue\WIN64\Default
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\.NETFramework\NGenQueueMSI\WIN64\Default
  • HKEY_CLASSES_ROOT\.dll
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\.dll\(Default)
  • HKEY_CLASSES_ROOT\dllfile
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\dllfile\AutoRegister
  • HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\SideBySide
  • HKEY_CURRENT_USER\Software
  • HKEY_CURRENT_USER\Software\Classes\AppID
  • HKEY_CURRENT_USER\Software\Classes\AppID\{B415CD14-B45D-4BCA-B552-B06175C38606}
  • HKEY_CURRENT_USER\Software\Classes\AppID\{B415CD14-B45D-4BCA-B552-B06175C38606}\(Default)
  • HKEY_CURRENT_USER\Software\Classes\AppID\npszwplugin.dll
  • HKEY_CURRENT_USER\Software\Classes\AppID\npszwplugin.dll\AppID
  • HKEY_CURRENT_USER\Software\Classes\Sumszw.szwplugin.1
  • HKEY_CURRENT_USER\Software\Classes\Sumszw.szwplugin.1\(Default)
  • HKEY_CURRENT_USER\Software\Classes\Sumszw.szwplugin.1\CLSID
  • HKEY_CURRENT_USER\Software\Classes\Sumszw.szwplugin.1\CLSID\(Default)
  • HKEY_CURRENT_USER\Software\Classes\Sumszw.szwplugin
  • HKEY_CURRENT_USER\Software\Classes\Sumszw.szwplugin\(Default)
  • HKEY_CURRENT_USER\Software\Classes\Sumszw.szwplugin\CLSID
  • HKEY_CURRENT_USER\Software\Classes\Sumszw.szwplugin\CLSID\(Default)
  • HKEY_CURRENT_USER\Software\Classes\Sumszw.szwplugin\CurVer
  • HKEY_CURRENT_USER\Software\Classes\Sumszw.szwplugin\CurVer\(Default)
  • HKEY_CURRENT_USER\Software\Classes\CLSID
  • HKEY_CURRENT_USER\Software\Classes\Wow6432Node\CLSID\{92834c16-4bb2-5be0-8496-af603887da4d}
  • HKEY_CURRENT_USER\Software\Classes\Wow6432Node\CLSID\{92834c16-4bb2-5be0-8496-af603887da4d}\(Default)
  • HKEY_CURRENT_USER\Software\Classes\Wow6432Node\CLSID\{92834c16-4bb2-5be0-8496-af603887da4d}\ProgID
  • HKEY_CURRENT_USER\Software\Classes\Wow6432Node\CLSID\{92834c16-4bb2-5be0-8496-af603887da4d}\ProgID\(Default)
  • HKEY_CURRENT_USER\Software\Classes\Wow6432Node\CLSID\{92834c16-4bb2-5be0-8496-af603887da4d}\VersionIndependentProgID
  • HKEY_CURRENT_USER\Software\Classes\Wow6432Node\CLSID\{92834c16-4bb2-5be0-8496-af603887da4d}\VersionIndependentProgID\(Default)
  • HKEY_CURRENT_USER\Software\Classes\Wow6432Node\CLSID\{92834c16-4bb2-5be0-8496-af603887da4d}\Programmable
  • HKEY_CURRENT_USER\Software\Classes\Wow6432Node\CLSID\{92834c16-4bb2-5be0-8496-af603887da4d}\InprocServer32
  • HKEY_CURRENT_USER\Software\Classes\Wow6432Node\CLSID\{92834c16-4bb2-5be0-8496-af603887da4d}\InprocServer32\(Default)
  • HKEY_CURRENT_USER\Software\Classes\Wow6432Node\CLSID\{92834c16-4bb2-5be0-8496-af603887da4d}\InprocServer32\ThreadingModel
  • HKEY_CURRENT_USER\Software\Classes\Wow6432Node\CLSID\{92834c16-4bb2-5be0-8496-af603887da4d}\AppID
  • HKEY_CURRENT_USER\Software\Classes\Wow6432Node\CLSID\{92834c16-4bb2-5be0-8496-af603887da4d}\Control
  • HKEY_CURRENT_USER\Software\Classes\Wow6432Node\CLSID\{92834c16-4bb2-5be0-8496-af603887da4d}\MiscStatus
  • HKEY_CURRENT_USER\Software\Classes\Wow6432Node\CLSID\{92834c16-4bb2-5be0-8496-af603887da4d}\MiscStatus\(Default)
  • HKEY_CURRENT_USER\Software\Classes\Wow6432Node\CLSID\{92834c16-4bb2-5be0-8496-af603887da4d}\MiscStatus\1
  • HKEY_CURRENT_USER\Software\Classes\Wow6432Node\CLSID\{92834c16-4bb2-5be0-8496-af603887da4d}\MiscStatus\1\(Default)
  • HKEY_CURRENT_USER\Software\Classes\Wow6432Node\CLSID\{92834c16-4bb2-5be0-8496-af603887da4d}\TypeLib
  • HKEY_CURRENT_USER\Software\Classes\Wow6432Node\CLSID\{92834c16-4bb2-5be0-8496-af603887da4d}\TypeLib\(Default)
  • HKEY_CURRENT_USER\Software\Classes\Wow6432Node\CLSID\{92834c16-4bb2-5be0-8496-af603887da4d}\Version
  • HKEY_CURRENT_USER\Software\Classes\Wow6432Node\CLSID\{92834c16-4bb2-5be0-8496-af603887da4d}\Version\(Default)
  • HKEY_CURRENT_USER\Software\Classes\MIME
  • HKEY_CURRENT_USER\Software\Classes\MIME\Database
  • HKEY_CURRENT_USER\Software\Classes\MIME\Database\Content Type
  • HKEY_CURRENT_USER\Software\Classes\MIME\Database\Content Type\application/x-szwplugin
  • HKEY_CURRENT_USER\Software\Classes\MIME\Database\Content Type\application/x-szwplugin\(Default)
  • HKEY_CURRENT_USER\Software\Classes\MIME\Database\Content Type\application/x-szwplugin\Extension
  • HKEY_CURRENT_USER\Software\Classes\MIME\Database\Content Type\application/x-szwplugin\CLSID
  • HKEY_CURRENT_USER\Software\Microsoft
  • HKEY_CURRENT_USER\Software\Microsoft\Windows
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Ext
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Ext\PreApproved
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{92834c16-4bb2-5be0-8496-af603887da4d}
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Ext\Stats
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{92834c16-4bb2-5be0-8496-af603887da4d}
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{92834c16-4bb2-5be0-8496-af603887da4d}\iexplore
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{92834c16-4bb2-5be0-8496-af603887da4d}\iexplore\AllowedDomains
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{92834c16-4bb2-5be0-8496-af603887da4d}\iexplore\AllowedDomains\*
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{92834c16-4bb2-5be0-8496-af603887da4d}\iexplore\Count
  • HKEY_CURRENT_USER\Software\MozillaPlugins
  • HKEY_CURRENT_USER\Software\classes
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\OLEAUT
  • HKEY_CURRENT_USER\Software\Classes\TypeLib
  • HKEY_CURRENT_USER\Software\Classes\TypeLib\{73F92EE3-0C4F-53E3-8FDA-A571E532950E}
  • HKEY_CURRENT_USER\Software\Classes\TypeLib\{73F92EE3-0C4F-53E3-8FDA-A571E532950E}\1.0
  • HKEY_CURRENT_USER\Software\Classes\TypeLib\{73F92EE3-0C4F-53E3-8FDA-A571E532950E}\1.0\(Default)
  • HKEY_CURRENT_USER\Software\Classes\TypeLib\{73F92EE3-0C4F-53E3-8FDA-A571E532950E}\1.0\FLAGS
  • HKEY_CURRENT_USER\Software\Classes\TypeLib\{73F92EE3-0C4F-53E3-8FDA-A571E532950E}\1.0\FLAGS\(Default)
  • HKEY_CURRENT_USER\Software\Classes\TypeLib\{73F92EE3-0C4F-53E3-8FDA-A571E532950E}\1.0\0
  • HKEY_CURRENT_USER\Software\Classes\TypeLib\{73F92EE3-0C4F-53E3-8FDA-A571E532950E}\1.0\0\win32
  • HKEY_CURRENT_USER\Software\Classes\TypeLib\{73F92EE3-0C4F-53E3-8FDA-A571E532950E}\1.0\0\win32\(Default)
  • HKEY_CURRENT_USER\Software\Classes\TypeLib\{73F92EE3-0C4F-53E3-8FDA-A571E532950E}\1.0\HELPDIR
  • HKEY_CURRENT_USER\Software\Classes\TypeLib\{73F92EE3-0C4F-53E3-8FDA-A571E532950E}\1.0\HELPDIR\(Default)
  • HKEY_CURRENT_USER\Software\Classes\Interface
  • HKEY_CURRENT_USER\Software\Classes\Wow6432Node\Interface\{1EE0264C-67B3-5477-953B-CF7F87D70680}
  • HKEY_CURRENT_USER\Software\Classes\Wow6432Node\Interface\{1EE0264C-67B3-5477-953B-CF7F87D70680}\(Default)
  • HKEY_CURRENT_USER\Software\Classes\Wow6432Node\Interface\{1EE0264C-67B3-5477-953B-CF7F87D70680}\ProxyStubClsid32
  • HKEY_CURRENT_USER\Software\Classes\Wow6432Node\Interface\{1EE0264C-67B3-5477-953B-CF7F87D70680}\ProxyStubClsid32\(Default)
  • HKEY_CURRENT_USER\Software\Classes\Wow6432Node\Interface\{1EE0264C-67B3-5477-953B-CF7F87D70680}\TypeLib
  • HKEY_CURRENT_USER\Software\Classes\Wow6432Node\Interface\{1EE0264C-67B3-5477-953B-CF7F87D70680}\TypeLib\(Default)
  • HKEY_CURRENT_USER\Software\Classes\Wow6432Node\Interface\{1EE0264C-67B3-5477-953B-CF7F87D70680}\TypeLib\Version
  • HKEY_CURRENT_USER\Software\Classes\Interface\{1EE0264C-67B3-5477-953B-CF7F87D70680}
  • HKEY_CURRENT_USER\Software\Classes\Interface\{1EE0264C-67B3-5477-953B-CF7F87D70680}\(Default)
  • HKEY_CURRENT_USER\Software\Classes\Interface\{1EE0264C-67B3-5477-953B-CF7F87D70680}\ProxyStubClsid32
  • HKEY_CURRENT_USER\Software\Classes\Interface\{1EE0264C-67B3-5477-953B-CF7F87D70680}\ProxyStubClsid32\(Default)
  • HKEY_CURRENT_USER\Software\Classes\Interface\{1EE0264C-67B3-5477-953B-CF7F87D70680}\TypeLib
  • HKEY_CURRENT_USER\Software\Classes\Interface\{1EE0264C-67B3-5477-953B-CF7F87D70680}\TypeLib\(Default)
  • HKEY_CURRENT_USER\Software\Classes\Interface\{1EE0264C-67B3-5477-953B-CF7F87D70680}\TypeLib\Version
  • HKEY_CURRENT_USER\Software\Classes\Wow6432Node\Interface\{BBA8BF1D-8C1E-5C71-8C9E-610A792952D8}
  • HKEY_CURRENT_USER\Software\Classes\Wow6432Node\Interface\{BBA8BF1D-8C1E-5C71-8C9E-610A792952D8}\(Default)
  • HKEY_CURRENT_USER\Software\Classes\Wow6432Node\Interface\{BBA8BF1D-8C1E-5C71-8C9E-610A792952D8}\ProxyStubClsid32
  • HKEY_CURRENT_USER\Software\Classes\Wow6432Node\Interface\{BBA8BF1D-8C1E-5C71-8C9E-610A792952D8}\ProxyStubClsid32\(Default)
  • HKEY_CURRENT_USER\Software\Classes\Wow6432Node\Interface\{BBA8BF1D-8C1E-5C71-8C9E-610A792952D8}\TypeLib
  • HKEY_CURRENT_USER\Software\Classes\Wow6432Node\Interface\{BBA8BF1D-8C1E-5C71-8C9E-610A792952D8}\TypeLib\(Default)
  • HKEY_CURRENT_USER\Software\Classes\Wow6432Node\Interface\{BBA8BF1D-8C1E-5C71-8C9E-610A792952D8}\TypeLib\Version
  • HKEY_CURRENT_USER\Software\Classes\Interface\{BBA8BF1D-8C1E-5C71-8C9E-610A792952D8}
  • HKEY_CURRENT_USER\Software\Classes\Interface\{BBA8BF1D-8C1E-5C71-8C9E-610A792952D8}\(Default)
  • HKEY_CURRENT_USER\Software\Classes\Interface\{BBA8BF1D-8C1E-5C71-8C9E-610A792952D8}\ProxyStubClsid32
  • HKEY_CURRENT_USER\Software\Classes\Interface\{BBA8BF1D-8C1E-5C71-8C9E-610A792952D8}\ProxyStubClsid32\(Default)
  • HKEY_CURRENT_USER\Software\Classes\Interface\{BBA8BF1D-8C1E-5C71-8C9E-610A792952D8}\TypeLib
  • HKEY_CURRENT_USER\Software\Classes\Interface\{BBA8BF1D-8C1E-5C71-8C9E-610A792952D8}\TypeLib\(Default)
  • HKEY_CURRENT_USER\Software\Classes\Interface\{BBA8BF1D-8C1E-5C71-8C9E-610A792952D8}\TypeLib\Version
  • HKEY_CURRENT_USER\Software\Classes\Wow6432Node\Interface\{446C0065-0A4E-5090-9094-FF9FDBFF5692}
  • HKEY_CURRENT_USER\Software\Classes\Wow6432Node\Interface\{446C0065-0A4E-5090-9094-FF9FDBFF5692}\(Default)
  • HKEY_CURRENT_USER\Software\Classes\Wow6432Node\Interface\{446C0065-0A4E-5090-9094-FF9FDBFF5692}\ProxyStubClsid32
  • HKEY_CURRENT_USER\Software\Classes\Wow6432Node\Interface\{446C0065-0A4E-5090-9094-FF9FDBFF5692}\ProxyStubClsid32\(Default)
  • HKEY_CURRENT_USER\Software\Classes\Wow6432Node\Interface\{446C0065-0A4E-5090-9094-FF9FDBFF5692}\TypeLib
  • HKEY_CURRENT_USER\Software\Classes\Wow6432Node\Interface\{446C0065-0A4E-5090-9094-FF9FDBFF5692}\TypeLib\(Default)
  • HKEY_CURRENT_USER\Software\Classes\Wow6432Node\Interface\{446C0065-0A4E-5090-9094-FF9FDBFF5692}\TypeLib\Version
  • HKEY_CURRENT_USER\Software\Classes\Interface\{446C0065-0A4E-5090-9094-FF9FDBFF5692}
  • HKEY_CURRENT_USER\Software\Classes\Interface\{446C0065-0A4E-5090-9094-FF9FDBFF5692}\(Default)
  • HKEY_CURRENT_USER\Software\Classes\Interface\{446C0065-0A4E-5090-9094-FF9FDBFF5692}\ProxyStubClsid32
  • HKEY_CURRENT_USER\Software\Classes\Interface\{446C0065-0A4E-5090-9094-FF9FDBFF5692}\ProxyStubClsid32\(Default)
  • HKEY_CURRENT_USER\Software\Classes\Interface\{446C0065-0A4E-5090-9094-FF9FDBFF5692}\TypeLib
  • HKEY_CURRENT_USER\Software\Classes\Interface\{446C0065-0A4E-5090-9094-FF9FDBFF5692}\TypeLib\(Default)
  • HKEY_CURRENT_USER\Software\Classes\Interface\{446C0065-0A4E-5090-9094-FF9FDBFF5692}\TypeLib\Version
  • HKEY_CLASSES_ROOT\AppID
  • HKEY_CURRENT_USER\Software\Classes\AppID\{6D85FED0-9D91-4885-A76B-C5CFD468CF23}
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{6D85FED0-9D91-4885-A76B-C5CFD468CF23}\(Default)
  • HKEY_CURRENT_USER\Software\Classes\AppID\ieplugin.DLL
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\ieplugin.DLL\AppID
  • HKEY_LOCAL_MACHINE\Software\Microsoft\Ole
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\OLE\MaximumAllowedAllocationSize
  • HKEY_CLASSES_ROOT\ieplugin.SZWCtrl1.0.0.1
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\ieplugin.SZWCtrl1.0.0.1\(Default)
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\ieplugin.SZWCtrl1.0.0.1\CLSID
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\ieplugin.SZWCtrl1.0.0.1\CLSID\(Default)
  • HKEY_CLASSES_ROOT\ieplugin.SZWCtrl
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\ieplugin.SZWCtrl\(Default)
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\ieplugin.SZWCtrl\CLSID
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\ieplugin.SZWCtrl\CLSID\(Default)
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\ieplugin.SZWCtrl\CurVer
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\ieplugin.SZWCtrl\CurVer\(Default)
  • HKEY_CLASSES_ROOT\CLSID
  • HKEY_CURRENT_USER\Software\Classes\Wow6432Node\CLSID\{A82F3915-72D8-4837-BDDC-4A3BBA9C725A}
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A82F3915-72D8-4837-BDDC-4A3BBA9C725A}\(Default)
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A82F3915-72D8-4837-BDDC-4A3BBA9C725A}\ProgID
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A82F3915-72D8-4837-BDDC-4A3BBA9C725A}\ProgID\(Default)
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A82F3915-72D8-4837-BDDC-4A3BBA9C725A}\VersionIndependentProgID
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A82F3915-72D8-4837-BDDC-4A3BBA9C725A}\VersionIndependentProgID\(Default)
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A82F3915-72D8-4837-BDDC-4A3BBA9C725A}\Programmable
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A82F3915-72D8-4837-BDDC-4A3BBA9C725A}\InprocServer32
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A82F3915-72D8-4837-BDDC-4A3BBA9C725A}\InprocServer32\(Default)
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A82F3915-72D8-4837-BDDC-4A3BBA9C725A}\InprocServer32\ThreadingModel
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A82F3915-72D8-4837-BDDC-4A3BBA9C725A}\AppID
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A82F3915-72D8-4837-BDDC-4A3BBA9C725A}\TypeLib
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A82F3915-72D8-4837-BDDC-4A3BBA9C725A}\TypeLib\(Default)
  • HKEY_CURRENT_USER\Software\Classes\TypeLib\{6D85FED0-9D91-4885-A76B-C5CFD468CF23}
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{6D85FED0-9D91-4885-A76B-C5CFD468CF23}\1.0
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{6D85FED0-9D91-4885-A76B-C5CFD468CF23}\1.0\(Default)
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{6D85FED0-9D91-4885-A76B-C5CFD468CF23}\1.0\FLAGS
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{6D85FED0-9D91-4885-A76B-C5CFD468CF23}\1.0\FLAGS\(Default)
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{6D85FED0-9D91-4885-A76B-C5CFD468CF23}\1.0\0
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{6D85FED0-9D91-4885-A76B-C5CFD468CF23}\1.0\0\win32
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{6D85FED0-9D91-4885-A76B-C5CFD468CF23}\1.0\0\win32\(Default)
  • HKEY_CURRENT_USER\Software\Classes\TypeLib\{6D85FED0-9D91-4885-A76B-C5CFD468CF23}\1.0\HELPDIR
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{6D85FED0-9D91-4885-A76B-C5CFD468CF23}\1.0\HELPDIR
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{6D85FED0-9D91-4885-A76B-C5CFD468CF23}\1.0\HELPDIR\(Default)
  • HKEY_CURRENT_USER\Software\Classes\Wow6432Node\Interface\{726F412C-1ECA-465C-9C85-DC277F331EDD}
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{726F412C-1ECA-465C-9C85-DC277F331EDD}\(Default)
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{726F412C-1ECA-465C-9C85-DC277F331EDD}\ProxyStubClsid32
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{726F412C-1ECA-465C-9C85-DC277F331EDD}\ProxyStubClsid32\(Default)
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{726F412C-1ECA-465C-9C85-DC277F331EDD}\TypeLib
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{726F412C-1ECA-465C-9C85-DC277F331EDD}\TypeLib\(Default)
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{726F412C-1ECA-465C-9C85-DC277F331EDD}\TypeLib\Version
  • HKEY_CURRENT_USER\Software\Classes\Interface\{726F412C-1ECA-465C-9C85-DC277F331EDD}
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{726F412C-1ECA-465C-9C85-DC277F331EDD}\(Default)
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{726F412C-1ECA-465C-9C85-DC277F331EDD}\ProxyStubClsid32
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{726F412C-1ECA-465C-9C85-DC277F331EDD}\ProxyStubClsid32\(Default)
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{726F412C-1ECA-465C-9C85-DC277F331EDD}\TypeLib
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{726F412C-1ECA-465C-9C85-DC277F331EDD}\TypeLib\(Default)
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{726F412C-1ECA-465C-9C85-DC277F331EDD}\TypeLib\Version
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\CTF\Compatibility\MasterZ.exe
  • HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows
  • HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows\DragMinDist
  • HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows\DragDelay
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache
读取的注册表键
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\CPC\Volume\{372941a3-1bd9-11e5-9838-806e6f6e6963}\Data
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\CPC\Volume\{372941a3-1bd9-11e5-9838-806e6f6e6963}\Generation
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\CPC\Volume\{372941a4-1bd9-11e5-9838-806e6f6e6963}\Data
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\CPC\Volume\{372941a4-1bd9-11e5-9838-806e6f6e6963}\Generation
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\Locale\00000804
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\Language Groups\a
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\CTF\TIP\{0000897b-83df-4b96-be07-0fb58b01c4a4}\LanguageProfile\0x00000000\{0001bea3-ed56-483d-a2e2-aeae25577436}\Enable
  • HKEY_CURRENT_USER\Keyboard Layout\Toggle\Language Hotkey
  • HKEY_CURRENT_USER\Keyboard Layout\Toggle\Hotkey
  • HKEY_CURRENT_USER\Keyboard Layout\Toggle\Layout Hotkey
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\CTF\EnableAnchorContext
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\DataStore_V1.0\Disable
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\DataStore_V1.0\DataFilePath
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Plane1
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Plane2
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Plane3
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Plane4
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Plane5
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Plane6
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Plane7
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Plane8
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Plane9
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Plane10
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Plane11
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Plane12
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Plane13
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Plane14
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Plane15
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\Plane16
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\SimSun\Plane1
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\SimSun\Plane2
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\SimSun\Plane3
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\SimSun\Plane4
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\SimSun\Plane5
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\SimSun\Plane6
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\SimSun\Plane7
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\SimSun\Plane8
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\SimSun\Plane9
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\SimSun\Plane10
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\SimSun\Plane11
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\SimSun\Plane12
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\SimSun\Plane13
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\SimSun\Plane14
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\SimSun\Plane15
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\LanguagePack\SurrogateFallback\SimSun\Plane16
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\DllNXOptions\UseFilter
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\DllNXOptions\System.dll
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\SESSION MANAGER\SafeProcessSearchMode
  • HKEY_CURRENT_USER\Control Panel\Desktop\SmoothScroll
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced\EnableBalloonTips
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced\ListviewAlphaSelect
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced\ListviewShadow
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced\AccListViewV6
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced\UseDoubleClickTimer
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\FontSubstitutes\\xe5\xae\x8b\xe4\xbd\x93
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\en-US
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\ExtendedLocale\en-US
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\Desktop\NameSpace\{031E4825-7B94-4dc3-B131-E946B44C8DD5}\SuppressionPolicy
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\Desktop\NameSpace\{04731B67-D933-450a-90E6-4ACD2E9408FE}\SuppressionPolicy
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\Desktop\NameSpace\{11016101-E366-4D22-BC06-4ADA335C892B}\SuppressionPolicy
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\Desktop\NameSpace\{138508bc-1e03-49ea-9c8f-ea9e1d05d65d}\SuppressionPolicy
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\Desktop\NameSpace\{26EE0668-A00A-44D7-9371-BEB064C98683}\SuppressionPolicy
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\Desktop\NameSpace\{4336a54d-038b-4685-ab02-99bb52d3fb8b}\SuppressionPolicy
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\Desktop\NameSpace\{450D8FBA-AD25-11D0-98A8-0800361B1103}\SuppressionPolicy
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\Desktop\NameSpace\{5399E694-6CE5-4D6C-8FCE-1D8870FDCBA0}\SuppressionPolicy
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\Desktop\NameSpace\{59031a47-3f72-44a7-89c5-5595fe6b30ee}\SuppressionPolicy
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\Desktop\NameSpace\{645FF040-5081-101B-9F08-00AA002F954E}\SuppressionPolicy
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\Desktop\NameSpace\{89D83576-6BD1-4c86-9454-BEB04E94C819}\SuppressionPolicy
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\Desktop\NameSpace\{9343812e-1c37-4a49-a12e-4b2d810d956b}\SuppressionPolicy
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\Desktop\NameSpace\{B0FBD52D-C4A7-4a19-985D-11309D1AC8AE}\SuppressionPolicy
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\Desktop\NameSpace\{B4FB3F98-C1EA-428d-A78A-D1F5659CBA93}\SuppressionPolicy
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\Desktop\NameSpace\{BD7A2E7B-21CB-41b2-A086-B309680C6B7E}\SuppressionPolicy
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\Desktop\NameSpace\{daf95313-e44d-46af-be1b-cbacea2c3065}\SuppressionPolicy
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\Desktop\NameSpace\{e345f35f-9397-435c-8f95-4e922c26259e}\SuppressionPolicy
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\Desktop\NameSpace\{ED228FDF-9EA8-4870-83b1-96b02CFE0D52}\SuppressionPolicy
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\Desktop\NameSpace\{F02C1A0D-BE21-4350-88B0-7367FC96EF3C}\SuppressionPolicy
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{208D2C60-3AEA-1069-A2D7-08002B30309D}\ShellFolder\Attributes
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{208D2C60-3AEA-1069-A2D7-08002B30309D}\ShellFolder\CallForAttributes
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{208D2C60-3AEA-1069-A2D7-08002B30309D}\ShellFolder\RestrictedAttributes
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{208D2C60-3AEA-1069-A2D7-08002B30309D}\ShellFolder\WantsFORDISPLAY
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{208D2C60-3AEA-1069-A2D7-08002B30309D}\ShellFolder\HideFolderVerbs
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{208D2C60-3AEA-1069-A2D7-08002B30309D}\ShellFolder\UseDropHandler
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{208D2C60-3AEA-1069-A2D7-08002B30309D}\ShellFolder\WantsFORPARSING
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{208D2C60-3AEA-1069-A2D7-08002B30309D}\ShellFolder\WantsParseDisplayName
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{208D2C60-3AEA-1069-A2D7-08002B30309D}\ShellFolder\QueryForOverlay
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{208D2C60-3AEA-1069-A2D7-08002B30309D}\ShellFolder\MapNetDriveVerbs
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{208D2C60-3AEA-1069-A2D7-08002B30309D}\ShellFolder\QueryForInfoTip
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{208D2C60-3AEA-1069-A2D7-08002B30309D}\ShellFolder\HideInWebView
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{208D2C60-3AEA-1069-A2D7-08002B30309D}\ShellFolder\HideOnDesktopPerUser
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{208D2C60-3AEA-1069-A2D7-08002B30309D}\ShellFolder\WantsAliasedNotifications
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{208D2C60-3AEA-1069-A2D7-08002B30309D}\ShellFolder\WantsUniversalDelegate
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{208D2C60-3AEA-1069-A2D7-08002B30309D}\ShellFolder\NoFileFolderJunction
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{208D2C60-3AEA-1069-A2D7-08002B30309D}\ShellFolder\PinToNameSpaceTree
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{208D2C60-3AEA-1069-A2D7-08002B30309D}\ShellFolder\HasNavigationEnum
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\NonEnum\{208D2C60-3AEA-1069-A2D7-08002B30309D}
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{871C5380-42A0-1069-A2EA-08002B30309D}\ShellFolder\Attributes
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{871C5380-42A0-1069-A2EA-08002B30309D}\ShellFolder\CallForAttributes
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{871C5380-42A0-1069-A2EA-08002B30309D}\ShellFolder\RestrictedAttributes
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{871C5380-42A0-1069-A2EA-08002B30309D}\ShellFolder\WantsFORDISPLAY
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{871C5380-42A0-1069-A2EA-08002B30309D}\ShellFolder\HideFolderVerbs
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{871C5380-42A0-1069-A2EA-08002B30309D}\ShellFolder\UseDropHandler
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{871C5380-42A0-1069-A2EA-08002B30309D}\ShellFolder\WantsFORPARSING
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{871C5380-42A0-1069-A2EA-08002B30309D}\ShellFolder\WantsParseDisplayName
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{871C5380-42A0-1069-A2EA-08002B30309D}\ShellFolder\QueryForOverlay
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{871C5380-42A0-1069-A2EA-08002B30309D}\ShellFolder\MapNetDriveVerbs
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{871C5380-42A0-1069-A2EA-08002B30309D}\ShellFolder\QueryForInfoTip
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{871C5380-42A0-1069-A2EA-08002B30309D}\ShellFolder\HideInWebView
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{871C5380-42A0-1069-A2EA-08002B30309D}\ShellFolder\HideOnDesktopPerUser
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{871C5380-42A0-1069-A2EA-08002B30309D}\ShellFolder\WantsAliasedNotifications
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{871C5380-42A0-1069-A2EA-08002B30309D}\ShellFolder\WantsUniversalDelegate
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{871C5380-42A0-1069-A2EA-08002B30309D}\ShellFolder\NoFileFolderJunction
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{871C5380-42A0-1069-A2EA-08002B30309D}\ShellFolder\PinToNameSpaceTree
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{871C5380-42A0-1069-A2EA-08002B30309D}\ShellFolder\HasNavigationEnum
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\CLSID\{871C5380-42A0-1069-A2EA-08002B30309D}\ShellFolder\Attributes
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\NonEnum\{871C5380-42A0-1069-A2EA-08002B30309D}
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{871C5380-42A0-1069-A2EA-08002B30309D}\InProcServer32\(Default)
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{871C5380-42A0-1069-A2EA-08002B30309D}\InProcServer32\LoadWithoutCOM
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Cached\{871C5380-42A0-1069-A2EA-08002B30309D} {000214E6-0000-0000-C000-000000000046} 0xFFFF
  • HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\SQMClient\Windows\CEIPEnable
  • HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\CreateUriCacheSize
  • HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\CreateUriCacheSize
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\CreateUriCacheSize
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Internet Settings\CreateUriCacheSize
  • HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\EnablePunycode
  • HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\EnablePunycode
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\EnablePunycode
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\MAIN\FeatureControl\FEATURE_HTTP_USERNAME_PASSWORD_DISABLE\MasterZ_Custom_93.exe
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\MAIN\FeatureControl\FEATURE_HTTP_USERNAME_PASSWORD_DISABLE\*
  • HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Security_HKLM_only
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{645FF040-5081-101B-9F08-00AA002F954E}\ShellFolder\Attributes
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{645FF040-5081-101B-9F08-00AA002F954E}\ShellFolder\CallForAttributes
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{645FF040-5081-101B-9F08-00AA002F954E}\ShellFolder\RestrictedAttributes
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{645FF040-5081-101B-9F08-00AA002F954E}\ShellFolder\WantsFORDISPLAY
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{645FF040-5081-101B-9F08-00AA002F954E}\ShellFolder\HideFolderVerbs
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{645FF040-5081-101B-9F08-00AA002F954E}\ShellFolder\UseDropHandler
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{645FF040-5081-101B-9F08-00AA002F954E}\ShellFolder\WantsFORPARSING
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{645FF040-5081-101B-9F08-00AA002F954E}\ShellFolder\WantsParseDisplayName
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{645FF040-5081-101B-9F08-00AA002F954E}\ShellFolder\QueryForOverlay
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{645FF040-5081-101B-9F08-00AA002F954E}\ShellFolder\MapNetDriveVerbs
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{645FF040-5081-101B-9F08-00AA002F954E}\ShellFolder\QueryForInfoTip
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{645FF040-5081-101B-9F08-00AA002F954E}\ShellFolder\HideInWebView
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{645FF040-5081-101B-9F08-00AA002F954E}\ShellFolder\HideOnDesktopPerUser
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{645FF040-5081-101B-9F08-00AA002F954E}\ShellFolder\WantsAliasedNotifications
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{645FF040-5081-101B-9F08-00AA002F954E}\ShellFolder\WantsUniversalDelegate
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{645FF040-5081-101B-9F08-00AA002F954E}\ShellFolder\NoFileFolderJunction
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{645FF040-5081-101B-9F08-00AA002F954E}\ShellFolder\PinToNameSpaceTree
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{645FF040-5081-101B-9F08-00AA002F954E}\ShellFolder\HasNavigationEnum
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\NonEnum\{645FF040-5081-101B-9F08-00AA002F954E}
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{26EE0668-A00A-44D7-9371-BEB064C98683}\ShellFolder\Attributes
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{26EE0668-A00A-44D7-9371-BEB064C98683}\ShellFolder\CallForAttributes
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{26EE0668-A00A-44D7-9371-BEB064C98683}\ShellFolder\RestrictedAttributes
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{26EE0668-A00A-44D7-9371-BEB064C98683}\ShellFolder\WantsFORDISPLAY
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{26EE0668-A00A-44D7-9371-BEB064C98683}\ShellFolder\HideFolderVerbs
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{26EE0668-A00A-44D7-9371-BEB064C98683}\ShellFolder\UseDropHandler
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{26EE0668-A00A-44D7-9371-BEB064C98683}\ShellFolder\WantsFORPARSING
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{26EE0668-A00A-44D7-9371-BEB064C98683}\ShellFolder\WantsParseDisplayName
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{26EE0668-A00A-44D7-9371-BEB064C98683}\ShellFolder\QueryForOverlay
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{26EE0668-A00A-44D7-9371-BEB064C98683}\ShellFolder\MapNetDriveVerbs
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{26EE0668-A00A-44D7-9371-BEB064C98683}\ShellFolder\QueryForInfoTip
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{26EE0668-A00A-44D7-9371-BEB064C98683}\ShellFolder\HideInWebView
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{26EE0668-A00A-44D7-9371-BEB064C98683}\ShellFolder\HideOnDesktopPerUser
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{26EE0668-A00A-44D7-9371-BEB064C98683}\ShellFolder\WantsAliasedNotifications
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{26EE0668-A00A-44D7-9371-BEB064C98683}\ShellFolder\WantsUniversalDelegate
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{26EE0668-A00A-44D7-9371-BEB064C98683}\ShellFolder\NoFileFolderJunction
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{26EE0668-A00A-44D7-9371-BEB064C98683}\ShellFolder\PinToNameSpaceTree
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{26EE0668-A00A-44D7-9371-BEB064C98683}\ShellFolder\HasNavigationEnum
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\NonEnum\{26EE0668-A00A-44D7-9371-BEB064C98683}
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{031E4825-7B94-4DC3-B131-E946B44C8DD5}\ShellFolder\Attributes
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{031E4825-7B94-4DC3-B131-E946B44C8DD5}\ShellFolder\CallForAttributes
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{031E4825-7B94-4DC3-B131-E946B44C8DD5}\ShellFolder\RestrictedAttributes
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{031E4825-7B94-4DC3-B131-E946B44C8DD5}\ShellFolder\WantsFORDISPLAY
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{031E4825-7B94-4DC3-B131-E946B44C8DD5}\ShellFolder\HideFolderVerbs
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{031E4825-7B94-4DC3-B131-E946B44C8DD5}\ShellFolder\UseDropHandler
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{031E4825-7B94-4DC3-B131-E946B44C8DD5}\ShellFolder\WantsFORPARSING
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{031E4825-7B94-4DC3-B131-E946B44C8DD5}\ShellFolder\WantsParseDisplayName
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{031E4825-7B94-4DC3-B131-E946B44C8DD5}\ShellFolder\QueryForOverlay
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{031E4825-7B94-4DC3-B131-E946B44C8DD5}\ShellFolder\MapNetDriveVerbs
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{031E4825-7B94-4DC3-B131-E946B44C8DD5}\ShellFolder\QueryForInfoTip
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{031E4825-7B94-4DC3-B131-E946B44C8DD5}\ShellFolder\HideInWebView
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{031E4825-7B94-4DC3-B131-E946B44C8DD5}\ShellFolder\HideOnDesktopPerUser
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{031E4825-7B94-4DC3-B131-E946B44C8DD5}\ShellFolder\WantsAliasedNotifications
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{031E4825-7B94-4DC3-B131-E946B44C8DD5}\ShellFolder\WantsUniversalDelegate
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{031E4825-7B94-4DC3-B131-E946B44C8DD5}\ShellFolder\NoFileFolderJunction
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{031E4825-7B94-4DC3-B131-E946B44C8DD5}\ShellFolder\PinToNameSpaceTree
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{031E4825-7B94-4DC3-B131-E946B44C8DD5}\ShellFolder\HasNavigationEnum
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\NonEnum\{031E4825-7B94-4DC3-B131-E946B44C8DD5}
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{04731B67-D933-450A-90E6-4ACD2E9408FE}\ShellFolder\Attributes
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{04731B67-D933-450A-90E6-4ACD2E9408FE}\ShellFolder\CallForAttributes
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{04731B67-D933-450A-90E6-4ACD2E9408FE}\ShellFolder\RestrictedAttributes
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{04731B67-D933-450A-90E6-4ACD2E9408FE}\ShellFolder\WantsFORDISPLAY
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{04731B67-D933-450A-90E6-4ACD2E9408FE}\ShellFolder\HideFolderVerbs
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{04731B67-D933-450A-90E6-4ACD2E9408FE}\ShellFolder\UseDropHandler
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{04731B67-D933-450A-90E6-4ACD2E9408FE}\ShellFolder\WantsFORPARSING
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{04731B67-D933-450A-90E6-4ACD2E9408FE}\ShellFolder\WantsParseDisplayName
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{04731B67-D933-450A-90E6-4ACD2E9408FE}\ShellFolder\QueryForOverlay
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{04731B67-D933-450A-90E6-4ACD2E9408FE}\ShellFolder\MapNetDriveVerbs
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{04731B67-D933-450A-90E6-4ACD2E9408FE}\ShellFolder\QueryForInfoTip
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{04731B67-D933-450A-90E6-4ACD2E9408FE}\ShellFolder\HideInWebView
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{04731B67-D933-450A-90E6-4ACD2E9408FE}\ShellFolder\HideOnDesktopPerUser
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{04731B67-D933-450A-90E6-4ACD2E9408FE}\ShellFolder\WantsAliasedNotifications
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{04731B67-D933-450A-90E6-4ACD2E9408FE}\ShellFolder\WantsUniversalDelegate
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{04731B67-D933-450A-90E6-4ACD2E9408FE}\ShellFolder\NoFileFolderJunction
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{04731B67-D933-450A-90E6-4ACD2E9408FE}\ShellFolder\PinToNameSpaceTree
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{04731B67-D933-450A-90E6-4ACD2E9408FE}\ShellFolder\HasNavigationEnum
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\NonEnum\{04731B67-D933-450A-90E6-4ACD2E9408FE}
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{11016101-E366-4D22-BC06-4ADA335C892B}\ShellFolder\Attributes
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{11016101-E366-4D22-BC06-4ADA335C892B}\ShellFolder\CallForAttributes
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{11016101-E366-4D22-BC06-4ADA335C892B}\ShellFolder\RestrictedAttributes
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{11016101-E366-4D22-BC06-4ADA335C892B}\ShellFolder\WantsFORDISPLAY
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{11016101-E366-4D22-BC06-4ADA335C892B}\ShellFolder\HideFolderVerbs
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{11016101-E366-4D22-BC06-4ADA335C892B}\ShellFolder\UseDropHandler
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{11016101-E366-4D22-BC06-4ADA335C892B}\ShellFolder\WantsFORPARSING
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{11016101-E366-4D22-BC06-4ADA335C892B}\ShellFolder\WantsParseDisplayName
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{11016101-E366-4D22-BC06-4ADA335C892B}\ShellFolder\QueryForOverlay
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{11016101-E366-4D22-BC06-4ADA335C892B}\ShellFolder\MapNetDriveVerbs
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{11016101-E366-4D22-BC06-4ADA335C892B}\ShellFolder\QueryForInfoTip
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{11016101-E366-4D22-BC06-4ADA335C892B}\ShellFolder\HideInWebView
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{11016101-E366-4D22-BC06-4ADA335C892B}\ShellFolder\HideOnDesktopPerUser
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{11016101-E366-4D22-BC06-4ADA335C892B}\ShellFolder\WantsAliasedNotifications
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{11016101-E366-4D22-BC06-4ADA335C892B}\ShellFolder\WantsUniversalDelegate
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{11016101-E366-4D22-BC06-4ADA335C892B}\ShellFolder\NoFileFolderJunction
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{11016101-E366-4D22-BC06-4ADA335C892B}\ShellFolder\PinToNameSpaceTree
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{11016101-E366-4D22-BC06-4ADA335C892B}\ShellFolder\HasNavigationEnum
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\NonEnum\{11016101-E366-4D22-BC06-4ADA335C892B}
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{138508BC-1E03-49EA-9C8F-EA9E1D05D65D}\ShellFolder\Attributes
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{138508BC-1E03-49EA-9C8F-EA9E1D05D65D}\ShellFolder\CallForAttributes
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{138508BC-1E03-49EA-9C8F-EA9E1D05D65D}\ShellFolder\RestrictedAttributes
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{138508BC-1E03-49EA-9C8F-EA9E1D05D65D}\ShellFolder\WantsFORDISPLAY
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{138508BC-1E03-49EA-9C8F-EA9E1D05D65D}\ShellFolder\HideFolderVerbs
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{138508BC-1E03-49EA-9C8F-EA9E1D05D65D}\ShellFolder\UseDropHandler
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{138508BC-1E03-49EA-9C8F-EA9E1D05D65D}\ShellFolder\WantsFORPARSING
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{138508BC-1E03-49EA-9C8F-EA9E1D05D65D}\ShellFolder\WantsParseDisplayName
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{138508BC-1E03-49EA-9C8F-EA9E1D05D65D}\ShellFolder\QueryForOverlay
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{138508BC-1E03-49EA-9C8F-EA9E1D05D65D}\ShellFolder\MapNetDriveVerbs
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{138508BC-1E03-49EA-9C8F-EA9E1D05D65D}\ShellFolder\QueryForInfoTip
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{138508BC-1E03-49EA-9C8F-EA9E1D05D65D}\ShellFolder\HideInWebView
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{138508BC-1E03-49EA-9C8F-EA9E1D05D65D}\ShellFolder\HideOnDesktopPerUser
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{138508BC-1E03-49EA-9C8F-EA9E1D05D65D}\ShellFolder\WantsAliasedNotifications
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{138508BC-1E03-49EA-9C8F-EA9E1D05D65D}\ShellFolder\WantsUniversalDelegate
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{138508BC-1E03-49EA-9C8F-EA9E1D05D65D}\ShellFolder\NoFileFolderJunction
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{138508BC-1E03-49EA-9C8F-EA9E1D05D65D}\ShellFolder\PinToNameSpaceTree
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{138508BC-1E03-49EA-9C8F-EA9E1D05D65D}\ShellFolder\HasNavigationEnum
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\NonEnum\{138508BC-1E03-49EA-9C8F-EA9E1D05D65D}
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{4336A54D-038B-4685-AB02-99BB52D3FB8B}\ShellFolder\Attributes
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{4336A54D-038B-4685-AB02-99BB52D3FB8B}\ShellFolder\CallForAttributes
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{4336A54D-038B-4685-AB02-99BB52D3FB8B}\ShellFolder\RestrictedAttributes
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{4336A54D-038B-4685-AB02-99BB52D3FB8B}\ShellFolder\WantsFORDISPLAY
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{4336A54D-038B-4685-AB02-99BB52D3FB8B}\ShellFolder\HideFolderVerbs
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{4336A54D-038B-4685-AB02-99BB52D3FB8B}\ShellFolder\UseDropHandler
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{4336A54D-038B-4685-AB02-99BB52D3FB8B}\ShellFolder\WantsFORPARSING
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{4336A54D-038B-4685-AB02-99BB52D3FB8B}\ShellFolder\WantsParseDisplayName
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{4336A54D-038B-4685-AB02-99BB52D3FB8B}\ShellFolder\QueryForOverlay
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{4336A54D-038B-4685-AB02-99BB52D3FB8B}\ShellFolder\MapNetDriveVerbs
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{4336A54D-038B-4685-AB02-99BB52D3FB8B}\ShellFolder\QueryForInfoTip
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{4336A54D-038B-4685-AB02-99BB52D3FB8B}\ShellFolder\HideInWebView
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{4336A54D-038B-4685-AB02-99BB52D3FB8B}\ShellFolder\HideOnDesktopPerUser
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{4336A54D-038B-4685-AB02-99BB52D3FB8B}\ShellFolder\WantsAliasedNotifications
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{4336A54D-038B-4685-AB02-99BB52D3FB8B}\ShellFolder\WantsUniversalDelegate
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{4336A54D-038B-4685-AB02-99BB52D3FB8B}\ShellFolder\NoFileFolderJunction
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{4336A54D-038B-4685-AB02-99BB52D3FB8B}\ShellFolder\PinToNameSpaceTree
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{4336A54D-038B-4685-AB02-99BB52D3FB8B}\ShellFolder\HasNavigationEnum
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\NonEnum\{4336A54D-038B-4685-AB02-99BB52D3FB8B}
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{450D8FBA-AD25-11D0-98A8-0800361B1103}\ShellFolder\Attributes
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{450D8FBA-AD25-11D0-98A8-0800361B1103}\ShellFolder\CallForAttributes
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{450D8FBA-AD25-11D0-98A8-0800361B1103}\ShellFolder\RestrictedAttributes
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{450D8FBA-AD25-11D0-98A8-0800361B1103}\ShellFolder\WantsFORDISPLAY
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{450D8FBA-AD25-11D0-98A8-0800361B1103}\ShellFolder\HideFolderVerbs
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{450D8FBA-AD25-11D0-98A8-0800361B1103}\ShellFolder\UseDropHandler
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{450D8FBA-AD25-11D0-98A8-0800361B1103}\ShellFolder\WantsFORPARSING
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{450D8FBA-AD25-11D0-98A8-0800361B1103}\ShellFolder\WantsParseDisplayName
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{450D8FBA-AD25-11D0-98A8-0800361B1103}\ShellFolder\QueryForOverlay
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{450D8FBA-AD25-11D0-98A8-0800361B1103}\ShellFolder\MapNetDriveVerbs
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{450D8FBA-AD25-11D0-98A8-0800361B1103}\ShellFolder\QueryForInfoTip
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{450D8FBA-AD25-11D0-98A8-0800361B1103}\ShellFolder\HideInWebView
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{450D8FBA-AD25-11D0-98A8-0800361B1103}\ShellFolder\HideOnDesktopPerUser
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{450D8FBA-AD25-11D0-98A8-0800361B1103}\ShellFolder\WantsAliasedNotifications
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{450D8FBA-AD25-11D0-98A8-0800361B1103}\ShellFolder\WantsUniversalDelegate
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{450D8FBA-AD25-11D0-98A8-0800361B1103}\ShellFolder\NoFileFolderJunction
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{450D8FBA-AD25-11D0-98A8-0800361B1103}\ShellFolder\PinToNameSpaceTree
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{450D8FBA-AD25-11D0-98A8-0800361B1103}\ShellFolder\HasNavigationEnum
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\NonEnum\{450D8FBA-AD25-11D0-98A8-0800361B1103}
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{5399E694-6CE5-4D6C-8FCE-1D8870FDCBA0}\ShellFolder\Attributes
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{5399E694-6CE5-4D6C-8FCE-1D8870FDCBA0}\ShellFolder\CallForAttributes
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{5399E694-6CE5-4D6C-8FCE-1D8870FDCBA0}\ShellFolder\RestrictedAttributes
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{5399E694-6CE5-4D6C-8FCE-1D8870FDCBA0}\ShellFolder\WantsFORDISPLAY
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{5399E694-6CE5-4D6C-8FCE-1D8870FDCBA0}\ShellFolder\HideFolderVerbs
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{5399E694-6CE5-4D6C-8FCE-1D8870FDCBA0}\ShellFolder\UseDropHandler
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{5399E694-6CE5-4D6C-8FCE-1D8870FDCBA0}\ShellFolder\WantsFORPARSING
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{5399E694-6CE5-4D6C-8FCE-1D8870FDCBA0}\ShellFolder\WantsParseDisplayName
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{5399E694-6CE5-4D6C-8FCE-1D8870FDCBA0}\ShellFolder\QueryForOverlay
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{5399E694-6CE5-4D6C-8FCE-1D8870FDCBA0}\ShellFolder\MapNetDriveVerbs
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{5399E694-6CE5-4D6C-8FCE-1D8870FDCBA0}\ShellFolder\QueryForInfoTip
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{5399E694-6CE5-4D6C-8FCE-1D8870FDCBA0}\ShellFolder\HideInWebView
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{5399E694-6CE5-4D6C-8FCE-1D8870FDCBA0}\ShellFolder\HideOnDesktopPerUser
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{5399E694-6CE5-4D6C-8FCE-1D8870FDCBA0}\ShellFolder\WantsAliasedNotifications
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{5399E694-6CE5-4D6C-8FCE-1D8870FDCBA0}\ShellFolder\WantsUniversalDelegate
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{5399E694-6CE5-4D6C-8FCE-1D8870FDCBA0}\ShellFolder\NoFileFolderJunction
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{5399E694-6CE5-4D6C-8FCE-1D8870FDCBA0}\ShellFolder\PinToNameSpaceTree
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{5399E694-6CE5-4D6C-8FCE-1D8870FDCBA0}\ShellFolder\HasNavigationEnum
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\NonEnum\{5399E694-6CE5-4D6C-8FCE-1D8870FDCBA0}
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{89D83576-6BD1-4C86-9454-BEB04E94C819}\ShellFolder\Attributes
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{89D83576-6BD1-4C86-9454-BEB04E94C819}\ShellFolder\CallForAttributes
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{89D83576-6BD1-4C86-9454-BEB04E94C819}\ShellFolder\RestrictedAttributes
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{89D83576-6BD1-4C86-9454-BEB04E94C819}\ShellFolder\WantsFORDISPLAY
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{89D83576-6BD1-4C86-9454-BEB04E94C819}\ShellFolder\HideFolderVerbs
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{89D83576-6BD1-4C86-9454-BEB04E94C819}\ShellFolder\UseDropHandler
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{89D83576-6BD1-4C86-9454-BEB04E94C819}\ShellFolder\WantsFORPARSING
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{89D83576-6BD1-4C86-9454-BEB04E94C819}\ShellFolder\WantsParseDisplayName
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{89D83576-6BD1-4C86-9454-BEB04E94C819}\ShellFolder\QueryForOverlay
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{89D83576-6BD1-4C86-9454-BEB04E94C819}\ShellFolder\MapNetDriveVerbs
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{89D83576-6BD1-4C86-9454-BEB04E94C819}\ShellFolder\QueryForInfoTip
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{89D83576-6BD1-4C86-9454-BEB04E94C819}\ShellFolder\HideInWebView
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{89D83576-6BD1-4C86-9454-BEB04E94C819}\ShellFolder\HideOnDesktopPerUser
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{89D83576-6BD1-4C86-9454-BEB04E94C819}\ShellFolder\WantsAliasedNotifications
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{89D83576-6BD1-4C86-9454-BEB04E94C819}\ShellFolder\WantsUniversalDelegate
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{89D83576-6BD1-4C86-9454-BEB04E94C819}\ShellFolder\NoFileFolderJunction
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{89D83576-6BD1-4C86-9454-BEB04E94C819}\ShellFolder\PinToNameSpaceTree
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{89D83576-6BD1-4C86-9454-BEB04E94C819}\ShellFolder\HasNavigationEnum
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\NonEnum\{89D83576-6BD1-4C86-9454-BEB04E94C819}
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{9343812E-1C37-4A49-A12E-4B2D810D956B}\ShellFolder\Attributes
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{9343812E-1C37-4A49-A12E-4B2D810D956B}\ShellFolder\CallForAttributes
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{9343812E-1C37-4A49-A12E-4B2D810D956B}\ShellFolder\RestrictedAttributes
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{9343812E-1C37-4A49-A12E-4B2D810D956B}\ShellFolder\WantsFORDISPLAY
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{9343812E-1C37-4A49-A12E-4B2D810D956B}\ShellFolder\HideFolderVerbs
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{9343812E-1C37-4A49-A12E-4B2D810D956B}\ShellFolder\UseDropHandler
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{9343812E-1C37-4A49-A12E-4B2D810D956B}\ShellFolder\WantsFORPARSING
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{9343812E-1C37-4A49-A12E-4B2D810D956B}\ShellFolder\WantsParseDisplayName
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{9343812E-1C37-4A49-A12E-4B2D810D956B}\ShellFolder\QueryForOverlay
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{9343812E-1C37-4A49-A12E-4B2D810D956B}\ShellFolder\MapNetDriveVerbs
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{9343812E-1C37-4A49-A12E-4B2D810D956B}\ShellFolder\QueryForInfoTip
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{9343812E-1C37-4A49-A12E-4B2D810D956B}\ShellFolder\HideInWebView
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{9343812E-1C37-4A49-A12E-4B2D810D956B}\ShellFolder\HideOnDesktopPerUser
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{9343812E-1C37-4A49-A12E-4B2D810D956B}\ShellFolder\WantsAliasedNotifications
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{9343812E-1C37-4A49-A12E-4B2D810D956B}\ShellFolder\WantsUniversalDelegate
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{9343812E-1C37-4A49-A12E-4B2D810D956B}\ShellFolder\NoFileFolderJunction
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{9343812E-1C37-4A49-A12E-4B2D810D956B}\ShellFolder\PinToNameSpaceTree
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{9343812E-1C37-4A49-A12E-4B2D810D956B}\ShellFolder\HasNavigationEnum
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\NonEnum\{9343812E-1C37-4A49-A12E-4B2D810D956B}
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{B0FBD52D-C4A7-4A19-985D-11309D1AC8AE}\ShellFolder\Attributes
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{B0FBD52D-C4A7-4A19-985D-11309D1AC8AE}\ShellFolder\CallForAttributes
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{B0FBD52D-C4A7-4A19-985D-11309D1AC8AE}\ShellFolder\RestrictedAttributes
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{B0FBD52D-C4A7-4A19-985D-11309D1AC8AE}\ShellFolder\WantsFORDISPLAY
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{B0FBD52D-C4A7-4A19-985D-11309D1AC8AE}\ShellFolder\HideFolderVerbs
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{B0FBD52D-C4A7-4A19-985D-11309D1AC8AE}\ShellFolder\UseDropHandler
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{B0FBD52D-C4A7-4A19-985D-11309D1AC8AE}\ShellFolder\WantsFORPARSING
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{B0FBD52D-C4A7-4A19-985D-11309D1AC8AE}\ShellFolder\WantsParseDisplayName
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{B0FBD52D-C4A7-4A19-985D-11309D1AC8AE}\ShellFolder\QueryForOverlay
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{B0FBD52D-C4A7-4A19-985D-11309D1AC8AE}\ShellFolder\MapNetDriveVerbs
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{B0FBD52D-C4A7-4A19-985D-11309D1AC8AE}\ShellFolder\QueryForInfoTip
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{B0FBD52D-C4A7-4A19-985D-11309D1AC8AE}\ShellFolder\HideInWebView
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{B0FBD52D-C4A7-4A19-985D-11309D1AC8AE}\ShellFolder\HideOnDesktopPerUser
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{B0FBD52D-C4A7-4A19-985D-11309D1AC8AE}\ShellFolder\WantsAliasedNotifications
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{B0FBD52D-C4A7-4A19-985D-11309D1AC8AE}\ShellFolder\WantsUniversalDelegate
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{B0FBD52D-C4A7-4A19-985D-11309D1AC8AE}\ShellFolder\NoFileFolderJunction
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{B0FBD52D-C4A7-4A19-985D-11309D1AC8AE}\ShellFolder\PinToNameSpaceTree
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{B0FBD52D-C4A7-4A19-985D-11309D1AC8AE}\ShellFolder\HasNavigationEnum
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\NonEnum\{B0FBD52D-C4A7-4A19-985D-11309D1AC8AE}
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{B4FB3F98-C1EA-428D-A78A-D1F5659CBA93}\ShellFolder\Attributes
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{B4FB3F98-C1EA-428D-A78A-D1F5659CBA93}\ShellFolder\CallForAttributes
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{B4FB3F98-C1EA-428D-A78A-D1F5659CBA93}\ShellFolder\RestrictedAttributes
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{B4FB3F98-C1EA-428D-A78A-D1F5659CBA93}\ShellFolder\WantsFORDISPLAY
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{B4FB3F98-C1EA-428D-A78A-D1F5659CBA93}\ShellFolder\HideFolderVerbs
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{B4FB3F98-C1EA-428D-A78A-D1F5659CBA93}\ShellFolder\UseDropHandler
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{B4FB3F98-C1EA-428D-A78A-D1F5659CBA93}\ShellFolder\WantsFORPARSING
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{B4FB3F98-C1EA-428D-A78A-D1F5659CBA93}\ShellFolder\WantsParseDisplayName
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{B4FB3F98-C1EA-428D-A78A-D1F5659CBA93}\ShellFolder\QueryForOverlay
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{B4FB3F98-C1EA-428D-A78A-D1F5659CBA93}\ShellFolder\MapNetDriveVerbs
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{B4FB3F98-C1EA-428D-A78A-D1F5659CBA93}\ShellFolder\QueryForInfoTip
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{B4FB3F98-C1EA-428D-A78A-D1F5659CBA93}\ShellFolder\HideInWebView
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{B4FB3F98-C1EA-428D-A78A-D1F5659CBA93}\ShellFolder\HideOnDesktopPerUser
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{B4FB3F98-C1EA-428D-A78A-D1F5659CBA93}\ShellFolder\WantsAliasedNotifications
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{B4FB3F98-C1EA-428D-A78A-D1F5659CBA93}\ShellFolder\WantsUniversalDelegate
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{B4FB3F98-C1EA-428D-A78A-D1F5659CBA93}\ShellFolder\NoFileFolderJunction
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{B4FB3F98-C1EA-428D-A78A-D1F5659CBA93}\ShellFolder\PinToNameSpaceTree
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{B4FB3F98-C1EA-428D-A78A-D1F5659CBA93}\ShellFolder\HasNavigationEnum
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\NonEnum\{B4FB3F98-C1EA-428D-A78A-D1F5659CBA93}
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{BD7A2E7B-21CB-41B2-A086-B309680C6B7E}\ShellFolder\Attributes
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{BD7A2E7B-21CB-41B2-A086-B309680C6B7E}\ShellFolder\CallForAttributes
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{BD7A2E7B-21CB-41B2-A086-B309680C6B7E}\ShellFolder\RestrictedAttributes
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{BD7A2E7B-21CB-41B2-A086-B309680C6B7E}\ShellFolder\WantsFORDISPLAY
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{BD7A2E7B-21CB-41B2-A086-B309680C6B7E}\ShellFolder\HideFolderVerbs
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{BD7A2E7B-21CB-41B2-A086-B309680C6B7E}\ShellFolder\UseDropHandler
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{BD7A2E7B-21CB-41B2-A086-B309680C6B7E}\ShellFolder\WantsFORPARSING
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{BD7A2E7B-21CB-41B2-A086-B309680C6B7E}\ShellFolder\WantsParseDisplayName
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{BD7A2E7B-21CB-41B2-A086-B309680C6B7E}\ShellFolder\QueryForOverlay
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{BD7A2E7B-21CB-41B2-A086-B309680C6B7E}\ShellFolder\MapNetDriveVerbs
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{BD7A2E7B-21CB-41B2-A086-B309680C6B7E}\ShellFolder\QueryForInfoTip
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{BD7A2E7B-21CB-41B2-A086-B309680C6B7E}\ShellFolder\HideInWebView
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{BD7A2E7B-21CB-41B2-A086-B309680C6B7E}\ShellFolder\HideOnDesktopPerUser
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{BD7A2E7B-21CB-41B2-A086-B309680C6B7E}\ShellFolder\WantsAliasedNotifications
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{BD7A2E7B-21CB-41B2-A086-B309680C6B7E}\ShellFolder\WantsUniversalDelegate
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{BD7A2E7B-21CB-41B2-A086-B309680C6B7E}\ShellFolder\NoFileFolderJunction
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{BD7A2E7B-21CB-41B2-A086-B309680C6B7E}\ShellFolder\PinToNameSpaceTree
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{BD7A2E7B-21CB-41B2-A086-B309680C6B7E}\ShellFolder\HasNavigationEnum
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\NonEnum\{BD7A2E7B-21CB-41B2-A086-B309680C6B7E}
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{DAF95313-E44D-46AF-BE1B-CBACEA2C3065}\ShellFolder\Attributes
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{DAF95313-E44D-46AF-BE1B-CBACEA2C3065}\ShellFolder\CallForAttributes
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{DAF95313-E44D-46AF-BE1B-CBACEA2C3065}\ShellFolder\RestrictedAttributes
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{DAF95313-E44D-46AF-BE1B-CBACEA2C3065}\ShellFolder\WantsFORDISPLAY
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{DAF95313-E44D-46AF-BE1B-CBACEA2C3065}\ShellFolder\HideFolderVerbs
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{DAF95313-E44D-46AF-BE1B-CBACEA2C3065}\ShellFolder\UseDropHandler
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{DAF95313-E44D-46AF-BE1B-CBACEA2C3065}\ShellFolder\WantsFORPARSING
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{DAF95313-E44D-46AF-BE1B-CBACEA2C3065}\ShellFolder\WantsParseDisplayName
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{DAF95313-E44D-46AF-BE1B-CBACEA2C3065}\ShellFolder\QueryForOverlay
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{DAF95313-E44D-46AF-BE1B-CBACEA2C3065}\ShellFolder\MapNetDriveVerbs
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{DAF95313-E44D-46AF-BE1B-CBACEA2C3065}\ShellFolder\QueryForInfoTip
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{DAF95313-E44D-46AF-BE1B-CBACEA2C3065}\ShellFolder\HideInWebView
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{DAF95313-E44D-46AF-BE1B-CBACEA2C3065}\ShellFolder\HideOnDesktopPerUser
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{DAF95313-E44D-46AF-BE1B-CBACEA2C3065}\ShellFolder\WantsAliasedNotifications
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{DAF95313-E44D-46AF-BE1B-CBACEA2C3065}\ShellFolder\WantsUniversalDelegate
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{DAF95313-E44D-46AF-BE1B-CBACEA2C3065}\ShellFolder\NoFileFolderJunction
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{DAF95313-E44D-46AF-BE1B-CBACEA2C3065}\ShellFolder\PinToNameSpaceTree
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{DAF95313-E44D-46AF-BE1B-CBACEA2C3065}\ShellFolder\HasNavigationEnum
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\NonEnum\{DAF95313-E44D-46AF-BE1B-CBACEA2C3065}
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{E345F35F-9397-435C-8F95-4E922C26259E}\ShellFolder\Attributes
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{E345F35F-9397-435C-8F95-4E922C26259E}\ShellFolder\CallForAttributes
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{E345F35F-9397-435C-8F95-4E922C26259E}\ShellFolder\RestrictedAttributes
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{E345F35F-9397-435C-8F95-4E922C26259E}\ShellFolder\WantsFORDISPLAY
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{E345F35F-9397-435C-8F95-4E922C26259E}\ShellFolder\HideFolderVerbs
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{E345F35F-9397-435C-8F95-4E922C26259E}\ShellFolder\UseDropHandler
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{E345F35F-9397-435C-8F95-4E922C26259E}\ShellFolder\WantsFORPARSING
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{E345F35F-9397-435C-8F95-4E922C26259E}\ShellFolder\WantsParseDisplayName
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{E345F35F-9397-435C-8F95-4E922C26259E}\ShellFolder\QueryForOverlay
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{E345F35F-9397-435C-8F95-4E922C26259E}\ShellFolder\MapNetDriveVerbs
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{E345F35F-9397-435C-8F95-4E922C26259E}\ShellFolder\QueryForInfoTip
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{E345F35F-9397-435C-8F95-4E922C26259E}\ShellFolder\HideInWebView
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{E345F35F-9397-435C-8F95-4E922C26259E}\ShellFolder\HideOnDesktopPerUser
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{E345F35F-9397-435C-8F95-4E922C26259E}\ShellFolder\WantsAliasedNotifications
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{E345F35F-9397-435C-8F95-4E922C26259E}\ShellFolder\WantsUniversalDelegate
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{E345F35F-9397-435C-8F95-4E922C26259E}\ShellFolder\NoFileFolderJunction
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{E345F35F-9397-435C-8F95-4E922C26259E}\ShellFolder\PinToNameSpaceTree
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{E345F35F-9397-435C-8F95-4E922C26259E}\ShellFolder\HasNavigationEnum
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\NonEnum\{E345F35F-9397-435C-8F95-4E922C26259E}
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{ED228FDF-9EA8-4870-83B1-96B02CFE0D52}\ShellFolder\Attributes
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{ED228FDF-9EA8-4870-83B1-96B02CFE0D52}\ShellFolder\CallForAttributes
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{ED228FDF-9EA8-4870-83B1-96B02CFE0D52}\ShellFolder\RestrictedAttributes
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{ED228FDF-9EA8-4870-83B1-96B02CFE0D52}\ShellFolder\WantsFORDISPLAY
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{ED228FDF-9EA8-4870-83B1-96B02CFE0D52}\ShellFolder\HideFolderVerbs
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{ED228FDF-9EA8-4870-83B1-96B02CFE0D52}\ShellFolder\UseDropHandler
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{ED228FDF-9EA8-4870-83B1-96B02CFE0D52}\ShellFolder\WantsFORPARSING
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{ED228FDF-9EA8-4870-83B1-96B02CFE0D52}\ShellFolder\WantsParseDisplayName
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{ED228FDF-9EA8-4870-83B1-96B02CFE0D52}\ShellFolder\QueryForOverlay
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{ED228FDF-9EA8-4870-83B1-96B02CFE0D52}\ShellFolder\MapNetDriveVerbs
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{ED228FDF-9EA8-4870-83B1-96B02CFE0D52}\ShellFolder\QueryForInfoTip
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{ED228FDF-9EA8-4870-83B1-96B02CFE0D52}\ShellFolder\HideInWebView
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{ED228FDF-9EA8-4870-83B1-96B02CFE0D52}\ShellFolder\HideOnDesktopPerUser
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{ED228FDF-9EA8-4870-83B1-96B02CFE0D52}\ShellFolder\WantsAliasedNotifications
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{ED228FDF-9EA8-4870-83B1-96B02CFE0D52}\ShellFolder\WantsUniversalDelegate
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{ED228FDF-9EA8-4870-83B1-96B02CFE0D52}\ShellFolder\NoFileFolderJunction
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{ED228FDF-9EA8-4870-83B1-96B02CFE0D52}\ShellFolder\PinToNameSpaceTree
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{ED228FDF-9EA8-4870-83B1-96B02CFE0D52}\ShellFolder\HasNavigationEnum
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\NonEnum\{ED228FDF-9EA8-4870-83B1-96B02CFE0D52}
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{F02C1A0D-BE21-4350-88B0-7367FC96EF3C}\ShellFolder\Attributes
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{F02C1A0D-BE21-4350-88B0-7367FC96EF3C}\ShellFolder\CallForAttributes
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{F02C1A0D-BE21-4350-88B0-7367FC96EF3C}\ShellFolder\RestrictedAttributes
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{F02C1A0D-BE21-4350-88B0-7367FC96EF3C}\ShellFolder\WantsFORDISPLAY
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{F02C1A0D-BE21-4350-88B0-7367FC96EF3C}\ShellFolder\HideFolderVerbs
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{F02C1A0D-BE21-4350-88B0-7367FC96EF3C}\ShellFolder\UseDropHandler
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{F02C1A0D-BE21-4350-88B0-7367FC96EF3C}\ShellFolder\WantsFORPARSING
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{F02C1A0D-BE21-4350-88B0-7367FC96EF3C}\ShellFolder\WantsParseDisplayName
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{F02C1A0D-BE21-4350-88B0-7367FC96EF3C}\ShellFolder\QueryForOverlay
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{F02C1A0D-BE21-4350-88B0-7367FC96EF3C}\ShellFolder\MapNetDriveVerbs
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{F02C1A0D-BE21-4350-88B0-7367FC96EF3C}\ShellFolder\QueryForInfoTip
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{F02C1A0D-BE21-4350-88B0-7367FC96EF3C}\ShellFolder\HideInWebView
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{F02C1A0D-BE21-4350-88B0-7367FC96EF3C}\ShellFolder\HideOnDesktopPerUser
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{F02C1A0D-BE21-4350-88B0-7367FC96EF3C}\ShellFolder\WantsAliasedNotifications
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{F02C1A0D-BE21-4350-88B0-7367FC96EF3C}\ShellFolder\WantsUniversalDelegate
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{F02C1A0D-BE21-4350-88B0-7367FC96EF3C}\ShellFolder\NoFileFolderJunction
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{F02C1A0D-BE21-4350-88B0-7367FC96EF3C}\ShellFolder\PinToNameSpaceTree
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{F02C1A0D-BE21-4350-88B0-7367FC96EF3C}\ShellFolder\HasNavigationEnum
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\NonEnum\{F02C1A0D-BE21-4350-88B0-7367FC96EF3C}
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\AllowFileCLSIDJunctions
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\AllowFileCLSIDJunctions
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\.exe\(Default)
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\exefile\DocObject
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\SystemFileAssociations\.exe\DocObject
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\exefile\BrowseInPlace
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\SystemFileAssociations\.exe\BrowseInPlace
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\.exe\Content Type
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\exefile\IsShortcut
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\SystemFileAssociations\.exe\IsShortcut
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\exefile\AlwaysShowExt
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\SystemFileAssociations\.exe\AlwaysShowExt
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\exefile\NeverShowExt
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\SystemFileAssociations\.exe\NeverShowExt
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\KindMap\.exe
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\exefile\shell\open\command\DelegateExecute
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\.asp\(Default)
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\.bas\(Default)
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\.bat\(Default)
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\.cer\(Default)
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\.chm\(Default)
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\.cmd\(Default)
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\.com\(Default)
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\.cpl\(Default)
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\.crt\(Default)
  • HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Internet Explorer\Security\DisableSecuritySettingsCheck
  • HKEY_LOCAL_MACHINE\SYSTEM\Setup\SystemSetupInProgress
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\0\Flags
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\1\Flags
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\2\Flags
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\3\Flags
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\4\Flags
  • HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_LOCALMACHINE_LOCKDOWN\MasterZ_Custom_93.exe
  • HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_LOCALMACHINE_LOCKDOWN\*
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\MAIN\FeatureControl\FEATURE_LOCALMACHINE_LOCKDOWN\MasterZ_Custom_93.exe
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\MAIN\FeatureControl\FEATURE_LOCALMACHINE_LOCKDOWN\*
  • HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\SpecialFoldersCacheSize
  • HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\SpecialFoldersCacheSize
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\SpecialFoldersCacheSize
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Internet Settings\SpecialFoldersCacheSize
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\MAIN\FeatureControl\FEATURE_PROTOCOL_LOCKDOWN\MasterZ_Custom_93.exe
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\MAIN\FeatureControl\FEATURE_PROTOCOL_LOCKDOWN\*
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\0\1806
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\0\1806
  • HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\safer\codeidentifiers\TransparentEnabled
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\exefile\shell\open\command\command
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\exefile\shell\open\command\(Default)
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\InheritConsoleHandles
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\InheritConsoleHandles
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\RestrictRun
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\RestrictRun
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\DisallowRun
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\DisallowRun
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\exefile\shell\open\SetWorkingDirectoryFromTarget
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\exefile\shell\open\NoWorkingDirectory
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\DllNXOptions\FindProcDLL.dll
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\DllNXOptions\nsExec.dll
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Drive\shellex\FolderExtensions\{fbeb8a05-beee-4442-804e-409d6c4515e9}\DriveMask
  • HKEY_CURRENT_USER\Control Panel\International\sCountry
  • HKEY_CURRENT_USER\Control Panel\International\Locale
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\User Shell Folders\Common Desktop
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\User Shell Folders\Common Documents
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\User Shell Folders\CommonPictures
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\User Shell Folders\CommonMusic
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\User Shell Folders\CommonVideo
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders\{DE92C1C7-837F-4F69-A3BB-86E631204A23}
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders\My Music
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\User Shell Folders\{3D644C9B-1FB8-4F30-9B45-F670235F79C0}
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ProfileList\ProfilesDirectory
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders\Startup
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\User Shell Folders\Common Startup
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ProfileList\Public
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\User Shell Folders\Common Programs
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\ProgramFilesDir
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\CommonFilesDir
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders\{52A4F021-7B75-48A9-9F6B-4B87A210BC8F}
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders\AppData
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\DllNXOptions\InstallOptions.dll
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\Windows Error Reporting\WMR\Disable
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\Hostname
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters\Domain
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{D4781CD6-E5D3-44DF-AD94-930EFE48A887}\ProxyStubClsid32\(Default)
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\zh-Hans
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\ExtendedLocale\zh-Hans
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\zh
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\ExtendedLocale\zh
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\en
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\ExtendedLocale\en
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{9556DC99-828C-11CF-A37E-00AA003240C7}\ProxyStubClsid32\(Default)
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D68AF00A-29CB-43FA-8504-CE99A996D9EA}\(Default)
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D68AF00A-29CB-43FA-8504-CE99A996D9EA}\InprocServer32\InprocServer32
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D68AF00A-29CB-43FA-8504-CE99A996D9EA}\InprocServer32\(Default)
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D68AF00A-29CB-43FA-8504-CE99A996D9EA}\InprocServer32\ThreadingModel
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{027947E1-D731-11CE-A357-000000000001}\ProxyStubClsid32\(Default)
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{1B1CAD8C-2DAB-11D2-B604-00104B703EFD}\(Default)
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{1B1CAD8C-2DAB-11D2-B604-00104B703EFD}\InprocServer32\InprocServer32
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{1B1CAD8C-2DAB-11D2-B604-00104B703EFD}\InprocServer32\(Default)
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{1B1CAD8C-2DAB-11D2-B604-00104B703EFD}\InprocServer32\ThreadingModel
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{1C1C45EE-4395-11D2-B60B-00104B703EFD}\ProxyStubClsid32\(Default)
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{423EC01E-2E35-11D2-B604-00104B703EFD}\ProxyStubClsid32\(Default)
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\WBEM\CIMOM\EnableObjectValidation
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\WBEM\CIMOM\Logging
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\GRE_Initialize\DisableMetaFiles
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Command Processor\DisableUNCCheck
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Command Processor\EnableExtensions
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Command Processor\DelayedExpansion
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Command Processor\DefaultColor
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Command Processor\CompletionChar
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Command Processor\PathCompletionChar
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Command Processor\AutoRun
  • HKEY_CURRENT_USER\Software\Microsoft\Command Processor\DisableUNCCheck
  • HKEY_CURRENT_USER\Software\Microsoft\Command Processor\EnableExtensions
  • HKEY_CURRENT_USER\Software\Microsoft\Command Processor\DelayedExpansion
  • HKEY_CURRENT_USER\Software\Microsoft\Command Processor\DefaultColor
  • HKEY_CURRENT_USER\Software\Microsoft\Command Processor\CompletionChar
  • HKEY_CURRENT_USER\Software\Microsoft\Command Processor\PathCompletionChar
  • HKEY_CURRENT_USER\Software\Microsoft\Command Processor\AutoRun
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows NT\CurrentVersion\CurrentBuildNumber
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\TCPIP6\Parameters\DisabledComponents
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\iphlpsvc\config\Connectivity_Platform_Enabled
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Cryptography\OID\EncodingType 0\CryptDllFindOIDInfo\1.3.6.1.4.1.311.44.3.4!7\Name
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\MUI\StringCacheSettings\StringCacheGeneration
  • HKEY_CURRENT_USER\Software\Classes\Local Settings\MuiCache\4B\AAF68885\@%SystemRoot%\system32\p2pcollab.dll,-8042
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Cryptography\OID\EncodingType 0\CryptDllFindOIDInfo\1.3.6.1.4.1.311.47.1.1!7\Name
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Cryptography\OID\EncodingType 0\CryptDllFindOIDInfo\1.3.6.1.4.1.311.64.1.1!7\Name
  • HKEY_CURRENT_USER\Software\Classes\Local Settings\MuiCache\4B\AAF68885\@%SystemRoot%\system32\dnsapi.dll,-103
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\napagent\LocalConfig\Enable Tracing
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\napagent\LocalConfig\Tracing Level
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\napagent\Qecs\79617\Friendly Name
  • HKEY_CURRENT_USER\Software\Classes\Local Settings\MuiCache\4B\AAF68885\@%SystemRoot%\system32\dhcpqec.dll,-100
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\napagent\Qecs\79617\Description
  • HKEY_CURRENT_USER\Software\Classes\Local Settings\MuiCache\4B\AAF68885\@%SystemRoot%\system32\dhcpqec.dll,-101
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\napagent\Qecs\79617\Version
  • HKEY_CURRENT_USER\Software\Classes\Local Settings\MuiCache\4B\AAF68885\@%SystemRoot%\system32\dhcpqec.dll,-103
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\napagent\Qecs\79617\Enabled
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\napagent\Qecs\79617\Vendor Name
  • HKEY_CURRENT_USER\Software\Classes\Local Settings\MuiCache\4B\AAF68885\@%SystemRoot%\system32\dhcpqec.dll,-102
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\napagent\Qecs\79617\Info Clsid
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\napagent\Qecs\79617\Config Clsid
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\napagent\Qecs\79617\Validator Clsid
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\napagent\Qecs\79617\Registration Date
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\napagent\Qecs\79617\Component Type
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\napagent\Qecs\79619\Friendly Name
  • HKEY_CURRENT_USER\Software\Classes\Local Settings\MuiCache\4B\AAF68885\@%SystemRoot%\system32\napipsec.dll,-1
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\napagent\Qecs\79619\Description
  • HKEY_CURRENT_USER\Software\Classes\Local Settings\MuiCache\4B\AAF68885\@%SystemRoot%\system32\napipsec.dll,-2
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\napagent\Qecs\79619\Version
  • HKEY_CURRENT_USER\Software\Classes\Local Settings\MuiCache\4B\AAF68885\@%SystemRoot%\system32\napipsec.dll,-4
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\napagent\Qecs\79619\Enabled
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\napagent\Qecs\79619\Vendor Name
  • HKEY_CURRENT_USER\Software\Classes\Local Settings\MuiCache\4B\AAF68885\@%SystemRoot%\system32\napipsec.dll,-3
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\napagent\Qecs\79619\Info Clsid
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\napagent\Qecs\79619\Config Clsid
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\napagent\Qecs\79619\Validator Clsid
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\napagent\Qecs\79619\Registration Date
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\napagent\Qecs\79619\Component Type
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\napagent\Qecs\79621\Friendly Name
  • HKEY_CURRENT_USER\Software\Classes\Local Settings\MuiCache\4B\AAF68885\@%SystemRoot%\system32\tsgqec.dll,-100
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\napagent\Qecs\79621\Description
  • HKEY_CURRENT_USER\Software\Classes\Local Settings\MuiCache\4B\AAF68885\@%SystemRoot%\system32\tsgqec.dll,-101
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\napagent\Qecs\79621\Version
  • HKEY_CURRENT_USER\Software\Classes\Local Settings\MuiCache\4B\AAF68885\@%SystemRoot%\system32\tsgqec.dll,-102
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\napagent\Qecs\79621\Enabled
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\napagent\Qecs\79621\Vendor Name
  • HKEY_CURRENT_USER\Software\Classes\Local Settings\MuiCache\4B\AAF68885\@%SystemRoot%\system32\tsgqec.dll,-103
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\napagent\Qecs\79621\Info Clsid
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\napagent\Qecs\79621\Config Clsid
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\napagent\Qecs\79621\Validator Clsid
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\napagent\Qecs\79621\Registration Date
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\napagent\Qecs\79621\Component Type
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\napagent\Qecs\79623\Friendly Name
  • HKEY_CURRENT_USER\Software\Classes\Local Settings\MuiCache\4B\AAF68885\@%SystemRoot%\system32\eapqec.dll,-100
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\napagent\Qecs\79623\Description
  • HKEY_CURRENT_USER\Software\Classes\Local Settings\MuiCache\4B\AAF68885\@%SystemRoot%\system32\eapqec.dll,-101
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\napagent\Qecs\79623\Version
  • HKEY_CURRENT_USER\Software\Classes\Local Settings\MuiCache\4B\AAF68885\@%SystemRoot%\system32\eapqec.dll,-102
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\napagent\Qecs\79623\Enabled
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\napagent\Qecs\79623\Vendor Name
  • HKEY_CURRENT_USER\Software\Classes\Local Settings\MuiCache\4B\AAF68885\@%SystemRoot%\system32\eapqec.dll,-103
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\napagent\Qecs\79623\Info Clsid
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\napagent\Qecs\79623\Config Clsid
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\napagent\Qecs\79623\Validator Clsid
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\napagent\Qecs\79623\Registration Date
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\napagent\Qecs\79623\Component Type
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\napagent\LocalConfig\PlumbIpsecPolicy
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\OLE\AppCompat\RaiseDefaultAuthnLevel
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\OLE\DefaultAccessPermission
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{00000134-0000-0000-C000-000000000046}\ProxyStubClsid32\(Default)
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Rpc\Extensions\RemoteRpcDll
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SQMClient\Windows\DisabledProcesses\F6C4EC9A
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SQMClient\Windows\DisabledSessions\MachineThrottling
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SQMClient\Windows\DisabledSessions\GlobalSession
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows NT\CurrentVersion\Winlogon\UserenvDebugLevel
  • HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\System\GpSvcDebugLevel
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\PeerDist\Service\Enable
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\PeerDist\Service\PolicyRefreshInProgress
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\PeerDist\DownloadManager\TransportDllPath
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\PeerDist\DownloadManager\CryptoAlgo
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\PeerDist\SecurityManager\BlockSize
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\PeerDist\SecurityManager\NumBlocksPerSegment
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\PeerDist\SecurityManager\Restricted\Seed
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\PeerDist\HostedCache\ServerRole
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\PeerDist\HostedCache\ClientAuth
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\PeerDist\HostedCache\TransportDllPath
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\PeerDist\HostedCache\MaxSimultaneousDownloads
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\PeerDist\HostedCache\MaxSimultaneousUploads
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\PeerDist\HostedCache\MaxPendingOffers
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\PeerDist\HostedCache\MaxPendingDownloads
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\PeerDist\HostedCache\DoNotUseSSL
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\PeerDist\DiscoveryManager\RepubQuorumSize
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\PeerDist\DiscoveryManager\MinBackoffWindow
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\PeerDist\DiscoveryManager\DiscoveryProviderDllPath
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\PeerDist\Roaming\ForceRoamingDetect
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\PeerDist\Roaming\RefreshDllName
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\PeerDist\Roaming\RefreshProcName
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Rpc\SecurityService\DefaultAuthLevel
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\HTTP\ObjectName
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\napagent\ImagePath
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\napagent\Type
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\napagent\Start
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\napagent\ErrorControl
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\napagent\Tag
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\napagent\DependOnService
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\napagent\DependOnGroup
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\napagent\Group
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\napagent\ObjectName
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\gpsvc\ImagePath
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\gpsvc\Type
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\gpsvc\Start
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\gpsvc\ErrorControl
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\gpsvc\Tag
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\gpsvc\DependOnService
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\gpsvc\DependOnGroup
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\gpsvc\Group
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\gpsvc\ObjectName
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\DcomLaunch\ObjectName
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\RpcEptMapper\ObjectName
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\RpcSs\ObjectName
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\EventSystem\ObjectName
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\BITS\ObjectName
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\BITS\ImagePath
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\BITS\WOW64
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\BITS\RequiredPrivileges
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\BITS\Type
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\BITS\Start
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\BITS\ErrorControl
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\BITS\Tag
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\BITS\DependOnService
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\BITS\DependOnGroup
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\BITS\Group
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\clr_optimization_v4.0.30319_32\ObjectName
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\clr_optimization_v4.0.30319_32\ImagePath
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\clr_optimization_v4.0.30319_32\WOW64
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ProfileList\ProgramData
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ProfileList\Default
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ProgramFilesDir
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\CommonFilesDir
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ProgramFilesDir (x86)
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\CommonFilesDir (x86)
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ProgramW6432Dir
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\CommonW6432Dir
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ProfileList\S-1-5-18\ProfileImagePath
  • HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders\AppData
  • HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders\Local AppData
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\clr_optimization_v4.0.30319_32\Environment
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\clr_optimization_v4.0.30319_32\RequiredPrivileges
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\clr_optimization_v4.0.30319_64\ObjectName
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\clr_optimization_v4.0.30319_64\ImagePath
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\clr_optimization_v4.0.30319_64\WOW64
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\clr_optimization_v4.0.30319_64\Environment
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\clr_optimization_v4.0.30319_64\RequiredPrivileges
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\FontCache\ObjectName
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\FontCache\ImagePath
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\FontCache\WOW64
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\AppIDSvc\ImagePath
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\AppIDSvc\WOW64
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Appinfo\ImagePath
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Appinfo\WOW64
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\AppMgmt\ImagePath
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\AppMgmt\WOW64
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\AxInstSV\ImagePath
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\AxInstSV\WOW64
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\BDESVC\ImagePath
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\BDESVC\WOW64
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\bthserv\ImagePath
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\bthserv\WOW64
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\dot3svc\ImagePath
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\dot3svc\WOW64
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\EapHost\ImagePath
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\EapHost\WOW64
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\EFS\ImagePath
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\EFS\WOW64
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\fdPHost\ImagePath
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\fdPHost\WOW64
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\FDResPub\ImagePath
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\FDResPub\WOW64
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\hidserv\ImagePath
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\hidserv\WOW64
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\hkmsvc\ImagePath
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\hkmsvc\WOW64
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\HomeGroupListener\ImagePath
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\HomeGroupListener\WOW64
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\HomeGroupProvider\ImagePath
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\HomeGroupProvider\WOW64
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\idsvc\ImagePath
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\idsvc\WOW64
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\IPBusEnum\ImagePath
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\IPBusEnum\WOW64
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\KeyIso\ImagePath
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\KeyIso\WOW64
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\KtmRm\ImagePath
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\KtmRm\WOW64
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\lltdsvc\ImagePath
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\lltdsvc\WOW64
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Mcx2Svc\ImagePath
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Mcx2Svc\WOW64
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\MpsSvc\ImagePath
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\MpsSvc\WOW64
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\MSiSCSI\ImagePath
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\MSiSCSI\WOW64
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\napagent\WOW64
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Netlogon\ImagePath
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Netlogon\WOW64
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\NetMsmqActivator\ImagePath
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\NetMsmqActivator\WOW64
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\NetPipeActivator\ImagePath
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\NetPipeActivator\WOW64
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\NetTcpActivator\ImagePath
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\NetTcpActivator\WOW64
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\NetTcpPortSharing\ImagePath
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\NetTcpPortSharing\WOW64
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\p2pimsvc\ImagePath
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\p2pimsvc\WOW64
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\p2psvc\ImagePath
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\p2psvc\WOW64
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\PeerDistSvc\ImagePath
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\PeerDistSvc\WOW64
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\pla\ImagePath
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\pla\WOW64
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\PNRPAutoReg\ImagePath
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\PNRPAutoReg\WOW64
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\PNRPsvc\ImagePath
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\PNRPsvc\WOW64
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\ProtectedStorage\ImagePath
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\ProtectedStorage\WOW64
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\QWAVE\ImagePath
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\QWAVE\WOW64
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\RasAuto\ImagePath
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\RasAuto\WOW64
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\RasMan\ImagePath
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\RasMan\WOW64
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\RemoteAccess\ImagePath
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\RemoteAccess\WOW64
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\RemoteRegistry\ImagePath
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\RemoteRegistry\WOW64
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\SCardSvr\ImagePath
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\SCardSvr\WOW64
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\SCPolicySvc\ImagePath
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\SCPolicySvc\WOW64
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\seclogon\ImagePath
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\seclogon\WOW64
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\SensrSvc\ImagePath
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\SensrSvc\WOW64
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\SharedAccess\ImagePath
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\SharedAccess\WOW64
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\sppuinotify\ImagePath
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\sppuinotify\WOW64
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\SSDPSRV\ImagePath
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\SSDPSRV\WOW64
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\SstpSvc\ImagePath
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\SstpSvc\WOW64
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\SysMain\ImagePath
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\SysMain\WOW64
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\TabletInputService\ImagePath
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\TabletInputService\WOW64
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\TapiSrv\ImagePath
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\TapiSrv\WOW64
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\TBS\ImagePath
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\TBS\WOW64
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\THREADORDER\ImagePath
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\THREADORDER\WOW64
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\upnphost\ImagePath
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\upnphost\WOW64
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VaultSvc\ImagePath
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VaultSvc\WOW64
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\W32Time\ImagePath
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\W32Time\WOW64
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WbioSrvc\ImagePath
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WbioSrvc\WOW64
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\wcncsvc\ImagePath
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\wcncsvc\WOW64
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WcsPlugInService\ImagePath
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WcsPlugInService\WOW64
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WebClient\ImagePath
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WebClient\WOW64
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Wecsvc\ImagePath
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Wecsvc\WOW64
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\wercplsupport\ImagePath
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\wercplsupport\WOW64
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WerSvc\ImagePath
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WerSvc\WOW64
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WinDefend\ImagePath
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WinDefend\WOW64
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WinHttpAutoProxySvc\ImagePath
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WinHttpAutoProxySvc\WOW64
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WinRM\ImagePath
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WinRM\WOW64
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Wlansvc\ImagePath
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Wlansvc\WOW64
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WPCSvc\ImagePath
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WPCSvc\WOW64
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WPDBusEnum\ImagePath
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WPDBusEnum\WOW64
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\wscsvc\ImagePath
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\wscsvc\WOW64
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\wuauserv\ImagePath
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\wuauserv\WOW64
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\wudfsvc\ImagePath
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\wudfsvc\WOW64
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WwanSvc\ImagePath
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WwanSvc\WOW64
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\AppIDSvc\RequiredPrivileges
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\FDResPub\RequiredPrivileges
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\FontCache\RequiredPrivileges
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Mcx2Svc\RequiredPrivileges
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\QWAVE\RequiredPrivileges
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\SCardSvr\RequiredPrivileges
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\SensrSvc\RequiredPrivileges
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\SSDPSRV\RequiredPrivileges
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\TBS\RequiredPrivileges
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\upnphost\RequiredPrivileges
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\wcncsvc\RequiredPrivileges
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ProfileList\S-1-5-19\ProfileImagePath
  • HKEY_USERS\S-1-5-19\Software\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders\AppData
  • HKEY_USERS\S-1-5-19\Software\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders\Local AppData
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\FontCache\Environment
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\sppsvc\ObjectName
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\sppsvc\ImagePath
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\sppsvc\WOW64
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\sppsvc\RequiredPrivileges
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ProfileList\S-1-5-20\ProfileImagePath
  • HKEY_USERS\S-1-5-20\Software\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders\AppData
  • HKEY_USERS\S-1-5-20\Software\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders\Local AppData
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\sppsvc\Environment
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Winmgmt\ObjectName
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\wscsvc\ObjectName
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\wscsvc\RequiredPrivileges
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\wuauserv\Type
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\wuauserv\Start
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\wuauserv\ErrorControl
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\wuauserv\Tag
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\wuauserv\DependOnService
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\wuauserv\DependOnGroup
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\wuauserv\Group
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\wuauserv\ObjectName
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\wscsvc\Type
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\wscsvc\Start
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\wscsvc\ErrorControl
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\wscsvc\Tag
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\wscsvc\DependOnService
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\wscsvc\DependOnGroup
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\wscsvc\Group
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\.NETFramework\NGenServiceDebugLog
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\.NETFramework\NicPath
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\.NETFramework\RegistryRoot
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\.NETFramework\AssemblyPath
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\.NETFramework\AssemblyPath2
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\NET Framework Setup\NDP\v4\Client\Install
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\.NETFramework\NGEN_USE_PRIVATE_STORE
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\.NETFramework\DefaultVersion
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\.NETFramework\Version
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\.NETFramework\ZapSet
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\.NETFramework\v2.0.50727\NGENService\Roots\WorkPending
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\.NETFramework\v2.0.50727\NGENService\State\PendingUpdate
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\.NETFramework\NGenServiceDebugLog
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\.NETFramework\NicPath
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\.NETFramework\RegistryRoot
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\.NETFramework\AssemblyPath
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\.NETFramework\AssemblyPath2
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\NET Framework Setup\NDP\v4\Client\Install
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\.NETFramework\NGEN_USE_PRIVATE_STORE
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\.NETFramework\DefaultVersion
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\.NETFramework\Version
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\.NETFramework\ZapSet
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\.NETFramework\v2.0.50727\NGENService\Roots\WorkPending
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\.NETFramework\v2.0.50727\NGENService\State\PendingUpdate
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\.dll\(Default)
  • HKEY_CURRENT_USER\Software\Classes\TypeLib\{73F92EE3-0C4F-53E3-8FDA-A571E532950E}\1.0\(Default)
  • HKEY_CURRENT_USER\Software\Classes\TypeLib\{73F92EE3-0C4F-53E3-8FDA-A571E532950E}\1.0\FLAGS\(Default)
  • HKEY_CURRENT_USER\Software\Classes\TypeLib\{73F92EE3-0C4F-53E3-8FDA-A571E532950E}\1.0\0\win32\(Default)
  • HKEY_CURRENT_USER\Software\Classes\TypeLib\{73F92EE3-0C4F-53E3-8FDA-A571E532950E}\1.0\HELPDIR\(Default)
  • HKEY_CURRENT_USER\Software\Classes\Wow6432Node\Interface\{1EE0264C-67B3-5477-953B-CF7F87D70680}\(Default)
  • HKEY_CURRENT_USER\Software\Classes\Wow6432Node\Interface\{1EE0264C-67B3-5477-953B-CF7F87D70680}\ProxyStubClsid32\(Default)
  • HKEY_CURRENT_USER\Software\Classes\Wow6432Node\Interface\{1EE0264C-67B3-5477-953B-CF7F87D70680}\TypeLib\(Default)
  • HKEY_CURRENT_USER\Software\Classes\Wow6432Node\Interface\{1EE0264C-67B3-5477-953B-CF7F87D70680}\TypeLib\Version
  • HKEY_CURRENT_USER\Software\Classes\Interface\{1EE0264C-67B3-5477-953B-CF7F87D70680}\(Default)
  • HKEY_CURRENT_USER\Software\Classes\Interface\{1EE0264C-67B3-5477-953B-CF7F87D70680}\ProxyStubClsid32\(Default)
  • HKEY_CURRENT_USER\Software\Classes\Interface\{1EE0264C-67B3-5477-953B-CF7F87D70680}\TypeLib\(Default)
  • HKEY_CURRENT_USER\Software\Classes\Interface\{1EE0264C-67B3-5477-953B-CF7F87D70680}\TypeLib\Version
  • HKEY_CURRENT_USER\Software\Classes\Wow6432Node\Interface\{BBA8BF1D-8C1E-5C71-8C9E-610A792952D8}\(Default)
  • HKEY_CURRENT_USER\Software\Classes\Wow6432Node\Interface\{BBA8BF1D-8C1E-5C71-8C9E-610A792952D8}\ProxyStubClsid32\(Default)
  • HKEY_CURRENT_USER\Software\Classes\Wow6432Node\Interface\{BBA8BF1D-8C1E-5C71-8C9E-610A792952D8}\TypeLib\(Default)
  • HKEY_CURRENT_USER\Software\Classes\Wow6432Node\Interface\{BBA8BF1D-8C1E-5C71-8C9E-610A792952D8}\TypeLib\Version
  • HKEY_CURRENT_USER\Software\Classes\Interface\{BBA8BF1D-8C1E-5C71-8C9E-610A792952D8}\(Default)
  • HKEY_CURRENT_USER\Software\Classes\Interface\{BBA8BF1D-8C1E-5C71-8C9E-610A792952D8}\ProxyStubClsid32\(Default)
  • HKEY_CURRENT_USER\Software\Classes\Interface\{BBA8BF1D-8C1E-5C71-8C9E-610A792952D8}\TypeLib\(Default)
  • HKEY_CURRENT_USER\Software\Classes\Interface\{BBA8BF1D-8C1E-5C71-8C9E-610A792952D8}\TypeLib\Version
  • HKEY_CURRENT_USER\Software\Classes\Wow6432Node\Interface\{446C0065-0A4E-5090-9094-FF9FDBFF5692}\(Default)
  • HKEY_CURRENT_USER\Software\Classes\Wow6432Node\Interface\{446C0065-0A4E-5090-9094-FF9FDBFF5692}\ProxyStubClsid32\(Default)
  • HKEY_CURRENT_USER\Software\Classes\Wow6432Node\Interface\{446C0065-0A4E-5090-9094-FF9FDBFF5692}\TypeLib\(Default)
  • HKEY_CURRENT_USER\Software\Classes\Wow6432Node\Interface\{446C0065-0A4E-5090-9094-FF9FDBFF5692}\TypeLib\Version
  • HKEY_CURRENT_USER\Software\Classes\Interface\{446C0065-0A4E-5090-9094-FF9FDBFF5692}\(Default)
  • HKEY_CURRENT_USER\Software\Classes\Interface\{446C0065-0A4E-5090-9094-FF9FDBFF5692}\ProxyStubClsid32\(Default)
  • HKEY_CURRENT_USER\Software\Classes\Interface\{446C0065-0A4E-5090-9094-FF9FDBFF5692}\TypeLib\(Default)
  • HKEY_CURRENT_USER\Software\Classes\Interface\{446C0065-0A4E-5090-9094-FF9FDBFF5692}\TypeLib\Version
  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\OLE\MaximumAllowedAllocationSize
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{6D85FED0-9D91-4885-A76B-C5CFD468CF23}\1.0\(Default)
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{6D85FED0-9D91-4885-A76B-C5CFD468CF23}\1.0\FLAGS\(Default)
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{6D85FED0-9D91-4885-A76B-C5CFD468CF23}\1.0\0\win32\(Default)
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{6D85FED0-9D91-4885-A76B-C5CFD468CF23}\1.0\HELPDIR\(Default)
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{726F412C-1ECA-465C-9C85-DC277F331EDD}\(Default)
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{726F412C-1ECA-465C-9C85-DC277F331EDD}\ProxyStubClsid32\(Default)
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{726F412C-1ECA-465C-9C85-DC277F331EDD}\TypeLib\(Default)
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{726F412C-1ECA-465C-9C85-DC277F331EDD}\TypeLib\Version
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{726F412C-1ECA-465C-9C85-DC277F331EDD}\(Default)
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{726F412C-1ECA-465C-9C85-DC277F331EDD}\ProxyStubClsid32\(Default)
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{726F412C-1ECA-465C-9C85-DC277F331EDD}\TypeLib\(Default)
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{726F412C-1ECA-465C-9C85-DC277F331EDD}\TypeLib\Version
  • HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows\DragMinDist
  • HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows\DragDelay
修改的注册表键
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\UNCAsIntranet
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\AutoDetect
  • HKEY_CURRENT_USER\Software\szw\MasterZ
  • HKEY_CURRENT_USER\Software\szw\MasterZ\StationLastupdateTime
  • HKEY_CURRENT_USER\Software\szw\MasterZ\Setup
  • HKEY_CURRENT_USER\Software\szw\MasterZ\Setup\AxLog
  • HKEY_CURRENT_USER\Software\szw\MasterZ\Setup\AxLogFile
  • HKEY_CURRENT_USER\Software\szw\MasterZ\Setup\Client
  • HKEY_CURRENT_USER\Software\szw\MasterZ\Setup\DownLoad Path
  • HKEY_CURRENT_USER\Software\szw\MasterZ\Setup\Install Path
  • HKEY_CURRENT_USER\Software\szw\MasterZ\Setup\MCProc
  • HKEY_CURRENT_USER\Software\szw\MasterZ\Setup\KWproc
  • HKEY_CURRENT_USER\Software\szw\MasterZ\Setup\registerfileTime
  • HKEY_CURRENT_USER\Software\szw\MasterZ\Setup\version
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\16898.cc
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\16898.cc\http
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\sumszw.com\www
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\sumszw.com\www\http
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\MAIN\FeatureControl\FEATURE_BROWSER_EMULATION\Engine.exe
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\MAIN\FeatureControl\FEATURE_BROWSER_EMULATION\MC.exe
  • HKEY_CURRENT_USER\Software\MozillaPlugins\sumszw.com/szwplugin\Path
  • HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Uninstall\\xe6\xa0\x87\xe5\x87\x86\xe4\xbb\xb6
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\\xe6\xa0\x87\xe5\x87\x86\xe4\xbb\xb6\DisplayName
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\\xe6\xa0\x87\xe5\x87\x86\xe4\xbb\xb6\UninstallString
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\\xe6\xa0\x87\xe5\x87\x86\xe4\xbb\xb6\DisplayIcon
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\\xe6\xa0\x87\xe5\x87\x86\xe4\xbb\xb6\URLInfoAbout
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\\xe6\xa0\x87\xe5\x87\x86\xe4\xbb\xb6\Publisher
  • HKEY_CURRENT_USER\Software\Classes\Local Settings\MuiCache\4B\AAF68885\LanguageList
  • HKEY_CURRENT_USER\Software\Classes\Local Settings\MuiCache\4B\AAF68885\@%SystemRoot%\system32\dhcpqec.dll,-100
  • HKEY_CURRENT_USER\Software\Classes\Local Settings\MuiCache\4B\AAF68885\@%SystemRoot%\system32\dhcpqec.dll,-101
  • HKEY_CURRENT_USER\Software\Classes\Local Settings\MuiCache\4B\AAF68885\@%SystemRoot%\system32\dhcpqec.dll,-103
  • HKEY_CURRENT_USER\Software\Classes\Local Settings\MuiCache\4B\AAF68885\@%SystemRoot%\system32\dhcpqec.dll,-102
  • HKEY_CURRENT_USER\Software\Classes\Local Settings\MuiCache\4B\AAF68885\@%SystemRoot%\system32\napipsec.dll,-1
  • HKEY_CURRENT_USER\Software\Classes\Local Settings\MuiCache\4B\AAF68885\@%SystemRoot%\system32\napipsec.dll,-2
  • HKEY_CURRENT_USER\Software\Classes\Local Settings\MuiCache\4B\AAF68885\@%SystemRoot%\system32\napipsec.dll,-4
  • HKEY_CURRENT_USER\Software\Classes\Local Settings\MuiCache\4B\AAF68885\@%SystemRoot%\system32\napipsec.dll,-3
  • HKEY_CURRENT_USER\Software\Classes\Local Settings\MuiCache\4B\AAF68885\@%SystemRoot%\system32\tsgqec.dll,-100
  • HKEY_CURRENT_USER\Software\Classes\Local Settings\MuiCache\4B\AAF68885\@%SystemRoot%\system32\tsgqec.dll,-101
  • HKEY_CURRENT_USER\Software\Classes\Local Settings\MuiCache\4B\AAF68885\@%SystemRoot%\system32\tsgqec.dll,-102
  • HKEY_CURRENT_USER\Software\Classes\Local Settings\MuiCache\4B\AAF68885\@%SystemRoot%\system32\tsgqec.dll,-103
  • HKEY_CURRENT_USER\Software\Classes\Local Settings\MuiCache\4B\AAF68885\@%SystemRoot%\system32\eapqec.dll,-100
  • HKEY_CURRENT_USER\Software\Classes\Local Settings\MuiCache\4B\AAF68885\@%SystemRoot%\system32\eapqec.dll,-101
  • HKEY_CURRENT_USER\Software\Classes\Local Settings\MuiCache\4B\AAF68885\@%SystemRoot%\system32\eapqec.dll,-102
  • HKEY_CURRENT_USER\Software\Classes\Local Settings\MuiCache\4B\AAF68885\@%SystemRoot%\system32\eapqec.dll,-103
  • HKEY_CURRENT_USER\Software\Classes\AppID\{B415CD14-B45D-4BCA-B552-B06175C38606}
  • HKEY_CURRENT_USER\Software\Classes\AppID\{B415CD14-B45D-4BCA-B552-B06175C38606}\(Default)
  • HKEY_CURRENT_USER\Software\Classes\AppID\npszwplugin.dll
  • HKEY_CURRENT_USER\Software\Classes\AppID\npszwplugin.dll\AppID
  • HKEY_CURRENT_USER\Software\Classes\Sumszw.szwplugin.1
  • HKEY_CURRENT_USER\Software\Classes\Sumszw.szwplugin.1\(Default)
  • HKEY_CURRENT_USER\Software\Classes\Sumszw.szwplugin.1\CLSID
  • HKEY_CURRENT_USER\Software\Classes\Sumszw.szwplugin.1\CLSID\(Default)
  • HKEY_CURRENT_USER\Software\Classes\Sumszw.szwplugin
  • HKEY_CURRENT_USER\Software\Classes\Sumszw.szwplugin\(Default)
  • HKEY_CURRENT_USER\Software\Classes\Sumszw.szwplugin\CLSID
  • HKEY_CURRENT_USER\Software\Classes\Sumszw.szwplugin\CLSID\(Default)
  • HKEY_CURRENT_USER\Software\Classes\Sumszw.szwplugin\CurVer
  • HKEY_CURRENT_USER\Software\Classes\Sumszw.szwplugin\CurVer\(Default)
  • HKEY_CURRENT_USER\Software\Classes\Wow6432Node\CLSID\{92834c16-4bb2-5be0-8496-af603887da4d}
  • HKEY_CURRENT_USER\Software\Classes\Wow6432Node\CLSID\{92834c16-4bb2-5be0-8496-af603887da4d}\(Default)
  • HKEY_CURRENT_USER\Software\Classes\Wow6432Node\CLSID\{92834c16-4bb2-5be0-8496-af603887da4d}\ProgID
  • HKEY_CURRENT_USER\Software\Classes\Wow6432Node\CLSID\{92834c16-4bb2-5be0-8496-af603887da4d}\ProgID\(Default)
  • HKEY_CURRENT_USER\Software\Classes\Wow6432Node\CLSID\{92834c16-4bb2-5be0-8496-af603887da4d}\VersionIndependentProgID
  • HKEY_CURRENT_USER\Software\Classes\Wow6432Node\CLSID\{92834c16-4bb2-5be0-8496-af603887da4d}\VersionIndependentProgID\(Default)
  • HKEY_CURRENT_USER\Software\Classes\Wow6432Node\CLSID\{92834c16-4bb2-5be0-8496-af603887da4d}\Programmable
  • HKEY_CURRENT_USER\Software\Classes\Wow6432Node\CLSID\{92834c16-4bb2-5be0-8496-af603887da4d}\InprocServer32
  • HKEY_CURRENT_USER\Software\Classes\Wow6432Node\CLSID\{92834c16-4bb2-5be0-8496-af603887da4d}\InprocServer32\(Default)
  • HKEY_CURRENT_USER\Software\Classes\Wow6432Node\CLSID\{92834c16-4bb2-5be0-8496-af603887da4d}\InprocServer32\ThreadingModel
  • HKEY_CURRENT_USER\Software\Classes\Wow6432Node\CLSID\{92834c16-4bb2-5be0-8496-af603887da4d}\AppID
  • HKEY_CURRENT_USER\Software\Classes\Wow6432Node\CLSID\{92834c16-4bb2-5be0-8496-af603887da4d}\Control
  • HKEY_CURRENT_USER\Software\Classes\Wow6432Node\CLSID\{92834c16-4bb2-5be0-8496-af603887da4d}\MiscStatus
  • HKEY_CURRENT_USER\Software\Classes\Wow6432Node\CLSID\{92834c16-4bb2-5be0-8496-af603887da4d}\MiscStatus\(Default)
  • HKEY_CURRENT_USER\Software\Classes\Wow6432Node\CLSID\{92834c16-4bb2-5be0-8496-af603887da4d}\MiscStatus\1
  • HKEY_CURRENT_USER\Software\Classes\Wow6432Node\CLSID\{92834c16-4bb2-5be0-8496-af603887da4d}\MiscStatus\1\(Default)
  • HKEY_CURRENT_USER\Software\Classes\Wow6432Node\CLSID\{92834c16-4bb2-5be0-8496-af603887da4d}\TypeLib
  • HKEY_CURRENT_USER\Software\Classes\Wow6432Node\CLSID\{92834c16-4bb2-5be0-8496-af603887da4d}\TypeLib\(Default)
  • HKEY_CURRENT_USER\Software\Classes\Wow6432Node\CLSID\{92834c16-4bb2-5be0-8496-af603887da4d}\Version
  • HKEY_CURRENT_USER\Software\Classes\Wow6432Node\CLSID\{92834c16-4bb2-5be0-8496-af603887da4d}\Version\(Default)
  • HKEY_CURRENT_USER\Software\Classes\MIME\Database\Content Type\application/x-szwplugin
  • HKEY_CURRENT_USER\Software\Classes\MIME\Database\Content Type\application/x-szwplugin\(Default)
  • HKEY_CURRENT_USER\Software\Classes\MIME\Database\Content Type\application/x-szwplugin\Extension
  • HKEY_CURRENT_USER\Software\Classes\MIME\Database\Content Type\application/x-szwplugin\CLSID
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{92834c16-4bb2-5be0-8496-af603887da4d}
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{92834c16-4bb2-5be0-8496-af603887da4d}
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{92834c16-4bb2-5be0-8496-af603887da4d}\iexplore
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{92834c16-4bb2-5be0-8496-af603887da4d}\iexplore\AllowedDomains
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{92834c16-4bb2-5be0-8496-af603887da4d}\iexplore\AllowedDomains\*
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{92834c16-4bb2-5be0-8496-af603887da4d}\iexplore\Count
  • HKEY_CURRENT_USER\Software\MozillaPlugins\sumszw.com/szwplugin
  • HKEY_CURRENT_USER\Software\Classes\TypeLib\{73F92EE3-0C4F-53E3-8FDA-A571E532950E}
  • HKEY_CURRENT_USER\Software\Classes\TypeLib\{73F92EE3-0C4F-53E3-8FDA-A571E532950E}\1.0
  • HKEY_CURRENT_USER\Software\Classes\TypeLib\{73F92EE3-0C4F-53E3-8FDA-A571E532950E}\1.0\(Default)
  • HKEY_CURRENT_USER\Software\Classes\TypeLib\{73F92EE3-0C4F-53E3-8FDA-A571E532950E}\1.0\FLAGS
  • HKEY_CURRENT_USER\Software\Classes\TypeLib\{73F92EE3-0C4F-53E3-8FDA-A571E532950E}\1.0\FLAGS\(Default)
  • HKEY_CURRENT_USER\Software\Classes\TypeLib\{73F92EE3-0C4F-53E3-8FDA-A571E532950E}\1.0\0
  • HKEY_CURRENT_USER\Software\Classes\TypeLib\{73F92EE3-0C4F-53E3-8FDA-A571E532950E}\1.0\0\win32
  • HKEY_CURRENT_USER\Software\Classes\TypeLib\{73F92EE3-0C4F-53E3-8FDA-A571E532950E}\1.0\0\win32\(Default)
  • HKEY_CURRENT_USER\Software\Classes\TypeLib\{73F92EE3-0C4F-53E3-8FDA-A571E532950E}\1.0\HELPDIR
  • HKEY_CURRENT_USER\Software\Classes\TypeLib\{73F92EE3-0C4F-53E3-8FDA-A571E532950E}\1.0\HELPDIR\(Default)
  • HKEY_CURRENT_USER\Software\Classes\Wow6432Node\Interface\{1EE0264C-67B3-5477-953B-CF7F87D70680}
  • HKEY_CURRENT_USER\Software\Classes\Wow6432Node\Interface\{1EE0264C-67B3-5477-953B-CF7F87D70680}\(Default)
  • HKEY_CURRENT_USER\Software\Classes\Wow6432Node\Interface\{1EE0264C-67B3-5477-953B-CF7F87D70680}\ProxyStubClsid32
  • HKEY_CURRENT_USER\Software\Classes\Wow6432Node\Interface\{1EE0264C-67B3-5477-953B-CF7F87D70680}\ProxyStubClsid32\(Default)
  • HKEY_CURRENT_USER\Software\Classes\Wow6432Node\Interface\{1EE0264C-67B3-5477-953B-CF7F87D70680}\TypeLib
  • HKEY_CURRENT_USER\Software\Classes\Wow6432Node\Interface\{1EE0264C-67B3-5477-953B-CF7F87D70680}\TypeLib\(Default)
  • HKEY_CURRENT_USER\Software\Classes\Wow6432Node\Interface\{1EE0264C-67B3-5477-953B-CF7F87D70680}\TypeLib\Version
  • HKEY_CURRENT_USER\Software\Classes\Interface\{1EE0264C-67B3-5477-953B-CF7F87D70680}
  • HKEY_CURRENT_USER\Software\Classes\Interface\{1EE0264C-67B3-5477-953B-CF7F87D70680}\(Default)
  • HKEY_CURRENT_USER\Software\Classes\Interface\{1EE0264C-67B3-5477-953B-CF7F87D70680}\ProxyStubClsid32
  • HKEY_CURRENT_USER\Software\Classes\Interface\{1EE0264C-67B3-5477-953B-CF7F87D70680}\ProxyStubClsid32\(Default)
  • HKEY_CURRENT_USER\Software\Classes\Interface\{1EE0264C-67B3-5477-953B-CF7F87D70680}\TypeLib
  • HKEY_CURRENT_USER\Software\Classes\Interface\{1EE0264C-67B3-5477-953B-CF7F87D70680}\TypeLib\(Default)
  • HKEY_CURRENT_USER\Software\Classes\Interface\{1EE0264C-67B3-5477-953B-CF7F87D70680}\TypeLib\Version
  • HKEY_CURRENT_USER\Software\Classes\Wow6432Node\Interface\{BBA8BF1D-8C1E-5C71-8C9E-610A792952D8}
  • HKEY_CURRENT_USER\Software\Classes\Wow6432Node\Interface\{BBA8BF1D-8C1E-5C71-8C9E-610A792952D8}\(Default)
  • HKEY_CURRENT_USER\Software\Classes\Wow6432Node\Interface\{BBA8BF1D-8C1E-5C71-8C9E-610A792952D8}\ProxyStubClsid32
  • HKEY_CURRENT_USER\Software\Classes\Wow6432Node\Interface\{BBA8BF1D-8C1E-5C71-8C9E-610A792952D8}\ProxyStubClsid32\(Default)
  • HKEY_CURRENT_USER\Software\Classes\Wow6432Node\Interface\{BBA8BF1D-8C1E-5C71-8C9E-610A792952D8}\TypeLib
  • HKEY_CURRENT_USER\Software\Classes\Wow6432Node\Interface\{BBA8BF1D-8C1E-5C71-8C9E-610A792952D8}\TypeLib\(Default)
  • HKEY_CURRENT_USER\Software\Classes\Wow6432Node\Interface\{BBA8BF1D-8C1E-5C71-8C9E-610A792952D8}\TypeLib\Version
  • HKEY_CURRENT_USER\Software\Classes\Interface\{BBA8BF1D-8C1E-5C71-8C9E-610A792952D8}
  • HKEY_CURRENT_USER\Software\Classes\Interface\{BBA8BF1D-8C1E-5C71-8C9E-610A792952D8}\(Default)
  • HKEY_CURRENT_USER\Software\Classes\Interface\{BBA8BF1D-8C1E-5C71-8C9E-610A792952D8}\ProxyStubClsid32
  • HKEY_CURRENT_USER\Software\Classes\Interface\{BBA8BF1D-8C1E-5C71-8C9E-610A792952D8}\ProxyStubClsid32\(Default)
  • HKEY_CURRENT_USER\Software\Classes\Interface\{BBA8BF1D-8C1E-5C71-8C9E-610A792952D8}\TypeLib
  • HKEY_CURRENT_USER\Software\Classes\Interface\{BBA8BF1D-8C1E-5C71-8C9E-610A792952D8}\TypeLib\(Default)
  • HKEY_CURRENT_USER\Software\Classes\Interface\{BBA8BF1D-8C1E-5C71-8C9E-610A792952D8}\TypeLib\Version
  • HKEY_CURRENT_USER\Software\Classes\Wow6432Node\Interface\{446C0065-0A4E-5090-9094-FF9FDBFF5692}
  • HKEY_CURRENT_USER\Software\Classes\Wow6432Node\Interface\{446C0065-0A4E-5090-9094-FF9FDBFF5692}\(Default)
  • HKEY_CURRENT_USER\Software\Classes\Wow6432Node\Interface\{446C0065-0A4E-5090-9094-FF9FDBFF5692}\ProxyStubClsid32
  • HKEY_CURRENT_USER\Software\Classes\Wow6432Node\Interface\{446C0065-0A4E-5090-9094-FF9FDBFF5692}\ProxyStubClsid32\(Default)
  • HKEY_CURRENT_USER\Software\Classes\Wow6432Node\Interface\{446C0065-0A4E-5090-9094-FF9FDBFF5692}\TypeLib
  • HKEY_CURRENT_USER\Software\Classes\Wow6432Node\Interface\{446C0065-0A4E-5090-9094-FF9FDBFF5692}\TypeLib\(Default)
  • HKEY_CURRENT_USER\Software\Classes\Wow6432Node\Interface\{446C0065-0A4E-5090-9094-FF9FDBFF5692}\TypeLib\Version
  • HKEY_CURRENT_USER\Software\Classes\Interface\{446C0065-0A4E-5090-9094-FF9FDBFF5692}
  • HKEY_CURRENT_USER\Software\Classes\Interface\{446C0065-0A4E-5090-9094-FF9FDBFF5692}\(Default)
  • HKEY_CURRENT_USER\Software\Classes\Interface\{446C0065-0A4E-5090-9094-FF9FDBFF5692}\ProxyStubClsid32
  • HKEY_CURRENT_USER\Software\Classes\Interface\{446C0065-0A4E-5090-9094-FF9FDBFF5692}\ProxyStubClsid32\(Default)
  • HKEY_CURRENT_USER\Software\Classes\Interface\{446C0065-0A4E-5090-9094-FF9FDBFF5692}\TypeLib
  • HKEY_CURRENT_USER\Software\Classes\Interface\{446C0065-0A4E-5090-9094-FF9FDBFF5692}\TypeLib\(Default)
  • HKEY_CURRENT_USER\Software\Classes\Interface\{446C0065-0A4E-5090-9094-FF9FDBFF5692}\TypeLib\Version
  • HKEY_CURRENT_USER\Software\Classes\AppID\{6D85FED0-9D91-4885-A76B-C5CFD468CF23}
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{6D85FED0-9D91-4885-A76B-C5CFD468CF23}\(Default)
  • HKEY_CURRENT_USER\Software\Classes\AppID\ieplugin.DLL
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\ieplugin.DLL\AppID
  • HKEY_CLASSES_ROOT\ieplugin.SZWCtrl1.0.0.1
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\ieplugin.SZWCtrl1.0.0.1\(Default)
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\ieplugin.SZWCtrl1.0.0.1\CLSID
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\ieplugin.SZWCtrl1.0.0.1\CLSID\(Default)
  • HKEY_CLASSES_ROOT\ieplugin.SZWCtrl
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\ieplugin.SZWCtrl\(Default)
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\ieplugin.SZWCtrl\CLSID
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\ieplugin.SZWCtrl\CLSID\(Default)
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\ieplugin.SZWCtrl\CurVer
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\ieplugin.SZWCtrl\CurVer\(Default)
  • HKEY_CURRENT_USER\Software\Classes\Wow6432Node\CLSID\{A82F3915-72D8-4837-BDDC-4A3BBA9C725A}
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A82F3915-72D8-4837-BDDC-4A3BBA9C725A}\(Default)
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A82F3915-72D8-4837-BDDC-4A3BBA9C725A}\ProgID
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A82F3915-72D8-4837-BDDC-4A3BBA9C725A}\ProgID\(Default)
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A82F3915-72D8-4837-BDDC-4A3BBA9C725A}\VersionIndependentProgID
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A82F3915-72D8-4837-BDDC-4A3BBA9C725A}\VersionIndependentProgID\(Default)
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A82F3915-72D8-4837-BDDC-4A3BBA9C725A}\Programmable
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A82F3915-72D8-4837-BDDC-4A3BBA9C725A}\InprocServer32
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A82F3915-72D8-4837-BDDC-4A3BBA9C725A}\InprocServer32\(Default)
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A82F3915-72D8-4837-BDDC-4A3BBA9C725A}\InprocServer32\ThreadingModel
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A82F3915-72D8-4837-BDDC-4A3BBA9C725A}\AppID
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A82F3915-72D8-4837-BDDC-4A3BBA9C725A}\TypeLib
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A82F3915-72D8-4837-BDDC-4A3BBA9C725A}\TypeLib\(Default)
  • HKEY_CURRENT_USER\Software\Classes\TypeLib\{6D85FED0-9D91-4885-A76B-C5CFD468CF23}
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{6D85FED0-9D91-4885-A76B-C5CFD468CF23}\1.0
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{6D85FED0-9D91-4885-A76B-C5CFD468CF23}\1.0\(Default)
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{6D85FED0-9D91-4885-A76B-C5CFD468CF23}\1.0\FLAGS
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{6D85FED0-9D91-4885-A76B-C5CFD468CF23}\1.0\FLAGS\(Default)
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{6D85FED0-9D91-4885-A76B-C5CFD468CF23}\1.0\0
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{6D85FED0-9D91-4885-A76B-C5CFD468CF23}\1.0\0\win32
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{6D85FED0-9D91-4885-A76B-C5CFD468CF23}\1.0\0\win32\(Default)
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{6D85FED0-9D91-4885-A76B-C5CFD468CF23}\1.0\HELPDIR
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{6D85FED0-9D91-4885-A76B-C5CFD468CF23}\1.0\HELPDIR\(Default)
  • HKEY_CURRENT_USER\Software\Classes\Wow6432Node\Interface\{726F412C-1ECA-465C-9C85-DC277F331EDD}
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{726F412C-1ECA-465C-9C85-DC277F331EDD}\(Default)
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{726F412C-1ECA-465C-9C85-DC277F331EDD}\ProxyStubClsid32
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{726F412C-1ECA-465C-9C85-DC277F331EDD}\ProxyStubClsid32\(Default)
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{726F412C-1ECA-465C-9C85-DC277F331EDD}\TypeLib
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{726F412C-1ECA-465C-9C85-DC277F331EDD}\TypeLib\(Default)
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{726F412C-1ECA-465C-9C85-DC277F331EDD}\TypeLib\Version
  • HKEY_CURRENT_USER\Software\Classes\Interface\{726F412C-1ECA-465C-9C85-DC277F331EDD}
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{726F412C-1ECA-465C-9C85-DC277F331EDD}\(Default)
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{726F412C-1ECA-465C-9C85-DC277F331EDD}\ProxyStubClsid32
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{726F412C-1ECA-465C-9C85-DC277F331EDD}\ProxyStubClsid32\(Default)
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{726F412C-1ECA-465C-9C85-DC277F331EDD}\TypeLib
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{726F412C-1ECA-465C-9C85-DC277F331EDD}\TypeLib\(Default)
  • HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{726F412C-1ECA-465C-9C85-DC277F331EDD}\TypeLib\Version
删除的注册表键
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\ProxyBypass
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\ProxyBypass
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\IntranetName
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\IntranetName
  • HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\SESSION MANAGER\PendingFileRenameOperations
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\MAIN\FeatureControl\FEATURE_BROWSER_EMULATION\Sumengine2.exe
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\MAIN\FeatureControl\FEATURE_BROWSER_EMULATION\webMcProc.exe
  • HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\MasterZ
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run\MasterZ
API解析
  • cryptbase.dll.SystemFunction036
  • shfolder.dll.SHGetFolderPathW
  • setupapi.dll.CM_Get_Device_Interface_List_Size_ExW
  • setupapi.dll.CM_Get_Device_Interface_List_ExW
  • kernel32.dll.GetUserDefaultUILanguage
  • kernel32.dll.FlsAlloc
  • kernel32.dll.FlsFree
  • kernel32.dll.FlsGetValue
  • kernel32.dll.FlsSetValue
  • kernel32.dll.InitializeCriticalSectionEx
  • kernel32.dll.CreateEventExW
  • kernel32.dll.CreateSemaphoreExW
  • kernel32.dll.SetThreadStackGuarantee
  • kernel32.dll.CreateThreadpoolTimer
  • kernel32.dll.SetThreadpoolTimer
  • kernel32.dll.WaitForThreadpoolTimerCallbacks
  • kernel32.dll.CloseThreadpoolTimer
  • kernel32.dll.CreateThreadpoolWait
  • kernel32.dll.SetThreadpoolWait
  • kernel32.dll.CloseThreadpoolWait
  • kernel32.dll.FlushProcessWriteBuffers
  • kernel32.dll.FreeLibraryWhenCallbackReturns
  • kernel32.dll.GetCurrentProcessorNumber
  • kernel32.dll.GetLogicalProcessorInformation
  • kernel32.dll.CreateSymbolicLinkW
  • kernel32.dll.EnumSystemLocalesEx
  • kernel32.dll.CompareStringEx
  • kernel32.dll.GetDateFormatEx
  • kernel32.dll.GetLocaleInfoEx
  • kernel32.dll.GetTimeFormatEx
  • kernel32.dll.GetUserDefaultLocaleName
  • kernel32.dll.IsValidLocaleName
  • kernel32.dll.LCMapStringEx
  • kernel32.dll.GetTickCount64
  • nstbciaskinengine.dll.InitialLog
  • comctl32.dll.RegisterClassNameW
  • uxtheme.dll.EnableThemeDialogTexture
  • ole32.dll.CoInitializeEx
  • ole32.dll.CoUninitialize
  • ole32.dll.CoRegisterInitializeSpy
  • ole32.dll.CoRevokeInitializeSpy
  • gdi32.dll.GetLayout
  • gdi32.dll.GdiRealizationInfo
  • gdi32.dll.FontIsLinked
  • advapi32.dll.RegOpenKeyExW
  • advapi32.dll.RegQueryInfoKeyW
  • gdi32.dll.GetTextFaceAliasW
  • advapi32.dll.RegEnumValueW
  • advapi32.dll.RegCloseKey
  • advapi32.dll.RegQueryValueExW
  • advapi32.dll.RegQueryValueExA
  • advapi32.dll.RegEnumKeyExW
  • gdi32.dll.GetTextExtentExPointWPri
  • system.dll.Call
  • kernel32.dll.GetDiskFreeSpaceExW
  • system.dll.Int64Op
  • kernel32.dll.CreateMutexW
  • nstbciaskinengine.dll.PrintLog
  • uxtheme.dll.OpenThemeData
  • imm32.dll.ImmIsIME
  • gdi32.dll.GetFontAssocStatus
  • gdi32.dll.GdiIsMetaPrintDC
  • ole32.dll.OleInitialize
  • propsys.dll.PSCreateMemoryPropertyStore
  • propsys.dll.PSPropertyBag_WriteDWORD
  • propsys.dll.PSPropertyBag_ReadDWORD
  • propsys.dll.PSPropertyBag_ReadGUID
  • urlmon.dll.CreateUri
  • kernel32.dll.InitializeSRWLock
  • kernel32.dll.AcquireSRWLockExclusive
  • kernel32.dll.AcquireSRWLockShared
  • kernel32.dll.ReleaseSRWLockExclusive
  • kernel32.dll.ReleaseSRWLockShared
  • propsys.dll.PSPropertyBag_ReadStrAlloc
  • propsys.dll.#430
  • advapi32.dll.RegGetValueW
  • ole32.dll.CoTaskMemRealloc
  • propsys.dll.InitPropVariantFromStringAsVector
  • propsys.dll.PSCoerceToCanonicalValue
  • propsys.dll.PropVariantToStringAlloc
  • ole32.dll.CoAllowSetForegroundWindow
  • ole32.dll.CoCreateInstance
  • shell32.dll.SHGetFolderPathW
  • advapi32.dll.SaferGetPolicyInformation
  • ntdll.dll.RtlDllShutdownInProgress
  • comctl32.dll.#329
  • ole32.dll.OleUninitialize
  • comctl32.dll.#388
  • oleaut32.dll.#500
  • findprocdll.dll.FindProc
  • psapi.dll.EnumProcesses
  • psapi.dll.EnumProcessModules
  • psapi.dll.GetModuleBaseNameW
  • nsexec.dll.Exec
  • kernel32.dll.IsWow64Process
  • nsexec.dll.ExecToLog
  • advapi32.dll.RegDeleteKeyExW
  • kernel32.dll.GetCurrentProcess
  • system.dll.Alloc
  • kernel32.dll.GetVersionExW
  • system.dll.Free
  • installoptions.dll.initDialog
  • installoptions.dll.show
  • sechost.dll.LookupAccountNameLocalW
  • advapi32.dll.LookupAccountSidW
  • sechost.dll.LookupAccountSidLocalW
  • winsta.dll.WinStationFreeMemory
  • winsta.dll.WinStationCloseServer
  • winsta.dll.WinStationOpenServerW
  • winsta.dll.WinStationFreeGAPMemory
  • winsta.dll.WinStationGetAllProcesses
  • winsta.dll.WinStationEnumerateProcesses
  • kernel32.dll.SortGetHandle
  • kernel32.dll.SortCloseHandle
  • kernel32.dll.GetThreadPreferredUILanguages
  • kernel32.dll.SetThreadPreferredUILanguages
  • kernel32.dll.LocaleNameToLCID
  • kernel32.dll.LCIDToLocaleName
  • kernel32.dll.GetSystemDefaultLocaleName
  • oleaut32.dll.#283
  • oleaut32.dll.#284
  • kernel32.dll.RegOpenKeyExW
  • ntdll.dll.EtwUnregisterTraceGuids
  • cryptsp.dll.CryptReleaseContext
  • kernel32.dll.SetThreadUILanguage
  • kernel32.dll.CopyFileExW
  • kernel32.dll.IsDebuggerPresent
  • kernel32.dll.SetConsoleInputExeNameW
  • rpcrt4.dll.I_RpcSNCHOption
  • sechost.dll.OpenSCManagerW
  • sechost.dll.OpenServiceW
  • sechost.dll.CloseServiceHandle
  • rasmontr.dll.InitHelperDll
  • nshwfp.dll.InitHelperDll
  • dhcpcmonitor.dll.InitHelperDll
  • wshelper.dll.InitHelperDll
  • nshhttp.dll.InitHelperDll
  • fwcfg.dll.InitHelperDll
  • authfwcfg.dll.InitHelperDll
  • ifmon.dll.InitHelperDll
  • netiohlp.dll.InitHelperDll
  • whhelper.dll.InitHelperDll
  • hnetmon.dll.InitHelperDll
  • rpcnsh.dll.InitHelperDll
  • dot3cfg.dll.InitHelperDll
  • napmontr.dll.InitHelperDll
  • nshipsec.dll.InitHelperDll
  • p2pnetsh.dll.InitHelperDll
  • wlancfg.dll.InitHelperDll
  • peerdistsh.dll.InitHelperDll
  • sechost.dll.QueryServiceStatus
  • sechost.dll.StartServiceW
  • cryptsp.dll.CryptEnumProvidersW
  • user32.dll.LoadStringW
  • advapi32.dll.RegCreateKeyExW
  • sechost.dll.QueryServiceConfigW
  • ole32.dll.CoTaskMemFree
  • cryptsp.dll.CryptAcquireContextW
  • cryptsp.dll.CryptGenRandom
  • rpcrtremote.dll.I_RpcExtInitializeExtensionPoint
  • httpapi.dll.HttpInitialize
  • userenv.dll.RegisterGPNotification
  • userenv.dll.UnregisterGPNotification
  • gpapi.dll.RegisterGPNotificationInternal
  • bcryptprimitives.dll.GetHashInterface
  • bcryptprimitives.dll.GetCipherInterface
  • advapi32.dll.CreateWellKnownSid
  • httpapi.dll.HttpTerminate
  • gpapi.dll.UnregisterGPNotificationInternal
  • oleaut32.dll.#9
  • advapi32.dll.StartServiceCtrlDispatcherW
  • npszwplugin.dll.DllRegisterServer
  • kernel32.dll.NlsGetCacheUpdateCount
  • oleaut32.dll.RegisterTypeLibForUser
  • advapi32.dll.RegOpenKeyW
  • ieplugin.dll.DllRegisterServer
  • xmlrw.dll.GetXmlObj
  • keyrw.dll.CreateObj
  • keyrw.dll.DeleteMem
  • xmlrw.dll.DeleteMemory
  • kernel32.dll.SetUnhandledExceptionFilter
  • kernel32.dll.IsProcessorFeaturePresent
  • user32.dll.GetWindowInfo
  • user32.dll.GetAncestor
  • user32.dll.GetMonitorInfoA
  • user32.dll.EnumDisplayMonitors
  • user32.dll.EnumDisplayDevicesA
  • gdi32.dll.ExtTextOutW
  • urlmon.dll.#414
  • rasapi32.dll.RasConnectionNotificationW
  • sechost.dll.NotifyServiceStatusChangeA